Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

windows 10 browsing and apps not all working like it should


  • This topic is locked This topic is locked
17 replies to this topic

#1 Anora

Anora

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Local time:06:11 AM

Posted 27 September 2015 - 05:51 PM

so i just got a log made log whit Hijackthis for you all
 
I have tride to use the tool you guys offer but what ever i have is bloking it from beinf downloaded giving me a page error witch is my current problems some sites working others not

Logfile of Trend Micro HijackThis v2.0.5
Scan saved at 7:44:16 PM, on 9/27/2015
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v11.0 (11.00.10240.16412)

FIREFOX: 41.0 (x86 en-US)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
I:\Program Files (x86)\Origin\Origin.exe
C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\CyberLink\PowerDVD15\PowerDVD15Agent.exe
C:\Program Files (x86)\APC\PowerChute Personal Edition\apcsystray.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\SyncServer.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWelcome.exe
C:\Program Files (x86)\Notepad++\notepad++.exe
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe
C:\Users\Anora\Downloads\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_60\bin\ssv.dll
O2 - BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_60\bin\jp2ssv.dll
O4 - HKLM\..\Run: [LiveUpdate 5] C:\Program Files (x86)\MSI\Live Update 5\BootStartLiveupdate.exe /reminder
O4 - HKLM\..\Run: [Fast Boot] C:\Program Files (x86)\MSI\Fast Boot\StartFastBoot.exe
O4 - HKLM\..\Run: [Dropbox] "C:\Program Files (x86)\Dropbox\Client\Dropbox.exe" /systemstartup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [PowerDVD15Agent] "C:\Program Files (x86)\CyberLink\PowerDVD15\PowerDVD15Agent.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [Display] C:\Program Files (x86)\APC\PowerChute Personal Edition\DataCollectionLauncher.exe
O4 - HKLM\..\Run: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
O4 - HKLM\..\Run: [SDTray] "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe"
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
O4 - HKCU\..\Run: [OneDrive] "C:\Users\Anora\AppData\Local\Microsoft\OneDrive\OneDrive.exe" /background
O4 - HKCU\..\Run: [EADM] "I:\Program Files (x86)\Origin\Origin.exe" -AutoStart
O4 - HKUS\S-1-5-19\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [OneDriveSetup] C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (User 'NETWORK SERVICE')
O4 - Global Startup: APC UPS Status.lnk = C:\Program Files (x86)\APC\PowerChute Personal Edition\Display.exe
O4 - Global Startup: Killer Network Manager.lnk = ?
O9 - Extra button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: http://*.webcompanion.com
O18 - Protocol: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O18 - Protocol: tbauth - {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\SysWOW64\tbauth.dll
O20 - Winlogon Notify: SDWinLogon - SDWinLogon.dll (file missing)
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\WINDOWS\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\WINDOWS\system32\atiesrxx.exe (file missing)
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: APC Data Service - Schneider Electric - C:\Program Files (x86)\APC\PowerChute Personal Edition\dataserv.exe
O23 - Service: APC UPS Service - Schneider Electric - C:\Program Files (x86)\APC\PowerChute Personal Edition\mainserv.exe
O23 - Service: Apple Mobile Device Service - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Avast Antivirus (avast! Antivirus) - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Dropbox Update Service (dbupdate) (dbupdate) - Dropbox, Inc. - C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
O23 - Service: Dropbox Update Service (dbupdatem) (dbupdatem) - Dropbox, Inc. - C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
O23 - Service: @%SystemRoot%\system32\DiagSvcs\DiagnosticsHub.StandardCollector.ServiceRes.dll,-1000 (diagnosticshub.standardcollector.service) - Unknown owner - C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe (file missing)
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\WINDOWS\system32\fxssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\WINDOWS\system32\IEEtwCollector.exe (file missing)
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\WINDOWS\System32\msdtc.exe (file missing)
O23 - Service: MSI_FastBoot - MSI - C:\Program Files (x86)\MSI\Fast Boot\FastBootService.exe
O23 - Service: @mqutil.dll,-6102 (MSMQ) - Unknown owner - C:\WINDOWS\system32\mqsvc.exe (file missing)
O23 - Service: MySQL56 - Unknown owner - C:\Program Files\MySQL\MySQL Server 5.6\bin\mysqld.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\System32\ngcsvc.dll,-100 (NgcSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Origin Client Service - Electronic Arts - I:\Program Files (x86)\Origin\OriginClientService.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Qualcomm Atheros Killer Service V2 - Qualcomm Atheros - C:\Program Files\Qualcomm Atheros\Network Manager\KillerService.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\WINDOWS\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Spybot-S&D 2 Scanner Service (SDScannerService) - Safer-Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
O23 - Service: Spybot-S&D 2 Updating Service (SDUpdateService) - Safer-Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
O23 - Service: Spybot-S&D 2 Security Center Service (SDWSCService) - Safer-Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
O23 - Service: @%SystemRoot%\system32\SensorDataService.exe,-101 (SensorDataService) - Unknown owner - C:\WINDOWS\System32\SensorDataService.exe (file missing)
O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\WINDOWS\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\WINDOWS\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\WINDOWS\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\WINDOWS\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\WINDOWS\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\WINDOWS\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-320 (WdNisSvc) - Unknown owner - C:\Program Files (x86)\Windows Defender\NisSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 11260 bytes

Attached Files


Edited by Oh My!, 27 September 2015 - 07:03 PM.


BC AdBot (Login to Remove)

 


#2 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 37,005 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:03:11 AM

Posted 27 September 2015 - 07:07 PM

Greetings Anora and :welcome: to BleepingComputer's Virus/Trojan/Spyware/Malware Removal forum.

My name is Oh My! and I am here to help you! Now that we are "friends" please call me Gary.

If you would allow me to call you by your first name I would prefer to do that.

===================================================

Ground Rules:
  • First, I would like to inform you that most of us here at Bleeping Computer offer our expert assistance out of the goodness of our hearts. Please try to match our commitment to you with your patience toward us. If this was easy we would never have met.
  • Please do not run any tools or take any steps other than those I will provide for you while we work on your computer together. I need to be certain about the state of your computer in order to provide appropriate and effective steps for you to take. Most often "well intentioned" (and usually panic driven!) independent efforts can make things much worse for both of us. If at any point you would prefer to take your own steps please let me know, I will not be offended. I would be happy to focus on the many others who are waiting in line for assistance.
  • Please perform all steps in the order they are listed in each set of instructions. Some steps may be a bit complicated. If things are not clear, be sure to stop and let me know. We need to work on this together with confidence.
  • Please copy and paste all logs into your post unless directed otherwise. Please do not re-run any programs I suggest. If you encounter problems simply stop and tell me.
  • When you post your reply, use the Replytopic.jpg button instead.
  • In the upper right hand corner of the topic you will see the Followtopic.jpg button. Click on this then choose Immediate E-Mail notification and then Proceed and you will be sent an email once I have posted a response.
  • If you do not reply to your topic after 5 days we assume it has been abandoned and I will close it.
  • When your computer is clean I will alert you of such. I will also provide for you detailed information about how you can combat future infections.
  • I would like to remind you to make no further changes to your computer unless I direct you to do so.
===================================================

Now that I am assisting you, you can expect that I will be very responsive to your situation. If you are able, I would request you check this thread at least once per day so that we can try to resolve your issues effectively and efficiently. If you are going to be delayed please be considerate and post that information so that I know you are still with me. Unfortunately, there are many people waiting to be assisted and not enough of us at BleepingComputer to go around. I appreciate your understanding and diligence.

Thank you for your patience thus far.

If you can't complete the below step in Safe Mode with Networking please download FRST onto a USB device from a clean computer then transfer it to the infected machine.

===================================================

Farbar Recovery Scan Tool (FRST)

--------------------
  • Boot your computer into Safe Mode with Networking
  • Download Farbar Recover Scan Tool for either 32 bit or 64 bit systems and save it to your desktop <<< Important
  • If you are unsure if you have 32 bit or 64 bit simply download and try one. If that doesn't run properly the other one should
  • Double click the icon
  • Click Yes to the disclaimer
  • Make sure the Addition.txt box is checked
  • Click Scan and allow the program to run
  • Click OK on the Scan complete screen, then OK on the Addition.txt pop up screen
  • 2 Notepad documents should now be open on your desktop.
  • Please copy and paste the contents of both in your reply
===================================================

System Summary Information

--------------------
  • Press the windows key Windows_Logo_key.gif + r on your keyboard at the same time
  • Type msinfo32 and press Enter
  • Left click on System Summary
  • Click File, Save, and name the file Summary
  • Zip and attach the file to your reply
===================================================

Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it. :thumbsup2:
  • FRST results
  • Addition log
  • System Summary Information

Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#3 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 37,005 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:03:11 AM

Posted 30 September 2015 - 03:01 PM

Greetings,

===================================================

3 Day Bump

It has been more than 3 days since my last post.
  • Do you still need help with this?
  • If after 48hrs you have not replied to this thread then it will have to be closed.

Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#4 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 37,005 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:03:11 AM

Posted 02 October 2015 - 09:16 PM

Due to the lack of feedback, this topic is now closed.

In the event you still have problems, please send me or any Moderator a Private Message and ask them to reopen this topic within the next 5 days.

Please include a link to your topic in the Private Message. Thank you.
Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#5 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 37,005 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:03:11 AM

Posted 03 October 2015 - 08:10 AM

This topic has been re-opened at the request of the person who originally posted.
Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#6 Anora

Anora
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Local time:06:11 AM

Posted 05 October 2015 - 09:36 AM

I may have fixed it on my own but just incase im submiting this still. Thanks in advance.

I think it was a driver problem by what i saw just neded an update

 

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:04-10-2015
Ran by Anora (administrator) on ANORA-PC (05-10-2015 11:28:50)
Running from C:\Users\Anora\Desktop
Loaded Profiles: Anora (Available Profiles: Anora & Classic .NET AppPool & dynmap & wildrenter)
Platform: Windows 10 Pro (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Schneider Electric) C:\Program Files (x86)\APC\PowerChute Personal Edition\mainserv.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Advanced Micro Devices, Inc.) C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe
(Microsoft Corporation) C:\Windows\System32\mqsvc.exe
() C:\Program Files\MySQL\MySQL Server 5.6\bin\mysqld.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(Rivet Networks) C:\Program Files\Killer Networking\Network Manager\KillerService.exe
(Micro-Star INT'L CO., LTD.) C:\Program Files (x86)\MSI\Live Update\MSI_LiveUpdate_Service.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersServer.exe
(Microsoft Corporation) C:\Windows\System32\Speech_OneCore\Common\SpeechRuntime.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Electronic Arts) I:\Program Files (x86)\Origin\Origin.exe
(Vag-Labs) C:\Program Files (x86)\Vag-Labs\RAM Monitor\RAM Monitor.exe
(Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
(Schneider Electric) C:\Program Files (x86)\APC\PowerChute Personal Edition\apcsystray.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD15\PowerDVD15Agent.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\MOM.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
(Micro-Star INT'L CO., LTD.) C:\Program Files (x86)\MSI\Live Update\Live Update.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\CCC.exe
(TeamSpeak Systems GmbH) C:\Program Files\TeamSpeak 3 Client\ts3client_win64.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.6224.42281.0_x64__8wekyb3d8bbwe\HxMail.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.6224.42281.0_x64__8wekyb3d8bbwe\HxTsr.exe
(Valve Corporation) I:\Program Files (x86)\Steam\Steam.exe
(Valve Corporation) I:\Program Files (x86)\Steam\bin\steamwebhelper.exe
(Valve Corporation) I:\Program Files (x86)\Steam\bin\steamwebhelper.exe
(MultiMC Contributors) J:\MultyMc5\MultiMC.exe
(Oracle Corporation) C:\Program Files\Java\jre1.8.0_60\bin\java.exe
(Valve Corporation) I:\Program Files (x86)\Steam\GameOverlayUI.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_19_0_0_185.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_19_0_0_185.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8492800 2015-06-24] (Realtek Semiconductor)
HKLM\...\Run: [VIAxHCUtl] => C:\Program Files\VIA XHCI UASP Utility\usb3Monitor
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [170256 2015-09-15] (Apple Inc.)
HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [36710768 2015-10-01] (Dropbox, Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [597552 2015-08-04] (Oracle Corporation)
HKLM-x32\...\Run: [PowerDVD15Agent] => C:\Program Files (x86)\CyberLink\PowerDVD15\PowerDVD15Agent.exe [949960 2015-08-10] (CyberLink Corp.)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe [767176 2015-08-21] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [Display] => C:\Program Files (x86)\APC\PowerChute Personal Edition\DataCollectionLauncher.exe [284024 2012-01-24] (Schneider Electric)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [6134544 2015-09-25] (AVAST Software)
HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [4101576 2014-06-24] (Safer-Networking Ltd.)
HKLM-x32\...\Run: [Live Update] => C:\Program Files (x86)\MSI\Live Update\Live Update.exe [11328464 2015-09-11] (Micro-Star INT'L CO., LTD.)
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
HKU\S-1-5-21-434036944-719920970-2392407034-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [53729824 2015-08-07] (Skype Technologies S.A.)
HKU\S-1-5-21-434036944-719920970-2392407034-1000\...\Run: [EADM] => I:\Program Files (x86)\Origin\Origin.exe [3638768 2015-10-02] (Electronic Arts)
HKU\S-1-5-21-434036944-719920970-2392407034-1000\...\Run: [RAM Monitor] => C:\Program Files (x86)\Vag-Labs\RAM Monitor\RAM Monitor.exe [562176 2008-10-29] (Vag-Labs)
HKU\S-1-5-21-434036944-719920970-2392407034-1000\...\Policies\system: [DisableLockWorkstation] 0
ShellIconOverlayIdentifiers: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.dll [2015-10-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.dll [2015-10-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.dll [2015-10-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.dll [2015-10-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.dll [2015-10-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.dll [2015-10-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.dll [2015-10-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.dll [2015-10-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2015-09-25] (AVAST Software)
ShellIconOverlayIdentifiers-x32: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.27.dll [2015-10-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.27.dll [2015-10-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.27.dll [2015-10-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.27.dll [2015-10-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.27.dll [2015-10-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.27.dll [2015-10-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.27.dll [2015-10-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.27.dll [2015-10-01] (Dropbox, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\APC UPS Status.lnk [2015-09-19]
ShortcutTarget: APC UPS Status.lnk -> C:\Program Files (x86)\APC\PowerChute Personal Edition\Display.exe (Schneider Electric)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Killer Network Manager.lnk [2015-10-02]
ShortcutTarget: Killer Network Manager.lnk -> C:\Program Files\Killer Networking\Network Manager\NetworkManager.exe (Rivet Networks)
BootExecute: autocheck autochk * sdnclean64.exe

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 64.71.255.204 64.71.255.198
Tcpip\..\Interfaces\{a06edd46-d5b5-47bb-ae28-6973544822b8}: [DhcpNameServer] 64.71.255.204 64.71.255.198

Internet Explorer:
==================
HKU\S-1-5-21-434036944-719920970-2392407034-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/en-ca/?ocid=iehp
SearchScopes: HKU\S-1-5-21-434036944-719920970-2392407034-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_60\bin\ssv.dll [2015-08-28] (Oracle Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-09-25] (AVAST Software)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-05-01] (Microsoft Corporation)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_60\bin\jp2ssv.dll [2015-08-28] (Oracle Corporation)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\ssv.dll [2015-08-28] (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-09-25] (AVAST Software)
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01] (Microsoft Corporation)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\jp2ssv.dll [2015-08-28] (Oracle Corporation)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-05-01] (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01] (Microsoft Corporation)

FireFox:
========
FF ProfilePath: C:\Users\Anora\AppData\Roaming\Mozilla\Firefox\Profiles\htphesra.default-1441742598665
FF Homepage: about:home
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_19_0_0_185.dll [2015-09-22] ()
FF Plugin: @java.com/DTPlugin,version=11.60.2 -> C:\Program Files\Java\jre1.8.0_60\bin\dtplugin\npDeployJava1.dll [2015-08-28] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.60.2 -> C:\Program Files\Java\jre1.8.0_60\bin\plugin2\npjp2.dll [2015-08-28] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_19_0_0_185.dll [2015-09-22] ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-10-30] ()
FF Plugin-x32: @java.com/DTPlugin,version=11.60.2 -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\dtplugin\npDeployJava1.dll [2015-08-28] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.60.2 -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\plugin2\npjp2.dll [2015-08-28] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Extension: YouTube Unblocker - C:\Users\Anora\AppData\Roaming\Mozilla\Firefox\Profiles\htphesra.default-1441742598665\Extensions\youtubeunblocker@unblocker.yt [2015-09-08]
FF Extension: DownThemAll! AntiContainer - C:\Users\Anora\AppData\Roaming\Mozilla\Firefox\Profiles\htphesra.default-1441742598665\Extensions\anticontainer@downthemall.net.xpi [2015-09-08]
FF Extension: Element Hiding Helper for Adblock Plus - C:\Users\Anora\AppData\Roaming\Mozilla\Firefox\Profiles\htphesra.default-1441742598665\Extensions\elemhidehelper@adblockplus.org.xpi [2015-09-08]
FF Extension: FurAffinity Extender - C:\Users\Anora\AppData\Roaming\Mozilla\Firefox\Profiles\htphesra.default-1441742598665\Extensions\faextender@neocodenetworks.com.xpi [2015-09-14]
FF Extension: Forecastfox (fix version) - C:\Users\Anora\AppData\Roaming\Mozilla\Firefox\Profiles\htphesra.default-1441742598665\Extensions\forecastfox@s3_fix_version.xpi [2015-09-08]
FF Extension: YouTube mp3 - C:\Users\Anora\AppData\Roaming\Mozilla\Firefox\Profiles\htphesra.default-1441742598665\Extensions\info@youtube-mp3.org.xpi [2015-09-08]
FF Extension: Long URL Please - C:\Users\Anora\AppData\Roaming\Mozilla\Firefox\Profiles\htphesra.default-1441742598665\Extensions\longurlplease@darragh.curran.xpi [2015-09-08]
FF Extension: Status-4-Evar - C:\Users\Anora\AppData\Roaming\Mozilla\Firefox\Profiles\htphesra.default-1441742598665\Extensions\status4evar@caligonstudios.com.xpi [2015-09-08]
FF Extension: TortoiseSVN Menu - C:\Users\Anora\AppData\Roaming\Mozilla\Firefox\Profiles\htphesra.default-1441742598665\Extensions\tsvnmenu@pumacode.org.xpi [2015-09-08]
FF Extension: 1-Click YouTube Video Downloader - C:\Users\Anora\AppData\Roaming\Mozilla\Firefox\Profiles\htphesra.default-1441742598665\Extensions\YoutubeDownloader@PeterOlayev.com.xpi [2015-09-08]
FF Extension: YouTube High Definition - C:\Users\Anora\AppData\Roaming\Mozilla\Firefox\Profiles\htphesra.default-1441742598665\Extensions\{7b1bf0b6-a1b9-42b0-b75d-252036438bdc}.xpi [2015-09-08]
FF Extension: Adblock Plus - C:\Users\Anora\AppData\Roaming\Mozilla\Firefox\Profiles\htphesra.default-1441742598665\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-09-08]
FF Extension: DownThemAll! - C:\Users\Anora\AppData\Roaming\Mozilla\Firefox\Profiles\htphesra.default-1441742598665\Extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi [2015-09-08]
FF Extension: Download Manager Tweak - C:\Users\Anora\AppData\Roaming\Mozilla\Firefox\Profiles\htphesra.default-1441742598665\Extensions\{F8A55C97-3DB6-4961-A81D-0DE0080E53CB}.xpi [2015-09-08]
FF Extension: No Name - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2015-09-30]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2015-09-25]

Chrome:
=======
CHR HKU\S-1-5-21-434036944-719920970-2392407034-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [bknbnapaddjdnbilpmlacdkjdkjmbjhd] - hxxp://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [bknbnapaddjdnbilpmlacdkjdkjmbjhd] - hxxp://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx [2015-09-25]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-09-25]

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AMD FUEL Service; C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe [344064 2015-08-21] (Advanced Micro Devices, Inc.) [File not signed]
S2 APC Data Service; C:\Program Files (x86)\APC\PowerChute Personal Edition\dataserv.exe [21880 2012-01-24] (Schneider Electric)
R2 APC UPS Service; C:\Program Files (x86)\APC\PowerChute Personal Edition\mainserv.exe [705912 2012-01-24] (Schneider Electric)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77104 2015-09-02] (Apple Inc.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [146600 2015-09-25] (AVAST Software)
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1394816 2015-05-01] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1772672 2015-05-01] (Microsoft Corporation)
S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [136048 2015-08-13] (Dropbox, Inc.)
S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [136048 2015-08-13] (Dropbox, Inc.)
R2 Killer Service V2; C:\Program Files\Killer Networking\Network Manager\KillerService.exe [402432 2015-07-07] (Rivet Networks) [File not signed]
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2015-06-18] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation)
R2 MSI_LiveUpdate_Service; C:\Program Files (x86)\MSI\Live Update\MSI_LiveUpdate_Service.exe [1768912 2015-09-11] (Micro-Star INT'L CO., LTD.)
R2 MSMQ; C:\Windows\system32\mqsvc.exe [26112 2015-08-20] (Microsoft Corporation)
R2 MySQL56; C:\Program Files\MySQL\MySQL Server 5.6\bin\mysqld.exe [13061632 2015-07-15] () [File not signed]
S3 Origin Client Service; I:\Program Files (x86)\Origin\OriginClientService.exe [2078216 2015-10-02] (Electronic Arts)
R2 PnkBstrA; C:\WINDOWS\SysWOW64\PnkBstrA.exe [66872 2015-09-14] ()
R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1738168 2014-06-24] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2088408 2014-06-27] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2014-04-25] (Safer-Networking Ltd.)
S3 Te.Service; C:\Program Files (x86)\Windows Kits\8.1\Testing\Runtimes\TAEF\Wex.Services.exe [119808 2013-08-22] (Microsoft Corporation) [File not signed]
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [5702416 2015-09-11] (TeamViewer GmbH)
S3 w3logsvc; C:\Windows\system32\inetsrv\w3logsvc.dll [84480 2015-08-20] (Microsoft Corporation)
R2 W3SVC; C:\Windows\system32\inetsrv\iisw3adm.dll [578560 2015-08-20] (Microsoft Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [362928 2015-07-10] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-07-10] (Microsoft Corporation)

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R0 amdkmafd; C:\Windows\System32\drivers\amdkmafd.sys [40720 2015-07-28] (Advanced Micro Devices, Inc.)
R2 AODDriver4.3; C:\Program Files\AMD\ATI.ACE\Fuel\amd64\AODDriver2.sys [59616 2014-02-11] (Advanced Micro Devices)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [28656 2015-09-25] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [90968 2015-09-25] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-09-25] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65224 2015-09-25] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1049880 2015-09-25] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [448968 2015-09-25] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [153744 2015-09-25] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [274808 2015-09-25] (AVAST Software)
R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdWT6.sys [102912 2015-07-21] (Advanced Micro Devices)
S3 dc1-controller; C:\Windows\System32\drivers\dc1-controller.sys [50688 2015-07-10] (Microsoft Corp.)
S3 DCamUSBNovatek; C:\Windows\System32\Drivers\nvtcam.sys [2746624 2010-07-14] (Hewlett-Packard) [File not signed]
S3 ipadtst; C:\Program Files (x86)\MSI\Super Charger\ipadtst_64.sys [20464 2013-11-11] (Windows ® Win 7 DDK provider)
S3 Ke2200; C:\Windows\System32\drivers\e22w7x64.sys [154320 2013-03-20] (Qualcomm Atheros, Inc.)
R3 KillerEth; C:\Windows\System32\drivers\e22w10x64.sys [124464 2015-04-27] (Qualcomm Atheros, Inc.)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2015-06-18] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [113880 2015-10-05] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2015-06-18] (Malwarebytes Corporation)
R3 MQAC; C:\Windows\System32\drivers\mqac.sys [175104 2015-08-20] (Microsoft Corporation)
S3 NTIOLib_1_0_3; C:\Program Files (x86)\MSI\Super Charger\NTIOLib_X64.sys [13368 2012-10-25] (MSI)
S3 NTIOLib_1_0_6; C:\Program Files (x86)\Setup Files\Ms7693vM30\NTIOLib_X64.sys [11888 2011-01-06] (MSI) [File not signed]
S3 NTIOLib_FastBoot; C:\Program Files (x86)\MSI\Fast Boot\NTIOLib_X64.sys [13368 2012-10-26] (MSI)
S3 NTIOLib_MSIClock_CC; C:\Program Files (x86)\MSI\Command Center\ClockGen\NTIOLib_X64.sys [13368 2012-11-20] (MSI)
S3 NTIOLib_MSICPU_CC; C:\Program Files (x86)\MSI\Command Center\CPU\NTIOLib_X64.sys [13368 2012-11-20] (MSI)
S3 NTIOLib_MSIDDR_CC; C:\Program Files (x86)\MSI\Command Center\DDR\NTIOLib_X64.sys [13368 2012-11-26] (MSI)
S3 NTIOLib_MSISMB_CC; C:\Program Files (x86)\MSI\Command Center\SMBus\NTIOLib_X64.sys [13368 2012-11-19] (MSI)
R3 Phosgene; C:\Windows\system32\DRIVERS\Phosgene.sys [32120 2015-06-08] ()
S3 UdeCx; C:\Windows\System32\drivers\udecx.sys [44032 2015-07-10] ()
S3 usbser64; C:\Windows\system32\DRIVERS\usbser.sys [67072 2015-08-20] (Microsoft Corporation)
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44568 2015-07-10] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [291680 2015-07-10] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [119648 2015-07-10] (Microsoft Corporation)
R2 {687703DE-DC6D-4649-892B-B8497854A6AB}; C:\Program Files (x86)\CyberLink\PowerDVD15\Common\NavFilter\000.fcl [29896 2015-08-10] (CyberLink Corp.)
U3 idsvc; no ImagePath
S3 NTIOLib_MSICOMM_CC; \??\C:\Program Files (x86)\MSI\Command Center\NTIOLib_X64.sys [X]
S3 NTIOLib_MSIFrequency_CC; \??\C:\Program Files (x86)\MSI\Command Center\ClockGen\CPU_Frequency\NTIOLib_X64.sys [X]
S3 NTIOLib_MSIRatio_CC; \??\C:\Program Files (x86)\MSI\Command Center\CPU\CPU_Ratio\NTIOLib_X64.sys [X]
S3 NTIOLib_MSISuperIO_CC; \??\C:\Program Files (x86)\MSI\Command Center\SuperIO\NTIOLib_X64.sys [X]
S3 wfpcapture; \SystemRoot\System32\drivers\wfpcapture.sys [X]
U3 wpcsvc; no ImagePath

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-10-05 11:28 - 2015-10-05 11:29 - 00025962 _____ C:\Users\Anora\Desktop\FRST.txt
2015-10-05 11:28 - 2015-10-05 11:28 - 00000000 ____D C:\Users\Anora\Desktop\FRST-OlderVersion
2015-10-05 11:18 - 2015-10-05 11:18 - 00016148 _____ C:\WINDOWS\system32\ANORA-PC_Anora_HistoryPrediction.bin
2015-10-05 01:30 - 2015-10-05 01:30 - 00109628 _____ C:\Users\Anora\Downloads\A Different Perspective ( 19 - Chapter 19_ We've Only Just Begun ).txt
2015-10-05 01:30 - 2015-10-05 01:30 - 00015497 _____ C:\Users\Anora\Downloads\The Monster of Canterlot ( 56 -  ).txt
2015-10-04 21:56 - 2015-10-04 21:56 - 00011820 _____ C:\Users\Anora\Downloads\ResourceLoader-1.2.jar
2015-10-04 21:49 - 2015-10-04 21:50 - 18393499 _____ C:\Users\Anora\Downloads\UNZIP ME - Sim-U-Kraft Reloaded 1.0.4a - UNZIP ME.zip
2015-10-04 21:45 - 2015-10-04 21:45 - 00589182 _____ C:\Users\Anora\Downloads\Sim-U-Kraft Mod Installer 1.7.10.zip
2015-10-04 21:23 - 2015-10-04 21:23 - 01177769 _____ C:\Users\Anora\Downloads\SimCraftClientLauncher.jar
2015-10-04 16:16 - 2015-10-04 16:16 - 00351928 _____ C:\Users\Anora\Downloads\EnderZoo-1.7.10-1.0.15.32(1).jar
2015-10-03 19:43 - 2015-10-03 19:43 - 00000000 ____D C:\Users\Anora\AppData\Roaming\TeamViewer
2015-10-03 19:09 - 2015-10-03 19:09 - 00001112 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 10.lnk
2015-10-03 19:09 - 2015-10-03 19:09 - 00001100 _____ C:\Users\Public\Desktop\TeamViewer 10.lnk
2015-10-03 19:09 - 2015-10-03 19:09 - 00000000 ____D C:\Program Files (x86)\TeamViewer
2015-10-03 19:08 - 2015-10-03 19:08 - 08159440 _____ (TeamViewer GmbH) C:\Users\Anora\Downloads\TeamViewer_Setup_en-jfx.exe
2015-10-03 13:50 - 2015-10-03 13:50 - 01177521 _____ C:\Users\Anora\Desktop\GraveStone-2.12.4.jar
2015-10-03 13:43 - 2015-10-03 13:43 - 00583293 _____ C:\Users\Anora\Downloads\Gravestone Mod Installer 1.7.10.zip
2015-10-03 10:41 - 2015-10-03 10:41 - 00138825 _____ C:\Users\Anora\Documents\summary.zip
2015-10-03 10:40 - 2015-10-03 10:40 - 03486834 _____ C:\Users\Anora\Documents\summary.nfo
2015-10-03 10:11 - 2015-10-03 10:11 - 00000000 _____ C:\Users\Anora\Desktop\New Text Document.txt
2015-10-03 10:04 - 2015-10-03 10:06 - 00065325 _____ C:\Users\Anora\Downloads\Addition.txt
2015-10-03 10:02 - 2015-10-05 11:29 - 00000000 ____D C:\FRST
2015-10-03 10:02 - 2015-10-05 11:28 - 02193920 _____ (Farbar) C:\Users\Anora\Desktop\FRST64.exe
2015-10-03 10:02 - 2015-10-03 10:04 - 00096729 _____ C:\Users\Anora\Downloads\FRST.txt
2015-10-03 08:51 - 2015-10-03 08:51 - 00000000 ____D C:\ApcTempReg
2015-10-02 21:10 - 2015-10-02 21:10 - 00000020 ___SH C:\Users\dynmap\ntuser.ini
2015-10-02 21:10 - 2015-10-02 21:10 - 00000000 ____D C:\Users\dynmap
2015-10-02 21:10 - 2015-08-20 09:27 - 00000000 ___RD C:\Users\dynmap\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-10-02 21:10 - 2015-07-10 08:04 - 00000000 __RSD C:\Users\dynmap\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell
2015-10-02 21:10 - 2015-07-10 08:04 - 00000000 ___RD C:\Users\dynmap\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-10-02 21:10 - 2015-07-10 08:04 - 00000000 ___RD C:\Users\dynmap\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2015-10-02 21:10 - 2015-07-10 08:04 - 00000000 ____D C:\Users\dynmap\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-10-02 19:47 - 2015-10-02 19:47 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Kits
2015-10-02 19:44 - 2015-10-02 19:44 - 00000000 ____D C:\Program Files (x86)\Windows Kits
2015-10-02 19:37 - 2015-09-15 13:12 - 00812008 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2015-10-02 19:37 - 2015-09-15 13:12 - 00178152 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2015-10-02 19:26 - 2015-05-12 18:13 - 00061464 _____ (Advanced Micro Devices) C:\WINDOWS\system32\Drivers\usbfilter.sys
2015-10-02 19:24 - 2015-10-02 19:24 - 51527840 _____ (AMD Inc.) C:\Users\Anora\Downloads\amd-catalyst-15.7.1-sb-sata-ahci-win10-win8.1-win7.exe
2015-10-02 19:20 - 2015-10-02 19:20 - 00002104 _____ C:\Users\Public\Desktop\MSI Live Update 6.lnk
2015-10-02 19:20 - 2015-10-02 19:20 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MSI
2015-10-02 19:18 - 2015-10-02 19:19 - 06980685 _____ C:\Users\Anora\Downloads\LiveUpdate.zip
2015-10-02 19:12 - 2015-10-02 19:13 - 00000000 ____D C:\ProgramData\Killer
2015-10-02 19:12 - 2015-10-02 19:12 - 00002801 _____ C:\Users\Public\Desktop\Killer Network Manager.lnk
2015-10-02 19:12 - 2015-10-02 19:12 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Killer Networking
2015-10-02 19:10 - 2015-10-02 19:10 - 00000000 ____D C:\Program Files\Killer Networking
2015-10-02 18:56 - 2015-10-02 19:07 - 261180638 _____ C:\Users\Anora\Downloads\Killer_network_w10.zip
2015-10-02 18:56 - 2015-10-02 18:58 - 238920953 _____ C:\Users\Anora\Downloads\realtek_hd_audio(1).zip
2015-10-02 18:55 - 2015-10-02 19:00 - 04424219 _____ C:\Users\Anora\Downloads\7693vM3.zip
2015-10-02 18:44 - 2015-10-02 18:44 - 00991968 _____ (Microsoft Corporation) C:\Users\Anora\Downloads\wdksetup.exe
2015-10-02 18:37 - 2015-10-02 18:37 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Vag-Labs
2015-10-02 18:37 - 2015-10-02 18:37 - 00000000 ____D C:\Program Files (x86)\Vag-Labs
2015-10-02 18:36 - 2015-10-02 18:37 - 00335927 _____ C:\Users\Anora\Downloads\ram_monitor_setup.zip
2015-10-02 18:36 - 2015-10-02 18:36 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox
2015-10-02 18:22 - 2015-10-02 18:22 - 00000000 ____D C:\Users\Anora\AppData\Local\Micro-Star_Int'l_Co.,_Ltd
2015-10-02 18:20 - 2015-10-02 18:20 - 00100635 _____ C:\Users\Anora\Downloads\MSIAfterburnerRemoteServer.zip
2015-10-02 07:17 - 2015-10-02 07:17 - 00052002 _____ C:\Users\Anora\Downloads\TiCTooltips-mc1.7.10-1.2.5.jar
2015-10-02 07:13 - 2015-10-02 07:13 - 00457912 _____ C:\Users\Anora\Downloads\EnderCore-1.7.10-0.1.0.24_beta.jar
2015-10-02 07:05 - 2015-10-02 07:05 - 00025539 _____ C:\Users\Anora\Downloads\WailaHarvestability-mc1.7.x-1.1.2.jar
2015-10-02 07:04 - 2015-10-02 07:04 - 00074135 _____ C:\Users\Anora\Downloads\WAILAPlugins-MC1.7.10-0.1.2-21.jar
2015-10-01 05:14 - 2015-09-17 03:49 - 06487248 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2015-10-01 05:14 - 2015-09-17 03:28 - 05120056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2015-10-01 05:14 - 2015-09-17 03:12 - 16708608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2015-10-01 05:14 - 2015-09-17 03:07 - 21875712 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2015-10-01 05:14 - 2015-09-17 03:04 - 07569408 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll
2015-10-01 05:14 - 2015-09-17 03:00 - 24595456 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2015-10-01 05:14 - 2015-09-17 02:54 - 03781120 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2015-10-01 05:14 - 2015-09-17 02:53 - 07055872 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll
2015-10-01 05:14 - 2015-09-17 02:51 - 13027840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2015-10-01 05:14 - 2015-09-17 02:51 - 02660864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll
2015-10-01 05:14 - 2015-09-17 02:47 - 07523328 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2015-10-01 05:14 - 2015-09-17 02:45 - 19325440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2015-10-01 05:14 - 2015-09-17 02:40 - 06101504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mos.dll
2015-10-01 05:14 - 2015-09-17 02:37 - 18806272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2015-10-01 05:14 - 2015-09-17 02:35 - 05079552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll
2015-10-01 05:13 - 2015-09-24 21:13 - 01276416 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifinetworkmanager.dll
2015-10-01 05:13 - 2015-09-24 20:17 - 02178560 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2015-10-01 05:13 - 2015-09-24 20:08 - 03586560 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2015-10-01 05:13 - 2015-09-24 20:06 - 01423872 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataService.dll
2015-10-01 05:13 - 2015-09-24 20:01 - 00856576 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContactApis.dll
2015-10-01 05:13 - 2015-09-24 20:00 - 01205248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Unistore.dll
2015-10-01 05:13 - 2015-09-24 19:42 - 01795072 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll
2015-10-01 05:13 - 2015-09-24 19:25 - 00928256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Unistore.dll
2015-10-01 05:13 - 2015-09-24 19:25 - 00625152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ContactApis.dll
2015-10-01 05:13 - 2015-09-17 03:50 - 02464216 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2015-10-01 05:13 - 2015-09-17 03:50 - 01563392 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll
2015-10-01 05:13 - 2015-09-17 03:49 - 08020816 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2015-10-01 05:13 - 2015-09-17 03:49 - 01563472 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpmde.dll
2015-10-01 05:13 - 2015-09-17 03:49 - 00894256 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Wdf01000.sys
2015-10-01 05:13 - 2015-09-17 03:48 - 02824248 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll
2015-10-01 05:13 - 2015-09-17 03:48 - 02494712 _____ C:\WINDOWS\system32\CoreUIComponents.dll
2015-10-01 05:13 - 2015-09-17 03:48 - 02432336 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2015-10-01 05:13 - 2015-09-17 03:48 - 02156400 _____ (Microsoft Corporation) C:\WINDOWS\system32\hevcdecoder.dll
2015-10-01 05:13 - 2015-09-17 03:48 - 01983824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2015-10-01 05:13 - 2015-09-17 03:48 - 00809352 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll
2015-10-01 05:13 - 2015-09-17 03:48 - 00784136 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
2015-10-01 05:13 - 2015-09-17 03:48 - 00555768 _____ (Microsoft Corporation) C:\WINDOWS\system32\directmanipulation.dll
2015-10-01 05:13 - 2015-09-17 03:48 - 00537080 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWanAPI.dll
2015-10-01 05:13 - 2015-09-17 03:48 - 00476760 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFCaptureEngine.dll
2015-10-01 05:13 - 2015-09-17 03:47 - 01397088 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll
2015-10-01 05:13 - 2015-09-17 03:44 - 00781976 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfds.dll
2015-10-01 05:13 - 2015-09-17 03:43 - 00966416 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll
2015-10-01 05:13 - 2015-09-17 03:37 - 01295712 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpx.dll
2015-10-01 05:13 - 2015-09-17 03:28 - 02154808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2015-10-01 05:13 - 2015-09-17 03:28 - 01357888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winmde.dll
2015-10-01 05:13 - 2015-09-17 03:27 - 01766952 _____ C:\WINDOWS\SysWOW64\CoreUIComponents.dll
2015-10-01 05:13 - 2015-09-17 03:27 - 00454512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\directmanipulation.dll
2015-10-01 05:13 - 2015-09-17 03:26 - 02446648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2vdec.dll
2015-10-01 05:13 - 2015-09-17 03:26 - 00646672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll
2015-10-01 05:13 - 2015-09-17 03:26 - 00428128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWanAPI.dll
2015-10-01 05:13 - 2015-09-17 03:25 - 00962400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll
2015-10-01 05:13 - 2015-09-17 03:21 - 00658528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfds.dll
2015-10-01 05:13 - 2015-09-17 03:20 - 00764416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.appcore.dll
2015-10-01 05:13 - 2015-09-17 03:06 - 00467968 _____ (Microsoft Corporation) C:\WINDOWS\system32\MBMediaManager.dll
2015-10-01 05:13 - 2015-09-17 03:05 - 02226688 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll
2015-10-01 05:13 - 2015-09-17 03:04 - 00910848 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedStartModel.dll
2015-10-01 05:13 - 2015-09-17 03:00 - 03248640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2015-10-01 05:13 - 2015-09-17 03:00 - 02417664 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
2015-10-01 05:13 - 2015-09-17 02:58 - 00503808 _____ (Microsoft Corporation) C:\WINDOWS\system32\tileobjserver.dll
2015-10-01 05:13 - 2015-09-17 02:57 - 02228736 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll
2015-10-01 05:13 - 2015-09-17 02:57 - 00281600 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEEventDispatcher.dll
2015-10-01 05:13 - 2015-09-17 02:56 - 00859136 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll
2015-10-01 05:13 - 2015-09-17 02:55 - 02236416 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2015-10-01 05:13 - 2015-09-17 02:55 - 01601536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Speech.dll
2015-10-01 05:13 - 2015-09-17 02:54 - 00780288 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2015-10-01 05:13 - 2015-09-17 02:52 - 01181696 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
2015-10-01 05:13 - 2015-09-17 02:52 - 00591360 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmsvc.dll
2015-10-01 05:13 - 2015-09-17 02:52 - 00570880 _____ (Microsoft Corporation) C:\WINDOWS\system32\MbaeApi.dll
2015-10-01 05:13 - 2015-09-17 02:51 - 01203712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Bluetooth.dll
2015-10-01 05:13 - 2015-09-17 02:51 - 01067520 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2015-10-01 05:13 - 2015-09-17 02:49 - 02740224 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2015-10-01 05:13 - 2015-09-17 02:49 - 01290240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Shell.dll
2015-10-01 05:13 - 2015-09-17 02:49 - 01010176 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXService.dll
2015-10-01 05:13 - 2015-09-17 02:48 - 02093056 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidsvc.dll
2015-10-01 05:13 - 2015-09-17 02:48 - 00517632 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationController.dll
2015-10-01 05:13 - 2015-09-17 02:48 - 00408064 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredProvDataModel.dll
2015-10-01 05:13 - 2015-09-17 02:48 - 00387584 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppBroker.dll
2015-10-01 05:13 - 2015-09-17 02:47 - 00513536 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngcsvc.dll
2015-10-01 05:13 - 2015-09-17 02:45 - 04791296 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2015-10-01 05:13 - 2015-09-17 02:45 - 01331200 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll
2015-10-01 05:13 - 2015-09-17 02:45 - 00869376 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlCore.dll
2015-10-01 05:13 - 2015-09-17 02:45 - 00627712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.dll
2015-10-01 05:13 - 2015-09-17 02:44 - 00526336 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll
2015-10-01 05:13 - 2015-09-17 02:43 - 01213440 _____ (Microsoft Corporation) C:\WINDOWS\system32\RemoteNaturalLanguage.dll
2015-10-01 05:13 - 2015-09-17 02:43 - 00378368 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemEventsBrokerServer.dll
2015-10-01 05:13 - 2015-09-17 02:42 - 02646528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
2015-10-01 05:13 - 2015-09-17 02:41 - 00217088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VEEventDispatcher.dll
2015-10-01 05:13 - 2015-09-17 02:40 - 01918464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
2015-10-01 05:13 - 2015-09-17 02:40 - 01162240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Speech.dll
2015-10-01 05:13 - 2015-09-17 02:39 - 00587264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll
2015-10-01 05:13 - 2015-09-17 02:38 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\usoapi.dll
2015-10-01 05:13 - 2015-09-17 02:37 - 00454656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MbaeApi.dll
2015-10-01 05:13 - 2015-09-17 02:35 - 02207232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2015-10-01 05:13 - 2015-09-17 02:35 - 01820160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Logon.dll
2015-10-01 05:13 - 2015-09-17 02:35 - 00828928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Bluetooth.dll
2015-10-01 05:13 - 2015-09-17 02:32 - 03579904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2015-10-01 05:13 - 2015-09-17 02:32 - 00336384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CredProvDataModel.dll
2015-10-01 05:13 - 2015-09-17 02:31 - 05454848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2015-10-01 05:13 - 2015-09-17 02:29 - 01104384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll
2015-10-01 05:13 - 2015-09-17 02:29 - 00677888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapControlCore.dll
2015-10-01 05:13 - 2015-09-17 02:26 - 00899584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RemoteNaturalLanguage.dll
2015-10-01 05:13 - 2015-09-17 02:16 - 00512000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll
2015-10-01 05:13 - 2015-09-12 23:05 - 02987520 _____ (Microsoft Corporation) C:\WINDOWS\system32\esent.dll
2015-10-01 05:13 - 2015-09-12 22:41 - 02639872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\esent.dll
2015-10-01 05:12 - 2015-09-24 21:35 - 00257024 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataAccountApis.dll
2015-10-01 05:12 - 2015-09-24 21:34 - 00223232 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneCallHistoryApis.dll
2015-10-01 05:12 - 2015-09-24 20:34 - 00195584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataAccountApis.dll
2015-10-01 05:12 - 2015-09-24 20:34 - 00172032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PhoneCallHistoryApis.dll
2015-10-01 05:12 - 2015-09-24 20:24 - 00796160 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll
2015-10-01 05:12 - 2015-09-24 20:24 - 00689152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll
2015-10-01 05:12 - 2015-09-24 20:23 - 00579072 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
2015-10-01 05:12 - 2015-09-24 20:07 - 01382400 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2015-10-01 05:12 - 2015-09-24 20:05 - 00288256 _____ (Microsoft Corporation) C:\WINDOWS\system32\PimIndexMaintenance.dll
2015-10-01 05:12 - 2015-09-24 20:01 - 00685568 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppointmentApis.dll
2015-10-01 05:12 - 2015-09-24 20:00 - 00752640 _____ (Microsoft Corporation) C:\WINDOWS\system32\ChatApis.dll
2015-10-01 05:12 - 2015-09-24 20:00 - 00720896 _____ (Microsoft Corporation) C:\WINDOWS\system32\EmailApis.dll
2015-10-01 05:12 - 2015-09-24 20:00 - 00163840 _____ (Microsoft Corporation) C:\WINDOWS\system32\CallHistoryClient.dll
2015-10-01 05:12 - 2015-09-24 19:53 - 00590336 _____ (Microsoft Corporation) C:\WINDOWS\system32\MessagingDataModel2.dll
2015-10-01 05:12 - 2015-09-24 19:43 - 00613376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll
2015-10-01 05:12 - 2015-09-24 19:43 - 00480256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Web.Core.dll
2015-10-01 05:12 - 2015-09-24 19:25 - 00579584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppointmentApis.dll
2015-10-01 05:12 - 2015-09-24 19:25 - 00557568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ChatApis.dll
2015-10-01 05:12 - 2015-09-24 19:25 - 00525312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EmailApis.dll
2015-10-01 05:12 - 2015-09-24 19:24 - 00131072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CallHistoryClient.dll
2015-10-01 05:12 - 2015-09-24 19:19 - 00466432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MessagingDataModel2.dll
2015-10-01 05:12 - 2015-09-19 02:14 - 00102304 _____ (Microsoft Corporation) C:\WINDOWS\system32\omadmapi.dll
2015-10-01 05:12 - 2015-09-17 03:50 - 00099664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pdc.sys
2015-10-01 05:12 - 2015-09-17 03:50 - 00088384 _____ (Microsoft Corporation) C:\WINDOWS\system32\remoteaudioendpoint.dll
2015-10-01 05:12 - 2015-09-17 03:49 - 00553808 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncHost.exe
2015-10-01 05:12 - 2015-09-17 03:49 - 00501008 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
2015-10-01 05:12 - 2015-09-17 03:48 - 00584656 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll
2015-10-01 05:12 - 2015-09-17 03:48 - 00516448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBHUB3.SYS
2015-10-01 05:12 - 2015-09-17 03:48 - 00505696 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2015-10-01 05:12 - 2015-09-17 03:48 - 00406864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\FWPKCLNT.SYS
2015-10-01 05:12 - 2015-09-17 03:48 - 00395088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2015-10-01 05:12 - 2015-09-17 03:48 - 00332624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fastfat.sys
2015-10-01 05:12 - 2015-09-17 03:48 - 00278352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys
2015-10-01 05:12 - 2015-09-17 03:48 - 00243760 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
2015-10-01 05:12 - 2015-09-17 03:39 - 00081488 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2015-10-01 05:12 - 2015-09-17 03:37 - 01168736 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys
2015-10-01 05:12 - 2015-09-17 03:28 - 00441168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncHost.exe
2015-10-01 05:12 - 2015-09-17 03:28 - 00407608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
2015-10-01 05:12 - 2015-09-17 03:28 - 00074880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\remoteaudioendpoint.dll
2015-10-01 05:12 - 2015-09-17 03:26 - 01895568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hevcdecoder.dll
2015-10-01 05:12 - 2015-09-17 03:26 - 00508248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf.dll
2015-10-01 05:12 - 2015-09-17 03:26 - 00434376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFCaptureEngine.dll
2015-10-01 05:12 - 2015-09-17 03:11 - 00160256 _____ (Microsoft Corporation) C:\WINDOWS\system32\enrollmentapi.dll
2015-10-01 05:12 - 2015-09-17 03:10 - 00169984 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmregistration.dll
2015-10-01 05:12 - 2015-09-17 03:09 - 00269312 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll
2015-10-01 05:12 - 2015-09-17 03:09 - 00143360 _____ (Microsoft Corporation) C:\WINDOWS\system32\provops.dll
2015-10-01 05:12 - 2015-09-17 03:08 - 00494592 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll
2015-10-01 05:12 - 2015-09-17 03:08 - 00053760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Speech.Pal.dll
2015-10-01 05:12 - 2015-09-17 03:08 - 00026624 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManagerShellext.exe
2015-10-01 05:12 - 2015-09-17 03:06 - 00690688 _____ (Microsoft Corporation) C:\WINDOWS\system32\CellularAPI.dll
2015-10-01 05:12 - 2015-09-17 03:06 - 00149504 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringservice.dll
2015-10-01 05:12 - 2015-09-17 03:05 - 00483328 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneDriveSettingSyncProvider.dll
2015-10-01 05:12 - 2015-09-17 03:04 - 00504320 _____ (Microsoft Corporation) C:\WINDOWS\system32\DataSenseHandlers.dll
2015-10-01 05:12 - 2015-09-17 03:03 - 00267776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Management.dll
2015-10-01 05:12 - 2015-09-17 03:03 - 00187904 _____ (Microsoft Corporation) C:\WINDOWS\system32\provisioningcsp.dll
2015-10-01 05:12 - 2015-09-17 03:03 - 00154624 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcertinst.exe
2015-10-01 05:12 - 2015-09-17 03:03 - 00088064 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngckeyenum.dll
2015-10-01 05:12 - 2015-09-17 03:03 - 00083968 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceEnroller.exe
2015-10-01 05:12 - 2015-09-17 03:02 - 00168960 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmmigrator.dll
2015-10-01 05:12 - 2015-09-17 03:02 - 00068096 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseDesktopAppMgmtCSP.dll
2015-10-01 05:12 - 2015-09-17 03:00 - 00446976 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapConfiguration.dll
2015-10-01 05:12 - 2015-09-17 03:00 - 00106496 _____ (Microsoft Corporation) C:\WINDOWS\system32\KeywordDetectorMsftSidAdapter.dll
2015-10-01 05:12 - 2015-09-17 02:57 - 00403456 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenrollengine.dll
2015-10-01 05:12 - 2015-09-17 02:57 - 00137728 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEStoreEventHandlers.dll
2015-10-01 05:12 - 2015-09-17 02:56 - 00521728 _____ (Microsoft Corporation) C:\WINDOWS\system32\PsmServiceExtHost.dll
2015-10-01 05:12 - 2015-09-17 02:56 - 00317440 _____ (Microsoft Corporation) C:\WINDOWS\system32\configmanager2.dll
2015-10-01 05:12 - 2015-09-17 02:55 - 00671232 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUDFx02000.dll
2015-10-01 05:12 - 2015-09-17 02:55 - 00366592 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll
2015-10-01 05:12 - 2015-09-17 02:55 - 00346112 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngccredprov.dll
2015-10-01 05:12 - 2015-09-17 02:55 - 00202240 _____ (Microsoft Corporation) C:\WINDOWS\system32\accountaccessor.dll
2015-10-01 05:12 - 2015-09-17 02:55 - 00121856 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcsps.dll
2015-10-01 05:12 - 2015-09-17 02:55 - 00120832 _____ (Microsoft Corporation) C:\WINDOWS\system32\omadmclient.exe
2015-10-01 05:12 - 2015-09-17 02:55 - 00073728 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwancfg.dll
2015-10-01 05:12 - 2015-09-17 02:54 - 00324096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2015-10-01 05:12 - 2015-09-17 02:52 - 06572032 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanmm.dll
2015-10-01 05:12 - 2015-09-17 02:52 - 01216512 _____ (Microsoft Corporation) C:\WINDOWS\system32\netcenter.dll
2015-10-01 05:12 - 2015-09-17 02:52 - 00856576 _____ (Microsoft Corporation) C:\WINDOWS\system32\MPSSVC.dll
2015-10-01 05:12 - 2015-09-17 02:52 - 00465920 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanconn.dll
2015-10-01 05:12 - 2015-09-17 02:52 - 00371712 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlasvc.dll
2015-10-01 05:12 - 2015-09-17 02:52 - 00204800 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmcsp.dll
2015-10-01 05:12 - 2015-09-17 02:52 - 00162304 _____ (Microsoft Corporation) C:\WINDOWS\system32\SubscriptionMgr.dll
2015-10-01 05:12 - 2015-09-17 02:51 - 01812480 _____ (Microsoft Corporation) C:\WINDOWS\system32\pnidui.dll
2015-10-01 05:12 - 2015-09-17 02:51 - 00359936 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncsi.dll
2015-10-01 05:12 - 2015-09-17 02:51 - 00145920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mdmregistration.dll
2015-10-01 05:12 - 2015-09-17 02:50 - 00421888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Bluetooth.dll
2015-10-01 05:12 - 2015-09-17 02:50 - 00320000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\portcls.sys
2015-10-01 05:12 - 2015-09-17 02:50 - 00312832 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsApi.dll
2015-10-01 05:12 - 2015-09-17 02:50 - 00221184 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationPeWiFi.dll
2015-10-01 05:12 - 2015-09-17 02:50 - 00204288 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationPeCell.dll
2015-10-01 05:12 - 2015-09-17 02:50 - 00036352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\buttonconverter.sys
2015-10-01 05:12 - 2015-09-17 02:49 - 00771072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2015-10-01 05:12 - 2015-09-17 02:49 - 00439296 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationWebproxy.dll
2015-10-01 05:12 - 2015-09-17 02:49 - 00342016 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationGeofences.dll
2015-10-01 05:12 - 2015-09-17 02:49 - 00268800 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationFramework.dll
2015-10-01 05:12 - 2015-09-17 02:49 - 00215552 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationCrowdsource.dll
2015-10-01 05:12 - 2015-09-17 02:49 - 00176640 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationPeIP.dll
2015-10-01 05:12 - 2015-09-17 02:49 - 00095744 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationWiFiAdapter.dll
2015-10-01 05:12 - 2015-09-17 02:49 - 00041472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Speech.Pal.dll
2015-10-01 05:12 - 2015-09-17 02:48 - 00347136 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncryptprov.dll
2015-10-01 05:12 - 2015-09-17 02:48 - 00273920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.LockScreen.dll
2015-10-01 05:12 - 2015-09-17 02:47 - 00371712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OneDriveSettingSyncProvider.dll
2015-10-01 05:12 - 2015-09-17 02:47 - 00186880 _____ (Microsoft Corporation) C:\WINDOWS\system32\cloudAP.dll
2015-10-01 05:12 - 2015-09-17 02:46 - 00928256 _____ (Microsoft Corporation) C:\WINDOWS\system32\JpMapControl.dll
2015-10-01 05:12 - 2015-09-17 02:46 - 00621056 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
2015-10-01 05:12 - 2015-09-17 02:46 - 00414208 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll
2015-10-01 05:12 - 2015-09-17 02:46 - 00224256 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCore.dll
2015-10-01 05:12 - 2015-09-17 02:46 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCsp.dll
2015-10-01 05:12 - 2015-09-17 02:46 - 00084480 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDMAppInstaller.exe
2015-10-01 05:12 - 2015-09-17 02:46 - 00079872 _____ (Microsoft Corporation) C:\WINDOWS\system32\HttpsDataSource.dll
2015-10-01 05:12 - 2015-09-17 02:46 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\syncmlhook.dll
2015-10-01 05:12 - 2015-09-17 02:45 - 00832512 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll
2015-10-01 05:12 - 2015-09-17 02:45 - 00193024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Management.dll
2015-10-01 05:12 - 2015-09-17 02:44 - 01844736 _____ (Microsoft Corporation) C:\WINDOWS\system32\workfolderssvc.dll
2015-10-01 05:12 - 2015-09-17 02:44 - 00599552 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnapps.dll
2015-10-01 05:12 - 2015-09-17 02:44 - 00274944 _____ (Microsoft Corporation) C:\WINDOWS\system32\syncutil.dll
2015-10-01 05:12 - 2015-09-17 02:43 - 00328704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapConfiguration.dll
2015-10-01 05:12 - 2015-09-17 02:43 - 00185344 _____ (Microsoft Corporation) C:\WINDOWS\system32\psmsrv.dll
2015-10-01 05:12 - 2015-09-17 02:39 - 00247808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2015-10-01 05:12 - 2015-09-17 02:36 - 01171456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netcenter.dll
2015-10-01 05:12 - 2015-09-17 02:34 - 00253440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsApi.dll
2015-10-01 05:12 - 2015-09-17 02:33 - 00574464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll
2015-10-01 05:12 - 2015-09-17 02:32 - 00313856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LockAppBroker.dll
2015-10-01 05:12 - 2015-09-17 02:32 - 00195072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.LockScreen.dll
2015-10-01 05:12 - 2015-09-17 02:31 - 00268800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ncryptprov.dll
2015-10-01 05:12 - 2015-09-17 02:30 - 00311808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll
2015-10-01 05:12 - 2015-09-17 02:29 - 00701952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\JpMapControl.dll
2015-10-01 05:12 - 2015-09-17 02:29 - 00464896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.dll
2015-10-01 05:12 - 2015-09-17 02:28 - 00473088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wpnapps.dll
2015-09-30 18:39 - 2015-09-30 18:39 - 00000683 _____ C:\Users\Anora\Downloads\transcript.txt
2015-09-30 18:03 - 2015-09-30 18:05 - 00001266 _____ C:\Users\Anora\Desktop\receapt.txt
2015-09-30 17:02 - 2015-09-30 17:06 - 00001271 _____ C:\Users\Anora\Desktop\Redme first.txt
2015-09-30 16:13 - 2015-10-02 18:22 - 00000000 ____D C:\server
2015-09-30 15:41 - 2015-10-02 19:35 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2015-09-29 22:54 - 2015-09-29 22:54 - 00000020 ___SH C:\Users\wildrenter\ntuser.ini
2015-09-29 22:54 - 2015-09-29 22:54 - 00000000 ____D C:\Users\wildrenter
2015-09-29 22:54 - 2015-08-20 09:27 - 00000000 ___RD C:\Users\wildrenter\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-09-29 22:54 - 2015-07-10 08:04 - 00000000 __RSD C:\Users\wildrenter\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell
2015-09-29 22:54 - 2015-07-10 08:04 - 00000000 ___RD C:\Users\wildrenter\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-09-29 22:54 - 2015-07-10 08:04 - 00000000 ___RD C:\Users\wildrenter\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2015-09-29 22:54 - 2015-07-10 08:04 - 00000000 ____D C:\Users\wildrenter\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-09-29 22:51 - 2015-09-29 22:51 - 04260481 _____ C:\Users\Anora\Downloads\Dynmap-2.2-forge-1.7.10.jar
2015-09-29 22:51 - 2015-09-29 22:51 - 04109948 _____ C:\Users\Anora\Downloads\Dynmap-2.2-forge-1.8.0.jar
2015-09-29 20:43 - 2015-09-29 20:43 - 00236479 _____ C:\Users\Anora\Downloads\additionalpipes-4.6.1.jar
2015-09-29 18:05 - 2015-09-30 16:51 - 00000000 ____D C:\Users\Anora\AppData\Roaming\OBS
2015-09-29 18:05 - 2015-09-29 18:51 - 00001004 _____ C:\Users\Anora\Desktop\Open Broadcaster Software.lnk
2015-09-29 18:05 - 2015-09-29 18:05 - 00000000 ____D C:\Users\Anora\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Open Broadcaster Software
2015-09-29 18:05 - 2015-09-29 18:05 - 00000000 ____D C:\Program Files\OBS
2015-09-29 18:05 - 2015-09-29 18:05 - 00000000 ____D C:\Program Files (x86)\OBS
2015-09-29 18:04 - 2015-09-29 18:05 - 07420880 _____ C:\Users\Anora\Downloads\OBS_0_655b_Installer.exe
2015-09-28 21:27 - 2015-09-28 21:28 - 00158100 _____ C:\Users\Anora\Downloads\ironchest-1.7.10-6.0.60.741-universal.jar
2015-09-28 21:24 - 2015-09-28 21:24 - 00145782 _____ C:\Users\Anora\Downloads\CodeChickenCore-1.7.10-1.0.7.47-universal.jar
2015-09-28 21:24 - 2015-09-28 21:24 - 00106701 _____ C:\Users\Anora\Downloads\ChickenChunks-1.7.10-1.3.4.19-universal.jar
2015-09-28 21:23 - 2015-09-28 21:23 - 00145063 _____ C:\Users\Anora\Downloads\EnderStorage-1.7.10-1.4.7.37-universal.jar
2015-09-28 21:22 - 2015-09-28 21:22 - 00160161 _____ C:\Users\Anora\Downloads\Translocator-1.7.10-1.1.2.15-universal.jar
2015-09-28 21:20 - 2015-09-28 21:20 - 00513018 _____ C:\Users\Anora\Downloads\NotEnoughItems-1.7.10-1.0.5.118-universal.jar
2015-09-28 21:18 - 2015-09-28 21:19 - 00164873 _____ C:\Users\Anora\Downloads\ironchest-1.8-6.0.99.749-universal.jar
2015-09-28 21:17 - 2015-09-28 21:17 - 00440712 _____ C:\Users\Anora\Downloads\Jabba-1.2.1a_1.7.10.jar
2015-09-28 21:15 - 2015-09-28 21:15 - 00544821 _____ C:\Users\Anora\Downloads\Waila-1.5.10_1.7.10.jar
2015-09-28 19:57 - 2015-09-28 19:57 - 00000215 _____ C:\Users\Anora\Desktop\Problem loading page.URL
2015-09-28 08:09 - 2015-09-28 08:09 - 00000000 _____ C:\WINDOWS\setupact.log
2015-09-27 19:44 - 2015-09-27 19:44 - 00011262 _____ C:\Users\Anora\Documents\hijackthis.log
2015-09-27 19:38 - 2015-09-27 19:38 - 00388608 _____ (Trend Micro Inc.) C:\Users\Anora\Downloads\HijackThis.exe
2015-09-27 19:18 - 2015-09-27 19:18 - 07424696 _____ C:\Users\Anora\Downloads\spybotsd_includes(1).exe
2015-09-27 17:48 - 2015-09-27 17:49 - 07424696 _____ C:\Users\Anora\Downloads\spybotsd_includes.exe
2015-09-25 17:26 - 2009-06-10 18:00 - 00000824 _____ C:\WINDOWS\system32\Drivers\etc\hosts.20150925-172615.backup
2015-09-25 17:16 - 2015-10-05 10:33 - 00113880 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-09-25 17:15 - 2015-09-27 20:23 - 00001171 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-09-25 17:15 - 2015-09-27 20:23 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-09-25 17:15 - 2015-09-27 20:23 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-09-25 17:15 - 2015-09-25 17:15 - 00000000 ____D C:\ProgramData\Malwarebytes
2015-09-25 17:15 - 2015-06-18 09:48 - 00064216 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
2015-09-25 17:15 - 2015-06-18 09:47 - 00109272 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2015-09-25 17:15 - 2015-06-18 09:47 - 00025816 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2015-09-25 17:14 - 2015-09-27 19:00 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2015-09-25 17:14 - 2015-09-25 17:45 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
2015-09-25 17:14 - 2015-09-25 17:14 - 00001460 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk
2015-09-25 17:14 - 2015-09-25 17:14 - 00001448 _____ C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
2015-09-25 17:14 - 2015-09-25 17:14 - 00000000 ____D C:\WINDOWS\System32\Tasks\Safer-Networking
2015-09-25 17:14 - 2015-09-25 17:14 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
2015-09-25 17:14 - 2013-09-20 10:49 - 00021040 _____ (Safer Networking Limited) C:\WINDOWS\system32\sdnclean64.exe
2015-09-25 17:12 - 2015-09-25 17:15 - 21545336 _____ (Malwarebytes Corporation ) C:\Users\Anora\Downloads\mbam-setup-sem-2.1.6.1022.exe
2015-09-25 17:12 - 2015-09-25 17:13 - 46525608 _____ (Safer-Networking Ltd. ) C:\Users\Anora\Downloads\spybot-2.4.exe
2015-09-25 17:12 - 2015-09-25 17:12 - 21545336 _____ (Malwarebytes Corporation ) C:\Users\Anora\Downloads\mbam-setup-sem-2.1.6.1022(1).exe
2015-09-25 17:10 - 2015-09-25 17:10 - 00000000 ____D C:\Users\Anora\AppData\Roaming\AVAST Software
2015-09-25 17:07 - 2015-09-25 17:07 - 00001927 _____ C:\Users\Public\Desktop\Avast Free Antivirus.lnk
2015-09-25 17:07 - 2015-09-25 17:07 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
2015-09-25 17:06 - 2015-09-28 08:08 - 00004280 _____ C:\WINDOWS\System32\Tasks\avast! Emergency Update
2015-09-25 17:06 - 2015-09-25 17:06 - 00448968 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSP.sys
2015-09-25 17:06 - 2015-09-25 17:06 - 00378880 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe
2015-09-25 17:06 - 2015-09-25 17:06 - 00274808 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswVmm.sys
2015-09-25 17:06 - 2015-09-25 17:06 - 00153744 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswStm.sys
2015-09-25 17:06 - 2015-09-25 17:06 - 00093528 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr2.sys
2015-09-25 17:06 - 2015-09-25 17:06 - 00090968 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys
2015-09-25 17:06 - 2015-09-25 17:06 - 00065224 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRvrt.sys
2015-09-25 17:06 - 2015-09-25 17:06 - 00043112 _____ (AVAST Software) C:\WINDOWS\avastSS.scr
2015-09-25 17:06 - 2015-09-25 17:06 - 00028656 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswHwid.sys
2015-09-25 17:06 - 2015-09-25 17:05 - 01049880 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSnx.sys
2015-09-25 17:05 - 2015-09-25 17:05 - 00000000 ____D C:\Program Files\AVAST Software
2015-09-25 17:02 - 2015-09-25 17:02 - 00000000 ____D C:\ProgramData\AVAST Software
2015-09-25 17:01 - 2015-09-25 17:02 - 05500000 _____ (Avast Software s.r.o.) C:\Users\Anora\Downloads\avast_free_antivirus_setup_online.exe
2015-09-25 16:14 - 2015-09-25 16:18 - 00116959 _____ C:\Users\Anora\Downloads\fastcraft-1.21.jar
2015-09-25 15:55 - 2015-09-25 15:55 - 00000925 _____ C:\Users\Anora\Desktop\MultiMC.lnk
2015-09-25 09:43 - 2015-10-02 19:11 - 00000000 ____D C:\WINDOWS\system32\appmgmt
2015-09-22 07:51 - 2015-09-22 07:51 - 18819272 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerInstaller.exe
2015-09-20 14:40 - 2015-09-20 14:40 - 00891845 _____ C:\Users\Anora\Downloads\natura-1.7.10-2.2.0.1.jar
2015-09-20 13:25 - 2015-09-20 13:25 - 00182350 _____ C:\Users\Anora\Downloads\Reis-Minimap-Mod-1.7.10.jar
2015-09-20 13:22 - 2015-09-20 13:22 - 00094792 _____ C:\Users\Anora\Downloads\[1.7.10]Treecapitator-universal-2.0.4.jar
2015-09-20 13:21 - 2015-09-20 13:21 - 00099264 _____ C:\Users\Anora\Downloads\[1.8]Treecapitator-universal-2.0.5.jar
2015-09-20 13:20 - 2015-09-20 13:20 - 00198525 _____ C:\Users\Anora\Downloads\[1.7.10]bspkrsCore-universal-6.16.jar
2015-09-20 13:20 - 2015-09-20 13:20 - 00063133 _____ C:\Users\Anora\Downloads\[1.8]bspkrsCore-universal-7.01.jar
2015-09-20 12:37 - 2015-09-20 12:37 - 00150110 _____ C:\Users\Anora\Downloads\fpsplus.zip
2015-09-20 12:36 - 2015-09-20 12:36 - 00868722 _____ C:\Users\Anora\Downloads\OptiFine_1.7.10_HD_C1.jar
2015-09-20 12:23 - 2015-09-20 12:23 - 02180152 _____ C:\Users\Anora\Downloads\ThermalFoundation-[1.7.10]1.2.0-102(1).jar
2015-09-20 12:21 - 2015-09-20 12:21 - 00158708 _____ C:\Users\Anora\Downloads\iChunUtil-4.0.0.jar
2015-09-20 12:20 - 2015-09-20 12:20 - 00390664 _____ C:\Users\Anora\Downloads\iChunUtil-5.4.0.jar
2015-09-20 12:18 - 2015-09-20 12:18 - 00049712 _____ C:\Users\Anora\Downloads\MetallurgyCore-1.7.10-4.0.4.18.jar
2015-09-20 12:15 - 2015-09-20 12:15 - 01482797 _____ C:\Users\Anora\Downloads\bdlib-1.9.2.104-mc1.7.10.jar
2015-09-20 12:03 - 2015-09-20 12:03 - 00501229 _____ C:\Users\Anora\Downloads\ae2stuff-0.5.0.56-mc1.7.10.jar
2015-09-20 12:01 - 2015-09-20 12:01 - 01719328 _____ C:\Users\Anora\Downloads\MineFactoryReloaded-[1.7.10]2.8.0-104(1).jar
2015-09-20 12:01 - 2015-09-20 12:01 - 01228305 _____ C:\Users\Anora\Downloads\thaumicenergistics-0.8.10.10.jar
2015-09-20 11:59 - 2015-09-20 11:59 - 01020024 _____ C:\Users\Anora\Downloads\OpenPeripheral-1.7.10-AIO-5.jar
2015-09-20 11:59 - 2015-09-20 11:59 - 00862338 _____ C:\Users\Anora\Downloads\OpenModsLib-1.7.10-0.8.jar
2015-09-20 11:56 - 2015-09-20 11:56 - 01397898 _____ C:\Users\Anora\Downloads\ComputerCraft1.74.jar
2015-09-20 11:54 - 2015-09-20 11:54 - 05725609 _____ C:\Users\Anora\Downloads\BiomesOPlenty-1.7.10-2.1.0.1396-universal.jar
2015-09-20 11:53 - 2015-09-20 11:53 - 00351928 _____ C:\Users\Anora\Downloads\EnderZoo-1.7.10-1.0.15.32.jar
2015-09-20 11:52 - 2015-09-20 11:52 - 00221921 _____ C:\Users\Anora\Downloads\InventoryTweaks-1.58-147.jar
2015-09-20 11:51 - 2015-09-20 11:51 - 00225817 _____ C:\Users\Anora\Downloads\InventoryTweaks-1.59-176.jar
2015-09-20 11:49 - 2015-09-20 11:49 - 04066035 _____ C:\Users\Anora\Downloads\EnderIO-1.7.10-2.2.8.381.jar
2015-09-20 11:48 - 2015-09-20 11:48 - 00265023 _____ C:\Users\Anora\Downloads\ABO-MC1.7.10-BC7-release3.0.2.jar
2015-09-20 11:47 - 2015-09-20 11:47 - 03190760 _____ C:\Users\Anora\Downloads\logisticspipes-0.9.2.48.jar
2015-09-20 11:41 - 2015-09-20 11:42 - 02141043 _____ C:\Users\Anora\Downloads\ThaumicTinkerer-2.5-1.7.10-164.jar
2015-09-20 11:40 - 2015-09-20 11:40 - 12565807 _____ C:\Users\Anora\Downloads\Thaumcraft-1.7.10-4.2.3.5.jar
2015-09-20 11:37 - 2015-09-20 11:37 - 01039858 _____ C:\Users\Anora\Downloads\Morph-Beta-0.9.2.jar
2015-09-20 11:34 - 2015-09-20 11:34 - 02207842 _____ C:\Users\Anora\Downloads\mystcraft-1.7.10-0.12.3.00.jar
2015-09-20 11:31 - 2015-09-20 11:31 - 02110837 _____ C:\Users\Anora\Downloads\extrautilities-1.2.11.jar
2015-09-20 11:29 - 2015-09-20 11:29 - 11151826 _____ C:\Users\Anora\Downloads\ExtraTiC-1.7.10-1.4.5.jar
2015-09-20 11:28 - 2015-09-20 11:28 - 05529579 _____ C:\Users\Anora\Downloads\TConstruct-1.7.10-1.8.7.jar
2015-09-20 11:28 - 2015-09-20 11:28 - 00200413 _____ C:\Users\Anora\Downloads\Mantle-1.7.10-0.3.2a.jar
2015-09-20 11:25 - 2015-09-20 11:26 - 01529588 _____ C:\Users\Anora\Downloads\Metallurgy-1.7.10-4.0.6.80.jar
2015-09-20 11:24 - 2015-09-20 11:25 - 00462208 _____ C:\Users\Anora\Downloads\ThermalDynamics-[1.7.10]1.1.0-161.jar
2015-09-20 11:24 - 2015-09-20 11:25 - 00079555 _____ C:\Users\Anora\Downloads\NetherOres-[1.7.10]2.3.0-12.jar
2015-09-20 11:24 - 2015-09-20 11:24 - 02384406 _____ C:\Users\Anora\Downloads\ThermalExpansion-[1.7.10]4.0.3B1-218.jar
2015-09-20 11:24 - 2015-09-20 11:24 - 01719328 _____ C:\Users\Anora\Downloads\MineFactoryReloaded-[1.7.10]2.8.0-104.jar
2015-09-20 11:23 - 2015-09-20 11:24 - 02180152 _____ C:\Users\Anora\Downloads\ThermalFoundation-[1.7.10]1.2.0-102.jar
2015-09-20 11:23 - 2015-09-20 11:23 - 01068485 _____ C:\Users\Anora\Downloads\CoFHCore-[1.7.10]3.0.3-303.jar
2015-09-20 11:16 - 2015-09-20 11:16 - 00352856 _____ C:\Users\Anora\Downloads\WR-CBE-1.7.10-1.4.1.9-universal.jar
2015-09-20 11:15 - 2015-09-20 11:16 - 03682125 _____ C:\Users\Anora\Downloads\twilightforest-1.7.10-2.3.7.jar
2015-09-20 11:15 - 2015-09-20 11:15 - 00507333 _____ C:\Users\Anora\Downloads\NotEnoughItems-1.7.10-1.0.3.74-universal.jar
2015-09-20 11:15 - 2015-09-20 11:15 - 00160155 _____ C:\Users\Anora\Downloads\Translocator-1.7.10-1.1.1.14-universal.jar
2015-09-20 11:14 - 2015-09-20 11:14 - 00157678 _____ C:\Users\Anora\Downloads\CodeChickenCore-1.7.10-1.0.4.29-universal.jar
2015-09-20 11:14 - 2015-09-20 11:14 - 00143274 _____ C:\Users\Anora\Downloads\EnderStorage-1.7.10-1.4.5.27-universal.jar
2015-09-20 11:14 - 2015-09-20 11:14 - 00105665 _____ C:\Users\Anora\Downloads\ChickenChunks-1.7.10-1.3.4.16-universal.jar
2015-09-20 11:13 - 2015-09-20 11:13 - 00510432 _____ C:\Users\Anora\Downloads\NotEnoughItems-1.8-1.0.5.82-universal.jar
2015-09-20 11:13 - 2015-09-20 11:13 - 00433012 _____ C:\Users\Anora\Downloads\CodeChickenCore-1.8-1.0.5.34-universal.jar
2015-09-20 11:11 - 2015-09-20 11:11 - 00386789 _____ C:\Users\Anora\Downloads\ForgeRelocation-0.0.1.4-universal.jar
2015-09-20 11:11 - 2015-09-20 11:11 - 00025361 _____ C:\Users\Anora\Downloads\ForgeRelocationFMP-0.0.1.2-universal.jar
2015-09-20 11:10 - 2015-09-20 11:10 - 00632050 _____ C:\Users\Anora\Downloads\ProjectRed-1.7.10-4.7.0pre9.92-Lighting.jar
2015-09-20 11:10 - 2015-09-20 11:10 - 00472590 _____ C:\Users\Anora\Downloads\ProjectRed-1.7.10-4.7.0pre9.92-World.jar
2015-09-20 11:10 - 2015-09-20 11:10 - 00083858 _____ C:\Users\Anora\Downloads\ProjectRed-1.7.10-4.7.0pre9.92-Compat.jar
2015-09-20 11:09 - 2015-09-20 11:10 - 02088848 _____ C:\Users\Anora\Downloads\ProjectRed-1.7.10-4.7.0pre9.92-Mechanical.jar
2015-09-20 11:09 - 2015-09-20 11:09 - 03912822 _____ C:\Users\Anora\Downloads\ProjectRed-1.7.10-4.7.0pre9.92-Integration.jar
2015-09-20 11:09 - 2015-09-20 11:09 - 01654363 _____ C:\Users\Anora\Downloads\ProjectRed-1.7.10-4.7.0pre9.92-Fabrication.jar
2015-09-20 11:08 - 2015-09-20 11:08 - 01420057 _____ C:\Users\Anora\Downloads\ProjectRed-1.7.10-4.7.0pre9.92-Base.jar
2015-09-20 11:07 - 2015-09-20 11:07 - 00750651 _____ C:\Users\Anora\Downloads\MrTJPCore-1.1.0.31-universal.jar
2015-09-20 11:05 - 2015-09-20 11:05 - 02526302 _____ C:\Users\Anora\Downloads\appliedenergistics2-rv2-stable-10.jar
2015-09-20 11:05 - 2015-09-20 11:05 - 00694287 _____ C:\Users\Anora\Downloads\StevesFactoryManagerA93.jar
2015-09-20 11:01 - 2015-09-20 11:01 - 03165700 _____ C:\Users\Anora\Downloads\forestry_1.7.10-3.6.6.24.jar
2015-09-20 11:00 - 2015-09-20 11:00 - 03679674 _____ C:\Users\Anora\Downloads\Railcraft_1.7.10-9.7.0.0.jar
2015-09-20 10:59 - 2015-09-20 10:59 - 00218789 _____ C:\Users\Anora\Downloads\buildcraft-compat-7.0.12.jar
2015-09-20 10:58 - 2015-09-20 10:59 - 02487585 _____ C:\Users\Anora\Downloads\buildcraft-7.0.23.jar
2015-09-19 20:57 - 2012-01-23 13:02 - 00008810 _____ C:\Users\Anora\Desktop\relnotes.txt
2015-09-19 20:31 - 2015-09-19 20:31 - 00004324 _____ C:\Users\Anora\Downloads\PMAR-8PAG5T_R0_EN.zip
2015-09-19 20:29 - 2015-09-19 20:29 - 00000276 _____ C:\Users\Anora\Documents\PowerChute Technical Data.txt
2015-09-19 20:18 - 2015-09-19 20:18 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\APC
2015-09-19 20:18 - 2015-09-19 20:18 - 00000000 ____D C:\Program Files (x86)\APC
2015-09-19 20:17 - 2015-09-19 20:17 - 15922552 _____ (Schneider Electric) C:\Users\Anora\Downloads\PCPEInstaller.exe
2015-09-19 20:17 - 2015-09-19 20:17 - 13923704 _____ (Schneider Electric) C:\Users\Anora\PCPE Setup.exe
2015-09-19 20:17 - 2015-09-19 20:17 - 13338112 _____ C:\Users\Anora\PCPE_3.0.1.msi
2015-09-19 20:17 - 2015-09-19 20:17 - 01079808 _____ (Microsoft Corporation) C:\Users\Anora\mfc80u.dll
2015-09-19 20:17 - 2015-09-19 20:17 - 00626688 _____ (Microsoft Corporation) C:\Users\Anora\msvcr80.dll
2015-09-19 20:17 - 2015-09-19 20:17 - 00021880 _____ (Schneider Electric) C:\Users\Anora\grm_res.dll
2015-09-19 20:17 - 2015-09-19 20:17 - 00021880 _____ (Schneider Electric) C:\Users\Anora\fr_res.dll
2015-09-19 20:17 - 2015-09-19 20:17 - 00021368 _____ (Schneider Electric) C:\Users\Anora\pt_res.dll
2015-09-19 20:17 - 2015-09-19 20:17 - 00021368 _____ (Schneider Electric) C:\Users\Anora\it_res.dll
2015-09-19 20:17 - 2015-09-19 20:17 - 00021368 _____ (Schneider Electric) C:\Users\Anora\es_res.dll
2015-09-19 20:17 - 2015-09-19 20:17 - 00021368 _____ (Schneider Electric) C:\Users\Anora\en_res.dll
2015-09-19 20:17 - 2015-09-19 20:17 - 00020856 _____ (Schneider Electric) C:\Users\Anora\ru_res.dll
2015-09-19 20:17 - 2015-09-19 20:17 - 00020344 _____ (Schneider Electric) C:\Users\Anora\jp_res.dll
2015-09-19 20:17 - 2015-09-19 20:17 - 00019832 _____ (Schneider Electric) C:\Users\Anora\zh_res.dll
2015-09-19 20:17 - 2015-09-19 20:17 - 00018808 _____ C:\Users\Anora\ResourceReader.dll
2015-09-19 20:17 - 2015-09-19 20:17 - 00000550 _____ C:\Users\Anora\Microsoft.VC80.MFC.manifest
2015-09-19 20:17 - 2015-09-19 20:17 - 00000522 _____ C:\Users\Anora\Microsoft.VC80.CRT.manifest
2015-09-19 20:17 - 2015-09-19 20:17 - 00000024 _____ C:\Users\Anora\dotnetfolder.txt
2015-09-19 16:59 - 2015-09-19 17:01 - 114675363 _____ C:\Users\Anora\Downloads\Borderlands.zip
2015-09-18 20:08 - 2015-09-18 20:08 - 00000000 ____D C:\ProgramData\ATI
2015-09-18 15:56 - 2015-09-18 15:56 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
2015-09-18 15:49 - 2015-09-18 15:57 - 00000000 ____D C:\Users\Anora\AppData\Roaming\Apple Computer
2015-09-18 15:49 - 2015-09-18 15:49 - 00001782 _____ C:\Users\Public\Desktop\iTunes.lnk
2015-09-18 15:49 - 2015-09-18 15:49 - 00000000 ____D C:\Users\Anora\AppData\Local\Apple Computer
2015-09-18 15:49 - 2015-09-18 15:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2015-09-18 15:47 - 2015-09-18 15:49 - 00000000 ____D C:\Program Files\iTunes
2015-09-18 15:47 - 2015-09-18 15:47 - 00000000 ____D C:\ProgramData\Apple Computer
2015-09-18 15:47 - 2015-09-18 15:47 - 00000000 ____D C:\Program Files\iPod
2015-09-18 15:47 - 2015-09-18 15:47 - 00000000 ____D C:\Program Files (x86)\iTunes
2015-09-18 15:46 - 2015-09-18 15:46 - 00002535 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
2015-09-18 15:46 - 2015-09-18 15:46 - 00000000 ____D C:\WINDOWS\System32\Tasks\Apple
2015-09-18 15:46 - 2015-09-18 15:46 - 00000000 ____D C:\Users\Anora\AppData\Local\Apple
2015-09-18 15:46 - 2015-09-18 15:46 - 00000000 ____D C:\Program Files (x86)\Apple Software Update
2015-09-18 15:45 - 2015-09-18 15:46 - 00000000 ____D C:\ProgramData\Apple
2015-09-18 15:45 - 2015-09-18 15:46 - 00000000 ____D C:\Program Files\Common Files\Apple
2015-09-18 15:45 - 2015-09-18 15:45 - 00000000 ____D C:\Program Files\Bonjour
2015-09-18 15:45 - 2015-09-18 15:45 - 00000000 ____D C:\Program Files (x86)\Bonjour
2015-09-18 15:41 - 2015-09-18 15:44 - 167601944 _____ (Apple Inc.) C:\Users\Anora\Downloads\iTunes6464Setup.exe
2015-09-15 23:24 - 2015-09-18 19:49 - 00000000 ____D C:\pq
2015-09-15 23:19 - 2015-09-15 23:24 - 00320319 _____ C:\Users\Anora\Downloads\pq6-2.zip
2015-09-15 16:39 - 2015-09-15 16:39 - 01031608 _____ (CyberLink) C:\Users\Anora\Downloads\CyberLink_PowerDVD_Downloader.exe
2015-09-15 16:13 - 2015-09-15 16:13 - 00000506 _____ C:\Users\Anora\Downloads\new 1.txt
2015-09-14 23:02 - 2015-09-14 23:02 - 00469807 _____ C:\Users\Anora\Downloads\Super Smash Brothers_ Disharmony.txt
2015-09-14 22:56 - 2015-09-14 23:00 - 42827912 _____ ( ) C:\Users\Anora\Downloads\BD_3DAdvisor_7510_Generic_BD_CDT140213-01.exe
2015-09-14 21:26 - 2015-09-25 09:32 - 00000000 ____D C:\Users\Anora\AppData\Roaming\Raptr
2015-09-14 21:26 - 2015-09-25 09:32 - 00000000 ____D C:\Program Files (x86)\Raptr
2015-09-14 21:26 - 2015-09-14 21:26 - 00058661 _____ C:\WINDOWS\SysWOW64\CCCInstall_201509142126330631.log
2015-09-14 21:26 - 2015-09-14 21:26 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center
2015-09-14 21:17 - 2015-09-14 21:17 - 00061037 _____ C:\WINDOWS\SysWOW64\CCCInstall_201509142117299777.log
2015-09-14 21:08 - 2015-09-14 21:12 - 313171288 _____ (AMD Inc.) C:\Users\Anora\Downloads\amd-catalyst-15.8beta-64bit-win10-win8.1-win7-aug23.exe
2015-09-14 20:55 - 2015-09-14 20:55 - 00000000 ____D C:\Users\Anora\Documents\BioWare
2015-09-14 07:45 - 2015-09-14 07:45 - 00669184 _____ C:\WINDOWS\SysWOW64\pbsvc.exe
2015-09-14 07:45 - 2015-09-14 07:45 - 00103736 _____ C:\WINDOWS\SysWOW64\PnkBstrB.exe
2015-09-14 07:45 - 2015-09-14 07:45 - 00066872 _____ C:\WINDOWS\SysWOW64\PnkBstrA.exe
2015-09-13 23:03 - 2015-09-13 23:04 - 00000000 ____D C:\Users\Anora\Documents\My Spore Creations
2015-09-13 23:03 - 2015-09-13 23:04 - 00000000 ____D C:\Users\Anora\AppData\Roaming\SPORE
2015-09-13 23:01 - 2015-09-13 23:01 - 00000000 __RHD C:\Users\Anora\AppData\Roaming\SecuROM
2015-09-13 22:15 - 2015-09-13 22:15 - 00000000 ____D C:\Users\Anora\Documents\Respawn
2015-09-13 21:14 - 2015-10-03 08:51 - 00000000 ____D C:\ProgramData\Origin
2015-09-13 21:14 - 2015-09-13 21:14 - 00000749 _____ C:\Users\Public\Desktop\Origin.lnk
2015-09-13 21:13 - 2015-09-13 21:13 - 17113896 _____ (Electronic Arts, Inc.) C:\Users\Anora\Downloads\OriginThinSetup.exe
2015-09-13 21:10 - 2015-09-13 21:10 - 295536398 _____ C:\Users\Anora\Documents\backup.reg
2015-09-13 19:35 - 2015-09-13 21:14 - 00000000 ____D C:\ProgramData\Electronic Arts
2015-09-13 19:35 - 2015-09-13 19:35 - 00000000 ____D C:\Users\Anora\Documents\SimCity
2015-09-13 19:11 - 2015-09-13 22:15 - 00000000 ____D C:\Users\Anora\AppData\Local\Origin
2015-09-13 19:11 - 2015-09-13 21:15 - 00000000 ____D C:\Users\Anora\AppData\Roaming\Origin
2015-09-13 10:48 - 2015-09-13 10:48 - 01042908 _____ C:\Users\Anora\Downloads\PSP File Manager & Extractor (1.2).zip
2015-09-12 16:12 - 2015-09-12 16:15 - 00042910 _____ C:\Users\Public\Desktop\CyberLink PowerDVD 15.0.zip
2015-09-10 19:51 - 2015-09-10 20:23 - 00000000 ____D C:\Users\Anora\AppData\Local\Warframe
2015-09-10 18:20 - 2015-09-10 18:20 - 00000000 ____D C:\Users\Anora\AppData\Local\BANDAI NAMCO Games
2015-09-10 07:38 - 2015-09-10 07:38 - 00000000 ____D C:\Users\Anora\AppData\Local\NeatoUpgrader
2015-09-10 07:38 - 2015-09-10 07:38 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Neato Updater Tool v2
2015-09-10 07:38 - 2015-09-10 07:38 - 00000000 ____D C:\Program Files\DIFX
2015-09-10 07:38 - 2015-09-10 07:38 - 00000000 ____D C:\Program Files (x86)\Neato Robotics
2015-09-10 07:36 - 2015-09-10 07:37 - 02070016 _____ (Neato Robotics, Inc) C:\Users\Anora\Downloads\NeatoUpdaterToolInstaller_x64.exe
2015-09-08 20:31 - 2015-08-27 03:36 - 03620736 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2015-09-08 20:31 - 2015-08-27 03:32 - 00608936 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2015-09-08 20:31 - 2015-08-27 02:59 - 02880032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2015-09-08 20:31 - 2015-08-27 02:54 - 00541248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2015-09-08 20:31 - 2015-08-27 02:54 - 00365568 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
2015-09-08 20:31 - 2015-08-27 02:51 - 02350592 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll
2015-09-08 20:31 - 2015-08-27 02:51 - 01774592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Immersive.dll
2015-09-08 20:31 - 2015-08-27 02:49 - 01008640 _____ (Microsoft Corporation) C:\WINDOWS\system32\schedsvc.dll
2015-09-08 20:31 - 2015-08-27 02:47 - 12503552 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2015-09-08 20:31 - 2015-08-27 02:43 - 00826880 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2015-09-08 20:31 - 2015-08-27 02:43 - 00576000 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2015-09-08 20:31 - 2015-08-27 02:42 - 00596480 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSync.dll
2015-09-08 20:31 - 2015-08-27 02:42 - 00187904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.PicturePassword.dll
2015-09-08 20:31 - 2015-08-27 02:42 - 00184320 _____ (Microsoft Corporation) C:\WINDOWS\system32\shacct.dll
2015-09-08 20:31 - 2015-08-27 02:39 - 00045568 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2015-09-08 20:31 - 2015-08-27 02:23 - 00303104 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
2015-09-08 20:31 - 2015-08-27 02:16 - 02153472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll
2015-09-08 20:31 - 2015-08-27 02:16 - 01612288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Immersive.dll
2015-09-08 20:31 - 2015-08-27 02:12 - 00650752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2015-09-08 20:31 - 2015-08-27 02:12 - 00504320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2015-09-08 20:31 - 2015-08-27 02:11 - 00484352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSync.dll
2015-09-08 20:31 - 2015-08-27 02:11 - 00139776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shacct.dll
2015-09-08 20:31 - 2015-08-27 02:09 - 11262464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2015-09-08 20:31 - 2015-08-27 02:08 - 00037376 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
2015-09-08 17:03 - 2015-09-08 17:03 - 00000000 ____D C:\Users\Anora\Desktop\Old Firefox Data
2015-09-07 09:10 - 2015-09-07 09:10 - 00090668 _____ C:\Users\Anora\Downloads\A Different Perspective ( 18 - Chapter 18_ Ascendancy ).txt
2015-09-06 23:55 - 2015-09-06 23:55 - 00000000 ___RD C:\Users\Anora\3D Objects
2015-09-06 23:54 - 2015-09-06 23:54 - 24834448 _____ (ReviverSoft) C:\Users\Anora\Downloads\PCReviverSetup-SpeedTest.exe
2015-09-06 23:41 - 2015-09-06 23:41 - 00000000 ____D C:\Users\Anora\Documents\MPC-HC Capture
2015-09-06 23:40 - 2015-09-06 23:40 - 00000000 ____D C:\Users\Anora\AppData\Roaming\MPC-HC
2015-09-06 23:37 - 2015-09-10 07:44 - 00002856 _____ C:\WINDOWS\SysWOW64\LavasoftTcpServiceOff.ini
2015-09-06 23:37 - 2015-09-10 07:44 - 00002856 _____ C:\WINDOWS\system32\LavasoftTcpServiceOff.ini
2015-09-06 23:37 - 2015-09-06 23:37 - 00425744 _____ (Lavasoft Limited) C:\WINDOWS\system32\LavasoftTcpService64.dll
2015-09-06 23:37 - 2015-09-06 23:37 - 00345360 _____ (Lavasoft Limited) C:\WINDOWS\SysWOW64\LavasoftTcpService.dll
2015-09-06 23:36 - 2015-09-06 23:36 - 00003008 _____ C:\WINDOWS\System32\Tasks\klcp_update
2015-09-06 23:36 - 2015-09-06 23:36 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack
2015-09-06 23:36 - 2015-09-06 23:36 - 00000000 ____D C:\Program Files (x86)\K-Lite Codec Pack
2015-09-06 23:36 - 2015-08-24 15:00 - 00112128 _____ C:\WINDOWS\SysWOW64\ff_vfw.dll
2015-09-06 23:36 - 2015-06-22 10:25 - 00254976 _____ C:\WINDOWS\system32\xvidvfw.dll
2015-09-06 23:36 - 2015-06-22 10:25 - 00240128 _____ C:\WINDOWS\SysWOW64\xvidvfw.dll
2015-09-06 23:36 - 2015-06-22 10:24 - 00729088 _____ C:\WINDOWS\system32\xvidcore.dll
2015-09-06 23:36 - 2015-06-22 10:24 - 00655872 _____ C:\WINDOWS\SysWOW64\xvidcore.dll
2015-09-06 23:36 - 2015-02-28 12:22 - 03571200 _____ (x264vfw project) C:\WINDOWS\system32\x264vfw64.dll
2015-09-06 23:36 - 2015-02-28 12:21 - 03591680 _____ (x264vfw project) C:\WINDOWS\SysWOW64\x264vfw.dll
2015-09-06 23:36 - 2012-07-21 07:55 - 00180736 _____ (fccHandler) C:\WINDOWS\system32\ac3acm.acm
2015-09-06 23:36 - 2012-07-21 07:54 - 00122880 _____ (fccHandler) C:\WINDOWS\SysWOW64\ac3acm.acm
2015-09-06 23:36 - 2011-12-07 14:37 - 00148992 _____ ( ) C:\WINDOWS\system32\lagarith.dll
2015-09-06 23:36 - 2011-12-07 14:32 - 00216064 _____ ( ) C:\WINDOWS\SysWOW64\lagarith.dll
2015-09-06 23:34 - 2015-09-06 23:39 - 11538178 _____ ( ) C:\Users\Anora\Downloads\klcp_update_1141_20150904.exe
2015-09-06 23:33 - 2015-09-06 23:34 - 41563740 _____ ( ) C:\Users\Anora\Downloads\K-Lite_Codec_Pack_1140_Mega.exe
2015-09-06 22:55 - 2015-09-06 22:55 - 00000000 ____D C:\Users\Anora\AppData\LocalLow\Hyper Hippo Productions Ltd_
2015-09-05 17:28 - 2015-09-05 17:28 - 00000000 ____D C:\Users\Anora\AppData\Local\DunDefLauncher
2015-09-05 11:19 - 2015-09-05 11:19 - 00000000 ____D C:\Users\Anora\AppData\LocalLow\ProjectorGames

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-10-05 11:28 - 2015-08-13 08:43 - 00000000 ____D C:\Users\Anora\AppData\Roaming\Skype
2015-10-05 11:28 - 2015-07-10 09:22 - 00000275 _____ C:\WINDOWS\WindowsUpdate.log
2015-10-05 11:24 - 2015-08-13 08:28 - 00000000 ____D C:\Users\Anora\AppData\Roaming\TS3Client
2015-10-05 11:21 - 2015-08-15 11:02 - 00000000 ____D C:\Users\Anora\AppData\Roaming\Azureus
2015-10-05 10:51 - 2015-08-13 08:23 - 00000830 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-10-05 10:45 - 2015-08-13 09:40 - 00000906 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job
2015-10-05 10:34 - 2015-07-10 08:04 - 00000000 ____D C:\WINDOWS\system32\sru
2015-10-05 09:45 - 2015-08-13 09:40 - 00000902 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskMachineCore.job
2015-10-05 06:10 - 2015-08-29 22:46 - 00004150 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{EA2E53CE-F334-47B7-8980-3556B6318B92}
2015-10-04 09:29 - 2015-07-10 08:04 - 00000000 ____D C:\WINDOWS\AppReadiness
2015-10-04 00:26 - 2015-07-10 08:04 - 00000000 ____D C:\WINDOWS\rescache
2015-10-03 08:52 - 2015-08-20 09:21 - 01012590 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2015-10-03 08:52 - 2015-08-13 09:45 - 00000000 ___RD C:\Users\Anora\Dropbox
2015-10-03 08:52 - 2015-08-13 09:40 - 00000000 ____D C:\Users\Anora\AppData\Local\Dropbox
2015-10-03 08:44 - 2015-07-10 09:21 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-10-02 19:47 - 2015-08-20 14:04 - 00000000 ____D C:\Program Files (x86)\MSBuild
2015-10-02 19:44 - 2015-08-20 09:19 - 00000000 ____D C:\ProgramData\Package Cache
2015-10-02 19:35 - 2015-08-20 09:15 - 00010394 _____ C:\WINDOWS\PFRO.log
2015-10-02 19:35 - 2015-08-13 08:03 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2015-10-02 19:34 - 2015-07-10 06:05 - 00524288 ___SH C:\WINDOWS\system32\config\BBI
2015-10-02 19:31 - 2015-07-10 08:04 - 00000000 ___SD C:\WINDOWS\SysWOW64\F12
2015-10-02 19:31 - 2015-07-10 08:04 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility
2015-10-02 19:30 - 2015-07-10 08:04 - 00000000 ___SD C:\WINDOWS\system32\F12
2015-10-02 19:30 - 2015-07-10 08:04 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2015-10-02 19:30 - 2015-07-10 08:04 - 00000000 ____D C:\WINDOWS\system32\SystemResetPlatform
2015-10-02 19:30 - 2015-07-10 08:04 - 00000000 ____D C:\WINDOWS\system32\appraiser
2015-10-02 19:29 - 2015-07-10 08:04 - 00000000 ___RD C:\WINDOWS\PurchaseDialog
2015-10-02 19:29 - 2015-07-10 08:04 - 00000000 ____D C:\WINDOWS\Provisioning
2015-10-02 19:29 - 2015-07-10 08:04 - 00000000 ____D C:\WINDOWS\L2Schemas
2015-10-02 19:26 - 2015-08-20 09:18 - 00000000 ____D C:\Program Files\AMD
2015-10-02 19:25 - 2015-08-13 08:11 - 00000000 ____D C:\AMD
2015-10-02 19:21 - 2015-08-27 22:14 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Seagate
2015-10-02 19:20 - 2015-08-13 09:50 - 00000000 ____D C:\Program Files\MySQL
2015-10-02 19:20 - 2015-08-13 09:03 - 00000000 ____D C:\Program Files (x86)\MSI
2015-10-02 19:20 - 2015-08-13 07:50 - 00000000 ____D C:\MSI
2015-10-02 19:19 - 2015-08-13 09:48 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MySQL
2015-10-02 19:18 - 2015-08-13 09:47 - 00000000 ____D C:\Program Files (x86)\MySQL
2015-10-02 19:17 - 2015-08-13 09:51 - 00000023 _____ C:\WINDOWS\ODBCINST.INI
2015-10-02 19:12 - 2015-08-13 07:55 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2015-10-02 19:10 - 2015-08-13 08:01 - 00000000 ____D C:\Program Files (x86)\Realtek
2015-10-02 19:09 - 2015-08-13 07:54 - 00000000 ____D C:\ProgramData\Downloaded Installations
2015-10-02 19:09 - 2015-08-13 07:54 - 00000000 _____ C:\Users\Anora\AppData\Local\Driver_LOM_8161Present.flag
2015-10-02 18:37 - 2015-08-13 09:40 - 00000000 ____D C:\Program Files (x86)\Dropbox
2015-10-01 07:23 - 2015-07-10 07:55 - 00000000 ____D C:\WINDOWS\CbsTemp
2015-09-30 21:56 - 2015-08-14 07:36 - 00000000 ____D C:\Users\Anora\AppData\Local\FirestormOS_x64
2015-09-28 08:00 - 2015-08-20 09:23 - 00000000 ____D C:\Users\Anora
2015-09-27 20:21 - 2015-07-10 08:04 - 00000000 ____D C:\WINDOWS\LiveKernelReports
2015-09-27 19:40 - 2015-08-13 07:43 - 00000000 ____D C:\Users\Anora\AppData\Local\VirtualStore
2015-09-25 16:06 - 2015-08-17 17:01 - 00000000 ____D C:\Users\Anora\AppData\Local\ftblauncher
2015-09-25 13:18 - 2015-08-13 08:28 - 00000000 ____D C:\Program Files\TeamSpeak 3 Client
2015-09-25 09:31 - 2015-08-20 09:43 - 00000000 ____D C:\Users\Anora\AppData\Local\Packages
2015-09-25 09:26 - 2015-08-14 00:36 - 00000000 ____D C:\Program Files\LinkShellExtension
2015-09-25 09:25 - 2015-08-29 19:07 - 00000000 ____D C:\Program Files (x86)\CyberLink
2015-09-22 07:51 - 2015-08-13 08:23 - 00003804 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2015-09-18 16:01 - 2015-08-13 08:37 - 00000000 ____D C:\Users\Anora\AppData\Local\AMD
2015-09-15 19:40 - 2015-08-29 19:05 - 00000000 ____D C:\ProgramData\SUPPORTDIR
2015-09-15 16:39 - 2015-08-29 19:05 - 00000000 ____D C:\ProgramData\CyberLink
2015-09-14 21:25 - 2015-08-13 08:23 - 00000000 ____D C:\ProgramData\AMD
2015-09-14 21:20 - 2015-08-20 09:19 - 00000000 ____D C:\Program Files (x86)\ATI Technologies
2015-09-13 17:02 - 2015-08-30 17:42 - 00000080 _____ C:\Users\Anora\AppData\Local剜捯獫慴⁲慇敭屳呇⁁屖湥楴汴浥湥⹴湩潦
2015-09-13 17:02 - 2015-08-30 17:42 - 00000000 ____D C:\Program Files (x86)\Rockstar Games
2015-09-13 17:02 - 2015-08-30 17:41 - 00000000 ____D C:\Program Files\Rockstar Games
2015-09-12 16:11 - 2015-08-29 19:05 - 00000000 ____D C:\ProgramData\install_clap
2015-09-10 07:43 - 2015-07-10 09:20 - 00193696 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2015-09-10 07:41 - 2015-07-10 10:14 - 00000000 ____D C:\Program Files\Windows Journal
2015-09-08 23:19 - 2015-08-13 08:31 - 00000000 ____D C:\WINDOWS\system32\MRT

==================== Files in the root of some directories =======

2015-08-13 07:54 - 2015-10-02 19:09 - 0000000 _____ () C:\Users\Anora\AppData\Local\Driver_LOM_8161Present.flag
2015-08-22 18:22 - 2015-08-22 18:22 - 0000600 _____ () C:\Users\Anora\AppData\Local\PUTTY.RND

Files to move or delete:
====================
C:\Users\Anora\en_res.dll
C:\Users\Anora\es_res.dll
C:\Users\Anora\fr_res.dll
C:\Users\Anora\grm_res.dll
C:\Users\Anora\it_res.dll
C:\Users\Anora\jp_res.dll
C:\Users\Anora\mfc80u.dll
C:\Users\Anora\msvcr80.dll
C:\Users\Anora\PCPE Setup.exe
C:\Users\Anora\pt_res.dll
C:\Users\Anora\ResourceReader.dll
C:\Users\Anora\ru_res.dll
C:\Users\Anora\zh_res.dll


Some files in TEMP:
====================
C:\Users\Anora\AppData\Local\Temp\CH.dll
C:\Users\Anora\AppData\Local\Temp\COMAP.EXE
C:\Users\Anora\AppData\Local\Temp\drm_dyndata_7370014.dll
C:\Users\Anora\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpcwzmbn.dll
C:\Users\Anora\AppData\Local\Temp\i4jdel0.exe
C:\Users\Anora\AppData\Local\Temp\jre-8u60-windows-au.exe
C:\Users\Anora\AppData\Local\Temp\npp.6.8.3.Installer.exe
C:\Users\Anora\AppData\Local\Temp\raptrpatch.exe
C:\Users\Anora\AppData\Local\Temp\raptr_stub.exe
C:\Users\Anora\AppData\Local\Temp\xmlUpdater.exe


==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-10-01 07:19

==================== End of FRST.txt ============================

 

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:04-10-2015
Ran by Anora (administrator) on ANORA-PC (05-10-2015 11:28:50)
Running from C:\Users\Anora\Desktop
Loaded Profiles: Anora (Available Profiles: Anora & Classic .NET AppPool & dynmap & wildrenter)
Platform: Windows 10 Pro (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Schneider Electric) C:\Program Files (x86)\APC\PowerChute Personal Edition\mainserv.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Advanced Micro Devices, Inc.) C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe
(Microsoft Corporation) C:\Windows\System32\mqsvc.exe
() C:\Program Files\MySQL\MySQL Server 5.6\bin\mysqld.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(Rivet Networks) C:\Program Files\Killer Networking\Network Manager\KillerService.exe
(Micro-Star INT'L CO., LTD.) C:\Program Files (x86)\MSI\Live Update\MSI_LiveUpdate_Service.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersServer.exe
(Microsoft Corporation) C:\Windows\System32\Speech_OneCore\Common\SpeechRuntime.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Electronic Arts) I:\Program Files (x86)\Origin\Origin.exe
(Vag-Labs) C:\Program Files (x86)\Vag-Labs\RAM Monitor\RAM Monitor.exe
(Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
(Schneider Electric) C:\Program Files (x86)\APC\PowerChute Personal Edition\apcsystray.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD15\PowerDVD15Agent.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\MOM.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
(Micro-Star INT'L CO., LTD.) C:\Program Files (x86)\MSI\Live Update\Live Update.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\CCC.exe
(TeamSpeak Systems GmbH) C:\Program Files\TeamSpeak 3 Client\ts3client_win64.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.6224.42281.0_x64__8wekyb3d8bbwe\HxMail.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.6224.42281.0_x64__8wekyb3d8bbwe\HxTsr.exe
(Valve Corporation) I:\Program Files (x86)\Steam\Steam.exe
(Valve Corporation) I:\Program Files (x86)\Steam\bin\steamwebhelper.exe
(Valve Corporation) I:\Program Files (x86)\Steam\bin\steamwebhelper.exe
(MultiMC Contributors) J:\MultyMc5\MultiMC.exe
(Oracle Corporation) C:\Program Files\Java\jre1.8.0_60\bin\java.exe
(Valve Corporation) I:\Program Files (x86)\Steam\GameOverlayUI.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_19_0_0_185.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_19_0_0_185.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8492800 2015-06-24] (Realtek Semiconductor)
HKLM\...\Run: [VIAxHCUtl] => C:\Program Files\VIA XHCI UASP Utility\usb3Monitor
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [170256 2015-09-15] (Apple Inc.)
HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [36710768 2015-10-01] (Dropbox, Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [597552 2015-08-04] (Oracle Corporation)
HKLM-x32\...\Run: [PowerDVD15Agent] => C:\Program Files (x86)\CyberLink\PowerDVD15\PowerDVD15Agent.exe [949960 2015-08-10] (CyberLink Corp.)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe [767176 2015-08-21] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [Display] => C:\Program Files (x86)\APC\PowerChute Personal Edition\DataCollectionLauncher.exe [284024 2012-01-24] (Schneider Electric)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [6134544 2015-09-25] (AVAST Software)
HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [4101576 2014-06-24] (Safer-Networking Ltd.)
HKLM-x32\...\Run: [Live Update] => C:\Program Files (x86)\MSI\Live Update\Live Update.exe [11328464 2015-09-11] (Micro-Star INT'L CO., LTD.)
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
HKU\S-1-5-21-434036944-719920970-2392407034-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [53729824 2015-08-07] (Skype Technologies S.A.)
HKU\S-1-5-21-434036944-719920970-2392407034-1000\...\Run: [EADM] => I:\Program Files (x86)\Origin\Origin.exe [3638768 2015-10-02] (Electronic Arts)
HKU\S-1-5-21-434036944-719920970-2392407034-1000\...\Run: [RAM Monitor] => C:\Program Files (x86)\Vag-Labs\RAM Monitor\RAM Monitor.exe [562176 2008-10-29] (Vag-Labs)
HKU\S-1-5-21-434036944-719920970-2392407034-1000\...\Policies\system: [DisableLockWorkstation] 0
ShellIconOverlayIdentifiers: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.dll [2015-10-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.dll [2015-10-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.dll [2015-10-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.dll [2015-10-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.dll [2015-10-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.dll [2015-10-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.dll [2015-10-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.dll [2015-10-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2015-09-25] (AVAST Software)
ShellIconOverlayIdentifiers-x32: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.27.dll [2015-10-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.27.dll [2015-10-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.27.dll [2015-10-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.27.dll [2015-10-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.27.dll [2015-10-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.27.dll [2015-10-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.27.dll [2015-10-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.27.dll [2015-10-01] (Dropbox, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\APC UPS Status.lnk [2015-09-19]
ShortcutTarget: APC UPS Status.lnk -> C:\Program Files (x86)\APC\PowerChute Personal Edition\Display.exe (Schneider Electric)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Killer Network Manager.lnk [2015-10-02]
ShortcutTarget: Killer Network Manager.lnk -> C:\Program Files\Killer Networking\Network Manager\NetworkManager.exe (Rivet Networks)
BootExecute: autocheck autochk * sdnclean64.exe

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 64.71.255.204 64.71.255.198
Tcpip\..\Interfaces\{a06edd46-d5b5-47bb-ae28-6973544822b8}: [DhcpNameServer] 64.71.255.204 64.71.255.198

Internet Explorer:
==================
HKU\S-1-5-21-434036944-719920970-2392407034-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/en-ca/?ocid=iehp
SearchScopes: HKU\S-1-5-21-434036944-719920970-2392407034-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_60\bin\ssv.dll [2015-08-28] (Oracle Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-09-25] (AVAST Software)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-05-01] (Microsoft Corporation)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_60\bin\jp2ssv.dll [2015-08-28] (Oracle Corporation)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\ssv.dll [2015-08-28] (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-09-25] (AVAST Software)
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01] (Microsoft Corporation)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\jp2ssv.dll [2015-08-28] (Oracle Corporation)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-05-01] (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01] (Microsoft Corporation)

FireFox:
========
FF ProfilePath: C:\Users\Anora\AppData\Roaming\Mozilla\Firefox\Profiles\htphesra.default-1441742598665
FF Homepage: about:home
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_19_0_0_185.dll [2015-09-22] ()
FF Plugin: @java.com/DTPlugin,version=11.60.2 -> C:\Program Files\Java\jre1.8.0_60\bin\dtplugin\npDeployJava1.dll [2015-08-28] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.60.2 -> C:\Program Files\Java\jre1.8.0_60\bin\plugin2\npjp2.dll [2015-08-28] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_19_0_0_185.dll [2015-09-22] ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-10-30] ()
FF Plugin-x32: @java.com/DTPlugin,version=11.60.2 -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\dtplugin\npDeployJava1.dll [2015-08-28] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.60.2 -> C:\Program Files (x86)\Java\jre1.8.0_60\bin\plugin2\npjp2.dll [2015-08-28] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Extension: YouTube Unblocker - C:\Users\Anora\AppData\Roaming\Mozilla\Firefox\Profiles\htphesra.default-1441742598665\Extensions\youtubeunblocker@unblocker.yt [2015-09-08]
FF Extension: DownThemAll! AntiContainer - C:\Users\Anora\AppData\Roaming\Mozilla\Firefox\Profiles\htphesra.default-1441742598665\Extensions\anticontainer@downthemall.net.xpi [2015-09-08]
FF Extension: Element Hiding Helper for Adblock Plus - C:\Users\Anora\AppData\Roaming\Mozilla\Firefox\Profiles\htphesra.default-1441742598665\Extensions\elemhidehelper@adblockplus.org.xpi [2015-09-08]
FF Extension: FurAffinity Extender - C:\Users\Anora\AppData\Roaming\Mozilla\Firefox\Profiles\htphesra.default-1441742598665\Extensions\faextender@neocodenetworks.com.xpi [2015-09-14]
FF Extension: Forecastfox (fix version) - C:\Users\Anora\AppData\Roaming\Mozilla\Firefox\Profiles\htphesra.default-1441742598665\Extensions\forecastfox@s3_fix_version.xpi [2015-09-08]
FF Extension: YouTube mp3 - C:\Users\Anora\AppData\Roaming\Mozilla\Firefox\Profiles\htphesra.default-1441742598665\Extensions\info@youtube-mp3.org.xpi [2015-09-08]
FF Extension: Long URL Please - C:\Users\Anora\AppData\Roaming\Mozilla\Firefox\Profiles\htphesra.default-1441742598665\Extensions\longurlplease@darragh.curran.xpi [2015-09-08]
FF Extension: Status-4-Evar - C:\Users\Anora\AppData\Roaming\Mozilla\Firefox\Profiles\htphesra.default-1441742598665\Extensions\status4evar@caligonstudios.com.xpi [2015-09-08]
FF Extension: TortoiseSVN Menu - C:\Users\Anora\AppData\Roaming\Mozilla\Firefox\Profiles\htphesra.default-1441742598665\Extensions\tsvnmenu@pumacode.org.xpi [2015-09-08]
FF Extension: 1-Click YouTube Video Downloader - C:\Users\Anora\AppData\Roaming\Mozilla\Firefox\Profiles\htphesra.default-1441742598665\Extensions\YoutubeDownloader@PeterOlayev.com.xpi [2015-09-08]
FF Extension: YouTube High Definition - C:\Users\Anora\AppData\Roaming\Mozilla\Firefox\Profiles\htphesra.default-1441742598665\Extensions\{7b1bf0b6-a1b9-42b0-b75d-252036438bdc}.xpi [2015-09-08]
FF Extension: Adblock Plus - C:\Users\Anora\AppData\Roaming\Mozilla\Firefox\Profiles\htphesra.default-1441742598665\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-09-08]
FF Extension: DownThemAll! - C:\Users\Anora\AppData\Roaming\Mozilla\Firefox\Profiles\htphesra.default-1441742598665\Extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}.xpi [2015-09-08]
FF Extension: Download Manager Tweak - C:\Users\Anora\AppData\Roaming\Mozilla\Firefox\Profiles\htphesra.default-1441742598665\Extensions\{F8A55C97-3DB6-4961-A81D-0DE0080E53CB}.xpi [2015-09-08]
FF Extension: No Name - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2015-09-30]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2015-09-25]

Chrome:
=======
CHR HKU\S-1-5-21-434036944-719920970-2392407034-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [bknbnapaddjdnbilpmlacdkjdkjmbjhd] - hxxp://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [bknbnapaddjdnbilpmlacdkjdkjmbjhd] - hxxp://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx [2015-09-25]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-09-25]

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AMD FUEL Service; C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe [344064 2015-08-21] (Advanced Micro Devices, Inc.) [File not signed]
S2 APC Data Service; C:\Program Files (x86)\APC\PowerChute Personal Edition\dataserv.exe [21880 2012-01-24] (Schneider Electric)
R2 APC UPS Service; C:\Program Files (x86)\APC\PowerChute Personal Edition\mainserv.exe [705912 2012-01-24] (Schneider Electric)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77104 2015-09-02] (Apple Inc.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [146600 2015-09-25] (AVAST Software)
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1394816 2015-05-01] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1772672 2015-05-01] (Microsoft Corporation)
S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [136048 2015-08-13] (Dropbox, Inc.)
S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [136048 2015-08-13] (Dropbox, Inc.)
R2 Killer Service V2; C:\Program Files\Killer Networking\Network Manager\KillerService.exe [402432 2015-07-07] (Rivet Networks) [File not signed]
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2015-06-18] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation)
R2 MSI_LiveUpdate_Service; C:\Program Files (x86)\MSI\Live Update\MSI_LiveUpdate_Service.exe [1768912 2015-09-11] (Micro-Star INT'L CO., LTD.)
R2 MSMQ; C:\Windows\system32\mqsvc.exe [26112 2015-08-20] (Microsoft Corporation)
R2 MySQL56; C:\Program Files\MySQL\MySQL Server 5.6\bin\mysqld.exe [13061632 2015-07-15] () [File not signed]
S3 Origin Client Service; I:\Program Files (x86)\Origin\OriginClientService.exe [2078216 2015-10-02] (Electronic Arts)
R2 PnkBstrA; C:\WINDOWS\SysWOW64\PnkBstrA.exe [66872 2015-09-14] ()
R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1738168 2014-06-24] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2088408 2014-06-27] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2014-04-25] (Safer-Networking Ltd.)
S3 Te.Service; C:\Program Files (x86)\Windows Kits\8.1\Testing\Runtimes\TAEF\Wex.Services.exe [119808 2013-08-22] (Microsoft Corporation) [File not signed]
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [5702416 2015-09-11] (TeamViewer GmbH)
S3 w3logsvc; C:\Windows\system32\inetsrv\w3logsvc.dll [84480 2015-08-20] (Microsoft Corporation)
R2 W3SVC; C:\Windows\system32\inetsrv\iisw3adm.dll [578560 2015-08-20] (Microsoft Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [362928 2015-07-10] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-07-10] (Microsoft Corporation)

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R0 amdkmafd; C:\Windows\System32\drivers\amdkmafd.sys [40720 2015-07-28] (Advanced Micro Devices, Inc.)
R2 AODDriver4.3; C:\Program Files\AMD\ATI.ACE\Fuel\amd64\AODDriver2.sys [59616 2014-02-11] (Advanced Micro Devices)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [28656 2015-09-25] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [90968 2015-09-25] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-09-25] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65224 2015-09-25] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1049880 2015-09-25] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [448968 2015-09-25] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [153744 2015-09-25] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [274808 2015-09-25] (AVAST Software)
R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdWT6.sys [102912 2015-07-21] (Advanced Micro Devices)
S3 dc1-controller; C:\Windows\System32\drivers\dc1-controller.sys [50688 2015-07-10] (Microsoft Corp.)
S3 DCamUSBNovatek; C:\Windows\System32\Drivers\nvtcam.sys [2746624 2010-07-14] (Hewlett-Packard) [File not signed]
S3 ipadtst; C:\Program Files (x86)\MSI\Super Charger\ipadtst_64.sys [20464 2013-11-11] (Windows ® Win 7 DDK provider)
S3 Ke2200; C:\Windows\System32\drivers\e22w7x64.sys [154320 2013-03-20] (Qualcomm Atheros, Inc.)
R3 KillerEth; C:\Windows\System32\drivers\e22w10x64.sys [124464 2015-04-27] (Qualcomm Atheros, Inc.)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2015-06-18] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [113880 2015-10-05] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2015-06-18] (Malwarebytes Corporation)
R3 MQAC; C:\Windows\System32\drivers\mqac.sys [175104 2015-08-20] (Microsoft Corporation)
S3 NTIOLib_1_0_3; C:\Program Files (x86)\MSI\Super Charger\NTIOLib_X64.sys [13368 2012-10-25] (MSI)
S3 NTIOLib_1_0_6; C:\Program Files (x86)\Setup Files\Ms7693vM30\NTIOLib_X64.sys [11888 2011-01-06] (MSI) [File not signed]
S3 NTIOLib_FastBoot; C:\Program Files (x86)\MSI\Fast Boot\NTIOLib_X64.sys [13368 2012-10-26] (MSI)
S3 NTIOLib_MSIClock_CC; C:\Program Files (x86)\MSI\Command Center\ClockGen\NTIOLib_X64.sys [13368 2012-11-20] (MSI)
S3 NTIOLib_MSICPU_CC; C:\Program Files (x86)\MSI\Command Center\CPU\NTIOLib_X64.sys [13368 2012-11-20] (MSI)
S3 NTIOLib_MSIDDR_CC; C:\Program Files (x86)\MSI\Command Center\DDR\NTIOLib_X64.sys [13368 2012-11-26] (MSI)
S3 NTIOLib_MSISMB_CC; C:\Program Files (x86)\MSI\Command Center\SMBus\NTIOLib_X64.sys [13368 2012-11-19] (MSI)
R3 Phosgene; C:\Windows\system32\DRIVERS\Phosgene.sys [32120 2015-06-08] ()
S3 UdeCx; C:\Windows\System32\drivers\udecx.sys [44032 2015-07-10] ()
S3 usbser64; C:\Windows\system32\DRIVERS\usbser.sys [67072 2015-08-20] (Microsoft Corporation)
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44568 2015-07-10] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [291680 2015-07-10] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [119648 2015-07-10] (Microsoft Corporation)
R2 {687703DE-DC6D-4649-892B-B8497854A6AB}; C:\Program Files (x86)\CyberLink\PowerDVD15\Common\NavFilter\000.fcl [29896 2015-08-10] (CyberLink Corp.)
U3 idsvc; no ImagePath
S3 NTIOLib_MSICOMM_CC; \??\C:\Program Files (x86)\MSI\Command Center\NTIOLib_X64.sys [X]
S3 NTIOLib_MSIFrequency_CC; \??\C:\Program Files (x86)\MSI\Command Center\ClockGen\CPU_Frequency\NTIOLib_X64.sys [X]
S3 NTIOLib_MSIRatio_CC; \??\C:\Program Files (x86)\MSI\Command Center\CPU\CPU_Ratio\NTIOLib_X64.sys [X]
S3 NTIOLib_MSISuperIO_CC; \??\C:\Program Files (x86)\MSI\Command Center\SuperIO\NTIOLib_X64.sys [X]
S3 wfpcapture; \SystemRoot\System32\drivers\wfpcapture.sys [X]
U3 wpcsvc; no ImagePath

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-10-05 11:28 - 2015-10-05 11:29 - 00025962 _____ C:\Users\Anora\Desktop\FRST.txt
2015-10-05 11:28 - 2015-10-05 11:28 - 00000000 ____D C:\Users\Anora\Desktop\FRST-OlderVersion
2015-10-05 11:18 - 2015-10-05 11:18 - 00016148 _____ C:\WINDOWS\system32\ANORA-PC_Anora_HistoryPrediction.bin
2015-10-05 01:30 - 2015-10-05 01:30 - 00109628 _____ C:\Users\Anora\Downloads\A Different Perspective ( 19 - Chapter 19_ We've Only Just Begun ).txt
2015-10-05 01:30 - 2015-10-05 01:30 - 00015497 _____ C:\Users\Anora\Downloads\The Monster of Canterlot ( 56 -  ).txt
2015-10-04 21:56 - 2015-10-04 21:56 - 00011820 _____ C:\Users\Anora\Downloads\ResourceLoader-1.2.jar
2015-10-04 21:49 - 2015-10-04 21:50 - 18393499 _____ C:\Users\Anora\Downloads\UNZIP ME - Sim-U-Kraft Reloaded 1.0.4a - UNZIP ME.zip
2015-10-04 21:45 - 2015-10-04 21:45 - 00589182 _____ C:\Users\Anora\Downloads\Sim-U-Kraft Mod Installer 1.7.10.zip
2015-10-04 21:23 - 2015-10-04 21:23 - 01177769 _____ C:\Users\Anora\Downloads\SimCraftClientLauncher.jar
2015-10-04 16:16 - 2015-10-04 16:16 - 00351928 _____ C:\Users\Anora\Downloads\EnderZoo-1.7.10-1.0.15.32(1).jar
2015-10-03 19:43 - 2015-10-03 19:43 - 00000000 ____D C:\Users\Anora\AppData\Roaming\TeamViewer
2015-10-03 19:09 - 2015-10-03 19:09 - 00001112 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 10.lnk
2015-10-03 19:09 - 2015-10-03 19:09 - 00001100 _____ C:\Users\Public\Desktop\TeamViewer 10.lnk
2015-10-03 19:09 - 2015-10-03 19:09 - 00000000 ____D C:\Program Files (x86)\TeamViewer
2015-10-03 19:08 - 2015-10-03 19:08 - 08159440 _____ (TeamViewer GmbH) C:\Users\Anora\Downloads\TeamViewer_Setup_en-jfx.exe
2015-10-03 13:50 - 2015-10-03 13:50 - 01177521 _____ C:\Users\Anora\Desktop\GraveStone-2.12.4.jar
2015-10-03 13:43 - 2015-10-03 13:43 - 00583293 _____ C:\Users\Anora\Downloads\Gravestone Mod Installer 1.7.10.zip
2015-10-03 10:41 - 2015-10-03 10:41 - 00138825 _____ C:\Users\Anora\Documents\summary.zip
2015-10-03 10:40 - 2015-10-03 10:40 - 03486834 _____ C:\Users\Anora\Documents\summary.nfo
2015-10-03 10:11 - 2015-10-03 10:11 - 00000000 _____ C:\Users\Anora\Desktop\New Text Document.txt
2015-10-03 10:04 - 2015-10-03 10:06 - 00065325 _____ C:\Users\Anora\Downloads\Addition.txt
2015-10-03 10:02 - 2015-10-05 11:29 - 00000000 ____D C:\FRST
2015-10-03 10:02 - 2015-10-05 11:28 - 02193920 _____ (Farbar) C:\Users\Anora\Desktop\FRST64.exe
2015-10-03 10:02 - 2015-10-03 10:04 - 00096729 _____ C:\Users\Anora\Downloads\FRST.txt
2015-10-03 08:51 - 2015-10-03 08:51 - 00000000 ____D C:\ApcTempReg
2015-10-02 21:10 - 2015-10-02 21:10 - 00000020 ___SH C:\Users\dynmap\ntuser.ini
2015-10-02 21:10 - 2015-10-02 21:10 - 00000000 ____D C:\Users\dynmap
2015-10-02 21:10 - 2015-08-20 09:27 - 00000000 ___RD C:\Users\dynmap\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-10-02 21:10 - 2015-07-10 08:04 - 00000000 __RSD C:\Users\dynmap\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell
2015-10-02 21:10 - 2015-07-10 08:04 - 00000000 ___RD C:\Users\dynmap\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-10-02 21:10 - 2015-07-10 08:04 - 00000000 ___RD C:\Users\dynmap\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2015-10-02 21:10 - 2015-07-10 08:04 - 00000000 ____D C:\Users\dynmap\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-10-02 19:47 - 2015-10-02 19:47 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Kits
2015-10-02 19:44 - 2015-10-02 19:44 - 00000000 ____D C:\Program Files (x86)\Windows Kits
2015-10-02 19:37 - 2015-09-15 13:12 - 00812008 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2015-10-02 19:37 - 2015-09-15 13:12 - 00178152 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2015-10-02 19:26 - 2015-05-12 18:13 - 00061464 _____ (Advanced Micro Devices) C:\WINDOWS\system32\Drivers\usbfilter.sys
2015-10-02 19:24 - 2015-10-02 19:24 - 51527840 _____ (AMD Inc.) C:\Users\Anora\Downloads\amd-catalyst-15.7.1-sb-sata-ahci-win10-win8.1-win7.exe
2015-10-02 19:20 - 2015-10-02 19:20 - 00002104 _____ C:\Users\Public\Desktop\MSI Live Update 6.lnk
2015-10-02 19:20 - 2015-10-02 19:20 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MSI
2015-10-02 19:18 - 2015-10-02 19:19 - 06980685 _____ C:\Users\Anora\Downloads\LiveUpdate.zip
2015-10-02 19:12 - 2015-10-02 19:13 - 00000000 ____D C:\ProgramData\Killer
2015-10-02 19:12 - 2015-10-02 19:12 - 00002801 _____ C:\Users\Public\Desktop\Killer Network Manager.lnk
2015-10-02 19:12 - 2015-10-02 19:12 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Killer Networking
2015-10-02 19:10 - 2015-10-02 19:10 - 00000000 ____D C:\Program Files\Killer Networking
2015-10-02 18:56 - 2015-10-02 19:07 - 261180638 _____ C:\Users\Anora\Downloads\Killer_network_w10.zip
2015-10-02 18:56 - 2015-10-02 18:58 - 238920953 _____ C:\Users\Anora\Downloads\realtek_hd_audio(1).zip
2015-10-02 18:55 - 2015-10-02 19:00 - 04424219 _____ C:\Users\Anora\Downloads\7693vM3.zip
2015-10-02 18:44 - 2015-10-02 18:44 - 00991968 _____ (Microsoft Corporation) C:\Users\Anora\Downloads\wdksetup.exe
2015-10-02 18:37 - 2015-10-02 18:37 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Vag-Labs
2015-10-02 18:37 - 2015-10-02 18:37 - 00000000 ____D C:\Program Files (x86)\Vag-Labs
2015-10-02 18:36 - 2015-10-02 18:37 - 00335927 _____ C:\Users\Anora\Downloads\ram_monitor_setup.zip
2015-10-02 18:36 - 2015-10-02 18:36 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox
2015-10-02 18:22 - 2015-10-02 18:22 - 00000000 ____D C:\Users\Anora\AppData\Local\Micro-Star_Int'l_Co.,_Ltd
2015-10-02 18:20 - 2015-10-02 18:20 - 00100635 _____ C:\Users\Anora\Downloads\MSIAfterburnerRemoteServer.zip
2015-10-02 07:17 - 2015-10-02 07:17 - 00052002 _____ C:\Users\Anora\Downloads\TiCTooltips-mc1.7.10-1.2.5.jar
2015-10-02 07:13 - 2015-10-02 07:13 - 00457912 _____ C:\Users\Anora\Downloads\EnderCore-1.7.10-0.1.0.24_beta.jar
2015-10-02 07:05 - 2015-10-02 07:05 - 00025539 _____ C:\Users\Anora\Downloads\WailaHarvestability-mc1.7.x-1.1.2.jar
2015-10-02 07:04 - 2015-10-02 07:04 - 00074135 _____ C:\Users\Anora\Downloads\WAILAPlugins-MC1.7.10-0.1.2-21.jar
2015-10-01 05:14 - 2015-09-17 03:49 - 06487248 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2015-10-01 05:14 - 2015-09-17 03:28 - 05120056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2015-10-01 05:14 - 2015-09-17 03:12 - 16708608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2015-10-01 05:14 - 2015-09-17 03:07 - 21875712 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2015-10-01 05:14 - 2015-09-17 03:04 - 07569408 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll
2015-10-01 05:14 - 2015-09-17 03:00 - 24595456 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2015-10-01 05:14 - 2015-09-17 02:54 - 03781120 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2015-10-01 05:14 - 2015-09-17 02:53 - 07055872 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll
2015-10-01 05:14 - 2015-09-17 02:51 - 13027840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2015-10-01 05:14 - 2015-09-17 02:51 - 02660864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll
2015-10-01 05:14 - 2015-09-17 02:47 - 07523328 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2015-10-01 05:14 - 2015-09-17 02:45 - 19325440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2015-10-01 05:14 - 2015-09-17 02:40 - 06101504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mos.dll
2015-10-01 05:14 - 2015-09-17 02:37 - 18806272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2015-10-01 05:14 - 2015-09-17 02:35 - 05079552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll
2015-10-01 05:13 - 2015-09-24 21:13 - 01276416 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifinetworkmanager.dll
2015-10-01 05:13 - 2015-09-24 20:17 - 02178560 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2015-10-01 05:13 - 2015-09-24 20:08 - 03586560 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2015-10-01 05:13 - 2015-09-24 20:06 - 01423872 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataService.dll
2015-10-01 05:13 - 2015-09-24 20:01 - 00856576 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContactApis.dll
2015-10-01 05:13 - 2015-09-24 20:00 - 01205248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Unistore.dll
2015-10-01 05:13 - 2015-09-24 19:42 - 01795072 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll
2015-10-01 05:13 - 2015-09-24 19:25 - 00928256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Unistore.dll
2015-10-01 05:13 - 2015-09-24 19:25 - 00625152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ContactApis.dll
2015-10-01 05:13 - 2015-09-17 03:50 - 02464216 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2015-10-01 05:13 - 2015-09-17 03:50 - 01563392 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll
2015-10-01 05:13 - 2015-09-17 03:49 - 08020816 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2015-10-01 05:13 - 2015-09-17 03:49 - 01563472 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpmde.dll
2015-10-01 05:13 - 2015-09-17 03:49 - 00894256 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Wdf01000.sys
2015-10-01 05:13 - 2015-09-17 03:48 - 02824248 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll
2015-10-01 05:13 - 2015-09-17 03:48 - 02494712 _____ C:\WINDOWS\system32\CoreUIComponents.dll
2015-10-01 05:13 - 2015-09-17 03:48 - 02432336 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2015-10-01 05:13 - 2015-09-17 03:48 - 02156400 _____ (Microsoft Corporation) C:\WINDOWS\system32\hevcdecoder.dll
2015-10-01 05:13 - 2015-09-17 03:48 - 01983824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2015-10-01 05:13 - 2015-09-17 03:48 - 00809352 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll
2015-10-01 05:13 - 2015-09-17 03:48 - 00784136 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
2015-10-01 05:13 - 2015-09-17 03:48 - 00555768 _____ (Microsoft Corporation) C:\WINDOWS\system32\directmanipulation.dll
2015-10-01 05:13 - 2015-09-17 03:48 - 00537080 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWanAPI.dll
2015-10-01 05:13 - 2015-09-17 03:48 - 00476760 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFCaptureEngine.dll
2015-10-01 05:13 - 2015-09-17 03:47 - 01397088 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll
2015-10-01 05:13 - 2015-09-17 03:44 - 00781976 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfds.dll
2015-10-01 05:13 - 2015-09-17 03:43 - 00966416 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll
2015-10-01 05:13 - 2015-09-17 03:37 - 01295712 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpx.dll
2015-10-01 05:13 - 2015-09-17 03:28 - 02154808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2015-10-01 05:13 - 2015-09-17 03:28 - 01357888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winmde.dll
2015-10-01 05:13 - 2015-09-17 03:27 - 01766952 _____ C:\WINDOWS\SysWOW64\CoreUIComponents.dll
2015-10-01 05:13 - 2015-09-17 03:27 - 00454512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\directmanipulation.dll
2015-10-01 05:13 - 2015-09-17 03:26 - 02446648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2vdec.dll
2015-10-01 05:13 - 2015-09-17 03:26 - 00646672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll
2015-10-01 05:13 - 2015-09-17 03:26 - 00428128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWanAPI.dll
2015-10-01 05:13 - 2015-09-17 03:25 - 00962400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll
2015-10-01 05:13 - 2015-09-17 03:21 - 00658528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfds.dll
2015-10-01 05:13 - 2015-09-17 03:20 - 00764416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.appcore.dll
2015-10-01 05:13 - 2015-09-17 03:06 - 00467968 _____ (Microsoft Corporation) C:\WINDOWS\system32\MBMediaManager.dll
2015-10-01 05:13 - 2015-09-17 03:05 - 02226688 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll
2015-10-01 05:13 - 2015-09-17 03:04 - 00910848 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedStartModel.dll
2015-10-01 05:13 - 2015-09-17 03:00 - 03248640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2015-10-01 05:13 - 2015-09-17 03:00 - 02417664 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
2015-10-01 05:13 - 2015-09-17 02:58 - 00503808 _____ (Microsoft Corporation) C:\WINDOWS\system32\tileobjserver.dll
2015-10-01 05:13 - 2015-09-17 02:57 - 02228736 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll
2015-10-01 05:13 - 2015-09-17 02:57 - 00281600 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEEventDispatcher.dll
2015-10-01 05:13 - 2015-09-17 02:56 - 00859136 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll
2015-10-01 05:13 - 2015-09-17 02:55 - 02236416 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2015-10-01 05:13 - 2015-09-17 02:55 - 01601536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Speech.dll
2015-10-01 05:13 - 2015-09-17 02:54 - 00780288 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2015-10-01 05:13 - 2015-09-17 02:52 - 01181696 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
2015-10-01 05:13 - 2015-09-17 02:52 - 00591360 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmsvc.dll
2015-10-01 05:13 - 2015-09-17 02:52 - 00570880 _____ (Microsoft Corporation) C:\WINDOWS\system32\MbaeApi.dll
2015-10-01 05:13 - 2015-09-17 02:51 - 01203712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Bluetooth.dll
2015-10-01 05:13 - 2015-09-17 02:51 - 01067520 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2015-10-01 05:13 - 2015-09-17 02:49 - 02740224 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2015-10-01 05:13 - 2015-09-17 02:49 - 01290240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Shell.dll
2015-10-01 05:13 - 2015-09-17 02:49 - 01010176 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXService.dll
2015-10-01 05:13 - 2015-09-17 02:48 - 02093056 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidsvc.dll
2015-10-01 05:13 - 2015-09-17 02:48 - 00517632 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationController.dll
2015-10-01 05:13 - 2015-09-17 02:48 - 00408064 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredProvDataModel.dll
2015-10-01 05:13 - 2015-09-17 02:48 - 00387584 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppBroker.dll
2015-10-01 05:13 - 2015-09-17 02:47 - 00513536 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngcsvc.dll
2015-10-01 05:13 - 2015-09-17 02:45 - 04791296 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2015-10-01 05:13 - 2015-09-17 02:45 - 01331200 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll
2015-10-01 05:13 - 2015-09-17 02:45 - 00869376 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlCore.dll
2015-10-01 05:13 - 2015-09-17 02:45 - 00627712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.dll
2015-10-01 05:13 - 2015-09-17 02:44 - 00526336 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll
2015-10-01 05:13 - 2015-09-17 02:43 - 01213440 _____ (Microsoft Corporation) C:\WINDOWS\system32\RemoteNaturalLanguage.dll
2015-10-01 05:13 - 2015-09-17 02:43 - 00378368 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemEventsBrokerServer.dll
2015-10-01 05:13 - 2015-09-17 02:42 - 02646528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
2015-10-01 05:13 - 2015-09-17 02:41 - 00217088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VEEventDispatcher.dll
2015-10-01 05:13 - 2015-09-17 02:40 - 01918464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
2015-10-01 05:13 - 2015-09-17 02:40 - 01162240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Speech.dll
2015-10-01 05:13 - 2015-09-17 02:39 - 00587264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll
2015-10-01 05:13 - 2015-09-17 02:38 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\usoapi.dll
2015-10-01 05:13 - 2015-09-17 02:37 - 00454656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MbaeApi.dll
2015-10-01 05:13 - 2015-09-17 02:35 - 02207232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2015-10-01 05:13 - 2015-09-17 02:35 - 01820160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Logon.dll
2015-10-01 05:13 - 2015-09-17 02:35 - 00828928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Bluetooth.dll
2015-10-01 05:13 - 2015-09-17 02:32 - 03579904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2015-10-01 05:13 - 2015-09-17 02:32 - 00336384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CredProvDataModel.dll
2015-10-01 05:13 - 2015-09-17 02:31 - 05454848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2015-10-01 05:13 - 2015-09-17 02:29 - 01104384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll
2015-10-01 05:13 - 2015-09-17 02:29 - 00677888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapControlCore.dll
2015-10-01 05:13 - 2015-09-17 02:26 - 00899584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RemoteNaturalLanguage.dll
2015-10-01 05:13 - 2015-09-17 02:16 - 00512000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll
2015-10-01 05:13 - 2015-09-12 23:05 - 02987520 _____ (Microsoft Corporation) C:\WINDOWS\system32\esent.dll
2015-10-01 05:13 - 2015-09-12 22:41 - 02639872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\esent.dll
2015-10-01 05:12 - 2015-09-24 21:35 - 00257024 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataAccountApis.dll
2015-10-01 05:12 - 2015-09-24 21:34 - 00223232 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneCallHistoryApis.dll
2015-10-01 05:12 - 2015-09-24 20:34 - 00195584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataAccountApis.dll
2015-10-01 05:12 - 2015-09-24 20:34 - 00172032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PhoneCallHistoryApis.dll
2015-10-01 05:12 - 2015-09-24 20:24 - 00796160 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll
2015-10-01 05:12 - 2015-09-24 20:24 - 00689152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll
2015-10-01 05:12 - 2015-09-24 20:23 - 00579072 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
2015-10-01 05:12 - 2015-09-24 20:07 - 01382400 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2015-10-01 05:12 - 2015-09-24 20:05 - 00288256 _____ (Microsoft Corporation) C:\WINDOWS\system32\PimIndexMaintenance.dll
2015-10-01 05:12 - 2015-09-24 20:01 - 00685568 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppointmentApis.dll
2015-10-01 05:12 - 2015-09-24 20:00 - 00752640 _____ (Microsoft Corporation) C:\WINDOWS\system32\ChatApis.dll
2015-10-01 05:12 - 2015-09-24 20:00 - 00720896 _____ (Microsoft Corporation) C:\WINDOWS\system32\EmailApis.dll
2015-10-01 05:12 - 2015-09-24 20:00 - 00163840 _____ (Microsoft Corporation) C:\WINDOWS\system32\CallHistoryClient.dll
2015-10-01 05:12 - 2015-09-24 19:53 - 00590336 _____ (Microsoft Corporation) C:\WINDOWS\system32\MessagingDataModel2.dll
2015-10-01 05:12 - 2015-09-24 19:43 - 00613376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll
2015-10-01 05:12 - 2015-09-24 19:43 - 00480256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Web.Core.dll
2015-10-01 05:12 - 2015-09-24 19:25 - 00579584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppointmentApis.dll
2015-10-01 05:12 - 2015-09-24 19:25 - 00557568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ChatApis.dll
2015-10-01 05:12 - 2015-09-24 19:25 - 00525312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EmailApis.dll
2015-10-01 05:12 - 2015-09-24 19:24 - 00131072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CallHistoryClient.dll
2015-10-01 05:12 - 2015-09-24 19:19 - 00466432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MessagingDataModel2.dll
2015-10-01 05:12 - 2015-09-19 02:14 - 00102304 _____ (Microsoft Corporation) C:\WINDOWS\system32\omadmapi.dll
2015-10-01 05:12 - 2015-09-17 03:50 - 00099664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pdc.sys
2015-10-01 05:12 - 2015-09-17 03:50 - 00088384 _____ (Microsoft Corporation) C:\WINDOWS\system32\remoteaudioendpoint.dll
2015-10-01 05:12 - 2015-09-17 03:49 - 00553808 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncHost.exe
2015-10-01 05:12 - 2015-09-17 03:49 - 00501008 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
2015-10-01 05:12 - 2015-09-17 03:48 - 00584656 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll
2015-10-01 05:12 - 2015-09-17 03:48 - 00516448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBHUB3.SYS
2015-10-01 05:12 - 2015-09-17 03:48 - 00505696 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2015-10-01 05:12 - 2015-09-17 03:48 - 00406864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\FWPKCLNT.SYS
2015-10-01 05:12 - 2015-09-17 03:48 - 00395088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2015-10-01 05:12 - 2015-09-17 03:48 - 00332624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fastfat.sys
2015-10-01 05:12 - 2015-09-17 03:48 - 00278352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys
2015-10-01 05:12 - 2015-09-17 03:48 - 00243760 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
2015-10-01 05:12 - 2015-09-17 03:39 - 00081488 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2015-10-01 05:12 - 2015-09-17 03:37 - 01168736 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys
2015-10-01 05:12 - 2015-09-17 03:28 - 00441168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncHost.exe
2015-10-01 05:12 - 2015-09-17 03:28 - 00407608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
2015-10-01 05:12 - 2015-09-17 03:28 - 00074880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\remoteaudioendpoint.dll
2015-10-01 05:12 - 2015-09-17 03:26 - 01895568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hevcdecoder.dll
2015-10-01 05:12 - 2015-09-17 03:26 - 00508248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf.dll
2015-10-01 05:12 - 2015-09-17 03:26 - 00434376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFCaptureEngine.dll
2015-10-01 05:12 - 2015-09-17 03:11 - 00160256 _____ (Microsoft Corporation) C:\WINDOWS\system32\enrollmentapi.dll
2015-10-01 05:12 - 2015-09-17 03:10 - 00169984 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmregistration.dll
2015-10-01 05:12 - 2015-09-17 03:09 - 00269312 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll
2015-10-01 05:12 - 2015-09-17 03:09 - 00143360 _____ (Microsoft Corporation) C:\WINDOWS\system32\provops.dll
2015-10-01 05:12 - 2015-09-17 03:08 - 00494592 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll
2015-10-01 05:12 - 2015-09-17 03:08 - 00053760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Speech.Pal.dll
2015-10-01 05:12 - 2015-09-17 03:08 - 00026624 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManagerShellext.exe
2015-10-01 05:12 - 2015-09-17 03:06 - 00690688 _____ (Microsoft Corporation) C:\WINDOWS\system32\CellularAPI.dll
2015-10-01 05:12 - 2015-09-17 03:06 - 00149504 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringservice.dll
2015-10-01 05:12 - 2015-09-17 03:05 - 00483328 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneDriveSettingSyncProvider.dll
2015-10-01 05:12 - 2015-09-17 03:04 - 00504320 _____ (Microsoft Corporation) C:\WINDOWS\system32\DataSenseHandlers.dll
2015-10-01 05:12 - 2015-09-17 03:03 - 00267776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Management.dll
2015-10-01 05:12 - 2015-09-17 03:03 - 00187904 _____ (Microsoft Corporation) C:\WINDOWS\system32\provisioningcsp.dll
2015-10-01 05:12 - 2015-09-17 03:03 - 00154624 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcertinst.exe
2015-10-01 05:12 - 2015-09-17 03:03 - 00088064 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngckeyenum.dll
2015-10-01 05:12 - 2015-09-17 03:03 - 00083968 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceEnroller.exe
2015-10-01 05:12 - 2015-09-17 03:02 - 00168960 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmmigrator.dll
2015-10-01 05:12 - 2015-09-17 03:02 - 00068096 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseDesktopAppMgmtCSP.dll
2015-10-01 05:12 - 2015-09-17 03:00 - 00446976 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapConfiguration.dll
2015-10-01 05:12 - 2015-09-17 03:00 - 00106496 _____ (Microsoft Corporation) C:\WINDOWS\system32\KeywordDetectorMsftSidAdapter.dll
2015-10-01 05:12 - 2015-09-17 02:57 - 00403456 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenrollengine.dll
2015-10-01 05:12 - 2015-09-17 02:57 - 00137728 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEStoreEventHandlers.dll
2015-10-01 05:12 - 2015-09-17 02:56 - 00521728 _____ (Microsoft Corporation) C:\WINDOWS\system32\PsmServiceExtHost.dll
2015-10-01 05:12 - 2015-09-17 02:56 - 00317440 _____ (Microsoft Corporation) C:\WINDOWS\system32\configmanager2.dll
2015-10-01 05:12 - 2015-09-17 02:55 - 00671232 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUDFx02000.dll
2015-10-01 05:12 - 2015-09-17 02:55 - 00366592 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll
2015-10-01 05:12 - 2015-09-17 02:55 - 00346112 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngccredprov.dll
2015-10-01 05:12 - 2015-09-17 02:55 - 00202240 _____ (Microsoft Corporation) C:\WINDOWS\system32\accountaccessor.dll
2015-10-01 05:12 - 2015-09-17 02:55 - 00121856 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcsps.dll
2015-10-01 05:12 - 2015-09-17 02:55 - 00120832 _____ (Microsoft Corporation) C:\WINDOWS\system32\omadmclient.exe
2015-10-01 05:12 - 2015-09-17 02:55 - 00073728 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwancfg.dll
2015-10-01 05:12 - 2015-09-17 02:54 - 00324096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2015-10-01 05:12 - 2015-09-17 02:52 - 06572032 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanmm.dll
2015-10-01 05:12 - 2015-09-17 02:52 - 01216512 _____ (Microsoft Corporation) C:\WINDOWS\system32\netcenter.dll
2015-10-01 05:12 - 2015-09-17 02:52 - 00856576 _____ (Microsoft Corporation) C:\WINDOWS\system32\MPSSVC.dll
2015-10-01 05:12 - 2015-09-17 02:52 - 00465920 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanconn.dll
2015-10-01 05:12 - 2015-09-17 02:52 - 00371712 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlasvc.dll
2015-10-01 05:12 - 2015-09-17 02:52 - 00204800 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmcsp.dll
2015-10-01 05:12 - 2015-09-17 02:52 - 00162304 _____ (Microsoft Corporation) C:\WINDOWS\system32\SubscriptionMgr.dll
2015-10-01 05:12 - 2015-09-17 02:51 - 01812480 _____ (Microsoft Corporation) C:\WINDOWS\system32\pnidui.dll
2015-10-01 05:12 - 2015-09-17 02:51 - 00359936 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncsi.dll
2015-10-01 05:12 - 2015-09-17 02:51 - 00145920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mdmregistration.dll
2015-10-01 05:12 - 2015-09-17 02:50 - 00421888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Bluetooth.dll
2015-10-01 05:12 - 2015-09-17 02:50 - 00320000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\portcls.sys
2015-10-01 05:12 - 2015-09-17 02:50 - 00312832 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsApi.dll
2015-10-01 05:12 - 2015-09-17 02:50 - 00221184 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationPeWiFi.dll
2015-10-01 05:12 - 2015-09-17 02:50 - 00204288 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationPeCell.dll
2015-10-01 05:12 - 2015-09-17 02:50 - 00036352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\buttonconverter.sys
2015-10-01 05:12 - 2015-09-17 02:49 - 00771072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2015-10-01 05:12 - 2015-09-17 02:49 - 00439296 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationWebproxy.dll
2015-10-01 05:12 - 2015-09-17 02:49 - 00342016 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationGeofences.dll
2015-10-01 05:12 - 2015-09-17 02:49 - 00268800 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationFramework.dll
2015-10-01 05:12 - 2015-09-17 02:49 - 00215552 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationCrowdsource.dll
2015-10-01 05:12 - 2015-09-17 02:49 - 00176640 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationPeIP.dll
2015-10-01 05:12 - 2015-09-17 02:49 - 00095744 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationWiFiAdapter.dll
2015-10-01 05:12 - 2015-09-17 02:49 - 00041472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Speech.Pal.dll
2015-10-01 05:12 - 2015-09-17 02:48 - 00347136 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncryptprov.dll
2015-10-01 05:12 - 2015-09-17 02:48 - 00273920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.LockScreen.dll
2015-10-01 05:12 - 2015-09-17 02:47 - 00371712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OneDriveSettingSyncProvider.dll
2015-10-01 05:12 - 2015-09-17 02:47 - 00186880 _____ (Microsoft Corporation) C:\WINDOWS\system32\cloudAP.dll
2015-10-01 05:12 - 2015-09-17 02:46 - 00928256 _____ (Microsoft Corporation) C:\WINDOWS\system32\JpMapControl.dll
2015-10-01 05:12 - 2015-09-17 02:46 - 00621056 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
2015-10-01 05:12 - 2015-09-17 02:46 - 00414208 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll
2015-10-01 05:12 - 2015-09-17 02:46 - 00224256 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCore.dll
2015-10-01 05:12 - 2015-09-17 02:46 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCsp.dll
2015-10-01 05:12 - 2015-09-17 02:46 - 00084480 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDMAppInstaller.exe
2015-10-01 05:12 - 2015-09-17 02:46 - 00079872 _____ (Microsoft Corporation) C:\WINDOWS\system32\HttpsDataSource.dll
2015-10-01 05:12 - 2015-09-17 02:46 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\syncmlhook.dll
2015-10-01 05:12 - 2015-09-17 02:45 - 00832512 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll
2015-10-01 05:12 - 2015-09-17 02:45 - 00193024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Management.dll
2015-10-01 05:12 - 2015-09-17 02:44 - 01844736 _____ (Microsoft Corporation) C:\WINDOWS\system32\workfolderssvc.dll
2015-10-01 05:12 - 2015-09-17 02:44 - 00599552 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnapps.dll
2015-10-01 05:12 - 2015-09-17 02:44 - 00274944 _____ (Microsoft Corporation) C:\WINDOWS\system32\syncutil.dll
2015-10-01 05:12 - 2015-09-17 02:43 - 00328704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapConfiguration.dll
2015-10-01 05:12 - 2015-09-17 02:43 - 00185344 _____ (Microsoft Corporation) C:\WINDOWS\system32\psmsrv.dll
2015-10-01 05:12 - 2015-09-17 02:39 - 00247808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2015-10-01 05:12 - 2015-09-17 02:36 - 01171456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netcenter.dll
2015-10-01 05:12 - 2015-09-17 02:34 - 00253440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsApi.dll
2015-10-01 05:12 - 2015-09-17 02:33 - 00574464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll
2015-10-01 05:12 - 2015-09-17 02:32 - 00313856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LockAppBroker.dll
2015-10-01 05:12 - 2015-09-17 02:32 - 00195072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.LockScreen.dll
2015-10-01 05:12 - 2015-09-17 02:31 - 00268800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ncryptprov.dll
2015-10-01 05:12 - 2015-09-17 02:30 - 00311808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll
2015-10-01 05:12 - 2015-09-17 02:29 - 00701952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\JpMapControl.dll
2015-10-01 05:12 - 2015-09-17 02:29 - 00464896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.dll
2015-10-01 05:12 - 2015-09-17 02:28 - 00473088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wpnapps.dll
2015-09-30 18:39 - 2015-09-30 18:39 - 00000683 _____ C:\Users\Anora\Downloads\transcript.txt
2015-09-30 18:03 - 2015-09-30 18:05 - 00001266 _____ C:\Users\Anora\Desktop\receapt.txt
2015-09-30 17:02 - 2015-09-30 17:06 - 00001271 _____ C:\Users\Anora\Desktop\Redme first.txt
2015-09-30 16:13 - 2015-10-02 18:22 - 00000000 ____D C:\server
2015-09-30 15:41 - 2015-10-02 19:35 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2015-09-29 22:54 - 2015-09-29 22:54 - 00000020 ___SH C:\Users\wildrenter\ntuser.ini
2015-09-29 22:54 - 2015-09-29 22:54 - 00000000 ____D C:\Users\wildrenter
2015-09-29 22:54 - 2015-08-20 09:27 - 00000000 ___RD C:\Users\wildrenter\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-09-29 22:54 - 2015-07-10 08:04 - 00000000 __RSD C:\Users\wildrenter\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell
2015-09-29 22:54 - 2015-07-10 08:04 - 00000000 ___RD C:\Users\wildrenter\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-09-29 22:54 - 2015-07-10 08:04 - 00000000 ___RD C:\Users\wildrenter\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2015-09-29 22:54 - 2015-07-10 08:04 - 00000000 ____D C:\Users\wildrenter\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-09-29 22:51 - 2015-09-29 22:51 - 04260481 _____ C:\Users\Anora\Downloads\Dynmap-2.2-forge-1.7.10.jar
2015-09-29 22:51 - 2015-09-29 22:51 - 04109948 _____ C:\Users\Anora\Downloads\Dynmap-2.2-forge-1.8.0.jar
2015-09-29 20:43 - 2015-09-29 20:43 - 00236479 _____ C:\Users\Anora\Downloads\additionalpipes-4.6.1.jar
2015-09-29 18:05 - 2015-09-30 16:51 - 00000000 ____D C:\Users\Anora\AppData\Roaming\OBS
2015-09-29 18:05 - 2015-09-29 18:51 - 00001004 _____ C:\Users\Anora\Desktop\Open Broadcaster Software.lnk
2015-09-29 18:05 - 2015-09-29 18:05 - 00000000 ____D C:\Users\Anora\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Open Broadcaster Software
2015-09-29 18:05 - 2015-09-29 18:05 - 00000000 ____D C:\Program Files\OBS
2015-09-29 18:05 - 2015-09-29 18:05 - 00000000 ____D C:\Program Files (x86)\OBS
2015-09-29 18:04 - 2015-09-29 18:05 - 07420880 _____ C:\Users\Anora\Downloads\OBS_0_655b_Installer.exe
2015-09-28 21:27 - 2015-09-28 21:28 - 00158100 _____ C:\Users\Anora\Downloads\ironchest-1.7.10-6.0.60.741-universal.jar
2015-09-28 21:24 - 2015-09-28 21:24 - 00145782 _____ C:\Users\Anora\Downloads\CodeChickenCore-1.7.10-1.0.7.47-universal.jar
2015-09-28 21:24 - 2015-09-28 21:24 - 00106701 _____ C:\Users\Anora\Downloads\ChickenChunks-1.7.10-1.3.4.19-universal.jar
2015-09-28 21:23 - 2015-09-28 21:23 - 00145063 _____ C:\Users\Anora\Downloads\EnderStorage-1.7.10-1.4.7.37-universal.jar
2015-09-28 21:22 - 2015-09-28 21:22 - 00160161 _____ C:\Users\Anora\Downloads\Translocator-1.7.10-1.1.2.15-universal.jar
2015-09-28 21:20 - 2015-09-28 21:20 - 00513018 _____ C:\Users\Anora\Downloads\NotEnoughItems-1.7.10-1.0.5.118-universal.jar
2015-09-28 21:18 - 2015-09-28 21:19 - 00164873 _____ C:\Users\Anora\Downloads\ironchest-1.8-6.0.99.749-universal.jar
2015-09-28 21:17 - 2015-09-28 21:17 - 00440712 _____ C:\Users\Anora\Downloads\Jabba-1.2.1a_1.7.10.jar
2015-09-28 21:15 - 2015-09-28 21:15 - 00544821 _____ C:\Users\Anora\Downloads\Waila-1.5.10_1.7.10.jar
2015-09-28 19:57 - 2015-09-28 19:57 - 00000215 _____ C:\Users\Anora\Desktop\Problem loading page.URL
2015-09-28 08:09 - 2015-09-28 08:09 - 00000000 _____ C:\WINDOWS\setupact.log
2015-09-27 19:44 - 2015-09-27 19:44 - 00011262 _____ C:\Users\Anora\Documents\hijackthis.log
2015-09-27 19:38 - 2015-09-27 19:38 - 00388608 _____ (Trend Micro Inc.) C:\Users\Anora\Downloads\HijackThis.exe
2015-09-27 19:18 - 2015-09-27 19:18 - 07424696 _____ C:\Users\Anora\Downloads\spybotsd_includes(1).exe
2015-09-27 17:48 - 2015-09-27 17:49 - 07424696 _____ C:\Users\Anora\Downloads\spybotsd_includes.exe
2015-09-25 17:26 - 2009-06-10 18:00 - 00000824 _____ C:\WINDOWS\system32\Drivers\etc\hosts.20150925-172615.backup
2015-09-25 17:16 - 2015-10-05 10:33 - 00113880 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-09-25 17:15 - 2015-09-27 20:23 - 00001171 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-09-25 17:15 - 2015-09-27 20:23 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-09-25 17:15 - 2015-09-27 20:23 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-09-25 17:15 - 2015-09-25 17:15 - 00000000 ____D C:\ProgramData\Malwarebytes
2015-09-25 17:15 - 2015-06-18 09:48 - 00064216 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
2015-09-25 17:15 - 2015-06-18 09:47 - 00109272 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2015-09-25 17:15 - 2015-06-18 09:47 - 00025816 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2015-09-25 17:14 - 2015-09-27 19:00 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2015-09-25 17:14 - 2015-09-25 17:45 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
2015-09-25 17:14 - 2015-09-25 17:14 - 00001460 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk
2015-09-25 17:14 - 2015-09-25 17:14 - 00001448 _____ C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
2015-09-25 17:14 - 2015-09-25 17:14 - 00000000 ____D C:\WINDOWS\System32\Tasks\Safer-Networking
2015-09-25 17:14 - 2015-09-25 17:14 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
2015-09-25 17:14 - 2013-09-20 10:49 - 00021040 _____ (Safer Networking Limited) C:\WINDOWS\system32\sdnclean64.exe
2015-09-25 17:12 - 2015-09-25 17:15 - 21545336 _____ (Malwarebytes Corporation ) C:\Users\Anora\Downloads\mbam-setup-sem-2.1.6.1022.exe
2015-09-25 17:12 - 2015-09-25 17:13 - 46525608 _____ (Safer-Networking Ltd. ) C:\Users\Anora\Downloads\spybot-2.4.exe
2015-09-25 17:12 - 2015-09-25 17:12 - 21545336 _____ (Malwarebytes Corporation ) C:\Users\Anora\Downloads\mbam-setup-sem-2.1.6.1022(1).exe
2015-09-25 17:10 - 2015-09-25 17:10 - 00000000 ____D C:\Users\Anora\AppData\Roaming\AVAST Software
2015-09-25 17:07 - 2015-09-25 17:07 - 00001927 _____ C:\Users\Public\Desktop\Avast Free Antivirus.lnk
2015-09-25 17:07 - 2015-09-25 17:07 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
2015-09-25 17:06 - 2015-09-28 08:08 - 00004280 _____ C:\WINDOWS\System32\Tasks\avast! Emergency Update
2015-09-25 17:06 - 2015-09-25 17:06 - 00448968 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSP.sys
2015-09-25 17:06 - 2015-09-25 17:06 - 00378880 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe
2015-09-25 17:06 - 2015-09-25 17:06 - 00274808 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswVmm.sys
2015-09-25 17:06 - 2015-09-25 17:06 - 00153744 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswStm.sys
2015-09-25 17:06 - 2015-09-25 17:06 - 00093528 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr2.sys
2015-09-25 17:06 - 2015-09-25 17:06 - 00090968 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys
2015-09-25 17:06 - 2015-09-25 17:06 - 00065224 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRvrt.sys
2015-09-25 17:06 - 2015-09-25 17:06 - 00043112 _____ (AVAST Software) C:\WINDOWS\avastSS.scr
2015-09-25 17:06 - 2015-09-25 17:06 - 00028656 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswHwid.sys
2015-09-25 17:06 - 2015-09-25 17:05 - 01049880 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSnx.sys
2015-09-25 17:05 - 2015-09-25 17:05 - 00000000 ____D C:\Program Files\AVAST Software
2015-09-25 17:02 - 2015-09-25 17:02 - 00000000 ____D C:\ProgramData\AVAST Software
2015-09-25 17:01 - 2015-09-25 17:02 - 05500000 _____ (Avast Software s.r.o.) C:\Users\Anora\Downloads\avast_free_antivirus_setup_online.exe
2015-09-25 16:14 - 2015-09-25 16:18 - 00116959 _____ C:\Users\Anora\Downloads\fastcraft-1.21.jar
2015-09-25 15:55 - 2015-09-25 15:55 - 00000925 _____ C:\Users\Anora\Desktop\MultiMC.lnk
2015-09-25 09:43 - 2015-10-02 19:11 - 00000000 ____D C:\WINDOWS\system32\appmgmt
2015-09-22 07:51 - 2015-09-22 07:51 - 18819272 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerInstaller.exe
2015-09-20 14:40 - 2015-09-20 14:40 - 00891845 _____ C:\Users\Anora\Downloads\natura-1.7.10-2.2.0.1.jar
2015-09-20 13:25 - 2015-09-20 13:25 - 00182350 _____ C:\Users\Anora\Downloads\Reis-Minimap-Mod-1.7.10.jar
2015-09-20 13:22 - 2015-09-20 13:22 - 00094792 _____ C:\Users\Anora\Downloads\[1.7.10]Treecapitator-universal-2.0.4.jar
2015-09-20 13:21 - 2015-09-20 13:21 - 00099264 _____ C:\Users\Anora\Downloads\[1.8]Treecapitator-universal-2.0.5.jar
2015-09-20 13:20 - 2015-09-20 13:20 - 00198525 _____ C:\Users\Anora\Downloads\[1.7.10]bspkrsCore-universal-6.16.jar
2015-09-20 13:20 - 2015-09-20 13:20 - 00063133 _____ C:\Users\Anora\Downloads\[1.8]bspkrsCore-universal-7.01.jar
2015-09-20 12:37 - 2015-09-20 12:37 - 00150110 _____ C:\Users\Anora\Downloads\fpsplus.zip
2015-09-20 12:36 - 2015-09-20 12:36 - 00868722 _____ C:\Users\Anora\Downloads\OptiFine_1.7.10_HD_C1.jar
2015-09-20 12:23 - 2015-09-20 12:23 - 02180152 _____ C:\Users\Anora\Downloads\ThermalFoundation-[1.7.10]1.2.0-102(1).jar
2015-09-20 12:21 - 2015-09-20 12:21 - 00158708 _____ C:\Users\Anora\Downloads\iChunUtil-4.0.0.jar
2015-09-20 12:20 - 2015-09-20 12:20 - 00390664 _____ C:\Users\Anora\Downloads\iChunUtil-5.4.0.jar
2015-09-20 12:18 - 2015-09-20 12:18 - 00049712 _____ C:\Users\Anora\Downloads\MetallurgyCore-1.7.10-4.0.4.18.jar
2015-09-20 12:15 - 2015-09-20 12:15 - 01482797 _____ C:\Users\Anora\Downloads\bdlib-1.9.2.104-mc1.7.10.jar
2015-09-20 12:03 - 2015-09-20 12:03 - 00501229 _____ C:\Users\Anora\Downloads\ae2stuff-0.5.0.56-mc1.7.10.jar
2015-09-20 12:01 - 2015-09-20 12:01 - 01719328 _____ C:\Users\Anora\Downloads\MineFactoryReloaded-[1.7.10]2.8.0-104(1).jar
2015-09-20 12:01 - 2015-09-20 12:01 - 01228305 _____ C:\Users\Anora\Downloads\thaumicenergistics-0.8.10.10.jar
2015-09-20 11:59 - 2015-09-20 11:59 - 01020024 _____ C:\Users\Anora\Downloads\OpenPeripheral-1.7.10-AIO-5.jar
2015-09-20 11:59 - 2015-09-20 11:59 - 00862338 _____ C:\Users\Anora\Downloads\OpenModsLib-1.7.10-0.8.jar
2015-09-20 11:56 - 2015-09-20 11:56 - 01397898 _____ C:\Users\Anora\Downloads\ComputerCraft1.74.jar
2015-09-20 11:54 - 2015-09-20 11:54 - 05725609 _____ C:\Users\Anora\Downloads\BiomesOPlenty-1.7.10-2.1.0.1396-universal.jar
2015-09-20 11:53 - 2015-09-20 11:53 - 00351928 _____ C:\Users\Anora\Downloads\EnderZoo-1.7.10-1.0.15.32.jar
2015-09-20 11:52 - 2015-09-20 11:52 - 00221921 _____ C:\Users\Anora\Downloads\InventoryTweaks-1.58-147.jar
2015-09-20 11:51 - 2015-09-20 11:51 - 00225817 _____ C:\Users\Anora\Downloads\InventoryTweaks-1.59-176.jar
2015-09-20 11:49 - 2015-09-20 11:49 - 04066035 _____ C:\Users\Anora\Downloads\EnderIO-1.7.10-2.2.8.381.jar
2015-09-20 11:48 - 2015-09-20 11:48 - 00265023 _____ C:\Users\Anora\Downloads\ABO-MC1.7.10-BC7-release3.0.2.jar
2015-09-20 11:47 - 2015-09-20 11:47 - 03190760 _____ C:\Users\Anora\Downloads\logisticspipes-0.9.2.48.jar
2015-09-20 11:41 - 2015-09-20 11:42 - 02141043 _____ C:\Users\Anora\Downloads\ThaumicTinkerer-2.5-1.7.10-164.jar
2015-09-20 11:40 - 2015-09-20 11:40 - 12565807 _____ C:\Users\Anora\Downloads\Thaumcraft-1.7.10-4.2.3.5.jar
2015-09-20 11:37 - 2015-09-20 11:37 - 01039858 _____ C:\Users\Anora\Downloads\Morph-Beta-0.9.2.jar
2015-09-20 11:34 - 2015-09-20 11:34 - 02207842 _____ C:\Users\Anora\Downloads\mystcraft-1.7.10-0.12.3.00.jar
2015-09-20 11:31 - 2015-09-20 11:31 - 02110837 _____ C:\Users\Anora\Downloads\extrautilities-1.2.11.jar
2015-09-20 11:29 - 2015-09-20 11:29 - 11151826 _____ C:\Users\Anora\Downloads\ExtraTiC-1.7.10-1.4.5.jar
2015-09-20 11:28 - 2015-09-20 11:28 - 05529579 _____ C:\Users\Anora\Downloads\TConstruct-1.7.10-1.8.7.jar
2015-09-20 11:28 - 2015-09-20 11:28 - 00200413 _____ C:\Users\Anora\Downloads\Mantle-1.7.10-0.3.2a.jar
2015-09-20 11:25 - 2015-09-20 11:26 - 01529588 _____ C:\Users\Anora\Downloads\Metallurgy-1.7.10-4.0.6.80.jar
2015-09-20 11:24 - 2015-09-20 11:25 - 00462208 _____ C:\Users\Anora\Downloads\ThermalDynamics-[1.7.10]1.1.0-161.jar
2015-09-20 11:24 - 2015-09-20 11:25 - 00079555 _____ C:\Users\Anora\Downloads\NetherOres-[1.7.10]2.3.0-12.jar
2015-09-20 11:24 - 2015-09-20 11:24 - 02384406 _____ C:\Users\Anora\Downloads\ThermalExpansion-[1.7.10]4.0.3B1-218.jar
2015-09-20 11:24 - 2015-09-20 11:24 - 01719328 _____ C:\Users\Anora\Downloads\MineFactoryReloaded-[1.7.10]2.8.0-104.jar
2015-09-20 11:23 - 2015-09-20 11:24 - 02180152 _____ C:\Users\Anora\Downloads\ThermalFoundation-[1.7.10]1.2.0-102.jar
2015-09-20 11:23 - 2015-09-20 11:23 - 01068485 _____ C:\Users\Anora\Downloads\CoFHCore-[1.7.10]3.0.3-303.jar
2015-09-20 11:16 - 2015-09-20 11:16 - 00352856 _____ C:\Users\Anora\Downloads\WR-CBE-1.7.10-1.4.1.9-universal.jar
2015-09-20 11:15 - 2015-09-20 11:16 - 03682125 _____ C:\Users\Anora\Downloads\twilightforest-1.7.10-2.3.7.jar
2015-09-20 11:15 - 2015-09-20 11:15 - 00507333 _____ C:\Users\Anora\Downloads\NotEnoughItems-1.7.10-1.0.3.74-universal.jar
2015-09-20 11:15 - 2015-09-20 11:15 - 00160155 _____ C:\Users\Anora\Downloads\Translocator-1.7.10-1.1.1.14-universal.jar
2015-09-20 11:14 - 2015-09-20 11:14 - 00157678 _____ C:\Users\Anora\Downloads\CodeChickenCore-1.7.10-1.0.4.29-universal.jar
2015-09-20 11:14 - 2015-09-20 11:14 - 00143274 _____ C:\Users\Anora\Downloads\EnderStorage-1.7.10-1.4.5.27-universal.jar
2015-09-20 11:14 - 2015-09-20 11:14 - 00105665 _____ C:\Users\Anora\Downloads\ChickenChunks-1.7.10-1.3.4.16-universal.jar
2015-09-20 11:13 - 2015-09-20 11:13 - 00510432 _____ C:\Users\Anora\Downloads\NotEnoughItems-1.8-1.0.5.82-universal.jar
2015-09-20 11:13 - 2015-09-20 11:13 - 00433012 _____ C:\Users\Anora\Downloads\CodeChickenCore-1.8-1.0.5.34-universal.jar
2015-09-20 11:11 - 2015-09-20 11:11 - 00386789 _____ C:\Users\Anora\Downloads\ForgeRelocation-0.0.1.4-universal.jar
2015-09-20 11:11 - 2015-09-20 11:11 - 00025361 _____ C:\Users\Anora\Downloads\ForgeRelocationFMP-0.0.1.2-universal.jar
2015-09-20 11:10 - 2015-09-20 11:10 - 00632050 _____ C:\Users\Anora\Downloads\ProjectRed-1.7.10-4.7.0pre9.92-Lighting.jar
2015-09-20 11:10 - 2015-09-20 11:10 - 00472590 _____ C:\Users\Anora\Downloads\ProjectRed-1.7.10-4.7.0pre9.92-World.jar
2015-09-20 11:10 - 2015-09-20 11:10 - 00083858 _____ C:\Users\Anora\Downloads\ProjectRed-1.7.10-4.7.0pre9.92-Compat.jar
2015-09-20 11:09 - 2015-09-20 11:10 - 02088848 _____ C:\Users\Anora\Downloads\ProjectRed-1.7.10-4.7.0pre9.92-Mechanical.jar
2015-09-20 11:09 - 2015-09-20 11:09 - 03912822 _____ C:\Users\Anora\Downloads\ProjectRed-1.7.10-4.7.0pre9.92-Integration.jar
2015-09-20 11:09 - 2015-09-20 11:09 - 01654363 _____ C:\Users\Anora\Downloads\ProjectRed-1.7.10-4.7.0pre9.92-Fabrication.jar
2015-09-20 11:08 - 2015-09-20 11:08 - 01420057 _____ C:\Users\Anora\Downloads\ProjectRed-1.7.10-4.7.0pre9.92-Base.jar
2015-09-20 11:07 - 2015-09-20 11:07 - 00750651 _____ C:\Users\Anora\Downloads\MrTJPCore-1.1.0.31-universal.jar
2015-09-20 11:05 - 2015-09-20 11:05 - 02526302 _____ C:\Users\Anora\Downloads\appliedenergistics2-rv2-stable-10.jar
2015-09-20 11:05 - 2015-09-20 11:05 - 00694287 _____ C:\Users\Anora\Downloads\StevesFactoryManagerA93.jar
2015-09-20 11:01 - 2015-09-20 11:01 - 03165700 _____ C:\Users\Anora\Downloads\forestry_1.7.10-3.6.6.24.jar
2015-09-20 11:00 - 2015-09-20 11:00 - 03679674 _____ C:\Users\Anora\Downloads\Railcraft_1.7.10-9.7.0.0.jar
2015-09-20 10:59 - 2015-09-20 10:59 - 00218789 _____ C:\Users\Anora\Downloads\buildcraft-compat-7.0.12.jar
2015-09-20 10:58 - 2015-09-20 10:59 - 02487585 _____ C:\Users\Anora\Downloads\buildcraft-7.0.23.jar
2015-09-19 20:57 - 2012-01-23 13:02 - 00008810 _____ C:\Users\Anora\Desktop\relnotes.txt
2015-09-19 20:31 - 2015-09-19 20:31 - 00004324 _____ C:\Users\Anora\Downloads\PMAR-8PAG5T_R0_EN.zip
2015-09-19 20:29 - 2015-09-19 20:29 - 00000276 _____ C:\Users\Anora\Documents\PowerChute Technical Data.txt
2015-09-19 20:18 - 2015-09-19 20:18 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\APC
2015-09-19 20:18 - 2015-09-19 20:18 - 00000000 ____D C:\Program Files (x86)\APC
2015-09-19 20:17 - 2015-09-19 20:17 - 15922552 _____ (Schneider Electric) C:\Users\Anora\Downloads\PCPEInstaller.exe
2015-09-19 20:17 - 2015-09-19 20:17 - 13923704 _____ (Schneider Electric) C:\Users\Anora\PCPE Setup.exe
2015-09-19 20:17 - 2015-09-19 20:17 - 13338112 _____ C:\Users\Anora\PCPE_3.0.1.msi
2015-09-19 20:17 - 2015-09-19 20:17 - 01079808 _____ (Microsoft Corporation) C:\Users\Anora\mfc80u.dll
2015-09-19 20:17 - 2015-09-19 20:17 - 00626688 _____ (Microsoft Corporation) C:\Users\Anora\msvcr80.dll
2015-09-19 20:17 - 2015-09-19 20:17 - 00021880 _____ (Schneider Electric) C:\Users\Anora\grm_res.dll
2015-09-19 20:17 - 2015-09-19 20:17 - 00021880 _____ (Schneider Electric) C:\Users\Anora\fr_res.dll
2015-09-19 20:17 - 2015-09-19 20:17 - 00021368 _____ (Schneider Electric) C:\Users\Anora\pt_res.dll
2015-09-19 20:17 - 2015-09-19 20:17 - 00021368 _____ (Schneider Electric) C:\Users\Anora\it_res.dll
2015-09-19 20:17 - 2015-09-19 20:17 - 00021368 _____ (Schneider Electric) C:\Users\Anora\es_res.dll
2015-09-19 20:17 - 2015-09-19 20:17 - 00021368 _____ (Schneider Electric) C:\Users\Anora\en_res.dll
2015-09-19 20:17 - 2015-09-19 20:17 - 00020856 _____ (Schneider Electric) C:\Users\Anora\ru_res.dll
2015-09-19 20:17 - 2015-09-19 20:17 - 00020344 _____ (Schneider Electric) C:\Users\Anora\jp_res.dll
2015-09-19 20:17 - 2015-09-19 20:17 - 00019832 _____ (Schneider Electric) C:\Users\Anora\zh_res.dll
2015-09-19 20:17 - 2015-09-19 20:17 - 00018808 _____ C:\Users\Anora\ResourceReader.dll
2015-09-19 20:17 - 2015-09-19 20:17 - 00000550 _____ C:\Users\Anora\Microsoft.VC80.MFC.manifest
2015-09-19 20:17 - 2015-09-19 20:17 - 00000522 _____ C:\Users\Anora\Microsoft.VC80.CRT.manifest
2015-09-19 20:17 - 2015-09-19 20:17 - 00000024 _____ C:\Users\Anora\dotnetfolder.txt
2015-09-19 16:59 - 2015-09-19 17:01 - 114675363 _____ C:\Users\Anora\Downloads\Borderlands.zip
2015-09-18 20:08 - 2015-09-18 20:08 - 00000000 ____D C:\ProgramData\ATI
2015-09-18 15:56 - 2015-09-18 15:56 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
2015-09-18 15:49 - 2015-09-18 15:57 - 00000000 ____D C:\Users\Anora\AppData\Roaming\Apple Computer
2015-09-18 15:49 - 2015-09-18 15:49 - 00001782 _____ C:\Users\Public\Desktop\iTunes.lnk
2015-09-18 15:49 - 2015-09-18 15:49 - 00000000 ____D C:\Users\Anora\AppData\Local\Apple Computer
2015-09-18 15:49 - 2015-09-18 15:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2015-09-18 15:47 - 2015-09-18 15:49 - 00000000 ____D C:\Program Files\iTunes
2015-09-18 15:47 - 2015-09-18 15:47 - 00000000 ____D C:\ProgramData\Apple Computer
2015-09-18 15:47 - 2015-09-18 15:47 - 00000000 ____D C:\Program Files\iPod
2015-09-18 15:47 - 2015-09-18 15:47 - 00000000 ____D C:\Program Files (x86)\iTunes
2015-09-18 15:46 - 2015-09-18 15:46 - 00002535 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
2015-09-18 15:46 - 2015-09-18 15:46 - 00000000 ____D C:\WINDOWS\System32\Tasks\Apple
2015-09-18 15:46 - 2015-09-18 15:46 - 00000000 ____D C:\Users\Anora\AppData\Local\Apple
2015-09-18 15:46 - 2015-09-18 15:46 - 00000000 ____D C:\Program Files (x86)\Apple Software Update
2015-09-18 15:45 - 2015-09-18 15:46 - 00000000 ____D C:\ProgramData\Apple
2015-09-18 15:45 - 2015-09-18 15:46 - 00000000 ____D C:\Program Files\Common Files\Apple
2015-09-18 15:45 - 2015-09-18 15:45 - 00000000 ____D C:\Program Files\Bonjour
2015-09-18 15:45 - 2015-09-18 15:45 - 00000000 ____D C:\Program Files (x86)\Bonjour
2015-09-18 15:41 - 2015-09-18 15:44 - 167601944 _____ (Apple Inc.) C:\Users\Anora\Downloads\iTunes6464Setup.exe
2015-09-15 23:24 - 2015-09-18 19:49 - 00000000 ____D C:\pq
2015-09-15 23:19 - 2015-09-15 23:24 - 00320319 _____ C:\Users\Anora\Downloads\pq6-2.zip
2015-09-15 16:39 - 2015-09-15 16:39 - 01031608 _____ (CyberLink) C:\Users\Anora\Downloads\CyberLink_PowerDVD_Downloader.exe
2015-09-15 16:13 - 2015-09-15 16:13 - 00000506 _____ C:\Users\Anora\Downloads\new 1.txt
2015-09-14 23:02 - 2015-09-14 23:02 - 00469807 _____ C:\Users\Anora\Downloads\Super Smash Brothers_ Disharmony.txt
2015-09-14 22:56 - 2015-09-14 23:00 - 42827912 _____ ( ) C:\Users\Anora\Downloads\BD_3DAdvisor_7510_Generic_BD_CDT140213-01.exe
2015-09-14 21:26 - 2015-09-25 09:32 - 00000000 ____D C:\Users\Anora\AppData\Roaming\Raptr
2015-09-14 21:26 - 2015-09-25 09:32 - 00000000 ____D C:\Program Files (x86)\Raptr
2015-09-14 21:26 - 2015-09-14 21:26 - 00058661 _____ C:\WINDOWS\SysWOW64\CCCInstall_201509142126330631.log
2015-09-14 21:26 - 2015-09-14 21:26 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center
2015-09-14 21:17 - 2015-09-14 21:17 - 00061037 _____ C:\WINDOWS\SysWOW64\CCCInstall_201509142117299777.log
2015-09-14 21:08 - 2015-09-14 21:12 - 313171288 _____ (AMD Inc.) C:\Users\Anora\Downloads\amd-catalyst-15.8beta-64bit-win10-win8.1-win7-aug23.exe
2015-09-14 20:55 - 2015-09-14 20:55 - 00000000 ____D C:\Users\Anora\Documents\BioWare
2015-09-14 07:45 - 2015-09-14 07:45 - 00669184 _____ C:\WINDOWS\SysWOW64\pbsvc.exe
2015-09-14 07:45 - 2015-09-14 07:45 - 00103736 _____ C:\WINDOWS\SysWOW64\PnkBstrB.exe
2015-09-14 07:45 - 2015-09-14 07:45 - 00066872 _____ C:\WINDOWS\SysWOW64\PnkBstrA.exe
2015-09-13 23:03 - 2015-09-13 23:04 - 00000000 ____D C:\Users\Anora\Documents\My Spore Creations
2015-09-13 23:03 - 2015-09-13 23:04 - 00000000 ____D C:\Users\Anora\AppData\Roaming\SPORE
2015-09-13 23:01 - 2015-09-13 23:01 - 00000000 __RHD C:\Users\Anora\AppData\Roaming\SecuROM
2015-09-13 22:15 - 2015-09-13 22:15 - 00000000 ____D C:\Users\Anora\Documents\Respawn
2015-09-13 21:14 - 2015-10-03 08:51 - 00000000 ____D C:\ProgramData\Origin
2015-09-13 21:14 - 2015-09-13 21:14 - 00000749 _____ C:\Users\Public\Desktop\Origin.lnk
2015-09-13 21:13 - 2015-09-13 21:13 - 17113896 _____ (Electronic Arts, Inc.) C:\Users\Anora\Downloads\OriginThinSetup.exe
2015-09-13 21:10 - 2015-09-13 21:10 - 295536398 _____ C:\Users\Anora\Documents\backup.reg
2015-09-13 19:35 - 2015-09-13 21:14 - 00000000 ____D C:\ProgramData\Electronic Arts
2015-09-13 19:35 - 2015-09-13 19:35 - 00000000 ____D C:\Users\Anora\Documents\SimCity
2015-09-13 19:11 - 2015-09-13 22:15 - 00000000 ____D C:\Users\Anora\AppData\Local\Origin
2015-09-13 19:11 - 2015-09-13 21:15 - 00000000 ____D C:\Users\Anora\AppData\Roaming\Origin
2015-09-13 10:48 - 2015-09-13 10:48 - 01042908 _____ C:\Users\Anora\Downloads\PSP File Manager & Extractor (1.2).zip
2015-09-12 16:12 - 2015-09-12 16:15 - 00042910 _____ C:\Users\Public\Desktop\CyberLink PowerDVD 15.0.zip
2015-09-10 19:51 - 2015-09-10 20:23 - 00000000 ____D C:\Users\Anora\AppData\Local\Warframe
2015-09-10 18:20 - 2015-09-10 18:20 - 00000000 ____D C:\Users\Anora\AppData\Local\BANDAI NAMCO Games
2015-09-10 07:38 - 2015-09-10 07:38 - 00000000 ____D C:\Users\Anora\AppData\Local\NeatoUpgrader
2015-09-10 07:38 - 2015-09-10 07:38 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Neato Updater Tool v2
2015-09-10 07:38 - 2015-09-10 07:38 - 00000000 ____D C:\Program Files\DIFX
2015-09-10 07:38 - 2015-09-10 07:38 - 00000000 ____D C:\Program Files (x86)\Neato Robotics
2015-09-10 07:36 - 2015-09-10 07:37 - 02070016 _____ (Neato Robotics, Inc) C:\Users\Anora\Downloads\NeatoUpdaterToolInstaller_x64.exe
2015-09-08 20:31 - 2015-08-27 03:36 - 03620736 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2015-09-08 20:31 - 2015-08-27 03:32 - 00608936 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2015-09-08 20:31 - 2015-08-27 02:59 - 02880032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2015-09-08 20:31 - 2015-08-27 02:54 - 00541248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2015-09-08 20:31 - 2015-08-27 02:54 - 00365568 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
2015-09-08 20:31 - 2015-08-27 02:51 - 02350592 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll
2015-09-08 20:31 - 2015-08-27 02:51 - 01774592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Immersive.dll
2015-09-08 20:31 - 2015-08-27 02:49 - 01008640 _____ (Microsoft Corporation) C:\WINDOWS\system32\schedsvc.dll
2015-09-08 20:31 - 2015-08-27 02:47 - 12503552 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2015-09-08 20:31 - 2015-08-27 02:43 - 00826880 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2015-09-08 20:31 - 2015-08-27 02:43 - 00576000 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2015-09-08 20:31 - 2015-08-27 02:42 - 00596480 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSync.dll
2015-09-08 20:31 - 2015-08-27 02:42 - 00187904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.PicturePassword.dll
2015-09-08 20:31 - 2015-08-27 02:42 - 00184320 _____ (Microsoft Corporation) C:\WINDOWS\system32\shacct.dll
2015-09-08 20:31 - 2015-08-27 02:39 - 00045568 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2015-09-08 20:31 - 2015-08-27 02:23 - 00303104 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
2015-09-08 20:31 - 2015-08-27 02:16 - 02153472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll
2015-09-08 20:31 - 2015-08-27 02:16 - 01612288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Immersive.dll
2015-09-08 20:31 - 2015-08-27 02:12 - 00650752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2015-09-08 20:31 - 2015-08-27 02:12 - 00504320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2015-09-08 20:31 - 2015-08-27 02:11 - 00484352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSync.dll
2015-09-08 20:31 - 2015-08-27 02:11 - 00139776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shacct.dll
2015-09-08 20:31 - 2015-08-27 02:09 - 11262464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2015-09-08 20:31 - 2015-08-27 02:08 - 00037376 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
2015-09-08 17:03 - 2015-09-08 17:03 - 00000000 ____D C:\Users\Anora\Desktop\Old Firefox Data
2015-09-07 09:10 - 2015-09-07 09:10 - 00090668 _____ C:\Users\Anora\Downloads\A Different Perspective ( 18 - Chapter 18_ Ascendancy ).txt
2015-09-06 23:55 - 2015-09-06 23:55 - 00000000 ___RD C:\Users\Anora\3D Objects
2015-09-06 23:54 - 2015-09-06 23:54 - 24834448 _____ (ReviverSoft) C:\Users\Anora\Downloads\PCReviverSetup-SpeedTest.exe
2015-09-06 23:41 - 2015-09-06 23:41 - 00000000 ____D C:\Users\Anora\Documents\MPC-HC Capture
2015-09-06 23:40 - 2015-09-06 23:40 - 00000000 ____D C:\Users\Anora\AppData\Roaming\MPC-HC
2015-09-06 23:37 - 2015-09-10 07:44 - 00002856 _____ C:\WINDOWS\SysWOW64\LavasoftTcpServiceOff.ini
2015-09-06 23:37 - 2015-09-10 07:44 - 00002856 _____ C:\WINDOWS\system32\LavasoftTcpServiceOff.ini
2015-09-06 23:37 - 2015-09-06 23:37 - 00425744 _____ (Lavasoft Limited) C:\WINDOWS\system32\LavasoftTcpService64.dll
2015-09-06 23:37 - 2015-09-06 23:37 - 00345360 _____ (Lavasoft Limited) C:\WINDOWS\SysWOW64\LavasoftTcpService.dll
2015-09-06 23:36 - 2015-09-06 23:36 - 00003008 _____ C:\WINDOWS\System32\Tasks\klcp_update
2015-09-06 23:36 - 2015-09-06 23:36 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack
2015-09-06 23:36 - 2015-09-06 23:36 - 00000000 ____D C:\Program Files (x86)\K-Lite Codec Pack
2015-09-06 23:36 - 2015-08-24 15:00 - 00112128 _____ C:\WINDOWS\SysWOW64\ff_vfw.dll
2015-09-06 23:36 - 2015-06-22 10:25 - 00254976 _____ C:\WINDOWS\system32\xvidvfw.dll
2015-09-06 23:36 - 2015-06-22 10:25 - 00240128 _____ C:\WINDOWS\SysWOW64\xvidvfw.dll
2015-09-06 23:36 - 2015-06-22 10:24 - 00729088 _____ C:\WINDOWS\system32\xvidcore.dll
2015-09-06 23:36 - 2015-06-22 10:24 - 00655872 _____ C:\WINDOWS\SysWOW64\xvidcore.dll
2015-09-06 23:36 - 2015-02-28 12:22 - 03571200 _____ (x264vfw project) C:\WINDOWS\system32\x264vfw64.dll
2015-09-06 23:36 - 2015-02-28 12:21 - 03591680 _____ (x264vfw project) C:\WINDOWS\SysWOW64\x264vfw.dll
2015-09-06 23:36 - 2012-07-21 07:55 - 00180736 _____ (fccHandler) C:\WINDOWS\system32\ac3acm.acm
2015-09-06 23:36 - 2012-07-21 07:54 - 00122880 _____ (fccHandler) C:\WINDOWS\SysWOW64\ac3acm.acm
2015-09-06 23:36 - 2011-12-07 14:37 - 00148992 _____ ( ) C:\WINDOWS\system32\lagarith.dll
2015-09-06 23:36 - 2011-12-07 14:32 - 00216064 _____ ( ) C:\WINDOWS\SysWOW64\lagarith.dll
2015-09-06 23:34 - 2015-09-06 23:39 - 11538178 _____ ( ) C:\Users\Anora\Downloads\klcp_update_1141_20150904.exe
2015-09-06 23:33 - 2015-09-06 23:34 - 41563740 _____ ( ) C:\Users\Anora\Downloads\K-Lite_Codec_Pack_1140_Mega.exe
2015-09-06 22:55 - 2015-09-06 22:55 - 00000000 ____D C:\Users\Anora\AppData\LocalLow\Hyper Hippo Productions Ltd_
2015-09-05 17:28 - 2015-09-05 17:28 - 00000000 ____D C:\Users\Anora\AppData\Local\DunDefLauncher
2015-09-05 11:19 - 2015-09-05 11:19 - 00000000 ____D C:\Users\Anora\AppData\LocalLow\ProjectorGames

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-10-05 11:28 - 2015-08-13 08:43 - 00000000 ____D C:\Users\Anora\AppData\Roaming\Skype
2015-10-05 11:28 - 2015-07-10 09:22 - 00000275 _____ C:\WINDOWS\WindowsUpdate.log
2015-10-05 11:24 - 2015-08-13 08:28 - 00000000 ____D C:\Users\Anora\AppData\Roaming\TS3Client
2015-10-05 11:21 - 2015-08-15 11:02 - 00000000 ____D C:\Users\Anora\AppData\Roaming\Azureus
2015-10-05 10:51 - 2015-08-13 08:23 - 00000830 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-10-05 10:45 - 2015-08-13 09:40 - 00000906 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job
2015-10-05 10:34 - 2015-07-10 08:04 - 00000000 ____D C:\WINDOWS\system32\sru
2015-10-05 09:45 - 2015-08-13 09:40 - 00000902 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskMachineCore.job
2015-10-05 06:10 - 2015-08-29 22:46 - 00004150 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{EA2E53CE-F334-47B7-8980-3556B6318B92}
2015-10-04 09:29 - 2015-07-10 08:04 - 00000000 ____D C:\WINDOWS\AppReadiness
2015-10-04 00:26 - 2015-07-10 08:04 - 00000000 ____D C:\WINDOWS\rescache
2015-10-03 08:52 - 2015-08-20 09:21 - 01012590 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2015-10-03 08:52 - 2015-08-13 09:45 - 00000000 ___RD C:\Users\Anora\Dropbox
2015-10-03 08:52 - 2015-08-13 09:40 - 00000000 ____D C:\Users\Anora\AppData\Local\Dropbox
2015-10-03 08:44 - 2015-07-10 09:21 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-10-02 19:47 - 2015-08-20 14:04 - 00000000 ____D C:\Program Files (x86)\MSBuild
2015-10-02 19:44 - 2015-08-20 09:19 - 00000000 ____D C:\ProgramData\Package Cache
2015-10-02 19:35 - 2015-08-20 09:15 - 00010394 _____ C:\WINDOWS\PFRO.log
2015-10-02 19:35 - 2015-08-13 08:03 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2015-10-02 19:34 - 2015-07-10 06:05 - 00524288 ___SH C:\WINDOWS\system32\config\BBI
2015-10-02 19:31 - 2015-07-10 08:04 - 00000000 ___SD C:\WINDOWS\SysWOW64\F12
2015-10-02 19:31 - 2015-07-10 08:04 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility
2015-10-02 19:30 - 2015-07-10 08:04 - 00000000 ___SD C:\WINDOWS\system32\F12
2015-10-02 19:30 - 2015-07-10 08:04 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2015-10-02 19:30 - 2015-07-10 08:04 - 00000000 ____D C:\WINDOWS\system32\SystemResetPlatform
2015-10-02 19:30 - 2015-07-10 08:04 - 00000000 ____D C:\WINDOWS\system32\appraiser
2015-10-02 19:29 - 2015-07-10 08:04 - 00000000 ___RD C:\WINDOWS\PurchaseDialog
2015-10-02 19:29 - 2015-07-10 08:04 - 00000000 ____D C:\WINDOWS\Provisioning
2015-10-02 19:29 - 2015-07-10 08:04 - 00000000 ____D C:\WINDOWS\L2Schemas
2015-10-02 19:26 - 2015-08-20 09:18 - 00000000 ____D C:\Program Files\AMD
2015-10-02 19:25 - 2015-08-13 08:11 - 00000000 ____D C:\AMD
2015-10-02 19:21 - 2015-08-27 22:14 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Seagate
2015-10-02 19:20 - 2015-08-13 09:50 - 00000000 ____D C:\Program Files\MySQL
2015-10-02 19:20 - 2015-08-13 09:03 - 00000000 ____D C:\Program Files (x86)\MSI
2015-10-02 19:20 - 2015-08-13 07:50 - 00000000 ____D C:\MSI
2015-10-02 19:19 - 2015-08-13 09:48 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MySQL
2015-10-02 19:18 - 2015-08-13 09:47 - 00000000 ____D C:\Program Files (x86)\MySQL
2015-10-02 19:17 - 2015-08-13 09:51 - 00000023 _____ C:\WINDOWS\ODBCINST.INI
2015-10-02 19:12 - 2015-08-13 07:55 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2015-10-02 19:10 - 2015-08-13 08:01 - 00000000 ____D C:\Program Files (x86)\Realtek
2015-10-02 19:09 - 2015-08-13 07:54 - 00000000 ____D C:\ProgramData\Downloaded Installations
2015-10-02 19:09 - 2015-08-13 07:54 - 00000000 _____ C:\Users\Anora\AppData\Local\Driver_LOM_8161Present.flag
2015-10-02 18:37 - 2015-08-13 09:40 - 00000000 ____D C:\Program Files (x86)\Dropbox
2015-10-01 07:23 - 2015-07-10 07:55 - 00000000 ____D C:\WINDOWS\CbsTemp
2015-09-30 21:56 - 2015-08-14 07:36 - 00000000 ____D C:\Users\Anora\AppData\Local\FirestormOS_x64
2015-09-28 08:00 - 2015-08-20 09:23 - 00000000 ____D C:\Users\Anora
2015-09-27 20:21 - 2015-07-10 08:04 - 00000000 ____D C:\WINDOWS\LiveKernelReports
2015-09-27 19:40 - 2015-08-13 07:43 - 00000000 ____D C:\Users\Anora\AppData\Local\VirtualStore
2015-09-25 16:06 - 2015-08-17 17:01 - 00000000 ____D C:\Users\Anora\AppData\Local\ftblauncher
2015-09-25 13:18 - 2015-08-13 08:28 - 00000000 ____D C:\Program Files\TeamSpeak 3 Client
2015-09-25 09:31 - 2015-08-20 09:43 - 00000000 ____D C:\Users\Anora\AppData\Local\Packages
2015-09-25 09:26 - 2015-08-14 00:36 - 00000000 ____D C:\Program Files\LinkShellExtension
2015-09-25 09:25 - 2015-08-29 19:07 - 00000000 ____D C:\Program Files (x86)\CyberLink
2015-09-22 07:51 - 2015-08-13 08:23 - 00003804 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2015-09-18 16:01 - 2015-08-13 08:37 - 00000000 ____D C:\Users\Anora\AppData\Local\AMD
2015-09-15 19:40 - 2015-08-29 19:05 - 00000000 ____D C:\ProgramData\SUPPORTDIR
2015-09-15 16:39 - 2015-08-29 19:05 - 00000000 ____D C:\ProgramData\CyberLink
2015-09-14 21:25 - 2015-08-13 08:23 - 00000000 ____D C:\ProgramData\AMD
2015-09-14 21:20 - 2015-08-20 09:19 - 00000000 ____D C:\Program Files (x86)\ATI Technologies
2015-09-13 17:02 - 2015-08-30 17:42 - 00000080 _____ C:\Users\Anora\AppData\Local剜捯獫慴⁲慇敭屳呇⁁屖湥楴汴浥湥⹴湩潦
2015-09-13 17:02 - 2015-08-30 17:42 - 00000000 ____D C:\Program Files (x86)\Rockstar Games
2015-09-13 17:02 - 2015-08-30 17:41 - 00000000 ____D C:\Program Files\Rockstar Games
2015-09-12 16:11 - 2015-08-29 19:05 - 00000000 ____D C:\ProgramData\install_clap
2015-09-10 07:43 - 2015-07-10 09:20 - 00193696 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2015-09-10 07:41 - 2015-07-10 10:14 - 00000000 ____D C:\Program Files\Windows Journal
2015-09-08 23:19 - 2015-08-13 08:31 - 00000000 ____D C:\WINDOWS\system32\MRT

==================== Files in the root of some directories =======

2015-08-13 07:54 - 2015-10-02 19:09 - 0000000 _____ () C:\Users\Anora\AppData\Local\Driver_LOM_8161Present.flag
2015-08-22 18:22 - 2015-08-22 18:22 - 0000600 _____ () C:\Users\Anora\AppData\Local\PUTTY.RND

Files to move or delete:
====================
C:\Users\Anora\en_res.dll
C:\Users\Anora\es_res.dll
C:\Users\Anora\fr_res.dll
C:\Users\Anora\grm_res.dll
C:\Users\Anora\it_res.dll
C:\Users\Anora\jp_res.dll
C:\Users\Anora\mfc80u.dll
C:\Users\Anora\msvcr80.dll
C:\Users\Anora\PCPE Setup.exe
C:\Users\Anora\pt_res.dll
C:\Users\Anora\ResourceReader.dll
C:\Users\Anora\ru_res.dll
C:\Users\Anora\zh_res.dll


Some files in TEMP:
====================
C:\Users\Anora\AppData\Local\Temp\CH.dll
C:\Users\Anora\AppData\Local\Temp\COMAP.EXE
C:\Users\Anora\AppData\Local\Temp\drm_dyndata_7370014.dll
C:\Users\Anora\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpcwzmbn.dll
C:\Users\Anora\AppData\Local\Temp\i4jdel0.exe
C:\Users\Anora\AppData\Local\Temp\jre-8u60-windows-au.exe
C:\Users\Anora\AppData\Local\Temp\npp.6.8.3.Installer.exe
C:\Users\Anora\AppData\Local\Temp\raptrpatch.exe
C:\Users\Anora\AppData\Local\Temp\raptr_stub.exe
C:\Users\Anora\AppData\Local\Temp\xmlUpdater.exe


==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-10-01 07:19

==================== End of FRST.txt ============================

Attached Files


Edited by Anora, 05 October 2015 - 09:37 AM.


#7 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 37,005 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:03:11 AM

Posted 05 October 2015 - 01:07 PM

Greetings,

Thanks for the update.

You listed the FRST report twice. Do you have an Addition.txt file on your desktop you can post?

Please do this.

===================================================

Farbar's Recovery Scan Tool - Run Fix in Normal or Safe Mode

--------------------
  • Press the Windows key Windows_Logo_key.gif + r on your keyboard at the same time. Type in notepad and press Enter
  • Please copy and paste the contents of the below code box into the open notepad and save it to your desktop (<<<Important) as fixlist.txt
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
U3 idsvc; no ImagePath
S3 NTIOLib_MSICOMM_CC; \??\C:\Program Files (x86)\MSI\Command Center\NTIOLib_X64.sys [X]
S3 NTIOLib_MSIFrequency_CC; \??\C:\Program Files (x86)\MSI\Command Center\ClockGen\CPU_Frequency\NTIOLib_X64.sys [X]
S3 NTIOLib_MSIRatio_CC; \??\C:\Program Files (x86)\MSI\Command Center\CPU\CPU_Ratio\NTIOLib_X64.sys [X]
S3 NTIOLib_MSISuperIO_CC; \??\C:\Program Files (x86)\MSI\Command Center\SuperIO\NTIOLib_X64.sys [X]
S3 wfpcapture; \SystemRoot\System32\drivers\wfpcapture.sys [X]
U3 wpcsvc; no ImagePath
2015-09-13 17:02 - 2015-08-30 17:42 - 00000080 _____ C:\Users\Anora\AppData\Local剜捯獫慴⁲慇敭屳呇⁁屖湥楴汴浥湥⹴湩潦
C:\Users\Anora\en_res.dll
C:\Users\Anora\es_res.dll
C:\Users\Anora\fr_res.dll
C:\Users\Anora\grm_res.dll
C:\Users\Anora\it_res.dll
C:\Users\Anora\jp_res.dll
C:\Users\Anora\mfc80u.dll
C:\Users\Anora\msvcr80.dll
C:\Users\Anora\PCPE Setup.exe
C:\Users\Anora\pt_res.dll
C:\Users\Anora\ResourceReader.dll
C:\Users\Anora\ru_res.dll
C:\Users\Anora\zh_res.dll
File: C:\Users\Anora\AppData\Local\Temp\CH.dll
  • Launch FRST and press the Fix button just once and wait, the program will automatically launch fixlist.txt.
  • The tool will create a log on the desktop called Fixlog.txt. Please copy and paste the contents of the file in your reply.
===================================================

Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it. :thumbsup2:
  • Addition.txt
  • Fixlog

Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#8 Anora

Anora
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Local time:06:11 AM

Posted 05 October 2015 - 08:33 PM

my bad tought i coppide the addition.txt as well

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version:04-10-2015
Ran by Anora (2015-10-05 22:28:00)
Running from C:\Users\Anora\Desktop
Windows 10 Pro (X64) (2015-08-20 12:43:09)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-434036944-719920970-2392407034-500 - Administrator - Disabled)
Anora (S-1-5-21-434036944-719920970-2392407034-1000 - Administrator - Enabled) => C:\Users\Anora
DefaultAccount (S-1-5-21-434036944-719920970-2392407034-503 - Limited - Disabled)
Guest (S-1-5-21-434036944-719920970-2392407034-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-434036944-719920970-2392407034-1002 - Limited - Enabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Spybot - Search and Destroy (Enabled - Up to date) {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe Flash Player 19 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 19.0.0.185 - Adobe Systems Incorporated)
Adobe Photoshop CS6 (HKLM-x32\...\Adobe Photoshop CS6) (Version: 13.0.0.0 - © The Computer Guy Tony)
AdVenture Capitalist (HKLM-x32\...\Steam App 346900) (Version:  - Hyper Hippo Games)
AMD Catalyst Control Center (HKLM-x32\...\WUCCCApp) (Version: 1.00.0000 - AMD)
AMD Catalyst Install Manager (HKLM\...\{3F48F53E-BC0F-A72E-AC89-EA9C3F8F4701}) (Version: 8.0.916.0 - Advanced Micro Devices, Inc.)
Apple Application Support (32-bit) (HKLM-x32\...\{3540ADD5-822B-47FB-B1C2-CD7B2C8E9FEC}) (Version: 4.0.2 - Apple Inc.)
Apple Application Support (64-bit) (HKLM\...\{C9C0FE2C-602E-49D7-8C42-5B9E8FF04798}) (Version: 4.0.2 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{FD244E19-6EFE-4A2D-948A-0D45D4C168BE}) (Version: 9.0.0.26 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{FFD1F7F1-1AC9-4BC4-A908-0686D635ABAF}) (Version: 2.1.4.131 - Apple Inc.)
Avast Free Antivirus (HKLM-x32\...\Avast) (Version: 10.4.2233 - AVAST Software)
Blender (HKLM-x32\...\Steam App 365670) (Version:  - Blender Foundation)
Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
Borderlands: The Pre-Sequel (HKLM-x32\...\Steam App 261640) (Version:  - 2K Australia)
Canon IJ Network Tool (HKLM-x32\...\Canon_IJ_Network_UTILITY) (Version: 3.1.1 - Canon Inc.)
Canon MP495 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP495_series) (Version:  - Canon Inc.)
Canon My Printer (HKLM-x32\...\CanonMyPrinter) (Version: 3.2.1 - Canon Inc.)
Command & Conquer™ The Ultimate Collection Additional Content (HKLM-x32\...\{1A882F29-BC18-4AC2-A71E-0FC30FA32568}) (Version: 1.0.0.0 - Electronic Arts)
CPUID CPU-Z 1.73 (HKLM\...\CPUID CPU-Z_is1) (Version:  - )
Crysis (HKLM-x32\...\{E70E73B2-DABD-40E4-AE50-81B22567F418}) (Version: 1.1.1.6115 - Electronic Arts)
Crysis®3 (HKLM-x32\...\{4198AE83-A3C6-4C41-85C8-EC63E990696E}) (Version: 1.0.0.0 - Electronic Arts)
Crysis®3 Digital Deluxe Edition Content (HKLM-x32\...\{2A8C5AE3-2772-4EB1-8206-D5E53D111A61}) (Version: 1.0.0.0 - Electronic Arts)
CyberLink PowerDVD 15 (HKLM-x32\...\{DE85B8F3-D088-4D6E-A970-EE0BC7883A66}) (Version: 15.0.2003.58 - CyberLink Corp.)
Dragon Age: Origins (HKLM-x32\...\{AEC81925-9C76-4707-84A9-40696C613ED3}) (Version: 1.05.0.0 - Electronic Arts)
DRAGON BALL XENOVERSE (HKLM-x32\...\Steam App 323470) (Version:  - DIMPS)
Dropbox (HKLM-x32\...\Dropbox) (Version: 3.10.7 - Dropbox, Inc.)
Dropbox Update Helper (x32 Version: 1.3.27.35 - Dropbox, Inc.) Hidden
Dungeon Defenders II (HKLM-x32\...\Steam App 236110) (Version:  - Trendy Entertainment)
Epic Games Launcher (HKLM\...\{7C8ED4CE-7D28-442D-AD14-C95C18A7CB1A}) (Version: 1.1.35.0 - Epic Games, Inc.)
FaceRig Virtual Video driver version 1.0 (HKLM-x32\...\{7D6A1A0F-F57E-4C6B-9331-86CBC7D5C787}_is1) (Version: 1.0 - Adoriasoft LLC)
FINAL FANTASY XIII-2 (HKLM-x32\...\Steam App 292140) (Version:  - SQUARE ENIX)
Firestorm SecondLife and OpenSim viewer (Version: 4.7.47323 - Phoenix Viewer Project) Hidden
Firestorm-Releasex64 x64 (HKLM-x32\...\{87a36c50-4766-41e3-b23b-2354a2ff60bf}) (Version: 4.7.47323 - Phoenix Firestorm Project Inc)
GitHub (HKU\S-1-5-21-434036944-719920970-2392407034-1000\...\5f7eb300e2ea4ebf) (Version: 3.0.4.0 - GitHub, Inc.)
iTunes (HKLM\...\{88509E20-3936-4D88-A1C0-B274C7BB5151}) (Version: 12.3.0.44 - Apple Inc.)
Java 8 Update 60 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86418060F0}) (Version: 8.0.600.27 - Oracle Corporation)
Java 8 Update 60 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218060F0}) (Version: 8.0.600.27 - Oracle Corporation)
Killer Bandwidth Control Filter Driver (Version: 1.1.54.1095 - Rivet Networks) Hidden
Killer E220x Drivers (Version: 1.1.54.1095 - Rivet Networks) Hidden
Killer Network Manager (Version: 1.1.54.1095 - Rivet Networks) Hidden
Killer Performance Suite (HKLM-x32\...\{E70DB50B-10B4-46BC-9DE2-AB8B49E061EE}) (Version: 1.1.54.1095 - Rivet Networks)
Kits Configuration Installer (x32 Version: 8.100.26846 - Microsoft) Hidden
K-Lite Mega Codec Pack 11.4.1 (HKLM-x32\...\KLiteCodecPack_is1) (Version: 11.4.1 - )
Malwarebytes Anti-Malware version 2.1.8.1057 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.1.8.1057 - Malwarebytes Corporation)
METAL GEAR SOLID V: THE PHANTOM PAIN (HKLM-x32\...\Steam App 287700) (Version:  - Konami Digital Entertainment)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40728.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{A49F249F-0C91-497F-86DF-B2585E8E76B7}) (Version: 8.0.50727.42 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6E8E85E8-CE4B-4FF5-91F7-04999C9FAE6A}) (Version: 8.0.50727.42 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Mozilla Firefox 41.0.1 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 41.0.1 (x86 en-US)) (Version: 41.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 41.0.1.5750 - Mozilla)
MSI Live Update 6 (HKLM-x32\...\{4F46CF54-47D2-41F4-B230-B0954C544420}}_is1) (Version: 6.1.008 - MSI)
MySQL Installer for Windows - Community (HKLM-x32\...\{7B49388D-361F-48CD-BF2E-B655892626F0}) (Version: 1.4.9.0 - Oracle Corporation)
MySQL Server 5.6 (HKLM\...\{F9D015C6-E9AE-455D-8DDA-BE8B77F3004E}) (Version: 5.6.26 - Oracle Corporation)
Neato Updater Tool v2 (HKLM-x32\...\{292156D3-43B5-4C96-B79A-94E40F8D8991}) (Version: 3.0 - Neato Robotics, Inc)
Notepad++ (HKLM-x32\...\Notepad++) (Version: 6.8.3 - Notepad++ Team)
ONE PIECE PIRATE WARRIORS 3 (HKLM-x32\...\Steam App 331600) (Version:  - KOEI TECMO GAMES CO., LTD.)
Open Broadcaster Software (HKLM-x32\...\Open Broadcaster Software) (Version:  - )
Origin (HKLM-x32\...\Origin) (Version: 9.7.2.53208 - Electronic Arts, Inc.)
PHP Manager 1.2 for IIS 7 (HKLM\...\{E851486F-1FE2-44F0-85ED-F969088A68EE}) (Version: 1.2.0 -  )
Planetary Annihilation (HKLM\...\{0FE10D49-7DD1-4E7B-935E-CF22EDBA11D0}) (Version:  - Uber Entertainment)
Platform (x32 Version: 1.42 - VIA Technologies, Inc.) Hidden
PowerChute Personal Edition 3.0.2 (HKLM-x32\...\{8ED262EE-FC73-47A9-BB86-D92223246881}) (Version: 3.0.2 - Schneider Electric)
PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.986 - Even Balance, Inc.)
PuTTY release 0.65 (HKLM-x32\...\PuTTY_is1) (Version: 0.65 - Simon Tatham)
RAM Monitor 1.0 (HKLM-x32\...\{C7705355-27D8-48E3-99AF-2B864386A5C5}_is1) (Version:  - Vag-Labs)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7535 - Realtek Semiconductor Corp.)
Rockstar Games Social Club (HKLM-x32\...\Rockstar Games Social Club) (Version: 1.1.6.5 - Rockstar Games)
Saints Row: Gat out of Hell (HKLM-x32\...\Steam App 301910) (Version:  - Deep Silver Volition)
SDK ARM Additions (x32 Version: 8.100.26846 - Microsoft Corporation) Hidden
SDK ARM Additions EULA (x32 Version: 8.100.26846 - Microsoft Corporations) Hidden
SDK ARM Redistributables (x32 Version: 8.100.26846 - Microsoft Corporation) Hidden
SDK Debuggers ARM (x32 Version: 8.100.26846 - Microsoft Corporation) Hidden
SimCity™ (HKLM-x32\...\{F70FDE4B-8F86-4eb6-8C8E-636EC89F6419}) (Version: 4.0.86.0859 - Electronic Arts)
Skype Click to Call (HKLM-x32\...\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 7.4.0.9058 - Microsoft Corporation)
Skype™ 7.8 (HKLM-x32\...\{6A0549A9-1B96-498C-ACBC-3943001FEB19}) (Version: 7.8.102 - Skype Technologies S.A.)
SPORE™ (HKLM-x32\...\{9DF0196F-B6B8-4C3A-8790-DE42AA530101}) (Version: 1.00.0000 - Electronic Arts)
Spybot - Search & Destroy (HKLM-x32\...\{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1) (Version: 2.4.40 - Safer-Networking Ltd.)
Star Citizen Launcher (HKU\S-1-5-21-434036944-719920970-2392407034-1000\...\Star Citizen Launcher) (Version: 00.01.00.00 - Cloud Imperium Games)
TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.17 - TeamSpeak Systems GmbH)
TeamViewer 10 (HKLM-x32\...\TeamViewer) (Version: 10.0.47484 - TeamViewer)
Titanfall™ (HKLM-x32\...\{347EE0C3-0690-48F6-A231-53853C2A80D6}) (Version: 1.0.10.1 - Electronic Arts)
VIA Platform Device Manager (HKLM-x32\...\InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}) (Version: 1.42 - VIA Technologies, Inc.)
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.1 - VideoLAN)
Vuze (HKLM\...\8461-7759-5462-8226) (Version: 5.6.2.0 - Azureus Software, Inc.)
WebM Project Directshow Filters (HKU\S-1-5-21-434036944-719920970-2392407034-1000\...\webmdshow) (Version:  - )
Windows Driver Kit for Windows 8.1 (HKLM-x32\...\{aba88724-37eb-4f03-b83b-45199c5a7cf5}) (Version: 8.100.26846 - Microsoft Corporation)
WinRAR 5.21 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.21.0 - win.rar GmbH)
Xiph.Org Open Codecs 0.85.17777 (HKLM-x32\...\Open Codecs) (Version: 0.85.17777 - Xiph.Org)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== Restore Points =========================

23-09-2015 17:53:58 Windows Update
25-09-2015 09:24:55 Removed MySQL Examples and Samples 5.6
01-10-2015 07:19:08 Windows Update
02-10-2015 19:07:52 Removed Realtek Ethernet Controller Driver

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-13 23:34 - 2015-09-25 17:26 - 00450709 ____R C:\WINDOWS\system32\Drivers\etc\hosts
127.0.0.1    www.007guard.com
127.0.0.1    007guard.com
127.0.0.1    008i.com
127.0.0.1    www.008k.com
127.0.0.1    008k.com
127.0.0.1    www.00hq.com
127.0.0.1    00hq.com
127.0.0.1    010402.com
127.0.0.1    www.032439.com
127.0.0.1    032439.com
127.0.0.1    www.0scan.com
127.0.0.1    0scan.com
127.0.0.1    1000gratisproben.com
127.0.0.1    www.1000gratisproben.com
127.0.0.1    1001namen.com
127.0.0.1    www.1001namen.com
127.0.0.1    100888290cs.com
127.0.0.1    www.100888290cs.com
127.0.0.1    www.100sexlinks.com
127.0.0.1    100sexlinks.com
127.0.0.1    10sek.com
127.0.0.1    www.10sek.com
127.0.0.1    www.1-2005-search.com
127.0.0.1    1-2005-search.com
127.0.0.1    123fporn.info
127.0.0.1    www.123fporn.info
127.0.0.1    123haustiereundmehr.com
127.0.0.1    www.123haustiereundmehr.com
127.0.0.1    123moviedownload.com

There are 1000 more lines.


==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {0344001C-35FF-44A9-BAFC-7A62233B6283} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
Task: {1924B85E-7991-4E4A-9B75-AF41CB2C4733} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {19B085FD-186D-4483-AE61-61DEA5E3235E} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe [2014-06-24] (Safer-Networking Ltd.)
Task: {1A207788-234D-4190-959C-9D0C5FE0277A} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe [2014-06-27] (Safer-Networking Ltd.)
Task: {22B4DDDF-ADBB-46F5-98CD-E4EFF5B287DF} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\Windows\ehome\ehrec.exe
Task: {2430B07C-0D04-4D43-A5C9-FBAD27DC3E90} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\Windows\ehome\ehPrivJob.exe
Task: {309B91F3-DB05-4651-886B-51D2BB377D97} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {36C4521F-07B7-4C36-B837-DE0902ABEAB8} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {3F66788A-FB65-4003-A3D2-56537F561FDD} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\Windows\ehome\ehPrivJob.exe
Task: {42C88AC6-2549-4185-A532-5D85F72F1695} - System32\Tasks\Microsoft\Microsoft Antimalware\Microsoft Antimalware Scheduled Scan => C:\Program Files\Microsoft Security Client\MpCmdRun.exe
Task: {445BCB70-8A5D-492A-87DA-183F994661E8} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION
Task: {6A5495ED-A695-47F9-9CF4-BF36433BF892} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {6FD5C2A9-01B8-4F51-A7ED-4D8396E5E9C0} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\Windows\ehome\ehPrivJob.exe
Task: {77308C69-87AC-4EC5-88CB-2B702EC3F240} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2015-08-13] (Dropbox, Inc.)
Task: {83176A2B-3343-4924-AEF3-F77AADA2C88E} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\Windows\ehome\ehPrivJob.exe
Task: {8448A3FC-0B97-4EB0-B428-6024741B642A} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\Windows\ehome\mcupdate.exe
Task: {884E4A4C-7DCE-4CCA-9D4A-97BF6B31425E} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe [2014-06-24] (Safer-Networking Ltd.)
Task: {8D3CF647-EDEA-47EB-BA86-F90176BAB335} - System32\Tasks\klcp_update => C:\Program Files (x86)\K-Lite Codec Pack\Tools\CodecTweakTool.exe [2015-08-24] ()
Task: {8F4C3A2F-D807-437E-BAA4-10DF9721ED47} - \Microsoft\Windows\File Classification Infrastructure\Property Definition Sync -> No File <==== ATTENTION
Task: {90F3122E-BACA-420F-A5C6-328341F2B509} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\Windows\ehome\ehPrivJob.exe
Task: {92E984CC-BB3A-4776-B733-FAEDAD77AA18} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\Windows\ehome\ehPrivJob.exe
Task: {97EAD47E-914B-48A6-BFF1-C2CFFBF75048} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {99D19368-3339-473E-A7F9-07F870737740} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {A38976A1-DB00-4DF4-96E8-EA74A8719549} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2015-08-27] (Apple Inc.)
Task: {A5DEC08A-ABBE-4B96-9E3E-10FC71CFB1A0} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\Windows\ehome\ehPrivJob.exe
Task: {A7B12029-4379-4C29-B02B-60DABA812D9C} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\Windows\ehome\MCUpdate.exe
Task: {A84F8755-9A13-45D7-A0D8-31210B3ABE0A} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\Windows\ehome\mcupdate.exe
Task: {AA5FCFD5-7108-4409-882A-F98F8ACE096D} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2015-09-25] (AVAST Software)
Task: {B0C3350E-391D-475E-B67C-4816DFD11686} - System32\Tasks\MySQL\Installer\ManifestUpdate => C:\Program Files (x86)\MySQL\MySQL Installer for Windows\MySQLInstallerConsole.exe [2015-07-18] (Oracle Corporation)
Task: {B252FBF1-1355-4DBB-83D7-7C0D2181A41B} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\Windows\ehome\ehPrivJob.exe
Task: {B5598F48-19C9-48F0-9CF7-7B511DEB99D3} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {BDA245D9-7A03-42A2-83D8-4D9B4043A34E} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\Windows\ehome\ehPrivJob.exe
Task: {BDF4E673-83A7-4684-B084-A0362BF9D0A1} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\Windows\ehome\ehPrivJob.exe
Task: {C0A7402B-5815-486D-B7FF-46460D8E82E1} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {C9C88B30-7544-4C1C-90CC-BB038408F852} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\Windows\ehome\ehPrivJob.exe
Task: {D30C7960-0886-48E2-BE8C-424ECF951E61} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {D4AC86D9-C96F-40E9-8BE1-58D1F27CAF66} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {DC7E7644-5345-4EDF-BB68-531D2BB69AE1} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\Windows\ehome\ehPrivJob.exe
Task: {E3036E4C-A7F5-4432-A565-4A52930E109D} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {E7708ADB-F5E5-4EB6-9753-98A803287C68} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2015-08-13] (Dropbox, Inc.)
Task: {F1667936-660E-4DD6-9888-EE3B1549F8E8} - System32\Tasks\{2B16F297-B0B7-425A-917C-1F3C3ADB57B4} => pcalua.exe -a C:\Users\Anora\Downloads\HardLinkShellExt_X64.exe -d C:\Users\Anora\Downloads
Task: {F3394054-4048-4819-BE5D-04D10489D62B} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\Windows\ehome\mcupdate.exe
Task: {F3906CE1-A63A-42C6-A6A3-43EE758261AF} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {F8E76FF3-EC58-4970-85C1-325E20447185} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\Windows\ehome\ehPrivJob.exe
Task: {FC8F70C8-94E0-42FE-A0A3-D3A61BE5F877} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-09-22] (Adobe Systems Incorporated)
Task: {FD952D3B-2F40-4052-8541-286320769310} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineCore.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe

==================== Loaded Modules (Whitelisted) ==============

2015-08-20 14:10 - 2015-08-20 14:10 - 00032768 _____ () C:\WINDOWS\SYSTEM32\licensemanagerapi.dll
2015-09-15 14:25 - 2015-09-15 14:25 - 00085800 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2015-09-15 14:25 - 2015-09-15 14:25 - 01328912 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2015-08-20 14:10 - 2015-08-20 14:10 - 00404480 _____ () C:\WINDOWS\System32\diagtrack_wininternal.dll
2015-07-15 00:13 - 2015-07-15 00:13 - 13061632 _____ () C:\Program Files\MySQL\MySQL Server 5.6\bin\mysqld.exe
2015-09-14 07:45 - 2015-09-14 07:45 - 00066872 _____ () C:\WINDOWS\SysWOW64\PnkBstrA.exe
2015-10-01 05:13 - 2015-09-17 03:48 - 02494712 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
2015-10-01 05:13 - 2015-09-17 03:48 - 02494712 _____ () C:\WINDOWS\System32\CoreUIComponents.dll
2015-04-15 17:13 - 2015-04-15 17:13 - 00222720 _____ () C:\Program Files (x86)\Notepad++\NppShell_06.dll
2015-10-01 05:13 - 2015-09-17 02:43 - 02028544 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RulesService.dll
2015-10-01 05:12 - 2015-09-17 02:42 - 00471040 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2015-10-01 05:12 - 2015-09-17 02:42 - 00619008 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SignalsManager.dll
2015-10-01 05:13 - 2015-09-17 02:43 - 00928768 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RulesBackgroundTasks.dll
2015-10-01 05:12 - 2015-09-17 02:42 - 01808384 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2015-10-01 05:12 - 2015-09-17 02:48 - 00429056 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll
2015-07-10 07:59 - 2015-07-10 07:59 - 00143360 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\XamlTileRendering.dll
2015-10-01 05:12 - 2015-09-17 03:04 - 00642048 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\MtcUvc.dll
2015-10-01 05:14 - 2015-09-17 02:44 - 06569472 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2015-10-01 05:13 - 2015-09-17 02:49 - 00884736 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Actions.dll
2015-10-01 05:13 - 2015-09-17 02:43 - 02274816 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2015-07-10 08:00 - 2015-07-10 10:14 - 00210432 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.ProxyStub.dll
2015-08-21 22:09 - 2015-08-21 22:09 - 00102400 _____ () C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Proxy.Native.dll
2015-08-04 04:54 - 2015-09-25 13:18 - 00175080 _____ () C:\Program Files\TeamSpeak 3 Client\quazip.dll
2015-08-04 04:53 - 2015-09-25 13:18 - 00103400 _____ () C:\Program Files\TeamSpeak 3 Client\soundbackends\directsound_win64.dll
2015-08-04 04:54 - 2015-09-25 13:18 - 00108008 _____ () C:\Program Files\TeamSpeak 3 Client\soundbackends\windowsaudiosession_win64.dll
2015-08-04 04:54 - 2015-09-25 13:18 - 00312296 _____ () C:\Program Files\TeamSpeak 3 Client\plugins\clientquery_plugin.dll
2015-08-04 04:54 - 2015-09-25 13:18 - 00483816 _____ () C:\Program Files\TeamSpeak 3 Client\plugins\teamspeak_control_plugin.dll
2015-07-17 10:10 - 2015-09-25 13:18 - 00317440 _____ () C:\Program Files\TeamSpeak 3 Client\ssleay32.dll
2015-07-17 10:10 - 2015-09-25 13:18 - 01709056 _____ () C:\Program Files\TeamSpeak 3 Client\LIBEAY32.dll
2015-08-20 14:10 - 2015-08-20 14:10 - 00293376 _____ () C:\WINDOWS\SYSTEM32\textinputframework.dll
2015-09-25 17:06 - 2015-09-25 17:06 - 00103376 _____ () C:\Program Files\AVAST Software\Avast\log.dll
2015-09-25 17:06 - 2015-09-25 17:06 - 00123976 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
2015-10-02 18:06 - 2015-10-02 18:06 - 02966528 _____ () C:\Program Files\AVAST Software\Avast\defs\15100202\algo.dll
2015-10-05 18:13 - 2015-10-05 18:13 - 02966528 _____ () C:\Program Files\AVAST Software\Avast\defs\15100501\algo.dll
2015-09-25 17:14 - 2014-05-13 12:04 - 00109400 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlThirdParty150.bpl
2015-09-25 17:14 - 2014-05-13 12:04 - 00167768 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlFileFormats150.bpl
2015-09-25 17:14 - 2014-05-13 12:04 - 00416600 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\DEC150.bpl
2015-09-25 17:14 - 2012-08-23 10:38 - 00574840 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\sqlite3.dll
2015-09-25 17:14 - 2012-04-03 17:06 - 00565640 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\av\BDSmartDB.dll
2015-10-02 19:20 - 2005-07-18 13:43 - 00160256 _____ () C:\Program Files (x86)\MSI\Live Update\unrar.dll
2015-09-13 21:15 - 2015-10-02 16:21 - 01016832 _____ () I:\Program Files (x86)\Origin\platforms\qwindows.dll
2015-09-13 21:15 - 2015-10-02 16:21 - 00028160 _____ () I:\Program Files (x86)\Origin\imageformats\qgif.dll
2015-09-13 21:15 - 2015-10-02 16:21 - 00029696 _____ () I:\Program Files (x86)\Origin\imageformats\qico.dll
2015-09-13 21:15 - 2015-10-02 16:21 - 00256000 _____ () I:\Program Files (x86)\Origin\imageformats\qjpeg.dll
2015-09-13 21:15 - 2015-10-02 16:21 - 00266240 _____ () I:\Program Files (x86)\Origin\imageformats\qmng.dll
2015-09-13 21:15 - 2015-10-02 16:21 - 00023552 _____ () I:\Program Files (x86)\Origin\imageformats\qtga.dll
2015-09-13 21:15 - 2015-10-02 16:21 - 00346112 _____ () I:\Program Files (x86)\Origin\imageformats\qtiff.dll
2015-09-13 21:15 - 2015-10-02 16:21 - 00023552 _____ () I:\Program Files (x86)\Origin\imageformats\qwbmp.dll
2015-09-13 21:15 - 2015-10-02 16:21 - 00243200 _____ () I:\Program Files (x86)\Origin\mediaservice\wmfengine.dll
2015-10-01 23:53 - 2015-10-01 20:07 - 00166416 _____ () C:\Program Files (x86)\Dropbox\Client\EnterpriseDataAdapter.dll
2015-10-03 08:51 - 2015-10-03 08:51 - 00071168 _____ () c:\users\anora\appdata\local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpcwzmbn.dll
2015-10-02 18:36 - 2015-09-23 20:07 - 00012800 _____ () C:\Program Files (x86)\Dropbox\Client\QtQuick.2\qtquick2plugin.dll
2015-10-01 23:54 - 2015-09-23 20:07 - 00779776 _____ () C:\Program Files (x86)\Dropbox\Client\QtQuick\Controls\qtquickcontrolsplugin.dll
2015-10-02 18:36 - 2015-09-23 20:07 - 00056320 _____ () C:\Program Files (x86)\Dropbox\Client\QtQuick\Layouts\qquicklayoutsplugin.dll
2015-10-02 18:36 - 2015-09-23 20:07 - 00012288 _____ () C:\Program Files (x86)\Dropbox\Client\QtQuick\Window.2\windowplugin.dll
2015-08-29 19:14 - 2015-08-10 03:18 - 00867256 _____ () C:\Program Files (x86)\CyberLink\PowerDVD15\common\UNO\UNO.dll
2015-08-29 19:13 - 2013-12-10 08:31 - 00074240 _____ () C:\Program Files (x86)\CyberLink\PowerDVD15\Common\Koan\_ctypes.pyd
2015-08-29 19:13 - 2013-12-10 08:31 - 00285184 _____ () C:\Program Files (x86)\CyberLink\PowerDVD15\Common\Koan\_hashlib.pyd
2015-08-29 19:13 - 2013-12-10 08:31 - 00040960 _____ () C:\Program Files (x86)\CyberLink\PowerDVD15\Common\Koan\_socket.pyd
2015-08-29 19:13 - 2013-12-10 08:31 - 00721920 _____ () C:\Program Files (x86)\CyberLink\PowerDVD15\Common\Koan\_ssl.pyd
2015-09-25 17:06 - 2015-09-25 17:06 - 40539648 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2015-08-28 20:01 - 2015-08-28 20:01 - 00019040 _____ () C:\Program Files (x86)\Java\jre1.8.0_60\bin\jp2native.dll
2013-02-28 11:52 - 2015-07-03 13:12 - 00778240 _____ () I:\Program Files (x86)\Steam\SDL2.dll
2015-01-19 21:35 - 2015-07-03 13:12 - 04962816 _____ () I:\Program Files (x86)\Steam\v8.dll
2014-05-22 16:24 - 2015-08-19 17:39 - 02413248 _____ () I:\Program Files (x86)\Steam\video.dll
2015-01-19 21:35 - 2015-07-03 13:12 - 01556992 _____ () I:\Program Files (x86)\Steam\icui18n.dll
2015-01-19 21:35 - 2015-07-03 13:12 - 01187840 _____ () I:\Program Files (x86)\Steam\icuuc.dll
2014-08-29 07:18 - 2014-12-01 18:31 - 02396672 _____ () I:\Program Files (x86)\Steam\libavcodec-56.dll
2014-08-29 07:18 - 2014-12-01 18:31 - 00479744 _____ () I:\Program Files (x86)\Steam\libavformat-56.dll
2014-08-29 07:18 - 2014-12-01 18:31 - 00332800 _____ () I:\Program Files (x86)\Steam\libavresample-2.dll
2014-08-29 07:18 - 2014-12-01 18:31 - 00442880 _____ () I:\Program Files (x86)\Steam\libavutil-54.dll
2014-08-29 07:18 - 2014-12-01 18:31 - 00485888 _____ () I:\Program Files (x86)\Steam\libswscale-3.dll
2012-05-02 16:39 - 2015-08-19 17:39 - 00704192 _____ () I:\Program Files (x86)\Steam\bin\chromehtml.DLL
2015-07-22 00:56 - 2015-07-26 22:13 - 00171008 _____ () I:\Program Files (x86)\Steam\bin\openvr_api.dll
2012-05-02 16:39 - 2015-07-03 13:12 - 39553928 _____ () I:\Program Files (x86)\Steam\bin\libcef.dll
2015-09-11 07:47 - 2015-09-11 07:44 - 00068681 _____ () J:\MultyMc5\librainbow.dll
2015-09-11 07:47 - 2015-10-04 22:00 - 03453469 _____ () J:\MultyMc5\libMultiMC_logic.dll
2014-06-05 01:00 - 2015-09-11 07:44 - 00119822 _____ () J:\MultyMc5\libgcc_s_dw2-1.dll
2014-06-05 01:00 - 2015-09-11 07:44 - 01026574 _____ () J:\MultyMc5\libstdc++-6.dll
2015-09-11 07:47 - 2015-09-28 21:30 - 00306768 _____ () J:\MultyMc5\libnbt++.dll
2015-09-28 21:30 - 2015-09-28 21:30 - 00107520 _____ () J:\MultyMc5\zlib1.dll
2015-06-08 16:06 - 2015-06-08 16:06 - 00014336 _____ () C:\Program Files (x86)\Notepad++\plugins\NppExport.dll
2015-05-15 11:24 - 2015-05-15 11:24 - 02873856 _____ () C:\Program Files (x86)\Notepad++\plugins\NppFTP.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== EXE Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)

IE restricted site: HKU\.DEFAULT\...\007guard.com -> install.007guard.com
IE restricted site: HKU\.DEFAULT\...\008i.com -> 008i.com
IE restricted site: HKU\.DEFAULT\...\008k.com -> www.008k.com
IE restricted site: HKU\.DEFAULT\...\00hq.com -> www.00hq.com
IE restricted site: HKU\.DEFAULT\...\010402.com -> 010402.com
IE restricted site: HKU\.DEFAULT\...\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
IE restricted site: HKU\.DEFAULT\...\0scan.com -> www.0scan.com
IE restricted site: HKU\.DEFAULT\...\1-2005-search.com -> www.1-2005-search.com
IE restricted site: HKU\.DEFAULT\...\1-domains-registrations.com -> www.1-domains-registrations.com
IE restricted site: HKU\.DEFAULT\...\1000gratisproben.com -> www.1000gratisproben.com
IE restricted site: HKU\.DEFAULT\...\1001namen.com -> www.1001namen.com
IE restricted site: HKU\.DEFAULT\...\100888290cs.com -> mir.100888290cs.com
IE restricted site: HKU\.DEFAULT\...\100sexlinks.com -> www.100sexlinks.com
IE restricted site: HKU\.DEFAULT\...\10sek.com -> www.10sek.com
IE restricted site: HKU\.DEFAULT\...\12-26.net -> user1.12-26.net
IE restricted site: HKU\.DEFAULT\...\12-27.net -> user1.12-27.net
IE restricted site: HKU\.DEFAULT\...\123fporn.info -> www.123fporn.info
IE restricted site: HKU\.DEFAULT\...\123haustiereundmehr.com -> www.123haustiereundmehr.com
IE restricted site: HKU\.DEFAULT\...\123moviedownload.com -> www.123moviedownload.com
IE restricted site: HKU\.DEFAULT\...\123simsen.com -> www.123simsen.com

There are 7867 more restricted sites.

==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-434036944-719920970-2392407034-1000\Control Panel\Desktop\\Wallpaper -> C:\WINDOWS\web\wallpaper\Windows\img0.jpg
DNS Servers: 64.71.255.204 - 64.71.255.198
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)

HKLM\...\StartupApproved\StartupFolder: => "Killer Network Manager.lnk"
HKLM\...\StartupApproved\Run: => "VIAxHCUtl"
HKLM\...\StartupApproved\Run32: => "LiveUpdate 5"
HKLM\...\StartupApproved\Run32: => "Command Center"
HKLM\...\StartupApproved\Run32: => "Fast Boot"
HKU\S-1-5-21-434036944-719920970-2392407034-1000\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-434036944-719920970-2392407034-1000\...\StartupApproved\Run: => "MySQL Notifier"
HKU\S-1-5-21-434036944-719920970-2392407034-1000\...\StartupApproved\Run: => "Speech Recognition"

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [MSMQ-In-TCP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-Out-TCP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-In-UDP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-Out-UDP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [WCF-NetTcpActivator-In-TCP-64bit] => (Allow) LPort=808
FirewallRules: [{00E957EF-BDA8-42CD-A285-DDB0A034F750}] => (Allow) J:\Program Files (x86)\SteamLibrary\steamapps\common\Tales from the Borderlands\Borderlands.exe
FirewallRules: [{BAA44427-4A3E-4A23-995E-9B4D1267CC53}] => (Allow) J:\Program Files (x86)\SteamLibrary\steamapps\common\Tales from the Borderlands\Borderlands.exe
FirewallRules: [{0D6C0E83-25BE-4473-9E61-85C1A476F974}] => (Allow) I:\Program Files (x86)\Steam\steamapps\common\FaceRig\Bin\FaceRig.exe
FirewallRules: [{6DE68C75-D372-4042-A5CA-169B119BCE90}] => (Allow) I:\Program Files (x86)\Steam\steamapps\common\FaceRig\Bin\FaceRig.exe
FirewallRules: [{53EF6E28-5266-40EA-96B2-13C467B397EA}] => (Allow) I:\Program Files (x86)\Steam\steamapps\common\FaceRig\Bin\Launcher.exe
FirewallRules: [{8BB23A15-531D-4E65-8830-6C59C93A68B9}] => (Allow) I:\Program Files (x86)\Steam\steamapps\common\FaceRig\Bin\Launcher.exe
FirewallRules: [{82821574-3841-4A63-B523-BF3467E8F5D7}] => (Allow) J:\Program Files (x86)\SteamLibrary\steamapps\common\Grand Theft Auto V\GTAVLauncher.exe
FirewallRules: [{D2752788-089D-4961-A7BC-123884737BA0}] => (Allow) J:\Program Files (x86)\SteamLibrary\steamapps\common\Grand Theft Auto V\GTAVLauncher.exe
FirewallRules: [{76BE7752-876A-4D27-9042-8F8C6C0BEB4C}] => (Allow) I:\Program Files (x86)\Steam\steamapps\common\Path of Exile\PathOfExileSteam.exe
FirewallRules: [{CB0F7869-8F39-41DB-A3B9-F16FC2CC2197}] => (Allow) I:\Program Files (x86)\Steam\steamapps\common\Path of Exile\PathOfExileSteam.exe
FirewallRules: [{F54EBE01-751B-4A58-9003-4FC7E150B661}] => (Allow) I:\Program Files (x86)\Steam\steamapps\common\Dragon's Prophet\LaunchPad.exe
FirewallRules: [{12B1D31B-FB23-4A37-9D5B-83FABD1A407B}] => (Allow) I:\Program Files (x86)\Steam\steamapps\common\Dragon's Prophet\LaunchPad.exe
FirewallRules: [{7347249D-907E-4BDB-9D71-D6C68C76CE7A}] => (Allow) J:\Program Files (x86)\SteamLibrary\steamapps\common\FortressCraft\64\FC_64.exe
FirewallRules: [{E6D79A6D-9D09-4DAA-A417-896A04868931}] => (Allow) J:\Program Files (x86)\SteamLibrary\steamapps\common\FortressCraft\64\FC_64.exe
FirewallRules: [{55D8DCE6-DF18-4F11-93D0-D9AA54F21EBF}] => (Allow) J:\Program Files (x86)\SteamLibrary\steamapps\common\Game Dev Tycoon\nw.exe
FirewallRules: [{EAFE67A7-FF87-457C-B794-460CD088349F}] => (Allow) J:\Program Files (x86)\SteamLibrary\steamapps\common\Game Dev Tycoon\nw.exe
FirewallRules: [UDP Query User{747FA6AA-96B0-49A0-8AAA-91A6BE1767A0}C:\program files\java\jre1.8.0_51\bin\java.exe] => (Allow) C:\program files\java\jre1.8.0_51\bin\java.exe
FirewallRules: [TCP Query User{759B3C41-2B43-41EF-87FE-7E22E572A66B}C:\program files\java\jre1.8.0_51\bin\java.exe] => (Allow) C:\program files\java\jre1.8.0_51\bin\java.exe
FirewallRules: [{A84B1002-6202-459F-B739-FF14A5875216}] => (Allow) I:\Program Files (x86)\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe
FirewallRules: [{32F1E975-FB55-4956-B6B5-476812813145}] => (Allow) I:\Program Files (x86)\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe
FirewallRules: [{64853C43-BC84-486A-93F6-FB055867E61E}] => (Allow) C:\Program Files\Vuze\Azureus.exe
FirewallRules: [{F8A8DB30-2B52-45C2-8900-BF84B81EF2BE}] => (Allow) C:\Program Files\Vuze\Azureus.exe
FirewallRules: [{3AB29B73-9793-40EE-B1E6-FB4697F148D1}] => (Allow) J:\Program Files (x86)\SteamLibrary\steamapps\common\ARK\ShooterGame\Binaries\Win64\ShooterGame.exe
FirewallRules: [{108C420E-D26C-4C35-9235-4248D4516ABE}] => (Allow) J:\Program Files (x86)\SteamLibrary\steamapps\common\ARK\ShooterGame\Binaries\Win64\ShooterGame.exe
FirewallRules: [{9C324EE5-AC64-4C58-8910-E166ED010BA1}] => (Allow) I:\Program Files (x86)\Steam\steamapps\common\SpaceEngineers\Bin64\SpaceEngineers.exe
FirewallRules: [{C2FE5228-15B6-494A-A232-D714F3D87C31}] => (Allow) I:\Program Files (x86)\Steam\steamapps\common\SpaceEngineers\Bin64\SpaceEngineers.exe
FirewallRules: [{9A18C41E-2F49-47BE-B3AD-323809FC4C65}] => (Allow) J:\Program Files (x86)\SteamLibrary\steamapps\common\Homeworld\HWLauncher\Launcher.exe
FirewallRules: [{754AA452-52F6-412D-A468-FA339C8001EE}] => (Allow) J:\Program Files (x86)\SteamLibrary\steamapps\common\Homeworld\HWLauncher\Launcher.exe
FirewallRules: [{D142F07D-AB7A-4CD8-82C8-A1DF680AD432}] => (Allow) J:\Program Files (x86)\SteamLibrary\steamapps\common\The Forest\TheForest.exe
FirewallRules: [{D226581D-2946-42DD-8528-AABDF183D7F2}] => (Allow) J:\Program Files (x86)\SteamLibrary\steamapps\common\The Forest\TheForest.exe
FirewallRules: [{B57D8E33-A224-4C1D-86C5-B22C8B12541A}] => (Allow) J:\Program Files (x86)\SteamLibrary\steamapps\common\star conflict\game.exe
FirewallRules: [{16E50EC5-1D12-4A62-BBBA-5E86876920FE}] => (Allow) J:\Program Files (x86)\SteamLibrary\steamapps\common\star conflict\game.exe
FirewallRules: [{0581C265-0A4F-4B45-9928-E4A62723B2D4}] => (Allow) J:\Program Files (x86)\SteamLibrary\steamapps\common\Marvel Heroes\UnrealEngine3\Binaries\Win64\MarvelHeroes2015.exe
FirewallRules: [{2C3DCFBA-9F7B-4694-ADC8-4EF99BC64384}] => (Allow) J:\Program Files (x86)\SteamLibrary\steamapps\common\Marvel Heroes\UnrealEngine3\Binaries\Win64\MarvelHeroes2015.exe
FirewallRules: [UDP Query User{64161A0E-B1EC-4A44-A514-D4BF27BB00B8}C:\program files\firestorm-betax64\slvoice.exe] => (Allow) C:\program files\firestorm-betax64\slvoice.exe
FirewallRules: [TCP Query User{BB96EB6A-D11F-4B93-8A93-9FD74DC03497}C:\program files\firestorm-betax64\slvoice.exe] => (Allow) C:\program files\firestorm-betax64\slvoice.exe
FirewallRules: [{7DCDC7ED-C3E7-4906-93EB-66115056D012}] => (Allow) LPort=3306
FirewallRules: [{9D31AB4A-3CB2-4496-9FD4-BABB60770257}] => (Allow) LPort=3306
FirewallRules: [UDP Query User{E0F66568-9E99-432B-B007-DA980FE5328F}D:\program files (x86)\steam\steamapps\common\left 4 dead 2\left4dead2.exe] => (Allow) D:\program files (x86)\steam\steamapps\common\left 4 dead 2\left4dead2.exe
FirewallRules: [TCP Query User{99750164-0DFE-4B82-BBC2-4405E9AC9B49}D:\program files (x86)\steam\steamapps\common\left 4 dead 2\left4dead2.exe] => (Allow) D:\program files (x86)\steam\steamapps\common\left 4 dead 2\left4dead2.exe
FirewallRules: [{E2AE1E35-94E5-4C83-A839-FA420C9A3734}] => (Allow) I:\Program Files (x86)\Steam\steamapps\common\GarrysMod\hl2.exe
FirewallRules: [{E3306F43-BE6F-4496-9318-A659C477C8B9}] => (Allow) I:\Program Files (x86)\Steam\steamapps\common\GarrysMod\hl2.exe
FirewallRules: [{7675D0C4-6BBB-45F6-B2CF-C49E87AA62A9}] => (Allow) I:\Program Files (x86)\Steam\steamapps\common\Half-Life 2\hl2.exe
FirewallRules: [{84C1EC93-D6F6-497D-B956-C818FA67BEC4}] => (Allow) I:\Program Files (x86)\Steam\steamapps\common\Half-Life 2\hl2.exe
FirewallRules: [{164F8A00-35FF-44F5-99BA-ACDB12BDE0E4}] => (Allow) I:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{BF7001F7-490E-4EFF-B0BE-9AF8B2CB2E15}] => (Allow) I:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{4ADDD993-D6C4-4614-8B16-CC1BFFD29C80}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{6F85200E-993E-45F6-B8CF-7838E52E7259}] => (Allow) I:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{0722BC3A-C074-4F96-8830-9985DE03C95B}] => (Allow) I:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{89D698C9-0226-4558-95EA-954CCBFDDF30}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{37B53344-F728-4FF8-84D6-8E816BE6CB55}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{3C0CC382-AA44-4A60-9E81-E6B95B6F302C}] => (Allow) I:\Program Files (x86)\Steam\steamapps\common\3DMark\3DMarkLauncher.exe
FirewallRules: [{F79BE50F-E44E-4105-83B2-FD449FD93062}] => (Allow) I:\Program Files (x86)\Steam\steamapps\common\3DMark\3DMarkLauncher.exe
FirewallRules: [{2038EFB2-6CA0-4F27-9062-C3465B6D00C2}] => (Allow) I:\Program Files (x86)\Steam\steamapps\common\3DMark\bin\x86\3DMark.exe
FirewallRules: [{A024198E-9BB3-432C-AE21-4264B8EE9497}] => (Allow) I:\Program Files (x86)\Steam\steamapps\common\3DMark\bin\x86\3DMark.exe
FirewallRules: [{E5B66365-77DC-4F81-AD29-77BBA255BA0E}] => (Allow) I:\Program Files (x86)\Steam\steamapps\common\3DMark\bin\x64\3DMark.exe
FirewallRules: [{3DA13208-5B01-417C-BD4A-4FBAC43B747B}] => (Allow) I:\Program Files (x86)\Steam\steamapps\common\3DMark\bin\x64\3DMark.exe
FirewallRules: [{D32D5EE5-2C6D-4458-B24E-7F3AA6E9E243}] => (Allow) J:\Program Files (x86)\SteamLibrary\steamapps\common\Clicker Heroes\Clicker Heroes.exe
FirewallRules: [{40BCD2C4-275C-49D3-93D2-47323172E857}] => (Allow) J:\Program Files (x86)\SteamLibrary\steamapps\common\Clicker Heroes\Clicker Heroes.exe
FirewallRules: [{0B7C82C2-F617-4344-AAFC-978F4178647D}] => (Allow) J:\Program Files (x86)\SteamLibrary\steamapps\common\Blender\blender.exe
FirewallRules: [{9993AA5B-35A2-40B4-9068-85377FBC81A9}] => (Allow) J:\Program Files (x86)\SteamLibrary\steamapps\common\Blender\blender.exe
FirewallRules: [{A0FD8D66-5D06-431A-889F-CD161A8402B4}] => (Allow) J:\Program Files (x86)\SteamLibrary\steamapps\common\Saints Row Gat out of Hell\SaintsRowGatOutOfHell.exe
FirewallRules: [{5631858D-1C24-402F-B566-3111D3D4B7B3}] => (Allow) J:\Program Files (x86)\SteamLibrary\steamapps\common\Saints Row Gat out of Hell\SaintsRowGatOutOfHell.exe
FirewallRules: [TCP Query User{F5652633-8CC1-4EB8-B686-CC4A4ABFFEA7}C:\program files\firestorm-releasex64\slvoice.exe] => (Allow) C:\program files\firestorm-releasex64\slvoice.exe
FirewallRules: [UDP Query User{FEDCC0D4-FBA3-4BC6-B705-F9C286B5AB6C}C:\program files\firestorm-releasex64\slvoice.exe] => (Allow) C:\program files\firestorm-releasex64\slvoice.exe
FirewallRules: [TCP Query User{37BF9376-A956-4E4A-9315-7025C3D1ED48}J:\program files\cloud imperium games\patcher\cigpatcher.exe] => (Allow) J:\program files\cloud imperium games\patcher\cigpatcher.exe
FirewallRules: [UDP Query User{4A40EF62-8B48-4FD6-A48E-10A01719BE56}J:\program files\cloud imperium games\patcher\cigpatcher.exe] => (Allow) J:\program files\cloud imperium games\patcher\cigpatcher.exe
FirewallRules: [TCP Query User{745ECD8D-11E6-46DA-8C08-764006F2CCDD}J:\program files\cloud imperium games\starcitizen\public\bin64\starcitizen.exe] => (Allow) J:\program files\cloud imperium games\starcitizen\public\bin64\starcitizen.exe
FirewallRules: [UDP Query User{43C346FD-1028-46F6-AA4A-3F082E8E76A8}J:\program files\cloud imperium games\starcitizen\public\bin64\starcitizen.exe] => (Allow) J:\program files\cloud imperium games\starcitizen\public\bin64\starcitizen.exe
FirewallRules: [TCP Query User{6B15BEE6-D743-4C58-AE36-833226980C80}J:\program files (x86)\starcraft ii - legacy of the void beta\versions\base37164\sc2_x64.exe] => (Allow) J:\program files (x86)\starcraft ii - legacy of the void beta\versions\base37164\sc2_x64.exe
FirewallRules: [UDP Query User{7C96CF08-885C-463C-8C93-9CB554A2A9EB}J:\program files (x86)\starcraft ii - legacy of the void beta\versions\base37164\sc2_x64.exe] => (Allow) J:\program files (x86)\starcraft ii - legacy of the void beta\versions\base37164\sc2_x64.exe
FirewallRules: [{8CA49AA9-A00D-4AD1-BEB6-CA0C8DF05136}] => (Allow) J:\Program Files (x86)\SteamLibrary\steamapps\common\StarMade\StarMade-starter.exe
FirewallRules: [{7E63E245-653F-4BAF-82E0-F9BF15C98982}] => (Allow) J:\Program Files (x86)\SteamLibrary\steamapps\common\StarMade\StarMade-starter.exe
FirewallRules: [{CCA2C664-2407-4B68-817C-6E1161BF9C37}] => (Allow) J:\Program Files (x86)\SteamLibrary\steamapps\common\OPPW3\oppw3.exe
FirewallRules: [{0432B0AE-7B8D-4BA2-9210-54A44FB58EC7}] => (Allow) J:\Program Files (x86)\SteamLibrary\steamapps\common\OPPW3\oppw3.exe
FirewallRules: [{DFBF7DED-DB50-41FF-B4CD-391732033B5D}] => (Allow) J:\Program Files (x86)\SteamLibrary\steamapps\common\FINAL FANTASY XIII-2\FFXiii2Launcher.exe
FirewallRules: [{93B2A3DC-CEC5-40AF-B37D-14E3A56AF6BE}] => (Allow) J:\Program Files (x86)\SteamLibrary\steamapps\common\FINAL FANTASY XIII-2\FFXiii2Launcher.exe
FirewallRules: [{7234AC54-8A18-466F-B0A7-2F3763833500}] => (Allow) J:\Program Files (x86)\SteamLibrary\steamapps\common\BorderlandsPreSequel\Binaries\Win32\Launcher.exe
FirewallRules: [{7C113E7C-675C-4920-96DD-B7082222FC28}] => (Allow) J:\Program Files (x86)\SteamLibrary\steamapps\common\BorderlandsPreSequel\Binaries\Win32\Launcher.exe
FirewallRules: [TCP Query User{82EA0284-25FC-4F3C-83D5-C8464399D6B2}J:\program files (x86)\steamlibrary\steamapps\common\borderlandspresequel\binaries\win32\borderlandspresequel.exe] => (Allow) J:\program files (x86)\steamlibrary\steamapps\common\borderlandspresequel\binaries\win32\borderlandspresequel.exe
FirewallRules: [UDP Query User{5E47433D-A45C-42B9-9EE4-58B47CC4341E}J:\program files (x86)\steamlibrary\steamapps\common\borderlandspresequel\binaries\win32\borderlandspresequel.exe] => (Allow) J:\program files (x86)\steamlibrary\steamapps\common\borderlandspresequel\binaries\win32\borderlandspresequel.exe
FirewallRules: [TCP Query User{B23777F6-8B79-4E0C-9900-BF49C0C99639}J:\program files (x86)\steamlibrary\steamapps\common\asteroids\aslauncher.exe] => (Allow) J:\program files (x86)\steamlibrary\steamapps\common\asteroids\aslauncher.exe
FirewallRules: [UDP Query User{F205CE4C-8C3A-4B38-9B40-5082AF46F4F5}J:\program files (x86)\steamlibrary\steamapps\common\asteroids\aslauncher.exe] => (Allow) J:\program files (x86)\steamlibrary\steamapps\common\asteroids\aslauncher.exe
FirewallRules: [TCP Query User{BC14774B-3AFE-4F40-B2A4-9A7792DD36C8}J:\program files (x86)\steamlibrary\steamapps\common\asteroids\aslauncher.exe.new.exe] => (Allow) J:\program files (x86)\steamlibrary\steamapps\common\asteroids\aslauncher.exe.new.exe
FirewallRules: [UDP Query User{B2F2A757-0077-49A9-B34F-7C646F4D179C}J:\program files (x86)\steamlibrary\steamapps\common\asteroids\aslauncher.exe.new.exe] => (Allow) J:\program files (x86)\steamlibrary\steamapps\common\asteroids\aslauncher.exe.new.exe
FirewallRules: [{2B845BE4-0F6C-4E28-9DE8-59ECB69C2A7C}] => (Allow) J:\Program Files (x86)\SteamLibrary\steamapps\common\Asteroids\Game.exe
FirewallRules: [TCP Query User{343A65E7-9868-43CC-A8F3-712AACD7DDA4}J:\program files (x86)\steamlibrary\steamapps\common\aperture tag\portal2.exe] => (Allow) J:\program files (x86)\steamlibrary\steamapps\common\aperture tag\portal2.exe
FirewallRules: [UDP Query User{B72E89B8-80B6-4408-AAF3-DA299F44BD50}J:\program files (x86)\steamlibrary\steamapps\common\aperture tag\portal2.exe] => (Allow) J:\program files (x86)\steamlibrary\steamapps\common\aperture tag\portal2.exe
FirewallRules: [{FA9A058C-CFD8-4559-9578-E7DADE9E561F}] => (Allow) J:\Program Files (x86)\SteamLibrary\steamapps\common\Grand Theft Auto V\GTA5.exe
FirewallRules: [{C533E7FB-7BCD-4C62-A61A-177676CF3808}] => (Allow) J:\Program Files (x86)\SteamLibrary\steamapps\common\Grand Theft Auto V\GTA5.exe
FirewallRules: [TCP Query User{A4D56A3E-231A-41BC-A2BF-A30012C25819}J:\program files (x86)\steamlibrary\steamapps\common\crysis 2\bin32\crysis2.exe] => (Allow) J:\program files (x86)\steamlibrary\steamapps\common\crysis 2\bin32\crysis2.exe
FirewallRules: [UDP Query User{270D6C89-5396-49F6-99C5-1CD2626A85FF}J:\program files (x86)\steamlibrary\steamapps\common\crysis 2\bin32\crysis2.exe] => (Allow) J:\program files (x86)\steamlibrary\steamapps\common\crysis 2\bin32\crysis2.exe
FirewallRules: [{D71F7323-896B-4B39-AE05-C6A32B3B530D}] => (Allow) J:\Program Files (x86)\SteamLibrary\steamapps\common\MGS_TPP\mgsvtpp.exe
FirewallRules: [{1AAC77A7-CAF2-47E1-8251-61E016CC3D47}] => (Allow) J:\Program Files (x86)\SteamLibrary\steamapps\common\MGS_TPP\mgsvtpp.exe
FirewallRules: [{7BEB4AE5-3064-4AD7-A72D-26BB4CBEFE2A}] => (Allow) J:\Program Files (x86)\SteamLibrary\steamapps\common\X Rebirth\XRebirth.exe
FirewallRules: [{C8FD374C-88BE-460F-B82D-BAF92C4AD4F2}] => (Allow) J:\Program Files (x86)\SteamLibrary\steamapps\common\X Rebirth\XRebirth.exe
FirewallRules: [{599FA0F8-D077-4422-8DC3-D27AB35746E8}] => (Allow) I:\Program Files (x86)\Steam\steamapps\common\Evolve\Bin64_SteamRetail\Evolve.exe
FirewallRules: [{B9D473C0-BA08-4CDA-85DF-F1B0A4AC1675}] => (Allow) I:\Program Files (x86)\Steam\steamapps\common\Evolve\Bin64_SteamRetail\Evolve.exe
FirewallRules: [{517D004E-29E4-442C-AEFD-CAD3FB05B6B6}] => (Allow) J:\Program Files (x86)\SteamLibrary\steamapps\common\Saints Row IV\SaintsRowIV.exe
FirewallRules: [{478F9B71-97A5-4F5D-B23A-2C17B127FC5F}] => (Allow) J:\Program Files (x86)\SteamLibrary\steamapps\common\Saints Row IV\SaintsRowIV.exe
FirewallRules: [TCP Query User{2B4744C4-32E8-429D-8D42-7320313B14F6}C:\program files\java\jre1.8.0_60\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_60\bin\javaw.exe
FirewallRules: [UDP Query User{AD6FC3B7-327F-446A-A371-6DAA3D4899F0}C:\program files\java\jre1.8.0_60\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_60\bin\javaw.exe
FirewallRules: [TCP Query User{B2B0F21A-F54C-45D9-9DE9-7AA46613EB25}J:\program files\epic games\4.9\engine\binaries\win64\ue4editor.exe] => (Allow) J:\program files\epic games\4.9\engine\binaries\win64\ue4editor.exe
FirewallRules: [UDP Query User{C8470D55-440B-47C1-AE53-8DA0E5BBC93C}J:\program files\epic games\4.9\engine\binaries\win64\ue4editor.exe] => (Allow) J:\program files\epic games\4.9\engine\binaries\win64\ue4editor.exe
FirewallRules: [TCP Query User{9907C837-4EAE-46A2-894B-356A4B0D61AC}J:\program files\epic games\4.9\engine\binaries\dotnet\swarmagent.exe] => (Allow) J:\program files\epic games\4.9\engine\binaries\dotnet\swarmagent.exe
FirewallRules: [UDP Query User{D5337C2C-18DE-409F-BA1A-6A01A9C90660}J:\program files\epic games\4.9\engine\binaries\dotnet\swarmagent.exe] => (Allow) J:\program files\epic games\4.9\engine\binaries\dotnet\swarmagent.exe
FirewallRules: [TCP Query User{F377E7C7-53CE-4A5D-8CCE-C67995CF0C10}J:\program files\unreal\unrealtournamentdev\engine\binaries\win64\ue4-win64-test.exe] => (Allow) J:\program files\unreal\unrealtournamentdev\engine\binaries\win64\ue4-win64-test.exe
FirewallRules: [UDP Query User{D0C2019A-1134-4DBF-9B6C-2BCD01341C9E}J:\program files\unreal\unrealtournamentdev\engine\binaries\win64\ue4-win64-test.exe] => (Allow) J:\program files\unreal\unrealtournamentdev\engine\binaries\win64\ue4-win64-test.exe
FirewallRules: [{5E70BEFF-9896-4258-A4C5-5B171C9FF6B7}] => (Allow) I:\Program Files (x86)\Steam\steamapps\common\Dungeon Defenders 2\DunDefLauncher.exe
FirewallRules: [{2A7F21E0-693A-4C69-A869-D8C2D668FAEE}] => (Allow) I:\Program Files (x86)\Steam\steamapps\common\Dungeon Defenders 2\DunDefLauncher.exe
FirewallRules: [{C4CF72A4-E059-4EA9-BF8A-B7F73C4D8862}] => (Allow) I:\Program Files (x86)\Steam\steamapps\common\AdVenture Capitalist\adventure-capitalist.exe
FirewallRules: [{9EB28605-3649-4FD7-9186-373CC6A4DEFE}] => (Allow) I:\Program Files (x86)\Steam\steamapps\common\AdVenture Capitalist\adventure-capitalist.exe
FirewallRules: [{0D127286-CB4A-4DCC-B41A-12E7F661015F}] => (Allow) J:\Program Files (x86)\SteamLibrary\steamapps\common\Take On Mars\TKOM.exe
FirewallRules: [{18FF03ED-25AA-4758-AFE3-AD3D6B5B874F}] => (Allow) J:\Program Files (x86)\SteamLibrary\steamapps\common\Take On Mars\TKOM.exe
FirewallRules: [{1A2B3F54-C84E-46CB-9ECB-E2F695FCAEEE}] => (Allow) J:\Program Files (x86)\SteamLibrary\steamapps\common\Take On Mars\TKOM_dev.exe
FirewallRules: [{4761F78D-7781-48AC-B5BC-B24EC35AFE96}] => (Allow) J:\Program Files (x86)\SteamLibrary\steamapps\common\Take On Mars\TKOM_dev.exe
FirewallRules: [{CA671494-3289-4BF2-9843-6F8B2E308516}] => (Allow) J:\Program Files (x86)\SteamLibrary\steamapps\common\Take On Mars\TKOM_loader.exe
FirewallRules: [{94E5AA25-9A82-4201-A0A4-5E3E28A57D1A}] => (Allow) J:\Program Files (x86)\SteamLibrary\steamapps\common\Take On Mars\TKOM_loader.exe
FirewallRules: [{2409C3C8-EAED-411D-910A-FB13F4AA02CE}] => (Allow) J:\Program Files (x86)\SteamLibrary\steamapps\common\DB Xenoverse\DBXV.exe
FirewallRules: [{D333B3D2-C033-439D-B811-068FEDEBF928}] => (Allow) J:\Program Files (x86)\SteamLibrary\steamapps\common\DB Xenoverse\DBXV.exe
FirewallRules: [{A5BE3477-8340-48C8-B6C0-709371D0B26C}] => (Allow) J:\Program Files (x86)\SteamLibrary\steamapps\common\Warframe\Warframe.exe
FirewallRules: [{B5FC34FB-E28E-485B-877A-9CEB91F30DA3}] => (Allow) J:\Program Files (x86)\SteamLibrary\steamapps\common\Warframe\Warframe.x64.exe
FirewallRules: [{EAAFA84F-57A9-4CF3-8E70-0D446E7E1277}] => (Allow) J:\Program Files (x86)\SteamLibrary\steamapps\common\Warframe\Warframe.exe
FirewallRules: [{26C4BE09-0CA6-4D96-B803-93307E5E6778}] => (Allow) J:\Program Files (x86)\SteamLibrary\steamapps\common\Warframe\Warframe.x64.exe
FirewallRules: [{1DC7F26F-2BA3-4C8A-B323-725F06FD5FFD}] => (Allow) J:\Program Files (x86)\SteamLibrary\steamapps\common\Warframe\Tools\Launcher.exe
FirewallRules: [{539BC554-825E-4A32-9038-C5CB9A6E0AB2}] => (Allow) J:\Program Files (x86)\SteamLibrary\steamapps\common\Warframe\Tools\RemoteCrashSender.exe
FirewallRules: [{8A00F051-D006-4616-8810-471C4FA780B1}] => (Allow) J:\Program Files (x86)\SteamLibrary\steamapps\common\Warframe\Warframe.exe
FirewallRules: [{9221677B-48C6-4763-8528-B916A4CFA1E8}] => (Allow) J:\Program Files (x86)\SteamLibrary\steamapps\common\Warframe\Warframe.x64.exe
FirewallRules: [{68A41C77-2574-4F82-8A25-5B9E05324162}] => (Allow) J:\Program Files (x86)\SteamLibrary\steamapps\common\Warframe\Warframe.exe
FirewallRules: [{842F7AC6-62DB-46D9-84E4-A9283EB6EA21}] => (Allow) J:\Program Files (x86)\SteamLibrary\steamapps\common\Warframe\Warframe.x64.exe
FirewallRules: [{D3E6A6C8-0769-4DC2-B0E0-0054C26B69BD}] => (Allow) J:\Program Files (x86)\SteamLibrary\steamapps\common\Warframe\Tools\Launcher.exe
FirewallRules: [{9C41A322-EDAE-4975-8A14-98F1E3196DE6}] => (Allow) J:\Program Files (x86)\SteamLibrary\steamapps\common\Warframe\Tools\RemoteCrashSender.exe
FirewallRules: [{7094DFA9-0EE4-4870-8750-D3D419162D90}] => (Allow) I:\Program Files (x86)\Origin Games\SimCity\SimCity\SimCity.exe
FirewallRules: [{68D7355B-54C5-458B-9B75-4D1B52CB0E74}] => (Allow) I:\Program Files (x86)\Origin Games\SimCity\SimCity\SimCity.exe
FirewallRules: [{346312FB-FDB3-419D-B4C6-8480A8556F48}] => (Allow) J:\Program Files (x86)\Origen games\Titanfall\Titanfall.exe
FirewallRules: [{9F34B5C0-EE80-495A-A0F8-EC16E5B05465}] => (Allow) J:\Program Files (x86)\Origen games\Titanfall\Titanfall.exe
FirewallRules: [{C76FBF51-5246-44BF-A07B-D377E0CB9651}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{81A5CCA9-889B-451B-A070-16350CD25359}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{AC3356EC-8702-4BFF-BDA3-5BBC9098ECB1}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{614F9373-6837-4932-8AED-95E62B57A584}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{570C6208-2FAA-461C-9D1A-86173A5034D4}] => (Allow) I:\Program Files (x86)\Origin Games\Crysis\Bin32\Crysis.exe
FirewallRules: [{2E55175E-AFCC-4B75-9EF2-398CBE14ADF0}] => (Allow) I:\Program Files (x86)\Origin Games\Crysis\Bin32\Crysis.exe
FirewallRules: [{C9758687-856C-4310-81B5-5B06A13F7EE5}] => (Allow) I:\Program Files (x86)\Origin Games\Crysis 3\Bin32\Crysis3.exe
FirewallRules: [{248E8970-BD67-4238-86FE-ECF3DA1B7BD3}] => (Allow) I:\Program Files (x86)\Origin Games\Crysis 3\Bin32\Crysis3.exe
FirewallRules: [{C41A7B36-0184-4449-9BC7-A4D0EBD9782B}] => (Allow) I:\Program Files (x86)\Origin Games\Crysis 3\Crysis 3 - Digital Deluxe Edition Content\Launcher.exe
FirewallRules: [{0544F0EE-869F-4AC6-9B00-1C541D6FF54F}] => (Allow) I:\Program Files (x86)\Origin Games\Crysis 3\Crysis 3 - Digital Deluxe Edition Content\Launcher.exe
FirewallRules: [{53C673D0-EDB7-4548-B967-CEB46835870C}] => (Allow) I:\Program Files (x86)\Origin Games\Dragon Age\bin_ship\daorigins.exe
FirewallRules: [{BA4C9C4D-3635-404B-B184-BF9A15A42467}] => (Allow) I:\Program Files (x86)\Origin Games\Dragon Age\bin_ship\daorigins.exe
FirewallRules: [{67BADAAC-B655-4FDA-A56D-6A1269DB0F0D}] => (Allow) C:\Program Files (x86)\Raptr\raptr.exe
FirewallRules: [{24CF4069-1834-4AF8-96BC-6090785D2B0E}] => (Allow) C:\Program Files (x86)\Raptr\raptr.exe
FirewallRules: [{ECAEFDA0-B5BE-4119-99CA-1A8466C233E5}] => (Allow) C:\Program Files (x86)\Raptr\raptr_im.exe
FirewallRules: [{037CDD72-7B61-4A71-9F71-D0CA71445473}] => (Allow) C:\Program Files (x86)\Raptr\raptr_im.exe
FirewallRules: [{20D4067C-70F9-4B01-8677-BB27F95A0342}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD15\PowerDVD.exe
FirewallRules: [{D46DFE3D-E692-4FE6-88E3-3BA96D5CB560}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD15\Kernel\DMS\CLMSServerPDVD15.exe
FirewallRules: [{B682FC37-1A66-45C4-9091-9900E4BB7EB5}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD15\PowerDVD15Agent.exe
FirewallRules: [{EAE00E5F-A266-4D7C-BA7B-073F6EEEAD17}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD15\Movie\PowerDVDMovie.exe
FirewallRules: [{499D445E-6B79-4167-9FFE-6F0F148BEC83}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD15\Movie\PowerDVD Cinema\PowerDVDCinema.exe
FirewallRules: [{00B74323-CA34-4252-8A35-B11F848AF67B}] => (Allow) I:\Program Files (x86)\Steam\steamapps\common\Dungeon Defenders\Binaries\Win32\DungeonDefenders.exe
FirewallRules: [{6013D4D1-398F-4CCF-92E2-A82F15F266F9}] => (Allow) I:\Program Files (x86)\Steam\steamapps\common\Dungeon Defenders\Binaries\Win32\DungeonDefenders.exe
FirewallRules: [{91AAA5DA-F9E4-4DEB-896F-15BEB6C829C4}] => (Allow) I:\Program Files (x86)\Steam\steamapps\common\Day of Defeat Source\hl2.exe
FirewallRules: [{F969DB3D-F549-44F7-B1AA-B8F90556143D}] => (Allow) I:\Program Files (x86)\Steam\steamapps\common\Day of Defeat Source\hl2.exe
FirewallRules: [{CE3EB05E-0829-4227-8F4C-1FA771FDFC00}] => (Allow) I:\Program Files (x86)\Steam\steamapps\common\Counter-Strike Source\hl2.exe
FirewallRules: [{6007A199-B3C0-41C9-B9DF-AB5A30EA9948}] => (Allow) I:\Program Files (x86)\Steam\steamapps\common\Counter-Strike Source\hl2.exe
FirewallRules: [{BE70D0C1-3416-4461-8609-8ABBE46F711A}] => (Allow) J:\Program Files (x86)\SteamLibrary\steamapps\common\Half-Life 2 Deathmatch\hl2.exe
FirewallRules: [{B52C5D56-6BB0-42F6-AEF4-27E802C82A0D}] => (Allow) J:\Program Files (x86)\SteamLibrary\steamapps\common\Half-Life 2 Deathmatch\hl2.exe
FirewallRules: [{74F124C8-9B9A-419E-ADBF-6B504F6A2833}] => (Allow) I:\Program Files (x86)\Steam\steamapps\common\RailWorks\RailWorks.exe
FirewallRules: [{765341B2-C9A2-4967-9A11-E1FCA7222A45}] => (Allow) I:\Program Files (x86)\Steam\steamapps\common\RailWorks\RailWorks.exe
FirewallRules: [{D5E9B070-904B-45F3-8D4D-DBC741503B93}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{4F27367D-5910-4078-83CB-6B734E363B1E}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{45EEE2B4-E0BE-4310-BF99-373B0EE23FA5}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{86C7BDB4-C13C-460D-8FC9-98D3EBF2BB0B}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{56EB30FE-6145-4547-90F9-242512BB2960}] => (Allow) C:\Program Files\iTunes\iTunes.exe
FirewallRules: [{ED865C50-72E9-43BD-89B5-2FF64F53FC16}] => (Allow) I:\Program Files (x86)\Origin Games\Command and Conquer The Ultimate Collection Additional Content\Launcher.exe
FirewallRules: [{6B6BFE23-841F-4770-8399-D3D9D3224E84}] => (Allow) I:\Program Files (x86)\Origin Games\Command and Conquer The Ultimate Collection Additional Content\Launcher.exe
FirewallRules: [TCP Query User{30134FC8-3963-4D7C-92C9-838FC4D21E16}C:\program files\java\jre1.8.0_60\bin\java.exe] => (Allow) C:\program files\java\jre1.8.0_60\bin\java.exe
FirewallRules: [UDP Query User{B02507DE-9F7B-4E40-B7C5-8CBA10AC5C6D}C:\program files\java\jre1.8.0_60\bin\java.exe] => (Allow) C:\program files\java\jre1.8.0_60\bin\java.exe
FirewallRules: [{61C64D75-AD16-448B-887A-87A6091437DF}] => (Allow) I:\Program Files (x86)\Steam\steamapps\common\gamemaker_studio\GameMakerPlayer.exe
FirewallRules: [{ACAB7BF8-73F8-457F-B6D7-48E9EFBA0D79}] => (Allow) I:\Program Files (x86)\Steam\steamapps\common\gamemaker_studio\GameMakerPlayer.exe
FirewallRules: [{EAE6A61A-A3E4-412F-8A82-81C133F7FE98}] => (Allow) J:\Program Files (x86)\SteamLibrary\steamapps\common\Half-Life 1 Source Deathmatch\hl2.exe
FirewallRules: [{5EB853D2-822F-44CC-89ED-3779DD9E1382}] => (Allow) J:\Program Files (x86)\SteamLibrary\steamapps\common\Half-Life 1 Source Deathmatch\hl2.exe
FirewallRules: [{857EEF41-867A-466A-84A8-55DA4E9794D5}] => (Allow) I:\Program Files (x86)\Steam\steamapps\common\Dawn of War 2\DOW2.exe
FirewallRules: [{8C9EDB74-A3E2-48CD-8048-83C1CFABE08B}] => (Allow) I:\Program Files (x86)\Steam\steamapps\common\Dawn of War 2\DOW2.exe
FirewallRules: [{EF62B6DF-EEE7-4E8D-A0FB-EB9C86C90558}] => (Allow) J:\Program Files (x86)\steam\steamapps\common\left 4 dead 2\left4dead2.exe
FirewallRules: [{F77F8922-7369-4651-9FDB-F77CF2499E79}] => (Allow) J:\Program Files (x86)\steam\steamapps\common\left 4 dead 2\left4dead2.exe
FirewallRules: [{3F677AAB-DADA-44E6-955F-3073BE123BF2}] => (Allow) LPort=82
FirewallRules: [{A9689BB0-4F29-437F-9669-E79FCDF0E585}] => (Allow) %SystemDrive%\server\afterburner\MSIAfterburnerRemoteServer.exe
FirewallRules: [{B12A8E29-C41C-45A3-8352-1C3C0B4BFCDE}] => (Allow) %SystemDrive%\server\afterburner\MSIAfterburnerRemoteServer.exe
FirewallRules: [{F6D39DAA-A1A9-4D7D-A6DA-C32F29FED357}] => (Allow) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
FirewallRules: [{2A2023A5-8F23-45C3-BA28-9C6042BC814F}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{69313EA1-23DA-4BE5-B93A-B1548991532A}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{EB60DC04-8BB8-4321-85BD-D5D41EEAB9F5}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{DC24E087-B398-42A0-836F-E9D4FF54F3B9}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe] => Enabled:Spybot - Search & Destroy tray access
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe] => Enabled:Spybot-S&D 2 Scanner Service
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe] => Enabled:Spybot-S&D 2 Updater
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe] => Enabled:Spybot-S&D 2 Background update service

==================== Faulty Device Manager Devices =============

Name: High Definition Audio Bus
Description: High Definition Audio Bus
Class Guid: {4d36e97d-e325-11ce-bfc1-08002be10318}
Manufacturer: AMD
Service: HDAudBus
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.


==================== Event log errors: =========================

Application errors:
==================
Error: (10/05/2015 03:46:41 AM) (Source: ESENT) (EventID: 413) (User: )
Description: SettingSyncHost (6664) Unable to create a new logfile because the database cannot write to the log drive. The drive may be read-only, out of disk space, misconfigured, or corrupted. Error -1032.

Error: (10/05/2015 03:46:41 AM) (Source: ESENT) (EventID: 488) (User: )
Description: SettingSyncHost (6664) An attempt to create the file "C:\WINDOWS\system32\edbtmp.log" failed with system error 5 (0x00000005): "Access is denied. ".  The create file operation will fail with error -1032 (0xfffffbf8).

Error: (10/05/2015 03:46:30 AM) (Source: ESENT) (EventID: 413) (User: )
Description: SettingSyncHost (6664) Unable to create a new logfile because the database cannot write to the log drive. The drive may be read-only, out of disk space, misconfigured, or corrupted. Error -1032.

Error: (10/05/2015 03:46:30 AM) (Source: ESENT) (EventID: 488) (User: )
Description: SettingSyncHost (6664) An attempt to create the file "C:\WINDOWS\system32\edbtmp.log" failed with system error 5 (0x00000005): "Access is denied. ".  The create file operation will fail with error -1032 (0xfffffbf8).

Error: (10/05/2015 03:46:20 AM) (Source: ESENT) (EventID: 413) (User: )
Description: SettingSyncHost (6664) Unable to create a new logfile because the database cannot write to the log drive. The drive may be read-only, out of disk space, misconfigured, or corrupted. Error -1032.

Error: (10/05/2015 03:46:20 AM) (Source: ESENT) (EventID: 488) (User: )
Description: SettingSyncHost (6664) An attempt to create the file "C:\WINDOWS\system32\edbtmp.log" failed with system error 5 (0x00000005): "Access is denied. ".  The create file operation will fail with error -1032 (0xfffffbf8).

Error: (10/05/2015 03:46:10 AM) (Source: ESENT) (EventID: 413) (User: )
Description: SettingSyncHost (6664) Unable to create a new logfile because the database cannot write to the log drive. The drive may be read-only, out of disk space, misconfigured, or corrupted. Error -1032.

Error: (10/05/2015 03:46:10 AM) (Source: ESENT) (EventID: 488) (User: )
Description: SettingSyncHost (6664) An attempt to create the file "C:\WINDOWS\system32\edbtmp.log" failed with system error 5 (0x00000005): "Access is denied. ".  The create file operation will fail with error -1032 (0xfffffbf8).

Error: (10/05/2015 03:45:59 AM) (Source: ESENT) (EventID: 413) (User: )
Description: SettingSyncHost (6664) Unable to create a new logfile because the database cannot write to the log drive. The drive may be read-only, out of disk space, misconfigured, or corrupted. Error -1032.

Error: (10/05/2015 03:45:59 AM) (Source: ESENT) (EventID: 488) (User: )
Description: SettingSyncHost (6664) An attempt to create the file "C:\WINDOWS\system32\edbtmp.log" failed with system error 5 (0x00000005): "Access is denied. ".  The create file operation will fail with error -1032 (0xfffffbf8).


System errors:
=============
Error: (10/05/2015 05:24:05 AM) (Source: DCOM) (EventID: 10016) (User: ANORA-PC)
Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}Anora-PCAnoraS-1-5-21-434036944-719920970-2392407034-1000LocalHost (Using LRPC)Microsoft.WindowsStore_2015.9.25.0_x64__8wekyb3d8bbweS-1-15-2-1609473798-1231923017-684268153-4268514328-882773646-2760585773-1760938157

Error: (10/03/2015 08:58:13 AM) (Source: Service Control Manager) (EventID: 7024) (User: )
Description: The Xbox Live Auth Manager service terminated with the following service-specific error:
%%0

Error: (10/03/2015 08:52:36 AM) (Source: DCOM) (EventID: 10016) (User: ANORA-PC)
Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}Anora-PCAnoraS-1-5-21-434036944-719920970-2392407034-1000LocalHost (Using LRPC)Microsoft.Windows.Cortana_1.4.8.176_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742

Error: (10/03/2015 08:52:36 AM) (Source: DCOM) (EventID: 10016) (User: ANORA-PC)
Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}Anora-PCAnoraS-1-5-21-434036944-719920970-2392407034-1000LocalHost (Using LRPC)Microsoft.Windows.Cortana_1.4.8.176_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742

Error: (10/03/2015 08:52:36 AM) (Source: DCOM) (EventID: 10016) (User: ANORA-PC)
Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}Anora-PCAnoraS-1-5-21-434036944-719920970-2392407034-1000LocalHost (Using LRPC)Microsoft.Windows.Cortana_1.4.8.176_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742

Error: (10/03/2015 08:52:36 AM) (Source: DCOM) (EventID: 10016) (User: ANORA-PC)
Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}Anora-PCAnoraS-1-5-21-434036944-719920970-2392407034-1000LocalHost (Using LRPC)Microsoft.Windows.Cortana_1.4.8.176_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742

Error: (10/03/2015 08:52:36 AM) (Source: DCOM) (EventID: 10016) (User: ANORA-PC)
Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}Anora-PCAnoraS-1-5-21-434036944-719920970-2392407034-1000LocalHost (Using LRPC)Microsoft.Windows.Cortana_1.4.8.176_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742

Error: (10/03/2015 08:52:36 AM) (Source: DCOM) (EventID: 10016) (User: ANORA-PC)
Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}Anora-PCAnoraS-1-5-21-434036944-719920970-2392407034-1000LocalHost (Using LRPC)Microsoft.Windows.Cortana_1.4.8.176_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742

Error: (10/03/2015 08:52:36 AM) (Source: DCOM) (EventID: 10016) (User: ANORA-PC)
Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}Anora-PCAnoraS-1-5-21-434036944-719920970-2392407034-1000LocalHost (Using LRPC)Microsoft.Windows.Cortana_1.4.8.176_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742

Error: (10/03/2015 08:52:36 AM) (Source: DCOM) (EventID: 10016) (User: ANORA-PC)
Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}Anora-PCAnoraS-1-5-21-434036944-719920970-2392407034-1000LocalHost (Using LRPC)Microsoft.Windows.Cortana_1.4.8.176_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742


CodeIntegrity:
===================================
  Date: 2015-10-03 08:45:34.514
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\nvtcam.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2015-09-15 23:22:19.457
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2015-09-15 23:22:19.440
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2015-09-15 23:22:19.424
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2015-09-15 23:22:19.390
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2015-09-15 23:22:19.200
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2015-09-15 16:50:40.119
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2015-09-15 16:50:40.101
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2015-09-15 16:50:40.078
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2015-09-15 16:50:36.219
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.


==================== Memory info ===========================

Processor: AMD Phenom™ II X6 1055T Processor
Percentage of memory in use: 25%
Total physical RAM: 16345.63 MB
Available physical RAM: 12104.99 MB
Total Virtual: 32729.63 MB
Available Virtual: 25698.03 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:297.43 GB) (Free:223.54 GB) NTFS
Drive e: (New Volume) (Fixed) (Total:55.89 GB) (Free:10.13 GB) exFAT
Drive f: () (Removable) (Total:14.83 GB) (Free:14.59 GB) FAT32
Drive i: (Iomega_Ext_Drive) (Fixed) (Total:930.7 GB) (Free:50.1 GB) NTFS
Drive j: (New Volume) (Fixed) (Total:1863.01 GB) (Free:540.33 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 298.1 GB) (Disk ID: E9495AAB)

Partition: GPT.

========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 1863 GB) (Disk ID: B1882887)
Partition 1: (Not Active) - (Size=1863 GB) - (Type=07 NTFS)

========================================================
Disk: 2 (MBR Code: Windows 7 or 8) (Size: 55.9 GB) (Disk ID: F04AEAE3)
Partition 1: (Not Active) - (Size=55.9 GB) - (Type=07 NTFS)
Attempted reading MBR returned 0 bytes.
 Could not read MBR for disk 3.

========================================================
Disk: 4 (Size: 14.8 GB) (Disk ID: 00000000)

Partition: GPT.

==================== End of Addition.txt ============================

 

 

Fix result of Farbar Recovery Scan Tool (x64) Version:04-10-2015
Ran by Anora (2015-10-05 22:39:21) Run:2
Running from C:\Users\Anora\Desktop
Loaded Profiles: Anora (Available Profiles: Anora & Classic .NET AppPool & dynmap & wildrenter)
Boot Mode: Normal
==============================================

fixlist content:
*****************
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
U3 idsvc; no ImagePath
S3 NTIOLib_MSICOMM_CC; \??\C:\Program Files (x86)\MSI\Command Center\NTIOLib_X64.sys [X]
S3 NTIOLib_MSIFrequency_CC; \??\C:\Program Files (x86)\MSI\Command Center\ClockGen\CPU_Frequency\NTIOLib_X64.sys [X]
S3 NTIOLib_MSIRatio_CC; \??\C:\Program Files (x86)\MSI\Command Center\CPU\CPU_Ratio\NTIOLib_X64.sys [X]
S3 NTIOLib_MSISuperIO_CC; \??\C:\Program Files (x86)\MSI\Command Center\SuperIO\NTIOLib_X64.sys [X]
S3 wfpcapture; \SystemRoot\System32\drivers\wfpcapture.sys [X]
U3 wpcsvc; no ImagePath
2015-09-13 17:02 - 2015-08-30 17:42 - 00000080 _____ C:\Users\Anora\AppData\Local???????????????????
C:\Users\Anora\en_res.dll
C:\Users\Anora\es_res.dll
C:\Users\Anora\fr_res.dll
C:\Users\Anora\grm_res.dll
C:\Users\Anora\it_res.dll
C:\Users\Anora\jp_res.dll
C:\Users\Anora\mfc80u.dll
C:\Users\Anora\msvcr80.dll
C:\Users\Anora\PCPE Setup.exe
C:\Users\Anora\pt_res.dll
C:\Users\Anora\ResourceReader.dll
C:\Users\Anora\ru_res.dll
C:\Users\Anora\zh_res.dll
File: C:\Users\Anora\AppData\Local\Temp\CH.dll
*****************

"HKLM\Software\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SDWinLogon" => key removed successfully
idsvc => service removed successfully
NTIOLib_MSICOMM_CC => service removed successfully
NTIOLib_MSIFrequency_CC => service removed successfully
NTIOLib_MSIRatio_CC => service removed successfully
NTIOLib_MSISuperIO_CC => service removed successfully
wfpcapture => service removed successfully
wpcsvc => service removed successfully

=========== "C:\Users\Anora\AppData\Local???????????????????" ==========

C:\Users\Anora\AppData\Local剜捯獫慴⁲慇敭屳呇⁁屖湥楴汴浥湥⹴湩潦 => moved successfully

========= End -> "C:\Users\Anora\AppData\Local???????????????????" ========

C:\Users\Anora\en_res.dll => moved successfully
C:\Users\Anora\es_res.dll => moved successfully
C:\Users\Anora\fr_res.dll => moved successfully
C:\Users\Anora\grm_res.dll => moved successfully
C:\Users\Anora\it_res.dll => moved successfully
C:\Users\Anora\jp_res.dll => moved successfully
C:\Users\Anora\mfc80u.dll => moved successfully
C:\Users\Anora\msvcr80.dll => moved successfully
C:\Users\Anora\PCPE Setup.exe => moved successfully
C:\Users\Anora\pt_res.dll => moved successfully
C:\Users\Anora\ResourceReader.dll => moved successfully
C:\Users\Anora\ru_res.dll => moved successfully
C:\Users\Anora\zh_res.dll => moved successfully

========================= File: C:\Users\Anora\AppData\Local\Temp\CH.dll ========================

File not signed
MD5: C01FFE76E99778EF24DD6F55AB029C53
Creation and modification date: 2015-08-22 12:43 - 2015-08-22 12:43
Size: 0003072
Attributes: ----A
Company Name:
Internal Name:
Original Name:
Product:
Description:
File Version:
Product Version:
Copyright:

====== End of File: ======


==== End of Fixlog 22:39:22 ====


Edited by Anora, 05 October 2015 - 08:41 PM.


#9 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 37,005 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:03:11 AM

Posted 05 October 2015 - 09:42 PM

Thanks,

Do you know what this directory is?

J:\MultyMc5

Please do this.

===================================================

Farbar's Recovery Scan Tool - Run Fix in Normal or Safe Mode

--------------------
  • Press the Windows key Windows_Logo_key.gif + r on your keyboard at the same time. Type in notepad and press Enter
  • Please copy and paste the contents of the below code box into the open notepad and save it to your desktop (<<<Important) as fixlist.txt
Task: {0344001C-35FF-44A9-BAFC-7A62233B6283} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
Task: {1924B85E-7991-4E4A-9B75-AF41CB2C4733} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {445BCB70-8A5D-492A-87DA-183F994661E8} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION
Task: {6A5495ED-A695-47F9-9CF4-BF36433BF892} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {8F4C3A2F-D807-437E-BAA4-10DF9721ED47} - \Microsoft\Windows\File Classification Infrastructure\Property Definition Sync -> No File <==== ATTENTION
Task: {97EAD47E-914B-48A6-BFF1-C2CFFBF75048} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {99D19368-3339-473E-A7F9-07F870737740} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {B5598F48-19C9-48F0-9CF7-7B511DEB99D3} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {D30C7960-0886-48E2-BE8C-424ECF951E61} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {D4AC86D9-C96F-40E9-8BE1-58D1F27CAF66} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {E3036E4C-A7F5-4432-A565-4A52930E109D} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {FD952D3B-2F40-4052-8541-286320769310} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
C:\Users\Anora\AppData\Local\Temp\CH.dll
  • Launch FRST and press the Fix button just once and wait, the program will automatically launch fixlist.txt.
  • The tool will create a log on the desktop called Fixlog.txt. Please copy and paste the contents of the file in your reply.
===================================================

Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it. :thumbsup2:
  • Do you recognize the Directory?
  • Fixlog

Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#10 Anora

Anora
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Local time:06:11 AM

Posted 06 October 2015 - 09:22 AM

That is MultyMc I labeled it different so yes I recognize the Directory

 

Fix result of Farbar Recovery Scan Tool (x64) Version:04-10-2015
Ran by Anora (2015-10-06 11:20:01) Run:3
Running from C:\Users\Anora\Desktop
Loaded Profiles: Anora (Available Profiles: Anora & Classic .NET AppPool & dynmap & wildrenter)
Boot Mode: Normal
==============================================

fixlist content:
*****************
Task: {0344001C-35FF-44A9-BAFC-7A62233B6283} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
Task: {1924B85E-7991-4E4A-9B75-AF41CB2C4733} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {445BCB70-8A5D-492A-87DA-183F994661E8} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION
Task: {6A5495ED-A695-47F9-9CF4-BF36433BF892} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {8F4C3A2F-D807-437E-BAA4-10DF9721ED47} - \Microsoft\Windows\File Classification Infrastructure\Property Definition Sync -> No File <==== ATTENTION
Task: {97EAD47E-914B-48A6-BFF1-C2CFFBF75048} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {99D19368-3339-473E-A7F9-07F870737740} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {B5598F48-19C9-48F0-9CF7-7B511DEB99D3} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {D30C7960-0886-48E2-BE8C-424ECF951E61} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {D4AC86D9-C96F-40E9-8BE1-58D1F27CAF66} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {E3036E4C-A7F5-4432-A565-4A52930E109D} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {FD952D3B-2F40-4052-8541-286320769310} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
C:\Users\Anora\AppData\Local\Temp\CH.dll
*****************

"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{0344001C-35FF-44A9-BAFC-7A62233B6283}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0344001C-35FF-44A9-BAFC-7A62233B6283}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Time-5d" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{1924B85E-7991-4E4A-9B75-AF41CB2C4733}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1924B85E-7991-4E4A-9B75-AF41CB2C4733}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{445BCB70-8A5D-492A-87DA-183F994661E8}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{445BCB70-8A5D-492A-87DA-183F994661E8}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{6A5495ED-A695-47F9-9CF4-BF36433BF892}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6A5495ED-A695-47F9-9CF4-BF36433BF892}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfig" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{8F4C3A2F-D807-437E-BAA4-10DF9721ED47}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8F4C3A2F-D807-437E-BAA4-10DF9721ED47}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\File Classification Infrastructure\Property Definition Sync" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{97EAD47E-914B-48A6-BFF1-C2CFFBF75048}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{97EAD47E-914B-48A6-BFF1-C2CFFBF75048}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{99D19368-3339-473E-A7F9-07F870737740}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{99D19368-3339-473E-A7F9-07F870737740}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{B5598F48-19C9-48F0-9CF7-7B511DEB99D3}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B5598F48-19C9-48F0-9CF7-7B511DEB99D3}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{D30C7960-0886-48E2-BE8C-424ECF951E61}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D30C7960-0886-48E2-BE8C-424ECF951E61}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{D4AC86D9-C96F-40E9-8BE1-58D1F27CAF66}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D4AC86D9-C96F-40E9-8BE1-58D1F27CAF66}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Logon-5d" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{E3036E4C-A7F5-4432-A565-4A52930E109D}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E3036E4C-A7F5-4432-A565-4A52930E109D}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\launchtrayprocess" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{FD952D3B-2F40-4052-8541-286320769310}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FD952D3B-2F40-4052-8541-286320769310}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxcontent" => key removed successfully
C:\Users\Anora\AppData\Local\Temp\CH.dll => moved successfully

==== End of Fixlog 11:20:02 ====



#11 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 37,005 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:03:11 AM

Posted 06 October 2015 - 12:57 PM

Very good, thank you.

Please do this.

===================================================

ESET Online Scanner

--------------------

I'd like us to scan your machine with ESET OnlineScan This process may may take several hours, that is normal.
  • Hold down Control and click on this link to open ESET OnlineScan in a new window.
  • Click Run ESET Online Scanner.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on esetsmartinstaller_enu.exe to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the icon on your desktop.
  • Check YES, I accept the Terms of Use.
  • Click the Start button.
  • Click Enable detection of potentially unwanted applications
  • Accept any security warnings from your browser.
  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • When the scan completes, click List Threats
  • Copy and paste the information in your next reply. Note: If no malware was found you will not get a log.
  • Click the Back button.
  • Check Uninstall application on close and Delete quarantined files
  • Click the Finish button.
  • Close the ESET window and reboot your computer
===================================================

screen317's Security Check

--------------------
  • Please download screen317's Security Check to your desktop
  • Double-click icon to launch the program
  • Click OK
  • Select Run Note: If you receive an error message saying UNSUPPORTED OPERATING SYSTEM! ABORTED! reboot your computer and attempt to run it again
  • Allow the program to run
  • A Notepad document will open on your desktop. Please copy and paste the contents in your reply
===================================================

Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it. :thumbsup2:
  • ESET log
  • Security Check log
  • How is your computer running?

Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#12 Anora

Anora
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Local time:06:11 AM

Posted 07 October 2015 - 07:01 AM

J:\downloads\cbsidlm-cbsi176-SHA1_Generator-ORG-75760552.exe    a variant of Win32/CNETInstaller.B potentially unwanted application    cleaned by deleting - quarantined
J:\downloads\daemon-tools-4.48.1(1).exe    Win32/DownWare.L potentially unwanted application    deleted - quarantined
J:\downloads\daemon-tools-4.48.1.exe    Win32/JoyDownloader.D potentially unwanted application    deleted - quarantined
J:\downloads\FileZilla_3.7.4.1_win32-setup.exe    a variant of Win32/InstallCore.IO potentially unwanted application    cleaned by deleting - quarantined
J:\downloads\FileZilla_3.8.0_win32-setup.exe    a variant of Win32/InstallCore.LB potentially unwanted application    cleaned by deleting - quarantined
J:\downloads\FileZilla_3.8.1_win32-setup.exe    a variant of Win32/InstallCore.LA potentially unwanted application    cleaned by deleting - quarantined
J:\downloads\FileZilla_Server-0_9_44.exe    a variant of Win32/InstallCore.LB potentially unwanted application    cleaned by deleting - quarantined
J:\downloads\SHOUTcastv198.exe    a variant of Win32/OpenInstall potentially unwanted application    cleaned by deleting - quarantined
J:\downloads\slicesetup.exe    a variant of Win32/Toolbar.Conduit.I potentially unwanted application    deleted - quarantined
J:\downloads\SoftonicDownloader_for_kung-fu-panda.exe    a variant of Win32/SoftonicDownloader.F potentially unwanted application    cleaned by deleting - quarantined
J:\downloads\Xplorer360beta6rar.exe    a variant of Win32/OpenInstall potentially unwanted application    cleaned by deleting - quarantined

 

 

 Results of screen317's Security Check version 1.009  
   x64 (UAC is enabled)  
 Internet Explorer 11  
``````````````Antivirus/Firewall Check:``````````````
 Windows Firewall Enabled!  
Windows Defender   
avast! Antivirus   
 Antivirus up to date!   
`````````Anti-malware/Other Utilities Check:`````````
 MVPS Hosts File  
 Spybot - Search & Destroy
 Java 8 Update 60  
 Adobe Flash Player     19.0.0.185  
 Mozilla Firefox (41.0.1)
````````Process Check: objlist.exe by Laurent````````  
 Malwarebytes Anti-Malware mbamservice.exe  
 Malwarebytes Anti-Malware mbam.exe  
 Spybot Teatimer.exe is disabled!
 Malwarebytes Anti-Malware mbamscheduler.exe   
 AVAST Software Avast AvastSvc.exe  
 AVAST Software Avast AvastUI.exe  
`````````````````System Health check`````````````````
 Total Fragmentation on Drive C:  %
````````````````````End of Log``````````````````````

Hmmm I need to check to see why teatimer is not running


Edited by Anora, 07 October 2015 - 07:02 AM.


#13 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 37,005 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:03:11 AM

Posted 07 October 2015 - 11:03 AM

Other than Spybot everything looks good.

Let me know what you find.
Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#14 Anora

Anora
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Gender:Not Telling
  • Local time:06:11 AM

Posted 07 October 2015 - 02:12 PM

seams the problem is the version of spybot  i am using dose not come whit teatimer



#15 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 37,005 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:03:11 AM

Posted 07 October 2015 - 05:02 PM

OK, are there any remaining issues?


Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users