Welcome to WindowsInstructed Forums

Welcome to the WindowsInstructed Forums

Sign-up for an account today to receive free malware removal help. Personal Windows help and much more. Or continue as a guest and ask any question you would like to ask us! Please do remember that being a member you get advantages like notifications of replies and faster replies from most members. Also members don't see ads ;) 

We hope to help you with your issues.

The WindowsInstructed Forums Staff

All Activity

This stream auto-updates   

  1. Today
  2. Yesterday
  3. http://bit.ly/2b4BrQB

  4. http://goo.gl/uEqm8T

  5. Last week
  6. http://projectgold.ru/aliexpressless/milesi_brand_Women_Leather___Busine_aUj4cMxr8.html

  7. http://goo.gl/LQEYpC

  8. Earlier
  9. Download the Ultimate Boot CD for windows. Or the FalconFour CD Start the video below at 53 minutes. Follow the instructions for using the Ultimate Boot CD. Run the Fix HDC Hard Drive Controller fix...
  10. My laptop shows the repairing disk errors and wouldn't restart, I've tried to reboot it by pressing the power button, but it still goes back to the same screen. I've tried following the instructions posted below, what do I do now?
  11. Sorry for the delay, you still having issues?
  12. Sorry for delay, still having issues?
  13. Hello... Please help.. how can i fix this problem on my laptop.. "repairing disk errors" .. been waiting for hours but still the windows not loading.. =\ thanks!
  14. my computer behaving weird. on start windows start and after logo screen is blue and there are three icon and curser. I click on power and opens three option.I click on restarts and it works very well and can work there is no other problem I am novice please advise.
  15. So I got both of those tools but still my laptop just goes straight to this loop there is nothing I can do to stop this loop I've tried ever thibg possible
  16. Not a problem. In return buy the next home less person you see a 24 ounce beer for me. That will certainly bring that person joy.
  17. Yes unfortunate.... I just remove trash, I'd suggest not running it. I really do not care to go into detail. Optimize your internet connection. Click here for instructions. suggest the following in place of adblock. Alternate DNS Server. Ad Blocking DNS. Ublock Origin. Anti Ad Block Killer. Also, keep your browsing private with these tools: Self Destructing Cookies. Self Destructing Cookies Chrome. Some items to keep you safe on the internet. VooDoo Shield. control of what is running on your machine Qualys BrowserCheck To update plugins. Web Of Trust To Avoid Shady Websites. Unchecky To Avoid Bundled Software. Privazer To Clean up your mahcine. Now Lets Clean up the tools we used and remove old restore points. Download DelFix by "Xplode" to your Desktop. Right Click the tool and Run as Admin ( Xp Users Double Click) Put a check mark next the items below: Remove disinfection tools Create registry backup Purge System Restore Now click on "Run" button. allow the program to complete its work. all the tools we used will be removed. Tool will create and open a log report (DelFix.txt) Note: The report can be located at the following location C:\DelFix.txt
  18. Hello Kris, I think that has solved the problem. I have not seen the error dialog since applying the last step. What clean up work should I do before putting this system to work? I noticed my screen gadgets are gone. I really like to monitor CPU load and Temp, GPU load and Temp, Network connection and activity, and Hard disk drives connection and free space. I guess they are a security risk? Thank you for the help. Paul
  19. If the above fixlist fails to solve the issue, then please upload a new ZHP Diag log and we will go from there.
  20. FRST Fix. Download attached fixlist.txt file and save it to the Desktop. NOTE. It's important that both files, FRST/FRST64 and fixlist.txt are in the same location or the fix will not work. NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system Run FRST/FRST64 and press the Fix button just once and wait. If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run. When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply. fixlist.txt ClearLNK Download ClearLNK save it to your desktop. Drag the file Shortcut.txt made with FRST earlier. As per picture. A report on the work as a file ClearLNK- <date> .log Will be produced, post that log.
  21. Ok all tasks are completed the Kill Rogue report: RogueKiller V12.9.9.0 (x64) [Feb 27 2017] (Free) by Adlice Software mail : http://www.adlice.com/contact/ Feedback : http://forum.adlice.com Website : http://www.adlice.com/download/roguekiller/ Blog : http://www.adlice.com Operating System : Windows 10 (10.0.14393) 64 bits version Started in : Normal mode User : Dad [Administrator] Started from : C:\Users\TT\Desktop\RogueKillerX64.exe Mode : Delete -- Date : 03/01/2017 17:51:53 (Duration : 00:13:54) ¤¤¤ Processes : 0 ¤¤¤ ¤¤¤ Registry : 17 ¤¤¤ [PUP.Gen1] (X86) HKEY_LOCAL_MACHINE\Software\Mail.Ru -> Deleted [PUP.Gen1] (X86) HKEY_LOCAL_MACHINE\Software\Uniblue -> Deleted [PUP.Gen1] (X64) HKEY_USERS\S-1-5-21-2438100261-443141923-189968324-1001\Software\CoinisRevShare -> Deleted [PUP.Gen1] (X64) HKEY_USERS\S-1-5-21-2438100261-443141923-189968324-1001\Software\DownloadAdmin -> Deleted [PUP.Gen1] (X64) HKEY_USERS\S-1-5-21-2438100261-443141923-189968324-1001\Software\Mail.Ru -> Deleted [PUP.Gen1] (X64) HKEY_USERS\S-1-5-21-2438100261-443141923-189968324-1001\Software\ProductSetup -> Deleted [PUP.Gen1] (X86) HKEY_USERS\S-1-5-21-2438100261-443141923-189968324-1001\Software\CoinisRevShare -> Deleted [PUP.Gen1] (X86) HKEY_USERS\S-1-5-21-2438100261-443141923-189968324-1001\Software\DownloadAdmin -> Deleted [PUP.Gen1] (X86) HKEY_USERS\S-1-5-21-2438100261-443141923-189968324-1001\Software\Mail.Ru -> Deleted [PUP.Gen1] (X86) HKEY_USERS\S-1-5-21-2438100261-443141923-189968324-1001\Software\ProductSetup -> Deleted [PUP.Gen1] (X64) HKEY_USERS\S-1-5-21-2438100261-443141923-189968324-1001\Software\AppDataLow\Software\Mail.Ru -> Deleted [PUP.Gen1] (X86) HKEY_USERS\S-1-5-21-2438100261-443141923-189968324-1001\Software\AppDataLow\Software\Mail.Ru -> Deleted [PUM.HomePage] (X64) HKEY_USERS\S-1-5-21-2438100261-443141923-189968324-1001\Software\Microsoft\Internet Explorer\Main | Start Page : http://mail.ru/cnt/10445?gp=811036 -> Replaced (http://go.microsoft.com/fwlink/p/?LinkId=255141) [PUM.HomePage] (X86) HKEY_USERS\S-1-5-21-2438100261-443141923-189968324-1001\Software\Microsoft\Internet Explorer\Main | Start Page : http://mail.ru/cnt/10445?gp=811036 -> Replaced (http://go.microsoft.com/fwlink/p/?LinkId=255141) [Suspicious.Path|PUP.Gen0|PUP.Gen1] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules | {68F254C8-88A1-4428-BEB1-F9D33036C754} : v2.26|Action=Allow|Active=TRUE|Dir=In|Protocol=17|LPort=5353|App=C:\Users\TT\AppData\Local\Amigo\Application\amigo.exe|Name=Amigo (mDNS-In)|Desc=Inbound rule for Amigo to allow mDNS traffic.|EmbedCtxt=Amigo| [x] -> Deleted [PUM.Policies] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System | ConsentPromptBehaviorAdmin : 0 -> Replaced (2) [PUM.Policies] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System | ConsentPromptBehaviorAdmin : 0 -> Replaced (2) ¤¤¤ Tasks : 0 ¤¤¤ ¤¤¤ Files : 13 ¤¤¤ [PUP.Gen1][Folder] C:\ProgramData\Lavasoft\Web Companion -> Removed at reboot [91] [PUP.Gen1][File] C:\ProgramData\Lavasoft\Web Companion\Definitions\MaliciousUrlDaily.zip -> Deleted [PUP.Gen1][File] C:\ProgramData\Lavasoft\Web Companion\Definitions\MaliciousUrlWeekly.zip -> Deleted [PUP.Gen1][Folder] C:\ProgramData\Lavasoft\Web Companion\Definitions -> Deleted [PUP.Gen1][File] C:\ProgramData\Lavasoft\Web Companion\Icons\yahoo.ico -> Deleted [PUP.Gen1][Folder] C:\ProgramData\Lavasoft\Web Companion\Icons -> Deleted [PUP.Gen1][File] C:\ProgramData\Lavasoft\Web Companion\Logs\Webcompanion\adblocker.log -> Deleted [PUP.Gen1][File] C:\ProgramData\Lavasoft\Web Companion\Logs\Webcompanion\pupmanager.log -> Deleted [PUP.Gen1][File] C:\ProgramData\Lavasoft\Web Companion\Logs\Webcompanion\wcassistant.log -> Deleted [PUP.Gen1][File] C:\ProgramData\Lavasoft\Web Companion\Logs\Webcompanion\webcompanion.log -> Deleted [PUP.Gen1][Folder] C:\ProgramData\Lavasoft\Web Companion\Logs\Webcompanion -> Deleted [PUP.Gen1][File] C:\ProgramData\Lavasoft\Web Companion\Logs\WindowsService\WCAssistantServiceLog.log -> Removed at reboot [20] [PUP.Gen1][Folder] C:\ProgramData\Lavasoft\Web Companion\Logs\WindowsService -> Removed at reboot [91] [PUP.Gen1][Folder] C:\ProgramData\Lavasoft\Web Companion\Logs -> Removed at reboot [91] [PUP.Gen1][File] C:\ProgramData\Lavasoft\Web Companion\Options\ActiveFeatures.zip -> Deleted [PUP.Gen1][File] C:\ProgramData\Lavasoft\Web Companion\Options\CurrentReleaseNotes.txt -> Deleted [PUP.Gen1][File] C:\ProgramData\Lavasoft\Web Companion\Options\install.txt -> Deleted [PUP.Gen1][File] C:\ProgramData\Lavasoft\Web Companion\Options\LatestReleaseNotes.txt -> Deleted [PUP.Gen1][File] C:\ProgramData\Lavasoft\Web Companion\Options\partner.txt -> Deleted [PUP.Gen1][File] C:\ProgramData\Lavasoft\Web Companion\Options\ServicePartnerInfo.txt -> Deleted [PUP.Gen1][File] C:\ProgramData\Lavasoft\Web Companion\Options\Statistics.txt -> Deleted [PUP.Gen1][File] C:\ProgramData\Lavasoft\Web Companion\Options\UpdateServer.txt -> Deleted [PUP.Gen1][Folder] C:\ProgramData\Lavasoft\Web Companion\Options -> Deleted [PUP.Gen1][Folder] C:\ProgramData\Mail.Ru -> Deleted [PUP.Gen1][File] C:\ProgramData\Mail.Ru\Id -> Deleted [PUP.Gen1][Folder] C:\ProgramData\Uniblue -> Deleted [PUP.Gen1][File] C:\ProgramData\Uniblue\mac_id.dat -> Deleted [Hj.Shortcut][File] C:\Users\TT\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Mail.Ru.lnk [LNK@] C:\Windows\System32\rundll32.exe url,FileProtocolHandler "http://www.mail.ru/cnt/20775012?gp=811035" -> Shortcut cleaned [PUP.Gen1][Folder] C:\Users\TT\AppData\Roaming\Lavasoft\Web Companion -> Deleted [PUP.Gen1][File] C:\Users\TT\AppData\Roaming\Lavasoft\Web Companion\Options\Language.txt -> Deleted [PUP.Gen1][Folder] C:\Users\TT\AppData\Roaming\Lavasoft\Web Companion\Options -> Deleted [PUP.Gen1][Folder] C:\Users\TT\AppData\Local\Mail.Ru -> Deleted [PUP.Gen1][File] C:\Users\TT\AppData\Local\Mail.Ru\GoMailRu.ico -> Deleted [PUP.Gen1][File] C:\Users\TT\AppData\Local\Mail.Ru\mrkeeper.exe -> Deleted [PUP.Gen1][File] C:\Users\TT\AppData\Local\Mail.Ru\Sputnik\MailRu.ico -> Deleted [PUP.Gen1][Folder] C:\Users\TT\AppData\Local\Mail.Ru\Sputnik -> Deleted [PUP.Gen1][Folder] C:\Users\TT\AppData\Local\PackageAware -> Deleted [Tr.Gen0][File] C:\Users\TT\AppData\Local\Temp\1.txt -> Deleted [Tr.Gen0][File] C:\Users\TT\AppData\Local\Temp\5.txt -> Deleted [PUP.Gen1][Folder] C:\ProgramData\Lavasoft\Web Companion -> Removed at reboot [91] [PUP.Gen1][File] C:\ProgramData\Lavasoft\Web Companion\Logs\WindowsService\WCAssistantServiceLog.log -> Removed at reboot [20] [PUP.Gen1][Folder] C:\ProgramData\Lavasoft\Web Companion\Logs\WindowsService -> Removed at reboot [91] [PUP.Gen1][Folder] C:\ProgramData\Lavasoft\Web Companion\Logs -> Removed at reboot [91] [PUP.Gen1][Folder] C:\ProgramData\Mail.Ru -> ERROR [3] [PUP.Gen1][Folder] C:\ProgramData\Uniblue -> ERROR [3] [PUP.Gen1][Folder] C:\Program Files (x86)\Lavasoft\Web Companion -> Removed at reboot [91] [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\Ad-Aware Web Companion.exe -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\BCUEngineS.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\BCUSDK.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\BrowserDock.exe -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\BrowserDock.exe.config -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\BrowserManager.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\BrowserParameters.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\de-DE\Lavasoft.ArrowHelper.UI.resources.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\de-DE\Lavasoft.WebBar.UI.resources.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\de-DE\WebCompanion.resources.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\de-DE\WebCompanionInstaller.resources.dll -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Lavasoft\Web Companion\Application\de-DE -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\en-US\Lavasoft.ArrowHelper.UI.resources.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\en-US\Lavasoft.WebBar.UI.resources.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\en-US\WebCompanion.resources.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\en-US\WebCompanionInstaller.resources.dll -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Lavasoft\Web Companion\Application\en-US -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\es-ES\Lavasoft.ArrowHelper.UI.resources.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\es-ES\Lavasoft.WebBar.UI.resources.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\es-ES\WebCompanion.resources.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\es-ES\WebCompanionInstaller.resources.dll -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Lavasoft\Web Companion\Application\es-ES -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\Esent.Interop.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\Extension\@wcextensionff.xpi -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Lavasoft\Web Companion\Application\Extension -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\fr-CA\Lavasoft.ArrowHelper.UI.resources.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\fr-CA\Lavasoft.WebBar.UI.resources.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\fr-CA\WebCompanion.resources.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\fr-CA\WebCompanionInstaller.resources.dll -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Lavasoft\Web Companion\Application\fr-CA -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\ICSharpCode.SharpZipLib.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\Interop.IWshRuntimeLibrary.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\Interop.LavasoftTcpServiceLib.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\Interop.SHDocVw.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\Interop.Shell32.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\it-IT\Lavasoft.ArrowHelper.UI.resources.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\it-IT\Lavasoft.WebBar.UI.resources.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\it-IT\WebCompanion.resources.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\it-IT\WebCompanionInstaller.resources.dll -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Lavasoft\Web Companion\Application\it-IT -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\ja-JP\Lavasoft.ArrowHelper.UI.resources.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\ja-JP\Lavasoft.WebBar.UI.resources.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\ja-JP\WebCompanion.resources.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\ja-JP\WebCompanionInstaller.resources.dll -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Lavasoft\Web Companion\Application\ja-JP -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.AdAware.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.adblocker.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.ArrowHelper.UI.exe -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.ArrowHelper.UI.exe.config -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.Automation.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.AvastWrapper.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.Common.Platform.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.CSharp.Utilities.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.IEController.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.PersistantStorage.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.PUP.Management.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.SearchProtect.Business.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.SearchProtect.Business.dll.config -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.SearchProtect.Repositories.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.SearchProtect.Repositories.dll.config -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.SmartAssemblyUI.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.SysInfo.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.Uninstall.exe -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.Uninstall.exe.config -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.UpdateComponents.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.Utils.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.Utils.SqlLite.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.Utils.SqlLite.dll.config -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.WCAssistant.Service.Logger.dll -> Removed at reboot [5] [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.WCAssistant.WcfService.dll -> Removed at reboot [5] [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.WCAssistant.WinService.exe -> Removed at reboot [5] [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.WCAssistant.WinService.exe.config -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.WebBar.UI.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.WebBar.UI.dll.config -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\log4net.dll -> Removed at reboot [5] [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\LogicNP.EZShellExtensions.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\LZ4.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\Microsoft.mshtml.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\Newtonsoft.Json.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\pt-BR\Lavasoft.ArrowHelper.UI.resources.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\pt-BR\Lavasoft.WebBar.UI.resources.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\pt-BR\WebCompanion.resources.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\pt-BR\WebCompanionInstaller.resources.dll -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Lavasoft\Web Companion\Application\pt-BR -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\ru-RU\Lavasoft.ArrowHelper.UI.resources.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\ru-RU\Lavasoft.WebBar.UI.resources.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\ru-RU\WebCompanion.resources.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\ru-RU\WebCompanionInstaller.resources.dll -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Lavasoft\Web Companion\Application\ru-RU -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\SmartAssembly.ReportException.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\SmartExceptionsCore.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\System.Data.SQLite.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\System.Data.SQLite.Linq.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\tr-TR\Lavasoft.ArrowHelper.UI.resources.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\tr-TR\Lavasoft.WebBar.UI.resources.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\tr-TR\WebCompanion.resources.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\tr-TR\WebCompanionInstaller.resources.dll -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Lavasoft\Web Companion\Application\tr-TR -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebcompaionReimageIcon.ico -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanion.exe -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanion.exe.config -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanionExtensionIE.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanionIcon.ico -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanionIcon_Pro.ico -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanionInstaller.exe -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanionInstaller.exe.config -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanionInstaller.pdb -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\x64\SQLite.Interop.dll -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Lavasoft\Web Companion\Application\x64 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\x86\SQLite.Interop.dll -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Lavasoft\Web Companion\Application\x86 -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\zh-CHS\WebCompanionInstaller.resources.dll -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Lavasoft\Web Companion\Application\zh-CHS -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\zh-Hans\Lavasoft.ArrowHelper.UI.resources.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\zh-Hans\Lavasoft.WebBar.UI.resources.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\Application\zh-Hans\WebCompanion.resources.dll -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Lavasoft\Web Companion\Application\zh-Hans -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Lavasoft\Web Companion\Application -> Removed at reboot [91] [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\TcpService\2.3.4.7\LavasoftLSPInstaller.exe -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\TcpService\2.3.4.7\LavasoftLSPInstaller.ini -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\TcpService\2.3.4.7\LavasoftLSPInstaller64.exe -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\TcpService\2.3.4.7\LavasoftTcpService.dll -> Deleted [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\TcpService\2.3.4.7\LavasoftTcpService.exe -> Removed at reboot [5] [PUP.Gen1][File] C:\Program Files (x86)\Lavasoft\Web Companion\TcpService\2.3.4.7\LavasoftTcpService64.dll -> Deleted [PUP.Gen1][Folder] C:\Program Files (x86)\Lavasoft\Web Companion\TcpService\2.3.4.7 -> Removed at reboot [91] [PUP.Gen1][Folder] C:\Program Files (x86)\Lavasoft\Web Companion\TcpService -> Removed at reboot [91] ¤¤¤ WMI : 0 ¤¤¤ ¤¤¤ Hosts File : 0 ¤¤¤ ¤¤¤ Antirootkit : 0 (Driver: Loaded) ¤¤¤ ¤¤¤ Web browsers : 0 ¤¤¤ ¤¤¤ MBR Check : ¤¤¤ +++++ PhysicalDrive0: Samsung SSD 850 EVO 250GB +++++ --- User --- [MBR] f8126ec478872dce2e470741f3e5074b [BSP] 080554b5f121156ed0dd490dd61f7049 : HP|VT.Unknown MBR Code Partition table: 0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 100 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader] 1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 206848 | Size: 238374 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader] User = LL1 ... OK User = LL2 ... OK +++++ PhysicalDrive1: ST2000DM001-1ER164 +++++ --- User --- [MBR] 97b5494ad59d099d5a2b2a5922c53e9b [BSP] 2be012e68fc1c21752c7a87113cd952e : Windows Vista/7/8|VT.Unknown MBR Code Partition table: 0 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 1907727 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader] User = LL1 ... OK User = LL2 ... OK The JRT log: ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Malwarebytes Version: 8.1.1 (02.11.2017) Operating System: Windows 10 Pro x64 Ran by Dad (Administrator) on Wed 03/01/2017 at 18:46:48.79 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ File System: 0 Registry: 1 Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{FFEBBF0A-C22C-4172-89FF-45215A135AC7} (Registry Key) ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on Wed 03/01/2017 at 18:48:24.52 End of JRT log Adware hung the first time through leaving its warning dialog on the screen. I stopped it rebooted and ran again and it completed. Later I found 4 reports in the folder. All are attached here with the last one being posted. # AdwCleaner v6.044 - Logfile created 01/03/2017 at 19:30:07 # Updated on 28/02/2017 by Malwarebytes # Database : 2017-03-01.1 [Local] # Operating System : Windows 10 Pro (X64) # Username : Dad - F4PC # Running from : C:\Users\TT\Desktop\adwcleaner_6.044.exe # Mode: Clean # Support : https://www.malwarebytes.com/support ***** [ Services ] ***** ***** [ Folders ] ***** ***** [ Files ] ***** [#] File deleted: C:\Windows\SysNative\LavasoftTcpService64.dll [-] File deleted: C:\Windows\SysWoW64\lavasofttcpservice.dll ***** [ DLL ] ***** ***** [ WMI ] ***** ***** [ Shortcuts ] ***** ***** [ Scheduled Tasks ] ***** ***** [ Registry ] ***** ***** [ Web browsers ] ***** ************************* :: "Tracing" keys deleted :: Winsock settings cleared ************************* C:\AdwCleaner\AdwCleaner[C0].txt - [14564 Bytes] - [01/03/2017 18:56:59] C:\AdwCleaner\AdwCleaner[C2].txt - [940 Bytes] - [01/03/2017 19:30:07] C:\AdwCleaner\AdwCleaner[S0].txt - [13510 Bytes] - [01/03/2017 18:56:19] C:\AdwCleaner\AdwCleaner[S1].txt - [1369 Bytes] - [01/03/2017 19:27:29] ########## EOF - C:\AdwCleaner\AdwCleaner[C2].txt - [1159 Bytes] ########## The FRST.TXT is: Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 01-03-2017 Ran by Dad (administrator) on F4PC (01-03-2017 21:41:24) Running from C:\Users\TT\Desktop Loaded Profiles: Dad (Available Profiles: Dad) Platform: Windows 10 Pro Version 1607 (X64) Language: English (United States) Internet Explorer Version 11 (Default browser: Edge) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe (Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe (Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (Electronic Arts) C:\Program Files (x86)\Origin\OriginWebHelperService.exe (Realtek Semiconductor Corp.) C:\Windows\RtkBtManServ.exe () C:\Program Files (x86)\Even Balance, Inc\PunkBuster\PB\PnkBstrA.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.11.110.0_x64__kzf8qxf38zg5c\SkypeHost.exe (AddGadgets) C:\Users\TT\Downloads\PCMeter\PCMeterV4\PCMeterV0.4.exe (Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (ZabKat) C:\Program Files\zabkat\xplorer2\xplorer2_64.exe (Adobe Systems Incorporated) C:\Program Files\Adobe\Elements 13 Organizer\PhotoshopElementsFileAgent.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.32.7\GoogleCrashHandler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.32.7\GoogleCrashHandler64.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe (Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_17.214.10010.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.17012.10301.0_x64__8wekyb3d8bbwe\Video.UI.exe ==================== Registry (Whitelisted) ==================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [ShadowPlay] => "C:\WINDOWS\system32\rundll32.exe" C:\WINDOWS\system32\nvspcap64.dll,ShadowPlayOnSystemStart HKLM\...\Run: [Malwarebytes TrayApp] => C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe [2780112 2017-01-20] (Malwarebytes) HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [508128 2016-07-01] (Adobe Systems Incorporated) HKLM\...\Run: [WindowsDefender] => C:\Program Files\Windows Defender\MSASCuiL.exe [631808 2016-11-20] (Microsoft Corporation) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2016-12-12] (Oracle Corporation) HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [MS Word To EPUB Converter Software.exe] => [X] HKLM-x32\...\Run: [VirtualCloneDrive] => C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [88984 2013-03-10] (Elaborate Bytes AG) HKLM-x32\...\Run: [IseUI] => C:\Program Files (x86)\COMODO\Internet Security Essentials\vkise.exe HKLM-x32\...\Run: [Adobe Creative Cloud] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2384984 2016-12-09] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Everything] => C:\Program Files (x86)\Everything\Everything.exe [1048576 2014-08-05] () HKU\S-1-5-21-2438100261-443141923-189968324-1001\...\Run: [ClearScreen Player] => "C:\Program Files (x86)\ClearScreenPlayer\ClearScreenPlayer.exe" /autostart=1 HKU\S-1-5-21-2438100261-443141923-189968324-1001\...\Run: [HP OfficeJet 4650 series (NET)] => C:\Program Files\HP\HP OfficeJet 4650 series\Bin\ScanToPCActivationApp.exe [3651080 2015-03-09] (Hewlett-Packard Development Company, LP) HKU\S-1-5-21-2438100261-443141923-189968324-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [2881824 2017-01-18] (Valve Corporation) HKU\S-1-5-21-2438100261-443141923-189968324-1001\...\Run: [Chromium] => c:\users\tt\appdata\local\chromium\application\chrome.exe [1044480 2016-01-25] (The Chromium Authors) HKU\S-1-5-21-2438100261-443141923-189968324-1001\...\Run: [CCleaner] => C:\Program Files\CCleaner\CCleaner64.exe [9363672 2017-02-07] (Piriform Ltd) HKU\S-1-5-21-2438100261-443141923-189968324-1001\...\MountPoints2: {08c40c0e-f6d0-11e6-8851-645a046bdb93} - "G:\VerizonSWUpgradeAssistantLauncher.exe" HKU\S-1-5-21-2438100261-443141923-189968324-1001\...\MountPoints2: {08c41ebc-f6d0-11e6-8851-645a046bdb93} - "E:\setup\rsrc\Autorun.exe" ShellIconOverlayIdentifiers: [ AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2016-10-25] () ShellIconOverlayIdentifiers: [ AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2016-10-25] () ShellIconOverlayIdentifiers: [ AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2016-10-25] () Startup: C:\Users\TT\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Sidebar894.lnk [2017-03-01] ShortcutTarget: Sidebar894.lnk -> C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation) GroupPolicy: Restriction <======= ATTENTION GroupPolicy\User: Restriction <======= ATTENTION CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{2ea7977b-8d4a-4f2e-83af-4dce0c4ac128}: [DhcpNameServer] 127.0.0.1 Tcpip\..\Interfaces\{583d061d-5760-47e3-af09-0c731c4dd803}: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{a341fb9e-f316-4b36-ba27-825fcc57037c}: [DhcpNameServer] 192.168.1.1 Internet Explorer: ================== HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = www.google.com SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-2438100261-443141923-189968324-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2016-12-28] (Microsoft Corporation) BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL [2016-12-28] (Microsoft Corporation) BHO-x32: Show Naturalreader Bar -> {127AD70F-B2B7-4f6a-ACD9-C7B1FE48C8C0} -> C:\Windows\syswow64\MsiExec.exe [2016-07-16] (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\ssv.dll [2017-02-13] (Oracle Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\jp2ssv.dll [2017-02-13] (Oracle Corporation) Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2016-12-28] (Microsoft Corporation) Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2016-12-28] (Microsoft Corporation) Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2016-12-28] (Microsoft Corporation) Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2016-12-28] (Microsoft Corporation) StartMenuInternet: IEXPLORE.EXE - iexplore.exe FireFox: ======== FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2016-12-09] (Adobe Systems) FF Plugin-x32: @java.com/DTPlugin,version=11.121.2 -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\dtplugin\npDeployJava1.dll [2017-02-13] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.121.2 -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\plugin2\npjp2.dll [2017-02-13] (Oracle Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2016-12-28] (Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2017-01-20] (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2017-01-20] (NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-29] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-29] (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN) FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2016-12-09] (Adobe Systems) Chrome: ======= CHR HomePage: Default -> hxxp://www.google.com/ CHR StartupUrls: Default -> "hxxps://www.google.com/?gws_rd=ssl" CHR Profile: C:\Users\TT\AppData\Local\Google\Chrome\User Data\Default [2017-02-28] CHR Extension: (Google Slides) - C:\Users\TT\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-12-29] CHR Extension: (Google Docs) - C:\Users\TT\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-12-29] CHR Extension: (Google Drive) - C:\Users\TT\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-12-29] CHR Extension: (YouTube) - C:\Users\TT\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-12-29] CHR Extension: (One-click Downloader) - C:\Users\TT\AppData\Local\Google\Chrome\User Data\Default\Extensions\efjodfcplkcccafghgnbnpgedgakohog [2017-02-19] CHR Extension: (Google Sheets) - C:\Users\TT\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-12-29] CHR Extension: (Google Docs Offline) - C:\Users\TT\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-12-29] CHR Extension: (Chrome Web Store Payments) - C:\Users\TT\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-02-11] CHR Extension: (Gmail) - C:\Users\TT\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-12-29] CHR Extension: (Chrome Media Router) - C:\Users\TT\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-02-12] ==================== Services (Whitelisted) ==================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 AdobeActiveFileMonitor13.0; C:\Program Files\Adobe\Elements 13 Organizer\PhotoshopElementsFileAgent.exe [231120 2015-01-30] (Adobe Systems Incorporated) R2 AdobeUpdateService; C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [753240 2016-12-09] (Adobe Systems Incorporated) R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2227312 2017-01-19] (Adobe Systems, Incorporated) R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [3699904 2016-12-28] (Microsoft Corporation) R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4355024 2017-01-20] (Malwarebytes) R2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [462784 2017-01-20] (NVIDIA Corporation) S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [462784 2017-01-20] (NVIDIA Corporation) R2 NVDisplay.ContainerLocalSystem; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [464440 2017-01-20] (NVIDIA Corporation) R2 NvTelemetryContainer; C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe [425408 2017-01-20] (NVIDIA Corporation) S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2124296 2017-02-25] (Electronic Arts) R2 Origin Web Helper Service; C:\Program Files (x86)\Origin\OriginWebHelperService.exe [2185232 2017-02-25] (Electronic Arts) R2 PnkBstrA; C:\Program Files (x86)\Even Balance, Inc\PunkBuster\PB\PnkBstrA.exe [63040 2011-03-09] () R2 RtkBtManServ; C:\Windows\RtkBtManServ.exe [258864 2016-10-26] (Realtek Semiconductor Corp.) S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [2889896 2016-11-20] (Microsoft Corporation) R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347328 2016-07-16] (Microsoft Corporation) R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103720 2016-07-16] (Microsoft Corporation) S2 NVIDIA Wireless Controller Service; "C:\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe" [X] ===================== Drivers (Whitelisted) ====================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R3 bcmsmbsp; C:\Windows\System32\drivers\bcmsmbsp.sys [54048 2015-09-09] (Broadcom Corporation.) R1 ESProtectionDriver; C:\Windows\system32\drivers\mbae64.sys [77416 2017-01-20] () R3 ISCT; C:\Windows\System32\drivers\ISCTD64.sys [47008 2013-07-30] () R2 MBAMChameleon; C:\Windows\system32\drivers\MBAMChameleon.sys [176584 2017-03-01] (Malwarebytes) R3 MBAMFarflt; C:\Windows\system32\drivers\farflt.sys [110536 2017-03-01] (Malwarebytes) R3 MBAMProtection; C:\Windows\system32\drivers\mbam.sys [43968 2017-03-01] (Malwarebytes) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [251848 2017-03-01] (Malwarebytes) S3 NetAdapterCx; C:\Windows\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] () R3 nvlddmkm; C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_02838dee03d82b94\nvlddmkm.sys [14427064 2017-01-21] (NVIDIA Corporation) S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [27584 2017-01-20] (NVIDIA Corporation) R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [46016 2017-01-20] (NVIDIA Corporation) R3 nvvhci; C:\Windows\System32\drivers\nvvhci.sys [57792 2017-01-20] (NVIDIA Corporation) R0 PxHlpa64; C:\Windows\System32\drivers\PxHlpa64.sys [56336 2013-09-03] (Corel Corporation) R3 RtkBtFilter; C:\Windows\system32\DRIVERS\RtkBtfilter.sys [719424 2016-10-26] (Realtek Semiconductor Corporation) R3 RTWlanE; C:\Windows\System32\drivers\rtwlane.sys [5144064 2016-07-16] (Realtek Semiconductor Corporation ) S2 SecDrv; C:\Windows\SysWOW64\drivers\SECDRV.SYS [163644 2017-02-21] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) [File not signed] U3 TrueSight; C:\Windows\System32\drivers\TrueSight.sys [28272 2017-03-01] () S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation) R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation) R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation) R3 WinRing0_1_2_0; C:\Users\TT\AppData\Local\Temp\tmpE295.tmp [14544 2017-02-12] (OpenLibSys.org) <==== ATTENTION ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One Month Created files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2017-03-01 21:41 - 2017-03-01 21:41 - 00017780 _____ C:\Users\TT\Desktop\FRST.txt 2017-03-01 21:40 - 2017-03-01 21:41 - 00000000 ____D C:\FRST 2017-03-01 21:38 - 2017-03-01 21:38 - 02423808 _____ (Farbar) C:\Users\TT\Desktop\FRST64.exe 2017-03-01 18:54 - 2017-03-01 19:30 - 00000000 ____D C:\AdwCleaner 2017-03-01 18:53 - 2017-03-01 18:53 - 04031440 _____ C:\Users\TT\Desktop\adwcleaner_6.044.exe 2017-03-01 18:48 - 2017-03-01 18:48 - 00000684 _____ C:\Users\TT\Desktop\JRT.txt 2017-03-01 18:43 - 2017-03-01 18:43 - 01663736 _____ (Malwarebytes) C:\Users\TT\Desktop\JRT.exe 2017-03-01 18:38 - 2017-03-01 19:32 - 00000000 ____D C:\Users\TT\Desktop\Reports 2017-03-01 18:34 - 2017-03-01 18:34 - 00045416 _____ C:\Users\TT\Desktop\rk_81ED.txt 2017-03-01 17:51 - 2017-03-01 17:51 - 00028272 _____ C:\Windows\system32\Drivers\TrueSight.sys 2017-03-01 17:51 - 2017-03-01 17:51 - 00000000 ____D C:\ProgramData\RogueKiller 2017-03-01 17:46 - 2017-03-01 17:46 - 26044488 _____ C:\Users\TT\Desktop\RogueKillerX64.exe 2017-03-01 17:38 - 2017-03-01 17:38 - 00002670 _____ C:\Windows\System32\Tasks\journalaboutlifeorgscopesm 2017-03-01 17:31 - 2017-03-01 17:38 - 00002276 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC 2017-03-01 17:31 - 2017-03-01 17:31 - 00000872 _____ C:\Users\Public\Desktop\CCleaner.lnk 2017-03-01 17:31 - 2017-03-01 17:31 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner 2017-03-01 17:31 - 2017-03-01 17:31 - 00000000 ____D C:\Program Files\CCleaner 2017-02-28 17:02 - 2017-02-28 17:02 - 01722368 _____ C:\Users\TT\Desktop\9d8b2c00-b787-47dc-8afa-7859fd1f1222.pdf 2017-02-28 11:34 - 2017-02-28 11:34 - 00141665 _____ C:\Users\TT\Desktop\ZHPDiag.txt 2017-02-28 11:32 - 2017-02-28 11:33 - 00000000 ____D C:\Users\TT\AppData\Roaming\ZHP 2017-02-28 11:31 - 2017-02-28 11:31 - 02705920 _____ C:\Users\TT\Desktop\ZHPDiag3.exe 2017-02-27 21:27 - 2017-03-01 17:41 - 00000000 ____D C:\Users\TT\AppData\Roaming\Everything 2017-02-27 21:27 - 2017-02-27 21:27 - 00000000 ____D C:\Users\TT\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Everything 2017-02-27 21:27 - 2017-02-27 21:27 - 00000000 ____D C:\Program Files (x86)\Everything 2017-02-27 21:26 - 2017-02-27 21:26 - 00928203 _____ () C:\Users\TT\Downloads\Everything-1.3.4.686.x86.Multilingual-Setup.exe 2017-02-27 18:34 - 2017-02-27 18:34 - 00000000 ____D C:\Users\TT\AppData\Roaming\dvdcss 2017-02-27 18:29 - 2017-02-27 18:37 - 00000000 ____D C:\Users\TT\AppData\Roaming\vlc 2017-02-27 17:51 - 2017-02-27 17:51 - 00001148 _____ C:\Users\Public\Desktop\VLC media player.lnk 2017-02-27 17:51 - 2017-02-27 17:51 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN 2017-02-27 17:51 - 2017-02-27 17:51 - 00000000 ____D C:\Program Files (x86)\VideoLAN 2017-02-27 17:49 - 2017-02-27 17:49 - 30533688 _____ C:\Users\TT\Downloads\vlc-2.2.4-win32.exe 2017-02-25 21:07 - 2017-02-25 21:07 - 00000000 ____D C:\Users\TT\AppData\LocalLow\Adobe 2017-02-25 21:06 - 2017-03-01 07:08 - 00000000 ___RD C:\Users\TT\Creative Cloud Files 2017-02-25 21:06 - 2017-02-27 21:35 - 00000000 ____D C:\ProgramData\boost_interprocess 2017-02-25 21:05 - 2017-02-25 21:05 - 00001307 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Creative Cloud.lnk 2017-02-25 21:05 - 2017-02-25 21:05 - 00001295 _____ C:\Users\Public\Desktop\Adobe Creative Cloud.lnk 2017-02-25 21:04 - 2017-02-25 21:04 - 00000000 ____D C:\Program Files (x86)\Adobe 2017-02-25 16:51 - 2017-02-25 16:51 - 00000000 ____D C:\Windows\SysWOW64\AGEIA 2017-02-25 16:51 - 2017-02-25 16:51 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AGEIA 2017-02-25 16:51 - 2017-02-25 16:51 - 00000000 ____D C:\Program Files (x86)\AGEIA Technologies 2017-02-25 16:37 - 2017-03-01 17:38 - 00002804 _____ C:\Windows\System32\Tasks\AdobeAAMUpdater-1.0-F4PC-Dad 2017-02-25 16:31 - 2017-02-25 16:31 - 00000000 __RHD C:\Users\TT\AppData\Roaming\SecuROM 2017-02-25 16:30 - 2017-02-25 16:30 - 00000000 ____D C:\Program Files (x86)\Even Balance, Inc 2017-02-25 16:26 - 2017-02-25 16:37 - 00000000 ____D C:\ProgramData\regid.1986-12.com.adobe 2017-02-25 16:26 - 2017-02-25 16:26 - 00001060 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop Elements 13.lnk 2017-02-25 16:26 - 2017-02-25 16:26 - 00001048 _____ C:\Users\Public\Desktop\Adobe Photoshop Elements 13.lnk 2017-02-25 16:24 - 2017-02-25 16:43 - 00000000 ____D C:\Program Files\Adobe 2017-02-25 16:23 - 2017-02-25 16:45 - 00000000 ____D C:\Program Files\Common Files\Adobe 2017-02-25 16:23 - 2013-09-03 05:01 - 00056336 ____N (Corel Corporation) C:\Windows\system32\Drivers\PxHlpa64.sys 2017-02-25 16:23 - 2012-04-24 05:01 - 00011376 ____N (Corel Corporation) C:\Windows\system32\Drivers\cdralw2k.sys 2017-02-25 16:23 - 2012-04-24 05:01 - 00010864 ____N (Corel Corporation) C:\Windows\system32\Drivers\cdr4_xp.sys 2017-02-25 16:19 - 2017-02-25 21:07 - 00000000 ____D C:\ProgramData\Adobe 2017-02-25 15:49 - 2017-02-25 15:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Medal of Honor Pacific Assault™ 2017-02-25 15:41 - 2017-02-25 16:09 - 00000000 ____D C:\Program Files (x86)\Origin Games 2017-02-25 15:40 - 2017-02-25 15:40 - 00001071 _____ C:\Users\Public\Desktop\Origin.lnk 2017-02-25 15:40 - 2017-02-25 15:40 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Origin 2017-02-25 15:40 - 2017-02-25 15:40 - 00000000 ____D C:\Program Files (x86)\Origin 2017-02-25 15:38 - 2017-02-25 15:41 - 00000000 ____D C:\Users\TT\AppData\Local\Origin 2017-02-25 15:38 - 2017-02-25 15:38 - 52489832 _____ (Electronic Arts) C:\Users\TT\Downloads\OriginThinSetupBeta.exe 2017-02-25 15:38 - 2017-02-25 15:38 - 00000000 ____D C:\Users\TT\.QtWebEngineProcess 2017-02-25 15:38 - 2017-02-25 15:38 - 00000000 ____D C:\Users\TT\.Origin 2017-02-25 13:31 - 2017-02-25 13:32 - 00000000 __HDC C:\ProgramData\{92D5D750-AA6D-437A-9732-D540EA9E7693} 2017-02-25 13:31 - 2017-02-25 13:31 - 00001088 _____ C:\Users\Public\Desktop\ThumbsPlus 10.lnk 2017-02-25 13:31 - 2017-02-25 13:31 - 00000257 _____ C:\Windows\ODBCINST.INI 2017-02-25 13:31 - 2017-02-25 13:31 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ThumbsPlus 10 2017-02-25 13:31 - 2017-02-25 13:31 - 00000000 ____D C:\Program Files (x86)\ThumbsPlus 10 2017-02-25 12:49 - 2017-02-27 21:14 - 00000000 ____D C:\Users\TT\AppData\Roaming\ThumbsPlus 2017-02-25 12:48 - 2017-02-27 21:15 - 00000000 ____D C:\ProgramData\ThumbsPlus 2017-02-25 12:48 - 2017-02-25 12:48 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ThumbsPlus 7 2017-02-25 12:48 - 2017-02-25 12:48 - 00000000 ____D C:\Program Files (x86)\Thumbs7 2017-02-25 11:54 - 2017-02-25 11:54 - 00002077 _____ C:\Users\TT\Desktop\TextMaker 2016.lnk 2017-02-25 11:54 - 2017-02-25 11:54 - 00002077 _____ C:\Users\TT\Desktop\PlanMaker 2016.lnk 2017-02-25 11:42 - 2017-02-25 11:43 - 00000000 ____D C:\Program Files (x86)\SoftMaker Office 2016 2017-02-25 11:42 - 2017-02-25 11:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SoftMaker Office 2016 2017-02-25 07:04 - 2017-03-01 19:30 - 00251848 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2017-02-25 07:04 - 2017-03-01 19:30 - 00110536 _____ (Malwarebytes) C:\Windows\system32\Drivers\farflt.sys 2017-02-25 07:04 - 2017-03-01 19:30 - 00043968 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys 2017-02-25 07:04 - 2017-03-01 18:41 - 00176584 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMChameleon.sys 2017-02-25 07:04 - 2017-03-01 17:41 - 00091584 _____ (Malwarebytes) C:\Windows\system32\Drivers\mwac.sys 2017-02-25 07:04 - 2017-02-25 07:04 - 00001921 _____ C:\Users\Public\Desktop\Malwarebytes.lnk 2017-02-25 07:04 - 2017-02-25 07:04 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes 2017-02-25 07:04 - 2017-02-25 07:04 - 00000000 ____D C:\ProgramData\Malwarebytes 2017-02-25 07:04 - 2017-02-25 07:04 - 00000000 ____D C:\Program Files\Malwarebytes 2017-02-25 07:04 - 2017-01-20 07:47 - 00077416 _____ C:\Windows\system32\Drivers\mbae64.sys 2017-02-25 07:03 - 2017-02-25 07:03 - 55566792 _____ (Malwarebytes ) C:\Users\TT\Downloads\mb3-setup-consumer-3.0.6.1469.exe 2017-02-24 21:39 - 2017-02-24 21:39 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2016-Tools 2017-02-24 19:16 - 2017-02-24 19:16 - 00001688 _____ C:\Users\TT\Documents\old.reg 2017-02-24 10:18 - 2017-02-20 13:58 - 00425744 _____ (Lavasoft Limited) C:\Windows\system32\LavasoftTcpService64.dll 2017-02-24 08:28 - 2017-02-24 08:28 - 00000000 ____D C:\Users\TT\AppData\Roaming\Ubisoft 2017-02-24 08:13 - 2017-02-24 08:13 - 00000000 ____D C:\Program Files (x86)\Ubisoft 2017-02-24 07:59 - 2017-02-24 07:59 - 00000000 ____D C:\ProgramData\Ubisoft 2017-02-23 20:40 - 2017-03-01 17:39 - 00002434 _____ C:\Windows\System32\Tasks\{43719454-2974-4532-A795-986B56FC87E0} 2017-02-23 19:16 - 2017-02-23 19:20 - 00000000 ____D C:\Users\TT\AppData\LocalLow\Unity 2017-02-23 19:16 - 2017-02-23 19:20 - 00000000 ____D C:\Users\TT\AppData\Local\Unity 2017-02-23 17:38 - 2017-02-25 16:31 - 00000000 ____D C:\Users\TT\Documents\EA Games 2017-02-23 17:04 - 2017-02-23 17:04 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EA Games 2017-02-23 17:04 - 2017-02-23 17:04 - 00000000 ____D C:\Program Files (x86)\EA GAMES 2017-02-23 16:49 - 2017-02-23 16:49 - 00000000 ____D C:\Program Files (x86)\EACOM 2017-02-23 16:40 - 2017-02-23 16:40 - 00000000 ____D C:\Program Files (x86)\Electronic Arts 2017-02-23 14:46 - 2017-02-25 16:29 - 00000000 ____D C:\Users\TT\Desktop\MOH 2017-02-23 14:21 - 2017-02-23 14:21 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Medal of Honor - Allied Assault War Chest [GOG.com] 2017-02-23 14:18 - 2017-02-23 14:18 - 00000000 ____D C:\GOG Games 2017-02-23 14:14 - 2017-02-23 14:14 - 00000000 ____D C:\Users\TT\Desktop\COD 2017-02-21 19:33 - 2017-03-01 17:39 - 00002436 _____ C:\Windows\System32\Tasks\{28DA7460-C7EC-4276-A1FF-B9EAF7FDFEF6} 2017-02-21 19:30 - 2017-02-21 19:30 - 00000293 _____ C:\Windows\game.ini 2017-02-21 19:30 - 2017-02-21 19:30 - 00000000 __SHD C:\Windows\ftpcache 2017-02-21 19:30 - 2017-02-21 19:30 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Activision 2017-02-21 16:01 - 2017-02-21 16:01 - 00000745 _____ C:\Windows\COD.INI 2017-02-21 16:01 - 2017-02-21 16:01 - 00000000 ____D C:\Users\TT\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Call of Duty 2017-02-21 15:28 - 2017-02-26 09:21 - 00000000 ____D C:\Program Files (x86)\Call of Duty 2017-02-21 14:05 - 2017-02-23 13:34 - 00000000 ____D C:\Users\TT\AppData\Local\Activision 2017-02-21 13:41 - 2017-02-21 18:22 - 00000000 ____D C:\Program Files (x86)\Activision 2017-02-21 10:22 - 2017-02-21 10:22 - 00682280 _____ C:\Windows\SysWOW64\pbsvc.exe 2017-02-21 10:22 - 2017-02-21 10:22 - 00107832 _____ C:\Windows\SysWOW64\PnkBstrB.exe 2017-02-21 10:22 - 2017-02-21 10:22 - 00066872 _____ C:\Windows\SysWOW64\PnkBstrA.exe 2017-02-20 18:34 - 2017-02-23 20:18 - 00000000 ____D C:\Users\TT\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam 2017-02-20 17:27 - 2017-02-20 17:28 - 00000000 ____D C:\Users\TT\AppData\Local\Steam 2017-02-20 17:26 - 2017-02-20 17:26 - 01446792 _____ C:\Users\TT\Downloads\SteamSetup.exe 2017-02-20 16:50 - 2017-03-01 17:41 - 00000000 ____D C:\Program Files (x86)\Steam 2017-02-20 16:50 - 2017-02-20 17:26 - 00001041 _____ C:\Users\Public\Desktop\Steam.lnk 2017-02-20 16:50 - 2017-02-20 17:26 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam 2017-02-20 16:15 - 2017-02-20 16:15 - 00000000 ____D C:\Users\TT\AppData\Local\NowUSeeItPlayerOsm 2017-02-20 14:43 - 2017-02-21 20:15 - 00163644 _____ (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) C:\Windows\SysWOW64\Drivers\SECDRV.SYS 2017-02-20 14:43 - 2017-02-20 14:43 - 00000000 ____D C:\Users\TT\AppData\Local\ElevatedDiagnostics 2017-02-20 14:42 - 2017-03-01 17:39 - 00002342 _____ C:\Windows\System32\Tasks\{56E113F0-C191-4BC8-B6E6-5CEB7013EEE2} 2017-02-20 14:05 - 2017-02-20 14:06 - 00000000 ____D C:\Users\TT\AppData\Roaming\ImgBurn 2017-02-20 13:59 - 2017-02-20 14:07 - 00000000 ____D C:\Program Files (x86)\COMODO 2017-02-20 13:59 - 2017-02-20 13:59 - 00001955 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ImgBurn.lnk 2017-02-20 13:59 - 2017-02-20 13:59 - 00001943 _____ C:\Users\Public\Desktop\ImgBurn.lnk 2017-02-20 13:59 - 2017-02-20 13:59 - 00000000 ____D C:\Users\TT\AppData\Local\CrashRpt 2017-02-20 13:59 - 2017-02-20 13:59 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ImgBurn 2017-02-20 13:59 - 2017-02-20 13:59 - 00000000 ____D C:\Program Files (x86)\ImgBurn 2017-02-20 13:58 - 2017-03-01 18:40 - 00000000 ____D C:\ProgramData\Lavasoft 2017-02-20 13:58 - 2017-03-01 18:40 - 00000000 ____D C:\Program Files (x86)\Lavasoft 2017-02-20 13:58 - 2017-03-01 18:32 - 00000000 ____D C:\Users\TT\AppData\Roaming\Lavasoft 2017-02-20 13:58 - 2017-02-25 07:08 - 00000000 ____D C:\Program Files\COMODO 2017-02-20 13:58 - 2017-02-20 14:07 - 00000000 ____D C:\ProgramData\COMODO 2017-02-20 13:58 - 2017-02-20 13:58 - 00000000 ____D C:\Users\TT\AppData\Local\Lavasoft 2017-02-20 13:58 - 2017-02-20 13:58 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft 2017-02-20 13:58 - 2017-02-20 13:58 - 00000000 ____D C:\Program Files (x86)\InstallPrepared 2017-02-20 13:30 - 2017-02-20 13:30 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Auran 2017-02-20 13:15 - 2017-02-20 13:15 - 00001107 _____ C:\Users\Public\Desktop\Launch TS12.lnk 2017-02-20 13:15 - 2017-02-20 13:15 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\N3V Games 2017-02-20 13:03 - 2017-02-20 13:03 - 00000000 ____D C:\Program Files (x86)\N3V Games 2017-02-20 12:58 - 2017-02-21 08:14 - 00000000 ____D C:\Windows\system32\appmgmt 2017-02-20 12:25 - 2017-02-23 19:31 - 00021840 ____T C:\Windows\SysWOW64\SIntfNT.dll 2017-02-20 12:25 - 2017-02-23 19:31 - 00017212 ____T C:\Windows\SysWOW64\SIntf32.dll 2017-02-20 12:25 - 2017-02-23 19:31 - 00012067 ____T C:\Windows\SysWOW64\SIntf16.dll 2017-02-20 12:07 - 2017-02-23 16:49 - 00000500 _____ C:\Windows\eReg.dat 2017-02-20 11:26 - 2017-02-20 11:26 - 00002043 _____ C:\Users\Public\Desktop\NaturalReader 14.lnk 2017-02-20 10:46 - 2017-02-20 10:47 - 00000000 ____D C:\Users\TT\D-Fend Reloaded 2017-02-20 10:46 - 2017-02-20 10:46 - 16048953 _____ (Written by Alexander Herzog) C:\Users\TT\Downloads\D-Fend-Reloaded-1.4.4-Setup.exe 2017-02-20 10:46 - 2017-02-20 10:46 - 00001153 _____ C:\Users\Public\Desktop\D-Fend Reloaded.lnk 2017-02-20 10:46 - 2017-02-20 10:46 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\D-Fend Reloaded 2017-02-20 10:46 - 2017-02-20 10:46 - 00000000 ____D C:\Program Files (x86)\D-Fend Reloaded 2017-02-20 09:57 - 2017-02-20 09:57 - 00001332 _____ C:\Users\Public\Desktop\Virtual CloneDrive.lnk 2017-02-20 09:57 - 2017-02-20 09:57 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Elaborate Bytes 2017-02-20 09:57 - 2017-02-20 09:57 - 00000000 ____D C:\Program Files (x86)\Elaborate Bytes 2017-02-20 00:51 - 2017-02-20 11:48 - 00000000 ____D C:\Users\TT\Documents\Registrations 2017-02-20 00:50 - 2017-02-20 00:50 - 00000000 ____D C:\Users\TT\Documents\receipts 2017-02-19 23:11 - 2017-02-19 23:11 - 00001397 _____ C:\Users\Public\Desktop\MS Word To EPUB Converter Software.lnk 2017-02-19 23:11 - 2017-02-19 23:11 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MS Word To EPUB Converter Software 2017-02-19 23:11 - 2017-02-19 23:11 - 00000000 ____D C:\Program Files (x86)\MS Word To EPUB Converter Software 2017-02-19 23:11 - 2005-06-15 03:00 - 00102400 _____ (TechSmith Corporation) C:\Windows\SysWOW64\tsccvid.dll 2017-02-19 21:46 - 2017-02-19 21:46 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf 2017-02-19 08:29 - 2017-02-19 08:29 - 00001058 _____ C:\Users\TT\Desktop\DAD'S Notes.txt - Shortcut.lnk 2017-02-19 08:26 - 2017-02-28 12:02 - 00023027 _____ C:\Users\TT\Documents\DAD'S Notes.txt 2017-02-18 16:03 - 2017-02-18 16:03 - 00000031 _____ C:\Windows\script.txt 2017-02-18 16:02 - 2017-02-24 08:13 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2017-02-18 16:02 - 2017-02-18 16:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung 2017-02-18 16:02 - 2017-02-18 16:02 - 00000000 ____D C:\Program Files (x86)\Samsung 2017-02-18 15:59 - 2017-02-18 15:59 - 13944028 _____ C:\Users\TT\Downloads\Samsung_Magician_Installer.zip 2017-02-18 15:55 - 2017-02-18 15:55 - 36941793 _____ C:\Users\TT\Downloads\Samsung_Data_Migration_Setup_v30.zip 2017-02-17 14:29 - 2017-02-19 08:08 - 00000000 ____D C:\Users\TT\Documents\F4pc Spec Sheets 2017-02-16 13:54 - 2017-03-01 17:38 - 00002720 _____ C:\Windows\System32\Tasks\HPCustParticipation HP OfficeJet 4650 series 2017-02-16 13:54 - 2017-02-23 14:19 - 00000000 ____D C:\Users\TT\AppData\Roaming\HpUpdate 2017-02-16 13:54 - 2017-02-16 13:54 - 00002322 _____ C:\Users\Public\Desktop\HP OfficeJet 4650 series.lnk 2017-02-16 13:54 - 2017-02-16 13:54 - 00002069 _____ C:\Users\Public\Desktop\HP Photo Creations.lnk 2017-02-16 13:54 - 2017-02-16 13:54 - 00001259 _____ C:\Users\Public\Desktop\Shop for Supplies - HP OfficeJet 4650 series.lnk 2017-02-16 13:54 - 2017-02-16 13:54 - 00000978 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\I.R.I.S. OCR Registration.lnk 2017-02-16 13:54 - 2017-02-16 13:54 - 00000057 _____ C:\ProgramData\Ament.ini 2017-02-16 13:54 - 2017-02-16 13:54 - 00000000 ____D C:\ProgramData\Visan 2017-02-16 13:54 - 2017-02-16 13:54 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP 2017-02-16 13:54 - 2017-02-16 13:54 - 00000000 ____D C:\ProgramData\HP Photo Creations 2017-02-16 13:54 - 2017-02-16 13:54 - 00000000 ____D C:\Program Files\HP 2017-02-16 13:54 - 2017-02-16 13:54 - 00000000 ____D C:\Program Files (x86)\HP Photo Creations 2017-02-16 13:54 - 2017-02-16 13:54 - 00000000 ____D C:\Program Files (x86)\HP 2017-02-16 13:54 - 2015-03-09 14:44 - 00807432 ____N (Hewlett-Packard Development Company, LP) C:\Windows\system32\HPDiscoPMD911.dll 2017-02-16 13:48 - 2017-02-16 13:54 - 00000000 ____D C:\Users\TT\AppData\Local\HP 2017-02-16 13:11 - 2017-02-16 13:54 - 00000000 ____D C:\ProgramData\HP 2017-02-16 13:11 - 2017-02-16 13:48 - 00000000 ____D C:\Users\TT\AppData\Roaming\HP_Easy_Start 2017-02-15 06:27 - 2017-02-15 06:27 - 00001805 _____ C:\Users\TT\Desktop\Diabetes Records PHS.xls - Shortcut.lnk 2017-02-14 20:31 - 2017-03-01 17:38 - 00003458 _____ C:\Windows\System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2017-02-14 20:31 - 2017-01-20 13:39 - 00156608 _____ (NVIDIA Corporation) C:\Windows\system32\nvaudcap64v.dll 2017-02-14 20:31 - 2017-01-20 13:39 - 00124352 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll 2017-02-14 20:31 - 2017-01-20 13:39 - 00057792 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvhci.sys 2017-02-14 20:31 - 2017-01-20 08:36 - 00001951 _____ C:\Windows\NvTelemetryContainerRecovery.bat 2017-02-14 11:19 - 2017-02-14 11:49 - 00000000 ____D C:\Program Files (x86)\naturalreader 2017-02-13 19:33 - 2017-02-14 20:32 - 00000000 ____D C:\Users\TT\AppData\Local\NVIDIA 2017-02-13 19:33 - 2017-02-14 20:31 - 00001494 _____ C:\Users\Public\Desktop\GeForce Experience.lnk 2017-02-13 19:28 - 2017-03-01 17:38 - 00002918 _____ C:\Windows\System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2017-02-13 19:28 - 2017-02-13 19:28 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation 2017-02-13 19:28 - 2017-01-20 13:39 - 01872320 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll 2017-02-13 19:28 - 2017-01-20 13:39 - 01755072 _____ (NVIDIA Corporation) C:\Windows\system32\nvspbridge64.dll 2017-02-13 19:28 - 2017-01-20 13:39 - 01464768 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll 2017-02-13 19:28 - 2017-01-20 13:39 - 01317312 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspbridge.dll 2017-02-13 19:28 - 2017-01-20 13:39 - 00120256 _____ C:\Windows\system32\NvRtmpStreamer64.dll 2017-02-13 19:27 - 2017-02-13 19:27 - 00000000 ____D C:\Program Files (x86)\VulkanRT 2017-02-13 19:27 - 2017-01-20 11:38 - 00514616 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll 2017-02-13 19:27 - 2017-01-20 09:07 - 00134080 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe 2017-02-13 19:27 - 2016-12-15 19:33 - 00273696 _____ C:\Windows\SysWOW64\vulkan-1.dll 2017-02-13 19:27 - 2016-12-15 19:33 - 00266528 _____ C:\Windows\system32\vulkan-1.dll 2017-02-13 19:27 - 2016-12-15 19:33 - 00111392 _____ C:\Windows\SysWOW64\vulkaninfo.exe 2017-02-13 19:27 - 2016-12-15 19:32 - 00125728 _____ C:\Windows\system32\vulkaninfo.exe 2017-02-13 19:25 - 2017-01-23 19:00 - 00047664 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap64.dll 2017-02-13 19:25 - 2017-01-20 13:39 - 00046016 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys 2017-02-13 19:25 - 2017-01-20 11:38 - 40192056 _____ C:\Windows\system32\nvcompiler.dll 2017-02-13 19:25 - 2017-01-20 11:38 - 35272760 _____ C:\Windows\SysWOW64\nvcompiler.dll 2017-02-13 19:25 - 2017-01-20 11:38 - 34974656 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll 2017-02-13 19:25 - 2017-01-20 11:38 - 28239928 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll 2017-02-13 19:25 - 2017-01-20 11:38 - 19008576 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll 2017-02-13 19:25 - 2017-01-20 11:38 - 14677272 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll 2017-02-13 19:25 - 2017-01-20 11:38 - 11123936 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll 2017-02-13 19:25 - 2017-01-20 11:38 - 11019192 _____ (NVIDIA Corporation) C:\Windows\system32\nvptxJitCompiler.dll 2017-02-13 19:25 - 2017-01-20 11:38 - 09308896 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll 2017-02-13 19:25 - 2017-01-20 11:38 - 08990584 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvptxJitCompiler.dll 2017-02-13 19:25 - 2017-01-20 11:38 - 03597640 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll 2017-02-13 19:25 - 2017-01-20 11:38 - 03167288 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll 2017-02-13 19:25 - 2017-01-20 11:38 - 02715072 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll 2017-02-13 19:25 - 2017-01-20 11:38 - 01985080 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6437849.dll 2017-02-13 19:25 - 2017-01-20 11:38 - 01591352 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6437849.dll 2017-02-13 19:25 - 2017-01-20 11:38 - 01051584 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll 2017-02-13 19:25 - 2017-01-20 11:38 - 00988608 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll 2017-02-13 19:25 - 2017-01-20 11:38 - 00960568 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll 2017-02-13 19:25 - 2017-01-20 11:38 - 00946456 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncMFTH264.dll 2017-02-13 19:25 - 2017-01-20 11:38 - 00944224 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncMFThevc.dll 2017-02-13 19:25 - 2017-01-20 11:38 - 00909760 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll 2017-02-13 19:25 - 2017-01-20 11:38 - 00721952 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncMFTH264.dll 2017-02-13 19:25 - 2017-01-20 11:38 - 00719160 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncMFThevc.dll 2017-02-13 19:25 - 2017-01-20 11:38 - 00687224 _____ (NVIDIA Corporation) C:\Windows\system32\nvfatbinaryLoader.dll 2017-02-13 19:25 - 2017-01-20 11:38 - 00618232 _____ (NVIDIA Corporation) C:\Windows\system32\nvmcumd.dll 2017-02-13 19:25 - 2017-01-20 11:38 - 00609216 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFROpenGL.dll 2017-02-13 19:25 - 2017-01-20 11:38 - 00606776 _____ (NVIDIA Corporation) C:\Windows\system32\nvDecMFTMjpeg.dll 2017-02-13 19:25 - 2017-01-20 11:38 - 00576192 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvfatbinaryLoader.dll 2017-02-13 19:25 - 2017-01-20 11:38 - 00573120 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll 2017-02-13 19:25 - 2017-01-20 11:38 - 00499136 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFROpenGL.dll 2017-02-13 19:25 - 2017-01-20 11:38 - 00483384 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvDecMFTMjpeg.dll 2017-02-13 19:25 - 2017-01-20 11:38 - 00447800 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll 2017-02-13 19:25 - 2017-01-20 11:38 - 00000669 _____ C:\Windows\SysWOW64\nv-vk32.json 2017-02-13 19:25 - 2017-01-20 11:38 - 00000669 _____ C:\Windows\system32\nv-vk64.json 2017-02-13 11:37 - 2017-02-13 11:38 - 00000000 ____D C:\ProgramData\Oracle 2017-02-13 11:37 - 2017-02-13 11:37 - 00097856 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2017-02-13 11:37 - 2017-02-13 11:37 - 00000000 ____D C:\Users\TT\AppData\Roaming\Sun 2017-02-13 11:37 - 2017-02-13 11:37 - 00000000 ____D C:\Users\TT\AppData\LocalLow\Sun 2017-02-13 11:37 - 2017-02-13 11:37 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java 2017-02-13 11:37 - 2017-02-13 11:37 - 00000000 ____D C:\Program Files (x86)\Java 2017-02-13 06:19 - 2017-02-15 06:08 - 00000069 _____ C:\Users\TT\AppData\Roaming\WB.CFG 2017-02-12 22:54 - 2017-02-12 22:54 - 00000000 ____D C:\Users\TT\AppData\Local\Apps\2.0 2017-02-12 21:46 - 2017-02-19 21:46 - 00000000 ____D C:\Windows\System32\Tasks\NCH Software 2017-02-12 21:46 - 2017-02-12 21:46 - 00002340 _____ C:\Users\TT\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NCH Suite.lnk 2017-02-12 21:46 - 2017-02-12 21:46 - 00002132 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NCH Suite.lnk 2017-02-12 21:46 - 2017-02-12 21:46 - 00001368 _____ C:\Users\Public\Desktop\NCH Suite.lnk 2017-02-12 21:46 - 2017-02-12 21:46 - 00001228 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PhotoPad Image Editor.lnk 2017-02-12 21:46 - 2017-02-12 21:46 - 00001216 _____ C:\Users\Public\Desktop\PhotoPad Image Editor.lnk 2017-02-12 21:46 - 2017-02-12 21:46 - 00000000 ____D C:\Users\TT\AppData\Roaming\NCH Software 2017-02-12 21:46 - 2017-02-12 21:46 - 00000000 ____D C:\ProgramData\NCH Software 2017-02-12 21:46 - 2017-02-12 21:46 - 00000000 ____D C:\Program Files (x86)\NCH Software 2017-02-12 21:25 - 2017-03-01 08:49 - 00000000 ____D C:\Users\TT\.FBReader 2017-02-12 21:25 - 2017-02-12 21:25 - 00000000 ____D C:\Users\TT\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FBReader for Windows 2017-02-12 21:25 - 2017-02-12 21:25 - 00000000 ____D C:\Program Files (x86)\FBReader 2017-02-12 21:03 - 2017-02-14 09:58 - 00000000 ____D C:\Users\TT\Naturalsoft 2017-02-12 21:01 - 2017-02-20 11:31 - 00000000 ____D C:\Users\TT\AppData\Local\Downloaded Installations 2017-02-12 20:51 - 2017-02-12 20:51 - 00000000 ____D C:\Program Files (x86)\Natural Voice Mike16 2017-02-12 20:49 - 2017-02-12 20:51 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Natural Voice Reader 2017-02-12 20:49 - 2017-02-12 20:49 - 00000000 ____D C:\Program Files (x86)\Natural Voice Reader Enterprise 2017-02-12 20:44 - 2017-02-12 20:44 - 00000000 ____D C:\ProgramData\NaturalSoft Co. Ltd 2017-02-12 20:43 - 2017-02-20 11:32 - 00000000 ____D C:\Program Files (x86)\naturalsoft 2017-02-12 20:43 - 2017-02-12 21:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\naturalsoft 2017-02-12 20:43 - 2017-02-12 20:44 - 00000000 ____D C:\Users\TT\Documents\Naturalsoft 2017-02-12 20:43 - 2017-02-12 20:43 - 00000000 ____D C:\Users\TT\AppData\Roaming\Acapela Group 2017-02-12 20:43 - 2017-02-12 20:43 - 00000000 ____D C:\ProgramData\NaturalSoft 2017-02-12 20:43 - 2017-02-12 20:43 - 00000000 ____D C:\Program Files (x86)\TTS1.4 2017-02-12 19:49 - 2017-03-01 07:32 - 00000000 ____D C:\ProgramData\SoftMaker 2017-02-12 19:48 - 2017-02-26 01:08 - 00000000 ____D C:\Users\TT\Documents\SoftMaker 2017-02-12 19:48 - 2017-02-25 11:50 - 00000000 ____D C:\Users\TT\AppData\Roaming\SoftMaker 2017-02-12 18:47 - 2017-02-12 18:47 - 00000000 ____D C:\Users\TT\AppData\Local\PST_Walker_Software 2017-02-12 17:05 - 2017-02-01 13:23 - 00016384 _____ C:\Users\TT\Documents\WF Chking 2017.xls 2017-02-12 17:01 - 2017-02-12 07:22 - 00023040 _____ C:\Users\TT\Documents\Diabetes Records PHS.bak 2017-02-12 13:36 - 2017-02-25 11:45 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2017-02-12 13:36 - 2017-02-25 11:43 - 00001287 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Thunderbird.lnk 2017-02-12 13:36 - 2017-02-25 11:43 - 00001275 _____ C:\Users\Public\Desktop\Mozilla Thunderbird.lnk 2017-02-12 13:36 - 2017-02-25 11:43 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird 2017-02-12 13:36 - 2017-02-20 13:22 - 00000000 ____D C:\Users\TT\AppData\Roaming\Mozilla 2017-02-12 13:36 - 2017-02-12 13:44 - 00000000 ____D C:\Users\TT\AppData\Local\Thunderbird 2017-02-12 13:36 - 2017-02-12 13:36 - 00000000 ____D C:\Users\TT\AppData\Roaming\Thunderbird 2017-02-12 12:50 - 2017-02-12 19:23 - 00000000 ____D C:\Users\TT\Documents\Outlook Files 2017-02-12 12:16 - 2017-03-01 07:10 - 00000000 ____D C:\Users\TT\AppData\Local\Adobe 2017-02-12 12:15 - 2017-02-23 19:16 - 00000344 __RSH C:\ProgramData\ntuser.pol 2017-02-12 11:52 - 2017-02-12 11:52 - 00000000 ____D C:\Windows\System32\Tasks\PCMeter 2017-02-12 11:32 - 2017-02-12 11:32 - 00000000 ____D C:\Program Files\Reference Assemblies 2017-02-12 11:32 - 2017-02-12 11:32 - 00000000 ____D C:\Program Files\MSBuild 2017-02-12 11:32 - 2017-02-12 11:32 - 00000000 ____D C:\Program Files (x86)\Reference Assemblies 2017-02-12 11:32 - 2017-02-12 11:32 - 00000000 ____D C:\Program Files (x86)\MSBuild 2017-02-12 11:30 - 2016-05-25 14:31 - 01166520 _____ (Microsoft Corporation) C:\Windows\system32\PresentationNative_v0300.dll 2017-02-12 11:30 - 2016-05-25 14:31 - 00124624 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll 2017-02-12 11:30 - 2016-05-25 14:31 - 00035480 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe 2017-02-12 11:30 - 2016-05-25 11:03 - 00778936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationNative_v0300.dll 2017-02-12 11:30 - 2016-05-25 11:03 - 00103120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll 2017-02-12 11:30 - 2016-05-25 11:03 - 00035480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TsWpfWrp.exe 2017-02-12 11:28 - 2017-02-12 11:28 - 00000000 ____D C:\Users\TT\Downloads\PCMeter 2017-02-12 11:13 - 2017-02-27 21:18 - 00000841 _____ C:\Users\TT\AppData\Roaming\Drives Meter_Settings.ini 2017-02-12 11:11 - 2017-03-01 17:41 - 00000027 _____ C:\Users\TT\AppData\Roaming\Network Meter_Usage.ini 2017-02-12 11:08 - 2017-02-12 11:08 - 00000000 ____D C:\Users\TT\AppData\Local\CEF 2017-02-12 11:00 - 2017-03-01 17:00 - 00010801 _____ C:\Users\TT\Network_Meter_Data.js 2017-02-12 11:00 - 2017-03-01 13:42 - 00006174 _____ C:\Users\TT\IP_Log_Data.js 2017-02-12 11:00 - 2017-02-12 12:05 - 00001369 _____ C:\Users\TT\AppData\Roaming\Network Meter_Settings.ini 2017-02-12 10:57 - 2017-02-12 12:08 - 00000285 _____ C:\Users\TT\AppData\Roaming\GPU MeterV2_Settings.ini 2017-02-12 10:56 - 2017-02-12 12:05 - 00000627 _____ C:\Users\TT\AppData\Roaming\All CPU MeterV3_Settings.ini 2017-02-12 10:52 - 2017-03-01 17:08 - 00000000 ____D C:\Users\TT\AppData\Local\Sidebar7 2017-02-12 10:51 - 2017-02-12 10:54 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\8GadgetPack 2017-02-12 10:13 - 2017-02-12 10:13 - 00001066 _____ C:\Users\Public\Desktop\xplorer2 pro x64.lnk 2017-02-12 10:13 - 2017-02-12 10:13 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\xplorer2 pro x64 2017-02-12 10:13 - 2017-02-12 10:13 - 00000000 ____D C:\Program Files\zabkat 2017-02-12 08:54 - 2017-02-21 07:00 - 00000000 ____D C:\Users\TT\AppData\Local\Chromium 2017-02-12 04:54 - 2016-12-21 02:08 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe 2017-02-12 04:54 - 2016-12-20 23:44 - 00120320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\poqexec.exe 2017-02-12 04:51 - 2017-02-12 04:51 - 00000000 ____D C:\Users\TT\AppData\LocalLow\Temp 2017-02-12 02:38 - 2017-02-12 00:13 - 00000000 ___DC C:\Windows\Panther 2017-02-12 02:32 - 2017-02-12 02:32 - 23678464 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 22563840 _____ (Microsoft Corporation) C:\Windows\system32\edgehtml.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 22224480 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 20969928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 19417600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 19413504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\edgehtml.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 17188864 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 13869056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 13084160 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 12177920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 09131008 _____ (Microsoft Corporation) C:\Windows\system32\twinui.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 08168000 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Protection.PlayReady.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 08129536 _____ (Microsoft Corporation) C:\Windows\system32\Chakra.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 08075776 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 07816032 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2017-02-12 02:32 - 2017-02-12 02:32 - 07812096 _____ (Microsoft Corporation) C:\Windows\system32\BingMaps.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 07654400 _____ (Microsoft Corporation) C:\Windows\system32\mos.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 07626752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinui.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 07469056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 07219672 _____ (Microsoft Corporation) C:\Windows\system32\windows.storage.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 06668040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Protection.PlayReady.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 06664192 _____ (Microsoft Corporation) C:\Windows\system32\mspaint.exe 2017-02-12 02:32 - 2017-02-12 02:32 - 06474752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mspaint.exe 2017-02-12 02:32 - 2017-02-12 02:32 - 06285312 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 06109184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mos.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 06044160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Chakra.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 05722832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\windows.storage.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 05611008 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 05511680 _____ (Microsoft Corporation) C:\Windows\system32\aclui.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 05398016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aclui.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 05380608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\BingMaps.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 05114368 _____ (Microsoft Corporation) C:\Windows\system32\cdp.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 05061120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 04749312 _____ (Microsoft Corporation) C:\Windows\system32\SettingsHandlers_nt.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 04746752 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 04708864 _____ (Microsoft Corporation) C:\Windows\system32\ExplorerFrame.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 04673304 _____ (Microsoft Corporation) C:\Windows\explorer.exe 2017-02-12 02:32 - 2017-02-12 02:32 - 04612608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 04474368 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_47.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 04423680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ExplorerFrame.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 04311736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe 2017-02-12 02:32 - 2017-02-12 02:32 - 04149248 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 04136448 _____ (Microsoft Corporation) C:\Windows\system32\Windows.StateRepository.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 04130440 _____ (Microsoft Corporation) C:\Windows\system32\mfcore.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 03892864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfcore.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 03777536 _____ (Microsoft Corporation) C:\Windows\system32\MFMediaEngine.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 03733504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_47.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 03689984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 03666432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 03616768 _____ (Microsoft Corporation) C:\Windows\system32\win32kfull.sys 2017-02-12 02:32 - 2017-02-12 02:32 - 03542016 _____ (Microsoft Corporation) C:\Windows\system32\actxprxy.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 03441152 _____ (Microsoft Corporation) C:\Windows\system32\MapRouter.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 03400192 _____ (Microsoft Corporation) C:\Windows\system32\SyncCenter.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 03370496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.StateRepository.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 03306496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFMediaEngine.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 03198464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cdp.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 03134976 _____ (Microsoft Corporation) C:\Windows\system32\rdpcore.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 03059200 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 02998272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32kfull.sys 2017-02-12 02:32 - 2017-02-12 02:32 - 02953216 _____ (Microsoft Corporation) C:\Windows\system32\MapGeocoder.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 02913144 _____ (Microsoft Corporation) C:\Windows\system32\combase.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 02852864 _____ (Microsoft Corporation) C:\Windows\system32\SystemSettingsThresholdAdminFlowUI.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 02828376 _____ (Microsoft Corporation) C:\Windows\system32\d3d11.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 02820096 _____ (Microsoft Corporation) C:\Windows\system32\InputService.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 02800128 _____ (Microsoft Corporation) C:\Windows\system32\netshell.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 02748416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpcore.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 02716672 _____ (Microsoft Corporation) C:\Windows\system32\WsmSvc.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 02691072 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Logon.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 02682880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netshell.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 02681200 _____ C:\Windows\system32\CoreUIComponents.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 02677544 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 02669056 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 02611200 _____ (Microsoft Corporation) C:\Windows\system32\gameux.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 02510848 _____ (Microsoft Corporation) C:\Windows\system32\NetworkMobileSettings.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 02484736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gameux.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 02482280 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 02362880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MapRouter.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 02333184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmSvc.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 02323728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 02317824 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 02287616 _____ (Microsoft Corporation) C:\Windows\system32\dwmcore.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 02277248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 02275840 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentServer.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 02256384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 02213760 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 02206496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 02189664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys 2017-02-12 02:32 - 2017-02-12 02:32 - 02186896 _____ (Microsoft Corporation) C:\Windows\system32\hevcdecoder.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 02169184 _____ (Microsoft Corporation) C:\Windows\system32\AppVEntSubsystems64.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 02166752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\combase.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 02138112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InputService.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 02109952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MapGeocoder.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 02104320 _____ (Microsoft Corporation) C:\Windows\system32\wlidsvc.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 02084352 _____ (Microsoft Corporation) C:\Windows\system32\DeviceFlows.DataModel.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 02048496 _____ C:\Windows\SysWOW64\CoreUIComponents.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 02009600 _____ (Microsoft Corporation) C:\Windows\system32\SRHInproc.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 01992704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dwmcore.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 01988560 _____ (Microsoft Corporation) C:\Windows\system32\mfmp4srcsnk.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 01969912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\hevcdecoder.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 01908224 _____ (Microsoft Corporation) C:\Windows\system32\AzureSettingSyncProvider.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 01886344 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 01883648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Logon.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 01859264 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 01852720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfmp4srcsnk.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 01779712 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 01755136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DeviceFlows.DataModel.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 01738560 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 01726976 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Immersive.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 01709056 _____ (Microsoft Corporation) C:\Windows\system32\UIAutomationCore.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 01706488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 01702392 _____ (Microsoft Corporation) C:\Windows\system32\mfasfsrcsnk.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 01694712 _____ (Microsoft Corporation) C:\Windows\system32\winmde.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 01692672 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentExtensions.onecore.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 01691136 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe 2017-02-12 02:32 - 2017-02-12 02:32 - 01669984 _____ (Microsoft Corporation) C:\Windows\system32\AppVIntegration.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 01637728 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 01631232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.Resources.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 01631232 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.Resources.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 01600632 _____ (Microsoft Corporation) C:\Windows\system32\sppobjs.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 01595392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 01589760 _____ (Microsoft Corporation) C:\Windows\system32\msdtctm.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 01576448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\actxprxy.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 01572768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 01572768 _____ (Microsoft Corporation) C:\Windows\system32\gdi32full.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 01557808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winmde.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 01556480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Immersive.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 01513472 _____ (Microsoft Corporation) C:\Windows\system32\win32kbase.sys 2017-02-12 02:32 - 2017-02-12 02:32 - 01503544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 01490432 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 01477632 _____ (Microsoft Corporation) C:\Windows\system32\wsecedit.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 01473048 _____ (Microsoft Corporation) C:\Windows\system32\mfplat.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 01469792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppVEntSubsystems32.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 01461200 _____ (Microsoft Corporation) C:\Windows\system32\user32.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 01454504 _____ (Microsoft Corporation) C:\Windows\system32\mfnetsrc.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 01435896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user32.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 01430720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 01418312 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 01415752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32full.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 01400160 _____ (Microsoft Corporation) C:\Windows\system32\AppVEntSubsystemController.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 01366016 _____ (Microsoft Corporation) C:\Windows\system32\wpncore.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 01360464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfnetsrc.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\usercpl.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 01357824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIAutomationCore.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 01356864 _____ (Microsoft Corporation) C:\Windows\system32\ClipUp.exe 2017-02-12 02:32 - 2017-02-12 02:32 - 01354320 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi 2017-02-12 02:32 - 2017-02-12 02:32 - 01336320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wsecedit.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 01300600 _____ (Microsoft Corporation) C:\Windows\system32\mfmpeg2srcsnk.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 01300480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSVPXENC.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 01293152 _____ (Microsoft Corporation) C:\Windows\system32\LicenseManager.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 01292288 _____ (Microsoft Corporation) C:\Windows\system32\MSVPXENC.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 01277344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfasfsrcsnk.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 01274712 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 01267512 _____ (Microsoft Corporation) C:\Windows\system32\WinTypes.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 01263856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msctf.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 01255936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AzureSettingSyncProvider.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 01235296 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 01231872 _____ (Microsoft Corporation) C:\Windows\system32\dosvc.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 01228288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usercpl.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 01220096 _____ (Microsoft Corporation) C:\Windows\system32\wscui.cpl 2017-02-12 02:32 - 2017-02-12 02:32 - 01201872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfmpeg2srcsnk.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 01196544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscui.cpl 2017-02-12 02:32 - 2017-02-12 02:32 - 01173496 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe 2017-02-12 02:32 - 2017-02-12 02:32 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSVP9DEC.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 01123912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfplat.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 01121280 _____ (Microsoft Corporation) C:\Windows\system32\aadtb.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 01100128 _____ (Microsoft Corporation) C:\Windows\system32\hvix64.exe 2017-02-12 02:32 - 2017-02-12 02:32 - 01071736 _____ (Microsoft Corporation) C:\Windows\system32\mfnetcore.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 01069720 _____ (Microsoft Corporation) C:\Windows\system32\MrmCoreR.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 01062912 _____ (Microsoft Corporation) C:\Windows\system32\SettingSyncCore.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 01062480 _____ (Microsoft Corporation) C:\Windows\system32\mfsvr.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 01060864 _____ (Microsoft Corporation) C:\Windows\system32\JpMapControl.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 01054048 _____ (Microsoft Corporation) C:\Windows\system32\AppVPolicy.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 01051112 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi 2017-02-12 02:32 - 2017-02-12 02:32 - 01031680 _____ (Microsoft Corporation) C:\Windows\system32\MapsStore.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 01005568 _____ (Microsoft Corporation) C:\Windows\system32\D3D12.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 01004544 _____ (Microsoft Corporation) C:\Windows\system32\enterprisecsps.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 01002496 _____ (Microsoft Corporation) C:\Windows\system32\SRH.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00992096 _____ (Microsoft Corporation) C:\Windows\system32\AppVManifest.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00991232 _____ (Microsoft Corporation) C:\Windows\system32\comdlg32.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00989024 _____ (Microsoft Corporation) C:\Windows\system32\hvax64.exe 2017-02-12 02:32 - 2017-02-12 02:32 - 00981504 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Security.Authentication.OnlineId.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00980832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfnetcore.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00967168 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bthport.sys 2017-02-12 02:32 - 2017-02-12 02:32 - 00960000 _____ (Microsoft Corporation) C:\Windows\system32\modernexecserver.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00959112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00952416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfsvr.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00947712 _____ (Microsoft Corporation) C:\Windows\system32\MSVP9DEC.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00947552 _____ (Microsoft Corporation) C:\Windows\system32\hvloader.efi 2017-02-12 02:32 - 2017-02-12 02:32 - 00936960 _____ (Microsoft Corporation) C:\Windows\system32\MCRecvSrc.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00936448 _____ (Microsoft Corporation) C:\Windows\system32\NMAA.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00932864 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00912896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comdlg32.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00909312 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Search.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00905216 _____ (Microsoft Corporation) C:\Windows\system32\MapControlCore.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00894096 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe 2017-02-12 02:32 - 2017-02-12 02:32 - 00886272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aadtb.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00883712 _____ (Microsoft Corporation) C:\Windows\system32\samsrv.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00882680 _____ (Microsoft Corporation) C:\Windows\system32\EditionUpgradeManagerObj.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00870912 _____ (Microsoft Corporation) C:\Windows\system32\msdtcprx.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00870400 _____ (Microsoft Corporation) C:\Windows\system32\mfmkvsrcsnk.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00869888 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00869848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MrmCoreR.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00866816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Cred.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00861024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\LicenseManager.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00860672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SettingSyncCore.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00846560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WinTypes.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00842240 _____ (Microsoft Corporation) C:\Windows\system32\ntshrui.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00838144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JpMapControl.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00837632 _____ (Microsoft Corporation) C:\Windows\system32\wbiosrvc.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00822624 _____ (Microsoft Corporation) C:\Windows\system32\AppVClient.exe 2017-02-12 02:32 - 2017-02-12 02:32 - 00813408 _____ (Microsoft Corporation) C:\Windows\system32\AppVEntStreamingManager.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00811872 _____ (Microsoft Corporation) C:\Windows\system32\hvloader.exe 2017-02-12 02:32 - 2017-02-12 02:32 - 00806400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3D12.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00779776 _____ (Microsoft Corporation) C:\Windows\system32\cscui.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00779616 _____ (Microsoft Corporation) C:\Windows\system32\AppVReporting.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00772608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntshrui.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00764392 _____ (Microsoft Corporation) C:\Windows\system32\CoreMessaging.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00760832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\NMAA.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00755712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00752992 _____ (Microsoft Corporation) C:\Windows\system32\AppVOrchestration.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00748544 _____ (Microsoft Corporation) C:\Windows\system32\StoreAgent.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00746496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdtcprx.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00743224 _____ (Microsoft Corporation) C:\Windows\system32\sppwinob.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00730624 _____ (Microsoft Corporation) C:\Windows\system32\fveapi.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00716800 _____ (Microsoft Corporation) C:\Windows\system32\ShareHost.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00715264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MapControlCore.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00715104 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\vhdmp.sys 2017-02-12 02:32 - 2017-02-12 02:32 - 00713216 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys 2017-02-12 02:32 - 2017-02-12 02:32 - 00712192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00711680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Search.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00707584 _____ (Microsoft Corporation) C:\Windows\system32\LogonController.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00704352 _____ (Microsoft Corporation) C:\Windows\system32\AppVEntVirtualization.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00696160 _____ (Microsoft Corporation) C:\Windows\system32\AppVPublishing.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00691712 _____ (Microsoft Corporation) C:\Windows\system32\lsm.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\ieproxy.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00673792 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe 2017-02-12 02:32 - 2017-02-12 02:32 - 00658784 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms2.sys 2017-02-12 02:32 - 2017-02-12 02:32 - 00657920 _____ (Microsoft Corporation) C:\Windows\system32\rasmans.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00650752 _____ (Microsoft Corporation) C:\Windows\system32\RDXService.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00641024 _____ (Microsoft Corporation) C:\Windows\system32\ngccredprov.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00640000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MCRecvSrc.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00637400 _____ (Microsoft Corporation) C:\Windows\system32\dxgi.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00635904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00632320 _____ (Microsoft Corporation) C:\Windows\system32\rasapi32.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00624048 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys 2017-02-12 02:32 - 2017-02-12 02:32 - 00620544 _____ (Microsoft Corporation) C:\Windows\system32\bcastdvr.exe 2017-02-12 02:32 - 2017-02-12 02:32 - 00615424 _____ (Microsoft Corporation) C:\Windows\system32\wpnprv.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00603488 _____ (Microsoft Corporation) C:\Windows\system32\ContentDeliveryManager.Utilities.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00600576 _____ (Microsoft Corporation) C:\Windows\system32\cryptui.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00590960 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00590336 _____ (Microsoft Corporation) C:\Windows\system32\efswrt.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00587776 _____ (Microsoft Corporation) C:\Windows\system32\vpnike.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00584544 _____ (Microsoft Corporation) C:\Windows\system32\SettingSyncHost.exe 2017-02-12 02:32 - 2017-02-12 02:32 - 00574464 _____ (Microsoft Corporation) C:\Windows\system32\SettingsHandlers_StorageSense.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00571744 _____ (Microsoft Corporation) C:\Windows\system32\AppVCatalog.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00567296 _____ (Microsoft Corporation) C:\Windows\system32\DevicePairing.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00566784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ShareHost.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00565248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rasapi32.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00560128 _____ (Microsoft Corporation) C:\Windows\system32\AppReadiness.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00557568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\StoreAgent.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00553984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptui.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00545280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfmkvsrcsnk.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00539648 _____ (Microsoft Corporation) C:\Windows\system32\usocore.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00539136 _____ (Microsoft Corporation) C:\Windows\system32\PlayToManager.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00527880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxgi.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00519168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ngccredprov.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00513376 _____ (Microsoft Corporation) C:\Windows\system32\TransportDSA.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00509792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SettingSyncHost.exe 2017-02-12 02:32 - 2017-02-12 02:32 - 00506880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DevicePairing.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00505856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcastdvr.exe 2017-02-12 02:32 - 2017-02-12 02:32 - 00497152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\LogonController.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00495104 _____ (Microsoft Corporation) C:\Windows\system32\DataSenseHandlers.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00489472 _____ (Microsoft Corporation) C:\Windows\system32\NetSetupShim.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00483840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CoreMessaging.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00462336 _____ (Microsoft Corporation) C:\Windows\system32\fhsettingsprovider.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00455520 _____ (Microsoft Corporation) C:\Windows\system32\securekernel.exe 2017-02-12 02:32 - 2017-02-12 02:32 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\dmenrollengine.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00454592 _____ (Microsoft Corporation) C:\Windows\system32\services.exe 2017-02-12 02:32 - 2017-02-12 02:32 - 00446976 _____ (Microsoft Corporation) C:\Windows\system32\MapConfiguration.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00440320 _____ (Microsoft Corporation) C:\Windows\system32\fhcfg.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00433664 _____ (Microsoft Corporation) C:\Windows\system32\TextInputFramework.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00433504 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdbss.sys 2017-02-12 02:32 - 2017-02-12 02:32 - 00431616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\efswrt.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00425984 _____ (Microsoft Corporation) C:\Windows\system32\aadcloudap.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00424616 _____ (Microsoft Corporation) C:\Windows\system32\MFPlay.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00418952 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00418304 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.BlockedShutdown.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00411648 _____ (Microsoft Corporation) C:\Windows\system32\cdpsvc.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00411136 _____ (Microsoft Corporation) C:\Windows\system32\facecredentialprovider.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00410112 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentClient.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00409088 _____ (Microsoft Corporation) C:\Windows\system32\NgcCtnr.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00407552 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Internal.Management.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00406368 _____ (Microsoft Corporation) C:\Windows\system32\AppVScripting.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00404832 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00402272 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys 2017-02-12 02:32 - 2017-02-12 02:32 - 00400384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PlayToManager.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00396800 _____ (Microsoft Corporation) C:\Windows\system32\StorSvc.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00395264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dmenrollengine.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00391168 _____ (Microsoft Corporation) C:\Windows\system32\wuuhext.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00389632 _____ (Microsoft Corporation) C:\Windows\system32\stobject.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00389632 _____ (Microsoft Corporation) C:\Windows\system32\ActivationManager.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00388096 _____ (Microsoft Corporation) C:\Windows\system32\zipfldr.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00382784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AUDIOKSE.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00381952 _____ (Microsoft Corporation) C:\Windows\system32\cryptngc.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00380928 _____ (Microsoft Corporation) C:\Windows\system32\wincorlib.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00379392 _____ (Microsoft Corporation) C:\Windows\system32\apprepsync.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00377184 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\clfs.sys 2017-02-12 02:32 - 2017-02-12 02:32 - 00376832 _____ (Microsoft Corporation) C:\Windows\system32\CryptoWinRT.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00374448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFPlay.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00368640 _____ (Microsoft Corporation) C:\Windows\system32\OneBackupHandler.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00366080 _____ (Microsoft Corporation) C:\Windows\system32\SearchFolder.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00366080 _____ (Microsoft Corporation) C:\Windows\system32\RDXTaskFactory.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00364544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\NetSetupShim.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00363520 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.BioFeedback.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00360448 _____ (Microsoft Corporation) C:\Windows\system32\rdpencom.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00360040 _____ (Microsoft Corporation) C:\Windows\system32\SystemSettingsAdminFlows.exe 2017-02-12 02:32 - 2017-02-12 02:32 - 00359936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mtxclu.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00358912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\stobject.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00353280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TextInputFramework.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00352768 _____ (Microsoft Corporation) C:\Windows\system32\cloudAP.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00352096 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fastfat.sys 2017-02-12 02:32 - 2017-02-12 02:32 - 00349184 _____ (Microsoft Corporation) C:\Windows\system32\provengine.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00348672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\zipfldr.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00347648 _____ (Microsoft Corporation) C:\Windows\system32\rascustom.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00341344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00339456 _____ (Microsoft Corporation) C:\Windows\system32\cdpusersvc.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00335712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\pci.sys 2017-02-12 02:32 - 2017-02-12 02:32 - 00333312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ActivationManager.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00332288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MapConfiguration.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00328008 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Storage.ApplicationData.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00324096 _____ (Microsoft Corporation) C:\Windows\system32\domgmt.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00320000 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00319288 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00318976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpencom.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00318464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchFolder.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00313856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppXDeploymentClient.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00313856 _____ (Microsoft Corporation) C:\Windows\system32\moshostcore.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00310784 _____ (Microsoft Corporation) C:\Windows\system32\SyncSettings.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00306176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieproxy.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00306176 _____ (Microsoft Corporation) C:\Windows\system32\msdtcuiu.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00298496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Internal.Management.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00295424 _____ (Microsoft Corporation) C:\Windows\system32\CloudBackupSettings.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00290816 _____ (Microsoft Corporation) C:\Windows\system32\updatehandlers.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00289792 _____ (Microsoft Corporation) C:\Windows\system32\DeveloperOptionsSettingsHandlers.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00288768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wincorlib.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptngc.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00285696 _____ (Microsoft Corporation) C:\Windows\system32\EnterpriseAppMgmtSvc.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00285184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.BlockedShutdown.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00284672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apprepsync.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00283648 _____ (Microsoft Corporation) C:\Windows\system32\wkssvc.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00282624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys 2017-02-12 02:32 - 2017-02-12 02:32 - 00278016 _____ (Microsoft Corporation) C:\Windows\system32\netplwiz.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00266752 _____ (Microsoft Corporation) C:\Windows\system32\ConsoleLogon.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00266544 _____ (Microsoft Corporation) C:\Windows\system32\policymanager.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00263472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Storage.ApplicationData.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00261632 _____ (Microsoft Corporation) C:\Windows\system32\indexeddbserver.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00261120 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Core.TextInput.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00260608 _____ (Microsoft Corporation) C:\Windows\system32\InstallAgentUserBroker.exe 2017-02-12 02:32 - 2017-02-12 02:32 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdtcuiu.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00258560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\xboxgip.sys 2017-02-12 02:32 - 2017-02-12 02:32 - 00257024 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.CredDialogController.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00253952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.BioFeedback.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00253952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00248480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\policymanager.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00245600 _____ (Microsoft Corporation) C:\Windows\system32\offlinesam.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00241504 _____ (Microsoft Corporation) C:\Windows\system32\CloudExperienceHost.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00241504 _____ (Microsoft Corporation) C:\Windows\system32\AppVShNotify.exe 2017-02-12 02:32 - 2017-02-12 02:32 - 00237056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SyncSettings.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00236544 _____ (Microsoft Corporation) C:\Windows\system32\WinSCard.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00234496 _____ (Microsoft Corporation) C:\Windows\system32\KnobsCore.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00231936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.LockScreen.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00231424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CloudBackupSettings.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00223744 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2017-02-12 02:32 - 2017-02-12 02:32 - 00223584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys 2017-02-12 02:32 - 2017-02-12 02:32 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InstallAgentUserBroker.exe 2017-02-12 02:32 - 2017-02-12 02:32 - 00219488 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tpm.sys 2017-02-12 02:32 - 2017-02-12 02:32 - 00218976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\offlinesam.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00213504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.CredDialogController.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00211968 _____ (Microsoft Corporation) C:\Windows\system32\InstallAgent.exe 2017-02-12 02:32 - 2017-02-12 02:32 - 00208896 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Internal.UI.Logon.ProxyStub.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00206848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Core.TextInput.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2017-02-12 02:32 - 2017-02-12 02:32 - 00201728 _____ (Microsoft Corporation) C:\Windows\system32\ScDeviceEnum.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00198856 _____ (Microsoft Corporation) C:\Windows\system32\wscapi.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00198656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\indexeddbserver.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00198656 _____ (Microsoft Corporation) C:\Windows\system32\BcastDVRHelper.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00198144 _____ (Microsoft Corporation) C:\Windows\system32\dpapisrv.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00193536 _____ (Microsoft Corporation) C:\Windows\system32\certprop.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00190816 _____ (Microsoft Corporation) C:\Windows\system32\AppVDllSurrogate.exe 2017-02-12 02:32 - 2017-02-12 02:32 - 00187520 _____ (Microsoft Corporation) C:\Windows\system32\CloudStorageWizard.exe 2017-02-12 02:32 - 2017-02-12 02:32 - 00187392 _____ (Microsoft Corporation) C:\Windows\system32\mdmregistration.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00185344 _____ (Microsoft Corporation) C:\Windows\system32\DisplayManager.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00184832 _____ (Microsoft Corporation) C:\Windows\system32\wscsvc.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InstallAgent.exe 2017-02-12 02:32 - 2017-02-12 02:32 - 00178176 _____ (Microsoft Corporation) C:\Windows\system32\sppnp.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00176128 _____ (Microsoft Corporation) C:\Windows\system32\apprepapi.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00172544 _____ (Microsoft Corporation) C:\Windows\system32\DeviceEnroller.exe 2017-02-12 02:32 - 2017-02-12 02:32 - 00172528 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00170496 _____ (Microsoft Corporation) C:\Windows\system32\AppCapture.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00168424 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00167848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscapi.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00167424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WinSCard.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00165376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mdmregistration.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00164352 _____ (Microsoft Corporation) C:\Windows\system32\dialserver.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\EnterpriseModernAppMgmtCSP.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00163752 _____ (Microsoft Corporation) C:\Windows\system32\RTWorkQ.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00161792 _____ (Microsoft Corporation) C:\Windows\system32\EditionUpgradeHelper.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00159744 _____ (Microsoft Corporation) C:\Windows\system32\ACPBackgroundManagerPolicy.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00159232 _____ (Microsoft Corporation) C:\Windows\system32\wscinterop.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00158720 _____ (Microsoft Corporation) C:\Windows\system32\VEStoreEventHandlers.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00157536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CloudStorageWizard.exe 2017-02-12 02:32 - 2017-02-12 02:32 - 00156672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\BcastDVRHelper.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00152416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RTWorkQ.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00151040 _____ (Microsoft Corporation) C:\Windows\system32\MapsBtSvc.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00147968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32k.sys 2017-02-12 02:32 - 2017-02-12 02:32 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\dmcertinst.exe 2017-02-12 02:32 - 2017-02-12 02:32 - 00147456 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00143360 _____ (Microsoft Corporation) C:\Windows\system32\EDPCleanup.exe 2017-02-12 02:32 - 2017-02-12 02:32 - 00142176 _____ (Microsoft Corporation) C:\Windows\system32\migisol.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00140288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppCapture.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00138240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DisplayManager.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00137568 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sendmail.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00136032 _____ (Microsoft Corporation) C:\Windows\system32\ImplatSetup.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00128352 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\partmgr.sys 2017-02-12 02:32 - 2017-02-12 02:32 - 00126568 _____ (Microsoft Corporation) C:\Windows\system32\mfaudiocnv.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00125952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apprepapi.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00125952 _____ (Microsoft Corporation) C:\Windows\system32\setupugc.exe 2017-02-12 02:32 - 2017-02-12 02:32 - 00122880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sendmail.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00122880 _____ (Microsoft Corporation) C:\Windows\system32\Windows.StateRepositoryClient.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00122208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\migisol.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00119808 _____ (Microsoft Corporation) C:\Windows\system32\KnobsCsp.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00119296 _____ (Microsoft Corporation) C:\Windows\system32\InputLocaleManager.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00117248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MapsBtSvc.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00117240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00115200 _____ (Microsoft Corporation) C:\Windows\system32\IdCtrls.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00114176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setupugc.exe 2017-02-12 02:32 - 2017-02-12 02:32 - 00110080 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Networking.BackgroundTransfer.BackgroundManagerPolicy.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00109056 _____ (Microsoft Corporation) C:\Windows\system32\ReportingCSP.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00108544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wscinterop.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00107520 _____ (Microsoft Corporation) C:\Windows\system32\VPNv2CSP.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00106896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcrypt.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\RjvMDMConfig.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00104448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Internal.UI.Logon.ProxyStub.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00101216 _____ (Microsoft Corporation) C:\Windows\system32\DeviceReactivation.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\browserbroker.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00096256 _____ (Microsoft Corporation) C:\Windows\system32\umpoext.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00094208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.StateRepositoryClient.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00092672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InputLocaleManager.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00092512 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00091936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfaudiocnv.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00091648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.BackgroundTransfer.BackgroundManagerPolicy.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\updatepolicy.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\MosStorage.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00089416 _____ (Microsoft Corporation) C:\Windows\system32\remoteaudioendpoint.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\NetCfgNotifyObjectHost.exe 2017-02-12 02:32 - 2017-02-12 02:32 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\EditBufferTestHook.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\ProvPluginEng.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00082944 _____ (Microsoft Corporation) C:\Windows\system32\moshost.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\HttpsDataSource.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00076984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\remoteaudioendpoint.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00074752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\updatepolicy.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\Windows.StateRepositoryBroker.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00071168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MosStorage.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00068096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\EditBufferTestHook.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00068096 _____ (Microsoft Corporation) C:\Windows\system32\ProvSysprep.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00068096 _____ (Microsoft Corporation) C:\Windows\system32\lpremove.exe 2017-02-12 02:32 - 2017-02-12 02:32 - 00065024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\NetCfgNotifyObjectHost.exe 2017-02-12 02:32 - 2017-02-12 02:32 - 00058880 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Shell.Search.UriHandler.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00053248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xolehlp.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00049152 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Shell.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Shell.Search.UriHandler.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\LaunchWinApp.exe 2017-02-12 02:32 - 2017-02-12 02:32 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\modem.sys 2017-02-12 02:32 - 2017-02-12 02:32 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\EAMProgressHandler.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00040960 _____ (Microsoft Corporation) C:\Windows\system32\CbtBackgroundManagerPolicy.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\WordBreakers.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00034816 _____ (Microsoft Corporation) C:\Windows\system32\ReAgentc.exe 2017-02-12 02:32 - 2017-02-12 02:32 - 00034304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\LaunchWinApp.exe 2017-02-12 02:32 - 2017-02-12 02:32 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManHTTPConfig.exe 2017-02-12 02:32 - 2017-02-12 02:32 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WordBreakers.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00032256 _____ (Microsoft Corporation) C:\Windows\system32\WSManHTTPConfig.exe 2017-02-12 02:32 - 2017-02-12 02:32 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ReAgentc.exe 2017-02-12 01:36 - 2017-02-12 01:36 - 00008192 _____ C:\Windows\system32\config\userdiff 2017-02-12 00:13 - 2017-02-12 07:43 - 00000000 ____D C:\Users\TT\AppData\Local\ConnectedDevicesPlatform 2017-02-12 00:13 - 2017-02-12 00:13 - 00000020 ___SH C:\Users\TT\ntuser.ini 2017-02-12 00:13 - 2017-02-12 00:13 - 00000000 _SHDL C:\Users\Default\My Documents 2017-02-12 00:13 - 2017-02-12 00:13 - 00000000 _SHDL C:\Users\Default\Documents\My Videos 2017-02-12 00:13 - 2017-02-12 00:13 - 00000000 _SHDL C:\Users\Default\Documents\My Pictures 2017-02-12 00:13 - 2017-02-12 00:13 - 00000000 _SHDL C:\Users\Default\Documents\My Music 2017-02-12 00:13 - 2017-02-12 00:13 - 00000000 _SHDL C:\Users\Default User\Documents\My Videos 2017-02-12 00:13 - 2017-02-12 00:13 - 00000000 _SHDL C:\Users\Default User\Documents\My Pictures 2017-02-12 00:13 - 2017-02-12 00:13 - 00000000 _SHDL C:\Users\Default User\Documents\My Music 2017-02-12 00:11 - 2017-02-12 00:12 - 00007623 _____ C:\Windows\diagwrn.xml 2017-02-12 00:11 - 2017-02-12 00:12 - 00007623 _____ C:\Windows\diagerr.xml 2017-02-12 00:10 - 2017-03-01 17:39 - 00003044 _____ C:\Windows\System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2017-02-12 00:10 - 2017-03-01 17:39 - 00003016 _____ C:\Windows\System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2017-02-12 00:10 - 2017-03-01 17:39 - 00002898 _____ C:\Windows\System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2017-02-12 00:10 - 2017-03-01 17:39 - 00002846 _____ C:\Windows\System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2017-02-12 00:10 - 2017-03-01 17:39 - 00002828 _____ C:\Windows\System32\Tasks\OneDrive Standalone Update Task v2 2017-02-12 00:10 - 2017-03-01 17:39 - 00002804 _____ C:\Windows\System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} 2017-02-12 00:10 - 2017-03-01 17:38 - 00003404 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2017-02-12 00:10 - 2017-03-01 17:38 - 00003180 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2017-02-12 00:07 - 2017-02-12 00:07 - 00022744 _____ C:\Windows\system32\emptyregdb.dat 2017-02-12 00:02 - 2017-02-12 00:02 - 00001576 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk 2017-02-11 23:59 - 2017-02-12 00:03 - 00000000 ____D C:\Windows\system32\config\bbimigrate 2017-02-11 23:57 - 2017-02-26 14:09 - 00000000 ____D C:\Users\TT 2017-02-11 23:57 - 2017-02-11 23:57 - 00000000 _SHDL C:\Users\TT\My Documents 2017-02-11 23:57 - 2017-02-11 23:57 - 00000000 _SHDL C:\Users\TT\Documents\My Videos 2017-02-11 23:57 - 2017-02-11 23:57 - 00000000 _SHDL C:\Users\TT\Documents\My Pictures 2017-02-11 23:57 - 2017-02-11 23:57 - 00000000 _SHDL C:\Users\TT\Documents\My Music 2017-02-11 23:54 - 2017-02-14 20:31 - 00000000 ____D C:\ProgramData\NVIDIA Corporation 2017-02-11 23:54 - 2017-02-14 20:31 - 00000000 ____D C:\Program Files\NVIDIA Corporation 2017-02-11 23:54 - 2017-02-14 20:31 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation 2017-02-11 23:54 - 2017-02-11 23:54 - 00000000 ____D C:\ProgramData\Realtek 2017-02-11 23:54 - 2017-01-20 10:13 - 06401984 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll 2017-02-11 23:54 - 2017-01-20 10:13 - 02479160 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll 2017-02-11 23:54 - 2017-01-20 10:13 - 01762752 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll 2017-02-11 23:54 - 2017-01-20 10:13 - 00548800 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshext.dll 2017-02-11 23:54 - 2017-01-20 10:13 - 00393784 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll 2017-02-11 23:54 - 2017-01-20 10:13 - 00083512 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshextr.dll 2017-02-11 23:54 - 2017-01-20 10:13 - 00069568 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll 2017-02-11 23:54 - 2017-01-18 07:57 - 07755067 _____ C:\Windows\system32\nvcoproc.bin 2017-02-11 19:16 - 2017-02-11 19:16 - 00000000 ____D C:\Users\TT\AppData\Roaming\Macromedia 2017-02-11 11:29 - 2017-02-11 11:29 - 00000000 _____ C:\Users\TT\AppData\Local\{2C76CAA0-E6A0-4230-ADA2-B0C54116E1F8} 2017-02-10 11:09 - 2017-03-01 08:38 - 00000000 ____D C:\Users\TT\AppData\Local\CrashDumps 2017-02-10 11:09 - 2017-02-10 11:09 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games ==================== One Month Modified files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2017-03-01 21:35 - 2016-11-20 13:41 - 00000000 ____D C:\Windows\system32\SleepStudy 2017-03-01 19:30 - 2016-12-29 21:15 - 00000000 ____D C:\ProgramData\NVIDIA 2017-03-01 19:30 - 2016-11-20 13:41 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2017-03-01 19:30 - 2016-07-16 01:04 - 00524288 _____ C:\Windows\system32\config\BBI 2017-03-01 15:47 - 2016-07-16 06:47 - 00000000 ___HD C:\Program Files\WindowsApps 2017-03-01 15:47 - 2016-07-16 06:47 - 00000000 ____D C:\Windows\AppReadiness 2017-02-26 12:09 - 2016-07-16 06:47 - 00000000 ____D C:\Windows\LiveKernelReports 2017-02-26 12:08 - 2016-12-29 18:51 - 00000000 ____D C:\Users\TT\AppData\Roaming\Origin 2017-02-26 12:08 - 2016-12-29 18:48 - 00000000 ____D C:\ProgramData\Origin 2017-02-25 21:12 - 2016-12-29 18:36 - 00000000 ____D C:\Users\TT\AppData\Roaming\Adobe 2017-02-25 21:05 - 2016-12-29 18:50 - 00000000 ____D C:\ProgramData\Package Cache 2017-02-25 16:53 - 2016-07-16 06:45 - 00000000 ____D C:\Windows\INF 2017-02-25 16:30 - 2016-12-29 23:13 - 00000000 ____D C:\ProgramData\Electronic Arts 2017-02-25 11:45 - 2016-11-20 13:40 - 00362216 _____ C:\Windows\system32\FNTCACHE.DAT 2017-02-25 11:44 - 2016-12-29 18:39 - 00000000 ___RD C:\Users\TT\OneDrive 2017-02-25 07:16 - 2016-12-29 18:39 - 00002396 _____ C:\Users\TT\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk 2017-02-24 21:39 - 2016-03-14 13:28 - 00002592 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Word 2016.lnk 2017-02-24 21:39 - 2016-03-14 13:28 - 00002588 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel 2016.lnk 2017-02-24 21:39 - 2016-03-14 13:28 - 00002567 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint 2016.lnk 2017-02-24 21:39 - 2016-03-14 13:28 - 00002542 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Publisher 2016.lnk 2017-02-24 21:39 - 2016-03-14 13:28 - 00002509 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Access 2016.lnk 2017-02-24 21:39 - 2016-03-14 13:28 - 00002506 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote 2016.lnk 2017-02-24 21:39 - 2016-03-14 13:28 - 00002478 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook 2016.lnk 2017-02-24 21:39 - 2016-03-14 13:18 - 00000000 ____D C:\Program Files (x86)\Microsoft Office 2017-02-22 21:39 - 2016-03-15 08:33 - 00000000 ____D C:\Windows\system32\MRT 2017-02-22 21:38 - 2016-03-15 08:33 - 138020592 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe 2017-02-21 17:40 - 2016-07-16 06:36 - 00000000 ____D C:\Windows\CbsTemp 2017-02-20 12:08 - 2016-07-16 06:47 - 00000000 ____D C:\Windows\Help 2017-02-19 10:28 - 2016-11-20 13:51 - 01025102 _____ C:\Windows\system32\PerfStringBackup.INI 2017-02-18 16:15 - 2016-07-16 06:47 - 00028672 _____ C:\Windows\system32\config\BCD-Template 2017-02-18 06:58 - 2016-12-29 18:36 - 00000000 ____D C:\Users\TT\AppData\Local\VirtualStore 2017-02-15 10:27 - 2016-12-29 18:42 - 00002353 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2017-02-15 10:27 - 2016-12-29 18:42 - 00002341 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2017-02-15 06:46 - 2016-07-16 06:47 - 00000000 ____D C:\Windows\rescache 2017-02-15 06:41 - 2016-11-20 13:31 - 00000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection 2017-02-15 06:41 - 2016-11-20 13:04 - 00000000 ____D C:\Windows\SysWOW64\winrm 2017-02-15 06:41 - 2016-11-20 13:04 - 00000000 ____D C:\Windows\SysWOW64\WCN 2017-02-15 06:41 - 2016-11-20 13:04 - 00000000 ____D C:\Windows\SysWOW64\slmgr 2017-02-15 06:41 - 2016-11-20 13:04 - 00000000 ____D C:\Windows\SysWOW64\Printing_Admin_Scripts 2017-02-15 06:41 - 2016-11-20 13:04 - 00000000 ____D C:\Windows\system32\winrm 2017-02-15 06:41 - 2016-11-20 13:04 - 00000000 ____D C:\Windows\system32\WCN 2017-02-15 06:41 - 2016-11-20 13:04 - 00000000 ____D C:\Windows\system32\slmgr 2017-02-15 06:41 - 2016-11-20 13:04 - 00000000 ____D C:\Windows\system32\Printing_Admin_Scripts 2017-02-15 06:41 - 2016-07-16 06:47 - 00000000 ___SD C:\Windows\SysWOW64\F12 2017-02-15 06:41 - 2016-07-16 06:47 - 00000000 ___SD C:\Windows\SysWOW64\DiagSvcs 2017-02-15 06:41 - 2016-07-16 06:47 - 00000000 ___SD C:\Windows\system32\F12 2017-02-15 06:41 - 2016-07-16 06:47 - 00000000 ___SD C:\Windows\system32\dsc 2017-02-15 06:41 - 2016-07-16 06:47 - 00000000 ___SD C:\Windows\system32\DiagSvcs 2017-02-15 06:41 - 2016-07-16 06:47 - 00000000 ___RD C:\Windows\MiracastView 2017-02-15 06:41 - 2016-07-16 06:47 - 00000000 ___RD C:\Windows\ImmersiveControlPanel 2017-02-15 06:41 - 2016-07-16 06:47 - 00000000 ___RD C:\Program Files\Windows Defender 2017-02-15 06:41 - 2016-07-16 06:47 - 00000000 ____D C:\Windows\SysWOW64\oobe 2017-02-15 06:41 - 2016-07-16 06:47 - 00000000 ____D C:\Windows\SysWOW64\MUI 2017-02-15 06:41 - 2016-07-16 06:47 - 00000000 ____D C:\Windows\SysWOW64\es-MX 2017-02-15 06:41 - 2016-07-16 06:47 - 00000000 ____D C:\Windows\SysWOW64\Com 2017-02-15 06:41 - 2016-07-16 06:47 - 00000000 ____D C:\Windows\system32\SystemResetPlatform 2017-02-15 06:41 - 2016-07-16 06:47 - 00000000 ____D C:\Windows\system32\oobe 2017-02-15 06:41 - 2016-07-16 06:47 - 00000000 ____D C:\Windows\system32\MUI 2017-02-15 06:41 - 2016-07-16 06:47 - 00000000 ____D C:\Windows\system32\migwiz 2017-02-15 06:41 - 2016-07-16 06:47 - 00000000 ____D C:\Windows\system32\es-MX 2017-02-15 06:41 - 2016-07-16 06:47 - 00000000 ____D C:\Windows\system32\Com 2017-02-15 06:41 - 2016-07-16 06:47 - 00000000 ____D C:\Windows\PolicyDefinitions 2017-02-15 06:41 - 2016-07-16 06:47 - 00000000 ____D C:\Windows\IME 2017-02-15 06:41 - 2016-07-16 06:47 - 00000000 ____D C:\Program Files\Windows Photo Viewer 2017-02-15 06:41 - 2016-07-16 06:47 - 00000000 ____D C:\Program Files\Common Files\System 2017-02-15 06:41 - 2016-07-16 06:47 - 00000000 ____D C:\Program Files (x86)\Windows Photo Viewer 2017-02-15 06:41 - 2016-07-16 06:47 - 00000000 ____D C:\Program Files (x86)\Windows Defender 2017-02-15 06:41 - 2016-07-16 01:04 - 00000000 ____D C:\Windows\SysWOW64\Dism 2017-02-15 06:41 - 2016-07-16 01:04 - 00000000 ____D C:\Windows\system32\Sysprep 2017-02-15 06:41 - 2016-07-16 01:04 - 00000000 ____D C:\Windows\system32\Dism 2017-02-15 06:41 - 2016-07-16 01:04 - 00000000 ____D C:\Windows\servicing 2017-02-15 06:27 - 2016-07-16 06:47 - 00000000 ____D C:\Windows\SysWOW64\en-GB 2017-02-15 06:27 - 2016-07-16 06:47 - 00000000 ____D C:\Windows\system32\en-GB 2017-02-14 20:42 - 2017-01-27 14:50 - 00000000 ____D C:\Users\TT\AppData\Roaming\NVIDIA 2017-02-14 20:42 - 2016-12-29 21:19 - 00000000 ____D C:\Users\TT\AppData\Local\NVIDIA Corporation 2017-02-12 22:53 - 2016-12-29 18:36 - 00000000 ____D C:\Users\TT\AppData\Local\Packages 2017-02-12 12:15 - 2016-07-16 06:47 - 00000000 ____D C:\Windows\SysWOW64\GroupPolicy 2017-02-12 12:15 - 2015-10-30 02:24 - 00000000 ___HD C:\Windows\system32\GroupPolicy 2017-02-12 10:53 - 2016-07-16 06:47 - 00000000 ___SD C:\Program Files (x86)\Windows Sidebar 2017-02-12 10:51 - 2016-07-16 06:47 - 00000000 ___SD C:\Program Files\Windows Sidebar 2017-02-12 10:09 - 2016-07-16 06:47 - 00000000 ____D C:\Windows\system32\spool 2017-02-12 04:51 - 2016-07-16 06:47 - 00000000 ____D C:\Windows\appcompat 2017-02-12 02:34 - 2016-07-16 06:47 - 00000000 ____D C:\Windows\system32\WinBioPlugIns 2017-02-12 02:34 - 2016-07-16 06:47 - 00000000 ____D C:\Windows\ShellExperiences 2017-02-12 02:34 - 2016-07-16 06:47 - 00000000 ____D C:\Windows\Provisioning 2017-02-12 02:34 - 2016-07-16 06:47 - 00000000 ____D C:\Windows\bcastdvr 2017-02-12 02:30 - 2016-07-16 06:42 - 00180224 _____ (Microsoft Corporation) C:\Windows\system32\enrollmentapi.dll 2017-02-12 00:14 - 2016-11-20 13:54 - 00000000 __RHD C:\Users\Public\AccountPictures 2017-02-12 00:11 - 2016-07-16 06:47 - 00000000 ____D C:\Windows\system32\WinBioDatabase 2017-02-12 00:11 - 2016-07-16 06:47 - 00000000 ____D C:\Windows\Registration 2017-02-12 00:11 - 2015-10-30 02:24 - 00000000 ____D C:\Windows\system32\Tasks_Migrated 2017-02-12 00:07 - 2016-07-16 06:47 - 00000000 __RHD C:\Users\Public\Libraries 2017-02-12 00:03 - 2016-12-29 18:46 - 00000000 ____D C:\Users\TT\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RivaTuner Statistics Server 2017-02-12 00:03 - 2016-12-29 18:46 - 00000000 ____D C:\Users\TT\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MSI Afterburner 2017-02-12 00:03 - 2016-12-29 18:45 - 00000000 ____D C:\Users\TT\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR 2017-02-12 00:03 - 2016-12-29 18:45 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR 2017-02-12 00:03 - 2016-07-16 06:47 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2017-02-12 00:03 - 2016-07-16 01:04 - 00032768 _____ C:\Windows\system32\config\ELAM 2017-02-12 00:02 - 2015-10-30 01:28 - 00000000 ____D C:\Users\Default.migrated 2017-02-12 00:00 - 2017-01-27 13:17 - 00000000 ____D C:\Windows\SysWOW64\BestPractices 2017-02-12 00:00 - 2017-01-27 13:17 - 00000000 ____D C:\Windows\system32\BestPractices 2017-02-12 00:00 - 2016-12-27 13:17 - 00000000 ____D C:\Program Files\Intel 2017-02-12 00:00 - 2016-11-20 13:12 - 00000000 ____D C:\Windows\OCR 2017-02-12 00:00 - 2016-07-16 06:47 - 00000000 ____D C:\Program Files\Common Files\microsoft shared 2017-02-11 20:44 - 2016-03-15 08:33 - 00000000 ____D C:\Windows\SysWOW64\nn-NO 2017-02-11 20:44 - 2016-03-15 08:33 - 00000000 ____D C:\Windows\system32\nn-NO 2017-02-11 20:22 - 2016-12-27 13:17 - 00000180 _____ C:\Windows\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat 2017-02-11 18:06 - 2016-12-29 18:46 - 00000000 ____D C:\Program Files (x86)\RivaTuner Statistics Server 2017-02-06 14:48 - 2016-07-16 06:49 - 00835576 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2017-02-06 14:48 - 2016-07-16 06:49 - 00177656 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl ==================== Files in the root of some directories ======= 2017-02-12 10:56 - 2017-02-12 12:05 - 0000627 _____ () C:\Users\TT\AppData\Roaming\All CPU MeterV3_Settings.ini 2017-02-12 11:13 - 2017-02-27 21:18 - 0000841 _____ () C:\Users\TT\AppData\Roaming\Drives Meter_Settings.ini 2017-02-12 10:57 - 2017-02-12 12:08 - 0000285 _____ () C:\Users\TT\AppData\Roaming\GPU MeterV2_Settings.ini 2017-02-12 11:00 - 2017-02-12 12:05 - 0001369 _____ () C:\Users\TT\AppData\Roaming\Network Meter_Settings.ini 2017-02-12 11:11 - 2017-03-01 17:41 - 0000027 _____ () C:\Users\TT\AppData\Roaming\Network Meter_Usage.ini 2017-02-13 06:19 - 2017-02-15 06:08 - 0000069 _____ () C:\Users\TT\AppData\Roaming\WB.CFG 2017-02-11 11:29 - 2017-02-11 11:29 - 0000000 _____ () C:\Users\TT\AppData\Local\{2C76CAA0-E6A0-4230-ADA2-B0C54116E1F8} 2017-02-16 13:54 - 2017-02-16 13:54 - 0000057 _____ () C:\ProgramData\Ament.ini Files to move or delete: ==================== C:\Users\TT\IP_Log_Data.js C:\Users\TT\Network_Meter_Data.js Some files in TEMP: ==================== 2017-02-25 21:04 - 2017-02-25 21:04 - 0288456 _____ (Adobe Systems Incorporated) C:\Users\TT\AppData\Local\Temp\AAMHelper.exe 2017-02-25 21:03 - 2015-08-06 22:30 - 2212144 _____ (Adobe Systems Incorporated) C:\Users\TT\AppData\Local\Temp\AdobeApplicationManager.exe 2017-02-15 10:26 - 2017-02-15 10:27 - 1129376 _____ (Google Inc.) C:\Users\TT\AppData\Local\Temp\ChromeSetup.exe 2017-03-01 17:51 - 2017-02-12 02:32 - 1886344 _____ (Microsoft Corporation) C:\Users\TT\AppData\Local\Temp\dllnt_dump.dll 2017-02-25 16:30 - 2017-02-25 16:52 - 0208896 _____ (Sony DADC Austria AG) C:\Users\TT\AppData\Local\Temp\drm_dyndata_7360007.dll 2017-02-11 18:59 - 2016-12-29 07:43 - 0860776 _____ (NVIDIA Corporation) C:\Users\TT\AppData\Local\Temp\nvSCPAPI64.dll 2017-02-13 19:25 - 2016-12-29 07:43 - 0351680 _____ (NVIDIA Corporation) C:\Users\TT\AppData\Local\Temp\nvStInst.exe 2017-02-13 19:28 - 2016-11-17 08:44 - 1135552 _____ (NVIDIA Corporation) C:\Users\TT\AppData\Local\Temp\NvTelemetry.dll 2017-02-13 19:28 - 2016-11-17 08:44 - 0217024 _____ (NVIDIA Corporation) C:\Users\TT\AppData\Local\Temp\NvTelemetryAPI32.dll 2017-02-13 19:28 - 2016-11-17 08:44 - 0268736 _____ (NVIDIA Corporation) C:\Users\TT\AppData\Local\Temp\NvTelemetryAPI64.dll 2017-02-24 08:33 - 2017-02-24 08:33 - 36713400 _____ () C:\Users\TT\AppData\Local\Temp\ubi7F54.tmp.exe 2017-02-24 07:44 - 2008-03-06 13:00 - 0459400 ____R (Macrovision Corporation) C:\Users\TT\AppData\Local\Temp\_isD6E3.exe 2017-02-24 08:13 - 2008-03-06 13:00 - 0459400 ____R (Macrovision Corporation) C:\Users\TT\AppData\Local\Temp\_isD9C4.exe ==================== Bamital & volsnap ====================== (There is no automatic fix for files that do not pass verification.) C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\dnsapi.dll => File is digitally signed C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2017-02-25 14:12 ==================== End of FRST.txt ============================ The Addition.txt is: Additional scan result of Farbar Recovery Scan Tool (x64) Version: 01-03-2017 Ran by Dad (01-03-2017 21:42:06) Running from C:\Users\TT\Desktop Windows 10 Pro Version 1607 (X64) (2017-02-12 05:13:37) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-2438100261-443141923-189968324-500 - Administrator - Disabled) Dad (S-1-5-21-2438100261-443141923-189968324-1001 - Administrator - Enabled) => C:\Users\TT DefaultAccount (S-1-5-21-2438100261-443141923-189968324-503 - Limited - Disabled) Guest (S-1-5-21-2438100261-443141923-189968324-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-2438100261-443141923-189968324-1003 - Limited - Enabled) ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 8GadgetPack (HKLM-x32\...\{35C86AEB-A4C6-49E3-90B7-245F2C7FDEC7}) (Version: 21.0.0 - 8GadgetPack.net) Adobe Creative Cloud (HKLM-x32\...\Adobe Creative Cloud) (Version: 3.9.5.353 - Adobe Systems Incorporated) Adobe Photoshop Elements 13 (HKLM-x32\...\{609818B9-23EB-4196-B466-EFE05E92A32F}) (Version: 13.1 - Adobe Systems Incorporated) AGEIA PhysX v7.07.09 (HKLM-x32\...\{65F1CF63-31E0-450B-96F3-4A88BE7361A6}) (Version: 7.07.09 - AGEIA Technologies, Inc.) Ansel (Version: 378.49 - NVIDIA Corporation) Hidden Assassin's Creed (HKLM-x32\...\{8CFA9151-6404-409A-AF22-4632D04582FD}) (Version: 1.00 - Ubisoft) Call of Duty (HKLM-x32\...\Call of Duty) (Version: - ) Call of Duty(R) - World at War(TM) (HKLM-x32\...\InstallShield_{D80A6A73-E58A-4673-AFF5-F12D7110661F}) (Version: 1.7 - Activision) Call of Duty(R) - World at War(TM) (x32 Version: 1.0 - Activision) Hidden Call of Duty(R) - World at War(TM) 1.1 Patch (x32 Version: - ) Hidden Call of Duty(R) - World at War(TM) 1.1 Patch (x32 Version: 1.1 - Activision) Hidden Call of Duty(R) - World at War(TM) 1.2 Patch (x32 Version: - ) Hidden Call of Duty(R) - World at War(TM) 1.2 Patch (x32 Version: 1.2 - Activision) Hidden Call of Duty(R) - World at War(TM) 1.4 Patch (x32 Version: - ) Hidden Call of Duty(R) - World at War(TM) 1.4 Patch (x32 Version: 1.4 - Activision) Hidden Call of Duty(R) - World at War(TM) 1.5 Patch (x32 Version: - ) Hidden Call of Duty(R) - World at War(TM) 1.5 Patch (x32 Version: 1.5 - Activision) Hidden Call of Duty(R) - World at War(TM) 1.6 Patch (x32 Version: - ) Hidden Call of Duty(R) - World at War(TM) 1.6 Patch (x32 Version: 1.6 - Activision) Hidden Call of Duty(R) - World at War(TM) 1.7 Patch (x32 Version: - ) Hidden Call of Duty(R) - World at War(TM) 1.7 Patch (x32 Version: 1.7 - Activision) Hidden Call of Duty(R) 2 (HKLM-x32\...\InstallShield_{D0A05794-48C2-4424-A15A-9F20FCFDD374}) (Version: 1.00.0000 - Activision) Call of Duty(R) 2 (x32 Version: 1.00.0000 - Activision) Hidden Call of Duty: Black Ops - Multiplayer (HKLM\...\Steam App 42710) (Version: - Treyarch) Call of Duty: Black Ops (HKLM\...\Steam App 42700) (Version: - Treyarch) Call of Duty: Modern Warfare 2 - Multiplayer (HKLM\...\Steam App 10190) (Version: - Infinity Ward) Call of Duty: Modern Warfare 2 (HKLM\...\Steam App 10180) (Version: - Infinity Ward) CCleaner (HKLM\...\CCleaner) (Version: 5.27 - Piriform) D-Fend Reloaded 1.4.4 (deinstall) (HKLM-x32\...\D-Fend Reloaded) (Version: 1.4.4 - Alexander Herzog) EA.com Update (HKLM-x32\...\{9AB97F52-512B-43EF-AAEC-4825C17B32ED}) (Version: - ) Everything 1.3.4.686 (x86) (HKLM-x32\...\Everything) (Version: - ) FBReader for Windows (HKLM-x32\...\FBReader for Windows) (Version: - ) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 56.0.2924.87 - Google Inc.) Google Update Helper (x32 Version: 1.3.32.7 - Google Inc.) Hidden Heather (HKLM-x32\...\{F3715E9A-9C16-423F-9E50-39DE0F7A5BF1}) (Version: 1.00.0000 - Naturalsoft) HP Dropbox Plugin (HKLM-x32\...\{23617173-F935-4C17-A323-EB1207F3ED49}) (Version: 36.0.31.53050 - Hewlett-Packard Co.) HP Google Drive Plugin (HKLM-x32\...\{AFF80405-E56A-48E7-98FC-8E46E261949F}) (Version: 36.0.31.53050 - Hewlett-Packard Co.) HP OfficeJet 4650 series Basic Device Software (HKLM\...\{AD2313B9-714F-496E-AD7F-20532E833EB2}) (Version: 36.0.72.54013 - Hewlett-Packard Co.) HP OfficeJet 4650 series Help (HKLM-x32\...\{20CA428A-0827-4441-BC64-5C577EA970AD}) (Version: 36.0.0 - Hewlett Packard) HP Photo Creations (HKLM-x32\...\HP Photo Creations) (Version: 1.0.0.9572 - HP) HP Update (HKLM-x32\...\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard) I.R.I.S. OCR (HKLM-x32\...\{C60E2D8F-0FC0-497D-A149-90F3B361937C}) (Version: 12.3.6.9 - HP) ImgBurn (HKLM-x32\...\ImgBurn) (Version: 2.5.8.0 - LIGHTNING UK!) Java 8 Update 121 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180121F0}) (Version: 8.0.1210.13 - Oracle Corporation) katevoice (HKLM-x32\...\{AF3065C7-038D-4FF7-8B78-47AC123B52C2}) (Version: 1.00.0000 - CanadaC Software) Malwarebytes version 3.0.6.1469 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.0.6.1469 - Malwarebytes) Medal of Honor - Allied Assault War Chest (HKLM-x32\...\GOGPACKMEDALOFHONORPACK_is1) (Version: 2.0.0.21 - GOG.com) Medal of Honor Airborne (HKLM-x32\...\{25F28E39-FDBB-11DB-8314-0800200C9A66}) (Version: 1.0.1.0 - Electronic Arts) Medal of Honor Pacific Assault(tm) Patch2 (HKLM-x32\...\{824539D7-D27E-4CC3-B36F-6404B5EB726B}) (Version: 1.0 - Electronic Arts) Medal of Honor: Pacific Assault™ (HKLM-x32\...\{56CFA833-F44F-4199-8C58-7F8B38F2BC7B}) (Version: 1.2.1.280 - Electronic Arts) Microsoft Office 365 - de-de (HKLM\...\O365HomePremRetail - de-de) (Version: 16.0.7571.2109 - Microsoft Corporation) Microsoft Office 365 - es-es (HKLM\...\O365HomePremRetail - es-es) (Version: 16.0.7571.2109 - Microsoft Corporation) Microsoft Office 365 - fi-fi (HKLM\...\O365HomePremRetail - fi-fi) (Version: 16.0.7571.2109 - Microsoft Corporation) Microsoft Office 365 - nb-no (HKLM\...\O365HomePremRetail - nb-no) (Version: 16.0.7571.2109 - Microsoft Corporation) Microsoft Office 365 - nn-no (HKLM\...\O365HomePremRetail - nn-no) (Version: 16.0.7571.2109 - Microsoft Corporation) Microsoft OneDrive (HKU\S-1-5-21-2438100261-443141923-189968324-1001\...\OneDriveSetup.exe) (Version: 17.3.6743.1212 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (HKLM\...\{350AA351-21FA-3270-8B7A-835434E766AD}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23918 (HKLM-x32\...\{dab68466-3a7d-41a8-a5cf-415e3ff8ef71}) (Version: 14.0.23918.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23918 (HKLM-x32\...\{2e085fd2-a3e4-4b39-8e10-6b8d35f55244}) (Version: 14.0.23918.0 - Microsoft Corporation) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 45.7.1 - Mozilla) Mozilla Thunderbird 45.7.1 (x86 en-US) (HKLM-x32\...\Mozilla Thunderbird 45.7.1 (x86 en-US)) (Version: 45.7.1 - Mozilla) MS Word To EPUB Converter Software (HKLM-x32\...\MS Word To EPUB Converter Software_is1) (Version: - Sobolsoft) MSI Afterburner 4.3.0 (HKLM-x32\...\Afterburner) (Version: 4.3.0 - MSI Co., LTD) Natural Voice Crystal16 (HKLM-x32\...\{5B1C8D6A-0968-45BA-8D22-F002A94EC278}) (Version: 1.4 - NaturalReaders.com) Natural Voice Mike16 (HKLM-x32\...\{BA733C73-C917-4BEA-8285-1F6F077671FA}) (Version: 2.6.0 - Natural voices reader) NaturalReader 14 (HKLM-x32\...\{9BB1F2B5-0A9D-402B-9613-DC5BCF878C22}) (Version: 1.00.0000 - Naturalsoft) NaturalReader 14 Free (HKLM-x32\...\{773ED0E5-538E-4E86-8E00-719630613290}) (Version: 1.00.0000 - Naturalsoft) NaturalReader10 (HKLM-x32\...\{A97657A7-A685-4EC4-AB91-534819E88EF9}) (Version: 10 - NaturalSoft) NVIDIA 3D Vision Controller Driver 369.04 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 369.04 - NVIDIA Corporation) NVIDIA 3D Vision Driver 378.49 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 378.49 - NVIDIA Corporation) NVIDIA GeForce Experience 3.3.0.95 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.3.0.95 - NVIDIA Corporation) NVIDIA Graphics Driver 378.49 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 378.49 - NVIDIA Corporation) NVIDIA HD Audio Driver 1.3.34.21 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.21 - NVIDIA Corporation) NVIDIA PhysX System Software 9.16.0318 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.16.0318 - NVIDIA Corporation) NvNodejs (Version: 3.3.0.95 - NVIDIA Corporation) Hidden NvTelemetry (Version: 2.3.5.0 - NVIDIA Corporation) Hidden NvvHci (Version: 2.02.0.5 - NVIDIA Corporation) Hidden Office 16 Click-to-Run Extensibility Component (x32 Version: 16.0.7571.2109 - Microsoft Corporation) Hidden Office 16 Click-to-Run Extensibility Component 64-bit Registration (Version: 16.0.7571.2109 - Microsoft Corporation) Hidden Office 16 Click-to-Run Licensing Component (Version: 16.0.7571.2109 - Microsoft Corporation) Hidden Office 16 Click-to-Run Localization Component (x32 Version: 16.0.7571.2109 - Microsoft Corporation) Hidden Origin (HKLM-x32\...\Origin) (Version: 10.4.4.20019 - Electronic Arts, Inc.) PaulVoice (HKLM-x32\...\{A191501B-6BC4-426F-8FB9-CFCE4CE45B23}) (Version: 1.00.0000 - CanadaC Software) PhotoPad Image Editor (HKLM-x32\...\PhotoPad) (Version: 3.00 - NCH Software) Product Improvement Study for HP OfficeJet 4650 series (HKLM\...\{75534DD0-9FB9-410A-AD7B-0E4470F0558D}) (Version: 36.0.72.54013 - Hewlett-Packard Co.) PunkBuster (HKLM-x32\...\{EFF1798F-4286-406E-B48D-BF7F6102E644}) (Version: 1.0.0.0 - Even Balance, Inc.) PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.986 - Even Balance, Inc.) RivaTuner Statistics Server 6.5.0 (HKLM-x32\...\RTSS) (Version: 6.5.0 - Unwinder) Samsung Data Migration (HKLM-x32\...\{3B304604-0BF5-488E-AB95-F2F2E31206F3}) (Version: 3.0 - Samsung) SHIELD Streaming (Version: 7.1.0351 - NVIDIA Corporation) Hidden SHIELD Wireless Controller Driver (Version: 3.3.0.95 - NVIDIA Corporation) Hidden SoftMaker Office 2016 (HKLM-x32\...\{8EBB8452-274B-465D-8324-00B0832FBB05}) (Version: 16.0.3815 - SoftMaker Software GmbH) Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation) Sub Command (HKLM\...\Steam App 2920) (Version: - Sonalysts) ThumbsPlus 10 (HKLM-x32\...\ThumbsPlus 10) (Version: - Cerious Software) ThumbsPlus 10 (x32 Version: 10.1.0.4011 - Cerious Software Inc.) Hidden ThumbsPlus version 7 SP2 (HKLM-x32\...\ThumbsPlus7) (Version: 7.0 SP2 - Cerious Software, Inc.) Trainz 'Blue Comet' Addon Pack (HKLM-x32\...\AuranTS2009_DLC0_is1) (Version: - Auran) Trainz Simulator 12 (HKLM-x32\...\AuranTS2009_is1) (Version: - Auran) VirtualCloneDrive (HKLM-x32\...\VirtualCloneDrive) (Version: 5.5.0.0 - Elaborate Bytes) VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.4 - VideoLAN) Vulkan Run Time Libraries 1.0.37.0 (HKLM\...\VulkanRT1.0.37.0) (Version: 1.0.37.0 - LunarG, Inc.) Web Companion (HKLM-x32\...\{0d31f3ef-4d7e-42ea-9cdb-b37e85183f4b}) (Version: 2.3.1521.2957 - Lavasoft) WinRAR 5.40 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.40.0 - win.rar GmbH) xplorer² professional 64 bit (HKLM\...\xplorer2p64) (Version: 2.4.0.0 - Zabkat) Zip Motion Block Video codec (Remove Only) (HKLM-x32\...\ZMBV) (Version: - DOSBox Team) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-2438100261-443141923-189968324-1001_Classes\CLSID\{083f5ae0-2b0a-11dd-bd0b-0800200c9a66}\InprocServer32 -> C:\Windows\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2438100261-443141923-189968324-1001_Classes\CLSID\{0B7AD8D3-094A-44DE-A348-83C6C3FA347C}\InprocServer32 -> C:\Users\TT\AppData\Local\Microsoft\Windows Sidebar\Gadgets\Clipboarder.gadget\Release\Clipboarder64.dll (Helmut Buhler) CustomCLSID: HKU\S-1-5-21-2438100261-443141923-189968324-1001_Classes\CLSID\{0E270DAA-1BE6-48F2-AC49-63C3A3E9D8B3}\InprocServer32 -> %%systemroot%%\system32\shell32.dll => No File CustomCLSID: HKU\S-1-5-21-2438100261-443141923-189968324-1001_Classes\CLSID\{0E7BE950-4ACC-47CB-834B-41A8B96BBFF9}\InprocServer32 -> C:\Users\TT\AppData\Local\Microsoft\Windows Sidebar\Gadgets\Sidebar7.gadget\Release\Sidebar7.64.dll (Helmut Buhler) CustomCLSID: HKU\S-1-5-21-2438100261-443141923-189968324-1001_Classes\CLSID\{5b55a44a-d008-49aa-9234-86fb7709bc0a}\InprocServer32 -> C:\Windows\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-2438100261-443141923-189968324-1001_Classes\CLSID\{e8c77137-e224-5791-b6e9-ff0305797a13}\InprocServer32 -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems) ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {08251D6E-F044-40CD-B94B-CCE38D0944C0} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16\OLicenseHeartbeat.exe [2016-12-28] (Microsoft Corporation) Task: {0B120E8B-3FE5-47E1-8835-6053D7BA60DE} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2017-02-07] (Piriform Ltd) Task: {0CE02469-D09D-4339-BF85-06492E24FC90} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2016-12-28] (Microsoft Corporation) Task: {0E46CC7D-6D49-4F26-B903-A3F6D55510BE} - System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe [2017-01-20] (NVIDIA Corporation) Task: {1A010389-912E-4521-828C-26AFC4E7F18E} - System32\Tasks\{28DA7460-C7EC-4276-A1FF-B9EAF7FDFEF6} => pcalua.exe -a "C:\Program Files (x86)\Activision\Call of Duty 2\cod2sp_s.exe" -d "C:\Program Files (x86)\Activision\Call of Duty 2\" Task: {1C586589-41F6-4684-B459-440E212C742C} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2017-01-20] (NVIDIA Corporation) Task: {36181163-DADF-4AF0-BD6A-DE63BF87B1AD} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_ERROR_HB => C:\Windows\system32\MRT.exe [2017-02-22] (Microsoft Corporation) Task: {43A76F3C-8CC3-4474-BFA5-AC417ADB0B1B} - System32\Tasks\{56E113F0-C191-4BC8-B6E6-5CEB7013EEE2} => pcalua.exe -a "C:\Program Files (x86)\Call of Duty\CoDSP.exe" -d C:\PROGRA~2\CALLOF~1 Task: {56245026-DCB4-469C-845E-C035C612762E} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2016-12-28] (Microsoft Corporation) Task: {5B0E1075-F9C8-46E3-AE24-498FF57185A0} - System32\Tasks\{43719454-2974-4532-A795-986B56FC87E0} => pcalua.exe -a "C:\Program Files (x86)\EA GAMES\Medal of Honor Pacific Assault(tm)\mohpa_setup.exe" -d C:\PROGRA~2\EAGAME~1\MEDALO~1 Task: {6318E625-1428-4E9A-976C-1E9EF9F72EC0} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-12-29] (Google Inc.) Task: {645B3336-FC30-46C2-945C-8E676F6E3512} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [2017-01-20] (NVIDIA Corporation) Task: {6E652FCF-9B1D-4878-A30E-8F26AED9AE07} - System32\Tasks\HPCustParticipation HP OfficeJet 4650 series => C:\Program Files\HP\HP OfficeJet 4650 series\Bin\HPCustPartic.exe [2015-03-09] (Hewlett-Packard Development Company, LP) Task: {8E4DB1CD-1DEC-4EAE-847C-2E59946406E8} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-12-29] (Google Inc.) Task: {8F511948-E920-4B4E-869A-2883480F1F2F} - System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2017-01-20] (NVIDIA Corporation) Task: {916FA6F1-2CD3-491F-948A-A3714E06EC79} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\Program Files\Windows Defender\\MpCmdRun.exe [2016-07-16] (Microsoft Corporation) Task: {A48B40B8-6736-4779-A8CE-27803A077FE3} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2017-01-20] (NVIDIA Corporation) Task: {AF9DB14D-907B-4BB3-B227-767D12E0506F} - System32\Tasks\AdobeAAMUpdater-1.0-F4PC-Dad => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2016-07-01] (Adobe Systems Incorporated) Task: {B2F650B6-4DC4-42CB-B928-20F501784A02} - System32\Tasks\PCMeter\Startup => C:\Users\TT\Downloads\PCMeter\PCMeterV4\PCMeterV0.4.exe [2017-02-12] (AddGadgets) Task: {C1755ED3-3523-4A6A-ACAE-D44F413ECC73} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\Program Files\Windows Defender\\MpCmdRun.exe [2016-07-16] (Microsoft Corporation) Task: {D656F027-CBDA-4C8D-B4CC-B8DC1D4840B1} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\Program Files\Windows Defender\\MpCmdRun.exe [2016-07-16] (Microsoft Corporation) Task: {E9AB2EC7-08EA-406F-8D22-D90CC4032A0C} - System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2017-01-20] (NVIDIA Corporation) Task: {F59848F6-B5D8-4539-BBCD-07F00838D6D1} - System32\Tasks\journalaboutlifeorgscopesm => launchwinapp.exe journalaboutlife.org/scopesm Task: {FAE9967A-57EF-4BE9-AB0E-46DD35D7079C} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2017-01-20] (NVIDIA Corporation) Task: {FBDA26D6-8CDC-4064-AF0E-98B830002B1B} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\Program Files\Windows Defender\\MpCmdRun.exe [2016-07-16] (Microsoft Corporation) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) ==================== Shortcuts ============================= (The entries could be listed to be restored or removed.) Shortcut: C:\Users\TT\Favorites\NCH Software Download Site.lnk -> hxxp://www.nchsoftware.com/index.htm ==================== Loaded Modules (Whitelisted) ============== 2016-07-16 06:42 - 2016-07-16 06:42 - 00231424 _____ () C:\Windows\SYSTEM32\ism32k.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 02681200 _____ () C:\Windows\system32\CoreUIComponents.dll 2017-02-11 23:54 - 2017-01-20 10:13 - 00134712 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll 2017-02-25 07:04 - 2017-01-20 07:47 - 02264352 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\PoliciesControllerImpl.dll 2017-02-25 07:04 - 2017-01-20 07:47 - 02829776 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\arwlib.dll 2017-02-13 19:28 - 2017-01-20 13:39 - 04489152 _____ () C:\Program Files\NVIDIA Corporation\NvContainer\Poco.dll 2017-02-13 19:28 - 2017-01-20 13:39 - 01147328 _____ () C:\Program Files\NVIDIA Corporation\NvContainer\libprotobuf.dll 2011-03-09 10:56 - 2011-03-09 10:56 - 00063040 _____ () C:\Program Files (x86)\Even Balance, Inc\PunkBuster\PB\PnkBstrA.exe 2017-02-12 02:32 - 2017-02-12 02:32 - 02681200 _____ () C:\Windows\SYSTEM32\CoreUIComponents.dll 2016-10-25 09:57 - 2016-10-25 09:57 - 00491184 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll 2016-11-20 13:11 - 2016-11-20 13:11 - 00134656 _____ () C:\Windows\ShellExperiences\Windows.UI.Shell.SharedUtilities.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00474112 _____ () C:\Windows\ShellExperiences\QuickActions.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 09760768 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 01401856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 00757248 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CSGSuggestLib.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 01033216 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Actions.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 02424320 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll 2017-02-12 02:32 - 2017-02-12 02:32 - 04853760 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll 2017-02-22 06:35 - 2017-02-22 06:35 - 00073728 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.11.110.0_x64__kzf8qxf38zg5c\SkypeHost.exe 2017-02-22 06:35 - 2017-02-22 06:35 - 00179712 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.11.110.0_x64__kzf8qxf38zg5c\SkypeBackgroundTasks.dll 2017-02-22 06:35 - 2017-02-22 06:35 - 42895360 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.11.110.0_x64__kzf8qxf38zg5c\SkyWrap.dll 2017-02-12 08:03 - 2017-02-12 08:04 - 02215424 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.11.110.0_x64__kzf8qxf38zg5c\roottools.dll 2017-03-01 15:47 - 2017-03-01 15:47 - 00019456 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_17.214.10010.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe 2017-03-01 15:47 - 2017-03-01 15:47 - 21149696 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_17.214.10010.0_x64__8wekyb3d8bbwe\Microsoft.Photos.dll 2017-03-01 15:47 - 2017-03-01 15:47 - 05380096 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_17.214.10010.0_x64__8wekyb3d8bbwe\MediaEngine.dll 2016-12-29 23:07 - 2016-12-29 23:08 - 00680448 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_17.214.10010.0_x64__8wekyb3d8bbwe\Microsoft.DesignCore.dll 2017-03-01 15:47 - 2017-03-01 15:47 - 00387584 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_17.214.10010.0_x64__8wekyb3d8bbwe\Microsoft.RichMedia.Ink.Controls.dll 2017-03-01 15:47 - 2017-03-01 15:47 - 01047552 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_17.214.10010.0_x64__8wekyb3d8bbwe\Microsoft.Sharing.dll 2016-12-29 23:07 - 2016-12-29 23:08 - 00291328 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_17.214.10010.0_x64__8wekyb3d8bbwe\StoreRatingPromotion.dll 2017-02-25 15:40 - 2017-02-25 15:39 - 02493440 _____ () C:\Program Files (x86)\Origin\libGLESv2.dll 2017-02-13 19:28 - 2017-01-20 13:39 - 00018880 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll 2017-02-13 19:28 - 2017-01-20 13:39 - 00900032 _____ () C:\Program Files (x86)\NVIDIA Corporation\NvContainer\libprotobuf.dll 2017-02-13 19:28 - 2017-01-20 13:39 - 03774400 _____ () C:\Program Files (x86)\NVIDIA Corporation\NvContainer\Poco.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service" ==================== Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) HKU\S-1-5-21-2438100261-443141923-189968324-1001\Software\Classes\.exe: => <===== ATTENTION HKU\S-1-5-21-2438100261-443141923-189968324-1001\Software\Classes\.scr: => <===== ATTENTION ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) IE trusted site: HKU\.DEFAULT\...\localhost -> localhost IE trusted site: HKU\S-1-5-21-2438100261-443141923-189968324-1001\...\localhost -> localhost ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2015-10-30 02:24 - 2015-10-30 02:21 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-2438100261-443141923-189968324-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\TT\AppData\Local\Microsoft\Windows\Themes\RoamedThemeFiles\DesktopBackground\windows photo viewer wallpaper.jpg DNS Servers: 192.168.1.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 2) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == HKLM\...\StartupApproved\Run: => "ShadowPlay" HKLM\...\StartupApproved\Run32: => "HP Software Update" HKLM\...\StartupApproved\Run32: => "SunJavaUpdateSched" HKLM\...\StartupApproved\Run32: => "IseUI" HKLM\...\StartupApproved\Run32: => "VirtualCloneDrive" HKLM\...\StartupApproved\Run32: => "Adobe Creative Cloud" HKLM\...\StartupApproved\Run32: => "AdobeAAMUpdater-1.0" HKLM\...\StartupApproved\Run32: => "Everything" HKLM\...\StartupApproved\Run32: => "Malwarebytes TrayApp" HKLM\...\StartupApproved\Run32: => "MS Word To EPUB Converter Software.exe" HKU\S-1-5-21-2438100261-443141923-189968324-1001\...\StartupApproved\StartupFolder: => "Sidebar894.lnk" HKU\S-1-5-21-2438100261-443141923-189968324-1001\...\StartupApproved\Run: => "OneDrive" HKU\S-1-5-21-2438100261-443141923-189968324-1001\...\StartupApproved\Run: => "EADM" HKU\S-1-5-21-2438100261-443141923-189968324-1001\...\StartupApproved\Run: => "Chromium" HKU\S-1-5-21-2438100261-443141923-189968324-1001\...\StartupApproved\Run: => "ClearScreen Player" HKU\S-1-5-21-2438100261-443141923-189968324-1001\...\StartupApproved\Run: => "HP OfficeJet 4650 series (NET)" HKU\S-1-5-21-2438100261-443141923-189968324-1001\...\StartupApproved\Run: => "Steam" HKU\S-1-5-21-2438100261-443141923-189968324-1001\...\StartupApproved\Run: => "CCleaner" ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139 FirewallRules: [{8C47B058-C067-430B-BAA9-452E4D28FC38}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe FirewallRules: [{551D6306-8571-4B81-A707-596F2963E112}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\NvContainer.exe FirewallRules: [{59C2D190-DB4C-484C-B1FE-0341371E8C5C}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\NvContainer.exe FirewallRules: [{24C09F9D-DB25-4F7B-A43C-F19696E06D26}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe FirewallRules: [{444892EE-681A-4C0C-83FC-2368786AB28E}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{8D5D735E-A52B-401A-868E-FD8CFDB9F458}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe FirewallRules: [{7D89B144-2B89-4DA7-859B-A7BFB8D07D77}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe FirewallRules: [{430D9AA1-9E72-419E-87E0-AB7FE9C33002}] => (Allow) C:\Users\TT\AppData\Local\Temp\7zS4A40\HP.EasyStart.exe FirewallRules: [{63067292-2DF2-43C5-9CE2-EFB565F1FB7D}] => (Allow) C:\Program Files\HP\HP OfficeJet 4650 series\bin\FaxPrinterUtility.exe FirewallRules: [{7CD4C6CF-4A1F-48DE-962C-D62D5F361C33}] => (Allow) C:\Program Files\HP\HP OfficeJet 4650 series\bin\FaxApplications.exe FirewallRules: [{210541F0-8966-463A-B501-BCF01A98B00E}] => (Allow) C:\Program Files\HP\HP OfficeJet 4650 series\bin\DigitalWizards.exe FirewallRules: [{28DDC44C-6BFE-49CE-A7F6-40FE923FF543}] => (Allow) C:\Program Files\HP\HP OfficeJet 4650 series\bin\SendAFax.exe FirewallRules: [{B2DA308B-8374-4994-AEB5-1CA2D474C36F}] => (Allow) C:\Program Files\HP\HP OfficeJet 4650 series\Bin\DeviceSetup.exe FirewallRules: [{B52280E9-9828-43B6-9A7D-B92B90A1ACC3}] => (Allow) LPort=5357 FirewallRules: [{FA1B8E09-6ED9-4B5D-A809-CB3007E15251}] => (Allow) C:\Program Files\HP\HP OfficeJet 4650 series\Bin\HPNetworkCommunicatorCom.exe FirewallRules: [{396F6E43-5B79-41D8-8D9A-9B8F09637B53}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{A7868B2E-E349-44DE-8825-942906B1618B}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{063C1309-99E5-47FB-A2CA-FC4930E57F15}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe FirewallRules: [{F4F00C7A-4BB1-4F5A-9170-AED991FB3F18}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe FirewallRules: [{0CC9E324-80F5-4B5B-838F-249CD0497731}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Call of Duty Modern Warfare 2\iw4mp.exe FirewallRules: [{B7E9188F-6182-4FB6-A050-9FB240B2DD4D}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Call of Duty Modern Warfare 2\iw4mp.exe FirewallRules: [{A5A39536-D57D-4470-9832-5A639AC16A1B}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Call of Duty Modern Warfare 2\iw4sp.exe FirewallRules: [{C3FF6C19-F151-4667-B809-165A6989C10C}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Call of Duty Modern Warfare 2\iw4sp.exe FirewallRules: [{EBA7FD69-DC88-45F9-8B4B-35DB05F270D3}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Call of Duty Black Ops\BlackOpsMP.exe FirewallRules: [{7263EF9B-4CBA-477F-862E-834ECA623E68}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Call of Duty Black Ops\BlackOpsMP.exe FirewallRules: [{C6E2D769-7282-4D65-9DD8-E59E216A620B}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Call of Duty Black Ops\BlackOps.exe FirewallRules: [{CC10613D-ADED-4305-8884-26AC512A4452}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Call of Duty Black Ops\BlackOps.exe FirewallRules: [{AEF1C8E5-DFCA-4349-90F3-07D0853A32CB}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe FirewallRules: [{54EA3797-33B5-4222-BB1A-EE9D940AB511}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe FirewallRules: [{EC9F57A6-6B67-4FEB-B040-ECA6274655AC}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe FirewallRules: [{7122B8C9-E7AF-44D8-B15D-CA064CBD48A9}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe FirewallRules: [{D2F0A01F-FF7B-4CC8-9BFC-78D3FE22FFE1}] => (Allow) C:\Program Files (x86)\Activision\Call of Duty - World at War\CoDWaW.exe FirewallRules: [{DAA116F1-2B92-4F64-AD9D-849C351E15F4}] => (Allow) C:\Program Files (x86)\Activision\Call of Duty - World at War\CoDWaW.exe FirewallRules: [{4FBD60EC-618F-4D72-A636-686F26F64F11}] => (Allow) C:\Program Files (x86)\Activision\Call of Duty - World at War\CoDWaWmp.exe FirewallRules: [{A1C0E464-1313-438D-BCA7-4BBE5BD74903}] => (Allow) C:\Program Files (x86)\Activision\Call of Duty - World at War\CoDWaWmp.exe FirewallRules: [TCP Query User{FBBB3261-C28D-4923-B629-ABFBAC4CD71C}C:\gog games\medal of honor - allied assault war chest\mohaa.exe] => (Allow) C:\gog games\medal of honor - allied assault war chest\mohaa.exe FirewallRules: [UDP Query User{06BC1594-083A-457C-A1FD-661DC15A835F}C:\gog games\medal of honor - allied assault war chest\mohaa.exe] => (Allow) C:\gog games\medal of honor - allied assault war chest\mohaa.exe FirewallRules: [TCP Query User{4FB5297E-A678-404C-8870-9FA20E9390E0}C:\program files (x86)\ea games\medal of honor pacific assault(tm)\mohpa.exe] => (Allow) C:\program files (x86)\ea games\medal of honor pacific assault(tm)\mohpa.exe FirewallRules: [UDP Query User{045C3996-F936-4B13-9831-C991D108977C}C:\program files (x86)\ea games\medal of honor pacific assault(tm)\mohpa.exe] => (Allow) C:\program files (x86)\ea games\medal of honor pacific assault(tm)\mohpa.exe FirewallRules: [{21A3981F-523E-4FF9-96D1-DC765301D457}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Sub Command\Steamrun.exe FirewallRules: [{AC79821B-DD60-459B-B398-5F9099BCEBA6}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Sub Command\Steamrun.exe FirewallRules: [{C18454A6-CADA-4217-AD74-317DA03A2278}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed\AssassinsCreed_Dx9.exe FirewallRules: [{0BCE6E34-6B61-4DE7-8A6F-48B9953A3F8B}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed\AssassinsCreed_Dx9.exe FirewallRules: [{C76018C9-4ACF-4F05-975D-04C7C86D7479}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed\AssassinsCreed_Dx10.exe FirewallRules: [{6A864263-1788-41D4-BA17-BA23DEF6196F}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed\AssassinsCreed_Dx10.exe FirewallRules: [{6A8E839B-2572-4488-B880-74F0950E6666}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed\AssassinsCreed_Launcher.exe FirewallRules: [{2AC3B325-9D8B-4233-B731-2BB5BB5EDD96}] => (Allow) C:\Program Files (x86)\Ubisoft\Assassin's Creed\AssassinsCreed_Launcher.exe FirewallRules: [{4850AA82-5A43-4A3E-B09B-0FE8E70A17CF}] => (Allow) C:\Program Files (x86)\Origin Games\Medal of Honor Pacific Assault\mohpa.exe FirewallRules: [{CD18C8C3-1872-4C16-B3E9-893D6AEBF527}] => (Allow) C:\Program Files (x86)\Origin Games\Medal of Honor Pacific Assault\mohpa.exe FirewallRules: [{22C2AB5C-C3D0-4988-8D50-BE212A9D5712}] => (Allow) C:\Program Files (x86)\Origin Games\Medal of Honor Pacific Assault\mohpa_setup.exe FirewallRules: [{12255C43-3C35-44D7-A602-344A1191A135}] => (Allow) C:\Program Files (x86)\Origin Games\Medal of Honor Pacific Assault\mohpa_setup.exe FirewallRules: [{6E38B53C-7552-4357-B9FB-2CD8DD67348C}] => (Allow) C:\Program Files (x86)\Origin Games\Medal of Honor Airborne\UnrealEngine3\Binaries\MOHA.exe FirewallRules: [{D9AA5545-1A21-4009-80CF-E61BC2363310}] => (Allow) C:\Program Files (x86)\Origin Games\Medal of Honor Airborne\UnrealEngine3\Binaries\MOHA.exe FirewallRules: [{84187577-EE24-4C64-A7CC-0A79A2C36D78}] => (Allow) C:\Program Files (x86)\Even Balance, Inc\PunkBuster\PB\PnkBstrA.exe FirewallRules: [{8DF7D3C4-8762-437C-9E5A-E29F57C36296}] => (Allow) C:\Program Files (x86)\Even Balance, Inc\PunkBuster\PB\PnkBstrA.exe ==================== Restore Points ========================= ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (03/01/2017 07:25:28 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: The program adwcleaner_6.044.exe version 6.0.4.4 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel. Process ID: d88 Start Time: 01d292e728f214c7 Termination Time: 3 Application Path: C:\Users\TT\Desktop\adwcleaner_6.044.exe Report Id: 7a712590-fede-11e6-886c-645a046bdb94 Faulting package full name: Faulting package-relative application ID: Error: (03/01/2017 06:46:49 PM) (Source: System Restore) (EventID: 8193) (User: ) Description: Failed to create restore point (Process = C:\Users\TT\AppData\Local\Temp\jrt\CreateRestorePoint.exe "JRT Pre-Junkware Removal"; Description = JRT Pre-Junkware Removal; Error = 0x80070422). Error: (03/01/2017 06:04:29 PM) (Source: Application Error) (EventID: 1000) (User: ) Description: Faulting application name: wmiprvse.exe, version: 10.0.14393.0, time stamp: 0x57899ab2 Faulting module name: ntdll.dll, version: 10.0.14393.479, time stamp: 0x5825887f Exception code: 0xc0000374 Fault offset: 0x00000000000f8283 Faulting process id: 0x1d10 Faulting application start time: 0x01d292dd0856788a Faulting application path: C:\Windows\system32\wbem\wmiprvse.exe Faulting module path: C:\Windows\SYSTEM32\ntdll.dll Report Id: 4c19f5dc-182f-48c5-9ba4-2b1216a4e64b Faulting package full name: Faulting package-relative application ID: Error: (03/01/2017 05:41:12 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: Activation context generation failed for "C:\Program Files (x86)\ThumbsPlus 10\Bin\Thumbs10.exe".Error in manifest or policy file "" on line . A component version required by the application conflicts with another component version already active. Conflicting components are:. Component 1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.447_none_89c64d28dafea4b9.manifest. Component 2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.447_none_42191651c6827bb3.manifest. Error: (03/01/2017 05:32:44 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: Activation context generation failed for "C:\ProgramData\{92D5D750-AA6D-437A-9732-D540EA9E7693}\OFFLINE\E52451D1\3347E48C\Thumbs10.exe".Error in manifest or policy file "" on line . A component version required by the application conflicts with another component version already active. Conflicting components are:. Component 1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.447_none_89c64d28dafea4b9.manifest. Component 2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.447_none_42191651c6827bb3.manifest. Error: (03/01/2017 05:32:21 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: Activation context generation failed for "C:\Program Files (x86)\ThumbsPlus 10\Bin\Thumbs10.exe".Error in manifest or policy file "" on line . A component version required by the application conflicts with another component version already active. Conflicting components are:. Component 1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.447_none_89c64d28dafea4b9.manifest. Component 2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.447_none_42191651c6827bb3.manifest. Error: (03/01/2017 05:31:20 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: Activation context generation failed for "C:\Program Files (x86)\ThumbsPlus 10\Bin\Thumbs10.exe".Error in manifest or policy file "" on line . A component version required by the application conflicts with another component version already active. Conflicting components are:. Component 1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.447_none_89c64d28dafea4b9.manifest. Component 2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.447_none_42191651c6827bb3.manifest. Error: (03/01/2017 04:38:17 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: Activation context generation failed for "C:\Program Files (x86)\ThumbsPlus 10\Bin\Thumbs10.exe".Error in manifest or policy file "" on line . A component version required by the application conflicts with another component version already active. Conflicting components are:. Component 1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.447_none_89c64d28dafea4b9.manifest. Component 2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.447_none_42191651c6827bb3.manifest. Error: (03/01/2017 04:38:16 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: Activation context generation failed for "C:\Program Files (x86)\ThumbsPlus 10\Bin\Thumbs10.exe".Error in manifest or policy file "" on line . A component version required by the application conflicts with another component version already active. Conflicting components are:. Component 1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.447_none_89c64d28dafea4b9.manifest. Component 2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.447_none_42191651c6827bb3.manifest. Error: (03/01/2017 04:37:58 PM) (Source: SideBySide) (EventID: 78) (User: ) Description: Activation context generation failed for "C:\Program Files (x86)\ThumbsPlus 10\Bin\Thumbs10.exe".Error in manifest or policy file "" on line . A component version required by the application conflicts with another component version already active. Conflicting components are:. Component 1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.447_none_89c64d28dafea4b9.manifest. Component 2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.14393.447_none_42191651c6827bb3.manifest. System errors: ============= Error: (03/01/2017 07:30:45 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {8D8F4F83-3594-4F07-8369-FC3C3CAE4919} and APPID {F72671A9-012C-4725-9D2F-2A4D32D65169} to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Error: (03/01/2017 07:30:43 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {6B3B8D23-FA8D-40B9-8DBD-B950333E2C52} and APPID {4839DDB7-58C2-48F5-8283-E1D1807D0D7D} to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Error: (03/01/2017 07:30:43 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {6B3B8D23-FA8D-40B9-8DBD-B950333E2C52} and APPID {4839DDB7-58C2-48F5-8283-E1D1807D0D7D} to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Error: (03/01/2017 07:30:42 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The SecDrv service failed to start due to the following error: This driver has been blocked from loading Error: (03/01/2017 07:30:42 PM) (Source: Application Popup) (EventID: 1060) (User: ) Description: \??\C:\Windows\SysWow64\drivers\SECDRV.SYS Error: (03/01/2017 07:30:18 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {D63B10C5-BB46-4990-A94F-E40B9D520160} and APPID {9CA88EE3-ACB7-47C8-AFC4-AB702511C276} to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Error: (03/01/2017 07:30:06 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: The Print Spooler service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 5000 milliseconds: Restart the service. Error: (03/01/2017 07:30:06 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: The Windows Search service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service. Error: (03/01/2017 07:30:06 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: The Windows Media Player Network Sharing Service service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service. Error: (03/01/2017 07:30:06 PM) (Source: Service Control Manager) (EventID: 7031) (User: ) Description: The NVIDIA LocalSystem Container service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 5000 milliseconds: Restart the service. CodeIntegrity: =================================== Date: 2017-03-01 21:36:27.989 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume2\Windows\System32\nvspcap64.dll that did not meet the Store signing level requirements. Date: 2017-03-01 21:36:13.912 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume2\Windows\System32\nvspcap64.dll that did not meet the Store signing level requirements. Date: 2017-03-01 18:42:21.051 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume2\Windows\System32\nvspcap64.dll that did not meet the Store signing level requirements. Date: 2017-03-01 18:41:22.308 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume2\Windows\System32\nvspcap64.dll that did not meet the Store signing level requirements. Date: 2017-03-01 17:44:22.611 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume2\Windows\System32\nvspcap64.dll that did not meet the Store signing level requirements. Date: 2017-03-01 17:35:50.161 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Windows\System32\LavasoftTcpService64.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-03-01 17:35:50.158 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Windows\System32\LavasoftTcpService64.dll that did not meet the Custom 3 / Antimalware signing level requirements. Date: 2017-03-01 07:56:57.315 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume2\Windows\System32\nvspcap64.dll that did not meet the Store signing level requirements. Date: 2017-03-01 07:45:10.685 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume2\Windows\System32\nvspcap64.dll that did not meet the Store signing level requirements. Date: 2017-03-01 07:11:54.152 Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume2\Windows\System32\nvspcap64.dll that did not meet the Store signing level requirements. ==================== Memory info =========================== Processor: Intel(R) Core(TM) i5-4570 CPU @ 3.20GHz Percentage of memory in use: 12% Total physical RAM: 16335.7 MB Available physical RAM: 14268.21 MB Total Virtual: 18767.7 MB Available Virtual: 16629.83 MB ==================== Drives ================================ Drive c: (F4pc-HD01) (Fixed) (Total:232.79 GB) (Free:111.43 GB) NTFS Drive d: (F4pc-HD02) (Fixed) (Total:1863.01 GB) (Free:1566.69 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 232.9 GB) (Disk ID: 8D387B80) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=232.8 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 1863 GB) (Disk ID: 1E4AB19E) Partition 1: (Not Active) - (Size=1863 GB) - (Type=07 NTFS) ==================== End of Addition.txt ============================ I have attached the Shortcut.txt Thank you ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ AdwCleaner[C0].txt AdwCleaner[C2].txt AdwCleaner[S0].txt AdwCleaner[S1].txt Shortcut.txt
  22. Hello Kris, Here is the results: ~ ZHPDiag v2017.2.27.37 By Nicolas Coolman (2017/02/27) ~ Run by Dad (Administrator) (2017/02/28 11:32:33) ~ Web: https://www.nicolascoolman.com ~ Blog: https://nicolascoolman.eu/ ~ Facebook: https://www.facebook.com/nicolascoolman1 ~ State version: Version OK ~ Mode: Scan ~ Report: C:\Users\TT\Desktop\ZHPDiag.txt ~ Report: C:\Users\TT\AppData\Roaming\ZHP\ZHPDiag.txt ~ UAC: Activate ~ System startup: Normal (Normal boot) Windows 10 Pro, 64-bit (Build 14393) =>.Microsoft Corporation ---\\ Internet Browsers (3) - 0s ~ GCIE: Google Chrome v56.0.2924.87 ~ MFIE: Mozilla Thunderbird 45.7.1 (x86 en-US) ~ MSIE: Internet Explorer v11.576.14393.0 ---\\ Windows Product Information (3) - 3s ~ Windows Server License Manager Script : OK ~ Licence Script File Génération : OK Windows Automatic Updates : OK ---\\ System protection software (1) - 4s Windows Defender (Activate) (Protection) ---\\ Information on the system (6) - 0s ~ Operating System: Intel64 Family 6 Model 60 Stepping 3, GenuineIntel ~ Operating System: 64-bit ~ Boot mode: Normal (Normal boot) Total RAM: 16727.76 MB (78% free) : OK =>.RAM Value System Restore: Activé (Enable) System drive C: has 114 GB (47%) free of 238 GB : OK =>.Disk Space ---\\ Connection to the system mode (3) - 0s ~ Computer Name: F4PC ~ User Name: Dad ~ Logged in as Administrator ---\\ Enumeration of the disk units (2) - 0s ~ Drive C: has 114 GB free of 238 GB (System) ~ Drive D: has 1604 GB free of 1907 GB ---\\ State of the Windows Security Center (7) - 0s [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer] NoActiveDesktopChanges: Modified [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] EnableLUA: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\NOHIDDEN] CheckedValue: Modified [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL] CheckedValue: OK [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Associations] Application: OK [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] Shell: OK [HKLM\SYSTEM\CurrentControlSet\Services\COMSysApp] Type: OK ---\\ Search Generic System Files (24) - 1s [MD5.4E10FB1A015B49AC68F76C1A3F4D9C0F] - 12/02/2017 - (.Microsoft Corporation - Windows Explorer.) -- C:\Windows\Explorer.exe [4673304] =>.Microsoft Windows® [MD5.C7645D43451C6D94D87F4D07BDE59C89] - 16/07/2016 - (.Microsoft Corporation - Windows host process (Rundll32).) -- C:\Windows\System32\rundll32.exe [69632] =>.Microsoft Corporation [MD5.99A19C9A74E2F9820E501DCE77F84F70] - 16/07/2016 - (.Microsoft Corporation - Windows Start-Up Application.) -- C:\Windows\System32\Wininit.exe [304240] =>.Microsoft Windows Publisher® [MD5.E584CDC70F694F9A984A060A8291EB04] - 12/02/2017 - (.Microsoft Corporation - Internet Extensions for Win32.) -- C:\Windows\System32\wininet.dll [2669056] =>.Microsoft Corporation [MD5.917F081E2AB667C44F7D96DE1D16DFAE] - 12/02/2017 - (.Microsoft Corporation - Windows Logon Application.) -- C:\Windows\System32\Winlogon.exe [673792] =>.Microsoft Corporation [MD5.9600B7F2F89DE60A80D13DE42F672834] - 16/07/2016 - (.Microsoft Corporation - Software Licensing Library.) -- C:\Windows\System32\sppcomapi.dll [402432] =>.Microsoft Corporation [MD5.96B8A433F6407DE34850927C96C6CE9B] - 20/11/2016 - (.Microsoft Corporation - DNS Client API DLL.) -- C:\Windows\System32\dnsapi.dll [646136] =>.Microsoft Windows® [MD5.227CFE3EDA82029AAC1C088A16297CD7] - 20/11/2016 - (.Microsoft Corporation - DNS Client API DLL.) -- C:\Windows\Syswow64\dnsapi.dll [496872] =>.Microsoft Windows® [MD5.323AA1953ED9C01E23F740FA891FE064] - 20/11/2016 - (.Microsoft Corporation - Ancillary Function Driver for WinSock.) -- C:\Windows\System32\drivers\AFD.sys [584032] =>.Microsoft Windows® [MD5.A10F989A812B57B9695F6C305907C9C6] - 16/07/2016 - (.Microsoft Corporation - ATAPI IDE Miniport Driver.) -- C:\Windows\System32\drivers\atapi.sys [28512] =>.Microsoft Windows® [MD5.F8FB51B9EF6372610E9B31A1D86B62FC] - 16/07/2016 - (.Microsoft Corporation - CD-ROM File System Driver.) -- C:\Windows\System32\drivers\Cdfs.sys [92160] =>.Microsoft Corporation [MD5.613D0137C269187FA298A157E3D14A18] - 16/07/2016 - (.Microsoft Corporation - SCSI CD-ROM Driver.) -- C:\Windows\System32\drivers\Cdrom.sys [173056] =>.Microsoft Corporation [MD5.0D1D392ED2597F295956D058D33BD7C3] - 20/11/2016 - (.Microsoft Corporation - DFS Namespace Client Driver.) -- C:\Windows\System32\drivers\DfsC.sys [144896] =>.Microsoft Corporation [MD5.10E3515FE5DBA6656FA62C29342EC4A1] - 16/07/2016 - (.Microsoft Corporation - High Definition Audio Bus Driver.) -- C:\Windows\System32\drivers\HDAudBus.sys [83456] =>.Microsoft Corporation [MD5.B54B30992620C97230013A74461C8517] - 16/07/2016 - (.Microsoft Corporation - i8042 Port Driver.) -- C:\Windows\System32\drivers\i8042prt.sys [114176] =>.Microsoft Corporation [MD5.F1DAECC3B3D6399875D4F10529D6A77C] - 16/07/2016 - (.Microsoft Corporation - IP Network Address Translator.) -- C:\Windows\System32\drivers\IpNat.sys [212480] =>.Microsoft Corporation [MD5.E671EDAB0726E05ECEF4058B4CD73C4D] - 20/11/2016 - (.Microsoft Corporation - Windows NT SMB Minirdr.) -- C:\Windows\System32\drivers\MRxSmb.sys [450392] =>.Microsoft Windows® [MD5.6FEBB0A847FFD5F057B9AC8889F1B9A7] - 16/07/2016 - (.Microsoft Corporation - MBT Transport driver.) -- C:\Windows\System32\drivers\netBT.sys [279040] =>.Microsoft Corporation [MD5.DB69C6DA8B3DDFDC547D455CA23A8250] - 20/11/2016 - (.Microsoft Corporation - NT File System Driver.) -- C:\Windows\System32\drivers\ntfs.sys [2255712] =>.Microsoft Windows® [MD5.6B81BF7853D161DB8AC62CD8B9C2DE6B] - 16/07/2016 - (.Microsoft Corporation - Parallel Port Driver.) -- C:\Windows\System32\drivers\Parport.sys [96768] =>.Microsoft Corporation [MD5.17E565710172ED71B8531D8822E1C5D1] - 16/07/2016 - (.Microsoft Corporation - RAS L2TP mini-port/call-manager driver.) -- C:\Windows\System32\drivers\Rasl2tp.sys [104960] =>.Microsoft Corporation [MD5.7135785C21CA79D270D11037C43D3F19] - 20/11/2016 - (.Microsoft Corporation - Microsoft RDP Device redirector.) -- C:\Windows\System32\drivers\rdpdr.sys [177152] =>.Microsoft Corporation [MD5.9D2DD64A0B51C56285512DC9454340F6] - 16/07/2016 - (.Microsoft Corporation - TDI Translation Driver.) -- C:\Windows\System32\drivers\tdx.sys [118112] =>.Microsoft Windows® [MD5.BF2546583BB75F01DDA60A7921DFB230] - 16/07/2016 - (.Microsoft Corporation - Volume Shadow Copy driver.) -- C:\Windows\System32\drivers\volsnap.sys [391520] =>.Microsoft Windows® ---\\ Non Microsoft non disabled Windows Services (14) - 1s O23 - Service: Adobe Active File Monitor V13 (AdobeActiveFileMonitor13.0) . (.Adobe Systems Incorporated - Adobe Photoshop Elements 13.0 (component).) - C:\Program Files\Adobe\Elements 13 Organizer\PhotoshopElementsFileAgent.exe =>.Adobe Systems Incorporated® O23 - Service: (AdobeUpdateService) . (.Adobe Systems Incorporated - Adobe Update Service.) - C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe =>.Adobe Systems Incorporated® O23 - Service: Adobe Genuine Software Integrity Service (AGSService) . (.Adobe Systems, Incorporated - Adobe Genuine Software Integrity Service.) - C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe =>.Adobe Systems Incorporated® O23 - Service: Google Update Service (gupdate) (gupdate) . (.Google Inc. - Google Installer.) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe =>.Google Inc® O23 - Service: LavasoftTcpService (LavasoftTcpService) . (.Lavasoft Limited - .) - C:\Program Files (x86)\Lavasoft\Web Companion\TcpService\2.3.4.7\LavasoftTcpService.exe =>.Lavasoft Limited® O23 - Service: Malwarebytes Service (MBAMService) . (.Malwarebytes - Malwarebytes Service.) - C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe =>.Malwarebytes Corporation® O23 - Service: NVIDIA LocalSystem Container (NvContainerLocalSystem) . (.NVIDIA Corporation - NVIDIA Container.) - C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe =>.NVIDIA Corporation® O23 - Service: NVIDIA Display Container LS (NVDisplay.ContainerLocalSystem) . (.NVIDIA Corporation - NVIDIA Container.) - C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe =>.NVIDIA Corporation® O23 - Service: NVIDIA Wireless Controller Service (NVIDIA Wireless Controller Service) . (...) - C:\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe (.not file.) O23 - Service: NVIDIA Telemetry Container (NvTelemetryContainer) . (.NVIDIA Corporation - NVIDIA Container.) - C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe =>.NVIDIA Corporation® O23 - Service: Origin Web Helper Service (Origin Web Helper Service) . (.Electronic Arts - OriginWebHelperService.) - C:\Program Files (x86)\Origin\OriginWebHelperService.exe =>.Electronic Arts, Inc.® O23 - Service: PunkBuster (PnkBstrA) . (...) - C:\Program Files (x86)\Even Balance, Inc\PunkBuster\PB\PnkBstrA.exe =>.Even Balance, Inc.® O23 - Service: @oem2.inf,%BtDevMan.SvcDesc%;Realtek Bluetooth Device Manag (RtkBtManServ) . (.Realtek Semiconductor Corp. - Realtek Bluetooth Device Manager Service Ap.) - C:\Windows\RtkBtManServ.exe =>.Realtek Semiconductor Corp.® O23 - Service: WC Assistant (WCAssistantService) . (.Copyright © 2014 - SPWindowsService.) - C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.WCAssistant.WinService.exe {6DE41F889CF84643F324B3D5} ---\\ Services not Microsoft (SR=Run, SS=Stop) (19) - 28s SR - Auto [30/01/2015] [ 231120] Adobe Active File Monitor V13 (AdobeActiveFileMonitor13.0) . (.Adobe Systems Incorporated.) - C:\Program Files\Adobe\Elements 13 Organizer\PhotoshopElementsFileAgent.exe =>.Adobe Systems Incorporated® SR - Auto [09/12/2016] [ 753240] (AdobeUpdateService) . (.Adobe Systems Incorporated.) - C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe =>.Adobe Systems Incorporated® SR - Auto [19/01/2017] [ 2227312] Adobe Genuine Software Integrity Service (AGSService) . (.Adobe Systems, Incorporated.) - C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe =>.Adobe Systems Incorporated® SS - Auto [29/12/2016] [ 153752] Google Update Service (gupdate) (gupdate) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe =>.Google Inc® SS - Demand [29/12/2016] [ 153752] Google Update Service (gupdatem) (gupdatem) . (.Google Inc..) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe =>.Google Inc® SR - Auto [20/02/2017] [ 2751760] LavasoftTcpService (LavasoftTcpService) . (.Lavasoft Limited.) - C:\Program Files (x86)\Lavasoft\Web Companion\TcpService\2.3.4.7\LavasoftTcpService.exe =>.Lavasoft Limited® SR - Auto [20/01/2017] [ 4355024] Malwarebytes Service (MBAMService) . (.Malwarebytes.) - C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe =>.Malwarebytes Corporation® SS - Demand [06/02/2017] [ 147400] Mozilla Maintenance Service (MozillaMaintenance) . (.Mozilla Foundation.) - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe =>.Mozilla Corporation® SR - Auto [20/01/2017] [ 462784] NVIDIA LocalSystem Container (NvContainerLocalSystem) . (.NVIDIA Corporation.) - C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe =>.NVIDIA Corporation® SS - Demand [20/01/2017] [ 462784] NVIDIA NetworkService Container (NvContainerNetworkService) . (.NVIDIA Corporation.) - C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe =>.NVIDIA Corporation® SR - Auto [20/01/2017] [ 464440] NVIDIA Display Container LS (NVDisplay.ContainerLocalSystem) . (.NVIDIA Corporation.) - C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe =>.NVIDIA Corporation® SR - Auto [20/01/2017] [ 425408] NVIDIA Telemetry Container (NvTelemetryContainer) . (.NVIDIA Corporation.) - C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe =>.NVIDIA Corporation® SS - Demand [25/02/2017] [ 2124296] Origin Client Service (Origin Client Service) . (.Electronic Arts.) - C:\Program Files (x86)\Origin\OriginClientService.exe =>.Electronic Arts, Inc.® SR - Auto [25/02/2017] [ 2185232] Origin Web Helper Service (Origin Web Helper Service) . (.Electronic Arts.) - C:\Program Files (x86)\Origin\OriginWebHelperService.exe =>.Electronic Arts, Inc.® SR - Auto [09/03/2011] [ 63040] PunkBuster (PnkBstrA) . (...) - C:\Program Files (x86)\Even Balance, Inc\PunkBuster\PB\PnkBstrA.exe =>.Even Balance, Inc.® SR - Auto [26/10/2016] [ 258864] @oem2.inf,%BtDevMan.SvcDesc%;Realtek Bluetooth Device Manag (RtkBtManServ) . (.Realtek Semiconductor Corp..) - C:\Windows\RtkBtManServ.exe =>.Realtek Semiconductor Corp.® SR - Demand [18/01/2017] [ 1464096] Steam Client Service (Steam Client Service) . (.Valve Corporation.) - C:\Program Files (x86)\Common Files\Steam\SteamService.exe =>.Valve® SR - Auto [20/02/2017] [ 25240] WC Assistant (WCAssistantService) . (.Copyright © 2014.) - C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.WCAssistant.WinService.exe {6DE41F889CF84643F324B3D5} SS - Demand [12/02/2017] [ 14544] WinRing0_1_2_0 (WinRing0_1_2_0) . (.OpenLibSys.org.) - C:\Users\TT\AppData\Local\Temp\tmpE295.tmp =>.Noriyuki MIYAZAKI® ---\\ Task Planned Automatically (30) - 13s [MD5.48515EEA1608ECD83FE26C7490460F59] [APT] [AdobeAAMUpdater-1.0-F4PC-Dad] (.Adobe Systems Incorporated.) -- C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [508128] (.Activate.) =>.Adobe Systems Incorporated® [MD5.A8FD9222E4D72596BB37DA8BE95C0BA4] [APT] [GoogleUpdateTaskMachineCore] (.Google Inc..) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153752] (.Activate.) =>.Google Inc® [MD5.A8FD9222E4D72596BB37DA8BE95C0BA4] [APT] [GoogleUpdateTaskMachineUA] (.Google Inc..) -- C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [153752] (.Activate.) =>.Google Inc® [MD5.5A36192184D9B7F67E4E81962751DC5B] [APT] [HPCustParticipation HP OfficeJet 4650 series] (.Hewlett-Packard Development Company, LP.) -- C:\Program Files\HP\HP OfficeJet 4650 series\Bin\HPCustPartic.exe [6105096] (.Activate.) =>.Hewlett Packard® [MD5.62D705A1C4F8FBDD2941CCD2E9DEC206] [APT] [NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}] (.NVIDIA Corporation.) -- C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [462784] (.Activate.) =>.NVIDIA Corporation® [MD5.415EC48C7F31716569B17B0DDC989433] [APT] [NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}] (.NVIDIA Corporation.) -- C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [781248] (.Activate.) =>.NVIDIA Corporation® [MD5.F7BF729844CE919A860C2D0D1F686367] [APT] [NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}] (.NVIDIA Corporation.) -- C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [641984] (.Activate.) =>.NVIDIA Corporation® [MD5.F7BF729844CE919A860C2D0D1F686367] [APT] [NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}] (.NVIDIA Corporation.) -- C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [641984] (.Activate.) =>.NVIDIA Corporation® [MD5.BBEA191AF28EA5ACB6D76003257C20EC] [APT] [NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}] (.NVIDIA Corporation.) -- C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe [436160] (.Activate.) =>.NVIDIA Corporation® [MD5.C0F29430B8026788829AD7542BF66CA8] [APT] [NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}] (.NVIDIA Corporation.) -- C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [714688] (.Activate.) =>.NVIDIA Corporation® [MD5.C0F29430B8026788829AD7542BF66CA8] [APT] [NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}] (.NVIDIA Corporation.) -- C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [714688] (.Activate.) =>.NVIDIA Corporation® [MD5.3C658B5EB206FDAD0CF325D6CA46DA95] [APT] [{28DA7460-C7EC-4276-A1FF-B9EAF7FDFEF6}] (...) -- C:\Program Files (x86)\Activision\Call of Duty 2\CoD2SP_s.exe [1753088] (.Activate.) [MD5.AE157A2AE7221321D32840E0076277F0] [APT] [{43719454-2974-4532-A795-986B56FC87E0}] (.Electronic Arts Inc..) -- C:\Program Files (x86)\EA GAMES\Medal of Honor Pacific Assault(tm)\mohpa_setup.exe [4050944] (.Activate.) =>.Electronic Arts Inc. [MD5.215860CB0EEBA63E6116FBFEA3BF349A] [APT] [{56E113F0-C191-4BC8-B6E6-5CEB7013EEE2}] (...) -- C:\Program Files (x86)\Call of Duty\CoDSP.exe [1716224] (.Activate.) [MD5.9B83FC51DBD35470EEE8B2EA5DCD1E99] [APT] [PCMeter\Startup] (.AddGadgets.) -- C:\Users\TT\Downloads\PCMeter\PCMeterV4\PCMeterV0.4.exe [119008] (.Activate.) =>.AddGadgets IT® O39 - APT: AdobeAAMUpdater-1.0-F4PC-Dad - (.Adobe Systems Incorporated.) -- C:\Windows\System32\Tasks\AdobeAAMUpdater-1.0-F4PC-Dad [3582] =>.Adobe Systems Incorporated® O39 - APT: GoogleUpdateTaskMachineCore - (.Google Inc..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore [3120] =>.Google Inc® O39 - APT: GoogleUpdateTaskMachineUA - (.Google Inc..) -- C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA [3344] =>.Google Inc® O39 - APT: HPCustParticipation HP OfficeJet 4650 series - (.Hewlett-Packard Development Company, LP.) -- C:\Windows\System32\Tasks\HPCustParticipation HP OfficeJet 4650 series [3710] =>.Hewlett Packard® O39 - APT: NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - (.NVIDIA Corporation.) -- C:\Windows\System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} [4308] =>.NVIDIA Corporation® O39 - APT: NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - (.NVIDIA Corporation.) -- C:\Windows\System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} [3884] =>.NVIDIA Corporation® O39 - APT: NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - (.NVIDIA Corporation.) -- C:\Windows\System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} [3894] =>.NVIDIA Corporation® O39 - APT: NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - (.NVIDIA Corporation.) -- C:\Windows\System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} [3654] =>.NVIDIA Corporation® O39 - APT: NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - (.NVIDIA Corporation.) -- C:\Windows\System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} [3858] =>.NVIDIA Corporation® O39 - APT: NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - (.NVIDIA Corporation.) -- C:\Windows\System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} [3696] =>.NVIDIA Corporation® O39 - APT: NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - (.NVIDIA Corporation.) -- C:\Windows\System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} [3866] =>.NVIDIA Corporation® O39 - APT: Unknown - (.Microsoft Corporation.) -- C:\Windows\System32\Tasks\OneDrive Standalone Update Task v2 [2768] =>.Microsoft Corporation O39 - APT: {28DA7460-C7EC-4276-A1FF-B9EAF7FDFEF6} - (...) -- C:\Windows\System32\Tasks\{28DA7460-C7EC-4276-A1FF-B9EAF7FDFEF6} [3370] O39 - APT: {43719454-2974-4532-A795-986B56FC87E0} - (.Electronic Arts Inc..) -- C:\Windows\System32\Tasks\{43719454-2974-4532-A795-986B56FC87E0} [3368] =>.Electronic Arts Inc. O39 - APT: {56E113F0-C191-4BC8-B6E6-5CEB7013EEE2} - (...) -- C:\Windows\System32\Tasks\{56E113F0-C191-4BC8-B6E6-5CEB7013EEE2} [3276] ---\\ Auto loading programs from Registry and folders (20) - 0s O4 - HKLM\..\Run: [WindowsDefender] . (.Microsoft Corporation - Windows Defender notification icon.) -- C:\Program Files\Windows Defender\MSASCuiL.exe =>.Microsoft Corporation O4 - HKLM\..\Run: [ShadowPlay] . (.Microsoft Corporation - Windows host process (Rundll32).) -- C:\Windows\System32\rundll32.exe =>.Microsoft Corporation O4 - HKLM\..\Run: [Malwarebytes TrayApp] . (.Malwarebytes - Malwarebytes Tray Application.) -- C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe =>.Malwarebytes Corporation® O4 - HKLM\..\Run: [AdobeAAMUpdater-1.0] . (.Adobe Systems Incorporated - Adobe Updater Startup Utility.) -- C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe =>.Adobe Systems Incorporated® O4 - HKCU\..\Run: [OneDrive] . (.Microsoft Corporation - Microsoft OneDrive.) -- C:\Users\TT\AppData\Local\Microsoft\OneDrive\OneDrive.exe =>.Microsoft Corporation® O4 - HKCU\..\Run: [ClearScreen Player] C:\Program Files (x86)\ClearScreenPlayer\ClearScreenPlayer.exe (.not file.) O4 - HKCU\..\Run: [HP OfficeJet 4650 series (NET)] . (.Hewlett-Packard Development Company, LP - ScanToPCActivationApp.) -- C:\Program Files\HP\HP OfficeJet 4650 series\Bin\ScanToPCActivationApp.exe =>.Hewlett Packard® O4 - HKCU\..\Run: [Web Companion] . (.Lavasoft - Web Companion.) -- C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanion.exe {6DE41F889CF84643F324B3D5} =>.Lavasoft O4 - HKCU\..\Run: [Steam] . (.Valve Corporation - Steam Client Bootstrapper.) -- C:\Program Files (x86)\Steam\Steam.exe =>.Valve® O4 - HKCU\..\Run: [Chromium] . (.The Chromium Authors - Chromium.) -- c:\Users\TT\AppData\Local\Chromium\application\chrome.exe =>.The Chromium Authors O4 - HKLM\..\Wow6432Node\Run: [SunJavaUpdateSched] . (.Oracle Corporation - Java Update Scheduler.) -- C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe =>.Oracle America, Inc.® O4 - HKLM\..\Wow6432Node\Run: [HP Software Update] . (.Hewlett-Packard - hpwuSchd Application.) -- C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe =>.Hewlett-Packard Company® O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] . (.Microsoft Corporation - Microsoft OneDrive Setup.) -- C:\Windows\SysWOW64\OneDriveSetup.exe =>.Microsoft Corporation® O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] . (.Microsoft Corporation - Microsoft OneDrive Setup.) -- C:\Windows\SysWOW64\OneDriveSetup.exe =>.Microsoft Corporation® O4 - HKUS\S-1-5-21-2438100261-443141923-189968324-1001\..\Run: [OneDrive] . (.Microsoft Corporation - Microsoft OneDrive.) -- C:\Users\TT\AppData\Local\Microsoft\OneDrive\OneDrive.exe =>.Microsoft Corporation® O4 - HKUS\S-1-5-21-2438100261-443141923-189968324-1001\..\Run: [ClearScreen Player] C:\Program Files (x86)\ClearScreenPlayer\ClearScreenPlayer.exe (.not file.) O4 - HKUS\S-1-5-21-2438100261-443141923-189968324-1001\..\Run: [HP OfficeJet 4650 series (NET)] . (.Hewlett-Packard Development Company, LP - ScanToPCActivationApp.) -- C:\Program Files\HP\HP OfficeJet 4650 series\Bin\ScanToPCActivationApp.exe =>.Hewlett Packard® O4 - HKUS\S-1-5-21-2438100261-443141923-189968324-1001\..\Run: [Web Companion] . (.Lavasoft - Web Companion.) -- C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanion.exe {6DE41F889CF84643F324B3D5} =>.Lavasoft O4 - HKUS\S-1-5-21-2438100261-443141923-189968324-1001\..\Run: [Steam] . (.Valve Corporation - Steam Client Bootstrapper.) -- C:\Program Files (x86)\Steam\Steam.exe =>.Valve® O4 - HKUS\S-1-5-21-2438100261-443141923-189968324-1001\..\Run: [Chromium] . (.The Chromium Authors - Chromium.) -- c:\Users\TT\AppData\Local\Chromium\application\chrome.exe =>.The Chromium Authors ---\\ Process running (47) - 2s [MD5.F2C12A68577CA1A069A394A535A176CC] - (.NVIDIA Corporation - NVIDIA Container.) -- C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [464440] [PID.1300] =>.NVIDIA Corporation® [MD5.2B874307502F677558178FE5A1EB45C1] - (.NVIDIA Corporation - NVIDIA User Experience Driver Component.) -- C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe [1286592] [PID.1448] =>.NVIDIA Corporation® [MD5.F2EB8EB5FC46FB849498BBEF2AD6539D] - (.Adobe Systems, Incorporated - Adobe Genuine Software Integrity Service.) -- C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2227312] [PID.2608] =>.Adobe Systems Incorporated® [MD5.5B4D60ACCEA6918DBBB8C9FD4ADBDD29] - (.Adobe Systems Incorporated - Adobe Update Service.) -- C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [753240] [PID.2684] =>.Adobe Systems Incorporated® [MD5.804E3246E3E73D4A936F2F4BCDC53A2D] - (.Malwarebytes - Malwarebytes Service.) -- C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4355024] [PID.2708] =>.Malwarebytes Corporation® [MD5.62D705A1C4F8FBDD2941CCD2E9DEC206] - (.NVIDIA Corporation - NVIDIA Container.) -- C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [462784] [PID.2768] =>.NVIDIA Corporation® [MD5.8FB6D64CB42E660C4534D38013D64A03] - (.Lavasoft Limited - .) -- C:\Program Files (x86)\Lavasoft\Web Companion\TcpService\2.3.4.7\LavasoftTcpService.exe [2751760] [PID.2780] =>.Lavasoft Limited® [MD5.282423AA3B0648082647103A5C42B66C] - (.NVIDIA Corporation - NVIDIA Container.) -- C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe [425408] [PID.2788] =>.NVIDIA Corporation® [MD5.3458347B7D15E95F0A073F0E5BB4CB5C] - (.Electronic Arts - OriginWebHelperService.) -- C:\Program Files (x86)\Origin\OriginWebHelperService.exe [2185232] [PID.2796] =>.Electronic Arts, Inc.® [MD5.C183B7E8C4DD96AF66D7ACE48D2D9B05] - (...) -- C:\Program Files (x86)\Even Balance, Inc\PunkBuster\PB\PnkBstrA.exe [63040] [PID.2832] =>.Even Balance, Inc.® [MD5.E475F42E177DDC7CE6066F9DFCC98DF0] - (.Realtek Semiconductor Corp. - Realtek Bluetooth Device Manager Service Ap.) -- C:\Windows\RtkBtManServ.exe [258864] [PID.2860] =>.Realtek Semiconductor Corp.® [MD5.5A2A1F4B4848BAE1147FFC0D628377F0] - (.Copyright © 2014 - SPWindowsService.) -- C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.WCAssistant.WinService.exe [25240] [PID.2876] {6DE41F889CF84643F324B3D5} [MD5.F6722135AA290CE0AC930084C0DC3BAD] - (.NVIDIA Corporation - NVIDIA Container.) -- C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe [425408] [PID.4012] =>.NVIDIA Corporation® [MD5.BEEDC296881D39DC2A305E17E2B98133] - (.NVIDIA Corporation - NVIDIA Settings.) -- C:\Program Files\NVIDIA Corporation\Display\nvtray.exe [2456632] [PID.4364] =>.NVIDIA Corporation® [MD5.9B83FC51DBD35470EEE8B2EA5DCD1E99] - (.AddGadgets - AddGadgets.) -- C:\Users\TT\Downloads\PCMeter\PCMeterV4\PCMeterV0.4.exe [119008] [PID.5076] =>.AddGadgets IT® [MD5.5D1DBC65EDEE3F51A7B4BB3752444307] - (...) -- C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.11.110.0_x64__kzf8qxf38zg5c\SkypeHost.exe [73728] [PID.7072] =>.Skype Technologies [MD5.FE40EC349D80C0ED24A5808DCFE9A0D2] - (.Google Inc. - Google Crash Handler.) -- C:\Program Files (x86)\Google\Update\1.3.32.7\GoogleCrashHandler.exe [288920] [PID.7528] =>.Google Inc® [MD5.B5C7D56B6DB76C66E24B4B735BB66509] - (.Google Inc. - Google Crash Handler.) -- C:\Program Files (x86)\Google\Update\1.3.32.7\GoogleCrashHandler64.exe [366232] [PID.7548] =>.Google Inc® [MD5.A6A21A7D544675E98C040DA18904CF50] - (.Malwarebytes - Malwarebytes Tray Application.) -- C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe [2780112] [PID.8272] =>.Malwarebytes Corporation® [MD5.EAD8BFF3BF75C7D0B28527303EA13933] - (.Hewlett-Packard Development Company, LP - ScanToPCActivationApp.) -- C:\Program Files\HP\HP OfficeJet 4650 series\Bin\ScanToPCActivationApp.exe [3651080] [PID.8408] =>.Hewlett Packard® [MD5.5A394ABF992560A6701B91786BF4327F] - (.Lavasoft - Web Companion.) -- C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanion.exe [1869464] [PID.8596] {6DE41F889CF84643F324B3D5} =>.Lavasoft [MD5.5710E80EAB62305C4FD4D968567448D2] - (.Valve Corporation - Steam Client Bootstrapper.) -- C:\Program Files (x86)\Steam\Steam.exe [2881824] [PID.9124] =>.Valve® [MD5.395CB6E8C67BFB1063AD86987909C184] - (.Oracle Corporation - Java Update Scheduler.) -- C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288] [PID.9300] =>.Oracle America, Inc.® [MD5.34D296AFC913E302953C70463EF09A48] - (.Hewlett-Packard - hpwuSchd Application.) -- C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe [96056] [PID.9376] =>.Hewlett-Packard Company® [MD5.3BD79A1F6D2EA0FDDEA3F8914B2A6A0C] - (.Elaborate Bytes AG - Virtual CloneDrive Daemon.) -- C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [88984] [PID.9496] =>.Elaborate Bytes AG® [MD5.6302798F2560E25EB980992B1C4C5F81] - (.Adobe Systems Incorporated - Adobe Creative Cloud.) -- C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2384984] [PID.9756] =>.Adobe Systems Incorporated® [MD5.1AADD0EFD6C8736FF2051E415F0D9EE5] - (.Valve Corporation - Steam Client WebHelper.) -- C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe [2183456] [PID.9812] =>.Valve® [MD5.596DC69BB40A96FCA4B19D9D1E221E34] - (.Valve Corporation - Steam Client Service.) -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe [1464096] [PID.9944] =>.Valve® [MD5.9D54F3E5E4D102AB27E190CBEC14B355] - (.Copyright (C) 2014 David Carpenter - Everything.) -- C:\Program Files (x86)\Everything\Everything.exe [1048576] [PID.9972] =>.Copyright (c) 2014 David Carpenter [MD5.FC46A8F11091473A97489EFAAFA05245] - (.Adobe Systems Incorporated - Adobe IPC Broker.) -- C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe [1029808] [PID.9452] =>.Adobe Systems Incorporated® [MD5.9D54F3E5E4D102AB27E190CBEC14B355] - (.Copyright (C) 2014 David Carpenter - Everything.) -- C:\Program Files (x86)\Everything\Everything.exe [1048576] [PID.3884] =>.Copyright (c) 2014 David Carpenter [MD5.22536611AEB045A262CB1916986F7B13] - (.NVIDIA Corporation - NVIDIA Capture Server.) -- C:\Program Files\NVIDIA Corporation\ShadowPlay\nvspcaps64.exe [7551936] [PID.9984] =>.NVIDIA Corporation® [MD5.F55BB0DD4BBBF85468A3AAE80FDFEFE0] - (.Adobe Systems Incorporated - Creative Cloud.) -- C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe [2361944] [PID.10312] =>.Adobe Systems Incorporated® [MD5.126469238DF2614EE76D283B91BAB1B2] - (.Adobe Systems Incorporated - Adobe CEF Helper.) -- C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\HEX\Adobe CEF Helper.exe [191064] [PID.10440] =>.Adobe Systems Incorporated® [MD5.EDBE124B959B4DA17EC72184886CE136] - (.NVIDIA Corporation - NVIDIA Share.) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe [1447360] [PID.10664] =>.NVIDIA Corporation® [MD5.EDBE124B959B4DA17EC72184886CE136] - (.NVIDIA Corporation - NVIDIA Share.) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe [1447360] [PID.11080] =>.NVIDIA Corporation® [MD5.3BAA7000BD8D0952BA78CFA28F63A916] - (.Node.js - NVIDIA Web Helper Service.) -- C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe [15547328] [PID.11208] =>.NVIDIA Corporation® [MD5.E8A5FD680DDC606597CDC92BD5E57857] - (.Copyright © 2013-2016, Adobe Systems Incorporated. Al - Core Sync.) -- C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe [31723696] [PID.10528] =>.Adobe Systems Incorporated® [MD5.5CF3602D0CF016A739C1C14B9E054BCF] - (.Adobe Systems Incorporated - CCXProcess.) -- C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\CCXProcess.exe [149592] [PID.10308] =>.Adobe Systems Incorporated® [MD5.E06A0564ED1370E4EEF2217EE4F4C2CE] - (.Node.js - Node.js: Server-side JavaScript.) -- C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\libs\node.exe [11798680] [PID.9888] =>.Node.js Foundation® [MD5.AA883A4F23D662B9F213D7C10A16782F] - (.Adobe Systems Incorporated - CCLibraries.) -- C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\CCLibrary.exe [149592] [PID.12168] =>.Adobe Systems Incorporated® [MD5.E06A0564ED1370E4EEF2217EE4F4C2CE] - (.Node.js - Node.js: Server-side JavaScript.) -- C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\libs\node.exe [11798680] [PID.12176] =>.Node.js Foundation® [MD5.5600EDBAB87FDAA92B09838D28FB2203] - (.Adobe Systems Incorporated - Adobe Photoshop Elements 13.0 (component).) -- C:\Program Files\Adobe\Elements 13 Organizer\PhotoshopElementsFileAgent.exe [231120] [PID.9356] =>.Adobe Systems Incorporated® [MD5.BF84A015DC0EBD7EE217635758008F43] - (.Hewlett-Packard Development Company, LP - HPNetworkCommunicatorCom.) -- C:\Program Files\HP\HP OfficeJet 4650 series\Bin\HPNetworkCommunicatorCom.exe [1212936] [PID.12396] =>.Hewlett Packard® [MD5.F521C7C0DC19A1F7F54EC7987677FD2B] - (...) -- C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.1118.10000.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe [19456] [PID.6232] =>.Microsoft Corporation [MD5.E90774F7C3FF6AFEB0F59A86571FBCC4] - (.ZabKat - xplorer² - explorer replacement.) -- C:\Program Files\zabkat\xplorer2\xplorer2_64.exe [1726240] [PID.480] =>.Nikolaos Bozinis® [MD5.6E2F0DE7B5EBEE2640EB49707A40AD50] - (.Nicolas Coolman - ZHPDiag.) -- C:\Users\TT\Desktop\ZHPDiag3.exe [2705920] [PID.2984] =>.Nicolas Coolman ---\\ Google Chrome, Start,Search,Extensions (20) - 1s G0 - GCSP: Preferences [User Data\Default][HomePage] http://192.168.1.109:8060 G0 - GCSP: Preferences [User Data\Default][HomePage] http://192.168.1.121:8060 G0 - GCSP: Preferences [User Data\Default][HomePage] http://storiesonline.net G0 - GCSP: Preferences [User Data\Default][HomePage] http://www.mcstories.com G0 - GCSP: Preferences [User Data\Default][HomePage] http://apis.google.com =>.Google Inc. G0 - GCSP: Preferences [User Data\Default][HomePage] http://fonts.gstatic.com =>.Google Inc. G0 - GCSP: Preferences [User Data\Default][HomePage] http://ssl.gstatic.com =>.Google Inc. G0 - GCSP: Preferences [User Data\Default][HomePage] http://www.google.com =>.Google Inc. G0 - GCSP: Preferences [User Data\Default][HomePage] http://www.gstatic.com =>.Google Inc. G0 - GCSP: Secure Preferences [User Data\Default][HomePage] http://www.google.com/ =>.Google Inc. G2 - GCE: Preference [User Data\Default] [aapocclcgogkmnckokdopfmhonfmgoek] Google Chrome manifest =>.Google Inc. =>.Google Inc. G2 - GCE: Preference [User Data\Default] [aohghmighlieiainnegkcijnfilokake] Google Chrome manifest =>.Google Inc. =>.Google Inc. G2 - GCE: Preference [User Data\Default] [apdfllckaahabafndbhieahigkjlhalf] Google Chrome manifest =>.Google Inc. G2 - GCE: Preference [User Data\Default] [blpcfgokakmgnkcojhhkbfbldkacnbeo] Google Chrome manifest =>.Google Inc. G2 - GCE: Preference [User Data\Default] [efjodfcplkcccafghgnbnpgedgakohog] Google Chrome manifest =>.Google Inc. G2 - GCE: Preference [User Data\Default] [felcaaldnbdncclmgdcncolpebgiejap] Google Chrome manifest =>.Google Inc. =>.Google Inc. G2 - GCE: Preference [User Data\Default] [ghbmnnjooekpmoecnnnilnnbdlolhkhi] Google Chrome manifest =>.Google Inc. =>.Google Inc. G2 - GCE: Preference [User Data\Default] [nmmhkkegccagdldgiimedpiccmgmieda] Google Chrome manifest =>.Google Inc. G2 - GCE: Preference [User Data\Default] [pjkljhegncpnkpknbcohdijeoejaedia] Google Chrome manifest =>.Google Inc. G2 - GCE: Preference [User Data\Default] [pkedcjkdefgpdelpbcmbmeomcjbeemfm] Chrome Media Router =>.Google Inc. ---\\ Internet Explorer Extensions, Start, Search (16) - 0s R0 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://mail.ru/ R0 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = www.google.com =>.Google Inc. R0 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = www.google.com =>.Google Inc. R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ =>.Microsoft Corporation R1 - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com =>.Google Inc. R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ =>.Microsoft Corporation R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/ =>.Microsoft Corporation R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons =>.Microsoft Corporation R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk =>.Microsoft Corporation R1 - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/ =>.Microsoft Corporation R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/ =>.Microsoft Corporation R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/ =>.Microsoft Corporation R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/ =>.Microsoft Corporation R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Extensions Off Page = about:noadd-ons =>.Microsoft Corporation R1 - HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Main,Security Risk Page = about:securityrisk =>.Microsoft Corporation R3 - URLSearchHook: (no name) - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} Orphan =>.Microsoft Internet Explorer ---\\ Microsoft Edge,Plugins,Start,Search,Extensions (19) - 0s E4 - Microsoft Edge Favorites: HKU\S-1-5-21-2438100261-443141923-189968324-1001\url = http://app.plex.tv/web/app E4 - Microsoft Edge Favorites: HKU\S-1-5-21-2438100261-443141923-189968324-1001\url = http://www.optimum.net E4 - Microsoft Edge Favorites: HKU\S-1-5-21-2438100261-443141923-189968324-1001\url = http://www.imdb.com E4 - Microsoft Edge Favorites: HKU\S-1-5-21-2438100261-443141923-189968324-1001\url = http://www.mylifetime.com E4 - Microsoft Edge Favorites: HKU\S-1-5-21-2438100261-443141923-189968324-1001\url = http://www.msn.com/ =>.Microsoft Corporation E4 - Microsoft Edge Favorites: HKU\S-1-5-21-2438100261-443141923-189968324-1001\url = http://movies.netflix.com/ E4 - Microsoft Edge Favorites: HKU\S-1-5-21-2438100261-443141923-189968324-1001\url = http://www.thetvdb.com E4 - Microsoft Edge Favorites: HKU\S-1-5-21-2438100261-443141923-189968324-1001\url = http://partners.titantv.com/ E4 - Microsoft Edge Favorites: HKU\S-1-5-21-2438100261-443141923-189968324-1001\url = http://www.usanetwork.com E4 - Microsoft Edge Favorites: HKU\S-1-5-21-2438100261-443141923-189968324-1001\url = http://community.wdc.com/ E4 - Microsoft Edge Favorites: HKU\S-1-5-21-2438100261-443141923-189968324-1001\url = http://www.avsforum.com/ E4 - Microsoft Edge Favorites: HKU\S-1-5-21-2438100261-443141923-189968324-1001\url = http://go.microsoft.com/ =>.Microsoft Corporation E4 - Microsoft Edge Favorites: HKU\S-1-5-21-2438100261-443141923-189968324-1001\url = http://abc.go.com E4 - Microsoft Edge Favorites: HKU\S-1-5-21-2438100261-443141923-189968324-1001\url = http://thetvdb.com E4 - Microsoft Edge Favorites: HKU\S-1-5-21-2438100261-443141923-189968324-1001\url = http://www.mcstories.com E4 - Microsoft Edge Favorites: HKU\S-1-5-21-2438100261-443141923-189968324-1001\url = http://storiesonline.net/ E4 - Microsoft Edge Favorites: HKU\S-1-5-21-2438100261-443141923-189968324-1001\url = http://forum.windowsinstructed.com E4 - Microsoft Edge Favorites: HKU\S-1-5-21-2438100261-443141923-189968324-1001\url = http://www.amazon.com/ =>.Amazon Corporation E4 - Microsoft Edge Favorites: HKU\S-1-5-21-2438100261-443141923-189968324-1001\url = http://www.amctv.com ---\\ Internet Explorer, Proxy Management (3) - 0s R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyEnable = 0 R5 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings,MigrateProxy = 1 R5 - HKLM\SYSTEM\CurrentControlSet\services\NlaSvc\Parameters\Internet\ManualProxies [] ---\\ Line Analysis, IniFiles, Auto loading programs (3) - 0s F2 - REG:system.ini: UserInit=C:\Windows\system32\userinit.exe (.Microsoft Corporation.) =>.Microsoft Corporation F2 - REG:system.ini: Shell=C:\Windows\explorer.exe (.Microsoft Corporation.) =>.Microsoft Corporation F2 - REG:system.ini: VMApplet= ---\\ Hosts file redirection (1) - 0s ~ Le fichier hôte est sain (The hosts file is clean) (21) ---\\ Browser Helper Object (BHO) (2) - 0s O2 - BHO: Lync Click to Call BHO [64Bits] - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} (.Orphan.) O2 - BHO: Microsoft OneDrive for Business Browser Helper [64Bits] - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} (.Orphan.) ---\\ Global shortcuts Startup (110) - 5s O4 - GS\Desktop [Administrator]: DAD'S Notes.txt - Shortcut.lnk . (...) C:\Users\TT\Documents\DAD'S Notes.txt O4 - GS\Desktop [Administrator]: Diabetes Records PHS.xls - Shortcut.lnk . (.Dad - .) C:\Users\TT\OneDrive\Documents\My Documents\Diabetes Records PHS.xls O4 - GS\Desktop [Administrator]: PlanMaker 2016.lnk . (.SoftMaker Software GmbH - PlanMaker.) C:\Program Files (x86)\SoftMaker Office 2016\PlanMaker.exe =>.SoftMaker Software GmbH® O4 - GS\Desktop [Administrator]: TextMaker 2016.lnk . (.SoftMaker Software GmbH - TextMaker.) C:\Program Files (x86)\SoftMaker Office 2016\TextMaker.exe =>.SoftMaker Software GmbH® O4 - GS\Desktop [Administrator]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\TT\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman O4 - GS\Quicklaunch [Administrator]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc® O4 - GS\Quicklaunch [Administrator]: ImgBurn.lnk . (.LIGHTNING UK! - ImgBurn - The Ultimate Image Burner!.) C:\Program Files (x86)\ImgBurn\ImgBurn.exe =>.LIGHTNING UK! O4 - GS\Quicklaunch [Administrator]: Mail.Ru.lnk . (.Microsoft Corporation - Windows host process (Rundll32).) C:\Windows\System32\rundll32.exe url,FileProtocolHandler "http://www.mail.ru/ =>.Microsoft Corporation O4 - GS\Quicklaunch [Administrator]: Microsoft Outlook.lnk . (.Microsoft Corporation - Microsoft Outlook.) C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE /recycle =>.Microsoft Corporation® O4 - GS\Quicklaunch [Administrator]: ThumbsPlus 7.lnk . (.Cerious Software, Inc. - ThumbsPlus 7 SP2.) C:\Program Files (x86)\Thumbs7\Thumbs.exe {5C70051CA1CE9F0CAC0744D1764DEC11} O4 - GS\sendTo [Administrator]: Bluetooth File Transfer.LNK . (.Microsoft Corporation - .) C:\Windows\System32\fsquirt.exe =>.Microsoft Corporation O4 - GS\sendTo [Administrator]: Fax Recipient.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\Windows\system32\WFS.exe /SendTo =>.Microsoft Corporation O4 - GS\TaskBar [Administrator]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc® O4 - GS\TaskBar [Administrator]: Mozilla Thunderbird.lnk . (.Mozilla Corporation - Thunderbird.) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe =>.Mozilla Corporation® O4 - GS\TaskBar [Administrator]: xplorer2 pro x64.lnk . (.ZabKat - xplorer² - explorer replacement.) C:\Program Files\zabkat\xplorer2\xplorer2_64.exe /M =>.Nikolaos Bozinis® O4 - GS\Startup [Administrator]: Sidebar465.lnk . (.Microsoft Corporation - Windows Desktop Gadgets.) C:\Program Files (x86)\Windows Sidebar\sidebar.exe =>.Microsoft Corporation O4 - GS\Programs [Administrator]: NCH Suite.lnk . (.NCH Software - PhotoPad Image Editor.) C:\Program Files (x86)\NCH Software\PhotoPad\photopad.exe -extsuite =>.NCH Software® O4 - GS\Programs [Administrator]: OneDrive.lnk . (.Microsoft Corporation - Microsoft OneDrive.) C:\Users\TT\AppData\Local\Microsoft\OneDrive\OneDrive.exe =>.Microsoft Corporation® O4 - GS\Desktop [Dad]: DAD'S Notes.txt - Shortcut.lnk . (...) C:\Users\TT\Documents\DAD'S Notes.txt O4 - GS\Desktop [Dad]: Diabetes Records PHS.xls - Shortcut.lnk . (.Dad - .) C:\Users\TT\OneDrive\Documents\My Documents\Diabetes Records PHS.xls O4 - GS\Desktop [Dad]: PlanMaker 2016.lnk . (.SoftMaker Software GmbH - PlanMaker.) C:\Program Files (x86)\SoftMaker Office 2016\PlanMaker.exe =>.SoftMaker Software GmbH® O4 - GS\Desktop [Dad]: TextMaker 2016.lnk . (.SoftMaker Software GmbH - TextMaker.) C:\Program Files (x86)\SoftMaker Office 2016\TextMaker.exe =>.SoftMaker Software GmbH® O4 - GS\Desktop [Dad]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\TT\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman O4 - GS\Quicklaunch [Dad]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc® O4 - GS\Quicklaunch [Dad]: ImgBurn.lnk . (.LIGHTNING UK! - ImgBurn - The Ultimate Image Burner!.) C:\Program Files (x86)\ImgBurn\ImgBurn.exe =>.LIGHTNING UK! O4 - GS\Quicklaunch [Dad]: Mail.Ru.lnk . (.Microsoft Corporation - Windows host process (Rundll32).) C:\Windows\System32\rundll32.exe url,FileProtocolHandler "http://www.mail.ru/ =>.Microsoft Corporation O4 - GS\Quicklaunch [Dad]: Microsoft Outlook.lnk . (.Microsoft Corporation - Microsoft Outlook.) C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE /recycle =>.Microsoft Corporation® O4 - GS\Quicklaunch [Dad]: ThumbsPlus 7.lnk . (.Cerious Software, Inc. - ThumbsPlus 7 SP2.) C:\Program Files (x86)\Thumbs7\Thumbs.exe {5C70051CA1CE9F0CAC0744D1764DEC11} O4 - GS\sendTo [Dad]: Bluetooth File Transfer.LNK . (.Microsoft Corporation - .) C:\Windows\System32\fsquirt.exe =>.Microsoft Corporation O4 - GS\sendTo [Dad]: Fax Recipient.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\Windows\system32\WFS.exe /SendTo =>.Microsoft Corporation O4 - GS\TaskBar [Dad]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc® O4 - GS\TaskBar [Dad]: Mozilla Thunderbird.lnk . (.Mozilla Corporation - Thunderbird.) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe =>.Mozilla Corporation® O4 - GS\TaskBar [Dad]: xplorer2 pro x64.lnk . (.ZabKat - xplorer² - explorer replacement.) C:\Program Files\zabkat\xplorer2\xplorer2_64.exe /M =>.Nikolaos Bozinis® O4 - GS\Startup [Dad]: Sidebar465.lnk . (.Microsoft Corporation - Windows Desktop Gadgets.) C:\Program Files (x86)\Windows Sidebar\sidebar.exe =>.Microsoft Corporation O4 - GS\Programs [Dad]: NCH Suite.lnk . (.NCH Software - PhotoPad Image Editor.) C:\Program Files (x86)\NCH Software\PhotoPad\photopad.exe -extsuite =>.NCH Software® O4 - GS\Programs [Dad]: OneDrive.lnk . (.Microsoft Corporation - Microsoft OneDrive.) C:\Users\TT\AppData\Local\Microsoft\OneDrive\OneDrive.exe =>.Microsoft Corporation® O4 - GS\Desktop [Guest]: DAD'S Notes.txt - Shortcut.lnk . (...) C:\Users\TT\Documents\DAD'S Notes.txt O4 - GS\Desktop [Guest]: Diabetes Records PHS.xls - Shortcut.lnk . (.Dad - .) C:\Users\TT\OneDrive\Documents\My Documents\Diabetes Records PHS.xls O4 - GS\Desktop [Guest]: PlanMaker 2016.lnk . (.SoftMaker Software GmbH - PlanMaker.) C:\Program Files (x86)\SoftMaker Office 2016\PlanMaker.exe =>.SoftMaker Software GmbH® O4 - GS\Desktop [Guest]: TextMaker 2016.lnk . (.SoftMaker Software GmbH - TextMaker.) C:\Program Files (x86)\SoftMaker Office 2016\TextMaker.exe =>.SoftMaker Software GmbH® O4 - GS\Desktop [Guest]: ZHPDiag.lnk . (.Nicolas Coolman - ZHPDiag.) C:\Users\TT\AppData\Roaming\ZHP\ZHPDiag3.exe =>.Nicolas Coolman O4 - GS\Quicklaunch [Guest]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc® O4 - GS\Quicklaunch [Guest]: ImgBurn.lnk . (.LIGHTNING UK! - ImgBurn - The Ultimate Image Burner!.) C:\Program Files (x86)\ImgBurn\ImgBurn.exe =>.LIGHTNING UK! O4 - GS\Quicklaunch [Guest]: Mail.Ru.lnk . (.Microsoft Corporation - Windows host process (Rundll32).) C:\Windows\System32\rundll32.exe url,FileProtocolHandler "http://www.mail.ru/ =>.Microsoft Corporation O4 - GS\Quicklaunch [Guest]: Microsoft Outlook.lnk . (.Microsoft Corporation - Microsoft Outlook.) C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE /recycle =>.Microsoft Corporation® O4 - GS\Quicklaunch [Guest]: ThumbsPlus 7.lnk . (.Cerious Software, Inc. - ThumbsPlus 7 SP2.) C:\Program Files (x86)\Thumbs7\Thumbs.exe {5C70051CA1CE9F0CAC0744D1764DEC11} O4 - GS\sendTo [Guest]: Bluetooth File Transfer.LNK . (.Microsoft Corporation - .) C:\Windows\System32\fsquirt.exe =>.Microsoft Corporation O4 - GS\sendTo [Guest]: Fax Recipient.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\Windows\system32\WFS.exe /SendTo =>.Microsoft Corporation O4 - GS\TaskBar [Guest]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc® O4 - GS\TaskBar [Guest]: Mozilla Thunderbird.lnk . (.Mozilla Corporation - Thunderbird.) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe =>.Mozilla Corporation® O4 - GS\TaskBar [Guest]: xplorer2 pro x64.lnk . (.ZabKat - xplorer² - explorer replacement.) C:\Program Files\zabkat\xplorer2\xplorer2_64.exe /M =>.Nikolaos Bozinis® O4 - GS\Startup [Guest]: Sidebar465.lnk . (.Microsoft Corporation - Windows Desktop Gadgets.) C:\Program Files (x86)\Windows Sidebar\sidebar.exe =>.Microsoft Corporation O4 - GS\Programs [Guest]: NCH Suite.lnk . (.NCH Software - PhotoPad Image Editor.) C:\Program Files (x86)\NCH Software\PhotoPad\photopad.exe -extsuite =>.NCH Software® O4 - GS\Programs [Guest]: OneDrive.lnk . (.Microsoft Corporation - Microsoft OneDrive.) C:\Users\TT\AppData\Local\Microsoft\OneDrive\OneDrive.exe =>.Microsoft Corporation® O4 - GS\CommonDesktop [Public]: Adobe Creative Cloud.lnk . (.Adobe Systems Incorporated - Adobe Creative Cloud.) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe =>.Adobe Systems Incorporated® O4 - GS\CommonDesktop [Public]: Adobe Photoshop Elements 13.lnk . (.Adobe Systems Incorporated - Adobe Photoshop Elements 13.) C:\Program Files\Adobe\Elements 13 Organizer\Photoshop Elements 13.0.exe =>.Adobe Systems Incorporated® O4 - GS\CommonDesktop [Public]: D-Fend Reloaded.lnk . (.Alexander Herzog - D-Fend Reloaded.) C:\Program Files (x86)\D-Fend Reloaded\DFend.exe O4 - GS\CommonDesktop [Public]: GeForce Experience.lnk . (.NVIDIA Corporation - NVIDIA GeForce Experience.) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe =>.NVIDIA Corporation® O4 - GS\CommonDesktop [Public]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc® O4 - GS\CommonDesktop [Public]: HP OfficeJet 4650 series.lnk . (.Hewlett-Packard Development Company, LP - .) C:\Program Files (x86)\HP\HP OfficeJet 4650 series\Bin\HP OfficeJet 4650 series.exe -Start UDCDevicePage =>.Hewlett-Packard Development Company, LP O4 - GS\CommonDesktop [Public]: HP Photo Creations.lnk . (.Visan / RocketLife - PhotoProduct.exe.) C:\Program Files (x86)\HP Photo Creations\PhotoProduct.exe =>.Visan Industries® O4 - GS\CommonDesktop [Public]: ImgBurn.lnk . (.LIGHTNING UK! - ImgBurn - The Ultimate Image Burner!.) C:\Program Files (x86)\ImgBurn\ImgBurn.exe =>.LIGHTNING UK! O4 - GS\CommonDesktop [Public]: Launch TS12.lnk . (...) C:\Program Files (x86)\N3V Games\TS12\Trainz.exe O4 - GS\CommonDesktop [Public]: Malwarebytes.lnk . (.Malwarebytes - Malwarebytes.) C:\Program Files\Malwarebytes\Anti-Malware\mbam.exe =>.Malwarebytes Corporation® O4 - GS\CommonDesktop [Public]: Mozilla Thunderbird.lnk . (.Mozilla Corporation - Thunderbird.) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe =>.Mozilla Corporation® O4 - GS\CommonDesktop [Public]: MS Word To EPUB Converter Software.lnk . (.Organization - .) C:\Program Files (x86)\MS Word To EPUB Converter Software\MS Word To EPUB Converter Software.exe O4 - GS\CommonDesktop [Public]: NaturalReader 14.lnk . (.Naturalsoft - .) C:\Program Files (x86)\naturalsoft\NR14\NR14.exe =>.NaturalSoft O4 - GS\CommonDesktop [Public]: NCH Suite.lnk . (.NCH Software - PhotoPad Image Editor.) C:\Program Files (x86)\NCH Software\PhotoPad\photopad.exe -suite =>.NCH Software® O4 - GS\CommonDesktop [Public]: Origin.lnk . (.Electronic Arts - Origin.) C:\Program Files (x86)\Origin\Origin.exe =>.Electronic Arts, Inc.® O4 - GS\CommonDesktop [Public]: PhotoPad Image Editor.lnk . (.NCH Software - PhotoPad Image Editor.) C:\Program Files (x86)\NCH Software\PhotoPad\photopad.exe =>.NCH Software® O4 - GS\CommonDesktop [Public]: Shop for Supplies - HP OfficeJet 4650 series.lnk . (.Hewlett-Packard Development Company, LP - .) C:\Program Files (x86)\HP\HP OfficeJet 4650 series\Bin\hpqDTSS.exe =>.Hewlett-Packard Development Company, LP O4 - GS\CommonDesktop [Public]: Steam.lnk . (.Valve Corporation - Steam Client Bootstrapper.) C:\Program Files (x86)\Steam\Steam.exe =>.Valve® O4 - GS\CommonDesktop [Public]: ThumbsPlus 10.lnk . (.Cerious Software Inc. - ThumbsPlus.) C:\Program Files (x86)\ThumbsPlus 10\Bin\Thumbs10.exe {4B03917FA9D9B450EF91D6B2E888A53B} =>.Cerious Software Inc. O4 - GS\CommonDesktop [Public]: Virtual CloneDrive.lnk . (.Elaborate Bytes AG - VirtualCloneDrive Preferences.) C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDPrefs.exe =>.Elaborate Bytes AG O4 - GS\CommonDesktop [Public]: VLC media player.lnk . (.VideoLAN - VLC media player.) C:\Program Files (x86)\VideoLAN\VLC\vlc.exe =>.VideoLAN® O4 - GS\CommonDesktop [Public]: xplorer2 pro x64.lnk . (.ZabKat - xplorer² - explorer replacement.) C:\Program Files\zabkat\xplorer2\xplorer2_64.exe /M =>.Nikolaos Bozinis® O4 - GS\Programs [Public]: NCH Suite.lnk . (.NCH Software - PhotoPad Image Editor.) C:\Program Files (x86)\NCH Software\PhotoPad\photopad.exe -extsuite =>.NCH Software® O4 - GS\Programs [Public]: OneDrive.lnk . (.Microsoft Corporation - Microsoft OneDrive.) C:\Users\TT\AppData\Local\Microsoft\OneDrive\OneDrive.exe =>.Microsoft Corporation® O4 - GS\Accessories [Public]: Internet Explorer.lnk . (.Microsoft Corporation - Internet Explorer.) C:\Program Files (x86)\Internet Explorer\iexplore.exe =>.Microsoft Corporation® O4 - GS\Accessories [Public]: Notepad.lnk . (.Microsoft Corporation - Notepad.) C:\Windows\system32\notepad.exe =>.Microsoft Corporation O4 - GS\Accessories [Public]: Math Input Panel.lnk . (.Microsoft Corporation - .) C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\mip.exe =>.Microsoft Corporation O4 - GS\Accessories [Public]: Paint.lnk . (.Microsoft Corporation - Paint.) C:\Windows\system32\mspaint.exe =>.Microsoft Corporation O4 - GS\Accessories [Public]: Quick Assist.lnk . (.Microsoft Corporation - Quick Assist.) C:\Windows\system32\quickassist.exe =>.Microsoft Corporation O4 - GS\Accessories [Public]: Remote Desktop Connection.lnk . (.Microsoft Corporation - Remote Desktop Connection.) C:\Windows\system32\mstsc.exe =>.Microsoft Corporation O4 - GS\Accessories [Public]: Snipping Tool.lnk . (.Microsoft Corporation - Snipping Tool.) C:\Windows\system32\SnippingTool.exe =>.Microsoft Corporation O4 - GS\Accessories [Public]: Steps Recorder.lnk . (.Microsoft Corporation - Steps Recorder.) C:\Windows\system32\psr.exe =>.Microsoft Corporation O4 - GS\Accessories [Public]: Windows Fax and Scan.lnk . (.Microsoft Corporation - Microsoft Windows Fax and Scan.) C:\Windows\system32\WFS.exe =>.Microsoft Corporation O4 - GS\Accessories [Public]: Windows Media Player.lnk . (.Microsoft Corporation - Windows Media Player.) C:\Program Files (x86)\Windows Media Player\wmplayer.exe /prefetch:1 =>.Microsoft Corporation O4 - GS\Accessories [Public]: Wordpad.lnk . (.Microsoft Corporation - Windows Wordpad Application.) C:\Program Files (x86)\Windows NT\Accessories\wordpad.exe =>.Microsoft Corporation O4 - GS\Accessories [Public]: XPS Viewer.lnk . (.Microsoft Corporation - XPS Viewer.) C:\Windows\system32\xpsrchvw.exe =>.Microsoft Corporation O4 - GS\SystemTools [Public]: Character Map.lnk . (.Microsoft Corporation - Character Map.) C:\Windows\system32\charmap.exe =>.Microsoft Corporation O4 - GS\ProgramsCommon [Public]: Access 2016.lnk . (.Microsoft Corporation - Microsoft Access.) C:\Program Files (x86)\Microsoft Office\root\Office16\MSACCESS.EXE =>.Microsoft Corporation® O4 - GS\ProgramsCommon [Public]: Adobe Creative Cloud.lnk . (.Adobe Systems Incorporated - Adobe Creative Cloud.) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe =>.Adobe Systems Incorporated® O4 - GS\ProgramsCommon [Public]: Adobe Photoshop Elements 13.lnk . (.Adobe Systems Incorporated - Adobe Photoshop Elements 13.) C:\Program Files\Adobe\Elements 13 Organizer\Photoshop Elements 13.0.exe =>.Adobe Systems Incorporated® O4 - GS\ProgramsCommon [Public]: Excel 2016.lnk . (.Microsoft Corporation - Microsoft Excel.) C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE =>.Microsoft Corporation® O4 - GS\ProgramsCommon [Public]: Google Chrome.lnk . (.Google Inc. - Google Chrome.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc® O4 - GS\ProgramsCommon [Public]: I.R.I.S. OCR Registration.lnk . (.I.R.I.S. Image Recognition Integrated Systems - Registration Wizard.) C:\Program Files (x86)\HP\IrisOCR_12.3.6.9\regipe.exe {178E76DEA2BA449382DDB07A73C39D69} O4 - GS\ProgramsCommon [Public]: ImgBurn.lnk . (.LIGHTNING UK! - ImgBurn - The Ultimate Image Burner!.) C:\Program Files (x86)\ImgBurn\ImgBurn.exe =>.LIGHTNING UK! O4 - GS\ProgramsCommon [Public]: Immersive Control Panel.lnk . (.Microsoft Corporation - Windows Control Panel.) C:\Windows\System32\Control.exe =>.Microsoft Corporation O4 - GS\ProgramsCommon [Public]: MiracastView.lnk . (.Microsoft Corporation - MiracastView.) C:\Windows\MiracastView\MiracastView.exe =>.Microsoft Windows® O4 - GS\ProgramsCommon [Public]: Mozilla Thunderbird.lnk . (.Mozilla Corporation - Thunderbird.) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe =>.Mozilla Corporation® O4 - GS\ProgramsCommon [Public]: NCH Suite.lnk . (.NCH Software - PhotoPad Image Editor.) C:\Program Files (x86)\NCH Software\PhotoPad\photopad.exe -extsuite =>.NCH Software® O4 - GS\ProgramsCommon [Public]: OneNote 2016.lnk . (.Microsoft Corporation - Microsoft OneNote.) C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE =>.Microsoft Corporation® O4 - GS\ProgramsCommon [Public]: Outlook 2016.lnk . (.Microsoft Corporation - Microsoft Outlook.) C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE =>.Microsoft Corporation® O4 - GS\ProgramsCommon [Public]: PhotoPad Image Editor.lnk . (.NCH Software - PhotoPad Image Editor.) C:\Program Files (x86)\NCH Software\PhotoPad\photopad.exe =>.NCH Software® O4 - GS\ProgramsCommon [Public]: PowerPoint 2016.lnk . (.Microsoft Corporation - Microsoft PowerPoint.) C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE =>.Microsoft Corporation® O4 - GS\ProgramsCommon [Public]: PrintDialog.lnk . (.Microsoft Corporation - Print Dialog.) C:\Windows\PrintDialog\PrintDialog.exe =>.Microsoft Windows® O4 - GS\ProgramsCommon [Public]: Publisher 2016.lnk . (.Microsoft Corporation - Microsoft Publisher.) C:\Program Files (x86)\Microsoft Office\root\Office16\MSPUB.EXE =>.Microsoft Corporation® O4 - GS\ProgramsCommon [Public]: Windows Media Player.lnk . (.Microsoft Corporation - Windows Media Player.) C:\Program Files (x86)\Windows Media Player\wmplayer.exe /prefetch:1 =>.Microsoft Corporation O4 - GS\ProgramsCommon [Public]: Word 2016.lnk . (.Microsoft Corporation - Microsoft Word.) C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE =>.Microsoft Corporation® ---\\ Lop.com/Domain Hijackers (4) - 0s O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 =>.Local IP Adress O17 - HKLM\System\CCS\Services\Tcpip\..\{2ea7977b-8d4a-4f2e-83af-4dce0c4ac128}: DhcpNameServer = 127.0.0.1 O17 - HKLM\System\CCS\Services\Tcpip\..\{583d061d-5760-47e3-af09-0c731c4dd803}: DhcpNameServer = 192.168.1.1 =>.Local IP Adress O17 - HKLM\System\CCS\Services\Tcpip\..\{a341fb9e-f316-4b36-ba27-825fcc57037c}: DhcpNameServer = 192.168.1.1 =>.Local IP Adress ---\\ Extra protocols (26) - 0s O18 - Handler: about [64Bits] - {3050F406-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\Windows\SysWOW64\mshtml.dll =>.Microsoft Corporation O18 - Handler: cdl [64Bits] - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation O18 - Handler: dvd [64Bits] - {12D51199-0DB5-46FE-A120-47A3D7D937CC} . (.Microsoft Corporation - ActiveX control for streaming video.) -- C:\Windows\SysWOW64\MSVidCtl.dll =>.Microsoft Corporation O18 - Handler: file [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation O18 - Handler: ftp [64Bits] - {79eac9e3-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation O18 - Handler: http [64Bits] - {79eac9e2-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation O18 - Handler: https [64Bits] - {79eac9e5-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation O18 - Handler: its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\SysWOW64\itss.dll =>.Microsoft Corporation O18 - Handler: javascript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\Windows\SysWOW64\mshtml.dll =>.Microsoft Corporation O18 - Handler: local [64Bits] - {79eac9e7-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation O18 - Handler: mailto [64Bits] - {3050f3DA-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\Windows\SysWOW64\mshtml.dll =>.Microsoft Corporation O18 - Handler: mhtml [64Bits] - {05300401-BCBC-11d0-85E3-00C04FD85AB4} . (.Microsoft Corporation - Microsoft Internet Messaging API Resources.) -- C:\Windows\SysWOW64\inetcomm.dll =>.Microsoft Corporation O18 - Handler: mk [64Bits] - {79eac9e6-baf9-11ce-8c82-00aa004ba90b} . (.Microsoft Corporation - OLE32 Extensions for Win32.) -- C:\Windows\SysWOW64\urlmon.dll =>.Microsoft Corporation O18 - Handler: ms-its [64Bits] - {9D148291-B9C8-11D0-A4CC-0000F80149F6} . (.Microsoft Corporation - Microsoft® InfoTech Storage System Library.) -- C:\Windows\SysWOW64\itss.dll =>.Microsoft Corporation O18 - Handler: mso-minsb-roaming.16 [64Bits] - {83C25742-A9F7-49FB-9138-434302C88D07} . (.Microsoft Corporation - Microsoft Office 2016 component.) -- C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL =>.Microsoft Corporation® O18 - Handler: mso-minsb.16 [64Bits] - {42089D2D-912D-4018-9087-2B87803E93FB} . (.Microsoft Corporation - Microsoft Office 2016 component.) -- C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL =>.Microsoft Corporation® O18 - Handler: osf-roaming.16 [64Bits] - {42089D2D-912D-4018-9087-2B87803E93FB} . (.Microsoft Corporation - Microsoft Office 2016 component.) -- C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL =>.Microsoft Corporation® O18 - Handler: osf.16 [64Bits] - {5504BE45-A83B-4808-900A-3A5C36E7F77A} . (.Microsoft Corporation - Microsoft Office 2016 component.) -- C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL =>.Microsoft Corporation® O18 - Handler: res [64Bits] - {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\Windows\SysWOW64\mshtml.dll =>.Microsoft Corporation O18 - Handler: tbauth [64Bits] - {14654CA6-5711-491D-B89A-58E571679951} . (.Microsoft Corporation - TBAuth protocol handler.) -- C:\Windows\SysWOW64\tbauth.dll =>.Microsoft Corporation O18 - Handler: tv [64Bits] - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} . (.Microsoft Corporation - ActiveX control for streaming video.) -- C:\Windows\SysWOW64\MSVidCtl.dll =>.Microsoft Corporation O18 - Handler: vbscript [64Bits] - {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} . (.Microsoft Corporation - Microsoft (R) HTML Viewer.) -- C:\Windows\SysWOW64\mshtml.dll =>.Microsoft Corporation O18 - Handler: windows.tbauth [64Bits] - {14654CA6-5711-491D-B89A-58E571679951} . (.Microsoft Corporation - TBAuth protocol handler.) -- C:\Windows\SysWOW64\tbauth.dll =>.Microsoft Corporation O18 - Filter: application/octet-stream [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\SysWOW64\mscoree.dll =>.Microsoft Corporation O18 - Filter: application/x-complus [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\SysWOW64\mscoree.dll =>.Microsoft Corporation O18 - Filter: application/x-msdownload [64Bits] - {1E66F26B-79EE-11D2-8710-00C04F79ED0D} . (.Microsoft Corporation - Microsoft .NET Runtime Execution Engine.) -- C:\Windows\SysWOW64\mscoree.dll =>.Microsoft Corporation ---\\ Software installed (123) - 12s O42 - Logiciel: 8GadgetPack - (.8GadgetPack.net.) [HKLM][64Bits] -- {35C86AEB-A4C6-49E3-90B7-245F2C7FDEC7} O42 - Logiciel: Adobe Creative Cloud - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- Adobe Creative Cloud =>.Adobe Systems Incorporated® O42 - Logiciel: Adobe Photoshop Elements 13 - (.Adobe Systems Incorporated.) [HKLM][64Bits] -- {609818B9-23EB-4196-B466-EFE05E92A32F} =>.Adobe Systems Incorporated® O42 - Logiciel: AGEIA PhysX v7.07.09 - (.AGEIA Technologies, Inc..) [HKLM][64Bits] -- {65F1CF63-31E0-450B-96F3-4A88BE7361A6} =>.AGEIA Technologies, Inc. O42 - Logiciel: Ansel - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Ansel =>.NVIDIA Corporation O42 - Logiciel: Assassin's Creed - (.Ubisoft.) [HKLM][64Bits] -- {8CFA9151-6404-409A-AF22-4632D04582FD} =>.UBISOFT ENTERTAINMENT INC.® O42 - Logiciel: Call of Duty - (..) [HKLM][64Bits] -- Call of Duty O42 - Logiciel: Call of Duty(R) - World at War(TM) - (.Activision.) [HKLM][64Bits] -- {D80A6A73-E58A-4673-AFF5-F12D7110661F} =>.Activision O42 - Logiciel: Call of Duty(R) - World at War(TM) - (.Activision.) [HKLM][64Bits] -- InstallShield_{D80A6A73-E58A-4673-AFF5-F12D7110661F} =>.Activision O42 - Logiciel: Call of Duty(R) - World at War(TM) 1.1 Patch - (..) [HKLM][64Bits] -- InstallShield_{AFAE2B15-89A0-4215-A030-F7B5B478886B} O42 - Logiciel: Call of Duty(R) - World at War(TM) 1.1 Patch - (.Activision.) [HKLM][64Bits] -- {AFAE2B15-89A0-4215-A030-F7B5B478886B} =>.Activision O42 - Logiciel: Call of Duty(R) - World at War(TM) 1.2 Patch - (..) [HKLM][64Bits] -- InstallShield_{2BF0AE92-C3BC-4112-9066-1546342B1FAE} O42 - Logiciel: Call of Duty(R) - World at War(TM) 1.2 Patch - (.Activision.) [HKLM][64Bits] -- {2BF0AE92-C3BC-4112-9066-1546342B1FAE} =>.Activision O42 - Logiciel: Call of Duty(R) - World at War(TM) 1.4 Patch - (..) [HKLM][64Bits] -- InstallShield_{9F01A67B-7D67-482F-9D4F-D5980A440FD4} O42 - Logiciel: Call of Duty(R) - World at War(TM) 1.4 Patch - (.Activision.) [HKLM][64Bits] -- {9F01A67B-7D67-482F-9D4F-D5980A440FD4} =>.Activision O42 - Logiciel: Call of Duty(R) - World at War(TM) 1.5 Patch - (..) [HKLM][64Bits] -- InstallShield_{C3DC2DF5-EFAC-4055-9010-31F7C545DD9E} O42 - Logiciel: Call of Duty(R) - World at War(TM) 1.5 Patch - (.Activision.) [HKLM][64Bits] -- {C3DC2DF5-EFAC-4055-9010-31F7C545DD9E} =>.Activision O42 - Logiciel: Call of Duty(R) - World at War(TM) 1.6 Patch - (..) [HKLM][64Bits] -- InstallShield_{064DC64E-7A2F-4FDF-B598-E3C0747BBB9C} O42 - Logiciel: Call of Duty(R) - World at War(TM) 1.6 Patch - (.Activision.) [HKLM][64Bits] -- {064DC64E-7A2F-4FDF-B598-E3C0747BBB9C} =>.Activision O42 - Logiciel: Call of Duty(R) - World at War(TM) 1.7 Patch - (..) [HKLM][64Bits] -- InstallShield_{750C87B8-AF19-4C3C-B791-50D9C83AE572} O42 - Logiciel: Call of Duty(R) - World at War(TM) 1.7 Patch - (.Activision.) [HKLM][64Bits] -- {750C87B8-AF19-4C3C-B791-50D9C83AE572} =>.Activision O42 - Logiciel: Call of Duty(R) 2 - (.Activision.) [HKLM][64Bits] -- {D0A05794-48C2-4424-A15A-9F20FCFDD374} =>.Activision O42 - Logiciel: Call of Duty(R) 2 - (.Activision.) [HKLM][64Bits] -- InstallShield_{D0A05794-48C2-4424-A15A-9F20FCFDD374} =>.Activision O42 - Logiciel: Call of Duty: Black Ops - (.Treyarch.) [HKLM][64Bits] -- Steam App 42700 =>.Valve® O42 - Logiciel: Call of Duty: Black Ops - Multiplayer - (.Treyarch.) [HKLM][64Bits] -- Steam App 42710 =>.Valve® O42 - Logiciel: Call of Duty: Modern Warfare 2 - (.Infinity Ward.) [HKLM][64Bits] -- Steam App 10180 =>.Valve® O42 - Logiciel: Call of Duty: Modern Warfare 2 - Multiplayer - (.Infinity Ward.) [HKLM][64Bits] -- Steam App 10190 =>.Valve® O42 - Logiciel: D-Fend Reloaded 1.4.4 (deinstall) - (.Alexander Herzog.) [HKLM][64Bits] -- D-Fend Reloaded O42 - Logiciel: EA.com Update - (..) [HKLM][64Bits] -- {9AB97F52-512B-43EF-AAEC-4825C17B32ED} O42 - Logiciel: Everything 1.3.4.686 (x86) - (.Voidtools.) [HKLM][64Bits] -- Everything =>.Voidtools O42 - Logiciel: FBReader for Windows - (.FBReader.) [HKLM][64Bits] -- FBReader for Windows O42 - Logiciel: Google Chrome - (.Google Inc..) [HKLM][64Bits] -- Google Chrome =>.Google Inc® O42 - Logiciel: Google Update Helper - (.Google Inc..) [HKLM][64Bits] -- {60EC980A-BDA2-4CB6-A427-B07A5498B4CA} =>.Google Inc. O42 - Logiciel: Heather - (.Naturalsoft.) [HKLM][64Bits] -- {F3715E9A-9C16-423F-9E50-39DE0F7A5BF1} =>.NaturalSoft O42 - Logiciel: HP Dropbox Plugin - (.Hewlett-Packard Co..) [HKLM][64Bits] -- {23617173-F935-4C17-A323-EB1207F3ED49} =>.Hewlett-Packard Co. O42 - Logiciel: HP Google Drive Plugin - (.Hewlett-Packard Co..) [HKLM][64Bits] -- {AFF80405-E56A-48E7-98FC-8E46E261949F} =>.Hewlett-Packard Co. O42 - Logiciel: HP OfficeJet 4650 series Basic Device Software - (.Hewlett-Packard Co..) [HKLM][64Bits] -- {AD2313B9-714F-496E-AD7F-20532E833EB2} =>.Hewlett-Packard Co. O42 - Logiciel: HP OfficeJet 4650 series Help - (.Hewlett Packard.) [HKLM][64Bits] -- {20CA428A-0827-4441-BC64-5C577EA970AD} =>.Hewlett Packard O42 - Logiciel: HP Photo Creations - (.HP.) [HKLM][64Bits] -- HP Photo Creations =>.Visan Industries® O42 - Logiciel: HP Update - (.Hewlett-Packard.) [HKLM][64Bits] -- {912D30CF-F39E-4B31-AD9A-123C6B794EE2} =>.Hewlett-Packard O42 - Logiciel: I.R.I.S. OCR - (.HP.) [HKLM][64Bits] -- {C60E2D8F-0FC0-497D-A149-90F3B361937C} =>.HP O42 - Logiciel: ImgBurn - (.LIGHTNING UK!.) [HKLM][64Bits] -- ImgBurn =>.LIGHTNING UK! O42 - Logiciel: Java 8 Update 121 - (.Oracle Corporation.) [HKLM][64Bits] -- {26A24AE4-039D-4CA4-87B4-2F32180121F0} =>.Oracle Corporation O42 - Logiciel: Java Auto Updater - (.Oracle Corporation.) [HKLM][64Bits] -- {4A03706F-666A-4037-7777-5F2748764D10} =>.Oracle Corporation O42 - Logiciel: katevoice - (.CanadaC Software.) [HKLM][64Bits] -- {AF3065C7-038D-4FF7-8B78-47AC123B52C2} O42 - Logiciel: Malwarebytes version 3.0.6.1469 - (.Malwarebytes.) [HKLM][64Bits] -- {35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1 =>.Malwarebytes Corporation® O42 - Logiciel: Medal of Honor - Allied Assault War Chest - (.GOG.com.) [HKLM][64Bits] -- GOGPACKMEDALOFHONORPACK_is1 =>.GOG Limited® O42 - Logiciel: Medal of Honor Airborne - (.Electronic Arts.) [HKLM][64Bits] -- {25F28E39-FDBB-11DB-8314-0800200C9A66} =>.Electronic Arts O42 - Logiciel: Medal of Honor Pacific Assault(tm) Patch2 - (.Electronic Arts.) [HKLM][64Bits] -- {824539D7-D27E-4CC3-B36F-6404B5EB726B} =>.Electronic Arts O42 - Logiciel: Medal of Honor: Pacific Assault™ - (.Electronic Arts.) [HKLM][64Bits] -- {56CFA833-F44F-4199-8C58-7F8B38F2BC7B} =>.Electronic Arts, Inc.® O42 - Logiciel: Microsoft OneDrive - (.Microsoft Corporation.) [HKCU][64Bits] -- OneDriveSetup.exe =>.Microsoft Corporation® O42 - Logiciel: Mozilla Maintenance Service - (.Mozilla.) [HKLM][64Bits] -- MozillaMaintenanceService =>.Mozilla O42 - Logiciel: Mozilla Thunderbird 45.7.1 (x86 en-US) - (.Mozilla.) [HKLM][64Bits] -- Mozilla Thunderbird 45.7.1 (x86 en-US) =>.Mozilla Corporation® O42 - Logiciel: MS Word To EPUB Converter Software - (.Sobolsoft.) [HKLM][64Bits] -- MS Word To EPUB Converter Software_is1 =>.Sobolsoft O42 - Logiciel: MSI Afterburner 4.3.0 - (.MSI Co., LTD.) [HKLM][64Bits] -- Afterburner =>.MSI Co., LTD O42 - Logiciel: Natural Voice Crystal16 - (.NaturalReaders.com.) [HKLM][64Bits] -- {5B1C8D6A-0968-45BA-8D22-F002A94EC278} O42 - Logiciel: Natural Voice Mike16 - (.Natural voices reader.) [HKLM][64Bits] -- {BA733C73-C917-4BEA-8285-1F6F077671FA} O42 - Logiciel: NaturalReader 14 - (.Naturalsoft.) [HKLM][64Bits] -- {9BB1F2B5-0A9D-402B-9613-DC5BCF878C22} =>.NaturalSoft O42 - Logiciel: NaturalReader 14 Free - (.Naturalsoft.) [HKLM][64Bits] -- {773ED0E5-538E-4E86-8E00-719630613290} =>.NaturalSoft O42 - Logiciel: NaturalReader10 - (.NaturalSoft.) [HKLM][64Bits] -- {A97657A7-A685-4EC4-AB91-534819E88EF9} =>.NaturalSoft O42 - Logiciel: NVIDIA 3D Vision Controller Driver 369.04 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB =>.NVIDIA Corporation O42 - Logiciel: NVIDIA 3D Vision Driver 378.49 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision =>.NVIDIA Corporation O42 - Logiciel: NVIDIA Backend - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvBackend =>.NVIDIA Corporation O42 - Logiciel: NVIDIA Container - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer =>.NVIDIA Corporation O42 - Logiciel: NVIDIA Control Panel 378.49 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel =>.NVIDIA Corporation O42 - Logiciel: NVIDIA Display Container - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVDisplayContainer =>.NVIDIA Corporation O42 - Logiciel: NVIDIA Display Container LS - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVDisplayContainerLS =>.NVIDIA Corporation O42 - Logiciel: NVIDIA Elevated User Container - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.UserElevated =>.NVIDIA Corporation O42 - Logiciel: NVIDIA GeForce Experience 3.3.0.95 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience =>.NVIDIA Corporation O42 - Logiciel: NVIDIA Graphics Driver 378.49 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver =>.NVIDIA Corporation O42 - Logiciel: NVIDIA HD Audio Driver 1.3.34.21 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver =>.NVIDIA Corporation O42 - Logiciel: NVIDIA Install Application - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer =>.NVIDIA Corporation O42 - Logiciel: NVIDIA LocalSystem Container - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.LocalSystem =>.NVIDIA Corporation O42 - Logiciel: NVIDIA Message Bus for NvContainer - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.MessageBus =>.NVIDIA Corporation O42 - Logiciel: NVIDIA NetworkService Container - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.NetworkService =>.NVIDIA Corporation O42 - Logiciel: NVIDIA Optimus Update 23.23.0.0 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Optimus =>.NVIDIA Corporation O42 - Logiciel: NVIDIA PhysX System Software 9.16.0318 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX =>.NVIDIA Corporation O42 - Logiciel: NVIDIA Session Container - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.Session =>.NVIDIA Corporation O42 - Logiciel: NVIDIA ShadowPlay 3.3.0.95 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_ShadowPlay =>.NVIDIA Corporation O42 - Logiciel: Nvidia Share - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_OSC =>.NVIDIA Corporation O42 - Logiciel: NVIDIA Stereoscopic 3D Driver - (.NVIDIA Corporation.) [HKLM][64Bits] -- NVIDIAStereo =>.NVIDIA Corporation® O42 - Logiciel: NVIDIA Telemetry Container - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvTelemetryContainer =>.NVIDIA Corporation O42 - Logiciel: NVIDIA Update 23.23.0.0 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update =>.NVIDIA Corporation O42 - Logiciel: NVIDIA Update Core - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Update.Core =>.NVIDIA Corporation O42 - Logiciel: NVIDIA User Container - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.User =>.NVIDIA Corporation O42 - Logiciel: NVIDIA Virtual Audio 3.51.2 - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_VirtualAudio.Driver =>.NVIDIA Corporation O42 - Logiciel: NVIDIA Watchdog Plugin for NvContainer - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvPlugin.Watchdog =>.NVIDIA Corporation O42 - Logiciel: NVIDIA Wireless Controller Service - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GfExperienceService =>.NVIDIA Corporation O42 - Logiciel: NvNodejs - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvNodejs =>.NVIDIA Corporation O42 - Logiciel: NvTelemetry - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvTelemetry =>.NVIDIA Corporation O42 - Logiciel: NvvHci - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvvHci =>.NVIDIA Corporation O42 - Logiciel: Office 16 Click-to-Run Extensibility Component - (.Microsoft Corporation.) [HKLM][64Bits] -- {90160000-008C-0000-0000-0000000FF1CE} =>.Microsoft Corporation O42 - Logiciel: Office 16 Click-to-Run Extensibility Component 64-bit Registration - (.Microsoft Corporation.) [HKLM][64Bits] -- {90160000-00DD-0000-1000-0000000FF1CE} =>.Microsoft Corporation O42 - Logiciel: Office 16 Click-to-Run Licensing Component - (.Microsoft Corporation.) [HKLM][64Bits] -- {90160000-008F-0000-1000-0000000FF1CE} =>.Microsoft Corporation O42 - Logiciel: Office 16 Click-to-Run Localization Component - (.Microsoft Corporation.) [HKLM][64Bits] -- {90160000-008C-0407-0000-0000000FF1CE} =>.Microsoft Corporation O42 - Logiciel: Office 16 Click-to-Run Localization Component - (.Microsoft Corporation.) [HKLM][64Bits] -- {90160000-008C-040B-0000-0000000FF1CE} =>.Microsoft Corporation O42 - Logiciel: Office 16 Click-to-Run Localization Component - (.Microsoft Corporation.) [HKLM][64Bits] -- {90160000-008C-0414-0000-0000000FF1CE} =>.Microsoft Corporation O42 - Logiciel: Office 16 Click-to-Run Localization Component - (.Microsoft Corporation.) [HKLM][64Bits] -- {90160000-008C-0C0A-0000-0000000FF1CE} =>.Microsoft Corporation O42 - Logiciel: Origin - (.Electronic Arts, Inc..) [HKLM][64Bits] -- Origin =>.Electronic Arts, Inc.® O42 - Logiciel: PaulVoice - (.CanadaC Software.) [HKLM][64Bits] -- {A191501B-6BC4-426F-8FB9-CFCE4CE45B23} O42 - Logiciel: PhotoPad Image Editor - (.NCH Software.) [HKLM][64Bits] -- PhotoPad =>.NCH Software® O42 - Logiciel: Product Improvement Study for HP OfficeJet 4650 series - (.Hewlett-Packard Co..) [HKLM][64Bits] -- {75534DD0-9FB9-410A-AD7B-0E4470F0558D} =>.Hewlett-Packard Co. O42 - Logiciel: PunkBuster - (.Even Balance, Inc..) [HKLM][64Bits] -- {EFF1798F-4286-406E-B48D-BF7F6102E644} =>.Even Balance, Inc. O42 - Logiciel: PunkBuster Services - (.Even Balance, Inc..) [HKLM][64Bits] -- PunkBusterSvc =>.Even Balance, Inc.® O42 - Logiciel: RivaTuner Statistics Server 6.5.0 - (.Unwinder.) [HKLM][64Bits] -- RTSS =>.Unwinder O42 - Logiciel: Samsung Data Migration - (.Samsung.) [HKLM][64Bits] -- {3B304604-0BF5-488E-AB95-F2F2E31206F3} =>.Samsung O42 - Logiciel: SHIELD Streaming - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GFExperience.NvStreamSrv =>.NVIDIA Corporation O42 - Logiciel: SHIELD Wireless Controller Driver - (.NVIDIA Corporation.) [HKLM][64Bits] -- {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_ShieldWirelessController =>.NVIDIA Corporation O42 - Logiciel: SoftMaker Office 2016 - (.SoftMaker Software GmbH.) [HKLM][64Bits] -- {8EBB8452-274B-465D-8324-00B0832FBB05} =>.SoftMaker Software GmbH O42 - Logiciel: Steam - (.Valve Corporation.) [HKLM][64Bits] -- Steam =>.Valve® O42 - Logiciel: Sub Command - (.Sonalysts.) [HKLM][64Bits] -- Steam App 2920 =>.Valve® O42 - Logiciel: ThumbsPlus 10 - (.Cerious Software Inc..) [HKLM][64Bits] -- {4E3BEDC4-E3A1-4211-875D-38B6B921ADCF} {4B03917FA9D9B450EF91D6B2E888A53B} =>.Cerious Software Inc. O42 - Logiciel: ThumbsPlus 10 - (.Cerious Software.) [HKLM][64Bits] -- ThumbsPlus 10 {4B03917FA9D9B450EF91D6B2E888A53B} O42 - Logiciel: ThumbsPlus version 7 SP2 - (.Cerious Software, Inc..) [HKLM][64Bits] -- ThumbsPlus7 O42 - Logiciel: Trainz 'Blue Comet' Addon Pack - (.Auran.) [HKLM][64Bits] -- AuranTS2009_DLC0_is1 =>.Auran O42 - Logiciel: Trainz Simulator 12 - (.Auran.) [HKLM][64Bits] -- AuranTS2009_is1 =>.Auran O42 - Logiciel: VirtualCloneDrive - (.Elaborate Bytes.) [HKLM][64Bits] -- VirtualCloneDrive =>.Elaborate Bytes O42 - Logiciel: VLC media player - (.VideoLAN.) [HKLM][64Bits] -- VLC media player =>.VideoLAN O42 - Logiciel: Vulkan Run Time Libraries 1.0.37.0 - (.LunarG, Inc..) [HKLM][64Bits] -- VulkanRT1.0.37.0 =>.LunarG, Inc.® O42 - Logiciel: Web Companion - (.Lavasoft.) [HKLM][64Bits] -- {0d31f3ef-4d7e-42ea-9cdb-b37e85183f4b} {6DE41F889CF84643F324B3D5} =>.Lavasoft O42 - Logiciel: WinRAR 5.40 (64-bit) - (.win.rar GmbH.) [HKLM][64Bits] -- WinRAR archiver =>.win.rar GmbH® O42 - Logiciel: xplorer² professional 64 bit - (.Zabkat.) [HKLM][64Bits] -- xplorer2p64 =>.Zabkat O42 - Logiciel: Zip Motion Block Video codec (Remove Only) - (.DOSBox Team.) [HKLM][64Bits] -- ZMBV =>.DOSBox Team ---\\ HKCU & HKLM Software Keys (108) - 12s HKLM\SOFTWARE\Wow6432Node\8GadgetPack =>.Helmut Buhler HKLM\SOFTWARE\Wow6432Node\activision =>.Activision HKLM\SOFTWARE\Wow6432Node\AGEIA Technologies =>.AGEIA Technologies HKLM\SOFTWARE\Wow6432Node\ATT HKLM\SOFTWARE\Wow6432Node\Auran =>.Auran Games HKLM\SOFTWARE\Wow6432Node\Cerious Software Inc. =>.Cerious Software Inc. HKLM\SOFTWARE\Wow6432Node\ComodoGroup =>.ComodoGroup HKLM\SOFTWARE\Wow6432Node\D-Fend Reloaded HKLM\SOFTWARE\Wow6432Node\Design Science HKLM\SOFTWARE\Wow6432Node\EA Games =>.EA Games HKLM\SOFTWARE\Wow6432Node\EACOM =>.Electronic Arts, Inc. HKLM\SOFTWARE\Wow6432Node\Elaborate Bytes =>.Elaborate Bytes HKLM\SOFTWARE\Wow6432Node\Electronic Arts =>.Electronic Arts HKLM\SOFTWARE\Wow6432Node\Even Balance, Inc. =>.Even Balance, Inc. HKLM\SOFTWARE\Wow6432Node\GOG.com =>.GOG.com HKLM\SOFTWARE\Wow6432Node\Google =>.Google HKLM\SOFTWARE\Wow6432Node\Hewlett-Packard =>.Hewlett-Packard HKLM\SOFTWARE\Wow6432Node\ImgBurn =>.Lightning UK HKLM\SOFTWARE\Wow6432Node\InstallShield =>.InstallShield HKLM\SOFTWARE\Wow6432Node\Intel =>.Intel HKLM\SOFTWARE\Wow6432Node\JavaSoft =>.JavaSoft HKLM\SOFTWARE\Wow6432Node\JreMetrics =>.JreMetrics HKLM\SOFTWARE\Wow6432Node\Khronos =>.Khronos HKLM\SOFTWARE\Wow6432Node\Lavasoft =>.Lavasoft HKLM\SOFTWARE\Wow6432Node\Macromedia =>.Macromedia HKLM\SOFTWARE\Wow6432Node\Mail.Ru =>.Mail.Ru HKLM\SOFTWARE\Wow6432Node\MimarSinan =>.Mimar Sinan HKLM\SOFTWARE\Wow6432Node\Mozilla =>.Mozilla HKLM\SOFTWARE\Wow6432Node\MozillaPlugins =>.MozillaPlugins HKLM\SOFTWARE\Wow6432Node\MSI =>.MSI HKLM\SOFTWARE\Wow6432Node\Naturalreader10 HKLM\SOFTWARE\Wow6432Node\NCH Software =>.NCH Software HKLM\SOFTWARE\Wow6432Node\NVIDIA Corporation =>.nVidia Corporation HKLM\SOFTWARE\Wow6432Node\ODBC =>.DB Connectivity Solutions HKLM\SOFTWARE\Wow6432Node\Origin =>.Electronic Arts, Inc. HKLM\SOFTWARE\Wow6432Node\Origin Games =>.Electronic Arts, Inc. HKLM\SOFTWARE\Wow6432Node\PrivacyKeeper HKLM\SOFTWARE\Wow6432Node\RocketLife =>.RocketLife HKLM\SOFTWARE\Wow6432Node\Samsung =>.Samsung Electronics HKLM\SOFTWARE\Wow6432Node\SoftMaker Software GmbH =>.SoftMaker Software GmbH HKLM\SOFTWARE\Wow6432Node\Ubisoft =>.Ubisoft HKLM\SOFTWARE\Wow6432Node\Uniblue =>.Superfluous.Uniblue HKLM\SOFTWARE\Wow6432Node\Unwinder =>.Unwinder HKLM\SOFTWARE\Wow6432Node\Valve =>.Valve HKLM\SOFTWARE\Wow6432Node\VideoLAN =>.VideoLAN HKLM\SOFTWARE\Wow6432Node\Visan =>.Visan Software HKLM\SOFTWARE\Wow6432Node\Voice =>.Legitimate HKLM\SOFTWARE\Wow6432Node\WinClon4.0 HKLM\SOFTWARE\Wow6432Node\WOW6432Node =>.Microsoft Corporation HKLM\SOFTWARE\Wow6432Node\Even Balance =>.Even Balance Inc HKLM\SOFTWARE\Wow6432Node\RegisteredApplications =>.Microsoft Corporation HKCU\SOFTWARE\2015 =>.Games Software HKCU\SOFTWARE\8GadgetPack =>.Helmut Buhler HKCU\SOFTWARE\Adobe =>.Adobe HKCU\SOFTWARE\AppDataLow =>.Microsoft Corporation HKCU\SOFTWARE\Caphyon =>.Caphyon HKCU\SOFTWARE\Cerious Software Inc. =>.Cerious Software Inc. HKCU\SOFTWARE\Chromium =>.Chromium HKCU\SOFTWARE\ClearScreenPlayer HKCU\SOFTWARE\Clipboarder =>.Helmut Buhler HKCU\SOFTWARE\CoinisRevShare HKCU\SOFTWARE\ComodoGroup =>.ComodoGroup HKCU\SOFTWARE\DownloadAdmin =>PUP.Optional.UpdateAdmin HKCU\SOFTWARE\EA Games =>.EA Games HKCU\SOFTWARE\Elaborate Bytes =>.Elaborate Bytes HKCU\SOFTWARE\Electronic Arts =>.Electronic Arts HKCU\SOFTWARE\FBReader =>.FBReader HKCU\SOFTWARE\GOG.com =>.GOG.com HKCU\SOFTWARE\Google =>.Google HKCU\SOFTWARE\Hewlett-Packard =>.Hewlett-Packard HKCU\SOFTWARE\HP =>.HP HKCU\SOFTWARE\ImgBurn =>.Lightning UK HKCU\SOFTWARE\JavaSoft =>.JavaSoft HKCU\SOFTWARE\JEDI-VCL =>.JEDI Project HKCU\SOFTWARE\LogiShrd =>.LogiShrd HKCU\SOFTWARE\Mail.Ru =>.Mail.Ru HKCU\SOFTWARE\Malwarebytes =>.Malwarebytes HKCU\SOFTWARE\Mozilla =>.Mozilla HKCU\SOFTWARE\MozillaPlugins =>.MozillaPlugins HKCU\SOFTWARE\MSI =>.MSI HKCU\SOFTWARE\NCH Software =>.NCH Software HKCU\SOFTWARE\Netscape =>.Netscape HKCU\SOFTWARE\NVIDIA Corporation =>.nVidia Corporation HKCU\SOFTWARE\ODBC =>.DB Connectivity Solutions HKCU\SOFTWARE\PrivacyKeeperValidity HKCU\SOFTWARE\ProductSetup =>Adware.InstallCore HKCU\SOFTWARE\PSTWalker HKCU\SOFTWARE\RegisteredApplications =>.Microsoft Corporation HKCU\SOFTWARE\SecuROM =>.SecuROM HKCU\SOFTWARE\SoftMaker Software GmbH =>.SoftMaker Software GmbH HKCU\SOFTWARE\Sonalysts Combat Simulations HKCU\SOFTWARE\SyncEngines =>.Microsoft Corporation HKCU\SOFTWARE\Ubisoft =>.Ubisoft HKCU\SOFTWARE\undefined =>.Superfluous.Downloader HKCU\SOFTWARE\Unity =>.Unity HKCU\SOFTWARE\Unwinder =>.Unwinder HKCU\SOFTWARE\Valve =>.Valve HKCU\SOFTWARE\VB and VBA Program Settings =>.Microsoft Corporation HKCU\SOFTWARE\Visan =>.Visan Software HKCU\SOFTWARE\WinRAR =>.WinRAR HKCU\SOFTWARE\WinRAR SFX =>.RarLab HKCU\SOFTWARE\Wow6432Node =>.Microsoft Corporation HKCU\SOFTWARE\Xpom =>.Mail.Ru HKCU\SOFTWARE\ZabaraKatranemia Plc =>.ZabaraKatranemia Plc HKCU\SOFTWARE\ZHP =>.Nicolas Coolman HKCU\SOFTWARE\AppDataLow\Software =>.Microsoft Corporation HKCU\SOFTWARE\AppDataLow\Software\Mail.Ru =>.Mail.Ru HKCU\SOFTWARE\AppDataLow\Software\Unity =>.Unity ---\\ Contents of the Common Files folders (266) - 6s O43 - CFD: 25/02/2017 - [] AD -- C:\Program Files\Adobe =>.Adobe Systems Incorporated® O43 - CFD: 25/02/2017 - [] D -- C:\Program Files\Common Files =>.Microsoft Corporation O43 - CFD: 25/02/2017 - [0] D -- C:\Program Files\COMODO =>.Comodo O43 - CFD: 16/02/2017 - [] D -- C:\Program Files\HP =>.Hewlett-Packard O43 - CFD: 12/02/2017 - [] D -- C:\Program Files\Intel =>.Intel Corporation O43 - CFD: 15/02/2017 - [] D -- C:\Program Files\Internet Explorer =>.Microsoft Corporation O43 - CFD: 25/02/2017 - [] D -- C:\Program Files\Malwarebytes =>.Malwarebytes O43 - CFD: 14/03/2016 - [] D -- C:\Program Files\Microsoft Office 15 =>.Microsoft Corporation O43 - CFD: 12/02/2017 - [] D -- C:\Program Files\MSBuild =>.Microsoft Corporation O43 - CFD: 14/02/2017 - [] D -- C:\Program Files\NVIDIA Corporation =>.nVidia Corporation O43 - CFD: 12/02/2017 - [] D -- C:\Program Files\Reference Assemblies =>.Microsoft Corporation O43 - CFD: 20/11/2016 - [0] HD -- C:\Program Files\Uninstall Information =>.Microsoft Corporation O43 - CFD: 15/02/2017 - [] RD -- C:\Program Files\Windows Defender =>.Microsoft Corporation O43 - CFD: 15/02/2017 - [] D -- C:\Program Files\Windows Defender Advanced Threat Protection =>.Microsoft Corporation O43 - CFD: 20/11/2016 - [] D -- C:\Program Files\Windows Mail =>.Microsoft Corporation O43 - CFD: 15/02/2017 - [] D -- C:\Program Files\Windows Media Player =>.Microsoft Corporation O43 - CFD: 16/07/2016 - [] D -- C:\Program Files\Windows Multimedia Platform =>.Microsoft Corporation O43 - CFD: 16/07/2016 - [] D -- C:\Program Files\Windows NT =>.Microsoft Corporation O43 - CFD: 15/02/2017 - [] D -- C:\Program Files\Windows Photo Viewer =>.Microsoft Corporation O43 - CFD: 16/07/2016 - [] D -- C:\Program Files\Windows Portable Devices =>.Microsoft Corporation O43 - CFD: 12/02/2017 - [] SD -- C:\Program Files\Windows Sidebar =>.Microsoft Corporation O43 - CFD: 25/02/2017 - [] HD -- C:\Program Files\WindowsApps =>.Microsoft Corporation O43 - CFD: 16/07/2016 - [] D -- C:\Program Files\WindowsPowerShell =>.Microsoft Corporation O43 - CFD: 29/12/2016 - [] AD -- C:\Program Files\WinRAR =>.win.rar GmbH® O43 - CFD: 12/02/2017 - [] D -- C:\Program Files\zabkat =>.Zabkat O43 - CFD: 21/02/2017 - [] D -- C:\Program Files (x86)\Activision =>.Activision O43 - CFD: 25/02/2017 - [] D -- C:\Program Files (x86)\Adobe =>.Adobe Systems Incorporated® O43 - CFD: 25/02/2017 - [] AD -- C:\Program Files (x86)\AGEIA Technologies =>.AGEIA Technologies O43 - CFD: 26/02/2017 - [] D -- C:\Program Files (x86)\Call of Duty =>.Games Software O43 - CFD: 25/02/2017 - [] D -- C:\Program Files (x86)\Common Files =>.Microsoft Corporation O43 - CFD: 20/02/2017 - [0] D -- C:\Program Files (x86)\COMODO =>.Comodo O43 - CFD: 20/02/2017 - [] AD -- C:\Program Files (x86)\D-Fend Reloaded O43 - CFD: 23/02/2017 - [] D -- C:\Program Files (x86)\EA GAMES =>.EA Games O43 - CFD: 23/02/2017 - [] D -- C:\Program Files (x86)\EACOM O43 - CFD: 20/02/2017 - [] D -- C:\Program Files (x86)\Elaborate Bytes =>.Elaborate Bytes O43 - CFD: 23/02/2017 - [] D -- C:\Program Files (x86)\Electronic Arts =>.Electronic Arts O43 - CFD: 25/02/2017 - [] D -- C:\Program Files (x86)\Even Balance, Inc =>.Even Balance, Inc.® O43 - CFD: 27/02/2017 - [] D -- C:\Program Files (x86)\Everything =>.Everything O43 - CFD: 12/02/2017 - [] D -- C:\Program Files (x86)\FBReader =>.FBReader O43 - CFD: 29/12/2016 - [] D -- C:\Program Files (x86)\Google =>.Google Inc® O43 - CFD: 16/02/2017 - [] AD -- C:\Program Files (x86)\HP =>.Hewlett-Packard O43 - CFD: 16/02/2017 - [] D -- C:\Program Files (x86)\HP Photo Creations =>.Visan Industries® O43 - CFD: 20/02/2017 - [] AD -- C:\Program Files (x86)\ImgBurn =>.Lightning UK O43 - CFD: 20/02/2017 - [0] D -- C:\Program Files (x86)\InstallPrepared O43 - CFD: 24/02/2017 - [] HD -- C:\Program Files (x86)\InstallShield Installation Information =>.InstallShield Software O43 - CFD: 15/02/2017 - [] AD -- C:\Program Files (x86)\Internet Explorer =>.Microsoft Corporation O43 - CFD: 13/02/2017 - [] D -- C:\Program Files (x86)\Java =>.Oracle O43 - CFD: 20/02/2017 - [] D -- C:\Program Files (x86)\Lavasoft =>.Lavasoft O43 - CFD: 24/02/2017 - [] AD -- C:\Program Files (x86)\Microsoft Office =>.Microsoft Corporation O43 - CFD: 12/02/2017 - [] D -- C:\Program Files (x86)\Microsoft.NET =>.Microsoft Corporation O43 - CFD: 25/02/2017 - [] D -- C:\Program Files (x86)\Mozilla Maintenance Service =>.Mozilla O43 - CFD: 25/02/2017 - [] AD -- C:\Program Files (x86)\Mozilla Thunderbird =>.Mozilla O43 - CFD: 19/02/2017 - [] AD -- C:\Program Files (x86)\MS Word To EPUB Converter Software O43 - CFD: 12/02/2017 - [] D -- C:\Program Files (x86)\MSBuild =>.Microsoft Corporation O43 - CFD: 29/12/2016 - [] D -- C:\Program Files (x86)\MSI Afterburner =>.Micro-Star International Co O43 - CFD: 20/02/2017 - [] D -- C:\Program Files (x86)\N3V Games =>.N3V Games O43 - CFD: 12/02/2017 - [] AD -- C:\Program Files (x86)\Natural Voice Mike16 O43 - CFD: 12/02/2017 - [] AD -- C:\Program Files (x86)\Natural Voice Reader Enterprise O43 - CFD: 14/02/2017 - [] D -- C:\Program Files (x86)\naturalreader O43 - CFD: 20/02/2017 - [] AD -- C:\Program Files (x86)\naturalsoft {7200336E3BA603F96EDBAC55DC19731B} =>.NaturalSoft O43 - CFD: 12/02/2017 - [] D -- C:\Program Files (x86)\NCH Software =>.NCH Software O43 - CFD: 14/02/2017 - [] D -- C:\Program Files (x86)\NVIDIA Corporation =>.nVidia Corporation O43 - CFD: 25/02/2017 - [] AD -- C:\Program Files (x86)\Origin =>.Electronic Arts, Inc. O43 - CFD: 25/02/2017 - [] D -- C:\Program Files (x86)\Origin Games =>.Electronic Arts, Inc. O43 - CFD: 12/02/2017 - [] D -- C:\Program Files (x86)\Reference Assemblies =>.Microsoft Corporation O43 - CFD: 11/02/2017 - [] D -- C:\Program Files (x86)\RivaTuner Statistics Server =>.RivaTuner O43 - CFD: 18/02/2017 - [] D -- C:\Program Files (x86)\Samsung =>.Samsung Electronics O43 - CFD: 25/02/2017 - [] AD -- C:\Program Files (x86)\SoftMaker Office 2016 =>.Microsoft Corporation O43 - CFD: 27/02/2017 - [] D -- C:\Program Files (x86)\Steam =>.Steam Games O43 - CFD: 25/02/2017 - [] D -- C:\Program Files (x86)\Thumbs7 O43 - CFD: 25/02/2017 - [] AD -- C:\Program Files (x86)\ThumbsPlus 10 O43 - CFD: 12/02/2017 - [] D -- C:\Program Files (x86)\TTS1.4 O43 - CFD: 24/02/2017 - [] D -- C:\Program Files (x86)\Ubisoft =>.Ubisoft O43 - CFD: 27/02/2017 - [] D -- C:\Program Files (x86)\VideoLAN =>.VideoLan Team O43 - CFD: 13/02/2017 - [] D -- C:\Program Files (x86)\VulkanRT =>.LunarG, Inc O43 - CFD: 15/02/2017 - [] D -- C:\Program Files (x86)\Windows Defender =>.Microsoft Corporation O43 - CFD: 20/11/2016 - [] D -- C:\Program Files (x86)\Windows Mail =>.Microsoft Corporation O43 - CFD: 15/02/2017 - [] D -- C:\Program Files (x86)\Windows Media Player =>.Microsoft Corporation O43 - CFD: 16/07/2016 - [] D -- C:\Program Files (x86)\Windows Multimedia Platform =>.Microsoft Corporation O43 - CFD: 16/07/2016 - [] D -- C:\Program Files (x86)\Windows NT =>.Microsoft Corporation O43 - CFD: 15/02/2017 - [] D -- C:\Program Files (x86)\Windows Photo Viewer =>.Microsoft Corporation O43 - CFD: 16/07/2016 - [] D -- C:\Program Files (x86)\Windows Portable Devices =>.Microsoft Corporation O43 - CFD: 12/02/2017 - [] ASD -- C:\Program Files (x86)\Windows Sidebar =>.Microsoft Corporation O43 - CFD: 16/07/2016 - [] D -- C:\Program Files (x86)\WindowsPowerShell =>.Microsoft Corporation O43 - CFD: 12/02/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\8GadgetPack =>.8GadgetPack O43 - CFD: 16/07/2016 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility =>.Microsoft Corporation O43 - CFD: 12/02/2017 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories =>.Microsoft Corporation O43 - CFD: 21/02/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Activision =>.Activision O43 - CFD: 20/11/2016 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools =>.Administrative Tools O43 - CFD: 25/02/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AGEIA =>.AGEIA Technilogies O43 - CFD: 20/02/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Auran =>.Auran Games O43 - CFD: 20/02/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\D-Fend Reloaded O43 - CFD: 23/02/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EA Games =>.EA Games O43 - CFD: 20/02/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Elaborate Bytes =>.Elaborate Bytes O43 - CFD: 10/02/2017 - [0] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games =>.Microsoft Corporation O43 - CFD: 16/02/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP =>.Hewlett-Packard O43 - CFD: 20/02/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ImgBurn =>.Lightning UK O43 - CFD: 13/02/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java =>.Oracle O43 - CFD: 20/02/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft =>.Lavasoft O43 - CFD: 16/07/2016 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance =>.Microsoft Corporation O43 - CFD: 25/02/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes =>.Malwarebytes O43 - CFD: 23/02/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Medal of Honor - Allied Assault War Chest [GOG.com] O43 - CFD: 25/02/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Medal of Honor Pacific Assault™ O43 - CFD: 24/02/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2016-Tools =>.Microsoft Corporation O43 - CFD: 19/02/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MS Word To EPUB Converter Software O43 - CFD: 20/02/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\N3V Games =>.N3V Games O43 - CFD: 12/02/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Natural Voice Reader O43 - CFD: 12/02/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\naturalsoft =>.NaturalSoft O43 - CFD: 13/02/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation =>.nVidia Corporation O43 - CFD: 25/02/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Origin =>.Electronic Arts, Inc. O43 - CFD: 18/02/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung =>.Samsung Electronics O43 - CFD: 25/02/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SoftMaker Office 2016 =>.Microsoft Corporation O43 - CFD: 20/02/2017 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp =>.Microsoft Corporation O43 - CFD: 20/02/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam =>.Steam Games O43 - CFD: 16/07/2016 - [] RD -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools =>.Microsoft Corporation O43 - CFD: 25/02/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ThumbsPlus 10 O43 - CFD: 25/02/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ThumbsPlus 7 O43 - CFD: 27/02/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN =>.VideoLan Team O43 - CFD: 12/02/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR =>.WinRAR O43 - CFD: 12/02/2017 - [] D -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\xplorer2 pro x64 O43 - CFD: 25/02/2017 - [] D -- C:\ProgramData\Adobe =>.Adobe O43 - CFD: 12/02/2017 - [0] SHD -- C:\ProgramData\Application Data =>.Microsoft Corporation O43 - CFD: 27/02/2017 - [] D -- C:\ProgramData\boost_interprocess =>.boost.org O43 - CFD: 16/07/2016 - [0] D -- C:\ProgramData\Comms =>.Microsoft Corporation O43 - CFD: 20/02/2017 - [] D -- C:\ProgramData\COMODO =>.Comodo O43 - CFD: 12/02/2017 - [0] SHD -- C:\ProgramData\Desktop =>.Microsoft Corporation O43 - CFD: 12/02/2017 - [0] SHD -- C:\ProgramData\Documents =>.Microsoft Corporation O43 - CFD: 27/01/2017 - [] D -- C:\ProgramData\EA Core =>.Electronic Arts, Inc. O43 - CFD: 27/01/2017 - [] D -- C:\ProgramData\EA Logs =>.Electronic Arts, Inc. O43 - CFD: 25/02/2017 - [] D -- C:\ProgramData\Electronic Arts =>.Electronic Arts O43 - CFD: 16/02/2017 - [] AD -- C:\ProgramData\HP =>.Hewlett-Packard O43 - CFD: 16/02/2017 - [] AD -- C:\ProgramData\HP Photo Creations =>.HP Photo Creations O43 - CFD: 20/02/2017 - [] D -- C:\ProgramData\Lavasoft =>.Lavasoft O43 - CFD: 23/02/2017 - [] D -- C:\ProgramData\Mail.Ru =>.Mail.Ru O43 - CFD: 25/02/2017 - [] D -- C:\ProgramData\Malwarebytes =>.Malwarebytes O43 - CFD: 24/02/2017 - [] SD -- C:\ProgramData\Microsoft =>.Microsoft Corporation O43 - CFD: 20/11/2016 - [] D -- C:\ProgramData\Microsoft OneDrive =>.Microsoft Corporation O43 - CFD: 12/02/2017 - [] D -- C:\ProgramData\NaturalSoft =>.NaturalSoft O43 - CFD: 12/02/2017 - [] D -- C:\ProgramData\NaturalSoft Co. Ltd O43 - CFD: 12/02/2017 - [] D -- C:\ProgramData\NCH Software =>.NCH Software O43 - CFD: 27/02/2017 - [] D -- C:\ProgramData\NVIDIA =>.nVidia Corporation O43 - CFD: 14/02/2017 - [] D -- C:\ProgramData\NVIDIA Corporation =>.nVidia Corporation O43 - CFD: 13/02/2017 - [] D -- C:\ProgramData\Oracle =>.Oracle O43 - CFD: 26/02/2017 - [] D -- C:\ProgramData\Origin =>.Electronic Arts, Inc. O43 - CFD: 25/02/2017 - [] D -- C:\ProgramData\Package Cache =>.Microsoft Corporation O43 - CFD: 11/02/2017 - [] D -- C:\ProgramData\Realtek =>.Realtek O43 - CFD: 25/02/2017 - [] D -- C:\ProgramData\regid.1986-12.com.adobe =>.Adobe Inc. O43 - CFD: 12/02/2017 - [] AD -- C:\ProgramData\regid.1991-06.com.microsoft =>.Microsoft Corporation O43 - CFD: 28/02/2017 - [] D -- C:\ProgramData\SoftMaker =>.SoftMaker O43 - CFD: 16/07/2016 - [0] D -- C:\ProgramData\SoftwareDistribution =>.Microsoft Corporation O43 - CFD: 12/02/2017 - [0] SHD -- C:\ProgramData\Start Menu =>.Microsoft Corporation O43 - CFD: 12/02/2017 - [0] SHD -- C:\ProgramData\Templates =>.Microsoft Corporation O43 - CFD: 27/02/2017 - [] AD -- C:\ProgramData\ThumbsPlus O43 - CFD: 24/02/2017 - [] D -- C:\ProgramData\Ubisoft =>.Ubisoft O43 - CFD: 25/02/2017 - [] D -- C:\ProgramData\Uniblue =>.Superfluous.Uniblue O43 - CFD: 20/11/2016 - [] D -- C:\ProgramData\USOPrivate =>.Microsoft Corporation O43 - CFD: 20/11/2016 - [] D -- C:\ProgramData\USOShared =>.Microsoft Corporation O43 - CFD: 16/02/2017 - [] D -- C:\ProgramData\Visan =>.Visan Industries O43 - CFD: 25/02/2017 - [] HDC -- C:\ProgramData\{92D5D750-AA6D-437A-9732-D540EA9E7693} O43 - CFD: 25/02/2017 - [] D -- C:\Program Files (x86)\Common Files\Adobe =>.Adobe O43 - CFD: 20/02/2017 - [0] D -- C:\Program Files (x86)\Common Files\COMODO =>.Comodo O43 - CFD: 27/01/2017 - [] AD -- C:\Program Files (x86)\Common Files\DESIGNER =>.Designer O43 - CFD: 25/02/2017 - [] HD -- C:\Program Files (x86)\Common Files\EAInstaller =>.Electronic Arts, Inc. O43 - CFD: 23/02/2017 - [] D -- C:\Program Files (x86)\Common Files\InstallShield =>.InstallShield O43 - CFD: 12/02/2017 - [] D -- C:\Program Files (x86)\Common Files\Intel =>.Intel Corporation O43 - CFD: 13/02/2017 - [] D -- C:\Program Files (x86)\Common Files\Java =>.Oracle O43 - CFD: 12/02/2017 - [] AD -- C:\Program Files (x86)\Common Files\Microsoft Shared =>.Microsoft Corporation O43 - CFD: 25/02/2017 - [] D -- C:\Program Files (x86)\Common Files\Nikon =>.Nikon O43 - CFD: 25/02/2017 - [] D -- C:\Program Files (x86)\Common Files\PX Storage Engine =>.Sonic Solutions O43 - CFD: 16/07/2016 - [] D -- C:\Program Files (x86)\Common Files\Services =>.Microsoft Corporation O43 - CFD: 21/02/2017 - [] D -- C:\Program Files (x86)\Common Files\Steam =>.Steam Games O43 - CFD: 15/02/2017 - [] D -- C:\Program Files (x86)\Common Files\System =>.Microsoft Corporation O43 - CFD: 25/02/2017 - [] D -- C:\Program Files (x86)\Common Files\Wise Installation Wizard =>.Seagate O43 - CFD: 12/02/2017 - [] D -- C:\Users\TT\AppData\Roaming\Acapela Group =>.Acapela Group O43 - CFD: 25/02/2017 - [] D -- C:\Users\TT\AppData\Roaming\Adobe =>.Adobe O43 - CFD: 27/02/2017 - [] D -- C:\Users\TT\AppData\Roaming\dvdcss =>.VideoLan Team O43 - CFD: 27/02/2017 - [] D -- C:\Users\TT\AppData\Roaming\Everything =>.Everything O43 - CFD: 23/02/2017 - [] D -- C:\Users\TT\AppData\Roaming\HpUpdate =>.Hewlett-Packard O43 - CFD: 16/02/2017 - [] D -- C:\Users\TT\AppData\Roaming\HP_Easy_Start =>.Hewlett-Packard O43 - CFD: 20/02/2017 - [] D -- C:\Users\TT\AppData\Roaming\ImgBurn =>.Lightning UK O43 - CFD: 24/02/2017 - [] D -- C:\Users\TT\AppData\Roaming\InstallShield =>.InstallShield O43 - CFD: 20/02/2017 - [] D -- C:\Users\TT\AppData\Roaming\Lavasoft =>.Lavasoft O43 - CFD: 11/02/2017 - [] D -- C:\Users\TT\AppData\Roaming\Macromedia =>.Macromedia O43 - CFD: 20/02/2017 - [] SD -- C:\Users\TT\AppData\Roaming\Microsoft =>.Microsoft Corporation O43 - CFD: 20/02/2017 - [] D -- C:\Users\TT\AppData\Roaming\Mozilla =>.Mozilla Corporation O43 - CFD: 12/02/2017 - [] D -- C:\Users\TT\AppData\Roaming\NCH Software =>.NCH Software O43 - CFD: 14/02/2017 - [] D -- C:\Users\TT\AppData\Roaming\NVIDIA =>.nVidia Corporation O43 - CFD: 26/02/2017 - [] D -- C:\Users\TT\AppData\Roaming\Origin =>.Electronic Arts, Inc. O43 - CFD: 25/02/2017 - [] RHD -- C:\Users\TT\AppData\Roaming\SecuROM =>.SecuROM O43 - CFD: 29/12/2016 - [] D -- C:\Users\TT\AppData\Roaming\Skype =>.Skype O43 - CFD: 25/02/2017 - [] D -- C:\Users\TT\AppData\Roaming\SoftMaker =>.SoftMaker O43 - CFD: 13/02/2017 - [] D -- C:\Users\TT\AppData\Roaming\Sun =>.Oracle O43 - CFD: 27/02/2017 - [] D -- C:\Users\TT\AppData\Roaming\ThumbsPlus O43 - CFD: 12/02/2017 - [] D -- C:\Users\TT\AppData\Roaming\Thunderbird =>.Thunderbird O43 - CFD: 24/02/2017 - [] D -- C:\Users\TT\AppData\Roaming\Ubisoft =>.Ubisoft O43 - CFD: 27/02/2017 - [] D -- C:\Users\TT\AppData\Roaming\vlc =>.VideoLan Team O43 - CFD: 29/12/2016 - [] D -- C:\Users\TT\AppData\Roaming\WinRAR =>.WinRAR O43 - CFD: 28/02/2017 - [] D -- C:\Users\TT\AppData\Roaming\ZHP =>.Nicolas Coolman O43 - CFD: 29/12/2016 - [0] D -- C:\Users\TT\AppData\Local\ActiveSync =>.Microsoft Corporation O43 - CFD: 23/02/2017 - [] D -- C:\Users\TT\AppData\Local\Activision =>.Activision O43 - CFD: 28/02/2017 - [] D -- C:\Users\TT\AppData\Local\Adobe =>.Adobe O43 - CFD: 11/02/2017 - [0] SHD -- C:\Users\TT\AppData\Local\Application Data =>.Microsoft Corporation O43 - CFD: 12/02/2017 - [] D -- C:\Users\TT\AppData\Local\Apps =>.Microsoft Corporation O43 - CFD: 12/02/2017 - [] D -- C:\Users\TT\AppData\Local\CEF =>.CEF O43 - CFD: 21/02/2017 - [] D -- C:\Users\TT\AppData\Local\Chromium =>.Chromium O43 - CFD: 29/12/2016 - [] D -- C:\Users\TT\AppData\Local\Comms =>.Microsoft Corporation O43 - CFD: 12/02/2017 - [] D -- C:\Users\TT\AppData\Local\ConnectedDevicesPlatform =>.Microsoft Corporation O43 - CFD: 26/02/2017 - [] D -- C:\Users\TT\AppData\Local\CrashDumps =>.Microsoft Corporation O43 - CFD: 20/02/2017 - [] D -- C:\Users\TT\AppData\Local\CrashRpt =>.Superfluous.CrashReports O43 - CFD: 20/02/2017 - [] D -- C:\Users\TT\AppData\Local\Diagnostics =>.Microsoft Corporation O43 - CFD: 20/02/2017 - [] D -- C:\Users\TT\AppData\Local\Downloaded Installations =>.Microsoft Corporation O43 - CFD: 20/02/2017 - [] D -- C:\Users\TT\AppData\Local\ElevatedDiagnostics =>.Microsoft Corporation O43 - CFD: 07/01/2017 - [] D -- C:\Users\TT\AppData\Local\Google =>.Google O43 - CFD: 11/02/2017 - [0] SHD -- C:\Users\TT\AppData\Local\History =>.Microsoft Corporation O43 - CFD: 16/02/2017 - [] D -- C:\Users\TT\AppData\Local\HP =>.Hewlett-Packard O43 - CFD: 20/02/2017 - [] D -- C:\Users\TT\AppData\Local\Lavasoft =>.Lavasoft O43 - CFD: 23/02/2017 - [] D -- C:\Users\TT\AppData\Local\Mail.Ru =>.Mail.Ru O43 - CFD: 19/02/2017 - [] D -- C:\Users\TT\AppData\Local\Microsoft =>.Microsoft Corporation O43 - CFD: 29/12/2016 - [] D -- C:\Users\TT\AppData\Local\MicrosoftEdge =>.Microsoft Corporation O43 - CFD: 20/02/2017 - [] D -- C:\Users\TT\AppData\Local\NowUSeeItPlayerOsm =>.Superfluous.NowUSeeItPlayer O43 - CFD: 14/02/2017 - [] D -- C:\Users\TT\AppData\Local\NVIDIA =>.nVidia Corporation O43 - CFD: 14/02/2017 - [] D -- C:\Users\TT\AppData\Local\NVIDIA Corporation =>.nVidia Corporation O43 - CFD: 25/02/2017 - [] D -- C:\Users\TT\AppData\Local\Origin =>.Electronic Arts, Inc. O43 - CFD: 25/02/2017 - [0] D -- C:\Users\TT\AppData\Local\PackageAware =>PUP.Optional.BearShare O43 - CFD: 12/02/2017 - [] D -- C:\Users\TT\AppData\Local\Packages =>.Microsoft Corporation O43 - CFD: 07/01/2017 - [0] D -- C:\Users\TT\AppData\Local\PeerDistRepub =>.Microsoft Corporation O43 - CFD: 12/02/2017 - [] D -- C:\Users\TT\AppData\Local\Programs =>.Microsoft Corporation O43 - CFD: 12/02/2017 - [] D -- C:\Users\TT\AppData\Local\PST_Walker_Software O43 - CFD: 29/12/2016 - [] D -- C:\Users\TT\AppData\Local\Publishers =>.Microsoft Corporation O43 - CFD: 28/02/2017 - [] D -- C:\Users\TT\AppData\Local\Sidebar7 =>.Sidebar7 O43 - CFD: 20/02/2017 - [] D -- C:\Users\TT\AppData\Local\Steam =>.Steam Games O43 - CFD: 28/02/2017 - [] D -- C:\Users\TT\AppData\Local\Temp =>.Microsoft Corporation O43 - CFD: 11/02/2017 - [0] SHD -- C:\Users\TT\AppData\Local\Temporary Internet Files =>.Microsoft Corporation O43 - CFD: 12/02/2017 - [] D -- C:\Users\TT\AppData\Local\Thunderbird =>.Thunderbird O43 - CFD: 29/12/2016 - [] D -- C:\Users\TT\AppData\Local\TileDataLayer =>.Microsoft Corporation O43 - CFD: 23/02/2017 - [0] D -- C:\Users\TT\AppData\Local\Unity =>.Unity O43 - CFD: 18/02/2017 - [] D -- C:\Users\TT\AppData\Local\VirtualStore =>.Microsoft Corporation O43 - CFD: 12/02/2017 - [0] D -- C:\Users\TT\AppData\Local\Programs\Common =>.Microsoft Corporation O43 - CFD: 16/07/2016 - [] RD -- C:\Users\TT\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility =>.Microsoft Corporation O43 - CFD: 12/02/2017 - [] RD -- C:\Users\TT\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories =>.Microsoft Corporation O43 - CFD: 12/02/2017 - [] RD -- C:\Users\TT\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools =>.Administrative Tools O43 - CFD: 21/02/2017 - [] D -- C:\Users\TT\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Call of Duty =>.Games Software O43 - CFD: 27/02/2017 - [] D -- C:\Users\TT\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Everything =>.Everything O43 - CFD: 12/02/2017 - [] D -- C:\Users\TT\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FBReader for Windows =>.FBReader O43 - CFD: 16/07/2016 - [] D -- C:\Users\TT\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance =>.Microsoft Corporation O43 - CFD: 12/02/2017 - [] D -- C:\Users\TT\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MSI Afterburner =>.Micro-Star International Co O43 - CFD: 12/02/2017 - [] D -- C:\Users\TT\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\RivaTuner Statistics Server =>.RivaTuner O43 - CFD: 27/02/2017 - [] RD -- C:\Users\TT\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup =>.Microsoft Corporation O43 - CFD: 23/02/2017 - [] D -- C:\Users\TT\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam =>.Steam Games O43 - CFD: 16/07/2016 - [] RD -- C:\Users\TT\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools =>.Microsoft Corporation O43 - CFD: 16/07/2016 - [] RD -- C:\Users\TT\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell =>.Microsoft Corporation O43 - CFD: 12/02/2017 - [] D -- C:\Users\TT\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR =>.WinRAR O43 - CFD: 12/02/2017 - [0] SHD -- C:\Users\Default\AppData\Local\Application Data =>.Microsoft Corporation O43 - CFD: 12/02/2017 - [0] SHD -- C:\Users\Default\AppData\Local\History =>.Microsoft Corporation O43 - CFD: 20/11/2016 - [] D -- C:\Users\Default\AppData\Local\Microsoft =>.Microsoft Corporation O43 - CFD: 16/07/2016 - [0] D -- C:\Users\Default\AppData\Local\Temp =>.Microsoft Corporation O43 - CFD: 12/02/2017 - [0] SHD -- C:\Users\Default\AppData\Local\Temporary Internet Files =>.Microsoft Corporation O43 - CFD: 12/02/2017 - [0] SHD -- C:\Users\Default User\AppData\Local\Application Data =>.Microsoft Corporation O43 - CFD: 12/02/2017 - [0] SHD -- C:\Users\Default User\AppData\Local\History =>.Microsoft Corporation O43 - CFD: 20/11/2016 - [] D -- C:\Users\Default User\AppData\Local\Microsoft =>.Microsoft Corporation O43 - CFD: 16/07/2016 - [0] D -- C:\Users\Default User\AppData\Local\Temp =>.Microsoft Corporation O43 - CFD: 12/02/2017 - [0] SHD -- C:\Users\Default User\AppData\Local\Temporary Internet Files =>.Microsoft Corporation O43 - CFD: 12/02/2017 - [] -- C:\Windows\System32\Config\systemprofile\AppData\Local\Chromium =>.Chromium O43 - CFD: 24/02/2017 - [] -- C:\Windows\System32\Config\systemprofile\AppData\Local\LavasoftTcpService =>PUP.Optional.LavasoftWebCompanion O43 - CFD: 12/02/2017 - [] D -- C:\Windows\System32\Config\systemprofile\AppData\Local\Microsoft =>.Microsoft Corporation O43 - CFD: 21/02/2017 - [0] D -- C:\Windows\System32\Config\systemprofile\AppData\Local\PeerDistRepub =>.Microsoft Corporation ---\\ Latest files created in Prefetcher (1) - 4s O45 - LFCP:[MD5.6280406888847086F3D60C05B7CCE232] 24/02/2017 A -- C:\Windows\Prefetch\UPDATEADMIN.EXE-861ABA6B.pf =>PUP.Optional.UpdateAdmin ---\\ ShellIconOverlayIdentifiers (SIOI) (5) - 1s O106 - SIOI: ErrorOverlayHandler Class [ OneDrive1] - {BBACC218-34EA-4666-9D7A-C78F2274A524}. (.Microsoft Corporation - Microsoft OneDrive Shell Extension.) -- C:\Users\TT\AppData\Local\Microsoft\OneDrive\17.3.6743.1212_1\FileSyncShell.dll =>.Microsoft Corporation® O106 - SIOI: SharedOverlayHandler Class [ OneDrive2] - {5AB7172C-9C11-405C-8DD5-AF20F3606282}. (.Microsoft Corporation - Microsoft OneDrive Shell Extension.) -- C:\Users\TT\AppData\Local\Microsoft\OneDrive\17.3.6743.1212_1\FileSyncShell.dll =>.Microsoft Corporation® O106 - SIOI: SharedSyncingOverlayHandler Class [ OneDrive3] - {A78ED123-AB77-406B-9962-2A5D9D2F7F30}. (.Microsoft Corporation - Microsoft OneDrive Shell Extension.) -- C:\Users\TT\AppData\Local\Microsoft\OneDrive\17.3.6743.1212_1\FileSyncShell.dll =>.Microsoft Corporation® O106 - SIOI: UpToDateOverlayHandler Class [ OneDrive4] - {F241C880-6982-4CE5-8CF7-7085BA96DA5A}. (.Microsoft Corporation - Microsoft OneDrive Shell Extension.) -- C:\Users\TT\AppData\Local\Microsoft\OneDrive\17.3.6743.1212_1\FileSyncShell.dll =>.Microsoft Corporation® O106 - SIOI: SyncingOverlayHandler Class [ OneDrive5] - {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}. (.Microsoft Corporation - Microsoft OneDrive Shell Extension.) -- C:\Users\TT\AppData\Local\Microsoft\OneDrive\17.3.6743.1212_1\FileSyncShell.dll =>.Microsoft Corporation® ---\\ System Drivers List (65) - 8s O58 - SDL:2016/07/16 06:41:53 A . (.LSI - LSI 3ware SCSI Storport Driver.) -- C:\Windows\System32\drivers\3ware.sys [107360] =>.Microsoft Windows® O58 - SDL:2016/07/16 06:41:53 A . (.PMC-Sierra - PMC-Sierra Storport Driver For SPC8x6G SAS.) -- C:\Windows\System32\drivers\adp80xx.sys [1135456] =>.Microsoft Windows® O58 - SDL:2016/07/16 06:41:53 A . (.Advanced Micro Devices - AHCI 1.3 Device Driver.) -- C:\Windows\System32\drivers\amdsata.sys [83296] =>.Microsoft Windows® O58 - SDL:2016/07/16 06:41:53 A . (.AMD Technologies Inc. - AMD Technology AHCI Compatible Controller D.) -- C:\Windows\System32\drivers\amdsbs.sys [259424] =>.Microsoft Windows® O58 - SDL:2016/07/16 06:41:53 A . (.Advanced Micro Devices - Storage Filter Driver.) -- C:\Windows\System32\drivers\amdxata.sys [26976] =>.Microsoft Windows® O58 - SDL:2016/07/16 06:41:53 A . (.PMC-Sierra, Inc. - Adaptec SAS RAID WS03 Driver.) -- C:\Windows\System32\drivers\arcsas.sys [131936] =>.Microsoft Windows® O58 - SDL:2016/07/16 06:41:53 A . (.Windows (R) Win 7 DDK provider - BCM Function 2 Device Driver.) -- C:\Windows\System32\drivers\bcmfn.sys [9728] =>.Windows (R) Win 7 DDK provider O58 - SDL:2016/07/16 06:41:53 A . (.Windows (R) Win 7 DDK provider - BCM Function 2 Device Driver.) -- C:\Windows\System32\drivers\bcmfn2.sys [9728] =>.Windows (R) Win 7 DDK provider O58 - SDL:2015/09/09 23:59:16 A . (.Broadcom Corporation. - Broadcom SMBus Controller Driver.) -- C:\Windows\System32\drivers\bcmsmbsp.sys [54048] =>.Broadcom Corporation® O58 - SDL:2016/07/16 06:41:52 A . (.QLogic Corporation - QLogic Gigabit Ethernet VBD.) -- C:\Windows\System32\drivers\bxvbda.sys [533856] =>.Microsoft Windows® O58 - SDL:2012/04/24 05:01:00 N . (.Corel Corporation - CDR4 64-bit CD and DVD Place Holder Driver.) -- C:\Windows\System32\drivers\cdr4_xp.sys [10864] =>.Corel Corporation® O58 - SDL:2012/04/24 05:01:00 N . (.Corel Corporation - CDRAL 64-bit Place Holder Driver (see PxHel.) -- C:\Windows\System32\drivers\cdralw2k.sys [11376] =>.Corel Corporation® O58 - SDL:2016/07/16 06:41:53 A . (.Chelsio Communications - Chelsio iSCSI Crash Dump Driver.) -- C:\Windows\System32\drivers\cht4dx64.sys [102752] =>.Microsoft Windows® O58 - SDL:2016/07/16 06:41:53 A . (.Chelsio Communications - Chelsio iSCSI VMiniport Driver.) -- C:\Windows\System32\drivers\cht4sx64.sys [346976] =>.Microsoft Windows® O58 - SDL:2016/07/16 06:41:53 A . (.Chelsio Communications - Virtual Bus Driver for Chelsio ® T4 Chipset.) -- C:\Windows\System32\drivers\cht4vx64.sys [2104160] =>.Microsoft Windows® O58 - SDL:2014/12/20 17:31:04 A . (.Elaborate Bytes AG - ElbyCD Windows x64 I/O driver.) -- C:\Windows\System32\drivers\ElbyCDIO.sys [40344] =>.Elaborate Bytes AG® O58 - SDL:2016/07/16 06:41:52 A . (.QLogic Corporation - QLogic 10 GigE VBD.) -- C:\Windows\System32\drivers\evbda.sys [3418976] =>.Microsoft Windows® O58 - SDL:2017/02/27 21:34:33 A . (.Malwarebytes - Malwarebytes Anti-Ransomware Protection.) -- C:\Windows\System32\drivers\farflt.sys [110536] =>.Malwarebytes Corporation® O58 - SDL:2016/07/16 06:41:53 A . (.Hewlett-Packard Company - Smart Array SAS/SATA Controller Media Drive.) -- C:\Windows\System32\drivers\HpSAMD.sys [64352] =>.Microsoft Windows® O58 - SDL:2016/07/16 06:41:54 A . (.Intel(R) Corporation - Intel(R) Serial IO GPIO Controller Driver.) -- C:\Windows\System32\drivers\iagpio.sys [33280] =>.Intel(R) Corporation O58 - SDL:2016/07/16 06:41:54 A . (.Intel(R) Corporation - Intel(R) Serial IO I2C Driver.) -- C:\Windows\System32\drivers\iai2c.sys [81408] =>.Intel(R) Corporation O58 - SDL:2016/07/16 06:41:54 A . (.Intel Corporation - Intel(R) Serial IO GPIO Driver v2.) -- C:\Windows\System32\drivers\iaLPSS2i_GPIO2.sys [64512] =>.Intel Corporation O58 - SDL:2016/07/16 06:41:54 A . (.Intel Corporation - Intel(R) Serial IO I2C Driver v2.) -- C:\Windows\System32\drivers\iaLPSS2i_I2C.sys [176384] =>.Intel Corporation - Embedded Subsystems and IP Blocks Group® O58 - SDL:2016/07/16 06:41:52 A . (.Intel Corporation - Intel(R) Serial IO GPIO Controller Driver.) -- C:\Windows\System32\drivers\iaLPSSi_GPIO.sys [38128] =>.Intel Corporation - Client Components Group® O58 - SDL:2016/07/16 06:41:50 A . (.Intel Corporation - Intel(R) Serial IO I2C Controller Driver.) -- C:\Windows\System32\drivers\iaLPSSi_I2C.sys [113152] =>.Intel Corporation O58 - SDL:2016/07/16 06:41:53 A . (.Intel Corporation - Intel(R) Rapid Storage Technology driver (i.) -- C:\Windows\System32\drivers\iaStorAV.sys [673120] =>.Microsoft Windows® O58 - SDL:2016/07/16 06:41:53 A . (.Intel Corporation - Intel Matrix Storage Manager driver - x64.) -- C:\Windows\System32\drivers\iaStorV.sys [412000] =>.Microsoft Windows® O58 - SDL:2016/07/16 06:41:53 A . (.Mellanox - InfiniBand Fabric Bus Driver.) -- C:\Windows\System32\drivers\ibbus.sys [526176] =>.Microsoft Windows® O58 - SDL:2013/07/30 22:32:06 A . (.Authors - Intel(R) Smart Connect Technology Device Dr.) -- C:\Windows\System32\drivers\ISCTD64.sys [47008] =>.Intel(R) Smart Connect software® O58 - SDL:2016/07/16 06:41:53 A . (.Qualcomm Atheros Co., Ltd. - Qualcomm Atheros Ar81xx series PCI-E Gigabi.) -- C:\Windows\System32\drivers\L1C63x64.sys [121344] =>.Qualcomm Atheros Co., Ltd. O58 - SDL:2016/07/16 06:41:53 A . (.LSI Corporation - LSI Fusion-MPT SAS Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_sas.sys [108896] =>.Microsoft Windows® O58 - SDL:2016/07/16 06:41:53 A . (.LSI Corporation - LSI SAS Gen2 Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_sas2i.sys [105824] =>.Microsoft Windows® O58 - SDL:2016/07/16 06:41:53 A . (.Avago Technologies - Avago SAS Gen3 Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_sas3i.sys [101216] =>.Microsoft Windows® O58 - SDL:2016/07/16 06:41:53 A . (.LSI Corporation - LSI SSS PCIe/Flash Driver (StorPort).) -- C:\Windows\System32\drivers\lsi_sss.sys [82776] =>.Microsoft Windows® O58 - SDL:2017/01/20 07:47:44 A . (.Authors - .) -- C:\Windows\System32\drivers\mbae64.sys [77416] =>.Malwarebytes Corporation® O58 - SDL:2017/02/27 21:34:33 A . (.Malwarebytes - Malwarebytes Real-Time Protection.) -- C:\Windows\System32\drivers\mbam.sys [43968] =>.Malwarebytes Corporation® O58 - SDL:2017/02/25 07:04:33 A . (.Malwarebytes - Malwarebytes Chameleon.) -- C:\Windows\System32\drivers\MBAMChameleon.sys [176584] =>.Malwarebytes Corporation® O58 - SDL:2017/02/27 21:34:33 A . (.Malwarebytes - Malwarebytes SwissArmy.) -- C:\Windows\System32\drivers\MBAMSwissArmy.sys [251848] =>.Malwarebytes Corporation® O58 - SDL:2016/07/16 06:41:53 A . (.Avago Technologies - MEGASAS RAID Controller Driver for Windows.) -- C:\Windows\System32\drivers\megasas.sys [59744] =>.Microsoft Windows® O58 - SDL:2016/11/20 13:10:57 A . (.Avago Technologies - MEGASAS RAID Controller Driver for Windows.) -- C:\Windows\System32\drivers\MegaSas2i.sys [64352] =>.Microsoft Windows® O58 - SDL:2016/07/16 06:41:53 A . (.LSI Corporation, Inc. - LSI MegaRAID Software RAID Driver.) -- C:\Windows\System32\drivers\megasr.sys [575840] =>.Microsoft Windows® O58 - SDL:2016/07/16 06:41:53 A . (.Mellanox - MLX4 Bus Driver.) -- C:\Windows\System32\drivers\mlx4_bus.sys [842584] =>.Microsoft Windows® O58 - SDL:2016/07/16 06:41:53 A . (.Marvell Semiconductor, Inc. - Marvell Flash Controller Driver.) -- C:\Windows\System32\drivers\mvumis.sys [63840] =>.Microsoft Windows® O58 - SDL:2017/02/28 07:47:58 A . (.Malwarebytes - Malwarebytes Web Protection.) -- C:\Windows\System32\drivers\mwac.sys [91584] =>.Malwarebytes Corporation® O58 - SDL:2016/07/16 06:41:53 A . (.Mellanox - NetworkDirect Support Filter Driver.) -- C:\Windows\System32\drivers\ndfltr.sys [108896] =>.Microsoft Windows® O58 - SDL:2016/07/16 06:42:03 A . (.Authors - .) -- C:\Windows\System32\drivers\NetAdapterCx.sys [90624] =>.Microsoft Corporation O58 - SDL:2017/01/23 19:00:01 A . (.NVIDIA Corporation - NVIDIA HDMI Audio Driver.) -- C:\Windows\System32\drivers\nvhda64v.sys [217528] =>.NVIDIA Corporation® O58 - SDL:2016/07/16 06:41:53 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) RAID Driver.) -- C:\Windows\System32\drivers\nvraid.sys [150368] =>.Microsoft Windows® O58 - SDL:2016/07/16 06:41:53 A . (.NVIDIA Corporation - NVIDIA® nForce(TM) Sata Performance Driver.) -- C:\Windows\System32\drivers\nvstor.sys [166240] =>.Microsoft Windows® O58 - SDL:2017/01/20 13:39:20 A . (.NVIDIA Corporation - NVIDIA Virtual Audio Driver.) -- C:\Windows\System32\drivers\nvvad64v.sys [46016] =>.NVIDIA Corporation® O58 - SDL:2017/01/20 13:39:20 A . (.NVIDIA Corporation - Virtual USB Host Controller driver.) -- C:\Windows\System32\drivers\nvvhci.sys [57792] =>.NVIDIA Corporation® O58 - SDL:2016/07/16 06:41:53 A . (.Avago Technologies - MEGASAS RAID Controller Driver for Windows.) -- C:\Windows\System32\drivers\percsas2i.sys [58720] =>.Microsoft Windows® O58 - SDL:2016/07/16 06:41:53 A . (.Avago Technologies - MEGASAS RAID Controller Driver for Windows.) -- C:\Windows\System32\drivers\percsas3i.sys [61792] =>.Microsoft Windows® O58 - SDL:2013/09/03 05:01:00 N . (.Corel Corporation - Px Engine Device Driver for 64-bit (x86-64).) -- C:\Windows\System32\drivers\PxHlpa64.sys [56336] =>.Corel Corporation® O58 - SDL:2016/10/26 01:01:50 A . (.Realtek Semiconductor Corporation - Realtek Bluetooth Filter Driver.) -- C:\Windows\System32\drivers\RtkBtfilter.sys [719424] =>.Realtek Semiconductor Corp.® O58 - SDL:2016/07/16 06:41:50 A . (.Realtek Semiconductor Corporation - Realtek PCIE NDIS Driver 42654.) -- C:\Windows\System32\drivers\rtwlane.sys [5144064] =>.Realtek Semiconductor Corporation O58 - SDL:2016/07/16 06:41:53 A . (.Silicon Integrated Systems Corp. - SiS RAID Stor Miniport Driver.) -- C:\Windows\System32\drivers\sisraid2.sys [44896] =>.Microsoft Windows® O58 - SDL:2016/07/16 06:41:53 A . (.Silicon Integrated Systems - SiS AHCI Stor-Miniport Driver.) -- C:\Windows\System32\drivers\sisraid4.sys [81760] =>.Microsoft Windows® O58 - SDL:2016/07/16 06:41:53 A . (.Promise Technology, Inc. - Promise SuperTrak EX Series Driver for Wind.) -- C:\Windows\System32\drivers\stexstor.sys [31072] =>.Microsoft Windows® O58 - SDL:2016/04/04 02:06:10 A . (.Intel Corporation - Intel(R) Management Engine Interface.) -- C:\Windows\System32\drivers\TeeDriverW8x64.sys [195152] =>.Intel(R) Embedded Subsystems and IP Blocks Group® O58 - SDL:2014/05/03 11:53:40 A . (.Elaborate Bytes AG - Virtual CloneDrive storage miniport.) -- C:\Windows\System32\drivers\VClone.sys [34816] =>.Elaborate Bytes AG O58 - SDL:2016/07/16 06:41:53 A . (.VIA Technologies Inc.,Ltd - VIA RAID DRIVER FOR AMD-X86-64.) -- C:\Windows\System32\drivers\vsmraid.sys [166752] =>.Microsoft Windows® O58 - SDL:2016/07/16 06:41:53 A . (.VIA Corporation - VIA StorX RAID Controller Driver.) -- C:\Windows\System32\drivers\VSTXRAID.SYS [305504] =>.Microsoft Windows® O58 - SDL:2016/07/16 06:41:53 A . (.Mellanox - Kernel WinMad.) -- C:\Windows\System32\drivers\winmad.sys [32096] =>.Microsoft Windows® O58 - SDL:2016/07/16 06:41:53 A . (.Mellanox - Kernel WinVerbs.) -- C:\Windows\System32\drivers\winverbs.sys [64864] =>.Microsoft Windows® ---\\ Last modified or created user files (5) - 4s O61 - LFC: 2017/02/23 19:14:59 A . (..) -- C:\Users\TT\AppData\Local\Mail.Ru\mrkeeper.exe [1448152] {2019877A933D8E2E71548EA4AB4827F1} O61 - LFC: 2017/02/25 15:38:52 A . (..) -- C:\Users\TT\AppData\Local\Origin\ThinSetup\10.0.1.29730\icudt51.dll [727457] O61 - LFC: 2017/02/25 15:38:52 A . (..) -- C:\Users\TT\AppData\Local\Origin\ThinSetup\10.0.1.29730\libEGL.dll [12288] O61 - LFC: 2017/02/25 15:38:52 A . (..) -- C:\Users\TT\AppData\Local\Origin\ThinSetup\10.0.1.29730\libGLESv2.dll [2493440] O61 - LFC: 2017/02/25 15:38:53 A . (..) -- C:\Users\TT\AppData\Local\Origin\ThinSetup\10.0.1.29730\QtWebEngineProcess.exe [15872] ---\\ File Associations Shell Spawning (10) - 0s O67 - Shell Spawning: <.bat> <batfile>[HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.cpl> <cplfile>[HKLM\..\cplopen\Command] (.Microsoft Corporation - Windows Control Panel.) -- C:\Windows\System32\control.exe =>.Microsoft Corporation O67 - Shell Spawning: <.cmd> <cmdfile>[HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.com> <comfile>[HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.evt> <evtfile>[HKLM\..\open\Command] (.Microsoft Corporation - Event Viewer Snapin Launcher.) -- C:\Windows\System32\eventvwr.exe =>.Microsoft Corporation O67 - Shell Spawning: <.exe> <exefile>[HKLM\..\open\Command] (...) -- "%1" %* O67 - Shell Spawning: <.html> <htmlfile>[HKLM\..\open\Command] (.Microsoft Corporation - Internet Explorer.) -- C:\Program Files\Internet Explorer\iexplore.exe =>.Microsoft Corporation® O67 - Shell Spawning: <.js> <JSFile>[HKLM\..\open\Command] (.Microsoft Corporation - Microsoft ® Windows Based Script Host.) -- C:\Windows\System32\wscript.exe =>.Microsoft Corporation O67 - Shell Spawning: <.reg> <regfile>[HKLM\..\open\Command] (.Microsoft Corporation - Registry Editor.) -- C:\Windows\regedit.exe =>.Microsoft Corporation O67 - Shell Spawning: <.scr> <scrfile>[HKLM\..\open\Command] (...) -- "%1" /S ---\\ Start Menu Internet (8) - 0s O68 - StartMenuInternet: <Google Chrome> <Google Chrome>[HKLM\..\Shell\open\Command] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc® O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer>[HKLM\..\Shell\open\Command] (...) -- iexplore.exe O68 - StartMenuInternet: <Google Chrome> <Google Chrome>[HKLM\..\InstallInfo\ShowIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc. O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer>[HKLM\..\InstallInfo\ShowIconsCommand] (.Microsoft Corporation - IE Per-User Initialization Utility.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation O68 - StartMenuInternet: <Google Chrome> <Google Chrome>[HKLM\..\InstallInfo\ReinstallCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc. O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer>[HKLM\..\InstallInfo\ReinstallCommand] (.Microsoft Corporation - IE Per-User Initialization Utility.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation O68 - StartMenuInternet: <Google Chrome> <Google Chrome>[HKLM\..\InstallInfo\HideIconsCommand] (.Google Inc. - Google Chrome.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe =>.Google Inc. O68 - StartMenuInternet: <IEXPLORE.EXE> <Internet Explorer>[HKLM\..\InstallInfo\HideIconsCommand] (.Microsoft Corporation - IE Per-User Initialization Utility.) -- C:\Windows\System32\ie4uinit.exe =>.Microsoft Corporation ---\\ Search Browser Infection (1) - 0s O69 - SBI: SearchScopes [HKCU] {FFEBBF0A-C22C-4172-89FF-45215A135AC7} - (Поиск@Mail.Ru) - http://go.mail.ru/ ---\\ Search Svchost Services (46) - 1s O83 - Search Svchost Services: CertPropSvc (CertPropSvc) . (.Microsoft Corporation - Microsoft Smartcard Certificate Propagation.) -- C:\Windows\System32\certprop.dll [193536] =>.Microsoft Corporation O83 - Search Svchost Services: SCPolicySvc (SCPolicySvc) . (.Microsoft Corporation - Microsoft Smartcard Certificate Propagation.) -- C:\Windows\System32\certprop.dll [193536] =>.Microsoft Corporation O83 - Search Svchost Services: lanmanserver (lanmanserver) . (.Microsoft Corporation - Server Service DLL.) -- C:\Windows\system32\srvsvc.dll [305152] =>.Microsoft Corporation O83 - Search Svchost Services: gpsvc (gpsvc) . (.Microsoft Corporation - Group Policy Client.) -- C:\Windows\System32\gpsvc.dll [1227264] =>.Microsoft Corporation O83 - Search Svchost Services: IKEEXT (IKEEXT) . (.Microsoft Corporation - IKE extension.) -- C:\Windows\System32\ikeext.dll [932352] =>.Microsoft Corporation O83 - Search Svchost Services: iphlpsvc (iphlpsvc) . (.Microsoft Corporation - Service that offers IPv6 connectivity over.) -- C:\Windows\System32\iphlpsvc.dll [945664] =>.Microsoft Corporation O83 - Search Svchost Services: seclogon (seclogon) . (.Microsoft Corporation - Secondary Logon Service DLL.) -- C:\Windows\system32\seclogon.dll [31232] =>.Microsoft Corporation O83 - Search Svchost Services: AppInfo (AppInfo) . (.Microsoft Corporation - Application Information Service.) -- C:\Windows\System32\appinfo.dll [125952] =>.Microsoft Corporation O83 - Search Svchost Services: msiscsi (msiscsi) . (.Microsoft Corporation - iSCSI Discovery service.) -- C:\Windows\system32\iscsiexe.dll [151552] =>.Microsoft Corporation O83 - Search Svchost Services: EapHost (EapHost) . (.Microsoft Corporation - Microsoft EAPHost service.) -- C:\Windows\System32\eapsvc.dll [112128] =>.Microsoft Corporation O83 - Search Svchost Services: schedule (schedule) . (.Microsoft Corporation - Task Scheduler Service.) -- C:\Windows\system32\schedsvc.dll [948224] =>.Microsoft Corporation O83 - Search Svchost Services: winmgmt (winmgmt) . (.Microsoft Corporation - WMI.) -- C:\Windows\system32\wbem\WMIsvc.dll [222720] =>.Microsoft Corporation O83 - Search Svchost Services: browser (browser) . (.Microsoft Corporation - Computer Browser Service DLL.) -- C:\Windows\System32\browser.dll [134656] =>.Microsoft Corporation O83 - Search Svchost Services: SessionEnv (SessionEnv) . (.Microsoft Corporation - Remote Desktop Configuration service.) -- C:\Windows\System32\SessEnv.dll [387072] =>.Microsoft Corporation O83 - Search Svchost Services: wercplsupport (wercplsupport) . (.Microsoft Corporation - Problem Reports and Solutions.) -- C:\Windows\System32\wercplsupport.dll [94208] =>.Microsoft Corporation O83 - Search Svchost Services: shpamsvc (shpamsvc) . (.Microsoft Corporation - SharedPC.AccountManager.) -- C:\Windows\system32\Windows.SharedPC.AccountManager.dll [161792] =>.Microsoft Corporation O83 - Search Svchost Services: Themes (Themes) . (.Microsoft Corporation - Windows Shell Theme Service Dll.) -- C:\Windows\system32\themeservice.dll [70656] =>.Microsoft Corporation O83 - Search Svchost Services: lfsvc (lfsvc) . (.Microsoft Corporation - Geolocation Service.) -- C:\Windows\System32\lfsvc.dll [37376] =>.Microsoft Corporation O83 - Search Svchost Services: DmEnrollmentSvc (DmEnrollmentSvc) . (.Microsoft Corporation - Windows Managent Service DLL.) -- C:\Windows\System32\Windows.Internal.Management.dll [407552] =>.Microsoft Corporation O83 - Search Svchost Services: Irmon (Irmon) . (.Microsoft Corporation - Infrared Monitor.) -- C:\Windows\System32\irmon.dll [25088] =>.Microsoft Corporation O83 - Search Svchost Services: Rasauto (Rasauto) . (.Microsoft Corporation - Remote Access AutoDial Manager.) -- C:\Windows\System32\rasauto.dll [105472] =>.Microsoft Corporation O83 - Search Svchost Services: Rasman (Rasman) . (.Microsoft Corporation - Remote Access Connection Manager.) -- C:\Windows\System32\rasmans.dll [657920] =>.Microsoft Corporation O83 - Search Svchost Services: Remoteaccess (Remoteaccess) . (.Microsoft Corporation - Dynamic Interface Manager.) -- C:\Windows\System32\mprdim.dll [496128] =>.Microsoft Corporation O83 - Search Svchost Services: SENS (SENS) . (.Microsoft Corporation - System Event Notification Service (SENS).) -- C:\Windows\System32\sens.dll [70656] =>.Microsoft Corporation O83 - Search Svchost Services: Sharedaccess (Sharedaccess) . (.Microsoft Corporation - Microsoft NAT Helper Components.) -- C:\Windows\System32\ipnathlp.dll [541696] =>.Microsoft Corporation O83 - Search Svchost Services: Tapisrv (Tapisrv) . (.Microsoft Corporation - Microsoft® Windows(TM) Telephony Server.) -- C:\Windows\System32\tapisrv.dll [309248] =>.Microsoft Corporation O83 - Search Svchost Services: wuauserv (wuauserv) . (.Microsoft Corporation - Windows Update Agent.) -- C:\Windows\system32\wuaueng.dll [2317824] =>.Microsoft Corporation O83 - Search Svchost Services: BITS (BITS) . (.Microsoft Corporation - Background Intelligent Transfer Service.) -- C:\Windows\System32\qmgr.dll [1054208] =>.Microsoft Corporation O83 - Search Svchost Services: ShellHWDetection (ShellHWDetection) . (.Microsoft Corporation - Windows Shell Services Dll.) -- C:\Windows\System32\shsvcs.dll [617472] =>.Microsoft Corporation O83 - Search Svchost Services: dmwappushservice (dmwappushservice) . (.Microsoft Corporation - dmwappushsvc.) -- C:\Windows\system32\dmwappushsvc.dll [57344] =>.Microsoft Corporation O83 - Search Svchost Services: WpnService (WpnService) . (.Microsoft Corporation - Windows Push Notification System Service.) -- C:\Windows\system32\WpnService.dll [234496] =>.Microsoft Corporation O83 - Search Svchost Services: XboxNetApiSvc (XboxNetApiSvc) . (.Microsoft Corporation - Xbox Live Networking Service.) -- C:\Windows\system32\XboxNetApiSvc.dll [1025536] =>.Microsoft Corporation O83 - Search Svchost Services: DcpSvc (DcpSvc) . (.Microsoft Corporation - dcpsvc Task.) -- C:\Windows\system32\dcpsvc.dll [183808] =>.Microsoft Corporation O83 - Search Svchost Services: RetailDemo (RetailDemo) . (.Microsoft Corporation - RDXService.) -- C:\Windows\system32\RDXService.dll [650752] =>.Microsoft Corporation O83 - Search Svchost Services: BDESVC (BDESVC) . (.Microsoft Corporation - BDE Service.) -- C:\Windows\System32\bdesvc.dll [361472] =>.Microsoft Corporation O83 - Search Svchost Services: DsmSvc (DsmSvc) . (.Microsoft Corporation - Device Setup Manager.) -- C:\Windows\System32\DeviceSetupManager.dll [197632] =>.Microsoft Corporation O83 - Search Svchost Services: NcaSvc (NcaSvc) . (.Microsoft Corporation - Microsoft Network Connectivity Assistant Se.) -- C:\Windows\System32\ncasvc.dll [167936] =>.Microsoft Corporation O83 - Search Svchost Services: AppMgmt (AppMgmt) . (.Microsoft Corporation - Software installation Service.) -- C:\Windows\System32\appmgmts.dll [197632] =>.Microsoft Corporation O83 - Search Svchost Services: ProfSvc (ProfSvc) . (.Microsoft Corporation - ProfSvc.) -- C:\Windows\system32\profsvc.dll [358400] =>.Microsoft Corporation O83 - Search Svchost Services: UsoSvc (UsoSvc) . (.Microsoft Corporation - Update Session Orchestrator Core.) -- C:\Windows\system32\usocore.dll [539648] =>.Microsoft Corporation O83 - Search Svchost Services: wisvc (wisvc) . (.Microsoft Corporation - Flight Settings.) -- C:\Windows\system32\flightsettings.dll [635904] =>.Microsoft Corporation O83 - Search Svchost Services: UserManager (UserManager) . (.Microsoft Corporation - UserMgr.) -- C:\Windows\System32\usermgr.dll [1020928] =>.Microsoft Corporation O83 - Search Svchost Services: wlidsvc (wlidsvc) . (.Microsoft Corporation - Microsoft® Account Service.) -- C:\Windows\system32\wlidsvc.dll [2104320] =>.Microsoft Corporation O83 - Search Svchost Services: XblAuthManager (XblAuthManager) . (.Microsoft Corporation - Xbox Live Auth Manager.) -- C:\Windows\System32\XblAuthManager.dll [1013248] =>.Microsoft Corporation O83 - Search Svchost Services: XblGameSave (XblGameSave) . (.Microsoft Corporation - Xbox Live Game Save Service.) -- C:\Windows\System32\XblGameSave.dll [1159680] =>.Microsoft Corporation O83 - Search Svchost Services: NetSetupSvc (NetSetupSvc) . (.Microsoft Corporation - Network Setup Service.) -- C:\Windows\System32\NetSetupSvc.dll [265728] =>.Microsoft Corporation ---\\ Product Upgrade Codes (1) - 0s O90 - PUC: "5C59CF75147BC96468703BC9CE248342" . (.UpdateAdmin.) -- C:\Windows\Installer\{57FC95C5-B741-469C-8607-B39CEC423824}\icon.ico =>PUP.Optional.UpdateAdmin ---\\ Windows Installer Scan (1) - 1s [MD5.] [WIS][2017/02/20 13:58:55] (.DownloadAdmin - Windows Installer XML Toolset (3.8.1128.0).) -- C:\Windows\Installer\5eaab19.msi [372736] =>PUP.Optional.UpdateAdmin ---\\ Additional Scan (O88) (13) - 0s HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA} =>.Superfluous.Orphan HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA} =>.Superfluous.Orphan HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} =>.Superfluous.Orphan HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} =>.Superfluous.Orphan C:\ProgramData\Uniblue =>.Superfluous.Uniblue C:\Users\TT\AppData\Local\CrashRpt =>.Superfluous.CrashReports C:\Users\TT\AppData\Local\NowUSeeItPlayerOsm =>.Superfluous.NowUSeeItPlayer C:\Users\TT\AppData\Local\PackageAware =>PUP.Optional.BearShare C:\Windows\Prefetch\UPDATEADMIN.EXE-861ABA6B.pf =>PUP.Optional.UpdateAdmin C:\Windows\Installer\{57FC95C5-B741-469C-8607-B39CEC423824}\icon.ico =>PUP.Optional.UpdateAdmin HKLM\Software\Classes\Installer\Products\5C59CF75147BC96468703BC9CE248342 =>PUP.Optional.UpdateAdmin HKLM\Software\Classes\Installer\Features\5C59CF75147BC96468703BC9CE248342 =>PUP.Optional.UpdateAdmin C:\Windows\Installer\5eaab19.msi =>PUP.Optional.UpdateAdmin ---\\ Summary of the elements found (8) - 0s https://nicolascoolman.eu/2017/01/20/logiciels-superflus/ =>.Superfluous.Uniblue https://nicolascoolman.eu/2017/01/27/repaquetage-et-infection/ =>PUP.Optional.UpdateAdmin https://www.anti-malware.top/2016/04/22/adware-installcore/ =>Adware.InstallCore https://nicolascoolman.eu/2017/01/20/logiciels-superflus/ =>.Superfluous.Downloader https://nicolascoolman.eu/2017/01/20/logiciels-superflus/ =>.Superfluous.CrashReports https://www.anti-malware.top/2016/04/23/pup-optional-nowuseeitplayer/ =>.Superfluous.NowUSeeItPlayer https://www.nicolascoolman.com/fr/pup-bearshare/ =>PUP.Optional.BearShare https://www.anti-malware.top/2016/04/26/superfluous-lavasoftwebcompanion/ =>PUP.Optional.LavasoftWebCompanion ~ Unselected Options: O82, ~ End of the scan, 38601 items in 02mn18s (1135)(0) Thank you
  23. ZHP Diag Scan Download ZHP Diag to your desktop. 1. Right Click Run as Admin. 2. Click the Scanner button. When complete please push the report button. A notepad will open... copy and paste the report in your next reply.
  24. Hi Kris, Thank you for the suggestion but the problem remains. Everything search engine did find "journalaboutlife.org/scopesm" in c:\Windows\System32\tasks. I deleted it and also deleted it from the Recycle Bin. I rebooted the PC and ran the search again. It wasn't found by Everything search this time. Yet 20 minutes later the same dialog pops up again. Do you have any further ideas? What is the next step? Thank you again. Paul
  25. Use the everything search engine or autoruns to find the journalaboutlife.org/scopesm entry, then delete it.
  26. Soo.... did you manage to fix it? I have the same problem btw..
  27. I am working with a new Window 10 based computer and have been reinstalling some favorite game software. In the last two days I get an annoying error dialog (with red X icon) that pops on the screen every 30 minutes. It states "Windows can not find 'journalaboutlife.org/scopesm'. Make sure you typed the name correctly, and then try again." (I have attached a screen capture jpg of the dialog if it will help) I never intentionally used software or a site called 'journalaboutlife.org'. So far, I ran Windows Defender and Malewarebytes, both deleted items (mostly PUP's), I rebooted after but still get the problem stated above. I re-ran both WD and MB but no further maleware was found. I can't identify the event of this dialog in Event Viewer. I don't know what software is causing this error. Would somebody please help me track it down? Thank you.
  28. Load more activity

WindowsInstructed Forums

Welcome on the WindowsInstructed Forums. If you have any Windows question or Malware related question then this is the place to be. All your connections are securely encrypted with our server so your privacy is protected as well!