Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

browser hijacked


  • This topic is locked This topic is locked
11 replies to this topic

#1 willhippy

willhippy

  • Members
  • 157 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Bethlehem. PA
  • Local time:08:21 AM

Posted 07 October 2015 - 03:38 PM

IE  firefox and google all have been switched to yahoo. In IE if I go to internet options I can change it back by clicking on use default and home.  It always goes back to yahoo. thanks in advance for any help you can give me. :tophat:



BC AdBot (Login to Remove)

 


#2 jntkwx

jntkwx

  • Malware Response Team
  • 4,339 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:New England, U.S.A.
  • Local time:08:21 AM

Posted 08 October 2015 - 03:46 PM

Hello,

Please follow the instructions in ==>This Guide<== starting at step 6. If you cannot complete a step, skip it and continue.

Once the proper logs are created, then post them in a reply to this topic by using the Add Reply button.

If you can produce at least some of the logs, then please create the post and explain what happens when you try to create the log(s) that you couldn't get. If you cannot produce any of the logs, then still post the reply and explain that you followed the Prep. Guide, were unable to create the logs, and describe what happens when you try to create the logs.


Edited by jntkwx, 08 October 2015 - 03:46 PM.

Regards,
Jason

 

Simple and easy ways to keep your computer safe and secure on the Internet

If I am helping you and have not returned in 48 hours, please feel free to send me a PM with a link to the topic.
My help is free... however, if you wish to show appreciation and support me personally fighting against malware, please consider a donation: btn_donate_SM.gif


#3 willhippy

willhippy
  • Topic Starter

  • Members
  • 157 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Bethlehem. PA
  • Local time:08:21 AM

Posted 09 October 2015 - 10:23 AM

Here is first log

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:08-10-2015
Ran by Will (administrator) on WILL-PC (09-10-2015 11:09:35)
Running from C:\Users\Will\Desktop
Loaded Profiles: Will (Available Profiles: Will & DefaultAppPool)
Platform: Windows 10 Pro (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Edge)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgrsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgcsrva.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe
(Microsoft Corporation) C:\Windows\System32\mqsvc.exe
(VIA Technologies, Inc.) C:\Windows\System32\ViakaraokeSrv.exe
(BiniSoft.org) C:\Program Files\Windows Firewall Control\wfcs.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgnsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgemca.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe
(Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersServer.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Photosmart 6520 series\Bin\ScanToPCActivationApp.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2015\avgui.exe
(BiniSoft.org) C:\Program Files\Windows Firewall Control\wfc.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Photosmart 6520 series\Bin\HPNetworkCommunicator.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.6306.42251.0_x64__8wekyb3d8bbwe\HxTsr.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsStore_2015.10.5.0_x64__8wekyb3d8bbwe\WinStore.Mobile.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.6306.42251.0_x64__8wekyb3d8bbwe\HxCalendarAppImm.exe
(Microsoft Corporation) C:\Windows\System32\Speech_OneCore\Common\SpeechRuntime.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.6306.42251.0_x64__8wekyb3d8bbwe\HxMail.exe
(Microsoft Corporation) C:\Windows\SoftwareDistribution\Download\Install\vstor_redist.exe
(Microsoft Corporation) J:\28a14ef71fc82b5f8f\Setup.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Microsoft Corporation) J:\28a14ef71fc82b5f8f\vstor40\vstor40_x64.exe
(Microsoft Corporation) J:\4a88c6b25d4c5a28be3f2e\install.exe
(Microsoft Corporation) C:\Windows\SysWOW64\msiexec.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Microsoft Corporation) C:\Windows\SysWOW64\msiexec.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\ngen.exe
() C:\Program Files\WindowsApps\Microsoft.Windows.Photos_15.1001.16470.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(LastPass) C:\Users\Will\AppData\LocalLow\LastPass\LastPassBroker.exe
(Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil_ActiveX.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [767176 2015-08-21] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [Raptr] => C:\Program Files (x86)\Raptr\raptrstub.exe [56080 2015-10-01] (Raptr, Inc)
HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\AVG2015\avgui.exe [3775912 2015-08-24] (AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [CLMLServer] => C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe [107816 2010-08-03] (CyberLink)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [hpqSRMon] => C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe [150528 2008-07-22] (Hewlett-Packard)
HKLM-x32\...\Run: [NBAgent] => C:\Program Files (x86)\Nero\Nero 11\Nero BackItUp\NBAgent.exe [1493288 2012-01-13] (Nero AG)
HKU\S-1-5-21-3276915167-1117282696-2501375683-1000\...\Run: [Power2GoExpress] => C:\Program Files (x86)\CyberLink\Power2Go\Power2GoExpress.exe [2643240 2011-04-07] (CyberLink Corp.)
HKU\S-1-5-21-3276915167-1117282696-2501375683-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [57981568 2015-09-28] (Skype Technologies S.A.)
HKU\S-1-5-21-3276915167-1117282696-2501375683-1000\...\Run: [HP Photosmart 6520 series (NET)] => C:\Program Files\HP\HP Photosmart 6520 series\Bin\ScanToPCActivationApp.exe [2573416 2012-10-17] (Hewlett-Packard Co.)
HKU\S-1-5-21-3276915167-1117282696-2501375683-1000\...\Run: [GoogleChromeAutoLaunch_6AD0AEF8648A7A9E4002E611E95AC001] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [815944 2015-09-23] (Google Inc.)
HKU\S-1-5-21-3276915167-1117282696-2501375683-1000\...\Run: [BingSvc] => C:\Users\Will\AppData\Local\Microsoft\BingSvc\BingSvc.exe [144008 2015-04-07] (© 2015 Microsoft Corporation)
HKU\S-1-5-21-3276915167-1117282696-2501375683-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\WINDOWS\system32\PhotoScreensaver.scr [583680 2015-07-10] (Microsoft Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk [2015-09-08]
ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Install LastPass IE RunOnce.lnk [2015-09-08]
ShortcutTarget: Install LastPass IE RunOnce.lnk -> C:\Program Files (x86)\Common Files\lpuninstall.exe (LastPass)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Windows Firewall Control.lnk [2015-09-14]
ShortcutTarget: Windows Firewall Control.lnk -> C:\Program Files\Windows Firewall Control\wfc.exe (BiniSoft.org)
Startup: C:\Users\Will\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Monitor Ink Alerts - HP Photosmart 6520 series (Network).lnk [2015-09-08]
ShortcutTarget: Monitor Ink Alerts - HP Photosmart 6520 series (Network).lnk -> C:\Program Files\HP\HP Photosmart 6520 series\Bin\HPStatusBL.dll (Hewlett-Packard Co.)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{728109c4-ef30-442c-8372-98ffad22d414}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{77b7bf05-dc03-4d5d-b614-879d64ee645c}: [DhcpNameServer] 192.168.1.1

Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-3276915167-1117282696-2501375683-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/?ocid=iehp
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://us.yhs4.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wncy_dnldwz_15_40_ssg02&param1=1&param2=f%3D4%26b%3DIE%26cc%3Dus%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1QzutCtD0B0FyEzzyB0C0B0E0D0BtDtByDtDtN0D0Tzu0StCtAyCyCtN1L2XzutAtFtCtBtFzyzytFtDtN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2SyEyBtAtD0D0BzyyBtGyDtAyB0BtGyEtA0FyCtG0AyB0CyBtGtAzyyD0CtCyDyE0AtD0Azz0A2QtN1M1F1B2Z1V1N2Y1L1Qzu2Szz0C0B0DtCyCzytCtG0A0EzyyCtGyEtD0EyEtGzztCyD0EtGzzyD0DyCzzyE0D0E0B0CyC0E2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCtDyEzz%26cr%3D1376615847%26a%3Dwncy_dnldwz_15_40_ssg02%26os%3DWindows%2B10%2BPro&p={searchTerms}
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://us.yhs4.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wncy_dnldwz_15_40_ssg02&param1=1&param2=f%3D4%26b%3DIE%26cc%3Dus%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1QzutCtD0B0FyEzzyB0C0B0E0D0BtDtByDtDtN0D0Tzu0StCtAyCyCtN1L2XzutAtFtCtBtFzyzytFtDtN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2SyEyBtAtD0D0BzyyBtGyDtAyB0BtGyEtA0FyCtG0AyB0CyBtGtAzyyD0CtCyDyE0AtD0Azz0A2QtN1M1F1B2Z1V1N2Y1L1Qzu2Szz0C0B0DtCyCzytCtG0A0EzyyCtGyEtD0EyEtGzztCyD0EtGzzyD0DyCzzyE0D0E0B0CyC0E2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCtDyEzz%26cr%3D1376615847%26a%3Dwncy_dnldwz_15_40_ssg02%26os%3DWindows%2B10%2BPro&p={searchTerms}
SearchScopes: HKU\S-1-5-21-3276915167-1117282696-2501375683-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?FORM=U220DF&PC=U220&q={searchTerms}&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-3276915167-1117282696-2501375683-1000 -> C11B665336AA4D9B9BEAF0753DACE497 URL = hxxp://us.yhs4.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wncy_dnldwz_15_40_ssg02&param1=1&param2=f%3D4%26b%3DIE%26cc%3Dus%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1QzutCtD0B0FyEzzyB0C0B0E0D0BtDtByDtDtN0D0Tzu0StCtAyCyCtN1L2XzutAtFtCtBtFzyzytFtDtN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2SyEyBtAtD0D0BzyyBtGyDtAyB0BtGyEtA0FyCtG0AyB0CyBtGtAzyyD0CtCyDyE0AtD0Azz0A2QtN1M1F1B2Z1V1N2Y1L1Qzu2Szz0C0B0DtCyCzytCtG0A0EzyyCtGyEtD0EyEtGzztCyD0EtGzzyD0DyCzzyE0D0E0B0CyC0E2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCtDyEzz%26cr%3D1376615847%26a%3Dwncy_dnldwz_15_40_ssg02%26os%3DWindows%2B10%2BPro&p={searchTerms}
SearchScopes: HKU\S-1-5-21-3276915167-1117282696-2501375683-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?FORM=U220DF&PC=U220&q={searchTerms}&src=IE-SearchBox
BHO: LastPass Vault -> {95D9ECF5-2A4D-4550-BE49-70D42F71296E} -> C:\Program Files (x86)\LastPass\LPToolbar_x64.dll [2015-09-08] (LastPass)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-05-01] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: HP Print Enhancer -> {0347C33E-8762-4905-BF09-768834316C61} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2009-09-20] (Hewlett-Packard Co.)
BHO-x32: LastPass Vault -> {95D9ECF5-2A4D-4550-BE49-70D42F71296E} -> C:\Program Files (x86)\LastPass\LPToolbar.dll [2015-09-08] (LastPass)
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01] (Microsoft Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: HP Smart BHO Class -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2009-09-20] (Hewlett-Packard Co.)
Toolbar: HKLM - LastPass Toolbar - {9f6b5cc3-5c7b-4b5c-97af-19dec1e380e5} - C:\Program Files (x86)\LastPass\LPToolbar_x64.dll [2015-09-08] (LastPass)
Toolbar: HKLM-x32 - LastPass Toolbar - {9f6b5cc3-5c7b-4b5c-97af-19dec1e380e5} - C:\Program Files (x86)\LastPass\LPToolbar.dll [2015-09-08] (LastPass)
Handler-x32: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files (x86)\Belarc\BelarcAdvisor\System\BAVoilaX.dll [2015-08-05] (Belarc, Inc.)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-05-01] (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01] (Microsoft Corporation)
StartMenuInternet: IEXPLORE.EXE - iexplore.exe

FireFox:
========
FF ProfilePath: C:\Users\Will\AppData\Roaming\Mozilla\Firefox\Profiles\bygq1y9z.default
FF DefaultSearchEngine: Bing
FF SelectedSearchEngine: Bing
FF SearchEngineOrder.3: Bing
FF Keyword.URL: hxxp://www.bing.com/search?FORM=U356DF&PC=U356&q=
FF Homepage: hxxp://www.msn.com/?pc=U356&ocid=U356DHP&osmkt=en-us
hxxp://us.yhs4.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wncy_dnldwz_15_40_ssg02&param1=1&param2=f%3D1%26b%3DFirefox%26cc%3Dus%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1QzutCtD0B0FyEzzyB0C0B0E0D0BtDtByDtDtN0D0Tzu0StCtAyCyCtN1L2XzutAtFtCtBtFzyzytFtDtN1L1Czu1ByEtN1L1G1B1V1N2Y1L1Qzu2SyEyBtAtD0D0BzyyBtGyDtAyB0BtGyEtA0FyCtG0AyB0CyBtGtAzyyD0CtCyDyE0AtD0Azz0A2QtN1M1F1B2Z1V1N2Y1L1Qzu2Szz0C0B0DtCyCzytCtG0A0EzyyCtGyEtD0EyEtGzztCyD0EtGzzyD0DyCzzyE0D0E0B0CyC0E2QtN0A0LzuyEtN1B2Z1V1T1S1NzutCtDyEzz%26cr%3D1376615847%26a%3Dwncy_dnldwz_15_40_ssg02%26os%3DWindows%2B10%2BPro
FF Plugin: @lastpass.com/NPLastPass -> C:\Program Files (x86)\LastPass\nplastpass64.dll [2015-09-08] (LastPass)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @lastpass.com/NPLastPass -> C:\Program Files (x86)\LastPass\nplastpass64.dll [2015-09-08] (LastPass)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @Nero.com/KM -> C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL [2012-01-13] (Nero AG)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-16] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-16] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-07-03] (Adobe Systems Inc.)
FF Extension: Flash Video Downloader - YouTube HD Download [4K] - C:\Users\Will\AppData\Roaming\Mozilla\Firefox\Profiles\bygq1y9z.default\Extensions\artur.dubovoy@gmail.com [2015-09-26]
FF Extension: Bing Search - C:\Users\Will\AppData\Roaming\Mozilla\Firefox\Profiles\bygq1y9z.default\Extensions\bingsearch.full@microsoft.com [2015-09-28]
FF Extension: Xmarks - C:\Users\Will\AppData\Roaming\Mozilla\Firefox\Profiles\bygq1y9z.default\Extensions\foxmarks@kei.com [2015-09-26]
FF Extension: Youtube Downloader - 4K Download - C:\Users\Will\AppData\Roaming\Mozilla\Firefox\Profiles\bygq1y9z.default\Extensions\paulsaintuzb@gmail.com [2015-09-26]
FF Extension: LastPass - C:\Users\Will\AppData\Roaming\Mozilla\Firefox\Profiles\bygq1y9z.default\Extensions\support@lastpass.com [2015-09-26]
FF Extension: InvisibleHand - C:\Users\Will\AppData\Roaming\Mozilla\Firefox\Profiles\bygq1y9z.default\Extensions\canitbecheaper@trafficbroker.co.uk.xpi [2015-09-26]
FF Extension: Medooc. SearchEngine - C:\Users\Will\AppData\Roaming\Mozilla\Firefox\Profiles\bygq1y9z.default\Extensions\daviddeutsch1002@yahoo.com.xpi [2015-09-26]
FF Extension: Video Downloader Professional - C:\Users\Will\AppData\Roaming\Mozilla\Firefox\Profiles\bygq1y9z.default\Extensions\ffext_basicvideoext@startpage24.xpi [2015-09-26]
FF Extension: i2Symbol (Emoticons, Smileys, Symbols) - C:\Users\Will\AppData\Roaming\Mozilla\Firefox\Profiles\bygq1y9z.default\Extensions\i2symbol@sciweavers.org.xpi [2015-09-26]
FF Extension: PriceBlink - C:\Users\Will\AppData\Roaming\Mozilla\Firefox\Profiles\bygq1y9z.default\Extensions\info@priceblink.com.xpi [2015-09-26]
FF Extension: The Camelizer - Price Tracker - C:\Users\Will\AppData\Roaming\Mozilla\Firefox\Profiles\bygq1y9z.default\Extensions\izer@camelcamelcamel.com.xpi [2015-09-26]
FF Extension: Online Games - C:\Users\Will\AppData\Roaming\Mozilla\Firefox\Profiles\bygq1y9z.default\Extensions\jid0-RJnyEjyiGjzbBui2er5zHZhzPSE@jetpack.xpi [2015-09-26]
FF Extension: Jigsaw Puzzle Maker - C:\Users\Will\AppData\Roaming\Mozilla\Firefox\Profiles\bygq1y9z.default\Extensions\jid0-yofxTjDXTIZkYYiDeUXrpyA8TFU@jetpack.xpi [2015-09-26]
FF Extension: Test Pilot - C:\Users\Will\AppData\Roaming\Mozilla\Firefox\Profiles\bygq1y9z.default\Extensions\testpilot@labs.mozilla.com.xpi [2015-09-26]
FF Extension: Torrent Finder Toolbar - C:\Users\Will\AppData\Roaming\Mozilla\Firefox\Profiles\bygq1y9z.default\Extensions\TFToolbarX@torrent-finder.xpi [2015-09-26]
FF Extension: Fasterfox - C:\Users\Will\AppData\Roaming\Mozilla\Firefox\Profiles\bygq1y9z.default\Extensions\{c36177c0-224a-11da-8cd6-0800200c9a91}.xpi [2015-09-26]
FF HKLM-x32\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2015-09-08]
FF HKU\S-1-5-21-3276915167-1117282696-2501375683-1000\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
StartMenuInternet: FIREFOX.EXE - firefox.exe

Chrome:
=======
CHR HomePage: Default -> hxxp://www.msn.com/?pc=__PARAM__&ocid=__PARAM__DHP&osmkt=en-us
CHR StartupUrls: Default -> "hxxp://www.my.msn.com/","hxxps://www.google.com/intl/en/chrome/browser/welcome.html"
CHR Profile: C:\Users\Will\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Floorplanner) - C:\Users\Will\AppData\Local\Google\Chrome\User Data\Default\Extensions\abopacaefhbognnmeigicfpgnmpideag [2015-09-21]
CHR Extension: (Instrumente) - C:\Users\Will\AppData\Local\Google\Chrome\User Data\Default\Extensions\ahchimdkljhhfjkklkafookapgikdhkk [2015-09-21]
CHR Extension: (Xmarks Bookmark Sync) - C:\Users\Will\AppData\Local\Google\Chrome\User Data\Default\Extensions\ajpgkpeckebdhofmmjfgcjjiiejpodla [2015-09-21]
CHR Extension: (Dictanote - Speech Recognizer) - C:\Users\Will\AppData\Local\Google\Chrome\User Data\Default\Extensions\aomjekmpappghadlogpigifkghlmebjk [2015-09-21]
CHR Extension: (BeFunky Photo Editor) - C:\Users\Will\AppData\Local\Google\Chrome\User Data\Default\Extensions\apfkepiiddolifkgjmfdgpnipgnfejab [2015-09-21]
CHR Extension: (Send this page by email) - C:\Users\Will\AppData\Local\Google\Chrome\User Data\Default\Extensions\bcamgnkjooghefjjfgfhnepedkodbgec [2015-09-21]
CHR Extension: (Chrome Tips Beta (by Google)) - C:\Users\Will\AppData\Local\Google\Chrome\User Data\Default\Extensions\bdmbgfhokojnnaliemjgbahnfeggocpe [2015-09-21]
CHR Extension: (WiBit) - C:\Users\Will\AppData\Local\Google\Chrome\User Data\Default\Extensions\bejaaogemoligmkbmeafkhnaegkggihf [2015-09-21]
CHR Extension: (YouTube) - C:\Users\Will\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-21]
CHR Extension: (Honey) - C:\Users\Will\AppData\Local\Google\Chrome\User Data\Default\Extensions\bmnlcjabgnpnenekpadlanbbkooimhnj [2015-09-21]
CHR Extension: (Movies Downloader) - C:\Users\Will\AppData\Local\Google\Chrome\User Data\Default\Extensions\bniohfejmhpjpljbllpgohpaloanjgjf [2015-09-21]
CHR Extension: (Form Filler) - C:\Users\Will\AppData\Local\Google\Chrome\User Data\Default\Extensions\bnjjngeaknajbdcgpfkgnonkmififhfo [2015-09-21]
CHR Extension: (Nimbus Screenshot and Screencast) - C:\Users\Will\AppData\Local\Google\Chrome\User Data\Default\Extensions\bpconcjcammlapcogcnnelfmaeghhagj [2015-09-21]
CHR Extension: (FVD Suggestions) - C:\Users\Will\AppData\Local\Google\Chrome\User Data\Default\Extensions\caoielngcdpgeldnckhponffkiajaobo [2015-09-21]
CHR Extension: (Webmail Ad Blocker) - C:\Users\Will\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbhfdchmklhpcngcgjmpdbjakdggkkjp [2015-09-21]
CHR Extension: (Adblock Plus) - C:\Users\Will\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2015-09-21]
CHR Extension: (Google Search) - C:\Users\Will\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-09-21]
CHR Extension: (Email this page (by Google)) - C:\Users\Will\AppData\Local\Google\Chrome\User Data\Default\Extensions\dbeoemfhkdniadbojeencpkgmobndpai [2015-09-21]
CHR Extension: (Logitech Smooth Scrolling) - C:\Users\Will\AppData\Local\Google\Chrome\User Data\Default\Extensions\dkpejdfnpdkhifgbancbammdijojoffk [2015-09-21]
CHR Extension: (ICE Quick Stream) - C:\Users\Will\AppData\Local\Google\Chrome\User Data\Default\Extensions\dpioikmjnfipgphjldakcaocbbpnfabl [2015-09-21]
CHR Extension: (eyeCare - Protect your vision) - C:\Users\Will\AppData\Local\Google\Chrome\User Data\Default\Extensions\eeeningnfkaonkonalpcicgemnnijjhn [2015-09-21]
CHR Extension: (Bloody Pressure) - C:\Users\Will\AppData\Local\Google\Chrome\User Data\Default\Extensions\eemipfoeaegklklcngpmdbaemegjdbdl [2015-09-21]
CHR Extension: (Pixlr-o-matic) - C:\Users\Will\AppData\Local\Google\Chrome\User Data\Default\Extensions\ehcibdjmpjlekgjhepbfmenfppliikcj [2015-09-21]
CHR Extension: (Video Downloader professional) - C:\Users\Will\AppData\Local\Google\Chrome\User Data\Default\Extensions\elicpjhcidhpjomhibiffojpinpmmpil [2015-09-21]
CHR Extension: (Converter) - C:\Users\Will\AppData\Local\Google\Chrome\User Data\Default\Extensions\elogiihmdefhdcainoihdcfpnfbimpnd [2015-09-21]
CHR Extension: (Snapshot 2) - C:\Users\Will\AppData\Local\Google\Chrome\User Data\Default\Extensions\ffgfedebnhmhkcfhhjoikplfafgpihpo [2015-09-21]
CHR Extension: (Chrome Web Store Launcher (by Google)) - C:\Users\Will\AppData\Local\Google\Chrome\User Data\Default\Extensions\gecgipfabdickgidpmbicneamekgbaej [2015-09-21]
CHR Extension: (Video Downloader Super) - C:\Users\Will\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghciphhakbampjemlfbahnhhaemoeolf [2015-09-21]
CHR Extension: (The Camelizer) - C:\Users\Will\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghnomdcacenbmilgjigehppbamfndblo [2015-09-21]
CHR Extension: (Dictionary by Dictionary.com) - C:\Users\Will\AppData\Local\Google\Chrome\User Data\Default\Extensions\gikhgcaliglmioibbockkmjknfnepbdh [2015-09-21]
CHR Extension: (History Eraser) - C:\Users\Will\AppData\Local\Google\Chrome\User Data\Default\Extensions\gjieilkfnnjoihjjonajndjldjoagffm [2015-09-21]
CHR Extension: (Downloads Folder Launcher) - C:\Users\Will\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmhianpphjibhflcnebkmkkdojjigbjd [2015-09-21]
CHR Extension: (Webcam) - C:\Users\Will\AppData\Local\Google\Chrome\User Data\Default\Extensions\gnbhgamgannegfcmholgllkakldhajeg [2015-09-21]
CHR Extension: (LastPass: Free Password Manager) - C:\Users\Will\AppData\Local\Google\Chrome\User Data\Default\Extensions\hdokiejnpimakedhajhdlcegeplioahd [2015-09-21]
CHR Extension: (FabCam) - C:\Users\Will\AppData\Local\Google\Chrome\User Data\Default\Extensions\hejilffmihldhlfocnabcgndjjpgadfl [2015-09-21]
CHR Extension: (Where to delete an account) - C:\Users\Will\AppData\Local\Google\Chrome\User Data\Default\Extensions\hfpofkfbabpbbmchmiekfnlcgaedbgcf [2015-09-21]
CHR Extension: (Dictionary) - C:\Users\Will\AppData\Local\Google\Chrome\User Data\Default\Extensions\hpgblgbmcleigbahedfgempmpnlkhhpk [2015-09-21]
CHR Extension: (Apps Launcher) - C:\Users\Will\AppData\Local\Google\Chrome\User Data\Default\Extensions\ijmgkhchjindcjamnckoiahagecjnkdc [2015-09-21]
CHR Extension: (Clearly) - C:\Users\Will\AppData\Local\Google\Chrome\User Data\Default\Extensions\iooicodkiihhpojmmeghjclgihfjdjhj [2015-09-21]
CHR Extension: (Vine Video Download) - C:\Users\Will\AppData\Local\Google\Chrome\User Data\Default\Extensions\jebahcljabjndemkadpdnablhinojkil [2015-09-21]
CHR Extension: (Family Medical Info) - C:\Users\Will\AppData\Local\Google\Chrome\User Data\Default\Extensions\jobbajojigcglfmadbkgjmnacpifklbp [2015-09-21]
CHR Extension: (Autodesk Homestyler) - C:\Users\Will\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdmmkfaghgcicheaimnpffeeekheafkb [2015-09-21]
CHR Extension: (Malware Search) - C:\Users\Will\AppData\Local\Google\Chrome\User Data\Default\Extensions\kgleioieeffejophokeklefchfglgmnk [2015-09-21]
CHR Extension: (Unit Convertor) - C:\Users\Will\AppData\Local\Google\Chrome\User Data\Default\Extensions\kkaklafnbnpegjnlplfgadnobkgdkinf [2015-09-21]
CHR Extension: (TouristEye Planner) - C:\Users\Will\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpjpejalhlnocbhggpnokneghfenoneg [2015-09-21]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Will\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-09-09]
CHR Extension: (Webcam Toy) - C:\Users\Will\AppData\Local\Google\Chrome\User Data\Default\Extensions\lfbgimoladefibpklnfmkpknadbklade [2015-09-21]
CHR Extension: (Numerics Calculator & Converter) - C:\Users\Will\AppData\Local\Google\Chrome\User Data\Default\Extensions\liglcienpnkhdajdfmnpbgmpjglonipe [2015-09-21]
CHR Extension: (Google Maps) - C:\Users\Will\AppData\Local\Google\Chrome\User Data\Default\Extensions\lneaknkopdijkpnocmklfnjbeapigfbh [2015-09-21]
CHR Extension: (Puzzle for Chrome) - C:\Users\Will\AppData\Local\Google\Chrome\User Data\Default\Extensions\mbalnpbcmecdckpghgacibglihkgamkl [2015-09-21]
CHR Extension: (Google Dictionary (by Google)) - C:\Users\Will\AppData\Local\Google\Chrome\User Data\Default\Extensions\mgijmajocgfcbeboacabfgobmjgjcoja [2015-09-21]
CHR Extension: (Google Mail Checker) - C:\Users\Will\AppData\Local\Google\Chrome\User Data\Default\Extensions\mihcahmgecmbnbcchbopgniflfhgnkff [2015-09-21]
CHR Extension: (CashControl) - C:\Users\Will\AppData\Local\Google\Chrome\User Data\Default\Extensions\mioaopmpfgkncgbbfnmpoegppfcgmoek [2015-09-21]
CHR Extension: (Universal Unit Converter) - C:\Users\Will\AppData\Local\Google\Chrome\User Data\Default\Extensions\nafkejlpknmikohhgdelefdeeieplkog [2015-09-21]
CHR Extension: (Similar Sites) - C:\Users\Will\AppData\Local\Google\Chrome\User Data\Default\Extensions\necpbmbhhdiplmfhmjicabdeighkndkn [2015-09-21]
CHR Extension: (Webutation) - C:\Users\Will\AppData\Local\Google\Chrome\User Data\Default\Extensions\nfclfmabiojpommfcalfdgjjeaahnjbj [2015-09-21]
CHR Extension: (Wikipedia Instant) - C:\Users\Will\AppData\Local\Google\Chrome\User Data\Default\Extensions\nlnikhpimclelcopmneehjglfppbnojd [2015-09-21]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Will\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-09-09]
CHR Extension: (Fast Video Downloader) - C:\Users\Will\AppData\Local\Google\Chrome\User Data\Default\Extensions\nocpfkkbaekckhcoekockfbidpcjgkbd [2015-09-21]
CHR Extension: (Personal Blocklist (by Google)) - C:\Users\Will\AppData\Local\Google\Chrome\User Data\Default\Extensions\nolijncfnkgaikbjbdaogikpmpbdcdef [2015-09-21]
CHR Extension: (OneClick Cleaner App) - C:\Users\Will\AppData\Local\Google\Chrome\User Data\Default\Extensions\oadiaahhieelhhffeofkdchgfpjehjok [2015-09-21]
CHR Extension: (PotatoSmile) - C:\Users\Will\AppData\Local\Google\Chrome\User Data\Default\Extensions\oalbpfagfhfkcmklpdanadjpbfdedndn [2015-09-21]
CHR Extension: (Camera) - C:\Users\Will\AppData\Local\Google\Chrome\User Data\Default\Extensions\ofmpffnppnlgkgmbgidhhjcglloeejpg [2015-09-21]
CHR Extension: (Travelmath) - C:\Users\Will\AppData\Local\Google\Chrome\User Data\Default\Extensions\ofpimeaclblbaodahnhhmlblagijlnad [2015-09-21]
CHR Extension: (Print Friendly & PDF) - C:\Users\Will\AppData\Local\Google\Chrome\User Data\Default\Extensions\ohlencieiipommannpdfcmfdpjjmeolj [2015-09-21]
CHR Extension: (Click&Clean App) - C:\Users\Will\AppData\Local\Google\Chrome\User Data\Default\Extensions\pdabfienifkbhoihedcgeogidfmibmhp [2015-09-21]
CHR Extension: (Gmail) - C:\Users\Will\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-09-21]
CHR HKU\S-1-5-21-3276915167-1117282696-2501375683-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [fcfenmboojpjinhpgggodefccipikbpd] - hxxps://clients2.google.com/service/update2/crx
StartMenuInternet: Google Chrome - chrome.exe

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2015\avgidsagent.exe [3637160 2015-08-24] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files (x86)\AVG\AVG2015\avgwdsvc.exe [335656 2015-08-24] (AVG Technologies CZ, s.r.o.)
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1394816 2015-05-01] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1772672 2015-05-01] (Microsoft Corporation)
R3 hpqcxs08; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcxs08.dll [249344 2009-09-20] (Hewlett-Packard Co.) [File not signed]
R2 hpqddsvc; C:\Program Files (x86)\HP\Digital Imaging\bin\hpqddsvc.dll [133120 2009-09-20] (Hewlett-Packard Co.) [File not signed]
R2 HPSLPSVC; C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL [1037824 2009-09-20] (Hewlett-Packard Co.) [File not signed]
R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [24888 2015-07-26] (Hewlett-Packard Company)
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe [69632 2005-11-14] (Macrovision Corporation) [File not signed]
R2 MSMQ; C:\Windows\system32\mqsvc.exe [26112 2015-09-12] (Microsoft Corporation)
S2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2008-12-03] (Hewlett-Packard) [File not signed]
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2008-12-03] (Hewlett-Packard) [File not signed]
R2 VIAKaraokeService; C:\Windows\system32\viakaraokesrv.exe [36504 2015-06-22] (VIA Technologies, Inc.)
S3 w3logsvc; C:\Windows\system32\inetsrv\w3logsvc.dll [84480 2015-09-12] (Microsoft Corporation)
R2 W3SVC; C:\Windows\system32\inetsrv\iisw3adm.dll [578560 2015-09-12] (Microsoft Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [362928 2015-07-10] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-07-10] (Microsoft Corporation)
R2 _wfcs; C:\Program Files\Windows Firewall Control\wfcs.exe [104448 2015-09-14] (BiniSoft.org) [File not signed]

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdWT6.sys [102912 2015-05-28] (Advanced Micro Devices)
S0 Avgboota; C:\Windows\System32\DRIVERS\avgboota.sys [21152 2015-03-27] (AVG Technologies CZ, s.r.o.)
R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [162784 2015-03-11] (AVG Technologies CZ, s.r.o.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [313264 2015-08-19] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [297904 2015-08-19] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [259040 2015-06-16] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [378336 2015-05-07] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [250800 2015-08-04] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [40928 2015-03-20] (AVG Technologies CZ, s.r.o.)
R1 Avgwfpa; C:\Windows\system32\DRIVERS\avgwfpa.sys [304560 2015-08-04] (AVG Technologies CZ, s.r.o.)
R3 dot4; C:\Windows\system32\DRIVERS\Dot4.sys [151968 2012-10-19] (Windows ® Win 7 DDK provider)
R3 Dot4Print; C:\Windows\System32\drivers\Dot4Prt.sys [27040 2012-10-19] (Windows ® Win 7 DDK provider)
R1 HWiNFO32; C:\WINDOWS\SysWOW64\drivers\HWiNFO64A.SYS [26528 2015-10-04] (REALiX™)
R3 MQAC; C:\Windows\System32\drivers\mqac.sys [175104 2015-09-12] (Microsoft Corporation)
R3 netr28x; C:\Windows\System32\drivers\netr28x.sys [2512016 2015-07-10] (MediaTek Inc.)
R0 pwdrvio; C:\Windows\System32\pwdrvio.sys [19152 2013-09-30] ()
S3 pwdspio; C:\WINDOWS\system32\pwdspio.sys [12504 2013-09-30] ()
R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [587264 2015-07-10] (Realtek )
S3 UdeCx; C:\Windows\System32\drivers\udecx.sys [44032 2015-07-10] ()
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44568 2015-07-10] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [291680 2015-07-10] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [119648 2015-07-10] (Microsoft Corporation)
U3 idsvc; no ImagePath
S3 wfpcapture; \SystemRoot\System32\drivers\wfpcapture.sys [X]
U3 wpcsvc; no ImagePath

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-10-09 11:09 - 2015-10-09 11:09 - 00035043 _____ C:\Users\Will\Desktop\FRST.txt
2015-10-09 11:07 - 2015-10-09 11:07 - 02194944 _____ (Farbar) C:\Users\Will\Desktop\FRST64.exe
2015-10-09 10:57 - 2015-10-09 11:09 - 00000000 ____D C:\FRST
2015-10-09 09:15 - 2015-10-09 09:15 - 00016148 _____ C:\WINDOWS\system32\WILL-PC_Will_HistoryPrediction.bin
2015-10-09 08:35 - 2015-10-09 08:35 - 00448512 _____ (OldTimer Tools) C:\Users\Will\Downloads\TFC (1).exe
2015-10-09 08:35 - 2015-10-09 08:35 - 00000774 _____ C:\Users\Will\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TFC.lnk
2015-10-09 08:34 - 2015-10-09 08:35 - 00448512 _____ (OldTimer Tools) C:\Users\Will\Downloads\TFC.exe
2015-10-08 14:31 - 2015-10-08 14:31 - 00000000 ___HD C:\OneDriveTemp
2015-10-08 14:31 - 2015-10-08 14:31 - 00000000 ____D C:\ProgramData\ATI
2015-10-08 08:55 - 2015-10-08 08:55 - 00061917 _____ C:\WINDOWS\SysWOW64\CCCInstall_201510080855578037.log
2015-10-08 08:55 - 2015-10-08 08:55 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center
2015-10-08 08:55 - 2015-10-08 08:55 - 00000000 ____D C:\Program Files\ATI Technologies
2015-10-08 08:54 - 2015-10-08 08:55 - 00000000 ____D C:\Program Files (x86)\ATI Technologies
2015-10-08 08:53 - 2015-10-08 08:53 - 00066655 _____ C:\WINDOWS\SysWOW64\CCCInstall_201510080853313237.log
2015-10-08 08:52 - 2015-10-08 08:52 - 00000000 ____D C:\Users\Default\AppData\Roaming\ATI
2015-10-08 08:52 - 2015-10-08 08:52 - 00000000 ____D C:\Users\Default\AppData\Local\ATI
2015-10-08 08:52 - 2015-10-08 08:52 - 00000000 ____D C:\Users\Default User\AppData\Roaming\ATI
2015-10-08 08:52 - 2015-10-08 08:52 - 00000000 ____D C:\Users\Default User\AppData\Local\ATI
2015-10-08 08:48 - 2015-10-08 08:50 - 00000000 ____D C:\WINDOWS\LastGood
2015-10-08 08:47 - 2015-10-08 08:47 - 00243696 _____ C:\WINDOWS\system32\clinfo.exe
2015-10-08 08:47 - 2015-10-08 08:47 - 00136176 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\mantle64.dll
2015-10-08 08:47 - 2015-10-08 08:47 - 00122352 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\mantle32.dll
2015-10-08 08:47 - 2015-10-08 08:47 - 00111600 _____ C:\WINDOWS\system32\hsa-thunk64.dll
2015-10-08 08:47 - 2015-10-08 08:47 - 00111088 _____ C:\WINDOWS\SysWOW64\hsa-thunk.dll
2015-10-08 08:47 - 2015-10-08 08:47 - 00103408 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\mantleaxl64.dll
2015-10-08 08:47 - 2015-10-08 08:47 - 00096752 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\mantleaxl32.dll
2015-10-08 08:47 - 2015-10-08 08:47 - 00012784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\detoured.dll
2015-10-08 08:47 - 2015-10-08 08:47 - 00012784 _____ (Microsoft Corporation) C:\WINDOWS\system32\detoured.dll
2015-10-08 08:46 - 2015-10-08 08:46 - 47794160 _____ (Advanced Micro Devices Inc.) C:\WINDOWS\system32\amdocl64.dll
2015-10-08 08:46 - 2015-10-08 08:46 - 30776304 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\atio6axx.dll
2015-10-08 08:46 - 2015-10-08 08:46 - 27544560 _____ (Advanced Micro Devices Inc.) C:\WINDOWS\system32\amdocl12cl64.dll
2015-10-08 08:46 - 2015-10-08 08:46 - 25320432 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\atioglxx.dll
2015-10-08 08:46 - 2015-10-08 08:46 - 15725552 _____ (Advanced Micro Devices Inc.) C:\WINDOWS\system32\aticaldd64.dll
2015-10-08 08:46 - 2015-10-08 08:46 - 14310896 _____ (Advanced Micro Devices Inc.) C:\WINDOWS\SysWOW64\aticaldd.dll
2015-10-08 08:46 - 2015-10-08 08:46 - 09355016 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\amdxc64.dll
2015-10-08 08:46 - 2015-10-08 08:46 - 07683096 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\amdxc32.dll
2015-10-08 08:46 - 2015-10-08 08:46 - 06686192 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\amdmantle64.dll
2015-10-08 08:46 - 2015-10-08 08:46 - 05216240 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\amdmantle32.dll
2015-10-08 08:46 - 2015-10-08 08:46 - 03471376 _____ C:\WINDOWS\SysWOW64\atiumdva.cap
2015-10-08 08:46 - 2015-10-08 08:46 - 03437632 _____ C:\WINDOWS\system32\atiumd6a.cap
2015-10-08 08:46 - 2015-10-08 08:46 - 01196032 _____ C:\WINDOWS\system32\amdocl_as64.exe
2015-10-08 08:46 - 2015-10-08 08:46 - 01070592 _____ C:\WINDOWS\system32\amdocl_ld64.exe
2015-10-08 08:46 - 2015-10-08 08:46 - 01004032 _____ C:\WINDOWS\SysWOW64\amdocl_as32.exe
2015-10-08 08:46 - 2015-10-08 08:46 - 00935408 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\atiadlxx.dll
2015-10-08 08:46 - 2015-10-08 08:46 - 00833800 _____ C:\WINDOWS\system32\amdicdxx.dat
2015-10-08 08:46 - 2015-10-08 08:46 - 00807424 _____ C:\WINDOWS\SysWOW64\amdocl_ld32.exe
2015-10-08 08:46 - 2015-10-08 08:46 - 00662392 _____ C:\WINDOWS\SysWOW64\atiapfxx.blb
2015-10-08 08:46 - 2015-10-08 08:46 - 00662392 _____ C:\WINDOWS\system32\atiapfxx.blb
2015-10-08 08:46 - 2015-10-08 08:46 - 00631280 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\amdlvr64.dll
2015-10-08 08:46 - 2015-10-08 08:46 - 00524272 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\amdlvr32.dll
2015-10-08 08:46 - 2015-10-08 08:46 - 00471320 _____ C:\WINDOWS\system32\amdmiracast.dll
2015-10-08 08:46 - 2015-10-08 08:46 - 00375792 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\atiapfxx.exe
2015-10-08 08:46 - 2015-10-08 08:46 - 00341488 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\ATIODE.exe
2015-10-08 08:46 - 2015-10-08 08:46 - 00213488 _____ C:\WINDOWS\system32\amdgfxinfo64.dll
2015-10-08 08:46 - 2015-10-08 08:46 - 00199664 _____ (AMD) C:\WINDOWS\system32\atitmm64.dll
2015-10-08 08:46 - 2015-10-08 08:46 - 00198640 _____ C:\WINDOWS\SysWOW64\amdgfxinfo32.dll
2015-10-08 08:46 - 2015-10-08 08:46 - 00177344 _____ C:\WINDOWS\system32\ativce03.dat
2015-10-08 08:46 - 2015-10-08 08:46 - 00175648 _____ C:\WINDOWS\system32\amde31a.dat
2015-10-08 08:46 - 2015-10-08 08:46 - 00168944 _____ C:\WINDOWS\system32\atieah64.exe
2015-10-08 08:46 - 2015-10-08 08:46 - 00165360 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atig6txx.dll
2015-10-08 08:46 - 2015-10-08 08:46 - 00152560 _____ C:\WINDOWS\SysWOW64\atieah32.exe
2015-10-08 08:46 - 2015-10-08 08:46 - 00143344 _____ C:\WINDOWS\system32\amdhdl64.dll
2015-10-08 08:46 - 2015-10-08 08:46 - 00132080 _____ C:\WINDOWS\SysWOW64\amdhdl32.dll
2015-10-08 08:46 - 2015-10-08 08:46 - 00100816 _____ C:\WINDOWS\system32\ativce02.dat
2015-10-08 08:46 - 2015-10-08 08:46 - 00088000 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atimpc64.dll
2015-10-08 08:46 - 2015-10-08 08:46 - 00088000 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\amdpcom64.dll
2015-10-08 08:46 - 2015-10-08 08:46 - 00083952 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atig6pxx.dll
2015-10-08 08:46 - 2015-10-08 08:46 - 00081168 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atimpc32.dll
2015-10-08 08:46 - 2015-10-08 08:46 - 00081160 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\amdpcom32.dll
2015-10-08 08:46 - 2015-10-08 08:46 - 00078320 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atiglpxx.dll
2015-10-08 08:46 - 2015-10-08 08:46 - 00078320 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atiglpxx.dll
2015-10-08 08:46 - 2015-10-08 08:46 - 00073712 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.dll
2015-10-08 08:46 - 2015-10-08 08:46 - 00071152 _____ (Advanced Micro Devices Inc.) C:\WINDOWS\system32\aticalrt64.dll
2015-10-08 08:46 - 2015-10-08 08:46 - 00068080 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.dll
2015-10-08 08:46 - 2015-10-08 08:46 - 00064496 _____ (Advanced Micro Devices Inc.) C:\WINDOWS\system32\aticalcl64.dll
2015-10-08 08:46 - 2015-10-08 08:46 - 00060912 _____ (Advanced Micro Devices Inc.) C:\WINDOWS\SysWOW64\aticalrt.dll
2015-10-08 08:46 - 2015-10-08 08:46 - 00059888 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\ATIODCLI.exe
2015-10-08 08:46 - 2015-10-08 08:46 - 00059376 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\amdmmcl6.dll
2015-10-08 08:46 - 2015-10-08 08:46 - 00057840 _____ (Advanced Micro Devices Inc.) C:\WINDOWS\SysWOW64\aticalcl.dll
2015-10-08 08:46 - 2015-10-08 08:46 - 00052208 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\Drivers\ati2erec.dll
2015-10-08 08:46 - 2015-10-08 08:46 - 00048112 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\amdmmcl.dll
2015-10-08 08:46 - 2015-10-08 08:46 - 00038384 _____ (AMD) C:\WINDOWS\system32\atimuixx.dll
2015-10-07 08:16 - 2015-10-07 08:16 - 00000000 _____ C:\eb8a1304eec7690736df388a
2015-10-07 08:16 - 2015-10-07 08:16 - 00000000 _____ C:\e21c02f7ea62d4cbbf1543
2015-10-07 08:16 - 2015-10-07 08:16 - 00000000 _____ C:\dfcd3f7e37e2cd2b9f4a58d20f89b7f7
2015-10-07 08:16 - 2015-10-07 08:16 - 00000000 _____ C:\ca985ff25eb59928e2c831
2015-10-07 08:16 - 2015-10-07 08:16 - 00000000 _____ C:\800ee3b0049fbbd8b5
2015-10-07 08:16 - 2015-10-07 08:16 - 00000000 _____ C:\7ab19f3774a69f23a31870
2015-10-07 08:16 - 2015-10-07 08:16 - 00000000 _____ C:\656eb6bb05d5bc6e49108ea0911f
2015-10-07 08:16 - 2015-10-07 08:16 - 00000000 _____ C:\4b635db90d8ba7f072080945
2015-10-06 10:34 - 2015-10-06 10:34 - 00000000 ____D C:\Users\Will\AppData\Roaming\dvdcss
2015-10-06 10:33 - 2015-10-06 10:34 - 00000000 ____D C:\Users\Will\AppData\Roaming\vlc
2015-10-06 10:33 - 2015-10-06 10:33 - 00001143 _____ C:\Users\Public\Desktop\VLC media player.lnk
2015-10-06 10:33 - 2015-10-06 10:33 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2015-10-06 10:32 - 2015-10-06 10:32 - 00000000 ____D C:\Program Files (x86)\VideoLAN
2015-10-06 10:31 - 2015-10-06 10:32 - 28849904 _____ C:\Users\Will\Downloads\vlc-2.2.1-win32.exe
2015-10-05 07:45 - 2015-10-05 07:45 - 00469776 _____ (Microsoft Corporation) C:\WINDOWS\system32\coin98ip.dll
2015-10-05 07:45 - 2015-10-05 07:45 - 00466736 _____ (Microsoft Corporation) C:\WINDOWS\system32\coin98itp.dll
2015-10-04 08:31 - 2015-10-04 08:32 - 00002229 _____ C:\Users\Public\Desktop\Driver Booster 3.lnk
2015-10-04 08:31 - 2015-10-04 08:32 - 00000000 ____D C:\Users\Will\AppData\LocalLow\IObit
2015-10-04 08:31 - 2015-10-04 08:31 - 00026528 _____ (REALiX™) C:\WINDOWS\SysWOW64\Drivers\HWiNFO64A.SYS
2015-10-04 08:31 - 2015-10-04 08:31 - 00003428 _____ C:\WINDOWS\System32\Tasks\Driver Booster Scheduler
2015-10-04 08:31 - 2015-10-04 08:31 - 00003074 _____ C:\WINDOWS\System32\Tasks\Driver Booster SkipUAC (Will)
2015-10-04 08:31 - 2015-10-04 08:31 - 00000000 ____D C:\WINDOWS\Tasks\ImCleanDisabled
2015-10-04 08:31 - 2015-10-04 08:31 - 00000000 ____D C:\Users\Will\AppData\Roaming\IObit
2015-10-04 08:31 - 2015-10-04 08:31 - 00000000 ____D C:\ProgramData\ProductData
2015-10-04 08:31 - 2015-10-04 08:31 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Driver Booster 3
2015-10-04 08:31 - 2015-10-04 08:31 - 00000000 ____D C:\ProgramData\IObit
2015-10-04 08:31 - 2015-10-04 08:31 - 00000000 ____D C:\Program Files (x86)\IObit
2015-10-01 16:47 - 2015-10-01 16:47 - 25780408 _____ C:\Users\Will\Downloads\CommunityShowcaseAqua3.themepack
2015-10-01 11:27 - 2015-09-17 02:50 - 02464216 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2015-10-01 11:27 - 2015-09-17 02:49 - 06487248 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2015-10-01 11:27 - 2015-09-17 02:48 - 02824248 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll
2015-10-01 11:27 - 2015-09-17 02:28 - 05120056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2015-10-01 11:27 - 2015-09-17 02:12 - 16708608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2015-10-01 11:27 - 2015-09-17 02:07 - 21875712 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2015-10-01 11:27 - 2015-09-17 02:04 - 07569408 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll
2015-10-01 11:27 - 2015-09-17 02:00 - 24595456 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2015-10-01 11:27 - 2015-09-17 02:00 - 02417664 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
2015-10-01 11:27 - 2015-09-17 01:54 - 03781120 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2015-10-01 11:27 - 2015-09-17 01:53 - 07055872 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll
2015-10-01 11:27 - 2015-09-17 01:51 - 13027840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2015-10-01 11:27 - 2015-09-17 01:51 - 02660864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll
2015-10-01 11:27 - 2015-09-17 01:47 - 07523328 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2015-10-01 11:27 - 2015-09-17 01:45 - 19325440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2015-10-01 11:27 - 2015-09-17 01:40 - 06101504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mos.dll
2015-10-01 11:27 - 2015-09-17 01:37 - 18806272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2015-10-01 11:27 - 2015-09-17 01:35 - 05079552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll
2015-10-01 11:27 - 2015-09-17 01:31 - 05454848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2015-10-01 11:26 - 2015-09-24 20:13 - 01276416 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifinetworkmanager.dll
2015-10-01 11:26 - 2015-09-24 19:24 - 00796160 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll
2015-10-01 11:26 - 2015-09-24 19:24 - 00689152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll
2015-10-01 11:26 - 2015-09-24 19:23 - 00579072 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
2015-10-01 11:26 - 2015-09-24 19:17 - 02178560 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2015-10-01 11:26 - 2015-09-24 19:08 - 03586560 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2015-10-01 11:26 - 2015-09-24 19:07 - 01382400 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2015-10-01 11:26 - 2015-09-24 19:06 - 01423872 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataService.dll
2015-10-01 11:26 - 2015-09-24 19:01 - 00856576 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContactApis.dll
2015-10-01 11:26 - 2015-09-24 19:00 - 01205248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Unistore.dll
2015-10-01 11:26 - 2015-09-24 19:00 - 00752640 _____ (Microsoft Corporation) C:\WINDOWS\system32\ChatApis.dll
2015-10-01 11:26 - 2015-09-24 18:43 - 00613376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll
2015-10-01 11:26 - 2015-09-24 18:42 - 01795072 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll
2015-10-01 11:26 - 2015-09-24 18:25 - 00928256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Unistore.dll
2015-10-01 11:26 - 2015-09-24 18:25 - 00625152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ContactApis.dll
2015-10-01 11:26 - 2015-09-17 02:50 - 01563392 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll
2015-10-01 11:26 - 2015-09-17 02:49 - 08020816 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2015-10-01 11:26 - 2015-09-17 02:49 - 01563472 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpmde.dll
2015-10-01 11:26 - 2015-09-17 02:49 - 00894256 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Wdf01000.sys
2015-10-01 11:26 - 2015-09-17 02:49 - 00553808 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncHost.exe
2015-10-01 11:26 - 2015-09-17 02:48 - 02494712 _____ C:\WINDOWS\system32\CoreUIComponents.dll
2015-10-01 11:26 - 2015-09-17 02:48 - 02432336 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2015-10-01 11:26 - 2015-09-17 02:48 - 02156400 _____ (Microsoft Corporation) C:\WINDOWS\system32\hevcdecoder.dll
2015-10-01 11:26 - 2015-09-17 02:48 - 01983824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2015-10-01 11:26 - 2015-09-17 02:48 - 00809352 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll
2015-10-01 11:26 - 2015-09-17 02:48 - 00784136 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
2015-10-01 11:26 - 2015-09-17 02:48 - 00584656 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll
2015-10-01 11:26 - 2015-09-17 02:48 - 00555768 _____ (Microsoft Corporation) C:\WINDOWS\system32\directmanipulation.dll
2015-10-01 11:26 - 2015-09-17 02:48 - 00537080 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWanAPI.dll
2015-10-01 11:26 - 2015-09-17 02:48 - 00516448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBHUB3.SYS
2015-10-01 11:26 - 2015-09-17 02:48 - 00505696 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2015-10-01 11:26 - 2015-09-17 02:48 - 00476760 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFCaptureEngine.dll
2015-10-01 11:26 - 2015-09-17 02:48 - 00395088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2015-10-01 11:26 - 2015-09-17 02:48 - 00332624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fastfat.sys
2015-10-01 11:26 - 2015-09-17 02:48 - 00243760 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
2015-10-01 11:26 - 2015-09-17 02:47 - 01397088 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll
2015-10-01 11:26 - 2015-09-17 02:44 - 00781976 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfds.dll
2015-10-01 11:26 - 2015-09-17 02:43 - 00966416 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll
2015-10-01 11:26 - 2015-09-17 02:37 - 01295712 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpx.dll
2015-10-01 11:26 - 2015-09-17 02:28 - 02154808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2015-10-01 11:26 - 2015-09-17 02:28 - 01357888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winmde.dll
2015-10-01 11:26 - 2015-09-17 02:28 - 00441168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncHost.exe
2015-10-01 11:26 - 2015-09-17 02:27 - 01766952 _____ C:\WINDOWS\SysWOW64\CoreUIComponents.dll
2015-10-01 11:26 - 2015-09-17 02:27 - 00454512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\directmanipulation.dll
2015-10-01 11:26 - 2015-09-17 02:26 - 02446648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2vdec.dll
2015-10-01 11:26 - 2015-09-17 02:26 - 01895568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hevcdecoder.dll
2015-10-01 11:26 - 2015-09-17 02:26 - 00646672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll
2015-10-01 11:26 - 2015-09-17 02:26 - 00508248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf.dll
2015-10-01 11:26 - 2015-09-17 02:26 - 00434376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFCaptureEngine.dll
2015-10-01 11:26 - 2015-09-17 02:26 - 00428128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWanAPI.dll
2015-10-01 11:26 - 2015-09-17 02:25 - 00962400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll
2015-10-01 11:26 - 2015-09-17 02:21 - 00658528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfds.dll
2015-10-01 11:26 - 2015-09-17 02:20 - 00764416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.appcore.dll
2015-10-01 11:26 - 2015-09-17 02:09 - 00269312 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll
2015-10-01 11:26 - 2015-09-17 02:08 - 00494592 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll
2015-10-01 11:26 - 2015-09-17 02:06 - 00690688 _____ (Microsoft Corporation) C:\WINDOWS\system32\CellularAPI.dll
2015-10-01 11:26 - 2015-09-17 02:06 - 00467968 _____ (Microsoft Corporation) C:\WINDOWS\system32\MBMediaManager.dll
2015-10-01 11:26 - 2015-09-17 02:06 - 00149504 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringservice.dll
2015-10-01 11:26 - 2015-09-17 02:05 - 02226688 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll
2015-10-01 11:26 - 2015-09-17 02:05 - 00483328 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneDriveSettingSyncProvider.dll
2015-10-01 11:26 - 2015-09-17 02:04 - 00910848 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedStartModel.dll
2015-10-01 11:26 - 2015-09-17 02:00 - 03248640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2015-10-01 11:26 - 2015-09-17 01:58 - 00503808 _____ (Microsoft Corporation) C:\WINDOWS\system32\tileobjserver.dll
2015-10-01 11:26 - 2015-09-17 01:57 - 02228736 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll
2015-10-01 11:26 - 2015-09-17 01:57 - 00403456 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenrollengine.dll
2015-10-01 11:26 - 2015-09-17 01:57 - 00281600 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEEventDispatcher.dll
2015-10-01 11:26 - 2015-09-17 01:57 - 00137728 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEStoreEventHandlers.dll
2015-10-01 11:26 - 2015-09-17 01:56 - 00859136 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll
2015-10-01 11:26 - 2015-09-17 01:56 - 00521728 _____ (Microsoft Corporation) C:\WINDOWS\system32\PsmServiceExtHost.dll
2015-10-01 11:26 - 2015-09-17 01:55 - 02236416 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2015-10-01 11:26 - 2015-09-17 01:55 - 01601536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Speech.dll
2015-10-01 11:26 - 2015-09-17 01:55 - 00671232 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUDFx02000.dll
2015-10-01 11:26 - 2015-09-17 01:55 - 00366592 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll
2015-10-01 11:26 - 2015-09-17 01:55 - 00346112 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngccredprov.dll
2015-10-01 11:26 - 2015-09-17 01:55 - 00120832 _____ (Microsoft Corporation) C:\WINDOWS\system32\omadmclient.exe
2015-10-01 11:26 - 2015-09-17 01:54 - 00780288 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2015-10-01 11:26 - 2015-09-17 01:52 - 01181696 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
2015-10-01 11:26 - 2015-09-17 01:52 - 00591360 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmsvc.dll
2015-10-01 11:26 - 2015-09-17 01:52 - 00570880 _____ (Microsoft Corporation) C:\WINDOWS\system32\MbaeApi.dll
2015-10-01 11:26 - 2015-09-17 01:52 - 00465920 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanconn.dll
2015-10-01 11:26 - 2015-09-17 01:52 - 00204800 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmcsp.dll
2015-10-01 11:26 - 2015-09-17 01:52 - 00162304 _____ (Microsoft Corporation) C:\WINDOWS\system32\SubscriptionMgr.dll
2015-10-01 11:26 - 2015-09-17 01:51 - 01812480 _____ (Microsoft Corporation) C:\WINDOWS\system32\pnidui.dll
2015-10-01 11:26 - 2015-09-17 01:51 - 01203712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Bluetooth.dll
2015-10-01 11:26 - 2015-09-17 01:51 - 01067520 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2015-10-01 11:26 - 2015-09-17 01:51 - 00359936 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncsi.dll
2015-10-01 11:26 - 2015-09-17 01:50 - 00312832 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsApi.dll
2015-10-01 11:26 - 2015-09-17 01:49 - 02740224 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2015-10-01 11:26 - 2015-09-17 01:49 - 01290240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Shell.dll
2015-10-01 11:26 - 2015-09-17 01:49 - 01010176 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXService.dll
2015-10-01 11:26 - 2015-09-17 01:48 - 02093056 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidsvc.dll
2015-10-01 11:26 - 2015-09-17 01:48 - 00517632 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationController.dll
2015-10-01 11:26 - 2015-09-17 01:48 - 00408064 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredProvDataModel.dll
2015-10-01 11:26 - 2015-09-17 01:48 - 00387584 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppBroker.dll
2015-10-01 11:26 - 2015-09-17 01:48 - 00347136 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncryptprov.dll
2015-10-01 11:26 - 2015-09-17 01:48 - 00273920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.LockScreen.dll
2015-10-01 11:26 - 2015-09-17 01:47 - 00513536 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngcsvc.dll
2015-10-01 11:26 - 2015-09-17 01:47 - 00371712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OneDriveSettingSyncProvider.dll
2015-10-01 11:26 - 2015-09-17 01:47 - 00186880 _____ (Microsoft Corporation) C:\WINDOWS\system32\cloudAP.dll
2015-10-01 11:26 - 2015-09-17 01:46 - 00928256 _____ (Microsoft Corporation) C:\WINDOWS\system32\JpMapControl.dll
2015-10-01 11:26 - 2015-09-17 01:46 - 00414208 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll
2015-10-01 11:26 - 2015-09-17 01:46 - 00224256 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCore.dll
2015-10-01 11:26 - 2015-09-17 01:46 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCsp.dll
2015-10-01 11:26 - 2015-09-17 01:45 - 04791296 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2015-10-01 11:26 - 2015-09-17 01:45 - 01331200 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll
2015-10-01 11:26 - 2015-09-17 01:45 - 00869376 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlCore.dll
2015-10-01 11:26 - 2015-09-17 01:45 - 00832512 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll
2015-10-01 11:26 - 2015-09-17 01:45 - 00627712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.dll
2015-10-01 11:26 - 2015-09-17 01:44 - 01844736 _____ (Microsoft Corporation) C:\WINDOWS\system32\workfolderssvc.dll
2015-10-01 11:26 - 2015-09-17 01:44 - 00526336 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll
2015-10-01 11:26 - 2015-09-17 01:43 - 01213440 _____ (Microsoft Corporation) C:\WINDOWS\system32\RemoteNaturalLanguage.dll
2015-10-01 11:26 - 2015-09-17 01:43 - 00378368 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemEventsBrokerServer.dll
2015-10-01 11:26 - 2015-09-17 01:43 - 00185344 _____ (Microsoft Corporation) C:\WINDOWS\system32\psmsrv.dll
2015-10-01 11:26 - 2015-09-17 01:42 - 02646528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
2015-10-01 11:26 - 2015-09-17 01:41 - 00217088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VEEventDispatcher.dll
2015-10-01 11:26 - 2015-09-17 01:40 - 01918464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
2015-10-01 11:26 - 2015-09-17 01:40 - 01162240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Speech.dll
2015-10-01 11:26 - 2015-09-17 01:39 - 00587264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll
2015-10-01 11:26 - 2015-09-17 01:38 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\usoapi.dll
2015-10-01 11:26 - 2015-09-17 01:37 - 00454656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MbaeApi.dll
2015-10-01 11:26 - 2015-09-17 01:35 - 02207232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2015-10-01 11:26 - 2015-09-17 01:35 - 01820160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Logon.dll
2015-10-01 11:26 - 2015-09-17 01:35 - 00828928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Bluetooth.dll
2015-10-01 11:26 - 2015-09-17 01:34 - 00253440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsApi.dll
2015-10-01 11:26 - 2015-09-17 01:32 - 03579904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2015-10-01 11:26 - 2015-09-17 01:32 - 00336384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CredProvDataModel.dll
2015-10-01 11:26 - 2015-09-17 01:32 - 00313856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LockAppBroker.dll
2015-10-01 11:26 - 2015-09-17 01:32 - 00195072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.LockScreen.dll
2015-10-01 11:26 - 2015-09-17 01:30 - 00311808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll
2015-10-01 11:26 - 2015-09-17 01:29 - 01104384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll
2015-10-01 11:26 - 2015-09-17 01:29 - 00701952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\JpMapControl.dll
2015-10-01 11:26 - 2015-09-17 01:29 - 00677888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapControlCore.dll
2015-10-01 11:26 - 2015-09-17 01:29 - 00464896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.dll
2015-10-01 11:26 - 2015-09-17 01:26 - 00899584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RemoteNaturalLanguage.dll
2015-10-01 11:26 - 2015-09-17 01:16 - 00512000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll
2015-10-01 11:26 - 2015-09-12 22:05 - 02987520 _____ (Microsoft Corporation) C:\WINDOWS\system32\esent.dll
2015-10-01 11:26 - 2015-09-12 21:41 - 02639872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\esent.dll
2015-10-01 11:25 - 2015-09-24 20:35 - 00257024 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataAccountApis.dll
2015-10-01 11:25 - 2015-09-24 20:34 - 00223232 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneCallHistoryApis.dll
2015-10-01 11:25 - 2015-09-24 19:34 - 00195584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataAccountApis.dll
2015-10-01 11:25 - 2015-09-24 19:34 - 00172032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PhoneCallHistoryApis.dll
2015-10-01 11:25 - 2015-09-24 19:05 - 00288256 _____ (Microsoft Corporation) C:\WINDOWS\system32\PimIndexMaintenance.dll
2015-10-01 11:25 - 2015-09-24 19:01 - 00685568 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppointmentApis.dll
2015-10-01 11:25 - 2015-09-24 19:00 - 00720896 _____ (Microsoft Corporation) C:\WINDOWS\system32\EmailApis.dll
2015-10-01 11:25 - 2015-09-24 19:00 - 00163840 _____ (Microsoft Corporation) C:\WINDOWS\system32\CallHistoryClient.dll
2015-10-01 11:25 - 2015-09-24 18:53 - 00590336 _____ (Microsoft Corporation) C:\WINDOWS\system32\MessagingDataModel2.dll
2015-10-01 11:25 - 2015-09-24 18:43 - 00480256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Web.Core.dll
2015-10-01 11:25 - 2015-09-24 18:25 - 00579584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppointmentApis.dll
2015-10-01 11:25 - 2015-09-24 18:25 - 00557568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ChatApis.dll
2015-10-01 11:25 - 2015-09-24 18:25 - 00525312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EmailApis.dll
2015-10-01 11:25 - 2015-09-24 18:24 - 00131072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CallHistoryClient.dll
2015-10-01 11:25 - 2015-09-24 18:19 - 00466432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MessagingDataModel2.dll
2015-10-01 11:25 - 2015-09-19 01:14 - 00102304 _____ (Microsoft Corporation) C:\WINDOWS\system32\omadmapi.dll
2015-10-01 11:25 - 2015-09-17 02:50 - 00099664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pdc.sys
2015-10-01 11:25 - 2015-09-17 02:50 - 00088384 _____ (Microsoft Corporation) C:\WINDOWS\system32\remoteaudioendpoint.dll
2015-10-01 11:25 - 2015-09-17 02:49 - 00501008 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
2015-10-01 11:25 - 2015-09-17 02:48 - 00406864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\FWPKCLNT.SYS
2015-10-01 11:25 - 2015-09-17 02:48 - 00278352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys
2015-10-01 11:25 - 2015-09-17 02:39 - 00081488 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2015-10-01 11:25 - 2015-09-17 02:37 - 01168736 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys
2015-10-01 11:25 - 2015-09-17 02:28 - 00407608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
2015-10-01 11:25 - 2015-09-17 02:28 - 00074880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\remoteaudioendpoint.dll
2015-10-01 11:25 - 2015-09-17 02:11 - 00160256 _____ (Microsoft Corporation) C:\WINDOWS\system32\enrollmentapi.dll
2015-10-01 11:25 - 2015-09-17 02:10 - 00169984 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmregistration.dll
2015-10-01 11:25 - 2015-09-17 02:09 - 00143360 _____ (Microsoft Corporation) C:\WINDOWS\system32\provops.dll
2015-10-01 11:25 - 2015-09-17 02:08 - 00053760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Speech.Pal.dll
2015-10-01 11:25 - 2015-09-17 02:08 - 00026624 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManagerShellext.exe
2015-10-01 11:25 - 2015-09-17 02:04 - 00504320 _____ (Microsoft Corporation) C:\WINDOWS\system32\DataSenseHandlers.dll
2015-10-01 11:25 - 2015-09-17 02:03 - 00267776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Management.dll
2015-10-01 11:25 - 2015-09-17 02:03 - 00187904 _____ (Microsoft Corporation) C:\WINDOWS\system32\provisioningcsp.dll
2015-10-01 11:25 - 2015-09-17 02:03 - 00154624 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcertinst.exe
2015-10-01 11:25 - 2015-09-17 02:03 - 00088064 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngckeyenum.dll
2015-10-01 11:25 - 2015-09-17 02:03 - 00083968 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceEnroller.exe
2015-10-01 11:25 - 2015-09-17 02:02 - 00168960 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmmigrator.dll
2015-10-01 11:25 - 2015-09-17 02:02 - 00068096 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseDesktopAppMgmtCSP.dll
2015-10-01 11:25 - 2015-09-17 02:00 - 00446976 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapConfiguration.dll
2015-10-01 11:25 - 2015-09-17 02:00 - 00106496 _____ (Microsoft Corporation) C:\WINDOWS\system32\KeywordDetectorMsftSidAdapter.dll
2015-10-01 11:25 - 2015-09-17 01:56 - 00317440 _____ (Microsoft Corporation) C:\WINDOWS\system32\configmanager2.dll
2015-10-01 11:25 - 2015-09-17 01:55 - 00202240 _____ (Microsoft Corporation) C:\WINDOWS\system32\accountaccessor.dll
2015-10-01 11:25 - 2015-09-17 01:55 - 00121856 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcsps.dll
2015-10-01 11:25 - 2015-09-17 01:55 - 00073728 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwancfg.dll
2015-10-01 11:25 - 2015-09-17 01:54 - 00324096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2015-10-01 11:25 - 2015-09-17 01:52 - 06572032 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanmm.dll
2015-10-01 11:25 - 2015-09-17 01:52 - 01216512 _____ (Microsoft Corporation) C:\WINDOWS\system32\netcenter.dll
2015-10-01 11:25 - 2015-09-17 01:52 - 00856576 _____ (Microsoft Corporation) C:\WINDOWS\system32\MPSSVC.dll
2015-10-01 11:25 - 2015-09-17 01:52 - 00371712 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlasvc.dll
2015-10-01 11:25 - 2015-09-17 01:51 - 00145920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mdmregistration.dll
2015-10-01 11:25 - 2015-09-17 01:50 - 00421888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Bluetooth.dll
2015-10-01 11:25 - 2015-09-17 01:50 - 00320000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\portcls.sys
2015-10-01 11:25 - 2015-09-17 01:50 - 00221184 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationPeWiFi.dll
2015-10-01 11:25 - 2015-09-17 01:50 - 00204288 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationPeCell.dll
2015-10-01 11:25 - 2015-09-17 01:50 - 00036352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\buttonconverter.sys
2015-10-01 11:25 - 2015-09-17 01:49 - 00771072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2015-10-01 11:25 - 2015-09-17 01:49 - 00439296 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationWebproxy.dll
2015-10-01 11:25 - 2015-09-17 01:49 - 00342016 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationGeofences.dll
2015-10-01 11:25 - 2015-09-17 01:49 - 00268800 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationFramework.dll
2015-10-01 11:25 - 2015-09-17 01:49 - 00215552 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationCrowdsource.dll
2015-10-01 11:25 - 2015-09-17 01:49 - 00176640 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationPeIP.dll
2015-10-01 11:25 - 2015-09-17 01:49 - 00095744 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationWiFiAdapter.dll
2015-10-01 11:25 - 2015-09-17 01:49 - 00041472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Speech.Pal.dll
2015-10-01 11:25 - 2015-09-17 01:46 - 00621056 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
2015-10-01 11:25 - 2015-09-17 01:46 - 00084480 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDMAppInstaller.exe
2015-10-01 11:25 - 2015-09-17 01:46 - 00079872 _____ (Microsoft Corporation) C:\WINDOWS\system32\HttpsDataSource.dll
2015-10-01 11:25 - 2015-09-17 01:46 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\syncmlhook.dll
2015-10-01 11:25 - 2015-09-17 01:45 - 00193024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Management.dll
2015-10-01 11:25 - 2015-09-17 01:44 - 00599552 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnapps.dll
2015-10-01 11:25 - 2015-09-17 01:44 - 00274944 _____ (Microsoft Corporation) C:\WINDOWS\system32\syncutil.dll
2015-10-01 11:25 - 2015-09-17 01:43 - 00328704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapConfiguration.dll
2015-10-01 11:25 - 2015-09-17 01:39 - 00247808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2015-10-01 11:25 - 2015-09-17 01:36 - 01171456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netcenter.dll
2015-10-01 11:25 - 2015-09-17 01:33 - 00574464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll
2015-10-01 11:25 - 2015-09-17 01:31 - 00268800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ncryptprov.dll
2015-10-01 11:25 - 2015-09-17 01:28 - 00473088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wpnapps.dll
2015-09-30 09:38 - 2015-09-30 09:39 - 00217928 _____ C:\Users\Will\Downloads\Hiren's_BootCD.exe
2015-09-28 19:17 - 2015-09-29 08:19 - 00000000 ____D C:\Users\Will\AppData\Roaming\ImgBurn
2015-09-28 18:53 - 2015-09-28 20:45 - 2916417536 _____ C:\Users\Will\Downloads\Driver-Resource-DVD-Windows-7-64bit.iso
2015-09-28 16:24 - 2015-09-28 17:54 - 3320903680 _____ C:\Users\Will\Downloads\Windows-7-All-x64-English.iso
2015-09-28 16:06 - 2015-09-29 09:59 - 00000000 ____D C:\Users\Will\Documents\Outlook Files
2015-09-28 16:01 - 2015-09-29 08:37 - 00001270 _____ C:\Users\Public\Desktop\Vz In-Home Agent.lnk
2015-09-28 16:01 - 2015-09-29 08:37 - 00000000 ____D C:\Users\Will\AppData\Roaming\Verizon
2015-09-28 16:01 - 2015-09-28 16:01 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Vz In-Home Agent
2015-09-28 16:01 - 2015-09-28 16:01 - 00000000 ____D C:\Program Files (x86)\Verizon
2015-09-28 16:01 - 2015-09-28 16:01 - 00000000 _____ C:\Users\Will\Downloads\VzInHomeAgent.exe.rfr835z.partial
2015-09-28 15:41 - 2015-09-29 08:37 - 00001792 _____ C:\Users\Will\Install-VzInHomeAgentLog.log
2015-09-28 15:41 - 2015-09-28 15:41 - 01496152 _____ C:\Users\Will\Downloads\VzInHomeAgent.exe
2015-09-28 09:31 - 2015-09-28 09:31 - 00000000 ____D C:\Users\Will\AppData\LocalLow\Adobe
2015-09-28 09:31 - 2015-09-28 09:31 - 00000000 ____D C:\Users\Will\AppData\Local\CEF
2015-09-28 09:28 - 2015-09-28 09:29 - 00000000 ____D C:\Users\Will\AppData\Local\Deployment
2015-09-28 09:16 - 2015-10-02 08:39 - 00000000 ____D C:\Users\Will\AppData\Local\Setup79516937
2015-09-28 09:16 - 2015-09-28 09:16 - 58082952 _____ (Microsoft Corporation) C:\Users\Will\Downloads\IE11-Install [1].exe
2015-09-28 09:15 - 2015-10-02 08:39 - 00000000 ____D C:\Users\Will\AppData\Local\{5BFD6DA1-7F55-0119-12CD-24F136A5D869}
2015-09-28 09:15 - 2015-09-28 09:16 - 00000000 ____D C:\Users\Will\AppData\Local\role
2015-09-28 09:14 - 2015-09-28 09:14 - 01004856 _____ (Web Installer ) C:\Users\Will\Downloads\IE11-Install.exe
2015-09-27 11:31 - 2015-09-27 12:04 - 00003972 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task
2015-09-27 11:31 - 2015-09-27 11:31 - 00002124 _____ C:\Users\Public\Desktop\Acrobat Reader DC.lnk
2015-09-27 11:30 - 2015-09-27 11:30 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2015-09-27 11:24 - 2015-10-09 08:22 - 00004150 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{98612AE2-C099-468D-9871-8A39429B37FB}
2015-09-27 11:21 - 2015-09-27 11:22 - 00921488 _____ (Web ) C:\Users\Will\Downloads\Adobe Reader Setup.exe
2015-09-27 11:18 - 2015-09-27 11:34 - 00000000 ____D C:\Users\Will\Documents\Readiris
2015-09-27 11:17 - 2015-09-27 11:17 - 00001071 _____ C:\Users\Public\Desktop\Readiris Pro 12.lnk
2015-09-27 11:17 - 2015-09-27 11:17 - 00000150 _____ C:\WINDOWS\Readiris.ini
2015-09-27 11:17 - 2015-09-27 11:17 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\I.R.I.S. Applications
2015-09-27 11:17 - 2015-09-27 11:17 - 00000000 ____D C:\Program Files (x86)\Readiris Pro 12
2015-09-27 10:46 - 2015-09-27 10:46 - 00002753 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Streets & Trips 2013.lnk
2015-09-27 10:43 - 2015-09-27 10:45 - 00000000 ____D C:\Program Files (x86)\Microsoft Streets & Trips 2013
2015-09-27 10:30 - 2015-09-27 10:30 - 00000000 ____D C:\Program Files (x86)\MSECache
2015-09-27 08:54 - 2015-09-27 08:55 - 00913127 _____ C:\Users\Will\Downloads\Movie.zip
2015-09-26 16:31 - 2015-09-26 16:31 - 00000000 ____D C:\Users\Will\Downloads\dell5010
2015-09-26 16:29 - 2015-09-28 18:51 - 00000000 ____D C:\Users\Will\AppData\Roaming\EZ93DownloadManager
2015-09-26 16:29 - 2015-09-26 16:29 - 00713367 _____ C:\Users\Will\Downloads\EZ93DownloadManager (1).exe
2015-09-26 16:28 - 2015-09-26 16:28 - 00713367 _____ C:\Users\Will\Downloads\EZ93DownloadManager.exe
2015-09-26 12:17 - 2015-09-26 12:19 - 66112265 _____ C:\Users\Will\Downloads\WNA1100_Setup_v2.1.0.2.zip
2015-09-26 10:35 - 2015-09-28 09:15 - 00001220 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-09-26 10:35 - 2015-09-26 10:41 - 00000000 ____D C:\Users\Will\AppData\Local\Mozilla
2015-09-26 10:35 - 2015-09-26 10:37 - 00000000 ____D C:\Users\Will\AppData\Roaming\Mozilla
2015-09-26 10:35 - 2015-09-26 10:35 - 00001232 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-09-26 10:35 - 2015-09-26 10:35 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2015-09-26 10:35 - 2015-09-26 10:35 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2015-09-26 10:33 - 2015-09-26 10:34 - 00243688 _____ C:\Users\Will\Downloads\Firefox Setup Stub 41.0.exe
2015-09-25 09:03 - 2015-09-25 09:03 - 00000000 ____D C:\WINDOWS\PCHEALTH
2015-09-25 08:53 - 2015-09-25 08:53 - 00000000 ____D C:\Users\Will\AppData\Roaming\edu.media.mit.Scratch2Editor
2015-09-25 08:52 - 2015-09-27 11:30 - 00000000 ____D C:\Program Files (x86)\Adobe
2015-09-25 08:52 - 2015-09-25 08:52 - 18509368 _____ (Adobe Systems Inc.) C:\Users\Will\Downloads\AdobeAIRInstaller (1).exe
2015-09-25 08:45 - 2015-09-25 08:45 - 00000962 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Scratch 2.lnk
2015-09-25 08:45 - 2015-09-25 08:45 - 00000950 _____ C:\Users\Public\Desktop\Scratch 2.lnk
2015-09-25 08:45 - 2015-09-25 08:45 - 00000000 ____D C:\Users\Default\AppData\Roaming\Macromedia
2015-09-25 08:45 - 2015-09-25 08:45 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Macromedia
2015-09-25 08:45 - 2015-09-25 08:45 - 00000000 ____D C:\Program Files (x86)\Scratch 2
2015-09-25 08:39 - 2015-09-25 08:41 - 45330294 _____ C:\Users\Will\Downloads\Scratch-439.3.exe
2015-09-25 08:25 - 2015-09-27 12:03 - 00000000 ____D C:\ProgramData\Adobe
2015-09-25 08:24 - 2015-09-25 08:25 - 18509368 _____ (Adobe Systems Inc.) C:\Users\Will\Downloads\AdobeAIRInstaller.exe
2015-09-25 08:14 - 2015-09-28 09:31 - 00000000 ____D C:\Users\Will\AppData\Local\Adobe
2015-09-25 08:12 - 2015-09-27 08:58 - 00000000 ____D C:\Users\Will\Desktop\Scratch
2015-09-24 08:19 - 2015-09-24 08:20 - 00000000 ____D C:\Users\Will\.idlerc
2015-09-23 07:23 - 2015-09-23 07:23 - 00000000 ____D C:\Users\Will\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HP
2015-09-22 08:52 - 2015-09-22 08:59 - 00000022 _____ C:\Users\Will\Downloads\VIAHDAud_v11_1000b_08182015.zip
2015-09-22 08:49 - 2015-09-22 08:49 - 04944608 _____ (Advanced Micro Devices, Inc.) C:\Users\Will\Downloads\autodetectutility.exe
2015-09-20 10:38 - 2015-09-20 10:38 - 00001104 _____ C:\WINDOWS\PWCMDLST.BAK
2015-09-20 10:26 - 2015-09-20 10:26 - 00001025 _____ C:\Users\Public\Desktop\MiniTool Partition Wizard Free.lnk
2015-09-20 10:26 - 2015-09-20 10:26 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MiniTool Partition Wizard Free 9.1
2015-09-20 10:26 - 2015-09-20 10:26 - 00000000 ____D C:\Program Files\MiniTool Partition Wizard Free 9.1
2015-09-20 10:26 - 2015-08-11 12:22 - 03067392 _____ C:\WINDOWS\system32\pwNative.exe
2015-09-20 10:26 - 2013-09-30 15:26 - 00019152 ____N C:\WINDOWS\system32\pwdrvio.sys
2015-09-20 10:26 - 2013-09-30 15:26 - 00012504 ____N C:\WINDOWS\system32\pwdspio.sys
2015-09-20 10:24 - 2015-09-20 10:25 - 32262960 _____ (MiniTool Solution Ltd. ) C:\Users\Will\Downloads\pwfree91.exe
2015-09-20 09:03 - 2015-10-06 12:05 - 00000000 ____D C:\Users\Will\Desktop\learn
2015-09-20 09:02 - 2015-09-20 09:02 - 00001124 _____ C:\Users\Will\Desktop\Notepad++.lnk
2015-09-20 09:02 - 2015-09-20 09:02 - 00000000 ____D C:\Users\Will\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Notepad++
2015-09-20 09:02 - 2015-09-20 09:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Notepad++
2015-09-20 09:01 - 2015-09-24 08:27 - 00000000 ____D C:\Users\Will\AppData\Roaming\Notepad++
2015-09-20 09:01 - 2015-09-20 09:02 - 00000000 ____D C:\Program Files (x86)\Notepad++
2015-09-20 09:01 - 2015-09-20 09:01 - 05311104 _____ C:\Users\Will\Downloads\npp.6.8.3.Installer.exe
2015-09-20 08:27 - 2015-09-20 08:27 - 00000000 ____D C:\Users\Will\BACKUP
2015-09-17 10:58 - 2015-09-17 10:58 - 00000020 ___SH C:\Users\DefaultAppPool\ntuser.ini
2015-09-17 10:58 - 2015-09-17 10:58 - 00000000 ____D C:\Users\DefaultAppPool
2015-09-17 10:58 - 2015-09-17 09:25 - 00000000 ____D C:\Users\DefaultAppPool\AppData\Local\Microsoft Help
2015-09-17 10:58 - 2015-09-12 18:41 - 00000000 ____D C:\Users\DefaultAppPool\AppData\Roaming\TuneUp Software
2015-09-17 10:58 - 2015-09-12 18:26 - 00000000 ___RD C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-09-17 10:58 - 2015-07-10 07:04 - 00000000 __RSD C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell
2015-09-17 10:58 - 2015-07-10 07:04 - 00000000 ___RD C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-09-17 10:58 - 2015-07-10 07:04 - 00000000 ___RD C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2015-09-17 10:58 - 2015-07-10 07:04 - 00000000 ____D C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-09-17 09:25 - 2015-09-17 09:25 - 00000000 ____D C:\Users\Default\AppData\Local\Microsoft Help
2015-09-17 09:25 - 2015-09-17 09:25 - 00000000 ____D C:\Users\Default User\AppData\Local\Microsoft Help
2015-09-17 09:13 - 2015-09-17 09:13 - 00000000 ____D C:\Users\Will\AppData\LocalLow\Temp
2015-09-17 09:10 - 2015-09-17 09:10 - 00001341 _____ C:\Users\Will\Desktop\Revo Uninstaller.lnk
2015-09-17 09:10 - 2015-09-17 09:10 - 00000000 ____D C:\Program Files (x86)\VS Revo Group
2015-09-17 09:09 - 2015-09-17 09:10 - 02623656 _____ (VS Revo Group Ltd.) C:\Users\Will\Downloads\revosetup.exe
2015-09-17 08:20 - 2015-09-19 12:09 - 00076244 _____ C:\Reflect_Install.log
2015-09-17 08:03 - 2015-09-17 08:20 - 00000000 ____D C:\ProgramData\Macrium
2015-09-16 18:29 - 2015-09-16 18:29 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
2015-09-16 08:34 - 2015-09-16 08:34 - 00000000 ____D C:\3a2b8a2e6a611b23e5fb74
2015-09-16 08:33 - 2015-09-17 00:33 - 00000000 ____D C:\8ac5d4d53ea3c044155b1d
2015-09-16 08:26 - 2015-09-16 08:26 - 00000000 ____D C:\Users\Will\AppData\Local\PeerDistRepub
2015-09-14 17:45 - 2015-09-14 17:45 - 00000621 _____ C:\Users\Will\Desktop\prodtuctkey.vbs
2015-09-14 17:37 - 2015-09-14 17:37 - 00001099 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Windows Firewall Control.lnk
2015-09-14 17:37 - 2015-09-14 17:37 - 00001093 _____ C:\Users\Public\Desktop\Windows Firewall Control.lnk
2015-09-14 17:37 - 2015-09-14 17:37 - 00000000 ____D C:\Program Files\Windows Firewall Control
2015-09-14 17:36 - 2015-09-14 17:36 - 00365056 _____ (BiniSoft.org) C:\Users\Will\Downloads\wfc4setup.exe
2015-09-13 11:10 - 2015-09-13 11:11 - 02953520 _____ (AVAST Software) C:\Users\Will\Downloads\avast-browser-cleanup.exe
2015-09-13 10:38 - 2015-09-13 10:38 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2015-09-13 10:38 - 2015-09-13 10:38 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2015-09-13 10:38 - 2015-09-13 10:38 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2015-09-13 10:37 - 2015-09-13 10:37 - 13155552 _____ (Microsoft Corporation) C:\Users\Will\Downloads\Silverlight_x64.exe
2015-09-13 10:33 - 2015-09-16 10:42 - 00000000 ____D C:\Users\Will\AppData\Local\MicrosoftEdge
2015-09-12 22:07 - 2015-09-12 19:02 - 00000000 ___DC C:\WINDOWS\Panther
2015-09-12 22:06 - 2015-09-12 18:18 - 00000000 __SHD C:\Recovery
2015-09-12 22:01 - 2015-09-12 22:01 - 00000000 ____D C:\Windows.old
2015-09-12 22:00 - 2015-09-15 12:12 - 00812008 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2015-09-12 22:00 - 2015-09-15 12:12 - 00178152 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2015-09-12 21:59 - 2015-09-12 21:59 - 14241792 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll
2015-09-12 21:59 - 2015-09-12 21:59 - 12589056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll
2015-09-12 21:59 - 2015-09-12 21:59 - 12503552 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2015-09-12 21:59 - 2015-09-12 21:59 - 11262464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2015-09-12 21:59 - 2015-09-12 21:59 - 02880032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2015-09-12 21:59 - 2015-09-12 21:59 - 02116448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
2015-09-12 21:59 - 2015-09-12 21:59 - 01822280 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2015-09-12 21:59 - 2015-09-12 21:59 - 01533496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2015-09-12 21:59 - 2015-09-12 21:59 - 01411072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Editing.dll
2015-09-12 21:59 - 2015-09-12 21:59 - 01200400 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcrt4.dll
2015-09-12 21:59 - 2015-09-12 21:59 - 01087296 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll
2015-09-12 21:59 - 2015-09-12 21:59 - 01043968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Editing.dll
2015-09-12 21:59 - 2015-09-12 21:59 - 01043872 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll
2015-09-12 21:59 - 2015-09-12 21:59 - 01025840 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsrcsnk.dll
2015-09-12 21:59 - 2015-09-12 21:59 - 00980832 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
2015-09-12 21:59 - 2015-09-12 21:59 - 00918320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll
2015-09-12 21:59 - 2015-09-12 21:59 - 00896144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsrcsnk.dll
2015-09-12 21:59 - 2015-09-12 21:59 - 00877016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll
2015-09-12 21:59 - 2015-09-12 21:59 - 00846336 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll
2015-09-12 21:59 - 2015-09-12 21:59 - 00826880 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2015-09-12 21:59 - 2015-09-12 21:59 - 00816576 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll
2015-09-12 21:59 - 2015-09-12 21:59 - 00799232 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpccpl.dll
2015-09-12 21:59 - 2015-09-12 21:59 - 00713312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll
2015-09-12 21:59 - 2015-09-12 21:59 - 00670208 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll
2015-09-12 21:59 - 2015-09-12 21:59 - 00596480 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSync.dll
2015-09-12 21:59 - 2015-09-12 21:59 - 00584704 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Sensors.dll
2015-09-12 21:59 - 2015-09-12 21:59 - 00569344 _____ (Microsoft Corporation) C:\WINDOWS\system32\MCRecvSrc.dll
2015-09-12 21:59 - 2015-09-12 21:59 - 00527952 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2015-09-12 21:59 - 2015-09-12 21:59 - 00497152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToManager.dll
2015-09-12 21:59 - 2015-09-12 21:59 - 00487424 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmkvsrcsnk.dll
2015-09-12 21:59 - 2015-09-12 21:59 - 00484352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSync.dll
2015-09-12 21:59 - 2015-09-12 21:59 - 00480256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MCRecvSrc.dll
2015-09-12 21:59 - 2015-09-12 21:59 - 00445240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioEng.dll
2015-09-12 21:59 - 2015-09-12 21:59 - 00437248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Sensors.dll
2015-09-12 21:59 - 2015-09-12 21:59 - 00420352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GamePanel.exe
2015-09-12 21:59 - 2015-09-12 21:59 - 00404480 _____ C:\WINDOWS\system32\diagtrack_wininternal.dll
2015-09-12 21:59 - 2015-09-12 21:59 - 00373248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmkvsrcsnk.dll
2015-09-12 21:59 - 2015-09-12 21:59 - 00333168 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFPlay.dll
2015-09-12 21:59 - 2015-09-12 21:59 - 00294912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll
2015-09-12 21:59 - 2015-09-12 21:59 - 00285632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFPlay.dll
2015-09-12 21:59 - 2015-09-12 21:59 - 00280064 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2015-09-12 21:59 - 2015-09-12 21:59 - 00275456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcastdvr.exe
2015-09-12 21:59 - 2015-09-12 21:59 - 00195584 _____ (Microsoft Corporation) C:\WINDOWS\system32\fwpolicyiomgr.dll
2015-09-12 21:59 - 2015-09-12 21:59 - 00187392 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupSvc.dll
2015-09-12 21:59 - 2015-09-12 21:59 - 00163328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fwpolicyiomgr.dll
2015-09-12 21:59 - 2015-09-12 21:59 - 00137216 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationPermissions.dll
2015-09-12 21:59 - 2015-09-12 21:59 - 00102752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mountmgr.sys
2015-09-12 21:59 - 2015-09-12 21:59 - 00097128 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcd.dll
2015-09-12 21:59 - 2015-09-12 21:59 - 00082616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcd.dll
2015-09-12 21:59 - 2015-09-12 21:59 - 00078848 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationFrameworkInternalPS.dll
2015-09-12 21:59 - 2015-09-12 21:59 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Cortana.PAL.Desktop.dll
2015-09-12 21:59 - 2015-09-12 21:59 - 00052264 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wpcfltr.sys
2015-09-12 21:58 - 2015-09-12 21:58 - 22324656 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 20857848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 11557888 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 09889792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 08613200 _____ (Microsoft Corp.) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 06878256 _____ (Microsoft Corp.) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 06305792 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Search.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 04760576 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExplorerFrame.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 04611584 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 04532304 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2015-09-12 21:58 - 2015-09-12 21:58 - 04398080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Search.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 04350464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExplorerFrame.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 04169728 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIRibbon.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 04048808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2015-09-12 21:58 - 2015-09-12 21:58 - 03687936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msi.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 03620736 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 03527168 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 03443200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIRibbon.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 03362816 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 03248128 _____ (Microsoft Corporation) C:\WINDOWS\system32\msftedit.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 02748416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 02606080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msftedit.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 02558976 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssrch.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 02446336 _____ C:\WINDOWS\system32\InputService.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 02415104 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWrite.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 02350592 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 02153472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 02147080 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d9.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 02125312 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 02112512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 01985024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWrite.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 01964544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssrch.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 01888768 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 01867160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d9.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 01823232 _____ C:\WINDOWS\SysWOW64\InputService.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 01774592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Immersive.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 01714176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.appcore.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 01679360 _____ (Microsoft Corporation) C:\WINDOWS\system32\FntCache.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 01643872 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 01612288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Immersive.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 01602560 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 01593344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 01591856 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 01521664 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActiveSyncProvider.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 01418240 _____ (Microsoft Corporation) C:\WINDOWS\system32\RecoveryDrive.exe
2015-09-12 21:58 - 2015-09-12 21:58 - 01417216 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 01380864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 01365072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 01294352 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2015-09-12 21:58 - 2015-09-12 21:58 - 01294336 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcnwiz.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 01234944 _____ (Microsoft Corporation) C:\WINDOWS\system32\aitstatic.exe
2015-09-12 21:58 - 2015-09-12 21:58 - 01226752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wcnwiz.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 01201664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Cred.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 01169408 _____ (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 01135312 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipUp.exe
2015-09-12 21:58 - 2015-09-12 21:58 - 01123400 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2015-09-12 21:58 - 2015-09-12 21:58 - 01106432 _____ (Microsoft Corporation) C:\WINDOWS\system32\sysmain.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 01101792 _____ (Microsoft Corporation) C:\WINDOWS\system32\MrmCoreR.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 01061888 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 01031680 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorDataService.exe
2015-09-12 21:58 - 2015-09-12 21:58 - 01018568 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2015-09-12 21:58 - 2015-09-12 21:58 - 01008640 _____ (Microsoft Corporation) C:\WINDOWS\system32\schedsvc.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00993104 _____ (Microsoft Corporation) C:\WINDOWS\system32\ReAgent.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00934752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\refsv1.sys
2015-09-12 21:58 - 2015-09-12 21:58 - 00902656 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchIndexer.exe
2015-09-12 21:58 - 2015-09-12 21:58 - 00893440 _____ (Microsoft Corporation) C:\WINDOWS\system32\MbaeApiPublic.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00872448 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntshrui.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00858408 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2015-09-12 21:58 - 2015-09-12 21:58 - 00855552 _____ (Microsoft Corporation) C:\WINDOWS\system32\winhttp.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00850432 _____ (Microsoft Corporation) C:\WINDOWS\system32\comdlg32.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00845664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ReAgent.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00841728 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Import.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00823336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MrmCoreR.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00814080 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctfuimanager.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00801632 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe
2015-09-12 21:58 - 2015-09-12 21:58 - 00798208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntshrui.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00783872 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00754688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Cred.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00752640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctfuimanager.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00752640 _____ (Microsoft Corporation) C:\WINDOWS\system32\efscore.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00750592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comdlg32.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00712192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchIndexer.exe
2015-09-12 21:58 - 2015-09-12 21:58 - 00705520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rpcrt4.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00700256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe
2015-09-12 21:58 - 2015-09-12 21:58 - 00695136 _____ (Microsoft Corporation) C:\WINDOWS\system32\wimgapi.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00685568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdiWiFi.sys
2015-09-12 21:58 - 2015-09-12 21:58 - 00680448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.Connectivity.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00679424 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppContracts.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00677888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00671232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MbaeApiPublic.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00667136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winhttp.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00658568 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipSVC.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00654848 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToManager.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00650752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00642560 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdbui.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00632168 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00630160 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00609592 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00608936 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2015-09-12 21:58 - 2015-09-12 21:58 - 00601344 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2015-09-12 21:58 - 2015-09-12 21:58 - 00595456 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00594472 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Shell.Broker.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00589824 _____ (Microsoft Corporation) C:\WINDOWS\system32\uxtheme.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00589312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\efscore.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00584704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIRibbonRes.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00584704 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIRibbonRes.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00584544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wimgapi.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00576000 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00575488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Import.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00573440 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Cortana.Desktop.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00565088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\acpi.sys
2015-09-12 21:58 - 2015-09-12 21:58 - 00553472 _____ (Microsoft Corporation) C:\WINDOWS\system32\GamePanel.exe
2015-09-12 21:58 - 2015-09-12 21:58 - 00542720 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchFolder.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00541248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2015-09-12 21:58 - 2015-09-12 21:58 - 00521568 _____ (Microsoft Corporation) C:\WINDOWS\system32\wimserv.exe
2015-09-12 21:58 - 2015-09-12 21:58 - 00507696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxgi.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00505344 _____ C:\WINDOWS\system32\EditionUpgradeManagerObj.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00504320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00503296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.Connectivity.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00498016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbhub.sys
2015-09-12 21:58 - 2015-09-12 21:58 - 00497664 _____ (Microsoft Corporation) C:\WINDOWS\system32\WlanMediaManager.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00494592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LogonController.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00485888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.BlockedShutdown.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00458752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\uxtheme.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00452608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchFolder.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00442208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storport.sys
2015-09-12 21:58 - 2015-09-12 21:58 - 00441344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppContracts.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00430592 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcomapi.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00425824 _____ (Microsoft Corporation) C:\WINDOWS\system32\hal.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00416256 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcdedit.exe
2015-09-12 21:58 - 2015-09-12 21:58 - 00414720 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.BioFeedback.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00413184 _____ C:\WINDOWS\system32\diagtrack_win.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00387584 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupShim.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00373072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS
2015-09-12 21:58 - 2015-09-12 21:58 - 00365568 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00356352 _____ (Microsoft Corporation) C:\WINDOWS\system32\stobject.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00343040 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocore.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00342528 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.exe
2015-09-12 21:58 - 2015-09-12 21:58 - 00336384 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchProtocolHost.exe
2015-09-12 21:58 - 2015-09-12 21:58 - 00335248 _____ (Microsoft Corporation) C:\WINDOWS\system32\wintrust.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00329728 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00325984 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pci.sys
2015-09-12 21:58 - 2015-09-12 21:58 - 00322048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.BlockedShutdown.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00322048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\stobject.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00322048 _____ (Microsoft Corporation) C:\WINDOWS\system32\vaultsvc.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00316928 _____ (Microsoft Corporation) C:\WINDOWS\system32\ConhostV2.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00310784 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActionCenter.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00306688 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationObjFactory.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00303104 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00296960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Bluetooth.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00293376 _____ C:\WINDOWS\system32\TextInputFramework.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00292856 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppHost.exe
2015-09-12 21:58 - 2015-09-12 21:58 - 00291840 _____ (Microsoft Corporation) C:\WINDOWS\system32\systemcpl.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00290312 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininit.exe
2015-09-12 21:58 - 2015-09-12 21:58 - 00287744 _____ (Microsoft Corporation) C:\WINDOWS\system32\provhandlers.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00283648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.BioFeedback.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00280576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchProtocolHost.exe
2015-09-12 21:58 - 2015-09-12 21:58 - 00279552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\systemcpl.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00274432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupShim.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00271872 _____ (Microsoft Corporation) C:\WINDOWS\system32\ConsoleLogon.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00268800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NotificationObjFactory.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00265480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wintrust.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00263168 _____ (Microsoft Corporation) C:\WINDOWS\system32\DisplayManager.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00261632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActionCenter.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00253952 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_UserAccount.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00252768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContentDeliveryManager.Utilities.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00247296 _____ C:\WINDOWS\system32\facecredentialprovider.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00246272 _____ (Microsoft Corporation) C:\WINDOWS\system32\PackageStateRoaming.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00243800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LockAppHost.exe
2015-09-12 21:58 - 2015-09-12 21:58 - 00242176 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatehandlers.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00237392 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdyboost.sys
2015-09-12 21:58 - 2015-09-12 21:58 - 00235520 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Notifications.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00235008 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserMgrProxy.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00232960 _____ (Microsoft Corporation) C:\WINDOWS\system32\DevicesFlowBroker.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00229376 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorService.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00215040 _____ (Microsoft Corporation) C:\WINDOWS\system32\notepad.exe
2015-09-12 21:58 - 2015-09-12 21:58 - 00215040 _____ (Microsoft Corporation) C:\WINDOWS\notepad.exe
2015-09-12 21:58 - 2015-09-12 21:58 - 00208736 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxAllUserStore.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00208384 _____ (Microsoft Corporation) C:\WINDOWS\system32\srumsvc.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00207872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\notepad.exe
2015-09-12 21:58 - 2015-09-12 21:58 - 00204288 _____ (Microsoft Corporation) C:\WINDOWS\system32\OmaDmAgent.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00200704 _____ C:\WINDOWS\SysWOW64\TextInputFramework.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00200528 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wof.sys
2015-09-12 21:58 - 2015-09-12 21:58 - 00195584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PackageStateRoaming.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00193536 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedStartModelShim.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00193024 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseModernAppMgmtCSP.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00191488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DisplayManager.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00190464 _____ (Microsoft Corporation) C:\WINDOWS\system32\ReInfo.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00187904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.PicturePassword.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00186880 _____ (Microsoft Corporation) C:\WINDOWS\system32\BootMenuUX.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00184320 _____ (Microsoft Corporation) C:\WINDOWS\system32\shacct.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00181760 _____ (Microsoft Corporation) C:\WINDOWS\system32\shutdownux.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00181088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxAllUserStore.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00179712 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_SignInOptions.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00179712 _____ (Microsoft Corporation) C:\WINDOWS\system32\coredpus.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00179200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\srumsvc.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00176640 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcdboot.exe
2015-09-12 21:58 - 2015-09-12 21:58 - 00171520 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinBioDataModel.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00169984 _____ (Microsoft Corporation) C:\WINDOWS\system32\storewuauth.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00168960 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe
2015-09-12 21:58 - 2015-09-12 21:58 - 00167424 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Privacy.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00162304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ReInfo.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00159744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserMgrProxy.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00155136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tunnel.sys
2015-09-12 21:58 - 2015-09-12 21:58 - 00151040 _____ (Microsoft Corporation) C:\WINDOWS\system32\TabSvc.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00150528 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2015-09-12 21:58 - 2015-09-12 21:58 - 00140288 _____ (Microsoft Corporation) C:\WINDOWS\system32\WcnApi.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00139776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shacct.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00131584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Core.TextInput.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00123392 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssprxy.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00122880 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEDataLayerHelpers.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00120832 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkStatus.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00117760 _____ (Microsoft Corporation) C:\WINDOWS\system32\dafWCN.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00116736 _____ (Microsoft Corporation) C:\WINDOWS\system32\sendmail.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00115712 _____ (Microsoft Corporation) C:\WINDOWS\system32\MbaeParserTask.exe
2015-09-12 21:58 - 2015-09-12 21:58 - 00112640 _____ (Microsoft Corporation) C:\WINDOWS\system32\fdWCN.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00107520 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmapi.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00104960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sendmail.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00100352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WcnApi.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00095744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fdWCN.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00093696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmapi.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00091648 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsNativeApi.V2.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00084480 _____ (Microsoft Corporation) C:\WINDOWS\system32\spbcd.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00081920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VEDataLayerHelpers.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00080720 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\stornvme.sys
2015-09-12 21:58 - 2015-09-12 21:58 - 00080384 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxSysprep.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00079872 _____ (Microsoft Corporation) C:\WINDOWS\system32\BthRadioMedia.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00078848 _____ (Microsoft Corporation) C:\WINDOWS\system32\VPNv2CSP.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00078336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsNativeApi.V2.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00075264 _____ (Microsoft Corporation) C:\WINDOWS\system32\ACPBackgroundManagerPolicy.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\setbcdlocale.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00069120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\spbcd.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00068096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Cortana.ProxyStub.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00067072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbser.sys
2015-09-12 21:58 - 2015-09-12 21:58 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\system32\msiexec.exe
2015-09-12 21:58 - 2015-09-12 21:58 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthhfenum.sys
2015-09-12 21:58 - 2015-09-12 21:58 - 00064000 _____ (Microsoft Corporation) C:\WINDOWS\system32\unenrollhook.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00061280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dam.sys
2015-09-12 21:58 - 2015-09-12 21:58 - 00060928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Cortana.OneCore.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msiexec.exe
2015-09-12 21:58 - 2015-09-12 21:58 - 00057856 _____ (Microsoft Corporation) C:\WINDOWS\system32\hmkd.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00055296 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe
2015-09-12 21:58 - 2015-09-12 21:58 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\system32\omadmprc.exe
2015-09-12 21:58 - 2015-09-12 21:58 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringclient.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00050176 _____ (Microsoft Corporation) C:\WINDOWS\system32\WcnNetsh.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00046432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\msgpiowin32.sys
2015-09-12 21:58 - 2015-09-12 21:58 - 00046080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\UcmUcsi.sys
2015-09-12 21:58 - 2015-09-12 21:58 - 00045568 _____ (Microsoft Corporation) C:\WINDOWS\system32\wfdprov.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00045568 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00045056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hmkd.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00042496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tetheringclient.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00041984 _____ (Microsoft Corporation) C:\WINDOWS\system32\VoiceActivationManager.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00037376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wfdprov.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00037376 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00034816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VoiceActivationManager.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00032768 _____ C:\WINDOWS\system32\LicenseManagerApi.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00032768 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuautoappupdate.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00032768 _____ (Microsoft Corporation) C:\WINDOWS\system32\calc.exe
2015-09-12 21:58 - 2015-09-12 21:58 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\calc.exe
2015-09-12 21:58 - 2015-09-12 21:58 - 00028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationControllerPS.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00008847 _____ C:\WINDOWS\system32\ResPriHMImageList
2015-09-12 21:50 - 2015-09-12 21:50 - 00008192 _____ C:\WINDOWS\system32\config\userdiff
2015-09-12 21:47 - 2015-09-12 21:47 - 00000000 ____D C:\WINDOWS\SysWOW64\BestPractices
2015-09-12 21:47 - 2015-09-12 21:47 - 00000000 ____D C:\WINDOWS\system32\msmq
2015-09-12 21:47 - 2015-09-12 21:47 - 00000000 ____D C:\WINDOWS\system32\BestPractices
2015-09-12 21:47 - 2015-09-12 21:47 - 00000000 ____D C:\Program Files\Reference Assemblies
2015-09-12 21:47 - 2015-09-12 21:47 - 00000000 ____D C:\Program Files\MSBuild
2015-09-12 21:47 - 2015-09-12 21:47 - 00000000 ____D C:\Program Files (x86)\Reference Assemblies
2015-09-12 21:47 - 2015-09-12 21:47 - 00000000 ____D C:\Program Files (x86)\MSBuild
2015-09-12 21:47 - 2015-09-12 21:47 - 00000000 ____D C:\inetpub
2015-09-12 21:45 - 2015-06-17 22:10 - 01166520 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationNative_v0300.dll
2015-09-12 21:45 - 2015-06-17 22:10 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\system32\TsWpfWrp.exe
2015-09-12 21:45 - 2015-05-30 01:07 - 00778936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationNative_v0300.dll
2015-09-12 21:45 - 2015-05-30 01:07 - 00102608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2015-09-12 21:45 - 2015-05-30 01:07 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TsWpfWrp.exe
2015-09-12 21:44 - 2015-06-17 22:10 - 00124112 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll
2015-09-12 20:13 - 2015-09-18 08:50 - 00000000 ___RD C:\Users\Will\3D Objects
2015-09-12 19:30 - 2015-09-12 19:33 - 00000000 ____D C:\Users\Will\AppData\Local\PackageStaging
2015-09-12 19:16 - 2015-10-09 08:36 - 00000000 ____D C:\Users\Will\OneDrive
2015-09-12 19:16 - 2015-09-16 07:39 - 00002372 _____ C:\Users\Will\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2015-09-12 19:09 - 2015-09-12 20:37 - 00000000 ____D C:\Users\Will\AppData\Local\Comms
2015-09-12 19:07 - 2015-09-12 19:07 - 00000000 ____D C:\ProgramData\Microsoft OneDrive
2015-09-12 19:04 - 2015-09-12 19:04 - 00046080 _____ (Hewlett-Packard Corporation) C:\WINDOWS\system32\hpz3lw71.dll
2015-09-12 19:03 - 2015-09-12 19:03 - 00000000 ____D C:\Users\Will\AppData\Local\Publishers
2015-09-12 19:01 - 2015-09-12 19:01 - 00000000 ____D C:\Users\Will\AppData\Local\NetworkTiles
2015-09-12 18:59 - 2015-10-06 10:30 - 00000000 ____D C:\Users\Will\AppData\Local\Packages
2015-09-12 18:59 - 2015-09-12 18:59 - 00000020 ___SH C:\Users\Will\ntuser.ini
2015-09-12 18:59 - 2015-09-12 18:59 - 00000000 ____D C:\Users\Will\AppData\Local\TileDataLayer
2015-09-12 18:52 - 2015-09-12 18:52 - 00022744 _____ C:\WINDOWS\system32\emptyregdb.dat
2015-09-12 18:41 - 2015-09-12 18:41 - 00000000 ____D C:\Users\Default\AppData\Roaming\TuneUp Software
2015-09-12 18:41 - 2015-09-12 18:41 - 00000000 ____D C:\Users\Default User\AppData\Roaming\TuneUp Software
2015-09-12 18:35 - 2015-09-12 18:35 - 00000000 ____D C:\Users\Will\AppData\Local\Avg
2015-09-12 18:35 - 2015-07-10 06:59 - 02718208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2015-09-12 18:26 - 2015-09-12 18:26 - 00001576 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2015-09-12 18:21 - 2015-09-12 18:21 - 00000000 ____D C:\Program Files\Common Files\SpeechEngines
2015-09-12 18:19 - 2015-10-06 11:21 - 00000000 ____D C:\Users\Will
2015-09-12 18:19 - 2015-09-12 18:59 - 00000000 ___RD C:\Users\Will\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-09-12 18:19 - 2015-07-10 07:04 - 00000000 __RSD C:\Users\Will\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell
2015-09-12 18:19 - 2015-07-10 07:04 - 00000000 ___RD C:\Users\Will\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-09-12 18:19 - 2015-07-10 07:04 - 00000000 ___RD C:\Users\Will\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2015-09-12 18:19 - 2015-07-10 07:04 - 00000000 ____D C:\Users\Will\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-09-12 18:18 - 2015-10-08 13:10 - 01005534 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2015-09-12 18:18 - 2015-09-12 18:19 - 00021209 _____ C:\WINDOWS\iis.log
2015-09-12 18:18 - 2015-09-12 18:18 - 00961296 _____ C:\WINDOWS\SysWOW64\PerfStringBackup.INI
2015-09-12 18:14 - 2015-09-12 18:22 - 00000000 ____D C:\ProgramData\Package Cache
2015-09-12 18:13 - 2015-09-12 18:21 - 00000000 ____D C:\Program Files\AMD
2015-09-12 18:13 - 2015-09-12 18:13 - 00000000 ____D C:\Program Files\Common Files\ATI Technologies
2015-09-12 18:13 - 2015-09-12 18:13 - 00000000 _____ C:\WINDOWS\ativpsrm.bin
2015-09-12 18:12 - 2015-09-12 18:12 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
2015-09-12 18:12 - 2015-09-12 18:12 - 00000000 ____D C:\WINDOWS\system32\SRSLabs
2015-09-12 18:12 - 2015-09-12 18:12 - 00000000 ____D C:\Program Files\VIA
2015-09-12 18:09 - 2015-09-12 18:10 - 00023696 _____ C:\WINDOWS\system32\NetSetupMig.log
2015-09-12 18:08 - 2015-09-29 10:11 - 00040168 _____ C:\WINDOWS\PFRO.log
2015-09-12 17:16 - 2015-07-10 07:00 - 00000001 ___SH C:\BOOTNXT
2015-09-12 17:12 - 2015-09-12 18:53 - 00006611 _____ C:\WINDOWS\comsetup.log
2015-09-12 16:02 - 2015-09-12 17:11 - 00000000 ___HD C:\$Windows.~BT
2015-09-12 14:57 - 2015-09-12 14:57 - 00000000 ___HD C:\$Windows.~WS
2015-09-12 14:56 - 2015-09-12 14:57 - 19733696 _____ (Microsoft Corporation) C:\Users\Will\Downloads\MediaCreationToolx64.exe
2015-09-12 14:31 - 2015-09-12 18:54 - 00010449 _____ C:\WINDOWS\diagerr.xml
2015-09-12 14:31 - 2015-09-12 18:54 - 00009528 _____ C:\WINDOWS\diagwrn.xml
2015-09-12 14:27 - 2015-09-12 15:56 - 00000000 ____D C:\ESD
2015-09-12 12:31 - 2015-09-12 12:34 - 00000000 ____D C:\AdwCleaner
2015-09-12 12:07 - 2015-09-25 08:36 - 00113880 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-09-12 12:06 - 2015-09-12 18:29 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-09-12 12:06 - 2015-09-12 12:06 - 00001106 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-09-12 12:06 - 2015-09-12 12:06 - 00000000 ____D C:\ProgramData\Malwarebytes
2015-09-12 12:06 - 2015-09-12 12:06 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-09-12 12:06 - 2015-06-18 08:41 - 00109272 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2015-09-12 12:06 - 2015-06-18 08:41 - 00063704 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
2015-09-12 12:06 - 2015-06-18 08:41 - 00025816 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mbam.sys
2015-09-10 14:24 - 2015-09-10 14:24 - 01795952 _____ (Microsoft Corporation) C:\WINDOWS\system32\WdfCoInstaller01011.dll
2015-09-10 12:53 - 2015-09-12 18:29 - 00000000 ____D C:\Users\Will\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PhotoZoom Classic 6
2015-09-10 12:53 - 2015-09-10 12:53 - 00000946 _____ C:\Users\Will\Desktop\PhotoZoom Classic 6.lnk
2015-09-10 12:53 - 2015-09-10 12:53 - 00000000 ____D C:\Program Files\PhotoZoom Classic 6
2015-09-10 12:37 - 2015-09-12 18:29 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ImgBurn
2015-09-10 12:37 - 2015-09-10 12:37 - 00001881 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ImgBurn.lnk
2015-09-10 12:37 - 2015-09-10 12:37 - 00001869 _____ C:\Users\Public\Desktop\ImgBurn.lnk
2015-09-10 12:37 - 2015-09-10 12:37 - 00000000 ____D C:\Program Files (x86)\ImgBurn
2015-09-10 10:35 - 2015-09-10 10:35 - 00053615 _____ C:\WINDOWS\SysWOW64\CCCInstall_201509101035558115.log
2015-09-10 10:33 - 2015-09-10 10:33 - 00000000 ____D C:\Program Files (x86)\AMD
2015-09-10 10:20 - 2015-10-08 08:51 - 00000000 ____D C:\AMD
2015-09-10 10:14 - 2015-09-10 10:20 - 300806184 _____ (AMD Inc.) C:\Users\Will\Downloads\amd-catalyst-15.7.1-with-dotnet45-win7-64bit.exe
2015-09-10 10:03 - 2015-09-10 10:08 - 00000000 ____D C:\Users\Will\AppData\Roaming\Serif
2015-09-10 09:56 - 2015-09-10 09:56 - 00002505 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Serif PanoramaPlus X4.lnk
2015-09-10 09:56 - 2015-09-10 09:56 - 00002176 _____ C:\Users\Public\Desktop\Serif PanoramaPlus X4.lnk
2015-09-10 09:56 - 2015-09-10 09:56 - 00000000 ____D C:\Users\Will\AppData\LocalLow\Apple Computer
2015-09-10 09:52 - 2015-09-12 18:22 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Serif Applications
2015-09-10 09:52 - 2015-09-10 09:56 - 00000000 ____D C:\Program Files (x86)\Serif
2015-09-10 09:52 - 2015-09-10 09:52 - 00002495 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Serif AlbumPlus Organizer.lnk
2015-09-10 09:52 - 2015-09-10 09:52 - 00002481 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Serif PhotoPlus X4.lnk
2015-09-10 09:52 - 2015-09-10 09:52 - 00002129 _____ C:\Users\Public\Desktop\Serif PhotoPlus X4.lnk
2015-09-10 09:42 - 2015-09-12 18:53 - 00003180 _____ C:\WINDOWS\System32\Tasks\{F64690A7-57D1-4691-8404-F8579E46153F}
2015-09-10 09:14 - 2015-09-12 18:29 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
2015-09-10 09:12 - 2015-09-10 09:12 - 00000000 ____D C:\WINDOWS\System32\Tasks\OfficeSoftwareProtectionPlatform
2015-09-10 09:11 - 2015-09-10 09:11 - 00000000 ____D C:\Program Files\Microsoft Office
2015-09-10 09:10 - 2015-09-28 10:02 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-09-10 09:10 - 2015-09-10 09:30 - 00000000 ____D C:\Program Files (x86)\Microsoft Office
2015-09-10 09:10 - 2015-09-10 09:10 - 00000000 ____D C:\Users\Will\AppData\Local\Microsoft Help
2015-09-10 09:10 - 2015-09-10 09:10 - 00000000 ____D C:\Program Files (x86)\Microsoft Analysis Services
2015-09-10 09:09 - 2015-09-10 09:09 - 00000000 __RHD C:\MSOCache
2015-09-10 09:05 - 2015-09-12 18:22 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\onOne Software
2015-09-10 09:05 - 2015-09-10 09:05 - 00002025 _____ C:\Users\Public\Desktop\Perfect Effects 9.lnk
2015-09-10 09:05 - 2015-09-10 09:05 - 00000000 ____D C:\Users\Will\AppData\Roaming\onOne Software
2015-09-10 09:05 - 2015-09-10 09:05 - 00000000 ____D C:\ProgramData\Nalpeiron
2015-09-10 09:04 - 2015-09-10 09:04 - 00000000 ____D C:\Program Files\onOne Software
2015-09-10 09:04 - 2015-09-10 09:04 - 00000000 ____D C:\Program Files (x86)\onOne Software
2015-09-10 09:02 - 2015-09-10 09:05 - 00000000 ____D C:\ProgramData\onOne Software
2015-09-10 08:55 - 2015-09-10 09:01 - 288334040 _____ (on1) C:\Users\Will\Downloads\Perfect_Effects_9.5.0_PE.exe
2015-09-09 11:02 - 2015-09-09 11:02 - 00002797 _____ C:\Users\Public\Desktop\Nero Video 11.lnk
2015-09-09 11:00 - 2015-09-09 11:00 - 00002109 _____ C:\Users\Public\Desktop\Nero Kwik Media.lnk
2015-09-09 10:57 - 2015-09-09 10:57 - 00002881 _____ C:\Users\Public\Desktop\Nero 11.lnk
2015-09-09 10:57 - 2015-09-09 10:57 - 00002783 _____ C:\Users\Public\Desktop\Nero BackItUp 11.lnk
2015-09-09 10:53 - 2015-09-09 10:53 - 00002843 _____ C:\Users\Public\Desktop\Nero Burning ROM 11.lnk
2015-09-09 10:51 - 2015-09-12 18:29 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero
2015-09-09 10:50 - 2015-09-09 11:14 - 00000000 ____D C:\ProgramData\Nero
2015-09-09 10:39 - 2015-09-09 11:07 - 00000000 ____D C:\Program Files (x86)\Nero
2015-09-09 10:39 - 2011-12-01 11:42 - 00072240 _____ (Nero AG) C:\WINDOWS\system32\Drivers\NBVol.sys
2015-09-09 10:39 - 2011-12-01 11:42 - 00015920 _____ (Nero AG) C:\WINDOWS\system32\Drivers\NBVolUp.sys
2015-09-09 10:31 - 2010-05-26 11:41 - 00248672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx11_43.dll
2015-09-09 10:29 - 2009-09-04 17:29 - 01974616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_42.dll
2015-09-09 10:27 - 2010-05-26 11:41 - 00470880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_43.dll
2015-09-09 10:26 - 2009-09-04 17:29 - 01892184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_42.dll
2015-09-09 10:24 - 2010-05-26 11:41 - 01998168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_43.dll
2015-09-09 10:22 - 2008-10-15 06:22 - 04379984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_40.dll
2015-09-09 10:20 - 2010-05-26 11:41 - 01868128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dcsx_43.dll
2015-09-09 10:19 - 2007-07-19 18:14 - 03727720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_35.dll
2015-09-09 10:17 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_43.dll
2015-09-09 10:16 - 2007-05-16 16:45 - 03497832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_34.dll
2015-09-09 10:14 - 2006-03-31 12:40 - 02388176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_30.dll
2015-09-09 09:12 - 2015-09-12 18:29 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Python 3.4
2015-09-09 09:11 - 2015-09-09 09:11 - 00000000 ____D C:\Users\Will\AppData\Local\pip
2015-09-09 09:10 - 2015-09-09 09:11 - 00000000 ____D C:\Python34
2015-09-09 09:03 - 2015-10-03 08:43 - 00001600 _____ C:\Users\Will\Qdata1OFXLOG.DAT
2015-09-09 08:52 - 2015-09-12 18:29 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Python 2.7
2015-09-09 08:50 - 2015-09-09 08:51 - 00000000 ____D C:\Python27
2015-09-09 08:47 - 2015-09-09 08:49 - 00000000 ____D C:\Users\Will\Desktop\python
2015-09-09 08:41 - 2015-09-28 09:15 - 00002260 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-09-09 08:41 - 2015-09-12 18:29 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-09-09 08:40 - 2015-10-09 10:55 - 00000922 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2015-09-09 08:40 - 2015-10-09 07:54 - 00000918 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2015-09-09 08:40 - 2015-09-16 09:54 - 00000000 ____D C:\Users\Will\AppData\Local\Google
2015-09-09 08:40 - 2015-09-16 07:50 - 00003980 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2015-09-09 08:40 - 2015-09-16 07:49 - 00003748 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2015-09-09 08:40 - 2015-09-09 08:41 - 00000000 ____D C:\Program Files (x86)\Google
2015-09-09 08:39 - 2015-09-09 08:39 - 00000000 ____D C:\Users\Will\AppData\Local\Apps\2.0
2015-09-09 08:07 - 2015-09-09 08:07 - 00000000 ____D C:\Users\Will\AppData\Roaming\Macromedia

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-10-09 11:09 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\system32\sru
2015-10-09 11:06 - 2015-09-08 10:31 - 00000000 ____D C:\Users\Will\AppData\Roaming\Skype
2015-10-09 08:55 - 2015-07-10 08:22 - 00000275 _____ C:\WINDOWS\WindowsUpdate.log
2015-10-09 08:18 - 2015-09-07 13:21 - 00000000 ____D C:\ProgramData\MFAData
2015-10-09 02:32 - 2015-09-07 13:01 - 00000000 ____D C:\Users\Will\AppData\Roaming\Raptr
2015-10-08 18:46 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\AppReadiness
2015-10-08 14:33 - 2015-09-08 10:30 - 00000000 ____D C:\ProgramData\Skype
2015-10-08 08:47 - 2015-08-20 21:46 - 00874480 _____ (AMD) C:\WINDOWS\system32\coinst_15.20.dll
2015-10-08 08:46 - 2015-08-20 21:51 - 12088008 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atidxx64.dll
2015-10-08 08:46 - 2015-08-20 21:51 - 10211016 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atidxx32.dll
2015-10-08 08:46 - 2015-08-20 21:51 - 08982440 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atiumd6a.dll
2015-10-08 08:46 - 2015-08-20 21:51 - 08864928 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atiumd64.dll
2015-10-08 08:46 - 2015-08-20 21:51 - 08009360 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atiumdva.dll
2015-10-08 08:46 - 2015-08-20 21:51 - 07482560 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atiumdag.dll
2015-10-08 08:46 - 2015-08-20 21:51 - 01479808 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\aticfx64.dll
2015-10-08 08:46 - 2015-08-20 21:51 - 01223552 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\aticfx32.dll
2015-10-08 08:46 - 2015-08-20 21:51 - 00162240 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atiuxp64.dll
2015-10-08 08:46 - 2015-08-20 21:51 - 00143056 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atiuxpag.dll
2015-10-08 08:46 - 2015-08-20 21:51 - 00130072 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atiu9p64.dll
2015-10-08 08:46 - 2015-08-20 21:51 - 00112368 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atiu9pag.dll
2015-10-08 08:46 - 2015-08-20 21:46 - 39721456 _____ (Advanced Micro Devices Inc.) C:\WINDOWS\SysWOW64\amdocl.dll
2015-10-08 08:46 - 2015-08-20 21:46 - 22327280 _____ (Advanced Micro Devices Inc.) C:\WINDOWS\SysWOW64\amdocl12cl.dll
2015-10-08 08:46 - 2015-08-20 21:46 - 21648880 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\Drivers\atikmdag.sys
2015-10-08 08:46 - 2015-08-20 21:46 - 01256432 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\atiadlxx.dll
2015-10-08 08:46 - 2015-08-20 21:46 - 00935408 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\atiadlxy.dll
2015-10-08 08:46 - 2015-08-20 21:46 - 00683504 _____ (AMD) C:\WINDOWS\system32\atieclxx.exe
2015-10-08 08:46 - 2015-08-20 21:46 - 00674288 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\Drivers\atikmpag.sys
2015-10-08 08:46 - 2015-08-20 21:46 - 00451056 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\atidemgy.dll
2015-10-08 08:46 - 2015-08-20 21:46 - 00255472 _____ (AMD) C:\WINDOWS\system32\atiesrxx.exe
2015-10-08 08:46 - 2015-08-20 21:46 - 00150512 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atigktxx.dll
2015-10-07 09:33 - 2015-09-07 11:01 - 00000000 ____D C:\Users\Will\AppData\Local\VirtualStore
2015-10-06 12:02 - 2015-09-07 13:01 - 00000000 ____D C:\Program Files (x86)\Raptr
2015-10-06 11:59 - 2015-07-10 08:21 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-10-06 11:58 - 2015-07-10 05:05 - 00524288 ___SH C:\WINDOWS\system32\config\BBI
2015-10-06 11:20 - 2015-07-10 07:04 - 00000000 ___SD C:\WINDOWS\SysWOW64\F12
2015-10-06 11:20 - 2015-07-10 07:04 - 00000000 ___SD C:\WINDOWS\system32\F12
2015-10-06 11:20 - 2015-07-10 07:04 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility
2015-10-06 11:20 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2015-10-06 11:20 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\system32\SystemResetPlatform
2015-10-06 11:20 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\system32\appraiser
2015-10-06 11:19 - 2015-07-10 07:04 - 00000000 ___RD C:\WINDOWS\PurchaseDialog
2015-10-06 11:19 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\Provisioning
2015-10-06 11:19 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\L2Schemas
2015-10-05 07:45 - 2015-07-10 06:55 - 00000000 ____D C:\WINDOWS\CbsTemp
2015-10-04 00:04 - 2015-07-10 05:05 - 00032768 ___SH C:\WINDOWS\system32\config\ELAM
2015-10-03 08:45 - 2015-09-08 09:53 - 04218880 _____ C:\Users\Will\Qdata1.QDF
2015-10-02 08:39 - 2015-09-07 13:26 - 00000000 ____D C:\ProgramData\AVG2015
2015-09-28 09:59 - 2009-07-13 22:34 - 00000513 _____ C:\WINDOWS\win.ini
2015-09-28 09:31 - 2015-09-07 19:09 - 00000000 ____D C:\Users\Will\AppData\Roaming\Adobe
2015-09-28 09:25 - 2015-09-07 17:09 - 00028551 _____ C:\WINDOWS\IE11_main.log
2015-09-28 08:56 - 2015-09-08 10:35 - 00000000 ____D C:\Users\Will\AppData\LocalLow\LastPass
2015-09-27 11:50 - 2015-07-10 08:20 - 00018905 _____ C:\WINDOWS\setupact.log
2015-09-27 11:12 - 2015-07-10 08:20 - 00354040 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2015-09-20 08:17 - 2015-09-08 09:43 - 00000000 ____D C:\Program Files (x86)\Quicken
2015-09-17 15:08 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\system32\NDF
2015-09-16 07:36 - 2015-09-08 16:00 - 00000000 ____D C:\Users\Will\AppData\Roaming\HpUpdate
2015-09-13 09:16 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\system32\restore
2015-09-13 04:49 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\appcompat
2015-09-12 22:07 - 2015-07-10 07:04 - 00028672 _____ C:\WINDOWS\system32\config\BCD-Template
2015-09-12 22:00 - 2015-07-10 09:14 - 00000000 ____D C:\Program Files\Windows Journal
2015-09-12 22:00 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\SysWOW64\oobe
2015-09-12 22:00 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\system32\oobe
2015-09-12 22:00 - 2015-07-10 05:05 - 00000000 ____D C:\WINDOWS\SysWOW64\Dism
2015-09-12 22:00 - 2015-07-10 05:05 - 00000000 ____D C:\WINDOWS\system32\Dism
2015-09-12 21:47 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\SysWOW64\inetsrv
2015-09-12 21:47 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\system32\inetsrv
2015-09-12 21:47 - 2015-07-10 07:01 - 00096768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa.tlb
2015-09-12 21:47 - 2015-07-10 07:01 - 00091136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa30.tlb
2015-09-12 21:47 - 2015-07-10 07:01 - 00055808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa20.tlb
2015-09-12 21:47 - 2015-07-10 07:01 - 00037376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa10.tlb
2015-09-12 21:46 - 2015-07-10 07:01 - 00635904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqsnap.dll
2015-09-12 21:46 - 2015-07-10 07:01 - 00562176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqutil.dll
2015-09-12 21:46 - 2015-07-10 07:01 - 00265728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqoa.dll
2015-09-12 21:46 - 2015-07-10 07:01 - 00168960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iisRtl.dll
2015-09-12 21:46 - 2015-07-10 07:01 - 00161792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqrt.dll
2015-09-12 21:46 - 2015-07-10 07:01 - 00050688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\admwprox.dll
2015-09-12 21:46 - 2015-07-10 07:01 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ahadmin.dll
2015-09-12 21:46 - 2015-07-10 07:01 - 00016896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iisreset.exe
2015-09-12 21:46 - 2015-07-10 07:01 - 00014848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mqcertui.dll
2015-09-12 21:46 - 2015-07-10 07:01 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wamregps.dll
2015-09-12 21:46 - 2015-07-10 07:01 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iisrstap.dll
2015-09-12 21:46 - 2015-07-10 07:01 - 00009096 _____ C:\WINDOWS\SysWOW64\msmqtrc.mof
2015-09-12 21:46 - 2015-07-10 07:00 - 01417728 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqqm.dll
2015-09-12 21:46 - 2015-07-10 07:00 - 00813056 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqsnap.dll
2015-09-12 21:46 - 2015-07-10 07:00 - 00564224 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqutil.dll
2015-09-12 21:46 - 2015-07-10 07:00 - 00316928 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa.dll
2015-09-12 21:46 - 2015-07-10 07:00 - 00229888 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqrt.dll
2015-09-12 21:46 - 2015-07-10 07:00 - 00202240 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisRtl.dll
2015-09-12 21:46 - 2015-07-10 07:00 - 00175104 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mqac.sys
2015-09-12 21:46 - 2015-07-10 07:00 - 00130048 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqlogmgr.dll
2015-09-12 21:46 - 2015-07-10 07:00 - 00096768 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa.tlb
2015-09-12 21:46 - 2015-07-10 07:00 - 00091136 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa30.tlb
2015-09-12 21:46 - 2015-07-10 07:00 - 00055808 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa20.tlb
2015-09-12 21:46 - 2015-07-10 07:00 - 00055808 _____ (Microsoft Corporation) C:\WINDOWS\system32\admwprox.dll
2015-09-12 21:46 - 2015-07-10 07:00 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\system32\ahadmin.dll
2015-09-12 21:46 - 2015-07-10 07:00 - 00052736 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqbkup.exe
2015-09-12 21:46 - 2015-07-10 07:00 - 00037376 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqoa10.tlb
2015-09-12 21:46 - 2015-07-10 07:00 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqsvc.exe
2015-09-12 21:46 - 2015-07-10 07:00 - 00018944 _____ (Microsoft Corporation) C:\WINDOWS\system32\mqcertui.dll
2015-09-12 21:46 - 2015-07-10 07:00 - 00018432 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisreset.exe
2015-09-12 21:46 - 2015-07-10 07:00 - 00015360 _____ (Microsoft Corporation) C:\WINDOWS\system32\wamregps.dll
2015-09-12 21:46 - 2015-07-10 07:00 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisrstap.dll
2015-09-12 21:46 - 2015-07-10 07:00 - 00009096 _____ C:\WINDOWS\system32\msmqtrc.mof
2015-09-12 19:12 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\system32\WinBioDatabase
2015-09-12 19:03 - 2015-07-10 07:04 - 00000000 ___RD C:\WINDOWS\PrintDialog
2015-09-12 19:03 - 2015-07-10 07:04 - 00000000 ___RD C:\WINDOWS\MiracastView
2015-09-12 19:02 - 2015-07-10 07:04 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2015-09-12 18:57 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\rescache
2015-09-12 18:53 - 2015-09-08 16:00 - 00003724 _____ C:\WINDOWS\System32\Tasks\HPCustParticipation HP Photosmart 6520 series
2015-09-12 18:53 - 2015-09-08 12:50 - 00003214 _____ C:\WINDOWS\System32\Tasks\Microsoft_MKC_Logon_Task_ipoint.exe
2015-09-12 18:53 - 2015-09-08 12:50 - 00003212 _____ C:\WINDOWS\System32\Tasks\Microsoft_MKC_Logon_Task_itype.exe
2015-09-12 18:53 - 2015-09-08 09:22 - 00003342 _____ C:\WINDOWS\System32\Tasks\{BE360029-1A25-495D-90E8-03327D70C798}
2015-09-12 18:53 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\Registration
2015-09-12 18:51 - 2015-09-07 13:27 - 00000000 ____D C:\Program Files\Common Files\AV
2015-09-12 18:51 - 2015-07-10 07:04 - 00000000 __RSD C:\WINDOWS\Media
2015-09-12 18:51 - 2015-07-10 07:04 - 00000000 __RHD C:\Users\Public\Libraries
2015-09-12 18:47 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\system32\spool
2015-09-12 18:41 - 2015-09-07 13:26 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
2015-09-12 18:41 - 2015-07-10 07:04 - 00000000 ___HD C:\WINDOWS\ELAMBKUP
2015-09-12 18:29 - 2015-09-08 16:00 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP
2015-09-12 18:29 - 2015-09-08 12:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Mouse and Keyboard Center
2015-09-12 18:29 - 2015-09-08 10:35 - 00000000 ____D C:\Users\Will\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\LastPass
2015-09-12 18:29 - 2015-09-08 10:35 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LastPass
2015-09-12 18:29 - 2015-09-08 09:44 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Quicken 2013
2015-09-12 18:29 - 2015-09-07 19:39 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CyberLink Power2Go
2015-09-12 18:29 - 2015-09-07 13:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Gaming Evolved
2015-09-12 18:29 - 2015-07-10 09:14 - 00000000 ____D C:\WINDOWS\ShellNew
2015-09-12 18:29 - 2015-07-10 07:04 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2015-09-12 18:26 - 2015-07-10 07:05 - 00004362 _____ C:\WINDOWS\DtcInstall.log
2015-09-12 18:26 - 2015-07-10 07:04 - 00000000 ___RD C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-09-12 18:26 - 2015-07-10 07:04 - 00000000 ___RD C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-09-12 18:26 - 2009-07-13 23:20 - 00000000 ____D C:\Users\Default.migrated
2015-09-12 18:23 - 2015-09-08 18:32 - 00000000 ____D C:\WINDOWS\SysWOW64\spool
2015-09-12 18:23 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\SysWOW64\zh-HK
2015-09-12 18:23 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\SysWOW64\tr-TR
2015-09-12 18:23 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\SysWOW64\migwiz
2015-09-12 18:23 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\SysWOW64\IME
2015-09-12 18:23 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\system32\zh-HK
2015-09-12 18:23 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\system32\tr-TR
2015-09-12 18:23 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\system32\IME
2015-09-12 18:22 - 2015-09-08 10:31 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2015-09-12 18:22 - 2015-07-10 07:04 - 00000000 __SHD C:\Program Files (x86)\Windows Sidebar
2015-09-12 18:22 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\schemas
2015-09-12 18:22 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\PolicyDefinitions
2015-09-12 18:22 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\Cursors
2015-09-12 18:22 - 2011-04-12 04:28 - 00000000 ___RD C:\Users\Public\Recorded TV
2015-09-12 18:21 - 2015-07-10 07:04 - 00000000 __SHD C:\Program Files\Windows Sidebar
2015-09-12 18:21 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\system32\Recovery
2015-09-12 18:21 - 2015-07-10 07:04 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2015-09-12 18:21 - 2009-07-14 01:32 - 00000000 ____D C:\Program Files\DVD Maker
2015-09-12 18:18 - 2015-07-10 05:05 - 00000000 ____D C:\WINDOWS\system32\Sysprep
2015-09-12 18:08 - 2015-07-10 05:05 - 00000000 __RHD C:\Users\Default
2015-09-12 17:19 - 2015-09-07 13:43 - 01979924 _____ C:\WINDOWS\WindowsUpdate (1).log
2015-09-12 17:17 - 2015-09-07 14:39 - 00008192 __RSH C:\BOOTSECT.BAK
2015-09-12 16:11 - 2009-07-14 00:45 - 00031904 ____H C:\WINDOWS\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-09-12 16:11 - 2009-07-14 00:45 - 00031904 ____H C:\WINDOWS\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-09-12 12:34 - 2015-09-08 18:35 - 00000000 ____D C:\Users\Will\AppData\Roaming\Yahoo!
2015-09-12 12:34 - 2015-09-08 18:35 - 00000000 ____D C:\Program Files (x86)\Yahoo!
2015-09-10 14:24 - 2015-07-08 21:06 - 00095016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dc3d.sys
2015-09-10 09:54 - 2015-09-07 11:37 - 00118552 _____ C:\Users\Will\AppData\Local\GDIPFONTCACHEV1.DAT
2015-09-10 09:03 - 2015-09-07 19:39 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2015-09-09 09:07 - 2015-09-07 13:21 - 00000000 ____D C:\Users\Will\AppData\Local\Avg2015

==================== Files in the root of some directories =======

2015-10-07 08:16 - 2015-10-07 08:16 - 0000000 _____ () C:\Program Files (x86)\Common Files\AMD
2015-09-08 10:38 - 2015-09-08 10:38 - 16790552 _____ (LastPass) C:\Program Files (x86)\Common Files\lpuninstall.exe
2015-09-08 15:59 - 2015-09-08 15:59 - 0000057 _____ () C:\ProgramData\Ament.ini
2015-09-08 18:25 - 2015-09-08 18:37 - 0001262 _____ () C:\ProgramData\hpzinstall.log

Files to move or delete:
====================
C:\Users\Will\Qdata1OFXLOG.DAT


==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-10-01 07:44

==================== End of FRST.txt ============================

#4 willhippy

willhippy
  • Topic Starter

  • Members
  • 157 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Bethlehem. PA
  • Local time:08:21 AM

Posted 09 October 2015 - 10:25 AM

second log


Additional scan result of Farbar Recovery Scan Tool (x64) Version:08-10-2015
Ran by Will (2015-10-09 11:10:18)
Running from C:\Users\Will\Desktop
Windows 10 Pro (X64) (2015-09-12 22:58:53)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-3276915167-1117282696-2501375683-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-3276915167-1117282696-2501375683-503 - Limited - Disabled)
Guest (S-1-5-21-3276915167-1117282696-2501375683-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3276915167-1117282696-2501375683-1002 - Limited - Enabled)
Will (S-1-5-21-3276915167-1117282696-2501375683-1000 - Administrator - Enabled) => C:\Users\Will

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: AVG AntiVirus Free Edition 2015 (Enabled - Up to date) {4D41356F-32AD-7C42-C820-63775EE4F413}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: AVG AntiVirus Free Edition 2015 (Enabled - Up to date) {F620D48B-1497-73CC-F290-58052563BEAE}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

64 Bit HP CIO Components Installer (Version: 6.2.1 - Hewlett-Packard) Hidden
Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 15.008.20082 - Adobe Systems Incorporated)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 19.0.0.190 - Adobe Systems Incorporated)
AIO_CDA_ProductContext (x32 Version: 130.0.365.000 - Hewlett-Packard) Hidden
AIO_CDA_Software (x32 Version: 130.0.365.000 - Hewlett-Packard) Hidden
AIO_Scan (x32 Version: 130.0.365.000 - Hewlett-Packard) Hidden
AMD Catalyst Control Center (HKLM-x32\...\WUCCCApp) (Version: 1.00.0000 - AMD)
AMD Catalyst Install Manager (HKLM\...\{7E5DC2C5-115A-322B-976C-219237FAED66}) (Version: 8.0.916.0 - Advanced Micro Devices, Inc.)
AVG 2015 (HKLM\...\AVG) (Version: 2015.0.6140 - AVG Technologies)
AVG 2015 (Version: 15.0.4435 - AVG Technologies) Hidden
AVG 2015 (Version: 15.0.6140 - AVG Technologies) Hidden
Belarc Advisor 8.5a (HKLM-x32\...\Belarc Advisor) (Version: 8.5.1.0 - Belarc Inc.)
BenVista PhotoZoom Classic 6.0 (HKU\S-1-5-21-3276915167-1117282696-2501375683-1000\...\PhotoZoom Classic 6) (Version: 6.0 - BenVista Ltd.)
BufferChm (x32 Version: 130.0.331.000 - Hewlett-Packard) Hidden
C5100 (x32 Version: 130.0.365.000 - Hewlett-Packard) Hidden
c5100_Help (x32 Version: 82.0.256.000 - Hewlett-Packard) Hidden
Copy (x32 Version: 130.0.428.000 - Hewlett-Packard) Hidden
CyberLink Power2Go (HKLM-x32\...\InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 7.0.0.1607 - CyberLink Corp.)
Destinations (x32 Version: 130.0.0.0 - Hewlett-Packard) Hidden
DeviceDiscovery (x32 Version: 130.0.465.000 - Hewlett-Packard) Hidden
DocProc (x32 Version: 13.0.0.0 - Hewlett-Packard) Hidden
Driver Booster 3.0 (HKLM-x32\...\Driver Booster_is1) (Version: 3.0 - IObit)
Fax (x32 Version: 130.0.418.000 - Hewlett-Packard) Hidden
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 45.0.2454.101 - Google Inc.)
Google Update Helper (x32 Version: 1.3.28.15 - Google Inc.) Hidden
GPBaseService2 (x32 Version: 130.0.371.000 - Hewlett-Packard) Hidden
High-Definition Video Playback (x32 Version: 11.1.11100.4.196 - Nero AG) Hidden
HP Customer Participation Program 13.0 (HKLM\...\HPExtendedCapabilities) (Version: 13.0 - HP)
HP Imaging Device Functions 13.0 (HKLM\...\HP Imaging Device Functions) (Version: 13.0 - HP)
HP Photo Creations (HKLM-x32\...\HP Photo Creations) (Version: 1.0.0.7702 - HP)
HP Photosmart 6520 series Basic Device Software (HKLM\...\{1151BCF8-3246-4E34-9C17-22E66318C41C}) (Version: 28.0.1315.0 - Hewlett-Packard Co.)
HP Photosmart 6520 series Help (HKLM-x32\...\{D3293275-1002-41F5-BC37-099B4251FF5B}) (Version: 28.0.0 - Hewlett Packard)
HP Photosmart 6520 series Product Improvement Study (HKLM\...\{F144E07C-4019-4092-BE25-B57819C97D2F}) (Version: 28.0.1315.0 - Hewlett-Packard Co.)
HP Photosmart All-In-One Driver Software 13.0 Rel. A (HKLM\...\{17016DA1-F040-4032-BD36-34DD317BC9D5}) (Version: 13.0 - HP)
HP Photosmart Essential 3.5 (HKLM\...\HP Photosmart Essential) (Version: 3.5 - HP)
HP Smart Web Printing 4.51 (HKLM\...\HP Smart Web Printing) (Version: 4.51 - HP)
HP Solution Center 13.0 (HKLM\...\HP Solution Center & Imaging Support Tools) (Version: 13.0 - HP)
HP Support Solutions Framework (HKLM-x32\...\{F6A11738-3EE4-4573-AEA5-6CD5D491C167}) (Version: 12.0.30.81 - Hewlett-Packard Company)
HP Update (HKLM-x32\...\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
HPPhotoGadget (x32 Version: 130.0.282.000 - Hewlett-Packard) Hidden
HPPhotoSmartDiscLabelContent1 (x32 Version: 2.04.0000 - Hewlett-Packard) Hidden
HPPhotosmartEssential (x32 Version: 2.04.0000 - Hewlett-Packard) Hidden
HPProductAssistant (x32 Version: 130.0.371.000 - Hewlett-Packard) Hidden
HPSSupply (x32 Version: 130.0.371.000 - Hewlett-Packard) Hidden
ImgBurn (HKLM-x32\...\ImgBurn) (Version: 2.5.8.0 - LIGHTNING UK!)
iSEEK AnswerWorks English Runtime (HKLM-x32\...\{18A8E78B-9EF2-496E-B310-BCD8E4C1DAB3}) (Version: 010.000.0101 - Vantage Linguistics)
LastPass (uninstall only) (HKLM-x32\...\LastPass) (Version: - LastPass)
Malwarebytes Anti-Malware version 2.1.8.1057 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.1.8.1057 - Malwarebytes Corporation)
MarketResearch (x32 Version: 130.0.374.000 - Hewlett-Packard) Hidden
Microsoft Access database engine 2010 (English) (HKLM-x32\...\{90140000-00D1-0409-0000-0000000FF1CE}) (Version: 14.0.6029.1000 - Microsoft Corporation)
Microsoft Mouse and Keyboard Center (HKLM\...\Microsoft Mouse and Keyboard Center) (Version: 2.5.166.0 - Microsoft Corporation)
Microsoft Office Home and Student 2010 (HKLM-x32\...\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40728.0 - Microsoft Corporation)
Microsoft Streets & Trips 2013 (HKLM-x32\...\{C82185E8-C27B-4EF4-2013-4444BC2C2B6D}) (Version: 19.0.17.2200 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
MiniTool Partition Wizard Free 9.1 (HKLM\...\{05D996FA-ADCB-4D23-BA3C-A7C184A8FAC6}_is1) (Version: - MiniTool Solution Ltd.)
Mozilla Firefox 41.0 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 41.0 (x86 en-US)) (Version: 41.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 41.0 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
Nero 11 Platinum (HKLM-x32\...\{79B3E8EE-35F2-4CCD-82D9-4A57F408E449}) (Version: 11.2.00700 - Nero AG)
Nero Backup Drivers (HKLM\...\{D600D357-5CB9-4DE9-8FD4-14E208BD1970}) (Version: 1.0.11100.8.0 - Nero AG)
Network64 (Version: 130.0.572.000 - Hewlett-Packard) Hidden
Notepad++ (HKLM-x32\...\Notepad++) (Version: 6.8.3 - Notepad++ Team)
OCR Software by I.R.I.S. 13.0 (HKLM\...\HPOCR) (Version: 13.0 - HP)
Perfect Effects 9 (HKLM-x32\...\Perfect Effects 9 PE) (Version: 9.5.0 - on1)
Python 2.7.10 (HKLM-x32\...\{E2B51919-207A-43EB-AE78-733F9C6797C2}) (Version: 2.7.10150 - Python Software Foundation)
Python 3.4.3 (HKLM-x32\...\{CCD588A7-8D55-49F1-A30C-47FAB40889ED}) (Version: 3.4.16490 - Python Software Foundation)
Quicken 2013 (HKLM-x32\...\{034DD4BB-F0D6-4ECF-B064-8E39E3EF7076}) (Version: 22.1.12.7 - Intuit)
Raptr (HKLM-x32\...\Raptr) (Version: - )
Readiris Pro 12 (HKLM-x32\...\{A24F20F6-3BE3-4D25-BD0C-D7AEF7D180D4}) (Version: 12.00.5639 - I.R.I.S.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.92.115.2015 - Realtek)
Revo Uninstaller 1.95 (HKLM-x32\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group)
Scan (x32 Version: 13.0.0.0 - Hewlett-Packard) Hidden
Scratch 2 Offline Editor (HKLM-x32\...\edu.media.mit.Scratch2Editor) (Version: 439.3 - MIT Media Lab)
Scratch 2 Offline Editor (x32 Version: 255.3 - MIT Media Lab) Hidden
Serif PanoramaPlus X4 (HKLM-x32\...\{35EDE682-4AE5-47D6-B44F-103F859951DC}) (Version: 4.0.3.010 - Serif (Europe) Ltd)
Serif PhotoPlus X4 (HKLM-x32\...\{AFA3224E-8AD6-4EFA-9DBA-A2E499F30282}) (Version: 14.0.2.013 - Serif (Europe) Ltd)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version: - Microsoft)
Shop for HP Supplies (HKLM\...\Shop for HP Supplies) (Version: 13.0 - HP)
Skype Click to Call (HKLM-x32\...\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 7.4.0.9058 - Microsoft Corporation)
Skype™ 7.12 (HKLM-x32\...\{6A0549A9-1B96-498C-ACBC-3943001FEB19}) (Version: 7.12.101 - Skype Technologies S.A.)
SmartWebPrinting (x32 Version: 130.0.457.000 - Hewlett-Packard) Hidden
SolutionCenter (x32 Version: 130.0.373.000 - Hewlett-Packard) Hidden
Status (x32 Version: 130.0.469.000 - Hewlett-Packard) Hidden
Toolbox (x32 Version: 130.0.648.000 - Hewlett-Packard) Hidden
TrayApp (x32 Version: 130.0.422.000 - Hewlett-Packard) Hidden
UnloadSupport (x32 Version: 11.0.0 - Hewlett-Packard) Hidden
Visual Studio 2012 x64 Redistributables (HKLM\...\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
Visual Studio 2012 x86 Redistributables (HKLM-x32\...\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.1 - VideoLAN)
Vz In-Home Agent (HKLM-x32\...\VzInHomeAgent) (Version: 9.0.79.0 - Verizon)
WebReg (x32 Version: 130.0.132.017 - Hewlett-Packard) Hidden
Welcome App (Start-up experience) (x32 Version: 11.0.23500.0.0 - Nero AG) Hidden
Windows Firewall Control (HKLM\...\Windows Firewall Control) (Version: 4.5.4.2 - BiniSoft.org)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-3276915167-1117282696-2501375683-1000_Classes\CLSID\{3DF9CFF3-ED57-EB48-0B31-BA7F06FBA804}\InprocServer32 -> no filepath
CustomCLSID: HKU\S-1-5-21-3276915167-1117282696-2501375683-1000_Classes\CLSID\{835A1375-87B6-52C4-71AF-28FC4AE976BA}\InprocServer32 -> no filepath

==================== Restore Points =========================

01-10-2015 08:25:47 Windows Update
04-10-2015 09:19:37 Windows Update
07-10-2015 09:46:32 Windows Update

==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-13 22:34 - 2009-06-10 17:00 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {037C5C40-76EA-467C-A883-54EA407BC98F} - System32\Tasks\Microsoft_MKC_Logon_Task_ipoint.exe => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2015-07-08] (Microsoft Corporation)
Task: {083BD449-D9E6-4C22-90AD-B6332AAA5C43} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {1865BB76-4518-4FE7-A1D3-2C7A2E514CBA} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {1AAFB021-B4B4-4077-8595-45012BDE5FDC} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\Windows\ehome\ehrec.exe
Task: {22F8E596-BBC6-4595-8E56-A9EBD5FEACBC} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\Windows\ehome\ehPrivJob.exe
Task: {25E8994B-824E-4F47-8394-07CDD524C22F} - System32\Tasks\Driver Booster Scheduler => C:\Program Files (x86)\IObit\Driver Booster\Scheduler.exe [2015-09-14] (IObit)
Task: {34D253A2-EC29-4D8A-880A-A6080287E573} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-09] (Google Inc.)
Task: {375E73DE-8917-4C65-95C2-D36C304FBC3C} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {38413D2D-AA01-42EE-BC4B-A4A27CD364C4} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\Windows\ehome\ehPrivJob.exe
Task: {3E5953FC-9392-491B-B3B4-7C1A44EB4FFA} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\Windows\ehome\ehPrivJob.exe
Task: {41233BA5-4C14-43B2-BF67-7BDF6EFA9E41} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\Windows\ehome\ehPrivJob.exe
Task: {4D93C689-AB19-4A01-9BAD-83E4F7C5DC06} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\Windows\ehome\ehPrivJob.exe
Task: {54EAB674-29ED-48A9-91D4-CDEB02637D5B} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\Windows\ehome\ehPrivJob.exe
Task: {61B457B4-6158-46F3-8BCE-ECE260C07B41} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\Windows\ehome\mcupdate.exe
Task: {6906DEB2-8C65-48FA-BF54-4F10057B1E05} - System32\Tasks\Driver Booster SkipUAC (Will) => C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe [2015-09-18] (IObit)
Task: {7348A23E-9152-4506-BA2F-08930B8C4733} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\Windows\ehome\ehPrivJob.exe
Task: {74AB30D1-6321-421C-A607-2A07E88AC8FE} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\Windows\ehome\ehPrivJob.exe
Task: {791045A1-EAA2-4A5D-98A3-948CBFF90703} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {7EA6AED3-222C-4BC7-9078-1B7052AC3E81} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {898EBF84-7341-4E86-8F15-A5C80197F68F} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {8F4C3A2F-D807-437E-BAA4-10DF9721ED47} - \Microsoft\Windows\File Classification Infrastructure\Property Definition Sync -> No File <==== ATTENTION
Task: {93941A8C-B62A-4383-9647-48543C3D46EB} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\Windows\ehome\ehPrivJob.exe
Task: {9CF1022C-3096-42C8-B7D1-C45AD2ECFA68} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-07-07] (Adobe Systems Incorporated)
Task: {9CF49CEF-72AF-4AAC-92AE-C806F82B5BA9} - System32\Tasks\HPCustParticipation HP Photosmart 6520 series => C:\Program Files\HP\HP Photosmart 6520 series\Bin\HPCustPartic.exe [2012-10-17] (Hewlett-Packard Co.)
Task: {9EA7480C-8D0C-433C-B01B-877F8806F468} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\Windows\ehome\mcupdate.exe
Task: {AECE943D-33B9-4668-B77B-EA9A0CC8DCFE} - System32\Tasks\{F64690A7-57D1-4691-8404-F8579E46153F} => pcalua.exe -a D:\Start.exe -d D:\
Task: {B6E03635-430A-4401-97B5-CECB3D8D1264} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {BF0F6333-C70C-47F3-96E4-3F9487BC879D} - System32\Tasks\Microsoft_MKC_Logon_Task_itype.exe => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2015-07-08] (Microsoft Corporation)
Task: {C04ECDB0-5C5E-4950-95B1-75E511E2EF4C} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-09] (Google Inc.)
Task: {C366E052-25DF-4D80-8544-B857320EB13C} - System32\Tasks\{BE360029-1A25-495D-90E8-03327D70C798} => pcalua.exe -a C:\Users\Will\Downloads\v10_1200a\v10_1200a\SETUP.EXE -d C:\Users\Will\Downloads\v10_1200a\v10_1200a
Task: {C8F5B2F4-EB42-4152-9ABC-1505084A1BC0} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\Windows\ehome\ehPrivJob.exe
Task: {CDBB0BED-E1FE-4BC1-99B5-A6533C8B7398} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {CFA2B44A-0F67-47AC-9A27-24EF7A40D9AA} - System32\Tasks\Microsoft\Windows\Media Center\StartRecording => C:\Windows\ehome\ehrec.exe
Task: {D47C5385-20C1-4C54-8C4C-4F0F97F210B5} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\Windows\ehome\mcupdate.exe
Task: {E2A236A6-34FC-4DE0-8EE0-7088DB3E7421} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\Windows\ehome\ehPrivJob.exe
Task: {EB0DBF94-1EE7-430A-964F-C4C4B843E19F} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {F05CD53A-E6A0-434D-BB79-92CE2B21405D} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\Windows\ehome\MCUpdate.exe
Task: {F1A8A093-3349-4860-8008-56A142489D8A} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\Windows\ehome\ehPrivJob.exe
Task: {F8ACB413-39D3-4D67-B676-F06DA10F8B06} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\Windows\ehome\ehPrivJob.exe

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (Whitelisted) ==============

2015-07-10 07:00 - 2015-07-10 07:00 - 00028160 _____ () C:\WINDOWS\SYSTEM32\efsext.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00032768 _____ () C:\WINDOWS\SYSTEM32\licensemanagerapi.dll
2015-09-12 21:59 - 2015-09-12 21:59 - 00404480 _____ () C:\WINDOWS\System32\diagtrack_wininternal.dll
2015-10-01 11:26 - 2015-09-17 02:48 - 02494712 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
2015-10-01 11:26 - 2015-09-17 01:43 - 02028544 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RulesService.dll
2015-10-01 11:25 - 2015-09-17 01:42 - 00471040 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2015-10-01 11:25 - 2015-09-17 01:42 - 00619008 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SignalsManager.dll
2015-10-01 11:26 - 2015-09-17 02:48 - 02494712 _____ () C:\WINDOWS\System32\CoreUIComponents.dll
2015-10-01 11:26 - 2015-09-17 01:48 - 00429056 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll
2015-07-10 06:59 - 2015-07-10 06:59 - 00143360 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\XamlTileRendering.dll
2015-10-01 11:27 - 2015-09-17 01:44 - 06569472 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2015-10-01 11:26 - 2015-09-17 01:49 - 00884736 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Actions.dll
2015-10-01 11:25 - 2015-09-17 01:42 - 01808384 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2015-10-01 11:26 - 2015-09-17 01:43 - 02274816 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2015-07-10 07:00 - 2015-07-10 09:14 - 00210432 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.ProxyStub.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00577024 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.NodeWinrtWrap.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00181248 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\dss_service\node_modules\nodert-buffer-utils\bin\NodeRT_Buffer_Utils.node
2015-09-12 21:58 - 2015-09-12 21:58 - 00559616 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\dss_service\node_modules\windows.storage.streams\bin\NodeRT_Windows_Storage_Streams.node
2015-09-12 21:58 - 2015-09-12 21:58 - 00643072 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\dss_service\node_modules\windows.foundation.diagnostics\bin\NodeRT_Windows_Foundation_Diagnostics.node
2015-07-10 07:00 - 2015-07-10 09:14 - 00037888 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\dss_service\node_modules\winrt-projections\bin\Winrt_Projections.node
2015-09-12 21:58 - 2015-09-12 21:58 - 00796160 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\dss_service\node_modules\windows.web.http\bin\NodeRT_Windows_Web_Http.node
2015-09-12 21:58 - 2015-09-12 21:58 - 00961536 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\dss_service\node_modules\windows.web.http.headers\bin\NodeRT_Windows_Web_Http_Headers.node
2015-09-12 21:58 - 2015-09-12 21:58 - 00204288 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\dss_service\node_modules\windows.web.http.filters\bin\NodeRT_Windows_Web_Http_Filters.node
2015-09-12 21:58 - 2015-09-12 21:58 - 00397824 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\dss_service\node_modules\windows.foundation\bin\NodeRT_Windows_Foundation.node
2015-09-12 21:58 - 2015-09-12 21:58 - 00074240 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\dss_service\node_modules\windows.networking\bin\NodeRT_Windows_Networking.node
2015-09-12 21:59 - 2015-09-12 21:59 - 00093696 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\dss_service\node_modules\windows.security.cryptography\bin\NodeRT_Windows_Security_Cryptography.node
2015-09-12 21:59 - 2015-09-12 21:59 - 00124416 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\dss_service\node_modules\windows.cortana.pal\bin\NodeRT_Windows_Cortana_PAL.node
2015-10-07 17:52 - 2015-10-07 17:52 - 08395776 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsStore_2015.10.5.0_x64__8wekyb3d8bbwe\WinStore.Entertainment.Mobile.dll
2015-10-07 17:52 - 2015-10-07 17:52 - 02311680 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsStore_2015.10.5.0_x64__8wekyb3d8bbwe\MS.Entertainment.Common.Mobile.dll
2015-09-12 21:58 - 2015-09-12 21:58 - 00293376 _____ () C:\WINDOWS\SYSTEM32\textinputframework.dll
2015-10-03 03:43 - 2015-10-03 03:43 - 00012288 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_15.1001.16470.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
2015-10-03 03:43 - 2015-10-03 03:43 - 10814464 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_15.1001.16470.0_x64__8wekyb3d8bbwe\Microsoft.Photos.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\4b635db90d8ba7f072080945:Win32App
AlternateDataStreams: C:\656eb6bb05d5bc6e49108ea0911f:Win32App
AlternateDataStreams: C:\7ab19f3774a69f23a31870:Win32App
AlternateDataStreams: C:\800ee3b0049fbbd8b5:Win32App
AlternateDataStreams: C:\ca985ff25eb59928e2c831:Win32App
AlternateDataStreams: C:\dfcd3f7e37e2cd2b9f4a58d20f89b7f7:Win32App
AlternateDataStreams: C:\e21c02f7ea62d4cbbf1543:Win32App
AlternateDataStreams: C:\eb8a1304eec7690736df388a:Win32App
AlternateDataStreams: C:\Python27:Win32App
AlternateDataStreams: C:\Program Files\Microsoft Mouse and Keyboard Center:Win32App
AlternateDataStreams: C:\Program Files\Microsoft Silverlight:Win32App
AlternateDataStreams: C:\Program Files\MiniTool Partition Wizard Free 9.1:Win32App
AlternateDataStreams: C:\Program Files\onOne Software:Win32App
AlternateDataStreams: C:\Program Files (x86)\AMD:Win32App
AlternateDataStreams: C:\Program Files (x86)\HP:Win32App
AlternateDataStreams: C:\Program Files (x86)\ImgBurn:Win32App
AlternateDataStreams: C:\Program Files (x86)\LastPass:Win32App
AlternateDataStreams: C:\Program Files (x86)\Malwarebytes Anti-Malware:Win32App
AlternateDataStreams: C:\Program Files (x86)\Microsoft Office:Win32App
AlternateDataStreams: C:\Program Files (x86)\Microsoft Streets & Trips 2013:Win32App
AlternateDataStreams: C:\Program Files (x86)\Mozilla Firefox:Win32App
AlternateDataStreams: C:\Program Files (x86)\Nero:Win32App
AlternateDataStreams: C:\Program Files (x86)\Quicken:Win32App
AlternateDataStreams: C:\Program Files (x86)\Readiris Pro 12:Win32App
AlternateDataStreams: C:\Program Files (x86)\Scratch 2:Win32App
AlternateDataStreams: C:\Program Files\Common Files\microsoft shared:Win32App
AlternateDataStreams: C:\ProgramData\AVG2015:Win32App
AlternateDataStreams: C:\ProgramData\HP:Win32App
AlternateDataStreams: C:\ProgramData\HP Photo Creations:Win32App
AlternateDataStreams: C:\ProgramData\HP Product Assistant:Win32App
AlternateDataStreams: C:\ProgramData\Nero:Win32App
AlternateDataStreams: C:\Users\Will\Desktop\python:Win32App
AlternateDataStreams: C:\Users\Will\AppData\Local\Temp:Win32App

==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== EXE Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-3276915167-1117282696-2501375683-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Will\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)


==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [MSMQ-In-TCP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-Out-TCP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-In-UDP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-Out-UDP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [WCF-NetTcpActivator-In-TCP-64bit] => (Allow) LPort=808
FirewallRules: [{4F29D097-72D0-4BD9-9831-B1614FA571E8}] => (Allow) C:\Users\Will\AppData\Local\Temp\nsc169E.tmp\Installer-10847481.exe
FirewallRules: [{B1068BC0-C5BC-42AF-ADAB-0E542C4F0960}] => (Allow) C:\Users\Will\AppData\Local\Temp\nsc169E.tmp\Installer-10847481.exe
FirewallRules: [UDP Query User{C11E38A8-F683-49DF-93C5-F6C2DC12DCC6}C:\program files\onone software\perfect effects 9\perfect effects 9.exe] => (Allow) C:\program files\onone software\perfect effects 9\perfect effects 9.exe
FirewallRules: [TCP Query User{BCEF5CD5-83E8-4439-AF7B-74AE96946903}C:\program files\onone software\perfect effects 9\perfect effects 9.exe] => (Allow) C:\program files\onone software\perfect effects 9\perfect effects 9.exe
FirewallRules: [{27AF2BBE-C8D4-40EF-AF71-132F8604A281}] => (Allow) C:\Program Files (x86)\HP\digital imaging\smart web printing\smartwebprintexe.exe
FirewallRules: [{84FFA434-2EC6-419C-A573-37A871ED75EA}] => (Allow) C:\Program Files (x86)\HP\hp software update\hpwucli.exe
FirewallRules: [{4F4D38A1-6A6A-443E-897D-D60783D0F801}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqusgh.exe
FirewallRules: [{D81B5746-F05A-4FFE-9AE4-F0A0523906C9}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqusgm.exe
FirewallRules: [{35659ADF-BEC2-489D-89DA-C0E4C53F1D15}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe
FirewallRules: [{41F90221-7E1A-4083-AA2E-0E0A4E2DFA1C}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgplgtupl.exe
FirewallRules: [{5456DA41-C412-4EEB-AFBC-94FC32B0FD6E}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqpse.exe
FirewallRules: [{2CE01B35-12E8-433C-A43B-621CB256A243}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqfxt08.exe
FirewallRules: [{8B3EA9BD-AD67-4BA1-AE72-955012E961E5}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpofxs08.exe
FirewallRules: [{A2EDC82A-2A64-496B-8C2A-AE24A7E76941}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqpsapp.exe
FirewallRules: [{B69E08AD-2633-4028-8246-20048C3A2B05}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqsudi.exe
FirewallRules: [{5A2266FC-EB72-4FA3-9C4D-D594B56CB45E}] => (Allow) C:\Program Files (x86)\common files\hp\digital imaging\bin\hpqphotocrm.exe
FirewallRules: [{8D15E48D-D436-41D3-B655-F84085D29D96}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpiscnapp.exe
FirewallRules: [{0399C148-14E7-48E7-BBD3-80CBE29F1C23}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqnrs08.exe
FirewallRules: [{F6C7692A-ED48-433E-A3ED-56B1F27FB550}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpoews01.exe
FirewallRules: [{CB0C3ECB-B3E1-48C2-B526-315AC0B6BE1D}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpzwiz01.exe
FirewallRules: [{53B8B74F-45B2-4458-A08D-1837648DCDE0}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpfccopy.exe
FirewallRules: [{2B661164-EA55-4C20-B2D1-A25186F5D31D}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcopy2.exe
FirewallRules: [{B9524902-2B9B-49C6-8CD7-7A952B4D6D90}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqkygrp.exe
FirewallRules: [{8279D29B-EF12-4C06-8DD0-B55312C2491B}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hposid01.exe
FirewallRules: [{705AE12C-BD7F-4E49-965D-6250E79EE526}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hposfx08.exe
FirewallRules: [{E5A62B4C-7E50-49EB-BAA6-61655A433C91}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpofxm08.exe
FirewallRules: [{ADFBFD4F-B8FB-4DB6-A68B-191483FDF3FF}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqste08.exe
FirewallRules: [{1F0C22FA-95CC-4802-AC7E-79DA17B20454}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
FirewallRules: [{DC6BD8C5-19A0-4CB1-A6B7-46C4E125B647}] => (Allow) C:\Users\Will\AppData\Local\Temp\7zS497F\HPDiagnosticCoreUI.exe
FirewallRules: [{2AA758E0-87FC-47D1-BC57-A0F59DFC211B}] => (Allow) C:\Users\Will\AppData\Local\Temp\7zS497F\HPDiagnosticCoreUI.exe
FirewallRules: [{7A1DFE9E-6258-44CE-9B38-DDEBCD48D3EE}] => (Allow) C:\Program Files\HP\HP Photosmart 6520 series\Bin\HPNetworkCommunicatorCom.exe
FirewallRules: [{FF2090EF-8664-428C-849C-251E7A6271E6}] => (Allow) C:\Program Files\HP\HP Photosmart 6520 series\Bin\HPNetworkCommunicator.exe
FirewallRules: [{0F507ADA-CF20-4E13-8C07-7F13A8F0040D}] => (Allow) C:\Program Files\HP\HP Photosmart 6520 series\Bin\DeviceSetup.exe
FirewallRules: [{CE35C92F-CC0F-4627-905B-A8C3D997638D}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{080BE8D9-43FF-4457-815A-74F2BE5F1A5D}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgemca.exe
FirewallRules: [{6AF79A6C-6639-40B6-9DC6-F162362F135B}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgemca.exe
FirewallRules: [{629F86CE-92CF-4231-BD32-A21F8F367E1E}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgmfapx.exe
FirewallRules: [{7D761A4A-B75D-43FC-88B9-728729A94686}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgmfapx.exe
FirewallRules: [{0DD285ED-B4F7-462B-A489-E0BD19D7CAF2}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgdiagex.exe
FirewallRules: [{EA3B25E2-58AF-477E-BA7D-0206EAF80A04}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgdiagex.exe
FirewallRules: [{8ED1AC23-9270-4FC7-9D81-CB8E128896FC}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgnsa.exe
FirewallRules: [{035E9031-B57D-48AC-9129-DCD6F1AD0017}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgnsa.exe
FirewallRules: [{25AF8FEE-4134-445E-A82F-517FE5510440}] => (Allow) C:\Program Files (x86)\Raptr\raptr_im.exe
FirewallRules: [{3BBC30A7-A30C-4AF1-921E-3D32EA15B0BD}] => (Allow) C:\Program Files (x86)\Raptr\raptr_im.exe
FirewallRules: [{144117EF-0435-4C0E-9D6A-BC3BD8FD70A6}] => (Allow) C:\Program Files (x86)\Raptr\raptr.exe
FirewallRules: [{61028932-CFEA-42D3-A7D8-399952B84864}] => (Allow) C:\Program Files (x86)\Raptr\raptr.exe
FirewallRules: [{D04A0C09-128C-49A5-B85D-2C5A9CF168F8}] => (Allow) C:\WINDOWS\explorer.exe
FirewallRules: [{5E35B4BA-6E72-40C5-A097-588F16869C9E}] => (Allow) C:\Program Files\Windows Firewall Control\wfc.exe
FirewallRules: [{57B2054D-862B-4017-8FDB-424FFF7AFF9B}] => (Allow) C:\WINDOWS\system32\wwahost.exe
FirewallRules: [{1BBEF604-19A1-4883-A276-E1985B0FE6DA}] => (Block) C:\WINDOWS\system32\svchost.exe
FirewallRules: [{4F33CBA6-8459-460B-B02D-5B8271933D3E}] => (Block) C:\WINDOWS\system32\svchost.exe
FirewallRules: [{981506CD-E3A1-4FDA-8BF0-1D4BE0057928}] => (Block) C:\WINDOWS\system32\svchost.exe
FirewallRules: [{60ED38EE-E2F9-4716-AB0B-F86B05EB70D6}] => (Block) C:\WINDOWS\system32\svchost.exe
FirewallRules: [{9F02266A-1EEC-4CE5-88B3-F2C82F4F41D8}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{3902E232-7570-4045-89F9-61D7AFF18542}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{80CCA246-1AD7-4E30-B635-15FF88743245}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{8B16CE06-FBA4-416C-B1D0-E743192846FB}] => (Allow) C:\Program Files (x86)\Raptr\raptr.exe
FirewallRules: [{DA657764-E4B0-477C-B571-65145D060AAB}] => (Allow) C:\Program Files (x86)\Raptr\raptr.exe
FirewallRules: [{8C109969-FC2F-4B6C-A496-D88E087AB206}] => (Allow) C:\Program Files (x86)\Raptr\raptr_im.exe
FirewallRules: [{8DE5F0DD-6921-4A47-8C32-593888EAB43A}] => (Allow) C:\Program Files (x86)\Raptr\raptr_im.exe

==================== Faulty Device Manager Devices =============

Name:
Description:
Class Guid: {4d36e979-e325-11ce-bfc1-08002be10318}
Manufacturer:
Service:
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.


==================== Event log errors: =========================

Application errors:
==================
Error: (10/09/2015 09:06:29 AM) (Source: ESENT) (EventID: 413) (User: )
Description: SettingSyncHost (12144) Unable to create a new logfile because the database cannot write to the log drive. The drive may be read-only, out of disk space, misconfigured, or corrupted. Error -1032.

Error: (10/09/2015 09:06:29 AM) (Source: ESENT) (EventID: 488) (User: )
Description: SettingSyncHost (12144) An attempt to create the file "C:\WINDOWS\system32\edbtmp.log" failed with system error 5 (0x00000005): "Access is denied. ". The create file operation will fail with error -1032 (0xfffffbf8).

Error: (10/09/2015 09:06:18 AM) (Source: ESENT) (EventID: 413) (User: )
Description: SettingSyncHost (12144) Unable to create a new logfile because the database cannot write to the log drive. The drive may be read-only, out of disk space, misconfigured, or corrupted. Error -1032.

Error: (10/09/2015 09:06:18 AM) (Source: ESENT) (EventID: 488) (User: )
Description: SettingSyncHost (12144) An attempt to create the file "C:\WINDOWS\system32\edbtmp.log" failed with system error 5 (0x00000005): "Access is denied. ". The create file operation will fail with error -1032 (0xfffffbf8).

Error: (10/09/2015 09:06:08 AM) (Source: ESENT) (EventID: 413) (User: )
Description: SettingSyncHost (12144) Unable to create a new logfile because the database cannot write to the log drive. The drive may be read-only, out of disk space, misconfigured, or corrupted. Error -1032.

Error: (10/09/2015 09:06:08 AM) (Source: ESENT) (EventID: 488) (User: )
Description: SettingSyncHost (12144) An attempt to create the file "C:\WINDOWS\system32\edbtmp.log" failed with system error 5 (0x00000005): "Access is denied. ". The create file operation will fail with error -1032 (0xfffffbf8).

Error: (10/09/2015 09:05:58 AM) (Source: ESENT) (EventID: 413) (User: )
Description: SettingSyncHost (12144) Unable to create a new logfile because the database cannot write to the log drive. The drive may be read-only, out of disk space, misconfigured, or corrupted. Error -1032.

Error: (10/09/2015 09:05:58 AM) (Source: ESENT) (EventID: 488) (User: )
Description: SettingSyncHost (12144) An attempt to create the file "C:\WINDOWS\system32\edbtmp.log" failed with system error 5 (0x00000005): "Access is denied. ". The create file operation will fail with error -1032 (0xfffffbf8).

Error: (10/09/2015 09:05:47 AM) (Source: ESENT) (EventID: 413) (User: )
Description: SettingSyncHost (12144) Unable to create a new logfile because the database cannot write to the log drive. The drive may be read-only, out of disk space, misconfigured, or corrupted. Error -1032.

Error: (10/09/2015 09:05:47 AM) (Source: ESENT) (EventID: 488) (User: )
Description: SettingSyncHost (12144) An attempt to create the file "C:\WINDOWS\system32\edbtmp.log" failed with system error 5 (0x00000005): "Access is denied. ". The create file operation will fail with error -1032 (0xfffffbf8).


System errors:
=============
Error: (10/09/2015 08:36:09 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Adobe Acrobat Update Service service terminated unexpectedly. It has done this 1 time(s).

Error: (10/09/2015 08:13:07 AM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 10. The Windows SChannel error state is 10.

Error: (10/09/2015 08:13:07 AM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 10. The Windows SChannel error state is 10.

Error: (10/08/2015 02:27:40 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Sync Host_Session1 service to connect.

Error: (10/08/2015 02:27:40 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the User Data Storage_Session1 service to connect.

Error: (10/08/2015 02:27:33 PM) (Source: DCOM) (EventID: 10001) (User: WILL-PC)
Description: "C:\WINDOWS\system32\backgroundTaskHost.exe" -ServerName:CortanaUI.AppXy7vb4pc2dr3kc93kfc509b1d0arkfb2x.mca31CortanaUI.AppXtpp90jhw9p0njjb85kvhxpppgrqfp117.mcaUnavailableUnavailable

Error: (10/08/2015 02:27:32 PM) (Source: DCOM) (EventID: 10010) (User: WILL-PC)
Description: CortanaUI.AppXjxtspbn4351hrtx8tc95e89kaz3h2f1f.mca

Error: (10/08/2015 02:27:29 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The User Data Access_Session1 service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service.

Error: (10/08/2015 02:27:29 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The User Data Storage_Session1 service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service.

Error: (10/08/2015 02:27:29 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Contact Data_Session1 service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service.


CodeIntegrity:
===================================
Date: 2015-10-07 10:19:53.849
Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume3\Windows\assembly\GAC\Microsoft.StdFormat\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.StdFormat.dll that did not meet the Microsoft signing level requirements.

Date: 2015-10-07 10:19:53.776
Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume3\Windows\assembly\GAC\ADODB\7.0.3300.0__b03f5f7f11d50a3a\ADODB.dll that did not meet the Microsoft signing level requirements.

Date: 2015-10-07 10:19:53.696
Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume3\Windows\assembly\GAC\MSDATASRC\7.0.3300.0__b03f5f7f11d50a3a\MSDATASRC.dll that did not meet the Microsoft signing level requirements.

Date: 2015-10-07 10:19:53.365
Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume3\Windows\assembly\GAC\Microsoft.StdFormat\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.StdFormat.dll that did not meet the Microsoft signing level requirements.

Date: 2015-10-07 10:19:53.215
Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume3\Windows\assembly\GAC\ADODB\7.0.3300.0__b03f5f7f11d50a3a\ADODB.dll that did not meet the Microsoft signing level requirements.

Date: 2015-10-07 10:19:53.092
Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume3\Windows\assembly\GAC\MSDATASRC\7.0.3300.0__b03f5f7f11d50a3a\MSDATASRC.dll that did not meet the Microsoft signing level requirements.

Date: 2015-10-07 10:19:50.746
Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume3\Windows\assembly\GAC\stdole\7.0.3300.0__b03f5f7f11d50a3a\stdole.dll that did not meet the Microsoft signing level requirements.

Date: 2015-10-07 10:19:49.835
Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume3\Windows\assembly\GAC\stdole\7.0.3300.0__b03f5f7f11d50a3a\stdole.dll that did not meet the Microsoft signing level requirements.

Date: 2015-10-07 09:58:44.341
Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume3\Windows\assembly\GAC\Microsoft.StdFormat\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.StdFormat.dll that did not meet the Microsoft signing level requirements.

Date: 2015-10-07 09:58:44.300
Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume3\Windows\assembly\GAC\ADODB\7.0.3300.0__b03f5f7f11d50a3a\ADODB.dll that did not meet the Microsoft signing level requirements.


==================== Memory info ===========================

Processor: Intel® Core™ i3-2120 CPU @ 3.30GHz
Percentage of memory in use: 67%
Total physical RAM: 4078.28 MB
Available physical RAM: 1309.9 MB
Total Virtual: 8174.28 MB
Available Virtual: 4179.67 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:124.01 GB) (Free:15.64 GB) NTFS ==>[drive with boot components (obtained from BCD)]
Drive f: (SYSTEM) (Fixed) (Total:0.49 GB) (Free:0.45 GB) NTFS
Drive j: (WINDOWS) (Fixed) (Total:931.02 GB) (Free:699.09 GB) NTFS
Drive k: () (Fixed) (Total:574.62 GB) (Free:574.45 GB) NTFS
Drive l: (WINDOWS) (Fixed) (Total:658.64 GB) (Free:435.06 GB) NTFS ==>[system with boot components (obtained from reading drive)]

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: 6CC9DD12)
Partition 1: (Not Active) - (Size=500 MB) - (Type=07 NTFS)
Partition 2: (Active) - (Size=931 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 698.6 GB) (Disk ID: 58361309)
Partition 1: (Active) - (Size=124 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=574.6 GB) - (Type=OF Extended)

========================================================
Disk: 5 (MBR Code: Windows 7 or Vista) (Size: 658.6 GB) (Disk ID: A731E3CE)
Partition 1: (Not Active) - (Size=658.6 GB) - (Type=07 NTFS)

==================== End of Addition.txt ============================

#5 jntkwx

jntkwx

  • Malware Response Team
  • 4,339 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:New England, U.S.A.
  • Local time:08:21 AM

Posted 09 October 2015 - 11:39 AM

I see you have Adwcleaner installed.

 

Please download the latest version of AdwCleaner by Xplode and save to your Desktop.

  • Double click on AdwCleaner.exe to run the tool.
    Right-click and select Run As Administrator
  • The tool will start to update the database, please wait a bit.
  • Click on I agree button.
  • Click on the Scan button.
  • AdwCleaner will begin...be patient as the scan may take some time to complete.
  • After the scan has finished, click on the Logfile button...a logfile (AdwCleaner[S#].txt) will open in Notepad for review (where the largest value of # represents the most recent report).
  • The contents of the log file may be confusing. Unless you see a program name that you know should not be removed, don't worry about it. If you see an entry you want to keep, let me know about it.
  • Copy and paste the contents of that logfile in your next reply.
  • A copy of all logfiles are saved in the C:\AdwCleaner folder which was created when running the tool.

Regards,
Jason

 

Simple and easy ways to keep your computer safe and secure on the Internet

If I am helping you and have not returned in 48 hours, please feel free to send me a PM with a link to the topic.
My help is free... however, if you wish to show appreciation and support me personally fighting against malware, please consider a donation: btn_donate_SM.gif


#6 willhippy

willhippy
  • Topic Starter

  • Members
  • 157 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Bethlehem. PA
  • Local time:08:21 AM

Posted 09 October 2015 - 02:59 PM

Here is the log
# AdwCleaner v5.007 - Logfile created 11/09/2015 at 21:12:56
# Updated 08/09/2015 by Xplode
# Database : 2015-09-10.1 [Server]
# Operating system : Windows 10 Home (x64)
# Username : will - WILL-LAPTOP
# Running from : E:\Downloads\AdwCleaner.exe
# Option : Scan
# Support : http://toolslib.net/forum

***** [ Services ] *****


***** [ Folders ] *****

Folder Found : C:\Users\will\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc
Folder Found : C:\Users\will\AppData\Local\Google\Chrome\User Data\Default\Extensions\elicpjhcidhpjomhibiffojpinpmmpil
Folder Found : C:\Users\will\AppData\Local\Google\Chrome\User Data\Default\Extensions\bmnlcjabgnpnenekpadlanbbkooimhnj
Folder Found : C:\Users\will\AppData\Local\Google\Chrome\User Data\Default\Extensions\dkpejdfnpdkhifgbancbammdijojoffk

***** [ Files ] *****

File Found : C:\Users\will\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\elicpjhcidhpjomhibiffojpinpmmpil

***** [ Shortcuts ] *****


***** [ Scheduled tasks ] *****


***** [ Registry ] *****


***** [ Web browsers ] *****

[C:\Users\will\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Found : ask.com
[C:\Users\will\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Found : aol.com
[C:\Users\will\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Found : bmnlcjabgnpnenekpadlanbbkooimhnj
[C:\Users\will\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Found : dkpejdfnpdkhifgbancbammdijojoffk
[C:\Users\will\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Found : elicpjhcidhpjomhibiffojpinpmmpil
[C:\Users\will\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Found : faoigfclahgbjjjaopddafnnapmeppnc
[C:\Users\will\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Found : fkjlohfdjcjhmfcabomglnciodlnplhk
[C:\Users\will\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Found : oalbpfagfhfkcmklpdanadjpbfdedndn
[C:\Users\will\AppData\Local\Comodo\Chromodo\User Data\Default\Web data] [Search Provider] Found : aol.com
[C:\Users\will\AppData\Local\Comodo\Chromodo\User Data\Default\Web data] [Search Provider] Found : ask.com

########## EOF - C:\AdwCleaner\AdwCleaner[S2].txt - [2378 bytes] ##########
# AdwCleaner v5.009 - Logfile created 30/09/2015 at 20:27:20
# Updated 27/09/2015 by Xplode
# Database : 2015-09-30.1 [Server]
# Operating system : Windows 10 Home (x64)
# Username : will - WILL-LAPTOP
# Running from : E:\Downloads\AdwCleaner(2).exe
# Option : Scan
# Support : http://toolslib.net/forum

***** [ Services ] *****


***** [ Folders ] *****


***** [ Files ] *****

File Found : C:\Users\will\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\elicpjhcidhpjomhibiffojpinpmmpil

***** [ Shortcuts ] *****


***** [ Scheduled tasks ] *****


***** [ Registry ] *****


***** [ Web browsers ] *****

[C:\Users\will\AppData\Roaming\Mozilla\Firefox\Profiles\38rvlw7h.default\prefs.js] [Preference] Found : user_pref("keyword.URL", "hxxp://searchinterneat-a.akamaihd.net/s?eq=U0EeE1xZE1oZB1ZEfQANAgwVRwESbVoJA19cFQZHJBQBBQxBDAVHd11cBFhBR1dFdB9aFQQTR0cFME0FB18EURNNfWtdEkwdVUZrNVs=&q={searchTerms}");
[C:\Users\will\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Found : faoigfclahgbjjjaopddafnnapmeppnc
[C:\Users\will\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Found : fkjlohfdjcjhmfcabomglnciodlnplhk
[C:\Users\will\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Found : oalbpfagfhfkcmklpdanadjpbfdedndn

########## EOF - C:\AdwCleaner\AdwCleaner[S2].txt - [3823 bytes] ##########
# AdwCleaner v5.013 - Logfile created 09/10/2015 at 15:17:49
# Updated 09/10/2015 by Xplode
# Database : 2015-10-09.3 [Server]
# Operating system : Windows 10 Home (x64)
# Username : will - WILL-LAPTOP
# Running from : C:\Users\will\Desktop\AdwCleaner.exe
# Option : Scan
# Support : http://toolslib.net/forum

***** [ Services ] *****

Service Found : swdumon
Service Found : Service Mgr ResultsHub
Service Found : Update Mgr ResultsHub

***** [ Folders ] *****

Folder Found : C:\Program Files (x86)\Results Hub
Folder Found : C:\Program Files (x86)\Common Files\3929cb63-cbbd-4b9c-8b92-a50fbd04e656
Folder Found : C:\Program Files (x86)\Common Files\3929cb63-cbbd-4b9c-8b92-a50fbd04e656
Folder Found : C:\ProgramData\Results Hub
Folder Found : C:\ProgramData\3929cb63-cbbd-4b9c-8b92-a50fbd04e656
Folder Found : C:\ProgramData\3929cb63-cbbd-4b9c-8b92-a50fbd04e656
Folder Found : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Results Hub
Folder Found : C:\Users\will\AppData\Local\DriverToolkit
Folder Found : C:\Users\will\AppData\Local\slimware utilities inc
Folder Found : C:\Users\will\AppData\Local\Chromium\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc
Folder Found : C:\Users\will\AppData\Local\Chromium\User Data\Default\Extensions\oalbpfagfhfkcmklpdanadjpbfdedndn
Folder Found : C:\Users\will\AppData\Local\Chromium\User Data\Default\Extensions\elicpjhcidhpjomhibiffojpinpmmpil
Folder Found : C:\Users\will\AppData\Local\Chromium\User Data\Default\Extensions\bmnlcjabgnpnenekpadlanbbkooimhnj
Folder Found : C:\Users\will\AppData\Local\Chromium\User Data\Default\Extensions\dkpejdfnpdkhifgbancbammdijojoffk
Folder Found : C:\Users\will\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc
Folder Found : C:\Users\will\AppData\Local\Google\Chrome\User Data\Default\Extensions\oalbpfagfhfkcmklpdanadjpbfdedndn
Folder Found : C:\Users\will\AppData\Local\Google\Chrome\User Data\Default\Extensions\elicpjhcidhpjomhibiffojpinpmmpil
Folder Found : C:\Users\will\AppData\Local\Google\Chrome\User Data\Default\Extensions\bmnlcjabgnpnenekpadlanbbkooimhnj
Folder Found : C:\Users\will\AppData\Local\Google\Chrome\User Data\Default\Extensions\dkpejdfnpdkhifgbancbammdijojoffk
Folder Found : C:\Users\will\AppData\Roaming\OpenCandy
Folder Found : C:\Users\will\AppData\Roaming\UpdaterEX

***** [ Files ] *****

File Found : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ResultsHubDesktopSearch.lnk
File Found : C:\Users\will\AppData\Local\Chromium\User Data\Default\Local Extension Settings\elicpjhcidhpjomhibiffojpinpmmpil
File Found : C:\Users\will\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\elicpjhcidhpjomhibiffojpinpmmpil
File Found : C:\Users\will\AppData\Roaming\Mozilla\Firefox\Profiles\38rvlw7h.default\user.js
File Found : C:\Users\will\AppData\Roaming\Mozilla\Firefox\Profiles\38rvlw7h.default\searchplugins\palikan.xml
File Found : C:\Users\will\AppData\Roaming\Mozilla\Firefox\Profiles\38rvlw7h.default\searchplugins\default.xml
File Found : C:\WINDOWS\SysNative\drivers\swdumon.sys

***** [ DLLs ] *****


***** [ Shortcuts ] *****


***** [ Scheduled tasks ] *****

Task Found : UpdaterEX
Task Found : Go_Palikan

***** [ Registry ] *****

Key Found : HKCU\Software\Classes\CLSID\{A2DF06F9-A21A-44A8-8A99-8B9C84F29160}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{F83D1872-D9FF-47F8-B5A0-49CC51E24EE8}
Key Found : HKLM\SOFTWARE\Classes\CLSID\{99415057-7C50-439D-AA20-02D83C071B61}
Key Found : HKCU\Software\UpdaterEX
Key Found : HKCU\Software\Smart PC Solutions
Key Found : HKCU\Software\DriverToolkit
Key Found : HKCU\Software\PRODUCTSETUP
Key Found : HKCU\Software\SlimWare Utilities Inc
Key Found : HKCU\Software\go_palikan
Key Found : HKLM\SOFTWARE\SlimWare Utilities Inc
Key Found : HKLM\SOFTWARE\SLIMWARE UTILITIES, INC.
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\UpdaterEX
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Results Hub
Key Found : [x64] HKCU\Software\UpdaterEX
Key Found : [x64] HKCU\Software\Smart PC Solutions
Key Found : [x64] HKCU\Software\DriverToolkit
Key Found : [x64] HKCU\Software\PRODUCTSETUP
Key Found : [x64] HKCU\Software\SlimWare Utilities Inc
Key Found : [x64] HKCU\Software\go_palikan
Data Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page] - hxxp://searchinterneat-a.akamaihd.net/h?eq=U0EeCFZVBB8SRggadVoNBV9FEBhAcVteTA1CRVEOeV0NURRBRQJHJFxZUV8TRwEFIk0FA1ADB0VXfVBdFElXTwhxJUpNDU0CaUBB
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\OldSearch
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
Data Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes [DefaultScope] - {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6586d803-df30-46d3-a89a-4136c8571d45}
Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\OldSearch
Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
Data Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes [DefaultScope] - {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
Key Found : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6586d803-df30-46d3-a89a-4136c8571d45}
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
Data Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes [DefaultScope] - {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
Key Found : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6586d803-df30-46d3-a89a-4136c8571d45}
Key Found : HKU\S-1-5-21-1958726619-2033566604-2034206773-1001\Software\Microsoft\Internet Explorer\SearchScopes\OldSearch
Key Found : HKU\S-1-5-21-1958726619-2033566604-2034206773-1001\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
Data Found : HKU\S-1-5-21-1958726619-2033566604-2034206773-1001\Software\Microsoft\Internet Explorer\SearchScopes [DefaultScope] - {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
Key Found : HKU\S-1-5-21-1958726619-2033566604-2034206773-1001\Software\Microsoft\Internet Explorer\SearchScopes\{6586d803-df30-46d3-a89a-4136c8571d45}

***** [ Web browsers ] *****

[C:\Users\will\AppData\Roaming\Mozilla\Firefox\Profiles\38rvlw7h.default\prefs.js] [Preference] Found : user_pref("browser.newtab.url", "hxxp://searchinterneat-a.akamaihd.net/t?eq=U0EeFFhaR1oWHAwWIwxcBw1ADFYSIl8VVQoVRRgaJAwITAkVFlFHJVgIB1sXFRNBNARaB0tXUUEeGGlxR1dMc1BQNVVMEnEEQw==");
[C:\Users\will\AppData\Roaming\Mozilla\Firefox\Profiles\38rvlw7h.default\prefs.js] [Preference] Found : user_pref("keyword.URL", "hxxp://searchinterneat-a.akamaihd.net/s?eq=U0EeE1xZE1oZB1ZEfQANAgwVRwESbVoJA19cFQZHJBQBBQxBDAVHd11cBFhBR1dFdB9aFQQTR0cFME0FB18EURNNfWtdEkwdVUZrNVs=&q={searchTerms}");
[C:\Users\will\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Found : searchinterneat-a.akamaihd.net
[C:\Users\will\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Found : palikan
[C:\Users\will\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Startup_URLs] Found : hxxp://searchinterneat-a.akamaihd.net/h?eq=U0EeCFZVBB8SRggadVoNBV9FEBhAcVteTA1CRVEOeV0NURRBRQJHJFxZUV8TRwEFIk0FA1oDB0VXfV5bFElXTwhxJUpNDU0CaUBB
[C:\Users\will\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Default_Search_Provider_Data] Found : hxxp://searchinterneat-a.akamaihd.net/s?eq=U0EeE1xZE1oZB1ZEfQANAgwVRwESbVoJA19cFQZHJBQBBQxBDAVHd11cBFhBR1dFdB9aFQQTQkcFME0FBloEURNNfWtdEkwdVUZrNVs=&q={searchTerms}
[C:\Users\will\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Found : bmnlcjabgnpnenekpadlanbbkooimhnj
[C:\Users\will\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Found : dkpejdfnpdkhifgbancbammdijojoffk
[C:\Users\will\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Found : elicpjhcidhpjomhibiffojpinpmmpil
[C:\Users\will\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Found : faoigfclahgbjjjaopddafnnapmeppnc
[C:\Users\will\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Found : fkjlohfdjcjhmfcabomglnciodlnplhk
[C:\Users\will\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Found : oalbpfagfhfkcmklpdanadjpbfdedndn
[C:\Users\will\AppData\Local\Chromium\User Data\Default\Web data] [Search Provider] Found : palikan
[C:\Users\will\AppData\Local\Chromium\User Data\Default\Secure Preferences] [Extension] Found : bmnlcjabgnpnenekpadlanbbkooimhnj
[C:\Users\will\AppData\Local\Chromium\User Data\Default\Secure Preferences] [Extension] Found : dkpejdfnpdkhifgbancbammdijojoffk
[C:\Users\will\AppData\Local\Chromium\User Data\Default\Secure Preferences] [Extension] Found : elicpjhcidhpjomhibiffojpinpmmpil
[C:\Users\will\AppData\Local\Chromium\User Data\Default\Secure Preferences] [Extension] Found : faoigfclahgbjjjaopddafnnapmeppnc
[C:\Users\will\AppData\Local\Chromium\User Data\Default\Secure Preferences] [Extension] Found : fkjlohfdjcjhmfcabomglnciodlnplhk
[C:\Users\will\AppData\Local\Chromium\User Data\Default\Secure Preferences] [Extension] Found : oalbpfagfhfkcmklpdanadjpbfdedndn

########## EOF - C:\AdwCleaner\AdwCleaner[S2].txt - [13327 bytes] ##########

#7 jntkwx

jntkwx

  • Malware Response Team
  • 4,339 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:New England, U.S.A.
  • Local time:08:21 AM

Posted 09 October 2015 - 03:11 PM

Double click on AdwCleaner.exe to run the tool again. (right-click and select Run As Administrator)

  • The tool will start to update the database, please wait a bit.
  • Click on the Scan button.
  • AdwCleaner will begin to scan your computer like it did before.
  • After the scan has finished...
     
  • This time click on the Cleaning button.
  • Press OK when asked to close all programs and follow the onscreen prompts.
  • Press OK again to allow AdwCleaner to restart the computer and complete the removal process.
  • After rebooting, a logfile report (AdwCleaner[C#].txt) will open automatically (where the largest value of # represents the most recent report).
  • Copy and paste the contents of that logfile in your next reply.
  • A copy of that logfile will also be saved in the C:\AdwCleaner folder.

 

How is your computer running now?


Regards,
Jason

 

Simple and easy ways to keep your computer safe and secure on the Internet

If I am helping you and have not returned in 48 hours, please feel free to send me a PM with a link to the topic.
My help is free... however, if you wish to show appreciation and support me personally fighting against malware, please consider a donation: btn_donate_SM.gif


#8 willhippy

willhippy
  • Topic Starter

  • Members
  • 157 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Bethlehem. PA
  • Local time:08:21 AM

Posted 09 October 2015 - 03:18 PM

oops sorry I forgot to run clean (senior moment) Here is the log
# AdwCleaner v5.007 - Logfile created 11/09/2015 at 21:02:44
# Updated 08/09/2015 by Xplode
# Database : 2015-09-10.1 [Server]
# Operating system : Windows 10 Home (x64)
# Username : will - WILL-LAPTOP
# Running from : E:\Downloads\adwcleaner_5.007.exe
# Option : Cleaning
# Support : http://toolslib.net/forum

***** [ Services ] *****

[-] Service Deleted : swdumon

***** [ Folders ] *****

[-] Folder Deleted : C:\Program Files (x86)\Yahoo!\Companion
[-] Folder Deleted : C:\Users\will\AppData\Local\slimware utilities inc
[-] Folder Deleted : C:\Users\will\AppData\Local\Google\Chrome\User Data\Default\Extensions\oalbpfagfhfkcmklpdanadjpbfdedndn
[-] Folder Deleted : C:\Users\will\AppData\Local\Google\Chrome\User Data\Default\Extensions\elicpjhcidhpjomhibiffojpinpmmpil
[-] Folder Deleted : C:\Users\will\AppData\Local\Google\Chrome\User Data\Default\Extensions\bmnlcjabgnpnenekpadlanbbkooimhnj
[-] Folder Deleted : C:\Users\will\AppData\Local\Google\Chrome\User Data\Default\Extensions\dkpejdfnpdkhifgbancbammdijojoffk
[-] Folder Deleted : C:\Users\will\AppData\Roaming\Yahoo!\Companion

***** [ Files ] *****

[-] File Deleted : C:\Users\will\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\elicpjhcidhpjomhibiffojpinpmmpil
[-] File Deleted : C:\WINDOWS\Sysnative\drivers\swdumon.sys

***** [ Shortcuts ] *****


***** [ Scheduled tasks ] *****


***** [ Registry ] *****

[-] Key Deleted : HKLM\SOFTWARE\Google\Chrome\NativeMessagingHosts\avgsh
[-] Key Deleted : HKLM\SOFTWARE\Classes\YBrowserToolbar.YBrowserToolbar.1
[-] Key Deleted : HKLM\SOFTWARE\Classes\YBrowserToolbar.YBrowserToolbar
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{9522B3FB-7A2B-4646-8AF6-36E7F593073C}
[-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{81CA8FCD-1420-4A07-B47D-B30F3DDA79E1}
[-] Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID [{58124A0B-DC32-4180-9BFF-E0E21AE34026}]
[-] Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID [{977AE9CC-AF83-45E8-9E03-E2798216E2D5}]
[-] Key Deleted : HKU\.DEFAULT\Software\Yahoo\Companion
[-] Key Deleted : HKU\.DEFAULT\Software\AppDataLow\Software\AskToolbar
[-] Key Deleted : HKU\.DEFAULT\Software\AppDataLow\Software\Compete
[-] Key Deleted : HKU\.DEFAULT\Software\AppDataLow\Software\Yahoo\Companion
[-] Key Deleted : HKCU\Software\SlimWare Utilities Inc
[-] Key Deleted : HKCU\Software\Yahoo\Companion
[-] Key Deleted : HKCU\Software\Yahoo\YFriendsBar
[-] Key Deleted : HKCU\Software\AppDataLow\Software\Yahoo\Companion
[-] Key Deleted : HKLM\SOFTWARE\SlimWare Utilities Inc
[-] Key Deleted : HKLM\SOFTWARE\Yahoo\Companion
[!] Key Not Deleted : [x64] HKCU\Software\SlimWare Utilities Inc
[!] Key Not Deleted : [x64] HKCU\Software\Yahoo\Companion
[!] Key Not Deleted : [x64] HKCU\Software\Yahoo\YFriendsBar
[!] Key Not Deleted : HKU\.DEFAULT\Software\AppDataLow\Software\AskToolbar
[!] Key Not Deleted : HKU\.DEFAULT\Software\AppDataLow\Software\Compete
[!] Key Not Deleted : HKU\.DEFAULT\Software\AppDataLow\Software\Yahoo\Companion
[!] Key Not Deleted : HKU\S-1-5-21-1958726619-2033566604-2034206773-1001\Software\AppDataLow\Software\Yahoo\Companion
[!] Key Not Deleted : HKU\S-1-5-18\Software\AppDataLow\Software\AskToolbar
[!] Key Not Deleted : HKU\S-1-5-18\Software\AppDataLow\Software\Compete
[!] Key Not Deleted : HKU\S-1-5-18\Software\AppDataLow\Software\Yahoo\Companion

***** [ Web browsers ] *****

[-] [C:\Users\will\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : aol.com
[-] [C:\Users\will\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : ask.com
[-] [C:\Users\will\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : bmnlcjabgnpnenekpadlanbbkooimhnj
[-] [C:\Users\will\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : dkpejdfnpdkhifgbancbammdijojoffk
[-] [C:\Users\will\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : elicpjhcidhpjomhibiffojpinpmmpil
[-] [C:\Users\will\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : faoigfclahgbjjjaopddafnnapmeppnc
[-] [C:\Users\will\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : fkjlohfdjcjhmfcabomglnciodlnplhk
# AdwCleaner v5.009 - Logfile created 30/09/2015 at 20:13:27
# Updated 27/09/2015 by Xplode
# Database : 2015-09-30.1 [Server]
# Operating system : Windows 10 Home (x64)
# Username : will - WILL-LAPTOP
# Running from : E:\Downloads\AdwCleaner.exe
# Option : Cleaning
# Support : http://toolslib.net/forum

***** [ Services ] *****

[-] Service Deleted : Service Mgr ResultsHub
[-] Service Deleted : Update Mgr ResultsHub

***** [ Folders ] *****

[-] Folder Deleted : C:\Program Files (x86)\Results Hub
[-] Folder Deleted : C:\Program Files (x86)\Common Files\3929cb63-cbbd-4b9c-8b92-a50fbd04e656
[!] Folder Not Deleted : C:\Program Files (x86)\Common Files\3929cb63-cbbd-4b9c-8b92-a50fbd04e656
[-] Folder Deleted : C:\ProgramData\Results Hub
[-] Folder Deleted : C:\ProgramData\3929cb63-cbbd-4b9c-8b92-a50fbd04e656
[!] Folder Not Deleted : C:\ProgramData\3929cb63-cbbd-4b9c-8b92-a50fbd04e656
[-] Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Results Hub
[-] Folder Deleted : C:\Users\will\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc
[-] Folder Deleted : C:\Users\will\AppData\Local\Google\Chrome\User Data\Default\Extensions\oalbpfagfhfkcmklpdanadjpbfdedndn
[-] Folder Deleted : C:\Users\will\AppData\Local\Google\Chrome\User Data\Default\Extensions\elicpjhcidhpjomhibiffojpinpmmpil
[-] Folder Deleted : C:\Users\will\AppData\Local\Google\Chrome\User Data\Default\Extensions\bmnlcjabgnpnenekpadlanbbkooimhnj
[-] Folder Deleted : C:\Users\will\AppData\Local\Google\Chrome\User Data\Default\Extensions\dkpejdfnpdkhifgbancbammdijojoffk
[-] Folder Deleted : C:\Users\will\AppData\Roaming\OpenCandy
[-] Folder Deleted : C:\Users\will\AppData\Roaming\UpdaterEX

***** [ Files ] *****

[-] File Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ResultsHubDesktopSearch.lnk
[-] File Deleted : C:\Users\will\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\elicpjhcidhpjomhibiffojpinpmmpil
[-] File Deleted : C:\Users\will\AppData\Roaming\Mozilla\Firefox\Profiles\38rvlw7h.default\searchplugins\yahoo_ff.xml
[-] File Deleted : C:\Users\will\AppData\Roaming\Mozilla\Firefox\Profiles\38rvlw7h.default\user.js
[-] File Deleted : C:\Users\will\AppData\Roaming\Mozilla\Firefox\Profiles\38rvlw7h.default\searchplugins\search-simple.xml
[-] File Deleted : C:\Users\will\AppData\Roaming\Mozilla\Firefox\Profiles\38rvlw7h.default\searchplugins\yahoo.xml

***** [ Shortcuts ] *****


***** [ Scheduled tasks ] *****

[-] Task Deleted : UpdaterEX

***** [ Registry ] *****

[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F83D1872-D9FF-47F8-B5A0-49CC51E24EE8}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{99415057-7C50-439D-AA20-02D83C071B61}
[-] Key Deleted : HKCU\Software\UpdaterEX
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\UpdaterEX
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Results Hub
[!] Key Not Deleted : [x64] HKCU\Software\UpdaterEX
[-] Data Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
[-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\OldSearch
[-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
[-] Data Restored : HKCU\Software\Microsoft\Internet Explorer\SearchScopes [DefaultScope]
[!] Key Not Deleted : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\OldSearch
[!] Key Not Deleted : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
[-] Data Restored : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes [DefaultScope]
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
[-] Data Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes [DefaultScope]
[!] Key Not Deleted : HKU\S-1-5-21-1958726619-2033566604-2034206773-1001\Software\Microsoft\Internet Explorer\SearchScopes\OldSearch
[!] Key Not Deleted : HKU\S-1-5-21-1958726619-2033566604-2034206773-1001\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
[-] Data Restored : HKU\S-1-5-21-1958726619-2033566604-2034206773-1001\Software\Microsoft\Internet Explorer\SearchScopes [DefaultScope]

***** [ Web browsers ] *****

[-] [C:\Users\will\AppData\Roaming\Mozilla\Firefox\Profiles\38rvlw7h.default\prefs.js] [Preference] Deleted : user_pref("browser.newtab.url", "hxxp://searchinterneat-a.akamaihd.net/t?eq=U0EeFFhaR1oWHAwWIwxcBw1ADFYSIl8VVQoVRRgaJAwITAkVFlFHJVgIB1sXFRNBNARaB0tXUUEeGGlxR1dMc1BQNVVMEnEEQw==");
[-] [C:\Users\will\AppData\Roaming\Mozilla\Firefox\Profiles\38rvlw7h.default\prefs.js] [Preference] Deleted : user_pref("browser.startup.homepage", "hxxp://searchinterneat-a.akamaihd.net/h?eq=U0EeCFZVBB8SRggadVoNBV9FEBhAcVteTA1CRVEOeV0NURRBRQJHJFxZUV8TRwEFIk0FA18DB0VXfWFoKB8fHGdGM0xUFUo5VFc=");
[-] [C:\Users\will\AppData\Roaming\Mozilla\Firefox\Profiles\38rvlw7h.default\prefs.js] [Preference] Deleted : user_pref("keyword.URL", "hxxp://searchinterneat-a.akamaihd.net/s?eq=U0EeE1xZE1oZB1ZEfQANAgwVRwESbVoJA19cFQZHJBQBBQxBDAVHd11cBFhBR1dFdB9aFQQTR0cFME0FB18EURNNfWtdEkwdVUZrNVs=&q={searchTerms}");
[-] [C:\Users\will\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Startup_URLs] Deleted : hxxp://searchinterneat-a.akamaihd.net/h?eq=U0EeCFZVBB8SRggadVoNBV9FEBhAcVteTA1CRVEOeV0NURRBRQJHJFxZUV8TRwEFIk0FA1oDB0VXfV5bFElXTwhxJUpNDU0CaUBB
[-] [C:\Users\will\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Default_Search_Provider_Data] Deleted : hxxp://searchinterneat-a.akamaihd.net/s?eq=U0EeE1xZE1oZB1ZEfQANAgwVRwESbVoJA19cFQZHJBQBBQxBDAVHd11cBFhBR1dFdB9aFQQTQkcFME0FBloEURNNfWtdEkwdVUZrNVs=&q={searchTerms}
# AdwCleaner v5.013 - Logfile created 09/10/2015 at 15:47:47
# Updated 09/10/2015 by Xplode
# Database : 2015-10-09.3 [Server]
# Operating system : Windows 10 Home (x64)
# Username : will - WILL-LAPTOP
# Running from : C:\Users\will\Desktop\AdwCleaner.exe
# Option : Cleaning
# Support : http://toolslib.net/forum

***** [ Services ] *****

[-] Service Deleted : swdumon
[-] Service Deleted : Service Mgr ResultsHub
[-] Service Deleted : Update Mgr ResultsHub

***** [ Folders ] *****

[-] Folder Deleted : C:\Program Files (x86)\Results Hub
[-] Folder Deleted : C:\Program Files (x86)\Common Files\3929cb63-cbbd-4b9c-8b92-a50fbd04e656
[!] Folder Not Deleted : C:\Program Files (x86)\Common Files\3929cb63-cbbd-4b9c-8b92-a50fbd04e656
[-] Folder Deleted : C:\ProgramData\Results Hub
[-] Folder Deleted : C:\ProgramData\3929cb63-cbbd-4b9c-8b92-a50fbd04e656
[!] Folder Not Deleted : C:\ProgramData\3929cb63-cbbd-4b9c-8b92-a50fbd04e656
[-] Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Results Hub
[-] Folder Deleted : C:\Users\will\AppData\Local\DriverToolkit
[-] Folder Deleted : C:\Users\will\AppData\Local\slimware utilities inc
[-] Folder Deleted : C:\Users\will\AppData\Local\Chromium\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc
[-] Folder Deleted : C:\Users\will\AppData\Local\Chromium\User Data\Default\Extensions\oalbpfagfhfkcmklpdanadjpbfdedndn
[-] Folder Deleted : C:\Users\will\AppData\Local\Chromium\User Data\Default\Extensions\elicpjhcidhpjomhibiffojpinpmmpil
[-] Folder Deleted : C:\Users\will\AppData\Local\Chromium\User Data\Default\Extensions\bmnlcjabgnpnenekpadlanbbkooimhnj
[-] Folder Deleted : C:\Users\will\AppData\Local\Chromium\User Data\Default\Extensions\dkpejdfnpdkhifgbancbammdijojoffk
[-] Folder Deleted : C:\Users\will\AppData\Local\Google\Chrome\User Data\Default\Extensions\faoigfclahgbjjjaopddafnnapmeppnc
[-] Folder Deleted : C:\Users\will\AppData\Local\Google\Chrome\User Data\Default\Extensions\oalbpfagfhfkcmklpdanadjpbfdedndn
[-] Folder Deleted : C:\Users\will\AppData\Local\Google\Chrome\User Data\Default\Extensions\elicpjhcidhpjomhibiffojpinpmmpil
[-] Folder Deleted : C:\Users\will\AppData\Local\Google\Chrome\User Data\Default\Extensions\bmnlcjabgnpnenekpadlanbbkooimhnj
[-] Folder Deleted : C:\Users\will\AppData\Local\Google\Chrome\User Data\Default\Extensions\dkpejdfnpdkhifgbancbammdijojoffk
[-] Folder Deleted : C:\Users\will\AppData\Roaming\OpenCandy
[-] Folder Deleted : C:\Users\will\AppData\Roaming\UpdaterEX

***** [ Files ] *****

[-] File Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ResultsHubDesktopSearch.lnk
[-] File Deleted : C:\Users\will\AppData\Local\Chromium\User Data\Default\Local Extension Settings\elicpjhcidhpjomhibiffojpinpmmpil
[-] File Deleted : C:\Users\will\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\elicpjhcidhpjomhibiffojpinpmmpil
[-] File Deleted : C:\Users\will\AppData\Roaming\Mozilla\Firefox\Profiles\38rvlw7h.default\user.js
[-] File Deleted : C:\Users\will\AppData\Roaming\Mozilla\Firefox\Profiles\38rvlw7h.default\searchplugins\palikan.xml
[-] File Deleted : C:\Users\will\AppData\Roaming\Mozilla\Firefox\Profiles\38rvlw7h.default\searchplugins\default.xml
[-] File Deleted : C:\WINDOWS\SysNative\drivers\swdumon.sys

***** [ DLLs ] *****


***** [ Shortcuts ] *****


***** [ Scheduled tasks ] *****

[-] Task Deleted : UpdaterEX
[-] Task Deleted : Go_Palikan

***** [ Registry ] *****

[-] Key Deleted : HKCU\Software\Classes\CLSID\{A2DF06F9-A21A-44A8-8A99-8B9C84F29160}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F83D1872-D9FF-47F8-B5A0-49CC51E24EE8}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{99415057-7C50-439D-AA20-02D83C071B61}
[-] Key Deleted : HKCU\Software\UpdaterEX
[-] Key Deleted : HKCU\Software\Smart PC Solutions
[-] Key Deleted : HKCU\Software\DriverToolkit
[-] Key Deleted : HKCU\Software\PRODUCTSETUP
[-] Key Deleted : HKCU\Software\SlimWare Utilities Inc
[-] Key Deleted : HKCU\Software\go_palikan
[-] Key Deleted : HKLM\SOFTWARE\SlimWare Utilities Inc
[-] Key Deleted : HKLM\SOFTWARE\SLIMWARE UTILITIES, INC.
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\UpdaterEX
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Results Hub
[!] Key Not Deleted : [x64] HKCU\Software\UpdaterEX
[!] Key Not Deleted : [x64] HKCU\Software\Smart PC Solutions
[!] Key Not Deleted : [x64] HKCU\Software\DriverToolkit
[!] Key Not Deleted : [x64] HKCU\Software\PRODUCTSETUP
[!] Key Not Deleted : [x64] HKCU\Software\SlimWare Utilities Inc
[!] Key Not Deleted : [x64] HKCU\Software\go_palikan
[-] Data Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
[-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\OldSearch
[-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
[-] Data Restored : HKCU\Software\Microsoft\Internet Explorer\SearchScopes [DefaultScope]
[-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6586d803-df30-46d3-a89a-4136c8571d45}
[!] Key Not Deleted : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\OldSearch
[!] Key Not Deleted : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
[-] Data Restored : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes [DefaultScope]
[!] Key Not Deleted : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6586d803-df30-46d3-a89a-4136c8571d45}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
[-] Data Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes [DefaultScope]
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6586d803-df30-46d3-a89a-4136c8571d45}
[!] Key Not Deleted : HKU\S-1-5-21-1958726619-2033566604-2034206773-1001\Software\Microsoft\Internet Explorer\SearchScopes\OldSearch
[!] Key Not Deleted : HKU\S-1-5-21-1958726619-2033566604-2034206773-1001\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}
[-] Data Restored : HKU\S-1-5-21-1958726619-2033566604-2034206773-1001\Software\Microsoft\Internet Explorer\SearchScopes [DefaultScope]
[!] Key Not Deleted : HKU\S-1-5-21-1958726619-2033566604-2034206773-1001\Software\Microsoft\Internet Explorer\SearchScopes\{6586d803-df30-46d3-a89a-4136c8571d45}

***** [ Web browsers ] *****

[-] [C:\Users\will\AppData\Roaming\Mozilla\Firefox\Profiles\38rvlw7h.default\prefs.js] [Preference] Deleted : user_pref("browser.newtab.url", "hxxp://searchinterneat-a.akamaihd.net/t?eq=U0EeFFhaR1oWHAwWIwxcBw1ADFYSIl8VVQoVRRgaJAwITAkVFlFHJVgIB1sXFRNBNARaB0tXUUEeGGlxR1dMc1BQNVVMEnEEQw==");
[-] [C:\Users\will\AppData\Roaming\Mozilla\Firefox\Profiles\38rvlw7h.default\prefs.js] [Preference] Deleted : user_pref("keyword.URL", "hxxp://searchinterneat-a.akamaihd.net/s?eq=U0EeE1xZE1oZB1ZEfQANAgwVRwESbVoJA19cFQZHJBQBBQxBDAVHd11cBFhBR1dFdB9aFQQTR0cFME0FB18EURNNfWtdEkwdVUZrNVs=&q={searchTerms}");
[-] [C:\Users\will\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : searchinterneat-a.akamaihd.net
[-] [C:\Users\will\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : palikan
[-] [C:\Users\will\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Startup_URLs] Deleted : hxxp://searchinterneat-a.akamaihd.net/h?eq=U0EeCFZVBB8SRggadVoNBV9FEBhAcVteTA1CRVEOeV0NURRBRQJHJFxZUV8TRwEFIk0FA1oDB0VXfV5bFElXTwhxJUpNDU0CaUBB
[-] [C:\Users\will\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Default_Search_Provider_Data] Deleted : hxxp://searchinterneat-a.akamaihd.net/s?eq=U0EeE1xZE1oZB1ZEfQANAgwVRwESbVoJA19cFQZHJBQBBQxBDAVHd11cBFhBR1dFdB9aFQQTQkcFME0FBloEURNNfWtdEkwdVUZrNVs=&q={searchTerms}
[-] [C:\Users\will\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : bmnlcjabgnpnenekpadlanbbkooimhnj
[-] [C:\Users\will\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : dkpejdfnpdkhifgbancbammdijojoffk
[-] [C:\Users\will\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : elicpjhcidhpjomhibiffojpinpmmpil
[-] [C:\Users\will\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : faoigfclahgbjjjaopddafnnapmeppnc
[-] [C:\Users\will\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : fkjlohfdjcjhmfcabomglnciodlnplhk
[-] [C:\Users\will\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences] [Extension] Deleted : oalbpfagfhfkcmklpdanadjpbfdedndn
[-] [C:\Users\will\AppData\Local\Chromium\User Data\Default\Web Data] [Search Provider] Deleted : palikan
[-] [C:\Users\will\AppData\Local\Chromium\User Data\Default\Secure Preferences] [Extension] Deleted : bmnlcjabgnpnenekpadlanbbkooimhnj
[-] [C:\Users\will\AppData\Local\Chromium\User Data\Default\Secure Preferences] [Extension] Deleted : dkpejdfnpdkhifgbancbammdijojoffk
[-] [C:\Users\will\AppData\Local\Chromium\User Data\Default\Secure Preferences] [Extension] Deleted : elicpjhcidhpjomhibiffojpinpmmpil
[-] [C:\Users\will\AppData\Local\Chromium\User Data\Default\Secure Preferences] [Extension] Deleted : faoigfclahgbjjjaopddafnnapmeppnc
[-] [C:\Users\will\AppData\Local\Chromium\User Data\Default\Secure Preferences] [Extension] Deleted : fkjlohfdjcjhmfcabomglnciodlnplhk
[-] [C:\Users\will\AppData\Local\Chromium\User Data\Default\Secure Preferences] [Extension] Deleted : oalbpfagfhfkcmklpdanadjpbfdedndn

*************************

:: Winsock settings cleared

########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [20056 bytes] ##########

#9 jntkwx

jntkwx

  • Malware Response Team
  • 4,339 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:New England, U.S.A.
  • Local time:08:21 AM

Posted 09 October 2015 - 07:08 PM

That's ok. :)

 

How is the computer running now? Does the browser still seem to be hijacked? Please be as descriptive as possible.


Regards,
Jason

 

Simple and easy ways to keep your computer safe and secure on the Internet

If I am helping you and have not returned in 48 hours, please feel free to send me a PM with a link to the topic.
My help is free... however, if you wish to show appreciation and support me personally fighting against malware, please consider a donation: btn_donate_SM.gif


#10 willhippy

willhippy
  • Topic Starter

  • Members
  • 157 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Bethlehem. PA
  • Local time:08:21 AM

Posted 09 October 2015 - 07:45 PM

computer is great now thanks for the help

#11 jntkwx

jntkwx

  • Malware Response Team
  • 4,339 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:New England, U.S.A.
  • Local time:08:21 AM

Posted 09 October 2015 - 07:55 PM

You're welcome. It appears your computer is clean of malware!

 

Clean Upcleanupm.PNG

Now we remove all the tools we used (including their logs and quarantine folders), restore your settings and delete old and possibly infected system restore points:

  • You can uninstall programs that you had to install in the control panel if you so wish.
  • Download delfix.pngDelFix (by Xplode) and save it to your Desktop.
    • Close all running programs and start delfix.exe.
    • Make sure that all available options are checked.
    • Click on Run
    • DelFix should remove all our tools and delete itself afterwards. I don't need the log file.
  • If there is still something left you can delete it manually.

Tips

I recommend to read and follow advice in the "16 simple and easy ways to keep your computer safe and secure on the Internet" [ Link ] by Lawrence Abrams.


Edited by jntkwx, 09 October 2015 - 07:56 PM.

Regards,
Jason

 

Simple and easy ways to keep your computer safe and secure on the Internet

If I am helping you and have not returned in 48 hours, please feel free to send me a PM with a link to the topic.
My help is free... however, if you wish to show appreciation and support me personally fighting against malware, please consider a donation: btn_donate_SM.gif


#12 jntkwx

jntkwx

  • Malware Response Team
  • 4,339 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:New England, U.S.A.
  • Local time:08:21 AM

Posted 11 October 2015 - 03:02 PM

It appears that this issue is resolved, therefore I am closing the topic. If that is not the case and you need or wish to continue with this topic, please send me or any Moderator a Personal Message (PM) that you would like this topic re-opened.
Regards,
Jason

 

Simple and easy ways to keep your computer safe and secure on the Internet

If I am helping you and have not returned in 48 hours, please feel free to send me a PM with a link to the topic.
My help is free... however, if you wish to show appreciation and support me personally fighting against malware, please consider a donation: btn_donate_SM.gif





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users