Hello. My computer is infected with a virus, and is being used as a gateway to spread other viruses. What is happening is that a message is being generated in MS Outlook, and sent to my entire address book. I have attached the requested information.
Thanks,
Andrew
aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
Run date: 2015-09-13 18:11:42
—————————–
18:11:42.273 OS Version: Windows x64 6.2.9200
18:11:42.273 Number of processors: 4 586 0x3C03
18:11:42.273 ComputerName: PC-DOWNSTAIRS UserName: Andrew
18:11:43.461 Initialize success
18:11:44.585 VM: initialized successfully
18:11:44.585 VM: Intel CPU supported
18:11:55.637 VM: disk I/O iaStorA.sys
18:14:19.228 AVAST engine defs: 15091202
18:14:37.557 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\0000002e
18:14:37.557 Disk 0 Vendor: ST1000DM003-1ER162 CC45 Size: 953869MB BusType: 11
18:14:38.586 Disk 2 \Device\Harddisk2\DR2 -> \Device\00000049
18:14:38.586 Disk 2 Vendor: Generic- 1.00 Size: 953869MB BusType: 1
18:14:38.601 Disk 3 \Device\Harddisk3\DR3 -> \Device\0000004a
18:14:38.601 Disk 3 Vendor: Generic- 1.00 Size: 953869MB BusType: 1
18:14:38.617 Disk 4 \Device\Harddisk4\DR4 -> \Device\0000004b
18:14:38.617 Disk 4 Vendor: Generic- 1.00 Size: 953869MB BusType: 1
18:14:38.632 Disk 5 \Device\Harddisk5\DR5 -> \Device\0000004c
18:14:38.632 Disk 5 Vendor: Generic- 1.00 Size: 953869MB BusType: 1
18:14:38.773 Disk 0 MBR read successfully
18:14:38.789 Disk 0 MBR scan
18:14:38.804 Disk 0 unknown MBR code
18:14:38.804 Disk 0 Partition 1 00 EE GPT 2097151 MB offset 1
18:14:38.867 Disk 0 scanning C:\Windows\system32\drivers
18:14:50.758 Service scanning
18:15:16.478 Modules scanning
18:15:16.478 Disk 0 trace - called modules:
18:15:16.603 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys storport.sys hal.dll iaStorA.sys
18:15:16.618 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xffffe00079f0a060]
18:15:16.634 3 CLASSPNP.SYS[fffff800cb002170] -> nt!IofCallDriver -> [0xffffe000780f7e50]
18:15:16.634 5 ACPI.sys[fffff800ca842c21] -> nt!IofCallDriver -> [0xffffe000780f9e50]
18:15:16.650 7 ACPI.sys[fffff800ca842c21] -> nt!IofCallDriver -> \Device\0000002e[0xffffe000780fb450]
18:15:17.790 AVAST engine scan C:\Windows
18:15:20.446 AVAST engine scan C:\Windows\system32
18:18:45.322 AVAST engine scan C:\Windows\system32\drivers
18:19:03.962 AVAST engine scan C:\Users\Andrew
18:22:41.797 AVAST engine scan C:\ProgramData
18:23:40.021 Disk 0 statistics 4037949/0/0 @ 246.67 MB/s
18:23:40.021 Scan finished successfully
18:25:12.400 Disk 0 MBR has been saved successfully to "C:\Users\Andrew\Desktop\MBR.dat"
18:25:12.400 The log file has been saved successfully to "C:\Users\Andrew\Desktop\aswMBR Log.txt"
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:13-09-2015 02
Ran by [removed] (administrator) on PC-DOWNSTAIRS (13-09-2015 18:35:05)
Running from C:\Users\[removed]\Downloads
[removed]
Platform: Windows 8.1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Andrea Electronics Corporation) C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
(Dell Inc.) C:\Program Files (x86)\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\platform\McSvcHost\McS28B0.tmp
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(McAfee, Inc.) C:\Program Files (x86)\McAfee\SiteAdvisor\mcsacore.exe
(Dell Inc.) C:\Program Files (x86)\Dell Customer Connect\OTBSurvey.exe
(Dell) C:\Program Files\Dell\Dell Data Services\DDSSvc.exe
(Dell) C:\Program Files\Dell\Dell Foundation Services\DFSSvc.exe
(Dell Inc.) C:\Program Files\Dell\DellDataVault\DellDataVaultWiz.exe
(Dell Inc.) C:\Program Files (x86)\Dell Update\DellUpService.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
(SoftThinks SAS) C:\Program Files (x86)\Dell Backup and Recovery\SftService.exe
(Dell Inc.) C:\Program Files\Dell\DellDataVault\DellDataVault.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\CSP\1.6.1008.0\McCSPServiceHost.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\systemcore\mfemms.exe
(McAfee, Inc.) C:\Windows\System32\mfevtps.exe
(McAfee, Inc.) C:\Windows\System32\mfevtps.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\systemcore\mfefire.exe
(McAfee, Inc.) C:\Program Files\mcafee\msc\McAPExe.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\systemcore\mfefire.exe
(Microsoft) C:\Program Files\Dell\Dell Foundation Services\DFSSystrayUI.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(Dell Inc.) C:\Program Files (x86)\Dell Update\DellUpTray.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonX86\Microsoft Shared\OFFICE15\csisyncclient.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
() C:\Program Files (x86)\Dropbox\DropboxOEM\DropboxOEM.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\root\office15\ONENOTEM.EXE
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\root\office15\outlook.exe
(Microsoft Corporation) C:\Windows\System32\WWAHost.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\platform\McUICnt.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
(SoftThinks - Dell) C:\Program Files (x86)\Dell Backup and Recovery\Components\DBRUpdate\DBRUpd.exe
(SoftThinks - Dell) C:\Program Files (x86)\Dell Backup and Recovery\Toaster.exe
(Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
() C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\ui\updateui.exe
(SoftThinks - Dell) C:\Program Files (x86)\Dell Backup and Recovery\Components\Shell\DBRSync.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
(Microsoft Corporation) C:\Windows\SysWOW64\dllhost.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.Reader_6.4.9926.17994_x64__8wekyb3d8bbwe\glcnd.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil_ActiveX.exe
(PC-Doctor, Inc.) C:\Program Files\Dell\SupportAssist\imstrayicon.exe
(Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17709_none_fa7932f59afc2e40\TiWorker.exe
(Farbar) C:\Users\Andrew\Downloads\FRST64 (1).exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\…\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7202520 2013-08-13] (Realtek Semiconductor)
HKLM\…\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1321688 2013-08-07] (Realtek Semiconductor)
HKLM\…\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [287592 2013-08-07] (Intel Corporation)
HKLM-x32\…\Run: [DropboxOEM] => C:\Program Files (x86)\Dropbox\DropboxOEM\DropboxOEM.exe [462160 2014-09-02] ()
ShellIconOverlayIdentifiers: [DBARFileBackuped] -> {831cebdd-6baf-4432-be76-9e0989c14aef} => C:\Program Files (x86)\Dell Backup and Recovery\Components\Shell\DBROverlayIconBackuped.dll [2014-12-30] (Softthinks SAS)
ShellIconOverlayIdentifiers: [DBARFileNotBackuped] -> {275e4fd7-21ef-45cf-a836-832e5d2cc1b3} => C:\Program Files (x86)\Dell Backup and Recovery\Components\Shell\DBROverlayIconNotBackuped.dll [2014-12-30] (Softthinks SAS)
ShellIconOverlayIdentifiers: [DBRShellOverlayBackupFile] -> {831CEBDD-6BAF-4432-BE76-9E0989C14AEF} => C:\Program Files (x86)\Dell Backup and Recovery\Components\Shell\DBROverlayIconBackuped.dll [2014-12-30] (Softthinks SAS)
ShellIconOverlayIdentifiers: [DBRShellOverlayModifiedBackupFile] -> {275E4FD7-21EF-45CF-A836-832E5D2CC1B3} => C:\Program Files (x86)\Dell Backup and Recovery\Components\Shell\DBROverlayIconNotBackuped.dll [2014-12-30] (Softthinks SAS)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk [2015-02-15]
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
Startup: C:\Users\Andrew\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Send to OneNote.lnk [2015-07-20]
ShortcutTarget: Send to OneNote.lnk -> C:\Program Files\Microsoft Office 15\root\office15\ONENOTEM.EXE (Microsoft Corporation)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254 [removed]
Tcpip\..\Interfaces\{3F3B97C2-85A3-4699-8B87-57A1F17BF68D}: [DhcpNameServer] 192.168.1.254 [removed]
Internet Explorer:
==================
HKU\S-1-5-21-4210094547-1222425090-1366728247-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.ca/
HKU\S-1-5-21-4210094547-1222425090-1366728247-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://dell13.msn.com/?pc=DCJB
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-4210094547-1222425090-1366728247-1001 -> DefaultScope {83907E20-E373-4656-8B43-E566B348F1B3} URL =
SearchScopes: HKU\S-1-5-21-4210094547-1222425090-1366728247-1001 -> {83907E20-E373-4656-8B43-E566B348F1B3} URL =
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2015-07-14] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2015-07-14] (Microsoft Corporation)
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll [2015-09-02] (McAfee, Inc.)
Handler-x32: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll [2015-09-02] (McAfee, Inc.)
Handler-x32: intu-tt2014 - {97BB39CB-9ABA-4513-81E7-1D6FDA0854B8} - C:\Program Files (x86)\TurboTax 2014\ic2014pp.dll [2014-11-22] (Intuit Canada, a general partnership/une société en nom collectif.)
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL [2015-06-09] (Microsoft Corporation)
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll [2015-09-02] (McAfee, Inc.)
Handler-x32: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll [2015-09-02] (McAfee, Inc.)
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\mcafee\msc\McSnIePl64.dll [2015-08-21] (McAfee, Inc.)
Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\msc\McSnIePl.dll [2015-08-21] (McAfee, Inc.)
FireFox:
========
FF Plugin: @mcafee.com/MSC,version=10 -> c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL [2015-08-21] ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2014-02-19] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2014-02-19] (Intel Corporation)
FF Plugin-x32: @mcafee.com/MSC,version=10 -> c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL [2015-08-21] ()
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [2015-06-07] (Microsoft Corporation)
FF HKLM\…\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor
FF Extension: McAfee WebAdvisor - C:\Program Files (x86)\McAfee\SiteAdvisor [2015-06-07]
FF HKLM-x32\…\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor
FF HKLM-x32\…\Thunderbird\Extensions: [[removed]] - C:\Program Files\McAfee\MSK
FF Extension: McAfee Anti-Spam Thunderbird Extension - C:\Program Files\McAfee\MSK [2015-06-07]
Chrome:
=======
CHR HKLM\…\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - C:\Program Files (x86)\McAfee\SiteAdvisor\McChPlg.crx [2015-09-03]
CHR HKLM-x32\…\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - C:\Program Files (x86)\McAfee\SiteAdvisor\McChPlg.crx [2015-09-03]
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S2 0325231442057966mcinstcleanup; C:\Windows\TEMP\032523~1.EXE [882000 2015-06-18] (McAfee, Inc.)
S2 BcmBtRSupport; C:\Windows\system32\BtwRSupportService.exe [2251992 2015-02-15] (Broadcom Corporation.)
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2765496 2015-07-14] (Microsoft Corporation)
R2 Dell Customer Connect; C:\Program Files (x86)\Dell Customer Connect\OTBSurvey.exe [145288 2015-04-09] (Dell Inc.)
R2 Dell Data Services; C:\Program Files\Dell\Dell Data Services\DDSSvc.exe [46792 2015-06-19] (Dell)
R2 Dell Foundation Services; C:\Program Files\Dell\Dell Foundation Services\DFSSvc.exe [116424 2015-08-18] (Dell)
R2 DellDataVault; C:\Program Files\Dell\DellDataVault\DellDataVault.exe [2573520 2015-05-22] (Dell Inc.)
R2 DellDataVaultWiz; C:\Program Files\Dell\DellDataVault\DellDataVaultWiz.exe [201936 2015-05-22] (Dell Inc.)
S3 DellProdRegManager; C:\Program Files (x86)\Dell Product Registration\regmgrsvc.exe [293440 2014-04-01] (Aviata, Inc.)
R2 DellUpdate; C:\Program Files (x86)\Dell Update\DellUpService.exe [237272 2015-08-27] (Dell Inc.)
R2 HomeNetSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [368048 2015-07-21] (McAfee, Inc.)
R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [24888 2015-07-26] (Hewlett-Packard Company)
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15720 2013-08-07] (Intel Corporation)
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [887232 2014-01-31] (Intel(R) Corporation)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [131544 2014-02-19] (Intel Corporation)
R3 iumsvc; C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [174368 2014-01-17] ()
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [154584 2014-02-19] (Intel Corporation)
R2 McAfee SiteAdvisor Service; C:\Program Files (x86)\McAfee\SiteAdvisor\McSACore.exe [157928 2015-09-02] (McAfee, Inc.)
R2 McAPExe; C:\Program Files\McAfee\MSC\McAPExe.exe [782608 2015-08-21] (McAfee, Inc.)
S3 McAWFwk; c:\Program Files\Common Files\McAfee\ActWiz\McAWFwk.exe [333584 2013-09-26] (McAfee, Inc.)
R2 mcbootdelaystartsvc; C:\Program Files\Common Files\McAfee\platform\McSvcHost\McSvHost.exe [368048 2015-07-21] (McAfee, Inc.)
R2 mccspsvc; C:\Program Files\Common Files\McAfee\CSP\1.6.1008.0\McCSPServiceHost.exe [1694152 2015-07-23] (McAfee, Inc.)
R2 McMPFSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [368048 2015-07-21] (McAfee, Inc.)
R2 McNaiAnn; C:\Program Files\Common Files\McAfee\platform\McSvcHost\McSvHost.exe [368048 2015-07-21] (McAfee, Inc.)
S3 McODS; C:\Program Files\mcafee\VirusScan\mcods.exe [639456 2015-07-17] (McAfee, Inc.)
S4 McOobeSv2; C:\Program Files\Common Files\McAfee\platform\McSvcHost\McSvHost.exe [368048 2015-07-21] (McAfee, Inc.)
R2 mcpltsvc; C:\Program Files\Common Files\McAfee\platform\McSvcHost\McSvHost.exe [368048 2015-07-21] (McAfee, Inc.)
R2 McProxy; C:\Program Files\Common Files\McAfee\platform\McSvcHost\McSvHost.exe [368048 2015-07-21] (McAfee, Inc.)
R3 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [232656 2015-06-29] (McAfee, Inc.)
R2 mfemms; C:\Program Files\Common Files\McAfee\SystemCore\\mfemms.exe [373704 2015-07-06] (McAfee, Inc.)
R2 mfevtp; C:\Windows\system32\mfevtps.exe [254792 2015-06-29] (McAfee, Inc.)
R2 MSK80Service; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [368048 2015-07-21] (McAfee, Inc.)
S2 Net Driver HPZ12; C:\Windows\System32\HPZinw12.dll [50688 2014-11-17] (Hewlett-Packard) [File not signed]
S2 Pml Driver HPZ12; C:\Windows\System32\HPZipm12.dll [66048 2014-11-17] (Hewlett-Packard) [File not signed]
R2 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [253776 2013-07-29] (CyberLink)
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [246488 2013-06-18] (Realtek Semiconductor)
R2 SftService; C:\Program Files (x86)\Dell Backup and Recovery\sftservice.exe [2005392 2015-02-12] (SoftThinks SAS)
R2 SupportAssistAgent; C:\Program Files (x86)\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe [20648 2015-06-11] (Dell Inc.)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366552 2015-07-07] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2015-07-07] (Microsoft Corporation)
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 bcbtums; C:\Windows\system32\drivers\bcbtums.sys [170712 2015-02-15] (Broadcom Corporation.)
R3 BCM43XX; C:\Windows\system32\DRIVERS\bcmwl63a.sys [7545008 2015-02-15] (Broadcom Corporation)
R3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [226304 2014-03-18] (Microsoft Corporation)
R3 cfwids; C:\Windows\System32\drivers\cfwids.sys [77536 2015-07-02] (McAfee, Inc.)
R1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [91712 2013-03-05] (CyberLink)
R3 DDDriver; C:\Windows\system32\drivers\DDDriver64Dcsa.sys [23760 2015-02-26] (Dell Computer Corporation)
R3 DellProf; C:\Windows\system32\drivers\DellProf.sys [24240 2015-05-22] (Dell Computer Corporation)
S0 ebdrv; C:\Windows\System32\drivers\evbda.sys [3357024 2013-08-22] (Broadcom Corporation)
S3 HipShieldK; C:\Windows\System32\drivers\HipShieldK.sys [207208 2015-05-19] (McAfee, Inc.)
R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [116736 2014-02-19] (Intel Corporation)
R3 mfeaack; C:\Windows\System32\drivers\mfeaack.sys [412440 2015-07-02] (McAfee, Inc.)
R3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [347800 2015-07-02] (McAfee, Inc.)
S0 mfeelamk; C:\Windows\System32\drivers\mfeelamk.sys [80920 2015-07-02] (McAfee, Inc.)
R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [496888 2015-07-02] (McAfee, Inc.)
R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [875928 2015-07-02] (McAfee, Inc.)
R3 mfencbdc; C:\Windows\System32\DRIVERS\mfencbdc.sys [529080 2015-06-28] (McAfee, Inc.)
S3 mfencrk; C:\Windows\System32\DRIVERS\mfencrk.sys [109728 2015-06-28] (McAfee, Inc.)
R3 mfesapsn; C:\Program Files (x86)\McAfee\SiteAdvisor\x64\mfesapsn.sys [37960 2015-09-02] (McAfee, Inc.)
R0 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [344704 2015-07-02] (McAfee, Inc.)
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44560 2015-07-07] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [270168 2015-07-07] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114520 2015-07-07] (Microsoft Corporation)
U3 aswMBR; \??\C:\Users\Andrew\AppData\Local\Temp\aswMBR.sys [X]
U3 aswVmm; \??\C:\Users\Andrew\AppData\Local\Temp\aswVmm.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-09-13 18:35 - 2015-09-13 18:35 - 00019927 _____ C:\Users\Andrew\Downloads\FRST.txt
2015-09-13 18:34 - 2015-09-13 18:35 - 00000000 ____D C:\FRST
2015-09-13 18:33 - 2015-09-13 18:34 - 02190848 _____ (Farbar) C:\Users\Andrew\Downloads\FRST64 (1).exe
2015-09-13 18:27 - 2015-09-13 18:29 - 02190848 _____ (Farbar) C:\Users\Andrew\Downloads\FRST64.exe
2015-09-13 18:25 - 2015-09-13 18:25 - 00000512 _____ C:\Users\Andrew\Desktop\MBR.dat
2015-09-13 17:39 - 2015-09-13 17:39 - 00000000 ____D C:\Users\Public\Documents\Hewlett-Packard
2015-09-13 17:35 - 2015-09-13 17:35 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
2015-09-09 21:46 - 2015-09-09 21:46 - 00000000 ____D C:\Program Files (x86)\HP
2015-09-09 21:46 - 2009-10-14 13:25 - 00157184 _____ (Hewlett-Packard Corporation) C:\Windows\system32\hpcpn093.dll
2015-09-09 21:46 - 2009-10-14 13:16 - 00276480 _____ (Hewlett Packard Corporation) C:\Windows\SysWOW64\hpcc3093.DLL
2015-09-09 21:46 - 2009-02-25 20:08 - 00671816 _____ (HP) C:\Windows\SysWOW64\hpcdmc32.DLL
2015-09-09 21:46 - 2007-07-16 15:29 - 00059928 _____ (Hewlett-Packard) C:\Windows\SysWOW64\fxcompchannel.dll
2015-09-09 21:44 - 2015-09-09 21:49 - 00000386 _____ C:\ProgramData\hpzinstall.log
2015-09-09 21:43 - 2015-09-09 21:50 - 00000000 ____D C:\ProgramData\HP
2015-09-09 21:43 - 2015-09-09 21:43 - 00000000 ____D C:\ProgramData\Hewlett-Packard
2015-09-09 21:43 - 2015-09-09 21:43 - 00000000 _____ C:\Windows\HPMProp.INI
2015-09-09 21:43 - 2014-11-20 08:23 - 00194288 _____ (Hewlett-Packard) C:\Windows\system32\hppdcompio.dll
2015-09-09 21:43 - 2014-11-20 08:23 - 00168176 _____ (Hewlett-Packard) C:\Windows\SysWOW64\hppccompio.dll
2015-09-09 21:43 - 2014-11-20 08:23 - 00060144 _____ (Hewlett-Packard) C:\Windows\system32\FxCompChannel_x64.dll
2015-09-09 21:43 - 2014-11-20 08:14 - 00237296 _____ (Hewlett-Packard Company) C:\Windows\system32\hpmlm135.dll
2015-09-09 21:43 - 2014-11-20 08:14 - 00162032 _____ (Hewlett-Packard) C:\Windows\system32\hpmtp175.dll
2015-09-09 21:43 - 2014-11-20 08:13 - 00217328 _____ (Hewlett-Packard) C:\Windows\system32\hpmml175.dll
2015-09-09 21:43 - 2014-11-20 08:13 - 00200432 _____ (Hewlett-Packard) C:\Windows\system32\hpmja175.dll
2015-09-09 21:43 - 2014-11-20 08:13 - 00189680 _____ (Hewlett-Packard) C:\Windows\system32\hpmpm081.dll
2015-09-09 21:43 - 2014-11-20 08:13 - 00073968 _____ (Hewlett-Packard) C:\Windows\system32\hpmpw081.dll
2015-09-09 21:43 - 2014-11-20 08:11 - 00457456 _____ (Hewlett-Packard Corporation) C:\Windows\system32\hpcpn175.dll
2015-09-09 21:43 - 2014-11-20 08:11 - 00140016 _____ (Hewlett-Packard) C:\Windows\system32\hpcjpm.dll
2015-09-09 21:43 - 2014-11-20 08:07 - 00452336 _____ (Hewlett Packard Corporation) C:\Windows\SysWOW64\hpcc3175.dll
2015-09-09 21:43 - 2009-09-28 13:44 - 01121792 _____ (Hewlett-Packard) C:\Windows\system32\hpptsp05_x64.dll
2015-09-09 21:43 - 2009-09-28 13:37 - 00770048 _____ (Hewlett-Packard) C:\Windows\SysWOW64\hpptsp05.dll
2015-09-09 21:43 - 2009-09-21 17:20 - 00003212 _____ C:\Windows\system32\hppls2320.spf
2015-09-09 21:43 - 2009-08-26 16:15 - 00995840 _____ (Hewlett-Packard) C:\Windows\system32\hpxp2320_x64.dll
2015-09-09 21:43 - 2008-09-30 09:52 - 00747008 _____ (Hewlett-Packard) C:\Windows\system32\hppasc12_x64.dll
2015-09-09 21:43 - 2008-09-30 09:52 - 00234496 _____ (Hewlett Packard) C:\Windows\system32\hppdew12_x64.dll
2015-09-09 21:43 - 2008-09-30 09:52 - 00234496 _____ (Hewlett Packard) C:\Windows\system32\hppafx12_x64.dll
2015-09-09 21:43 - 2008-09-30 09:52 - 00165376 _____ (Hewlett-Packard) C:\Windows\system32\hppdpr12_x64.dll
2015-09-09 21:43 - 2008-09-30 09:52 - 00000665 _____ C:\Windows\system32\hppapr12.dat
2015-09-09 21:43 - 2007-07-16 15:29 - 00059928 _____ (Hewlett-Packard) C:\Windows\SysWOW64\fxfaxchannel.dll
2015-09-09 21:43 - 2007-07-16 15:29 - 00031256 _____ (Hewlett Packard) C:\Windows\system32\Drivers\hpfx64gen.sys
2015-09-09 21:43 - 2007-07-16 15:29 - 00023064 _____ (Hewlett Packard) C:\Windows\system32\Drivers\hpfx64fax.sys
2015-09-09 21:43 - 2007-07-16 15:29 - 00020504 _____ (Hewlett Packard) C:\Windows\system32\Drivers\hpfx64bulk.sys
2015-09-09 21:41 - 2015-09-09 21:41 - 00000000 ____D C:\HP Universal Print Driver
2015-09-09 21:32 - 2015-09-09 21:32 - 00000000 ____D C:\Program Files (x86)\Hewlett-Packard
2015-09-09 21:28 - 2015-09-09 21:28 - 00032832 _____ C:\Windows\SysWOW64\rnd_chunk.bin
2015-09-08 15:24 - 2015-09-02 20:18 - 02531400 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2015-09-08 15:24 - 2015-09-02 20:17 - 01903848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2015-09-08 15:24 - 2015-09-02 12:48 - 02345472 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2015-09-08 15:24 - 2015-09-02 11:09 - 01556992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2015-09-08 15:23 - 2015-09-01 20:56 - 04175872 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-09-08 15:23 - 2015-09-01 20:55 - 00358912 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2015-09-08 15:23 - 2015-09-01 20:50 - 00044032 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2015-09-08 15:23 - 2015-09-01 20:17 - 00301568 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2015-09-08 15:23 - 2015-09-01 20:13 - 00035840 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2015-09-08 15:23 - 2015-08-26 20:48 - 00136904 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2015-09-08 15:23 - 2015-08-26 12:00 - 00721920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2015-09-08 15:23 - 2015-08-26 12:00 - 00124928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2015-09-08 15:23 - 2015-08-26 12:00 - 00081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2015-09-08 15:23 - 2015-08-26 12:00 - 00029696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2015-09-08 15:23 - 2015-08-26 08:46 - 03705344 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2015-09-08 15:23 - 2015-08-26 08:29 - 02240512 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2015-09-08 15:23 - 2015-08-26 08:27 - 00891904 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2015-09-08 15:23 - 2015-08-26 08:27 - 00409088 _____ (Microsoft Corporation) C:\Windows\system32\WUSettingsProvider.dll
2015-09-08 15:23 - 2015-08-26 08:26 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2015-09-08 15:23 - 2015-08-26 08:26 - 00095744 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2015-09-08 15:23 - 2015-08-26 08:26 - 00035840 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2015-09-08 15:23 - 2015-08-22 12:19 - 25188352 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-09-08 15:23 - 2015-08-22 11:35 - 02886144 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-09-08 15:23 - 2015-08-22 11:34 - 00585216 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-09-08 15:23 - 2015-08-22 11:22 - 19856384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-09-08 15:23 - 2015-08-22 11:21 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-09-08 15:23 - 2015-08-22 11:20 - 05923840 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-09-08 15:23 - 2015-08-22 10:55 - 00504832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2015-09-08 15:23 - 2015-08-22 10:50 - 02279424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-09-08 15:23 - 2015-08-22 10:50 - 01032704 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll
2015-09-08 15:23 - 2015-08-22 10:45 - 00665600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2015-09-08 15:23 - 2015-08-22 10:44 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2015-09-08 15:23 - 2015-08-22 10:41 - 14451712 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-09-08 15:23 - 2015-08-22 10:41 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-09-08 15:23 - 2015-08-22 10:41 - 00720384 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-09-08 15:23 - 2015-08-22 10:41 - 00374784 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-09-08 15:23 - 2015-08-22 10:39 - 02126336 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-09-08 15:23 - 2015-08-22 10:28 - 04520448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-09-08 15:23 - 2015-08-22 10:26 - 02427392 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-09-08 15:23 - 2015-08-22 10:23 - 00880128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll
2015-09-08 15:23 - 2015-08-22 10:22 - 12857344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-09-08 15:23 - 2015-08-22 10:20 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2015-09-08 15:23 - 2015-08-22 10:18 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2015-09-08 15:23 - 2015-08-22 10:18 - 00689152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2015-09-08 15:23 - 2015-08-22 10:18 - 00327168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2015-09-08 15:23 - 2015-08-22 10:14 - 01545728 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-09-08 15:23 - 2015-08-22 10:01 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-09-08 15:23 - 2015-08-22 10:00 - 01951232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-09-08 15:23 - 2015-08-22 09:56 - 01310720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-09-08 15:23 - 2015-08-22 09:55 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2015-09-08 15:23 - 2015-08-03 15:15 - 00074928 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2015-09-08 15:23 - 2015-08-03 15:15 - 00065600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll
2015-09-08 15:23 - 2015-08-01 08:22 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2015-09-08 15:23 - 2015-07-31 21:47 - 00229376 _____ (Microsoft Corporation) C:\Windows\system32\schtasks.exe
2015-09-08 15:23 - 2015-07-31 21:45 - 00182784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schtasks.exe
2015-09-08 15:23 - 2015-07-31 21:38 - 01265152 _____ (Microsoft Corporation) C:\Windows\system32\schedsvc.dll
2015-09-08 15:23 - 2015-07-31 21:37 - 00468992 _____ (Microsoft Corporation) C:\Windows\system32\taskeng.exe
2015-09-08 15:23 - 2015-07-31 21:37 - 00359936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\taskeng.exe
2015-09-08 15:23 - 2015-07-30 11:18 - 00268288 _____ (Microsoft Corporation) C:\Windows\system32\InkEd.dll
2015-09-08 15:23 - 2015-07-30 10:22 - 00230912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InkEd.dll
2015-09-08 15:23 - 2015-07-22 08:34 - 02775552 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2015-09-08 15:23 - 2015-07-22 08:33 - 01728000 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Immersive.dll
2015-09-08 15:23 - 2015-07-22 08:25 - 02461184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2015-09-08 15:23 - 2015-07-22 08:25 - 01546752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Immersive.dll
2015-09-08 15:23 - 2015-07-22 08:19 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\UtcResources.dll
2015-09-08 15:23 - 2015-07-22 07:52 - 01633792 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll
2015-09-08 15:23 - 2015-07-18 12:31 - 00194048 _____ (Microsoft Corporation) C:\Windows\system32\shacct.dll
2015-09-08 15:23 - 2015-07-18 12:29 - 00655872 _____ (Microsoft Corporation) C:\Windows\system32\SettingSync.dll
2015-09-08 15:23 - 2015-07-18 12:29 - 00148480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shacct.dll
2015-09-08 15:23 - 2015-07-18 12:27 - 00520192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SettingSync.dll
2015-09-08 15:23 - 2015-07-17 08:15 - 00951296 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll
2015-09-08 15:23 - 2015-07-17 08:10 - 00749568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll
2015-09-08 15:23 - 2015-07-13 21:27 - 00063488 _____ (Microsoft Corporation) C:\Windows\system32\tzsync.exe
2015-09-08 15:23 - 2015-07-13 13:10 - 00411455 _____ C:\Windows\system32\ApnDatabase.xml
2015-09-08 15:23 - 2015-07-09 10:14 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll
2015-09-08 15:23 - 2015-07-03 15:51 - 01380056 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2015-09-08 15:23 - 2015-07-03 08:00 - 01097216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2015-09-08 15:23 - 2015-06-27 05:47 - 00118616 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2015-09-08 15:23 - 2015-06-19 11:07 - 02819072 _____ (Microsoft Corporation) C:\Windows\system32\SettingsHandlers.dll
2015-09-08 15:22 - 2015-07-10 13:06 - 00118272 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\bthpan.sys
2015-08-28 13:26 - 2015-08-28 13:26 - 00000000 ____D C:\Program Files (x86)\Dell Update
2015-08-16 19:57 - 2015-09-05 18:42 - 00082944 _____ C:\Users\Andrew\Desktop\Password List.xls
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-09-13 18:33 - 2015-02-15 07:57 - 00000000 ____D C:\Program Files (x86)\Dell Backup and Recovery
2015-09-13 18:33 - 2015-02-15 07:41 - 01972261 _____ C:\Windows\WindowsUpdate.log
2015-09-13 18:32 - 2015-06-07 13:48 - 00000000 ____D C:\Users\Andrew\Documents\Outlook Files
2015-09-13 18:21 - 2015-06-07 02:20 - 00003950 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{689CB81E-41D0-4679-8171-CAB74331F557}
2015-09-13 18:02 - 2013-08-22 09:36 - 00000000 ____D C:\Windows\system32\sru
2015-09-13 17:57 - 2015-06-07 02:19 - 00003600 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-4210094547-1222425090-1366728247-1001
2015-09-13 17:32 - 2015-06-07 02:16 - 00000000 ____D C:\Users\Andrew\OneDrive
2015-09-13 17:31 - 2015-02-15 07:53 - 00016974 _____ C:\Windows\SysWOW64\Gms.log
2015-09-12 05:56 - 2013-08-22 09:36 - 00000000 ____D C:\Windows\rescache
2015-09-12 05:40 - 2015-07-22 04:58 - 00003064 _____ C:\Windows\System32\Tasks\McAfeeLogon
2015-09-12 05:40 - 2015-07-22 04:58 - 00000000 ____D C:\Windows\System32\Tasks\McAfee
2015-09-12 05:39 - 2015-02-15 08:00 - 00000000 ____D C:\Program Files (x86)\McAfee
2015-09-12 05:37 - 2014-03-18 03:53 - 00865408 _____ C:\Windows\system32\PerfStringBackup.INI
2015-09-12 05:34 - 2013-08-22 08:46 - 00026819 _____ C:\Windows\setupact.log
2015-09-12 05:32 - 2013-08-22 08:45 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-09-12 05:32 - 2013-08-22 08:44 - 00492960 _____ C:\Windows\system32\FNTCACHE.DAT
2015-09-12 05:31 - 2014-03-18 03:44 - 00054356 _____ C:\Windows\PFRO.log
2015-09-12 05:30 - 2013-08-22 09:36 - 00000000 ____D C:\Windows\PolicyDefinitions
2015-09-12 05:30 - 2013-08-22 07:25 - 00262144 ___SH C:\Windows\system32\config\BBI
2015-09-12 05:14 - 2013-08-22 09:36 - 00000000 ____D C:\Windows\AppReadiness
2015-09-10 21:26 - 2015-02-15 08:00 - 00000000 ____D C:\ProgramData\McAfee
2015-09-08 20:10 - 2013-08-22 09:20 - 00000000 ____D C:\Windows\CbsTemp
2015-09-08 20:09 - 2014-03-18 03:38 - 00000000 ____D C:\Program Files\Windows Journal
2015-09-08 20:08 - 2015-06-10 05:12 - 00000000 ____D C:\Windows\system32\MRT
2015-09-07 15:42 - 2013-08-22 07:25 - 00262144 ___SH C:\Windows\system32\config\ELAM
2015-09-04 04:55 - 2015-02-13 13:52 - 00000000 __SHD C:\System Recovery
2015-09-03 19:30 - 2015-06-07 12:29 - 00000000 ____D C:\Program Files\Microsoft Office 15
2015-09-03 18:26 - 2015-06-07 12:39 - 00004998 _____ C:\Windows\System32\Tasks\Microsoft Office 15 Sync Maintenance for PC-DOWNSTAIRS-Andrew PC-Downstairs
2015-08-30 14:45 - 2013-08-22 09:36 - 00000000 ____D C:\Windows\system32\Recovery
2015-08-28 13:26 - 2015-02-15 07:56 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell
2015-08-26 18:37 - 2015-06-10 05:12 - 134753440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-08-23 13:39 - 2015-02-15 07:55 - 00000000 ____D C:\Program Files\Dell
2015-08-20 08:04 - 2015-06-07 12:39 - 00003108 _____ C:\Windows\System32\Tasks\Microsoft OneDrive Auto Update Task-S-1-5-21-4210094547-1222425090-1366728247-1001
2015-08-16 19:31 - 2015-06-07 02:14 - 00000000 ____D C:\Users\Andrew\AppData\Local\Packages
2015-08-16 14:43 - 2015-02-15 08:00 - 00000000 ____D C:\Program Files\Common Files\McAfee
2015-08-16 13:30 - 2015-06-17 17:25 - 00000000 ____D C:\Windows\system32\appraiser
2015-08-16 13:30 - 2015-06-17 17:23 - 00000000 ___SD C:\Windows\system32\CompatTel
2015-08-16 13:30 - 2013-08-22 09:36 - 00000000 ___RD C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-08-16 13:30 - 2013-08-22 09:36 - 00000000 ___RD C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-08-16 13:30 - 2013-08-22 09:36 - 00000000 ____D C:\Program Files\Windows Defender
2015-08-16 13:30 - 2013-08-22 09:36 - 00000000 ____D C:\Program Files (x86)\Windows Defender
==================== Files in the root of some directories =======
2015-02-15 07:41 - 2015-02-15 07:41 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
2015-09-09 21:44 - 2015-09-09 21:49 - 0000386 _____ () C:\ProgramData\hpzinstall.log
2015-02-15 07:53 - 2015-02-15 07:54 - 0000121 _____ () C:\ProgramData\{1FBF6C24-C1fD-4101-A42B-0C564F9E8E79}.log
2015-02-15 07:51 - 2015-02-15 07:51 - 0000106 _____ () C:\ProgramData\{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}.log
2015-02-15 07:51 - 2015-02-15 07:52 - 0000111 _____ () C:\ProgramData\{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}.log
2015-02-15 07:52 - 2015-02-15 07:53 - 0000108 _____ () C:\ProgramData\{B46BEA36-0B71-4A4E-AE41-87241643FA0A}.log
2015-02-15 07:51 - 2015-02-15 07:51 - 0000107 _____ () C:\ProgramData\{C59C179C-668D-49A9-B6EA-0121CCFC1243}.log
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-09-06 05:14
==================== End of FRST.txt ============================
Additional scan result of Farbar Recovery Scan Tool (x64) Version:13-09-2015 02
Ran by [removed] (2015-09-13 18:35:36)
Running from C:\Users\[removed]\Downloads
Windows 8.1 (X64) (2015-06-07 08:13:52)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-4210094547-1222425090-1366728247-500 - Administrator - Disabled)
Andrew (S-1-5-21-4210094547-1222425090-1366728247-1001 - Administrator - Enabled) => C:\Users\Andrew
Guest (S-1-5-21-4210094547-1222425090-1366728247-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-4210094547-1222425090-1366728247-1003 - Limited - Enabled)
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: McAfee Anti-Virus and Anti-Spyware (Enabled - Up to date) {DA9F8ED0-D0DE-39CC-F55A-51AB4CC1B556}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: McAfee Anti-Virus and Anti-Spyware (Enabled - Up to date) {61FE6F34-F6E4-3642-CFEA-6AD93746FFEB}
FW: McAfee Firewall (Enabled) {E2A40FF5-9AB1-3894-DE05-F89EB212F22D}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
64 Bit HP CIO Components Installer (Version: 18.2.4 - Hewlett-Packard) Hidden
Cisco EAP-FAST Module (x32 Version: 2.2.14 - Cisco Systems, Inc.) Hidden
Cisco LEAP Module (x32 Version: 1.0.19 - Cisco Systems, Inc.) Hidden
Cisco PEAP Module (x32 Version: 1.1.6 - Cisco Systems, Inc.) Hidden
CyberLink Media Suite Essentials (HKLM-x32\…\InstallShield_{8F14AA37-5193-4A14-BD5B-BDF9B361AEF7}) (Version: 10.0 - CyberLink Corp.)
Dell Backup and Recovery (HKLM-x32\…\{0ED7EE95-6A97-47AA-AD73-152C08A15B04}) (Version: 1.8.1.70 - Dell Inc.)
Dell Customer Connect (HKLM-x32\…\{FEFDCDCF-C49C-45D0-AAF8-5345858ADEC7}) (Version: 1.2.1.0 - Dell Inc.)
Dell Data Services (HKLM\…\{815D96BA-2FC6-4F61-9BE3-2CFE446E8ECF}) (Version: 1.2.7.0 - Dell Inc.)
Dell Data Vault (Version: 4.3.4.0 - Dell Inc.) Hidden
Dell Digital Delivery (HKLM-x32\…\{BC8233D8-59BA-4D40-92B9-4FDE7452AA8B}) (Version: 3.0.3999.0 - Dell Products, LP)
Dell Foundation Services (HKLM\…\{D605CD24-103D-4DB6-B572-653851213C46}) (Version: 2.2.65.0 - Dell Inc.)
Dell Product Registration (HKLM-x32\…\{17FFE63C-6734-4950-B488-134B5A2505F7}) (Version: 2.04.0280 - Aviata Inc.)
Dell SupportAssist (HKLM\…\PC-Doctor for Windows) (Version: 1.1.6664.10 - Dell)
Dell SupportAssistAgent (HKLM-x32\…\{287348C8-8B47-4C36-AF28-441A3B7D8722}) (Version: 1.1.0.47 - Dell)
Dell Update (HKLM-x32\…\{DB82968B-57A4-4397-81A5-ECAB21B5DFCD}) (Version: 1.7.1015.0 - Dell Inc.)
Dropbox 20 GB (HKLM-x32\…\{597A58EC-42D6-4940-8739-FB94491B013C}) (Version: 0.9.0 - Dropbox, Inc.)
DW WLAN Card (HKLM\…\DW WLAN Card) (Version: 6.30.223.227 - Dell Inc.)
HP Support Solutions Framework (HKLM-x32\…\{F6A11738-3EE4-4573-AEA5-6CD5D491C167}) (Version: 12.0.30.81 - Hewlett-Packard Company)
Intel(R) Chipset Device Software (x32 Version: 10.0.13 - Intel(R) Corporation) Hidden
Intel(R) Management Engine Components (HKLM\…\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 10.0.0.1168 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM\…\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 12.8.0.1016 - Intel Corporation)
Intel(R) Update Manager (HKLM-x32\…\{AD6B46F2-FE21-496F-BE90-BE19AABE353C}) (Version: 2.2.12 - Intel Corporation)
McAfee LiveSafe – Internet Security (HKLM-x32\…\MSC) (Version: 14.0.4121 - McAfee, Inc.)
McAfee WebAdvisor (HKLM-x32\…\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}) (Version: 4.0.158 - McAfee, Inc.)
Microsoft Office 365 - en-us (HKLM\…\O365HomePremRetail - en-us) (Version: 15.0.4745.1002 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-4210094547-1222425090-1366728247-1001\…\OneDriveSetup.exe) (Version: 17.3.5930.0814 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Office 15 Click-to-Run Extensibility Component (x32 Version: 15.0.4745.1002 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Licensing Component (Version: 15.0.4745.1002 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Localization Component (x32 Version: 15.0.4745.1002 - Microsoft Corporation) Hidden
Realtek Card Reader (HKLM-x32\…\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.2.9200.30164 - Realtek Semiconductor Corp.)
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7016 - Realtek Semiconductor Corp.)
TurboTax 2014 (HKLM-x32\…\{0B69B187-4F9F-41C2-B850-735D1A323571}) (Version: 1.00.0000 - Intuit Canada)
WIDCOMM Bluetooth Software (HKLM\…\{C6D9ED03-6FCF-4410-9CB7-45CA285F9E11}) (Version: 12.0.0.9800 - Broadcom Corporation)
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-4210094547-1222425090-1366728247-1001_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\Andrew\AppData\Local\Microsoft\OneDrive\17.3.5930.0814\amd64\FileSyncApi64.dll (Microsoft Corporation)
==================== Restore Points =========================
27-08-2015 03:00:18 Scheduled Checkpoint
03-09-2015 03:36:35 Scheduled Checkpoint
08-09-2015 20:05:53 Windows Update
09-09-2015 21:32:33 Installed HP Support Solutions Framework
==================== Hosts content: ===============================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2013-08-22 07:25 - 2013-08-22 07:25 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {0AAE2AE8-26C3-4EA0-B056-986460C53CC2} - System32\Tasks\Microsoft Office 15 Sync Maintenance for PC-DOWNSTAIRS-Andrew PC-Downstairs => C:\Program Files\Microsoft Office 15\Root\Office15\MsoSync.exe [2015-06-02] (Microsoft Corporation)
Task: {2FB238D0-14C3-4196-97AE-47475CFF6A3F} - System32\Tasks\PCDoctorBackgroundMonitorTask => C:\Program Files\Dell\SupportAssist\uaclauncher.exe [2015-05-25] (PC-Doctor, Inc.)
Task: {3673DC64-2538-490F-8151-1763A5AF67C0} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\Windows\system32\MRT.exe [2015-08-26] (Microsoft Corporation)
Task: {5113CF79-E5B8-490F-B091-8D9FE6CC46FB} - System32\Tasks\Microsoft OneDrive Auto Update Task-S-1-5-21-4210094547-1222425090-1366728247-1001 => %localappdata%\Microsoft\OneDrive\OneDrive.exe
Task: {51EC2792-04D6-4E29-8B48-A6132A98D66E} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2015-07-14] (Microsoft Corporation)
Task: {5B5101F9-AB53-44A3-AE08-DF428C740F14} - System32\Tasks\Microsoft\Windows\Application Experience\ProgramDataUpdater => Rundll32.exe invagent.dll,RunUpdate -noappraiser
Task: {6A81C1D2-C4F7-41C7-8EAB-3FDF82902DB9} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473-Logon => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [2014-01-17] ()
Task: {6E84F34F-2C8A-4F9D-ACD7-3A4E588E2D5B} - System32\Tasks\McAfeeLogon => C:\Program Files\Common Files\McAfee\platform\McUICnt.exe [2015-07-21] (McAfee, Inc.)
Task: {7AE6FEE2-D97D-4090-8B1A-F7943F18D37A} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe [2014-01-17] ()
Task: {7FE4F727-DD8B-4D1F-BE09-6A5877458F8B} - System32\Tasks\Dell SupportAssistAgent AutoUpdate => C:\Program Files (x86)\Dell\SupportAssistAgent\bin\SupportAssist.exe [2015-06-11] (Dell Inc.)
Task: {992B122E-B55C-41A8-92E0-BEB40127C8F6} - System32\Tasks\PCDEventLauncherTask => C:\Program Files\Dell\SupportAssist\sessionchecker.exe [2015-05-25] (PC-Doctor, Inc.)
Task: {A132ECCD-F3FE-41FB-865F-DB574B73EEEA} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonx86\Microsoft Shared\OFFICE15\OLicenseHeartbeat.exe [2015-07-14] (Microsoft Corporation)
Task: {A1EB6991-6723-4EF7-B00E-8678C172482C} - System32\Tasks\McAfee Remediation (Prepare) => C:\Program Files\Common Files\AV\McAfee Anti-Virus And Anti-Spyware\upgrade.exe [2015-06-01] (McAfee, Inc.)
Task: {A9F25D7D-A072-487C-92BF-D20FD1D8A562} - System32\Tasks\McAfee\McAfee Auto Maintenance Task Agent
Task: {CBAAE2F5-D401-4DE1-962D-793318B85051} - System32\Tasks\CLMLSvc_P2G8 => C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe [2013-03-04] (CyberLink)
Task: {D942E7FE-95AD-401B-8C4A-452B88907E67} - System32\Tasks\SystemToolsDailyTest => uaclauncher.exe
Task: {DFCD4933-85A5-4D71-89A2-39368531817C} - System32\Tasks\Dell\Dell Product Registration Update => C:\Program Files (x86)\Dell Product Registration\prodreg.exe [2014-04-01] (Aviata Inc)
Task: {E74CB2C7-C446-4C6D-88D1-0B0FA8BB63F7} - System32\Tasks\Dell\Dell Product Registration => C:\Program Files (x86)\Dell Product Registration\prodreg.exe [2014-04-01] (Aviata Inc)
Task: {F10CC3CD-11B6-46AC-971D-912690CBD228} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2015-07-14] (Microsoft Corporation)
Task: {F255D1A4-505C-43DC-8A47-3FD5EC265EA9} - System32\Tasks\CLVDLauncher => C:\Program Files (x86)\CyberLink\Power2Go8\CLVDLauncher.exe [2013-03-22] (CyberLink Corp.)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Loaded Modules (Whitelisted) ==============
2015-02-15 07:41 - 2014-01-07 18:48 - 00117536 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2014-06-03 14:46 - 2014-06-03 14:46 - 00049408 _____ () C:\Program Files\WIDCOMM\Bluetooth Software\btwleapi.dll
2015-06-07 12:29 - 2014-05-20 09:19 - 00105640 _____ () C:\Program Files\Microsoft Office 15\ClientX64\ApiClient.dll
2015-06-09 06:14 - 2015-06-09 06:14 - 08898720 _____ () C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\1033\GrooveIntlResource.dll
2014-09-02 13:40 - 2014-09-02 13:40 - 00462160 _____ () C:\Program Files (x86)\Dropbox\DropboxOEM\DropboxOEM.exe
2014-01-17 12:06 - 2014-01-17 12:06 - 00174368 _____ () C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe
2015-06-22 09:40 - 2015-05-19 19:26 - 00107256 _____ () C:\Program Files\Dell\SupportAssist\libCSharpCommonCS.dll
2015-06-22 09:40 - 2015-05-19 19:26 - 00553720 _____ () C:\Program Files\Dell\SupportAssist\libAsapiCSharp.dll
2014-02-19 20:51 - 2014-02-19 20:51 - 01241560 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll
2015-06-09 06:14 - 2015-06-09 06:14 - 00316576 _____ () C:\Program Files\Microsoft Office 15\Root\VFS\ProgramFilesCommonX86\Microsoft Shared\OFFICE15\AppVIsvStream32.dll
2014-09-02 13:40 - 2014-09-02 13:40 - 00214352 _____ () C:\Program Files (x86)\Dropbox\DropboxOEM\Ledger.dll
2014-09-02 13:40 - 2014-09-02 13:40 - 00114000 _____ () C:\Program Files (x86)\Dropbox\DropboxOEM\zlib1.dll
2015-06-09 06:12 - 2015-06-09 06:12 - 00316576 _____ () C:\Program Files\Microsoft Office 15\root\office15\AppVIsvStream32.dll
2015-06-28 11:45 - 2015-06-16 08:08 - 01032360 _____ () C:\Program Files\Microsoft Office 15\Root\Office15\ADDINS\UmOutlookAddin.dll
2015-02-15 07:51 - 2013-03-04 21:40 - 00626240 _____ () C:\Program Files (x86)\CyberLink\Power2Go8\CLMediaLibrary.dll
2013-03-05 13:41 - 2013-03-05 13:41 - 00015424 _____ () C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvcPS.dll
2015-02-26 10:07 - 2015-02-09 09:14 - 01905904 _____ () C:\Program Files (x86)\Dell Backup and Recovery\Components\Restore\STRestoreAPI.dll
2015-02-15 07:59 - 2012-11-26 01:19 - 01153384 _____ () C:\Program Files (x86)\Dell Backup and Recovery\Components\Restore\libxml2.dll
2015-02-26 10:07 - 2014-02-18 12:12 - 00117568 _____ () C:\Program Files (x86)\Dell Backup and Recovery\Components\Restore\zlib1.dll
2014-01-17 12:06 - 2014-01-17 12:06 - 00041248 _____ () C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\win32api.pyd
2014-01-17 12:06 - 2014-01-17 12:06 - 00059680 _____ () C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\pywintypes27.dll
2014-01-17 12:06 - 2014-01-17 12:06 - 00119072 _____ () C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\pythoncom27.dll
2014-01-17 12:06 - 2014-01-17 12:06 - 00562464 _____ () C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\urlmon.dll
2014-01-17 12:06 - 2014-01-17 12:06 - 00401184 _____ () C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iertutil.dll
2014-01-17 12:06 - 2014-01-17 12:06 - 00411936 _____ () C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\WININET.dll
2014-01-17 12:07 - 2014-01-17 12:07 - 00020256 _____ () C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\_multiprocessing.pyd
2014-01-17 12:06 - 2014-01-17 12:06 - 00025376 _____ () C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\win32service.pyd
2014-01-17 12:06 - 2014-01-17 12:06 - 00022816 _____ () C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\servicemanager.pyd
2014-01-17 12:06 - 2014-01-17 12:06 - 00018208 _____ () C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\win32event.pyd
2014-01-17 12:07 - 2014-01-17 12:07 - 00027424 _____ () C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\_socket.pyd
2014-01-17 12:07 - 2014-01-17 12:07 - 00277280 _____ () C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\_ssl.pyd
2014-01-17 12:07 - 2014-01-17 12:07 - 00113952 _____ () C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\_hashlib.pyd
2014-01-17 12:06 - 2014-01-17 12:06 - 00016672 _____ () C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\select.pyd
2014-01-17 12:07 - 2014-01-17 12:07 - 00040736 _____ () C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\_ctypes.pyd
2014-01-17 12:06 - 2014-01-17 12:06 - 00336160 _____ () C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\_bsddb.pyd
2014-01-17 12:06 - 2014-01-17 12:06 - 00023328 _____ () C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\win32process.pyd
2014-01-17 12:06 - 2014-01-17 12:06 - 00020256 _____ () C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\win32ts.pyd
2014-01-17 12:06 - 2014-01-17 12:06 - 00018720 _____ () C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\win32profile.pyd
2014-01-17 12:06 - 2014-01-17 12:06 - 00042784 _____ () C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\win32security.pyd
2014-01-17 12:06 - 2014-01-17 12:06 - 00023328 _____ () C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\win32evtlog.pyd
2014-01-17 12:06 - 2014-01-17 12:06 - 00024864 _____ () C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\win32inet.pyd
2014-01-17 12:06 - 2014-01-17 12:06 - 00021280 _____ () C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\EnvironmentID.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
AlternateDataStreams: C:\Users\Andrew\OneDrive:ms-properties
==================== Safe Mode (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McNaiAnn => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeaack => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeaack.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeavfk => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeavfk.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefire => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfemms => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfetdi2k => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfetdi2k.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfevtp => ""="Service"
==================== EXE Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-4210094547-1222425090-1366728247-1001\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Theme2\img12.jpg
DNS Servers: 192.168.1.254 - [removed]
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
(Currently there is no automatic fix for this section.)
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [{E6D7E9DE-4FCD-42EA-9CF8-E6F57173D743}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDirector10\PDR10.EXE
FirewallRules: [{6527391A-1693-464A-BE37-1A7AABC333D2}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\Movie\PowerDVD Cinema\PowerDVDCinema12.exe
FirewallRules: [{DBD8F6C8-7009-4087-B551-2021422CDCD6}] => (Allow) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
FirewallRules: [{D73D7302-9422-4CD5-A767-535510D3CF0E}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\outlook.exe
FirewallRules: [{E96FAFA3-D956-4B4E-8CC6-2E5F629CADE5}] => (Allow) C:\Users\Andrew\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (09/12/2015 05:28:58 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: PC-DOWNSTAIRS)
Description: Activation of app microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1 failed with error: -2144927141 See the Microsoft-Windows-TWinUI/Operational log for additional information.
Error: (09/12/2015 05:28:58 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: PC-DOWNSTAIRS)
Description: Activation of app microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1 failed with error: -2144927141 See the Microsoft-Windows-TWinUI/Operational log for additional information.
Error: (09/10/2015 09:26:14 PM) (Source: Application) (EventID: 0) (User: )
Description: OpenService failed: The specified service does not exist as an installed service
Error: (09/09/2015 09:50:40 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: hpzscr40.EXE, version: 10.0.0.76, time stamp: 0x473001c2
Faulting module name: ntdll.dll, version: 6.3.9600.17936, time stamp: 0x55a68e0c
Exception code: 0xc00000fd
Fault offset: 0x0000000000053c4f
Faulting process id: 0x26f8
Faulting application start time: 0xhpzscr40.EXE0
Faulting application path: hpzscr40.EXE1
Faulting module path: hpzscr40.EXE2
Report Id: hpzscr40.EXE3
Faulting package full name: hpzscr40.EXE4
Faulting package-relative application ID: hpzscr40.EXE5
Error: (09/09/2015 09:47:44 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: DrvInst.exe, version: 6.3.9600.17415, time stamp: 0x54505373
Faulting module name: hppdpr12_x64.DLL, version: 2.0.0.9, time stamp: 0x477e9d5b
Exception code: 0xc000000d
Fault offset: 0x0000000000008f44
Faulting process id: 0x1e38
Faulting application start time: 0xDrvInst.exe0
Faulting application path: DrvInst.exe1
Faulting module path: DrvInst.exe2
Report Id: DrvInst.exe3
Faulting package full name: DrvInst.exe4
Faulting package-relative application ID: DrvInst.exe5
Error: (09/09/2015 09:28:31 PM) (Source: Perflib) (EventID: 1023) (User: )
Description: rdyboost4
Error: (09/06/2015 09:30:52 AM) (Source: Microsoft-Windows-LocationProvider) (EventID: 2006) (User: NT AUTHORITY)
Description: There was an error with the Windows Location Provider database
Error: (09/05/2015 06:27:48 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program WWAHost.exe version 6.3.9600.17415 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
Process ID: 1e4c
Start Time: 01d0e83a749a1385
Termination Time: 15
Application Path: C:\Windows\System32\WWAHost.exe
Report Id: 17c0acee-542e-11e5-8264-acd1b8cbcae2
Faulting package full name: winstore_1.0.0.0_neutral_neutral_cw5n1h2txyewy
Faulting package-relative application ID: Windows.Store
Error: (08/26/2015 12:11:02 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: McSACore.exe, version: 4.0.1.124, time stamp: 0x55c0d68f
Faulting module name: saupkeep.dll_unloaded, version: 4.0.1.124, time stamp: 0x55c0d682
Exception code: 0xc0000005
Fault offset: 0x00000000000af1b6
Faulting process id: 0x2638
Faulting application start time: 0xMcSACore.exe0
Faulting application path: McSACore.exe1
Faulting module path: McSACore.exe2
Report Id: McSACore.exe3
Faulting package full name: McSACore.exe4
Faulting package-relative application ID: McSACore.exe5
Error: (08/12/2015 02:37:47 PM) (Source: Microsoft-Windows-LocationProvider) (EventID: 2006) (User: NT AUTHORITY)
Description: There was an error with the Windows Location Provider database
System errors:
=============
Error: (09/12/2015 05:42:00 AM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The Interactive Services Detection service terminated with the following error:
%%1
Error: (09/12/2015 05:28:53 AM) (Source: DCOM) (EventID: 10010) (User: PC-DOWNSTAIRS)
Description: Microsoft.WindowsLive.Mail.AppXj3e9v0xw9sf8t58nqr15tqqb2yq4zsfg.mca
Error: (09/12/2015 05:28:53 AM) (Source: DCOM) (EventID: 10010) (User: PC-DOWNSTAIRS)
Description: Microsoft.WindowsLive.Mail.AppXj3e9v0xw9sf8t58nqr15tqqb2yq4zsfg.mca
Error: (09/09/2015 05:35:50 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x80240020: Upgrade to Windows 10 Home.
Error: (09/08/2015 08:31:53 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 10. The Windows SChannel error state is 10.
Error: (09/08/2015 08:31:53 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 10. The Windows SChannel error state is 10.
Error: (09/08/2015 03:19:24 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x80240020: Upgrade to Windows 10 Home.
Error: (09/07/2015 07:18:03 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x80240020: Upgrade to Windows 10 Home.
Error: (09/07/2015 12:07:10 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x80240020: Upgrade to Windows 10 Home.
Error: (09/06/2015 10:11:50 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The McAfee Boot Delay Start Service service failed to start due to the following error:
%%1053
Microsoft Office:
=========================
Error: (09/12/2015 05:28:58 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: PC-DOWNSTAIRS)
Description: microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1-2144927141
Error: (09/12/2015 05:28:58 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: PC-DOWNSTAIRS)
Description: microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1-2144927141
Error: (09/10/2015 09:26:14 PM) (Source: Application) (EventID: 0) (User: )
Description: OpenService failed: The specified service does not exist as an installed service
Error: (09/09/2015 09:50:40 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: hpzscr40.EXE10.0.0.76473001c2ntdll.dll6.3.9600.1793655a68e0cc00000fd0000000000053c4f26f801d0eb7bb5939c21C:\PROGRA~3\HP\INSTAL~1\Temp\hpzscr40.EXEC:\Windows\SYSTEM32\ntdll.dll19dfcbb4-576f-11e5-8264-acd1b8cbcae2
Error: (09/09/2015 09:47:44 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: DrvInst.exe6.3.9600.1741554505373hppdpr12_x64.DLL2.0.0.9477e9d5bc000000d0000000000008f441e3801d0eb7b47b197d2C:\Windows\system32\DrvInst.exeC:\Windows\system32\hppdpr12_x64.DLLb0eeea5c-576e-11e5-8264-acd1b8cbcae2
Error: (09/09/2015 09:28:31 PM) (Source: Perflib) (EventID: 1023) (User: )
Description: rdyboost4
Error: (09/06/2015 09:30:52 AM) (Source: Microsoft-Windows-LocationProvider) (EventID: 2006) (User: NT AUTHORITY)
Description: -2147024883
Error: (09/05/2015 06:27:48 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: WWAHost.exe6.3.9600.174151e4c01d0e83a749a138515C:\Windows\System32\WWAHost.exe17c0acee-542e-11e5-8264-acd1b8cbcae2winstore_1.0.0.0_neutral_neutral_cw5n1h2txyewyWindows.Store
Error: (08/26/2015 12:11:02 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: McSACore.exe4.0.1.12455c0d68fsaupkeep.dll_unloaded4.0.1.12455c0d682c000000500000000000af1b6263801d0dd81616b64b9C:\Program Files (x86)\McAfee\SiteAdvisor\McSACore.exesaupkeep.dllcf05fda5-4c1d-11e5-8263-acd1b8cbcae2
Error: (08/12/2015 02:37:47 PM) (Source: Microsoft-Windows-LocationProvider) (EventID: 2006) (User: NT AUTHORITY)
Description: -2147024883
==================== Memory info ===========================
Processor: Intel(R) Core(TM) i5-4460 CPU @ 3.20GHz
Percentage of memory in use: 34%
Total physical RAM: 8143.21 MB
Available physical RAM: 5364.12 MB
Total Virtual: 9423.21 MB
Available Virtual: 5843.57 MB
==================== Drives ================================
Drive c: (OS) (Fixed) (Total:921.72 GB) (Free:873.91 GB) NTFS
Drive i: () (Removable) (Total:1.81 GB) (Free:1.81 GB) FAT32
Drive k: (ESP) (Fixed) (Total:0.48 GB) (Free:0.43 GB) FAT32
Drive x: (WINRETOOLS) (Fixed) (Total:0.73 GB) (Free:0.45 GB) NTFS
Drive y: (PBR Image) (Fixed) (Total:8.4 GB) (Free:0.73 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: 5D302944)
Partition: GPT.
========================================================
Disk: 1 (Size: 1.8 GB) (Disk ID: 01CF0A93)
Partition 1: (Active) - (Size=1.8 GB) - (Type=0B)
==================== End of Addition.txt ============================