==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-06-22 21:02 - 2013-08-22 16:36 - 00000000 ____D C:\windows\system32\sru
2015-06-22 21:01 - 2014-11-19 21:05 - 00000000 ____D C:\Users\Andy\AppData\Roaming\Skype
2015-06-22 20:58 - 2014-11-18 21:29 - 00000000 ____D C:\Users\Andy\AppData\Local\Pokki
2015-06-22 20:43 - 2014-11-18 21:52 - 00136408 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2015-06-22 20:43 - 2013-12-13 22:39 - 01507618 _____ C:\windows\WindowsUpdate.log
2015-06-22 20:16 - 2015-05-05 21:01 - 00004956 _____ C:\windows\System32\Tasks\Microsoft Office 15 Sync Maintenance for ANDYB-Andy AndyB
2015-06-22 20:16 - 2014-11-28 00:55 - 00000000 __SHD C:\Users\Andy\AppData\Local\EmieBrowserModeList
2015-06-22 20:16 - 2014-11-25 19:50 - 00000000 __SHD C:\Users\Andy\AppData\Local\EmieUserList
2015-06-22 20:16 - 2014-11-25 19:50 - 00000000 __SHD C:\Users\Andy\AppData\Local\EmieSiteList
2015-06-22 19:07 - 2014-11-18 21:39 - 00003910 _____ C:\windows\System32\Tasks\User_Feed_Synchronization-{F86E7D95-7EBA-4E82-8488-02425C2010A8}
2015-06-22 19:01 - 2014-11-19 21:11 - 00000000 ___RD C:\Users\Andy\Dropbox
2015-06-22 19:01 - 2014-11-19 21:07 - 00000000 ____D C:\Users\Andy\AppData\Roaming\Dropbox
2015-06-22 19:00 - 2014-11-18 23:03 - 00000000 ____D C:\Program Files (x86)\Steam
2015-06-22 18:59 - 2014-11-24 22:02 - 00000526 ____H C:\windows\Tasks\SoftwareProvider-S-394265216.job
2015-06-22 18:59 - 2014-11-22 23:12 - 00000000 __RDO C:\Users\Andy\OneDrive
2015-06-22 18:58 - 2013-08-22 15:46 - 00042777 _____ C:\windows\setupact.log
2015-06-22 18:58 - 2013-08-22 15:45 - 00000006 ____H C:\windows\Tasks\SA.DAT
2015-06-21 23:41 - 2013-12-13 23:16 - 00027136 _____ C:\windows\system32\VfService.trf
2015-06-21 22:36 - 2014-11-18 21:37 - 00003598 _____ C:\windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3031754157-338325955-3198346124-1002
2015-06-21 22:24 - 2013-10-07 19:23 - 00082576 _____ C:\windows\PFRO.log
2015-06-21 19:26 - 2013-10-07 19:27 - 00865408 _____ C:\windows\system32\PerfStringBackup.INI
2015-06-21 19:20 - 2013-08-22 14:25 - 00262144 ___SH C:\windows\system32\config\BBI
2015-06-20 18:33 - 2013-08-22 16:36 - 00000000 ____D C:\windows\AppReadiness
2015-06-20 17:30 - 2015-01-10 22:26 - 00098216 _____ (Oracle Corporation) C:\windows\SysWOW64\WindowsAccessBridge-32.dll
2015-06-20 17:30 - 2015-01-10 22:25 - 00000000 ____D C:\Program Files (x86)\Java
2015-06-20 17:29 - 2014-11-25 19:52 - 00000000 ____D C:\Users\Andy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2015-06-20 17:29 - 2014-11-25 19:52 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2015-06-20 17:29 - 2014-11-25 19:52 - 00000000 ____D C:\Program Files\WinRAR
2015-06-19 23:08 - 2013-08-22 16:36 - 00000000 ____D C:\windows\rescache
2015-06-19 19:24 - 2015-03-07 18:07 - 00000000 ____D C:\ProgramData{51ed5111-b074-b87d-51ed-d5111b074446}
2015-06-18 19:53 - 2014-11-19 00:56 - 00000000 ____D C:\ProgramData\Skype
2015-06-16 19:56 - 2014-11-20 22:19 - 00000000 ____D C:\windows\system32\MRT
2015-06-16 19:46 - 2014-11-20 22:19 - 140135120 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2015-06-16 00:12 - 2014-11-18 23:05 - 00000000 ____D C:\Users\Andy\AppData\Roaming\BitComet
2015-06-11 00:34 - 2014-12-13 20:46 - 00000000 ____D C:\windows\system32\appraiser
2015-06-11 00:34 - 2014-11-28 00:33 - 00000000 ___SD C:\windows\system32\CompatTel
2015-06-11 00:34 - 2013-08-22 16:36 - 00000000 ___RD C:\windows\ToastData
2015-06-10 20:11 - 2013-08-22 16:20 - 00000000 ____D C:\windows\CbsTemp
2015-06-10 19:15 - 2013-08-22 15:44 - 00492000 _____ C:\windows\system32\FNTCACHE.DAT
2015-06-09 23:59 - 2013-08-22 16:36 - 00000000 ____D C:\windows\PolicyDefinitions
2015-06-08 20:41 - 2013-08-22 16:36 - 00000000 ____D C:\windows\Speech
2015-06-08 19:47 - 2014-11-18 21:52 - 00001125 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-06-08 19:47 - 2014-11-18 21:52 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-06-08 19:47 - 2014-11-18 21:51 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-06-05 19:20 - 2014-11-24 22:01 - 00000000 ____D C:\ProgramData\18041650861050864990
2015-06-03 17:18 - 2014-11-28 00:36 - 00792568 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2015-06-03 17:18 - 2014-11-28 00:36 - 00178168 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-06-01 19:16 - 2014-11-18 21:33 - 00002283 _____ C:\Users\Andy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PC App Store.lnk
2015-05-31 22:43 - 2014-11-18 21:42 - 00000000 ____D C:\Users\Andy\AppData\Local\CrashDumps
2015-05-23 12:15 - 2015-05-21 20:47 - 00027579 _____ C:\Users\Andy\Documents\Eurovision Spreadsheet.xlsx
2015-05-23 11:29 - 2014-11-19 00:56 - 00000000 ___RD C:\Program Files (x86)\Skype

==================== Files in the root of some directories =======

2015-06-05 19:20 - 2015-06-22 19:59 - 0000024 _____ () C:\Users\Andy\AppData\Roaming\appdataFr25.bin
2015-03-18 22:37 - 2015-05-12 19:53 - 0000020 _____ () C:\Users\Andy\AppData\Roaming\appdataFr3.bin
2014-11-18 23:57 - 2014-11-18 23:57 - 1249792 _____ (http://www.ruby-lang.org/) C:\Users\Andy\AppData\Roaming\msvcr90-ruby191.dll
2015-05-12 20:19 - 2015-05-12 20:19 - 0000000 _____ () C:\Users\Andy\AppData\Local\Temp.dat
2013-12-13 22:48 - 2013-12-13 22:48 - 0000000 ____H () C:\ProgramData\DP45977C.lfl

Some files in TEMP:

C:\Users\Andy\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpgu9czm.dll

==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2015-06-19 21:58

==================== End of log ============================