After an Avast update, my computer kept locking up while browsing, unless I disabled Avast. Since then, my computer seems slower, and I found a suspicious file:
C:\32788R22FWJFW\EN-US\cmd.3XE.mui
Frst.txt
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:01-12-2015
Ran by Andree Rezai (administrator) on ANDREEREZAI-PC (04-12-2015 13:37:06)
Running from C:\Users\Andree Rezai\Desktop
Loaded Profiles: Andree Rezai (Available Profiles: Andree Rezai)
Platform: Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) Language: English (United States)
Internet Explorer Version 9 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [7021880 2015-12-04] (AVAST Software)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2015-12-04] (AVAST Software)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
Tcpip\..\Interfaces\{D17C858C-B8C6-4EFE-8C0F-EBC2C2848AE3}: [DhcpNameServer] 192.168.2.1
Internet Explorer:
==================
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-2436680478-200282203-879032571-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-2436680478-200282203-879032571-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yahoo.com/
SearchScopes: HKU\S-1-5-21-2436680478-200282203-879032571-1000 -> DefaultScope {7B9F4103-F692-470F-AF26-D23F5E4E2F3D} URL = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}&rlz=1I7ADSA_en
SearchScopes: HKU\S-1-5-21-2436680478-200282203-879032571-1000 -> {7B9F4103-F692-470F-AF26-D23F5E4E2F3D} URL = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}&rlz=1I7ADSA_en
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_66\bin\ssv.dll [2015-11-24] (Oracle Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-12-04] (AVAST Software)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_66\bin\jp2ssv.dll [2015-11-24] (Oracle Corporation)
Toolbar: HKU\S-1-5-21-2436680478-200282203-879032571-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_17-windows-i586.cab
DPF: {CAFEEFAC-0017-0000-0009-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_09-windows-i586.cab
DPF: {CAFEEFAC-0017-0000-0017-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_17-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_17-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
FireFox:
========
FF ProfilePath: C:\Users\Andree Rezai\AppData\Roaming\Mozilla\Firefox\Profiles\n57uf3ip.default
FF DefaultSearchEngine: Google
FF DefaultSearchEngine.US: Google
FF Homepage: hxxp://www.google.com/
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_19_0_0_245.dll [2015-11-10] ()
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf -> C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2015-02-11] (Foxit Corporation)
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf -> C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2015-02-11] (Foxit Corporation)
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xdp -> C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2015-02-11] (Foxit Corporation)
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xfdf -> C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2015-02-11] (Foxit Corporation)
FF Plugin: @java.com/DTPlugin,version=11.66.2 -> C:\Program Files\Java\jre1.8.0_66\bin\dtplugin\npDeployJava1.dll [2015-11-24] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.66.2 -> C:\Program Files\Java\jre1.8.0_66\bin\plugin2\npjp2.dll [2015-11-24] (Oracle Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-03] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-03] (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.1.0 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.3 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.0 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-02] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-2436680478-200282203-879032571-1000: @facebook.com/FBPlugin,version=1.0.1 -> C:\Users\Andree Rezai\AppData\Roaming\Facebook\npfbplugin_1_0_1.dll [2010-02-01] ( )
FF Plugin HKU\S-1-5-21-2436680478-200282203-879032571-1000: @yahoo.com/BrowserPlus,version=2.9.8 -> C:\Users\Andree Rezai\AppData\Local\Yahoo!\BrowserPlus\2.9.8\Plugins\npybrowserplus_2.9.8.dll [2010-08-04] (Yahoo! Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll [2014-12-02] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin.dll [2015-09-01] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll [2015-09-01] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll [2015-09-01] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll [2015-09-01] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll [2015-09-01] (Apple Inc.)
FF Extension: Microsoft .NET Framework Assistant - C:\Users\Andree Rezai\AppData\Roaming\Mozilla\Firefox\Profiles\n57uf3ip.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b}.xpi [2012-03-17] [not signed]
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} [2015-11-06] [not signed]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2009-12-01] [not signed]
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2015-12-04]
Chrome:
=======
CHR HomePage: Default -> hxxp://www.google.com
CHR StartupUrls: Default -> "hxxp://canogaparkhs.org/","hxxp://misis.lausd.net/start","hxxp://home.lausd.net/","hxxp://mail.lausd.net/"
CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\44.0.2403.155\ppGoogleNaClPluginChrome.dll => No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\44.0.2403.155\pdf.dll => No File
CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\44.0.2403.155\gcswf32.dll => No File
CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32_11_2_202_233.dll => No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll => No File
CHR Plugin: (Java Deployment Toolkit 6.0.310.5) - C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll => No File
CHR Plugin: (Java(TM) Platform SE 6 U31) - C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll => No File
CHR Plugin: (downloadUpdater) - C:\Program Files\Mozilla Firefox\plugins\npdnu.dll => No File
CHR Plugin: (downloadUpdater2) - C:\Program Files\Mozilla Firefox\plugins\npdnupdater2.dll => No File
CHR Plugin: (QuickTime Plug-in 7.1.3) - C:\Program Files\QuickTime\plugins\npqtplugin.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.1.3) - C:\Program Files\QuickTime\plugins\npqtplugin2.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.1.3) - C:\Program Files\QuickTime\plugins\npqtplugin3.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.1.3) - C:\Program Files\QuickTime\plugins\npqtplugin4.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.1.3) - C:\Program Files\QuickTime\plugins\npqtplugin5.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.1.3) - C:\Program Files\QuickTime\plugins\npqtplugin6.dll => No File
CHR Plugin: (QuickTime Plug-in 7.1.3) - C:\Program Files\QuickTime\plugins\npqtplugin7.dll => No File
CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll => No File
CHR Plugin: (BrowserPlus (from Yahoo!) v2.9.8) - C:\Users\Andree Rezai\AppData\Local\Yahoo!\BrowserPlus\2.9.8\Plugins\npybrowserplus_2.9.8.dll (Yahoo! Inc.)
CHR Plugin: (Facebook Plugin) - C:\Users\Andree Rezai\AppData\Roaming\Facebook\npfbplugin_1_0_1.dll ( )
CHR Plugin: (Shockwave for Director) - C:\Windows\system32\Adobe\Director\np32dsw.dll => No File
CHR Plugin: (Silverlight Plug-In) - c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll => No File
CHR Plugin: (Windows Presentation Foundation) - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
CHR Profile: C:\Users\Andree Rezai\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Avast Online Security) - C:\Users\Andree Rezai\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2015-08-12]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Andree Rezai\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-08-12]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Andree Rezai\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-08-12]
CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-12-04]
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [226440 2015-12-04] (AVAST Software)
S3 IJPLMSVC; C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE [103808 2008-01-22] ()
S4 MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [1513784 2015-10-05] (Malwarebytes)
S2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [272952 2008-01-20] (Microsoft Corporation)
S2 FoxitCloudUpdateService; "C:\Program Files\Foxit Software\Foxit Reader\Foxit Cloud\FCUpdateService.exe" [X]
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [24016 2015-12-04] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [81168 2015-12-04] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr.sys [55200 2015-12-04] (AVAST Software)
S0 aswRvrt; C:\Windows\system32\Drivers\aswRvrt.sys [49776 2015-12-04] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [794952 2015-12-04] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [435976 2015-12-04] (AVAST Software)
R3 aswStmXP; C:\Windows\system32\drivers\aswStmXP.sys [165104 2015-12-04] (AVAST Software)
R3 aswTdi; C:\Windows\system32\drivers\aswTdi.sys [58016 2015-12-04] (AVAST Software)
R0 aswVmm; C:\Windows\system32\Drivers\aswVmm.sys [209432 2015-12-04] (AVAST Software)
R1 HWiNFO32; C:\Windows\system32\drivers\HWiNFO32.SYS [23840 2015-12-02] (REALiX(tm))
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2015-10-05] (Malwarebytes)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2015-10-05] (Malwarebytes Corporation)
R3 NETwLv32; C:\Windows\System32\DRIVERS\NETwLv32.sys [6639616 2015-12-02] (Intel Corporation)
S3 NuidFltr; C:\Windows\System32\DRIVERS\NuidFltr.sys [14736 2009-05-09] (Microsoft Corporation)
U5 AppMgmt; C:\Windows\system32\svchost.exe [21504 2008-01-20] (Microsoft Corporation)
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-12-04 13:37 - 2015-12-04 13:37 - 00015318 _____ C:\Users\Andree Rezai\Desktop\FRST.txt
2015-12-04 13:35 - 2015-12-04 13:37 - 00000000 ____D C:\FRST
2015-12-04 13:32 - 2015-12-04 13:33 - 01721344 _____ (Farbar) C:\Users\Andree Rezai\Desktop\FRST.exe
2015-12-04 13:14 - 2015-12-04 13:09 - 00794952 _____ (AVAST Software) C:\Windows\system32\Drivers\aswEBAB.tmp
2015-12-04 13:14 - 2015-12-04 13:09 - 00435976 _____ (AVAST Software) C:\Windows\system32\Drivers\aswF35D.tmp
2015-12-04 13:14 - 2015-12-04 13:09 - 00322760 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2015-12-04 13:14 - 2015-12-04 13:09 - 00209432 _____ (AVAST Software) C:\Windows\system32\Drivers\aswF477.tmp
2015-12-04 13:14 - 2015-12-04 13:09 - 00165104 _____ (AVAST Software) C:\Windows\system32\Drivers\aswF572.tmp
2015-12-04 13:14 - 2015-12-04 13:09 - 00081168 _____ (AVAST Software) C:\Windows\system32\Drivers\aswF08E.tmp
2015-12-04 13:14 - 2015-12-04 13:09 - 00058016 _____ (AVAST Software) C:\Windows\system32\Drivers\aswF6BB.tmp
2015-12-04 13:14 - 2015-12-04 13:09 - 00055200 _____ (AVAST Software) C:\Windows\system32\Drivers\aswED80.tmp
2015-12-04 13:14 - 2015-12-04 13:09 - 00049776 _____ (AVAST Software) C:\Windows\system32\Drivers\aswF198.tmp
2015-12-04 13:14 - 2015-12-04 13:09 - 00024016 _____ (AVAST Software) C:\Windows\system32\Drivers\aswEED8.tmp
2015-12-04 13:10 - 2015-12-04 13:10 - 00000000 ____D C:\Users\Andree Rezai\AppData\Roaming\AVAST Software
2015-12-04 13:10 - 2015-12-04 13:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
2015-12-04 13:09 - 2015-12-04 13:09 - 00794952 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2015-12-04 13:09 - 2015-12-04 13:09 - 00435976 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2015-12-04 13:09 - 2015-12-04 13:09 - 00209432 _____ (AVAST Software) C:\Windows\system32\Drivers\aswVmm.sys
2015-12-04 13:09 - 2015-12-04 13:09 - 00165104 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStmXP.sys
2015-12-04 13:09 - 2015-12-04 13:09 - 00081168 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2015-12-04 13:09 - 2015-12-04 13:09 - 00058016 _____ (AVAST Software) C:\Windows\system32\Drivers\aswTdi.sys
2015-12-04 13:09 - 2015-12-04 13:09 - 00055200 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr.sys
2015-12-04 13:09 - 2015-12-04 13:09 - 00049776 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys
2015-12-04 13:09 - 2015-12-04 13:09 - 00043112 _____ (AVAST Software) C:\Windows\avastSS.scr
2015-12-04 13:09 - 2015-12-04 13:09 - 00024016 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHwid.sys
2015-12-04 13:05 - 2015-12-04 13:05 - 00000000 ____D C:\Program Files\AVAST Software
2015-12-04 12:51 - 2015-12-04 12:51 - 05084256 _____ (AVAST Software) C:\Users\Andree Rezai\Downloads\avast_free_antivirus_setup_online_cnet2.exe
2015-12-03 15:20 - 2015-12-03 15:20 - 00000259 _____ C:\Users\Andree Rezai\Desktop\Virus and Malware Removal - TechSpot Forums.URL
2015-12-02 12:55 - 2015-12-02 12:55 - 00002101 _____ C:\Users\Andree Rezai\Desktop\JRT.txt
2015-12-02 12:28 - 2015-12-02 12:28 - 00000000 ____H C:\ProgramData\DP45977C.lfl
2015-12-02 12:27 - 2015-12-02 12:27 - 00000000 ____D C:\Windows\system32\DAX2
2015-12-02 12:26 - 2015-12-02 12:26 - 00000000 ____D C:\Windows\system32\RTCOM
2015-12-02 12:26 - 2015-12-02 12:26 - 00000000 ____D C:\Program Files\Realtek
2015-12-02 12:22 - 2015-12-02 12:22 - 72113152 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RCoRes.dat
2015-12-02 12:22 - 2015-12-02 12:22 - 13789440 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioRealtek.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 11899824 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxVoiceAPO30.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 11785136 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxVoiceAPO40.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 07162128 _____ (Dolby Laboratories) C:\Windows\system32\R4EEP32A.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 07044952 _____ (Dolby Laboratories) C:\Windows\system32\DDPP32A.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 05804772 _____ C:\Windows\system32\Drivers\rtvienna.dat
2015-12-02 12:22 - 2015-12-02 12:22 - 05073344 _____ (Nahimic Inc) C:\Windows\system32\NAHIMICV2apo.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 04713224 _____ (Nahimic Inc) C:\Windows\system32\NAHIMICAPOlfx.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 03522264 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\Drivers\RTKVHDA.sys
2015-12-02 12:22 - 2015-12-02 12:22 - 02862488 _____ C:\Windows\system32\Drivers\RTAIODAT.DAT
2015-12-02 12:22 - 2015-12-02 12:22 - 02820120 _____ (Fortemedia Corporation) C:\Windows\system32\FMAPO.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 02637528 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTSndMgr.cpl
2015-12-02 12:22 - 2015-12-02 12:22 - 02630872 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkPgExt.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 02585816 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RltkAPO.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 02394328 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkApoApi.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 02370480 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO70.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 01940056 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioEQ.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 01861976 _____ (Dolby Laboratories) C:\Windows\system32\DolbyDAX2APOv211.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 01823320 _____ (Waves Audio Ltd.) C:\Windows\system32\WavesGUILib.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 01783056 _____ (Waves Audio Ltd.) C:\Windows\system32\WavesLib.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 01782616 _____ (Dolby Laboratories) C:\Windows\system32\DolbyDAX2APOv201.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 01708248 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCoInstII.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 01509480 _____ (DTS) C:\Windows\system32\DTSS2SpeakerDLL.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 01490960 _____ (Conexant Systems Inc.) C:\Windows\system32\CX32APO.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 01490264 _____ (Dolby Laboratories) C:\Windows\system32\DDPD32A.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 01379760 _____ (TOSHIBA Corporation) C:\Windows\system32\tosade.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 01292904 _____ (DTS) C:\Windows\system32\DTSS2HeadphoneDLL.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 01220200 _____ (DTS) C:\Windows\system32\DTSBoostDLL.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 01160112 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO60.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 01055888 _____ (Synopsys, Inc.) C:\Windows\system32\SRRPTR.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 01022120 _____ (SRS Labs, Inc.) C:\Windows\system32\slcnt32.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 01010096 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO50.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00973232 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO40.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00948336 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxSpeechAPO.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00945456 _____ (Nahimic Inc) C:\Windows\system32\NahimicAPONSControl.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00919600 _____ (Sony Corporation) C:\Windows\system32\SFSS_APO.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00865960 _____ (DTS, Inc.) C:\Windows\system32\sl3apo32.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00852016 _____ (Sony Corporation) C:\Windows\system32\MISS_APO.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00850264 _____ (Dolby Laboratories) C:\Windows\system32\DolbyDAX2APOProp.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00844192 _____ (TOSHIBA Corporation) C:\Windows\system32\tadefxapo2.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00818096 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxVoiceAPO20.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00790272 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPOShell.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00704656 _____ (Sound Research, Corp.) C:\Windows\system32\SEHDRA32.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00654952 _____ (DTS) C:\Windows\system32\DTSBassEnhancementDLL.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00631400 _____ (DTS) C:\Windows\system32\DTSSymmetryDLL.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00611496 _____ (DTS, Inc.) C:\Windows\system32\sltech32.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00601704 _____ (DTS) C:\Windows\system32\DTSVoiceClarityDLL.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00555664 _____ (Sound Research, Corp.) C:\Windows\system32\SECOMN32.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00519368 _____ (Andrea Electronics Corporation) C:\Windows\system32\AERTACap.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00509184 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxVolumeSDAPO.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00509184 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO30.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00458344 _____ (DTS) C:\Windows\system32\DTSNeoPCDLL.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00426944 _____ (DTS) C:\Windows\system32\DTSU2PLFX32.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00403392 _____ (DTS) C:\Windows\system32\DTSU2PGFX32.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00389736 _____ (DTS) C:\Windows\system32\DTSGainCompensatorDLL.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00388752 _____ (Synopsys, Inc.) C:\Windows\system32\SRAPO.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00375400 _____ (DTS) C:\Windows\system32\DTSLimiterDLL.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00372368 _____ (Sound Research, Corp.) C:\Windows\system32\SEAPO32.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00359768 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEP32A.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00357712 _____ (Knowles Acoustics ) C:\Windows\system32\KAAPORT.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00352016 _____ (Dolby Laboratories) C:\Windows\system32\R4EED32A.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00346048 _____ (DTS) C:\Windows\system32\DTSU2PREC32.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00345328 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSTSXT.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00329360 _____ (Synopsys, Inc.) C:\Windows\system32\SRCOM.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00296560 _____ (ICEpower a/s) C:\Windows\system32\ICEsoundAPO.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00295768 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RP3DHT32.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00295768 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RP3DAA32.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00294744 _____ (Dolby Laboratories) C:\Windows\system32\HiFiDAX2API.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00274264 _____ (Dolby Laboratories) C:\Windows\system32\DDPO32A.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00232792 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO20.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00223912 _____ (TODO: <Company name>) C:\Windows\system32\slprp32.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00221528 _____ (Dolby Laboratories) C:\Windows\system32\DDPA32.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00220088 _____ (TOSHIBA Corporation) C:\Windows\system32\tossaemaxapo32.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00218728 _____ (DTS) C:\Windows\system32\DTSGFXAPONS.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00218728 _____ (DTS) C:\Windows\system32\DTSGFXAPO.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00218216 _____ (DTS) C:\Windows\system32\DTSLFXAPO.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00214368 _____ (Synopsys, Inc.) C:\Windows\system32\SFNHK.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00188696 _____ C:\Windows\system32\AcpiServiceVnA.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00185584 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSTSHD.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00173296 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSHP360.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00170840 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEED32A.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00140528 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSWOW.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00134584 _____ (TOSHIBA Corporation) C:\Windows\system32\tadefxapo.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00132368 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00106768 _____ (Dolby Laboratories) C:\Windows\system32\R4EEL32A.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00095840 _____ (Andrea Electronics Corporation) C:\Windows\system32\AERTARen.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00092584 _____ (Real Sound Lab SIA) C:\Windows\system32\CONEQMSAPOGUILibrary.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00091920 _____ (Dolby Laboratories) C:\Windows\system32\R4EEA32A.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00087864 _____ C:\Windows\system32\audioLibVc.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00078680 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEL32A.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00074080 _____ (Synopsys, Inc.) C:\Windows\system32\SFCOM.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00068960 _____ (Synopsys, Inc.) C:\Windows\system32\SFAPO.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00064856 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEG32A.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00062224 _____ (Dolby Laboratories) C:\Windows\system32\R4EEG32A.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00058264 _____ (TOSHIBA CORPORATION.) C:\Windows\system32\TepeqAPO.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00013416 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCoLDR.dll
2015-12-02 11:56 - 2015-12-02 11:56 - 06639616 _____ (Intel Corporation) C:\Windows\system32\Drivers\NETwLv32.sys
2015-12-02 11:56 - 2015-12-02 11:56 - 02756608 _____ (Intel Corporation) C:\Windows\system32\NETwLr32.dll
2015-12-02 11:56 - 2015-12-02 11:56 - 00675840 _____ (Intel Corporation) C:\Windows\system32\NETwLc32.dll
2015-12-02 11:51 - 2015-12-02 11:51 - 00311296 _____ (Marvell) C:\Windows\system32\Drivers\yk60x86.sys
2015-12-02 11:51 - 2015-12-02 11:51 - 00282624 _____ (Marvell) C:\Windows\system32\ykx32mpcoinst.dll
2015-12-02 11:46 - 2015-12-02 11:46 - 00000000 ____D C:\Users\Public\Foxit Software
2015-12-02 11:45 - 2015-12-02 11:45 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Foxit Reader
2015-12-02 11:43 - 2015-12-02 12:53 - 00000000 ____D C:\Users\Andree Rezai\AppData\Roaming\IObit
2015-12-02 11:43 - 2015-12-02 12:53 - 00000000 ____D C:\ProgramData\IObit
2015-12-02 11:43 - 2015-12-02 11:45 - 00000000 ____D C:\Users\Andree Rezai\AppData\LocalLow\IObit
2015-12-02 11:43 - 2015-12-02 11:43 - 00023840 _____ (REALiX(tm)) C:\Windows\system32\Drivers\HWiNFO32.SYS
2015-12-02 11:43 - 2015-12-02 11:43 - 00000000 ____D C:\Windows\Tasks\ImCleanDisabled
2015-12-02 11:42 - 2015-12-02 11:46 - 00000000 ____D C:\PatchMyPCUpdates
2015-12-02 11:42 - 2015-12-02 11:42 - 00000764 _____ C:\Users\Public\Desktop\CCleaner.lnk
2015-12-02 11:11 - 2015-12-02 11:11 - 00000000 ____D C:\Users\Andree Rezai\AppData\Roaming\CrystalIdea Software
2015-11-24 23:55 - 2015-11-24 23:55 - 00000000 ____D C:\Program Files\Common Files\Java
2015-11-18 03:17 - 2015-11-18 03:17 - 00014365 _____ C:\Users\Andree Rezai\Downloads\POLY_DIV_Qz.pdf
2015-11-18 03:15 - 2015-11-18 03:15 - 00015516 _____ C:\Users\Andree Rezai\Downloads\INV_FUN2.pdf
2015-11-15 23:09 - 2015-11-15 23:09 - 00073468 _____ C:\Users\Andree Rezai\Downloads\doc08.pdf
2015-11-11 01:19 - 2015-10-17 06:24 - 02068480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-11-11 01:09 - 2015-10-17 08:01 - 00501248 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-11-11 01:09 - 2015-10-13 06:31 - 00273408 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2015-11-11 01:09 - 2015-10-13 06:31 - 00072192 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys
2015-11-11 01:08 - 2015-10-14 12:22 - 01206192 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2015-11-11 01:08 - 2015-10-14 08:01 - 03606464 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2015-11-11 01:08 - 2015-10-14 08:01 - 03554752 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-11-11 01:04 - 2015-10-10 08:02 - 00526272 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys
2015-11-11 01:00 - 2015-09-26 08:05 - 00281600 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-11-11 01:00 - 2015-09-26 08:04 - 00206336 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-11-11 01:00 - 2015-09-26 05:21 - 00274432 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll
2015-11-11 01:00 - 2015-09-22 05:11 - 00440768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-11-10 23:40 - 2015-10-31 10:40 - 12376576 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-11-10 23:40 - 2015-10-31 10:38 - 09727488 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-11-10 23:40 - 2015-10-31 10:38 - 00367616 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-11-10 23:40 - 2015-10-31 10:37 - 01830912 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-11-10 23:40 - 2015-10-31 10:36 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-11-10 23:40 - 2015-10-31 10:36 - 01789440 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-11-10 23:40 - 2015-10-31 10:36 - 01436160 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-11-10 23:40 - 2015-10-31 10:36 - 01093632 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-11-10 23:40 - 2015-10-31 10:36 - 01088512 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-11-10 23:40 - 2015-10-31 10:36 - 00711168 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-11-10 23:40 - 2015-10-31 10:36 - 00615424 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-11-10 23:40 - 2015-10-31 10:36 - 00412672 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-11-10 23:40 - 2015-10-31 10:36 - 00358400 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-11-10 23:40 - 2015-10-31 10:36 - 00232960 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2015-11-10 23:40 - 2015-10-31 10:36 - 00216064 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-11-10 23:40 - 2015-10-31 10:36 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-11-10 23:40 - 2015-10-31 10:36 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-11-10 23:40 - 2015-10-31 10:36 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-11-10 23:40 - 2015-10-31 10:36 - 00064512 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-11-10 23:40 - 2015-10-31 10:36 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2015-11-10 23:40 - 2015-10-31 10:36 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2015-11-10 23:40 - 2015-10-31 10:36 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2015-11-08 11:37 - 2015-11-08 11:37 - 00000330 _____ C:\Users\Andree Rezai\Desktop\Agoura Hills, CA - Google Maps.URL
2015-11-07 23:26 - 2015-11-07 23:26 - 00000263 _____ C:\Users\Andree Rezai\Desktop\Search Results.URL
2015-11-07 12:13 - 2015-11-07 12:13 - 00055897 _____ C:\Users\Andree Rezai\Downloads\availability-list-spring-2014.pdf
2015-11-06 22:30 - 2015-11-06 22:30 - 00663025 _____ C:\Users\Andree Rezai\Downloads\burbot.pdf
2015-11-06 16:46 - 2015-11-06 16:46 - 00091311 _____ C:\Users\Andree Rezai\Downloads\abalone.pdf
2015-11-06 10:17 - 2015-11-07 17:28 - 00000000 ____D C:\Program Files\Mozilla Firefox
2015-11-04 20:57 - 2015-11-04 20:57 - 01259940 _____ C:\Users\Andree Rezai\Downloads\060_Iglesiasetal2005.pdf
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-12-04 13:36 - 2006-11-02 03:18 - 00000000 ____D C:\Windows
2015-12-04 12:52 - 2012-03-29 10:48 - 00000000 ____D C:\ProgramData\AVAST Software
2015-12-04 12:48 - 2009-11-29 10:07 - 00000886 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-12-04 12:45 - 2012-06-14 08:22 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-12-04 12:40 - 2012-11-19 12:51 - 00002096 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2015-12-04 12:40 - 2012-11-19 12:51 - 00002096 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2015-12-04 12:40 - 2009-11-29 10:07 - 00000882 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-12-04 12:40 - 2006-11-02 05:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-12-04 03:20 - 2006-11-02 05:01 - 00032582 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2015-12-02 17:06 - 2009-11-29 14:03 - 00000000 ____D C:\Users\Andree Rezai\AppData\Roaming\Macromedia
2015-12-02 12:51 - 2015-01-27 14:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2015-12-02 12:51 - 2009-11-29 15:34 - 00000000 ____D C:\Program Files\Java
2015-12-02 12:37 - 2006-11-02 03:18 - 00000000 ____D C:\Windows\system32\spool
2015-12-02 12:35 - 2009-11-29 10:07 - 00000000 ____D C:\Program Files\Google
2015-12-02 12:26 - 2009-11-29 08:54 - 00000000 ____D C:\Users\Andree Rezai
2015-12-02 12:25 - 2006-11-02 03:18 - 00000000 ____D C:\Windows\inf
2015-12-02 12:00 - 2012-11-20 19:21 - 00006526 _____ C:\Windows\system32\PerfStringBackup.TMP
2015-12-02 11:37 - 2009-11-29 07:30 - 00000000 ____D C:\Windows.old
2015-12-02 11:37 - 2006-11-02 03:18 - 00000000 ___SD C:\Windows\Downloaded Program Files
2015-12-02 11:28 - 2009-11-29 15:27 - 00000000 ____D C:\Windows\PCHEALTH
2015-12-02 11:28 - 2006-11-02 03:18 - 00000000 ____D C:\Windows\security
2015-12-02 11:16 - 2009-12-04 19:51 - 00000000 ____D C:\Users\Andree Rezai\AppData\LocalLow\Macromedia
2015-12-02 11:16 - 2009-12-04 19:51 - 00000000 ____D C:\Users\Andree Rezai\AppData\LocalLow\Adobe
2015-12-02 11:15 - 2009-12-04 19:51 - 00000000 ____D C:\ProgramData\Google
2015-12-02 11:15 - 2009-11-29 10:07 - 00000000 ____D C:\Users\Andree Rezai\AppData\Local\Google
2015-12-02 11:14 - 2013-03-26 09:54 - 00000000 ____D C:\Program Files\7-Zip
2015-11-30 11:59 - 2015-03-29 08:08 - 00000000 ____D C:\Windows\system32\vbox
2015-11-25 12:42 - 2014-06-16 08:26 - 00170200 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-11-25 12:36 - 2009-12-05 07:12 - 00000059 _____ C:\Windows\wpd99.drv
2015-11-25 12:36 - 2009-12-05 07:12 - 00000000 ____D C:\ProgramData\pdf995
2015-11-25 01:06 - 2009-11-29 08:32 - 00000000 ____D C:\Windows\Panther
2015-11-24 23:55 - 2015-09-01 14:54 - 00000000 ____D C:\Users\Andree Rezai\.oracle_jre_usage
2015-11-24 23:53 - 2015-01-27 14:09 - 00095840 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2015-11-11 17:11 - 2014-12-16 16:37 - 00000000 ____D C:\Users\Andree Rezai\Desktop\Grade Pro
2015-11-11 10:57 - 2006-11-02 03:18 - 00000000 ____D C:\Windows\rescache
2015-11-11 10:40 - 2006-11-02 04:47 - 00303576 _____ C:\Windows\system32\FNTCACHE.DAT
2015-11-11 10:35 - 2006-11-02 04:37 - 00000000 ____D C:\Program Files\Windows Journal
2015-11-11 10:35 - 2006-11-02 03:18 - 00000000 ____D C:\Windows\PolicyDefinitions
2015-11-11 01:19 - 2013-08-14 02:20 - 00000000 ____D C:\Windows\system32\MRT
2015-11-11 01:11 - 2006-11-02 02:24 - 143250520 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2015-11-11 01:10 - 2009-11-29 15:25 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-11-10 17:45 - 2012-03-27 21:20 - 00780488 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-11-10 17:45 - 2012-03-17 13:13 - 00142536 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-11-07 17:28 - 2012-04-25 06:26 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
==================== Files in the root of some directories =======
2010-01-22 15:34 - 2015-10-16 23:34 - 0001596 _____ () C:\Users\Andree Rezai\AppData\Roaming\Sketchpad 5 Preferences.dat
2014-10-31 13:56 - 2014-10-31 13:56 - 0000680 _____ () C:\Users\Andree Rezai\AppData\Local\d3d9caps.dat
2009-11-29 09:27 - 2015-07-28 17:55 - 0102912 _____ () C:\Users\Andree Rezai\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-12-02 12:28 - 2015-12-02 12:28 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
Files to move or delete:
====================
C:\Users\Andree Rezai\instmsia.exe
C:\Users\Andree Rezai\instmsiw.exe
C:\Users\Andree Rezai\setup.exe
Some files in TEMP:
====================
C:\Users\Andree Rezai\AppData\Local\Temp\FoxitUpdater.exe
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-12-04 12:47
==================== End of FRST.txt ============================
C:\32788R22FWJFW\EN-US\cmd.3XE.mui
Frst.txt
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:01-12-2015
Ran by Andree Rezai (administrator) on ANDREEREZAI-PC (04-12-2015 13:37:06)
Running from C:\Users\Andree Rezai\Desktop
Loaded Profiles: Andree Rezai (Available Profiles: Andree Rezai)
Platform: Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) Language: English (United States)
Internet Explorer Version 9 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [7021880 2015-12-04] (AVAST Software)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2015-12-04] (AVAST Software)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
Tcpip\..\Interfaces\{D17C858C-B8C6-4EFE-8C0F-EBC2C2848AE3}: [DhcpNameServer] 192.168.2.1
Internet Explorer:
==================
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-2436680478-200282203-879032571-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-2436680478-200282203-879032571-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yahoo.com/
SearchScopes: HKU\S-1-5-21-2436680478-200282203-879032571-1000 -> DefaultScope {7B9F4103-F692-470F-AF26-D23F5E4E2F3D} URL = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}&rlz=1I7ADSA_en
SearchScopes: HKU\S-1-5-21-2436680478-200282203-879032571-1000 -> {7B9F4103-F692-470F-AF26-D23F5E4E2F3D} URL = hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}&rlz=1I7ADSA_en
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_66\bin\ssv.dll [2015-11-24] (Oracle Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-12-04] (AVAST Software)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_66\bin\jp2ssv.dll [2015-11-24] (Oracle Corporation)
Toolbar: HKU\S-1-5-21-2436680478-200282203-879032571-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_17-windows-i586.cab
DPF: {CAFEEFAC-0017-0000-0009-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_09-windows-i586.cab
DPF: {CAFEEFAC-0017-0000-0017-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_17-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_17-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
FireFox:
========
FF ProfilePath: C:\Users\Andree Rezai\AppData\Roaming\Mozilla\Firefox\Profiles\n57uf3ip.default
FF DefaultSearchEngine: Google
FF DefaultSearchEngine.US: Google
FF Homepage: hxxp://www.google.com/
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_19_0_0_245.dll [2015-11-10] ()
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf -> C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2015-02-11] (Foxit Corporation)
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf -> C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2015-02-11] (Foxit Corporation)
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xdp -> C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2015-02-11] (Foxit Corporation)
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xfdf -> C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2015-02-11] (Foxit Corporation)
FF Plugin: @java.com/DTPlugin,version=11.66.2 -> C:\Program Files\Java\jre1.8.0_66\bin\dtplugin\npDeployJava1.dll [2015-11-24] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.66.2 -> C:\Program Files\Java\jre1.8.0_66\bin\plugin2\npjp2.dll [2015-11-24] (Oracle Corporation)
FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll [2008-07-29] (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-03] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-03] (Google Inc.)
FF Plugin: @videolan.org/vlc,version=2.1.0 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.3 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.0 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-02] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-2436680478-200282203-879032571-1000: @facebook.com/FBPlugin,version=1.0.1 -> C:\Users\Andree Rezai\AppData\Roaming\Facebook\npfbplugin_1_0_1.dll [2010-02-01] ( )
FF Plugin HKU\S-1-5-21-2436680478-200282203-879032571-1000: @yahoo.com/BrowserPlus,version=2.9.8 -> C:\Users\Andree Rezai\AppData\Local\Yahoo!\BrowserPlus\2.9.8\Plugins\npybrowserplus_2.9.8.dll [2010-08-04] (Yahoo! Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll [2014-12-02] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin.dll [2015-09-01] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll [2015-09-01] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll [2015-09-01] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll [2015-09-01] (Apple Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll [2015-09-01] (Apple Inc.)
FF Extension: Microsoft .NET Framework Assistant - C:\Users\Andree Rezai\AppData\Roaming\Mozilla\Firefox\Profiles\n57uf3ip.default\Extensions\{20a82645-c095-46ed-80e3-08825760534b}.xpi [2012-03-17] [not signed]
FF Extension: Java Console - C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} [2015-11-06] [not signed]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2009-12-01] [not signed]
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2015-12-04]
Chrome:
=======
CHR HomePage: Default -> hxxp://www.google.com
CHR StartupUrls: Default -> "hxxp://canogaparkhs.org/","hxxp://misis.lausd.net/start","hxxp://home.lausd.net/","hxxp://mail.lausd.net/"
CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\44.0.2403.155\ppGoogleNaClPluginChrome.dll => No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\44.0.2403.155\pdf.dll => No File
CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\44.0.2403.155\gcswf32.dll => No File
CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32_11_2_202_233.dll => No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll => No File
CHR Plugin: (Java Deployment Toolkit 6.0.310.5) - C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll => No File
CHR Plugin: (Java(TM) Platform SE 6 U31) - C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll => No File
CHR Plugin: (downloadUpdater) - C:\Program Files\Mozilla Firefox\plugins\npdnu.dll => No File
CHR Plugin: (downloadUpdater2) - C:\Program Files\Mozilla Firefox\plugins\npdnupdater2.dll => No File
CHR Plugin: (QuickTime Plug-in 7.1.3) - C:\Program Files\QuickTime\plugins\npqtplugin.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.1.3) - C:\Program Files\QuickTime\plugins\npqtplugin2.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.1.3) - C:\Program Files\QuickTime\plugins\npqtplugin3.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.1.3) - C:\Program Files\QuickTime\plugins\npqtplugin4.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.1.3) - C:\Program Files\QuickTime\plugins\npqtplugin5.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.1.3) - C:\Program Files\QuickTime\plugins\npqtplugin6.dll => No File
CHR Plugin: (QuickTime Plug-in 7.1.3) - C:\Program Files\QuickTime\plugins\npqtplugin7.dll => No File
CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll => No File
CHR Plugin: (BrowserPlus (from Yahoo!) v2.9.8) - C:\Users\Andree Rezai\AppData\Local\Yahoo!\BrowserPlus\2.9.8\Plugins\npybrowserplus_2.9.8.dll (Yahoo! Inc.)
CHR Plugin: (Facebook Plugin) - C:\Users\Andree Rezai\AppData\Roaming\Facebook\npfbplugin_1_0_1.dll ( )
CHR Plugin: (Shockwave for Director) - C:\Windows\system32\Adobe\Director\np32dsw.dll => No File
CHR Plugin: (Silverlight Plug-In) - c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll => No File
CHR Plugin: (Windows Presentation Foundation) - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
CHR Profile: C:\Users\Andree Rezai\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Avast Online Security) - C:\Users\Andree Rezai\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2015-08-12]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Andree Rezai\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-08-12]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Andree Rezai\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-08-12]
CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-12-04]
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [226440 2015-12-04] (AVAST Software)
S3 IJPLMSVC; C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE [103808 2008-01-22] ()
S4 MBAMScheduler; C:\Program Files\Malwarebytes Anti-Malware\mbamscheduler.exe [1513784 2015-10-05] (Malwarebytes)
S2 MBAMService; C:\Program Files\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [272952 2008-01-20] (Microsoft Corporation)
S2 FoxitCloudUpdateService; "C:\Program Files\Foxit Software\Foxit Reader\Foxit Cloud\FCUpdateService.exe" [X]
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [24016 2015-12-04] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [81168 2015-12-04] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr.sys [55200 2015-12-04] (AVAST Software)
S0 aswRvrt; C:\Windows\system32\Drivers\aswRvrt.sys [49776 2015-12-04] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [794952 2015-12-04] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [435976 2015-12-04] (AVAST Software)
R3 aswStmXP; C:\Windows\system32\drivers\aswStmXP.sys [165104 2015-12-04] (AVAST Software)
R3 aswTdi; C:\Windows\system32\drivers\aswTdi.sys [58016 2015-12-04] (AVAST Software)
R0 aswVmm; C:\Windows\system32\Drivers\aswVmm.sys [209432 2015-12-04] (AVAST Software)
R1 HWiNFO32; C:\Windows\system32\drivers\HWiNFO32.SYS [23840 2015-12-02] (REALiX(tm))
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2015-10-05] (Malwarebytes)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2015-10-05] (Malwarebytes Corporation)
R3 NETwLv32; C:\Windows\System32\DRIVERS\NETwLv32.sys [6639616 2015-12-02] (Intel Corporation)
S3 NuidFltr; C:\Windows\System32\DRIVERS\NuidFltr.sys [14736 2009-05-09] (Microsoft Corporation)
U5 AppMgmt; C:\Windows\system32\svchost.exe [21504 2008-01-20] (Microsoft Corporation)
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-12-04 13:37 - 2015-12-04 13:37 - 00015318 _____ C:\Users\Andree Rezai\Desktop\FRST.txt
2015-12-04 13:35 - 2015-12-04 13:37 - 00000000 ____D C:\FRST
2015-12-04 13:32 - 2015-12-04 13:33 - 01721344 _____ (Farbar) C:\Users\Andree Rezai\Desktop\FRST.exe
2015-12-04 13:14 - 2015-12-04 13:09 - 00794952 _____ (AVAST Software) C:\Windows\system32\Drivers\aswEBAB.tmp
2015-12-04 13:14 - 2015-12-04 13:09 - 00435976 _____ (AVAST Software) C:\Windows\system32\Drivers\aswF35D.tmp
2015-12-04 13:14 - 2015-12-04 13:09 - 00322760 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2015-12-04 13:14 - 2015-12-04 13:09 - 00209432 _____ (AVAST Software) C:\Windows\system32\Drivers\aswF477.tmp
2015-12-04 13:14 - 2015-12-04 13:09 - 00165104 _____ (AVAST Software) C:\Windows\system32\Drivers\aswF572.tmp
2015-12-04 13:14 - 2015-12-04 13:09 - 00081168 _____ (AVAST Software) C:\Windows\system32\Drivers\aswF08E.tmp
2015-12-04 13:14 - 2015-12-04 13:09 - 00058016 _____ (AVAST Software) C:\Windows\system32\Drivers\aswF6BB.tmp
2015-12-04 13:14 - 2015-12-04 13:09 - 00055200 _____ (AVAST Software) C:\Windows\system32\Drivers\aswED80.tmp
2015-12-04 13:14 - 2015-12-04 13:09 - 00049776 _____ (AVAST Software) C:\Windows\system32\Drivers\aswF198.tmp
2015-12-04 13:14 - 2015-12-04 13:09 - 00024016 _____ (AVAST Software) C:\Windows\system32\Drivers\aswEED8.tmp
2015-12-04 13:10 - 2015-12-04 13:10 - 00000000 ____D C:\Users\Andree Rezai\AppData\Roaming\AVAST Software
2015-12-04 13:10 - 2015-12-04 13:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
2015-12-04 13:09 - 2015-12-04 13:09 - 00794952 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2015-12-04 13:09 - 2015-12-04 13:09 - 00435976 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2015-12-04 13:09 - 2015-12-04 13:09 - 00209432 _____ (AVAST Software) C:\Windows\system32\Drivers\aswVmm.sys
2015-12-04 13:09 - 2015-12-04 13:09 - 00165104 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStmXP.sys
2015-12-04 13:09 - 2015-12-04 13:09 - 00081168 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2015-12-04 13:09 - 2015-12-04 13:09 - 00058016 _____ (AVAST Software) C:\Windows\system32\Drivers\aswTdi.sys
2015-12-04 13:09 - 2015-12-04 13:09 - 00055200 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr.sys
2015-12-04 13:09 - 2015-12-04 13:09 - 00049776 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys
2015-12-04 13:09 - 2015-12-04 13:09 - 00043112 _____ (AVAST Software) C:\Windows\avastSS.scr
2015-12-04 13:09 - 2015-12-04 13:09 - 00024016 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHwid.sys
2015-12-04 13:05 - 2015-12-04 13:05 - 00000000 ____D C:\Program Files\AVAST Software
2015-12-04 12:51 - 2015-12-04 12:51 - 05084256 _____ (AVAST Software) C:\Users\Andree Rezai\Downloads\avast_free_antivirus_setup_online_cnet2.exe
2015-12-03 15:20 - 2015-12-03 15:20 - 00000259 _____ C:\Users\Andree Rezai\Desktop\Virus and Malware Removal - TechSpot Forums.URL
2015-12-02 12:55 - 2015-12-02 12:55 - 00002101 _____ C:\Users\Andree Rezai\Desktop\JRT.txt
2015-12-02 12:28 - 2015-12-02 12:28 - 00000000 ____H C:\ProgramData\DP45977C.lfl
2015-12-02 12:27 - 2015-12-02 12:27 - 00000000 ____D C:\Windows\system32\DAX2
2015-12-02 12:26 - 2015-12-02 12:26 - 00000000 ____D C:\Windows\system32\RTCOM
2015-12-02 12:26 - 2015-12-02 12:26 - 00000000 ____D C:\Program Files\Realtek
2015-12-02 12:22 - 2015-12-02 12:22 - 72113152 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RCoRes.dat
2015-12-02 12:22 - 2015-12-02 12:22 - 13789440 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioRealtek.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 11899824 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxVoiceAPO30.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 11785136 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxVoiceAPO40.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 07162128 _____ (Dolby Laboratories) C:\Windows\system32\R4EEP32A.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 07044952 _____ (Dolby Laboratories) C:\Windows\system32\DDPP32A.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 05804772 _____ C:\Windows\system32\Drivers\rtvienna.dat
2015-12-02 12:22 - 2015-12-02 12:22 - 05073344 _____ (Nahimic Inc) C:\Windows\system32\NAHIMICV2apo.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 04713224 _____ (Nahimic Inc) C:\Windows\system32\NAHIMICAPOlfx.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 03522264 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\Drivers\RTKVHDA.sys
2015-12-02 12:22 - 2015-12-02 12:22 - 02862488 _____ C:\Windows\system32\Drivers\RTAIODAT.DAT
2015-12-02 12:22 - 2015-12-02 12:22 - 02820120 _____ (Fortemedia Corporation) C:\Windows\system32\FMAPO.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 02637528 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTSndMgr.cpl
2015-12-02 12:22 - 2015-12-02 12:22 - 02630872 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkPgExt.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 02585816 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RltkAPO.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 02394328 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkApoApi.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 02370480 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO70.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 01940056 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioEQ.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 01861976 _____ (Dolby Laboratories) C:\Windows\system32\DolbyDAX2APOv211.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 01823320 _____ (Waves Audio Ltd.) C:\Windows\system32\WavesGUILib.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 01783056 _____ (Waves Audio Ltd.) C:\Windows\system32\WavesLib.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 01782616 _____ (Dolby Laboratories) C:\Windows\system32\DolbyDAX2APOv201.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 01708248 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCoInstII.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 01509480 _____ (DTS) C:\Windows\system32\DTSS2SpeakerDLL.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 01490960 _____ (Conexant Systems Inc.) C:\Windows\system32\CX32APO.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 01490264 _____ (Dolby Laboratories) C:\Windows\system32\DDPD32A.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 01379760 _____ (TOSHIBA Corporation) C:\Windows\system32\tosade.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 01292904 _____ (DTS) C:\Windows\system32\DTSS2HeadphoneDLL.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 01220200 _____ (DTS) C:\Windows\system32\DTSBoostDLL.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 01160112 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO60.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 01055888 _____ (Synopsys, Inc.) C:\Windows\system32\SRRPTR.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 01022120 _____ (SRS Labs, Inc.) C:\Windows\system32\slcnt32.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 01010096 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO50.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00973232 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO40.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00948336 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxSpeechAPO.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00945456 _____ (Nahimic Inc) C:\Windows\system32\NahimicAPONSControl.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00919600 _____ (Sony Corporation) C:\Windows\system32\SFSS_APO.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00865960 _____ (DTS, Inc.) C:\Windows\system32\sl3apo32.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00852016 _____ (Sony Corporation) C:\Windows\system32\MISS_APO.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00850264 _____ (Dolby Laboratories) C:\Windows\system32\DolbyDAX2APOProp.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00844192 _____ (TOSHIBA Corporation) C:\Windows\system32\tadefxapo2.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00818096 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxVoiceAPO20.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00790272 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPOShell.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00704656 _____ (Sound Research, Corp.) C:\Windows\system32\SEHDRA32.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00654952 _____ (DTS) C:\Windows\system32\DTSBassEnhancementDLL.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00631400 _____ (DTS) C:\Windows\system32\DTSSymmetryDLL.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00611496 _____ (DTS, Inc.) C:\Windows\system32\sltech32.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00601704 _____ (DTS) C:\Windows\system32\DTSVoiceClarityDLL.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00555664 _____ (Sound Research, Corp.) C:\Windows\system32\SECOMN32.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00519368 _____ (Andrea Electronics Corporation) C:\Windows\system32\AERTACap.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00509184 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxVolumeSDAPO.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00509184 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO30.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00458344 _____ (DTS) C:\Windows\system32\DTSNeoPCDLL.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00426944 _____ (DTS) C:\Windows\system32\DTSU2PLFX32.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00403392 _____ (DTS) C:\Windows\system32\DTSU2PGFX32.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00389736 _____ (DTS) C:\Windows\system32\DTSGainCompensatorDLL.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00388752 _____ (Synopsys, Inc.) C:\Windows\system32\SRAPO.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00375400 _____ (DTS) C:\Windows\system32\DTSLimiterDLL.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00372368 _____ (Sound Research, Corp.) C:\Windows\system32\SEAPO32.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00359768 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEP32A.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00357712 _____ (Knowles Acoustics ) C:\Windows\system32\KAAPORT.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00352016 _____ (Dolby Laboratories) C:\Windows\system32\R4EED32A.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00346048 _____ (DTS) C:\Windows\system32\DTSU2PREC32.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00345328 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSTSXT.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00329360 _____ (Synopsys, Inc.) C:\Windows\system32\SRCOM.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00296560 _____ (ICEpower a/s) C:\Windows\system32\ICEsoundAPO.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00295768 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RP3DHT32.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00295768 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RP3DAA32.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00294744 _____ (Dolby Laboratories) C:\Windows\system32\HiFiDAX2API.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00274264 _____ (Dolby Laboratories) C:\Windows\system32\DDPO32A.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00232792 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO20.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00223912 _____ (TODO: <Company name>) C:\Windows\system32\slprp32.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00221528 _____ (Dolby Laboratories) C:\Windows\system32\DDPA32.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00220088 _____ (TOSHIBA Corporation) C:\Windows\system32\tossaemaxapo32.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00218728 _____ (DTS) C:\Windows\system32\DTSGFXAPONS.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00218728 _____ (DTS) C:\Windows\system32\DTSGFXAPO.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00218216 _____ (DTS) C:\Windows\system32\DTSLFXAPO.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00214368 _____ (Synopsys, Inc.) C:\Windows\system32\SFNHK.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00188696 _____ C:\Windows\system32\AcpiServiceVnA.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00185584 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSTSHD.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00173296 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSHP360.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00170840 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEED32A.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00140528 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSWOW.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00134584 _____ (TOSHIBA Corporation) C:\Windows\system32\tadefxapo.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00132368 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00106768 _____ (Dolby Laboratories) C:\Windows\system32\R4EEL32A.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00095840 _____ (Andrea Electronics Corporation) C:\Windows\system32\AERTARen.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00092584 _____ (Real Sound Lab SIA) C:\Windows\system32\CONEQMSAPOGUILibrary.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00091920 _____ (Dolby Laboratories) C:\Windows\system32\R4EEA32A.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00087864 _____ C:\Windows\system32\audioLibVc.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00078680 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEL32A.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00074080 _____ (Synopsys, Inc.) C:\Windows\system32\SFCOM.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00068960 _____ (Synopsys, Inc.) C:\Windows\system32\SFAPO.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00064856 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEG32A.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00062224 _____ (Dolby Laboratories) C:\Windows\system32\R4EEG32A.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00058264 _____ (TOSHIBA CORPORATION.) C:\Windows\system32\TepeqAPO.dll
2015-12-02 12:22 - 2015-12-02 12:22 - 00013416 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCoLDR.dll
2015-12-02 11:56 - 2015-12-02 11:56 - 06639616 _____ (Intel Corporation) C:\Windows\system32\Drivers\NETwLv32.sys
2015-12-02 11:56 - 2015-12-02 11:56 - 02756608 _____ (Intel Corporation) C:\Windows\system32\NETwLr32.dll
2015-12-02 11:56 - 2015-12-02 11:56 - 00675840 _____ (Intel Corporation) C:\Windows\system32\NETwLc32.dll
2015-12-02 11:51 - 2015-12-02 11:51 - 00311296 _____ (Marvell) C:\Windows\system32\Drivers\yk60x86.sys
2015-12-02 11:51 - 2015-12-02 11:51 - 00282624 _____ (Marvell) C:\Windows\system32\ykx32mpcoinst.dll
2015-12-02 11:46 - 2015-12-02 11:46 - 00000000 ____D C:\Users\Public\Foxit Software
2015-12-02 11:45 - 2015-12-02 11:45 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Foxit Reader
2015-12-02 11:43 - 2015-12-02 12:53 - 00000000 ____D C:\Users\Andree Rezai\AppData\Roaming\IObit
2015-12-02 11:43 - 2015-12-02 12:53 - 00000000 ____D C:\ProgramData\IObit
2015-12-02 11:43 - 2015-12-02 11:45 - 00000000 ____D C:\Users\Andree Rezai\AppData\LocalLow\IObit
2015-12-02 11:43 - 2015-12-02 11:43 - 00023840 _____ (REALiX(tm)) C:\Windows\system32\Drivers\HWiNFO32.SYS
2015-12-02 11:43 - 2015-12-02 11:43 - 00000000 ____D C:\Windows\Tasks\ImCleanDisabled
2015-12-02 11:42 - 2015-12-02 11:46 - 00000000 ____D C:\PatchMyPCUpdates
2015-12-02 11:42 - 2015-12-02 11:42 - 00000764 _____ C:\Users\Public\Desktop\CCleaner.lnk
2015-12-02 11:11 - 2015-12-02 11:11 - 00000000 ____D C:\Users\Andree Rezai\AppData\Roaming\CrystalIdea Software
2015-11-24 23:55 - 2015-11-24 23:55 - 00000000 ____D C:\Program Files\Common Files\Java
2015-11-18 03:17 - 2015-11-18 03:17 - 00014365 _____ C:\Users\Andree Rezai\Downloads\POLY_DIV_Qz.pdf
2015-11-18 03:15 - 2015-11-18 03:15 - 00015516 _____ C:\Users\Andree Rezai\Downloads\INV_FUN2.pdf
2015-11-15 23:09 - 2015-11-15 23:09 - 00073468 _____ C:\Users\Andree Rezai\Downloads\doc08.pdf
2015-11-11 01:19 - 2015-10-17 06:24 - 02068480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-11-11 01:09 - 2015-10-17 08:01 - 00501248 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2015-11-11 01:09 - 2015-10-13 06:31 - 00273408 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2015-11-11 01:09 - 2015-10-13 06:31 - 00072192 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys
2015-11-11 01:08 - 2015-10-14 12:22 - 01206192 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2015-11-11 01:08 - 2015-10-14 08:01 - 03606464 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2015-11-11 01:08 - 2015-10-14 08:01 - 03554752 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-11-11 01:04 - 2015-10-10 08:02 - 00526272 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys
2015-11-11 01:00 - 2015-09-26 08:05 - 00281600 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2015-11-11 01:00 - 2015-09-26 08:04 - 00206336 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2015-11-11 01:00 - 2015-09-26 05:21 - 00274432 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll
2015-11-11 01:00 - 2015-09-22 05:11 - 00440768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-11-10 23:40 - 2015-10-31 10:40 - 12376576 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-11-10 23:40 - 2015-10-31 10:38 - 09727488 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-11-10 23:40 - 2015-10-31 10:38 - 00367616 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-11-10 23:40 - 2015-10-31 10:37 - 01830912 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-11-10 23:40 - 2015-10-31 10:36 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-11-10 23:40 - 2015-10-31 10:36 - 01789440 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-11-10 23:40 - 2015-10-31 10:36 - 01436160 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-11-10 23:40 - 2015-10-31 10:36 - 01093632 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-11-10 23:40 - 2015-10-31 10:36 - 01088512 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-11-10 23:40 - 2015-10-31 10:36 - 00711168 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-11-10 23:40 - 2015-10-31 10:36 - 00615424 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-11-10 23:40 - 2015-10-31 10:36 - 00412672 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-11-10 23:40 - 2015-10-31 10:36 - 00358400 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-11-10 23:40 - 2015-10-31 10:36 - 00232960 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2015-11-10 23:40 - 2015-10-31 10:36 - 00216064 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-11-10 23:40 - 2015-10-31 10:36 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-11-10 23:40 - 2015-10-31 10:36 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-11-10 23:40 - 2015-10-31 10:36 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-11-10 23:40 - 2015-10-31 10:36 - 00064512 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-11-10 23:40 - 2015-10-31 10:36 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2015-11-10 23:40 - 2015-10-31 10:36 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2015-11-10 23:40 - 2015-10-31 10:36 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2015-11-08 11:37 - 2015-11-08 11:37 - 00000330 _____ C:\Users\Andree Rezai\Desktop\Agoura Hills, CA - Google Maps.URL
2015-11-07 23:26 - 2015-11-07 23:26 - 00000263 _____ C:\Users\Andree Rezai\Desktop\Search Results.URL
2015-11-07 12:13 - 2015-11-07 12:13 - 00055897 _____ C:\Users\Andree Rezai\Downloads\availability-list-spring-2014.pdf
2015-11-06 22:30 - 2015-11-06 22:30 - 00663025 _____ C:\Users\Andree Rezai\Downloads\burbot.pdf
2015-11-06 16:46 - 2015-11-06 16:46 - 00091311 _____ C:\Users\Andree Rezai\Downloads\abalone.pdf
2015-11-06 10:17 - 2015-11-07 17:28 - 00000000 ____D C:\Program Files\Mozilla Firefox
2015-11-04 20:57 - 2015-11-04 20:57 - 01259940 _____ C:\Users\Andree Rezai\Downloads\060_Iglesiasetal2005.pdf
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-12-04 13:36 - 2006-11-02 03:18 - 00000000 ____D C:\Windows
2015-12-04 12:52 - 2012-03-29 10:48 - 00000000 ____D C:\ProgramData\AVAST Software
2015-12-04 12:48 - 2009-11-29 10:07 - 00000886 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-12-04 12:45 - 2012-06-14 08:22 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-12-04 12:40 - 2012-11-19 12:51 - 00002096 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2015-12-04 12:40 - 2012-11-19 12:51 - 00002096 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2015-12-04 12:40 - 2009-11-29 10:07 - 00000882 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-12-04 12:40 - 2006-11-02 05:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-12-04 03:20 - 2006-11-02 05:01 - 00032582 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2015-12-02 17:06 - 2009-11-29 14:03 - 00000000 ____D C:\Users\Andree Rezai\AppData\Roaming\Macromedia
2015-12-02 12:51 - 2015-01-27 14:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2015-12-02 12:51 - 2009-11-29 15:34 - 00000000 ____D C:\Program Files\Java
2015-12-02 12:37 - 2006-11-02 03:18 - 00000000 ____D C:\Windows\system32\spool
2015-12-02 12:35 - 2009-11-29 10:07 - 00000000 ____D C:\Program Files\Google
2015-12-02 12:26 - 2009-11-29 08:54 - 00000000 ____D C:\Users\Andree Rezai
2015-12-02 12:25 - 2006-11-02 03:18 - 00000000 ____D C:\Windows\inf
2015-12-02 12:00 - 2012-11-20 19:21 - 00006526 _____ C:\Windows\system32\PerfStringBackup.TMP
2015-12-02 11:37 - 2009-11-29 07:30 - 00000000 ____D C:\Windows.old
2015-12-02 11:37 - 2006-11-02 03:18 - 00000000 ___SD C:\Windows\Downloaded Program Files
2015-12-02 11:28 - 2009-11-29 15:27 - 00000000 ____D C:\Windows\PCHEALTH
2015-12-02 11:28 - 2006-11-02 03:18 - 00000000 ____D C:\Windows\security
2015-12-02 11:16 - 2009-12-04 19:51 - 00000000 ____D C:\Users\Andree Rezai\AppData\LocalLow\Macromedia
2015-12-02 11:16 - 2009-12-04 19:51 - 00000000 ____D C:\Users\Andree Rezai\AppData\LocalLow\Adobe
2015-12-02 11:15 - 2009-12-04 19:51 - 00000000 ____D C:\ProgramData\Google
2015-12-02 11:15 - 2009-11-29 10:07 - 00000000 ____D C:\Users\Andree Rezai\AppData\Local\Google
2015-12-02 11:14 - 2013-03-26 09:54 - 00000000 ____D C:\Program Files\7-Zip
2015-11-30 11:59 - 2015-03-29 08:08 - 00000000 ____D C:\Windows\system32\vbox
2015-11-25 12:42 - 2014-06-16 08:26 - 00170200 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-11-25 12:36 - 2009-12-05 07:12 - 00000059 _____ C:\Windows\wpd99.drv
2015-11-25 12:36 - 2009-12-05 07:12 - 00000000 ____D C:\ProgramData\pdf995
2015-11-25 01:06 - 2009-11-29 08:32 - 00000000 ____D C:\Windows\Panther
2015-11-24 23:55 - 2015-09-01 14:54 - 00000000 ____D C:\Users\Andree Rezai\.oracle_jre_usage
2015-11-24 23:53 - 2015-01-27 14:09 - 00095840 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll
2015-11-11 17:11 - 2014-12-16 16:37 - 00000000 ____D C:\Users\Andree Rezai\Desktop\Grade Pro
2015-11-11 10:57 - 2006-11-02 03:18 - 00000000 ____D C:\Windows\rescache
2015-11-11 10:40 - 2006-11-02 04:47 - 00303576 _____ C:\Windows\system32\FNTCACHE.DAT
2015-11-11 10:35 - 2006-11-02 04:37 - 00000000 ____D C:\Program Files\Windows Journal
2015-11-11 10:35 - 2006-11-02 03:18 - 00000000 ____D C:\Windows\PolicyDefinitions
2015-11-11 01:19 - 2013-08-14 02:20 - 00000000 ____D C:\Windows\system32\MRT
2015-11-11 01:11 - 2006-11-02 02:24 - 143250520 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2015-11-11 01:10 - 2009-11-29 15:25 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-11-10 17:45 - 2012-03-27 21:20 - 00780488 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2015-11-10 17:45 - 2012-03-17 13:13 - 00142536 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2015-11-07 17:28 - 2012-04-25 06:26 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
==================== Files in the root of some directories =======
2010-01-22 15:34 - 2015-10-16 23:34 - 0001596 _____ () C:\Users\Andree Rezai\AppData\Roaming\Sketchpad 5 Preferences.dat
2014-10-31 13:56 - 2014-10-31 13:56 - 0000680 _____ () C:\Users\Andree Rezai\AppData\Local\d3d9caps.dat
2009-11-29 09:27 - 2015-07-28 17:55 - 0102912 _____ () C:\Users\Andree Rezai\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-12-02 12:28 - 2015-12-02 12:28 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
Files to move or delete:
====================
C:\Users\Andree Rezai\instmsia.exe
C:\Users\Andree Rezai\instmsiw.exe
C:\Users\Andree Rezai\setup.exe
Some files in TEMP:
====================
C:\Users\Andree Rezai\AppData\Local\Temp\FoxitUpdater.exe
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-12-04 12:47
==================== End of FRST.txt ============================
Last edited by a moderator: