TechnoDino
2015-12-10, 19:19
Again, not sure how, my computer is infected with the SearchSafe Malware. The omnibox search bar in Chrome will only use SafeSearch. This seems to be one tough piece of malware to remove. The following is all the initial requested initial scans (in no particular order).
Thanks
John :cool:
aka TechnoDino
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:09-12-2015
Ran by John (administrator) on JOHN (09-12-2015 21:05:25)
Running from C:\Users\John\Desktop
Loaded Profiles: John (Available Profiles: John)
Platform: Windows 10 Home (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
(ASUS Cloud Corporation) C:\Program Files (x86)\ASUS\WebStorage\2.1.15.438\AsusWSWinService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe
(Intel(R) Corporation) C:\Program Files\Intel\TXE Components\TCS\HeciServer.exe
(McAfee, Inc.) C:\Program Files (x86)\McAfee\SiteAdvisor\mcsacore.exe
(McAfee, Inc.) C:\Windows\System32\mfevtps.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe
(Samsung Electronics Co., Ltd.) C:\Windows\System32\spool\drivers\x64\3\NetFaxServer64.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
(McAfee, Inc.) C:\Program Files\McAfee\MSC\McAPExe.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
() C:\Wamp\mysql\bin\mysqld.exe
(Apache Software Foundation) C:\Wamp\apache2\bin\httpd.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
(McAfee, Inc.) C:\Windows\System32\mfevtps.exe
(Apache Software Foundation) C:\Wamp\apache2\bin\httpd.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\CSP\1.6.1180.0\McCSPServiceHost.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
() C:\Program Files\WindowsApps\Microsoft.Windows.Photos_15.1208.10480.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\Platform\McUICnt.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [CDAServer] => C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe [464608 2014-09-08] ()
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [3350760 2015-08-06] (ELAN Microelectronics Corp.)
HKLM\...\Run: [LogiOptionsAppBroker] => C:\Program Files\Logitech\LogiOptions\LogiOptions.exe /noui
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [170256 2015-10-16] (Apple Inc.)
HKLM\...\Run: [EvtMgr6] => C:\Program Files\Logitech\SetPointP\SetPoint.exe [3113592 2015-08-25] (Logitech, Inc.)
HKLM-x32\...\Run: [ASUSPRP] => C:\Program Files (x86)\ASUS\APRP\APRP.EXE [1080992 2014-04-18] (ASUSTek Computer Inc.)
HKLM-x32\...\Run: [WebStorage] => C:\Program Files (x86)\ASUS\WebStorage\2.2.4.537\ASUSWSLoader.exe [63272 2015-10-12] ()
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [60688 2015-10-13] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [597552 2015-08-04] (Oracle Corporation)
HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [4127488 2015-06-16] (Safer-Networking Ltd.)
HKLM-x32\...\Run: [ASUS Ai Charger] => C:\Program Files (x86)\ASUS\ASUS Ai Charger\AiChargerAP.exe [547984 2012-08-13] (ASUSTek Computer Inc.)
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
HKU\S-1-5-21-246760859-398526146-1931071061-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8591272 2015-11-16] (Piriform Ltd)
HKU\S-1-5-21-246760859-398526146-1931071061-1001\...\Run: [EEDSpeedLauncher] => rundll32.exe C:\Windows\system32\eed_ec.dll,SpeedLauncher
HKU\S-1-5-21-246760859-398526146-1931071061-1001\...\Run: [appnhost] => C:\Users\John\AppData\Local\Mixesoft\AppNHost\appnhost.exe [453176 2014-08-08] (Mixesoft Project)
HKU\S-1-5-21-246760859-398526146-1931071061-1001\...\Run: [SpybotPostWindows10UpgradeReInstall] => "C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe"
HKU\S-1-5-21-246760859-398526146-1931071061-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [48138880 2015-10-14] (Skype Technologies S.A.)
IFEO\apnmcp.exe: [Debugger] tasklist.exe
IFEO\AppIntegrator64.exe: [Debugger] tasklist.exe
IFEO\brs.exe: [Debugger] tasklist.exe
IFEO\bservice.exe: [Debugger] tasklist.exe
IFEO\bservice64.exe: [Debugger] tasklist.exe
IFEO\cltmng.exe: [Debugger] tasklist.exe
IFEO\cltmngui.exe: [Debugger] tasklist.exe
IFEO\DatamngrUI.exe: [Debugger] tasklist.exe
IFEO\dsrlte.exe: [Debugger] tasklist.exe
IFEO\DTUpdate.exe: [Debugger] tasklist.exe
IFEO\ExtensionUpdaterService.exe: [Debugger] tasklist.exe
IFEO\FrameworkEngine.exe: [Debugger] tasklist.exe
IFEO\HpUI.exe: [Debugger] tasklist.exe
IFEO\IdcLdr.exe: [Debugger] tasklist.exe
IFEO\IdcLdr_x64.exe: [Debugger] tasklist.exe
IFEO\IMGUpdater.exe: [Debugger] tasklist.exe
IFEO\keepmysettingsx.exe: [Debugger] tasklist.exe
IFEO\Loader32.exe: [Debugger] tasklist.exe
IFEO\Loader64.exe: [Debugger] tasklist.exe
IFEO\loggingserver.exe: [Debugger] tasklist.exe
IFEO\Lrcnta.exe: [Debugger] tasklist.exe
IFEO\PastaLeadsService.exe: [Debugger] tasklist.exe
IFEO\PastaLeadsWinApp.exe: [Debugger] tasklist.exe
IFEO\patch_ff.exe: [Debugger] tasklist.exe
IFEO\PluginService.exe: [Debugger] tasklist.exe
IFEO\ProtectWindowsManager.exe: [Debugger] tasklist.exe
IFEO\SafeFinder.exe: [Debugger] tasklist.exe
IFEO\searcharmor.exe: [Debugger] tasklist.exe
IFEO\search_protect.exe: [Debugger] tasklist.exe
IFEO\smu.exe: [Debugger] tasklist.exe
IFEO\spbiu.exe: [Debugger] tasklist.exe
IFEO\srptm.exe: [Debugger] tasklist.exe
IFEO\srpts.exe: [Debugger] tasklist.exe
IFEO\srptsl.exe: [Debugger] tasklist.exe
IFEO\SystemkService.exe: [Debugger] tasklist.exe
IFEO\SystemSockets.exe: [Debugger] tasklist.exe
IFEO\TBNotifier.exe: [Debugger] tasklist.exe
IFEO\TNT2User.exe: [Debugger] tasklist.exe
IFEO\Toolbar.exe: [Debugger] tasklist.exe
IFEO\ToolbarUpdater.exe: [Debugger] tasklist.exe
IFEO\vprot.exe: [Debugger] tasklist.exe
IFEO\wb.exe: [Debugger] tasklist.exe
IFEO\YTDownloader.exe: [Debugger] tasklist.exe
ShellIconOverlayIdentifiers: [!AsusWSShellExt_B] -> {6D4133E5-0742-4ADC-8A8C-9303440F7191} => C:\Program Files (x86)\Common Files\AWS\2.2.4.537\ASUSWSShellExt64.dll [2015-04-22] (ASUS Cloud Corporation.)
ShellIconOverlayIdentifiers: [!AsusWSShellExt_O] -> {64174815-8D98-4CE6-8646-4C039977D809} => C:\Program Files (x86)\Common Files\AWS\2.2.4.537\ASUSWSShellExt64.dll [2015-04-22] (ASUS Cloud Corporation.)
ShellIconOverlayIdentifiers: [!AsusWSShellExt_U] -> {1C5AB7B1-0B38-4EC4-9093-7FD277E2AF4E} => C:\Program Files (x86)\Common Files\AWS\2.2.4.537\ASUSWSShellExt64.dll [2015-04-22] (ASUS Cloud Corporation.)
ShellIconOverlayIdentifiers: [###MegaShellExtPending] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => No File
ShellIconOverlayIdentifiers: [###MegaShellExtSynced] -> {05B38830-F4E9-4329-978B-1DD28605D202} => No File
ShellIconOverlayIdentifiers: [###MegaShellExtSyncing] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => No File
ShellIconOverlayIdentifiers: [1MegaSync0Synced] -> {A52C9916-2007-4C7F-A2D7-0C9612427BD2} => C:\Users\John\AppData\Local\MEGAsync\bin\o\mssoverlay.dll [2013-09-12] (TODO: <Company name>)
ShellIconOverlayIdentifiers: [1MegaSync1Pended] -> {A34CE349-F239-4DA5-9551-4660962F6CD9} => C:\Users\John\AppData\Local\MEGAsync\bin\o\mspoverlay.dll [2013-09-12] (TODO: <Company name>)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Install SafeKey FF RunOnce.lnk [2015-12-09]
ShortcutTarget: Install SafeKey FF RunOnce.lnk -> C:\Program Files (x86)\Common Files\lpuninstall.exe (McAfee)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Install SafeKey IE RunOnce.lnk [2015-12-09]
ShortcutTarget: Install SafeKey IE RunOnce.lnk -> C:\Program Files (x86)\Common Files\lpuninstall.exe (McAfee)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Samsung Network PC Fax.lnk [2015-12-09]
ShortcutTarget: Samsung Network PC Fax.lnk -> C:\Windows\System32\spool\drivers\x64\3\NetFaxTray64.exe (Samsung Electronics Co., Ltd.)
Startup: C:\Users\John\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MEGAsync.lnk [2015-12-09]
ShortcutTarget: MEGAsync.lnk -> C:\Users\John\AppData\Local\MEGAsync\bin\MEGAsync.exe (Mega Limited)
Startup: C:\Users\John\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Send to OneNote.lnk [2015-12-09]
ShortcutTarget: Send to OneNote.lnk -> C:\Program Files\Microsoft Office 15\root\office15\ONENOTEM.EXE (No File)
BootExecute: autocheck autochk * sdnclean64.exe
GroupPolicy: Restriction - Chrome <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254
Tcpip\..\Interfaces\{8a96babe-cb5d-48b4-ad72-832762343bf2}: [DhcpNameServer] 40.54.1.18
Tcpip\..\Interfaces\{9db2bf17-d35c-4524-a632-3c674da021de}: [DhcpNameServer] 192.168.1.254
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page =
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-246760859-398526146-1931071061-1001\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_60\bin\ssv.dll [2015-08-28] (Oracle Corporation)
BHO: McAfee SafeKey Vault -> {9DB059B3-DD36-4a55-846C-59BE42A1202A} -> C:\Program Files (x86)\SafeKey\LPToolbar_x64.dll [2015-12-09] (McAfee)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-10-12] (Microsoft Corporation)
BHO: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll [2015-08-25] (Logitech, Inc.)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_60\bin\jp2ssv.dll [2015-08-28] (Oracle Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_51\bin\ssv.dll [2015-08-01] (Oracle Corporation)
BHO-x32: McAfee SafeKey Vault -> {9DB059B3-DD36-4a55-846C-59BE42A1202A} -> C:\Program Files (x86)\SafeKey\LPToolbar.dll [2015-12-09] (McAfee)
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-10-12] (Microsoft Corporation)
BHO-x32: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll [2015-08-25] (Logitech, Inc.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_51\bin\jp2ssv.dll [2015-08-01] (Oracle Corporation)
Toolbar: HKLM - McAfee SafeKey - {61D700C1-7D8D-43c5-9C13-4FF85157CFE6} - C:\Program Files (x86)\SafeKey\LPToolbar_x64.dll [2015-12-09] (McAfee)
Toolbar: HKLM-x32 - McAfee SafeKey - {61D700C1-7D8D-43c5-9C13-4FF85157CFE6} - C:\Program Files (x86)\SafeKey\LPToolbar.dll [2015-12-09] (McAfee)
DPF: HKLM-x32 {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\mcieplg.dll [2015-12-02] (McAfee, Inc.)
Handler-x32: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\mcieplg.dll [2015-12-02] (McAfee, Inc.)
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\mcieplg.dll [2015-12-02] (McAfee, Inc.)
Handler-x32: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\mcieplg.dll [2015-12-02] (McAfee, Inc.)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-10-12] (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-10-12] (Microsoft Corporation)
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\McAfee\MSC\McSnIePl64.dll [2015-09-28] (McAfee, Inc.)
Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\MSC\McSnIePl.dll [2015-09-28] (McAfee, Inc.)
FireFox:
========
FF ProfilePath: C:\Users\John\AppData\Roaming\Mozilla\Firefox\Profiles\3ER5j3l5.default
FF DefaultSearchEngine.US: DuckDuckGo
FF Plugin: @java.com/DTPlugin,version=11.60.2 -> C:\Program Files\Java\jre1.8.0_60\bin\dtplugin\npDeployJava1.dll [2015-08-28] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.60.2 -> C:\Program Files\Java\jre1.8.0_60\bin\plugin2\npjp2.dll [2015-08-28] (Oracle Corporation)
FF Plugin: @mcafee.com/MSC,version=10 -> c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL [2015-09-28] ()
FF Plugin: @videolan.org/vlc,version=2.2.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-16] (VideoLAN)
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\WINDOWS\SysWOW64\Adobe\Director\np32dsw_1220162.dll [2015-08-31] (Adobe Systems, Inc.)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2015-10-08] ()
FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.xdp -> C:\Program Files (x86)\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [No File]
FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.xfdf -> C:\Program Files (x86)\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [No File]
FF Plugin-x32: @java.com/DTPlugin,version=11.51.2 -> C:\Program Files (x86)\Java\jre1.8.0_51\bin\dtplugin\npDeployJava1.dll [2015-08-01] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.51.2 -> C:\Program Files (x86)\Java\jre1.8.0_51\bin\plugin2\npjp2.dll [2015-08-01] (Oracle Corporation)
FF Plugin-x32: @mcafee.com/MSC,version=10 -> c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL [2015-09-28] ()
FF Plugin-x32: @mcafee.com/MVT -> C:\Program Files (x86)\McAfee\Supportability\MVT\NPMVTPlugin.dll [2015-11-09] (McAfee, Inc.)
FF Plugin-x32: @Motive.com/NpMotive,version=1.1 -> C:\Program Files (x86)\ATT\8.5.0.48\ma\bin\npMotive.dll [No File]
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-08] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-08] (Google Inc.)
FF Plugin HKU\S-1-5-21-246760859-398526146-1931071061-1001: @citrixonline.com/appdetectorplugin -> C:\Users\John\AppData\Local\Citrix\Plugins\104\npappdetector.dll [2014-11-20] (Citrix Online)
FF SearchPlugin: C:\Users\John\AppData\Roaming\Mozilla\Firefox\Profiles\3ER5j3l5.default\searchplugins\McSiteAdvisor.xml [2015-12-07]
FF Extension: McAfee WebAdvisor - C:\Program Files (x86)\McAfee\SiteAdvisor\saffplg.xpi [2015-11-23]
FF Extension: Avira Browser Safety - C:\Users\John\AppData\Roaming\Mozilla\Firefox\Profiles\3ER5j3l5.default\Extensions\abs@avira.com [2015-12-07] [not signed]
FF Extension: Ghostery - C:\Users\John\AppData\Roaming\Mozilla\Firefox\Profiles\3ER5j3l5.default\Extensions\firefox@ghostery.com.xpi [2015-12-07]
FF Extension: Privacy Badger - C:\Users\John\AppData\Roaming\Mozilla\Firefox\Profiles\3ER5j3l5.default\Extensions\jid1-MnnxcxisBPnSXQ@jetpack.xpi [2015-12-07]
FF Extension: McAfee SafeKey - C:\Users\John\AppData\Roaming\Mozilla\Firefox\Profiles\3ER5j3l5.default\Extensions\{072844D3-7DEE-45F6-A406-E87F76302E4B} [2015-12-09] [not signed]
FF Extension: Adblock Plus - C:\Users\John\AppData\Roaming\Mozilla\Firefox\Profiles\3ER5j3l5.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-12-07]
FF Extension: Motive Extension - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\mcciwbch@motive.com.xpi [2015-08-21] [not signed]
FF HKLM\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor\saffplg.xpi
FF HKLM-x32\...\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt
FF Extension: Logitech SetPoint - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt [2015-11-21] [not signed]
FF HKLM-x32\...\Firefox\Extensions: [{jid1-vS7biDmom8YxhA@jetpack}] - C:\Users\John\AppData\Roaming\Mozilla\Firefox\Profiles\3ER5j3l5.default\extensions\{jid1-vS7biDmom8YxhA@jetpack} => not found
FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor\saffplg.xpi
FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK
FF Extension: McAfee Anti-Spam Thunderbird Extension - C:\Program Files\McAfee\MSK [2015-11-23] [not signed]
Chrome:
=======
CHR DefaultSearchKeyword: Default -> d
CHR Profile: C:\Users\John\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-12-08]
CHR Extension: (McAfee SafeKey) - C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\Extensions\agbnjankikoaabjkmfbaceggjliabkbn [2015-12-09]
CHR Extension: (Google Docs) - C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-12-08]
CHR Extension: (Google Drive) - C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-12-08]
CHR Extension: (YouTube) - C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-12-08]
CHR Extension: (DuckDuckGo for Chrome) - C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\Extensions\bpphkkgodbfncbcpgopijlfakfgmclao [2015-12-08]
CHR Extension: (Adblock Plus) - C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2015-12-08]
CHR Extension: (Google Search) - C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-12-08]
CHR Extension: (Google Sheets) - C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-12-08]
CHR Extension: (SiteAdvisor) - C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2015-12-08]
CHR Extension: (Print this page with CleanPrint) - C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\Extensions\fklmmmdcofimkjmfjdnobmmgmefbapkf [2015-12-08]
CHR Extension: (Google Docs Offline) - C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-12-08]
CHR Extension: (History Eraser) - C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\Extensions\gjieilkfnnjoihjjonajndjldjoagffm [2015-12-08]
CHR Extension: (History Eraser App) - C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjolhjmdgbhebcdnfjhngobjggghoipa [2015-12-08]
CHR Extension: (Skype Click to Call) - C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2015-12-08]
CHR Extension: (Ghostery) - C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\Extensions\mlomiejdfkolichcflejclcbmpeaniij [2015-12-08]
CHR Extension: (Chrome Web Store Payments) - C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-12-08]
CHR Extension: (Click&Clean App) - C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\Extensions\pdabfienifkbhoihedcgeogidfmibmhp [2015-12-08]
CHR Extension: (Gmail) - C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-12-08]
CHR Extension: (Privacy Badger) - C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkehgijcmpdhfbdbbnkijodmdjhbjlgp [2015-12-08]
CHR HKLM\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - C:\Program Files (x86)\McAfee\SiteAdvisor\McChPlg.crx [2015-12-03]
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-246760859-398526146-1931071061-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [gdfjhiclilbjdpeejgcgebmmihkkofji] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [agbnjankikoaabjkmfbaceggjliabkbn] - C:\Program Files (x86)\SafeKey\lpchrome.crx [2015-12-09]
CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - C:\Program Files (x86)\McAfee\SiteAdvisor\McChPlg.crx [2015-12-03]
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [gdfjhiclilbjdpeejgcgebmmihkkofji] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2015-10-12]
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77104 2015-10-07] (Apple Inc.)
R2 Asus WebStorage Windows Service; C:\Program Files (x86)\ASUS\WebStorage\2.1.15.438\AsusWSWinService.exe [71168 2014-11-06] (ASUS Cloud Corporation) [File not signed]
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1433216 2015-10-12] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1773696 2015-10-12] (Microsoft Corporation)
R2 ETDService; C:\Program Files\Elantech\ETDService.exe [147688 2015-08-06] (ELAN Microelectronics Corp.)
R2 HomeNetSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [368584 2015-09-01] (McAfee, Inc.)
R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [330136 2015-10-11] (Intel Corporation)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\TXE Components\TCS\HeciServer.exe [733696 2013-07-01] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\TXE Components\TCS\SocketHeciServer.exe [822232 2013-07-01] (Intel(R) Corporation)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
R2 McAfee SiteAdvisor Service; C:\Program Files (x86)\McAfee\SiteAdvisor\McSACore.exe [157928 2015-12-02] (McAfee, Inc.)
R2 McAPExe; C:\Program Files\McAfee\MSC\McAPExe.exe [783120 2015-09-28] (McAfee, Inc.)
R2 mcbootdelaystartsvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [368584 2015-09-01] (McAfee, Inc.)
R2 mccspsvc; C:\Program Files\Common Files\McAfee\CSP\1.6.1180.0\McCSPServiceHost.exe [1694152 2015-09-01] (McAfee, Inc.)
R2 McMPFSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [368584 2015-09-01] (McAfee, Inc.)
R2 McNaiAnn; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [368584 2015-09-01] (McAfee, Inc.)
S3 McODS; C:\Program Files\McAfee\VirusScan\mcods.exe [639456 2015-08-11] (McAfee, Inc.)
R2 mcpltsvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [368584 2015-09-01] (McAfee, Inc.)
R2 McProxy; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [368584 2015-09-01] (McAfee, Inc.)
R3 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [232656 2015-07-31] (McAfee, Inc.)
R2 mfemms; C:\Program Files\Common Files\McAfee\SystemCore\\mfemms.exe [376264 2015-08-10] (McAfee, Inc.)
R3 mfevtp; C:\WINDOWS\system32\mfevtps.exe [254792 2015-07-31] (McAfee, Inc.)
R2 MSK80Service; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [368584 2015-09-01] (McAfee, Inc.)
R2 Samsung Network Fax Server; C:\Windows\system32\spool\drivers\x64\3\NetFaxServer64.exe [801472 2015-03-10] (Samsung Electronics Co., Ltd.)
S2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1750712 2015-06-16] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2102496 2015-06-16] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [224712 2015-07-24] (Safer-Networking Ltd.)
R2 wampstackApache; C:\Wamp\apache2\bin\httpd.exe [22528 2015-07-12] (Apache Software Foundation) [File not signed]
R2 wampstackMySQL; C:\Wamp\mysql\bin\mysqld.exe [11053568 2015-07-14] () [File not signed]
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [362928 2015-07-10] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-07-10] (Microsoft Corporation)
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 athr; C:\Windows\System32\drivers\athw10x.sys [4325544 2015-06-26] (Qualcomm Atheros Communications, Inc.)
R3 ATP; C:\Windows\System32\drivers\AsusTP.sys [100776 2015-07-28] (ASUS Corporation)
R3 cfwids; C:\Windows\System32\drivers\cfwids.sys [80768 2015-08-10] (McAfee, Inc.)
S3 HipShieldK; C:\Windows\System32\drivers\HipShieldK.sys [207208 2015-05-19] (McAfee, Inc.)
R3 kbfiltr; C:\Windows\System32\drivers\kbfiltr.sys [17280 2012-08-05] ( )
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2015-10-05] (Malwarebytes)
S3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2015-10-05] (Malwarebytes Corporation)
R0 MBI; C:\Windows\System32\drivers\MBI.sys [29464 2013-10-27] (Intel Corporation)
R3 mfeaack; C:\Windows\System32\drivers\mfeaack.sys [413432 2015-08-10] (McAfee, Inc.)
R3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [349096 2015-08-10] (McAfee, Inc.)
S0 mfeelamk; C:\Windows\System32\drivers\mfeelamk.sys [82072 2015-08-10] (McAfee, Inc.)
R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [495856 2015-08-10] (McAfee, Inc.)
R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [839376 2015-08-10] (McAfee, Inc.)
R3 mfencbdc; C:\Windows\system32\DRIVERS\mfencbdc.sys [537408 2015-08-12] (McAfee, Inc.)
S3 mfencrk; C:\Windows\system32\DRIVERS\mfencrk.sys [111256 2015-08-12] (McAfee, Inc.)
R3 mfesapsn; C:\Program Files (x86)\McAfee\SiteAdvisor\x64\mfesapsn.sys [37960 2015-12-02] (McAfee, Inc.)
R0 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [244024 2015-08-10] (McAfee, Inc.)
R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [895256 2015-07-07] (Realtek )
R3 TXEIx64; C:\Windows\System32\drivers\TXEIx64.sys [88592 2014-01-15] (Intel Corporation)
S3 UdeCx; C:\Windows\System32\drivers\udecx.sys [44032 2015-07-10] ()
U5 vrvd5; C:\Windows\System32\Drivers\vrvd5.sys [13344 2015-05-08] (Rsupport Corporation)
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44568 2015-07-10] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [291680 2015-07-10] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [119648 2015-07-10] (Microsoft Corporation)
U3 aswMBR; C:\Users\John\AppData\Local\Temp\aswMBR.sys [62728 2015-12-09] () [File not signed]
U3 aswVmm; C:\Users\John\AppData\Local\Temp\aswVmm.sys [224896 2015-12-09] ()
S3 MREMP50; \??\C:\PROGRA~2\COMMON~1\Motive\MREMP50.SYS [X]
S3 MREMP50a64; \??\C:\PROGRA~1\COMMON~1\Motive\MREMP50a64.SYS [X]
S3 MREMPR5; \??\C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS [X]
S3 MRENDIS5; \??\C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS [X]
S3 MRESP50; \??\C:\PROGRA~2\COMMON~1\Motive\MRESP50.SYS [X]
S3 MRESP50a64; \??\C:\PROGRA~1\COMMON~1\Motive\MRESP50a64.SYS [X]
S3 wfpcapture; \SystemRoot\System32\drivers\wfpcapture.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-12-09 20:01 - 2015-12-09 20:01 - 00000080 _____ C:\Users\Public\Desktop\McAfee LiveSafe - Internet Security.lnk
2015-12-09 19:43 - 2015-12-09 19:43 - 00016148 _____ C:\WINDOWS\system32\JOHN_John_HistoryPrediction.bin
2015-12-09 17:13 - 2015-12-09 21:04 - 00000000 ____D C:\Users\John\Desktop\Removal
2015-12-09 17:04 - 2015-12-09 21:06 - 00031106 _____ C:\Users\John\Desktop\FRST.txt
2015-12-09 17:04 - 2015-12-09 21:05 - 00000000 ____D C:\FRST
2015-12-09 16:57 - 2015-12-09 17:15 - 05198336 _____ (AVAST Software) C:\Users\John\Desktop\aswMBR.exe
2015-12-09 16:56 - 2015-12-09 17:04 - 02369024 _____ (Farbar) C:\Users\John\Desktop\FRST64.exe
2015-12-09 16:46 - 2015-12-09 19:01 - 01599336 _____ (Malwarebytes) C:\Users\John\Desktop\JRT.exe
2015-12-09 16:04 - 2015-12-09 16:39 - 00000000 ____D C:\Users\John\AppData\LocalLow\SafeKey
2015-12-09 16:04 - 2015-12-09 16:14 - 00000000 ____D C:\Program Files (x86)\SafeKey
2015-12-08 20:44 - 2015-12-08 20:44 - 02870984 _____ (ESET) C:\Users\John\Downloads\esetsmartinstaller_enu.exe
2015-12-08 19:32 - 2015-12-09 20:01 - 00002328 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-12-08 19:32 - 2015-12-08 19:32 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-12-08 19:30 - 2015-12-09 20:35 - 00000904 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2015-12-08 19:30 - 2015-12-09 19:35 - 00000900 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2015-12-08 19:30 - 2015-12-08 19:30 - 00927824 _____ (Google Inc.) C:\Users\John\Downloads\ChromeSetup.exe
2015-12-08 19:30 - 2015-12-08 19:30 - 00003962 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2015-12-08 19:30 - 2015-12-08 19:30 - 00003730 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2015-12-07 20:30 - 2015-12-07 20:30 - 00000000 ____D C:\Users\John\New folder
2015-12-07 19:38 - 2015-12-07 20:03 - 00000000 ____D C:\Users\John\AppData\Local\Mozilla
2015-12-03 10:09 - 2015-12-03 10:09 - 38390188 _____ C:\Users\John\Downloads\Samsung M2070 Manual.pdf
2015-12-03 09:57 - 2015-12-03 09:57 - 24708972 _____ C:\Users\John\Downloads\M2070_V3.00.01.22.zip
2015-12-03 09:56 - 2015-12-03 10:11 - 10642432 _____ (Samsung Electronics Co., Ltd.) C:\Users\John\Downloads\PCFax_V1.11.28.exe
2015-12-02 15:30 - 2015-12-02 15:31 - 00000000 ____D C:\Users\John\AppData\Local\Foxit PhantomPDF
2015-12-02 12:33 - 2015-12-02 12:33 - 00000000 ____D C:\Users\John\Downloads\ideaChef
2015-12-02 12:28 - 2015-12-02 12:43 - 00000000 ____D C:\Users\John\Downloads\PDE_2_Proposals
2015-12-02 10:58 - 2015-11-16 12:32 - 00919040 _____ (Farbar) C:\WINDOWS\mod_frst.exe
2015-11-29 23:34 - 2015-11-29 23:34 - 00282624 _____ C:\Users\John\Downloads\appnhost.msi
2015-11-27 21:25 - 2015-12-08 19:25 - 00000000 ____D C:\Users\John\AppData\Roaming\Foxit Software
2015-11-27 21:18 - 2015-12-02 14:57 - 00000000 ____D C:\Users\John\Desktop\Holiday Images
2015-11-25 20:46 - 2015-12-09 17:00 - 318353758 _____ C:\Users\John\Desktop\AllMyNotes.ddb
2015-11-25 20:18 - 2015-12-09 20:01 - 00001187 _____ C:\Users\Public\Desktop\LibreOffice 5.0.lnk
2015-11-25 20:18 - 2015-11-25 20:18 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LibreOffice 5.0
2015-11-25 20:15 - 2015-11-25 20:18 - 00000000 ____D C:\Program Files\LibreOffice 5
2015-11-25 14:44 - 2015-11-25 14:44 - 00000000 _____ C:\WINDOWS\system32\SBRC.dat
2015-11-25 14:04 - 2015-11-25 19:53 - 00000000 ____D C:\ProgramData\STOPzilla!
2015-11-25 14:04 - 2015-11-25 14:04 - 00000000 ____D C:\Program Files (x86)\iS3
2015-11-25 13:41 - 2015-11-25 13:41 - 00000258 __RSH C:\ProgramData\ntuser.pol
2015-11-25 13:18 - 2015-11-23 20:37 - 00001431 _____ C:\WINDOWS\system32\Drivers\etc\hosts.20151125-131803.backup
2015-11-23 22:27 - 2015-11-23 22:27 - 00001951 _____ C:\Users\Public\Desktop\McAfee LiveSafe – Internet Security.lnk
2015-11-23 22:26 - 2015-05-19 13:59 - 00207208 _____ (McAfee, Inc.) C:\WINDOWS\system32\Drivers\HipShieldK.sys
2015-11-23 22:25 - 2015-11-23 22:25 - 00003138 _____ C:\WINDOWS\System32\Tasks\McAfeeLogon
2015-11-23 22:25 - 2015-11-23 22:25 - 00000000 ____D C:\WINDOWS\System32\Tasks\McAfee
2015-11-23 22:25 - 2015-11-23 22:25 - 00000000 ____D C:\Program Files (x86)\McAfee.com
2015-11-23 22:23 - 2015-11-23 22:23 - 00000000 ____D C:\Program Files\McAfee.com
2015-11-23 22:22 - 2015-12-08 20:38 - 00000000 ____D C:\Program Files (x86)\McAfee
2015-11-23 22:22 - 2015-11-23 22:26 - 00000000 ____D C:\Program Files\McAfee
2015-11-23 22:22 - 2015-11-23 22:22 - 00000000 ____D C:\Program Files\Common Files\AV
2015-11-23 22:18 - 2015-11-24 19:22 - 00000000 ____D C:\ProgramData\McAfee
2015-11-23 22:18 - 2015-11-23 22:25 - 00000000 ____D C:\Program Files\Common Files\McAfee
2015-11-23 22:18 - 2015-07-31 12:33 - 00254792 _____ (McAfee, Inc.) C:\WINDOWS\system32\mfevtps.exe
2015-11-23 21:58 - 2015-11-24 19:48 - 00000000 ____D C:\Users\John\AppData\Local\LogMeIn Rescue Applet
2015-11-23 20:48 - 2015-11-23 20:48 - 00003298 _____ C:\WINDOWS\System32\Tasks\{76248857-E513-4734-B019-700E5104411D}
2015-11-23 20:24 - 2015-11-23 20:24 - 00000248 _____ C:\rescue.info
2015-11-22 22:25 - 2015-11-22 22:25 - 00047504 _____ C:\Users\John\Desktop\2015_11_22_Comments on IdeaChef sent to Rui.pdf
2015-11-21 21:44 - 2015-11-21 21:44 - 00000000 ____D C:\Program Files\Logitech
2015-11-21 21:00 - 2015-11-04 23:13 - 00577888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\afd.sys
2015-11-21 21:00 - 2015-11-04 22:20 - 21873664 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2015-11-21 21:00 - 2015-11-04 22:18 - 24597504 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2015-11-21 21:00 - 2015-11-04 21:47 - 19326464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2015-11-21 20:59 - 2015-11-04 23:15 - 00541024 _____ (Microsoft Corporation) C:\WINDOWS\system32\mcupdate_GenuineIntel.dll
2015-11-21 20:59 - 2015-11-04 22:56 - 01083072 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2015-11-21 20:59 - 2015-11-04 22:56 - 00025280 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe
2015-11-21 20:59 - 2015-11-04 22:18 - 03248128 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2015-11-21 20:59 - 2015-11-04 21:59 - 02675200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepository.dll
2015-11-21 20:59 - 2015-11-04 21:54 - 00502272 _____ (Microsoft Corporation) C:\WINDOWS\system32\dlnashext.dll
2015-11-21 20:59 - 2015-11-04 21:35 - 18803712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2015-11-21 20:59 - 2015-11-04 21:28 - 11262976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2015-11-21 20:59 - 2015-11-04 21:27 - 02049536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepository.dll
2015-11-21 20:59 - 2015-11-04 21:23 - 00441344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dlnashext.dll
2015-11-21 20:58 - 2015-11-04 23:15 - 08020832 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2015-11-21 20:58 - 2015-11-04 23:14 - 00459104 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\netio.sys
2015-11-21 20:58 - 2015-11-04 23:11 - 01392480 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll
2015-11-21 20:58 - 2015-11-04 22:56 - 00116064 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tdx.sys
2015-11-21 20:58 - 2015-11-04 22:24 - 02878512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2015-11-21 20:58 - 2015-11-04 22:17 - 02418688 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
2015-11-21 20:58 - 2015-11-04 21:42 - 02647040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
2015-11-21 20:58 - 2015-11-04 21:40 - 01918976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
2015-11-21 20:57 - 2015-11-04 23:06 - 03621248 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2015-11-21 20:57 - 2015-11-04 22:12 - 00515072 _____ (Microsoft Corporation) C:\WINDOWS\system32\internetmail.dll
2015-11-21 20:57 - 2015-11-04 21:59 - 03587072 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2015-11-21 20:57 - 2015-11-04 21:55 - 00145408 _____ (Microsoft Corporation) C:\WINDOWS\system32\dssvc.dll
2015-11-21 20:57 - 2015-11-04 21:35 - 02639872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\esent.dll
2015-11-21 20:56 - 2015-11-04 22:30 - 00961376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll
2015-11-21 20:56 - 2015-11-04 22:23 - 00076800 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll
2015-11-21 20:56 - 2015-11-04 22:10 - 12504064 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2015-11-21 20:56 - 2015-11-04 22:10 - 02987520 _____ (Microsoft Corporation) C:\WINDOWS\system32\esent.dll
2015-11-21 20:56 - 2015-11-04 22:07 - 01068032 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2015-11-21 20:56 - 2015-11-04 22:06 - 00453120 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Usb.dll
2015-11-21 20:56 - 2015-11-04 22:03 - 02180608 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2015-11-21 20:56 - 2015-11-04 22:03 - 01015808 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXService.dll
2015-11-21 20:56 - 2015-11-04 22:01 - 00713216 _____ (Microsoft Corporation) C:\WINDOWS\system32\usermgr.dll
2015-11-21 20:56 - 2015-11-04 21:56 - 01795072 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll
2015-11-21 20:55 - 2015-11-04 22:05 - 01602560 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2015-11-21 20:55 - 2015-11-04 22:01 - 00579072 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
2015-11-21 20:55 - 2015-11-04 21:58 - 01383936 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2015-11-21 20:55 - 2015-11-04 21:58 - 00627712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.dll
2015-11-21 20:55 - 2015-11-04 21:34 - 00311296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Usb.dll
2015-11-21 20:55 - 2015-11-04 21:33 - 01380864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2015-11-21 20:55 - 2015-11-04 21:30 - 00767488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2015-11-21 20:55 - 2015-11-04 21:27 - 00464896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.dll
2015-11-21 20:54 - 2015-11-04 23:06 - 00966416 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll
2015-11-21 20:54 - 2015-11-04 22:23 - 00762888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.appcore.dll
2015-11-21 20:54 - 2015-11-04 22:11 - 00333312 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2015-11-21 20:54 - 2015-11-04 22:05 - 00826880 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2015-11-21 20:53 - 2015-11-04 23:01 - 00607408 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2015-11-21 20:53 - 2015-11-04 22:18 - 00539728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2015-11-21 20:53 - 2015-11-04 22:01 - 00949760 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2015-11-21 20:53 - 2015-11-04 21:33 - 00650240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2015-11-21 18:23 - 2015-11-21 18:23 - 00000144 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2015-11-21 18:17 - 2015-11-23 20:50 - 00000000 ____D C:\Users\Administrator.john.016
2015-11-21 18:11 - 2015-11-23 20:50 - 00000000 ____D C:\Users\Administrator.john.015
2015-11-21 18:11 - 2015-11-23 20:50 - 00000000 ____D C:\Users\Administrator.john.014
2015-11-21 18:11 - 2015-11-21 18:11 - 00000000 ____D C:\Users\Default\AppData\Roaming\Macromedia
2015-11-21 18:11 - 2015-11-21 18:11 - 00000000 ____D C:\Users\Default\AppData\Roaming\Adobe
2015-11-21 18:11 - 2015-11-21 18:11 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Macromedia
2015-11-21 18:11 - 2015-11-21 18:11 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Adobe
2015-11-21 18:00 - 2015-11-23 20:50 - 00000000 ____D C:\Users\TEMP.john
2015-11-21 18:00 - 2015-11-23 20:50 - 00000000 ____D C:\Users\Administrator.john.012
2015-11-21 18:00 - 2015-11-21 18:00 - 00000000 ____D C:\Users\Administrator.john.013
2015-11-16 13:56 - 2015-11-23 20:50 - 00000000 ____D C:\Users\Administrator.john.011
2015-11-16 12:38 - 2015-11-23 20:50 - 00000000 ____D C:\Users\Administrator.john.010
2015-11-16 12:09 - 2015-11-23 20:50 - 00000000 ____D C:\Users\TEMP
2015-11-16 12:09 - 2015-11-23 20:50 - 00000000 ____D C:\Users\Administrator.john.009
2015-11-16 12:08 - 2015-11-23 20:50 - 00000000 ____D C:\Users\Administrator.john.008
2015-11-16 11:53 - 2015-12-09 18:57 - 00000000 ____D C:\Users\Administrator.john.007
2015-11-16 11:41 - 2015-11-23 20:50 - 00000000 ____D C:\Users\Administrator.john.005
2015-11-16 11:41 - 2015-11-16 11:41 - 00000000 ____D C:\Users\Administrator.john.006
2015-11-16 11:31 - 2015-11-23 20:50 - 00000000 ____D C:\Users\Administrator.john.004
2015-11-16 11:19 - 2015-11-23 20:50 - 00000000 ____D C:\Users\Administrator.john.003
2015-11-16 11:17 - 2015-11-16 11:17 - 00012920 ____N C:\bootsqm.dat
2015-11-16 11:17 - 2015-11-16 11:17 - 00000000 __SHD C:\found.000
2015-11-13 22:39 - 2015-11-16 13:14 - 00057344 _____ C:\WINDOWS\system32\config\sam.lbk
2015-11-13 21:39 - 2015-11-23 20:50 - 00000000 ____D C:\Users\Administrator.john.002
2015-11-13 21:27 - 2015-11-23 20:50 - 00000000 ____D C:\Users\Administrator.john.001
2015-11-13 20:59 - 2015-11-23 20:50 - 00000000 ____D C:\Users\Administrator.john.000
2015-11-13 20:59 - 2015-11-23 20:50 - 00000000 ____D C:\Users\Administrator.john
2015-11-13 20:41 - 2015-11-21 18:11 - 00000000 __SHD C:\Users\Administrator\IntelGraphicsProfiles
2015-11-13 20:40 - 2015-11-23 20:50 - 00000000 ____D C:\Users\Administrator
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-12-09 20:49 - 2014-11-20 11:55 - 00000566 _____ C:\WINDOWS\Tasks\G2MUpdateTask-S-1-5-21-246760859-398526146-1931071061-1001.job
2015-12-09 20:19 - 2015-07-10 05:04 - 00000000 ____D C:\WINDOWS\AppReadiness
2015-12-09 20:07 - 2015-06-08 16:42 - 00000662 _____ C:\WINDOWS\Tasks\G2MUploadTask-S-1-5-21-246760859-398526146-1931071061-1001.job
2015-12-09 20:02 - 2015-11-04 16:33 - 00001078 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ownCloud.lnk
2015-12-09 20:02 - 2015-10-01 19:43 - 00001450 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk
2015-12-09 20:02 - 2015-07-30 12:20 - 00002367 _____ C:\Users\John\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2015-12-09 20:02 - 2015-07-30 11:38 - 00001540 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2015-12-09 20:02 - 2015-06-29 10:30 - 00000906 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UltraDefrag.lnk
2015-12-09 20:02 - 2015-06-29 09:53 - 00002523 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
2015-12-09 20:02 - 2015-06-29 09:53 - 00002477 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Serif DrawPlus X6.lnk
2015-12-09 20:02 - 2015-06-29 09:37 - 00002467 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Serif WebPlus X7.lnk
2015-12-09 20:01 - 2015-11-04 16:33 - 00001072 _____ C:\Users\Public\Desktop\ownCloud.lnk
2015-12-09 20:01 - 2015-11-04 11:36 - 00001778 _____ C:\Users\Public\Desktop\iTunes.lnk
2015-12-09 20:01 - 2015-10-28 15:53 - 00001167 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-12-09 20:01 - 2015-10-22 17:34 - 00002634 _____ C:\Users\Public\Desktop\Skype.lnk
2015-12-09 20:01 - 2015-10-21 17:10 - 00001346 _____ C:\Users\Public\Desktop\WebStorage.lnk
2015-12-09 20:01 - 2015-10-07 09:18 - 00000506 _____ C:\Users\John\Desktop\Notepad_F.lnk
2015-12-09 20:01 - 2015-10-01 19:43 - 00001444 _____ C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
2015-12-09 20:01 - 2015-10-01 19:38 - 00001162 _____ C:\Users\Public\Desktop\Spybot Anti-Beacon.lnk
2015-12-09 20:01 - 2015-09-17 17:02 - 00002064 _____ C:\Users\Public\Desktop\NetBeans IDE 8.0.2.lnk
2015-12-09 20:01 - 2015-08-26 12:04 - 00000916 _____ C:\Users\Public\Desktop\VLC media player.lnk
2015-12-09 20:01 - 2015-08-12 09:03 - 00002168 _____ C:\Users\John\Desktop\AllMyNotes Organizer.lnk
2015-12-09 20:01 - 2015-08-03 18:29 - 00001160 _____ C:\Users\John\Desktop\MEGAsync.lnk
2015-12-09 20:01 - 2015-07-29 11:10 - 00002008 _____ C:\Users\Public\Desktop\FileZilla Client.lnk
2015-12-09 20:01 - 2015-07-23 08:24 - 00001087 _____ C:\Users\Public\Desktop\SpywareBlaster.lnk
2015-12-09 20:01 - 2015-06-29 10:30 - 00000900 _____ C:\Users\Public\Desktop\UltraDefrag.lnk
2015-12-09 20:01 - 2014-11-14 19:22 - 00000863 _____ C:\Users\Public\Desktop\CCleaner.lnk
2015-12-09 19:09 - 2015-10-28 15:53 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-12-09 19:03 - 2015-07-10 03:05 - 00000000 ____D C:\Windows
2015-12-09 17:55 - 2015-07-10 05:04 - 00000000 ____D C:\WINDOWS\rescache
2015-12-09 17:31 - 2015-07-10 05:04 - 00000000 ___HD C:\Program Files\WindowsApps
2015-12-09 16:04 - 2015-10-14 15:03 - 00000000 ____D C:\Users\John\Downloads\Stuff to Install
2015-12-09 16:03 - 2015-10-22 17:34 - 00000000 ____D C:\Users\John\AppData\Roaming\Skype
2015-12-09 14:48 - 2015-07-10 04:55 - 00000000 ____D C:\WINDOWS\CbsTemp
2015-12-09 12:00 - 2015-05-13 16:10 - 00003544 _____ C:\WINDOWS\System32\Tasks\ASUS Live Update1
2015-12-09 12:00 - 2015-05-13 16:10 - 00003534 _____ C:\WINDOWS\System32\Tasks\ASUS Live Update2
2015-12-08 20:47 - 2015-07-30 11:49 - 00875126 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2015-12-08 20:47 - 2015-07-10 05:02 - 00000000 ____D C:\WINDOWS\INF
2015-12-08 20:46 - 2014-10-25 20:18 - 00000000 ____D C:\Users\John\AppData\Roaming\WebStorage
2015-12-08 20:40 - 2015-10-21 17:37 - 00000000 ____D C:\ProgramData\ASUS Smart Gesture
2015-12-08 20:39 - 2015-07-30 12:05 - 00000000 __SHD C:\Users\John\IntelGraphicsProfiles
2015-12-08 20:39 - 2015-07-30 11:27 - 00000000 ____D C:\Users\John
2015-12-08 20:38 - 2015-07-10 06:21 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-12-08 20:34 - 2015-07-10 05:04 - 00000000 ____D C:\WINDOWS\LiveKernelReports
2015-12-08 19:32 - 2014-10-26 06:56 - 00000000 ____D C:\Users\John\AppData\Local\Google
2015-12-08 19:31 - 2014-10-26 06:56 - 00000000 ____D C:\Program Files (x86)\Google
2015-12-08 19:20 - 2015-08-21 19:48 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2015-12-07 20:09 - 2015-06-08 16:42 - 00003804 _____ C:\WINDOWS\System32\Tasks\G2MUploadTask-S-1-5-21-246760859-398526146-1931071061-1001
2015-12-07 20:09 - 2014-11-20 11:55 - 00003708 _____ C:\WINDOWS\System32\Tasks\G2MUpdateTask-S-1-5-21-246760859-398526146-1931071061-1001
2015-12-07 19:59 - 2014-10-31 14:06 - 00000000 ____D C:\WINDOWS\system32\MRT
2015-12-07 19:49 - 2014-10-31 14:06 - 145617392 ____N (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2015-12-07 19:42 - 2015-07-10 03:05 - 00032768 ___SH C:\WINDOWS\system32\config\ELAM
2015-12-07 19:38 - 2014-10-28 09:28 - 00000000 ____D C:\Users\John\AppData\Roaming\Mozilla
2015-12-03 15:27 - 2015-10-15 10:15 - 00000000 ____D C:\ProgramData\boost_interprocess
2015-12-02 12:32 - 2015-07-17 19:48 - 00000000 ____D C:\Users\John\Downloads\AllMyNotes
2015-11-30 18:32 - 2015-07-10 05:06 - 00826872 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2015-11-30 18:32 - 2015-07-10 05:06 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2015-11-27 03:36 - 2015-07-10 06:20 - 00428592 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2015-11-27 03:35 - 2015-07-10 03:05 - 00262144 ___SH C:\WINDOWS\system32\config\BBI
2015-11-27 03:31 - 2015-07-10 05:04 - 00000000 ____D C:\WINDOWS\system32\appraiser
2015-11-25 20:03 - 2015-08-03 19:30 - 00000000 ____D C:\ProgramData\Package Cache
2015-11-25 13:51 - 2014-10-26 06:54 - 00000000 __SHD C:\Users\John\AppData\Local\EmieUserList
2015-11-25 13:51 - 2014-10-26 06:54 - 00000000 __SHD C:\Users\John\AppData\Local\EmieSiteList
2015-11-25 13:48 - 2015-10-28 15:27 - 00000000 ____D C:\AdwCleaner
2015-11-25 13:42 - 2014-11-19 19:29 - 00000000 ____D C:\ProgramData\TEMP
2015-11-25 13:41 - 2015-07-23 08:24 - 00000000 ____D C:\Program Files (x86)\SpywareBlaster
2015-11-25 13:35 - 2014-10-25 20:12 - 00000000 ____D C:\Users\John\AppData\Local\Packages
2015-11-25 13:33 - 2015-07-10 05:04 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2015-11-25 13:15 - 2014-11-01 10:14 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2015-11-24 19:22 - 2015-01-18 21:01 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
2015-11-23 22:36 - 2014-11-17 20:00 - 00000000 ____D C:\Users\John\AppData\Roaming\Samsung
2015-11-23 22:24 - 2015-07-10 05:04 - 00000000 ___HD C:\WINDOWS\ELAMBKUP
2015-11-23 20:50 - 2013-08-22 07:36 - 00000000 ____D C:\Users\Default.migrated
2015-11-21 21:55 - 2014-10-25 20:17 - 00000000 __RDO C:\Users\John\OneDrive
2015-11-21 21:45 - 2014-11-20 09:40 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logitech
2015-11-21 21:45 - 2014-11-20 09:40 - 00000000 ____D C:\Program Files\Common Files\LogiShrd
2015-11-21 21:44 - 2014-11-20 09:40 - 00000000 ____D C:\ProgramData\LogiShrd
2015-11-13 20:41 - 2014-10-26 10:48 - 00000000 __RHD C:\Users\Public\AccountPictures
==================== Files in the root of some directories =======
2014-12-03 16:46 - 2015-12-09 16:14 - 32372200 _____ (McAfee) C:\Program Files (x86)\Common Files\lpuninstall.exe
2015-01-31 16:09 - 2015-01-31 16:09 - 0001279 _____ () C:\Users\John\AppData\Local\recently-used.xbel
2015-08-27 08:17 - 2015-08-27 08:17 - 0007605 _____ () C:\Users\John\AppData\Local\Resmon.ResmonCfg
2015-07-30 11:21 - 2015-07-30 11:21 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
2014-04-18 16:51 - 2012-09-07 05:40 - 0000256 _____ () C:\ProgramData\SetStretch.cmd
Some files in TEMP:
====================
C:\Users\John\AppData\Local\Temp\FoxitUpdater.exe
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-12-09 14:22
==================== End of FRST.txt ============================
Thanks
John :cool:
aka TechnoDino
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:09-12-2015
Ran by John (administrator) on JOHN (09-12-2015 21:05:25)
Running from C:\Users\John\Desktop
Loaded Profiles: John (Available Profiles: John)
Platform: Windows 10 Home (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
(ASUS Cloud Corporation) C:\Program Files (x86)\ASUS\WebStorage\2.1.15.438\AsusWSWinService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe
(Intel(R) Corporation) C:\Program Files\Intel\TXE Components\TCS\HeciServer.exe
(McAfee, Inc.) C:\Program Files (x86)\McAfee\SiteAdvisor\mcsacore.exe
(McAfee, Inc.) C:\Windows\System32\mfevtps.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe
(Samsung Electronics Co., Ltd.) C:\Windows\System32\spool\drivers\x64\3\NetFaxServer64.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
(McAfee, Inc.) C:\Program Files\McAfee\MSC\McAPExe.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
() C:\Wamp\mysql\bin\mysqld.exe
(Apache Software Foundation) C:\Wamp\apache2\bin\httpd.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
(McAfee, Inc.) C:\Windows\System32\mfevtps.exe
(Apache Software Foundation) C:\Wamp\apache2\bin\httpd.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\CSP\1.6.1180.0\McCSPServiceHost.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
() C:\Program Files\WindowsApps\Microsoft.Windows.Photos_15.1208.10480.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\Platform\McUICnt.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [CDAServer] => C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe [464608 2014-09-08] ()
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [3350760 2015-08-06] (ELAN Microelectronics Corp.)
HKLM\...\Run: [LogiOptionsAppBroker] => C:\Program Files\Logitech\LogiOptions\LogiOptions.exe /noui
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [170256 2015-10-16] (Apple Inc.)
HKLM\...\Run: [EvtMgr6] => C:\Program Files\Logitech\SetPointP\SetPoint.exe [3113592 2015-08-25] (Logitech, Inc.)
HKLM-x32\...\Run: [ASUSPRP] => C:\Program Files (x86)\ASUS\APRP\APRP.EXE [1080992 2014-04-18] (ASUSTek Computer Inc.)
HKLM-x32\...\Run: [WebStorage] => C:\Program Files (x86)\ASUS\WebStorage\2.2.4.537\ASUSWSLoader.exe [63272 2015-10-12] ()
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [60688 2015-10-13] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [597552 2015-08-04] (Oracle Corporation)
HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [4127488 2015-06-16] (Safer-Networking Ltd.)
HKLM-x32\...\Run: [ASUS Ai Charger] => C:\Program Files (x86)\ASUS\ASUS Ai Charger\AiChargerAP.exe [547984 2012-08-13] (ASUSTek Computer Inc.)
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
HKU\S-1-5-21-246760859-398526146-1931071061-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8591272 2015-11-16] (Piriform Ltd)
HKU\S-1-5-21-246760859-398526146-1931071061-1001\...\Run: [EEDSpeedLauncher] => rundll32.exe C:\Windows\system32\eed_ec.dll,SpeedLauncher
HKU\S-1-5-21-246760859-398526146-1931071061-1001\...\Run: [appnhost] => C:\Users\John\AppData\Local\Mixesoft\AppNHost\appnhost.exe [453176 2014-08-08] (Mixesoft Project)
HKU\S-1-5-21-246760859-398526146-1931071061-1001\...\Run: [SpybotPostWindows10UpgradeReInstall] => "C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe"
HKU\S-1-5-21-246760859-398526146-1931071061-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [48138880 2015-10-14] (Skype Technologies S.A.)
IFEO\apnmcp.exe: [Debugger] tasklist.exe
IFEO\AppIntegrator64.exe: [Debugger] tasklist.exe
IFEO\brs.exe: [Debugger] tasklist.exe
IFEO\bservice.exe: [Debugger] tasklist.exe
IFEO\bservice64.exe: [Debugger] tasklist.exe
IFEO\cltmng.exe: [Debugger] tasklist.exe
IFEO\cltmngui.exe: [Debugger] tasklist.exe
IFEO\DatamngrUI.exe: [Debugger] tasklist.exe
IFEO\dsrlte.exe: [Debugger] tasklist.exe
IFEO\DTUpdate.exe: [Debugger] tasklist.exe
IFEO\ExtensionUpdaterService.exe: [Debugger] tasklist.exe
IFEO\FrameworkEngine.exe: [Debugger] tasklist.exe
IFEO\HpUI.exe: [Debugger] tasklist.exe
IFEO\IdcLdr.exe: [Debugger] tasklist.exe
IFEO\IdcLdr_x64.exe: [Debugger] tasklist.exe
IFEO\IMGUpdater.exe: [Debugger] tasklist.exe
IFEO\keepmysettingsx.exe: [Debugger] tasklist.exe
IFEO\Loader32.exe: [Debugger] tasklist.exe
IFEO\Loader64.exe: [Debugger] tasklist.exe
IFEO\loggingserver.exe: [Debugger] tasklist.exe
IFEO\Lrcnta.exe: [Debugger] tasklist.exe
IFEO\PastaLeadsService.exe: [Debugger] tasklist.exe
IFEO\PastaLeadsWinApp.exe: [Debugger] tasklist.exe
IFEO\patch_ff.exe: [Debugger] tasklist.exe
IFEO\PluginService.exe: [Debugger] tasklist.exe
IFEO\ProtectWindowsManager.exe: [Debugger] tasklist.exe
IFEO\SafeFinder.exe: [Debugger] tasklist.exe
IFEO\searcharmor.exe: [Debugger] tasklist.exe
IFEO\search_protect.exe: [Debugger] tasklist.exe
IFEO\smu.exe: [Debugger] tasklist.exe
IFEO\spbiu.exe: [Debugger] tasklist.exe
IFEO\srptm.exe: [Debugger] tasklist.exe
IFEO\srpts.exe: [Debugger] tasklist.exe
IFEO\srptsl.exe: [Debugger] tasklist.exe
IFEO\SystemkService.exe: [Debugger] tasklist.exe
IFEO\SystemSockets.exe: [Debugger] tasklist.exe
IFEO\TBNotifier.exe: [Debugger] tasklist.exe
IFEO\TNT2User.exe: [Debugger] tasklist.exe
IFEO\Toolbar.exe: [Debugger] tasklist.exe
IFEO\ToolbarUpdater.exe: [Debugger] tasklist.exe
IFEO\vprot.exe: [Debugger] tasklist.exe
IFEO\wb.exe: [Debugger] tasklist.exe
IFEO\YTDownloader.exe: [Debugger] tasklist.exe
ShellIconOverlayIdentifiers: [!AsusWSShellExt_B] -> {6D4133E5-0742-4ADC-8A8C-9303440F7191} => C:\Program Files (x86)\Common Files\AWS\2.2.4.537\ASUSWSShellExt64.dll [2015-04-22] (ASUS Cloud Corporation.)
ShellIconOverlayIdentifiers: [!AsusWSShellExt_O] -> {64174815-8D98-4CE6-8646-4C039977D809} => C:\Program Files (x86)\Common Files\AWS\2.2.4.537\ASUSWSShellExt64.dll [2015-04-22] (ASUS Cloud Corporation.)
ShellIconOverlayIdentifiers: [!AsusWSShellExt_U] -> {1C5AB7B1-0B38-4EC4-9093-7FD277E2AF4E} => C:\Program Files (x86)\Common Files\AWS\2.2.4.537\ASUSWSShellExt64.dll [2015-04-22] (ASUS Cloud Corporation.)
ShellIconOverlayIdentifiers: [###MegaShellExtPending] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => No File
ShellIconOverlayIdentifiers: [###MegaShellExtSynced] -> {05B38830-F4E9-4329-978B-1DD28605D202} => No File
ShellIconOverlayIdentifiers: [###MegaShellExtSyncing] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => No File
ShellIconOverlayIdentifiers: [1MegaSync0Synced] -> {A52C9916-2007-4C7F-A2D7-0C9612427BD2} => C:\Users\John\AppData\Local\MEGAsync\bin\o\mssoverlay.dll [2013-09-12] (TODO: <Company name>)
ShellIconOverlayIdentifiers: [1MegaSync1Pended] -> {A34CE349-F239-4DA5-9551-4660962F6CD9} => C:\Users\John\AppData\Local\MEGAsync\bin\o\mspoverlay.dll [2013-09-12] (TODO: <Company name>)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Install SafeKey FF RunOnce.lnk [2015-12-09]
ShortcutTarget: Install SafeKey FF RunOnce.lnk -> C:\Program Files (x86)\Common Files\lpuninstall.exe (McAfee)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Install SafeKey IE RunOnce.lnk [2015-12-09]
ShortcutTarget: Install SafeKey IE RunOnce.lnk -> C:\Program Files (x86)\Common Files\lpuninstall.exe (McAfee)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Samsung Network PC Fax.lnk [2015-12-09]
ShortcutTarget: Samsung Network PC Fax.lnk -> C:\Windows\System32\spool\drivers\x64\3\NetFaxTray64.exe (Samsung Electronics Co., Ltd.)
Startup: C:\Users\John\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MEGAsync.lnk [2015-12-09]
ShortcutTarget: MEGAsync.lnk -> C:\Users\John\AppData\Local\MEGAsync\bin\MEGAsync.exe (Mega Limited)
Startup: C:\Users\John\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Send to OneNote.lnk [2015-12-09]
ShortcutTarget: Send to OneNote.lnk -> C:\Program Files\Microsoft Office 15\root\office15\ONENOTEM.EXE (No File)
BootExecute: autocheck autochk * sdnclean64.exe
GroupPolicy: Restriction - Chrome <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254
Tcpip\..\Interfaces\{8a96babe-cb5d-48b4-ad72-832762343bf2}: [DhcpNameServer] 40.54.1.18
Tcpip\..\Interfaces\{9db2bf17-d35c-4524-a632-3c674da021de}: [DhcpNameServer] 192.168.1.254
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page =
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-246760859-398526146-1931071061-1001\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_60\bin\ssv.dll [2015-08-28] (Oracle Corporation)
BHO: McAfee SafeKey Vault -> {9DB059B3-DD36-4a55-846C-59BE42A1202A} -> C:\Program Files (x86)\SafeKey\LPToolbar_x64.dll [2015-12-09] (McAfee)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-10-12] (Microsoft Corporation)
BHO: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll [2015-08-25] (Logitech, Inc.)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_60\bin\jp2ssv.dll [2015-08-28] (Oracle Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_51\bin\ssv.dll [2015-08-01] (Oracle Corporation)
BHO-x32: McAfee SafeKey Vault -> {9DB059B3-DD36-4a55-846C-59BE42A1202A} -> C:\Program Files (x86)\SafeKey\LPToolbar.dll [2015-12-09] (McAfee)
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-10-12] (Microsoft Corporation)
BHO-x32: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll [2015-08-25] (Logitech, Inc.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_51\bin\jp2ssv.dll [2015-08-01] (Oracle Corporation)
Toolbar: HKLM - McAfee SafeKey - {61D700C1-7D8D-43c5-9C13-4FF85157CFE6} - C:\Program Files (x86)\SafeKey\LPToolbar_x64.dll [2015-12-09] (McAfee)
Toolbar: HKLM-x32 - McAfee SafeKey - {61D700C1-7D8D-43c5-9C13-4FF85157CFE6} - C:\Program Files (x86)\SafeKey\LPToolbar.dll [2015-12-09] (McAfee)
DPF: HKLM-x32 {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\mcieplg.dll [2015-12-02] (McAfee, Inc.)
Handler-x32: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\mcieplg.dll [2015-12-02] (McAfee, Inc.)
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\mcieplg.dll [2015-12-02] (McAfee, Inc.)
Handler-x32: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\mcieplg.dll [2015-12-02] (McAfee, Inc.)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-10-12] (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-10-12] (Microsoft Corporation)
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\McAfee\MSC\McSnIePl64.dll [2015-09-28] (McAfee, Inc.)
Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\MSC\McSnIePl.dll [2015-09-28] (McAfee, Inc.)
FireFox:
========
FF ProfilePath: C:\Users\John\AppData\Roaming\Mozilla\Firefox\Profiles\3ER5j3l5.default
FF DefaultSearchEngine.US: DuckDuckGo
FF Plugin: @java.com/DTPlugin,version=11.60.2 -> C:\Program Files\Java\jre1.8.0_60\bin\dtplugin\npDeployJava1.dll [2015-08-28] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.60.2 -> C:\Program Files\Java\jre1.8.0_60\bin\plugin2\npjp2.dll [2015-08-28] (Oracle Corporation)
FF Plugin: @mcafee.com/MSC,version=10 -> c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL [2015-09-28] ()
FF Plugin: @videolan.org/vlc,version=2.2.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-16] (VideoLAN)
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\WINDOWS\SysWOW64\Adobe\Director\np32dsw_1220162.dll [2015-08-31] (Adobe Systems, Inc.)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2015-10-08] ()
FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.xdp -> C:\Program Files (x86)\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [No File]
FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.xfdf -> C:\Program Files (x86)\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [No File]
FF Plugin-x32: @java.com/DTPlugin,version=11.51.2 -> C:\Program Files (x86)\Java\jre1.8.0_51\bin\dtplugin\npDeployJava1.dll [2015-08-01] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.51.2 -> C:\Program Files (x86)\Java\jre1.8.0_51\bin\plugin2\npjp2.dll [2015-08-01] (Oracle Corporation)
FF Plugin-x32: @mcafee.com/MSC,version=10 -> c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL [2015-09-28] ()
FF Plugin-x32: @mcafee.com/MVT -> C:\Program Files (x86)\McAfee\Supportability\MVT\NPMVTPlugin.dll [2015-11-09] (McAfee, Inc.)
FF Plugin-x32: @Motive.com/NpMotive,version=1.1 -> C:\Program Files (x86)\ATT\8.5.0.48\ma\bin\npMotive.dll [No File]
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-08] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-08] (Google Inc.)
FF Plugin HKU\S-1-5-21-246760859-398526146-1931071061-1001: @citrixonline.com/appdetectorplugin -> C:\Users\John\AppData\Local\Citrix\Plugins\104\npappdetector.dll [2014-11-20] (Citrix Online)
FF SearchPlugin: C:\Users\John\AppData\Roaming\Mozilla\Firefox\Profiles\3ER5j3l5.default\searchplugins\McSiteAdvisor.xml [2015-12-07]
FF Extension: McAfee WebAdvisor - C:\Program Files (x86)\McAfee\SiteAdvisor\saffplg.xpi [2015-11-23]
FF Extension: Avira Browser Safety - C:\Users\John\AppData\Roaming\Mozilla\Firefox\Profiles\3ER5j3l5.default\Extensions\abs@avira.com [2015-12-07] [not signed]
FF Extension: Ghostery - C:\Users\John\AppData\Roaming\Mozilla\Firefox\Profiles\3ER5j3l5.default\Extensions\firefox@ghostery.com.xpi [2015-12-07]
FF Extension: Privacy Badger - C:\Users\John\AppData\Roaming\Mozilla\Firefox\Profiles\3ER5j3l5.default\Extensions\jid1-MnnxcxisBPnSXQ@jetpack.xpi [2015-12-07]
FF Extension: McAfee SafeKey - C:\Users\John\AppData\Roaming\Mozilla\Firefox\Profiles\3ER5j3l5.default\Extensions\{072844D3-7DEE-45F6-A406-E87F76302E4B} [2015-12-09] [not signed]
FF Extension: Adblock Plus - C:\Users\John\AppData\Roaming\Mozilla\Firefox\Profiles\3ER5j3l5.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-12-07]
FF Extension: Motive Extension - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\mcciwbch@motive.com.xpi [2015-08-21] [not signed]
FF HKLM\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor\saffplg.xpi
FF HKLM-x32\...\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt
FF Extension: Logitech SetPoint - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt [2015-11-21] [not signed]
FF HKLM-x32\...\Firefox\Extensions: [{jid1-vS7biDmom8YxhA@jetpack}] - C:\Users\John\AppData\Roaming\Mozilla\Firefox\Profiles\3ER5j3l5.default\extensions\{jid1-vS7biDmom8YxhA@jetpack} => not found
FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor\saffplg.xpi
FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK
FF Extension: McAfee Anti-Spam Thunderbird Extension - C:\Program Files\McAfee\MSK [2015-11-23] [not signed]
Chrome:
=======
CHR DefaultSearchKeyword: Default -> d
CHR Profile: C:\Users\John\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-12-08]
CHR Extension: (McAfee SafeKey) - C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\Extensions\agbnjankikoaabjkmfbaceggjliabkbn [2015-12-09]
CHR Extension: (Google Docs) - C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-12-08]
CHR Extension: (Google Drive) - C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-12-08]
CHR Extension: (YouTube) - C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-12-08]
CHR Extension: (DuckDuckGo for Chrome) - C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\Extensions\bpphkkgodbfncbcpgopijlfakfgmclao [2015-12-08]
CHR Extension: (Adblock Plus) - C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2015-12-08]
CHR Extension: (Google Search) - C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-12-08]
CHR Extension: (Google Sheets) - C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-12-08]
CHR Extension: (SiteAdvisor) - C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2015-12-08]
CHR Extension: (Print this page with CleanPrint) - C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\Extensions\fklmmmdcofimkjmfjdnobmmgmefbapkf [2015-12-08]
CHR Extension: (Google Docs Offline) - C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-12-08]
CHR Extension: (History Eraser) - C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\Extensions\gjieilkfnnjoihjjonajndjldjoagffm [2015-12-08]
CHR Extension: (History Eraser App) - C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\Extensions\jjolhjmdgbhebcdnfjhngobjggghoipa [2015-12-08]
CHR Extension: (Skype Click to Call) - C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2015-12-08]
CHR Extension: (Ghostery) - C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\Extensions\mlomiejdfkolichcflejclcbmpeaniij [2015-12-08]
CHR Extension: (Chrome Web Store Payments) - C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-12-08]
CHR Extension: (Click&Clean App) - C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\Extensions\pdabfienifkbhoihedcgeogidfmibmhp [2015-12-08]
CHR Extension: (Gmail) - C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-12-08]
CHR Extension: (Privacy Badger) - C:\Users\John\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkehgijcmpdhfbdbbnkijodmdjhbjlgp [2015-12-08]
CHR HKLM\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - C:\Program Files (x86)\McAfee\SiteAdvisor\McChPlg.crx [2015-12-03]
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-246760859-398526146-1931071061-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [gdfjhiclilbjdpeejgcgebmmihkkofji] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [agbnjankikoaabjkmfbaceggjliabkbn] - C:\Program Files (x86)\SafeKey\lpchrome.crx [2015-12-09]
CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - C:\Program Files (x86)\McAfee\SiteAdvisor\McChPlg.crx [2015-12-03]
CHR HKLM-x32\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [gdfjhiclilbjdpeejgcgebmmihkkofji] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2015-10-12]
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77104 2015-10-07] (Apple Inc.)
R2 Asus WebStorage Windows Service; C:\Program Files (x86)\ASUS\WebStorage\2.1.15.438\AsusWSWinService.exe [71168 2014-11-06] (ASUS Cloud Corporation) [File not signed]
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1433216 2015-10-12] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1773696 2015-10-12] (Microsoft Corporation)
R2 ETDService; C:\Program Files\Elantech\ETDService.exe [147688 2015-08-06] (ELAN Microelectronics Corp.)
R2 HomeNetSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [368584 2015-09-01] (McAfee, Inc.)
R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [330136 2015-10-11] (Intel Corporation)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\TXE Components\TCS\HeciServer.exe [733696 2013-07-01] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\TXE Components\TCS\SocketHeciServer.exe [822232 2013-07-01] (Intel(R) Corporation)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
R2 McAfee SiteAdvisor Service; C:\Program Files (x86)\McAfee\SiteAdvisor\McSACore.exe [157928 2015-12-02] (McAfee, Inc.)
R2 McAPExe; C:\Program Files\McAfee\MSC\McAPExe.exe [783120 2015-09-28] (McAfee, Inc.)
R2 mcbootdelaystartsvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [368584 2015-09-01] (McAfee, Inc.)
R2 mccspsvc; C:\Program Files\Common Files\McAfee\CSP\1.6.1180.0\McCSPServiceHost.exe [1694152 2015-09-01] (McAfee, Inc.)
R2 McMPFSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [368584 2015-09-01] (McAfee, Inc.)
R2 McNaiAnn; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [368584 2015-09-01] (McAfee, Inc.)
S3 McODS; C:\Program Files\McAfee\VirusScan\mcods.exe [639456 2015-08-11] (McAfee, Inc.)
R2 mcpltsvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [368584 2015-09-01] (McAfee, Inc.)
R2 McProxy; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [368584 2015-09-01] (McAfee, Inc.)
R3 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [232656 2015-07-31] (McAfee, Inc.)
R2 mfemms; C:\Program Files\Common Files\McAfee\SystemCore\\mfemms.exe [376264 2015-08-10] (McAfee, Inc.)
R3 mfevtp; C:\WINDOWS\system32\mfevtps.exe [254792 2015-07-31] (McAfee, Inc.)
R2 MSK80Service; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [368584 2015-09-01] (McAfee, Inc.)
R2 Samsung Network Fax Server; C:\Windows\system32\spool\drivers\x64\3\NetFaxServer64.exe [801472 2015-03-10] (Samsung Electronics Co., Ltd.)
S2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1750712 2015-06-16] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2102496 2015-06-16] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [224712 2015-07-24] (Safer-Networking Ltd.)
R2 wampstackApache; C:\Wamp\apache2\bin\httpd.exe [22528 2015-07-12] (Apache Software Foundation) [File not signed]
R2 wampstackMySQL; C:\Wamp\mysql\bin\mysqld.exe [11053568 2015-07-14] () [File not signed]
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [362928 2015-07-10] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-07-10] (Microsoft Corporation)
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 athr; C:\Windows\System32\drivers\athw10x.sys [4325544 2015-06-26] (Qualcomm Atheros Communications, Inc.)
R3 ATP; C:\Windows\System32\drivers\AsusTP.sys [100776 2015-07-28] (ASUS Corporation)
R3 cfwids; C:\Windows\System32\drivers\cfwids.sys [80768 2015-08-10] (McAfee, Inc.)
S3 HipShieldK; C:\Windows\System32\drivers\HipShieldK.sys [207208 2015-05-19] (McAfee, Inc.)
R3 kbfiltr; C:\Windows\System32\drivers\kbfiltr.sys [17280 2012-08-05] ( )
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2015-10-05] (Malwarebytes)
S3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2015-10-05] (Malwarebytes Corporation)
R0 MBI; C:\Windows\System32\drivers\MBI.sys [29464 2013-10-27] (Intel Corporation)
R3 mfeaack; C:\Windows\System32\drivers\mfeaack.sys [413432 2015-08-10] (McAfee, Inc.)
R3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [349096 2015-08-10] (McAfee, Inc.)
S0 mfeelamk; C:\Windows\System32\drivers\mfeelamk.sys [82072 2015-08-10] (McAfee, Inc.)
R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [495856 2015-08-10] (McAfee, Inc.)
R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [839376 2015-08-10] (McAfee, Inc.)
R3 mfencbdc; C:\Windows\system32\DRIVERS\mfencbdc.sys [537408 2015-08-12] (McAfee, Inc.)
S3 mfencrk; C:\Windows\system32\DRIVERS\mfencrk.sys [111256 2015-08-12] (McAfee, Inc.)
R3 mfesapsn; C:\Program Files (x86)\McAfee\SiteAdvisor\x64\mfesapsn.sys [37960 2015-12-02] (McAfee, Inc.)
R0 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [244024 2015-08-10] (McAfee, Inc.)
R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [895256 2015-07-07] (Realtek )
R3 TXEIx64; C:\Windows\System32\drivers\TXEIx64.sys [88592 2014-01-15] (Intel Corporation)
S3 UdeCx; C:\Windows\System32\drivers\udecx.sys [44032 2015-07-10] ()
U5 vrvd5; C:\Windows\System32\Drivers\vrvd5.sys [13344 2015-05-08] (Rsupport Corporation)
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44568 2015-07-10] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [291680 2015-07-10] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [119648 2015-07-10] (Microsoft Corporation)
U3 aswMBR; C:\Users\John\AppData\Local\Temp\aswMBR.sys [62728 2015-12-09] () [File not signed]
U3 aswVmm; C:\Users\John\AppData\Local\Temp\aswVmm.sys [224896 2015-12-09] ()
S3 MREMP50; \??\C:\PROGRA~2\COMMON~1\Motive\MREMP50.SYS [X]
S3 MREMP50a64; \??\C:\PROGRA~1\COMMON~1\Motive\MREMP50a64.SYS [X]
S3 MREMPR5; \??\C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS [X]
S3 MRENDIS5; \??\C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS [X]
S3 MRESP50; \??\C:\PROGRA~2\COMMON~1\Motive\MRESP50.SYS [X]
S3 MRESP50a64; \??\C:\PROGRA~1\COMMON~1\Motive\MRESP50a64.SYS [X]
S3 wfpcapture; \SystemRoot\System32\drivers\wfpcapture.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-12-09 20:01 - 2015-12-09 20:01 - 00000080 _____ C:\Users\Public\Desktop\McAfee LiveSafe - Internet Security.lnk
2015-12-09 19:43 - 2015-12-09 19:43 - 00016148 _____ C:\WINDOWS\system32\JOHN_John_HistoryPrediction.bin
2015-12-09 17:13 - 2015-12-09 21:04 - 00000000 ____D C:\Users\John\Desktop\Removal
2015-12-09 17:04 - 2015-12-09 21:06 - 00031106 _____ C:\Users\John\Desktop\FRST.txt
2015-12-09 17:04 - 2015-12-09 21:05 - 00000000 ____D C:\FRST
2015-12-09 16:57 - 2015-12-09 17:15 - 05198336 _____ (AVAST Software) C:\Users\John\Desktop\aswMBR.exe
2015-12-09 16:56 - 2015-12-09 17:04 - 02369024 _____ (Farbar) C:\Users\John\Desktop\FRST64.exe
2015-12-09 16:46 - 2015-12-09 19:01 - 01599336 _____ (Malwarebytes) C:\Users\John\Desktop\JRT.exe
2015-12-09 16:04 - 2015-12-09 16:39 - 00000000 ____D C:\Users\John\AppData\LocalLow\SafeKey
2015-12-09 16:04 - 2015-12-09 16:14 - 00000000 ____D C:\Program Files (x86)\SafeKey
2015-12-08 20:44 - 2015-12-08 20:44 - 02870984 _____ (ESET) C:\Users\John\Downloads\esetsmartinstaller_enu.exe
2015-12-08 19:32 - 2015-12-09 20:01 - 00002328 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-12-08 19:32 - 2015-12-08 19:32 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-12-08 19:30 - 2015-12-09 20:35 - 00000904 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2015-12-08 19:30 - 2015-12-09 19:35 - 00000900 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2015-12-08 19:30 - 2015-12-08 19:30 - 00927824 _____ (Google Inc.) C:\Users\John\Downloads\ChromeSetup.exe
2015-12-08 19:30 - 2015-12-08 19:30 - 00003962 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2015-12-08 19:30 - 2015-12-08 19:30 - 00003730 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2015-12-07 20:30 - 2015-12-07 20:30 - 00000000 ____D C:\Users\John\New folder
2015-12-07 19:38 - 2015-12-07 20:03 - 00000000 ____D C:\Users\John\AppData\Local\Mozilla
2015-12-03 10:09 - 2015-12-03 10:09 - 38390188 _____ C:\Users\John\Downloads\Samsung M2070 Manual.pdf
2015-12-03 09:57 - 2015-12-03 09:57 - 24708972 _____ C:\Users\John\Downloads\M2070_V3.00.01.22.zip
2015-12-03 09:56 - 2015-12-03 10:11 - 10642432 _____ (Samsung Electronics Co., Ltd.) C:\Users\John\Downloads\PCFax_V1.11.28.exe
2015-12-02 15:30 - 2015-12-02 15:31 - 00000000 ____D C:\Users\John\AppData\Local\Foxit PhantomPDF
2015-12-02 12:33 - 2015-12-02 12:33 - 00000000 ____D C:\Users\John\Downloads\ideaChef
2015-12-02 12:28 - 2015-12-02 12:43 - 00000000 ____D C:\Users\John\Downloads\PDE_2_Proposals
2015-12-02 10:58 - 2015-11-16 12:32 - 00919040 _____ (Farbar) C:\WINDOWS\mod_frst.exe
2015-11-29 23:34 - 2015-11-29 23:34 - 00282624 _____ C:\Users\John\Downloads\appnhost.msi
2015-11-27 21:25 - 2015-12-08 19:25 - 00000000 ____D C:\Users\John\AppData\Roaming\Foxit Software
2015-11-27 21:18 - 2015-12-02 14:57 - 00000000 ____D C:\Users\John\Desktop\Holiday Images
2015-11-25 20:46 - 2015-12-09 17:00 - 318353758 _____ C:\Users\John\Desktop\AllMyNotes.ddb
2015-11-25 20:18 - 2015-12-09 20:01 - 00001187 _____ C:\Users\Public\Desktop\LibreOffice 5.0.lnk
2015-11-25 20:18 - 2015-11-25 20:18 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LibreOffice 5.0
2015-11-25 20:15 - 2015-11-25 20:18 - 00000000 ____D C:\Program Files\LibreOffice 5
2015-11-25 14:44 - 2015-11-25 14:44 - 00000000 _____ C:\WINDOWS\system32\SBRC.dat
2015-11-25 14:04 - 2015-11-25 19:53 - 00000000 ____D C:\ProgramData\STOPzilla!
2015-11-25 14:04 - 2015-11-25 14:04 - 00000000 ____D C:\Program Files (x86)\iS3
2015-11-25 13:41 - 2015-11-25 13:41 - 00000258 __RSH C:\ProgramData\ntuser.pol
2015-11-25 13:18 - 2015-11-23 20:37 - 00001431 _____ C:\WINDOWS\system32\Drivers\etc\hosts.20151125-131803.backup
2015-11-23 22:27 - 2015-11-23 22:27 - 00001951 _____ C:\Users\Public\Desktop\McAfee LiveSafe – Internet Security.lnk
2015-11-23 22:26 - 2015-05-19 13:59 - 00207208 _____ (McAfee, Inc.) C:\WINDOWS\system32\Drivers\HipShieldK.sys
2015-11-23 22:25 - 2015-11-23 22:25 - 00003138 _____ C:\WINDOWS\System32\Tasks\McAfeeLogon
2015-11-23 22:25 - 2015-11-23 22:25 - 00000000 ____D C:\WINDOWS\System32\Tasks\McAfee
2015-11-23 22:25 - 2015-11-23 22:25 - 00000000 ____D C:\Program Files (x86)\McAfee.com
2015-11-23 22:23 - 2015-11-23 22:23 - 00000000 ____D C:\Program Files\McAfee.com
2015-11-23 22:22 - 2015-12-08 20:38 - 00000000 ____D C:\Program Files (x86)\McAfee
2015-11-23 22:22 - 2015-11-23 22:26 - 00000000 ____D C:\Program Files\McAfee
2015-11-23 22:22 - 2015-11-23 22:22 - 00000000 ____D C:\Program Files\Common Files\AV
2015-11-23 22:18 - 2015-11-24 19:22 - 00000000 ____D C:\ProgramData\McAfee
2015-11-23 22:18 - 2015-11-23 22:25 - 00000000 ____D C:\Program Files\Common Files\McAfee
2015-11-23 22:18 - 2015-07-31 12:33 - 00254792 _____ (McAfee, Inc.) C:\WINDOWS\system32\mfevtps.exe
2015-11-23 21:58 - 2015-11-24 19:48 - 00000000 ____D C:\Users\John\AppData\Local\LogMeIn Rescue Applet
2015-11-23 20:48 - 2015-11-23 20:48 - 00003298 _____ C:\WINDOWS\System32\Tasks\{76248857-E513-4734-B019-700E5104411D}
2015-11-23 20:24 - 2015-11-23 20:24 - 00000248 _____ C:\rescue.info
2015-11-22 22:25 - 2015-11-22 22:25 - 00047504 _____ C:\Users\John\Desktop\2015_11_22_Comments on IdeaChef sent to Rui.pdf
2015-11-21 21:44 - 2015-11-21 21:44 - 00000000 ____D C:\Program Files\Logitech
2015-11-21 21:00 - 2015-11-04 23:13 - 00577888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\afd.sys
2015-11-21 21:00 - 2015-11-04 22:20 - 21873664 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2015-11-21 21:00 - 2015-11-04 22:18 - 24597504 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2015-11-21 21:00 - 2015-11-04 21:47 - 19326464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2015-11-21 20:59 - 2015-11-04 23:15 - 00541024 _____ (Microsoft Corporation) C:\WINDOWS\system32\mcupdate_GenuineIntel.dll
2015-11-21 20:59 - 2015-11-04 22:56 - 01083072 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2015-11-21 20:59 - 2015-11-04 22:56 - 00025280 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe
2015-11-21 20:59 - 2015-11-04 22:18 - 03248128 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2015-11-21 20:59 - 2015-11-04 21:59 - 02675200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepository.dll
2015-11-21 20:59 - 2015-11-04 21:54 - 00502272 _____ (Microsoft Corporation) C:\WINDOWS\system32\dlnashext.dll
2015-11-21 20:59 - 2015-11-04 21:35 - 18803712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2015-11-21 20:59 - 2015-11-04 21:28 - 11262976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2015-11-21 20:59 - 2015-11-04 21:27 - 02049536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepository.dll
2015-11-21 20:59 - 2015-11-04 21:23 - 00441344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dlnashext.dll
2015-11-21 20:58 - 2015-11-04 23:15 - 08020832 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2015-11-21 20:58 - 2015-11-04 23:14 - 00459104 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\netio.sys
2015-11-21 20:58 - 2015-11-04 23:11 - 01392480 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll
2015-11-21 20:58 - 2015-11-04 22:56 - 00116064 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tdx.sys
2015-11-21 20:58 - 2015-11-04 22:24 - 02878512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2015-11-21 20:58 - 2015-11-04 22:17 - 02418688 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
2015-11-21 20:58 - 2015-11-04 21:42 - 02647040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
2015-11-21 20:58 - 2015-11-04 21:40 - 01918976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
2015-11-21 20:57 - 2015-11-04 23:06 - 03621248 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2015-11-21 20:57 - 2015-11-04 22:12 - 00515072 _____ (Microsoft Corporation) C:\WINDOWS\system32\internetmail.dll
2015-11-21 20:57 - 2015-11-04 21:59 - 03587072 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2015-11-21 20:57 - 2015-11-04 21:55 - 00145408 _____ (Microsoft Corporation) C:\WINDOWS\system32\dssvc.dll
2015-11-21 20:57 - 2015-11-04 21:35 - 02639872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\esent.dll
2015-11-21 20:56 - 2015-11-04 22:30 - 00961376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll
2015-11-21 20:56 - 2015-11-04 22:23 - 00076800 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll
2015-11-21 20:56 - 2015-11-04 22:10 - 12504064 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2015-11-21 20:56 - 2015-11-04 22:10 - 02987520 _____ (Microsoft Corporation) C:\WINDOWS\system32\esent.dll
2015-11-21 20:56 - 2015-11-04 22:07 - 01068032 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2015-11-21 20:56 - 2015-11-04 22:06 - 00453120 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Usb.dll
2015-11-21 20:56 - 2015-11-04 22:03 - 02180608 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2015-11-21 20:56 - 2015-11-04 22:03 - 01015808 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXService.dll
2015-11-21 20:56 - 2015-11-04 22:01 - 00713216 _____ (Microsoft Corporation) C:\WINDOWS\system32\usermgr.dll
2015-11-21 20:56 - 2015-11-04 21:56 - 01795072 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll
2015-11-21 20:55 - 2015-11-04 22:05 - 01602560 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2015-11-21 20:55 - 2015-11-04 22:01 - 00579072 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
2015-11-21 20:55 - 2015-11-04 21:58 - 01383936 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2015-11-21 20:55 - 2015-11-04 21:58 - 00627712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.dll
2015-11-21 20:55 - 2015-11-04 21:34 - 00311296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Usb.dll
2015-11-21 20:55 - 2015-11-04 21:33 - 01380864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2015-11-21 20:55 - 2015-11-04 21:30 - 00767488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2015-11-21 20:55 - 2015-11-04 21:27 - 00464896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.dll
2015-11-21 20:54 - 2015-11-04 23:06 - 00966416 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll
2015-11-21 20:54 - 2015-11-04 22:23 - 00762888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.appcore.dll
2015-11-21 20:54 - 2015-11-04 22:11 - 00333312 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2015-11-21 20:54 - 2015-11-04 22:05 - 00826880 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2015-11-21 20:53 - 2015-11-04 23:01 - 00607408 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2015-11-21 20:53 - 2015-11-04 22:18 - 00539728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2015-11-21 20:53 - 2015-11-04 22:01 - 00949760 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2015-11-21 20:53 - 2015-11-04 21:33 - 00650240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2015-11-21 18:23 - 2015-11-21 18:23 - 00000144 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2015-11-21 18:17 - 2015-11-23 20:50 - 00000000 ____D C:\Users\Administrator.john.016
2015-11-21 18:11 - 2015-11-23 20:50 - 00000000 ____D C:\Users\Administrator.john.015
2015-11-21 18:11 - 2015-11-23 20:50 - 00000000 ____D C:\Users\Administrator.john.014
2015-11-21 18:11 - 2015-11-21 18:11 - 00000000 ____D C:\Users\Default\AppData\Roaming\Macromedia
2015-11-21 18:11 - 2015-11-21 18:11 - 00000000 ____D C:\Users\Default\AppData\Roaming\Adobe
2015-11-21 18:11 - 2015-11-21 18:11 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Macromedia
2015-11-21 18:11 - 2015-11-21 18:11 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Adobe
2015-11-21 18:00 - 2015-11-23 20:50 - 00000000 ____D C:\Users\TEMP.john
2015-11-21 18:00 - 2015-11-23 20:50 - 00000000 ____D C:\Users\Administrator.john.012
2015-11-21 18:00 - 2015-11-21 18:00 - 00000000 ____D C:\Users\Administrator.john.013
2015-11-16 13:56 - 2015-11-23 20:50 - 00000000 ____D C:\Users\Administrator.john.011
2015-11-16 12:38 - 2015-11-23 20:50 - 00000000 ____D C:\Users\Administrator.john.010
2015-11-16 12:09 - 2015-11-23 20:50 - 00000000 ____D C:\Users\TEMP
2015-11-16 12:09 - 2015-11-23 20:50 - 00000000 ____D C:\Users\Administrator.john.009
2015-11-16 12:08 - 2015-11-23 20:50 - 00000000 ____D C:\Users\Administrator.john.008
2015-11-16 11:53 - 2015-12-09 18:57 - 00000000 ____D C:\Users\Administrator.john.007
2015-11-16 11:41 - 2015-11-23 20:50 - 00000000 ____D C:\Users\Administrator.john.005
2015-11-16 11:41 - 2015-11-16 11:41 - 00000000 ____D C:\Users\Administrator.john.006
2015-11-16 11:31 - 2015-11-23 20:50 - 00000000 ____D C:\Users\Administrator.john.004
2015-11-16 11:19 - 2015-11-23 20:50 - 00000000 ____D C:\Users\Administrator.john.003
2015-11-16 11:17 - 2015-11-16 11:17 - 00012920 ____N C:\bootsqm.dat
2015-11-16 11:17 - 2015-11-16 11:17 - 00000000 __SHD C:\found.000
2015-11-13 22:39 - 2015-11-16 13:14 - 00057344 _____ C:\WINDOWS\system32\config\sam.lbk
2015-11-13 21:39 - 2015-11-23 20:50 - 00000000 ____D C:\Users\Administrator.john.002
2015-11-13 21:27 - 2015-11-23 20:50 - 00000000 ____D C:\Users\Administrator.john.001
2015-11-13 20:59 - 2015-11-23 20:50 - 00000000 ____D C:\Users\Administrator.john.000
2015-11-13 20:59 - 2015-11-23 20:50 - 00000000 ____D C:\Users\Administrator.john
2015-11-13 20:41 - 2015-11-21 18:11 - 00000000 __SHD C:\Users\Administrator\IntelGraphicsProfiles
2015-11-13 20:40 - 2015-11-23 20:50 - 00000000 ____D C:\Users\Administrator
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-12-09 20:49 - 2014-11-20 11:55 - 00000566 _____ C:\WINDOWS\Tasks\G2MUpdateTask-S-1-5-21-246760859-398526146-1931071061-1001.job
2015-12-09 20:19 - 2015-07-10 05:04 - 00000000 ____D C:\WINDOWS\AppReadiness
2015-12-09 20:07 - 2015-06-08 16:42 - 00000662 _____ C:\WINDOWS\Tasks\G2MUploadTask-S-1-5-21-246760859-398526146-1931071061-1001.job
2015-12-09 20:02 - 2015-11-04 16:33 - 00001078 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ownCloud.lnk
2015-12-09 20:02 - 2015-10-01 19:43 - 00001450 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk
2015-12-09 20:02 - 2015-07-30 12:20 - 00002367 _____ C:\Users\John\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2015-12-09 20:02 - 2015-07-30 11:38 - 00001540 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2015-12-09 20:02 - 2015-06-29 10:30 - 00000906 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UltraDefrag.lnk
2015-12-09 20:02 - 2015-06-29 09:53 - 00002523 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
2015-12-09 20:02 - 2015-06-29 09:53 - 00002477 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Serif DrawPlus X6.lnk
2015-12-09 20:02 - 2015-06-29 09:37 - 00002467 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Serif WebPlus X7.lnk
2015-12-09 20:01 - 2015-11-04 16:33 - 00001072 _____ C:\Users\Public\Desktop\ownCloud.lnk
2015-12-09 20:01 - 2015-11-04 11:36 - 00001778 _____ C:\Users\Public\Desktop\iTunes.lnk
2015-12-09 20:01 - 2015-10-28 15:53 - 00001167 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-12-09 20:01 - 2015-10-22 17:34 - 00002634 _____ C:\Users\Public\Desktop\Skype.lnk
2015-12-09 20:01 - 2015-10-21 17:10 - 00001346 _____ C:\Users\Public\Desktop\WebStorage.lnk
2015-12-09 20:01 - 2015-10-07 09:18 - 00000506 _____ C:\Users\John\Desktop\Notepad_F.lnk
2015-12-09 20:01 - 2015-10-01 19:43 - 00001444 _____ C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
2015-12-09 20:01 - 2015-10-01 19:38 - 00001162 _____ C:\Users\Public\Desktop\Spybot Anti-Beacon.lnk
2015-12-09 20:01 - 2015-09-17 17:02 - 00002064 _____ C:\Users\Public\Desktop\NetBeans IDE 8.0.2.lnk
2015-12-09 20:01 - 2015-08-26 12:04 - 00000916 _____ C:\Users\Public\Desktop\VLC media player.lnk
2015-12-09 20:01 - 2015-08-12 09:03 - 00002168 _____ C:\Users\John\Desktop\AllMyNotes Organizer.lnk
2015-12-09 20:01 - 2015-08-03 18:29 - 00001160 _____ C:\Users\John\Desktop\MEGAsync.lnk
2015-12-09 20:01 - 2015-07-29 11:10 - 00002008 _____ C:\Users\Public\Desktop\FileZilla Client.lnk
2015-12-09 20:01 - 2015-07-23 08:24 - 00001087 _____ C:\Users\Public\Desktop\SpywareBlaster.lnk
2015-12-09 20:01 - 2015-06-29 10:30 - 00000900 _____ C:\Users\Public\Desktop\UltraDefrag.lnk
2015-12-09 20:01 - 2014-11-14 19:22 - 00000863 _____ C:\Users\Public\Desktop\CCleaner.lnk
2015-12-09 19:09 - 2015-10-28 15:53 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-12-09 19:03 - 2015-07-10 03:05 - 00000000 ____D C:\Windows
2015-12-09 17:55 - 2015-07-10 05:04 - 00000000 ____D C:\WINDOWS\rescache
2015-12-09 17:31 - 2015-07-10 05:04 - 00000000 ___HD C:\Program Files\WindowsApps
2015-12-09 16:04 - 2015-10-14 15:03 - 00000000 ____D C:\Users\John\Downloads\Stuff to Install
2015-12-09 16:03 - 2015-10-22 17:34 - 00000000 ____D C:\Users\John\AppData\Roaming\Skype
2015-12-09 14:48 - 2015-07-10 04:55 - 00000000 ____D C:\WINDOWS\CbsTemp
2015-12-09 12:00 - 2015-05-13 16:10 - 00003544 _____ C:\WINDOWS\System32\Tasks\ASUS Live Update1
2015-12-09 12:00 - 2015-05-13 16:10 - 00003534 _____ C:\WINDOWS\System32\Tasks\ASUS Live Update2
2015-12-08 20:47 - 2015-07-30 11:49 - 00875126 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2015-12-08 20:47 - 2015-07-10 05:02 - 00000000 ____D C:\WINDOWS\INF
2015-12-08 20:46 - 2014-10-25 20:18 - 00000000 ____D C:\Users\John\AppData\Roaming\WebStorage
2015-12-08 20:40 - 2015-10-21 17:37 - 00000000 ____D C:\ProgramData\ASUS Smart Gesture
2015-12-08 20:39 - 2015-07-30 12:05 - 00000000 __SHD C:\Users\John\IntelGraphicsProfiles
2015-12-08 20:39 - 2015-07-30 11:27 - 00000000 ____D C:\Users\John
2015-12-08 20:38 - 2015-07-10 06:21 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-12-08 20:34 - 2015-07-10 05:04 - 00000000 ____D C:\WINDOWS\LiveKernelReports
2015-12-08 19:32 - 2014-10-26 06:56 - 00000000 ____D C:\Users\John\AppData\Local\Google
2015-12-08 19:31 - 2014-10-26 06:56 - 00000000 ____D C:\Program Files (x86)\Google
2015-12-08 19:20 - 2015-08-21 19:48 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2015-12-07 20:09 - 2015-06-08 16:42 - 00003804 _____ C:\WINDOWS\System32\Tasks\G2MUploadTask-S-1-5-21-246760859-398526146-1931071061-1001
2015-12-07 20:09 - 2014-11-20 11:55 - 00003708 _____ C:\WINDOWS\System32\Tasks\G2MUpdateTask-S-1-5-21-246760859-398526146-1931071061-1001
2015-12-07 19:59 - 2014-10-31 14:06 - 00000000 ____D C:\WINDOWS\system32\MRT
2015-12-07 19:49 - 2014-10-31 14:06 - 145617392 ____N (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2015-12-07 19:42 - 2015-07-10 03:05 - 00032768 ___SH C:\WINDOWS\system32\config\ELAM
2015-12-07 19:38 - 2014-10-28 09:28 - 00000000 ____D C:\Users\John\AppData\Roaming\Mozilla
2015-12-03 15:27 - 2015-10-15 10:15 - 00000000 ____D C:\ProgramData\boost_interprocess
2015-12-02 12:32 - 2015-07-17 19:48 - 00000000 ____D C:\Users\John\Downloads\AllMyNotes
2015-11-30 18:32 - 2015-07-10 05:06 - 00826872 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2015-11-30 18:32 - 2015-07-10 05:06 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2015-11-27 03:36 - 2015-07-10 06:20 - 00428592 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2015-11-27 03:35 - 2015-07-10 03:05 - 00262144 ___SH C:\WINDOWS\system32\config\BBI
2015-11-27 03:31 - 2015-07-10 05:04 - 00000000 ____D C:\WINDOWS\system32\appraiser
2015-11-25 20:03 - 2015-08-03 19:30 - 00000000 ____D C:\ProgramData\Package Cache
2015-11-25 13:51 - 2014-10-26 06:54 - 00000000 __SHD C:\Users\John\AppData\Local\EmieUserList
2015-11-25 13:51 - 2014-10-26 06:54 - 00000000 __SHD C:\Users\John\AppData\Local\EmieSiteList
2015-11-25 13:48 - 2015-10-28 15:27 - 00000000 ____D C:\AdwCleaner
2015-11-25 13:42 - 2014-11-19 19:29 - 00000000 ____D C:\ProgramData\TEMP
2015-11-25 13:41 - 2015-07-23 08:24 - 00000000 ____D C:\Program Files (x86)\SpywareBlaster
2015-11-25 13:35 - 2014-10-25 20:12 - 00000000 ____D C:\Users\John\AppData\Local\Packages
2015-11-25 13:33 - 2015-07-10 05:04 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2015-11-25 13:15 - 2014-11-01 10:14 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2015-11-24 19:22 - 2015-01-18 21:01 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
2015-11-23 22:36 - 2014-11-17 20:00 - 00000000 ____D C:\Users\John\AppData\Roaming\Samsung
2015-11-23 22:24 - 2015-07-10 05:04 - 00000000 ___HD C:\WINDOWS\ELAMBKUP
2015-11-23 20:50 - 2013-08-22 07:36 - 00000000 ____D C:\Users\Default.migrated
2015-11-21 21:55 - 2014-10-25 20:17 - 00000000 __RDO C:\Users\John\OneDrive
2015-11-21 21:45 - 2014-11-20 09:40 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logitech
2015-11-21 21:45 - 2014-11-20 09:40 - 00000000 ____D C:\Program Files\Common Files\LogiShrd
2015-11-21 21:44 - 2014-11-20 09:40 - 00000000 ____D C:\ProgramData\LogiShrd
2015-11-13 20:41 - 2014-10-26 10:48 - 00000000 __RHD C:\Users\Public\AccountPictures
==================== Files in the root of some directories =======
2014-12-03 16:46 - 2015-12-09 16:14 - 32372200 _____ (McAfee) C:\Program Files (x86)\Common Files\lpuninstall.exe
2015-01-31 16:09 - 2015-01-31 16:09 - 0001279 _____ () C:\Users\John\AppData\Local\recently-used.xbel
2015-08-27 08:17 - 2015-08-27 08:17 - 0007605 _____ () C:\Users\John\AppData\Local\Resmon.ResmonCfg
2015-07-30 11:21 - 2015-07-30 11:21 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
2014-04-18 16:51 - 2012-09-07 05:40 - 0000256 _____ () C:\ProgramData\SetStretch.cmd
Some files in TEMP:
====================
C:\Users\John\AppData\Local\Temp\FoxitUpdater.exe
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-12-09 14:22
==================== End of FRST.txt ============================