Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

C: Drive full? Is it infected?


  • This topic is locked This topic is locked
6 replies to this topic

#1 kalvin689

kalvin689

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:12:19 PM

Posted 20 March 2016 - 09:05 AM

Title. Furthermore, this is a computer that I recently built ( 8 Months ago) So I doubt that I used up that amount of disk space already! Help please!



BC AdBot (Login to Remove)

 


#2 kalvin689

kalvin689
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:12:19 PM

Posted 20 March 2016 - 04:13 PM

Bump. I've also realised that it is in fact a virus because I've been sent emails about password changes and also someone bought something using my amazon account! Help needed!



#3 kalvin689

kalvin689
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:12:19 PM

Posted 21 March 2016 - 05:24 AM

Please help. My paypal account has now been used to purchase items totalling £200. In desperate need of help!



#4 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 37,033 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:04:19 AM

Posted 21 March 2016 - 05:49 PM

Greetings kalvin689 and :welcome: to BleepingComputer's Virus/Trojan/Spyware/Malware Removal forum.

My name is Oh My! and I am here to help you! Now that we are "friends" please call me Gary.

If you would allow me to call you by your first name I would prefer to do that.

===================================================

Ground Rules:
  • First, I would like to inform you that most of us here at Bleeping Computer offer our expert assistance out of the goodness of our hearts. Please try to match our commitment to you with your patience toward us. If this was easy we would never have met.
  • Please do not run any tools or take any steps other than those I will provide for you while we work on your computer together. I need to be certain about the state of your computer in order to provide appropriate and effective steps for you to take. Most often "well intentioned" (and usually panic driven!) independent efforts can make things much worse for both of us. If at any point you would prefer to take your own steps please let me know, I will not be offended. I would be happy to focus on the many others who are waiting in line for assistance.
  • Please perform all steps in the order they are listed in each set of instructions. Some steps may be a bit complicated. If things are not clear, be sure to stop and let me know. We need to work on this together with confidence.
  • Please copy and paste all logs into your post unless directed otherwise. Please do not re-run any programs I suggest. If you encounter problems simply stop and tell me.
  • When you post your reply, use the Replytopic.jpg button instead.
  • In the upper right hand corner of the topic you will see the Followtopic.jpg button. Click on this then choose Immediate E-Mail notification and then Proceed and you will be sent an email once I have posted a response.
  • If you do not reply to your topic after 5 days we assume it has been abandoned and I will close it.
  • When your computer is clean I will alert you of such. I will also provide for you detailed information about how you can combat future infections.
  • I would like to remind you to make no further changes to your computer unless I direct you to do so.
===================================================

Now that I am assisting you, you can expect that I will be very responsive to your situation. If you are able, I would request you check this thread at least once per day so that we can try to resolve your issues effectively and efficiently. If you are going to be delayed please be considerate and post that information so that I know you are still with me. Unfortunately, there are many people waiting to be assisted and not enough of us at BleepingComputer to go around. I appreciate your understanding and diligence.

Thank you for your patience thus far.

Please do this.

===================================================

Farbar Recovery Scan Tool (FRST)

--------------------
  • Download Farbar Recover Scan Tool for either 32 bit or 64 bit systems and save it to your Desktop. If FRST.exe is not on your Desktop please move it to that location. <<< Important
  • Double click the icon
  • Click Yes to the disclaimer
  • Make sure the Addition.txt box is checked
  • Click Scan and allow the program to run
  • Click OK on the Scan complete screen, then OK on the Addition.txt pop up screen
  • 2 Notepad documents should now be open on your desktop.
  • Please copy and paste the contents of both in your reply
===================================================

System Summary Information

--------------------
  • Press the windows key Windows_Logo_key.gif + r on your keyboard at the same time
  • Type msinfo32 and press Enter
  • Left click on System Summary
  • Click File, Save, and name the file Summary
  • Zip and attach the file to your reply
===================================================

Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it. :thumbsup2:
  • FRST results
  • Addition log
  • System Summary Information

Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#5 kalvin689

kalvin689
  • Topic Starter

  • Members
  • 14 posts
  • OFFLINE
  •  
  • Local time:12:19 PM

Posted 22 March 2016 - 06:05 AM

Hi Gary, I posted another in another section of the forum and got a reply http://www.bleepingcomputer.com/forums/t/608503/c-drive-full-and-people-are-making-unauthorised-payments-via-paypal/#entry3961587. I don't know if this will help you! However I will still follow your instructions, thank you !!!

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:05-03-2016 01

Ran by Kalvin (administrator) on KALVIN-PC (22-03-2016 10:48:13)

Running from C:\Users\Kalvin\Downloads

Loaded Profiles: Kalvin (Available Profiles: Kalvin)

Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)

Internet Explorer Version 11 (Default browser: Chrome)

Boot Mode: Normal

Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

 

==================== Processes (Whitelisted) =================

 

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

 

(AMD) C:\Windows\System32\atiesrxx.exe

(AMD) C:\Windows\System32\atieclxx.exe

(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe

(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe

(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe

(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe

(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe

(Avast Software) C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe

(Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe

(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe

(Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe

(VIA Technologies, Inc.) C:\Program Files\VIA XHCI UASP Utility\usb3Monitor.exe

(Microsoft Corporation) C:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe

(Apple Inc.) D:\Itunes\iTunesHelper.exe

(Nota Inc.) C:\Program Files (x86)\Gyazo\GyStation.exe

(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe

(Spotify Ltd) C:\Users\Kalvin\AppData\Roaming\Spotify\SpotifyWebHelper.exe

(Domit UK LTD) C:\Users\Kalvin\AppData\Local\MP3 Skype recorder\MP3SkypeRecorder.exe

(Raptr, Inc) C:\Program Files (x86)\Raptr\raptrstub.exe

(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe

(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe

(Intel Corporation) C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe

(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe

(Advanced Micro Devices Inc.) C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\MOM.exe

(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe

(Microsoft Corporation) C:\Windows\System32\consent.exe

(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.29.5\GoogleCrashHandler.exe

(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.29.5\GoogleCrashHandler64.exe

(Advanced Micro Devices Inc.) C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\CCC.exe

(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe

(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

(Microsoft Corporation) C:\Windows\System32\wbem\WMIADAP.exe

(Microsoft Corporation) C:\Windows\System32\dllhost.exe

 

==================== Registry (Whitelisted) ===========================

 

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

 

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8484056 2015-06-12] (Realtek Semiconductor)

HKLM\...\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [14601160 2015-07-02] (Logitech Inc.)

HKLM\...\Run: [VIAxHCUtl] => C:\Program Files\VIA XHCI UASP Utility\usb3Monitor

HKLM\...\Run: [XboxStat] => C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe [825184 2009-09-30] (Microsoft Corporation)

HKLM\...\Run: [iTunesHelper] => D:\Itunes\iTunesHelper.exe [170256 2015-12-17] (Apple Inc.)

HKLM-x32\...\Run: [Raptr] => C:\Program Files (x86)\Raptr\raptrstub.exe [56080 2015-12-11] (Raptr, Inc)

HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [7004376 2015-11-06] (AVAST Software)

HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [296216 2015-07-24] (Intel Corporation)

HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe [767176 2015-07-28] (Advanced Micro Devices, Inc.)

HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)

HKLM-x32\...\Run: [] => [X]

HKU\S-1-5-21-3803452205-4226285346-3461252913-1000\...\Run: [Steam] => D:\Steam\steam.exe [3074128 2016-03-10] (Valve Corporation)

HKU\S-1-5-21-3803452205-4226285346-3461252913-1000\...\Run: [Gyazo] => C:\Program Files (x86)\Gyazo\GyStation.exe [3586848 2016-02-17] (Nota Inc.)

HKU\S-1-5-21-3803452205-4226285346-3461252913-1000\...\Run: [GoogleDriveSync] => C:\Program Files (x86)\Google\Drive\googledrivesync.exe [23260000 2016-02-24] (Google)

HKU\S-1-5-21-3803452205-4226285346-3461252913-1000\...\Run: [Spotify Web Helper] => C:\Users\Kalvin\AppData\Roaming\Spotify\SpotifyWebHelper.exe [1524336 2016-03-19] (Spotify Ltd)

HKU\S-1-5-21-3803452205-4226285346-3461252913-1000\...\Run: [MP3 Skype recorder] => C:\Users\Kalvin\AppData\Local\MP3 Skype recorder\MP3SkypeRecorder.exe [2223768 2016-02-17] (Domit UK LTD)

ShellIconOverlayIdentifiers: [  GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-02-24] (Google)

ShellIconOverlayIdentifiers: [  GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-02-24] (Google)

ShellIconOverlayIdentifiers: [  GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-02-24] (Google)

ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2015-11-06] (AVAST Software)

Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Install LastPass FF RunOnce.lnk [2016-03-20]

ShortcutTarget: Install LastPass FF RunOnce.lnk -> C:\Program Files (x86)\Common Files\lpuninstall.exe (LastPass)

Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Install LastPass IE RunOnce.lnk [2016-03-20]

ShortcutTarget: Install LastPass IE RunOnce.lnk -> C:\Program Files (x86)\Common Files\lpuninstall.exe (LastPass)

CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION

 

==================== Internet (Whitelisted) ====================

 

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

 

Tcpip\Parameters: [DhcpNameServer] 192.168.1.254 192.168.1.254

Tcpip\..\Interfaces\{AEBC8276-2431-4B4B-9D2C-89089913ADAA}: [DhcpNameServer] 192.168.1.254 192.168.1.254

 

Internet Explorer:

==================

HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION

BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2016-02-28] (Microsoft Corporation)

BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-11-06] (AVAST Software)

BHO: LastPass Vault -> {95D9ECF5-2A4D-4550-BE49-70D42F71296E} -> C:\Program Files (x86)\LastPass\LPToolbar_x64.dll [2016-03-20] (LastPass)

BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\URLREDIR.DLL [2016-02-28] (Microsoft Corporation)

BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL [2016-02-28] (Microsoft Corporation)

BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-11-06] (AVAST Software)

BHO-x32: LastPass Vault -> {95D9ECF5-2A4D-4550-BE49-70D42F71296E} -> C:\Program Files (x86)\LastPass\LPToolbar.dll [2016-03-20] (LastPass)

BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\root\Office16\URLREDIR.DLL [2016-02-28] (Microsoft Corporation)

Toolbar: HKLM - LastPass Toolbar - {9f6b5cc3-5c7b-4b5c-97af-19dec1e380e5} - C:\Program Files (x86)\LastPass\LPToolbar_x64.dll [2016-03-20] (LastPass)

Toolbar: HKLM-x32 - LastPass Toolbar - {9f6b5cc3-5c7b-4b5c-97af-19dec1e380e5} - C:\Program Files (x86)\LastPass\LPToolbar.dll [2016-03-20] (LastPass)

Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2016-02-28] (Microsoft Corporation)

Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2016-02-28] (Microsoft Corporation)

Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2016-02-28] (Microsoft Corporation)

Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2016-02-28] (Microsoft Corporation)

 

FireFox:

========

FF ProfilePath: C:\Users\Kalvin\AppData\Roaming\Mozilla\Firefox\Profiles\igmzlsmz.default

FF Plugin: @lastpass.com/NPLastPass -> C:\Program Files (x86)\LastPass\nplastpass64.dll [2016-03-20] (LastPass)

FF Plugin: @microsoft.com/GENUINE -> disabled [No File]

FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2015-10-14] ()

FF Plugin-x32: @lastpass.com/NPLastPass -> C:\Program Files (x86)\LastPass\nplastpass64.dll [2016-03-20] (LastPass)

FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]

FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2016-02-28] (Microsoft Corporation)

FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.)

FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.)

FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF

FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2015-11-07]

FF HKLM-x32\...\Firefox\Extensions: [sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF

FF Extension: Avast SafePrice - C:\Program Files\AVAST Software\Avast\SafePrice\FF [2015-11-06]

 

Chrome:

=======

CHR HomePage: Default -> hxxp://google.co.uk/

CHR StartupUrls: Default -> "hxxp://isearch.avg.com/?cid={8599EAFB-C2C8-46B9-94AD-FF21C68E3189}&mid=0e61a8f2e86947d08fe15dc0e3d0ea6c-7f7d72e3a41d0cb219331819cf619f80adc52e50&lang=en&ds=ft011&pr=sa&d=2012-06-14 20:56:38&v=11.1.0.12&sap=hp","hxxp://search.b1.org/?bsrc=4hcxr&chid=c162341","hxxp://search.babylon.com/?affID=112060&tt=3612_6&babsrc=HP_ss_pr_pr&mntrId=de166134000000000000742f68923f26","hxxp://www.search.ask.com/?tpid=ORJ-M&o=APN11806&pf=VM1&trgb=CR&p2=%5EBTF%5EYYYYYY%5EYY%5EGB&gct=hp&apn_ptnrs=%5EBTF&apn_dtid=%5EYYYYYY%5EYY%5EGB&apn_dbr=cr_41.0.2272.118&apn_uid=FC765C1C-5BA3-45DD-A6C3-4020A9AD4B4D&itbv=15.0.0.7&doi=2015-04-08&psv=&pt=tb"

CHR Profile: C:\Users\Kalvin\AppData\Local\Google\Chrome\User Data\Default

CHR Extension: (Google Slides) - C:\Users\Kalvin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-07-24]

CHR Extension: (TabTab - New tab page) - C:\Users\Kalvin\AppData\Local\Google\Chrome\User Data\Default\Extensions\alinppachfoplkpifadofmchbggehmoi [2015-08-25]

CHR Extension: (Google Docs) - C:\Users\Kalvin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-07-24]

CHR Extension: (Google Drive) - C:\Users\Kalvin\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-21]

CHR Extension: (YouTube) - C:\Users\Kalvin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-24]

CHR Extension: (Gom VPN - Bypass and unblock) - C:\Users\Kalvin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ckiahbcmlmkpfiijecbpflfahoimklke [2016-02-15]

CHR Extension: (Google Search) - C:\Users\Kalvin\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-27]

CHR Extension: (Block site) - C:\Users\Kalvin\AppData\Local\Google\Chrome\User Data\Default\Extensions\eiimnmioipafcokbfikbljfdeojpcgbh [2015-08-25]

CHR Extension: (Google Sheets) - C:\Users\Kalvin\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-07-24]

CHR Extension: (News Feed Eradicator for Facebook) - C:\Users\Kalvin\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjcldmjmjhkklehbacihaiopjklihlgg [2015-11-20]

CHR Extension: (Google Docs Offline) - C:\Users\Kalvin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-16]

CHR Extension: (AdBlock) - C:\Users\Kalvin\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2016-03-18]

CHR Extension: (Avast Online Security) - C:\Users\Kalvin\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2016-01-28]

CHR Extension: (LastPass: Free Password Manager) - C:\Users\Kalvin\AppData\Local\Google\Chrome\User Data\Default\Extensions\hdokiejnpimakedhajhdlcegeplioahd [2016-03-20]

CHR Extension: (Kindle Cloud Reader) - C:\Users\Kalvin\AppData\Local\Google\Chrome\User Data\Default\Extensions\icdipabjmbhpdkjaihfjoikhjjeneebd [2015-09-07]

CHR Extension: (Reddit Enhancement Suite) - C:\Users\Kalvin\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbmfpngjjgdllneeigpgjifpgocmfgmb [2016-03-17]

CHR Extension: (Application Launcher for Drive (by Google)) - C:\Users\Kalvin\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2015-09-09]

CHR Extension: (Chrome Web Store Payments) - C:\Users\Kalvin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-07-27]

CHR Extension: (Oddshot) - C:\Users\Kalvin\AppData\Local\Google\Chrome\User Data\Default\Extensions\olnoeeagkgpkplnhmnnlgodjnjgckhja [2016-03-13]

CHR Extension: (Recently Closed Tabs) - C:\Users\Kalvin\AppData\Local\Google\Chrome\User Data\Default\Extensions\opefiliglgllmponlmoajkfbcaigocfc [2016-02-23]

CHR Extension: (Gmail) - C:\Users\Kalvin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-07-24]

CHR HKLM\...\Chrome\Extension: [hdokiejnpimakedhajhdlcegeplioahd] - hxxp://clients2.google.com/service/update2/crx

CHR HKU\S-1-5-21-3803452205-4226285346-3461252913-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] - hxxps://clients2.google.com/service/update2/crx

CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChromeSp.crx [2015-11-06]

CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-11-06]

CHR HKLM-x32\...\Chrome\Extension: [hdokiejnpimakedhajhdlcegeplioahd] - hxxp://clients2.google.com/service/update2/crx

 

==================== Services (Whitelisted) ========================

 

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

 

R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77104 2015-10-07] (Apple Inc.)

R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [174416 2015-11-06] (AVAST Software)

R3 AvastVBoxSvc; C:\Program Files\AVAST Software\Avast\ng\vbox\AvastVBoxSVC.exe [5554152 2015-11-06] (Avast Software)

R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [2804976 2016-02-28] (Microsoft Corporation)

R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1514464 2016-03-10] (Malwarebytes)

R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1136608 2016-03-10] (Malwarebytes)

R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)

 

===================== Drivers (Whitelisted) ==========================

 

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

 

R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [28656 2015-11-06] (AVAST Software)

R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [97648 2015-11-06] (AVAST Software)

R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-11-06] (AVAST Software)

R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65224 2015-11-06] (AVAST Software)

R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1059656 2015-11-06] (AVAST Software)

R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [449992 2015-11-06] (AVAST Software)

R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [154256 2015-11-06] (AVAST Software)

R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [273784 2015-11-06] (AVAST Software)

S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)

R1 HWiNFO32; C:\Windows\system32\drivers\HWiNFO64A.SYS [27552 2015-07-28] (REALiX™)

R3 ISCT; C:\Windows\System32\DRIVERS\ISCTD64.sys [46568 2013-01-18] ()

R2 LGCoreTemp; C:\Program Files\Logitech Gaming Software\Drivers\LgCoreTemp\lgcoretemp.sys [14184 2015-06-21] (Logitech)

R3 LGJoyXlCore; C:\Windows\System32\drivers\LGJoyXlCore.sys [68384 2015-06-10] (Logitech Inc.)

R3 LGSHidFilt; C:\Windows\System32\DRIVERS\LGSHidFilt.Sys [64280 2013-05-30] (Logitech Inc.)

R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [27008 2016-03-10] (Malwarebytes)

R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [192216 2016-03-22] (Malwarebytes)

R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64896 2016-03-10] (Malwarebytes Corporation)

R0 ngvss; C:\Windows\System32\Drivers\ngvss.sys [147088 2015-11-06] (AVAST Software)

R2 VBoxAswDrv; C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [310904 2015-11-06] (Avast Software)

R3 VUSB3HUB; C:\Windows\System32\DRIVERS\ViaHub3.sys [225792 2014-10-31] (VIA Technologies, Inc.)

R3 xhcdrv; C:\Windows\System32\DRIVERS\xhcdrv.sys [305664 2014-10-31] (VIA Technologies, Inc.)

 

==================== NetSvcs (Whitelisted) ===================

 

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

 

==================== One Month Created files and folders ========

 

(If an entry is included in the fixlist, the file/folder will be moved.)

 

2016-03-22 10:48 - 2016-03-22 10:48 - 00020195 _____ C:\Users\Kalvin\Downloads\FRST.txt

2016-03-22 10:48 - 2016-03-22 10:48 - 00000000 ____D C:\FRST

2016-03-22 10:47 - 2016-03-22 10:47 - 02374144 _____ (Farbar) C:\Users\Kalvin\Downloads\FRST64.exe

2016-03-21 23:21 - 2016-03-21 23:21 - 00137728 _____ C:\Users\Kalvin\Downloads\Opposition (2).ppt

2016-03-21 23:18 - 2016-03-21 23:18 - 00137728 _____ C:\Users\Kalvin\Downloads\Opposition (1).ppt

2016-03-21 23:17 - 2016-03-21 23:17 - 00137728 _____ C:\Users\Kalvin\Downloads\Opposition.ppt

2016-03-21 23:13 - 2016-03-21 23:13 - 00000224 _____ C:\Users\Kalvin\Downloads\eset.txt

2016-03-21 23:13 - 2016-03-21 23:13 - 00000000 ____D C:\Users\Kalvin\Downloads\New folder

2016-03-21 22:06 - 2016-03-21 23:15 - 00207774 _____ C:\TDSSKiller.3.1.0.9_21.03.2016_22.06.24_log.txt

2016-03-21 22:04 - 2016-03-21 22:04 - 02870984 _____ (ESET) C:\Users\Kalvin\Downloads\esetsmartinstaller_enu.exe

2016-03-21 22:04 - 2016-03-21 22:04 - 02870984 _____ (ESET) C:\Users\Kalvin\Downloads\esetsmartinstaller_enu (1).exe

2016-03-21 22:04 - 2016-03-21 22:04 - 00000000 ____D C:\Program Files (x86)\ESET

2016-03-21 22:03 - 2016-03-21 22:03 - 04633146 _____ C:\Users\Kalvin\Downloads\tdsskiller (2).zip

2016-03-21 22:03 - 2016-03-21 22:03 - 01610352 _____ (Malwarebytes) C:\Users\Kalvin\Downloads\JRT (2).exe

2016-03-21 21:58 - 2016-03-21 21:59 - 00207852 _____ C:\TDSSKiller.3.1.0.9_21.03.2016_21.58.05_log.txt

2016-03-21 21:55 - 2016-03-21 22:01 - 00001213 _____ C:\Users\Kalvin\Desktop\JRT.txt

2016-03-21 21:54 - 2016-03-21 21:54 - 04633146 _____ C:\Users\Kalvin\Downloads\tdsskiller (1).zip

2016-03-21 21:54 - 2016-03-21 21:54 - 01610352 _____ (Malwarebytes) C:\Users\Kalvin\Downloads\JRT (1).exe

2016-03-21 21:54 - 2016-03-21 21:54 - 01530368 _____ C:\Users\Kalvin\Downloads\AdwCleaner (1).exe

2016-03-21 21:53 - 2016-03-21 21:53 - 01610352 _____ (Malwarebytes) C:\Users\Kalvin\Downloads\JRT.exe

2016-03-21 21:46 - 2016-03-21 21:58 - 00000000 ____D C:\AdwCleaner

2016-03-21 21:46 - 2016-03-21 21:46 - 01530368 _____ C:\Users\Kalvin\Downloads\AdwCleaner.exe

2016-03-21 21:41 - 2016-03-21 21:48 - 00208478 _____ C:\TDSSKiller.3.1.0.9_21.03.2016_21.41.57_log.txt

2016-03-21 21:41 - 2016-03-21 21:41 - 04633146 _____ C:\Users\Kalvin\Downloads\tdsskiller.zip

2016-03-21 21:41 - 2016-03-21 21:41 - 00000000 ____D C:\Users\Kalvin\Downloads\tdsskiller

2016-03-21 21:39 - 2016-03-21 23:44 - 00031583 _____ C:\Users\Kalvin\Downloads\MTB.txt

2016-03-21 21:37 - 2016-03-21 21:37 - 00891392 _____ (Farbar) C:\Users\Kalvin\Downloads\MiniToolBox.exe

2016-03-21 21:22 - 2016-03-21 21:22 - 01948012 _____ C:\Users\Kalvin\Downloads\image.jpeg

2016-03-21 21:22 - 2016-03-21 21:22 - 01851250 _____ C:\Users\Kalvin\Downloads\image (1).jpeg

2016-03-21 17:39 - 2016-03-21 17:43 - 00000000 ____D C:\Users\Kalvin\AppData\Roaming\DAPV9

2016-03-21 12:32 - 2016-03-21 12:34 - 22851472 _____ (Malwarebytes ) C:\Users\Kalvin\Downloads\mbam-setup-2.2.1.1043 (1).exe

2016-03-21 11:47 - 2016-03-22 10:42 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys

2016-03-21 11:47 - 2016-03-21 11:47 - 00001106 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk

2016-03-21 11:47 - 2016-03-21 11:47 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware

2016-03-21 11:47 - 2016-03-21 11:47 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware

2016-03-21 11:47 - 2016-03-10 14:09 - 00064896 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys

2016-03-21 11:47 - 2016-03-10 14:08 - 00140672 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys

2016-03-21 11:47 - 2016-03-10 14:08 - 00027008 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys

2016-03-21 11:42 - 2016-03-21 11:43 - 22851472 _____ (Malwarebytes ) C:\Users\Kalvin\Downloads\mbam-setup-2.2.1.1043.exe

2016-03-20 20:12 - 2016-03-20 20:12 - 00268066 _____ C:\Users\Kalvin\Downloads\2015-07-25-1307-36 (1).flv

2016-03-20 20:11 - 2016-03-20 20:11 - 00268066 _____ C:\Users\Kalvin\Downloads\2015-07-25-1307-36.flv

2016-03-20 16:28 - 2016-03-20 20:11 - 00000000 ____D C:\Users\Kalvin\AppData\Local\CrashDumps

2016-03-20 15:50 - 2016-03-20 15:50 - 00000000 ____D C:\Users\Kalvin\Documents\League of Legends

2016-03-20 15:12 - 2016-03-20 15:13 - 00000000 ____D C:\Users\Kalvin\AppData\LocalLow\LastPass

2016-03-20 15:12 - 2016-03-20 15:12 - 00001192 _____ C:\Users\Public\Desktop\My LastPass Vault.lnk

2016-03-20 15:12 - 2016-03-20 15:12 - 00000000 ____D C:\Users\Kalvin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\LastPass

2016-03-20 15:12 - 2016-03-20 15:12 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LastPass

2016-03-20 15:10 - 2016-03-20 15:12 - 00000000 ____D C:\Program Files (x86)\LastPass

2016-03-20 15:09 - 2016-03-20 15:09 - 21572120 _____ (LastPass) C:\Users\Kalvin\Downloads\lastpass_x64.exe

2016-03-20 13:43 - 2016-03-21 17:49 - 00028272 _____ C:\Windows\system32\Drivers\TrueSight.sys

2016-03-20 13:42 - 2016-03-20 14:48 - 00000000 ____D C:\ProgramData\RogueKiller

2016-03-20 13:42 - 2016-03-20 13:42 - 00000858 _____ C:\Users\Public\Desktop\RogueKiller.lnk

2016-03-20 13:42 - 2016-03-20 13:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RogueKiller

2016-03-20 13:42 - 2016-03-20 13:42 - 00000000 ____D C:\Program Files\RogueKiller

2016-03-20 13:41 - 2016-03-20 13:42 - 28805368 _____ (Adlice Software ) C:\Users\Kalvin\Downloads\setup.exe

2016-03-20 12:14 - 2016-03-20 12:14 - 00014824 _____ C:\Users\Kalvin\Downloads\Sum1 2016.docm

2016-03-20 12:14 - 2016-03-20 12:14 - 00014687 _____ C:\Users\Kalvin\Downloads\Easter Hol 2016.docm

2016-03-20 12:03 - 2016-03-20 12:03 - 30668968 _____ (Riot Games) C:\Users\Kalvin\Downloads\LeagueofLegends_EUW_Installer_9_15_2014 (8).exe

2016-03-20 11:54 - 2016-03-20 11:54 - 30668968 _____ (Riot Games) C:\Users\Kalvin\Downloads\Unconfirmed 95599.crdownload

2016-03-16 17:45 - 2016-03-16 17:45 - 00599580 _____ C:\Users\Kalvin\Downloads\maths OCR Core 4 June 2015 (4724).pdf

2016-03-15 22:23 - 2016-03-15 22:23 - 00599752 _____ C:\Users\Kalvin\Downloads\Core 4 June 2015 worked solutions.zip

2016-03-15 18:46 - 2016-03-15 18:46 - 00055586 _____ C:\Users\Kalvin\Downloads\download (8).htm

2016-03-14 20:33 - 2016-03-14 20:33 - 00177725 _____ C:\Users\Kalvin\Downloads\new doc 25 (2).pdf

2016-03-14 20:33 - 2016-03-14 20:33 - 00177725 _____ C:\Users\Kalvin\Downloads\new doc 25 (1).pdf

2016-03-14 20:32 - 2016-03-14 20:32 - 00177725 _____ C:\Users\Kalvin\Downloads\new doc 25.pdf

2016-03-13 19:44 - 2016-03-13 19:44 - 00125010 _____ C:\Users\Kalvin\Downloads\download (7).htm

2016-03-13 12:25 - 2016-03-13 12:25 - 00195040 _____ C:\Users\Kalvin\Downloads\4754-01B Insert Jun15.pdf

2016-03-12 11:16 - 2016-03-12 11:17 - 125168408 _____ (Apple Inc.) C:\Users\Kalvin\Downloads\icloudsetup.exe

2016-03-12 11:11 - 2016-03-12 11:13 - 129561781 _____ C:\Users\Kalvin\Downloads\The Life of Pablo.zip

2016-03-12 11:11 - 2016-03-12 11:12 - 11479113 _____ C:\Users\Kalvin\Downloads\01 Ultralight Beam (feat. Chance the Rapper & Kirk Franklin).m4a

2016-03-10 23:14 - 2016-03-13 23:14 - 00000000 ____D C:\Users\Kalvin\Documents\History AS Retakes-

2016-03-09 20:38 - 2016-03-09 20:38 - 00035436 _____ C:\Users\Kalvin\Downloads\bar-38.htm

2016-03-09 18:55 - 2016-03-09 18:55 - 00142077 _____ C:\Users\Kalvin\Downloads\M1 Jun 07.pdf

2016-03-09 17:20 - 2016-03-09 18:03 - 00000000 ____D C:\Users\Kalvin\AppData\Roaming\MP3SkypeRecorder

2016-03-09 17:20 - 2016-03-09 17:20 - 00002109 _____ C:\Users\Kalvin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MP3 Skype recorder.lnk

2016-03-09 17:20 - 2016-03-09 17:20 - 00002101 _____ C:\Users\Kalvin\Desktop\MP3 Skype recorder.lnk

2016-03-09 17:20 - 2016-03-09 17:20 - 00000000 ____D C:\Users\Kalvin\AppData\Local\MP3 Skype recorder

2016-03-09 17:20 - 2016-03-09 17:20 - 00000000 ____D C:\Users\Kalvin\AppData\Local\Domit_UK_LTD

2016-03-09 17:20 - 2016-03-09 17:20 - 00000000 ____D C:\ProgramData\IsolatedStorage

2016-03-09 17:12 - 2016-03-09 17:13 - 06053888 _____ C:\Users\Kalvin\Downloads\MP3SkypeRecorderSetup.msi

2016-03-08 22:19 - 2016-02-04 17:52 - 03211264 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys

2016-03-08 22:19 - 2015-11-19 14:07 - 00994760 _____ (Microsoft Corporation) C:\Windows\system32\ucrtbase.dll

2016-03-08 22:19 - 2015-11-19 14:07 - 00063840 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-private-l1-1-0.dll

2016-03-08 22:19 - 2015-11-19 14:07 - 00020832 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-math-l1-1-0.dll

2016-03-08 22:19 - 2015-11-19 14:07 - 00019808 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-multibyte-l1-1-0.dll

2016-03-08 22:19 - 2015-11-19 14:07 - 00017760 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-string-l1-1-0.dll

2016-03-08 22:19 - 2015-11-19 14:07 - 00017760 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-stdio-l1-1-0.dll

2016-03-08 22:19 - 2015-11-19 14:07 - 00016224 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-runtime-l1-1-0.dll

2016-03-08 22:19 - 2015-11-19 14:07 - 00015712 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-convert-l1-1-0.dll

2016-03-08 22:19 - 2015-11-19 14:07 - 00014176 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-time-l1-1-0.dll

2016-03-08 22:19 - 2015-11-19 14:07 - 00014176 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-2-0.dll

2016-03-08 22:19 - 2015-11-19 14:07 - 00013664 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll

2016-03-08 22:19 - 2015-11-19 14:07 - 00012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-process-l1-1-0.dll

2016-03-08 22:19 - 2015-11-19 14:07 - 00012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-heap-l1-1-0.dll

2016-03-08 22:19 - 2015-11-19 14:07 - 00012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-conio-l1-1-0.dll

2016-03-08 22:19 - 2015-11-19 14:07 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-utility-l1-1-0.dll

2016-03-08 22:19 - 2015-11-19 14:07 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-locale-l1-1-0.dll

2016-03-08 22:19 - 2015-11-19 14:07 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-environment-l1-1-0.dll

2016-03-08 22:19 - 2015-11-19 14:07 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-2-0.dll

2016-03-08 22:19 - 2015-11-19 14:07 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-1.dll

2016-03-08 22:19 - 2015-11-19 14:07 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l2-1-0.dll

2016-03-08 22:19 - 2015-11-19 14:07 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-timezone-l1-1-0.dll

2016-03-08 22:19 - 2015-11-19 14:07 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l2-1-0.dll

2016-03-08 22:19 - 2015-11-19 14:07 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-2-0.dll

2016-03-08 22:19 - 2015-11-19 14:06 - 00922432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ucrtbase.dll

2016-03-08 22:19 - 2015-11-19 14:06 - 00066400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-private-l1-1-0.dll

2016-03-08 22:19 - 2015-11-19 14:06 - 00022368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-math-l1-1-0.dll

2016-03-08 22:19 - 2015-11-19 14:06 - 00019808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-multibyte-l1-1-0.dll

2016-03-08 22:19 - 2015-11-19 14:06 - 00017760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-string-l1-1-0.dll

2016-03-08 22:19 - 2015-11-19 14:06 - 00017760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-stdio-l1-1-0.dll

2016-03-08 22:19 - 2015-11-19 14:06 - 00016224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-runtime-l1-1-0.dll

2016-03-08 22:19 - 2015-11-19 14:06 - 00015712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-convert-l1-1-0.dll

2016-03-08 22:19 - 2015-11-19 14:06 - 00014176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-time-l1-1-0.dll

2016-03-08 22:19 - 2015-11-19 14:06 - 00014176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-2-0.dll

2016-03-08 22:19 - 2015-11-19 14:06 - 00013664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-filesystem-l1-1-0.dll

2016-03-08 22:19 - 2015-11-19 14:06 - 00012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-process-l1-1-0.dll

2016-03-08 22:19 - 2015-11-19 14:06 - 00012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-heap-l1-1-0.dll

2016-03-08 22:19 - 2015-11-19 14:06 - 00012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-conio-l1-1-0.dll

2016-03-08 22:19 - 2015-11-19 14:06 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-utility-l1-1-0.dll

2016-03-08 22:19 - 2015-11-19 14:06 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-locale-l1-1-0.dll

2016-03-08 22:19 - 2015-11-19 14:06 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-environment-l1-1-0.dll

2016-03-08 22:19 - 2015-11-19 14:06 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-2-0.dll

2016-03-08 22:19 - 2015-11-19 14:06 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-1.dll

2016-03-08 22:19 - 2015-11-19 14:06 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l2-1-0.dll

2016-03-08 22:19 - 2015-11-19 14:06 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-timezone-l1-1-0.dll

2016-03-08 22:19 - 2015-11-19 14:06 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l2-1-0.dll

2016-03-08 22:19 - 2015-11-19 14:06 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-2-0.dll

2016-03-08 22:18 - 2016-02-12 18:52 - 03169792 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll

2016-03-08 22:18 - 2016-02-12 18:52 - 00192512 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll

2016-03-08 22:18 - 2016-02-12 18:52 - 00098816 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll

2016-03-08 22:18 - 2016-02-12 18:44 - 00091136 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll

2016-03-08 22:18 - 2016-02-12 18:39 - 00174080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll

2016-03-08 22:18 - 2016-02-12 18:22 - 02610688 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll

2016-03-08 22:18 - 2016-02-12 18:19 - 00709120 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll

2016-03-08 22:18 - 2016-02-12 18:18 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe

2016-03-08 22:18 - 2016-02-12 18:18 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll

2016-03-08 22:18 - 2016-02-12 18:18 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe

2016-03-08 22:18 - 2016-02-12 18:18 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll

2016-03-08 22:18 - 2016-02-12 18:18 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll

2016-03-08 22:18 - 2016-02-12 18:06 - 00573440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll

2016-03-08 22:18 - 2016-02-12 18:05 - 00093696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll

2016-03-08 22:18 - 2016-02-12 18:05 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe

2016-03-08 22:18 - 2016-02-12 18:05 - 00030208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll

2016-03-08 22:18 - 2016-02-09 06:53 - 00387792 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll

2016-03-08 22:18 - 2016-02-09 06:10 - 00341200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll

2016-03-08 22:18 - 2016-02-08 21:05 - 20352512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll

2016-03-08 22:18 - 2016-02-08 20:51 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb

2016-03-08 22:18 - 2016-02-08 20:39 - 00496640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll

2016-03-08 22:18 - 2016-02-08 20:39 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll

2016-03-08 22:18 - 2016-02-08 20:38 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec

2016-03-08 22:18 - 2016-02-08 20:38 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll

2016-03-08 22:18 - 2016-02-08 20:37 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll

2016-03-08 22:18 - 2016-02-08 20:34 - 02280448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll

2016-03-08 22:18 - 2016-02-08 20:32 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll

2016-03-08 22:18 - 2016-02-08 20:31 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll

2016-03-08 22:18 - 2016-02-08 20:30 - 00476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll

2016-03-08 22:18 - 2016-02-08 20:28 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll

2016-03-08 22:18 - 2016-02-08 20:28 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll

2016-03-08 22:18 - 2016-02-08 20:28 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe

2016-03-08 22:18 - 2016-02-08 20:20 - 00416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll

2016-03-08 22:18 - 2016-02-08 20:16 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll

2016-03-08 22:18 - 2016-02-08 20:15 - 00091136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll

2016-03-08 22:18 - 2016-02-08 20:13 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll

2016-03-08 22:18 - 2016-02-08 20:12 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll

2016-03-08 22:18 - 2016-02-08 20:11 - 00279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll

2016-03-08 22:18 - 2016-02-08 20:10 - 04611072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll

2016-03-08 22:18 - 2016-02-08 20:10 - 00130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll

2016-03-08 22:18 - 2016-02-08 20:05 - 25816576 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll

2016-03-08 22:18 - 2016-02-08 20:03 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll

2016-03-08 22:18 - 2016-02-08 20:02 - 13012480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll

2016-03-08 22:18 - 2016-02-08 20:02 - 00687104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll

2016-03-08 22:18 - 2016-02-08 20:01 - 02050560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl

2016-03-08 22:18 - 2016-02-08 20:01 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll

2016-03-08 22:18 - 2016-02-08 19:43 - 02121216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll

2016-03-08 22:18 - 2016-02-08 19:39 - 01311744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll

2016-03-08 22:18 - 2016-02-08 19:38 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll

2016-03-08 22:18 - 2016-02-08 18:41 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb

2016-03-08 22:18 - 2016-02-08 18:41 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll

2016-03-08 22:18 - 2016-02-08 18:27 - 02887680 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll

2016-03-08 22:18 - 2016-02-08 18:27 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll

2016-03-08 22:18 - 2016-02-08 18:26 - 00571904 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll

2016-03-08 22:18 - 2016-02-08 18:26 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec

2016-03-08 22:18 - 2016-02-08 18:26 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll

2016-03-08 22:18 - 2016-02-08 18:26 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll

2016-03-08 22:18 - 2016-02-08 18:19 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll

2016-03-08 22:18 - 2016-02-08 18:18 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll

2016-03-08 22:18 - 2016-02-08 18:16 - 06052352 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll

2016-03-08 22:18 - 2016-02-08 18:15 - 00615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll

2016-03-08 22:18 - 2016-02-08 18:14 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe

2016-03-08 22:18 - 2016-02-08 18:14 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe

2016-03-08 22:18 - 2016-02-08 18:13 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll

2016-03-08 22:18 - 2016-02-08 18:13 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll

2016-03-08 22:18 - 2016-02-08 18:06 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe

2016-03-08 22:18 - 2016-02-08 18:03 - 00489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll

2016-03-08 22:18 - 2016-02-08 17:55 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll

2016-03-08 22:18 - 2016-02-08 17:54 - 00107520 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll

2016-03-08 22:18 - 2016-02-08 17:52 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll

2016-03-08 22:18 - 2016-02-08 17:51 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll

2016-03-08 22:18 - 2016-02-08 17:49 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll

2016-03-08 22:18 - 2016-02-08 17:47 - 00152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll

2016-03-08 22:18 - 2016-02-08 17:37 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll

2016-03-08 22:18 - 2016-02-08 17:35 - 00718336 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe

2016-03-08 22:18 - 2016-02-08 17:34 - 00798720 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll

2016-03-08 22:18 - 2016-02-08 17:33 - 14613504 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll

2016-03-08 22:18 - 2016-02-08 17:33 - 02123264 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl

2016-03-08 22:18 - 2016-02-08 17:33 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll

2016-03-08 22:18 - 2016-02-08 17:19 - 02597376 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll

2016-03-08 22:18 - 2016-02-08 17:07 - 01546752 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll

2016-03-08 22:18 - 2016-02-08 16:55 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll

2016-03-08 22:18 - 2016-02-03 18:58 - 00862208 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll

2016-03-08 22:18 - 2016-02-03 18:52 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\asycfilt.dll

2016-03-08 22:18 - 2016-02-03 18:49 - 00572416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll

2016-03-08 22:18 - 2016-02-03 18:43 - 00067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\asycfilt.dll

2016-03-08 22:18 - 2016-02-03 18:07 - 00091648 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBSTOR.SYS

2016-03-08 22:18 - 2016-01-11 19:11 - 01684416 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys

2016-03-08 22:17 - 2016-02-19 19:02 - 00038336 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe

2016-03-08 22:17 - 2016-02-19 18:54 - 01168896 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll

2016-03-08 22:17 - 2016-02-19 14:07 - 01373184 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll

2016-03-08 22:17 - 2016-02-11 18:56 - 05572032 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe

2016-03-08 22:17 - 2016-02-11 18:56 - 00154560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys

2016-03-08 22:17 - 2016-02-11 18:56 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys

2016-03-08 22:17 - 2016-02-11 18:52 - 01733592 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll

2016-03-08 22:17 - 2016-02-11 18:49 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll

2016-03-08 22:17 - 2016-02-11 18:49 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll

2016-03-08 22:17 - 2016-02-11 18:49 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll

2016-03-08 22:17 - 2016-02-11 18:49 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll

2016-03-08 22:17 - 2016-02-11 18:49 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll

2016-03-08 22:17 - 2016-02-11 18:49 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll

2016-03-08 22:17 - 2016-02-11 18:49 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll

2016-03-08 22:17 - 2016-02-11 18:49 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll

2016-03-08 22:17 - 2016-02-11 18:48 - 01214464 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll

2016-03-08 22:17 - 2016-02-11 18:48 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll

2016-03-08 22:17 - 2016-02-11 18:48 - 00344064 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll

2016-03-08 22:17 - 2016-02-11 18:48 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll

2016-03-08 22:17 - 2016-02-11 18:48 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll

2016-03-08 22:17 - 2016-02-11 18:47 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll

2016-03-08 22:17 - 2016-02-11 18:45 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll

2016-03-08 22:17 - 2016-02-11 18:45 - 00312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll

2016-03-08 22:17 - 2016-02-11 18:45 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll

2016-03-08 22:17 - 2016-02-11 18:45 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll

2016-03-08 22:17 - 2016-02-11 18:44 - 03994560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe

2016-03-08 22:17 - 2016-02-11 18:44 - 03938240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe

2016-03-08 22:17 - 2016-02-11 18:44 - 01461248 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll

2016-03-08 22:17 - 2016-02-11 18:44 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll

2016-03-08 22:17 - 2016-02-11 18:44 - 00730112 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll

2016-03-08 22:17 - 2016-02-11 18:44 - 00422400 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll

2016-03-08 22:17 - 2016-02-11 18:42 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll

2016-03-08 22:17 - 2016-02-11 18:42 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll

2016-03-08 22:17 - 2016-02-11 18:42 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll

2016-03-08 22:17 - 2016-02-11 18:41 - 01314328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll

2016-03-08 22:17 - 2016-02-11 18:41 - 00880128 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll

2016-03-08 22:17 - 2016-02-11 18:41 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll

2016-03-08 22:17 - 2016-02-11 18:41 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll

2016-03-08 22:17 - 2016-02-11 18:41 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll

2016-03-08 22:17 - 2016-02-11 18:41 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll

2016-03-08 22:17 - 2016-02-11 18:41 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll

2016-03-08 22:17 - 2016-02-11 18:41 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll

2016-03-08 22:17 - 2016-02-11 18:41 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll

2016-03-08 22:17 - 2016-02-11 18:41 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll

2016-03-08 22:17 - 2016-02-11 18:41 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll

2016-03-08 22:17 - 2016-02-11 18:41 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll

2016-03-08 22:17 - 2016-02-11 18:41 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll

2016-03-08 22:17 - 2016-02-11 18:41 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll

2016-03-08 22:17 - 2016-02-11 18:41 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll

2016-03-08 22:17 - 2016-02-11 18:41 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll

2016-03-08 22:17 - 2016-02-11 18:41 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll

2016-03-08 22:17 - 2016-02-11 18:41 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll

2016-03-08 22:17 - 2016-02-11 18:41 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll

2016-03-08 22:17 - 2016-02-11 18:41 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll

2016-03-08 22:17 - 2016-02-11 18:41 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll

2016-03-08 22:17 - 2016-02-11 18:41 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll

2016-03-08 22:17 - 2016-02-11 18:41 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll

2016-03-08 22:17 - 2016-02-11 18:41 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll

2016-03-08 22:17 - 2016-02-11 18:41 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll

2016-03-08 22:17 - 2016-02-11 18:41 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll

2016-03-08 22:17 - 2016-02-11 18:41 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll

2016-03-08 22:17 - 2016-02-11 18:41 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll

2016-03-08 22:17 - 2016-02-11 18:41 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll

2016-03-08 22:17 - 2016-02-11 18:41 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll

2016-03-08 22:17 - 2016-02-11 18:41 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll

2016-03-08 22:17 - 2016-02-11 18:41 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll

2016-03-08 22:17 - 2016-02-11 18:38 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll

2016-03-08 22:17 - 2016-02-11 18:38 - 00665088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll

2016-03-08 22:17 - 2016-02-11 18:38 - 00275456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll

2016-03-08 22:17 - 2016-02-11 18:38 - 00171520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll

2016-03-08 22:17 - 2016-02-11 18:38 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll

2016-03-08 22:17 - 2016-02-11 18:38 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll

2016-03-08 22:17 - 2016-02-11 18:38 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll

2016-03-08 22:17 - 2016-02-11 18:37 - 00251392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll

2016-03-08 22:17 - 2016-02-11 18:37 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll

2016-03-08 22:17 - 2016-02-11 18:37 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll

2016-03-08 22:17 - 2016-02-11 18:35 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll

2016-03-08 22:17 - 2016-02-11 18:35 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll

2016-03-08 22:17 - 2016-02-11 18:35 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll

2016-03-08 22:17 - 2016-02-11 18:34 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll

2016-03-08 22:17 - 2016-02-11 18:33 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll

2016-03-08 22:17 - 2016-02-11 18:31 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll

2016-03-08 22:17 - 2016-02-11 18:30 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll

2016-03-08 22:17 - 2016-02-11 18:30 - 00642560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll

2016-03-08 22:17 - 2016-02-11 18:30 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll

2016-03-08 22:17 - 2016-02-11 18:30 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll

2016-03-08 22:17 - 2016-02-11 18:30 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll

2016-03-08 22:17 - 2016-02-11 18:30 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll

2016-03-08 22:17 - 2016-02-11 18:30 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll

2016-03-08 22:17 - 2016-02-11 18:30 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll

2016-03-08 22:17 - 2016-02-11 18:30 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll

2016-03-08 22:17 - 2016-02-11 18:30 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll

2016-03-08 22:17 - 2016-02-11 18:30 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll

2016-03-08 22:17 - 2016-02-11 18:30 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll

2016-03-08 22:17 - 2016-02-11 18:30 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll

2016-03-08 22:17 - 2016-02-11 18:30 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll

2016-03-08 22:17 - 2016-02-11 18:30 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll

2016-03-08 22:17 - 2016-02-11 18:30 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll

2016-03-08 22:17 - 2016-02-11 18:30 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll

2016-03-08 22:17 - 2016-02-11 18:30 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll

2016-03-08 22:17 - 2016-02-11 18:30 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll

2016-03-08 22:17 - 2016-02-11 18:30 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll

2016-03-08 22:17 - 2016-02-11 18:30 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll

2016-03-08 22:17 - 2016-02-11 18:30 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll

2016-03-08 22:17 - 2016-02-11 18:30 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll

2016-03-08 22:17 - 2016-02-11 18:30 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll

2016-03-08 22:17 - 2016-02-11 18:30 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll

2016-03-08 22:17 - 2016-02-11 18:30 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll

2016-03-08 22:17 - 2016-02-11 18:30 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll

2016-03-08 22:17 - 2016-02-11 17:48 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe

2016-03-08 22:17 - 2016-02-11 17:43 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe

2016-03-08 22:17 - 2016-02-11 17:41 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe

2016-03-08 22:17 - 2016-02-11 17:40 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe

2016-03-08 22:17 - 2016-02-11 17:34 - 00290816 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys

2016-03-08 22:17 - 2016-02-11 17:34 - 00159232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys

2016-03-08 22:17 - 2016-02-11 17:33 - 00129024 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys

2016-03-08 22:17 - 2016-02-11 17:32 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe

2016-03-08 22:17 - 2016-02-11 17:32 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe

2016-03-08 22:17 - 2016-02-11 17:32 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe

2016-03-08 22:17 - 2016-02-11 17:32 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll

2016-03-08 22:17 - 2016-02-11 17:32 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe

2016-03-08 22:17 - 2016-02-11 17:32 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe

2016-03-08 22:17 - 2016-02-11 17:31 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll

2016-03-08 22:17 - 2016-02-11 17:30 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll

2016-03-08 22:17 - 2016-02-11 17:30 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll

2016-03-08 22:17 - 2016-02-11 17:30 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll

2016-03-08 22:17 - 2016-02-11 17:30 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll

2016-03-08 22:17 - 2016-02-11 14:07 - 00689152 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll

2016-03-08 22:17 - 2016-02-09 09:57 - 14634496 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll

2016-03-08 22:17 - 2016-02-09 09:57 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL

2016-03-08 22:17 - 2016-02-09 09:56 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx

2016-03-08 22:17 - 2016-02-09 09:56 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll

2016-03-08 22:17 - 2016-02-09 09:55 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\seclogon.dll

2016-03-08 22:17 - 2016-02-09 09:54 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll

2016-03-08 22:17 - 2016-02-09 09:51 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL

2016-03-08 22:17 - 2016-02-09 09:51 - 11411456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll

2016-03-08 22:17 - 2016-02-09 09:13 - 00008192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\spwmp.dll

2016-03-08 22:17 - 2016-02-09 09:13 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdxm.ocx

2016-03-08 22:17 - 2016-02-09 09:13 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxmasf.dll

2016-03-08 22:17 - 2016-02-05 18:54 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll

2016-03-08 22:17 - 2016-02-05 18:54 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll

2016-03-08 22:17 - 2016-02-05 18:53 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll

2016-03-08 22:17 - 2016-02-05 18:53 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll

2016-03-08 22:17 - 2016-02-05 18:50 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll

2016-03-08 22:17 - 2016-02-05 18:44 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll

2016-03-08 22:17 - 2016-02-05 18:42 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll

2016-03-08 22:17 - 2016-02-05 17:48 - 00372736 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll

2016-03-08 22:17 - 2016-02-05 17:43 - 00299520 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll

2016-03-08 22:17 - 2016-02-05 17:43 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll

2016-03-08 22:17 - 2016-02-05 14:07 - 00696832 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll

2016-03-08 22:17 - 2016-02-05 14:07 - 00499200 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll

2016-03-08 22:17 - 2016-02-05 14:07 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll

2016-03-08 22:17 - 2016-02-05 01:19 - 00381440 _____ (Microsoft Corporation) C:\Windows\system32\mfds.dll

2016-03-08 22:17 - 2016-02-04 18:41 - 00296448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfds.dll

2016-03-08 21:17 - 2016-03-08 21:17 - 00336304 _____ C:\Users\Kalvin\Downloads\ECON3 January 2012 (3).pdf

2016-03-07 21:03 - 2016-03-07 21:03 - 00088821 _____ C:\Users\Kalvin\Downloads\The History Tutor Booking Form.pdf

2016-03-07 21:00 - 2016-03-07 21:00 - 00037695 _____ C:\Users\Kalvin\Downloads\2.htm

2016-03-07 20:43 - 2016-03-07 20:43 - 01028096 _____ C:\Users\Kalvin\Downloads\rev-June-12-Russian-and-Its-Rulers1 (1).ppt

2016-03-07 19:40 - 2016-03-07 19:40 - 00336304 _____ C:\Users\Kalvin\Downloads\ECON3 January 2012 (2).pdf

2016-03-07 15:43 - 2016-03-07 15:43 - 00001453 _____ C:\Users\Public\Desktop\iTunes.lnk

2016-03-07 15:43 - 2016-03-07 15:43 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes

2016-03-07 15:43 - 2016-03-07 15:43 - 00000000 ____D C:\Program Files\iPod

2016-03-07 15:43 - 2016-03-07 15:43 - 00000000 ____D C:\Program Files (x86)\iTunes

2016-03-07 15:42 - 2016-03-07 15:42 - 00000000 ____D C:\Windows\System32\Tasks\Apple

2016-03-07 15:42 - 2016-03-07 15:42 - 00000000 ____D C:\Program Files\Bonjour

2016-03-07 15:42 - 2016-03-07 15:42 - 00000000 ____D C:\Program Files (x86)\Bonjour

2016-03-07 15:42 - 2016-03-07 15:42 - 00000000 ____D C:\Program Files (x86)\Apple Software Update

2016-03-07 15:22 - 2016-03-07 15:22 - 01607168 _____ C:\Users\Kalvin\Downloads\Russia 1855-1964 pwg2015 (2).ppt

2016-03-07 15:19 - 2016-03-07 15:20 - 77713671 _____ C:\Users\Kalvin\Downloads\Russel Tarr INSET.zip

2016-03-07 15:11 - 2016-03-07 15:11 - 00074168 _____ C:\Users\Kalvin\Downloads\Government in Russia- by function (4).pptx

2016-03-07 15:07 - 2016-03-07 15:07 - 01028096 _____ C:\Users\Kalvin\Downloads\rev-June-12-Russian-and-Its-Rulers1.ppt

2016-03-07 15:03 - 2016-03-07 15:03 - 00729088 _____ C:\Users\Kalvin\Downloads\revMay11_russia1 (4).ppt

2016-03-07 15:03 - 2016-03-07 15:03 - 00729088 _____ C:\Users\Kalvin\Downloads\revMay11_russia1 (3).ppt

2016-03-07 13:11 - 2016-03-07 13:11 - 00106220 _____ C:\Users\Kalvin\Downloads\Russia-Overview (5).pptx

2016-03-07 12:34 - 2016-03-07 12:34 - 01830508 _____ C:\Users\Kalvin\Downloads\2015 A Level and IB Summer Reading Guide.pdf

2016-03-07 12:29 - 2016-03-07 12:29 - 02715313 _____ C:\Users\Kalvin\Downloads\PGS Sixth Form Prospectus 2015.pdf

2016-03-07 12:27 - 2016-03-07 12:27 - 00000000 _____ C:\Users\Kalvin\Downloads\network_file.phtml

2016-03-07 12:27 - 2016-03-07 12:27 - 00000000 _____ C:\Users\Kalvin\Downloads\network_file (1).phtml

2016-03-07 11:55 - 2016-03-07 11:55 - 00106220 _____ C:\Users\Kalvin\Downloads\Russia-Overview (4).pptx

2016-03-07 11:07 - 2016-03-07 11:07 - 00222221 _____ C:\Users\Kalvin\Downloads\Smith Yearbook Photos 2016.pdf

2016-03-06 22:50 - 2016-03-06 22:50 - 04941312 _____ ( ) C:\Users\Kalvin\Downloads\chilDefense alpha test 0.something low.exe

2016-03-06 20:28 - 2016-03-06 20:28 - 00000099 ____H C:\Users\Kalvin\Downloads\.~lock.History Revision to put on mp3 (1).doc#

2016-03-06 18:03 - 2016-03-06 18:03 - 00106220 _____ C:\Users\Kalvin\Downloads\Russia-Overview (3).pptx

2016-03-06 18:03 - 2016-03-06 18:03 - 00000099 ____H C:\Users\Kalvin\Downloads\.~lock.Russia-Overview (3).pptx#

2016-03-06 18:01 - 2016-03-06 18:01 - 00330752 _____ C:\Users\Kalvin\Downloads\Themes Planning.ppt

2016-03-06 17:17 - 2016-03-06 17:17 - 00000099 ____H C:\Users\Kalvin\Downloads\.~lock.past papers by theme (1).docx#

2016-03-06 17:04 - 2016-03-06 17:04 - 00000099 ____H C:\Users\Kalvin\Downloads\.~lock.Russia 1855-1964 revision guide and past questions PWG 2015 (2).doc#

2016-03-06 16:57 - 2016-03-06 16:57 - 02193719 _____ C:\Users\Kalvin\Downloads\EM PeriodStudy Jan 2010.pdf

2016-03-06 16:56 - 2016-03-06 16:56 - 01656865 _____ C:\Users\Kalvin\Downloads\Russian themes exemplar June 2010 (2).pdf

2016-03-06 16:49 - 2016-03-06 16:49 - 00729088 _____ C:\Users\Kalvin\Downloads\revMay11_russia1 (2).ppt

2016-03-06 15:50 - 2016-03-06 15:50 - 00729088 _____ C:\Users\Kalvin\Downloads\revMay11_russia1 (1).ppt

2016-03-06 15:06 - 2016-03-06 15:06 - 00087253 _____ C:\Users\Kalvin\Downloads\Change in Russian Government (1).pptx

2016-03-06 15:06 - 2016-03-06 15:06 - 00069303 _____ C:\Users\Kalvin\Downloads\The communist rulers were effective autocrats (3).pptx

2016-03-06 15:05 - 2016-03-06 15:05 - 00415506 _____ C:\Users\Kalvin\Downloads\Nature of Government (2).pptx

2016-03-06 15:04 - 2016-03-06 15:04 - 00452608 _____ C:\Users\Kalvin\Downloads\Government and People (2).ppt

2016-03-06 15:03 - 2016-03-06 15:03 - 01632256 _____ C:\Users\Kalvin\Downloads\A level History 2013.ppt

2016-03-06 15:03 - 2016-03-06 15:03 - 00415506 _____ C:\Users\Kalvin\Downloads\Nature of Government (1).pptx

2016-03-06 15:02 - 2016-03-06 15:02 - 00074107 _____ C:\Users\Kalvin\Downloads\Government in Russia- by function (3).pptx

2016-03-06 15:01 - 2016-03-06 15:01 - 00452608 _____ C:\Users\Kalvin\Downloads\Government and People (1).ppt

2016-03-06 14:52 - 2016-03-06 14:52 - 01607168 _____ C:\Users\Kalvin\Downloads\Russia 1855-1964 pwg2015 (1).ppt

2016-03-06 14:50 - 2016-03-06 14:50 - 02159984 _____ C:\Users\Kalvin\Downloads\3_sources analysis on Alexander III.pdf

2016-03-06 14:50 - 2016-03-06 14:50 - 00074168 _____ C:\Users\Kalvin\Downloads\Government in Russia- by function (2).pptx

2016-03-06 14:45 - 2016-03-06 14:45 - 00091658 _____ C:\Users\Kalvin\Downloads\Russian Government – Turning Points (3).pptx

2016-03-06 14:42 - 2016-03-06 14:42 - 00452608 _____ C:\Users\Kalvin\Downloads\Government and People.ppt

2016-03-06 14:42 - 2016-03-06 14:42 - 00074168 _____ C:\Users\Kalvin\Downloads\Government in Russia- by function (1).pptx

2016-03-06 14:42 - 2016-03-06 14:42 - 00050030 _____ C:\Users\Kalvin\Downloads\Govt Tsarist and Soviet Russia.pptx

2016-03-06 14:41 - 2016-03-06 14:41 - 00070264 _____ C:\Users\Kalvin\Downloads\Turning Points - Political (1).pptx

2016-03-06 14:36 - 2016-03-06 14:36 - 00091658 _____ C:\Users\Kalvin\Downloads\Russian Government – Turning Points (2).pptx

2016-03-06 14:35 - 2016-03-06 14:35 - 00087253 _____ C:\Users\Kalvin\Downloads\Change in Russian Government.pptx

2016-03-06 14:34 - 2016-03-06 14:34 - 00069303 _____ C:\Users\Kalvin\Downloads\The communist rulers were effective autocrats (2).pptx

2016-03-06 14:34 - 2016-03-06 14:34 - 00069303 _____ C:\Users\Kalvin\Downloads\The communist rulers were effective autocrats (1).pptx

2016-03-06 13:55 - 2016-03-06 13:55 - 00074168 _____ C:\Users\Kalvin\Downloads\Government in Russia- by function.pptx

2016-03-06 13:52 - 2016-03-06 13:52 - 00415506 _____ C:\Users\Kalvin\Downloads\Nature of Government.pptx

2016-03-06 13:49 - 2016-03-06 13:49 - 00086935 _____ C:\Users\Kalvin\Downloads\Russia, 1855-1964- Opposition.pptx

2016-03-06 13:45 - 2016-03-06 13:45 - 00079171 _____ C:\Users\Kalvin\Downloads\Autocracy.pptx

2016-03-06 13:43 - 2016-03-06 13:43 - 00091658 _____ C:\Users\Kalvin\Downloads\Russian Government – Turning Points (1).pptx

2016-03-06 13:43 - 2016-03-06 13:43 - 00070264 _____ C:\Users\Kalvin\Downloads\Turning Points - Political.pptx

2016-03-06 13:40 - 2016-03-06 13:40 - 00091658 _____ C:\Users\Kalvin\Downloads\Russian Government – Turning Points.pptx

2016-03-06 13:39 - 2016-03-06 13:39 - 00069303 _____ C:\Users\Kalvin\Downloads\The communist rulers were effective autocrats.pptx

2016-03-06 13:35 - 2016-03-06 13:35 - 01817462 _____ C:\Users\Kalvin\Downloads\Tsar Nicholas II.pptx

2016-03-06 13:32 - 2016-03-06 13:32 - 00213504 _____ C:\Users\Kalvin\Downloads\_Thumbs.db

2016-03-06 13:32 - 2016-03-06 13:32 - 00011960 _____ C:\Users\Kalvin\Downloads\timeline.notebook

2016-03-05 22:23 - 2016-03-05 22:23 - 00842866 _____ C:\Users\Kalvin\Downloads\rev-june-12-russian-and-its-rulers1.pptx

2016-03-05 19:47 - 2016-03-05 19:47 - 00336304 _____ C:\Users\Kalvin\Downloads\ECON3 January 2012 (1).pdf

2016-03-05 19:36 - 2016-03-05 19:37 - 00670720 _____ C:\Users\Kalvin\Downloads\Scheme of Work Master.xls

2016-03-05 19:29 - 2016-03-05 19:29 - 00097338 _____ C:\Users\Kalvin\Downloads\AQA-ECON3-W-MS-JAN_12_[1] (2).pdf

2016-03-02 23:56 - 2016-03-02 23:56 - 00729088 _____ C:\Users\Kalvin\Downloads\revMay11_russia1.ppt

2016-03-02 19:22 - 2016-03-02 19:23 - 80174088 _____ C:\Users\Kalvin\Downloads\Ace_Stream_Media_3.1.2_VLC_1.1.12.exe

2016-03-02 19:15 - 2016-03-02 19:15 - 00000584 _____ C:\Users\Kalvin\Downloads\url.htm

2016-03-01 17:04 - 2016-03-01 17:06 - 118399958 _____ C:\Users\Kalvin\Downloads\TheShreddedChef (1).pdf

2016-02-28 19:49 - 2016-02-28 19:49 - 00000099 ____H C:\Users\Kalvin\Downloads\.~lock.2016 PGS Yearbook and Leavers Book Questions (2).docx#

2016-02-28 14:12 - 2016-02-28 14:13 - 80174088 _____ C:\Users\Kalvin\Downloads\Unconfirmed 735721.crdownload

2016-02-28 09:53 - 2016-02-28 09:53 - 15177663 _____ C:\Users\Kalvin\Downloads\CHAT LOGS.rar

2016-02-25 20:22 - 2016-02-25 20:23 - 80174088 _____ C:\Users\Kalvin\Downloads\Unconfirmed 760231.crdownload

2016-02-23 23:21 - 2016-02-23 23:21 - 00344099 _____ C:\Users\Kalvin\Downloads\wage_differentials_and_wage_discrimination (1).pptx

2016-02-23 23:19 - 2016-02-23 23:19 - 01055519 _____ C:\Users\Kalvin\Downloads\Wage Differentials.pdf

2016-02-23 23:19 - 2016-02-23 23:19 - 00344099 _____ C:\Users\Kalvin\Downloads\wage_differentials_and_wage_discrimination.pptx

2016-02-23 22:36 - 2016-02-23 22:36 - 00270392 _____ C:\Users\Kalvin\Downloads\6EC03 June 2010 MS.pdf

2016-02-23 22:34 - 2016-02-23 22:34 - 00411452 _____ C:\Users\Kalvin\Downloads\ECON3 June 2010.pdf

2016-02-23 22:14 - 2016-02-23 22:14 - 00037707 _____ C:\Users\Kalvin\Downloads\00 MJW A2 economics micro Unit 3 homework tasks 2015-16.xlsx

2016-02-23 20:11 - 2016-02-23 20:11 - 00000000 _____ C:\Users\Kalvin\Downloads\Unconfirmed 386187.crdownload

 

==================== One Month Modified files and folders ========

 

(If an entry is included in the fixlist, the file/folder will be moved.)

 

2016-03-22 10:48 - 2009-07-14 05:13 - 00781790 _____ C:\Windows\system32\PerfStringBackup.INI

2016-03-22 10:48 - 2009-07-14 03:20 - 00000000 ____D C:\Windows\inf

2016-03-22 10:42 - 2015-09-08 21:09 - 00000000 ___RD C:\Users\Kalvin\Google Drive

2016-03-22 10:42 - 2015-07-24 21:33 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update

2016-03-22 10:42 - 2015-07-24 20:57 - 00000000 ____D C:\Users\Kalvin\AppData\Roaming\Raptr

2016-03-22 10:42 - 2015-07-24 20:02 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job

2016-03-22 10:42 - 2009-07-14 05:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT

2016-03-22 00:35 - 2015-07-24 20:02 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job

2016-03-21 21:17 - 2009-07-14 04:45 - 00021872 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0

2016-03-21 21:17 - 2009-07-14 04:45 - 00021872 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0

2016-03-21 19:54 - 2015-08-16 12:35 - 00000000 ____D C:\Users\Kalvin\AppData\Roaming\.ACEStream

2016-03-21 19:54 - 2015-08-16 12:34 - 00000000 ____D C:\Users\Kalvin\AppData\Roaming\ACEStream

2016-03-21 17:27 - 2015-07-25 00:17 - 00000000 ____D C:\Users\Kalvin\AppData\Local\Spotify

2016-03-21 17:27 - 2015-07-24 22:22 - 00000000 ____D C:\Users\Kalvin\AppData\Roaming\Skype

2016-03-21 17:23 - 2015-07-25 00:16 - 00000000 ____D C:\Users\Kalvin\AppData\Roaming\Spotify

2016-03-20 12:09 - 2015-07-24 21:34 - 00000000 ____D C:\Users\Kalvin\AppData\Roaming\Riot Games

2016-03-15 19:36 - 2015-07-24 20:03 - 00002195 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk

2016-03-15 19:36 - 2015-07-24 20:03 - 00002183 _____ C:\Users\Public\Desktop\Google Chrome.lnk

2016-03-14 18:47 - 2016-02-16 13:17 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft

2016-03-14 18:47 - 2016-02-16 13:16 - 00000000 ____D C:\Program Files (x86)\Microsoft Office

2016-03-12 17:50 - 2009-07-14 03:20 - 00000000 ____D C:\Windows\rescache

2016-03-10 21:40 - 2015-09-08 20:28 - 00002042 _____ C:\Users\Public\Desktop\Google Slides.lnk

2016-03-10 21:40 - 2015-09-08 20:28 - 00002040 _____ C:\Users\Public\Desktop\Google Sheets.lnk

2016-03-10 21:40 - 2015-09-08 20:28 - 00002030 _____ C:\Users\Public\Desktop\Google Docs.lnk

2016-03-10 21:40 - 2015-09-08 20:28 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive

2016-03-10 16:11 - 2009-07-14 04:45 - 00375312 _____ C:\Windows\system32\FNTCACHE.DAT

2016-03-08 22:44 - 2015-07-25 11:03 - 00000000 ____D C:\Windows\system32\MRT

2016-03-08 22:43 - 2015-07-25 12:47 - 00000000 ____D C:\Windows\system32\appraiser

2016-03-08 22:43 - 2015-07-25 11:03 - 143659408 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe

2016-03-08 19:45 - 2015-07-24 21:33 - 00000000 ____D C:\ProgramData\Skype

2016-03-07 15:43 - 2015-09-13 15:49 - 00000000 ____D C:\Users\Kalvin\AppData\Roaming\Apple Computer

2016-03-07 15:43 - 2015-09-13 15:49 - 00000000 ____D C:\Program Files\Common Files\Apple

2016-03-07 15:42 - 2015-09-13 15:49 - 00002519 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk

2016-03-04 16:13 - 2015-07-25 04:25 - 00000000 ____D C:\Windows\Panther

2016-03-02 16:58 - 2015-07-30 15:12 - 00003414 _____ C:\Windows\System32\Tasks\GyazoUpdateTaskMachineDaily

2016-03-02 16:58 - 2015-07-30 15:12 - 00003288 _____ C:\Windows\System32\Tasks\GyazoUpdateTaskMachine

2016-03-02 16:58 - 2015-07-30 15:12 - 00000000 ____D C:\Program Files (x86)\Gyazo

2016-02-26 22:43 - 2015-07-25 21:00 - 00000000 ___SD C:\Windows\SysWOW64\GWX

2016-02-26 22:43 - 2015-07-25 21:00 - 00000000 ___SD C:\Windows\system32\GWX

 

==================== Files in the root of some directories =======

 

2016-03-20 15:12 - 2016-03-20 15:12 - 21572120 _____ (LastPass) C:\Program Files (x86)\Common Files\lpuninstall.exe

2015-09-28 21:15 - 2015-09-28 21:15 - 0000057 _____ () C:\ProgramData\Ament.ini

2015-07-24 20:32 - 2015-07-24 20:32 - 0000000 ____H () C:\ProgramData\DP45977C.lfl

2016-02-16 12:14 - 2016-02-16 12:14 - 0000000 _____ () C:\ProgramData\mitmtest-service.log

 

Some files in TEMP:

====================

C:\Users\Kalvin\AppData\Local\Temp\dllnt_dump.dll

C:\Users\Kalvin\AppData\Local\Temp\sqlite3.dll

 

==================== Bamital & volsnap =================

 

(There is no automatic fix for files that do not pass verification.)

 

C:\Windows\system32\winlogon.exe => File is digitally signed

C:\Windows\system32\wininit.exe => File is digitally signed

C:\Windows\SysWOW64\wininit.exe => File is digitally signed

C:\Windows\explorer.exe => File is digitally signed

C:\Windows\SysWOW64\explorer.exe => File is digitally signed

C:\Windows\system32\svchost.exe => File is digitally signed

C:\Windows\SysWOW64\svchost.exe => File is digitally signed

C:\Windows\system32\services.exe => File is digitally signed

C:\Windows\system32\User32.dll => File is digitally signed

C:\Windows\SysWOW64\User32.dll => File is digitally signed

C:\Windows\system32\userinit.exe => File is digitally signed

C:\Windows\SysWOW64\userinit.exe => File is digitally signed

C:\Windows\system32\rpcss.dll => File is digitally signed

C:\Windows\system32\dnsapi.dll => File is digitally signed

C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed

C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed

 

LastRegBack: 2016-03-21 16:57

 

==================== End of FRST.txt ============================

Additional scan result of Farbar Recovery Scan Tool (x64) Version:05-03-2016 01

Ran by Kalvin (2016-03-22 10:48:27)

Running from C:\Users\Kalvin\Downloads

Windows 7 Home Premium Service Pack 1 (X64) (2015-07-24 19:32:01)

Boot Mode: Normal

==========================================================

 

==================== Accounts: =============================

 

Administrator (S-1-5-21-3803452205-4226285346-3461252913-500 - Administrator - Disabled)

Guest (S-1-5-21-3803452205-4226285346-3461252913-501 - Limited - Disabled)

Kalvin (S-1-5-21-3803452205-4226285346-3461252913-1000 - Administrator - Enabled) => C:\Users\Kalvin

 

==================== Security Center ========================

 

(If an entry is included in the fixlist, it will be removed.)

 

AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}

AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}

 

==================== Installed Programs ======================

 

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

 

AMD Catalyst Install Manager (HKLM\...\{F37078EA-4B6A-1D6F-6FED-3EDF2117B42C}) (Version: 8.0.916.0 - Advanced Micro Devices, Inc.)

Apple Application Support (32-bit) (HKLM-x32\...\{7FA9ECCF-A2DE-4DA1-BFF3-81260DBDA68F}) (Version: 4.1.2 - Apple Inc.)

Apple Application Support (64-bit) (HKLM\...\{691F30EB-9009-475A-B8A9-E1BF39598FD5}) (Version: 4.1.2 - Apple Inc.)

Apple Mobile Device Support (HKLM\...\{3540181E-340A-4E7A-B409-31663472B2F7}) (Version: 9.1.0.6 - Apple Inc.)

Apple Software Update (HKLM-x32\...\{FFD1F7F1-1AC9-4BC4-A908-0686D635ABAF}) (Version: 2.1.4.131 - Apple Inc.)

ARK: Survival Evolved (HKLM-x32\...\Steam App 346110) (Version:  - Studio Wildcard)

Avast Free Antivirus (HKLM-x32\...\Avast) (Version: 11.1.2241 - AVAST Software)

Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)

ESET Online Scanner v3 (HKLM-x32\...\ESET Online Scanner) (Version:  - )

Google Chrome (HKLM-x32\...\Google Chrome) (Version: 49.0.2623.87 - Google Inc.)

Google Drive (HKLM-x32\...\{895D0391-459F-4D45-B8DD-13F0DE70C66E}) (Version: 1.28.1549.1322 - Google, Inc.)

Google Update Helper (x32 Version: 1.3.29.5 - Google Inc.) Hidden

Gyazo 3.2.1 (HKLM-x32\...\{6DB8C365-E719-4BA5-9594-10DFC244D3FD}_is1) (Version:  - Nota Inc.)

HP ENVY 4500 series Basic Device Software (HKLM\...\{6915424E-704F-4F5D-9057-9C7B406B36DB}) (Version: 32.3.198.49673 - Hewlett-Packard Co.)

HP ENVY 4500 series Help (HKLM-x32\...\{95BECC50-22B4-4FCA-8A2E-BF77713E6D3A}) (Version: 30.0.0 - Hewlett Packard)

HP Photo Creations (HKLM-x32\...\HP Photo Creations) (Version: 1.0.0.7702 - HP)

HP Update (HKLM-x32\...\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)

Intel® Chipset Device Software (x32 Version: 10.0.27 - Intel® Corporation) Hidden

Intel® USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 3.0.5.69 - Intel Corporation)

iTunes (HKLM\...\{FBEB98F8-64E4-4FA3-A15E-4A9F42FF962E}) (Version: 12.3.2.35 - Apple Inc.)

LastPass (uninstall only) (HKLM-x32\...\LastPass) (Version:  - LastPass)

LibreOffice 5.0.3.2 (HKLM-x32\...\{D61E7AA0-0380-49B9-8DDD-7685E2306176}) (Version: 5.0.3.2 - The Document Foundation)

Logitech Gaming Software 8.70 (HKLM\...\Logitech Gaming Software) (Version: 8.70.315 - Logitech Inc.)

Malwarebytes Anti-Malware version 2.2.1.1043 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes)

Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)

Microsoft OneNote Home and Student 2016 - en-us (HKLM\...\OneNoteFreeRetail - en-us) (Version: 16.0.6568.2036 - Microsoft Corporation)

Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)

Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)

Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)

Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)

Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)

Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)

Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)

Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)

Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)

Microsoft Xbox 360 Accessories 1.2 (HKLM\...\{D9C50188-12D5-4D3E-8F00-682346C2AA5F}) (Version: 1.20.146.0 - Microsoft)

Microsoft XNA Framework Redistributable 4.0 (HKLM-x32\...\{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}) (Version: 4.0.20823.0 - Microsoft Corporation)

Mozilla Firefox 43.0.1 (x86 en-GB) (HKLM-x32\...\Mozilla Firefox 43.0.1 (x86 en-GB)) (Version: 43.0.1 - Mozilla)

Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 41.0.2.5765 - Mozilla)

MP3 Skype recorder (HKLM-x32\...\{DBB52EA7-3390-4764-8CFE-6CF7541FA7FD}) (Version: 4.19.1.0 - Domit LTD)

NVIDIA PhysX (HKLM-x32\...\{B455E95A-B804-439F-B533-336B1635AE97}) (Version: 9.14.0702 - NVIDIA Corporation)

Office 16 Click-to-Run Extensibility Component (x32 Version: 16.0.6528.1017 - Microsoft Corporation) Hidden

Office 16 Click-to-Run Licensing Component (Version: 16.0.6528.1017 - Microsoft Corporation) Hidden

Office 16 Click-to-Run Localization Component (x32 Version: 16.0.6528.1017 - Microsoft Corporation) Hidden

Open Broadcaster Software (HKLM-x32\...\Open Broadcaster Software) (Version:  - )

Platform (x32 Version: 1.42 - VIA Technologies, Inc.) Hidden

Product Improvement Study for HP ENVY 4500 series (HKLM\...\{58139103-BACF-4BDC-B71C-955F9164ADA6}) (Version: 32.3.198.49673 - Hewlett-Packard Co.)

Raptr (HKLM-x32\...\Raptr) (Version:  - )

Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7534 - Realtek Semiconductor Corp.)

Rocket League (HKLM-x32\...\Steam App 252950) (Version:  - Psyonix)

RogueKiller version 12 (HKLM\...\8B3D7924-ED89-486B-8322-E8594065D5CB_is1) (Version: 12 - Adlice Software)

Skype™ 7.18 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.18.112 - Skype Technologies S.A.)

Spotify (HKU\S-1-5-21-3803452205-4226285346-3461252913-1000\...\Spotify) (Version: 1.0.25.127.g58007b4c - Spotify AB)

Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)

TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.16 - TeamSpeak Systems GmbH)

Terraria (HKLM-x32\...\Steam App 105600) (Version:  - Re-Logic)

TP-LINK TL-WN781ND Driver (HKLM-x32\...\{87C7B472-9BC2-43C8-9F03-86D2908E1A51}) (Version: 1.3.1 - TP-LINK)

VIA Platform Device Manager (HKLM-x32\...\InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}) (Version: 1.42 - VIA Technologies, Inc.)

WinRAR 5.21 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.21.0 - win.rar GmbH)

 

==================== Custom CLSID (Whitelisted): ==========================

 

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

 

==================== Scheduled Tasks (Whitelisted) =============

 

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

 

Task: {07654EF7-FDF4-4F07-9831-53E19EB7FD7D} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2016-02-28] (Microsoft Corporation)

Task: {0F2F6ED7-3CF2-4825-9157-F656BFDB79A3} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-07-24] (Google Inc.)

Task: {2A98561C-D2E8-47DA-A1D4-82F20663FF64} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2015-11-06] (AVAST Software)

Task: {30E714AF-2D18-4746-8C8E-DB20BC226400} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2016-02-28] (Microsoft Corporation)

Task: {37947409-391F-4AAD-A0C5-26518350049A} - System32\Tasks\HPCustParticipation HP ENVY 4500 series => C:\Program Files\HP\HP ENVY 4500 series\Bin\HPCustPartic.exe [2014-07-21] (Hewlett-Packard Development Company, LP)

Task: {5CB82ECC-3240-458F-A655-E13EC256940B} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-07-24] (Google Inc.)

Task: {8DD0DFA4-A44B-4BC6-9C28-9EA79FD39DA9} - System32\Tasks\CANCEL g2a Shield

Task: {9D297286-87D4-4A2B-8A59-15FEA18909A4} - System32\Tasks\GyazoUpdateTaskMachineDaily => C:\Program Files (x86)\Gyazo\GyazoUpdate.exe [2016-02-17] ()

Task: {AB85FCB6-E3B8-481C-B9A1-60D133D78462} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe [2016-03-05] (AVAST Software)

Task: {AF9532C6-CF5B-4A95-A970-A3C9B4F78B14} - System32\Tasks\GyazoUpdateTaskMachine => C:\Program Files (x86)\Gyazo\GyazoUpdate.exe [2016-02-17] ()

Task: {C0F6434B-E3C6-4E5D-9247-4065067BDEB1} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2015-08-27] (Apple Inc.)

 

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

 

Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

 

==================== Shortcuts =============================

 

(The entries could be listed to be restored or removed.)

 

==================== Loaded Modules (Whitelisted) ==============

 

2015-05-15 15:26 - 2015-05-15 15:26 - 00085832 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll

2015-12-17 18:38 - 2015-12-17 18:38 - 01328912 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll

2016-02-16 13:16 - 2016-02-28 02:20 - 00173248 _____ () C:\Program Files\Common Files\Microsoft Shared\ClickToRun\ApiClient.dll

2016-03-14 18:46 - 2016-02-28 10:22 - 08914120 _____ () C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\1033\GrooveIntlResource.dll

2015-03-07 00:07 - 2015-03-07 00:07 - 00908568 _____ () C:\Program Files\Logitech Gaming Software\libGLESv2.dll

2015-07-02 00:28 - 2015-07-02 00:28 - 01095448 _____ () C:\Program Files\Logitech Gaming Software\platforms\qwindows.dll

2015-03-07 00:07 - 2015-03-07 00:07 - 00060184 _____ () C:\Program Files\Logitech Gaming Software\libEGL.dll

2015-07-02 00:28 - 2015-07-02 00:28 - 00240408 _____ () C:\Program Files\Logitech Gaming Software\imageformats\qjpeg.dll

2015-11-06 19:22 - 2015-11-06 19:22 - 00103888 _____ () C:\Program Files\AVAST Software\Avast\log.dll

2015-11-06 19:22 - 2015-11-06 19:22 - 00125512 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll

2016-03-21 21:10 - 2016-03-21 21:10 - 02856960 _____ () C:\Program Files\AVAST Software\Avast\defs\16032102\algo.dll

2015-11-06 19:22 - 2015-11-06 19:22 - 00466448 _____ () C:\Program Files\AVAST Software\Avast\ffl2.dll

2016-03-22 10:42 - 2016-03-22 10:42 - 02857472 _____ () C:\Program Files\AVAST Software\Avast\defs\16032200\algo.dll

2010-11-22 22:56 - 2010-11-22 22:56 - 00043008 _____ () C:\Program Files (x86)\Raptr\_socket.pyd

2010-11-22 22:56 - 2010-11-22 22:56 - 00805376 _____ () C:\Program Files (x86)\Raptr\_ssl.pyd

2010-11-22 22:57 - 2010-11-22 22:57 - 00096256 _____ () C:\Program Files (x86)\Raptr\win32api.pyd

2010-11-22 22:56 - 2010-11-22 22:56 - 00110592 _____ () C:\Program Files (x86)\Raptr\pywintypes26.dll

2010-11-22 22:57 - 2010-11-22 22:57 - 00017920 _____ () C:\Program Files (x86)\Raptr\win32event.pyd

2010-11-22 22:57 - 2010-11-22 22:57 - 00036352 _____ () C:\Program Files (x86)\Raptr\win32process.pyd

2014-05-13 23:26 - 2014-05-13 23:26 - 01662464 _____ () C:\Program Files (x86)\Raptr\PyQt4.QtCore.pyd

2014-05-13 23:26 - 2014-05-13 23:26 - 00067584 _____ () C:\Program Files (x86)\Raptr\sip.pyd

2014-05-13 23:26 - 2014-05-13 23:26 - 05812736 _____ () C:\Program Files (x86)\Raptr\PyQt4.QtGui.pyd

2010-11-22 22:56 - 2010-11-22 22:56 - 00356864 _____ () C:\Program Files (x86)\Raptr\_hashlib.pyd

2010-11-22 22:56 - 2010-11-22 22:56 - 00087040 _____ () C:\Program Files (x86)\Raptr\_ctypes.pyd

2010-11-22 22:57 - 2010-11-22 22:57 - 00111104 _____ () C:\Program Files (x86)\Raptr\win32file.pyd

2016-03-22 10:42 - 2016-03-22 10:42 - 00098816 _____ () C:\Users\Kalvin\AppData\Local\Temp\_MEI31442\win32api.pyd

2016-03-22 10:42 - 2016-03-22 10:42 - 00110080 _____ () C:\Users\Kalvin\AppData\Local\Temp\_MEI31442\pywintypes27.dll

2016-03-22 10:42 - 2016-03-22 10:42 - 00364544 _____ () C:\Users\Kalvin\AppData\Local\Temp\_MEI31442\pythoncom27.dll

2016-03-22 10:42 - 2016-03-22 10:42 - 00320512 _____ () C:\Users\Kalvin\AppData\Local\Temp\_MEI31442\win32com.shell.shell.pyd

2016-03-22 10:42 - 2016-03-22 10:42 - 00776704 _____ () C:\Users\Kalvin\AppData\Local\Temp\_MEI31442\_hashlib.pyd

2016-03-22 10:42 - 2016-03-22 10:42 - 01176576 _____ () C:\Users\Kalvin\AppData\Local\Temp\_MEI31442\wx._core_.pyd

2016-03-22 10:42 - 2016-03-22 10:42 - 00806400 _____ () C:\Users\Kalvin\AppData\Local\Temp\_MEI31442\wx._gdi_.pyd

2016-03-22 10:42 - 2016-03-22 10:42 - 00816128 _____ () C:\Users\Kalvin\AppData\Local\Temp\_MEI31442\wx._windows_.pyd

2016-03-22 10:42 - 2016-03-22 10:42 - 01067008 _____ () C:\Users\Kalvin\AppData\Local\Temp\_MEI31442\wx._controls_.pyd

2016-03-22 10:42 - 2016-03-22 10:42 - 00733184 _____ () C:\Users\Kalvin\AppData\Local\Temp\_MEI31442\wx._misc_.pyd

2016-03-22 10:42 - 2016-03-22 10:42 - 00682496 _____ () C:\Users\Kalvin\AppData\Local\Temp\_MEI31442\pysqlite2._sqlite.pyd

2016-03-22 10:42 - 2016-03-22 10:42 - 00088064 _____ () C:\Users\Kalvin\AppData\Local\Temp\_MEI31442\_ctypes.pyd

2016-03-22 10:42 - 2016-03-22 10:42 - 00119808 _____ () C:\Users\Kalvin\AppData\Local\Temp\_MEI31442\win32file.pyd

2016-03-22 10:42 - 2016-03-22 10:42 - 00108544 _____ () C:\Users\Kalvin\AppData\Local\Temp\_MEI31442\win32security.pyd

2016-03-22 10:42 - 2016-03-22 10:42 - 00007168 _____ () C:\Users\Kalvin\AppData\Local\Temp\_MEI31442\hashobjs_ext.pyd

2016-03-22 10:42 - 2016-03-22 10:42 - 00017920 _____ () C:\Users\Kalvin\AppData\Local\Temp\_MEI31442\thumbnails_ext.pyd

2016-03-22 10:42 - 2016-03-22 10:42 - 00088064 _____ () C:\Users\Kalvin\AppData\Local\Temp\_MEI31442\usb_ext.pyd

2016-03-22 10:42 - 2016-03-22 10:42 - 00167936 _____ () C:\Users\Kalvin\AppData\Local\Temp\_MEI31442\win32gui.pyd

2016-03-22 10:42 - 2016-03-22 10:42 - 00018432 _____ () C:\Users\Kalvin\AppData\Local\Temp\_MEI31442\win32event.pyd

2016-03-22 10:42 - 2016-03-22 10:42 - 00046080 _____ () C:\Users\Kalvin\AppData\Local\Temp\_MEI31442\_socket.pyd

2016-03-22 10:42 - 2016-03-22 10:42 - 01208320 _____ () C:\Users\Kalvin\AppData\Local\Temp\_MEI31442\_ssl.pyd

2016-03-22 10:42 - 2016-03-22 10:42 - 00128512 _____ () C:\Users\Kalvin\AppData\Local\Temp\_MEI31442\_elementtree.pyd

2016-03-22 10:42 - 2016-03-22 10:42 - 00127488 _____ () C:\Users\Kalvin\AppData\Local\Temp\_MEI31442\pyexpat.pyd

2016-03-22 10:42 - 2016-03-22 10:42 - 00013824 _____ () C:\Users\Kalvin\AppData\Local\Temp\_MEI31442\common.time34.pyd

2016-03-22 10:42 - 2016-03-22 10:42 - 00038912 _____ () C:\Users\Kalvin\AppData\Local\Temp\_MEI31442\win32inet.pyd

2016-03-22 10:42 - 2016-03-22 10:42 - 00036864 _____ () C:\Users\Kalvin\AppData\Local\Temp\_MEI31442\_psutil_windows.pyd

2016-03-22 10:42 - 2016-03-22 10:42 - 00525208 _____ () C:\Users\Kalvin\AppData\Local\Temp\_MEI31442\windows._lib_cacheinvalidation.pyd

2016-03-22 10:42 - 2016-03-22 10:42 - 00011264 _____ () C:\Users\Kalvin\AppData\Local\Temp\_MEI31442\win32crypt.pyd

2016-03-22 10:42 - 2016-03-22 10:42 - 00077312 _____ () C:\Users\Kalvin\AppData\Local\Temp\_MEI31442\wx._html2.pyd

2016-03-22 10:42 - 2016-03-22 10:42 - 00027136 _____ () C:\Users\Kalvin\AppData\Local\Temp\_MEI31442\_multiprocessing.pyd

2016-03-22 10:42 - 2016-03-22 10:42 - 00020480 _____ () C:\Users\Kalvin\AppData\Local\Temp\_MEI31442\_yappi.pyd

2016-03-22 10:42 - 2016-03-22 10:42 - 00035840 _____ () C:\Users\Kalvin\AppData\Local\Temp\_MEI31442\win32process.pyd

2016-03-22 10:42 - 2016-03-22 10:42 - 00686080 _____ () C:\Users\Kalvin\AppData\Local\Temp\_MEI31442\unicodedata.pyd

2016-03-22 10:42 - 2016-03-22 10:42 - 00078848 _____ () C:\Users\Kalvin\AppData\Local\Temp\_MEI31442\wx._animate.pyd

2016-03-22 10:42 - 2016-03-22 10:42 - 00123392 _____ () C:\Users\Kalvin\AppData\Local\Temp\_MEI31442\wx._wizard.pyd

2016-03-22 10:42 - 2016-03-22 10:42 - 00024064 _____ () C:\Users\Kalvin\AppData\Local\Temp\_MEI31442\win32pipe.pyd

2016-03-22 10:42 - 2016-03-22 10:42 - 00010240 _____ () C:\Users\Kalvin\AppData\Local\Temp\_MEI31442\select.pyd

2016-03-22 10:42 - 2016-03-22 10:42 - 00025600 _____ () C:\Users\Kalvin\AppData\Local\Temp\_MEI31442\win32pdh.pyd

2016-03-22 10:42 - 2016-03-22 10:42 - 00017408 _____ () C:\Users\Kalvin\AppData\Local\Temp\_MEI31442\win32profile.pyd

2016-03-22 10:42 - 2016-03-22 10:42 - 00022528 _____ () C:\Users\Kalvin\AppData\Local\Temp\_MEI31442\win32ts.pyd

2015-07-24 21:33 - 2015-07-24 21:33 - 40540672 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll

2015-07-24 20:58 - 2014-02-10 12:44 - 04592128 _____ () C:\Users\Kalvin\AppData\Local\Google\Chrome\User Data\SwiftShader\3.2.6.45159\libglesv2.dll

2015-07-24 20:58 - 2014-02-10 12:44 - 00112128 _____ () C:\Users\Kalvin\AppData\Local\Google\Chrome\User Data\SwiftShader\3.2.6.45159\libegl.dll

 

==================== Alternate Data Streams (Whitelisted) =========

 

(If an entry is included in the fixlist, only the ADS will be removed.)

 

==================== Safe Mode (Whitelisted) ===================

 

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

 

==================== EXE Association (Whitelisted) ===============

 

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)

 

==================== Internet Explorer trusted/restricted ===============

 

(If an entry is included in the fixlist, it will be removed from the registry.)

 

==================== Hosts content: ===============================

 

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

 

2009-07-14 02:34 - 2009-06-10 21:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts

 

==================== Other Areas ============================

 

(Currently there is no automatic fix for this section.)

 

HKU\S-1-5-21-3803452205-4226285346-3461252913-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Kalvin\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg

DNS Servers: 192.168.1.254

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)

Windows Firewall is enabled.

 

==================== MSCONFIG/TASK MANAGER disabled items ==

 

(Currently there is no automatic fix for this section.)

 

==================== FirewallRules (Whitelisted) ===============

 

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

 

FirewallRules: [{E0004880-6413-4F28-B59A-831579B5F817}] => (Allow) D:\Steam\Steam.exe

FirewallRules: [{52DA725F-1AAA-4A5E-9C82-C1C6463B4179}] => (Allow) D:\Steam\Steam.exe

FirewallRules: [{458FF570-4F7C-497A-8DD8-6923D621E864}] => (Allow) D:\Steam\bin\steamwebhelper.exe

FirewallRules: [{DAAC66DD-8186-4EE5-BFC4-921F3C102178}] => (Allow) D:\Steam\bin\steamwebhelper.exe

FirewallRules: [{BB0A656D-B2B1-4E99-9AE5-E20A43B9574C}] => (Allow) D:\Steam\steamapps\common\Terraria\Terraria.exe

FirewallRules: [{3F104BAE-AEE1-4297-97C7-8257EAF676AF}] => (Allow) D:\Steam\steamapps\common\Terraria\Terraria.exe

FirewallRules: [TCP Query User{E214551E-707E-41EE-91D0-9DC3858009EA}C:\program files\logitech gaming software\lcore.exe] => (Allow) C:\program files\logitech gaming software\lcore.exe

FirewallRules: [UDP Query User{91E01A1E-5EE0-40BB-B207-8A9FA8E2EAFD}C:\program files\logitech gaming software\lcore.exe] => (Allow) C:\program files\logitech gaming software\lcore.exe

FirewallRules: [TCP Query User{034045E1-29CB-4E42-8749-452C7B94DA32}C:\users\kalvin\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\kalvin\appdata\roaming\spotify\spotify.exe

FirewallRules: [UDP Query User{3B6B9E86-4344-4A06-8CFC-37D29F5E22F9}C:\users\kalvin\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\kalvin\appdata\roaming\spotify\spotify.exe

FirewallRules: [{005DF6D8-F5C4-4CFC-984B-BF1E7D44CACB}] => (Allow) D:\Steam\steamapps\common\ARK\ShooterGame\Binaries\Win64\ShooterGame.exe

FirewallRules: [{4E852D26-D52A-4298-8131-814852D9D94B}] => (Allow) D:\Steam\steamapps\common\ARK\ShooterGame\Binaries\Win64\ShooterGame.exe

FirewallRules: [{93C24220-BA13-4A61-8AF5-D044F876A4C6}] => (Allow) D:\Battle.net\Battle.net.exe

FirewallRules: [{959224BF-DAE3-4A96-8509-90037E350DA5}] => (Allow) D:\Battle.net\Battle.net.exe

FirewallRules: [TCP Query User{D2954DFE-D17E-4923-92DD-43021F1706A4}C:\program files (x86)\heroes of the storm\versions\base36144\heroesofthestorm_x64.exe] => (Allow) C:\program files (x86)\heroes of the storm\versions\base36144\heroesofthestorm_x64.exe

FirewallRules: [UDP Query User{1D203EB1-C489-46A4-849D-2FCA08133065}C:\program files (x86)\heroes of the storm\versions\base36144\heroesofthestorm_x64.exe] => (Allow) C:\program files (x86)\heroes of the storm\versions\base36144\heroesofthestorm_x64.exe

FirewallRules: [TCP Query User{1418704F-2DC8-4592-94D3-5AC08421308E}C:\users\kalvin\appdata\roaming\acestream\engine\ace_engine.exe] => (Allow) C:\users\kalvin\appdata\roaming\acestream\engine\ace_engine.exe

FirewallRules: [UDP Query User{654AD7AF-0282-4966-80F9-828D8FC94072}C:\users\kalvin\appdata\roaming\acestream\engine\ace_engine.exe] => (Allow) C:\users\kalvin\appdata\roaming\acestream\engine\ace_engine.exe

FirewallRules: [TCP Query User{82778381-C662-433F-84AA-310A4B940BB2}C:\users\kalvin\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\kalvin\appdata\roaming\spotify\spotify.exe

FirewallRules: [UDP Query User{B918F93A-F9EA-4BF7-B16F-4FE5E3F65A85}C:\users\kalvin\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\kalvin\appdata\roaming\spotify\spotify.exe

FirewallRules: [{7330D490-9DE5-49F2-9A69-809052362769}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe

FirewallRules: [{DE3F4D41-070A-4506-BEF8-AF1B422A2E01}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe

FirewallRules: [TCP Query User{416DF86E-BA4A-4C3C-8A5B-FE8EF847AB75}C:\program files\logitech gaming software\lcore.exe] => (Allow) C:\program files\logitech gaming software\lcore.exe

FirewallRules: [UDP Query User{9EBCA4A6-7AB5-43B0-AE74-EF6185D09DE1}C:\program files\logitech gaming software\lcore.exe] => (Allow) C:\program files\logitech gaming software\lcore.exe

FirewallRules: [{720559D0-15FA-4622-83AC-5ADFA6CF327D}] => (Allow) C:\Users\Kalvin\AppData\Local\Temp\7zS118E\HPDiagnosticCoreUI.exe

FirewallRules: [{13EE1CC8-0818-4019-9C37-8C6077E787B6}] => (Allow) C:\Users\Kalvin\AppData\Local\Temp\7zS118E\HPDiagnosticCoreUI.exe

FirewallRules: [{F21E88C5-D40B-4538-B754-43A4D80CDDA3}] => (Allow) C:\Program Files\HP\HP ENVY 4500 series\Bin\DeviceSetup.exe

FirewallRules: [{0256D662-3DA2-4029-934C-DF3374AF7E76}] => (Allow) LPort=5357

FirewallRules: [{2BA22561-E259-4E45-815F-058DD83D0244}] => (Allow) C:\Program Files\HP\HP ENVY 4500 series\Bin\HPNetworkCommunicatorCom.exe

FirewallRules: [TCP Query User{15215EB4-0E60-410B-99D9-CB8C256D03F4}C:\users\kalvin\downloads\lolskinview\lolskinview.exe] => (Allow) C:\users\kalvin\downloads\lolskinview\lolskinview.exe

FirewallRules: [UDP Query User{6512A671-056F-4AB4-BB7D-2504917AF346}C:\users\kalvin\downloads\lolskinview\lolskinview.exe] => (Allow) C:\users\kalvin\downloads\lolskinview\lolskinview.exe

FirewallRules: [{90C56D25-D8C7-4E47-8D4F-5AF5261DDF81}] => (Allow) C:\Program Files\AVAST Software\Avast\ng\vbox\aswFe.exe

FirewallRules: [{64381A12-95C8-478F-9182-59484EB5FAEE}] => (Allow) C:\Program Files\AVAST Software\Avast\ng\vbox\aswFe.exe

FirewallRules: [TCP Query User{291C99B5-A537-468F-A435-133D9FF213E8}C:\users\kalvin\appdata\roaming\acestream\engine\ace_engine.exe] => (Block) C:\users\kalvin\appdata\roaming\acestream\engine\ace_engine.exe

FirewallRules: [UDP Query User{36AB8D07-0B89-45E7-88ED-77F03CABF1C2}C:\users\kalvin\appdata\roaming\acestream\engine\ace_engine.exe] => (Block) C:\users\kalvin\appdata\roaming\acestream\engine\ace_engine.exe

FirewallRules: [{E4BBB176-BE19-43DE-85FA-8BAFC48CBAE5}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe

FirewallRules: [{2493F413-8D50-4C25-974B-AD7B7D086663}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe

FirewallRules: [{FDC2EE2C-B397-40BC-BD4C-B80FB32DB860}] => (Allow) C:\Program Files (x86)\Raptr\raptr.exe

FirewallRules: [{4DED1A70-BC06-4613-89DD-BB0B16A32416}] => (Allow) C:\Program Files (x86)\Raptr\raptr.exe

FirewallRules: [{0CA4EDC3-27D9-4885-99F4-6A582F78397C}] => (Allow) C:\Program Files (x86)\Raptr\raptr_im.exe

FirewallRules: [{B82D7860-E484-4954-8A39-FC8680782F6F}] => (Allow) C:\Program Files (x86)\Raptr\raptr_im.exe

FirewallRules: [{798A8424-F16F-4581-8F1D-2C79E349C592}] => (Allow) D:\Steam\steamapps\common\rocketleague\Binaries\Win32\RocketLeague.exe

FirewallRules: [{4919080C-F79A-4CE6-8F47-1FA55B7106C5}] => (Allow) D:\Steam\steamapps\common\rocketleague\Binaries\Win32\RocketLeague.exe

FirewallRules: [{C37C3C69-8E09-427B-BBC1-3365BF012B5C}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe

FirewallRules: [{4C69B527-3F6B-4E9C-A0C4-AC4E6C1B78AD}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe

FirewallRules: [{695E6D47-4B1A-471B-91FF-6B007196DE62}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe

FirewallRules: [{702C22C2-304C-4487-9101-FCEC51231A23}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe

FirewallRules: [{E9957859-13D4-46A7-A0EC-93976A85E920}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe

FirewallRules: [{79D3FF59-E542-45E5-BB7F-63FDE1C3F87B}] => (Allow) D:\Itunes\iTunes.exe

FirewallRules: [{0FA36369-139E-4AEB-A06E-D9A73C805EB2}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

 

==================== Restore Points =========================

 

21-03-2016 20:25:01 Scheduled Checkpoint

21-03-2016 21:53:42 JRT Pre-Junkware Removal

21-03-2016 21:59:42 JRT Pre-Junkware Removal

 

==================== Faulty Device Manager Devices =============

 

Name:

Description:

Class Guid:

Manufacturer:

Service:

Problem: : The drivers for this device are not installed. (Code 28)

Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

 

Name: Ethernet Controller

Description: Ethernet Controller

Class Guid:

Manufacturer:

Service:

Problem: : The drivers for this device are not installed. (Code 28)

Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

 

==================== Event log errors: =========================

 

Application errors:

==================

Error: (03/22/2016 10:42:43 AM) (Source: Bonjour Service) (EventID: 100) (User: )

Description: Local Hostname Kalvin-PC.local already in use; will try Kalvin-PC-2.local instead

 

Error: (03/22/2016 10:42:43 AM) (Source: Bonjour Service) (EventID: 100) (User: )

Description: mDNSCoreReceiveResponse: ProbeCount 2; will deregister    4 Kalvin-PC.local. Addr 192.168.1.148

 

Error: (03/22/2016 10:42:43 AM) (Source: Bonjour Service) (EventID: 100) (User: )

Description: mDNSCoreReceiveResponse: Received from 192.168.1.64:5353    4 kalvin-PC.local. Addr 192.168.1.64

 

Error: (03/22/2016 10:42:41 AM) (Source: WinMgmt) (EventID: 10) (User: )

Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

 

Error: (03/21/2016 11:13:39 PM) (Source: SideBySide) (EventID: 80) (User: )

Description: Activation context generation failed for "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest1".Error in manifest or policy file "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest2" on line C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest3.

A component version required by the application conflicts with another component version already active.

Conflicting components are:.

Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest.

Component 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d.manifest.

 

Error: (03/21/2016 11:13:39 PM) (Source: SideBySide) (EventID: 80) (User: )

Description: Activation context generation failed for "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest1".Error in manifest or policy file "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest2" on line C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest3.

A component version required by the application conflicts with another component version already active.

Conflicting components are:.

Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest.

Component 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d.manifest.

 

Error: (03/21/2016 10:04:18 PM) (Source: SideBySide) (EventID: 80) (User: )

Description: Activation context generation failed for "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest1".Error in manifest or policy file "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest2" on line C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest3.

A component version required by the application conflicts with another component version already active.

Conflicting components are:.

Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757.manifest.

Component 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_41e855142bd5705d.manifest.

 

Error: (03/21/2016 09:09:15 PM) (Source: WinMgmt) (EventID: 10) (User: )

Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

 

Error: (03/21/2016 07:55:01 PM) (Source: WinMgmt) (EventID: 10) (User: )

Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

 

Error: (03/21/2016 06:23:42 PM) (Source: Bonjour Service) (EventID: 100) (User: )

Description: Task Scheduling Error: m->NextScheduledSPRetry 29001

 

System errors:

=============

Error: (03/22/2016 10:43:55 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)

Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)

 

Error: (03/22/2016 10:42:42 AM) (Source: NetBT) (EventID: 4321) (User: )

Description: The name "KALVIN-PC      :20" could not be registered on the interface with IP address 192.168.1.148.

The computer with the IP address 192.168.1.64 did not allow the name to be claimed by

this computer.

 

Error: (03/22/2016 10:42:42 AM) (Source: NetBT) (EventID: 4321) (User: )

Description: The name "KALVIN-PC      :0" could not be registered on the interface with IP address 192.168.1.148.

The computer with the IP address 192.168.1.64 did not allow the name to be claimed by

this computer.

 

Error: (03/22/2016 10:42:42 AM) (Source: Server) (EventID: 2505) (User: )

Description: The server could not bind to the transport \Device\NetBT_Tcpip_{AEBC8276-2431-4B4B-9D2C-89089913ADAA} because another computer on the network has the same name.  The server could not start.

 

Error: (03/21/2016 11:11:16 PM) (Source: Service Control Manager) (EventID: 7000) (User: )

Description: The eapihdrv service failed to start due to the following error:

%%1275

 

Error: (03/21/2016 11:11:16 PM) (Source: Application Popup) (EventID: 1060) (User: )

Description: \??\C:\Users\Kalvin\AppData\Local\Temp\ehdrv.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.

 

Error: (03/21/2016 11:11:15 PM) (Source: Service Control Manager) (EventID: 7000) (User: )

Description: The eapihdrv service failed to start due to the following error:

%%1275

 

Error: (03/21/2016 11:11:15 PM) (Source: Application Popup) (EventID: 1060) (User: )

Description: \??\C:\Users\Kalvin\AppData\Local\Temp\ehdrv.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.

 

Error: (03/21/2016 11:11:15 PM) (Source: Service Control Manager) (EventID: 7000) (User: )

Description: The eapihdrv service failed to start due to the following error:

%%1275

 

Error: (03/21/2016 11:11:15 PM) (Source: Application Popup) (EventID: 1060) (User: )

Description: \??\C:\Users\Kalvin\AppData\Local\Temp\ehdrv.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.

 

CodeIntegrity:

===================================

 Date: 2015-07-25 11:30:26.279

 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files\Logitech Gaming Software\Drivers\LgCoreTemp\LgCoreTemp.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

 

 Date: 2015-07-25 11:30:26.232

 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files\Logitech Gaming Software\Drivers\LgCoreTemp\LgCoreTemp.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

 

 Date: 2015-07-25 11:30:20.356

 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\drivers\LGBusEnum.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

 

 Date: 2015-07-25 11:30:20.356

 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\drivers\LGBusEnum.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

 

 Date: 2015-07-25 11:10:45.558

 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files\Logitech Gaming Software\Drivers\LgCoreTemp\LgCoreTemp.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

 

 Date: 2015-07-25 11:10:45.508

 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files\Logitech Gaming Software\Drivers\LgCoreTemp\LgCoreTemp.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

 

 Date: 2015-07-25 11:10:40.464

 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\drivers\LGBusEnum.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

 

 Date: 2015-07-25 11:10:40.464

 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\drivers\LGBusEnum.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

 

 Date: 2015-07-25 01:24:45.557

 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files\Logitech Gaming Software\Drivers\LgCoreTemp\LgCoreTemp.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

 

 Date: 2015-07-25 01:24:45.537

 Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files\Logitech Gaming Software\Drivers\LgCoreTemp\LgCoreTemp.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

 

==================== Memory info ===========================

 

Processor: Intel® Core™ i5-4590 CPU @ 3.30GHz

Percentage of memory in use: 45%

Total physical RAM: 8134.52 MB

Available physical RAM: 4452.96 MB

Total Virtual: 16267.25 MB

Available Virtual: 12594.98 MB

 

==================== Drives ================================

 

Drive c: () (Fixed) (Total:232.79 GB) (Free:18.85 GB) NTFS

Drive d: (Kalvins stuff) (Fixed) (Total:931.39 GB) (Free:780.29 GB) NTFS

 

==================== MBR & Partition Table ==================

 

========================================================

Disk: 0 (MBR Code: Windows 7 or 8) (Size: 232.9 GB) (Disk ID: 4E378C44)

Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)

Partition 2: (Not Active) - (Size=232.8 GB) - (Type=07 NTFS)

 

========================================================

Disk: 1 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 00000000)

 

Partition: GPT.

 

==================== End of Addition.txt ============================

 

Attached Files



#6 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 37,033 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:04:19 AM

Posted 22 March 2016 - 09:16 AM

Greetings,

We should only have one open topic so I will close this and leave you in boopme's capable hands.
Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#7 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 37,033 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:04:19 AM

Posted 22 March 2016 - 09:16 AM

It appears that this issue is resolved, therefore I am closing the topic. If that is not the case and you need or wish to continue with this topic, please send me or any Moderator a Personal Message (PM) that you would like this topic re-opened.
Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users