Hey guys, Thanks in advance for your help!
I am on Windows 10 x64, all updates, etc. About a week ago I stupidly downloaded a suspicious file. Windows Defender immediately quarantined it and said it has Backdoor:MSIL/Bladabindi -- I thought that was the end of it until a few days later I noticed that google.com didn't work. I found that in my proxy settings I had a script setup which redirects google to another IP. I blocked that IP in firewall and set proxy settings to default.
I scanned with ZHPcleaner, Malwarebytes, TDS killer, Eset online scan, adwcleaner, ZHP cleaner, Rogue killer, Comodo rescue disk, Spybot, and nothing was found.
The proxy change reappeared a day later, and I saw somebody on another forum told me they had same issue and found the following registry key: [HKEY_CURRENT_USER\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings]
"AutoConfigURL"="http://localhost.world/localhost.host" -- I had the same reg key and deleted it. Since then I haven't had any proxy setting changes.
My only current issue now is that sometimes I will see a blank Command Prompt window open and Chrome will be closed. This has been happening maybe once a day. It only happened once when I was in front of computer and I wasn't able to see the program being run.
I would really appreciate some help with getting rid of this virus remnant. Thank you
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:17-12-2015
Ran by Michael (administrator) on MOTHERSHIP (17-12-2015 12:34:28)
Running from D:\Michael\Downloads
Loaded Profiles: Michael (Available Profiles: Michael & nancy & Administrator)
Platform: Windows 10 Pro Version 1511 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Pulse Secure, LLC) C:\Program Files (x86)\Common Files\Juniper Networks\JUNS\dsAccessService.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Schneider Electric) C:\Program Files (x86)\APC\PowerChute Personal Edition\mainserv.exe
(Advanced Micro Devices) C:\Program Files\AMD\{920DEC42-4CA5-4d1d-9487-67BE645CDDFC}\amdacpusrsvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(SEIKO EPSON CORPORATION) C:\Program Files\EPSON\EpsonCustomerParticipation\EPCP.exe
(Marvell) C:\Program Files (x86)\Marvell\mv91xx\util\mvpnplistener.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
(Mr. John aka japamd) C:\Program Files (x86)\RadeonPro\RadeonProSupport.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(Seiko Epson Corporation) C:\Windows\System32\escsvc64.exe
(Schneider Electric) C:\Program Files (x86)\APC\PowerChute Personal Edition\dataserv.exe
(Pulse Secure, LLC) C:\Program Files (x86)\Common Files\Juniper Networks\JUNS\dsAccessService.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
() C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.29.1\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.29.1\GoogleCrashHandler64.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_w32.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_x64.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe
(CMedia) C:\Program Files\UNi Xonar Audio\Customapp\AsusAudioCenter.exe
() C:\Windows\SysWOW64\HsMgr.exe
() C:\Windows\System\HsMgr64.exe
(Space Sciences Laboratory) C:\Program Files\BOINC\boinctray.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\cnext.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
(Spotify Ltd) C:\Users\Michael\AppData\Roaming\Spotify\SpotifyWebHelper.exe
(BitTorrent, Inc.) C:\Users\Michael\AppData\Roaming\BitTorrent Sync\BTSync.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Flux Software LLC) C:\Users\Michael\AppData\Local\FluxSoftware\Flux\flux.exe
(Space Sciences Laboratory) C:\Program Files\BOINC\boincmgr.exe
(Space Sciences Laboratory) C:\Program Files\BOINC\boinc.exe
(Microsoft Corporation) C:\Windows\System32\StikyNot.exe
(SEIKO EPSON CORPORATION) C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe
(Apple Inc.) C:\Program Files (x86)\AirPort\APAgent.exe
(Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
(Schneider Electric) C:\Program Files (x86)\APC\PowerChute Personal Edition\apcsystray.exe
(Evernote Corp., 305 Walnut Street, Redwood City, CA 94063) C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe
() C:\Program Files (x86)\SpeedFan\speedfan.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Adobe Systems Inc.) C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\acrotray.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
(Power Software Ltd) C:\Program Files\PowerISO\PWRISOVM.EXE
(Intuit Inc.) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
(Intel Corporation) C:\Program Files\Intel\Intel® Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files\Intel\Intel® Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Security Assist\isa.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe
(Microsoft Corporation) C:\Windows\System32\InstallAgent.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.6515.64021.0_x64__8wekyb3d8bbwe\HxCalendarAppImm.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.6515.64021.0_x64__8wekyb3d8bbwe\HxTsr.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsStore_2015.25.5.0_x64__8wekyb3d8bbwe\WinStore.Mobile.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\cmd.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\AppleChromeDAV.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [13318424 2015-03-12] (Logitech Inc.)
HKLM\...\Run: [apmwinapp] => C:\Program Files (x86)\Paragon Software\HFS+ for Windows 8 Free Edition\apmwinsrv.exe [66768 2014-11-10] ()
HKLM\...\Run: [Cmaudio8788] => C:\WINDOWS\syswow64\RunDll32.exe C:\WINDOWS\Syswow64\cmicnfgp.dll,CMICtrlWnd
HKLM\...\Run: [Cmaudio8788GX] => C:\WINDOWS\syswow64\HsMgr.exe [200704 2008-07-11] ()
HKLM\...\Run: [Cmaudio8788GX64] => C:\WINDOWS\system\HsMgr64.exe [282112 2008-07-11] ()
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [500936 2015-05-25] (Adobe Systems Incorporated)
HKLM\...\Run: [boinctray] => C:\Program Files\BOINC\boinctray.exe [68928 2015-08-27] (Space Sciences Laboratory)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [170256 2015-10-16] (Apple Inc.)
HKLM\...\Run: [StartCN] => C:\Program Files\AMD\CNext\CNext\cnext.exe [4866760 2015-11-29] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [EEventManager] => C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe [1058400 2012-01-26] (SEIKO EPSON CORPORATION)
HKLM-x32\...\Run: [FUFAXRCV] => C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXRCV.exe [642664 2013-12-24] (SEIKO EPSON CORPORATION)
HKLM-x32\...\Run: [FUFAXSTM] => C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe [863848 2013-12-24] (SEIKO EPSON CORPORATION)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-10-02] (Apple Inc.)
HKLM-x32\...\Run: [AirPort Base Station Agent] => C:\Program Files (x86)\AirPort\APAgent.exe [771360 2009-11-11] (Apple Inc.)
HKLM-x32\...\Run: [Display] => C:\Program Files (x86)\APC\PowerChute Personal Edition\DataCollectionLauncher.exe [284024 2012-01-24] (Schneider Electric)
HKLM-x32\...\Run: [LifeCam] => "C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe"
HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [24952456 2015-12-08] (Dropbox, Inc.)
HKLM-x32\...\Run: [PulseSecure] => C:\Program Files (x86)\Common Files\Juniper Networks\JamUI\Pulse.exe [2826584 2015-07-06] (Pulse Secure, LLC)
HKLM-x32\...\Run: [XPE] => C:\Program Files (x86)\XPE Windows 10 DPI Fix\XPEWindows10_DPI.exe [28672 2015-08-21] (XPExplorer.com - 2015)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [596528 2015-11-09] (Oracle Corporation)
HKLM-x32\...\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Acrotray.exe [1856184 2015-09-30] (Adobe Systems Inc.)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [4101576 2014-06-24] (Safer-Networking Ltd.)
HKLM-x32\...\Run: [PWRISOVM.EXE] => C:\Program Files\PowerISO\PWRISOVM.EXE [408888 2015-10-08] (Power Software Ltd)
Winlogon\Notify\GoToAssist: C:\Program Files (x86)\Citrix\GoToAssist Corporate\1121\G2AWinLogon_x64.dll (Citrix Online, a division of Citrix Systems, Inc.)
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
HKU\S-1-5-21-2172870717-1373750500-4216110194-1001\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [60688 2015-10-21] (Apple Inc.)
HKU\S-1-5-21-2172870717-1373750500-4216110194-1001\...\Run: [Spotify Web Helper] => C:\Users\Michael\AppData\Roaming\Spotify\SpotifyWebHelper.exe [2345584 2015-12-03] (Spotify Ltd)
HKU\S-1-5-21-2172870717-1373750500-4216110194-1001\...\Run: [1987D95A86FCFAF5B82FFA7E9B4B7814763EFF83._service_run] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [799560 2015-12-11] (Google Inc.)
HKU\S-1-5-21-2172870717-1373750500-4216110194-1001\...\Run: [Google Update] => C:\Users\Michael\AppData\Local\Google\Update\GoogleUpdate.exe [144200 2015-08-06] (Google Inc.)
HKU\S-1-5-21-2172870717-1373750500-4216110194-1001\...\Run: [BitTorrent Sync] => C:\Users\Michael\AppData\Roaming\BitTorrent Sync\BTSync.exe [6884888 2015-12-08] (BitTorrent, Inc.)
HKU\S-1-5-21-2172870717-1373750500-4216110194-1001\...\Run: [f.lux] => C:\Users\Michael\AppData\Local\FluxSoftware\Flux\flux.exe [1017224 2013-10-23] (Flux Software LLC)
HKU\S-1-5-21-2172870717-1373750500-4216110194-1001\...\Run: [boincmgr] => C:\Program Files\BOINC\boincmgr.exe [9016128 2015-08-27] (Space Sciences Laboratory)
HKU\S-1-5-21-2172870717-1373750500-4216110194-1001\...\Run: [Todoist] => C:\Users\Michael\AppData\Local\Todoist\WindowsDesktopApp\Todoist.exe [171080 2015-09-29] (Doist Ltd.)
HKU\S-1-5-21-2172870717-1373750500-4216110194-1001\...\Run: [RESTART_STICKY_NOTES] => C:\Windows\System32\StikyNot.exe [465920 2015-10-30] (Microsoft Corporation)
HKU\S-1-5-21-2172870717-1373750500-4216110194-1001\...\Run: [Spotify] => C:\Users\Michael\AppData\Roaming\Spotify\Spotify.exe [8270448 2015-12-03] (Spotify Ltd)
HKU\S-1-5-21-2172870717-1373750500-4216110194-1001\...\Run: [Plex Media Server] => C:\Program Files (x86)\Plex\Plex Media Server\Plex Media Server.exe [6580872 2015-11-17] (Plex, Inc.)
HKU\S-1-5-21-2172870717-1373750500-4216110194-1001\...\Run: [SpybotPostWindows10UpgradeReInstall] => C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe [1011200 2015-07-28] (Safer-Networking Ltd.)
HKU\S-1-5-21-2172870717-1373750500-4216110194-1001\...\RunOnce: [Uninstall C:\Users\Michael\AppData\Local\Microsoft\OneDrive\17.3.5951.0827_3\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Michael\AppData\Local\Microsoft\OneDrive\17.3.5951.0827_3\amd64"
HKU\S-1-5-18\...\Run: [EPLTarget\P0000000000000000] => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YATIJHE.EXE [283232 2012-02-28] (SEIKO EPSON CORPORATION)
ShellIconOverlayIdentifiers: [ GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2015-11-04] (Google)
ShellIconOverlayIdentifiers: [ GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2015-11-04] (Google)
ShellIconOverlayIdentifiers: [ GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2015-11-04] (Google)
ShellIconOverlayIdentifiers: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.28.dll [2015-12-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.28.dll [2015-12-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.28.dll [2015-12-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.28.dll [2015-12-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.28.dll [2015-12-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.28.dll [2015-12-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.28.dll [2015-12-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.28.dll [2015-12-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [!BTSync2.0.105Done] -> {581FFA04-FC33-0069-0002-95003A5CDE89} => C:\Program Files (x86)\BitTorrent Sync\SyncShellExtension_33554537.dll [2015-04-12] ()
ShellIconOverlayIdentifiers: [!BTSync2.0.105RO] -> {581FFA03-FC33-0069-0002-95003A5CDE89} => C:\Program Files (x86)\BitTorrent Sync\SyncShellExtension_33554537.dll [2015-04-12] ()
ShellIconOverlayIdentifiers: [!BTSync2.0.105RW] -> {581FFA02-FC33-0069-0002-95003A5CDE89} => C:\Program Files (x86)\BitTorrent Sync\SyncShellExtension_33554537.dll [2015-04-12] ()
ShellIconOverlayIdentifiers-x32: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.28.dll [2015-12-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.28.dll [2015-12-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.28.dll [2015-12-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.28.dll [2015-12-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.28.dll [2015-12-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.28.dll [2015-12-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.28.dll [2015-12-08] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.28.dll [2015-12-08] (Dropbox, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\APC UPS Status.lnk [2015-06-13]
ShortcutTarget: APC UPS Status.lnk -> C:\Program Files (x86)\APC\PowerChute Personal Edition\Display.exe (Schneider Electric)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Install LastPass IE RunOnce.lnk [2015-08-18]
ShortcutTarget: Install LastPass IE RunOnce.lnk -> C:\Program Files (x86)\Common Files\lpuninstall.exe (LastPass)
Startup: C:\Users\Michael\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EvernoteClipper.lnk [2015-10-04]
ShortcutTarget: EvernoteClipper.lnk -> C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)
BootExecute: autocheck autochk * sdnclean64.exe
GroupPolicyScripts: Restriction <======= ATTENTION
GroupPolicyScripts\User: Restriction <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 10.0.1.1
Tcpip\..\Interfaces\{180892fa-a373-4654-acc7-5f2407b9951b}: [DhcpNameServer] 10.0.1.1
Tcpip\..\Interfaces\{43b137f6-0950-4b8c-84bb-4657e8457627}: [DhcpNameServer] 10.0.1.1
Tcpip\..\Interfaces\{54b5a040-16de-413f-988a-6742bc17e8f6}: [DhcpNameServer] 10.0.1.1
Tcpip\..\Interfaces\{6777532f-aaa9-4dc6-9a04-57223d6585e8}: [DhcpNameServer] 10.0.1.1
Tcpip\..\Interfaces\{88343a25-6a6d-4b34-b574-f310992125e7}: [DhcpNameServer] 10.0.1.1
Tcpip\..\Interfaces\{af7f0e6a-c62f-4d9e-a2d2-2ba864ade9a3}: [NameServer] 160.129.6.22,129.59.1.10
Tcpip\..\Interfaces\{cc1755c7-ffd5-4267-9f01-c2482f90c40d}: [DhcpNameServer] 10.0.1.1
Tcpip\..\Interfaces\{e19b2732-fb6b-485c-b4a6-a417e1a4d5d3}: [DhcpNameServer] 10.0.1.1
Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
SearchScopes: HKU\S-1-5-21-2172870717-1373750500-4216110194-1001 -> 8DD2282DDC7C5C4A371A13CA0F65B180 URL = hxxp://internet-start.net/?q={searchTerms}
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2015-12-15] (Microsoft Corporation)
BHO: Java Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_66\bin\ssv.dll [2015-12-08] (Oracle Corporation)
BHO: LastPass Vault -> {95D9ECF5-2A4D-4550-BE49-70D42F71296E} -> C:\Program Files (x86)\LastPass\LPToolbar_x64.dll [2015-08-18] (LastPass)
BHO: Adobe Acrobat Create PDF Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\x64\AcroIEFavStub.dll [2015-09-30] (Adobe Systems Incorporated)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-10-12] (Microsoft Corporation)
BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL [2015-12-15] (Microsoft Corporation)
BHO: Java Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_66\bin\jp2ssv.dll [2015-12-08] (Oracle Corporation)
BHO: Adobe Acrobat Create PDF from Selection -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\x64\AcroIEFavStub.dll [2015-09-30] (Adobe Systems Incorporated)
BHO-x32: No Name -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> No File
BHO-x32: Java Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\ssv.dll [2015-12-08] (Oracle Corporation)
BHO-x32: Evernote extension -> {92EF2EAD-A7CE-4424-B0DB-499CF856608E} -> C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll [2015-12-01] (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)
BHO-x32: LastPass Vault -> {95D9ECF5-2A4D-4550-BE49-70D42F71296E} -> C:\Program Files (x86)\LastPass\LPToolbar.dll [2015-08-18] (LastPass)
BHO-x32: Adobe Acrobat Create PDF Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll [2015-09-30] (Adobe Systems Incorporated)
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-10-12] (Microsoft Corporation)
BHO-x32: No Name -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> No File
BHO-x32: Java Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\jp2ssv.dll [2015-12-08] (Oracle Corporation)
BHO-x32: Adobe Acrobat Create PDF from Selection -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll [2015-09-30] (Adobe Systems Incorporated)
Toolbar: HKLM - LastPass Toolbar - {9f6b5cc3-5c7b-4b5c-97af-19dec1e380e5} - C:\Program Files (x86)\LastPass\LPToolbar_x64.dll [2015-08-18] (LastPass)
Toolbar: HKLM - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\x64\AcroIEFavStub.dll [2015-09-30] (Adobe Systems Incorporated)
Toolbar: HKLM-x32 - LastPass Toolbar - {9f6b5cc3-5c7b-4b5c-97af-19dec1e380e5} - C:\Program Files (x86)\LastPass\LPToolbar.dll [2015-08-18] (LastPass)
Toolbar: HKLM-x32 - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll [2015-09-30] (Adobe Systems Incorporated)
DPF: HKLM-x32 {F27237D7-93C8-44C2-AC6E-D6057B9A918F} hxxps://juniper.net/dana-cached/sc/JuniperSetupClient.cab
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2015-12-15] (Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2015-12-15] (Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2015-12-15] (Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2015-12-15] (Microsoft Corporation)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-10-12] (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-10-12] (Microsoft Corporation)
Edge:
======
Edge HomeButtonPage: HKU\S-1-5-21-2172870717-1373750500-4216110194-1001 -> hxxp://www.yandex.ru/?win=203&clid=2100767-002
FireFox:
========
FF ProfilePath: C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\37lpeheh.default
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_20_0_0_235.dll [2015-12-08] ()
FF Plugin: @java.com/DTPlugin,version=11.66.2 -> C:\Program Files\Java\jre1.8.0_66\bin\dtplugin\npDeployJava1.dll [2015-12-08] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.66.2 -> C:\Program Files\Java\jre1.8.0_66\bin\plugin2\npjp2.dll [2015-12-08] (Oracle Corporation)
FF Plugin: @lastpass.com/NPLastPass -> C:\Program Files (x86)\LastPass\nplastpass64.dll [2015-08-18] (LastPass)
FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2014-09-22] (VideoLAN)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [2015-03-09] (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_20_0_0_235.dll [2015-12-08] ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2015-10-08] ()
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf -> C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\FOXIT READER\plugins\npFoxitReaderPlugin.dll [No File]
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf -> C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\FOXIT READER\plugins\npFoxitReaderPlugin.dll [No File]
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xdp -> C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\FOXIT READER\plugins\npFoxitReaderPlugin.dll [No File]
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xfdf -> C:\PROGRAM FILES (X86)\FOXIT SOFTWARE\FOXIT READER\plugins\npFoxitReaderPlugin.dll [No File]
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll [2015-10-13] (Google, Inc.)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.68 -> C:\Program Files\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll [2015-04-21] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2015-04-21] (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.66.2 -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\dtplugin\npDeployJava1.dll [2015-12-08] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.66.2 -> C:\Program Files (x86)\Java\jre1.8.0_66\bin\plugin2\npjp2.dll [2015-12-08] (Oracle Corporation)
FF Plugin-x32: @lastpass.com/NPLastPass -> C:\Program Files (x86)\LastPass\nplastpass64.dll [2015-08-18] (LastPass)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [No File]
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2015-12-15] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-04] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-04] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: Adobe Acrobat -> C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2015-09-30] (Adobe Systems Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-09-30] (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [2015-03-09] (Adobe Systems)
FF Plugin HKU\S-1-5-21-2172870717-1373750500-4216110194-1001: @citrixonline.com/appdetectorplugin -> C:\Users\Michael\AppData\Local\Citrix\Plugins\104\npappdetector.dll [2015-08-28] (Citrix Online)
FF Plugin HKU\S-1-5-21-2172870717-1373750500-4216110194-1001: @tools.google.com/Google Update;version=3 -> C:\Users\Michael\AppData\Local\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-04] (Google Inc.)
FF Plugin HKU\S-1-5-21-2172870717-1373750500-4216110194-1001: @tools.google.com/Google Update;version=9 -> C:\Users\Michael\AppData\Local\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-04] (Google Inc.)
FF Plugin HKU\S-1-5-21-2172870717-1373750500-4216110194-1001: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [2015-09-16] ()
FF SearchPlugin: C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\37lpeheh.default\searchplugins\yandex.ru-183702.xml [2015-11-18]
FF Extension: LastPass - C:\Users\Michael\AppData\Roaming\Mozilla\Firefox\Profiles\37lpeheh.default\extensions\support@lastpass.com [2015-10-27]
FF HKLM-x32\...\Firefox\Extensions: [fdm_ffext@freedownloadmanager.org] - C:\Program Files (x86)\Free Download Manager\Firefox\Extension
FF Extension: Free Download Manager extension - C:\Program Files (x86)\Free Download Manager\Firefox\Extension [2015-10-26]
FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension@web2pdf.adobedotcom] - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn
FF Extension: Adobe Acrobat DC - Create PDF - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn [2015-12-09] [not signed]
FF HKU\S-1-5-21-2172870717-1373750500-4216110194-1001\...\Firefox\Extensions: [fdm_ffext@freedownloadmanager.org] - C:\Program Files (x86)\Free Download Manager\Firefox\Extension
Chrome:
=======
CHR HomePage: Default -> yandex.ru/?__PARAM__from=chromehp
CHR DefaultSearchKeyword: Default -> google.com_
CHR Session Restore: Default -> is enabled.
CHR Plugin: (Widevine Content Decryption Module) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\WidevineCDM\1.4.8.866\_platform_specific\win_x64\widevinecdmadapter.dll (Google Inc.)
CHR Plugin: (Widevine Content Decryption Module) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\WidevineCDM\1.4.8.824\_platform_specific\win_x64\widevinecdmadapter.dll => No File
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\47.0.2526.106\PepperFlash\pepflashplayer.dll ()
CHR Profile: C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-06-25]
CHR Extension: (Magic Actions for YouTube™) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\abjcfabbhafbcdfjoecdgepllmpfceif [2015-12-09]
CHR Extension: (Xmarks Bookmark Sync) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\ajpgkpeckebdhofmmjfgcjjiiejpodla [2015-06-25]
CHR Extension: (Google Docs) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-06-25]
CHR Extension: (Google Drive) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-20]
CHR Extension: (YouTube) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-25]
CHR Extension: (Ratings Preview for YouTube™) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\cgbhdenfmgbagncdmgbholejjpmmiank [2015-06-25]
CHR Extension: (Pushbullet) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\chlffgpmiacpedhhbkiomidkjlcfhogd [2015-12-14]
CHR Extension: (uBlock Origin) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpalhdlnbpafiamejdnhcphjbkeiagm [2015-12-14]
CHR Extension: (Videostream for Google Chromecast™) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\cnciopoikihiagdjbjpnocolokfelagl [2015-12-17]
CHR Extension: (Google Search) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-26]
CHR Extension: (Mailto: for Gmail™) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\dgkkmcknielgdhebimdnfahpipajcpjn [2015-12-09]
CHR Extension: (Gmelius for Gmail) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\dheionainndbbpoacpnopgmnihkcmnkl [2015-12-14]
CHR Extension: (Google Cast (Beta)) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\dliochdbjfkdbacpmhlcpmleaejidimm [2015-12-08]
CHR Extension: (Dropbox for Gmail) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\dpdmhfocilnekecfjgimjdeckachfbec [2015-12-06]
CHR Extension: (Zotero Connector) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\ekhagklcjbdpajgpjgmbionohlpdbjgc [2015-06-25]
CHR Extension: (Google Play Music) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\fahmaaghhglfmonjliepjlchgpgfmobi [2015-12-08]
CHR Extension: (Google Sheets) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-06-25]
CHR Extension: (Wunderlist - To-do and Task list) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjliknjliaohjgjajlgolhijphojjdkc [2015-12-02]
CHR Extension: (iCloud Bookmarks) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\fkepacicchenbjecpbpbclokcabebhah [2015-09-13]
CHR Extension: (Reddit votes) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\geedigenhgnhbebebbjlidlalocdggjl [2015-06-25]
CHR Extension: (Google Docs Offline) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-11-17]
CHR Extension: (LastPass: Free Password Manager) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\hdokiejnpimakedhajhdlcegeplioahd [2015-10-26]
CHR Extension: (Checker Plus for Google Calendar™) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\hkhggnncdpfibdhinjiegagmopldibha [2015-12-09]
CHR Extension: (Google Keep - notes and lists) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmjkmjkepdijhoojdojkdfohbdgmmhki [2015-12-14]
CHR Extension: (Dropbox) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\ioekoebejdcmnlefjiknokhhafglcjdl [2015-06-29]
CHR Extension: (Google Tasks Offline (Unofficial)) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\jekhpicinnaamcmadbipjejafgkjdokh [2015-06-25]
CHR Extension: (Reddit Enhancement Suite) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbmfpngjjgdllneeigpgjifpgocmfgmb [2015-06-25]
CHR Extension: (StumbleUpon) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\kcahibnffhnnjcedflmchmokndkjnhpg [2015-06-25]
CHR Extension: (Simplenote) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfjoocpipbbafoimjgbkmfnjcjejdbjo [2015-06-25]
CHR Extension: (Auto HD For YouTube™) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\koiaokdomkpjdgniimnkhgbilbjgpeak [2015-06-25]
CHR Extension: (Evernote Web) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbfehkoinhhcknnbdgnnmjhiladcgbol [2015-06-25]
CHR Extension: (Graph Your Inbox) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\lghnjmocfihonjdijomigppjlpdgdeji [2015-06-25]
CHR Extension: (Boomerang for Gmail) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\mdanidgdpmkimeiiojknlnekblgmpdll [2015-12-14]
CHR Extension: (Flashcontrol) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfidmkgnfgnkihnjeklbekckimkipmoe [2015-12-17]
CHR Extension: (Google Dictionary (by Google)) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\mgijmajocgfcbeboacabfgobmjgjcoja [2015-06-25]
CHR Extension: (Pocket) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjcnijlhddpbdemagnpefmlkjdagkogk [2015-09-01]
CHR Extension: (Google Hangouts) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\nckgahadagoaajjgafhacjanaoiihapd [2015-12-09]
CHR Extension: (Save to Pocket) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\niloccemoadcdkdjlinkgdfekeahmflj [2015-10-16]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-07-26]
CHR Extension: (Cite This For Me: Web Citer) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\nnnmhgkokpalnmbeighfomegjfkklkle [2015-06-25]
CHR Extension: (APK Downloader) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\obhlfmheblhjhkmacldlhdnbgbaiigba [2015-06-25]
CHR Extension: (Checker Plus for Gmail™) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\oeopbcgkkoapgobdbedcemjljbihmemj [2015-11-28]
CHR Extension: (Page Notes) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\omjdheidbhoghpfdnndkgoelfiogjfla [2015-09-06]
CHR Extension: (Amazon Assistant for Chrome) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbjikboenpfhbbejgkoklgkhjpfogcam [2015-12-14]
CHR Extension: (Evernote Web Clipper) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\pioclpoplcdbaefihamjohnefbikjilc [2015-09-23]
CHR Extension: (Gmail) - C:\Users\Michael\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-06-25]
CHR HKLM\...\Chrome\Extension: [hdokiejnpimakedhajhdlcegeplioahd] - hxxp://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [bejnpnkhfgfkcpgikiinojlmdcjimobi] - hxxp://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [bhjcgomkanpkpblokebecknhahgkcmoo] - hxxp://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [cpegcopcfajiiibidlaelhjjblpefbjk] - hxxp://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [fdjdjkkjoiomafnihnobkinnfjnnlhdg] - hxxp://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [hdokiejnpimakedhajhdlcegeplioahd] - hxxp://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2015-10-12]
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 amdacpusrsvc; C:\Program Files\AMD\{920DEC42-4CA5-4d1d-9487-67BE645CDDFC}\amdacpusrsvc.exe [121856 2015-11-29] (Advanced Micro Devices) [File not signed]
R2 APC Data Service; C:\Program Files (x86)\APC\PowerChute Personal Edition\dataserv.exe [21880 2012-01-24] (Schneider Electric)
R2 APC UPS Service; C:\Program Files (x86)\APC\PowerChute Personal Edition\mainserv.exe [705912 2012-01-24] (Schneider Electric)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77104 2015-10-07] (Apple Inc.)
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1433216 2015-10-12] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1773696 2015-10-12] (Microsoft Corporation)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [2748600 2015-12-04] (Microsoft Corporation)
S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2015-11-21] (Dropbox, Inc.)
S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2015-11-21] (Dropbox, Inc.)
R2 EpsonScanSvc; C:\WINDOWS\system32\EscSvc64.exe [135824 2011-12-12] (Seiko Epson Corporation)
S3 GoToAssist; C:\Program Files (x86)\Citrix\GoToAssist Corporate\1121\G2AC_Service.exe [310080 2015-08-28] (Citrix Online, a division of Citrix Systems, Inc.)
S3 Intel® Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [881152 2015-05-22] (Intel® Corporation)
R3 Intel® Security Assist; C:\Program Files (x86)\Intel\Intel® Security Assist\isa.exe [335872 2015-05-19] (Intel Corporation) [File not signed]
S2 isaHelperSvc; C:\Program Files (x86)\Intel\Intel® Security Assist\isaHelperService.exe [7680 2015-05-19] () [File not signed]
R2 jhi_service; C:\Program Files\Intel\Intel® Management Engine Components\DAL\jhi_service.exe [223008 2015-07-06] (Intel Corporation)
R2 JuniperAccessService; C:\Program Files (x86)\Common Files\Juniper Networks\JUNS\dsAccessService.exe [162136 2015-07-06] (Pulse Secure, LLC)
R2 LMS; C:\Program Files\Intel\Intel® Management Engine Components\LMS\LMS.exe [415520 2015-07-06] (Intel Corporation)
R2 Marvell PNP Listener; C:\Program Files (x86)\Marvell\mv91xx\util\mvpnplistener.exe [96584 2014-12-01] (Marvell)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1513784 2015-10-05] (Malwarebytes)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
S3 PAExec; C:\WINDOWS\PAExec.exe [207872 2015-08-12] (Power Admin LLC) [File not signed]
R2 RadeonPro Support Service; C:\Program Files (x86)\RadeonPro\RadeonProSupport.exe [20608 2013-11-04] (Mr. John aka japamd) [File not signed]
R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1738168 2014-06-24] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2088408 2014-06-27] (Safer-Networking Ltd.)
S3 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2014-04-25] (Safer-Networking Ltd.)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [6887696 2015-11-30] (TeamViewer GmbH)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2015-10-30] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-10-30] (Microsoft Corporation)
S3 rpcapd; "C:\Program Files (x86)\WinPcap\rpcapd.exe" -d -f "C:\Program Files (x86)\WinPcap\rpcapd.ini"
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 amdacpksd; C:\WINDOWS\system32\drivers\amdacpksd.sys [297672 2015-09-30] (Advanced Micro Devices)
S0 amdkmafd; C:\Windows\System32\drivers\amdkmafd.sys [40720 2015-07-28] (Advanced Micro Devices, Inc.)
R0 amdkmpfd; C:\Windows\System32\drivers\amdkmpfd.sys [62152 2014-10-27] (Advanced Micro Devices, Inc.)
R0 apmwin; C:\Windows\System32\DRIVERS\apmwin.sys [35024 2014-11-10] (Paragon Software Group)
R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdWT6.sys [102912 2015-09-17] (Advanced Micro Devices)
R3 BCM43XX; C:\Windows\system32\DRIVERS\bcmwl63a.sys [8510640 2014-02-06] (Broadcom Corporation)
S3 BCMWL63A; C:\Windows\system32\DRIVERS\bcmwl63a.sys [8510640 2014-02-06] (Broadcom Corporation)
S3 CLVirtualBus02; C:\Windows\System32\drivers\CLVirtualBus02.sys [103176 2015-03-18] (CyberLink)
R3 cmudaxp; C:\Windows\system32\drivers\cmudaxp.sys [2735616 2013-12-11] (C-Media Inc)
R3 CORK70; C:\Windows\system32\drivers\CORK70.sys [25600 2012-10-31] ( )
S3 CorsairVBusDriver; C:\Windows\System32\drivers\CorsairVBusDriver.sys [47840 2015-07-06] (Corsair)
S3 CorsairVHidDriver; C:\Windows\System32\drivers\CorsairVHidDriver.sys [21728 2015-07-06] (Corsair)
R0 gpt_loader; C:\Windows\System32\DRIVERS\gpt_loader.sys [61136 2014-11-10] (Paragon Software Group)
S3 Hfsplus; C:\Windows\System32\DRIVERS\hfsplus.sys [205008 2014-11-10] (Paragon Software Group)
R2 HfsplusRec; C:\Windows\System32\DRIVERS\hfsplusrec.sys [15568 2014-11-10] (Paragon Software Group)
R1 jnprns; C:\Windows\system32\DRIVERS\jnprns.sys [507192 2015-07-05] (Juniper Networks)
S4 jnprTdi_814_60057; C:\WINDOWS\system32\Drivers\jnprTdi_814_60057.sys [108344 2015-07-06] (Pulse Secure, LLC)
S3 jnprva; C:\Windows\System32\drivers\jnprva.sys [30072 2015-07-05] (Juniper Networks, Inc.)
R3 JnprVaMgr; C:\Windows\System32\drivers\jnprvamgr.sys [45352 2015-07-05] (Juniper Networks, Inc.)
R3 LcUvcUpper; C:\Windows\system32\DRIVERS\LcUvcUpper.sys [37912 2015-09-30] (Microsoft Corporation)
R3 LGSHidFilt; C:\Windows\system32\DRIVERS\LGSHidFilt.Sys [64280 2013-05-30] (Logitech Inc.)
R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2015-10-05] (Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [192216 2015-12-17] (Malwarebytes)
R3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2015-10-05] (Malwarebytes Corporation)
R3 MEIx64; C:\Windows\System32\drivers\TeeDriverW8x64.sys [184096 2015-06-29] (Intel Corporation)
R0 mounthlp; C:\Windows\System32\DRIVERS\mounthlp.sys [42704 2014-11-10] (Paragon Software Group)
R2 npf; C:\Windows\System32\drivers\npf.sys [36600 2014-08-18] (Riverbed Technology, Inc.)
S3 qcusbser; C:\Windows\system32\DRIVERS\qcusbser.sys [242688 2013-04-24] (QUALCOMM Incorporated) [File not signed]
R3 RTCore64; C:\Program Files (x86)\MSI Afterburner\RTCore64.sys [13536 2015-05-27] ()
R3 ScpVBus; C:\Windows\System32\drivers\ScpVBus.sys [39168 2013-05-05] (Scarlet.Crush Productions)
R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [42696 2015-07-23] (Synaptics Incorporated)
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation)
R2 WinI2C-DDC; C:\WINDOWS\system32\drivers\DDCDrv.sys [20832 2015-08-07] (Nicomsoft Ltd.)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-12-15 12:56 - 2015-12-15 12:56 - 00000218 _____ C:\Users\Michael\AppData\Local\recently-used.xbel
2015-12-15 12:56 - 2015-12-15 12:56 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerISO
2015-12-15 12:34 - 2015-12-15 12:34 - 00000000 ____D C:\Users\Michael\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows 7 USB DVD Download Tool
2015-12-15 12:34 - 2015-12-15 12:34 - 00000000 ____D C:\Users\Michael\AppData\Local\Apps\Windows 7 USB DVD Download Tool
2015-12-15 09:00 - 2015-12-15 09:38 - 00000000 ____D C:\Kaspersky Rescue Disk 10.0
2015-12-14 19:21 - 2015-12-14 19:21 - 00000000 ____D C:\Program Files\Common Files\AV
2015-12-14 19:21 - 2015-07-28 17:52 - 00821920 _____ (Safer-Networking Ltd. ) C:\Users\Public\Desktop\Post Win10 Spybot-install.exe
2015-12-14 19:17 - 2015-12-14 19:24 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2015-12-14 19:17 - 2015-12-14 19:22 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
2015-12-14 19:17 - 2015-12-14 19:17 - 00001464 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk
2015-12-14 19:17 - 2015-12-14 19:17 - 00001452 _____ C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
2015-12-14 19:17 - 2015-12-14 19:17 - 00000000 ____D C:\WINDOWS\System32\Tasks\Safer-Networking
2015-12-14 19:17 - 2015-12-14 19:17 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
2015-12-14 19:17 - 2013-09-20 10:49 - 00021040 _____ (Safer Networking Limited) C:\WINDOWS\system32\sdnclean64.exe
2015-12-14 19:05 - 2015-12-17 09:25 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-12-14 19:05 - 2015-12-14 19:05 - 00001175 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-12-14 19:05 - 2015-12-14 19:05 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-12-14 19:05 - 2015-12-14 19:05 - 00000000 ____D C:\ProgramData\Malwarebytes
2015-12-14 19:05 - 2015-12-14 19:05 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-12-14 19:05 - 2015-10-05 09:50 - 00109272 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2015-12-14 19:05 - 2015-10-05 09:50 - 00064216 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
2015-12-14 19:05 - 2015-10-05 09:50 - 00025816 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
2015-12-14 18:50 - 2015-12-14 18:50 - 00002125 _____ C:\Users\Michael\Desktop\ZHPCleaner.txt
2015-12-14 18:49 - 2015-12-14 18:49 - 00012872 _____ (SurfRight B.V.) C:\WINDOWS\system32\bootdelete.exe
2015-12-14 18:46 - 2015-12-14 18:46 - 00000917 _____ C:\Users\Michael\Desktop\ZHPCleaner.lnk
2015-12-14 17:57 - 2015-12-14 17:57 - 00000000 ____D C:\Users\nancy\AppData\Local\Apple Computer
2015-12-14 12:03 - 2015-12-14 12:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Evernote
2015-12-13 18:05 - 2015-12-14 18:49 - 00000000 ____D C:\ProgramData\HitmanPro
2015-12-13 12:30 - 2015-12-17 12:34 - 00000000 ____D C:\FRST
2015-12-13 12:30 - 2015-12-17 12:32 - 00109816 _____ C:\Users\Michael\Desktop\FRST.txt
2015-12-13 12:18 - 2015-12-14 18:42 - 00000000 ____D C:\AdwCleaner
2015-12-13 12:00 - 2015-12-13 12:00 - 01938944 _____ C:\Users\Michael\ZHPCleaner.exe
2015-12-11 22:20 - 2015-12-11 22:20 - 00000000 ____D C:\Users\nancy\AppData\Local\Adobe
2015-12-11 22:15 - 2015-12-11 22:15 - 00001247 _____ C:\Users\nancy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CNext.lnk
2015-12-11 22:10 - 2015-12-11 22:10 - 00000000 ____D C:\Users\nancy\AppData\Local\AMD
2015-12-11 22:09 - 2015-12-11 22:09 - 00000020 ___SH C:\Users\nancy\ntuser.ini
2015-12-11 22:09 - 2015-12-11 22:09 - 00000000 ____D C:\Users\nancy\AppData\Local\Publishers
2015-12-11 19:49 - 2015-12-11 19:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox
2015-12-10 10:04 - 2015-12-10 10:04 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCloud
2015-12-09 22:03 - 2015-12-09 22:04 - 00108682 _____ C:\TDSSKiller.3.1.0.7_09.12.2015_22.03.22_log.txt
2015-12-09 21:54 - 2015-12-09 22:36 - 00000000 ____D C:\ProgramData\RogueKiller
2015-12-09 21:54 - 2015-12-09 21:54 - 00036608 _____ C:\WINDOWS\system32\Drivers\TrueSight.sys
2015-12-09 21:54 - 2015-12-09 21:54 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RogueKiller
2015-12-09 21:54 - 2015-12-09 21:54 - 00000000 ____D C:\Program Files\RogueKiller
2015-12-09 21:43 - 2015-12-14 18:50 - 00000000 ____D C:\Users\Michael\AppData\Roaming\ZHP
2015-12-09 21:43 - 2015-12-09 21:43 - 00079064 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\orye.sys
2015-12-09 21:42 - 2015-12-09 21:52 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2015-12-09 11:55 - 2015-12-11 03:48 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2015-12-09 11:35 - 2015-12-09 11:48 - 00002469 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat DC.lnk
2015-12-09 11:35 - 2015-12-09 11:46 - 00002114 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat Distiller DC.lnk
2015-12-09 11:30 - 2015-12-16 18:00 - 00000548 _____ C:\WINDOWS\Tasks\Adobe Acrobat Pro DC Update.job
2015-12-09 11:30 - 2015-12-09 11:30 - 00003448 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Pro DC Update
2015-12-09 11:30 - 2015-12-09 11:30 - 00000000 ____D C:\Users\Michael\AppData\Roaming\Adobe Acrobat Pro DC
2015-12-08 22:00 - 2015-12-01 01:12 - 02152800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
2015-12-08 22:00 - 2015-11-24 06:07 - 01817160 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2015-12-08 22:00 - 2015-11-24 05:07 - 03671896 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2015-12-08 22:00 - 2015-11-24 05:06 - 01540768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2015-12-08 22:00 - 2015-11-24 04:26 - 01399224 _____ (Microsoft Corporation) C:\WINDOWS\system32\user32.dll
2015-12-08 22:00 - 2015-11-24 04:03 - 02918808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2015-12-08 22:00 - 2015-11-24 04:01 - 02756096 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb
2015-12-08 22:00 - 2015-11-24 03:54 - 00007680 _____ (Microsoft Corporation) C:\WINDOWS\system32\readingviewresources.dll
2015-12-08 22:00 - 2015-11-24 03:53 - 00115200 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2015-12-08 22:00 - 2015-11-24 03:45 - 00018944 _____ (Microsoft Corporation) C:\WINDOWS\system32\wshrm.dll
2015-12-08 22:00 - 2015-11-24 03:37 - 00147968 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rmcast.sys
2015-12-08 22:00 - 2015-11-24 03:26 - 01337240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll
2015-12-08 22:00 - 2015-11-24 03:19 - 00182784 _____ (Microsoft Corporation) C:\WINDOWS\system32\shutdownux.dll
2015-12-08 22:00 - 2015-11-24 03:12 - 00523776 _____ (Microsoft Corporation) C:\WINDOWS\system32\catsrvut.dll
2015-12-08 22:00 - 2015-11-24 02:58 - 00604672 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2015-12-08 22:00 - 2015-11-24 02:55 - 01393664 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2015-12-08 22:00 - 2015-11-24 02:54 - 02756096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb
2015-12-08 22:00 - 2015-11-24 02:52 - 01717248 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll
2015-12-08 22:00 - 2015-11-24 02:49 - 01648640 _____ (Microsoft Corporation) C:\WINDOWS\system32\comsvcs.dll
2015-12-08 22:00 - 2015-11-24 02:27 - 03593216 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2015-12-08 22:00 - 2015-11-24 02:14 - 00415744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\catsrvut.dll
2015-12-08 22:00 - 2015-11-24 02:03 - 00503296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2015-12-08 22:00 - 2015-11-24 01:59 - 01467392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GdiPlus.dll
2015-12-08 22:00 - 2015-11-24 01:57 - 01328128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comsvcs.dll
2015-12-08 22:00 - 2015-11-24 01:35 - 22393856 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2015-12-08 22:00 - 2015-11-24 01:29 - 02352128 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll
2015-12-08 22:00 - 2015-11-24 01:25 - 24601600 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2015-12-08 22:00 - 2015-11-24 01:23 - 13381120 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2015-12-08 22:00 - 2015-11-24 01:11 - 18678272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2015-12-08 22:00 - 2015-11-24 01:09 - 19338240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2015-12-08 22:00 - 2015-11-24 01:08 - 12125184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2015-12-08 22:00 - 2015-11-24 01:04 - 02155008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll
2015-12-08 21:03 - 2015-12-08 21:03 - 00000000 ____D C:\Program Files (x86)\Acrobat
2015-12-08 17:10 - 2015-12-08 17:10 - 00001116 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 11.lnk
2015-12-08 13:44 - 2015-12-08 13:44 - 00000000 ____D C:\Program Files (x86)\AMD
2015-12-08 13:43 - 2015-11-29 14:20 - 00223744 _____ C:\WINDOWS\system32\dgtrayicon.exe
2015-12-08 13:43 - 2015-09-29 20:11 - 00674816 _____ (AMD) C:\WINDOWS\system32\atieclxx.exe
2015-12-08 13:43 - 2015-09-29 20:10 - 00246784 _____ (AMD) C:\WINDOWS\system32\atiesrxx.exe
2015-12-08 13:43 - 2015-09-29 19:47 - 01247744 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\atiadlxx.dll
2015-12-08 13:43 - 2014-09-03 06:55 - 00004096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\detoured.dll
2015-12-08 13:43 - 2014-09-03 06:55 - 00004096 _____ (Microsoft Corporation) C:\WINDOWS\system32\detoured.dll
2015-12-08 13:43 - 2013-04-10 09:34 - 00332800 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\ATIODE.exe
2015-12-08 13:43 - 2013-04-10 09:34 - 00051200 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\ATIODCLI.exe
2015-12-02 17:44 - 2015-11-22 04:47 - 07476576 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2015-12-02 17:44 - 2015-11-22 04:47 - 02653816 _____ C:\WINDOWS\system32\CoreUIComponents.dll
2015-12-02 17:44 - 2015-11-22 04:41 - 01859448 _____ C:\WINDOWS\SysWOW64\CoreUIComponents.dll
2015-12-02 17:44 - 2015-11-22 04:41 - 01284960 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll
2015-12-02 17:44 - 2015-11-22 04:41 - 00026408 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2015-12-02 17:44 - 2015-11-22 04:35 - 00538632 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWanAPI.dll
2015-12-02 17:44 - 2015-11-22 04:34 - 00975200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll
2015-12-02 17:44 - 2015-11-22 04:34 - 00080600 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwapi.dll
2015-12-02 17:44 - 2015-11-22 04:33 - 00095072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdstor.sys
2015-12-02 17:44 - 2015-11-22 04:33 - 00058408 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsNativeApi.dll
2015-12-02 17:44 - 2015-11-22 04:33 - 00051680 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsUtilsV2.dll
2015-12-02 17:44 - 2015-11-22 04:30 - 00604928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2015-12-02 17:44 - 2015-11-22 04:30 - 00161632 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
2015-12-02 17:44 - 2015-11-22 04:26 - 00431232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWanAPI.dll
2015-12-02 17:44 - 2015-11-22 04:25 - 00063528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wwapi.dll
2015-12-02 17:44 - 2015-11-22 04:24 - 02772584 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11.dll
2015-12-02 17:44 - 2015-11-22 04:20 - 00795840 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2015-12-02 17:44 - 2015-11-22 04:19 - 00440160 _____ (Microsoft Corporation) C:\WINDOWS\system32\services.exe
2015-12-02 17:44 - 2015-11-22 04:14 - 02185840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11.dll
2015-12-02 17:44 - 2015-11-22 04:00 - 00089088 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsCSP.dll
2015-12-02 17:44 - 2015-11-22 04:00 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosResource.dll
2015-12-02 17:44 - 2015-11-22 03:57 - 00110592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft-Windows-MapControls.dll
2015-12-02 17:44 - 2015-11-22 03:57 - 00036352 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCoreRes.dll
2015-12-02 17:44 - 2015-11-22 03:57 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft-Windows-MosTrace.dll
2015-12-02 17:44 - 2015-11-22 03:57 - 00009728 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft-Windows-MosHost.dll
2015-12-02 17:44 - 2015-11-22 03:56 - 01268736 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.dll
2015-12-02 17:44 - 2015-11-22 03:56 - 00064000 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosHostClient.dll
2015-12-02 17:44 - 2015-11-22 03:56 - 00064000 _____ (Microsoft Corporation) C:\WINDOWS\system32\ihvrilproxy.dll
2015-12-02 17:44 - 2015-11-22 03:56 - 00055808 _____ (Microsoft Corporation) C:\WINDOWS\system32\rilproxy.dll
2015-12-02 17:44 - 2015-11-22 03:55 - 00070656 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblAuthManagerProxy.dll
2015-12-02 17:44 - 2015-11-22 03:55 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsBtSvcProxy.dll
2015-12-02 17:44 - 2015-11-22 03:54 - 00138240 _____ (Microsoft Corporation) C:\WINDOWS\system32\ETWCoreUIComponentsResources.dll
2015-12-02 17:44 - 2015-11-22 03:54 - 00117248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\capimg.sys
2015-12-02 17:44 - 2015-11-22 03:54 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsNativeApi.V2.dll
2015-12-02 17:44 - 2015-11-22 03:54 - 00075264 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanprotdim.dll
2015-12-02 17:44 - 2015-11-22 03:54 - 00044032 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsplib.dll
2015-12-02 17:44 - 2015-11-22 03:54 - 00032256 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups2.dll
2015-12-02 17:44 - 2015-11-22 03:54 - 00028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\WordBreakers.dll
2015-12-02 17:44 - 2015-11-22 03:54 - 00028160 _____ (Microsoft Corporation) C:\WINDOWS\system32\nativemap.dll
2015-12-02 17:44 - 2015-11-22 03:54 - 00003072 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlStringsRes.dll
2015-12-02 17:44 - 2015-11-22 03:52 - 16984576 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2015-12-02 17:44 - 2015-11-22 03:52 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininetlui.dll
2015-12-02 17:44 - 2015-11-22 03:52 - 00060928 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblAuthTokenBrokerExt.dll
2015-12-02 17:44 - 2015-11-22 03:52 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll
2015-12-02 17:44 - 2015-11-22 03:52 - 00028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\mapsupdatetask.dll
2015-12-02 17:44 - 2015-11-22 03:51 - 00157184 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcertinst.exe
2015-12-02 17:44 - 2015-11-22 03:51 - 00119808 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsBtSvc.dll
2015-12-02 17:44 - 2015-11-22 03:51 - 00072704 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosStorage.dll
2015-12-02 17:44 - 2015-11-22 03:51 - 00042496 _____ (Microsoft Corporation) C:\WINDOWS\system32\mapstoasttask.dll
2015-12-02 17:44 - 2015-11-22 03:51 - 00034304 _____ (Microsoft Corporation) C:\WINDOWS\system32\iernonce.dll
2015-12-02 17:44 - 2015-11-22 03:50 - 00074240 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssign32.dll
2015-12-02 17:44 - 2015-11-22 03:49 - 00162304 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCensus.exe
2015-12-02 17:44 - 2015-11-22 03:49 - 00066560 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshost.dll
2015-12-02 17:44 - 2015-11-22 03:49 - 00066560 _____ (Microsoft Corporation) C:\WINDOWS\system32\iesetup.dll
2015-12-02 17:44 - 2015-11-22 03:49 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\Wwanpref.dll
2015-12-02 17:44 - 2015-11-22 03:48 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosResource.dll
2015-12-02 17:44 - 2015-11-22 03:47 - 00269824 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshostcore.dll
2015-12-02 17:44 - 2015-11-22 03:46 - 00248832 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserMgrProxy.dll
2015-12-02 17:44 - 2015-11-22 03:46 - 00209920 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmcsp.dll
2015-12-02 17:44 - 2015-11-22 03:45 - 06572032 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanmm.dll
2015-12-02 17:44 - 2015-11-22 03:45 - 00638464 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
2015-12-02 17:44 - 2015-11-22 03:45 - 00264192 _____ (Nokia) C:\WINDOWS\system32\NmaDirect.dll
2015-12-02 17:44 - 2015-11-22 03:45 - 00220672 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2015-12-02 17:44 - 2015-11-22 03:45 - 00110592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Microsoft-Windows-MapControls.dll
2015-12-02 17:44 - 2015-11-22 03:45 - 00073728 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwancfg.dll
2015-12-02 17:44 - 2015-11-22 03:45 - 00036352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCoreRes.dll
2015-12-02 17:44 - 2015-11-22 03:45 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Microsoft-Windows-MosTrace.dll
2015-12-02 17:44 - 2015-11-22 03:45 - 00009728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Microsoft-Windows-MosHost.dll
2015-12-02 17:44 - 2015-11-22 03:44 - 01268736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Resources.dll
2015-12-02 17:44 - 2015-11-22 03:44 - 00558080 _____ (Microsoft Corporation) C:\WINDOWS\system32\MBMediaManager.dll
2015-12-02 17:44 - 2015-11-22 03:44 - 00048640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosHostClient.dll
2015-12-02 17:44 - 2015-11-22 03:43 - 00704000 _____ (Microsoft Corporation) C:\WINDOWS\system32\CellularAPI.dll
2015-12-02 17:44 - 2015-11-22 03:43 - 00459776 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapConfiguration.dll
2015-12-02 17:44 - 2015-11-22 03:43 - 00382464 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2015-12-02 17:44 - 2015-11-22 03:43 - 00342016 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorService.dll
2015-12-02 17:44 - 2015-11-22 03:43 - 00041984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XblAuthManagerProxy.dll
2015-12-02 17:44 - 2015-11-22 03:42 - 13017600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2015-12-02 17:44 - 2015-11-22 03:42 - 07979008 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll
2015-12-02 17:44 - 2015-11-22 03:42 - 00589312 _____ (Microsoft Corporation) C:\WINDOWS\system32\MbaeApi.dll
2015-12-02 17:44 - 2015-11-22 03:42 - 00168960 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmmigrator.dll
2015-12-02 17:44 - 2015-11-22 03:42 - 00138240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ETWCoreUIComponentsResources.dll
2015-12-02 17:44 - 2015-11-22 03:42 - 00024064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WordBreakers.dll
2015-12-02 17:44 - 2015-11-22 03:42 - 00003072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapControlStringsRes.dll
2015-12-02 17:44 - 2015-11-22 03:41 - 01814528 _____ (Microsoft Corporation) C:\WINDOWS\system32\pnidui.dll
2015-12-02 17:44 - 2015-11-22 03:41 - 00948224 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblAuthManager.dll
2015-12-02 17:44 - 2015-11-22 03:41 - 00607232 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmsvc.dll
2015-12-02 17:44 - 2015-11-22 03:40 - 01056256 _____ (Microsoft Corporation) C:\WINDOWS\system32\JpMapControl.dll
2015-12-02 17:44 - 2015-11-22 03:40 - 00850432 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll
2015-12-02 17:44 - 2015-11-22 03:40 - 00465920 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanconn.dll
2015-12-02 17:44 - 2015-11-22 03:40 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininetlui.dll
2015-12-02 17:44 - 2015-11-22 03:40 - 00049152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XblAuthTokenBrokerExt.dll
2015-12-02 17:44 - 2015-11-22 03:39 - 02126848 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2015-12-02 17:44 - 2015-11-22 03:39 - 01713664 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRHInproc.dll
2015-12-02 17:44 - 2015-11-22 03:39 - 00988160 _____ (Microsoft Corporation) C:\WINDOWS\system32\NMAA.dll
2015-12-02 17:44 - 2015-11-22 03:39 - 00957440 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll
2015-12-02 17:44 - 2015-11-22 03:39 - 00938496 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlCore.dll
2015-12-02 17:44 - 2015-11-22 03:39 - 00870400 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll
2015-12-02 17:44 - 2015-11-22 03:39 - 00783360 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2015-12-02 17:44 - 2015-11-22 03:39 - 00114688 _____ (Microsoft Corporation) C:\WINDOWS\system32\offlinelsa.dll
2015-12-02 17:44 - 2015-11-22 03:39 - 00086528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapsBtSvc.dll
2015-12-02 17:44 - 2015-11-22 03:39 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosStorage.dll
2015-12-02 17:44 - 2015-11-22 03:39 - 00045568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jsproxy.dll
2015-12-02 17:44 - 2015-11-22 03:38 - 01223168 _____ (Microsoft Corporation) C:\WINDOWS\system32\Unistore.dll
2015-12-02 17:44 - 2015-11-22 03:38 - 01212928 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
2015-12-02 17:44 - 2015-11-22 03:38 - 00912384 _____ (Microsoft Corporation) C:\WINDOWS\system32\usermgr.dll
2015-12-02 17:44 - 2015-11-22 03:38 - 00320000 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptngc.dll
2015-12-02 17:44 - 2015-11-22 03:38 - 00060928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssign32.dll
2015-12-02 17:44 - 2015-11-22 03:37 - 02624512 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll
2015-12-02 17:44 - 2015-11-22 03:37 - 01395200 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll
2015-12-02 17:44 - 2015-11-22 03:37 - 00515584 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll
2015-12-02 17:44 - 2015-11-22 03:36 - 01042432 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingOnlineServices.dll
2015-12-02 17:44 - 2015-11-22 03:34 - 02843136 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdp.dll
2015-12-02 17:44 - 2015-11-22 03:34 - 00345600 _____ (Microsoft Corporation) C:\WINDOWS\system32\TextInputFramework.dll
2015-12-02 17:44 - 2015-11-22 03:34 - 00175616 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll
2015-12-02 17:44 - 2015-11-22 03:34 - 00166912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserMgrProxy.dll
2015-12-02 17:44 - 2015-11-22 03:34 - 00108544 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputLocaleManager.dll
2015-12-02 17:44 - 2015-11-22 03:34 - 00075264 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditBufferTestHook.dll
2015-12-02 17:44 - 2015-11-22 03:33 - 02587136 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
2015-12-02 17:44 - 2015-11-22 03:33 - 00205824 _____ (Nokia) C:\WINDOWS\SysWOW64\NmaDirect.dll
2015-12-02 17:44 - 2015-11-22 03:32 - 00346112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapConfiguration.dll
2015-12-02 17:44 - 2015-11-22 03:32 - 00340480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToDevice.dll
2015-12-02 17:44 - 2015-11-22 03:32 - 00334848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2015-12-02 17:44 - 2015-11-22 03:31 - 07199232 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll
2015-12-02 17:44 - 2015-11-22 03:31 - 00470528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MbaeApi.dll
2015-12-02 17:44 - 2015-11-22 03:31 - 00416768 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenrollengine.dll
2015-12-02 17:44 - 2015-11-22 03:30 - 02598400 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll
2015-12-02 17:44 - 2015-11-22 03:29 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\JpMapControl.dll
2015-12-02 17:44 - 2015-11-22 03:28 - 01734656 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2015-12-02 17:44 - 2015-11-22 03:28 - 01443328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRHInproc.dll
2015-12-02 17:44 - 2015-11-22 03:28 - 01387008 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2015-12-02 17:44 - 2015-11-22 03:28 - 00948224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Unistore.dll
2015-12-02 17:44 - 2015-11-22 03:28 - 00870400 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll
2015-12-02 17:44 - 2015-11-22 03:28 - 00793600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRH.dll
2015-12-02 17:44 - 2015-11-22 03:28 - 00784896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NMAA.dll
2015-12-02 17:44 - 2015-11-22 03:28 - 00686592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2015-12-02 17:44 - 2015-11-22 03:28 - 00100864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\offlinelsa.dll
2015-12-02 17:44 - 2015-11-22 03:27 - 03993600 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2015-12-02 17:44 - 2015-11-22 03:27 - 02049024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2015-12-02 17:44 - 2015-11-22 03:27 - 01944576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputService.dll
2015-12-02 17:44 - 2015-11-22 03:27 - 00711680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapControlCore.dll
2015-12-02 17:44 - 2015-11-22 03:27 - 00241664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cryptngc.dll
2015-12-02 17:44 - 2015-11-22 03:27 - 00160768 _____ (Microsoft Corporation) C:\WINDOWS\system32\enrollmentapi.dll
2015-12-02 17:44 - 2015-11-22 03:26 - 03355136 _____ (Microsoft Corporation) C:\WINDOWS\system32\msftedit.dll
2015-12-02 17:44 - 2015-11-22 03:26 - 01139200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll
2015-12-02 17:44 - 2015-11-22 03:26 - 00709120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingOnlineServices.dll
2015-12-02 17:44 - 2015-11-22 03:26 - 00421888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LogonController.dll
2015-12-02 17:44 - 2015-11-22 03:25 - 06297088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mos.dll
2015-12-02 17:44 - 2015-11-22 03:25 - 02280448 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2015-12-02 17:44 - 2015-11-22 03:25 - 00133632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Core.TextInput.dll
2015-12-02 17:44 - 2015-11-22 03:24 - 02647552 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2015-12-02 17:44 - 2015-11-22 03:24 - 01995264 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActiveSyncProvider.dll
2015-12-02 17:44 - 2015-11-22 03:24 - 00245760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TextInputFramework.dll
2015-12-02 17:44 - 2015-11-22 03:24 - 00083456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputLocaleManager.dll
2015-12-02 17:44 - 2015-11-22 03:24 - 00059904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EditBufferTestHook.dll
2015-12-02 17:44 - 2015-11-22 03:23 - 05202944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll
2015-12-02 17:44 - 2015-11-22 03:20 - 01860096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cdp.dll
2015-12-02 17:44 - 2015-11-22 03:19 - 02064384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
2015-12-02 17:44 - 2015-11-22 03:18 - 01505280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2015-12-02 17:44 - 2015-11-22 03:18 - 00697856 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToManager.dll
2015-12-02 17:44 - 2015-11-22 03:18 - 00458752 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToDevice.dll
2015-12-02 17:44 - 2015-11-22 03:17 - 02680320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msftedit.dll
2015-12-02 17:44 - 2015-11-22 03:17 - 02121216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2015-12-02 17:44 - 2015-11-22 03:16 - 01706496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActiveSyncProvider.dll
2015-12-02 17:44 - 2015-11-22 03:11 - 00517632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToManager.dll
2015-11-29 15:35 - 2015-11-29 15:35 - 02420736 _____ C:\WINDOWS\system32\amdacpusl.pdb
2015-11-29 15:33 - 2015-11-29 15:33 - 00364544 _____ (Advanced Micro Devices) C:\WINDOWS\system32\amdacpusl.dll
2015-11-29 15:33 - 2015-11-29 15:33 - 00306176 _____ C:\WINDOWS\system32\amdacpusl.pdb.pub
2015-11-29 15:33 - 2015-11-29 15:33 - 00248832 _____ (Advanced Micro Devices) C:\WINDOWS\SysWOW64\amdacpusl.dll
2015-11-25 13:44 - 2015-11-21 00:21 - 00809312 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe
2015-11-25 13:44 - 2015-11-21 00:02 - 00704352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe
2015-11-25 13:44 - 2015-11-20 23:44 - 00204800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft-Windows-AppModelExecEvents.dll
2015-11-25 13:44 - 2015-11-20 23:29 - 00286720 _____ (Microsoft Corporation) C:\WINDOWS\system32\deviceaccess.dll
2015-11-25 13:44 - 2015-11-20 23:07 - 00227840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\deviceaccess.dll
2015-11-24 21:42 - 2015-11-24 21:42 - 00001024 _____ C:\.rnd
2015-11-24 21:42 - 2015-11-24 21:42 - 00000000 ____D C:\ProgramData\Paessler
2015-11-24 21:42 - 2015-11-24 21:42 - 00000000 ____D C:\Program Files\WinPcap
2015-11-24 21:41 - 2015-11-26 11:01 - 00000000 ____D C:\Program Files (x86)\PRTG Network Monitor
2015-11-24 14:51 - 2015-11-24 14:51 - 00000000 ____D C:\ProgramData\ATI
2015-11-24 14:23 - 2015-11-24 14:23 - 00001247 _____ C:\Users\Michael\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CNext.lnk
2015-11-24 14:17 - 2015-12-08 13:44 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Settings
2015-11-24 14:17 - 2015-11-24 14:17 - 00004296 _____ C:\WINDOWS\System32\Tasks\AMD Updater
2015-11-24 01:33 - 2015-11-29 14:32 - 00865280 _____ (AMD) C:\WINDOWS\system32\coinst_15.30.dll
2015-11-23 22:43 - 2015-11-23 22:43 - 00323588 _____ C:\WINDOWS\system32\ativvaxy_el.dat
2015-11-23 22:43 - 2015-11-23 22:43 - 00320992 _____ C:\WINDOWS\system32\ativvaxy_el_nd.dat
2015-11-23 22:43 - 2015-11-23 22:43 - 00261920 _____ C:\WINDOWS\system32\ativvaxy_stn_nd.dat
2015-11-23 22:41 - 2015-11-23 22:41 - 00166560 _____ C:\WINDOWS\system32\amde34a.dat
2015-11-23 22:41 - 2015-11-23 22:41 - 00007112 _____ C:\WINDOWS\system32\AMDKernelEvents.man
2015-11-23 18:09 - 2015-11-23 18:09 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Plex Media Server
2015-11-21 10:08 - 2015-11-21 10:08 - 00129033 _____ C:\Users\Michael\Desktop\SessionI-SubjectMatter-102515.pdf
2015-11-18 21:17 - 2015-09-30 00:22 - 10114240 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atidxx32.dll
2015-11-18 21:17 - 2015-09-30 00:22 - 00133016 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atiuxpag.dll
2015-11-18 18:37 - 2015-11-18 18:38 - 00000000 ____D C:\Users\Michael\AppData\Local\Yandex
2015-11-18 18:37 - 2015-11-18 18:37 - 00000000 ____D C:\Users\Michael\AppData\LocalLow\Yandex
2015-11-18 18:36 - 2015-11-18 18:39 - 00000000 ____D C:\Users\Michael\AppData\Roaming\DriverPack Easy Search
2015-11-18 18:36 - 2015-11-18 18:39 - 00000000 ____D C:\Program Files (x86)\DriverPack Notifier
2015-11-18 18:36 - 2015-11-18 18:38 - 00000000 ____D C:\Users\Michael\AppData\Roaming\Yandex
2015-11-18 18:36 - 2015-11-18 18:38 - 00000000 ____D C:\Users\Michael\AppData\Roaming\Opera Software
2015-11-18 18:36 - 2015-11-18 18:38 - 00000000 ____D C:\Users\Michael\AppData\Local\Opera Software
2015-11-18 18:36 - 2015-11-18 18:38 - 00000000 ____D C:\Program Files (x86)\Opera
2015-11-18 18:36 - 2015-11-18 18:36 - 00000000 ____D C:\Users\Michael\AppData\Roaming\DriverPack Notifier
2015-11-18 18:36 - 2015-11-18 18:36 - 00000000 ____D C:\Users\Michael\AppData\Local\Xpom
2015-11-18 18:36 - 2015-11-18 18:36 - 00000000 ____D C:\Users\Michael\AppData\Local\Nichrome
2015-11-18 18:36 - 2015-11-18 18:36 - 00000000 ____D C:\Users\Michael\AppData\Local\Chromium
2015-11-18 18:35 - 2015-05-29 17:05 - 00646408 _____ (Intel Corporation) C:\WINDOWS\system32\Drivers\iaStorA.sys
2015-11-18 18:35 - 2015-05-06 00:56 - 00334984 _____ (Marvell Semiconductor, Inc.) C:\WINDOWS\system32\Drivers\mvs91xx.sys
2015-11-18 18:35 - 2015-05-06 00:56 - 00015496 _____ (Marvell Semiconductor Inc.) C:\WINDOWS\system32\Drivers\mvxxmm.sys
2015-11-18 18:35 - 2015-04-14 04:49 - 00036352 _____ (<Marvell>) C:\WINDOWS\system32\mv91xxm.dll
2015-11-18 18:34 - 2015-11-18 18:36 - 00000000 ____D C:\Users\Michael\AppData\Roaming\DRPSu
2015-11-18 16:56 - 2015-11-13 00:43 - 02544264 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2015-11-18 16:56 - 2015-11-13 00:43 - 00586208 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll
2015-11-18 16:56 - 2015-11-13 00:41 - 22572632 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2015-11-18 16:56 - 2015-11-13 00:33 - 00911648 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcomp.dll
2015-11-18 16:56 - 2015-11-13 00:21 - 02179584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2015-11-18 16:56 - 2015-11-13 00:21 - 00511320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf.dll
2015-11-18 16:56 - 2015-11-13 00:18 - 21125408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2015-11-18 16:56 - 2015-11-12 23:58 - 11545088 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2015-11-18 16:56 - 2015-11-12 23:39 - 02444288 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll
2015-11-18 16:56 - 2015-11-12 23:29 - 09918976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2015-11-18 16:56 - 2015-11-12 23:19 - 02001408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.appcore.dll
2015-11-18 16:55 - 2015-11-13 00:55 - 00035680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wimmount.sys
2015-11-18 16:55 - 2015-11-13 00:51 - 00698208 _____ (Microsoft Corporation) C:\WINDOWS\system32\wimgapi.dll
2015-11-18 16:55 - 2015-11-13 00:51 - 00523616 _____ (Microsoft Corporation) C:\WINDOWS\system32\wimserv.exe
2015-11-18 16:55 - 2015-11-13 00:51 - 00334736 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanager.dll
2015-11-18 16:55 - 2015-11-13 00:43 - 00536768 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2015-11-18 16:55 - 2015-11-13 00:43 - 00369912 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
2015-11-18 16:55 - 2015-11-13 00:43 - 00245848 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
2015-11-18 16:55 - 2015-11-13 00:43 - 00110032 _____ (Microsoft Corporation) C:\WINDOWS\system32\EncDump.dll
2015-11-18 16:55 - 2015-11-13 00:43 - 00035656 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfpmp.exe
2015-11-18 16:55 - 2015-11-13 00:42 - 00516544 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
2015-11-18 16:55 - 2015-11-13 00:42 - 00408128 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll
2015-11-18 16:55 - 2015-11-13 00:42 - 00088392 _____ (Microsoft Corporation) C:\WINDOWS\system32\remoteaudioendpoint.dll
2015-11-18 16:55 - 2015-11-13 00:33 - 00586080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wimgapi.dll
2015-11-18 16:55 - 2015-11-13 00:33 - 00092352 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2015-11-18 16:55 - 2015-11-13 00:32 - 00296488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\policymanager.dll
2015-11-18 16:55 - 2015-11-13 00:21 - 00454056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioEng.dll
2015-11-18 16:55 - 2015-11-13 00:21 - 00405048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
2015-11-18 16:55 - 2015-11-13 00:21 - 00366224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AUDIOKSE.dll
2015-11-18 16:55 - 2015-11-13 00:21 - 00116728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfps.dll
2015-11-18 16:55 - 2015-11-13 00:21 - 00073360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\remoteaudioendpoint.dll
2015-11-18 16:55 - 2015-11-13 00:21 - 00032040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfpmp.exe
2015-11-18 16:55 - 2015-11-13 00:09 - 00675064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dcomp.dll
2015-11-18 16:55 - 2015-11-13 00:07 - 00028160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Management.Provisioning.ProxyStub.dll
2015-11-18 16:55 - 2015-11-13 00:06 - 00052736 _____ (Microsoft Corporation) C:\WINDOWS\system32\RemovableMediaProvisioningPlugin.dll
2015-11-18 16:55 - 2015-11-13 00:05 - 00122368 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCsp.dll
2015-11-18 16:55 - 2015-11-13 00:05 - 00078336 _____ (Microsoft Corporation) C:\WINDOWS\system32\BarcodeProvisioningPlugin.dll
2015-11-18 16:55 - 2015-11-13 00:05 - 00043520 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.proxy.dll
2015-11-18 16:55 - 2015-11-13 00:05 - 00030720 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringconfigsp.dll
2015-11-18 16:55 - 2015-11-13 00:04 - 00089600 _____ (Microsoft Corporation) C:\WINDOWS\system32\NFCProvisioningPlugin.dll
2015-11-18 16:55 - 2015-11-13 00:04 - 00037376 _____ (Microsoft Corporation) C:\WINDOWS\system32\LaunchWinApp.exe
2015-11-18 16:55 - 2015-11-13 00:04 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\IcsEntitlementHost.exe
2015-11-18 16:55 - 2015-11-13 00:03 - 00077312 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProvPluginEng.dll
2015-11-18 16:55 - 2015-11-13 00:03 - 00052736 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringclient.dll
2015-11-18 16:55 - 2015-11-13 00:02 - 00231936 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCore.dll
2015-11-18 16:55 - 2015-11-13 00:02 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe
2015-11-18 16:55 - 2015-11-13 00:01 - 00192000 _____ (Microsoft Corporation) C:\WINDOWS\system32\provisioningcsp.dll
2015-11-18 16:55 - 2015-11-13 00:00 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzautoupdate.dll
2015-11-18 16:55 - 2015-11-13 00:00 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\system32\provtool.exe
2015-11-18 16:55 - 2015-11-12 23:59 - 00086528 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppCapture.dll
2015-11-18 16:55 - 2015-11-12 23:58 - 00162304 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringservice.dll
2015-11-18 16:55 - 2015-11-12 23:57 - 00623616 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneProviders.dll
2015-11-18 16:55 - 2015-11-12 23:57 - 00543232 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll
2015-11-18 16:55 - 2015-11-12 23:56 - 00292352 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll
2015-11-18 16:55 - 2015-11-12 23:56 - 00286208 _____ (Microsoft Corporation) C:\WINDOWS\system32\provhandlers.dll
2015-11-18 16:55 - 2015-11-12 23:56 - 00163328 _____ (Microsoft Corporation) C:\WINDOWS\system32\provops.dll
2015-11-18 16:55 - 2015-11-12 23:55 - 00450560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Bluetooth.dll
2015-11-18 16:55 - 2015-11-12 23:55 - 00165376 _____ (Microsoft Corporation) C:\WINDOWS\system32\provdatastore.dll
2015-11-18 16:55 - 2015-11-12 23:54 - 00275456 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2015-11-18 16:55 - 2015-11-12 23:53 - 00517632 _____ (Microsoft Corporation) C:\WINDOWS\system32\winspool.drv
2015-11-18 16:55 - 2015-11-12 23:53 - 00497664 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmkvsrcsnk.dll
2015-11-18 16:55 - 2015-11-12 23:50 - 01063424 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2015-11-18 16:55 - 2015-11-12 23:49 - 00674816 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.dll
2015-11-18 16:55 - 2015-11-12 23:40 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LaunchWinApp.exe
2015-11-18 16:55 - 2015-11-12 23:40 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcastdvr.proxy.dll
2015-11-18 16:55 - 2015-11-12 23:37 - 00160768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgent.exe
2015-11-18 16:55 - 2015-11-12 23:34 - 00070656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppCapture.dll
2015-11-18 16:55 - 2015-11-12 23:33 - 00414720 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.exe
2015-11-18 16:55 - 2015-11-12 23:32 - 00409088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StoreAgent.dll
2015-11-18 16:55 - 2015-11-12 23:30 - 00334336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcastdvr.exe
2015-11-18 16:55 - 2015-11-12 23:30 - 00315904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Bluetooth.dll
2015-11-18 16:55 - 2015-11-12 23:28 - 00382464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmkvsrcsnk.dll
2015-11-18 16:55 - 2015-11-12 23:27 - 00400896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winspool.drv
2015-11-18 16:55 - 2015-11-12 23:23 - 00490496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.dll
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-12-17 12:31 - 2015-10-30 00:28 - 00000000 ____D C:\Windows
2015-12-17 12:26 - 2015-02-25 16:43 - 00000000 ____D C:\Users\Michael\AppData\Roaming\BitTorrent Sync
2015-12-17 12:16 - 2015-09-14 22:14 - 00000932 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job
2015-12-17 12:12 - 2015-08-28 15:42 - 00000830 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-12-17 11:56 - 2015-02-24 11:44 - 00000000 ____D C:\ProgramData\BOINC
2015-12-17 11:45 - 2015-08-06 20:25 - 00000938 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2172870717-1373750500-4216110194-1001UA.job
2015-12-17 11:40 - 2015-06-25 11:15 - 00000928 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2015-12-17 10:16 - 2015-09-14 22:14 - 00000928 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskMachineCore.job
2015-12-17 09:50 - 2015-02-24 11:38 - 00004162 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{43EB6EA7-BF27-4F04-88FB-A68B608738CB}
2015-12-17 05:26 - 2015-06-22 14:47 - 00879220 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2015-12-17 05:25 - 2015-10-30 01:21 - 00000000 ____D C:\WINDOWS\INF
2015-12-17 03:45 - 2015-08-06 20:25 - 00000886 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-2172870717-1373750500-4216110194-1001Core.job
2015-12-17 02:40 - 2015-06-25 11:15 - 00000924 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2015-12-16 22:25 - 2015-10-30 01:24 - 00000000 ____D C:\WINDOWS\AppReadiness
2015-12-16 18:41 - 2015-10-30 01:24 - 00000000 ___HD C:\Program Files\WindowsApps
2015-12-15 19:55 - 2015-10-30 01:24 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2015-12-15 19:54 - 2015-02-24 18:36 - 00000000 ____D C:\Program Files (x86)\Microsoft Office
2015-12-15 18:39 - 2015-06-22 15:45 - 00000000 ____D C:\Users\Michael\AppData\Local\ActiveSync
2015-12-15 18:37 - 2015-11-06 17:56 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-12-15 18:37 - 2015-02-24 18:09 - 00000000 ____D C:\Program Files (x86)\SpeedFan
2015-12-15 18:37 - 2015-02-24 17:53 - 00000000 ____D C:\Users\Michael\AppData\Roaming\Dropbox
2015-12-15 18:37 - 2015-02-24 17:34 - 00000000 ____D C:\Program Files (x86)\TeamViewer
2015-12-15 16:08 - 2015-11-06 17:51 - 00065536 _____ C:\WINDOWS\system32\spu_storage.bin
2015-12-15 16:08 - 2015-03-13 22:13 - 00003136 _____ C:\WINDOWS\System32\Tasks\MSIAfterburner
2015-12-15 15:27 - 2015-07-03 13:35 - 00025640 _____ (Windows ® Server 2003 DDK provider) C:\WINDOWS\gdrv.sys
2015-12-15 14:57 - 2015-10-30 00:28 - 01310720 ___SH C:\WINDOWS\system32\config\BBI
2015-12-15 13:45 - 2015-02-24 17:52 - 00000000 ____D C:\Program Files (x86)\Steam
2015-12-15 13:25 - 2015-03-30 15:29 - 00000000 ____D C:\Program Files\PowerISO
2015-12-15 12:58 - 2015-02-25 17:04 - 00000000 ____D C:\Users\Michael\AppData\Roaming\deluge
2015-12-15 06:33 - 2015-02-24 17:40 - 00003498 _____ C:\WINDOWS\System32\Tasks\Apple Diagnostics
2015-12-14 17:57 - 2015-10-02 22:40 - 00000000 ____D C:\Users\nancy\AppData\Roaming\Apple Computer
2015-12-13 21:16 - 2015-10-02 22:42 - 00000000 ____D C:\Users\nancy\AppData\Local\ActiveSync
2015-12-13 12:00 - 2015-11-06 17:51 - 00000000 ____D C:\Users\Michael
2015-12-12 22:22 - 2015-06-22 15:37 - 00000000 ____D C:\Users\Michael\3D Objects
2015-12-12 05:00 - 2015-02-24 11:34 - 00000000 ____D C:\Users\Michael\AppData\Local\Packages
2015-12-11 23:23 - 2015-10-02 22:40 - 00000000 ____D C:\Users\nancy\AppData\Local\Google
2015-12-11 22:43 - 2015-10-02 22:40 - 00000000 ____D C:\Users\nancy\AppData\Local\Packages
2015-12-11 22:25 - 2015-10-02 22:40 - 00000000 ____D C:\Users\nancy\AppData\Local\PackageStaging
2015-12-11 22:20 - 2015-10-02 22:40 - 00000000 ____D C:\Users\nancy\AppData\Roaming\Adobe
2015-12-11 22:10 - 2015-10-02 22:40 - 00002378 _____ C:\Users\nancy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2015-12-11 22:10 - 2015-10-02 22:40 - 00000000 ___RD C:\Users\nancy\OneDrive
2015-12-11 22:09 - 2015-11-06 17:51 - 00000000 ____D C:\Users\nancy
2015-12-11 22:09 - 2015-10-02 22:40 - 00002336 _____ C:\Users\nancy\Desktop\Google Chrome.lnk
2015-12-11 22:09 - 2015-06-22 14:53 - 00000000 __RHD C:\Users\Public\AccountPictures
2015-12-11 19:49 - 2015-09-14 22:14 - 00000000 ____D C:\Program Files (x86)\Dropbox
2015-12-10 10:05 - 2015-10-26 15:47 - 00000000 ____D C:\Users\Michael\AppData\Local\D3308A52-78A1-47AD-8000-4AE771D4C732.aplzod
2015-12-10 10:05 - 2015-10-08 15:38 - 00000258 __RSH C:\ProgramData\ntuser.pol
2015-12-09 21:43 - 2015-10-30 01:24 - 00000000 ____D C:\WINDOWS\ModemLogs
2015-12-09 21:08 - 2015-08-28 15:40 - 00000000 ___HD C:\ProgramData\SsiRecord
2015-12-09 20:23 - 2015-11-09 07:49 - 00000000 ____D C:\Users\Michael\AppData\Local\Deployment
2015-12-09 20:23 - 2015-10-20 18:45 - 00000125 _____ C:\Users\Michael\Desktop\Remote Proctor Now.url
2015-12-09 20:23 - 2015-08-28 15:40 - 00004084 _____ C:\WINDOWS\System32\Tasks\goloader1
2015-12-09 20:23 - 2015-08-28 15:40 - 00000000 ____D C:\Users\Michael\Documents\SsiAuthenticate
2015-12-09 20:23 - 2015-08-28 15:40 - 00000000 ____D C:\ProgramData\SsiAuthenticate
2015-12-09 19:57 - 2015-11-06 17:50 - 00343360 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2015-12-09 19:57 - 2015-10-30 01:24 - 00000000 ____D C:\WINDOWS\system32\oobe
2015-12-09 14:16 - 2015-02-24 18:21 - 00000600 _____ C:\Users\Michael\AppData\Local\PUTTY.RND
2015-12-09 14:16 - 2015-02-24 18:19 - 00000000 ____D C:\Users\Michael\AppData\Roaming\FileZilla
2015-12-09 11:55 - 2015-10-13 12:29 - 00003972 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task
2015-12-09 11:55 - 2015-03-11 15:39 - 00000000 ____D C:\Users\Michael\AppData\Local\Adobe
2015-12-09 11:55 - 2015-03-08 10:14 - 00000000 ____D C:\Program Files (x86)\Adobe
2015-12-09 11:48 - 2015-03-21 13:12 - 00001543 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Application Manager.lnk
2015-12-09 11:42 - 2015-03-11 15:39 - 00000000 ____D C:\ProgramData\regid.1986-12.com.adobe
2015-12-09 11:34 - 2015-03-11 15:38 - 00000000 ____D C:\ProgramData\Adobe
2015-12-08 22:14 - 2015-10-30 01:11 - 00000000 ____D C:\WINDOWS\CbsTemp
2015-12-08 22:14 - 2015-02-26 05:37 - 00000000 ____D C:\WINDOWS\system32\MRT
2015-12-08 21:39 - 2015-02-25 19:00 - 00301728 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2015-12-08 21:26 - 2015-02-24 17:41 - 00000000 ____D C:\Users\Michael\AppData\Roaming\TeamViewer
2015-12-08 21:21 - 2015-06-12 17:04 - 00000000 ____D C:\ProgramData\Oracle
2015-12-08 21:21 - 2015-04-08 09:59 - 00000000 ____D C:\Users\Michael\AppData\Roaming\Spotify
2015-12-08 21:21 - 2015-04-08 09:59 - 00000000 ____D C:\Users\Michael\AppData\Local\Spotify
2015-12-08 21:20 - 2015-08-27 21:01 - 00000000 ____D C:\Users\Michael\.oracle_jre_usage
2015-12-08 21:20 - 2015-08-17 19:29 - 00000000 ____D C:\Program Files (x86)\Java
2015-12-08 21:20 - 2015-06-25 19:21 - 00110176 _____ (Oracle Corporation) C:\WINDOWS\system32\WindowsAccessBridge-64.dll
2015-12-08 21:20 - 2015-06-25 19:20 - 00000000 ____D C:\Program Files\Java
2015-12-08 21:20 - 2015-06-12 17:04 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2015-12-08 21:05 - 2015-11-06 19:49 - 00000000 ___DC C:\WINDOWS\Panther
2015-12-08 19:25 - 2015-05-28 18:45 - 00000000 ____D C:\Users\Michael\AppData\Roaming\HexChat
2015-12-08 13:44 - 2015-11-06 17:51 - 00000000 ____D C:\Program Files\AMD
2015-12-06 13:07 - 2015-04-14 12:22 - 00000000 ____D C:\Users\Michael\AppData\Roaming\Audacity
2015-12-04 03:40 - 2015-08-06 20:25 - 00004060 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2172870717-1373750500-4216110194-1001UA
2015-12-04 03:40 - 2015-08-06 20:25 - 00003684 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2172870717-1373750500-4216110194-1001Core
2015-12-04 02:35 - 2015-06-25 11:15 - 00003986 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2015-12-04 02:35 - 2015-06-25 11:15 - 00003754 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2015-12-03 19:15 - 2015-09-01 19:23 - 00000000 ____D C:\Users\Michael\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
2015-12-03 18:38 - 2015-10-30 01:24 - 00000000 ____D C:\WINDOWS\rescache
2015-12-02 18:16 - 2015-10-30 01:24 - 00000000 ___SD C:\WINDOWS\Downloaded Program Files
2015-12-02 17:46 - 2015-10-30 01:24 - 00000000 ____D C:\WINDOWS\system32\SystemResetPlatform
2015-11-30 18:33 - 2015-10-30 01:26 - 00826872 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2015-11-30 18:33 - 2015-10-30 01:26 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2015-11-28 19:17 - 2015-02-24 18:07 - 00000000 ____D C:\Users\Michael\AppData\Roaming\vlc
2015-11-26 11:01 - 2015-05-02 00:28 - 00000000 ____D C:\ProgramData\TEMP
2015-11-25 22:35 - 2015-07-01 09:30 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive
2015-11-24 14:17 - 2015-10-03 16:05 - 00000000 ____D C:\Users\Michael\AppData\Local\AMD
2015-11-24 14:15 - 2015-02-24 11:44 - 00000000 ____D C:\AMD
2015-11-24 13:07 - 2015-07-18 17:55 - 00000000 ____D C:\ProgramData\SUPPORTDIR
2015-11-24 13:06 - 2015-07-18 18:02 - 00000000 ____D C:\Users\Michael\Documents\CyberLink
2015-11-24 13:06 - 2015-07-18 17:58 - 00000000 ____D C:\Users\Michael\AppData\Local\CyberLink
2015-11-24 13:06 - 2015-07-18 17:55 - 00000000 ____D C:\ProgramData\CyberLink
2015-11-24 13:06 - 2015-02-24 18:49 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2015-11-24 13:05 - 2015-11-05 20:28 - 00000000 ____D C:\Users\Michael\AppData\Roaming\dvdcss
2015-11-23 19:10 - 2015-02-26 05:37 - 140158008 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2015-11-23 18:09 - 2015-09-20 02:26 - 00000000 ____D C:\ProgramData\Package Cache
2015-11-21 10:11 - 2015-09-14 22:14 - 00003992 _____ C:\WINDOWS\System32\Tasks\DropboxUpdateTaskMachineUA
2015-11-21 10:11 - 2015-09-14 22:14 - 00003760 _____ C:\WINDOWS\System32\Tasks\DropboxUpdateTaskMachineCore
2015-11-18 21:18 - 2015-09-08 10:11 - 00000000 ____D C:\Users\Michael\AppData\Local\CrashDumps
2015-11-18 21:18 - 2015-05-03 17:56 - 00000000 ____D C:\Users\Michael\AppData\Roaming\Free Download Manager
2015-11-18 20:03 - 2015-10-30 01:24 - 00000000 ___RD C:\WINDOWS\PurchaseDialog
2015-11-18 20:03 - 2015-10-30 01:24 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2015-11-18 20:03 - 2015-10-30 01:24 - 00000000 ____D C:\WINDOWS\system32\appraiser
2015-11-18 20:03 - 2015-10-30 01:24 - 00000000 ____D C:\WINDOWS\Provisioning
2015-11-18 20:03 - 2015-10-30 00:28 - 00000000 ____D C:\WINDOWS\SysWOW64\Dism
2015-11-18 20:03 - 2015-10-30 00:28 - 00000000 ____D C:\WINDOWS\system32\Dism
2015-11-17 17:36 - 2015-10-10 14:37 - 00000000 ___RD C:\Users\Michael\OneDrive
2015-11-17 17:33 - 2015-10-10 14:37 - 00002384 _____ C:\Users\Michael\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2015-11-17 15:57 - 2015-02-26 06:00 - 00000000 ____D C:\Users\Michael\Documents\My Kindle Content
==================== Files in the root of some directories =======
2015-06-18 22:09 - 2015-06-17 10:09 - 0000040 ____H () C:\Program Files (x86)\57012c43.tmp
2015-08-12 03:29 - 2015-08-10 15:29 - 0000040 ____H () C:\Program Files (x86)\a71c9ac4.tmp
2015-08-18 17:43 - 2015-08-18 17:43 - 16790552 _____ (LastPass) C:\Program Files (x86)\Common Files\lpuninstall.exe
2015-06-17 20:42 - 2015-06-17 20:42 - 0000600 _____ () C:\Users\Michael\AppData\Roaming\PUTTY.RND
2015-04-08 11:20 - 2015-09-09 12:20 - 0001456 _____ () C:\Users\Michael\AppData\Local\Adobe Save for Web 13.0 Prefs
2015-05-20 18:34 - 2015-05-20 18:51 - 2128896 _____ () C:\Users\Michael\AppData\Local\file__0.localstorage
2015-02-24 18:21 - 2015-12-09 14:16 - 0000600 _____ () C:\Users\Michael\AppData\Local\PUTTY.RND
2015-12-15 12:56 - 2015-12-15 12:56 - 0000218 _____ () C:\Users\Michael\AppData\Local\recently-used.xbel
2015-03-30 15:37 - 2015-03-30 16:11 - 0000469 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.400.32.bc
Files to move or delete:
====================
C:\Users\Michael\en_res.dll
C:\Users\Michael\es_res.dll
C:\Users\Michael\fr_res.dll
C:\Users\Michael\grm_res.dll
C:\Users\Michael\it_res.dll
C:\Users\Michael\jp_res.dll
C:\Users\Michael\mfc80u.dll
C:\Users\Michael\msvcr80.dll
C:\Users\Michael\PCPE Setup.exe
C:\Users\Michael\pt_res.dll
C:\Users\Michael\ResourceReader.dll
C:\Users\Michael\ru_res.dll
C:\Users\Michael\ZHPCleaner.exe
C:\Users\Michael\zh_res.dll
Some files in TEMP:
====================
C:\Users\Michael\AppData\Local\Temp\Acrobat_DC_Web_WWMUI.exe
C:\Users\Michael\AppData\Local\Temp\dllnt_dump.dll
C:\Users\Michael\AppData\Local\Temp\jre-8u66-windows-au.exe
C:\Users\Michael\AppData\Local\Temp\sfamcc00001.dll
C:\Users\Michael\AppData\Local\Temp\sfareca00001.dll
C:\Users\Michael\AppData\Local\Temp\sqlite3.dll
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-12-10 18:04
==================== End of FRST.txt ============================