Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 06-05-2015 01
Ran by Neal (administrator) on HOMESCHOOL1 on 08-05-2015 12:55:29
Running from C:\Users\Neal\Desktop
Loaded Profiles: Neal (Available profiles: Neal & Sean & Noelle & Administrator)
Platform: Windows 8.1 (X64) OS Language: English (United States)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe
(Hewlett-Packard Company) C:\Windows\System32\hpservice.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(Microsoft Corporation) C:\Windows\SysWOW64\dllhost.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe
(CyberLink) C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe
(Apple Computer, Inc.) C:\Program Files (x86)\QuickTime\qttask.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
(Microsoft Corporation) C:\Windows\SysWOW64\dllhost.exe
(WildTangent) C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe
(Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
(Akeo Consulting (
http://akeo.ie)) C:\Users\Neal\AppData\Local\Temp\8FB3.tmp
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
() C:\Users\Neal\AppData\Local\Temp\9FD4.tmp
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Microsoft Corporation) C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Microsoft Corporation) C:\Windows\SysWOW64\logagent.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Microsoft Corporation) C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
(Microsoft Corporation) C:\Windows\System32\wermgr.exe
(Microsoft Corporation) C:\Windows\System32\cmd.exe
(Microsoft Corporation) C:\Windows\System32\cmd.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
Failed to access process -> HPConnectedRemoteService.exe
(Microsoft Corporation) C:\Windows\System32\WerFault.exe
(Microsoft Corporation) C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
Failed to access process -> HPConnectedRemoteService.exe
(Microsoft Corporation) C:\Windows\System32\WerFault.exe
Failed to access process -> HPConnectedRemoteService.exe
(Microsoft Corporation) C:\Windows\System32\WerFault.exe
Failed to access process -> HPConnectedRemoteService.exe
(Microsoft Corporation) C:\Windows\System32\WerFault.exe
(Microsoft Corporation) C:\Windows\SysWOW64\dvdupgrd.exe
(Microsoft Corporation) C:\Windows\SysWOW64\dllhst3g.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP Connected Remote\HPConnectedRemoteService.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20413_x64__8wekyb3d8bbwe\livecomm.exe
(Microsoft Corporation) C:\Windows\SysWOW64\regsvr32.exe
(Microsoft Corporation) C:\Windows\SysWOW64\NAPSTAT.EXE
(Microsoft Corporation) C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [1664000 2012-08-20] (IDT, Inc.)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2916152 2012-08-24] (Synaptics Incorporated)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766688 2014-07-04] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [CLVirtualDrive] => C:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe [491632 2012-09-10] (CyberLink Corp.)
HKLM-x32\...\Run: [RemoteControl10] => C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [93296 2012-07-13] (CyberLink Corp.)
HKLM-x32\...\Run: [HP Quick Launch] => C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe [581024 2012-09-07] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [HP CoolSense] => C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe [1342008 2012-09-14] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\qttask.exe [77824 2014-08-18] (Apple Computer, Inc.)
HKU\S-1-5-21-4105420370-3369507210-3028615837-1002\...\Run: [AVNworks] => C:\Users\Neal\AppData\Local\AVNworks\L_4bv.exe
HKU\S-1-5-21-4105420370-3369507210-3028615837-1002\...\Run: [udsfurd] => rundll32 "C:\Users\Neal\AppData\Local\udsfurd.dll",udsfurd <===== ATTENTION
HKU\S-1-5-21-4105420370-3369507210-3028615837-1002\...\Run: [BluetoothManager] => rundll32.exe "%appdata%\Microsoft\bstack.dll",bs_init
HKU\S-1-5-21-4105420370-3369507210-3028615837-1002\...A8F59079A8D5}\localserver32: rundll32.exe javascript:"reie8\..\mshtml,RunHTMLApplication ";eval("qvnoq7<odv!@buhwdYNckdbu)#VRbshq (the data entry has 27907 more characters). <==== Poweliks!
Startup: C:\Users\Neal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\HELP_DECRYPT.HTML [2015-05-08] ()
Startup: C:\Users\Neal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\HELP_DECRYPT.PNG [2015-05-08] ()
Startup: C:\Users\Neal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\HELP_DECRYPT.TXT [2015-05-08] ()
InternetURL: C:\Users\Neal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\HELP_DECRYPT.URL -> hxxp://7oqnsnzwwnm6zb7y.gigapaysun.com/1sL7j4w
ShellIconOverlayIdentifiers: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File
ShellIconOverlayIdentifiers: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File
ShellIconOverlayIdentifiers: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File
ShellIconOverlayIdentifiers-x32: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File
ShellIconOverlayIdentifiers-x32: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File
ShellIconOverlayIdentifiers-x32: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://g.msn.com/HPNOT13/1
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://g.msn.com/HPNOT13/1
HKU\S-1-5-21-4105420370-3369507210-3028615837-1002\Software\Microsoft\Internet Explorer\Main,Start Page =
http://g.msn.com/HPNOT13/1
HKU\S-1-5-21-4105420370-3369507210-3028615837-1002\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://g.msn.com/HPNOT13/1
SearchScopes: HKLM -> {72A94EC8-3F90-47F1-9886-E2A151F94BD1} URL =
http://www.amazon.com/s/ref=azs_osd...ode=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKLM -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL =
http://rover.ebay.com/rover/1/711-154371-11896-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms}
SearchScopes: HKLM-x32 -> {72A94EC8-3F90-47F1-9886-E2A151F94BD1} URL =
http://www.amazon.com/s/ref=azs_osd...ode=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKLM-x32 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL =
http://rover.ebay.com/rover/1/711-154371-11896-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms}
SearchScopes: HKU\S-1-5-21-4105420370-3369507210-3028615837-1002 -> {72A94EC8-3F90-47F1-9886-E2A151F94BD1} URL =
http://www.amazon.com/s/ref=azs_osd...ode=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKU\S-1-5-21-4105420370-3369507210-3028615837-1002 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL =
http://rover.ebay.com/rover/1/711-154371-11896-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms}
BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll No File
Toolbar: HKU\S-1-5-21-4105420370-3369507210-3028615837-1002 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
FireFox:
========
FF ProfilePath: C:\Users\Neal\AppData\Roaming\Mozilla\Firefox\Profiles\hjieooub.default
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\windows\SysWOW64\Adobe\Director\np32dsw_1166636.dll [2012-08-08] (Adobe Systems, Inc.)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll [2014-05-13] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3503.0728 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-07-28] (Microsoft Corporation)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll [2014-11-14] ()
FF Extension: Windows Script Host Shell Object - C:\Users\Neal\AppData\Roaming\Mozilla\Firefox\Profiles\hjieooub.default\Extensions\{F92861AD-1977-2B60-239A-3484A474500F} [2015-05-02]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [344064 2014-07-04] (Advanced Micro Devices, Inc.) [File not signed]
S3 BthHFSrv; C:\Windows\System32\BthHFSrv.dll [324608 2014-10-28] (Microsoft Corporation)
R2 GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [373312 2015-04-14] (WildTangent)
R2 HPConnectedRemote; C:\Program Files (x86)\Hewlett-Packard\HP Connected Remote\HPConnectedRemoteService.exe [35744 2012-10-12] (Hewlett-Packard)
R2 IconMan_R; C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [2451456 2012-07-13] (Realsil Microelectronics Inc.) [File not signed]
S3 w3logsvc; C:\Windows\system32\inetsrv\w3logsvc.dll [76800 2014-09-11] (Microsoft Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366520 2015-02-03] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2015-02-03] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 AODDriver4.2.0; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [59648 2013-09-20] (Advanced Micro Devices)
R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdW86.sys [91648 2012-08-21] (Advanced Micro Devices)
R1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [92536 2012-06-25] (CyberLink)
R3 RSP2STOR; C:\Windows\system32\DRIVERS\RtsP2Stor.sys [269968 2012-07-03] (Realtek Semiconductor Corp.)
S3 SmbDrv; C:\Windows\System32\drivers\Smb_driver_AMDASF.sys [41272 2012-08-24] (Synaptics Incorporated)
S3 SmbDrvI; C:\Windows\System32\drivers\Smb_driver_Intel.sys [43832 2012-08-24] (Synaptics Incorporated)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2015-02-03] (Microsoft Corporation)
R3 WirelessButtonDriver; C:\Windows\System32\drivers\WirelessButtonDriver64.sys [20800 2012-08-31] (Hewlett-Packard Development Company, L.P.)
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-05-08 12:55 - 2015-05-08 13:03 - 00013856 _____ () C:\Users\Neal\Desktop\FRST.txt
2015-05-08 12:54 - 2015-05-08 12:49 - 02102272 _____ (Farbar) C:\Users\Neal\Desktop\FRST64.exe
2015-05-08 12:49 - 2015-05-08 12:53 - 00000000 ____D () C:\Users\Neal\AppData\Roaming\Local Store
2015-05-08 12:48 - 2015-05-08 12:48 - 00008602 _____ () C:\Users\Neal\Desktop\HELP_DECRYPT.HTML
2015-05-08 12:48 - 2015-05-08 12:48 - 00000284 _____ () C:\Users\Neal\Desktop\HELP_DECRYPT.URL
2015-05-08 12:47 - 2015-05-08 12:47 - 00008602 _____ () C:\Users\Neal\HELP_DECRYPT.HTML
2015-05-08 12:47 - 2015-05-08 12:47 - 00004244 _____ () C:\Users\Neal\HELP_DECRYPT.TXT
2015-05-08 12:47 - 2015-05-08 12:47 - 00004244 _____ () C:\Users\Neal\Desktop\HELP_DECRYPT.TXT
2015-05-08 12:47 - 2015-05-08 12:47 - 00000284 _____ () C:\Users\Neal\HELP_DECRYPT.URL
2015-05-08 12:45 - 2015-05-08 12:49 - 02102272 _____ (Farbar) C:\Users\Neal\Downloads\FRST64.exe
2015-05-08 12:45 - 2015-05-08 12:45 - 00008602 _____ () C:\Users\Neal\AppData\Roaming\HELP_DECRYPT.HTML
2015-05-08 12:45 - 2015-05-08 12:45 - 00008602 _____ () C:\Users\Neal\AppData\HELP_DECRYPT.HTML
2015-05-08 12:45 - 2015-05-08 12:45 - 00004244 _____ () C:\Users\Neal\AppData\Roaming\HELP_DECRYPT.TXT
2015-05-08 12:45 - 2015-05-08 12:45 - 00004244 _____ () C:\Users\Neal\AppData\HELP_DECRYPT.TXT
2015-05-08 12:45 - 2015-05-08 12:45 - 00000284 _____ () C:\Users\Neal\AppData\Roaming\HELP_DECRYPT.URL
2015-05-08 12:45 - 2015-05-08 12:45 - 00000284 _____ () C:\Users\Neal\AppData\HELP_DECRYPT.URL
2015-05-08 12:41 - 2015-05-08 12:41 - 00061952 _____ () C:\Users\Neal\AppData\Local\udsfurd.dll
2015-05-08 12:40 - 2015-05-08 12:40 - 01141248 _____ (Farbar) C:\Users\Neal\Downloads\FRST.exe
2015-05-08 12:40 - 2015-05-08 12:40 - 00051399 _____ (Akeo Consulting (
http://akeo.ie)) C:\Users\Neal\AppData\Roaming\KVBYU9X3r2RExfg-3Lgv9E1FtUo5Mxw-Qa6PRGFJ5I1m8Xq-eToIcy4CmFQps6j.exe
2015-05-08 11:48 - 2015-05-08 11:48 - 00000288 _____ () C:\Users\Neal\Desktop\test.txt
2015-05-08 11:45 - 2015-05-08 11:45 - 00000000 ____D () C:\HP
2015-05-07 15:19 - 2015-05-08 12:56 - 00000000 ____D () C:\FRST
2015-05-07 14:06 - 2015-05-07 14:06 - 00000000 ____D () C:\WINDOWS\pss
2015-05-07 11:46 - 2015-05-07 11:46 - 00000327 _____ () C:\Users\Neal\AppData\Roaming\jna71bgagagt1yabja
2015-05-05 14:10 - 2015-05-08 12:43 - 00000000 ___HD () C:\ProgramData\{F66CB4EE-546F-4D54-9332-216DE189AAB0}
2015-05-05 02:17 - 2015-05-07 15:53 - 00000000 ____D () C:\ProgramData\BlueStacks
2015-05-04 22:12 - 2015-05-04 22:12 - 00000000 ____D () C:\Users\Noelle\Documents\julius caesar
2015-04-17 09:45 - 2015-04-17 09:45 - 00000000 ____D () C:\WINDOWS\system32\appraiser
2015-04-14 19:50 - 2015-03-23 16:59 - 07476032 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2015-04-14 19:50 - 2015-03-23 16:59 - 01733952 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2015-04-14 19:50 - 2015-03-23 16:59 - 00360480 _____ (Microsoft Corporation) C:\WINDOWS\system32\sechost.dll
2015-04-14 19:50 - 2015-03-23 16:58 - 01498872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2015-04-14 19:50 - 2015-03-23 16:45 - 00257216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sechost.dll
2015-04-14 19:50 - 2015-03-19 23:12 - 00246272 _____ (Microsoft Corporation) C:\WINDOWS\system32\microsoft-windows-system-events.dll
2015-04-14 19:50 - 2015-03-19 23:10 - 00285184 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64.dll
2015-04-14 19:50 - 2015-03-19 23:10 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64cpu.dll
2015-04-14 19:50 - 2015-03-19 22:17 - 00411648 _____ (Microsoft Corporation) C:\WINDOWS\system32\tracerpt.exe
2015-04-14 19:50 - 2015-03-19 21:41 - 00369152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tracerpt.exe
2015-04-14 19:50 - 2015-03-19 21:40 - 00950784 _____ (Microsoft Corporation) C:\WINDOWS\system32\tdh.dll
2015-04-14 19:50 - 2015-03-19 21:16 - 00749568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tdh.dll
2015-04-14 19:50 - 2015-03-14 03:20 - 01385256 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll
2015-04-14 19:50 - 2015-03-14 03:13 - 01124352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll
2015-04-14 19:50 - 2015-03-12 23:32 - 24980480 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2015-04-14 19:50 - 2015-03-12 22:50 - 06025216 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2015-04-14 19:50 - 2015-03-12 22:42 - 19695616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2015-04-14 19:50 - 2015-03-12 22:00 - 14397440 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2015-04-14 19:50 - 2015-03-12 21:58 - 00259072 _____ (Microsoft Corporation) C:\WINDOWS\system32\pku2u.dll
2015-04-14 19:50 - 2015-03-12 21:49 - 04305408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2015-04-14 19:50 - 2015-03-12 21:37 - 00208896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\pku2u.dll
2015-04-14 19:50 - 2015-02-20 18:49 - 00780800 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsm.dll
2015-04-14 19:49 - 2015-03-22 17:45 - 00227328 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepdu.dll
2015-04-14 19:49 - 2015-03-22 17:09 - 01111552 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2015-04-14 19:49 - 2015-03-22 17:09 - 00957440 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2015-04-14 19:49 - 2015-03-22 17:09 - 00769024 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2015-04-14 19:49 - 2015-03-22 17:09 - 00726528 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2015-04-14 19:49 - 2015-03-22 17:09 - 00419328 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2015-04-14 19:49 - 2015-03-22 17:09 - 00030720 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2015-04-14 19:49 - 2015-03-14 03:54 - 00133256 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2015-04-14 19:49 - 2015-03-13 20:56 - 00066048 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups.dll
2015-04-14 19:49 - 2015-03-13 20:56 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups2.dll
2015-04-14 19:49 - 2015-03-13 20:51 - 00015360 _____ (Microsoft Corporation) C:\WINDOWS\system32\wu.upgrade.ps.dll
2015-04-14 19:49 - 2015-03-13 20:37 - 00267264 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinSetupUI.dll
2015-04-14 19:49 - 2015-03-13 20:14 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wups.dll
2015-04-14 19:49 - 2015-03-13 19:22 - 03678720 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2015-04-14 19:49 - 2015-03-13 19:12 - 00140288 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuwebv.dll
2015-04-14 19:49 - 2015-03-13 19:12 - 00035840 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapp.exe
2015-04-14 19:49 - 2015-03-13 19:09 - 00200192 _____ (Microsoft Corporation) C:\WINDOWS\system32\storewuauth.dll
2015-04-14 19:49 - 2015-03-13 19:08 - 00408064 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUSettingsProvider.dll
2015-04-14 19:49 - 2015-03-13 19:08 - 00095744 _____ (Microsoft Corporation) C:\WINDOWS\system32\wudriver.dll
2015-04-14 19:49 - 2015-03-13 19:06 - 02373632 _____ (Microsoft Corporation) C:\WINDOWS\system32\wucltux.dll
2015-04-14 19:49 - 2015-03-13 19:06 - 00891392 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2015-04-14 19:49 - 2015-03-13 19:02 - 00124928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuwebv.dll
2015-04-14 19:49 - 2015-03-13 19:02 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapp.exe
2015-04-14 19:49 - 2015-03-13 18:59 - 00721920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2015-04-14 19:49 - 2015-03-13 18:59 - 00081920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wudriver.dll
2015-04-14 19:49 - 2015-03-12 23:08 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2015-04-14 19:49 - 2015-03-12 23:07 - 02886144 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2015-04-14 19:49 - 2015-03-12 22:53 - 00816128 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2015-04-14 19:49 - 2015-03-12 22:28 - 00503296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2015-04-14 19:49 - 2015-03-12 22:26 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2015-04-14 19:49 - 2015-03-12 22:22 - 02278400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2015-04-14 19:49 - 2015-03-12 22:17 - 01032704 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll
2015-04-14 19:49 - 2015-03-12 22:16 - 00664064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2015-04-14 19:49 - 2015-03-12 22:08 - 00720384 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2015-04-14 19:49 - 2015-03-12 22:07 - 00801280 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2015-04-14 19:49 - 2015-03-12 21:50 - 00880128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcomm.dll
2015-04-14 19:49 - 2015-03-12 21:45 - 02358784 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2015-04-14 19:49 - 2015-03-12 21:44 - 00689152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2015-04-14 19:49 - 2015-03-12 21:34 - 12825600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2015-04-14 19:49 - 2015-03-12 21:33 - 01548288 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2015-04-14 19:49 - 2015-03-12 21:22 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2015-04-14 19:49 - 2015-03-12 21:20 - 01888256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2015-04-14 19:49 - 2015-03-12 21:16 - 01311232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2015-04-14 19:49 - 2015-03-12 21:14 - 00710144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2015-04-14 19:49 - 2015-03-04 05:25 - 00377152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\clfs.sys
2015-04-14 19:49 - 2015-03-03 22:04 - 00075264 _____ (Microsoft Corporation) C:\WINDOWS\system32\clfsw32.dll
2015-04-14 19:49 - 2015-03-03 21:19 - 00058880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\clfsw32.dll
2015-04-14 19:49 - 2015-02-24 03:32 - 00991552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\http.sys
2015-04-14 19:49 - 2014-12-02 18:09 - 00192000 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll
2015-04-08 12:05 - 2015-04-08 12:06 - 00000000 ___SD () C:\WINDOWS\system32\GWX
2015-04-08 12:05 - 2015-04-08 12:05 - 00000000 ___SD () C:\WINDOWS\SysWOW64\GWX
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-05-08 13:00 - 2013-08-22 10:36 - 00000000 ____D () C:\WINDOWS\system32\sru
2015-05-08 12:47 - 2014-09-11 16:28 - 00000000 ____D () C:\Users\Neal
2015-05-08 12:38 - 2014-09-11 17:08 - 00000000 __RDO () C:\Users\Neal\OneDrive
2015-05-08 12:37 - 2013-08-22 09:46 - 00422748 _____ () C:\WINDOWS\setupact.log
2015-05-08 12:37 - 2013-08-22 09:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2015-05-08 12:37 - 2013-08-22 08:25 - 00524288 ___SH () C:\WINDOWS\system32\config\BBI
2015-05-08 11:55 - 2014-08-18 12:57 - 00003934 _____ () C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{E6DB391A-67E2-49DF-ADDD-A578345A07FB}
2015-05-08 09:17 - 2014-09-11 16:13 - 01818681 _____ () C:\WINDOWS\WindowsUpdate.log
2015-05-08 08:50 - 2014-03-18 04:54 - 00055204 _____ () C:\WINDOWS\PFRO.log
2015-05-08 08:48 - 2014-09-11 16:28 - 00000000 ____D () C:\Users\Noelle
2015-05-08 08:48 - 2014-09-11 16:28 - 00000000 ____D () C:\Users\Administrator
2015-05-08 08:48 - 2013-08-22 08:36 - 00000000 __RHD () C:\Users\Default
2015-05-07 15:54 - 2014-12-22 20:58 - 00000000 ____D () C:\Users\Neal\Documents\CyberLink
2015-05-07 15:54 - 2014-11-05 14:25 - 00000000 ____D () C:\Users\Neal\Desktop\noelle
2015-05-07 15:54 - 2014-09-30 15:50 - 00000000 ____D () C:\Users\Neal\Desktop\Master bath
2015-05-07 15:54 - 2014-09-27 08:39 - 00000000 ____D () C:\Users\Neal\Desktop\RN Liscense
2015-05-07 15:54 - 2014-09-13 14:40 - 00000000 ____D () C:\Users\Neal\Desktop\Hurst Review
2015-05-07 15:54 - 2014-09-03 08:33 - 00000000 ____D () C:\Users\Neal\Desktop\STVE
2015-05-07 15:54 - 2014-08-18 01:43 - 00000000 ____D () C:\Users\Neal\Desktop\General Sciencev2-MP3
2015-05-07 15:54 - 2014-08-18 00:52 - 00000000 ____D () C:\Users\Neal\.javaws
2015-05-07 15:53 - 2014-09-11 19:09 - 00000000 __SHD () C:\Recovery
2015-05-07 15:53 - 2014-09-11 16:17 - 00000000 ____D () C:\ProgramData\AMD
2015-05-07 15:53 - 2014-09-11 16:16 - 00000000 ____D () C:\ProgramData\Package Cache
2015-05-07 15:53 - 2014-09-08 07:29 - 00000000 ____D () C:\ProgramData\lx_Cats
2015-05-07 15:53 - 2014-08-18 20:50 - 00000000 ____D () C:\ProgramData\QuickTime
2015-05-07 15:53 - 2014-08-18 13:14 - 00000000 ____D () C:\ProgramData\Mozilla
2015-05-07 15:53 - 2014-07-11 14:35 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\ATI
2015-05-07 15:53 - 2014-07-11 14:35 - 00000000 ____D () C:\Users\Administrator\AppData\Local\ATI
2015-05-07 15:53 - 2014-07-11 14:35 - 00000000 ____D () C:\Users\Administrator\AppData\Local\AMD
2015-05-07 15:53 - 2014-07-11 14:35 - 00000000 ____D () C:\ProgramData\ATI
2015-05-07 15:53 - 2014-07-11 14:24 - 00000000 ____D () C:\ProgramData\Norton
2015-05-07 15:53 - 2014-07-11 14:16 - 00000000 ____D () C:\ProgramData\CyberLink
2015-05-07 15:53 - 2014-07-11 14:00 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Downloaded Installations
2015-05-07 15:53 - 2014-07-11 13:56 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Synaptics
2015-05-07 15:53 - 2014-07-11 13:56 - 00000000 ____D () C:\ProgramData\Synaptics
2015-05-07 15:53 - 2014-07-11 13:53 - 00000000 ____D () C:\ProgramData\Qualcomm Atheros
2015-05-07 15:53 - 2014-07-11 13:52 - 00000000 ____D () C:\ProgramData\Apple
2015-05-07 15:53 - 2012-10-29 21:18 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\FFSJ
2015-05-07 15:53 - 2012-10-29 21:16 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Hewlett-Packard
2015-05-07 15:53 - 2012-10-29 21:16 - 00000000 ____D () C:\ProgramData\WildTangent
2015-05-07 15:53 - 2012-10-29 21:10 - 00000000 ____D () C:\ProgramData\Hewlett-Packard
2015-05-07 15:53 - 2012-10-29 21:06 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Windows Live
2015-05-07 15:53 - 2012-10-29 21:06 - 00000000 ____D () C:\ProgramData\Microsoft SkyDrive
2015-05-07 15:53 - 2012-10-29 20:58 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\hpqLog
2015-05-07 15:53 - 2012-10-29 20:58 - 00000000 ____D () C:\ProgramData\install_clap
2015-05-07 15:53 - 2012-10-29 20:55 - 00000000 ___HD () C:\Users\Administrator\Documents\hp.system.package.metadata
2015-05-07 15:53 - 2012-08-03 19:02 - 00000000 __RHD () C:\SYSTEM.SAV
2015-05-07 15:53 - 2012-08-03 19:02 - 00000000 ____D () C:\SWSetup
2015-05-07 15:53 - 2012-08-03 17:29 - 00000000 ____D () C:\ProgramData\PRICache
2015-05-07 15:53 - 2012-08-03 17:28 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Adobe
2015-05-07 15:52 - 2014-09-11 18:59 - 00000000 ____D () C:\inetpub
2015-05-07 15:52 - 2014-09-11 16:12 - 00000000 ____D () C:\AMD
2015-05-07 15:52 - 2014-08-18 14:51 - 00000000 ___HD () C:\$SysReset
2015-05-07 13:54 - 2012-10-29 21:07 - 00000000 ___RD () C:\Users\Administrator\SkyDrive
2015-05-07 13:25 - 2014-09-08 19:54 - 00007332 _____ () C:\Users\Neal\Desktop\double barn doors.jpg.ezz
2015-05-07 13:25 - 2014-09-08 19:47 - 00009396 _____ () C:\Users\Neal\Desktop\tile size.jpg.ezz
2015-05-07 13:25 - 2014-09-08 19:45 - 00005972 _____ () C:\Users\Neal\Desktop\barn door.jpg.ezz
2015-05-07 13:25 - 2014-09-08 19:38 - 00006772 _____ () C:\Users\Neal\Desktop\imagesCAVYFP72.jpg.ezz
2015-05-07 13:25 - 2014-09-08 19:35 - 00009460 _____ () C:\Users\Neal\Desktop\imagesCA7CH076.jpg.ezz
2015-05-07 13:25 - 2014-09-08 19:30 - 00007556 _____ () C:\Users\Neal\Desktop\imagesCASKJVS5.jpg.ezz
2015-05-07 13:25 - 2014-09-08 19:22 - 00008660 _____ () C:\Users\Neal\Desktop\stone shower.jpg.ezz
2015-05-07 13:25 - 2014-09-08 19:19 - 00072372 _____ () C:\Users\Neal\Desktop\Nice-Rustic-Wooden-Look-in-Western-Style-Bathroom-Interior.jpg.ezz
2015-05-07 13:25 - 2014-09-08 19:14 - 00021940 _____ () C:\Users\Neal\Desktop\stoneshowers3.jpg.ezz
2015-05-07 13:25 - 2014-09-08 19:13 - 00126212 _____ () C:\Users\Neal\Desktop\shower-designs_stone.jpg.ezz
2015-05-07 13:25 - 2014-09-08 19:11 - 00145892 _____ () C:\Users\Neal\Desktop\bathroom-natural-cream-small-bathroom-renovation-idea-with-cream-stone-wall-colorful-border-and-shower-nice-small-bathroom-renovation-ideas-972x650.jpg.ezz
2015-05-07 13:25 - 2014-09-08 19:06 - 00042676 _____ () C:\Users\Neal\Desktop\thumb4_wlshower.jpg.ezz
2015-05-07 13:25 - 2014-08-17 23:39 - 10782340 _____ () C:\Users\Neal\Documents\9781616251185_ApologiaExploringCreationWithG.pdf.ezz
2015-05-07 13:25 - 2014-08-17 23:35 - 24867156 _____ () C:\Users\Neal\Desktop\9781616251345_ApologiaExploringCreationWithB.pdf.ezz
2015-05-07 13:25 - 2014-08-17 21:22 - 10782340 _____ () C:\Users\Neal\Desktop\9781616251185_ApologiaExploringCreationWithG.pdf.ezz
2015-05-07 13:25 - 2014-07-11 16:24 - 01440996 _____ () C:\Users\Neal\Desktop\CRCS Handbook.pdf.ezz
2015-05-07 13:13 - 2015-01-09 02:01 - 00003598 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-4105420370-3369507210-3028615837-1004
2015-05-07 12:47 - 2015-01-09 01:59 - 00000000 ___RD () C:\Users\Noelle\OneDrive
2015-05-07 01:07 - 2015-01-09 01:55 - 00003942 _____ () C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{C556DA80-233A-4939-81B7-D4F612CB4826}
2015-05-05 14:31 - 2013-08-22 10:36 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-05-05 14:31 - 2013-08-22 10:36 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-05-05 14:31 - 2013-08-22 10:36 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2015-05-05 14:31 - 2013-08-22 10:36 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-05-05 14:31 - 2013-08-22 10:36 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-05-05 14:31 - 2013-08-22 10:36 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2015-05-05 14:31 - 2013-08-22 10:36 - 00000000 ____D () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-05-05 14:31 - 2013-08-22 10:36 - 00000000 ____D () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-05-05 14:31 - 2012-10-29 20:58 - 00000000 ____D () C:\ProgramData\Temp
2015-05-05 14:30 - 2014-08-18 12:58 - 00000164 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.351.64.bc.ezz
2015-05-05 14:22 - 2014-09-13 14:24 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2015-05-05 14:22 - 2014-09-11 16:17 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center
2015-05-05 14:22 - 2014-08-18 20:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
2015-05-05 14:22 - 2014-08-18 20:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java Web Start
2015-05-05 14:22 - 2014-08-18 20:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\The Rosetta Stone
2015-05-05 14:22 - 2014-08-18 13:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TT Algebra 1
2015-05-05 14:22 - 2014-08-18 12:56 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Shopping and Services
2015-05-05 14:22 - 2014-07-11 14:08 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Communication and Chat
2015-05-05 14:22 - 2014-07-11 14:00 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Productivity and Tools
2015-05-05 14:22 - 2014-03-18 04:45 - 00000000 __RHD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tablet PC
2015-05-05 14:22 - 2013-08-22 10:36 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools
2015-05-05 14:22 - 2013-08-22 10:36 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2015-05-05 14:22 - 2013-08-22 10:36 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility
2015-05-05 14:22 - 2013-08-22 10:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-05-05 14:22 - 2012-10-29 21:17 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2015-05-05 14:22 - 2012-10-29 21:13 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP Help and Support
2015-05-05 14:22 - 2012-10-29 21:02 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Security and Protection
2015-05-05 14:21 - 2014-09-11 16:28 - 00000000 ___RD () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-05-05 14:21 - 2014-09-11 16:28 - 00000000 ___RD () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-05-05 14:21 - 2014-09-11 16:28 - 00000000 ___RD () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2015-05-05 14:21 - 2014-09-11 16:28 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-05-05 14:21 - 2012-08-03 17:28 - 00000000 ____D () C:\Users\Administrator\AppData\Local\Packages
2015-05-05 14:18 - 2014-03-18 04:45 - 00000000 ____D () C:\Program Files\Windows Journal
2015-05-05 14:18 - 2013-08-22 10:36 - 00000000 ____D () C:\Program Files\WindowsPowerShell
2015-05-05 14:18 - 2013-08-22 10:36 - 00000000 ____D () C:\Program Files\Windows Portable Devices
2015-05-05 14:18 - 2013-08-22 10:36 - 00000000 ____D () C:\Program Files\Windows Photo Viewer
2015-05-05 14:18 - 2013-08-22 10:36 - 00000000 ____D () C:\Program Files\Windows Multimedia Platform
2015-05-05 14:18 - 2013-08-22 10:36 - 00000000 ____D () C:\Program Files\Windows Defender
2015-05-05 14:17 - 2014-09-11 16:12 - 00000000 ____D () C:\Program Files\Common Files\ATI Technologies
2015-05-05 14:17 - 2014-07-11 13:52 - 00000000 ____D () C:\Program Files\Bonjour
2015-05-05 14:17 - 2013-08-22 10:36 - 00000000 ____D () C:\Program Files\Common Files\Services
2015-05-05 14:17 - 2013-08-22 10:36 - 00000000 ____D () C:\Program Files\Common Files\microsoft shared
2015-05-05 14:17 - 2012-09-18 21:56 - 00000000 ____D () C:\Program Files\Hewlett-Packard
2015-05-05 02:16 - 2012-10-29 21:16 - 00000000 ____D () C:\Program Files (x86)\WildTangent Games
2015-05-04 15:46 - 2014-08-15 09:06 - 00000000 ____D () C:\Users\Public\Documents\TT Algebra 1
2015-05-03 15:12 - 2015-03-16 12:27 - 00000000 ____D () C:\Users\Noelle\AppData\Roaming\Mozilla
2015-05-03 15:12 - 2015-01-21 13:05 - 00000000 ____D () C:\Users\Noelle\Documents\CyberLink
2015-05-03 15:12 - 2015-01-09 01:57 - 00000000 ____D () C:\Users\Noelle\AppData\Local\AMD
2015-05-03 15:12 - 2015-01-09 01:55 - 00000000 ____D () C:\Users\Noelle\AppData\Roaming\Adobe
2015-05-03 15:10 - 2014-08-18 13:15 - 00000000 ____D () C:\Users\Neal\AppData\Roaming\Mozilla
2015-05-03 15:10 - 2014-08-18 13:00 - 00000000 ____D () C:\Users\Neal\AppData\Local\AMD
2015-05-03 15:10 - 2014-08-18 12:58 - 00000000 ____D () C:\Users\Neal\AppData\Roaming\Hewlett-Packard
2015-05-03 15:10 - 2014-08-18 12:56 - 00000000 ____D () C:\Users\Neal\AppData\Roaming\Adobe
2015-05-03 15:10 - 2014-08-18 12:53 - 00000000 ____D () C:\Users\Neal\AppData\Local\Power2Go8
2015-04-20 13:56 - 2013-08-22 10:36 - 00000000 ____D () C:\WINDOWS\rescache
2015-04-18 20:18 - 2013-08-22 10:36 - 00000000 ____D () C:\WINDOWS\AppCompat
2015-04-17 09:52 - 2014-03-18 05:03 - 00956480 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2015-04-17 09:45 - 2015-03-29 21:04 - 00000000 ___SD () C:\WINDOWS\system32\CompatTel
2015-04-14 20:35 - 2014-08-23 00:19 - 00000000 ____D () C:\WINDOWS\system32\MRT
2015-04-14 20:33 - 2014-08-23 00:19 - 128913832 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2015-04-14 20:33 - 2012-07-26 02:59 - 00000000 ____D () C:\WINDOWS\CbsTemp
==================== Files in the root of some directories =======
2015-05-08 12:45 - 2015-05-08 12:45 - 0008602 _____ () C:\Users\Neal\AppData\Roaming\HELP_DECRYPT.HTML
2015-05-08 12:45 - 2015-05-08 12:45 - 0045579 _____ () C:\Users\Neal\AppData\Roaming\HELP_DECRYPT.PNG
2015-05-08 12:45 - 2015-05-08 12:45 - 0004244 _____ () C:\Users\Neal\AppData\Roaming\HELP_DECRYPT.TXT
2015-05-08 12:45 - 2015-05-08 12:45 - 0000284 _____ () C:\Users\Neal\AppData\Roaming\HELP_DECRYPT.URL
2015-05-07 11:46 - 2015-05-07 11:46 - 0000327 _____ () C:\Users\Neal\AppData\Roaming\jna71bgagagt1yabja
2015-05-08 12:40 - 2015-05-08 12:40 - 0051399 _____ (Akeo Consulting (
http://akeo.ie)) C:\Users\Neal\AppData\Roaming\KVBYU9X3r2RExfg-3Lgv9E1FtUo5Mxw-Qa6PRGFJ5I1m8Xq-eToIcy4CmFQps6j.exe
2015-05-07 11:46 - 2015-05-07 11:46 - 0079648 _____ () C:\Users\Neal\AppData\Roaming\R.E.M. - Reveal - 07 - Beat A Drum.mp3
2015-05-08 12:41 - 2015-05-08 12:41 - 0061952 _____ () C:\Users\Neal\AppData\Local\udsfurd.dll
2014-09-15 20:51 - 2015-02-04 14:46 - 0000342 _____ () C:\ProgramData\lxee.log
2014-09-25 19:06 - 2015-02-04 15:05 - 0009990 _____ () C:\ProgramData\lxeeJSW.log
2014-09-08 07:27 - 2015-02-04 14:46 - 0000392 _____ () C:\ProgramData\lxeescan.log
2014-08-18 12:58 - 2015-05-05 14:30 - 0000164 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.351.64.bc.ezz
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-05-03 15:35
==================== End Of Log ============================