Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:27-02-2016 Ran by [removed] (administrator) on GSOVENDEN-PC (27-02-2016 22:17:40) Running from C:\Users\[removed]\Documents\Computing\Troubleshooting Tools\FRST64 [removed] Platform: Windows 7 Professional Service Pack 1 (X64) Language: English (United States) Internet Explorer Version 9 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (Stardock Corporation) C:\Program Files\Dell\DellDock\DockLogin.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Andrea Electronics Corporation) C:\Windows\System32\AERTSr64.exe (APC) C:\Program Files (x86)\APC\PowerChute Business Edition\agent\pbeagent.exe (APC) C:\Program Files (x86)\APC\PowerChute Business Edition\server\pbeserver.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe (Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe () C:\Program Files (x86)\Dell\PowerNap\PowerNap.Service.exe (Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\VS7DEBUG\MDM.EXE (Symantec Corporation) C:\Program Files (x86)\Engine\6.4.1.14\ccsvchst.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe () C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe (SoftThinks SAS) C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe (EnTech Taiwan) C:\Program Files (x86)\softOSD\softOSD.exe (Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Imfinity Pte Ltd) C:\Program Files (x86)\Dell\PowerNap\PowerNapWatcher.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (SoftThinks - Dell) C:\Program Files (x86)\Dell DataSafe Local Backup\Toaster.exe () C:\Program Files (x86)\Dell DataSafe Local Backup\Components\scheduler\STService.exe (Realtek Semiconductor) C:\Windows\RAVCpl64.exe (Symantec Corporation) C:\Program Files (x86)\Engine\6.4.1.14\ccsvchst.exe (PixArt Imaging Incorporation) C:\Windows\PixArt\PAC7302\Monitor.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Octoshape ApS) C:\Users\G.S. Ovenden\AppData\Roaming\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe (Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD Quick View\WDDMStatus.exe (RealNetworks, Inc.) C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe (Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqste08.exe (Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqbam08.exe (Hewlett-Packard) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe (Symantec Corporation) C:\Program Files (x86)\Norton Utilities 14\RMTray.exe (Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe (CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\OFFICE11\WINWORD.EXE (Microsoft Corporation) C:\Windows\splwow64.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Google Inc.) C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe (Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil64_20_0_0_306_ActiveX.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\OFFICE11\OUTLOOK.EXE (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe ==================== Registry (Whitelisted) =========================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [Skytel] => Skytel.exe HKLM\...\Run: [RtHDVCpl] => C:\Windows\RAVCpl64.exe [6475808 2008-09-02] (Realtek Semiconductor) HKLM\...\Run: [PAC7302_Monitor] => C:\Windows\PixArt\PAC7302\Monitor.exe [319488 2006-11-03] (PixArt Imaging Incorporation) HKLM\...\Run: [IAAnotif] => C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe [186904 2009-06-04] (Intel Corporation) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [WD Quick View] => C:\Program Files (x86)\Western Digital\WD Quick View\WDDMStatus.exe [5537136 2013-08-14] (Western Digital Technologies, Inc.) HKLM-x32\...\Run: [TkBellExe] => C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe [295072 2013-02-18] (RealNetworks, Inc.) HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.) HKLM-x32\...\Run: [hpqSRMon] => C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe [150528 2008-07-22] (Hewlett-Packard) HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [334896 2015-04-30] (Oracle Corporation) HKLM-x32\...\RunOnce: [dslToasterLauncher] => C:\Program Files (x86)\Dell DataSafe Local Backup\ToasterLauncher.exe [450880 2012-01-26] (SoftThinks) HKLM-x32\...\RunOnce: [Launcher] => C:\Program Files (x86)\Dell DataSafe Local Backup\Components\scheduler\Launcher.exe [165184 2012-01-26] (Softthinks) Winlogon\Notify\GoToAssist: C:\Program Files (x86)\Citrix\GoToAssist\514\G2AWinLogon_x64.dll [X] HKU\S-1-5-21-2615649320-1316126405-2989575285-1001\...\Run: [Octoshape Streaming Services] => C:\Users\G.S. Ovenden\AppData\Roaming\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe [70936 2009-01-08] (Octoshape ApS) HKU\S-1-5-21-2615649320-1316126405-2989575285-1001\...\MountPoints2: {47a832e4-d4fc-11e5-ac91-a4badbf97430} - F:\ONSPCLCK.exe HKU\S-1-5-21-2615649320-1316126405-2989575285-1001\...\MountPoints2: {55d7b1ba-9e71-11df-9087-a4badbf97430} - "F:\WD SmartWare.exe" autoplay=true HKU\S-1-5-21-2615649320-1316126405-2989575285-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\Mystify.scr [242688 2010-11-20] (Microsoft Corporation) ShellIconOverlayIdentifiers: [OverlayExcluded] -> {4433A54A-1AC8-432F-90FC-85F045CF383C} => C:\Program Files (x86)\Engine64\6.4.1.14\buShell.dll [2012-07-26] (Symantec Corporation) ShellIconOverlayIdentifiers: [OverlayPending] -> {F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225} => C:\Program Files (x86)\Engine64\6.4.1.14\buShell.dll [2012-07-26] (Symantec Corporation) ShellIconOverlayIdentifiers: [OverlayProtected] -> {476D0EA3-80F9-48B5-B70B-05E677C9C148} => C:\Program Files (x86)\Engine64\6.4.1.14\buShell.dll [2012-07-26] (Symantec Corporation) Startup: C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk [2010-04-19] ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation) Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk [2010-04-19] ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation) Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk [2010-04-19] ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation) Startup: C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk [2010-04-19] ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 Tcpip\..\Interfaces\{028A418B-7D75-4E3A-B894-2610DF43532B}: [DhcpNameServer] 192.168.2.1 Internet Explorer: ================== HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.symantec.com/redirects/security_response/fix_homepage/index.jsp?lg=en&pid=N360&pvid=21.6.0.32 HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.symantec.com/redirects/security_response/fix_homepage/index.jsp?lg=en&pid=N360&pvid=21.6.0.32 HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.symantec.com/redirects/security_response/fix_homepage/index.jsp?lg=en&pid=N360&pvid=21.6.0.32 HKU\S-1-5-21-2615649320-1316126405-2989575285-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.msn.com/USCON/23 HKU\S-1-5-21-2615649320-1316126405-2989575285-1001\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.google.com/ie HKU\S-1-5-21-2615649320-1316126405-2989575285-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://forums.yesterdaystractors.com/viewforum.php?f=10 URLSearchHook: HKLM-x32 - Elf 1 Toolbar - {22e03916-85c5-44b0-8dc9-1830c11238d9} - C:\Program Files (x86)\Elf_1\prxtbElf0.dll (Conduit Ltd.) URLSearchHook: HKU\S-1-5-21-2615649320-1316126405-2989575285-1001 - Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.) URLSearchHook: HKU\S-1-5-21-2615649320-1316126405-2989575285-1001 - Elf 1 Toolbar - {22e03916-85c5-44b0-8dc9-1830c11238d9} - C:\Program Files (x86)\Elf_1\prxtbElf0.dll (Conduit Ltd.) SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?} SearchScopes: HKLM -> {BE2B1A27-352D-4856-AF09-4D23137B5253} URL = hxxp://www.bing.com/search?q={searchTerms}&form=DLCDF8&pc=MDDC&src=IE-SearchBox SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 -> {B3CF572A-A7FA-4422-8BBA-F2D4F0CFE8A7} URL = hxxp://www.bing.com/search?q={searchTerms}&form=DLCDF8&pc=MDDC&src=IE-SearchBox SearchScopes: HKU\S-1-5-21-2615649320-1316126405-2989575285-1001 -> {043C5167-00BB-4324-AF7E-62013FAEDACF} URL = hxxp://vshare.toolbarhome.com/search.aspx?q={searchTerms}&srch={searchReason} SearchScopes: HKU\S-1-5-21-2615649320-1316126405-2989575285-1001 -> {B3CF572A-A7FA-4422-8BBA-F2D4F0CFE8A7} URL = BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_73\bin\ssv.dll [2016-02-13] (Oracle Corporation) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.) BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-03-04] (Google Inc.) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_73\bin\jp2ssv.dll [2016-02-13] (Oracle Corporation) BHO-x32: &Yahoo! Toolbar Helper -> {02478D38-C3F9-4efb-9B51-7695ECA05670} -> C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll [2008-07-28] (Yahoo! Inc.) BHO-x32: HP Print Enhancer -> {0347C33E-8762-4905-BF09-768834316C61} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2010-05-28] (Hewlett-Packard Co.) BHO-x32: vShare Plugin -> {043C5167-00BB-4324-AF7E-62013FAEDACF} -> C:\Program Files (x86)\vShare\vshare_toolbar.dll [2010-10-20] () BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-07-27] (Adobe Systems Incorporated) BHO-x32: Elf 1 Toolbar -> {22e03916-85c5-44b0-8dc9-1830c11238d9} -> C:\Program Files (x86)\Elf_1\prxtbElf0.dll [2011-01-17] (Conduit Ltd.) BHO-x32: RealNetworks Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll [2012-11-29] (RealDownloader) BHO-x32: Norton Identity Protection -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files (x86)\Engine\6.4.1.14\coIEPlg.dll [2013-02-01] (Symantec Corporation) BHO-x32: Norton Vulnerability Protection -> {6D53EC84-6AAE-4787-AEEE-F4628F01010C} -> C:\Program Files (x86)\Engine\6.4.1.14\IPS\IPSBHO.DLL [2012-06-20] (Symantec Corporation) BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.) BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2015-03-04] (Google Inc.) BHO-x32: Freemake.YoutubeButton -> {e9e8eb35-ff77-455d-b677-91e5e4fc06c2} -> C:\Windows\SysWOW64\mscoree.dll [2010-11-04] (Microsoft Corporation) BHO-x32: SingleInstance Class -> {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} -> C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll [2008-07-28] (Yahoo! Inc) BHO-x32: HP Smart BHO Class -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2010-05-28] (Hewlett-Packard Co.) Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-03-04] (Google Inc.) Toolbar: HKLM-x32 - Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll [2008-07-28] (Yahoo! Inc.) Toolbar: HKLM-x32 - Elf 1 Toolbar - {22e03916-85c5-44b0-8dc9-1830c11238d9} - C:\Program Files (x86)\Elf_1\prxtbElf0.dll [2011-01-17] (Conduit Ltd.) Toolbar: HKLM-x32 - vShare Plugin - {043C5167-00BB-4324-AF7E-62013FAEDACF} - C:\Program Files (x86)\vShare\vshare_toolbar.dll [2010-10-20] () Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2015-03-04] (Google Inc.) Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Engine\6.4.1.14\coIEPlg.dll [2013-02-01] (Symantec Corporation) Toolbar: HKU\S-1-5-21-2615649320-1316126405-2989575285-1001 -> No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File Toolbar: HKU\S-1-5-21-2615649320-1316126405-2989575285-1001 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-03-04] (Google Inc.) Toolbar: HKU\S-1-5-21-2615649320-1316126405-2989575285-1001 -> No Name - {043C5167-00BB-4324-AF7E-62013FAEDACF} - No File Toolbar: HKU\S-1-5-21-2615649320-1316126405-2989575285-1001 -> No Name - {22E03916-85C5-44B0-8DC9-1830C11238D9} - No File Toolbar: HKU\S-1-5-21-2615649320-1316126405-2989575285-1001 -> No Name - {30F9B915-B755-4826-820B-08FBA6BD249D} - No File DPF: HKLM-x32 {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} hxxp://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab DPF: HKLM-x32 {17492023-C23A-453E-A040-C7C580BBF700} hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab DPF: HKLM-x32 {49312E18-AA92-4CC2-BB97-55DEA7BCADD6} hxxps://support.dell.com/systemprofiler/SysProExe.CAB DPF: HKLM-x32 {C7DB51B4-BCF7-4923-8874-7F1A0DC92277} hxxp://office.microsoft.com/officeupdate/content/opuc4.cab DPF: HKLM-x32 {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - No File Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - No File Handler-x32: vsharechrome - {3F3A4B8A-86FC-43A4-BB00-6D7EBE9D4484} - C:\Program Files (x86)\vShare\vshare_toolbar.dll [2010-10-20] () FireFox: ======== FF ProfilePath: C:\Users\G.S. Ovenden\AppData\Roaming\Mozilla\Firefox\Profiles\4msy7fke.default-1437940090253 FF Homepage: hxxp://forums.yesterdaystractors.com/viewforum.php?f=10 hxxp://forums.yesterdaystractors.com/viewforum.php?f=10 FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_20_0_0_306.dll [2016-02-09] () FF Plugin: @java.com/DTPlugin,version=11.73.2 -> C:\Program Files\Java\jre1.8.0_73\bin\dtplugin\npDeployJava1.dll [2016-02-13] (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.73.2 -> C:\Program Files\Java\jre1.8.0_73\bin\plugin2\npjp2.dll [2016-02-13] (Oracle Corporation) FF Plugin: @microsoft.com/GENUINE -> disabled [No File] FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_20_0_0_306.dll [2016-02-09] () FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2013-04-08] () FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File] FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2015-02-03] (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2015-02-03] (NVIDIA Corporation) FF Plugin-x32: @real.com/nppl3260;version=16.0.0.282 -> c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll [2013-02-18] (RealNetworks, Inc.) FF Plugin-x32: @real.com/nprndlchromebrowserrecordext;version=1.3.0 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll [2012-11-29] (RealNetworks, Inc.) FF Plugin-x32: @real.com/nprndlhtml5videoshim;version=1.3.0 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll [2012-11-29] (RealNetworks, Inc.) FF Plugin-x32: @real.com/nprndlpepperflashvideoshim;version=1.3.0 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll [2012-11-29] (RealNetworks, Inc.) FF Plugin-x32: @real.com/nprpplugin;version=16.0.0.282 -> c:\program files (x86)\real\realplayer\Netscape6\nprpplugin.dll [2013-02-18] (RealPlayer) FF Plugin-x32: @realnetworks.com/npdlplugin;version=1 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll [2012-11-29] (RealDownloader) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-18] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-18] (Google Inc.) FF Plugin-x32: @veetle.com/vbp;version=0.9.17 -> C:\Program Files (x86)\Veetle\VLCBroadcast\npvbp.dll [2010-03-22] (Veetle Inc) FF Plugin-x32: @veetle.com/veetleCorePlugin,version=0.9.18 -> C:\Program Files (x86)\Veetle\plugins\npVeetle.dll [2010-09-25] (Veetle Inc) FF Plugin-x32: @veetle.com/veetlePlayerPlugin,version=0.9.18 -> C:\Program Files (x86)\Veetle\Player\npvlc.dll [2010-09-21] (Veetle Inc) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2012-07-27] (Adobe Systems Inc.) FF Plugin HKU\S-1-5-21-2615649320-1316126405-2989575285-1001: @octoshape.com/Octoshape Streaming Services,version=1.0 -> C:\Users\G.S. Ovenden\AppData\Roaming\Octoshape\Octoshape Streaming Services\sua-1312180-0-npoctoshape.dll [2013-12-18] (Octoshape ApS) FF Plugin HKU\S-1-5-21-2615649320-1316126405-2989575285-1001: @tools.google.com/Google Update;version=3 -> C:\Users\G.S. Ovenden\AppData\Local\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-01] (Google Inc.) FF Plugin HKU\S-1-5-21-2615649320-1316126405-2989575285-1001: @tools.google.com/Google Update;version=9 -> C:\Users\G.S. Ovenden\AppData\Local\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-01] (Google Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npdjvu.dll [2009-07-31] (LizardTech) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll [2012-07-27] (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppl3260.dll [2013-02-18] (RealNetworks, Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll [2014-10-19] (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll [2014-10-19] (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll [2014-10-19] (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll [2014-10-19] (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll [2014-10-19] (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nprpplugin.dll [2013-02-18] (RealPlayer) FF Plugin ProgramFiles/Appdata: C:\Users\G.S. Ovenden\AppData\Roaming\mozilla\plugins\npoctoshape.dll [2014-08-05] (Octoshape ApS) FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} [2015-06-02] [not signed] FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} [2015-06-02] [not signed] FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0038-ABCDEFFEDCBA} [2015-06-02] [not signed] FF HKLM-x32\...\Firefox\Extensions: [{34712C68-7391-4c47-94F3-8F88D49AD632}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2013-02-18] [not signed] FF HKLM-x32\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext FF HKLM-x32\...\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\Freemake\Freemake Youtube Mp3 Converter\BrowserPlugin\Firefox\[removed] FF Extension: Freemake Video Downloader Plugin - C:\Program Files (x86)\Freemake\Freemake Youtube Mp3 Converter\BrowserPlugin\Firefox\[removed] [2014-02-19] [not signed] FF HKLM-x32\...\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\Freemake\Freemake Youtube Mp3 Converter\BrowserPlugin\Firefox\[removed] FF Extension: Freemake Youtube Download Button - C:\Program Files (x86)\Freemake\Freemake Youtube Mp3 Converter\BrowserPlugin\Firefox\[removed] [2014-02-19] [not signed] FF HKLM-x32\...\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2014-10-13] [not signed] FF HKLM-x32\...\Firefox\Extensions: [{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.3.0.14\coFFPlgn FF Extension: Norton Toolbar - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.3.0.14\coFFPlgn [2016-02-27] [not signed] FF HKLM-x32\...\Firefox\Extensions: [{BBDA0591-3099-440a-AA10-41764D9DB4DB}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.3.0.14\IPSFFPlgn FF Extension: Norton Vulnerability Protection - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.3.0.14\IPSFFPlgn [2015-06-30] [not signed] FF HKU\S-1-5-21-2615649320-1316126405-2989575285-1001\...\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 Chrome: ======= CHR Profile: C:\Users\G.S. Ovenden\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Store) - C:\Users\G.S. Ovenden\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-03-11] CHR Extension: (Google Drive) - C:\Users\G.S. Ovenden\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-03-11] CHR Extension: (YouTube) - C:\Users\G.S. Ovenden\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-03-11] CHR Extension: (Freemake Video Downloader) - C:\Users\G.S. Ovenden\AppData\Local\Google\Chrome\User Data\Default\Extensions\bpegkgagfojjbcpkihigfmkojdmmimdf [2014-04-01] CHR Extension: (Google Search) - C:\Users\G.S. Ovenden\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-04-01] CHR Extension: (Freemake Youtube Download Button) - C:\Users\G.S. Ovenden\AppData\Local\Google\Chrome\User Data\Default\Extensions\ehgldbbpchgpcfagfpfjgoomddhccfgh [2014-04-01] CHR Extension: (RealDownloader) - C:\Users\G.S. Ovenden\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji [2014-04-01] CHR Extension: (Store) - C:\Users\G.S. Ovenden\AppData\Local\Google\Chrome\User Data\Default\Extensions\iikflkcanblccfahdhdonehdalibjnif [2014-08-13] CHR Extension: (Store) - C:\Users\G.S. Ovenden\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk [2015-03-11] CHR Extension: (Google Wallet) - C:\Users\G.S. Ovenden\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-03-11] CHR Extension: (Gmail) - C:\Users\G.S. Ovenden\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-03-11] CHR HKLM-x32\...\Chrome\Extension: [bpegkgagfojjbcpkihigfmkojdmmimdf] - C:\Program Files (x86)\Freemake\Freemake Youtube Mp3 Converter\BrowserPlugin\Chrome\Freemake.Plugin.Chrome.crx [2013-08-12] CHR HKLM-x32\...\Chrome\Extension: [ehgldbbpchgpcfagfpfjgoomddhccfgh] - C:\Program Files (x86)\Freemake\Freemake Youtube Mp3 Converter\BrowserPlugin\Chrome\ChromeYoutubePlugin.crx [2013-08-12] CHR HKLM-x32\...\Chrome\Extension: [idhngdhcfkoamngbedgpaokgjbnpdiji] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx [2012-11-29] CHR HKLM-x32\...\Chrome\Extension: [mkfokfffehpeedafpekjeddnmnjhmcmk] - C:\Program Files (x86)\Engine\6.4.1.14\Exts\Chrome.crx [2015-07-14] ==================== Services (Whitelisted) ======================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 AERTFilters; C:\Windows\system32\AERTSr64.exe [88576 2008-07-15] (Andrea Electronics Corporation) R2 APCPBEAgent; C:\Program Files (x86)\APC\PowerChute Business Edition\agent\pbeagent.exe [34168 2011-01-26] (APC) R2 APCPBEServer; C:\Program Files (x86)\APC\PowerChute Business Edition\server\pbeserver.exe [54728 2011-01-26] (APC) R2 dell_power_nap_service; C:\Program Files (x86)\Dell\PowerNap\PowerNap.Service.exe [11776 2010-03-24] () [File not signed] R2 DockLoginService; C:\Program Files\Dell\DellDock\DockLogin.exe [155648 2009-06-09] (Stardock Corporation) [File not signed] R2 HPSLPSVC; C:\Users\GS47E1~1.OVE\AppData\Local\Temp\7zS4EF7\hpslpsvc64.dll [1039360 2013-07-19] (Hewlett-Packard Co.) [File not signed] S3 Media Jukebox 14 Service; C:\Program Files (x86)\J River\Media Jukebox 14\JRService.exe [379400 2010-07-15] (J. River, Inc.) R2 N360; C:\Program Files (x86)\Engine\6.4.1.14\ccSvcHst.exe [138272 2012-06-15] (Symantec Corporation) R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2010-08-06] (Hewlett-Packard) [File not signed] R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [14997280 2013-08-27] (NVIDIA Corporation) R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2010-08-06] (Hewlett-Packard) [File not signed] R2 RealNetworks Downloader Resolver Service; C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [38608 2012-11-29] () R2 softOSD; C:\Program Files (x86)\softOSD\softOSD.exe [288824 2010-02-24] (EnTech Taiwan) R2 WDDriveService; C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe [270704 2013-11-02] (Western Digital Technologies, Inc.) S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation) S2 SessionLauncher; C:\Users\GS47E1~1.OVE\AppData\Local\Temp\DX9\SessionLauncher.exe [X] ===================== Drivers (Whitelisted) ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R1 BHDrvx64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.3.0.14\Definitions\BASHDefs\20160213.003\BHDrvx64.sys [1665608 2015-10-08] (Symantec Corporation) R1 ccSet_N360; C:\Windows\system32\drivers\N360x64\0604010.00E\ccSetx64.sys [167072 2012-06-06] (Symantec Corporation) S3 DDDriver; C:\Windows\System32\drivers\DDDriver64Dcsa.sys [23760 2015-02-26] (Dell Computer Corporation) S3 DellProf; C:\Windows\System32\drivers\DellProf.sys [23312 2015-02-26] (Dell Computer Corporation) S3 ebdrv; C:\Windows\system32\DRIVERS\evbda.sys [3286016 2009-06-10] (Broadcom Corporation) R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [498512 2015-11-18] (Symantec Corporation) R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [157520 2016-02-07] (Symantec Corporation) R1 IDSVia64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.3.0.14\Definitions\IPSDefs\20160226.001\IDSvia64.sys [767224 2015-12-04] (Symantec Corporation) S3 libusb0; C:\Windows\System32\DRIVERS\libusb0.sys [40552 2011-03-16] (hxxp://libusb-win32.sourceforge.net) R3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.3.0.14\Definitions\VirusDefs\20160227.001\ENG64.SYS [138488 2016-02-22] (Symantec Corporation) R3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_6.3.0.14\Definitions\VirusDefs\20160227.001\EX64.SYS [2148080 2016-02-22] (Symantec Corporation) R2 npf; C:\Windows\System32\drivers\npf.sys [35344 2011-02-11] (CACE Technologies, Inc.) S3 PAC7302; C:\Windows\System32\DRIVERS\PAC7302.SYS [527360 2007-09-10] (PixArt Imaging Inc.) S1 RxFilter; C:\Windows\SysWOW64\DRIVERS\RxFilter.sys [65520 2009-06-26] (Sonic Solutions) R1 se64a; C:\Windows\System32\Drivers\se64a.sys [14032 2007-05-03] (EnTech Taiwan) R1 se64a; C:\Windows\SysWOW64\Drivers\se64a.sys [14032 2007-05-03] (EnTech Taiwan) R3 SRTSP; C:\Windows\System32\Drivers\N360x64\0604010.00E\SRTSP64.SYS [737952 2012-07-05] (Symantec Corporation) R1 SRTSPX; C:\Windows\system32\drivers\N360x64\0604010.00E\SRTSPX64.SYS [37536 2012-07-05] (Symantec Corporation) R0 SymDS; C:\Windows\System32\drivers\N360x64\0604010.00E\SYMDS64.SYS [451192 2012-04-17] (Symantec Corporation) R0 SymEFA; C:\Windows\System32\drivers\N360x64\0604010.00E\SYMEFA64.SYS [1129120 2012-05-21] (Symantec Corporation) R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [175736 2015-06-30] (Symantec Corporation) R1 SymIRON; C:\Windows\system32\drivers\N360x64\0604010.00E\Ironx64.SYS [190072 2012-04-17] (Symantec Corporation) R1 SymNetS; C:\Windows\System32\Drivers\N360x64\0604010.00E\SYMNETS.SYS [405624 2012-04-17] (Symantec Corporation) S3 MREMP50; \??\C:\PROGRA~2\COMMON~1\Motive\MREMP50.SYS [X] S3 MREMP50a64; \??\C:\PROGRA~1\COMMON~1\Motive\MREMP50a64.SYS [X] S3 MREMPR5; \??\C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS [X] S3 MRENDIS5; \??\C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS [X] S3 MRESP50; \??\C:\PROGRA~2\COMMON~1\Motive\MRESP50.SYS [X] S3 MRESP50a64; \??\C:\PROGRA~1\COMMON~1\Motive\MRESP50a64.SYS [X] S4 nvvad_WaveExtensible; system32\drivers\nvvad64v.sys [X] S3 RtsUIR; system32\DRIVERS\Rts516xIR.sys [X] S3 USBCCID; system32\DRIVERS\RtsUCcid.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One Month Created files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2016-02-27 22:15 - 2016-02-27 22:17 - 00000000 ____D C:\FRST 2016-02-21 23:36 - 2016-02-22 12:23 - 00000000 ____D C:\Users\G.S. Ovenden\My Pictures Outdated 2016-02-21 23:17 - 2016-02-21 23:24 - 00000000 ____D C:\Users\Public\Documents\Outlook Backup 2016-02-21 20:48 - 2016-02-21 20:54 - 00000000 ____D C:\Users\G.S. Ovenden\Documents\Automotive Current 2016-02-21 11:12 - 2016-02-24 16:01 - 00003302 _____ C:\Windows\ntbtlog.txt 2016-02-20 22:15 - 2016-02-20 22:31 - 1020699254 _____ C:\Users\G.S. Ovenden\Desktop\CBS.zip 2016-02-20 22:02 - 2016-02-20 22:14 - 00000000 ____D C:\Users\G.S. Ovenden\Desktop\CBS 2016-02-20 19:46 - 2016-02-20 19:46 - 00653824 _____ C:\Users\G.S. Ovenden\Desktop\MicrosoftFixit50446.msi 2016-02-17 15:14 - 2016-02-17 15:18 - 00000000 ____D C:\MGADiagToolOutput 2016-02-17 15:13 - 2016-02-17 15:13 - 00000000 ____D C:\ProgramData\Office Genuine Advantage 2016-02-17 14:56 - 2016-02-17 14:56 - 00003384 _____ C:\Windows\System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-2615649320-1316126405-2989575285-1001 2016-02-17 14:56 - 2016-02-17 14:56 - 00003264 _____ C:\Windows\System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-2615649320-1316126405-2989575285-1001 2016-02-16 17:56 - 2016-02-16 17:56 - 00000000 ____D C:\Users\Public\Downloads\NetZip 2016-02-16 17:23 - 2016-01-11 14:11 - 01684416 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys 2016-02-16 17:20 - 2015-11-19 09:07 - 00994760 _____ (Microsoft Corporation) C:\Windows\system32\ucrtbase.dll 2016-02-16 17:20 - 2015-11-19 09:07 - 00063840 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-private-l1-1-0.dll 2016-02-16 17:20 - 2015-11-19 09:07 - 00020832 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-math-l1-1-0.dll 2016-02-16 17:20 - 2015-11-19 09:07 - 00019808 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-multibyte-l1-1-0.dll 2016-02-16 17:20 - 2015-11-19 09:07 - 00017760 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-string-l1-1-0.dll 2016-02-16 17:20 - 2015-11-19 09:07 - 00017760 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-stdio-l1-1-0.dll 2016-02-16 17:20 - 2015-11-19 09:07 - 00016224 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-runtime-l1-1-0.dll 2016-02-16 17:20 - 2015-11-19 09:07 - 00015712 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-convert-l1-1-0.dll 2016-02-16 17:20 - 2015-11-19 09:07 - 00014176 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-time-l1-1-0.dll 2016-02-16 17:20 - 2015-11-19 09:07 - 00014176 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-2-0.dll 2016-02-16 17:20 - 2015-11-19 09:07 - 00013664 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll 2016-02-16 17:20 - 2015-11-19 09:07 - 00012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-process-l1-1-0.dll 2016-02-16 17:20 - 2015-11-19 09:07 - 00012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-heap-l1-1-0.dll 2016-02-16 17:20 - 2015-11-19 09:07 - 00012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-conio-l1-1-0.dll 2016-02-16 17:20 - 2015-11-19 09:07 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-utility-l1-1-0.dll 2016-02-16 17:20 - 2015-11-19 09:07 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-locale-l1-1-0.dll 2016-02-16 17:20 - 2015-11-19 09:07 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-environment-l1-1-0.dll 2016-02-16 17:20 - 2015-11-19 09:07 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-2-0.dll 2016-02-16 17:20 - 2015-11-19 09:07 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-1.dll 2016-02-16 17:20 - 2015-11-19 09:07 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l2-1-0.dll 2016-02-16 17:20 - 2015-11-19 09:07 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-timezone-l1-1-0.dll 2016-02-16 17:20 - 2015-11-19 09:07 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l2-1-0.dll 2016-02-16 17:20 - 2015-11-19 09:07 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-2-0.dll 2016-02-16 17:20 - 2015-11-19 09:06 - 00922432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ucrtbase.dll 2016-02-16 17:20 - 2015-11-19 09:06 - 00066400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-private-l1-1-0.dll 2016-02-16 17:20 - 2015-11-19 09:06 - 00022368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-math-l1-1-0.dll 2016-02-16 17:20 - 2015-11-19 09:06 - 00019808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-multibyte-l1-1-0.dll 2016-02-16 17:20 - 2015-11-19 09:06 - 00017760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-string-l1-1-0.dll 2016-02-16 17:20 - 2015-11-19 09:06 - 00017760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-stdio-l1-1-0.dll 2016-02-16 17:20 - 2015-11-19 09:06 - 00016224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-runtime-l1-1-0.dll 2016-02-16 17:20 - 2015-11-19 09:06 - 00015712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-convert-l1-1-0.dll 2016-02-16 17:20 - 2015-11-19 09:06 - 00014176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-time-l1-1-0.dll 2016-02-16 17:20 - 2015-11-19 09:06 - 00014176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-2-0.dll 2016-02-16 17:20 - 2015-11-19 09:06 - 00013664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-filesystem-l1-1-0.dll 2016-02-16 17:20 - 2015-11-19 09:06 - 00012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-process-l1-1-0.dll 2016-02-16 17:20 - 2015-11-19 09:06 - 00012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-heap-l1-1-0.dll 2016-02-16 17:20 - 2015-11-19 09:06 - 00012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-conio-l1-1-0.dll 2016-02-16 17:20 - 2015-11-19 09:06 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-utility-l1-1-0.dll 2016-02-16 17:20 - 2015-11-19 09:06 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-locale-l1-1-0.dll 2016-02-16 17:20 - 2015-11-19 09:06 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-environment-l1-1-0.dll 2016-02-16 17:20 - 2015-11-19 09:06 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-2-0.dll 2016-02-16 17:20 - 2015-11-19 09:06 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-1.dll 2016-02-16 17:20 - 2015-11-19 09:06 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l2-1-0.dll 2016-02-16 17:20 - 2015-11-19 09:06 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-timezone-l1-1-0.dll 2016-02-16 17:20 - 2015-11-19 09:06 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l2-1-0.dll 2016-02-16 17:20 - 2015-11-19 09:06 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-2-0.dll 2016-02-15 10:59 - 2016-02-15 10:59 - 00000000 ____D C:\ProgramData\Malwarebytes 2016-02-15 10:58 - 2016-02-15 16:14 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable) 2016-02-15 10:58 - 2016-02-15 10:58 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2016-02-15 10:57 - 2016-02-15 10:57 - 00109272 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys 2016-02-14 22:38 - 2016-02-14 22:38 - 00000000 ____D C:\ProgramData\ParetoLogic 2016-02-14 18:18 - 2016-02-16 17:36 - 00003362 _____ C:\Windows\System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-2615649320-1316126405-2989575285-1001 2016-02-14 10:38 - 2016-02-14 10:39 - 00000000 ____D C:\Users\G.S. Ovenden\Documents\Bell Telephone 2016-02-13 15:43 - 2016-02-13 15:43 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2016-02-13 15:43 - 2016-02-13 15:42 - 00110176 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll 2016-02-13 15:42 - 2016-02-13 15:42 - 00000000 ____D C:\Program Files\Java 2016-02-13 15:08 - 2016-02-13 15:08 - 00003344 _____ C:\Windows\System32\Tasks\{EE8B125D-A057-4764-93B8-C6B998EC6051} 2016-02-10 17:00 - 2016-02-10 17:01 - 00217650 _____ C:\TDSSKiller.3.1.0.9_10.02.2016_17.00.07_log.txt 2016-02-10 16:08 - 2016-02-10 16:12 - 00000000 ____D C:\c769892024d6e5fff9d6f154397badd3 2016-02-10 13:14 - 2016-02-10 13:15 - 00000490 _____ C:\TDSSKiller.3.1.0.9_10.02.2016_13.14.15_log.txt 2016-02-10 13:03 - 2016-02-10 13:13 - 00000490 _____ C:\TDSSKiller.3.1.0.9_10.02.2016_13.03.37_log.txt 2016-02-09 22:04 - 2016-01-22 01:19 - 14179840 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2016-02-09 22:04 - 2016-01-22 01:15 - 01866752 _____ (Microsoft Corporation) C:\Windows\system32\ExplorerFrame.dll 2016-02-09 22:04 - 2016-01-22 01:12 - 01940992 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll 2016-02-09 22:04 - 2016-01-22 01:05 - 12877824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2016-02-09 22:04 - 2016-01-22 01:00 - 01498624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ExplorerFrame.dll 2016-02-09 22:04 - 2016-01-22 00:59 - 01805824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll 2016-02-09 22:04 - 2016-01-22 00:19 - 03231232 _____ (Microsoft Corporation) C:\Windows\explorer.exe 2016-02-09 22:04 - 2016-01-22 00:12 - 02973184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe 2016-02-09 22:00 - 2016-01-16 14:06 - 00025024 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe 2016-02-09 22:00 - 2016-01-16 13:54 - 01162240 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2016-02-09 22:00 - 2016-01-11 09:08 - 01362944 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll 2016-02-09 22:00 - 2016-01-11 09:08 - 00696320 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll 2016-02-09 22:00 - 2016-01-11 09:08 - 00677376 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll 2016-02-09 22:00 - 2016-01-11 09:08 - 00499200 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll 2016-02-09 22:00 - 2016-01-11 09:08 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll 2016-02-09 20:14 - 2016-01-07 12:53 - 03211776 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2016-02-09 19:34 - 2016-01-16 14:01 - 02085888 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll 2016-02-09 19:34 - 2016-01-16 13:36 - 01413632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll 2016-02-09 18:57 - 2015-12-20 13:50 - 03180544 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll 2016-02-09 18:57 - 2015-12-20 13:50 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll 2016-02-09 18:57 - 2015-12-20 09:08 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll 2016-02-09 17:33 - 2016-01-22 01:27 - 05573056 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2016-02-09 17:33 - 2016-01-22 01:27 - 00154560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2016-02-09 17:33 - 2016-01-22 01:27 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2016-02-09 17:33 - 2016-01-22 01:24 - 01733592 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2016-02-09 17:33 - 2016-01-22 01:20 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll 2016-02-09 17:33 - 2016-01-22 01:20 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2016-02-09 17:33 - 2016-01-22 01:20 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2016-02-09 17:33 - 2016-01-22 01:20 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll 2016-02-09 17:33 - 2016-01-22 01:20 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2016-02-09 17:33 - 2016-01-22 01:20 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2016-02-09 17:33 - 2016-01-22 01:20 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2016-02-09 17:33 - 2016-01-22 01:20 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll 2016-02-09 17:33 - 2016-01-22 01:20 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2016-02-09 17:33 - 2016-01-22 01:20 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2016-02-09 17:33 - 2016-01-22 01:19 - 01214464 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2016-02-09 17:33 - 2016-01-22 01:19 - 00344064 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2016-02-09 17:33 - 2016-01-22 01:19 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2016-02-09 17:33 - 2016-01-22 01:18 - 00961024 _____ (Microsoft Corporation) C:\Windows\system32\CPFilters.dll 2016-02-09 17:33 - 2016-01-22 01:18 - 00723968 _____ (Microsoft Corporation) C:\Windows\system32\EncDec.dll 2016-02-09 17:33 - 2016-01-22 01:18 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2016-02-09 17:33 - 2016-01-22 01:17 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2016-02-09 17:33 - 2016-01-22 01:17 - 00312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2016-02-09 17:33 - 2016-01-22 01:17 - 00159744 _____ (Microsoft Corporation) C:\Windows\system32\mtxoci.dll 2016-02-09 17:33 - 2016-01-22 01:16 - 01461248 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2016-02-09 17:33 - 2016-01-22 01:16 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll 2016-02-09 17:33 - 2016-01-22 01:16 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll 2016-02-09 17:33 - 2016-01-22 01:15 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2016-02-09 17:33 - 2016-01-22 01:15 - 00730112 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2016-02-09 17:33 - 2016-01-22 01:15 - 00422400 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2016-02-09 17:33 - 2016-01-22 01:13 - 03993536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2016-02-09 17:33 - 2016-01-22 01:13 - 03938752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2016-02-09 17:33 - 2016-01-22 01:13 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll 2016-02-09 17:33 - 2016-01-22 01:13 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll 2016-02-09 17:33 - 2016-01-22 01:13 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2016-02-09 17:33 - 2016-01-22 01:12 - 00880128 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll 2016-02-09 17:33 - 2016-01-22 01:12 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll 2016-02-09 17:33 - 2016-01-22 01:12 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll 2016-02-09 17:33 - 2016-01-22 01:12 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll 2016-02-09 17:33 - 2016-01-22 01:12 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll 2016-02-09 17:33 - 2016-01-22 01:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2016-02-09 17:33 - 2016-01-22 01:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2016-02-09 17:33 - 2016-01-22 01:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2016-02-09 17:33 - 2016-01-22 01:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll 2016-02-09 17:33 - 2016-01-22 01:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2016-02-09 17:33 - 2016-01-22 01:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll 2016-02-09 17:33 - 2016-01-22 01:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2016-02-09 17:33 - 2016-01-22 01:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2016-02-09 17:33 - 2016-01-22 01:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2016-02-09 17:33 - 2016-01-22 01:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll 2016-02-09 17:33 - 2016-01-22 01:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll 2016-02-09 17:33 - 2016-01-22 01:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2016-02-09 17:33 - 2016-01-22 01:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll 2016-02-09 17:33 - 2016-01-22 01:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2016-02-09 17:33 - 2016-01-22 01:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll 2016-02-09 17:33 - 2016-01-22 01:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll 2016-02-09 17:33 - 2016-01-22 01:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll 2016-02-09 17:33 - 2016-01-22 01:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll 2016-02-09 17:33 - 2016-01-22 01:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2016-02-09 17:33 - 2016-01-22 01:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll 2016-02-09 17:33 - 2016-01-22 01:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2016-02-09 17:33 - 2016-01-22 01:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2016-02-09 17:33 - 2016-01-22 01:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2016-02-09 17:33 - 2016-01-22 01:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll 2016-02-09 17:33 - 2016-01-22 01:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2016-02-09 17:33 - 2016-01-22 01:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll 2016-02-09 17:33 - 2016-01-22 01:09 - 01314328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2016-02-09 17:33 - 2016-01-22 01:06 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2016-02-09 17:33 - 2016-01-22 01:06 - 00665088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll 2016-02-09 17:33 - 2016-01-22 01:06 - 00275456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2016-02-09 17:33 - 2016-01-22 01:06 - 00171520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll 2016-02-09 17:33 - 2016-01-22 01:06 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2016-02-09 17:33 - 2016-01-22 01:06 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll 2016-02-09 17:33 - 2016-01-22 01:06 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll 2016-02-09 17:33 - 2016-01-22 01:06 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2016-02-09 17:33 - 2016-01-22 01:05 - 00251392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2016-02-09 17:33 - 2016-01-22 01:05 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2016-02-09 17:33 - 2016-01-22 01:04 - 00642048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CPFilters.dll 2016-02-09 17:33 - 2016-01-22 01:04 - 00535040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\EncDec.dll 2016-02-09 17:33 - 2016-01-22 01:02 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2016-02-09 17:33 - 2016-01-22 01:02 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll 2016-02-09 17:33 - 2016-01-22 01:02 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2016-02-09 17:33 - 2016-01-22 01:02 - 00176128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msorcl32.dll 2016-02-09 17:33 - 2016-01-22 01:02 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll 2016-02-09 17:33 - 2016-01-22 01:02 - 00114176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mtxoci.dll 2016-02-09 17:33 - 2016-01-22 01:02 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll 2016-02-09 17:33 - 2016-01-22 00:59 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll 2016-02-09 17:33 - 2016-01-22 00:59 - 00642560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll 2016-02-09 17:33 - 2016-01-22 00:59 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll 2016-02-09 17:33 - 2016-01-22 00:59 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll 2016-02-09 17:33 - 2016-01-22 00:59 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll 2016-02-09 17:33 - 2016-01-22 00:59 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll 2016-02-09 17:33 - 2016-01-22 00:59 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll 2016-02-09 17:33 - 2016-01-22 00:59 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll 2016-02-09 17:33 - 2016-01-22 00:59 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll 2016-02-09 17:33 - 2016-01-22 00:59 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll 2016-02-09 17:33 - 2016-01-22 00:59 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll 2016-02-09 17:33 - 2016-01-22 00:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll 2016-02-09 17:33 - 2016-01-22 00:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll 2016-02-09 17:33 - 2016-01-22 00:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll 2016-02-09 17:33 - 2016-01-22 00:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll 2016-02-09 17:33 - 2016-01-22 00:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll 2016-02-09 17:33 - 2016-01-22 00:59 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll 2016-02-09 17:33 - 2016-01-22 00:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll 2016-02-09 17:33 - 2016-01-22 00:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll 2016-02-09 17:33 - 2016-01-22 00:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll 2016-02-09 17:33 - 2016-01-22 00:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll 2016-02-09 17:33 - 2016-01-22 00:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll 2016-02-09 17:33 - 2016-01-22 00:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll 2016-02-09 17:33 - 2016-01-22 00:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll 2016-02-09 17:33 - 2016-01-22 00:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll 2016-02-09 17:33 - 2016-01-22 00:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll 2016-02-09 17:33 - 2016-01-22 00:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll 2016-02-09 17:33 - 2016-01-22 00:59 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll 2016-02-09 17:33 - 2016-01-22 00:13 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe 2016-02-09 17:33 - 2016-01-22 00:07 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe 2016-02-09 17:33 - 2016-01-22 00:07 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe 2016-02-09 17:33 - 2016-01-22 00:05 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe 2016-02-09 17:33 - 2016-01-21 23:59 - 00159232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys 2016-02-09 17:33 - 2016-01-21 23:58 - 00290816 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys 2016-02-09 17:33 - 2016-01-21 23:58 - 00129024 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys 2016-02-09 17:33 - 2016-01-21 23:57 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe 2016-02-09 17:33 - 2016-01-21 23:57 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2016-02-09 17:33 - 2016-01-21 23:53 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2016-02-09 17:33 - 2016-01-21 23:53 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2016-02-09 17:33 - 2016-01-21 23:53 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2016-02-09 17:33 - 2016-01-21 23:53 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2016-02-09 17:33 - 2016-01-21 23:51 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll 2016-02-09 17:33 - 2016-01-21 23:51 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll 2016-02-09 17:33 - 2016-01-21 23:51 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll 2016-02-09 17:33 - 2016-01-21 23:51 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll 2016-02-09 17:33 - 2016-01-21 23:51 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll 2016-02-09 16:19 - 2016-01-07 12:42 - 00141312 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys 2016-02-09 16:19 - 2016-01-06 14:02 - 00275456 _____ (Microsoft Corporation) C:\Windows\system32\InkEd.dll 2016-02-09 16:19 - 2016-01-06 14:02 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\jnwmon.dll 2016-02-09 16:19 - 2016-01-06 13:41 - 00216064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InkEd.dll 2016-02-08 20:29 - 2016-02-21 11:14 - 00000000 ____D C:\NPE 2016-02-07 07:49 - 2015-02-03 19:00 - 00608072 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe 2016-02-07 07:49 - 2015-02-03 11:18 - 04229086 _____ C:\Windows\system32\nvcoproc.bin 2016-02-07 05:47 - 2016-01-11 14:05 - 03169792 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll 2016-02-07 05:47 - 2016-01-11 14:05 - 00192512 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll 2016-02-07 05:47 - 2016-01-11 14:05 - 00098816 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll 2016-02-07 05:47 - 2016-01-11 13:52 - 00091136 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll 2016-02-07 05:47 - 2016-01-11 13:47 - 00174080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll 2016-02-07 05:47 - 2016-01-11 13:26 - 02610176 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2016-02-07 05:47 - 2016-01-11 13:24 - 00709120 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll 2016-02-07 05:47 - 2016-01-11 13:23 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe 2016-02-07 05:47 - 2016-01-11 13:23 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll 2016-02-07 05:47 - 2016-01-11 13:23 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe 2016-02-07 05:47 - 2016-01-11 13:23 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll 2016-02-07 05:47 - 2016-01-11 13:23 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll 2016-02-07 05:47 - 2016-01-11 13:14 - 00573440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll 2016-02-07 05:47 - 2016-01-11 13:14 - 00093696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll 2016-02-07 05:47 - 2016-01-11 13:14 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe 2016-02-07 05:47 - 2016-01-11 13:14 - 00030208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll 2016-02-03 17:43 - 2016-02-03 20:40 - 00003780 _____ C:\Windows\System32\Tasks\GS Ovenden 2016-02-02 22:49 - 2016-02-02 22:49 - 00003360 _____ C:\Windows\System32\Tasks\{311925F0-6761-460D-A405-B78FE05E7511} 2016-02-02 22:49 - 2016-02-02 22:49 - 00000000 ____D C:\Windows\B9DB4C7601A446D58910F7AA6376DBAF.TMP 2016-02-02 20:38 - 2016-02-02 21:21 - 00000000 ____D C:\Windows\pss 2016-02-02 19:25 - 2016-02-27 19:23 - 00003484 _____ C:\Windows\System32\Tasks\PCDEventLauncherTask 2016-02-02 19:25 - 2016-02-02 19:25 - 00004050 _____ C:\Windows\System32\Tasks\PCDoctorBackgroundMonitorTask 2016-02-02 19:25 - 2016-02-02 19:25 - 00003360 _____ C:\Windows\System32\Tasks\PCDDataUploadTask 2016-02-02 19:25 - 2016-02-02 19:25 - 00003240 _____ C:\Windows\System32\Tasks\SystemToolsDailyTest 2016-02-02 19:25 - 2016-02-02 19:25 - 00000000 ____D C:\ProgramData\PC-Doctor for Windows 2016-02-02 19:25 - 2016-02-02 19:25 - 00000000 ____D C:\Program Files\Dell Support Center 2016-02-02 16:41 - 2016-02-02 16:41 - 00003354 _____ C:\Windows\System32\Tasks\{706B4E89-02AF-492E-A271-BD9953D0630A} 2016-02-02 16:19 - 2016-02-02 16:19 - 00003344 _____ C:\Windows\System32\Tasks\{1365222F-FDD4-4454-91AA-7FA686CC023E} 2016-02-02 13:52 - 2016-02-02 13:52 - 00000000 ____D C:\Users\G.S. Ovenden\AppData\Local\{0E6C7222-9EC3-4BA9-95CB-2FDA52201B23} 2016-02-01 23:23 - 2016-02-07 05:07 - 00000000 ____D C:\Users\G.S. Ovenden\.oracle_jre_usage 2016-02-01 23:23 - 2016-02-01 23:23 - 00000000 ____D C:\Users\G.S. Ovenden\AppData\Roaming\Sun 2016-01-31 20:21 - 2016-02-07 17:31 - 00000000 ___RD C:\Users\G.S. Ovenden\Documents\Notes 2016-01-30 12:33 - 2016-01-30 12:39 - 00000000 ____D C:\Users\G.S. Ovenden\AppData\Roaming\Norton Utilities 14 ==================== One Month Modified files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2016-02-27 22:07 - 2014-04-01 11:30 - 00000884 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2615649320-1316126405-2989575285-1001Core.job 2016-02-27 22:01 - 2014-04-01 11:30 - 00000936 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2615649320-1316126405-2989575285-1001UA.job 2016-02-27 21:58 - 2009-07-13 23:45 - 00025424 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2016-02-27 21:58 - 2009-07-13 23:45 - 00025424 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2016-02-27 21:47 - 2015-04-07 20:15 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2016-02-27 21:31 - 2010-05-17 07:06 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2016-02-27 19:16 - 2015-08-10 11:29 - 00000000 ____D C:\Windows\System32\Tasks\Remediation 2016-02-27 19:13 - 2010-05-10 08:22 - 00000000 ____D C:\Users\G.S. Ovenden\AppData\Local\SoftThinks 2016-02-27 19:13 - 2010-04-19 12:21 - 00000000 ____D C:\Users\Default\AppData\Local\SoftThinks 2016-02-27 19:13 - 2010-04-19 12:21 - 00000000 ____D C:\Users\Default User\AppData\Local\SoftThinks 2016-02-27 19:12 - 2010-05-17 07:06 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2016-02-27 19:11 - 2010-04-19 11:54 - 00000000 ____D C:\ProgramData\NVIDIA 2016-02-27 19:11 - 2009-07-14 00:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2016-02-23 11:27 - 2004-02-15 13:46 - 00000000 ____D C:\Users\G.S. Ovenden\Documents\New Job Search 2016-02-22 20:20 - 2010-05-10 08:27 - 00000000 ____D C:\Users\G.S. Ovenden\AppData\Local\VirtualStore 2016-02-22 20:04 - 2005-07-15 06:12 - 00000000 ____D C:\Users\G.S. Ovenden\Documents\Computing 2016-02-22 11:06 - 2009-07-14 00:13 - 00786662 _____ C:\Windows\system32\PerfStringBackup.INI 2016-02-22 11:06 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\inf 2016-02-21 23:36 - 2010-05-10 08:22 - 00000000 ____D C:\Users\G.S. Ovenden 2016-02-21 21:32 - 2012-10-30 12:55 - 00000000 ____D C:\Users\G.S. Ovenden\Documents\Verbatim 2016-02-21 21:25 - 2004-02-15 13:46 - 00000000 ____D C:\Users\G.S. Ovenden\Documents\Transfer 2016-02-21 21:12 - 2007-04-16 08:40 - 00000000 ____D C:\Users\G.S. Ovenden\Documents\Combo 2016-02-21 21:11 - 2005-05-05 08:44 - 00000000 ____D C:\Users\G.S. Ovenden\Documents\Club of Rome 2016-02-21 21:09 - 2004-02-15 13:47 - 00000000 ____D C:\Users\G.S. Ovenden\Documents\Business Planning 2016-02-21 20:54 - 2004-04-23 10:36 - 00000000 ____D C:\Users\G.S. Ovenden\Documents\Automotive 2016-02-21 19:59 - 2012-07-15 20:21 - 00000000 ____D C:\Users\G.S. Ovenden\Documents\Tools 2016-02-21 19:48 - 2014-11-30 16:36 - 00000000 ____D C:\Users\G.S. Ovenden\Documents\Real Estate I 2016-02-21 18:41 - 2010-11-04 06:38 - 00000000 ____D C:\Users\G.S. Ovenden\Documents\Quotes 2016-02-21 18:37 - 2006-05-29 06:51 - 00000000 ____D C:\Users\G.S. Ovenden\Documents\Elaine's Piano 2016-02-21 18:36 - 2006-08-25 06:45 - 00000000 ____D C:\Users\G.S. Ovenden\Documents\Parents 2016-02-21 18:29 - 2005-03-21 10:02 - 00000000 ____D C:\Users\G.S. Ovenden\Documents\Newspaper Articles 2016-02-21 18:21 - 2005-04-04 23:16 - 00000000 ____D C:\Users\G.S. Ovenden\Documents\My Received Files 2016-02-21 18:20 - 2004-12-04 13:28 - 00000000 ____D C:\Users\G.S. Ovenden\Documents\My eBooks 2016-02-21 18:16 - 2007-11-13 12:44 - 00000000 ____D C:\Users\G.S. Ovenden\Documents\Money Storage 2016-02-21 18:07 - 2004-02-15 13:46 - 00000000 ____D C:\Users\G.S. Ovenden\Documents\McMaster I 2016-02-21 18:06 - 2008-08-12 20:33 - 00000000 ____D C:\Users\G.S. Ovenden\Documents\McMaster 2016-02-21 18:01 - 2004-05-10 07:06 - 00000000 ____D C:\Users\G.S. Ovenden\Documents\Judith 2016-02-21 17:52 - 2004-05-10 15:30 - 00000000 ____D C:\Users\G.S. Ovenden\Documents\Hunting 2016-02-21 17:49 - 2004-02-15 13:47 - 00000000 ____D C:\Users\G.S. Ovenden\Documents\Government 2016-02-21 17:42 - 2004-04-11 16:26 - 00000000 ____D C:\Users\G.S. Ovenden\Documents\Deck 2016-02-21 17:11 - 2010-07-21 16:50 - 00000000 ____D C:\Users\G.S. Ovenden\AppData\Local\CrashDumps 2016-02-21 17:10 - 2006-07-04 21:19 - 00000000 ____D C:\temp 2016-02-21 16:00 - 2011-03-02 16:30 - 00000000 ____D C:\Users\G.S. Ovenden\AppData\Roaming\PCDr 2016-02-21 12:26 - 2016-01-27 13:51 - 00000000 ____D C:\Users\G.S. Ovenden\AppData\Local\NPE 2016-02-21 00:25 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\rescache 2016-02-20 17:02 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\PolicyDefinitions 2016-02-17 21:17 - 2012-04-25 19:31 - 00000000 ____D C:\Users\G.S. Ovenden\Documents\Computer 2016-02-17 21:17 - 2004-04-25 19:09 - 00000000 ____D C:\Users\G.S. Ovenden\Documents\Construction 2016-02-17 15:12 - 2011-03-28 15:51 - 00000000 ____D C:\ProgramData\TEMP 2016-02-17 11:04 - 2016-01-11 13:03 - 00000000 ____D C:\Program Files\Mozilla Firefox 2016-02-16 17:36 - 2014-09-30 14:44 - 00003242 _____ C:\Windows\System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-2615649320-1316126405-2989575285-1001 2016-02-16 10:12 - 2012-05-13 15:52 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight 2016-02-15 16:44 - 2013-07-14 14:07 - 00000000 ____D C:\Windows\system32\MRT 2016-02-15 16:39 - 2010-05-10 16:50 - 146614896 ____N (Microsoft Corporation) C:\Windows\system32\MRT.exe 2016-02-15 11:45 - 2009-07-14 02:46 - 00000000 ____D C:\Windows\ShellNew 2016-02-15 11:12 - 2016-01-17 14:16 - 00001111 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2016-02-14 23:28 - 2010-08-03 08:22 - 00000000 ____D C:\Users\G.S. Ovenden\AppData\Local\Deployment 2016-02-14 10:55 - 2012-01-17 11:41 - 00000000 ____D C:\Users\G.S. Ovenden\Documents\Insurance 2016-02-14 10:54 - 2004-02-15 13:46 - 00000000 ____D C:\Users\G.S. Ovenden\Documents\SGL 2016-02-14 10:50 - 2004-12-07 09:09 - 00000000 ____D C:\Users\G.S. Ovenden\Documents\Resume 2016-02-14 10:49 - 2004-02-15 13:46 - 00000000 ____D C:\Users\G.S. Ovenden\Documents\Job Search 2016-02-14 10:42 - 2007-08-08 13:43 - 00000000 ____D C:\Users\G.S. Ovenden\Documents\Real Estate 2016-02-14 10:42 - 2004-02-15 13:46 - 00000000 ____D C:\Users\G.S. Ovenden\Documents\Lists 2016-02-14 10:02 - 2004-02-15 13:46 - 00000000 ____D C:\Users\G.S. Ovenden\Documents\PVV 2016-02-13 20:44 - 2004-12-05 21:31 - 00000000 ____D C:\Users\G.S. Ovenden\Documents\EMC 2016-02-13 20:41 - 2004-12-04 16:08 - 00000000 ____D C:\Users\G.S. Ovenden\Documents\Backup 2016-02-13 20:41 - 2004-04-06 10:08 - 00000000 ____D C:\Users\G.S. Ovenden\Documents\Companies 2016-02-13 20:38 - 2007-03-11 18:59 - 00000000 ____D C:\Users\G.S. Ovenden\Documents\Calendar 2016-02-13 20:36 - 2004-11-26 17:20 - 00000000 ____D C:\Users\G.S. Ovenden\Documents\All Other Files 2016-02-13 18:59 - 2009-07-13 22:20 - 00000000 ____D C:\Windows\registration 2016-02-13 17:44 - 2010-05-11 06:48 - 00000000 ____D C:\Program Files (x86)\Java 2016-02-13 17:15 - 2013-10-20 14:43 - 00000000 ____D C:\ProgramData\Oracle 2016-02-13 14:33 - 2012-04-25 20:48 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation 2016-02-10 16:45 - 2015-06-30 09:12 - 00000000 ____D C:\Program Files (x86)\MUI 2016-02-10 16:45 - 2015-06-30 09:12 - 00000000 ____D C:\Program Files (x86)\Branding 2016-02-10 14:37 - 2013-08-25 13:59 - 00000000 ____D C:\Users\UpdatusUser 2016-02-10 14:37 - 2010-05-10 12:29 - 00000000 ____D C:\Users\Administrator 2016-02-10 14:31 - 2013-07-24 08:47 - 00000000 ____D C:\Program Files (x86)\Freemake 2016-02-10 00:35 - 2009-07-14 00:08 - 00032582 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2016-02-09 23:28 - 2015-07-12 16:34 - 10424320 _____ C:\Users\Administrator\s-1-5-21-2615649320-1316126405-2989575285-500.rrr 2016-02-09 23:28 - 2015-07-12 16:34 - 00245760 _____ C:\Users\UpdatusUser\s-1-5-21-2615649320-1316126405-2989575285-1004.rrr 2016-02-09 22:00 - 2015-04-15 08:12 - 00000000 ____D C:\Windows\system32\appraiser 2016-02-09 22:00 - 2014-04-27 16:32 - 00000000 ___SD C:\Windows\system32\CompatTel 2016-02-09 20:48 - 2015-04-07 20:15 - 00003768 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2016-02-09 20:48 - 2012-04-07 19:51 - 00796864 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2016-02-09 20:48 - 2011-05-22 18:19 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2016-02-09 20:16 - 2009-07-13 23:45 - 00471504 _____ C:\Windows\system32\FNTCACHE.DAT 2016-02-09 16:41 - 2009-07-14 02:47 - 00000000 ____D C:\Program Files\Windows Journal 2016-02-08 21:20 - 2013-05-28 18:00 - 00000000 ____D C:\Program Files\Common Files\Western Digital 2016-02-08 21:20 - 2013-05-28 17:58 - 00000000 ____D C:\ProgramData\Package Cache 2016-02-08 20:30 - 2015-04-12 13:42 - 00008192 _____ C:\Windows\SysWOW64\WDPABKP.dat 2016-02-08 17:39 - 2010-05-17 06:33 - 00000000 ____D C:\Users\G.S. Ovenden\AppData\Local\ElevatedDiagnostics 2016-02-08 16:31 - 2009-07-13 22:20 - 00000000 ____D C:\PerfLogs 2016-02-07 17:31 - 2010-05-11 10:34 - 00000000 ___RD C:\Users\G.S. Ovenden\Documents\Scanned Documents 2016-02-07 17:31 - 2009-07-13 22:20 - 00000000 __RHD C:\Users\Public\Libraries 2016-02-07 17:31 - 2007-11-21 10:24 - 00000000 ____D C:\Users\G.S. Ovenden\Documents\Sympatico 2016-02-07 17:31 - 2007-01-01 09:45 - 00000000 ____D C:\Users\G.S. Ovenden\Documents\Radios 2016-02-07 17:31 - 2004-05-31 14:36 - 00000000 ___SD C:\Users\G.S. Ovenden\Documents\My Data Sources 2016-02-07 17:31 - 2004-02-15 13:46 - 00000000 ____D C:\Users\G.S. Ovenden\Documents\Was in Windows 2016-02-07 17:31 - 2004-02-15 13:46 - 00000000 ____D C:\Users\G.S. Ovenden\Documents\Toyota Tours 1_files 2016-02-07 17:30 - 2010-05-10 16:23 - 00000000 ____D C:\ProgramData\Norton 2016-02-07 17:28 - 2014-10-20 20:15 - 00000000 ____D C:\Users\G.S. Ovenden\Documents\Banking 2016-02-07 17:28 - 2008-09-22 13:51 - 00000000 ____D C:\Users\G.S. Ovenden\Documents\Lorna 2016-02-07 17:28 - 2004-08-10 20:18 - 00000000 ____D C:\Users\G.S. Ovenden\Documents\Tractor 2016-02-07 17:28 - 2004-02-15 13:46 - 00000000 ____D C:\Users\G.S. Ovenden\Documents\Taxes 2016-02-07 17:28 - 2004-02-15 13:45 - 00000000 ____D C:\Users\G.S. Ovenden\Documents\Transfer to New 2016-02-07 17:25 - 2011-06-09 19:39 - 00000000 ____D C:\Program Files\Western Digital 2016-02-07 17:25 - 2010-06-02 11:52 - 00000000 ____D C:\ProgramData\Real 2016-02-07 17:25 - 2010-05-10 13:06 - 00000000 ____D C:\Users\G.S. Ovenden\Documents\Fax 2016-02-07 17:25 - 2004-09-03 07:58 - 00000000 ____D C:\Users\G.S. Ovenden\Documents\Equinox 2016-02-07 17:25 - 2004-02-15 13:47 - 00000000 ____D C:\Users\G.S. Ovenden\Documents\Faith 2016-02-07 08:06 - 2013-09-22 14:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation 2016-02-07 08:06 - 2012-04-25 20:47 - 00000000 ____D C:\ProgramData\NVIDIA Corporation 2016-02-07 07:48 - 2012-04-25 20:46 - 00000000 ____D C:\Program Files\NVIDIA Corporation 2016-02-06 18:20 - 2014-10-13 15:17 - 00000000 ____D C:\Users\G.S. Ovenden\AppData\Roaming\HpUpdate 2016-02-03 16:46 - 2015-03-18 10:36 - 00000000 ____D C:\ProgramData\SupportAssistAgent 2016-02-02 19:25 - 2010-04-19 12:11 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell 2016-02-02 19:25 - 2010-04-19 12:03 - 00000000 ____D C:\ProgramData\PCDr 2016-02-02 14:55 - 2016-01-25 14:31 - 00000000 ___SD C:\Windows\system32\GWX 2016-02-01 21:55 - 2014-04-01 11:30 - 00003920 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2615649320-1316126405-2989575285-1001UA 2016-02-01 21:55 - 2014-04-01 11:30 - 00003524 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2615649320-1316126405-2989575285-1001Core 2016-01-31 17:30 - 2010-05-10 10:28 - 00000000 ___DC C:\Users\G.S. Ovenden\AppData\Local\MigWiz 2016-01-31 11:19 - 2011-03-28 15:51 - 00000000 ____D C:\Program Files (x86)\Norton Utilities 14 2016-01-30 23:45 - 2010-08-04 18:21 - 00000000 ____D C:\Windows\system32\appmgmt 2016-01-30 12:33 - 2009-07-14 00:32 - 00000000 ____D C:\Windows\Downloaded Program Files 2016-01-28 06:00 - 2010-04-19 12:02 - 00000000 ____D C:\Program Files (x86)\Dell DataSafe Local Backup ==================== Files in the root of some directories ======= 2009-02-13 10:02 - 2009-02-13 10:02 - 0080896 _____ (Microsoft Corporation) C:\Program Files\devcon_amd64.exe 2015-06-30 09:12 - 2012-08-10 00:44 - 0000172 _____ () C:\Program Files (x86)\isolate.ini 2014-10-13 17:19 - 2014-10-13 17:19 - 0000697 _____ () C:\Users\G.S. Ovenden\AppData\Roaming\ConvAPIPlugin.log 2010-05-11 10:09 - 2010-05-11 10:09 - 0000235 _____ () C:\Users\G.S. Ovenden\AppData\Roaming\devices.xml 2010-05-11 10:09 - 2010-05-11 10:09 - 0000012 _____ () C:\Users\G.S. Ovenden\AppData\Roaming\settings.xml 2011-05-23 06:44 - 2013-04-08 15:34 - 0000984 _____ () C:\Users\G.S. Ovenden\AppData\Roaming\wklnhst.dat 2013-09-22 21:17 - 2014-02-19 19:40 - 0004608 _____ () C:\Users\G.S. Ovenden\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2011-10-20 09:11 - 2011-12-13 16:47 - 0007609 _____ () C:\Users\G.S. Ovenden\AppData\Local\Resmon.ResmonCfg 2010-05-10 20:51 - 2014-10-13 17:26 - 0005381 _____ () C:\ProgramData\hpzinstall.log Files to move or delete: ==================== C:\Users\Firefox\Firefox Setup 3.6.3.exe C:\Users\G.S. Ovenden\hpothb07.dat ==================== Bamital & volsnap ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\dnsapi.dll => File is digitally signed C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2016-02-18 00:38 ==================== End of FRST.txt ============================