FRST . txt
[removed]
Platform: Windows 8.1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
() C:\ProgramData\DatacardService\HWDeviceService64.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Lenovo(beijing) Limited) C:\Windows\System32\LenovoWiFiHotspotSvr.exe
(Lenovo) C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LsvUIService.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
() C:\ProgramData\Mobile Partner\OnlineUpdate\ouc.exe
(PointGrab LTD) C:\Program Files (x86)\Lenovo\Motion Control\PGService.exe
(PointGrab LTD) C:\Program Files (x86)\Lenovo\Motion Control\PG_Service_Launcher.exe
(Lenovo) C:\Program Files\Lenovo Yoga PhoneCompanion\PhoneCompanionPusher.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(PointGrab LTD) C:\Program Files (x86)\Lenovo\Motion Control\WebcamSplitterServer.exe
() C:\Program Files\CyberLink\Shared files\RichVideo64.exe
() C:\Program Files (x86)\Lenovo\Lenovo VeriFace Pro\VfConnectorService.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Lenovo) C:\ProgramData\LenovoTransition\Server\x64\ymc.exe
() C:\Program Files (x86)\Lenovo\Yoga Picks\Service\x64\YogaPicks.AppService.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Microsoft Corporation) C:\Windows\System32\InputMethod\CHS\ChsIME.exe
(Huawei Technologies Co., Ltd.) C:\ProgramData\DatacardService\DCSHelper.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
(Intel Corporation) C:\Windows\System32\igfxTray.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek semiconductor) C:\Windows\RTFTrack.exe
(Lenovo) C:\Program Files\Lenovo Yoga PhoneCompanion\Yoga Phone Companion.exe
() C:\Program Files (x86)\Lenovo\Lenovo Transition\Transition.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Manager\utility.exe
(Lenovo) C:\Program Files (x86)\Lenovo\Yoga Picks\Yoga Picks.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
() C:\Program Files (x86)\Lenovo\Lenovo Transition\TransitionServer.exe
(Lenovo) C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LsvTrayLoad.exe
() C:\Program Files\Lenovo Yoga PhoneCompanion\adb.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonX86\Microsoft Shared\OFFICE15\CSISYNCCLIENT.EXE
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\root\office15\msosync.exe
(Lenovo) C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LsvController.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\ismagent.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\…\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [287592 2014-03-27] (Intel Corporation)
HKLM\…\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13667032 2014-01-22] (Realtek Semiconductor)
HKLM\…\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1374936 2014-01-13] (Realtek Semiconductor)
HKLM\…\Run: [RtHDVBg_LENOVO_DOLBYDRAGON] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1374936 2014-01-13] (Realtek Semiconductor)
HKLM\…\Run: [RtHDVBg_LENOVO_MICPKEY] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1374936 2014-01-13] (Realtek Semiconductor)
HKLM\…\Run: [RtsFT] => C:\windows\RTFTrack.exe [6340312 2013-10-18] (Realtek semiconductor)
HKLM\…\Run: [Yoga PhoneCompanion] => C:\Program Files\Lenovo Yoga PhoneCompanion\Yoga Phone Companion.exe [844304 2014-07-22] (Lenovo)
HKLM\…\Run: [AutoStartTransition] => C:\Program Files (x86)\Lenovo\Lenovo Transition\Transition.exe [294672 2014-07-22] ()
HKLM\…\Run: [Energy Manager] => C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe [15813616 2014-07-22] (Lenovo(beijing) Limited)
HKLM\…\Run: [Lenovo Utility] => C:\Program Files (x86)\Lenovo\Energy Manager\Utility.exe [80880 2014-07-22] (Lenovo(beijing) Limited)
HKLM-x32\…\Run: [Yoga Picks] => C:\Program Files (x86)\Lenovo\Yoga Picks\Yoga Picks.exe [119280 2014-01-07] (Lenovo)
HKLM-x32\…\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [335232 2015-03-07] (Oracle Corporation)
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-648119318-4113145362-2409287244-1001 -> {CAAA82DD-3477-40F8-BA0E-F1B8D2B0DB99} URL =
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2015-06-09] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2015-06-16] (Microsoft Corporation)
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL [2015-04-01] (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{7DA0D1A2-70F9-47C3-BC28-7F89087C5CB0}: [DhcpNameServer] 169.254.54.64
Tcpip\..\Interfaces\{D0819CE9-A454-45FD-9F0F-B53A73CE30DF}: [DhcpNameServer] 192.168.1.1
FireFox:
========
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-09-17] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-09-17] (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.40.2 -> C:\Program Files (x86)\Java\jre1.8.0_40\bin\dtplugin\npDeployJava1.dll [2015-04-09] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.40.2 -> C:\Program Files (x86)\Java\jre1.8.0_40\bin\plugin2\npjp2.dll [2015-04-09] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [2015-03-30] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-21] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-05-21] (Google Inc.)
Chrome:
=======
CHR dev: Chrome dev build detected! <======= ATTENTION
CHR Profile: C:\Users\Keng Ling\AppData\Local\Google\Chrome\User Data\Profile 1
CHR Extension: (YouTube) - C:\Users\Keng Ling\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-02-18]
CHR Extension: (Google Search) - C:\Users\Keng Ling\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-02-18]
CHR Extension: (Google Wallet) - C:\Users\Keng Ling\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-02-18]
CHR Extension: (Gmail) - C:\Users\Keng Ling\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-02-18]
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 BthHFSrv; C:\Windows\System32\BthHFSrv.dll [324608 2014-10-29] (Microsoft Corporation)
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2753720 2015-07-01] (Microsoft Corporation)
R2 HWDeviceService64.exe; C:\ProgramData\DatacardService\HWDeviceService64.exe [346976 2011-03-14] ()
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [16232 2014-03-27] (Intel Corporation)
R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [282072 2014-03-11] (Intel Corporation)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [747520 2013-08-28] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [828376 2013-08-28] (Intel(R) Corporation)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [131544 2013-09-17] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-09-17] (Intel Corporation)
R2 LenovoWiFiHotspotSvr; C:\Windows\System32\LenovoWiFiHotspotSvr.exe [198192 2014-07-22] (Lenovo(beijing) Limited)
R2 LsvUIService; C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LsvUIService.exe [70416 2014-07-22] (Lenovo)
S2 Mobile Partner. RunOuc; C:\Program Files (x86)\Mobile Partner\UpdateDog\ouc.exe [655744 2012-06-28] ()
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [284912 2014-01-18] ()
R2 PGService; C:\Program Files (x86)\Lenovo\Motion Control\PGService.exe [167176 2014-02-25] (PointGrab LTD)
R2 PG_Service_Launcher; C:\Program Files (x86)\Lenovo\Motion Control\PG_Service_Launcher.exe [512776 2014-02-25] (PointGrab LTD)
R2 PhoneCompanionPusher; C:\Program Files\Lenovo Yoga PhoneCompanion\PhoneCompanionPusher.exe [285712 2014-07-22] (Lenovo)
S3 PhoneCompanionVap; C:\Program Files\Lenovo Yoga PhoneCompanion\PhoneCompanionVap.exe [304144 2014-07-22] (Lenovo)
R2 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [390632 2012-04-24] ()
R2 VeriFaceSrv; C:\Program Files (x86)\Lenovo\Lenovo VeriFace Pro\VfConnectorService.exe [67856 2014-07-22] ()
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366520 2015-02-04] (Microsoft Corporation)
S3 wifimansvc; C:\Program Files (x86)\Mobile Partner\eap\wifimansvc.exe [605696 2012-08-06] () [File not signed]
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2015-02-04] (Microsoft Corporation)
R2 ymc; C:\ProgramData\LenovoTransition\Server\x64\ymc.exe [33040 2014-07-22] (Lenovo)
R2 YogaPicks.AppService; C:\Program Files (x86)\Lenovo\Yoga Picks\Service\x64\YogaPicks.AppService.exe [19440 2014-01-07] ()
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3816176 2014-01-18] (Intel® Corporation)
S2 gupdate; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /svc [X]
S3 gupdatem; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /medsvc [X]
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 AX88772; C:\Windows\system32\DRIVERS\ax88772.sys [113864 2013-07-18] (ASIX Electronics Corp.)
R3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [226304 2014-03-18] (Microsoft Corporation)
S3 huawei_wwanecm; C:\Windows\system32\DRIVERS\ew_juwwanecm.sys [238080 2012-06-06] (Huawei Technologies Co., Ltd.)
R3 ibtusb; C:\Windows\system32\DRIVERS\ibtusb.sys [142280 2013-10-18] (Intel Corporation)
R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [99288 2013-09-17] (Intel Corporation)
R3 NETwNb64; C:\Windows\system32\DRIVERS\Netwbw02.sys [3433952 2014-02-19] (Intel Corporation)
S3 NETwNe64; C:\Windows\system32\DRIVERS\NETwew02.sys [4649440 2013-06-18] (Intel Corporation)
S3 NPF; C:\Windows\System32\drivers\NPF.sys [35344 2012-06-06] (CACE Technologies, Inc.)
S3 NPF; C:\Windows\SysWOW64\drivers\NPF.sys [35344 2012-06-06] (CACE Technologies, Inc.)
R3 rtsuvc; C:\Windows\system32\DRIVERS\rtsuvc.sys [8876248 2013-10-18] (Realtek Semiconductor Corp.)
R3 SensorsHIDClassDriver; C:\Windows\System32\drivers\WUDFRd.sys [226304 2014-10-29] (Microsoft Corporation)
R3 SensorsServiceDriver; C:\Windows\System32\drivers\WUDFRd.sys [226304 2014-10-29] (Microsoft Corporation)
R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [34544 2013-12-19] (Synaptics Incorporated)
R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2015-02-04] (Microsoft Corporation)
S3 wsvd; C:\Windows\system32\DRIVERS\wsvd.sys [102376 2012-06-14] ("CyberLink)
S3 EagleX64; \??\C:\windows\system32\drivers\EagleX64.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-08-06 10:05 - 2015-08-06 10:05 - 00017208 _____ C:\Users\Keng Ling\Downloads\FRST.txt
2015-08-06 10:04 - 2015-08-06 10:05 - 00000000 ____D C:\FRST
2015-08-06 10:04 - 2015-08-06 10:04 - 02169856 _____ (Farbar) C:\Users\Keng Ling\Downloads\FRST64.exe
2015-08-03 11:23 - 2015-08-03 11:47 - 72169331 _____ C:\Users\Keng Ling\Desktop\Planetshakers.m4a
2015-08-01 21:47 - 2015-07-25 21:34 - 01084928 _____ (Microsoft Corporation) C:\windows\system32\appraiser.dll
2015-08-01 19:31 - 2015-08-01 19:31 - 00000000 _____ C:\autoexec.bat
2015-08-01 19:30 - 2015-08-01 19:30 - 03237248 _____ (Enigma Software Group USA, LLC.) C:\Users\Keng Ling\Downloads\SpyHunter-Installer.exe
2015-07-26 20:28 - 2015-07-26 20:29 - 02248704 _____ C:\Users\Keng Ling\Downloads\adwcleaner_4.208.exe
2015-07-26 17:41 - 2015-07-26 17:41 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Keng Ling\Downloads\revosetup.exe
2015-07-26 17:41 - 2015-07-26 17:41 - 00001291 _____ C:\Users\Keng Ling\Desktop\Revo Uninstaller.lnk
2015-07-26 17:41 - 2015-07-26 17:41 - 00000000 ____D C:\Program Files (x86)\VS Revo Group
2015-07-21 16:14 - 2015-07-21 16:47 - 44792000 _____ C:\Users\Keng Ling\Downloads\Full_Movie_HDRip_HD720p_x624[YIFY].rar
2015-07-21 16:14 - 2015-07-21 16:14 - 00014417 _____ C:\Users\Keng Ling\Downloads\Full_Movie_BluRayRip_HD720p_x624[YIFY].rar.torrent
2015-07-21 15:48 - 2015-07-14 22:14 - 00358912 _____ (Adobe Systems Incorporated) C:\windows\system32\atmfd.dll
2015-07-21 15:48 - 2015-07-14 22:14 - 00301056 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\atmfd.dll
2015-07-21 15:48 - 2015-07-14 22:14 - 00035840 _____ (Adobe Systems) C:\windows\SysWOW64\atmlib.dll
2015-07-21 15:48 - 2015-07-14 22:13 - 00044032 _____ (Adobe Systems) C:\windows\system32\atmlib.dll
2015-07-19 01:26 - 2015-05-12 00:34 - 00332800 _____ (Microsoft Corporation) C:\windows\system32\fhcpl.dll
2015-07-18 02:04 - 2015-07-18 02:09 - 794375838 _____ C:\Users\Keng Ling\Downloads\SBS Camp Evolution.zip
2015-07-18 01:52 - 2015-07-18 01:57 - 00000000 ____D C:\Users\Keng Ling\Desktop\BIOLOGICAL SCIENCES
2015-07-18 01:50 - 2015-07-18 01:56 - 306936352 _____ C:\Users\Keng Ling\Downloads\Y2 S1.zip
2015-07-18 01:50 - 2015-07-18 01:53 - 256079802 _____ C:\Users\Keng Ling\Downloads\Y2 S2.zip
2015-07-18 01:50 - 2015-07-18 01:51 - 22020536 _____ C:\Users\Keng Ling\Downloads\BS1003_ORGANIC CHEMISTRY.zip
2015-07-18 01:50 - 2015-07-18 01:51 - 12271874 _____ C:\Users\Keng Ling\Downloads\BS1001_INTRO TO BIO.zip
2015-07-18 01:50 - 2015-07-18 01:50 - 05540020 _____ C:\Users\Keng Ling\Downloads\PE.zip
2015-07-18 01:50 - 2015-07-18 01:50 - 01678373 _____ C:\Users\Keng Ling\Downloads\UE.zip
2015-07-18 01:50 - 2015-07-18 01:50 - 00119650 _____ C:\Users\Keng Ling\Downloads\WORKPLACE SAFETY & HEALTH.zip
2015-07-18 01:49 - 2015-07-18 01:50 - 33685067 _____ C:\Users\Keng Ling\Downloads\Y1 S2.zip
2015-07-18 00:37 - 2015-05-03 08:39 - 00227328 _____ (Microsoft Corporation) C:\windows\system32\profsvc.dll
2015-07-18 00:37 - 2015-04-30 07:22 - 00130048 _____ (Microsoft Corporation) C:\windows\system32\WiFiDisplay.dll
2015-07-18 00:36 - 2015-06-30 06:43 - 00026288 _____ (Microsoft Corporation) C:\windows\system32\CompatTelRunner.exe
2015-07-18 00:36 - 2015-06-29 23:07 - 01145856 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll
2015-07-18 00:36 - 2015-06-29 23:07 - 00764928 _____ (Microsoft Corporation) C:\windows\system32\invagent.dll
2015-07-18 00:36 - 2015-06-29 23:07 - 00433152 _____ (Microsoft Corporation) C:\windows\system32\devinv.dll
2015-07-18 00:36 - 2015-06-29 23:07 - 00067584 _____ (Microsoft Corporation) C:\windows\system32\acmigration.dll
2015-07-18 00:36 - 2015-06-27 07:21 - 00726528 _____ (Microsoft Corporation) C:\windows\system32\generaltel.dll
2015-07-18 00:36 - 2015-06-27 07:21 - 00227328 _____ (Microsoft Corporation) C:\windows\system32\aepdu.dll
2015-07-18 00:36 - 2015-05-12 21:19 - 00294912 _____ (Microsoft Corporation) C:\windows\system32\SystemEventsBrokerServer.dll
2015-07-18 00:36 - 2015-05-12 02:17 - 01201664 ____C (Microsoft Corporation) C:\windows\system32\Drivers\bthport.sys
2015-07-18 00:36 - 2015-05-08 01:50 - 22292672 _____ (Microsoft Corporation) C:\windows\system32\shell32.dll
2015-07-18 00:36 - 2015-05-08 01:00 - 03109376 _____ (Microsoft Corporation) C:\windows\system32\ExplorerFrame.dll
2015-07-18 00:36 - 2015-05-08 00:53 - 19734960 _____ (Microsoft Corporation) C:\windows\SysWOW64\shell32.dll
2015-07-18 00:36 - 2015-05-08 00:12 - 02706432 _____ (Microsoft Corporation) C:\windows\SysWOW64\ExplorerFrame.dll
2015-07-18 00:36 - 2015-05-07 23:21 - 00522240 _____ (Microsoft Corporation) C:\windows\system32\GeofenceMonitorService.dll
2015-07-18 00:36 - 2015-05-07 23:05 - 00367104 _____ (Microsoft Corporation) C:\windows\SysWOW64\GeofenceMonitorService.dll
2015-07-18 00:36 - 2015-05-03 23:09 - 00274944 _____ (Microsoft Corporation) C:\windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2015-07-18 00:36 - 2015-05-03 23:07 - 07784448 _____ (Microsoft Corporation) C:\windows\system32\Windows.Data.Pdf.dll
2015-07-18 00:36 - 2015-05-03 22:58 - 00210944 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2015-07-18 00:36 - 2015-05-03 22:57 - 05264384 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.Data.Pdf.dll
2015-07-18 00:36 - 2015-05-03 22:55 - 00971776 _____ (Microsoft Corporation) C:\windows\system32\WSShared.dll
2015-07-18 00:36 - 2015-05-03 22:49 - 00811008 _____ (Microsoft Corporation) C:\windows\SysWOW64\WSShared.dll
2015-07-18 00:36 - 2015-05-02 07:33 - 00410739 _____ C:\windows\system32\ApnDatabase.xml
2015-07-18 00:36 - 2015-04-28 21:13 - 00513480 _____ C:\windows\SysWOW64\locale.nls
2015-07-18 00:36 - 2015-04-28 21:13 - 00513480 _____ C:\windows\system32\locale.nls
2015-07-18 00:36 - 2015-04-25 10:25 - 00020992 _____ (Microsoft Corporation) C:\windows\system32\Drivers\usb8023.sys
2015-07-18 00:36 - 2015-04-23 23:47 - 03084288 _____ (Microsoft Corporation) C:\windows\system32\msftedit.dll
2015-07-18 00:36 - 2015-04-23 23:16 - 02471424 _____ (Microsoft Corporation) C:\windows\SysWOW64\msftedit.dll
2015-07-18 00:36 - 2014-11-05 03:25 - 00059712 ____C (Microsoft Corporation) C:\windows\system32\Drivers\kbdclass.sys
2015-07-18 00:36 - 2014-11-05 03:25 - 00051008 ____C (Microsoft Corporation) C:\windows\system32\Drivers\mouclass.sys
2015-07-18 00:36 - 2014-11-04 14:55 - 00026112 ____C (Microsoft Corporation) C:\windows\system32\Drivers\sermouse.sys
2015-07-18 00:36 - 2014-11-04 14:54 - 00108544 ____C (Microsoft Corporation) C:\windows\system32\Drivers\i8042prt.sys
2015-07-18 00:36 - 2014-11-04 14:54 - 00032256 ____C (Microsoft Corporation) C:\windows\system32\Drivers\kbdhid.sys
2015-07-18 00:36 - 2014-11-04 14:54 - 00030208 ____C (Microsoft Corporation) C:\windows\system32\Drivers\mouhid.sys
2015-07-16 12:11 - 2015-07-16 12:42 - 552401305 _____ C:\Users\Keng Ling\Downloads\prom.zip
2015-07-15 23:47 - 2015-07-10 03:51 - 00136904 _____ (Microsoft Corporation) C:\windows\system32\wuauclt.exe
2015-07-15 23:47 - 2015-07-10 02:40 - 00359936 _____ (Microsoft Corporation) C:\windows\system32\WinSetupUI.dll
2015-07-15 23:47 - 2015-07-10 00:03 - 03701760 _____ (Microsoft Corporation) C:\windows\system32\wuaueng.dll
2015-07-15 23:47 - 2015-07-09 23:54 - 00035840 _____ (Microsoft Corporation) C:\windows\system32\wuapp.exe
2015-07-15 23:47 - 2015-07-09 23:53 - 00140288 _____ (Microsoft Corporation) C:\windows\system32\wuwebv.dll
2015-07-15 23:47 - 2015-07-09 23:50 - 00409088 _____ (Microsoft Corporation) C:\windows\system32\WUSettingsProvider.dll
2015-07-15 23:47 - 2015-07-09 23:50 - 00095744 _____ (Microsoft Corporation) C:\windows\system32\wudriver.dll
2015-07-15 23:47 - 2015-07-09 23:48 - 00891904 _____ (Microsoft Corporation) C:\windows\system32\wuapi.dll
2015-07-15 23:47 - 2015-07-09 23:46 - 02229248 _____ (Microsoft Corporation) C:\windows\system32\wucltux.dll
2015-07-15 23:47 - 2015-07-09 23:38 - 00029696 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapp.exe
2015-07-15 23:47 - 2015-07-09 23:37 - 00124928 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuwebv.dll
2015-07-15 23:47 - 2015-07-09 23:35 - 00081920 _____ (Microsoft Corporation) C:\windows\SysWOW64\wudriver.dll
2015-07-15 23:47 - 2015-07-09 23:34 - 00721920 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapi.dll
2015-07-15 23:47 - 2015-07-02 06:08 - 05923840 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2015-07-15 23:47 - 2015-07-02 05:14 - 04520448 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2015-07-15 23:47 - 2015-06-28 13:07 - 00442712 _____ (Microsoft Corporation) C:\windows\system32\msv1_0.dll
2015-07-15 23:47 - 2015-06-28 13:07 - 00178008 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecpkg.sys
2015-07-15 23:47 - 2015-06-28 13:06 - 01311960 _____ (Microsoft Corporation) C:\windows\system32\rpcrt4.dll
2015-07-15 23:47 - 2015-06-28 13:06 - 00332120 _____ (Microsoft Corporation) C:\windows\SysWOW64\msv1_0.dll
2015-07-15 23:47 - 2015-06-28 00:42 - 00747520 _____ (Microsoft Corporation) C:\windows\SysWOW64\rpcrt4.dll
2015-07-15 23:47 - 2015-06-27 11:13 - 00202240 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb20.sys
2015-07-15 23:47 - 2015-06-27 11:12 - 00401408 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb.sys
2015-07-15 23:47 - 2015-06-27 11:12 - 00284672 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb10.sys
2015-07-15 23:47 - 2015-06-27 11:08 - 00066048 _____ (Microsoft Corporation) C:\windows\system32\wups.dll
2015-07-15 23:47 - 2015-06-27 11:08 - 00052224 _____ (Microsoft Corporation) C:\windows\system32\wups2.dll
2015-07-15 23:47 - 2015-06-27 10:40 - 00445440 _____ (Microsoft Corporation) C:\windows\system32\certcli.dll
2015-07-15 23:47 - 2015-06-27 10:14 - 00027136 _____ (Microsoft Corporation) C:\windows\SysWOW64\wups.dll
2015-07-15 23:47 - 2015-06-27 10:05 - 01441792 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll
2015-07-15 23:47 - 2015-06-27 10:00 - 00989184 _____ (Microsoft Corporation) C:\windows\system32\kerberos.dll
2015-07-15 23:47 - 2015-06-27 09:53 - 00324096 _____ (Microsoft Corporation) C:\windows\SysWOW64\certcli.dll
2015-07-15 23:47 - 2015-06-27 09:26 - 00802816 _____ (Microsoft Corporation) C:\windows\SysWOW64\kerberos.dll
2015-07-15 23:47 - 2015-06-25 10:31 - 04177920 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2015-07-15 23:47 - 2015-06-16 06:41 - 00065024 _____ (Microsoft Corporation) C:\windows\system32\msiexec.exe
2015-07-15 23:47 - 2015-06-16 06:24 - 03320320 _____ (Microsoft Corporation) C:\windows\system32\msi.dll
2015-07-15 23:47 - 2015-06-16 05:16 - 00059904 _____ (Microsoft Corporation) C:\windows\SysWOW64\msiexec.exe
2015-07-15 23:47 - 2015-06-16 05:09 - 03607552 _____ (Microsoft Corporation) C:\windows\SysWOW64\msi.dll
2015-07-15 23:47 - 2015-06-16 04:50 - 02774528 _____ (Microsoft Corporation) C:\windows\system32\authui.dll
2015-07-15 23:47 - 2015-06-16 03:57 - 02460160 _____ (Microsoft Corporation) C:\windows\SysWOW64\authui.dll
2015-07-15 23:47 - 2015-05-31 05:18 - 00037888 _____ (Microsoft Corporation) C:\windows\system32\werdiagcontroller.dll
2015-07-15 23:47 - 2015-05-31 03:36 - 00230400 _____ (Microsoft Corporation) C:\windows\system32\AudioEndpointBuilder.dll
2015-07-15 23:47 - 2015-05-31 03:35 - 00911360 _____ (Microsoft Corporation) C:\windows\system32\audiosrv.dll
2015-07-15 23:46 - 2015-07-03 05:21 - 19877376 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2015-07-15 23:46 - 2015-07-03 04:50 - 02279424 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2015-07-15 23:46 - 2015-07-03 04:49 - 25193984 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2015-07-15 23:46 - 2015-07-03 04:23 - 02885632 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2015-07-15 23:46 - 2015-07-03 04:19 - 12855296 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2015-07-15 23:46 - 2015-07-03 03:55 - 01310720 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2015-07-15 23:46 - 2015-07-03 03:20 - 14453248 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2015-07-15 23:46 - 2015-07-03 02:59 - 01545728 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2015-07-15 23:45 - 2015-06-16 13:36 - 01661576 _____ (Microsoft Corporation) C:\windows\system32\ole32.dll
2015-07-15 23:45 - 2015-06-16 13:36 - 01212248 _____ (Microsoft Corporation) C:\windows\SysWOW64\ole32.dll
2015-07-15 23:45 - 2015-06-16 06:39 - 00584192 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2015-07-15 23:45 - 2015-06-16 06:38 - 00088064 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll
2015-07-15 23:45 - 2015-06-16 06:26 - 00633856 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2015-07-15 23:45 - 2015-06-16 06:24 - 00816640 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
2015-07-15 23:45 - 2015-06-16 06:02 - 00087552 _____ (Microsoft Corporation) C:\windows\system32\tdc.ocx
2015-07-15 23:45 - 2015-06-16 05:58 - 00199680 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2015-07-15 23:45 - 2015-06-16 05:57 - 00092160 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2015-07-15 23:45 - 2015-06-16 05:56 - 00145408 _____ (Microsoft Corporation) C:\windows\system32\iepeers.dll
2015-07-15 23:45 - 2015-06-16 05:55 - 00316928 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2015-07-15 23:45 - 2015-06-16 05:49 - 01032704 _____ (Microsoft Corporation) C:\windows\system32\inetcomm.dll
2015-07-15 23:45 - 2015-06-16 05:41 - 00262144 _____ (Microsoft Corporation) C:\windows\system32\webcheck.dll
2015-07-15 23:45 - 2015-06-16 05:38 - 00801280 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2015-07-15 23:45 - 2015-06-16 05:36 - 02125824 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2015-07-15 23:45 - 2015-06-16 05:17 - 02880000 _____ (Microsoft Corporation) C:\windows\system32\actxprxy.dll
2015-07-15 23:45 - 2015-06-16 05:16 - 02427392 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2015-07-15 23:45 - 2015-06-16 05:15 - 00504320 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2015-07-15 23:45 - 2015-06-16 05:13 - 00064000 _____ (Microsoft Corporation) C:\windows\SysWOW64\MshtmlDac.dll
2015-07-15 23:45 - 2015-06-16 05:04 - 00478208 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2015-07-15 23:45 - 2015-06-16 05:03 - 00664064 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript.dll
2015-07-15 23:45 - 2015-06-16 04:52 - 00800768 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2015-07-15 23:45 - 2015-06-16 04:47 - 00073216 _____ (Microsoft Corporation) C:\windows\SysWOW64\tdc.ocx
2015-07-15 23:45 - 2015-06-16 04:44 - 00168960 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll
2015-07-15 23:45 - 2015-06-16 04:43 - 00076288 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
2015-07-15 23:45 - 2015-06-16 04:42 - 00128000 _____ (Microsoft Corporation) C:\windows\SysWOW64\iepeers.dll
2015-07-15 23:45 - 2015-06-16 04:41 - 00285696 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
2015-07-15 23:45 - 2015-06-16 04:37 - 00880128 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcomm.dll
2015-07-15 23:45 - 2015-06-16 04:32 - 00230400 _____ (Microsoft Corporation) C:\windows\SysWOW64\webcheck.dll
2015-07-15 23:45 - 2015-06-16 04:31 - 00689152 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2015-07-15 23:45 - 2015-06-16 04:30 - 02052608 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2015-07-15 23:45 - 2015-06-16 04:30 - 00327168 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll
2015-07-15 23:45 - 2015-06-16 04:17 - 01048576 _____ (Microsoft Corporation) C:\windows\SysWOW64\actxprxy.dll
2015-07-15 23:45 - 2015-06-16 04:07 - 01951232 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2015-07-15 23:45 - 2015-06-16 04:02 - 00710144 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2015-07-15 23:45 - 2015-06-11 11:49 - 01380600 _____ (Microsoft Corporation) C:\windows\system32\gdi32.dll
2015-07-15 23:45 - 2015-06-11 00:13 - 01097216 _____ (Microsoft Corporation) C:\windows\SysWOW64\gdi32.dll
2015-07-15 23:45 - 2015-05-08 00:47 - 00564224 _____ (Microsoft Corporation) C:\windows\system32\apphelp.dll
2015-07-12 17:49 - 2015-08-01 19:23 - 00000024 _____ C:\Users\Keng Ling\AppData\Roaming\appdataFr25.bin
2015-07-12 17:30 - 2015-07-12 17:30 - 00000000 ____D C:\Users\Keng Ling\AppData\Local\GWX
2015-07-10 21:39 - 2015-08-02 15:57 - 00000000 ___HD C:\$Windows.~BT
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-08-06 10:02 - 2013-08-22 23:36 - 00000000 ____D C:\windows\system32\sru
2015-08-06 09:59 - 2014-07-22 18:03 - 01057876 _____ C:\windows\WindowsUpdate.log
2015-08-06 09:59 - 2013-08-22 23:36 - 00000000 ____D C:\windows\AppReadiness
2015-08-06 09:58 - 2015-06-16 20:31 - 00004982 _____ C:\windows\System32\Tasks\Microsoft Office 15 Sync Maintenance for Peanut-Keng Ling Peanut
2015-08-06 09:58 - 2015-06-16 20:31 - 00000000 ____D C:\Users\Keng Ling\OneDrive
2015-08-06 09:57 - 2014-03-18 17:44 - 00215006 _____ C:\windows\PFRO.log
2015-08-06 09:57 - 2013-08-22 22:46 - 00052327 _____ C:\windows\setupact.log
2015-08-06 09:57 - 2013-08-22 22:45 - 00000006 ____H C:\windows\Tasks\SA.DAT
2015-08-06 09:56 - 2014-07-22 19:06 - 00002560 _____ C:\windows\system32\VfService.trf
2015-08-06 09:56 - 2013-08-22 21:25 - 00262144 ___SH C:\windows\system32\config\BBI
2015-08-06 09:55 - 2015-02-18 20:54 - 00003934 _____ C:\windows\System32\Tasks\User_Feed_Synchronization-{8313204A-2A2B-4621-AF26-3557D402B16A}
2015-08-06 09:54 - 2015-06-29 02:21 - 00450000 _____ C:\windows\system32\prfh0804.dat
2015-08-06 09:54 - 2015-06-29 02:21 - 00140290 _____ C:\windows\system32\prfc0804.dat
2015-08-06 09:54 - 2014-03-18 17:53 - 01438230 _____ C:\windows\system32\PerfStringBackup.INI
2015-08-04 04:15 - 2015-02-18 22:35 - 00113880 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2015-08-03 22:20 - 2014-09-18 03:21 - 00003598 _____ C:\windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-648119318-4113145362-2409287244-1001
2015-08-02 16:03 - 2014-04-04 03:15 - 00000000 ____D C:\windows\Panther
2015-08-01 22:24 - 2013-08-22 23:20 - 00000000 ____D C:\windows\CbsTemp
2015-08-01 19:25 - 2015-03-30 23:05 - 00003100 _____ C:\windows\System32\Tasks\Microsoft OneDrive Auto Update Task-S-1-5-21-648119318-4113145362-2409287244-1001
2015-07-26 20:03 - 2015-02-18 20:57 - 00002214 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-07-25 19:36 - 2015-04-04 20:25 - 00000000 ___SD C:\windows\system32\GWX
2015-07-24 22:30 - 2014-09-18 03:15 - 00000000 ____D C:\Users\Keng Ling\AppData\Local\Packages
2015-07-21 19:22 - 2013-08-22 23:36 - 00000000 ____D C:\windows\rescache
2015-07-21 16:05 - 2015-03-30 23:01 - 00000000 ____D C:\Program Files\Microsoft Office 15
2015-07-21 15:52 - 2013-08-22 22:44 - 00492000 _____ C:\windows\system32\FNTCACHE.DAT
2015-07-18 16:45 - 2013-08-22 23:36 - 00000000 ___RD C:\windows\ToastData
2015-07-18 16:45 - 2013-08-22 23:36 - 00000000 ____D C:\windows\WinStore
2015-07-18 01:53 - 2015-02-19 11:49 - 00000000 ___SD C:\windows\system32\CompatTel
2015-07-18 01:53 - 2015-02-19 11:49 - 00000000 ____D C:\windows\system32\appraiser
2015-07-18 01:53 - 2015-02-19 02:20 - 00000000 ____D C:\windows\system32\MRT
2015-07-18 01:48 - 2015-04-04 20:25 - 00000000 ___SD C:\windows\SysWOW64\GWX
2015-07-14 05:10 - 2015-02-19 12:55 - 00792568 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2015-07-14 05:10 - 2015-02-19 12:55 - 00178168 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
==================== Files in the root of some directories =======
2015-07-12 17:49 - 2015-08-01 19:23 - 0000024 _____ () C:\Users\Keng Ling\AppData\Roaming\appdataFr25.bin
2015-06-29 23:27 - 2015-06-29 23:27 - 0000000 _____ () C:\Users\Keng Ling\AppData\Local\Temp.dat
2014-07-22 18:31 - 2014-07-22 18:31 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
Some files in TEMP:
====================
C:\Users\Keng Ling\AppData\Local\Temp\oct1439.tmp.exe
C:\Users\Keng Ling\AppData\Local\Temp\oct19FB.tmp.exe
C:\Users\Keng Ling\AppData\Local\Temp\oct27FA.tmp.exe
C:\Users\Keng Ling\AppData\Local\Temp\oct98DE.tmp.exe
C:\Users\Keng Ling\AppData\Local\Temp\octB3E.tmp.exe
C:\Users\Keng Ling\AppData\Local\Temp\octC112.tmp.exe
C:\Users\Keng Ling\AppData\Local\Temp\octC383.tmp.exe
C:\Users\Keng Ling\AppData\Local\Temp\octC4B8.tmp.exe
C:\Users\Keng Ling\AppData\Local\Temp\octC99.tmp.exe
C:\Users\Keng Ling\AppData\Local\Temp\octCA.tmp.exe
C:\Users\Keng Ling\AppData\Local\Temp\octD02.tmp.exe
C:\Users\Keng Ling\AppData\Local\Temp\octDFB8.tmp.exe
C:\Users\Keng Ling\AppData\Local\Temp\octFE77.tmp.exe
C:\Users\Keng Ling\AppData\Local\Temp\octFE7B.tmp.exe
C:\Users\Keng Ling\AppData\Local\Temp\Quarantine.exe
C:\Users\Keng Ling\AppData\Local\Temp\sqlite3.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\windows\system32\winlogon.exe => File is digitally signed
C:\windows\system32\wininit.exe => File is digitally signed
C:\windows\explorer.exe => File is digitally signed
C:\windows\SysWOW64\explorer.exe => File is digitally signed
C:\windows\system32\svchost.exe => File is digitally signed
C:\windows\SysWOW64\svchost.exe => File is digitally signed
C:\windows\system32\services.exe => File is digitally signed
C:\windows\system32\User32.dll => File is digitally signed
C:\windows\SysWOW64\User32.dll => File is digitally signed
C:\windows\system32\userinit.exe => File is digitally signed
C:\windows\SysWOW64\userinit.exe => File is digitally signed
C:\windows\system32\rpcss.dll => File is digitally signed
C:\windows\system32\dnsapi.dll => File is digitally signed
C:\windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-08-01 22:22
==================== End of log ============================
Addition.txt
Additional scan result of Farbar Recovery Scan Tool (x64) Version:02-08-2015 01
Ran by [removed] (2015-08-06 10:06:11)
Running from C:\Users\[removed]\Downloads
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-648119318-4113145362-2409287244-500 - Administrator - Disabled)
Guest (S-1-5-21-648119318-4113145362-2409287244-501 - Limited - Disabled)
Keng Ling (S-1-5-21-648119318-4113145362-2409287244-1001 - Administrator - Enabled) => C:\Users\Keng Ling
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
CyberLink MediaStory (HKLM-x32\…\InstallShield_{55762F9A-FCE3-45d5-817B-051218658423}) (Version: 1.0.1314 - CyberLink Corp.)
CyberLink PowerDirector 10 (HKLM-x32\…\InstallShield_{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}) (Version: 10.0.0.2810 - CyberLink Corp.)
CyberLink PowerDirector 10 (Version: 10.0.0.2810 - CyberLink Corp.) Hidden
Dolby Digital Plus Home Theater (HKLM\…\{7E3D8FA1-6092-469A-955B-68FC4A2C67CA}) (Version: 7.5.1.1 - Dolby Laboratories Inc)
Energy Manager (HKLM-x32\…\InstallShield_{AC768037-7079-4658-AC24-2897650E0ABE}) (Version: 1.0.0.35 - Lenovo)
Energy Manager (x32 Version: 1.0.0.35 - Lenovo) Hidden
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 43.0.2357.130 - Google Inc.)
Google Update Helper (x32 Version: 1.3.27.5 - Google Inc.) Hidden
Intel Experience Center - Configuration (x32 Version: 1.7.0.179 - Intel) Hidden
Intel(R) Experience Center Desktop Software (HKLM-x32\…\{3608ec0a-56b4-4d9d-b038-9b3e51d72582}) (Version: 1.7.0.179 - Intel)
Intel(R) Management Engine Components (HKLM-x32\…\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.5.15.1730 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\…\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3496 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM\…\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 13.0.2.1000 - Intel Corporation)
Intel(R) Update Manager (x32 Version: 1.6.2.69 - Intel Corporation) Hidden
Intel(R) Wireless Bluetooth(R) 4.0 (HKLM-x32\…\{96C730E4-F055-4118-BDF3-6E071763853C}) (Version: 3.0.1342.02 - Intel Corporation)
Intel® PROSet/Wireless Software (HKLM-x32\…\{7e493493-a430-4b7b-b8a2-48d61599e220}) (Version: 17.0.0 - Intel Corporation)
Java 8 Update 40 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F83218040F0}) (Version: 8.0.400 - Oracle Corporation)
Lenovo EasyCamera (HKLM-x32\…\{E0A7ED39-8CD6-4351-93C3-69CCA00D12B4}) (Version: 6.2.9200.10249 - Realtek Semiconductor Corp.)
Lenovo Experience Improvement (HKLM\…\LenovoExperienceImprovement) (Version: 1.0.4.0 - Lenovo)
Lenovo FusionEngine (HKLM-x32\…\Lenovo FusionEngine) (Version: 1.0.13.0 - Lenovo, Inc.)
Lenovo Mobile Phone Wireless Import (HKLM-x32\…\InstallShield_{DFB2E0D6-8DDE-49A4-B8F7-03C14DACCBA6}) (Version: 1.1.1.8 - Lenovo)
Lenovo Mobile Phone Wireless Import (x32 Version: 1.1.1.8 - Lenovo) Hidden
Lenovo Motion Control (HKLM-x32\…\InstallShield_{E9325F15-6339-45E8-9DC4-C2D44B623039}) (Version: 2.5.1.0224 - PointGrab)
Lenovo Motion Control (x32 Version: 2.5.1.0224 - PointGrab) Hidden
Lenovo OneKey Recovery (HKLM-x32\…\InstallShield_{46F4D124-20E5-4D12-BE52-EC177A7A4B42}) (Version: 8.0.0.2105 - CyberLink Corp.)
Lenovo OneKey Recovery (Version: 8.0.0.2105 - CyberLink Corp.) Hidden
Lenovo Photo Master (HKLM-x32\…\InstallShield_{BC94C56A-3649-420C-8756-2ADEBE399D33}) (Version: 1.0.52953.1504 - CyberLink Corp.)
Lenovo Photo Master (x32 Version: 1.0.52953.1504 - CyberLink Corp.) Hidden
Lenovo Smart Voice (HKLM\…\Lenovo SmartVoice) (Version: 1.0.2.2 - Lenovo)
Lenovo Transition (HKLM\…\Lenovo Transition) (Version: 2.0.13.10181 - Lenovo)
Lenovo VeriFace Pro (HKLM\…\Lenovo VeriFace) (Version: 5.0.14.1061 - Lenovo)
Lenovo Yoga 2 Demo (HKLM-x32\…\{03C682A4-05CD-4D22-B50A-B9C3C5F2B137}) (Version: 1.0.7 - Lenovo)
Lenovo Yoga PhoneCompanion (HKLM-x32\…\InstallShield_{0F82EA83-B0C5-4AB9-9695-DFE92C5FD57B}) (Version: 1.1.9.5 - Lenovo)
Lenovo Yoga PhoneCompanion (x32 Version: 1.1.9.5 - Lenovo) Hidden
Malwarebytes Anti-Malware version 2.1.8.1057 (HKLM-x32\…\Malwarebytes Anti-Malware_is1) (Version: 2.1.8.1057 - Malwarebytes Corporation)
Microsoft Office 365 - en-us (HKLM\…\O365HomePremRetail - en-us) (Version: 15.0.4737.1003 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-648119318-4113145362-2409287244-1001\…\OneDriveSetup.exe) (Version: 17.3.5907.0716 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\…\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Mobile Partner (HKLM-x32\…\Mobile Partner) (Version: 23.009.05.00.203 - Huawei Technologies Co.,Ltd)
Office 15 Click-to-Run Extensibility Component (x32 Version: 15.0.4737.1003 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Licensing Component (Version: 15.0.4737.1003 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Localization Component (x32 Version: 15.0.4737.1003 - Microsoft Corporation) Hidden
Realtek Card Reader (HKLM-x32\…\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.2.9600.39053 - Realtek Semiconductor Corp.)
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7161 - Realtek Semiconductor Corp.)
Revo Uninstaller 1.95 (HKLM-x32\…\Revo Uninstaller) (Version: 1.95 - VS Revo Group)
Synaptics Pointing Device Driver (HKLM\…\SynTPDeinstKey) (Version: 17.0.14.71 - Synaptics Incorporated)
Update for CHS Microsoft IME HAP Dictionary (Version: 16.0.1560.1 - Microsoft Corporation) Hidden
User Manuals (HKLM-x32\…\InstallShield_{F07C2CF8-4C53-4EC3-8162-A6221E36EB88}) (Version: 3.0.0.3 - Lenovo)
User Manuals (x32 Version: 3.0.0.3 - Lenovo) Hidden
Windows Driver Package - Lenovo (ACPIVPC) System (02/17/2013 9.52.0.776) (HKLM\…\35DD26BE48DAF4A9F35F969F3CB1E3E1435E661E) (Version: 02/17/2013 9.52.0.776 - Lenovo)
Windows Driver Package - Lenovo (WUDFRd) LenovoVhid (07/25/2013 10.30.0.288) (HKLM\…\6BCA401E9CBEED970D75F55FA5320F60D11984E9) (Version: 07/25/2013 10.30.0.288 - Lenovo)
WinRAR 5.21 (32-bit) (HKLM-x32\…\WinRAR archiver) (Version: 5.21.0 - win.rar GmbH)
Yoga Picks (HKLM-x32\…\{267C8BA0-876B-4589-9F14-EFB84ABCEA7F}) (Version: 1.5.014.0106 - Lenovo)
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-648119318-4113145362-2409287244-1001_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\windows\system32\igfxEM.exe (Intel Corporation)
CustomCLSID: HKU\S-1-5-21-648119318-4113145362-2409287244-1001_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\Keng Ling\AppData\Local\Microsoft\OneDrive\17.3.5907.0716\amd64\FileSyncApi64.dll (Microsoft Corporation)
==================== Restore Points =========================
16-07-2015 13:36:27 Windows Update
21-07-2015 15:51:01 Windows Update
26-07-2015 17:42:26 Revo Uninstaller's restore point - TerminusKeeper
01-08-2015 22:22:04 Windows Update
==================== Hosts content: ===============================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2013-08-22 21:25 - 2013-08-22 21:25 - 00000824 ____N C:\windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {1D333F56-8774-46E9-BEC5-34C163F5697A} - System32\Tasks\Lenovo\Experience Improvement Logon => C:\Program Files\Lenovo\ExperienceImprovement\LenovoExperienceImprovement.exe [2013-06-03] (Lenovo)
Task: {22C3EAE4-AB23-4740-9411-760E9687AFA7} - System32\Tasks\Microsoft Office 15 Sync Maintenance for Peanut-Keng Ling Peanut => C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe [2015-06-02] (Microsoft Corporation)
Task: {32A44705-A3DD-4DF7-BB1A-3CE9633A74FF} - System32\Tasks\ISM-UpdateService-e57b59e7-5862-4250-9ce0-76fb411dc0d2-Logon => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\Bootstrap.exe [2013-07-04] (Intel Corporation)
Task: {636ED2CE-2B39-4117-BABA-4F721C550FDC} - \Bidaily Synchronize Task[pr] No Task File <==== ATTENTION
Task: {7263D23C-3791-4F80-9039-D3B3A2E500CA} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2015-07-01] (Microsoft Corporation)
Task: {8CE52C5E-4D81-47BF-91F2-E1624C59A156} - System32\Tasks\ISM-UpdateService-e57b59e7-5862-4250-9ce0-76fb411dc0d2 => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\Bootstrap.exe [2013-07-04] (Intel Corporation)
Task: {9BC9B254-B7E7-4D6B-8C42-35AC14590681} - System32\Tasks\Synaptics TouchPad Enhancements => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2013-12-19] (Synaptics Incorporated)
Task: {C07410D6-D5A2-4440-B02B-A746D49754E9} - System32\Tasks\Microsoft OneDrive Auto Update Task-S-1-5-21-648119318-4113145362-2409287244-1001 => %localappdata%\Microsoft\OneDrive\OneDrive.exe
Task: {CA8C03CE-E4C5-40A6-B500-96F7C6408316} - System32\Tasks\DolbySelectorTask => C:\Program Files\Dolby Digital Plus\ddp.exe
Task: {D62355DB-C777-44A1-BE48-FFE46A919DED} - System32\Tasks\Lenovo Smart Voice => C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LsvTrayLoad.exe [2014-07-22] (Lenovo)
Task: {DEF87012-576B-44EA-A909-BE17B61726B9} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\windows\system32\MRT.exe [2015-07-03] (Microsoft Corporation)
Task: {E1CAE276-5894-4C4E-A52D-9D35DCC11153} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2015-07-01] (Microsoft Corporation)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Loaded Modules (Whitelisted) ==============
2015-03-30 23:01 - 2014-05-20 09:19 - 00105640 _____ () C:\Program Files\Microsoft Office 15\ClientX64\ApiClient.dll
2011-03-14 23:27 - 2011-03-14 23:27 - 00346976 _____ () C:\ProgramData\DatacardService\HWDeviceService64.exe
2015-02-18 21:52 - 2012-06-28 10:46 - 00655744 _____ () C:\ProgramData\Mobile Partner\OnlineUpdate\ouc.exe
2014-07-22 19:06 - 2012-04-24 18:43 - 00390632 ____N () C:\Program Files\CyberLink\Shared files\RichVideo64.exe
2014-07-22 19:06 - 2014-07-22 19:06 - 00067856 _____ () C:\Program Files (x86)\Lenovo\Lenovo VeriFace Pro\VfConnectorService.exe
2014-07-22 19:06 - 2014-07-22 19:06 - 00672016 _____ () C:\Program Files (x86)\Lenovo\Lenovo VeriFace Pro\VfDataStorageInterface.dll
2014-07-22 19:06 - 2014-07-22 19:06 - 00061200 _____ () C:\ProgramData\LenovoTransition\Server\x64\dptf.dll
2014-07-22 19:04 - 2014-01-07 06:14 - 00019440 _____ () C:\Program Files (x86)\Lenovo\Yoga Picks\Service\x64\YogaPicks.AppService.exe
2015-04-01 15:43 - 2015-04-01 15:43 - 08898720 _____ () C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\1033\GrooveIntlResource.dll
2014-07-22 19:06 - 2014-07-22 19:06 - 00294672 _____ () C:\Program Files (x86)\Lenovo\Lenovo Transition\Transition.exe
2014-07-22 19:04 - 2014-01-07 05:58 - 00044016 _____ () C:\Program Files (x86)\Lenovo\Yoga Picks\Util.dll
2015-03-07 23:03 - 2015-03-07 23:03 - 00207872 _____ () C:\windows\assembly\NativeImages_v4.0.30319_64\Windows.System\a4efa88b742703220e527956d8ab4e84\Windows.System.ni.dll
2015-03-07 23:03 - 2015-03-07 23:03 - 01259520 _____ () C:\windows\assembly\NativeImages_v4.0.30319_64\Windows.Networking\8f0dd293f95c402613c49fb2fac85bdd\Windows.Networking.ni.dll
2015-03-07 23:03 - 2015-03-07 23:03 - 00363520 _____ () C:\windows\assembly\NativeImages_v4.0.30319_64\Windows.Foundation\6382e6f5ad8b7a9db4f5cd4817e70319\Windows.Foundation.ni.dll
2014-07-22 19:06 - 2014-07-22 19:06 - 00108304 _____ () C:\Program Files (x86)\Lenovo\Lenovo Transition\TransitionServer.exe
2014-07-22 19:06 - 2014-07-22 19:06 - 00815104 _____ () C:\Program Files\Lenovo Yoga PhoneCompanion\adb.exe
2015-02-18 21:52 - 2009-01-10 18:32 - 00011362 _____ () C:\ProgramData\Mobile Partner\OnlineUpdate\mingwm10.dll
2015-02-18 21:52 - 2009-06-23 02:42 - 00043008 _____ () C:\ProgramData\Mobile Partner\OnlineUpdate\libgcc_s_dw2-1.dll
2015-02-18 21:52 - 2010-07-23 12:58 - 02415104 _____ () C:\ProgramData\Mobile Partner\OnlineUpdate\QtCore4.dll
2015-02-18 21:52 - 2010-02-10 22:10 - 01148416 _____ () C:\ProgramData\Mobile Partner\OnlineUpdate\QtNetwork4.dll
2015-02-18 21:52 - 2012-06-28 10:34 - 00843264 _____ () C:\ProgramData\Mobile Partner\OnlineUpdate\QueryStrategy.dll
2015-02-18 21:52 - 2010-02-10 22:06 - 00398336 _____ () C:\ProgramData\Mobile Partner\OnlineUpdate\QtXml4.dll
2014-02-25 07:39 - 2014-02-25 07:39 - 00013576 _____ () C:\Program Files (x86)\Lenovo\Motion Control\PointGrabDeviceAPI.dll
2014-07-22 19:06 - 2014-07-22 19:06 - 00102672 _____ () C:\Program Files (x86)\Lenovo\Lenovo Transition\Config\1366\TransitionLib.dll
2014-07-22 19:06 - 2014-07-22 19:06 - 00101648 _____ () C:\Program Files (x86)\Lenovo\Lenovo Transition\LUpdatePackage.dll
2014-07-22 19:06 - 2014-07-22 19:06 - 00101648 _____ () C:\Program Files (x86)\Lenovo\Lenovo Smart Voice\LUpdatePackage.dll
2015-04-01 15:43 - 2015-04-01 15:43 - 00316576 _____ () C:\Program Files\Microsoft Office 15\Root\VFS\ProgramFilesCommonX86\Microsoft Shared\OFFICE15\AppVIsvStream32.dll
2015-04-01 15:42 - 2015-04-01 15:42 - 00316576 _____ () C:\Program Files\Microsoft Office 15\Root\Office15\AppVIsvStream32.dll
2014-07-22 18:28 - 2013-09-17 03:17 - 01242584 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll
2014-02-25 07:39 - 2014-02-25 07:39 - 02690312 _____ () C:\Program Files (x86)\Lenovo\Motion Control\WebcamSplitterFilter.ax
2015-06-24 00:10 - 2015-06-20 13:46 - 01281864 _____ () C:\Program Files (x86)\Google\Chrome\Application\43.0.2357.130\libglesv2.dll
2015-06-24 00:10 - 2015-06-20 13:46 - 00080712 _____ () C:\Program Files (x86)\Google\Chrome\Application\43.0.2357.130\libegl.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
AlternateDataStreams: C:\Users\Keng Ling\OneDrive:ms-properties
==================== Safe Mode (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""
==================== EXE Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-648119318-4113145362-2409287244-1001\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Lenovo\LenovoWallPaper.jpg
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
(Currently there is no automatic fix for this section.)
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [{5536175F-D753-4FFC-8566-850AB49991B4}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
FirewallRules: [{9E32A640-318B-4D4F-80E6-8C989B4154A5}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
FirewallRules: [{BC3B45A1-0B93-4936-B69B-322F57DD121F}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
FirewallRules: [{711B98C1-0609-409C-85FF-781FEA8B69EE}] => (Allow) C:\Program Files\CyberLink\PowerDirector10\PDR10.EXE
FirewallRules: [{9BD8A0EB-31B0-4E8E-9C4E-1CAF25FA315A}] => (Allow) C:\Program Files (x86)\Lenovo\Lenovo Photo Master\PhotoPlus.exe
FirewallRules: [{70F9C12A-1BAA-4B2A-97CE-49A5D9A578E8}] => (Allow) C:\Program Files (x86)\Lenovo\Lenovo Photo Master\subsys\AdvPhotoEditor\PhotoDirector5.exe
FirewallRules: [{2C76A6A0-460C-41B4-910C-25B4B355C56E}] => (Allow) LPort=55100
FirewallRules: [{A28978D5-130D-4775-8831-02512A8D2144}] => (Allow) C:\Program Files\Lenovo PhotoMasterImport\PhotoMasterImport.exe
FirewallRules: [{8D9556FF-5BFF-47D7-B5BA-BD3C2238D350}] => (Allow) C:\Users\Keng Ling\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe
FirewallRules: [{6CD11B93-F829-47C1-8C88-99ED74F3566E}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\outlook.exe
FirewallRules: [{6052E8A8-F2B2-4B06-8B76-5616A2AEB80B}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (08/06/2015 09:57:39 AM) (Source: LenovoWiFiHotspotSvr) (EventID: 1) (User: )
Description: LenovoWiFiHotspotSvrCommandMonitorThread,StopICS success. failed with 0
Error: (08/06/2015 09:57:21 AM) (Source: LenovoWiFiHotspotSvr) (EventID: 1) (User: )
Description: LenovoWiFiHotspotSvrEnter ThreadNetworkMonitorAtRunTime. failed with 0
Error: (08/06/2015 09:55:36 AM) (Source: LenovoWiFiHotspotSvr) (EventID: 1) (User: )
Description: LenovoWiFiHotspotSvrSvc RESUMEAUTOMATIC control event received. failed with 0
Error: (08/06/2015 09:51:42 AM) (Source: PhoneCompanionVap_ICS) (EventID: 1) (User: )
Description: PhoneCompanionVap_ICSIcsMgr : Enable Ics Get Public Guid error. failed with -2147024809
Error: (08/06/2015 09:51:42 AM) (Source: LenovoWiFiHotspotSvr) (EventID: 1) (User: )
Description: LenovoWiFiHotspotSvrCommandMonitorThread,Network state change event received. failed with 0
Error: (08/06/2015 09:51:42 AM) (Source: PhoneCompanionVap_ICS) (EventID: 1) (User: )
Description: PhoneCompanionVap_ICSIcsMgr : Enable Ics Get Public Guid error. failed with -2147024809
Error: (08/06/2015 09:51:42 AM) (Source: LenovoWiFiHotspotSvr) (EventID: 1) (User: )
Description: LenovoWiFiHotspotSvrCommandMonitorThread,Network state change event received. failed with 0
Error: (08/06/2015 09:51:41 AM) (Source: PhoneCompanionVap_ICS) (EventID: 1) (User: )
Description: PhoneCompanionVap_ICSIcsMgr : Enable Ics Get Public Guid error. failed with -2147024809
Error: (08/06/2015 09:51:41 AM) (Source: LenovoWiFiHotspotSvr) (EventID: 1) (User: )
Description: LenovoWiFiHotspotSvrCommandMonitorThread,Network state change event received. failed with 0
Error: (08/06/2015 09:51:41 AM) (Source: PhoneCompanionVap_ICS) (EventID: 1) (User: )
Description: PhoneCompanionVap_ICSIcsMgr : Enable Ics Get Public Guid error. failed with -2147024809
System errors:
=============
Error: (08/06/2015 09:59:37 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Google Update Service (gupdate) service failed to start due to the following error:
%%2
Error: (08/06/2015 09:57:47 AM) (Source: DCOM) (EventID: 10016) (User: PEANUT)
Description: application-specificLocalLaunch{7022A3B3-D004-4F52-AF11-E9E987FEE25F}{ADA41B3C-C6FD-4A08-8CC1-D6EFDE67BE7D}PeanutKeng LingS-1-5-21-648119318-4113145362-2409287244-1001LocalHost (Using LRPC)UnavailableUnavailable
Error: (08/06/2015 09:57:47 AM) (Source: DCOM) (EventID: 10016) (User: PEANUT)
Description: application-specificLocalLaunch{7022A3B3-D004-4F52-AF11-E9E987FEE25F}{ADA41B3C-C6FD-4A08-8CC1-D6EFDE67BE7D}PeanutKeng LingS-1-5-21-648119318-4113145362-2409287244-1001LocalHost (Using LRPC)UnavailableUnavailable
Error: (08/06/2015 09:57:23 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Mobile Partner. OUC service failed to start due to the following error:
%%1053
Error: (08/06/2015 09:57:23 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Mobile Partner. OUC service to connect.
Error: (08/06/2015 09:56:38 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Group Policy Client service failed to start due to the following error:
%%1053
Error: (08/06/2015 09:56:38 AM) (Source: DCOM) (EventID: 10010) (User: PEANUT)
Description: {82C49192-BE68-467F-BF50-971FD01DABF3}
Error: (08/06/2015 09:56:38 AM) (Source: DCOM) (EventID: 10010) (User: PEANUT)
Description: {03E64E17-B220-4052-9B9B-155F9CB8E016}
Error: (08/06/2015 09:56:37 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Application Experience service failed to start due to the following error:
%%1053
Error: (08/06/2015 09:56:37 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Group Policy Client service failed to start due to the following error:
%%1053
Microsoft Office:
=========================
Error: (08/06/2015 09:57:39 AM) (Source: LenovoWiFiHotspotSvr) (EventID: 1) (User: )
Description: LenovoWiFiHotspotSvrCommandMonitorThread,StopICS success. failed with 0
Error: (08/06/2015 09:57:21 AM) (Source: LenovoWiFiHotspotSvr) (EventID: 1) (User: )
Description: LenovoWiFiHotspotSvrEnter ThreadNetworkMonitorAtRunTime. failed with 0
Error: (08/06/2015 09:55:36 AM) (Source: LenovoWiFiHotspotSvr) (EventID: 1) (User: )
Description: LenovoWiFiHotspotSvrSvc RESUMEAUTOMATIC control event received. failed with 0
Error: (08/06/2015 09:51:42 AM) (Source: PhoneCompanionVap_ICS) (EventID: 1) (User: )
Description: PhoneCompanionVap_ICSIcsMgr : Enable Ics Get Public Guid error. failed with -2147024809
Error: (08/06/2015 09:51:42 AM) (Source: LenovoWiFiHotspotSvr) (EventID: 1) (User: )
Description: LenovoWiFiHotspotSvrCommandMonitorThread,Network state change event received. failed with 0
Error: (08/06/2015 09:51:42 AM) (Source: PhoneCompanionVap_ICS) (EventID: 1) (User: )
Description: PhoneCompanionVap_ICSIcsMgr : Enable Ics Get Public Guid error. failed with -2147024809
Error: (08/06/2015 09:51:42 AM) (Source: LenovoWiFiHotspotSvr) (EventID: 1) (User: )
Description: LenovoWiFiHotspotSvrCommandMonitorThread,Network state change event received. failed with 0
Error: (08/06/2015 09:51:41 AM) (Source: PhoneCompanionVap_ICS) (EventID: 1) (User: )
Description: PhoneCompanionVap_ICSIcsMgr : Enable Ics Get Public Guid error. failed with -2147024809
Error: (08/06/2015 09:51:41 AM) (Source: LenovoWiFiHotspotSvr) (EventID: 1) (User: )
Description: LenovoWiFiHotspotSvrCommandMonitorThread,Network state change event received. failed with 0
Error: (08/06/2015 09:51:41 AM) (Source: PhoneCompanionVap_ICS) (EventID: 1) (User: )
Description: PhoneCompanionVap_ICSIcsMgr : Enable Ics Get Public Guid error. failed with -2147024809
==================== Memory info ===========================
Processor: Intel(R) Core(TM) i3-4030U CPU @ 1.90GHz
Percentage of memory in use: 47%
Total physical RAM: 4016.96 MB
Available physical RAM: 2125.46 MB
Total Virtual: 5296.96 MB
Available Virtual: 2953.79 MB
==================== Drives ================================
Drive c: (Windows8_OS) (Fixed) (Total:423.21 GB) (Free:343.86 GB) NTFS ==>[system with boot components (obtained from reading drive)]
Drive d: (LENOVO) (Fixed) (Total:25 GB) (Free:22.56 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 465.8 GB) (Disk ID: 87D8B3AE)
Partition: GPT Partition Type.
==================== End of log ============================