Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:20-11-2015 Ran by [removed] (administrator) on LAMPO (21-11-2015 17:22:45) Running from C:\Users\[removed]\Desktop [removed] Platform: Windows 10 Home (X64) Language: English (United States) Internet Explorer Version 11 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (HP) C:\Program Files (x86)\HP SimplePass\TrueSuiteService.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Intel Corporation) C:\Windows\System32\igfxCUIService.exe (IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe (Hewlett-Packard Company) C:\Windows\System32\hpservice.exe (QIHU 360 SOFTWARE CO. LIMITED) C:\Program Files (x86)\360\Total Security\safemon\QHActiveDefense.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPWMISVC.exe (Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe () C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe () C:\Windows\System32\valWBFPolicyService.exe (DEVGURU Co., LTD.) C:\Program Files\SAMSUNG\USB Drivers\25_escape\conn\ss_conn_service.exe (Seagate Technology LLC) C:\Program Files (x86)\Seagate\Seagate_Media\Sync\MediaAggreService.exe (Qihu Software Co. Limited) C:\Program Files (x86)\360\Total Security\safemon\QHWatchdog.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (AuthenTec Inc.) C:\Program Files (x86)\HP SimplePass\TouchControl.exe () C:\Program Files (x86)\HP SimplePass\IEWebSiteLogon.exe (Intel Corporation) C:\Windows\System32\igfxEM.exe (Intel Corporation) C:\Windows\System32\igfxHK.exe (Intel Corporation) C:\Windows\System32\igfxTray.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe (Flux Software LLC) C:\Users\weeel\AppData\Local\FluxSoftware\Flux\flux.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe (Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPMSGSVC.exe (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP 3D DriveGuard\AccelerometerSt.exe (Seagate LLC) C:\Program Files (x86)\Seagate\Seagate_Media\AgrregationStatus\stxmediamenumgr.exe (QIHU 360 SOFTWARE CO. LIMITED) C:\Program Files (x86)\360\Total Security\safemon\QHSafeTray.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe ==================== Registry (Whitelisted) =========================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [1703424 2013-12-21] (IDT, Inc.) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3945656 2015-09-05] (Synaptics Incorporated) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [HPMessageService] => C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPMSGSVC.exe [1045304 2013-10-08] (Hewlett-Packard Development Company, L.P.) HKLM-x32\...\Run: [AccelerometerSysTrayApplet] => C:\Program Files (x86)\Hewlett-Packard\HP 3D DriveGuard\AccelerometerST.exe [77088 2013-07-24] (Hewlett-Packard Company) HKLM-x32\...\Run: [mobilegeni daemon] => C:\Program Files (x86)\Mobogenie\DaemonProcess.exe HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-10-02] (Apple Inc.) HKLM-x32\...\Run: [KiesTrayAgent] => C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe HKLM-x32\...\Run: [FreeAgentTheaterTrayIcon] => C:\Program Files (x86)\Seagate\Seagate_Media\AgrregationStatus\StxMediaMenuMgr.exe [189480 2014-03-13] (Seagate LLC) HKLM-x32\...\Run: [QHSafeTray] => C:\Program Files (x86)\360\Total Security\safemon\360Tray.exe [301176 2015-11-20] (QIHU 360 SOFTWARE CO. LIMITED) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [597552 2015-08-04] (Oracle Corporation) Winlogon\Notify\igfxcui: igfxdev.dll [X] HKU\S-1-5-21-3622977173-2670285063-1210919453-1002\...\Run: [ViStart] => C:\Users\weeel\AppData\Roaming\ViStart\ViStart.exe HKU\S-1-5-21-3622977173-2670285063-1210919453-1002\...\Run: [NukeMetro] => "C:\Users\weeel\AppData\Roaming\ViStart\ViStart.exe" /nuke_metro HKU\S-1-5-21-3622977173-2670285063-1210919453-1002\...\Run: [uTorrent] => C:\Users\weeel\AppData\Roaming\uTorrent\uTorrent.exe [1696096 2015-08-28] (BitTorrent Inc.) HKU\S-1-5-21-3622977173-2670285063-1210919453-1002\...\Run: [f.lux] => C:\Users\weeel\AppData\Local\FluxSoftware\Flux\flux.exe [1017224 2013-10-24] (Flux Software LLC) HKU\S-1-5-21-3622977173-2670285063-1210919453-1002\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\WINDOWS\WLXPGSS.SCR [322248 2014-03-31] (Microsoft Corporation) AppInit_DLLs: C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [176904 2015-07-23] (NVIDIA Corporation) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\iSCTsysTray.lnk [2013-06-13] ShortcutTarget: iSCTsysTray.lnk -> C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTsysTray8.exe (Intel Corporation) Startup: C:\Users\weeel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Seagate NA42VK61 Product Registration.lnk [2015-11-15] ShortcutTarget: Seagate NA42VK61 Product Registration.lnk -> C:\Users\weeel\AppData\Roaming\Leadertech\PowerRegister\Seagate NA42VK61 Product Registration.exe (Leader Technologies/Seagate) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{75a154ab-12f3-43b5-885a-f16cf70ca1ec}: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{a98264b4-6d73-40f6-a930-f116ee8a375c}: [DhcpNameServer] 192.168.1.1 Internet Explorer: ================== HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.duckduckgo.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = www.duckduckgo.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.jp.msn.com/HPALL13/15 HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.symantec.com/redirects/security_response/fix_homepage/index.jsp?lg=en&pid=NAV&pvid=21.6.0.32 HKU\S-1-5-21-3622977173-2670285063-1210919453-1002\Software\Microsoft\Internet Explorer\Main,Start Page = www.duckduckgo.com HKU\S-1-5-21-3622977173-2670285063-1210919453-1002\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.jp.msn.com/HPALL13/15 SearchScopes: HKLM -> DefaultScope {4826BEE3-5902-42EA-8CAB-DB1F2F3FCCDD} URL = hxxps://duckduckgo.com/?q={searchTerms} SearchScopes: HKLM -> {4826BEE3-5902-42EA-8CAB-DB1F2F3FCCDD} URL = hxxps://duckduckgo.com/?q={searchTerms} SearchScopes: HKLM-x32 -> DefaultScope {4826BEE3-5902-42EA-8CAB-DB1F2F3FCCDD} URL = hxxps://duckduckgo.com/?q={searchTerms} SearchScopes: HKLM-x32 -> {4826BEE3-5902-42EA-8CAB-DB1F2F3FCCDD} URL = hxxps://duckduckgo.com/?q={searchTerms} SearchScopes: HKU\S-1-5-21-3622977173-2670285063-1210919453-1002 -> DefaultScope {4826BEE3-5902-42EA-8CAB-DB1F2F3FCCDD} URL = hxxps://duckduckgo.com/?q={searchTerms} SearchScopes: HKU\S-1-5-21-3622977173-2670285063-1210919453-1002 -> {3BD44F0E-0596-4008-AEE0-45D47E3A8F0E} URL = hxxp://www2.mystart.com/results.php?pr=vmn&id=yolobartb&v=1_0&ent=ch&q={searchTerms} SearchScopes: HKU\S-1-5-21-3622977173-2670285063-1210919453-1002 -> {4826BEE3-5902-42EA-8CAB-DB1F2F3FCCDD} URL = hxxps://duckduckgo.com/?q={searchTerms} BHO: SafeMon Class -> {B69F34DD-F0F9-42DC-9EDD-957187DA688D} -> C:\Program Files (x86)\360\Total Security\safemon\safemon64.dll [2015-11-13] (Qihu 360 Software Co., Ltd.) BHO: BHOImpl Class -> {E1499FE7-129D-4B6E-B681-DDF21E14172C} -> C:\Users\weeel\Documents\iTools\Plugin\iToolsBHO64.dll [2014-07-13] (iTools.hk) BHO-x32: Norton Vulnerability Protection -> {6D53EC84-6AAE-4787-AEEE-F4628F01010C} -> C:\Program Files (x86)\Norton AntiVirus\Engine\21.7.0.11\IPS\IPSBHO.DLL => No File BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\ssv.dll [2015-11-21] (Oracle Corporation) BHO-x32: SafeMon Class -> {B69F34DD-F0F9-42DC-9EDD-957187DA688D} -> C:\Program Files (x86)\360\Total Security\safemon\safemon.dll [2015-11-13] (Qihu 360 Software Co., Ltd.) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\jp2ssv.dll [2015-11-21] (Oracle Corporation) BHO-x32: BHOImpl Class -> {E1499FE7-129D-4B6E-B681-DDF21E14172C} -> C:\Users\weeel\Documents\iTools\Plugin\iToolsBHO.dll [2014-07-13] (iTools.hk) Toolbar: HKU\S-1-5-21-3622977173-2670285063-1210919453-1002 -> No Name - {0329E7D6-6F54-462D-93F6-F5C3118BADF2} - No File Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies) FireFox: ======== FF ProfilePath: C:\Users\weeel\AppData\Roaming\Mozilla\Firefox\Profiles\l7cg8hvw.default-1382944321897 FF DefaultSearchEngine: DuckDuckGo FF SearchEngineOrder.1: default-search.net FF SelectedSearchEngine: DuckDuckGo FF Homepage: hxxps://duckduckgo.com/ FF NetworkProxy: "user_pref("extensions.browsec.backup.network.proxy.autoconfig_url", ""); FF NetworkProxy: "user_pref("extensions.browsec.backup.network.proxy.ftp", ""); FF NetworkProxy: "user_pref("extensions.browsec.backup.network.proxy.ftp_port", 0); FF NetworkProxy: "user_pref("extensions.browsec.backup.network.proxy.http", ""); FF NetworkProxy: "user_pref("extensions.browsec.backup.network.proxy.http_port", 0); FF NetworkProxy: "user_pref("extensions.browsec.backup.network.proxy.no_proxies_on", "localhost, 127.0.0.1"); FF NetworkProxy: "user_pref("extensions.browsec.backup.network.proxy.share_proxy_settings", false); FF NetworkProxy: "user_pref("extensions.browsec.backup.network.proxy.ssl", ""); FF NetworkProxy: "user_pref("extensions.browsec.backup.network.proxy.ssl_port", 0); FF NetworkProxy: "user_pref("extensions.browsec.backup.network.proxy.type", 0); FF Keyword.URL: hxxp://www.default-search.net/search?sid=503&aid=100&itype=n&ver=13898&tm=474&src=ds&p= FF NetworkProxy: "type", 0 FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_19_0_0_245.dll [2015-11-12] () FF Plugin: @itools.hk/npiTools, version=1.0.0 -> C:\Users\weeel\Documents\iTools\Plugin\npiTools.dll [2014-07-13] () FF Plugin: @java.com/DTPlugin,version=10.40.2 -> C:\WINDOWS\system32\npDeployJava1.dll [2013-09-22] (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_19_0_0_245.dll [2015-11-12] () FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\WINDOWS\SysWOW64\Adobe\Director\np32dsw_1221171.dll [2015-10-19] (Adobe Systems, Inc.) FF Plugin-x32: @authentec.com/ffwloplugin -> C:\Program Files (x86)\HP SimplePass\npffwloplugin.dll [2013-02-08] ( HP) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.66 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-09-29] (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-09-29] (Intel Corporation) FF Plugin-x32: @itools.hk/npiTools, version=1.0.0 -> C:\Users\weeel\Documents\iTools\Plugin\npiTools.dll [2014-07-13] () FF Plugin-x32: @java.com/DTPlugin,version=11.60.2 -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\dtplugin\npDeployJava1.dll [2015-11-21] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.60.2 -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\plugin2\npjp2.dll [2015-11-21] (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation) FF Plugin-x32: @Nero.com/KM -> C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL [2012-08-23] (Nero AG) FF Plugin-x32: @videolan.org/vlc,version=2.1.0 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-14] (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-14] (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-14] (VideoLAN) FF Plugin HKU\S-1-5-21-3622977173-2670285063-1210919453-1002: @citrixonline.com/appdetectorplugin -> C:\Users\weeel\AppData\Local\Citrix\Plugins\104\npappdetector.dll [2015-10-18] (Citrix Online) FF Plugin HKU\S-1-5-21-3622977173-2670285063-1210919453-1002: @hola.org/vlc,version=1.7.860 -> C:\Users\weeel\AppData\Local\Hola\firefox\app\vlc [2015-05-17] () FF Plugin ProgramFiles/Appdata: C:\Users\weeel\AppData\Roaming\mozilla\plugins\np-mswmp.dll [2009-09-26] (Microsoft Corporation) FF SearchPlugin: C:\Users\weeel\AppData\Roaming\Mozilla\Firefox\Profiles\l7cg8hvw.default-1382944321897\searchplugins\default-search.xml [2014-09-18] FF SearchPlugin: C:\Users\weeel\AppData\Roaming\Mozilla\Firefox\Profiles\l7cg8hvw.default-1382944321897\searchplugins\duckduckgo.xml [2013-10-30] FF SearchPlugin: C:\Users\weeel\AppData\Roaming\Mozilla\Firefox\Profiles\l7cg8hvw.default-1382944321897\searchplugins\startpage-https.xml [2015-11-20] FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\default-search.xml [2014-09-18] FF Extension: Ant Video Downloader - C:\Users\weeel\AppData\Roaming\Mozilla\Firefox\Profiles\l7cg8hvw.default-1382944321897\extensions\[removed] [2015-05-30] FF Extension: HTTPS-Everywhere - C:\Users\weeel\AppData\Roaming\Mozilla\Firefox\Profiles\l7cg8hvw.default-1382944321897\extensions\[removed] [2015-08-28] FF Extension: 360 Internet Protection - C:\Program Files (x86)\360\Total Security\safemon\webprotection_firefox [2015-11-20] FF Extension: Ghostery - C:\Users\weeel\AppData\Roaming\Mozilla\Firefox\Profiles\l7cg8hvw.default-1382944321897\Extensions\[removed] [2015-11-06] FF Extension: Pin It button - C:\Users\weeel\AppData\Roaming\Mozilla\Firefox\Profiles\l7cg8hvw.default-1382944321897\Extensions\[removed] [2015-08-09] FF Extension: Adblock Edge - C:\Users\weeel\AppData\Roaming\Mozilla\Firefox\Profiles\l7cg8hvw.default-1382944321897\Extensions\{fe272bd1-5f76-4ea4-8501-a05d35d823fc}.xpi [2015-05-29] FF Extension: TrueSuite Website Logon - C:\Program Files (x86)\Mozilla Firefox\distribution\bundles\[removed] [2015-11-10] [not signed] FF HKLM\...\Firefox\Extensions: [{C1A2A613-35F1-4FCF-B27F-2840527B6556}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_22.5.0.124\coFFAddon => not found FF HKLM-x32\...\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\SearchPredict\PRFireFox => not found FF HKLM-x32\...\Firefox\Extensions: [{0329E7D6-6F54-462D-93F6-F5C3118BADF2}] - C:\Program Files (x86)\SPEEDbit Video Downloader\SPFireFox => not found FF HKLM-x32\...\Firefox\Extensions: [{C1A2A613-35F1-4FCF-B27F-2840527B6556}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_22.5.0.124\coFFAddon => not found FF HKLM-x32\...\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\360\Total Security\safemon\webprotection_firefox FF HKU\S-1-5-21-3622977173-2670285063-1210919453-1002\...\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\The Sea App (Firefox) FF Extension: The SEA App (C) - C:\Program Files (x86)\The Sea App (Firefox) [2015-07-08] [not signed] Chrome: ======= CHR HKLM-x32\...\Chrome\Extension: [hmbkhknacohfhbmmpnmbkgdffdbildof] - C:\Program Files (x86)\HP SimplePass\tschrome.crx [2012-12-13] ==================== Services (Whitelisted) ======================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) S3 ChromodoUpdater; C:\Program Files (x86)\Comodo\Chromodo\chromodo_updater.exe [1984696 2015-11-18] (Comodo) R2 FPLService; C:\Program Files (x86)\HP SimplePass\TrueSuiteService.exe [1641768 2013-02-08] (HP) R2 FreeAgentTheater Service; C:\Program Files (x86)\Seagate\Seagate_Media\Sync\MediaAggreService.exe [243752 2014-03-13] (Seagate Technology LLC) R2 HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [92160 2013-11-04] (Hewlett-Packard Company) [File not signed] R2 HPWMISVC; c:\Program Files (x86)\Hewlett-Packard\HP System Event\HPWMISVC.exe [1039160 2013-10-08] (Hewlett-Packard Development Company, L.P.) R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15344 2013-04-11] (Intel Corporation) R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [330136 2015-10-13] (Intel Corporation) R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [732160 2012-12-11] (Intel(R) Corporation) [File not signed] S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [803872 2012-12-11] (Intel(R) Corporation) R2 ISCTAgent; C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe [180200 2013-02-14] () R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165336 2013-01-15] (Intel Corporation) U2 OneSyncSvc_Session14; C:\WINDOWS\system32\svchost.exe [39856 2015-07-10] (Microsoft Corporation) U2 OneSyncSvc_Session14; C:\WINDOWS\SysWOW64\svchost.exe [35176 2015-07-11] (Microsoft Corporation) U3 PimIndexMaintenanceSvc_Session14; C:\WINDOWS\system32\svchost.exe [39856 2015-07-10] (Microsoft Corporation) U3 PimIndexMaintenanceSvc_Session14; C:\WINDOWS\SysWOW64\svchost.exe [35176 2015-07-11] (Microsoft Corporation) R2 QHActiveDefense; C:\Program Files (x86)\360\Total Security\safemon\QHActiveDefense.exe [903288 2015-11-20] (QIHU 360 SOFTWARE CO. LIMITED) R2 ss_conn_service; C:\Program Files\SAMSUNG\USB Drivers\25_escape\conn\ss_conn_service.exe [743688 2014-10-13] (DEVGURU Co., LTD.) R2 STacSV; C:\Program Files\IDT\WDM\STacSV64.exe [339456 2013-12-21] (IDT, Inc.) [File not signed] S3 TrueService; C:\Program Files\Common Files\AuthenTec\TrueService.exe [401856 2013-01-08] (AuthenTec, Inc.) U3 UnistoreSvc_Session14; C:\WINDOWS\System32\svchost.exe [39856 2015-07-10] (Microsoft Corporation) U3 UnistoreSvc_Session14; C:\WINDOWS\SysWOW64\svchost.exe [35176 2015-07-11] (Microsoft Corporation) U3 UserDataSvc_Session14; C:\WINDOWS\system32\svchost.exe [39856 2015-07-10] (Microsoft Corporation) U3 UserDataSvc_Session14; C:\WINDOWS\SysWOW64\svchost.exe [35176 2015-07-11] (Microsoft Corporation) R2 valWBFPolicyService; C:\Windows\system32\valWBFPolicyService.exe [28160 2013-03-20] () [File not signed] S3 w3logsvc; C:\Windows\system32\inetsrv\w3logsvc.dll [84480 2015-08-02] (Microsoft Corporation) S3 w3logsvc; C:\WINDOWS\SysWOW64\inetsrv\w3logsvc.dll [72192 2015-08-02] (Microsoft Corporation) S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [362928 2015-07-10] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-07-10] (Microsoft Corporation) S3 APNMCP; "C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe" [X] ===================== Drivers (Whitelisted) ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R1 360AntiHacker; C:\Windows\System32\Drivers\360AntiHacker64.sys [137808 2015-11-13] (360.cn) R3 360AvFlt; C:\Windows\System32\DRIVERS\360AvFlt.sys [77904 2015-11-13] (360.cn) R3 360AvFlt; C:\Windows\SysWOW64\DRIVERS\360AvFlt.sys [77904 2015-11-13] (360.cn) R1 360Box64; C:\Windows\System32\DRIVERS\360Box64.sys [319568 2015-11-13] (360.cn) R1 360Camera; C:\Windows\System32\Drivers\360Camera64.sys [40520 2015-11-13] (360.cn) R1 360FsFlt; C:\Windows\System32\DRIVERS\360FsFlt.sys [367696 2015-11-13] (360.cn) R1 BAPIDRV; C:\Windows\System32\DRIVERS\BAPIDRV64.sys [178768 2015-11-13] (360.cn) R3 BthL2caScoIfSrv; C:\Windows\System32\Drivers\BtL2caScoIf.sys [54064 2013-04-26] (Ralink Corporation) R3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [237568 2015-07-10] (Microsoft Corporation) R1 ElRawDisk; C:\WINDOWS\system32\drivers\rsdrvx64.sys [26024 2009-02-12] (EldoS Corporation) R3 ikbevent; C:\Windows\system32\DRIVERS\ikbevent.sys [21048 2013-02-14] () R3 imsevent; C:\Windows\system32\DRIVERS\imsevent.sys [21048 2013-02-14] () R3 ISCT; C:\Windows\System32\drivers\ISCTD64.sys [47008 2013-07-30] () R3 netr28x; C:\Windows\system32\DRIVERS\netr28x.sys [2554528 2015-06-12] (MediaTek Inc.) S3 RSP2STOR; C:\Windows\system32\DRIVERS\RtsP2Stor.sys [310528 2015-06-05] (Realtek Semiconductor Corp.) R3 rtbth; C:\Windows\System32\drivers\rtbth.sys [1219200 2015-06-03] (Ralink Technology, Corp.) S3 SmbDrv; C:\Windows\System32\drivers\Smb_driver_AMDASF.sys [28400 2013-02-06] (Synaptics Incorporated) R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [44216 2015-09-05] (Synaptics Incorporated) S3 UdeCx; C:\Windows\System32\drivers\udecx.sys [44032 2015-07-10] () S1 UimBus; C:\Windows\System32\drivers\UimBus.sys [102664 2014-10-30] () S1 Uim_DEVIM; C:\Windows\System32\drivers\uim_devim.sys [25992 2014-10-30] () S1 Uim_IM; C:\Windows\System32\drivers\uim_im.sys [700680 2014-10-30] () S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44568 2015-07-10] (Microsoft Corporation) S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [291680 2015-07-10] (Microsoft Corporation) S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [119648 2015-07-10] (Microsoft Corporation) R3 WirelessButtonDriver; C:\Windows\System32\drivers\WirelessButtonDriver64.sys [20800 2012-09-01] (Hewlett-Packard Development Company, L.P.) R3 WPRO_41_2001; C:\Windows\System32\drivers\WPRO_41_2001.sys [34752 2015-11-21] () S3 wfpcapture; \SystemRoot\System32\drivers\wfpcapture.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One Month Created files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2015-11-21 17:21 - 2015-11-21 17:21 - 00040206 _____ C:\Users\weeel\Desktop\Addition.txt 2015-11-21 17:20 - 2015-11-21 17:22 - 00024412 _____ C:\Users\weeel\Desktop\FRST.txt 2015-11-21 17:20 - 2015-11-21 17:22 - 00000000 ____D C:\FRST 2015-11-21 17:19 - 2015-11-21 17:20 - 02345984 _____ (Farbar) C:\Users\weeel\Desktop\FRST64.exe 2015-11-21 17:14 - 2015-11-21 17:14 - 00016148 _____ C:\WINDOWS\system32\LAMPO_weeel_HistoryPrediction.bin 2015-11-21 12:43 - 2015-11-21 12:43 - 00000000 ____D C:\Users\weeel\AppData\Roaming\Sun 2015-11-21 12:43 - 2015-11-21 12:43 - 00000000 ____D C:\Users\weeel\AppData\LocalLow\Oracle 2015-11-21 12:43 - 2015-11-21 12:43 - 00000000 ____D C:\Users\weeel\.oracle_jre_usage 2015-11-21 09:35 - 2015-11-21 09:35 - 00094656 _____ (CACE Technologies) C:\WINDOWS\system32\WPRO_41_2001woem.tmp 2015-11-21 09:33 - 2015-11-21 09:33 - 00000000 __SHD C:\$360Section 2015-11-21 07:46 - 2015-11-21 07:46 - 00000000 _____ C:\WINDOWS\System32\Tasks\CIS_{81EFDD93-DBBE-415B-BE6E-49B9664E3E82} 2015-11-20 22:47 - 2015-11-20 22:48 - 517264235 _____ C:\Users\weeel\Desktop\RESONANCE BEINGS OF FREQUENCY - OFFICIAL - YouTube.mp4 2015-11-20 22:28 - 2015-11-20 22:30 - 696919304 _____ C:\Users\weeel\Desktop\Strawman - The Nature of the Cage OFFICIAL - YouTube.mp4 2015-11-20 21:46 - 2015-11-21 09:33 - 00000000 ____D C:\ProgramData\360Quarant 2015-11-20 21:45 - 2015-11-21 12:39 - 00000000 ____D C:\WINDOWS\Tasks\360Disabled 2015-11-20 21:45 - 2015-11-21 07:43 - 00000000 ____D C:\Users\weeel\AppData\Roaming\360safe 2015-11-20 21:44 - 2015-11-21 17:20 - 00000000 ____D C:\Users\weeel\AppData\LocalLow\360WD 2015-11-20 21:44 - 2015-11-20 21:45 - 00000000 ____D C:\ProgramData\360safe 2015-11-20 21:44 - 2015-11-20 21:44 - 00000000 ____D C:\Users\weeel\AppData\Roaming\360TotalSecurity 2015-11-20 21:44 - 2015-11-20 21:44 - 00000000 ____D C:\ProgramData\360TotalSecurity 2015-11-20 21:44 - 2015-11-13 04:10 - 00367696 _____ (360.cn) C:\WINDOWS\system32\Drivers\360fsflt.sys 2015-11-20 21:44 - 2015-11-13 04:10 - 00077904 _____ (360.cn) C:\WINDOWS\SysWOW64\Drivers\360AvFlt.sys 2015-11-20 21:43 - 2015-11-20 21:43 - 00001233 _____ C:\Users\Public\Desktop\360 Total Security.lnk 2015-11-20 21:43 - 2015-11-20 21:43 - 00000000 _RSHD C:\360SANDBOX 2015-11-20 21:43 - 2015-11-20 21:43 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\360 Security Center 2015-11-20 21:43 - 2015-11-13 04:10 - 00319568 _____ (360.cn) C:\WINDOWS\system32\Drivers\360Box64.sys 2015-11-20 21:43 - 2015-11-13 04:10 - 00178768 _____ (360.cn) C:\WINDOWS\system32\Drivers\BAPIDRV64.SYS 2015-11-20 21:43 - 2015-11-13 04:10 - 00137808 _____ (360.cn) C:\WINDOWS\system32\Drivers\360AntiHacker64.sys 2015-11-20 21:43 - 2015-11-13 04:10 - 00077904 _____ (360.cn) C:\WINDOWS\system32\Drivers\360AvFlt.sys 2015-11-20 21:43 - 2015-11-13 04:10 - 00040520 _____ (360.cn) C:\WINDOWS\system32\Drivers\360Camera64.sys 2015-11-20 21:42 - 2015-11-20 21:42 - 00000000 ____D C:\Program Files (x86)\360 2015-11-20 21:41 - 2015-11-20 21:42 - 41816696 _____ C:\Users\weeel\Downloads\360TS_Setup.exe 2015-11-20 21:40 - 2015-11-20 21:40 - 00000046 _____ C:\WINDOWS\wininit.ini 2015-11-20 21:32 - 2015-11-20 21:40 - 01346168 _____ (QIHU 360 SOFTWARE CO. LIMITED) C:\Users\weeel\Downloads\360TS_Setup_Mini_OG_DS_SPDA.exe 2015-11-18 14:13 - 2015-11-18 14:13 - 00000000 ____D C:\Program Files (x86)\Comodo 2015-11-15 19:31 - 2015-11-21 12:39 - 00000000 ____D C:\WINDOWS\System32\Tasks\COMODO 2015-11-15 19:22 - 2015-11-15 19:29 - 225688096 _____ (COMODO) C:\Users\weeel\Downloads\cav_installer.exe 2015-11-15 19:19 - 2015-11-21 07:44 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Comodo 2015-11-15 19:19 - 2015-11-15 19:19 - 00001206 _____ C:\Users\Public\Desktop\Internet (Chromodo).lnk 2015-11-15 19:19 - 2015-11-15 19:19 - 00000000 ____D C:\Users\weeel\AppData\Local\Comodo 2015-11-15 19:17 - 2015-11-21 07:48 - 00000000 ____D C:\ProgramData\Comodo 2015-11-15 19:04 - 2015-11-15 19:19 - 225688096 _____ (COMODO) C:\Users\weeel\Downloads\cav_installer_5964_b8.exe 2015-11-15 19:04 - 2015-11-15 19:17 - 225688096 _____ (COMODO) C:\Users\weeel\Downloads\cispremium_installer_5962_fe.exe 2015-11-12 20:52 - 2015-11-05 18:15 - 08020832 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe 2015-11-12 20:52 - 2015-11-05 18:15 - 00541024 _____ (Microsoft Corporation) C:\WINDOWS\system32\mcupdate_GenuineIntel.dll 2015-11-12 20:52 - 2015-11-05 18:14 - 00459104 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\netio.sys 2015-11-12 20:52 - 2015-11-05 18:13 - 00577888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\afd.sys 2015-11-12 20:52 - 2015-11-05 18:11 - 01392480 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll 2015-11-12 20:52 - 2015-11-05 17:56 - 01083072 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll 2015-11-12 20:52 - 2015-11-05 17:56 - 00116064 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tdx.sys 2015-11-12 20:52 - 2015-11-05 17:56 - 00025280 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe 2015-11-12 20:52 - 2015-11-05 17:24 - 02878512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll 2015-11-12 20:52 - 2015-11-05 17:20 - 21873664 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll 2015-11-12 20:52 - 2015-11-05 17:18 - 24597504 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll 2015-11-12 20:52 - 2015-11-05 17:18 - 03248128 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll 2015-11-12 20:52 - 2015-11-05 17:17 - 02418688 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll 2015-11-12 20:52 - 2015-11-05 16:59 - 02675200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepository.dll 2015-11-12 20:52 - 2015-11-05 16:54 - 00502272 _____ (Microsoft Corporation) C:\WINDOWS\system32\dlnashext.dll 2015-11-12 20:52 - 2015-11-05 16:47 - 19326464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll 2015-11-12 20:52 - 2015-11-05 16:42 - 02647040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll 2015-11-12 20:52 - 2015-11-05 16:40 - 01918976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll 2015-11-12 20:52 - 2015-11-05 16:35 - 18803712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll 2015-11-12 20:52 - 2015-11-05 16:28 - 11262976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll 2015-11-12 20:52 - 2015-11-05 16:27 - 02049536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepository.dll 2015-11-12 20:52 - 2015-11-05 16:23 - 00441344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dlnashext.dll 2015-11-12 20:51 - 2015-11-05 18:06 - 03621248 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll 2015-11-12 20:51 - 2015-11-05 18:06 - 00966416 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll 2015-11-12 20:51 - 2015-11-05 18:01 - 00607408 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe 2015-11-12 20:51 - 2015-11-05 17:30 - 00961376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll 2015-11-12 20:51 - 2015-11-05 17:23 - 00762888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.appcore.dll 2015-11-12 20:51 - 2015-11-05 17:23 - 00076800 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll 2015-11-12 20:51 - 2015-11-05 17:18 - 00539728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe 2015-11-12 20:51 - 2015-11-05 17:12 - 00515072 _____ (Microsoft Corporation) C:\WINDOWS\system32\internetmail.dll 2015-11-12 20:51 - 2015-11-05 17:11 - 00333312 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll 2015-11-12 20:51 - 2015-11-05 17:10 - 12504064 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll 2015-11-12 20:51 - 2015-11-05 17:10 - 02987520 _____ (Microsoft Corporation) C:\WINDOWS\system32\esent.dll 2015-11-12 20:51 - 2015-11-05 17:07 - 01068032 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll 2015-11-12 20:51 - 2015-11-05 17:06 - 00453120 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Usb.dll 2015-11-12 20:51 - 2015-11-05 17:05 - 01602560 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll 2015-11-12 20:51 - 2015-11-05 17:05 - 00826880 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll 2015-11-12 20:51 - 2015-11-05 17:03 - 02180608 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll 2015-11-12 20:51 - 2015-11-05 17:03 - 01015808 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXService.dll 2015-11-12 20:51 - 2015-11-05 17:01 - 00949760 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll 2015-11-12 20:51 - 2015-11-05 17:01 - 00713216 _____ (Microsoft Corporation) C:\WINDOWS\system32\usermgr.dll 2015-11-12 20:51 - 2015-11-05 17:01 - 00579072 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe 2015-11-12 20:51 - 2015-11-05 16:59 - 03587072 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys 2015-11-12 20:51 - 2015-11-05 16:58 - 01383936 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys 2015-11-12 20:51 - 2015-11-05 16:58 - 00627712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.dll 2015-11-12 20:51 - 2015-11-05 16:56 - 01795072 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll 2015-11-12 20:51 - 2015-11-05 16:55 - 00145408 _____ (Microsoft Corporation) C:\WINDOWS\system32\dssvc.dll 2015-11-12 20:51 - 2015-11-05 16:35 - 02639872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\esent.dll 2015-11-12 20:51 - 2015-11-05 16:34 - 00311296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Usb.dll 2015-11-12 20:51 - 2015-11-05 16:33 - 01380864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll 2015-11-12 20:51 - 2015-11-05 16:33 - 00650240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll 2015-11-12 20:51 - 2015-11-05 16:30 - 00767488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll 2015-11-12 20:51 - 2015-11-05 16:27 - 00464896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.dll 2015-11-10 16:17 - 2015-11-14 21:34 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2015-11-09 21:19 - 2015-11-09 21:19 - 00000000 ____D C:\Users\weeel\Desktop\OpenOffice 4.1.2 (en-US) Installation Files 2015-11-09 21:12 - 2015-11-09 21:17 - 140783556 _____ C:\Users\weeel\Downloads\Apache_OpenOffice_4.1.2_Win_x86_install_en-US.exe 2015-10-30 14:48 - 2015-10-30 15:59 - 14083072 _____ C:\Users\weeel\Desktop\HOw to make awesome compost.ppt ==================== One Month Modified files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2015-11-21 16:52 - 2015-07-11 00:04 - 00000000 ____D C:\WINDOWS\system32\sru 2015-11-21 16:39 - 2015-10-18 14:10 - 00000670 _____ C:\WINDOWS\Tasks\G2MUploadTask-S-1-5-21-3622977173-2670285063-1210919453-1002.job 2015-11-21 16:26 - 2015-10-18 14:10 - 00000574 _____ C:\WINDOWS\Tasks\G2MUpdateTask-S-1-5-21-3622977173-2670285063-1210919453-1002.job 2015-11-21 14:59 - 2013-09-11 18:58 - 00004148 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{BC3E4D17-E80C-4089-A7E4-0D451DAA0BD1} 2015-11-21 13:12 - 2013-09-11 19:22 - 00000000 ____D C:\Users\weeel\AppData\Local\CrashDumps 2015-11-21 12:44 - 2013-04-24 17:12 - 00000000 ____D C:\WINDOWS\SysWOW64\Adobe 2015-11-21 12:43 - 2015-08-01 15:19 - 00000000 ____D C:\Users\weeel 2015-11-21 12:43 - 2014-10-15 20:41 - 00097888 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll 2015-11-21 12:43 - 2014-10-15 20:41 - 00000000 ____D C:\Program Files (x86)\Java 2015-11-21 12:43 - 2013-09-22 16:16 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2015-11-21 12:41 - 2014-04-27 14:46 - 00000000 ____D C:\Users\weeel\AppData\Roaming\Skype 2015-11-21 12:39 - 2015-05-17 16:04 - 00002818 _____ C:\WINDOWS\System32\Tasks\Seagate_Install_Launch 2015-11-21 12:39 - 2013-09-21 17:33 - 00003104 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater 2015-11-21 12:39 - 2013-09-21 17:33 - 00000830 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job 2015-11-21 09:37 - 2015-07-11 01:22 - 00000275 _____ C:\WINDOWS\WindowsUpdate.log 2015-11-21 09:36 - 2013-09-11 18:55 - 00000000 ____D C:\Users\weeel\AppData\LocalLow\AuthenTec 2015-11-21 09:35 - 2015-08-01 15:09 - 00680606 _____ C:\WINDOWS\PFRO.log 2015-11-21 09:35 - 2015-07-11 01:21 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT 2015-11-21 09:35 - 2013-06-13 03:34 - 00034752 _____ C:\WINDOWS\system32\Drivers\WPRO_41_2001.sys 2015-11-21 09:34 - 2015-07-10 22:05 - 00262144 ___SH C:\WINDOWS\system32\config\BBI 2015-11-21 07:46 - 2013-09-21 18:54 - 00000000 ____D C:\Users\weeel\AppData\Roaming\uTorrent 2015-11-20 22:33 - 2013-09-15 14:08 - 00000000 ____D C:\Users\weeel\AppData\Roaming\vlc 2015-11-20 22:08 - 2015-10-18 14:10 - 00003820 _____ C:\WINDOWS\System32\Tasks\G2MUploadTask-S-1-5-21-3622977173-2670285063-1210919453-1002 2015-11-20 22:08 - 2015-10-18 14:10 - 00003724 _____ C:\WINDOWS\System32\Tasks\G2MUpdateTask-S-1-5-21-3622977173-2670285063-1210919453-1002 2015-11-20 21:51 - 2015-08-02 11:07 - 00000000 ___DC C:\WINDOWS\Panther 2015-11-20 21:51 - 2013-06-13 03:42 - 00000000 ____D C:\ProgramData\Temp 2015-11-20 21:50 - 2014-01-09 11:10 - 00002548 _____ C:\WINDOWS\System32\Tasks\YCMServiceAgent 2015-11-20 21:50 - 2013-10-18 21:40 - 00002346 _____ C:\WINDOWS\System32\Tasks\{B533C221-71A6-4388-8B32-5A39403A06C7} 2015-11-20 21:50 - 2013-10-12 23:51 - 00002346 _____ C:\WINDOWS\System32\Tasks\{80A730D1-5DFE-4152-B5BF-08ACCF6B4552} 2015-11-20 21:50 - 2013-10-12 16:57 - 00002346 _____ C:\WINDOWS\System32\Tasks\{2B4E485A-F7C1-48E2-8DD2-0DF44A717715} 2015-11-20 21:50 - 2013-10-12 16:55 - 00002346 _____ C:\WINDOWS\System32\Tasks\{E33410C1-572E-4BBD-9B37-F8802D19D3CC} 2015-11-20 21:50 - 2013-06-13 03:58 - 00000000 ____D C:\ProgramData\Norton 2015-11-20 21:50 - 2013-06-13 03:54 - 00000000 ____D C:\ProgramData\install_clap 2015-11-20 21:39 - 2013-10-15 14:34 - 00003236 _____ C:\WINDOWS\System32\Tasks\HPCeeScheduleForweeel 2015-11-20 21:39 - 2013-10-15 14:34 - 00000344 _____ C:\WINDOWS\Tasks\HPCeeScheduleForweeel.job 2015-11-20 21:10 - 2013-09-21 22:21 - 00000000 ___RD C:\Users\weeel\Desktop\U Torrent Downloading 2015-11-20 20:18 - 2015-07-11 00:04 - 00000000 ____D C:\WINDOWS\AppReadiness 2015-11-20 20:12 - 2013-09-11 19:20 - 00000000 ____D C:\Users\weeel\Documents\Youcam 2015-11-18 17:47 - 2013-09-23 16:50 - 00000000 ____D C:\WINDOWS\system32\MRT 2015-11-18 17:40 - 2013-09-23 16:50 - 145617392 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2015-11-17 20:59 - 2013-09-11 20:42 - 00000000 ____D C:\Users\weeel\Documents\Will Work Notes 2015-11-17 19:27 - 2014-02-11 21:07 - 00000000 ____D C:\Users\weeel\AppData\Roaming\ConverterLite 2015-11-17 19:23 - 2015-08-01 15:18 - 01284754 _____ C:\WINDOWS\system32\PerfStringBackup.INI 2015-11-17 19:05 - 2015-07-11 01:20 - 00039512 _____ C:\WINDOWS\setupact.log 2015-11-15 21:05 - 2015-03-09 21:01 - 00000000 ____D C:\Users\weeel\Desktop\Pics to get printed March 2015 2015-11-15 20:12 - 2013-09-21 18:55 - 00001097 _____ C:\Users\weeel\Desktop\µTorrent.lnk 2015-11-15 20:01 - 2015-07-11 00:04 - 00000000 ___HD C:\WINDOWS\ELAMBKUP 2015-11-15 20:01 - 2015-07-10 22:05 - 00032768 ___SH C:\WINDOWS\system32\config\ELAM 2015-11-15 19:40 - 2013-06-13 03:47 - 00000000 ____D C:\Program Files (x86)\HP SimplePass 2015-11-15 19:11 - 2015-10-15 19:05 - 00000000 ____D C:\Users\weeel\Desktop\The Truth About Cancer 2015-11-15 14:55 - 2015-07-11 00:04 - 00000000 ____D C:\WINDOWS\rescache 2015-11-14 21:38 - 2015-07-11 00:04 - 00000000 ____D C:\WINDOWS\system32\appraiser 2015-11-14 21:34 - 2013-09-15 18:30 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2015-11-14 19:37 - 2015-07-10 23:55 - 00000000 ____D C:\WINDOWS\CbsTemp 2015-11-04 07:40 - 2014-04-27 14:45 - 00000000 ____D C:\ProgramData\Skype 2015-11-04 07:20 - 2015-10-06 13:47 - 00810488 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe 2015-11-04 07:20 - 2015-10-06 13:47 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl 2015-11-03 20:13 - 2015-08-01 16:01 - 00002381 _____ C:\Users\weeel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk 2015-11-03 20:13 - 2015-08-01 16:01 - 00000000 ___RD C:\Users\weeel\OneDrive 2015-10-27 19:29 - 2013-10-19 17:17 - 00000000 ____D C:\Users\weeel\AppData\Local\Windows Live 2015-10-23 06:37 - 2014-09-23 19:10 - 00000000 ____D C:\Users\weeel\Desktop\Power Bill ==================== Files in the root of some directories ======= 2014-07-30 21:07 - 2015-03-13 21:47 - 0005632 _____ () C:\Users\weeel\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2015-07-15 21:37 - 2015-07-15 21:37 - 0000017 _____ () C:\Users\weeel\AppData\Local\resmon.resmoncfg ==================== Bamital & volsnap ================= (There is no automatic fix for files that do not pass verification.) C:\WINDOWS\system32\winlogon.exe => File is digitally signed C:\WINDOWS\system32\wininit.exe => File is digitally signed C:\WINDOWS\explorer.exe => File is digitally signed C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed C:\WINDOWS\system32\svchost.exe => File is digitally signed C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed C:\WINDOWS\system32\services.exe => File is digitally signed C:\WINDOWS\system32\User32.dll => File is digitally signed C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed C:\WINDOWS\system32\userinit.exe => File is digitally signed C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed C:\WINDOWS\system32\rpcss.dll => File is digitally signed C:\WINDOWS\system32\dnsapi.dll => File is digitally signed C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-11-14 22:28 ==================== End of FRST.txt ============================