Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Browser errors and multiple COM surrogates after virus cleanup


  • Please log in to reply
8 replies to this topic

#1 JusTLC

JusTLC

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Lithuania
  • Local time:10:54 PM

Posted 28 August 2015 - 06:38 PM

So I got a run in with a virus recently, opened a questionable .exe and, yeah, my performance dropped, so I ran MBAM and it found several detections and now my PC performance is on par. But ever since, my browser doesn't load some websites from time to time (i.e. bleepingcomputer.com) and it shows errors:

DNS_PROBE_FINISHED_NXDOMAIN
or
ERR_NAME_RESOLUTION_FAILED

Also, whenever I open task manager, there seem to be 3 COM surrogate procceses running. After a few seconds, 2 of them dissapear, but whenever I reopen task manager, same thing happens.

I'm not sure if I still have a virus, but I've been encountering these problems right after the infection and I think it may have something to do with it.

Thanks in advance.

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:28-08-2015

Ran by Justinas (administrator) on DESKTOP-GGB2RP0 (29-08-2015 02:00:09)
Running from C:\Users\Justinas\Downloads
Loaded Profiles: Justinas (Available Profiles: Justinas & Nerijus)
Platform: Windows 10 Enterprise (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\sched.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avguard.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
(@ByELDI) C:\Program Files\KMSpico\Service_KMS.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avshadow.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.28.1\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.28.1\GoogleCrashHandler64.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_w32.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_x64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Microsoft Corporation) C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avgnt.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Spotify Ltd) C:\Users\Justinas\AppData\Roaming\Spotify\Spotify.exe
(Spotify Ltd) C:\Users\Justinas\AppData\Roaming\Spotify\SpotifyCrashService.exe
(Spotify Ltd) C:\Users\Justinas\AppData\Roaming\Spotify\Spotify.exe
(Spotify Ltd) C:\Users\Justinas\AppData\Roaming\Spotify\SpotifyWebHelper.exe
(Spotify Ltd) C:\Users\Justinas\AppData\Roaming\Spotify\Spotify.exe
(Blizzard Entertainment) C:\ProgramData\Battle.net\Agent\Agent.4318\Agent.exe
(Blizzard Entertainment) C:\Program Files (x86)\Battle.net\Battle.net.6119\Battle.net.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
() C:\Riot Games\League of Legends\RADS\system\rads_user_kernel.exe
() C:\Riot Games\League of Legends\RADS\projects\lol_launcher\releases\0.0.0.252\deploy\LoLLauncher.exe
() C:\Riot Games\League of Legends\RADS\projects\lol_patcher\releases\0.0.0.36\deploy\LoLPatcher.exe
() C:\Riot Games\League of Legends\RADS\projects\lol_patcher\releases\0.0.0.36\deploy\LoLPatcherUx.exe
() C:\Riot Games\League of Legends\RADS\projects\lol_patcher\releases\0.0.0.36\deploy\LoLPatcherUx.exe
() C:\Riot Games\League of Legends\RADS\projects\lol_patcher\releases\0.0.0.36\deploy\LoLPatcherUx.exe
(GOG.com) C:\Program Files (x86)\GalaxyClient\GalaxyClient.exe
(GOG.com) C:\Program Files (x86)\GalaxyClient\GalaxyClient Helper.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
 
 
==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13885696 2015-08-01] (Realtek Semiconductor)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2634896 2015-07-24] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [170256 2015-08-13] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [334896 2015-06-08] (Oracle Corporation)
HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [39175960 2015-08-14] (Dropbox, Inc.)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\Antivirus\avgnt.exe [782008 2015-08-26] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe [134368 2015-07-02] (Avira Operations GmbH & Co. KG)
HKU\S-1-5-19\...\Run: [OneDriveSetup] => C:\Windows\SysWOW64\OneDriveSetup.exe [7805120 2015-07-10] (Microsoft Corporation)
HKU\S-1-5-20\...\Run: [OneDriveSetup] => C:\Windows\SysWOW64\OneDriveSetup.exe [7805120 2015-07-10] (Microsoft Corporation)
HKU\S-1-5-21-3691003279-1683200719-2023029133-1001\...\Run: [OneDrive] => C:\Users\Justinas\AppData\Local\Microsoft\OneDrive\OneDrive.exe [402632 2015-08-01] (Microsoft Corporation)
HKU\S-1-5-21-3691003279-1683200719-2023029133-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [2899136 2015-08-19] (Valve Corporation)
HKU\S-1-5-21-3691003279-1683200719-2023029133-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [53655680 2015-07-28] (Skype Technologies S.A.)
HKU\S-1-5-21-3691003279-1683200719-2023029133-1001\...\Run: [Spotify Web Helper] => C:\Users\Justinas\AppData\Roaming\Spotify\SpotifyWebHelper.exe [2018360 2015-08-28] (Spotify Ltd)
HKU\S-1-5-21-3691003279-1683200719-2023029133-1001\...\Run: [GalaxyClient] => C:\Program Files (x86)\GalaxyClient\GalaxyClient.exe [7249976 2015-08-12] (GOG.com)
HKU\S-1-5-21-3691003279-1683200719-2023029133-1001\...\Run: [Spotify] => C:\Users\Justinas\AppData\Roaming\Spotify\Spotify.exe [7389752 2015-08-28] (Spotify Ltd)
HKU\S-1-5-21-3691003279-1683200719-2023029133-1001\...\Run: [VideoDownloaderUltimate] => C:\ProgramData\VideoDownloaderUltimateWinApp\VideoDownloaderUltimate.exe /repair
HKU\S-1-5-21-3691003279-1683200719-2023029133-1001\...\RunOnce: [Uninstall C:\Users\Justinas\AppData\Local\Microsoft\OneDrive\17.3.5892.0626\amd64] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Justinas\AppData\Local\Microsoft\OneDrive\17.3.5892.0626\amd64"
ShellIconOverlayIdentifiers: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.dll [2015-08-14] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.dll [2015-08-14] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.dll [2015-08-14] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.dll [2015-08-14] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.dll [2015-08-14] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.dll [2015-08-14] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.dll [2015-08-14] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.dll [2015-08-14] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.27.dll [2015-08-14] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.27.dll [2015-08-14] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.27.dll [2015-08-14] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.27.dll [2015-08-14] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.27.dll [2015-08-14] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.27.dll [2015-08-14] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.27.dll [2015-08-14] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.27.dll [2015-08-14] (Dropbox, Inc.)
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
HKU\S-1-5-21-3691003279-1683200719-2023029133-1001\Software\Microsoft\Internet Explorer\Main,Local Page = %11%\blank.htm
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_51\bin\ssv.dll [2015-08-01] (Oracle Corporation)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_51\bin\jp2ssv.dll [2015-08-01] (Oracle Corporation)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_51\bin\ssv.dll [2015-08-01] (Oracle Corporation)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_51\bin\jp2ssv.dll [2015-08-01] (Oracle Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 192.168.0.1
Tcpip\..\Interfaces\{be2c2e50-5c38-4a77-9f14-7bad6b5f6b9a}: [DhcpNameServer] 192.168.0.1 192.168.0.1
 
FireFox:
========
FF ProfilePath: C:\Users\Justinas\AppData\Roaming\Mozilla\Firefox\Profiles\yq8q00kp.default
FF Homepage: google.com
FF Plugin: @java.com/DTPlugin,version=11.51.2 -> C:\Program Files\Java\jre1.8.0_51\bin\dtplugin\npDeployJava1.dll [2015-08-01] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.51.2 -> C:\Program Files\Java\jre1.8.0_51\bin\plugin2\npjp2.dll [2015-08-01] (Oracle Corporation)
FF Plugin: @videolan.org/vlc,version=2.2.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-16] (VideoLAN)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2015-07-30] ()
FF Plugin-x32: @java.com/DTPlugin,version=11.51.2 -> C:\Program Files (x86)\Java\jre1.8.0_51\bin\dtplugin\npDeployJava1.dll [2015-08-01] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.51.2 -> C:\Program Files (x86)\Java\jre1.8.0_51\bin\plugin2\npjp2.dll [2015-08-01] (Oracle Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-08-16] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-08-16] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-07-03] (Adobe Systems Inc.)
FF Extension: Flash Video Downloader - YouTube HD Download [4K] - C:\Users\Justinas\AppData\Roaming\Mozilla\Firefox\Profiles\yq8q00kp.default\Extensions\artur.dubovoy@gmail.com [2015-08-14]
FF Extension: Ghostery - C:\Users\Justinas\AppData\Roaming\Mozilla\Firefox\Profiles\yq8q00kp.default\Extensions\firefox@ghostery.com.xpi [2015-08-14]
FF Extension: DownThemAll! - C:\Users\Justinas\AppData\Roaming\Mozilla\Firefox\Profiles\yq8q00kp.default\Extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi [2015-08-14]
 
Chrome: 
=======
CHR Profile: C:\Users\Justinas\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\Justinas\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-08-16]
CHR Extension: (Magic Actions for YouTube™) - C:\Users\Justinas\AppData\Local\Google\Chrome\User Data\Default\Extensions\abjcfabbhafbcdfjoecdgepllmpfceif [2015-08-16]
CHR Extension: (Google Docs) - C:\Users\Justinas\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-08-16]
CHR Extension: (Google Drive) - C:\Users\Justinas\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-08-16]
CHR Extension: (SavvyConnect) - C:\Users\Justinas\AppData\Local\Google\Chrome\User Data\Default\Extensions\bbdfnhblopmjjmghkgflplloabcclbmj [2015-08-16]
CHR Extension: (YouTube) - C:\Users\Justinas\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-08-16]
CHR Extension: (Google Search) - C:\Users\Justinas\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-08-16]
CHR Extension: (Google Sheets) - C:\Users\Justinas\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-08-16]
CHR Extension: (AdBlock) - C:\Users\Justinas\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2015-08-16]
CHR Extension: (Avast Online Security) - C:\Users\Justinas\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2015-08-16]
CHR Extension: (Wolfram
Alpha (Official)) - C:\Users\Justinas\AppData\Local\Google\Chrome\User Data\Default\Extensions\icncamkooinmbehmkeilcccmoljfkdhp [2015-08-16]
CHR Extension: (Reddit Enhancement Suite) - C:\Users\Justinas\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbmfpngjjgdllneeigpgjifpgocmfgmb [2015-08-16]
CHR Extension: (Better Battlelog (BBLog)) - C:\Users\Justinas\AppData\Local\Google\Chrome\User Data\Default\Extensions\kjlfnjepjdmlppapoikepbaabbghofma [2015-08-16]
CHR Extension: (Little Alchemy) - C:\Users\Justinas\AppData\Local\Google\Chrome\User Data\Default\Extensions\knkapnclbofjjgicpkfoagdjohlfjhpd [2015-08-16]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Justinas\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-08-16]
CHR Extension: (Google Maps) - C:\Users\Justinas\AppData\Local\Google\Chrome\User Data\Default\Extensions\lneaknkopdijkpnocmklfnjbeapigfbh [2015-08-16]
CHR Extension: (Google Dictionary (by Google)) - C:\Users\Justinas\AppData\Local\Google\Chrome\User Data\Default\Extensions\mgijmajocgfcbeboacabfgobmjgjcoja [2015-08-16]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Justinas\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-08-16]
CHR Extension: (Hover Zoom) - C:\Users\Justinas\AppData\Local\Google\Chrome\User Data\Default\Extensions\nonjdcjchghhkdoolnlbekcfllmednbl [2015-08-16]
CHR Extension: (Universe) - C:\Users\Justinas\AppData\Local\Google\Chrome\User Data\Default\Extensions\oecmlnmneeeeiccpcohlffnipjhngmdk [2015-08-16]
CHR Extension: (Gmail) - C:\Users\Justinas\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-08-16]
 
==================== Services (Whitelisted) ========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S2 AntiVirMailService; C:\Program Files (x86)\Avira\Antivirus\avmailc7.exe [887128 2015-07-15] (Avira Operations GmbH & Co. KG)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\Antivirus\sched.exe [461672 2015-08-26] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\Antivirus\avguard.exe [461672 2015-08-26] (Avira Operations GmbH & Co. KG)
S4 AntiVirWebService; C:\Program Files (x86)\Avira\Antivirus\avwebg7.exe [1213072 2015-08-26] (Avira Operations GmbH & Co. KG)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77128 2015-05-29] (Apple Inc.)
R2 Avira.ServiceHost; C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe [218816 2015-07-02] (Avira Operations GmbH & Co. KG)
S3 BthHFSrv; C:\Windows\System32\BthHFSrv.dll [326144 2015-07-10] (Microsoft Corporation)
S3 CDPSvc; C:\Windows\System32\CDPSvc.dll [134144 2015-07-10] (Microsoft Corporation)
R2 CoreMessagingRegistrar; C:\Windows\system32\coremessaging.dll [808856 2015-07-22] (Microsoft Corporation)
R2 CoreMessagingRegistrar; C:\Windows\SysWOW64\coremessaging.dll [510976 2015-07-22] (Microsoft Corporation)
S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [136048 2015-08-01] (Dropbox, Inc.)
S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [136048 2015-08-01] (Dropbox, Inc.)
S3 diagnosticshub.standardcollector.service; C:\Windows\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe [27136 2015-07-10] (Microsoft Corporation)
S3 DmEnrollmentSvc; C:\Windows\system32\Windows.Internal.Management.dll [267776 2015-07-10] (Microsoft Corporation)
S3 DmEnrollmentSvc; C:\Windows\SysWOW64\Windows.Internal.Management.dll [193024 2015-07-10] (Microsoft Corporation)
S3 embeddedmode; C:\Windows\System32\embeddedmodesvc.dll [87040 2015-07-10] (Microsoft Corporation)
S3 EntAppSvc; C:\Windows\system32\EnterpriseAppMgmtSvc.dll [275456 2015-07-10] (Microsoft Corporation)
S3 GalaxyClientService; C:\Program Files (x86)\GalaxyClient\GalaxyClientService.exe [1720888 2015-08-12] (GOG.com)
S3 GalaxyCommunication; C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe [6874680 2015-08-12] (GOG.com)
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1155216 2015-07-24] (NVIDIA Corporation)
S3 icssvc; C:\Windows\System32\tetheringservice.dll [148992 2015-08-11] (Microsoft Corporation)
R3 lfsvc; C:\Windows\SysWOW64\lfsvc.dll [22528 2015-07-10] (Microsoft Corporation)
R3 LicenseManager; C:\Windows\system32\LicenseManagerSvc.dll [21504 2015-07-10] (Microsoft Corporation)
S2 MapsBroker; C:\Windows\System32\moshost.dll [62464 2015-07-10] (Microsoft Corporation)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1871504 2015-07-24] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [5544592 2015-07-24] (NVIDIA Corporation)
S2 OneSyncSvc; C:\Windows\System32\APHostService.dll [296960 2015-07-10] (Microsoft Corporation)
R2 OneSyncSvc_Session2; C:\Windows\system32\svchost.exe [39856 2015-07-10] (Microsoft Corporation)
R2 OneSyncSvc_Session2; C:\Windows\SysWOW64\svchost.exe [35176 2015-07-10] (Microsoft Corporation)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2007048 2015-08-17] (Electronic Arts)
S3 PimIndexMaintenanceSvc; C:\Windows\System32\PimIndexMaintenance.dll [289280 2015-07-10] (Microsoft Corporation)
R3 PimIndexMaintenanceSvc_Session2; C:\Windows\system32\svchost.exe [39856 2015-07-10] (Microsoft Corporation)
R3 PimIndexMaintenanceSvc_Session2; C:\Windows\SysWOW64\svchost.exe [35176 2015-07-10] (Microsoft Corporation)
S3 RetailDemo; C:\Windows\system32\RDXService.dll [996352 2015-08-11] (Microsoft Corporation)
S3 SensorDataService; C:\Windows\System32\SensorDataService.exe [1031680 2015-07-12] (Microsoft Corporation)
R2 Service KMSELDI; C:\Program Files\KMSpico\Service_KMS.exe [985280 2015-07-22] (@ByELDI) [File not signed]
R3 StateRepository; C:\Windows\system32\windows.staterepository.dll [2674176 2015-07-10] (Microsoft Corporation)
R3 StateRepository; C:\Windows\SysWOW64\windows.staterepository.dll [2049024 2015-07-10] (Microsoft Corporation)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [5613328 2015-07-29] (TeamViewer GmbH)
S3 UnistoreSvc; C:\Windows\System32\unistore.dll [1203200 2015-07-24] (Microsoft Corporation)
S3 UnistoreSvc; C:\Windows\SysWOW64\unistore.dll [925696 2015-07-24] (Microsoft Corporation)
R3 UnistoreSvc_Session2; C:\Windows\System32\svchost.exe [39856 2015-07-10] (Microsoft Corporation)
R3 UnistoreSvc_Session2; C:\Windows\SysWOW64\svchost.exe [35176 2015-07-10] (Microsoft Corporation)
S3 UserDataSvc; C:\Windows\System32\userdataservice.dll [1420288 2015-07-30] (Microsoft Corporation)
R3 UserDataSvc_Session2; C:\Windows\system32\svchost.exe [39856 2015-07-10] (Microsoft Corporation)
R3 UserDataSvc_Session2; C:\Windows\SysWOW64\svchost.exe [35176 2015-07-10] (Microsoft Corporation)
S3 vmicvmsession; C:\Windows\System32\ICSvc.dll [506880 2015-07-10] (Microsoft Corporation)
S3 WalletService; C:\Windows\system32\WalletService.dll [504320 2015-07-10] (Microsoft Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [362928 2015-07-10] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-07-10] (Microsoft Corporation)
S3 XblAuthManager; C:\Windows\System32\XblAuthManager.dll [918016 2015-07-10] (Microsoft Corporation)
S3 XblGameSave; C:\Windows\System32\XblGameSave.dll [1149440 2015-07-10] (Microsoft Corporation)
S3 XboxNetApiSvc; C:\Windows\system32\XboxNetApiSvc.dll [1019392 2015-07-10] (Microsoft Corporation)
 
===================== Drivers (Whitelisted) ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [137288 2015-07-15] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [148632 2015-07-15] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [28600 2015-07-15] (Avira Operations GmbH & Co. KG)
R2 avnetflt; C:\Windows\system32\DRIVERS\avnetflt.sys [43576 2015-07-15] (Avira Operations GmbH & Co. KG)
R3 CompositeBus; C:\Windows\System32\DriverStore\FileRepository\compositebus.inf_amd64_98334ba6e76853ba\CompositeBus.sys [39936 2015-07-10] (Microsoft Corporation)
S0 ebdrv; C:\Windows\System32\drivers\evbda.sys [3436896 2015-07-10] (QLogic Corporation)
R1 FileCrypt; C:\Windows\System32\drivers\filecrypt.sys [83968 2015-07-10] (Microsoft Corporation)
S3 genericusbfn; C:\Windows\System32\drivers\genericusbfn.sys [20992 2015-07-10] (Microsoft Corporation)
R1 GpuEnergyDrv; C:\Windows\System32\drivers\gpuenergydrv.sys [8192 2015-07-10] (Microsoft Corporation)
S3 ibbus; C:\Windows\System32\drivers\ibbus.sys [424800 2015-07-10] (Mellanox)
S3 IoQos; C:\Windows\System32\drivers\ioqos.sys [26624 2015-07-10] (Microsoft Corporation)
S0 LSI_SAS3i; C:\Windows\System32\drivers\lsi_sas3i.sys [99168 2015-07-10] (Avago Technologies)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-06-18] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64216 2015-06-18] (Malwarebytes Corporation)
S3 mlx4_bus; C:\Windows\System32\drivers\mlx4_bus.sys [705376 2015-07-10] (Mellanox)
S3 ndfltr; C:\Windows\System32\drivers\ndfltr.sys [76128 2015-07-10] (Mellanox)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19600 2015-07-24] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [47976 2015-07-03] (NVIDIA Corporation)
R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [587264 2015-07-10] (Realtek                                            )
R2 storqosflt; C:\Windows\System32\drivers\storqosflt.sys [61952 2015-07-10] (Microsoft Corporation)
R3 swenum; C:\Windows\System32\DriverStore\FileRepository\swenum.inf_amd64_2a699e44676b7781\swenum.sys [17760 2015-07-10] (Microsoft Corporation)
S3 UcmCx0101; C:\Windows\System32\Drivers\UcmCx.sys [61952 2015-07-10] (Microsoft Corporation)
S3 UcmUcsi; C:\Windows\System32\drivers\UcmUcsi.sys [46080 2015-07-14] (Microsoft Corporation)
S3 UdeCx; C:\Windows\System32\drivers\udecx.sys [44032 2015-07-10] ()
R0 WindowsTrustedRT; C:\Windows\System32\drivers\WindowsTrustedRT.sys [106520 2015-07-10] (Microsoft Corporation)
R0 WindowsTrustedRTProxy; C:\Windows\System32\drivers\WindowsTrustedRTProxy.sys [17944 2015-07-10] (Microsoft Corporation)
S3 WinMad; C:\Windows\System32\drivers\winmad.sys [26976 2015-07-10] (Mellanox)
S3 WinRing0_1_2_0; C:\Users\Justinas\Desktop\CPU Temp\WinRing0x64.sys [14544 2008-07-26] (OpenLibSys.org)
S3 WinVerbs; C:\Windows\System32\drivers\winverbs.sys [59232 2015-07-10] (Mellanox)
S3 xboxgip; C:\Windows\System32\drivers\xboxgip.sys [222720 2015-07-10] (Microsoft Corporation)
S3 xinputhid; C:\Windows\System32\drivers\xinputhid.sys [25600 2015-07-10] (Microsoft Corporation)
S3 wfpcapture; \SystemRoot\System32\drivers\wfpcapture.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-08-29 02:00 - 2015-08-29 02:01 - 00028596 _____ C:\Users\Justinas\Downloads\FRST.txt
2015-08-29 01:58 - 2015-08-29 02:00 - 00000000 ____D C:\FRST
2015-08-29 01:55 - 2015-08-29 01:55 - 00016148 _____ C:\Windows\system32\DESKTOP-GGB2RP0_Nerijus_HistoryPrediction.bin
2015-08-29 01:55 - 2015-08-29 01:55 - 00016148 _____ C:\Windows\system32\DESKTOP-GGB2RP0_Justinas_HistoryPrediction.bin
2015-08-29 01:53 - 2015-08-29 01:53 - 00000000 ____D C:\Users\Nerijus\AppData\Roaming\Macromedia
2015-08-29 01:53 - 2015-08-29 01:53 - 00000000 ____D C:\Users\Nerijus\AppData\Roaming\Avira
2015-08-29 01:51 - 2015-08-29 01:52 - 00002389 _____ C:\Users\Nerijus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2015-08-29 01:51 - 2015-08-29 01:52 - 00000000 ___RD C:\Users\Nerijus\OneDrive
2015-08-29 01:49 - 2015-08-29 01:58 - 02186752 _____ (Farbar) C:\Users\Justinas\Downloads\FRST64.exe
2015-08-29 01:49 - 2015-08-29 01:49 - 00000000 ____D C:\Users\Nerijus\AppData\Local\MicrosoftEdge
2015-08-29 01:48 - 2015-08-29 01:48 - 00000000 ____D C:\Users\Nerijus\AppData\Local\NVIDIA
2015-08-29 01:48 - 2015-08-29 01:48 - 00000000 ____D C:\Users\Nerijus\AppData\Local\Dropbox
2015-08-29 01:47 - 2015-08-29 01:47 - 00000000 ____D C:\Users\Nerijus\AppData\Local\Publishers
2015-08-29 01:46 - 2015-08-29 01:46 - 00000000 ____D C:\Users\Nerijus\AppData\Roaming\Adobe
2015-08-29 01:46 - 2015-08-29 01:46 - 00000000 ____D C:\Users\Nerijus\AppData\Local\Google
2015-08-29 01:45 - 2015-08-29 01:51 - 00000000 ____D C:\Users\Nerijus
2015-08-29 01:45 - 2015-08-29 01:47 - 00000000 ____D C:\Users\Nerijus\AppData\Local\Packages
2015-08-29 01:45 - 2015-08-29 01:46 - 00000000 ___RD C:\Users\Nerijus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-08-29 01:45 - 2015-08-29 01:45 - 00000020 ___SH C:\Users\Nerijus\ntuser.ini
2015-08-29 01:45 - 2015-08-29 01:45 - 00000000 ____D C:\Users\Nerijus\AppData\Local\VirtualStore
2015-08-29 01:45 - 2015-08-29 01:45 - 00000000 ____D C:\Users\Nerijus\AppData\Local\TileDataLayer
2015-08-29 01:45 - 2015-07-10 14:04 - 00000000 __RSD C:\Users\Nerijus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell
2015-08-29 01:45 - 2015-07-10 14:04 - 00000000 ___RD C:\Users\Nerijus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-08-29 01:45 - 2015-07-10 14:04 - 00000000 ___RD C:\Users\Nerijus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2015-08-29 01:45 - 2015-07-10 14:04 - 00000000 ____D C:\Users\Nerijus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-08-29 00:27 - 2015-08-29 00:27 - 00000000 ____D C:\ProgramData\Riot Games
2015-08-29 00:25 - 2008-07-12 08:18 - 03851784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_39.dll
2015-08-29 00:25 - 2008-07-12 08:18 - 01493528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_39.dll
2015-08-29 00:25 - 2008-07-12 08:18 - 00467984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_39.dll
2015-08-29 00:24 - 2015-08-29 00:24 - 00001585 _____ C:\Users\Public\Desktop\League of Legends.lnk
2015-08-29 00:24 - 2015-08-29 00:24 - 00000000 ____D C:\Riot Games
2015-08-29 00:24 - 2015-08-29 00:24 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\League of Legends
2015-08-29 00:22 - 2015-08-29 00:25 - 00000000 ____D C:\Users\Justinas\AppData\Roaming\Riot Games
2015-08-29 00:19 - 2015-08-29 00:20 - 30668968 _____ (Riot Games) C:\Users\Justinas\Downloads\LeagueofLegends_EUW_Installer_9_15_2014.exe
2015-08-28 14:03 - 2015-08-29 00:41 - 00135680 ___SH C:\Users\Justinas\Desktop\Thumbs.db
2015-08-28 12:45 - 2015-08-28 13:32 - 00000000 ____D C:\Users\Justinas\Downloads\Monsters University (2013) [1080p]
2015-08-28 12:45 - 2015-08-28 12:45 - 00000000 ____D C:\Users\Justinas\Downloads\Wreck-It Ralph (2012) [1080p]
2015-08-28 01:33 - 2015-08-28 13:02 - 00000000 ____D C:\Users\Justinas\Downloads\From Up On Poppy Hill (2011) 1080p [Jpn 5.0 & Eng] Blu-ray (Studio Ghibli)
2015-08-28 01:32 - 2015-08-28 01:34 - 00000000 ____D C:\Users\Justinas\Downloads\The Girl Who Leapt Through Time (2006) 1080p [Jpn 5.1 & Eng 5.1] Blu-ray
2015-08-28 01:31 - 2015-08-28 02:00 - 00000000 ____D C:\Users\Justinas\Downloads\My Neighbor Totoro (1988) 1080p [Jpn & Eng] Blu-ray (Studio Ghibli)
2015-08-28 01:12 - 2015-08-28 01:12 - 00001497 _____ C:\Users\Public\Desktop\FIFA 15.lnk
2015-08-28 01:12 - 2015-08-28 01:12 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FIFA 15
2015-08-28 01:11 - 2015-08-28 01:11 - 00000000 ____D C:\Users\Justinas\Downloads\SC-F-15-UE-C-U
2015-08-28 01:00 - 2015-08-28 01:00 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FIFA 15 Ultimate Team Edition
2015-08-28 00:39 - 2015-08-28 00:39 - 00000000 ____D C:\Program Files (x86)\FIFA 15 Ultimate Team Edition
2015-08-28 00:19 - 2015-08-13 07:22 - 02093056 _____ (Microsoft Corporation) C:\Windows\system32\wlidsvc.dll
2015-08-28 00:19 - 2015-08-13 07:07 - 19323392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-08-28 00:19 - 2015-08-13 06:53 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppXDeploymentClient.dll
2015-08-28 00:19 - 2015-08-11 13:03 - 08021840 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-08-28 00:19 - 2015-08-11 13:03 - 00442208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys
2015-08-28 00:19 - 2015-08-11 13:02 - 00080720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\stornvme.sys
2015-08-28 00:19 - 2015-08-11 12:52 - 00993104 _____ (Microsoft Corporation) C:\Windows\system32\ReAgent.dll
2015-08-28 00:19 - 2015-08-11 12:50 - 01643872 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll
2015-08-28 00:19 - 2015-08-11 12:40 - 04048808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe
2015-08-28 00:19 - 2015-08-11 12:40 - 02151208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfcore.dll
2015-08-28 00:19 - 2015-08-11 12:40 - 00918320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfplat.dll
2015-08-28 00:19 - 2015-08-11 12:38 - 00454000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\directmanipulation.dll
2015-08-28 00:19 - 2015-08-11 12:37 - 00243800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\LockAppHost.exe
2015-08-28 00:19 - 2015-08-11 12:31 - 02880032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-08-28 00:19 - 2015-08-11 12:26 - 00845664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ReAgent.dll
2015-08-28 00:19 - 2015-08-11 12:20 - 02224640 _____ (Microsoft Corporation) C:\Windows\system32\NetworkMobileSettings.dll
2015-08-28 00:19 - 2015-08-11 12:20 - 00483328 _____ (Microsoft Corporation) C:\Windows\system32\OneDriveSettingSyncProvider.dll
2015-08-28 00:19 - 2015-08-11 12:19 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\SettingsHandlers_Notifications.dll
2015-08-28 00:19 - 2015-08-11 12:13 - 00413184 _____ C:\Windows\system32\diagtrack_win.dll
2015-08-28 00:19 - 2015-08-11 12:11 - 00553472 _____ (Microsoft Corporation) C:\Windows\system32\GamePanel.exe
2015-08-28 00:19 - 2015-08-11 12:10 - 00778752 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.dll
2015-08-28 00:19 - 2015-08-11 12:10 - 00324096 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2015-08-28 00:19 - 2015-08-11 12:09 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\wuautoappupdate.dll
2015-08-28 00:19 - 2015-08-11 12:07 - 01178112 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll
2015-08-28 00:19 - 2015-08-11 12:07 - 00593920 _____ (Microsoft Corporation) C:\Windows\system32\wcmsvc.dll
2015-08-28 00:19 - 2015-08-11 12:06 - 07523328 _____ (Microsoft Corporation) C:\Windows\system32\Chakra.dll
2015-08-28 00:19 - 2015-08-11 12:06 - 02662400 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Logon.dll
2015-08-28 00:19 - 2015-08-11 12:05 - 03527168 _____ (Microsoft Corporation) C:\Windows\system32\tquery.dll
2015-08-28 00:19 - 2015-08-11 12:05 - 00996352 _____ (Microsoft Corporation) C:\Windows\system32\RDXService.dll
2015-08-28 00:19 - 2015-08-11 12:03 - 02558976 _____ (Microsoft Corporation) C:\Windows\system32\mssrch.dll
2015-08-28 00:19 - 2015-08-11 12:02 - 03588096 _____ (Microsoft Corporation) C:\Windows\system32\win32kfull.sys
2015-08-28 00:19 - 2015-08-11 12:02 - 00186368 _____ (Microsoft Corporation) C:\Windows\system32\cloudAP.dll
2015-08-28 00:19 - 2015-08-11 12:01 - 01334784 _____ (Microsoft Corporation) C:\Windows\system32\UIAutomationCore.dll
2015-08-28 00:19 - 2015-08-11 12:00 - 00336384 _____ (Microsoft Corporation) C:\Windows\system32\SearchProtocolHost.exe
2015-08-28 00:19 - 2015-08-11 11:59 - 01106432 _____ (Microsoft Corporation) C:\Windows\system32\sysmain.dll
2015-08-28 00:19 - 2015-08-11 11:59 - 00642560 _____ (Microsoft Corporation) C:\Windows\system32\rdbui.dll
2015-08-28 00:19 - 2015-08-11 11:59 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\mssprxy.dll
2015-08-28 00:19 - 2015-08-11 11:59 - 00042496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tetheringclient.dll
2015-08-28 00:19 - 2015-08-11 11:58 - 00372224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\OneDriveSettingSyncProvider.dll
2015-08-28 00:19 - 2015-08-11 11:57 - 13024768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.dll
2015-08-28 00:19 - 2015-08-11 11:57 - 00159744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UserMgrProxy.dll
2015-08-28 00:19 - 2015-08-11 11:51 - 01916928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFMediaEngine.dll
2015-08-28 00:19 - 2015-08-11 11:51 - 01823232 _____ C:\Windows\SysWOW64\InputService.dll
2015-08-28 00:19 - 2015-08-11 11:50 - 00420352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\GamePanel.exe
2015-08-28 00:19 - 2015-08-11 11:50 - 00200704 _____ C:\Windows\SysWOW64\TextInputFramework.dll
2015-08-28 00:19 - 2015-08-11 11:50 - 00131584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Core.TextInput.dll
2015-08-28 00:19 - 2015-08-11 11:49 - 00586752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.dll
2015-08-28 00:19 - 2015-08-11 11:49 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2015-08-28 00:19 - 2015-08-11 11:48 - 00671232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MbaeApiPublic.dll
2015-08-28 00:19 - 2015-08-11 11:47 - 00448512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MbaeApi.dll
2015-08-28 00:19 - 2015-08-11 11:45 - 18805760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\edgehtml.dll
2015-08-28 00:19 - 2015-08-11 11:45 - 01820672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Logon.dll
2015-08-28 00:19 - 2015-08-11 11:43 - 02748416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tquery.dll
2015-08-28 00:19 - 2015-08-11 11:42 - 05454848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Chakra.dll
2015-08-28 00:19 - 2015-08-11 11:40 - 01964544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssrch.dll
2015-08-28 00:19 - 2015-08-11 11:40 - 01593856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dwmcore.dll
2015-08-28 00:19 - 2015-08-11 11:40 - 01112064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIAutomationCore.dll
2015-08-28 00:19 - 2015-08-11 11:39 - 00280576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchProtocolHost.exe
2015-08-28 00:19 - 2015-08-11 11:38 - 00162304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ReInfo.dll
2015-08-28 00:18 - 2015-08-13 07:33 - 24593408 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-08-28 00:18 - 2015-08-13 07:23 - 02178560 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentServer.dll
2015-08-28 00:18 - 2015-08-13 07:20 - 00414208 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentClient.dll
2015-08-28 00:18 - 2015-08-13 07:17 - 01795072 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentExtensions.dll
2015-08-28 00:18 - 2015-08-11 13:04 - 04532304 _____ (Microsoft Corporation) C:\Windows\explorer.exe
2015-08-28 00:18 - 2015-08-11 13:04 - 02462648 _____ (Microsoft Corporation) C:\Windows\system32\mfcore.dll
2015-08-28 00:18 - 2015-08-11 13:04 - 01087296 _____ (Microsoft Corporation) C:\Windows\system32\mfplat.dll
2015-08-28 00:18 - 2015-08-11 13:02 - 00554744 _____ (Microsoft Corporation) C:\Windows\system32\directmanipulation.dll
2015-08-28 00:18 - 2015-08-11 13:02 - 00292856 _____ (Microsoft Corporation) C:\Windows\system32\LockAppHost.exe
2015-08-28 00:18 - 2015-08-11 12:57 - 03622256 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-08-28 00:18 - 2015-08-11 12:23 - 16706560 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.dll
2015-08-28 00:18 - 2015-08-11 12:22 - 21875200 _____ (Microsoft Corporation) C:\Windows\system32\edgehtml.dll
2015-08-28 00:18 - 2015-08-11 12:21 - 00148992 _____ (Microsoft Corporation) C:\Windows\system32\tetheringservice.dll
2015-08-28 00:18 - 2015-08-11 12:21 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\tetheringclient.dll
2015-08-28 00:18 - 2015-08-11 12:18 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\UserMgrProxy.dll
2015-08-28 00:18 - 2015-08-11 12:16 - 02416640 _____ (Microsoft Corporation) C:\Windows\system32\MFMediaEngine.dll
2015-08-28 00:18 - 2015-08-11 12:14 - 00404480 _____ C:\Windows\system32\diagtrack_wininternal.dll
2015-08-28 00:18 - 2015-08-11 12:11 - 02446336 _____ C:\Windows\system32\InputService.dll
2015-08-28 00:18 - 2015-08-11 12:10 - 00293376 _____ C:\Windows\system32\TextInputFramework.dll
2015-08-28 00:18 - 2015-08-11 12:08 - 00893440 _____ (Microsoft Corporation) C:\Windows\system32\MbaeApiPublic.dll
2015-08-28 00:18 - 2015-08-11 12:08 - 00563200 _____ (Microsoft Corporation) C:\Windows\system32\MbaeApi.dll
2015-08-28 00:18 - 2015-08-11 12:07 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\MbaeParserTask.exe
2015-08-28 00:18 - 2015-08-11 12:05 - 00342016 _____ (Microsoft Corporation) C:\Windows\system32\LocationGeofences.dll
2015-08-28 00:18 - 2015-08-11 12:05 - 00269312 _____ (Microsoft Corporation) C:\Windows\system32\LocationFramework.dll
2015-08-28 00:18 - 2015-08-11 12:05 - 00137216 _____ (Microsoft Corporation) C:\Windows\system32\LocationPermissions.dll
2015-08-28 00:18 - 2015-08-11 12:05 - 00078848 _____ (Microsoft Corporation) C:\Windows\system32\LocationFrameworkInternalPS.dll
2015-08-28 00:18 - 2015-08-11 12:02 - 01890304 _____ (Microsoft Corporation) C:\Windows\system32\dwmcore.dll
2015-08-28 00:18 - 2015-08-11 12:02 - 00621056 _____ (Microsoft Corporation) C:\Windows\system32\enterprisecsps.dll
2015-08-28 00:18 - 2015-08-11 12:00 - 00274432 _____ (Microsoft Corporation) C:\Windows\system32\syncutil.dll
2015-08-27 23:32 - 2015-08-27 23:36 - 00000000 ____D C:\Users\Justinas\Downloads\FIFA 15 Ultimate Team Edition.Incl. Update 4-ZM
2015-08-27 23:31 - 2015-08-28 00:54 - 252231215 _____ C:\Users\Justinas\Downloads\SC-F-15-UE-C-U.rar
2015-08-27 21:30 - 2015-08-27 21:38 - 00000000 ____D C:\Users\Justinas\Documents\FIFA 13
2015-08-27 20:52 - 2015-08-19 07:50 - 00609592 _____ (Microsoft Corporation) C:\Windows\system32\ci.dll
2015-08-27 20:04 - 2015-08-27 20:05 - 12875561 _____ C:\Users\Justinas\Downloads\NBA.2K14.Crack.Only-RELOADED.rar
2015-08-26 01:53 - 2015-08-26 01:53 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox
2015-08-23 00:36 - 2015-08-23 00:36 - 00000000 ____D C:\Users\Justinas\AppData\Local\Apps\2.0
2015-08-23 00:35 - 2015-08-23 00:35 - 00120010 _____ C:\Users\Justinas\Downloads\YouTube Video Downloader.zip
2015-08-23 00:28 - 2015-08-23 00:28 - 01996616 _____ (Link64 GmbH) C:\Users\Justinas\Downloads\VDU_install.exe
2015-08-22 23:16 - 2015-08-22 23:16 - 00114229 _____ C:\Users\Justinas\Downloads\HSCT.json
2015-08-22 12:12 - 2015-08-29 01:54 - 00000000 ____D C:\Temp
2015-08-22 12:10 - 2015-08-22 12:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FIFA 13
2015-08-22 11:55 - 2015-08-22 11:55 - 00000000 ____D C:\Program Files\Reference Assemblies
2015-08-22 11:55 - 2015-08-22 11:55 - 00000000 ____D C:\Program Files\MSBuild
2015-08-22 11:55 - 2015-08-22 11:55 - 00000000 ____D C:\Program Files (x86)\Reference Assemblies
2015-08-22 11:55 - 2015-08-22 11:55 - 00000000 ____D C:\Program Files (x86)\MSBuild
2015-08-22 11:52 - 2015-06-17 18:10 - 01166520 _____ (Microsoft Corporation) C:\Windows\system32\PresentationNative_v0300.dll
2015-08-22 11:52 - 2015-06-17 18:10 - 00124112 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-08-22 11:52 - 2015-06-17 18:10 - 00035480 _____ (Microsoft Corporation) C:\Windows\system32\TsWpfWrp.exe
2015-08-22 11:52 - 2015-05-29 21:07 - 00778936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationNative_v0300.dll
2015-08-22 11:52 - 2015-05-29 21:07 - 00102608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2015-08-22 11:52 - 2015-05-29 21:07 - 00035480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TsWpfWrp.exe
2015-08-21 14:22 - 2015-08-21 14:22 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2015-08-20 17:23 - 2015-08-20 21:59 - 00000214 _____ C:\Windows\Tasks\CreateExplorerShellUnelevatedTask.job
2015-08-20 17:21 - 2015-08-20 17:21 - 00000000 ____D C:\Windows\pss
2015-08-20 14:28 - 2015-08-20 14:28 - 00000000 ____D C:\Users\Justinas\AppData\Roaming\2K Sports
2015-08-20 14:27 - 2015-08-28 01:41 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-08-20 14:24 - 2015-08-20 14:24 - 00000168 _____ C:\Windows\SysWOW64\none
2015-08-20 14:15 - 2015-08-20 16:45 - 00000260 _____ C:\Windows\SysWOW64\slp.bat
2015-08-20 14:15 - 2015-08-20 16:45 - 00000135 _____ C:\Windows\SysWOW64\bhnd.vbs
2015-08-20 14:15 - 2015-08-20 14:15 - 00001159 _____ C:\Users\Public\Desktop\NBA 2K14.lnk
2015-08-20 14:15 - 2015-08-20 14:15 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\2K Sports
2015-08-20 14:10 - 2015-08-20 14:10 - 00032256 _____ C:\Windows\SysWOW64\instsrv.exe
2015-08-20 14:10 - 2015-08-20 14:10 - 00000000 ____D C:\Windows\SysWOW64\32
2015-08-20 14:10 - 2015-08-20 14:10 - 00000000 _____ C:\Windows\SysWOW64\64.dat
2015-08-20 14:10 - 2015-08-20 14:09 - 00044032 _____ (NirSoft) C:\Windows\SysWOW64\nircmd.exe
2015-08-20 14:06 - 2015-08-20 14:06 - 00000000 ____D C:\Program Files (x86)\2K Sports
2015-08-20 10:44 - 2015-08-20 10:44 - 00000222 _____ C:\Users\Justinas\Desktop\Rocket League.url
2015-08-20 10:43 - 2015-08-20 10:44 - 00000000 ____D C:\ProgramData\X360CE
2015-08-20 10:43 - 2015-08-20 10:43 - 01378618 _____ C:\Users\Justinas\Downloads\x360ce.zip
2015-08-18 20:16 - 2015-08-18 20:16 - 00002183 _____ C:\Users\Justinas\Desktop\The Witcher® 3 - Wild Hunt.lnk
2015-08-18 20:16 - 2015-08-18 20:16 - 00001834 _____ C:\Users\Justinas\Desktop\Hearthstone.lnk
2015-08-17 20:00 - 2015-08-17 20:00 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\The Witcher® 3 - Wild Hunt [GOG.com]
2015-08-17 11:11 - 2015-08-18 12:04 - 1233606656 _____ C:\Users\Justinas\Downloads\FIFA 15 Ultimate Team Edition.Incl. Update 4-ZM.iso
2015-08-17 03:49 - 2015-08-17 04:12 - 00000000 ____D C:\Users\Justinas\Downloads\Inherent Vice (2014) [1080p]
2015-08-17 02:23 - 2015-08-17 03:07 - 00000000 ____D C:\Users\Justinas\Downloads\Saving Private Ryan (1998) [1080p]
2015-08-17 02:05 - 2015-08-17 03:27 - 00000000 ____D C:\Users\Justinas\Downloads\Pulp Fiction (1994) [1080p]
2015-08-17 00:17 - 2015-08-17 00:21 - 00000000 ____D C:\Program Files (x86)\Origin Games
2015-08-17 00:16 - 2015-08-27 21:30 - 00000000 ____D C:\Users\Justinas\AppData\Local\Origin
2015-08-17 00:16 - 2015-08-19 13:55 - 00000000 ____D C:\Users\Justinas\AppData\Roaming\Origin
2015-08-17 00:16 - 2015-08-17 00:16 - 00000000 ___HD C:\ProgramData\CanonBJ
2015-08-17 00:16 - 2015-08-17 00:16 - 00000000 ____D C:\Windows\system32\STRING
2015-08-17 00:16 - 2013-04-04 05:00 - 00391168 _____ (CANON INC.) C:\Windows\system32\CNMLMBU.DLL
2015-08-17 00:16 - 2013-01-24 16:24 - 00359936 _____ (CANON INC.) C:\Windows\system32\CNMN6PPM.DLL
2015-08-17 00:16 - 2013-01-24 16:24 - 00039424 _____ (CANON INC.) C:\Windows\system32\CNMN6UI.DLL
2015-08-17 00:16 - 2013-01-24 16:23 - 00366592 _____ (CANON INC.) C:\Windows\SysWOW64\CNMNPPM.DLL
2015-08-17 00:15 - 2015-08-17 00:16 - 00000000 ___HD C:\Program Files\CanonBJ
2015-08-17 00:14 - 2015-08-17 00:15 - 27110984 _____ C:\Users\Justinas\Downloads\mp68-win-mg5500-1_02-ea32_2.exe
2015-08-16 23:43 - 2015-08-17 07:41 - 00000000 ____D C:\Users\Justinas\Downloads\Star Wars Episode I, II, III, IV, V, VI - Complete Saga George Lucas Eng Subs 720p [H264-mp4]
2015-08-16 23:43 - 2015-08-17 01:10 - 00000000 ____D C:\Users\Justinas\Downloads\Inception (2010)
2015-08-16 23:42 - 2015-08-16 23:42 - 00000000 ____D C:\Users\Justinas\Downloads\The Maze Runner (2014) [1080p]
2015-08-16 23:35 - 2015-08-28 01:13 - 00000000 ____D C:\ProgramData\Origin
2015-08-16 23:35 - 2015-08-20 13:47 - 00000000 ____D C:\ProgramData\Electronic Arts
2015-08-16 23:35 - 2015-08-17 00:15 - 00000000 ____D C:\Program Files (x86)\Origin
2015-08-16 23:35 - 2015-08-16 23:35 - 00001052 _____ C:\Users\Public\Desktop\Origin.lnk
2015-08-16 23:35 - 2015-08-16 23:35 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Origin
2015-08-16 22:11 - 2015-08-22 10:15 - 00002260 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-08-16 22:11 - 2015-08-16 22:11 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-08-16 22:07 - 2015-08-29 01:47 - 00000930 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-08-16 22:07 - 2015-08-29 01:12 - 00000934 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-08-16 22:07 - 2015-08-16 22:11 - 00000000 ____D C:\Users\Justinas\AppData\Local\Google
2015-08-16 22:07 - 2015-08-16 22:11 - 00000000 ____D C:\Program Files (x86)\Google
2015-08-16 22:07 - 2015-08-16 22:07 - 00003992 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-08-16 22:07 - 2015-08-16 22:07 - 00003760 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2015-08-16 22:06 - 2015-08-16 22:07 - 00931408 _____ (Google Inc.) C:\Users\Justinas\Downloads\ChromeSetup.exe
2015-08-14 17:00 - 2015-08-14 17:00 - 00001822 _____ C:\Users\Public\Desktop\iTunes.lnk
2015-08-14 17:00 - 2015-08-14 17:00 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2015-08-14 17:00 - 2015-08-14 17:00 - 00000000 ____D C:\Program Files\iTunes
2015-08-14 17:00 - 2015-08-14 17:00 - 00000000 ____D C:\Program Files\iPod
2015-08-14 17:00 - 2015-08-14 17:00 - 00000000 ____D C:\Program Files (x86)\iTunes
2015-08-14 15:05 - 2015-08-14 15:14 - 00000000 ____D C:\Users\Justinas\AppData\Local\Mozilla
2015-08-14 15:05 - 2015-08-14 15:08 - 00000000 ____D C:\Users\Justinas\AppData\Roaming\Mozilla
2015-08-14 15:03 - 2015-08-14 15:03 - 00242768 _____ C:\Users\Justinas\Downloads\Firefox Setup Stub 40.0.2.exe
2015-08-13 01:47 - 2015-08-13 01:50 - 00000000 ____D C:\Windows\system32\MRT
2015-08-13 01:47 - 2015-07-28 10:59 - 132483416 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-08-11 22:45 - 2015-08-03 05:18 - 08613200 _____ (Microsoft Corp.) C:\Windows\system32\Windows.Media.Protection.PlayReady.dll
2015-08-11 22:45 - 2015-08-03 05:13 - 22322624 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2015-08-11 22:45 - 2015-08-03 04:56 - 06878256 _____ (Microsoft Corp.) C:\Windows\SysWOW64\Windows.Media.Protection.PlayReady.dll
2015-08-11 22:45 - 2015-08-03 04:50 - 20857848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2015-08-11 22:45 - 2015-08-03 04:18 - 12503552 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-08-11 22:44 - 2015-08-08 10:29 - 01822280 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2015-08-11 22:44 - 2015-08-08 10:19 - 00608936 _____ (Microsoft Corporation) C:\Windows\system32\fontdrvhost.exe
2015-08-11 22:44 - 2015-08-08 10:01 - 01533496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2015-08-11 22:44 - 2015-08-08 09:48 - 00539728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontdrvhost.exe
2015-08-11 22:44 - 2015-08-08 09:40 - 00365056 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2015-08-11 22:44 - 2015-08-08 09:24 - 02415104 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2015-08-11 22:44 - 2015-08-08 09:24 - 01679360 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2015-08-11 22:44 - 2015-08-08 09:15 - 00303104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2015-08-11 22:44 - 2015-08-08 09:00 - 01985024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2015-08-11 22:44 - 2015-08-06 06:17 - 00237392 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdyboost.sys
2015-08-11 22:44 - 2015-08-06 06:17 - 00200528 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\wof.sys
2015-08-11 22:44 - 2015-08-06 05:22 - 00685568 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdiWiFi.sys
2015-08-11 22:44 - 2015-08-05 07:49 - 00783112 _____ (Microsoft Corporation) C:\Windows\system32\mfsvr.dll
2015-08-11 22:44 - 2015-08-05 07:29 - 00644128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfsvr.dll
2015-08-11 22:44 - 2015-08-05 07:00 - 00310784 _____ (Microsoft Corporation) C:\Windows\system32\ActionCenter.dll
2015-08-11 22:44 - 2015-08-05 06:54 - 01274880 _____ (Microsoft Corporation) C:\Windows\system32\wifinetworkmanager.dll
2015-08-11 22:44 - 2015-08-05 06:47 - 01383424 _____ (Microsoft Corporation) C:\Windows\system32\win32kbase.sys
2015-08-11 22:44 - 2015-08-05 06:39 - 00261632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ActionCenter.dll
2015-08-11 22:44 - 2015-08-04 07:07 - 00102752 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mountmgr.sys
2015-08-11 22:44 - 2015-08-04 07:06 - 00583128 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2015-08-11 22:44 - 2015-08-04 07:06 - 00243248 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll
2015-08-11 22:44 - 2015-08-04 06:23 - 00078848 _____ (Microsoft Corporation) C:\Windows\system32\VPNv2CSP.dll
2015-08-11 22:44 - 2015-08-04 05:59 - 01212416 _____ (Microsoft Corporation) C:\Windows\system32\RemoteNaturalLanguage.dll
2015-08-11 22:44 - 2015-08-04 05:47 - 00898560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RemoteNaturalLanguage.dll
2015-08-11 22:44 - 2015-08-03 05:32 - 00306688 _____ (Microsoft Corporation) C:\Windows\system32\NotificationObjFactory.dll
2015-08-11 22:44 - 2015-08-03 05:28 - 00268800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\NotificationObjFactory.dll
2015-08-11 22:44 - 2015-08-03 05:19 - 00505696 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms2.sys
2015-08-11 22:44 - 2015-08-03 05:19 - 00393568 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys
2015-08-11 22:44 - 2015-08-03 05:18 - 01983840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2015-08-11 22:44 - 2015-08-03 05:18 - 00594472 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Internal.Shell.Broker.dll
2015-08-11 22:44 - 2015-08-03 05:18 - 00046432 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msgpiowin32.sys
2015-08-11 22:44 - 2015-08-03 05:17 - 00516960 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBHUB3.SYS
2015-08-11 22:44 - 2015-08-03 05:17 - 00052264 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\wpcfltr.sys
2015-08-11 22:44 - 2015-08-03 05:12 - 00801632 _____ (Microsoft Corporation) C:\Windows\system32\WWAHost.exe
2015-08-11 22:44 - 2015-08-03 04:49 - 00700256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WWAHost.exe
2015-08-11 22:44 - 2015-08-03 04:31 - 00911360 _____ (Microsoft Corporation) C:\Windows\system32\SharedStartModel.dll
2015-08-11 22:44 - 2015-08-03 04:30 - 00253952 _____ (Microsoft Corporation) C:\Windows\system32\SettingsHandlers_UserAccount.dll
2015-08-11 22:44 - 2015-08-03 04:24 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\tileobjserver.dll
2015-08-11 22:44 - 2015-08-03 04:24 - 00282112 _____ (Microsoft Corporation) C:\Windows\system32\VEEventDispatcher.dll
2015-08-11 22:44 - 2015-08-03 04:24 - 00193536 _____ (Microsoft Corporation) C:\Windows\system32\SharedStartModelShim.dll
2015-08-11 22:44 - 2015-08-03 04:23 - 00122880 _____ (Microsoft Corporation) C:\Windows\system32\VEDataLayerHelpers.dll
2015-08-11 22:44 - 2015-08-03 04:22 - 01601536 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Speech.dll
2015-08-11 22:44 - 2015-08-03 04:22 - 01008640 _____ (Microsoft Corporation) C:\Windows\system32\schedsvc.dll
2015-08-11 22:44 - 2015-08-03 04:22 - 00317440 _____ (Microsoft Corporation) C:\Windows\system32\configmanager2.dll
2015-08-11 22:44 - 2015-08-03 04:21 - 00179712 _____ (Microsoft Corporation) C:\Windows\system32\coredpus.dll
2015-08-11 22:44 - 2015-08-03 04:19 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\notepad.exe
2015-08-11 22:44 - 2015-08-03 04:19 - 00215040 _____ (Microsoft Corporation) C:\Windows\notepad.exe
2015-08-11 22:44 - 2015-08-03 04:18 - 03780096 _____ (Microsoft Corporation) C:\Windows\system32\SettingsHandlers_nt.dll
2015-08-11 22:44 - 2015-08-03 04:18 - 00162304 _____ (Microsoft Corporation) C:\Windows\system32\SubscriptionMgr.dll
2015-08-11 22:44 - 2015-08-03 04:18 - 00120832 _____ (Microsoft Corporation) C:\Windows\system32\NetworkStatus.dll
2015-08-11 22:44 - 2015-08-03 04:15 - 01290752 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Shell.dll
2015-08-11 22:44 - 2015-08-03 04:15 - 00595456 _____ (Microsoft Corporation) C:\Windows\system32\LogonController.dll
2015-08-11 22:44 - 2015-08-03 04:15 - 00573440 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Cortana.Desktop.dll
2015-08-11 22:44 - 2015-08-03 04:15 - 00384000 _____ (Microsoft Corporation) C:\Windows\system32\LockAppBroker.dll
2015-08-11 22:44 - 2015-08-03 04:15 - 00171520 _____ (Microsoft Corporation) C:\Windows\system32\WinBioDataModel.dll
2015-08-11 22:44 - 2015-08-03 04:14 - 00273920 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.LockScreen.dll
2015-08-11 22:44 - 2015-08-03 04:14 - 00247808 _____ C:\Windows\system32\facecredentialprovider.dll
2015-08-11 22:44 - 2015-08-03 04:12 - 00217088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\VEEventDispatcher.dll
2015-08-11 22:44 - 2015-08-03 04:12 - 00081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\VEDataLayerHelpers.dll
2015-08-11 22:44 - 2015-08-03 04:11 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\msctfuimanager.dll
2015-08-11 22:44 - 2015-08-03 04:10 - 01162240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Speech.dll
2015-08-11 22:44 - 2015-08-03 04:06 - 00207872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
2015-08-11 22:44 - 2015-08-03 04:03 - 00494592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\LogonController.dll
2015-08-11 22:44 - 2015-08-03 04:02 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\LockAppBroker.dll
2015-08-11 22:44 - 2015-08-03 04:02 - 00195072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.LockScreen.dll
2015-08-11 22:44 - 2015-08-03 04:01 - 11262464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-08-11 22:44 - 2015-08-03 03:59 - 00752640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msctfuimanager.dll
2015-08-10 20:41 - 2015-08-10 20:42 - 00000000 ____D C:\Program Files (x86)\Democracy 3
2015-08-10 15:02 - 2015-08-10 15:02 - 00001682 _____ C:\Users\Public\Desktop\Democracy 3.lnk
2015-08-10 15:02 - 2015-08-10 15:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Democracy 3 [GOG.com]
2015-08-10 15:02 - 2015-08-10 15:02 - 00000000 ____D C:\GOG Games
2015-08-10 14:31 - 2015-08-10 14:41 - 148013192 _____ (GOG.com ) C:\Users\Justinas\Downloads\setup_democracy3_2.0.0.3.exe
2015-08-09 18:52 - 2015-08-09 18:52 - 00330853 _____ C:\Users\Justinas\Downloads\RealTemp_370.zip
2015-08-09 18:52 - 2015-08-09 18:52 - 00000000 ____D C:\Users\Justinas\Desktop\CPU Temp
2015-08-09 15:44 - 2015-08-09 15:44 - 00000000 ____D C:\ProgramData\Last.fm
2015-08-09 15:42 - 2015-08-09 15:44 - 00000000 ____D C:\Users\Justinas\AppData\Roaming\Winamp
2015-08-09 15:42 - 2015-08-09 15:42 - 00001052 _____ C:\Users\Public\Desktop\Winamp.lnk
2015-08-09 15:41 - 2015-08-09 15:41 - 00305664 _____ (Secure By Design Inc.) C:\Users\Justinas\Downloads\Ninite Winamp Installer.exe
2015-08-09 15:39 - 2015-08-09 15:39 - 00305664 _____ (Secure By Design Inc.) C:\Users\Justinas\Downloads\Ninite foobar2000 Installer.exe
2015-08-09 15:30 - 2015-08-27 23:46 - 00000000 ____D C:\Users\Justinas\AppData\Local\Last.fm
2015-08-09 15:30 - 2015-08-09 15:30 - 00001116 _____ C:\Users\Public\Desktop\Last.fm Scrobbler.lnk
2015-08-09 15:30 - 2015-08-09 15:30 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Last.fm
2015-08-09 15:30 - 2015-08-09 15:30 - 00000000 ____D C:\Program Files (x86)\Last.fm
2015-08-09 15:29 - 2015-08-09 15:29 - 15963960 _____ (Last.fm ) C:\Users\Justinas\Downloads\Last.fm-2.1.37.exe
2015-08-09 15:00 - 2015-08-09 15:00 - 00001399 _____ C:\Users\Justinas\Desktop\Life Is Strange.lnk
2015-08-09 15:00 - 2015-08-09 15:00 - 00000000 ____D C:\Users\Justinas\AppData\Roaming\Life Is Strange
2015-08-09 14:46 - 2015-08-09 14:51 - 00000000 ____D C:\Program Files (x86)\Life Is Strange
2015-08-09 14:43 - 2015-08-09 14:43 - 00001124 _____ C:\Users\Justinas\Desktop\Battle.net.lnk
2015-08-08 06:34 - 2015-08-08 06:37 - 00000000 ____D C:\Users\Justinas\Downloads\Jupiter Ascending (2015)
2015-08-08 05:15 - 2015-08-08 05:23 - 00000000 ____D C:\Users\Justinas\Downloads\The Fault in Our Stars (2014)
2015-08-07 07:29 - 2015-08-07 10:42 - 00000000 ____D C:\Users\Justinas\Downloads\[R.G. Mechanics] Life is Strange
2015-08-05 22:42 - 2015-07-30 09:24 - 01561872 _____ (Microsoft Corporation) C:\Windows\system32\winmde.dll
2015-08-05 22:42 - 2015-07-30 09:23 - 00527952 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll
2015-08-05 22:42 - 2015-07-30 09:21 - 00816576 _____ (Microsoft Corporation) C:\Windows\system32\mfmpeg2srcsnk.dll
2015-08-05 22:42 - 2015-07-30 09:17 - 01200400 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2015-08-05 22:42 - 2015-07-30 09:17 - 01025840 _____ (Microsoft Corporation) C:\Windows\system32\mfsrcsnk.dll
2015-08-05 22:42 - 2015-07-30 09:16 - 02147080 _____ (Microsoft Corporation) C:\Windows\system32\d3d9.dll
2015-08-05 22:42 - 2015-07-30 09:15 - 00632168 _____ (Microsoft Corporation) C:\Windows\system32\dxgi.dll
2015-08-05 22:42 - 2015-07-30 09:14 - 00333168 _____ (Microsoft Corporation) C:\Windows\system32\MFPlay.dll
2015-08-05 22:42 - 2015-07-30 09:09 - 01562968 _____ (Microsoft Corporation) C:\Windows\system32\wmpmde.dll
2015-08-05 22:42 - 2015-07-30 09:06 - 01043872 _____ (Microsoft Corporation) C:\Windows\system32\mfmp4srcsnk.dll
2015-08-05 22:42 - 2015-07-30 09:05 - 02498808 _____ C:\Windows\system32\CoreUIComponents.dll
2015-08-05 22:42 - 2015-07-30 09:05 - 00501008 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll
2015-08-05 22:42 - 2015-07-30 09:04 - 01396064 _____ (Microsoft Corporation) C:\Windows\system32\LicenseManager.dll
2015-08-05 22:42 - 2015-07-30 09:03 - 02116448 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2015-08-05 22:42 - 2015-07-30 08:24 - 00252768 _____ (Microsoft Corporation) C:\Windows\system32\ContentDeliveryManager.Utilities.dll
2015-08-05 22:42 - 2015-07-30 07:29 - 00705520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2015-08-05 22:42 - 2015-07-30 07:26 - 01867160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d9.dll
2015-08-05 22:42 - 2015-07-30 07:26 - 00877016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfmp4srcsnk.dll
2015-08-05 22:42 - 2015-07-30 07:25 - 01356368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winmde.dll
2015-08-05 22:42 - 2015-07-30 07:25 - 00713312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfmpeg2srcsnk.dll
2015-08-05 22:42 - 2015-07-30 07:24 - 01769056 _____ C:\Windows\SysWOW64\CoreUIComponents.dll
2015-08-05 22:42 - 2015-07-30 07:24 - 00445240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll
2015-08-05 22:42 - 2015-07-30 07:24 - 00407616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll
2015-08-05 22:42 - 2015-07-30 07:24 - 00285632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFPlay.dll
2015-08-05 22:42 - 2015-07-30 07:22 - 00896144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfsrcsnk.dll
2015-08-05 22:42 - 2015-07-30 07:22 - 00507696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxgi.dll
2015-08-05 22:42 - 2015-07-30 07:21 - 00962400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\LicenseManager.dll
2015-08-05 22:42 - 2015-07-30 07:12 - 00287744 _____ (Microsoft Corporation) C:\Windows\system32\provhandlers.dll
2015-08-05 22:42 - 2015-07-30 07:12 - 00268800 _____ (Microsoft Corporation) C:\Windows\system32\provengine.dll
2015-08-05 22:42 - 2015-07-30 07:09 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\LicenseManagerShellext.exe
2015-08-05 22:42 - 2015-07-30 07:08 - 00494592 _____ (Microsoft Corporation) C:\Windows\system32\StoreAgent.dll
2015-08-05 22:42 - 2015-07-30 07:08 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\InstallAgent.exe
2015-08-05 22:42 - 2015-07-30 07:08 - 00055296 _____ (Microsoft Corporation) C:\Windows\system32\MusNotificationUx.exe
2015-08-05 22:42 - 2015-07-30 06:59 - 00187904 _____ (Microsoft Corporation) C:\Windows\system32\provisioningcsp.dll
2015-08-05 22:42 - 2015-07-30 06:52 - 00859136 _____ (Microsoft Corporation) C:\Windows\system32\modernexecserver.dll
2015-08-05 22:42 - 2015-07-30 06:52 - 00521216 _____ (Microsoft Corporation) C:\Windows\system32\PsmServiceExtHost.dll
2015-08-05 22:42 - 2015-07-30 06:52 - 00075264 _____ (Microsoft Corporation) C:\Windows\system32\ACPBackgroundManagerPolicy.dll
2015-08-05 22:42 - 2015-07-30 06:49 - 11557888 _____ (Microsoft Corporation) C:\Windows\system32\twinui.dll
2015-08-05 22:42 - 2015-07-30 06:46 - 02125312 _____ (Microsoft Corporation) C:\Windows\system32\twinui.appcore.dll
2015-08-05 22:42 - 2015-07-30 06:46 - 00487424 _____ (Microsoft Corporation) C:\Windows\system32\mfmkvsrcsnk.dll
2015-08-05 22:42 - 2015-07-30 06:46 - 00204288 _____ (Microsoft Corporation) C:\Windows\system32\wcmcsp.dll
2015-08-05 22:42 - 2015-07-30 06:45 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\fwpolicyiomgr.dll
2015-08-05 22:42 - 2015-07-30 06:45 - 00155136 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tunnel.sys
2015-08-05 22:42 - 2015-07-30 06:44 - 00280064 _____ (Microsoft Corporation) C:\Windows\system32\AudioEndpointBuilder.dll
2015-08-05 22:42 - 2015-07-30 06:44 - 00229376 _____ (Microsoft Corporation) C:\Windows\system32\SensorService.dll
2015-08-05 22:42 - 2015-07-30 06:44 - 00091648 _____ (Microsoft Corporation) C:\Windows\system32\SensorsNativeApi.V2.dll
2015-08-05 22:42 - 2015-07-30 06:44 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bthhfenum.sys
2015-08-05 22:42 - 2015-07-30 06:44 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\VoiceActivationManager.dll
2015-08-05 22:42 - 2015-07-30 06:42 - 00518144 _____ (Microsoft Corporation) C:\Windows\system32\NotificationController.dll
2015-08-05 22:42 - 2015-07-30 06:41 - 00407040 _____ (Microsoft Corporation) C:\Windows\system32\CredProvDataModel.dll
2015-08-05 22:42 - 2015-07-30 06:41 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\NotificationControllerPS.dll
2015-08-05 22:42 - 2015-07-30 06:40 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\wpncore.dll
2015-08-05 22:42 - 2015-07-30 06:38 - 01420288 _____ (Microsoft Corporation) C:\Windows\system32\UserDataService.dll
2015-08-05 22:42 - 2015-07-30 06:38 - 00080384 _____ (Microsoft Corporation) C:\Windows\system32\AppxSysprep.dll
2015-08-05 22:42 - 2015-07-30 06:34 - 00599552 _____ (Microsoft Corporation) C:\Windows\system32\wpnapps.dll
2015-08-05 22:42 - 2015-07-30 06:29 - 00654848 _____ (Microsoft Corporation) C:\Windows\system32\PlayToManager.dll
2015-08-05 22:42 - 2015-07-30 06:15 - 09889792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinui.dll
2015-08-05 22:42 - 2015-07-30 06:07 - 00163328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fwpolicyiomgr.dll
2015-08-05 22:42 - 2015-07-30 06:06 - 00373248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfmkvsrcsnk.dll
2015-08-05 22:42 - 2015-07-30 06:06 - 00078336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SensorsNativeApi.V2.dll
2015-08-05 22:42 - 2015-07-30 06:06 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\VoiceActivationManager.dll
2015-08-05 22:42 - 2015-07-30 06:04 - 01714176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinui.appcore.dll
2015-08-05 22:42 - 2015-07-30 06:04 - 00335360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CredProvDataModel.dll
2015-08-05 22:42 - 2015-07-30 05:59 - 00473088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wpnapps.dll
2015-08-05 22:42 - 2015-07-30 05:58 - 00497152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PlayToManager.dll
2015-08-03 22:36 - 2015-08-03 22:36 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
2015-08-03 00:39 - 2015-08-03 04:57 - 00000000 ____D C:\Users\Justinas\Downloads\Ted (2012) [1080p]
2015-08-03 00:37 - 2015-08-03 07:52 - 00000000 ____D C:\Users\Justinas\Downloads\Schindlers List (1993)
2015-08-03 00:33 - 2015-08-03 00:33 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\qBittorrent
2015-08-02 12:38 - 2015-08-09 01:24 - 00000000 ____D C:\Users\Justinas\AppData\Roaming\vlc
2015-08-02 02:28 - 2015-08-02 02:28 - 00000000 ____D C:\Windows\system32\SleepStudy
2015-08-01 23:06 - 2015-08-01 23:06 - 00000000 ____D C:\Users\Justinas\AppData\Local\NVIDIA Corporation
2015-08-01 23:06 - 2015-08-01 23:06 - 00000000 ____D C:\Users\Justinas\AppData\Local\NVIDIA
2015-08-01 23:01 - 2015-08-01 23:01 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2015-08-01 23:01 - 2015-07-24 07:21 - 01756608 _____ (NVIDIA Corporation) C:\Windows\system32\nvspbridge64.dll
2015-08-01 23:01 - 2015-07-24 07:21 - 01710568 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll
2015-08-01 23:01 - 2015-07-24 07:21 - 01423304 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll
2015-08-01 23:01 - 2015-07-24 07:21 - 01316000 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspbridge.dll
2015-08-01 23:00 - 2015-07-03 07:28 - 00069992 _____ (NVIDIA Corporation) C:\Windows\system32\nvaudcap64v.dll
2015-08-01 23:00 - 2015-07-03 07:28 - 00065896 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll
2015-08-01 23:00 - 2015-07-03 07:28 - 00047976 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys
2015-08-01 22:54 - 2015-08-01 22:54 - 00000000 ____D C:\Users\Justinas\AppData\Local\GalaxyCommunicationService
2015-08-01 22:21 - 2015-08-01 22:21 - 00000000 ____D C:\Windows\system32\appmgmt
2015-08-01 22:14 - 2015-08-21 22:49 - 00000000 ____D C:\Users\Justinas\Documents\The Witcher 3
2015-08-01 16:09 - 2015-08-01 16:09 - 00000000 ____D C:\Users\Justinas\AppData\Local\TeamViewer
2015-08-01 13:35 - 2015-08-22 12:05 - 00000000 ____D C:\Users\Public\Documents\_Darbai
2015-08-01 13:34 - 2015-08-01 13:34 - 00000000 ____D C:\Program Files (x86)\AGEIA Technologies
2015-08-01 13:34 - 2010-06-02 04:55 - 00527192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_7.dll
2015-08-01 13:34 - 2010-06-02 04:55 - 00518488 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_7.dll
2015-08-01 13:34 - 2010-06-02 04:55 - 00239960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_7.dll
2015-08-01 13:34 - 2010-06-02 04:55 - 00176984 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_7.dll
2015-08-01 13:34 - 2010-06-02 04:55 - 00077656 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_5.dll
2015-08-01 13:34 - 2010-06-02 04:55 - 00074072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_5.dll
2015-08-01 13:34 - 2010-05-26 11:41 - 02526056 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_43.dll
2015-08-01 13:34 - 2010-05-26 11:41 - 02401112 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_43.dll
2015-08-01 13:34 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_43.dll
2015-08-01 13:34 - 2010-05-26 11:41 - 01998168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_43.dll
2015-08-01 13:34 - 2010-05-26 11:41 - 01907552 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_43.dll
2015-08-01 13:34 - 2010-05-26 11:41 - 01868128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dcsx_43.dll
2015-08-01 13:34 - 2010-05-26 11:41 - 00511328 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_43.dll
2015-08-01 13:34 - 2010-05-26 11:41 - 00470880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_43.dll
2015-08-01 13:34 - 2010-05-26 11:41 - 00276832 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_43.dll
2015-08-01 13:34 - 2010-05-26 11:41 - 00248672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx11_43.dll
2015-08-01 13:34 - 2010-02-04 10:01 - 00530776 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_6.dll
2015-08-01 13:34 - 2010-02-04 10:01 - 00528216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_6.dll
2015-08-01 13:34 - 2010-02-04 10:01 - 00238936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_6.dll
2015-08-01 13:34 - 2010-02-04 10:01 - 00176984 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_6.dll
2015-08-01 13:34 - 2010-02-04 10:01 - 00078680 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_4.dll
2015-08-01 13:34 - 2010-02-04 10:01 - 00074072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_4.dll
2015-08-01 13:34 - 2010-02-04 10:01 - 00024920 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_7.dll
2015-08-01 13:34 - 2010-02-04 10:01 - 00022360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_7.dll
2015-08-01 13:34 - 2009-09-04 17:44 - 00517960 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_5.dll
2015-08-01 13:34 - 2009-09-04 17:44 - 00515416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_5.dll
2015-08-01 13:34 - 2009-09-04 17:44 - 00238936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_5.dll
2015-08-01 13:34 - 2009-09-04 17:44 - 00176968 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_5.dll
2015-08-01 13:34 - 2009-09-04 17:44 - 00073544 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_3.dll
2015-08-01 13:34 - 2009-09-04 17:44 - 00069464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_3.dll
2015-08-01 13:34 - 2009-09-04 17:29 - 05554512 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_42.dll
2015-08-01 13:34 - 2009-09-04 17:29 - 05501792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dcsx_42.dll
2015-08-01 13:34 - 2009-09-04 17:29 - 02582888 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_42.dll
2015-08-01 13:34 - 2009-09-04 17:29 - 02475352 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_42.dll
2015-08-01 13:34 - 2009-09-04 17:29 - 01974616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_42.dll
2015-08-01 13:34 - 2009-09-04 17:29 - 01892184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_42.dll
2015-08-01 13:34 - 2009-09-04 17:29 - 00523088 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_42.dll
2015-08-01 13:34 - 2009-09-04 17:29 - 00453456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_42.dll
2015-08-01 13:34 - 2009-09-04 17:29 - 00285024 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_42.dll
2015-08-01 13:34 - 2009-09-04 17:29 - 00235344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx11_42.dll
2015-08-01 13:34 - 2009-03-16 14:18 - 00521560 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_4.dll
2015-08-01 13:34 - 2009-03-16 14:18 - 00517448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_4.dll
2015-08-01 13:34 - 2009-03-16 14:18 - 00235352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_4.dll
2015-08-01 13:34 - 2009-03-16 14:18 - 00174936 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_4.dll
2015-08-01 13:34 - 2009-03-16 14:18 - 00024920 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_6.dll
2015-08-01 13:34 - 2009-03-16 14:18 - 00022360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_6.dll
2015-08-01 13:34 - 2009-03-09 15:27 - 05425496 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_41.dll
2015-08-01 13:34 - 2009-03-09 15:27 - 04178264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_41.dll
2015-08-01 13:34 - 2009-03-09 15:27 - 02430312 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_41.dll
2015-08-01 13:34 - 2009-03-09 15:27 - 01846632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_41.dll
2015-08-01 13:34 - 2009-03-09 15:27 - 00520544 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_41.dll
2015-08-01 13:34 - 2009-03-09 15:27 - 00453456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_41.dll
2015-08-01 13:34 - 2008-10-27 10:04 - 00518480 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_3.dll
2015-08-01 13:34 - 2008-10-27 10:04 - 00514384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_3.dll
2015-08-01 13:34 - 2008-10-27 10:04 - 00074576 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_2.dll
2015-08-01 13:34 - 2008-10-27 10:04 - 00070992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_2.dll
2015-08-01 13:34 - 2008-10-15 06:22 - 05631312 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_40.dll
2015-08-01 13:34 - 2008-10-15 06:22 - 04379984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_40.dll
2015-08-01 13:34 - 2008-10-15 06:22 - 02605920 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_40.dll
2015-08-01 13:34 - 2008-10-15 06:22 - 02036576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_40.dll
2015-08-01 13:34 - 2008-10-15 06:22 - 00519000 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_40.dll
2015-08-01 13:34 - 2008-10-15 06:22 - 00452440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_40.dll
2015-08-01 13:33 - 2015-08-22 06:18 - 00080997 _____ C:\Windows\DirectX.log
2015-08-01 13:33 - 2015-08-01 13:34 - 00000000 ____D C:\Users\Public\Documents\Install
2015-08-01 13:33 - 2008-10-27 10:04 - 00235856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_3.dll
2015-08-01 13:33 - 2008-10-27 10:04 - 00175440 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_3.dll
2015-08-01 13:33 - 2008-10-27 10:04 - 00025936 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_5.dll
2015-08-01 13:33 - 2008-10-27 10:04 - 00023376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_5.dll
2015-08-01 13:33 - 2008-07-31 10:41 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_2.dll
2015-08-01 13:33 - 2008-07-31 10:41 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_2.dll
2015-08-01 13:33 - 2008-07-31 10:41 - 00072200 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_1.dll
2015-08-01 13:33 - 2008-07-31 10:41 - 00068616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_1.dll
2015-08-01 13:33 - 2008-07-31 10:40 - 00513544 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_2.dll
2015-08-01 13:33 - 2008-07-31 10:40 - 00509448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_2.dll
2015-08-01 13:33 - 2008-07-10 11:00 - 04992520 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_39.dll
2015-08-01 13:33 - 2008-07-10 11:00 - 01942552 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_39.dll
2015-08-01 13:33 - 2008-07-10 11:00 - 00540688 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_39.dll
2015-08-01 13:33 - 2008-05-30 14:19 - 00511496 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_1.dll
2015-08-01 13:33 - 2008-05-30 14:19 - 00507400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_1.dll
2015-08-01 13:33 - 2008-05-30 14:18 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_1.dll
2015-08-01 13:33 - 2008-05-30 14:18 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_1.dll
2015-08-01 13:33 - 2008-05-30 14:17 - 00068104 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_0.dll
2015-08-01 13:33 - 2008-05-30 14:17 - 00065032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_0.dll
2015-08-01 13:33 - 2008-05-30 14:17 - 00025608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_4.dll
2015-08-01 13:33 - 2008-05-30 14:16 - 00028168 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_4.dll
2015-08-01 13:33 - 2008-05-30 14:11 - 04991496 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_38.dll
2015-08-01 13:33 - 2008-05-30 14:11 - 03850760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_38.dll
2015-08-01 13:33 - 2008-05-30 14:11 - 01941528 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_38.dll
2015-08-01 13:33 - 2008-05-30 14:11 - 01491992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_38.dll
2015-08-01 13:33 - 2008-05-30 14:11 - 00540688 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_38.dll
2015-08-01 13:33 - 2008-05-30 14:11 - 00467984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_38.dll
2015-08-01 13:33 - 2008-03-05 16:04 - 00489480 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_0.dll
2015-08-01 13:33 - 2008-03-05 16:03 - 00479752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_0.dll
2015-08-01 13:33 - 2008-03-05 16:03 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_0.dll
2015-08-01 13:33 - 2008-03-05 16:03 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_0.dll
2015-08-01 13:33 - 2008-03-05 16:00 - 00028168 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_3.dll
2015-08-01 13:33 - 2008-03-05 16:00 - 00025608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_3.dll
2015-08-01 13:33 - 2008-03-05 15:56 - 04910088 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_37.dll
2015-08-01 13:33 - 2008-03-05 15:56 - 03786760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_37.dll
2015-08-01 13:33 - 2008-03-05 15:56 - 01860120 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_37.dll
2015-08-01 13:33 - 2008-03-05 15:56 - 01420824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_37.dll
2015-08-01 13:33 - 2008-02-05 23:07 - 00529424 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_37.dll
2015-08-01 13:33 - 2008-02-05 23:07 - 00462864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_37.dll
2015-08-01 13:33 - 2007-10-22 03:40 - 00411656 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_10.dll
2015-08-01 13:33 - 2007-10-22 03:39 - 00267272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_10.dll
2015-08-01 13:33 - 2007-10-22 03:37 - 00021000 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_2.dll
2015-08-01 13:33 - 2007-10-22 03:37 - 00017928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_2.dll
2015-08-01 13:33 - 2007-10-12 15:14 - 05081608 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_36.dll
2015-08-01 13:33 - 2007-10-12 15:14 - 03734536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_36.dll
2015-08-01 13:33 - 2007-10-12 15:14 - 02006552 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_36.dll
2015-08-01 13:33 - 2007-10-12 15:14 - 01374232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_36.dll
2015-08-01 13:33 - 2007-10-02 09:56 - 00508264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_36.dll
2015-08-01 13:33 - 2007-10-02 09:56 - 00444776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_36.dll
2015-08-01 13:33 - 2007-07-20 00:57 - 00411496 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_9.dll
2015-08-01 13:33 - 2007-07-20 00:57 - 00267112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_9.dll
2015-08-01 13:33 - 2007-07-19 18:14 - 05073256 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_35.dll
2015-08-01 13:33 - 2007-07-19 18:14 - 03727720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_35.dll
2015-08-01 13:33 - 2007-07-19 18:14 - 01985904 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_35.dll
2015-08-01 13:33 - 2007-07-19 18:14 - 01358192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_35.dll
2015-08-01 13:33 - 2007-07-19 18:14 - 00508264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_35.dll
2015-08-01 13:33 - 2007-07-19 18:14 - 00444776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_35.dll
2015-08-01 13:33 - 2007-06-20 20:49 - 00409960 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_8.dll
2015-08-01 13:33 - 2007-06-20 20:46 - 00266088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_8.dll
2015-08-01 13:33 - 2007-05-16 16:45 - 04496232 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_34.dll
2015-08-01 13:33 - 2007-05-16 16:45 - 03497832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_34.dll
2015-08-01 13:33 - 2007-05-16 16:45 - 01401200 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_34.dll
2015-08-01 13:33 - 2007-05-16 16:45 - 01124720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_34.dll
2015-08-01 13:33 - 2007-05-16 16:45 - 00506728 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_34.dll
2015-08-01 13:33 - 2007-05-16 16:45 - 00443752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_34.dll
2015-08-01 13:33 - 2007-04-04 18:55 - 00403304 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_7.dll
2015-08-01 13:33 - 2007-04-04 18:55 - 00261480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_7.dll
2015-08-01 13:33 - 2007-04-04 18:54 - 00107368 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_3.dll
2015-08-01 13:33 - 2007-04-04 18:53 - 00081768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_3.dll
2015-08-01 13:33 - 2007-03-15 16:57 - 00506728 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_33.dll
2015-08-01 13:33 - 2007-03-15 16:57 - 00443752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_33.dll
2015-08-01 13:33 - 2007-03-12 16:42 - 04494184 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_33.dll
2015-08-01 13:33 - 2007-03-12 16:42 - 03495784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_33.dll
2015-08-01 13:33 - 2007-03-12 16:42 - 01400176 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_33.dll
2015-08-01 13:33 - 2007-03-12 16:42 - 01123696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_33.dll
2015-08-01 13:33 - 2007-03-05 12:42 - 00017688 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_1.dll
2015-08-01 13:33 - 2007-03-05 12:42 - 00015128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\x3daudio1_1.dll
2015-08-01 13:33 - 2007-01-24 15:27 - 00393576 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_6.dll
2015-08-01 13:33 - 2007-01-24 15:27 - 00255848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_6.dll
2015-08-01 13:33 - 2006-12-08 12:02 - 00251672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_5.dll
2015-08-01 13:33 - 2006-12-08 12:00 - 00390424 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_5.dll
2015-08-01 13:33 - 2006-11-29 13:06 - 04398360 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_32.dll
2015-08-01 13:33 - 2006-11-29 13:06 - 03426072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_32.dll
2015-08-01 13:33 - 2006-11-29 13:06 - 00469264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10.dll
2015-08-01 13:33 - 2006-11-29 13:06 - 00440080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10.dll
2015-08-01 13:33 - 2006-09-28 16:05 - 03977496 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_31.dll
2015-08-01 13:33 - 2006-09-28 16:05 - 02414360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_31.dll
2015-08-01 13:33 - 2006-09-28 16:05 - 00237848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_4.dll
2015-08-01 13:33 - 2006-09-28 16:04 - 00364824 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_4.dll
2015-08-01 13:33 - 2006-07-28 09:31 - 00083736 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_2.dll
2015-08-01 13:33 - 2006-07-28 09:30 - 00363288 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_3.dll
2015-08-01 13:33 - 2006-07-28 09:30 - 00236824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_3.dll
2015-08-01 13:33 - 2006-07-28 09:30 - 00062744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_2.dll
2015-08-01 13:33 - 2006-05-31 07:24 - 00230168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_2.dll
2015-08-01 13:33 - 2006-05-31 07:22 - 00354072 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_2.dll
2015-08-01 13:33 - 2006-03-31 12:41 - 03927248 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_30.dll
2015-08-01 13:33 - 2006-03-31 12:40 - 02388176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_30.dll
2015-08-01 13:33 - 2006-03-31 12:40 - 00352464 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_1.dll
2015-08-01 13:33 - 2006-03-31 12:39 - 00229584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_1.dll
2015-08-01 13:33 - 2006-03-31 12:39 - 00083664 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_1.dll
2015-08-01 13:33 - 2006-03-31 12:39 - 00062672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_1.dll
2015-08-01 13:33 - 2006-02-03 08:43 - 03830992 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_29.dll
2015-08-01 13:33 - 2006-02-03 08:43 - 02332368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_29.dll
2015-08-01 13:33 - 2006-02-03 08:42 - 00355536 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_0.dll
2015-08-01 13:33 - 2006-02-03 08:42 - 00230096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_0.dll
2015-08-01 13:33 - 2006-02-03 08:41 - 00016592 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_0.dll
2015-08-01 13:33 - 2006-02-03 08:41 - 00014032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\x3daudio1_0.dll
2015-08-01 13:33 - 2005-12-05 18:09 - 03815120 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_28.dll
2015-08-01 13:33 - 2005-12-05 18:09 - 02323664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_28.dll
2015-08-01 13:33 - 2005-07-22 19:59 - 03807440 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_27.dll
2015-08-01 13:33 - 2005-07-22 19:59 - 02319568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_27.dll
2015-08-01 13:33 - 2005-05-26 15:34 - 03767504 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_26.dll
2015-08-01 13:33 - 2005-05-26 15:34 - 02297552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_26.dll
2015-08-01 13:33 - 2005-03-18 17:19 - 03823312 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_25.dll
2015-08-01 13:33 - 2005-03-18 17:19 - 02337488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_25.dll
2015-08-01 13:33 - 2005-02-05 19:45 - 03544272 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_24.dll
2015-08-01 13:33 - 2005-02-05 19:45 - 02222800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_24.dll
2015-08-01 13:22 - 2015-08-01 13:22 - 00000000 ____D C:\Users\Justinas\Tracing
2015-08-01 13:21 - 2015-08-29 01:40 - 00000000 ____D C:\Users\Justinas\AppData\Roaming\Skype
2015-08-01 13:21 - 2015-08-01 13:21 - 00000000 ____D C:\Users\Justinas\AppData\Local\Skype
2015-08-01 13:13 - 2015-08-01 13:13 - 00000000 ____D C:\Users\Justinas\AppData\Local\Evernote
2015-08-01 13:04 - 2015-08-01 13:04 - 00000000 ____D C:\Users\Justinas\AppData\Local\Adobe
2015-08-01 12:52 - 2015-08-01 02:13 - 00000000 ____D C:\Windows\Panther
2015-08-01 12:45 - 2015-08-09 15:00 - 00000000 ____D C:\ProgramData\Package Cache
2015-08-01 12:45 - 2015-08-04 20:07 - 00002022 _____ C:\Users\Public\Desktop\GOG Galaxy.lnk
2015-08-01 12:45 - 2015-08-04 20:00 - 00000000 ____D C:\Program Files (x86)\GalaxyClient
2015-08-01 12:45 - 2015-08-01 12:45 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GOG.com
2015-08-01 12:45 - 2015-08-01 12:45 - 00000000 ____D C:\ProgramData\GOG.com
2015-08-01 11:40 - 2015-08-01 11:40 - 00000000 ____D C:\Users\Justinas\AppData\Local\Blizzard
2015-08-01 07:03 - 2015-08-10 15:04 - 00000000 ____D C:\Users\Justinas\Documents\My Games
2015-08-01 06:38 - 2015-08-01 06:38 - 00000000 ____D C:\Users\Justinas\AppData\Roaming\Avira
2015-08-01 06:37 - 2015-08-26 15:53 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2015-08-01 06:36 - 2015-07-15 08:37 - 00148632 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys
2015-08-01 06:36 - 2015-07-15 08:37 - 00137288 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2015-08-01 06:36 - 2015-07-15 08:37 - 00043576 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys
2015-08-01 06:36 - 2015-07-15 08:37 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys
2015-08-01 06:35 - 2015-08-02 11:48 - 00000000 ____D C:\ProgramData\Avira
2015-08-01 06:35 - 2015-08-02 11:48 - 00000000 ____D C:\Program Files (x86)\Avira
2015-08-01 05:34 - 2015-08-01 05:34 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-08-01 05:34 - 2015-08-01 05:34 - 00000000 ____D C:\ProgramData\Malwarebytes
2015-08-01 05:34 - 2015-08-01 05:34 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-08-01 05:34 - 2015-06-18 09:23 - 00109272 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-08-01 05:34 - 2015-06-18 09:23 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-08-01 05:34 - 2015-06-18 09:23 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-08-01 05:33 - 2015-08-03 22:36 - 00000000 ____D C:\Users\Justinas\AppData\Roaming\Apple Computer
2015-08-01 05:33 - 2015-08-01 05:33 - 00000000 ____D C:\Users\Justinas\AppData\Local\Apple Computer
2015-08-01 05:32 - 2015-08-14 17:00 - 00000000 ____D C:\Program Files\Common Files\Apple
2015-08-01 05:32 - 2015-08-01 05:32 - 00002535 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
2015-08-01 05:32 - 2015-08-01 05:32 - 00000000 ____D C:\Windows\System32\Tasks\Apple
2015-08-01 05:32 - 2015-08-01 05:32 - 00000000 ____D C:\Users\Justinas\AppData\Local\Apple
2015-08-01 05:32 - 2015-08-01 05:32 - 00000000 ____D C:\ProgramData\Apple Computer
2015-08-01 05:32 - 2015-08-01 05:32 - 00000000 ____D C:\Program Files\Bonjour
2015-08-01 05:32 - 2015-08-01 05:32 - 00000000 ____D C:\Program Files (x86)\Bonjour
2015-08-01 05:32 - 2015-08-01 05:32 - 00000000 ____D C:\Program Files (x86)\Apple Software Update
2015-08-01 05:31 - 2015-08-01 05:32 - 00000000 ____D C:\ProgramData\Apple
2015-08-01 04:09 - 2015-08-02 05:56 - 00000000 ____D C:\Users\Justinas\Downloads\BioShock.Infinite.Complete.Edition.EN-RU.Repack.by.z10yded
2015-08-01 04:07 - 2015-08-28 16:07 - 00000000 ____D C:\Users\Justinas\AppData\Roaming\qBittorrent
2015-08-01 04:07 - 2015-08-01 04:07 - 00000000 ____D C:\Users\Justinas\AppData\Local\qBittorrent
2015-08-01 04:02 - 2015-08-01 04:02 - 00004608 _____ C:\Windows\SECOH-QAD.exe
2015-08-01 04:02 - 2015-08-01 04:02 - 00003584 _____ C:\Windows\SECOH-QAD.dll
2015-08-01 04:00 - 2015-08-01 04:03 - 00000000 ____D C:\Program Files\KMSpico
2015-08-01 04:00 - 2015-08-01 04:00 - 00003482 _____ C:\Windows\System32\Tasks\AutoPico Daily Restart
2015-08-01 04:00 - 2015-08-01 04:00 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\KMSpico
2015-08-01 04:00 - 2010-12-06 05:16 - 00090112 _____ (Vestris Inc.) C:\Windows\system32\Vestris.ResourceLib.dll
2015-08-01 03:56 - 2015-08-01 03:57 - 00000000 ____D C:\Users\Justinas\Downloads\KMSpico v10.0.102040 Beta-P2P
2015-08-01 03:53 - 2015-08-02 11:59 - 00003972 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2015-08-01 03:52 - 2015-08-29 00:12 - 00000000 ___RD C:\Users\Justinas\Dropbox
2015-08-01 03:52 - 2015-08-01 03:52 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2015-08-01 03:52 - 2015-08-01 03:52 - 00001104 __RSH C:\ProgramData\ntuser.pol
2015-08-01 03:52 - 2015-08-01 03:52 - 00000000 ____D C:\Program Files (x86)\Adobe
2015-08-01 03:51 - 2015-08-02 11:58 - 00000000 ____D C:\ProgramData\Adobe
2015-08-01 03:51 - 2015-08-01 03:51 - 00000000 ____D C:\Users\Justinas\AppData\Local\Steam
2015-08-01 03:51 - 2015-08-01 03:51 - 00000000 ____D C:\Users\Justinas\AppData\Local\CEF
2015-08-01 03:45 - 2015-08-29 01:50 - 00000944 _____ C:\Windows\Tasks\DropboxUpdateTaskMachineUA.job
2015-08-01 03:45 - 2015-08-29 01:45 - 00000940 _____ C:\Windows\Tasks\DropboxUpdateTaskMachineCore.job
2015-08-01 03:45 - 2015-08-29 00:12 - 00000000 ____D C:\Users\Justinas\AppData\Local\Dropbox
2015-08-01 03:45 - 2015-08-26 01:53 - 00000000 ____D C:\Program Files (x86)\Dropbox
2015-08-01 03:45 - 2015-08-19 12:21 - 00000000 ____D C:\Program Files (x86)\Hearthstone
2015-08-01 03:45 - 2015-08-01 03:45 - 00004004 _____ C:\Windows\System32\Tasks\DropboxUpdateTaskMachineUA
2015-08-01 03:45 - 2015-08-01 03:45 - 00003772 _____ C:\Windows\System32\Tasks\DropboxUpdateTaskMachineCore
2015-08-01 03:45 - 2015-08-01 03:45 - 00000000 ____D C:\Users\Justinas\AppData\Roaming\Dropbox
2015-08-01 03:45 - 2015-08-01 03:45 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hearthstone
2015-08-01 03:45 - 2015-08-01 03:45 - 00000000 ____D C:\ProgramData\Dropbox
2015-08-01 03:43 - 2015-08-29 01:59 - 00000000 ____D C:\Users\Justinas\AppData\Local\Battle.net
2015-08-01 03:43 - 2015-08-29 00:19 - 00000000 ____D C:\Program Files (x86)\Battle.net
2015-08-01 03:43 - 2015-08-29 00:14 - 00000000 ____D C:\Users\Justinas\AppData\Local\Spotify
2015-08-01 03:43 - 2015-08-01 03:44 - 00000000 ____D C:\Users\Justinas\AppData\Roaming\Battle.net
2015-08-01 03:43 - 2015-08-01 03:43 - 00001865 _____ C:\Users\Justinas\Desktop\Spotify.lnk
2015-08-01 03:43 - 2015-08-01 03:43 - 00001851 _____ C:\Users\Justinas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spotify.lnk
2015-08-01 03:43 - 2015-08-01 03:43 - 00000000 ____D C:\Users\Justinas\AppData\Local\Blizzard Entertainment
2015-08-01 03:43 - 2015-08-01 03:43 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battle.net
2015-08-01 03:43 - 2015-08-01 03:43 - 00000000 ____D C:\ProgramData\Blizzard Entertainment
2015-08-01 03:42 - 2015-08-29 01:49 - 00000000 ____D C:\Users\Justinas\AppData\Roaming\Spotify
2015-08-01 03:39 - 2015-08-01 03:39 - 00002640 _____ C:\Users\Public\Desktop\Skype.lnk
2015-08-01 03:39 - 2015-08-01 03:39 - 00000000 ___RD C:\Program Files (x86)\Skype
2015-08-01 03:39 - 2015-08-01 03:39 - 00000000 ____D C:\ProgramData\Skype
2015-08-01 03:39 - 2015-08-01 03:39 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2015-08-01 03:38 - 2015-08-01 03:38 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2015-08-01 03:38 - 2015-08-01 03:38 - 00000000 ____D C:\Program Files\VideoLAN
2015-08-01 03:37 - 2015-08-09 15:42 - 00000000 ____D C:\Program Files (x86)\Winamp
2015-08-01 03:37 - 2015-08-01 03:37 - 00000000 ____D C:\Users\Justinas\AppData\Local\PeerDistRepub
2015-08-01 03:36 - 2015-08-03 00:33 - 00000000 ____D C:\Program Files (x86)\qBittorrent
2015-08-01 03:35 - 2015-08-01 03:35 - 00000000 ____D C:\ProgramData\Battle.net
2015-08-01 03:34 - 2015-08-28 00:49 - 00000000 ____D C:\Program Files (x86)\Steam
2015-08-01 03:34 - 2015-08-04 20:08 - 00001902 _____ C:\Users\Public\Desktop\Steam.lnk
2015-08-01 03:34 - 2015-08-01 03:35 - 00000000 ____D C:\Program Files (x86)\TeamViewer
2015-08-01 03:34 - 2015-08-01 03:34 - 00001116 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 10.lnk
2015-08-01 03:34 - 2015-08-01 03:34 - 00001104 _____ C:\Users\Public\Desktop\TeamViewer 10.lnk
2015-08-01 03:34 - 2015-08-01 03:34 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
2015-08-01 03:34 - 2015-08-01 03:34 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
2015-08-01 03:34 - 2015-08-01 03:34 - 00000000 ____D C:\Program Files\7-Zip
2015-08-01 03:34 - 2015-08-01 03:33 - 00110688 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll
2015-08-01 03:33 - 2015-08-01 03:33 - 00000000 ____D C:\ProgramData\Sun
2015-08-01 03:33 - 2015-08-01 03:33 - 00000000 ____D C:\Program Files\Java
2015-08-01 03:33 - 2015-08-01 03:32 - 00097888 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2015-08-01 03:32 - 2015-08-01 03:32 - 00000000 ____D C:\Users\Justinas\AppData\Roaming\Macromedia
2015-08-01 03:32 - 2015-08-01 03:32 - 00000000 ____D C:\ProgramData\Oracle
2015-08-01 03:32 - 2015-08-01 03:32 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2015-08-01 03:32 - 2015-08-01 03:32 - 00000000 ____D C:\Program Files (x86)\Java
2015-08-01 02:54 - 2015-08-01 02:54 - 00000000 ____D C:\Users\Justinas\Documents\Sound recordings
2015-08-01 02:39 - 2015-07-05 13:08 - 00300704 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2015-08-01 02:38 - 2015-08-01 02:38 - 00000000 ____D C:\Windows\SysWOW64\RTCOM
2015-08-01 02:38 - 2015-08-01 02:38 - 00000000 ____D C:\Program Files\Realtek
2015-08-01 02:37 - 2015-08-01 02:37 - 04504320 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\Drivers\RTKVHD64.sys
2015-08-01 02:37 - 2015-08-01 02:37 - 03271912 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkApi64.dll
2015-08-01 02:37 - 2015-08-01 02:37 - 03232448 _____ (Fortemedia Corporation) C:\Windows\system32\FMAPO64.dll
2015-08-01 02:37 - 2015-08-01 02:37 - 02926848 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtPgEx64.dll
2015-08-01 02:37 - 2015-08-01 02:37 - 02882408 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RltkAPO64.dll
2015-08-01 02:37 - 2015-08-01 02:37 - 02813457 _____ C:\Windows\system32\Drivers\RTAIODAT.DAT
2015-08-01 02:37 - 2015-08-01 02:37 - 02710784 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTSnMg64.cpl
2015-08-01 02:37 - 2015-08-01 02:37 - 02050184 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioEQ64.dll
2015-08-01 02:37 - 2015-08-01 02:37 - 01756928 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RCoInstII64.dll
2015-08-01 02:37 - 2015-08-01 02:37 - 01336528 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTCOM64.dll
2015-08-01 02:37 - 2015-08-01 02:37 - 00914024 _____ (Creative Technology Ltd.) C:\Windows\system32\MBAPO64.dll
2015-08-01 02:37 - 2015-08-01 02:37 - 00768816 _____ (Creative Technology Ltd.) C:\Windows\SysWOW64\MBAPO32.dll
2015-08-01 02:37 - 2015-08-01 02:37 - 00645456 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtDataProc64.dll
2015-08-01 02:37 - 2015-08-01 02:37 - 00574248 _____ (Andrea Electronics Corporation) C:\Windows\system32\AERTAC64.dll
2015-08-01 02:37 - 2015-08-01 02:37 - 00532384 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSTSX64.dll
2015-08-01 02:37 - 2015-08-01 02:37 - 00410032 _____ (Creative Technology Ltd.) C:\Windows\system32\MBWrp64.dll
2015-08-01 02:37 - 2015-08-01 02:37 - 00387320 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEP64A.dll
2015-08-01 02:37 - 2015-08-01 02:37 - 00343712 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtlCPAPI64.dll
2015-08-01 02:37 - 2015-08-01 02:37 - 00330568 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO20.dll
2015-08-01 02:37 - 2015-08-01 02:37 - 00321720 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RP3DHT64.dll
2015-08-01 02:37 - 2015-08-01 02:37 - 00321720 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RP3DAA64.dll
2015-08-01 02:37 - 2015-08-01 02:37 - 00221968 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSTSH64.dll
2015-08-01 02:37 - 2015-08-01 02:37 - 00214832 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEED64A.dll
2015-08-01 02:37 - 2015-08-01 02:37 - 00209536 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSHP64.dll
2015-08-01 02:37 - 2015-08-01 02:37 - 00176968 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCfg64.dll
2015-08-01 02:37 - 2015-08-01 02:37 - 00166208 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSWOW64.dll
2015-08-01 02:37 - 2015-08-01 02:37 - 00122328 _____ (Real Sound Lab SIA) C:\Windows\system32\CONEQMSAPOGUILibrary.dll
2015-08-01 02:37 - 2015-08-01 02:37 - 00118600 _____ (Andrea Electronics Corporation) C:\Windows\system32\AERTAR64.dll
2015-08-01 02:37 - 2015-08-01 02:37 - 00110984 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEL64A.dll
2015-08-01 02:37 - 2015-08-01 02:37 - 00088352 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEG64A.dll
2015-08-01 02:37 - 2015-08-01 02:37 - 00074608 _____ (Creative Technology Ltd.) C:\Windows\system32\MBppld64.dll
2015-08-01 02:37 - 2015-08-01 02:37 - 00069928 _____ (Creative Technology Ltd.) C:\Windows\system32\MBPPCn64.dll
2015-08-01 02:37 - 2015-08-01 02:37 - 00023696 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCoLDR64.dll
2015-08-01 02:37 - 2015-07-22 06:54 - 14241792 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2015-08-01 02:37 - 2015-07-22 06:11 - 12589056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2015-08-01 02:37 - 2015-07-11 04:17 - 06305792 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Search.dll
2015-08-01 02:37 - 2015-07-11 03:51 - 04398080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Search.dll
2015-08-01 02:36 - 2015-07-26 08:16 - 01018568 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2015-08-01 02:36 - 2015-07-26 08:16 - 00858408 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe
2015-08-01 02:36 - 2015-07-26 08:14 - 01294352 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2015-08-01 02:36 - 2015-07-26 08:14 - 01123400 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
2015-08-01 02:36 - 2015-07-26 08:13 - 06488312 _____ (Microsoft Corporation) C:\Windows\system32\windows.storage.dll
2015-08-01 02:36 - 2015-07-26 07:28 - 05118024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\windows.storage.dll
2015-08-01 02:36 - 2015-07-26 06:49 - 04760576 _____ (Microsoft Corporation) C:\Windows\system32\ExplorerFrame.dll
2015-08-01 02:36 - 2015-07-26 06:49 - 00872448 _____ (Microsoft Corporation) C:\Windows\system32\ntshrui.dll
2015-08-01 02:36 - 2015-07-26 06:47 - 00356352 _____ (Microsoft Corporation) C:\Windows\system32\stobject.dll
2015-08-01 02:36 - 2015-07-26 06:40 - 00850432 _____ (Microsoft Corporation) C:\Windows\system32\comdlg32.dll
2015-08-01 02:36 - 2015-07-26 06:40 - 00542720 _____ (Microsoft Corporation) C:\Windows\system32\SearchFolder.dll
2015-08-01 02:36 - 2015-07-26 06:39 - 00578048 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2015-08-01 02:36 - 2015-07-26 06:39 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\sendmail.dll
2015-08-01 02:36 - 2015-07-26 06:38 - 04350464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ExplorerFrame.dll
2015-08-01 02:36 - 2015-07-26 06:35 - 00322048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\stobject.dll
2015-08-01 02:36 - 2015-07-26 06:34 - 00798208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntshrui.dll
2015-08-01 02:36 - 2015-07-26 06:30 - 00750592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comdlg32.dll
2015-08-01 02:36 - 2015-07-26 06:30 - 00452608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchFolder.dll
2015-08-01 02:36 - 2015-07-26 06:29 - 00104960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sendmail.dll
2015-08-01 02:36 - 2015-07-24 06:30 - 00498016 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
2015-08-01 02:36 - 2015-07-24 06:18 - 00980832 _____ (Microsoft Corporation) C:\Windows\system32\SecConfig.efi
2015-08-01 02:36 - 2015-07-24 06:17 - 00695136 _____ (Microsoft Corporation) C:\Windows\system32\wimgapi.dll
2015-08-01 02:36 - 2015-07-24 06:17 - 00521568 _____ (Microsoft Corporation) C:\Windows\system32\wimserv.exe
2015-08-01 02:36 - 2015-07-24 06:12 - 00584544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wimgapi.dll
2015-08-01 02:36 - 2015-07-24 05:55 - 00503296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Networking.Connectivity.dll
2015-08-01 02:36 - 2015-07-24 05:52 - 00680448 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Networking.Connectivity.dll
2015-08-01 02:36 - 2015-07-24 05:46 - 00303616 _____ (Microsoft Corporation) C:\Windows\system32\MBMediaManager.dll
2015-08-01 02:36 - 2015-07-24 05:44 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\SettingsHandlers_Privacy.dll
2015-08-01 02:36 - 2015-07-24 05:40 - 03248640 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.dll
2015-08-01 02:36 - 2015-07-24 05:39 - 02646528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.dll
2015-08-01 02:36 - 2015-07-24 05:34 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\usocore.dll
2015-08-01 02:36 - 2015-07-24 05:30 - 00799232 _____ (Microsoft Corporation) C:\Windows\system32\wpccpl.dll
2015-08-01 02:36 - 2015-07-24 05:29 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbser.sys
2015-08-01 02:36 - 2015-07-24 05:25 - 01203200 _____ (Microsoft Corporation) C:\Windows\system32\Unistore.dll
2015-08-01 02:36 - 2015-07-24 05:24 - 01418240 _____ (Microsoft Corporation) C:\Windows\system32\RecoveryDrive.exe
2015-08-01 02:36 - 2015-07-24 05:24 - 01061888 _____ (Microsoft Corporation) C:\Windows\system32\reseteng.dll
2015-08-01 02:36 - 2015-07-24 05:24 - 00925696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Unistore.dll
2015-08-01 02:36 - 2015-07-24 05:24 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\ReInfo.dll
2015-08-01 02:36 - 2015-07-22 08:18 - 00808856 _____ (Microsoft Corporation) C:\Windows\system32\CoreMessaging.dll
2015-08-01 02:36 - 2015-07-22 08:15 - 00565088 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\acpi.sys
2015-08-01 02:36 - 2015-07-22 08:02 - 00966424 _____ (Microsoft Corporation) C:\Windows\system32\twinapi.appcore.dll
2015-08-01 02:36 - 2015-07-22 07:13 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\calc.exe
2015-08-01 02:36 - 2015-07-22 07:02 - 00589824 _____ (Microsoft Corporation) C:\Windows\system32\uxtheme.dll
2015-08-01 02:36 - 2015-07-22 07:00 - 02235904 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2015-08-01 02:36 - 2015-07-22 07:00 - 00783872 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2015-08-01 02:36 - 2015-07-22 07:00 - 00169984 _____ (Microsoft Corporation) C:\Windows\system32\storewuauth.dll
2015-08-01 02:36 - 2015-07-22 06:59 - 01773056 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Immersive.dll
2015-08-01 02:36 - 2015-07-22 06:55 - 01203200 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.Bluetooth.dll
2015-08-01 02:36 - 2015-07-22 06:55 - 00421888 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Internal.Bluetooth.dll
2015-08-01 02:36 - 2015-07-22 06:53 - 00762896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinapi.appcore.dll
2015-08-01 02:36 - 2015-07-22 06:46 - 00856064 _____ (Microsoft Corporation) C:\Windows\system32\ContactApis.dll
2015-08-01 02:36 - 2015-07-22 06:21 - 00031232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\calc.exe
2015-08-01 02:36 - 2015-07-22 06:13 - 01611264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Immersive.dll
2015-08-01 02:36 - 2015-07-22 06:13 - 00677888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2015-08-01 02:36 - 2015-07-22 06:10 - 00828416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Bluetooth.dll
2015-08-01 02:36 - 2015-07-22 06:09 - 00296960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Internal.Bluetooth.dll
2015-08-01 02:36 - 2015-07-22 06:07 - 00458752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\uxtheme.dll
2015-08-01 02:36 - 2015-07-22 06:03 - 00623616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ContactApis.dll
2015-08-01 02:36 - 2015-07-22 05:50 - 00510976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CoreMessaging.dll
2015-08-01 02:36 - 2015-07-19 07:04 - 00658568 _____ (Microsoft Corporation) C:\Windows\system32\ClipSVC.dll
2015-08-01 02:36 - 2015-07-19 06:54 - 01168736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys
2015-08-01 02:36 - 2015-07-19 06:23 - 00505344 _____ C:\Windows\system32\EditionUpgradeManagerObj.dll
2015-08-01 02:36 - 2015-07-19 06:18 - 00430592 _____ (Microsoft Corporation) C:\Windows\system32\sppcomapi.dll
2015-08-01 02:36 - 2015-07-19 06:02 - 00590336 _____ (Microsoft Corporation) C:\Windows\system32\MessagingDataModel2.dll
2015-08-01 02:36 - 2015-07-19 05:39 - 00465920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MessagingDataModel2.dll
2015-08-01 02:36 - 2015-07-18 11:47 - 00082616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcd.dll
2015-08-01 02:36 - 2015-07-18 10:43 - 00575488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Import.dll
2015-08-01 02:36 - 2015-07-18 10:37 - 01043968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Editing.dll
2015-08-01 02:36 - 2015-07-18 10:29 - 03443200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIRibbon.dll
2015-08-01 02:36 - 2015-07-18 10:28 - 00584704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIRibbonRes.dll
2015-08-01 02:36 - 2015-07-18 10:28 - 00037376 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2015-08-01 02:36 - 2015-07-18 10:26 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\spbcd.dll
2015-08-01 02:36 - 2015-07-18 08:17 - 00097128 _____ (Microsoft Corporation) C:\Windows\system32\bcd.dll
2015-08-01 02:36 - 2015-07-18 08:02 - 00290312 _____ (Microsoft Corporation) C:\Windows\system32\wininit.exe
2015-08-01 02:36 - 2015-07-18 07:06 - 00841728 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Import.dll
2015-08-01 02:36 - 2015-07-18 06:59 - 01411072 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Editing.dll
2015-08-01 02:36 - 2015-07-18 06:59 - 00232960 _____ (Microsoft Corporation) C:\Windows\system32\DevicesFlowBroker.dll
2015-08-01 02:36 - 2015-07-18 06:52 - 04169728 _____ (Microsoft Corporation) C:\Windows\system32\UIRibbon.dll
2015-08-01 02:36 - 2015-07-18 06:50 - 00584704 _____ (Microsoft Corporation) C:\Windows\system32\UIRibbonRes.dll
2015-08-01 02:36 - 2015-07-18 06:50 - 00045568 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2015-08-01 02:36 - 2015-07-18 06:49 - 00416256 _____ (Microsoft Corporation) C:\Windows\system32\bcdedit.exe
2015-08-01 02:36 - 2015-07-18 06:49 - 00186880 _____ (Microsoft Corporation) C:\Windows\system32\BootMenuUX.dll
2015-08-01 02:36 - 2015-07-18 06:49 - 00084480 _____ (Microsoft Corporation) C:\Windows\system32\spbcd.dll
2015-08-01 02:36 - 2015-07-18 06:48 - 00185856 _____ (Microsoft Corporation) C:\Windows\system32\psmsrv.dll
2015-08-01 02:36 - 2015-07-18 06:48 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\bcdboot.exe
2015-08-01 02:36 - 2015-07-18 06:47 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2015-08-01 02:36 - 2015-07-17 07:23 - 00934752 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\refsv1.sys
2015-08-01 02:36 - 2015-07-17 07:13 - 00601344 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2015-08-01 02:36 - 2015-07-17 07:12 - 00630160 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
2015-08-01 02:36 - 2015-07-17 07:07 - 00425824 _____ (Microsoft Corporation) C:\Windows\system32\hal.dll
2015-08-01 02:36 - 2015-07-17 05:39 - 00446976 _____ (Microsoft Corporation) C:\Windows\system32\MapConfiguration.dll
2015-08-01 02:36 - 2015-07-17 05:39 - 00107520 _____ (Microsoft Corporation) C:\Windows\system32\dwmapi.dll
2015-08-01 02:36 - 2015-07-17 05:36 - 07569408 _____ (Microsoft Corporation) C:\Windows\system32\mos.dll
2015-08-01 02:36 - 2015-07-17 05:33 - 00120832 _____ (Microsoft Corporation) C:\Windows\system32\omadmclient.exe
2015-08-01 02:36 - 2015-07-17 05:33 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\omadmprc.exe
2015-08-01 02:36 - 2015-07-17 05:32 - 00329728 _____ (Microsoft Corporation) C:\Windows\system32\MusUpdateHandlers.dll
2015-08-01 02:36 - 2015-07-17 05:31 - 01417216 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2015-08-01 02:36 - 2015-07-17 05:26 - 07051264 _____ (Microsoft Corporation) C:\Windows\system32\BingMaps.dll
2015-08-01 02:36 - 2015-07-17 05:26 - 00584704 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.Sensors.dll
2015-08-01 02:36 - 2015-07-17 05:24 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\efscore.dll
2015-08-01 02:36 - 2015-07-17 05:19 - 00869376 _____ (Microsoft Corporation) C:\Windows\system32\MapControlCore.dll
2015-08-01 02:36 - 2015-07-17 05:19 - 00832512 _____ (Microsoft Corporation) C:\Windows\system32\MapsStore.dll
2015-08-01 02:36 - 2015-07-17 05:18 - 00902656 _____ (Microsoft Corporation) C:\Windows\system32\SearchIndexer.exe
2015-08-01 02:36 - 2015-07-17 05:05 - 00328704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MapConfiguration.dll
2015-08-01 02:36 - 2015-07-17 05:05 - 00093696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dwmapi.dll
2015-08-01 02:36 - 2015-07-17 04:56 - 06101504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mos.dll
2015-08-01 02:36 - 2015-07-17 04:53 - 00437248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Sensors.dll
2015-08-01 02:36 - 2015-07-17 04:51 - 05076480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\BingMaps.dll
2015-08-01 02:36 - 2015-07-17 04:50 - 00589312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\efscore.dll
2015-08-01 02:36 - 2015-07-17 04:44 - 00712192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchIndexer.exe
2015-08-01 02:36 - 2015-07-16 08:39 - 00061280 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dam.sys
2015-08-01 02:36 - 2015-07-16 07:09 - 00150528 _____ (Microsoft Corporation) C:\Windows\system32\MusNotification.exe
2015-08-01 02:36 - 2015-07-16 07:04 - 01201664 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Cred.dll
2015-08-01 02:36 - 2015-07-16 07:03 - 00060928 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Cortana.OneCore.dll
2015-08-01 02:36 - 2015-07-16 07:01 - 00193024 _____ (Microsoft Corporation) C:\Windows\system32\EnterpriseModernAppMgmtCSP.dll
2015-08-01 02:36 - 2015-07-16 06:54 - 00137216 _____ (Microsoft Corporation) C:\Windows\system32\VEStoreEventHandlers.dll
2015-08-01 02:36 - 2015-07-16 06:47 - 00754688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Cred.dll
2015-08-01 02:36 - 2015-07-16 06:45 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\winhttp.dll
2015-08-01 02:36 - 2015-07-16 06:44 - 02741760 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-08-01 02:36 - 2015-07-16 06:43 - 01602560 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-08-01 02:36 - 2015-07-16 06:41 - 00271872 _____ (Microsoft Corporation) C:\Windows\system32\ConsoleLogon.dll
2015-08-01 02:36 - 2015-07-16 06:40 - 00181760 _____ (Microsoft Corporation) C:\Windows\system32\shutdownux.dll
2015-08-01 02:36 - 2015-07-16 06:36 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\ConhostV2.dll
2015-08-01 02:36 - 2015-07-16 06:35 - 01521664 _____ (Microsoft Corporation) C:\Windows\system32\ActiveSyncProvider.dll
2015-08-01 02:36 - 2015-07-16 06:33 - 00208384 _____ (Microsoft Corporation) C:\Windows\system32\srumsvc.dll
2015-08-01 02:36 - 2015-07-16 06:32 - 00667136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winhttp.dll
2015-08-01 02:36 - 2015-07-16 06:29 - 01380864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-08-01 02:36 - 2015-07-16 06:27 - 02207744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-08-01 02:36 - 2015-07-16 06:19 - 00179200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srumsvc.dll
2015-08-01 02:36 - 2015-07-15 06:21 - 01365072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2015-08-01 02:36 - 2015-07-15 05:49 - 01591856 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2015-08-01 02:36 - 2015-07-15 05:49 - 00325984 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\pci.sys
2015-08-01 02:36 - 2015-07-15 05:41 - 01135312 _____ (Microsoft Corporation) C:\Windows\system32\ClipUp.exe
2015-08-01 02:36 - 2015-07-15 05:22 - 02112512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\actxprxy.dll
2015-08-01 02:36 - 2015-07-15 05:16 - 00251392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SensorsApi.dll
2015-08-01 02:36 - 2015-07-15 05:04 - 00032768 _____ C:\Windows\system32\LicenseManagerApi.dll
2015-08-01 02:36 - 2015-07-15 04:57 - 00204288 _____ (Microsoft Corporation) C:\Windows\system32\OmaDmAgent.dll
2015-08-01 02:36 - 2015-07-15 04:47 - 04611584 _____ (Microsoft Corporation) C:\Windows\system32\actxprxy.dll
2015-08-01 02:36 - 2015-07-15 04:41 - 00310784 _____ (Microsoft Corporation) C:\Windows\system32\SensorsApi.dll
2015-08-01 02:36 - 2015-07-15 04:37 - 00068096 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Cortana.ProxyStub.dll
2015-08-01 02:36 - 2015-07-15 04:35 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\unenrollhook.dll
2015-08-01 02:36 - 2015-07-15 04:27 - 00056320 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Cortana.PAL.Desktop.dll
2015-08-01 02:36 - 2015-07-14 06:00 - 00208736 _____ (Microsoft Corporation) C:\Windows\system32\AppxAllUserStore.dll
2015-08-01 02:36 - 2015-07-14 05:37 - 00181088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppxAllUserStore.dll
2015-08-01 02:36 - 2015-07-14 05:04 - 00046080 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\UcmUcsi.sys
2015-08-01 02:36 - 2015-07-14 04:51 - 00151040 _____ (Microsoft Corporation) C:\Windows\system32\TabSvc.dll
2015-08-01 02:36 - 2015-07-14 04:49 - 00366592 _____ (Microsoft Corporation) C:\Windows\system32\wuuhext.dll
2015-08-01 02:36 - 2015-07-14 04:38 - 00291840 _____ (Microsoft Corporation) C:\Windows\system32\systemcpl.dll
2015-08-01 02:36 - 2015-07-14 04:20 - 00279552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\systemcpl.dll
2015-08-01 02:36 - 2015-07-13 03:01 - 00342528 _____ (Microsoft Corporation) C:\Windows\system32\bcastdvr.exe
2015-08-01 02:36 - 2015-07-13 02:30 - 00275456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcastdvr.exe
2015-08-01 02:36 - 2015-07-12 03:38 - 00242176 _____ (Microsoft Corporation) C:\Windows\system32\updatehandlers.dll
2015-08-01 02:36 - 2015-07-12 03:25 - 01031680 _____ (Microsoft Corporation) C:\Windows\system32\SensorDataService.exe
2015-08-01 02:36 - 2015-07-12 03:18 - 00679424 _____ (Microsoft Corporation) C:\Windows\system32\AppContracts.dll
2015-08-01 02:36 - 2015-07-12 02:46 - 00441344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppContracts.dll
2015-08-01 02:36 - 2015-07-11 04:28 - 00414720 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.BioFeedback.dll
2015-08-01 02:36 - 2015-07-11 04:07 - 00485888 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.BlockedShutdown.dll
2015-08-01 02:36 - 2015-07-11 04:05 - 00263168 _____ (Microsoft Corporation) C:\Windows\system32\DisplayManager.dll
2015-08-01 02:36 - 2015-07-11 04:04 - 03362816 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2015-08-01 02:36 - 2015-07-11 04:03 - 03248128 _____ (Microsoft Corporation) C:\Windows\system32\msftedit.dll
2015-08-01 02:36 - 2015-07-11 04:03 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\msiexec.exe
2015-08-01 02:36 - 2015-07-11 04:02 - 00283648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.BioFeedback.dll
2015-08-01 02:36 - 2015-07-11 04:01 - 04791296 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-08-01 02:36 - 2015-07-11 03:57 - 00670208 _____ (Microsoft Corporation) C:\Windows\system32\ieproxy.dll
2015-08-01 02:36 - 2015-07-11 03:43 - 00322048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.BlockedShutdown.dll
2015-08-01 02:36 - 2015-07-11 03:42 - 00191488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DisplayManager.dll
2015-08-01 02:36 - 2015-07-11 03:41 - 03687936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2015-08-01 02:36 - 2015-07-11 03:40 - 03579904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-08-01 02:36 - 2015-07-11 03:40 - 02606080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msftedit.dll
2015-08-01 02:36 - 2015-07-11 03:40 - 00058368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msiexec.exe
2015-08-01 02:36 - 2015-07-11 03:34 - 00294912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieproxy.dll
2015-08-01 02:36 - 2015-07-10 18:51 - 00823336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MrmCoreR.dll
2015-08-01 02:36 - 2015-07-10 18:47 - 00265480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2015-08-01 02:36 - 2015-07-10 18:00 - 01101792 _____ (Microsoft Corporation) C:\Windows\system32\MrmCoreR.dll
2015-08-01 02:36 - 2015-07-10 17:52 - 00335248 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2015-08-01 02:36 - 2015-07-10 13:59 - 00179712 _____ (Microsoft Corporation) C:\Windows\system32\SettingsHandlers_SignInOptions.dll
2015-08-01 02:36 - 2015-07-10 13:42 - 00045056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\hmkd.dll
2015-08-01 02:36 - 2015-07-10 13:10 - 00057856 _____ (Microsoft Corporation) C:\Windows\system32\hmkd.dll
2015-08-01 02:36 - 2015-07-10 13:07 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\PackageInspector.exe
2015-08-01 02:36 - 2015-07-10 13:05 - 00480256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MCRecvSrc.dll
2015-08-01 02:36 - 2015-07-10 12:53 - 01169408 _____ (Microsoft Corporation) C:\Windows\system32\dosvc.dll
2015-08-01 02:36 - 2015-07-10 12:35 - 00359936 _____ (Microsoft Corporation) C:\Windows\system32\ncsi.dll
2015-08-01 02:36 - 2015-07-10 12:31 - 01067520 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
2015-08-01 02:36 - 2015-07-10 12:29 - 00569344 _____ (Microsoft Corporation) C:\Windows\system32\MCRecvSrc.dll
2015-08-01 02:31 - 2015-08-01 23:06 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2015-08-01 02:31 - 2015-08-01 23:01 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2015-08-01 02:31 - 2015-08-01 23:01 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2015-08-01 02:31 - 2015-08-01 02:31 - 42730312 _____ C:\Windows\system32\nvcompiler.dll
2015-08-01 02:31 - 2015-08-01 02:31 - 37749064 _____ C:\Windows\SysWOW64\nvcompiler.dll
2015-08-01 02:31 - 2015-08-01 02:31 - 30518928 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2015-08-01 02:31 - 2015-08-01 02:31 - 22973584 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2015-08-01 02:31 - 2015-08-01 02:31 - 18376584 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll
2015-08-01 02:31 - 2015-08-01 02:31 - 16160440 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2015-08-01 02:31 - 2015-08-01 02:31 - 16011680 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
2015-08-01 02:31 - 2015-08-01 02:31 - 15754192 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
2015-08-01 02:31 - 2015-08-01 02:31 - 14511608 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2015-08-01 02:31 - 2015-08-01 02:31 - 13274904 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2015-08-01 02:31 - 2015-08-01 02:31 - 12973680 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll
2015-08-01 02:31 - 2015-08-01 02:31 - 11843384 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2015-08-01 02:31 - 2015-08-01 02:31 - 11142984 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2015-08-01 02:31 - 2015-08-01 02:31 - 03351864 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll
2015-08-01 02:31 - 2015-08-01 02:31 - 02963208 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
2015-08-01 02:31 - 2015-08-01 02:31 - 02360976 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2015-08-01 02:31 - 2015-08-01 02:31 - 02164040 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2015-08-01 02:31 - 2015-08-01 02:31 - 01898128 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6435362.dll
2015-08-01 02:31 - 2015-08-01 02:31 - 01557648 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6435362.dll
2015-08-01 02:31 - 2015-08-01 02:31 - 01165192 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll
2015-08-01 02:31 - 2015-08-01 02:31 - 01061008 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2015-08-01 02:31 - 2015-08-01 02:31 - 01053000 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2015-08-01 02:31 - 2015-08-01 02:31 - 00991152 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
2015-08-01 02:31 - 2015-08-01 02:31 - 00983368 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2015-08-01 02:31 - 2015-08-01 02:31 - 00976528 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2015-08-01 02:31 - 2015-08-01 02:31 - 00176904 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll
2015-08-01 02:31 - 2015-08-01 02:31 - 00155280 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
2015-08-01 02:31 - 2015-08-01 02:31 - 00150832 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll
2015-08-01 02:31 - 2015-08-01 02:31 - 00128512 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll
2015-08-01 02:31 - 2015-08-01 02:31 - 00112784 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll
2015-08-01 02:31 - 2015-08-01 02:31 - 00031976 _____ C:\Windows\system32\nvinfo.pb
2015-08-01 02:24 - 2015-08-01 02:24 - 00001051 _____ C:\Users\Justinas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Optional Features.lnk
2015-08-01 02:24 - 2015-07-09 20:37 - 01870848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MLS2.dll
2015-08-01 02:24 - 2015-07-09 20:36 - 06225920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\NlsLexicons0027.dll
2015-08-01 02:24 - 2015-07-09 20:36 - 00131072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\NlsData0027.dll
2015-08-01 02:24 - 2015-07-09 20:26 - 01909248 _____ (Microsoft Corporation) C:\Windows\system32\MLS2.dll
2015-08-01 02:24 - 2015-07-09 20:25 - 06225920 _____ (Microsoft Corporation) C:\Windows\system32\NlsLexicons0027.dll
2015-08-01 02:24 - 2015-07-09 20:25 - 00174592 _____ (Microsoft Corporation) C:\Windows\system32\NlsData0027.dll
2015-08-01 02:21 - 2015-08-01 13:02 - 00000000 ____D C:\Users\Justinas\AppData\Local\Comms
2015-08-01 02:18 - 2015-08-01 02:40 - 00000000 ____D C:\Users\Justinas\AppData\Local\MicrosoftEdge
2015-08-01 02:17 - 2015-08-08 17:18 - 00000000 ___RD C:\Users\Justinas\OneDrive
2015-08-01 02:17 - 2015-08-01 02:18 - 00002347 _____ C:\Users\Justinas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2015-08-01 02:17 - 2015-08-01 02:17 - 00000000 ____D C:\ProgramData\Microsoft OneDrive
2015-08-01 02:16 - 2015-08-01 02:16 - 00000000 ____D C:\Users\Justinas\AppData\Local\Publishers
2015-08-01 02:15 - 2015-08-20 14:21 - 00000000 ____D C:\Users\Justinas
2015-08-01 02:15 - 2015-08-04 19:49 - 00000000 ____D C:\Users\Justinas\AppData\Local\Packages
2015-08-01 02:15 - 2015-08-01 13:04 - 00000000 ____D C:\Users\Justinas\AppData\Roaming\Adobe
2015-08-01 02:15 - 2015-08-01 02:15 - 00016148 _____ C:\Windows\system32\DESKTOP-GGB2RP0_defaultuser0_HistoryPrediction.bin
2015-08-01 02:15 - 2015-08-01 02:15 - 00000020 ___SH C:\Users\Justinas\ntuser.ini
2015-08-01 02:15 - 2015-08-01 02:15 - 00000000 ___RD C:\Users\Justinas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-08-01 02:15 - 2015-08-01 02:15 - 00000000 ____D C:\Users\Justinas\AppData\Local\VirtualStore
2015-08-01 02:15 - 2015-08-01 02:15 - 00000000 ____D C:\Users\Justinas\AppData\Local\TileDataLayer
2015-08-01 02:15 - 2015-07-10 14:04 - 00000000 __RSD C:\Users\Justinas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell
2015-08-01 02:15 - 2015-07-10 14:04 - 00000000 ___RD C:\Users\Justinas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-08-01 02:15 - 2015-07-10 14:04 - 00000000 ___RD C:\Users\Justinas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2015-08-01 02:15 - 2015-07-10 14:04 - 00000000 ____D C:\Users\Justinas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-08-01 02:11 - 2015-08-01 02:11 - 00016148 _____ C:\Windows\system32\DESKTOP-K4N3H1D_defaultuser0_HistoryPrediction.bin
2015-08-01 02:02 - 2015-08-21 20:42 - 00830266 _____ C:\Windows\system32\PerfStringBackup.INI
2015-08-01 01:58 - 2015-08-01 01:58 - 00000000 ____D C:\Windows\CSC
2015-08-01 01:57 - 2015-08-01 01:57 - 00000000 __SHD C:\Recovery
2015-08-01 01:55 - 2015-07-10 13:59 - 02718208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PrintConfig.dll
2015-08-01 01:53 - 2015-08-28 04:03 - 00175002 _____ C:\Windows\PFRO.log
2015-08-01 01:53 - 2015-08-01 01:53 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
2015-07-31 20:00 - 2015-08-22 12:05 - 00000000 ____D C:\Users\Public\Documents\ievos
2015-07-31 19:44 - 2015-08-23 09:30 - 00000000 ____D C:\Users\Justinas\Documents\backup
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-08-29 01:47 - 2015-07-10 14:04 - 00000000 ____D C:\Windows\AppReadiness
2015-08-29 01:45 - 2015-07-10 15:22 - 00000275 _____ C:\Windows\WindowsUpdate.log
2015-08-29 01:12 - 2015-07-10 14:04 - 00000000 ____D C:\Windows\system32\sru
2015-08-28 12:41 - 2015-07-10 13:55 - 00000000 ____D C:\Windows\CbsTemp
2015-08-28 04:03 - 2015-07-10 15:21 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-08-28 04:02 - 2015-07-10 12:05 - 00524288 ___SH C:\Windows\system32\config\BBI
2015-08-28 04:01 - 2015-07-10 14:04 - 00000000 ____D C:\Windows\system32\WinBioPlugIns
2015-08-28 04:01 - 2015-07-10 14:04 - 00000000 ____D C:\Windows\system32\appraiser
2015-08-22 17:21 - 2015-07-10 14:04 - 00000000 ____D C:\Windows\rescache
2015-08-21 20:39 - 2015-07-10 15:20 - 00010381 _____ C:\Windows\setupact.log
2015-08-17 00:19 - 2015-07-10 14:04 - 00000000 ____D C:\Windows\system32\NDF
2015-08-14 11:47 - 2015-07-10 15:20 - 00197880 _____ C:\Windows\system32\FNTCACHE.DAT
2015-08-14 11:45 - 2015-07-10 14:04 - 00000000 ___RD C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-08-14 11:45 - 2015-07-10 14:04 - 00000000 ___RD C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-08-14 11:45 - 2015-07-10 14:04 - 00000000 ____D C:\Windows\system32\oobe
2015-08-08 18:38 - 2015-07-10 14:06 - 00794088 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-08-08 18:38 - 2015-07-10 14:06 - 00179688 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-08-07 07:16 - 2015-07-10 14:04 - 00000000 ____D C:\Windows\Provisioning
2015-08-01 13:33 - 2015-07-10 14:04 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2015-08-01 12:51 - 2015-07-10 14:04 - 00028672 _____ C:\Windows\system32\config\BCD-Template
2015-08-01 03:50 - 2015-07-10 14:04 - 00000000 ___HD C:\Windows\system32\GroupPolicy
2015-08-01 03:27 - 2015-07-10 14:04 - 00000000 ____D C:\Windows\appcompat
2015-08-01 02:49 - 2015-07-10 14:04 - 00000000 ___RD C:\Windows\PurchaseDialog
2015-08-01 02:49 - 2015-07-10 14:04 - 00000000 ___RD C:\Windows\ImmersiveControlPanel
2015-08-01 02:49 - 2015-07-10 14:04 - 00000000 ____D C:\Windows\SysWOW64\oobe
2015-08-01 02:49 - 2015-07-10 14:04 - 00000000 ____D C:\Windows\system32\SystemResetPlatform
2015-08-01 02:49 - 2015-07-10 12:05 - 00000000 ____D C:\Windows\SysWOW64\Dism
2015-08-01 02:49 - 2015-07-10 12:05 - 00000000 ____D C:\Windows\system32\Dism
2015-08-01 02:31 - 2015-07-10 14:00 - 00105288 _____ (Khronos Group) C:\Windows\SysWOW64\opencl.dll
2015-08-01 02:22 - 2015-07-10 14:04 - 00000000 ____D C:\Windows\system32\WinBioDatabase
2015-08-01 02:15 - 2015-07-10 14:04 - 00000000 ___RD C:\Windows\PrintDialog
2015-08-01 02:15 - 2015-07-10 14:04 - 00000000 ___RD C:\Windows\MiracastView
2015-08-01 01:59 - 2015-07-10 14:04 - 00000000 ____D C:\Windows\system32\restore
2015-08-01 01:56 - 2015-07-10 14:04 - 00000000 ____D C:\Windows\system32\spool
2015-08-01 01:56 - 2015-07-10 14:04 - 00000000 ____D C:\Windows\system32\FxsTmp
2015-08-01 01:55 - 2015-07-10 14:05 - 00002133 _____ C:\Windows\DtcInstall.log
2015-08-01 01:55 - 2015-07-10 14:04 - 00000000 ____D C:\Windows\system32\Recovery
2015-08-01 01:55 - 2015-07-10 12:05 - 00000000 ____D C:\Windows\system32\Sysprep
2015-08-01 01:53 - 2015-07-10 12:05 - 00000000 __RHD C:\Users\Default
 
Some files in TEMP:
====================
C:\Users\Justinas\AppData\Local\Temp\341434.exe
C:\Users\Justinas\AppData\Local\Temp\7za.exe
C:\Users\Justinas\AppData\Local\Temp\avgnt.exe
C:\Users\Justinas\AppData\Local\Temp\drm_dialogs.dll
C:\Users\Justinas\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpldhqzd.dll
C:\Users\Justinas\AppData\Local\Temp\jre-8u60-windows-au.exe
C:\Users\Justinas\AppData\Local\Temp\vdu_uninstall_ad81e86.exe
C:\Users\Nerijus\AppData\Local\Temp\avgnt.exe
C:\Users\Nerijus\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpwxb_xe.dll
 
 
==================== Bamital & volsnap =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2015-08-25 20:11
 
==================== End of FRST.txt ============================
 

 



BC AdBot (Login to Remove)

 


#2 JusTLC

JusTLC
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Lithuania
  • Local time:10:54 PM

Posted 28 August 2015 - 06:45 PM

Posted too much topic copies, sorry, didn't mean to do that, will try to delete them.
 
ADDITION
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version:28-08-2015
Ran by Justinas (2015-08-29 02:03:09)
Running from C:\Users\Justinas\Downloads
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-3691003279-1683200719-2023029133-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-3691003279-1683200719-2023029133-503 - Limited - Disabled)
Guest (S-1-5-21-3691003279-1683200719-2023029133-501 - Limited - Enabled)
HomeGroupUser$ (S-1-5-21-3691003279-1683200719-2023029133-1003 - Limited - Enabled)
Justinas (S-1-5-21-3691003279-1683200719-2023029133-1001 - Administrator - Enabled) => C:\Users\Justinas
Nerijus (S-1-5-21-3691003279-1683200719-2023029133-1004 - Limited - Enabled) => C:\Users\Nerijus
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Avira Antivirus (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Avira Antivirus (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov)
Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 15.008.20082 - Adobe Systems Incorporated)
Apple Application Support (32-bit) (HKLM-x32\...\{7FE25256-B7C1-480D-B736-10A67A833AEA}) (Version: 3.2 - Apple Inc.)
Apple Application Support (64-bit) (HKLM\...\{B255D495-4734-4E9B-B4F5-96702FD4A7B9}) (Version: 3.2 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{5D61F006-168C-4B8B-B7FD-F113C10AE0E4}) (Version: 8.2.1.3 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Avira (HKLM-x32\...\{a5e00a72-db4a-4f77-8874-d1265b8fcd7e}) (Version: 1.1.42.10415 - Avira Operations GmbH & Co. KG)
Avira (x32 Version: 1.1.42.10415 - Avira Operations GmbH & Co. KG) Hidden
Avira Antivirus (HKLM-x32\...\Avira Antivirus) (Version: 15.0.12.420 - Avira Operations GmbH & Co. KG)
Battle.net (HKLM-x32\...\Battle.net) (Version:  - Blizzard Entertainment)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Canon MG5500 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG5500_series) (Version: 1.02 - Canon Inc.)
Democracy 3 (HKLM-x32\...\GOGPACKDEMOCRACY3_is1) (Version: 2.0.0.3 - GOG.com)
Democracy 3 Realistic Taxes Mod (HKLM-x32\...\Democracy 3_is1) (Version:  - Positech Games)
Dota 2 (HKLM-x32\...\Steam App 570) (Version:  - Valve)
Dropbox (HKLM-x32\...\Dropbox) (Version: 3.8.8 - Dropbox, Inc.)
Dropbox Update Helper (x32 Version: 1.3.27.35 - Dropbox, Inc.) Hidden
EA SPORTS™ FIFA 15 (HKLM-x32\...\{3D4ADA2B-F028-4307-ADF4-6F9AA44725DA}) (Version: 1.4.0.0 - Electronic Arts)
FIFA 13 (HKLM-x32\...\{A29E18C2-7AB1-4b6b-848C-5D5E2C85F0C0}) (Version: 1.8.0.0 - Electronic Arts)
FIFA 15 Ultimate Team Edition version 1.0 (HKLM-x32\...\{32C4CF13-4052-488F-90B0-C5A15C5E2E0E}_is1) (Version: 1.0 - )
GOG Galaxy (HKLM-x32\...\{7258BA11-600C-430E-A759-27E2C691A335}_is1) (Version:  - GOG.com)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 44.0.2403.157 - Google Inc.)
Google Update Helper (x32 Version: 1.3.28.1 - Google Inc.) Hidden
Hearthstone (HKLM-x32\...\Hearthstone) (Version:  - Blizzard Entertainment)
iTunes (HKLM\...\{BFEAB774-C7DC-4032-B05A-DA5F7CB7B365}) (Version: 12.2.2.25 - Apple Inc.)
Java 8 Update 51 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86418051F0}) (Version: 8.0.510 - Oracle Corporation)
Java 8 Update 51 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218051F0}) (Version: 8.0.510 - Oracle Corporation)
KMSpico (HKLM\...\{8B29D47F-92E2-4C20-9EE0-F710991F5D7C}_is1) (Version:  - )
Last.fm Scrobbler 2.1.37 (HKLM-x32\...\LastFM_is1) (Version:  - Last.fm)
League of Legends (HKLM-x32\...\League of Legends 3.0.1) (Version: 3.0.1 - Riot Games)
League of Legends (x32 Version: 3.0.1 - Riot Games) Hidden
Life Is Strange (HKLM-x32\...\Life Is Strange_R.G. Mechanics_is1) (Version:  - R.G. Mechanics, spider91)
Malwarebytes Anti-Malware version 2.1.8.1057 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.1.8.1057 - Malwarebytes Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{f0080ca2-80ae-4958-b6eb-e8fa916d744a}) (Version: 11.0.61030.0 - Корпорация Майкрософт)
NBA 2K14 (HKLM-x32\...\{4FE0545A-1BF3-4B9B-A044-6E1EE719E197}) (Version: 1.0.0 - 2K Sports)
NVIDIA GeForce Experience 2.5.12.11 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.5.12.11 - NVIDIA Corporation)
NVIDIA PhysX (HKLM-x32\...\{B455E95A-B804-439F-B533-336B1635AE97}) (Version: 9.14.0702 - NVIDIA Corporation)
Origin (HKLM-x32\...\Origin) (Version: 9.7.2.53208 - Electronic Arts, Inc.)
qBittorrent 3.2.3 (HKLM-x32\...\qBittorrent) (Version: 3.2.3 - The qBittorrent project)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7535 - Realtek Semiconductor Corp.)
Rocket League (HKLM-x32\...\Steam App 252950) (Version:  - Psyonix)
SHIELD Streaming (Version: 4.1.3000 - NVIDIA Corporation) Hidden
SHIELD Wireless Controller Driver (Version: 2.5.12.11 - NVIDIA Corporation) Hidden
Skype™ 7.7 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.7.103 - Skype Technologies S.A.)
Spotify (HKU\S-1-5-21-3691003279-1683200719-2023029133-1001\...\Spotify) (Version: 1.0.12.161.g64b0797c - Spotify AB)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
TeamViewer 10 (HKLM-x32\...\TeamViewer) (Version: 10.0.45471 - TeamViewer)
The Witcher 3 - Wild Hunt (HKLM-x32\...\1207664643_is1) (Version: 1.0.8.2 - GOG.com)
The Witcher 3: Wild Hunt - Alternative Look for Ciri (HKLM-x32\...\Alternative Look for Ciri_is1) (Version: 1.0.0.0 - GOG.com)
The Witcher 3: Wild Hunt - Alternative Look for Yennefer (HKLM-x32\...\Alternative Look for Yennefer_is1) (Version: 1.0.0.0 - GOG.com)
The Witcher 3: Wild Hunt - Alternative Look for Triss (HKLM-x32\...\Alternative Look for Triss_is1) (Version: 1.0.0.0 - GOG.com)
The Witcher 3: Wild Hunt - Ballad Heroes - Neutral Gwent Card Set (HKLM-x32\...\Ballad Heroes - Neutral Gwent Card Set_is1) (Version: 1.0.0.0 - GOG.com)
The Witcher 3: Wild Hunt - Beard and Hairstyle Set (HKLM-x32\...\Beard and Hairstyle Set_is1) (Version: 1.0.0.0 - GOG.com)
The Witcher 3: Wild Hunt - Elite Crossbow Set (HKLM-x32\...\Elite Crossbow Set_is1) (Version: 1.0.0.0 - GOG.com)
The Witcher 3: Wild Hunt - New Finisher Animations (HKLM-x32\...\New Finisher Animations_is1) (Version: 1.0.0.0 - GOG.com)
The Witcher 3: Wild Hunt - New Quest - Contract - Skellige's Most Wanted (HKLM-x32\...\New Quest - Contract: Skellige's Most Wanted_is1) (Version: 1.0.0.0 - GOG.com)
The Witcher 3: Wild Hunt - New Quest - Contract Missing Miners (HKLM-x32\...\New Quest - Contract Missing Miners_is1) (Version: 1.0.0.0 - GOG.com)
The Witcher 3: Wild Hunt - New Quest - Fool's Gold (HKLM-x32\...\New Quest - Fool's Gold_is1) (Version: 1.0.0.0 - GOG.com)
The Witcher 3: Wild Hunt - New Quest - Scavenger Hunt - Wolf School Gear (HKLM-x32\...\New Quest - Scavenger Hunt: Wolf School Gear_is1) (Version: 1.0.0.0 - GOG.com)
The Witcher 3: Wild Hunt - New Quest - Where the Cat and Wolf Play... (HKLM-x32\...\New Quest - Where the Cat and Wolf Play..._is1) (Version: 1.0.0.0 - GOG.com)
The Witcher 3: Wild Hunt - Nilfgaardian Armor Set (HKLM-x32\...\Nilfgaardian Armor Set_is1) (Version: 1.0.0.0 - GOG.com)
The Witcher 3: Wild Hunt - Skellige Armor Set (HKLM-x32\...\Skellige Armor Set_is1) (Version: 1.0.0.0 - GOG.com)
The Witcher 3: Wild Hunt - Temerian Armor Set (HKLM-x32\...\Temerian Armor Set_is1) (Version: 1.0.0.0 - GOG.com)
VLC media player (HKLM\...\VLC media player) (Version: 2.2.1 - VideoLAN)
Winamp (HKLM-x32\...\Winamp) (Version: 5.666  - Nullsoft, Inc)
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-3691003279-1683200719-2023029133-1001_Classes\CLSID\{018D5C66-4533-4307-9B53-224DE2ED1FE6}\InprocServer32 -> C:\Windows\system32\shell32.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3691003279-1683200719-2023029133-1001_Classes\CLSID\{1BF42E4C-4AF4-4CFD-A1A0-CF2960B8F63E}\InprocServer32 -> C:\Users\Justinas\AppData\Local\Microsoft\OneDrive\17.3.5907.0716\amd64\FileSyncShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3691003279-1683200719-2023029133-1001_Classes\CLSID\{5AB7172C-9C11-405C-8DD5-AF20F3606282}\InprocServer32 -> C:\Users\Justinas\AppData\Local\Microsoft\OneDrive\17.3.5907.0716\amd64\FileSyncShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3691003279-1683200719-2023029133-1001_Classes\CLSID\{7AFDFDDB-F914-11E4-8377-6C3BE50D980C}\InprocServer32 -> C:\Users\Justinas\AppData\Local\Microsoft\OneDrive\17.3.5907.0716\amd64\FileSyncShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3691003279-1683200719-2023029133-1001_Classes\CLSID\{82CA8DE3-01AD-4CEA-9D75-BE4C51810A9E}\InprocServer32 -> C:\Users\Justinas\AppData\Local\Microsoft\OneDrive\17.3.5907.0716\amd64\FileSyncShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3691003279-1683200719-2023029133-1001_Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}\InprocServer32 -> C:\Users\Justinas\AppData\Local\Microsoft\OneDrive\17.3.5907.0716\amd64\FileSyncShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3691003279-1683200719-2023029133-1001_Classes\CLSID\{A78ED123-AB77-406B-9962-2A5D9D2F7F30}\InprocServer32 -> C:\Users\Justinas\AppData\Local\Microsoft\OneDrive\17.3.5907.0716\amd64\FileSyncShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3691003279-1683200719-2023029133-1001_Classes\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}\InprocServer32 -> C:\Users\Justinas\AppData\Local\Microsoft\OneDrive\17.3.5907.0716\amd64\FileSyncShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3691003279-1683200719-2023029133-1001_Classes\CLSID\{CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B}\InprocServer32 -> C:\Users\Justinas\AppData\Local\Microsoft\OneDrive\17.3.5907.0716\amd64\FileSyncShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3691003279-1683200719-2023029133-1001_Classes\CLSID\{E31EA727-12ED-4702-820C-4B6445F28E1A}\InprocServer32 -> C:\Windows\system32\shell32.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3691003279-1683200719-2023029133-1001_Classes\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}\InprocServer32 -> C:\Users\Justinas\AppData\Local\Microsoft\OneDrive\17.3.5907.0716\amd64\FileSyncShell64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3691003279-1683200719-2023029133-1001_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\Justinas\AppData\Local\Microsoft\OneDrive\17.3.5907.0716\amd64\FileSyncApi64.dll (Microsoft Corporation)
 
==================== Restore Points =========================
 
22-08-2015 03:10:05 Scheduled Checkpoint
28-08-2015 00:13:10 Windows Update
28-08-2015 00:13:42 Windows Update
29-08-2015 00:22:28 Installed Microsoft Visual C++ 2005 Redistributable (x64)
 
==================== Hosts content: ===============================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2015-07-10 14:04 - 2015-07-10 14:02 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {00EEBA9C-F9EF-4272-B793-C830FBADD359} - System32\Tasks\Microsoft\Windows\ApplicationData\DsSvcCleanup => C:\Windows\system32\dstokenclean.exe [2015-07-10] (Microsoft Corporation)
Task: {0CCA7916-2916-4F12-BD32-1E3BE31E1269} - System32\Tasks\Microsoft\Windows\Workplace Join\Automatic-Device-Join => C:\Windows\System32\dsregcmd.exe [2015-07-10] (Microsoft Corporation)
Task: {19865544-CE08-40BE-8B8C-87C47681433D} - System32\Tasks\Microsoft\Windows\WindowsUpdate\sihboot => C:\Windows\System32\sihclient.exe [2015-07-10] (Microsoft Corporation)
Task: {1DB834CA-05B6-4391-B6DB-AB9FDD4A7681} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\Windows\system32\MRT.exe [2015-07-28] (Microsoft Corporation)
Task: {1E45ACB1-80CD-4F99-AC56-7D34EA1A403B} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-07-07] (Adobe Systems Incorporated)
Task: {3336CAB9-7609-40F8-BA37-1D0D8A1CE522} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-16] (Google Inc.)
Task: {3D5A6674-33DD-4830-A1F2-5C3837DAFDE9} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-16] (Google Inc.)
Task: {3F6E048D-6404-433B-8F5F-CFF4D89BF89E} - System32\Tasks\Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser => Rundll32.exe generaltel.dll,RunTelemetryW
Task: {41160EA0-208B-4C3E-B4DB-805BBABC6B93} - System32\Tasks\Microsoft\Windows\Feedback\Siuf\DmClient => C:\Windows\system32\dmclient.exe [2015-07-10] (Microsoft Corporation)
Task: {4DC73F4D-BC5D-45AB-AEB1-90B8CCBF1DDE} - System32\Tasks\AutoPico Daily Restart => C:\Program Files\KMSpico\AutoPico.exe [2015-07-22] (@ByELDI)
Task: {696E93E6-1743-4C1F-BCA7-AD3F0C52ABB4} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2015-08-01] (Dropbox, Inc.)
Task: {73551810-E5F4-433E-9494-0D00B55C855E} - System32\Tasks\Microsoft\Windows\Maps\MapsToastTask
Task: {78B77FA3-9D97-441D-97B6-68CEA40B4F74} - System32\Tasks\Microsoft\Windows\Application Experience\ProgramDataUpdater => Rundll32.exe generaltel.dll,RunTelemetry -maintenance
Task: {8DF84CB3-D8E0-4307-A35B-CA74E21786DB} - System32\Tasks\Microsoft\Windows\Clip\License Validation => C:\Windows\system32\ClipUp.exe [2015-07-15] (Microsoft Corporation)
Task: {A095EFCE-A6CA-494D-942B-A849AD45144C} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {A5B6CD85-1B57-49B9-BA80-5D5D65F02826} - System32\Tasks\Microsoft\Windows\AppID\EDP Policy Manager
Task: {ABDDB2B4-6253-47BB-9F60-159FFA40B6D0} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2015-08-01] (Dropbox, Inc.)
Task: {C56AFFD3-06B8-4A16-AF7E-F7A6EB3FAE9E} - System32\Tasks\Microsoft\Windows\TPM\Tpm-HASCertRetr
Task: {C5EE2EA2-5312-4D1F-B9D0-41B18DF31B78} - System32\Tasks\Microsoft\Windows\WindowsUpdate\sih => C:\Windows\System32\sihclient.exe [2015-07-10] (Microsoft Corporation)
Task: {C7A236B2-12E1-46DC-9501-3B1B0209CC09} - System32\Tasks\Microsoft\Windows\Location\WindowsActionDialog => C:\Windows\System32\WindowsActionDialog.exe [2015-07-10] (Microsoft Corporation)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\Windows\Tasks\CreateExplorerShellUnelevatedTask.job => C:\Windows\explorer.exe
Task: C:\Windows\Tasks\DropboxUpdateTaskMachineCore.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
Task: C:\Windows\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
 
==================== Loaded Modules (Whitelisted) ==============
 
2015-08-01 02:36 - 2015-07-15 05:04 - 00032768 _____ () C:\Windows\SYSTEM32\licensemanagerapi.dll
2015-08-28 00:18 - 2015-08-11 12:14 - 00404480 _____ () C:\Windows\System32\diagtrack_wininternal.dll
2015-05-15 16:26 - 2015-05-15 16:26 - 00085832 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2015-05-15 16:26 - 2015-05-15 16:26 - 01346344 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2015-08-05 22:42 - 2015-07-30 09:05 - 02498808 _____ () C:\Windows\system32\CoreUIComponents.dll
2015-08-05 22:42 - 2015-07-30 09:05 - 02498808 _____ () C:\Windows\System32\CoreUIComponents.dll
2015-08-11 22:44 - 2015-08-03 04:11 - 06569472 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2015-07-10 14:00 - 2015-07-10 16:28 - 00471040 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2015-08-28 00:18 - 2015-08-11 11:58 - 01808384 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2015-08-11 22:44 - 2015-08-03 04:09 - 02274816 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2015-07-10 14:00 - 2015-07-10 16:28 - 00210432 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.ProxyStub.dll
2015-07-10 13:59 - 2015-07-10 13:59 - 00429056 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll
2014-01-21 16:54 - 2015-08-29 00:25 - 01294336 _____ () C:\Riot Games\League of Legends\RADS\system\rads_user_kernel.exe
2015-08-29 00:25 - 2015-08-29 00:25 - 02371576 _____ () C:\Riot Games\League of Legends\RADS\projects\lol_launcher\releases\0.0.0.252\deploy\LoLLauncher.exe
2015-08-29 00:27 - 2015-08-29 00:27 - 04242424 _____ () C:\Riot Games\League of Legends\RADS\projects\lol_patcher\releases\0.0.0.36\deploy\LoLPatcher.exe
2015-08-29 00:27 - 2015-08-29 00:27 - 03195384 _____ () C:\Riot Games\League of Legends\RADS\projects\lol_patcher\releases\0.0.0.36\deploy\LoLPatcherUx.exe
2015-08-01 23:01 - 2015-07-24 07:22 - 00011920 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll
2015-08-29 00:12 - 2015-08-29 00:12 - 00071168 _____ () c:\users\justinas\appdata\local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpldhqzd.dll
2015-08-01 03:48 - 2015-08-05 08:26 - 00012800 _____ () C:\Program Files (x86)\Dropbox\Client\QtQuick.2\qtquick2plugin.dll
2015-08-01 03:48 - 2015-08-05 08:26 - 00779776 _____ () C:\Program Files (x86)\Dropbox\Client\QtQuick\Controls\qtquickcontrolsplugin.dll
2015-08-01 03:48 - 2015-08-05 08:26 - 00056320 _____ () C:\Program Files (x86)\Dropbox\Client\QtQuick\Layouts\qquicklayoutsplugin.dll
2015-08-01 03:48 - 2015-08-05 08:26 - 00012288 _____ () C:\Program Files (x86)\Dropbox\Client\QtQuick\Window.2\windowplugin.dll
2015-08-22 10:15 - 2015-08-18 08:23 - 01405768 _____ () C:\Program Files (x86)\Google\Chrome\Application\44.0.2403.157\libglesv2.dll
2015-08-22 10:15 - 2015-08-18 08:23 - 00081224 _____ () C:\Program Files (x86)\Google\Chrome\Application\44.0.2403.157\libegl.dll
2015-08-01 03:43 - 2015-08-28 15:22 - 45066296 _____ () C:\Users\Justinas\AppData\Roaming\Spotify\libcef.dll
2015-08-01 03:43 - 2015-08-28 15:22 - 01649208 _____ () C:\Users\Justinas\AppData\Roaming\Spotify\libglesv2.dll
2015-08-01 03:43 - 2015-08-28 15:22 - 00080952 _____ () C:\Users\Justinas\AppData\Roaming\Spotify\libegl.dll
2015-08-29 00:19 - 2015-08-29 00:19 - 26065408 _____ () C:\Program Files (x86)\Battle.net\Battle.net.6119\libcef.dll
2015-08-29 00:19 - 2015-08-29 00:19 - 00739840 _____ () C:\Program Files (x86)\Battle.net\Battle.net.6119\libGLESv2.dll
2015-08-29 00:19 - 2015-08-29 00:19 - 00909312 _____ () C:\Program Files (x86)\Battle.net\Battle.net.6119\platforms\qwindows.dll
2015-08-29 00:19 - 2015-08-29 00:19 - 00130048 _____ () C:\Program Files (x86)\Battle.net\Battle.net.6119\libEGL.dll
2015-08-29 00:19 - 2015-08-29 00:19 - 00020992 _____ () C:\Program Files (x86)\Battle.net\Battle.net.6119\imageformats\qgif.dll
2015-08-29 00:19 - 2015-08-29 00:19 - 00021504 _____ () C:\Program Files (x86)\Battle.net\Battle.net.6119\imageformats\qico.dll
2015-08-29 00:19 - 2015-08-29 00:19 - 00205312 _____ () C:\Program Files (x86)\Battle.net\Battle.net.6119\imageformats\qjpeg.dll
2015-08-29 00:19 - 2015-08-29 00:19 - 00225792 _____ () C:\Program Files (x86)\Battle.net\Battle.net.6119\imageformats\qmng.dll
2015-08-29 00:19 - 2015-08-29 00:19 - 00015872 _____ () C:\Program Files (x86)\Battle.net\Battle.net.6119\imageformats\qsvg.dll
2015-08-29 00:19 - 2015-08-29 00:19 - 00312832 _____ () C:\Program Files (x86)\Battle.net\Battle.net.6119\imageformats\qtiff.dll
2015-08-29 00:19 - 2015-08-29 00:19 - 00010240 _____ () C:\Program Files (x86)\Battle.net\Battle.net.6119\qml\QtQuick.2\qtquick2plugin.dll
2015-08-29 00:19 - 2015-08-29 00:19 - 00054272 _____ () C:\Program Files (x86)\Battle.net\Battle.net.6119\qml\QtQuick\Layouts\qquicklayoutsplugin.dll
2015-08-29 00:19 - 2015-08-29 00:19 - 00010240 _____ () C:\Program Files (x86)\Battle.net\Battle.net.6119\qml\QtQml\Models.2\modelsplugin.dll
2015-08-29 00:27 - 2015-08-29 00:27 - 01738232 _____ () C:\Riot Games\League of Legends\RADS\projects\lol_patcher\releases\0.0.0.36\deploy\RiotLauncher.dll
2015-08-29 00:27 - 2015-08-29 00:27 - 34851320 _____ () C:\Riot Games\League of Legends\RADS\projects\lol_patcher\releases\0.0.0.36\deploy\libcef.dll
2015-08-29 00:27 - 2015-08-29 00:27 - 01383416 _____ () C:\Riot Games\League of Legends\RADS\projects\lol_patcher\releases\0.0.0.36\deploy\icui18n.dll
2015-08-29 00:27 - 2015-08-29 00:27 - 01142264 _____ () C:\Riot Games\League of Legends\RADS\projects\lol_patcher\releases\0.0.0.36\deploy\icuuc.dll
2015-08-29 00:27 - 2015-08-29 00:27 - 04382200 _____ () C:\Riot Games\League of Legends\RADS\projects\lol_patcher\releases\0.0.0.36\deploy\v8.dll
2015-08-29 00:27 - 2015-08-29 00:27 - 01825272 _____ () C:\Riot Games\League of Legends\RADS\projects\lol_patcher\releases\0.0.0.36\deploy\RiotRadsIO.dll
2015-08-29 00:27 - 2015-08-29 00:27 - 01339896 _____ () C:\Riot Games\League of Legends\RADS\projects\lol_patcher\releases\0.0.0.36\deploy\libglesv2.dll
2015-08-29 00:27 - 2015-08-29 00:27 - 00198648 _____ () C:\Riot Games\League of Legends\RADS\projects\lol_patcher\releases\0.0.0.36\deploy\libegl.dll
2015-08-29 00:27 - 2015-08-29 00:27 - 00953336 _____ () C:\Riot Games\League of Legends\RADS\projects\lol_patcher\releases\0.0.0.36\deploy\ffmpegsumo.dll
2015-08-01 12:45 - 2015-07-17 14:21 - 00566272 _____ () C:\Program Files (x86)\GalaxyClient\PocoUtil.dll
2015-08-01 12:45 - 2015-07-17 14:21 - 01202176 _____ () C:\Program Files (x86)\GalaxyClient\PocoNet.dll
2015-08-01 12:45 - 2015-07-17 14:21 - 02577408 _____ () C:\Program Files (x86)\GalaxyClient\PocoData.dll
2015-08-01 12:45 - 2015-07-17 14:21 - 00477184 _____ () C:\Program Files (x86)\GalaxyClient\PocoDataSQLite.dll
2015-08-01 12:45 - 2015-07-17 14:21 - 00515584 _____ () C:\Program Files (x86)\GalaxyClient\PocoXML.dll
2015-08-01 12:45 - 2015-07-17 14:21 - 00340480 _____ () C:\Program Files (x86)\GalaxyClient\PocoZip.dll
2015-08-01 12:45 - 2015-07-17 14:21 - 01784320 _____ () C:\Program Files (x86)\GalaxyClient\PocoFoundation.dll
2015-08-01 12:45 - 2015-07-17 14:21 - 00332288 _____ () C:\Program Files (x86)\GalaxyClient\PocoNetSSL.dll
2015-08-01 12:45 - 2015-07-17 14:21 - 00415744 _____ () C:\Program Files (x86)\GalaxyClient\PocoJSON.dll
2015-08-01 12:45 - 2015-07-17 14:21 - 41299456 _____ () C:\Program Files (x86)\GalaxyClient\libcef.dll
2015-08-01 12:45 - 2015-07-17 14:20 - 00139776 _____ () C:\Program Files (x86)\GalaxyClient\expat.dll
2015-08-01 12:45 - 2015-07-17 14:21 - 00649728 _____ () C:\Program Files (x86)\GalaxyClient\sqlite.dll
2015-08-01 12:45 - 2015-07-17 14:21 - 00172032 _____ () C:\Program Files (x86)\GalaxyClient\PocoCrypto.dll
2015-08-01 12:45 - 2015-07-17 14:21 - 00412672 _____ () C:\Program Files (x86)\GalaxyClient\pcre.dll
2015-08-01 12:45 - 2015-07-17 14:21 - 00094208 _____ () C:\Program Files (x86)\GalaxyClient\zlib.dll
2015-08-01 12:45 - 2015-07-17 14:21 - 00107520 _____ () C:\Program Files (x86)\GalaxyClient\ZLIB1.dll
2015-08-01 12:45 - 2015-07-17 14:20 - 00888832 _____ () C:\Program Files (x86)\GalaxyClient\ffmpegsumo.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ahcache.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CoreMessagingRegistrar => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\StateRepository => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TileDataModelSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\UserManager => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Ahcache.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CoreMessagingRegistrar => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\StateRepository => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TileDataModelSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\UserManager => ""="Service"
 
==================== EXE Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-3691003279-1683200719-2023029133-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Justinas\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper
DNS Servers: 192.168.0.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
(Currently there is no automatic fix for this section.)
 
HKLM\...\StartupApproved\Run: => "iTunesHelper"
HKU\S-1-5-21-3691003279-1683200719-2023029133-1001\...\StartupApproved\Run: => "GalaxyClient"
HKU\S-1-5-21-3691003279-1683200719-2023029133-1001\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-3691003279-1683200719-2023029133-1001\...\StartupApproved\Run: => "Spotify"
HKU\S-1-5-21-3691003279-1683200719-2023029133-1001\...\StartupApproved\Run: => "Spotify Web Helper"
HKU\S-1-5-21-3691003279-1683200719-2023029133-1001\...\StartupApproved\Run: => "Steam"
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [SPPSVC-In-TCP] => (Allow) %SystemRoot%\system32\sppextcomobj.exe
FirewallRules: [SPPSVC-In-TCP-NoScope] => (Allow) %SystemRoot%\system32\sppextcomobj.exe
FirewallRules: [{F24E69CB-9F00-4D6E-B57E-ED861187E97A}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{3F73C4CD-3158-440B-A5A1-2B13FEA5CD7D}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{CCECEC0B-01CA-460B-9B3A-AF8913CC93C7}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{159C8F9D-2F8A-406F-A539-AF7D2763D515}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{20A92632-32C5-4BC4-9175-110F099930FA}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{61523278-3D4D-445F-B2BD-EE1930BB724B}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{E60A1508-03F2-4BA2-92D5-7E074A949B4D}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{25D81964-D045-48EA-8905-94B0BEC762A6}] => (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe
FirewallRules: [{3C42CD4C-37CB-449D-A11F-C192ADAE0D97}] => (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe
FirewallRules: [{F2A9C7E5-8E89-477E-B177-42E5DECF1CF2}] => (Allow) C:\Program Files (x86)\Hearthstone\Hearthstone.exe
FirewallRules: [{70A23406-7C0F-4F5E-A6AA-3C88F1462747}] => (Allow) C:\Program Files (x86)\Hearthstone\Hearthstone.exe
FirewallRules: [{3BA34602-B161-41CC-AB9B-EDF75F77E688}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{69A9E835-34AA-4772-B914-A008B10C3AE3}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{E4A744EA-821A-427D-9499-280440F88DA2}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{0EAFF920-A613-4B3A-B2D0-D3A783273AE9}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{BA8B4FAC-2A3D-42B4-AA78-2705236FBF47}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{3C86DF16-1ADE-4D92-83F1-05298CBBE378}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [TCP Query User{BC807284-0A73-4D8B-AF19-05D68847EA86}C:\users\justinas\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\justinas\appdata\roaming\spotify\spotify.exe
FirewallRules: [UDP Query User{757B7F04-2284-4C4D-9952-D8ED493348C3}C:\users\justinas\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\justinas\appdata\roaming\spotify\spotify.exe
FirewallRules: [{A3BB2E08-E918-4BBB-92B6-151C24FE04EE}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{B6C11490-1C05-47BB-919D-83D977624A3D}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{79F859D7-A983-4F5D-8946-DDAE679922FC}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
FirewallRules: [{1A11FBC9-9935-41A6-B5C5-8E787093494A}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
FirewallRules: [{320D21E6-2912-4942-B64F-F19797BA87D9}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
FirewallRules: [{84298EA5-96D4-4BE2-B7CE-984353C77DC1}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{590AC022-FD33-4C7E-BBCB-589A27C4C542}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{56A0361C-BADF-4256-B4C0-48EFD7DEE929}] => (Allow) C:\Program Files (x86)\qBittorrent\qbittorrent.exe
FirewallRules: [{50FBA548-DFF2-44CE-9F74-82E5D5CCD652}] => (Allow) C:\Program Files (x86)\qBittorrent\qbittorrent.exe
FirewallRules: [{55DD34B8-8E00-4777-8466-28A21BF5091C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\rocketleague\Binaries\Win32\RocketLeague.exe
FirewallRules: [{83BE7965-EE36-4B51-9785-1F45839D77D2}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\rocketleague\Binaries\Win32\RocketLeague.exe
FirewallRules: [{09EC78D9-841A-4A85-BE4C-1B2C7E797996}] => (Allow) C:\Program Files (x86)\Winamp\winamp.exe
FirewallRules: [{8A366E0F-0D9B-4F2B-960A-F7EB4FC9E45B}] => (Allow) C:\Program Files (x86)\Winamp\winamp.exe
FirewallRules: [TCP Query User{DF518594-3D37-41F9-821D-4C6669A774E0}C:\program files (x86)\qbittorrent\qbittorrent.exe] => (Allow) C:\program files (x86)\qbittorrent\qbittorrent.exe
FirewallRules: [UDP Query User{70924E88-6DA0-4EE8-BFEE-279445D3ECF3}C:\program files (x86)\qbittorrent\qbittorrent.exe] => (Allow) C:\program files (x86)\qbittorrent\qbittorrent.exe
FirewallRules: [TCP Query User{BCDE2C96-32F8-4FFA-B678-7B13F6A78913}C:\program files (x86)\hearthstone\hearthstone.exe] => (Allow) C:\program files (x86)\hearthstone\hearthstone.exe
FirewallRules: [UDP Query User{3415ADE8-9545-4DCD-8BB0-C6DECD9AFFA0}C:\program files (x86)\hearthstone\hearthstone.exe] => (Allow) C:\program files (x86)\hearthstone\hearthstone.exe
FirewallRules: [{FE0DB041-3497-4F23-8DED-B69579089E19}] => (Allow) C:\Program Files\iTunes\iTunes.exe
FirewallRules: [{77208DE2-1060-493A-A792-DBC248EE7774}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\rocketleague\Binaries\Win32\RocketLeague.exe
FirewallRules: [{A110DA95-98C0-4333-B0CF-8FA89672E0A8}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\rocketleague\Binaries\Win32\RocketLeague.exe
FirewallRules: [{A2B6664A-D132-45D1-B0B2-7EBB05BEACB9}] => (Allow) C:\Program Files (x86)\2K Sports\NBA 2K14\nba2k14.exe
FirewallRules: [{83C32883-0917-4EF8-9595-B05251F6EB65}] => (Allow) C:\Program Files (x86)\2K Sports\NBA 2K14\nba2k14.exe
FirewallRules: [{1774BA3C-279D-411A-A1FB-5DB393E0D6F6}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\dota.exe
FirewallRules: [{C2E05557-ED60-4E5A-9376-693427D3DD75}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\dota 2 beta\dota.exe
FirewallRules: [{9B816639-9D58-4077-9EB8-D1FACDC18BC9}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{EB0C0D3C-53D3-4437-BE41-6802986C9A28}] => (Allow) C:\Program Files (x86)\Origin Games\FIFA 13\Game\fifa13.exe
FirewallRules: [{A581BD1A-D80F-4B0C-89E0-434EC8F15134}] => (Allow) C:\Program Files (x86)\Origin Games\FIFA 13\Game\fifa13.exe
FirewallRules: [TCP Query User{6F8A51F8-AB4E-436C-871C-751AA726BAAC}C:\programdata\videodownloaderultimatewinapp\videodownloaderultimate.exe] => (Allow) C:\programdata\videodownloaderultimatewinapp\videodownloaderultimate.exe
FirewallRules: [UDP Query User{BE969CA8-555C-4E46-852D-DB62D08B3D35}C:\programdata\videodownloaderultimatewinapp\videodownloaderultimate.exe] => (Allow) C:\programdata\videodownloaderultimatewinapp\videodownloaderultimate.exe
FirewallRules: [{183BFA8C-8F98-4AD0-B8B5-82F7CE7FECFF}] => (Allow) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
FirewallRules: [{D57E7247-EDB4-4FCE-B511-186FFA079A24}] => (Allow) C:\Program Files (x86)\FIFA 15 Ultimate Team Edition\FIFA 15 Ultimate Team Edition\fifasetup\fifaconfig.exe
FirewallRules: [{CF96A7A9-ED54-41A6-8884-398AAFE25C8E}] => (Allow) C:\Program Files (x86)\FIFA 15 Ultimate Team Edition\FIFA 15 Ultimate Team Edition\fifasetup\fifaconfig.exe
 
==================== Faulty Device Manager Devices =============
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (08/29/2015 12:22:34 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.
 
Details:
AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol.
 
System Error:
Access is denied.
.
 
Error: (08/29/2015 12:11:34 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: ShellExperienceHost.exe, version: 10.0.10240.16425, time stamp: 0x55bec5f5
Faulting module name: StartUI.dll, version: 10.0.10240.16431, time stamp: 0x55c9bb30
Exception code: 0xc0000005
Fault offset: 0x0000000000067e73
Faulting process id: 0x2970
Faulting application start time: 0xShellExperienceHost.exe0
Faulting application path: ShellExperienceHost.exe1
Faulting module path: ShellExperienceHost.exe2
Report Id: ShellExperienceHost.exe3
Faulting package full name: ShellExperienceHost.exe4
Faulting package-relative application ID: ShellExperienceHost.exe5
 
Error: (08/28/2015 04:14:20 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: DESKTOP-GGB2RP0)
Description: Activation of app Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy!App failed with error: -2144927141 See the Microsoft-Windows-TWinUI/Operational log for additional information.
 
Error: (08/28/2015 04:14:15 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: DESKTOP-GGB2RP0)
Description: Activation of app Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI failed with error: -2144927141 See the Microsoft-Windows-TWinUI/Operational log for additional information.
 
Error: (08/28/2015 01:13:58 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: fifa15.exe, version: 1.4.0.0, time stamp: 0x545d6637
Faulting module name: ntdll.dll, version: 10.0.10240.16430, time stamp: 0x55c59f92
Exception code: 0xc0000005
Fault offset: 0x0000000000025a5d
Faulting process id: 0x2a94
Faulting application start time: 0xfifa15.exe0
Faulting application path: fifa15.exe1
Faulting module path: fifa15.exe2
Report Id: fifa15.exe3
Faulting package full name: fifa15.exe4
Faulting package-relative application ID: fifa15.exe5
 
Error: (08/28/2015 01:13:27 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: fifa15.exe, version: 1.4.0.0, time stamp: 0x545d6637
Faulting module name: ntdll.dll, version: 10.0.10240.16430, time stamp: 0x55c59f92
Exception code: 0xc0000005
Fault offset: 0x0000000000025a5d
Faulting process id: 0xb58
Faulting application start time: 0xfifa15.exe0
Faulting application path: fifa15.exe1
Faulting module path: fifa15.exe2
Report Id: fifa15.exe3
Faulting package full name: fifa15.exe4
Faulting package-relative application ID: fifa15.exe5
 
Error: (08/28/2015 01:10:25 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program 7zFM.exe version 9.20.0.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.
 
Process ID: 289c
 
Start Time: 01d0e114d68f988a
 
Termination Time: 4294967295
 
Application Path: C:\Program Files\7-Zip\7zFM.exe
 
Report Id: 6a349a6a-4d08-11e5-9bd3-001fd0570ddf
 
Faulting package full name: 
 
Faulting package-relative application ID:
 
Error: (08/28/2015 01:09:12 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: RocketLeague.exe, version: 1.0.10897.0, time stamp: 0x55cc4d80
Faulting module name: gameoverlayrenderer.dll, version: 2.92.69.85, time stamp: 0x55d4caaf
Exception code: 0xc0000005
Fault offset: 0x000c0497
Faulting process id: 0x1d50
Faulting application start time: 0xRocketLeague.exe0
Faulting application path: RocketLeague.exe1
Faulting module path: RocketLeague.exe2
Report Id: RocketLeague.exe3
Faulting package full name: RocketLeague.exe4
Faulting package-relative application ID: RocketLeague.exe5
 
Error: (08/28/2015 12:13:48 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.
 
Details:
AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol.
 
System Error:
Access is denied.
.
 
Error: (08/28/2015 12:13:14 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.
 
Details:
AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol.
 
System Error:
Access is denied.
.
 
 
System errors:
=============
Error: (08/29/2015 01:57:39 AM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY)
Description: {BFE18E9C-6D87-4450-B37C-E02F0B373803}
 
Error: (08/29/2015 01:55:06 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Sync Host_Session3 service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
 
Error: (08/29/2015 01:55:05 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: application-specificLocalActivation{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)UnavailableUnavailable
 
Error: (08/29/2015 01:51:49 AM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-GGB2RP0)
Description: application-specificLocalActivation{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}DESKTOP-GGB2RP0JustinasS-1-5-21-3691003279-1683200719-2023029133-1001LocalHost (Using LRPC)UnavailableUnavailable
 
Error: (08/29/2015 01:50:23 AM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY)
Description: {BFE18E9C-6D87-4450-B37C-E02F0B373803}
 
Error: (08/29/2015 01:47:45 AM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-GGB2RP0)
Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}DESKTOP-GGB2RP0NerijusS-1-5-21-3691003279-1683200719-2023029133-1004LocalHost (Using LRPC)Microsoft.Windows.Cortana_1.4.8.176_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742
 
Error: (08/29/2015 01:47:45 AM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-GGB2RP0)
Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}DESKTOP-GGB2RP0NerijusS-1-5-21-3691003279-1683200719-2023029133-1004LocalHost (Using LRPC)Microsoft.Windows.Cortana_1.4.8.176_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742
 
Error: (08/29/2015 01:47:45 AM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-GGB2RP0)
Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}DESKTOP-GGB2RP0NerijusS-1-5-21-3691003279-1683200719-2023029133-1004LocalHost (Using LRPC)Microsoft.Windows.Cortana_1.4.8.176_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742
 
Error: (08/29/2015 01:47:45 AM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-GGB2RP0)
Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}DESKTOP-GGB2RP0NerijusS-1-5-21-3691003279-1683200719-2023029133-1004LocalHost (Using LRPC)Microsoft.Windows.Cortana_1.4.8.176_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742
 
Error: (08/29/2015 01:47:45 AM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-GGB2RP0)
Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}DESKTOP-GGB2RP0NerijusS-1-5-21-3691003279-1683200719-2023029133-1004LocalHost (Using LRPC)Microsoft.Windows.Cortana_1.4.8.176_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742
 
 
Microsoft Office:
=========================
Error: (08/29/2015 12:22:34 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Details:
AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol.
 
System Error:
Access is denied.
 
Error: (08/29/2015 12:11:34 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: ShellExperienceHost.exe10.0.10240.1642555bec5f5StartUI.dll10.0.10240.1643155c9bb30c00000050000000000067e73297001d0e1d61bd12acbC:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exeC:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\StartUI.dll78471b64-d41e-4703-b96d-fe09710fb0f1Microsoft.Windows.ShellExperienceHost_10.0.10240.16384_neutral_neutral_cw5n1h2txyewyApp
 
Error: (08/28/2015 04:14:20 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: DESKTOP-GGB2RP0)
Description: Microsoft.Windows.CloudExperienceHost_cw5n1h2txyewy!App-2144927141
 
Error: (08/28/2015 04:14:15 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: DESKTOP-GGB2RP0)
Description: Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI-2144927141
 
Error: (08/28/2015 01:13:58 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: fifa15.exe1.4.0.0545d6637ntdll.dll10.0.10240.1643055c59f92c00000050000000000025a5d2a9401d0e115ab7be807C:\Program Files (x86)\FIFA 15 Ultimate Team Edition\FIFA 15 Ultimate Team Edition\fifa15.exeC:\Windows\SYSTEM32\ntdll.dllb02a23f8-5358-49d3-be8f-d33972cd5354
 
Error: (08/28/2015 01:13:27 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: fifa15.exe1.4.0.0545d6637ntdll.dll10.0.10240.1643055c59f92c00000050000000000025a5db5801d0e11598c48cfbC:\Program Files (x86)\FIFA 15 Ultimate Team Edition\FIFA 15 Ultimate Team Edition\fifa15.exeC:\Windows\SYSTEM32\ntdll.dlla77b8ac5-ae4b-43b4-97f7-a13c74358868
 
Error: (08/28/2015 01:10:25 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: 7zFM.exe9.20.0.0289c01d0e114d68f988a4294967295C:\Program Files\7-Zip\7zFM.exe6a349a6a-4d08-11e5-9bd3-001fd0570ddf
 
Error: (08/28/2015 01:09:12 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: RocketLeague.exe1.0.10897.055cc4d80gameoverlayrenderer.dll2.92.69.8555d4caafc0000005000c04971d5001d0e11230733363C:\Program Files (x86)\Steam\steamapps\common\rocketleague\Binaries\Win32\RocketLeague.exeC:\Program Files (x86)\Steam\gameoverlayrenderer.dll0d0476c7-b0eb-42eb-aa8a-f894597f5485
 
Error: (08/28/2015 12:13:48 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Details:
AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol.
 
System Error:
Access is denied.
 
Error: (08/28/2015 12:13:14 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Details:
AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol.
 
System Error:
Access is denied.
 
 
CodeIntegrity:
===================================
  Date: 2015-08-09 15:35:32.067
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\winhttp.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-08-09 15:35:32.044
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\winhttp.dll because the set of per-page image hashes could not be found on the system.
 
 
==================== Memory info =========================== 
 
Processor: Intel® Core™2 Quad CPU Q6600 @ 2.40GHz
Percentage of memory in use: 84%
Total physical RAM: 4094.49 MB
Available physical RAM: 650.7 MB
Total Virtual: 8446.49 MB
Available Virtual: 2448.54 MB
 
==================== Drives ================================
 
Drive c: () (Fixed) (Total:931.02 GB) (Free:694.87 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 5390FCFA)
Partition 1: (Active) - (Size=500 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=931 GB) - (Type=07 NTFS)
 
==================== End of Addition.txt ============================


#3 nasdaq

nasdaq

  • Malware Response Team
  • 38,936 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:03:54 PM

Posted 30 August 2015 - 08:14 AM

Hello, Welcome to BleepingComputer.
I'm nasdaq and will be helping you.

If you can please print this topic it will make it easier for you to follow the instructions and complete all of the necessary steps in the order listed.
===

Press the windows key Windows_Logo_key.gif+ r on your keyboard at the same time. This will open the RUN BOX.
Type Notepad and and click the OK key.
Please copy the entire contents of the code box below to the a new file.


start

CreateRestorePoint:
EmptyTemp:
CloseProcesses:

(@ByELDI) C:\Program Files\KMSpico\Service_KMS.exe
HKU\S-1-5-21-3691003279-1683200719-2023029133-1001\...\Run: [VideoDownloaderUltimate] => C:\ProgramData\VideoDownloaderUltimateWinApp\VideoDownloaderUltimate.exe /repair
FF Extension: Flash Video Downloader - YouTube HD Download [4K] - C:\Users\Justinas\AppData\Roaming\Mozilla\Firefox\Profiles\yq8q00kp.default\Extensions\artur.dubovoy@gmail.com [2015-08-14]
CHR Extension: (SavvyConnect) - C:\Users\Justinas\AppData\Local\Google\Chrome\User Data\Default\Extensions\bbdfnhblopmjjmghkgflplloabcclbmj [2015-08-16]
CHR Extension: (Avast Online Security) - C:\Users\Justinas\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2015-08-16]
CHR Extension: (Wolfram Alpha (Official)) - C:\Users\Justinas\AppData\Local\Google\Chrome\User Data\Default\Extensions\icncamkooinmbehmkeilcccmoljfkdhp [2015-08-16]
R2 Service KMSELDI; C:\Program Files\KMSpico\Service_KMS.exe [985280 2015-07-22] (@ByELDI) [File not signed]
S3 wfpcapture; \SystemRoot\System32\drivers\wfpcapture.sys [X]
C:\ProgramData\VideoDownloaderUltimateWinApp
C:\Users\Justinas\AppData\Roaming\Mozilla\Firefox\Profiles\yq8q00kp.default\Extensions\artur.dubovoy@gmail.com
C:\Users\Justinas\AppData\Local\Google\Chrome\User Data\Default\Extensions\bbdfnhblopmjjmghkgflplloabcclbmj
C:\Users\Justinas\AppData\Local\Google\Chrome\User Data\Default\Extensions\icncamkooinmbehmkeilcccmoljfkdhp
C:\Program Files\KMSpico

End
Save the file as fixlist.txt in the same folder where the Farbar tool is running from.
The location is listed in the 3rd line of the Farbar log you have submitted.

Run FRST and click Fix only once and wait.

Restart the computer normally to reset the registry.

The tool will create a log (Fixlog.txt) please post it to your reply.
===

Please download AdwCleaner by Xplode onto your Desktop.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click the Scan button and wait for the process to complete.
  • Click the Report button and the report will open in Notepad.
IMPORTANT
  • If you click the Clean button all items listed in the report will be removed.
If you find some false positive items or programs that you wish to keep, Close the AdwCleaner windows.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click the Scan button and wait for the process to complete.
  • Check off the element(s) you wish to keep.
  • Click on the Clean button follow the prompts.
  • A log file will automatically open after the scan has finished.
  • Please post the content of that log file with your next answer.
  • You can find the log file at C:\AdwCleaner[Sn].txt (n is a number).
===

Reset Chrome...
Open Google Chrome, click on menu icon google-chrome-setting-icon.png which is located right side top of the google chrome.
 
Click "Settings" then "Show advanced settings" at the bottom of the screen.
 
Click "Reset browser settings" button.
 
Clear your cache and cookies
https://support.google.com/chromebook/answer/183083?hl=en
Select "From the beginning of time"

Restart Chrome.


How is the computer running now?

#4 JusTLC

JusTLC
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Lithuania
  • Local time:10:54 PM

Posted 30 August 2015 - 05:46 PM

Hi nasdaq, thanks for the help.

 

Overall, I've encountered no chrome errors I've mentioned before and it seems to be more responsive, but that's probably because of the extensions.

 

The multiple COM Surrogates are still here though, I'll post a print screen of it.

 

And for the logs:

 

Fix result of Farbar Recovery Scan Tool (x64) Version:30-08-2015
Ran by Justinas (2015-08-30 21:57:46) Run:1
Running from C:\Users\Justinas\Downloads
Loaded Profiles: Justinas (Available Profiles: Justinas & Nerijus)
Boot Mode: Normal
==============================================
 
fixlist content:
*****************
 
start
 
CreateRestorePoint:
EmptyTemp:
CloseProcesses:
 
(@ByELDI) C:\Program Files\KMSpico\Service_KMS.exe
HKU\S-1-5-21-3691003279-1683200719-2023029133-1001\...\Run: [VideoDownloaderUltimate] => C:\ProgramData\VideoDownloaderUltimateWinApp\VideoDownloaderUltimate.exe /repair
FF Extension: Flash Video Downloader - YouTube HD Download [4K] - C:\Users\Justinas\AppData\Roaming\Mozilla\Firefox\Profiles\yq8q00kp.default\Extensions\artur.dubovoy@gmail.com [2015-08-14]
CHR Extension: (SavvyConnect) - C:\Users\Justinas\AppData\Local\Google\Chrome\User Data\Default\Extensions\bbdfnhblopmjjmghkgflplloabcclbmj [2015-08-16]
CHR Extension: (Avast Online Security) - C:\Users\Justinas\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2015-08-16]
CHR Extension: (Wolfram Alpha (Official)) - C:\Users\Justinas\AppData\Local\Google\Chrome\User Data\Default\Extensions\icncamkooinmbehmkeilcccmoljfkdhp [2015-08-16]
R2 Service KMSELDI; C:\Program Files\KMSpico\Service_KMS.exe [985280 2015-07-22] (@ByELDI) [File not signed]
S3 wfpcapture; \SystemRoot\System32\drivers\wfpcapture.sys [X]
C:\ProgramData\VideoDownloaderUltimateWinApp
C:\Users\Justinas\AppData\Roaming\Mozilla\Firefox\Profiles\yq8q00kp.default\Extensions\artur.dubovoy@gmail.com
C:\Users\Justinas\AppData\Local\Google\Chrome\User Data\Default\Extensions\bbdfnhblopmjjmghkgflplloabcclbmj
C:\Users\Justinas\AppData\Local\Google\Chrome\User Data\Default\Extensions\icncamkooinmbehmkeilcccmoljfkdhp
C:\Program Files\KMSpico
 
End
*****************
 
Restore point was successfully created.
Processes closed successfully.
C:\Program Files\KMSpico\Service_KMS.exe => Could not close process
HKU\S-1-5-21-3691003279-1683200719-2023029133-1001\Software\Microsoft\Windows\CurrentVersion\Run\\VideoDownloaderUltimate => value removed successfully
C:\Users\Justinas\AppData\Roaming\Mozilla\Firefox\Profiles\yq8q00kp.default\Extensions\artur.dubovoy@gmail.com => moved successfully
C:\Users\Justinas\AppData\Roaming\Mozilla\Firefox\Profiles\yq8q00kp.default\Extensions\artur.dubovoy@gmail.com => path removed successfully
C:\Users\Justinas\AppData\Local\Google\Chrome\User Data\Default\Extensions\bbdfnhblopmjjmghkgflplloabcclbmj => moved successfully
C:\Users\Justinas\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki => moved successfully
C:\Users\Justinas\AppData\Local\Google\Chrome\User Data\Default\Extensions\icncamkooinmbehmkeilcccmoljfkdhp => moved successfully
Service KMSELDI => service removed successfully
wfpcapture => service removed successfully
"C:\ProgramData\VideoDownloaderUltimateWinApp" => File/Folder not found.
"C:\Users\Justinas\AppData\Roaming\Mozilla\Firefox\Profiles\yq8q00kp.default\Extensions\artur.dubovoy@gmail.com" => File/Folder not found.
"C:\Users\Justinas\AppData\Local\Google\Chrome\User Data\Default\Extensions\bbdfnhblopmjjmghkgflplloabcclbmj" => File/Folder not found.
"C:\Users\Justinas\AppData\Local\Google\Chrome\User Data\Default\Extensions\icncamkooinmbehmkeilcccmoljfkdhp" => File/Folder not found.
C:\Program Files\KMSpico => moved successfully
EmptyTemp: => 1.7 GB temporary data Removed.
 
 
The system needed a reboot.. 
 
==== End of Fixlog 21:59:26 ====
 
# AdwCleaner v5.004 - Logfile created 31/08/2015 at 01:21:30
# Updated 26/08/2015 by Xplode
# Database : 2015-08-30.1 [Server]
# Operating system : Windows 10 Enterprise  (x64)
# Username : Justinas - DESKTOP-GGB2RP0
# Running from : C:\Users\Justinas\Downloads\adwcleaner_5.004.exe
# Option : Scan
 
***** [ Services ] *****
 
 
***** [ Folders ] *****
 
 
***** [ Files ] *****
 
 
***** [ Shortcuts ] *****
 
 
***** [ Scheduled tasks ] *****
 
 
***** [ Registry ] *****
 
 
***** [ Web browsers ] *****
 
[C:\Users\Justinas\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Found : aol.com
[C:\Users\Justinas\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Found : ask.com
[C:\Users\Justinas\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Homepage] Found : hxxp://www.trovi.com/?gd=&ctid=CT3321459&octid=EB_ORIGINAL_CTID&ISID=M09E575EF-CB28-4215-B99B-F821A219392B&SearchSource=55&CUI=&UM=6&UP=SP75FB8D5A-DB12-4896-99B0-9304E57CD219&SSPV=
 
########## EOF - C:\AdwCleaner\AdwCleaner[S2].txt - [1069 bytes] ##########
 

 

Attached Files



#5 nasdaq

nasdaq

  • Malware Response Team
  • 38,936 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:03:54 PM

Posted 31 August 2015 - 07:42 AM

Please run the AdwCleaner tool and clean all this is found.

===

Download to your Desktop the Junkware Removal Tool Download from this link.
http://www.bleepingcomputer.com/download/junkware-removal-tool/

Shutdown your antivirus to avoid any conflicts.
Right click the icon - disable for say 20 mins.
Right-mouse click JRT.exe and select Run as administrator (If using XP just double click on the icon to run it.)
The tool will open and start scanning your system.
Please be patient as this can take a while to complete.
On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
Post the contents of JRT.txt into your next message.
======

--RogueKiller--
  • Download & SAVE to your Desktop Download RogueKiller
  • Quit all programs that you may have started.
  • Please disconnect any USB or external drives from the computer before you run this scan!
  • For Vista or Windows 7, right-click and select "Run as Administrator to start"
  • For Windows XP, double-click to start.
  • Wait until Prescan has finished ...
  • When instructed Click on "Scan" button
  • Wait until the Status box shows "Scan Finished"
  • Click on "Report"
  • Click on Export TXT button save the file as RogueReport.txt
  • The file RogueReport.txt will be saved in the desktop.
  • Close the program.
  • Open the file with Notepad and Copy/paste the content into your next reply.
<<<>>>

Let me know if the problem persists.

#6 JusTLC

JusTLC
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Lithuania
  • Local time:10:54 PM

Posted 02 September 2015 - 12:19 PM

Okay, so, after the scans the problem still persists, I've tried to reinstall Chrome just in case, but it had no effect.

 

Task manager shows 2 COM Surrogates now.

 

Logs:

 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 7.6.0 (08.31.2015:1)
OS: Windows 10 Enterprise x64
Ran by Justinas on 2015-09-02 at 10:48:28,53
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
 
 
 
~~~ Services
 
 
 
~~~ Tasks
 
 
 
~~~ Registry Values
 
 
 
~~~ Registry Keys
 
 
 
~~~ Files
 
 
 
~~~ Folders
 
 
 
~~~ Chrome
 
 
[C:\Users\Justinas\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - default search provider reset
 
[C:\Users\Justinas\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - Extensions Deleted:
 
[C:\Users\Justinas\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - default search provider reset
 
[C:\Users\Justinas\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - Extensions Deleted:
[]
 
 
 
 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 2015-09-02 at 10:51:34,10
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
RogueKiller V10.10.3.0 (x64) [Aug 31 2015] by Adlice Software
 
Operating System : Windows 10 (10.0.10240) 64 bits version
Started in : Normal mode
User : Justinas [Administrator]
Started from : C:\Users\Justinas\Desktop\RogueKillerX64.exe
Mode : Scan -- Date : 09/02/2015 20:11:10
 
¤¤¤ Processes : 0 ¤¤¤
 
¤¤¤ Registry : 2 ¤¤¤
[PUM.StartMenu] (X64) HKEY_USERS\S-1-5-21-3691003279-1683200719-2023029133-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_TrackProgs : 0  -> Found
[PUM.StartMenu] (X86) HKEY_USERS\S-1-5-21-3691003279-1683200719-2023029133-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_TrackProgs : 0  -> Found
 
¤¤¤ Tasks : 0 ¤¤¤
 
¤¤¤ Files : 0 ¤¤¤
 
¤¤¤ Hosts File : 0 ¤¤¤
 
¤¤¤ Antirootkit : 0 (Driver: Loaded) ¤¤¤
 
¤¤¤ Web browsers : 0 ¤¤¤
 
¤¤¤ MBR Check : ¤¤¤
+++++ PhysicalDrive0: TOSHIBA DT01ACA100 ATA Device +++++
--- User ---
[MBR] edfa383886b5cc668e6043b509b0e2ec
[BSP] cbcf5acfa2ad7ea17a9984fc75bbc271 : Windows Vista/7/8|VT.Unknown MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 500 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 1026048 | Size: 953366 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 ... OK
User = LL2 ... OK
 


#7 nasdaq

nasdaq

  • Malware Response Team
  • 38,936 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:03:54 PM

Posted 02 September 2015 - 12:39 PM


Please make sure you have all the important Windows 7 security updates.

This page may help.
http://windows.microsoft.com/en-ca/windows-10/getstarted-choose-how-updates-are-installed

#8 JusTLC

JusTLC
  • Topic Starter

  • Members
  • 11 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Lithuania
  • Local time:10:54 PM

Posted 02 September 2015 - 12:50 PM

It's up to date.

 

Also, the page you've linked doesn't load properly no matter how many times I refresh it. It occasionally happens with other websites.

Attached Files



#9 nasdaq

nasdaq

  • Malware Response Team
  • 38,936 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:03:54 PM

Posted 03 September 2015 - 06:53 AM

I do not have Windows 10 presently.
I get the page OK with Windows 7.

Try this fix.
http://www.bleepingcomputer.com/forums/t/588448/browser-errors-and-multiple-com-surrogates-after-virus-cleanup/

If that does not solve your problem I suggest you start a new topic in the Windows 10 forum.

http://www.bleepingcomputer.com/forums/f/229/windows-10/

Someone will be able to help you there.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users