Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Urgent malware issues


  • This topic is locked This topic is locked
56 replies to this topic

#1 willyman18

willyman18

  • Members
  • 66 posts
  • OFFLINE
  •  
  • Local time:04:44 AM

Posted 25 March 2016 - 04:23 PM

Hello
My computer keeps installing a lot of programs without me telling it to do so.
I am really worried could you please help me?

BC AdBot (Login to Remove)

 


#2 pystryker

pystryker

  • Malware Response Team
  • 730 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:10:44 PM

Posted 25 March 2016 - 08:01 PM

Hello and welcome to Bleeping Computer! My nickname is Pystryker :) , and I will be helping you with your issue today.


Before we get started, I have a few things I need to go over with you
  • If you are receiving help for this issue at another forum, please let me know so I can close this thread.
  • Please download to and run all requested tools from your Desktop.
  • Please do not install any new software during the cleaning process other than the tools I provide for you. This can hinder the cleaning process.
  • At the top of your post, please click on the "Follow this topic" button and make sure that the "Received notification" box is checked and set to "Instantly" This will send an email to you as soon as I reply to your topic, allowing us to solve your problem faster.
  • If any of your security programs give you a warning about any tool I ask you to use, please do not worry. All the links and tools I provide to you will be safe.
  • Please do not run any tools other than the ones I ask you to, when I ask you to. Some of these tools can be very dangerous if used improperly. Also, if you use a tool that I have not requested you use, it can cause false positives, thereby delaying the complete cleaning of your machine.
  • This is a complicated process. It requires several steps, patience, and careful following of my instructions in the order they are given to diagnose your problems to get your machine back in working order.
  • Please stay with me until the end of all steps and procedures and I declare your system clean. Just because there is a lack of symptoms does not indicate a clean machine. I promise to do the same for you.
  • It is impossible for me to know what interactions may happen between your computer's software and the tools we will use to clean your machine. Therefore, I highly recommend you backup any critical personal files on your machine before we start.
  • If you have any questions at all, please don't hesitate to ask. There's no such thing as a stupid question when dealing with malware.
  • If you are unsure of an instruction I give you, or if something unexepected occurs, Do NOT proceed! Stop and ask for clarification of the instruction or tell me what occurred.
  • Please remember, the fixes are for your machine and your machine ONLY! Do not use these fixes on any other machine, each fix is tailor made for your system only. Using a fix on another machine can and will cause serious damage.
  • Once we have cleaned your machine, we'll have some cleanup and prevention steps to go through. We will also provide you with some information about how to reduce your chances of infection and get some protections in place to help defend you against this in the future
  • Please be patient while I am analyzing your logs. I know you are probably scared and very frustrated with this problem, but I am a volunteer and sometimes life does get in the way. :)
Now, let's get started, shall we? :thumbsup:


Please download Farbar Recovery Scan Tool and save it to your Desktop.

Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
  • Right click to run as administrator (XP users click run after receipt of Windows Security Warning - Open File). When the tool opens click Yes to disclaimer.
  • Place a check in the box marked Addition.txt

    farbarmainpanel_zps77bf9e25.jpg
  • Press Scan button.
  • It will produce a log called FRST.txt in the same directory the tool is run from.
  • Please copy and paste log back here.
  • The first time the tool is run it generates another log (Addition.txt - also located in the same directory as FRST.exe/FRST64.exe). Please also paste that along with the FRST.txt into your reply.
Things I need to see in your next post:

Please post each of these logs as a separate reply in this thread.

FRST Log

Addition.txt Log

I close my topics if there is no response after 3 days. Please PM a moderator or myself to reopen your topic.

Please PM me only if I'm helping you with your computer issues and I have not responded in 2 days. Please remember, I'm a volunteer and sometimes life does get in the way. :)

Please stay with me until I declare your machine clean. Absence of symptoms does not ensure your machine is clean.

If you'd like to make a donation via Paypal, please click here.





#3 willyman18

willyman18
  • Topic Starter

  • Members
  • 66 posts
  • OFFLINE
  •  
  • Local time:04:44 AM

Posted 26 March 2016 - 06:52 AM

For some reason I cannot load up any websites and I keep getting pop ups saying update now which I am not clicking.
One of the pop ups said it has stopped me from using any browsers

#4 willyman18

willyman18
  • Topic Starter

  • Members
  • 66 posts
  • OFFLINE
  •  
  • Local time:04:44 AM

Posted 26 March 2016 - 07:02 AM

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:05-03-2016 01
Ran by willi (administrator) on WINDOWS-J2K2PN4 (26-03-2016 11:55:15)
Running from F:\willi
Loaded Profiles: willi (Available Profiles: willi)
Platform: Windows 10 Home Version 1511 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA) C:\Program Files (x86)\NVIDIA Corporation\nTune\nTuneService.exe
(DTS, Inc) C:\Program Files\Realtek\Audio\HDA\DTSU2PAuSrv64.exe
() C:\Program Files (x86)\ASUS\AXSP\1.02.00\atkexComSvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\asww10mon.exe
() C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
() C:\Users\willi\AppData\Local\SunnyDay13\usun.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
() C:\Users\willi\AppData\Roaming\cpuminer\cpm.exe
(Nota Inc.) C:\Program Files (x86)\Gyazo\GyStation.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Curse, Inc) C:\Users\willi\AppData\Roaming\Curse Client\Bin\Curse.exe
() C:\Program Files\Scan 3XS\menu.exe
() C:\Program Files (x86)\SunnyDay13\SunnyDay.exe
() C:\Program Files (x86)\rec_gb_236\rec_gb_236.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Curse, Inc.) C:\Users\willi\AppData\Roaming\Curse Client\Bin\Electron\CurseUI.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Intel Corporation) C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
(Intel Corporation) C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
(Microsoft Corporation) C:\Windows\System32\Taskmgr.exe
(Avast Software) C:\Program Files\AVAST Software\SZBrowser\1.48.2066.44\SZBrowser.exe
(Avast Software) C:\Program Files\AVAST Software\SZBrowser\1.48.2066.44\SZBrowser_crashreporter.exe
(Avast Software) C:\Program Files\AVAST Software\SZBrowser\1.48.2066.44\SZBrowser.exe
(Avast Software) C:\Program Files\AVAST Software\SZBrowser\1.48.2066.44\SZBrowser.exe
(Avast Software) C:\Program Files\AVAST Software\SZBrowser\1.48.2066.44\SZBrowser.exe
(Avast Software) C:\Program Files\AVAST Software\SZBrowser\1.48.2066.44\SZBrowser.exe
(Avast Software) C:\Program Files\AVAST Software\SZBrowser\1.48.2066.44\SZBrowser.exe
(Avast Software) C:\Program Files\AVAST Software\SZBrowser\1.48.2066.44\SZBrowser.exe
(Avast Software) C:\Program Files\AVAST Software\SZBrowser\1.48.2066.44\SZBrowser.exe
(Avast Software) C:\Program Files\AVAST Software\SZBrowser\1.48.2066.44\SZBrowser.exe
(Avast Software) C:\Program Files\AVAST Software\SZBrowser\1.48.2066.44\SZBrowser.exe
(Avast Software) C:\Program Files\AVAST Software\SZBrowser\1.48.2066.44\SZBrowser.exe
(Avast Software) C:\Program Files\AVAST Software\SZBrowser\1.48.2066.44\SZBrowser.exe
(Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
() C:\Program Files\AVAST Software\Avast\avastnm.exe
(Avast Software) C:\Program Files\AVAST Software\SZBrowser\1.48.2066.44\SZBrowser.exe
(Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
() C:\Program Files\AVAST Software\Avast\avastnm.exe
(Avast Software) C:\Program Files\AVAST Software\SZBrowser\1.48.2066.44\SZBrowser.exe
(Avast Software) C:\Program Files\AVAST Software\SZBrowser\1.48.2066.44\SZBrowser.exe
(Avast Software) C:\Program Files\AVAST Software\SZBrowser\1.48.2066.44\SZBrowser.exe
(Avast Software) C:\Program Files\AVAST Software\SZBrowser\1.48.2066.44\SZBrowser.exe
(Avast Software) C:\Program Files\AVAST Software\SZBrowser\1.48.2066.44\SZBrowser.exe
(Avast Software) C:\Program Files\AVAST Software\SZBrowser\1.48.2066.44\SZBrowser.exe
(Avast Software) C:\Program Files\AVAST Software\SZBrowser\1.48.2066.44\SZBrowser.exe
(Avast Software) C:\Program Files\AVAST Software\SZBrowser\1.48.2066.44\SZBrowser.exe
(Avast Software) C:\Program Files\AVAST Software\SZBrowser\1.48.2066.44\SZBrowser.exe
(Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
(Avast Software) C:\Program Files\AVAST Software\SZBrowser\1.48.2066.44\SZBrowser.exe
() C:\Program Files\AVAST Software\Avast\avastnm.exe
(Avast Software) C:\Program Files\AVAST Software\SZBrowser\1.48.2066.44\SZBrowser.exe
(Avast Software) C:\Program Files\AVAST Software\SZBrowser\1.48.2066.44\SZBrowser.exe
 
 
==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [ScanMenu] => C:\Program Files\Scan 3XS\menu.exe [1197568 2015-12-10] ()
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe [322472 2015-06-23] (Intel Corporation)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8484056 2015-06-12] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_DTS] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1393880 2015-04-28] (Realtek Semiconductor)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2789248 2016-02-17] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => "C:\windows\system32\rundll32.exe" C:\windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [cpuminer] => C:\Users\willi\AppData\Roaming\cpuminer\cpm.exe [1417216 2016-02-29] ()
HKLM-x32\...\Run: [ScanMenu] => C:\Program Files\Scan 3XS\menu.exe [1197568 2015-12-10] ()
HKLM-x32\...\Run: [win_en_77] => [X]
HKLM-x32\...\Run: [sun13] => C:\Program Files (x86)\SunnyDay13\SunnyDay.exe [4055728 2016-03-24] ()
HKLM-x32\...\Run: [rec_gb_236] => C:\Program Files (x86)\rec_gb_236\rec_gb_236.exe [4054704 2016-03-23] ()
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [7139256 2016-03-25] (AVAST Software)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [596016 2016-01-29] (Oracle Corporation)
HKLM-x32\...\RunOnce: [usun.exe] => C:\Users\willi\AppData\Local\SunnyDay13\usun.exe [3247280 2016-03-24] ()
HKU\S-1-5-21-3667704814-1699542734-850788743-1002\...\Run: [Steam] => F:\programs\steam\steam.exe [3074128 2016-03-10] (Valve Corporation)
HKU\S-1-5-21-3667704814-1699542734-850788743-1002\...\Run: [Gyazo] => C:\Program Files (x86)\Gyazo\GyStation.exe [3586848 2016-02-17] (Nota Inc.)
HKU\S-1-5-21-3667704814-1699542734-850788743-1002\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [50670720 2016-03-01] (Skype Technologies S.A.)
HKU\S-1-5-21-3667704814-1699542734-850788743-1002\...\Run: [NVIDIA nTune] => C:\Program Files (x86)\NVIDIA Corporation\nTune\nTuneCmd.exe [98304 2007-09-04] (NVIDIA)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2016-03-25] (AVAST Software)
Startup: C:\Users\willi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Curse.lnk [2016-03-25]
ShortcutTarget: Curse.lnk -> C:\Users\willi\AppData\Roaming\Curse Client\Bin\Curse.exe (Curse, Inc)
Startup: C:\Users\willi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CurseClientStartup.ccip [2016-01-01] ()
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Winsock: Catalog9-x64 01 C:\windows\system32\zdengine64.dll [341670 2016-03-25] (zdengine)
Winsock: Catalog9-x64 02 C:\windows\system32\zdengine64.dll [341670 2016-03-25] (zdengine)
Winsock: Catalog9-x64 03 C:\windows\system32\zdengine64.dll [341670 2016-03-25] (zdengine)
Winsock: Catalog9-x64 04 C:\windows\system32\zdengine64.dll [341670 2016-03-25] (zdengine)
Winsock: Catalog9-x64 16 C:\windows\system32\zdengine64.dll [341670 2016-03-25] (zdengine)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\Parameters: [NameServer] 8.8.8.8,8.8.8.4
Tcpip\..\Interfaces\{b583a9b8-65ca-463c-8fc0-15a808345548}: [DhcpNameServer] 192.168.0.1
ManualProxies: 
 
Internet Explorer:
==================
HKU\S-1-5-21-3667704814-1699542734-850788743-1002\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.scan.co.uk
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_74\bin\ssv.dll [2016-03-26] (Oracle Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2016-03-25] (AVAST Software)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_74\bin\jp2ssv.dll [2016-03-26] (Oracle Corporation)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> F:\Program Files (x86)\bin\ssv.dll => No File
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2016-03-25] (AVAST Software)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> F:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> F:\Program Files (x86)\bin\jp2ssv.dll => No File
 
FireFox:
========
FF Plugin: @java.com/DTPlugin,version=11.74.2 -> C:\Program Files\Java\jre1.8.0_74\bin\dtplugin\npDeployJava1.dll [2016-03-26] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.74.2 -> C:\Program Files\Java\jre1.8.0_74\bin\plugin2\npjp2.dll [2016-03-26] (Oracle Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll [2014-04-03] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2014-04-03] (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.66.2 -> F:\Program Files (x86)\bin\dtplugin\npDeployJava1.dll [No File]
FF Plugin-x32: @java.com/JavaPlugin,version=11.66.2 -> F:\Program Files (x86)\bin\plugin2\npjp2.dll [No File]
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> F:\Program Files (x86)\Microsoft Office\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> F:\Program Files (x86)\Microsoft Office\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-03-05] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-03-05] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> f:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-01-21] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.2 -> f:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-01-21] (VideoLAN)
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2016-03-25]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
 
Chrome: 
=======
CHR HomePage: Profile 1 -> hxxp://www-searching.com/?s=G3Ozftpbl0cshmoBD,0fcbd9b9-0d39-4234-9c15-2195883a9a88,&prd=smw
CHR StartupUrls: Profile 1 -> "hxxp://www-searching.com/?s=G3Ozftpbl0cshmoBD,0fcbd9b9-0d39-4234-9c15-2195883a9a88,&prd=smw"
CHR DefaultSearchURL: Profile 1 -> hxxp://www-searching.com/search.aspx?s=G3Ozftpbl0cshmoBD,0fcbd9b9-0d39-4234-9c15-2195883a9a88,&prd=smw&q={searchTerms}
CHR DefaultSearchKeyword: Profile 1 -> www-searching.com
CHR DefaultSuggestURL: Profile 1 -> hxxp://api.searchpredict.com/api/?rqtype=ffplugin&siteID=8661&dbCode=1&command={searchTerms}
CHR Profile: C:\Users\willi\AppData\Local\Google\Chrome\User Data\Default
CHR Profile: C:\Users\willi\AppData\Local\Google\Chrome\User Data\Profile 1
CHR Extension: (Google Slides) - C:\Users\willi\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-01-15]
CHR Extension: (Google Docs) - C:\Users\willi\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2016-01-15]
CHR Extension: (Google Drive) - C:\Users\willi\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-01-15]
CHR Extension: (YouTube) - C:\Users\willi\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-01-15]
CHR Extension: (Adblock Plus) - C:\Users\willi\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2016-03-09]
CHR Extension: (Google Search) - C:\Users\willi\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2016-01-15]
CHR Extension: (Google Sheets) - C:\Users\willi\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-01-15]
CHR Extension: (Google Docs Offline) - C:\Users\willi\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-15]
CHR Extension: (Chrome Web Store Payments) - C:\Users\willi\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-01-15]
CHR Extension: (Gmail) - C:\Users\willi\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-01-15]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2016-03-25]
 
==================== Services (Whitelisted) ========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 asComSvc; C:\Program Files (x86)\ASUS\AXSP\1.02.00\atkexComSvc.exe [936728 2013-07-04] ()
U2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [237096 2016-03-25] (AVAST Software)
R2 DTSAudioSvc; C:\Program Files\Realtek\Audio\HDA\DTSU2PAuSrv64.exe [240576 2013-10-07] (DTS, Inc)
S3 Futuremark SystemInfo Service; C:\Program Files (x86)\Futuremark\SystemInfo\FMSISvc.exe [342240 2015-11-05] (Futuremark)
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1164672 2016-02-17] (NVIDIA Corporation)
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [18856 2015-06-23] (Intel Corporation)
S3 Intel® Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [887232 2014-01-31] (Intel® Corporation)
R2 Intel® ME Service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe [131544 2014-04-03] (Intel Corporation)
S3 iumsvc; C:\Program Files (x86)\Intel\Intel® Update Manager\bin\iumsvc.exe [178312 2015-09-25] (Intel Corporation)
S2 jhi_service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe [154584 2014-04-03] (Intel Corporation)
R2 nTuneService; C:\Program Files (x86)\NVIDIA Corporation\nTune\nTuneService.exe [180224 2007-09-04] (NVIDIA) [File not signed]
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1880960 2016-02-17] (NVIDIA Corporation)
R3 NvStreamNetworkSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [6474112 2016-02-17] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [2609024 2016-02-17] (NVIDIA Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2015-10-30] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-10-30] (Microsoft Corporation)
 
===================== Drivers (Whitelisted) ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [15232 2013-07-04] ()
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [37656 2016-03-25] (AVAST Software)
R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [37144 2016-03-26] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [107792 2016-03-25] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [103064 2016-03-25] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [74544 2016-03-25] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1070904 2016-03-25] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [463744 2016-03-25] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [165344 2016-03-25] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [287016 2016-03-25] (AVAST Software)
S3 DIRECTIO37; C:\Program Files\BurnInTest\DirectIo64.sys [31376 2015-02-16] ()
R3 e1dexpress; C:\Windows\system32\DRIVERS\e1d65x64.sys [530416 2015-06-18] (Intel Corporation)
R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [118272 2014-04-03] (Intel Corporation)
R3 NVR0Dev; C:\windows\nvoclk64.sys [39968 2007-09-04] (NVidia Corp.)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [28032 2016-02-17] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [47760 2015-12-18] (NVIDIA Corporation)
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation)
R2 zdwfp; C:\windows\system32\Drivers\zdwfp64.sys [46352 2016-03-04] (zdengine)
S3 e1edc438-f640-4184-a443-d2a7c37a01dc; \??\C:\3XS-TESTS\OA30\690b33e1-0462-4e84-9bea-c7552b45432a.sys [X]
S4 NVHDA; \SystemRoot\system32\drivers\nvhda64v.sys [X]
S1 owfrxpjm; \??\C:\windows\system32\drivers\owfrxpjm.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2016-03-26 11:55 - 2016-03-26 11:55 - 00000000 ____D C:\FRST
2016-03-26 07:36 - 2016-03-26 07:36 - 00037144 _____ (AVAST Software) C:\windows\system32\Drivers\aswKbd.sys
2016-03-26 07:36 - 2016-03-26 07:36 - 00003178 _____ C:\windows\System32\Tasks\SafeZone scheduled Autoupdate 1458977815
2016-03-26 07:36 - 2016-03-26 07:36 - 00001088 _____ C:\Users\Public\Desktop\Avast SafeZone Browser.lnk
2016-03-26 07:36 - 2016-03-26 07:36 - 00001088 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast SafeZone Browser.lnk
2016-03-25 22:25 - 2016-03-25 22:23 - 00398152 _____ (AVAST Software) C:\windows\system32\aswBoot.exe
2016-03-25 22:24 - 2016-03-25 22:25 - 00003040 _____ C:\windows\System32\Tasks\avast! Windows 10 Start Menu helper
2016-03-25 22:24 - 2016-03-25 22:24 - 00001985 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast Free Antivirus.lnk
2016-03-25 22:24 - 2016-03-25 22:24 - 00001973 _____ C:\Users\Public\Desktop\Avast Free Antivirus.lnk
2016-03-25 22:24 - 2016-03-25 22:24 - 00000000 ____D C:\Users\willi\AppData\Roaming\AVAST Software
2016-03-25 22:23 - 2016-03-25 22:25 - 00004006 _____ C:\windows\System32\Tasks\avast! Emergency Update
2016-03-25 22:23 - 2016-03-25 22:24 - 01070904 _____ (AVAST Software) C:\windows\system32\Drivers\aswSnx.sys
2016-03-25 22:23 - 2016-03-25 22:24 - 00107792 _____ (AVAST Software) C:\windows\system32\Drivers\aswMonFlt.sys
2016-03-25 22:23 - 2016-03-25 22:23 - 00463744 _____ (AVAST Software) C:\windows\system32\Drivers\aswSP.sys
2016-03-25 22:23 - 2016-03-25 22:23 - 00287016 _____ (AVAST Software) C:\windows\system32\Drivers\aswVmm.sys
2016-03-25 22:23 - 2016-03-25 22:23 - 00165344 _____ (AVAST Software) C:\windows\system32\Drivers\aswStm.sys
2016-03-25 22:23 - 2016-03-25 22:23 - 00103064 _____ (AVAST Software) C:\windows\system32\Drivers\aswRdr2.sys
2016-03-25 22:23 - 2016-03-25 22:23 - 00074544 _____ (AVAST Software) C:\windows\system32\Drivers\aswRvrt.sys
2016-03-25 22:23 - 2016-03-25 22:23 - 00052184 _____ (AVAST Software) C:\windows\avastSS.scr
2016-03-25 22:23 - 2016-03-25 22:23 - 00037656 _____ (AVAST Software) C:\windows\system32\Drivers\aswHwid.sys
2016-03-25 22:23 - 2016-03-25 22:23 - 00001271 _____ C:\Users\willi\Desktop\Continue Flash Video Player Installation.lnk
2016-03-25 22:22 - 2016-03-26 07:36 - 00000000 ____D C:\ProgramData\AVAST Software
2016-03-25 22:22 - 2016-03-26 07:36 - 00000000 ____D C:\Program Files\AVAST Software
2016-03-25 21:38 - 2016-03-25 22:21 - 00011056 _____ C:\windows\SysWOW64\zdengineOff.ini
2016-03-25 21:38 - 2016-03-25 22:21 - 00011056 _____ C:\windows\system32\zdengineOff.ini
2016-03-25 21:38 - 2016-03-25 21:38 - 00000000 ___HD C:\OneDriveTemp
2016-03-25 21:38 - 2016-03-25 21:37 - 00341670 _____ (zdengine) C:\windows\system32\zdengine64.dll
2016-03-25 21:38 - 2016-03-04 14:13 - 00046352 _____ (zdengine) C:\windows\system32\Drivers\zdwfp64.sys
2016-03-25 21:34 - 2016-03-25 21:34 - 00000000 ____D C:\windows\system32\todp
2016-03-25 21:32 - 2016-03-25 21:32 - 00000000 ____D C:\Users\willi\AppData\Local\rec_gb_236
2016-03-25 21:32 - 2016-03-25 21:32 - 00000000 ____D C:\Program Files (x86)\SunnyDayApps
2016-03-25 21:32 - 2016-03-25 21:32 - 00000000 ____D C:\Program Files (x86)\rec_gb_236
2016-03-25 21:29 - 2016-03-26 11:45 - 00000000 ____D C:\Users\willi\AppData\Local\SunnyDay13
2016-03-25 21:29 - 2016-03-25 23:14 - 00000000 ____D C:\Users\willi\AppData\Local\A56F9120-1458941358-11D3-A25A-2C56DC48B2D3
2016-03-25 21:29 - 2016-03-25 21:29 - 00000000 ____D C:\Program Files (x86)\SunnyDay13
2016-03-25 21:16 - 2016-03-25 21:16 - 00192216 _____ (Malwarebytes) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2016-03-25 21:15 - 2016-03-25 21:36 - 00001171 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2016-03-25 21:15 - 2016-03-25 21:15 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2016-03-25 21:15 - 2016-03-25 21:15 - 00000000 ____D C:\ProgramData\Malwarebytes
2016-03-25 21:15 - 2016-03-25 21:15 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2016-03-25 21:15 - 2016-03-10 14:09 - 00065408 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys
2016-03-25 21:15 - 2016-03-10 14:08 - 00140672 _____ (Malwarebytes) C:\windows\system32\Drivers\mbamchameleon.sys
2016-03-25 21:15 - 2016-03-10 14:08 - 00027008 _____ (Malwarebytes) C:\windows\system32\Drivers\mbam.sys
2016-03-25 21:03 - 2016-03-25 21:03 - 00000000 ____D C:\Users\willi\AppData\Roaming\MCorp
2016-03-25 21:01 - 2016-03-25 21:01 - 00000000 ____D C:\Program Files (x86)\ExploreTech
2016-03-25 20:59 - 2016-03-25 23:09 - 00000000 ____D C:\Program Files\Baomkybrile
2016-03-25 20:59 - 2016-03-25 21:35 - 00000000 ____D C:\Users\willi\AppData\Roaming\Memuomi
2016-03-25 20:59 - 2016-03-25 21:33 - 00000000 ____D C:\Users\willi\AppData\LocalLow\Company
2016-03-25 20:59 - 2016-03-25 21:01 - 00000000 ____D C:\Users\willi\AppData\Local\app
2016-03-25 20:59 - 2016-03-25 20:59 - 00003418 _____ C:\windows\System32\Tasks\Bimui
2016-03-25 20:59 - 2016-03-25 20:59 - 00000000 ____D C:\Users\willi\AppData\Local\Tempfolder
2016-03-25 20:59 - 2016-03-25 20:59 - 00000000 ____D C:\uninst
2016-03-25 20:57 - 2016-03-25 21:33 - 00000000 ____D C:\Users\willi\AppData\Local\A56F9120-1458939472-11D3-A25A-2C56DC48B2D3
2016-03-25 20:57 - 2016-03-25 20:57 - 00000000 ____D C:\Users\willi\AppData\Roaming\cpuminer
2016-03-24 20:12 - 2016-03-25 21:38 - 00000002 _____ C:\END
2016-03-24 20:12 - 2016-03-25 21:05 - 00000000 ____D C:\Program Files\Common Files\Soobzo
2016-03-24 20:12 - 2016-03-24 20:12 - 00003450 _____ C:\windows\System32\Tasks\NIFQIDEGATILRONX
2016-03-24 20:12 - 2016-03-24 20:12 - 00000374 ____H C:\windows\Tasks\NIFQIDEGATILRONX.job
2016-03-24 20:11 - 2016-03-26 08:11 - 00000000 ____D C:\Program Files (x86)\QuickSearch
2016-03-24 20:11 - 2016-03-24 20:12 - 00187904 _____ C:\windows\rsrcs.dll
2016-03-24 20:11 - 2016-03-24 20:11 - 00000000 ____D C:\ProgramData\28341ff220e0446c9fff27c4493d622e
2016-03-24 20:11 - 2016-03-24 20:11 - 00000000 ____D C:\ProgramData\19a87fa1ec024bbcbb41931263354405
2016-03-24 20:02 - 2016-03-24 20:00 - 00001006 _____ C:\windows\system32\Drivers\etc\hp.bak
2016-03-23 09:00 - 2016-03-23 09:00 - 00000889 _____ C:\windows\SysWOW64\${LOGFILE}
2016-03-23 08:57 - 2016-03-23 08:57 - 06493696 _____ C:\Users\willi\AppData\Roaming\agent.dat
2016-03-23 08:57 - 2016-03-23 08:57 - 01622132 _____ C:\Users\willi\AppData\Roaming\Zimlux.tst
2016-03-23 08:57 - 2016-03-23 08:57 - 00127488 _____ C:\Users\willi\AppData\Roaming\Installer.dat
2016-03-23 08:57 - 2016-03-23 08:57 - 00072707 _____ C:\Users\willi\AppData\Roaming\Jaytom.tst
2016-03-23 08:57 - 2016-03-23 08:57 - 00018432 _____ C:\Users\willi\AppData\Roaming\Main.dat
2016-03-23 08:57 - 2016-03-23 08:57 - 00000000 ____D C:\Users\willi\AppData\Roaming\Mozilla
2016-03-23 08:57 - 2016-03-23 08:57 - 00000000 ____D C:\ProgramData\Quoteexs
2016-03-23 08:56 - 2016-03-25 21:33 - 00000000 ____D C:\Users\willi\AppData\Roaming\Store
2016-03-23 08:56 - 2016-03-23 08:56 - 00000000 ____D C:\Users\willi\AppData\Roaming\WTools
2016-03-23 08:56 - 2016-03-23 08:56 - 00000000 ____D C:\ProgramData\DivX
2016-03-23 08:49 - 2016-03-23 08:49 - 00000000 ____D C:\Users\willi\AppData\Roaming\vlc
2016-03-23 08:48 - 2016-03-25 21:36 - 00000835 _____ C:\Users\Public\Desktop\VLC media player.lnk
2016-03-23 08:43 - 2016-03-23 09:02 - 00000000 ____D C:\Users\willi\AppData\Roaming\uTorrent
2016-03-17 20:47 - 2016-03-17 20:47 - 00000000 ____D C:\Users\willi\AppData\Roaming\.mono
2016-03-17 20:47 - 2016-03-17 20:47 - 00000000 ____D C:\ProgramData\.mono
2016-03-13 20:51 - 2016-03-25 21:36 - 00000922 _____ C:\Users\Public\Desktop\Hearthstone.lnk
2016-03-08 22:46 - 2016-03-08 22:46 - 00018521 _____ C:\Users\willi\Documents\cloudbass NEW_HOLIDAY_REQUEST_FORM (1).xlsx
2016-03-08 18:45 - 2016-03-01 05:31 - 00848168 _____ (Microsoft Corporation) C:\windows\system32\mfsvr.dll
2016-03-08 18:45 - 2016-03-01 05:22 - 00709688 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfsvr.dll
2016-03-08 18:45 - 2016-02-24 09:52 - 01997328 _____ (Microsoft Corporation) C:\windows\system32\KernelBase.dll
2016-03-08 18:45 - 2016-02-24 09:51 - 07474528 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe
2016-03-08 18:45 - 2016-02-24 09:48 - 00713568 _____ (Microsoft Corporation) C:\windows\system32\invagent.dll
2016-03-08 18:45 - 2016-02-24 09:47 - 01173344 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll
2016-03-08 18:45 - 2016-02-24 09:40 - 00513888 _____ (Microsoft Corporation) C:\windows\system32\devinv.dll
2016-03-08 18:45 - 2016-02-24 09:34 - 01613664 _____ (Microsoft Corporation) C:\windows\system32\diagtrack.dll
2016-03-08 18:45 - 2016-02-24 09:28 - 03449168 _____ (Microsoft Corporation) C:\windows\system32\WSService.dll
2016-03-08 18:45 - 2016-02-24 09:15 - 01557768 _____ (Microsoft Corporation) C:\windows\SysWOW64\KernelBase.dll
2016-03-08 18:45 - 2016-02-24 08:58 - 00794888 _____ (Microsoft Corporation) C:\windows\system32\mfds.dll
2016-03-08 18:45 - 2016-02-24 08:54 - 00127840 _____ (Microsoft Corporation) C:\windows\system32\Drivers\USBSTOR.SYS
2016-03-08 18:45 - 2016-02-24 08:51 - 01322248 _____ (Microsoft Corporation) C:\windows\system32\ole32.dll
2016-03-08 18:45 - 2016-02-24 08:50 - 00808800 _____ (Microsoft Corporation) C:\windows\system32\WWAHost.exe
2016-03-08 18:45 - 2016-02-24 08:46 - 06607080 _____ (Microsoft Corporation) C:\windows\system32\windows.storage.dll
2016-03-08 18:45 - 2016-02-24 08:43 - 00625000 _____ (Microsoft Corporation) C:\windows\system32\ClipSVC.dll
2016-03-08 18:45 - 2016-02-24 08:39 - 00358752 _____ (Microsoft Corporation) C:\windows\system32\msv1_0.dll
2016-03-08 18:45 - 2016-02-24 08:39 - 00141560 _____ (Microsoft Corporation) C:\windows\system32\AuthHost.exe
2016-03-08 18:45 - 2016-02-24 08:19 - 00670928 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfds.dll
2016-03-08 18:45 - 2016-02-24 08:14 - 00216416 _____ (Microsoft Corporation) C:\windows\system32\AppxAllUserStore.dll
2016-03-08 18:45 - 2016-02-24 08:11 - 01997152 _____ (Microsoft Corporation) C:\windows\system32\Drivers\dxgkrnl.sys
2016-03-08 18:45 - 2016-02-24 08:11 - 00957608 _____ (Microsoft Corporation) C:\windows\SysWOW64\ole32.dll
2016-03-08 18:45 - 2016-02-24 08:11 - 00703840 _____ (Microsoft Corporation) C:\windows\SysWOW64\WWAHost.exe
2016-03-08 18:45 - 2016-02-24 08:11 - 00652392 _____ (Microsoft Corporation) C:\windows\system32\dxgi.dll
2016-03-08 18:45 - 2016-02-24 08:11 - 00394080 _____ (Microsoft Corporation) C:\windows\system32\Drivers\dxgmms1.sys
2016-03-08 18:45 - 2016-02-24 08:11 - 00258280 _____ (Microsoft Corporation) C:\windows\system32\sqmapi.dll
2016-03-08 18:45 - 2016-02-24 08:10 - 00630632 _____ (Microsoft Corporation) C:\windows\system32\fontdrvhost.exe
2016-03-08 18:45 - 2016-02-24 08:10 - 00576864 _____ (Microsoft Corporation) C:\windows\system32\Drivers\dxgmms2.sys
2016-03-08 18:45 - 2016-02-24 08:09 - 00640472 _____ (Microsoft Corporation) C:\windows\system32\wer.dll
2016-03-08 18:45 - 2016-02-24 08:09 - 00147808 _____ (Microsoft Corporation) C:\windows\system32\wermgr.exe
2016-03-08 18:45 - 2016-02-24 08:06 - 05242496 _____ (Microsoft Corporation) C:\windows\SysWOW64\windows.storage.dll
2016-03-08 18:45 - 2016-02-24 07:59 - 00294752 _____ (Microsoft Corporation) C:\windows\SysWOW64\msv1_0.dll
2016-03-08 18:45 - 2016-02-24 07:39 - 00045568 _____ (Microsoft Corporation) C:\windows\system32\UserDataTypeHelperUtil.dll
2016-03-08 18:45 - 2016-02-24 07:39 - 00023552 _____ (Microsoft Corporation) C:\windows\system32\ExtrasXmlParser.dll
2016-03-08 18:45 - 2016-02-24 07:38 - 00187744 _____ (Microsoft Corporation) C:\windows\SysWOW64\AppxAllUserStore.dll
2016-03-08 18:45 - 2016-02-24 07:38 - 00111616 _____ (Microsoft Corporation) C:\windows\system32\UserDataTimeUtil.dll
2016-03-08 18:45 - 2016-02-24 07:37 - 00045056 _____ (Microsoft Corporation) C:\windows\system32\UserDataLanguageUtil.dll
2016-03-08 18:45 - 2016-02-24 07:36 - 00060416 _____ (Microsoft Corporation) C:\windows\system32\PimIndexMaintenanceClient.dll
2016-03-08 18:45 - 2016-02-24 07:35 - 00540752 _____ (Microsoft Corporation) C:\windows\SysWOW64\fontdrvhost.exe
2016-03-08 18:45 - 2016-02-24 07:35 - 00523752 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxgi.dll
2016-03-08 18:45 - 2016-02-24 07:35 - 00220064 _____ (Microsoft Corporation) C:\windows\SysWOW64\sqmapi.dll
2016-03-08 18:45 - 2016-02-24 07:35 - 00045568 _____ (Adobe Systems) C:\windows\system32\atmlib.dll
2016-03-08 18:45 - 2016-02-24 07:33 - 00538736 _____ (Microsoft Corporation) C:\windows\SysWOW64\wer.dll
2016-03-08 18:45 - 2016-02-24 07:33 - 00141664 _____ (Microsoft Corporation) C:\windows\SysWOW64\wermgr.exe
2016-03-08 18:45 - 2016-02-24 07:31 - 00118272 _____ (Microsoft Corporation) C:\windows\system32\fontsub.dll
2016-03-08 18:45 - 2016-02-24 07:30 - 00025600 _____ (Microsoft Corporation) C:\windows\system32\wfapigp.dll
2016-03-08 18:45 - 2016-02-24 07:28 - 00070656 _____ (Microsoft Corporation) C:\windows\system32\POSyncServices.dll
2016-03-08 18:45 - 2016-02-24 07:23 - 00091648 _____ (Microsoft Corporation) C:\windows\system32\asycfilt.dll
2016-03-08 18:45 - 2016-02-24 07:23 - 00068096 _____ (Microsoft Corporation) C:\windows\system32\UserDataPlatformHelperUtil.dll
2016-03-08 18:45 - 2016-02-24 07:22 - 00196608 _____ (Microsoft Corporation) C:\windows\system32\fwpolicyiomgr.dll
2016-03-08 18:45 - 2016-02-24 07:20 - 00195072 _____ (Microsoft Corporation) C:\windows\system32\VCardParser.dll
2016-03-08 18:45 - 2016-02-24 07:20 - 00167936 _____ (Microsoft Corporation) C:\windows\system32\dafBth.dll
2016-03-08 18:45 - 2016-02-24 07:20 - 00087552 _____ (Microsoft Corporation) C:\windows\system32\AppxSysprep.dll
2016-03-08 18:45 - 2016-02-24 07:19 - 00145408 _____ (Microsoft Corporation) C:\windows\system32\dssvc.dll
2016-03-08 18:45 - 2016-02-24 07:19 - 00031232 _____ (Microsoft Corporation) C:\windows\system32\seclogon.dll
2016-03-08 18:45 - 2016-02-24 07:15 - 00365568 _____ (Adobe Systems Incorporated) C:\windows\system32\atmfd.dll
2016-03-08 18:45 - 2016-02-24 07:14 - 00274944 _____ (Microsoft Corporation) C:\windows\system32\ExSMime.dll
2016-03-08 18:45 - 2016-02-24 07:13 - 00121856 _____ (Microsoft Corporation) C:\windows\system32\AppointmentActivation.dll
2016-03-08 18:45 - 2016-02-24 07:12 - 00243712 _____ (Microsoft Corporation) C:\windows\system32\cemapi.dll
2016-03-08 18:45 - 2016-02-24 07:12 - 00221184 _____ (Microsoft Corporation) C:\windows\system32\PhoneCallHistoryApis.dll
2016-03-08 18:45 - 2016-02-24 07:10 - 00093184 _____ (Microsoft Corporation) C:\windows\system32\wpninprc.dll
2016-03-08 18:45 - 2016-02-24 07:09 - 00258560 _____ (Microsoft Corporation) C:\windows\system32\UserDataAccountApis.dll
2016-03-08 18:45 - 2016-02-24 07:09 - 00161792 _____ (Microsoft Corporation) C:\windows\system32\AppxSip.dll
2016-03-08 18:45 - 2016-02-24 07:07 - 00252928 _____ (Microsoft Corporation) C:\windows\system32\PimIndexMaintenance.dll
2016-03-08 18:45 - 2016-02-24 07:05 - 00208896 _____ (Microsoft Corporation) C:\windows\system32\storewuauth.dll
2016-03-08 18:45 - 2016-02-24 07:03 - 00088576 _____ (Microsoft Corporation) C:\windows\SysWOW64\olepro32.dll
2016-03-08 18:45 - 2016-02-24 07:02 - 00161280 _____ (Microsoft Corporation) C:\windows\system32\CallHistoryClient.dll
2016-03-08 18:45 - 2016-02-24 07:01 - 00764928 _____ (Microsoft Corporation) C:\windows\system32\Chakradiag.dll
2016-03-08 18:45 - 2016-02-24 07:01 - 00146432 _____ (Microsoft Corporation) C:\windows\system32\AuthBroker.dll
2016-03-08 18:45 - 2016-02-24 07:01 - 00067584 _____ (Microsoft Corporation) C:\windows\system32\profext.dll
2016-03-08 18:45 - 2016-02-24 07:00 - 00214528 _____ (Microsoft Corporation) C:\windows\system32\Windows.Devices.Scanners.dll
2016-03-08 18:45 - 2016-02-24 06:59 - 00450560 _____ (Microsoft Corporation) C:\windows\system32\Windows.Internal.Bluetooth.dll
2016-03-08 18:45 - 2016-02-24 06:59 - 00360448 _____ (Microsoft Corporation) C:\windows\system32\vaultsvc.dll
2016-03-08 18:45 - 2016-02-24 06:59 - 00318976 _____ (Microsoft Corporation) C:\windows\system32\domgmt.dll
2016-03-08 18:45 - 2016-02-24 06:58 - 00685568 _____ (Microsoft Corporation) C:\windows\system32\scapi.dll
2016-03-08 18:45 - 2016-02-24 06:55 - 00790528 _____ (Microsoft Corporation) C:\windows\system32\EmailApis.dll
2016-03-08 18:45 - 2016-02-24 06:55 - 00224256 _____ (Microsoft Corporation) C:\windows\system32\PackageStateRoaming.dll
2016-03-08 18:45 - 2016-02-24 06:55 - 00018944 _____ (Microsoft Corporation) C:\windows\SysWOW64\ExtrasXmlParser.dll
2016-03-08 18:45 - 2016-02-24 06:54 - 00526336 _____ (Microsoft Corporation) C:\windows\system32\FirewallAPI.dll
2016-03-08 18:45 - 2016-02-24 06:54 - 00288768 _____ (Microsoft Corporation) C:\windows\system32\vaultcli.dll
2016-03-08 18:45 - 2016-02-24 06:54 - 00228352 _____ (Microsoft Corporation) C:\windows\system32\wsqmcons.exe
2016-03-08 18:45 - 2016-02-24 06:54 - 00037888 _____ (Microsoft Corporation) C:\windows\SysWOW64\UserDataTypeHelperUtil.dll
2016-03-08 18:45 - 2016-02-24 06:53 - 00089088 _____ (Microsoft Corporation) C:\windows\SysWOW64\UserDataTimeUtil.dll
2016-03-08 18:45 - 2016-02-24 06:53 - 00037888 _____ (Microsoft Corporation) C:\windows\SysWOW64\UserDataLanguageUtil.dll
2016-03-08 18:45 - 2016-02-24 06:52 - 00451584 _____ (Microsoft Corporation) C:\windows\system32\werui.dll
2016-03-08 18:45 - 2016-02-24 06:52 - 00048128 _____ (Microsoft Corporation) C:\windows\SysWOW64\PimIndexMaintenanceClient.dll
2016-03-08 18:45 - 2016-02-24 06:51 - 00037376 _____ (Adobe Systems) C:\windows\SysWOW64\atmlib.dll
2016-03-08 18:45 - 2016-02-24 06:49 - 00726528 _____ (Microsoft Corporation) C:\windows\system32\ChatApis.dll
2016-03-08 18:45 - 2016-02-24 06:47 - 00093696 _____ (Microsoft Corporation) C:\windows\SysWOW64\fontsub.dll
2016-03-08 18:45 - 2016-02-24 06:46 - 00020480 _____ (Microsoft Corporation) C:\windows\SysWOW64\wfapigp.dll
2016-03-08 18:45 - 2016-02-24 06:44 - 01713664 _____ (Microsoft Corporation) C:\windows\system32\SRHInproc.dll
2016-03-08 18:45 - 2016-02-24 06:44 - 00915456 _____ (Microsoft Corporation) C:\windows\system32\configurationclient.dll
2016-03-08 18:45 - 2016-02-24 06:44 - 00700416 _____ (Microsoft Corporation) C:\windows\system32\AppointmentApis.dll
2016-03-08 18:45 - 2016-02-24 06:44 - 00056320 _____ (Microsoft Corporation) C:\windows\SysWOW64\POSyncServices.dll
2016-03-08 18:45 - 2016-02-24 06:43 - 00957952 _____ (Microsoft Corporation) C:\windows\system32\SRH.dll
2016-03-08 18:45 - 2016-02-24 06:43 - 00286720 _____ (Microsoft Corporation) C:\windows\system32\deviceaccess.dll
2016-03-08 18:45 - 2016-02-24 06:41 - 00982016 _____ (Microsoft Corporation) C:\windows\system32\AppxPackaging.dll
2016-03-08 18:45 - 2016-02-24 06:41 - 00436736 _____ (Microsoft Corporation) C:\windows\system32\AppXDeploymentClient.dll
2016-03-08 18:45 - 2016-02-24 06:40 - 01224704 _____ (Microsoft Corporation) C:\windows\system32\Unistore.dll
2016-03-08 18:45 - 2016-02-24 06:40 - 00078848 _____ (Microsoft Corporation) C:\windows\SysWOW64\asycfilt.dll
2016-03-08 18:45 - 2016-02-24 06:40 - 00056320 _____ (Microsoft Corporation) C:\windows\SysWOW64\UserDataPlatformHelperUtil.dll
2016-03-08 18:45 - 2016-02-24 06:39 - 01390592 _____ (Microsoft Corporation) C:\windows\system32\win32kbase.sys
2016-03-08 18:45 - 2016-02-24 06:39 - 00164864 _____ (Microsoft Corporation) C:\windows\SysWOW64\fwpolicyiomgr.dll
2016-03-08 18:45 - 2016-02-24 06:38 - 00150528 _____ (Microsoft Corporation) C:\windows\SysWOW64\VCardParser.dll
2016-03-08 18:45 - 2016-02-24 06:36 - 01847808 _____ (Microsoft Corporation) C:\windows\system32\WMPDMC.exe
2016-03-08 18:45 - 2016-02-24 06:34 - 00938496 _____ (Microsoft Corporation) C:\windows\system32\ContactApis.dll
2016-03-08 18:45 - 2016-02-24 06:34 - 00303104 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\atmfd.dll
2016-03-08 18:45 - 2016-02-24 06:32 - 00223744 _____ (Microsoft Corporation) C:\windows\SysWOW64\ExSMime.dll
2016-03-08 18:45 - 2016-02-24 06:32 - 00098304 _____ (Microsoft Corporation) C:\windows\SysWOW64\AppointmentActivation.dll
2016-03-08 18:45 - 2016-02-24 06:31 - 00200704 _____ (Microsoft Corporation) C:\windows\SysWOW64\cemapi.dll
2016-03-08 18:45 - 2016-02-24 06:31 - 00169984 _____ (Microsoft Corporation) C:\windows\SysWOW64\PhoneCallHistoryApis.dll
2016-03-08 18:45 - 2016-02-24 06:28 - 00870912 _____ (Microsoft Corporation) C:\windows\system32\MPSSVC.dll
2016-03-08 18:45 - 2016-02-24 06:28 - 00196608 _____ (Microsoft Corporation) C:\windows\SysWOW64\UserDataAccountApis.dll
2016-03-08 18:45 - 2016-02-24 06:28 - 00135168 _____ (Microsoft Corporation) C:\windows\SysWOW64\AppxSip.dll
2016-03-08 18:45 - 2016-02-24 06:25 - 00401408 _____ (Microsoft Corporation) C:\windows\system32\sharemediacpl.dll
2016-03-08 18:45 - 2016-02-24 06:23 - 00129024 _____ (Microsoft Corporation) C:\windows\SysWOW64\CallHistoryClient.dll
2016-03-08 18:45 - 2016-02-24 06:22 - 00053248 _____ (Microsoft Corporation) C:\windows\SysWOW64\profext.dll
2016-03-08 18:45 - 2016-02-24 06:21 - 00315904 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.Internal.Bluetooth.dll
2016-03-08 18:45 - 2016-02-24 06:21 - 00168448 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.Devices.Scanners.dll
2016-03-08 18:45 - 2016-02-24 06:18 - 01490432 _____ (Microsoft Corporation) C:\windows\system32\UserDataService.dll
2016-03-08 18:45 - 2016-02-24 06:18 - 00575488 _____ (Microsoft Corporation) C:\windows\SysWOW64\EmailApis.dll
2016-03-08 18:45 - 2016-02-24 06:18 - 00184832 _____ (Microsoft Corporation) C:\windows\SysWOW64\PackageStateRoaming.dll
2016-03-08 18:45 - 2016-02-24 06:17 - 00369664 _____ (Microsoft Corporation) C:\windows\SysWOW64\FirewallAPI.dll
2016-03-08 18:45 - 2016-02-24 06:16 - 00394752 _____ (Microsoft Corporation) C:\windows\SysWOW64\werui.dll
2016-03-08 18:45 - 2016-02-24 06:13 - 00540160 _____ (Microsoft Corporation) C:\windows\SysWOW64\ChatApis.dll
2016-03-08 18:45 - 2016-02-24 06:11 - 03593216 _____ (Microsoft Corporation) C:\windows\system32\win32kfull.sys
2016-03-08 18:45 - 2016-02-24 06:09 - 01443328 _____ (Microsoft Corporation) C:\windows\SysWOW64\SRHInproc.dll
2016-03-08 18:45 - 2016-02-24 06:09 - 00793600 _____ (Microsoft Corporation) C:\windows\SysWOW64\SRH.dll
2016-03-08 18:45 - 2016-02-24 06:09 - 00552960 _____ (Microsoft Corporation) C:\windows\SysWOW64\AppointmentApis.dll
2016-03-08 18:45 - 2016-02-24 06:09 - 00228352 _____ (Microsoft Corporation) C:\windows\SysWOW64\deviceaccess.dll
2016-03-08 18:45 - 2016-02-24 06:07 - 00949248 _____ (Microsoft Corporation) C:\windows\SysWOW64\Unistore.dll
2016-03-08 18:45 - 2016-02-24 06:07 - 00890368 _____ (Microsoft Corporation) C:\windows\SysWOW64\AppxPackaging.dll
2016-03-08 18:45 - 2016-02-24 06:07 - 00342528 _____ (Microsoft Corporation) C:\windows\SysWOW64\AppXDeploymentClient.dll
2016-03-08 18:45 - 2016-02-24 06:04 - 01497088 _____ (Microsoft Corporation) C:\windows\SysWOW64\WMPDMC.exe
2016-03-08 18:45 - 2016-02-24 06:03 - 00769536 _____ (Microsoft Corporation) C:\windows\SysWOW64\ContactApis.dll
2016-03-08 18:45 - 2016-02-24 06:01 - 01831936 _____ (Microsoft Corporation) C:\windows\system32\AppXDeploymentExtensions.dll
2016-03-08 18:45 - 2016-02-24 06:00 - 02273792 _____ (Microsoft Corporation) C:\windows\system32\wuaueng.dll
2016-03-08 18:45 - 2016-02-24 06:00 - 01098752 _____ (Microsoft Corporation) C:\windows\system32\dosvc.dll
2016-03-08 18:45 - 2016-02-24 05:57 - 02158592 _____ (Microsoft Corporation) C:\windows\system32\AppXDeploymentServer.dll
2016-03-08 18:45 - 2016-02-24 05:55 - 01996288 _____ (Microsoft Corporation) C:\windows\system32\ActiveSyncProvider.dll
2016-03-08 18:45 - 2016-02-24 05:43 - 00184320 _____ (Microsoft Corporation) C:\windows\system32\fwbase.dll
2016-03-08 18:45 - 2016-02-24 05:34 - 01707520 _____ (Microsoft Corporation) C:\windows\SysWOW64\ActiveSyncProvider.dll
2016-03-08 18:45 - 2016-02-24 05:22 - 00163328 _____ (Microsoft Corporation) C:\windows\SysWOW64\fwbase.dll
2016-03-08 18:45 - 2016-02-24 05:20 - 22376960 _____ (Microsoft Corporation) C:\windows\system32\edgehtml.dll
2016-03-08 18:45 - 2016-02-24 05:18 - 18677760 _____ (Microsoft Corporation) C:\windows\SysWOW64\edgehtml.dll
2016-03-08 18:45 - 2016-02-24 05:12 - 19339776 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2016-03-08 18:45 - 2016-02-24 05:12 - 05321728 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.Data.Pdf.dll
2016-03-08 18:45 - 2016-02-24 05:10 - 24600576 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2016-03-08 18:45 - 2016-02-24 05:09 - 06972416 _____ (Microsoft Corporation) C:\windows\system32\Windows.Data.Pdf.dll
2016-03-08 18:45 - 2016-02-24 05:05 - 12586496 _____ (Microsoft Corporation) C:\windows\SysWOW64\wmp.dll
2016-03-08 18:45 - 2016-02-24 05:03 - 14252544 _____ (Microsoft Corporation) C:\windows\system32\wmp.dll
2016-03-08 18:45 - 2016-02-24 04:59 - 05661696 _____ (Microsoft Corporation) C:\windows\SysWOW64\Chakra.dll
2016-03-08 18:45 - 2016-02-24 04:55 - 07835648 _____ (Microsoft Corporation) C:\windows\system32\Chakra.dll
2016-03-06 13:33 - 2016-03-25 21:36 - 00002332 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2016-03-05 19:14 - 2016-03-05 19:14 - 00000000 ____D C:\Program Files (x86)\Google
2016-03-03 23:29 - 2016-03-03 23:29 - 00000000 ____D C:\Users\willi\AppData\Roaming\NVIDIA
2016-03-01 20:45 - 2016-03-01 20:45 - 00372736 _____ (NVIDIA Corporation) C:\windows\system32\NVUNINST.EXE
2016-03-01 20:45 - 2016-03-01 20:45 - 00000000 ____D C:\Program Files (x86)\NVIDIA nTune Performance Application
2016-03-01 20:45 - 2007-07-03 16:41 - 01524736 _____ (Microsoft Corporation) C:\windows\system32\MFC71.dll
2016-03-01 20:45 - 2007-07-03 16:41 - 00978944 _____ (Microsoft Corporation) C:\windows\system32\msvcp71.dll
2016-03-01 20:45 - 2007-07-03 16:41 - 00520192 _____ (Microsoft Corporation) C:\windows\system32\msvcr71.dll
2016-03-01 20:45 - 2007-06-25 22:21 - 02065920 _____ (NVIDIA Corporation) C:\windows\system32\nvcplUI.exe
2016-03-01 20:45 - 2007-06-25 22:21 - 01064448 _____ (NVIDIA Corporation) C:\windows\system32\nvcplUIR.dll
2016-03-01 20:45 - 2007-06-25 22:21 - 00403456 _____ (NVIDIA Corporation) C:\windows\system32\nvcpl.cpl
2016-03-01 20:45 - 2007-06-25 22:21 - 00381952 _____ (NVIDIA Corporation) C:\windows\system32\nvexpBar.dll
2016-03-01 20:40 - 2016-03-25 21:36 - 00001450 _____ C:\Users\Public\Desktop\GeForce Experience.lnk
2016-03-01 20:34 - 2016-03-26 07:49 - 00110176 _____ (Oracle Corporation) C:\windows\system32\WindowsAccessBridge-64.dll
2016-03-01 20:34 - 2016-03-26 07:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2016-03-01 20:34 - 2016-03-26 07:49 - 00000000 ____D C:\Program Files\Java
2016-03-01 20:15 - 2016-03-01 20:15 - 00000000 ____D C:\ProgramData\NVIDIA
2016-03-01 20:15 - 2016-02-23 23:57 - 00215608 _____ (Khronos Group) C:\windows\system32\OpenCL.dll
2016-03-01 20:15 - 2016-02-23 23:57 - 00201664 _____ (Khronos Group) C:\windows\SysWOW64\OpenCL.dll
2016-03-01 20:15 - 2016-02-23 20:28 - 06368824 _____ (NVIDIA Corporation) C:\windows\system32\nvcpl.dll
2016-03-01 20:15 - 2016-02-23 20:28 - 06154909 _____ C:\windows\system32\nvcoproc.bin
2016-03-01 20:15 - 2016-02-23 20:28 - 02993720 _____ (NVIDIA Corporation) C:\windows\system32\nvsvc64.dll
2016-03-01 20:15 - 2016-02-23 20:28 - 02563128 _____ (NVIDIA Corporation) C:\windows\system32\nvsvcr.dll
2016-03-01 20:15 - 2016-02-23 20:28 - 01263040 _____ (NVIDIA Corporation) C:\windows\system32\nvvsvc.exe
2016-03-01 20:15 - 2016-02-23 20:28 - 00530368 _____ (NVIDIA Corporation) C:\windows\system32\nv3dappshext.dll
2016-03-01 20:15 - 2016-02-23 20:28 - 00393784 _____ (NVIDIA Corporation) C:\windows\system32\nvmctray.dll
2016-03-01 20:15 - 2016-02-23 20:28 - 00081856 _____ (NVIDIA Corporation) C:\windows\system32\nv3dappshextr.dll
2016-03-01 20:15 - 2016-02-23 20:28 - 00071224 _____ (NVIDIA Corporation) C:\windows\system32\nvshext.dll
2016-03-01 20:14 - 2016-02-25 01:04 - 12479040 _____ (NVIDIA Corporation) C:\windows\system32\Drivers\nvlddmkm.sys
2016-03-01 20:14 - 2016-02-23 23:57 - 42983480 _____ C:\windows\system32\nvcompiler.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 37616184 _____ C:\windows\SysWOW64\nvcompiler.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 31120952 _____ (NVIDIA Corporation) C:\windows\system32\nvoglv64.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 24944064 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvoglv32.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 21201784 _____ (NVIDIA Corporation) C:\windows\system32\nvopencl.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 20742072 _____ (NVIDIA Corporation) C:\windows\system32\nvcuda.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 19779456 _____ (NVIDIA Corporation) C:\windows\system32\nvwgf2umx.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 17631304 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvopencl.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 17224472 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvcuda.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 17175056 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvwgf2um.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 17117128 _____ (NVIDIA Corporation) C:\windows\system32\nvd3dumx.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 14115136 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvd3dum.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 03649760 _____ (NVIDIA Corporation) C:\windows\system32\nvapi64.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 03231360 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvapi.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 02541504 _____ (NVIDIA Corporation) C:\windows\system32\nvcuvid.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 02187712 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvcuvid.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 01924152 _____ (NVIDIA Corporation) C:\windows\system32\nvdispco6436200.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 01571776 _____ (NVIDIA Corporation) C:\windows\system32\nvdispgenco6436200.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 00950328 _____ (NVIDIA Corporation) C:\windows\system32\NvFBC64.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 00880576 _____ (NVIDIA Corporation) C:\windows\system32\NvIFR64.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 00786688 _____ (NVIDIA Corporation) C:\windows\system32\nvEncMFTH264.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 00784824 _____ (NVIDIA Corporation) C:\windows\system32\nvEncMFThevc.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 00747064 _____ (NVIDIA Corporation) C:\windows\SysWOW64\NvFBC.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 00689600 _____ (NVIDIA Corporation) C:\windows\SysWOW64\NvIFR.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 00632336 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvEncMFTH264.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 00630776 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvEncMFThevc.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 00601936 _____ C:\windows\system32\nvmcumd.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 00541184 _____ (NVIDIA Corporation) C:\windows\system32\nvumdshimx.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 00445912 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvumdshim.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 00425016 _____ (NVIDIA Corporation) C:\windows\system32\NvIFROpenGL.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 00383424 _____ (NVIDIA Corporation) C:\windows\system32\nvDecMFTMjpeg.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 00379448 _____ (NVIDIA Corporation) C:\windows\SysWOW64\NvIFROpenGL.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 00378968 _____ (NVIDIA Corporation) C:\windows\system32\nvEncodeAPI64.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 00346560 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvDecMFTMjpeg.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 00316960 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvEncodeAPI.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 00175552 _____ (NVIDIA Corporation) C:\windows\system32\nvinitx.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 00153208 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvinit.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 00151368 _____ (NVIDIA Corporation) C:\windows\system32\nvoglshim64.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 00128512 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvoglshim32.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 00035832 _____ C:\windows\system32\nvinfo.pb
2016-03-01 19:47 - 2016-03-01 19:48 - 00000000 ____D C:\Users\willi\AppData\Local\NVIDIA
2016-03-01 19:47 - 2016-02-17 06:40 - 01903344 _____ (NVIDIA Corporation) C:\windows\system32\nvspcap64.dll
2016-03-01 19:47 - 2016-02-17 06:40 - 01756424 _____ (NVIDIA Corporation) C:\windows\system32\nvspbridge64.dll
2016-03-01 19:47 - 2016-02-17 06:40 - 01571624 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvspcap.dll
2016-03-01 19:47 - 2016-02-17 06:40 - 01316184 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvspbridge.dll
2016-03-01 19:47 - 2016-02-17 06:40 - 00112216 _____ C:\windows\system32\NvRtmpStreamer64.dll
2016-03-01 19:47 - 2015-12-18 06:11 - 00047760 _____ (NVIDIA Corporation) C:\windows\system32\Drivers\nvvad64v.sys
2016-03-01 19:47 - 2015-12-18 06:10 - 00099472 _____ (NVIDIA Corporation) C:\windows\system32\nvaudcap64v.dll
2016-03-01 19:47 - 2015-12-18 06:10 - 00090768 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvaudcap32v.dll
2016-03-01 19:11 - 2016-02-23 11:29 - 01030416 _____ (Microsoft Corporation) C:\windows\system32\winresume.efi
2016-03-01 19:11 - 2016-02-23 11:29 - 00874968 _____ (Microsoft Corporation) C:\windows\system32\winresume.exe
2016-03-01 19:11 - 2016-02-23 11:27 - 02654872 _____ C:\windows\system32\CoreUIComponents.dll
2016-03-01 19:11 - 2016-02-23 11:27 - 01317640 _____ (Microsoft Corporation) C:\windows\system32\winload.efi
2016-03-01 19:11 - 2016-02-23 11:27 - 01141504 _____ (Microsoft Corporation) C:\windows\system32\winload.exe
2016-03-01 19:11 - 2016-02-23 11:25 - 02152288 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ntfs.sys
2016-03-01 19:11 - 2016-02-23 11:25 - 01818696 _____ (Microsoft Corporation) C:\windows\system32\ntdll.dll
2016-03-01 19:11 - 2016-02-23 11:25 - 00563552 _____ (Microsoft Corporation) C:\windows\system32\Drivers\acpi.sys
2016-03-01 19:11 - 2016-02-23 11:15 - 00779384 _____ (Microsoft Corporation) C:\windows\system32\taskschd.dll
2016-03-01 19:11 - 2016-02-23 11:08 - 00989536 _____ (Microsoft Corporation) C:\windows\system32\SecConfig.efi
2016-03-01 19:11 - 2016-02-23 10:34 - 01859960 _____ C:\windows\SysWOW64\CoreUIComponents.dll
2016-03-01 19:11 - 2016-02-23 10:34 - 01542816 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntdll.dll
2016-03-01 19:11 - 2016-02-23 10:33 - 00696160 _____ (Microsoft Corporation) C:\windows\system32\NetSetupEngine.dll
2016-03-01 19:11 - 2016-02-23 10:33 - 00389992 _____ (Microsoft Corporation) C:\windows\system32\wlanapi.dll
2016-03-01 19:11 - 2016-02-23 10:32 - 08705672 _____ (Microsoft Corp.) C:\windows\system32\Windows.Media.Protection.PlayReady.dll
2016-03-01 19:11 - 2016-02-23 10:32 - 02544264 _____ (Microsoft Corporation) C:\windows\system32\mfcore.dll
2016-03-01 19:11 - 2016-02-23 10:32 - 01152328 _____ (Microsoft Corporation) C:\windows\system32\mfasfsrcsnk.dll
2016-03-01 19:11 - 2016-02-23 10:32 - 01062480 _____ (Microsoft Corporation) C:\windows\system32\mfmp4srcsnk.dll
2016-03-01 19:11 - 2016-02-23 10:32 - 00498448 _____ (Microsoft Corporation) C:\windows\system32\MFCaptureEngine.dll
2016-03-01 19:11 - 2016-02-23 10:32 - 00369912 _____ (Microsoft Corporation) C:\windows\system32\audiodg.exe
2016-03-01 19:11 - 2016-02-23 10:31 - 01017032 _____ (Microsoft Corporation) C:\windows\system32\mfsrcsnk.dll
2016-03-01 19:11 - 2016-02-23 10:31 - 00819648 _____ (Microsoft Corporation) C:\windows\system32\mfmpeg2srcsnk.dll
2016-03-01 19:11 - 2016-02-23 10:31 - 00536256 _____ (Microsoft Corporation) C:\windows\system32\AudioSes.dll
2016-03-01 19:11 - 2016-02-23 10:31 - 00476728 _____ (Microsoft Corporation) C:\windows\system32\msvproc.dll
2016-03-01 19:11 - 2016-02-23 10:31 - 00408120 _____ (Microsoft Corporation) C:\windows\system32\AUDIOKSE.dll
2016-03-01 19:11 - 2016-02-23 10:25 - 03671888 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2016-03-01 19:11 - 2016-02-23 10:22 - 00572272 _____ (Microsoft Corporation) C:\windows\SysWOW64\taskschd.dll
2016-03-01 19:11 - 2016-02-23 10:21 - 22564328 _____ (Microsoft Corporation) C:\windows\system32\shell32.dll
2016-03-01 19:11 - 2016-02-23 10:17 - 00146272 _____ (Microsoft Corporation) C:\windows\system32\Drivers\appid.sys
2016-03-01 19:11 - 2016-02-23 09:45 - 02773096 _____ (Microsoft Corporation) C:\windows\system32\d3d11.dll
2016-03-01 19:11 - 2016-02-23 09:40 - 00430944 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb.sys
2016-03-01 19:11 - 2016-02-23 09:39 - 00502112 _____ (Microsoft Corporation) C:\windows\SysWOW64\NetSetupEngine.dll
2016-03-01 19:11 - 2016-02-23 09:38 - 06952088 _____ (Microsoft Corp.) C:\windows\SysWOW64\Windows.Media.Protection.PlayReady.dll
2016-03-01 19:11 - 2016-02-23 09:38 - 02180136 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfcore.dll
2016-03-01 19:11 - 2016-02-23 09:38 - 00980352 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfasfsrcsnk.dll
2016-03-01 19:11 - 2016-02-23 09:38 - 00895080 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfsrcsnk.dll
2016-03-01 19:11 - 2016-02-23 09:38 - 00882720 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfmp4srcsnk.dll
2016-03-01 19:11 - 2016-02-23 09:38 - 00450912 _____ (Microsoft Corporation) C:\windows\SysWOW64\MFCaptureEngine.dll
2016-03-01 19:11 - 2016-02-23 09:38 - 00420928 _____ (Microsoft Corporation) C:\windows\SysWOW64\msvproc.dll
2016-03-01 19:11 - 2016-02-23 09:37 - 00713824 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfmpeg2srcsnk.dll
2016-03-01 19:11 - 2016-02-23 09:32 - 00791744 _____ (Microsoft Corporation) C:\windows\system32\generaltel.dll
2016-03-01 19:11 - 2016-02-23 09:30 - 02919320 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2016-03-01 19:11 - 2016-02-23 09:27 - 21124344 _____ (Microsoft Corporation) C:\windows\SysWOW64\shell32.dll
2016-03-01 19:11 - 2016-02-23 09:27 - 00376536 _____ (Microsoft Corporation) C:\windows\system32\Windows.Media.MediaControl.dll
2016-03-01 19:11 - 2016-02-23 09:25 - 00534368 _____ (Microsoft Corporation) C:\windows\system32\Drivers\USBHUB3.SYS
2016-03-01 19:11 - 2016-02-23 09:20 - 01139712 _____ (Microsoft Corporation) C:\windows\system32\XblGameSave.dll
2016-03-01 19:11 - 2016-02-23 09:20 - 00238592 _____ (Microsoft Corporation) C:\windows\system32\Drivers\xboxgip.sys
2016-03-01 19:11 - 2016-02-23 09:19 - 00029696 _____ (Microsoft Corporation) C:\windows\system32\Drivers\xinputhid.sys
2016-03-01 19:11 - 2016-02-23 09:17 - 00649216 _____ (Microsoft Corporation) C:\windows\system32\ngcsvc.dll
2016-03-01 19:11 - 2016-02-23 09:12 - 00077824 _____ (Microsoft Corporation) C:\windows\system32\provpackageapidll.dll
2016-03-01 19:11 - 2016-02-23 09:10 - 00027648 _____ (Microsoft Corporation) C:\windows\system32\WiFiConfigSP.dll
2016-03-01 19:11 - 2016-02-23 09:07 - 00037376 _____ (Microsoft Corporation) C:\windows\system32\LaunchWinApp.exe
2016-03-01 19:11 - 2016-02-23 09:07 - 00026112 _____ (Microsoft Corporation) C:\windows\system32\wlansvcpal.dll
2016-03-01 19:11 - 2016-02-23 09:06 - 00129536 _____ (Microsoft Corporation) C:\windows\system32\flvprophandler.dll
2016-03-01 19:11 - 2016-02-23 09:01 - 00104960 _____ (Microsoft Corporation) C:\windows\system32\Drivers\rasl2tp.sys
2016-03-01 19:11 - 2016-02-23 09:00 - 00069632 _____ (Microsoft Corporation) C:\windows\system32\EnterpriseDesktopAppMgmtCSP.dll
2016-03-01 19:11 - 2016-02-23 09:00 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\wfdprov.dll
2016-03-01 19:11 - 2016-02-23 08:58 - 00069632 _____ (Microsoft Corporation) C:\windows\system32\wininetlui.dll
2016-03-01 19:11 - 2016-02-23 08:58 - 00052224 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2016-03-01 19:11 - 2016-02-23 08:58 - 00025088 _____ (Microsoft Corporation) C:\windows\system32\irmon.dll
2016-03-01 19:11 - 2016-02-23 08:57 - 00199168 _____ (Microsoft Corporation) C:\windows\system32\InstallAgent.exe
2016-03-01 19:11 - 2016-02-23 08:56 - 02186864 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3d11.dll
2016-03-01 19:11 - 2016-02-23 08:55 - 00114688 _____ (Microsoft Corporation) C:\windows\system32\Drivers\bridge.sys
2016-03-01 19:11 - 2016-02-23 08:53 - 00115712 _____ (Microsoft Corporation) C:\windows\system32\srpapi.dll
2016-03-01 19:11 - 2016-02-23 08:53 - 00099328 _____ (Microsoft Corporation) C:\windows\system32\ngckeyenum.dll
2016-03-01 19:11 - 2016-02-23 08:52 - 00087040 _____ (Microsoft Corporation) C:\windows\system32\MDMAppInstaller.exe
2016-03-01 19:11 - 2016-02-23 08:50 - 00159232 _____ (Microsoft Corporation) C:\windows\system32\DeviceCensus.exe
2016-03-01 19:11 - 2016-02-23 08:48 - 00086528 _____ (Microsoft Corporation) C:\windows\system32\AppCapture.dll
2016-03-01 19:11 - 2016-02-23 08:48 - 00041984 _____ (Microsoft Corporation) C:\windows\system32\TimeBrokerClient.dll
2016-03-01 19:11 - 2016-02-23 08:40 - 00074240 _____ (Microsoft Corporation) C:\windows\system32\SMSRouter.dll
2016-03-01 19:11 - 2016-02-23 08:39 - 00178176 _____ (Microsoft Corporation) C:\windows\system32\psmsrv.dll
2016-03-01 19:11 - 2016-02-23 08:38 - 00320000 _____ (Microsoft Corporation) C:\windows\system32\MSFlacDecoder.dll
2016-03-01 19:11 - 2016-02-23 08:38 - 00287712 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.Media.MediaControl.dll
2016-03-01 19:11 - 2016-02-23 08:37 - 00617984 _____ (Microsoft Corporation) C:\windows\system32\StorSvc.dll
2016-03-01 19:11 - 2016-02-23 08:37 - 00274944 _____ (Microsoft Corporation) C:\windows\system32\DisplayManager.dll
2016-03-01 19:11 - 2016-02-23 08:37 - 00204288 _____ (Microsoft Corporation) C:\windows\system32\NetSetupSvc.dll
2016-03-01 19:11 - 2016-02-23 08:36 - 00216576 _____ (Microsoft Corporation) C:\windows\system32\QuickActionsDataModel.dll
2016-03-01 19:11 - 2016-02-23 08:34 - 00305664 _____ (Microsoft Corporation) C:\windows\system32\wifiprofilessettinghandler.dll
2016-03-01 19:11 - 2016-02-23 08:34 - 00189952 _____ (Microsoft Corporation) C:\windows\system32\WiFiDisplay.dll
2016-03-01 19:11 - 2016-02-23 08:33 - 00558080 _____ (Microsoft Corporation) C:\windows\system32\MBMediaManager.dll
2016-03-01 19:11 - 2016-02-23 08:32 - 00414720 _____ (Microsoft Corporation) C:\windows\system32\bcastdvr.exe
2016-03-01 19:11 - 2016-02-23 08:31 - 00463360 _____ (Microsoft Corporation) C:\windows\system32\wlansec.dll
2016-03-01 19:11 - 2016-02-23 08:29 - 00591872 _____ (Microsoft Corporation) C:\windows\system32\SmsRouterSvc.dll
2016-03-01 19:11 - 2016-02-23 08:28 - 00275456 _____ (Microsoft Corporation) C:\windows\system32\AudioEndpointBuilder.dll
2016-03-01 19:11 - 2016-02-23 08:27 - 00307712 _____ (Microsoft Corporation) C:\windows\system32\usbmon.dll
2016-03-01 19:11 - 2016-02-23 08:26 - 00372224 _____ (Microsoft Corporation) C:\windows\system32\MDEServer.exe
2016-03-01 19:11 - 2016-02-23 08:23 - 00412672 _____ (Microsoft Corporation) C:\windows\system32\wlanmsm.dll
2016-03-01 19:11 - 2016-02-23 08:22 - 00567808 _____ (Microsoft Corporation) C:\windows\system32\MCRecvSrc.dll
2016-03-01 19:11 - 2016-02-23 08:20 - 00847360 _____ (Microsoft Corporation) C:\windows\system32\netlogon.dll
2016-03-01 19:11 - 2016-02-23 08:20 - 00606720 _____ (Microsoft Corporation) C:\windows\system32\wcmsvc.dll
2016-03-01 19:11 - 2016-02-23 08:20 - 00493568 _____ (Microsoft Corporation) C:\windows\system32\mfmkvsrcsnk.dll
2016-03-01 19:11 - 2016-02-23 08:20 - 00330240 _____ (Microsoft Corporation) C:\windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2016-03-01 19:11 - 2016-02-23 08:19 - 00948736 _____ (Microsoft Corporation) C:\windows\system32\XblAuthManager.dll
2016-03-01 19:11 - 2016-02-23 08:19 - 00517632 _____ (Microsoft Corporation) C:\windows\system32\winspool.drv
2016-03-01 19:11 - 2016-02-23 08:18 - 00557056 _____ (Microsoft Corporation) C:\windows\system32\PsmServiceExtHost.dll
2016-03-01 19:11 - 2016-02-23 08:14 - 00828928 _____ (Microsoft Corporation) C:\windows\system32\Windows.AccountsControl.dll
2016-03-01 19:11 - 2016-02-23 08:14 - 00029696 _____ (Microsoft Corporation) C:\windows\SysWOW64\LaunchWinApp.exe
2016-03-01 19:11 - 2016-02-23 08:12 - 00852480 _____ (Microsoft Corporation) C:\windows\system32\Windows.ApplicationModel.Store.dll
2016-03-01 19:11 - 2016-02-23 08:11 - 00587776 _____ (Microsoft Corporation) C:\windows\system32\bisrv.dll
2016-03-01 19:11 - 2016-02-23 08:10 - 00997376 _____ (Microsoft Corporation) C:\windows\system32\schedsvc.dll
2016-03-01 19:11 - 2016-02-23 08:10 - 00474624 _____ (Microsoft Corporation) C:\windows\system32\NetSetupShim.dll
2016-03-01 19:11 - 2016-02-23 08:09 - 01054208 _____ (Microsoft Corporation) C:\windows\system32\audiosrv.dll
2016-03-01 19:11 - 2016-02-23 08:09 - 00988160 _____ (Microsoft Corporation) C:\windows\system32\SharedStartModel.dll
2016-03-01 19:11 - 2016-02-23 08:09 - 00870400 _____ (Microsoft Corporation) C:\windows\system32\modernexecserver.dll
2016-03-01 19:11 - 2016-02-23 08:06 - 01213440 _____ (Microsoft Corporation) C:\windows\system32\wwansvc.dll
2016-03-01 19:11 - 2016-02-23 08:06 - 00065536 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininetlui.dll
2016-03-01 19:11 - 2016-02-23 08:06 - 00045568 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2016-03-01 19:11 - 2016-02-23 08:05 - 00161280 _____ (Microsoft Corporation) C:\windows\SysWOW64\InstallAgent.exe
2016-03-01 19:11 - 2016-02-23 08:04 - 01131520 _____ (Microsoft Corporation) C:\windows\system32\Windows.Media.Audio.dll
2016-03-01 19:11 - 2016-02-23 08:04 - 00673792 _____ (Microsoft Corporation) C:\windows\system32\Windows.UI.dll
2016-03-01 19:11 - 2016-02-23 08:04 - 00382464 _____ (Microsoft Corporation) C:\windows\system32\wuuhext.dll
2016-03-01 19:11 - 2016-02-23 08:02 - 01318912 _____ (Microsoft Corporation) C:\windows\system32\wifinetworkmanager.dll
2016-03-01 19:11 - 2016-02-23 08:02 - 00755712 _____ (Microsoft Corporation) C:\windows\system32\spoolsv.exe
2016-03-01 19:11 - 2016-02-23 08:02 - 00285696 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb10.sys
2016-03-01 19:11 - 2016-02-23 08:00 - 02624512 _____ (Microsoft Corporation) C:\windows\system32\InputService.dll
2016-03-01 19:11 - 2016-02-23 07:58 - 00345600 _____ (Microsoft Corporation) C:\windows\system32\TextInputFramework.dll
2016-03-01 19:11 - 2016-02-23 07:58 - 00175616 _____ (Microsoft Corporation) C:\windows\system32\Windows.UI.Core.TextInput.dll
2016-03-01 19:11 - 2016-02-23 07:58 - 00163840 _____ (Microsoft Corporation) C:\windows\system32\TimeBrokerServer.dll
2016-03-01 19:11 - 2016-02-23 07:58 - 00108544 _____ (Microsoft Corporation) C:\windows\system32\InputLocaleManager.dll
2016-03-01 19:11 - 2016-02-23 07:57 - 00031744 _____ (Microsoft Corporation) C:\windows\SysWOW64\TimeBrokerClient.dll
2016-03-01 19:11 - 2016-02-23 07:52 - 00456704 _____ (Microsoft Corporation) C:\windows\system32\ipnathlp.dll
2016-03-01 19:11 - 2016-02-23 07:50 - 00266752 _____ (Microsoft Corporation) C:\windows\SysWOW64\MSFlacDecoder.dll
2016-03-01 19:11 - 2016-02-23 07:49 - 00200704 _____ (Microsoft Corporation) C:\windows\SysWOW64\DisplayManager.dll
2016-03-01 19:11 - 2016-02-23 07:48 - 00838144 _____ (Microsoft Corporation) C:\windows\system32\uDWM.dll
2016-03-01 19:11 - 2016-02-23 07:47 - 00157184 _____ (Microsoft Corporation) C:\windows\SysWOW64\WiFiDisplay.dll
2016-03-01 19:11 - 2016-02-23 07:38 - 00480256 _____ (Microsoft Corporation) C:\windows\SysWOW64\MCRecvSrc.dll
2016-03-01 19:11 - 2016-02-23 07:37 - 01118208 _____ (Microsoft Corporation) C:\windows\system32\localspl.dll
2016-03-01 19:11 - 2016-02-23 07:37 - 00613376 _____ (Microsoft Corporation) C:\windows\system32\SettingSync.dll
2016-03-01 19:11 - 2016-02-23 07:36 - 00713728 _____ (Microsoft Corporation) C:\windows\SysWOW64\netlogon.dll
2016-03-01 19:11 - 2016-02-23 07:36 - 00379392 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfmkvsrcsnk.dll
2016-03-01 19:11 - 2016-02-23 07:36 - 00250880 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2016-03-01 19:11 - 2016-02-23 07:35 - 00400896 _____ (Microsoft Corporation) C:\windows\SysWOW64\winspool.drv
2016-03-01 19:11 - 2016-02-23 07:31 - 00585216 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.AccountsControl.dll
2016-03-01 19:11 - 2016-02-23 07:30 - 01731584 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2016-03-01 19:11 - 2016-02-23 07:30 - 00646656 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.ApplicationModel.Store.dll
2016-03-01 19:11 - 2016-02-23 07:29 - 00349696 _____ (Microsoft Corporation) C:\windows\SysWOW64\NetSetupShim.dll
2016-03-01 19:11 - 2016-02-23 07:28 - 00555520 _____ (Microsoft Corporation) C:\windows\system32\SyncController.dll
2016-03-01 19:11 - 2016-02-23 07:28 - 00256512 _____ (Microsoft Corporation) C:\windows\system32\accountaccessor.dll
2016-03-01 19:11 - 2016-02-23 07:24 - 04827136 _____ (Microsoft Corporation) C:\windows\system32\ExplorerFrame.dll
2016-03-01 19:11 - 2016-02-23 07:24 - 02755584 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2016-03-01 19:11 - 2016-02-23 07:24 - 01105920 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.Media.Audio.dll
2016-03-01 19:11 - 2016-02-23 07:24 - 00489984 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.UI.dll
2016-03-01 19:11 - 2016-02-23 07:22 - 01944576 _____ (Microsoft Corporation) C:\windows\SysWOW64\InputService.dll
2016-03-01 19:11 - 2016-02-23 07:21 - 00245760 _____ (Microsoft Corporation) C:\windows\SysWOW64\TextInputFramework.dll
2016-03-01 19:11 - 2016-02-23 07:21 - 00133632 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.UI.Core.TextInput.dll
2016-03-01 19:11 - 2016-02-23 07:20 - 00083456 _____ (Microsoft Corporation) C:\windows\SysWOW64\InputLocaleManager.dll
2016-03-01 19:11 - 2016-02-23 07:17 - 02635264 _____ (Microsoft Corporation) C:\windows\system32\Windows.UI.Logon.dll
2016-03-01 19:11 - 2016-02-23 07:14 - 00990720 _____ (Microsoft Corporation) C:\windows\system32\SettingSyncCore.dll
2016-03-01 19:11 - 2016-02-23 07:11 - 01390080 _____ (Microsoft Corporation) C:\windows\system32\Windows.UI.Shell.dll
2016-03-01 19:11 - 2016-02-23 07:05 - 00503296 _____ (Microsoft Corporation) C:\windows\SysWOW64\SettingSync.dll
2016-03-01 19:11 - 2016-02-23 07:01 - 02295808 _____ (Microsoft Corporation) C:\windows\system32\wlansvc.dll
2016-03-01 19:11 - 2016-02-23 06:59 - 01500672 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2016-03-01 19:11 - 2016-02-23 06:58 - 00450560 _____ (Microsoft Corporation) C:\windows\SysWOW64\SyncController.dll
2016-03-01 19:11 - 2016-02-23 06:56 - 04412928 _____ (Microsoft Corporation) C:\windows\SysWOW64\ExplorerFrame.dll
2016-03-01 19:11 - 2016-02-23 06:55 - 04894208 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2016-03-01 19:11 - 2016-02-23 06:55 - 02229760 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2016-03-01 19:11 - 2016-02-23 06:53 - 01799168 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.UI.Logon.dll
2016-03-01 19:11 - 2016-02-23 06:52 - 11545600 _____ (Microsoft Corporation) C:\windows\system32\twinui.dll
2016-03-01 19:11 - 2016-02-23 06:51 - 00754176 _____ (Microsoft Corporation) C:\windows\SysWOW64\SettingSyncCore.dll
2016-03-01 19:11 - 2016-02-23 06:50 - 09919488 _____ (Microsoft Corporation) C:\windows\SysWOW64\twinui.dll
2016-03-01 19:11 - 2016-02-23 06:42 - 03425792 _____ (Microsoft Corporation) C:\windows\system32\Windows.Media.dll
2016-03-01 19:11 - 2016-02-23 06:41 - 02912256 _____ (Microsoft Corporation) C:\windows\system32\CertEnroll.dll
2016-03-01 19:11 - 2016-02-23 06:39 - 13382656 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2016-03-01 19:11 - 2016-02-23 06:39 - 02581504 _____ (Microsoft Corporation) C:\windows\system32\MFMediaEngine.dll
2016-03-01 19:11 - 2016-02-23 06:36 - 12125696 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2016-03-01 19:11 - 2016-02-23 06:36 - 03666432 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2016-03-01 19:11 - 2016-02-23 06:35 - 07533568 _____ (Microsoft Corporation) C:\windows\system32\mstscax.dll
2016-03-01 19:11 - 2016-02-23 06:33 - 02604032 _____ (Microsoft Corporation) C:\windows\SysWOW64\CertEnroll.dll
2016-03-01 19:11 - 2016-02-23 06:32 - 02793472 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.Media.dll
2016-03-01 19:11 - 2016-02-23 06:30 - 02061312 _____ (Microsoft Corporation) C:\windows\SysWOW64\MFMediaEngine.dll
2016-03-01 19:11 - 2016-02-23 06:28 - 06740992 _____ (Microsoft Corporation) C:\windows\SysWOW64\mstscax.dll
2016-03-01 19:11 - 2016-02-09 04:28 - 00277856 _____ (Microsoft Corporation) C:\windows\system32\Drivers\sdbus.sys
2016-03-01 19:11 - 2016-02-09 04:13 - 00185184 _____ (Microsoft Corporation) C:\windows\system32\Drivers\dumpsd.sys
2016-03-01 19:11 - 2016-02-09 03:24 - 00641536 _____ (Microsoft Corporation) C:\windows\system32\enterprisecsps.dll
2016-03-01 19:11 - 2016-02-09 03:18 - 00297472 _____ (Microsoft Corporation) C:\windows\system32\thumbcache.dll
2016-03-01 19:11 - 2016-02-09 03:18 - 00237056 _____ (Microsoft Corporation) C:\windows\SysWOW64\thumbcache.dll
2016-03-01 19:11 - 2016-02-09 03:07 - 01626624 _____ (Microsoft Corporation) C:\windows\SysWOW64\dwmcore.dll
2016-03-01 19:11 - 2016-02-09 03:07 - 00086016 _____ (Microsoft Corporation) C:\windows\system32\DeviceEnroller.exe
2016-03-01 19:11 - 2016-02-09 03:04 - 01946624 _____ (Microsoft Corporation) C:\windows\system32\dwmcore.dll
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2016-03-26 11:49 - 2015-12-14 15:19 - 00881036 _____ C:\windows\system32\PerfStringBackup.INI
2016-03-26 11:49 - 2015-10-30 07:21 - 00000000 ____D C:\windows\INF
2016-03-26 11:43 - 2016-01-01 22:51 - 00000000 ____D C:\Users\willi\AppData\Roaming\Curse Client
2016-03-26 11:43 - 2016-01-01 22:38 - 00000000 ____D C:\Users\willi\AppData\Local\Deployment
2016-03-26 11:43 - 2015-12-27 16:33 - 00000000 ____D C:\Users\willi\AppData\Roaming\Skype
2016-03-26 11:42 - 2015-12-25 09:11 - 00000924 _____ C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-03-26 11:42 - 2015-12-14 15:14 - 00000006 ____H C:\windows\Tasks\SA.DAT
2016-03-26 11:41 - 2015-10-30 06:28 - 00524288 ___SH C:\windows\system32\config\BBI
2016-03-26 08:19 - 2015-12-25 09:11 - 00000928 _____ C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-03-26 07:49 - 2015-12-25 19:36 - 00000000 ____D C:\Users\willi\.oracle_jre_usage
2016-03-26 07:48 - 2016-01-31 02:01 - 00000000 ____D C:\Users\willi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2016-03-26 07:48 - 2016-01-31 02:01 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2016-03-26 07:48 - 2016-01-31 02:01 - 00000000 ____D C:\Program Files\WinRAR
2016-03-26 07:45 - 2015-12-25 19:36 - 00004166 _____ C:\windows\System32\Tasks\User_Feed_Synchronization-{1D84A35C-070A-44DA-9AB2-285C5EA815E7}
2016-03-26 07:43 - 2015-10-30 07:24 - 00000000 ____D C:\windows\system32\NDF
2016-03-25 22:26 - 2015-12-25 09:09 - 00000000 ___RD C:\Users\willi\OneDrive
2016-03-25 21:36 - 2016-01-24 23:17 - 00001001 _____ C:\Users\Public\Desktop\Guild Wars 2.lnk
2016-03-25 21:36 - 2016-01-21 08:27 - 00001579 _____ C:\Users\Public\Desktop\League of Legends.lnk
2016-03-25 21:36 - 2016-01-01 22:51 - 00001093 _____ C:\Users\willi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Curse.lnk
2016-03-25 21:36 - 2016-01-01 22:51 - 00001087 _____ C:\Users\willi\Desktop\Curse.lnk
2016-03-25 21:36 - 2015-12-29 18:13 - 00000588 _____ C:\Users\willi\Desktop\Speccy.lnk
2016-03-25 21:36 - 2015-12-28 22:26 - 00000826 _____ C:\Users\Public\Desktop\Battle.net.lnk
2016-03-25 21:36 - 2015-12-27 16:33 - 00002634 _____ C:\Users\Public\Desktop\Skype.lnk
2016-03-25 21:36 - 2015-12-25 20:19 - 00001051 _____ C:\Users\Public\Desktop\Gyazo.lnk
2016-03-25 21:36 - 2015-12-25 18:02 - 00001286 _____ C:\Users\willi\Desktop\TeamSpeak 3 Client.lnk
2016-03-25 21:36 - 2015-12-25 09:12 - 00002338 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-03-25 21:36 - 2015-12-25 09:09 - 00002367 _____ C:\Users\willi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2016-03-25 21:36 - 2015-12-15 11:54 - 00001273 _____ C:\Users\Public\Desktop\3DMark.lnk
2016-03-25 21:35 - 2015-10-30 09:02 - 00000000 ____D C:\windows\DigitalLocker
2016-03-25 21:04 - 2015-10-30 07:24 - 00000000 ___HD C:\Program Files\WindowsApps
2016-03-25 21:04 - 2015-10-30 07:24 - 00000000 ____D C:\windows\AppReadiness
2016-03-25 20:57 - 2015-12-25 18:03 - 00000000 ____D C:\Users\willi\AppData\Roaming\TS3Client
2016-03-25 20:57 - 2015-12-14 15:24 - 00000000 __RHD C:\Users\Public\AccountPictures
2016-03-23 08:48 - 2015-12-25 18:56 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2016-03-23 08:24 - 2015-12-27 16:33 - 00000000 ___RD C:\Program Files (x86)\Skype
2016-03-23 08:24 - 2015-12-27 16:33 - 00000000 ____D C:\ProgramData\Skype
2016-03-22 23:09 - 2015-12-29 18:46 - 00000000 ____D C:\Users\willi\AppData\Local\CrashDumps
2016-03-22 20:31 - 2015-10-30 07:11 - 00000000 ____D C:\windows\CbsTemp
2016-03-22 00:19 - 2015-12-28 22:26 - 00000000 ____D C:\Users\willi\AppData\Local\Battle.net
2016-03-13 20:44 - 2015-12-28 22:26 - 00000000 ____D C:\Users\willi\AppData\Roaming\Battle.net
2016-03-13 20:44 - 2015-12-28 22:23 - 00000000 ____D C:\ProgramData\Battle.net
2016-03-12 19:02 - 2015-12-25 09:06 - 00000000 ____D C:\Users\willi
2016-03-11 20:47 - 2015-12-25 21:08 - 00000000 ____D C:\Users\willi\Documents\My Games
2016-03-09 17:46 - 2015-12-14 15:09 - 00348872 _____ C:\windows\system32\FNTCACHE.DAT
2016-03-09 00:30 - 2015-10-30 07:24 - 00000000 ____D C:\Program Files\Windows Portable Devices
2016-03-09 00:30 - 2015-10-30 07:24 - 00000000 ____D C:\Program Files\Windows Multimedia Platform
2016-03-09 00:30 - 2015-10-30 07:24 - 00000000 ____D C:\Program Files (x86)\Windows Portable Devices
2016-03-09 00:30 - 2015-10-30 07:24 - 00000000 ____D C:\Program Files (x86)\Windows Multimedia Platform
2016-03-08 18:52 - 2015-12-15 14:07 - 00000000 ____D C:\windows\system32\MRT
2016-03-08 18:50 - 2015-12-15 14:07 - 143659408 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2016-03-08 07:12 - 2015-10-30 07:26 - 00829944 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2016-03-08 07:12 - 2015-10-30 07:26 - 00176632 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2016-03-06 17:00 - 2016-02-22 20:42 - 00000000 ____D C:\Users\willi\AppData\Local\Frontier_Developments
2016-03-06 10:59 - 2015-12-25 09:43 - 00000000 ____D C:\Users\willi\AppData\Roaming\.minecraft
2016-03-05 19:14 - 2015-12-25 09:11 - 00003986 _____ C:\windows\System32\Tasks\GoogleUpdateTaskMachineUA
2016-03-05 19:14 - 2015-12-25 09:11 - 00003754 _____ C:\windows\System32\Tasks\GoogleUpdateTaskMachineCore
2016-03-02 17:41 - 2015-10-30 07:24 - 00000000 ____D C:\windows\rescache
2016-03-02 08:00 - 2015-12-25 20:19 - 00003544 _____ C:\windows\System32\Tasks\GyazoUpdateTaskMachineDaily
2016-03-02 08:00 - 2015-12-25 20:19 - 00003408 _____ C:\windows\System32\Tasks\GyazoUpdateTaskMachine
2016-03-02 08:00 - 2015-12-25 20:19 - 00000000 ____D C:\Program Files (x86)\Gyazo
2016-03-01 20:45 - 2015-12-15 11:51 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2016-03-01 20:45 - 2015-12-15 11:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2016-03-01 20:45 - 2015-12-15 11:49 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2016-03-01 20:16 - 2015-10-30 09:07 - 00000000 ____D C:\Program Files\Windows Journal
2016-03-01 20:16 - 2015-10-30 07:24 - 00000000 __RSD C:\windows\Media
2016-03-01 20:16 - 2015-10-30 07:24 - 00000000 ___RD C:\windows\PurchaseDialog
2016-03-01 20:16 - 2015-10-30 07:24 - 00000000 ____D C:\windows\system32\WinBioPlugIns
2016-03-01 20:16 - 2015-10-30 07:24 - 00000000 ____D C:\windows\system32\SystemResetPlatform
2016-03-01 20:16 - 2015-10-30 07:24 - 00000000 ____D C:\windows\system32\appraiser
2016-03-01 20:16 - 2015-10-30 07:24 - 00000000 ____D C:\windows\bcastdvr
2016-03-01 20:16 - 2015-10-30 06:28 - 00000000 ____D C:\windows\SysWOW64\Dism
2016-03-01 20:16 - 2015-10-30 06:28 - 00000000 ____D C:\windows\system32\Dism
2016-03-01 20:15 - 2015-12-15 11:48 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2016-03-01 20:15 - 2015-10-30 07:24 - 00000000 ____D C:\windows\Help
2016-03-01 20:14 - 2015-12-15 11:49 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2016-03-01 19:29 - 2015-12-25 09:07 - 00000000 ____D C:\Users\willi\AppData\Local\NVIDIA Corporation
 
==================== Files in the root of some directories =======
 
2016-03-23 08:57 - 2016-03-23 08:57 - 6493696 _____ () C:\Users\willi\AppData\Roaming\agent.dat
2016-03-23 08:57 - 2016-03-23 08:57 - 0127488 _____ () C:\Users\willi\AppData\Roaming\Installer.dat
2016-03-23 08:57 - 2016-03-23 08:57 - 0072707 _____ () C:\Users\willi\AppData\Roaming\Jaytom.tst
2016-03-23 08:57 - 2016-03-23 08:57 - 0018432 _____ () C:\Users\willi\AppData\Roaming\Main.dat
2016-03-23 08:57 - 2016-03-23 08:57 - 1622132 _____ () C:\Users\willi\AppData\Roaming\Zimlux.tst
2015-12-15 11:52 - 2015-12-15 11:52 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
 
Some files in TEMP:
====================
C:\Users\willi\AppData\Local\Temp\C04A.tmp.exe
C:\Users\willi\AppData\Local\Temp\dxdiag.exe
C:\Users\willi\AppData\Local\Temp\Gw2.exe
C:\Users\willi\AppData\Local\Temp\ICReinstall_FlashVideoPlayer.exe
C:\Users\willi\AppData\Local\Temp\jansi-64-3383648849998240709.dll
C:\Users\willi\AppData\Local\Temp\jre-8u71-windows-au.exe
C:\Users\willi\AppData\Local\Temp\jre-8u73-windows-au.exe
C:\Users\willi\AppData\Local\Temp\nvSCPAPI.dll
C:\Users\willi\AppData\Local\Temp\nvSCPAPI64.dll
C:\Users\willi\AppData\Local\Temp\nvStInst.exe
C:\Users\willi\AppData\Local\Temp\tu17p84.exe
 
 
==================== Bamital & volsnap =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\windows\system32\winlogon.exe => File is digitally signed
C:\windows\system32\wininit.exe => File is digitally signed
C:\windows\explorer.exe => File is digitally signed
C:\windows\SysWOW64\explorer.exe => File is digitally signed
C:\windows\system32\svchost.exe => File is digitally signed
C:\windows\SysWOW64\svchost.exe => File is digitally signed
C:\windows\system32\services.exe => File is digitally signed
C:\windows\system32\User32.dll => File is digitally signed
C:\windows\SysWOW64\User32.dll => File is digitally signed
C:\windows\system32\userinit.exe => File is digitally signed
C:\windows\SysWOW64\userinit.exe => File is digitally signed
C:\windows\system32\rpcss.dll => File is digitally signed
C:\windows\system32\dnsapi.dll
[2015-10-30 07:18] - [2015-10-30 07:18] - 0686984 ____A (Microsoft Corporation) EA5CC9EE0AF6B2323B60D5CC3170E10E
 
C:\windows\SysWOW64\dnsapi.dll
[2015-10-30 07:18] - [2015-10-30 07:18] - 0535088 ____A () D41D8CD98F00B204E9800998ECF8427E
 
C:\windows\SysWOW64\dnsapi.dll => no Company Name <===== ATTENTION
 
C:\windows\system32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2016-03-23 15:23
 
==================== End of FRST.txt ============================


#5 willyman18

willyman18
  • Topic Starter

  • Members
  • 66 posts
  • OFFLINE
  •  
  • Local time:04:44 AM

Posted 26 March 2016 - 07:04 AM

Additional scan result of Farbar Recovery Scan Tool (x64) Version:05-03-2016 01
Ran by willi (2016-03-26 11:55:38)
Running from F:\willi
Windows 10 Home Version 1511 (X64) (2015-12-25 09:05:47)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-3667704814-1699542734-850788743-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-3667704814-1699542734-850788743-503 - Limited - Disabled)
Guest (S-1-5-21-3667704814-1699542734-850788743-501 - Limited - Disabled)
willi (S-1-5-21-3667704814-1699542734-850788743-1002 - Administrator - Enabled) => C:\Users\willi
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
3DMark (HKLM-x32\...\{12d6e0d7-21d5-4755-9da2-70352c6f7558}) (Version: 1.5.915.0 - Futuremark)
3DMark (Version: 1.5.915.0 - Futuremark) Hidden
Asmedia ASM106x SATA Host Controller Driver (HKLM-x32\...\{61942EF5-2CD8-47D4-869C-2E9A8BB085F1}) (Version: 2.0.9.0001 - Asmedia Technology)
Avast Free Antivirus (HKLM-x32\...\Avast) (Version: 11.1.2253 - AVAST Software)
Awesomenauts (HKLM-x32\...\Steam App 204300) (Version:  - Ronimo Games)
Battle.net (HKLM-x32\...\Battle.net) (Version:  - Blizzard Entertainment)
Block N Load (HKLM-x32\...\Steam App 299360) (Version:  - Jagex)
Body Text Feathering (HKLM-x32\...\PopupProduct) (Version: 1.0.0.0 - Body Text Feathering) <==== ATTENTION
BurnInTest v8.0 Pro (HKLM\...\BurnInTest_is1) (Version: 8.0.1041.0 - Passmark Software)
Counter-Strike (HKLM\...\Steam App 10) (Version:  - Valve)
Counter-Strike: Condition Zero (HKLM\...\Steam App 80) (Version:  - Valve)
Counter-Strike: Global Offensive (HKLM-x32\...\Steam App 730) (Version:  - Valve)
Counter-Strike: Source (HKLM-x32\...\Steam App 240) (Version:  - Valve)
Curse (HKLM-x32\...\{DEE70742-F4E9-44CA-B2B9-EE95DCF37295}) (Version: 6.0.0.0 - Curse)
Curse Client (HKU\S-1-5-21-3667704814-1699542734-850788743-1002\...\101a9f93b8f0bb6f) (Version: 5.1.1.844 - Curse)
Day of Defeat: Source (HKLM\...\Steam App 300) (Version:  - Valve)
Dungeon Defenders II (HKLM-x32\...\Steam App 236110) (Version:  - Trendy Entertainment)
Elite Dangerous (HKLM-x32\...\Steam App 359320) (Version:  - Frontier Developments)
Futuremark SystemInfo (HKLM-x32\...\{70690D9E-3D00-47D6-9CE9-BC3B6F900447}) (Version: 4.41.563.0 - Futuremark)
Garry's Mod (HKLM-x32\...\Steam App 4000) (Version:  - Facepunch Studios)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 49.0.2623.87 - Google Inc.)
Google Update Helper (x32 Version: 1.3.29.5 - Google Inc.) Hidden
Grand Theft Auto V (HKLM-x32\...\Steam App 271590) (Version:  - Rockstar North)
Guild Wars 2 (HKLM-x32\...\Guild Wars 2) (Version:  - NCsoft Corporation, Ltd.)
Guns of Icarus Online (HKLM-x32\...\Steam App 209080) (Version:  - Muse Games)
Gyazo 3.2.1 (HKLM-x32\...\{6DB8C365-E719-4BA5-9594-10DFC244D3FD}_is1) (Version:  - Nota Inc.)
Half-Life (HKLM-x32\...\Steam App 70) (Version:  - Valve)
Half-Life 2 (HKLM-x32\...\Steam App 220) (Version:  - Valve)
Half-Life 2: Episode One (HKLM-x32\...\Steam App 380) (Version:  - Valve)
Half-Life 2: Episode Two (HKLM-x32\...\Steam App 420) (Version:  - Valve)
Half-Life 2: Lost Coast (HKLM\...\Steam App 340) (Version:  - Valve)
Half-Life: Source (HKLM\...\Steam App 280) (Version:  - Valve)
Hearthstone (HKLM-x32\...\Hearthstone) (Version:  - Blizzard Entertainment)
Intel® Chipset Device Software (x32 Version: 10.0.27 - Intel® Corporation) Hidden
Intel® Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 10.0.1.1000 - Intel Corporation)
Intel® Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 14.5.0.1081 - Intel Corporation)
Intel® Update Manager (HKLM-x32\...\{B991A1BC-DE0F-41B3-9037-B2F948F706EC}) (Version: 3.1.1228 - Intel Corporation)
Java 8 Update 73 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86418073F0}) (Version: 8.0.730.2 - Oracle Corporation)
Java 8 Update 74 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86418074F0}) (Version: 8.0.740.2 - Oracle Corporation)
Kerbal Space Program (HKLM-x32\...\Steam App 220200) (Version:  - Squad)
Killing Floor (HKLM-x32\...\Steam App 1250) (Version:  - Tripwire Interactive)
League of Legends (HKLM-x32\...\League of Legends 3.0.1) (Version: 3.0.1 - Riot Games)
League of Legends (x32 Version: 3.0.1 - Riot Games) Hidden
Left 4 Dead (HKLM-x32\...\Steam App 500) (Version:  - Valve)
Left 4 Dead 2 (HKLM\...\Steam App 550) (Version:  - Valve)
Mad Riders (HKLM-x32\...\Steam App 208860) (Version:  - Techland)
Malwarebytes Anti-Malware version 2.2.1.1043 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes)
Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation)
Microsoft Office Home and Student 2010 (HKLM-x32\...\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Minecraft (HKLM-x32\...\{1C16BCA3-EBC1-49F6-8623-8FBFB9CCC872}) (Version: 1.0.3.0 - Mojang)
NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version:  - )
NVIDIA GeForce Experience 2.10.2.40 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.10.2.40 - NVIDIA Corporation)
NVIDIA Graphics Driver 362.00 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 362.00 - NVIDIA Corporation)
NVIDIA nTune (HKLM-x32\...\InstallShield_{7C7F30F4-94E7-4AA8-8941-90C4A80C68BF}) (Version: 1.00.0000 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.15.0428 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.15.0428 - NVIDIA Corporation)
PerformanceTest v8.0 (HKLM\...\PerformanceTest 8_is1) (Version: 8.0.1047.0 - Passmark Software)
Portal 2 (HKLM-x32\...\Steam App 620) (Version:  - Valve)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7541 - Realtek Semiconductor Corp.)
Rocket League (HKLM-x32\...\Steam App 252950) (Version:  - Psyonix)
Rockstar Games Social Club (HKLM-x32\...\Rockstar Games Social Club) (Version: 1.1.7.2 - Rockstar Games)
RollerCoaster Tycoon 3: Platinum! (HKLM-x32\...\Steam App 2700) (Version:  - Frontier)
SafeZone Stable 1.48.2066.44 (x32 Version: 1.48.2066.44 - Avast Software) Hidden
Saints Row: The Third (HKLM-x32\...\Steam App 55230) (Version:  - Volition)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version:  - Microsoft)
Setup (HKLM-x32\...\{7ADF667E-E14D-4D2C-827C-B0108F0D93BC}) (Version:  - ) <==== ATTENTION
SHIELD Streaming (Version: 5.1.0270 - NVIDIA Corporation) Hidden
SHIELD Wireless Controller Driver (Version: 2.10.2.40 - NVIDIA Corporation) Hidden
Sid Meier's Civilization V (HKLM-x32\...\Steam App 8930) (Version:  - 2K Games, Inc.)
Skype™ 7.21 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.21.100 - Skype Technologies S.A.)
SNOW (HKLM\...\Steam App 244930) (Version:  - Poppermost Productions)
Speccy (HKLM\...\Speccy) (Version: 1.29 - Piriform)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
SunnyDay (HKLM-x32\...\SunnyDay13_is1) (Version:  - SUNNYDAY)
SunnyDayApps Maintenance 013.236 (HKLM-x32\...\rec_gb_236_is1) (Version:  - SUNNYDAYAPPS) <==== ATTENTION
Tabletop Simulator (HKLM\...\Steam App 286160) (Version:  - Berserk Games)
Team Fortress 2 (HKLM-x32\...\Steam App 440) (Version:  - Valve)
TeamSpeak 3 Client (HKU\S-1-5-21-3667704814-1699542734-850788743-1002\...\TeamSpeak 3 Client) (Version: 3.0.18 - TeamSpeak Systems GmbH)
Terraria (HKLM-x32\...\Steam App 105600) (Version:  - Re-Logic)
The Sims™ 3 (HKLM-x32\...\Steam App 47890) (Version:  - The Sims Studio)
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.2 - VideoLAN)
WinRAR 5.31 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.31.0 - win.rar GmbH)
Worms Revolution (HKLM-x32\...\Steam App 200170) (Version:  - Team17 Digital Ltd)
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-3667704814-1699542734-850788743-1002_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\willi\AppData\Local\Microsoft\OneDrive\17.3.6302.0225\FileCoAuth.exe (Microsoft Corporation)
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {1940DA92-C768-4AB4-B53B-71D302B85408} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-03-05] (Google Inc.)
Task: {1E3ACD2E-602B-4DB0-987F-ECF96F23DF13} - System32\Tasks\avast! Windows 10 Start Menu helper => c:\program files\avast software\avast\asww10mon.exe [2016-03-25] (AVAST Software)
Task: {3827EA74-9908-4874-8BC4-CC4FF97F4725} - System32\Tasks\SafeZone scheduled Autoupdate 1458977815 => C:\Program Files\AVAST Software\SZBrowser\launcher.exe [2016-02-01] (Avast Software)
Task: {3EB44B1E-7494-4E9F-897E-BF835AE2434A} - System32\Tasks\Bimui => C:\PROGRA~1\BAOMKY~1\Boeehir.bat
Task: {4D63DB2A-839D-49AB-8542-78A26ACB5BAC} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473-Logon => C:\Program Files (x86)\Intel\Intel® Update Manager\bin\iumsvc.exe [2015-09-25] (Intel Corporation)
Task: {83C15578-2BAD-4E9A-9ACE-5185B3A9E5C6} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 => C:\Program Files (x86)\Intel\Intel® Update Manager\bin\iumsvc.exe [2015-09-25] (Intel Corporation)
Task: {8A8CB5AD-622B-4CE9-818C-606E72B334CE} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2016-03-25] (AVAST Software)
Task: {99D91490-F9C7-4488-BA3E-AE684A56730F} - System32\Tasks\NIFQIDEGATILRONX => C:\ProgramData\Service1104\Service1104.exe <==== ATTENTION
Task: {A7D1B83E-CCE1-41A3-93CA-563B9B0A7282} - System32\Tasks\GyazoUpdateTaskMachine => C:\Program Files (x86)\Gyazo\GyazoUpdate.exe [2016-02-17] ()
Task: {B197630C-FE6B-4346-8B0D-AA722B4E044B} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\windows\system32\MRT.exe [2016-03-08] (Microsoft Corporation)
Task: {BA3BFDA4-E247-41A2-A95D-39254FA36F0F} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-03-05] (Google Inc.)
Task: {CC646D0F-A353-4B18-B6B0-2798D9D5A618} - \{080C0D47-0E04-0E0A-0C11-78097E05110C} -> No File <==== ATTENTION
Task: {CE84A1E1-5F0A-4497-859E-42296F9EDA8C} - System32\Tasks\GyazoUpdateTaskMachineDaily => C:\Program Files (x86)\Gyazo\GyazoUpdate.exe [2016-02-17] ()
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\NIFQIDEGATILRONX.job => C:\ProgramData\Service1104\Service1104.exe <==== ATTENTION
 
==================== Shortcuts =============================
 
(The entries could be listed to be restored or removed.)
 
==================== Loaded Modules (Whitelisted) ==============
 
2015-10-30 07:17 - 2015-10-30 07:17 - 00028672 _____ () C:\windows\SYSTEM32\efsext.dll
2015-10-30 07:18 - 2015-10-30 07:18 - 00185856 _____ () C:\windows\SYSTEM32\ism32k.dll
2016-03-01 20:15 - 2016-02-23 20:28 - 00134712 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2016-03-01 19:47 - 2016-02-17 06:56 - 01416064 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\MessageBus.dll
2016-03-01 19:47 - 2016-02-17 06:56 - 00299392 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamBase.dll
2016-03-01 19:47 - 2016-02-17 06:56 - 03613056 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\Poco.dll
2015-12-15 11:54 - 2013-07-04 03:32 - 00936728 _____ () C:\Program Files (x86)\ASUS\AXSP\1.02.00\atkexComSvc.exe
2016-03-01 19:11 - 2016-02-23 11:27 - 02654872 _____ () C:\windows\system32\CoreUIComponents.dll
2016-03-01 19:11 - 2016-02-23 11:27 - 02654872 _____ () C:\windows\System32\CoreUIComponents.dll
2016-01-21 19:24 - 2016-01-21 19:25 - 00144384 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe
2016-03-25 21:29 - 2016-03-24 13:28 - 03247280 _____ () C:\Users\willi\AppData\Local\SunnyDay13\usun.exe
2015-12-26 09:43 - 2015-12-07 04:14 - 00093696 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\Windows.UI.Shell.SharedUtilities.dll
2016-03-01 19:11 - 2016-02-23 08:36 - 00472064 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll
2016-01-13 20:54 - 2016-01-05 01:29 - 07992832 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2016-01-13 20:54 - 2016-01-05 01:23 - 00591360 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2016-01-28 17:28 - 2016-01-16 05:10 - 02483200 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2016-01-28 17:28 - 2016-01-16 05:13 - 04089856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2016-02-29 18:19 - 2016-02-29 18:19 - 01417216 _____ () C:\Users\willi\AppData\Roaming\cpuminer\cpm.exe
2015-12-14 16:01 - 2015-12-10 14:12 - 01197568 _____ () C:\Program Files\Scan 3XS\menu.exe
2016-03-25 21:29 - 2016-03-24 13:28 - 04055728 _____ () C:\Program Files (x86)\SunnyDay13\SunnyDay.exe
2016-03-25 21:32 - 2016-03-23 15:19 - 04054704 _____ () C:\Program Files (x86)\rec_gb_236\rec_gb_236.exe
2016-03-25 22:24 - 2016-03-25 22:24 - 00258896 _____ () C:\Program Files\AVAST Software\Avast\avastnm.exe
2016-03-25 22:23 - 2016-03-25 22:23 - 00113496 _____ () C:\Program Files\AVAST Software\Avast\log.dll
2016-03-25 22:23 - 2016-03-25 22:23 - 00133768 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
2016-03-25 22:25 - 2016-03-25 22:25 - 02857472 _____ () C:\Program Files\AVAST Software\Avast\defs\16032501\algo.dll
2016-03-25 22:23 - 2016-03-25 22:23 - 00480760 _____ () C:\Program Files\AVAST Software\Avast\ffl2.dll
2015-12-15 11:54 - 2016-03-26 11:42 - 00039720 _____ () C:\Program Files (x86)\ASUS\AXSP\1.02.00\PEbiosinterface32.dll
2015-12-15 11:54 - 2013-07-04 03:32 - 00104448 _____ () C:\Program Files (x86)\ASUS\AXSP\1.02.00\ATKEX.dll
2016-01-21 19:24 - 2016-01-21 19:25 - 00141312 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeBackgroundTasks.dll
2016-01-21 19:24 - 2016-01-21 19:25 - 22330368 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkyWrap.dll
2016-03-01 19:47 - 2016-02-17 07:02 - 00020352 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll
2015-12-23 17:23 - 2015-12-23 17:23 - 00393608 _____ () C:\Users\willi\AppData\Roaming\Curse Client\Bin\opus.dll
2016-03-25 22:23 - 2016-03-25 22:23 - 40539648 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2014-04-03 16:48 - 2014-04-03 16:48 - 01241560 _____ () C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\ACE.dll
2016-03-26 07:36 - 2016-02-01 09:50 - 62337016 _____ () C:\Program Files\AVAST Software\SZBrowser\1.48.2066.44\SZBrowser.dll
2016-03-26 07:36 - 2016-02-01 09:50 - 02074104 _____ () C:\Program Files\AVAST Software\SZBrowser\1.48.2066.44\libglesv2.dll
2016-03-26 07:36 - 2016-02-01 09:50 - 00081400 _____ () C:\Program Files\AVAST Software\SZBrowser\1.48.2066.44\libegl.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\zdengine => ""="service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\zdwfp => ""="Driver"
 
==================== EXE Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
 
==================== Hosts content: ==========================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2015-10-30 07:24 - 2016-03-25 21:34 - 00001626 ____A C:\windows\system32\Drivers\etc\hosts
 
107.178.255.88 www.google-analytics.com
107.178.255.88 www.statcounter.com
107.178.255.88 statcounter.com
107.178.255.88 ssl.google-analytics.com
107.178.255.88 partner.googleadservices.com
107.178.255.88 google-analytics.com
107.178.248.130 static.doubleclick.net
107.178.247.130 connect.facebook.net
107.178.255.88 www.google-analytics.com
107.178.255.88 www.statcounter.com
107.178.255.88 statcounter.com
107.178.255.88 ssl.google-analytics.com
107.178.255.88 partner.googleadservices.com
107.178.255.88 google-analytics.com
107.178.248.130 static.doubleclick.net
107.178.247.130 connect.facebook.net127.0.0.1       down.baidu2016.com
127.0.0.1       123.sogou.com
127.0.0.1       www.czzsyzgm.com
127.0.0.1       www.czzsyzxl.com
127.0.0.1       union.baidu2019.com
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-3667704814-1699542734-850788743-1002\Control Panel\Desktop\\Wallpaper -> C:\Users\willi\AppData\Local\Microsoft\Windows\Themes\RoamedThemeFiles\DesktopBackground\natsu-dragneel-fairy-tail-26497-1920x1080.jpg
DNS Servers: 192.168.0.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
(Currently there is no automatic fix for this section.)
 
HKLM\...\StartupApproved\Run: => "SpaceSoundPro"
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [{201E47EB-C9A1-476A-B43D-C1779055AE1B}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{96F27A94-7F9A-4ED5-9BB1-644E9E3D2518}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{ACA75CB3-1E1F-4D3E-AE24-DE6483C10E7D}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{0487CE41-2066-4ED6-A8E9-0BEB786A3AF5}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [TCP Query User{AB0BBA93-F45A-40F6-9BFE-ABA17C57ACBF}C:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => (Allow) C:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe
FirewallRules: [UDP Query User{665B9E1F-CC7A-49BA-B295-C9BA126679A0}C:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => (Allow) C:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe
FirewallRules: [{9993BB27-C584-4638-B651-B67BE8FB1383}] => (Allow) F:\steam\Steam.exe
FirewallRules: [{7B1A6F2F-B754-4966-8227-1ACE9CA638DA}] => (Allow) F:\steam\Steam.exe
FirewallRules: [{3263E5E6-5DA7-42BA-AE00-C07597ABF0A8}] => (Allow) F:\steam\bin\steamwebhelper.exe
FirewallRules: [{F636CE73-CE9E-41D4-8CFE-A045F081393B}] => (Allow) F:\steam\bin\steamwebhelper.exe
FirewallRules: [{9AB064BF-A248-4EE6-A9C1-104135D97543}] => (Allow) F:\programs\steam\Steam.exe
FirewallRules: [{0F526DD0-46EA-4440-B120-5328792C0BDC}] => (Allow) F:\programs\steam\Steam.exe
FirewallRules: [{CCD5058C-EE53-432B-AD59-504CBB8323C0}] => (Allow) F:\programs\steam\bin\steamwebhelper.exe
FirewallRules: [{DB1F0D6A-2AFB-4C97-959C-EEB85E96C871}] => (Allow) F:\programs\steam\bin\steamwebhelper.exe
FirewallRules: [TCP Query User{809A53F1-9EFE-49DB-8212-E00C405990CD}F:\programs\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => (Allow) F:\programs\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe
FirewallRules: [UDP Query User{79853E54-DA99-49D5-8975-D904CAD81626}F:\programs\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => (Allow) F:\programs\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe
FirewallRules: [{B25392EB-6173-42A7-AFC4-7CC33F424BAA}] => (Allow) F:\programs\steam\steamapps\common\Team Fortress 2\hl2.exe
FirewallRules: [{FEEAACC5-536B-4129-9924-69E818AAB033}] => (Allow) F:\programs\steam\steamapps\common\Team Fortress 2\hl2.exe
FirewallRules: [{25CB5E06-2E90-4708-B354-BFBE80D11CAB}] => (Allow) F:\programs\steam\steamapps\common\Dungeon Defenders 2\DunDefLauncher.exe
FirewallRules: [{E865D4D1-D86C-4602-B9C8-62A3B52A2F3C}] => (Allow) F:\programs\steam\steamapps\common\Dungeon Defenders 2\DunDefLauncher.exe
FirewallRules: [{A98013B8-0401-444C-B07D-D2118E0DD7EE}] => (Allow) F:\programs\steam\steamapps\common\GarrysMod\hl2.exe
FirewallRules: [{B988F01D-7458-4985-AFC6-7C12622EAB38}] => (Allow) F:\programs\steam\steamapps\common\GarrysMod\hl2.exe
FirewallRules: [{F75CB5CA-0AE2-4CA1-8846-683D5BACE322}] => (Allow) F:\programs\steam\steamapps\common\Guns of Icarus Online\GunsOfIcarusOnline.exe
FirewallRules: [{838F48FF-DAD5-436E-A57C-85343F3B47EB}] => (Allow) F:\programs\steam\steamapps\common\Guns of Icarus Online\GunsOfIcarusOnline.exe
FirewallRules: [{9005653E-BB32-4227-9EF5-CDC81532DEA0}] => (Allow) F:\programs\steam\steamapps\common\Half-Life\hl.exe
FirewallRules: [{0A14CECA-A334-4234-9426-033F743438D4}] => (Allow) F:\programs\steam\steamapps\common\Half-Life\hl.exe
FirewallRules: [{8CD3CF01-331B-46C1-AC60-A92C9115A921}] => (Allow) F:\programs\steam\steamapps\common\The Sims 3\Game\Bin\Sims3Launcher.exe
FirewallRules: [{CFB44566-8B8E-46A1-BDBA-493370E22614}] => (Allow) F:\programs\steam\steamapps\common\The Sims 3\Game\Bin\Sims3Launcher.exe
FirewallRules: [{1034F588-0876-4B22-8F8E-C7DDBD2697AA}] => (Allow) F:\programs\steam\steamapps\common\Counter-Strike Source\hl2.exe
FirewallRules: [{0A239529-2631-4814-926A-B8905F201712}] => (Allow) F:\programs\steam\steamapps\common\Counter-Strike Source\hl2.exe
FirewallRules: [{9DA6194A-D6E0-485A-91DB-19F2FD1FC968}] => (Allow) F:\programs\steam\steamapps\common\Half-Life 2\hl2.exe
FirewallRules: [{72FC88EE-1367-405D-9A89-47FF43BE5E1B}] => (Allow) F:\programs\steam\steamapps\common\Half-Life 2\hl2.exe
FirewallRules: [{51A3A7F3-ED95-4970-8271-DC51C5C84D64}] => (Allow) F:\programs\steam\steamapps\common\Portal 2\portal2.exe
FirewallRules: [{BCA26FBB-0B2A-408A-8497-1209561DD254}] => (Allow) F:\programs\steam\steamapps\common\Portal 2\portal2.exe
FirewallRules: [{FF5A3B15-83DB-4253-B300-BCE41EEC4A91}] => (Allow) F:\programs\steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe
FirewallRules: [{491040AE-D317-4298-A6F5-310D6EF77980}] => (Allow) F:\programs\steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe
FirewallRules: [{4AB34ACA-1061-4E22-83BC-ADB93BD360B5}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{CB2B250C-9843-43A1-A180-E194150B12DC}] => (Allow) F:\programs\steam\steamapps\common\Awesomenauts\AwesomenautsLauncher.exe
FirewallRules: [{0CF6D27C-2AFA-4C92-9010-1840CB2F8BC7}] => (Allow) F:\programs\steam\steamapps\common\Awesomenauts\AwesomenautsLauncher.exe
FirewallRules: [TCP Query User{262213AA-3BCD-4E07-9698-913299DC235A}F:\programs\steam\steamapps\common\awesomenauts\awesomenauts.exe] => (Allow) F:\programs\steam\steamapps\common\awesomenauts\awesomenauts.exe
FirewallRules: [UDP Query User{D05FF10C-2E88-4B5B-BEE2-E0C88D404C5F}F:\programs\steam\steamapps\common\awesomenauts\awesomenauts.exe] => (Allow) F:\programs\steam\steamapps\common\awesomenauts\awesomenauts.exe
FirewallRules: [{7119C0AC-7296-4EC5-8AD7-A54CB0823641}] => (Allow) F:\programs\steam\steamapps\common\left 4 dead\left4dead.exe
FirewallRules: [{ACB766FE-437A-4781-90D7-9FD8AE8F204C}] => (Allow) F:\programs\steam\steamapps\common\left 4 dead\left4dead.exe
FirewallRules: [{56576593-8919-46F6-8477-072A01C7CA26}] => (Allow) F:\programs\steam\steamapps\common\Terraria\Terraria.exe
FirewallRules: [{7CF8C62E-F6C0-43CE-BC28-82615B2EE5C0}] => (Allow) F:\programs\steam\steamapps\common\Terraria\Terraria.exe
FirewallRules: [{AE6015E0-53B1-4ED8-A933-461556301798}] => (Allow) F:\programs\steam\steamapps\common\Grand Theft Auto V\GTAVLauncher.exe
FirewallRules: [{0C91482D-F8E7-4281-984E-D5CC90B9FE6E}] => (Allow) F:\programs\steam\steamapps\common\Grand Theft Auto V\GTAVLauncher.exe
FirewallRules: [TCP Query User{2DF0CB36-BD4B-41E1-BBC8-36277F3FD9E2}F:\programs\steam\steamapps\common\grand theft auto v\gta5.exe] => (Allow) F:\programs\steam\steamapps\common\grand theft auto v\gta5.exe
FirewallRules: [UDP Query User{5AE17C85-D229-40D3-AE39-D8D5353F0502}F:\programs\steam\steamapps\common\grand theft auto v\gta5.exe] => (Allow) F:\programs\steam\steamapps\common\grand theft auto v\gta5.exe
FirewallRules: [TCP Query User{316BE518-1768-4FE2-8881-982D248472DB}F:\program files (x86)\bin\javaw.exe] => (Allow) F:\program files (x86)\bin\javaw.exe
FirewallRules: [UDP Query User{E7823DF4-9679-49E8-A950-8AF044AC0783}F:\program files (x86)\bin\javaw.exe] => (Allow) F:\program files (x86)\bin\javaw.exe
FirewallRules: [TCP Query User{3D33E0FD-0EE6-4D92-9A77-57D60D36CF43}C:\users\willi\documents\curse\minecraft\install\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => (Allow) C:\users\willi\documents\curse\minecraft\install\runtime\jre-x64\1.8.0_25\bin\javaw.exe
FirewallRules: [UDP Query User{D799C251-E566-424F-91F0-A6D47AE71098}C:\users\willi\documents\curse\minecraft\install\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => (Allow) C:\users\willi\documents\curse\minecraft\install\runtime\jre-x64\1.8.0_25\bin\javaw.exe
FirewallRules: [TCP Query User{CD885183-2B54-48C4-B472-5DCCC20C37F9}C:\program files (x86)\hearthstone\hearthstone.exe] => (Allow) C:\program files (x86)\hearthstone\hearthstone.exe
FirewallRules: [UDP Query User{DC61BA1C-A033-494A-A6F3-65FA9D15D307}C:\program files (x86)\hearthstone\hearthstone.exe] => (Allow) C:\program files (x86)\hearthstone\hearthstone.exe
FirewallRules: [TCP Query User{DA050A56-4E0D-4B5A-8549-8F05DADFE739}F:\program files (x86)\hearthstone\hearthstone.exe] => (Allow) F:\program files (x86)\hearthstone\hearthstone.exe
FirewallRules: [UDP Query User{98C597D7-D021-4D42-9EF0-84EDC8417820}F:\program files (x86)\hearthstone\hearthstone.exe] => (Allow) F:\program files (x86)\hearthstone\hearthstone.exe
FirewallRules: [{162ABC6D-588C-44B4-9A12-026A2B869208}] => (Block) F:\program files (x86)\hearthstone\hearthstone.exe
FirewallRules: [{D8CEF056-9796-46A8-A9F5-2FBB8B1103AB}] => (Block) F:\program files (x86)\hearthstone\hearthstone.exe
FirewallRules: [{20B3A30A-857D-4A35-9CD5-191B8E69159E}] => (Allow) F:\programs\steam\steamapps\common\Rollercoaster Tycoon 3 Gold\RCT3plus.exe
FirewallRules: [{7D9F751C-0912-4ED9-AA9A-1E809E2F5C7B}] => (Allow) F:\programs\steam\steamapps\common\Rollercoaster Tycoon 3 Gold\RCT3plus.exe
FirewallRules: [{A27E403C-CE68-4651-B6CB-B2DFF2A96DD9}] => (Allow) F:\programs\steam\steamapps\common\Kerbal Space Program\KSP.exe
FirewallRules: [{430667C4-3361-4813-8BD4-D131F979D0BB}] => (Allow) F:\programs\steam\steamapps\common\Kerbal Space Program\KSP.exe
FirewallRules: [{477D0C71-BD50-4B6A-8FCC-8566D27BFB8C}] => (Allow) F:\programs\steam\steamapps\common\Mad Riders\MadRidersGame_x86.exe
FirewallRules: [{C8B0A614-92B0-4BB7-8D22-D6DD035692F6}] => (Allow) F:\programs\steam\steamapps\common\Mad Riders\MadRidersGame_x86.exe
FirewallRules: [{0AE2D886-881E-42C9-B19E-9D9E8FF4CE7E}] => (Allow) F:\programs\steam\steamapps\common\Sid Meier's Civilization V\Launcher.exe
FirewallRules: [{F3AC6D54-D614-4AC9-823C-E31D7EE02AC3}] => (Allow) F:\programs\steam\steamapps\common\Sid Meier's Civilization V\Launcher.exe
FirewallRules: [TCP Query User{10C9D80B-7542-498D-A7E1-B67DE617F226}C:\program files\java\jre1.8.0_73\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_73\bin\javaw.exe
FirewallRules: [UDP Query User{9358E8A9-B07F-4095-BD6B-0E551FD4CEAD}C:\program files\java\jre1.8.0_73\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_73\bin\javaw.exe
FirewallRules: [{D5985B5E-78F9-490A-964A-1128886CD8ED}] => (Allow) F:\programs\steam\steamapps\common\Elite Dangerous\EDLaunch.exe
FirewallRules: [{47EEFF78-FBDC-4E86-AC27-091B3D5A2BED}] => (Allow) F:\programs\steam\steamapps\common\Elite Dangerous\EDLaunch.exe
FirewallRules: [TCP Query User{8C18B95E-CB66-41CF-A599-7F2AA3AE184A}F:\programs\steam\steamapps\common\elite dangerous\products\elite-dangerous-64\elitedangerous64.exe] => (Allow) F:\programs\steam\steamapps\common\elite dangerous\products\elite-dangerous-64\elitedangerous64.exe
FirewallRules: [UDP Query User{4D1C49BD-4F0B-4ABD-95A7-B50F4B13CD47}F:\programs\steam\steamapps\common\elite dangerous\products\elite-dangerous-64\elitedangerous64.exe] => (Allow) F:\programs\steam\steamapps\common\elite dangerous\products\elite-dangerous-64\elitedangerous64.exe
FirewallRules: [{A83EA25B-1414-49E2-97BC-EE15BB273109}] => (Allow) F:\programs\steam\steamapps\common\KillingFloor\System\KillingFloor.exe
FirewallRules: [{AF0BD400-31C8-457E-961D-7CDE94FFDE1A}] => (Allow) F:\programs\steam\steamapps\common\KillingFloor\System\KillingFloor.exe
FirewallRules: [{A25E0DE9-862E-4227-BD12-93BEDCBEFACF}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{056F4BF4-7A91-4898-8789-CF98D28B788D}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{E543F3D9-9A9A-4ED4-B068-D6395AB2E43F}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
FirewallRules: [{34E2119A-AEBC-4B60-9EB4-E871063CC07A}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
FirewallRules: [{B613E4E5-FA2D-415E-8795-F7466A10393B}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
FirewallRules: [{8E4BFFD4-5FFE-45F7-BD02-69C2F0D01C8A}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{F3ED1D50-863E-4CDA-B223-05C151518A69}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{8D402B54-6E7B-4759-AD24-DA5341DCE179}] => (Allow) F:\programs\steam\steamapps\common\Saints Row the Third\game_launcher.exe
FirewallRules: [{FFA99A41-B17D-408E-B854-B55F08E73D90}] => (Allow) F:\programs\steam\steamapps\common\Saints Row the Third\game_launcher.exe
FirewallRules: [{4B5CA611-3D8D-4AED-9617-6970FA9A893D}] => (Allow) F:\programs\steam\steamapps\common\BlockNLoad\Win64\BlockNLoad.exe
FirewallRules: [{DB1E966A-2B3C-4F80-8997-27F25CA5C344}] => (Allow) F:\programs\steam\steamapps\common\BlockNLoad\Win64\BlockNLoad.exe
FirewallRules: [{29B4EF85-555E-4CE2-9D54-D4C707D5B443}] => (Allow) F:\programs\steam\steamapps\common\WormsRevolution\WormsRevolution.exe
FirewallRules: [{BC1E2A07-4D96-45DB-BE11-8F0F506A09A2}] => (Allow) F:\programs\steam\steamapps\common\WormsRevolution\WormsRevolution.exe
FirewallRules: [{EA201721-810E-4646-AE3F-212424721C51}] => (Allow) F:\programs\steam\steamapps\common\rocketleague\Binaries\Win32\RocketLeague.exe
FirewallRules: [{84BFBF42-9262-4261-AF92-7E113DE10B99}] => (Allow) F:\programs\steam\steamapps\common\rocketleague\Binaries\Win32\RocketLeague.exe
FirewallRules: [{7C7EA3DD-EE74-4333-A3C0-B77941D0FF4E}] => (Allow) F:\programs\steam\steamapps\common\Tabletop Simulator\Tabletop Simulator.exe
FirewallRules: [{082A5A87-BCCD-4AE5-B4CB-60DF7E64272A}] => (Allow) F:\programs\steam\steamapps\common\Tabletop Simulator\Tabletop Simulator.exe
FirewallRules: [{7E98EFD6-74E6-416A-8791-7810FAE6FF87}] => (Allow) F:\programs\steam\steamapps\common\SNOW\Bin64\playSNOW.exe
FirewallRules: [{BE73CCDB-EF63-48E2-A22C-326607FC82FE}] => (Allow) F:\programs\steam\steamapps\common\SNOW\Bin64\playSNOW.exe
FirewallRules: [{D627A690-78DB-4EC1-9569-8C0CF217968E}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{10213DA6-4365-4E2B-98D6-80C8992D1DBC}] => (Allow) F:\programs\steam\steamapps\common\Guns of Icarus Online\workshop\Workshop.exe
FirewallRules: [{F45EF6CF-A420-42F6-AA78-69CEDE6BAA5D}] => (Allow) F:\programs\steam\steamapps\common\Guns of Icarus Online\workshop\Workshop.exe
FirewallRules: [{995F1F24-9E31-492A-882A-0A61F7FF2306}] => (Allow) F:\programs\steam\steamapps\common\Day of Defeat Source\hl2.exe
FirewallRules: [{BF854ECF-15E1-43EE-B636-3A8FFEC74816}] => (Allow) F:\programs\steam\steamapps\common\Day of Defeat Source\hl2.exe
FirewallRules: [{95998DAD-4039-4F93-A57C-FFF5039C418D}] => (Allow) F:\programs\steam\steamapps\common\Left 4 Dead 2\left4dead2.exe
FirewallRules: [{E4B31629-82DE-4865-9D55-47F9E3E6CE47}] => (Allow) F:\programs\steam\steamapps\common\Left 4 Dead 2\left4dead2.exe
FirewallRules: [{CF982D8D-D5E3-4EC8-B11D-C0F942F09E26}] => (Allow) C:\Users\willi\AppData\Local\Apps\2.0\GNJTZPBV.KQ1\P211G6GV.WC4\curs..tion_9e9e83ddf3ed3ead_0005.0001_fb8944c2684f5b6c\CurseClient.exe
FirewallRules: [{A85ED7C0-9768-4D28-B196-69BFF62481A0}] => (Allow) C:\Users\willi\AppData\Local\Apps\2.0\GNJTZPBV.KQ1\P211G6GV.WC4\curs..tion_9e9e83ddf3ed3ead_0005.0001_fb8944c2684f5b6c\CurseClient.exe
 
==================== Restore Points =========================
 
08-03-2016 18:46:02 Windows Update
12-03-2016 18:52:20 Windows Update
16-03-2016 15:49:40 Windows Update
19-03-2016 16:14:58 Windows Update
22-03-2016 18:42:08 Windows Update
25-03-2016 21:10:17 Windows Update
 
==================== Faulty Device Manager Devices =============
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (03/26/2016 11:48:33 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program CurseUI.exe version 0.36.7.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.
 
Process ID: 1c9c
 
Start Time: 01d18754b5bd52da
 
Termination Time: 4294967295
 
Application Path: C:\Users\willi\AppData\Roaming\Curse Client\Bin\Electron\CurseUI.exe
 
Report Id: aa212116-f348-11e5-b22a-2c56dc48b2d3
 
Faulting package full name: 
 
Faulting package-relative application ID:
 
Error: (03/26/2016 11:44:30 AM) (Source: IntelDalJhi) (EventID: 11) (User: )
Description: Intel® Dynamic Application Loader Host Interface Service has encountered an internal connection problem.
 
Error: (03/26/2016 11:36:18 AM) (Source: IntelDalJhi) (EventID: 11) (User: )
Description: Intel® Dynamic Application Loader Host Interface Service has encountered an internal connection problem.
 
Error: (03/26/2016 07:38:26 AM) (Source: IntelDalJhi) (EventID: 11) (User: )
Description: Intel® Dynamic Application Loader Host Interface Service has encountered an internal connection problem.
 
Error: (03/25/2016 09:34:51 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: NvStreamService.exe, version: 5.1.2045.819, time stamp: 0x56c40f26
Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception code: 0xc0000005
Fault offset: 0x0000027089003890
Faulting process id: 0xad0
Faulting application start time: 0xNvStreamService.exe0
Faulting application path: NvStreamService.exe1
Faulting module path: NvStreamService.exe2
Report Id: NvStreamService.exe3
Faulting package full name: NvStreamService.exe4
Faulting package-relative application ID: NvStreamService.exe5
 
Error: (03/25/2016 09:34:19 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: WINDOWS-J2K2PN4)
Description: Activation of app Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI failed with error: -2144927149 See the Microsoft-Windows-TWinUI/Operational log for additional information.
 
Error: (03/25/2016 09:34:07 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: WINDOWS-J2K2PN4)
Description: Activation of app Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI failed with error: -2144927149 See the Microsoft-Windows-TWinUI/Operational log for additional information.
 
Error: (03/25/2016 09:33:50 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: WINDOWS-J2K2PN4)
Description: Activation of app Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI failed with error: -2144927149 See the Microsoft-Windows-TWinUI/Operational log for additional information.
 
Error: (03/25/2016 09:33:45 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: WINDOWS-J2K2PN4)
Description: Activation of app Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI failed with error: -2144927149 See the Microsoft-Windows-TWinUI/Operational log for additional information.
 
Error: (03/25/2016 09:33:42 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: WINDOWS-J2K2PN4)
Description: Activation of app Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI failed with error: -2144927149 See the Microsoft-Windows-TWinUI/Operational log for additional information.
 
 
System errors:
=============
Error: (03/26/2016 11:41:40 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The User Data Access_1a1fef service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
 
Error: (03/26/2016 11:41:40 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The User Data Storage_1a1fef service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
 
Error: (03/26/2016 11:41:40 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Contact Data_1a1fef service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
 
Error: (03/26/2016 11:41:40 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Sync Host_1a1fef service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
 
Error: (03/26/2016 11:41:40 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: application-specificLocalActivation{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)UnavailableUnavailable
 
Error: (03/26/2016 08:20:24 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The User Data Access_1ebc47 service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
 
Error: (03/26/2016 08:20:24 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The User Data Storage_1ebc47 service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
 
Error: (03/26/2016 08:20:24 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Contact Data_1ebc47 service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
 
Error: (03/26/2016 08:20:24 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Sync Host_1ebc47 service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
 
Error: (03/26/2016 08:20:24 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: application-specificLocalActivation{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)UnavailableUnavailable
 
 
CodeIntegrity:
===================================
  Date: 2016-03-25 17:05:35.120
  Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2016-03-24 20:13:38.138
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\SpaceSoundPro\SpaceSoundPro.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2016-03-24 20:13:38.132
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\SpaceSoundPro\SpaceSoundPro.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2016-03-24 20:13:22.754
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\SpaceSoundPro\SpaceSoundPro.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2016-03-24 20:13:22.748
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\SpaceSoundPro\SpaceSoundPro.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2016-03-24 20:13:21.208
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\SpaceSoundPro\SpaceSoundPro.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2016-03-24 20:13:21.202
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\SpaceSoundPro\SpaceSoundPro.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2016-03-24 20:13:19.602
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\SpaceSoundPro\SpaceSoundPro.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2016-03-24 20:13:19.597
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\SpaceSoundPro\SpaceSoundPro.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2016-03-24 20:13:18.698
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\SpaceSoundPro\SpaceSoundPro.dll because the set of per-page image hashes could not be found on the system.
 
 
==================== Memory info =========================== 
 
Processor: Intel® Core™ i7-5820K CPU @ 3.30GHz
Percentage of memory in use: 24%
Total physical RAM: 16284.21 MB
Available physical RAM: 12279.49 MB
Total Virtual: 18716.21 MB
Available Virtual: 14654.39 MB
 
==================== Drives ================================
 
Drive c: (OSDisk) (Fixed) (Total:220.73 GB) (Free:138.04 GB) NTFS
Drive d: (SAMSUNG) (Fixed) (Total:931.51 GB) (Free:671.99 GB) NTFS
Drive f: (Storage) (Fixed) (Total:1862.89 GB) (Free:1581.5 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (Size: 223.6 GB) (Disk ID: 2B4024BB)
 
Partition: GPT.
 
========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 1863 GB) (Disk ID: 00000000)
 
Partition: GPT.
 
========================================================
Disk: 2 (Size: 931.5 GB) (Disk ID: 4F86173B)
Partition 1: (Active) - (Size=931.5 GB) - (Type=07 NTFS)
 
==================== End of Addition.txt ============================


#6 pystryker

pystryker

  • Malware Response Team
  • 730 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:10:44 PM

Posted 26 March 2016 - 07:22 AM

Hello :)

I'm currently analyzing you logs, however, I can't find any information on the file below. If you can use a browser on the machine, I'd like you to upload it to VirusTotal for scanning.


Step 1: Upload File
  • Please go to VirusTotal.org by clicking here
  • Please click on Choose File
  • When the window opens, navigate to the location listed in the box below and select file that is listed in that location.

    C:\Program Files (x86)\rec_gb_236\rec_gb_236.exe

  • Once you have selected the file, click the blue Scan It! button.
  • VirusTotal will scan the file and produce a report for you. Please copy the link the address bar when it shows you the report and post it in your next reply.
Things I need to see in your next post:

VirusTotal Link

I close my topics if there is no response after 3 days. Please PM a moderator or myself to reopen your topic.

Please PM me only if I'm helping you with your computer issues and I have not responded in 2 days. Please remember, I'm a volunteer and sometimes life does get in the way. :)

Please stay with me until I declare your machine clean. Absence of symptoms does not ensure your machine is clean.

If you'd like to make a donation via Paypal, please click here.





#7 willyman18

willyman18
  • Topic Starter

  • Members
  • 66 posts
  • OFFLINE
  •  
  • Local time:04:44 AM

Posted 26 March 2016 - 07:27 AM

https://www.virustotal.com/en/file/4adaa6536b7c36c2c3e3062c26e720524916845797d89777cdc9efc2340e1254/analysis/1458995105/



#8 pystryker

pystryker

  • Malware Response Team
  • 730 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:10:44 PM

Posted 26 March 2016 - 08:00 AM

Hello :)

Thank you for the link, that file is infected and will be removed . We've got a lot of work to do. The infections have patched a Windows system file and we'll fix that as soon as we get rid of the infections.

When you post the requested logs, please let me know how the machine is running at this point.

Let's get started. :thumbup2:


Step 1: Program Uninstalls

Please uninstall the following programs from your machine as they are adware/malware related. If one of the programs fails to uninstall, please move on to the next one in the list.
  • Body Text Feathering
  • Setup
  • SunnyDayApps Maintenance 013.236
Step 2: Fix with FRST

Important: Before performing this step, please move FRST64.exe from F:\willi to your Desktop or the fix will not work. All tools must be run from the Desktop for maximum effect.
  • Open notepad (Start =>All Programs => Accessories => Notepad). Please copy the entire contents of the code box below. (To do this highlight the contents of the box, right click on it and select copy.
  • Right-click in the open notepad and select Paste).
  • Save it on the desktop as fixlist.txt

    NOTE: It's important that both files, FRST/FRST64 and fixlist.txt are in the same location or the fix will not work.

Start
CreateRestorePoint:
CloseProcesses:
() C:\Users\willi\AppData\Local\SunnyDay13\usun.exe
C:\Users\willi\AppData\Local\SunnyDay13
() C:\Users\willi\AppData\Roaming\cpuminer\cpm.exe
C:\Users\willi\AppData\Roaming\cpuminer
() C:\Program Files (x86)\SunnyDay13\SunnyDay.exe
C:\Program Files (x86)\SunnyDay13
HKLM\...\Run: [cpuminer] => C:\Users\willi\AppData\Roaming\cpuminer\cpm.exe [1417216 2016-02-29] ()
HKLM-x32\...\Run: [win_en_77] => [X]
HKLM-x32\...\Run: [sun13] => C:\Program Files (x86)\SunnyDay13\SunnyDay.exe [4055728 2016-03-24] ()
HKLM-x32\...\RunOnce: [usun.exe] => C:\Users\willi\AppData\Local\SunnyDay13\usun.exe [3247280 2016-03-24] ()
() C:\Program Files (x86)\rec_gb_236\rec_gb_236.exe
HKLM-x32\...\Run: [rec_gb_236] => C:\Program Files (x86)\rec_gb_236\rec_gb_236.exe [4054704 2016-03-23] ()
Winsock: Catalog9-x64 01 C:\windows\system32\zdengine64.dll [341670 2016-03-25] (zdengine)
Winsock: Catalog9-x64 02 C:\windows\system32\zdengine64.dll [341670 2016-03-25] (zdengine)
Winsock: Catalog9-x64 03 C:\windows\system32\zdengine64.dll [341670 2016-03-25] (zdengine)
Winsock: Catalog9-x64 04 C:\windows\system32\zdengine64.dll [341670 2016-03-25] (zdengine)
Winsock: Catalog9-x64 16 C:\windows\system32\zdengine64.dll [341670 2016-03-25] (zdengine)
C:\windows\system32\zdengine64.dll
BHO-x32: Java Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> F:\Program Files (x86)\bin\jp2ssv.dll => No File
FF Plugin-x32: @java.com/DTPlugin,version=11.66.2 -> F:\Program Files (x86)\bin\dtplugin\npDeployJava1.dll [No File]
FF Plugin-x32: @java.com/JavaPlugin,version=11.66.2 -> F:\Program Files (x86)\bin\plugin2\npjp2.dll [No File]
CHR HomePage: Profile 1 -> hxxp://www-searching.com/?s=G3Ozftpbl0cshmoBD,0fcbd9b9-0d39-4234-9c15-2195883a9a88,&prd=smw
CHR StartupUrls: Profile 1 -> "hxxp://www-searching.com/?s=G3Ozftpbl0cshmoBD,0fcbd9b9-0d39-4234-9c15-2195883a9a88,&prd=smw"
CHR DefaultSearchURL: Profile 1 -> hxxp://www-searching.com/search.aspx?s=G3Ozftpbl0cshmoBD,0fcbd9b9-0d39-4234-9c15-2195883a9a88,&prd=smw&q={searchTerms}
CHR DefaultSearchKeyword: Profile 1 -> www-searching.com
CHR DefaultSuggestURL: Profile 1 -> hxxp://api.searchpredict.com/api/?rqtype=ffplugin&siteID=8661&dbCode=1&command={searchTerms}
R2 zdwfp; C:\windows\system32\Drivers\zdwfp64.sys [46352 2016-03-04] (zdengine)
S3 e1edc438-f640-4184-a443-d2a7c37a01dc; \??\C:\3XS-TESTS\OA30\690b33e1-0462-4e84-9bea-c7552b45432a.sys [X]
S4 NVHDA; \SystemRoot\system32\drivers\nvhda64v.sys [X]
S1 owfrxpjm; \??\C:\windows\system32\drivers\owfrxpjm.sys [X]
C:\windows\system32\Drivers\zdwfp64.sys
2016-03-25 21:38 - 2016-03-25 22:21 - 00011056 _____ C:\windows\SysWOW64\zdengineOff.ini
2016-03-25 21:38 - 2016-03-25 22:21 - 00011056 _____ C:\windows\system32\zdengineOff.ini
2016-03-25 21:32 - 2016-03-25 21:32 - 00000000 ____D C:\Users\willi\AppData\Local\rec_gb_236
2016-03-25 21:32 - 2016-03-25 21:32 - 00000000 ____D C:\Program Files (x86)\SunnyDayApps
2016-03-25 21:32 - 2016-03-25 21:32 - 00000000 ____D C:\Program Files (x86)\rec_gb_236
2016-03-25 21:29 - 2016-03-26 11:45 - 00000000 ____D C:\Users\willi\AppData\Local\SunnyDay13
2016-03-25 21:29 - 2016-03-25 21:29 - 00000000 ____D C:\Program Files (x86)\SunnyDay13
2016-03-25 20:57 - 2016-03-25 20:57 - 00000000 ____D C:\Users\willi\AppData\Roaming\cpuminer
2016-03-24 20:12 - 2016-03-25 21:38 - 00000002 _____ C:\END
Task: {99D91490-F9C7-4488-BA3E-AE684A56730F} - System32\Tasks\NIFQIDEGATILRONX => C:\ProgramData\Service1104\Service1104.exe <==== ATTENTION
2016-03-24 20:12 - 2016-03-24 20:12 - 00003450 _____ C:\windows\System32\Tasks\NIFQIDEGATILRONX
2016-03-24 20:12 - 2016-03-24 20:12 - 00000374 ____H C:\windows\Tasks\NIFQIDEGATILRONX.job
2016-03-24 20:11 - 2016-03-26 08:11 - 00000000 ____D C:\Program Files (x86)\QuickSearch
Task: {CC646D0F-A353-4B18-B6B0-2798D9D5A618} - \{080C0D47-0E04-0E0A-0C11-78097E05110C} -> No File <==== ATTENTION
Task: C:\windows\Tasks\NIFQIDEGATILRONX.job => C:\ProgramData\Service1104\Service1104.exe <==== ATTENTION
C:\ProgramData\Service1104
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\zdengine => ""="service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\zdwfp => ""="Driver"
CMD: netsh winsock reset catalog
CMD: bitsadmin /reset /allusers
CMD: netsh advfirewall reset
CMD: netsh advfirewall set allprofiles state on
CMD: ipconfig /flushdns
Emptytemp:
Hosts:
End


NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system.


Run FRST and press the Fix button just once and wait. The tool will make a log on the desktop (Fixlog.txt) please post it in your next reply.


Step 3: Junkware Removal Tool

junkware-removal-tool_zpspjolgpuh.png Please download Junkware Removal Tool to your desktop.
  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.
Step 4: AdwCleaner

Download ADWcleaner by clicking here. Please save it to your Desktop


adwcleanerscreen_zpsm6wq1ei9.jpg
  • Double click (Vista and 7 Users)right click the adwcleaner.exe file and click Run as Adminstrator and accept the UAC prompt to run AdwCleaner
  • Once AdwCleaner's control panel is open and it says "Waiting for Action", click on Options at the top of the control panel.
  • Please Check the following options:
    • Reset Proxy Settings
    • Reset Winsock Settings
    • Reset TCP/IP Settings
    • Reset Firewall Settings
    • Reset IPSec Settings
    • Reset BITS Queue
    • Reset Internet Explorer Policies
    • Reset Chrome Policies
  • Close any open windows or browsers.
  • Pause your Anti-Virus program if it is running.
  • Once it starts, click on the Scan button.
  • Let the scan complete itself. This may take a few minutes.
  • Once the scan has finished, it will say "Pending, uncheck elements you don't want to remove.", don't worry about unchecking anything and then click the Cleaning button. When finished, it will ask to reboot. Please reboot.
  • When the machine has rebooted, a log will be produced. Please copy/paste that in your next reply. Here's how:
    • Click the Logfile button and the log will open. Copy and Paste the contents of the log file into your next reply.
    This report is also saved at C:\Adwcleaner
Step 5: Frest Scan with FRST
  • Start Farbar's Recovery Scan Tool and press the Scan button.
  • FRST will scan your system and produce two logs: FRST.txt and Addition.txt. Please post them in your next reply.
Things I need to see in your next post:

Please post each of these logs as a separate reply in this thread.

Fixlog.txt Log

Junkware Removal Tool Log

AdwCleaner Log

Fresh FRST.txt Log

Fresh Addition.txt Log

How is the machine running?

I close my topics if there is no response after 3 days. Please PM a moderator or myself to reopen your topic.

Please PM me only if I'm helping you with your computer issues and I have not responded in 2 days. Please remember, I'm a volunteer and sometimes life does get in the way. :)

Please stay with me until I declare your machine clean. Absence of symptoms does not ensure your machine is clean.

If you'd like to make a donation via Paypal, please click here.





#9 willyman18

willyman18
  • Topic Starter

  • Members
  • 66 posts
  • OFFLINE
  •  
  • Local time:04:44 AM

Posted 26 March 2016 - 08:10 AM

Fix result of Farbar Recovery Scan Tool (x64) Version:05-03-2016 01
Ran by willi (2016-03-26 13:08:43) Run:1
Running from C:\Users\willi\Desktop
Loaded Profiles: willi (Available Profiles: willi)
Boot Mode: Normal
==============================================
 
fixlist content:
*****************
Start
CreateRestorePoint:
CloseProcesses:
() C:\Users\willi\AppData\Local\SunnyDay13\usun.exe
C:\Users\willi\AppData\Local\SunnyDay13
() C:\Users\willi\AppData\Roaming\cpuminer\cpm.exe
C:\Users\willi\AppData\Roaming\cpuminer
() C:\Program Files (x86)\SunnyDay13\SunnyDay.exe
C:\Program Files (x86)\SunnyDay13
HKLM\...\Run: [cpuminer] => C:\Users\willi\AppData\Roaming\cpuminer\cpm.exe [1417216 2016-02-29] ()
HKLM-x32\...\Run: [win_en_77] => [X]
HKLM-x32\...\Run: [sun13] => C:\Program Files (x86)\SunnyDay13\SunnyDay.exe [4055728 2016-03-24] ()
HKLM-x32\...\RunOnce: [usun.exe] => C:\Users\willi\AppData\Local\SunnyDay13\usun.exe [3247280 2016-03-24] ()
() C:\Program Files (x86)\rec_gb_236\rec_gb_236.exe
HKLM-x32\...\Run: [rec_gb_236] => C:\Program Files (x86)\rec_gb_236\rec_gb_236.exe [4054704 2016-03-23] ()
Winsock: Catalog9-x64 01 C:\windows\system32\zdengine64.dll [341670 2016-03-25] (zdengine)
Winsock: Catalog9-x64 02 C:\windows\system32\zdengine64.dll [341670 2016-03-25] (zdengine)
Winsock: Catalog9-x64 03 C:\windows\system32\zdengine64.dll [341670 2016-03-25] (zdengine)
Winsock: Catalog9-x64 04 C:\windows\system32\zdengine64.dll [341670 2016-03-25] (zdengine)
Winsock: Catalog9-x64 16 C:\windows\system32\zdengine64.dll [341670 2016-03-25] (zdengine)
C:\windows\system32\zdengine64.dll
BHO-x32: Java Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> F:\Program Files (x86)\bin\jp2ssv.dll => No File
FF Plugin-x32: @java.com/DTPlugin,version=11.66.2 -> F:\Program Files (x86)\bin\dtplugin\npDeployJava1.dll [No File]
FF Plugin-x32: @java.com/JavaPlugin,version=11.66.2 -> F:\Program Files (x86)\bin\plugin2\npjp2.dll [No File]
CHR HomePage: Profile 1 -> hxxp://www-searching.com/?s=G3Ozftpbl0cshmoBD,0fcbd9b9-0d39-4234-9c15-2195883a9a88,&prd=smw
CHR StartupUrls: Profile 1 -> "hxxp://www-searching.com/?s=G3Ozftpbl0cshmoBD,0fcbd9b9-0d39-4234-9c15-2195883a9a88,&prd=smw"
CHR DefaultSearchURL: Profile 1 -> hxxp://www-searching.com/search.aspx?s=G3Ozftpbl0cshmoBD,0fcbd9b9-0d39-4234-9c15-2195883a9a88,&prd=smw&q={searchTerms}
CHR DefaultSearchKeyword: Profile 1 -> www-searching.com
CHR DefaultSuggestURL: Profile 1 -> hxxp://api.searchpredict.com/api/?rqtype=ffplugin&siteID=8661&dbCode=1&command={searchTerms}
R2 zdwfp; C:\windows\system32\Drivers\zdwfp64.sys [46352 2016-03-04] (zdengine)
S3 e1edc438-f640-4184-a443-d2a7c37a01dc; \??\C:\3XS-TESTS\OA30\690b33e1-0462-4e84-9bea-c7552b45432a.sys [X]
S4 NVHDA; \SystemRoot\system32\drivers\nvhda64v.sys [X]
S1 owfrxpjm; \??\C:\windows\system32\drivers\owfrxpjm.sys [X]
C:\windows\system32\Drivers\zdwfp64.sys
2016-03-25 21:38 - 2016-03-25 22:21 - 00011056 _____ C:\windows\SysWOW64\zdengineOff.ini
2016-03-25 21:38 - 2016-03-25 22:21 - 00011056 _____ C:\windows\system32\zdengineOff.ini
2016-03-25 21:32 - 2016-03-25 21:32 - 00000000 ____D C:\Users\willi\AppData\Local\rec_gb_236
2016-03-25 21:32 - 2016-03-25 21:32 - 00000000 ____D C:\Program Files (x86)\SunnyDayApps
2016-03-25 21:32 - 2016-03-25 21:32 - 00000000 ____D C:\Program Files (x86)\rec_gb_236
2016-03-25 21:29 - 2016-03-26 11:45 - 00000000 ____D C:\Users\willi\AppData\Local\SunnyDay13
2016-03-25 21:29 - 2016-03-25 21:29 - 00000000 ____D C:\Program Files (x86)\SunnyDay13
2016-03-25 20:57 - 2016-03-25 20:57 - 00000000 ____D C:\Users\willi\AppData\Roaming\cpuminer
2016-03-24 20:12 - 2016-03-25 21:38 - 00000002 _____ C:\END
Task: {99D91490-F9C7-4488-BA3E-AE684A56730F} - System32\Tasks\NIFQIDEGATILRONX => C:\ProgramData\Service1104\Service1104.exe <==== ATTENTION
2016-03-24 20:12 - 2016-03-24 20:12 - 00003450 _____ C:\windows\System32\Tasks\NIFQIDEGATILRONX
2016-03-24 20:12 - 2016-03-24 20:12 - 00000374 ____H C:\windows\Tasks\NIFQIDEGATILRONX.job
2016-03-24 20:11 - 2016-03-26 08:11 - 00000000 ____D C:\Program Files (x86)\QuickSearch
Task: {CC646D0F-A353-4B18-B6B0-2798D9D5A618} - \{080C0D47-0E04-0E0A-0C11-78097E05110C} -> No File <==== ATTENTION
Task: C:\windows\Tasks\NIFQIDEGATILRONX.job => C:\ProgramData\Service1104\Service1104.exe <==== ATTENTION
C:\ProgramData\Service1104
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\zdengine => ""="service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\zdwfp => ""="Driver"
CMD: netsh winsock reset catalog
CMD: bitsadmin /reset /allusers
CMD: netsh advfirewall reset
CMD: netsh advfirewall set allprofiles state on
CMD: ipconfig /flushdns
Emptytemp:
Hosts:
End
*****************
 
Restore point was successfully created.
Processes closed successfully.
C:\Users\willi\AppData\Local\SunnyDay13\usun.exe => No running process found
"C:\Users\willi\AppData\Local\SunnyDay13" => not found.
C:\Users\willi\AppData\Roaming\cpuminer\cpm.exe => No running process found
"C:\Users\willi\AppData\Roaming\cpuminer" => not found.
C:\Program Files (x86)\SunnyDay13\SunnyDay.exe => No running process found
"C:\Program Files (x86)\SunnyDay13" => not found.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\cpuminer => value not found.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\win_en_77 => value removed successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\sun13 => value removed successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\RunOnce\\usun.exe => value not found.
C:\Program Files (x86)\rec_gb_236\rec_gb_236.exe => No running process found
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\rec_gb_236 => value removed successfully
"HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000001" => key removed successfully
"HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000002" => key removed successfully
"HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000003" => key removed successfully
"HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000004" => key removed successfully
"HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries64\000000000016" => key removed successfully
C:\windows\system32\zdengine64.dll => moved successfully
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}" => key removed successfully
"HKCR\Wow6432Node\CLSID\{DBC80044-A445-435b-BC74-9C25C1C588A9}" => key removed successfully
"HKLM\Software\Wow6432Node\MozillaPlugins\@java.com/DTPlugin,version=11.66.2" => key removed successfully
"HKLM\Software\Wow6432Node\MozillaPlugins\@java.com/JavaPlugin,version=11.66.2" => key removed successfully
Chrome HomePage => removed successfully
Chrome StartupUrls => removed successfully
Chrome DefaultSearchURL => removed successfully
Chrome DefaultSearchKeyword => removed successfully
Chrome DefaultSuggestURL => removed successfully
zdwfp => Unable to stop service.
zdwfp => service removed successfully
e1edc438-f640-4184-a443-d2a7c37a01dc => service removed successfully
NVHDA => service removed successfully
owfrxpjm => service removed successfully
C:\windows\system32\Drivers\zdwfp64.sys => moved successfully
C:\windows\SysWOW64\zdengineOff.ini => moved successfully
C:\windows\system32\zdengineOff.ini => moved successfully
"C:\Users\willi\AppData\Local\rec_gb_236" => not found.
"C:\Program Files (x86)\SunnyDayApps" => not found.
"C:\Program Files (x86)\rec_gb_236" => not found.
"C:\Users\willi\AppData\Local\SunnyDay13" => not found.
"C:\Program Files (x86)\SunnyDay13" => not found.
"C:\Users\willi\AppData\Roaming\cpuminer" => not found.
C:\END => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{99D91490-F9C7-4488-BA3E-AE684A56730F}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{99D91490-F9C7-4488-BA3E-AE684A56730F}" => key removed successfully
C:\windows\System32\Tasks\NIFQIDEGATILRONX => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\NIFQIDEGATILRONX" => key removed successfully
"C:\windows\System32\Tasks\NIFQIDEGATILRONX" => not found.
C:\windows\Tasks\NIFQIDEGATILRONX.job => moved successfully
C:\Program Files (x86)\QuickSearch => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{CC646D0F-A353-4B18-B6B0-2798D9D5A618}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CC646D0F-A353-4B18-B6B0-2798D9D5A618}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{080C0D47-0E04-0E0A-0C11-78097E05110C}" => key removed successfully
C:\windows\Tasks\NIFQIDEGATILRONX.job => not found.
"C:\ProgramData\Service1104" => not found.
"HKLM\System\CurrentControlSet\Control\SafeBoot\Network\zdengine" => key removed successfully
"HKLM\System\CurrentControlSet\Control\SafeBoot\Network\zdwfp" => key removed successfully
 
=========  netsh winsock reset catalog =========
 
Initialization Function InitHelperDll in NSHHTTP.DLL failed to start with error code 10107
 
Sucessfully reset the Winsock Catalog.
You must restart the computer in order to complete the reset.
 
 
========= End of CMD: =========
 
 
=========  bitsadmin /reset /allusers =========
 
 
BITSADMIN version 3.0 [ 7.8.10586 ]
BITS administration utility.
© Copyright 2000-2006 Microsoft Corp.
 
BITSAdmin is deprecated and is not guaranteed to be available in future versions of Windows.
Administrative tools for the BITS service are now provided by BITS PowerShell cmdlets.
 
{E14DB9AC-85CE-4C19-BCA0-30A59E29A405} canceled.
{9C62459B-D2C3-4630-9D6F-7C0532F3EDD5} canceled.
2 out of 2 jobs canceled.
 
========= End of CMD: =========
 
 
=========  netsh advfirewall reset =========
 
Ok.
 
 
========= End of CMD: =========
 
 
=========  netsh advfirewall set allprofiles state on =========
 
Ok.
 
 
========= End of CMD: =========
 
 
=========  ipconfig /flushdns =========
 
 
Windows IP Configuration
 
Successfully flushed the DNS Resolver Cache.
 
========= End of CMD: =========
 
C:\Windows\System32\Drivers\etc\hosts => moved successfully
Hosts restored successfully.
EmptyTemp: => 2.1 GB temporary data Removed.
 
 
The system needed a reboot.
 
==== End of Fixlog 13:09:08 ====


#10 willyman18

willyman18
  • Topic Starter

  • Members
  • 66 posts
  • OFFLINE
  •  
  • Local time:04:44 AM

Posted 26 March 2016 - 08:21 AM

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.0.4 (03.14.2016)
Operating System: Windows 10 Home x64 
Ran by willi (Administrator) on 26/03/2016 at 13:15:34.18
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
 
 
 
File System: 7 
 
Successfully deleted: C:\ProgramData\19a87fa1ec024bbcbb41931263354405 (Folder) 
Successfully deleted: C:\ProgramData\28341ff220e0446c9fff27c4493d622e (Folder) 
Successfully deleted: C:\Users\willi\Appdata\LocalLow\company (Folder) 
Successfully deleted: C:\Users\willi\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\search.lnk (Shortcut) 
Successfully deleted: C:\Users\willi\AppData\Roaming\store (Folder) 
Successfully deleted: C:\Users\willi\AppData\Roaming\wtools (Folder) 
Successfully deleted: C:\windows\prefetch\AVAST_FREE_ANTIVIRUS_SETUP_ON-A7C84363.pf (File) 
 
 
 
Registry: 0 
 
 
 
 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 26/03/2016 at 13:17:36.74
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


#11 willyman18

willyman18
  • Topic Starter

  • Members
  • 66 posts
  • OFFLINE
  •  
  • Local time:04:44 AM

Posted 26 March 2016 - 08:30 AM

# AdwCleaner v5.105 - Logfile created 26/03/2016 at 13:26:30
# Updated 21/03/2016 by Xplode
# Database : 2016-03-20.7 [Local]
# Operating system : Windows 10 Home  (x64)
# Username : willi - WINDOWS-J2K2PN4
# Running from : C:\Users\willi\Desktop\AdwCleaner.exe
# Option : Clean
 
***** [ Services ] *****
 
 
***** [ Folders ] *****
 
[-] Folder Deleted : C:\Program Files (x86)\ExploreTech
[-] Folder Deleted : C:\Users\willi\AppData\Local\A56F9120-1458939472-11D3-A25A-2C56DC48B2D3
[-] Folder Deleted : C:\Users\willi\AppData\Local\A56F9120-1458941358-11D3-A25A-2C56DC48B2D3
[-] Folder Deleted : C:\windows\SysWOW64\config\systemprofile\AppData\Local\zdengine
 
***** [ Files ] *****
 
 
***** [ DLLs ] *****
 
[-] File Disinfected : C:\windows\Sysnative\dnsapi.dll
 
***** [ Shortcuts ] *****
 
 
***** [ Scheduled tasks ] *****
 
 
***** [ Registry ] *****
 
[-] Key Deleted : HKLM\SOFTWARE\CLASSES\APPID\zdengine.EXE
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\3679CA35668772304D30A5FB873B0FA77BB70D54
[-] Key Deleted : HKLM\SOFTWARE\microsoft\windows nt\currentversion\Image File Execution Options\MsMpEng.exe
[-] Key Deleted : HKLM\SOFTWARE\Classes\zdengineLib.DataContainer
[-] Key Deleted : HKLM\SOFTWARE\Classes\zdengineLib.DataContainer.1
[-] Key Deleted : HKLM\SOFTWARE\Classes\zdengineLib.DataController
[-] Key Deleted : HKLM\SOFTWARE\Classes\zdengineLib.DataController.1
[-] Key Deleted : HKLM\SOFTWARE\Classes\zdengineLib.DataTable
[-] Key Deleted : HKLM\SOFTWARE\Classes\zdengineLib.DataTable.1
[-] Key Deleted : HKLM\SOFTWARE\Classes\zdengineLib.DataTableFields
[-] Key Deleted : HKLM\SOFTWARE\Classes\zdengineLib.DataTableFields.1
[-] Key Deleted : HKLM\SOFTWARE\Classes\zdengineLib.DataTableHolder
[-] Key Deleted : HKLM\SOFTWARE\Classes\zdengineLib.DataTableHolder.1
[-] Key Deleted : HKLM\SOFTWARE\Classes\zdengineLib.LSPLogic
[-] Key Deleted : HKLM\SOFTWARE\Classes\zdengineLib.LSPLogic.1
[-] Key Deleted : HKLM\SOFTWARE\Classes\zdengineLib.ReadOnlyManager
[-] Key Deleted : HKLM\SOFTWARE\Classes\zdengineLib.ReadOnlyManager.1
[-] Key Deleted : HKLM\SOFTWARE\Classes\zdengineLib.WFPController
[-] Key Deleted : HKLM\SOFTWARE\Classes\zdengineLib.WFPController.1
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{8FF10FED-2F0A-4F7F-BE87-B04F1DCD4319}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{0FF03983-EAA6-4628-8E7C-387B2D4F8EF2}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3A71C84A-1CC4-4201-B037-C81CE118D66F}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{432599E9-40CF-41E3-951A-E1E81B7B1D29}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{7D215707-3E74-4E0E-A078-2C95E1CDE233}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9295785F-8C01-4ED3-9322-8BE5C17CA141}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B98E44C8-7BB7-4A4A-B8D2-60874CA109B2}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C656BCEB-6B19-4992-9975-D53CEA283356}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D5AC4B9C-8EE4-48AD-A77E-1560AD886A0B}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D6914FD3-FD8E-45AD-8993-901E7B2759FD}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E0106905-0EDD-4F56-BDB5-890A1F6E8F47}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E26E880F-176C-4007-B2A7-B8F27621EC51}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E776B534-9402-4049-87C3-089EC0F54BAF}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FCFBBE24-2ADA-4D6E-A381-DEC6E3EAEE21}
[-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{63492C58-6CD7-4FF7-8495-06A6869643EE}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{0FF03983-EAA6-4628-8E7C-387B2D4F8EF2}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{3A71C84A-1CC4-4201-B037-C81CE118D66F}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{432599E9-40CF-41E3-951A-E1E81B7B1D29}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{7D215707-3E74-4E0E-A078-2C95E1CDE233}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{9295785F-8C01-4ED3-9322-8BE5C17CA141}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{B98E44C8-7BB7-4A4A-B8D2-60874CA109B2}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{C656BCEB-6B19-4992-9975-D53CEA283356}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{D5AC4B9C-8EE4-48AD-A77E-1560AD886A0B}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{D6914FD3-FD8E-45AD-8993-901E7B2759FD}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{E0106905-0EDD-4F56-BDB5-890A1F6E8F47}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{E26E880F-176C-4007-B2A7-B8F27621EC51}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{E776B534-9402-4049-87C3-089EC0F54BAF}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{FCFBBE24-2ADA-4D6E-A381-DEC6E3EAEE21}
[-] Key Deleted : HKCU\Software\DAILYPCCLEAN
[-] Key Deleted : HKCU\Software\Microsoft\Tinstalls
[-] Key Deleted : HKCU\Software\Store
[-] Key Deleted : HKCU\Software\Tutorials
[-] Key Deleted : HKCU\Software\TutoTag
[-] Key Deleted : HKCU\Software\WTools
[-] Key Deleted : HKCU\Software\MICROSOFT\OTUT
[-] Key Deleted : HKLM\SOFTWARE\QuickSearch
[-] Key Deleted : HKLM\SOFTWARE\Tutorials
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7ADF667E-E14D-4D2C-827C-B0108F0D93BC}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PopupProduct
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\VOPackage
[-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\DOMStorage\bestpriceninja.com
[-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\DOMStorage\bubbledock.co.uk
[-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\DOMStorage\inst.bubbledock.co.uk
[-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\DOMStorage\nps.pastaleads.com
[-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\DOMStorage\pastaleads.com
[-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\DOMStorage\pstatic.bestpriceninja.com
[-] Value Deleted : HKU\S-1-5-21-3667704814-1699542734-850788743-1002\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run [Selection Tools]
[-] Value Deleted : HKU\S-1-5-21-3667704814-1699542734-850788743-1002\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run [WindApp]
[-] Value Deleted : HKU\S-1-5-21-3667704814-1699542734-850788743-1002\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run [Buzzing Dhol]
 
***** [ Web browsers ] *****
 
 
*************************
 
:: Proxy settings cleared
:: Winsock settings cleared
:: TCP/IP settings cleared
:: Firewall settings cleared
:: IPSec settings cleared
:: BITS queue cleared
:: IE policies deleted
:: Chrome policies deleted
 
*************************
 
C:\AdwCleaner\AdwCleaner[C1].txt - [6861 bytes] - [26/03/2016 13:26:30]
C:\AdwCleaner\AdwCleaner[S1].txt - [6960 bytes] - [26/03/2016 13:24:35]
 
########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [7007 bytes] ##########


#12 willyman18

willyman18
  • Topic Starter

  • Members
  • 66 posts
  • OFFLINE
  •  
  • Local time:04:44 AM

Posted 26 March 2016 - 08:34 AM

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:05-03-2016 01
Ran by willi (administrator) on WINDOWS-J2K2PN4 (26-03-2016 13:31:31)
Running from C:\Users\willi\Desktop
Loaded Profiles: willi (Available Profiles: willi)
Platform: Windows 10 Home Version 1511 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(NVIDIA) C:\Program Files (x86)\NVIDIA Corporation\nTune\nTuneService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
() C:\Program Files (x86)\ASUS\AXSP\1.02.00\atkexComSvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
(DTS, Inc) C:\Program Files\Realtek\Audio\HDA\DTSU2PAuSrv64.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\asww10mon.exe
() C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(NVIDIA Corporation) C:\Users\willi\AppData\Local\NVIDIA\NvBackend\ApplicationOntology\NvOAWrapperCache.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Nota Inc.) C:\Program Files (x86)\Gyazo\GyStation.exe
(Curse, Inc) C:\Users\willi\AppData\Roaming\Curse Client\Bin\Curse.exe
() C:\Program Files\Scan 3XS\menu.exe
(Curse) C:\Users\willi\AppData\Local\Apps\2.0\GNJTZPBV.KQ1\P211G6GV.WC4\curs..tion_9e9e83ddf3ed3ead_0005.0001_fb8944c2684f5b6c\CurseClient.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Curse, Inc.) C:\Users\willi\AppData\Roaming\Curse Client\Bin\Electron\CurseUI.exe
(Curse, Inc.) C:\Users\willi\AppData\Roaming\Curse Client\Bin\Electron\CurseUI.exe
(Curse, Inc.) C:\Users\willi\AppData\Roaming\Curse Client\Bin\Electron\CurseUI.exe
(Curse, Inc.) C:\Users\willi\AppData\Roaming\Curse Client\Bin\Electron\CurseUI.exe
(Avast Software) C:\Program Files\AVAST Software\SZBrowser\1.48.2066.44\SZBrowser.exe
(Avast Software) C:\Program Files\AVAST Software\SZBrowser\1.48.2066.44\SZBrowser_crashreporter.exe
(Avast Software) C:\Program Files\AVAST Software\SZBrowser\1.48.2066.44\SZBrowser.exe
(Avast Software) C:\Program Files\AVAST Software\SZBrowser\1.48.2066.44\SZBrowser.exe
(Avast Software) C:\Program Files\AVAST Software\SZBrowser\1.48.2066.44\SZBrowser.exe
(Avast Software) C:\Program Files\AVAST Software\SZBrowser\1.48.2066.44\SZBrowser.exe
(Avast Software) C:\Program Files\AVAST Software\SZBrowser\1.48.2066.44\SZBrowser.exe
(Avast Software) C:\Program Files\AVAST Software\SZBrowser\1.48.2066.44\SZBrowser.exe
(Avast Software) C:\Program Files\AVAST Software\SZBrowser\1.48.2066.44\SZBrowser.exe
(Avast Software) C:\Program Files\AVAST Software\SZBrowser\1.48.2066.44\SZBrowser.exe
(Avast Software) C:\Program Files\AVAST Software\SZBrowser\1.48.2066.44\SZBrowser.exe
(Avast Software) C:\Program Files\AVAST Software\SZBrowser\1.48.2066.44\SZBrowser.exe
(Avast Software) C:\Program Files\AVAST Software\SZBrowser\1.48.2066.44\SZBrowser.exe
(Avast Software) C:\Program Files\AVAST Software\SZBrowser\1.48.2066.44\SZBrowser.exe
(Avast Software) C:\Program Files\AVAST Software\SZBrowser\1.48.2066.44\SZBrowser.exe
(Avast Software) C:\Program Files\AVAST Software\SZBrowser\1.48.2066.44\SZBrowser.exe
(Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
(Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
() C:\Program Files\AVAST Software\Avast\avastnm.exe
() C:\Program Files\AVAST Software\Avast\avastnm.exe
(Avast Software) C:\Program Files\AVAST Software\SZBrowser\1.48.2066.44\SZBrowser.exe
(Avast Software) C:\Program Files\AVAST Software\SZBrowser\1.48.2066.44\SZBrowser.exe
(Avast Software) C:\Program Files\AVAST Software\SZBrowser\1.48.2066.44\SZBrowser.exe
(Avast Software) C:\Program Files\AVAST Software\SZBrowser\1.48.2066.44\SZBrowser.exe
(Avast Software) C:\Program Files\AVAST Software\SZBrowser\1.48.2066.44\SZBrowser.exe
(Avast Software) C:\Program Files\AVAST Software\SZBrowser\1.48.2066.44\SZBrowser.exe
(Avast Software) C:\Program Files\AVAST Software\SZBrowser\1.48.2066.44\SZBrowser.exe
(Avast Software) C:\Program Files\AVAST Software\SZBrowser\1.48.2066.44\SZBrowser.exe
(Avast Software) C:\Program Files\AVAST Software\SZBrowser\1.48.2066.44\SZBrowser.exe
(Avast Software) C:\Program Files\AVAST Software\SZBrowser\1.48.2066.44\SZBrowser.exe
(Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
() C:\Program Files\AVAST Software\Avast\avastnm.exe
(Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
(Intel Corporation) C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
(Intel Corporation) C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
 
 
==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [ScanMenu] => C:\Program Files\Scan 3XS\menu.exe [1197568 2015-12-10] ()
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe [322472 2015-06-23] (Intel Corporation)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8484056 2015-06-12] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_DTS] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1393880 2015-04-28] (Realtek Semiconductor)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2789248 2016-02-17] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => "C:\windows\system32\rundll32.exe" C:\windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM-x32\...\Run: [ScanMenu] => C:\Program Files\Scan 3XS\menu.exe [1197568 2015-12-10] ()
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [7139256 2016-03-25] (AVAST Software)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [596016 2016-01-29] (Oracle Corporation)
HKU\S-1-5-21-3667704814-1699542734-850788743-1002\...\Run: [Steam] => F:\programs\steam\steam.exe [3074128 2016-03-10] (Valve Corporation)
HKU\S-1-5-21-3667704814-1699542734-850788743-1002\...\Run: [Gyazo] => C:\Program Files (x86)\Gyazo\GyStation.exe [3586848 2016-02-17] (Nota Inc.)
HKU\S-1-5-21-3667704814-1699542734-850788743-1002\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [50670720 2016-03-01] (Skype Technologies S.A.)
HKU\S-1-5-21-3667704814-1699542734-850788743-1002\...\Run: [NVIDIA nTune] => C:\Program Files (x86)\NVIDIA Corporation\nTune\nTuneCmd.exe [98304 2007-09-04] (NVIDIA)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2016-03-25] (AVAST Software)
Startup: C:\Users\willi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Curse.lnk [2016-03-25]
ShortcutTarget: Curse.lnk -> C:\Users\willi\AppData\Roaming\Curse Client\Bin\Curse.exe (Curse, Inc)
Startup: C:\Users\willi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CurseClientStartup.ccip [2016-01-01] ()
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\Parameters: [NameServer] 8.8.8.8,8.8.8.4
Tcpip\..\Interfaces\{b583a9b8-65ca-463c-8fc0-15a808345548}: [DhcpNameServer] 192.168.0.1
ManualProxies: 
 
Internet Explorer:
==================
HKU\S-1-5-21-3667704814-1699542734-850788743-1002\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.scan.co.uk
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_74\bin\ssv.dll [2016-03-26] (Oracle Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2016-03-25] (AVAST Software)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_74\bin\jp2ssv.dll [2016-03-26] (Oracle Corporation)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> F:\Program Files (x86)\bin\ssv.dll => No File
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2016-03-25] (AVAST Software)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> F:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
 
FireFox:
========
FF Plugin: @java.com/DTPlugin,version=11.74.2 -> C:\Program Files\Java\jre1.8.0_74\bin\dtplugin\npDeployJava1.dll [2016-03-26] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.74.2 -> C:\Program Files\Java\jre1.8.0_74\bin\plugin2\npjp2.dll [2016-03-26] (Oracle Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll [2014-04-03] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2014-04-03] (Intel Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> F:\Program Files (x86)\Microsoft Office\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> F:\Program Files (x86)\Microsoft Office\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-03-05] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-03-05] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> f:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-01-21] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.2 -> f:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-01-21] (VideoLAN)
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2016-03-25]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
 
Chrome: 
=======
CHR Profile: C:\Users\willi\AppData\Local\Google\Chrome\User Data\Default
CHR Profile: C:\Users\willi\AppData\Local\Google\Chrome\User Data\Profile 1
CHR Extension: (Google Slides) - C:\Users\willi\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-01-15]
CHR Extension: (Google Docs) - C:\Users\willi\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2016-01-15]
CHR Extension: (Google Drive) - C:\Users\willi\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-01-15]
CHR Extension: (YouTube) - C:\Users\willi\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-01-15]
CHR Extension: (Adblock Plus) - C:\Users\willi\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2016-03-09]
CHR Extension: (Google Search) - C:\Users\willi\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2016-01-15]
CHR Extension: (Google Sheets) - C:\Users\willi\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-01-15]
CHR Extension: (Google Docs Offline) - C:\Users\willi\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-15]
CHR Extension: (Chrome Web Store Payments) - C:\Users\willi\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-01-15]
CHR Extension: (Gmail) - C:\Users\willi\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-01-15]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2016-03-25]
 
==================== Services (Whitelisted) ========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 asComSvc; C:\Program Files (x86)\ASUS\AXSP\1.02.00\atkexComSvc.exe [936728 2013-07-04] ()
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [237096 2016-03-25] (AVAST Software)
R2 DTSAudioSvc; C:\Program Files\Realtek\Audio\HDA\DTSU2PAuSrv64.exe [240576 2013-10-07] (DTS, Inc)
S3 Futuremark SystemInfo Service; C:\Program Files (x86)\Futuremark\SystemInfo\FMSISvc.exe [342240 2015-11-05] (Futuremark)
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1164672 2016-02-17] (NVIDIA Corporation)
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [18856 2015-06-23] (Intel Corporation)
S3 Intel® Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [887232 2014-01-31] (Intel® Corporation)
R2 Intel® ME Service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe [131544 2014-04-03] (Intel Corporation)
S3 iumsvc; C:\Program Files (x86)\Intel\Intel® Update Manager\bin\iumsvc.exe [178312 2015-09-25] (Intel Corporation)
S2 jhi_service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe [154584 2014-04-03] (Intel Corporation)
R2 nTuneService; C:\Program Files (x86)\NVIDIA Corporation\nTune\nTuneService.exe [180224 2007-09-04] (NVIDIA) [File not signed]
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1880960 2016-02-17] (NVIDIA Corporation)
R3 NvStreamNetworkSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [6474112 2016-02-17] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [2609024 2016-02-17] (NVIDIA Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2015-10-30] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-10-30] (Microsoft Corporation)
 
===================== Drivers (Whitelisted) ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [15232 2013-07-04] ()
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [37656 2016-03-25] (AVAST Software)
R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [37144 2016-03-26] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [107792 2016-03-25] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [103064 2016-03-25] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [74544 2016-03-25] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1070904 2016-03-25] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [463744 2016-03-25] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [165344 2016-03-25] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [287016 2016-03-25] (AVAST Software)
S3 DIRECTIO37; C:\Program Files\BurnInTest\DirectIo64.sys [31376 2015-02-16] ()
R3 e1dexpress; C:\Windows\system32\DRIVERS\e1d65x64.sys [530416 2015-06-18] (Intel Corporation)
R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [118272 2014-04-03] (Intel Corporation)
R3 NVR0Dev; C:\windows\nvoclk64.sys [39968 2007-09-04] (NVidia Corp.)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [28032 2016-02-17] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [47760 2015-12-18] (NVIDIA Corporation)
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation)
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2016-03-26 13:22 - 2016-03-26 13:26 - 00000000 ____D C:\AdwCleaner
2016-03-26 13:21 - 2016-03-26 13:21 - 01530368 _____ C:\Users\willi\Desktop\AdwCleaner.exe
2016-03-26 13:17 - 2016-03-26 13:17 - 00001154 _____ C:\Users\willi\Desktop\JRT.txt
2016-03-26 13:11 - 2016-03-26 13:11 - 01610352 _____ (Malwarebytes) C:\Users\willi\Desktop\JRT.exe
2016-03-26 13:08 - 2016-03-26 13:09 - 00010773 _____ C:\Users\willi\Desktop\Fixlog.txt
2016-03-26 13:06 - 2016-03-26 13:31 - 00018579 _____ C:\Users\willi\Desktop\FRST.txt
2016-03-26 13:06 - 2016-03-26 13:07 - 00045848 _____ C:\Users\willi\Desktop\Addition.txt
2016-03-26 13:03 - 2016-03-26 11:54 - 02374144 _____ (Farbar) C:\Users\willi\Desktop\FRST64.exe
2016-03-26 11:55 - 2016-03-26 13:31 - 00000000 ____D C:\FRST
2016-03-26 07:36 - 2016-03-26 07:36 - 00037144 _____ (AVAST Software) C:\windows\system32\Drivers\aswKbd.sys
2016-03-26 07:36 - 2016-03-26 07:36 - 00003178 _____ C:\windows\System32\Tasks\SafeZone scheduled Autoupdate 1458977815
2016-03-26 07:36 - 2016-03-26 07:36 - 00001088 _____ C:\Users\Public\Desktop\Avast SafeZone Browser.lnk
2016-03-26 07:36 - 2016-03-26 07:36 - 00001088 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast SafeZone Browser.lnk
2016-03-25 22:25 - 2016-03-25 22:23 - 00398152 _____ (AVAST Software) C:\windows\system32\aswBoot.exe
2016-03-25 22:24 - 2016-03-25 22:25 - 00003040 _____ C:\windows\System32\Tasks\avast! Windows 10 Start Menu helper
2016-03-25 22:24 - 2016-03-25 22:24 - 00001985 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast Free Antivirus.lnk
2016-03-25 22:24 - 2016-03-25 22:24 - 00001973 _____ C:\Users\Public\Desktop\Avast Free Antivirus.lnk
2016-03-25 22:24 - 2016-03-25 22:24 - 00000000 ____D C:\Users\willi\AppData\Roaming\AVAST Software
2016-03-25 22:23 - 2016-03-25 22:25 - 00004006 _____ C:\windows\System32\Tasks\avast! Emergency Update
2016-03-25 22:23 - 2016-03-25 22:24 - 01070904 _____ (AVAST Software) C:\windows\system32\Drivers\aswSnx.sys
2016-03-25 22:23 - 2016-03-25 22:24 - 00107792 _____ (AVAST Software) C:\windows\system32\Drivers\aswMonFlt.sys
2016-03-25 22:23 - 2016-03-25 22:23 - 00463744 _____ (AVAST Software) C:\windows\system32\Drivers\aswSP.sys
2016-03-25 22:23 - 2016-03-25 22:23 - 00287016 _____ (AVAST Software) C:\windows\system32\Drivers\aswVmm.sys
2016-03-25 22:23 - 2016-03-25 22:23 - 00165344 _____ (AVAST Software) C:\windows\system32\Drivers\aswStm.sys
2016-03-25 22:23 - 2016-03-25 22:23 - 00103064 _____ (AVAST Software) C:\windows\system32\Drivers\aswRdr2.sys
2016-03-25 22:23 - 2016-03-25 22:23 - 00074544 _____ (AVAST Software) C:\windows\system32\Drivers\aswRvrt.sys
2016-03-25 22:23 - 2016-03-25 22:23 - 00052184 _____ (AVAST Software) C:\windows\avastSS.scr
2016-03-25 22:23 - 2016-03-25 22:23 - 00037656 _____ (AVAST Software) C:\windows\system32\Drivers\aswHwid.sys
2016-03-25 22:23 - 2016-03-25 22:23 - 00001271 _____ C:\Users\willi\Desktop\Continue Flash Video Player Installation.lnk
2016-03-25 22:22 - 2016-03-26 07:36 - 00000000 ____D C:\ProgramData\AVAST Software
2016-03-25 22:22 - 2016-03-26 07:36 - 00000000 ____D C:\Program Files\AVAST Software
2016-03-25 21:38 - 2016-03-25 21:38 - 00000000 ___HD C:\OneDriveTemp
2016-03-25 21:34 - 2016-03-25 21:34 - 00000000 ____D C:\windows\system32\todp
2016-03-25 21:16 - 2016-03-25 21:16 - 00192216 _____ (Malwarebytes) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2016-03-25 21:15 - 2016-03-25 21:36 - 00001171 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2016-03-25 21:15 - 2016-03-25 21:15 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2016-03-25 21:15 - 2016-03-25 21:15 - 00000000 ____D C:\ProgramData\Malwarebytes
2016-03-25 21:15 - 2016-03-25 21:15 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2016-03-25 21:15 - 2016-03-10 14:09 - 00065408 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys
2016-03-25 21:15 - 2016-03-10 14:08 - 00140672 _____ (Malwarebytes) C:\windows\system32\Drivers\mbamchameleon.sys
2016-03-25 21:15 - 2016-03-10 14:08 - 00027008 _____ (Malwarebytes) C:\windows\system32\Drivers\mbam.sys
2016-03-25 21:03 - 2016-03-25 21:03 - 00000000 ____D C:\Users\willi\AppData\Roaming\MCorp
2016-03-25 20:59 - 2016-03-25 23:09 - 00000000 ____D C:\Program Files\Baomkybrile
2016-03-25 20:59 - 2016-03-25 21:35 - 00000000 ____D C:\Users\willi\AppData\Roaming\Memuomi
2016-03-25 20:59 - 2016-03-25 21:01 - 00000000 ____D C:\Users\willi\AppData\Local\app
2016-03-25 20:59 - 2016-03-25 20:59 - 00003418 _____ C:\windows\System32\Tasks\Bimui
2016-03-25 20:59 - 2016-03-25 20:59 - 00000000 ____D C:\Users\willi\AppData\Local\Tempfolder
2016-03-25 20:59 - 2016-03-25 20:59 - 00000000 ____D C:\uninst
2016-03-24 20:12 - 2016-03-25 21:05 - 00000000 ____D C:\Program Files\Common Files\Soobzo
2016-03-24 20:11 - 2016-03-24 20:12 - 00187904 _____ C:\windows\rsrcs.dll
2016-03-24 20:02 - 2016-03-24 20:00 - 00001006 _____ C:\windows\system32\Drivers\etc\hp.bak
2016-03-23 09:00 - 2016-03-23 09:00 - 00000889 _____ C:\windows\SysWOW64\${LOGFILE}
2016-03-23 08:57 - 2016-03-23 08:57 - 06493696 _____ C:\Users\willi\AppData\Roaming\agent.dat
2016-03-23 08:57 - 2016-03-23 08:57 - 01622132 _____ C:\Users\willi\AppData\Roaming\Zimlux.tst
2016-03-23 08:57 - 2016-03-23 08:57 - 00127488 _____ C:\Users\willi\AppData\Roaming\Installer.dat
2016-03-23 08:57 - 2016-03-23 08:57 - 00072707 _____ C:\Users\willi\AppData\Roaming\Jaytom.tst
2016-03-23 08:57 - 2016-03-23 08:57 - 00018432 _____ C:\Users\willi\AppData\Roaming\Main.dat
2016-03-23 08:57 - 2016-03-23 08:57 - 00000000 ____D C:\Users\willi\AppData\Roaming\Mozilla
2016-03-23 08:57 - 2016-03-23 08:57 - 00000000 ____D C:\ProgramData\Quoteexs
2016-03-23 08:56 - 2016-03-23 08:56 - 00000000 ____D C:\ProgramData\DivX
2016-03-23 08:49 - 2016-03-23 08:49 - 00000000 ____D C:\Users\willi\AppData\Roaming\vlc
2016-03-23 08:48 - 2016-03-25 21:36 - 00000835 _____ C:\Users\Public\Desktop\VLC media player.lnk
2016-03-23 08:43 - 2016-03-23 09:02 - 00000000 ____D C:\Users\willi\AppData\Roaming\uTorrent
2016-03-17 20:47 - 2016-03-17 20:47 - 00000000 ____D C:\Users\willi\AppData\Roaming\.mono
2016-03-17 20:47 - 2016-03-17 20:47 - 00000000 ____D C:\ProgramData\.mono
2016-03-13 20:51 - 2016-03-25 21:36 - 00000922 _____ C:\Users\Public\Desktop\Hearthstone.lnk
2016-03-08 22:46 - 2016-03-08 22:46 - 00018521 _____ C:\Users\willi\Documents\cloudbass NEW_HOLIDAY_REQUEST_FORM (1).xlsx
2016-03-08 18:45 - 2016-03-01 05:31 - 00848168 _____ (Microsoft Corporation) C:\windows\system32\mfsvr.dll
2016-03-08 18:45 - 2016-03-01 05:22 - 00709688 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfsvr.dll
2016-03-08 18:45 - 2016-02-24 09:52 - 01997328 _____ (Microsoft Corporation) C:\windows\system32\KernelBase.dll
2016-03-08 18:45 - 2016-02-24 09:51 - 07474528 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe
2016-03-08 18:45 - 2016-02-24 09:48 - 00713568 _____ (Microsoft Corporation) C:\windows\system32\invagent.dll
2016-03-08 18:45 - 2016-02-24 09:47 - 01173344 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll
2016-03-08 18:45 - 2016-02-24 09:40 - 00513888 _____ (Microsoft Corporation) C:\windows\system32\devinv.dll
2016-03-08 18:45 - 2016-02-24 09:34 - 01613664 _____ (Microsoft Corporation) C:\windows\system32\diagtrack.dll
2016-03-08 18:45 - 2016-02-24 09:28 - 03449168 _____ (Microsoft Corporation) C:\windows\system32\WSService.dll
2016-03-08 18:45 - 2016-02-24 09:15 - 01557768 _____ (Microsoft Corporation) C:\windows\SysWOW64\KernelBase.dll
2016-03-08 18:45 - 2016-02-24 08:58 - 00794888 _____ (Microsoft Corporation) C:\windows\system32\mfds.dll
2016-03-08 18:45 - 2016-02-24 08:54 - 00127840 _____ (Microsoft Corporation) C:\windows\system32\Drivers\USBSTOR.SYS
2016-03-08 18:45 - 2016-02-24 08:51 - 01322248 _____ (Microsoft Corporation) C:\windows\system32\ole32.dll
2016-03-08 18:45 - 2016-02-24 08:50 - 00808800 _____ (Microsoft Corporation) C:\windows\system32\WWAHost.exe
2016-03-08 18:45 - 2016-02-24 08:46 - 06607080 _____ (Microsoft Corporation) C:\windows\system32\windows.storage.dll
2016-03-08 18:45 - 2016-02-24 08:43 - 00625000 _____ (Microsoft Corporation) C:\windows\system32\ClipSVC.dll
2016-03-08 18:45 - 2016-02-24 08:39 - 00358752 _____ (Microsoft Corporation) C:\windows\system32\msv1_0.dll
2016-03-08 18:45 - 2016-02-24 08:39 - 00141560 _____ (Microsoft Corporation) C:\windows\system32\AuthHost.exe
2016-03-08 18:45 - 2016-02-24 08:19 - 00670928 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfds.dll
2016-03-08 18:45 - 2016-02-24 08:14 - 00216416 _____ (Microsoft Corporation) C:\windows\system32\AppxAllUserStore.dll
2016-03-08 18:45 - 2016-02-24 08:11 - 01997152 _____ (Microsoft Corporation) C:\windows\system32\Drivers\dxgkrnl.sys
2016-03-08 18:45 - 2016-02-24 08:11 - 00957608 _____ (Microsoft Corporation) C:\windows\SysWOW64\ole32.dll
2016-03-08 18:45 - 2016-02-24 08:11 - 00703840 _____ (Microsoft Corporation) C:\windows\SysWOW64\WWAHost.exe
2016-03-08 18:45 - 2016-02-24 08:11 - 00652392 _____ (Microsoft Corporation) C:\windows\system32\dxgi.dll
2016-03-08 18:45 - 2016-02-24 08:11 - 00394080 _____ (Microsoft Corporation) C:\windows\system32\Drivers\dxgmms1.sys
2016-03-08 18:45 - 2016-02-24 08:11 - 00258280 _____ (Microsoft Corporation) C:\windows\system32\sqmapi.dll
2016-03-08 18:45 - 2016-02-24 08:10 - 00630632 _____ (Microsoft Corporation) C:\windows\system32\fontdrvhost.exe
2016-03-08 18:45 - 2016-02-24 08:10 - 00576864 _____ (Microsoft Corporation) C:\windows\system32\Drivers\dxgmms2.sys
2016-03-08 18:45 - 2016-02-24 08:09 - 00640472 _____ (Microsoft Corporation) C:\windows\system32\wer.dll
2016-03-08 18:45 - 2016-02-24 08:09 - 00147808 _____ (Microsoft Corporation) C:\windows\system32\wermgr.exe
2016-03-08 18:45 - 2016-02-24 08:06 - 05242496 _____ (Microsoft Corporation) C:\windows\SysWOW64\windows.storage.dll
2016-03-08 18:45 - 2016-02-24 07:59 - 00294752 _____ (Microsoft Corporation) C:\windows\SysWOW64\msv1_0.dll
2016-03-08 18:45 - 2016-02-24 07:39 - 00045568 _____ (Microsoft Corporation) C:\windows\system32\UserDataTypeHelperUtil.dll
2016-03-08 18:45 - 2016-02-24 07:39 - 00023552 _____ (Microsoft Corporation) C:\windows\system32\ExtrasXmlParser.dll
2016-03-08 18:45 - 2016-02-24 07:38 - 00187744 _____ (Microsoft Corporation) C:\windows\SysWOW64\AppxAllUserStore.dll
2016-03-08 18:45 - 2016-02-24 07:38 - 00111616 _____ (Microsoft Corporation) C:\windows\system32\UserDataTimeUtil.dll
2016-03-08 18:45 - 2016-02-24 07:37 - 00045056 _____ (Microsoft Corporation) C:\windows\system32\UserDataLanguageUtil.dll
2016-03-08 18:45 - 2016-02-24 07:36 - 00060416 _____ (Microsoft Corporation) C:\windows\system32\PimIndexMaintenanceClient.dll
2016-03-08 18:45 - 2016-02-24 07:35 - 00540752 _____ (Microsoft Corporation) C:\windows\SysWOW64\fontdrvhost.exe
2016-03-08 18:45 - 2016-02-24 07:35 - 00523752 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxgi.dll
2016-03-08 18:45 - 2016-02-24 07:35 - 00220064 _____ (Microsoft Corporation) C:\windows\SysWOW64\sqmapi.dll
2016-03-08 18:45 - 2016-02-24 07:35 - 00045568 _____ (Adobe Systems) C:\windows\system32\atmlib.dll
2016-03-08 18:45 - 2016-02-24 07:33 - 00538736 _____ (Microsoft Corporation) C:\windows\SysWOW64\wer.dll
2016-03-08 18:45 - 2016-02-24 07:33 - 00141664 _____ (Microsoft Corporation) C:\windows\SysWOW64\wermgr.exe
2016-03-08 18:45 - 2016-02-24 07:31 - 00118272 _____ (Microsoft Corporation) C:\windows\system32\fontsub.dll
2016-03-08 18:45 - 2016-02-24 07:30 - 00025600 _____ (Microsoft Corporation) C:\windows\system32\wfapigp.dll
2016-03-08 18:45 - 2016-02-24 07:28 - 00070656 _____ (Microsoft Corporation) C:\windows\system32\POSyncServices.dll
2016-03-08 18:45 - 2016-02-24 07:23 - 00091648 _____ (Microsoft Corporation) C:\windows\system32\asycfilt.dll
2016-03-08 18:45 - 2016-02-24 07:23 - 00068096 _____ (Microsoft Corporation) C:\windows\system32\UserDataPlatformHelperUtil.dll
2016-03-08 18:45 - 2016-02-24 07:22 - 00196608 _____ (Microsoft Corporation) C:\windows\system32\fwpolicyiomgr.dll
2016-03-08 18:45 - 2016-02-24 07:20 - 00195072 _____ (Microsoft Corporation) C:\windows\system32\VCardParser.dll
2016-03-08 18:45 - 2016-02-24 07:20 - 00167936 _____ (Microsoft Corporation) C:\windows\system32\dafBth.dll
2016-03-08 18:45 - 2016-02-24 07:20 - 00087552 _____ (Microsoft Corporation) C:\windows\system32\AppxSysprep.dll
2016-03-08 18:45 - 2016-02-24 07:19 - 00145408 _____ (Microsoft Corporation) C:\windows\system32\dssvc.dll
2016-03-08 18:45 - 2016-02-24 07:19 - 00031232 _____ (Microsoft Corporation) C:\windows\system32\seclogon.dll
2016-03-08 18:45 - 2016-02-24 07:15 - 00365568 _____ (Adobe Systems Incorporated) C:\windows\system32\atmfd.dll
2016-03-08 18:45 - 2016-02-24 07:14 - 00274944 _____ (Microsoft Corporation) C:\windows\system32\ExSMime.dll
2016-03-08 18:45 - 2016-02-24 07:13 - 00121856 _____ (Microsoft Corporation) C:\windows\system32\AppointmentActivation.dll
2016-03-08 18:45 - 2016-02-24 07:12 - 00243712 _____ (Microsoft Corporation) C:\windows\system32\cemapi.dll
2016-03-08 18:45 - 2016-02-24 07:12 - 00221184 _____ (Microsoft Corporation) C:\windows\system32\PhoneCallHistoryApis.dll
2016-03-08 18:45 - 2016-02-24 07:10 - 00093184 _____ (Microsoft Corporation) C:\windows\system32\wpninprc.dll
2016-03-08 18:45 - 2016-02-24 07:09 - 00258560 _____ (Microsoft Corporation) C:\windows\system32\UserDataAccountApis.dll
2016-03-08 18:45 - 2016-02-24 07:09 - 00161792 _____ (Microsoft Corporation) C:\windows\system32\AppxSip.dll
2016-03-08 18:45 - 2016-02-24 07:07 - 00252928 _____ (Microsoft Corporation) C:\windows\system32\PimIndexMaintenance.dll
2016-03-08 18:45 - 2016-02-24 07:05 - 00208896 _____ (Microsoft Corporation) C:\windows\system32\storewuauth.dll
2016-03-08 18:45 - 2016-02-24 07:03 - 00088576 _____ (Microsoft Corporation) C:\windows\SysWOW64\olepro32.dll
2016-03-08 18:45 - 2016-02-24 07:02 - 00161280 _____ (Microsoft Corporation) C:\windows\system32\CallHistoryClient.dll
2016-03-08 18:45 - 2016-02-24 07:01 - 00764928 _____ (Microsoft Corporation) C:\windows\system32\Chakradiag.dll
2016-03-08 18:45 - 2016-02-24 07:01 - 00146432 _____ (Microsoft Corporation) C:\windows\system32\AuthBroker.dll
2016-03-08 18:45 - 2016-02-24 07:01 - 00067584 _____ (Microsoft Corporation) C:\windows\system32\profext.dll
2016-03-08 18:45 - 2016-02-24 07:00 - 00214528 _____ (Microsoft Corporation) C:\windows\system32\Windows.Devices.Scanners.dll
2016-03-08 18:45 - 2016-02-24 06:59 - 00450560 _____ (Microsoft Corporation) C:\windows\system32\Windows.Internal.Bluetooth.dll
2016-03-08 18:45 - 2016-02-24 06:59 - 00360448 _____ (Microsoft Corporation) C:\windows\system32\vaultsvc.dll
2016-03-08 18:45 - 2016-02-24 06:59 - 00318976 _____ (Microsoft Corporation) C:\windows\system32\domgmt.dll
2016-03-08 18:45 - 2016-02-24 06:58 - 00685568 _____ (Microsoft Corporation) C:\windows\system32\scapi.dll
2016-03-08 18:45 - 2016-02-24 06:55 - 00790528 _____ (Microsoft Corporation) C:\windows\system32\EmailApis.dll
2016-03-08 18:45 - 2016-02-24 06:55 - 00224256 _____ (Microsoft Corporation) C:\windows\system32\PackageStateRoaming.dll
2016-03-08 18:45 - 2016-02-24 06:55 - 00018944 _____ (Microsoft Corporation) C:\windows\SysWOW64\ExtrasXmlParser.dll
2016-03-08 18:45 - 2016-02-24 06:54 - 00526336 _____ (Microsoft Corporation) C:\windows\system32\FirewallAPI.dll
2016-03-08 18:45 - 2016-02-24 06:54 - 00288768 _____ (Microsoft Corporation) C:\windows\system32\vaultcli.dll
2016-03-08 18:45 - 2016-02-24 06:54 - 00228352 _____ (Microsoft Corporation) C:\windows\system32\wsqmcons.exe
2016-03-08 18:45 - 2016-02-24 06:54 - 00037888 _____ (Microsoft Corporation) C:\windows\SysWOW64\UserDataTypeHelperUtil.dll
2016-03-08 18:45 - 2016-02-24 06:53 - 00089088 _____ (Microsoft Corporation) C:\windows\SysWOW64\UserDataTimeUtil.dll
2016-03-08 18:45 - 2016-02-24 06:53 - 00037888 _____ (Microsoft Corporation) C:\windows\SysWOW64\UserDataLanguageUtil.dll
2016-03-08 18:45 - 2016-02-24 06:52 - 00451584 _____ (Microsoft Corporation) C:\windows\system32\werui.dll
2016-03-08 18:45 - 2016-02-24 06:52 - 00048128 _____ (Microsoft Corporation) C:\windows\SysWOW64\PimIndexMaintenanceClient.dll
2016-03-08 18:45 - 2016-02-24 06:51 - 00037376 _____ (Adobe Systems) C:\windows\SysWOW64\atmlib.dll
2016-03-08 18:45 - 2016-02-24 06:49 - 00726528 _____ (Microsoft Corporation) C:\windows\system32\ChatApis.dll
2016-03-08 18:45 - 2016-02-24 06:47 - 00093696 _____ (Microsoft Corporation) C:\windows\SysWOW64\fontsub.dll
2016-03-08 18:45 - 2016-02-24 06:46 - 00020480 _____ (Microsoft Corporation) C:\windows\SysWOW64\wfapigp.dll
2016-03-08 18:45 - 2016-02-24 06:44 - 01713664 _____ (Microsoft Corporation) C:\windows\system32\SRHInproc.dll
2016-03-08 18:45 - 2016-02-24 06:44 - 00915456 _____ (Microsoft Corporation) C:\windows\system32\configurationclient.dll
2016-03-08 18:45 - 2016-02-24 06:44 - 00700416 _____ (Microsoft Corporation) C:\windows\system32\AppointmentApis.dll
2016-03-08 18:45 - 2016-02-24 06:44 - 00056320 _____ (Microsoft Corporation) C:\windows\SysWOW64\POSyncServices.dll
2016-03-08 18:45 - 2016-02-24 06:43 - 00957952 _____ (Microsoft Corporation) C:\windows\system32\SRH.dll
2016-03-08 18:45 - 2016-02-24 06:43 - 00286720 _____ (Microsoft Corporation) C:\windows\system32\deviceaccess.dll
2016-03-08 18:45 - 2016-02-24 06:41 - 00982016 _____ (Microsoft Corporation) C:\windows\system32\AppxPackaging.dll
2016-03-08 18:45 - 2016-02-24 06:41 - 00436736 _____ (Microsoft Corporation) C:\windows\system32\AppXDeploymentClient.dll
2016-03-08 18:45 - 2016-02-24 06:40 - 01224704 _____ (Microsoft Corporation) C:\windows\system32\Unistore.dll
2016-03-08 18:45 - 2016-02-24 06:40 - 00078848 _____ (Microsoft Corporation) C:\windows\SysWOW64\asycfilt.dll
2016-03-08 18:45 - 2016-02-24 06:40 - 00056320 _____ (Microsoft Corporation) C:\windows\SysWOW64\UserDataPlatformHelperUtil.dll
2016-03-08 18:45 - 2016-02-24 06:39 - 01390592 _____ (Microsoft Corporation) C:\windows\system32\win32kbase.sys
2016-03-08 18:45 - 2016-02-24 06:39 - 00164864 _____ (Microsoft Corporation) C:\windows\SysWOW64\fwpolicyiomgr.dll
2016-03-08 18:45 - 2016-02-24 06:38 - 00150528 _____ (Microsoft Corporation) C:\windows\SysWOW64\VCardParser.dll
2016-03-08 18:45 - 2016-02-24 06:36 - 01847808 _____ (Microsoft Corporation) C:\windows\system32\WMPDMC.exe
2016-03-08 18:45 - 2016-02-24 06:34 - 00938496 _____ (Microsoft Corporation) C:\windows\system32\ContactApis.dll
2016-03-08 18:45 - 2016-02-24 06:34 - 00303104 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\atmfd.dll
2016-03-08 18:45 - 2016-02-24 06:32 - 00223744 _____ (Microsoft Corporation) C:\windows\SysWOW64\ExSMime.dll
2016-03-08 18:45 - 2016-02-24 06:32 - 00098304 _____ (Microsoft Corporation) C:\windows\SysWOW64\AppointmentActivation.dll
2016-03-08 18:45 - 2016-02-24 06:31 - 00200704 _____ (Microsoft Corporation) C:\windows\SysWOW64\cemapi.dll
2016-03-08 18:45 - 2016-02-24 06:31 - 00169984 _____ (Microsoft Corporation) C:\windows\SysWOW64\PhoneCallHistoryApis.dll
2016-03-08 18:45 - 2016-02-24 06:28 - 00870912 _____ (Microsoft Corporation) C:\windows\system32\MPSSVC.dll
2016-03-08 18:45 - 2016-02-24 06:28 - 00196608 _____ (Microsoft Corporation) C:\windows\SysWOW64\UserDataAccountApis.dll
2016-03-08 18:45 - 2016-02-24 06:28 - 00135168 _____ (Microsoft Corporation) C:\windows\SysWOW64\AppxSip.dll
2016-03-08 18:45 - 2016-02-24 06:25 - 00401408 _____ (Microsoft Corporation) C:\windows\system32\sharemediacpl.dll
2016-03-08 18:45 - 2016-02-24 06:23 - 00129024 _____ (Microsoft Corporation) C:\windows\SysWOW64\CallHistoryClient.dll
2016-03-08 18:45 - 2016-02-24 06:22 - 00053248 _____ (Microsoft Corporation) C:\windows\SysWOW64\profext.dll
2016-03-08 18:45 - 2016-02-24 06:21 - 00315904 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.Internal.Bluetooth.dll
2016-03-08 18:45 - 2016-02-24 06:21 - 00168448 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.Devices.Scanners.dll
2016-03-08 18:45 - 2016-02-24 06:18 - 01490432 _____ (Microsoft Corporation) C:\windows\system32\UserDataService.dll
2016-03-08 18:45 - 2016-02-24 06:18 - 00575488 _____ (Microsoft Corporation) C:\windows\SysWOW64\EmailApis.dll
2016-03-08 18:45 - 2016-02-24 06:18 - 00184832 _____ (Microsoft Corporation) C:\windows\SysWOW64\PackageStateRoaming.dll
2016-03-08 18:45 - 2016-02-24 06:17 - 00369664 _____ (Microsoft Corporation) C:\windows\SysWOW64\FirewallAPI.dll
2016-03-08 18:45 - 2016-02-24 06:16 - 00394752 _____ (Microsoft Corporation) C:\windows\SysWOW64\werui.dll
2016-03-08 18:45 - 2016-02-24 06:13 - 00540160 _____ (Microsoft Corporation) C:\windows\SysWOW64\ChatApis.dll
2016-03-08 18:45 - 2016-02-24 06:11 - 03593216 _____ (Microsoft Corporation) C:\windows\system32\win32kfull.sys
2016-03-08 18:45 - 2016-02-24 06:09 - 01443328 _____ (Microsoft Corporation) C:\windows\SysWOW64\SRHInproc.dll
2016-03-08 18:45 - 2016-02-24 06:09 - 00793600 _____ (Microsoft Corporation) C:\windows\SysWOW64\SRH.dll
2016-03-08 18:45 - 2016-02-24 06:09 - 00552960 _____ (Microsoft Corporation) C:\windows\SysWOW64\AppointmentApis.dll
2016-03-08 18:45 - 2016-02-24 06:09 - 00228352 _____ (Microsoft Corporation) C:\windows\SysWOW64\deviceaccess.dll
2016-03-08 18:45 - 2016-02-24 06:07 - 00949248 _____ (Microsoft Corporation) C:\windows\SysWOW64\Unistore.dll
2016-03-08 18:45 - 2016-02-24 06:07 - 00890368 _____ (Microsoft Corporation) C:\windows\SysWOW64\AppxPackaging.dll
2016-03-08 18:45 - 2016-02-24 06:07 - 00342528 _____ (Microsoft Corporation) C:\windows\SysWOW64\AppXDeploymentClient.dll
2016-03-08 18:45 - 2016-02-24 06:04 - 01497088 _____ (Microsoft Corporation) C:\windows\SysWOW64\WMPDMC.exe
2016-03-08 18:45 - 2016-02-24 06:03 - 00769536 _____ (Microsoft Corporation) C:\windows\SysWOW64\ContactApis.dll
2016-03-08 18:45 - 2016-02-24 06:01 - 01831936 _____ (Microsoft Corporation) C:\windows\system32\AppXDeploymentExtensions.dll
2016-03-08 18:45 - 2016-02-24 06:00 - 02273792 _____ (Microsoft Corporation) C:\windows\system32\wuaueng.dll
2016-03-08 18:45 - 2016-02-24 06:00 - 01098752 _____ (Microsoft Corporation) C:\windows\system32\dosvc.dll
2016-03-08 18:45 - 2016-02-24 05:57 - 02158592 _____ (Microsoft Corporation) C:\windows\system32\AppXDeploymentServer.dll
2016-03-08 18:45 - 2016-02-24 05:55 - 01996288 _____ (Microsoft Corporation) C:\windows\system32\ActiveSyncProvider.dll
2016-03-08 18:45 - 2016-02-24 05:43 - 00184320 _____ (Microsoft Corporation) C:\windows\system32\fwbase.dll
2016-03-08 18:45 - 2016-02-24 05:34 - 01707520 _____ (Microsoft Corporation) C:\windows\SysWOW64\ActiveSyncProvider.dll
2016-03-08 18:45 - 2016-02-24 05:22 - 00163328 _____ (Microsoft Corporation) C:\windows\SysWOW64\fwbase.dll
2016-03-08 18:45 - 2016-02-24 05:20 - 22376960 _____ (Microsoft Corporation) C:\windows\system32\edgehtml.dll
2016-03-08 18:45 - 2016-02-24 05:18 - 18677760 _____ (Microsoft Corporation) C:\windows\SysWOW64\edgehtml.dll
2016-03-08 18:45 - 2016-02-24 05:12 - 19339776 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2016-03-08 18:45 - 2016-02-24 05:12 - 05321728 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.Data.Pdf.dll
2016-03-08 18:45 - 2016-02-24 05:10 - 24600576 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2016-03-08 18:45 - 2016-02-24 05:09 - 06972416 _____ (Microsoft Corporation) C:\windows\system32\Windows.Data.Pdf.dll
2016-03-08 18:45 - 2016-02-24 05:05 - 12586496 _____ (Microsoft Corporation) C:\windows\SysWOW64\wmp.dll
2016-03-08 18:45 - 2016-02-24 05:03 - 14252544 _____ (Microsoft Corporation) C:\windows\system32\wmp.dll
2016-03-08 18:45 - 2016-02-24 04:59 - 05661696 _____ (Microsoft Corporation) C:\windows\SysWOW64\Chakra.dll
2016-03-08 18:45 - 2016-02-24 04:55 - 07835648 _____ (Microsoft Corporation) C:\windows\system32\Chakra.dll
2016-03-06 13:33 - 2016-03-25 21:36 - 00002332 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2016-03-05 19:14 - 2016-03-05 19:14 - 00000000 ____D C:\Program Files (x86)\Google
2016-03-03 23:29 - 2016-03-03 23:29 - 00000000 ____D C:\Users\willi\AppData\Roaming\NVIDIA
2016-03-01 20:45 - 2016-03-01 20:45 - 00372736 _____ (NVIDIA Corporation) C:\windows\system32\NVUNINST.EXE
2016-03-01 20:45 - 2016-03-01 20:45 - 00000000 ____D C:\Program Files (x86)\NVIDIA nTune Performance Application
2016-03-01 20:45 - 2007-07-03 16:41 - 01524736 _____ (Microsoft Corporation) C:\windows\system32\MFC71.dll
2016-03-01 20:45 - 2007-07-03 16:41 - 00978944 _____ (Microsoft Corporation) C:\windows\system32\msvcp71.dll
2016-03-01 20:45 - 2007-07-03 16:41 - 00520192 _____ (Microsoft Corporation) C:\windows\system32\msvcr71.dll
2016-03-01 20:45 - 2007-06-25 22:21 - 02065920 _____ (NVIDIA Corporation) C:\windows\system32\nvcplUI.exe
2016-03-01 20:45 - 2007-06-25 22:21 - 01064448 _____ (NVIDIA Corporation) C:\windows\system32\nvcplUIR.dll
2016-03-01 20:45 - 2007-06-25 22:21 - 00403456 _____ (NVIDIA Corporation) C:\windows\system32\nvcpl.cpl
2016-03-01 20:45 - 2007-06-25 22:21 - 00381952 _____ (NVIDIA Corporation) C:\windows\system32\nvexpBar.dll
2016-03-01 20:40 - 2016-03-25 21:36 - 00001450 _____ C:\Users\Public\Desktop\GeForce Experience.lnk
2016-03-01 20:34 - 2016-03-26 07:49 - 00110176 _____ (Oracle Corporation) C:\windows\system32\WindowsAccessBridge-64.dll
2016-03-01 20:34 - 2016-03-26 07:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2016-03-01 20:34 - 2016-03-26 07:49 - 00000000 ____D C:\Program Files\Java
2016-03-01 20:15 - 2016-03-01 20:15 - 00000000 ____D C:\ProgramData\NVIDIA
2016-03-01 20:15 - 2016-02-23 23:57 - 00215608 _____ (Khronos Group) C:\windows\system32\OpenCL.dll
2016-03-01 20:15 - 2016-02-23 23:57 - 00201664 _____ (Khronos Group) C:\windows\SysWOW64\OpenCL.dll
2016-03-01 20:15 - 2016-02-23 20:28 - 06368824 _____ (NVIDIA Corporation) C:\windows\system32\nvcpl.dll
2016-03-01 20:15 - 2016-02-23 20:28 - 06154909 _____ C:\windows\system32\nvcoproc.bin
2016-03-01 20:15 - 2016-02-23 20:28 - 02993720 _____ (NVIDIA Corporation) C:\windows\system32\nvsvc64.dll
2016-03-01 20:15 - 2016-02-23 20:28 - 02563128 _____ (NVIDIA Corporation) C:\windows\system32\nvsvcr.dll
2016-03-01 20:15 - 2016-02-23 20:28 - 01263040 _____ (NVIDIA Corporation) C:\windows\system32\nvvsvc.exe
2016-03-01 20:15 - 2016-02-23 20:28 - 00530368 _____ (NVIDIA Corporation) C:\windows\system32\nv3dappshext.dll
2016-03-01 20:15 - 2016-02-23 20:28 - 00393784 _____ (NVIDIA Corporation) C:\windows\system32\nvmctray.dll
2016-03-01 20:15 - 2016-02-23 20:28 - 00081856 _____ (NVIDIA Corporation) C:\windows\system32\nv3dappshextr.dll
2016-03-01 20:15 - 2016-02-23 20:28 - 00071224 _____ (NVIDIA Corporation) C:\windows\system32\nvshext.dll
2016-03-01 20:14 - 2016-02-25 01:04 - 12479040 _____ (NVIDIA Corporation) C:\windows\system32\Drivers\nvlddmkm.sys
2016-03-01 20:14 - 2016-02-23 23:57 - 42983480 _____ C:\windows\system32\nvcompiler.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 37616184 _____ C:\windows\SysWOW64\nvcompiler.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 31120952 _____ (NVIDIA Corporation) C:\windows\system32\nvoglv64.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 24944064 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvoglv32.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 21201784 _____ (NVIDIA Corporation) C:\windows\system32\nvopencl.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 20742072 _____ (NVIDIA Corporation) C:\windows\system32\nvcuda.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 19779456 _____ (NVIDIA Corporation) C:\windows\system32\nvwgf2umx.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 17631304 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvopencl.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 17224472 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvcuda.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 17175056 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvwgf2um.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 17117128 _____ (NVIDIA Corporation) C:\windows\system32\nvd3dumx.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 14115136 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvd3dum.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 03649760 _____ (NVIDIA Corporation) C:\windows\system32\nvapi64.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 03231360 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvapi.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 02541504 _____ (NVIDIA Corporation) C:\windows\system32\nvcuvid.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 02187712 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvcuvid.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 01924152 _____ (NVIDIA Corporation) C:\windows\system32\nvdispco6436200.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 01571776 _____ (NVIDIA Corporation) C:\windows\system32\nvdispgenco6436200.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 00950328 _____ (NVIDIA Corporation) C:\windows\system32\NvFBC64.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 00880576 _____ (NVIDIA Corporation) C:\windows\system32\NvIFR64.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 00786688 _____ (NVIDIA Corporation) C:\windows\system32\nvEncMFTH264.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 00784824 _____ (NVIDIA Corporation) C:\windows\system32\nvEncMFThevc.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 00747064 _____ (NVIDIA Corporation) C:\windows\SysWOW64\NvFBC.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 00689600 _____ (NVIDIA Corporation) C:\windows\SysWOW64\NvIFR.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 00632336 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvEncMFTH264.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 00630776 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvEncMFThevc.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 00601936 _____ C:\windows\system32\nvmcumd.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 00541184 _____ (NVIDIA Corporation) C:\windows\system32\nvumdshimx.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 00445912 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvumdshim.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 00425016 _____ (NVIDIA Corporation) C:\windows\system32\NvIFROpenGL.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 00383424 _____ (NVIDIA Corporation) C:\windows\system32\nvDecMFTMjpeg.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 00379448 _____ (NVIDIA Corporation) C:\windows\SysWOW64\NvIFROpenGL.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 00378968 _____ (NVIDIA Corporation) C:\windows\system32\nvEncodeAPI64.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 00346560 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvDecMFTMjpeg.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 00316960 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvEncodeAPI.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 00175552 _____ (NVIDIA Corporation) C:\windows\system32\nvinitx.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 00153208 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvinit.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 00151368 _____ (NVIDIA Corporation) C:\windows\system32\nvoglshim64.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 00128512 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvoglshim32.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 00035832 _____ C:\windows\system32\nvinfo.pb
2016-03-01 19:47 - 2016-03-01 19:48 - 00000000 ____D C:\Users\willi\AppData\Local\NVIDIA
2016-03-01 19:47 - 2016-02-17 06:40 - 01903344 _____ (NVIDIA Corporation) C:\windows\system32\nvspcap64.dll
2016-03-01 19:47 - 2016-02-17 06:40 - 01756424 _____ (NVIDIA Corporation) C:\windows\system32\nvspbridge64.dll
2016-03-01 19:47 - 2016-02-17 06:40 - 01571624 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvspcap.dll
2016-03-01 19:47 - 2016-02-17 06:40 - 01316184 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvspbridge.dll
2016-03-01 19:47 - 2016-02-17 06:40 - 00112216 _____ C:\windows\system32\NvRtmpStreamer64.dll
2016-03-01 19:47 - 2015-12-18 06:11 - 00047760 _____ (NVIDIA Corporation) C:\windows\system32\Drivers\nvvad64v.sys
2016-03-01 19:47 - 2015-12-18 06:10 - 00099472 _____ (NVIDIA Corporation) C:\windows\system32\nvaudcap64v.dll
2016-03-01 19:47 - 2015-12-18 06:10 - 00090768 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvaudcap32v.dll
2016-03-01 19:11 - 2016-02-23 11:29 - 01030416 _____ (Microsoft Corporation) C:\windows\system32\winresume.efi
2016-03-01 19:11 - 2016-02-23 11:29 - 00874968 _____ (Microsoft Corporation) C:\windows\system32\winresume.exe
2016-03-01 19:11 - 2016-02-23 11:27 - 02654872 _____ C:\windows\system32\CoreUIComponents.dll
2016-03-01 19:11 - 2016-02-23 11:27 - 01317640 _____ (Microsoft Corporation) C:\windows\system32\winload.efi
2016-03-01 19:11 - 2016-02-23 11:27 - 01141504 _____ (Microsoft Corporation) C:\windows\system32\winload.exe
2016-03-01 19:11 - 2016-02-23 11:25 - 02152288 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ntfs.sys
2016-03-01 19:11 - 2016-02-23 11:25 - 01818696 _____ (Microsoft Corporation) C:\windows\system32\ntdll.dll
2016-03-01 19:11 - 2016-02-23 11:25 - 00563552 _____ (Microsoft Corporation) C:\windows\system32\Drivers\acpi.sys
2016-03-01 19:11 - 2016-02-23 11:15 - 00779384 _____ (Microsoft Corporation) C:\windows\system32\taskschd.dll
2016-03-01 19:11 - 2016-02-23 11:08 - 00989536 _____ (Microsoft Corporation) C:\windows\system32\SecConfig.efi
2016-03-01 19:11 - 2016-02-23 10:34 - 01859960 _____ C:\windows\SysWOW64\CoreUIComponents.dll
2016-03-01 19:11 - 2016-02-23 10:34 - 01542816 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntdll.dll
2016-03-01 19:11 - 2016-02-23 10:33 - 00696160 _____ (Microsoft Corporation) C:\windows\system32\NetSetupEngine.dll
2016-03-01 19:11 - 2016-02-23 10:33 - 00389992 _____ (Microsoft Corporation) C:\windows\system32\wlanapi.dll
2016-03-01 19:11 - 2016-02-23 10:32 - 08705672 _____ (Microsoft Corp.) C:\windows\system32\Windows.Media.Protection.PlayReady.dll
2016-03-01 19:11 - 2016-02-23 10:32 - 02544264 _____ (Microsoft Corporation) C:\windows\system32\mfcore.dll
2016-03-01 19:11 - 2016-02-23 10:32 - 01152328 _____ (Microsoft Corporation) C:\windows\system32\mfasfsrcsnk.dll
2016-03-01 19:11 - 2016-02-23 10:32 - 01062480 _____ (Microsoft Corporation) C:\windows\system32\mfmp4srcsnk.dll
2016-03-01 19:11 - 2016-02-23 10:32 - 00498448 _____ (Microsoft Corporation) C:\windows\system32\MFCaptureEngine.dll
2016-03-01 19:11 - 2016-02-23 10:32 - 00369912 _____ (Microsoft Corporation) C:\windows\system32\audiodg.exe
2016-03-01 19:11 - 2016-02-23 10:31 - 01017032 _____ (Microsoft Corporation) C:\windows\system32\mfsrcsnk.dll
2016-03-01 19:11 - 2016-02-23 10:31 - 00819648 _____ (Microsoft Corporation) C:\windows\system32\mfmpeg2srcsnk.dll
2016-03-01 19:11 - 2016-02-23 10:31 - 00536256 _____ (Microsoft Corporation) C:\windows\system32\AudioSes.dll
2016-03-01 19:11 - 2016-02-23 10:31 - 00476728 _____ (Microsoft Corporation) C:\windows\system32\msvproc.dll
2016-03-01 19:11 - 2016-02-23 10:31 - 00408120 _____ (Microsoft Corporation) C:\windows\system32\AUDIOKSE.dll
2016-03-01 19:11 - 2016-02-23 10:25 - 03671888 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2016-03-01 19:11 - 2016-02-23 10:22 - 00572272 _____ (Microsoft Corporation) C:\windows\SysWOW64\taskschd.dll
2016-03-01 19:11 - 2016-02-23 10:21 - 22564328 _____ (Microsoft Corporation) C:\windows\system32\shell32.dll
2016-03-01 19:11 - 2016-02-23 10:17 - 00146272 _____ (Microsoft Corporation) C:\windows\system32\Drivers\appid.sys
2016-03-01 19:11 - 2016-02-23 09:45 - 02773096 _____ (Microsoft Corporation) C:\windows\system32\d3d11.dll
2016-03-01 19:11 - 2016-02-23 09:40 - 00430944 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb.sys
2016-03-01 19:11 - 2016-02-23 09:39 - 00502112 _____ (Microsoft Corporation) C:\windows\SysWOW64\NetSetupEngine.dll
2016-03-01 19:11 - 2016-02-23 09:38 - 06952088 _____ (Microsoft Corp.) C:\windows\SysWOW64\Windows.Media.Protection.PlayReady.dll
2016-03-01 19:11 - 2016-02-23 09:38 - 02180136 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfcore.dll
2016-03-01 19:11 - 2016-02-23 09:38 - 00980352 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfasfsrcsnk.dll
2016-03-01 19:11 - 2016-02-23 09:38 - 00895080 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfsrcsnk.dll
2016-03-01 19:11 - 2016-02-23 09:38 - 00882720 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfmp4srcsnk.dll
2016-03-01 19:11 - 2016-02-23 09:38 - 00450912 _____ (Microsoft Corporation) C:\windows\SysWOW64\MFCaptureEngine.dll
2016-03-01 19:11 - 2016-02-23 09:38 - 00420928 _____ (Microsoft Corporation) C:\windows\SysWOW64\msvproc.dll
2016-03-01 19:11 - 2016-02-23 09:37 - 00713824 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfmpeg2srcsnk.dll
2016-03-01 19:11 - 2016-02-23 09:32 - 00791744 _____ (Microsoft Corporation) C:\windows\system32\generaltel.dll
2016-03-01 19:11 - 2016-02-23 09:30 - 02919320 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2016-03-01 19:11 - 2016-02-23 09:27 - 21124344 _____ (Microsoft Corporation) C:\windows\SysWOW64\shell32.dll
2016-03-01 19:11 - 2016-02-23 09:27 - 00376536 _____ (Microsoft Corporation) C:\windows\system32\Windows.Media.MediaControl.dll
2016-03-01 19:11 - 2016-02-23 09:25 - 00534368 _____ (Microsoft Corporation) C:\windows\system32\Drivers\USBHUB3.SYS
2016-03-01 19:11 - 2016-02-23 09:20 - 01139712 _____ (Microsoft Corporation) C:\windows\system32\XblGameSave.dll
2016-03-01 19:11 - 2016-02-23 09:20 - 00238592 _____ (Microsoft Corporation) C:\windows\system32\Drivers\xboxgip.sys
2016-03-01 19:11 - 2016-02-23 09:19 - 00029696 _____ (Microsoft Corporation) C:\windows\system32\Drivers\xinputhid.sys
2016-03-01 19:11 - 2016-02-23 09:17 - 00649216 _____ (Microsoft Corporation) C:\windows\system32\ngcsvc.dll
2016-03-01 19:11 - 2016-02-23 09:12 - 00077824 _____ (Microsoft Corporation) C:\windows\system32\provpackageapidll.dll
2016-03-01 19:11 - 2016-02-23 09:10 - 00027648 _____ (Microsoft Corporation) C:\windows\system32\WiFiConfigSP.dll
2016-03-01 19:11 - 2016-02-23 09:07 - 00037376 _____ (Microsoft Corporation) C:\windows\system32\LaunchWinApp.exe
2016-03-01 19:11 - 2016-02-23 09:07 - 00026112 _____ (Microsoft Corporation) C:\windows\system32\wlansvcpal.dll
2016-03-01 19:11 - 2016-02-23 09:06 - 00129536 _____ (Microsoft Corporation) C:\windows\system32\flvprophandler.dll
2016-03-01 19:11 - 2016-02-23 09:01 - 00104960 _____ (Microsoft Corporation) C:\windows\system32\Drivers\rasl2tp.sys
2016-03-01 19:11 - 2016-02-23 09:00 - 00069632 _____ (Microsoft Corporation) C:\windows\system32\EnterpriseDesktopAppMgmtCSP.dll
2016-03-01 19:11 - 2016-02-23 09:00 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\wfdprov.dll
2016-03-01 19:11 - 2016-02-23 08:58 - 00069632 _____ (Microsoft Corporation) C:\windows\system32\wininetlui.dll
2016-03-01 19:11 - 2016-02-23 08:58 - 00052224 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2016-03-01 19:11 - 2016-02-23 08:58 - 00025088 _____ (Microsoft Corporation) C:\windows\system32\irmon.dll
2016-03-01 19:11 - 2016-02-23 08:57 - 00199168 _____ (Microsoft Corporation) C:\windows\system32\InstallAgent.exe
2016-03-01 19:11 - 2016-02-23 08:56 - 02186864 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3d11.dll
2016-03-01 19:11 - 2016-02-23 08:55 - 00114688 _____ (Microsoft Corporation) C:\windows\system32\Drivers\bridge.sys
2016-03-01 19:11 - 2016-02-23 08:53 - 00115712 _____ (Microsoft Corporation) C:\windows\system32\srpapi.dll
2016-03-01 19:11 - 2016-02-23 08:53 - 00099328 _____ (Microsoft Corporation) C:\windows\system32\ngckeyenum.dll
2016-03-01 19:11 - 2016-02-23 08:52 - 00087040 _____ (Microsoft Corporation) C:\windows\system32\MDMAppInstaller.exe
2016-03-01 19:11 - 2016-02-23 08:50 - 00159232 _____ (Microsoft Corporation) C:\windows\system32\DeviceCensus.exe
2016-03-01 19:11 - 2016-02-23 08:48 - 00086528 _____ (Microsoft Corporation) C:\windows\system32\AppCapture.dll
2016-03-01 19:11 - 2016-02-23 08:48 - 00041984 _____ (Microsoft Corporation) C:\windows\system32\TimeBrokerClient.dll
2016-03-01 19:11 - 2016-02-23 08:40 - 00074240 _____ (Microsoft Corporation) C:\windows\system32\SMSRouter.dll
2016-03-01 19:11 - 2016-02-23 08:39 - 00178176 _____ (Microsoft Corporation) C:\windows\system32\psmsrv.dll
2016-03-01 19:11 - 2016-02-23 08:38 - 00320000 _____ (Microsoft Corporation) C:\windows\system32\MSFlacDecoder.dll
2016-03-01 19:11 - 2016-02-23 08:38 - 00287712 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.Media.MediaControl.dll
2016-03-01 19:11 - 2016-02-23 08:37 - 00617984 _____ (Microsoft Corporation) C:\windows\system32\StorSvc.dll
2016-03-01 19:11 - 2016-02-23 08:37 - 00274944 _____ (Microsoft Corporation) C:\windows\system32\DisplayManager.dll
2016-03-01 19:11 - 2016-02-23 08:37 - 00204288 _____ (Microsoft Corporation) C:\windows\system32\NetSetupSvc.dll
2016-03-01 19:11 - 2016-02-23 08:36 - 00216576 _____ (Microsoft Corporation) C:\windows\system32\QuickActionsDataModel.dll
2016-03-01 19:11 - 2016-02-23 08:34 - 00305664 _____ (Microsoft Corporation) C:\windows\system32\wifiprofilessettinghandler.dll
2016-03-01 19:11 - 2016-02-23 08:34 - 00189952 _____ (Microsoft Corporation) C:\windows\system32\WiFiDisplay.dll
2016-03-01 19:11 - 2016-02-23 08:33 - 00558080 _____ (Microsoft Corporation) C:\windows\system32\MBMediaManager.dll
2016-03-01 19:11 - 2016-02-23 08:32 - 00414720 _____ (Microsoft Corporation) C:\windows\system32\bcastdvr.exe
2016-03-01 19:11 - 2016-02-23 08:31 - 00463360 _____ (Microsoft Corporation) C:\windows\system32\wlansec.dll
2016-03-01 19:11 - 2016-02-23 08:29 - 00591872 _____ (Microsoft Corporation) C:\windows\system32\SmsRouterSvc.dll
2016-03-01 19:11 - 2016-02-23 08:28 - 00275456 _____ (Microsoft Corporation) C:\windows\system32\AudioEndpointBuilder.dll
2016-03-01 19:11 - 2016-02-23 08:27 - 00307712 _____ (Microsoft Corporation) C:\windows\system32\usbmon.dll
2016-03-01 19:11 - 2016-02-23 08:26 - 00372224 _____ (Microsoft Corporation) C:\windows\system32\MDEServer.exe
2016-03-01 19:11 - 2016-02-23 08:23 - 00412672 _____ (Microsoft Corporation) C:\windows\system32\wlanmsm.dll
2016-03-01 19:11 - 2016-02-23 08:22 - 00567808 _____ (Microsoft Corporation) C:\windows\system32\MCRecvSrc.dll
2016-03-01 19:11 - 2016-02-23 08:20 - 00847360 _____ (Microsoft Corporation) C:\windows\system32\netlogon.dll
2016-03-01 19:11 - 2016-02-23 08:20 - 00606720 _____ (Microsoft Corporation) C:\windows\system32\wcmsvc.dll
2016-03-01 19:11 - 2016-02-23 08:20 - 00493568 _____ (Microsoft Corporation) C:\windows\system32\mfmkvsrcsnk.dll
2016-03-01 19:11 - 2016-02-23 08:20 - 00330240 _____ (Microsoft Corporation) C:\windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2016-03-01 19:11 - 2016-02-23 08:19 - 00948736 _____ (Microsoft Corporation) C:\windows\system32\XblAuthManager.dll
2016-03-01 19:11 - 2016-02-23 08:19 - 00517632 _____ (Microsoft Corporation) C:\windows\system32\winspool.drv
2016-03-01 19:11 - 2016-02-23 08:18 - 00557056 _____ (Microsoft Corporation) C:\windows\system32\PsmServiceExtHost.dll
2016-03-01 19:11 - 2016-02-23 08:14 - 00828928 _____ (Microsoft Corporation) C:\windows\system32\Windows.AccountsControl.dll
2016-03-01 19:11 - 2016-02-23 08:14 - 00029696 _____ (Microsoft Corporation) C:\windows\SysWOW64\LaunchWinApp.exe
2016-03-01 19:11 - 2016-02-23 08:12 - 00852480 _____ (Microsoft Corporation) C:\windows\system32\Windows.ApplicationModel.Store.dll
2016-03-01 19:11 - 2016-02-23 08:11 - 00587776 _____ (Microsoft Corporation) C:\windows\system32\bisrv.dll
2016-03-01 19:11 - 2016-02-23 08:10 - 00997376 _____ (Microsoft Corporation) C:\windows\system32\schedsvc.dll
2016-03-01 19:11 - 2016-02-23 08:10 - 00474624 _____ (Microsoft Corporation) C:\windows\system32\NetSetupShim.dll
2016-03-01 19:11 - 2016-02-23 08:09 - 01054208 _____ (Microsoft Corporation) C:\windows\system32\audiosrv.dll
2016-03-01 19:11 - 2016-02-23 08:09 - 00988160 _____ (Microsoft Corporation) C:\windows\system32\SharedStartModel.dll
2016-03-01 19:11 - 2016-02-23 08:09 - 00870400 _____ (Microsoft Corporation) C:\windows\system32\modernexecserver.dll
2016-03-01 19:11 - 2016-02-23 08:06 - 01213440 _____ (Microsoft Corporation) C:\windows\system32\wwansvc.dll
2016-03-01 19:11 - 2016-02-23 08:06 - 00065536 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininetlui.dll
2016-03-01 19:11 - 2016-02-23 08:06 - 00045568 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2016-03-01 19:11 - 2016-02-23 08:05 - 00161280 _____ (Microsoft Corporation) C:\windows\SysWOW64\InstallAgent.exe
2016-03-01 19:11 - 2016-02-23 08:04 - 01131520 _____ (Microsoft Corporation) C:\windows\system32\Windows.Media.Audio.dll
2016-03-01 19:11 - 2016-02-23 08:04 - 00673792 _____ (Microsoft Corporation) C:\windows\system32\Windows.UI.dll
2016-03-01 19:11 - 2016-02-23 08:04 - 00382464 _____ (Microsoft Corporation) C:\windows\system32\wuuhext.dll
2016-03-01 19:11 - 2016-02-23 08:02 - 01318912 _____ (Microsoft Corporation) C:\windows\system32\wifinetworkmanager.dll
2016-03-01 19:11 - 2016-02-23 08:02 - 00755712 _____ (Microsoft Corporation) C:\windows\system32\spoolsv.exe
2016-03-01 19:11 - 2016-02-23 08:02 - 00285696 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb10.sys
2016-03-01 19:11 - 2016-02-23 08:00 - 02624512 _____ (Microsoft Corporation) C:\windows\system32\InputService.dll
2016-03-01 19:11 - 2016-02-23 07:58 - 00345600 _____ (Microsoft Corporation) C:\windows\system32\TextInputFramework.dll
2016-03-01 19:11 - 2016-02-23 07:58 - 00175616 _____ (Microsoft Corporation) C:\windows\system32\Windows.UI.Core.TextInput.dll
2016-03-01 19:11 - 2016-02-23 07:58 - 00163840 _____ (Microsoft Corporation) C:\windows\system32\TimeBrokerServer.dll
2016-03-01 19:11 - 2016-02-23 07:58 - 00108544 _____ (Microsoft Corporation) C:\windows\system32\InputLocaleManager.dll
2016-03-01 19:11 - 2016-02-23 07:57 - 00031744 _____ (Microsoft Corporation) C:\windows\SysWOW64\TimeBrokerClient.dll
2016-03-01 19:11 - 2016-02-23 07:52 - 00456704 _____ (Microsoft Corporation) C:\windows\system32\ipnathlp.dll
2016-03-01 19:11 - 2016-02-23 07:50 - 00266752 _____ (Microsoft Corporation) C:\windows\SysWOW64\MSFlacDecoder.dll
2016-03-01 19:11 - 2016-02-23 07:49 - 00200704 _____ (Microsoft Corporation) C:\windows\SysWOW64\DisplayManager.dll
2016-03-01 19:11 - 2016-02-23 07:48 - 00838144 _____ (Microsoft Corporation) C:\windows\system32\uDWM.dll
2016-03-01 19:11 - 2016-02-23 07:47 - 00157184 _____ (Microsoft Corporation) C:\windows\SysWOW64\WiFiDisplay.dll
2016-03-01 19:11 - 2016-02-23 07:38 - 00480256 _____ (Microsoft Corporation) C:\windows\SysWOW64\MCRecvSrc.dll
2016-03-01 19:11 - 2016-02-23 07:37 - 01118208 _____ (Microsoft Corporation) C:\windows\system32\localspl.dll
2016-03-01 19:11 - 2016-02-23 07:37 - 00613376 _____ (Microsoft Corporation) C:\windows\system32\SettingSync.dll
2016-03-01 19:11 - 2016-02-23 07:36 - 00713728 _____ (Microsoft Corporation) C:\windows\SysWOW64\netlogon.dll
2016-03-01 19:11 - 2016-02-23 07:36 - 00379392 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfmkvsrcsnk.dll
2016-03-01 19:11 - 2016-02-23 07:36 - 00250880 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2016-03-01 19:11 - 2016-02-23 07:35 - 00400896 _____ (Microsoft Corporation) C:\windows\SysWOW64\winspool.drv
2016-03-01 19:11 - 2016-02-23 07:31 - 00585216 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.AccountsControl.dll
2016-03-01 19:11 - 2016-02-23 07:30 - 01731584 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2016-03-01 19:11 - 2016-02-23 07:30 - 00646656 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.ApplicationModel.Store.dll
2016-03-01 19:11 - 2016-02-23 07:29 - 00349696 _____ (Microsoft Corporation) C:\windows\SysWOW64\NetSetupShim.dll
2016-03-01 19:11 - 2016-02-23 07:28 - 00555520 _____ (Microsoft Corporation) C:\windows\system32\SyncController.dll
2016-03-01 19:11 - 2016-02-23 07:28 - 00256512 _____ (Microsoft Corporation) C:\windows\system32\accountaccessor.dll
2016-03-01 19:11 - 2016-02-23 07:24 - 04827136 _____ (Microsoft Corporation) C:\windows\system32\ExplorerFrame.dll
2016-03-01 19:11 - 2016-02-23 07:24 - 02755584 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2016-03-01 19:11 - 2016-02-23 07:24 - 01105920 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.Media.Audio.dll
2016-03-01 19:11 - 2016-02-23 07:24 - 00489984 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.UI.dll
2016-03-01 19:11 - 2016-02-23 07:22 - 01944576 _____ (Microsoft Corporation) C:\windows\SysWOW64\InputService.dll
2016-03-01 19:11 - 2016-02-23 07:21 - 00245760 _____ (Microsoft Corporation) C:\windows\SysWOW64\TextInputFramework.dll
2016-03-01 19:11 - 2016-02-23 07:21 - 00133632 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.UI.Core.TextInput.dll
2016-03-01 19:11 - 2016-02-23 07:20 - 00083456 _____ (Microsoft Corporation) C:\windows\SysWOW64\InputLocaleManager.dll
2016-03-01 19:11 - 2016-02-23 07:17 - 02635264 _____ (Microsoft Corporation) C:\windows\system32\Windows.UI.Logon.dll
2016-03-01 19:11 - 2016-02-23 07:14 - 00990720 _____ (Microsoft Corporation) C:\windows\system32\SettingSyncCore.dll
2016-03-01 19:11 - 2016-02-23 07:11 - 01390080 _____ (Microsoft Corporation) C:\windows\system32\Windows.UI.Shell.dll
2016-03-01 19:11 - 2016-02-23 07:05 - 00503296 _____ (Microsoft Corporation) C:\windows\SysWOW64\SettingSync.dll
2016-03-01 19:11 - 2016-02-23 07:01 - 02295808 _____ (Microsoft Corporation) C:\windows\system32\wlansvc.dll
2016-03-01 19:11 - 2016-02-23 06:59 - 01500672 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2016-03-01 19:11 - 2016-02-23 06:58 - 00450560 _____ (Microsoft Corporation) C:\windows\SysWOW64\SyncController.dll
2016-03-01 19:11 - 2016-02-23 06:56 - 04412928 _____ (Microsoft Corporation) C:\windows\SysWOW64\ExplorerFrame.dll
2016-03-01 19:11 - 2016-02-23 06:55 - 04894208 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2016-03-01 19:11 - 2016-02-23 06:55 - 02229760 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2016-03-01 19:11 - 2016-02-23 06:53 - 01799168 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.UI.Logon.dll
2016-03-01 19:11 - 2016-02-23 06:52 - 11545600 _____ (Microsoft Corporation) C:\windows\system32\twinui.dll
2016-03-01 19:11 - 2016-02-23 06:51 - 00754176 _____ (Microsoft Corporation) C:\windows\SysWOW64\SettingSyncCore.dll
2016-03-01 19:11 - 2016-02-23 06:50 - 09919488 _____ (Microsoft Corporation) C:\windows\SysWOW64\twinui.dll
2016-03-01 19:11 - 2016-02-23 06:42 - 03425792 _____ (Microsoft Corporation) C:\windows\system32\Windows.Media.dll
2016-03-01 19:11 - 2016-02-23 06:41 - 02912256 _____ (Microsoft Corporation) C:\windows\system32\CertEnroll.dll
2016-03-01 19:11 - 2016-02-23 06:39 - 13382656 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2016-03-01 19:11 - 2016-02-23 06:39 - 02581504 _____ (Microsoft Corporation) C:\windows\system32\MFMediaEngine.dll
2016-03-01 19:11 - 2016-02-23 06:36 - 12125696 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2016-03-01 19:11 - 2016-02-23 06:36 - 03666432 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2016-03-01 19:11 - 2016-02-23 06:35 - 07533568 _____ (Microsoft Corporation) C:\windows\system32\mstscax.dll
2016-03-01 19:11 - 2016-02-23 06:33 - 02604032 _____ (Microsoft Corporation) C:\windows\SysWOW64\CertEnroll.dll
2016-03-01 19:11 - 2016-02-23 06:32 - 02793472 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.Media.dll
2016-03-01 19:11 - 2016-02-23 06:30 - 02061312 _____ (Microsoft Corporation) C:\windows\SysWOW64\MFMediaEngine.dll
2016-03-01 19:11 - 2016-02-23 06:28 - 06740992 _____ (Microsoft Corporation) C:\windows\SysWOW64\mstscax.dll
2016-03-01 19:11 - 2016-02-09 04:28 - 00277856 _____ (Microsoft Corporation) C:\windows\system32\Drivers\sdbus.sys
2016-03-01 19:11 - 2016-02-09 04:13 - 00185184 _____ (Microsoft Corporation) C:\windows\system32\Drivers\dumpsd.sys
2016-03-01 19:11 - 2016-02-09 03:24 - 00641536 _____ (Microsoft Corporation) C:\windows\system32\enterprisecsps.dll
2016-03-01 19:11 - 2016-02-09 03:18 - 00297472 _____ (Microsoft Corporation) C:\windows\system32\thumbcache.dll
2016-03-01 19:11 - 2016-02-09 03:18 - 00237056 _____ (Microsoft Corporation) C:\windows\SysWOW64\thumbcache.dll
2016-03-01 19:11 - 2016-02-09 03:07 - 01626624 _____ (Microsoft Corporation) C:\windows\SysWOW64\dwmcore.dll
2016-03-01 19:11 - 2016-02-09 03:07 - 00086016 _____ (Microsoft Corporation) C:\windows\system32\DeviceEnroller.exe
2016-03-01 19:11 - 2016-02-09 03:04 - 01946624 _____ (Microsoft Corporation) C:\windows\system32\dwmcore.dll
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2016-03-26 13:29 - 2016-01-01 22:51 - 00000000 ____D C:\Users\willi\AppData\Roaming\Curse Client
2016-03-26 13:29 - 2016-01-01 22:38 - 00000000 ____D C:\Users\willi\AppData\Local\Deployment
2016-03-26 13:29 - 2015-12-27 16:33 - 00000000 ____D C:\Users\willi\AppData\Roaming\Skype
2016-03-26 13:28 - 2015-12-25 09:11 - 00000924 _____ C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-03-26 13:28 - 2015-12-14 15:14 - 00000006 ____H C:\windows\Tasks\SA.DAT
2016-03-26 13:27 - 2015-10-30 06:28 - 00524288 ___SH C:\windows\system32\config\BBI
2016-03-26 13:20 - 2015-12-25 09:11 - 00000928 _____ C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-03-26 13:19 - 2015-12-14 15:19 - 00881036 _____ C:\windows\system32\PerfStringBackup.INI
2016-03-26 13:19 - 2015-10-30 07:21 - 00000000 ____D C:\windows\INF
2016-03-26 13:08 - 2015-12-15 11:54 - 00000000 ____D C:\windows\system32\temp
2016-03-26 07:49 - 2015-12-25 19:36 - 00000000 ____D C:\Users\willi\.oracle_jre_usage
2016-03-26 07:48 - 2016-01-31 02:01 - 00000000 ____D C:\Users\willi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2016-03-26 07:48 - 2016-01-31 02:01 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2016-03-26 07:48 - 2016-01-31 02:01 - 00000000 ____D C:\Program Files\WinRAR
2016-03-26 07:45 - 2015-12-25 19:36 - 00004166 _____ C:\windows\System32\Tasks\User_Feed_Synchronization-{1D84A35C-070A-44DA-9AB2-285C5EA815E7}
2016-03-26 07:43 - 2015-10-30 07:24 - 00000000 ____D C:\windows\system32\NDF
2016-03-25 22:26 - 2015-12-25 09:09 - 00000000 ___RD C:\Users\willi\OneDrive
2016-03-25 21:36 - 2016-01-24 23:17 - 00001001 _____ C:\Users\Public\Desktop\Guild Wars 2.lnk
2016-03-25 21:36 - 2016-01-21 08:27 - 00001579 _____ C:\Users\Public\Desktop\League of Legends.lnk
2016-03-25 21:36 - 2016-01-01 22:51 - 00001093 _____ C:\Users\willi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Curse.lnk
2016-03-25 21:36 - 2016-01-01 22:51 - 00001087 _____ C:\Users\willi\Desktop\Curse.lnk
2016-03-25 21:36 - 2015-12-29 18:13 - 00000588 _____ C:\Users\willi\Desktop\Speccy.lnk
2016-03-25 21:36 - 2015-12-28 22:26 - 00000826 _____ C:\Users\Public\Desktop\Battle.net.lnk
2016-03-25 21:36 - 2015-12-27 16:33 - 00002634 _____ C:\Users\Public\Desktop\Skype.lnk
2016-03-25 21:36 - 2015-12-25 20:19 - 00001051 _____ C:\Users\Public\Desktop\Gyazo.lnk
2016-03-25 21:36 - 2015-12-25 18:02 - 00001286 _____ C:\Users\willi\Desktop\TeamSpeak 3 Client.lnk
2016-03-25 21:36 - 2015-12-25 09:12 - 00002338 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-03-25 21:36 - 2015-12-25 09:09 - 00002367 _____ C:\Users\willi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2016-03-25 21:36 - 2015-12-15 11:54 - 00001273 _____ C:\Users\Public\Desktop\3DMark.lnk
2016-03-25 21:35 - 2015-10-30 09:02 - 00000000 ____D C:\windows\DigitalLocker
2016-03-25 21:04 - 2015-10-30 07:24 - 00000000 ___HD C:\Program Files\WindowsApps
2016-03-25 21:04 - 2015-10-30 07:24 - 00000000 ____D C:\windows\AppReadiness
2016-03-25 20:57 - 2015-12-25 18:03 - 00000000 ____D C:\Users\willi\AppData\Roaming\TS3Client
2016-03-25 20:57 - 2015-12-14 15:24 - 00000000 __RHD C:\Users\Public\AccountPictures
2016-03-23 08:48 - 2015-12-25 18:56 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2016-03-23 08:24 - 2015-12-27 16:33 - 00000000 ___RD C:\Program Files (x86)\Skype
2016-03-23 08:24 - 2015-12-27 16:33 - 00000000 ____D C:\ProgramData\Skype
2016-03-22 23:09 - 2015-12-29 18:46 - 00000000 ____D C:\Users\willi\AppData\Local\CrashDumps
2016-03-22 20:31 - 2015-10-30 07:11 - 00000000 ____D C:\windows\CbsTemp
2016-03-22 00:19 - 2015-12-28 22:26 - 00000000 ____D C:\Users\willi\AppData\Local\Battle.net
2016-03-13 20:44 - 2015-12-28 22:26 - 00000000 ____D C:\Users\willi\AppData\Roaming\Battle.net
2016-03-13 20:44 - 2015-12-28 22:23 - 00000000 ____D C:\ProgramData\Battle.net
2016-03-12 19:02 - 2015-12-25 09:06 - 00000000 ____D C:\Users\willi
2016-03-11 20:47 - 2015-12-25 21:08 - 00000000 ____D C:\Users\willi\Documents\My Games
2016-03-09 17:46 - 2015-12-14 15:09 - 00348872 _____ C:\windows\system32\FNTCACHE.DAT
2016-03-09 00:30 - 2015-10-30 07:24 - 00000000 ____D C:\Program Files\Windows Portable Devices
2016-03-09 00:30 - 2015-10-30 07:24 - 00000000 ____D C:\Program Files\Windows Multimedia Platform
2016-03-09 00:30 - 2015-10-30 07:24 - 00000000 ____D C:\Program Files (x86)\Windows Portable Devices
2016-03-09 00:30 - 2015-10-30 07:24 - 00000000 ____D C:\Program Files (x86)\Windows Multimedia Platform
2016-03-08 18:52 - 2015-12-15 14:07 - 00000000 ____D C:\windows\system32\MRT
2016-03-08 18:50 - 2015-12-15 14:07 - 143659408 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2016-03-08 07:12 - 2015-10-30 07:26 - 00829944 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2016-03-08 07:12 - 2015-10-30 07:26 - 00176632 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2016-03-06 17:00 - 2016-02-22 20:42 - 00000000 ____D C:\Users\willi\AppData\Local\Frontier_Developments
2016-03-06 10:59 - 2015-12-25 09:43 - 00000000 ____D C:\Users\willi\AppData\Roaming\.minecraft
2016-03-05 19:14 - 2015-12-25 09:11 - 00003986 _____ C:\windows\System32\Tasks\GoogleUpdateTaskMachineUA
2016-03-05 19:14 - 2015-12-25 09:11 - 00003754 _____ C:\windows\System32\Tasks\GoogleUpdateTaskMachineCore
2016-03-02 17:41 - 2015-10-30 07:24 - 00000000 ____D C:\windows\rescache
2016-03-02 08:00 - 2015-12-25 20:19 - 00003544 _____ C:\windows\System32\Tasks\GyazoUpdateTaskMachineDaily
2016-03-02 08:00 - 2015-12-25 20:19 - 00003408 _____ C:\windows\System32\Tasks\GyazoUpdateTaskMachine
2016-03-02 08:00 - 2015-12-25 20:19 - 00000000 ____D C:\Program Files (x86)\Gyazo
2016-03-01 20:45 - 2015-12-15 11:51 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2016-03-01 20:45 - 2015-12-15 11:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2016-03-01 20:45 - 2015-12-15 11:49 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2016-03-01 20:16 - 2015-10-30 09:07 - 00000000 ____D C:\Program Files\Windows Journal
2016-03-01 20:16 - 2015-10-30 07:24 - 00000000 __RSD C:\windows\Media
2016-03-01 20:16 - 2015-10-30 07:24 - 00000000 ___RD C:\windows\PurchaseDialog
2016-03-01 20:16 - 2015-10-30 07:24 - 00000000 ____D C:\windows\system32\WinBioPlugIns
2016-03-01 20:16 - 2015-10-30 07:24 - 00000000 ____D C:\windows\system32\SystemResetPlatform
2016-03-01 20:16 - 2015-10-30 07:24 - 00000000 ____D C:\windows\system32\appraiser
2016-03-01 20:16 - 2015-10-30 07:24 - 00000000 ____D C:\windows\bcastdvr
2016-03-01 20:16 - 2015-10-30 06:28 - 00000000 ____D C:\windows\SysWOW64\Dism
2016-03-01 20:16 - 2015-10-30 06:28 - 00000000 ____D C:\windows\system32\Dism
2016-03-01 20:15 - 2015-12-15 11:48 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2016-03-01 20:15 - 2015-10-30 07:24 - 00000000 ____D C:\windows\Help
2016-03-01 20:14 - 2015-12-15 11:49 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2016-03-01 19:29 - 2015-12-25 09:07 - 00000000 ____D C:\Users\willi\AppData\Local\NVIDIA Corporation
 
==================== Files in the root of some directories =======
 
2016-03-23 08:57 - 2016-03-23 08:57 - 6493696 _____ () C:\Users\willi\AppData\Roaming\agent.dat
2016-03-23 08:57 - 2016-03-23 08:57 - 0127488 _____ () C:\Users\willi\AppData\Roaming\Installer.dat
2016-03-23 08:57 - 2016-03-23 08:57 - 0072707 _____ () C:\Users\willi\AppData\Roaming\Jaytom.tst
2016-03-23 08:57 - 2016-03-23 08:57 - 0018432 _____ () C:\Users\willi\AppData\Roaming\Main.dat
2016-03-23 08:57 - 2016-03-23 08:57 - 1622132 _____ () C:\Users\willi\AppData\Roaming\Zimlux.tst
2015-12-15 11:52 - 2015-12-15 11:52 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
 
Some files in TEMP:
====================
C:\Users\willi\AppData\Local\Temp\sqlite3.dll
 
 
==================== Bamital & volsnap =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\windows\system32\winlogon.exe => File is digitally signed
C:\windows\system32\wininit.exe => File is digitally signed
C:\windows\explorer.exe => File is digitally signed
C:\windows\SysWOW64\explorer.exe => File is digitally signed
C:\windows\system32\svchost.exe => File is digitally signed
C:\windows\SysWOW64\svchost.exe => File is digitally signed
C:\windows\system32\services.exe => File is digitally signed
C:\windows\system32\User32.dll => File is digitally signed
C:\windows\SysWOW64\User32.dll => File is digitally signed
C:\windows\system32\userinit.exe => File is digitally signed
C:\windows\SysWOW64\userinit.exe => File is digitally signed
C:\windows\system32\rpcss.dll => File is digitally signed
C:\windows\system32\dnsapi.dll => File is digitally signed
C:\windows\SysWOW64\dnsapi.dll
[2015-10-30 07:18] - [2015-10-30 07:18] - 0535088 ____A () D41D8CD98F00B204E9800998ECF8427E
 
C:\windows\SysWOW64\dnsapi.dll => no Company Name <===== ATTENTION
 
C:\windows\system32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2016-03-23 15:23
 
==================== End of FRST.txt ============================

Additional scan result of Farbar Recovery Scan Tool (x64) Version:05-03-2016 01
Ran by willi (2016-03-26 13:31:53)
Running from C:\Users\willi\Desktop
Windows 10 Home Version 1511 (X64) (2015-12-25 09:05:47)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-3667704814-1699542734-850788743-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-3667704814-1699542734-850788743-503 - Limited - Disabled)
Guest (S-1-5-21-3667704814-1699542734-850788743-501 - Limited - Disabled)
willi (S-1-5-21-3667704814-1699542734-850788743-1002 - Administrator - Enabled) => C:\Users\willi
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
3DMark (HKLM-x32\...\{12d6e0d7-21d5-4755-9da2-70352c6f7558}) (Version: 1.5.915.0 - Futuremark)
3DMark (Version: 1.5.915.0 - Futuremark) Hidden
Asmedia ASM106x SATA Host Controller Driver (HKLM-x32\...\{61942EF5-2CD8-47D4-869C-2E9A8BB085F1}) (Version: 2.0.9.0001 - Asmedia Technology)
Avast Free Antivirus (HKLM-x32\...\Avast) (Version: 11.1.2253 - AVAST Software)
Awesomenauts (HKLM-x32\...\Steam App 204300) (Version:  - Ronimo Games)
Battle.net (HKLM-x32\...\Battle.net) (Version:  - Blizzard Entertainment)
Block N Load (HKLM-x32\...\Steam App 299360) (Version:  - Jagex)
BurnInTest v8.0 Pro (HKLM\...\BurnInTest_is1) (Version: 8.0.1041.0 - Passmark Software)
Counter-Strike (HKLM\...\Steam App 10) (Version:  - Valve)
Counter-Strike: Condition Zero (HKLM\...\Steam App 80) (Version:  - Valve)
Counter-Strike: Global Offensive (HKLM-x32\...\Steam App 730) (Version:  - Valve)
Counter-Strike: Source (HKLM-x32\...\Steam App 240) (Version:  - Valve)
Curse (HKLM-x32\...\{DEE70742-F4E9-44CA-B2B9-EE95DCF37295}) (Version: 6.0.0.0 - Curse)
Curse Client (HKU\S-1-5-21-3667704814-1699542734-850788743-1002\...\101a9f93b8f0bb6f) (Version: 5.1.1.844 - Curse)
Day of Defeat: Source (HKLM\...\Steam App 300) (Version:  - Valve)
Dungeon Defenders II (HKLM-x32\...\Steam App 236110) (Version:  - Trendy Entertainment)
Elite Dangerous (HKLM-x32\...\Steam App 359320) (Version:  - Frontier Developments)
Futuremark SystemInfo (HKLM-x32\...\{70690D9E-3D00-47D6-9CE9-BC3B6F900447}) (Version: 4.41.563.0 - Futuremark)
Garry's Mod (HKLM-x32\...\Steam App 4000) (Version:  - Facepunch Studios)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 49.0.2623.87 - Google Inc.)
Google Update Helper (x32 Version: 1.3.29.5 - Google Inc.) Hidden
Grand Theft Auto V (HKLM-x32\...\Steam App 271590) (Version:  - Rockstar North)
Guild Wars 2 (HKLM-x32\...\Guild Wars 2) (Version:  - NCsoft Corporation, Ltd.)
Guns of Icarus Online (HKLM-x32\...\Steam App 209080) (Version:  - Muse Games)
Gyazo 3.2.1 (HKLM-x32\...\{6DB8C365-E719-4BA5-9594-10DFC244D3FD}_is1) (Version:  - Nota Inc.)
Half-Life (HKLM-x32\...\Steam App 70) (Version:  - Valve)
Half-Life 2 (HKLM-x32\...\Steam App 220) (Version:  - Valve)
Half-Life 2: Episode One (HKLM-x32\...\Steam App 380) (Version:  - Valve)
Half-Life 2: Episode Two (HKLM-x32\...\Steam App 420) (Version:  - Valve)
Half-Life 2: Lost Coast (HKLM\...\Steam App 340) (Version:  - Valve)
Half-Life: Source (HKLM\...\Steam App 280) (Version:  - Valve)
Hearthstone (HKLM-x32\...\Hearthstone) (Version:  - Blizzard Entertainment)
Intel® Chipset Device Software (x32 Version: 10.0.27 - Intel® Corporation) Hidden
Intel® Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 10.0.1.1000 - Intel Corporation)
Intel® Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 14.5.0.1081 - Intel Corporation)
Intel® Update Manager (HKLM-x32\...\{B991A1BC-DE0F-41B3-9037-B2F948F706EC}) (Version: 3.1.1228 - Intel Corporation)
Java 8 Update 73 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86418073F0}) (Version: 8.0.730.2 - Oracle Corporation)
Java 8 Update 74 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86418074F0}) (Version: 8.0.740.2 - Oracle Corporation)
Kerbal Space Program (HKLM-x32\...\Steam App 220200) (Version:  - Squad)
Killing Floor (HKLM-x32\...\Steam App 1250) (Version:  - Tripwire Interactive)
League of Legends (HKLM-x32\...\League of Legends 3.0.1) (Version: 3.0.1 - Riot Games)
League of Legends (x32 Version: 3.0.1 - Riot Games) Hidden
Left 4 Dead (HKLM-x32\...\Steam App 500) (Version:  - Valve)
Left 4 Dead 2 (HKLM\...\Steam App 550) (Version:  - Valve)
Mad Riders (HKLM-x32\...\Steam App 208860) (Version:  - Techland)
Malwarebytes Anti-Malware version 2.2.1.1043 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes)
Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation)
Microsoft Office Home and Student 2010 (HKLM-x32\...\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Minecraft (HKLM-x32\...\{1C16BCA3-EBC1-49F6-8623-8FBFB9CCC872}) (Version: 1.0.3.0 - Mojang)
NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version:  - )
NVIDIA GeForce Experience 2.10.2.40 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.10.2.40 - NVIDIA Corporation)
NVIDIA Graphics Driver 362.00 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 362.00 - NVIDIA Corporation)
NVIDIA nTune (HKLM-x32\...\InstallShield_{7C7F30F4-94E7-4AA8-8941-90C4A80C68BF}) (Version: 1.00.0000 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.15.0428 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.15.0428 - NVIDIA Corporation)
PerformanceTest v8.0 (HKLM\...\PerformanceTest 8_is1) (Version: 8.0.1047.0 - Passmark Software)
Portal 2 (HKLM-x32\...\Steam App 620) (Version:  - Valve)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7541 - Realtek Semiconductor Corp.)
Rocket League (HKLM-x32\...\Steam App 252950) (Version:  - Psyonix)
Rockstar Games Social Club (HKLM-x32\...\Rockstar Games Social Club) (Version: 1.1.7.2 - Rockstar Games)
RollerCoaster Tycoon 3: Platinum! (HKLM-x32\...\Steam App 2700) (Version:  - Frontier)
SafeZone Stable 1.48.2066.44 (x32 Version: 1.48.2066.44 - Avast Software) Hidden
Saints Row: The Third (HKLM-x32\...\Steam App 55230) (Version:  - Volition)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version:  - Microsoft)
SHIELD Streaming (Version: 5.1.0270 - NVIDIA Corporation) Hidden
SHIELD Wireless Controller Driver (Version: 2.10.2.40 - NVIDIA Corporation) Hidden
Sid Meier's Civilization V (HKLM-x32\...\Steam App 8930) (Version:  - 2K Games, Inc.)
Skype™ 7.21 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.21.100 - Skype Technologies S.A.)
SNOW (HKLM\...\Steam App 244930) (Version:  - Poppermost Productions)
Speccy (HKLM\...\Speccy) (Version: 1.29 - Piriform)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
Tabletop Simulator (HKLM\...\Steam App 286160) (Version:  - Berserk Games)
Team Fortress 2 (HKLM-x32\...\Steam App 440) (Version:  - Valve)
TeamSpeak 3 Client (HKU\S-1-5-21-3667704814-1699542734-850788743-1002\...\TeamSpeak 3 Client) (Version: 3.0.18 - TeamSpeak Systems GmbH)
Terraria (HKLM-x32\...\Steam App 105600) (Version:  - Re-Logic)
The Sims™ 3 (HKLM-x32\...\Steam App 47890) (Version:  - The Sims Studio)
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.2 - VideoLAN)
WinRAR 5.31 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.31.0 - win.rar GmbH)
Worms Revolution (HKLM-x32\...\Steam App 200170) (Version:  - Team17 Digital Ltd)
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-3667704814-1699542734-850788743-1002_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\willi\AppData\Local\Microsoft\OneDrive\17.3.6302.0225\FileCoAuth.exe (Microsoft Corporation)
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {1940DA92-C768-4AB4-B53B-71D302B85408} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-03-05] (Google Inc.)
Task: {1E3ACD2E-602B-4DB0-987F-ECF96F23DF13} - System32\Tasks\avast! Windows 10 Start Menu helper => c:\program files\avast software\avast\asww10mon.exe [2016-03-25] (AVAST Software)
Task: {3827EA74-9908-4874-8BC4-CC4FF97F4725} - System32\Tasks\SafeZone scheduled Autoupdate 1458977815 => C:\Program Files\AVAST Software\SZBrowser\launcher.exe [2016-02-01] (Avast Software)
Task: {3EB44B1E-7494-4E9F-897E-BF835AE2434A} - System32\Tasks\Bimui => C:\PROGRA~1\BAOMKY~1\Boeehir.bat
Task: {4D63DB2A-839D-49AB-8542-78A26ACB5BAC} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473-Logon => C:\Program Files (x86)\Intel\Intel® Update Manager\bin\iumsvc.exe [2015-09-25] (Intel Corporation)
Task: {83C15578-2BAD-4E9A-9ACE-5185B3A9E5C6} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 => C:\Program Files (x86)\Intel\Intel® Update Manager\bin\iumsvc.exe [2015-09-25] (Intel Corporation)
Task: {8A8CB5AD-622B-4CE9-818C-606E72B334CE} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2016-03-25] (AVAST Software)
Task: {A7D1B83E-CCE1-41A3-93CA-563B9B0A7282} - System32\Tasks\GyazoUpdateTaskMachine => C:\Program Files (x86)\Gyazo\GyazoUpdate.exe [2016-02-17] ()
Task: {B197630C-FE6B-4346-8B0D-AA722B4E044B} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\windows\system32\MRT.exe [2016-03-08] (Microsoft Corporation)
Task: {BA3BFDA4-E247-41A2-A95D-39254FA36F0F} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-03-05] (Google Inc.)
Task: {CE84A1E1-5F0A-4497-859E-42296F9EDA8C} - System32\Tasks\GyazoUpdateTaskMachineDaily => C:\Program Files (x86)\Gyazo\GyazoUpdate.exe [2016-02-17] ()
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
 
==================== Shortcuts =============================
 
(The entries could be listed to be restored or removed.)
 
==================== Loaded Modules (Whitelisted) ==============
 
2015-10-30 07:17 - 2015-10-30 07:17 - 00028672 _____ () C:\windows\SYSTEM32\efsext.dll
2015-10-30 07:18 - 2015-10-30 07:18 - 00185856 _____ () C:\windows\SYSTEM32\ism32k.dll
2016-03-01 20:15 - 2016-02-23 20:28 - 00134712 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2015-12-15 11:54 - 2013-07-04 03:32 - 00936728 _____ () C:\Program Files (x86)\ASUS\AXSP\1.02.00\atkexComSvc.exe
2016-03-01 19:47 - 2016-02-17 06:56 - 01416064 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\MessageBus.dll
2016-03-01 19:47 - 2016-02-17 06:56 - 00299392 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamBase.dll
2016-03-01 19:47 - 2016-02-17 06:56 - 03613056 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\Poco.dll
2016-03-01 19:11 - 2016-02-23 11:27 - 02654872 _____ () C:\windows\system32\CoreUIComponents.dll
2016-03-01 19:11 - 2016-02-23 11:27 - 02654872 _____ () C:\windows\System32\CoreUIComponents.dll
2016-01-21 19:24 - 2016-01-21 19:25 - 00144384 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe
2015-12-26 09:43 - 2015-12-07 04:14 - 00093696 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\Windows.UI.Shell.SharedUtilities.dll
2016-03-01 19:11 - 2016-02-23 08:36 - 00472064 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll
2016-01-13 20:54 - 2016-01-05 01:29 - 07992832 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2016-01-13 20:54 - 2016-01-05 01:23 - 00591360 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2016-01-28 17:28 - 2016-01-16 05:10 - 02483200 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2016-01-28 17:28 - 2016-01-16 05:13 - 04089856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2015-12-14 16:01 - 2015-12-10 14:12 - 01197568 _____ () C:\Program Files\Scan 3XS\menu.exe
2016-01-01 22:39 - 2016-01-01 22:39 - 00016384 _____ () C:\Users\willi\AppData\Local\Apps\2.0\GNJTZPBV.KQ1\P211G6GV.WC4\curs..tion_9e9e83ddf3ed3ead_0005.0001_fb8944c2684f5b6c\Curse.CurseClient.WowDb.dll
2016-01-01 22:39 - 2016-01-01 22:39 - 00035840 _____ () C:\Users\willi\AppData\Local\Apps\2.0\GNJTZPBV.KQ1\P211G6GV.WC4\curs..tion_9e9e83ddf3ed3ead_0005.0001_fb8944c2684f5b6c\Curse.Advertising.dll
2016-03-25 22:24 - 2016-03-25 22:24 - 00258896 _____ () C:\Program Files\AVAST Software\Avast\avastnm.exe
2016-03-25 22:23 - 2016-03-25 22:23 - 00113496 _____ () C:\Program Files\AVAST Software\Avast\log.dll
2016-03-25 22:23 - 2016-03-25 22:23 - 00133768 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
2016-03-25 22:25 - 2016-03-25 22:25 - 02857472 _____ () C:\Program Files\AVAST Software\Avast\defs\16032501\algo.dll
2016-03-25 22:23 - 2016-03-25 22:23 - 00480760 _____ () C:\Program Files\AVAST Software\Avast\ffl2.dll
2015-12-15 11:54 - 2016-03-26 13:28 - 00039720 _____ () C:\Program Files (x86)\ASUS\AXSP\1.02.00\PEbiosinterface32.dll
2015-12-15 11:54 - 2013-07-04 03:32 - 00104448 _____ () C:\Program Files (x86)\ASUS\AXSP\1.02.00\ATKEX.dll
2016-01-21 19:24 - 2016-01-21 19:25 - 00141312 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeBackgroundTasks.dll
2016-01-21 19:24 - 2016-01-21 19:25 - 22330368 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkyWrap.dll
2016-03-01 19:47 - 2016-02-17 07:02 - 00020352 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll
2016-03-25 22:23 - 2016-03-25 22:23 - 40539648 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2016-03-20 08:39 - 2016-03-20 08:38 - 01690504 _____ () C:\Users\willi\AppData\Roaming\Curse Client\Bin\Electron\libglesv2.dll
2016-03-20 08:39 - 2016-03-20 08:38 - 00018312 _____ () C:\Users\willi\AppData\Roaming\Curse Client\Bin\Electron\libegl.dll
2016-03-26 07:36 - 2016-02-01 09:50 - 62337016 _____ () C:\Program Files\AVAST Software\SZBrowser\1.48.2066.44\SZBrowser.dll
2016-03-26 07:36 - 2016-02-01 09:50 - 02074104 _____ () C:\Program Files\AVAST Software\SZBrowser\1.48.2066.44\libglesv2.dll
2016-03-26 07:36 - 2016-02-01 09:50 - 00081400 _____ () C:\Program Files\AVAST Software\SZBrowser\1.48.2066.44\libegl.dll
2014-04-03 16:48 - 2014-04-03 16:48 - 01241560 _____ () C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\ACE.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
 
==================== EXE Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
 
==================== Hosts content: ===============================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2015-10-30 07:24 - 2016-03-26 13:08 - 00000027 ____A C:\windows\system32\Drivers\etc\hosts
 
127.0.0.1       localhost
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-3667704814-1699542734-850788743-1002\Control Panel\Desktop\\Wallpaper -> C:\Users\willi\AppData\Local\Microsoft\Windows\Themes\RoamedThemeFiles\DesktopBackground\natsu-dragneel-fairy-tail-26497-1920x1080.jpg
DNS Servers: 192.168.0.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
(Currently there is no automatic fix for this section.)
 
HKLM\...\StartupApproved\Run: => "SpaceSoundPro"
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [{F69E7180-B24D-4B19-8DA3-3AB427FBCB35}] => (Allow) F:\programs\steam\Steam.exe
FirewallRules: [{AF3038F3-CE6E-45FC-9492-464CAD57EA0D}] => (Allow) F:\programs\steam\Steam.exe
FirewallRules: [{330B635F-FA43-4866-8DBE-C322BD951BB4}] => (Allow) F:\programs\steam\bin\steamwebhelper.exe
FirewallRules: [{796089DA-786C-4B83-A2FA-3A578E5D0D68}] => (Allow) F:\programs\steam\bin\steamwebhelper.exe
 
==================== Restore Points =========================
 
08-03-2016 18:46:02 Windows Update
12-03-2016 18:52:20 Windows Update
16-03-2016 15:49:40 Windows Update
19-03-2016 16:14:58 Windows Update
22-03-2016 18:42:08 Windows Update
25-03-2016 21:10:17 Windows Update
26-03-2016 13:12:31 JRT Pre-Junkware Removal
26-03-2016 13:15:35 JRT Pre-Junkware Removal
26-03-2016 13:18:53 JRT Pre-Junkware Removal
 
==================== Faulty Device Manager Devices =============
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (03/26/2016 01:30:34 PM) (Source: IntelDalJhi) (EventID: 11) (User: )
Description: Intel® Dynamic Application Loader Host Interface Service has encountered an internal connection problem.
 
Error: (03/26/2016 01:18:54 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.
 
Details:
AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol.
 
System Error:
Access is denied.
.
 
Error: (03/26/2016 01:15:36 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.
 
Details:
AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol.
 
System Error:
Access is denied.
.
 
Error: (03/26/2016 01:15:27 PM) (Source: IntelDalJhi) (EventID: 11) (User: )
Description: Intel® Dynamic Application Loader Host Interface Service has encountered an internal connection problem.
 
Error: (03/26/2016 01:12:33 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.
 
Details:
AddLegacyDriverFiles: Unable to back up image of binary zdwfp.
 
System Error:
The system cannot find the file specified.
.
 
Error: (03/26/2016 01:12:33 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.
 
Details:
AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol.
 
System Error:
Access is denied.
.
 
Error: (03/26/2016 01:12:01 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: svchost.exe_DoSvc, version: 10.0.10586.0, time stamp: 0x5632d7ba
Faulting module name: webio.dll, version: 10.0.10586.0, time stamp: 0x5632d55a
Exception code: 0xc0000409
Fault offset: 0x0000000000035ce9
Faulting process id: 0x2b8
Faulting application start time: 0xsvchost.exe_DoSvc0
Faulting application path: svchost.exe_DoSvc1
Faulting module path: svchost.exe_DoSvc2
Report Id: svchost.exe_DoSvc3
Faulting package full name: svchost.exe_DoSvc4
Faulting package-relative application ID: svchost.exe_DoSvc5
 
Error: (03/26/2016 12:43:26 PM) (Source: Perflib) (EventID: 1008) (User: )
Description: WmiApRplC:\windows\system32\wbem\wmiaprpl.dll4
 
Error: (03/26/2016 12:43:26 PM) (Source: Perflib) (EventID: 1023) (User: )
Description: rdyboost4
 
Error: (03/26/2016 12:43:26 PM) (Source: PerfNet) (EventID: 2004) (User: )
Description: 
 
 
System errors:
=============
Error: (03/26/2016 01:27:49 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The User Data Access_3f141 service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
 
Error: (03/26/2016 01:27:49 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The User Data Storage_3f141 service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
 
Error: (03/26/2016 01:27:49 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Contact Data_3f141 service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
 
Error: (03/26/2016 01:27:49 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Sync Host_3f141 service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
 
Error: (03/26/2016 01:27:49 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: application-specificLocalActivation{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)UnavailableUnavailable
 
Error: (03/26/2016 01:26:58 PM) (Source: Service Control Manager) (EventID: 7032) (User: )
Description: The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Windows Search service, but this action failed with the following error: 
%%1056
 
Error: (03/26/2016 01:26:29 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The NVIDIA Display Driver Service service terminated unexpectedly.  It has done this 2 time(s).
 
Error: (03/26/2016 01:26:29 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Intel® ME Service service terminated unexpectedly.  It has done this 1 time(s).
 
Error: (03/26/2016 01:26:28 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Intel® Rapid Storage Technology service terminated unexpectedly.  It has done this 1 time(s).
 
Error: (03/26/2016 01:26:28 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Windows Search service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 30000 milliseconds: Restart the service.
 
 
CodeIntegrity:
===================================
  Date: 2016-03-25 17:05:35.120
  Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2016-03-24 20:13:38.138
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\SpaceSoundPro\SpaceSoundPro.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2016-03-24 20:13:38.132
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\SpaceSoundPro\SpaceSoundPro.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2016-03-24 20:13:22.754
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\SpaceSoundPro\SpaceSoundPro.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2016-03-24 20:13:22.748
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\SpaceSoundPro\SpaceSoundPro.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2016-03-24 20:13:21.208
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\SpaceSoundPro\SpaceSoundPro.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2016-03-24 20:13:21.202
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\SpaceSoundPro\SpaceSoundPro.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2016-03-24 20:13:19.602
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\SpaceSoundPro\SpaceSoundPro.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2016-03-24 20:13:19.597
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\SpaceSoundPro\SpaceSoundPro.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2016-03-24 20:13:18.698
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\SpaceSoundPro\SpaceSoundPro.dll because the set of per-page image hashes could not be found on the system.
 
 
==================== Memory info =========================== 
 
Processor: Intel® Core™ i7-5820K CPU @ 3.30GHz
Percentage of memory in use: 17%
Total physical RAM: 16284.21 MB
Available physical RAM: 13432.15 MB
Total Virtual: 18716.21 MB
Available Virtual: 14971.79 MB
 
==================== Drives ================================
 
Drive c: (OSDisk) (Fixed) (Total:220.73 GB) (Free:139.76 GB) NTFS
Drive d: (SAMSUNG) (Fixed) (Total:931.51 GB) (Free:671.99 GB) NTFS
Drive f: (Storage) (Fixed) (Total:1862.89 GB) (Free:1581.49 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (Size: 223.6 GB) (Disk ID: 2B4024BB)
 
Partition: GPT.
 
========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 1863 GB) (Disk ID: 00000000)
 
Partition: GPT.
 
========================================================
Disk: 2 (Size: 931.5 GB) (Disk ID: 4F86173B)
Partition 1: (Active) - (Size=931.5 GB) - (Type=07 NTFS)
 
==================== End of Addition.txt ============================


#13 pystryker

pystryker

  • Malware Response Team
  • 730 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:10:44 PM

Posted 26 March 2016 - 08:43 AM

We still have much to do, but how is the machine running at this point?

I close my topics if there is no response after 3 days. Please PM a moderator or myself to reopen your topic.

Please PM me only if I'm helping you with your computer issues and I have not responded in 2 days. Please remember, I'm a volunteer and sometimes life does get in the way. :)

Please stay with me until I declare your machine clean. Absence of symptoms does not ensure your machine is clean.

If you'd like to make a donation via Paypal, please click here.





#14 willyman18

willyman18
  • Topic Starter

  • Members
  • 66 posts
  • OFFLINE
  •  
  • Local time:04:44 AM

Posted 26 March 2016 - 08:47 AM

the machine isnt running too bad but i am still getting pop ups telling me to update and i still can only use avast safe browser because ie and chrome wont load any webpages at all



#15 pystryker

pystryker

  • Malware Response Team
  • 730 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:10:44 PM

Posted 26 March 2016 - 09:04 AM

the machine isnt running too bad but i am still getting pop ups telling me to update and i still can only use avast safe browser because ie and chrome wont load any webpages at all


Hello :)

Ok, let's repair the patched file. Please give me another update on the machine's performance after running these steps. :thumbup2:


Step 1: System File Checker
  • Click the Start button and in the Search bar, type in Command Prompt You will see cmd.exe appear at the top of the window.
  • Right click on it and select Run as Administrator. Answer Yes if the machine requests it.
  • When the Command Prompt window opens, type this in: sfc /scannow
  • Please note the space between sfc and /scannow, it must be there to execute the command.
  • The system scan will begin. It may take a while to complete
  • Once the scan is complete, enter the command below and press Enter.

copy %windir%\logs\cbs\cbs.log "%userprofile%\Desktop\cbs.txt"


This will copy a log cbs.txt to your Desktop. Please post it in your next reply.


Step 2: Fresh FRST Scan
  • Start Farbar's Recovery Scan Tool and press the Scan button.
  • FRST will scan your system and produce two logs: FRST.txt and Addition.txt. Please post them in your next reply.
Things I need to see in your next post:

Please post each of these logs as a separate reply in this thread.

cbs.txt Log

Fresh Frst.txt Log

Fresh Addition.txt Log

I close my topics if there is no response after 3 days. Please PM a moderator or myself to reopen your topic.

Please PM me only if I'm helping you with your computer issues and I have not responded in 2 days. Please remember, I'm a volunteer and sometimes life does get in the way. :)

Please stay with me until I declare your machine clean. Absence of symptoms does not ensure your machine is clean.

If you'd like to make a donation via Paypal, please click here.








0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users