Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:09-01-2015 Ran by [removed] (administrator) on LOGAN-PC (09-01-2016 18:07:37) Running from C:\Users\[removed]\Desktop\Antimalware [removed] Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States) Internet Explorer Version 11 (Default browser: Chrome) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (Intel Corporation) C:\Windows\System32\igfxCUIService.exe (SurfRight B.V.) C:\Program Files\HitmanPro\hmpsched.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Windows (R) Win 7 DDK provider) C:\Program Files (x86)\Bluetooth Suite\AdminService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe (Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe (Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe (Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe (Symantec Corporation) C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\12.1.5337.5000.105\Bin\ccSvcHst.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe (Intel Corporation) C:\Windows\System32\igfxHK.exe (Qualcomm®Atheros®) C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (Ruiware) C:\Program Files (x86)\Ruiware\WinPatrol\WinPatrol.exe () C:\Program Files\Qualcomm Atheros\Network Manager\NetworkManager.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe (Alienware) C:\Program Files\Alienware\Command Center\AWCCServiceController.exe (Symantec Corporation) C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\12.1.5337.5000.105\Bin\ccSvcHst.exe (Alienware) C:\Program Files\Alienware\Command Center\AlienwareAlienFXController.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe () C:\Program Files (x86)\Alienware On-Screen Display\AlienwareOn-ScreenDisplay.exe (Logitech Inc.) C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe (Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe (Alienware) C:\Program Files\Alienware\Command Center\AWCCApplicationWatcher32.exe (Alienware) C:\Program Files\Alienware\Command Center\AWCCApplicationWatcher64.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Alienware) C:\Program Files\Alienware\Command Center\AlienFusionService.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Alienware) C:\Program Files\Alienware\Command Center\AlienFusionController.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) =========================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3011312 2013-04-08] (Synaptics Incorporated) HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [286192 2013-04-10] (Intel Corporation) HKLM\...\Run: [] => [X] HKLM\...\Run: [Command Center Controllers] => C:\Program Files\Alienware\Command Center\AWCCStartupOrchestrator.exe [14056 2014-10-30] (Alienware) HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2771576 2015-12-08] (NVIDIA Corporation) HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [500936 2015-05-26] (Adobe Systems Incorporated) HKLM\...\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [15033976 2015-11-20] (Logitech Inc.) HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [292848 2013-04-24] (Intel Corporation) HKLM-x32\...\Run: [AlienwareOn-ScreenDisplay] => C:\Program Files (x86)\Alienware On-Screen Display\AlienwareOn-ScreenDisplay.exe [4593968 2013-11-15] () HKLM-x32\...\Run: [DivXMediaServer] => C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe [837640 2015-12-08] (DivX, LLC) HKLM-x32\...\Run: [LWS] => C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe [204136 2012-09-13] (Logitech Inc.) HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2015-08-06] (Apple Inc.) HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [596528 2015-11-09] (Oracle Corporation) HKLM\...\Policies\Explorer\Run: [BtvStack] => C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [132736 2013-09-25] (Qualcomm®Atheros®) HKU\S-1-5-21-4242849718-3108068718-1801462104-1000\...\Run: [Xvid] => powershell.exe -nologo -WindowStyle hidden -Noninteractive -NoProfile -ExecutionPolicy Bypass -File "C:\Program Files (x86)\Xvid\CheckUpdate.ps1" HKU\S-1-5-21-4242849718-3108068718-1801462104-1000\...\Run: [WinPatrol] => C:\Program Files (x86)\Ruiware\WinPatrol\winpatrol.exe [1216648 2015-08-05] (Ruiware) HKU\S-1-5-21-4242849718-3108068718-1801462104-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\Ribbons.scr [241664 2010-11-20] (Microsoft Corporation) AppInit_DLLs: C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [175368 2015-12-16] (NVIDIA Corporation) AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [153392 2015-12-16] (NVIDIA Corporation) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Killer Network Manager.lnk [2015-07-24] ShortcutTarget: Killer Network Manager.lnk -> C:\Windows\Installer\{F9D8E17A-8670-4D39-AFBE-9B599BB85B1A}\NetworkManager.exe_130C27D738F34C89BDDF21BCFD74B56D.exe (Flexera Software LLC) Startup: C:\Users\Hartley\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Logitech blank Product Registration.lnk [2016-01-09] ShortcutTarget: Logitech blank Product Registration.lnk -> C:\Program Files (x86)\Logitech\G930\eReg.exe (Leader Technologies/Logitech) Startup: C:\Users\Hartley\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Monitor Ink Alerts - HP Deskjet 1510 series.lnk [2016-01-09] ShortcutTarget: Monitor Ink Alerts - HP Deskjet 1510 series.lnk -> C:\Program Files\HP\HP Deskjet 1510 series\Bin\HPStatusBL.dll (Hewlett-Packard Co.) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) Hosts: 127.0.0.1 localhost Tcpip\Parameters: [DhcpNameServer] 192.168.1.254 Tcpip\..\Interfaces\{F79600A4-6CAB-462E-8A1E-0B8E4C7A884E}: [DhcpNameServer] 192.168.1.254 Tcpip\..\Interfaces\{F985AE58-524E-4E93-8073-B5CF9F281779}: [DhcpNameServer] 192.168.1.254 Internet Explorer: ================== BHO-x32: Symantec Vulnerability Protection -> {6D53EC84-6AAE-4787-AEEE-F4628F01010C} -> C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\12.1.5337.5000.105\bin\IPS\IPSBHO.DLL [2014-09-12] (Symantec Corporation) BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26] (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\ssv.dll [2015-11-27] (Oracle Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\jp2ssv.dll [2015-11-27] (Oracle Corporation) FireFox: ======== FF ProfilePath: C:\Users\Hartley\AppData\Roaming\Mozilla\Firefox\Profiles\nkq7bpl8.default FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_20_0_0_267.dll [2015-12-30] () FF Plugin: @microsoft.com/GENUINE -> disabled [No File] FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [2015-03-09] (Adobe Systems) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_20_0_0_267.dll [2015-12-30] () FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2015-10-14] () FF Plugin-x32: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll [2014-05-22] (DivX, LLC.) FF Plugin-x32: @divx.com/DivX Web Player Plug-In,version=1.0.0 -> C:\Program Files (x86)\DivX\DivX Web Player\npdivx32.dll [2015-12-02] (DivX, LLC) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=3.0.72 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-03-12] (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-03-12] (Intel Corporation) FF Plugin-x32: @java.com/DTPlugin,version=11.66.2 -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\dtplugin\npDeployJava1.dll [2015-11-27] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.66.2 -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\plugin2\npjp2.dll [2015-11-27] (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File] FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2015-12-16] (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2015-12-16] (NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-03] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-03] (Google Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-09-30] (Adobe Systems Inc.) FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [2015-03-09] (Adobe Systems) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll [2015-09-30] (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll [2015-10-24] (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll [2015-10-24] (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll [2015-10-24] (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll [2015-10-24] (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll [2015-10-24] (Apple Inc.) Chrome: ======= CHR Session Restore: Default -> is enabled. CHR Profile: C:\Users\Hartley\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Translate) - C:\Users\Hartley\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb [2015-11-17] CHR Extension: (Google Drive) - C:\Users\Hartley\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-21] CHR Extension: (Poper Blocker) - C:\Users\Hartley\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkkbcggnhapdmkeljlodobbkopceiche [2015-09-04] CHR Extension: (YouTube) - C:\Users\Hartley\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-25] CHR Extension: (Adblock Plus) - C:\Users\Hartley\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2016-01-05] CHR Extension: (uBlock Origin) - C:\Users\Hartley\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpalhdlnbpafiamejdnhcphjbkeiagm [2016-01-08] CHR Extension: (Google Search) - C:\Users\Hartley\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-27] CHR Extension: (AdBlock) - C:\Users\Hartley\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2016-01-08] CHR Extension: (Popup Blocker Pro) - C:\Users\Hartley\AppData\Local\Google\Chrome\User Data\Default\Extensions\kiodaajmphnkcajieajajinghpejdjai [2015-09-04] CHR Extension: (Chrome Web Store Payments) - C:\Users\Hartley\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-09-04] CHR Extension: (Translate) - C:\Users\Hartley\AppData\Local\Google\Chrome\User Data\Default\Extensions\pfcdpalkplkfpolmbdhedhicijelcjjp [2015-09-04] CHR Extension: (Gmail) - C:\Users\Hartley\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-09-05] ==================== Services (Whitelisted) ======================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77104 2015-10-07] (Apple Inc.) R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [312448 2013-09-25] (Windows (R) Win 7 DDK provider) [File not signed] R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1156216 2015-12-08] (NVIDIA Corporation) R2 HitmanProScheduler; C:\Program Files\HitmanPro\hmpsched.exe [127752 2015-12-24] (SurfRight B.V.) R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15344 2013-04-10] (Intel Corporation) S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [73728 2004-10-22] (Macrovision Corporation) [File not signed] R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [355232 2015-08-09] (Intel Corporation) R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [731648 2013-02-13] (Intel(R) Corporation) [File not signed] S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [820184 2013-02-13] (Intel(R) Corporation) S3 ioloEnergyBooster; C:\Program Files\Alienware\Command Center\ioloEnergyBooster.exe [6145872 2012-11-01] (iolo technologies, LLC) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-03-12] (Intel Corporation) R2 LogiRegistryService; C:\Program Files\Logitech Gaming Software\Drivers\APOService\LogiRegistryService.exe [193144 2015-11-20] (Logitech Inc.) R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1513784 2015-10-05] (Malwarebytes) R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes) S2 MSI_ODD_Service; C:\Program Files (x86)\msi\ODD Monitor\ODD_Monitor.exe [76800 2011-10-04] (Micro-Star Int'l Co., Ltd.) [File not signed] R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1872504 2015-12-08] (NVIDIA Corporation) R3 NvStreamNetworkSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [8185464 2015-12-08] (NVIDIA Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [6477432 2015-12-08] (NVIDIA Corporation) R2 SepMasterService; C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\12.1.5337.5000.105\Bin\ccSvcHst.exe [144496 2014-09-12] (Symantec Corporation) S3 SNAC; C:\Program Files (x86)\Symantec\Symantec Endpoint Protection\12.1.5337.5000.105\Bin64\snac64.exe [394592 2014-09-12] (Symantec Corporation) S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-26] (Microsoft Corporation) ===================== Drivers (Whitelisted) ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R3 Ak27x64; C:\Windows\System32\DRIVERS\Ak27x64.sys [4057808 2013-09-04] (Qualcomm Atheros, Inc.) S3 AX88178; C:\Windows\System32\DRIVERS\ax88178.sys [56320 2009-10-02] (ASIX Electronics Corp.) R1 BfLwf; C:\Windows\System32\DRIVERS\bflwfx64.sys [67888 2013-02-13] (Qualcomm Atheros, Inc.) R1 BHDrvx64; C:\ProgramData\Symantec\Symantec Endpoint Protection\12.1.5337.5000.105\Data\Definitions\BASHDefs\20151223.011\BHDrvx64.sys [1665608 2015-10-08] (Symantec Corporation) R3 BTATH_LWFLT; C:\Windows\System32\DRIVERS\btath_lwflt.sys [77464 2013-09-25] (Qualcomm Atheros) R1 ccSettings_{5A2B9522-769B-49C3-9B8E-C708A1FEF279}; C:\Windows\System32\Drivers\SEP\0C0114D9\1388.105\x64\ccSetx64.sys [162392 2014-09-12] (Symantec Corporation) S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation) R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [498512 2015-11-17] (Symantec Corporation) R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [157520 2015-11-17] (Symantec Corporation) R0 iaStorF; C:\Windows\System32\drivers\iaStorF.sys [28656 2013-04-10] (Intel Corporation) R1 IDSVia64; C:\ProgramData\Symantec\Symantec Endpoint Protection\12.1.5337.5000.105\Data\Definitions\IPSDefs\20160108.011\IDSvia64.sys [767224 2015-12-04] (Symantec Corporation) R3 Ke2200; C:\Windows\System32\DRIVERS\e22w7x64.sys [154320 2013-03-20] (Qualcomm Atheros, Inc.) R2 LGCoreTemp; C:\Program Files\Logitech Gaming Software\Drivers\LgCoreTemp\lgcoretemp.sys [14184 2015-06-21] (Logitech) R3 LGJoyXlCore; C:\Windows\System32\drivers\LGJoyXlCore.sys [68384 2015-06-10] (Logitech Inc.) S3 lgLowAudio; C:\Windows\System32\drivers\lgLowAudio.sys [26264 2015-11-20] (Logitech Inc.) R1 mbamchameleon; C:\Windows\system32\drivers\mbamchameleon.sys [109272 2015-10-05] (Malwarebytes) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-10-05] (Malwarebytes) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [192216 2016-01-09] (Malwarebytes) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-10-05] (Malwarebytes Corporation) R3 NAVENG; C:\ProgramData\Symantec\Symantec Endpoint Protection\12.1.5337.5000.105\Data\Definitions\VirusDefs\20160108.021\ENG64.SYS [138488 2015-10-27] (Symantec Corporation) R3 NAVEX15; C:\ProgramData\Symantec\Symantec Endpoint Protection\12.1.5337.5000.105\Data\Definitions\VirusDefs\20160108.021\EX64.SYS [2148080 2015-10-27] (Symantec Corporation) R3 NTIOLib_X64; C:\Program Files (x86)\msi\ODD Monitor\NTIOLib_X64.sys [14136 2010-01-18] (MSI) R1 nvkflt; C:\Windows\System32\DRIVERS\nvkflt.sys [299312 2015-12-16] (NVIDIA Corporation) R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19576 2015-12-08] (NVIDIA Corporation) R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [50472 2015-08-10] (NVIDIA Corporation) R3 SmbDrvI; C:\Windows\System32\DRIVERS\Smb_driver_Intel.sys [32496 2013-04-08] (Synaptics Incorporated) R1 SRTSP; C:\Windows\System32\Drivers\SEP\0C0114D9\1388.105\x64\SRTSP64.SYS [880856 2014-09-12] (Symantec Corporation) R1 SRTSPX; C:\Windows\System32\Drivers\SEP\0C0114D9\1388.105\x64\SRTSPX64.SYS [37592 2014-09-12] (Symantec Corporation) R3 ST_ACCEL; C:\Windows\System32\DRIVERS\ST_Accel.sys [87776 2013-04-11] (STMicroelectronics) R0 SymEFASI; C:\Windows\System32\drivers\symefasi\0500010.01F\symefasi.sys [1611992 2015-07-24] (Symantec Corporation) R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [177752 2015-07-24] (Symantec Corporation) R1 SymIRON; C:\Windows\System32\Drivers\SEP\0C0114D9\1388.105\x64\Ironx64.SYS [266968 2014-09-12] (Symantec Corporation) R1 SYMNETS; C:\Windows\System32\Drivers\SEP\0C0114D9\1388.105\x64\SYMNETS.SYS [593112 2014-09-12] (Symantec Corporation) S3 WsAudioDevice_383S(1); C:\Windows\System32\drivers\WsAudioDevice_383S(1).sys [29288 2015-07-30] (Wondershare) S1 BAPIDRV; system32\DRIVERS\BAPIDRV64.sys [X] ========================== Drivers MD5 ======================= C:\Windows\system32\drivers\1394ohci.sys ==> MD5 is legit C:\Windows\System32\drivers\ACPI.sys ==> MD5 is legit C:\Windows\system32\drivers\acpipmi.sys ==> MD5 is legit C:\Windows\system32\drivers\adp94xx.sys ==> MD5 is legit C:\Windows\system32\drivers\adpahci.sys ==> MD5 is legit C:\Windows\system32\drivers\adpu320.sys ==> MD5 is legit C:\Windows\system32\drivers\afd.sys 9A4A1EEE802BF2F878EE8EAB407B21B7 C:\Windows\system32\drivers\agp440.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\Ak27x64.sys 5D2BCDF8B56B19AA48DB66BAB221F3DE C:\Windows\system32\drivers\aliide.sys ==> MD5 is legit C:\Windows\system32\drivers\amdide.sys ==> MD5 is legit C:\Windows\system32\drivers\amdk8.sys ==> MD5 is legit C:\Windows\system32\drivers\amdppm.sys ==> MD5 is legit C:\Windows\system32\drivers\amdsata.sys D4121AE6D0C0E7E13AA221AA57EF2D49 C:\Windows\system32\drivers\amdsbs.sys ==> MD5 is legit C:\Windows\System32\drivers\amdxata.sys 540DAF1CEA6094886D72126FD7C33048 C:\Windows\system32\drivers\appid.sys 27DABFB4A6B0140C34DBEC713469592B C:\Windows\system32\drivers\arc.sys ==> MD5 is legit C:\Windows\system32\drivers\arcsas.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\asyncmac.sys ==> MD5 is legit C:\Windows\system32\drivers\atapi.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\btath_flt.sys 65DD42A358451920A703EEEC1AB4995B C:\Windows\System32\DRIVERS\ax88178.sys CAEBC32C72C6E454CA0F0931A049CA25 C:\Windows\system32\drivers\bxvbda.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\b57nd60a.sys ==> MD5 is legit C:\Windows\System32\Drivers\Beep.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\bflwfx64.sys 35BAC943C9C9C501B2DB888858D41F99 C:\ProgramData\Symantec\Symantec Endpoint Protection\12.1.5337.5000.105\Data\Definitions\BASHDefs\20151223.011\BHDrvx64.sys 9CF4428D09C73B6F633AF9E58B835689 C:\Windows\System32\DRIVERS\blbdrive.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\bowser.sys ==> MD5 is legit C:\Windows\system32\drivers\BrFiltLo.sys ==> MD5 is legit C:\Windows\system32\drivers\BrFiltUp.sys ==> MD5 is legit C:\Windows\System32\Drivers\Brserid.sys ==> MD5 is legit C:\Windows\System32\Drivers\BrSerWdm.sys ==> MD5 is legit C:\Windows\System32\Drivers\BrUsbMdm.sys ==> MD5 is legit C:\Windows\System32\Drivers\BrUsbSer.sys ==> MD5 is legit C:\Windows\System32\drivers\btath_a2dp.sys 84CB2D06BBAD7ADBE28483D38E0388BC C:\Windows\System32\drivers\btath_avdt.sys 13076306110021CC96B2C49B359BE2C5 C:\Windows\System32\DRIVERS\btath_bus.sys C6978F7EBA6F37D626482AC6B9390630 C:\Windows\System32\DRIVERS\btath_hcrp.sys 4AF7C20F94DAC343C01ED671C82DCB99 C:\Windows\System32\DRIVERS\btath_lwflt.sys 785C38070043BEEE9E9D591DE4067244 C:\Windows\System32\DRIVERS\btath_rcp.sys 859A116D748FBA603AF94C251DC5CF97 C:\Windows\System32\DRIVERS\btfilter.sys CFB35D65B55E510E1A94DB6BEC0EA328 C:\Windows\system32\drivers\BthEnum.sys CF98190A94F62E405C8CB255018B2315 C:\Windows\system32\drivers\bthmodem.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\bthpan.sys 02DD601B708DD0667E1331FA8518E9FF C:\Windows\System32\Drivers\BTHport.sys 738D0E9272F59EB7A1449C3EC118E6C4 C:\Windows\System32\Drivers\BTHUSB.sys F188B7394D81010767B6DF3178519A37 C:\Windows\System32\Drivers\SEP\0C0114D9\1388.105\x64\ccSetx64.sys 0510396A957E9FD7205BA62D3CAE4528 C:\Windows\System32\DRIVERS\cdfs.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\cdrom.sys ==> MD5 is legit C:\Windows\system32\drivers\circlass.sys ==> MD5 is legit C:\Windows\System32\CLFS.sys 404B7DF9CA4D1CB675045AF220FF3285 C:\Windows\System32\DRIVERS\CmBatt.sys ==> MD5 is legit C:\Windows\system32\drivers\cmdide.sys ==> MD5 is legit C:\Windows\System32\Drivers\cng.sys EC0511BB85BAA42A9734011685A6732C C:\Windows\System32\DRIVERS\compbatt.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\CompositeBus.sys ==> MD5 is legit C:\Windows\system32\drivers\crcdisk.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\dc3d.sys 60E9FF9E15FB88D5751A4529E8876DEE C:\Windows\System32\Drivers\dfsc.sys CF1F6326AC44C42F4615D4BD53188AC5 C:\Windows\System32\drivers\discache.sys ==> MD5 is legit C:\Windows\System32\drivers\disk.sys ==> MD5 is legit C:\Windows\system32\drivers\drmkaud.sys ==> MD5 is legit C:\Windows\System32\drivers\dxgkrnl.sys 87CE5C8965E101CCCED1F4675557E868 C:\Windows\system32\drivers\evbda.sys ==> MD5 is legit C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys DB817375F4D6D3F2556DE7777775D885 C:\Windows\system32\drivers\elxstor.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\EMSC.SYS E47D9D7E6E53892FC97282482F4AE307 C:\Windows\SysWOW64\DRIVERS\EMSC.SYS CF460F454A0473E6C7AD846B94D8382A C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys A47F76D4AAFD6193AAC5E049C560213D C:\Windows\system32\drivers\errdev.sys ==> MD5 is legit C:\Windows\System32\Drivers\exfat.sys ==> MD5 is legit C:\Windows\System32\Drivers\fastfat.sys ==> MD5 is legit C:\Windows\system32\drivers\fdc.sys ==> MD5 is legit C:\Windows\System32\drivers\fileinfo.sys ==> MD5 is legit C:\Windows\System32\drivers\filetrace.sys ==> MD5 is legit C:\Windows\system32\drivers\flpydisk.sys ==> MD5 is legit C:\Windows\System32\drivers\fltmgr.sys ==> MD5 is legit C:\Windows\System32\drivers\FsDepends.sys ==> MD5 is legit C:\Windows\System32\Drivers\Fs_Rec.sys 6BD9295CC032DD3077C671FCCF579A7B C:\Windows\System32\DRIVERS\fvevol.sys 8F6322049018354F45F05A2FD2D4E5E0 C:\Windows\system32\drivers\gagp30kx.sys ==> MD5 is legit C:\Windows\system32\drivers\hcw85cir.sys ==> MD5 is legit C:\Windows\System32\drivers\HdAudio.sys 975761C778E33CD22498059B91E7373A C:\Windows\System32\DRIVERS\HDAudBus.sys ==> MD5 is legit C:\Windows\system32\drivers\HidBatt.sys ==> MD5 is legit C:\Windows\system32\drivers\hidbth.sys ==> MD5 is legit C:\Windows\system32\drivers\hidir.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\hidusb.sys ==> MD5 is legit C:\Windows\system32\drivers\HpSAMD.sys ==> MD5 is legit C:\Windows\System32\drivers\HTTP.sys F61634BEC53F73702A10DE69F6DCAF57 C:\Windows\System32\drivers\hwpolicy.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\i8042prt.sys ==> MD5 is legit C:\Windows\System32\drivers\iaStorA.sys 118CBC8D092787B604115F5267F77AE8 C:\Windows\System32\drivers\iaStorF.sys 3372DDF2F7FD01B2E061D13E7C3D69BF C:\Windows\system32\drivers\iaStorV.sys AAAF44DB3BD0B9D1FB6969B23ECC8366 C:\ProgramData\Symantec\Symantec Endpoint Protection\12.1.5337.5000.105\Data\Definitions\IPSDefs\20160108.011\IDSvia64.sys 3448DB2B812AA873ED6E5D609B1DB067 C:\Windows\System32\DRIVERS\igdkmd64.sys 5863E2DD2E5C2D1B1F70C3826C162A7B C:\Windows\system32\drivers\iirsp.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\IntcDAud.sys 8E4044C6B71B2F837166F6EDB6BF9100 C:\Windows\system32\drivers\intelide.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\intelppm.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\ipfltdrv.sys ==> MD5 is legit C:\Windows\system32\drivers\IPMIDrv.sys ==> MD5 is legit C:\Windows\System32\drivers\ipnat.sys ==> MD5 is legit C:\Windows\System32\drivers\irenum.sys ==> MD5 is legit C:\Windows\system32\drivers\isapnp.sys ==> MD5 is legit C:\Windows\system32\drivers\msiscsi.sys 96BB922A0981BC7432C8CF52B5410FE6 C:\Windows\System32\DRIVERS\iusb3hcs.sys A26955DC2350415849C05496D5563E5A C:\Windows\System32\DRIVERS\iusb3hub.sys 67DE0E5CA733D0086326D242F74C72C0 C:\Windows\System32\DRIVERS\iusb3xhc.sys 91B6B48710A35E9F308BC97F29716427 C:\Windows\System32\DRIVERS\kbdclass.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\kbdhid.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\e22w7x64.sys 819433A6CFC8771F0A2B0BB8EF6125B1 C:\Windows\System32\Drivers\ksecdd.sys BCC83F22805F560C8A487F2F296A78FE C:\Windows\System32\Drivers\ksecpkg.sys 33D52A96BEEE8AFCE9E07EEC9FE0C9DB C:\Windows\system32\drivers\ksthunk.sys ==> MD5 is legit C:\Windows\System32\drivers\LGBusEnum.sys 17325C9B9ADB2BB99049936D0C9812C8 C:\Program Files\Logitech Gaming Software\Drivers\LgCoreTemp\lgcoretemp.sys 2D7F1C02B94D6F0F3E10107E5EA8E141 C:\Windows\System32\drivers\LGJoyXlCore.sys C7AF05942E041D4B1F345ACF79993BB3 C:\Windows\System32\drivers\lgLowAudio.sys 07B1C1927BAE6431D3DFB1816DF05BBA C:\Windows\System32\drivers\LGVirHid.sys 1DDB8DE3D6EEF31EDCF4977B2D2FAACC C:\Windows\System32\DRIVERS\lltdio.sys ==> MD5 is legit C:\Windows\system32\drivers\lsi_fc.sys ==> MD5 is legit C:\Windows\system32\drivers\lsi_sas.sys ==> MD5 is legit C:\Windows\system32\drivers\lsi_sas2.sys ==> MD5 is legit C:\Windows\system32\drivers\lsi_scsi.sys ==> MD5 is legit C:\Windows\system32\drivers\luafv.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\lvrs64.sys A401CFF74982D8DF851F20307C806073 C:\Windows\System32\DRIVERS\lvuvc64.sys 13384CB5F5813E65F31078D6ABFAAF38 C:\Windows\system32\drivers\mbamchameleon.sys 42B3F5C9FBC9B3F0E0BA6B5D7FC8E849 C:\Windows\system32\drivers\mbam.sys CFBC6C6D8A492697CABD1D353EE64933 C:\Windows\system32\drivers\MBAMSwissArmy.sys 78488AF2AB2111D67B3C4044707A519B C:\Windows\system32\drivers\mwac.sys D61070CFAD43038DC56AEAD9BFE9CE2A C:\Windows\system32\drivers\megasas.sys ==> MD5 is legit C:\Windows\system32\drivers\MegaSR.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\HECIx64.sys 2BB3EAE2EA641515D4B205CAB29E1624 C:\Windows\System32\drivers\modem.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\monitor.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\mouclass.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\mouhid.sys ==> MD5 is legit C:\Windows\System32\drivers\mountmgr.sys 67050452C0118BAF2883928E6FCCFE47 C:\Windows\system32\drivers\mpio.sys ==> MD5 is legit C:\Windows\System32\drivers\mpsdrv.sys ==> MD5 is legit C:\Windows\system32\drivers\mrxdav.sys AE3334958D8F631FF14A0AEB3D7EFB3A C:\Windows\System32\DRIVERS\mrxsmb.sys 73ADDCC406B86E7DA4416691E8E74BDA C:\Windows\System32\DRIVERS\mrxsmb10.sys 7C81098FBAF2EAF5B54B939F832B0F61 C:\Windows\System32\DRIVERS\mrxsmb20.sys ACB763673BCCE6C7B3B8F858C9FE4F1F C:\Windows\system32\drivers\msahci.sys ==> MD5 is legit C:\Windows\system32\drivers\msdsm.sys ==> MD5 is legit C:\Windows\System32\Drivers\Msfs.sys ==> MD5 is legit C:\Windows\System32\drivers\mshidkmdf.sys ==> MD5 is legit C:\Windows\System32\drivers\msisadrv.sys ==> MD5 is legit C:\Windows\System32\drivers\MSKSSRV.sys ==> MD5 is legit C:\Windows\System32\drivers\MSPCLOCK.sys ==> MD5 is legit C:\Windows\System32\drivers\MSPQM.sys ==> MD5 is legit C:\Windows\System32\Drivers\MsRPC.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\mssmbios.sys ==> MD5 is legit C:\Windows\System32\drivers\MSTEE.sys ==> MD5 is legit C:\Windows\system32\drivers\MTConfig.sys ==> MD5 is legit C:\Windows\System32\Drivers\mup.sys AA0C2BA3782E92BD85E2264BE418E67C C:\Windows\System32\DRIVERS\nwifi.sys ==> MD5 is legit C:\ProgramData\Symantec\Symantec Endpoint Protection\12.1.5337.5000.105\Data\Definitions\VirusDefs\20160108.021\ENG64.SYS FE7B38240E86075E6BC5953496B5C2F1 C:\ProgramData\Symantec\Symantec Endpoint Protection\12.1.5337.5000.105\Data\Definitions\VirusDefs\20160108.021\EX64.SYS C002FA84570CA35F704ACF0AC4A5EAB0 C:\Windows\System32\drivers\ndis.sys F7309F42555F8AAB7144A51A1F2585B0 C:\Windows\System32\DRIVERS\ndiscap.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\ndistapi.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\ndisuio.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\ndiswan.sys ==> MD5 is legit C:\Windows\System32\Drivers\NDProxy.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\netbios.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\netbt.sys ==> MD5 is legit C:\Windows\system32\drivers\nfrd960.sys ==> MD5 is legit C:\Windows\System32\Drivers\Npfs.sys ==> MD5 is legit C:\Windows\System32\drivers\nsiproxy.sys ==> MD5 is legit C:\Windows\System32\Drivers\Ntfs.sys 1A29A59A4C5BA6F8C85062A613B7E2B2 C:\Program Files (x86)\msi\ODD Monitor\NTIOLib_X64.sys 3F39F013168428C8E505A7B9E6CBA8A2 C:\Windows\System32\Drivers\Null.sys ==> MD5 is legit C:\Windows\system32\drivers\nusb3hub.sys 786DB821BFD57C0551DBBE4F75384A7D C:\Windows\system32\drivers\nusb3xhc.sys DAA8005CAF745042BB427A1ED7433354 C:\Windows\System32\DRIVERS\nvkflt.sys 3BC860F8B30A28D82D28EACDA897906E C:\Windows\System32\DRIVERS\nvlddmkm.sys 506692268C5B1052B37528B5EAE4B967 C:\Windows\System32\DRIVERS\nvpciflt.sys 50EAA27EF22C6A6E2E8C8E4C5F31FCD1 C:\Windows\system32\drivers\nvraid.sys 0A92CB65770442ED0DC44834632F66AD C:\Windows\system32\drivers\nvstor.sys DAB0E87525C10052BF65F06152F37E4A C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys 9F0938D041D6203DA3B95AA3EBE4C34E C:\Windows\System32\drivers\nvvad64v.sys 35DFC12FD7E44B7CB8CCD7E5A2B3975A C:\Windows\system32\drivers\nv_agp.sys ==> MD5 is legit C:\Windows\system32\drivers\ohci1394.sys ==> MD5 is legit C:\Windows\system32\drivers\parport.sys ==> MD5 is legit C:\Windows\System32\drivers\partmgr.sys E9766131EEADE40A27DC27D2D68FBA9C C:\Windows\System32\drivers\pci.sys ==> MD5 is legit C:\Windows\system32\drivers\pciide.sys ==> MD5 is legit C:\Windows\system32\drivers\pcmcia.sys ==> MD5 is legit C:\Windows\System32\drivers\pcw.sys ==> MD5 is legit C:\Windows\System32\drivers\peauth.sys ED6E75158D28D33A2E2A020AC5B2B59D C:\Windows\System32\DRIVERS\raspptp.sys ==> MD5 is legit C:\Windows\system32\drivers\processr.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\pacer.sys ==> MD5 is legit C:\Windows\system32\drivers\ql2300.sys ==> MD5 is legit C:\Windows\system32\drivers\ql40xx.sys ==> MD5 is legit C:\Windows\system32\drivers\qwavedrv.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\rasacd.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\AgileVpn.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\rasl2tp.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\raspppoe.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\rassstp.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\rdbss.sys 71B6F78D6444CCE6F77BC42917A4E8F7 C:\Windows\system32\drivers\rdpbus.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\RDPCDD.sys ==> MD5 is legit C:\Windows\System32\drivers\rdpencdd.sys ==> MD5 is legit C:\Windows\System32\drivers\rdprefmp.sys ==> MD5 is legit C:\Windows\System32\drivers\rdpvideominiport.sys 313F68E1A3E6345A4F47A36B07062F34 C:\Windows\System32\Drivers\RDPWD.sys FE571E088C2D83619D2D48D4E961BF41 C:\Windows\System32\drivers\rdyboost.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\revoflt.sys 9C3AC71A9934B884FAC567A8807E9C4D C:\Windows\System32\DRIVERS\rfcomm.sys 3DD798846E2C28102B922C56E71B7932 C:\Windows\System32\DRIVERS\RtsPStor.sys 73993E0AE5908C4AFE33D3E355E600BC C:\Windows\System32\DRIVERS\rspndr.sys ==> MD5 is legit C:\Windows\system32\drivers\sbp2port.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\scfilter.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\sdbus.sys 111E0EBC0AD79CB0FA014B907B231CF0 C:\Windows\System32\Drivers\secdrv.sys ==> MD5 is legit C:\Windows\system32\drivers\serenum.sys ==> MD5 is legit C:\Windows\system32\drivers\serial.sys ==> MD5 is legit C:\Windows\system32\drivers\sermouse.sys ==> MD5 is legit C:\Windows\system32\drivers\sffdisk.sys ==> MD5 is legit C:\Windows\system32\drivers\sffp_mmc.sys ==> MD5 is legit C:\Windows\system32\drivers\sffp_sd.sys ==> MD5 is legit C:\Windows\system32\drivers\sfloppy.sys ==> MD5 is legit C:\Windows\system32\drivers\SiSRaid2.sys ==> MD5 is legit C:\Windows\system32\drivers\sisraid4.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\smb.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\Smb_driver_Intel.sys 5476D773EE180AEB9CADA786EA131777 C:\Windows\System32\Drivers\spldr.sys ==> MD5 is legit C:\Windows\System32\Drivers\SEP\0C0114D9\1388.105\x64\SRTSP64.SYS 1EDDCBC683A90AC7E186ABF22B760839 C:\Windows\System32\Drivers\SEP\0C0114D9\1388.105\x64\SRTSPX64.SYS 68E7B6708B9EEE021301C483825D05EA C:\Windows\System32\DRIVERS\srv.sys 441FBA48BFF01FDB9D5969EBC1838F0B C:\Windows\System32\DRIVERS\srv2.sys B4ADEBBF5E3677CCE9651E0F01F7CC28 C:\Windows\System32\DRIVERS\srvnet.sys 27E461F0BE5BFF5FC737328F749538C3 C:\Windows\System32\DRIVERS\stdcfltn.sys E4EA2412FB1B8AEE33667A9CC6D456A4 C:\Windows\system32\drivers\stexstor.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\ST_Accel.sys 5515D39205E0B59045DED8573A9E2179 C:\Windows\System32\DRIVERS\swenum.sys ==> MD5 is legit C:\Windows\System32\drivers\symefasi\0500010.01F\symefasi.sys 6E61AFF94BC6556268C6F51431F9497E C:\Windows\system32\Drivers\SYMEVENT64x86.SYS 97E11C50CE52277B377396EA8838E539 C:\Windows\System32\Drivers\SEP\0C0114D9\1388.105\x64\Ironx64.SYS 2C95265BE19F338E1C1090E4E91055BB C:\Windows\System32\Drivers\SEP\0C0114D9\1388.105\x64\SYMNETS.SYS 5570A74FF9B1EFBC5154DD1E2F05C517 C:\Windows\System32\DRIVERS\SynTP.sys 75B2DF282F2D40C7DC721EC4CADC7DB5 C:\Windows\System32\drivers\tcpip.sys 04ADD18EE5CC9FBEDAEC1DD1CD0CB45E C:\Windows\System32\DRIVERS\tcpip.sys 04ADD18EE5CC9FBEDAEC1DD1CD0CB45E C:\Windows\System32\drivers\tcpipreg.sys 1B16D0BD9841794A6E0CDE0CEF744ABC C:\Windows\System32\drivers\tdpipe.sys ==> MD5 is legit C:\Windows\System32\drivers\tdtcp.sys 51C5ECEB1CDEE2468A1748BE550CFBC8 C:\Windows\System32\DRIVERS\tdx.sys AA77EB517D2F07A947294F260E3ACA83 C:\Windows\System32\DRIVERS\termdd.sys ==> MD5 is legit C:\Windows\system32\drivers\terminpt.sys EF4469AB69EB15E5D3754E6AEAFBCD3D C:\Windows\System32\DRIVERS\tssecsrv.sys E232A3B43A894BB327FC161529BD9ED1 C:\Windows\System32\drivers\tsusbflt.sys 17C6B51CBCCDED95B3CC14E22791F85E C:\Windows\system32\drivers\TsUsbGD.sys AD64450A4ABE076F5CB34CC08EEACB07 C:\Windows\System32\DRIVERS\tunnel.sys ==> MD5 is legit C:\Windows\system32\drivers\uagp35.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\udfs.sys ==> MD5 is legit C:\Windows\system32\drivers\uliagpkx.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\umbus.sys ==> MD5 is legit C:\Windows\system32\drivers\umpass.sys ==> MD5 is legit C:\Windows\System32\drivers\usbaudio.sys B0435098C81D04CAFFF80DDB746CD3A2 C:\Windows\System32\DRIVERS\usbccgp.sys DCA68B0943D6FA415F0C56C92158A83A C:\Windows\system32\drivers\usbcir.sys 80B0F7D5CCF86CEB5D402EAAF61FEC31 C:\Windows\system32\drivers\usbehci.sys 18A85013A3E0F7E1755365D287443965 C:\Windows\System32\DRIVERS\usbhub.sys 8D1196CFBB223621F2C67D45710F25BA C:\Windows\system32\drivers\usbohci.sys 765A92D428A8DB88B960DA5A8D6089DC C:\Windows\System32\DRIVERS\usbprint.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\usbscan.sys 9661DA76B4531B2DA272ECCE25A8AF24 C:\Windows\System32\DRIVERS\USBSTOR.SYS FED648B01349A3C8395A5169DB5FB7D6 C:\Windows\system32\drivers\usbuhci.sys DD253AFC3BC6CBA412342DE60C3647F3 C:\Windows\System32\Drivers\usbvideo.sys 1F775DA4CF1A3A1834207E975A72E9D7 C:\Windows\System32\drivers\vdrvroot.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\vgapnp.sys ==> MD5 is legit C:\Windows\System32\drivers\vga.sys ==> MD5 is legit C:\Windows\system32\drivers\vhdmp.sys ==> MD5 is legit C:\Windows\system32\drivers\viaide.sys ==> MD5 is legit C:\Windows\System32\drivers\volmgr.sys ==> MD5 is legit C:\Windows\System32\drivers\volmgrx.sys ==> MD5 is legit C:\Windows\System32\drivers\volsnap.sys ==> MD5 is legit C:\Windows\system32\drivers\vsmraid.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\vwifibus.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\vwififlt.sys ==> MD5 is legit C:\Windows\system32\drivers\wacompen.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\wanarp.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\wanarp.sys ==> MD5 is legit C:\Windows\system32\drivers\wd.sys ==> MD5 is legit C:\Windows\System32\drivers\Wdf01000.sys E2C933EDBC389386EBE6D2BA953F43D8 C:\Windows\System32\DRIVERS\wfplwf.sys ==> MD5 is legit C:\Windows\System32\drivers\wimmount.sys ==> MD5 is legit C:\Windows\SysWOW64\drivers\wimmount.sys ==> MD5 is legit C:\Windows\System32\DRIVERS\WinUsb.sys FE88B288356E7B47B74B13372ADD906D C:\Windows\System32\DRIVERS\wmiacpi.sys ==> MD5 is legit C:\Windows\system32\drivers\ws2ifsl.sys ==> MD5 is legit C:\Windows\System32\drivers\WsAudioDevice_383S(1).sys AD12F5C7251BB8D575D560894E73CBBA C:\Windows\System32\drivers\WudfPf.sys AB886378EEB55C6C75B4F2D14B6C869F C:\Windows\System32\DRIVERS\WUDFRd.sys DDA4CAF29D8C0A297F886BFE561E6659 ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One Month Created files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2016-01-09 18:07 - 2016-01-09 18:07 - 00000000 ____D C:\FRST 2016-01-09 14:49 - 2016-01-09 14:49 - 00000000 ___RD C:\Users\Hartley\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BT Devices 2016-01-08 14:26 - 2016-01-08 14:26 - 00008904 _____ C:\Users\Hartley\Desktop\VAIN BD.veg 2016-01-08 13:22 - 2016-01-08 13:22 - 05920862 _____ C:\Users\Hartley\Desktop\VAIN FOR JAPEN_x264.mp4 2016-01-08 13:20 - 2016-01-08 13:20 - 00415232 _____ C:\Users\Hartley\Desktop\06 Push Off the Ground.m4a.sfk 2016-01-08 13:20 - 2016-01-08 13:20 - 00008824 _____ C:\Users\Hartley\Desktop\Untitled.MP4.sfk 2016-01-08 00:10 - 2016-01-08 00:10 - 00000000 ____D C:\Windows\SysWOW64\NV 2016-01-08 00:10 - 2016-01-08 00:10 - 00000000 ____D C:\Windows\system32\NV 2016-01-08 00:10 - 2015-12-16 08:39 - 00103032 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe 2016-01-08 00:07 - 2015-12-16 11:34 - 42977072 _____ C:\Windows\system32\nvcompiler.dll 2016-01-08 00:07 - 2015-12-16 11:34 - 37609080 _____ C:\Windows\SysWOW64\nvcompiler.dll 2016-01-08 00:07 - 2015-12-16 11:34 - 31061624 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll 2016-01-08 00:07 - 2015-12-16 11:34 - 24895792 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll 2016-01-08 00:07 - 2015-12-16 11:34 - 21122456 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll 2016-01-08 00:07 - 2015-12-16 11:34 - 20663816 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll 2016-01-08 00:07 - 2015-12-16 11:34 - 18716176 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll 2016-01-08 00:07 - 2015-12-16 11:34 - 17561432 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll 2016-01-08 00:07 - 2015-12-16 11:34 - 17156968 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll 2016-01-08 00:07 - 2015-12-16 11:34 - 16981976 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll 2016-01-08 00:07 - 2015-12-16 11:34 - 16286888 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll 2016-01-08 00:07 - 2015-12-16 11:34 - 12334200 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys 2016-01-08 00:07 - 2015-12-16 11:34 - 03168376 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll 2016-01-08 00:07 - 2015-12-16 11:34 - 02755704 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll 2016-01-08 00:07 - 2015-12-16 11:34 - 00938104 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll 2016-01-08 00:07 - 2015-12-16 11:34 - 00872056 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll 2016-01-08 00:07 - 2015-12-16 11:34 - 00734512 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll 2016-01-08 00:07 - 2015-12-16 11:34 - 00681592 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll 2016-01-08 00:07 - 2015-12-16 11:34 - 00502080 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll 2016-01-08 00:07 - 2015-12-16 11:34 - 00423264 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll 2016-01-08 00:07 - 2015-12-16 11:34 - 00299312 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvkflt.sys 2016-01-08 00:07 - 2015-12-16 11:34 - 00151184 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll 2016-01-08 00:07 - 2015-12-16 11:34 - 00128696 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll 2016-01-08 00:07 - 2015-12-16 11:34 - 00031352 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvpciflt.sys 2016-01-07 01:09 - 2016-01-07 01:09 - 02497011 _____ C:\Users\Hartley\Desktop\VAIN FOR JAPEN.mp4 2016-01-06 23:28 - 2016-01-06 23:28 - 00000000 ____D C:\ProgramData\Logitech 2016-01-06 23:27 - 2016-01-06 23:27 - 00000000 ____D C:\Program Files\Logitech 2016-01-06 23:23 - 2016-01-06 23:24 - 37683312 _____ (Logitech ) C:\Users\Hartley\Desktop\g930_100364b_x64.exe 2016-01-03 20:44 - 2016-01-07 11:02 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2016-01-03 12:45 - 2016-01-03 12:45 - 868183498 _____ C:\Windows\MEMORY.DMP 2016-01-03 12:45 - 2016-01-03 12:45 - 00337920 _____ C:\Windows\Minidump\010316-33789-01.dmp 2016-01-03 12:45 - 2016-01-03 12:45 - 00000000 ____D C:\Windows\Minidump 2015-12-29 19:25 - 2015-12-29 19:25 - 00000000 ____D C:\Users\Hartley\Desktop\Psychology 2015-12-29 17:08 - 2015-12-29 17:08 - 00001755 _____ C:\Users\Public\Desktop\iTunes.lnk 2015-12-29 17:08 - 2015-12-29 17:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes 2015-12-29 17:07 - 2015-12-29 17:07 - 00000000 ____D C:\Program Files\iPod 2015-12-29 17:07 - 2015-12-29 17:07 - 00000000 ____D C:\Program Files (x86)\iTunes 2015-12-27 16:03 - 2015-12-27 16:03 - 00005052 _____ C:\TDSSKiller.3.1.0.9_27.12.2015_16.03.05_log.txt 2015-12-27 15:57 - 2015-12-27 16:01 - 00896646 _____ C:\TDSSKiller.3.1.0.9_27.12.2015_15.57.36_log.txt 2015-12-27 15:54 - 2015-12-27 15:55 - 00005318 _____ C:\TDSSKiller.3.1.0.9_27.12.2015_15.54.32_log.txt 2015-12-27 15:53 - 2015-12-27 15:53 - 00005152 _____ C:\TDSSKiller.3.1.0.5_27.12.2015_15.53.37_log.txt 2015-12-27 15:52 - 2015-12-27 15:53 - 00000434 _____ C:\TDSSKiller.3.1.0.5_27.12.2015_15.52.57_log.txt 2015-12-27 15:52 - 2015-12-27 15:52 - 00000434 _____ C:\TDSSKiller.3.1.0.5_27.12.2015_15.52.10_log.txt 2015-12-26 19:40 - 2015-12-26 19:41 - 10886063 _____ C:\Users\Hartley\Desktop\Teaser Trailer for Push.mp4 2015-12-26 19:30 - 2015-12-26 19:30 - 05641542 _____ C:\Users\Hartley\Desktop\Teaser Trailer.mp4 2015-12-26 16:13 - 2015-12-26 17:49 - 00000000 ____D C:\Users\Hartley\Desktop\Pen Pictures 2015-12-26 01:25 - 2015-12-26 20:21 - 00013464 _____ C:\Users\Hartley\Desktop\push.veg 2015-12-26 01:12 - 2015-12-26 01:13 - 01343049 _____ C:\Users\Hartley\Desktop\Trailer.mp4 2015-12-26 00:49 - 2015-12-26 01:08 - 03976790 _____ C:\Users\Hartley\Desktop\tease.mp4 2015-12-26 00:31 - 2015-12-26 00:31 - 09983559 _____ C:\Users\Hartley\Desktop\Untitled.MP4 2015-12-25 23:54 - 2015-12-26 00:04 - 00000000 ____D C:\Users\Hartley\Desktop\LA Intro 2015-12-25 14:17 - 2015-12-25 14:17 - 00000000 ____D C:\Users\Hartley\AppData\Local\Logitech 2015-12-25 14:14 - 2015-12-25 14:17 - 00000000 ____D C:\Program Files\Logitech Gaming Software 2015-12-25 14:13 - 2015-12-25 14:13 - 00000000 ____D C:\Users\Hartley\AppData\Roaming\Logitech 2015-12-25 14:13 - 2015-12-25 14:13 - 00000000 ____D C:\Users\Hartley\AppData\Roaming\Logishrd 2015-12-25 12:25 - 2015-12-29 18:55 - 00000000 ____D C:\tmp 2015-12-24 23:47 - 2015-12-26 00:02 - 804584664 _____ C:\Users\Hartley\Desktop\Push Intro.blend 2015-12-24 22:22 - 2015-12-24 22:22 - 00000000 ____D C:\Users\Hartley\AppData\Roaming\Blender Foundation 2015-12-24 21:50 - 2015-12-24 21:50 - 00000000 ____D C:\Users\Hartley\.thumbnails 2015-12-24 21:32 - 2015-12-24 21:32 - 00000000 ____D C:\Users\Hartley\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Blender 2015-12-24 21:30 - 2015-12-24 21:30 - 00000000 ____D C:\Program Files\Blender Foundation 2015-12-24 19:48 - 2015-12-24 19:48 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RogueKiller 2015-12-24 19:48 - 2015-12-24 19:48 - 00000000 ____D C:\Program Files\RogueKiller 2015-12-23 19:15 - 2015-12-22 15:14 - 08584929 _____ C:\Users\Hartley\Desktop\01 Start a New One.m4a 2015-12-23 18:24 - 2015-12-23 18:24 - 00000000 ____D C:\Program Files (x86)\FFmpeg for Audacity 2015-12-23 18:21 - 2015-12-23 18:21 - 00000000 ____D C:\Program Files (x86)\Lame For Audacity 2015-12-23 18:12 - 2015-12-22 20:32 - 10666416 _____ C:\Users\Hartley\Desktop\06 Push Off the Ground.m4a 2015-12-22 01:51 - 2015-12-16 11:34 - 01915696 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6436143.dll 2015-12-22 01:51 - 2015-12-16 11:34 - 01564976 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6436143.dll 2015-12-22 01:51 - 2015-12-16 11:34 - 00416376 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFROpenGL.dll 2015-12-22 01:51 - 2015-12-16 11:34 - 00370808 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFROpenGL.dll 2015-12-19 14:20 - 2015-12-30 22:44 - 00000000 ____D C:\Users\Hartley\Desktop\MENOWA'S LINKS 2015-12-19 13:51 - 2015-12-19 13:51 - 00000000 ____D C:\Users\Hartley\Downloads\Genki - An Integrated Course in Elementary Japanese [Second Edition] (2011) 2015-12-16 21:44 - 2015-12-26 15:31 - 00000000 ____D C:\AdwCleaner 2015-12-16 21:39 - 2015-12-16 21:47 - 27676736 _____ (Adlice Software ) C:\Users\Hartley\Downloads\setup.exe.part 2015-12-16 19:48 - 2015-12-24 19:48 - 00036608 _____ C:\Windows\system32\Drivers\TrueSight.sys 2015-12-16 19:48 - 2015-12-16 19:54 - 00000000 ____D C:\ProgramData\RogueKiller 2015-12-16 19:42 - 2015-12-16 19:42 - 00019834 ____H C:\Windows\Tasks\{0B050847-0D0D-7F0E-7E11-0B05080F117E}.job 2015-12-16 19:42 - 2015-12-16 19:42 - 00000000 ____D C:\ProgramData\802b8e8a-4161-1 2015-12-16 19:36 - 2015-12-16 19:36 - 00023212 _____ C:\Windows\System32\Tasks\{0B050847-0D0D-7F0E-7E11-0B05080F117E} 2015-12-16 19:36 - 2015-12-16 19:36 - 00000000 ____D C:\ProgramData\802b8e8a-27d3-0 2015-12-16 19:36 - 2015-12-16 19:36 - 00000000 ____D C:\ProgramData\802b8e8a-1207-1 2015-12-14 19:33 - 2015-12-14 19:33 - 00000000 ___RD C:\Program Files (x86)\Skype 2015-12-14 19:33 - 2015-12-14 19:33 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype 2015-12-13 01:55 - 2015-12-13 01:55 - 00000000 ____D C:\Users\Hartley\AppData\Local\Alienware 2015-12-12 19:28 - 2015-12-19 20:44 - 00009304 _____ C:\Users\Hartley\Desktop\XOUND.veg 2015-12-10 20:11 - 2015-12-10 20:14 - 49797913 _____ C:\Users\Hartley\Desktop\Xound FS Slowed down.wmv 2015-12-10 19:50 - 2015-12-10 19:50 - 15229741 _____ C:\Users\Hartley\Desktop\Xound FS_WMV V9.wmv 2015-12-10 19:33 - 2013-12-17 21:36 - 17006136 _____ (VS Revo Group) C:\Users\Hartley\Desktop\RevoUninPro.exe 2015-12-10 19:27 - 2015-12-10 19:27 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller Pro 2015-12-10 19:27 - 2015-12-10 19:27 - 00000000 ____D C:\Program Files\VS Revo Group 2015-12-10 19:27 - 2009-12-30 10:21 - 00031800 _____ (VS Revo Group) C:\Windows\system32\Drivers\revoflt.sys 2015-12-10 19:15 - 2015-12-10 19:15 - 00000000 ____D C:\Users\Hartley\Desktop\Revo Uninstaller Pro ==================== One Month Modified files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2016-01-09 18:07 - 2015-09-14 12:01 - 00000000 ____D C:\Users\Hartley\AppData\Roaming\Skype 2016-01-09 18:07 - 2015-08-16 19:30 - 00000000 ____D C:\Users\Hartley\Desktop\Antimalware 2016-01-09 18:07 - 2009-07-13 21:20 - 00000000 ____D C:\Windows 2016-01-09 17:57 - 2015-07-24 16:10 - 00000506 _____ C:\Windows\Tasks\SystemToolsDailyTest.job 2016-01-09 17:52 - 2015-07-24 15:15 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2016-01-09 17:50 - 2015-10-18 15:09 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2016-01-09 17:15 - 2015-09-04 15:57 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2016-01-09 15:03 - 2009-07-13 22:45 - 00020688 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2016-01-09 15:03 - 2009-07-13 22:45 - 00020688 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2016-01-09 14:48 - 2015-09-04 15:57 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2016-01-09 14:48 - 2015-07-24 15:11 - 00000000 ____D C:\ProgramData\NVIDIA 2016-01-09 14:48 - 2009-07-13 23:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2016-01-09 02:00 - 2015-07-24 15:14 - 00000000 ____D C:\Users\Hartley\AppData\Local\Adobe 2016-01-09 00:18 - 2009-07-13 23:13 - 00784286 _____ C:\Windows\system32\PerfStringBackup.INI 2016-01-09 00:18 - 2009-07-13 21:20 - 00000000 ____D C:\Windows\inf 2016-01-08 21:23 - 2015-09-08 04:10 - 00000000 ____D C:\Users\Hartley\AppData\Local\ElevatedDiagnostics 2016-01-08 21:23 - 2009-07-13 21:20 - 00000000 ____D C:\Windows\system32\NDF 2016-01-08 21:22 - 2015-07-24 14:18 - 00000000 ____D C:\Users\Hartley\Documents\Bluetooth Folder 2016-01-08 19:34 - 2015-07-24 13:41 - 00000000 ____D C:\ProgramData\Symantec 2016-01-08 13:21 - 2015-09-24 00:21 - 00000000 ____D C:\Users\Hartley\AppData\Roaming\Anvsoft 2016-01-08 00:10 - 2015-08-16 18:44 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation 2016-01-08 00:10 - 2015-07-24 16:08 - 00000000 ____D C:\Temp 2016-01-08 00:10 - 2015-07-24 15:11 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation 2016-01-08 00:08 - 2015-07-24 15:10 - 00000000 ____D C:\Program Files\NVIDIA Corporation 2016-01-07 20:12 - 2015-09-10 01:18 - 00000000 ____D C:\Users\Hartley\Desktop\Pens 2016-01-07 11:02 - 2015-07-24 13:38 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2016-01-07 00:15 - 2015-07-24 15:11 - 00000000 ____D C:\ProgramData\NVIDIA Corporation 2016-01-06 23:40 - 2015-07-24 13:45 - 00000000 ____D C:\Users\Hartley\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dell 2016-01-06 23:40 - 2015-07-24 13:45 - 00000000 ____D C:\Users\Hartley\AppData\Local\Deployment 2016-01-06 23:27 - 2015-09-08 03:19 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logitech 2016-01-06 23:27 - 2015-09-08 03:19 - 00000000 ____D C:\Program Files (x86)\Logitech 2016-01-06 23:26 - 2015-07-24 16:06 - 00000000 ____D C:\Users\Hartley\AppData\Local\Downloaded Installations 2016-01-06 22:56 - 2015-12-05 19:40 - 00000000 ____D C:\Users\Hartley\Desktop\Job Application 2016-01-06 20:15 - 2015-09-16 06:00 - 00000000 ____D C:\Users\Hartley\AppData\Local\Spotify 2016-01-06 19:00 - 2015-09-16 05:59 - 00000000 ____D C:\Users\Hartley\AppData\Roaming\Spotify 2016-01-03 13:52 - 2015-07-24 15:15 - 00796864 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2016-01-03 13:52 - 2015-07-24 15:15 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2016-01-03 13:52 - 2015-07-24 15:15 - 00003768 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2015-12-30 18:56 - 2015-09-04 23:53 - 00001619 _____ C:\Users\Hartley\Desktop\DivX Movies.lnk 2015-12-30 18:56 - 2015-09-04 23:53 - 00001093 _____ C:\Users\Public\Desktop\DivX Converter.lnk 2015-12-30 18:56 - 2015-09-04 23:53 - 00001068 _____ C:\Users\Public\Desktop\DivX Player.lnk 2015-12-30 18:56 - 2015-09-04 23:53 - 00000000 ____D C:\Users\Hartley\AppData\Roaming\DivX 2015-12-30 18:56 - 2015-09-04 23:53 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DivX 2015-12-30 18:56 - 2015-09-04 23:51 - 00000000 ____D C:\ProgramData\DivX 2015-12-30 18:56 - 2015-09-04 23:51 - 00000000 ____D C:\Program Files (x86)\DivX 2015-12-29 17:08 - 2015-10-01 06:43 - 00000000 ____D C:\Program Files\iTunes 2015-12-29 17:07 - 2015-10-01 06:42 - 00000000 ____D C:\Program Files\Common Files\Apple 2015-12-28 19:16 - 2015-12-05 01:54 - 00014127 ____H C:\Users\Hartley\Desktop\~WRL0003.tmp 2015-12-25 14:25 - 2009-07-13 22:45 - 00450384 _____ C:\Windows\system32\FNTCACHE.DAT 2015-12-25 12:39 - 2015-07-24 13:37 - 00122096 _____ C:\Users\Hartley\AppData\Local\GDIPFONTCACHEV1.DAT 2015-12-24 21:50 - 2015-07-24 16:27 - 00000000 ____D C:\Users\Hartley 2015-12-23 19:18 - 2015-09-21 14:16 - 00000000 ____D C:\Users\Hartley\AppData\Roaming\Audacity 2015-12-23 18:01 - 2015-11-29 19:03 - 00000000 ____D C:\Users\Hartley\Desktop\PS PRACTICE VIDEOS 2015-12-22 11:27 - 2015-07-24 15:13 - 00000000 __SHD C:\Users\Hartley\IntelGraphicsProfiles 2015-12-22 01:45 - 2015-08-16 18:48 - 00001383 _____ C:\Users\Public\Desktop\GeForce Experience.lnk 2015-12-19 14:05 - 2015-11-01 13:56 - 00000000 ____D C:\Users\Hartley\AppData\LocalLow\uTorrent 2015-12-19 14:05 - 2015-10-18 14:50 - 00000000 ____D C:\Users\Hartley\AppData\Roaming\uTorrent 2015-12-18 19:26 - 2015-07-24 16:04 - 00000000 ____D C:\Windows\I386 2015-12-16 21:32 - 2015-09-24 00:08 - 00000000 ____D C:\Users\Hartley\AppData\Roaming\Sony 2015-12-16 21:31 - 2015-09-04 16:00 - 00000000 ____D C:\Users\Hartley\AppData\Local\CrashDumps 2015-12-16 21:31 - 2013-01-30 07:51 - 00000000 ____D C:\Windows\Panther 2015-12-16 11:34 - 2015-07-24 15:10 - 14005408 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll 2015-12-16 11:34 - 2015-07-24 15:10 - 03637352 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll 2015-12-16 11:34 - 2015-07-24 15:10 - 03211760 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll 2015-12-16 11:34 - 2015-07-24 15:10 - 00469144 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll 2015-12-16 11:34 - 2015-07-24 15:10 - 00388560 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll 2015-12-16 11:34 - 2015-07-24 15:10 - 00175368 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll 2015-12-16 11:34 - 2015-07-24 15:10 - 00153392 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll 2015-12-16 11:34 - 2015-07-24 15:10 - 00034848 _____ C:\Windows\system32\nvinfo.pb 2015-12-16 08:53 - 2015-07-24 15:11 - 06359672 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll 2015-12-16 08:53 - 2015-07-24 15:11 - 02985080 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll 2015-12-16 08:53 - 2015-07-24 15:11 - 02554488 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll 2015-12-16 08:53 - 2015-07-24 15:11 - 01256240 _____ (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe 2015-12-16 08:53 - 2015-07-24 15:11 - 00523384 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshext.dll 2015-12-16 08:53 - 2015-07-24 15:11 - 00385328 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll 2015-12-16 08:53 - 2015-07-24 15:11 - 00075056 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshextr.dll 2015-12-16 08:53 - 2015-07-24 15:11 - 00062768 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll 2015-12-16 08:49 - 2015-07-24 15:11 - 06090019 _____ C:\Windows\system32\nvcoproc.bin 2015-12-16 02:29 - 2015-08-16 18:07 - 00000000 ___SD C:\Windows\SysWOW64\GWX 2015-12-16 02:29 - 2015-08-16 18:07 - 00000000 ___SD C:\Windows\system32\GWX 2015-12-16 01:29 - 2015-09-07 20:49 - 00000000 ____D C:\Users\Hartley\Desktop\Old Backup 2015-12-16 01:28 - 2015-09-14 11:29 - 00000401 _____ C:\Users\Hartley\Desktop\MOVIES I LIKED.txt 2015-12-15 20:18 - 2015-09-04 16:26 - 00002185 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2015-12-14 19:33 - 2015-09-14 12:01 - 00002697 _____ C:\Users\Public\Desktop\Skype.lnk 2015-12-14 19:33 - 2015-09-14 12:01 - 00000000 ____D C:\Users\Hartley\AppData\Local\Skype 2015-12-14 19:33 - 2015-09-14 12:01 - 00000000 ____D C:\ProgramData\Skype 2015-12-11 00:02 - 2009-07-13 21:20 - 00000000 ____D C:\Windows\rescache 2015-12-10 19:06 - 2015-10-23 20:52 - 00000000 ____D C:\Users\Hartley\AppData\Roaming\Wondershare 2015-12-10 19:06 - 2015-10-23 20:52 - 00000000 ____D C:\Users\Hartley\.android 2015-12-10 19:06 - 2015-10-23 20:52 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wondershare 2015-12-10 11:23 - 2015-11-17 18:54 - 00000000 ____D C:\ProgramData\Microsoft Help 2015-12-10 11:05 - 2015-09-17 06:16 - 00000000 ____D C:\ProgramData\Adobe ==================== Files in the root of some directories ======= 2015-07-24 16:33 - 2015-07-24 16:33 - 0000000 _____ () C:\Users\Hartley\AppData\Local\BluetoothPresent.flag 2015-07-24 16:33 - 2015-07-24 16:33 - 0000000 _____ () C:\Users\Hartley\AppData\Local\Driver_Jupiter_01Present.flag 2015-07-24 16:33 - 2015-07-24 16:33 - 0000000 _____ () C:\Users\Hartley\AppData\Local\Driver_LOM_8161Present.flag 2015-11-15 17:16 - 2015-11-15 17:16 - 0000057 _____ () C:\ProgramData\Ament.ini Files to move or delete: ==================== C:\Windows\Tasks\{0B050847-0D0D-7F0E-7E11-0B05080F117E}.job Some files in TEMP: ==================== C:\Users\Hartley\AppData\Local\Temp\DivXSetup.exe C:\Users\Hartley\AppData\Local\Temp\dllnt_dump.dll C:\Users\Hartley\AppData\Local\Temp\nvSCPAPI.dll C:\Users\Hartley\AppData\Local\Temp\nvStInst.exe ==================== Bamital & volsnap ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\dnsapi.dll => File is digitally signed C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed ==================== BCD ================================ Firmware Boot Manager --------------------- identifier {fwbootmgr} displayorder {bootmgr} {dc8643c4-324f-11e5-88d2-806e6f6e6963} {455249cd-8a47-11e5-9207-806e6f6e6963} {dc8643c3-324f-11e5-88d2-806e6f6e6963} {dc8643c0-324f-11e5-88d2-806e6f6e6963} {dc8643c1-324f-11e5-88d2-806e6f6e6963} {dc8643c2-324f-11e5-88d2-806e6f6e6963} timeout 2 Windows Boot Manager -------------------- identifier {bootmgr} device partition=\Device\HarddiskVolume1 path \EFI\Microsoft\Boot\bootmgfw.efi description Windows Boot Manager locale en-US inherit {globalsettings} default {current} resumeobject {92eaca0e-6ae2-11e2-afc3-c510d4749f06} displayorder {current} toolsdisplayorder {memdiag} timeout 30 Firmware Application (101fffff) ------------------------------- identifier {455249cd-8a47-11e5-9207-806e6f6e6963} description CD/DVD/CD-RW Drive Firmware Application (101fffff) ------------------------------- identifier {dc8643c0-324f-11e5-88d2-806e6f6e6963} description EFI USB Device Firmware Application (101fffff) ------------------------------- identifier {dc8643c1-324f-11e5-88d2-806e6f6e6963} description EFI DVD/CDROM Firmware Application (101fffff) ------------------------------- identifier {dc8643c2-324f-11e5-88d2-806e6f6e6963} description EFI Network Firmware Application (101fffff) ------------------------------- identifier {dc8643c3-324f-11e5-88d2-806e6f6e6963} description Network Firmware Application (101fffff) ------------------------------- identifier {dc8643c4-324f-11e5-88d2-806e6f6e6963} description Hard Drive Windows Boot Loader ------------------- identifier {current} device partition=C: path \Windows\system32\winload.efi description Windows 7 locale en-US inherit {bootloadersettings} recoverysequence {ec418053-3250-11e5-b912-70188b2e583e} recoveryenabled Yes osdevice partition=C: systemroot \Windows resumeobject {92eaca0e-6ae2-11e2-afc3-c510d4749f06} nx OptIn Windows Boot Loader ------------------- identifier {ec418053-3250-11e5-b912-70188b2e583e} device ramdisk=[C:]\Recovery\ec418053-3250-11e5-b912-70188b2e583e\Winre.wim,{ec418054-3250-11e5-b912-70188b2e583e} path \windows\system32\winload.efi description Windows Recovery Environment inherit {bootloadersettings} osdevice ramdisk=[C:]\Recovery\ec418053-3250-11e5-b912-70188b2e583e\Winre.wim,{ec418054-3250-11e5-b912-70188b2e583e} systemroot \windows nx OptIn winpe Yes Resume from Hibernate --------------------- identifier {92eaca0e-6ae2-11e2-afc3-c510d4749f06} device partition=C: path \Windows\system32\winresume.efi description Windows Resume Application locale en-US inherit {resumeloadersettings} filedevice partition=C: filepath \hiberfil.sys debugoptionenabled No Windows Memory Tester --------------------- identifier {memdiag} device partition=\Device\HarddiskVolume1 path \EFI\Microsoft\Boot\memtest.efi description Windows Memory Diagnostic locale en-US inherit {globalsettings} badmemoryaccess Yes EMS Settings ------------ identifier {emssettings} bootems Yes Debugger Settings ----------------- identifier {dbgsettings} debugtype Serial debugport 1 baudrate 115200 RAM Defects ----------- identifier {badmemory} Global Settings --------------- identifier {globalsettings} inherit {dbgsettings} {emssettings} {badmemory} Boot Loader Settings -------------------- identifier {bootloadersettings} inherit {globalsettings} {hypervisorsettings} Hypervisor Settings ------------------- identifier {hypervisorsettings} hypervisordebugtype Serial hypervisordebugport 1 hypervisorbaudrate 115200 Resume Loader Settings ---------------------- identifier {resumeloadersettings} inherit {globalsettings} Device options -------------- identifier {ec418054-3250-11e5-b912-70188b2e583e} description Ramdisk Options ramdisksdidevice partition=C: ramdisksdipath \Recovery\ec418053-3250-11e5-b912-70188b2e583e\boot.sdi LastRegBack: 2016-01-09 01:23 ==================== End of FRST.txt ============================