Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:05-03-2016 01
Ran by willi (administrator) on WINDOWS-J2K2PN4 (26-03-2016 13:31:31)
Running from C:\Users\willi\Desktop
Loaded Profiles: willi (Available Profiles: willi)
Platform: Windows 10 Home Version 1511 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(NVIDIA) C:\Program Files (x86)\NVIDIA Corporation\nTune\nTuneService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
() C:\Program Files (x86)\ASUS\AXSP\1.02.00\atkexComSvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
(DTS, Inc) C:\Program Files\Realtek\Audio\HDA\DTSU2PAuSrv64.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\asww10mon.exe
() C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(NVIDIA Corporation) C:\Users\willi\AppData\Local\NVIDIA\NvBackend\ApplicationOntology\NvOAWrapperCache.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Nota Inc.) C:\Program Files (x86)\Gyazo\GyStation.exe
(Curse, Inc) C:\Users\willi\AppData\Roaming\Curse Client\Bin\Curse.exe
() C:\Program Files\Scan 3XS\menu.exe
(Curse) C:\Users\willi\AppData\Local\Apps\2.0\GNJTZPBV.KQ1\P211G6GV.WC4\curs..tion_9e9e83ddf3ed3ead_0005.0001_fb8944c2684f5b6c\CurseClient.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Curse, Inc.) C:\Users\willi\AppData\Roaming\Curse Client\Bin\Electron\CurseUI.exe
(Curse, Inc.) C:\Users\willi\AppData\Roaming\Curse Client\Bin\Electron\CurseUI.exe
(Curse, Inc.) C:\Users\willi\AppData\Roaming\Curse Client\Bin\Electron\CurseUI.exe
(Curse, Inc.) C:\Users\willi\AppData\Roaming\Curse Client\Bin\Electron\CurseUI.exe
(Avast Software) C:\Program Files\AVAST Software\SZBrowser\1.48.2066.44\SZBrowser.exe
(Avast Software) C:\Program Files\AVAST Software\SZBrowser\1.48.2066.44\SZBrowser_crashreporter.exe
(Avast Software) C:\Program Files\AVAST Software\SZBrowser\1.48.2066.44\SZBrowser.exe
(Avast Software) C:\Program Files\AVAST Software\SZBrowser\1.48.2066.44\SZBrowser.exe
(Avast Software) C:\Program Files\AVAST Software\SZBrowser\1.48.2066.44\SZBrowser.exe
(Avast Software) C:\Program Files\AVAST Software\SZBrowser\1.48.2066.44\SZBrowser.exe
(Avast Software) C:\Program Files\AVAST Software\SZBrowser\1.48.2066.44\SZBrowser.exe
(Avast Software) C:\Program Files\AVAST Software\SZBrowser\1.48.2066.44\SZBrowser.exe
(Avast Software) C:\Program Files\AVAST Software\SZBrowser\1.48.2066.44\SZBrowser.exe
(Avast Software) C:\Program Files\AVAST Software\SZBrowser\1.48.2066.44\SZBrowser.exe
(Avast Software) C:\Program Files\AVAST Software\SZBrowser\1.48.2066.44\SZBrowser.exe
(Avast Software) C:\Program Files\AVAST Software\SZBrowser\1.48.2066.44\SZBrowser.exe
(Avast Software) C:\Program Files\AVAST Software\SZBrowser\1.48.2066.44\SZBrowser.exe
(Avast Software) C:\Program Files\AVAST Software\SZBrowser\1.48.2066.44\SZBrowser.exe
(Avast Software) C:\Program Files\AVAST Software\SZBrowser\1.48.2066.44\SZBrowser.exe
(Avast Software) C:\Program Files\AVAST Software\SZBrowser\1.48.2066.44\SZBrowser.exe
(Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
(Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
() C:\Program Files\AVAST Software\Avast\avastnm.exe
() C:\Program Files\AVAST Software\Avast\avastnm.exe
(Avast Software) C:\Program Files\AVAST Software\SZBrowser\1.48.2066.44\SZBrowser.exe
(Avast Software) C:\Program Files\AVAST Software\SZBrowser\1.48.2066.44\SZBrowser.exe
(Avast Software) C:\Program Files\AVAST Software\SZBrowser\1.48.2066.44\SZBrowser.exe
(Avast Software) C:\Program Files\AVAST Software\SZBrowser\1.48.2066.44\SZBrowser.exe
(Avast Software) C:\Program Files\AVAST Software\SZBrowser\1.48.2066.44\SZBrowser.exe
(Avast Software) C:\Program Files\AVAST Software\SZBrowser\1.48.2066.44\SZBrowser.exe
(Avast Software) C:\Program Files\AVAST Software\SZBrowser\1.48.2066.44\SZBrowser.exe
(Avast Software) C:\Program Files\AVAST Software\SZBrowser\1.48.2066.44\SZBrowser.exe
(Avast Software) C:\Program Files\AVAST Software\SZBrowser\1.48.2066.44\SZBrowser.exe
(Avast Software) C:\Program Files\AVAST Software\SZBrowser\1.48.2066.44\SZBrowser.exe
(Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
() C:\Program Files\AVAST Software\Avast\avastnm.exe
(Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
(Intel Corporation) C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
(Intel Corporation) C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [ScanMenu] => C:\Program Files\Scan 3XS\menu.exe [1197568 2015-12-10] ()
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe [322472 2015-06-23] (Intel Corporation)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8484056 2015-06-12] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_DTS] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1393880 2015-04-28] (Realtek Semiconductor)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2789248 2016-02-17] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => "C:\windows\system32\rundll32.exe" C:\windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM-x32\...\Run: [ScanMenu] => C:\Program Files\Scan 3XS\menu.exe [1197568 2015-12-10] ()
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [7139256 2016-03-25] (AVAST Software)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [596016 2016-01-29] (Oracle Corporation)
HKU\S-1-5-21-3667704814-1699542734-850788743-1002\...\Run: [Steam] => F:\programs\steam\steam.exe [3074128 2016-03-10] (Valve Corporation)
HKU\S-1-5-21-3667704814-1699542734-850788743-1002\...\Run: [Gyazo] => C:\Program Files (x86)\Gyazo\GyStation.exe [3586848 2016-02-17] (Nota Inc.)
HKU\S-1-5-21-3667704814-1699542734-850788743-1002\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [50670720 2016-03-01] (Skype Technologies S.A.)
HKU\S-1-5-21-3667704814-1699542734-850788743-1002\...\Run: [NVIDIA nTune] => C:\Program Files (x86)\NVIDIA Corporation\nTune\nTuneCmd.exe [98304 2007-09-04] (NVIDIA)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2016-03-25] (AVAST Software)
Startup: C:\Users\willi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Curse.lnk [2016-03-25]
ShortcutTarget: Curse.lnk -> C:\Users\willi\AppData\Roaming\Curse Client\Bin\Curse.exe (Curse, Inc)
Startup: C:\Users\willi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CurseClientStartup.ccip [2016-01-01] ()
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\Parameters: [NameServer] 8.8.8.8,8.8.8.4
Tcpip\..\Interfaces\{b583a9b8-65ca-463c-8fc0-15a808345548}: [DhcpNameServer] 192.168.0.1
ManualProxies:
Internet Explorer:
==================
HKU\S-1-5-21-3667704814-1699542734-850788743-1002\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.scan.co.uk
BHO: Java Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_74\bin\ssv.dll [2016-03-26] (Oracle Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2016-03-25] (AVAST Software)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO: Java Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_74\bin\jp2ssv.dll [2016-03-26] (Oracle Corporation)
BHO-x32: Java Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> F:\Program Files (x86)\bin\ssv.dll => No File
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2016-03-25] (AVAST Software)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> F:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
FireFox:
========
FF Plugin: @java.com/DTPlugin,version=11.74.2 -> C:\Program Files\Java\jre1.8.0_74\bin\dtplugin\npDeployJava1.dll [2016-03-26] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.74.2 -> C:\Program Files\Java\jre1.8.0_74\bin\plugin2\npjp2.dll [2016-03-26] (Oracle Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll [2014-04-03] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2014-04-03] (Intel Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> F:\Program Files (x86)\Microsoft Office\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> F:\Program Files (x86)\Microsoft Office\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-03-05] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-03-05] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> f:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-01-21] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.2 -> f:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-01-21] (VideoLAN)
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2016-03-25]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
Chrome:
=======
CHR Profile: C:\Users\willi\AppData\Local\Google\Chrome\User Data\Default
CHR Profile: C:\Users\willi\AppData\Local\Google\Chrome\User Data\Profile 1
CHR Extension: (Google Slides) - C:\Users\willi\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-01-15]
CHR Extension: (Google Docs) - C:\Users\willi\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2016-01-15]
CHR Extension: (Google Drive) - C:\Users\willi\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-01-15]
CHR Extension: (YouTube) - C:\Users\willi\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-01-15]
CHR Extension: (Adblock Plus) - C:\Users\willi\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2016-03-09]
CHR Extension: (Google Search) - C:\Users\willi\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2016-01-15]
CHR Extension: (Google Sheets) - C:\Users\willi\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-01-15]
CHR Extension: (Google Docs Offline) - C:\Users\willi\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-15]
CHR Extension: (Chrome Web Store Payments) - C:\Users\willi\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-01-15]
CHR Extension: (Gmail) - C:\Users\willi\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-01-15]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2016-03-25]
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 asComSvc; C:\Program Files (x86)\ASUS\AXSP\1.02.00\atkexComSvc.exe [936728 2013-07-04] ()
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [237096 2016-03-25] (AVAST Software)
R2 DTSAudioSvc; C:\Program Files\Realtek\Audio\HDA\DTSU2PAuSrv64.exe [240576 2013-10-07] (DTS, Inc)
S3 Futuremark SystemInfo Service; C:\Program Files (x86)\Futuremark\SystemInfo\FMSISvc.exe [342240 2015-11-05] (Futuremark)
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1164672 2016-02-17] (NVIDIA Corporation)
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [18856 2015-06-23] (Intel Corporation)
S3 Intel® Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [887232 2014-01-31] (Intel® Corporation)
R2 Intel® ME Service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe [131544 2014-04-03] (Intel Corporation)
S3 iumsvc; C:\Program Files (x86)\Intel\Intel® Update Manager\bin\iumsvc.exe [178312 2015-09-25] (Intel Corporation)
S2 jhi_service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe [154584 2014-04-03] (Intel Corporation)
R2 nTuneService; C:\Program Files (x86)\NVIDIA Corporation\nTune\nTuneService.exe [180224 2007-09-04] (NVIDIA) [File not signed]
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1880960 2016-02-17] (NVIDIA Corporation)
R3 NvStreamNetworkSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [6474112 2016-02-17] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [2609024 2016-02-17] (NVIDIA Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2015-10-30] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-10-30] (Microsoft Corporation)
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [15232 2013-07-04] ()
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [37656 2016-03-25] (AVAST Software)
R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [37144 2016-03-26] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [107792 2016-03-25] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [103064 2016-03-25] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [74544 2016-03-25] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1070904 2016-03-25] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [463744 2016-03-25] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [165344 2016-03-25] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [287016 2016-03-25] (AVAST Software)
S3 DIRECTIO37; C:\Program Files\BurnInTest\DirectIo64.sys [31376 2015-02-16] ()
R3 e1dexpress; C:\Windows\system32\DRIVERS\e1d65x64.sys [530416 2015-06-18] (Intel Corporation)
R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [118272 2014-04-03] (Intel Corporation)
R3 NVR0Dev; C:\windows\nvoclk64.sys [39968 2007-09-04] (NVidia Corp.)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [28032 2016-02-17] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [47760 2015-12-18] (NVIDIA Corporation)
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-03-26 13:22 - 2016-03-26 13:26 - 00000000 ____D C:\AdwCleaner
2016-03-26 13:21 - 2016-03-26 13:21 - 01530368 _____ C:\Users\willi\Desktop\AdwCleaner.exe
2016-03-26 13:17 - 2016-03-26 13:17 - 00001154 _____ C:\Users\willi\Desktop\JRT.txt
2016-03-26 13:11 - 2016-03-26 13:11 - 01610352 _____ (Malwarebytes) C:\Users\willi\Desktop\JRT.exe
2016-03-26 13:08 - 2016-03-26 13:09 - 00010773 _____ C:\Users\willi\Desktop\Fixlog.txt
2016-03-26 13:06 - 2016-03-26 13:31 - 00018579 _____ C:\Users\willi\Desktop\FRST.txt
2016-03-26 13:06 - 2016-03-26 13:07 - 00045848 _____ C:\Users\willi\Desktop\Addition.txt
2016-03-26 13:03 - 2016-03-26 11:54 - 02374144 _____ (Farbar) C:\Users\willi\Desktop\FRST64.exe
2016-03-26 11:55 - 2016-03-26 13:31 - 00000000 ____D C:\FRST
2016-03-26 07:36 - 2016-03-26 07:36 - 00037144 _____ (AVAST Software) C:\windows\system32\Drivers\aswKbd.sys
2016-03-26 07:36 - 2016-03-26 07:36 - 00003178 _____ C:\windows\System32\Tasks\SafeZone scheduled Autoupdate 1458977815
2016-03-26 07:36 - 2016-03-26 07:36 - 00001088 _____ C:\Users\Public\Desktop\Avast SafeZone Browser.lnk
2016-03-26 07:36 - 2016-03-26 07:36 - 00001088 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast SafeZone Browser.lnk
2016-03-25 22:25 - 2016-03-25 22:23 - 00398152 _____ (AVAST Software) C:\windows\system32\aswBoot.exe
2016-03-25 22:24 - 2016-03-25 22:25 - 00003040 _____ C:\windows\System32\Tasks\avast! Windows 10 Start Menu helper
2016-03-25 22:24 - 2016-03-25 22:24 - 00001985 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast Free Antivirus.lnk
2016-03-25 22:24 - 2016-03-25 22:24 - 00001973 _____ C:\Users\Public\Desktop\Avast Free Antivirus.lnk
2016-03-25 22:24 - 2016-03-25 22:24 - 00000000 ____D C:\Users\willi\AppData\Roaming\AVAST Software
2016-03-25 22:23 - 2016-03-25 22:25 - 00004006 _____ C:\windows\System32\Tasks\avast! Emergency Update
2016-03-25 22:23 - 2016-03-25 22:24 - 01070904 _____ (AVAST Software) C:\windows\system32\Drivers\aswSnx.sys
2016-03-25 22:23 - 2016-03-25 22:24 - 00107792 _____ (AVAST Software) C:\windows\system32\Drivers\aswMonFlt.sys
2016-03-25 22:23 - 2016-03-25 22:23 - 00463744 _____ (AVAST Software) C:\windows\system32\Drivers\aswSP.sys
2016-03-25 22:23 - 2016-03-25 22:23 - 00287016 _____ (AVAST Software) C:\windows\system32\Drivers\aswVmm.sys
2016-03-25 22:23 - 2016-03-25 22:23 - 00165344 _____ (AVAST Software) C:\windows\system32\Drivers\aswStm.sys
2016-03-25 22:23 - 2016-03-25 22:23 - 00103064 _____ (AVAST Software) C:\windows\system32\Drivers\aswRdr2.sys
2016-03-25 22:23 - 2016-03-25 22:23 - 00074544 _____ (AVAST Software) C:\windows\system32\Drivers\aswRvrt.sys
2016-03-25 22:23 - 2016-03-25 22:23 - 00052184 _____ (AVAST Software) C:\windows\avastSS.scr
2016-03-25 22:23 - 2016-03-25 22:23 - 00037656 _____ (AVAST Software) C:\windows\system32\Drivers\aswHwid.sys
2016-03-25 22:23 - 2016-03-25 22:23 - 00001271 _____ C:\Users\willi\Desktop\Continue Flash Video Player Installation.lnk
2016-03-25 22:22 - 2016-03-26 07:36 - 00000000 ____D C:\ProgramData\AVAST Software
2016-03-25 22:22 - 2016-03-26 07:36 - 00000000 ____D C:\Program Files\AVAST Software
2016-03-25 21:38 - 2016-03-25 21:38 - 00000000 ___HD C:\OneDriveTemp
2016-03-25 21:34 - 2016-03-25 21:34 - 00000000 ____D C:\windows\system32\todp
2016-03-25 21:16 - 2016-03-25 21:16 - 00192216 _____ (Malwarebytes) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2016-03-25 21:15 - 2016-03-25 21:36 - 00001171 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2016-03-25 21:15 - 2016-03-25 21:15 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2016-03-25 21:15 - 2016-03-25 21:15 - 00000000 ____D C:\ProgramData\Malwarebytes
2016-03-25 21:15 - 2016-03-25 21:15 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2016-03-25 21:15 - 2016-03-10 14:09 - 00065408 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys
2016-03-25 21:15 - 2016-03-10 14:08 - 00140672 _____ (Malwarebytes) C:\windows\system32\Drivers\mbamchameleon.sys
2016-03-25 21:15 - 2016-03-10 14:08 - 00027008 _____ (Malwarebytes) C:\windows\system32\Drivers\mbam.sys
2016-03-25 21:03 - 2016-03-25 21:03 - 00000000 ____D C:\Users\willi\AppData\Roaming\MCorp
2016-03-25 20:59 - 2016-03-25 23:09 - 00000000 ____D C:\Program Files\Baomkybrile
2016-03-25 20:59 - 2016-03-25 21:35 - 00000000 ____D C:\Users\willi\AppData\Roaming\Memuomi
2016-03-25 20:59 - 2016-03-25 21:01 - 00000000 ____D C:\Users\willi\AppData\Local\app
2016-03-25 20:59 - 2016-03-25 20:59 - 00003418 _____ C:\windows\System32\Tasks\Bimui
2016-03-25 20:59 - 2016-03-25 20:59 - 00000000 ____D C:\Users\willi\AppData\Local\Tempfolder
2016-03-25 20:59 - 2016-03-25 20:59 - 00000000 ____D C:\uninst
2016-03-24 20:12 - 2016-03-25 21:05 - 00000000 ____D C:\Program Files\Common Files\Soobzo
2016-03-24 20:11 - 2016-03-24 20:12 - 00187904 _____ C:\windows\rsrcs.dll
2016-03-24 20:02 - 2016-03-24 20:00 - 00001006 _____ C:\windows\system32\Drivers\etc\hp.bak
2016-03-23 09:00 - 2016-03-23 09:00 - 00000889 _____ C:\windows\SysWOW64\${LOGFILE}
2016-03-23 08:57 - 2016-03-23 08:57 - 06493696 _____ C:\Users\willi\AppData\Roaming\agent.dat
2016-03-23 08:57 - 2016-03-23 08:57 - 01622132 _____ C:\Users\willi\AppData\Roaming\Zimlux.tst
2016-03-23 08:57 - 2016-03-23 08:57 - 00127488 _____ C:\Users\willi\AppData\Roaming\Installer.dat
2016-03-23 08:57 - 2016-03-23 08:57 - 00072707 _____ C:\Users\willi\AppData\Roaming\Jaytom.tst
2016-03-23 08:57 - 2016-03-23 08:57 - 00018432 _____ C:\Users\willi\AppData\Roaming\Main.dat
2016-03-23 08:57 - 2016-03-23 08:57 - 00000000 ____D C:\Users\willi\AppData\Roaming\Mozilla
2016-03-23 08:57 - 2016-03-23 08:57 - 00000000 ____D C:\ProgramData\Quoteexs
2016-03-23 08:56 - 2016-03-23 08:56 - 00000000 ____D C:\ProgramData\DivX
2016-03-23 08:49 - 2016-03-23 08:49 - 00000000 ____D C:\Users\willi\AppData\Roaming\vlc
2016-03-23 08:48 - 2016-03-25 21:36 - 00000835 _____ C:\Users\Public\Desktop\VLC media player.lnk
2016-03-23 08:43 - 2016-03-23 09:02 - 00000000 ____D C:\Users\willi\AppData\Roaming\uTorrent
2016-03-17 20:47 - 2016-03-17 20:47 - 00000000 ____D C:\Users\willi\AppData\Roaming\.mono
2016-03-17 20:47 - 2016-03-17 20:47 - 00000000 ____D C:\ProgramData\.mono
2016-03-13 20:51 - 2016-03-25 21:36 - 00000922 _____ C:\Users\Public\Desktop\Hearthstone.lnk
2016-03-08 22:46 - 2016-03-08 22:46 - 00018521 _____ C:\Users\willi\Documents\cloudbass NEW_HOLIDAY_REQUEST_FORM (1).xlsx
2016-03-08 18:45 - 2016-03-01 05:31 - 00848168 _____ (Microsoft Corporation) C:\windows\system32\mfsvr.dll
2016-03-08 18:45 - 2016-03-01 05:22 - 00709688 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfsvr.dll
2016-03-08 18:45 - 2016-02-24 09:52 - 01997328 _____ (Microsoft Corporation) C:\windows\system32\KernelBase.dll
2016-03-08 18:45 - 2016-02-24 09:51 - 07474528 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe
2016-03-08 18:45 - 2016-02-24 09:48 - 00713568 _____ (Microsoft Corporation) C:\windows\system32\invagent.dll
2016-03-08 18:45 - 2016-02-24 09:47 - 01173344 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll
2016-03-08 18:45 - 2016-02-24 09:40 - 00513888 _____ (Microsoft Corporation) C:\windows\system32\devinv.dll
2016-03-08 18:45 - 2016-02-24 09:34 - 01613664 _____ (Microsoft Corporation) C:\windows\system32\diagtrack.dll
2016-03-08 18:45 - 2016-02-24 09:28 - 03449168 _____ (Microsoft Corporation) C:\windows\system32\WSService.dll
2016-03-08 18:45 - 2016-02-24 09:15 - 01557768 _____ (Microsoft Corporation) C:\windows\SysWOW64\KernelBase.dll
2016-03-08 18:45 - 2016-02-24 08:58 - 00794888 _____ (Microsoft Corporation) C:\windows\system32\mfds.dll
2016-03-08 18:45 - 2016-02-24 08:54 - 00127840 _____ (Microsoft Corporation) C:\windows\system32\Drivers\USBSTOR.SYS
2016-03-08 18:45 - 2016-02-24 08:51 - 01322248 _____ (Microsoft Corporation) C:\windows\system32\ole32.dll
2016-03-08 18:45 - 2016-02-24 08:50 - 00808800 _____ (Microsoft Corporation) C:\windows\system32\WWAHost.exe
2016-03-08 18:45 - 2016-02-24 08:46 - 06607080 _____ (Microsoft Corporation) C:\windows\system32\windows.storage.dll
2016-03-08 18:45 - 2016-02-24 08:43 - 00625000 _____ (Microsoft Corporation) C:\windows\system32\ClipSVC.dll
2016-03-08 18:45 - 2016-02-24 08:39 - 00358752 _____ (Microsoft Corporation) C:\windows\system32\msv1_0.dll
2016-03-08 18:45 - 2016-02-24 08:39 - 00141560 _____ (Microsoft Corporation) C:\windows\system32\AuthHost.exe
2016-03-08 18:45 - 2016-02-24 08:19 - 00670928 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfds.dll
2016-03-08 18:45 - 2016-02-24 08:14 - 00216416 _____ (Microsoft Corporation) C:\windows\system32\AppxAllUserStore.dll
2016-03-08 18:45 - 2016-02-24 08:11 - 01997152 _____ (Microsoft Corporation) C:\windows\system32\Drivers\dxgkrnl.sys
2016-03-08 18:45 - 2016-02-24 08:11 - 00957608 _____ (Microsoft Corporation) C:\windows\SysWOW64\ole32.dll
2016-03-08 18:45 - 2016-02-24 08:11 - 00703840 _____ (Microsoft Corporation) C:\windows\SysWOW64\WWAHost.exe
2016-03-08 18:45 - 2016-02-24 08:11 - 00652392 _____ (Microsoft Corporation) C:\windows\system32\dxgi.dll
2016-03-08 18:45 - 2016-02-24 08:11 - 00394080 _____ (Microsoft Corporation) C:\windows\system32\Drivers\dxgmms1.sys
2016-03-08 18:45 - 2016-02-24 08:11 - 00258280 _____ (Microsoft Corporation) C:\windows\system32\sqmapi.dll
2016-03-08 18:45 - 2016-02-24 08:10 - 00630632 _____ (Microsoft Corporation) C:\windows\system32\fontdrvhost.exe
2016-03-08 18:45 - 2016-02-24 08:10 - 00576864 _____ (Microsoft Corporation) C:\windows\system32\Drivers\dxgmms2.sys
2016-03-08 18:45 - 2016-02-24 08:09 - 00640472 _____ (Microsoft Corporation) C:\windows\system32\wer.dll
2016-03-08 18:45 - 2016-02-24 08:09 - 00147808 _____ (Microsoft Corporation) C:\windows\system32\wermgr.exe
2016-03-08 18:45 - 2016-02-24 08:06 - 05242496 _____ (Microsoft Corporation) C:\windows\SysWOW64\windows.storage.dll
2016-03-08 18:45 - 2016-02-24 07:59 - 00294752 _____ (Microsoft Corporation) C:\windows\SysWOW64\msv1_0.dll
2016-03-08 18:45 - 2016-02-24 07:39 - 00045568 _____ (Microsoft Corporation) C:\windows\system32\UserDataTypeHelperUtil.dll
2016-03-08 18:45 - 2016-02-24 07:39 - 00023552 _____ (Microsoft Corporation) C:\windows\system32\ExtrasXmlParser.dll
2016-03-08 18:45 - 2016-02-24 07:38 - 00187744 _____ (Microsoft Corporation) C:\windows\SysWOW64\AppxAllUserStore.dll
2016-03-08 18:45 - 2016-02-24 07:38 - 00111616 _____ (Microsoft Corporation) C:\windows\system32\UserDataTimeUtil.dll
2016-03-08 18:45 - 2016-02-24 07:37 - 00045056 _____ (Microsoft Corporation) C:\windows\system32\UserDataLanguageUtil.dll
2016-03-08 18:45 - 2016-02-24 07:36 - 00060416 _____ (Microsoft Corporation) C:\windows\system32\PimIndexMaintenanceClient.dll
2016-03-08 18:45 - 2016-02-24 07:35 - 00540752 _____ (Microsoft Corporation) C:\windows\SysWOW64\fontdrvhost.exe
2016-03-08 18:45 - 2016-02-24 07:35 - 00523752 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxgi.dll
2016-03-08 18:45 - 2016-02-24 07:35 - 00220064 _____ (Microsoft Corporation) C:\windows\SysWOW64\sqmapi.dll
2016-03-08 18:45 - 2016-02-24 07:35 - 00045568 _____ (Adobe Systems) C:\windows\system32\atmlib.dll
2016-03-08 18:45 - 2016-02-24 07:33 - 00538736 _____ (Microsoft Corporation) C:\windows\SysWOW64\wer.dll
2016-03-08 18:45 - 2016-02-24 07:33 - 00141664 _____ (Microsoft Corporation) C:\windows\SysWOW64\wermgr.exe
2016-03-08 18:45 - 2016-02-24 07:31 - 00118272 _____ (Microsoft Corporation) C:\windows\system32\fontsub.dll
2016-03-08 18:45 - 2016-02-24 07:30 - 00025600 _____ (Microsoft Corporation) C:\windows\system32\wfapigp.dll
2016-03-08 18:45 - 2016-02-24 07:28 - 00070656 _____ (Microsoft Corporation) C:\windows\system32\POSyncServices.dll
2016-03-08 18:45 - 2016-02-24 07:23 - 00091648 _____ (Microsoft Corporation) C:\windows\system32\asycfilt.dll
2016-03-08 18:45 - 2016-02-24 07:23 - 00068096 _____ (Microsoft Corporation) C:\windows\system32\UserDataPlatformHelperUtil.dll
2016-03-08 18:45 - 2016-02-24 07:22 - 00196608 _____ (Microsoft Corporation) C:\windows\system32\fwpolicyiomgr.dll
2016-03-08 18:45 - 2016-02-24 07:20 - 00195072 _____ (Microsoft Corporation) C:\windows\system32\VCardParser.dll
2016-03-08 18:45 - 2016-02-24 07:20 - 00167936 _____ (Microsoft Corporation) C:\windows\system32\dafBth.dll
2016-03-08 18:45 - 2016-02-24 07:20 - 00087552 _____ (Microsoft Corporation) C:\windows\system32\AppxSysprep.dll
2016-03-08 18:45 - 2016-02-24 07:19 - 00145408 _____ (Microsoft Corporation) C:\windows\system32\dssvc.dll
2016-03-08 18:45 - 2016-02-24 07:19 - 00031232 _____ (Microsoft Corporation) C:\windows\system32\seclogon.dll
2016-03-08 18:45 - 2016-02-24 07:15 - 00365568 _____ (Adobe Systems Incorporated) C:\windows\system32\atmfd.dll
2016-03-08 18:45 - 2016-02-24 07:14 - 00274944 _____ (Microsoft Corporation) C:\windows\system32\ExSMime.dll
2016-03-08 18:45 - 2016-02-24 07:13 - 00121856 _____ (Microsoft Corporation) C:\windows\system32\AppointmentActivation.dll
2016-03-08 18:45 - 2016-02-24 07:12 - 00243712 _____ (Microsoft Corporation) C:\windows\system32\cemapi.dll
2016-03-08 18:45 - 2016-02-24 07:12 - 00221184 _____ (Microsoft Corporation) C:\windows\system32\PhoneCallHistoryApis.dll
2016-03-08 18:45 - 2016-02-24 07:10 - 00093184 _____ (Microsoft Corporation) C:\windows\system32\wpninprc.dll
2016-03-08 18:45 - 2016-02-24 07:09 - 00258560 _____ (Microsoft Corporation) C:\windows\system32\UserDataAccountApis.dll
2016-03-08 18:45 - 2016-02-24 07:09 - 00161792 _____ (Microsoft Corporation) C:\windows\system32\AppxSip.dll
2016-03-08 18:45 - 2016-02-24 07:07 - 00252928 _____ (Microsoft Corporation) C:\windows\system32\PimIndexMaintenance.dll
2016-03-08 18:45 - 2016-02-24 07:05 - 00208896 _____ (Microsoft Corporation) C:\windows\system32\storewuauth.dll
2016-03-08 18:45 - 2016-02-24 07:03 - 00088576 _____ (Microsoft Corporation) C:\windows\SysWOW64\olepro32.dll
2016-03-08 18:45 - 2016-02-24 07:02 - 00161280 _____ (Microsoft Corporation) C:\windows\system32\CallHistoryClient.dll
2016-03-08 18:45 - 2016-02-24 07:01 - 00764928 _____ (Microsoft Corporation) C:\windows\system32\Chakradiag.dll
2016-03-08 18:45 - 2016-02-24 07:01 - 00146432 _____ (Microsoft Corporation) C:\windows\system32\AuthBroker.dll
2016-03-08 18:45 - 2016-02-24 07:01 - 00067584 _____ (Microsoft Corporation) C:\windows\system32\profext.dll
2016-03-08 18:45 - 2016-02-24 07:00 - 00214528 _____ (Microsoft Corporation) C:\windows\system32\Windows.Devices.Scanners.dll
2016-03-08 18:45 - 2016-02-24 06:59 - 00450560 _____ (Microsoft Corporation) C:\windows\system32\Windows.Internal.Bluetooth.dll
2016-03-08 18:45 - 2016-02-24 06:59 - 00360448 _____ (Microsoft Corporation) C:\windows\system32\vaultsvc.dll
2016-03-08 18:45 - 2016-02-24 06:59 - 00318976 _____ (Microsoft Corporation) C:\windows\system32\domgmt.dll
2016-03-08 18:45 - 2016-02-24 06:58 - 00685568 _____ (Microsoft Corporation) C:\windows\system32\scapi.dll
2016-03-08 18:45 - 2016-02-24 06:55 - 00790528 _____ (Microsoft Corporation) C:\windows\system32\EmailApis.dll
2016-03-08 18:45 - 2016-02-24 06:55 - 00224256 _____ (Microsoft Corporation) C:\windows\system32\PackageStateRoaming.dll
2016-03-08 18:45 - 2016-02-24 06:55 - 00018944 _____ (Microsoft Corporation) C:\windows\SysWOW64\ExtrasXmlParser.dll
2016-03-08 18:45 - 2016-02-24 06:54 - 00526336 _____ (Microsoft Corporation) C:\windows\system32\FirewallAPI.dll
2016-03-08 18:45 - 2016-02-24 06:54 - 00288768 _____ (Microsoft Corporation) C:\windows\system32\vaultcli.dll
2016-03-08 18:45 - 2016-02-24 06:54 - 00228352 _____ (Microsoft Corporation) C:\windows\system32\wsqmcons.exe
2016-03-08 18:45 - 2016-02-24 06:54 - 00037888 _____ (Microsoft Corporation) C:\windows\SysWOW64\UserDataTypeHelperUtil.dll
2016-03-08 18:45 - 2016-02-24 06:53 - 00089088 _____ (Microsoft Corporation) C:\windows\SysWOW64\UserDataTimeUtil.dll
2016-03-08 18:45 - 2016-02-24 06:53 - 00037888 _____ (Microsoft Corporation) C:\windows\SysWOW64\UserDataLanguageUtil.dll
2016-03-08 18:45 - 2016-02-24 06:52 - 00451584 _____ (Microsoft Corporation) C:\windows\system32\werui.dll
2016-03-08 18:45 - 2016-02-24 06:52 - 00048128 _____ (Microsoft Corporation) C:\windows\SysWOW64\PimIndexMaintenanceClient.dll
2016-03-08 18:45 - 2016-02-24 06:51 - 00037376 _____ (Adobe Systems) C:\windows\SysWOW64\atmlib.dll
2016-03-08 18:45 - 2016-02-24 06:49 - 00726528 _____ (Microsoft Corporation) C:\windows\system32\ChatApis.dll
2016-03-08 18:45 - 2016-02-24 06:47 - 00093696 _____ (Microsoft Corporation) C:\windows\SysWOW64\fontsub.dll
2016-03-08 18:45 - 2016-02-24 06:46 - 00020480 _____ (Microsoft Corporation) C:\windows\SysWOW64\wfapigp.dll
2016-03-08 18:45 - 2016-02-24 06:44 - 01713664 _____ (Microsoft Corporation) C:\windows\system32\SRHInproc.dll
2016-03-08 18:45 - 2016-02-24 06:44 - 00915456 _____ (Microsoft Corporation) C:\windows\system32\configurationclient.dll
2016-03-08 18:45 - 2016-02-24 06:44 - 00700416 _____ (Microsoft Corporation) C:\windows\system32\AppointmentApis.dll
2016-03-08 18:45 - 2016-02-24 06:44 - 00056320 _____ (Microsoft Corporation) C:\windows\SysWOW64\POSyncServices.dll
2016-03-08 18:45 - 2016-02-24 06:43 - 00957952 _____ (Microsoft Corporation) C:\windows\system32\SRH.dll
2016-03-08 18:45 - 2016-02-24 06:43 - 00286720 _____ (Microsoft Corporation) C:\windows\system32\deviceaccess.dll
2016-03-08 18:45 - 2016-02-24 06:41 - 00982016 _____ (Microsoft Corporation) C:\windows\system32\AppxPackaging.dll
2016-03-08 18:45 - 2016-02-24 06:41 - 00436736 _____ (Microsoft Corporation) C:\windows\system32\AppXDeploymentClient.dll
2016-03-08 18:45 - 2016-02-24 06:40 - 01224704 _____ (Microsoft Corporation) C:\windows\system32\Unistore.dll
2016-03-08 18:45 - 2016-02-24 06:40 - 00078848 _____ (Microsoft Corporation) C:\windows\SysWOW64\asycfilt.dll
2016-03-08 18:45 - 2016-02-24 06:40 - 00056320 _____ (Microsoft Corporation) C:\windows\SysWOW64\UserDataPlatformHelperUtil.dll
2016-03-08 18:45 - 2016-02-24 06:39 - 01390592 _____ (Microsoft Corporation) C:\windows\system32\win32kbase.sys
2016-03-08 18:45 - 2016-02-24 06:39 - 00164864 _____ (Microsoft Corporation) C:\windows\SysWOW64\fwpolicyiomgr.dll
2016-03-08 18:45 - 2016-02-24 06:38 - 00150528 _____ (Microsoft Corporation) C:\windows\SysWOW64\VCardParser.dll
2016-03-08 18:45 - 2016-02-24 06:36 - 01847808 _____ (Microsoft Corporation) C:\windows\system32\WMPDMC.exe
2016-03-08 18:45 - 2016-02-24 06:34 - 00938496 _____ (Microsoft Corporation) C:\windows\system32\ContactApis.dll
2016-03-08 18:45 - 2016-02-24 06:34 - 00303104 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\atmfd.dll
2016-03-08 18:45 - 2016-02-24 06:32 - 00223744 _____ (Microsoft Corporation) C:\windows\SysWOW64\ExSMime.dll
2016-03-08 18:45 - 2016-02-24 06:32 - 00098304 _____ (Microsoft Corporation) C:\windows\SysWOW64\AppointmentActivation.dll
2016-03-08 18:45 - 2016-02-24 06:31 - 00200704 _____ (Microsoft Corporation) C:\windows\SysWOW64\cemapi.dll
2016-03-08 18:45 - 2016-02-24 06:31 - 00169984 _____ (Microsoft Corporation) C:\windows\SysWOW64\PhoneCallHistoryApis.dll
2016-03-08 18:45 - 2016-02-24 06:28 - 00870912 _____ (Microsoft Corporation) C:\windows\system32\MPSSVC.dll
2016-03-08 18:45 - 2016-02-24 06:28 - 00196608 _____ (Microsoft Corporation) C:\windows\SysWOW64\UserDataAccountApis.dll
2016-03-08 18:45 - 2016-02-24 06:28 - 00135168 _____ (Microsoft Corporation) C:\windows\SysWOW64\AppxSip.dll
2016-03-08 18:45 - 2016-02-24 06:25 - 00401408 _____ (Microsoft Corporation) C:\windows\system32\sharemediacpl.dll
2016-03-08 18:45 - 2016-02-24 06:23 - 00129024 _____ (Microsoft Corporation) C:\windows\SysWOW64\CallHistoryClient.dll
2016-03-08 18:45 - 2016-02-24 06:22 - 00053248 _____ (Microsoft Corporation) C:\windows\SysWOW64\profext.dll
2016-03-08 18:45 - 2016-02-24 06:21 - 00315904 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.Internal.Bluetooth.dll
2016-03-08 18:45 - 2016-02-24 06:21 - 00168448 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.Devices.Scanners.dll
2016-03-08 18:45 - 2016-02-24 06:18 - 01490432 _____ (Microsoft Corporation) C:\windows\system32\UserDataService.dll
2016-03-08 18:45 - 2016-02-24 06:18 - 00575488 _____ (Microsoft Corporation) C:\windows\SysWOW64\EmailApis.dll
2016-03-08 18:45 - 2016-02-24 06:18 - 00184832 _____ (Microsoft Corporation) C:\windows\SysWOW64\PackageStateRoaming.dll
2016-03-08 18:45 - 2016-02-24 06:17 - 00369664 _____ (Microsoft Corporation) C:\windows\SysWOW64\FirewallAPI.dll
2016-03-08 18:45 - 2016-02-24 06:16 - 00394752 _____ (Microsoft Corporation) C:\windows\SysWOW64\werui.dll
2016-03-08 18:45 - 2016-02-24 06:13 - 00540160 _____ (Microsoft Corporation) C:\windows\SysWOW64\ChatApis.dll
2016-03-08 18:45 - 2016-02-24 06:11 - 03593216 _____ (Microsoft Corporation) C:\windows\system32\win32kfull.sys
2016-03-08 18:45 - 2016-02-24 06:09 - 01443328 _____ (Microsoft Corporation) C:\windows\SysWOW64\SRHInproc.dll
2016-03-08 18:45 - 2016-02-24 06:09 - 00793600 _____ (Microsoft Corporation) C:\windows\SysWOW64\SRH.dll
2016-03-08 18:45 - 2016-02-24 06:09 - 00552960 _____ (Microsoft Corporation) C:\windows\SysWOW64\AppointmentApis.dll
2016-03-08 18:45 - 2016-02-24 06:09 - 00228352 _____ (Microsoft Corporation) C:\windows\SysWOW64\deviceaccess.dll
2016-03-08 18:45 - 2016-02-24 06:07 - 00949248 _____ (Microsoft Corporation) C:\windows\SysWOW64\Unistore.dll
2016-03-08 18:45 - 2016-02-24 06:07 - 00890368 _____ (Microsoft Corporation) C:\windows\SysWOW64\AppxPackaging.dll
2016-03-08 18:45 - 2016-02-24 06:07 - 00342528 _____ (Microsoft Corporation) C:\windows\SysWOW64\AppXDeploymentClient.dll
2016-03-08 18:45 - 2016-02-24 06:04 - 01497088 _____ (Microsoft Corporation) C:\windows\SysWOW64\WMPDMC.exe
2016-03-08 18:45 - 2016-02-24 06:03 - 00769536 _____ (Microsoft Corporation) C:\windows\SysWOW64\ContactApis.dll
2016-03-08 18:45 - 2016-02-24 06:01 - 01831936 _____ (Microsoft Corporation) C:\windows\system32\AppXDeploymentExtensions.dll
2016-03-08 18:45 - 2016-02-24 06:00 - 02273792 _____ (Microsoft Corporation) C:\windows\system32\wuaueng.dll
2016-03-08 18:45 - 2016-02-24 06:00 - 01098752 _____ (Microsoft Corporation) C:\windows\system32\dosvc.dll
2016-03-08 18:45 - 2016-02-24 05:57 - 02158592 _____ (Microsoft Corporation) C:\windows\system32\AppXDeploymentServer.dll
2016-03-08 18:45 - 2016-02-24 05:55 - 01996288 _____ (Microsoft Corporation) C:\windows\system32\ActiveSyncProvider.dll
2016-03-08 18:45 - 2016-02-24 05:43 - 00184320 _____ (Microsoft Corporation) C:\windows\system32\fwbase.dll
2016-03-08 18:45 - 2016-02-24 05:34 - 01707520 _____ (Microsoft Corporation) C:\windows\SysWOW64\ActiveSyncProvider.dll
2016-03-08 18:45 - 2016-02-24 05:22 - 00163328 _____ (Microsoft Corporation) C:\windows\SysWOW64\fwbase.dll
2016-03-08 18:45 - 2016-02-24 05:20 - 22376960 _____ (Microsoft Corporation) C:\windows\system32\edgehtml.dll
2016-03-08 18:45 - 2016-02-24 05:18 - 18677760 _____ (Microsoft Corporation) C:\windows\SysWOW64\edgehtml.dll
2016-03-08 18:45 - 2016-02-24 05:12 - 19339776 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2016-03-08 18:45 - 2016-02-24 05:12 - 05321728 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.Data.Pdf.dll
2016-03-08 18:45 - 2016-02-24 05:10 - 24600576 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2016-03-08 18:45 - 2016-02-24 05:09 - 06972416 _____ (Microsoft Corporation) C:\windows\system32\Windows.Data.Pdf.dll
2016-03-08 18:45 - 2016-02-24 05:05 - 12586496 _____ (Microsoft Corporation) C:\windows\SysWOW64\wmp.dll
2016-03-08 18:45 - 2016-02-24 05:03 - 14252544 _____ (Microsoft Corporation) C:\windows\system32\wmp.dll
2016-03-08 18:45 - 2016-02-24 04:59 - 05661696 _____ (Microsoft Corporation) C:\windows\SysWOW64\Chakra.dll
2016-03-08 18:45 - 2016-02-24 04:55 - 07835648 _____ (Microsoft Corporation) C:\windows\system32\Chakra.dll
2016-03-06 13:33 - 2016-03-25 21:36 - 00002332 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2016-03-05 19:14 - 2016-03-05 19:14 - 00000000 ____D C:\Program Files (x86)\Google
2016-03-03 23:29 - 2016-03-03 23:29 - 00000000 ____D C:\Users\willi\AppData\Roaming\NVIDIA
2016-03-01 20:45 - 2016-03-01 20:45 - 00372736 _____ (NVIDIA Corporation) C:\windows\system32\NVUNINST.EXE
2016-03-01 20:45 - 2016-03-01 20:45 - 00000000 ____D C:\Program Files (x86)\NVIDIA nTune Performance Application
2016-03-01 20:45 - 2007-07-03 16:41 - 01524736 _____ (Microsoft Corporation) C:\windows\system32\MFC71.dll
2016-03-01 20:45 - 2007-07-03 16:41 - 00978944 _____ (Microsoft Corporation) C:\windows\system32\msvcp71.dll
2016-03-01 20:45 - 2007-07-03 16:41 - 00520192 _____ (Microsoft Corporation) C:\windows\system32\msvcr71.dll
2016-03-01 20:45 - 2007-06-25 22:21 - 02065920 _____ (NVIDIA Corporation) C:\windows\system32\nvcplUI.exe
2016-03-01 20:45 - 2007-06-25 22:21 - 01064448 _____ (NVIDIA Corporation) C:\windows\system32\nvcplUIR.dll
2016-03-01 20:45 - 2007-06-25 22:21 - 00403456 _____ (NVIDIA Corporation) C:\windows\system32\nvcpl.cpl
2016-03-01 20:45 - 2007-06-25 22:21 - 00381952 _____ (NVIDIA Corporation) C:\windows\system32\nvexpBar.dll
2016-03-01 20:40 - 2016-03-25 21:36 - 00001450 _____ C:\Users\Public\Desktop\GeForce Experience.lnk
2016-03-01 20:34 - 2016-03-26 07:49 - 00110176 _____ (Oracle Corporation) C:\windows\system32\WindowsAccessBridge-64.dll
2016-03-01 20:34 - 2016-03-26 07:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2016-03-01 20:34 - 2016-03-26 07:49 - 00000000 ____D C:\Program Files\Java
2016-03-01 20:15 - 2016-03-01 20:15 - 00000000 ____D C:\ProgramData\NVIDIA
2016-03-01 20:15 - 2016-02-23 23:57 - 00215608 _____ (Khronos Group) C:\windows\system32\OpenCL.dll
2016-03-01 20:15 - 2016-02-23 23:57 - 00201664 _____ (Khronos Group) C:\windows\SysWOW64\OpenCL.dll
2016-03-01 20:15 - 2016-02-23 20:28 - 06368824 _____ (NVIDIA Corporation) C:\windows\system32\nvcpl.dll
2016-03-01 20:15 - 2016-02-23 20:28 - 06154909 _____ C:\windows\system32\nvcoproc.bin
2016-03-01 20:15 - 2016-02-23 20:28 - 02993720 _____ (NVIDIA Corporation) C:\windows\system32\nvsvc64.dll
2016-03-01 20:15 - 2016-02-23 20:28 - 02563128 _____ (NVIDIA Corporation) C:\windows\system32\nvsvcr.dll
2016-03-01 20:15 - 2016-02-23 20:28 - 01263040 _____ (NVIDIA Corporation) C:\windows\system32\nvvsvc.exe
2016-03-01 20:15 - 2016-02-23 20:28 - 00530368 _____ (NVIDIA Corporation) C:\windows\system32\nv3dappshext.dll
2016-03-01 20:15 - 2016-02-23 20:28 - 00393784 _____ (NVIDIA Corporation) C:\windows\system32\nvmctray.dll
2016-03-01 20:15 - 2016-02-23 20:28 - 00081856 _____ (NVIDIA Corporation) C:\windows\system32\nv3dappshextr.dll
2016-03-01 20:15 - 2016-02-23 20:28 - 00071224 _____ (NVIDIA Corporation) C:\windows\system32\nvshext.dll
2016-03-01 20:14 - 2016-02-25 01:04 - 12479040 _____ (NVIDIA Corporation) C:\windows\system32\Drivers\nvlddmkm.sys
2016-03-01 20:14 - 2016-02-23 23:57 - 42983480 _____ C:\windows\system32\nvcompiler.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 37616184 _____ C:\windows\SysWOW64\nvcompiler.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 31120952 _____ (NVIDIA Corporation) C:\windows\system32\nvoglv64.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 24944064 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvoglv32.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 21201784 _____ (NVIDIA Corporation) C:\windows\system32\nvopencl.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 20742072 _____ (NVIDIA Corporation) C:\windows\system32\nvcuda.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 19779456 _____ (NVIDIA Corporation) C:\windows\system32\nvwgf2umx.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 17631304 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvopencl.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 17224472 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvcuda.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 17175056 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvwgf2um.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 17117128 _____ (NVIDIA Corporation) C:\windows\system32\nvd3dumx.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 14115136 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvd3dum.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 03649760 _____ (NVIDIA Corporation) C:\windows\system32\nvapi64.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 03231360 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvapi.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 02541504 _____ (NVIDIA Corporation) C:\windows\system32\nvcuvid.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 02187712 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvcuvid.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 01924152 _____ (NVIDIA Corporation) C:\windows\system32\nvdispco6436200.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 01571776 _____ (NVIDIA Corporation) C:\windows\system32\nvdispgenco6436200.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 00950328 _____ (NVIDIA Corporation) C:\windows\system32\NvFBC64.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 00880576 _____ (NVIDIA Corporation) C:\windows\system32\NvIFR64.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 00786688 _____ (NVIDIA Corporation) C:\windows\system32\nvEncMFTH264.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 00784824 _____ (NVIDIA Corporation) C:\windows\system32\nvEncMFThevc.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 00747064 _____ (NVIDIA Corporation) C:\windows\SysWOW64\NvFBC.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 00689600 _____ (NVIDIA Corporation) C:\windows\SysWOW64\NvIFR.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 00632336 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvEncMFTH264.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 00630776 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvEncMFThevc.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 00601936 _____ C:\windows\system32\nvmcumd.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 00541184 _____ (NVIDIA Corporation) C:\windows\system32\nvumdshimx.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 00445912 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvumdshim.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 00425016 _____ (NVIDIA Corporation) C:\windows\system32\NvIFROpenGL.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 00383424 _____ (NVIDIA Corporation) C:\windows\system32\nvDecMFTMjpeg.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 00379448 _____ (NVIDIA Corporation) C:\windows\SysWOW64\NvIFROpenGL.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 00378968 _____ (NVIDIA Corporation) C:\windows\system32\nvEncodeAPI64.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 00346560 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvDecMFTMjpeg.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 00316960 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvEncodeAPI.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 00175552 _____ (NVIDIA Corporation) C:\windows\system32\nvinitx.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 00153208 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvinit.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 00151368 _____ (NVIDIA Corporation) C:\windows\system32\nvoglshim64.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 00128512 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvoglshim32.dll
2016-03-01 20:14 - 2016-02-23 23:57 - 00035832 _____ C:\windows\system32\nvinfo.pb
2016-03-01 19:47 - 2016-03-01 19:48 - 00000000 ____D C:\Users\willi\AppData\Local\NVIDIA
2016-03-01 19:47 - 2016-02-17 06:40 - 01903344 _____ (NVIDIA Corporation) C:\windows\system32\nvspcap64.dll
2016-03-01 19:47 - 2016-02-17 06:40 - 01756424 _____ (NVIDIA Corporation) C:\windows\system32\nvspbridge64.dll
2016-03-01 19:47 - 2016-02-17 06:40 - 01571624 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvspcap.dll
2016-03-01 19:47 - 2016-02-17 06:40 - 01316184 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvspbridge.dll
2016-03-01 19:47 - 2016-02-17 06:40 - 00112216 _____ C:\windows\system32\NvRtmpStreamer64.dll
2016-03-01 19:47 - 2015-12-18 06:11 - 00047760 _____ (NVIDIA Corporation) C:\windows\system32\Drivers\nvvad64v.sys
2016-03-01 19:47 - 2015-12-18 06:10 - 00099472 _____ (NVIDIA Corporation) C:\windows\system32\nvaudcap64v.dll
2016-03-01 19:47 - 2015-12-18 06:10 - 00090768 _____ (NVIDIA Corporation) C:\windows\SysWOW64\nvaudcap32v.dll
2016-03-01 19:11 - 2016-02-23 11:29 - 01030416 _____ (Microsoft Corporation) C:\windows\system32\winresume.efi
2016-03-01 19:11 - 2016-02-23 11:29 - 00874968 _____ (Microsoft Corporation) C:\windows\system32\winresume.exe
2016-03-01 19:11 - 2016-02-23 11:27 - 02654872 _____ C:\windows\system32\CoreUIComponents.dll
2016-03-01 19:11 - 2016-02-23 11:27 - 01317640 _____ (Microsoft Corporation) C:\windows\system32\winload.efi
2016-03-01 19:11 - 2016-02-23 11:27 - 01141504 _____ (Microsoft Corporation) C:\windows\system32\winload.exe
2016-03-01 19:11 - 2016-02-23 11:25 - 02152288 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ntfs.sys
2016-03-01 19:11 - 2016-02-23 11:25 - 01818696 _____ (Microsoft Corporation) C:\windows\system32\ntdll.dll
2016-03-01 19:11 - 2016-02-23 11:25 - 00563552 _____ (Microsoft Corporation) C:\windows\system32\Drivers\acpi.sys
2016-03-01 19:11 - 2016-02-23 11:15 - 00779384 _____ (Microsoft Corporation) C:\windows\system32\taskschd.dll
2016-03-01 19:11 - 2016-02-23 11:08 - 00989536 _____ (Microsoft Corporation) C:\windows\system32\SecConfig.efi
2016-03-01 19:11 - 2016-02-23 10:34 - 01859960 _____ C:\windows\SysWOW64\CoreUIComponents.dll
2016-03-01 19:11 - 2016-02-23 10:34 - 01542816 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntdll.dll
2016-03-01 19:11 - 2016-02-23 10:33 - 00696160 _____ (Microsoft Corporation) C:\windows\system32\NetSetupEngine.dll
2016-03-01 19:11 - 2016-02-23 10:33 - 00389992 _____ (Microsoft Corporation) C:\windows\system32\wlanapi.dll
2016-03-01 19:11 - 2016-02-23 10:32 - 08705672 _____ (Microsoft Corp.) C:\windows\system32\Windows.Media.Protection.PlayReady.dll
2016-03-01 19:11 - 2016-02-23 10:32 - 02544264 _____ (Microsoft Corporation) C:\windows\system32\mfcore.dll
2016-03-01 19:11 - 2016-02-23 10:32 - 01152328 _____ (Microsoft Corporation) C:\windows\system32\mfasfsrcsnk.dll
2016-03-01 19:11 - 2016-02-23 10:32 - 01062480 _____ (Microsoft Corporation) C:\windows\system32\mfmp4srcsnk.dll
2016-03-01 19:11 - 2016-02-23 10:32 - 00498448 _____ (Microsoft Corporation) C:\windows\system32\MFCaptureEngine.dll
2016-03-01 19:11 - 2016-02-23 10:32 - 00369912 _____ (Microsoft Corporation) C:\windows\system32\audiodg.exe
2016-03-01 19:11 - 2016-02-23 10:31 - 01017032 _____ (Microsoft Corporation) C:\windows\system32\mfsrcsnk.dll
2016-03-01 19:11 - 2016-02-23 10:31 - 00819648 _____ (Microsoft Corporation) C:\windows\system32\mfmpeg2srcsnk.dll
2016-03-01 19:11 - 2016-02-23 10:31 - 00536256 _____ (Microsoft Corporation) C:\windows\system32\AudioSes.dll
2016-03-01 19:11 - 2016-02-23 10:31 - 00476728 _____ (Microsoft Corporation) C:\windows\system32\msvproc.dll
2016-03-01 19:11 - 2016-02-23 10:31 - 00408120 _____ (Microsoft Corporation) C:\windows\system32\AUDIOKSE.dll
2016-03-01 19:11 - 2016-02-23 10:25 - 03671888 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2016-03-01 19:11 - 2016-02-23 10:22 - 00572272 _____ (Microsoft Corporation) C:\windows\SysWOW64\taskschd.dll
2016-03-01 19:11 - 2016-02-23 10:21 - 22564328 _____ (Microsoft Corporation) C:\windows\system32\shell32.dll
2016-03-01 19:11 - 2016-02-23 10:17 - 00146272 _____ (Microsoft Corporation) C:\windows\system32\Drivers\appid.sys
2016-03-01 19:11 - 2016-02-23 09:45 - 02773096 _____ (Microsoft Corporation) C:\windows\system32\d3d11.dll
2016-03-01 19:11 - 2016-02-23 09:40 - 00430944 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb.sys
2016-03-01 19:11 - 2016-02-23 09:39 - 00502112 _____ (Microsoft Corporation) C:\windows\SysWOW64\NetSetupEngine.dll
2016-03-01 19:11 - 2016-02-23 09:38 - 06952088 _____ (Microsoft Corp.) C:\windows\SysWOW64\Windows.Media.Protection.PlayReady.dll
2016-03-01 19:11 - 2016-02-23 09:38 - 02180136 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfcore.dll
2016-03-01 19:11 - 2016-02-23 09:38 - 00980352 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfasfsrcsnk.dll
2016-03-01 19:11 - 2016-02-23 09:38 - 00895080 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfsrcsnk.dll
2016-03-01 19:11 - 2016-02-23 09:38 - 00882720 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfmp4srcsnk.dll
2016-03-01 19:11 - 2016-02-23 09:38 - 00450912 _____ (Microsoft Corporation) C:\windows\SysWOW64\MFCaptureEngine.dll
2016-03-01 19:11 - 2016-02-23 09:38 - 00420928 _____ (Microsoft Corporation) C:\windows\SysWOW64\msvproc.dll
2016-03-01 19:11 - 2016-02-23 09:37 - 00713824 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfmpeg2srcsnk.dll
2016-03-01 19:11 - 2016-02-23 09:32 - 00791744 _____ (Microsoft Corporation) C:\windows\system32\generaltel.dll
2016-03-01 19:11 - 2016-02-23 09:30 - 02919320 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2016-03-01 19:11 - 2016-02-23 09:27 - 21124344 _____ (Microsoft Corporation) C:\windows\SysWOW64\shell32.dll
2016-03-01 19:11 - 2016-02-23 09:27 - 00376536 _____ (Microsoft Corporation) C:\windows\system32\Windows.Media.MediaControl.dll
2016-03-01 19:11 - 2016-02-23 09:25 - 00534368 _____ (Microsoft Corporation) C:\windows\system32\Drivers\USBHUB3.SYS
2016-03-01 19:11 - 2016-02-23 09:20 - 01139712 _____ (Microsoft Corporation) C:\windows\system32\XblGameSave.dll
2016-03-01 19:11 - 2016-02-23 09:20 - 00238592 _____ (Microsoft Corporation) C:\windows\system32\Drivers\xboxgip.sys
2016-03-01 19:11 - 2016-02-23 09:19 - 00029696 _____ (Microsoft Corporation) C:\windows\system32\Drivers\xinputhid.sys
2016-03-01 19:11 - 2016-02-23 09:17 - 00649216 _____ (Microsoft Corporation) C:\windows\system32\ngcsvc.dll
2016-03-01 19:11 - 2016-02-23 09:12 - 00077824 _____ (Microsoft Corporation) C:\windows\system32\provpackageapidll.dll
2016-03-01 19:11 - 2016-02-23 09:10 - 00027648 _____ (Microsoft Corporation) C:\windows\system32\WiFiConfigSP.dll
2016-03-01 19:11 - 2016-02-23 09:07 - 00037376 _____ (Microsoft Corporation) C:\windows\system32\LaunchWinApp.exe
2016-03-01 19:11 - 2016-02-23 09:07 - 00026112 _____ (Microsoft Corporation) C:\windows\system32\wlansvcpal.dll
2016-03-01 19:11 - 2016-02-23 09:06 - 00129536 _____ (Microsoft Corporation) C:\windows\system32\flvprophandler.dll
2016-03-01 19:11 - 2016-02-23 09:01 - 00104960 _____ (Microsoft Corporation) C:\windows\system32\Drivers\rasl2tp.sys
2016-03-01 19:11 - 2016-02-23 09:00 - 00069632 _____ (Microsoft Corporation) C:\windows\system32\EnterpriseDesktopAppMgmtCSP.dll
2016-03-01 19:11 - 2016-02-23 09:00 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\wfdprov.dll
2016-03-01 19:11 - 2016-02-23 08:58 - 00069632 _____ (Microsoft Corporation) C:\windows\system32\wininetlui.dll
2016-03-01 19:11 - 2016-02-23 08:58 - 00052224 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2016-03-01 19:11 - 2016-02-23 08:58 - 00025088 _____ (Microsoft Corporation) C:\windows\system32\irmon.dll
2016-03-01 19:11 - 2016-02-23 08:57 - 00199168 _____ (Microsoft Corporation) C:\windows\system32\InstallAgent.exe
2016-03-01 19:11 - 2016-02-23 08:56 - 02186864 _____ (Microsoft Corporation) C:\windows\SysWOW64\d3d11.dll
2016-03-01 19:11 - 2016-02-23 08:55 - 00114688 _____ (Microsoft Corporation) C:\windows\system32\Drivers\bridge.sys
2016-03-01 19:11 - 2016-02-23 08:53 - 00115712 _____ (Microsoft Corporation) C:\windows\system32\srpapi.dll
2016-03-01 19:11 - 2016-02-23 08:53 - 00099328 _____ (Microsoft Corporation) C:\windows\system32\ngckeyenum.dll
2016-03-01 19:11 - 2016-02-23 08:52 - 00087040 _____ (Microsoft Corporation) C:\windows\system32\MDMAppInstaller.exe
2016-03-01 19:11 - 2016-02-23 08:50 - 00159232 _____ (Microsoft Corporation) C:\windows\system32\DeviceCensus.exe
2016-03-01 19:11 - 2016-02-23 08:48 - 00086528 _____ (Microsoft Corporation) C:\windows\system32\AppCapture.dll
2016-03-01 19:11 - 2016-02-23 08:48 - 00041984 _____ (Microsoft Corporation) C:\windows\system32\TimeBrokerClient.dll
2016-03-01 19:11 - 2016-02-23 08:40 - 00074240 _____ (Microsoft Corporation) C:\windows\system32\SMSRouter.dll
2016-03-01 19:11 - 2016-02-23 08:39 - 00178176 _____ (Microsoft Corporation) C:\windows\system32\psmsrv.dll
2016-03-01 19:11 - 2016-02-23 08:38 - 00320000 _____ (Microsoft Corporation) C:\windows\system32\MSFlacDecoder.dll
2016-03-01 19:11 - 2016-02-23 08:38 - 00287712 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.Media.MediaControl.dll
2016-03-01 19:11 - 2016-02-23 08:37 - 00617984 _____ (Microsoft Corporation) C:\windows\system32\StorSvc.dll
2016-03-01 19:11 - 2016-02-23 08:37 - 00274944 _____ (Microsoft Corporation) C:\windows\system32\DisplayManager.dll
2016-03-01 19:11 - 2016-02-23 08:37 - 00204288 _____ (Microsoft Corporation) C:\windows\system32\NetSetupSvc.dll
2016-03-01 19:11 - 2016-02-23 08:36 - 00216576 _____ (Microsoft Corporation) C:\windows\system32\QuickActionsDataModel.dll
2016-03-01 19:11 - 2016-02-23 08:34 - 00305664 _____ (Microsoft Corporation) C:\windows\system32\wifiprofilessettinghandler.dll
2016-03-01 19:11 - 2016-02-23 08:34 - 00189952 _____ (Microsoft Corporation) C:\windows\system32\WiFiDisplay.dll
2016-03-01 19:11 - 2016-02-23 08:33 - 00558080 _____ (Microsoft Corporation) C:\windows\system32\MBMediaManager.dll
2016-03-01 19:11 - 2016-02-23 08:32 - 00414720 _____ (Microsoft Corporation) C:\windows\system32\bcastdvr.exe
2016-03-01 19:11 - 2016-02-23 08:31 - 00463360 _____ (Microsoft Corporation) C:\windows\system32\wlansec.dll
2016-03-01 19:11 - 2016-02-23 08:29 - 00591872 _____ (Microsoft Corporation) C:\windows\system32\SmsRouterSvc.dll
2016-03-01 19:11 - 2016-02-23 08:28 - 00275456 _____ (Microsoft Corporation) C:\windows\system32\AudioEndpointBuilder.dll
2016-03-01 19:11 - 2016-02-23 08:27 - 00307712 _____ (Microsoft Corporation) C:\windows\system32\usbmon.dll
2016-03-01 19:11 - 2016-02-23 08:26 - 00372224 _____ (Microsoft Corporation) C:\windows\system32\MDEServer.exe
2016-03-01 19:11 - 2016-02-23 08:23 - 00412672 _____ (Microsoft Corporation) C:\windows\system32\wlanmsm.dll
2016-03-01 19:11 - 2016-02-23 08:22 - 00567808 _____ (Microsoft Corporation) C:\windows\system32\MCRecvSrc.dll
2016-03-01 19:11 - 2016-02-23 08:20 - 00847360 _____ (Microsoft Corporation) C:\windows\system32\netlogon.dll
2016-03-01 19:11 - 2016-02-23 08:20 - 00606720 _____ (Microsoft Corporation) C:\windows\system32\wcmsvc.dll
2016-03-01 19:11 - 2016-02-23 08:20 - 00493568 _____ (Microsoft Corporation) C:\windows\system32\mfmkvsrcsnk.dll
2016-03-01 19:11 - 2016-02-23 08:20 - 00330240 _____ (Microsoft Corporation) C:\windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2016-03-01 19:11 - 2016-02-23 08:19 - 00948736 _____ (Microsoft Corporation) C:\windows\system32\XblAuthManager.dll
2016-03-01 19:11 - 2016-02-23 08:19 - 00517632 _____ (Microsoft Corporation) C:\windows\system32\winspool.drv
2016-03-01 19:11 - 2016-02-23 08:18 - 00557056 _____ (Microsoft Corporation) C:\windows\system32\PsmServiceExtHost.dll
2016-03-01 19:11 - 2016-02-23 08:14 - 00828928 _____ (Microsoft Corporation) C:\windows\system32\Windows.AccountsControl.dll
2016-03-01 19:11 - 2016-02-23 08:14 - 00029696 _____ (Microsoft Corporation) C:\windows\SysWOW64\LaunchWinApp.exe
2016-03-01 19:11 - 2016-02-23 08:12 - 00852480 _____ (Microsoft Corporation) C:\windows\system32\Windows.ApplicationModel.Store.dll
2016-03-01 19:11 - 2016-02-23 08:11 - 00587776 _____ (Microsoft Corporation) C:\windows\system32\bisrv.dll
2016-03-01 19:11 - 2016-02-23 08:10 - 00997376 _____ (Microsoft Corporation) C:\windows\system32\schedsvc.dll
2016-03-01 19:11 - 2016-02-23 08:10 - 00474624 _____ (Microsoft Corporation) C:\windows\system32\NetSetupShim.dll
2016-03-01 19:11 - 2016-02-23 08:09 - 01054208 _____ (Microsoft Corporation) C:\windows\system32\audiosrv.dll
2016-03-01 19:11 - 2016-02-23 08:09 - 00988160 _____ (Microsoft Corporation) C:\windows\system32\SharedStartModel.dll
2016-03-01 19:11 - 2016-02-23 08:09 - 00870400 _____ (Microsoft Corporation) C:\windows\system32\modernexecserver.dll
2016-03-01 19:11 - 2016-02-23 08:06 - 01213440 _____ (Microsoft Corporation) C:\windows\system32\wwansvc.dll
2016-03-01 19:11 - 2016-02-23 08:06 - 00065536 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininetlui.dll
2016-03-01 19:11 - 2016-02-23 08:06 - 00045568 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2016-03-01 19:11 - 2016-02-23 08:05 - 00161280 _____ (Microsoft Corporation) C:\windows\SysWOW64\InstallAgent.exe
2016-03-01 19:11 - 2016-02-23 08:04 - 01131520 _____ (Microsoft Corporation) C:\windows\system32\Windows.Media.Audio.dll
2016-03-01 19:11 - 2016-02-23 08:04 - 00673792 _____ (Microsoft Corporation) C:\windows\system32\Windows.UI.dll
2016-03-01 19:11 - 2016-02-23 08:04 - 00382464 _____ (Microsoft Corporation) C:\windows\system32\wuuhext.dll
2016-03-01 19:11 - 2016-02-23 08:02 - 01318912 _____ (Microsoft Corporation) C:\windows\system32\wifinetworkmanager.dll
2016-03-01 19:11 - 2016-02-23 08:02 - 00755712 _____ (Microsoft Corporation) C:\windows\system32\spoolsv.exe
2016-03-01 19:11 - 2016-02-23 08:02 - 00285696 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb10.sys
2016-03-01 19:11 - 2016-02-23 08:00 - 02624512 _____ (Microsoft Corporation) C:\windows\system32\InputService.dll
2016-03-01 19:11 - 2016-02-23 07:58 - 00345600 _____ (Microsoft Corporation) C:\windows\system32\TextInputFramework.dll
2016-03-01 19:11 - 2016-02-23 07:58 - 00175616 _____ (Microsoft Corporation) C:\windows\system32\Windows.UI.Core.TextInput.dll
2016-03-01 19:11 - 2016-02-23 07:58 - 00163840 _____ (Microsoft Corporation) C:\windows\system32\TimeBrokerServer.dll
2016-03-01 19:11 - 2016-02-23 07:58 - 00108544 _____ (Microsoft Corporation) C:\windows\system32\InputLocaleManager.dll
2016-03-01 19:11 - 2016-02-23 07:57 - 00031744 _____ (Microsoft Corporation) C:\windows\SysWOW64\TimeBrokerClient.dll
2016-03-01 19:11 - 2016-02-23 07:52 - 00456704 _____ (Microsoft Corporation) C:\windows\system32\ipnathlp.dll
2016-03-01 19:11 - 2016-02-23 07:50 - 00266752 _____ (Microsoft Corporation) C:\windows\SysWOW64\MSFlacDecoder.dll
2016-03-01 19:11 - 2016-02-23 07:49 - 00200704 _____ (Microsoft Corporation) C:\windows\SysWOW64\DisplayManager.dll
2016-03-01 19:11 - 2016-02-23 07:48 - 00838144 _____ (Microsoft Corporation) C:\windows\system32\uDWM.dll
2016-03-01 19:11 - 2016-02-23 07:47 - 00157184 _____ (Microsoft Corporation) C:\windows\SysWOW64\WiFiDisplay.dll
2016-03-01 19:11 - 2016-02-23 07:38 - 00480256 _____ (Microsoft Corporation) C:\windows\SysWOW64\MCRecvSrc.dll
2016-03-01 19:11 - 2016-02-23 07:37 - 01118208 _____ (Microsoft Corporation) C:\windows\system32\localspl.dll
2016-03-01 19:11 - 2016-02-23 07:37 - 00613376 _____ (Microsoft Corporation) C:\windows\system32\SettingSync.dll
2016-03-01 19:11 - 2016-02-23 07:36 - 00713728 _____ (Microsoft Corporation) C:\windows\SysWOW64\netlogon.dll
2016-03-01 19:11 - 2016-02-23 07:36 - 00379392 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfmkvsrcsnk.dll
2016-03-01 19:11 - 2016-02-23 07:36 - 00250880 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2016-03-01 19:11 - 2016-02-23 07:35 - 00400896 _____ (Microsoft Corporation) C:\windows\SysWOW64\winspool.drv
2016-03-01 19:11 - 2016-02-23 07:31 - 00585216 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.AccountsControl.dll
2016-03-01 19:11 - 2016-02-23 07:30 - 01731584 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2016-03-01 19:11 - 2016-02-23 07:30 - 00646656 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.ApplicationModel.Store.dll
2016-03-01 19:11 - 2016-02-23 07:29 - 00349696 _____ (Microsoft Corporation) C:\windows\SysWOW64\NetSetupShim.dll
2016-03-01 19:11 - 2016-02-23 07:28 - 00555520 _____ (Microsoft Corporation) C:\windows\system32\SyncController.dll
2016-03-01 19:11 - 2016-02-23 07:28 - 00256512 _____ (Microsoft Corporation) C:\windows\system32\accountaccessor.dll
2016-03-01 19:11 - 2016-02-23 07:24 - 04827136 _____ (Microsoft Corporation) C:\windows\system32\ExplorerFrame.dll
2016-03-01 19:11 - 2016-02-23 07:24 - 02755584 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2016-03-01 19:11 - 2016-02-23 07:24 - 01105920 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.Media.Audio.dll
2016-03-01 19:11 - 2016-02-23 07:24 - 00489984 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.UI.dll
2016-03-01 19:11 - 2016-02-23 07:22 - 01944576 _____ (Microsoft Corporation) C:\windows\SysWOW64\InputService.dll
2016-03-01 19:11 - 2016-02-23 07:21 - 00245760 _____ (Microsoft Corporation) C:\windows\SysWOW64\TextInputFramework.dll
2016-03-01 19:11 - 2016-02-23 07:21 - 00133632 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.UI.Core.TextInput.dll
2016-03-01 19:11 - 2016-02-23 07:20 - 00083456 _____ (Microsoft Corporation) C:\windows\SysWOW64\InputLocaleManager.dll
2016-03-01 19:11 - 2016-02-23 07:17 - 02635264 _____ (Microsoft Corporation) C:\windows\system32\Windows.UI.Logon.dll
2016-03-01 19:11 - 2016-02-23 07:14 - 00990720 _____ (Microsoft Corporation) C:\windows\system32\SettingSyncCore.dll
2016-03-01 19:11 - 2016-02-23 07:11 - 01390080 _____ (Microsoft Corporation) C:\windows\system32\Windows.UI.Shell.dll
2016-03-01 19:11 - 2016-02-23 07:05 - 00503296 _____ (Microsoft Corporation) C:\windows\SysWOW64\SettingSync.dll
2016-03-01 19:11 - 2016-02-23 07:01 - 02295808 _____ (Microsoft Corporation) C:\windows\system32\wlansvc.dll
2016-03-01 19:11 - 2016-02-23 06:59 - 01500672 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2016-03-01 19:11 - 2016-02-23 06:58 - 00450560 _____ (Microsoft Corporation) C:\windows\SysWOW64\SyncController.dll
2016-03-01 19:11 - 2016-02-23 06:56 - 04412928 _____ (Microsoft Corporation) C:\windows\SysWOW64\ExplorerFrame.dll
2016-03-01 19:11 - 2016-02-23 06:55 - 04894208 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2016-03-01 19:11 - 2016-02-23 06:55 - 02229760 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2016-03-01 19:11 - 2016-02-23 06:53 - 01799168 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.UI.Logon.dll
2016-03-01 19:11 - 2016-02-23 06:52 - 11545600 _____ (Microsoft Corporation) C:\windows\system32\twinui.dll
2016-03-01 19:11 - 2016-02-23 06:51 - 00754176 _____ (Microsoft Corporation) C:\windows\SysWOW64\SettingSyncCore.dll
2016-03-01 19:11 - 2016-02-23 06:50 - 09919488 _____ (Microsoft Corporation) C:\windows\SysWOW64\twinui.dll
2016-03-01 19:11 - 2016-02-23 06:42 - 03425792 _____ (Microsoft Corporation) C:\windows\system32\Windows.Media.dll
2016-03-01 19:11 - 2016-02-23 06:41 - 02912256 _____ (Microsoft Corporation) C:\windows\system32\CertEnroll.dll
2016-03-01 19:11 - 2016-02-23 06:39 - 13382656 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2016-03-01 19:11 - 2016-02-23 06:39 - 02581504 _____ (Microsoft Corporation) C:\windows\system32\MFMediaEngine.dll
2016-03-01 19:11 - 2016-02-23 06:36 - 12125696 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2016-03-01 19:11 - 2016-02-23 06:36 - 03666432 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2016-03-01 19:11 - 2016-02-23 06:35 - 07533568 _____ (Microsoft Corporation) C:\windows\system32\mstscax.dll
2016-03-01 19:11 - 2016-02-23 06:33 - 02604032 _____ (Microsoft Corporation) C:\windows\SysWOW64\CertEnroll.dll
2016-03-01 19:11 - 2016-02-23 06:32 - 02793472 _____ (Microsoft Corporation) C:\windows\SysWOW64\Windows.Media.dll
2016-03-01 19:11 - 2016-02-23 06:30 - 02061312 _____ (Microsoft Corporation) C:\windows\SysWOW64\MFMediaEngine.dll
2016-03-01 19:11 - 2016-02-23 06:28 - 06740992 _____ (Microsoft Corporation) C:\windows\SysWOW64\mstscax.dll
2016-03-01 19:11 - 2016-02-09 04:28 - 00277856 _____ (Microsoft Corporation) C:\windows\system32\Drivers\sdbus.sys
2016-03-01 19:11 - 2016-02-09 04:13 - 00185184 _____ (Microsoft Corporation) C:\windows\system32\Drivers\dumpsd.sys
2016-03-01 19:11 - 2016-02-09 03:24 - 00641536 _____ (Microsoft Corporation) C:\windows\system32\enterprisecsps.dll
2016-03-01 19:11 - 2016-02-09 03:18 - 00297472 _____ (Microsoft Corporation) C:\windows\system32\thumbcache.dll
2016-03-01 19:11 - 2016-02-09 03:18 - 00237056 _____ (Microsoft Corporation) C:\windows\SysWOW64\thumbcache.dll
2016-03-01 19:11 - 2016-02-09 03:07 - 01626624 _____ (Microsoft Corporation) C:\windows\SysWOW64\dwmcore.dll
2016-03-01 19:11 - 2016-02-09 03:07 - 00086016 _____ (Microsoft Corporation) C:\windows\system32\DeviceEnroller.exe
2016-03-01 19:11 - 2016-02-09 03:04 - 01946624 _____ (Microsoft Corporation) C:\windows\system32\dwmcore.dll
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-03-26 13:29 - 2016-01-01 22:51 - 00000000 ____D C:\Users\willi\AppData\Roaming\Curse Client
2016-03-26 13:29 - 2016-01-01 22:38 - 00000000 ____D C:\Users\willi\AppData\Local\Deployment
2016-03-26 13:29 - 2015-12-27 16:33 - 00000000 ____D C:\Users\willi\AppData\Roaming\Skype
2016-03-26 13:28 - 2015-12-25 09:11 - 00000924 _____ C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-03-26 13:28 - 2015-12-14 15:14 - 00000006 ____H C:\windows\Tasks\SA.DAT
2016-03-26 13:27 - 2015-10-30 06:28 - 00524288 ___SH C:\windows\system32\config\BBI
2016-03-26 13:20 - 2015-12-25 09:11 - 00000928 _____ C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-03-26 13:19 - 2015-12-14 15:19 - 00881036 _____ C:\windows\system32\PerfStringBackup.INI
2016-03-26 13:19 - 2015-10-30 07:21 - 00000000 ____D C:\windows\INF
2016-03-26 13:08 - 2015-12-15 11:54 - 00000000 ____D C:\windows\system32\temp
2016-03-26 07:49 - 2015-12-25 19:36 - 00000000 ____D C:\Users\willi\.oracle_jre_usage
2016-03-26 07:48 - 2016-01-31 02:01 - 00000000 ____D C:\Users\willi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2016-03-26 07:48 - 2016-01-31 02:01 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2016-03-26 07:48 - 2016-01-31 02:01 - 00000000 ____D C:\Program Files\WinRAR
2016-03-26 07:45 - 2015-12-25 19:36 - 00004166 _____ C:\windows\System32\Tasks\User_Feed_Synchronization-{1D84A35C-070A-44DA-9AB2-285C5EA815E7}
2016-03-26 07:43 - 2015-10-30 07:24 - 00000000 ____D C:\windows\system32\NDF
2016-03-25 22:26 - 2015-12-25 09:09 - 00000000 ___RD C:\Users\willi\OneDrive
2016-03-25 21:36 - 2016-01-24 23:17 - 00001001 _____ C:\Users\Public\Desktop\Guild Wars 2.lnk
2016-03-25 21:36 - 2016-01-21 08:27 - 00001579 _____ C:\Users\Public\Desktop\League of Legends.lnk
2016-03-25 21:36 - 2016-01-01 22:51 - 00001093 _____ C:\Users\willi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Curse.lnk
2016-03-25 21:36 - 2016-01-01 22:51 - 00001087 _____ C:\Users\willi\Desktop\Curse.lnk
2016-03-25 21:36 - 2015-12-29 18:13 - 00000588 _____ C:\Users\willi\Desktop\Speccy.lnk
2016-03-25 21:36 - 2015-12-28 22:26 - 00000826 _____ C:\Users\Public\Desktop\Battle.net.lnk
2016-03-25 21:36 - 2015-12-27 16:33 - 00002634 _____ C:\Users\Public\Desktop\Skype.lnk
2016-03-25 21:36 - 2015-12-25 20:19 - 00001051 _____ C:\Users\Public\Desktop\Gyazo.lnk
2016-03-25 21:36 - 2015-12-25 18:02 - 00001286 _____ C:\Users\willi\Desktop\TeamSpeak 3 Client.lnk
2016-03-25 21:36 - 2015-12-25 09:12 - 00002338 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-03-25 21:36 - 2015-12-25 09:09 - 00002367 _____ C:\Users\willi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2016-03-25 21:36 - 2015-12-15 11:54 - 00001273 _____ C:\Users\Public\Desktop\3DMark.lnk
2016-03-25 21:35 - 2015-10-30 09:02 - 00000000 ____D C:\windows\DigitalLocker
2016-03-25 21:04 - 2015-10-30 07:24 - 00000000 ___HD C:\Program Files\WindowsApps
2016-03-25 21:04 - 2015-10-30 07:24 - 00000000 ____D C:\windows\AppReadiness
2016-03-25 20:57 - 2015-12-25 18:03 - 00000000 ____D C:\Users\willi\AppData\Roaming\TS3Client
2016-03-25 20:57 - 2015-12-14 15:24 - 00000000 __RHD C:\Users\Public\AccountPictures
2016-03-23 08:48 - 2015-12-25 18:56 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2016-03-23 08:24 - 2015-12-27 16:33 - 00000000 ___RD C:\Program Files (x86)\Skype
2016-03-23 08:24 - 2015-12-27 16:33 - 00000000 ____D C:\ProgramData\Skype
2016-03-22 23:09 - 2015-12-29 18:46 - 00000000 ____D C:\Users\willi\AppData\Local\CrashDumps
2016-03-22 20:31 - 2015-10-30 07:11 - 00000000 ____D C:\windows\CbsTemp
2016-03-22 00:19 - 2015-12-28 22:26 - 00000000 ____D C:\Users\willi\AppData\Local\Battle.net
2016-03-13 20:44 - 2015-12-28 22:26 - 00000000 ____D C:\Users\willi\AppData\Roaming\Battle.net
2016-03-13 20:44 - 2015-12-28 22:23 - 00000000 ____D C:\ProgramData\Battle.net
2016-03-12 19:02 - 2015-12-25 09:06 - 00000000 ____D C:\Users\willi
2016-03-11 20:47 - 2015-12-25 21:08 - 00000000 ____D C:\Users\willi\Documents\My Games
2016-03-09 17:46 - 2015-12-14 15:09 - 00348872 _____ C:\windows\system32\FNTCACHE.DAT
2016-03-09 00:30 - 2015-10-30 07:24 - 00000000 ____D C:\Program Files\Windows Portable Devices
2016-03-09 00:30 - 2015-10-30 07:24 - 00000000 ____D C:\Program Files\Windows Multimedia Platform
2016-03-09 00:30 - 2015-10-30 07:24 - 00000000 ____D C:\Program Files (x86)\Windows Portable Devices
2016-03-09 00:30 - 2015-10-30 07:24 - 00000000 ____D C:\Program Files (x86)\Windows Multimedia Platform
2016-03-08 18:52 - 2015-12-15 14:07 - 00000000 ____D C:\windows\system32\MRT
2016-03-08 18:50 - 2015-12-15 14:07 - 143659408 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2016-03-08 07:12 - 2015-10-30 07:26 - 00829944 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2016-03-08 07:12 - 2015-10-30 07:26 - 00176632 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2016-03-06 17:00 - 2016-02-22 20:42 - 00000000 ____D C:\Users\willi\AppData\Local\Frontier_Developments
2016-03-06 10:59 - 2015-12-25 09:43 - 00000000 ____D C:\Users\willi\AppData\Roaming\.minecraft
2016-03-05 19:14 - 2015-12-25 09:11 - 00003986 _____ C:\windows\System32\Tasks\GoogleUpdateTaskMachineUA
2016-03-05 19:14 - 2015-12-25 09:11 - 00003754 _____ C:\windows\System32\Tasks\GoogleUpdateTaskMachineCore
2016-03-02 17:41 - 2015-10-30 07:24 - 00000000 ____D C:\windows\rescache
2016-03-02 08:00 - 2015-12-25 20:19 - 00003544 _____ C:\windows\System32\Tasks\GyazoUpdateTaskMachineDaily
2016-03-02 08:00 - 2015-12-25 20:19 - 00003408 _____ C:\windows\System32\Tasks\GyazoUpdateTaskMachine
2016-03-02 08:00 - 2015-12-25 20:19 - 00000000 ____D C:\Program Files (x86)\Gyazo
2016-03-01 20:45 - 2015-12-15 11:51 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2016-03-01 20:45 - 2015-12-15 11:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2016-03-01 20:45 - 2015-12-15 11:49 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2016-03-01 20:16 - 2015-10-30 09:07 - 00000000 ____D C:\Program Files\Windows Journal
2016-03-01 20:16 - 2015-10-30 07:24 - 00000000 __RSD C:\windows\Media
2016-03-01 20:16 - 2015-10-30 07:24 - 00000000 ___RD C:\windows\PurchaseDialog
2016-03-01 20:16 - 2015-10-30 07:24 - 00000000 ____D C:\windows\system32\WinBioPlugIns
2016-03-01 20:16 - 2015-10-30 07:24 - 00000000 ____D C:\windows\system32\SystemResetPlatform
2016-03-01 20:16 - 2015-10-30 07:24 - 00000000 ____D C:\windows\system32\appraiser
2016-03-01 20:16 - 2015-10-30 07:24 - 00000000 ____D C:\windows\bcastdvr
2016-03-01 20:16 - 2015-10-30 06:28 - 00000000 ____D C:\windows\SysWOW64\Dism
2016-03-01 20:16 - 2015-10-30 06:28 - 00000000 ____D C:\windows\system32\Dism
2016-03-01 20:15 - 2015-12-15 11:48 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2016-03-01 20:15 - 2015-10-30 07:24 - 00000000 ____D C:\windows\Help
2016-03-01 20:14 - 2015-12-15 11:49 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2016-03-01 19:29 - 2015-12-25 09:07 - 00000000 ____D C:\Users\willi\AppData\Local\NVIDIA Corporation
==================== Files in the root of some directories =======
2016-03-23 08:57 - 2016-03-23 08:57 - 6493696 _____ () C:\Users\willi\AppData\Roaming\agent.dat
2016-03-23 08:57 - 2016-03-23 08:57 - 0127488 _____ () C:\Users\willi\AppData\Roaming\Installer.dat
2016-03-23 08:57 - 2016-03-23 08:57 - 0072707 _____ () C:\Users\willi\AppData\Roaming\Jaytom.tst
2016-03-23 08:57 - 2016-03-23 08:57 - 0018432 _____ () C:\Users\willi\AppData\Roaming\Main.dat
2016-03-23 08:57 - 2016-03-23 08:57 - 1622132 _____ () C:\Users\willi\AppData\Roaming\Zimlux.tst
2015-12-15 11:52 - 2015-12-15 11:52 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
Some files in TEMP:
====================
C:\Users\willi\AppData\Local\Temp\sqlite3.dll
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\windows\system32\winlogon.exe => File is digitally signed
C:\windows\system32\wininit.exe => File is digitally signed
C:\windows\explorer.exe => File is digitally signed
C:\windows\SysWOW64\explorer.exe => File is digitally signed
C:\windows\system32\svchost.exe => File is digitally signed
C:\windows\SysWOW64\svchost.exe => File is digitally signed
C:\windows\system32\services.exe => File is digitally signed
C:\windows\system32\User32.dll => File is digitally signed
C:\windows\SysWOW64\User32.dll => File is digitally signed
C:\windows\system32\userinit.exe => File is digitally signed
C:\windows\SysWOW64\userinit.exe => File is digitally signed
C:\windows\system32\rpcss.dll => File is digitally signed
C:\windows\system32\dnsapi.dll => File is digitally signed
C:\windows\SysWOW64\dnsapi.dll
[2015-10-30 07:18] - [2015-10-30 07:18] - 0535088 ____A () D41D8CD98F00B204E9800998ECF8427E
C:\windows\SysWOW64\dnsapi.dll => no Company Name <===== ATTENTION
C:\windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2016-03-23 15:23
==================== End of FRST.txt ============================
Additional scan result of Farbar Recovery Scan Tool (x64) Version:05-03-2016 01
Ran by willi (2016-03-26 13:31:53)
Running from C:\Users\willi\Desktop
Windows 10 Home Version 1511 (X64) (2015-12-25 09:05:47)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-3667704814-1699542734-850788743-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-3667704814-1699542734-850788743-503 - Limited - Disabled)
Guest (S-1-5-21-3667704814-1699542734-850788743-501 - Limited - Disabled)
willi (S-1-5-21-3667704814-1699542734-850788743-1002 - Administrator - Enabled) => C:\Users\willi
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
3DMark (HKLM-x32\...\{12d6e0d7-21d5-4755-9da2-70352c6f7558}) (Version: 1.5.915.0 - Futuremark)
3DMark (Version: 1.5.915.0 - Futuremark) Hidden
Asmedia ASM106x SATA Host Controller Driver (HKLM-x32\...\{61942EF5-2CD8-47D4-869C-2E9A8BB085F1}) (Version: 2.0.9.0001 - Asmedia Technology)
Avast Free Antivirus (HKLM-x32\...\Avast) (Version: 11.1.2253 - AVAST Software)
Awesomenauts (HKLM-x32\...\Steam App 204300) (Version: - Ronimo Games)
Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment)
Block N Load (HKLM-x32\...\Steam App 299360) (Version: - Jagex)
BurnInTest v8.0 Pro (HKLM\...\BurnInTest_is1) (Version: 8.0.1041.0 - Passmark Software)
Counter-Strike (HKLM\...\Steam App 10) (Version: - Valve)
Counter-Strike: Condition Zero (HKLM\...\Steam App 80) (Version: - Valve)
Counter-Strike: Global Offensive (HKLM-x32\...\Steam App 730) (Version: - Valve)
Counter-Strike: Source (HKLM-x32\...\Steam App 240) (Version: - Valve)
Curse (HKLM-x32\...\{DEE70742-F4E9-44CA-B2B9-EE95DCF37295}) (Version: 6.0.0.0 - Curse)
Curse Client (HKU\S-1-5-21-3667704814-1699542734-850788743-1002\...\101a9f93b8f0bb6f) (Version: 5.1.1.844 - Curse)
Day of Defeat: Source (HKLM\...\Steam App 300) (Version: - Valve)
Dungeon Defenders II (HKLM-x32\...\Steam App 236110) (Version: - Trendy Entertainment)
Elite Dangerous (HKLM-x32\...\Steam App 359320) (Version: - Frontier Developments)
Futuremark SystemInfo (HKLM-x32\...\{70690D9E-3D00-47D6-9CE9-BC3B6F900447}) (Version: 4.41.563.0 - Futuremark)
Garry's Mod (HKLM-x32\...\Steam App 4000) (Version: - Facepunch Studios)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 49.0.2623.87 - Google Inc.)
Google Update Helper (x32 Version: 1.3.29.5 - Google Inc.) Hidden
Grand Theft Auto V (HKLM-x32\...\Steam App 271590) (Version: - Rockstar North)
Guild Wars 2 (HKLM-x32\...\Guild Wars 2) (Version: - NCsoft Corporation, Ltd.)
Guns of Icarus Online (HKLM-x32\...\Steam App 209080) (Version: - Muse Games)
Gyazo 3.2.1 (HKLM-x32\...\{6DB8C365-E719-4BA5-9594-10DFC244D3FD}_is1) (Version: - Nota Inc.)
Half-Life (HKLM-x32\...\Steam App 70) (Version: - Valve)
Half-Life 2 (HKLM-x32\...\Steam App 220) (Version: - Valve)
Half-Life 2: Episode One (HKLM-x32\...\Steam App 380) (Version: - Valve)
Half-Life 2: Episode Two (HKLM-x32\...\Steam App 420) (Version: - Valve)
Half-Life 2: Lost Coast (HKLM\...\Steam App 340) (Version: - Valve)
Half-Life: Source (HKLM\...\Steam App 280) (Version: - Valve)
Hearthstone (HKLM-x32\...\Hearthstone) (Version: - Blizzard Entertainment)
Intel® Chipset Device Software (x32 Version: 10.0.27 - Intel® Corporation) Hidden
Intel® Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 10.0.1.1000 - Intel Corporation)
Intel® Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 14.5.0.1081 - Intel Corporation)
Intel® Update Manager (HKLM-x32\...\{B991A1BC-DE0F-41B3-9037-B2F948F706EC}) (Version: 3.1.1228 - Intel Corporation)
Java 8 Update 73 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86418073F0}) (Version: 8.0.730.2 - Oracle Corporation)
Java 8 Update 74 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86418074F0}) (Version: 8.0.740.2 - Oracle Corporation)
Kerbal Space Program (HKLM-x32\...\Steam App 220200) (Version: - Squad)
Killing Floor (HKLM-x32\...\Steam App 1250) (Version: - Tripwire Interactive)
League of Legends (HKLM-x32\...\League of Legends 3.0.1) (Version: 3.0.1 - Riot Games)
League of Legends (x32 Version: 3.0.1 - Riot Games) Hidden
Left 4 Dead (HKLM-x32\...\Steam App 500) (Version: - Valve)
Left 4 Dead 2 (HKLM\...\Steam App 550) (Version: - Valve)
Mad Riders (HKLM-x32\...\Steam App 208860) (Version: - Techland)
Malwarebytes Anti-Malware version 2.2.1.1043 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes)
Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation)
Microsoft Office Home and Student 2010 (HKLM-x32\...\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Minecraft (HKLM-x32\...\{1C16BCA3-EBC1-49F6-8623-8FBFB9CCC872}) (Version: 1.0.3.0 - Mojang)
NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version: - )
NVIDIA GeForce Experience 2.10.2.40 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.10.2.40 - NVIDIA Corporation)
NVIDIA Graphics Driver 362.00 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 362.00 - NVIDIA Corporation)
NVIDIA nTune (HKLM-x32\...\InstallShield_{7C7F30F4-94E7-4AA8-8941-90C4A80C68BF}) (Version: 1.00.0000 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.15.0428 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.15.0428 - NVIDIA Corporation)
PerformanceTest v8.0 (HKLM\...\PerformanceTest 8_is1) (Version: 8.0.1047.0 - Passmark Software)
Portal 2 (HKLM-x32\...\Steam App 620) (Version: - Valve)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7541 - Realtek Semiconductor Corp.)
Rocket League (HKLM-x32\...\Steam App 252950) (Version: - Psyonix)
Rockstar Games Social Club (HKLM-x32\...\Rockstar Games Social Club) (Version: 1.1.7.2 - Rockstar Games)
RollerCoaster Tycoon 3: Platinum! (HKLM-x32\...\Steam App 2700) (Version: - Frontier)
SafeZone Stable 1.48.2066.44 (x32 Version: 1.48.2066.44 - Avast Software) Hidden
Saints Row: The Third (HKLM-x32\...\Steam App 55230) (Version: - Volition)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version: - Microsoft)
SHIELD Streaming (Version: 5.1.0270 - NVIDIA Corporation) Hidden
SHIELD Wireless Controller Driver (Version: 2.10.2.40 - NVIDIA Corporation) Hidden
Sid Meier's Civilization V (HKLM-x32\...\Steam App 8930) (Version: - 2K Games, Inc.)
Skype™ 7.21 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.21.100 - Skype Technologies S.A.)
SNOW (HKLM\...\Steam App 244930) (Version: - Poppermost Productions)
Speccy (HKLM\...\Speccy) (Version: 1.29 - Piriform)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
Tabletop Simulator (HKLM\...\Steam App 286160) (Version: - Berserk Games)
Team Fortress 2 (HKLM-x32\...\Steam App 440) (Version: - Valve)
TeamSpeak 3 Client (HKU\S-1-5-21-3667704814-1699542734-850788743-1002\...\TeamSpeak 3 Client) (Version: 3.0.18 - TeamSpeak Systems GmbH)
Terraria (HKLM-x32\...\Steam App 105600) (Version: - Re-Logic)
The Sims 3 (HKLM-x32\...\Steam App 47890) (Version: - The Sims Studio)
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.2 - VideoLAN)
WinRAR 5.31 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.31.0 - win.rar GmbH)
Worms Revolution (HKLM-x32\...\Steam App 200170) (Version: - Team17 Digital Ltd)
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-3667704814-1699542734-850788743-1002_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\willi\AppData\Local\Microsoft\OneDrive\17.3.6302.0225\FileCoAuth.exe (Microsoft Corporation)
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {1940DA92-C768-4AB4-B53B-71D302B85408} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-03-05] (Google Inc.)
Task: {1E3ACD2E-602B-4DB0-987F-ECF96F23DF13} - System32\Tasks\avast! Windows 10 Start Menu helper => c:\program files\avast software\avast\asww10mon.exe [2016-03-25] (AVAST Software)
Task: {3827EA74-9908-4874-8BC4-CC4FF97F4725} - System32\Tasks\SafeZone scheduled Autoupdate 1458977815 => C:\Program Files\AVAST Software\SZBrowser\launcher.exe [2016-02-01] (Avast Software)
Task: {3EB44B1E-7494-4E9F-897E-BF835AE2434A} - System32\Tasks\Bimui => C:\PROGRA~1\BAOMKY~1\Boeehir.bat
Task: {4D63DB2A-839D-49AB-8542-78A26ACB5BAC} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473-Logon => C:\Program Files (x86)\Intel\Intel® Update Manager\bin\iumsvc.exe [2015-09-25] (Intel Corporation)
Task: {83C15578-2BAD-4E9A-9ACE-5185B3A9E5C6} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 => C:\Program Files (x86)\Intel\Intel® Update Manager\bin\iumsvc.exe [2015-09-25] (Intel Corporation)
Task: {8A8CB5AD-622B-4CE9-818C-606E72B334CE} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2016-03-25] (AVAST Software)
Task: {A7D1B83E-CCE1-41A3-93CA-563B9B0A7282} - System32\Tasks\GyazoUpdateTaskMachine => C:\Program Files (x86)\Gyazo\GyazoUpdate.exe [2016-02-17] ()
Task: {B197630C-FE6B-4346-8B0D-AA722B4E044B} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\windows\system32\MRT.exe [2016-03-08] (Microsoft Corporation)
Task: {BA3BFDA4-E247-41A2-A95D-39254FA36F0F} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-03-05] (Google Inc.)
Task: {CE84A1E1-5F0A-4497-859E-42296F9EDA8C} - System32\Tasks\GyazoUpdateTaskMachineDaily => C:\Program Files (x86)\Gyazo\GyazoUpdate.exe [2016-02-17] ()
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
==================== Shortcuts =============================
(The entries could be listed to be restored or removed.)
==================== Loaded Modules (Whitelisted) ==============
2015-10-30 07:17 - 2015-10-30 07:17 - 00028672 _____ () C:\windows\SYSTEM32\efsext.dll
2015-10-30 07:18 - 2015-10-30 07:18 - 00185856 _____ () C:\windows\SYSTEM32\ism32k.dll
2016-03-01 20:15 - 2016-02-23 20:28 - 00134712 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2015-12-15 11:54 - 2013-07-04 03:32 - 00936728 _____ () C:\Program Files (x86)\ASUS\AXSP\1.02.00\atkexComSvc.exe
2016-03-01 19:47 - 2016-02-17 06:56 - 01416064 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\MessageBus.dll
2016-03-01 19:47 - 2016-02-17 06:56 - 00299392 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamBase.dll
2016-03-01 19:47 - 2016-02-17 06:56 - 03613056 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\Poco.dll
2016-03-01 19:11 - 2016-02-23 11:27 - 02654872 _____ () C:\windows\system32\CoreUIComponents.dll
2016-03-01 19:11 - 2016-02-23 11:27 - 02654872 _____ () C:\windows\System32\CoreUIComponents.dll
2016-01-21 19:24 - 2016-01-21 19:25 - 00144384 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe
2015-12-26 09:43 - 2015-12-07 04:14 - 00093696 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\Windows.UI.Shell.SharedUtilities.dll
2016-03-01 19:11 - 2016-02-23 08:36 - 00472064 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll
2016-01-13 20:54 - 2016-01-05 01:29 - 07992832 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2016-01-13 20:54 - 2016-01-05 01:23 - 00591360 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2016-01-28 17:28 - 2016-01-16 05:10 - 02483200 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2016-01-28 17:28 - 2016-01-16 05:13 - 04089856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2015-12-14 16:01 - 2015-12-10 14:12 - 01197568 _____ () C:\Program Files\Scan 3XS\menu.exe
2016-01-01 22:39 - 2016-01-01 22:39 - 00016384 _____ () C:\Users\willi\AppData\Local\Apps\2.0\GNJTZPBV.KQ1\P211G6GV.WC4\curs..tion_9e9e83ddf3ed3ead_0005.0001_fb8944c2684f5b6c\Curse.CurseClient.WowDb.dll
2016-01-01 22:39 - 2016-01-01 22:39 - 00035840 _____ () C:\Users\willi\AppData\Local\Apps\2.0\GNJTZPBV.KQ1\P211G6GV.WC4\curs..tion_9e9e83ddf3ed3ead_0005.0001_fb8944c2684f5b6c\Curse.Advertising.dll
2016-03-25 22:24 - 2016-03-25 22:24 - 00258896 _____ () C:\Program Files\AVAST Software\Avast\avastnm.exe
2016-03-25 22:23 - 2016-03-25 22:23 - 00113496 _____ () C:\Program Files\AVAST Software\Avast\log.dll
2016-03-25 22:23 - 2016-03-25 22:23 - 00133768 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
2016-03-25 22:25 - 2016-03-25 22:25 - 02857472 _____ () C:\Program Files\AVAST Software\Avast\defs\16032501\algo.dll
2016-03-25 22:23 - 2016-03-25 22:23 - 00480760 _____ () C:\Program Files\AVAST Software\Avast\ffl2.dll
2015-12-15 11:54 - 2016-03-26 13:28 - 00039720 _____ () C:\Program Files (x86)\ASUS\AXSP\1.02.00\PEbiosinterface32.dll
2015-12-15 11:54 - 2013-07-04 03:32 - 00104448 _____ () C:\Program Files (x86)\ASUS\AXSP\1.02.00\ATKEX.dll
2016-01-21 19:24 - 2016-01-21 19:25 - 00141312 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeBackgroundTasks.dll
2016-01-21 19:24 - 2016-01-21 19:25 - 22330368 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkyWrap.dll
2016-03-01 19:47 - 2016-02-17 07:02 - 00020352 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll
2016-03-25 22:23 - 2016-03-25 22:23 - 40539648 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2016-03-20 08:39 - 2016-03-20 08:38 - 01690504 _____ () C:\Users\willi\AppData\Roaming\Curse Client\Bin\Electron\libglesv2.dll
2016-03-20 08:39 - 2016-03-20 08:38 - 00018312 _____ () C:\Users\willi\AppData\Roaming\Curse Client\Bin\Electron\libegl.dll
2016-03-26 07:36 - 2016-02-01 09:50 - 62337016 _____ () C:\Program Files\AVAST Software\SZBrowser\1.48.2066.44\SZBrowser.dll
2016-03-26 07:36 - 2016-02-01 09:50 - 02074104 _____ () C:\Program Files\AVAST Software\SZBrowser\1.48.2066.44\libglesv2.dll
2016-03-26 07:36 - 2016-02-01 09:50 - 00081400 _____ () C:\Program Files\AVAST Software\SZBrowser\1.48.2066.44\libegl.dll
2014-04-03 16:48 - 2014-04-03 16:48 - 01241560 _____ () C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\ACE.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
==================== Safe Mode (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
==================== EXE Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
==================== Hosts content: ===============================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2015-10-30 07:24 - 2016-03-26 13:08 - 00000027 ____A C:\windows\system32\Drivers\etc\hosts
127.0.0.1 localhost
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-3667704814-1699542734-850788743-1002\Control Panel\Desktop\\Wallpaper -> C:\Users\willi\AppData\Local\Microsoft\Windows\Themes\RoamedThemeFiles\DesktopBackground\natsu-dragneel-fairy-tail-26497-1920x1080.jpg
DNS Servers: 192.168.0.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
(Currently there is no automatic fix for this section.)
HKLM\...\StartupApproved\Run: => "SpaceSoundPro"
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [{F69E7180-B24D-4B19-8DA3-3AB427FBCB35}] => (Allow) F:\programs\steam\Steam.exe
FirewallRules: [{AF3038F3-CE6E-45FC-9492-464CAD57EA0D}] => (Allow) F:\programs\steam\Steam.exe
FirewallRules: [{330B635F-FA43-4866-8DBE-C322BD951BB4}] => (Allow) F:\programs\steam\bin\steamwebhelper.exe
FirewallRules: [{796089DA-786C-4B83-A2FA-3A578E5D0D68}] => (Allow) F:\programs\steam\bin\steamwebhelper.exe
==================== Restore Points =========================
08-03-2016 18:46:02 Windows Update
12-03-2016 18:52:20 Windows Update
16-03-2016 15:49:40 Windows Update
19-03-2016 16:14:58 Windows Update
22-03-2016 18:42:08 Windows Update
25-03-2016 21:10:17 Windows Update
26-03-2016 13:12:31 JRT Pre-Junkware Removal
26-03-2016 13:15:35 JRT Pre-Junkware Removal
26-03-2016 13:18:53 JRT Pre-Junkware Removal
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (03/26/2016 01:30:34 PM) (Source: IntelDalJhi) (EventID: 11) (User: )
Description: Intel® Dynamic Application Loader Host Interface Service has encountered an internal connection problem.
Error: (03/26/2016 01:18:54 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.
Details:
AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol.
System Error:
Access is denied.
.
Error: (03/26/2016 01:15:36 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.
Details:
AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol.
System Error:
Access is denied.
.
Error: (03/26/2016 01:15:27 PM) (Source: IntelDalJhi) (EventID: 11) (User: )
Description: Intel® Dynamic Application Loader Host Interface Service has encountered an internal connection problem.
Error: (03/26/2016 01:12:33 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.
Details:
AddLegacyDriverFiles: Unable to back up image of binary zdwfp.
System Error:
The system cannot find the file specified.
.
Error: (03/26/2016 01:12:33 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.
Details:
AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol.
System Error:
Access is denied.
.
Error: (03/26/2016 01:12:01 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: svchost.exe_DoSvc, version: 10.0.10586.0, time stamp: 0x5632d7ba
Faulting module name: webio.dll, version: 10.0.10586.0, time stamp: 0x5632d55a
Exception code: 0xc0000409
Fault offset: 0x0000000000035ce9
Faulting process id: 0x2b8
Faulting application start time: 0xsvchost.exe_DoSvc0
Faulting application path: svchost.exe_DoSvc1
Faulting module path: svchost.exe_DoSvc2
Report Id: svchost.exe_DoSvc3
Faulting package full name: svchost.exe_DoSvc4
Faulting package-relative application ID: svchost.exe_DoSvc5
Error: (03/26/2016 12:43:26 PM) (Source: Perflib) (EventID: 1008) (User: )
Description: WmiApRplC:\windows\system32\wbem\wmiaprpl.dll4
Error: (03/26/2016 12:43:26 PM) (Source: Perflib) (EventID: 1023) (User: )
Description: rdyboost4
Error: (03/26/2016 12:43:26 PM) (Source: PerfNet) (EventID: 2004) (User: )
Description:
System errors:
=============
Error: (03/26/2016 01:27:49 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The User Data Access_3f141 service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service.
Error: (03/26/2016 01:27:49 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The User Data Storage_3f141 service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service.
Error: (03/26/2016 01:27:49 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Contact Data_3f141 service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service.
Error: (03/26/2016 01:27:49 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Sync Host_3f141 service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service.
Error: (03/26/2016 01:27:49 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: application-specificLocalActivation{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)UnavailableUnavailable
Error: (03/26/2016 01:26:58 PM) (Source: Service Control Manager) (EventID: 7032) (User: )
Description: The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Windows Search service, but this action failed with the following error:
%%1056
Error: (03/26/2016 01:26:29 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The NVIDIA Display Driver Service service terminated unexpectedly. It has done this 2 time(s).
Error: (03/26/2016 01:26:29 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Intel® ME Service service terminated unexpectedly. It has done this 1 time(s).
Error: (03/26/2016 01:26:28 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Intel® Rapid Storage Technology service terminated unexpectedly. It has done this 1 time(s).
Error: (03/26/2016 01:26:28 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Windows Search service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service.
CodeIntegrity:
===================================
Date: 2016-03-25 17:05:35.120
Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2016-03-24 20:13:38.138
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\SpaceSoundPro\SpaceSoundPro.dll because the set of per-page image hashes could not be found on the system.
Date: 2016-03-24 20:13:38.132
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\SpaceSoundPro\SpaceSoundPro.dll because the set of per-page image hashes could not be found on the system.
Date: 2016-03-24 20:13:22.754
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\SpaceSoundPro\SpaceSoundPro.dll because the set of per-page image hashes could not be found on the system.
Date: 2016-03-24 20:13:22.748
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\SpaceSoundPro\SpaceSoundPro.dll because the set of per-page image hashes could not be found on the system.
Date: 2016-03-24 20:13:21.208
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\SpaceSoundPro\SpaceSoundPro.dll because the set of per-page image hashes could not be found on the system.
Date: 2016-03-24 20:13:21.202
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\SpaceSoundPro\SpaceSoundPro.dll because the set of per-page image hashes could not be found on the system.
Date: 2016-03-24 20:13:19.602
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\SpaceSoundPro\SpaceSoundPro.dll because the set of per-page image hashes could not be found on the system.
Date: 2016-03-24 20:13:19.597
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\SpaceSoundPro\SpaceSoundPro.dll because the set of per-page image hashes could not be found on the system.
Date: 2016-03-24 20:13:18.698
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\SpaceSoundPro\SpaceSoundPro.dll because the set of per-page image hashes could not be found on the system.
==================== Memory info ===========================
Processor: Intel® Core i7-5820K CPU @ 3.30GHz
Percentage of memory in use: 17%
Total physical RAM: 16284.21 MB
Available physical RAM: 13432.15 MB
Total Virtual: 18716.21 MB
Available Virtual: 14971.79 MB
==================== Drives ================================
Drive c: (OSDisk) (Fixed) (Total:220.73 GB) (Free:139.76 GB) NTFS
Drive d: (SAMSUNG) (Fixed) (Total:931.51 GB) (Free:671.99 GB) NTFS
Drive f: (Storage) (Fixed) (Total:1862.89 GB) (Free:1581.49 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 223.6 GB) (Disk ID: 2B4024BB)
Partition: GPT.
========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 1863 GB) (Disk ID: 00000000)
Partition: GPT.
========================================================
Disk: 2 (Size: 931.5 GB) (Disk ID: 4F86173B)
Partition 1: (Active) - (Size=931.5 GB) - (Type=07 NTFS)
==================== End of Addition.txt ============================