My laptop is only a few months into its working life and internet explorer has been hijacked by istartsurf.
I have not attempted to remove this product. I have searched Norton360 help for recommended action and their advice is to get assistance from one of the recommended malware forums, such as "What the Tech". I hope your experts can provide some assistance to remove this from my laptop.
aswMBR.txt 6.2KB
321 downloadsTony
Requested output below:-
Start of FSRT.txt
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:24-08-2015
Ran by PAK (administrator) on PAKCONSULTING (25-08-2015 14:46:37)
Running from C:\Users\PAK\Downloads
Loaded Profiles: UpdatusUser & PAK (Available Profiles: UpdatusUser & PAK)
Platform: Windows 8.1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Conexant Systems Inc.) C:\Windows\System32\CxAudMsg64.exe
(Juniper Networks) C:\Program Files (x86)\Juniper Networks\Common Files\dsNcService.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\ibtsiva.exe
(Intel® Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(LENOVO INCORPORATED.) C:\Program Files\lenovo\iMController\SystemAgentService.exe
(Lenovo(beijing) Limited) C:\Windows\System32\LenovoWiFiHotspotSvr.exe
(Maxthon) C:\Program Files (x86)\Maxthon\Modules\Service\Update\MaxthonUpdateSvc.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\systemcore\mfemms.exe
(McAfee, Inc.) C:\Windows\System32\mfevtps.exe
(Symantec Corporation) C:\Program Files (x86)\Norton 360\Engine\22.5.2.15\n360.exe
(Nitro PDF Software) C:\Program Files\Common Files\Nitro\Pro\9.0\NitroPDFDriverService9x64.exe
(Nalpeiron Ltd.) C:\Windows\SysWOW64\NLSSRV32.EXE
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Intel® Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
() C:\Program Files\CyberLink\Shared files\RichVideo64.exe
(Conexant Systems, Inc.) C:\Windows\SysWOW64\SASrv.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
() C:\Program Files (x86)\Lenovo\Lenovo VeriFace\VfConnectorService.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
() C:\Program Files (x86)\Lenovo\CCSDK\CCSDK.exe
(Intel Corporation) C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\CSP\1.5.495.0\McCSPServiceHost.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\platform\McSvcHost\McSvHost.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Symantec Corporation) C:\Program Files (x86)\Norton 360\Engine\22.5.2.15\n360.exe
(Pokki) C:\Users\PAK\AppData\Local\Pokki\Engine\ServiceHostAppUpdater.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
(Intel Corporation) C:\Windows\System32\igfxTray.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDIntelligent.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
() C:\Program Files (x86)\Lenovo\CCSDK\WinGather.exe
(Pokki) C:\Users\PAK\AppData\Local\Pokki\Engine\ServiceHostApp.exe
(Microsoft Corporation) C:\Windows\System32\WWAHost.exe
(Pokki) C:\Users\PAK\AppData\Local\Pokki\Engine\ServiceHostApp.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe
(Alcor) C:\Windows\WebCam\S6000\S6000Mnt.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\CAudioFilterAgent64.exe
() C:\Program Files\CONEXANT\ForteConfig\fmapp.exe
() C:\Program Files\Stagelight\StagelightUpdate.exe
(Lenovo) C:\Program Files\lenovo\Onekey Theater\OnekeyStudio.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Manager\utility.exe
(CyberLink) C:\Program Files (x86)\Lenovo\Power2Go\CLMLSvc_P2G8.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(Pokki) C:\Users\PAK\AppData\Local\Pokki\Engine\ServiceStartMenuIndexer.exe
(Citrix Systems, Inc.) C:\Program Files (x86)\Citrix\ICA Client\concentr.exe
(Citrix Systems, Inc.) C:\Program Files (x86)\Citrix\ICA Client\Receiver\Receiver.exe
(Citrix Systems, Inc.) C:\Program Files (x86)\Citrix\ICA Client\redirector.exe
(Citrix Systems, Inc.) C:\Program Files (x86)\Citrix\ICA Client\wfcrun32.exe
(Citrix Systems, Inc.) C:\Program Files (x86)\Citrix\ICA Client\SelfServicePlugin\SelfServicePlugin.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(CyberLink Corp.) C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\platform\McUICnt.exe
(Intel Corporation) C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
(McAfee, Inc.) C:\Program Files\mcafee\virusscan\mcods.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
(Symantec Corporation) C:\Program Files (x86)\Norton 360\Engine\22.5.2.15\conathst.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\44.0.2403.157\nacl64.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\44.0.2403.157\nacl64.exe
(AVAST Software) C:\Users\PAK\Downloads\aswMBR.exe
(Farbar) C:\Users\PAK\Downloads\FRST64 (1).exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [Nvtmru] => C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1028384 2013-10-18] (NVIDIA Corporation)
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe [287592 2014-02-27] (Intel Corporation)
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2891080 2013-10-17] (ELAN Microelectronics Corp.)
HKLM\...\Run: [S6000Mnt] => C:\windows\WebCam\S6000\S6000Mnt.exe [516608 2015-05-21] (Alcor)
HKLM\...\Run: [BTMTrayAgent] => rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll",TrayApp
HKLM\...\Run: [cAudioFilterAgent] => C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [907480 2013-09-05] (Conexant Systems, Inc.)
HKLM\...\Run: [ForteConfig] => C:\Program Files\Conexant\ForteConfig\fmapp.exe [49056 2010-10-26] ()
HKLM\...\Run: [SmartAudio] => C:\Program Files\CONEXANT\SAII\SACpl.exe [1647616 2012-06-13] (Conexant Systems, Inc.)
HKLM\...\Run: [StageLightUpdate] => C:\Program Files\Stagelight\StagelightUpdate.exe [1397208 2014-08-30] ()
HKLM\...\Run: [OnekeyStudio] => C:\Program Files\Lenovo\Onekey Theater\OnekeyStudio.exe [4196432 2012-09-15] (Lenovo)
HKLM\...\Run: [Energy Manager] => C:\Program Files (x86)\Lenovo\Energy Manager\Energy Manager.exe [15813616 2015-03-18] (Lenovo(beijing) Limited)
HKLM\...\Run: [Lenovo Utility] => C:\Program Files (x86)\Lenovo\Energy Manager\Utility.exe [80880 2015-03-18] (Lenovo(beijing) Limited)
HKLM-x32\...\Run: [CLMLServer_For_P2G8] => C:\Program Files (x86)\Lenovo\Power2Go\CLMLSvc_P2G8.exe [110344 2014-09-09] (CyberLink)
HKLM-x32\...\Run: [CLVirtualDrive] => C:\Program Files (x86)\Lenovo\Power2Go\VirtualDrive.exe [492808 2014-09-09] (CyberLink Corp.)
HKLM-x32\...\Run: [ConnectionCenter] => C:\Program Files (x86)\Citrix\ICA Client\concentr.exe [518496 2015-06-24] (Citrix Systems, Inc.)
HKLM-x32\...\Run: [Redirector] => C:\Program Files (x86)\Citrix\ICA Client\redirector.exe [231776 2015-06-24] (Citrix Systems, Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [597552 2015-08-04] (Oracle Corporation)
HKU\S-1-5-21-3391081986-1551245901-393088480-1002\...\RunOnce: [Application Restart #1] => C:\Users\PAK\AppData\Local\Pokki\Engine\HostAppService.exe --disable-internal-flash --noerrdialogs --no-message-box --disable-extensions --disable-web-security --disable-web-resources --disable-clien (the data entry has 545 more characters).
AppInit_DLLs: C:\PROGRA~2\LENOVO~1\LENOVO~1\bin\SPVC64~1.DLL => C:\Program Files (x86)\LenovoBrowserGuard\LenovoBrowserGuard\bin\SPVC64Loader.dll [206152 2014-07-22] (ClientConnect LTD)
AppInit_DLLs: C:\PROGRA~2\Amazon\AMAZON~1\AMAZON~2.DLL => C:\Program Files (x86)\Amazon\Amazon1ButtonApp\AmazonExtIE64.dll [119616 2014-09-27] (Amazon Inc.)
AppInit_DLLs-x32: C:\PROGRA~2\LENOVO~1\LENOVO~1\bin\SPVC32~1.DLL => C:\Program Files (x86)\LenovoBrowserGuard\LenovoBrowserGuard\bin\SPVC32Loader.dll [173896 2014-07-22] (ClientConnect LTD)
AppInit_DLLs-x32: C:\PROGRA~2\Amazon\AMAZON~1\AMAZON~3.DLL => C:\Program Files (x86)\Amazon\Amazon1ButtonApp\AmazonExtIE.dll [106304 2014-09-27] (Amazon Inc.)
ShellIconOverlayIdentifiers: [ OverlayExcluded] -> {4433A54A-1AC8-432F-90FC-85F045CF383C} => C:\Program Files (x86)\Norton 360\Engine64\22.5.2.15\buShell.dll [2015-07-13] (Symantec Corporation)
ShellIconOverlayIdentifiers: [ OverlayPending] -> {F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225} => C:\Program Files (x86)\Norton 360\Engine64\22.5.2.15\buShell.dll [2015-07-13] (Symantec Corporation)
ShellIconOverlayIdentifiers: [ OverlayProtected] -> {476D0EA3-80F9-48B5-B70B-05E677C9C148} => C:\Program Files (x86)\Norton 360\Engine64\22.5.2.15\buShell.dll [2015-07-13] (Symantec Corporation)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.istartsurf.com/?type=hp&ts=1437108416&z=1b940540ac02be4e5d3b2edg1zdcdm4g2e5b2c1t8q&from=tugs&uid=WDCXWD10JPCX-24UE4T0_WD-WXP1E946AJ096AJ09
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.istartsurf.com/?type=hp&ts=1437108416&z=1b940540ac02be4e5d3b2edg1zdcdm4g2e5b2c1t8q&from=tugs&uid=WDCXWD10JPCX-24UE4T0_WD-WXP1E946AJ096AJ09
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.istartsurf.com/web/?type=ds&ts=1437108416&z=1b940540ac02be4e5d3b2edg1zdcdm4g2e5b2c1t8q&from=tugs&uid=WDCXWD10JPCX-24UE4T0_WD-WXP1E946AJ096AJ09&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.istartsurf.com/web/?type=ds&ts=1437108416&z=1b940540ac02be4e5d3b2edg1zdcdm4g2e5b2c1t8q&from=tugs&uid=WDCXWD10JPCX-24UE4T0_WD-WXP1E946AJ096AJ09&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.istartsurf.com/?type=hp&ts=1437108416&z=1b940540ac02be4e5d3b2edg1zdcdm4g2e5b2c1t8q&from=tugs&uid=WDCXWD10JPCX-24UE4T0_WD-WXP1E946AJ096AJ09
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.istartsurf.com/?type=hp&ts=1437108416&z=1b940540ac02be4e5d3b2edg1zdcdm4g2e5b2c1t8q&from=tugs&uid=WDCXWD10JPCX-24UE4T0_WD-WXP1E946AJ096AJ09
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.istartsurf.com/web/?type=ds&ts=1437108416&z=1b940540ac02be4e5d3b2edg1zdcdm4g2e5b2c1t8q&from=tugs&uid=WDCXWD10JPCX-24UE4T0_WD-WXP1E946AJ096AJ09&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.istartsurf.com/web/?type=ds&ts=1437108416&z=1b940540ac02be4e5d3b2edg1zdcdm4g2e5b2c1t8q&from=tugs&uid=WDCXWD10JPCX-24UE4T0_WD-WXP1E946AJ096AJ09&q={searchTerms}
HKU\S-1-5-21-3391081986-1551245901-393088480-1002\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yahoo.com.au/
HKU\S-1-5-21-3391081986-1551245901-393088480-1002\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.istartsurf.com/?type=hp&ts=1437108416&z=1b940540ac02be4e5d3b2edg1zdcdm4g2e5b2c1t8q&from=tugs&uid=WDCXWD10JPCX-24UE4T0_WD-WXP1E946AJ096AJ09
HKU\S-1-5-21-3391081986-1551245901-393088480-1002\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://mystart.lenovo.com
URLSearchHook: [S-1-5-21-3391081986-1551245901-393088480-1001] ATTENTION => Default URLSearchHook is missing
SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.istartsurf.com/web/?type=ds&ts=1437108416&z=1b940540ac02be4e5d3b2edg1zdcdm4g2e5b2c1t8q&from=tugs&uid=WDCXWD10JPCX-24UE4T0_WD-WXP1E946AJ096AJ09&q={searchTerms}
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.istartsurf.com/web/?type=ds&ts=1437108416&z=1b940540ac02be4e5d3b2edg1zdcdm4g2e5b2c1t8q&from=tugs&uid=WDCXWD10JPCX-24UE4T0_WD-WXP1E946AJ096AJ09&q={searchTerms}
SearchScopes: HKLM-x32 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.istartsurf.com/web/?type=ds&ts=1437108416&z=1b940540ac02be4e5d3b2edg1zdcdm4g2e5b2c1t8q&from=tugs&uid=WDCXWD10JPCX-24UE4T0_WD-WXP1E946AJ096AJ09&q={searchTerms}
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.istartsurf.com/web/?type=ds&ts=1437108416&z=1b940540ac02be4e5d3b2edg1zdcdm4g2e5b2c1t8q&from=tugs&uid=WDCXWD10JPCX-24UE4T0_WD-WXP1E946AJ096AJ09&q={searchTerms}
SearchScopes: HKU\S-1-5-21-3391081986-1551245901-393088480-1002 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-3391081986-1551245901-393088480-1002 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.istartsurf.com/web/?type=ds&ts=1437108416&z=1b940540ac02be4e5d3b2edg1zdcdm4g2e5b2c1t8q&from=tugs&uid=WDCXWD10JPCX-24UE4T0_WD-WXP1E946AJ096AJ09&q={searchTerms}
BHO: Norton Identity Protection -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files (x86)\Norton 360\Engine64\22.5.2.15\coIEPlg.dll [2015-07-10] (Symantec Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2015-07-14] (Microsoft Corporation)
BHO-x32: Norton Identity Protection -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files (x86)\Norton 360\Engine\22.5.2.15\coIEPlg.dll [2015-07-10] (Symantec Corporation)
BHO-x32: Java Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\ssv.dll [2015-08-25] (Oracle Corporation)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2015-07-14] (Microsoft Corporation)
BHO-x32: Java Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\jp2ssv.dll [2015-08-25] (Oracle Corporation)
Toolbar: HKLM - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine64\22.5.2.15\coIEPlg.dll [2015-07-10] (Symantec Corporation)
Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\22.5.2.15\coIEPlg.dll [2015-07-10] (Symantec Corporation)
DPF: HKLM-x32 {997C5A94-77F6-427D-A388-AC2B6ECF0F7C} hxxp://qadsvr:8080/qadhome/client/setup.ocx
DPF: HKLM-x32 {F27237D7-93C8-44C2-AC6E-D6057B9A918F} hxxps://juniper.net/dana-cached/sc/JuniperSetupClient.cab
Filter-x32: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2015-06-24] (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2015-06-24] (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2015-06-24] (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2015-06-24] (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2015-06-24] (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2015-06-24] (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2015-06-24] (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2015-06-24] (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2015-06-24] (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2015-06-24] (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2015-06-24] (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2015-06-24] (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2015-06-24] (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2015-06-24] (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2015-06-24] (Citrix Systems, Inc.)
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\mcafee\msc\McSnIePl64.dll [2015-05-13] (McAfee, Inc.)
Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\msc\McSnIePl.dll [2015-05-13] (McAfee, Inc.)
Filter-x32: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2015-06-24] (Citrix Systems, Inc.)
Tcpip\Parameters: [DhcpNameServer] 198.142.0.51 211.29.132.12 198.142.235.14
Tcpip\..\Interfaces\{13259943-55A7-4692-8AB0-994F99AC2959}: [DhcpNameServer] 198.142.0.51 211.29.132.12 198.142.235.14
Tcpip\..\Interfaces\{5346D710-70A0-4BD9-82A0-F4EFABDB6A47}: [DhcpNameServer] 198.142.0.51 211.29.132.12 198.142.235.14
Tcpip\..\Interfaces\{971A15C5-34AC-4406-ACFB-5CAE1636289F}: [DhcpNameServer] 192.168.40.3 192.168.40.7
FireFox:
========
FF Plugin: @mcafee.com/MSC,version=10 -> c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL [2015-05-13] ()
FF Plugin-x32: @Citrix.com/npican -> C:\Program Files (x86)\Citrix\ICA Client\npicaN.dll [2015-06-24] (Citrix Systems, Inc.)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-09-17] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-09-17] (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.60.2 -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\dtplugin\npDeployJava1.dll [2015-08-25] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.60.2 -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\plugin2\npjp2.dll [2015-08-25] (Oracle Corporation)
FF Plugin-x32: @mcafee.com/MSC,version=10 -> c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL [2015-05-13] ()
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation)
FF Plugin-x32: @nitropdf.com/NitroPDF -> C:\Program Files (x86)\Nitro\Pro 9\npnitromozilla.dll [2013-12-13] (Nitro PDF)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-19] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-19] (Google Inc.)
FF HKLM-x32\...\Firefox\Extensions: [{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_22.5.0.124\coFFPlgn
FF Extension: Norton Toolbar - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_22.5.0.124\coFFPlgn [2015-08-25]
FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK
FF Extension: McAfee Anti-Spam Thunderbird Extension - C:\Program Files\McAfee\MSK [2015-03-18]
Chrome:
=======
CHR Profile: C:\Users\PAK\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\PAK\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-07-17]
CHR Extension: (Google Docs) - C:\Users\PAK\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-07-17]
CHR Extension: (Google Drive) - C:\Users\PAK\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-07-17]
CHR Extension: (YouTube) - C:\Users\PAK\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-07-17]
CHR Extension: (Norton Security Toolbar) - C:\Users\PAK\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjabmdjcfcfdmffimndhafhblfmpjdpe [2015-07-17]
CHR Extension: (Google Search) - C:\Users\PAK\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-07-17]
CHR Extension: (Google Sheets) - C:\Users\PAK\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-07-17]
CHR Extension: (Norton Identity Safe) - C:\Users\PAK\AppData\Local\Google\Chrome\User Data\Default\Extensions\iikflkcanblccfahdhdonehdalibjnif [2015-07-17]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\PAK\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-07-17]
CHR Extension: (Chrome Web Store Payments) - C:\Users\PAK\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-07-17]
CHR Extension: (Gmail) - C:\Users\PAK\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-07-17]
CHR HKLM\...\Chrome\Extension: [cjabmdjcfcfdmffimndhafhblfmpjdpe] - C:\Program Files (x86)\Norton 360\Engine\22.5.2.15\Exts\Chrome.crx [2015-07-28]
CHR HKLM-x32\...\Chrome\Extension: [cjabmdjcfcfdmffimndhafhblfmpjdpe] - C:\Program Files (x86)\Norton 360\Engine\22.5.2.15\Exts\Chrome.crx [2015-07-28]
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 BthHFSrv; C:\Windows\System32\BthHFSrv.dll [324608 2014-10-29] (Microsoft Corporation)
R2 CCSDK; C:\Program Files (x86)\Lenovo\CCSDK\CCSDK.exe [592880 2014-07-10] ()
R2 ETDService; C:\Program Files\Elantech\ETDService.exe [99632 2013-10-09] (ELAN Microelectronics Corp.)
S2 HomeNetSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [340744 2015-05-06] (McAfee, Inc.)
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [16232 2014-02-27] (Intel Corporation)
R2 iBtSiva; C:\Program Files (x86)\Intel\Bluetooth\ibtsiva.exe [121304 2014-08-07] (Intel Corporation)
R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [318568 2014-08-20] (Intel Corporation)
R2 Intel® Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [747520 2013-08-28] (Intel® Corporation) [File not signed]
S3 Intel® Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [828376 2013-08-28] (Intel® Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe [169432 2013-09-17] (Intel Corporation)
S3 Lenovo EasyPlus Hotspot; C:\Program Files (x86)\Common Files\lenovo\easyplussdk\bin\EPHotspot64.exe [561408 2014-09-23] (Lenovo)
R2 Lenovo System Agent Service; C:\Program Files\Lenovo\iMController\SystemAgentService.exe [584632 2015-03-06] (LENOVO INCORPORATED.)
R2 LenovoWiFiHotspotSvr; C:\Windows\System32\LenovoWiFiHotspotSvr.exe [198192 2015-03-18] (Lenovo(beijing) Limited)
R2 MaxthonUpdateSvc; C:\Program Files (x86)\Maxthon\Modules\Service\Update\MaxthonUpdateSvc.exe [1844024 2014-08-01] (Maxthon)
S3 McAPExe; C:\Program Files\McAfee\MSC\McAPExe.exe [754280 2015-05-13] (McAfee, Inc.)
S3 McAWFwk; c:\Program Files\Common Files\McAfee\ActWiz\McAWFwk.exe [332528 2014-03-13] (McAfee, Inc.)
S2 mcbootdelaystartsvc; C:\Program Files\Common Files\McAfee\platform\McSvcHost\McSvHost.exe [340744 2015-05-06] (McAfee, Inc.)
R2 mccspsvc; C:\Program Files\Common Files\McAfee\CSP\1.5.495.0\McCSPServiceHost.exe [207344 2015-06-04] (McAfee, Inc.)
S3 McMPFSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [340744 2015-05-06] (McAfee, Inc.)
S3 McNaiAnn; C:\Program Files\Common Files\McAfee\platform\McSvcHost\McSvHost.exe [340744 2015-05-06] (McAfee, Inc.)
R3 McODS; C:\Program Files\mcafee\VirusScan\mcods.exe [599304 2014-04-15] (McAfee, Inc.)
S4 McOobeSv2; C:\Program Files\Common Files\McAfee\platform\McSvcHost\McSvHost.exe [340744 2015-05-06] (McAfee, Inc.)
U3 mcpltsvc; C:\Program Files\Common Files\McAfee\platform\McSvcHost\McSvHost.exe [340744 2015-05-06] (McAfee, Inc.)
S3 McProxy; C:\Program Files\Common Files\McAfee\platform\McSvcHost\McSvHost.exe [340744 2015-05-06] (McAfee, Inc.)
S3 mfecore; C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe [1041192 2014-03-19] (McAfee, Inc.)
S3 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [232656 2015-04-08] (McAfee, Inc.)
R2 mfemms; C:\Program Files\Common Files\McAfee\SystemCore\\mfemms.exe [373704 2015-05-14] (McAfee, Inc.)
U2 mfevtp; C:\windows\system32\mfevtps.exe [250672 2015-04-08] (McAfee, Inc.)
U3 MSK80Service; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [340744 2015-05-06] (McAfee, Inc.)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [284912 2013-11-21] ()
R2 N360; C:\Program Files (x86)\Norton 360\Engine\22.5.2.15\N360.exe [282016 2015-07-17] (Symantec Corporation)
R2 NitroDriverReadSpool9; C:\Program Files\Common Files\Nitro\Pro\9.0\NitroPDFDriverService9x64.exe [230920 2013-12-13] (Nitro PDF Software)
R2 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [390632 2012-04-24] ()
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [5611280 2015-08-07] (TeamViewer GmbH)
R2 VeriFaceSrv; C:\Program Files (x86)\Lenovo\Lenovo VeriFace\VfConnectorService.exe [68368 2015-03-18] ()
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366552 2015-07-07] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2015-07-07] (Microsoft Corporation)
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3674864 2013-11-21] (Intel® Corporation)
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R1 BHDrvx64; C:\Program Files (x86)\Norton 360\NortonData\22.5.0.124\Definitions\BASHDefs\20150810.001\BHDrvx64.sys [1650936 2015-07-24] (Symantec Corporation)
R3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [226304 2014-03-18] (Microsoft Corporation)
R3 btmaux; C:\Windows\system32\DRIVERS\btmaux.sys [141624 2014-05-14] (Motorola Solutions, Inc.)
R3 btmhsf; C:\Windows\system32\DRIVERS\btmhsf.sys [1424184 2014-06-18] (Motorola Solutions, Inc.)
R1 ccSet_N360; C:\Windows\system32\drivers\N360x64\1605020.00F\ccSetx64.sys [173808 2015-07-11] (Symantec Corporation)
S3 cfwids; C:\Windows\System32\drivers\cfwids.sys [68784 2015-04-08] (McAfee, Inc.)
R1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [91912 2013-11-13] (CyberLink)
R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [498512 2015-07-28] (Symantec Corporation)
R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [153936 2015-07-28] (Symantec Corporation)
S3 HipShieldK; C:\Windows\System32\drivers\HipShieldK.sys [197704 2013-09-24] (McAfee, Inc.)
R3 ibtusb; C:\Windows\system32\DRIVERS\ibtusb.sys [220104 2014-08-07] (Intel Corporation)
R1 IDSVia64; C:\Program Files (x86)\Norton 360\NortonData\22.5.0.124\Definitions\IPSDefs\20150821.001\IDSvia64.sys [692984 2015-07-16] (Symantec Corporation)
R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [99288 2013-09-17] (Intel Corporation)
R3 mfeaack; C:\Windows\System32\drivers\mfeaack.sys [402888 2015-04-08] (McAfee, Inc.)
R3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [338272 2015-04-08] (McAfee, Inc.)
R0 mfedisk; C:\Windows\System32\DRIVERS\mfedisk.sys [101872 2015-04-08] (McAfee, Inc.)
S0 mfeelamk; C:\Windows\System32\drivers\mfeelamk.sys [80160 2015-04-08] (McAfee, Inc.)
R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [488000 2015-04-08] (McAfee, Inc.)
R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [864200 2015-04-08] (McAfee, Inc.)
R3 mfencbdc; C:\Windows\system32\DRIVERS\mfencbdc.sys [441264 2014-03-19] (McAfee, Inc.)
S3 mfencrk; C:\Windows\system32\DRIVERS\mfencrk.sys [96592 2014-03-19] (McAfee, Inc.)
R0 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [335944 2015-04-08] (McAfee, Inc.)
R3 NAVENG; C:\Program Files (x86)\Norton 360\NortonData\22.5.0.124\Definitions\VirusDefs\20150824.003\ENG64.SYS [138488 2015-05-20] (Symantec Corporation)
R3 NAVEX15; C:\Program Files (x86)\Norton 360\NortonData\22.5.0.124\Definitions\VirusDefs\20150824.003\EX64.SYS [2146040 2015-05-20] (Symantec Corporation)
R3 NETwNb64; C:\Windows\system32\DRIVERS\NETwbw02.sys [3609568 2013-12-25] (Intel Corporation)
S3 NETwNe64; C:\Windows\system32\DRIVERS\NETwew02.sys [4649440 2013-06-19] (Intel Corporation)
R3 S6000KNT; C:\Windows\System32\Drivers\S6000KNT.sys [899712 2015-05-21] (Bison)
R1 SRTSP; C:\Windows\System32\Drivers\N360x64\1605020.00F\SRTSP64.SYS [926448 2015-07-11] (Symantec Corporation)
R1 SRTSPX; C:\Windows\system32\drivers\N360x64\1605020.00F\SRTSPX64.SYS [50936 2015-07-11] (Symantec Corporation)
R0 SymEFASI; C:\Windows\System32\drivers\N360x64\1605020.00F\SYMEFASI64.SYS [1620720 2015-07-11] (Symantec Corporation)
S0 SymELAM; C:\Windows\System32\drivers\N360x64\1605020.00F\SymELAM.sys [24192 2015-07-11] (Symantec Corporation)
R3 SymEvent; C:\windows\system32\Drivers\SYMEVENT64x86.SYS [111344 2015-07-28] (Symantec Corporation)
R1 SymIRON; C:\Windows\system32\drivers\N360x64\1605020.00F\Ironx64.SYS [297720 2015-07-11] (Symantec Corporation)
R1 SymNetS; C:\Windows\System32\Drivers\N360x64\1605020.00F\SYMNETS.SYS [576248 2015-07-11] (Symantec Corporation)
S3 wsvd; C:\Windows\system32\DRIVERS\wsvd.sys [102376 2012-06-14] ("CyberLink)
U3 aswMBR; \??\C:\Users\PAK\AppData\Local\Temp\aswMBR.sys [X]
U3 aswVmm; \??\C:\Users\PAK\AppData\Local\Temp\aswVmm.sys [X]
========================== Drivers MD5 =======================
C:\Windows\System32\drivers\1394ohci.sys E1832BD9FD7E0FC2DC9FA5935DE3E8C1
C:\Windows\System32\drivers\3ware.sys AD508A1A46EC21B740AB31C28EFDFDB1
C:\Windows\System32\drivers\ACPI.sys E796AE43DDD1844281DB4D57294D17C0
C:\Windows\System32\Drivers\acpiex.sys AC8279D229398BCF05C3154ADCA86813
C:\Windows\System32\drivers\acpipagr.sys A8970D9BF23CD309E0403978A1B58F3F
C:\Windows\System32\drivers\acpipmi.sys 111A89C99C5B4F1A7BCE5F643DD86F65
C:\Windows\System32\drivers\acpitime.sys 5758387D68A20AE7D3245011B07E36E7
C:\Windows\System32\drivers\AcpiVpc.sys AF7A18603B0B82DFA5B420456FAF2201
C:\Windows\System32\drivers\ADP80XX.SYS 7C1FDF1B48298CBA7CE4BDD4978951AD
C:\Windows\system32\drivers\afd.sys 374E27295F0A9DCAA8FC96370F9BEEA5
C:\Windows\System32\drivers\agp440.sys 7DFAEBA9AD62D20102B576D5CAC45EC8
C:\Windows\System32\DRIVERS\ahcache.sys FE14D249D39368CA62D8DA6BC94AC694
C:\Windows\System32\drivers\amdk8.sys 7589DE749DB6F71A68489DCE04158729
C:\Windows\System32\drivers\amdppm.sys B46D2D89AFF8A9490FA8C98C7A5616E3
C:\Windows\System32\drivers\amdsata.sys D2BF2F94A47D332814910FD47C6BBCD2
C:\Windows\System32\drivers\amdsbs.sys A8E04943C7BBA7219AA50400272C3C6E
C:\Windows\System32\drivers\amdxata.sys CEA5F4F27CFC08E3A44D576811B35F50
C:\Windows\system32\drivers\appid.sys 415DD71628795197F7AFC176CBADC74E
C:\Windows\System32\drivers\arcsas.sys 65045784366F7EC5FB4E71BCF923187B
C:\Windows\system32\DRIVERS\asyncmac.sys 3DB7721F06BC2FEDB25029EA23AB27DA
C:\Windows\System32\drivers\atapi.sys 74B14192CF79A72F7536B27CB8814FBD
C:\Windows\System32\drivers\bxvbda.sys A4A73F631FE2AA2826FBE4A399B04DEF
C:\Windows\System32\drivers\BasicDisplay.sys 8CC7F7E4AFCBA605921B137ED7992C68
C:\Windows\System32\drivers\BasicRender.sys 38A82F4EE8C416A6744B6D30381ED768
C:\Windows\System32\drivers\bcmfn2.sys C1ABB0F7E3BEA48A0417BDF6FF14AB21
C:\Windows\System32\Drivers\Beep.sys EC19013E4CF87609534165DF897274D6
C:\Program Files (x86)\Norton 360\NortonData\22.5.0.124\Definitions\BASHDefs\20150810.001\BHDrvx64.sys 3E2882C7D02E34D5528BDDECD8CEF930
C:\Windows\System32\DRIVERS\bowser.sys 6B4FFFDDC618FCF64473CAA86E305697
C:\Windows\System32\drivers\BthAvrcpTg.sys A8F23D453A424FF4DE04989C4727ECC7
C:\Windows\System32\drivers\BthEnum.sys 1104A31260CCF4318C884E0AE6C513BF
C:\Windows\System32\drivers\bthhfenum.sys 272A62B660A48AEF366F8A1836CED19F
C:\Windows\System32\drivers\BthHFHid.sys 71FE2A48E4C93DDB9798C024880B6C07
C:\Windows\system32\DRIVERS\BthLEEnum.sys D30C67473A2E229662D21F27EAA9AAA5
C:\Windows\System32\drivers\bthmodem.sys 66B791F6B11DC4303DD18A224A501542
C:\Windows\System32\drivers\bthpan.sys 25BB93167DEF270188072603F92A1EF5
C:\Windows\System32\Drivers\BTHport.sys 0CC00ADC1B84C93FB46E1A0974E956E1
C:\Windows\System32\Drivers\BTHUSB.sys 08EA90955AED2D959EE67DF6EDF0E2B6
C:\Windows\system32\DRIVERS\btmaux.sys 70F8310E8B36DFCAD9A11720929E20ED
C:\Windows\system32\DRIVERS\btmhsf.sys 94A99773CC88E25E61E99EB137D7C176
C:\Windows\system32\drivers\N360x64\1605020.00F\ccSetx64.sys 5A1C7DBDDB001BC6F1D1720E655445E2
C:\Windows\System32\DRIVERS\cdfs.sys 2FA6510E33F7DEFEC03658B74101A9B9
C:\Windows\System32\drivers\cdrom.sys C6796EA22B513E3457514D92DCDB1A3D
C:\Windows\System32\drivers\cfwids.sys 35584BC0CF9B9F3CDA830396C4DEB6DB
C:\Windows\System32\drivers\circlass.sys BE9936EDD3267FAAFF94A7835867F00B
C:\Windows\System32\drivers\CLFS.sys 8EB7E70C2D348FE2476A2E3F2D585E3D
C:\Windows\system32\DRIVERS\CLVirtualDrive.sys 5C646CAC91E086F7FF53C7F2E857F263
C:\Windows\System32\drivers\CmBatt.sys EF6EF85DADC3184A10D8F2F7159973CB
C:\Windows\System32\Drivers\cng.sys 5E5AB950693F2C6D6ACBEE3A74697ED7
C:\Windows\system32\drivers\CHDRT64.sys 89D4BB6D7655AAC11174530359AD8CF6
C:\Windows\System32\drivers\CompositeBus.sys 03AAED827C36F35D70900558B8274905
C:\Windows\System32\drivers\condrv.sys A1FF7DFBFBE164CF92603C651D304DD2
C:\Windows\system32\DRIVERS\ctxusbm.sys DC08465037FA57A5203BDF3E963422C2
C:\Windows\System32\drivers\dam.sys 315BA4BC19316D72B2E037534E048B93
C:\Windows\System32\Drivers\dfsc.sys A03F362C5557E238CBFA914689C77248
C:\Windows\System32\drivers\disk.sys 4D40C9B33F738797CF50E77CB7C53E85
C:\Windows\System32\drivers\dmvsc.sys EB70A894708D1BC176AFD690FF06085F
C:\Windows\system32\drivers\drmkaud.sys 00C594D5A1DBD22AD8B2902B9F6EFF94
C:\Windows\system32\DRIVERS\dsNcAdpt.sys 0040A0132AAC1004E50055F8FBB14C08
C:\Windows\System32\drivers\dxgkrnl.sys E1BB0B6F00F470B451AB45EA13EBA0B3
C:\Windows\system32\DRIVERS\e1i63x64.sys FA988D76745C917CDFE20031C06DE860
C:\Windows\System32\drivers\evbda.sys 114BCFDF367FF37C3F1B0A96AF542E4D
C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys 93EA893A8C2C561648A559E48C723412
C:\Windows\System32\drivers\EhStorClass.sys 43531A5993380CC5113242C29D265FD9
C:\Windows\System32\drivers\EhStorTcgDrv.sys 6F8E738A9505A388B1157FDDE7B3101B
C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys 8400C9E33B68C556BF63AEF490EB145C
C:\Windows\System32\drivers\errdev.sys DFFFAE1442BA4076E18EED5E406FA0D3
C:\Windows\system32\DRIVERS\ETD.sys C9EC31F59DF549819862E8DA83E5E9B0
C:\Windows\System32\Drivers\exfat.sys 7729D294A555C7AEB281ED8E4D0E01E4
C:\Windows\System32\Drivers\fastfat.sys 7C4E0D5900B2A1D11EDD626D6DDB937B
C:\Windows\System32\drivers\fdc.sys 5D8402613E778B3BD45E687A8372710B
C:\Windows\System32\drivers\fileinfo.sys BCFD8B149B3ADF92D0DB1E909CAF0265
C:\Windows\System32\drivers\filetrace.sys A1A66C4FDAFD6B0289523232AFB7D8AF
C:\Windows\System32\drivers\flpydisk.sys BE743083CF7063C486A4398E3AEFE59A
C:\Windows\System32\drivers\fltmgr.sys C1FB505A73FA2E9019D32444AB33B75A
C:\Windows\System32\drivers\FsDepends.sys A7C31B168F371E8E6796219F23E354DB
C:\Windows\System32\Drivers\Fs_Rec.sys 09F460AFEDCA03F3BF6E07D1CCC9AC42
C:\Windows\System32\DRIVERS\fvevol.sys F152D55E497E12256290C43B31C7D0CE
C:\Windows\System32\drivers\fxppm.sys 9591D0B9351ED489EAFD9D1CE52A8015
C:\Windows\System32\drivers\gagp30kx.sys FC3EF65EE20D39F8749C2218DBA681CA
C:\Windows\System32\drivers\vmgencounter.sys 0BF5CAD281E25F1418E5B8875DC5ADD1
C:\Windows\System32\Drivers\msgpioclx.sys 8DF1254093B5C354CE725EB6B9B0DE19
C:\Windows\system32\drivers\HdAudio.sys 56F69F7C25FB67C970997D7066DBC593
C:\Windows\System32\drivers\HDAudBus.sys D4B7ED39C7900384D9E5C1283F1E7926
C:\Windows\System32\drivers\HidBatt.sys 10A70BC1871CD955D85CD88372724906
C:\Windows\System32\drivers\hidbth.sys 42F88B57CAE42FC10059C887B3FCFCEA
C:\Windows\System32\drivers\hidi2c.sys C241A8BAFBBFC90176EA0F5240EACC17
C:\Windows\System32\drivers\hidir.sys 9BDDEE26255421017E161CCB9D5EDA95
C:\Windows\System32\drivers\hidusb.sys 8DB8EAB9D0C6A5DF0BDCADEA239220B4
C:\Windows\System32\drivers\HipShieldK.sys 29F981739E50305128022CBE10B3659C
C:\Windows\System32\drivers\HpSAMD.sys A6AACEA4C785789BDA5912AD1FEDA80D
C:\Windows\System32\drivers\HTTP.sys E87A6D3B8FECD5B93BC0CFBB48C27970
C:\Windows\System32\drivers\hwpolicy.sys 90656C0B3864804B090434EFC582404F
C:\Windows\System32\drivers\hyperkbd.sys 6D6F9E3BF0484967E52F7E846BFF1CA1
C:\Windows\system32\DRIVERS\HyperVideo.sys 907C870F8C31F8DDD6F090857B46AB25
C:\Windows\System32\drivers\i8042prt.sys 49EE0AE9E5B64FFBBD06D55C4984B598
C:\Windows\System32\drivers\iaLPSSi_GPIO.sys 5D90E32E36CE5D4C535D17CE08AEAF05
C:\Windows\System32\drivers\iaLPSSi_I2C.sys DD05E7E80F52ADE9AEB292819920F32C
C:\Windows\System32\drivers\iaStorA.sys 815499B59D675E42A70894118E7A6422
C:\Windows\System32\drivers\iaStorAV.sys 08BFE413B0B4AA8DFA4B5684CE06D3DC
C:\Windows\System32\drivers\iaStorV.sys A2200C3033FA4EF249FC096A7A7D02A2
C:\Windows\system32\DRIVERS\ibtusb.sys 18DA57A6DBA2DFEFDCD52D1637FFB657
C:\Program Files (x86)\Norton 360\NortonData\22.5.0.124\Definitions\IPSDefs\20150821.001\IDSvia64.sys 19F52CF90BB4D05B5265773CA7011E4C
C:\Windows\system32\DRIVERS\igdkmd64.sys 540E8D8F386F38F9609572FE92997DA1
C:\Windows\system32\drivers\intelaud.sys FC7C456AF9B9811499EDBD10616832EE
C:\Windows\system32\DRIVERS\IntcDAud.sys 5F6F8E55DDB25BC41497DD11A85FC257
C:\Windows\System32\drivers\intelide.sys 4E448FCFFD00E8D657CD9E48D3E47157
C:\Windows\System32\drivers\intelpep.sys A770340FC02B999EF0DE6C2A6BC8437C
C:\Windows\System32\drivers\intelppm.sys 47E74A8E53C7C24DCE38311E1451C1D9
C:\Windows\System32\DRIVERS\ipfltdrv.sys 9DB76D7F9E4E53EFE5DD8C53DE837514
C:\Windows\System32\drivers\IPMIDrv.sys 9C096BF5E10CA8BFA56F32522A89FAF1
C:\Windows\System32\drivers\ipnat.sys B7342B3C58E91107F6E946A93D9D4EFD
C:\Windows\System32\drivers\irenum.sys AE44C526AB5F8A487D941CEB57B10C97
C:\Windows\System32\drivers\isapnp.sys 8AFEEA3955AA43616A60F133B1D25F21
C:\Windows\System32\drivers\msiscsi.sys D90AB68D0FAC9F357F663670FDBB511E
C:\Windows\System32\drivers\iwdbus.sys A90C843F4FDD7A07129BA73C6BE13976
C:\Windows\System32\drivers\kbdclass.sys 5917AFE4A3F695A54B99C1849C8207FE
C:\Windows\System32\drivers\kbdhid.sys 8CD840A062F6BDF41DDE3ACB96164B72
C:\Windows\system32\DRIVERS\kdnic.sys 813871C7D402A05F2E3A7075F9584A05
C:\Windows\System32\Drivers\ksecdd.sys 4E829B18D5BAEC29893792A3C671A847
C:\Windows\System32\Drivers\ksecpkg.sys 46711F40D0F9E63F786ED23F9BD5215E
C:\Windows\system32\drivers\ksthunk.sys 11AFB527AA370B1DAFD5C36F35F6D45F
C:\Windows\system32\DRIVERS\lltdio.sys C09010B3680860131631F53E8FE7BAD8
C:\Windows\System32\drivers\lsi_sas.sys C755AE4635457AA2A11F79C0DF857ABC
C:\Windows\System32\drivers\lsi_sas2.sys ADAC09CBE7A2040B7F68B5E5C9A75141
C:\Windows\System32\drivers\lsi_sas3.sys 04D1274BB9BBCCF12BD12374002AA191
C:\Windows\System32\drivers\lsi_sss.sys 327469EEF3833D0C584B7E88A76AEC0C
C:\Windows\system32\drivers\luafv.sys DDEE191AB32DFC22C6465002ECDF5EE4
C:\Windows\System32\drivers\megasas.sys EB5C03A070F30D64A6DF80E53B22F53F
C:\Windows\System32\drivers\megasr.sys F6F13533196DE7A582D422B0241E4363
C:\Windows\system32\DRIVERS\TeeDriverx64.sys E0EF6C1399A9B1AAA0B28590411BED04
C:\Windows\System32\drivers\mfeaack.sys 5880E568C905F4A6DD7B0124682AE552
C:\Windows\System32\drivers\mfeavfk.sys 8522BA5DB3B9D37845ABC0F28B0292B2
C:\Windows\System32\DRIVERS\mfedisk.sys 983CA8E34131695D6DE810990CE8FF69
C:\Windows\System32\drivers\mfeelamk.sys 4F19F95D2AE83D388732FF219323B012
C:\Windows\System32\drivers\mfefirek.sys 7B4D31713AAA449CB7A55C65A0CB701A
C:\Windows\System32\drivers\mfehidk.sys AB88A9E16450DD1F1D74368F832DC695
C:\Windows\system32\DRIVERS\mfencbdc.sys 57EC9D22D989DD67E91A51BE082B1083
C:\Windows\system32\DRIVERS\mfencrk.sys FCEEE953517CA72E4238954467CD63E8
C:\Windows\System32\drivers\mfewfpk.sys F265F0B2134A3C2896F56B1FD4D55F77
C:\Windows\System32\drivers\modem.sys 8B38C44F69259987C95135C9627E2378
C:\Windows\System32\drivers\monitor.sys 601589000CC90F0DF8DA2CC254A3CCC9
C:\Windows\System32\drivers\mouclass.sys 08374E4E5B8914DE6067CBA99F61E930
C:\Windows\System32\drivers\mouhid.sys 5FCBAB60598AE119E02B4C27DE6B99EA
C:\Windows\System32\drivers\mountmgr.sys 9A788037D768809DFD677F4BA08A224A
C:\Windows\System32\drivers\mpsdrv.sys 6FC047578785B0435F4E2660946D1ADC
C:\Windows\system32\drivers\mrxdav.sys DB32958F0E704EFBF7F15161A569E39F
C:\Windows\System32\DRIVERS\mrxsmb.sys 6FBDF2B1B025A8E6E069234362FFFFB7
C:\Windows\System32\DRIVERS\mrxsmb10.sys BCBD64220AD85C26823453FF1DC3EFBD
C:\Windows\System32\DRIVERS\mrxsmb20.sys 57C2473D501331211D6885FD59F3E44B
C:\Windows\system32\DRIVERS\bridge.sys F3C060444777A59FC63D920719E43CCD
C:\Windows\System32\Drivers\Msfs.sys D13329FBF8345B28AB30F44CC247DC08
C:\Windows\System32\drivers\msgpiowin32.sys C6B474E46F9E543B875981ED3FFE6ADD
C:\Windows\System32\drivers\mshidkmdf.sys 65C92EB9D08DB5C69F28C7FFD4E84E31
C:\Windows\System32\drivers\mshidumdf.sys 52299F086AC2DAFD100DD5DC4A8614BA
C:\Windows\System32\drivers\msisadrv.sys 36D92AF3343C3A3E57FEF11C449AEA4C
C:\Windows\system32\drivers\MSKSSRV.sys A9BBBD2BAE6142253B9195E949AC2E8D
C:\Windows\system32\DRIVERS\mslldp.sys 51B3AC0560848CD6D65AC2033E293113
C:\Windows\system32\drivers\MSPCLOCK.sys 7B2128EB875DCBC006E6A913211006D6
C:\Windows\system32\drivers\MSPQM.sys 1E88171579B218115C7A772F8DE04BD8
C:\Windows\System32\Drivers\MsRPC.sys BBE2A455053E63BECBF42C2F9B21FAE0
C:\Windows\System32\drivers\mssmbios.sys 8D6B7D515C5CBCDB75B928A0B73C3C5E
C:\Windows\system32\drivers\MSTEE.sys 115019AE01E0EB9C048530D2928AB4A2
C:\Windows\System32\drivers\MTConfig.sys 96D604A35070360F0DD4A7A8AF410B5E
C:\Windows\System32\Drivers\mup.sys 619CA29326B82372621DB2C0964D8365
C:\Windows\System32\drivers\mvumis.sys B8C35C94DCB2DFEAF03BB42131F2F77F
C:\Windows\system32\DRIVERS\nwifi.sys 008F7CED69FD5B30CBDE1E03C6F36A27
C:\Program Files (x86)\Norton 360\NortonData\22.5.0.124\Definitions\VirusDefs\20150824.003\ENG64.SYS 5A4EC58A5F2E63DB2092B343CF1B2834
C:\Program Files (x86)\Norton 360\NortonData\22.5.0.124\Definitions\VirusDefs\20150824.003\EX64.SYS 526EA496D7F06B3746775046B33027C1
C:\Windows\System32\drivers\ndis.sys 97DC5967F65503213FD1F1B3E4A6F983
C:\Windows\system32\DRIVERS\ndiscap.sys 8CECC8DA55F3274181FD1EA28AD76664
C:\Windows\system32\DRIVERS\NdisImPlatform.sys 269882812E9A68FFF1AFE1283D428322
C:\Windows\system32\DRIVERS\ndistapi.sys 82821F4EEC776B4CF11695A38F3ABA46
C:\Windows\system32\DRIVERS\ndisuio.sys B832B35055BA2B7B4181861FF94D8E59
C:\Windows\System32\drivers\NdisVirtualBus.sys 1F58E48EF75F34C35D8E93A0DC535CFE
C:\Windows\system32\DRIVERS\ndiswan.sys DEC29080202D4F9F17F55E18BCFCC41A
C:\Windows\system32\DRIVERS\ndiswan.sys DEC29080202D4F9F17F55E18BCFCC41A
C:\Windows\System32\Drivers\NDProxy.sys DDD7F92A83F74D1476B71FBA9530A8DC
C:\Windows\System32\drivers\Ndu.sys 3083926D1CC5B56EA0786527B557DD1B
C:\Windows\System32\DRIVERS\netbios.sys 42FF4975D032CAE558AE4BB8448F6E5A
C:\Windows\System32\DRIVERS\netbt.sys 0217532E19A748F0E5D569307363D5FD
C:\Windows\System32\drivers\netvsc63.sys D4DCE03870314D3354F3501F9DDD4123
C:\Windows\system32\DRIVERS\NETwbw02.sys 9F7C86B844F2A3B435547AFDC14EB4BC
C:\Windows\system32\DRIVERS\NETwew02.sys B636B4A8E59A73033B766EA7FD7C3B81
C:\Windows\System32\Drivers\Npfs.sys 8F44A2F57C9F1A19AC9C6288C10FB351
C:\Windows\System32\drivers\npsvctrig.sys CBDB4F0871C88DF930FC0E8588CA67FC
C:\Windows\System32\drivers\nsiproxy.sys 0E046FF5823B95326D10CF1B4AF23541
C:\Windows\System32\Drivers\Ntfs.sys 7F68063A5A0461E02BC860CE0E6BFDDC
C:\Windows\System32\Drivers\Null.sys EF1B290FC9F0E47CC0B537292BEE5904
C:\Windows\system32\DRIVERS\nvlddmkm.sys 0B01F2DCE39774A5EAE644C4FFC27217
C:\Windows\System32\drivers\nvraid.sys BC6B5942AFF25EBAF62DE43C3807EDF8
C:\Windows\System32\drivers\nvstor.sys 1F43ABFFAC3D6CA356851D517392966E
C:\Windows\System32\drivers\nv_agp.sys 6934A936A7369DFE37B7DBA93F5E5E49
C:\Windows\System32\drivers\parport.sys 764B1121867B2D9B31C491668AC72B2B
C:\Windows\System32\drivers\partmgr.sys BAFF6122CFC9F95CA175AD8C348179A4
C:\Windows\System32\drivers\pci.sys 91ED124E261EA8FAA1C0FFDF2A71B0C4
C:\Windows\System32\drivers\pciide.sys 346E38FCC6859A727DD28AFAD1F0AFF4
C:\Windows\System32\drivers\pcmcia.sys 4D3BDCC1C7B40C9D7B6AD990E6DEC397
C:\Windows\System32\drivers\pcw.sys BF28771D1436C88BE1D297D3098B0F7D
C:\Windows\System32\drivers\pdc.sys 24A8DFC07E4BAF29AEA26E383D4CC886
C:\Windows\System32\drivers\peauth.sys 0ECEE590F2E2EF969FB74A6FC583A1E6
C:\Windows\system32\DRIVERS\raspptp.sys E075CC071022BD4E9BE7C024717C0E0A
C:\Windows\System32\drivers\processr.sys ECD373F9571C745894367CC2635EA44F
C:\Windows\system32\DRIVERS\pacer.sys FC0141B4A5AD6D637D883C1A89FC45C5
C:\Windows\system32\drivers\qwavedrv.sys 83868EB2924E6BC21A54337C65D614D1
C:\Windows\System32\DRIVERS\rasacd.sys B337B1F1E82A83E20A1743E008E25C0F
C:\Windows\system32\DRIVERS\AgileVpn.sys E8FFD8BE3C50E7A71C5FBB87BDD1128E
C:\Windows\system32\DRIVERS\rasl2tp.sys BBB6272B7F46C4640A8CDB8A70C3450F
C:\Windows\system32\DRIVERS\raspppoe.sys 5247F308C4103CDC4FE12AE1D235800A
C:\Windows\system32\DRIVERS\rassstp.sys 41F631007A158FEBB67F0E2AD1601BBA
C:\Windows\System32\DRIVERS\rdbss.sys A1A5E79C0D1352AFDC08328A623DA051
C:\Windows\System32\drivers\rdpbus.sys 6B21EBF892CD8CACB71669B35AB5DE32
C:\Windows\System32\drivers\rdpdr.sys 680C1DAE268B6FB67FA21B389A8B79EF
C:\Windows\System32\drivers\rdpvideominiport.sys BC8A79C625568DDB7DCA49D0C2741A64
C:\Windows\System32\drivers\rdyboost.sys A26AEC49F318FEE141DDDB2C5F99B3E6
C:\Windows\System32\Drivers\ReFS.sys 615DFD97DEA56CE1C3A52185A3038FF8
C:\Windows\System32\drivers\rfcomm.sys DC66AE45816614D2999DCD3834DCCC4E
C:\Windows\system32\DRIVERS\rspndr.sys 2D05A5508F4685412F2B89E8C2189ABC
C:\Windows\System32\Drivers\RtsUVStor.sys 28B356BAB74470786867BF4DC261E17C
C:\Windows\system32\DRIVERS\Rt630x64.sys CFE738C524F35B6E523A4D0F54840C30
C:\Windows\System32\drivers\vms3cap.sys 1A063730F221B2746FF00457AE17E4F0
C:\Windows\System32\Drivers\S6000KNT.sys 8E1AB9D18C4D6A90EF78C516B827DE2A
C:\Windows\System32\drivers\sbp2port.sys C624A1B32211C3166EDB3F4AB02A30B7
C:\Windows\System32\DRIVERS\scfilter.sys 13BEA6C882D4D877A5A85CA149C86BC1
C:\Windows\System32\drivers\sdbus.sys C54B6B2170BF628FD42F799A66956D75
C:\Windows\System32\drivers\sdstor.sys 0B1E929D11A8E358106955603FAC65E8
C:\Windows\System32\Drivers\secdrv.sys ==> MD5 is legit
C:\Windows\System32\drivers\SerCx.sys DB2FF24CE0BDD15FE75870AFE312BA89
C:\Windows\System32\drivers\SerCx2.sys 0044B31F93946D5D41982314381FE431
C:\Windows\System32\drivers\serenum.sys 3CD600C089C1251BEEB4CD4CD5164F9E
C:\Windows\System32\drivers\serial.sys D864381BC9C725FAB01D94C060660166
C:\Windows\System32\drivers\sermouse.sys 148195AE95D9BC7375A08846439FDAC1
C:\Windows\System32\drivers\sfloppy.sys 472B7A5AC181C050888DB454663DD764
C:\Windows\System32\drivers\SiSRaid2.sys 2F518D13DD6F3053837FE606F1A2EA1F
C:\Windows\System32\drivers\sisraid4.sys 1AC9A200A9C49C4508F04AAFFCA34A3F
C:\Windows\System32\drivers\spaceport.sys D24B1945ED1F9C96DA786DBBF1E983CE
C:\Windows\System32\drivers\SpbCx.sys F337BE11071818FC3F5DC2940B6BDE34
C:\Windows\System32\Drivers\N360x64\1605020.00F\SRTSP64.SYS 3361466E3C5353CAB7E978C236FADF3B
C:\Windows\system32\drivers\N360x64\1605020.00F\SRTSPX64.SYS BA2ABBEA69BD1866C973DE11CB0CE9F8
C:\Windows\System32\DRIVERS\srv.sys 6416E79A58A8FCC33A447A4DDDD3BF04
C:\Windows\System32\DRIVERS\srv2.sys 00D8AC8E3053290BDE6EA2FB6810D2FC
C:\Windows\System32\DRIVERS\srvnet.sys D047CD668E6277FD80F0C613946F034C
C:\Windows\System32\drivers\stexstor.sys 366DEA74BBA65B362BCCFC6FC2ADFD8B
C:\Windows\System32\drivers\storahci.sys 0ED2E318ABB68C1A35A8B8038BDB4C90
C:\Windows\System32\drivers\vmstorfl.sys 8B9486B64E5FC17FB9CC04CA10B77A34
C:\Windows\System32\drivers\stornvme.sys 6B06E2D11E604BE2B1A406C4CB3B90DE
C:\Windows\System32\drivers\storvsc.sys 548759755BC73DAD663250239D7E0B9F
C:\Windows\System32\drivers\swenum.sys 65454187E0F8B6C0DCECB0287D06EC43
C:\Windows\System32\drivers\N360x64\1605020.00F\SYMEFASI64.SYS C9EC22D5B3C6B32A7C8B4A73870A7379
C:\Windows\System32\drivers\N360x64\1605020.00F\SymELAM.sys 1DE0CBF15AC67AE0E5B456ADEFB89493
C:\windows\system32\Drivers\SYMEVENT64x86.SYS 6DF8F618B93C821630C9BAA8DA3FAAAF
C:\Windows\system32\drivers\N360x64\1605020.00F\Ironx64.SYS 0891E59A27208B9B727BAB863B853E80
C:\Windows\System32\Drivers\N360x64\1605020.00F\SYMNETS.SYS 5EA70535B2A6504278E14943867B1B39
C:\Windows\System32\drivers\tcpip.sys 746DDF7D59AB8D721C88D48434597E8D
C:\Windows\system32\DRIVERS\tcpip.sys 746DDF7D59AB8D721C88D48434597E8D
C:\Windows\System32\drivers\tcpipreg.sys 41CF802064F72E55F50CA0A221FD36D4
C:\Windows\system32\DRIVERS\tdx.sys FFF28F9F6823EB1756C60F1649560BBF
C:\Windows\System32\drivers\terminpt.sys 232D185D2337F141311D0CF1983E1431
C:\Windows\system32\drivers\tpm.sys 82F909359600D3603FE852DB7F135626
C:\Windows\System32\drivers\tsusbflt.sys BF8F54CA37E9C9D6582C31C5761F8C93
C:\Windows\System32\drivers\TsUsbGD.sys 20185BEB7512EDE4EFECDFA148AC9F99
C:\Windows\system32\DRIVERS\tunnel.sys C8E0E78B5D284C2FF59BDFFDAF997242
C:\Windows\System32\drivers\uagp35.sys F6EEAD052943B5A3104C1405BB856C54
C:\Windows\System32\drivers\uaspstor.sys FE6067B1FD4E63650C667B33D080565B
C:\Windows\System32\drivers\ucx01000.sys 807F8CF3E973305FC435C61CBBEE2A49
C:\Windows\System32\DRIVERS\udfs.sys C61EAF8E1E4B2F62BA4FDF457440B2C6
C:\Windows\System32\drivers\UEFI.sys 9578691F297E1B1F519970FE6D47CB21
C:\Windows\System32\drivers\uliagpkx.sys 5EAB5117DDB24FC4D39E6FFFCF1837B9
C:\Windows\System32\drivers\umbus.sys DA34C39A18E60E7C3FA0630566408034
C:\Windows\System32\drivers\umpass.sys AE8294875E5446E359B1E8035D40C05E
C:\Windows\System32\drivers\usbccgp.sys FF78D053A05E5A394F4E3C1816CC65A8
C:\Windows\System32\drivers\usbcir.sys 0139248F6B95CF0D837B5B46A2722D40
C:\Windows\System32\drivers\usbehci.sys 48BA326A3DBA5B5BEB5F2777F4618696
C:\Windows\System32\drivers\usbhub.sys FEF0BC107812B36849741C3211BA6B60
C:\Windows\System32\drivers\UsbHub3.sys 95B0179BDA907252025DEEA183699FB3
C:\Windows\System32\drivers\usbohci.sys 3019097FB6C985EF24C058090FF3BDBD
C:\Windows\System32\drivers\usbprint.sys 4D655E3B684BE9B0F7FFD8A2935C348C
C:\Windows\System32\drivers\USBSTOR.SYS 66732C13628BDB1AB0D6FD46027327C2
C:\Windows\System32\drivers\usbuhci.sys 064260B3A5868AC894A4943543BC7AB7
C:\Windows\System32\Drivers\usbvideo.sys 5C8F604F6DC74177CDD8372D7B1ADFF0
C:\Windows\System32\drivers\USBXHCI.SYS 44603DA5A87FB491EF59C889EBBB4DDB
C:\Windows\System32\drivers\vdrvroot.sys FEB26E3B8345A7E8D62F945C4AE86562
C:\Windows\System32\drivers\VerifierExt.sys A026EDEAA5EECAE0B08E2748B616D4BD
C:\Windows\System32\drivers\vhdmp.sys C06E8481E068F170A258441639AC5792
C:\Windows\System32\drivers\viaide.sys 06D38968028E9AB19DE9B618C7B6D199
C:\Windows\System32\drivers\vmbus.sys 511AD3FF957A0127E6BD336FF6F89C38
C:\Windows\System32\drivers\VMBusHID.sys DA40BEA0A863CE768C940CA9723BF81F
C:\Windows\System32\drivers\volmgr.sys 55D7D963DE85162F1C49721E502F9744
C:\Windows\System32\drivers\volmgrx.sys CCB9E901F7254BF96D28EB1B0E5329B7
C:\Windows\System32\drivers\volsnap.sys 64CA2B4A49A8EAF495E435623ECCE7DB
C:\Windows\System32\drivers\vpci.sys EF31713EE4C7CCFE4049F7E7F15645A2
C:\Windows\System32\drivers\vsmraid.sys 4539F45F9F4C9757A86A56C949421E07
C:\Windows\System32\drivers\vstxraid.sys 0849B7260F26FE05EA56DED0672E2F4B
C:\Windows\System32\drivers\vwifibus.sys BE970C369E43B509C1EDA2B8FA7CECB0
C:\Windows\system32\DRIVERS\vwififlt.sys 35BF5C5F5E3C9902C98978C7640574DA
C:\Windows\system32\DRIVERS\vwifimp.sys 65ED7B9CFEA893DF7748D5FF692690DE
C:\Windows\System32\drivers\wacompen.sys 0910AB9ED404C1434E2D0376C2AD5D8B
C:\Windows\system32\DRIVERS\wanarp.sys 6505C9E72910F91D4C317EECF22D1DE6
C:\Windows\system32\DRIVERS\wanarp.sys 6505C9E72910F91D4C317EECF22D1DE6
C:\Windows\system32\drivers\WdBoot.sys 81285DDC994F03379DB46419300B2DCB
C:\Windows\System32\drivers\wdcsam64.sys D0335A55E5C3F812548E18300C2ACB62
C:\Windows\System32\drivers\Wdf01000.sys CB6C63FF8342B467E2EF76E98D5B934D
C:\Windows\system32\drivers\WdFilter.sys 26B8FED3F3B85F5F0C4BD03FD00B9941
C:\Windows\System32\Drivers\WdNisDrv.sys CE67080F00E0AF32755096CEA6430ABA
C:\Windows\System32\DRIVERS\wfplwfs.sys BAB713B409258DB7B5D9F9693F802B0E
C:\Windows\System32\drivers\wimmount.sys 5F66B7BB330AA80067FC66149A692620
C:\Windows\System32\drivers\wmiacpi.sys 2834D9D3B4F554A39C72F00EA3F0E128
C:\Windows\System32\Drivers\Wof.sys 7FC5667DF73D4B04AA457CC3A4180E09
C:\Windows\System32\DRIVERS\wpcfltr.sys A2468CC3509394A33C4C32F99563D845
C:\Windows\System32\drivers\WpdUpFltr.sys 9F2904B55F6CECCD1A8D986B5CE2609A
C:\Windows\system32\drivers\ws2ifsl.sys AE072B0339D0A18E455DC21666CAD572
C:\Windows\System32\drivers\WSDPrint.sys F586F3F1BF962FE9AE4316E0D896B22F
C:\Windows\system32\DRIVERS\wsvd.sys 72B4E9DF6456C43C42A1419B09486045
C:\Windows\System32\drivers\WudfPf.sys 481286719402E4BAEFEA0604AB1B5113
C:\Windows\System32\drivers\WUDFRd.sys D7B4859227B02BCC1055B279A63C937F
C:\Windows\System32\drivers\WUDFRd.sys D7B4859227B02BCC1055B279A63C937F
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-08-25 14:46 - 2015-08-25 14:46 - 00057461 _____ C:\Users\PAK\Downloads\FRST.txt
2015-08-25 14:45 - 2015-08-25 14:46 - 00000000 ____D C:\FRST
2015-08-25 14:44 - 2015-08-25 14:45 - 02186752 _____ (Farbar) C:\Users\PAK\Downloads\FRST64 (1).exe
2015-08-25 14:44 - 2015-08-25 14:44 - 02186752 _____ (Farbar) C:\Users\PAK\Downloads\FRST64.exe
2015-08-25 14:37 - 2015-08-25 14:37 - 00003116 _____ C:\Users\PAK\Documents\aswMBRtonyp96.txt
2015-08-25 14:37 - 2015-08-25 14:37 - 00000512 _____ C:\Users\PAK\Documents\MBR.dat
2015-08-25 14:24 - 2015-08-25 14:25 - 05198336 _____ (AVAST Software) C:\Users\PAK\Downloads\aswMBR.exe
2015-08-25 13:24 - 2015-08-25 13:24 - 00000000 ____D C:\Users\PAK\AppData\Roaming\Sun
2015-08-25 13:24 - 2015-08-25 13:24 - 00000000 ____D C:\Users\PAK\.oracle_jre_usage
2015-08-25 13:24 - 2015-08-25 13:24 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2015-08-25 13:24 - 2015-08-25 13:23 - 00097888 _____ (Oracle Corporation) C:\windows\SysWOW64\WindowsAccessBridge-32.dll
2015-08-25 13:23 - 2015-08-25 13:24 - 00000000 ____D C:\ProgramData\Oracle
2015-08-25 13:23 - 2015-08-25 13:23 - 00000000 ____D C:\Program Files (x86)\Java
2015-08-25 10:24 - 2015-08-25 13:44 - 00000000 ____D C:\Users\PAK\OneDrive
2015-08-23 17:48 - 2015-08-23 17:50 - 00000000 ____D C:\Taken
2015-08-23 17:39 - 2015-08-23 17:39 - 00000000 ____D C:\Madam Secretary
2015-08-23 14:40 - 2015-08-23 14:41 - 01226864 _____ C:\windows\Minidump\082315-66078-01.dmp
2015-08-23 14:40 - 2015-08-23 14:40 - 901919037 _____ C:\windows\MEMORY.DMP
2015-08-23 14:40 - 2015-08-23 14:40 - 00000000 ____D C:\windows\Minidump
2015-08-23 12:10 - 2015-08-11 11:20 - 25191936 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2015-08-23 12:10 - 2015-08-11 10:20 - 19871232 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2015-08-21 16:42 - 2015-08-25 13:42 - 00000000 ____D C:\Users\PAK\AppData\Local\CrashDumps
2015-08-21 16:26 - 2015-08-21 16:26 - 00000000 ____D C:\OAAT
2015-08-21 12:11 - 2015-08-21 12:11 - 00000000 ____D C:\Users\PAK\Documents\Lenovo
2015-08-21 12:11 - 2015-08-21 12:11 - 00000000 ____D C:\Users\PAK\Documents\CyberLink
2015-08-21 12:11 - 2015-08-21 12:11 - 00000000 ____D C:\Users\PAK\AppData\Roaming\WebApp
2015-08-21 12:11 - 2015-08-21 12:11 - 00000000 ____D C:\Users\PAK\AppData\Roaming\Lenovo
2015-08-21 12:11 - 2015-08-21 12:11 - 00000000 ____D C:\Users\PAK\AppData\Roaming\CyberLink
2015-08-21 12:11 - 2015-08-21 12:11 - 00000000 ____D C:\Users\PAK\AppData\Local\Cyberlink
2015-08-19 09:53 - 2015-08-19 09:53 - 00001933 _____ C:\Users\PAK\Desktop\dsNetworkConnect - Shortcut.lnk
2015-08-19 09:41 - 2015-08-19 09:41 - 00000000 ____D C:\Users\PAK\AppData\Roaming\QAD
2015-08-19 09:40 - 2015-08-19 09:40 - 00002293 _____ C:\Users\Public\Desktop\QAD Enterprise Applications 2.9.6.lnk
2015-08-19 09:40 - 2015-08-19 09:40 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QAD Enterprise Applications
2015-08-19 09:39 - 2015-08-19 09:39 - 00000000 ____D C:\Program Files (x86)\QAD
2015-08-19 09:24 - 2015-08-19 09:24 - 01007216 _____ (Juniper Networks) C:\Users\PAK\Downloads\JuniperSetupClientInstaller.exe
2015-08-19 09:14 - 2015-08-19 09:43 - 00000000 ____D C:\Program Files (x86)\TeamViewer
2015-08-19 09:14 - 2015-08-19 09:14 - 00001066 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 10.lnk
2015-08-19 09:14 - 2015-08-19 09:14 - 00001054 _____ C:\Users\Public\Desktop\TeamViewer 10.lnk
2015-08-19 09:14 - 2015-08-19 09:14 - 00000000 ____D C:\Users\PAK\AppData\Roaming\TeamViewer
2015-08-19 09:13 - 2015-08-19 09:13 - 08098552 _____ (TeamViewer GmbH) C:\Users\PAK\Downloads\TeamViewer_Setup_en-jhg.exe
2015-08-18 11:13 - 2015-08-18 11:13 - 00148086 _____ C:\Users\PAK\Downloads\Packaging.xlsx
2015-08-18 11:12 - 2015-08-18 11:12 - 00152964 _____ C:\Users\PAK\Downloads\Raws 13.08 (1).xlsx
2015-08-18 11:10 - 2015-08-18 11:10 - 00152964 _____ C:\Users\PAK\Downloads\Raws 13.08.xlsx
2015-08-18 09:51 - 2015-08-18 09:51 - 00010572 _____ C:\Users\PAK\Downloads\St Mary's Players Squad 2 2015.xlsx
2015-08-17 09:36 - 2015-07-31 00:04 - 00124624 _____ (Microsoft Corporation) C:\windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-08-17 09:36 - 2015-07-30 23:48 - 00103120 _____ (Microsoft Corporation) C:\windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2015-08-14 14:36 - 2015-08-19 09:35 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Juniper Networks
2015-08-14 14:35 - 2015-07-30 00:37 - 01994752 _____ (Microsoft Corporation) C:\windows\system32\DWrite.dll
2015-08-14 14:35 - 2015-07-30 00:30 - 01381888 _____ (Microsoft Corporation) C:\windows\system32\FntCache.dll
2015-08-14 14:35 - 2015-07-30 00:23 - 01559552 _____ (Microsoft Corporation) C:\windows\SysWOW64\DWrite.dll
2015-08-14 14:35 - 2015-07-25 04:57 - 04177408 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2015-08-14 14:35 - 2015-07-25 04:57 - 00358912 _____ (Adobe Systems Incorporated) C:\windows\system32\atmfd.dll
2015-08-14 14:35 - 2015-07-25 04:52 - 00044032 _____ (Adobe Systems) C:\windows\system32\atmlib.dll
2015-08-14 14:35 - 2015-07-25 03:27 - 00301568 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\atmfd.dll
2015-08-14 14:35 - 2015-07-25 03:23 - 00035840 _____ (Adobe Systems) C:\windows\SysWOW64\atmlib.dll
2015-08-14 14:35 - 2015-07-19 11:58 - 00136904 _____ (Microsoft Corporation) C:\windows\system32\wuauclt.exe
2015-08-14 14:35 - 2015-07-19 04:51 - 03704320 _____ (Microsoft Corporation) C:\windows\system32\wuaueng.dll
2015-08-14 14:35 - 2015-07-19 04:31 - 00140288 _____ (Microsoft Corporation) C:\windows\system32\wuwebv.dll
2015-08-14 14:35 - 2015-07-19 04:31 - 00095744 _____ (Microsoft Corporation) C:\windows\system32\wudriver.dll
2015-08-14 14:35 - 2015-07-19 04:31 - 00035840 _____ (Microsoft Corporation) C:\windows\system32\wuapp.exe
2015-08-14 14:35 - 2015-07-19 04:29 - 00409088 _____ (Microsoft Corporation) C:\windows\system32\WUSettingsProvider.dll
2015-08-14 14:35 - 2015-07-19 04:29 - 00124928 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuwebv.dll
2015-08-14 14:35 - 2015-07-19 04:29 - 00029696 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapp.exe
2015-08-14 14:35 - 2015-07-19 04:28 - 00081920 _____ (Microsoft Corporation) C:\windows\SysWOW64\wudriver.dll
2015-08-14 14:35 - 2015-07-19 04:12 - 02228736 _____ (Microsoft Corporation) C:\windows\system32\wucltux.dll
2015-08-14 14:35 - 2015-07-19 04:10 - 00891904 _____ (Microsoft Corporation) C:\windows\system32\wuapi.dll
2015-08-14 14:35 - 2015-07-19 04:09 - 00721920 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapi.dll
2015-08-14 14:35 - 2015-07-07 19:40 - 00270168 _____ (Microsoft Corporation) C:\windows\system32\Drivers\WdFilter.sys
2015-08-14 14:35 - 2015-07-07 19:40 - 00114520 _____ (Microsoft Corporation) C:\windows\system32\Drivers\WdNisDrv.sys
2015-08-14 14:35 - 2015-07-07 19:40 - 00044560 _____ (Microsoft Corporation) C:\windows\system32\Drivers\WdBoot.sys
2015-08-14 14:35 - 2015-06-10 04:27 - 00411133 _____ C:\windows\system32\ApnDatabase.xml
2015-08-14 14:34 - 2015-07-17 06:36 - 00584192 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2015-08-14 14:34 - 2015-07-17 06:36 - 00417792 _____ (Microsoft Corporation) C:\windows\system32\html.iec
2015-08-14 14:34 - 2015-07-17 06:35 - 02885632 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2015-08-14 14:34 - 2015-07-17 06:26 - 05923328 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2015-08-14 14:34 - 2015-07-17 06:23 - 00615936 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2015-08-14 14:34 - 2015-07-17 06:21 - 00816640 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
2015-08-14 14:34 - 2015-07-17 05:53 - 00145408 _____ (Microsoft Corporation) C:\windows\system32\iepeers.dll
2015-08-14 14:34 - 2015-07-17 05:51 - 00504320 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2015-08-14 14:34 - 2015-07-17 05:50 - 00341504 _____ (Microsoft Corporation) C:\windows\SysWOW64\html.iec
2015-08-14 14:34 - 2015-07-17 05:45 - 02279424 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2015-08-14 14:34 - 2015-07-17 05:45 - 01032704 _____ (Microsoft Corporation) C:\windows\system32\inetcomm.dll
2015-08-14 14:34 - 2015-07-17 05:41 - 00479232 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2015-08-14 14:34 - 2015-07-17 05:39 - 00664064 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript.dll
2015-08-14 14:34 - 2015-07-17 05:38 - 00262144 _____ (Microsoft Corporation) C:\windows\system32\webcheck.dll
2015-08-14 14:34 - 2015-07-17 05:36 - 00801280 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2015-08-14 14:34 - 2015-07-17 05:34 - 14451200 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2015-08-14 14:34 - 2015-07-17 05:32 - 02125824 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2015-08-14 14:34 - 2015-07-17 05:14 - 02880000 _____ (Microsoft Corporation) C:\windows\system32\actxprxy.dll
2015-08-14 14:34 - 2015-07-17 05:13 - 00880128 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcomm.dll
2015-08-14 14:34 - 2015-07-17 05:12 - 04520448 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2015-08-14 14:34 - 2015-07-17 05:12 - 02427904 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2015-08-14 14:34 - 2015-07-17 05:10 - 12856832 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2015-08-14 14:34 - 2015-07-17 05:06 - 00689152 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2015-08-14 14:34 - 2015-07-17 05:01 - 01545728 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2015-08-14 14:34 - 2015-07-17 04:52 - 01048576 _____ (Microsoft Corporation) C:\windows\SysWOW64\actxprxy.dll
2015-08-14 14:34 - 2015-07-17 04:49 - 00800768 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2015-08-14 14:34 - 2015-07-17 04:42 - 01951232 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2015-08-14 14:34 - 2015-07-17 04:38 - 01310720 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2015-08-14 14:34 - 2015-07-17 04:37 - 00710144 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2015-08-14 14:34 - 2015-07-16 10:29 - 07458648 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe
2015-08-14 14:34 - 2015-07-16 10:29 - 01735000 _____ (Microsoft Corporation) C:\windows\system32\ntdll.dll
2015-08-14 14:34 - 2015-07-16 10:29 - 00101720 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mountmgr.sys
2015-08-14 14:34 - 2015-07-16 10:28 - 01499920 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntdll.dll
2015-08-14 14:34 - 2015-07-11 03:54 - 01217024 _____ (Microsoft Corporation) C:\windows\system32\sysmain.dll
2015-08-14 14:34 - 2015-06-13 03:03 - 18823680 _____ (Microsoft Corporation) C:\windows\system32\Windows.UI.Xaml.dll
2015-08-14 14:34 - 2015-06-13 02:36 - 15159296 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.UI.Xaml.dll
2015-08-14 14:33 - 2015-08-14 14:33 - 00000000 ____D C:\Users\Public\Juniper Networks
2015-08-14 14:33 - 2010-02-19 10:22 - 00579952 _____ (Juniper Networks) C:\windows\SysWOW64\dsNcSmartCardProv.dll
2015-08-14 14:33 - 2010-02-19 10:22 - 00405360 _____ (Juniper Networks) C:\windows\SysWOW64\dsNcCredProv.dll
2015-08-14 14:32 - 2015-08-19 09:35 - 00000000 ____D C:\Users\PAK\AppData\Roaming\Juniper Networks
2015-08-14 14:32 - 2015-08-19 09:34 - 00000000 ____D C:\Program Files (x86)\Juniper Networks
2015-08-14 14:32 - 2015-08-14 14:36 - 02393904 _____ C:\Users\PAK\Downloads\NCInst64.exe
2015-08-14 14:29 - 2015-08-14 14:29 - 01342368 _____ C:\Users\PAK\Downloads\juniper-networks-network-connect.cpl
2015-08-14 14:29 - 2015-08-14 14:29 - 01342368 _____ C:\Users\PAK\Downloads\juniper-networks-network-connect (1).cpl
2015-08-14 14:29 - 2015-07-29 09:24 - 00025776 _____ (Microsoft Corporation) C:\windows\system32\CompatTelRunner.exe
2015-08-14 14:29 - 2015-07-29 00:24 - 01148416 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll
2015-08-14 14:29 - 2015-07-29 00:24 - 01116160 _____ (Microsoft Corporation) C:\windows\system32\appraiser.dll
2015-08-14 14:29 - 2015-07-29 00:24 - 00774144 _____ (Microsoft Corporation) C:\windows\system32\invagent.dll
2015-08-14 14:29 - 2015-07-29 00:24 - 00743424 _____ (Microsoft Corporation) C:\windows\system32\generaltel.dll
2015-08-14 14:29 - 2015-07-29 00:24 - 00437248 _____ (Microsoft Corporation) C:\windows\system32\devinv.dll
2015-08-14 14:29 - 2015-07-29 00:24 - 00069120 _____ (Microsoft Corporation) C:\windows\system32\acmigration.dll
2015-08-14 14:29 - 2015-07-15 07:59 - 01113944 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ndis.sys
2015-08-14 14:29 - 2015-07-15 07:59 - 00487256 _____ (Microsoft Corporation) C:\windows\system32\netcfgx.dll
2015-08-14 14:29 - 2015-07-15 07:59 - 00393560 _____ (Microsoft Corporation) C:\windows\SysWOW64\netcfgx.dll
2015-08-14 14:29 - 2015-07-14 13:22 - 02529880 _____ (Microsoft Corporation) C:\windows\system32\msxml6.dll
2015-08-14 14:29 - 2015-07-14 13:21 - 01901776 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml6.dll
2015-08-14 14:29 - 2015-07-14 05:46 - 00059392 _____ (Microsoft Corporation) C:\windows\system32\csrsrv.dll
2015-08-14 14:29 - 2015-07-14 05:45 - 00059392 _____ (Microsoft Corporation) C:\windows\system32\basesrv.dll
2015-08-14 14:29 - 2015-07-11 04:19 - 01101824 _____ (Microsoft Corporation) C:\windows\system32\rdvidcrl.dll
2015-08-14 14:29 - 2015-07-11 03:42 - 02345472 _____ (Microsoft Corporation) C:\windows\system32\msxml3.dll
2015-08-14 14:29 - 2015-07-11 03:14 - 00856064 _____ (Microsoft Corporation) C:\windows\SysWOW64\rdvidcrl.dll
2015-08-14 14:29 - 2015-07-11 03:13 - 07032320 _____ (Microsoft Corporation) C:\windows\system32\mstscax.dll
2015-08-14 14:29 - 2015-07-11 02:47 - 01556992 _____ (Microsoft Corporation) C:\windows\SysWOW64\msxml3.dll
2015-08-14 14:29 - 2015-07-11 02:31 - 06213120 _____ (Microsoft Corporation) C:\windows\SysWOW64\mstscax.dll
2015-08-14 14:29 - 2015-07-10 03:13 - 00221184 _____ (Microsoft Corporation) C:\windows\system32\notepad.exe
2015-08-14 14:29 - 2015-07-10 03:13 - 00221184 _____ (Microsoft Corporation) C:\windows\notepad.exe
2015-08-14 14:29 - 2015-07-10 02:30 - 00212992 _____ (Microsoft Corporation) C:\windows\SysWOW64\notepad.exe
2015-08-14 14:29 - 2015-07-02 08:19 - 00228864 _____ (Microsoft Corporation) C:\windows\system32\WebClnt.dll
2015-08-14 14:29 - 2015-07-02 08:16 - 00104448 _____ (Microsoft Corporation) C:\windows\system32\davclnt.dll
2015-08-14 14:29 - 2015-07-02 07:37 - 00198656 _____ (Microsoft Corporation) C:\windows\SysWOW64\WebClnt.dll
2015-08-14 14:29 - 2015-07-02 07:35 - 00087040 _____ (Microsoft Corporation) C:\windows\SysWOW64\davclnt.dll
2015-08-14 14:29 - 2015-06-12 06:12 - 02476376 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tcpip.sys
2015-08-14 14:29 - 2015-06-12 06:12 - 00428888 _____ (Microsoft Corporation) C:\windows\system32\Drivers\FWPKCLNT.SYS
2015-08-03 20:49 - 2015-08-03 20:49 - 00001390 _____ C:\Users\PAK\Downloads\UkZJLkRlc2t0b3A- (1).ica
2015-08-03 20:46 - 2015-08-03 20:47 - 46664016 _____ (Citrix Systems, Inc.) C:\Users\PAK\Downloads\CitrixReceiverWeb (1).exe
2015-08-03 20:46 - 2015-08-03 20:46 - 00001389 _____ C:\Users\PAK\Downloads\UkZJLkRlc2t0b3A-.ica
2015-08-03 20:29 - 2015-08-18 23:37 - 00000000 ____D C:\windows\system32\appraiser
2015-07-29 22:05 - 2015-07-29 22:07 - 08712528 _____ C:\Users\PAK\Downloads\video.wmv
2015-07-28 15:02 - 2015-07-28 15:02 - 00000000 ____D C:\windows\System32\Tasks\Norton 360
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-08-25 14:03 - 2015-03-18 05:58 - 01126053 _____ C:\windows\WindowsUpdate.log
2015-08-25 14:00 - 2013-08-23 01:36 - 00000000 ____D C:\windows\system32\sru
2015-08-25 13:56 - 2015-07-17 14:46 - 00000934 _____ C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-08-25 13:56 - 2015-07-17 14:46 - 00000930 _____ C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-08-25 13:52 - 2015-03-18 07:30 - 00000000 ____D C:\windows\System32\Tasks\Lenovo
2015-08-25 13:48 - 2015-07-02 20:08 - 00003596 _____ C:\windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3391081986-1551245901-393088480-1002
2015-08-25 13:46 - 2015-07-02 20:14 - 00002282 _____ C:\Users\PAK\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PC App Store.lnk
2015-08-25 13:45 - 2015-07-02 20:00 - 00000000 ____D C:\Users\PAK\AppData\Local\Pokki
2015-08-25 13:43 - 2015-07-02 20:14 - 00002144 _____ C:\Users\PAK\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Start Menu.lnk
2015-08-25 13:42 - 2015-07-19 12:49 - 00003248 _____ C:\windows\System32\Tasks\Pokki
2015-08-25 13:42 - 2015-03-18 06:53 - 01584086 _____ C:\Users\Public\CAFADEBUG.log
2015-08-25 13:41 - 2015-07-02 20:14 - 00002583 _____ C:\Users\PAK\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Lenovo Web Start.lnk
2015-08-25 13:31 - 2014-03-18 19:53 - 00865408 _____ C:\windows\system32\PerfStringBackup.INI
2015-08-25 13:26 - 2014-03-18 19:44 - 00027224 _____ C:\windows\PFRO.log
2015-08-25 13:26 - 2013-08-23 00:46 - 00028665 _____ C:\windows\setupact.log
2015-08-25 13:26 - 2013-08-23 00:45 - 00000006 ____H C:\windows\Tasks\SA.DAT
2015-08-25 13:25 - 2015-03-18 07:37 - 00002560 _____ C:\windows\system32\VfService.trf
2015-08-25 13:25 - 2013-08-22 23:25 - 00262144 ___SH C:\windows\system32\config\BBI
2015-08-25 13:24 - 2015-07-02 20:00 - 00000000 ____D C:\Users\PAK
2015-08-25 10:51 - 2013-08-23 01:36 - 00000000 ____D C:\windows\AppReadiness
2015-08-25 10:46 - 2015-07-02 20:01 - 00000000 ____D C:\Users\PAK\AppData\Local\Packages
2015-08-25 09:57 - 2015-07-17 14:47 - 00002514 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-08-23 14:40 - 2013-08-23 00:44 - 00492688 _____ C:\windows\system32\FNTCACHE.DAT
2015-08-23 12:11 - 2013-08-23 01:20 - 00000000 ____D C:\windows\CbsTemp
2015-08-21 12:11 - 2015-03-18 07:36 - 00000000 ____D C:\ProgramData\CyberLink
2015-08-21 12:11 - 2015-03-18 07:30 - 00000000 ____D C:\ProgramData\Lenovo
2015-08-19 09:39 - 2015-03-18 06:43 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2015-08-19 09:13 - 2013-08-22 23:25 - 00262144 ___SH C:\windows\system32\config\ELAM
2015-08-18 23:37 - 2015-03-18 06:29 - 00000000 ___SD C:\windows\system32\CompatTel
2015-08-18 23:37 - 2013-08-23 01:36 - 00000000 ___RD C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-08-18 23:37 - 2013-08-23 01:36 - 00000000 ___RD C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-08-18 23:37 - 2013-08-23 01:36 - 00000000 ____D C:\Program Files\Windows Defender
2015-08-18 23:37 - 2013-08-23 01:36 - 00000000 ____D C:\Program Files (x86)\Windows Defender
2015-08-18 10:45 - 2014-04-04 05:15 - 00000000 ____D C:\windows\Panther
2015-08-18 10:41 - 2015-07-10 23:39 - 00000000 ___HD C:\$Windows.~BT
2015-08-18 09:36 - 2015-03-18 07:42 - 00000000 ____D C:\ProgramData\Energy Manager
2015-08-17 09:36 - 2015-07-02 20:50 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2015-08-17 09:36 - 2015-07-02 20:38 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-08-17 09:35 - 2015-07-10 19:08 - 00000000 ____D C:\windows\system32\MRT
2015-08-17 09:31 - 2015-07-10 19:08 - 132483416 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2015-08-17 09:24 - 2013-08-22 23:25 - 00000167 _____ C:\windows\win.ini
2015-08-17 09:23 - 2013-08-23 01:36 - 00000000 ___RD C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-08-17 09:23 - 2013-08-23 01:36 - 00000000 ___RD C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-08-08 23:55 - 2013-08-23 01:38 - 00794088 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2015-08-08 23:55 - 2013-08-23 01:38 - 00179688 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-08-04 13:16 - 2015-07-19 17:58 - 00002240 ____H C:\Users\PAK\Documents\Default.rdp
2015-08-04 13:07 - 2013-08-23 01:36 - 00000000 ____D C:\windows\AppCompat
2015-08-04 13:06 - 2015-07-17 14:48 - 00000000 ____D C:\Program Files (x86)\gmsd_au_004010033
2015-08-03 20:33 - 2015-07-02 19:53 - 00000000 ___SD C:\windows\system32\GWX
2015-08-03 20:30 - 2013-08-23 01:36 - 00000000 ___HD C:\windows\ELAMBKUP
2015-08-03 20:29 - 2015-07-02 19:53 - 00000000 ___SD C:\windows\SysWOW64\GWX
2015-08-03 20:29 - 2013-08-23 01:36 - 00000000 ___RD C:\windows\ToastData
2015-08-03 20:29 - 2013-08-23 01:36 - 00000000 ____D C:\windows\WinStore
2015-07-28 20:44 - 2015-07-13 20:43 - 00000000 ____D C:\Users\PAK\AppData\Local\Citrix
2015-07-28 14:57 - 2015-07-15 10:36 - 00000000 ____D C:\windows\system32\Drivers\N360x64
2015-07-28 14:56 - 2015-07-15 10:37 - 00003206 _____ C:\windows\System32\Tasks\Norton WSC Integration
2015-07-28 14:55 - 2015-07-15 10:37 - 00002268 _____ C:\Users\Public\Desktop\Norton 360.LNK
2015-07-28 14:55 - 2015-07-15 10:36 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton 360
2015-07-28 14:53 - 2015-07-17 14:46 - 00000000 ____D C:\ProgramData\WeUkKR
2015-07-28 14:51 - 2015-07-17 14:48 - 00000000 ____D C:\Users\PAK\AppData\Local\gmsd_au_004010033
2015-07-28 14:48 - 2015-07-15 10:37 - 00111344 _____ (Symantec Corporation) C:\windows\system32\Drivers\SYMEVENT64x86.SYS
2015-07-28 14:48 - 2015-07-15 10:37 - 00008214 _____ C:\windows\system32\Drivers\SYMEVENT64x86.CAT
==================== Files in the root of some directories =======
2015-03-18 06:47 - 2013-11-29 09:46 - 0000517 _____ () C:\Program Files\unsetup.iss
2015-03-18 06:47 - 2013-11-29 09:46 - 0000517 _____ () C:\Program Files (x86)\unsetup.iss
2015-03-18 06:47 - 2013-11-29 09:46 - 0000517 _____ () C:\Program Files\Common Files\unsetup.iss
2015-03-18 06:47 - 2013-11-29 09:46 - 0000517 _____ () C:\Program Files (x86)\Common Files\unsetup.iss
2015-03-18 06:53 - 2015-03-18 06:53 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
Some files in TEMP:
====================
C:\Users\PAK\AppData\Local\Temp\ICReinstall_juniper-networks-network-connect (1).exe
C:\Users\PAK\AppData\Local\Temp\juniper-networks-network-connect (1).exe
C:\Users\PAK\AppData\Local\Temp\juniper-networks-network-connect.exe
C:\Users\PAK\AppData\Local\Temp\neoNCSetup64.exe
C:\Users\PAK\AppData\Local\Temp\oct18FA.tmp.exe
C:\Users\PAK\AppData\Local\Temp\oct2FAF.tmp.exe
C:\Users\PAK\AppData\Local\Temp\oct5D87.tmp.exe
C:\Users\PAK\AppData\Local\Temp\oct91CD.tmp.exe
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\windows\system32\winlogon.exe => File is digitally signed
C:\windows\system32\wininit.exe => File is digitally signed
C:\windows\explorer.exe => File is digitally signed
C:\windows\SysWOW64\explorer.exe => File is digitally signed
C:\windows\system32\svchost.exe => File is digitally signed
C:\windows\SysWOW64\svchost.exe => File is digitally signed
C:\windows\system32\services.exe => File is digitally signed
C:\windows\system32\User32.dll => File is digitally signed
C:\windows\SysWOW64\User32.dll => File is digitally signed
C:\windows\system32\userinit.exe => File is digitally signed
C:\windows\SysWOW64\userinit.exe => File is digitally signed
C:\windows\system32\rpcss.dll => File is digitally signed
C:\windows\system32\dnsapi.dll => File is digitally signed
C:\windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\windows\system32\Drivers\volsnap.sys => File is digitally signed
==================== BCD ================================
Firmware Boot Manager
---------------------
identifier {fwbootmgr}
displayorder {bootmgr}
{3d3db803-cce7-11e4-a1d3-806e6f6e6963}
{16faeb14-211b-11e5-825f-806e6f6e6963}
{3d3db801-cce7-11e4-a1d3-806e6f6e6963}
{3d3db802-cce7-11e4-a1d3-806e6f6e6963}
timeout 0
Windows Boot Manager
--------------------
identifier {bootmgr}
device partition=\Device\HarddiskVolume2
path \EFI\Microsoft\Boot\bootmgfw.efi
description Windows Boot Manager
locale en-US
inherit {globalsettings}
integrityservices Enable
default {current}
resumeobject {acd60cee-cc5f-11e4-9bb4-68f728a7bf67}
displayorder {current}
toolsdisplayorder {memdiag}
timeout 0
Firmware Application (101fffff)
-------------------------------
identifier {16faeb14-211b-11e5-825f-806e6f6e6963}
device partition=\Device\HarddiskVolume3
path \EFI\Microsoft\Boot\LrsBootMgr.efi
description Lenovo Recovery System
Firmware Application (101fffff)
-------------------------------
identifier {16faeb15-211b-11e5-825f-806e6f6e6963}
description EFI Network 0 for IPv4 (68-F7-28-A7-BF-67)
Firmware Application (101fffff)
-------------------------------
identifier {3d3db801-cce7-11e4-a1d3-806e6f6e6963}
description EFI USB Device
Firmware Application (101fffff)
-------------------------------
identifier {3d3db802-cce7-11e4-a1d3-806e6f6e6963}
description EFI DVD/CDROM
Firmware Application (101fffff)
-------------------------------
identifier {3d3db803-cce7-11e4-a1d3-806e6f6e6963}
description EFI Network
Firmware Application (101fffff)
-------------------------------
identifier {3d3db805-cce7-11e4-a1d3-806e6f6e6963}
description EFI Network 0 for IPv6 (68-F7-28-A7-BF-67)
Windows Boot Loader
-------------------
identifier {current}
device partition=C:
path \windows\system32\winload.efi
description Windows 8.1
locale en-US
inherit {bootloadersettings}
recoverysequence {b0c2bc28-ccdf-11e4-8258-f406696f0472}
integrityservices Enable
recoveryenabled Yes
isolatedcontext Yes
allowedinmemorysettings 0x15000075
osdevice partition=C:
systemroot \windows
resumeobject {acd60cee-cc5f-11e4-9bb4-68f728a7bf67}
nx OptIn
bootmenupolicy Standard
Windows Boot Loader
-------------------
identifier {b0c2bc28-ccdf-11e4-8258-f406696f0472}
device ramdisk=[\Device\HarddiskVolume1]\Recovery\WindowsRE\Winre.wim,{b0c2bc29-ccdf-11e4-8258-f406696f0472}
path \windows\system32\winload.efi
description Windows Recovery Environment
locale en-us
inherit {bootloadersettings}
displaymessage Recovery
displaymessageoverride Recovery
osdevice ramdisk=[\Device\HarddiskVolume1]\Recovery\WindowsRE\Winre.wim,{b0c2bc29-ccdf-11e4-8258-f406696f0472}
systemroot \windows
nx OptIn
bootmenupolicy Standard
winpe Yes
Resume from Hibernate
---------------------
identifier {acd60cee-cc5f-11e4-9bb4-68f728a7bf67}
device partition=C:
path \windows\system32\winresume.efi
description Windows Resume Application
locale en-US
inherit {resumeloadersettings}
recoverysequence {b0c2bc28-ccdf-11e4-8258-f406696f0472}
recoveryenabled Yes
isolatedcontext Yes
allowedinmemorysettings 0x15000075
filedevice partition=C:
filepath \hiberfil.sys
bootmenupolicy Standard
debugoptionenabled No
Windows Memory Tester
---------------------
identifier {memdiag}
device partition=\Device\HarddiskVolume2
path \EFI\Microsoft\Boot\memtest.efi
description Windows Memory Diagnostic
locale en-US
inherit {globalsettings}
badmemoryaccess Yes
EMS Settings
------------
identifier {emssettings}
bootems No
Debugger Settings
-----------------
identifier {dbgsettings}
debugtype Serial
debugport 1
baudrate 115200
RAM Defects
-----------
identifier {badmemory}
Global Settings
---------------
identifier {globalsettings}
inherit {dbgsettings}
{emssettings}
{badmemory}
Boot Loader Settings
--------------------
identifier {bootloadersettings}
inherit {globalsettings}
{hypervisorsettings}
Hypervisor Settings
-------------------
identifier {hypervisorsettings}
hypervisordebugtype Serial
hypervisordebugport 1
hypervisorbaudrate 115200
Resume Loader Settings
----------------------
identifier {resumeloadersettings}
inherit {globalsettings}
Setup Ramdisk Options
---------------------
identifier {ramdiskoptions}
description Ramdisk options
ramdisksdidevice boot
ramdisksdipath \boot\boot.sdi
Device options
--------------
identifier {b0c2bc29-ccdf-11e4-8258-f406696f0472}
description Windows Recovery
ramdisksdidevice partition=\Device\HarddiskVolume1
ramdisksdipath \Recovery\WindowsRE\boot.sdi
LastRegBack: 2014-08-24 07:30
==================== End of FRST.txt ============================
Start of Additional
Additional scan result of Farbar Recovery Scan Tool (x64) Version:24-08-2015
Ran by PAK (2015-08-25 14:47:19)
Running from C:\Users\PAK\Downloads
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-3391081986-1551245901-393088480-500 - Administrator - Disabled)
Guest (S-1-5-21-3391081986-1551245901-393088480-501 - Limited - Disabled)
PAK (S-1-5-21-3391081986-1551245901-393088480-1002 - Administrator - Enabled) => C:\Users\PAK
UpdatusUser (S-1-5-21-3391081986-1551245901-393088480-1001 - Limited - Enabled) => C:\Users\UpdatusUser
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Norton 360 (Enabled - Up to date) {53C7D717-52E2-B95E-FA61-6F32ECC805DB}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Norton 360 (Enabled - Up to date) {E8A636F3-74D8-B6D0-C0D1-5440974F4F66}
FW: Norton 360 (Enabled) {6BFC5632-188D-B806-D13E-C607121B42A0}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Amazon 1Button App (HKLM-x32\...\{3E69CC95-C0F6-4C74-8F43-74F9046F20B2}) (Version: 1.0.10 - Amazon)
CCSDK (HKLM-x32\...\{AE75190B-11B4-4F90-8254-DAB275CF2557}_is1) (Version: 1.0.3.4 - Lenovo)
Citrix Receiver (HKLM-x32\...\CitrixOnlinePluginPackWeb) (Version: 14.3.0.5014 - Citrix Systems, Inc.)
Conexant HD Audio (HKLM\...\CNXT_AUDIO_HDA) (Version: 8.65.28.50 - Conexant)
CyberLink MediaStory (HKLM-x32\...\InstallShield_{55762F9A-FCE3-45d5-817B-051218658423}) (Version: 1.0.1314 - CyberLink Corp.)
CyberLink Power2Go 8 (HKLM-x32\...\InstallShield_{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}) (Version: 8.0.0.4505 - CyberLink Corp.)
CyberLink PowerDirector 10 (HKLM-x32\...\InstallShield_{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}) (Version: 10.0.0.2810 - CyberLink Corp.)
CyberLink PowerDirector 10 (Version: 10.0.0.2810 - CyberLink Corp.) Hidden
Dependency Package Update (Version: 1.6.29.00 - Lenovo Inc.) Hidden
Dependency Package Update (Version: 1.6.36.00 - Lenovo Inc.) Hidden
Dependency Package Update (x32 Version: 1.6.32.00 - Lenovo Group Limited) Hidden
Dolby Digital Plus Home Theater (HKLM\...\{7E3D8FA1-6092-469A-955B-68FC4A2C67CA}) (Version: 7.5.1.1 - Dolby Laboratories Inc)
Energy Manager (HKLM-x32\...\InstallShield_{AC768037-7079-4658-AC24-2897650E0ABE}) (Version: 1.0.0.35 - Lenovo)
Energy Manager (x32 Version: 1.0.0.35 - Lenovo) Hidden
GamesDesktop 027.004010033 (HKLM-x32\...\gmsd_au_004010033_is1) (Version: - GAMESDESKTOP) <==== ATTENTION
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 44.0.2403.157 - Google Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.28.1 - Google Inc.) Hidden
Host App Service (HKU\S-1-5-21-3391081986-1551245901-393088480-1002\...\Pokki) (Version: 0.269.7.768 - Pokki)
Intel® Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.5.15.1730 - Intel Corporation)
Intel® Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3910 - Intel Corporation)
Intel® Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 13.0.0.1098 - Intel Corporation)
Intel® Wireless Bluetooth®(patch version 17.1.1431.1) (HKLM\...\{302600C1-6BDF-4FD1-1407-148929CC1385}) (Version: 17.1.1407.0480 - Intel Corporation)
Intel® PROSet/Wireless Software (HKLM-x32\...\{eff1d9d1-41fa-49ef-a986-082bfe49c293}) (Version: 16.8.0 - Intel Corporation)
istartsurf uninstall (HKLM-x32\...\istartsurf uninstall) (Version: - istartsurf) <==== ATTENTION
Java 8 Update 60 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218060F0}) (Version: 8.0.600.27 - Oracle Corporation)
Juniper Networks Network Connect 6.5.0 (HKLM-x32\...\Juniper Network Connect 6.5.0) (Version: 6.5.0.15255 - Juniper Networks)
Juniper Networks Network Connect 7.1.14 (HKLM-x32\...\Juniper Network Connect 7.1.14) (Version: 7.1.14.23943 - Juniper Networks)
Juniper Networks Setup Client (HKU\S-1-5-21-3391081986-1551245901-393088480-1002\...\Juniper_Setup_Client) (Version: 2.1.2.5973 - Juniper Networks)
Juniper Networks, Inc. Setup Client Activex Control (HKLM-x32\...\Juniper_Setup_Client Activex Control) (Version: 2.1.1.1 - Juniper Networks, Inc.)
Lenovo Browser Guard (HKLM-x32\...\LenovoBrowserGuard) (Version: 2.14.2.9 - ClientConnect LTD) <==== ATTENTION
Lenovo Dependency Package (HKLM\...\Lenovo Dependency Package_is1) (Version: 1.6.36.00 - Lenovo Group Limited)
Lenovo EasyCamera (HKLM-x32\...\{FC9B811E-39BC-4813-9E29-B83CCF700010}) (Version: 2.30.50.10 - Alcor)
Lenovo Experience Improvement (HKLM\...\LenovoExperienceImprovement) (Version: 1.0.19.0 - Lenovo)
Lenovo FusionEngine (HKLM-x32\...\Lenovo FusionEngine) (Version: 1.0.13.0 - Lenovo, Inc.)
Lenovo Mobile Phone Wireless Import (HKLM-x32\...\InstallShield_{DFB2E0D6-8DDE-49A4-B8F7-03C14DACCBA6}) (Version: 1.1.1.9 - Lenovo)
Lenovo Mobile Phone Wireless Import (x32 Version: 1.1.1.9 - Lenovo) Hidden
Lenovo OneKey Recovery (HKLM-x32\...\InstallShield_{46F4D124-20E5-4D12-BE52-EC177A7A4B42}) (Version: 8.0.0.2105 - CyberLink Corp.)
Lenovo OneKey Recovery (Version: 8.0.0.2105 - CyberLink Corp.) Hidden
Lenovo Photo Master (HKLM-x32\...\InstallShield_{BC94C56A-3649-420C-8756-2ADEBE399D33}) (Version: 1.0.1823.01 - CyberLink Corp.)
Lenovo Photo Master (x32 Version: 1.0.1823.01 - CyberLink Corp.) Hidden
Lenovo pointing device (HKLM\...\Elantech) (Version: 11.4.31.1 - ELAN Microelectronic Corp.)
Lenovo PowerDVD10 (HKLM-x32\...\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.5630.52 - CyberLink Corp.)
Lenovo PowerDVD10 (x32 Version: 10.0.5630.52 - CyberLink Corp.) Hidden
Lenovo VeriFace (HKLM\...\Lenovo VeriFace) (Version: 5.0.13.5261 - Lenovo)
Lenovo Web Start (HKU\S-1-5-21-3391081986-1551245901-393088480-1002\...\Pokki_04bb6df446330549a2cb8d67fbd1a745025b7bd1) (Version: 1.0.2.53457 - Pokki)
Maxthon Cloud Browser (HKLM-x32\...\Maxthon3) (Version: 4.4.2.2000 - Maxthon International Limited)
McAfee LiveSafe – Internet Security (HKLM-x32\...\MSC) (Version: 14.0.1076 - McAfee, Inc.)
Metric Collection SDK 35 (x32 Version: 1.2.0006.00 - Lenovo Group Limited) Hidden
Microsoft Office Standard 2013 (HKLM-x32\...\Office15.STANDARD) (Version: 15.0.4569.1506 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Nitro Pro 9 (HKLM\...\{70B831B7-A8EE-4C5F-8F34-F383D24B3A04}) (Version: 9.0.5.9 - Nitro)
Norton 360 (HKLM-x32\...\N360) (Version: 22.5.2.15 - Symantec Corporation)
NVIDIA GeForce Experience 1.7 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 1.7 - NVIDIA Corporation)
NVIDIA Graphics Driver 332.33 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 332.33 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.13.0927 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.0927 - NVIDIA Corporation)
Onekey Theater (HKLM-x32\...\{91CC5BAE-A098-40D3-A43B-C0DC7CE263FE}) (Version: 3.0.1.2 - Lenovo)
Online Plug-in (x32 Version: 14.3.0.5014 - Citrix Systems, Inc.) Hidden
Outils de vérification linguistique 2013 de Microsoft Office - Français (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Pro PC Cleaner (HKLM-x32\...\Pro PC Cleaner) (Version: 2.9.6 - Pro PC Cleaner) <==== ATTENTION
QAD Enterprise Applications 2.9.6 ( C:\Program Files (x86)\QAD\QAD Enterprise Applications 2.9.6 ) (HKLM-x32\...\{AB9DC79F-09C6-4F56-AD15-85CE41D83A55}) (Version: 2.9.6.17 - QAD)
Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.2.9200.39052 - Realtek Semiconductor Corp.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.20.815.2013 - Realtek)
Self-service Plug-in (x32 Version: 4.3.0.8352 - Citrix Systems, Inc.) Hidden
Service Pack 1 for Microsoft Office 2013 (KB2850036) 32-Bit Edition (HKLM-x32\...\{90150000-0012-0000-0000-0000000FF1CE}_Office15.STANDARD_{7F6C4883-A18C-459A-82C1-A2F9403F2DA6}) (Version: - Microsoft)
Setup (HKLM-x32\...\{7ADF667E-E14D-4D2C-827C-B0108F0D93BC}) (Version: - )
SHAREit (HKLM-x32\...\SHAREit_is1) (Version: 2.1.8.0 - Lenovo Group Limited)
Stagelight (HKLM\...\Stagelight) (Version: 2.0.0.5015 - Open Labs, LLC.)
Start Menu (HKU\S-1-5-21-3391081986-1551245901-393088480-1002\...\Pokki_Start_Menu) (Version: 0.269.7.768 - Pokki)
TeamViewer 10 (HKLM-x32\...\TeamViewer) (Version: 10.0.45862 - TeamViewer)
UESDK (HKLM-x32\...\{EB3F6640-58AE-4886-B8BA-466B6939A933}_is1) (Version: 1.0.2.7 - Lenovo)
User Manuals (HKLM-x32\...\InstallShield_{F07C2CF8-4C53-4EC3-8162-A6221E36EB88}) (Version: 3.0.0.3 - Lenovo)
User Manuals (x32 Version: 3.0.0.3 - Lenovo) Hidden
Web Shield (HKLM-x32\...\WebShield) (Version: 2.7.68 - Irrational Number Applications) <==== ATTENTION
Windows Driver Package - Lenovo (ACPIVPC) System (02/17/2013 9.52.0.776) (HKLM\...\35DD26BE48DAF4A9F35F969F3CB1E3E1435E661E) (Version: 02/17/2013 9.52.0.776 - Lenovo)
Windows Driver Package - Lenovo (WUDFRd) LenovoVhid (07/25/2013 10.30.0.288) (HKLM\...\6BCA401E9CBEED970D75F55FA5320F60D11984E9) (Version: 07/25/2013 10.30.0.288 - Lenovo)
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== Restore Points =========================
15-07-2015 00:44:18 Windows Update
17-07-2015 14:57:31 Norton_Power_Eraser_20150717145731084
30-07-2015 18:14:17 Windows Update
03-08-2015 18:54:24 Windows Update
17-08-2015 09:18:42 Windows Update
19-08-2015 09:39:34 Installed QAD Enterprise Applications
23-08-2015 12:10:04 Windows Update
==================== Hosts content: ===============================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2013-08-22 23:25 - 2015-08-21 08:00 - 00000824 ____A C:\windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {07565FC5-6EB1-4F3D-8973-D943E6479439} - System32\Tasks\Norton 360\Norton Error Analyzer => C:\Program Files (x86)\Norton 360\Engine\22.5.2.15\SymErr.exe [2015-05-20] (Symantec Corporation)
Task: {0E11A0B4-98D7-4F60-83E6-7DAA431F9AFD} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe
Task: {0F00F4BC-E851-481D-9886-0A6D1667D460} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-22] (Microsoft Corporation)
Task: {1A9CA1CD-F0B2-47FB-A14B-0F012FDF2332} - \ProPCCleaner_Start -> No File <==== ATTENTION
Task: {4CFE9716-594F-47CD-81E6-B8CE23AA0507} - System32\Tasks\Lenovo\Lenovo Customer Feedback Program 64 => C:\Program Files (x86)\Lenovo\Customer Feedback Program\Lenovo.TVT.CustomerFeedback.Agent.exe [2014-08-19] (Lenovo)
Task: {4E9B1AD6-3123-4072-BC32-0C1DCCFF62B9} - System32\Tasks\Microsoft\Windows\Application Experience\ProgramDataUpdater => Rundll32.exe invagent.dll,RunUpdate -noappraiser
Task: {52159AEC-BA23-46F3-846F-39E06E3C0345} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-07-17] (Google Inc.)
Task: {59980405-A884-4A27-B3A3-B6765C15CACD} - System32\Tasks\Lenovo\Dependency Package Auto Update => C:\Program Files\Lenovo\iMController\AutoUpdate.exe [2015-03-06] ()
Task: {7390E6AB-6731-4810-8B93-53B954EBC7C0} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-07-17] (Google Inc.)
Task: {8383A3A9-64E8-4FB5-8DB2-D16A8CAE000E} - System32\Tasks\McAfeeLogon => C:\Program Files\Common Files\McAfee\platform\McUICnt.exe [2015-05-06] (McAfee, Inc.)
Task: {8AD71FAB-B09D-42EA-8139-FD949CE2E39D} - System32\Tasks\Norton 360\Norton Error Processor => C:\Program Files (x86)\Norton 360\Engine\22.5.2.15\SymErr.exe [2015-05-20] (Symantec Corporation)
Task: {92385E23-8150-427B-A787-8B424428F3A2} - System32\Tasks\Lenovo\Lenovo Customer Feedback Program 64 35 => C:\Program Files (x86)\Lenovo\Customer Feedback Program 35\Lenovo.TVT.CustomerFeedback.Agent35.exe [2014-09-11] (Lenovo)
Task: {9448D30B-4A74-4E42-906B-C7E883F2DE15} - System32\Tasks\Pokki => %LOCALAPPDATA%\Pokki\Engine\ServiceHostAppUpdater.exe
Task: {9C4D0BA6-4D3E-438F-AB3B-B7237D9ED279} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\windows\system32\MRT.exe [2015-08-17] (Microsoft Corporation)
Task: {9FF29B48-F87E-4CF1-A3F2-DBFF57BA66BD} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-22] (Microsoft Corporation)
Task: {B5D02DC5-0D44-4EC3-B82D-39FD6E6D0122} - System32\Tasks\Osjneafolcat => C:\ProgramData\Osjneafolcat\1.0.4.1\ukedaorl.exe
Task: {CB8C8F8F-D15B-4C43-B983-F5FDE2C500AE} - System32\Tasks\Norton WSC Integration => C:\Program Files (x86)\Norton 360\Engine\22.5.2.15\WSCStub.exe [2015-07-17] (Symantec Corporation)
Task: {EA5047D0-53E8-4CE9-ABED-8F65C8FC21DA} - System32\Tasks\Maxthon Update => C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe [2014-09-11] (Maxthon International ltd.)
Task: {F172B636-54D6-4E75-AF45-B5E9356B98C1} - System32\Tasks\PDVDServ Task => C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.EXE [2013-03-09] (CyberLink Corp.)
Task: {FA3FE41A-8D2F-4311-9671-4DAC2F227F83} - System32\Tasks\Lenovo\Experience Improvement => C:\Program Files\Lenovo\ExperienceImprovement\LenovoExperienceImprovement.exe [2015-07-02] (Lenovo)
Task: {FE9E11B5-A80F-40FC-82FC-D90BE1ABC92B} - System32\Tasks\McAfee\McAfee Auto Maintenance Task Agent
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (Whitelisted) ==============
2015-03-18 07:34 - 2012-04-24 20:43 - 00390632 ____N () C:\Program Files\CyberLink\Shared files\RichVideo64.exe
2015-03-18 07:37 - 2015-03-18 07:37 - 00068368 _____ () C:\Program Files (x86)\Lenovo\Lenovo VeriFace\VfConnectorService.exe
2015-03-18 07:37 - 2015-03-18 07:37 - 00669288 _____ () C:\Program Files (x86)\Lenovo\Lenovo VeriFace\VfDataStorageInterface.dll
2015-03-18 07:29 - 2014-07-10 10:19 - 00592880 _____ () C:\Program Files (x86)\Lenovo\CCSDK\CCSDK.exe
2015-03-18 06:38 - 2014-01-06 18:13 - 00117536 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2015-05-13 18:31 - 2015-05-13 18:31 - 08898720 _____ () C:\Program Files\Microsoft Office\Office15\1033\GrooveIntlResource.dll
2015-03-18 07:29 - 2014-07-10 10:19 - 00397296 _____ () C:\Program Files (x86)\Lenovo\CCSDK\WinGather.exe
2015-03-18 06:53 - 2010-10-26 14:40 - 00049056 _____ () C:\Program Files\CONEXANT\ForteConfig\fmapp.exe
2014-08-30 08:34 - 2014-08-30 08:34 - 01397208 _____ () C:\Program Files\Stagelight\StagelightUpdate.exe
2015-03-18 06:44 - 2013-09-17 05:20 - 01242584 _____ () C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\ACE.dll
2015-04-29 06:15 - 2015-04-29 06:15 - 00569856 _____ () C:\Users\PAK\AppData\Local\Pokki\Engine\ppGoogleNaClPluginChrome.dll
2015-04-29 06:15 - 2015-04-29 06:15 - 01400846 _____ () C:\Users\PAK\AppData\Local\Pokki\Engine\avcodec-54.dll
2015-04-29 06:15 - 2015-04-29 06:15 - 00151054 _____ () C:\Users\PAK\AppData\Local\Pokki\Engine\avutil-51.dll
2015-04-29 06:15 - 2015-04-29 06:15 - 00222734 _____ () C:\Users\PAK\AppData\Local\Pokki\Engine\avformat-54.dll
2015-03-18 07:35 - 2014-07-04 14:35 - 00627672 _____ () C:\Program Files (x86)\Lenovo\Power2Go\CLMediaLibrary.dll
2014-07-05 05:35 - 2014-07-05 05:35 - 00016856 _____ () C:\Program Files (x86)\Lenovo\Power2Go\CLMLSvcPS.dll
2015-08-25 09:57 - 2015-08-18 15:23 - 01405768 _____ () C:\Program Files (x86)\Google\Chrome\Application\44.0.2403.157\libglesv2.dll
2015-08-25 09:57 - 2015-08-18 15:23 - 00081224 _____ () C:\Program Files (x86)\Google\Chrome\Application\44.0.2403.157\libegl.dll
2015-05-13 18:30 - 2015-05-13 18:30 - 08898720 _____ () C:\Program Files (x86)\Microsoft Office\Office15\1033\GrooveIntlResource.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
AlternateDataStreams: C:\Windows:nlsPreferences
AlternateDataStreams: C:\Users\PAK\OneDrive:ms-properties
==================== Safe Mode (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeaack => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeaack.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeavfk => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeavfk.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefire => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfemms => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfetdi2k => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfetdi2k.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfevtp => ""="Service"
==================== EXE Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-3391081986-1551245901-393088480-1002\Control Panel\Desktop\\Wallpaper -> C:\windows\Web\Wallpaper\Lenovo\LenovoWallPaper.jpg
DNS Servers: 198.142.0.51 - 211.29.132.12
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
(Currently there is no automatic fix for this section.)
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [{0233544F-C963-44B1-8E92-26CB70E2B337}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
FirewallRules: [{6ADD8C5F-3994-41F2-BF68-694CB4BB4A70}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
FirewallRules: [{1730479E-0B3E-4028-B7A8-A135B64B6DDD}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
FirewallRules: [{FE0CE762-D112-46B7-9B11-AC7B7C43EE22}] => (Allow) C:\Program Files (x86)\Lenovo\SHAREit\SHAREit.exe
FirewallRules: [{0AB7F2BC-5A15-4BBB-96FB-0A2E587B92FA}] => (Allow) C:\Program Files (x86)\Lenovo\SHAREit\SHAREit.exe
FirewallRules: [{5FBFFFED-B4B0-430C-BD9B-6480E153EBE2}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe
FirewallRules: [{00414B85-F0FB-472D-8B81-911069A6DAF0}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\Maxthon.exe
FirewallRules: [{B9FBE9EB-2A34-45C1-83A4-52EE8462B10C}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\MxUp.exe
FirewallRules: [{7EA5EBC6-1E50-47E5-A226-40E29097CB16}] => (Allow) C:\Program Files (x86)\Maxthon\Bin\MxUp.exe
FirewallRules: [{18E67096-2A3C-47F6-8BC7-2ED26E8AE27D}] => (Allow) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
FirewallRules: [{E4717BB7-D1E7-4EA1-8363-1B8D34CCDE40}] => (Allow) C:\Program Files\CyberLink\PowerDirector10\PDR10.EXE
FirewallRules: [{50DA25C0-2623-451C-8A98-3151CEC0DBA3}] => (Allow) C:\Program Files (x86)\Lenovo\PowerDVD10\PowerDVD Cinema\PowerDVDCinema10.exe
FirewallRules: [{3C6F6B47-66F0-463C-BF3A-C60B872C3161}] => (Allow) C:\Program Files (x86)\Lenovo\PowerDVD10\PowerDVD10.EXE
FirewallRules: [{F13F0E4A-D2EF-45E9-907D-0FA9825BA1D2}] => (Allow) C:\Program Files (x86)\Lenovo\Lenovo Photo Master\PhotoPlus.exe
FirewallRules: [{47843D15-6839-461E-A8A6-107248608530}] => (Allow) C:\Program Files (x86)\Lenovo\Lenovo Photo Master\subsys\AdvPhotoEditor\PhotoDirector5.exe
FirewallRules: [{460B8831-A26A-4105-AFDD-7A472B0B1B4D}] => (Allow) LPort=55100
FirewallRules: [{193BB77C-26BD-4FB3-BBB1-D8BDC1547A84}] => (Allow) C:\Program Files\Lenovo PhotoMasterImport\PhotoMasterImport.exe
FirewallRules: [{BB3874CF-ADFC-42F4-A5CF-58AEB3E3506C}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{DD8698FA-58A5-4462-87EB-BE74F1F54AEC}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{E2DFC42A-6627-4586-A195-EE70697FCA73}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{DCCB859A-CFE7-4EC0-B00E-071065844560}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{D1B634BA-463B-445B-8D28-89E666929B68}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (08/25/2015 01:42:10 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: ServiceHostApp.exe, version: 0.269.7.768, time stamp: 0x55d3c835
Faulting module name: libPokki.dll, version: 23.0.1271.64, time stamp: 0x55d3c6ba
Exception code: 0x80000003
Fault offset: 0x000633a0
Faulting process id: 0x164
Faulting application start time: 0xServiceHostApp.exe0
Faulting application path: ServiceHostApp.exe1
Faulting module path: ServiceHostApp.exe2
Report Id: ServiceHostApp.exe3
Faulting package full name: ServiceHostApp.exe4
Faulting package-relative application ID: ServiceHostApp.exe5
Error: (08/25/2015 10:27:21 AM) (Source: Microsoft-Windows-AppModel-State) (EventID: 10) (User: PAKCONSULTING)
Description: windows_ie_ac_0013
Error: (08/25/2015 10:27:18 AM) (Source: Microsoft-Windows-AppModel-State) (EventID: 10) (User: PAKCONSULTING)
Description: microsoft.windows.authhost.a_8wekyb3d8bbwe3
Error: (08/25/2015 10:21:28 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: WSHost.exe, version: 6.3.9600.17415, time stamp: 0x545040f3
Faulting module name: WinStoreUI.dll, version: 6.3.9600.17819, time stamp: 0x554636a9
Exception code: 0xc0000005
Fault offset: 0x00000000000569d9
Faulting process id: 0xfc8
Faulting application start time: 0xWSHost.exe0
Faulting application path: WSHost.exe1
Faulting module path: WSHost.exe2
Report Id: WSHost.exe3
Faulting package full name: WSHost.exe4
Faulting package-relative application ID: WSHost.exe5
Error: (08/21/2015 04:42:20 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: GWXUX.exe, version: 6.3.9600.17924, time stamp: 0x55959290
Faulting module name: ntdll.dll, version: 6.3.9600.17936, time stamp: 0x55a68e0c
Exception code: 0xc0000005
Fault offset: 0x000000000003d86e
Faulting process id: 0x628
Faulting application start time: 0xGWXUX.exe0
Faulting application path: GWXUX.exe1
Faulting module path: GWXUX.exe2
Report Id: GWXUX.exe3
Faulting package full name: GWXUX.exe4
Faulting package-relative application ID: GWXUX.exe5
Error: (08/19/2015 09:46:30 AM) (Source: RasClient) (EventID: 20227) (User: )
Description: CoId={7905AB36-35FD-4882-A889-02AB7A6FD852}: The user PAKCONSULTING\PAK dialed a connection named C-Cor-Juniper which has failed. The error code returned on failure is 2250.
Error: (08/19/2015 09:45:13 AM) (Source: RasClient) (EventID: 20227) (User: )
Description: CoId={4777609F-4392-444F-959A-11D722EA85F0}: The user PAKCONSULTING\PAK dialed a connection named C-Cor-Juniper which has failed. The error code returned on failure is 2250.
Error: (08/14/2015 03:30:24 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: N360.exe, version: 13.0.2.6, time stamp: 0x55772924
Faulting module name: ccLib.dll, version: 13.0.2.6, time stamp: 0x55772916
Exception code: 0xc0000005
Fault offset: 0x0006b050
Faulting process id: 0x73c
Faulting application start time: 0xN360.exe0
Faulting application path: N360.exe1
Faulting module path: N360.exe2
Report Id: N360.exe3
Faulting package full name: N360.exe4
Faulting package-relative application ID: N360.exe5
Error: (08/14/2015 02:40:38 PM) (Source: RasClient) (EventID: 20227) (User: )
Description: CoId={F04D003C-615F-4E07-8F9F-24FEA550A6FA}: The user PAKCONSULTING\PAK dialed a connection named C-Cor-Juniper which has failed. The error code returned on failure is 2250.
Error: (08/14/2015 02:40:18 PM) (Source: RasClient) (EventID: 20227) (User: )
Description: CoId={E311D02F-47AF-4689-94BA-72FDB8857BB2}: The user PAKCONSULTING\PAK dialed a connection named C-Cor which has failed. The error code returned on failure is 2250.
System errors:
=============
Error: (08/25/2015 01:56:52 PM) (Source: DCOM) (EventID: 10010) (User: PAKCONSULTING)
Description: {20966775-18A4-4299-B8E3-772C336B52A7}
Error: (08/25/2015 01:54:52 PM) (Source: DCOM) (EventID: 10010) (User: PAKCONSULTING)
Description: {20966775-18A4-4299-B8E3-772C336B52A7}
Error: (08/25/2015 01:52:52 PM) (Source: DCOM) (EventID: 10010) (User: PAKCONSULTING)
Description: {20966775-18A4-4299-B8E3-772C336B52A7}
Error: (08/25/2015 01:50:52 PM) (Source: DCOM) (EventID: 10010) (User: PAKCONSULTING)
Description: {20966775-18A4-4299-B8E3-772C336B52A7}
Error: (08/25/2015 01:48:52 PM) (Source: DCOM) (EventID: 10010) (User: PAKCONSULTING)
Description: {20966775-18A4-4299-B8E3-772C336B52A7}
Error: (08/25/2015 01:46:52 PM) (Source: DCOM) (EventID: 10010) (User: PAKCONSULTING)
Description: {20966775-18A4-4299-B8E3-772C336B52A7}
Error: (08/25/2015 01:46:42 PM) (Source: bowser) (EventID: 8003) (User: )
Description: The master browser has received a server announcement from the computer KELL-PC
that believes that it is the master browser for the domain on transport NetBT_Tcpip_{13259943-55A7-4692-8AB0-994F99AC2959}.
The master browser is stopping or an election is being forced.
Error: (08/25/2015 01:44:47 PM) (Source: DCOM) (EventID: 10010) (User: PAKCONSULTING)
Description: {20966775-18A4-4299-B8E3-772C336B52A7}
Error: (08/25/2015 01:31:08 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The McAfee Home Network service depends on the McAfee Validation Trust Protection Service service which failed to start because of the following error:
%%1070
Error: (08/25/2015 01:31:08 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: The McAfee Validation Trust Protection Service service hung on starting.
Microsoft Office:
=========================
Error: (08/25/2015 01:42:10 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: ServiceHostApp.exe0.269.7.76855d3c835libPokki.dll23.0.1271.6455d3c6ba80000003000633a016401d0dee804b76723C:\Users\PAK\AppData\Local\Pokki\Engine\ServiceHostApp.exeC:\Users\PAK\AppData\Local\Pokki\Engine\libPokki.dll4348bf5b-4adb-11e5-826b-f406696f0472
Error: (08/25/2015 10:27:21 AM) (Source: Microsoft-Windows-AppModel-State) (EventID: 10) (User: PAKCONSULTING)
Description: windows_ie_ac_0013
Error: (08/25/2015 10:27:18 AM) (Source: Microsoft-Windows-AppModel-State) (EventID: 10) (User: PAKCONSULTING)
Description: microsoft.windows.authhost.a_8wekyb3d8bbwe3
Error: (08/25/2015 10:21:28 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: WSHost.exe6.3.9600.17415545040f3WinStoreUI.dll6.3.9600.17819554636a9c000000500000000000569d9fc801d0decb2f154077C:\windows\WinStore\WSHost.exeC:\windows\winstore\WinStoreUI.dll39c61838-4abf-11e5-826a-f406696f0472
Error: (08/21/2015 04:42:20 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: GWXUX.exe6.3.9600.1792455959290ntdll.dll6.3.9600.1793655a68e0cc0000005000000000003d86e62801d0dbdc837cc088C:\windows\System32\GWX\GWXUX.exeC:\windows\SYSTEM32\ntdll.dllc4d20103-47cf-11e5-8269-f406696f0472
Error: (08/19/2015 09:46:30 AM) (Source: RasClient) (EventID: 20227) (User: )
Description: {7905AB36-35FD-4882-A889-02AB7A6FD852}PAKCONSULTING\PAKC-Cor-Juniper2250
Error: (08/19/2015 09:45:13 AM) (Source: RasClient) (EventID: 20227) (User: )
Description: {4777609F-4392-444F-959A-11D722EA85F0}PAKCONSULTING\PAKC-Cor-Juniper2250
Error: (08/14/2015 03:30:24 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: N360.exe13.0.2.655772924ccLib.dll13.0.2.655772916c00000050006b05073c01d0cdd880992f18C:\Program Files (x86)\Norton 360\Engine\22.5.2.15\N360.exeC:\Program Files (x86)\Norton 360\Engine\22.5.2.15\ccLib.dll8f807ed6-4245-11e5-8268-f406696f0472
Error: (08/14/2015 02:40:38 PM) (Source: RasClient) (EventID: 20227) (User: )
Description: {F04D003C-615F-4E07-8F9F-24FEA550A6FA}PAKCONSULTING\PAKC-Cor-Juniper2250
Error: (08/14/2015 02:40:18 PM) (Source: RasClient) (EventID: 20227) (User: )
Description: {E311D02F-47AF-4689-94BA-72FDB8857BB2}PAKCONSULTING\PAKC-Cor2250
==================== Memory info ===========================
Processor: Intel® Core i7-4510U CPU @ 2.00GHz
Percentage of memory in use: 28%
Total physical RAM: 8084.27 MB
Available physical RAM: 5801.61 MB
Total Virtual: 16276.27 MB
Available Virtual: 13515.97 MB
==================== Drives ================================
Drive c: (Windows8_OS) (Fixed) (Total:889.58 GB) (Free:803.65 GB) NTFS ==>[system with boot components (obtained from reading drive)]
Drive d: (LENOVO) (Fixed) (Total:25 GB) (Free:22.6 GB) NTFS
Drive f: (PAK USB) (Removable) (Total:3.73 GB) (Free:0.33 GB) FAT32
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: B35D6942)
Partition: GPT.
========================================================
Disk: 1 (MBR Code: Windows XP) (Size: 3.7 GB) (Disk ID: A1D39F95)
Partition 1: (Active) - (Size=3.7 GB) - (Type=0C)
==================== End of FRST.txt ============================