Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 15-04-2015 04
Ran by K (administrator) on DESTINY on 15-04-2015 20:05:24
Running from E:\
Loaded Profiles: K (Available profiles: K & Administrator)
Platform: Microsoft Windows XP Home Edition Service Pack 3 (X86) OS Language: English (United States)
Internet Explorer Version 8 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Microsoft Corporation) C:\WINDOWS\system32\scardsvr.exe
(Microsoft Corporation) C:\WINDOWS\system32\cisvc.exe
() C:\Program Files\Froyo_Android_Driver\Bin\MonServiceUDisk.exe
(Hefei Hejunzhengce Info Tech Co., Ltd.) C:\Program Files\Windows Audio\R1\AudioSrv.exe
(Microsoft Corporation) C:\WINDOWS\system32\wscntfy.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKU\S-1-5-18\...\RunOnce: [WUAppSetup] => C:\Program Files\Common Files\logishrd\WUApp32.exe [430080 2007-02-03] ()
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKU\S-1-5-21-725345543-1958367476-682003330-1004\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://www.bing.com
HKU\S-1-5-21-725345543-1958367476-682003330-1004\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache =
http://www.msn.com/?ocid=iehp
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: MSS+ Identifier -> {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} -> C:\Program Files\McAfee Security Scan\3.8.130\McAfeeMSS_IE.dll [2013-09-06] (McAfee, Inc.)
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C}
http://windowsupdate.microsoft.com/...ls/en/x86/client/wuweb_site.cab?1046191103890
DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455}
Winsock: Catalog9 01 C:\WINDOWS\system32\MyOSProtect.dll File Not found ()
Winsock: Catalog9 02 C:\WINDOWS\system32\MyOSProtect.dll File Not found ()
Winsock: Catalog9 18 C:\WINDOWS\system32\MyOSProtect.dll File Not found ()
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
FireFox:
========
FF ProfilePath: C:\Documents and Settings\K\Application Data\Mozilla\Firefox\Profiles\8aymfdzx.default
FF Plugin: @mcafee.com/McAfeeMssPlugin -> C:\Program Files\McAfee Security Scan\3.8.130\npMcAfeeMss.dll [2013-09-06] (McAfee, Inc.)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-04-06] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-04-06] (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.0.8 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2014-07-22] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2014-07-22] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2014-07-22] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2014-07-22] (VideoLAN)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-08-05] (Adobe Systems Inc.)
FF Extension: SNT - C:\Documents and Settings\K\Application Data\Mozilla\Firefox\Profiles\8aymfdzx.default\Extensions\
gliuyio@batooouaiei.com [2015-01-06]
FF Extension: EazyZoom - C:\Documents and Settings\K\Application Data\Mozilla\Firefox\Profiles\8aymfdzx.default\Extensions\
ke@feqdi.com [2015-04-06]
FF Extension: SmileysWeLove: Smileys for use with Facebook, GMail, and more - C:\Documents and Settings\K\Application Data\Mozilla\Firefox\Profiles\8aymfdzx.default\Extensions\
jid1-vW9nopuIAJiRHw@jetpack.xpi [2014-01-02]
FF Extension: Dynamo Combo 1.0.1 - C:\Documents and Settings\K\Application Data\Mozilla\Firefox\Profiles\8aymfdzx.default\Extensions\{bf5001a3-ae7a-4910-925a-5060ef2c0508}.xpi [2015-01-06]
FF Extension: Healthcare Gov Tool - C:\Program Files\Mozilla Firefox\extensions\
healthcare@healthcaregovtool.com.xpi [2015-03-17]
FF Extension: Healthcare Gov Tool - C:\Program Files\Mozilla Firefox\browser\extensions\
healthcare@healthcaregovtool.com.xpi [2015-03-17]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2013-07-22]
FF HKLM\...\Firefox\Extensions: [
wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
Chrome:
=======
CHR HomePage: Default ->
CHR Profile: C:\Documents and Settings\K\Local Settings\Application Data\Google\Chrome\User Data\Default
CHR Extension: (No Name) - C:\Documents and Settings\K\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-11-17]
CHR Extension: (Mp3Skull Toolbar) - C:\Documents and Settings\K\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\anaehjnjgheaikfecjlfokolkoalpnda [2015-04-06]
CHR Extension: (Google Docs) - C:\Documents and Settings\K\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-11-17]
CHR Extension: (Google Drive) - C:\Documents and Settings\K\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-11-17]
CHR Extension: (YouTube) - C:\Documents and Settings\K\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-10-09]
CHR Extension: (Google Search) - C:\Documents and Settings\K\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-11-17]
CHR Extension: (Mahjongg) - C:\Documents and Settings\K\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\dfhgecpiaaideopgfehpomehflocnphd [2014-10-09]
CHR Extension: (Mahjongg Mahjongg) - C:\Documents and Settings\K\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\djgifnjpclblfhjamijejgmmmajndglm [2014-10-09]
CHR Extension: (Free Smileys & Emoticons) - C:\Documents and Settings\K\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\eadohofilecbkoopckifdpenihdpdbfm [2014-10-09]
CHR Extension: (Mahjongg) - C:\Documents and Settings\K\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\eegpopcingfghbompjfejakfeaolmbop [2014-10-09]
CHR Extension: (Google Sheets) - C:\Documents and Settings\K\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-11-17]
CHR Extension: (Whist Card Game) - C:\Documents and Settings\K\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\hnogegkomblljannepeelpenlmbdolna [2014-10-09]
CHR Extension: (Chrome Hotword Shared Module) - C:\Documents and Settings\K\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-04-06]
CHR Extension: (Comic Webcam) - C:\Documents and Settings\K\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\lfffhmndpldceogndeognocbpmlgdemi [2014-10-09]
CHR Extension: (Frogger Classic) - C:\Documents and Settings\K\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\mamnieegbgfhklagjjbacjiidjojeogd [2014-10-09]
CHR Extension: (Dice) - C:\Documents and Settings\K\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\mkomhldhkbggnefgdjggpfaaljlfmahe [2014-10-09]
CHR Extension: (Mahjong Games with High Scores) - C:\Documents and Settings\K\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\ngcmfkldebnlhhnohafeahjkeihmcjjd [2014-10-09]
CHR Extension: (Google Wallet) - C:\Documents and Settings\K\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-10-09]
CHR Extension: (No Name) - C:\Documents and Settings\K\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\npeidojcmghjibnbnmjloedchcgdkbeo [2015-04-06]
CHR Extension: (No Name) - C:\Documents and Settings\K\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\oehpjpccmlcalbenfhnacjeocbjdonic [2015-04-06]
CHR Extension: (10,000) - C:\Documents and Settings\K\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\olabdgcmaiboddccbiajlekdekkkjjkb [2014-10-09]
CHR Extension: (Gmail) - C:\Documents and Settings\K\Local Settings\Application Data\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-11-17]
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 Browser; C:\WINDOWS\System32\browser.dll [78336 2012-07-06] (Microsoft Corporation) [File not signed]
S3 LPDSVC; C:\WINDOWS\system32\tcpsvcs.exe [19456 2006-02-28] (Microsoft Corporation)
S2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-03-17] (Malwarebytes Corporation)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.130\McCHSvc.exe [235216 2013-09-06] (McAfee, Inc.)
R2 UDisk Monitor; C:\Program Files\Froyo_Android_Driver\Bin\MonServiceUDisk.exe [517960 2012-04-20] ()
R2 WinAudioSrv_R1; C:\Program Files\Windows Audio\R1\AudioSrv.exe [4024920 2015-04-07] (Hefei Hejunzhengce Info Tech Co., Ltd.)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S3 CamDrL; C:\WINDOWS\System32\DRIVERS\Camdrl.sys [1075360 2007-02-03] (Logitech Inc.)
S3 CCDECODE; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [17024 2008-04-14] (Microsoft Corporation)
R3 E1000; C:\WINDOWS\System32\DRIVERS\e1000325.sys [99840 2002-11-12] (Intel Corporation)
S3 eustub; C:\WINDOWS\System32\DRIVERS\eusbstub.sys [13800 2014-09-27] (ELTIMA Software)
S3 Generalusbserialser20675; C:\WINDOWS\System32\DRIVERS\CT_U_USBSER.sys [112456 2012-04-20] (Incorporated)
S3 HPKBCCID; C:\WINDOWS\System32\DRIVERS\HPKBCCID.sys [48000 2012-03-05] (Hewlett-Packard Company)
S3 LVUSBSta; C:\WINDOWS\System32\drivers\LVUSBSta.sys [41504 2007-02-03] (Logitech Inc.)
S3 mbamchameleon; C:\WINDOWS\system32\drivers\mbamchameleon.sys [120024 2015-04-11] (Malwarebytes Corporation)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [23256 2015-03-17] (Malwarebytes Corporation)
S3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [119512 2015-04-11] (Malwarebytes Corporation)
S3 NdisIP; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [10880 2008-04-14] (Microsoft Corporation)
S3 nm; C:\WINDOWS\System32\DRIVERS\NMnt.sys [40320 2008-04-14] (Microsoft Corporation)
S3 PID_0928; C:\WINDOWS\System32\DRIVERS\LV561AV.SYS [495768 2009-04-30] (Logitech Inc.)
S3 vuhub; C:\WINDOWS\System32\DRIVERS\vuhub.sys [63848 2013-12-10] (ELTIMA Software)
U5 ScsiPort; C:\WINDOWS\system32\drivers\scsiport.sys [96384 2008-04-14] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-04-15 20:05 - 2015-04-15 20:05 - 00000000 ____D () C:\Documents and Settings\K\Desktop\LOST.DIR
2015-04-14 21:17 - 2015-04-14 21:19 - 98077435 _____ (Igor Pavlov) C:\Documents and Settings\K\Desktop\OTLPEStd.exe
2015-04-14 20:36 - 2015-04-14 20:40 - 127231689 _____ (Igor Pavlov) C:\Documents and Settings\K\Desktop\OTLPENet.exe
2015-04-13 21:37 - 2015-04-11 22:29 - 00049825 _____ () C:\Documents and Settings\K\My Documents\Addition.txt
2015-04-12 21:11 - 2015-04-14 18:57 - 01136128 _____ (Farbar) C:\Documents and Settings\K\Desktop\FRST.exe
2015-04-12 21:02 - 2015-04-12 21:02 - 00063127 _____ () C:\Documents and Settings\K\My Documents\FRST.txt
2015-04-12 20:54 - 2015-04-14 21:04 - 00000000 ____D () C:\Documents and Settings\K\My Documents\Techspot
2015-04-11 23:08 - 2015-04-11 23:08 - 00001919 _____ () C:\WINDOWS\epplauncher.mif
2015-04-11 23:07 - 2015-04-15 20:06 - 00000000 ____D () C:\Documents and Settings\K\Desktop\Virus
2015-04-11 22:10 - 2015-04-15 20:05 - 00000000 ___DC () C:\FRST
2015-04-11 20:33 - 2015-04-11 20:36 - 150062624 _____ (Avast Software s.r.o.) C:\Documents and Settings\K\My Documents\avast_free_antivirus_setup.exe
2015-04-11 19:23 - 2015-04-11 19:23 - 00000000 ___DC () C:\TDSSKiller_Quarantine
2015-04-11 18:36 - 2015-04-11 19:48 - 00000000 ___DC () C:\AdwCleaner
2015-04-11 02:41 - 2015-04-11 19:00 - 00119512 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-04-11 02:25 - 2015-04-11 02:40 - 00000000 ____D () C:\Program Files\Malwarebytes Anti-Malware
2015-04-11 02:25 - 2015-04-11 02:40 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes Anti-Malware
2015-04-11 02:25 - 2015-03-17 06:15 - 00023256 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2015-04-11 02:15 - 2012-05-18 17:09 - 44753295 ____N () C:\Documents and Settings\K\Desktop\forMybabe3gp.mp4
2015-04-10 03:59 - 2015-04-11 20:47 - 00000101 _____ () C:\Documents and Settings\K\Desktop\Commands.txt
2015-04-10 01:05 - 2015-04-10 01:05 - 00000000 ____D () C:\Documents and Settings\K\Application Data\Help
2015-04-10 00:18 - 2015-04-10 00:18 - 00001548 _____ () C:\Documents and Settings\K\Desktop\Command Prompt.lnk
2015-04-09 05:30 - 2015-04-09 05:30 - 00000000 ___HD () C:\WINDOWS\PIF
2015-04-08 23:15 - 2015-04-09 05:30 - 00000000 __HDC () C:\WINDOWS\ie8
2015-04-08 22:18 - 2015-04-08 22:21 - 00034548 _____ () C:\WINDOWS\ie8Uninst.log
2015-04-08 22:17 - 2015-04-08 22:17 - 16883056 _____ (Microsoft Corporation) C:\Documents and Settings\LocalService\My Documents\IE8-WinXp-x86.exe
2015-04-08 22:16 - 2015-04-14 23:16 - 00000368 _____ () C:\WINDOWS\Tasks\UpdateAdmin.job
2015-04-08 18:56 - 2015-04-11 02:51 - 00120024 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2015-04-08 12:23 - 2015-04-11 17:13 - 00000444 _____ () C:\Documents and Settings\K\Desktop\routes.txt
2015-04-08 05:21 - 2015-04-08 05:21 - 00000000 _SHDC () C:\Documents and Settings\Administrator.KEIONA.000\PrivacIE
2015-04-08 04:22 - 2015-04-12 21:19 - 00000000 __HDC () C:\Documents and Settings\Administrator.KEIONA.000\Local Settings\Temp
2015-04-08 04:22 - 2015-04-11 18:51 - 00000178 __SHC () C:\Documents and Settings\Administrator.KEIONA.000\ntuser.ini
2015-04-08 04:22 - 2015-04-08 05:21 - 00000000 ___DC () C:\Documents and Settings\Administrator.KEIONA.000
2015-04-08 04:22 - 2015-04-08 04:22 - 00000000 _SHDC () C:\Documents and Settings\Administrator.KEIONA.000\IETldCache
2015-04-08 04:22 - 2013-11-18 07:15 - 00001604 ___HC () C:\Documents and Settings\Administrator.KEIONA.000\Start Menu\Programs\Remote Assistance.lnk
2015-04-08 04:22 - 2013-07-09 03:09 - 00000000 __HDC () C:\Documents and Settings\Administrator.KEIONA.000\Local Settings\Application Data\Microsoft Help
2015-04-08 04:22 - 2003-02-25 07:57 - 00000000 _RHDC () C:\Documents and Settings\Administrator.KEIONA.000\Start Menu\Programs\Accessories
2015-04-08 03:22 - 2015-04-08 03:22 - 00000000 ____D () C:\Program Files\Windows Audio
2015-04-07 05:51 - 2015-04-07 05:51 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\Google Chrome
2015-04-07 05:48 - 2015-04-07 05:48 - 00000000 ____D () C:\Documents and Settings\K\Application Data\youtube-downloader-and-converter
2015-04-07 05:48 - 2015-04-07 05:48 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\Optimizer Pro v3.2
2015-04-07 02:27 - 2015-04-07 05:11 - 00002136 ____C () C:\Documents and Settings\All Users\Application Data\tempimage.bmp
2015-04-06 22:31 - 2015-04-06 22:31 - 00000000 ___DC () C:\Documents and Settings\All Users\Application Data\Windows VXM
2015-04-06 21:42 - 2015-04-06 21:42 - 00000000 ____D () C:\WINDOWS\SysHealthController
2015-04-06 21:42 - 2015-04-06 21:42 - 00000000 ____D () C:\WINDOWS\SysFilesController
2015-04-06 21:42 - 2015-04-06 21:42 - 00000000 ____D () C:\Program Files\SysFiles
2015-04-06 21:41 - 2015-04-06 21:41 - 00000000 ____D () C:\Program Files\YouTube Download Pool
2015-04-06 21:40 - 2015-04-07 05:14 - 00000000 ____D () C:\Program Files\user extensions
2015-04-06 21:40 - 2015-04-06 21:40 - 00000000 ____D () C:\Program Files\9135fa6f-851d-4210-8a06-c060645e7f6d
2015-04-06 21:34 - 2015-04-06 21:34 - 00000000 ____D () C:\Documents and Settings\K\Local Settings\Application Data\Deployment
2015-04-06 20:57 - 2015-04-06 20:57 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\McAfee Security Scan Plus
2015-04-06 20:56 - 2015-04-06 20:56 - 00000000 ___DC () C:\Documents and Settings\All Users\Application Data\McAfee Security Scan
2015-04-06 20:56 - 2015-04-06 20:56 - 00000000 ____D () C:\Program Files\McAfee Security Scan
2015-04-06 20:56 - 2015-04-06 20:56 - 00000000 ____D () C:\Program Files\FamilySearch Indexing
2015-04-06 20:56 - 2015-04-06 20:56 - 00000000 ____D () C:\Documents and Settings\K\.FamilySearchIndexing
2015-04-06 20:56 - 2015-04-06 20:56 - 00000000 ____D () C:\Documents and Settings\All Users\Start Menu\Programs\FamilySearch
2015-04-06 19:32 - 2015-04-09 03:21 - 00000004 _____ () C:\WINDOWS\system32\029B560A371F4E00AB32838EBC01B9E7
2015-04-06 19:12 - 2015-04-06 19:12 - 00000000 ____D () C:\Documents and Settings\LocalService\Local Settings\Application Data\{D2020D47-707D-4E26-B4D9-739C4F4C2E9A}
2015-04-06 19:11 - 2015-04-06 19:49 - 00000000 ___DC () C:\Documents and Settings\All Users\Application Data\{9d39d2a8-4a19-bd4c-9d39-9d2a84a14aa1}
2015-04-06 19:11 - 2015-04-06 19:11 - 00000000 ____D () C:\Documents and Settings\K\Application Data\Company
2015-04-06 19:11 - 2015-04-06 19:11 - 00000000 ____D () C:\Documents and Settings\K\Application Data\{D2020D47-707D-4E26-B4D9-739C4F4C2E9A}
2015-04-06 18:58 - 2015-04-06 18:58 - 00000000 ____D () C:\Documents and Settings\Fresh\Local Settings\Application Data\Crossbrowse
2015-04-06 18:41 - 2015-04-06 18:41 - 00000000 ___DC () C:\Documents and Settings\All Users\Application Data\COMODO
2015-04-06 18:40 - 2015-04-06 18:40 - 00000000 ____D () C:\Program Files\COMODO
2015-04-06 18:38 - 2015-04-12 21:15 - 00000000 ___DC () C:\Documents and Settings\All Users\Application Data\{d57a658c-02a3-56a6-d57a-a658c02a9630}
2015-04-06 18:36 - 2015-04-06 19:49 - 00000000 ____D () C:\Documents and Settings\K\Local Settings\Application Data\4C4C4544-1428345377-5010-805A-B9C04F533231
2015-04-06 18:17 - 2015-04-06 18:17 - 00001818 _____ () C:\Documents and Settings\All Users\Desktop\Google Chrome.lnk
2015-04-06 04:32 - 2015-04-06 20:54 - 00000000 ___DC () C:\138efef433ac4b7a372a18dc
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-04-15 20:06 - 2003-02-25 08:17 - 00000000 ____D () C:\Documents and Settings\K\Local Settings\Temp
2015-04-15 20:03 - 2014-03-16 08:48 - 00000214 _____ () C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Logon.job
2015-04-15 20:03 - 2003-02-25 08:01 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2015-04-15 20:03 - 2003-02-25 07:55 - 01101817 _____ () C:\WINDOWS\WindowsUpdate.log
2015-04-15 20:03 - 2003-02-25 00:44 - 00000159 _____ () C:\WINDOWS\wiadebug.log
2015-04-15 20:03 - 2003-02-25 00:44 - 00000049 _____ () C:\WINDOWS\wiaservc.log
2015-04-15 17:55 - 2003-02-25 08:01 - 00032558 _____ () C:\WINDOWS\SchedLgU.Txt
2015-04-14 23:24 - 2003-02-25 08:17 - 00000178 ___SH () C:\Documents and Settings\K\ntuser.ini
2015-04-14 19:49 - 2013-07-01 09:34 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\Microsoft Help
2015-04-14 19:48 - 2013-07-17 03:01 - 00000000 ____D () C:\WINDOWS\system32\MRT
2015-04-14 19:32 - 2013-06-28 15:45 - 125832184 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2015-04-14 19:17 - 2006-02-28 06:00 - 00000743 _____ () C:\WINDOWS\win.ini
2015-04-13 18:51 - 2014-09-13 13:32 - 00000000 ____D () C:\Documents and Settings\K\Application Data\vlc
2015-04-12 21:19 - 2013-10-03 12:30 - 00000000 ___HD () C:\Documents and Settings\Fresh\Local Settings\Temp
2015-04-12 21:19 - 2003-02-25 08:17 - 00000000 ____D () C:\Documents and Settings\K
2015-04-12 20:51 - 2006-02-28 06:00 - 00013646 ____H () C:\WINDOWS\system32\wpa.dbl
2015-04-11 23:44 - 2014-09-07 03:57 - 00039473 _____ () C:\WINDOWS\KB2964358-IE8.log
2015-04-11 23:44 - 2014-09-07 01:58 - 00075198 _____ () C:\WINDOWS\KB2936068-IE8.log
2015-04-11 23:44 - 2013-07-01 09:43 - 00065536 _____ () C:\WINDOWS\system32\config\OAlerts.evt
2015-04-11 23:27 - 2013-07-28 00:25 - 00000000 ____D () C:\WINDOWS\system32\NtmsData
2015-04-11 17:32 - 2013-07-27 16:29 - 00301400 _____ () C:\WINDOWS\pfirewall.log
2015-04-11 16:10 - 2013-11-25 01:22 - 00001585 _____ () C:\Documents and Settings\K\Desktop\Event.lnk
2015-04-11 16:10 - 2013-11-18 18:01 - 00001292 _____ () C:\Documents and Settings\K\Desktop\Shared.lnk
2015-04-11 02:25 - 2013-07-01 08:41 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\Malwarebytes
2015-04-11 01:56 - 2014-03-02 23:29 - 00493907 _____ () C:\WINDOWS\setupapi.log
2015-04-11 01:56 - 2003-02-25 00:40 - 36953687 _____ () C:\WINDOWS\setupact.log
2015-04-10 01:46 - 2014-09-17 00:46 - 00000128 _____ () C:\Documents and Settings\NetworkService\Application Data\WB.CFG
2015-04-10 01:16 - 2003-02-25 08:01 - 00000000 __SHD () C:\Documents and Settings\NetworkService
2015-04-10 01:05 - 2003-02-25 00:33 - 00000000 ____D () C:\WINDOWS\Help
2015-04-09 07:13 - 2013-07-27 16:29 - 04050606 _____ () C:\WINDOWS\pfirewall.log.old
2015-04-09 05:32 - 2013-06-28 15:49 - 00000000 ____D () C:\WINDOWS\ie8updates
2015-04-09 02:11 - 2013-06-28 14:36 - 00217689 _____ () C:\WINDOWS\updspapi.log
2015-04-09 02:11 - 2003-02-25 00:41 - 01740669 _____ () C:\WINDOWS\FaxSetup.log
2015-04-09 02:11 - 2003-02-25 00:41 - 01065035 _____ () C:\WINDOWS\ocgen.log
2015-04-09 02:11 - 2003-02-25 00:41 - 00724719 _____ () C:\WINDOWS\tsoc.log
2015-04-09 02:11 - 2003-02-25 00:41 - 00623449 _____ () C:\WINDOWS\comsetup.log
2015-04-09 02:11 - 2003-02-25 00:41 - 00416651 _____ () C:\WINDOWS\ntdtcsetup.log
2015-04-09 02:11 - 2003-02-25 00:41 - 00265582 _____ () C:\WINDOWS\iis6.log
2015-04-09 02:11 - 2003-02-25 00:41 - 00103451 _____ () C:\WINDOWS\ocmsn.log
2015-04-09 02:11 - 2003-02-25 00:41 - 00095469 _____ () C:\WINDOWS\msgsocm.log
2015-04-09 02:11 - 2003-02-25 00:41 - 00001355 _____ () C:\WINDOWS\imsins.log
2015-04-09 02:10 - 2014-02-16 22:31 - 00008661 ____C () C:\WINDOWS\KB2909210-IE8.log
2015-04-09 02:10 - 2003-02-25 00:41 - 00001355 _____ () C:\WINDOWS\imsins.BAK
2015-04-09 02:09 - 2013-07-01 08:31 - 00014279 ____C () C:\WINDOWS\KB2510531-IE8.log
2015-04-09 00:46 - 2015-01-04 22:50 - 00000010 _____ () C:\Documents and Settings\NetworkService\Local Settings\Application Data\DSI.DAT
2015-04-08 23:33 - 2013-06-28 14:42 - 00101340 ____C () C:\WINDOWS\spupdsvc.log
2015-04-08 23:29 - 2013-06-28 15:42 - 00253271 ____C () C:\WINDOWS\ie8_main.log
2015-04-08 23:27 - 2014-02-16 22:31 - 00046693 ____C () C:\WINDOWS\KB2909921-IE8.log
2015-04-08 23:26 - 2013-06-28 15:50 - 00090681 ____C () C:\WINDOWS\KB2598845-IE8.log
2015-04-08 23:25 - 2013-06-28 15:49 - 00108252 ____C () C:\WINDOWS\KB982381-IE8.log
2015-04-08 23:21 - 2013-06-28 15:47 - 00109348 ____C () C:\WINDOWS\ie8.log
2015-04-08 23:19 - 2003-02-25 00:33 - 00000000 ____D () C:\WINDOWS\Media
2015-04-08 22:29 - 2003-02-25 08:17 - 00000000 ___RD () C:\Documents and Settings\K\Start Menu\Programs\Accessories
2015-04-08 22:08 - 2003-02-25 08:01 - 00000000 __SHD () C:\Documents and Settings\LocalService
2015-04-08 20:11 - 2006-02-28 06:00 - 00000227 _____ () C:\WINDOWS\system.ini
2015-04-08 18:54 - 2014-09-28 06:57 - 00000000 ____D () C:\Documents and Settings\K\Desktop\status
2015-04-08 17:16 - 2003-02-25 07:57 - 00001568 _____ () C:\Documents and Settings\All Users\Start Menu\Set Program Access and Defaults.lnk
2015-04-08 17:16 - 2003-02-25 07:57 - 00001512 _____ () C:\Documents and Settings\All Users\Start Menu\Windows Update.lnk
2015-04-08 15:01 - 2014-03-16 08:48 - 00000208 _____ () C:\WINDOWS\Tasks\Microsoft Windows XP End of Service Notification Monthly.job
2015-04-08 12:08 - 2013-07-22 22:52 - 00001603 _____ () C:\Documents and Settings\K\Desktop\Restore.lnk
2015-04-08 11:13 - 2013-12-15 20:10 - 00001324 _____ () C:\WINDOWS\system32\d3d9caps.dat
2015-04-07 05:53 - 2013-10-03 12:30 - 00000000 ___HD () C:\Documents and Settings\Fresh
2015-04-07 05:52 - 2003-02-25 07:53 - 00000000 ____D () C:\WINDOWS\Registration
2015-04-07 05:14 - 2013-11-07 18:34 - 00568474 ____C () C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-S-1-5-21-725345543-1958367476-682003330-1004-0.dat
2015-04-07 05:14 - 2013-11-04 12:02 - 00284450 ____C () C:\Documents and Settings\LocalService\Local Settings\Application Data\WPFFontCache_v0400-System.dat
2015-04-07 02:09 - 2013-07-01 23:12 - 00000000 ____D () C:\Program Files\Google
2015-04-06 21:04 - 2015-01-06 21:20 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2015-04-06 21:04 - 2015-01-06 21:10 - 00000000 ____D () C:\Program Files\Unchecky
2015-04-06 20:56 - 2015-01-13 23:20 - 00000000 ____D () C:\Documents and Settings\K\Application Data\BitTorrent
2015-04-06 20:32 - 2015-01-12 04:09 - 00000000 __SDC () C:\Documents and Settings\Administrator.KEIONA
2015-04-06 19:49 - 2013-07-01 08:27 - 00000000 ____D () C:\Program Files\AVAST Software
2015-04-06 19:06 - 2014-09-13 20:22 - 00070776 _____ () C:\Documents and Settings\LocalService\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2015-04-06 17:06 - 2014-06-24 15:36 - 00000000 ____D () C:\Documents and Settings\K\My Documents\Cartoons
2015-04-06 16:51 - 2013-10-26 05:56 - 00000000 ____D () C:\Documents and Settings\All Users\Application Data\TEMP
2015-04-06 15:14 - 2013-07-01 10:47 - 00000000 ____D () C:\WINDOWS\Microsoft.NET
2015-04-06 06:37 - 2013-10-10 04:19 - 00636704 _____ () C:\WINDOWS\system32\PerfStringBackup.TMP
2015-04-06 04:49 - 2003-02-25 00:41 - 00000000 ____D () C:\Program Files\Common Files\Microsoft Shared
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
==================== End Of Log ============================