AfterTheFire
Posts: 34 +0
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 15-07-2017
Ran by djbobbysteele (administrator) on PDJE_PC (15-07-2017 16:33:28)
Running from C:\Users\djbobbysteele\Downloads
Loaded Profiles: djbobbysteele (Available Profiles: djbobbysteele & DefaultAppPool)
Platform: Windows 10 Home Version 1703 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Cypress Semiconductor Corporation) C:\Program Files\Cypress\TrackPad\CyTpService.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe
(Denon DJ) C:\Program Files (x86)\Denon DJ\DN-MC6000\AudioDevMon.exe
(Dropbox, Inc.) C:\Windows\System32\DbxSvc.exe
(Microsoft Corporation) C:\Windows\System32\mqsvc.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsStore_11705.1001.21.0_x64__8wekyb3d8bbwe\WinStore.App.exe
(DonationCoder) C:\Program Files (x86)\ScreenshotCaptor\ScreenshotCaptor.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Corporation) C:\Windows\System32\Taskmgr.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\cmd.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\AppleChromeDAV.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(The NWJS Community) C:\Program Files (x86)\The Neat Company\Neat Smart Organization System\Helium-shell\HeliumAppShell\Neat.exe
(The NWJS Community) C:\Program Files (x86)\The Neat Company\Neat Smart Organization System\Helium-shell\HeliumAppShell\Neat.exe
(The NWJS Community) C:\Program Files (x86)\The Neat Company\Neat Smart Organization System\Helium-shell\HeliumAppShell\Neat.exe
(The NWJS Community) C:\Program Files (x86)\The Neat Company\Neat Smart Organization System\Helium-shell\HeliumAppShell\Neat.exe
(Microsoft) C:\Program Files (x86)\The Neat Company\Neat Smart Organization System\Helium-shell\HeliumAppShell\binaries\NeatImageCaptureWrapper.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
() C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.18062.13720.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [629152 2017-03-18] (Microsoft Corporation)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [169744 2015-09-12] (Apple Inc.)
HKLM\...\Run: [WindowsDefender] => C:\Program Files\Windows Defender\MSASCuiL.exe [629152 2017-03-18] (Microsoft Corporation)
HKLM\...\Run: [Malwarebytes TrayApp] => C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe [3146704 2017-05-09] (Malwarebytes)
HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [3486520 2017-07-12] (Dropbox, Inc.)
HKLM-x32\...\Run: [Adobe Creative Cloud] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2383040 2016-10-12] (Adobe Systems Incorporated)
Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-21-3796937070-3348964198-3883336013-1000\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [67384 2016-07-08] (Apple Inc.)
HKU\S-1-5-21-3796937070-3348964198-3883336013-1000\...\Run: [Google Update] => C:\Users\djbobbysteele\AppData\Local\Google\Update\1.3.33.5\GoogleUpdateCore.exe [601168 2017-04-27] (Google Inc.)
HKU\S-1-5-21-3796937070-3348964198-3883336013-1000\...\Run: [Google Photos Backup] => C:\Users\djbobbysteele\AppData\Local\Programs\Google\Google Photos Backup\Google Photos Backup.exe [3790936 2016-04-08] (Google, Inc)
HKU\S-1-5-21-3796937070-3348964198-3883336013-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [9803992 2017-06-13] (Piriform Ltd)
HKU\S-1-5-21-3796937070-3348964198-3883336013-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\WINDOWS\system32\scrnsave.scr [37376 2017-03-18] (Microsoft Corporation)
AppInit_DLLs: C:\WINDOWS\system32\nvinitx.dll => No File
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SOLIDWORKS Background Downloader.lnk [2016-08-30]
ShortcutTarget: SOLIDWORKS Background Downloader.lnk -> C:\Program Files (x86)\Common Files\SOLIDWORKS Installation Manager\BackgroundDownloading\sldBgDwld.exe (Dassault Systèmes SolidWorks Corp.)
GroupPolicy: Restriction <==== ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 10.0.1.1
Tcpip\..\Interfaces\{0b828af4-7b2b-44cb-855a-0418e904c7e8}: [DhcpNameServer] 10.0.1.1
Tcpip\..\Interfaces\{e10f0252-5141-4e84-95af-3569028ed3d0}: [DhcpNameServer] 10.0.1.1
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.bing.com/search?FORM=INCOH1&PC=IC05&PTAG=ICO-fa0b4ca2
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?FORM=INCOH2&PC=IC05&PTAG=ICO-fa0b4ca2&q={searchTerms}
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?FORM=INCOH2&PC=IC05&PTAG=ICO-fa0b4ca2&q={searchTerms}
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?FORM=INCOH2&PC=IC05&PTAG=ICO-fa0b4ca2&q={searchTerms}
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?FORM=INCOH2&PC=IC05&PTAG=ICO-fa0b4ca2&q={searchTerms}
FireFox:
========
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2016-10-12] (Adobe Systems)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2015-12-18] ()
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-07-03] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-07-03] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-04-04] (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2016-10-12] (Adobe Systems)
FF Plugin HKU\S-1-5-21-3796937070-3348964198-3883336013-1000: @tools.google.com/Google Update;version=3 -> C:\Users\djbobbysteele\AppData\Local\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-27] (Google Inc.)
FF Plugin HKU\S-1-5-21-3796937070-3348964198-3883336013-1000: @tools.google.com/Google Update;version=9 -> C:\Users\djbobbysteele\AppData\Local\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-27] (Google Inc.)
Chrome:
=======
CHR Profile: C:\Users\djbobbysteele\AppData\Local\Google\Chrome\User Data\Default [2017-07-15]
CHR Extension: (Google Slides) - C:\Users\djbobbysteele\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-07-03]
CHR Extension: (Google Docs) - C:\Users\djbobbysteele\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-07-03]
CHR Extension: (Google Drive) - C:\Users\djbobbysteele\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-07-03]
CHR Extension: (YouTube) - C:\Users\djbobbysteele\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-07-03]
CHR Extension: (uTab) - C:\Users\djbobbysteele\AppData\Local\Google\Chrome\User Data\Default\Extensions\bpmmandcadflhnnaiclipadomfmdbjbp [2017-07-03]
CHR Extension: (Tidy Sidebar) - C:\Users\djbobbysteele\AppData\Local\Google\Chrome\User Data\Default\Extensions\dgmacifhhpefamjmolpipkijcofcmbgp [2017-07-03]
CHR Extension: (Adobe Acrobat) - C:\Users\djbobbysteele\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2017-07-03]
CHR Extension: (Hermes Tab) - C:\Users\djbobbysteele\AppData\Local\Google\Chrome\User Data\Default\Extensions\ehlceeijggpdgfcefmipcmdelickjgfg [2017-07-03]
CHR Extension: (Google Sheets) - C:\Users\djbobbysteele\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-07-03]
CHR Extension: (iCloud Bookmarks) - C:\Users\djbobbysteele\AppData\Local\Google\Chrome\User Data\Default\Extensions\fkepacicchenbjecpbpbclokcabebhah [2017-07-03]
CHR Extension: (GoToMeeting Pro Screensharing) - C:\Users\djbobbysteele\AppData\Local\Google\Chrome\User Data\Default\Extensions\gcgikpombjkodabhbdalkcdhmllafipp [2017-07-03]
CHR Extension: (Google Docs Offline) - C:\Users\djbobbysteele\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-07-03]
CHR Extension: (AdBlock) - C:\Users\djbobbysteele\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2017-07-03]
CHR Extension: (Cisco WebEx Extension) - C:\Users\djbobbysteele\AppData\Local\Google\Chrome\User Data\Default\Extensions\jlhmfgmfgeifomenelglieieghnjghma [2017-07-14]
CHR Extension: (Google Keep Chrome Extension) - C:\Users\djbobbysteele\AppData\Local\Google\Chrome\User Data\Default\Extensions\lpcaedmchfhocbbapmcbpinfpgnhiddi [2017-07-03]
CHR Extension: (Chrome Web Store Payments) - C:\Users\djbobbysteele\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-07-03]
CHR Extension: (Xodo PDF Viewer & Editor) - C:\Users\djbobbysteele\AppData\Local\Google\Chrome\User Data\Default\Extensions\okimpmfnmbjbaciaeaikdiecpobfomfh [2017-07-03]
CHR Extension: (Gmail) - C:\Users\djbobbysteele\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-07-03]
CHR Extension: (Chrome Media Router) - C:\Users\djbobbysteele\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-07-13]
CHR HKLM\...\Chrome\Extension: [bpmmandcadflhnnaiclipadomfmdbjbp] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM\...\Chrome\Extension: [ehlceeijggpdgfcefmipcmdelickjgfg] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [bpmmandcadflhnnaiclipadomfmdbjbp] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [ehlceeijggpdgfcefmipcmdelickjgfg] - hxxps://clients2.google.com/service/update2/crx
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AdobeUpdateService; C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [744640 2016-10-12] (Adobe Systems Incorporated)
R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2246256 2017-05-18] (Adobe Systems, Incorporated)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2016-03-02] (Apple Inc.)
R2 CyTpService; C:\Program Files\Cypress\TrackPad\CyTpService.exe [28160 2015-04-22] (Cypress Semiconductor Corporation)
S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-07-12] (Dropbox, Inc.)
S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-07-12] (Dropbox, Inc.)
R2 DbxSvc; C:\WINDOWS\system32\DbxSvc.exe [49992 2017-07-12] (Dropbox, Inc.)
R2 DNMC6000AudioDevMon; C:\Program Files (x86)\Denon DJ\DN-MC6000\AudioDevMon.exe [2382608 2015-06-01] (Denon DJ)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4470736 2017-05-09] (Malwarebytes)
R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [263264 2017-02-24] (Synaptics Incorporated)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [342264 2017-03-18] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [102816 2017-06-20] (Microsoft Corporation)
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 cykbfltrService; C:\WINDOWS\system32\DRIVERS\cykbfltr.sys [19968 2015-08-18] (Cypress Semiconductor, Inc.)
S3 cymfltrService; C:\WINDOWS\system32\DRIVERS\cymfltr.sys [102400 2015-08-18] (Cypress Semiconductor, Inc.)
S3 DNMC6000; C:\WINDOWS\system32\DRIVERS\DenonDJDNMC6000.sys [549648 2015-06-01] (Denon DJ)
R1 ESProtectionDriver; C:\WINDOWS\system32\drivers\mbae64.sys [77376 2017-06-27] ()
R2 MBAMChameleon; C:\WINDOWS\system32\drivers\MBAMChameleon.sys [188352 2017-07-03] (Malwarebytes)
R3 MBAMFarflt; C:\WINDOWS\system32\drivers\farflt.sys [101784 2017-07-14] (Malwarebytes)
R3 MBAMProtection; C:\WINDOWS\system32\drivers\mbam.sys [45472 2017-07-14] (Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [253856 2017-07-14] (Malwarebytes)
R3 MBAMWebProtection; C:\WINDOWS\system32\drivers\mwac.sys [93600 2017-07-15] (Malwarebytes)
R3 nvlddmkm; C:\WINDOWS\System32\DriverStore\FileRepository\nvdmwu.inf_amd64_26aa6356770b2e86\nvlddmkm.sys [13754936 2016-09-12] (NVIDIA Corporation)
S3 SDFRd; C:\WINDOWS\System32\drivers\SDFRd.sys [31128 2017-03-18] ()
U3 TrueSight; C:\Windows\System32\drivers\TrueSight.sys [28272 2017-07-14] ()
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [44632 2017-03-18] (Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\WdFilter.sys [294816 2017-03-18] (Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [121248 2017-03-18] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-07-15 16:33 - 2017-07-15 16:33 - 00000000 ____D C:\Users\djbobbysteele\Downloads\FRST-OlderVersion
2017-07-15 13:52 - 2017-07-15 13:52 - 00000000 ____D C:\Users\djbobbysteele\NeatUpdate
2017-07-15 13:51 - 2017-07-15 13:51 - 00000000 ____D C:\Program Files (x86)\GraphicsMagick-1.3.21-Q8
2017-07-15 09:45 - 2017-07-15 09:45 - 00130390 _____ C:\Users\djbobbysteele\Downloads\1499673918110.jpeg
2017-07-15 09:44 - 2017-07-15 09:44 - 00156147 _____ C:\Users\djbobbysteele\Downloads\1499673139148.jpeg
2017-07-15 09:43 - 2017-07-15 09:43 - 00180671 _____ C:\Users\djbobbysteele\Downloads\1499673683789.jpeg
2017-07-15 09:42 - 2017-07-15 09:42 - 00735792 _____ C:\Users\djbobbysteele\Downloads\1499673855452.jpeg
2017-07-15 09:42 - 2017-07-15 09:42 - 00197421 _____ C:\Users\djbobbysteele\Downloads\1499673590356.jpeg
2017-07-15 09:42 - 2017-07-15 09:42 - 00142199 _____ C:\Users\djbobbysteele\Downloads\1499673746977.jpeg
2017-07-14 08:04 - 2017-07-14 08:04 - 00012987 _____ C:\Users\djbobbysteele\Desktop\EVENTS 2011 TO PRESENT1.txt
2017-07-14 07:21 - 2017-07-14 07:21 - 00000000 ____D C:\Users\djbobbysteele\AppData\Local\CrashDumps
2017-07-14 07:20 - 2017-07-14 07:20 - 01663672 _____ (Malwarebytes) C:\Users\djbobbysteele\Downloads\JRT.exe
2017-07-14 07:01 - 2017-03-18 16:56 - 00105472 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthenum.sys
2017-07-14 07:01 - 2017-03-18 16:56 - 00085504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BTHUSB.SYS
2017-07-14 06:22 - 2017-07-14 06:22 - 00028272 _____ C:\WINDOWS\system32\Drivers\TrueSight.sys
2017-07-14 06:22 - 2017-07-14 06:22 - 00000000 ____D C:\ProgramData\RogueKiller
2017-07-14 06:21 - 2017-07-14 06:21 - 00000899 _____ C:\Users\Public\Desktop\RogueKiller.lnk
2017-07-14 06:21 - 2017-07-14 06:21 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RogueKiller
2017-07-14 06:21 - 2017-07-14 06:21 - 00000000 ____D C:\Program Files\RogueKiller
2017-07-14 06:18 - 2017-07-14 06:18 - 35612552 _____ (Adlice Software ) C:\Users\djbobbysteele\Desktop\RogueKiller_setup_ref3.exe
2017-07-13 19:19 - 2017-07-13 19:19 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox
2017-07-12 21:25 - 2017-07-12 21:25 - 00000000 ____D C:\Users\djbobbysteele\AppData\Local\Chromium
2017-07-12 19:57 - 2017-07-12 19:57 - 142267536 _____ C:\Users\djbobbysteele\Downloads\Tone Rios - Wanted (Club Rermix) (Clean).mp4
2017-07-12 19:57 - 2017-07-12 19:57 - 125833426 _____ C:\Users\djbobbysteele\Downloads\Mike Perry Feat. Casso - Inside the Lines (Galwaro Remix) (Clean).mp4
2017-07-12 19:56 - 2017-07-12 19:57 - 118717570 _____ C:\Users\djbobbysteele\Downloads\Clean Bandit Feat. Sean Paul & Anne Marie - Rockabye (Kavorka X TuneSquad Remix) (Clean).mp4
2017-07-12 19:52 - 2017-07-12 19:52 - 74509668 _____ C:\Users\djbobbysteele\Downloads\T-Mass & LZRD - Cash (Danny Diggz)(Clean).mp4
2017-07-12 19:51 - 2017-07-12 19:52 - 122401898 _____ C:\Users\djbobbysteele\Downloads\DJ Scene & Four Color Zack ft Mad Lion - Stomp (V.2 Remix)(Dirty).mp4
2017-07-12 19:50 - 2017-07-12 19:50 - 129079699 _____ C:\Users\djbobbysteele\Downloads\Turbotronic - One Time (Clubhunter Remix) (Clean).mp4
2017-07-12 19:49 - 2017-07-12 19:50 - 182933661 _____ C:\Users\djbobbysteele\Downloads\Turbotronic - Friday Night (Clubhunter) (Clean).mp4
2017-07-12 19:49 - 2017-07-12 19:50 - 175904079 _____ C:\Users\djbobbysteele\Downloads\Alex Gaudino - Destination Calabria (Justflow Remix) (Clean).mp4
2017-07-12 19:49 - 2017-07-12 19:49 - 84889476 _____ C:\Users\djbobbysteele\Downloads\Alan Walker ft. Gavin James - Tired (DOPEDROP Remix) (Clean).mp4
2017-07-12 19:43 - 2017-07-12 19:44 - 158804062 _____ C:\Users\djbobbysteele\Downloads\Crazy Frog - Axel F (STVW & Mountblaq Remix) (Dirty).mp4
2017-07-12 19:43 - 2017-07-12 19:44 - 112844933 _____ C:\Users\djbobbysteele\Downloads\A Billion Robots - One More Drink (Club Mix) (Clean).mp4
2017-07-12 19:41 - 2017-07-12 19:42 - 84672089 _____ C:\Users\djbobbysteele\Downloads\Martin Garrix & Dua Lipa - Scared To Be Lonely (Sammy Boyle Remix) (Clean).mp4
2017-07-12 19:41 - 2017-07-12 19:42 - 118236692 _____ C:\Users\djbobbysteele\Downloads\Luis Fonsi, Daddy Yankee Feat. Justin Bieber - Despacito (DROPSTARS Remix) (Clean).mp4
2017-07-12 19:40 - 2017-07-12 19:42 - 395931424 _____ C:\Users\djbobbysteele\Downloads\Clubhunter - Do Me (Turbotronic Mix) (Clean).mp4
2017-07-12 19:40 - 2017-07-12 19:42 - 158067706 _____ C:\Users\djbobbysteele\Downloads\Geo Da Silva, Sean Norvis with Dj Combo & Kizami - SummerTime (Fizo Faouez Remix) (Dirty).mp4
2017-07-12 19:40 - 2017-07-12 19:41 - 134472787 _____ C:\Users\djbobbysteele\Downloads\GoldFish feat. Diamond Thug - Deep Of The Night (dj 3b Remix) (Clean) .mp4
2017-07-12 19:36 - 2017-07-12 19:36 - 08704010 _____ C:\Users\djbobbysteele\Downloads\Detroit's Filthiest - Handprint.m4a
2017-07-12 19:32 - 2017-07-12 19:33 - 128578087 _____ C:\Users\djbobbysteele\Downloads\Zedd Feat. Matthew Koma - Spectrum Lyric Video Clean.mp4
Ran by djbobbysteele (administrator) on PDJE_PC (15-07-2017 16:33:28)
Running from C:\Users\djbobbysteele\Downloads
Loaded Profiles: djbobbysteele (Available Profiles: djbobbysteele & DefaultAppPool)
Platform: Windows 10 Home Version 1703 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Cypress Semiconductor Corporation) C:\Program Files\Cypress\TrackPad\CyTpService.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe
(Denon DJ) C:\Program Files (x86)\Denon DJ\DN-MC6000\AudioDevMon.exe
(Dropbox, Inc.) C:\Windows\System32\DbxSvc.exe
(Microsoft Corporation) C:\Windows\System32\mqsvc.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsStore_11705.1001.21.0_x64__8wekyb3d8bbwe\WinStore.App.exe
(DonationCoder) C:\Program Files (x86)\ScreenshotCaptor\ScreenshotCaptor.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Corporation) C:\Windows\System32\Taskmgr.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\cmd.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\AppleChromeDAV.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(The NWJS Community) C:\Program Files (x86)\The Neat Company\Neat Smart Organization System\Helium-shell\HeliumAppShell\Neat.exe
(The NWJS Community) C:\Program Files (x86)\The Neat Company\Neat Smart Organization System\Helium-shell\HeliumAppShell\Neat.exe
(The NWJS Community) C:\Program Files (x86)\The Neat Company\Neat Smart Organization System\Helium-shell\HeliumAppShell\Neat.exe
(The NWJS Community) C:\Program Files (x86)\The Neat Company\Neat Smart Organization System\Helium-shell\HeliumAppShell\Neat.exe
(Microsoft) C:\Program Files (x86)\The Neat Company\Neat Smart Organization System\Helium-shell\HeliumAppShell\binaries\NeatImageCaptureWrapper.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
() C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.18062.13720.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [629152 2017-03-18] (Microsoft Corporation)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [169744 2015-09-12] (Apple Inc.)
HKLM\...\Run: [WindowsDefender] => C:\Program Files\Windows Defender\MSASCuiL.exe [629152 2017-03-18] (Microsoft Corporation)
HKLM\...\Run: [Malwarebytes TrayApp] => C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe [3146704 2017-05-09] (Malwarebytes)
HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [3486520 2017-07-12] (Dropbox, Inc.)
HKLM-x32\...\Run: [Adobe Creative Cloud] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2383040 2016-10-12] (Adobe Systems Incorporated)
Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-21-3796937070-3348964198-3883336013-1000\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [67384 2016-07-08] (Apple Inc.)
HKU\S-1-5-21-3796937070-3348964198-3883336013-1000\...\Run: [Google Update] => C:\Users\djbobbysteele\AppData\Local\Google\Update\1.3.33.5\GoogleUpdateCore.exe [601168 2017-04-27] (Google Inc.)
HKU\S-1-5-21-3796937070-3348964198-3883336013-1000\...\Run: [Google Photos Backup] => C:\Users\djbobbysteele\AppData\Local\Programs\Google\Google Photos Backup\Google Photos Backup.exe [3790936 2016-04-08] (Google, Inc)
HKU\S-1-5-21-3796937070-3348964198-3883336013-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [9803992 2017-06-13] (Piriform Ltd)
HKU\S-1-5-21-3796937070-3348964198-3883336013-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\WINDOWS\system32\scrnsave.scr [37376 2017-03-18] (Microsoft Corporation)
AppInit_DLLs: C:\WINDOWS\system32\nvinitx.dll => No File
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SOLIDWORKS Background Downloader.lnk [2016-08-30]
ShortcutTarget: SOLIDWORKS Background Downloader.lnk -> C:\Program Files (x86)\Common Files\SOLIDWORKS Installation Manager\BackgroundDownloading\sldBgDwld.exe (Dassault Systèmes SolidWorks Corp.)
GroupPolicy: Restriction <==== ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 10.0.1.1
Tcpip\..\Interfaces\{0b828af4-7b2b-44cb-855a-0418e904c7e8}: [DhcpNameServer] 10.0.1.1
Tcpip\..\Interfaces\{e10f0252-5141-4e84-95af-3569028ed3d0}: [DhcpNameServer] 10.0.1.1
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.bing.com/search?FORM=INCOH1&PC=IC05&PTAG=ICO-fa0b4ca2
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?FORM=INCOH2&PC=IC05&PTAG=ICO-fa0b4ca2&q={searchTerms}
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?FORM=INCOH2&PC=IC05&PTAG=ICO-fa0b4ca2&q={searchTerms}
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?FORM=INCOH2&PC=IC05&PTAG=ICO-fa0b4ca2&q={searchTerms}
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?FORM=INCOH2&PC=IC05&PTAG=ICO-fa0b4ca2&q={searchTerms}
FireFox:
========
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2016-10-12] (Adobe Systems)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2015-12-18] ()
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-07-03] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-07-03] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-04-04] (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2016-10-12] (Adobe Systems)
FF Plugin HKU\S-1-5-21-3796937070-3348964198-3883336013-1000: @tools.google.com/Google Update;version=3 -> C:\Users\djbobbysteele\AppData\Local\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-27] (Google Inc.)
FF Plugin HKU\S-1-5-21-3796937070-3348964198-3883336013-1000: @tools.google.com/Google Update;version=9 -> C:\Users\djbobbysteele\AppData\Local\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-27] (Google Inc.)
Chrome:
=======
CHR Profile: C:\Users\djbobbysteele\AppData\Local\Google\Chrome\User Data\Default [2017-07-15]
CHR Extension: (Google Slides) - C:\Users\djbobbysteele\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-07-03]
CHR Extension: (Google Docs) - C:\Users\djbobbysteele\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-07-03]
CHR Extension: (Google Drive) - C:\Users\djbobbysteele\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-07-03]
CHR Extension: (YouTube) - C:\Users\djbobbysteele\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-07-03]
CHR Extension: (uTab) - C:\Users\djbobbysteele\AppData\Local\Google\Chrome\User Data\Default\Extensions\bpmmandcadflhnnaiclipadomfmdbjbp [2017-07-03]
CHR Extension: (Tidy Sidebar) - C:\Users\djbobbysteele\AppData\Local\Google\Chrome\User Data\Default\Extensions\dgmacifhhpefamjmolpipkijcofcmbgp [2017-07-03]
CHR Extension: (Adobe Acrobat) - C:\Users\djbobbysteele\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2017-07-03]
CHR Extension: (Hermes Tab) - C:\Users\djbobbysteele\AppData\Local\Google\Chrome\User Data\Default\Extensions\ehlceeijggpdgfcefmipcmdelickjgfg [2017-07-03]
CHR Extension: (Google Sheets) - C:\Users\djbobbysteele\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-07-03]
CHR Extension: (iCloud Bookmarks) - C:\Users\djbobbysteele\AppData\Local\Google\Chrome\User Data\Default\Extensions\fkepacicchenbjecpbpbclokcabebhah [2017-07-03]
CHR Extension: (GoToMeeting Pro Screensharing) - C:\Users\djbobbysteele\AppData\Local\Google\Chrome\User Data\Default\Extensions\gcgikpombjkodabhbdalkcdhmllafipp [2017-07-03]
CHR Extension: (Google Docs Offline) - C:\Users\djbobbysteele\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-07-03]
CHR Extension: (AdBlock) - C:\Users\djbobbysteele\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2017-07-03]
CHR Extension: (Cisco WebEx Extension) - C:\Users\djbobbysteele\AppData\Local\Google\Chrome\User Data\Default\Extensions\jlhmfgmfgeifomenelglieieghnjghma [2017-07-14]
CHR Extension: (Google Keep Chrome Extension) - C:\Users\djbobbysteele\AppData\Local\Google\Chrome\User Data\Default\Extensions\lpcaedmchfhocbbapmcbpinfpgnhiddi [2017-07-03]
CHR Extension: (Chrome Web Store Payments) - C:\Users\djbobbysteele\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-07-03]
CHR Extension: (Xodo PDF Viewer & Editor) - C:\Users\djbobbysteele\AppData\Local\Google\Chrome\User Data\Default\Extensions\okimpmfnmbjbaciaeaikdiecpobfomfh [2017-07-03]
CHR Extension: (Gmail) - C:\Users\djbobbysteele\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-07-03]
CHR Extension: (Chrome Media Router) - C:\Users\djbobbysteele\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-07-13]
CHR HKLM\...\Chrome\Extension: [bpmmandcadflhnnaiclipadomfmdbjbp] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM\...\Chrome\Extension: [ehlceeijggpdgfcefmipcmdelickjgfg] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [bpmmandcadflhnnaiclipadomfmdbjbp] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [ehlceeijggpdgfcefmipcmdelickjgfg] - hxxps://clients2.google.com/service/update2/crx
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AdobeUpdateService; C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [744640 2016-10-12] (Adobe Systems Incorporated)
R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2246256 2017-05-18] (Adobe Systems, Incorporated)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2016-03-02] (Apple Inc.)
R2 CyTpService; C:\Program Files\Cypress\TrackPad\CyTpService.exe [28160 2015-04-22] (Cypress Semiconductor Corporation)
S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-07-12] (Dropbox, Inc.)
S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-07-12] (Dropbox, Inc.)
R2 DbxSvc; C:\WINDOWS\system32\DbxSvc.exe [49992 2017-07-12] (Dropbox, Inc.)
R2 DNMC6000AudioDevMon; C:\Program Files (x86)\Denon DJ\DN-MC6000\AudioDevMon.exe [2382608 2015-06-01] (Denon DJ)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4470736 2017-05-09] (Malwarebytes)
R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [263264 2017-02-24] (Synaptics Incorporated)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [342264 2017-03-18] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [102816 2017-06-20] (Microsoft Corporation)
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 cykbfltrService; C:\WINDOWS\system32\DRIVERS\cykbfltr.sys [19968 2015-08-18] (Cypress Semiconductor, Inc.)
S3 cymfltrService; C:\WINDOWS\system32\DRIVERS\cymfltr.sys [102400 2015-08-18] (Cypress Semiconductor, Inc.)
S3 DNMC6000; C:\WINDOWS\system32\DRIVERS\DenonDJDNMC6000.sys [549648 2015-06-01] (Denon DJ)
R1 ESProtectionDriver; C:\WINDOWS\system32\drivers\mbae64.sys [77376 2017-06-27] ()
R2 MBAMChameleon; C:\WINDOWS\system32\drivers\MBAMChameleon.sys [188352 2017-07-03] (Malwarebytes)
R3 MBAMFarflt; C:\WINDOWS\system32\drivers\farflt.sys [101784 2017-07-14] (Malwarebytes)
R3 MBAMProtection; C:\WINDOWS\system32\drivers\mbam.sys [45472 2017-07-14] (Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [253856 2017-07-14] (Malwarebytes)
R3 MBAMWebProtection; C:\WINDOWS\system32\drivers\mwac.sys [93600 2017-07-15] (Malwarebytes)
R3 nvlddmkm; C:\WINDOWS\System32\DriverStore\FileRepository\nvdmwu.inf_amd64_26aa6356770b2e86\nvlddmkm.sys [13754936 2016-09-12] (NVIDIA Corporation)
S3 SDFRd; C:\WINDOWS\System32\drivers\SDFRd.sys [31128 2017-03-18] ()
U3 TrueSight; C:\Windows\System32\drivers\TrueSight.sys [28272 2017-07-14] ()
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [44632 2017-03-18] (Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\WdFilter.sys [294816 2017-03-18] (Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [121248 2017-03-18] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-07-15 16:33 - 2017-07-15 16:33 - 00000000 ____D C:\Users\djbobbysteele\Downloads\FRST-OlderVersion
2017-07-15 13:52 - 2017-07-15 13:52 - 00000000 ____D C:\Users\djbobbysteele\NeatUpdate
2017-07-15 13:51 - 2017-07-15 13:51 - 00000000 ____D C:\Program Files (x86)\GraphicsMagick-1.3.21-Q8
2017-07-15 09:45 - 2017-07-15 09:45 - 00130390 _____ C:\Users\djbobbysteele\Downloads\1499673918110.jpeg
2017-07-15 09:44 - 2017-07-15 09:44 - 00156147 _____ C:\Users\djbobbysteele\Downloads\1499673139148.jpeg
2017-07-15 09:43 - 2017-07-15 09:43 - 00180671 _____ C:\Users\djbobbysteele\Downloads\1499673683789.jpeg
2017-07-15 09:42 - 2017-07-15 09:42 - 00735792 _____ C:\Users\djbobbysteele\Downloads\1499673855452.jpeg
2017-07-15 09:42 - 2017-07-15 09:42 - 00197421 _____ C:\Users\djbobbysteele\Downloads\1499673590356.jpeg
2017-07-15 09:42 - 2017-07-15 09:42 - 00142199 _____ C:\Users\djbobbysteele\Downloads\1499673746977.jpeg
2017-07-14 08:04 - 2017-07-14 08:04 - 00012987 _____ C:\Users\djbobbysteele\Desktop\EVENTS 2011 TO PRESENT1.txt
2017-07-14 07:21 - 2017-07-14 07:21 - 00000000 ____D C:\Users\djbobbysteele\AppData\Local\CrashDumps
2017-07-14 07:20 - 2017-07-14 07:20 - 01663672 _____ (Malwarebytes) C:\Users\djbobbysteele\Downloads\JRT.exe
2017-07-14 07:01 - 2017-03-18 16:56 - 00105472 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthenum.sys
2017-07-14 07:01 - 2017-03-18 16:56 - 00085504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BTHUSB.SYS
2017-07-14 06:22 - 2017-07-14 06:22 - 00028272 _____ C:\WINDOWS\system32\Drivers\TrueSight.sys
2017-07-14 06:22 - 2017-07-14 06:22 - 00000000 ____D C:\ProgramData\RogueKiller
2017-07-14 06:21 - 2017-07-14 06:21 - 00000899 _____ C:\Users\Public\Desktop\RogueKiller.lnk
2017-07-14 06:21 - 2017-07-14 06:21 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RogueKiller
2017-07-14 06:21 - 2017-07-14 06:21 - 00000000 ____D C:\Program Files\RogueKiller
2017-07-14 06:18 - 2017-07-14 06:18 - 35612552 _____ (Adlice Software ) C:\Users\djbobbysteele\Desktop\RogueKiller_setup_ref3.exe
2017-07-13 19:19 - 2017-07-13 19:19 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox
2017-07-12 21:25 - 2017-07-12 21:25 - 00000000 ____D C:\Users\djbobbysteele\AppData\Local\Chromium
2017-07-12 19:57 - 2017-07-12 19:57 - 142267536 _____ C:\Users\djbobbysteele\Downloads\Tone Rios - Wanted (Club Rermix) (Clean).mp4
2017-07-12 19:57 - 2017-07-12 19:57 - 125833426 _____ C:\Users\djbobbysteele\Downloads\Mike Perry Feat. Casso - Inside the Lines (Galwaro Remix) (Clean).mp4
2017-07-12 19:56 - 2017-07-12 19:57 - 118717570 _____ C:\Users\djbobbysteele\Downloads\Clean Bandit Feat. Sean Paul & Anne Marie - Rockabye (Kavorka X TuneSquad Remix) (Clean).mp4
2017-07-12 19:52 - 2017-07-12 19:52 - 74509668 _____ C:\Users\djbobbysteele\Downloads\T-Mass & LZRD - Cash (Danny Diggz)(Clean).mp4
2017-07-12 19:51 - 2017-07-12 19:52 - 122401898 _____ C:\Users\djbobbysteele\Downloads\DJ Scene & Four Color Zack ft Mad Lion - Stomp (V.2 Remix)(Dirty).mp4
2017-07-12 19:50 - 2017-07-12 19:50 - 129079699 _____ C:\Users\djbobbysteele\Downloads\Turbotronic - One Time (Clubhunter Remix) (Clean).mp4
2017-07-12 19:49 - 2017-07-12 19:50 - 182933661 _____ C:\Users\djbobbysteele\Downloads\Turbotronic - Friday Night (Clubhunter) (Clean).mp4
2017-07-12 19:49 - 2017-07-12 19:50 - 175904079 _____ C:\Users\djbobbysteele\Downloads\Alex Gaudino - Destination Calabria (Justflow Remix) (Clean).mp4
2017-07-12 19:49 - 2017-07-12 19:49 - 84889476 _____ C:\Users\djbobbysteele\Downloads\Alan Walker ft. Gavin James - Tired (DOPEDROP Remix) (Clean).mp4
2017-07-12 19:43 - 2017-07-12 19:44 - 158804062 _____ C:\Users\djbobbysteele\Downloads\Crazy Frog - Axel F (STVW & Mountblaq Remix) (Dirty).mp4
2017-07-12 19:43 - 2017-07-12 19:44 - 112844933 _____ C:\Users\djbobbysteele\Downloads\A Billion Robots - One More Drink (Club Mix) (Clean).mp4
2017-07-12 19:41 - 2017-07-12 19:42 - 84672089 _____ C:\Users\djbobbysteele\Downloads\Martin Garrix & Dua Lipa - Scared To Be Lonely (Sammy Boyle Remix) (Clean).mp4
2017-07-12 19:41 - 2017-07-12 19:42 - 118236692 _____ C:\Users\djbobbysteele\Downloads\Luis Fonsi, Daddy Yankee Feat. Justin Bieber - Despacito (DROPSTARS Remix) (Clean).mp4
2017-07-12 19:40 - 2017-07-12 19:42 - 395931424 _____ C:\Users\djbobbysteele\Downloads\Clubhunter - Do Me (Turbotronic Mix) (Clean).mp4
2017-07-12 19:40 - 2017-07-12 19:42 - 158067706 _____ C:\Users\djbobbysteele\Downloads\Geo Da Silva, Sean Norvis with Dj Combo & Kizami - SummerTime (Fizo Faouez Remix) (Dirty).mp4
2017-07-12 19:40 - 2017-07-12 19:41 - 134472787 _____ C:\Users\djbobbysteele\Downloads\GoldFish feat. Diamond Thug - Deep Of The Night (dj 3b Remix) (Clean) .mp4
2017-07-12 19:36 - 2017-07-12 19:36 - 08704010 _____ C:\Users\djbobbysteele\Downloads\Detroit's Filthiest - Handprint.m4a
2017-07-12 19:32 - 2017-07-12 19:33 - 128578087 _____ C:\Users\djbobbysteele\Downloads\Zedd Feat. Matthew Koma - Spectrum Lyric Video Clean.mp4