Thomas Parks
Posts: 7 +0
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 29-05-2015
Ran by Thomas (administrator) on THOMAS-PC on 30-05-2015 18:24:15
Running from C:\Users\Thomas\Downloads
Loaded Profiles: Thomas (Available Profiles: Thomas)
Platform: Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: English (United States)
Internet Explorer Version 9 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
() C:\Windows\System32\WLTRYSVC.EXE
(Dell Inc.) C:\Windows\System32\BCMWLTRY.EXE
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\Apoint.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Dell Inc.) C:\Windows\System32\WLTRAY.EXE
(CyberLink Corp.) C:\Program Files\Dell\MediaDirect\PCMService.exe
(IDT, Inc.) C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe
(Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(SupportSoft, Inc.) C:\Program Files\Dell Support Center\bin\sprtcmd.exe
(Spotify Ltd) C:\Users\Thomas\AppData\Roaming\Spotify\SpotifyWebHelper.exe
(Avanquest Software ) C:\Program Files\Digital Line Detect\DLG.exe
(Andrea Electronics Corporation) C:\Windows\System32\AEstSrv.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
(Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe
(Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe
(SupportSoft, Inc.) C:\Program Files\Dell Support Center\bin\sprtsvc.exe
(IDT, Inc.) C:\Windows\System32\stacsv.exe
(Conexant Systems, Inc.) C:\Windows\System32\drivers\XAudio.exe
(Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\ApMsgFwd.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\ApntEx.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\hidfind.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe
(Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_17_0_0_188.exe
(Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_17_0_0_188.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [Windows Defender] => C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-20] (Microsoft Corporation)
HKLM\...\Run: [ECenter] => C:\Dell\E-Center\EULALauncher.exe [17920 2008-02-28] ( )
HKLM\...\Run: [Apoint] => C:\Program Files\DellTPad\Apoint.exe [167936 2008-05-04] (Alps Electric Co., Ltd.)
HKLM\...\Run: [IAAnotif] => C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe [174872 2007-03-21] (Intel Corporation)
HKLM\...\Run: [Broadcom Wireless Manager UI] => C:\Windows\system32\WLTRAY.exe [3444736 2008-05-18] (Dell Inc.)
HKLM\...\Run: [dscactivate] => C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe [16384 2008-03-11] ( )
HKLM\...\Run: [PCMService] => C:\Program Files\Dell\MediaDirect\PCMService.exe [184320 2007-12-21] (CyberLink Corp.)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2014-12-19] (Adobe Systems Incorporated)
HKLM\...\Run: [SigmatelSysTrayApp] => C:\Program Files\SigmaTel\C-Major Audio\WDM\sttray.exe [405504 2007-11-12] (IDT, Inc.)
HKLM\...\Run: [SDTray] => C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe [4101576 2014-06-24] (Safer-Networking Ltd.)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [981688 2015-04-30] (Microsoft Corporation)
Winlogon\Notify\GoToAssist: C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll [2008-08-09] (Citrix Online, a division of Citrix Systems, Inc.)
Winlogon\Notify\SDWinLogon: SDWinLogon.dll [X]
HKU\S-1-5-21-1581059466-491620939-3557866383-1000\...\Run: [DellSupportCenter] => C:\Program Files\Dell Support Center\bin\sprtcmd.exe [202544 2008-03-11] (SupportSoft, Inc.)
HKU\S-1-5-21-1581059466-491620939-3557866383-1000\...\Run: [Spotify Web Helper] => C:\Users\Thomas\AppData\Roaming\Spotify\SpotifyWebHelper.exe [2020920 2015-04-24] (Spotify Ltd)
AppInit_DLLs: c:\progra~1\google\google~2\goec62~1.dll => c:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll [111616 2008-08-09] (Google)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Digital Line Detect.lnk [2008-08-09]
ShortcutTarget: Digital Line Detect.lnk -> C:\Program Files\Digital Line Detect\DLG.exe (Avanquest Software )
BootExecute: autocheck autochk * sdnclean.exe
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-1581059466-491620939-3557866383-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
HKU\S-1-5-21-1581059466-491620939-3557866383-1000\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-1581059466-491620939-3557866383-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=2080810
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
Toolbar: HKLM - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll [2007-11-28] (Microsoft Corporation)
Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704 2011-08-30] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
FireFox:
========
FF ProfilePath: C:\Users\Thomas\AppData\Roaming\Mozilla\Firefox\Profiles\rc0cdch0.default
FF DefaultSearchEngine.US: Google
FF Homepage: https://www.gmail.com/intl/en/mail/help/about.html
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_17_0_0_188.dll [2015-05-21] ()
FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll [2014-10-30] ()
FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2015-04-29] (Adobe Systems Inc.)
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2015-03-29]
Chrome:
=======
CHR dev: Chrome dev build detected! <======= ATTENTION
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 dd25e48a; c:\Program Files\PatternGenerators\PatternGenerators.dll [1765888 2015-05-20] () [File not signed]
S3 GoogleDesktopManager-010708-104812; C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [29744 2008-08-09] (Google)
S3 GoToAssist; C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe [16680 2008-08-09] (Citrix Online, a division of Citrix Systems, Inc.)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [22216 2015-04-30] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [284504 2015-04-30] (Microsoft Corporation)
R2 SDScannerService; C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe [1738168 2014-06-24] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe [2088408 2014-06-27] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2014-04-25] (Safer-Networking Ltd.)
R2 sprtsvc_dellsupportcenter; C:\Program Files\Dell Support Center\bin\sprtsvc.exe [202544 2008-03-11] (SupportSoft, Inc.)
S2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [272952 2008-01-20] (Microsoft Corporation)
R2 wltrysvc; C:\Windows\System32\bcmwltry.exe [2506752 2008-05-18] (Dell Inc.) [File not signed]
S2 233d520f; "C:\Windows\system32\rundll32.exe" "c:\Program Files\SustainerPlus\SustainerPlus.dll",serv
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [245096 2015-03-04] (Microsoft Corporation)
S3 BCM42RLY; system32\drivers\BCM42RLY.sys [X]
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
S3 SymIM; system32\DRIVERS\SymIM.sys [X]
S3 SymIMMP; system32\DRIVERS\SymIM.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-05-30 18:24 - 2015-05-30 18:24 - 00011453 _____ () C:\Users\Thomas\Downloads\FRST.txt
2015-05-30 18:23 - 2015-05-30 18:24 - 00000000 ____D () C:\FRST
2015-05-30 18:22 - 2015-05-30 18:22 - 01147392 _____ (Farbar) C:\Users\Thomas\Downloads\FRST.exe
2015-05-29 21:31 - 2015-05-29 21:31 - 00000000 _____ () C:\Users\Thomas\AppData\Local\Temp.dat
2015-05-28 07:29 - 2015-05-28 07:29 - 00001969 _____ () C:\Users\Public\Desktop\Adobe Digital Editions 4.0.lnk
2015-05-23 12:13 - 2015-05-23 12:13 - 00001828 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
2015-05-23 12:13 - 2015-05-23 12:13 - 00000000 ____D () C:\Program Files\Microsoft Security Client
2015-05-20 22:16 - 2015-05-20 22:16 - 00000000 ____D () C:\Program Files\PatternGenerators
2015-05-20 21:21 - 2015-05-20 21:21 - 00000000 ____D () C:\Program Files\uCoz Safe authorization
2015-05-20 21:17 - 2015-05-20 21:32 - 00000000 ____D () C:\Program Files\SoftwarePlus
2015-05-20 21:16 - 2015-05-20 22:15 - 00000000 ____D () C:\Program Files\PCCpnApp
2015-05-20 21:14 - 2015-05-29 21:14 - 00000348 _____ () C:\Windows\Tasks\Bidaily Synchronize Task[pr].job
2015-05-20 16:35 - 2015-05-20 16:35 - 00000084 _____ () C:\Users\Thomas\Desktop\Volt Pace Mary Terry Friday New Hire Paper work.txt
2015-05-17 19:03 - 2015-05-17 19:06 - 00000000 ____D () C:\Users\Thomas\Documents\Anki
2015-05-17 19:02 - 2015-05-17 19:03 - 00000762 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Anki.lnk
2015-05-17 19:00 - 2015-05-17 19:01 - 23237295 _____ () C:\Users\Thomas\Downloads\anki-2.0.32.exe
2015-05-16 12:57 - 2015-05-16 12:57 - 00000183 _____ () C:\Windows\wininit.ini
2015-05-16 08:51 - 2015-04-30 09:03 - 00279040 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-05-16 08:44 - 2015-04-19 14:24 - 01029120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll
2015-05-16 08:44 - 2015-04-19 14:24 - 00219648 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll
2015-05-16 08:44 - 2015-04-19 14:24 - 00189952 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll
2015-05-16 08:44 - 2015-04-19 14:24 - 00160768 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll
2015-05-16 08:44 - 2015-04-19 13:19 - 01172480 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2015-05-16 08:44 - 2015-04-19 13:18 - 00486400 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll
2015-05-16 08:44 - 2015-04-19 13:13 - 00682496 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2015-05-16 08:44 - 2015-04-19 13:12 - 01072640 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2015-05-16 08:44 - 2015-04-19 13:12 - 00801792 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2015-05-16 08:44 - 2015-04-18 21:59 - 02065408 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-05-16 08:43 - 2015-04-30 06:14 - 00102608 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-05-16 08:29 - 2015-04-10 16:22 - 00279552 _____ (Microsoft Corporation) C:\Windows\system32\services.exe
2015-05-15 11:16 - 2015-05-15 11:16 - 00000162 _____ () C:\Users\Thomas\Documents\8.txt
2015-05-15 09:55 - 2015-05-30 15:46 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2015-05-15 08:44 - 2015-05-27 02:08 - 00000000 ____D () C:\Users\Thomas\AppData\Roaming\vlc
2015-05-15 08:10 - 2015-04-10 08:25 - 01810944 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-05-15 08:10 - 2015-04-10 08:21 - 01139200 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-05-15 08:10 - 2015-04-10 08:20 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-05-15 08:10 - 2015-04-10 08:20 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-05-15 08:10 - 2015-04-10 08:19 - 01804288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-05-15 08:10 - 2015-04-10 08:19 - 00718336 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-05-15 08:10 - 2015-04-10 08:19 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-05-15 08:10 - 2015-04-10 08:19 - 00421888 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-05-15 08:10 - 2015-04-10 08:19 - 00353792 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-05-15 08:10 - 2015-04-10 08:19 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2015-05-15 08:10 - 2015-04-10 08:19 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-05-15 08:10 - 2015-04-10 08:19 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-05-15 08:10 - 2015-04-10 08:18 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-05-15 08:10 - 2015-04-10 08:18 - 00223232 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-05-15 08:10 - 2015-04-10 08:18 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-05-15 08:10 - 2015-04-10 08:18 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-05-15 08:10 - 2015-04-10 08:18 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2015-05-15 08:10 - 2015-04-10 08:18 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2015-05-15 08:10 - 2015-04-10 08:18 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2015-05-15 08:09 - 2015-04-10 08:30 - 12379136 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-05-15 08:09 - 2015-04-10 08:25 - 00367616 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-05-15 08:09 - 2015-04-10 08:24 - 09750528 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-05-12 22:31 - 2015-05-12 22:31 - 00000000 ____D () C:\Windows\pss
2015-05-10 22:55 - 2015-05-30 18:16 - 00000644 _____ () C:\Windows\Tasks\Check for updates (Spybot - Search & Destroy).job
2015-05-10 22:55 - 2015-05-27 00:39 - 00000616 _____ () C:\Windows\Tasks\Refresh immunization (Spybot - Search & Destroy).job
2015-05-10 22:55 - 2015-05-12 09:57 - 00000446 _____ () C:\Windows\Tasks\Scan the system (Spybot - Search & Destroy).job
2015-05-10 22:54 - 2015-05-27 00:39 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2015-05-10 22:54 - 2015-05-10 22:59 - 00000000 ____D () C:\Program Files\Spybot - Search & Destroy 2
2015-05-10 22:54 - 2015-05-10 22:54 - 00001972 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk
2015-05-10 22:54 - 2015-05-10 22:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
2015-05-10 22:54 - 2013-09-20 10:49 - 00018968 _____ (Safer Networking Limited) C:\Windows\system32\sdnclean.exe
2015-05-10 22:52 - 2015-05-10 22:53 - 46525608 _____ (Safer-Networking Ltd. ) C:\Users\Thomas\Downloads\spybot-2-4.exe
2015-05-10 22:40 - 2015-05-10 22:40 - 02204160 _____ () C:\Users\Thomas\Downloads\adwcleaner_4.203.exe
2015-05-03 14:00 - 2015-05-03 14:00 - 00889416 _____ (Microsoft Corporation) C:\Users\Thomas\Downloads\dotNetFx40_Full_setup(1).exe
2015-05-01 14:10 - 2015-05-01 14:10 - 00027663 _____ () C:\Users\Thomas\Desktop\Thomas John Parks Resume.odt
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-05-30 18:22 - 2006-11-02 05:47 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2015-05-30 18:22 - 2006-11-02 05:47 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2015-05-30 18:22 - 2006-11-02 03:33 - 00756446 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-05-30 18:20 - 2015-04-22 22:00 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-05-30 18:19 - 2008-08-09 12:55 - 01795567 _____ () C:\Windows\WindowsUpdate.log
2015-05-30 18:14 - 2006-11-02 06:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-05-30 16:01 - 2006-11-02 06:01 - 00032556 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2015-05-30 15:46 - 2015-04-22 20:02 - 00000000 ____D () C:\AdwCleaner
2015-05-28 08:04 - 2015-04-19 08:00 - 00000000 ____D () C:\Users\Thomas\Desktop\Database Notes and Education
2015-05-28 07:29 - 2015-04-21 17:43 - 00001981 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Digital Editions 4.0.lnk
2015-05-28 07:16 - 2015-04-21 17:43 - 00000000 ____D () C:\Users\Thomas\Documents\My Digital Editions
2015-05-27 02:16 - 2015-03-30 21:22 - 00000000 ____D () C:\Users\Thomas\AppData\Roaming\Azureus
2015-05-27 02:06 - 2015-03-30 08:31 - 00047616 _____ () C:\Users\Thomas\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-05-27 01:34 - 2015-03-30 07:39 - 00000000 ____D () C:\Users\Thomas\AppData\Roaming\PeaZip
2015-05-25 11:09 - 2015-03-30 21:28 - 00005972 _____ () C:\Users\Thomas\AppData\Local\d3d9caps.dat
2015-05-23 12:13 - 2015-03-30 21:25 - 00001945 _____ () C:\Windows\epplauncher.mif
2015-05-21 19:41 - 2015-03-30 06:03 - 00000000 ____D () C:\Users\Thomas\AppData\Local\Adobe
2015-05-21 19:40 - 2015-04-22 22:00 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-05-21 19:40 - 2015-04-22 22:00 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-05-21 15:28 - 2008-01-20 19:47 - 00088992 _____ () C:\Windows\PFRO.log
2015-05-21 08:57 - 2015-04-02 16:06 - 00000000 ____D () C:\Users\Thomas\AppData\Local\Spotify
2015-05-21 08:54 - 2015-04-02 16:06 - 00000000 ____D () C:\Users\Thomas\AppData\Roaming\Spotify
2015-05-17 17:16 - 2006-11-02 05:47 - 00298672 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-05-17 15:21 - 2015-03-30 06:42 - 00000000 ____D () C:\Program Files\DiskInternals
2015-05-16 10:42 - 2006-11-02 04:18 - 00000000 ____D () C:\Windows\Microsoft.NET
2015-05-16 09:17 - 2006-11-02 05:37 - 00000000 ____D () C:\Windows\system32\XPSViewer
2015-05-16 09:17 - 2006-11-02 05:37 - 00000000 ____D () C:\Program Files\Windows Journal
2015-05-16 08:42 - 2015-03-29 10:51 - 00000000 ____D () C:\Windows\system32\MRT
2015-05-16 08:34 - 2006-11-02 03:24 - 137310008 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2015-05-15 22:32 - 2015-03-30 18:38 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2015-05-12 10:01 - 2015-03-30 20:47 - 00002425 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk
2015-05-12 10:01 - 2015-03-30 20:46 - 00000000 ____D () C:\Program Files\Common Files\Adobe
==================== Files in the root of some directories =======
2015-03-30 21:28 - 2015-05-25 11:09 - 0005972 _____ () C:\Users\Thomas\AppData\Local\d3d9caps.dat
2015-03-30 08:31 - 2015-05-27 02:06 - 0047616 _____ () C:\Users\Thomas\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-03-30 06:24 - 2015-03-30 06:24 - 0004662 _____ () C:\Users\Thomas\AppData\Local\Temp-log.txt
2015-05-29 21:31 - 2015-05-29 21:31 - 0000000 _____ () C:\Users\Thomas\AppData\Local\Temp.dat
Some files in TEMP:
====================
C:\Users\Thomas\AppData\Local\Temp\ade.exe
C:\Users\Thomas\AppData\Local\Temp\i4jdel0.exe
C:\Users\Thomas\AppData\Local\Temp\Quarantine.exe
C:\Users\Thomas\AppData\Local\Temp\sqlite3.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-05-30 18:21
==================== End of log ============================
Ran by Thomas (administrator) on THOMAS-PC on 30-05-2015 18:24:15
Running from C:\Users\Thomas\Downloads
Loaded Profiles: Thomas (Available Profiles: Thomas)
Platform: Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: English (United States)
Internet Explorer Version 9 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
() C:\Windows\System32\WLTRYSVC.EXE
(Dell Inc.) C:\Windows\System32\BCMWLTRY.EXE
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\Apoint.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Dell Inc.) C:\Windows\System32\WLTRAY.EXE
(CyberLink Corp.) C:\Program Files\Dell\MediaDirect\PCMService.exe
(IDT, Inc.) C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe
(Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(SupportSoft, Inc.) C:\Program Files\Dell Support Center\bin\sprtcmd.exe
(Spotify Ltd) C:\Users\Thomas\AppData\Roaming\Spotify\SpotifyWebHelper.exe
(Avanquest Software ) C:\Program Files\Digital Line Detect\DLG.exe
(Andrea Electronics Corporation) C:\Windows\System32\AEstSrv.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
(Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe
(Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe
(SupportSoft, Inc.) C:\Program Files\Dell Support Center\bin\sprtsvc.exe
(IDT, Inc.) C:\Windows\System32\stacsv.exe
(Conexant Systems, Inc.) C:\Windows\System32\drivers\XAudio.exe
(Safer-Networking Ltd.) C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\ApMsgFwd.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\ApntEx.exe
(Alps Electric Co., Ltd.) C:\Program Files\DellTPad\hidfind.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe
(Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_17_0_0_188.exe
(Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_17_0_0_188.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [Windows Defender] => C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-20] (Microsoft Corporation)
HKLM\...\Run: [ECenter] => C:\Dell\E-Center\EULALauncher.exe [17920 2008-02-28] ( )
HKLM\...\Run: [Apoint] => C:\Program Files\DellTPad\Apoint.exe [167936 2008-05-04] (Alps Electric Co., Ltd.)
HKLM\...\Run: [IAAnotif] => C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe [174872 2007-03-21] (Intel Corporation)
HKLM\...\Run: [Broadcom Wireless Manager UI] => C:\Windows\system32\WLTRAY.exe [3444736 2008-05-18] (Dell Inc.)
HKLM\...\Run: [dscactivate] => C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe [16384 2008-03-11] ( )
HKLM\...\Run: [PCMService] => C:\Program Files\Dell\MediaDirect\PCMService.exe [184320 2007-12-21] (CyberLink Corp.)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1022152 2014-12-19] (Adobe Systems Incorporated)
HKLM\...\Run: [SigmatelSysTrayApp] => C:\Program Files\SigmaTel\C-Major Audio\WDM\sttray.exe [405504 2007-11-12] (IDT, Inc.)
HKLM\...\Run: [SDTray] => C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe [4101576 2014-06-24] (Safer-Networking Ltd.)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [981688 2015-04-30] (Microsoft Corporation)
Winlogon\Notify\GoToAssist: C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll [2008-08-09] (Citrix Online, a division of Citrix Systems, Inc.)
Winlogon\Notify\SDWinLogon: SDWinLogon.dll [X]
HKU\S-1-5-21-1581059466-491620939-3557866383-1000\...\Run: [DellSupportCenter] => C:\Program Files\Dell Support Center\bin\sprtcmd.exe [202544 2008-03-11] (SupportSoft, Inc.)
HKU\S-1-5-21-1581059466-491620939-3557866383-1000\...\Run: [Spotify Web Helper] => C:\Users\Thomas\AppData\Roaming\Spotify\SpotifyWebHelper.exe [2020920 2015-04-24] (Spotify Ltd)
AppInit_DLLs: c:\progra~1\google\google~2\goec62~1.dll => c:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll [111616 2008-08-09] (Google)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Digital Line Detect.lnk [2008-08-09]
ShortcutTarget: Digital Line Detect.lnk -> C:\Program Files\Digital Line Detect\DLG.exe (Avanquest Software )
BootExecute: autocheck autochk * sdnclean.exe
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-1581059466-491620939-3557866383-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
HKU\S-1-5-21-1581059466-491620939-3557866383-1000\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-1581059466-491620939-3557866383-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=2080810
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
Toolbar: HKLM - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_05-windows-i586.cab
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll [2007-11-28] (Microsoft Corporation)
Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704 2011-08-30] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
FireFox:
========
FF ProfilePath: C:\Users\Thomas\AppData\Roaming\Mozilla\Firefox\Profiles\rc0cdch0.default
FF DefaultSearchEngine.US: Google
FF Homepage: https://www.gmail.com/intl/en/mail/help/about.html
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_17_0_0_188.dll [2015-05-21] ()
FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll [2014-10-30] ()
FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2015-04-29] (Adobe Systems Inc.)
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2015-03-29]
Chrome:
=======
CHR dev: Chrome dev build detected! <======= ATTENTION
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 dd25e48a; c:\Program Files\PatternGenerators\PatternGenerators.dll [1765888 2015-05-20] () [File not signed]
S3 GoogleDesktopManager-010708-104812; C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [29744 2008-08-09] (Google)
S3 GoToAssist; C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe [16680 2008-08-09] (Citrix Online, a division of Citrix Systems, Inc.)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [22216 2015-04-30] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [284504 2015-04-30] (Microsoft Corporation)
R2 SDScannerService; C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe [1738168 2014-06-24] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe [2088408 2014-06-27] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2014-04-25] (Safer-Networking Ltd.)
R2 sprtsvc_dellsupportcenter; C:\Program Files\Dell Support Center\bin\sprtsvc.exe [202544 2008-03-11] (SupportSoft, Inc.)
S2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [272952 2008-01-20] (Microsoft Corporation)
R2 wltrysvc; C:\Windows\System32\bcmwltry.exe [2506752 2008-05-18] (Dell Inc.) [File not signed]
S2 233d520f; "C:\Windows\system32\rundll32.exe" "c:\Program Files\SustainerPlus\SustainerPlus.dll",serv
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [245096 2015-03-04] (Microsoft Corporation)
S3 BCM42RLY; system32\drivers\BCM42RLY.sys [X]
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
S3 SymIM; system32\DRIVERS\SymIM.sys [X]
S3 SymIMMP; system32\DRIVERS\SymIM.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-05-30 18:24 - 2015-05-30 18:24 - 00011453 _____ () C:\Users\Thomas\Downloads\FRST.txt
2015-05-30 18:23 - 2015-05-30 18:24 - 00000000 ____D () C:\FRST
2015-05-30 18:22 - 2015-05-30 18:22 - 01147392 _____ (Farbar) C:\Users\Thomas\Downloads\FRST.exe
2015-05-29 21:31 - 2015-05-29 21:31 - 00000000 _____ () C:\Users\Thomas\AppData\Local\Temp.dat
2015-05-28 07:29 - 2015-05-28 07:29 - 00001969 _____ () C:\Users\Public\Desktop\Adobe Digital Editions 4.0.lnk
2015-05-23 12:13 - 2015-05-23 12:13 - 00001828 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
2015-05-23 12:13 - 2015-05-23 12:13 - 00000000 ____D () C:\Program Files\Microsoft Security Client
2015-05-20 22:16 - 2015-05-20 22:16 - 00000000 ____D () C:\Program Files\PatternGenerators
2015-05-20 21:21 - 2015-05-20 21:21 - 00000000 ____D () C:\Program Files\uCoz Safe authorization
2015-05-20 21:17 - 2015-05-20 21:32 - 00000000 ____D () C:\Program Files\SoftwarePlus
2015-05-20 21:16 - 2015-05-20 22:15 - 00000000 ____D () C:\Program Files\PCCpnApp
2015-05-20 21:14 - 2015-05-29 21:14 - 00000348 _____ () C:\Windows\Tasks\Bidaily Synchronize Task[pr].job
2015-05-20 16:35 - 2015-05-20 16:35 - 00000084 _____ () C:\Users\Thomas\Desktop\Volt Pace Mary Terry Friday New Hire Paper work.txt
2015-05-17 19:03 - 2015-05-17 19:06 - 00000000 ____D () C:\Users\Thomas\Documents\Anki
2015-05-17 19:02 - 2015-05-17 19:03 - 00000762 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Anki.lnk
2015-05-17 19:00 - 2015-05-17 19:01 - 23237295 _____ () C:\Users\Thomas\Downloads\anki-2.0.32.exe
2015-05-16 12:57 - 2015-05-16 12:57 - 00000183 _____ () C:\Windows\wininit.ini
2015-05-16 08:51 - 2015-04-30 09:03 - 00279040 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-05-16 08:44 - 2015-04-19 14:24 - 01029120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll
2015-05-16 08:44 - 2015-04-19 14:24 - 00219648 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll
2015-05-16 08:44 - 2015-04-19 14:24 - 00189952 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll
2015-05-16 08:44 - 2015-04-19 14:24 - 00160768 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll
2015-05-16 08:44 - 2015-04-19 13:19 - 01172480 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2015-05-16 08:44 - 2015-04-19 13:18 - 00486400 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll
2015-05-16 08:44 - 2015-04-19 13:13 - 00682496 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2015-05-16 08:44 - 2015-04-19 13:12 - 01072640 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2015-05-16 08:44 - 2015-04-19 13:12 - 00801792 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2015-05-16 08:44 - 2015-04-18 21:59 - 02065408 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-05-16 08:43 - 2015-04-30 06:14 - 00102608 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-05-16 08:29 - 2015-04-10 16:22 - 00279552 _____ (Microsoft Corporation) C:\Windows\system32\services.exe
2015-05-15 11:16 - 2015-05-15 11:16 - 00000162 _____ () C:\Users\Thomas\Documents\8.txt
2015-05-15 09:55 - 2015-05-30 15:46 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2015-05-15 08:44 - 2015-05-27 02:08 - 00000000 ____D () C:\Users\Thomas\AppData\Roaming\vlc
2015-05-15 08:10 - 2015-04-10 08:25 - 01810944 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-05-15 08:10 - 2015-04-10 08:21 - 01139200 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-05-15 08:10 - 2015-04-10 08:20 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-05-15 08:10 - 2015-04-10 08:20 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-05-15 08:10 - 2015-04-10 08:19 - 01804288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-05-15 08:10 - 2015-04-10 08:19 - 00718336 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-05-15 08:10 - 2015-04-10 08:19 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-05-15 08:10 - 2015-04-10 08:19 - 00421888 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-05-15 08:10 - 2015-04-10 08:19 - 00353792 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-05-15 08:10 - 2015-04-10 08:19 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2015-05-15 08:10 - 2015-04-10 08:19 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-05-15 08:10 - 2015-04-10 08:19 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-05-15 08:10 - 2015-04-10 08:18 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-05-15 08:10 - 2015-04-10 08:18 - 00223232 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-05-15 08:10 - 2015-04-10 08:18 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-05-15 08:10 - 2015-04-10 08:18 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-05-15 08:10 - 2015-04-10 08:18 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2015-05-15 08:10 - 2015-04-10 08:18 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2015-05-15 08:10 - 2015-04-10 08:18 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2015-05-15 08:09 - 2015-04-10 08:30 - 12379136 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-05-15 08:09 - 2015-04-10 08:25 - 00367616 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-05-15 08:09 - 2015-04-10 08:24 - 09750528 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-05-12 22:31 - 2015-05-12 22:31 - 00000000 ____D () C:\Windows\pss
2015-05-10 22:55 - 2015-05-30 18:16 - 00000644 _____ () C:\Windows\Tasks\Check for updates (Spybot - Search & Destroy).job
2015-05-10 22:55 - 2015-05-27 00:39 - 00000616 _____ () C:\Windows\Tasks\Refresh immunization (Spybot - Search & Destroy).job
2015-05-10 22:55 - 2015-05-12 09:57 - 00000446 _____ () C:\Windows\Tasks\Scan the system (Spybot - Search & Destroy).job
2015-05-10 22:54 - 2015-05-27 00:39 - 00000000 ____D () C:\ProgramData\Spybot - Search & Destroy
2015-05-10 22:54 - 2015-05-10 22:59 - 00000000 ____D () C:\Program Files\Spybot - Search & Destroy 2
2015-05-10 22:54 - 2015-05-10 22:54 - 00001972 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk
2015-05-10 22:54 - 2015-05-10 22:54 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
2015-05-10 22:54 - 2013-09-20 10:49 - 00018968 _____ (Safer Networking Limited) C:\Windows\system32\sdnclean.exe
2015-05-10 22:52 - 2015-05-10 22:53 - 46525608 _____ (Safer-Networking Ltd. ) C:\Users\Thomas\Downloads\spybot-2-4.exe
2015-05-10 22:40 - 2015-05-10 22:40 - 02204160 _____ () C:\Users\Thomas\Downloads\adwcleaner_4.203.exe
2015-05-03 14:00 - 2015-05-03 14:00 - 00889416 _____ (Microsoft Corporation) C:\Users\Thomas\Downloads\dotNetFx40_Full_setup(1).exe
2015-05-01 14:10 - 2015-05-01 14:10 - 00027663 _____ () C:\Users\Thomas\Desktop\Thomas John Parks Resume.odt
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-05-30 18:22 - 2006-11-02 05:47 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2015-05-30 18:22 - 2006-11-02 05:47 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2015-05-30 18:22 - 2006-11-02 03:33 - 00756446 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-05-30 18:20 - 2015-04-22 22:00 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-05-30 18:19 - 2008-08-09 12:55 - 01795567 _____ () C:\Windows\WindowsUpdate.log
2015-05-30 18:14 - 2006-11-02 06:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-05-30 16:01 - 2006-11-02 06:01 - 00032556 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2015-05-30 15:46 - 2015-04-22 20:02 - 00000000 ____D () C:\AdwCleaner
2015-05-28 08:04 - 2015-04-19 08:00 - 00000000 ____D () C:\Users\Thomas\Desktop\Database Notes and Education
2015-05-28 07:29 - 2015-04-21 17:43 - 00001981 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Digital Editions 4.0.lnk
2015-05-28 07:16 - 2015-04-21 17:43 - 00000000 ____D () C:\Users\Thomas\Documents\My Digital Editions
2015-05-27 02:16 - 2015-03-30 21:22 - 00000000 ____D () C:\Users\Thomas\AppData\Roaming\Azureus
2015-05-27 02:06 - 2015-03-30 08:31 - 00047616 _____ () C:\Users\Thomas\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-05-27 01:34 - 2015-03-30 07:39 - 00000000 ____D () C:\Users\Thomas\AppData\Roaming\PeaZip
2015-05-25 11:09 - 2015-03-30 21:28 - 00005972 _____ () C:\Users\Thomas\AppData\Local\d3d9caps.dat
2015-05-23 12:13 - 2015-03-30 21:25 - 00001945 _____ () C:\Windows\epplauncher.mif
2015-05-21 19:41 - 2015-03-30 06:03 - 00000000 ____D () C:\Users\Thomas\AppData\Local\Adobe
2015-05-21 19:40 - 2015-04-22 22:00 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-05-21 19:40 - 2015-04-22 22:00 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-05-21 15:28 - 2008-01-20 19:47 - 00088992 _____ () C:\Windows\PFRO.log
2015-05-21 08:57 - 2015-04-02 16:06 - 00000000 ____D () C:\Users\Thomas\AppData\Local\Spotify
2015-05-21 08:54 - 2015-04-02 16:06 - 00000000 ____D () C:\Users\Thomas\AppData\Roaming\Spotify
2015-05-17 17:16 - 2006-11-02 05:47 - 00298672 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-05-17 15:21 - 2015-03-30 06:42 - 00000000 ____D () C:\Program Files\DiskInternals
2015-05-16 10:42 - 2006-11-02 04:18 - 00000000 ____D () C:\Windows\Microsoft.NET
2015-05-16 09:17 - 2006-11-02 05:37 - 00000000 ____D () C:\Windows\system32\XPSViewer
2015-05-16 09:17 - 2006-11-02 05:37 - 00000000 ____D () C:\Program Files\Windows Journal
2015-05-16 08:42 - 2015-03-29 10:51 - 00000000 ____D () C:\Windows\system32\MRT
2015-05-16 08:34 - 2006-11-02 03:24 - 137310008 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2015-05-15 22:32 - 2015-03-30 18:38 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2015-05-12 10:01 - 2015-03-30 20:47 - 00002425 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk
2015-05-12 10:01 - 2015-03-30 20:46 - 00000000 ____D () C:\Program Files\Common Files\Adobe
==================== Files in the root of some directories =======
2015-03-30 21:28 - 2015-05-25 11:09 - 0005972 _____ () C:\Users\Thomas\AppData\Local\d3d9caps.dat
2015-03-30 08:31 - 2015-05-27 02:06 - 0047616 _____ () C:\Users\Thomas\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-03-30 06:24 - 2015-03-30 06:24 - 0004662 _____ () C:\Users\Thomas\AppData\Local\Temp-log.txt
2015-05-29 21:31 - 2015-05-29 21:31 - 0000000 _____ () C:\Users\Thomas\AppData\Local\Temp.dat
Some files in TEMP:
====================
C:\Users\Thomas\AppData\Local\Temp\ade.exe
C:\Users\Thomas\AppData\Local\Temp\i4jdel0.exe
C:\Users\Thomas\AppData\Local\Temp\Quarantine.exe
C:\Users\Thomas\AppData\Local\Temp\sqlite3.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-05-30 18:21
==================== End of log ============================