Hi there, trying to fix my daughters slow computer. It's been getting very bad lately, not even able to connect to the internet sometimes.
Sorry, having to post this in two parts, its too big for just the one.
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:13-06-2015
Ran by Sollux Captor (administrator) on CASSY-PC on 14-06-2015 13:52:30
Running from C:\Users\Cassy\Desktop
Loaded Profiles: Sollux Captor (Available Profiles: Sollux Captor)
Platform: Windows 8.1 Pro (X64) OS Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Comodo Security Solutions, Inc.) C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\WTabletServiceCon.exe
(Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cistray.exe
(Nico Mak Computing) C:\Program Files (x86)\WinZip Malware Protector\WinZipMalwareProtector.exe
() C:\Program Files (x86)\OneSystemCare\CleanupConsole.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
(Conexant Systems Inc.) C:\Windows\System32\CxAudMsg64.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Comodo Security Solutions, Inc.) C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exe
(Comodo Security Solutions, Inc.) C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe
() C:\Program Files\015\lxqvbcbiws32.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
(WN) C:\Program Files (x86)\Wordinator_1.10.0.17\Service\wsvc.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cavwp.exe
() C:\Program Files (x86)\Super Optimizer\SupOptSmartScan.exe
(CyberLink) C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\Pen_TabletUser.exe
(Wacom Technology) C:\Program Files\Tablet\Pen\WacomHost.exe
(Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe
(Lenovo (Beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\Pen_Tablet.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\Pen_TouchUser.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\utility.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
( ) C:\Program Files (x86)\LockKey\LockKey.exe
(Lenovo) C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe
(Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cis.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe
() C:\Program Files (x86)\ControlThis Parental Control\CloudNATIONAL.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cmdupd.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cavwp.exe
() C:\Program Files (x86)\Reg Pro Cleaner\Regprocleaner.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2809856 2012-01-16] (ELAN Microelectronics Corp.)
HKLM\...\Run: [cAudioFilterAgent] => C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [564352 2012-03-01] (Conexant Systems, Inc.)
HKLM\...\Run: [Energy Management] => C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [8071680 2012-07-07] (Lenovo (Beijing) Limited)
HKLM\...\Run: [EnergyUtility] => C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe [6193152 2012-07-07] (Lenovo(beijing) Limited)
HKLM\...\Run: [Lenovo EE Boot Optimizer] => C:\Program Files (x86)\Lenovo\Boot Optimizer\PopWnd.exe [206176 2012-07-07] (Lenovo)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [472984 2013-06-13] (Adobe Systems Incorporated)
HKLM\...\Run: [COMODO Internet Security] => C:\Program Files\COMODO\COMODO Internet Security\cistray.exe [1426136 2015-04-22] (COMODO)
HKLM-x32\...\Run: [332BigDog] => C:\Program Files (x86)\USB Camera2\VM332_STI.EXE [548864 2011-12-09] (Vimicro)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [LockKey] => C:\Program Files (x86)\LockKey\LockKey.exe [337776 2011-08-25] ( )
HKLM-x32\...\Run: [UpdatePRCShortCut] => C:\Program Files\Lenovo\OneKey App\OneKey Recovery\MUITransfer\MUIStartMenu.exe [222504 2009-05-13] (CyberLink Corp.)
HKLM-x32\...\Run: [VeriFaceManager] => C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe [329056 2012-07-07] (Lenovo)
HKLM-x32\...\Run: [YouCam Mirage] => C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe [136488 2011-01-29] (CyberLink)
HKLM-x32\...\Run: [YouCam Tray] => C:\Program Files (x86)\Lenovo\YouCam\YouCam.exe [228448 2011-01-29] (CyberLink Corp.)
HKLM-x32\...\Run: [BambooCore] => C:\Program Files (x86)\Bamboo Dock\BambooCore.exe [646744 2012-10-16] ()
HKLM-x32\...\Run: [Adobe Creative Cloud] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2236816 2013-08-08] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [4101584 2014-04-25] (Safer-Networking Ltd.)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5515496 2015-04-21] (Avast Software s.r.o.)
HKLM-x32\...\Run: [ComodoFSChrome] => "C:\Program Files (x86)\AdTrustMedia\PrivDog\FinalizeSetup.exe" /c
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766688 2015-02-22] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [tvncontrol] => C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe [2327248 2015-03-09] (Comodo Security Solutions, Inc.)
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
HKU\S-1-5-21-3775124505-4180658665-910221950-1001\...\Run: [GoogleChromeAutoLaunch_36970D3059E4608AE74B88E09A7E6CB3] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [813896 2015-06-10] (Google Inc.)
HKU\S-1-5-21-3775124505-4180658665-910221950-1001\...\Run: [Spybot-S&D Cleaning] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe [4566984 2014-04-25] (Safer-Networking Ltd.)
HKU\S-1-5-21-3775124505-4180658665-910221950-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [30877280 2014-12-11] (Skype Technologies S.A.)
HKU\S-1-5-21-3775124505-4180658665-910221950-1001\...\Run: [Super Optimizer] => C:\Program Files (x86)\Super Optimizer\SupOptLauncher.exe [676400 2015-06-11] ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2014-10-27]
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (McAfee, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Start GeekBuddy.lnk [2015-03-09]
ShortcutTarget: Start GeekBuddy.lnk -> C:\Program Files\COMODO\GeekBuddy\launcher.exe (Comodo Security Solutions, Inc.)
Startup: C:\Users\Cassy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\nnfflllt.lnk [2014-07-23]
ShortcutTarget: nnfflllt.lnk -> C:\Users\Cassy\AppData\Local\nnfflllt.exe (No File)
ShellIconOverlayIdentifiers: [ AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_v_1_1_0_x64.dll [2013-07-31] ()
ShellIconOverlayIdentifiers: [ AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_v_1_1_0_x64.dll [2013-07-31] ()
ShellIconOverlayIdentifiers: [ AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_v_1_1_0_x64.dll [2013-07-31] ()
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2015-04-21] (Avast Software s.r.o.)
ShellIconOverlayIdentifiers: [VeriFace Enc] -> {771C7324-DA80-49D3-8017-753B0AF60951} => C:\Windows\system32\IcnOvrly.dll [2012-07-07] ()
BootExecute: autocheck autochk * sdnclean64.exe
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
HKU\S-1-5-21-3775124505-4180658665-910221950-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig/redirectdomain?brand=LENN&bmod=LENN
HKU\S-1-5-21-3775124505-4180658665-910221950-1001\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.ca/
SearchScopes: HKU\S-1-5-21-3775124505-4180658665-910221950-1001 -> DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7LENN
SearchScopes: HKU\S-1-5-21-3775124505-4180658665-910221950-1001 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7LENN
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-04-21] (Avast Software s.r.o.)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-05-01] (Microsoft Corporation)
BHO-x32: MSS+ Identifier -> {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} -> C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll [2014-04-09] (McAfee, Inc.)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll [2015-01-25] (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-04-21] (Avast Software s.r.o.)
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-01-25] (Oracle Corporation)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-05-01] (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01] (Microsoft Corporation)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{45A70356-416B-4B42-8DB5-E3519E992D34}: [NameServer] 81.218.119.5,82.163.142.130
Tcpip\..\Interfaces\{B2A0856A-8ECE-4677-89A0-7FBDCE102A88}: [NameServer] 81.218.119.5,82.163.142.130
FireFox:
========
FF ProfilePath: C:\Users\Cassy\AppData\Roaming\Mozilla\Firefox\Profiles\4fgio0ge.default-1416152417215
FF DefaultSearchEngine: Google (avast)
FF DefaultSearchEngine.US: Google (avast)
FF DefaultSearchUrl: https://www.google.com/search/?trackid=sp-006
FF SearchEngineOrder.1: Google (avast)
FF SelectedSearchEngine: Google (avast)
FF Homepage: https://www.google.com/?trackid=sp-006
FF Keyword.URL: https://www.google.com/search/?trackid=sp-006
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_17_0_0_188.dll [2015-06-09] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-16] ( Microsoft Corporation)
FF Plugin: @wacom.com/wtPlugin,version=2.1.0.2 -> C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll [2012-05-23] (Wacom)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2013-08-08] (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_188.dll [2015-06-09] ()
FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 -> C:\WINDOWS\SysWOW64\npDeployJava1.dll [2013-06-23] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-01-25] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-17] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-17] (Google Inc.)
FF Plugin-x32: @wacom.com/wtPlugin,version=2.1.0.2 -> C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll [2012-05-23] (Wacom)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2014-05-08] (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2013-08-08] (Adobe Systems)
FF Plugin-x32: adobe.com/AdobeExManDetect -> C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\npAdobeExManDetectX86.dll No File
FF Plugin HKU\S-1-5-21-3775124505-4180658665-910221950-1001: wacom.com/WacomTabletPlugin -> C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll [2012-05-23] (Wacom)
FF SearchPlugin: C:\Users\Cassy\AppData\Roaming\Mozilla\Firefox\Profiles\4fgio0ge.default-1416152417215\searchplugins\google-avast.xml [2014-12-12]
FF Extension: NoScript - C:\Users\Cassy\AppData\Roaming\Mozilla\Firefox\Profiles\4fgio0ge.default-1416152417215\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2014-11-16]
FF Extension: Adblock Plus - C:\Users\Cassy\AppData\Roaming\Mozilla\Firefox\Profiles\4fgio0ge.default-1416152417215\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-11-28]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-09-21]
FF HKU\S-1-5-21-3775124505-4180658665-910221950-1001\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi
FF Extension: No Name - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi [2014-04-04]
Chrome:
=======
CHR Profile: C:\Users\Cassy\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Bookmark Manager) - C:\Users\Cassy\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmlllbghnfkpflemihljekbapjopfjik [2015-06-14]
CHR Extension: (Avast Online Security) - C:\Users\Cassy\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2014-09-22]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Cassy\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-06-03]
CHR Extension: (Skype Click to Call) - C:\Users\Cassy\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2014-02-09]
CHR Extension: (Google Wallet) - C:\Users\Cassy\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-10]
CHR HKLM-x32\...\Chrome\Extension: [bopakagnckmlgajfccecajhnimjiiedh] - http://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-04-21]
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2015-05-01]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [344064 2015-02-22] (Advanced Micro Devices, Inc.) [File not signed]
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [343336 2015-04-21] (Avast Software s.r.o.)
S3 BthHFSrv; C:\Windows\System32\BthHFSrv.dll [324608 2015-03-03] (Microsoft Corporation)
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1394816 2015-05-31] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1772672 2015-05-31] (Microsoft Corporation)
S2 cae99edb; c:\Program Files (x86)\Super Optimizer\SupOptStats.dll [3117104 2015-06-11] ()
R2 CLPSLauncher; C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe [70872 2015-03-09] (Comodo Security Solutions, Inc.)
R2 CmdAgent; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [5540424 2015-04-22] (COMODO)
S3 cmdvirth; C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe [2265816 2015-04-22] (COMODO)
R2 DragonUpdater; C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exe [2370240 2014-11-27] (Comodo Security Solutions, Inc.)
R2 GeekBuddyRSP; C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe [2327248 2015-03-09] (Comodo Security Solutions, Inc.)
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [73728 2004-10-22] (Macrovision Corporation) [File not signed]
R2 lxqvbcbiws32; C:\Program Files\015\lxqvbcbiws32.exe [622392 2015-06-14] ()
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [289256 2014-04-09] (McAfee, Inc.)
R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1738200 2014-04-25] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2081752 2014-04-25] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2014-04-25] (Safer-Networking Ltd.)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366520 2015-03-11] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2015-03-11] (Microsoft Corporation)
R2 wsvc_1.10.0.17; C:\Program Files (x86)\Wordinator_1.10.0.17\Service\wsvc.exe [278616 2015-06-11] (WN)
R2 WTabletServiceCon; C:\Program Files\Tablet\Pen\WTabletServiceCon.exe [619904 2012-11-14] (Wacom Technology, Corp.)
S3 AvastVBoxSvc; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [X]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 Apowersoft_AudioDevice; C:\Windows\system32\drivers\Apowersoft_AudioDevice.sys [31968 2012-10-08] (Wondershare)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29168 2015-04-21] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [89944 2015-04-21] (Avast Software s.r.o.)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-04-21] (Avast Software s.r.o.)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65736 2015-04-21] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1047320 2015-04-21] (Avast Software s.r.o.)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [442264 2015-04-21] (Avast Software s.r.o.)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [137288 2015-04-21] (Avast Software s.r.o.)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [272248 2015-04-21] ()
R3 athr; C:\Windows\system32\DRIVERS\athwnx.sys [3680256 2013-06-18] (Qualcomm Atheros Communications, Inc.)
R1 CFRMD; C:\Windows\System32\DRIVERS\CFRMD.sys [40224 2014-06-26] (Windows (R) Win 7 DDK provider)
R1 cmderd; C:\Windows\System32\DRIVERS\cmderd.sys [20696 2015-04-01] (COMODO)
R1 cmdGuard; C:\Windows\System32\DRIVERS\cmdguard.sys [820952 2015-04-01] (COMODO)
R1 cmdhlp; C:\Windows\system32\DRIVERS\cmdhlp.sys [35080 2015-04-01] (COMODO)
S3 dot4; C:\Windows\system32\DRIVERS\Dot4.sys [151968 2012-10-19] (Windows (R) Win 7 DDK provider)
S3 Dot4Print; C:\Windows\System32\drivers\Dot4Prt.sys [27040 2012-10-19] (Windows (R) Win 7 DDK provider)
R1 HMD; C:\Windows\system32\DRIVERS\hmd.sys [14888 2014-06-26] ()
R1 inspect; C:\Windows\system32\DRIVERS\inspect.sys [126720 2015-04-01] (COMODO)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2015-03-11] (Microsoft Corporation)
R1 wfd_1_10_0_17; C:\Windows\System32\drivers\wfd_1_10_0_17.sys [58240 2015-06-03] (WN)
S3 MBAMSwissArmy; \??\C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [X]
U4 VBoxAswDrv; \??\C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-06-14 13:52 - 2015-06-14 13:54 - 00023299 _____ C:\Users\Cassy\Desktop\FRST.txt
2015-06-14 13:52 - 2015-06-14 13:53 - 05198336 _____ (AVAST Software) C:\Users\Cassy\Desktop\aswMBR.exe
2015-06-14 13:49 - 2015-06-14 13:52 - 00000000 ____D C:\FRST
2015-06-14 13:46 - 2015-06-14 13:46 - 00000207 _____ C:\WINDOWS\tweaking.com-regbackup-CASSY-PC-Windows-8.1-Pro-(64-bit).dat
2015-06-14 13:40 - 2015-06-14 13:40 - 00002262 _____ C:\Users\Public\Desktop\Tweaking.com - Registry Backup.lnk
2015-06-14 13:40 - 2015-06-14 13:40 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tweaking.com
2015-06-14 13:35 - 2015-06-14 13:35 - 02109952 _____ (Farbar) C:\Users\Cassy\Desktop\FRST64.exe
2015-06-14 13:33 - 2015-06-14 13:35 - 04720448 _____ C:\Users\Cassy\Desktop\tweaking.com_registry_backup_setup(1).exe
2015-06-14 13:18 - 2015-06-14 13:18 - 00000000 ____D C:\Users\Cassy\AppData\Roaming\One System Care
2015-06-14 13:11 - 2015-06-14 13:11 - 00003238 _____ C:\WINDOWS\System32\Tasks\RPC
2015-06-14 13:09 - 2015-06-14 13:22 - 00000310 _____ C:\WINDOWS\Tasks\One System CareStartUp.job
2015-06-14 13:09 - 2015-06-14 13:17 - 00000310 _____ C:\WINDOWS\Tasks\One System CarePeriod.job
2015-06-14 13:09 - 2015-06-14 13:09 - 00002876 _____ C:\WINDOWS\System32\Tasks\One System CarePeriod
2015-06-14 13:09 - 2015-06-14 13:09 - 00002580 _____ C:\WINDOWS\System32\Tasks\One System CareStartUp
2015-06-14 13:09 - 2015-06-14 13:09 - 00000000 ____D C:\Users\Cassy\AppData\Roaming\VOPackage
2015-06-14 13:09 - 2015-06-14 13:09 - 00000000 ____D C:\Users\Cassy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VOPackage
2015-06-14 13:09 - 2015-06-14 13:09 - 00000000 ____D C:\Users\Cassy\AppData\Roaming\15586344-1434301786-E111-984C-DC0EA1FBF0C7
2015-06-14 13:08 - 2015-06-14 13:09 - 00000000 ____D C:\Program Files (x86)\OneSystemCare
2015-06-14 13:08 - 2015-06-14 13:08 - 00003342 _____ C:\WINDOWS\System32\Tasks\One System Care Run Delay
2015-06-14 13:08 - 2015-06-14 13:08 - 00003276 _____ C:\WINDOWS\System32\Tasks\One System Care Monitor
2015-06-14 13:08 - 2015-06-14 13:08 - 00001090 _____ C:\Users\Public\Desktop\Launch One System Care.lnk
2015-06-14 13:08 - 2015-06-14 13:08 - 00001030 _____ C:\Users\Cassy\Desktop\GUPlayer.lnk
2015-06-14 13:08 - 2015-06-14 13:08 - 00000000 ____D C:\Users\Cassy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GUPlayer
2015-06-14 13:08 - 2015-06-14 13:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneSystemCare
2015-06-14 13:08 - 2015-06-14 13:08 - 00000000 ____D C:\Program Files (x86)\GUPlayer
2015-06-14 13:07 - 2015-06-14 13:08 - 00000000 ____D C:\Program Files (x86)\ControlThis Parental Control
2015-06-14 13:07 - 2015-06-14 13:07 - 00026434 _____ C:\WINDOWS\System32\Tasks\CloudNATIONAL
2015-06-14 13:07 - 2015-06-14 13:07 - 00001220 _____ C:\Users\Public\Desktop\Reg Pro Cleaner.lnk
2015-06-14 13:07 - 2015-06-14 13:07 - 00001042 _____ C:\Users\Cassy\Desktop\PepperZip.lnk
2015-06-14 13:07 - 2015-06-14 13:07 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Reg Pro Cleaner
2015-06-14 13:07 - 2015-06-14 13:07 - 00000000 ____D C:\Program Files (x86)\Reg Pro Cleaner
2015-06-14 13:06 - 2015-06-14 13:07 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PepperZip
2015-06-14 13:06 - 2015-06-14 13:07 - 00000000 ____D C:\Program Files (x86)\PepperZip
2015-06-14 13:06 - 2015-06-14 13:06 - 00000000 ____D C:\Users\Cassy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PepperZip
2015-06-14 13:06 - 2015-06-14 13:06 - 00000000 ____D C:\Program Files\13
2015-06-14 13:06 - 2015-06-14 13:06 - 00000000 ____D C:\Program Files\015
2015-06-14 13:05 - 2015-06-14 13:05 - 00001739 _____ C:\Users\Cassy\Desktop\Continue Microsoft PowerPoint.lnk
2015-06-14 13:04 - 2015-06-14 13:04 - 00670816 _____ ( ) C:\Users\Cassy\Downloads\Microsoft PowerPoint.exe
2015-06-13 17:17 - 2015-06-09 17:20 - 00792568 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2015-06-13 17:17 - 2015-06-09 17:20 - 00178168 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2015-06-11 15:31 - 2015-06-14 13:28 - 00003280 _____ C:\WINDOWS\System32\Tasks\Super Optimizer Schedule
2015-06-11 15:31 - 2015-06-11 15:31 - 00000000 ____D C:\Users\Cassy\Documents\Super Optimizer
2015-06-11 15:31 - 2015-06-11 15:31 - 00000000 ____D C:\Users\Cassy\AppData\Roaming\Super Optimizer
2015-06-11 15:25 - 2015-06-14 13:28 - 00003116 _____ C:\WINDOWS\System32\Tasks\WinZip Malware Protector_startup
2015-06-11 15:24 - 2015-06-11 15:24 - 00000000 ____D C:\Users\Cassy\AppData\Roaming\Nico Mak Computing
2015-06-11 15:22 - 2015-06-14 12:49 - 00000000 ____D C:\Program Files (x86)\Super Optimizer
2015-06-11 15:22 - 2015-06-11 15:22 - 00000000 ____D C:\ProgramData\Nico Mak Computing
2015-06-11 15:22 - 2015-06-11 15:22 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZip Malware Protector
2015-06-11 15:22 - 2015-06-11 15:22 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Super Optimizer
2015-06-11 15:22 - 2015-06-11 15:22 - 00000000 ____D C:\Program Files (x86)\Wordinator_1.10.0.17
2015-06-11 15:22 - 2015-06-11 15:22 - 00000000 ____D C:\Program Files (x86)\WinZip Malware Protector
2015-06-11 15:22 - 2015-03-17 11:03 - 00020480 _____ C:\WINDOWS\system32\wsusnative64.exe
2015-06-11 15:16 - 2015-06-11 15:17 - 00736552 _____ (Web Application ) C:\Users\Cassy\Downloads\Malavida_Download_Manager(1).exe
2015-06-11 15:05 - 2015-06-14 13:17 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2015-06-10 03:30 - 2015-06-10 03:45 - 00000000 ____D C:\6b423640a31629c8fbf21cb2
2015-06-09 17:30 - 2015-06-09 17:30 - 01119232 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2015-06-09 17:30 - 2015-06-09 17:30 - 01020928 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2015-06-09 17:30 - 2015-06-09 17:30 - 00756736 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2015-06-09 17:30 - 2015-06-09 17:30 - 00700416 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2015-06-09 17:30 - 2015-06-09 17:30 - 00422912 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2015-06-09 17:30 - 2015-06-09 17:30 - 00227328 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepdu.dll
2015-06-09 17:30 - 2015-06-09 17:30 - 00193536 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll
2015-06-09 17:30 - 2015-06-09 17:30 - 00045568 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2015-06-09 17:30 - 2015-04-08 18:07 - 00410336 _____ C:\WINDOWS\system32\ApnDatabase.xml
2015-06-09 17:24 - 2015-06-09 17:24 - 01091072 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll
2015-06-09 17:24 - 2015-06-09 17:24 - 00477184 _____ (Microsoft Corporation) C:\WINDOWS\system32\puiobj.dll
2015-06-09 17:24 - 2015-06-09 17:24 - 00367104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\puiobj.dll
2015-06-09 17:24 - 2015-06-09 17:24 - 00309760 _____ (Microsoft Corporation) C:\WINDOWS\system32\compstui.dll
2015-06-09 17:24 - 2015-06-09 17:24 - 00222208 _____ (Microsoft Corporation) C:\WINDOWS\system32\rastapi.dll
2015-06-09 17:24 - 2015-06-09 17:24 - 00207872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rastapi.dll
2015-06-09 17:20 - 2015-05-25 09:23 - 00036864 _____ (Microsoft Corporation) C:\WINDOWS\system32\UtcResources.dll
2015-06-09 17:20 - 2015-05-25 09:07 - 01430528 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2015-06-09 17:20 - 2015-04-08 18:41 - 00158720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rgb9rast.dll
2015-06-09 17:20 - 2015-04-01 18:42 - 03097600 _____ (Microsoft Corporation) C:\WINDOWS\system32\msftedit.dll
2015-06-09 17:20 - 2015-04-01 18:30 - 02483712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msftedit.dll
2015-06-09 17:13 - 2015-06-09 17:13 - 24917504 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2015-06-09 17:13 - 2015-06-09 17:13 - 19607040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2015-06-09 17:13 - 2015-06-09 17:13 - 12829696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2015-06-09 17:13 - 2015-06-09 17:13 - 06026240 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2015-06-09 17:13 - 2015-06-09 17:13 - 02426880 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2015-06-09 17:13 - 2015-06-09 17:13 - 01018880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll
2015-06-09 17:13 - 2015-06-09 17:13 - 00653824 _____ (Microsoft Corporation) C:\WINDOWS\system32\comctl32.dll
2015-06-09 17:13 - 2015-06-09 17:13 - 00549888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comctl32.dll
2015-06-09 17:13 - 2015-04-16 02:17 - 00325464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS
2015-06-09 17:13 - 2015-04-13 18:37 - 00275968 _____ (Microsoft Corporation) C:\WINDOWS\system32\authz.dll
2015-06-09 17:13 - 2015-04-13 18:34 - 00180224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authz.dll
2015-06-09 17:13 - 2015-04-09 20:40 - 01249280 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll
2015-06-09 17:13 - 2015-04-01 00:21 - 00337408 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchProtocolHost.exe
2015-06-09 17:13 - 2015-04-01 00:18 - 00468480 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssph.dll
2015-06-09 17:13 - 2015-04-01 00:17 - 00248832 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssphtb.dll
2015-06-09 17:13 - 2015-04-01 00:08 - 00774144 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssvp.dll
2015-06-09 17:13 - 2015-03-31 23:46 - 03633664 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll
2015-06-09 17:13 - 2015-03-31 23:17 - 02551808 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssrch.dll
2015-06-09 17:13 - 2015-03-31 23:17 - 00903168 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchIndexer.exe
2015-06-09 17:13 - 2015-03-31 22:53 - 00391680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssph.dll
2015-06-09 17:13 - 2015-03-31 22:53 - 00272896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchProtocolHost.exe
2015-06-09 17:13 - 2015-03-31 22:45 - 02749952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll
2015-06-09 17:13 - 2015-03-31 22:45 - 00699392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssvp.dll
2015-06-09 17:13 - 2015-03-31 22:14 - 01920000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssrch.dll
2015-06-09 17:13 - 2015-03-31 22:12 - 00710144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchIndexer.exe
2015-06-09 17:12 - 2015-06-09 17:13 - 14404096 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2015-06-09 17:12 - 2015-06-09 17:13 - 04305920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2015-06-09 17:12 - 2015-06-09 17:13 - 02885632 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2015-06-09 17:12 - 2015-06-09 17:13 - 02278912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2015-06-09 17:12 - 2015-06-09 17:13 - 01950720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2015-06-09 17:12 - 2015-06-09 17:13 - 01545728 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2015-06-09 17:12 - 2015-06-09 17:13 - 01309696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2015-06-09 17:12 - 2015-06-09 17:12 - 02865152 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll
2015-06-09 17:12 - 2015-06-09 17:12 - 02125824 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2015-06-09 17:12 - 2015-06-09 17:12 - 02052608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2015-06-09 17:12 - 2015-06-09 17:12 - 01042944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll
2015-06-09 17:12 - 2015-06-09 17:12 - 01032704 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll
2015-06-09 17:12 - 2015-06-09 17:12 - 00880128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcomm.dll
2015-06-09 17:12 - 2015-06-09 17:12 - 00816640 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2015-06-09 17:12 - 2015-06-09 17:12 - 00814080 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll
2015-06-09 17:12 - 2015-06-09 17:12 - 00801280 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2015-06-09 17:12 - 2015-06-09 17:12 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2015-06-09 17:12 - 2015-06-09 17:12 - 00710144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2015-06-09 17:12 - 2015-06-09 17:12 - 00689152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2015-06-09 17:12 - 2015-06-09 17:12 - 00664064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2015-06-09 17:12 - 2015-06-09 17:12 - 00633856 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieui.dll
2015-06-09 17:12 - 2015-06-09 17:12 - 00620032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll
2015-06-09 17:12 - 2015-06-09 17:12 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2015-06-09 17:12 - 2015-06-09 17:12 - 00503808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2015-06-09 17:12 - 2015-06-09 17:12 - 00374272 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2015-06-09 17:12 - 2015-06-09 17:12 - 00327168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2015-06-09 17:12 - 2015-06-09 17:12 - 00316928 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll
2015-06-09 17:12 - 2015-06-09 17:12 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll
2015-06-09 17:12 - 2015-06-09 17:12 - 00262144 _____ (Microsoft Corporation) C:\WINDOWS\system32\webcheck.dll
2015-06-09 17:12 - 2015-06-09 17:12 - 00145408 _____ (Microsoft Corporation) C:\WINDOWS\system32\iepeers.dll
2015-06-09 17:12 - 2015-06-09 17:12 - 00128000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iepeers.dll
2015-06-09 17:12 - 2015-06-09 17:12 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2015-06-09 17:12 - 2015-06-09 17:12 - 00076288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll
2015-06-09 17:12 - 2015-05-22 23:14 - 00341504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\html.iec
2015-06-09 17:12 - 2015-05-22 15:00 - 00417792 _____ (Microsoft Corporation) C:\WINDOWS\system32\html.iec
2015-06-09 17:10 - 2015-05-21 12:47 - 04177920 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2015-06-03 13:06 - 2015-06-03 13:06 - 00058240 _____ (WN) C:\WINDOWS\system32\Drivers\wfd_1_10_0_17.sys
2015-05-30 18:42 - 2015-04-21 20:37 - 00364472 _____ (Avast Software s.r.o.) C:\WINDOWS\system32\aswBoot.exe
2015-05-19 14:56 - 2015-05-19 14:56 - 11408411 _____ C:\Users\Cassy\Desktop\Brockville Tourism.rar
2015-05-19 14:55 - 2015-05-18 16:31 - 11408330 _____ C:\Users\Cassy\Desktop\Brockville Tourism.odp
2015-05-16 19:09 - 2015-05-16 19:09 - 00000000 ____D C:\Users\Cassy\AppData\Local\CrashDumps
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-06-14 13:48 - 2012-07-07 06:57 - 00000924 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2015-06-14 13:46 - 2014-04-02 02:09 - 01383140 _____ C:\WINDOWS\WindowsUpdate.log
2015-06-14 13:45 - 2013-01-16 23:03 - 00003596 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3775124505-4180658665-910221950-1001
2015-06-14 13:40 - 2014-03-29 19:03 - 00000830 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-06-14 13:32 - 2014-04-02 16:01 - 00003958 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{2F252FFC-BBA2-4DB2-9694-0C83F154B9BB}
2015-06-14 13:32 - 2013-01-03 13:45 - 00000000 ____D C:\Users\Cassy\AppData\Local\Adobe
2015-06-14 13:24 - 2012-07-07 07:01 - 01359738 _____ C:\WINDOWS\system32\fastboot.set
2015-06-14 13:24 - 2012-07-07 06:57 - 00000920 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2015-06-14 13:24 - 2012-07-07 06:43 - 00000000 ____D C:\ProgramData\VeriFace
2015-06-14 13:22 - 2013-08-22 10:45 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-06-14 13:22 - 2012-12-25 21:57 - 00548404 _____ C:\FaceProv.log
2015-06-14 13:21 - 2013-08-22 10:46 - 00450289 _____ C:\WINDOWS\setupact.log
2015-06-14 13:17 - 2014-03-29 18:51 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2015-06-14 13:17 - 2013-11-14 03:20 - 01057778 _____ C:\WINDOWS\PFRO.log
2015-06-14 13:11 - 2014-11-14 18:21 - 00067500 _____ C:\WINDOWS\system32\Drivers\fvstore.dat
2015-06-14 13:11 - 2013-08-22 09:25 - 00262144 ___SH C:\WINDOWS\system32\config\BBI
2015-06-14 13:10 - 2012-12-25 19:47 - 00000000 ____D C:\Users\Cassy\AppData\Roaming\Skype
2015-06-14 13:08 - 2014-05-17 12:48 - 00000000 __SHD C:\Users\Cassy\AppData\Local\EmieUserList
2015-06-14 13:08 - 2014-05-17 12:48 - 00000000 __SHD C:\Users\Cassy\AppData\Local\EmieSiteList
2015-06-14 13:00 - 2013-08-22 11:36 - 00000000 ____D C:\WINDOWS\system32\sru
2015-06-13 20:47 - 2013-08-22 11:36 - 00000000 ____D C:\WINDOWS\AppReadiness
2015-06-13 17:15 - 2013-08-22 10:44 - 05047064 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2015-06-13 17:10 - 2014-12-14 11:20 - 00000000 ____D C:\WINDOWS\system32\appraiser
2015-06-13 17:10 - 2014-07-12 15:12 - 00000000 ___SD C:\WINDOWS\system32\CompatTel
2015-06-13 17:10 - 2013-08-22 11:36 - 00000000 ___RD C:\WINDOWS\ToastData
2015-06-13 17:09 - 2013-08-22 11:36 - 00000000 ____D C:\WINDOWS\PolicyDefinitions
2015-06-11 15:13 - 2014-02-27 17:09 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-06-11 15:12 - 2012-07-07 06:54 - 00000000 ____D C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2015-06-11 15:08 - 2013-11-14 03:17 - 00000000 ____D C:\WINDOWS\ShellNew
2015-06-11 15:07 - 2013-08-22 11:36 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2015-06-10 03:51 - 2012-07-26 03:59 - 00000000 ____D C:\WINDOWS\CbsTemp
2015-06-10 03:45 - 2014-03-04 16:51 - 00000000 ____D C:\WINDOWS\system32\MRT
2015-06-10 03:30 - 2013-02-20 20:54 - 140135120 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2015-06-10 00:54 - 2012-07-07 06:57 - 00002214 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-06-09 17:24 - 2013-11-14 03:23 - 02473472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2015-06-09 13:41 - 2014-03-29 19:03 - 00003718 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2015-06-03 19:22 - 2014-09-22 15:24 - 01474832 _____ C:\WINDOWS\system32\Drivers\sfi.dat
2015-05-31 18:38 - 2014-02-09 11:40 - 00000000 ___RD C:\Program Files (x86)\Skype
2015-05-30 20:35 - 2015-04-08 17:40 - 00000000 ___SD C:\WINDOWS\SysWOW64\GWX
2015-05-30 20:35 - 2015-04-08 17:40 - 00000000 ___SD C:\WINDOWS\system32\GWX
2015-05-30 20:25 - 2014-04-02 01:44 - 00000000 ____D C:\Users\Cassy
2015-05-30 18:43 - 2014-11-16 11:47 - 00001949 _____ C:\Users\Public\Desktop\Avast Free Antivirus.lnk
2015-05-30 18:42 - 2014-09-21 21:14 - 00003924 _____ C:\WINDOWS\System32\Tasks\avast! Emergency Update
2015-05-30 18:34 - 2014-09-22 15:25 - 00000000 ____D C:\WINDOWS\System32\Tasks\COMODO
2015-05-30 18:34 - 2013-08-22 09:36 - 00000000 ____D C:\WINDOWS\system32\Sysprep
2015-05-30 18:34 - 2013-06-23 17:57 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2015-05-30 18:34 - 2013-06-23 17:56 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
2015-05-30 18:34 - 2012-12-25 21:59 - 00000000 ____D C:\Users\Cassy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Lenovo
2015-05-30 18:34 - 2012-12-25 10:04 - 00000000 ____D C:\ProgramData\Energy Management
2015-05-30 18:34 - 2012-07-07 06:57 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-05-30 18:25 - 2013-08-22 11:36 - 00000000 ____D C:\WINDOWS\registration
2015-05-17 04:43 - 2012-07-07 06:57 - 00003896 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2015-05-17 04:43 - 2012-07-07 06:57 - 00003660 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2015-05-15 21:42 - 2013-08-22 11:36 - 00000000 ____D C:\WINDOWS\rescache
2015-05-15 18:34 - 2014-03-01 19:24 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2015-05-15 18:34 - 2014-03-01 19:24 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2015-05-15 18:32 - 2013-08-22 09:25 - 00262144 ___SH C:\WINDOWS\system32\config\BBI(22)
2015-05-15 18:30 - 2013-08-22 11:36 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2015-05-15 18:29 - 2013-08-22 09:36 - 00000000 ____D C:\WINDOWS\system32\AdvancedInstallers
==================== Files in the root of some directories =======
2014-02-23 11:51 - 2014-03-24 15:51 - 0000089 _____ () C:\Users\Cassy\AppData\Roaming\WB.CFG
2014-07-23 18:22 - 2014-09-14 18:35 - 0196608 _____ () C:\Users\Cassy\AppData\Local\nnfflllt.gdb
2014-07-23 18:22 - 2014-09-14 18:35 - 1092180 _____ () C:\Users\Cassy\AppData\Local\nnfflllt.gss
2013-08-08 19:04 - 2013-08-08 19:04 - 0000218 _____ () C:\Users\Cassy\AppData\Local\recently-used.xbel
Some files in TEMP:
====================
C:\Users\Cassy\AppData\Local\Temp\dlLogic.exe
C:\Users\Cassy\AppData\Local\Temp\spstub.exe
C:\Users\Cassy\AppData\Local\Temp\Uninstall.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-06-06 04:28
==================== End of log ============================
Sorry, having to post this in two parts, its too big for just the one.
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:13-06-2015
Ran by Sollux Captor (administrator) on CASSY-PC on 14-06-2015 13:52:30
Running from C:\Users\Cassy\Desktop
Loaded Profiles: Sollux Captor (Available Profiles: Sollux Captor)
Platform: Windows 8.1 Pro (X64) OS Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Comodo Security Solutions, Inc.) C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\WTabletServiceCon.exe
(Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cistray.exe
(Nico Mak Computing) C:\Program Files (x86)\WinZip Malware Protector\WinZipMalwareProtector.exe
() C:\Program Files (x86)\OneSystemCare\CleanupConsole.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
(Conexant Systems Inc.) C:\Windows\System32\CxAudMsg64.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Comodo Security Solutions, Inc.) C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exe
(Comodo Security Solutions, Inc.) C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe
() C:\Program Files\015\lxqvbcbiws32.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
(WN) C:\Program Files (x86)\Wordinator_1.10.0.17\Service\wsvc.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cavwp.exe
() C:\Program Files (x86)\Super Optimizer\SupOptSmartScan.exe
(CyberLink) C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\Pen_TabletUser.exe
(Wacom Technology) C:\Program Files\Tablet\Pen\WacomHost.exe
(Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe
(Lenovo (Beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\Pen_Tablet.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Pen\Pen_TouchUser.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\utility.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
( ) C:\Program Files (x86)\LockKey\LockKey.exe
(Lenovo) C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe
(Avast Software s.r.o.) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cis.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe
() C:\Program Files (x86)\ControlThis Parental Control\CloudNATIONAL.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cmdupd.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cavwp.exe
() C:\Program Files (x86)\Reg Pro Cleaner\Regprocleaner.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2809856 2012-01-16] (ELAN Microelectronics Corp.)
HKLM\...\Run: [cAudioFilterAgent] => C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [564352 2012-03-01] (Conexant Systems, Inc.)
HKLM\...\Run: [Energy Management] => C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [8071680 2012-07-07] (Lenovo (Beijing) Limited)
HKLM\...\Run: [EnergyUtility] => C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe [6193152 2012-07-07] (Lenovo(beijing) Limited)
HKLM\...\Run: [Lenovo EE Boot Optimizer] => C:\Program Files (x86)\Lenovo\Boot Optimizer\PopWnd.exe [206176 2012-07-07] (Lenovo)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [472984 2013-06-13] (Adobe Systems Incorporated)
HKLM\...\Run: [COMODO Internet Security] => C:\Program Files\COMODO\COMODO Internet Security\cistray.exe [1426136 2015-04-22] (COMODO)
HKLM-x32\...\Run: [332BigDog] => C:\Program Files (x86)\USB Camera2\VM332_STI.EXE [548864 2011-12-09] (Vimicro)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [LockKey] => C:\Program Files (x86)\LockKey\LockKey.exe [337776 2011-08-25] ( )
HKLM-x32\...\Run: [UpdatePRCShortCut] => C:\Program Files\Lenovo\OneKey App\OneKey Recovery\MUITransfer\MUIStartMenu.exe [222504 2009-05-13] (CyberLink Corp.)
HKLM-x32\...\Run: [VeriFaceManager] => C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe [329056 2012-07-07] (Lenovo)
HKLM-x32\...\Run: [YouCam Mirage] => C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe [136488 2011-01-29] (CyberLink)
HKLM-x32\...\Run: [YouCam Tray] => C:\Program Files (x86)\Lenovo\YouCam\YouCam.exe [228448 2011-01-29] (CyberLink Corp.)
HKLM-x32\...\Run: [BambooCore] => C:\Program Files (x86)\Bamboo Dock\BambooCore.exe [646744 2012-10-16] ()
HKLM-x32\...\Run: [Adobe Creative Cloud] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2236816 2013-08-08] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [4101584 2014-04-25] (Safer-Networking Ltd.)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5515496 2015-04-21] (Avast Software s.r.o.)
HKLM-x32\...\Run: [ComodoFSChrome] => "C:\Program Files (x86)\AdTrustMedia\PrivDog\FinalizeSetup.exe" /c
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766688 2015-02-22] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [tvncontrol] => C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe [2327248 2015-03-09] (Comodo Security Solutions, Inc.)
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
HKU\S-1-5-21-3775124505-4180658665-910221950-1001\...\Run: [GoogleChromeAutoLaunch_36970D3059E4608AE74B88E09A7E6CB3] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [813896 2015-06-10] (Google Inc.)
HKU\S-1-5-21-3775124505-4180658665-910221950-1001\...\Run: [Spybot-S&D Cleaning] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe [4566984 2014-04-25] (Safer-Networking Ltd.)
HKU\S-1-5-21-3775124505-4180658665-910221950-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [30877280 2014-12-11] (Skype Technologies S.A.)
HKU\S-1-5-21-3775124505-4180658665-910221950-1001\...\Run: [Super Optimizer] => C:\Program Files (x86)\Super Optimizer\SupOptLauncher.exe [676400 2015-06-11] ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2014-10-27]
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.8.150\SSScheduler.exe (McAfee, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Start GeekBuddy.lnk [2015-03-09]
ShortcutTarget: Start GeekBuddy.lnk -> C:\Program Files\COMODO\GeekBuddy\launcher.exe (Comodo Security Solutions, Inc.)
Startup: C:\Users\Cassy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\nnfflllt.lnk [2014-07-23]
ShortcutTarget: nnfflllt.lnk -> C:\Users\Cassy\AppData\Local\nnfflllt.exe (No File)
ShellIconOverlayIdentifiers: [ AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_v_1_1_0_x64.dll [2013-07-31] ()
ShellIconOverlayIdentifiers: [ AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_v_1_1_0_x64.dll [2013-07-31] ()
ShellIconOverlayIdentifiers: [ AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_v_1_1_0_x64.dll [2013-07-31] ()
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2015-04-21] (Avast Software s.r.o.)
ShellIconOverlayIdentifiers: [VeriFace Enc] -> {771C7324-DA80-49D3-8017-753B0AF60951} => C:\Windows\system32\IcnOvrly.dll [2012-07-07] ()
BootExecute: autocheck autochk * sdnclean64.exe
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
HKU\S-1-5-21-3775124505-4180658665-910221950-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig/redirectdomain?brand=LENN&bmod=LENN
HKU\S-1-5-21-3775124505-4180658665-910221950-1001\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.ca/
SearchScopes: HKU\S-1-5-21-3775124505-4180658665-910221950-1001 -> DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7LENN
SearchScopes: HKU\S-1-5-21-3775124505-4180658665-910221950-1001 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = http://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7LENN
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-04-21] (Avast Software s.r.o.)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-05-01] (Microsoft Corporation)
BHO-x32: MSS+ Identifier -> {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} -> C:\Program Files\McAfee Security Scan\3.8.150\McAfeeMSS_IE.dll [2014-04-09] (McAfee, Inc.)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll [2015-01-25] (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-04-21] (Avast Software s.r.o.)
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-01-25] (Oracle Corporation)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-05-01] (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01] (Microsoft Corporation)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{45A70356-416B-4B42-8DB5-E3519E992D34}: [NameServer] 81.218.119.5,82.163.142.130
Tcpip\..\Interfaces\{B2A0856A-8ECE-4677-89A0-7FBDCE102A88}: [NameServer] 81.218.119.5,82.163.142.130
FireFox:
========
FF ProfilePath: C:\Users\Cassy\AppData\Roaming\Mozilla\Firefox\Profiles\4fgio0ge.default-1416152417215
FF DefaultSearchEngine: Google (avast)
FF DefaultSearchEngine.US: Google (avast)
FF DefaultSearchUrl: https://www.google.com/search/?trackid=sp-006
FF SearchEngineOrder.1: Google (avast)
FF SelectedSearchEngine: Google (avast)
FF Homepage: https://www.google.com/?trackid=sp-006
FF Keyword.URL: https://www.google.com/search/?trackid=sp-006
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_17_0_0_188.dll [2015-06-09] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-16] ( Microsoft Corporation)
FF Plugin: @wacom.com/wtPlugin,version=2.1.0.2 -> C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll [2012-05-23] (Wacom)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2013-08-08] (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_188.dll [2015-06-09] ()
FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 -> C:\WINDOWS\SysWOW64\npDeployJava1.dll [2013-06-23] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-01-25] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-17] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-17] (Google Inc.)
FF Plugin-x32: @wacom.com/wtPlugin,version=2.1.0.2 -> C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll [2012-05-23] (Wacom)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2014-05-08] (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2013-08-08] (Adobe Systems)
FF Plugin-x32: adobe.com/AdobeExManDetect -> C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\npAdobeExManDetectX86.dll No File
FF Plugin HKU\S-1-5-21-3775124505-4180658665-910221950-1001: wacom.com/WacomTabletPlugin -> C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll [2012-05-23] (Wacom)
FF SearchPlugin: C:\Users\Cassy\AppData\Roaming\Mozilla\Firefox\Profiles\4fgio0ge.default-1416152417215\searchplugins\google-avast.xml [2014-12-12]
FF Extension: NoScript - C:\Users\Cassy\AppData\Roaming\Mozilla\Firefox\Profiles\4fgio0ge.default-1416152417215\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2014-11-16]
FF Extension: Adblock Plus - C:\Users\Cassy\AppData\Roaming\Mozilla\Firefox\Profiles\4fgio0ge.default-1416152417215\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-11-28]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-09-21]
FF HKU\S-1-5-21-3775124505-4180658665-910221950-1001\...\Firefox\Extensions: [{e4f94d1e-2f53-401e-8885-681602c0ddd8}] - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi
FF Extension: No Name - C:\ProgramData\McAfee Security Scan\Extensions\{e4f94d1e-2f53-401e-8885-681602c0ddd8}.xpi [2014-04-04]
Chrome:
=======
CHR Profile: C:\Users\Cassy\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Bookmark Manager) - C:\Users\Cassy\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmlllbghnfkpflemihljekbapjopfjik [2015-06-14]
CHR Extension: (Avast Online Security) - C:\Users\Cassy\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2014-09-22]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Cassy\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-06-03]
CHR Extension: (Skype Click to Call) - C:\Users\Cassy\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2014-02-09]
CHR Extension: (Google Wallet) - C:\Users\Cassy\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-09-10]
CHR HKLM-x32\...\Chrome\Extension: [bopakagnckmlgajfccecajhnimjiiedh] - http://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-04-21]
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2015-05-01]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [344064 2015-02-22] (Advanced Micro Devices, Inc.) [File not signed]
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [343336 2015-04-21] (Avast Software s.r.o.)
S3 BthHFSrv; C:\Windows\System32\BthHFSrv.dll [324608 2015-03-03] (Microsoft Corporation)
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1394816 2015-05-31] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1772672 2015-05-31] (Microsoft Corporation)
S2 cae99edb; c:\Program Files (x86)\Super Optimizer\SupOptStats.dll [3117104 2015-06-11] ()
R2 CLPSLauncher; C:\Program Files (x86)\Common Files\COMODO\launcher_service.exe [70872 2015-03-09] (Comodo Security Solutions, Inc.)
R2 CmdAgent; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [5540424 2015-04-22] (COMODO)
S3 cmdvirth; C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe [2265816 2015-04-22] (COMODO)
R2 DragonUpdater; C:\Program Files (x86)\Comodo\Dragon\dragon_updater.exe [2370240 2014-11-27] (Comodo Security Solutions, Inc.)
R2 GeekBuddyRSP; C:\Program Files (x86)\Common Files\COMODO\GeekBuddyRSP.exe [2327248 2015-03-09] (Comodo Security Solutions, Inc.)
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [73728 2004-10-22] (Macrovision Corporation) [File not signed]
R2 lxqvbcbiws32; C:\Program Files\015\lxqvbcbiws32.exe [622392 2015-06-14] ()
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [289256 2014-04-09] (McAfee, Inc.)
R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1738200 2014-04-25] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2081752 2014-04-25] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2014-04-25] (Safer-Networking Ltd.)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366520 2015-03-11] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2015-03-11] (Microsoft Corporation)
R2 wsvc_1.10.0.17; C:\Program Files (x86)\Wordinator_1.10.0.17\Service\wsvc.exe [278616 2015-06-11] (WN)
R2 WTabletServiceCon; C:\Program Files\Tablet\Pen\WTabletServiceCon.exe [619904 2012-11-14] (Wacom Technology, Corp.)
S3 AvastVBoxSvc; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [X]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 Apowersoft_AudioDevice; C:\Windows\system32\drivers\Apowersoft_AudioDevice.sys [31968 2012-10-08] (Wondershare)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29168 2015-04-21] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [89944 2015-04-21] (Avast Software s.r.o.)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-04-21] (Avast Software s.r.o.)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65736 2015-04-21] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1047320 2015-04-21] (Avast Software s.r.o.)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [442264 2015-04-21] (Avast Software s.r.o.)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [137288 2015-04-21] (Avast Software s.r.o.)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [272248 2015-04-21] ()
R3 athr; C:\Windows\system32\DRIVERS\athwnx.sys [3680256 2013-06-18] (Qualcomm Atheros Communications, Inc.)
R1 CFRMD; C:\Windows\System32\DRIVERS\CFRMD.sys [40224 2014-06-26] (Windows (R) Win 7 DDK provider)
R1 cmderd; C:\Windows\System32\DRIVERS\cmderd.sys [20696 2015-04-01] (COMODO)
R1 cmdGuard; C:\Windows\System32\DRIVERS\cmdguard.sys [820952 2015-04-01] (COMODO)
R1 cmdhlp; C:\Windows\system32\DRIVERS\cmdhlp.sys [35080 2015-04-01] (COMODO)
S3 dot4; C:\Windows\system32\DRIVERS\Dot4.sys [151968 2012-10-19] (Windows (R) Win 7 DDK provider)
S3 Dot4Print; C:\Windows\System32\drivers\Dot4Prt.sys [27040 2012-10-19] (Windows (R) Win 7 DDK provider)
R1 HMD; C:\Windows\system32\DRIVERS\hmd.sys [14888 2014-06-26] ()
R1 inspect; C:\Windows\system32\DRIVERS\inspect.sys [126720 2015-04-01] (COMODO)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2015-03-11] (Microsoft Corporation)
R1 wfd_1_10_0_17; C:\Windows\System32\drivers\wfd_1_10_0_17.sys [58240 2015-06-03] (WN)
S3 MBAMSwissArmy; \??\C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [X]
U4 VBoxAswDrv; \??\C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-06-14 13:52 - 2015-06-14 13:54 - 00023299 _____ C:\Users\Cassy\Desktop\FRST.txt
2015-06-14 13:52 - 2015-06-14 13:53 - 05198336 _____ (AVAST Software) C:\Users\Cassy\Desktop\aswMBR.exe
2015-06-14 13:49 - 2015-06-14 13:52 - 00000000 ____D C:\FRST
2015-06-14 13:46 - 2015-06-14 13:46 - 00000207 _____ C:\WINDOWS\tweaking.com-regbackup-CASSY-PC-Windows-8.1-Pro-(64-bit).dat
2015-06-14 13:40 - 2015-06-14 13:40 - 00002262 _____ C:\Users\Public\Desktop\Tweaking.com - Registry Backup.lnk
2015-06-14 13:40 - 2015-06-14 13:40 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tweaking.com
2015-06-14 13:35 - 2015-06-14 13:35 - 02109952 _____ (Farbar) C:\Users\Cassy\Desktop\FRST64.exe
2015-06-14 13:33 - 2015-06-14 13:35 - 04720448 _____ C:\Users\Cassy\Desktop\tweaking.com_registry_backup_setup(1).exe
2015-06-14 13:18 - 2015-06-14 13:18 - 00000000 ____D C:\Users\Cassy\AppData\Roaming\One System Care
2015-06-14 13:11 - 2015-06-14 13:11 - 00003238 _____ C:\WINDOWS\System32\Tasks\RPC
2015-06-14 13:09 - 2015-06-14 13:22 - 00000310 _____ C:\WINDOWS\Tasks\One System CareStartUp.job
2015-06-14 13:09 - 2015-06-14 13:17 - 00000310 _____ C:\WINDOWS\Tasks\One System CarePeriod.job
2015-06-14 13:09 - 2015-06-14 13:09 - 00002876 _____ C:\WINDOWS\System32\Tasks\One System CarePeriod
2015-06-14 13:09 - 2015-06-14 13:09 - 00002580 _____ C:\WINDOWS\System32\Tasks\One System CareStartUp
2015-06-14 13:09 - 2015-06-14 13:09 - 00000000 ____D C:\Users\Cassy\AppData\Roaming\VOPackage
2015-06-14 13:09 - 2015-06-14 13:09 - 00000000 ____D C:\Users\Cassy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VOPackage
2015-06-14 13:09 - 2015-06-14 13:09 - 00000000 ____D C:\Users\Cassy\AppData\Roaming\15586344-1434301786-E111-984C-DC0EA1FBF0C7
2015-06-14 13:08 - 2015-06-14 13:09 - 00000000 ____D C:\Program Files (x86)\OneSystemCare
2015-06-14 13:08 - 2015-06-14 13:08 - 00003342 _____ C:\WINDOWS\System32\Tasks\One System Care Run Delay
2015-06-14 13:08 - 2015-06-14 13:08 - 00003276 _____ C:\WINDOWS\System32\Tasks\One System Care Monitor
2015-06-14 13:08 - 2015-06-14 13:08 - 00001090 _____ C:\Users\Public\Desktop\Launch One System Care.lnk
2015-06-14 13:08 - 2015-06-14 13:08 - 00001030 _____ C:\Users\Cassy\Desktop\GUPlayer.lnk
2015-06-14 13:08 - 2015-06-14 13:08 - 00000000 ____D C:\Users\Cassy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GUPlayer
2015-06-14 13:08 - 2015-06-14 13:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneSystemCare
2015-06-14 13:08 - 2015-06-14 13:08 - 00000000 ____D C:\Program Files (x86)\GUPlayer
2015-06-14 13:07 - 2015-06-14 13:08 - 00000000 ____D C:\Program Files (x86)\ControlThis Parental Control
2015-06-14 13:07 - 2015-06-14 13:07 - 00026434 _____ C:\WINDOWS\System32\Tasks\CloudNATIONAL
2015-06-14 13:07 - 2015-06-14 13:07 - 00001220 _____ C:\Users\Public\Desktop\Reg Pro Cleaner.lnk
2015-06-14 13:07 - 2015-06-14 13:07 - 00001042 _____ C:\Users\Cassy\Desktop\PepperZip.lnk
2015-06-14 13:07 - 2015-06-14 13:07 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Reg Pro Cleaner
2015-06-14 13:07 - 2015-06-14 13:07 - 00000000 ____D C:\Program Files (x86)\Reg Pro Cleaner
2015-06-14 13:06 - 2015-06-14 13:07 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PepperZip
2015-06-14 13:06 - 2015-06-14 13:07 - 00000000 ____D C:\Program Files (x86)\PepperZip
2015-06-14 13:06 - 2015-06-14 13:06 - 00000000 ____D C:\Users\Cassy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PepperZip
2015-06-14 13:06 - 2015-06-14 13:06 - 00000000 ____D C:\Program Files\13
2015-06-14 13:06 - 2015-06-14 13:06 - 00000000 ____D C:\Program Files\015
2015-06-14 13:05 - 2015-06-14 13:05 - 00001739 _____ C:\Users\Cassy\Desktop\Continue Microsoft PowerPoint.lnk
2015-06-14 13:04 - 2015-06-14 13:04 - 00670816 _____ ( ) C:\Users\Cassy\Downloads\Microsoft PowerPoint.exe
2015-06-13 17:17 - 2015-06-09 17:20 - 00792568 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2015-06-13 17:17 - 2015-06-09 17:20 - 00178168 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2015-06-11 15:31 - 2015-06-14 13:28 - 00003280 _____ C:\WINDOWS\System32\Tasks\Super Optimizer Schedule
2015-06-11 15:31 - 2015-06-11 15:31 - 00000000 ____D C:\Users\Cassy\Documents\Super Optimizer
2015-06-11 15:31 - 2015-06-11 15:31 - 00000000 ____D C:\Users\Cassy\AppData\Roaming\Super Optimizer
2015-06-11 15:25 - 2015-06-14 13:28 - 00003116 _____ C:\WINDOWS\System32\Tasks\WinZip Malware Protector_startup
2015-06-11 15:24 - 2015-06-11 15:24 - 00000000 ____D C:\Users\Cassy\AppData\Roaming\Nico Mak Computing
2015-06-11 15:22 - 2015-06-14 12:49 - 00000000 ____D C:\Program Files (x86)\Super Optimizer
2015-06-11 15:22 - 2015-06-11 15:22 - 00000000 ____D C:\ProgramData\Nico Mak Computing
2015-06-11 15:22 - 2015-06-11 15:22 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZip Malware Protector
2015-06-11 15:22 - 2015-06-11 15:22 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Super Optimizer
2015-06-11 15:22 - 2015-06-11 15:22 - 00000000 ____D C:\Program Files (x86)\Wordinator_1.10.0.17
2015-06-11 15:22 - 2015-06-11 15:22 - 00000000 ____D C:\Program Files (x86)\WinZip Malware Protector
2015-06-11 15:22 - 2015-03-17 11:03 - 00020480 _____ C:\WINDOWS\system32\wsusnative64.exe
2015-06-11 15:16 - 2015-06-11 15:17 - 00736552 _____ (Web Application ) C:\Users\Cassy\Downloads\Malavida_Download_Manager(1).exe
2015-06-11 15:05 - 2015-06-14 13:17 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2015-06-10 03:30 - 2015-06-10 03:45 - 00000000 ____D C:\6b423640a31629c8fbf21cb2
2015-06-09 17:30 - 2015-06-09 17:30 - 01119232 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2015-06-09 17:30 - 2015-06-09 17:30 - 01020928 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2015-06-09 17:30 - 2015-06-09 17:30 - 00756736 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2015-06-09 17:30 - 2015-06-09 17:30 - 00700416 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2015-06-09 17:30 - 2015-06-09 17:30 - 00422912 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2015-06-09 17:30 - 2015-06-09 17:30 - 00227328 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepdu.dll
2015-06-09 17:30 - 2015-06-09 17:30 - 00193536 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll
2015-06-09 17:30 - 2015-06-09 17:30 - 00045568 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2015-06-09 17:30 - 2015-04-08 18:07 - 00410336 _____ C:\WINDOWS\system32\ApnDatabase.xml
2015-06-09 17:24 - 2015-06-09 17:24 - 01091072 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll
2015-06-09 17:24 - 2015-06-09 17:24 - 00477184 _____ (Microsoft Corporation) C:\WINDOWS\system32\puiobj.dll
2015-06-09 17:24 - 2015-06-09 17:24 - 00367104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\puiobj.dll
2015-06-09 17:24 - 2015-06-09 17:24 - 00309760 _____ (Microsoft Corporation) C:\WINDOWS\system32\compstui.dll
2015-06-09 17:24 - 2015-06-09 17:24 - 00222208 _____ (Microsoft Corporation) C:\WINDOWS\system32\rastapi.dll
2015-06-09 17:24 - 2015-06-09 17:24 - 00207872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rastapi.dll
2015-06-09 17:20 - 2015-05-25 09:23 - 00036864 _____ (Microsoft Corporation) C:\WINDOWS\system32\UtcResources.dll
2015-06-09 17:20 - 2015-05-25 09:07 - 01430528 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2015-06-09 17:20 - 2015-04-08 18:41 - 00158720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rgb9rast.dll
2015-06-09 17:20 - 2015-04-01 18:42 - 03097600 _____ (Microsoft Corporation) C:\WINDOWS\system32\msftedit.dll
2015-06-09 17:20 - 2015-04-01 18:30 - 02483712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msftedit.dll
2015-06-09 17:13 - 2015-06-09 17:13 - 24917504 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2015-06-09 17:13 - 2015-06-09 17:13 - 19607040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2015-06-09 17:13 - 2015-06-09 17:13 - 12829696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2015-06-09 17:13 - 2015-06-09 17:13 - 06026240 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2015-06-09 17:13 - 2015-06-09 17:13 - 02426880 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2015-06-09 17:13 - 2015-06-09 17:13 - 01018880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll
2015-06-09 17:13 - 2015-06-09 17:13 - 00653824 _____ (Microsoft Corporation) C:\WINDOWS\system32\comctl32.dll
2015-06-09 17:13 - 2015-06-09 17:13 - 00549888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comctl32.dll
2015-06-09 17:13 - 2015-04-16 02:17 - 00325464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS
2015-06-09 17:13 - 2015-04-13 18:37 - 00275968 _____ (Microsoft Corporation) C:\WINDOWS\system32\authz.dll
2015-06-09 17:13 - 2015-04-13 18:34 - 00180224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authz.dll
2015-06-09 17:13 - 2015-04-09 20:40 - 01249280 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll
2015-06-09 17:13 - 2015-04-01 00:21 - 00337408 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchProtocolHost.exe
2015-06-09 17:13 - 2015-04-01 00:18 - 00468480 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssph.dll
2015-06-09 17:13 - 2015-04-01 00:17 - 00248832 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssphtb.dll
2015-06-09 17:13 - 2015-04-01 00:08 - 00774144 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssvp.dll
2015-06-09 17:13 - 2015-03-31 23:46 - 03633664 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll
2015-06-09 17:13 - 2015-03-31 23:17 - 02551808 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssrch.dll
2015-06-09 17:13 - 2015-03-31 23:17 - 00903168 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchIndexer.exe
2015-06-09 17:13 - 2015-03-31 22:53 - 00391680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssph.dll
2015-06-09 17:13 - 2015-03-31 22:53 - 00272896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchProtocolHost.exe
2015-06-09 17:13 - 2015-03-31 22:45 - 02749952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll
2015-06-09 17:13 - 2015-03-31 22:45 - 00699392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssvp.dll
2015-06-09 17:13 - 2015-03-31 22:14 - 01920000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssrch.dll
2015-06-09 17:13 - 2015-03-31 22:12 - 00710144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchIndexer.exe
2015-06-09 17:12 - 2015-06-09 17:13 - 14404096 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2015-06-09 17:12 - 2015-06-09 17:13 - 04305920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2015-06-09 17:12 - 2015-06-09 17:13 - 02885632 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2015-06-09 17:12 - 2015-06-09 17:13 - 02278912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2015-06-09 17:12 - 2015-06-09 17:13 - 01950720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2015-06-09 17:12 - 2015-06-09 17:13 - 01545728 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2015-06-09 17:12 - 2015-06-09 17:13 - 01309696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2015-06-09 17:12 - 2015-06-09 17:12 - 02865152 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll
2015-06-09 17:12 - 2015-06-09 17:12 - 02125824 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2015-06-09 17:12 - 2015-06-09 17:12 - 02052608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2015-06-09 17:12 - 2015-06-09 17:12 - 01042944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll
2015-06-09 17:12 - 2015-06-09 17:12 - 01032704 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll
2015-06-09 17:12 - 2015-06-09 17:12 - 00880128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcomm.dll
2015-06-09 17:12 - 2015-06-09 17:12 - 00816640 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2015-06-09 17:12 - 2015-06-09 17:12 - 00814080 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll
2015-06-09 17:12 - 2015-06-09 17:12 - 00801280 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2015-06-09 17:12 - 2015-06-09 17:12 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2015-06-09 17:12 - 2015-06-09 17:12 - 00710144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2015-06-09 17:12 - 2015-06-09 17:12 - 00689152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2015-06-09 17:12 - 2015-06-09 17:12 - 00664064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2015-06-09 17:12 - 2015-06-09 17:12 - 00633856 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieui.dll
2015-06-09 17:12 - 2015-06-09 17:12 - 00620032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll
2015-06-09 17:12 - 2015-06-09 17:12 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2015-06-09 17:12 - 2015-06-09 17:12 - 00503808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2015-06-09 17:12 - 2015-06-09 17:12 - 00374272 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2015-06-09 17:12 - 2015-06-09 17:12 - 00327168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2015-06-09 17:12 - 2015-06-09 17:12 - 00316928 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll
2015-06-09 17:12 - 2015-06-09 17:12 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll
2015-06-09 17:12 - 2015-06-09 17:12 - 00262144 _____ (Microsoft Corporation) C:\WINDOWS\system32\webcheck.dll
2015-06-09 17:12 - 2015-06-09 17:12 - 00145408 _____ (Microsoft Corporation) C:\WINDOWS\system32\iepeers.dll
2015-06-09 17:12 - 2015-06-09 17:12 - 00128000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iepeers.dll
2015-06-09 17:12 - 2015-06-09 17:12 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2015-06-09 17:12 - 2015-06-09 17:12 - 00076288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll
2015-06-09 17:12 - 2015-05-22 23:14 - 00341504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\html.iec
2015-06-09 17:12 - 2015-05-22 15:00 - 00417792 _____ (Microsoft Corporation) C:\WINDOWS\system32\html.iec
2015-06-09 17:10 - 2015-05-21 12:47 - 04177920 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2015-06-03 13:06 - 2015-06-03 13:06 - 00058240 _____ (WN) C:\WINDOWS\system32\Drivers\wfd_1_10_0_17.sys
2015-05-30 18:42 - 2015-04-21 20:37 - 00364472 _____ (Avast Software s.r.o.) C:\WINDOWS\system32\aswBoot.exe
2015-05-19 14:56 - 2015-05-19 14:56 - 11408411 _____ C:\Users\Cassy\Desktop\Brockville Tourism.rar
2015-05-19 14:55 - 2015-05-18 16:31 - 11408330 _____ C:\Users\Cassy\Desktop\Brockville Tourism.odp
2015-05-16 19:09 - 2015-05-16 19:09 - 00000000 ____D C:\Users\Cassy\AppData\Local\CrashDumps
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-06-14 13:48 - 2012-07-07 06:57 - 00000924 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2015-06-14 13:46 - 2014-04-02 02:09 - 01383140 _____ C:\WINDOWS\WindowsUpdate.log
2015-06-14 13:45 - 2013-01-16 23:03 - 00003596 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3775124505-4180658665-910221950-1001
2015-06-14 13:40 - 2014-03-29 19:03 - 00000830 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-06-14 13:32 - 2014-04-02 16:01 - 00003958 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{2F252FFC-BBA2-4DB2-9694-0C83F154B9BB}
2015-06-14 13:32 - 2013-01-03 13:45 - 00000000 ____D C:\Users\Cassy\AppData\Local\Adobe
2015-06-14 13:24 - 2012-07-07 07:01 - 01359738 _____ C:\WINDOWS\system32\fastboot.set
2015-06-14 13:24 - 2012-07-07 06:57 - 00000920 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2015-06-14 13:24 - 2012-07-07 06:43 - 00000000 ____D C:\ProgramData\VeriFace
2015-06-14 13:22 - 2013-08-22 10:45 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-06-14 13:22 - 2012-12-25 21:57 - 00548404 _____ C:\FaceProv.log
2015-06-14 13:21 - 2013-08-22 10:46 - 00450289 _____ C:\WINDOWS\setupact.log
2015-06-14 13:17 - 2014-03-29 18:51 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2015-06-14 13:17 - 2013-11-14 03:20 - 01057778 _____ C:\WINDOWS\PFRO.log
2015-06-14 13:11 - 2014-11-14 18:21 - 00067500 _____ C:\WINDOWS\system32\Drivers\fvstore.dat
2015-06-14 13:11 - 2013-08-22 09:25 - 00262144 ___SH C:\WINDOWS\system32\config\BBI
2015-06-14 13:10 - 2012-12-25 19:47 - 00000000 ____D C:\Users\Cassy\AppData\Roaming\Skype
2015-06-14 13:08 - 2014-05-17 12:48 - 00000000 __SHD C:\Users\Cassy\AppData\Local\EmieUserList
2015-06-14 13:08 - 2014-05-17 12:48 - 00000000 __SHD C:\Users\Cassy\AppData\Local\EmieSiteList
2015-06-14 13:00 - 2013-08-22 11:36 - 00000000 ____D C:\WINDOWS\system32\sru
2015-06-13 20:47 - 2013-08-22 11:36 - 00000000 ____D C:\WINDOWS\AppReadiness
2015-06-13 17:15 - 2013-08-22 10:44 - 05047064 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2015-06-13 17:10 - 2014-12-14 11:20 - 00000000 ____D C:\WINDOWS\system32\appraiser
2015-06-13 17:10 - 2014-07-12 15:12 - 00000000 ___SD C:\WINDOWS\system32\CompatTel
2015-06-13 17:10 - 2013-08-22 11:36 - 00000000 ___RD C:\WINDOWS\ToastData
2015-06-13 17:09 - 2013-08-22 11:36 - 00000000 ____D C:\WINDOWS\PolicyDefinitions
2015-06-11 15:13 - 2014-02-27 17:09 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-06-11 15:12 - 2012-07-07 06:54 - 00000000 ____D C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2015-06-11 15:08 - 2013-11-14 03:17 - 00000000 ____D C:\WINDOWS\ShellNew
2015-06-11 15:07 - 2013-08-22 11:36 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2015-06-10 03:51 - 2012-07-26 03:59 - 00000000 ____D C:\WINDOWS\CbsTemp
2015-06-10 03:45 - 2014-03-04 16:51 - 00000000 ____D C:\WINDOWS\system32\MRT
2015-06-10 03:30 - 2013-02-20 20:54 - 140135120 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2015-06-10 00:54 - 2012-07-07 06:57 - 00002214 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-06-09 17:24 - 2013-11-14 03:23 - 02473472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2015-06-09 13:41 - 2014-03-29 19:03 - 00003718 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2015-06-03 19:22 - 2014-09-22 15:24 - 01474832 _____ C:\WINDOWS\system32\Drivers\sfi.dat
2015-05-31 18:38 - 2014-02-09 11:40 - 00000000 ___RD C:\Program Files (x86)\Skype
2015-05-30 20:35 - 2015-04-08 17:40 - 00000000 ___SD C:\WINDOWS\SysWOW64\GWX
2015-05-30 20:35 - 2015-04-08 17:40 - 00000000 ___SD C:\WINDOWS\system32\GWX
2015-05-30 20:25 - 2014-04-02 01:44 - 00000000 ____D C:\Users\Cassy
2015-05-30 18:43 - 2014-11-16 11:47 - 00001949 _____ C:\Users\Public\Desktop\Avast Free Antivirus.lnk
2015-05-30 18:42 - 2014-09-21 21:14 - 00003924 _____ C:\WINDOWS\System32\Tasks\avast! Emergency Update
2015-05-30 18:34 - 2014-09-22 15:25 - 00000000 ____D C:\WINDOWS\System32\Tasks\COMODO
2015-05-30 18:34 - 2013-08-22 09:36 - 00000000 ____D C:\WINDOWS\system32\Sysprep
2015-05-30 18:34 - 2013-06-23 17:57 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2015-05-30 18:34 - 2013-06-23 17:56 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
2015-05-30 18:34 - 2012-12-25 21:59 - 00000000 ____D C:\Users\Cassy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Lenovo
2015-05-30 18:34 - 2012-12-25 10:04 - 00000000 ____D C:\ProgramData\Energy Management
2015-05-30 18:34 - 2012-07-07 06:57 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-05-30 18:25 - 2013-08-22 11:36 - 00000000 ____D C:\WINDOWS\registration
2015-05-17 04:43 - 2012-07-07 06:57 - 00003896 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2015-05-17 04:43 - 2012-07-07 06:57 - 00003660 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2015-05-15 21:42 - 2013-08-22 11:36 - 00000000 ____D C:\WINDOWS\rescache
2015-05-15 18:34 - 2014-03-01 19:24 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2015-05-15 18:34 - 2014-03-01 19:24 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2015-05-15 18:32 - 2013-08-22 09:25 - 00262144 ___SH C:\WINDOWS\system32\config\BBI(22)
2015-05-15 18:30 - 2013-08-22 11:36 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2015-05-15 18:29 - 2013-08-22 09:36 - 00000000 ____D C:\WINDOWS\system32\AdvancedInstallers
==================== Files in the root of some directories =======
2014-02-23 11:51 - 2014-03-24 15:51 - 0000089 _____ () C:\Users\Cassy\AppData\Roaming\WB.CFG
2014-07-23 18:22 - 2014-09-14 18:35 - 0196608 _____ () C:\Users\Cassy\AppData\Local\nnfflllt.gdb
2014-07-23 18:22 - 2014-09-14 18:35 - 1092180 _____ () C:\Users\Cassy\AppData\Local\nnfflllt.gss
2013-08-08 19:04 - 2013-08-08 19:04 - 0000218 _____ () C:\Users\Cassy\AppData\Local\recently-used.xbel
Some files in TEMP:
====================
C:\Users\Cassy\AppData\Local\Temp\dlLogic.exe
C:\Users\Cassy\AppData\Local\Temp\spstub.exe
C:\Users\Cassy\AppData\Local\Temp\Uninstall.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-06-06 04:28
==================== End of log ============================