Dale Ferrier
Posts: 34 +0
I see this momentary dos box popup and then it disappears before I can tell what it is doing. I can't determine what it is or where it came from.
Here are the farbar logs:
FRST.txt
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 25-06-2017 01
Ran by dferrier (administrator) on LT3 (26-06-2017 22:42:29)
Running from C:\Users\dferrier\Desktop\malware removal\farbar
Loaded Profiles: dferrier (Available Profiles: dferrier)
Platform: Windows 8.1 Pro (Update) (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
(Qualcomm Atheros) C:\Program Files (x86)\Bluetooth Suite\AdminService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(SafeNet Inc.) C:\Windows\System32\hasplms.exe
(Hi-Rez Studios) C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Insyde Software Corp.) C:\Program Files (x86)\Hotkey\Driver\x64\HKClipSvc.exe
(Nalpeiron Ltd.) C:\Windows\SysWOW64\nlssrv32.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(CLEVO CO.) C:\Program Files (x86)\Hotkey\HotkeyService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Qualcomm Atheros) C:\Program Files\Qualcomm Atheros\Network Manager\KillerService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(StarWind Software) C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
(TechSmith Corporation) C:\Program Files (x86)\Common Files\TechSmith Shared\Uploader\UploaderService.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(X-Rite Inc.) C:\Program Files (x86)\X-Rite\Devices\Services\xritedeviced.exe
(X-Rite Inc.) C:\Program Files (x86)\X-Rite\Devices\Services\ColorMunki\ColorMunkiDeviceService.exe
(Silicondust USA Inc) C:\Program Files\Silicondust\HDHomeRun\hdhomerun_wmc_service.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Logitech, Inc.) C:\Program Files\Logitech\SetPointP\SetPoint.exe
(Tordex) C:\Program Files\TrueLaunchBar\tlbHost.exe
() C:\Program Files (x86)\X-Rite\ColorMunki Photo\Tools\ColorMunki Photo Tray.exe
(Logitech, Inc.) C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.exe
(CLEVO CO.) C:\Program Files (x86)\Hotkey\HkeyTray.exe
(Wondershare) C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
() C:\Program Files\Qualcomm Atheros\Network Manager\NetworkManager.exe
(TechSmith Corporation) C:\Program Files (x86)\TechSmith\Snagit 12\Snagit32.exe
(JRT Studio LLC) C:\Program Files (x86)\JRT Studio\Cheetah Sync\CheetahSync.exe
(TechSmith Corporation) C:\Program Files (x86)\TechSmith\Snagit 12\SnagPriv.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(CLEVO CO.) C:\Program Files (x86)\Hotkey\hotkeyrtk.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(TechSmith Corporation) C:\Program Files (x86)\TechSmith\Snagit 12\TscHelp.exe
(TechSmith Corporation) C:\Program Files (x86)\TechSmith\Snagit 12\SnagitEditor.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe
(Microsoft(R) Corporation) C:\Program Files (x86)\Microsoft Money Plus\MNYCoreFiles\msmoney.exe
(CLEVO CO.) C:\Program Files (x86)\Hotkey\hkysound.exe
(CLEVO CO.) C:\Program Files (x86)\Hotkey\ComboKeyTray.exe
(Microsoft Corporation) C:\Windows\splwow64.exe
(Oracle Corporation) C:\Program Files\Java\jre1.8.0_131\bin\javaw.exe
(FileZilla Project) C:\Program Files (x86)\FileZilla FTP Client\filezilla.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\Adobe Installer.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe
() C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\CCXProcess.exe
(Node.js) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\libs\node.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\CCLibrary.exe
(Node.js) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\libs\node.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\HEX\Adobe CEF Helper.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
(RedFox) C:\Program Files (x86)\RedFox\AnyDVD\AnyDVDtray.exe
() C:\Program Files (x86)\RedFox\AnyDVD\ADvdDiscHlp64.exe
(FileZilla Project) C:\Program Files (x86)\FileZilla FTP Client\fzsftp.exe
(HandBrake Team) C:\Program Files\HandBrake\HandBrake.exe
(Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(FreeDownloadManager.org) C:\Program Files\FreeDownloadManager.ORG\Free Download Manager\fdm.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2585744 2015-01-16] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13764312 2014-10-07] (Realtek Semiconductor)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [508128 2016-07-01] (Adobe Systems Incorporated)
HKLM\...\Run: [EvtMgr6] => C:\Program Files\Logitech\SetPointP\SetPoint.exe [3113592 2015-08-25] (Logitech, Inc.)
HKLM\...\Run: [HDHRFling] => C:\Program Files (x86)\HDHRFling\HDHRFling.exe [5553664 2015-07-16] (HDHRFling.com)
HKLM\...\Run: [WindowsDefender] => "%ProgramFiles%\Windows Defender\MSASCuiL.exe"
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59240 2011-09-27] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2011-10-24] (Apple Inc.)
HKLM-x32\...\Run: [CBSpoolDaemon] => "C:\Program Files (x86)\ImagePrint\spool\mux\muxd.exe"
HKLM-x32\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2137744 2016-10-08] (Wondershare)
HKLM-x32\...\Run: [DelaypluginInstall] => C:\ProgramData\Wondershare\Video Converter Ultimate\DelayPluginI.exe
HKLM-x32\...\Run: [PowerDVD16Agent] => C:\Program Files (x86)\CyberLink\PowerDVD16\PowerDVD16Agent.exe [525352 2016-12-06] (CyberLink Corp.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2017-03-15] (Oracle Corporation)
HKLM-x32\...\Run: [Adobe Creative Cloud] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2406496 2017-06-04] (Adobe Systems Incorporated)
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
HKU\S-1-5-21-1717685655-2789524432-2867823966-1001\...\Run: [tlbHost] => C:\Program Files\TrueLaunchBar\tlbHost.exe [560312 2015-10-03] (Tordex)
HKU\S-1-5-21-1717685655-2789524432-2867823966-1001\...\Run: [Reasonable NoClone] => [X]
HKU\S-1-5-21-1717685655-2789524432-2867823966-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3042592 2017-06-01] (Valve Corporation)
HKU\S-1-5-21-1717685655-2789524432-2867823966-1001\...\Run: [Adobe Acrobat Synchronizer] => "C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe"
HKU\S-1-5-21-1717685655-2789524432-2867823966-1001\...\Run: [AnyDVD] => C:\Program Files (x86)\RedFox\AnyDVD\AnyDVDtray.exe [11116544 2017-06-20] (RedFox)
HKU\S-1-5-21-1717685655-2789524432-2867823966-1001\...\Run: [Outlook Google Calendar Sync] => C:\Users\dferrier\AppData\Local\Apps\2.0\L8RQ2D3X.G1A\7GRZB6CY.0DV\outl..tion_a30846ba3587a523_0002.0004_d79036ab77ef318b\OutlookGoogleCalendarSync.exe [851968 2017-05-10] (Paul Woolcock)
HKU\S-1-5-21-1717685655-2789524432-2867823966-1001\...\Run: [AlcoholAutomount] => C:\Program Files (x86)\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe [39376 2015-03-12] (Alcohol Soft Development Team)
HKU\S-1-5-21-1717685655-2789524432-2867823966-1001\...\RunOnce: [Uninstall C:\Users\dferrier\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\dferrier\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64"
HKU\S-1-5-21-1717685655-2789524432-2867823966-1001\...\MountPoints2: {e21ce5d1-97ae-11e6-827a-c03896838b48} - "I:\LaunchU3.exe" -a
HKU\S-1-5-18\...\Run: [Reasonable NoClone] => "C:\Program Files (x86)\Reasonable NoClone 2011 Enterprise\NoClone.exe" null /startup
ShellIconOverlayIdentifiers: [ AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2017-05-26] ()
ShellIconOverlayIdentifiers: [ AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2017-05-26] ()
ShellIconOverlayIdentifiers: [ AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2017-05-26] ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ColorMunki Gamma.lnk [2016-02-20]
ShortcutTarget: ColorMunki Gamma.lnk -> C:\Program Files (x86)\X-Rite\ColorMunki Photo\Gamma\CalibrationLoader.exe (LOGO Kommunikations- und Drucktechnik GmbH & Co. KG)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ColorMunkiPhotoTray.exe.lnk [2016-02-20]
ShortcutTarget: ColorMunkiPhotoTray.exe.lnk -> C:\Program Files (x86)\X-Rite\ColorMunki Photo\Tools\ColorMunki Photo Tray.exe ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Hotkey.lnk [2015-11-17]
ShortcutTarget: Hotkey.lnk -> C:\Program Files (x86)\Hotkey\HkeyTray.exe (CLEVO CO.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Install LastPass FF RunOnce.lnk [2016-03-09]
ShortcutTarget: Install LastPass FF RunOnce.lnk -> C:\Program Files (x86)\Common Files\lpuninstall.exe (LastPass)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Install LastPass IE RunOnce.lnk [2016-03-09]
ShortcutTarget: Install LastPass IE RunOnce.lnk -> C:\Program Files (x86)\Common Files\lpuninstall.exe (LastPass)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Killer Network Manager.lnk [2015-11-17]
ShortcutTarget: Killer Network Manager.lnk -> C:\Windows\Installer\{71ACF663-CC95-429F-8C5C-0A1DC4EE8E78}\NetworkManager.exe_130C27D738F34C89BDDF21BCFD74B56D.exe (Flexera Software LLC)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Snagit 12.lnk [2015-12-28]
ShortcutTarget: Snagit 12.lnk -> C:\Program Files (x86)\TechSmith\Snagit 12\Snagit32.exe (TechSmith Corporation)
Startup: C:\Users\dferrier\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Cheetah Sync.lnk [2015-12-19]
ShortcutTarget: Cheetah Sync.lnk -> C:\Users\dferrier\AppData\Roaming\Microsoft\Installer\{0600EEDA-11EA-4588-81F3-8F1D89FC83DE}\_57396F6D95A618E977BED0.exe ()
Startup: C:\Users\dferrier\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Password Safe.lnk [2016-05-03]
ShortcutTarget: Password Safe.lnk -> C:\Program Files (x86)\Password Safe\pwsafe.exe (SourceForge.net)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\..\Interfaces\{09CBD398-74E7-49A5-A567-432F6F45A3AD}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{736478E9-51BE-4D47-993A-F99B5F526DCB}: [NameServer] 8.8.8.8,8.8.4.4,192.168.25.1
Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <==== ATTENTION
BHO: No Name -> {13D67BB7-DB5F-48AA-884D-7A5D94168509} -> No File
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2017-05-26] (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_131\bin\ssv.dll [2017-04-24] (Oracle Corporation)
BHO: LastPass Vault -> {95D9ECF5-2A4D-4550-BE49-70D42F71296E} -> C:\Program Files (x86)\LastPass\LPToolbar_x64.dll [2016-03-09] (LastPass)
BHO: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll [2015-08-25] (Logitech, Inc.)
BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL [2017-05-26] (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_131\bin\jp2ssv.dll [2017-04-24] (Oracle Corporation)
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll [2017-05-26] (Microsoft Corporation)
BHO-x32: LastPass Vault -> {95D9ECF5-2A4D-4550-BE49-70D42F71296E} -> C:\Program Files (x86)\LastPass\LPToolbar.dll [2016-03-09] (LastPass)
BHO-x32: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll [2015-08-25] (Logitech, Inc.)
BHO-x32: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\Office16\GROOVEEX.DLL [2017-05-26] (Microsoft Corporation)
Toolbar: HKLM - LastPass Toolbar - {9f6b5cc3-5c7b-4b5c-97af-19dec1e380e5} - C:\Program Files (x86)\LastPass\LPToolbar_x64.dll [2016-03-09] (LastPass)
Toolbar: HKLM-x32 - LastPass Toolbar - {9f6b5cc3-5c7b-4b5c-97af-19dec1e380e5} - C:\Program Files (x86)\LastPass\LPToolbar.dll [2016-03-09] (LastPass)
DPF: HKLM-x32 {FD3BEB0C-AB43-4253-9146-C371D48FBE0D} hxxp://192.168.25.250/web.cab
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-05-26] (Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-05-26] (Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-05-26] (Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-05-26] (Microsoft Corporation)
Handler: WSWSVCUchrome - No CLSID Value
FireFox:
========
FF ProfilePath: C:\Users\dferrier\AppData\Roaming\Mozilla\Firefox\Profiles\gs7v3iqm.default [2017-06-26]
FF Extension: (Free Download Manager extension) - C:\Users\dferrier\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\fdm_ffext@freedownloadmanager.org [2016-12-13]
FF Extension: (DownThemAll!) - C:\Users\dferrier\AppData\Roaming\Mozilla\Firefox\Profiles\gs7v3iqm.default\Extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi [2016-12-13]
FF HKLM-x32\...\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt
FF Extension: (Logitech SetPoint) - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt [2016-05-30] [not signed]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_26_0_0_131.dll [2017-06-20] ()
FF Plugin: @java.com/DTPlugin,version=11.131.2 -> C:\Program Files\Java\jre1.8.0_131\bin\dtplugin\npDeployJava1.dll [2017-04-24] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.131.2 -> C:\Program Files\Java\jre1.8.0_131\bin\plugin2\npjp2.dll [2017-04-24] (Oracle Corporation)
FF Plugin: @lastpass.com/NPLastPass -> C:\Program Files (x86)\LastPass\nplastpass64.dll [2016-03-09] (LastPass)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2017-06-04] (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_26_0_0_131.dll [2017-06-20] ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2014-03-20] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2014-03-20] (Intel Corporation)
FF Plugin-x32: @lastpass.com/NPLastPass -> C:\Program Files (x86)\LastPass\nplastpass64.dll [2016-03-09] (LastPass)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2017-05-26] (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2017-05-26] (Microsoft Corporation)
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-04-04] (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2017-06-04] (Adobe Systems)
FF Plugin-x32: adobe.com/AdobeExManDetect -> C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\npAdobeExManDetectX86.dll [No File]
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AdobeUpdateService; C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [814688 2017-06-04] (Adobe Systems Incorporated)
R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2246256 2017-05-18] (Adobe Systems, Incorporated)
R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [309376 2014-11-26] (Qualcomm Atheros) [File not signed]
S2 AxAutoMntSrv; C:\Program Files (x86)\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe [39376 2015-03-12] (Alcohol Soft Development Team)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [3971264 2017-05-14] (Microsoft Corporation)
R2 ColorMunkiService; C:\Program Files (x86)\X-Rite\Devices\Services\ColorMunki\ColorMunkiDeviceService.exe [147968 2009-10-21] (X-Rite Inc.) [File not signed]
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1148560 2015-01-16] (NVIDIA Corporation)
R2 hasplms; C:\Windows\system32\hasplms.exe [4621632 2015-04-14] (SafeNet Inc.)
S4 HDHomeRun RECORD; C:\Program Files\Silicondust\HDHomeRun\hdhomerun_record.exe [255936 2016-11-19] ()
R2 HDHomeRun WMC Service; C:\Program Files\Silicondust\HDHomeRun\hdhomerun_wmc_service.exe [33216 2016-11-19] (Silicondust USA Inc)
U2 HiPatchService; C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe [9728 2016-03-14] (Hi-Rez Studios) [File not signed]
R2 HKClipSvc; C:\Program Files (x86)\Hotkey\Driver\x64\HKClipSvc.exe [246272 2014-10-29] (Insyde Software Corp.) [File not signed]
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [328296 2014-10-29] (Intel Corporation)
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [887232 2014-01-31] (Intel(R) Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [154584 2014-03-20] (Intel Corporation)
S2 Net Driver HPZ12; C:\Windows\System32\HPZinw12.dll [50688 2014-11-17] (Hewlett-Packard) [File not signed]
R2 nlsX86cc; C:\Windows\SysWOW64\nlssrv32.exe [66560 2012-03-28] (Nalpeiron Ltd.) [File not signed]
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1706128 2015-01-16] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [21833360 2015-01-16] (NVIDIA Corporation)
S2 Pml Driver HPZ12; C:\Windows\System32\HPZipm12.dll [66048 2014-11-17] (Hewlett-Packard) [File not signed]
R2 PowerBiosServer; C:\Program Files (x86)\Hotkey\HotkeyService.exe [24064 2014-12-05] (CLEVO CO.) [File not signed]
R2 Qualcomm Atheros Killer Service V2; C:\Program Files\Qualcomm Atheros\Network Manager\KillerService.exe [386560 2014-12-11] (Qualcomm Atheros) [File not signed]
R2 StarWindServiceAE; C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [370688 2009-12-23] (StarWind Software) [File not signed]
R2 TechSmith Uploader Service; C:\Program Files (x86)\Common Files\TechSmith Shared\Uploader\UploaderService.exe [3408384 2015-01-26] (TechSmith Corporation) [File not signed]
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [361824 2017-01-12] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [119872 2017-01-12] (Microsoft Corporation)
R2 xritedeviced; C:\Program Files (x86)\X-Rite\Devices\Services\xritedeviced.exe [130048 2009-10-21] (X-Rite Inc.) [File not signed]
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 AirplaneModeHid; C:\Windows\system32\DRIVERS\AirplaneModeHid.sys [26888 2013-06-26] (Insyde Corporation)
S3 akshhl; C:\Windows\system32\DRIVERS\akshhl.sys [63944 2015-04-14] (SafeNet Inc.)
R3 AnyDVD; C:\Windows\System32\Drivers\AnyDVD.sys [154448 2016-07-11] (RedFox)
R3 AnyDVD; C:\Windows\SysWOW64\Drivers\AnyDVD.sys [154448 2016-07-11] (RedFox)
U3 axscsidrv; C:\Windows\System32\Drivers\axscsidrv.sys [304296 2017-05-10] (Alcohol Soft Development Team)
R1 BfLwf; C:\Windows\system32\DRIVERS\bwcW8x64.sys [98992 2014-11-19] (Qualcomm Atheros, Inc.)
S3 colormunki; C:\Windows\System32\Drivers\colormunki_x64.sys [51600 2007-10-02] (Thesycon GmbH, Germany)
S3 FTDIBUS; C:\Windows\system32\drivers\ftdibus.sys [119680 2017-03-08] (Future Technology Devices International Ltd.)
S3 FTSER2K; C:\Windows\system32\drivers\ftser2k.sys [89792 2017-03-08] (Future Technology Devices International Ltd.)
R3 HKKbdFltr; C:\Windows\system32\DRIVERS\HKKbdFltr.sys [41160 2014-10-29] (Insyde Software Corp.)
R3 HKMouFltr; C:\Windows\system32\DRIVERS\HKMouFltr.sys [40136 2014-10-29] (Insyde Software Corp.)
S3 kmloop; C:\Windows\system32\DRIVERS\loop.sys [15360 2013-08-22] (Microsoft Corporation)
R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [118272 2014-03-20] (Intel Corporation)
R1 MpKslfedbde4a; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{69A62411-B280-4E14-8837-A94D90F6D167}\MpKslfedbde4a.sys [44928 2017-06-06] (Microsoft Corporation)
S3 NETwNe64; C:\Windows\system32\DRIVERS\NETwew02.sys [4649440 2013-06-18] (Intel Corporation)
R1 npcap; C:\Windows\system32\DRIVERS\npcap.sys [71888 2016-12-15] (Insecure.Com LLC.)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19600 2015-01-16] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [38032 2014-11-22] (NVIDIA Corporation)
R3 PdiPorts; C:\Windows\System32\drivers\PdiPorts.sys [19248 2006-11-16] (Portrait Displays, Inc.)
R0 PxHlpa64; C:\Windows\System32\Drivers\PxHlpa64.sys [56336 2012-06-22] (Corel Corporation)
R3 Qcamain; C:\Windows\system32\DRIVERS\Qcamainx64.sys [2286080 2014-11-26] (Qualcomm Atheros, Inc.)
R3 RTSPER; C:\Windows\system32\DRIVERS\RtsPer.sys [502488 2014-05-07] (Realsil Semiconductor Corporation)
R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [31472 2014-01-09] (Synaptics Incorporated)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [394296 2016-09-29] (Duplex Secure Ltd.)
R1 SvThANSP; C:\Program Files (x86)\Hotkey\SvThANSP.sys [15224 2013-10-11] (Windows (R) Win 7 DDK provider)
U5 TMUSB; C:\Windows\System32\DRIVERS\TMUSB64.SYS [63096 2015-05-24] (Seiko Epson Corporation)
R3 TotRec8; C:\Windows\system32\drivers\TotRec8.sys [121424 2010-10-14] (High Criteria inc.)
S1 VBoxNetAdp; C:\Windows\system32\DRIVERS\VBoxNetAdp6.sys [131144 2017-04-28] (Oracle Corporation)
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [46600 2017-02-10] (Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [274776 2017-01-12] (Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [117592 2017-01-12] (Microsoft Corporation)
S3 xb1usb; C:\Windows\System32\drivers\xb1usb.sys [34016 2014-05-27] (Microsoft Corporation)
R2 {41E8078B-96D9-42DC-8789-A1CF102CD880}; C:\Program Files (x86)\CyberLink\PowerDVD16\Common\NavFilter\000.fcl [38168 2016-12-02] (CyberLink Corp.)
S3 akshasp; \SystemRoot\system32\DRIVERS\akshasp.sys [X]
S3 aksusb; \SystemRoot\System32\drivers\aksusb.sys [X]
U4 npcap_wifi; no ImagePath
S3 VMSMP; \SystemRoot\system32\DRIVERS\vmswitch.sys [X]
S3 xhunter1; \??\C:\Windows\xhunter1.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-06-26 22:24 - 2017-06-26 22:24 - 00000000 ____D C:\Users\dferrier\Documents\Larian Studios
2017-06-26 18:54 - 2017-06-26 18:54 - 00000000 ____D C:\Users\dferrier\AppData\Local\assistant
2017-06-26 09:40 - 2017-06-26 09:40 - 00000000 ____D C:\Users\dferrier\AppData\Local\Tempzxpsignfa540e18037a3bb7
2017-06-26 09:24 - 2017-06-26 09:24 - 00000000 ____D C:\Users\dferrier\AppData\Local\Tempzxpsign578bcde46b2f4cc1
2017-06-26 09:24 - 2017-06-26 09:24 - 00000000 ____D C:\Users\dferrier\AppData\Local\Tempzxpsign1357166ce04a90bf
2017-06-26 09:23 - 2017-06-26 09:23 - 00000000 ____D C:\Users\dferrier\AppData\Local\Tempzxpsigndb9fe1e7f1504d62
2017-06-26 09:23 - 2017-06-26 09:23 - 00000000 ____D C:\Users\dferrier\AppData\Local\Tempzxpsign96c0381969e20bb1
2017-06-26 09:23 - 2017-06-26 09:23 - 00000000 ____D C:\Users\dferrier\AppData\Local\Tempzxpsign651287fc3c066038
2017-06-25 20:48 - 2017-06-25 20:48 - 00000222 _____ C:\Users\dferrier\Desktop\Divinity Original Sin Enhanced Edition.url
2017-06-25 20:37 - 2017-06-25 20:37 - 00000222 _____ C:\Users\dferrier\Desktop\NieRAutomata.url
2017-06-25 15:23 - 2017-06-25 15:23 - 00000000 ____D C:\Users\dferrier\AppData\Local\Tempzxpsign25d1fc99f9022722
2017-06-25 15:22 - 2017-06-25 15:22 - 00000000 ____D C:\Users\dferrier\AppData\Local\Tempzxpsign286af6eabb30d5eb
2017-06-25 15:21 - 2017-06-25 15:21 - 00000000 ____D C:\Users\dferrier\AppData\Local\Tempzxpsignba4c71fe9b4f06e9
2017-06-25 15:21 - 2017-06-25 15:21 - 00000000 ____D C:\Users\dferrier\AppData\Local\Tempzxpsign5ee866bb11f640f3
2017-06-25 15:21 - 2017-06-25 15:21 - 00000000 ____D C:\Users\dferrier\AppData\Local\Tempzxpsign0dd32c54eab861a7
2017-06-25 14:58 - 2017-06-25 14:58 - 00000000 ____D C:\Users\dferrier\AppData\Local\Tempzxpsign364f1b7a0d04b681
2017-06-25 14:57 - 2017-06-25 14:57 - 00000000 ____D C:\Users\dferrier\AppData\Local\Tempzxpsign6ea42baa4cd384b0
2017-06-25 14:56 - 2017-06-25 14:56 - 00000000 ____D C:\Users\dferrier\AppData\Local\Tempzxpsign4fb6f498e6e2adb4
2017-06-25 14:56 - 2017-06-25 14:56 - 00000000 ____D C:\Users\dferrier\AppData\Local\Tempzxpsign1177dc734c3853e3
2017-06-25 14:51 - 2017-06-25 14:51 - 00001909 _____ C:\Users\Public\Desktop\Agisoft PhotoScan Standard (64 bit).lnk
2017-06-25 14:51 - 2017-06-25 14:51 - 00000000 ____D C:\Users\dferrier\AppData\Roaming\Agisoft
2017-06-25 14:51 - 2017-06-25 14:51 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Agisoft
2017-06-25 14:51 - 2017-06-25 14:51 - 00000000 ____D C:\Program Files\Agisoft
2017-06-25 14:21 - 2017-06-25 14:23 - 00000000 ____D C:\Users\dferrier\Documents\reo speedwagon tickets
2017-06-25 14:21 - 2017-06-25 14:21 - 00000000 ____D C:\Users\dferrier\Documents\New folder
2017-06-24 18:28 - 2017-06-24 18:28 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CraftWare 1.14
2017-06-24 18:28 - 2017-06-24 18:28 - 00000000 ____D C:\Program Files (x86)\CraftWare
2017-06-24 17:36 - 2017-06-24 17:36 - 00000000 ____D C:\Users\dferrier\AppData\Roaming\cura
2017-06-24 17:35 - 2017-06-24 17:36 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cura
2017-06-24 17:35 - 2017-06-24 17:35 - 00000000 ____D C:\Program Files\Cura 2.6
2017-06-23 17:50 - 2017-06-23 17:50 - 00000146 _____ C:\Users\dferrier\Desktop\Sound - Shortcut.lnk
2017-06-19 22:50 - 2017-06-24 17:36 - 00000000 ____D C:\Users\dferrier\AppData\Local\cura
2017-06-19 22:45 - 2017-06-24 17:34 - 00000000 ____D C:\Program Files\Cura 2.5
2017-06-19 14:03 - 2017-06-19 14:03 - 00000000 ____D C:\Users\dferrier\AppData\Local\Tempzxpsignb0ff42b22ad0a776
2017-06-19 14:03 - 2017-06-19 14:03 - 00000000 ____D C:\Users\dferrier\AppData\Local\Tempzxpsign3325c6ac85272be3
2017-06-19 13:23 - 2017-06-19 13:48 - 00000000 ____D C:\Users\dferrier\AppData\Roaming\FreeCAD
2017-06-19 13:23 - 2017-06-19 13:23 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FreeCAD 0.16
2017-06-19 13:18 - 2017-06-19 13:22 - 00000000 ____D C:\Program Files\FreeCAD 0.16
2017-06-19 12:43 - 2017-06-19 12:43 - 00001056 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CC 2017.lnk
2017-06-19 12:14 - 2017-06-19 12:14 - 00001000 _____ C:\Users\dferrier\Desktop\Adobe Lightroom.lnk
2017-06-19 12:14 - 2017-06-19 12:14 - 00001000 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Lightroom.lnk
2017-06-19 11:52 - 2017-06-19 11:52 - 00001245 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Creative Cloud.lnk
2017-06-19 11:52 - 2017-06-19 11:52 - 00001233 _____ C:\Users\Public\Desktop\Adobe Creative Cloud.lnk
2017-06-18 22:03 - 2017-06-18 22:03 - 00002205 _____ C:\Users\dferrier\AppData\Local\recently-used.xbel
2017-06-17 12:13 - 2017-06-17 12:13 - 07075640 _____ (Tim Kosse) C:\Users\dferrier\Downloads\FileZilla_3.26.2_win64-setup.exe
2017-06-16 10:37 - 2017-06-16 10:37 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mp3tag
2017-06-10 12:19 - 2017-06-10 12:19 - 1153990656 _____ C:\Users\dferrier\Downloads\The Quiet Man (1952) -.mkv
2017-06-10 12:18 - 2017-06-01 12:36 - 201645046 _____ C:\Users\dferrier\Downloads\The Making of The Quiet Man-featurette.mkv
2017-06-10 12:12 - 2017-06-10 12:13 - 07070840 _____ (Tim Kosse) C:\Users\dferrier\Downloads\FileZilla_3.26.1_win64-setup.exe
2017-06-09 18:18 - 2017-06-13 09:33 - 00000000 ____D C:\Users\dferrier\AppData\Roaming\MuseScore
2017-06-09 18:18 - 2017-06-09 18:18 - 00001069 _____ C:\Users\dferrier\Desktop\MuseScore 2.lnk
2017-06-09 18:18 - 2017-06-09 18:18 - 00000000 ____D C:\Users\dferrier\Documents\MuseScore2
2017-06-09 18:18 - 2017-06-09 18:18 - 00000000 ____D C:\Users\dferrier\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MuseScore 2
2017-06-09 18:18 - 2017-06-09 18:18 - 00000000 ____D C:\Users\dferrier\AppData\Local\MuseScore
2017-06-09 18:18 - 2017-06-09 18:18 - 00000000 ____D C:\Program Files (x86)\MuseScore 2
2017-06-05 21:32 - 2017-06-07 23:12 - 00000000 ____D C:\Users\dferrier\AppData\Roaming\Ultra Fractal 5
2017-06-05 21:32 - 2017-06-05 21:32 - 00001971 _____ C:\Users\dferrier\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ultra Fractal Server 5.04.lnk
2017-06-05 21:32 - 2017-06-05 21:32 - 00001955 _____ C:\Users\dferrier\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ultra Fractal 5.04.lnk
2017-06-05 21:32 - 2017-06-05 21:32 - 00001925 _____ C:\Users\dferrier\Desktop\Ultra Fractal 5.04.lnk
2017-06-05 21:32 - 2017-06-05 21:32 - 00000000 ____D C:\Users\dferrier\Documents\Ultra Fractal 5
2017-06-05 21:32 - 2017-06-05 21:32 - 00000000 ____D C:\Program Files (x86)\Ultra Fractal 5
2017-06-02 22:41 - 2017-06-02 22:41 - 00001113 _____ C:\Users\dferrier\Desktop\Acrosync.lnk
2017-06-02 22:41 - 2017-06-02 22:41 - 00000000 ____D C:\Users\dferrier\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Acrosync
2017-06-02 22:41 - 2017-06-02 22:41 - 00000000 ____D C:\Users\dferrier\AppData\Local\Acrosync
2017-06-01 12:51 - 2017-06-01 12:51 - 106528394 _____ C:\Users\dferrier\Downloads\plexmediaserver-1.7.2.3878-8088811b8.x86_64.rpm
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-06-26 22:42 - 2016-05-26 20:05 - 00000000 ____D C:\FRST
2017-06-26 22:41 - 2017-01-25 22:20 - 00000000 ____D C:\Users\dferrier\Desktop\malware removal
2017-06-26 22:35 - 2016-11-20 20:09 - 00000000 ____D C:\Users\dferrier\AppData\LocalLow\Mozilla
2017-06-26 22:27 - 2015-11-17 15:50 - 00025600 _____ C:\Users\dferrier\Documents\Joebob.xlsx
2017-06-26 22:27 - 2015-11-17 13:49 - 00000000 ____D C:\Users\dferrier\Documents\email
2017-06-26 22:25 - 2015-12-28 09:13 - 00000000 ____D C:\Users\dferrier\AppData\Local\CrashDumps
2017-06-26 22:24 - 2015-11-26 22:55 - 00000000 ____D C:\Program Files (x86)\Steam
2017-06-26 21:13 - 2016-12-13 21:29 - 00000000 ____D C:\Users\dferrier\AppData\Local\Free Download Manager
2017-06-26 14:07 - 2015-11-21 09:34 - 00000000 ____D C:\Users\dferrier\AppData\Local\Adobe
2017-06-26 12:59 - 2017-04-21 23:23 - 00000000 ____D C:\Users\dferrier\Documents\3d printing
2017-06-26 12:30 - 2016-05-26 17:06 - 00000000 __SHD C:\Users\dferrier\AppData\LocalLow\EmieUserList
2017-06-26 12:30 - 2016-05-26 17:05 - 00000000 __SHD C:\Users\dferrier\AppData\LocalLow\EmieSiteList
2017-06-26 12:30 - 2016-05-26 17:05 - 00000000 __SHD C:\Users\dferrier\AppData\Local\EmieUserList
2017-06-26 12:30 - 2016-05-26 17:05 - 00000000 __SHD C:\Users\dferrier\AppData\Local\EmieSiteList
2017-06-25 23:57 - 2015-11-17 12:52 - 00003600 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1717685655-2789524432-2867823966-1001
2017-06-25 22:05 - 2015-11-17 14:00 - 00000000 ____D C:\Users\dferrier\Documents\My Games
2017-06-25 20:48 - 2016-03-27 21:46 - 00000000 ____D C:\Users\dferrier\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2017-06-25 14:52 - 2013-09-10 08:49 - 00867660 _____ C:\Windows\system32\PerfStringBackup.INI
2017-06-25 14:52 - 2013-08-22 08:36 - 00000000 ____D C:\Windows\Inf
2017-06-24 18:29 - 2015-11-17 23:43 - 00000000 ____D C:\ProgramData\Package Cache
2017-06-24 18:29 - 2015-11-17 13:26 - 00000000 ____D C:\Program Files\DIFX
2017-06-24 01:44 - 2015-11-20 12:02 - 00000000 ____D C:\Users\dferrier\AppData\Roaming\HandBrake
2017-06-23 23:30 - 2015-12-29 16:42 - 00000000 ____D C:\Users\dferrier\AppData\Local\Battle.net
2017-06-23 22:39 - 2016-03-15 15:27 - 00000000 ____D C:\Program Files (x86)\StarCraft II
2017-06-23 22:36 - 2015-12-29 16:41 - 00000000 ____D C:\Program Files (x86)\Battle.net
2017-06-23 18:21 - 2016-06-23 17:42 - 00000000 ____D C:\Program Files (x86)\Overwatch Test
2017-06-23 17:51 - 2015-12-31 11:36 - 00000000 ____D C:\Users\dferrier\AppData\Roaming\MusicBee
2017-06-23 17:41 - 2016-03-15 15:27 - 00000000 ____D C:\Users\dferrier\Documents\StarCraft II
2017-06-23 17:36 - 2016-04-29 14:42 - 00000000 ____D C:\Program Files (x86)\Overwatch
2017-06-23 07:08 - 2016-09-18 19:04 - 00000600 _____ C:\Users\dferrier\AppData\Local\PUTTY.RND
2017-06-23 07:04 - 2015-12-04 08:54 - 00000000 ____D C:\Users\dferrier\AppData\Roaming\vlc
2017-06-22 17:44 - 2015-12-26 17:06 - 00000000 ____D C:\Users\dferrier\Documents\photography
2017-06-22 06:40 - 2016-05-26 17:07 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2017-06-22 06:02 - 2015-11-17 13:46 - 00000000 ____D C:\Users\dferrier\Documents\Bible
2017-06-22 00:05 - 2015-11-17 12:39 - 00000000 ____D C:\Users\dferrier\AppData\Local\Packages
2017-06-21 22:03 - 2016-12-06 11:41 - 00001114 _____ C:\Users\Public\Desktop\AnyDVD.lnk
2017-06-21 12:32 - 2015-11-17 13:49 - 00000000 ____D C:\Users\dferrier\Documents\bills
2017-06-20 22:11 - 2016-05-30 22:40 - 00018960 _____ (Logitech, Inc.) C:\Windows\system32\Drivers\LNonPnP.sys
2017-06-20 12:34 - 2015-11-17 12:39 - 00000000 ____D C:\Users\dferrier\AppData\Roaming\Adobe
2017-06-20 07:30 - 2013-08-22 10:36 - 00000000 ____D C:\Windows\SysWOW64\Macromed
2017-06-20 07:30 - 2013-08-22 10:36 - 00000000 ____D C:\Windows\system32\Macromed
2017-06-19 13:59 - 2016-03-01 00:36 - 00000000 ___RD C:\Users\dferrier\Creative Cloud Files
2017-06-19 13:59 - 2015-11-17 12:39 - 00000000 ____D C:\Users\dferrier
2017-06-19 13:57 - 2016-03-13 19:58 - 00000000 __RHD C:\Users\dferrier\lizzylizard@writeme.com Creative Cloud Files
2017-06-19 12:43 - 2015-11-17 13:46 - 00000000 ____D C:\Users\dferrier\Documents\Adobe
2017-06-19 12:40 - 2015-11-21 09:39 - 00000000 ____D C:\Program Files\Common Files\Adobe
2017-06-19 12:36 - 2015-11-21 09:42 - 00000000 ____D C:\Program Files\Adobe
2017-06-19 12:34 - 2015-11-21 09:34 - 00000000 ____D C:\ProgramData\Adobe
2017-06-19 05:58 - 2017-05-18 08:52 - 00000000 ____D C:\Users\dferrier\.gimp-2.8
2017-06-17 12:13 - 2016-11-30 23:12 - 00000000 ____D C:\Users\dferrier\AppData\Roaming\FileZilla
2017-06-16 10:49 - 2016-03-03 00:35 - 00000000 ____D C:\Users\dferrier\AppData\Roaming\Mp3tag
2017-06-16 10:37 - 2015-12-31 12:06 - 00000995 _____ C:\Users\Public\Desktop\Mp3tag.lnk
2017-06-16 10:37 - 2015-12-31 12:06 - 00000000 ____D C:\Program Files (x86)\Mp3tag
2017-06-15 09:36 - 2013-08-22 10:36 - 00000000 ____D C:\Windows\AppReadiness
2017-06-14 13:40 - 2016-01-09 16:41 - 00000000 ____D C:\Users\dferrier\Documents\atkins
2017-06-13 21:02 - 2013-08-22 10:20 - 00000000 ____D C:\Windows\CbsTemp
2017-06-13 13:57 - 2017-05-19 10:54 - 00000000 ____D C:\Users\dferrier\AppData\Local\gtk-2.0
2017-06-10 12:13 - 2016-11-30 23:12 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileZilla FTP Client
2017-06-10 12:13 - 2016-11-30 23:12 - 00000000 ____D C:\Program Files (x86)\FileZilla FTP Client
2017-06-04 22:56 - 2016-02-27 12:34 - 00000000 ____D C:\Users\dferrier\AppData\Local\Logos
2017-06-04 22:52 - 2016-02-27 13:24 - 00002291 _____ C:\Users\dferrier\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Logos Bible Software.lnk
2017-06-04 22:52 - 2016-02-27 13:24 - 00002283 _____ C:\Users\dferrier\Desktop\Logos Bible Software.lnk
2017-06-04 22:43 - 2016-02-27 14:08 - 00000000 ____D C:\Users\dferrier\Documents\Logos Log Files
2017-06-02 22:48 - 2013-08-22 10:36 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2017-06-02 22:46 - 2015-11-17 17:00 - 00000000 ____D C:\Program Files (x86)\Microsoft Office
2017-06-02 22:34 - 2015-12-19 14:49 - 00000000 ____D C:\Users\dferrier\Documents\JRT Studio
2017-06-02 22:31 - 2015-12-16 12:01 - 00000091 _____ C:\HaxLogs.txt
2017-06-02 22:30 - 2013-08-22 09:45 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2017-06-02 14:33 - 2017-04-01 09:23 - 00000000 ____D C:\Users\dferrier\Documents\solar power
2017-06-02 14:33 - 2016-07-26 16:54 - 00000000 ____D C:\Users\dferrier\Documents\Ham Radio
2017-06-02 09:20 - 2013-08-22 10:36 - 00000000 ____D C:\Windows\system32\FxsTmp
2017-06-01 07:58 - 2016-03-07 11:29 - 00004848 _____ C:\Users\dferrier\Documents\ax_files.xml
2017-05-27 14:01 - 2017-05-26 14:33 - 00004476 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
==================== Files in the root of some directories =======
2016-12-03 13:46 - 2016-12-03 13:47 - 0009272 _____ () C:\Program Files (x86)\DeviceManage Setup Log.txt
2016-03-09 18:50 - 2016-03-09 18:51 - 21572120 _____ (LastPass) C:\Program Files (x86)\Common Files\lpuninstall.exe
2015-11-21 22:12 - 2008-03-19 18:50 - 0097280 _____ () C:\Program Files (x86)\Common Files\pcsbClean.exe
2015-11-21 22:12 - 2008-03-06 22:31 - 0134656 _____ () C:\Program Files (x86)\Common Files\PCSBoff.exe
2016-03-01 15:53 - 2016-09-30 08:51 - 0000033 _____ () C:\Users\dferrier\AppData\Roaming\AdobeWLCMCache.dat
2015-08-05 10:51 - 2015-08-05 10:51 - 0000000 _____ () C:\Users\dferrier\AppData\Roaming\bdopatchtime.txt
2015-11-17 21:20 - 2017-02-15 12:37 - 0002491 _____ () C:\Users\dferrier\AppData\Roaming\LT3.MTBF.txt
2017-03-07 21:19 - 2017-03-07 21:19 - 0000600 _____ () C:\Users\dferrier\AppData\Roaming\PUTTY.RND
2017-05-19 09:38 - 2017-05-19 09:38 - 0000000 ____H () C:\Users\dferrier\AppData\Local\.urbackupclientgui_startonce
2015-11-17 22:04 - 2017-05-05 21:55 - 0007680 _____ () C:\Users\dferrier\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-11-17 15:08 - 2015-11-17 15:08 - 0000000 _____ () C:\Users\dferrier\AppData\Local\Driver_11ACPresent.flag
2016-09-18 19:04 - 2017-06-23 07:08 - 0000600 _____ () C:\Users\dferrier\AppData\Local\PUTTY.RND
2017-06-18 22:03 - 2017-06-18 22:03 - 0002205 _____ () C:\Users\dferrier\AppData\Local\recently-used.xbel
2015-12-26 19:07 - 2015-09-25 04:21 - 0016800 _____ () C:\Users\dferrier\AppData\Local\Z@!-5946ba91-ed5f-41a8-8801-12c6dbd9f3de.tmp
2015-12-26 19:07 - 2015-09-25 04:21 - 0015776 _____ () C:\Users\dferrier\AppData\Local\Z@S!-83152ba7-24c1-4572-9f40-f7b7dcf1c59d.tmp
2016-12-29 14:33 - 2017-01-02 21:55 - 0000143 _____ () C:\Users\dferrier\AppData\Local\zenmap.exe.log
2016-12-08 08:50 - 2017-05-10 21:15 - 0000085 ___SH () C:\ProgramData\.zreglib
2015-11-21 14:48 - 2015-11-21 14:48 - 0000115 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc
2015-11-21 14:06 - 2015-11-21 14:37 - 0000238 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.351.64.bc
2016-06-27 00:41 - 2016-06-27 00:41 - 0000090 _____ () C:\ProgramData\Temp.log
Some files in TEMP:
====================
2017-04-10 12:15 - 2017-04-10 12:15 - 10468271 _____ () C:\Users\dferrier\AppData\Local\Temp\handbrake-setup.exe
2016-08-25 16:43 - 2016-08-25 16:43 - 15301888 _____ (Microsoft Corporation) C:\Users\dferrier\AppData\Local\Temp\vc_redist_2015.x64.exe
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2017-06-18 02:48
==================== End of FRST.txt ============================
Here are the farbar logs:
FRST.txt
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 25-06-2017 01
Ran by dferrier (administrator) on LT3 (26-06-2017 22:42:29)
Running from C:\Users\dferrier\Desktop\malware removal\farbar
Loaded Profiles: dferrier (Available Profiles: dferrier)
Platform: Windows 8.1 Pro (Update) (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
(Qualcomm Atheros) C:\Program Files (x86)\Bluetooth Suite\AdminService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(SafeNet Inc.) C:\Windows\System32\hasplms.exe
(Hi-Rez Studios) C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Insyde Software Corp.) C:\Program Files (x86)\Hotkey\Driver\x64\HKClipSvc.exe
(Nalpeiron Ltd.) C:\Windows\SysWOW64\nlssrv32.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(CLEVO CO.) C:\Program Files (x86)\Hotkey\HotkeyService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Qualcomm Atheros) C:\Program Files\Qualcomm Atheros\Network Manager\KillerService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(StarWind Software) C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
(TechSmith Corporation) C:\Program Files (x86)\Common Files\TechSmith Shared\Uploader\UploaderService.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(X-Rite Inc.) C:\Program Files (x86)\X-Rite\Devices\Services\xritedeviced.exe
(X-Rite Inc.) C:\Program Files (x86)\X-Rite\Devices\Services\ColorMunki\ColorMunkiDeviceService.exe
(Silicondust USA Inc) C:\Program Files\Silicondust\HDHomeRun\hdhomerun_wmc_service.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Logitech, Inc.) C:\Program Files\Logitech\SetPointP\SetPoint.exe
(Tordex) C:\Program Files\TrueLaunchBar\tlbHost.exe
() C:\Program Files (x86)\X-Rite\ColorMunki Photo\Tools\ColorMunki Photo Tray.exe
(Logitech, Inc.) C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.exe
(CLEVO CO.) C:\Program Files (x86)\Hotkey\HkeyTray.exe
(Wondershare) C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
() C:\Program Files\Qualcomm Atheros\Network Manager\NetworkManager.exe
(TechSmith Corporation) C:\Program Files (x86)\TechSmith\Snagit 12\Snagit32.exe
(JRT Studio LLC) C:\Program Files (x86)\JRT Studio\Cheetah Sync\CheetahSync.exe
(TechSmith Corporation) C:\Program Files (x86)\TechSmith\Snagit 12\SnagPriv.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(CLEVO CO.) C:\Program Files (x86)\Hotkey\hotkeyrtk.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(TechSmith Corporation) C:\Program Files (x86)\TechSmith\Snagit 12\TscHelp.exe
(TechSmith Corporation) C:\Program Files (x86)\TechSmith\Snagit 12\SnagitEditor.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe
(Microsoft(R) Corporation) C:\Program Files (x86)\Microsoft Money Plus\MNYCoreFiles\msmoney.exe
(CLEVO CO.) C:\Program Files (x86)\Hotkey\hkysound.exe
(CLEVO CO.) C:\Program Files (x86)\Hotkey\ComboKeyTray.exe
(Microsoft Corporation) C:\Windows\splwow64.exe
(Oracle Corporation) C:\Program Files\Java\jre1.8.0_131\bin\javaw.exe
(FileZilla Project) C:\Program Files (x86)\FileZilla FTP Client\filezilla.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\Adobe Installer.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe
() C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\CCXProcess.exe
(Node.js) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\libs\node.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\CCLibrary.exe
(Node.js) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\libs\node.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\HEX\Adobe CEF Helper.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
(RedFox) C:\Program Files (x86)\RedFox\AnyDVD\AnyDVDtray.exe
() C:\Program Files (x86)\RedFox\AnyDVD\ADvdDiscHlp64.exe
(FileZilla Project) C:\Program Files (x86)\FileZilla FTP Client\fzsftp.exe
(HandBrake Team) C:\Program Files\HandBrake\HandBrake.exe
(Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(FreeDownloadManager.org) C:\Program Files\FreeDownloadManager.ORG\Free Download Manager\fdm.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2585744 2015-01-16] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13764312 2014-10-07] (Realtek Semiconductor)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [508128 2016-07-01] (Adobe Systems Incorporated)
HKLM\...\Run: [EvtMgr6] => C:\Program Files\Logitech\SetPointP\SetPoint.exe [3113592 2015-08-25] (Logitech, Inc.)
HKLM\...\Run: [HDHRFling] => C:\Program Files (x86)\HDHRFling\HDHRFling.exe [5553664 2015-07-16] (HDHRFling.com)
HKLM\...\Run: [WindowsDefender] => "%ProgramFiles%\Windows Defender\MSASCuiL.exe"
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59240 2011-09-27] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2011-10-24] (Apple Inc.)
HKLM-x32\...\Run: [CBSpoolDaemon] => "C:\Program Files (x86)\ImagePrint\spool\mux\muxd.exe"
HKLM-x32\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2137744 2016-10-08] (Wondershare)
HKLM-x32\...\Run: [DelaypluginInstall] => C:\ProgramData\Wondershare\Video Converter Ultimate\DelayPluginI.exe
HKLM-x32\...\Run: [PowerDVD16Agent] => C:\Program Files (x86)\CyberLink\PowerDVD16\PowerDVD16Agent.exe [525352 2016-12-06] (CyberLink Corp.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2017-03-15] (Oracle Corporation)
HKLM-x32\...\Run: [Adobe Creative Cloud] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2406496 2017-06-04] (Adobe Systems Incorporated)
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
HKU\S-1-5-21-1717685655-2789524432-2867823966-1001\...\Run: [tlbHost] => C:\Program Files\TrueLaunchBar\tlbHost.exe [560312 2015-10-03] (Tordex)
HKU\S-1-5-21-1717685655-2789524432-2867823966-1001\...\Run: [Reasonable NoClone] => [X]
HKU\S-1-5-21-1717685655-2789524432-2867823966-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3042592 2017-06-01] (Valve Corporation)
HKU\S-1-5-21-1717685655-2789524432-2867823966-1001\...\Run: [Adobe Acrobat Synchronizer] => "C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe"
HKU\S-1-5-21-1717685655-2789524432-2867823966-1001\...\Run: [AnyDVD] => C:\Program Files (x86)\RedFox\AnyDVD\AnyDVDtray.exe [11116544 2017-06-20] (RedFox)
HKU\S-1-5-21-1717685655-2789524432-2867823966-1001\...\Run: [Outlook Google Calendar Sync] => C:\Users\dferrier\AppData\Local\Apps\2.0\L8RQ2D3X.G1A\7GRZB6CY.0DV\outl..tion_a30846ba3587a523_0002.0004_d79036ab77ef318b\OutlookGoogleCalendarSync.exe [851968 2017-05-10] (Paul Woolcock)
HKU\S-1-5-21-1717685655-2789524432-2867823966-1001\...\Run: [AlcoholAutomount] => C:\Program Files (x86)\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe [39376 2015-03-12] (Alcohol Soft Development Team)
HKU\S-1-5-21-1717685655-2789524432-2867823966-1001\...\RunOnce: [Uninstall C:\Users\dferrier\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\dferrier\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64"
HKU\S-1-5-21-1717685655-2789524432-2867823966-1001\...\MountPoints2: {e21ce5d1-97ae-11e6-827a-c03896838b48} - "I:\LaunchU3.exe" -a
HKU\S-1-5-18\...\Run: [Reasonable NoClone] => "C:\Program Files (x86)\Reasonable NoClone 2011 Enterprise\NoClone.exe" null /startup
ShellIconOverlayIdentifiers: [ AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2017-05-26] ()
ShellIconOverlayIdentifiers: [ AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2017-05-26] ()
ShellIconOverlayIdentifiers: [ AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2017-05-26] ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ColorMunki Gamma.lnk [2016-02-20]
ShortcutTarget: ColorMunki Gamma.lnk -> C:\Program Files (x86)\X-Rite\ColorMunki Photo\Gamma\CalibrationLoader.exe (LOGO Kommunikations- und Drucktechnik GmbH & Co. KG)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ColorMunkiPhotoTray.exe.lnk [2016-02-20]
ShortcutTarget: ColorMunkiPhotoTray.exe.lnk -> C:\Program Files (x86)\X-Rite\ColorMunki Photo\Tools\ColorMunki Photo Tray.exe ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Hotkey.lnk [2015-11-17]
ShortcutTarget: Hotkey.lnk -> C:\Program Files (x86)\Hotkey\HkeyTray.exe (CLEVO CO.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Install LastPass FF RunOnce.lnk [2016-03-09]
ShortcutTarget: Install LastPass FF RunOnce.lnk -> C:\Program Files (x86)\Common Files\lpuninstall.exe (LastPass)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Install LastPass IE RunOnce.lnk [2016-03-09]
ShortcutTarget: Install LastPass IE RunOnce.lnk -> C:\Program Files (x86)\Common Files\lpuninstall.exe (LastPass)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Killer Network Manager.lnk [2015-11-17]
ShortcutTarget: Killer Network Manager.lnk -> C:\Windows\Installer\{71ACF663-CC95-429F-8C5C-0A1DC4EE8E78}\NetworkManager.exe_130C27D738F34C89BDDF21BCFD74B56D.exe (Flexera Software LLC)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Snagit 12.lnk [2015-12-28]
ShortcutTarget: Snagit 12.lnk -> C:\Program Files (x86)\TechSmith\Snagit 12\Snagit32.exe (TechSmith Corporation)
Startup: C:\Users\dferrier\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Cheetah Sync.lnk [2015-12-19]
ShortcutTarget: Cheetah Sync.lnk -> C:\Users\dferrier\AppData\Roaming\Microsoft\Installer\{0600EEDA-11EA-4588-81F3-8F1D89FC83DE}\_57396F6D95A618E977BED0.exe ()
Startup: C:\Users\dferrier\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Password Safe.lnk [2016-05-03]
ShortcutTarget: Password Safe.lnk -> C:\Program Files (x86)\Password Safe\pwsafe.exe (SourceForge.net)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\..\Interfaces\{09CBD398-74E7-49A5-A567-432F6F45A3AD}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{736478E9-51BE-4D47-993A-F99B5F526DCB}: [NameServer] 8.8.8.8,8.8.4.4,192.168.25.1
Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <==== ATTENTION
BHO: No Name -> {13D67BB7-DB5F-48AA-884D-7A5D94168509} -> No File
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2017-05-26] (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_131\bin\ssv.dll [2017-04-24] (Oracle Corporation)
BHO: LastPass Vault -> {95D9ECF5-2A4D-4550-BE49-70D42F71296E} -> C:\Program Files (x86)\LastPass\LPToolbar_x64.dll [2016-03-09] (LastPass)
BHO: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll [2015-08-25] (Logitech, Inc.)
BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL [2017-05-26] (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_131\bin\jp2ssv.dll [2017-04-24] (Oracle Corporation)
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll [2017-05-26] (Microsoft Corporation)
BHO-x32: LastPass Vault -> {95D9ECF5-2A4D-4550-BE49-70D42F71296E} -> C:\Program Files (x86)\LastPass\LPToolbar.dll [2016-03-09] (LastPass)
BHO-x32: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll [2015-08-25] (Logitech, Inc.)
BHO-x32: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\Office16\GROOVEEX.DLL [2017-05-26] (Microsoft Corporation)
Toolbar: HKLM - LastPass Toolbar - {9f6b5cc3-5c7b-4b5c-97af-19dec1e380e5} - C:\Program Files (x86)\LastPass\LPToolbar_x64.dll [2016-03-09] (LastPass)
Toolbar: HKLM-x32 - LastPass Toolbar - {9f6b5cc3-5c7b-4b5c-97af-19dec1e380e5} - C:\Program Files (x86)\LastPass\LPToolbar.dll [2016-03-09] (LastPass)
DPF: HKLM-x32 {FD3BEB0C-AB43-4253-9146-C371D48FBE0D} hxxp://192.168.25.250/web.cab
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-05-26] (Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-05-26] (Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-05-26] (Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-05-26] (Microsoft Corporation)
Handler: WSWSVCUchrome - No CLSID Value
FireFox:
========
FF ProfilePath: C:\Users\dferrier\AppData\Roaming\Mozilla\Firefox\Profiles\gs7v3iqm.default [2017-06-26]
FF Extension: (Free Download Manager extension) - C:\Users\dferrier\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\fdm_ffext@freedownloadmanager.org [2016-12-13]
FF Extension: (DownThemAll!) - C:\Users\dferrier\AppData\Roaming\Mozilla\Firefox\Profiles\gs7v3iqm.default\Extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi [2016-12-13]
FF HKLM-x32\...\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt
FF Extension: (Logitech SetPoint) - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt [2016-05-30] [not signed]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_26_0_0_131.dll [2017-06-20] ()
FF Plugin: @java.com/DTPlugin,version=11.131.2 -> C:\Program Files\Java\jre1.8.0_131\bin\dtplugin\npDeployJava1.dll [2017-04-24] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.131.2 -> C:\Program Files\Java\jre1.8.0_131\bin\plugin2\npjp2.dll [2017-04-24] (Oracle Corporation)
FF Plugin: @lastpass.com/NPLastPass -> C:\Program Files (x86)\LastPass\nplastpass64.dll [2016-03-09] (LastPass)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2017-06-04] (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_26_0_0_131.dll [2017-06-20] ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2014-03-20] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2014-03-20] (Intel Corporation)
FF Plugin-x32: @lastpass.com/NPLastPass -> C:\Program Files (x86)\LastPass\nplastpass64.dll [2016-03-09] (LastPass)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2017-05-26] (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2017-05-26] (Microsoft Corporation)
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-04-04] (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2017-06-04] (Adobe Systems)
FF Plugin-x32: adobe.com/AdobeExManDetect -> C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\npAdobeExManDetectX86.dll [No File]
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AdobeUpdateService; C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [814688 2017-06-04] (Adobe Systems Incorporated)
R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2246256 2017-05-18] (Adobe Systems, Incorporated)
R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [309376 2014-11-26] (Qualcomm Atheros) [File not signed]
S2 AxAutoMntSrv; C:\Program Files (x86)\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe [39376 2015-03-12] (Alcohol Soft Development Team)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [3971264 2017-05-14] (Microsoft Corporation)
R2 ColorMunkiService; C:\Program Files (x86)\X-Rite\Devices\Services\ColorMunki\ColorMunkiDeviceService.exe [147968 2009-10-21] (X-Rite Inc.) [File not signed]
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1148560 2015-01-16] (NVIDIA Corporation)
R2 hasplms; C:\Windows\system32\hasplms.exe [4621632 2015-04-14] (SafeNet Inc.)
S4 HDHomeRun RECORD; C:\Program Files\Silicondust\HDHomeRun\hdhomerun_record.exe [255936 2016-11-19] ()
R2 HDHomeRun WMC Service; C:\Program Files\Silicondust\HDHomeRun\hdhomerun_wmc_service.exe [33216 2016-11-19] (Silicondust USA Inc)
U2 HiPatchService; C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe [9728 2016-03-14] (Hi-Rez Studios) [File not signed]
R2 HKClipSvc; C:\Program Files (x86)\Hotkey\Driver\x64\HKClipSvc.exe [246272 2014-10-29] (Insyde Software Corp.) [File not signed]
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [328296 2014-10-29] (Intel Corporation)
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [887232 2014-01-31] (Intel(R) Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [154584 2014-03-20] (Intel Corporation)
S2 Net Driver HPZ12; C:\Windows\System32\HPZinw12.dll [50688 2014-11-17] (Hewlett-Packard) [File not signed]
R2 nlsX86cc; C:\Windows\SysWOW64\nlssrv32.exe [66560 2012-03-28] (Nalpeiron Ltd.) [File not signed]
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1706128 2015-01-16] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [21833360 2015-01-16] (NVIDIA Corporation)
S2 Pml Driver HPZ12; C:\Windows\System32\HPZipm12.dll [66048 2014-11-17] (Hewlett-Packard) [File not signed]
R2 PowerBiosServer; C:\Program Files (x86)\Hotkey\HotkeyService.exe [24064 2014-12-05] (CLEVO CO.) [File not signed]
R2 Qualcomm Atheros Killer Service V2; C:\Program Files\Qualcomm Atheros\Network Manager\KillerService.exe [386560 2014-12-11] (Qualcomm Atheros) [File not signed]
R2 StarWindServiceAE; C:\Program Files (x86)\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [370688 2009-12-23] (StarWind Software) [File not signed]
R2 TechSmith Uploader Service; C:\Program Files (x86)\Common Files\TechSmith Shared\Uploader\UploaderService.exe [3408384 2015-01-26] (TechSmith Corporation) [File not signed]
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [361824 2017-01-12] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [119872 2017-01-12] (Microsoft Corporation)
R2 xritedeviced; C:\Program Files (x86)\X-Rite\Devices\Services\xritedeviced.exe [130048 2009-10-21] (X-Rite Inc.) [File not signed]
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 AirplaneModeHid; C:\Windows\system32\DRIVERS\AirplaneModeHid.sys [26888 2013-06-26] (Insyde Corporation)
S3 akshhl; C:\Windows\system32\DRIVERS\akshhl.sys [63944 2015-04-14] (SafeNet Inc.)
R3 AnyDVD; C:\Windows\System32\Drivers\AnyDVD.sys [154448 2016-07-11] (RedFox)
R3 AnyDVD; C:\Windows\SysWOW64\Drivers\AnyDVD.sys [154448 2016-07-11] (RedFox)
U3 axscsidrv; C:\Windows\System32\Drivers\axscsidrv.sys [304296 2017-05-10] (Alcohol Soft Development Team)
R1 BfLwf; C:\Windows\system32\DRIVERS\bwcW8x64.sys [98992 2014-11-19] (Qualcomm Atheros, Inc.)
S3 colormunki; C:\Windows\System32\Drivers\colormunki_x64.sys [51600 2007-10-02] (Thesycon GmbH, Germany)
S3 FTDIBUS; C:\Windows\system32\drivers\ftdibus.sys [119680 2017-03-08] (Future Technology Devices International Ltd.)
S3 FTSER2K; C:\Windows\system32\drivers\ftser2k.sys [89792 2017-03-08] (Future Technology Devices International Ltd.)
R3 HKKbdFltr; C:\Windows\system32\DRIVERS\HKKbdFltr.sys [41160 2014-10-29] (Insyde Software Corp.)
R3 HKMouFltr; C:\Windows\system32\DRIVERS\HKMouFltr.sys [40136 2014-10-29] (Insyde Software Corp.)
S3 kmloop; C:\Windows\system32\DRIVERS\loop.sys [15360 2013-08-22] (Microsoft Corporation)
R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [118272 2014-03-20] (Intel Corporation)
R1 MpKslfedbde4a; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{69A62411-B280-4E14-8837-A94D90F6D167}\MpKslfedbde4a.sys [44928 2017-06-06] (Microsoft Corporation)
S3 NETwNe64; C:\Windows\system32\DRIVERS\NETwew02.sys [4649440 2013-06-18] (Intel Corporation)
R1 npcap; C:\Windows\system32\DRIVERS\npcap.sys [71888 2016-12-15] (Insecure.Com LLC.)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19600 2015-01-16] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [38032 2014-11-22] (NVIDIA Corporation)
R3 PdiPorts; C:\Windows\System32\drivers\PdiPorts.sys [19248 2006-11-16] (Portrait Displays, Inc.)
R0 PxHlpa64; C:\Windows\System32\Drivers\PxHlpa64.sys [56336 2012-06-22] (Corel Corporation)
R3 Qcamain; C:\Windows\system32\DRIVERS\Qcamainx64.sys [2286080 2014-11-26] (Qualcomm Atheros, Inc.)
R3 RTSPER; C:\Windows\system32\DRIVERS\RtsPer.sys [502488 2014-05-07] (Realsil Semiconductor Corporation)
R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [31472 2014-01-09] (Synaptics Incorporated)
R0 sptd; C:\Windows\System32\Drivers\sptd.sys [394296 2016-09-29] (Duplex Secure Ltd.)
R1 SvThANSP; C:\Program Files (x86)\Hotkey\SvThANSP.sys [15224 2013-10-11] (Windows (R) Win 7 DDK provider)
U5 TMUSB; C:\Windows\System32\DRIVERS\TMUSB64.SYS [63096 2015-05-24] (Seiko Epson Corporation)
R3 TotRec8; C:\Windows\system32\drivers\TotRec8.sys [121424 2010-10-14] (High Criteria inc.)
S1 VBoxNetAdp; C:\Windows\system32\DRIVERS\VBoxNetAdp6.sys [131144 2017-04-28] (Oracle Corporation)
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [46600 2017-02-10] (Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [274776 2017-01-12] (Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [117592 2017-01-12] (Microsoft Corporation)
S3 xb1usb; C:\Windows\System32\drivers\xb1usb.sys [34016 2014-05-27] (Microsoft Corporation)
R2 {41E8078B-96D9-42DC-8789-A1CF102CD880}; C:\Program Files (x86)\CyberLink\PowerDVD16\Common\NavFilter\000.fcl [38168 2016-12-02] (CyberLink Corp.)
S3 akshasp; \SystemRoot\system32\DRIVERS\akshasp.sys [X]
S3 aksusb; \SystemRoot\System32\drivers\aksusb.sys [X]
U4 npcap_wifi; no ImagePath
S3 VMSMP; \SystemRoot\system32\DRIVERS\vmswitch.sys [X]
S3 xhunter1; \??\C:\Windows\xhunter1.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-06-26 22:24 - 2017-06-26 22:24 - 00000000 ____D C:\Users\dferrier\Documents\Larian Studios
2017-06-26 18:54 - 2017-06-26 18:54 - 00000000 ____D C:\Users\dferrier\AppData\Local\assistant
2017-06-26 09:40 - 2017-06-26 09:40 - 00000000 ____D C:\Users\dferrier\AppData\Local\Tempzxpsignfa540e18037a3bb7
2017-06-26 09:24 - 2017-06-26 09:24 - 00000000 ____D C:\Users\dferrier\AppData\Local\Tempzxpsign578bcde46b2f4cc1
2017-06-26 09:24 - 2017-06-26 09:24 - 00000000 ____D C:\Users\dferrier\AppData\Local\Tempzxpsign1357166ce04a90bf
2017-06-26 09:23 - 2017-06-26 09:23 - 00000000 ____D C:\Users\dferrier\AppData\Local\Tempzxpsigndb9fe1e7f1504d62
2017-06-26 09:23 - 2017-06-26 09:23 - 00000000 ____D C:\Users\dferrier\AppData\Local\Tempzxpsign96c0381969e20bb1
2017-06-26 09:23 - 2017-06-26 09:23 - 00000000 ____D C:\Users\dferrier\AppData\Local\Tempzxpsign651287fc3c066038
2017-06-25 20:48 - 2017-06-25 20:48 - 00000222 _____ C:\Users\dferrier\Desktop\Divinity Original Sin Enhanced Edition.url
2017-06-25 20:37 - 2017-06-25 20:37 - 00000222 _____ C:\Users\dferrier\Desktop\NieRAutomata.url
2017-06-25 15:23 - 2017-06-25 15:23 - 00000000 ____D C:\Users\dferrier\AppData\Local\Tempzxpsign25d1fc99f9022722
2017-06-25 15:22 - 2017-06-25 15:22 - 00000000 ____D C:\Users\dferrier\AppData\Local\Tempzxpsign286af6eabb30d5eb
2017-06-25 15:21 - 2017-06-25 15:21 - 00000000 ____D C:\Users\dferrier\AppData\Local\Tempzxpsignba4c71fe9b4f06e9
2017-06-25 15:21 - 2017-06-25 15:21 - 00000000 ____D C:\Users\dferrier\AppData\Local\Tempzxpsign5ee866bb11f640f3
2017-06-25 15:21 - 2017-06-25 15:21 - 00000000 ____D C:\Users\dferrier\AppData\Local\Tempzxpsign0dd32c54eab861a7
2017-06-25 14:58 - 2017-06-25 14:58 - 00000000 ____D C:\Users\dferrier\AppData\Local\Tempzxpsign364f1b7a0d04b681
2017-06-25 14:57 - 2017-06-25 14:57 - 00000000 ____D C:\Users\dferrier\AppData\Local\Tempzxpsign6ea42baa4cd384b0
2017-06-25 14:56 - 2017-06-25 14:56 - 00000000 ____D C:\Users\dferrier\AppData\Local\Tempzxpsign4fb6f498e6e2adb4
2017-06-25 14:56 - 2017-06-25 14:56 - 00000000 ____D C:\Users\dferrier\AppData\Local\Tempzxpsign1177dc734c3853e3
2017-06-25 14:51 - 2017-06-25 14:51 - 00001909 _____ C:\Users\Public\Desktop\Agisoft PhotoScan Standard (64 bit).lnk
2017-06-25 14:51 - 2017-06-25 14:51 - 00000000 ____D C:\Users\dferrier\AppData\Roaming\Agisoft
2017-06-25 14:51 - 2017-06-25 14:51 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Agisoft
2017-06-25 14:51 - 2017-06-25 14:51 - 00000000 ____D C:\Program Files\Agisoft
2017-06-25 14:21 - 2017-06-25 14:23 - 00000000 ____D C:\Users\dferrier\Documents\reo speedwagon tickets
2017-06-25 14:21 - 2017-06-25 14:21 - 00000000 ____D C:\Users\dferrier\Documents\New folder
2017-06-24 18:28 - 2017-06-24 18:28 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CraftWare 1.14
2017-06-24 18:28 - 2017-06-24 18:28 - 00000000 ____D C:\Program Files (x86)\CraftWare
2017-06-24 17:36 - 2017-06-24 17:36 - 00000000 ____D C:\Users\dferrier\AppData\Roaming\cura
2017-06-24 17:35 - 2017-06-24 17:36 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cura
2017-06-24 17:35 - 2017-06-24 17:35 - 00000000 ____D C:\Program Files\Cura 2.6
2017-06-23 17:50 - 2017-06-23 17:50 - 00000146 _____ C:\Users\dferrier\Desktop\Sound - Shortcut.lnk
2017-06-19 22:50 - 2017-06-24 17:36 - 00000000 ____D C:\Users\dferrier\AppData\Local\cura
2017-06-19 22:45 - 2017-06-24 17:34 - 00000000 ____D C:\Program Files\Cura 2.5
2017-06-19 14:03 - 2017-06-19 14:03 - 00000000 ____D C:\Users\dferrier\AppData\Local\Tempzxpsignb0ff42b22ad0a776
2017-06-19 14:03 - 2017-06-19 14:03 - 00000000 ____D C:\Users\dferrier\AppData\Local\Tempzxpsign3325c6ac85272be3
2017-06-19 13:23 - 2017-06-19 13:48 - 00000000 ____D C:\Users\dferrier\AppData\Roaming\FreeCAD
2017-06-19 13:23 - 2017-06-19 13:23 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FreeCAD 0.16
2017-06-19 13:18 - 2017-06-19 13:22 - 00000000 ____D C:\Program Files\FreeCAD 0.16
2017-06-19 12:43 - 2017-06-19 12:43 - 00001056 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CC 2017.lnk
2017-06-19 12:14 - 2017-06-19 12:14 - 00001000 _____ C:\Users\dferrier\Desktop\Adobe Lightroom.lnk
2017-06-19 12:14 - 2017-06-19 12:14 - 00001000 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Lightroom.lnk
2017-06-19 11:52 - 2017-06-19 11:52 - 00001245 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Creative Cloud.lnk
2017-06-19 11:52 - 2017-06-19 11:52 - 00001233 _____ C:\Users\Public\Desktop\Adobe Creative Cloud.lnk
2017-06-18 22:03 - 2017-06-18 22:03 - 00002205 _____ C:\Users\dferrier\AppData\Local\recently-used.xbel
2017-06-17 12:13 - 2017-06-17 12:13 - 07075640 _____ (Tim Kosse) C:\Users\dferrier\Downloads\FileZilla_3.26.2_win64-setup.exe
2017-06-16 10:37 - 2017-06-16 10:37 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mp3tag
2017-06-10 12:19 - 2017-06-10 12:19 - 1153990656 _____ C:\Users\dferrier\Downloads\The Quiet Man (1952) -.mkv
2017-06-10 12:18 - 2017-06-01 12:36 - 201645046 _____ C:\Users\dferrier\Downloads\The Making of The Quiet Man-featurette.mkv
2017-06-10 12:12 - 2017-06-10 12:13 - 07070840 _____ (Tim Kosse) C:\Users\dferrier\Downloads\FileZilla_3.26.1_win64-setup.exe
2017-06-09 18:18 - 2017-06-13 09:33 - 00000000 ____D C:\Users\dferrier\AppData\Roaming\MuseScore
2017-06-09 18:18 - 2017-06-09 18:18 - 00001069 _____ C:\Users\dferrier\Desktop\MuseScore 2.lnk
2017-06-09 18:18 - 2017-06-09 18:18 - 00000000 ____D C:\Users\dferrier\Documents\MuseScore2
2017-06-09 18:18 - 2017-06-09 18:18 - 00000000 ____D C:\Users\dferrier\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MuseScore 2
2017-06-09 18:18 - 2017-06-09 18:18 - 00000000 ____D C:\Users\dferrier\AppData\Local\MuseScore
2017-06-09 18:18 - 2017-06-09 18:18 - 00000000 ____D C:\Program Files (x86)\MuseScore 2
2017-06-05 21:32 - 2017-06-07 23:12 - 00000000 ____D C:\Users\dferrier\AppData\Roaming\Ultra Fractal 5
2017-06-05 21:32 - 2017-06-05 21:32 - 00001971 _____ C:\Users\dferrier\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ultra Fractal Server 5.04.lnk
2017-06-05 21:32 - 2017-06-05 21:32 - 00001955 _____ C:\Users\dferrier\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ultra Fractal 5.04.lnk
2017-06-05 21:32 - 2017-06-05 21:32 - 00001925 _____ C:\Users\dferrier\Desktop\Ultra Fractal 5.04.lnk
2017-06-05 21:32 - 2017-06-05 21:32 - 00000000 ____D C:\Users\dferrier\Documents\Ultra Fractal 5
2017-06-05 21:32 - 2017-06-05 21:32 - 00000000 ____D C:\Program Files (x86)\Ultra Fractal 5
2017-06-02 22:41 - 2017-06-02 22:41 - 00001113 _____ C:\Users\dferrier\Desktop\Acrosync.lnk
2017-06-02 22:41 - 2017-06-02 22:41 - 00000000 ____D C:\Users\dferrier\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Acrosync
2017-06-02 22:41 - 2017-06-02 22:41 - 00000000 ____D C:\Users\dferrier\AppData\Local\Acrosync
2017-06-01 12:51 - 2017-06-01 12:51 - 106528394 _____ C:\Users\dferrier\Downloads\plexmediaserver-1.7.2.3878-8088811b8.x86_64.rpm
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-06-26 22:42 - 2016-05-26 20:05 - 00000000 ____D C:\FRST
2017-06-26 22:41 - 2017-01-25 22:20 - 00000000 ____D C:\Users\dferrier\Desktop\malware removal
2017-06-26 22:35 - 2016-11-20 20:09 - 00000000 ____D C:\Users\dferrier\AppData\LocalLow\Mozilla
2017-06-26 22:27 - 2015-11-17 15:50 - 00025600 _____ C:\Users\dferrier\Documents\Joebob.xlsx
2017-06-26 22:27 - 2015-11-17 13:49 - 00000000 ____D C:\Users\dferrier\Documents\email
2017-06-26 22:25 - 2015-12-28 09:13 - 00000000 ____D C:\Users\dferrier\AppData\Local\CrashDumps
2017-06-26 22:24 - 2015-11-26 22:55 - 00000000 ____D C:\Program Files (x86)\Steam
2017-06-26 21:13 - 2016-12-13 21:29 - 00000000 ____D C:\Users\dferrier\AppData\Local\Free Download Manager
2017-06-26 14:07 - 2015-11-21 09:34 - 00000000 ____D C:\Users\dferrier\AppData\Local\Adobe
2017-06-26 12:59 - 2017-04-21 23:23 - 00000000 ____D C:\Users\dferrier\Documents\3d printing
2017-06-26 12:30 - 2016-05-26 17:06 - 00000000 __SHD C:\Users\dferrier\AppData\LocalLow\EmieUserList
2017-06-26 12:30 - 2016-05-26 17:05 - 00000000 __SHD C:\Users\dferrier\AppData\LocalLow\EmieSiteList
2017-06-26 12:30 - 2016-05-26 17:05 - 00000000 __SHD C:\Users\dferrier\AppData\Local\EmieUserList
2017-06-26 12:30 - 2016-05-26 17:05 - 00000000 __SHD C:\Users\dferrier\AppData\Local\EmieSiteList
2017-06-25 23:57 - 2015-11-17 12:52 - 00003600 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1717685655-2789524432-2867823966-1001
2017-06-25 22:05 - 2015-11-17 14:00 - 00000000 ____D C:\Users\dferrier\Documents\My Games
2017-06-25 20:48 - 2016-03-27 21:46 - 00000000 ____D C:\Users\dferrier\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2017-06-25 14:52 - 2013-09-10 08:49 - 00867660 _____ C:\Windows\system32\PerfStringBackup.INI
2017-06-25 14:52 - 2013-08-22 08:36 - 00000000 ____D C:\Windows\Inf
2017-06-24 18:29 - 2015-11-17 23:43 - 00000000 ____D C:\ProgramData\Package Cache
2017-06-24 18:29 - 2015-11-17 13:26 - 00000000 ____D C:\Program Files\DIFX
2017-06-24 01:44 - 2015-11-20 12:02 - 00000000 ____D C:\Users\dferrier\AppData\Roaming\HandBrake
2017-06-23 23:30 - 2015-12-29 16:42 - 00000000 ____D C:\Users\dferrier\AppData\Local\Battle.net
2017-06-23 22:39 - 2016-03-15 15:27 - 00000000 ____D C:\Program Files (x86)\StarCraft II
2017-06-23 22:36 - 2015-12-29 16:41 - 00000000 ____D C:\Program Files (x86)\Battle.net
2017-06-23 18:21 - 2016-06-23 17:42 - 00000000 ____D C:\Program Files (x86)\Overwatch Test
2017-06-23 17:51 - 2015-12-31 11:36 - 00000000 ____D C:\Users\dferrier\AppData\Roaming\MusicBee
2017-06-23 17:41 - 2016-03-15 15:27 - 00000000 ____D C:\Users\dferrier\Documents\StarCraft II
2017-06-23 17:36 - 2016-04-29 14:42 - 00000000 ____D C:\Program Files (x86)\Overwatch
2017-06-23 07:08 - 2016-09-18 19:04 - 00000600 _____ C:\Users\dferrier\AppData\Local\PUTTY.RND
2017-06-23 07:04 - 2015-12-04 08:54 - 00000000 ____D C:\Users\dferrier\AppData\Roaming\vlc
2017-06-22 17:44 - 2015-12-26 17:06 - 00000000 ____D C:\Users\dferrier\Documents\photography
2017-06-22 06:40 - 2016-05-26 17:07 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2017-06-22 06:02 - 2015-11-17 13:46 - 00000000 ____D C:\Users\dferrier\Documents\Bible
2017-06-22 00:05 - 2015-11-17 12:39 - 00000000 ____D C:\Users\dferrier\AppData\Local\Packages
2017-06-21 22:03 - 2016-12-06 11:41 - 00001114 _____ C:\Users\Public\Desktop\AnyDVD.lnk
2017-06-21 12:32 - 2015-11-17 13:49 - 00000000 ____D C:\Users\dferrier\Documents\bills
2017-06-20 22:11 - 2016-05-30 22:40 - 00018960 _____ (Logitech, Inc.) C:\Windows\system32\Drivers\LNonPnP.sys
2017-06-20 12:34 - 2015-11-17 12:39 - 00000000 ____D C:\Users\dferrier\AppData\Roaming\Adobe
2017-06-20 07:30 - 2013-08-22 10:36 - 00000000 ____D C:\Windows\SysWOW64\Macromed
2017-06-20 07:30 - 2013-08-22 10:36 - 00000000 ____D C:\Windows\system32\Macromed
2017-06-19 13:59 - 2016-03-01 00:36 - 00000000 ___RD C:\Users\dferrier\Creative Cloud Files
2017-06-19 13:59 - 2015-11-17 12:39 - 00000000 ____D C:\Users\dferrier
2017-06-19 13:57 - 2016-03-13 19:58 - 00000000 __RHD C:\Users\dferrier\lizzylizard@writeme.com Creative Cloud Files
2017-06-19 12:43 - 2015-11-17 13:46 - 00000000 ____D C:\Users\dferrier\Documents\Adobe
2017-06-19 12:40 - 2015-11-21 09:39 - 00000000 ____D C:\Program Files\Common Files\Adobe
2017-06-19 12:36 - 2015-11-21 09:42 - 00000000 ____D C:\Program Files\Adobe
2017-06-19 12:34 - 2015-11-21 09:34 - 00000000 ____D C:\ProgramData\Adobe
2017-06-19 05:58 - 2017-05-18 08:52 - 00000000 ____D C:\Users\dferrier\.gimp-2.8
2017-06-17 12:13 - 2016-11-30 23:12 - 00000000 ____D C:\Users\dferrier\AppData\Roaming\FileZilla
2017-06-16 10:49 - 2016-03-03 00:35 - 00000000 ____D C:\Users\dferrier\AppData\Roaming\Mp3tag
2017-06-16 10:37 - 2015-12-31 12:06 - 00000995 _____ C:\Users\Public\Desktop\Mp3tag.lnk
2017-06-16 10:37 - 2015-12-31 12:06 - 00000000 ____D C:\Program Files (x86)\Mp3tag
2017-06-15 09:36 - 2013-08-22 10:36 - 00000000 ____D C:\Windows\AppReadiness
2017-06-14 13:40 - 2016-01-09 16:41 - 00000000 ____D C:\Users\dferrier\Documents\atkins
2017-06-13 21:02 - 2013-08-22 10:20 - 00000000 ____D C:\Windows\CbsTemp
2017-06-13 13:57 - 2017-05-19 10:54 - 00000000 ____D C:\Users\dferrier\AppData\Local\gtk-2.0
2017-06-10 12:13 - 2016-11-30 23:12 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileZilla FTP Client
2017-06-10 12:13 - 2016-11-30 23:12 - 00000000 ____D C:\Program Files (x86)\FileZilla FTP Client
2017-06-04 22:56 - 2016-02-27 12:34 - 00000000 ____D C:\Users\dferrier\AppData\Local\Logos
2017-06-04 22:52 - 2016-02-27 13:24 - 00002291 _____ C:\Users\dferrier\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Logos Bible Software.lnk
2017-06-04 22:52 - 2016-02-27 13:24 - 00002283 _____ C:\Users\dferrier\Desktop\Logos Bible Software.lnk
2017-06-04 22:43 - 2016-02-27 14:08 - 00000000 ____D C:\Users\dferrier\Documents\Logos Log Files
2017-06-02 22:48 - 2013-08-22 10:36 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2017-06-02 22:46 - 2015-11-17 17:00 - 00000000 ____D C:\Program Files (x86)\Microsoft Office
2017-06-02 22:34 - 2015-12-19 14:49 - 00000000 ____D C:\Users\dferrier\Documents\JRT Studio
2017-06-02 22:31 - 2015-12-16 12:01 - 00000091 _____ C:\HaxLogs.txt
2017-06-02 22:30 - 2013-08-22 09:45 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2017-06-02 14:33 - 2017-04-01 09:23 - 00000000 ____D C:\Users\dferrier\Documents\solar power
2017-06-02 14:33 - 2016-07-26 16:54 - 00000000 ____D C:\Users\dferrier\Documents\Ham Radio
2017-06-02 09:20 - 2013-08-22 10:36 - 00000000 ____D C:\Windows\system32\FxsTmp
2017-06-01 07:58 - 2016-03-07 11:29 - 00004848 _____ C:\Users\dferrier\Documents\ax_files.xml
2017-05-27 14:01 - 2017-05-26 14:33 - 00004476 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
==================== Files in the root of some directories =======
2016-12-03 13:46 - 2016-12-03 13:47 - 0009272 _____ () C:\Program Files (x86)\DeviceManage Setup Log.txt
2016-03-09 18:50 - 2016-03-09 18:51 - 21572120 _____ (LastPass) C:\Program Files (x86)\Common Files\lpuninstall.exe
2015-11-21 22:12 - 2008-03-19 18:50 - 0097280 _____ () C:\Program Files (x86)\Common Files\pcsbClean.exe
2015-11-21 22:12 - 2008-03-06 22:31 - 0134656 _____ () C:\Program Files (x86)\Common Files\PCSBoff.exe
2016-03-01 15:53 - 2016-09-30 08:51 - 0000033 _____ () C:\Users\dferrier\AppData\Roaming\AdobeWLCMCache.dat
2015-08-05 10:51 - 2015-08-05 10:51 - 0000000 _____ () C:\Users\dferrier\AppData\Roaming\bdopatchtime.txt
2015-11-17 21:20 - 2017-02-15 12:37 - 0002491 _____ () C:\Users\dferrier\AppData\Roaming\LT3.MTBF.txt
2017-03-07 21:19 - 2017-03-07 21:19 - 0000600 _____ () C:\Users\dferrier\AppData\Roaming\PUTTY.RND
2017-05-19 09:38 - 2017-05-19 09:38 - 0000000 ____H () C:\Users\dferrier\AppData\Local\.urbackupclientgui_startonce
2015-11-17 22:04 - 2017-05-05 21:55 - 0007680 _____ () C:\Users\dferrier\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-11-17 15:08 - 2015-11-17 15:08 - 0000000 _____ () C:\Users\dferrier\AppData\Local\Driver_11ACPresent.flag
2016-09-18 19:04 - 2017-06-23 07:08 - 0000600 _____ () C:\Users\dferrier\AppData\Local\PUTTY.RND
2017-06-18 22:03 - 2017-06-18 22:03 - 0002205 _____ () C:\Users\dferrier\AppData\Local\recently-used.xbel
2015-12-26 19:07 - 2015-09-25 04:21 - 0016800 _____ () C:\Users\dferrier\AppData\Local\Z@!-5946ba91-ed5f-41a8-8801-12c6dbd9f3de.tmp
2015-12-26 19:07 - 2015-09-25 04:21 - 0015776 _____ () C:\Users\dferrier\AppData\Local\Z@S!-83152ba7-24c1-4572-9f40-f7b7dcf1c59d.tmp
2016-12-29 14:33 - 2017-01-02 21:55 - 0000143 _____ () C:\Users\dferrier\AppData\Local\zenmap.exe.log
2016-12-08 08:50 - 2017-05-10 21:15 - 0000085 ___SH () C:\ProgramData\.zreglib
2015-11-21 14:48 - 2015-11-21 14:48 - 0000115 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc
2015-11-21 14:06 - 2015-11-21 14:37 - 0000238 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.351.64.bc
2016-06-27 00:41 - 2016-06-27 00:41 - 0000090 _____ () C:\ProgramData\Temp.log
Some files in TEMP:
====================
2017-04-10 12:15 - 2017-04-10 12:15 - 10468271 _____ () C:\Users\dferrier\AppData\Local\Temp\handbrake-setup.exe
2016-08-25 16:43 - 2016-08-25 16:43 - 15301888 _____ (Microsoft Corporation) C:\Users\dferrier\AppData\Local\Temp\vc_redist_2015.x64.exe
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2017-06-18 02:48
==================== End of FRST.txt ============================