Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 02-08-2014
Ran by Lawry Lsw (administrator) on ROYAL on 06-08-2014 01:22:38
Running from C:\Users\Lawrence\Desktop
Platform: Windows 8.1 Single Language (X64) OS Language: English (United States)
Internet Explorer Version 11
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: [url=http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/]Downloading Farbar Recovery Scan Tool[/url]
Download link for 64-Bit Version: [url=http://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/]Downloading Farbar Recovery Scan Tool[/url]
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: [url=http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/]FRST Tutorial - How to use Farbar Recovery Scan Tool - Malware Removal Guides and Tutorials[/url]
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Windows (R) Win 7 DDK provider) C:\Program Files (x86)\Bluetooth Suite\AdminService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
(Hi-Rez Studios) C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe
(McAfee, Inc.) C:\Windows\System32\mfevtps.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
() C:\Program Files (x86)\Lenovo\Lenovo VeriFace\VfConnectorService.exe
(Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
(McAfee, Inc.) C:\Program Files\mcafee\MSC\McAPExe.exe
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\AMCore\mcshield.exe
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\SystemCore\mfefire.exe
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\Platform\McSvcHost\McSvHost.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17200_none_fa7026dd9b04586e\TiWorker.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
() C:\Program Files (x86)\Garena Plus\ggdllhost.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Qualcomm®Atheros®) C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe
(Realtek semiconductor) C:\Windows\RTFTrack.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
() C:\Program Files (x86)\Bluetooth Suite\ActivateDesktop.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDIntelligent.exe
() C:\Windows\SysWOW64\UMonit64.exe
(Lenovo) C:\Program Files\Lenovo\Onekey Theater\OnekeyStudio.exe
(Lenovo (Beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe
(Lenovo(beijing) Limited) C:\Program Files (x86)\Lenovo\Energy Management\utility.exe
() C:\Program Files (x86)\Garena Plus\GarenaMessenger.exe
(Akamai Technologies, Inc.) C:\Users\Lawrence\AppData\Local\Akamai\netsession_win.exe
(Akamai Technologies, Inc.) C:\Users\Lawrence\AppData\Local\Akamai\netsession_win.exe
(CyberLink Corp.) C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\Platform\McUICnt.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\root\office15\msosync.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(McAfee, Inc.) C:\Program Files (x86)\McAfee\SiteAdvisor\saUI.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil_ActiveX.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtsFT] => C:\WINDOWS\RTFTrack.exe [6346312 2013-03-15] (Realtek semiconductor)
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2891592 2013-05-17] (ELAN Microelectronics Corp.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13545032 2013-05-28] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1308232 2013-05-20] (Realtek Semiconductor)
HKLM\...\Run: [Nvtmru] => "C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe"
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [286704 2013-05-01] (Intel Corporation)
HKLM\...\Run: [UMonit64] => C:\windows\SysWOW64\UMonit64.exe [40960 2013-04-09] ()
HKLM\...\Run: [OnekeyStudio] => C:\Program Files\Lenovo\Onekey Theater\OnekeyStudio.exe [4196432 2012-09-15] (Lenovo)
HKLM\...\Run: [Energy Management] => C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe [17097200 2013-10-12] (Lenovo (Beijing) Limited)
HKLM\...\Run: [EnergyUtility] => C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe [193008 2013-10-12] (Lenovo(beijing) Limited)
HKLM\...\Run: [ShadowPlay] => C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2403104 2014-07-25] (NVIDIA Corporation)
HKLM-x32\...\Run: [YouCam Tray] => C:\Program Files (x86)\Lenovo\YouCam\YouCamTray.exe [168464 2012-10-31] (CyberLink Corp.)
HKLM-x32\...\Run: [UpdateP2GShortCut] => C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe [217088 2012-04-19] (CyberLink Corp.)
HKLM-x32\...\Run: [RemoteControl10] => C:\Program Files (x86)\Lenovo\PowerDVD10\PDVD10Serv.exe [95192 2013-03-09] (CyberLink Corp.)
HKLM-x32\...\Run: [mcui_exe] => C:\Program Files\McAfee.com\Agent\mcagent.exe [537992 2014-04-25] (McAfee, Inc.)
HKLM-x32\...\Run: [Intel AppUp(SM) center] => C:\Program Files (x86)\Intel\IntelAppStore\bin\ismagent.exe [155488 2012-07-12] (Intel Corporation)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-22] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43816 2014-07-03] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-07-08] (Apple Inc.)
HKLM-x32\...\Run: [Aeria Ignite] => C:\Program Files (x86)\Aeria Games\Ignite\aeriaignite.exe [1925656 2013-06-07] (Aeria Games & Entertainment)
HKLM-x32\...\Run: [mcpltui_exe] => C:\Program Files\McAfee.com\Agent\mcagent.exe [537992 2014-04-25] (McAfee, Inc.)
Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
HKLM\...\Policies\Explorer\Run: [BtvStack] => C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [132736 2013-06-14] ( (Qualcomm®Atheros®))
HKLM\...\Policies\Explorer: [NoControlPanel] 0
HKLM\...\Policies\Explorer: [NoFolderOptions] 0
HKU\S-1-5-21-450748458-2682401420-2043914554-1002\...\Run: [GarenaPlus] => C:\Program Files (x86)\Garena Plus\GarenaMessenger.exe [9940272 2014-07-24] ()
HKU\S-1-5-21-450748458-2682401420-2043914554-1002\...\Run: [Akamai NetSession Interface] => C:\Users\Lawrence\AppData\Local\Akamai\netsession_win.exe [4672920 2014-04-17] (Akamai Technologies, Inc.)
AppInit_DLLs: C:\windows\system32\nvinitx.dll => C:\windows\system32\nvinitx.dll [166568 2014-07-03] (NVIDIA Corporation)
AppInit_DLLs: , C:\WINDOWS\system32\nvinitx.dll => C:\WINDOWS\system32\nvinitx.dll [166568 2014-07-03] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\WINDOWS\SysWOW64\nvinit.dll => C:\WINDOWS\SysWOW64\nvinit.dll [146480 2014-07-03] (NVIDIA Corporation)
ShellIconOverlayIdentifiers: SkyDrive1 -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File
ShellIconOverlayIdentifiers: SkyDrive2 -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File
ShellIconOverlayIdentifiers: SkyDrive3 -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File
ShellIconOverlayIdentifiers: SkyDrivePro1 (ErrorConflict) -> {8BA85C75-763B-4103-94EB-9470F12FE0F7} => C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
ShellIconOverlayIdentifiers: SkyDrivePro2 (SyncInProgress) -> {CD55129A-B1A1-438E-A425-CEBC7DC684EE} => C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
ShellIconOverlayIdentifiers: SkyDrivePro3 (InSync) -> {E768CD3B-BDDC-436D-9C13-E1B39CA257B1} => C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
ShellIconOverlayIdentifiers: SugarSyncBackedUp -> {0C4A258A-3F3B-4FFF-80A7-9B3BEC139472} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll (SugarSync, Inc.)
ShellIconOverlayIdentifiers: SugarSyncPending -> {62CCD8E3-9C21-41E1-B55E-1E26DFC68511} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll (SugarSync, Inc.)
ShellIconOverlayIdentifiers: SugarSyncRoot -> {A759AFF6-5851-457D-A540-F4ECED148351} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll (SugarSync, Inc.)
ShellIconOverlayIdentifiers: SugarSyncShared -> {1574C9EF-7D58-488F-B358-8B78C1538F51} => C:\Program Files (x86)\SugarSync\SugarSyncShellExt_x64.dll (SugarSync, Inc.)
ShellIconOverlayIdentifiers-x32: SkyDrive1 -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File
ShellIconOverlayIdentifiers-x32: SkyDrive2 -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File
ShellIconOverlayIdentifiers-x32: SkyDrive3 -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File
GroupPolicy: Group Policy on Chrome detected <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = [url=http://www.lenovo.com]Buy Computers Laptops & Tablets | For Those Who Do | Lenovo US[/url]
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [url=http://www.lenovo.com]Buy Computers Laptops & Tablets | For Those Who Do | Lenovo US[/url]
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
SearchScopes: HKLM - {F5FFD1E6-0FCD-4151-BFDF-6614F1963A57} URL = [url=http://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=LCJB]{searchTerms} - Bing[/url]
SearchScopes: HKLM-x32 - {F5FFD1E6-0FCD-4151-BFDF-6614F1963A57} URL = [url=http://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=LCJB]{searchTerms} - Bing[/url]
SearchScopes: HKCU - DefaultScope {309451D7-0DA0-4ECE-88EF-91992B0EA7DE} URL = [url=http://search.findwide.com/serp?guid={310C0A6B-B0D4-40AD-A231-1435A9325B38}&action=default_search&k={searchTerms]{searchTerms - Search Results[/url]}
SearchScopes: HKCU - {309451D7-0DA0-4ECE-88EF-91992B0EA7DE} URL = [url=http://search.findwide.com/serp?guid={310C0A6B-B0D4-40AD-A231-1435A9325B38}&action=default_search&k={searchTerms]{searchTerms - Search Results[/url]}
SearchScopes: HKCU - {7C0CC4AC-40DF-4CFC-BBED-5DE5FBC4BF27} URL = [url=http://search.yahoo.com/search?p={searchTerms}&fr=tightropetb&type=10953]{searchTerms} - Yahoo Search Results[/url]
SearchScopes: HKCU - {F5FFD1E6-0FCD-4151-BFDF-6614F1963A57} URL =
SearchScopes: HKCU - {FCEAC75E-3562-4E41-88A1-6E2A5FB49358} URL = [url=http://search.yahoo.com/search?fr=mcafee&type=A011US714&p={SearchTerms]{SearchTerms - Yahoo Search Results[/url]}
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO: McAfee SiteAdvisor BHO -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: ArcPluginIEBHO Class -> {84BFE29A-8139-402a-B2A4-C23AE9E1A75F} -> C:\Program Files (x86)\Perfect World Entertainment\Arc\Plugins\ArcPluginIE.dll (Perfect World Entertainment Inc)
BHO-x32: McAfee SiteAdvisor BHO -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
Toolbar: HKLM - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
Toolbar: HKLM - FindWide Toolbar - {1F7C99AC-F766-4BA8-96DB-380BD5DE6A65} - C:\Program Files (x86)\TNT2\Profiles\10953\passport64.dll No File
Toolbar: HKLM-x32 - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
Toolbar: HKCU - FindWide Toolbar - {1F7C99AC-F766-4BA8-96DB-380BD5DE6A65} - C:\Program Files (x86)\TNT2\Profiles\10953\passport64.dll No File
DPF: HKLM-x32 {6A060448-60F9-11D5-A6CD-0002B31F7455}
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
Handler-x32: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL (Microsoft Corporation)
Handler-x32: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\mcafee\MSC\McSnIePl64.dll (McAfee, Inc.)
Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\MSC\McSnIePl.dll (McAfee, Inc.)
Tcpip\Parameters: [DhcpNameServer] 10.0.0.138
FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_14_0_0_145.dll ()
FF Plugin: @mcafee.com/MSC,version=10 -> c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL ()
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_145.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=3.5.29 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @mcafee.com/MSC,version=10 -> c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL ()
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin-x32: @perfectworld.com/npArcPlayNowPlugin -> C:\Program Files (x86)\Perfect World Entertainment\Arc\Plugins\npArcPluginFF.dll (Perfect World Entertainment Inc)
FF Plugin-x32: @t.garena.com/garenatalk -> C:\Program Files (x86)\Garena Plus\bbtalk\plugins\npPlugin\npGarenaTalkPlugin.dll ( Garena)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
FF Plugin HKCU: [URL="http://www.exent.com/GameTreatWidget"]www.exent.com/GameTreatWidget[/URL] - C:\Program Files (x86)\Free Ride Games\npGameTreatWidget.dll No File
FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor
FF Extension: McAfee SiteAdvisor - C:\Program Files (x86)\McAfee\SiteAdvisor [2014-07-20]
FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK
FF Extension: McAfee Anti-Spam Thunderbird Extension - C:\Program Files\McAfee\MSK [2014-07-20]
Chrome:
=======
CHR HomePage:
CHR Extension: (Google Docs) - C:\Users\Lawrence\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-11-02]
CHR Extension: (Google Drive) - C:\Users\Lawrence\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-11-02]
CHR Extension: (YouTube) - C:\Users\Lawrence\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-11-02]
CHR Extension: (Google Search) - C:\Users\Lawrence\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-11-02]
CHR Extension: (Peter Bjorn and John) - C:\Users\Lawrence\AppData\Local\Google\Chrome\User Data\Default\Extensions\dmemmjoiahegfgfcenggecfhoedchfdl [2014-05-08]
CHR Extension: (SiteAdvisor) - C:\Users\Lawrence\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2013-11-27]
CHR Extension: (AdBlock) - C:\Users\Lawrence\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2013-11-02]
CHR Extension: (Google Wallet) - C:\Users\Lawrence\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-11-02]
CHR Extension: (Gmail) - C:\Users\Lawrence\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-11-02]
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S3 ArcService; C:\Program Files (x86)\Perfect World Entertainment\Arc\ArcService.exe [88400 2014-06-12] (Perfect World Entertainment Inc)
R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [312448 2013-06-14] (Windows (R) Win 7 DDK provider)
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2356912 2014-07-19] (Microsoft Corporation)
R2 HiPatchService; C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe [9216 2014-07-19] (Hi-Rez Studios) [File not signed]
R2 HomeNetSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15344 2013-05-01] (Intel Corporation)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [731648 2013-02-14] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [820184 2013-02-14] (Intel(R) Corporation)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [131544 2013-05-16] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-05-16] (Intel Corporation)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation)
R2 McAfee SiteAdvisor Service; C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [200728 2012-05-11] (McAfee, Inc.)
R2 McAPExe; C:\Program Files\McAfee\MSC\McAPExe.exe [178528 2014-04-25] (McAfee, Inc.)
R2 McMPFSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
R2 McNaiAnn; C:\Program Files\Common Files\mcafee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
S3 McODS; C:\Program Files\mcafee\VirusScan\mcods.exe [603424 2014-06-12] (McAfee, Inc.)
R2 mcpltsvc; C:\Program Files\Common Files\mcafee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
R2 McProxy; C:\Program Files\Common Files\mcafee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
R2 mfecore; C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe [1041192 2014-06-18] (McAfee, Inc.)
R2 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [219752 2014-06-20] (McAfee, Inc.)
R2 mfevtp; C:\WINDOWS\system32\mfevtps.exe [189912 2014-06-20] (McAfee, Inc.)
R2 MSK80Service; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1720608 2014-07-25] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [18956064 2014-07-25] (NVIDIA Corporation)
R2 VeriFaceSrv; C:\Program Files (x86)\Lenovo\Lenovo VeriFace\VfConnectorService.exe [68368 2013-10-12] ()
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347880 2014-03-24] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2014-03-24] (Microsoft Corporation)
R2 ZAtheros Bt and Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [323584 2013-06-14] (Atheros) [File not signed]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S3 BTATH_LWFLT; C:\Windows\system32\DRIVERS\btath_lwflt.sys [77464 2013-06-14] (Qualcomm Atheros)
S3 BthLEEnum; C:\Windows\System32\drivers\BthLEEnum.sys [226304 2013-12-05] (Microsoft Corporation)
R3 cfwids; C:\Windows\System32\drivers\cfwids.sys [72128 2014-06-20] (McAfee, Inc.)
R3 ETDSMBus; C:\Windows\system32\DRIVERS\ETDSMBus.sys [22280 2013-05-16] (ELAN Microelectronic Corp.)
S3 HipShieldK; C:\Windows\System32\drivers\HipShieldK.sys [197704 2013-09-23] (McAfee, Inc.)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [122584 2014-08-06] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2014-05-12] (Malwarebytes Corporation)
R3 mfeapfk; C:\Windows\System32\drivers\mfeapfk.sys [181704 2014-06-20] (McAfee, Inc.)
R3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [313544 2014-06-20] (McAfee, Inc.)
S0 mfeelamk; C:\Windows\System32\drivers\mfeelamk.sys [70600 2014-06-20] (McAfee, Inc.)
R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [523792 2014-06-20] (McAfee, Inc.)
R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [786296 2014-06-20] (McAfee, Inc.)
R3 mfencbdc; C:\Windows\system32\DRIVERS\mfencbdc.sys [444720 2014-06-18] (McAfee, Inc.)
S3 mfencrk; C:\Windows\system32\DRIVERS\mfencrk.sys [96592 2014-06-18] (McAfee, Inc.)
R0 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [348552 2014-06-20] (McAfee, Inc.)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [20256 2014-07-25] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [40392 2014-04-01] (NVIDIA Corporation)
R3 rtsuvc; C:\Windows\system32\DRIVERS\rtsuvc.sys [8243272 2013-03-15] (Realtek Semiconductor Corp.)
S3 USBAAPL64; C:\Windows\System32\Drivers\usbaapl64.sys [54784 2012-12-13] (Apple, Inc.) [File not signed]
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [123224 2014-03-24] (Microsoft Corporation)
S3 wsvd; C:\Windows\system32\DRIVERS\wsvd.sys [102376 2012-06-14] ("CyberLink)
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-08-06 01:22 - 2014-08-06 01:22 - 00000000 ____D () C:\Users\Lawrence\Desktop\FRST-OlderVersion
2014-08-06 01:16 - 2014-08-06 01:16 - 00001624 _____ () C:\Users\Lawrence\Desktop\JRT.txt
2014-08-06 01:11 - 2014-08-06 01:11 - 00004222 _____ () C:\Users\Lawrence\Desktop\AdwCleaner[S0].txt
2014-08-06 01:10 - 2014-08-06 01:10 - 00000000 ____D () C:\WINDOWS\ERUNT
2014-08-06 01:08 - 2014-08-06 01:08 - 01016261 _____ (Thisisu) C:\Users\Lawrence\Desktop\JRT.exe
2014-08-06 01:02 - 2014-08-06 01:02 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
2014-08-06 01:01 - 2014-08-06 01:21 - 00122584 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2014-08-06 01:00 - 2014-08-06 01:00 - 00001125 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-08-06 01:00 - 2014-08-06 01:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-08-06 01:00 - 2014-08-06 01:00 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-08-06 01:00 - 2014-08-06 01:00 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-08-06 01:00 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2014-08-06 01:00 - 2014-05-12 07:26 - 00064216 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
2014-08-06 01:00 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2014-08-06 00:51 - 2014-08-06 00:52 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Lawrence\Desktop\mbam-setup-2.0.2.1012.exe
2014-08-06 00:51 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\WINDOWS\SysWOW64\sqlite3.dll
2014-08-06 00:50 - 2014-08-06 00:55 - 00000000 ____D () C:\AdwCleaner
2014-08-06 00:49 - 2014-08-06 00:50 - 01361309 _____ () C:\Users\Lawrence\Desktop\AdwCleaner.exe
2014-08-05 22:35 - 2014-08-05 22:35 - 00000000 ____D () C:\Users\Lawrence\AppData\Local\Blizzard
2014-08-05 22:19 - 2014-08-05 22:19 - 00000000 ____D () C:\Users\Lawrence\Documents\Downloaded Videos Movie
2014-08-05 22:10 - 2014-08-05 22:21 - 00000000 ____D () C:\Users\Lawrence\AppData\Local\Maxiget
2014-08-05 22:10 - 2014-08-05 22:14 - 00000258 __RSH () C:\ProgramData\ntuser.pol
2014-08-05 22:10 - 2014-08-05 22:10 - 00000000 ____D () C:\Users\Lawrence\AppData\Local\MaxiGet Download Manager
2014-08-05 22:02 - 2014-08-05 23:45 - 00000000 ____D () C:\Program Files (x86)\Hearthstone
2014-08-05 22:02 - 2014-08-05 22:02 - 00001218 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HearthstoneHearthstone.lnk
2014-08-05 22:02 - 2014-08-05 22:02 - 00001172 _____ () C:\Users\Public\Desktop\Hearthstone.lnk
2014-08-05 22:02 - 2014-08-05 22:02 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hearthstone
2014-08-05 19:23 - 2014-08-05 19:23 - 00000000 ____D () C:\ProgramData\HipSoft
2014-08-05 19:19 - 2014-08-05 19:19 - 00000064 _____ () C:\WINDOWS\GPlrLanc.dat
2014-08-05 19:17 - 2014-08-05 22:15 - 00000000 ____D () C:\Users\Lawrence\AppData\Local\StormAlerts
2014-07-31 01:08 - 2014-07-31 01:08 - 00000000 ____D () C:\WINDOWS\SysWOW64\NV
2014-07-31 01:08 - 2014-07-31 01:08 - 00000000 ____D () C:\WINDOWS\system32\NV
2014-07-30 17:11 - 2014-07-30 17:11 - 00000000 ____D () C:\Program Files (x86)\AGEIA Technologies
2014-07-30 17:08 - 2014-07-03 06:48 - 31512520 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglv64.dll
2014-07-30 17:08 - 2014-07-03 06:48 - 24196896 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglv32.dll
2014-07-30 17:08 - 2014-07-03 06:48 - 22994208 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcompiler.dll
2014-07-30 17:08 - 2014-07-03 06:48 - 18626304 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvwgf2umx.dll
2014-07-30 17:08 - 2014-07-03 06:48 - 17555104 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvd3dumx.dll
2014-07-30 17:08 - 2014-07-03 06:48 - 16122344 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvwgf2um.dll
2014-07-30 17:08 - 2014-07-03 06:48 - 15294296 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcompiler.dll
2014-07-30 17:08 - 2014-07-03 06:48 - 13922752 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvopencl.dll
2014-07-30 17:08 - 2014-07-03 06:48 - 13835208 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll
2014-07-30 17:08 - 2014-07-03 06:48 - 12866008 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvlddmkm.sys
2014-07-30 17:08 - 2014-07-03 06:48 - 11283344 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvopencl.dll
2014-07-30 17:08 - 2014-07-03 06:48 - 11222048 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll
2014-07-30 17:08 - 2014-07-03 06:48 - 04247000 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll
2014-07-30 17:08 - 2014-07-03 06:48 - 03989960 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll
2014-07-30 17:08 - 2014-07-03 06:48 - 01890080 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6434052.dll
2014-07-30 17:08 - 2014-07-03 06:48 - 01539928 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6434052.dll
2014-07-30 17:08 - 2014-07-03 06:48 - 00944928 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll
2014-07-30 17:08 - 2014-07-03 06:48 - 00907096 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll
2014-07-30 17:08 - 2014-07-03 06:48 - 00903624 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll
2014-07-30 17:08 - 2014-07-03 06:48 - 00869152 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll
2014-07-30 17:08 - 2014-07-03 06:48 - 00502232 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll
2014-07-30 17:08 - 2014-07-03 06:48 - 00418760 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll
2014-07-30 17:08 - 2014-07-03 06:48 - 00391640 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFROpenGL.dll
2014-07-30 17:08 - 2014-07-03 06:48 - 00354016 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglshim64.dll
2014-07-30 17:08 - 2014-07-03 06:48 - 00348120 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFROpenGL.dll
2014-07-30 17:08 - 2014-07-03 06:48 - 00305600 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglshim32.dll
2014-07-30 17:08 - 2014-07-03 06:48 - 00032544 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvpciflt.sys
2014-07-30 16:15 - 2014-07-30 17:09 - 00000000 ____D () C:\WINDOWS\LastGood.Tmp
2014-07-30 16:15 - 2014-07-25 23:50 - 01715224 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspbridge64.dll
2014-07-30 16:15 - 2014-07-25 23:50 - 01291280 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspbridge.dll
2014-07-30 16:15 - 2014-04-01 02:42 - 00040392 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvvad64v.sys
2014-07-30 16:15 - 2014-04-01 02:42 - 00034760 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvaudcap32v.dll
2014-07-20 11:42 - 2014-08-06 01:02 - 00001871 _____ () C:\Users\Public\Desktop\McAfee Internet Security.lnk
2014-07-20 11:41 - 2014-07-20 11:41 - 00000000 ____D () C:\Program Files (x86)\McAfee.com
2014-07-20 11:41 - 2013-09-23 13:49 - 00197704 _____ (McAfee, Inc.) C:\WINDOWS\system32\Drivers\HipShieldK.sys
2014-07-20 11:40 - 2014-08-06 00:58 - 00000000 ____D () C:\Program Files (x86)\McAfee
2014-07-20 11:40 - 2014-07-20 11:40 - 00000000 ____D () C:\Program Files\McAfee.com
2014-07-20 11:35 - 2014-06-20 10:30 - 00189912 _____ (McAfee, Inc.) C:\WINDOWS\system32\mfevtps.exe
2014-07-20 11:07 - 2014-07-20 11:08 - 00000000 ____D () C:\ccbcdf3a6d8c10b8004fd3c5c5
2014-07-20 01:17 - 2014-07-20 01:18 - 00037817 _____ () C:\Users\Lawrence\Desktop\Addition.txt
2014-07-20 01:16 - 2014-08-06 01:22 - 00026138 _____ () C:\Users\Lawrence\Desktop\FRST.txt
2014-07-20 01:16 - 2014-08-06 01:22 - 00000000 ____D () C:\FRST
2014-07-20 01:15 - 2014-08-06 01:22 - 02094080 _____ (Farbar) C:\Users\Lawrence\Desktop\FRST64.exe
2014-07-19 18:46 - 2014-07-19 18:46 - 00003023 _____ () C:\Users\Lawrence\Desktop\HiJackThis.lnk
2014-07-19 18:46 - 2014-07-19 18:46 - 00000000 ____D () C:\Users\Lawrence\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis
2014-07-19 18:46 - 2014-07-19 18:46 - 00000000 ____D () C:\Program Files (x86)\Trend Micro
2014-07-19 18:14 - 2014-07-19 18:14 - 01402880 _____ () C:\Users\Lawrence\Desktop\HijackThis.msi
2014-07-19 14:42 - 2014-07-19 14:42 - 00000003 _____ () C:\WINDOWS\system32\HRUPPROG.EXIT
2014-07-19 14:42 - 2014-07-19 14:42 - 00000002 _____ () C:\WINDOWS\system32\HRUPPROG.TXT
2014-07-17 19:14 - 2014-07-17 19:14 - 00000000 ____D () C:\ProgramData\Riot Games
2014-07-17 18:44 - 2014-07-17 18:44 - 00688992 _____ (Swearware) C:\Users\Lawrence\Desktop\dds.com
2014-07-17 17:51 - 2014-07-17 18:04 - 00000000 _____ () C:\WINDOWS\system32\1
2014-07-16 23:54 - 2014-08-06 01:21 - 00004978 _____ () C:\WINDOWS\System32\Tasks\Microsoft Office 15 Sync Maintenance for ROYAL-Lawry Lsw Royal
2014-07-16 23:34 - 2014-07-16 23:32 - 04605016 _____ () C:\Users\Lawrence\Desktop\cbs.txt
2014-07-16 23:14 - 2014-07-16 23:14 - 00002464 _____ () C:\Users\Lawrence\Desktop\SFCFix.txt
2014-07-16 23:13 - 2014-07-16 23:13 - 01296920 _____ () C:\Users\Lawrence\Desktop\SFCFix.zip
2014-07-16 01:49 - 2014-07-16 23:12 - 00566784 _____ (niemiro) C:\Users\Lawrence\Desktop\SFCFix.exe
2014-07-16 01:42 - 2014-07-16 23:14 - 00000000 ____D () C:\Users\Lawrence\AppData\Local\niemiro
2014-07-16 01:42 - 2014-07-16 23:14 - 00000000 ____D () C:\SFCFix
2014-07-13 01:18 - 2014-07-13 01:18 - 00001052 _____ () C:\Users\Public\Desktop\Path of Exile.lnk
2014-07-13 01:13 - 2014-07-13 01:18 - 00000000 ____D () C:\Program Files (x86)\GarenaPoE
2014-07-12 16:15 - 2014-07-12 16:15 - 00000000 ____D () C:\Users\Lawrence\AppData\Local\Aeria Games
2014-07-12 16:14 - 2014-07-12 16:14 - 00000000 ____D () C:\ProgramData\Aeria Games
2014-07-12 16:12 - 2014-07-12 16:13 - 00000000 ___HD () C:\WINDOWS\msdownld.tmp
2014-07-12 16:12 - 2014-07-12 16:13 - 00000000 ____D () C:\WINDOWS\SysWOW64\directx
2014-07-12 16:12 - 2014-07-12 16:12 - 00001701 _____ () C:\Users\Lawrence\Desktop\Aura Kingdom.lnk
2014-07-12 16:00 - 2014-07-12 16:00 - 00002055 _____ () C:\Users\Public\Desktop\Aeria Ignite.lnk
2014-07-12 16:00 - 2014-07-12 16:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AeriaGames
2014-07-12 16:00 - 2014-07-12 16:00 - 00000000 ____D () C:\Program Files (x86)\Aeria Games
2014-07-12 15:03 - 2014-07-12 15:05 - 00000000 ____D () C:\Users\Lawrence\Documents\InfiniteCrisis
2014-07-12 15:03 - 2014-07-12 15:03 - 00000000 ____D () C:\Users\Lawrence\AppData\Local\InfiniteCrisis
2014-07-12 14:01 - 2014-07-12 14:01 - 00000000 ____D () C:\Users\Lawrence\AppData\Local\Turbine
2014-07-12 13:59 - 2014-07-12 15:00 - 00000000 ____D () C:\Program Files (x86)\InfiniteCrisis
2014-07-12 13:59 - 2014-07-12 13:59 - 00001107 _____ () C:\Users\Public\Desktop\InfiniteCrisis.lnk
2014-07-12 13:59 - 2014-07-12 13:59 - 00000000 ____D () C:\ProgramData\Turbine
2014-07-12 13:59 - 2014-07-12 13:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Infinite Crisis
2014-07-12 13:49 - 2014-07-12 13:53 - 140770440 _____ () C:\Users\Lawrence\Downloads\InfiniteCrisis-GLOBAL_Setup.exe
2014-07-12 13:47 - 2014-07-12 13:47 - 00000000 ____D () C:\Users\Lawrence\AppData\Local\Akamai
2014-07-12 12:58 - 2014-07-12 16:00 - 00000000 ____D () C:\AeriaGames
2014-07-12 12:57 - 2014-07-12 12:57 - 00581656 _____ (Aeria Games & Entertainment) C:\Users\Lawrence\Downloads\aurakingdom_us_downloader.exe
2014-07-11 16:09 - 2014-07-11 16:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2014-07-11 16:09 - 2014-07-11 16:09 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-07-11 16:09 - 2014-07-11 16:09 - 00000000 ____D () C:\Program Files\iTunes
2014-07-11 16:09 - 2014-07-11 16:09 - 00000000 ____D () C:\Program Files\iPod
2014-07-11 16:09 - 2014-07-11 16:09 - 00000000 ____D () C:\Program Files (x86)\iTunes
2014-07-11 16:03 - 2014-07-11 16:05 - 113509200 _____ (Apple Inc.) C:\Users\Lawrence\Downloads\iTunes64Setup.exe
2014-07-11 16:02 - 2014-08-06 01:08 - 00000830 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2014-07-11 16:02 - 2014-07-11 16:02 - 00003718 _____ () C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2014-07-10 09:53 - 2014-07-10 09:53 - 00000000 ___SD () C:\WINDOWS\system32\CompatTel
2014-07-10 09:48 - 2014-07-10 09:48 - 939619854 _____ () C:\WINDOWS\MEMORY.DMP
2014-07-10 05:01 - 2014-04-14 13:29 - 01018880 _____ (Microsoft Corporation) C:\WINDOWS\system32\termsrv.dll
2014-07-10 00:42 - 2014-06-17 08:26 - 00779264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\osk.exe
2014-07-10 00:42 - 2014-06-17 08:24 - 00834048 _____ (Microsoft Corporation) C:\WINDOWS\system32\osk.exe
2014-07-10 00:42 - 2014-06-07 00:20 - 04190720 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2014-07-10 00:42 - 2014-05-30 13:03 - 00563200 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\afd.sys
2014-07-10 00:42 - 2014-05-29 22:02 - 00565576 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2014-07-10 00:42 - 2014-05-29 17:55 - 00735232 _____ (Microsoft Corporation) C:\WINDOWS\system32\adtschema.dll
2014-07-10 00:42 - 2014-05-29 16:40 - 00735232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\adtschema.dll
2014-07-10 00:42 - 2014-05-29 16:37 - 00436224 _____ (Microsoft Corporation) C:\WINDOWS\system32\certcli.dll
2014-07-10 00:42 - 2014-05-29 15:34 - 00318976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certcli.dll
2014-07-10 00:42 - 2014-05-29 15:27 - 01417216 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2014-07-10 00:41 - 2014-06-19 11:39 - 23464448 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2014-07-10 00:41 - 2014-06-19 10:16 - 17276416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2014-07-10 00:41 - 2014-06-19 09:46 - 00250880 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2014-07-10 00:41 - 2014-06-19 08:57 - 00225280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2014-07-10 00:40 - 2014-07-01 08:45 - 00688128 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepdu.dll
2014-07-10 00:40 - 2014-06-28 17:48 - 00527360 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2014-07-10 00:40 - 2014-06-28 17:07 - 00385536 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2014-07-10 00:40 - 2014-06-19 10:48 - 02768384 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2014-07-10 00:40 - 2014-06-19 10:09 - 00452608 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtmsft.dll
2014-07-10 00:40 - 2014-06-19 09:51 - 05721088 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2014-07-10 00:40 - 2014-06-19 09:50 - 00085504 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2014-07-10 00:40 - 2014-06-19 09:48 - 00292864 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll
2014-07-10 00:40 - 2014-06-19 09:39 - 00608768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2014-07-10 00:40 - 2014-06-19 09:33 - 00631808 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2014-07-10 00:40 - 2014-06-19 09:32 - 02179072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2014-07-10 00:40 - 2014-06-19 09:27 - 02040832 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2014-07-10 00:40 - 2014-06-19 09:12 - 00367616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtmsft.dll
2014-07-10 00:40 - 2014-06-19 08:59 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll
2014-07-10 00:40 - 2014-06-19 08:58 - 02266112 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2014-07-10 00:40 - 2014-06-19 08:58 - 00239616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll
2014-07-10 00:40 - 2014-06-19 08:52 - 04254720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2014-07-10 00:40 - 2014-06-19 08:51 - 13527040 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2014-07-10 00:40 - 2014-06-19 08:49 - 00526336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2014-07-10 00:40 - 2014-06-19 08:45 - 01964544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2014-07-10 00:40 - 2014-06-19 08:35 - 11742208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2014-07-10 00:40 - 2014-06-19 08:34 - 01393664 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2014-07-10 00:40 - 2014-06-19 08:15 - 00846336 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2014-07-10 00:40 - 2014-06-19 08:13 - 01791488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2014-07-10 00:40 - 2014-06-19 08:09 - 01139200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2014-07-10 00:40 - 2014-06-19 08:07 - 00704512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2014-07-10 00:40 - 2014-06-06 23:04 - 00586240 _____ (Microsoft Corporation) C:\WINDOWS\system32\qedit.dll
2014-07-10 00:40 - 2014-06-06 22:18 - 00488960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\qedit.dll
2014-07-10 00:40 - 2014-05-31 20:07 - 00054776 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2014-07-10 00:40 - 2014-05-31 20:06 - 00555736 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll
2014-07-10 00:40 - 2014-05-31 13:40 - 13287936 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2014-07-10 00:40 - 2014-05-31 13:30 - 11792384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2014-07-10 00:40 - 2014-05-31 13:12 - 00249344 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2014-07-10 00:40 - 2014-05-31 13:06 - 00093696 _____ (Microsoft Corporation) C:\WINDOWS\system32\wudriver.dll
2014-07-10 00:40 - 2014-05-31 13:03 - 00827392 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2014-07-10 00:40 - 2014-05-31 13:01 - 00189952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2014-07-10 00:40 - 2014-05-31 12:56 - 00080896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wudriver.dll
2014-07-10 00:40 - 2014-05-31 12:54 - 00666624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2014-07-10 00:40 - 2014-05-31 12:48 - 03463680 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2014-07-10 00:40 - 2014-05-31 12:37 - 01054208 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll
2014-07-10 00:40 - 2014-05-31 12:36 - 00923136 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSShared.dll
2014-07-10 00:40 - 2014-05-31 12:35 - 00828928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.appcore.dll
2014-07-10 00:40 - 2014-05-31 12:32 - 00756224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSShared.dll
2014-07-10 00:29 - 2014-07-10 00:29 - 00079872 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSReset.exe
2014-07-08 23:16 - 2014-07-08 23:16 - 00001625 _____ () C:\Users\Public\Desktop\Play League of Legends.lnk
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-08-06 01:23 - 2014-07-20 01:16 - 00026138 _____ () C:\Users\Lawrence\Desktop\FRST.txt
2014-08-06 01:22 - 2014-08-06 01:22 - 00000000 ____D () C:\Users\Lawrence\Desktop\FRST-OlderVersion
2014-08-06 01:22 - 2014-07-20 01:16 - 00000000 ____D () C:\FRST
2014-08-06 01:22 - 2014-07-20 01:15 - 02094080 _____ (Farbar) C:\Users\Lawrence\Desktop\FRST64.exe
2014-08-06 01:21 - 2014-08-06 01:01 - 00122584 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2014-08-06 01:21 - 2014-07-16 23:54 - 00004978 _____ () C:\WINDOWS\System32\Tasks\Microsoft Office 15 Sync Maintenance for ROYAL-Lawry Lsw Royal
2014-08-06 01:21 - 2013-11-02 13:09 - 00000924 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2014-08-06 01:20 - 2014-06-25 17:19 - 00003496 _____ () C:\WINDOWS\System32\Tasks\gg_uac_daemon_Lawry Lsw
2014-08-06 01:20 - 2013-08-23 00:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT
2014-08-06 01:19 - 2013-10-12 12:39 - 00006656 _____ () C:\WINDOWS\system32\VfService.trf
2014-08-06 01:19 - 2013-09-30 14:02 - 00037136 _____ () C:\WINDOWS\PFRO.log
2014-08-06 01:19 - 2013-08-23 01:36 - 00000000 ____D () C:\WINDOWS\Registration
2014-08-06 01:19 - 2013-08-22 23:25 - 00262144 ___SH () C:\WINDOWS\system32\config\BBI
2014-08-06 01:17 - 2013-11-01 17:38 - 00003596 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-450748458-2682401420-2043914554-1002
2014-08-06 01:16 - 2014-08-06 01:16 - 00001624 _____ () C:\Users\Lawrence\Desktop\JRT.txt
2014-08-06 01:11 - 2014-08-06 01:11 - 00004222 _____ () C:\Users\Lawrence\Desktop\AdwCleaner[S0].txt
2014-08-06 01:10 - 2014-08-06 01:10 - 00000000 ____D () C:\WINDOWS\ERUNT
2014-08-06 01:08 - 2014-08-06 01:08 - 01016261 _____ (Thisisu) C:\Users\Lawrence\Desktop\JRT.exe
2014-08-06 01:08 - 2014-07-11 16:02 - 00000830 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2014-08-06 01:02 - 2014-08-06 01:02 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
2014-08-06 01:02 - 2014-07-20 11:42 - 00001871 _____ () C:\Users\Public\Desktop\McAfee Internet Security.lnk
2014-08-06 01:02 - 2013-11-03 03:39 - 00000000 ____D () C:\Users\Lawrence\AppData\Roaming\GarenaPlus
2014-08-06 01:02 - 2013-11-03 03:38 - 00000000 ____D () C:\ProgramData\GarenaMessenger
2014-08-06 01:00 - 2014-08-06 01:00 - 00001125 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-08-06 01:00 - 2014-08-06 01:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2014-08-06 01:00 - 2014-08-06 01:00 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-08-06 01:00 - 2014-08-06 01:00 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-08-06 01:00 - 2013-08-23 01:36 - 00000000 ____D () C:\WINDOWS\system32\sru
2014-08-06 00:58 - 2014-07-20 11:40 - 00000000 ____D () C:\Program Files (x86)\McAfee
2014-08-06 00:57 - 2013-08-22 23:25 - 00262144 ___SH () C:\WINDOWS\system32\config\ELAM
2014-08-06 00:56 - 2013-10-12 12:07 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-08-06 00:55 - 2014-08-06 00:50 - 00000000 ____D () C:\AdwCleaner
2014-08-06 00:52 - 2014-08-06 00:51 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Lawrence\Desktop\mbam-setup-2.0.2.1012.exe
2014-08-06 00:50 - 2014-08-06 00:49 - 01361309 _____ () C:\Users\Lawrence\Desktop\AdwCleaner.exe
2014-08-06 00:48 - 2013-11-02 13:09 - 00000928 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2014-08-05 23:45 - 2014-08-05 22:02 - 00000000 ____D () C:\Program Files (x86)\Hearthstone
2014-08-05 23:45 - 2014-06-25 01:16 - 00000000 ____D () C:\Users\Lawrence\AppData\Local\Battle.net
2014-08-05 22:35 - 2014-08-05 22:35 - 00000000 ____D () C:\Users\Lawrence\AppData\Local\Blizzard
2014-08-05 22:21 - 2014-08-05 22:10 - 00000000 ____D () C:\Users\Lawrence\AppData\Local\Maxiget
2014-08-05 22:19 - 2014-08-05 22:19 - 00000000 ____D () C:\Users\Lawrence\Documents\Downloaded Videos Movie
2014-08-05 22:15 - 2014-08-05 19:17 - 00000000 ____D () C:\Users\Lawrence\AppData\Local\StormAlerts
2014-08-05 22:14 - 2014-08-05 22:10 - 00000258 __RSH () C:\ProgramData\ntuser.pol
2014-08-05 22:10 - 2014-08-05 22:10 - 00000000 ____D () C:\Users\Lawrence\AppData\Local\MaxiGet Download Manager
2014-08-05 22:10 - 2013-08-23 01:36 - 00000000 ___HD () C:\WINDOWS\system32\GroupPolicy
2014-08-05 22:10 - 2013-08-23 01:36 - 00000000 ____D () C:\WINDOWS\SysWOW64\GroupPolicy
2014-08-05 22:07 - 2013-12-31 20:07 - 00016553 _____ () C:\Users\Lawrence\Desktop\Expenditure.xlsx
2014-08-05 22:02 - 2014-08-05 22:02 - 00001218 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HearthstoneHearthstone.lnk
2014-08-05 22:02 - 2014-08-05 22:02 - 00001172 _____ () C:\Users\Public\Desktop\Hearthstone.lnk
2014-08-05 22:02 - 2014-08-05 22:02 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hearthstone
2014-08-05 22:00 - 2013-11-04 09:34 - 00000000 __SHD () C:\Users\Lawrence\wc
2014-08-05 21:32 - 2013-11-27 08:11 - 01508813 _____ () C:\WINDOWS\WindowsUpdate.log
2014-08-05 21:14 - 2013-08-23 01:36 - 00000000 ____D () C:\WINDOWS\AppReadiness
2014-08-05 19:23 - 2014-08-05 19:23 - 00000000 ____D () C:\ProgramData\HipSoft
2014-08-05 19:19 - 2014-08-05 19:19 - 00000064 _____ () C:\WINDOWS\GPlrLanc.dat
2014-08-05 19:15 - 2013-08-23 01:36 - 00000000 ____D () C:\WINDOWS\Resources
2014-08-05 13:06 - 2013-11-02 20:32 - 00000000 ____D () C:\Program Files\Microsoft Office 15
2014-08-04 00:34 - 2013-11-01 17:23 - 00000000 ____D () C:\Users\Lawrence\AppData\Local\Packages
2014-08-02 11:21 - 2014-06-15 22:55 - 00000000 ____D () C:\Users\Lawrence\AppData\Local\PMB Files
2014-08-02 11:21 - 2014-06-15 22:55 - 00000000 ____D () C:\ProgramData\PMB Files
2014-08-02 11:20 - 2013-11-03 03:38 - 00000000 ____D () C:\Program Files (x86)\Garena Plus
2014-07-31 18:10 - 2014-06-25 01:15 - 00000000 ____D () C:\Program Files (x86)\Battle.net
2014-07-31 01:08 - 2014-07-31 01:08 - 00000000 ____D () C:\WINDOWS\SysWOW64\NV
2014-07-31 01:08 - 2014-07-31 01:08 - 00000000 ____D () C:\WINDOWS\system32\NV
2014-07-30 17:11 - 2014-07-30 17:11 - 00000000 ____D () C:\Program Files (x86)\AGEIA Technologies
2014-07-30 17:11 - 2013-11-27 08:11 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation
2014-07-30 17:10 - 2013-10-12 12:01 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-07-30 17:09 - 2014-07-30 16:15 - 00000000 ____D () C:\WINDOWS\LastGood.Tmp
2014-07-30 17:09 - 2013-11-27 08:11 - 00000000 ____D () C:\Program Files\NVIDIA Corporation
2014-07-30 16:16 - 2013-12-04 02:48 - 00000000 ____D () C:\Users\Lawrence\AppData\Local\NVIDIA Corporation
2014-07-30 16:15 - 2013-08-23 00:46 - 00340131 _____ () C:\WINDOWS\setupact.log
2014-07-25 23:50 - 2014-07-30 16:15 - 01715224 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspbridge64.dll
2014-07-25 23:50 - 2014-07-30 16:15 - 01291280 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspbridge.dll
2014-07-25 23:50 - 2013-12-02 00:48 - 01283136 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspcap64.dll
2014-07-25 23:50 - 2013-12-02 00:48 - 01126480 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspcap.dll
2014-07-23 19:55 - 2013-10-12 12:37 - 00000000 ____D () C:\Program Files\Common Files\mcafee
2014-07-23 19:55 - 2012-07-26 18:12 - 00000000 ___HD () C:\WINDOWS\ELAMBKUP
2014-07-22 23:56 - 2013-11-27 08:16 - 00000000 ____D () C:\Users\Lawrence
2014-07-20 14:41 - 2013-10-12 12:37 - 00000000 ____D () C:\ProgramData\McAfee
2014-07-20 11:41 - 2014-07-20 11:41 - 00000000 ____D () C:\Program Files (x86)\McAfee.com
2014-07-20 11:41 - 2013-10-12 12:37 - 00000000 ____D () C:\Program Files\mcafee
2014-07-20 11:40 - 2014-07-20 11:40 - 00000000 ____D () C:\Program Files\McAfee.com
2014-07-20 11:33 - 2013-08-23 00:44 - 00474072 _____ () C:\WINDOWS\system32\FNTCACHE.DAT
2014-07-20 11:08 - 2014-07-20 11:07 - 00000000 ____D () C:\ccbcdf3a6d8c10b8004fd3c5c5
2014-07-20 11:05 - 2012-07-26 15:37 - 00000000 ____D () C:\Users\Default.migrated
2014-07-20 11:04 - 2013-11-25 10:01 - 00000000 ____D () C:\Program Files\stinger
2014-07-20 01:18 - 2014-07-20 01:17 - 00037817 _____ () C:\Users\Lawrence\Desktop\Addition.txt
2014-07-19 18:46 - 2014-07-19 18:46 - 00003023 _____ () C:\Users\Lawrence\Desktop\HiJackThis.lnk
2014-07-19 18:46 - 2014-07-19 18:46 - 00000000 ____D () C:\Users\Lawrence\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis
2014-07-19 18:46 - 2014-07-19 18:46 - 00000000 ____D () C:\Program Files (x86)\Trend Micro
2014-07-19 18:46 - 2013-11-01 17:24 - 00000000 ____D () C:\Users\Lawrence\AppData\Local\VirtualStore
2014-07-19 18:14 - 2014-07-19 18:14 - 01402880 _____ () C:\Users\Lawrence\Desktop\HijackThis.msi
2014-07-19 14:42 - 2014-07-19 14:42 - 00000003 _____ () C:\WINDOWS\system32\HRUPPROG.EXIT
2014-07-19 14:42 - 2014-07-19 14:42 - 00000002 _____ () C:\WINDOWS\system32\HRUPPROG.TXT
2014-07-17 19:14 - 2014-07-17 19:14 - 00000000 ____D () C:\ProgramData\Riot Games
2014-07-17 18:44 - 2014-07-17 18:44 - 00688992 _____ (Swearware) C:\Users\Lawrence\Desktop\dds.com
2014-07-17 18:04 - 2014-07-17 17:51 - 00000000 _____ () C:\WINDOWS\system32\1
2014-07-16 23:32 - 2014-07-16 23:34 - 04605016 _____ () C:\Users\Lawrence\Desktop\cbs.txt
2014-07-16 23:14 - 2014-07-16 23:14 - 00002464 _____ () C:\Users\Lawrence\Desktop\SFCFix.txt
2014-07-16 23:14 - 2014-07-16 01:42 - 00000000 ____D () C:\Users\Lawrence\AppData\Local\niemiro
2014-07-16 23:14 - 2014-07-16 01:42 - 00000000 ____D () C:\SFCFix
2014-07-16 23:13 - 2014-07-16 23:13 - 01296920 _____ () C:\Users\Lawrence\Desktop\SFCFix.zip
2014-07-16 23:12 - 2014-07-16 01:49 - 00566784 _____ (niemiro) C:\Users\Lawrence\Desktop\SFCFix.exe
2014-07-16 16:05 - 2013-09-30 14:10 - 00865408 _____ () C:\WINDOWS\system32\PerfStringBackup.INI
2014-07-16 02:28 - 2012-07-26 17:59 - 00000000 ____D () C:\WINDOWS\CbsTemp
2014-07-13 01:18 - 2014-07-13 01:18 - 00001052 _____ () C:\Users\Public\Desktop\Path of Exile.lnk
2014-07-13 01:18 - 2014-07-13 01:13 - 00000000 ____D () C:\Program Files (x86)\GarenaPoE
2014-07-13 01:18 - 2013-11-03 03:39 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Garena
2014-07-12 16:17 - 2014-04-28 01:53 - 00000000 ____D () C:\Users\Lawrence\Desktop\Books!
2014-07-12 16:15 - 2014-07-12 16:15 - 00000000 ____D () C:\Users\Lawrence\AppData\Local\Aeria Games
2014-07-12 16:14 - 2014-07-12 16:14 - 00000000 ____D () C:\ProgramData\Aeria Games
2014-07-12 16:13 - 2014-07-12 16:12 - 00000000 ___HD () C:\WINDOWS\msdownld.tmp
2014-07-12 16:13 - 2014-07-12 16:12 - 00000000 ____D () C:\WINDOWS\SysWOW64\directx
2014-07-12 16:12 - 2014-07-12 16:12 - 00001701 _____ () C:\Users\Lawrence\Desktop\Aura Kingdom.lnk
2014-07-12 16:00 - 2014-07-12 16:00 - 00002055 _____ () C:\Users\Public\Desktop\Aeria Ignite.lnk
2014-07-12 16:00 - 2014-07-12 16:00 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AeriaGames
2014-07-12 16:00 - 2014-07-12 16:00 - 00000000 ____D () C:\Program Files (x86)\Aeria Games
2014-07-12 16:00 - 2014-07-12 12:58 - 00000000 ____D () C:\AeriaGames
2014-07-12 15:05 - 2014-07-12 15:03 - 00000000 ____D () C:\Users\Lawrence\Documents\InfiniteCrisis
2014-07-12 15:03 - 2014-07-12 15:03 - 00000000 ____D () C:\Users\Lawrence\AppData\Local\InfiniteCrisis
2014-07-12 15:00 - 2014-07-12 13:59 - 00000000 ____D () C:\Program Files (x86)\InfiniteCrisis
2014-07-12 14:01 - 2014-07-12 14:01 - 00000000 ____D () C:\Users\Lawrence\AppData\Local\Turbine
2014-07-12 14:00 - 2014-06-30 02:00 - 00028116 _____ () C:\WINDOWS\DirectX.log
2014-07-12 13:59 - 2014-07-12 13:59 - 00001107 _____ () C:\Users\Public\Desktop\InfiniteCrisis.lnk
2014-07-12 13:59 - 2014-07-12 13:59 - 00000000 ____D () C:\ProgramData\Turbine
2014-07-12 13:59 - 2014-07-12 13:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Infinite Crisis
2014-07-12 13:53 - 2014-07-12 13:49 - 140770440 _____ () C:\Users\Lawrence\Downloads\InfiniteCrisis-GLOBAL_Setup.exe
2014-07-12 13:47 - 2014-07-12 13:47 - 00000000 ____D () C:\Users\Lawrence\AppData\Local\Akamai
2014-07-12 12:57 - 2014-07-12 12:57 - 00581656 _____ (Aeria Games & Entertainment) C:\Users\Lawrence\Downloads\aurakingdom_us_downloader.exe
2014-07-11 16:09 - 2014-07-11 16:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2014-07-11 16:09 - 2014-07-11 16:09 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-07-11 16:09 - 2014-07-11 16:09 - 00000000 ____D () C:\Program Files\iTunes
2014-07-11 16:09 - 2014-07-11 16:09 - 00000000 ____D () C:\Program Files\iPod
2014-07-11 16:09 - 2014-07-11 16:09 - 00000000 ____D () C:\Program Files (x86)\iTunes
2014-07-11 16:06 - 2013-11-09 16:39 - 00000000 ____D () C:\ProgramData\Apple
2014-07-11 16:05 - 2014-07-11 16:03 - 113509200 _____ (Apple Inc.) C:\Users\Lawrence\Downloads\iTunes64Setup.exe
2014-07-11 16:02 - 2014-07-11 16:02 - 00003718 _____ () C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2014-07-10 10:28 - 2013-08-23 01:36 - 00000000 ____D () C:\WINDOWS\rescache
2014-07-10 09:54 - 2013-08-23 01:36 - 00000000 ___RD () C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2014-07-10 09:54 - 2013-08-23 01:36 - 00000000 ___RD () C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2014-07-10 09:53 - 2014-07-10 09:53 - 00000000 ___SD () C:\WINDOWS\system32\CompatTel
2014-07-10 09:52 - 2013-08-23 01:36 - 00000000 ___RD () C:\WINDOWS\ToastData
2014-07-10 09:52 - 2013-08-23 01:36 - 00000000 ____D () C:\WINDOWS\WinStore
2014-07-10 09:48 - 2014-07-10 09:48 - 939619854 _____ () C:\WINDOWS\MEMORY.DMP
2014-07-10 05:07 - 2013-11-04 05:56 - 00000000 ____D () C:\WINDOWS\system32\MRT
2014-07-10 05:06 - 2013-11-04 05:56 - 96441528 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2014-07-10 05:01 - 2013-08-23 00:46 - 00000440 _____ () C:\WINDOWS\setuperr.log
2014-07-10 05:00 - 2013-09-30 13:58 - 00000000 ____D () C:\Program Files\Windows Journal
2014-07-10 00:29 - 2014-07-10 00:29 - 00079872 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSReset.exe
2014-07-08 23:16 - 2014-07-08 23:16 - 00001625 _____ () C:\Users\Public\Desktop\Play League of Legends.lnk
2014-07-08 23:15 - 2013-11-01 18:08 - 00000000 ___RD () C:\Users\Lawrence\Desktop\Dekstop
Some content of TEMP:
====================
C:\Users\Lawrence\AppData\Local\Temp\dxwebsetup.exe
C:\Users\Lawrence\AppData\Local\Temp\lol_patch_131114to131127v3.exe
C:\Users\Lawrence\AppData\Local\Temp\lol_patch_131127to131217v2.exe
C:\Users\Lawrence\AppData\Local\Temp\lol_patch_131217to140110.exe
C:\Users\Lawrence\AppData\Local\Temp\lol_patch_140110to140121v2.exe
C:\Users\Lawrence\AppData\Local\Temp\lol_patch_140121to140212v2.exe
C:\Users\Lawrence\AppData\Local\Temp\lol_patch_140212to140214.exe
C:\Users\Lawrence\AppData\Local\Temp\lol_patch_140214to140220.exe
C:\Users\Lawrence\AppData\Local\Temp\lol_patch_140220to140306.exe
C:\Users\Lawrence\AppData\Local\Temp\lol_patch_140306to140307.exe
C:\Users\Lawrence\AppData\Local\Temp\lol_patch_140307to140325.exe
C:\Users\Lawrence\AppData\Local\Temp\lol_patch_140325to140401v2.exe
C:\Users\Lawrence\AppData\Local\Temp\lol_patch_140401to140409.exe
C:\Users\Lawrence\AppData\Local\Temp\lol_patch_140409to140410.exe
C:\Users\Lawrence\AppData\Local\Temp\lol_patch_140410to140429.exe
C:\Users\Lawrence\AppData\Local\Temp\lol_patch_140429to140430.exe
C:\Users\Lawrence\AppData\Local\Temp\lol_patch_140430to140513.exe
C:\Users\Lawrence\AppData\Local\Temp\lol_patch_140513to140529.exe
C:\Users\Lawrence\AppData\Local\Temp\lol_patch_140529to140610v2.exe
C:\Users\Lawrence\AppData\Local\Temp\lol_patch_140610to140624.exe
C:\Users\Lawrence\AppData\Local\Temp\lol_patch_140624to140708v2.exe
C:\Users\Lawrence\AppData\Local\Temp\lol_patch_140708to140722.exe
C:\Users\Lawrence\AppData\Local\Temp\lol_patch_140722to140805.exe
C:\Users\Lawrence\AppData\Local\Temp\OfficeSetup.exe
C:\Users\Lawrence\AppData\Local\Temp\Quarantine.exe
C:\Users\Lawrence\AppData\Local\Temp\Setup.x86.en-US_HomeStudentRetail_CNFY9-CRP43-TF6PQ-76VYF-BY2XR_TX_SG_.exe
C:\Users\Lawrence\AppData\Local\Temp\setup32.exe
C:\Users\Lawrence\AppData\Local\Temp\swt-win32-3349.dll
C:\Users\Lawrence\AppData\Local\Temp\Tsu301FFA7E.dll
C:\Users\Lawrence\AppData\Local\Temp\Tsu30F4D4DA.dll
C:\Users\Lawrence\AppData\Local\Temp\Tsu322EB8E2.dll
C:\Users\Lawrence\AppData\Local\Temp\UNT3DBF.tmp.exe
C:\Users\Lawrence\AppData\Local\Temp\UNT3DEF.tmp.exe
C:\Users\Lawrence\AppData\Local\Temp\UNT3DFE.tmp.exe
C:\Users\Lawrence\AppData\Local\Temp\UNT3DFF.tmp.exe
C:\Users\Lawrence\AppData\Local\Temp\UNT3E2E.tmp.exe
C:\Users\Lawrence\AppData\Local\Temp\UNT3E2F.tmp.exe
C:\Users\Lawrence\AppData\Local\Temp\UNT3E5E.tmp.exe
C:\Users\Lawrence\AppData\Local\Temp\UNT3E6E.tmp.exe
C:\Users\Lawrence\AppData\Local\Temp\UNT3E8E.tmp.exe
C:\Users\Lawrence\AppData\Local\Temp\UNT3EAE.tmp.exe
C:\Users\Lawrence\AppData\Local\Temp\UNT3EDD.tmp.exe
C:\Users\Lawrence\AppData\Local\Temp\UNT3F0D.tmp.exe
C:\Users\Lawrence\AppData\Local\Temp\UNT3F3D.tmp.exe
C:\Users\Lawrence\AppData\Local\Temp\UNT3F6A.tmp.exe
C:\Users\Lawrence\AppData\Local\Temp\UNT4065.tmp.exe
C:\Users\Lawrence\AppData\Local\Temp\UNT43B0.tmp.exe
C:\Users\Lawrence\AppData\Local\Temp\UNT43E0.tmp.exe
C:\Users\Lawrence\AppData\Local\Temp\UNT43F3.tmp.exe
C:\Users\Lawrence\AppData\Local\Temp\UNT4423.tmp.exe
C:\Users\Lawrence\AppData\Local\Temp\UNT4452.tmp.exe
C:\Users\Lawrence\AppData\Local\Temp\UNT4482.tmp.exe
C:\Users\Lawrence\AppData\Local\Temp\UNT44B2.tmp.exe
C:\Users\Lawrence\AppData\Local\Temp\UNT44E2.tmp.exe
C:\Users\Lawrence\AppData\Local\Temp\UNT4502.tmp.exe
C:\Users\Lawrence\AppData\Local\Temp\vcredist_x86.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-07-29 19:34
==================== End Of Log ============================