Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 29-01-2017
Ran by alrrm (ATTENTION: The user is not administrator) on AMANDA (02-02-2017 15:52:22)
Running from C:\Users\alrrm\Downloads
Loaded Profiles: alrrm & Administrator (Available Profiles: Amanda & alrrm & Administrator)
Platform: Windows 10 Home Version 1607 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Edge)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
http://www.geekstogo.com/forum/topic/33 ... scan-tool/==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
Failed to access process -> smss.exe
Failed to access process -> csrss.exe
Failed to access process -> wininit.exe
Failed to access process -> csrss.exe
Failed to access process -> services.exe
Failed to access process -> lsass.exe
Failed to access process -> svchost.exe
Failed to access process -> winlogon.exe
Failed to access process -> svchost.exe
Failed to access process -> dwm.exe
Failed to access process -> svchost.exe
Failed to access process -> svchost.exe
Failed to access process -> svchost.exe
Failed to access process -> svchost.exe
Failed to access process -> svchost.exe
Failed to access process -> svchost.exe
Failed to access process -> igfxCUIService.exe
Failed to access process -> svchost.exe
Failed to access process -> svchost.exe
Failed to access process -> svchost.exe
Failed to access process -> spoolsv.exe
Failed to access process -> svchost.exe
Failed to access process -> svchost.exe
Failed to access process -> svchost.exe
Failed to access process -> svchost.exe
Failed to access process -> SASCore64.exe
Failed to access process -> svchost.exe
Failed to access process -> dasHost.exe
Failed to access process -> DropboxUpdate.exe
Failed to access process -> PresentationFontCache.exe
Failed to access process -> SearchIndexer.exe
Failed to access process -> wmpnetwk.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
Failed to access process -> svchost.exe
Failed to access process -> dllhost.exe
Failed to access process -> ekrn.exe
(ESET) C:\Program Files\ESET\ESET Internet Security\egui.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
Failed to access process -> svchost.exe
() C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.10.152.0_x64__kzf8qxf38zg5c\SkypeHost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(OldTimer Tools) C:\Users\alrrm\Downloads\OTL.exe
Failed to access process -> DbxSvc.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.16122.10291.0_x64__8wekyb3d8bbwe\Video.UI.exe
(Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [1804360 2016-03-22] (NVIDIA Corporation)
HKLM\...\Run: [IgfxTray] => C:\Windows\system32\igfxtray.exe [401888 2016-11-30] ()
HKLM\...\Run: [HotKeysCmds] => "C:\Windows\system32\hkcmd.exe"
HKLM\...\Run: [Persistence] => "C:\Windows\system32\igfxpers.exe"
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
HKLM\...\Run: [Malwarebytes Anti-Ransomware] => "C:\Program Files\Malwarebytes\Anti-Ransomware\mbarw.exe"--starttray
HKLM-x32\...\Run: [WebStorage] => C:\Program Files (x86)\ASUS\WebStorage\2.1.2.301\ASUSWSLoader.exe [63296 2014-02-24] ()
HKLM-x32\...\Run: [ASUS InstantKey] => C:\Program Files (x86)\ASUS\ASUS Instant Key\Ikey_start.exe [14448 2014-01-28] (ASUS)
HKLM-x32\...\Run: [CLMLServer] => C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe [111120 2012-05-24] (CyberLink)
HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [26219896 2017-01-30] (Dropbox, Inc.)
HKLM-x32\...\RunOnce: [DeleteOnReboot] => C:\Users\ADMINI~1\AppData\Local\Temp\DeleteOnReboot.bat <===== ATTENTION
HKU\S-1-5-21-1881099098-1900828172-3762033838-1006\...\Run: [SUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [7943072 2017-02-01] (SUPERAntiSpyware)
ShellIconOverlayIdentifiers: [ DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.14.0.dll [2017-01-30] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.14.0.dll [2017-01-30] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.14.0.dll [2017-01-30] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.14.0.dll [2017-01-30] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.14.0.dll [2017-01-30] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.14.0.dll [2017-01-30] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.14.0.dll [2017-01-30] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.14.0.dll [2017-01-30] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.14.0.dll [2017-01-30] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.14.0.dll [2017-01-30] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [!AsusWSShellExt_B] -> {6D4133E5-0742-4ADC-8A8C-9303440F7191} => C:\Program Files (x86)\Common Files\AWS\2.1.2.301\ASUSWSShellExt64.dll [2013-06-25] (ASUS Cloud Corporation.)
ShellIconOverlayIdentifiers: [!AsusWSShellExt_O] -> {64174815-8D98-4CE6-8646-4C039977D809} => C:\Program Files (x86)\Common Files\AWS\2.1.2.301\ASUSWSShellExt64.dll [2013-06-25] (ASUS Cloud Corporation.)
ShellIconOverlayIdentifiers: [!AsusWSShellExt_U] -> {1C5AB7B1-0B38-4EC4-9093-7FD277E2AF4E} => C:\Program Files (x86)\Common Files\AWS\2.1.2.301\ASUSWSShellExt64.dll [2013-06-25] (ASUS Cloud Corporation.)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
ShellIconOverlayIdentifiers-x32: [ DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.14.0.dll [2017-01-30] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.14.0.dll [2017-01-30] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.14.0.dll [2017-01-30] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.14.0.dll [2017-01-30] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.14.0.dll [2017-01-30] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.14.0.dll [2017-01-30] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.14.0.dll [2017-01-30] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.14.0.dll [2017-01-30] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.14.0.dll [2017-01-30] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.14.0.dll [2017-01-30] (Dropbox, Inc.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254
Tcpip\..\Interfaces\{3554543f-d263-4537-aa82-95d6c294305e}: [DhcpNameServer] 192.168.1.254
Tcpip\..\Interfaces\{457b9519-13cf-442c-8bf4-40c067b4d8da}: [DhcpNameServer] 192.168.1.254
Internet Explorer:
==================
HKU\S-1-5-21-1881099098-1900828172-3762033838-1006\Software\Microsoft\Internet Explorer\Main,Start Page =
hxxp://asus13.msn.com/?pc=ASJBHKU\S-1-5-21-1881099098-1900828172-3762033838-1006\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
hxxp://asus13.msn.com/?pc=ASJBURLSearchHook: [S-1-5-21-1881099098-1900828172-3762033838-500] ATTENTION => Default URLSearchHook is missing
SearchScopes: HKU\S-1-5-21-1881099098-1900828172-3762033838-1006 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-1881099098-1900828172-3762033838-1006 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
FireFox:
========
FF DefaultProfile: s8zt1xfg.default
FF ProfilePath: C:\Users\alrrm\AppData\Roaming\Mozilla\Firefox\Profiles\s8zt1xfg.default [2017-02-01]
FF Extension: (All Aboard) - C:\Users\alrrm\AppData\Roaming\Mozilla\Firefox\Profiles\s8zt1xfg.default\Extensions\@all-aboard-v1-5 [2016-12-07]
FF Extension: (Google Scholar Button) - C:\Users\alrrm\AppData\Roaming\Mozilla\Firefox\Profiles\s8zt1xfg.default\Extensions\button@scholar.google.com.xpi [2016-12-23]
FF Extension: (Torrent Finder Toolbar) - C:\Users\alrrm\AppData\Roaming\Mozilla\Firefox\Profiles\s8zt1xfg.default\Extensions\TFToolbarX@torrent-finder.xpi [2016-12-23]
FF Extension: (Resurrect Pages) - C:\Users\alrrm\AppData\Roaming\Mozilla\Firefox\Profiles\s8zt1xfg.default\Extensions\{0c8fbd76-bdeb-4c52-9b24-d587ce7b9dc3}.xpi [2016-12-23]
FF Extension: (Search Helper) - C:\Users\alrrm\AppData\Roaming\Mozilla\Firefox\Profiles\s8zt1xfg.default\Extensions\{7233fab4-47f6-410e-98eb-ad01581755ed}.xpi [2016-12-23]
FF Extension: (FoxySpider) - C:\Users\alrrm\AppData\Roaming\Mozilla\Firefox\Profiles\s8zt1xfg.default\Extensions\{75df891f-e299-4725-b14f-7d52f086dea2}.xpi [2016-12-23]
FF Extension: (StumbleUpon) - C:\Users\alrrm\AppData\Roaming\Mozilla\Firefox\Profiles\s8zt1xfg.default\Extensions\{AE93811A-5C9A-4d34-8462-F7B864FC4696}.xpi [2016-12-23]
FF Extension: (Download YouTube Videos as MP4) - C:\Users\alrrm\AppData\Roaming\Mozilla\Firefox\Profiles\s8zt1xfg.default\Extensions\{b9bfaf1c-a63f-47cd-8b9a-29526ced9060}.xpi [2016-12-23]
FF Extension: (Ecosia — The search engine that plants trees!) - C:\Users\alrrm\AppData\Roaming\Mozilla\Firefox\Profiles\s8zt1xfg.default\Extensions\{d04b0b40-3dab-4f0b-97a6-04ec3eddbfb0}.xpi [2016-12-23]
FF Extension: (DownThemAll!) - C:\Users\alrrm\AppData\Roaming\Mozilla\Firefox\Profiles\s8zt1xfg.default\Extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi [2016-12-23]
FF Extension: (Scholar H-Index Calculator) - C:\Users\alrrm\AppData\Roaming\Mozilla\Firefox\Profiles\s8zt1xfg.default\Extensions\{e55904c8-769b-4ffe-8d47-48f411f37d22}.xpi [2016-12-23]
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-12-09] (Intel Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-16] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-16] (Google Inc.)
Chrome:
=======
CHR Profile: C:\Users\alrrm\AppData\Local\Google\Chrome\User Data\Default [2017-02-02]
CHR Extension: (Google Slides) - C:\Users\alrrm\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-12-04]
CHR Extension: (Google Docs) - C:\Users\alrrm\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-12-04]
CHR Extension: (Google Drive) - C:\Users\alrrm\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-12-04]
CHR Extension: (YouTube) - C:\Users\alrrm\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-12-04]
CHR Extension: (High Contrast) - C:\Users\alrrm\AppData\Local\Google\Chrome\User Data\Default\Extensions\djcfdncoelnlbldjfhinnjlhdjlikmph [2017-01-19]
CHR Extension: (Google Sheets) - C:\Users\alrrm\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-12-04]
CHR Extension: (Google Docs Offline) - C:\Users\alrrm\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-12-07]
CHR Extension: (VoiceNote II - Speech to text) - C:\Users\alrrm\AppData\Local\Google\Chrome\User Data\Default\Extensions\jimdfkeocobeeldobhpakapbhdeample [2016-12-20]
CHR Extension: (Chrome Web Store Payments) - C:\Users\alrrm\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-01-18]
CHR Extension: (Gmail) - C:\Users\alrrm\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-12-04]
CHR Extension: (Chrome Media Router) - C:\Users\alrrm\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-12-20]
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [172344 2014-07-22] (SUPERAntiSpyware.com)
S4 Asus WebStorage Windows Service; C:\Program Files (x86)\ASUS\WebStorage\2.1.2.301\AsusWSWinService.exe [71680 2014-02-24] (ASUS Cloud Corporation) [File not signed]
S4 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-12-23] (Dropbox, Inc.)
S4 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-12-23] (Dropbox, Inc.)
R2 DbxSvc; C:\Windows\system32\DbxSvc.exe [46400 2017-01-30] (Dropbox, Inc.)
R2 ekrn; C:\Program Files\ESET\ESET Internet Security\ekrn.exe [2836296 2016-12-14] (ESET)
R2 igfxCUIService2.0.0.0; C:\Windows\system32\igfxCUIService.exe [373728 2016-11-30] (Intel Corporation)
S4 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [747520 2013-08-27] (Intel(R) Corporation) [File not signed]
S4 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [828376 2013-08-27] (Intel(R) Corporation)
S4 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [131544 2013-12-09] (Intel Corporation)
S4 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-12-09] (Intel Corporation)
S3 lmhosts; C:\Windows\System32\svchost.exe [44496 2016-07-16] (Microsoft Corporation)
S3 lmhosts; C:\Windows\SysWOW64\svchost.exe [38792 2016-07-16] (Microsoft Corporation)
R2 NlaSvc; C:\Windows\System32\svchost.exe [44496 2016-07-16] (Microsoft Corporation)
R2 NlaSvc; C:\Windows\SysWOW64\svchost.exe [38792 2016-07-16] (Microsoft Corporation)
R2 nsi; C:\Windows\system32\svchost.exe [44496 2016-07-16] (Microsoft Corporation)
R2 nsi; C:\Windows\SysWOW64\svchost.exe [38792 2016-07-16] (Microsoft Corporation)
S4 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1593632 2014-01-20] (NVIDIA Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347328 2016-07-16] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103720 2016-07-16] (Microsoft Corporation)
S4 MB3Service; "C:\Program Files\Malwarebytes\Anti-Ransomware\MB3Service.exe" [X]
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 ATP; C:\Windows\System32\drivers\AsusTP.sys [101368 2015-12-14] (ASUS Corporation)
R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [132272 2016-12-05] (ESET)
R0 edevmon; C:\Windows\System32\DRIVERS\edevmon.sys [106768 2016-12-05] (ESET)
S0 eelam; C:\Windows\System32\DRIVERS\eelam.sys [15488 2016-12-09] (ESET)
R1 ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [180544 2016-12-05] (ESET)
S2 ekbdflt; C:\Windows\system32\DRIVERS\ekbdflt.sys [49672 2016-12-05] (ESET)
R1 epfw; C:\Windows\system32\DRIVERS\epfw.sys [77616 2016-12-05] (ESET)
R1 epfwwfp; C:\Windows\system32\DRIVERS\epfwwfp.sys [96856 2016-12-05] (ESET)
R0 IntelHSWPcc; C:\Windows\System32\drivers\IntelPcc.sys [74344 2013-08-05] (Intel Corporation)
R3 kbfiltr; C:\Windows\System32\drivers\kbfiltr.sys [17280 2012-08-05] ( )
R0 MB3SwissArmy; C:\Windows\System32\drivers\MB3SwissArmy.sys [228800 2016-12-23] (Malwarebytes)
R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [100312 2013-12-09] (Intel Corporation)
S3 NetAdapterCx; C:\Windows\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] ()
R3 netr28x; C:\Windows\System32\drivers\netr28x.sys [2504192 2016-07-16] (MediaTek Inc.)
R2 plctrl; C:\Program Files\ASUS\P4G\plctrl.sys [14136 2014-02-11] (Windows (R) Win 7 DDK provider)
R3 rtbth; C:\Windows\System32\drivers\rtbth.sys [1219200 2015-06-03] (Ralink Technology, Corp.)
R3 RTSPER; C:\Windows\system32\DRIVERS\RtsPer.sys [759552 2015-07-08] (Realsil Semiconductor Corporation)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation)
U0 aswVmm; no ImagePath
S3 dbx; system32\DRIVERS\dbx.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-02-02 15:52 - 2017-02-02 15:53 - 00020191 _____ C:\Users\alrrm\Downloads\FRST.txt
2017-02-02 15:50 - 2017-02-02 15:52 - 00000000 ___DC C:\FRST
2017-02-02 15:49 - 2017-02-02 15:50 - 02420736 _____ (Farbar) C:\Users\alrrm\Downloads\FRST64.exe
2017-02-02 13:34 - 2017-02-02 13:34 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox
2017-02-02 13:33 - 2017-02-02 13:33 - 00120150 _____ C:\Users\alrrm\Downloads\Extras.Txt
2017-02-02 13:31 - 2017-02-02 13:31 - 00167626 _____ C:\Users\alrrm\Downloads\OTL.Txt
2017-02-02 13:02 - 2017-02-02 13:02 - 00602112 _____ (OldTimer Tools) C:\Users\alrrm\Downloads\OTL.exe
2017-02-02 07:27 - 2017-02-02 07:27 - 00002121 _____ C:\Users\Public\Desktop\ESET Banking & Payment protection.lnk
2017-02-02 07:27 - 2017-02-02 07:27 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ESET
2017-02-02 07:27 - 2017-02-02 07:27 - 00000000 ____D C:\ProgramData\ESET
2017-02-02 07:27 - 2017-02-02 07:27 - 00000000 ____D C:\Program Files\ESET
2017-02-02 07:19 - 2017-02-02 07:31 - 00000000 ____D C:\Users\alrrm\AppData\Local\ESET
2017-02-02 07:18 - 2017-02-02 07:19 - 06771840 _____ (ESET spol. s r.o.) C:\Users\alrrm\Downloads\esetonlinescanner_enu.exe
2017-02-02 07:18 - 2017-02-02 07:19 - 03138176 _____ (ESET) C:\Users\alrrm\Downloads\eset_nod32_antivirus_live_installer.exe
2017-02-02 07:18 - 2017-02-02 07:19 - 03134592 _____ (ESET) C:\Users\alrrm\Downloads\eset_internet_security_live_installer.exe
2017-02-01 23:04 - 2017-02-02 07:03 - 00000000 ____D C:\Program Files\SUPERAntiSpyware
2017-02-01 23:04 - 2017-02-01 23:04 - 00001849 _____ C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
2017-02-01 23:04 - 2017-02-01 23:04 - 00000000 ____D C:\Users\Administrator\AppData\Roaming\SUPERAntiSpyware.com
2017-02-01 23:04 - 2017-02-01 23:04 - 00000000 ____D C:\ProgramData\SUPERAntiSpyware.com
2017-02-01 23:04 - 2017-02-01 23:04 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
2017-02-01 22:53 - 2017-02-01 22:53 - 00000000 ____D C:\Users\alrrm\Desktop\New folder
2017-02-01 14:37 - 2017-02-01 14:37 - 00016744 _____ C:\Users\alrrm\Documents\Untitled 17.odt
2017-02-01 07:05 - 2017-02-01 07:05 - 01611624 _____ C:\Users\alrrm\Downloads\1034013860-20160915-085349- (1).pdf
2017-02-01 07:04 - 2017-02-01 07:04 - 01611624 _____ C:\Users\alrrm\Downloads\1034013860-20160915-085349-.pdf
2017-02-01 06:20 - 2017-02-01 06:20 - 00097802 _____ C:\Users\alrrm\Downloads\1004109865-20061017-145807-.pdf
2017-02-01 06:18 - 2017-02-01 06:18 - 02651006 _____ C:\Users\alrrm\Downloads\1004066987-20060928-160658-.pdf
2017-02-01 06:05 - 2017-02-01 06:05 - 00315298 _____ C:\Users\alrrm\Downloads\1034014053-20160926-104539-.pdf
2017-02-01 06:03 - 2017-02-01 06:03 - 00139148 _____ C:\Users\alrrm\Downloads\1004641336-20070323-141026-.pdf
2017-02-01 06:01 - 2017-02-01 06:01 - 00298145 _____ C:\Users\alrrm\Downloads\1004357070-20070116-135449-.pdf
2017-02-01 03:16 - 2017-02-01 03:16 - 03508812 _____ C:\Users\alrrm\Downloads\etd8087_BReillySchmidt.pdf
2017-02-01 00:21 - 2017-02-01 00:21 - 00000091 ____H C:\Users\alrrm\Downloads\.~lock.Motion_To_Vacate_Judgment.doc#
2017-02-01 00:19 - 2017-02-01 14:37 - 00011888 _____ C:\Users\alrrm\Documents\Untitled 15.odt
2017-02-01 00:19 - 2017-02-01 00:19 - 00008782 _____ C:\Users\alrrm\Documents\Untitled 16.odt
2017-01-30 08:02 - 2017-01-30 08:02 - 00046400 _____ (Dropbox, Inc.) C:\Windows\system32\DbxSvc.exe
2017-01-30 08:02 - 2017-01-30 08:02 - 00046192 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-stable.sys
2017-01-30 08:02 - 2017-01-30 08:02 - 00046192 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-dev.sys
2017-01-30 08:02 - 2017-01-30 08:02 - 00046192 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-canary.sys
2017-01-30 07:08 - 2017-01-30 07:08 - 00000000 ____D C:\Windows\LastGood
2017-01-25 19:13 - 2017-01-25 19:13 - 00000000 _____ C:\Windows\system32\GfxValDisplayLog.bin
2017-01-25 19:12 - 2017-01-25 19:12 - 00000000 ____D C:\Windows\LastGood.Tmp
2017-01-25 15:17 - 2017-01-25 15:17 - 00134533 _____ C:\Users\alrrm\Downloads\1030182971-20150911-091540-.pdf
2017-01-25 15:01 - 2017-01-25 15:01 - 00266068 _____ C:\Users\alrrm\Downloads\161204001208_0001__161204001254_0001__161204001444_0001__161204001410_0001__161204001516_0001__161204001337_0001 (2).pdf
2017-01-25 15:01 - 2017-01-25 15:01 - 00266068 _____ C:\Users\alrrm\Downloads\161204001208_0001__161204001254_0001__161204001444_0001__161204001410_0001__161204001516_0001__161204001337_0001 (1).pdf
2017-01-24 16:19 - 2016-12-21 01:08 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe
2017-01-24 16:19 - 2016-12-20 22:44 - 00120320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\poqexec.exe
2017-01-23 09:12 - 2017-01-23 09:12 - 00881575 _____ C:\Users\alrrm\Downloads\providers (2).pdf
2017-01-23 09:09 - 2017-01-23 09:09 - 00881575 _____ C:\Users\alrrm\Downloads\providers (1).pdf
2017-01-23 08:51 - 2017-01-23 08:51 - 00040471 _____ C:\Users\alrrm\Downloads\Letter (4).pdf
2017-01-23 08:51 - 2017-01-23 08:51 - 00040471 _____ C:\Users\alrrm\Downloads\Letter (2).pdf
2017-01-23 08:51 - 2017-01-23 08:51 - 00040156 _____ C:\Users\alrrm\Downloads\Letter (3).pdf
2017-01-23 08:49 - 2017-01-23 08:49 - 00068142 _____ C:\Users\alrrm\Downloads\Letter (1).pdf
2017-01-23 08:49 - 2017-01-23 08:49 - 00040156 _____ C:\Users\alrrm\Downloads\Letter.pdf
2017-01-23 08:37 - 2017-01-23 08:37 - 00038802 _____ C:\Users\alrrm\Downloads\SoonerCare Benefit Comparison_091116.pdf
2017-01-23 05:55 - 2017-01-23 05:55 - 00867975 _____ C:\Users\alrrm\Downloads\343-1-672-1-10-20120918.pdf
2017-01-21 20:45 - 2017-01-21 20:45 - 00011974 _____ C:\Users\alrrm\Documents\Untitled 12.odt
2017-01-21 20:45 - 2017-01-21 20:45 - 00010625 _____ C:\Users\alrrm\Documents\Untitled 13.odt
2017-01-21 20:45 - 2017-01-21 20:45 - 00008598 _____ C:\Users\alrrm\Documents\Untitled 14.odt
2017-01-20 23:52 - 2017-01-20 23:52 - 00526643 _____ C:\Users\alrrm\Downloads\before-you-go.pdf
2017-01-20 12:25 - 2017-01-20 12:25 - 00000091 ____H C:\Users\alrrm\Downloads\.~lock.Ex-Parte-Motion-for-Order-Shortening-Time.doc#
2017-01-20 11:35 - 2017-01-20 11:35 - 00591629 _____ C:\Users\alrrm\Downloads\Tag_Gun_Do_s_and_Dont_s.pdf
2017-01-20 11:35 - 2017-01-20 11:35 - 00483757 _____ C:\Users\alrrm\Downloads\JBF_Pricing_Guideline_Jan_17.pdf
2017-01-20 11:35 - 2017-01-20 11:35 - 00447323 _____ C:\Users\alrrm\Downloads\Tagging_Time_Breaking_it_Down.pdf
2017-01-20 04:34 - 2017-01-20 04:34 - 02507803 _____ C:\Users\alrrm\Downloads\E7 - Ex Parte Motion for Order Shortening Time.pdf
2017-01-19 06:52 - 2017-02-01 15:56 - 00047616 ___SH C:\Users\alrrm\Documents\Thumbs.db
2017-01-18 04:23 - 2017-01-18 04:23 - 00260529 _____ C:\Users\alrrm\Downloads\BEHAVIORAL HEALTH DIRECTORY (2).pdf
2017-01-18 04:02 - 2017-01-18 04:02 - 00433759 _____ C:\Users\alrrm\Downloads\MNC_5_22_12_ DENIAL Clarification added.pdf
2017-01-18 03:40 - 2017-01-18 03:40 - 00014023 _____ C:\Users\alrrm\Documents\inventory.odt
2017-01-17 18:52 - 2017-01-17 18:53 - 00375990 _____ C:\Users\alrrm\Downloads\E1 - Ex Parte Motion Regarding Children.pdf
2017-01-17 18:48 - 2017-01-17 18:48 - 00099304 _____ C:\Users\alrrm\Downloads\Motion_for_Judgment.pdf
2017-01-17 18:48 - 2017-01-17 18:48 - 00000091 ____H C:\Users\alrrm\Downloads\.~lock.Motion_to_Dismiss_Complaint.doc#
2017-01-17 17:30 - 2017-01-17 17:30 - 00000000 ____D C:\Users\alrrm\AppData\Roaming\Scribus
2017-01-17 17:26 - 2017-01-17 17:26 - 00091233 _____ C:\Users\alrrm\Downloads\Ex_Parte_Temporary_Custody.pdf
2017-01-17 15:38 - 2017-02-01 00:17 - 00029696 ___SH C:\Users\alrrm\Desktop\Thumbs.db
2017-01-12 02:51 - 2017-01-12 02:51 - 00417568 _____ C:\Users\alrrm\Downloads\Credit and Collections Policy.pdf
2017-01-11 09:57 - 2017-01-11 09:57 - 00237994 _____ C:\Users\alrrm\Downloads\unconditionalwaiverandreleaseonfinalpayment.pdf
2017-01-11 09:36 - 2017-01-11 09:36 - 00237994 _____ C:\Users\alrrm\Documents\UnconditionalWaiverAndReleaseOnFinalPayment[114].pdf
2017-01-11 00:27 - 2016-12-22 17:13 - 00835576 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2017-01-11 00:27 - 2016-12-22 17:13 - 00177656 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2017-01-10 21:30 - 2016-12-21 02:08 - 00245600 _____ (Microsoft Corporation) C:\Windows\system32\offlinesam.dll
2017-01-10 21:30 - 2016-12-21 02:08 - 00136032 _____ (Microsoft Corporation) C:\Windows\system32\ImplatSetup.dll
2017-01-10 21:30 - 2016-12-21 02:04 - 07816032 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2017-01-10 21:30 - 2016-12-21 01:49 - 00328008 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Storage.ApplicationData.dll
2017-01-10 21:30 - 2016-12-21 01:46 - 00624048 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2017-01-10 21:30 - 2016-12-21 01:43 - 04130440 _____ (Microsoft Corporation) C:\Windows\system32\mfcore.dll
2017-01-10 21:30 - 2016-12-21 01:43 - 01454504 _____ (Microsoft Corporation) C:\Windows\system32\mfnetsrc.dll
2017-01-10 21:30 - 2016-12-21 01:43 - 01071736 _____ (Microsoft Corporation) C:\Windows\system32\mfnetcore.dll
2017-01-10 21:30 - 2016-12-21 01:43 - 00092512 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll
2017-01-10 21:30 - 2016-12-21 01:42 - 22224480 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2017-01-10 21:30 - 2016-12-21 01:42 - 01988560 _____ (Microsoft Corporation) C:\Windows\system32\mfmp4srcsnk.dll
2017-01-10 21:30 - 2016-12-21 01:42 - 01702392 _____ (Microsoft Corporation) C:\Windows\system32\mfasfsrcsnk.dll
2017-01-10 21:30 - 2016-12-21 01:42 - 01300600 _____ (Microsoft Corporation) C:\Windows\system32\mfmpeg2srcsnk.dll
2017-01-10 21:30 - 2016-12-21 01:42 - 00241504 _____ (Microsoft Corporation) C:\Windows\system32\CloudExperienceHost.dll
2017-01-10 21:30 - 2016-12-21 01:41 - 01600632 _____ (Microsoft Corporation) C:\Windows\system32\sppobjs.dll
2017-01-10 21:30 - 2016-12-21 01:37 - 00455520 _____ (Microsoft Corporation) C:\Windows\system32\securekernel.exe
2017-01-10 21:30 - 2016-12-21 01:15 - 22563840 _____ (Microsoft Corporation) C:\Windows\system32\edgehtml.dll
2017-01-10 21:30 - 2016-12-21 01:14 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\LaunchWinApp.exe
2017-01-10 21:30 - 2016-12-21 01:09 - 00368640 _____ (Microsoft Corporation) C:\Windows\system32\OneBackupHandler.dll
2017-01-10 21:30 - 2016-12-21 01:09 - 00363520 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.BioFeedback.dll
2017-01-10 21:30 - 2016-12-21 01:08 - 01292288 _____ (Microsoft Corporation) C:\Windows\system32\MSVPXENC.dll
2017-01-10 21:30 - 2016-12-21 01:08 - 00418304 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.BlockedShutdown.dll
2017-01-10 21:30 - 2016-12-21 01:08 - 00360448 _____ (Microsoft Corporation) C:\Windows\system32\rdpencom.dll
2017-01-10 21:30 - 2016-12-21 01:08 - 00289792 _____ (Microsoft Corporation) C:\Windows\system32\DeveloperOptionsSettingsHandlers.dll
2017-01-10 21:30 - 2016-12-21 01:08 - 00211968 _____ (Microsoft Corporation) C:\Windows\system32\InstallAgent.exe
2017-01-10 21:30 - 2016-12-21 01:07 - 00748544 _____ (Microsoft Corporation) C:\Windows\system32\StoreAgent.dll
2017-01-10 21:30 - 2016-12-21 01:06 - 06285312 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.dll
2017-01-10 21:30 - 2016-12-21 01:06 - 00310784 _____ (Microsoft Corporation) C:\Windows\system32\SyncSettings.dll
2017-01-10 21:30 - 2016-12-21 01:06 - 00260608 _____ (Microsoft Corporation) C:\Windows\system32\InstallAgentUserBroker.exe
2017-01-10 21:30 - 2016-12-21 01:06 - 00147456 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2017-01-10 21:30 - 2016-12-21 01:05 - 00425984 _____ (Microsoft Corporation) C:\Windows\system32\aadcloudap.dll
2017-01-10 21:30 - 2016-12-21 01:05 - 00261632 _____ (Microsoft Corporation) C:\Windows\system32\indexeddbserver.dll
2017-01-10 21:30 - 2016-12-21 01:05 - 00049152 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Shell.dll
2017-01-10 21:30 - 2016-12-21 01:01 - 09131008 _____ (Microsoft Corporation) C:\Windows\system32\twinui.dll
2017-01-10 21:30 - 2016-12-21 01:00 - 00440320 _____ (Microsoft Corporation) C:\Windows\system32\fhcfg.dll
2017-01-10 21:30 - 2016-12-21 00:59 - 01908224 _____ (Microsoft Corporation) C:\Windows\system32\AzureSettingSyncProvider.dll
2017-01-10 21:30 - 2016-12-21 00:59 - 00883712 _____ (Microsoft Corporation) C:\Windows\system32\samsrv.dll
2017-01-10 21:30 - 2016-12-21 00:58 - 23678464 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2017-01-10 21:30 - 2016-12-21 00:57 - 00462336 _____ (Microsoft Corporation) C:\Windows\system32\fhsettingsprovider.dll
2017-01-10 21:30 - 2016-12-21 00:56 - 00947712 _____ (Microsoft Corporation) C:\Windows\system32\MSVP9DEC.dll
2017-01-10 21:30 - 2016-12-21 00:56 - 00936960 _____ (Microsoft Corporation) C:\Windows\system32\MCRecvSrc.dll
2017-01-10 21:30 - 2016-12-21 00:55 - 08129536 _____ (Microsoft Corporation) C:\Windows\system32\Chakra.dll
2017-01-10 21:30 - 2016-12-21 00:55 - 04749312 _____ (Microsoft Corporation) C:\Windows\system32\SettingsHandlers_nt.dll
2017-01-10 21:30 - 2016-12-21 00:54 - 05511680 _____ (Microsoft Corporation) C:\Windows\system32\aclui.dll
2017-01-10 21:30 - 2016-12-21 00:53 - 06664192 _____ (Microsoft Corporation) C:\Windows\system32\mspaint.exe
2017-01-10 21:30 - 2016-12-21 00:53 - 04474368 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_47.dll
2017-01-10 21:30 - 2016-12-21 00:53 - 01692672 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentExtensions.onecore.dll
2017-01-10 21:30 - 2016-12-21 00:51 - 08075776 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2017-01-10 21:30 - 2016-12-21 00:51 - 05611008 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2017-01-10 21:30 - 2016-12-21 00:51 - 02275840 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentServer.dll
2017-01-10 21:30 - 2016-12-21 00:50 - 01490432 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2017-01-10 21:30 - 2016-12-21 00:49 - 04149248 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2017-01-10 21:30 - 2016-12-21 00:49 - 02691072 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Logon.dll
2017-01-10 21:30 - 2016-12-21 00:49 - 01062912 _____ (Microsoft Corporation) C:\Windows\system32\SettingSyncCore.dll
2017-01-10 21:30 - 2016-12-21 00:47 - 01121280 _____ (Microsoft Corporation) C:\Windows\system32\aadtb.dll
2017-01-10 21:30 - 2016-12-20 23:59 - 00218976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\offlinesam.dll
2017-01-10 21:30 - 2016-12-20 23:09 - 00263472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Storage.ApplicationData.dll
2017-01-10 21:30 - 2016-12-20 23:02 - 03892864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfcore.dll
2017-01-10 21:30 - 2016-12-20 23:02 - 01852720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfmp4srcsnk.dll
2017-01-10 21:30 - 2016-12-20 23:02 - 01360464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfnetsrc.dll
2017-01-10 21:30 - 2016-12-20 23:02 - 01277344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfasfsrcsnk.dll
2017-01-10 21:30 - 2016-12-20 23:02 - 01201872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfmpeg2srcsnk.dll
2017-01-10 21:30 - 2016-12-20 23:02 - 00980832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfnetcore.dll
2017-01-10 21:30 - 2016-12-20 23:01 - 20969928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2017-01-10 21:30 - 2016-12-20 22:46 - 00034304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\LaunchWinApp.exe
2017-01-10 21:30 - 2016-12-20 22:43 - 00285184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.BlockedShutdown.dll
2017-01-10 21:30 - 2016-12-20 22:41 - 00253952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.BioFeedback.dll
2017-01-10 21:30 - 2016-12-20 22:41 - 00231936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.LockScreen.dll
2017-01-10 21:30 - 2016-12-20 22:40 - 00557568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\StoreAgent.dll
2017-01-10 21:30 - 2016-12-20 22:40 - 00318976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpencom.dll
2017-01-10 21:30 - 2016-12-20 22:40 - 00237056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SyncSettings.dll
2017-01-10 21:30 - 2016-12-20 22:40 - 00180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InstallAgent.exe
2017-01-10 21:30 - 2016-12-20 22:39 - 01300480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSVPXENC.dll
2017-01-10 21:30 - 2016-12-20 22:39 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InstallAgentUserBroker.exe
2017-01-10 21:30 - 2016-12-20 22:38 - 00866816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Cred.dll
2017-01-10 21:30 - 2016-12-20 22:35 - 04612608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.dll
2017-01-10 21:30 - 2016-12-20 22:35 - 00198656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\indexeddbserver.dll
2017-01-10 21:30 - 2016-12-20 22:34 - 07626752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinui.dll
2017-01-10 21:30 - 2016-12-20 22:33 - 19413504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\edgehtml.dll
2017-01-10 21:30 - 2016-12-20 22:32 - 19417600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2017-01-10 21:30 - 2016-12-20 22:30 - 05398016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aclui.dll
2017-01-10 21:30 - 2016-12-20 22:30 - 01255936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AzureSettingSyncProvider.dll
2017-01-10 21:30 - 2016-12-20 22:27 - 00640000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MCRecvSrc.dll
2017-01-10 21:30 - 2016-12-20 22:26 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSVP9DEC.dll
2017-01-10 21:30 - 2016-12-20 22:25 - 07469056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2017-01-10 21:30 - 2016-12-20 22:25 - 06474752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mspaint.exe
2017-01-10 21:30 - 2016-12-20 22:24 - 06044160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Chakra.dll
2017-01-10 21:30 - 2016-12-20 22:24 - 05061120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll
2017-01-10 21:30 - 2016-12-20 22:24 - 03733504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_47.dll
2017-01-10 21:30 - 2016-12-20 22:24 - 00886272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aadtb.dll
2017-01-10 21:30 - 2016-12-20 22:22 - 01883648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Logon.dll
2017-01-10 21:30 - 2016-12-20 22:22 - 00860672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SettingSyncCore.dll
2017-01-10 21:30 - 2016-12-13 23:41 - 01235296 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2017-01-10 21:30 - 2016-12-13 23:41 - 00590960 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll
2017-01-10 21:30 - 2016-12-13 23:34 - 02482280 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll
2017-01-10 21:30 - 2016-12-13 23:33 - 01356864 _____ (Microsoft Corporation) C:\Windows\system32\ClipUp.exe
2017-01-10 21:30 - 2016-12-13 23:23 - 00404832 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2017-01-10 21:30 - 2016-12-13 23:21 - 02206496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll
2017-01-10 21:30 - 2016-12-13 23:19 - 00584544 _____ (Microsoft Corporation) C:\Windows\system32\SettingSyncHost.exe
2017-01-10 21:30 - 2016-12-13 23:18 - 00715104 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\vhdmp.sys
2017-01-10 21:30 - 2016-12-13 23:18 - 00335712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\pci.sys
2017-01-10 21:30 - 2016-12-13 23:17 - 00319288 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2017-01-10 21:30 - 2016-12-13 23:14 - 01694712 _____ (Microsoft Corporation) C:\Windows\system32\winmde.dll
2017-01-10 21:30 - 2016-12-13 23:14 - 00418952 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll
2017-01-10 21:30 - 2016-12-13 23:14 - 00089416 _____ (Microsoft Corporation) C:\Windows\system32\remoteaudioendpoint.dll
2017-01-10 21:30 - 2016-12-13 23:08 - 00341344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2017-01-10 21:30 - 2016-12-13 23:06 - 00509792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SettingSyncHost.exe
2017-01-10 21:30 - 2016-12-13 23:01 - 01557808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winmde.dll
2017-01-10 21:30 - 2016-12-13 23:01 - 00382784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AUDIOKSE.dll
2017-01-10 21:30 - 2016-12-13 23:01 - 00076984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\remoteaudioendpoint.dll
2017-01-10 21:30 - 2016-12-13 22:48 - 01631232 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.Resources.dll
2017-01-10 21:30 - 2016-12-13 22:46 - 01631232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.Resources.dll
2017-01-10 21:30 - 2016-12-13 22:46 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2017-01-10 21:30 - 2016-12-13 22:45 - 00147968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32k.sys
2017-01-10 21:30 - 2016-12-13 22:43 - 00201728 _____ (Microsoft Corporation) C:\Windows\system32\ScDeviceEnum.dll
2017-01-10 21:30 - 2016-12-13 22:42 - 00352768 _____ (Microsoft Corporation) C:\Windows\system32\cloudAP.dll
2017-01-10 21:30 - 2016-12-13 22:42 - 00236544 _____ (Microsoft Corporation) C:\Windows\system32\WinSCard.dll
2017-01-10 21:30 - 2016-12-13 22:42 - 00208896 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Internal.UI.Logon.ProxyStub.dll
2017-01-10 21:30 - 2016-12-13 22:42 - 00167424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WinSCard.dll
2017-01-10 21:30 - 2016-12-13 22:41 - 00223744 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2017-01-10 21:30 - 2016-12-13 22:40 - 00324096 _____ (Microsoft Corporation) C:\Windows\system32\domgmt.dll
2017-01-10 21:30 - 2016-12-13 22:40 - 00266752 _____ (Microsoft Corporation) C:\Windows\system32\ConsoleLogon.dll
2017-01-10 21:30 - 2016-12-13 22:40 - 00231424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CloudBackupSettings.dll
2017-01-10 21:30 - 2016-12-13 22:40 - 00193536 _____ (Microsoft Corporation) C:\Windows\system32\certprop.dll
2017-01-10 21:30 - 2016-12-13 22:39 - 00837632 _____ (Microsoft Corporation) C:\Windows\system32\wbiosrvc.dll
2017-01-10 21:30 - 2016-12-13 22:39 - 00290816 _____ (Microsoft Corporation) C:\Windows\system32\updatehandlers.dll
2017-01-10 21:30 - 2016-12-13 22:39 - 00257024 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.CredDialogController.dll
2017-01-10 21:30 - 2016-12-13 22:38 - 17188864 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.dll
2017-01-10 21:30 - 2016-12-13 22:38 - 13869056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.dll
2017-01-10 21:30 - 2016-12-13 22:38 - 00295424 _____ (Microsoft Corporation) C:\Windows\system32\CloudBackupSettings.dll
2017-01-10 21:30 - 2016-12-13 22:38 - 00213504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.CredDialogController.dll
2017-01-10 21:30 - 2016-12-13 22:37 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\updatepolicy.dll
2017-01-10 21:30 - 2016-12-13 22:36 - 01002496 _____ (Microsoft Corporation) C:\Windows\system32\SRH.dll
2017-01-10 21:30 - 2016-12-13 22:36 - 00539648 _____ (Microsoft Corporation) C:\Windows\system32\usocore.dll
2017-01-10 21:30 - 2016-12-13 22:36 - 00074752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\updatepolicy.dll
2017-01-10 21:30 - 2016-12-13 22:35 - 00755712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2017-01-10 21:30 - 2016-12-13 22:35 - 00712192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2017-01-10 21:30 - 2016-12-13 22:35 - 00600576 _____ (Microsoft Corporation) C:\Windows\system32\cryptui.dll
2017-01-10 21:30 - 2016-12-13 22:35 - 00553984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptui.dll
2017-01-10 21:30 - 2016-12-13 22:32 - 00497152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\LogonController.dll
2017-01-10 21:30 - 2016-12-13 22:26 - 00932864 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2017-01-10 21:30 - 2016-12-13 22:26 - 00869888 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2017-01-10 21:30 - 2016-12-13 22:25 - 02009600 _____ (Microsoft Corporation) C:\Windows\system32\SRHInproc.dll
2017-01-10 21:30 - 2016-12-13 22:24 - 01005568 _____ (Microsoft Corporation) C:\Windows\system32\D3D12.dll
2017-01-10 21:30 - 2016-12-13 22:24 - 00673792 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2017-01-10 21:30 - 2016-12-13 22:23 - 03134976 _____ (Microsoft Corporation) C:\Windows\system32\rdpcore.dll
2017-01-10 21:30 - 2016-12-13 22:23 - 01231872 _____ (Microsoft Corporation) C:\Windows\system32\dosvc.dll
2017-01-10 21:30 - 2016-12-13 22:22 - 02998272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32kfull.sys
2017-01-10 21:30 - 2016-12-13 22:22 - 02748416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpcore.dll
2017-01-10 21:30 - 2016-12-13 22:22 - 02317824 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2017-01-10 21:30 - 2016-12-13 22:22 - 01513472 _____ (Microsoft Corporation) C:\Windows\system32\win32kbase.sys
2017-01-10 21:30 - 2016-12-13 22:22 - 00707584 _____ (Microsoft Corporation) C:\Windows\system32\LogonController.dll
2017-01-10 21:30 - 2016-12-13 22:22 - 00391168 _____ (Microsoft Corporation) C:\Windows\system32\wuuhext.dll
2017-01-10 21:30 - 2016-12-13 22:21 - 03616768 _____ (Microsoft Corporation) C:\Windows\system32\win32kfull.sys
2017-01-10 21:30 - 2016-11-02 06:01 - 00484584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll
2017-01-10 21:30 - 2016-11-02 05:00 - 00534096 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll
2017-01-10 21:30 - 2016-11-02 04:28 - 00324608 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.LockScreen.dll
2017-01-10 21:30 - 2016-11-02 04:22 - 00337920 _____ (Microsoft Corporation) C:\Windows\system32\AudioEndpointBuilder.dll
2017-01-10 21:30 - 2016-11-02 04:21 - 00942080 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
2017-01-10 21:30 - 2016-08-01 22:30 - 00822784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Chakradiag.dll
2017-01-10 21:29 - 2016-12-21 01:13 - 00119808 _____ (Microsoft Corporation) C:\Windows\system32\KnobsCsp.dll
2017-01-10 21:29 - 2016-12-21 01:12 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\ProvPluginEng.dll
2017-01-10 21:29 - 2016-12-21 01:10 - 00234496 _____ (Microsoft Corporation) C:\Windows\system32\KnobsCore.dll
2017-01-10 21:29 - 2016-12-21 01:08 - 00349184 _____ (Microsoft Corporation) C:\Windows\system32\provengine.dll
2017-01-10 21:29 - 2016-12-13 22:40 - 00104448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Internal.UI.Logon.ProxyStub.dll
2017-01-10 21:29 - 2016-12-13 22:32 - 00806400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3D12.dll
2017-01-10 09:36 - 2017-01-10 09:36 - 00881575 _____ C:\Users\alrrm\Downloads\providers.pdf
2017-01-10 09:35 - 2017-01-10 09:35 - 00260529 _____ C:\Users\alrrm\Downloads\BEHAVIORAL HEALTH DIRECTORY (1).pdf
2017-01-05 10:17 - 2017-01-05 10:17 - 05106186 _____ C:\Users\alrrm\Downloads\GML_DMS-#4824455-v1-ESIS_TECH_2_-_RUTLEDGE_(793637).PDF
2017-01-05 10:17 - 2017-01-05 10:17 - 00108695 _____ C:\Users\alrrm\Downloads\GML_DMS-#4822204-v1-ESIS_AIR_BAG_DATA_(PDF)_-_RUTLEDGE_(793637).PDF
2017-01-05 10:17 - 2017-01-05 10:17 - 00007065 _____ C:\Users\alrrm\Downloads\GML_DMS-#4868293-v1-ESIS_LTR_(DENIAL)_-_RUTLEDGE_(793637).PDF
2017-01-05 08:14 - 2017-01-05 08:14 - 02052666 _____ C:\Users\alrrm\Downloads\Your-Family-Court-Survival-Guide_Checklist.pdf
2017-01-05 05:35 - 2017-01-05 05:35 - 00041987 _____ C:\Users\alrrm\Downloads\1034666605-20161019-162551-.tif
2017-01-05 05:34 - 2017-01-05 05:34 - 00086119 _____ C:\Users\alrrm\Downloads\1034014324-20160926-083025-.tif
2017-01-05 05:34 - 2017-01-05 05:34 - 00027199 _____ C:\Users\alrrm\Downloads\1034666604-20161019-161503-.tif
2017-01-03 13:30 - 2017-01-03 13:30 - 00000091 ____H C:\Users\alrrm\Downloads\.~lock.os10A.rtf#
2017-01-03 13:26 - 2017-01-03 13:26 - 00000091 ____H C:\Users\alrrm\Downloads\.~lock.os10.rtf#
2017-01-03 07:47 - 2017-01-03 07:47 - 00096778 _____ C:\Users\alrrm\Downloads\chss_-_12_-_motion_to_shorten_notice_periodpdf.pdf
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-02-02 15:35 - 2016-12-01 07:54 - 00000000 ____D C:\Windows\system32\SleepStudy
2017-02-02 13:35 - 2016-12-23 14:14 - 00000000 ____D C:\Program Files (x86)\Dropbox
2017-02-02 08:27 - 2016-07-16 05:47 - 00000000 ___HD C:\Program Files\WindowsApps
2017-02-02 08:27 - 2016-07-16 05:47 - 00000000 ____D C:\Windows\AppReadiness
2017-02-02 07:28 - 2016-07-16 05:47 - 00000000 ___HD C:\Windows\ELAMBKUP
2017-02-02 07:28 - 2016-07-16 05:45 - 00000000 ____D C:\Windows\INF
2017-02-02 07:05 - 2016-12-04 00:25 - 00000073 _____ C:\Users\alrrm\AppData\Roaming\sp_data.sys
2017-02-02 07:03 - 2016-12-04 00:25 - 00000000 __SHD C:\Users\alrrm\IntelGraphicsProfiles
2017-02-02 07:03 - 2016-12-04 00:06 - 00000180 _____ C:\Windows\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2017-02-02 07:03 - 2016-12-01 08:07 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2017-02-01 22:55 - 2016-12-17 20:35 - 00000000 ___DC C:\AdwCleaner
2017-02-01 22:40 - 2016-12-01 08:11 - 01740538 _____ C:\Windows\system32\PerfStringBackup.INI
2017-01-28 13:18 - 2016-12-04 00:25 - 00000000 ____D C:\Users\alrrm
2017-01-27 20:06 - 2016-07-16 05:47 - 00000000 ____D C:\Windows\LiveKernelReports
2017-01-26 10:26 - 2016-07-16 05:47 - 00000000 ____D C:\Windows\system32\NDF
2017-01-25 19:13 - 2016-12-01 08:41 - 00000200 _____ C:\Windows\system32\{EC94D02F-D200-4428-9531-05AF7F9799CB}.bat
2017-01-24 19:34 - 2016-07-16 05:36 - 00000000 ____D C:\Windows\CbsTemp
2017-01-24 08:38 - 2016-12-23 17:13 - 00000000 ___RD C:\Users\alrrm\Dropbox
2017-01-21 20:46 - 2016-12-04 00:27 - 00002403 _____ C:\Users\alrrm\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2017-01-21 20:46 - 2016-12-04 00:27 - 00000000 ___RD C:\Users\alrrm\OneDrive
2017-01-20 05:57 - 2016-12-23 12:59 - 00000000 ____D C:\Users\Administrator
2017-01-17 15:56 - 2016-12-07 15:28 - 00000000 ____D C:\Users\alrrm\AppData\LocalLow\Mozilla
2017-01-11 16:30 - 2016-07-16 05:47 - 00000000 ____D C:\Windows\rescache
2017-01-11 00:47 - 2016-12-26 09:45 - 00000000 ____D C:\Windows\pss
2017-01-11 00:28 - 2016-11-28 16:43 - 00000000 __RHD C:\Users\Public\AccountPictures
2017-01-11 00:26 - 2016-12-01 07:54 - 00267800 _____ C:\Windows\system32\FNTCACHE.DAT
2017-01-11 00:12 - 2016-07-16 05:47 - 00000000 ___RD C:\Windows\ImmersiveControlPanel
2017-01-11 00:12 - 2016-07-16 05:47 - 00000000 ____D C:\Windows\system32\WinBioPlugIns
2017-01-11 00:12 - 2016-07-16 05:47 - 00000000 ____D C:\Windows\system32\oobe
2017-01-11 00:12 - 2016-07-16 05:47 - 00000000 ____D C:\Windows\ShellExperiences
2017-01-11 00:12 - 2016-07-16 05:47 - 00000000 ____D C:\Windows\Provisioning
2017-01-10 22:56 - 2016-12-01 11:24 - 00000000 ____D C:\Windows\system32\MRT
2017-01-10 21:38 - 2016-12-01 11:24 - 135657872 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
==================== Files in the root of some directories =======
2016-12-04 00:25 - 2017-02-02 07:05 - 0000073 _____ () C:\Users\alrrm\AppData\Roaming\sp_data.sys
2016-12-01 07:56 - 2016-12-01 07:56 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
2014-05-16 14:02 - 2012-09-07 05:40 - 0000256 _____ () C:\ProgramData\SetStretch.cmd
2014-05-16 14:02 - 2009-07-22 04:04 - 0024576 _____ () C:\ProgramData\SetStretch.exe
2014-05-16 14:02 - 2012-09-07 05:37 - 0000103 _____ () C:\ProgramData\SetStretch.VBS
2016-11-28 16:55 - 2016-11-28 16:57 - 0000105 _____ () C:\ProgramData\{40BF1E83-20EB-11D8-97C5-0009C5020658}.log
2016-11-28 16:54 - 2016-11-28 16:55 - 0000107 _____ () C:\ProgramData\{C59C179C-668D-49A9-B6EA-0121CCFC1243}.log
2016-11-28 17:01 - 2016-11-28 17:02 - 0000111 _____ () C:\ProgramData\{E3739848-5329-48E3-8D28-5BBD6E8BE384}.log
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
ATTENTION: ==> Could not access BCD. The user is not administrator
==================== End of FRST.txt ============================