Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 29-08-2016 Ran by [removed] (administrator) on USER (30-08-2016 10:36:17) Running from C:\Users\[removed]\Desktop [removed] Platform: Windows 8.1 (Update) (X64) Language: English (United States) Internet Explorer Version 11 (Default browser: Chrome) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Intel Corporation) C:\Windows\System32\igfxCUIService.exe (IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome Remote Desktop\52.0.2743.48\remoting_host.exe () C:\ProgramData\DatacardService\HWDeviceService64.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome Remote Desktop\52.0.2743.48\remoting_host.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Phone Tools\CoreCon\11.0\Bin\IpOverUsbSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe () C:\Program Files (x86)\Wi-Fi\WiFiGxSvc.exe () C:\ProgramData\Photon\Huawei\EC306-1\OnlineUpdate\ouc.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (DEVGURU Co., LTD.) C:\Program Files\SAMSUNG\USB Drivers\25_escape\conn\ss_conn_service.exe (Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe (Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe (Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Huawei Technologies Co., Ltd.) C:\ProgramData\DatacardService\DCSHelper.exe (Intel Corporation) C:\Windows\System32\igfxEM.exe (Intel Corporation) C:\Windows\System32\igfxHK.exe (Intel Corporation) C:\Windows\System32\igfxTray.exe (Microsoft Corporation) C:\Windows\System32\SkyDrive.exe (IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe (Microsoft Corporation) C:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe (Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD Utilities\WDDriveUtilitiesHelper.exe (Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD Security\WDDriveAutoUnlock.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD Quick View\WDDMStatus.exe (Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe () C:\ProgramData\cu\cu.exe (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe () C:\Program Files (x86)\Photon\Huawei\EC306-1\Photon.exe (Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe (HP Inc.) C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe (Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Tx-Network) C:\Program Files (x86)\Wi-Fi\Wi-Fi.exe (Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20911_x64__8wekyb3d8bbwe\livecomm.exe (Farbar) C:\Users\user1\Desktop\FRST64 (1).exe ==================== Registry (Whitelisted) =========================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [1664000 2012-08-19] (IDT, Inc.) HKLM\...\Run: [XboxStat] => C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe [825184 2009-10-01] (Microsoft Corporation) HKLM\...\Run: [InstallerLauncher] => "C:\Program Files\Common Files\Bitdefender\SetupInformation\{6F57816A-791A-4159-A75F-CFD0C7EA4FBF}\setuplauncher.exe" /run:"C:\Program Files\Common Files\Bitdefender\SetupInformation\{6F57816A-791A-41 (the data entry has 36 more characters). HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [170256 2015-10-16] (Apple Inc.) HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [31016 2006-10-27] (Microsoft Corporation) HKLM-x32\...\Run: [DriveUtilitiesHelper] => C:\Program Files (x86)\Western Digital\WD Utilities\WDDriveUtilitiesHelper.exe [1852264 2014-05-23] (Western Digital Technologies, Inc.) HKLM-x32\...\Run: [WD Drive Unlocker] => C:\Program Files (x86)\Western Digital\WD Security\WDDriveAutoUnlock.exe [1694048 2014-05-23] (Western Digital Technologies, Inc.) HKLM-x32\...\Run: [WD Quick View] => C:\Program Files (x86)\Western Digital\WD Quick View\WDDMStatus.exe [5564784 2015-02-12] (Western Digital Technologies, Inc.) HKLM\...\Policies\Explorer: [TaskbarNoNotification] 0 HKLM\...\Policies\Explorer: [HideSCAHealth] 0 HKU\S-1-5-21-3268202683-2675470380-2750706328-1001\...\Run: [Google Update] => C:\Users\user1\AppData\Local\Google\Update\GoogleUpdate.exe [144200 2015-08-29] (Google Inc.) HKU\S-1-5-21-3268202683-2675470380-2750706328-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\Steam.exe [1610664 2015-04-20] (Valve Corporation) HKU\S-1-5-21-3268202683-2675470380-2750706328-1001\...\MountPoints2: {5726bac4-e755-11e4-8256-84349778df91} - "E:\WD Drive Unlock.exe" autoplay=true HKU\S-1-5-21-3268202683-2675470380-2750706328-1001\...\MountPoints2: {d08be517-e4be-11e4-8253-84349778df91} - "E:\Setup.exe" Startup: C:\Users\user1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\user1.lnk [2016-05-30] ShortcutTarget: user1.lnk -> C:\ProgramData\cu\cu.exe () CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) Tcpip\..\Interfaces\{1AEFE4FE-8F7A-47B6-9C42-FAEF59CBA108}: [DhcpNameServer] [removed] [removed] Tcpip\..\Interfaces\{2BE42B2D-6C4E-4B88-926E-9596C0293593}: [DhcpNameServer] [removed] [removed] Tcpip\..\Interfaces\{8EFF101F-C7FD-4ED9-8394-DB6860B7A3C4}: [DhcpNameServer] 192.168.43.1 Tcpip\..\Interfaces\{DA5EC3D0-C187-4570-A864-071A2AE4A2EF}: [DhcpNameServer] [removed] [removed] Internet Explorer: ================== HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = HKU\S-1-5-21-3268202683-2675470380-2750706328-1001\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.google.com/ie HKU\S-1-5-21-3268202683-2675470380-2750706328-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://yourtv.link SearchScopes: HKU\S-1-5-21-3268202683-2675470380-2750706328-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.google.com/cse?cx=partner-pub-8036109189802438%3A7790813904&ie=UTF-8&q={searchTerms}&sa=Search&siteurl=yourtv.link%2F SearchScopes: HKU\S-1-5-21-3268202683-2675470380-2750706328-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.google.com/cse?cx=partner-pub-8036109189802438%3A7790813904&ie=UTF-8&q={searchTerms}&sa=Search&siteurl=yourtv.link%2F BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [2016-07-21] (HP Inc.) BHO-x32: Microsoft Web Test Recorder 12.0 Helper -> {432dd630-7e03-4c97-9d62-b99f52df4fc2} -> C:\Program Files (x86)\Microsoft Visual Studio 12.0\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll [2013-10-05] (Microsoft Corporation) BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2006-10-27] (Microsoft Corporation) BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2016-07-21] (HP Inc.) FireFox: ======== FF ProfilePath: C:\Users\user1\AppData\Roaming\Mozilla\Firefox\Profiles\ej07sng5.default FF Homepage: hxxps://www.malwarebytes.org/restorebrowser/ FF SelectedSearchEngine: Google FF Homepage: hxxp://yourtv.link FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_23_0_0_151.dll [2016-08-24] () FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_23_0_0_151.dll [2016-08-24] () FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2015-10-08] () FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll [2015-10-13] (Google, Inc.) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.66 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-09-28] (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-09-28] (Intel Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll [2013-05-13] ( Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-08-01] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-08-01] (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2016-06-23] (Adobe Systems Inc.) FF Plugin HKU\S-1-5-21-3268202683-2675470380-2750706328-1001: @tools.google.com/Google Update;version=3 -> C:\Users\user1\AppData\Local\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-08-01] (Google Inc.) FF Plugin HKU\S-1-5-21-3268202683-2675470380-2750706328-1001: @tools.google.com/Google Update;version=9 -> C:\Users\user1\AppData\Local\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-08-01] (Google Inc.) FF Plugin HKU\S-1-5-21-3268202683-2675470380-2750706328-1001: hp.com/HPDetect -> C:\Users\user1\AppData\Roaming\HewlettPackard\HPDetect\1.0.0.0\npHPDetect.dll [2012-08-30] (HP) FF SearchPlugin: C:\Users\user1\AppData\Roaming\Mozilla\Firefox\Profiles\ej07sng5.default\searchplugins\Google .xml [2016-08-30] FF Extension: (PrriiceeMINus) - C:\Users\user1\AppData\Roaming\Mozilla\Firefox\Profiles\ej07sng5.default\Extensions\[removed] [2015-05-08] [not signed] FF Extension: (bestadblocker) - C:\Users\user1\AppData\Roaming\Mozilla\Firefox\Profiles\ej07sng5.default\Extensions\[removed] [2015-05-08] [not signed] Chrome: ======= CHR HomePage: Default -> hxxps://www.google.co.in/ CHR StartupUrls: Default -> "hxxp://google.com/","hxxp://in.msn.com/?pc=UP97&ocid=UP97DHP","chrome://newtab/?source=home" CHR DefaultSearchKeyword: Default -> google.co.in CHR Profile: C:\Users\user1\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (YouTube) - C:\Users\user1\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-10-19] CHR Extension: (Google Search) - C:\Users\user1\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-11-02] CHR Extension: (Mp3Skull Toolbar) - C:\Users\user1\AppData\Local\Google\Chrome\User Data\Default\Extensions\eninoobbhmobfofnpeahogndfglcheen [2016-07-14] CHR Extension: (Google Docs Offline) - C:\Users\user1\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-05-03] CHR Extension: (AdBlock) - C:\Users\user1\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2016-08-30] CHR Extension: (Ghostery) - C:\Users\user1\AppData\Local\Google\Chrome\User Data\Default\Extensions\mlomiejdfkolichcflejclcbmpeaniij [2016-08-29] CHR Extension: (Gmail) - C:\Users\user1\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-04-16] CHR Extension: (Chrome Media Router) - C:\Users\user1\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-08-30] ==================== Services (Whitelisted) ======================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77104 2015-10-07] (Apple Inc.) S3 c2wts; C:\Program Files\Windows Identity Foundation\v3.5\c2wtshost.exe [5632 2015-04-17] (Microsoft Corporation) R2 chromoting; C:\Program Files (x86)\Google\Chrome Remote Desktop\52.0.2743.48\remoting_host.exe [76616 2016-06-20] (Google Inc.) S3 fussvc; C:\Program Files (x86)\Windows Kits\8.1\App Certification Kit\fussvc.exe [142336 2014-02-20] (Microsoft Corporation) [File not signed] R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [29760 2016-07-04] (HP Inc.) R2 HWDeviceService64.exe; C:\ProgramData\DatacardService\HWDeviceService64.exe [351824 2014-01-15] () R2 IconMan_R; C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [2451456 2012-07-13] (Realsil Microelectronics Inc.) [File not signed] R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [319376 2014-10-02] (Intel Corporation) R2 Intel(R) Capability Licensing Service Interface; c:\Program Files\Intel\iCLS Client\HeciServer.exe [732160 2012-12-10] (Intel(R) Corporation) [File not signed] S3 Intel(R) Capability Licensing Service TCP IP Interface; c:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [803872 2012-12-10] (Intel(R) Corporation) R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [131032 2013-01-14] (Intel Corporation) R2 IpOverUsbSvc; C:\Program Files (x86)\Common Files\Microsoft Shared\Phone Tools\CoreCon\11.0\Bin\IpOverUsbSvc.exe [22768 2014-04-17] (Microsoft Corporation) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165336 2013-01-14] (Intel Corporation) R2 MDM; C:\Program Files (x86)\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe [335872 2006-10-27] (Microsoft Corporation) [File not signed] R2 MyWiFiRouterDHCP; C:\Program Files (x86)\Wi-Fi\WiFiGxSvc.exe [47464 2014-11-18] () S2 Photon. RunOuc; C:\Program Files (x86)\Photon\Huawei\EC306-1\UpdateDog\ouc.exe [651856 2013-10-26] () R2 ss_conn_service; C:\Program Files\SAMSUNG\USB Drivers\25_escape\conn\ss_conn_service.exe [743688 2014-12-03] (DEVGURU Co., LTD.) S3 Te.Service; C:\Program Files (x86)\Windows Kits\8.1\Testing\Runtimes\TAEF\Wex.Services.exe [119808 2013-08-22] (Microsoft Corporation) [File not signed] S3 vmicvss; C:\Windows\System32\ICSvc.dll [524800 2014-11-21] (Microsoft Corporation) S3 VsEtwService120; C:\Program Files\Microsoft Visual Studio 12.0\Common7\Packages\Debugger\Services\VsEtwService.exe [89232 2014-07-22] (Microsoft Corporation) R2 WDBackup; C:\Program Files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe [1042808 2015-02-12] (Western Digital Technologies, Inc.) R2 WDDriveService; C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe [302968 2015-02-12] (Western Digital Technologies, Inc.) R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366552 2015-07-07] (Microsoft Corporation) R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2015-07-07] (Microsoft Corporation) ===================== Drivers (Whitelisted) ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R3 athr; C:\Windows\system32\DRIVERS\athwbx.sys [3858944 2013-10-17] (Qualcomm Atheros Communications, Inc.) S0 ebdrv; C:\Windows\System32\drivers\evbda.sys [3357024 2013-08-22] (Broadcom Corporation) U5 GEARAspiWDM; C:\Windows\System32\Drivers\GEARAspiWDM.sys [33240 2012-10-03] (GEAR Software Inc.) R1 ndiskhaz; C:\Windows\system32\DRIVERS\ndiskhaz.sys [30536 2012-12-07] (Khalil Azzouzi) S3 RSP2STOR; C:\Windows\system32\DRIVERS\RtsP2Stor.sys [269968 2012-07-03] (Realtek Semiconductor Corp.) R3 SensorsSimulatorDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [226304 2014-11-21] (Microsoft Corporation) R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [33008 2013-05-07] (Synaptics Incorporated) R1 txwifinat; C:\Windows\system32\DRIVERS\txwifinat64.sys [35248 2014-12-01] (Nanjing Tongxiang Network Technology Co.,LTD) U5 UnlockerDriver5; C:\Program Files\Unlocker\UnlockerDriver5.sys [12352 2010-07-01] () S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44560 2015-07-07] (Microsoft Corporation) R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [270168 2015-07-07] (Microsoft Corporation) R2 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114520 2015-07-07] (Microsoft Corporation) R3 WirelessButtonDriver; C:\Windows\System32\drivers\WirelessButtonDriver64.sys [30384 2015-06-23] (HP Inc.) ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One Month Created files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2016-08-30 10:36 - 2016-08-30 10:36 - 00019761 _____ C:\Users\user1\Desktop\FRST.txt 2016-08-30 10:36 - 2016-08-30 10:36 - 00000000 ____D C:\FRST 2016-08-30 10:34 - 2016-08-30 10:35 - 02397696 _____ (Farbar) C:\Users\user1\Desktop\FRST64 (1).exe 2016-08-30 10:20 - 2016-08-30 10:20 - 00001508 _____ C:\Users\user1\Desktop\JRT.txt 2016-08-30 10:16 - 2016-08-30 10:24 - 00001988 _____ C:\Users\user1\Desktop\Rkill.txt 2016-08-30 09:48 - 2016-08-30 10:25 - 00000000 ____D C:\AdwCleaner 2016-08-30 09:43 - 2016-08-30 09:44 - 00232794 _____ C:\TDSSKiller.3.1.0.11_30.08.2016_09.43.06_log.txt 2016-08-30 09:18 - 2016-08-30 09:56 - 00000258 __RSH C:\Users\user1\ntuser.pol 2016-08-29 11:50 - 2016-08-29 11:50 - 00000000 ____D C:\Users\user1\AppData\LocalLow\uTorrent 2016-08-28 14:31 - 2016-08-28 14:31 - 00301557 _____ C:\Users\user1\Desktop\COMEDK Medical Form 2016.pdf 2016-08-27 21:08 - 2016-08-29 15:16 - 00000342 _____ C:\Windows\Tasks\HPCeeScheduleForuser1.job 2016-08-27 21:08 - 2016-08-27 21:08 - 00003156 _____ C:\Windows\System32\Tasks\HPCeeScheduleForuser1 2016-08-27 16:07 - 2016-08-27 16:07 - 00008334 _____ C:\Users\user1\Desktop\Payment.pdf 2016-08-26 22:44 - 2016-08-26 22:45 - 07497281 _____ C:\Users\user1\Desktop\DMEUG_2016_LIST_Latest1.pdf 2016-08-26 17:07 - 2016-08-27 10:23 - 00000000 ____D C:\Users\user1\Downloads\The Man Who Knew Infinity (2015) [YTS.AG] 2016-08-26 16:45 - 2016-08-26 16:45 - 00000000 ____D C:\Users\user1\Downloads\Now You See Me 2 (2016) [YTS.AG] 2016-08-26 11:29 - 2016-08-26 13:10 - 00000000 ____D C:\Users\user1\Downloads\Neighbors 2 Sorority Rising (2016) [YTS.AG] 2016-08-26 10:00 - 2016-08-26 11:29 - 00000000 ____D C:\Users\user1\Downloads\Me Before You (2016) [YTS.AG] 2016-08-26 09:14 - 2016-08-26 09:14 - 00129634 _____ C:\Users\user1\Desktop\GHSReceiptViewer.aspx TANISHQ.html 2016-08-26 09:14 - 2016-08-26 09:14 - 00000000 ____D C:\Users\user1\Desktop\GHSReceiptViewer.aspx TANISHQ_files 2016-08-25 21:20 - 2016-08-25 21:20 - 00170146 _____ C:\Users\user1\Desktop\GGSIPU Application Form.pdf 2016-08-25 13:22 - 2016-08-25 13:22 - 00012453 _____ C:\Users\user1\Downloads\Dark City (1998) [720p] [YTS.AG].torrent 2016-08-25 13:21 - 2016-08-25 13:21 - 00028623 _____ C:\Users\user1\Downloads\Starter for 10 (2006) [720p] [YTS.AG].torrent 2016-08-25 13:19 - 2016-08-26 10:21 - 00000000 ____D C:\Users\user1\Downloads\The Jungle Book (2016) [YTS.AG] 2016-08-25 13:19 - 2016-08-25 13:19 - 00038687 _____ C:\Users\user1\Downloads\Now You See Me 2 (2016) [720p] [YTS.AG].torrent 2016-08-25 13:19 - 2016-08-25 13:19 - 00032961 _____ C:\Users\user1\Downloads\Me Before You (2016) [720p] [YTS.AG].torrent 2016-08-25 13:19 - 2016-08-25 13:19 - 00032445 _____ C:\Users\user1\Downloads\The Man Who Knew Infinity (2015) [720p] [YTS.AG].torrent 2016-08-25 13:19 - 2016-08-25 13:19 - 00027669 _____ C:\Users\user1\Downloads\Neighbors 2- Sorority Rising (2016) [720p] [YTS.AG].torrent 2016-08-25 13:18 - 2016-08-25 13:18 - 00032265 _____ C:\Users\user1\Downloads\The Jungle Book (2016) [720p] [YTS.AG].torrent 2016-08-25 11:13 - 2016-08-25 11:13 - 00137013 _____ C:\Users\user1\Desktop\tanu adhar card.pdf 2016-08-23 17:17 - 2016-08-23 17:17 - 00131202 _____ C:\Users\user1\Desktop\ApplicationForm MANIPAL REGISTRATION.pdf 2016-08-22 22:26 - 2016-08-22 22:26 - 00228004 _____ C:\Users\user1\Desktop\Brochure_NEET_2016.pdf 2016-08-22 22:11 - 2016-08-22 22:11 - 00093382 _____ C:\Users\user1\Desktop\Samanya_Niwas_praman.pdf 2016-08-22 22:10 - 2016-08-22 22:10 - 00071919 _____ C:\Users\user1\Desktop\UP_Niwas_Praman.pdf 2016-08-22 22:08 - 2016-08-22 22:08 - 00059374 _____ C:\Users\user1\Desktop\UPOBC format.pdf 2016-08-22 22:05 - 2016-08-22 23:47 - 00000000 ____D C:\Users\user1\Desktop\__Online Registration for UP NEET 2016 Counselling___files 2016-08-22 22:05 - 2016-08-22 22:05 - 00024689 _____ C:\Users\user1\Desktop\__Online Registration for UP NEET 2016 Counselling__.html 2016-08-22 20:49 - 2016-08-22 20:49 - 00087822 _____ C:\Users\user1\Desktop\State Bank of India.pdf 2016-08-21 20:58 - 2016-08-21 20:58 - 00039347 _____ C:\Users\user1\Documents\2016-07-29-19-56-02-103_1469802362103_XXXPS5070X_Acknowledgement.pdf 2016-08-21 20:53 - 2016-08-21 20:53 - 00029737 _____ C:\Users\user1\Desktop\2016-07-29-19-56-02-103_1469802362103_XXXPS5070X_Acknowledgement.zip 2016-08-21 13:47 - 2016-08-21 13:47 - 00008718 _____ C:\Users\user1\Downloads\Online Application Form for MBBS-BDS nims.html 2016-08-21 13:47 - 2016-08-21 13:47 - 00000000 ____D C:\Users\user1\Downloads\Online Application Form for MBBS-BDS nims_files 2016-08-21 13:27 - 2016-08-21 13:27 - 00131202 _____ C:\Users\user1\Downloads\ApplicationForm NANIPAL.pdf 2016-08-20 11:13 - 2016-08-20 11:13 - 00000299 _____ C:\Users\user1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recycle Bin.lnk 2016-08-20 06:51 - 2016-07-02 09:59 - 00828408 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2016-08-20 06:51 - 2016-07-02 09:59 - 00176632 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2016-08-19 08:01 - 2014-04-16 05:05 - 00028352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aspnet_counters.dll 2016-08-19 08:01 - 2014-04-16 05:04 - 00029888 _____ (Microsoft Corporation) C:\Windows\system32\aspnet_counters.dll 2016-08-18 09:18 - 2016-08-18 09:18 - 00227925 _____ C:\Users\user1\Desktop\CBSE - NEET TEST 2016 Results.pdf 2016-08-17 15:38 - 2016-06-19 01:36 - 00590688 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fvevol.sys 2016-08-17 15:38 - 2016-06-19 01:36 - 00072408 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dumpfve.sys 2016-08-17 15:38 - 2016-06-12 01:22 - 00379232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys 2016-08-17 15:38 - 2016-06-12 01:22 - 00057184 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\stornvme.sys 2016-08-17 15:38 - 2016-06-11 23:35 - 00216576 _____ (Microsoft Corporation) C:\Windows\system32\gpresult.exe 2016-08-17 15:38 - 2016-06-11 22:20 - 00987136 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2016-08-17 15:38 - 2016-06-11 22:16 - 00482304 _____ (Microsoft Corporation) C:\Windows\system32\tpmvsc.dll 2016-08-17 15:38 - 2016-06-11 22:14 - 00509440 _____ (Microsoft Corporation) C:\Windows\system32\webio.dll 2016-08-17 15:38 - 2016-06-11 22:07 - 00796672 _____ (Microsoft Corporation) C:\Windows\system32\winhttp.dll 2016-08-17 15:38 - 2016-06-11 21:54 - 00800768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2016-08-17 15:38 - 2016-06-11 21:50 - 00413184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webio.dll 2016-08-17 15:38 - 2016-06-11 21:46 - 00626176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winhttp.dll 2016-08-17 15:38 - 2016-06-11 09:14 - 00107984 _____ (Microsoft Corporation) C:\Windows\system32\ncryptsslp.dll 2016-08-17 15:38 - 2016-06-11 09:14 - 00091416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncryptsslp.dll 2016-08-17 15:38 - 2016-06-11 01:37 - 03820544 _____ (Microsoft Corporation) C:\Windows\system32\rdpcore.dll 2016-08-17 15:38 - 2016-06-11 01:33 - 00432128 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2016-08-17 15:38 - 2016-06-11 00:34 - 03547136 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll 2016-08-17 15:38 - 2016-06-10 23:41 - 06521800 _____ (Microsoft Corporation) C:\Windows\system32\sppsvc.exe 2016-08-17 15:38 - 2016-06-10 23:41 - 01487992 _____ (Microsoft Corporation) C:\Windows\system32\sppobjs.dll 2016-08-17 15:38 - 2016-06-10 23:41 - 00261376 _____ (Microsoft Corporation) C:\Windows\system32\sppwinob.dll 2016-08-17 15:38 - 2016-06-10 23:41 - 00125024 _____ (Microsoft Corporation) C:\Windows\system32\cryptxml.dll 2016-08-17 15:38 - 2016-06-10 23:40 - 00099136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptxml.dll 2016-08-17 15:38 - 2016-06-10 23:37 - 03273728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpcore.dll 2016-08-17 15:38 - 2016-06-10 23:34 - 00357376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2016-08-17 15:38 - 2016-06-10 01:02 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll 2016-08-17 15:38 - 2016-06-09 23:48 - 00199168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebClnt.dll 2016-08-17 15:38 - 2016-06-04 06:08 - 01613528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2016-08-17 15:38 - 2016-06-04 06:07 - 01970968 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2016-08-17 15:38 - 2016-05-29 12:38 - 22361344 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2016-08-17 15:38 - 2016-05-29 00:01 - 19788688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2016-08-17 15:38 - 2016-05-19 02:26 - 01291776 _____ (Microsoft Corporation) C:\Windows\system32\certutil.exe 2016-08-17 15:38 - 2016-05-19 01:58 - 02635264 _____ (Microsoft Corporation) C:\Windows\system32\CertEnroll.dll 2016-08-17 15:38 - 2016-05-19 01:46 - 02317824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CertEnroll.dll 2016-08-17 15:38 - 2016-05-15 01:56 - 00136904 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe 2016-08-17 15:38 - 2016-05-14 10:49 - 01134768 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2016-08-17 15:38 - 2016-05-14 04:38 - 00111616 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys 2016-08-17 15:38 - 2016-05-14 04:38 - 00032768 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\hidusb.sys 2016-08-17 15:38 - 2016-05-14 03:54 - 00862720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2016-08-17 15:38 - 2016-05-14 03:12 - 03667968 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2016-08-17 15:38 - 2016-05-14 02:57 - 00409088 _____ (Microsoft Corporation) C:\Windows\system32\WUSettingsProvider.dll 2016-08-17 15:38 - 2016-05-14 02:56 - 02230784 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll 2016-08-17 15:38 - 2016-05-14 02:56 - 00897024 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll 2016-08-17 15:38 - 2016-05-14 02:46 - 00727040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll 2016-08-17 15:38 - 2016-05-13 00:06 - 00034600 _____ (Microsoft Corporation) C:\Windows\system32\UserAccountBroker.exe 2016-08-17 15:38 - 2016-05-12 23:09 - 00030984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UserAccountBroker.exe 2016-08-17 15:38 - 2016-05-07 03:29 - 00331608 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Classpnp.sys 2016-08-17 15:38 - 2016-05-06 22:43 - 00138240 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dfsc.sys 2016-08-17 15:38 - 2016-05-05 23:58 - 01661072 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll 2016-08-17 15:38 - 2016-05-05 23:09 - 01212256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll 2016-08-17 15:38 - 2016-05-05 22:48 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\msiexec.exe 2016-08-17 15:38 - 2016-05-05 22:32 - 03320832 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll 2016-08-17 15:38 - 2016-05-05 22:07 - 00059904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msiexec.exe 2016-08-17 15:38 - 2016-05-05 21:59 - 03607040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll 2016-08-17 15:38 - 2016-04-16 19:26 - 01080320 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL 2016-08-17 15:38 - 2016-04-10 11:05 - 00551256 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\vhdmp.sys 2016-08-17 15:38 - 2016-04-10 03:45 - 00026112 _____ (Microsoft Corporation) C:\Windows\system32\wfapigp.dll 2016-08-17 15:38 - 2016-04-10 03:44 - 00306176 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.Geolocation.dll 2016-08-17 15:38 - 2016-04-10 03:40 - 00816128 _____ (Microsoft Corporation) C:\Windows\system32\rpcss.dll 2016-08-17 15:38 - 2016-04-10 03:39 - 00754176 _____ (Microsoft Corporation) C:\Windows\system32\FirewallAPI.dll 2016-08-17 15:38 - 2016-04-10 03:32 - 00346112 _____ (Microsoft Corporation) C:\Windows\system32\LocationApi.dll 2016-08-17 15:38 - 2016-04-10 03:29 - 00218112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Geolocation.dll 2016-08-17 15:38 - 2016-04-10 03:26 - 00543232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FirewallAPI.dll 2016-08-17 15:38 - 2016-04-10 03:25 - 00881152 _____ (Microsoft Corporation) C:\Windows\system32\MPSSVC.dll 2016-08-17 15:38 - 2016-04-10 03:22 - 00281088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\LocationApi.dll 2016-08-17 15:38 - 2016-04-07 21:36 - 00927744 _____ (Microsoft Corporation) C:\Windows\system32\iphlpsvc.dll 2016-08-17 15:38 - 2016-04-07 02:51 - 00114528 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mup.sys 2016-08-17 15:38 - 2016-04-06 23:50 - 00402432 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdbss.sys 2016-08-17 15:38 - 2016-04-06 23:47 - 18825216 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.dll 2016-08-17 15:38 - 2016-04-06 21:55 - 15158272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.dll 2016-08-17 15:38 - 2016-04-06 04:07 - 00205824 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndiswan.sys 2016-08-17 15:38 - 2016-04-02 19:28 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\BdeHdCfgLib.dll 2016-08-17 15:37 - 2016-06-11 22:44 - 00192512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gpresult.exe 2016-08-17 15:37 - 2016-06-07 23:40 - 00083456 _____ (Microsoft Corporation) C:\Windows\system32\hbaapi.dll 2016-08-17 15:37 - 2016-06-07 22:43 - 00066560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\hbaapi.dll 2016-08-17 15:37 - 2016-05-19 03:24 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\certenc.dll 2016-08-17 15:37 - 2016-05-19 02:45 - 00044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certenc.dll 2016-08-17 15:37 - 2016-05-19 02:03 - 01060352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certutil.exe 2016-08-17 15:37 - 2016-05-14 04:38 - 00032512 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys 2016-08-17 15:37 - 2016-05-14 03:00 - 00035840 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe 2016-08-17 15:37 - 2016-05-14 02:59 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll 2016-08-17 15:37 - 2016-05-14 02:57 - 00095744 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll 2016-08-17 15:37 - 2016-05-14 02:48 - 00124928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll 2016-08-17 15:37 - 2016-05-14 02:48 - 00029696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe 2016-08-17 15:37 - 2016-05-14 02:46 - 00081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll 2016-08-17 15:37 - 2016-05-05 22:04 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\olepro32.dll 2016-08-17 15:37 - 2016-05-05 20:58 - 02778624 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll 2016-08-17 15:37 - 2016-05-05 20:46 - 02464768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll 2016-08-17 15:37 - 2016-04-10 03:29 - 00020480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wfapigp.dll 2016-08-17 15:37 - 2016-04-01 23:10 - 00322048 _____ (Microsoft Corporation) C:\Windows\system32\fvecpl.dll 2016-08-17 15:37 - 2016-04-01 22:23 - 00348672 _____ (Microsoft Corporation) C:\Windows\system32\bdesvc.dll 2016-08-17 15:37 - 2016-04-01 22:20 - 00737280 _____ (Microsoft Corporation) C:\Windows\system32\fveapi.dll 2016-08-17 15:37 - 2016-02-04 22:27 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\httpprxp.dll 2016-08-17 15:37 - 2016-02-04 22:19 - 00125440 _____ (Microsoft Corporation) C:\Windows\system32\httpprxm.dll 2016-08-17 15:37 - 2016-02-04 22:09 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\adhsvc.dll 2016-08-17 14:22 - 2016-08-02 11:24 - 20343808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2016-08-17 14:22 - 2016-08-02 11:21 - 00497664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2016-08-17 14:22 - 2016-08-02 11:08 - 00724992 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2016-08-17 14:22 - 2016-08-02 10:45 - 00692736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2016-08-17 14:22 - 2016-08-02 10:45 - 00330752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2016-08-17 14:22 - 2016-08-02 10:23 - 01316352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2016-08-17 14:22 - 2016-06-11 22:52 - 00145408 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2016-08-17 14:22 - 2016-06-11 22:14 - 00128000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2016-08-17 14:22 - 2016-02-09 01:59 - 00099328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\hlink.dll 2016-08-17 14:21 - 2016-08-02 12:24 - 25808384 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2016-08-17 14:21 - 2016-08-02 12:02 - 02894336 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2016-08-17 14:21 - 2016-08-02 12:01 - 00572416 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2016-08-17 14:21 - 2016-08-02 11:50 - 00615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2016-08-17 14:21 - 2016-08-02 11:48 - 06047744 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2016-08-17 14:21 - 2016-08-02 11:48 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2016-08-17 14:21 - 2016-08-02 11:25 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2016-08-17 14:21 - 2016-08-02 11:17 - 02286592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2016-08-17 14:21 - 2016-08-02 11:16 - 01032704 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll 2016-08-17 14:21 - 2016-08-02 11:11 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2016-08-17 14:21 - 2016-08-02 11:10 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2016-08-17 14:21 - 2016-08-02 11:09 - 00378880 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2016-08-17 14:21 - 2016-08-02 11:08 - 00806400 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2016-08-17 14:21 - 2016-08-02 11:06 - 02131456 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2016-08-17 14:21 - 2016-08-02 10:58 - 15412224 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2016-08-17 14:21 - 2016-08-02 10:53 - 02868224 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2016-08-17 14:21 - 2016-08-02 10:51 - 04608000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2016-08-17 14:21 - 2016-08-02 10:50 - 00880128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll 2016-08-17 14:21 - 2016-08-02 10:44 - 02055680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2016-08-17 14:21 - 2016-08-02 10:41 - 13808128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2016-08-17 14:21 - 2016-08-02 10:40 - 01550848 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2016-08-17 14:21 - 2016-08-02 10:29 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2016-08-17 14:21 - 2016-08-02 10:26 - 02393088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2016-08-17 14:21 - 2016-08-02 10:21 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2016-08-17 14:21 - 2016-06-11 22:51 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2016-08-17 14:21 - 2016-06-11 22:50 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2016-08-17 14:21 - 2016-06-11 22:13 - 00279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2016-08-17 14:21 - 2016-06-11 22:03 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2016-08-17 14:21 - 2016-02-08 23:44 - 00108544 _____ (Microsoft Corporation) C:\Windows\system32\hlink.dll 2016-08-17 14:21 - 2015-11-10 05:34 - 00476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2016-08-17 14:18 - 2016-05-18 11:01 - 00372568 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll 2016-08-17 14:18 - 2016-05-18 11:01 - 00315224 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll 2016-08-17 14:18 - 2016-05-14 04:34 - 00044032 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll 2016-08-17 14:18 - 2016-05-14 03:49 - 00035840 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll 2016-08-17 13:58 - 2016-06-26 01:35 - 00050368 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe 2016-08-17 13:58 - 2016-06-22 19:18 - 00268800 _____ (Microsoft Corporation) C:\Windows\system32\centel.dll 2016-08-17 13:58 - 2016-06-21 19:18 - 01490432 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll 2016-08-17 13:58 - 2016-06-21 19:18 - 01208320 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2016-08-17 13:58 - 2016-06-21 19:18 - 00571904 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll 2016-08-17 13:58 - 2016-06-21 19:18 - 00544256 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll 2016-08-17 13:58 - 2016-06-21 19:18 - 00294912 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll 2016-08-17 13:58 - 2016-06-21 19:18 - 00219136 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll 2016-08-17 13:58 - 2016-06-21 19:18 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll 2016-08-17 13:52 - 2016-07-08 19:48 - 04169216 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2016-08-17 13:52 - 2016-06-25 23:43 - 00165376 _____ (Microsoft Corporation) C:\Windows\system32\inetpp.dll 2016-08-17 13:52 - 2016-06-25 21:54 - 00345600 _____ (Microsoft Corporation) C:\Windows\system32\ntprint.dll 2016-08-17 13:52 - 2016-06-25 21:45 - 01094656 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll 2016-08-17 13:52 - 2016-06-25 21:43 - 00864256 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll 2016-08-17 13:52 - 2016-06-25 21:35 - 00306176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntprint.dll 2016-08-17 13:52 - 2016-05-13 00:08 - 00135336 _____ (Microsoft Corporation) C:\Windows\system32\gpapi.dll 2016-08-17 13:52 - 2016-05-12 23:13 - 00115704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gpapi.dll 2016-08-17 13:52 - 2016-05-12 21:47 - 00331776 _____ (Microsoft Corporation) C:\Windows\system32\polstore.dll 2016-08-17 13:52 - 2016-05-12 21:38 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\FwRemoteSvr.dll 2016-08-17 13:52 - 2016-05-12 21:37 - 01360896 _____ (Microsoft Corporation) C:\Windows\system32\gpsvc.dll 2016-08-17 13:52 - 2016-05-12 21:29 - 00398848 _____ (Microsoft Corporation) C:\Windows\system32\IPSECSVC.DLL 2016-08-17 13:52 - 2016-05-12 21:13 - 00291328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\polstore.dll 2016-08-17 13:52 - 2016-05-12 21:07 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FwRemoteSvr.dll 2016-08-17 13:52 - 2016-01-31 01:20 - 00477184 _____ (Microsoft Corporation) C:\Windows\system32\puiobj.dll 2016-08-17 13:52 - 2016-01-31 00:30 - 00192512 _____ (Microsoft Corporation) C:\Windows\system32\puiapi.dll 2016-08-17 13:52 - 2016-01-31 00:18 - 00269312 _____ (Microsoft Corporation) C:\Windows\system32\DafPrintProvider.dll 2016-08-17 13:52 - 2016-01-30 23:48 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\puiobj.dll 2016-08-17 13:52 - 2016-01-30 23:18 - 00167424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\puiapi.dll 2016-08-17 13:52 - 2016-01-30 23:11 - 00203776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DafPrintProvider.dll 2016-08-17 13:47 - 2016-07-06 19:56 - 07793152 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Data.Pdf.dll 2016-08-17 13:47 - 2016-07-06 19:56 - 07075328 _____ (Microsoft Corporation) C:\Windows\system32\glcndFilter.dll 2016-08-17 13:47 - 2016-07-06 19:53 - 05270016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\glcndFilter.dll 2016-08-17 13:47 - 2016-07-06 19:51 - 05265920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Data.Pdf.dll 2016-08-17 13:45 - 2016-07-09 05:39 - 00442712 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2016-08-17 13:45 - 2016-07-09 05:38 - 00332632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll 2016-08-17 13:45 - 2016-07-08 20:02 - 01753600 _____ (Microsoft Corporation) C:\Windows\system32\GdiPlus.dll 2016-08-17 13:45 - 2016-07-08 19:55 - 01491456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\GdiPlus.dll 2016-08-17 13:45 - 2016-07-08 19:52 - 01445376 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2016-08-17 13:45 - 2016-07-08 19:49 - 00840704 _____ (Microsoft Corporation) C:\Windows\system32\netlogon.dll 2016-08-17 13:45 - 2016-07-08 19:47 - 00696832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netlogon.dll 2016-08-17 13:45 - 2016-07-08 04:03 - 00201728 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys 2016-08-17 13:45 - 2016-07-08 03:23 - 00445440 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll 2016-08-17 13:45 - 2016-07-08 01:36 - 00324096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll 2016-08-17 13:45 - 2016-06-22 00:02 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe 2016-08-17 13:45 - 2016-06-21 19:42 - 00129536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\poqexec.exe 2016-08-17 13:45 - 2016-06-12 01:15 - 07445856 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2016-08-17 13:45 - 2016-05-19 04:48 - 00563024 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys 2016-08-17 13:45 - 2016-05-19 04:48 - 00397232 _____ (Microsoft Corporation) C:\Windows\system32\bcryptprimitives.dll 2016-08-17 13:45 - 2016-05-19 04:46 - 00178016 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2016-08-17 13:45 - 2016-05-19 03:58 - 00340880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcryptprimitives.dll 2016-08-17 13:42 - 2016-05-06 21:15 - 00748544 _____ (Microsoft Corporation) C:\Windows\system32\StructuredQuery.dll 2016-08-17 13:42 - 2016-05-06 20:53 - 00503808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\StructuredQuery.dll 2016-08-17 13:40 - 2016-03-10 23:13 - 00161280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msorcl32.dll 2016-08-17 13:40 - 2016-03-10 22:25 - 00166400 _____ (Microsoft Corporation) C:\Windows\system32\mtxoci.dll 2016-08-17 13:40 - 2016-03-10 22:12 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mtxoci.dll 2016-08-11 15:30 - 2016-08-11 21:33 - 00000000 ____D C:\Users\user1\Desktop\100 Greatest Bollywood Soundtracks Ever - Planet Bollywood Features_files 2016-08-11 15:30 - 2016-08-11 15:30 - 00046853 _____ C:\Users\user1\Desktop\100 Greatest Bollywood Soundtracks Ever - Planet Bollywood Features.html 2016-08-11 15:29 - 2016-08-11 21:33 - 00000000 ____D C:\Users\user1\Desktop\100 Greatest Bollywood Soundtracks Ever - Part 3 - Planet Bollywood Features_files 2016-08-11 15:29 - 2016-08-11 21:33 - 00000000 ____D C:\Users\user1\Desktop\100 Greatest Bollywood Soundtracks Ever - Part 2 - Planet Bollywood Features_files 2016-08-11 15:29 - 2016-08-11 15:29 - 00039862 _____ C:\Users\user1\Desktop\100 Greatest Bollywood Soundtracks Ever - Part 3 - Planet Bollywood Features.html 2016-08-11 15:29 - 2016-08-11 15:29 - 00039043 _____ C:\Users\user1\Desktop\100 Greatest Bollywood Soundtracks Ever - Part 2 - Planet Bollywood Features.html 2016-08-11 15:28 - 2016-08-11 21:33 - 00000000 ____D C:\Users\user1\Desktop\100 Greatest Bollywood Soundtracks Ever - Part 4 - Planet Bollywood Features_files 2016-08-11 15:28 - 2016-08-11 15:28 - 00045141 _____ C:\Users\user1\Desktop\100 Greatest Bollywood Soundtracks Ever - Part 4 - Planet Bollywood Features.html 2016-08-10 14:25 - 2016-08-10 14:25 - 00141871 _____ C:\Users\user1\Desktop\YASH VIR AADHAR.pdf ==================== One Month Modified files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2016-08-30 10:32 - 2015-04-16 08:19 - 00003598 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3268202683-2675470380-2750706328-1001 2016-08-30 10:29 - 2015-04-16 10:46 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2016-08-30 10:28 - 2015-04-16 10:29 - 00000912 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2016-08-30 10:27 - 2015-04-24 08:16 - 00008192 _____ C:\Windows\SysWOW64\WDPABKP.dat 2016-08-30 10:27 - 2015-04-17 00:32 - 00000000 ___RD C:\Users\user1\OneDrive 2016-08-30 10:26 - 2013-08-22 20:15 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2016-08-30 10:26 - 2013-08-22 18:55 - 00262144 ___SH C:\Windows\system32\config\BBI 2016-08-30 10:24 - 2013-12-28 17:35 - 00000000 ____D C:\Users\user1\Downloads\images 2016-08-30 10:18 - 2015-04-16 10:29 - 00000916 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2016-08-30 10:17 - 2015-04-17 09:06 - 00000918 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3268202683-2675470380-2750706328-1001UA.job 2016-08-30 10:14 - 2014-11-21 14:14 - 00006492 _____ C:\Windows\system32\PerfStringBackup.INI 2016-08-30 10:12 - 2015-10-15 13:35 - 00329728 ___SH C:\Users\user1\Desktop\Thumbs.db 2016-08-30 09:56 - 2015-04-17 13:29 - 00000000 __SHD C:\ProgramData\Google 2016-08-30 09:56 - 2015-04-16 08:12 - 00000000 ____D C:\Users\user1 2016-08-30 09:55 - 2015-04-16 10:41 - 00000000 __SHD C:\ProgramData\Mozilla 2016-08-30 09:32 - 2015-04-16 10:27 - 00003910 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{5D0A3D1B-5678-4769-9E6F-774691AF4237} 2016-08-30 09:17 - 2015-04-17 09:06 - 00000866 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3268202683-2675470380-2750706328-1001Core.job 2016-08-29 18:27 - 2016-06-14 19:34 - 00000000 ____D C:\Program Files (x86)\Wi-Fi 2016-08-29 18:12 - 2015-04-16 10:42 - 00000000 ____D C:\Users\user1\AppData\Roaming\vlc 2016-08-29 17:28 - 2016-05-30 09:42 - 00000000 ____D C:\Users\user1\Desktop\Tor Browser 2016-08-29 15:40 - 2013-08-22 20:50 - 00000000 ____D C:\Windows\CbsTemp 2016-08-29 15:19 - 2016-05-21 09:24 - 00000500 _____ C:\Windows\system32\Drivers\etc\hosts.ics 2016-08-29 15:11 - 2015-04-17 09:21 - 00000000 ____D C:\Users\user1\AppData\Roaming\uTorrent 2016-08-29 11:50 - 2013-08-22 19:06 - 00000000 ____D C:\Windows\Inf 2016-08-28 14:20 - 2016-06-09 12:48 - 00000000 ____D C:\Users\user1\Desktop\tanu photo , sign and finger scans 2016-08-27 19:01 - 2013-08-22 21:06 - 00000000 ___HD C:\Windows\system32\GroupPolicy 2016-08-27 19:01 - 2013-08-22 21:06 - 00000000 ____D C:\Windows\SysWOW64\GroupPolicy 2016-08-25 13:38 - 2015-04-20 10:34 - 00000000 ____D C:\Program Files (x86)\Steam 2016-08-24 15:44 - 2015-04-16 10:46 - 00003718 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2016-08-24 15:44 - 2013-08-22 21:06 - 00000000 ____D C:\Windows\SysWOW64\Macromed 2016-08-24 15:44 - 2013-08-22 21:06 - 00000000 ____D C:\Windows\system32\Macromed 2016-08-21 16:08 - 2013-08-22 21:06 - 00000000 ____D C:\Windows\rescache 2016-08-20 06:50 - 2013-08-22 20:14 - 00511696 _____ C:\Windows\system32\FNTCACHE.DAT 2016-08-19 09:37 - 2013-08-22 21:06 - 00000000 ___RD C:\Windows\ToastData 2016-08-19 09:36 - 2015-04-18 13:24 - 00000000 ____D C:\Windows\system32\appraiser 2016-08-19 09:36 - 2014-11-21 13:55 - 00000000 ____D C:\Program Files\Windows Journal 2016-08-19 08:18 - 2015-04-17 10:44 - 00000000 ____D C:\Windows\system32\MRT 2016-08-19 08:05 - 2015-04-17 10:44 - 147640136 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe 2016-08-18 09:25 - 2013-08-22 21:06 - 00000000 ___HD C:\Program Files\WindowsApps 2016-08-18 09:25 - 2013-08-22 21:06 - 00000000 ____D C:\Windows\AppReadiness 2016-08-10 14:32 - 2015-04-16 08:14 - 00000000 ____D C:\Users\user1\AppData\Roaming\Adobe 2016-08-09 10:20 - 2015-05-08 23:05 - 00002175 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2016-08-09 10:20 - 2015-05-08 23:05 - 00002163 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2016-08-01 09:13 - 2015-04-16 10:29 - 00003888 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2016-08-01 09:13 - 2015-04-16 10:29 - 00003652 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2016-08-01 09:12 - 2015-04-17 09:06 - 00003864 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3268202683-2675470380-2750706328-1001UA 2016-08-01 09:12 - 2015-04-17 09:06 - 00003484 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3268202683-2675470380-2750706328-1001Core ==================== Files in the root of some directories ======= 2015-05-08 22:52 - 2015-05-08 23:00 - 0000800 _____ () C:\Users\user1\AppData\Local\Temp-log.txt Some files in TEMP: ==================== C:\Users\user1\AppData\Local\Temp\cdo1691954858.dll C:\Users\user1\AppData\Local\Temp\cdo2380030705.dll C:\Users\user1\AppData\Local\Temp\cdo4068433098.dll C:\Users\user1\AppData\Local\Temp\cdo737675194.dll C:\Users\user1\AppData\Local\Temp\cdo956270952.dll C:\Users\user1\AppData\Local\Temp\Extract.exe C:\Users\user1\AppData\Local\Temp\GUR3421.exe C:\Users\user1\AppData\Local\Temp\HPSFUpdater.exe C:\Users\user1\AppData\Local\Temp\libeay32.dll C:\Users\user1\AppData\Local\Temp\msvcr120.dll C:\Users\user1\AppData\Local\Temp\sqlite3.dll C:\Users\user1\AppData\Local\Temp\UninstallHPSA.exe ==================== Bamital & volsnap ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\dnsapi.dll => File is digitally signed C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2016-08-17 13:32 ==================== End of FRST.txt ============================