Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:30-12-2015
Ran by Gil (administrator) on GILOFFICEPC (30-12-2015 13:23:33)
Running from C:\Users\Gil\Desktop
Loaded Profiles: Gil (Available Profiles: Gil)
Platform: Windows 8.1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
FRST Tutorial - How to use Farbar Recovery Scan Tool - Malware Removal Guides and Tutorials
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgrsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgcsrva.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Andrea Electronics Corporation) C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome Remote Desktop\47.0.2526.18\remoting_host.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgnsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgemca.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome Remote Desktop\47.0.2526.18\remoting_host.exe
(Intuit) C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
(Intuit Inc.) C:\Program Files (x86)\Common Files\Intuit\DataProtect\QBIDPService.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
(IvoSoft) C:\Program Files\Classic Shell\ClassicStartMenu.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_w32.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_x64.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.29.1\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.29.1\GoogleCrashHandler64.exe
(CyberLink) C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSMonitorServicePDVD12.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe
(CyberLink) C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Tweaking.com) C:\Program Files (x86)\Tweaking.com\Windows Repair (All in One)\WR_Tray_Icon.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(RingCentral, Inc.) C:\Program Files (x86)\RingCentral\RingCentral Softphone\RCHotKey.exe
(SugarSync, Inc.) C:\Program Files (x86)\SugarSync\SugarSync.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(RingCentral) C:\Program Files (x86)\RingCentral for Windows\Softphone.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgui.exe
(Intuit Inc.) C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
(Brother Industries, Ltd.) C:\Program Files (x86)\Browny02\BrYNSvc.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Corporation) C:\Windows\WinStore\WSHost.exe
(CyberLink) C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\root\office15\ONENOTE.EXE
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\root\office15\EXCEL.EXE
(Microsoft Corporation) C:\Windows\splwow64.exe
(HP Inc.) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7198424 2013-08-23] (Realtek Semiconductor)
HKLM\...\Run: [Classic Start Menu] => C:\Program Files\Classic Shell\ClassicStartMenu.exe [161728 2015-08-09] (IvoSoft)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [170256 2015-12-09] (Apple Inc.)
HKLM-x32\...\Run: [StartCCC] => c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642656 2013-02-26] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [BrStsMon00] => C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe [3076096 2012-06-06] (Brother Industries, Ltd.)
HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\AVG2015\avgui.exe [3780008 2015-10-30] (AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [Intuit SyncManager] => C:\Program Files (x86)\Common Files\Intuit\Sync\IntuitSyncManager.exe [3776824 2015-03-17] (Intuit Inc. All rights reserved.)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2015-08-06] (Apple Inc.)
HKU\S-1-5-21-2509790399-2890906804-1317435896-1001\...\Run: [Google Update] => C:\Users\Gil\AppData\Local\Google\Update\GoogleUpdate.exe [144200 2015-08-30] (Google Inc.)
HKU\S-1-5-21-2509790399-2890906804-1317435896-1001\...\Run: [ApplePhotoStreams] => C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [61200 2015-10-21] (Apple Inc.)
HKU\S-1-5-21-2509790399-2890906804-1317435896-1001\...\Run: [RCUI] => C:\Program Files (x86)\RingCentral\RingCentral Softphone\RCUI.exe [608560 2014-06-09] (RingCentral, Inc.)
HKU\S-1-5-21-2509790399-2890906804-1317435896-1001\...\Run: [RCHotKey] => C:\Program Files (x86)\RingCentral\RingCentral Softphone\RCHotKey.exe [30000 2014-06-09] (RingCentral, Inc.)
HKU\S-1-5-21-2509790399-2890906804-1317435896-1001\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [60688 2015-10-21] (Apple Inc.)
HKU\S-1-5-21-2509790399-2890906804-1317435896-1001\...\Run: [iCloudDrive] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe [103696 2015-10-21] (Apple Inc.)
HKU\S-1-5-21-2509790399-2890906804-1317435896-1001\...\Run: [RESTART_STICKY_NOTES] => C:\WINDOWS\system32\StikyNot.exe [457728 2013-11-14] (Microsoft Corporation)
HKU\S-1-5-21-2509790399-2890906804-1317435896-1001\...\Run: [Dropbox Update] => C:\Users\Gil\AppData\Local\Dropbox\Update\DropboxUpdate.exe [134512 2015-06-25] (Dropbox, Inc.)
HKU\S-1-5-21-2509790399-2890906804-1317435896-1001\...\Run: [SugarSync] => C:\Program Files (x86)\SugarSync\SugarSync.exe [18880528 2015-09-28] (SugarSync, Inc.)
HKU\S-1-5-21-2509790399-2890906804-1317435896-1001\...\Run: [RingCentral for Windows] => C:\Program Files (x86)\RingCentral for Windows\Softphone.exe [41250816 2015-10-01] (RingCentral)
HKU\S-1-5-21-2509790399-2890906804-1317435896-1001\...\Run: [MP3 Skype recorder] => C:\Users\Gil\AppData\Local\MP3 Skype recorder\MP3SkypeRecorder.exe [2216600 2015-11-02] (Domit UK LTD)
ShellIconOverlayIdentifiers: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File
ShellIconOverlayIdentifiers: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File
ShellIconOverlayIdentifiers: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File
ShellIconOverlayIdentifiers: ["DropboxExt1"] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Gil\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll [2015-12-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt2"] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Gil\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll [2015-12-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt3"] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Gil\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll [2015-12-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt4"] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Gil\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll [2015-12-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt5"] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Gil\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll [2015-12-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt6"] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Gil\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll [2015-12-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt7"] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Gil\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll [2015-12-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt8"] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Gil\AppData\Roaming\Dropbox\bin\DropboxExt64.28.dll [2015-12-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [SugarSyncPending] -> {62CCD8E3-9C21-41E1-B55E-1E26DFC68511} => C:\Program Files (x86)\SugarSync\x64\SugarSyncShellExt_x64.dll [2015-09-28] (SugarSync, Inc.)
ShellIconOverlayIdentifiers: [SugarSyncShared] -> {1574C9EF-7D58-488F-B358-8B78C1538F51} => C:\Program Files (x86)\SugarSync\x64\SugarSyncShellExt_x64.dll [2015-09-28] (SugarSync, Inc.)
ShellIconOverlayIdentifiers: [SugarSyncSharedSyncing] -> {F7395C2E-A5D8-4a32-9536-5C6A9F1DC450} => C:\Program Files (x86)\SugarSync\x64\SugarSyncShellExt_x64.dll [2015-09-28] (SugarSync, Inc.)
ShellIconOverlayIdentifiers: [SugarSyncSynced] -> {0C4A258A-3F3B-4FFF-80A7-9B3BEC139472} => C:\Program Files (x86)\SugarSync\x64\SugarSyncShellExt_x64.dll [2015-09-28] (SugarSync, Inc.)
ShellIconOverlayIdentifiers-x32: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File
ShellIconOverlayIdentifiers-x32: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File
ShellIconOverlayIdentifiers-x32: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File
ShellIconOverlayIdentifiers-x32: [ SkyDrivePro1 (ErrorConflict)] -> {8BA85C75-763B-4103-94EB-9470F12FE0F7} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2014-09-15] (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ SkyDrivePro2 (SyncInProgress)] -> {CD55129A-B1A1-438E-A425-CEBC7DC684EE} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2014-09-15] (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ SkyDrivePro3 (InSync)] -> {E768CD3B-BDDC-436D-9C13-E1B39CA257B1} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2014-09-15] (Microsoft Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Intuit Data Protect.lnk [2015-08-12]
ShortcutTarget: Intuit Data Protect.lnk -> C:\Program Files (x86)\Common Files\Intuit\DataProtect\IntuitDataProtect.exe (Intuit Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk [2015-08-12]
ShortcutTarget: QuickBooks Update Agent.lnk -> C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe (Intuit Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\QuickBooks_Standard_21.lnk [2015-08-12]
ShortcutTarget: QuickBooks_Standard_21.lnk -> C:\Program Files (x86)\Intuit\QuickBooks 2015\QBW32.EXE (Intuit Inc.)
Startup: C:\Users\Gil\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2015-07-22]
ShortcutTarget: Dropbox.lnk -> C:\Users\Gil\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 10.1.10.1
Tcpip\..\Interfaces\{89EF2115-7329-4358-9831-E3165525A286}: [DhcpNameServer] 10.1.10.1
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.msn.com/HPDSK13/1
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.msn.com/HPDSK13/1
HKU\S-1-5-21-2509790399-2890906804-1317435896-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.msn.com/HPDSK13/1
HKU\S-1-5-21-2509790399-2890906804-1317435896-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.msn.com/HPDSK13/1
SearchScopes: HKLM -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/711-154371-11896-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms}
SearchScopes: HKLM-x32 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/711-154371-11896-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms}
SearchScopes: HKU\S-1-5-21-2509790399-2890906804-1317435896-1001 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/711-154371-11896-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms}
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2014-09-15] (Microsoft Corporation)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-10-12] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2014-09-15] (Microsoft Corporation)
BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [2013-08-28] (Hewlett-Packard)
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll [2014-09-15] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll [2015-01-29] (Oracle Corporation)
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-10-12] (Microsoft Corporation)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2014-09-15] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-01-29] (Oracle Corporation)
BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2013-08-28] (Hewlett-Packard)
Toolbar: HKU\S-1-5-21-2509790399-2890906804-1317435896-1001 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
DPF: HKLM-x32 {523F7FBF-712D-467A-80CC-6BE7BC90CA73} hxxps://ocp.taxwise.com/ActiveX/ocpCheckRenderer.dll
DPF: HKLM-x32 {FF36CDA3-BE1A-4E1D-BD40-68E6D4E2A7F5} hxxps://ocp.taxwise.com/ActiveX/PrinterInformation.dll
Handler-x32: intu-help-qb8 - {CD17C364-2EC8-4929-91A9-C4839A20E909} - C:\Program Files (x86)\Intuit\QuickBooks 2015\HelpAsyncPluggableProtocol.dll [2015-10-15] (Intuit, Inc.)
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL [2014-09-01] (Microsoft Corporation)
Handler-x32: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - C:\WINDOWS\SysWOW64\mscoree.dll [2013-08-21] (Microsoft Corporation)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-10-12] (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-10-12] (Microsoft Corporation)
FireFox:
========
FF ProfilePath: C:\Users\Gil\AppData\Roaming\Mozilla\Firefox\Profiles\89awetsd.default
FF Keyword.URL:
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_20_0_0_267.dll [2015-12-29] ()
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_20_0_0_267.dll [2015-12-29] ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2015-10-14] ()
FF Plugin-x32: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll [2015-01-29] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-01-29] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2014-09-01] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [2014-02-23] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-09-12] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-03] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-03] (Google Inc.)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll [2012-10-12] ()
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-09-26] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-2509790399-2890906804-1317435896-1001: @citrixonline.com/appdetectorplugin -> C:\Users\Gil\AppData\Local\Citrix\Plugins\104\npappdetector.dll [2014-02-27] (Citrix Online)
FF Plugin HKU\S-1-5-21-2509790399-2890906804-1317435896-1001: @talk.google.com/GoogleTalkPlugin -> C:\Users\Gil\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll [2015-12-08] (Google)
FF Plugin HKU\S-1-5-21-2509790399-2890906804-1317435896-1001: @talk.google.com/O1DPlugin -> C:\Users\Gil\AppData\Roaming\Mozilla\plugins\npo1d.dll [2015-12-08] (Google)
FF Plugin HKU\S-1-5-21-2509790399-2890906804-1317435896-1001: @tools.google.com/Google Update;version=3 -> C:\Users\Gil\AppData\Local\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-03] (Google Inc.)
FF Plugin HKU\S-1-5-21-2509790399-2890906804-1317435896-1001: @tools.google.com/Google Update;version=9 -> C:\Users\Gil\AppData\Local\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-03] (Google Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\Gil\AppData\Roaming\mozilla\plugins\npatgpc.dll [2014-05-14] (Cisco WebEx LLC)
FF Plugin ProgramFiles/Appdata: C:\Users\Gil\AppData\Roaming\mozilla\plugins\npgoogletalk.dll [2015-12-08] (Google)
FF Plugin ProgramFiles/Appdata: C:\Users\Gil\AppData\Roaming\mozilla\plugins\npo1d.dll [2015-12-08] (Google)
FF Extension: FireFTP - C:\Users\Gil\AppData\Roaming\Mozilla\Firefox\Profiles\89awetsd.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f} [2015-06-01]
FF Extension: iCloud Bookmarks - C:\Users\Gil\AppData\Roaming\Mozilla\Firefox\Profiles\89awetsd.default\Extensions\firefoxdav@icloud.com [2015-05-29]
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2014-07-14] [not signed]
Chrome:
=======
CHR HomePage: Default -> hxxp://www.google.com/
CHR StartupUrls: Default -> "hxxp://gmail.com/"
CHR Plugin: (Shockwave Flash) - C:\Users\Gil\AppData\Local\Google\Chrome\User Data\PepperFlash\14.0.0.145\pepflashplayer.dll => No File
CHR Plugin: (Widevine Content Decryption Module) - C:\Users\Gil\AppData\Local\Google\Chrome\User Data\WidevineCDM\1.4.4.600\_platform_specific\win_x86\widevinecdmadapter.dll => No File
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\47.0.2526.106\ppGoogleNaClPluginChrome.dll => No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\47.0.2526.106\pdf.dll => No File
CHR Plugin: (ActiveTouch General Plugin Container) - C:\Users\Gil\AppData\Roaming\Mozilla\plugins\npatgpc.dll (Cisco WebEx LLC)
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (Java Deployment Toolkit 7.0.550.14) - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll => No File
CHR Plugin: (Java(TM) Platform SE 7 U55) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll => No File
CHR Plugin: (WildTangent Games App V2 Presence Detector) - C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll ()
CHR Plugin: (Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Plugin: (Microsoft Office 2013) - C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL (Microsoft Corporation)
CHR Plugin: (Citrix Online Web Deployment Plugin 1.0.0.104) - C:\Users\Gil\AppData\Local\Citrix\Plugins\104\npappdetector.dll (Citrix Online)
CHR Plugin: (Google Update) - C:\Users\Gil\AppData\Local\Google\Update\1.3.24.15\npGoogleUpdate3.dll => No File
CHR Plugin: (Google Talk Plugin) - C:\Users\Gil\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
CHR Plugin: (Google Talk Plugin Video Renderer) - C:\Users\Gil\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google)
CHR Plugin: (Shockwave Flash) - C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_145.dll => No File
CHR Profile: C:\Users\Gil\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Chord Finder) - C:\Users\Gil\AppData\Local\Google\Chrome\User Data\Default\Extensions\abhmjooncijgbgefdkimcfmfogildjen [2014-01-17]
CHR Extension: (Angry Birds) - C:\Users\Gil\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj [2015-01-13]
CHR Extension: (Google Docs) - C:\Users\Gil\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-02-11]
CHR Extension: (Google Drive) - C:\Users\Gil\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-21]
CHR Extension: (SocialBro) - C:\Users\Gil\AppData\Local\Google\Chrome\User Data\Default\Extensions\bagknoiagpifjfbempgignagkejmkljm [2014-10-22]
CHR Extension: (Norton Security Toolbar) - C:\Users\Gil\AppData\Local\Google\Chrome\User Data\Default\Extensions\bejnhdlplbjhffionohbdnpcbobfejcc [2015-08-07]
CHR Extension: (YouTube) - C:\Users\Gil\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-10-02]
CHR Extension: (Google Search) - C:\Users\Gil\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-29]
CHR Extension: (VUDU Movies) - C:\Users\Gil\AppData\Local\Google\Chrome\User Data\Default\Extensions\daomabnenlgkenegngdblacoobnncgib [2014-01-17]
CHR Extension: (WGT Golf Challenge) - C:\Users\Gil\AppData\Local\Google\Chrome\User Data\Default\Extensions\dcilimldmomiaihcfkmaldanopfejefg [2014-01-17]
CHR Extension: (PicMonkey) - C:\Users\Gil\AppData\Local\Google\Chrome\User Data\Default\Extensions\fgdgokchhicmaiacmgegjnppjkgogdhm [2014-10-25]
CHR Extension: (Stupeflix Video Maker) - C:\Users\Gil\AppData\Local\Google\Chrome\User Data\Default\Extensions\fkdmcfnoimoilncpjchamnenebopocem [2015-05-27]
CHR Extension: (Springpad) - C:\Users\Gil\AppData\Local\Google\Chrome\User Data\Default\Extensions\fkmopoamfjnmppabeaphohombnjcjgla [2014-01-17]
CHR Extension: (Chrome Remote Desktop) - C:\Users\Gil\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbchcmhmhahfdphkhkmpfmihenigjmpp [2015-11-09]
CHR Extension: (Google Docs Offline) - C:\Users\Gil\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-11-30]
CHR Extension: (NPR Infinite Player) - C:\Users\Gil\AppData\Local\Google\Chrome\User Data\Default\Extensions\hkpcelemhneoooapbbopolpjhmbfmnbf [2014-01-17]
CHR Extension: (Crackle) - C:\Users\Gil\AppData\Local\Google\Chrome\User Data\Default\Extensions\ibfamoapbmmmlknoopmmfofgladlinic [2015-09-22]
CHR Extension: (Apps Launcher) - C:\Users\Gil\AppData\Local\Google\Chrome\User Data\Default\Extensions\ijmgkhchjindcjamnckoiahagecjnkdc [2015-10-11]
CHR Extension: (60 Minutes) - C:\Users\Gil\AppData\Local\Google\Chrome\User Data\Default\Extensions\imjhdahelgojehmfmkmdfjcpfbglbfmj [2014-01-17]
CHR Extension: (Movi Kanti Revo) - C:\Users\Gil\AppData\Local\Google\Chrome\User Data\Default\Extensions\kkdkcgeghhfjiglphfppinecpcpnnbne [2014-01-17]
CHR Extension: (CashBase) - C:\Users\Gil\AppData\Local\Google\Chrome\User Data\Default\Extensions\klehkbljbmijfgbokipcjeialaonhjlc [2014-01-17]
CHR Extension: (Wave Accounting) - C:\Users\Gil\AppData\Local\Google\Chrome\User Data\Default\Extensions\knpkfcpnjfbniadmfchjpcigfhookhaa [2014-10-21]
CHR Extension: (Skype) - C:\Users\Gil\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2015-12-27]
CHR Extension: (Facebook Cover Maker) - C:\Users\Gil\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfbpohdhflnokmclkbieabhmhbnamcnk [2014-01-17]
CHR Extension: (DSL speedtest) - C:\Users\Gil\AppData\Local\Google\Chrome\User Data\Default\Extensions\mibbfkdeofpfmkclkgjfnjppdblhpddj [2014-01-17]
CHR Extension: (Finance41 Personal Finance Manager) - C:\Users\Gil\AppData\Local\Google\Chrome\User Data\Default\Extensions\nbgkhncobohkmgdjdiijlbgjidpnnkcd [2014-01-17]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Gil\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-08-07]
CHR Extension: (Buffer) - C:\Users\Gil\AppData\Local\Google\Chrome\User Data\Default\Extensions\noojglkidnpfjbincgijbaiedldjfbhh [2015-11-30]
CHR Extension: (Gmail) - C:\Users\Gil\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-04-27]
CHR HKLM\...\Chrome\Extension: [bejnhdlplbjhffionohbdnpcbobfejcc] - C:\Program Files (x86)\Norton Internet Security\Engine\20.6.0.27\Exts\Chrome.crx <not found>
CHR HKLM\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [bejnhdlplbjhffionohbdnpcbobfejcc] - C:\Program Files (x86)\Norton Internet Security\Engine\20.6.0.27\Exts\Chrome.crx <not found>
CHR HKLM-x32\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2015-10-12]
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77104 2015-10-07] (Apple Inc.)
S2 avgfws; C:\Program Files (x86)\AVG\AVG2015\avgfws.exe [1563664 2015-10-30] (AVG Technologies CZ, s.r.o.)
R2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe [3642280 2015-10-30] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe [335656 2015-10-30] (AVG Technologies CZ, s.r.o.)
R3 BrYNSvc; C:\Program Files (x86)\Browny02\BrYNSvc.exe [266240 2012-06-05] (Brother Industries, Ltd.) [File not signed]
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1433216 2015-10-12] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1773696 2015-10-12] (Microsoft Corporation)
R2 chromoting; C:\Program Files (x86)\Google\Chrome Remote Desktop\47.0.2526.18\remoting_host.exe [69448 2015-10-14] (Google Inc.)
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2428088 2014-08-11] (Microsoft Corporation)
R2 CyberLink PowerDVD 12 Media Server Monitor Service; c:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSMonitorServicePDVD12.exe [77576 2013-09-26] (CyberLink)
R2 CyberLink PowerDVD 12 Media Server Service; c:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe [298760 2013-09-26] (CyberLink)
R2 QBCFMonitorService; C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe [45056 2015-10-15] (Intuit) [File not signed]
S3 QBFCService; C:\Program Files (x86)\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe [65536 2014-12-06] (Intuit Inc.) [File not signed]
R2 QBVSS; C:\Program Files (x86)\Common Files\Intuit\DataProtect\QBIDPService.exe [1248256 2014-12-06] (Intuit Inc.) [File not signed]
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [289496 2013-08-23] (Realtek Semiconductor)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [6889232 2015-12-14] (TeamViewer GmbH)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347880 2014-03-23] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1640896 2014-03-23] (Microsoft Corporation)
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S0 Avgboota; C:\Windows\System32\DRIVERS\avgboota.sys [21152 2015-03-27] (AVG Technologies CZ, s.r.o.)
R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [162784 2015-03-11] (AVG Technologies CZ, s.r.o.)
R1 Avgfwfd; C:\Windows\system32\DRIVERS\avgfwd6a.sys [77760 2015-07-09] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [315312 2015-10-19] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [297904 2015-08-19] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [259040 2015-06-16] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [378336 2015-05-07] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [250800 2015-08-04] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [40928 2015-03-20] (AVG Technologies CZ, s.r.o.)
R1 Avgwfpa; C:\Windows\system32\DRIVERS\avgwfpa.sys [304560 2015-08-04] (AVG Technologies CZ, s.r.o.)
R1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [91712 2013-03-15] (CyberLink)
S3 CMUSBDAC; C:\Windows\system32\DRIVERS\CMUSBDAC.sys [358400 2013-05-09] (C-Media Inc.)
S0 ebdrv; C:\Windows\System32\drivers\evbda.sys [3357024 2013-08-22] (Broadcom Corporation)
R0 nlem64nt; C:\Windows\System32\Drivers\nlem64nt.sys [72808 2009-10-13] ()
R3 RSP2STOR; C:\Windows\system32\DRIVERS\RtsP2Stor.sys [288840 2013-05-16] (Realtek Semiconductor Corp.)
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [35856 2014-03-23] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [257880 2014-03-23] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [123224 2014-03-23] (Microsoft Corporation)
R3 MBAMSwissArmy; \??\C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-12-30 13:23 - 2015-12-30 13:24 - 00033736 _____ C:\Users\Gil\Desktop\FRST.txt
2015-12-30 13:22 - 2015-12-30 13:23 - 00000000 ____D C:\FRST
2015-12-30 13:21 - 2015-12-30 13:21 - 02370560 _____ (Farbar) C:\Users\Gil\Desktop\FRST64.exe
2015-12-30 12:54 - 2015-12-30 12:54 - 00103703 _____ C:\Users\Gil\Downloads\LakevilleSubwayPayrollReports (1).xls
2015-12-30 12:51 - 2015-12-30 12:51 - 00121631 _____ C:\Users\Gil\Downloads\EddyStreetSubwayPayrollReports (1).xls
2015-12-30 12:45 - 2015-12-30 12:45 - 00005732 _____ C:\Users\Gil\Downloads\ACFrOgAw-MUev_iDt-cKy5ts1EKZvB98s9udPusWi0PsJOEU5Jk22H1KC3LlA8q3rGdTs5YOndOC5VySRS1vccXx7xWrrCPPQ2vHL2FxVg_7tCL92xK_O8KTJNQ25Qw=.pdf
2015-12-30 12:44 - 2015-12-30 12:44 - 00022789 _____ C:\Users\Gil\Downloads\ACFrOgAR2XgA7qTPrak0mIJylshK7ZhBBJRWiRZ3M1sMDfFw7lTpWToe_snTVC0Imbe7n_vYPFJcf3aYA_m0BfuvdmNFIp3gWDwaB8LL-wPhQPo30vD7IFaHbG6wEas=.pdf
2015-12-30 12:39 - 2015-12-30 12:39 - 00197679 _____ C:\Users\Gil\Downloads\ListChkdskResult.exe
2015-12-30 12:39 - 2015-12-30 12:39 - 00013560 _____ C:\Users\Gil\Desktop\ListChkdskResult.txt
2015-12-30 12:28 - 2015-12-30 12:28 - 00069203 _____ C:\Users\Gil\Downloads\ACFrOgCb4k1paMKbsoMPxL_Gm78emqA3JzfFgLF3mgzm5ScysoyHpFLMkqCAvf_I0OVbA7KD7BB88VS1fLqlI9l3ywVjYNTM7QG1HXvrzIY6-Mko7aUIQOhNf00UoFs=.pdf
2015-12-29 14:54 - 2015-12-29 14:54 - 00012201 _____ C:\Users\Gil\Downloads\Melissa_Whetsel.pdf
2015-12-29 13:55 - 2015-12-29 13:55 - 00128642 _____ C:\Users\Gil\Downloads\kirk_application_2014.pdf
2015-12-29 13:06 - 2015-12-29 13:06 - 00010454 _____ C:\Users\Gil\Downloads\Tierra_Robinson.pdf
2015-12-29 11:21 - 2015-12-29 11:21 - 00050673 _____ C:\Users\Gil\Downloads\+15742470889-1223-140930-460.pdf
2015-12-28 17:40 - 2015-12-28 17:40 - 00006407 _____ C:\Users\Gil\Downloads\Brandi_Lafler (1).pdf
2015-12-28 17:23 - 2015-12-28 17:23 - 00008121 _____ C:\Users\Gil\Downloads\Beverly_Lax_Floyd.pdf
2015-12-28 17:22 - 2015-12-28 17:22 - 00006852 _____ C:\Users\Gil\Downloads\Jensen_Edsall.pdf
2015-12-28 17:22 - 2015-12-28 17:22 - 00006407 _____ C:\Users\Gil\Downloads\Brandi_Lafler.pdf
2015-12-28 13:14 - 2015-12-28 13:14 - 00035326 _____ C:\Users\Gil\Downloads\ACFrOgA8FMlXfCNC3iG1q0q6Za1GkVVVsN9GVslotycdhI0iqu-vIvvzJHWxglmFVEkOkHDOHlrg8PEfvjT-gIjSnP7MMFfrgOGQejpSg8SlWAL3GmCCmHX7BGi3ZnE=.pdf
2015-12-28 06:22 - 2015-12-28 06:22 - 05988008 _____ C:\Users\Gil\Downloads\CBS.zip
2015-12-28 06:15 - 2015-12-28 06:15 - 05988008 _____ C:\Users\Gil\Desktop\CBS.zip
2015-12-28 06:09 - 2015-12-28 10:23 - 00001126 _____ C:\Users\Gil\Desktop\SFCFix.txt
2015-12-28 06:09 - 2015-12-28 10:23 - 00000000 ____D C:\SFCFix
2015-12-28 04:43 - 2015-12-28 04:43 - 01319424 _____ (niemiro) C:\Users\Gil\Downloads\SFCFix.exe
2015-12-28 04:00 - 2015-12-28 04:00 - 00000000 ___HD C:\$Windows.~WS
2015-12-28 03:59 - 2015-12-28 03:59 - 07635472 _____ (Microsoft Corporation) C:\Users\Gil\Downloads\GetWindows10-pse_ggl (1).exe
2015-12-28 03:58 - 2015-12-28 03:58 - 04827551 _____ C:\Users\Gil\Downloads\Windows8.1-KB2919442-x86.msu
2015-12-28 03:57 - 2015-12-28 03:57 - 07635472 _____ (Microsoft Corporation) C:\Users\Gil\Downloads\GetWindows10-pse_ggl.exe
2015-12-28 03:54 - 2015-12-28 03:55 - 75351558 _____ C:\Users\Gil\Downloads\Windows8.1-KB2934018-x86.msu
2015-12-28 03:54 - 2015-12-28 03:55 - 26455888 _____ C:\Users\Gil\Downloads\Windows8.1-KB2932046-x86.msu
2015-12-28 03:54 - 2015-12-28 03:55 - 10452742 _____ C:\Users\Gil\Downloads\Windows8.1-KB2938439-x86.msu
2015-12-28 03:54 - 2015-12-28 03:54 - 02574218 _____ C:\Users\Gil\Downloads\Windows8.1-KB2959977-x86.msu
2015-12-28 03:54 - 2015-12-28 03:54 - 00309544 _____ C:\Users\Gil\Downloads\Windows8.1-KB2937592-x86.msu
2015-12-28 03:54 - 2015-12-28 03:54 - 00036016 _____ (Microsoft Corporation) C:\Users\Gil\Downloads\clearcompressionflag.exe
2015-12-28 03:53 - 2015-12-28 03:53 - 00000000 ____D C:\8b40cc25d43ee1cc2d61baab
2015-12-28 03:50 - 2015-12-28 03:53 - 334517159 _____ C:\Users\Gil\Downloads\Windows8.1-KB2919355-x86.msu
2015-12-28 03:29 - 2015-12-28 03:29 - 00000000 ____D C:\Users\Gil\AppData\Roaming\ClassicShell
2015-12-28 03:20 - 2015-12-28 03:35 - 00000000 ____D C:\AdwCleaner
2015-12-28 03:15 - 2015-12-28 03:15 - 01743360 _____ C:\Users\Gil\Downloads\AdwCleaner.exe
2015-12-28 02:52 - 2015-12-28 02:52 - 00000000 ____D C:\ProgramData\Malwarebytes
2015-12-28 02:49 - 2015-12-28 02:50 - 22908888 _____ (Malwarebytes ) C:\Users\Gil\Downloads\mbam-setup-2.2.0.1024.exe
2015-12-27 21:09 - 2015-12-27 21:09 - 07635472 _____ (Microsoft Corporation) C:\Users\Gil\Downloads\GetWindows10-sds_____________.exe
2015-12-27 17:34 - 2015-12-27 17:34 - 07635472 _____ (Microsoft Corporation) C:\Users\Gil\Downloads\GetWindows10-Web_Default_Attr.exe
2015-12-27 17:34 - 2015-12-27 17:34 - 00000000 ____D C:\$WINDOWS.~BT
2015-12-18 17:16 - 2015-12-18 17:15 - 02264920 _____ C:\Users\Public\DHAVAL PATEL 2013326112079.pdf
2015-12-18 16:54 - 2015-12-18 16:54 - 00107806 _____ C:\Users\Gil\Downloads\Greater MMBC- Letter.pdf
2015-12-18 15:46 - 2015-12-18 15:43 - 00098674 _____ C:\Users\Public\Documents\Logos_Business Entity Report Filing2015.pdf
2015-12-18 15:46 - 2015-12-18 15:42 - 00098671 _____ C:\Users\Public\Documents\Pure Assembly BER.pdf
2015-12-18 15:46 - 2015-12-14 09:18 - 00098527 _____ C:\Users\Public\Documents\TCD Business Entity Report Filing.pdf
2015-12-18 15:16 - 2015-12-18 15:16 - 00061737 _____ C:\Users\Gil\Downloads\+17185275661-1218-144715-226.pdf
2015-12-18 10:10 - 2015-12-18 10:08 - 03640802 _____ C:\Users\Public\BROWNCLARA 2014.pdf
2015-12-17 17:03 - 2013-07-17 14:34 - 05465600 _____ C:\Users\Public\Documents\CAS Brochure with testimonials.pub
2015-12-17 17:01 - 2013-07-05 08:04 - 04530688 _____ C:\Users\Public\Documents\CAS Brochure 2.pub
2015-12-17 16:59 - 2015-12-17 16:59 - 03474938 _____ C:\Users\Public\Documents\CAS Brochure.pdf
2015-12-17 14:09 - 2015-12-17 14:09 - 01839520 _____ (LogMeIn, Inc.) C:\Users\Gil\Downloads\Support-LogMeInRescue (2).exe
2015-12-15 16:58 - 2015-12-15 16:58 - 00251399 _____ C:\Users\Gil\Downloads\ECCU Statements_NHOM (2).pdf
2015-12-15 13:54 - 2015-12-15 13:54 - 00301871 _____ C:\Users\Gil\Downloads\GeneratePdf (2).pdf
2015-12-15 13:40 - 2015-12-15 13:40 - 00507977 _____ C:\Users\Gil\Downloads\ACFrOgDqkHo9rIDaqvUJrvdmURdBVLELeq1ByN_0cS4S1olIaCRBkRw6jhSA5Q_W8El1DkN4MGG7juj-192rBjDydCcFBTCC7pCxsPUYHNyL0DaAefYHk97-jtXX3bI=.pdf
2015-12-14 13:21 - 2015-12-14 13:21 - 00666785 _____ C:\Users\Gil\Downloads\ACFrOgCRWJrwswLKuNQYKB2s4ZOCWX6d0bWs6ZmtedJxjeGMlNlrAA513h8853OBD2cMpOvS_80jAH2uVovbUeWYEPn9OqyO_CAc-C6MtKS4449HoxGkheF3u24uXt0=.pdf
2015-12-14 09:21 - 2015-12-14 09:18 - 00098527 _____ C:\Users\Public\TCD Business Entity Report Filing.pdf
2015-12-14 09:06 - 2015-12-14 09:06 - 00224365 _____ C:\Users\Gil\Downloads\ViewPdfForm (18).pdf
2015-12-14 06:49 - 2015-12-14 06:49 - 00001808 _____ C:\Users\Public\Desktop\iTunes.lnk
2015-12-14 06:49 - 2015-12-14 06:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2015-12-14 06:48 - 2015-12-14 06:49 - 00000000 ____D C:\Program Files\iTunes
2015-12-14 06:48 - 2015-12-14 06:48 - 00000000 ____D C:\Program Files\iPod
2015-12-14 06:48 - 2015-12-14 06:48 - 00000000 ____D C:\Program Files (x86)\iTunes
2015-12-12 10:11 - 2015-12-12 10:11 - 00000000 ____D C:\Users\Gil\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2015-12-11 14:47 - 2015-12-11 14:47 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCloud
2015-12-11 14:46 - 2015-12-11 14:46 - 00001900 _____ C:\Users\Public\Desktop\QuickTime Player.lnk
2015-12-11 14:46 - 2015-12-11 14:46 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
2015-12-11 14:46 - 2015-12-11 14:46 - 00000000 ____D C:\Program Files (x86)\QuickTime
2015-12-11 11:06 - 2015-12-11 11:06 - 00226857 _____ C:\Users\Gil\Downloads\5224-January 2015.pdf
2015-12-11 11:06 - 2015-12-11 11:06 - 00224133 _____ C:\Users\Gil\Downloads\5224-February 2015.pdf
2015-12-11 11:06 - 2015-12-11 11:06 - 00222960 _____ C:\Users\Gil\Downloads\5972 March 2015.pdf
2015-12-11 11:06 - 2015-12-11 11:06 - 00220520 _____ C:\Users\Gil\Downloads\5078 March 2015.pdf
2015-12-11 11:06 - 2015-12-11 11:06 - 00220256 _____ C:\Users\Gil\Downloads\1878 March 2015.pdf
2015-12-11 11:06 - 2015-12-11 11:06 - 00219686 _____ C:\Users\Gil\Downloads\4595 March 2015.pdf
2015-12-11 11:06 - 2015-12-11 11:06 - 00206508 _____ C:\Users\Gil\Downloads\0555 March 2015.pdf
2015-12-11 11:05 - 2015-12-11 11:06 - 00218648 _____ C:\Users\Gil\Downloads\1894 March 2015.pdf
2015-12-11 11:05 - 2015-12-11 11:05 - 00227839 _____ C:\Users\Gil\Downloads\5224-March 2015.pdf
2015-12-11 11:05 - 2015-12-11 11:05 - 00220695 _____ C:\Users\Gil\Downloads\1886 March 2015.pdf
2015-12-11 11:05 - 2015-12-11 11:05 - 00219367 _____ C:\Users\Gil\Downloads\5115 March 2015.pdf
2015-12-04 18:32 - 2015-12-04 18:32 - 00306340 _____ C:\Users\Gil\Downloads\VCP_Interpretive_Guide_final_4-1-14.pdf
2015-12-04 18:32 - 2015-12-04 18:32 - 00252661 _____ C:\Users\Gil\Downloads\VCP_Interpretive_Guide.pdf
2015-12-04 18:30 - 2015-12-04 18:30 - 00158082 _____ C:\Users\Gil\Downloads\49443.pdf
2015-12-03 12:07 - 2015-12-03 12:07 - 03121525 _____ C:\Users\Gil\Downloads\103WaysToSave.pdf
2015-12-03 11:20 - 2015-12-03 11:20 - 00891300 _____ C:\Users\Gil\Downloads\Year-End-Letter-2015.pdf
2015-12-03 08:10 - 2015-12-03 08:10 - 01068534 _____ C:\Users\Gil\Downloads\ACFrOgDAiVYr4-p-YlsYJHiMJgchFVJRiTZmxFIZJNh-U-GoQWPSWNU754twhE0oUxDCE9v3Y-spuDmxdYXz53vnGMYWkDKjO9Qkc583KGSvfEvWZvhFinlbUHmkgAY=.pdf
2015-12-03 07:28 - 2015-12-03 08:16 - 00031103 _____ C:\Users\Gil\Downloads\Pastor List Sarasota 3.xlsx
2015-12-02 17:37 - 2015-12-02 17:37 - 00121367 _____ C:\Users\Gil\Downloads\Payroll Summary (4).xls
2015-12-02 16:23 - 2015-12-02 16:23 - 00078943 _____ C:\Users\Gil\Downloads\1070-126-54646056.pdf
2015-12-01 15:01 - 2015-12-01 15:01 - 00032108 _____ C:\Users\Gil\Downloads\ACFrOgBjNqHKGOOYQJeCsMju5UBsehwusQimfWKPJh7xn-KlJP8LdD0iDVAPM7YcWECiZP0tZ1kflY3YNADOBvSYThtsMdgfYezKkZQEKIGbWbw60b5Eo-H892jLckw=.pdf
2015-12-01 14:13 - 2015-12-01 14:40 - 00334728 _____ C:\Users\Gil\Downloads\Alpesh Patel- F433-A.pdf
2015-12-01 13:53 - 2015-12-01 13:53 - 00554552 _____ C:\Users\Gil\Downloads\ACFrOgBcWi9E4qM9dAUE_qImUb_YMhHObIRSsUUmzp1mNY7T2HSSkSl9-WvOzjeWA24B3KoXJJTWhZC-i991xEejdmj6iPlqdck-2oBKQMJP06zA7401-c6LqppvFoA=.pdf
2015-12-01 13:53 - 2015-12-01 13:53 - 00286949 _____ C:\Users\Gil\Downloads\F433-A (2).pdf
2015-11-30 15:22 - 2015-11-30 15:22 - 00093203 _____ C:\Users\Gil\Downloads\PressReleaseLetsBuyBlack365 20151127.pdf
2015-11-30 15:22 - 2015-11-30 15:22 - 00093203 _____ C:\Users\Gil\Downloads\PressReleaseLetsBuyBlack365 20151127 (1).pdf
2015-11-30 10:38 - 2015-11-30 10:38 - 00273097 _____ C:\Users\Gil\Downloads\Pearl Insurance Supplemental Form.pdf
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-12-30 13:24 - 2014-02-27 10:33 - 00000574 _____ C:\WINDOWS\Tasks\G2MUpdateTask-S-1-5-21-2509790399-2890906804-1317435896-1001.job
2015-12-30 13:23 - 2015-06-04 15:45 - 00003672 _____ C:\WINDOWS\System32\Tasks\G2MUploadTask-S-1-5-21-2509790399-2890906804-1317435896-1001
2015-12-30 13:23 - 2015-06-04 15:45 - 00000670 _____ C:\WINDOWS\Tasks\G2MUploadTask-S-1-5-21-2509790399-2890906804-1317435896-1001.job
2015-12-30 13:23 - 2014-02-27 10:33 - 00003576 _____ C:\WINDOWS\System32\Tasks\G2MUpdateTask-S-1-5-21-2509790399-2890906804-1317435896-1001
2015-12-30 13:23 - 2013-08-22 08:36 - 00000000 ____D C:\Windows
2015-12-30 13:16 - 2014-01-20 10:35 - 00000830 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-12-30 13:10 - 2015-06-25 12:00 - 00000934 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-2509790399-2890906804-1317435896-1001UA.job
2015-12-30 13:08 - 2014-02-17 09:05 - 00000924 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2509790399-2890906804-1317435896-1001UA.job
2015-12-30 12:54 - 2014-01-17 23:20 - 00000000 ____D C:\Users\Gil\AppData\Local\Packages
2015-12-30 12:49 - 2014-01-17 23:37 - 00000930 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2015-12-30 12:41 - 2015-08-21 07:30 - 00000000 ____D C:\Users\Gil\AppData\Local\ClassicShell
2015-12-30 12:29 - 2014-02-24 09:50 - 00000000 ____D C:\ProgramData\MFAData
2015-12-30 02:36 - 2014-02-17 01:32 - 00065536 _____ C:\WINDOWS\system32\spu_storage.bin
2015-12-30 02:15 - 2013-08-22 08:36 - 00000000 ____D C:\WINDOWS\Inf
2015-12-29 17:49 - 2014-01-17 23:37 - 00000926 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2015-12-29 17:08 - 2014-02-17 09:05 - 00000872 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2509790399-2890906804-1317435896-1001Core.job
2015-12-29 12:16 - 2014-01-20 10:35 - 00003718 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2015-12-29 06:17 - 2014-01-17 23:22 - 00003930 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{D68825D1-B856-4122-8B27-6C1EAD4A5443}
2015-12-29 02:10 - 2015-06-25 12:00 - 00000882 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-2509790399-2890906804-1317435896-1001Core.job
2015-12-28 12:45 - 2014-01-17 23:29 - 00003600 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2509790399-2890906804-1317435896-1001
2015-12-28 07:04 - 2012-07-26 02:59 - 00000000 ____D C:\WINDOWS\CbsTemp
2015-12-28 04:43 - 2014-09-02 09:55 - 00000000 ____D C:\Users\Gil\AppData\Local\ElevatedDiagnostics
2015-12-28 04:02 - 2014-02-17 04:30 - 00000000 ___DC C:\WINDOWS\Panther
2015-12-28 03:49 - 2013-11-14 02:28 - 00956476 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2015-12-28 03:43 - 2013-08-22 09:45 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-12-28 03:42 - 2013-08-22 08:25 - 00262144 ___SH C:\WINDOWS\system32\config\BBI
2015-12-27 22:24 - 2015-08-28 17:05 - 00000000 ____D C:\Users\Gil\QB
2015-12-27 20:49 - 2014-01-21 15:23 - 00000000 ____D C:\Program Files (x86)\TeamViewer
2015-12-27 17:36 - 2013-08-22 08:25 - 00262144 ___SH C:\WINDOWS\system32\config\ELAM
2015-12-25 08:54 - 2014-05-19 10:58 - 00003422 _____ C:\WINDOWS\System32\Tasks\Apple Diagnostics
2015-12-23 06:59 - 2015-11-03 21:04 - 00001026 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 11.lnk
2015-12-23 06:59 - 2015-11-03 21:04 - 00001014 _____ C:\Users\Public\Desktop\TeamViewer 11.lnk
2015-12-18 11:45 - 2015-08-12 15:28 - 00000090 _____ C:\WINDOWS\QBChanUtil_Trigger.ini
2015-12-17 13:39 - 2015-08-12 15:31 - 00000000 ____D C:\Users\Gil\AppData\Local\SugarSync
2015-12-17 13:38 - 2014-05-19 12:13 - 00000000 ____D C:\Users\Gil\AppData\Local\F4D7FF1A-50EE-4B39-A220-92E4671548C7.aplzod
2015-12-17 13:38 - 2014-05-01 17:56 - 00000000 ____D C:\Users\Gil\AppData\Local\Apple Computer
2015-12-17 06:02 - 2015-04-27 10:02 - 00000000 ___RD C:\Users\Gil\iCloudDrive
2015-12-16 14:05 - 2014-07-07 11:03 - 00000000 ____D C:\Users\Gil\AppData\Roaming\Canon
2015-12-16 13:55 - 2014-07-07 11:12 - 00000000 ____D C:\Users\Gil\Documents\Scanned Docs
2015-12-15 16:50 - 2014-01-17 23:38 - 00002246 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-12-15 13:09 - 2015-03-03 18:44 - 00000000 ____D C:\Users\Gil\Documents\Behrens 2014
2015-12-14 06:48 - 2014-05-01 17:53 - 00000000 ____D C:\Program Files\Common Files\Apple
2015-12-12 10:12 - 2014-04-26 08:53 - 00000000 ____D C:\Users\Gil\AppData\Roaming\Dropbox
2015-12-11 20:30 - 2015-05-12 23:49 - 00000000 ___RD C:\Users\Gil\OneDrive
2015-12-11 20:30 - 2014-09-01 01:47 - 00003098 _____ C:\WINDOWS\System32\Tasks\Microsoft OneDrive Auto Update Task-S-1-5-21-2509790399-2890906804-1317435896-1001
2015-12-11 18:15 - 2015-10-12 05:13 - 00003158 _____ C:\WINDOWS\System32\Tasks\HPCeeScheduleForGil
2015-12-11 18:15 - 2015-10-12 05:13 - 00000348 _____ C:\WINDOWS\Tasks\HPCeeScheduleForGil.job
2015-12-11 11:10 - 2014-02-10 10:56 - 02072576 ___SH C:\Users\Gil\Downloads\Thumbs.db
2015-12-03 17:44 - 2014-01-17 23:37 - 00003902 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2015-12-03 17:44 - 2014-01-17 23:37 - 00003666 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2015-12-03 17:03 - 2014-02-17 09:05 - 00003866 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2509790399-2890906804-1317435896-1001UA
2015-12-03 17:03 - 2014-02-17 09:05 - 00003486 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2509790399-2890906804-1317435896-1001Core
2015-11-30 10:42 - 2014-02-17 01:37 - 00000000 ____D C:\Users\Gil
==================== Files in the root of some directories =======
2014-02-25 20:24 - 2014-06-24 17:02 - 0003743 _____ () C:\Program Files (x86)\Mozilla Firefoxsafeguard-secure-search.xml
2015-09-24 13:14 - 2015-09-24 13:14 - 0003379 _____ () C:\Users\Gil\AppData\Roaming\QBFileDrTool.log
2015-04-27 16:13 - 2015-04-27 16:13 - 0000723 _____ () C:\ProgramData\ProgramData - Shortcut.lnk
Some files in TEMP:
====================
C:\Users\Gil\AppData\Local\Temp\Abspdf.exe
C:\Users\Gil\AppData\Local\Temp\acfpdfu.dll
C:\Users\Gil\AppData\Local\Temp\acfpdfuamd64.dll
C:\Users\Gil\AppData\Local\Temp\acfpdfui.dll
C:\Users\Gil\AppData\Local\Temp\acfpdfuia64.dll
C:\Users\Gil\AppData\Local\Temp\acfpdfuiamd64.dll
C:\Users\Gil\AppData\Local\Temp\acfpdfuiia64.dll
C:\Users\Gil\AppData\Local\Temp\cdintf.dll
C:\Users\Gil\AppData\Local\Temp\COMAP.EXE
C:\Users\Gil\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmplatpwd.dll
C:\Users\Gil\AppData\Local\Temp\PDFPRT400.exe
C:\Users\Gil\AppData\Local\Temp\RingCentralForWindows-7.4.1.exe
C:\Users\Gil\AppData\Local\Temp\SkypeSetup.exe
C:\Users\Gil\AppData\Local\Temp\sqlite3.dll
C:\Users\Gil\AppData\Local\Temp\xmllite.dll
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-12-28 06:54
==================== End of FRST.txt ============================