MH Lindsey
Posts: 195 +0
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-10-10 10:05 - 2011-06-23 12:11 - 00001828 _____ C:\Users\Public\Desktop\McAfee Total Protection.lnk
2015-10-10 10:05 - 2011-05-28 15:18 - 01804625 _____ C:\Windows\WindowsUpdate.log
2015-10-10 10:05 - 2009-07-13 22:13 - 00783464 _____ C:\Windows\system32\PerfStringBackup.INI
2015-10-10 10:01 - 2012-03-21 12:28 - 00000266 _____ C:\Windows\Tasks\HP Photo Creations Messager.job
2015-10-10 10:00 - 2012-01-09 18:33 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-10-10 10:00 - 2011-06-22 21:36 - 00000000 ____D C:\Users\Jacqueline\AppData\LocalLow\AuthenTec
2015-10-10 09:59 - 2009-07-13 22:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-10-10 09:58 - 2010-11-20 20:47 - 00816554 _____ C:\Windows\PFRO.log
2015-10-10 09:58 - 2009-07-13 21:51 - 00081674 _____ C:\Windows\setupact.log
2015-10-09 19:43 - 2009-07-13 19:34 - 00000215 _____ C:\Windows\system.ini
2015-10-09 19:41 - 2011-06-22 21:35 - 00000000 ____D C:\Users\Jacqueline
2015-10-09 19:38 - 2013-12-15 19:18 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-10-09 19:28 - 2012-01-09 18:33 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-10-09 19:13 - 2009-07-13 21:45 - 00032064 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-10-09 19:13 - 2009-07-13 21:45 - 00032064 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-10-09 19:08 - 2011-08-11 21:50 - 00000000 ____D C:\Users\Jacqueline\AppData\Local\CrashDumps
2015-10-09 18:33 - 2011-06-23 00:31 - 00003966 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{62BF689D-F1CB-45A1-9314-820592EAEC0D}
2015-10-09 17:02 - 2009-07-13 20:20 - 00000000 ____D C:\Windows\rescache
2015-10-09 15:37 - 2015-04-05 11:14 - 00000000 ___SD C:\Windows\system32\GWX
2015-10-08 15:23 - 2009-07-13 21:45 - 00357432 _____ C:\Windows\system32\FNTCACHE.DAT
2015-10-08 15:22 - 2013-11-26 17:58 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2015-10-08 15:19 - 2015-04-05 11:14 - 00000000 ___SD C:\Windows\SysWOW64\GWX
2015-10-08 15:19 - 2009-07-13 20:20 - 00000000 ____D C:\Windows\SysWOW64\Dism
2015-10-08 15:19 - 2009-07-13 20:20 - 00000000 ____D C:\Windows\system32\Dism
2015-10-08 15:19 - 2009-07-13 20:20 - 00000000 ____D C:\Windows\PolicyDefinitions
2015-10-08 15:15 - 2011-07-24 21:41 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-10-07 21:27 - 2009-07-13 20:20 - 00000000 ____D C:\Windows\L2Schemas
2015-10-07 19:39 - 2013-12-15 19:18 - 00780488 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-10-07 19:39 - 2013-12-15 19:18 - 00003768 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-10-07 19:39 - 2011-09-08 16:35 - 00142536 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-10-07 12:35 - 2007-01-01 18:25 - 00000000 ____D C:\Windows\Panther
2015-10-07 10:10 - 2014-10-20 10:35 - 00000000 ____D C:\Users\Jacqueline\AppData\Roaming\AVG2015
2015-10-07 10:10 - 2014-10-20 10:32 - 00000000 ____D C:\ProgramData\AVG2015
2015-10-07 10:10 - 2014-03-13 20:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
2015-10-07 10:10 - 2013-11-21 16:36 - 00000000 ____D C:\Program Files (x86)\PasswordBox
2015-10-07 10:10 - 2013-10-30 12:50 - 00000000 ____D C:\Program Files (x86)\AVG
2015-10-07 10:10 - 2013-10-29 14:24 - 00000000 ____D C:\ProgramData\MFAData
2015-10-07 10:10 - 2011-04-08 13:47 - 00000000 ____D C:\ProgramData\RoxioNow
2015-10-07 10:10 - 2009-07-13 20:20 - 00000000 ____D C:\Windows\servicing
2015-10-07 10:10 - 2009-07-13 20:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
2015-10-07 10:09 - 2009-07-13 20:20 - 00000000 ____D C:\Windows\registration
2015-10-06 17:23 - 2012-01-09 18:33 - 00003894 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-10-06 17:23 - 2012-01-09 18:33 - 00003642 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2015-10-06 15:46 - 2015-06-08 17:42 - 00003216 _____ C:\Windows\System32\Tasks\HPCeeScheduleForJacqueline
2015-10-06 15:46 - 2015-06-08 17:42 - 00000352 _____ C:\Windows\Tasks\HPCeeScheduleForJacqueline.job
2015-10-01 19:43 - 2011-12-01 15:53 - 00001414 _____ C:\Windows\Synaptics.log
2015-10-01 19:43 - 2011-05-28 15:25 - 00024484 _____ C:\Windows\DPINST.LOG
2015-10-01 19:42 - 2011-05-28 15:24 - 00000000 ____D C:\Windows\SysWOW64\sda
2015-10-01 19:42 - 2011-05-28 15:24 - 00000000 ____D C:\Program Files (x86)\Realtek
2015-10-01 19:42 - 2011-05-28 15:21 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel
2015-10-01 19:41 - 2011-05-28 15:20 - 00000000 ____D C:\Program Files (x86)\Intel
2015-10-01 19:40 - 2011-05-28 15:38 - 00000000 ____D C:\ProgramData\Downloaded Installations
2015-10-01 19:40 - 2011-04-08 13:48 - 00000000 ____D C:\ProgramData\Hewlett-Packard
2015-10-01 19:39 - 2011-06-23 00:31 - 00000000 ____D C:\Users\Jacqueline\AppData\Roaming\hpqlog
2015-10-01 19:39 - 2011-04-08 13:54 - 00000000 ___RD C:\Program Files\Online Services
2015-10-01 19:39 - 2011-04-08 13:48 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Online Services
2015-10-01 19:39 - 2011-04-08 13:40 - 00000000 ___RD C:\Program Files (x86)\Online Services
2015-10-01 17:21 - 2009-07-13 22:08 - 00032538 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2015-09-12 08:36 - 2011-04-08 13:52 - 00000000 ____D C:\Windows\en
2015-09-12 07:31 - 2012-05-27 10:18 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2015-09-12 07:31 - 2012-05-27 10:18 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2015-09-12 07:30 - 2014-12-27 19:30 - 00000000 ____D C:\Windows\system32\appraiser
2015-09-12 07:30 - 2014-05-21 18:40 - 00000000 ___SD C:\Windows\system32\CompatTel
2015-09-12 07:25 - 2012-05-27 10:19 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
==================== Files in the root of some directories =======
2012-03-07 15:44 - 2015-05-13 10:21 - 0029696 _____ () C:\Users\Jacqueline\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-12-25 21:01 - 2014-12-25 21:01 - 0000000 _____ () C:\Users\Jacqueline\AppData\Local\{C36D0A3D-5FB4-4FAD-A2A4-C9623DD123FB}
2012-03-21 12:25 - 2012-03-21 12:25 - 0000057 _____ () C:\ProgramData\Ament.ini
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-10-09 16:54
==================== End of FRST.txt ============================
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-10-10 10:05 - 2011-06-23 12:11 - 00001828 _____ C:\Users\Public\Desktop\McAfee Total Protection.lnk
2015-10-10 10:05 - 2011-05-28 15:18 - 01804625 _____ C:\Windows\WindowsUpdate.log
2015-10-10 10:05 - 2009-07-13 22:13 - 00783464 _____ C:\Windows\system32\PerfStringBackup.INI
2015-10-10 10:01 - 2012-03-21 12:28 - 00000266 _____ C:\Windows\Tasks\HP Photo Creations Messager.job
2015-10-10 10:00 - 2012-01-09 18:33 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-10-10 10:00 - 2011-06-22 21:36 - 00000000 ____D C:\Users\Jacqueline\AppData\LocalLow\AuthenTec
2015-10-10 09:59 - 2009-07-13 22:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-10-10 09:58 - 2010-11-20 20:47 - 00816554 _____ C:\Windows\PFRO.log
2015-10-10 09:58 - 2009-07-13 21:51 - 00081674 _____ C:\Windows\setupact.log
2015-10-09 19:43 - 2009-07-13 19:34 - 00000215 _____ C:\Windows\system.ini
2015-10-09 19:41 - 2011-06-22 21:35 - 00000000 ____D C:\Users\Jacqueline
2015-10-09 19:38 - 2013-12-15 19:18 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-10-09 19:28 - 2012-01-09 18:33 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-10-09 19:13 - 2009-07-13 21:45 - 00032064 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-10-09 19:13 - 2009-07-13 21:45 - 00032064 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-10-09 19:08 - 2011-08-11 21:50 - 00000000 ____D C:\Users\Jacqueline\AppData\Local\CrashDumps
2015-10-09 18:33 - 2011-06-23 00:31 - 00003966 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{62BF689D-F1CB-45A1-9314-820592EAEC0D}
2015-10-09 17:02 - 2009-07-13 20:20 - 00000000 ____D C:\Windows\rescache
2015-10-09 15:37 - 2015-04-05 11:14 - 00000000 ___SD C:\Windows\system32\GWX
2015-10-08 15:23 - 2009-07-13 21:45 - 00357432 _____ C:\Windows\system32\FNTCACHE.DAT
2015-10-08 15:22 - 2013-11-26 17:58 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2015-10-08 15:19 - 2015-04-05 11:14 - 00000000 ___SD C:\Windows\SysWOW64\GWX
2015-10-08 15:19 - 2009-07-13 20:20 - 00000000 ____D C:\Windows\SysWOW64\Dism
2015-10-08 15:19 - 2009-07-13 20:20 - 00000000 ____D C:\Windows\system32\Dism
2015-10-08 15:19 - 2009-07-13 20:20 - 00000000 ____D C:\Windows\PolicyDefinitions
2015-10-08 15:15 - 2011-07-24 21:41 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-10-07 21:27 - 2009-07-13 20:20 - 00000000 ____D C:\Windows\L2Schemas
2015-10-07 19:39 - 2013-12-15 19:18 - 00780488 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-10-07 19:39 - 2013-12-15 19:18 - 00003768 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-10-07 19:39 - 2011-09-08 16:35 - 00142536 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-10-07 12:35 - 2007-01-01 18:25 - 00000000 ____D C:\Windows\Panther
2015-10-07 10:10 - 2014-10-20 10:35 - 00000000 ____D C:\Users\Jacqueline\AppData\Roaming\AVG2015
2015-10-07 10:10 - 2014-10-20 10:32 - 00000000 ____D C:\ProgramData\AVG2015
2015-10-07 10:10 - 2014-03-13 20:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
2015-10-07 10:10 - 2013-11-21 16:36 - 00000000 ____D C:\Program Files (x86)\PasswordBox
2015-10-07 10:10 - 2013-10-30 12:50 - 00000000 ____D C:\Program Files (x86)\AVG
2015-10-07 10:10 - 2013-10-29 14:24 - 00000000 ____D C:\ProgramData\MFAData
2015-10-07 10:10 - 2011-04-08 13:47 - 00000000 ____D C:\ProgramData\RoxioNow
2015-10-07 10:10 - 2009-07-13 20:20 - 00000000 ____D C:\Windows\servicing
2015-10-07 10:10 - 2009-07-13 20:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
2015-10-07 10:09 - 2009-07-13 20:20 - 00000000 ____D C:\Windows\registration
2015-10-06 17:23 - 2012-01-09 18:33 - 00003894 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-10-06 17:23 - 2012-01-09 18:33 - 00003642 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2015-10-06 15:46 - 2015-06-08 17:42 - 00003216 _____ C:\Windows\System32\Tasks\HPCeeScheduleForJacqueline
2015-10-06 15:46 - 2015-06-08 17:42 - 00000352 _____ C:\Windows\Tasks\HPCeeScheduleForJacqueline.job
2015-10-01 19:43 - 2011-12-01 15:53 - 00001414 _____ C:\Windows\Synaptics.log
2015-10-01 19:43 - 2011-05-28 15:25 - 00024484 _____ C:\Windows\DPINST.LOG
2015-10-01 19:42 - 2011-05-28 15:24 - 00000000 ____D C:\Windows\SysWOW64\sda
2015-10-01 19:42 - 2011-05-28 15:24 - 00000000 ____D C:\Program Files (x86)\Realtek
2015-10-01 19:42 - 2011-05-28 15:21 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel
2015-10-01 19:41 - 2011-05-28 15:20 - 00000000 ____D C:\Program Files (x86)\Intel
2015-10-01 19:40 - 2011-05-28 15:38 - 00000000 ____D C:\ProgramData\Downloaded Installations
2015-10-01 19:40 - 2011-04-08 13:48 - 00000000 ____D C:\ProgramData\Hewlett-Packard
2015-10-01 19:39 - 2011-06-23 00:31 - 00000000 ____D C:\Users\Jacqueline\AppData\Roaming\hpqlog
2015-10-01 19:39 - 2011-04-08 13:54 - 00000000 ___RD C:\Program Files\Online Services
2015-10-01 19:39 - 2011-04-08 13:48 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Online Services
2015-10-01 19:39 - 2011-04-08 13:40 - 00000000 ___RD C:\Program Files (x86)\Online Services
2015-10-01 17:21 - 2009-07-13 22:08 - 00032538 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2015-09-12 08:36 - 2011-04-08 13:52 - 00000000 ____D C:\Windows\en
2015-09-12 07:31 - 2012-05-27 10:18 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2015-09-12 07:31 - 2012-05-27 10:18 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2015-09-12 07:30 - 2014-12-27 19:30 - 00000000 ____D C:\Windows\system32\appraiser
2015-09-12 07:30 - 2014-05-21 18:40 - 00000000 ___SD C:\Windows\system32\CompatTel
2015-09-12 07:25 - 2012-05-27 10:19 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
==================== Files in the root of some directories =======
2012-03-07 15:44 - 2015-05-13 10:21 - 0029696 _____ () C:\Users\Jacqueline\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-12-25 21:01 - 2014-12-25 21:01 - 0000000 _____ () C:\Users\Jacqueline\AppData\Local\{C36D0A3D-5FB4-4FAD-A2A4-C9623DD123FB}
2012-03-21 12:25 - 2012-03-21 12:25 - 0000057 _____ () C:\ProgramData\Ament.ini
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-10-09 16:54
==================== End of FRST.txt ============================