Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Malware creating popup on the desktop


  • This topic is locked This topic is locked
3 replies to this topic

#1 TheWhiteCottage

TheWhiteCottage

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:03:50 AM

Posted 27 May 2017 - 06:05 AM

Hello. I have started seeing a suspicious popup appear on my desktop every morning. It looks like this

 k7YewPS.png

 

 

 

Here are the results of the first scan: 
 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 24-05-2017
Ran by Noga (administrator) on NOGASDESK (27-05-2017 11:55:51)
Running from C:\Users\Noga\Downloads
Loaded Profiles: Noga (Available Profiles: user & Noga & Benjamin & Jacob & Guest)
Platform: Windows 7 Professional Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe
(Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Cisco WebEx LLC) C:\Windows\SysWOW64\atashost.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(Matrox Graphics Inc) C:\Program Files (x86)\Matrox Graphics\PowerDesk\Matrox.PDesk.Services.exe
(pdfforge GmbH) C:\Program Files\PDF Architect 4\creator-ws.exe
(© pdfforge GmbH.) C:\ProgramData\pdfforge\PDF Architect 4 Manager\PDF Architect 4\Architect Manager.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
(Check Point Software Technologies) C:\Program Files (x86)\CheckPoint\Endpoint Connect\TracSrvWrapper.exe
(GlavSoft LLC.) C:\Program Files (x86)\TightVNC\tvnserver.exe
(Microsoft Corporation) C:\Program Files\Windows Live\Mesh\wlcrasvc.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Syncables, LLC) C:\Program Files (x86)\Common Files\Syncables Shared\java\Syncables.exe
(Facebook Inc.) C:\Users\Noga\AppData\Local\Facebook\Update\FacebookUpdate.exe
(Hewlett-Packard Development Company, LP) C:\Program Files\HP\HP Officejet 5740 series\Bin\ScanToPCActivationApp.exe
(© 2015 Microsoft Corporation) C:\Users\Noga\AppData\Local\Microsoft\BingSvc\BingSvc.exe
(Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
(GlavSoft LLC.) C:\Program Files (x86)\TightVNC\tvnserver.exe
(Matrox Graphics Inc.) C:\Program Files (x86)\Matrox Graphics\PowerDesk\Matrox.PDesk.Startup.exe
(Citrix Systems, Inc.) C:\Program Files (x86)\Citrix\ICA Client\concentr.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe
(Matrox Graphics Inc.) C:\Program Files (x86)\Matrox Graphics\PowerDesk\Matrox.PDesk.Core.exe
(Citrix Systems, Inc.) C:\Program Files (x86)\Citrix\ICA Client\Receiver\Receiver.exe
(Dropbox, Inc.) C:\Users\Noga\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\root\Office16\ONENOTEM.EXE
(Hewlett-Packard Development Company, LP) C:\Program Files\HP\HP Officejet 5740 series\Bin\HPNetworkCommunicatorCom.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\tv_w32.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\tv_x64.exe
(Dropbox, Inc.) C:\Users\Noga\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Dropbox, Inc.) C:\Users\Noga\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Citrix Systems, Inc.) C:\Program Files (x86)\Citrix\SelfServicePlugin\SelfServicePlugin.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe
(Citrix Systems, Inc.) C:\Program Files (x86)\Citrix\ICA Client\wfcrun32.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\HEX\Adobe CEF Helper.exe
() C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\CCXProcess.exe
(Node.js) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\libs\node.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\HEX\Adobe CEF Helper.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\root\Office16\OUTLOOK.EXE
() C:\ProgramData\pdfforge\PDF Architect 4 Manager\PDF Architect 4\messenger.exe
(Microsoft Corporation) C:\Windows\System32\taskmgr.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\mspaint.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
 
==================== Registry (Whitelisted) ====================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [508128 2016-07-01] (Adobe Systems Incorporated)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1353680 2016-11-14] (Microsoft Corporation)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe [283160 2010-11-05] (Intel Corporation)
HKLM-x32\...\Run: [tvncontrol] => C:\Program Files (x86)\TightVNC\tvnserver.exe [828944 2011-08-03] (GlavSoft LLC.)
HKLM-x32\...\Run: [Matrox PowerDesk] => C:\Program Files (x86)\Matrox Graphics\PowerDesk\Matrox.PDesk.Startup.exe [892488 2011-08-16] (Matrox Graphics Inc.)
HKLM-x32\...\Run: [ConnectionCenter] => C:\Program Files (x86)\Citrix\ICA Client\concentr.exe [362432 2011-12-22] (Citrix Systems, Inc.)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [60712 2014-10-11] (Apple Inc.)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [157480 2014-10-15] (Apple Inc.)
HKLM-x32\...\Run: [Adobe Creative Cloud] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2384984 2016-12-09] (Adobe Systems Incorporated)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-2595249627-3671955670-1608175086-1001\...\Run: [Google Update] => C:\Users\Noga\AppData\Local\Google\Update\1.3.33.5\GoogleUpdateCore.exe [601168 2017-04-25] (Google Inc.)
HKU\S-1-5-21-2595249627-3671955670-1608175086-1001\...\Run: [Syncables] => C:\Program Files (x86)\Common Files\syncables Shared\java\Syncables.exe [ ] ()
HKU\S-1-5-21-2595249627-3671955670-1608175086-1001\...\Run: [Facebook Update] => C:\Users\Noga\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2013-06-26] (Facebook Inc.)
HKU\S-1-5-21-2595249627-3671955670-1608175086-1001\...\Run: [FXCMUpload] => "C:\Program Files (x86)\Myfxbook Ltd\Trading Station Publisher\Trading_Station_Publisher.exe" /autorun 
HKU\S-1-5-21-2595249627-3671955670-1608175086-1001\...\Run: [HP Officejet 5740 series (NET)] => C:\Program Files\HP\HP Officejet 5740 series\Bin\ScanToPCActivationApp.exe [3483656 2014-08-22] (Hewlett-Packard Development Company, LP)
HKU\S-1-5-21-2595249627-3671955670-1608175086-1001\...\Run: [BingSvc] => C:\Users\Noga\AppData\Local\Microsoft\BingSvc\BingSvc.exe [144008 2015-11-05] (© 2015 Microsoft Corporation)
HKU\S-1-5-21-2595249627-3671955670-1608175086-1001\...\MountPoints2: {f5fb1b51-87af-11e0-9dd9-002522a176c7} - E:\laucher.exe
HKU\S-1-5-21-2595249627-3671955670-1608175086-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> 
ShellIconOverlayIdentifiers: [ AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2016-10-25] ()
ShellIconOverlayIdentifiers: [ AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2016-10-25] ()
ShellIconOverlayIdentifiers: [ AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2016-10-25] ()
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Noga\AppData\Roaming\Dropbox\bin\DropboxExt64.16.0.dll [2017-05-16] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Noga\AppData\Roaming\Dropbox\bin\DropboxExt64.16.0.dll [2017-05-16] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Noga\AppData\Roaming\Dropbox\bin\DropboxExt64.16.0.dll [2017-05-16] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Noga\AppData\Roaming\Dropbox\bin\DropboxExt64.16.0.dll [2017-05-16] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Noga\AppData\Roaming\Dropbox\bin\DropboxExt.16.0.dll [2017-05-16] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Noga\AppData\Roaming\Dropbox\bin\DropboxExt.16.0.dll [2017-05-16] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Noga\AppData\Roaming\Dropbox\bin\DropboxExt.16.0.dll [2017-05-16] (Dropbox, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk [2012-06-27]
ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
Startup: C:\Users\Noga\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Check for TWS Updates.lnk [2012-04-20]
ShortcutTarget: Check for TWS Updates.lnk -> C:\Jts\WiseUpdt.exe ()
Startup: C:\Users\Noga\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2017-05-17]
ShortcutTarget: Dropbox.lnk -> C:\Users\Noga\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\Noga\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Send to OneNote.lnk [2016-02-07]
ShortcutTarget: Send to OneNote.lnk -> C:\Program Files\Microsoft Office\root\Office16\ONENOTEM.EXE (Microsoft Corporation)
GroupPolicy: Restriction <======= ATTENTION
GroupPolicyScripts: Restriction <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Tcpip\Parameters: [DhcpNameServer] 172.16.1.1
Tcpip\..\Interfaces\{3E94FE7E-F317-4AAB-888F-F74F517A77B2}: [DhcpNameServer] 172.16.1.1
 
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = 
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = 
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = 
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = 
HKU\S-1-5-21-2595249627-3671955670-1608175086-1001\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
SearchScopes: HKU\S-1-5-21-2595249627-3671955670-1608175086-1001 -> {91607fa7-3c2f-4f90-93e3-d5337a6b0ac2} URL = Playbryte-fa-verti/search/redirect/?type=default&user_id=2768d1cd-9d03-4acb-88d4-0d1cfdeb3f31&query={searchTerms}
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-04-24] (Google Inc.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\root\Office16\URLREDIR.DLL [2016-04-01] (Microsoft Corporation)
BHO-x32: HP Print Enhancer -> {0347C33E-8762-4905-BF09-768834316C61} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2010-05-28] (Hewlett-Packard Co.)
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll [2016-04-01] (Microsoft Corporation)
BHO-x32: PDF Architect 4 Helper -> {38279E1A-7019-40C1-B579-E99DFB3312E8} -> C:\Program Files (x86)\PDF Architect 4\creator-ie-helper.dll [2016-08-05] (pdfforge GmbH)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll [2015-01-25] (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.)
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2016-04-24] (Google Inc.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\URLREDIR.DLL [2016-04-01] (Microsoft Corporation)
BHO-x32: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\GROOVEEX.DLL [2016-04-01] (Microsoft Corporation)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-01-25] (Oracle Corporation)
BHO-x32: HP Smart BHO Class -> {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2010-05-28] (Hewlett-Packard Co.)
Toolbar: HKLM - No Name - {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} -  No File
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-04-24] (Google Inc.)
Toolbar: HKLM-x32 - No Name - {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} -  No File
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2016-04-24] (Google Inc.)
Toolbar: HKLM-x32 - PDF Architect 4 Toolbar - {23FD9C33-A9E1-48A1-8404-E5925CF1C8E1} - C:\Program Files (x86)\PDF Architect 4\creator-ie-plugin.dll [2016-08-05] (pdfforge GmbH)
Toolbar: HKU\S-1-5-21-2595249627-3671955670-1608175086-1001 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-04-24] (Google Inc.)
DPF: HKLM-x32 {02BCC737-B171-4746-94C9-0D8A0B2C0089} hxxp://office.microsoft.com/sites/production/ieawsdc32.cab
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxps://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: HKLM-x32 {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2016-04-01] (Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2016-04-01] (Microsoft Corporation)
Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2016-04-01] (Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2016-04-01] (Microsoft Corporation)
Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2016-04-01] (Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2016-04-01] (Microsoft Corporation)
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2016-04-01] (Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2016-04-01] (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2017-01-01] (Skype Technologies)
Filter-x32: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2011-12-22] (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2011-12-22] (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2011-12-22] (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2011-12-22] (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2011-12-22] (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2011-12-22] (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2011-12-22] (Citrix Systems, Inc.)
Filter-x32: application/x-ica; charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2011-12-22] (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2011-12-22] (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2011-12-22] (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2011-12-22] (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2011-12-22] (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2011-12-22] (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2011-12-22] (Citrix Systems, Inc.)
Filter-x32: application/x-ica;charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2011-12-22] (Citrix Systems, Inc.)
Filter-x32: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2011-12-22] (Citrix Systems, Inc.)
 
FireFox:
========
FF ProfilePath: C:\Users\Noga\AppData\Roaming\Mozilla\firefox\Profiles\u0n8e8p2.default [2015-11-18]
FF Homepage: Mozilla\firefox\Profiles\u0n8e8p2.default -> hxxp://www.google.co.uk
FF SelectedSearchEngine: Mozilla\firefox\Profiles\u0n8e8p2.default -> 
FF DefaultSearchEngine: Mozilla\firefox\Profiles\u0n8e8p2.default -> 
FF Extension: (Adblock Plus) - C:\Users\Noga\AppData\Roaming\Mozilla\firefox\Profiles\u0n8e8p2.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-03-11] [not signed]
FF HKLM\...\Firefox\Extensions: [pdf_architect_4_conv@pdfarchitect.org] - C:\Program Files\PDF Architect 4\resources\pdfarchitect4firefoxextension
FF Extension: (PDF Architect 4 Creator) - C:\Program Files\PDF Architect 4\resources\pdfarchitect4firefoxextension [2016-12-21] [not signed]
FF HKLM-x32\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: (HP Smart Web Printing) - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012-06-27] [not signed]
FF HKLM-x32\...\Firefox\Extensions: [ffpwdman@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender\Antispam32\ffpwdman => not found
FF HKU\S-1-5-21-2595249627-3671955670-1608175086-1001\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_21_0_0_197.dll [2016-03-24] ()
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50906.0\npctrl.dll [2017-03-09] ( Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2016-04-01] (Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2016-12-09] (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_197.dll [2016-03-24] ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-02-18] ()
FF Plugin-x32: @Citrix.com/npican -> C:\Program Files (x86)\Citrix\ICA Client\npicaN.dll [2011-12-22] (Citrix Systems, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll [2015-01-25] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-01-25] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-01-25] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\npctrl.dll [2017-03-09] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2016-04-01] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-28] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-28] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-04-05] (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2016-12-09] (Adobe Systems)
FF Plugin-x32: PDF Architect 4 -> C:\Program Files (x86)\PDF Architect 4\np-previewer.dll [2016-08-05] (pdfforge GmbH)
FF Plugin HKU\S-1-5-21-2595249627-3671955670-1608175086-1001: @citrixonline.com/appdetectorplugin -> C:\Users\Noga\AppData\Local\Citrix\Plugins\104\npappdetector.dll [2013-06-27] (Citrix Online)
FF Plugin HKU\S-1-5-21-2595249627-3671955670-1608175086-1001: @Skype Limited.com/Facebook Video Calling Plugin -> C:\Users\Noga\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll [2014-07-24] (Skype Limited)
FF Plugin HKU\S-1-5-21-2595249627-3671955670-1608175086-1001: @talk.google.com/GoogleTalkPlugin -> C:\Users\Noga\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll [2015-12-08] (Google)
FF Plugin HKU\S-1-5-21-2595249627-3671955670-1608175086-1001: @talk.google.com/O1DPlugin -> C:\Users\Noga\AppData\Roaming\Mozilla\plugins\npo1d.dll [2015-12-08] (Google)
FF Plugin HKU\S-1-5-21-2595249627-3671955670-1608175086-1001: @tools.google.com/Google Update;version=3 -> C:\Users\Noga\AppData\Local\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-25] (Google Inc.)
FF Plugin HKU\S-1-5-21-2595249627-3671955670-1608175086-1001: @tools.google.com/Google Update;version=9 -> C:\Users\Noga\AppData\Local\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-25] (Google Inc.)
FF Plugin HKU\S-1-5-21-2595249627-3671955670-1608175086-1001: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Noga\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2015-06-21] (Unity Technologies ApS)
FF Plugin ProgramFiles/Appdata: C:\Users\Noga\AppData\Roaming\mozilla\plugins\npatgpc.dll [2012-03-01] (Cisco WebEx LLC)
FF Plugin ProgramFiles/Appdata: C:\Users\Noga\AppData\Roaming\mozilla\plugins\npgoogletalk.dll [2015-12-08] (Google)
FF Plugin ProgramFiles/Appdata: C:\Users\Noga\AppData\Roaming\mozilla\plugins\npo1d.dll [2015-12-08] (Google)
 
Chrome: 
=======
CHR DefaultProfile: Default
CHR HomePage: Default -> msn.com/?pc=__PARAM__&ocid=__PARAM__DHP&osmkt=en-gb
CHR StartupUrls: Default -> "hxxp://www.forexfactory.com/calendar.php","hxxp://www.bkforex.com/dashboard/","hxxps://www.facebook.com/","hxxp://www.quora.com/Is-it-morally-justified-to-sacrifice-human-life-for-space-tourism/answer/Robert-Frost-1","hxxps://www.linkedin.com/people/pymk/hub?ref=global-nav&trk=nav_utilities_invites_header","hxxp://www.bloomberg.com/","hxxp://www.businessinsider.com/podcasts-that-make-you-smarter-2014-9?op=1&IR=T","hxxp://nocamels.com/2014/11/rosetta-mission-lands-on-comet-to-discover-possible-origins-of-life-on-earth/","hxxp://collectivelyconscious.net/","hxxp://ecowatch.com/2014/11/03/climate-change-plot-tony-perkins/?utm_source=EcoWatch+List&utm_campaign=8cebef5fa7-Top_News_11_4_2014&utm_medium=email&utm_term=0_49c7d43dc9-8cebef5fa7-85884549","hxxps://plus.google.com/u/0/","hxxp://www.pointofinquiry.org/","hxxps://www.youtube.com/results?search_query=Eva+Longoria+%E2%80%93+Food+Chains+%28HBO%29"
CHR DefaultSearchURL: Default -> hxxp://www.bing.com/search?FORM=__PARAM__DF&PC=__PARAM__&q={searchTerms}
CHR DefaultSearchKeyword: Default -> bing.com
CHR Session Restore: Default -> is enabled.
CHR Profile: C:\Users\Noga\AppData\Local\Google\Chrome\User Data\Default [2017-05-27]
CHR Extension: (Google Docs) - C:\Users\Noga\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-02-04]
CHR Extension: (Google Drive) - C:\Users\Noga\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-21]
CHR Extension: (YouTube) - C:\Users\Noga\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-26]
CHR Extension: (Bitdefender Wallet) - C:\Users\Noga\AppData\Local\Google\Chrome\User Data\Default\Extensions\ccahoghmggldkcdjiebjkidpfongdfbl [2014-11-07]
CHR Extension: (Google Search) - C:\Users\Noga\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-11-01]
CHR Extension: (Bitdefender Wallet) - C:\Users\Noga\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhhejlifdlcgcmogbggeomfodgklfaem [2015-12-09]
CHR Extension: (Adobe Acrobat) - C:\Users\Noga\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2017-03-16]
CHR Extension: (Google Docs Offline) - C:\Users\Noga\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-15]
CHR Extension: (AdBlock) - C:\Users\Noga\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2017-05-02]
CHR Extension: (Office Online) - C:\Users\Noga\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndjpnladcallmjemlbaebfadecfhkepb [2017-05-11]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Noga\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-03-16]
CHR Extension: (Gmail) - C:\Users\Noga\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-04-04]
CHR Extension: (Chrome Media Router) - C:\Users\Noga\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-05-18]
CHR HKU\S-1-5-21-2595249627-3671955670-1608175086-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [fcfenmboojpjinhpgggodefccipikbpd] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [bafafaommdbdmoanapkgbnemjnkllcga] - C:\Users\Noga\AppData\LocalLow\Playbryte\Chrome.crx <not found>
CHR HKLM-x32\...\Chrome\Extension: [ccahoghmggldkcdjiebjkidpfongdfbl] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [dhhejlifdlcgcmogbggeomfodgklfaem] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - hxxps://clients2.google.com/service/update2/crx
 
==================== Services (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 AdobeUpdateService; C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [753240 2016-12-09] (Adobe Systems Incorporated)
R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2227312 2017-02-27] (Adobe Systems, Incorporated)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [2823920 2016-03-20] (Microsoft Corporation)
S3 GoToAssist; C:\Program Files (x86)\Citrix\GoToAssist Corporate\1019\g2aservice.exe [309080 2014-05-16] (Citrix Online, a division of Citrix Systems, Inc.)
R2 HPSLPSVC; C:\Program Files (x86)\HP\Digital Imaging\bin\HPSLPSVC64.DLL [1039360 2010-10-22] (Hewlett-Packard Co.) [File not signed]
R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [26680 2016-02-18] (Hewlett-Packard Company)
R2 Matrox.Pdesk3.ServicesHost; C:\Program Files (x86)\Matrox Graphics\PowerDesk\Matrox.PDesk.Services.exe [3728456 2011-08-16] (Matrox Graphics Inc)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [119864 2016-11-14] (Microsoft Corporation)
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2010-08-06] (Hewlett-Packard) [File not signed]
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [361816 2016-11-14] (Microsoft Corporation)
S3 ose64; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [243232 2016-03-19] (Microsoft Corporation) [File not signed]
S3 PDF Architect 4; C:\Program Files\PDF Architect 4\ws.exe [2438880 2016-08-05] (pdfforge GmbH)
S3 PDF Architect 4 CrashHandler; C:\Program Files\PDF Architect 4\crash-handler-ws.exe [1038048 2016-08-05] (pdfforge GmbH)
R2 PDF Architect 4 Creator; C:\Program Files\PDF Architect 4\creator-ws.exe [851168 2016-08-05] (pdfforge GmbH)
R2 PDF Architect 4 Manager; C:\ProgramData\pdfforge\PDF Architect 4 Manager\PDF Architect 4\Architect Manager.exe [972056 2016-05-18] (© pdfforge GmbH.)
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2010-08-06] (Hewlett-Packard) [File not signed]
R2 TracSrvWrapper; C:\Program Files (x86)\CheckPoint\Endpoint Connect\TracSrvWrapper.exe [3487128 2009-12-30] (Check Point Software Technologies)
R2 tvnserver; C:\Program Files (x86)\TightVNC\tvnserver.exe [828944 2011-08-03] (GlavSoft LLC.)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
 
===================== Drivers (Whitelisted) ======================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S3 gbridge; C:\Windows\System32\DRIVERS\gbridge64.sys [48192 2009-10-13] (Gbridge LLC)
S3 hitmanpro37; C:\Windows\system32\drivers\hitmanpro37.sys [32152 2013-03-11] ()
S3 IntcDAud; C:\Windows\System32\DRIVERS\IntcDAud.sys [317440 2010-10-14] (Intel® Corporation) [File not signed]
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [295000 2016-08-25] (Microsoft Corporation)
R1 MpKsl41ce7119; c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{6BE7D84B-62D3-46A3-AF51-AB870E932211}\MpKsl41ce7119.sys [44928 2017-05-27] (Microsoft Corporation)
R3 MxMKm; C:\Windows\System32\DRIVERS\MxMKm64.sys [1647616 2011-08-15] (Matrox Graphics Inc.)
R3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [135928 2016-08-25] (Microsoft Corporation)
R3 vna_ap; C:\Windows\System32\DRIVERS\vnaap.sys [161256 2009-12-30] (Check Point Software Technologies)
S3 b06bdrv; \SystemRoot\system32\DRIVERS\bxvbda.sys [X]
S0 ignis; system32\DRIVERS\ignis.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2017-05-27 11:55 - 2017-05-27 11:56 - 00038676 _____ C:\Users\Noga\Downloads\FRST.txt
2017-05-27 11:55 - 2017-05-27 11:55 - 02429952 _____ (Farbar) C:\Users\Noga\Downloads\FRST64.exe
2017-05-27 11:55 - 2017-05-27 11:55 - 00000000 ____D C:\FRST
2017-05-26 12:31 - 2017-05-26 12:30 - 00006570 _____ C:\Users\Noga\Desktop\APPERLEYLEN01.rdp
2017-05-26 12:30 - 2017-05-26 12:30 - 00006570 _____ C:\Users\Noga\Downloads\APPERLEYLEN01.rdp
2017-05-26 08:15 - 2017-05-26 08:15 - 00000000 ___HD C:\OneDriveTemp
2017-05-25 23:38 - 2017-05-26 23:50 - 00017623 _____ C:\Users\Noga\Desktop\assets and liabilities.xlsx
2017-05-25 22:00 - 2017-05-25 22:00 - 00184823 _____ C:\Users\Noga\Downloads\Alladale Bookings Calendar (1).xlsx
2017-05-25 21:53 - 2017-05-25 21:53 - 00184973 _____ C:\Users\Noga\Downloads\Alladale Bookings Calendar.xlsx
2017-05-25 12:32 - 2017-05-25 12:32 - 00013549 _____ C:\Users\Noga\Downloads\Transaction (2).pdf
2017-05-22 22:25 - 2017-05-22 22:25 - 00003550 _____ C:\Windows\System32\Tasks\HP AR Program Upload - aee93b930a134545a2dfc1ed813b011ad23ad52c54bd40d8b8c49321019dc0d9
2017-05-18 12:29 - 2017-05-18 12:29 - 02234210 _____ C:\Users\Noga\Desktop\Tirley Securities Ltd - format sample.doc.odt
2017-05-17 19:24 - 2017-05-17 19:24 - 00000000 ____D C:\Users\Noga\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2017-05-15 20:17 - 2017-05-15 20:17 - 00295170 _____ C:\Users\Noga\Documents\Scan0001.pdf
2017-05-10 04:53 - 2017-04-28 02:14 - 05547240 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2017-05-10 04:53 - 2017-04-28 02:14 - 00706792 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2017-05-10 04:53 - 2017-04-28 02:14 - 00631176 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2017-05-10 04:53 - 2017-04-28 02:14 - 00154856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2017-05-10 04:53 - 2017-04-28 02:14 - 00095464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2017-05-10 04:53 - 2017-04-28 02:11 - 01732864 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2017-05-10 04:53 - 2017-04-28 02:10 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2017-05-10 04:53 - 2017-04-28 02:10 - 01212928 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2017-05-10 04:53 - 2017-04-28 02:10 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2017-05-10 04:53 - 2017-04-28 02:10 - 00730624 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2017-05-10 04:53 - 2017-04-28 02:10 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2017-05-10 04:53 - 2017-04-28 02:10 - 00419840 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2017-05-10 04:53 - 2017-04-28 02:10 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2017-05-10 04:53 - 2017-04-28 02:10 - 00345600 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2017-05-10 04:53 - 2017-04-28 02:10 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2017-05-10 04:53 - 2017-04-28 02:10 - 00312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2017-05-10 04:53 - 2017-04-28 02:10 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2017-05-10 04:53 - 2017-04-28 02:10 - 00215552 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2017-05-10 04:53 - 2017-04-28 02:10 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2017-05-10 04:53 - 2017-04-28 02:10 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll
2017-05-10 04:53 - 2017-04-28 02:10 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2017-05-10 04:53 - 2017-04-28 02:10 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2017-05-10 04:53 - 2017-04-28 02:10 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2017-05-10 04:53 - 2017-04-28 02:10 - 00063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2017-05-10 04:53 - 2017-04-28 02:10 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2017-05-10 04:53 - 2017-04-28 02:10 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2017-05-10 04:53 - 2017-04-28 02:10 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2017-05-10 04:53 - 2017-04-28 02:10 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2017-05-10 04:53 - 2017-04-28 02:10 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2017-05-10 04:53 - 2017-04-28 02:10 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2017-05-10 04:53 - 2017-04-28 02:09 - 00880640 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2017-05-10 04:53 - 2017-04-28 02:09 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2017-05-10 04:53 - 2017-04-28 02:09 - 00463872 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2017-05-10 04:53 - 2017-04-28 02:09 - 00123904 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll
2017-05-10 04:53 - 2017-04-28 02:09 - 00059904 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2017-05-10 04:53 - 2017-04-28 02:09 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2017-05-10 04:53 - 2017-04-28 02:09 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2017-05-10 04:53 - 2017-04-28 02:09 - 00034816 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2017-05-10 04:53 - 2017-04-28 02:09 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2017-05-10 04:53 - 2017-04-28 02:09 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2017-05-10 04:53 - 2017-04-28 02:09 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2017-05-10 04:53 - 2017-04-28 02:09 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2017-05-10 04:53 - 2017-04-28 02:09 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2017-05-10 04:53 - 2017-04-28 02:09 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2017-05-10 04:53 - 2017-04-28 02:09 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2017-05-10 04:53 - 2017-04-28 02:09 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2017-05-10 04:53 - 2017-04-28 02:09 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2017-05-10 04:53 - 2017-04-28 02:09 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2017-05-10 04:53 - 2017-04-28 02:09 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2017-05-10 04:53 - 2017-04-28 02:09 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2017-05-10 04:53 - 2017-04-28 02:09 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2017-05-10 04:53 - 2017-04-28 02:09 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2017-05-10 04:53 - 2017-04-28 02:09 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2017-05-10 04:53 - 2017-04-28 02:09 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2017-05-10 04:53 - 2017-04-28 02:09 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2017-05-10 04:53 - 2017-04-28 02:09 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2017-05-10 04:53 - 2017-04-28 02:09 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2017-05-10 04:53 - 2017-04-28 02:09 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2017-05-10 04:53 - 2017-04-28 02:09 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2017-05-10 04:53 - 2017-04-28 02:09 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2017-05-10 04:53 - 2017-04-28 02:09 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2017-05-10 04:53 - 2017-04-28 02:09 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2017-05-10 04:53 - 2017-04-28 02:09 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2017-05-10 04:53 - 2017-04-28 02:09 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2017-05-10 04:53 - 2017-04-28 02:09 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2017-05-10 04:53 - 2017-04-28 02:09 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2017-05-10 04:53 - 2017-04-28 02:09 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2017-05-10 04:53 - 2017-04-28 02:09 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2017-05-10 04:53 - 2017-04-28 01:36 - 04000488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2017-05-10 04:53 - 2017-04-28 01:36 - 03945192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2017-05-10 04:53 - 2017-04-28 01:34 - 01314112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2017-05-10 04:53 - 2017-04-28 01:32 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2017-05-10 04:53 - 2017-04-28 01:32 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2017-05-10 04:53 - 2017-04-28 01:32 - 00666112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2017-05-10 04:53 - 2017-04-28 01:32 - 00644096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2017-05-10 04:53 - 2017-04-28 01:32 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2017-05-10 04:53 - 2017-04-28 01:32 - 00342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
2017-05-10 04:53 - 2017-04-28 01:32 - 00275456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2017-05-10 04:53 - 2017-04-28 01:32 - 00261120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2017-05-10 04:53 - 2017-04-28 01:32 - 00254464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2017-05-10 04:53 - 2017-04-28 01:32 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2017-05-10 04:53 - 2017-04-28 01:32 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2017-05-10 04:53 - 2017-04-28 01:32 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2017-05-10 04:53 - 2017-04-28 01:32 - 00141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll
2017-05-10 04:53 - 2017-04-28 01:32 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2017-05-10 04:53 - 2017-04-28 01:32 - 00082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcrypt.dll
2017-05-10 04:53 - 2017-04-28 01:32 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2017-05-10 04:53 - 2017-04-28 01:32 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2017-05-10 04:53 - 2017-04-28 01:32 - 00050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll
2017-05-10 04:53 - 2017-04-28 01:32 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2017-05-10 04:53 - 2017-04-28 01:32 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2017-05-10 04:53 - 2017-04-28 01:32 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2017-05-10 04:53 - 2017-04-28 01:32 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2017-05-10 04:53 - 2017-04-28 01:32 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2017-05-10 04:53 - 2017-04-28 01:32 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2017-05-10 04:53 - 2017-04-28 01:32 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2017-05-10 04:53 - 2017-04-28 01:32 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2017-05-10 04:53 - 2017-04-28 01:32 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2017-05-10 04:53 - 2017-04-28 01:32 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2017-05-10 04:53 - 2017-04-28 01:32 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2017-05-10 04:53 - 2017-04-28 01:32 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2017-05-10 04:53 - 2017-04-28 01:32 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2017-05-10 04:53 - 2017-04-28 01:32 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2017-05-10 04:53 - 2017-04-28 01:32 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2017-05-10 04:53 - 2017-04-28 01:32 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2017-05-10 04:53 - 2017-04-28 01:32 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2017-05-10 04:53 - 2017-04-28 01:32 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2017-05-10 04:53 - 2017-04-28 01:32 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2017-05-10 04:53 - 2017-04-28 01:32 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2017-05-10 04:53 - 2017-04-28 01:32 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2017-05-10 04:53 - 2017-04-28 01:32 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2017-05-10 04:53 - 2017-04-28 01:32 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2017-05-10 04:53 - 2017-04-28 01:32 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2017-05-10 04:53 - 2017-04-28 01:32 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2017-05-10 04:53 - 2017-04-28 01:32 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2017-05-10 04:53 - 2017-04-28 01:32 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2017-05-10 04:53 - 2017-04-28 01:32 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2017-05-10 04:53 - 2017-04-28 01:32 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2017-05-10 04:53 - 2017-04-28 01:19 - 00148480 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2017-05-10 04:53 - 2017-04-28 01:19 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2017-05-10 04:53 - 2017-04-28 01:19 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2017-05-10 04:53 - 2017-04-28 01:18 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2017-05-10 04:53 - 2017-04-28 01:15 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2017-05-10 04:53 - 2017-04-28 01:14 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2017-05-10 04:53 - 2017-04-28 01:12 - 00159744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2017-05-10 04:53 - 2017-04-28 01:11 - 00291328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2017-05-10 04:53 - 2017-04-28 01:11 - 00129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2017-05-10 04:53 - 2017-04-28 01:11 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2017-05-10 04:53 - 2017-04-28 01:10 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2017-05-10 04:53 - 2017-04-28 01:10 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2017-05-10 04:53 - 2017-04-28 01:08 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2017-05-10 04:53 - 2017-04-28 01:08 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2017-05-10 04:53 - 2017-04-28 01:08 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2017-05-10 04:53 - 2017-04-28 01:08 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2017-05-10 04:53 - 2017-04-28 01:07 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
2017-05-10 04:53 - 2017-04-28 01:07 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2017-05-10 04:53 - 2017-04-28 01:07 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2017-05-10 04:53 - 2017-04-28 01:07 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2017-05-10 04:53 - 2017-04-28 01:07 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2017-05-10 04:53 - 2017-04-26 15:59 - 03220992 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2017-05-10 04:53 - 2017-04-21 16:34 - 01133568 _____ (Microsoft Corporation) C:\Windows\system32\cdosys.dll
2017-05-10 04:53 - 2017-04-21 16:15 - 00805376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2017-05-10 04:53 - 2017-04-20 01:00 - 00394448 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2017-05-10 04:53 - 2017-04-20 00:16 - 00346320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2017-05-10 04:53 - 2017-04-17 16:37 - 02065408 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll
2017-05-10 04:53 - 2017-04-17 16:37 - 00876544 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll
2017-05-10 04:53 - 2017-04-17 16:37 - 00512000 _____ (Microsoft Corporation) C:\Windows\system32\rpcss.dll
2017-05-10 04:53 - 2017-04-17 16:37 - 00026112 _____ (Microsoft Corporation) C:\Windows\system32\oleres.dll
2017-05-10 04:53 - 2017-04-17 16:37 - 00008704 _____ (Microsoft Corporation) C:\Windows\system32\comcat.dll
2017-05-10 04:53 - 2017-04-17 16:12 - 01417728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll
2017-05-10 04:53 - 2017-04-17 16:12 - 00581632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll
2017-05-10 04:53 - 2017-04-17 16:12 - 00026112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleres.dll
2017-05-10 04:53 - 2017-04-17 15:54 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comcat.dll
2017-05-10 04:53 - 2017-04-16 10:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2017-05-10 04:53 - 2017-04-16 10:16 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2017-05-10 04:53 - 2017-04-16 09:57 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2017-05-10 04:53 - 2017-04-16 09:55 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2017-05-10 04:53 - 2017-04-16 09:55 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2017-05-10 04:53 - 2017-04-16 09:54 - 00576512 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2017-05-10 04:53 - 2017-04-16 09:54 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2017-05-10 04:53 - 2017-04-16 09:51 - 02899456 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2017-05-10 04:53 - 2017-04-16 09:44 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2017-05-10 04:53 - 2017-04-16 09:43 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2017-05-10 04:53 - 2017-04-16 09:38 - 00615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2017-05-10 04:53 - 2017-04-16 09:37 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2017-05-10 04:53 - 2017-04-16 09:37 - 00116224 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2017-05-10 04:53 - 2017-04-16 09:36 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2017-05-10 04:53 - 2017-04-16 09:36 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2017-05-10 04:53 - 2017-04-16 09:35 - 25741312 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2017-05-10 04:53 - 2017-04-16 09:25 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2017-05-10 04:53 - 2017-04-16 09:21 - 00489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2017-05-10 04:53 - 2017-04-16 09:19 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2017-05-10 04:53 - 2017-04-16 09:18 - 05977600 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2017-05-10 04:53 - 2017-04-16 09:11 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2017-05-10 04:53 - 2017-04-16 09:10 - 00087552 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2017-05-10 04:53 - 2017-04-16 09:09 - 00107520 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2017-05-10 04:53 - 2017-04-16 09:04 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2017-05-10 04:53 - 2017-04-16 09:03 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2017-05-10 04:53 - 2017-04-16 09:02 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2017-05-10 04:53 - 2017-04-16 09:01 - 00499200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2017-05-10 04:53 - 2017-04-16 09:01 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2017-05-10 04:53 - 2017-04-16 09:01 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2017-05-10 04:53 - 2017-04-16 09:00 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2017-05-10 04:53 - 2017-04-16 09:00 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2017-05-10 04:53 - 2017-04-16 08:57 - 00152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2017-05-10 04:53 - 2017-04-16 08:53 - 02290176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2017-05-10 04:53 - 2017-04-16 08:52 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2017-05-10 04:53 - 2017-04-16 08:52 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2017-05-10 04:53 - 2017-04-16 08:49 - 20278272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2017-05-10 04:53 - 2017-04-16 08:48 - 00476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2017-05-10 04:53 - 2017-04-16 08:47 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2017-05-10 04:53 - 2017-04-16 08:47 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2017-05-10 04:53 - 2017-04-16 08:46 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2017-05-10 04:53 - 2017-04-16 08:43 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2017-05-10 04:53 - 2017-04-16 08:40 - 00806912 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2017-05-10 04:53 - 2017-04-16 08:40 - 00725504 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2017-05-10 04:53 - 2017-04-16 08:37 - 02132992 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2017-05-10 04:53 - 2017-04-16 08:37 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2017-05-10 04:53 - 2017-04-16 08:35 - 00416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2017-05-10 04:53 - 2017-04-16 08:30 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2017-05-10 04:53 - 2017-04-16 08:29 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2017-05-10 04:53 - 2017-04-16 08:28 - 00091136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2017-05-10 04:53 - 2017-04-16 08:25 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2017-05-10 04:53 - 2017-04-16 08:24 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2017-05-10 04:53 - 2017-04-16 08:22 - 00279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2017-05-10 04:53 - 2017-04-16 08:20 - 00130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2017-05-10 04:53 - 2017-04-16 08:12 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2017-05-10 04:53 - 2017-04-16 08:10 - 15250944 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2017-05-10 04:53 - 2017-04-16 08:10 - 00693248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2017-05-10 04:53 - 2017-04-16 08:08 - 04548608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2017-05-10 04:53 - 2017-04-16 08:08 - 02057216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2017-05-10 04:53 - 2017-04-16 08:08 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2017-05-10 04:53 - 2017-04-16 08:04 - 03241472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2017-05-10 04:53 - 2017-04-16 07:53 - 13661184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2017-05-10 04:53 - 2017-04-16 07:50 - 01544704 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2017-05-10 04:53 - 2017-04-16 07:40 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2017-05-10 04:53 - 2017-04-16 07:37 - 02767872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2017-05-10 04:53 - 2017-04-16 07:34 - 01314816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2017-05-10 04:53 - 2017-04-16 07:34 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2017-05-10 04:53 - 2017-04-12 16:32 - 01483776 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2017-05-10 04:53 - 2017-04-12 16:32 - 00229376 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2017-05-10 04:53 - 2017-04-12 16:32 - 00190976 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2017-05-10 04:53 - 2017-04-12 16:32 - 00141824 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2017-05-10 04:53 - 2017-04-12 16:26 - 00179200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2017-05-10 04:53 - 2017-04-12 16:25 - 01176064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2017-05-10 04:53 - 2017-04-12 16:25 - 00145920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2017-05-10 04:53 - 2017-04-12 16:25 - 00106496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2017-05-10 04:53 - 2017-04-07 16:34 - 00986856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2017-05-10 04:53 - 2017-04-07 16:34 - 00265448 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys
2017-05-10 04:53 - 2017-04-07 16:30 - 00405504 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2017-05-10 04:53 - 2017-04-07 16:30 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll
2017-05-10 04:53 - 2017-04-07 16:22 - 00312832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2017-05-10 04:53 - 2017-04-05 15:55 - 00460800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys
2017-05-10 04:53 - 2017-04-05 15:55 - 00405504 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys
2017-05-10 04:53 - 2017-04-05 15:55 - 00168960 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys
2017-05-10 04:53 - 2017-04-04 16:34 - 01895656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2017-05-10 04:53 - 2017-04-04 16:34 - 00377576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys
2017-05-10 04:53 - 2017-04-04 16:34 - 00287976 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS
2017-05-10 04:53 - 2017-04-04 15:53 - 00496128 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2017-05-10 04:53 - 2017-04-04 15:53 - 00117760 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys
2017-05-10 04:53 - 2017-03-10 17:32 - 01389056 _____ (Microsoft Corporation) C:\Windows\system32\pla.dll
2017-05-10 04:53 - 2017-03-10 17:32 - 00300544 _____ (Microsoft Corporation) C:\Windows\system32\pdh.dll
2017-05-10 04:53 - 2017-03-10 17:20 - 01508352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pla.dll
2017-05-10 04:53 - 2017-03-10 17:20 - 00237056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pdh.dll
2017-05-10 04:53 - 2017-03-10 16:57 - 00009216 _____ (Microsoft Corporation) C:\Windows\system32\plasrv.exe
2017-05-10 04:53 - 2017-03-10 16:55 - 00205312 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fastfat.sys
2017-05-10 04:53 - 2017-03-10 16:55 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\exfat.sys
2017-05-10 04:53 - 2017-03-09 17:34 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2017-05-10 04:53 - 2017-03-09 17:19 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2017-05-07 20:24 - 2017-05-07 20:24 - 01850185 _____ C:\Users\Noga\Desktop\10. Lister Family - May presentation.pptx
2017-05-07 11:01 - 2017-05-07 11:01 - 00020992 _____ C:\Users\Noga\Downloads\Toggl_time_entries_2017-04-01_to_2017-04-30 (5).xls
2017-05-07 11:00 - 2017-05-07 11:00 - 00051712 _____ C:\Users\Noga\Downloads\Toggl_time_entries_2017-04-01_to_2017-04-30 (4).xls
2017-05-07 10:59 - 2017-05-07 10:59 - 00022528 _____ C:\Users\Noga\Downloads\Toggl_time_entries_2017-04-01_to_2017-04-30 (3).xls
2017-05-07 10:59 - 2017-05-07 10:59 - 00021504 _____ C:\Users\Noga\Downloads\Toggl_time_entries_2017-04-01_to_2017-04-30 (2).xls
2017-05-07 10:58 - 2017-05-07 10:58 - 00010752 _____ C:\Users\Noga\Downloads\Toggl_time_entries_2017-04-01_to_2017-04-30 (1).xls
2017-05-07 10:57 - 2017-05-07 10:57 - 00057344 _____ C:\Users\Noga\Downloads\Toggl_time_entries_2017-04-01_to_2017-04-30.xls
2017-05-07 10:56 - 2017-05-07 10:56 - 00023040 _____ C:\Users\Noga\Downloads\Toggl_projects_2017-05-01_to_2017-05-07.xls
2017-05-05 23:32 - 2017-05-05 23:32 - 00012235 _____ C:\Users\Noga\Desktop\Monthly Revenue .xlsx
2017-05-04 00:41 - 2017-05-04 00:41 - 00000000 ___RD C:\Users\Noga\Desktop\Lister Family Office (3.5 back up)
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2017-05-27 11:44 - 2009-07-14 06:32 - 00000000 ____D C:\Windows\system32\FxsTmp
2017-05-27 11:34 - 2011-05-24 19:29 - 00000902 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2595249627-3671955670-1608175086-1000UA.job
2017-05-27 04:04 - 2009-07-14 05:45 - 00015360 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2017-05-27 04:04 - 2009-07-14 05:45 - 00015360 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2017-05-26 19:34 - 2011-05-24 19:29 - 00000850 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2595249627-3671955670-1608175086-1000Core.job
2017-05-26 08:15 - 2014-11-21 07:07 - 00000000 ___RD C:\Users\Noga\OneDrive
2017-05-26 01:11 - 2009-07-14 06:13 - 00006458 _____ C:\Windows\system32\PerfStringBackup.INI
2017-05-26 01:07 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2017-05-26 00:22 - 2012-08-05 17:50 - 02701312 ___SH C:\Users\Noga\Desktop\Thumbs.db
2017-05-25 20:24 - 2015-10-07 20:57 - 00008704 ___SH C:\Users\Noga\Documents\Thumbs.db
2017-05-25 09:07 - 2012-07-09 11:03 - 00000000 ___RD C:\Users\Noga\Desktop\Dropbox
2017-05-22 23:43 - 2012-04-13 06:14 - 00000000 ____D C:\Users\Noga\Desktop\Jacob
2017-05-19 22:59 - 2015-06-24 19:17 - 00000000 ____D C:\Users\Noga\AppData\Local\Dropbox
2017-05-17 19:24 - 2011-12-27 20:33 - 00000000 ____D C:\Users\Noga\AppData\Roaming\Dropbox
2017-05-14 19:49 - 2013-04-13 12:34 - 00334766 ____H C:\Users\Noga\Desktop\sync.ffs_db
2017-05-12 00:14 - 2012-02-27 11:23 - 00002195 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-05-11 04:12 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache
2017-05-11 03:23 - 2009-07-14 05:45 - 00442072 _____ C:\Windows\system32\FNTCACHE.DAT
2017-05-11 03:20 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\PolicyDefinitions
2017-05-07 22:50 - 2012-02-16 10:37 - 00000000 ____D C:\Users\Noga\AppData\Roaming\Skype
2017-05-07 01:42 - 2015-01-06 16:56 - 00004476 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2017-05-04 00:58 - 2012-03-02 21:23 - 00000000 ____D C:\Users\Noga\Desktop\White Cottage Ltd
2017-04-28 23:08 - 2016-05-10 23:45 - 00003330 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA1d1ab0db3b45cd3
2017-04-28 23:08 - 2016-05-10 23:45 - 00003202 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore1d1ab0db36d1998
 
==================== Files in the root of some directories =======
 
2012-06-05 12:22 - 2012-06-05 12:22 - 0000025 _____ () C:\Users\Noga\AppData\Roaming\bdfvconp.ini
2012-08-05 10:40 - 2012-10-02 23:43 - 0009315 _____ () C:\Users\Noga\AppData\Roaming\Comma Separated Values (Windows).EML
2015-10-24 00:11 - 2015-10-24 00:11 - 0000320 _____ () C:\Users\Noga\AppData\Roaming\SEC434660.trad
2013-06-24 13:37 - 2013-06-24 13:37 - 0000005 _____ () C:\Users\Noga\AppData\Roaming\WBPU-TTL.DAT
2014-01-28 19:48 - 2014-06-12 22:12 - 0000600 _____ () C:\Users\Noga\AppData\Roaming\winscp.rnd
2015-06-05 08:33 - 2015-06-11 22:34 - 0001035 _____ () C:\Users\Noga\AppData\Local\CPAUTO.tmp
2015-06-05 08:35 - 2015-06-05 08:35 - 0044623 _____ () C:\Users\Noga\AppData\Local\CPREBUILT.tmp
2014-04-04 17:57 - 2014-04-04 17:57 - 0004096 ____H () C:\Users\Noga\AppData\Local\keyfile3.drm
2011-06-09 14:49 - 2016-03-01 22:38 - 0000600 _____ () C:\Users\Noga\AppData\Local\PUTTY.RND
2013-01-28 08:38 - 2013-01-28 08:38 - 0007605 _____ () C:\Users\Noga\AppData\Local\Resmon.ResmonCfg
2012-09-23 22:39 - 2012-09-24 00:14 - 0000000 _____ () C:\Users\Noga\AppData\Local\¹º»¼½¾¿ÀÁÂÃÄÅÆÇÈÉÊËÌÍÎÏÐÑÒÓÔÕÖ×ØÙÚÛÜÝÞßàáâãäåæçèéêëìíîïðñòóôõö÷øùúûüýþÿ
2015-11-29 23:02 - 2015-11-29 23:02 - 0432299 _____ () C:\ProgramData\1448834088.bdinstall.bin
2015-12-08 03:14 - 2015-12-08 03:14 - 0025196 _____ () C:\ProgramData\1449540889.bdinstall.bin
2016-02-16 10:24 - 2016-02-16 10:24 - 0025115 _____ () C:\ProgramData\1455614638.bdinstall.bin
2016-03-22 16:20 - 2016-03-22 16:20 - 0025904 _____ () C:\ProgramData\1458660039.bdinstall.bin
2016-03-31 20:31 - 2016-03-31 20:31 - 0025976 _____ () C:\ProgramData\1459452679.bdinstall.bin
2016-04-08 18:50 - 2016-04-08 18:50 - 0000644 _____ () C:\ProgramData\1460137820.1232.bin
2016-04-08 18:50 - 2016-04-08 18:50 - 0000462 _____ () C:\ProgramData\1460137820.2040.bin
2016-04-08 18:50 - 2016-04-08 18:50 - 0095555 _____ () C:\ProgramData\1460137820.760.bin
2016-04-08 18:50 - 2016-04-08 18:50 - 0000644 _____ () C:\ProgramData\1460137851.1176.bin
2016-04-08 18:50 - 2016-04-08 18:50 - 0000462 _____ () C:\ProgramData\1460137851.1504.bin
2016-04-08 18:50 - 2016-04-08 18:50 - 0095555 _____ () C:\ProgramData\1460137851.696.bin
2016-04-08 18:51 - 2016-04-08 18:51 - 0019308 _____ () C:\ProgramData\1460137865.bdinstall.bin
2016-04-08 18:51 - 2016-04-08 18:51 - 0095555 _____ () C:\ProgramData\1460137873.408.bin
2016-04-08 18:51 - 2016-04-08 18:51 - 0000566 _____ () C:\ProgramData\1460137873.420.bin
2016-04-08 18:51 - 2016-04-08 18:51 - 0000461 _____ () C:\ProgramData\1460137873.820.bin
2015-09-25 21:41 - 2015-09-25 21:41 - 0000057 _____ () C:\ProgramData\Ament.ini
2012-06-27 16:13 - 2016-04-18 00:19 - 0001833 _____ () C:\ProgramData\hpzinstall.log
2011-09-26 14:32 - 2013-11-29 17:03 - 0000215 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc
2011-10-03 09:53 - 2015-11-25 19:56 - 0000268 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.351.64.bc
 
Some files in TEMP:
====================
2014-12-13 19:36 - 2014-12-13 19:36 - 0196608 ____N (Java™ Native Access (JNA)) C:\Users\Benjamin\AppData\Local\Temp\jna2913576329549756688.dll
2012-08-04 17:18 - 2012-08-04 17:18 - 0467992 _____ (Google Inc.) C:\Users\Jacob\AppData\Local\Temp\SearchWithGoogleUpdate.exe
2017-04-05 07:21 - 2017-04-05 07:21 - 0288456 _____ (Adobe Systems Incorporated) C:\Users\Noga\AppData\Local\Temp\AAMHelper.exe
2017-04-05 07:19 - 2015-03-05 08:54 - 2212008 _____ (Adobe Systems Incorporated) C:\Users\Noga\AppData\Local\Temp\AdobeApplicationManager.exe
2015-09-27 23:53 - 2014-11-19 10:25 - 1059168 _____ (Installer Setup                               ) C:\Users\Noga\AppData\Local\Temp\air263A.exe
2015-01-25 22:54 - 2015-01-25 22:54 - 0662936 _____ (Ask Partner Network) C:\Users\Noga\AppData\Local\Temp\APNSetup.exe
2013-11-17 16:08 - 2013-10-18 17:38 - 3705856 _____ () C:\Users\Noga\AppData\Local\Temp\bbxlinst_32.dll
2016-05-16 13:55 - 2016-05-16 13:55 - 1118360 _____ (© 2015 Microsoft Corporation) C:\Users\Noga\AppData\Local\Temp\BSvcProcessor.exe
2016-05-16 13:55 - 2016-05-16 13:55 - 0170128 _____ (© 2015 Microsoft Corporation) C:\Users\Noga\AppData\Local\Temp\BSvcUpdater.exe
2017-04-10 18:59 - 2017-04-10 18:59 - 3451392 _____ () C:\Users\Noga\AppData\Local\Temp\clean20.dll
2015-12-09 16:42 - 2015-12-09 16:42 - 0071168 _____ () C:\Users\Noga\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpmb4llz.dll
2017-04-10 18:59 - 2017-04-10 18:59 - 0008704 _____ (TradeStation Technologies) C:\Users\Noga\AppData\Local\Temp\GACInstaller.dll
2017-04-10 18:59 - 2017-04-10 18:59 - 0017920 _____ () C:\Users\Noga\AppData\Local\Temp\instutil.dll
2014-06-12 20:13 - 2014-06-12 20:13 - 0196608 ____N (Java™ Native Access (JNA)) C:\Users\Noga\AppData\Local\Temp\jna7486168748605499536.dll
2013-10-08 19:27 - 2013-10-08 19:27 - 0915368 _____ (Oracle Corporation) C:\Users\Noga\AppData\Local\Temp\jre-7u45-windows-i586-iftw.exe
2014-04-15 21:50 - 2014-04-15 21:50 - 0921512 _____ (Oracle Corporation) C:\Users\Noga\AppData\Local\Temp\jre-7u55-windows-i586-iftw.exe
2014-07-28 06:15 - 2014-07-28 06:15 - 0918440 _____ (Oracle Corporation) C:\Users\Noga\AppData\Local\Temp\jre-7u67-windows-i586-iftw.exe
2014-12-18 18:29 - 2014-12-18 18:29 - 0641448 _____ (Oracle Corporation) C:\Users\Noga\AppData\Local\Temp\jre-8u31-windows-au.exe
2013-07-18 15:06 - 2013-03-06 10:08 - 0049152 _____ (Microsoft Corporation) C:\Users\Noga\AppData\Local\Temp\Microsoft.Deployment.Compression.Cab.dll
2013-07-18 15:06 - 2013-03-06 10:08 - 0036864 _____ (Microsoft Corporation) C:\Users\Noga\AppData\Local\Temp\Microsoft.Deployment.Compression.dll
2013-07-18 15:06 - 2013-03-06 10:08 - 0176128 _____ (Microsoft Corporation) C:\Users\Noga\AppData\Local\Temp\Microsoft.Deployment.WindowsInstaller.dll
2013-07-18 15:06 - 2013-03-06 10:08 - 0057344 _____ (Microsoft Corporation) C:\Users\Noga\AppData\Local\Temp\Microsoft.Deployment.WindowsInstaller.Package.dll
2014-02-09 21:29 - 2014-02-09 21:29 - 0049664 _____ () C:\Users\Noga\AppData\Local\Temp\Mql4PathFinder.dll
2017-04-10 18:59 - 2017-04-10 18:59 - 0005632 _____ (TradeStation) C:\Users\Noga\AppData\Local\Temp\RegistASM.exe
2015-09-27 23:53 - 2014-11-19 10:25 - 1059168 _____ (Installer Setup                               ) C:\Users\Noga\AppData\Local\Temp\setup.exe
2014-10-20 17:09 - 2017-04-05 14:07 - 57551320 _____ (Skype Technologies S.A.) C:\Users\Noga\AppData\Local\Temp\SkypeSetup.exe
2012-03-16 05:13 - 2012-11-29 15:40 - 5687992 _____ (TeamViewer) C:\Users\Noga\AppData\Local\Temp\TeamViewer_.exe
2013-07-18 15:06 - 2013-03-06 17:48 - 0177008 _____ () C:\Users\Noga\AppData\Local\Temp\TradeStation.PatchUtility.exe
2017-04-10 18:59 - 2017-04-10 18:59 - 1548656 _____ (TradeStation Technologies, Inc.) C:\Users\Noga\AppData\Local\Temp\TSInst10.exe
2017-04-10 18:59 - 2017-04-10 18:59 - 0052736 _____ (TradeStation) C:\Users\Noga\AppData\Local\Temp\TSInstallCAUtils.dll
2017-05-25 09:12 - 2017-05-25 09:12 - 0011360 _____ (Tarma Software Research Pty Ltd) C:\Users\Noga\AppData\Local\Temp\_TinDel.exe
 
==================== Bamital & volsnap ======================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
 
LastRegBack: 2017-05-23 00:49
 
==================== End of FRST.txt ============================
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 24-05-2017
Ran by Noga (27-05-2017 11:57:01)
Running from C:\Users\Noga\Downloads
Windows 7 Professional Service Pack 1 (X64) (2011-05-16 15:11:04)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-2595249627-3671955670-1608175086-500 - Administrator - Disabled)
Benjamin (S-1-5-21-2595249627-3671955670-1608175086-1002 - Limited - Enabled) => C:\Users\Benjamin
Guest (S-1-5-21-2595249627-3671955670-1608175086-501 - Limited - Enabled) => C:\Users\Guest
HomeGroupUser$ (S-1-5-21-2595249627-3671955670-1608175086-1006 - Limited - Enabled)
Jacob (S-1-5-21-2595249627-3671955670-1608175086-1004 - Limited - Enabled) => C:\Users\Jacob
Noga (S-1-5-21-2595249627-3671955670-1608175086-1001 - Administrator - Enabled) => C:\Users\Noga
Steve (S-1-5-21-2595249627-3671955670-1608175086-1003 - Limited - Enabled)
user (S-1-5-21-2595249627-3671955670-1608175086-1000 - Administrator - Enabled) => C:\Users\user
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Microsoft Security Essentials (Enabled - Up to date) {71A27EC9-3DA6-45FC-60A7-004F623C6189}
AS: Microsoft Security Essentials (Enabled - Up to date) {CAC39F2D-1B9C-4A72-5A17-3B3D19BB2B34}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
64 Bit HP CIO Components Installer (Version: 7.2.8 - Hewlett-Packard) Hidden
6500_E709_eDocs (x32 Version: 1.00.0000 - Hewlett-Packard) Hidden
Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 17.009.20044 - Adobe Systems Incorporated)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 2.6.0.19140 - Adobe Systems Incorporated)
Adobe Captivate 9 (64 Bit) (HKLM-x32\...\{BF58ED42-4121-11E5-889B-DA4C38A5DEE9}) (Version: 9.0 - Adobe Systems Incorporated)
Adobe Captivate Quiz Results Analyzer (HKLM-x32\...\QuizResultsAnalyzer9) (Version: 9 - Adobe Systems Incorporated)
Adobe Creative Cloud (HKLM-x32\...\Adobe Creative Cloud) (Version: 3.9.5.353 - Adobe Systems Incorporated)
Adobe Flash Player 21 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 21.0.0.197 - Adobe Systems Incorporated)
Adobe Flash Player 21 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 21.0.0.197 - Adobe Systems Incorporated)
Adobe Flash Player 23 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 23.0.0.185 - Adobe Systems Incorporated)
Amazon Kindle (HKU\S-1-5-21-2595249627-3671955670-1608175086-1001\...\Amazon Kindle) (Version:  - Amazon)
Apple Application Support (HKLM-x32\...\{83CAF0DE-8D3B-4C37-A631-2B8F16EC3031}) (Version: 3.1 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{BDD99690-3541-4619-9D2A-3CDDB3E15F9E}) (Version: 8.0.5.6 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
bpd_scan (x32 Version: 3.00.0000 - Hewlett-Packard) Hidden
BPDSoftware (x32 Version: 140.0.000.000 - Hewlett-Packard) Hidden
BPDSoftware_Ini (x32 Version: 1.00.0000 - Hewlett-Packard) Hidden
BufferChm (x32 Version: 140.0.213.000 - Hewlett-Packard) Hidden
Check Point Endpoint Connect (HKLM-x32\...\{974D79BA-C8C2-4145-AAF7-B6EBB02803FC}) (Version: 5.41.0000 - CheckPoint)
Cisco WebEx Meetings (HKU\S-1-5-21-2595249627-3671955670-1608175086-1001\...\ActiveTouchMeetingClient) (Version:  - Cisco WebEx LLC)
Citrix Online Launcher (HKLM-x32\...\{1B1BF50E-ACE8-4481-B362-89544FB1CD4B}) (Version: 1.0.357 - Citrix)
Citrix Receiver (HKLM-x32\...\CitrixOnlinePluginPackWeb) (Version: 13.1.0.89 - Citrix Systems, Inc.)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Destinations (x32 Version: 130.0.0.0 - Hewlett-Packard) Hidden
DeviceDiscovery (x32 Version: 140.0.213.000 - Hewlett-Packard) Hidden
DocMgr (x32 Version: 140.0.65.000 - Hewlett-Packard) Hidden
DocProc (x32 Version: 140.0.100.000 - Hewlett-Packard) Hidden
DriverIdentifier 4.2 (HKLM-x32\...\{40A3E5DB-5EF8-4F04-BF3E-7AB87C4AE85A}_is1) (Version:  - DriverIdentifier)
Dropbox (HKU\S-1-5-21-2595249627-3671955670-1608175086-1001\...\Dropbox) (Version: 26.4.24 - Dropbox, Inc.)
English Country Tune (HKLM\...\Steam App 207570) (Version:  - increpare games)
Etron USB3.0 Host Controller (HKLM-x32\...\InstallShield_{DFBB738C-71D8-4DC5-B8D2-D65C37680E27}) (Version: 0.114 - Etron Technology)
Etron USB3.0 Host Controller (x32 Version: 0.114 - Etron Technology) Hidden
Facebook Video Calling 3.1.0.521 (HKLM-x32\...\{2091F234-EB58-4B80-8C96-8EB78C808CF7}) (Version: 3.1.521 - Skype Limited)
Fax (x32 Version: 140.0.213.000 - Hewlett-Packard) Hidden
File Type Assistant (HKLM-x32\...\Trusted Software Assistant_is1) (Version:  - Trusted Software) <==== ATTENTION
FileZilla Client 3.16.0 (HKLM-x32\...\FileZilla Client) (Version: 3.16.0 - Tim Kosse)
FreeFileSync 5.13 (HKLM-x32\...\FreeFileSync) (Version: 5.13 - Zenju)
FXCM MetaTrader 4 (HKLM-x32\...\FXCM MetaTrader 4) (Version: 4.00 - MetaQuotes Software Corp.)
FXCM Strategy Trader (HKLM-x32\...\FXCM Strategy Trader) (Version: 1.0.321 - FXCM)
FXCM Strategy Trader (x32 Version: 1.0.321 - FXCM) Hidden
FXCM Trading Station (HKLM-x32\...\FXCM Trading Station) (Version: 111313 - )
FXCM Trading Station (x32 Version: 111313 - FXCM) Hidden
FxPro cTrader (HKU\S-1-5-21-2595249627-3671955670-1608175086-1001\...\3adaa2a4f1ebb465) (Version: 1.38.65534.34939 - FxPro cTrader)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 58.0.3029.110 - Google Inc.)
Google Talk Plugin (HKLM-x32\...\{F9B579C2-D854-300A-BE62-A09EB9D722E4}) (Version: 5.41.3.0 - Google)
Google Toolbar for Internet Explorer (HKLM-x32\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.8231.2252 - Google Inc.)
Google Toolbar for Internet Explorer (x32 Version: 1.0.0 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.33.5 - Google Inc.) Hidden
GoToAssist Corporate (HKLM-x32\...\GoToAssist) (Version: 11.0.0.1019 - Citrix Online, a division of Citrix Systems, Inc.)
GoToMeeting 7.15.0.4732 (HKU\S-1-5-21-2595249627-3671955670-1608175086-1001\...\GoToMeeting) (Version: 7.15.0.4732 - CitrixOnline)
GPBaseService2 (x32 Version: 140.0.212.000 - Hewlett-Packard) Hidden
hotComm® CL (HKLM-x32\...\hotComm® CL) (Version: 8.00.003x - 1stWorks Corporation)
HP Customer Participation Program 14.0 (HKLM\...\HPExtendedCapabilities) (Version: 14.0 - HP)
HP Document Manager 2.0 (HKLM\...\HP Document Manager) (Version: 2.0 - HP)
HP Imaging Device Functions 14.0 (HKLM\...\HP Imaging Device Functions) (Version: 14.0 - HP)
HP Officejet 5740 series Basic Device Software (HKLM\...\{7FAA9D15-FF0B-4593-8D4A-0B941FD1977A}) (Version: 34.2.117.50647 - Hewlett-Packard Co.)
HP Officejet 5740 series Help (HKLM-x32\...\{F17D53C7-DCE8-469C-9690-CF8F5903519C}) (Version: 34.0.0 - Hewlett Packard)
HP Officejet 6500 E709 Series (HKLM\...\{58D79E62-CFC8-4331-8469-3A1B16E1769C}) (Version: 14.0 - HP)
HP Officejet 6500 E710n-z Basic Device Software (HKLM\...\{ADDF4B84-5D28-4EAE-8511-EF808C8BC81C}) (Version: 22.50.231.0 - Hewlett-Packard Co.)
HP Officejet 6500 E710n-z Help (HKLM-x32\...\{130E5108-547F-4482-91EE-F45C784E08C7}) (Version: 140.0.2.2 - Hewlett Packard)
HP Officejet 6500 E710n-z Product Improvement Study (HKLM\...\{D5510D28-D0E4-433E-A0F3-EE3FCECA60D2}) (Version: 22.50.231.0 - Hewlett-Packard Co.)
HP Photo Creations (HKLM-x32\...\HP Photo Creations) (Version: 1.0.0.9572 - HP)
HP Smart Web Printing 4.60 (HKLM\...\HP Smart Web Printing) (Version: 4.60 - HP)
HP Solution Center 14.0 (HKLM\...\HP Solution Center & Imaging Support Tools) (Version: 14.0 - HP)
HP Support Solutions Framework (HKLM-x32\...\{F6A11738-3EE4-4573-AEA5-6CD5D491C167}) (Version: 12.2.8.17 - Hewlett-Packard Company)
HP Update (HKLM-x32\...\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
HPDiagnosticAlert (x32 Version: 1.00.0000 - Microsoft) Hidden
HPProductAssistant (x32 Version: 140.0.213.000 - Hewlett-Packard) Hidden
I.R.I.S. OCR (HKLM-x32\...\{CA6BCA2F-EDEB-408F-850B-31404BE16A61}) (Version: 12.3.4.0 - HP)
ImgBurn (HKLM-x32\...\ImgBurn) (Version: 2.5.7.0 - LIGHTNING UK!)
Intel® Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation)
Intel® Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 10.1.0.1008 - Intel Corporation)
iTunes (HKLM\...\{2ABBBD91-91E5-4AD7-929A-FE15D1DC0576}) (Version: 12.0.1.26 - Apple Inc.)
Java 8 Update 31 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218031F0}) (Version: 8.0.310 - Oracle Corporation)
JavaFX 2.1.1 (HKLM-x32\...\{1111706F-666A-4037-7777-211328764D10}) (Version: 2.1.1 - Oracle Corporation)
join.me (HKU\S-1-5-21-2595249627-3671955670-1608175086-1001\...\JoinMe) (Version: 1.20.0.116 - LogMeIn, Inc.)
LinuxLive USB Creator (HKLM-x32\...\LinuxLive USB Creator) (Version: 2.8 - Thibaut Lauziere)
Manager (x32 Version: 4.1.4.27792 - 2015 pdfforge GmbH. All rights reserved) Hidden
MarketResearch (x32 Version: 140.0.214.000 - Hewlett-Packard) Hidden
Matrox M-Series WDDM Driver (HKLM-x32\...\Matrox Vista Driver Uninstaller) (Version:  - Matrox Graphics Inc.)
Matrox PowerDesk (HKLM\...\{105406F7-DD53-4C5C-9543-8B261D30FB29}) (Version: 1.12.0105.0815 4.01 (M-Series) - Matrox Graphics Inc.)
Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
MessageSave (remove only) (HKLM-x32\...\MessageSave) (Version:  - TechHit)
MetaTrader 4 Terminal (HKLM-x32\...\MetaTrader 4 Terminal) (Version: 4.00 - MetaQuotes Software Corp.)
Microsoft .NET Framework 4.6.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.6.01055 - Microsoft Corporation)
Microsoft ASP.NET MVC 2 (HKLM-x32\...\{DD8FF2F3-0D97-4CF3-AF78-FA0E1B242244}) (Version: 2.0.60926.0 - Microsoft Corporation)
Microsoft Office 365 - en-us (HKLM\...\O365HomePremRetail - en-us) (Version: 16.0.6741.2021 - Microsoft Corporation)
Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-2595249627-3671955670-1608175086-1001\...\OneDriveSetup.exe) (Version: 17.3.6799.0327 - Microsoft Corporation)
Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.10.209.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50906.0 - Microsoft Corporation)
Microsoft SOAP Toolkit 3.0 (HKLM-x32\...\{BCB4C18A-ACA6-4383-8688-E19933A705DD}) (Version: 3.0.1325.4 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148 (HKLM\...\{EE936C7A-EA40-31D5-9B65-8E3E089C3828}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729 (HKLM\...\{14297226-E0A0-3781-8911-E9D529552663}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23918 (HKLM-x32\...\{dab68466-3a7d-41a8-a5cf-415e3ff8ef71}) (Version: 14.0.23918.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23918 (HKLM-x32\...\{2e085fd2-a3e4-4b39-8e10-6b8d35f55244}) (Version: 14.0.23918.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.60825 - Microsoft Corporation)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 31.0 - Mozilla)
Mozilla Thunderbird 38.2.0 (x86 en-GB) (HKLM-x32\...\Mozilla Thunderbird 38.2.0 (x86 en-GB)) (Version: 38.2.0 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
NClass 2.04 (HKLM-x32\...\NClass_is1) (Version: 2.04 - Balazs Tihanyi)
Network64 (Version: 140.0.215.000 - Hewlett-Packard) Hidden
Network64 (Version: 140.0.221.000 - Hewlett-Packard) Hidden
NinjaTrader 7 (HKLM-x32\...\{24FC6468-8EA9-493B-A6CD-4F2DC1FD9A96}) (Version: 7.0.1021 - NinjaTrader)
NirSoft BlueScreenView (HKLM-x32\...\NirSoft BlueScreenView) (Version:  - )
OCR Software by I.R.I.S. 14.0 (HKLM\...\HPOCR) (Version: 14.0 - HP)
Office 16 Click-to-Run Extensibility Component (Version: 16.0.6701.1013 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (Version: 16.0.6701.1013 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (Version: 16.0.6701.1013 - Microsoft Corporation) Hidden
OGA Notifier 1.7.0105.14.0 (x32 Version: 1.7.0105.14.0 - Microsoft Corporation) Hidden
Online Plug-in (x32 Version: 13.1.0.89 - Citrix Systems, Inc.) Hidden
PDF Architect 4 (HKLM-x32\...\PDF Architect 4) (Version: 4.0.34.26215 - pdfforge GmbH)
PDF Architect 4 Create Module (Version: 4.1.5.29097 - pdfforge GmbH) Hidden
PDF Architect 4 Edit Module (Version: 4.1.5.29097 - pdfforge GmbH) Hidden
PDF Architect 4 View Module (Version: 4.1.5.29097 - pdfforge GmbH) Hidden
PDFCreator (HKLM\...\{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}) (Version: 2.4.1 - pdfforge GmbH)
PS3 Media Server (HKLM-x32\...\PS3 Media Server) (Version: 1.90.1 - PS3 Media Server)
Realtek Ethernet Controller Driver For Windows 7 (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.23.623.2010 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6167 - Realtek Semiconductor Corp.)
Rithmic Trader 12.29.0.0 (HKLM-x32\...\{F558281E-4F43-4597-8964-2E690FCB0A1E}) (Version: 12.29.0 - Omnesys Technologies, Inc.)
Scan (x32 Version: 140.0.167.000 - Hewlett-Packard) Hidden
Self-service Plug-in (x32 Version: 3.1.0.21744 - Citrix Systems, Inc.) Hidden
Skype Click to Call (HKLM-x32\...\{873F8E7C-10E6-449F-BD7E-5FBA7C8E1C9B}) (Version: 8.5.0.9167 - Microsoft Corporation)
Skype™ 7.33 (HKLM-x32\...\{3B7E914A-93D5-4A29-92BB-AF8C3F66C431}) (Version: 7.33.104 - Skype Technologies S.A.)
SmartWebPrinting (x32 Version: 140.0.213.000 - Hewlett-Packard) Hidden
SolutionCenter (x32 Version: 140.0.214.000 - Hewlett-Packard) Hidden
Status (x32 Version: 140.0.256.000 - Hewlett-Packard) Hidden
Syncables 360 (HKLM-x32\...\{D9CB27A3-0540-41F9-9DA1-855FF2AA84CA}) (Version: 7.0.991.15374 - Syncables)
SyncBackFree (HKLM-x32\...\SyncBackFree_is1) (Version: 6.3.13.0 - 2BrightSparks)
Syncios version 2.0.5 (HKLM-x32\...\{068A5D84-8419-4BDE-9689-FE65F412EFBB}_is1) (Version: 2.0.5 - Anvsoft, Inc.)
System Requirements Lab for Intel (HKLM-x32\...\{CD41B576-4787-4D5C-95EE-24A4ABD89CD3}) (Version: 4.4.24.0 - Husdawg, LLC)
Tallinex MetaTrader 4 (HKLM-x32\...\Tallinex MetaTrader 4) (Version: 4.00 - MetaQuotes Software Corp.)
TeamViewer 7 (HKLM-x32\...\TeamViewer 7) (Version: 7.0.14563 - TeamViewer)
TeamViewer 8 (HKLM-x32\...\TeamViewer 8) (Version: 8.0.44109 - TeamViewer)
TightVNC 2.0.4 (HKLM-x32\...\TightVNC) (Version: 2.0.4 - GlavSoft LLC.)
Toolbox (x32 Version: 140.0.428.000 - Hewlett-Packard) Hidden
Trader Workstation 4.0 (HKLM-x32\...\Trader Workstation 4.0) (Version:  - )
TradeStation 9.0 (HKLM-x32\...\{6EF11260-2361-409D-B91C-373D8732EED8}) (Version: 9.0.0.8768 - TradeStation Technologies)
TradeStation 9.1 (HKLM-x32\...\{B948B39D-214F-486E-BCD9-8AB691F8762A}) (Version: 9.01.00.12880 - TradeStation Technologies)
TrayApp (x32 Version: 140.0.213.000 - Hewlett-Packard) Hidden
Unity Web Player (HKU\S-1-5-21-2595249627-3671955670-1608175086-1001\...\UnityWebPlayer) (Version: 4.6.2f1 - Unity Technologies ApS)
WebReg (x32 Version: 140.0.213.017 - Hewlett-Packard) Hidden
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3555.0308 - Microsoft Corporation)
Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\...\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation)
Windows Media Player Firefox Plugin (HKLM-x32\...\{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}) (Version: 1.0.0.8 - Microsoft Corp)
WinRAR 4.20 (64-bit) (HKLM\...\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH)
Xvid MPEG-4 Video Codec (HKLM-x32\...\xvid) (Version:  - Xvid Development Team)
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-2595249627-3671955670-1608175086-1001_Classes\CLSID\{004B49B7-11B9-5058-FF22-08DD093ADC4B}\InprocServer32 -> {1848255E-9468-D082-08B5-39E985889A47} => No File
CustomCLSID: HKU\S-1-5-21-2595249627-3671955670-1608175086-1001_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Noga\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2595249627-3671955670-1608175086-1001_Classes\CLSID\{1423F872-3F7F-4E57-B621-8B1A9D49B448}\InprocServer32 -> C:\Users\Noga\AppData\Local\Google\Update\1.3.27.5\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-2595249627-3671955670-1608175086-1001_Classes\CLSID\{144DF3B2-2402-47AE-9583-5A045929A8D4}\InprocServer32 -> C:\Users\Noga\AppData\Local\Google\Update\1.3.33.5\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-2595249627-3671955670-1608175086-1001_Classes\CLSID\{162C6FB5-44D3-435B-903D-E613FA093FB5}\InprocServer32 -> C:\Users\Noga\AppData\Local\Microsoft\OneDrive\17.3.6799.0327\amd64\FileCoAuthLib64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-2595249627-3671955670-1608175086-1001_Classes\CLSID\{590C4387-5EBD-4D46-8A84-CD0BA2EF2856}\InprocServer32 -> C:\Users\Noga\AppData\Local\Google\Update\1.3.30.3\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-2595249627-3671955670-1608175086-1001_Classes\CLSID\{59B55F04-DE14-4BB8-92FF-C4A22EF2E5F4}\InprocServer32 -> C:\Users\Noga\AppData\Local\Google\Update\1.3.31.5\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-2595249627-3671955670-1608175086-1001_Classes\CLSID\{5C8C2A98-6133-4EBA-BBCC-34D9EA01FC2E}\InprocServer32 -> C:\Users\Noga\AppData\Local\Google\Update\1.3.28.1\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-2595249627-3671955670-1608175086-1001_Classes\CLSID\{78550997-5DEF-4A8A-BAF9-D5774E87AC98}\InprocServer32 -> C:\Users\Noga\AppData\Local\Google\Update\1.3.28.13\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-2595249627-3671955670-1608175086-1001_Classes\CLSID\{793EE463-1304-471C-ADF1-68C2FFB01247}\InprocServer32 -> C:\Users\Noga\AppData\Local\Google\Update\1.3.29.5\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-2595249627-3671955670-1608175086-1001_Classes\CLSID\{84B5A313-CD5D-4904-8BA2-AFDC81C1B309}\InprocServer32 -> C:\Users\Noga\AppData\Local\Citrix\GoToMeeting\4190\G2MOutlookAddin64.dll (Citrix Online, a division of Citrix Systems, Inc.)
CustomCLSID: HKU\S-1-5-21-2595249627-3671955670-1608175086-1001_Classes\CLSID\{8C46158B-D978-483C-A312-16EE5013BE04}\InprocServer32 -> C:\Users\Noga\AppData\Local\Google\Update\1.3.33.3\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-2595249627-3671955670-1608175086-1001_Classes\CLSID\{C3BC25C0-FCD3-4F01-AFDD-41373F017C9A}\InprocServer32 -> C:\Users\Noga\AppData\Local\Google\Update\1.3.26.9\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-2595249627-3671955670-1608175086-1001_Classes\CLSID\{CB492AF1-2CEF-4E58-BE47-471C77D0C8BA}\InprocServer32 -> C:\Users\Noga\AppData\Local\Google\Update\1.3.32.7\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-2595249627-3671955670-1608175086-1001_Classes\CLSID\{CC182BE1-84CE-4A57-B85C-FD4BBDF78CB2}\InprocServer32 -> C:\Users\Noga\AppData\Local\Google\Update\1.3.29.1\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-2595249627-3671955670-1608175086-1001_Classes\CLSID\{D0336C0B-7919-4C04-8CCE-2EBAE2ECE8C9}\InprocServer32 -> C:\Users\Noga\AppData\Local\Google\Update\1.3.25.11\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-2595249627-3671955670-1608175086-1001_Classes\CLSID\{D1EDC4F5-7F4D-4B12-906A-614ECF66DDAF}\InprocServer32 -> C:\Users\Noga\AppData\Local\Google\Update\1.3.28.15\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-2595249627-3671955670-1608175086-1001_Classes\CLSID\{DD0822FF-3A09-4BDC-B749-4B00B9115850}\InprocServer32 -> {5D06B960-9468-D082-3629-77AC85889A47} => No File
CustomCLSID: HKU\S-1-5-21-2595249627-3671955670-1608175086-1001_Classes\CLSID\{e8c77137-e224-5791-b6e9-ff0305797a13}\InprocServer32 -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems)
CustomCLSID: HKU\S-1-5-21-2595249627-3671955670-1608175086-1001_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\Noga\AppData\Local\Google\Update\1.3.33.5\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-2595249627-3671955670-1608175086-1001_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\Noga\AppData\Roaming\Dropbox\bin\DropboxExt64.16.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2595249627-3671955670-1608175086-1001_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Noga\AppData\Roaming\Dropbox\bin\DropboxExt64.16.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2595249627-3671955670-1608175086-1001_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Noga\AppData\Roaming\Dropbox\bin\DropboxExt64.16.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2595249627-3671955670-1608175086-1001_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Noga\AppData\Roaming\Dropbox\bin\DropboxExt64.16.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2595249627-3671955670-1608175086-1001_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Noga\AppData\Roaming\Dropbox\bin\DropboxExt64.16.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2595249627-3671955670-1608175086-1001_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Noga\AppData\Roaming\Dropbox\bin\DropboxExt64.16.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2595249627-3671955670-1608175086-1001_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Noga\AppData\Roaming\Dropbox\bin\DropboxExt64.16.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2595249627-3671955670-1608175086-1001_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Noga\AppData\Roaming\Dropbox\bin\DropboxExt64.16.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2595249627-3671955670-1608175086-1001_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Noga\AppData\Roaming\Dropbox\bin\DropboxExt64.16.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2595249627-3671955670-1608175086-1001_Classes\CLSID\{FB314EE1-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Noga\AppData\Roaming\Dropbox\bin\DropboxExt64.16.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2595249627-3671955670-1608175086-1001_Classes\CLSID\{FB314EE2-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Noga\AppData\Roaming\Dropbox\bin\DropboxExt64.16.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-2595249627-3671955670-1608175086-1001_Classes\CLSID\{FBC9D74C-AF55-4309-9FB2-C426E071637F}\InprocServer32 -> C:\Users\Noga\AppData\Roaming\Dropbox\bin\DropboxExt64.16.0.dll (Dropbox, Inc.)
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {06CE8FB7-238B-476D-8133-49437F2E445D} - System32\Tasks\{A6287378-75E4-4FCF-AA91-8B9BF126DC03} => pcalua.exe -a C:\Users\Noga\Downloads\remote.exe -d C:\Users\Noga\Downloads
Task: {06E2CBB8-60F3-4B5F-A593-18C780F2559F} - System32\Tasks\Microsoft\Microsoft Antimalware\Microsoft Antimalware Scheduled Scan => c:\Program Files\Microsoft Security Client\\MpCmdRun.exe [2016-11-14] (Microsoft Corporation)
Task: {0DEE167B-38A1-4AE1-A85F-3CA41E5AC0BB} - System32\Tasks\ProgramUpdateCheck => C:\Program Files (x86)\File Type Assistant\TSAssist.exe [2012-08-10] (Trusted Software ApS) <==== ATTENTION
Task: {25AFF8DB-F6A4-460E-B5DB-D627834AD06A} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-2595249627-3671955670-1608175086-1001UA => C:\Users\Noga\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-24] (Dropbox, Inc.)
Task: {27122F49-DF38-4E75-A8C8-477C2FB596A0} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2595249627-3671955670-1608175086-1001Core => C:\Users\Noga\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.)
Task: {27F7D2AE-DAF2-47DC-9C24-7C876013A370} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-10-19] (Adobe Systems Incorporated)
Task: {2F57269B-1E09-4E2D-AB1E-B0FDAC7D279C} - \Microsoft\Windows\WindowsBackup\ConfigNotification -> No File <==== ATTENTION
Task: {31237FFB-A8E7-4094-852B-2910F1EFCA5B} - System32\Tasks\{4952F359-6BA6-4181-93DC-060026D97A39} => pcalua.exe -a C:\Users\Noga\Downloads\EOTPRO_Indicator_Installer_Ninja_7p0p1000p4.exe -d C:\Users\Noga\Desktop
Task: {3F665821-6232-4762-889E-E1A635E6E392} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2595249627-3671955670-1608175086-1001UA => C:\Users\Noga\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.)
Task: {44C7B0B7-5143-4832-8B33-BE6AEB7DDA74} - System32\Tasks\HP AR Program Upload - 4473bca6ccf041a8960fcad743364842a351530c75744bd3b9bc27a407886930 => C:\Program Files\HP\HP Officejet 5740 series\bin\HPRewards.exe [2014-08-22] (Hewlett-Packard Development Company, LP)
Task: {44D998B8-7066-4136-9002-E10801019D80} - System32\Tasks\TradeStation Backup - Daily => C:\Program Files (x86)\TradeStation 9.1\Program\TSBackupRestore.exe [2014-06-16] (TradeStation Technologies, Inc.)
Task: {44E10F34-C309-42FB-B21D-DD648709CC00} - System32\Tasks\G2MUpdateTask-S-1-5-21-2595249627-3671955670-1608175086-1001 => C:\Users\Noga\AppData\Local\Citrix\GoToMeeting\4732\g2mupdate.exe [2016-03-30] (Citrix Online, a division of Citrix Systems, Inc.)
Task: {492DBEAA-7002-4BA7-9FF8-97D9E81DC5F0} - System32\Tasks\HP AR Program Upload - ef2d345f62b749a5be9464297617a8b46727789e22824a6e923d27a99fd07d3e => C:\Program Files\HP\HP Officejet 5740 series\bin\HPRewards.exe [2014-08-22] (Hewlett-Packard Development Company, LP)
Task: {4A56BF25-3375-4DC4-8371-1B5900201438} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe 
Task: {4C7CBE6B-CE90-4AAD-BE0F-229E9070692A} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {542BF24A-4D25-47A8-B88F-F92C4BE8D596} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-2595249627-3671955670-1608175086-1001Core => C:\Users\Noga\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-06-26] (Facebook Inc.)
Task: {590CE7A8-5043-4F79-BA60-E0C92004D051} - System32\Tasks\HPCustParticipation HP Officejet 6500 E710n-z => C:\Program Files\HP\HP Officejet 6500 E710n-z\Bin\HPCustPartic.exe [2010-11-16] (Hewlett-Packard Co.)
Task: {5C62950F-A442-488C-A470-E319839745EF} - System32\Tasks\HP AR Program Upload - 367ba1eab7684c7496fd1130d65e1f8e22aef0f17c384760894a88975cc45867 => C:\Program Files\HP\HP Officejet 5740 series\bin\HPRewards.exe [2014-08-22] (Hewlett-Packard Development Company, LP)
Task: {5C7AEFBA-5FB6-40A1-9621-EB0F4B01EE05} - System32\Tasks\Bitdefender Update Product Data_A17FD818A96743FAB28AC221BEB4B2C8 => C:\Program Files\Bitdefender\Bitdefender 2015\bdproductdata.exe 
Task: {6C475118-8A1E-4BA0-B739-C03EC9F86082} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [2016-03-07] (Hewlett-Packard)
Task: {710C9E9D-B64A-4E9E-899F-303F2B6DECB3} - System32\Tasks\Bitdefender Agent WatchDog_65D6944A0EF74FDAB96E31112AD39864 => C:\Program Files\Bitdefender Agent\WatchDog.exe 
Task: {717C7BC7-A5DC-433C-9C72-414263A8C5D8} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2017-04-25] (Adobe Systems Incorporated)
Task: {7233C184-71C3-40A9-9A1A-F86155ADC7F0} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-2595249627-3671955670-1608175086-1001Core => C:\Users\Noga\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-24] (Dropbox, Inc.)
Task: {732F4281-B87D-4FAB-920C-B585CA8DCF4E} - \Microsoft\Windows\Windows Activation Technologies\ValidationTask -> No File <==== ATTENTION
Task: {76784993-79FD-4AF6-8FB9-8AD64F858956} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2595249627-3671955670-1608175086-1001UA1d1ab06610612b => C:\Users\Noga\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.)
Task: {7B9323A8-0DA2-454F-9053-D89E0D84D577} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2595249627-3671955670-1608175086-1001Core1d1ab065e49597 => C:\Users\Noga\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.)
Task: {7EE32D11-F58B-4313-836C-085A244831B1} - System32\Tasks\G2MUploadTask-S-1-5-21-2595249627-3671955670-1608175086-1001 => C:\Users\Noga\AppData\Local\Citrix\GoToMeeting\4732\g2mupload.exe [2016-03-30] (Citrix Online, a division of Citrix Systems, Inc.)
Task: {8435931F-8069-4705-92B7-B97BDF2D3793} - System32\Tasks\HP AR Program Upload - aee93b930a134545a2dfc1ed813b011ad23ad52c54bd40d8b8c49321019dc0d9 => C:\Program Files\HP\HP Officejet 5740 series\bin\HPRewards.exe [2014-08-22] (Hewlett-Packard Development Company, LP)
Task: {848C7FF4-BBAB-48B5-B895-90D9803A8B96} - System32\Tasks\HP AR Program Upload - dac60fc30aa748e8a6cfedef3d1d1edc471c3a2caa5a410ab132254069881546 => C:\Program Files\HP\HP Officejet 5740 series\bin\HPRewards.exe [2014-08-22] (Hewlett-Packard Development Company, LP)
Task: {8FDE953D-DFC6-4912-8CF4-70FB94A42E4B} - System32\Tasks\GoogleUpdateTaskMachineCore1d1ab0db36d1998 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {9256D866-570B-44BA-8037-A3ECE40B05FA} - System32\Tasks\TradeStation Backup - Monthly => C:\Program Files (x86)\TradeStation 9.1\Program\TSBackupRestore.exe [2014-06-16] (TradeStation Technologies, Inc.)
Task: {9818E6C4-D1D7-48ED-BCCF-C82258641E6D} - System32\Tasks\{68A994DE-33DD-46E1-8F82-181F900DAE81} => Chrome.exe hxxp://ui.skype.com/ui/0/7.13.0.101/en/abandoninstall?page=tsProgressBar
Task: {994F79E5-1EC0-485F-8D25-A4CCEE2DB4F1} - System32\Tasks\FacebookUpdateTaskUserS-1-5-21-2595249627-3671955670-1608175086-1001UA => C:\Users\Noga\AppData\Local\Facebook\Update\FacebookUpdate.exe [2013-06-26] (Facebook Inc.)
Task: {9A13655D-F89A-4AC8-9DF1-6C3715D41D5F} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_21_0_0_197_pepper.exe [2016-03-24] (Adobe Systems Incorporated)
Task: {9D541FFD-8E78-4D96-986B-7338E92581C8} - System32\Tasks\{3704A309-0437-464B-8D42-01D8A0723843} => pcalua.exe -a "C:\Program Files (x86)\Evaer\EvaerUninstaller.exe" -d C:\Windows\system32
Task: {A5B15EC9-635A-47C0-9D15-3BD2CE6E666D} - System32\Tasks\{B0949691-916F-4737-B2D9-559BF6F705C9} => pcalua.exe -a "C:\Program Files (x86)\Tallinex MetaTrader 4\Uninstall.exe"
Task: {A6E9B648-C87F-4DB1-99ED-1224D7F4D94F} - System32\Tasks\GoogleUpdateTaskMachineUA1d1ab0db3b45cd3 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {AC4E5ACF-89F7-4220-BA21-81EE183975E2} - \Microsoft\Windows\Application Experience\AitAgent -> No File <==== ATTENTION
Task: {B248AA40-6BE2-4E77-940A-0A7FAA8C4842} - System32\Tasks\HP AR Program Upload - ea334c978943425bb161916806e2ab80651b9d95b3dc4bd3bde7cd2d53aa3e08 => C:\Program Files\HP\HP Officejet 5740 series\bin\HPRewards.exe [2014-08-22] (Hewlett-Packard Development Company, LP)
Task: {B75324F1-F9E6-4190-9D8A-162F078C48E7} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2016-03-20] (Microsoft Corporation)
Task: {C9025B50-D4BD-484A-968B-AC7C292D5B0E} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2595249627-3671955670-1608175086-1000UA => C:\Users\user\AppData\Local\Google\Update\GoogleUpdate.exe [2011-05-24] (Google Inc.)
Task: {CE851CAA-9CB9-45F6-8CCD-448CA9332C5D} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {CEE64558-E1A7-4D9D-80A7-2001912BE5B5} - \Microsoft\Windows\MemoryDiagnostic\CorruptionDetector -> No File <==== ATTENTION
Task: {DE77C7C9-A244-4A27-9C9D-CB7B2A612333} - \Microsoft\Windows\Windows Activation Technologies\ValidationTaskDeadline -> No File <==== ATTENTION
Task: {E09A163C-EF4B-47BB-A18A-AFFF2CB13DC9} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2595249627-3671955670-1608175086-1000Core => C:\Users\user\AppData\Local\Google\Update\GoogleUpdate.exe [2011-05-24] (Google Inc.)
Task: {E9E9C080-2052-436C-888C-CB839EEFB3AE} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2016-03-20] (Microsoft Corporation)
Task: {FA2BC0A6-8D4B-458A-85C8-2B8C72487513} - \Microsoft\Windows\MemoryDiagnostic\DecompressionFailureDetector -> No File <==== ATTENTION
Task: {FE8C5B3A-DF93-4C20-B090-AC0A1CB8D2CB} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files\Microsoft Office\root\vfs\ProgramFilesCommonx64\Microsoft Shared\Office16\OLicenseHeartbeat.exe [2016-04-01] (Microsoft Corporation)
Task: {FFD2EE75-8390-4906-9743-94C71192608F} - System32\Tasks\HP AR Program Upload - fe3ad587bad94cf0992d4c7e479e42e72d954056d05a4d31a8bc96022001fca3 => C:\Program Files\HP\HP Officejet 5740 series\bin\HPRewards.exe [2014-08-22] (Hewlett-Packard Development Company, LP)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\Windows\Tasks\Adobe Flash Player PPAPI Notifier.job => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_21_0_0_197_pepper.exe
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-2595249627-3671955670-1608175086-1001Core.job => C:\Users\Noga\AppData\Local\Dropbox\Update\DropboxUpdate.exe
Task: C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-2595249627-3671955670-1608175086-1001UA.job => C:\Users\Noga\AppData\Local\Dropbox\Update\DropboxUpdate.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2595249627-3671955670-1608175086-1001Core.job => C:\Users\Noga\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2595249627-3671955670-1608175086-1001UA.job => C:\Users\Noga\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\G2MUpdateTask-S-1-5-21-2595249627-3671955670-1608175086-1001.job => C:\Users\Noga\AppData\Local\Citrix\GoToMeeting\4732\g2mupdate.exe
Task: C:\Windows\Tasks\G2MUploadTask-S-1-5-21-2595249627-3671955670-1608175086-1001.job => C:\Users\Noga\AppData\Local\Citrix\GoToMeeting\4732\g2mupload.exe
Task: C:\Windows\Tasks\GoodSync - Email.job => C:\Program Files\Siber Systems\GoodSync\GoodSync.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2595249627-3671955670-1608175086-1000Core.job => C:\Users\user\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2595249627-3671955670-1608175086-1000UA.job => C:\Users\user\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2595249627-3671955670-1608175086-1001Core.job => C:\Users\Noga\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2595249627-3671955670-1608175086-1001UA.job => C:\Users\Noga\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\TradeStation Backup - Daily.job => C:\Program Files (x86)\TradeStation 9.1\Program\TSBackupRestore.exe K/Backup C:\Program Files (x86)\TradeStation 9.1\Templates\Backup\Daily.tsb
Task: C:\Windows\Tasks\TradeStation Backup - Monthly.job => C:\Program Files (x86)\TradeStation 9.1\Program\TSBackupRestore.exe M/Backup C:\Program Files (x86)\TradeStation 9.1\Templates\Backup\Monthly.tsb
 
==================== Shortcuts =============================
 
(The entries could be listed to be restored or removed.)
 
==================== Loaded Modules (Whitelisted) ==============
 
2015-11-06 05:38 - 2016-03-20 13:10 - 00173256 _____ () C:\Program Files\Common Files\Microsoft Shared\ClickToRun\ApiClient.dll
2016-10-25 09:57 - 2016-10-25 09:57 - 00491184 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll
2016-02-29 11:23 - 2016-02-29 11:23 - 00052912 _____ () C:\Program Files\FileZilla FTP Client\fzshellext_64.dll
2016-10-25 09:57 - 2016-10-25 09:57 - 31723696 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe
2016-03-15 06:53 - 2016-04-01 04:17 - 01402056 _____ () C:\Program Files\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
2016-03-15 06:54 - 2016-04-01 04:19 - 00588992 _____ () C:\Program Files\Microsoft Office\root\Office16\msfad.dll
2016-03-15 06:53 - 2016-04-01 04:17 - 00186048 _____ () C:\Program Files\Microsoft Office\Root\Office16\OUTLCTL.DLL
2016-05-18 13:03 - 2016-05-18 13:03 - 03356928 _____ () C:\ProgramData\pdfforge\PDF Architect 4 Manager\PDF Architect 4\messenger.exe
2017-05-12 00:14 - 2017-05-09 10:13 - 03767640 _____ () C:\Program Files (x86)\Google\Chrome\Application\58.0.3029.110\libglesv2.dll
2017-05-12 00:14 - 2017-05-09 10:13 - 00100696 _____ () C:\Program Files (x86)\Google\Chrome\Application\58.0.3029.110\libegl.dll
2014-10-11 14:06 - 2014-10-11 14:06 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2014-10-11 14:05 - 2014-10-11 14:05 - 01044776 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2017-05-11 03:29 - 2017-05-11 03:29 - 00169984 _____ () C:\Windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\e02990982d5c841556f4bc4041a38de0\IsdiInterop.ni.dll
2011-05-16 16:23 - 2010-11-05 23:50 - 00058880 _____ () C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IsdiInterop.dll
2016-12-09 15:09 - 2016-12-09 15:09 - 52051544 _____ () C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\CEF\libcef.dll
2010-04-01 23:23 - 2010-04-01 23:23 - 00290816 _____ () C:\Program Files (x86)\Matrox Graphics\PowerDesk\MtxDEDll.dll
2017-05-17 19:24 - 2017-05-16 21:55 - 00871744 _____ () C:\Users\Noga\AppData\Roaming\Dropbox\bin\dropbox_watchdog.dll
2017-05-17 19:24 - 2017-05-16 21:55 - 01787200 _____ () C:\Users\Noga\AppData\Roaming\Dropbox\bin\dropbox_crashpad.dll
2017-05-01 18:53 - 2017-04-26 01:38 - 00035792 _____ () C:\Users\Noga\AppData\Roaming\Dropbox\bin\_multiprocessing.pyd
2017-05-01 18:53 - 2017-04-26 01:38 - 00100296 _____ () C:\Users\Noga\AppData\Roaming\Dropbox\bin\_ctypes.pyd
2017-05-01 18:53 - 2017-04-26 01:38 - 00018888 _____ () C:\Users\Noga\AppData\Roaming\Dropbox\bin\select.pyd
2017-05-01 18:53 - 2017-05-16 22:00 - 00019776 _____ () C:\Users\Noga\AppData\Roaming\Dropbox\bin\tornado.speedups.pyd
2017-05-17 19:24 - 2017-05-16 22:00 - 00020824 _____ () C:\Users\Noga\AppData\Roaming\Dropbox\bin\cryptography.hazmat.bindings._constant_time.pyd
2017-05-01 18:53 - 2017-04-26 01:39 - 00123856 _____ () C:\Users\Noga\AppData\Roaming\Dropbox\bin\_cffi_backend.pyd
2017-05-01 18:53 - 2017-04-26 01:38 - 00694224 _____ () C:\Users\Noga\AppData\Roaming\Dropbox\bin\unicodedata.pyd
2017-05-17 19:24 - 2017-05-16 22:00 - 01729360 _____ () C:\Users\Noga\AppData\Roaming\Dropbox\bin\cryptography.hazmat.bindings._openssl.pyd
2017-05-17 19:24 - 2017-05-16 22:00 - 00020816 _____ () C:\Users\Noga\AppData\Roaming\Dropbox\bin\cryptography.hazmat.bindings._padding.pyd
2017-05-17 19:24 - 2017-04-26 01:38 - 00145864 _____ () C:\Users\Noga\AppData\Roaming\Dropbox\bin\pyexpat.pyd
2017-05-17 19:24 - 2017-04-26 01:39 - 00019408 _____ () C:\Users\Noga\AppData\Roaming\Dropbox\bin\faulthandler.pyd
2017-05-17 19:24 - 2017-04-26 01:38 - 00116688 _____ () C:\Users\Noga\AppData\Roaming\Dropbox\bin\pywintypes27.dll
2017-05-01 18:53 - 2017-04-26 01:40 - 00105928 _____ () C:\Users\Noga\AppData\Roaming\Dropbox\bin\win32api.pyd
2017-05-01 18:53 - 2017-05-16 22:01 - 00022864 _____ () C:\Users\Noga\AppData\Roaming\Dropbox\bin\winffi.crt.compiled._winffi_crt.pyd
2017-05-17 19:24 - 2017-05-16 22:00 - 00060736 _____ () C:\Users\Noga\AppData\Roaming\Dropbox\bin\psutil._psutil_windows.pyd
2017-05-17 19:24 - 2017-05-16 22:00 - 00038712 _____ () C:\Users\Noga\AppData\Roaming\Dropbox\bin\fastpath.pyd
2017-05-01 18:53 - 2017-04-26 01:40 - 00024528 _____ () C:\Users\Noga\AppData\Roaming\Dropbox\bin\win32event.pyd
2017-05-17 19:24 - 2017-04-26 01:38 - 00392656 _____ () C:\Users\Noga\AppData\Roaming\Dropbox\bin\pythoncom27.dll
2017-05-17 19:24 - 2017-04-26 01:40 - 00020936 _____ () C:\Users\Noga\AppData\Roaming\Dropbox\bin\mmapfile.pyd
2017-05-01 18:53 - 2017-04-26 01:40 - 00116176 _____ () C:\Users\Noga\AppData\Roaming\Dropbox\bin\win32security.pyd
2017-05-01 18:53 - 2017-05-16 22:00 - 00392512 _____ () C:\Users\Noga\AppData\Roaming\Dropbox\bin\win32com.shell.shell.pyd
2017-05-01 18:53 - 2017-04-26 01:40 - 00124880 _____ () C:\Users\Noga\AppData\Roaming\Dropbox\bin\win32file.pyd
2017-05-01 18:53 - 2017-05-16 22:01 - 00026456 _____ () C:\Users\Noga\AppData\Roaming\Dropbox\bin\winffi.kernel32.compiled._winffi_kernel32.pyd
2017-05-01 18:53 - 2017-04-26 01:40 - 00024016 _____ () C:\Users\Noga\AppData\Roaming\Dropbox\bin\win32clipboard.pyd
2017-05-01 18:53 - 2017-04-26 01:40 - 00175560 _____ () C:\Users\Noga\AppData\Roaming\Dropbox\bin\win32gui.pyd
2017-05-01 18:53 - 2017-04-26 01:40 - 00030160 _____ () C:\Users\Noga\AppData\Roaming\Dropbox\bin\win32pipe.pyd
2017-05-01 18:53 - 2017-04-26 01:40 - 00043472 _____ () C:\Users\Noga\AppData\Roaming\Dropbox\bin\win32process.pyd
2017-05-01 18:53 - 2017-04-26 01:40 - 00048592 _____ () C:\Users\Noga\AppData\Roaming\Dropbox\bin\win32service.pyd
2017-05-01 18:53 - 2017-04-26 01:40 - 00057808 _____ () C:\Users\Noga\AppData\Roaming\Dropbox\bin\win32evtlog.pyd
2017-05-01 18:53 - 2017-04-26 01:40 - 00024016 _____ () C:\Users\Noga\AppData\Roaming\Dropbox\bin\win32profile.pyd
2017-05-17 19:24 - 2017-05-16 22:00 - 00246608 _____ () C:\Users\Noga\AppData\Roaming\Dropbox\bin\breakpad.client.windows.handler.pyd
2017-05-17 19:24 - 2017-05-16 22:00 - 00027488 _____ () C:\Users\Noga\AppData\Roaming\Dropbox\bin\dropbox.infinite.win.compiled._driverinstallation.pyd
2017-05-17 19:24 - 2017-05-16 22:00 - 00022336 _____ () C:\Users\Noga\AppData\Roaming\Dropbox\bin\cpuid.compiled._cpuid.pyd
2017-05-17 19:24 - 2017-05-16 22:01 - 00082264 _____ () C:\Users\Noga\AppData\Roaming\Dropbox\bin\winenumhandles.compiled._WinEnumHandles.pyd
2017-05-01 18:53 - 2017-05-16 22:01 - 00025432 _____ () C:\Users\Noga\AppData\Roaming\Dropbox\bin\winscreenshot.compiled._CaptureScreenshot.pyd
2017-05-01 18:53 - 2017-04-26 01:40 - 00028616 _____ () C:\Users\Noga\AppData\Roaming\Dropbox\bin\win32ts.pyd
2017-05-17 19:24 - 2017-05-16 22:00 - 01826104 _____ () C:\Users\Noga\AppData\Roaming\Dropbox\bin\PyQt5.QtCore.pyd
2017-05-01 18:53 - 2017-04-26 01:39 - 00083912 _____ () C:\Users\Noga\AppData\Roaming\Dropbox\bin\sip.pyd
2017-05-17 19:24 - 2017-05-16 22:00 - 01972024 _____ () C:\Users\Noga\AppData\Roaming\Dropbox\bin\PyQt5.QtGui.pyd
2017-05-17 19:24 - 2017-05-16 22:00 - 03928896 _____ () C:\Users\Noga\AppData\Roaming\Dropbox\bin\PyQt5.QtWidgets.pyd
2017-05-17 19:24 - 2017-05-16 22:00 - 00171336 _____ () C:\Users\Noga\AppData\Roaming\Dropbox\bin\PyQt5.QtWebEngineWidgets.pyd
2017-05-17 19:24 - 2017-05-16 22:00 - 00042816 _____ () C:\Users\Noga\AppData\Roaming\Dropbox\bin\PyQt5.QtWebChannel.pyd
2017-05-17 19:24 - 2017-05-16 22:00 - 00531264 _____ () C:\Users\Noga\AppData\Roaming\Dropbox\bin\PyQt5.QtNetwork.pyd
2017-05-17 19:24 - 2017-05-16 22:00 - 00133432 _____ () C:\Users\Noga\AppData\Roaming\Dropbox\bin\PyQt5.QtWebKit.pyd
2017-05-17 19:24 - 2017-05-16 22:00 - 00224064 _____ () C:\Users\Noga\AppData\Roaming\Dropbox\bin\PyQt5.QtWebKitWidgets.pyd
2017-05-17 19:24 - 2017-05-16 22:00 - 00207680 _____ () C:\Users\Noga\AppData\Roaming\Dropbox\bin\PyQt5.QtPrintSupport.pyd
2017-05-01 18:53 - 2017-04-26 01:40 - 00060880 _____ () C:\Users\Noga\AppData\Roaming\Dropbox\bin\win32print.pyd
2017-05-01 18:53 - 2017-05-16 22:01 - 00054608 _____ () C:\Users\Noga\AppData\Roaming\Dropbox\bin\winrpcserver.compiled._RPCServer.pyd
2017-05-01 18:53 - 2017-05-16 22:01 - 00022864 _____ () C:\Users\Noga\AppData\Roaming\Dropbox\bin\winffi.user32.compiled._winffi_user32.pyd
2017-05-01 18:53 - 2017-05-16 22:01 - 00022872 _____ () C:\Users\Noga\AppData\Roaming\Dropbox\bin\winffi.iphlpapi.compiled._winffi_iphlpapi.pyd
2017-05-01 18:53 - 2017-05-16 22:01 - 00021848 _____ () C:\Users\Noga\AppData\Roaming\Dropbox\bin\winffi.winerror.compiled._winffi_winerror.pyd
2017-05-01 18:53 - 2017-05-16 22:01 - 00022872 _____ () C:\Users\Noga\AppData\Roaming\Dropbox\bin\winffi.wininet.compiled._winffi_wininet.pyd
2017-05-01 18:53 - 2017-04-26 01:40 - 00349128 _____ () C:\Users\Noga\AppData\Roaming\Dropbox\bin\winxpgui.pyd
2017-05-01 18:53 - 2017-05-16 22:01 - 00023896 _____ () C:\Users\Noga\AppData\Roaming\Dropbox\bin\winverifysignature.compiled._VerifySignature.pyd
2017-05-17 19:24 - 2017-05-16 22:00 - 00025936 _____ () C:\Users\Noga\AppData\Roaming\Dropbox\bin\librsyncffi.compiled._librsyncffi.pyd
2017-05-17 19:24 - 2017-04-26 01:34 - 00036296 _____ () C:\Users\Noga\AppData\Roaming\Dropbox\bin\librsync.dll
2017-05-17 19:24 - 2017-05-16 22:00 - 00084288 _____ () C:\Users\Noga\AppData\Roaming\Dropbox\bin\dropbox_sqlite_ext.DLL
2017-05-01 18:53 - 2017-05-16 22:01 - 00030536 _____ () C:\Users\Noga\AppData\Roaming\Dropbox\bin\wind3d11.compiled._wind3d11.pyd
2017-05-17 19:24 - 2017-04-26 01:43 - 00017864 _____ () C:\Users\Noga\AppData\Roaming\Dropbox\bin\libEGL.dll
2017-05-17 19:24 - 2017-04-26 01:43 - 01631184 _____ () C:\Users\Noga\AppData\Roaming\Dropbox\bin\libGLESv2.dll
2017-05-01 18:53 - 2017-05-16 22:01 - 00026456 _____ () C:\Users\Noga\AppData\Roaming\Dropbox\bin\winffi.winhttp.compiled._winffi_winhttp.pyd
2017-05-01 18:53 - 2017-05-16 22:01 - 00023368 _____ () C:\Users\Noga\AppData\Roaming\Dropbox\bin\wincrashpad.compiled._Crashpad.pyd
2017-05-17 19:24 - 2017-05-16 22:00 - 00546104 _____ () C:\Users\Noga\AppData\Roaming\Dropbox\bin\PyQt5.QtQuick.pyd
2017-05-17 19:24 - 2017-05-16 22:00 - 00357688 _____ () C:\Users\Noga\AppData\Roaming\Dropbox\bin\PyQt5.QtQml.pyd
2015-03-04 22:45 - 2017-04-26 01:45 - 00697304 _____ () C:\Users\Noga\AppData\Roaming\Dropbox\bin\QtQuick\Controls\qtquickcontrolsplugin.dll
2016-12-02 01:54 - 2016-12-02 01:54 - 00118272 _____ () \\?\C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\js\node_modules\fs-ext\build\Release\fs-ext.node
2016-12-02 01:54 - 2016-12-02 01:54 - 00223232 _____ () \\?\C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\js\node_modules\node-vulcanjs\build\Release\VulcanJS.node
2016-12-02 01:54 - 2016-12-02 01:54 - 00117248 _____ () \\?\C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\js\node_modules\ref\build\Release\binding.node
2016-12-02 01:54 - 2016-12-02 01:54 - 00124928 _____ () \\?\C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\js\node_modules\ffi\build\Release\ffi_bindings.node
2016-12-09 15:09 - 2016-12-09 15:09 - 00110680 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\js\node_modules\node-ProxyResolver\build\Release\ProxyResolverWin7.dll
2016-12-02 01:54 - 2016-12-02 01:54 - 00086528 _____ () \\?\C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\js\node_modules\idle-gc\build\Release\idle-gc.node
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
AlternateDataStreams: C:\Users\Benjamin\Downloads\SteamSetup.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Desktop\10. Lister Family - May presentation.pptx:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Noga\Desktop\Lister Family Office (3.5 back up):com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Noga\Downloads\act!_pro_v16_uk_eu.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\adwcleaner.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\base-crm-outlook (1).exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\base-crm-outlook.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\bbfbstd5.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\bbflbk5.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\bitdefender_windows_324e1e66-5bf6-4362-a4ef-7cd7ed68410c.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\bitdefender_windows_5c367878-4a99-48f0-93ca-a57d4ffaec3d.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\bluescreenview_setup.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\Business-in-a-Box_SetupLP.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\ccsetup500.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\chromeinstall-7u45.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\CodeTwoOutlookSyncEN.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\cubby.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\EOTPRO_Indicator_Installer_Ninja_7p0p1000p4 (1).exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\EvaerSetup (1).exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\EvaerSetup.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\FileZilla_3.16.0_win64-setup_bundled.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\Firefox Setup Stub 31.0.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\FXCM-MT4Install (1).exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\FXCM-MT4Install.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\fxTrade.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\FXTS2Install (1).EXE:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\FXTS2Install (2).EXE:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\FXTS2Install (3).EXE:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\gbridge-20b1363-xp--setup.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\GoodSync-Setup.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\GuruAid.Connect.Client (1).exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\GuruAid.Connect.Client.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\HPSupportSolutionsFramework-12.0.30.81.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\installer_adobe_flash_player_English.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\invastglobal4setup.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\iTunes64Setup.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\KinetickSupport.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\mbam-setup-1.75.0.1300.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\NTSupport (1).exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\NTSupport (2).exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\pms-1.90.1-setup-full-x64.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\putty.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\remote (1).exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\remote (2).exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\remote (3).exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\remote(1).exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\remote.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\RepairMSITool (1).exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\RepairMSITool (2).exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\RepairMSITool.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\setup (4).exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\setup.exe:BDU [22]
AlternateDataStreams: C:\Users\Noga\Downloads\Setup.X86.en-US_O365HomePremRetail_016ca42f-ca44-4c92-b057-b482f1ce3917_TX_DB_ (1).exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\Setup.X86.en-US_O365HomePremRetail_016ca42f-ca44-4c92-b057-b482f1ce3917_TX_DB_.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\Setup.X86.en-US_O365HomePremRetail_40c5d597-cf97-4299-ad06-ba9f58514f35_TX_DB_.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\SetupImgBurn_2.5.7.0.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\SkypeSetupFull.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\SteamSetup.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\StrategyTrader (1).exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\Support-LogMeInRescue (1).exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\Support-LogMeInRescue.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\supporttool_2015 (1).exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\supporttool_2015.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\Syncables360.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\SyncBack_Setup.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\syncios.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\tallinex4setup (1).exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\tallinex4setup (2).exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\tallinex4setup.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\The_New_Bitdefender_UninstallTool (1).exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\The_New_Bitdefender_UninstallTool.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\UnityWebPlayer.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\upgr.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\UPnPTest (1).exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\UPnPTest.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\uTorrent.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\Windows-KB841290-x86-ENU.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\winrar-x64-420.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\wlsetup-web (2).exe:BDU [0]
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\atashost => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\GoToAssist => ""="Service"
 
==================== Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
 
==================== Hosts content: ===============================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2009-07-14 03:34 - 2016-04-08 18:54 - 00000002 _____ C:\Windows\system32\Drivers\etc\hosts
 
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-2595249627-3671955670-1608175086-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Noga\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 172.16.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
MSCONFIG\startupreg: avichannel => "C:\Program Files (x86)\Evaer\videochannel.exe"
MSCONFIG\startupreg: CCleaner Monitoring => "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
MSCONFIG\startupreg: Check Point Endpoint Connect => "C:\Program Files (x86)\CheckPoint\Endpoint Connect\TrGUI.exe"
MSCONFIG\startupreg: Dropbox Update => "C:\Users\Noga\AppData\Local\Dropbox\Update\DropboxUpdate.exe" /c
MSCONFIG\startupreg: RtHDVCpl => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
MSCONFIG\startupreg: Skype => "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
MSCONFIG\startupreg: Steam => "C:\Users\Benjamin\Steam\steam.exe" -silent
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [SPPSVC-In-TCP] => (Allow) %SystemRoot%\system32\sppsvc.exe
FirewallRules: [SPPSVC-In-TCP-NoScope] => (Allow) %SystemRoot%\system32\sppsvc.exe
FirewallRules: [{C3001E51-34CF-4C10-AE9D-C44A73F3CBC8}] => (Allow) C:\Program Files\HP\HP Officejet 6500 E710n-z\Bin\DeviceSetup.exe
FirewallRules: [{BCEF2663-8875-4336-BE89-8F92B8B4164E}] => (Allow) C:\Program Files\HP\HP Officejet 6500 E710n-z\Bin\DeviceSetup.exe
FirewallRules: [{6A8437FA-2CAC-452F-B28F-E466684F3757}] => (Allow) C:\Program Files\HP\HP Officejet 6500 E710n-z\Bin\HPNetworkCommunicator.exe
FirewallRules: [{6AB5A0AC-8A2C-46F7-8D99-BB3B31D4A331}] => (Allow) C:\Program Files\HP\HP Officejet 6500 E710n-z\Bin\HPNetworkCommunicator.exe
FirewallRules: [{EAADD687-729C-4EDB-80FF-01F5B0536954}] => (Allow) C:\Program Files (x86)\TightVNC\tvnserver.exe
FirewallRules: [{414BFCFF-9C7E-4FA3-A330-C575EAD7EF40}] => (Allow) C:\Program Files (x86)\TightVNC\tvnserver.exe
FirewallRules: [{78F1D6DC-B6CD-46A8-B7D4-A8F6C74812E9}] => (Allow) C:\Program Files (x86)\TightVNC\vncviewer.exe
FirewallRules: [{325FC714-DC84-4B6E-9DB4-92F11EC02697}] => (Allow) C:\Program Files (x86)\TightVNC\vncviewer.exe
FirewallRules: [{BCE22113-6088-4196-A588-40820A6A0F91}] => (Allow) C:\Users\Noga\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{0D17915A-F835-4980-8D9E-56FA3815B4E4}] => (Allow) C:\Users\Noga\AppData\Roaming\Dropbox\bin\Dropbox.exe
FirewallRules: [{F2A1C7B6-8B3A-48AB-BF82-EDC1C0E8C95A}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
FirewallRules: [{DC3A0066-2B2B-4E36-9CF9-91443A1635DD}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqste08.exe
FirewallRules: [{FF51D19C-67F1-49DD-9847-E74559FEDC82}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpofxm08.exe
FirewallRules: [{4F2A4FDE-82A0-4E4A-A0C3-D8D8FF848F43}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hposfx08.exe
FirewallRules: [{86A9DA21-DC7A-4F6E-8E48-0B3E26667441}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hposid01.exe
FirewallRules: [{AD127283-C62F-4096-AF77-6DCE12F01A2C}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqkygrp.exe
FirewallRules: [{A1E0C1DF-17EF-4E6A-8FBF-26AB46FE347C}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpfccopy.exe
FirewallRules: [{84E6630A-BA37-4D65-A818-BAA5C7A7ED34}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpzwiz01.exe
FirewallRules: [{A0D58F67-0721-4506-B14B-A9A414635414}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpoews01.exe
FirewallRules: [{E717FE46-5025-4557-A5BB-3BA1C9EF84B4}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpiscnapp.exe
FirewallRules: [{A13B299A-1F16-46F6-B472-FB9393BE58D9}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpofxs08.exe
FirewallRules: [{D5D26025-0C5E-4163-9335-54A707A622F2}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqfxt08.exe
FirewallRules: [{5D464382-F855-4639-A462-15472F04F39C}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgplgtupl.exe
FirewallRules: [{8EBFE381-9FD4-4827-816C-5FCD5EBEB5E3}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe
FirewallRules: [{413F09FA-7719-4330-BDE2-C98A67750F59}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqusgm.exe
FirewallRules: [{F61E19A7-7246-4A6A-8BB1-7D52E9ED11B6}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqusgh.exe
FirewallRules: [{2EF08B9C-4E4D-4424-A9B8-A05F40ACE36B}] => (Allow) C:\Program Files (x86)\HP\hp software update\hpwucli.exe
FirewallRules: [{8ED1A6E4-C0E9-4D19-864A-1D4042FE1581}] => (Allow) C:\Program Files (x86)\HP\digital imaging\smart web printing\smartwebprintexe.exe
FirewallRules: [{C6A2ECDC-349A-43E7-9172-45399C359457}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\{58D79E62-CFC8-4331-8469-3A1B16E1769C}\setup\hpznui40.exe
FirewallRules: [{B06CD85B-8253-45B7-BD1F-8948345829D1}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{3DF1AFC5-C922-4527-A0A6-9DE18FA249AA}] => (Allow) LPort=2869
FirewallRules: [{87143ECC-BD46-431B-97CA-D50BDBA9BA6D}] => (Allow) LPort=1900
FirewallRules: [{3A82EA82-FFDD-4220-BBA9-4DAE3CAA18B3}] => (Allow) C:\Program Files (x86)\Windows Live\Mesh\MOE.exe
FirewallRules: [{8F113BD6-9A31-49C2-B082-946069B743F7}] => (Allow) C:\Program Files (x86)\File Type Assistant\TSAssist.exe
FirewallRules: [{077D9A95-767F-48EF-A334-963565BB6818}] => (Allow) C:\Program Files (x86)\TeamViewer\Version7\TeamViewer.exe
FirewallRules: [{AC0ADD42-2178-404C-AE7C-BC0CE5088B69}] => (Allow) C:\Program Files (x86)\TeamViewer\Version7\TeamViewer.exe
FirewallRules: [{C832B605-CC5E-4ABB-9206-FBB084C3691D}] => (Allow) C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe
FirewallRules: [{BD2F8A10-D043-490F-8157-387B5284CEA8}] => (Allow) C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe
FirewallRules: [{FFF204E3-A8D8-4A79-94AF-76DECDE6A0E6}] => (Allow) %ProgramFiles%\Windows Live\Mesh\wlcrasvc.exe
FirewallRules: [{A8C7FCBD-7E24-430C-9F6C-0D7BB4674E37}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{86D70C9B-8214-4FEF-A8C3-DB0A709C0F10}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{F6AF47A1-33DD-4016-950A-1F236935B5EA}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{D1A3F619-CF0F-44BC-A889-8E7C96F97D63}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{8F1D261E-109C-4D69-A1B6-8C13D9728155}] => (Allow) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe
FirewallRules: [{23198EEB-1B4D-4F80-AD81-006AFECB8EFE}] => (Allow) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe
FirewallRules: [{0D22B5DB-130B-411D-9F75-9219ED9BC8B3}] => (Allow) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
FirewallRules: [{3BB3533C-F053-4D78-A4AE-B42EFC75B769}] => (Allow) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
FirewallRules: [{CADB1C98-9C66-4459-85F2-5ED48BDAE178}] => (Allow) C:\Program Files (x86)\CheckPoint\Endpoint Connect\TracSrvWrapper.exe
FirewallRules: [{98ECC5CF-F799-4696-BDAE-EBE0BBD3913C}] => (Allow) C:\Program Files (x86)\CheckPoint\Endpoint Connect\TrGUI.exe
FirewallRules: [{B164E7AB-BB1D-436E-8E5F-C4BF0F6C69C6}] => (Allow) C:\Users\Noga\AppData\Local\Facebook\Video\Skype\FacebookVideoCalling.exe
FirewallRules: [{79CD5977-3EEC-4A58-8CA2-D8713B27C787}] => (Allow) C:\Users\Noga\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe
FirewallRules: [{45AE6F0A-504A-4F47-B009-666BF6B2B7F5}] => (Allow) C:\Program Files (x86)\iTunes\iTunes.exe
FirewallRules: [{401E42DB-DCCD-4DF6-B96B-772DACD6B9B1}] => (Allow) C:\Users\Benjamin\Steam\Steam.exe
FirewallRules: [{10523A1B-A9AE-4C67-A902-2AC74AA932F8}] => (Allow) C:\Users\Benjamin\Steam\Steam.exe
FirewallRules: [{C804F426-875E-41BC-ACC7-1E7A1446E96C}] => (Allow) C:\Users\Benjamin\Steam\bin\steamwebhelper.exe
FirewallRules: [{5546E725-A28D-4913-9A6C-D511948A1A33}] => (Allow) C:\Users\Benjamin\Steam\bin\steamwebhelper.exe
FirewallRules: [{BD8F78A9-49AC-4B33-AB5C-C10A7DA4DEAF}] => (Allow) C:\Users\Benjamin\Steam\steamapps\common\TalesMajEyal\t-engine.exe
FirewallRules: [{9FF0AF37-D38E-4F23-879C-305BC5B0D510}] => (Allow) C:\Users\Benjamin\Steam\steamapps\common\TalesMajEyal\t-engine.exe
FirewallRules: [{D21B0309-65FE-410E-BB56-DAD4885B2E3B}] => (Allow) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe
FirewallRules: [{D628E526-0DCE-41AF-B611-23BD7DB38718}] => (Allow) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe
FirewallRules: [{A6CE0FD5-C2D7-4A32-A176-839F7B663565}] => (Allow) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
FirewallRules: [{4087CCDB-7589-4C46-B04C-AB6D681F61CE}] => (Allow) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
FirewallRules: [{8D33334F-DC2B-4E7C-8E1B-0ABB955D4717}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{4E3BE868-34C5-430D-865D-2DABA747855E}] => (Allow) C:\Program Files\HP\HP Officejet 5740 series\bin\FaxApplications.exe
FirewallRules: [{A7FFFA10-F6EC-4460-9A33-02A37240B463}] => (Allow) C:\Program Files\HP\HP Officejet 5740 series\bin\DigitalWizards.exe
FirewallRules: [{18676520-050F-4D04-BF23-08779D88E673}] => (Allow) C:\Program Files\HP\HP Officejet 5740 series\bin\SendAFax.exe
FirewallRules: [{C033383D-948D-4F35-A228-E737E7CF8F43}] => (Allow) C:\Program Files\HP\HP Officejet 5740 series\Bin\DeviceSetup.exe
FirewallRules: [{5C7B0CC0-E61E-4DA2-8D9D-2F9DD03E12DA}] => (Allow) LPort=5357
FirewallRules: [{D2E6ABC0-510F-42DD-9D93-0C6CF58096EE}] => (Allow) C:\Program Files\HP\HP Officejet 5740 series\Bin\HPNetworkCommunicatorCom.exe
FirewallRules: [{CB44D292-F539-4E18-85BE-A5F3B9BA9CBA}] => (Allow) C2OutlookSync.exe
FirewallRules: [{8A99730D-9433-4BF7-80F2-E1118B039B13}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\outlook.exe
FirewallRules: [{007A13E6-C10C-4443-9590-50FBD20A1A57}] => (Allow) C:\Users\Noga\AppData\Local\Temp\7zS18D1\HPDiagnosticCoreUI.exe
FirewallRules: [{BEB616FE-196F-4C75-ACB1-E46808982724}] => (Allow) C:\Users\Noga\AppData\Local\Temp\7zS18D1\HPDiagnosticCoreUI.exe
FirewallRules: [{04A7AFE7-3BD5-41DF-B870-839773D9848C}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{A54E00DC-560E-446B-86BA-F20ED546F0D7}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{DBA8E664-6F48-439F-ADB4-69AC0AC455B6}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{06C1EBE7-F3D4-4F21-B3D1-2EEB2DD9B818}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{A8024075-9BC3-492A-9BCB-A08C372EB0F8}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\English Country Tune\English Country Tune.exe
FirewallRules: [{5F96C977-7C0D-4867-B54D-CA3BBEA3A2DD}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\English Country Tune\English Country Tune.exe
FirewallRules: [TCP Query User{110F937E-A565-4A09-9355-5A9808EBEE51}C:\users\noga\appdata\local\temp\bduninstall\x32\pcsftool.exe] => (Allow) C:\users\noga\appdata\local\temp\bduninstall\x32\pcsftool.exe
FirewallRules: [UDP Query User{CC2058A3-7586-4AE6-A97E-15AEB3D800BE}C:\users\noga\appdata\local\temp\bduninstall\x32\pcsftool.exe] => (Allow) C:\users\noga\appdata\local\temp\bduninstall\x32\pcsftool.exe
FirewallRules: [TCP Query User{2F1A66A5-7EFE-4D81-A15B-5CC1BCA77250}C:\users\noga\appdata\local\temp\bduninstall\x64\pcsftool.exe] => (Allow) C:\users\noga\appdata\local\temp\bduninstall\x64\pcsftool.exe
FirewallRules: [UDP Query User{3798DE66-A794-4062-BC1F-FFEB6157A0AA}C:\users\noga\appdata\local\temp\bduninstall\x64\pcsftool.exe] => (Allow) C:\users\noga\appdata\local\temp\bduninstall\x64\pcsftool.exe
FirewallRules: [TCP Query User{7D5921B2-5B9B-453B-974B-D3811356A4BC}C:\program files (x86)\ninjatrader 7\bin\ninjatrader.exe] => (Block) C:\program files (x86)\ninjatrader 7\bin\ninjatrader.exe
FirewallRules: [UDP Query User{0E742AFD-3BEC-4ADF-8978-4562B567B5D2}C:\program files (x86)\ninjatrader 7\bin\ninjatrader.exe] => (Block) C:\program files (x86)\ninjatrader 7\bin\ninjatrader.exe
FirewallRules: [{7BE3DEF1-75D5-4C9F-BD45-8E961E8A640C}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
 
==================== Restore Points =========================
 
18-05-2017 06:35:20 Windows Update
21-05-2017 21:52:21 Windows Update
25-05-2017 21:59:33 Windows Update
 
==================== Faulty Device Manager Devices =============
 
Name: Optiarc DVD RW AD-5260S
Description: CD-ROM Drive
Class Guid: {4d36e965-e325-11ce-bfc1-08002be10318}
Manufacturer: (Standard CD-ROM drives)
Service: cdrom
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (05/27/2017 10:20:53 AM) (Source: Office 2016 Licensing Service) (EventID: 0) (User: )
Description: Event-ID 0
 
Error: (05/26/2017 10:20:52 AM) (Source: Office 2016 Licensing Service) (EventID: 0) (User: )
Description: Event-ID 0
 
Error: (05/26/2017 01:11:55 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT AUTHORITY)
Description: Unloading the performance counter strings for service WmiApRpl (WmiApRpl) failed. The first DWORD in the Data section contains the error code.
 
Error: (05/26/2017 01:11:55 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY)
Description: The performance strings in the Performance registry value is corrupted when process Performance extension counter provider. The BaseIndex value from the Performance registry is the first DWORD in the Data section, LastCounter value is the second DWORD in the Data section, and LastHelp value is the third DWORD in the Data section.
 
Error: (05/25/2017 09:58:22 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: EXCEL.EXE, version: 16.0.6741.2021, time stamp: 0x56ef5649
Faulting module name: EXCEL.EXE, version: 16.0.6741.2021, time stamp: 0x56ef5649
Exception code: 0xc0000005
Fault offset: 0x00000000001bd7fa
Faulting process id: 0x1302c
Faulting application start time: 0x01d2d598b4f31682
Faulting application path: C:\Program Files\Microsoft Office\Root\Office16\EXCEL.EXE
Faulting module path: C:\Program Files\Microsoft Office\Root\Office16\EXCEL.EXE
Report Id: e2fe472e-418c-11e7-8030-54c834e2d70d
 
Error: (05/25/2017 10:20:53 AM) (Source: Office 2016 Licensing Service) (EventID: 0) (User: )
Description: Event-ID 0
 
Error: (05/24/2017 10:20:52 AM) (Source: Office 2016 Licensing Service) (EventID: 0) (User: )
Description: Event-ID 0
 
Error: (05/23/2017 10:20:53 AM) (Source: Office 2016 Licensing Service) (EventID: 0) (User: )
Description: Event-ID 0
 
Error: (05/22/2017 10:20:55 AM) (Source: Office 2016 Licensing Service) (EventID: 0) (User: )
Description: Event-ID 0
 
Error: (05/22/2017 12:51:50 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: EXCEL.EXE, version: 16.0.6741.2021, time stamp: 0x56ef5649
Faulting module name: chart.dll, version: 16.0.6701.1013, time stamp: 0x56ed76ce
Exception code: 0xc0000005
Fault offset: 0x000000000027fcd7
Faulting process id: 0x1206c
Faulting application start time: 0x01d2d2851b0fe13b
Faulting application path: C:\Program Files\Microsoft Office\Root\Office16\EXCEL.EXE
Faulting module path: C:\Program Files\Microsoft Office\Root\Office16\chart.dll
Report Id: 74addc42-3e80-11e7-8030-54c834e2d70d
 
 
System errors:
=============
Error: (05/26/2017 02:37:13 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: The following fatal alert was generated: 10. The internal error state is 10.
 
Error: (05/26/2017 01:07:52 AM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load: 
cdrom
ignis
 
Error: (05/25/2017 11:16:13 PM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: The following fatal alert was received: 70.
 
Error: (05/18/2017 09:45:08 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The HP Support Solutions Framework Service service failed to start due to the following error: 
The service did not respond to the start or control request in a timely fashion.
 
Error: (05/18/2017 09:45:08 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the HP Support Solutions Framework Service service to connect.
 
Error: (05/18/2017 09:42:32 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load: 
cdrom
ignis
 
Error: (05/11/2017 06:27:52 AM) (Source: DCOM) (EventID: 10010) (User: )
Description: The server {D085A4AB-CAB1-4729-9DF8-FCEEDDBD19E4} did not register with DCOM within the required timeout.
 
Error: (05/11/2017 06:26:47 AM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load: 
cdrom
ignis
 
Error: (05/11/2017 06:24:18 AM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 06:21:25 on ‎11/‎05/‎2017 was unexpected.
 
Error: (05/11/2017 03:24:25 AM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load: 
cdrom
ignis
 
 
CodeIntegrity:
===================================
  Date: 2017-05-27 10:10:14.225
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\l3codeca.acm because the set of per-page image hashes could not be found on the system.
 
  Date: 2017-05-27 09:40:14.303
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\l3codeca.acm because the set of per-page image hashes could not be found on the system.
 
  Date: 2017-05-27 09:10:07.395
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\l3codeca.acm because the set of per-page image hashes could not be found on the system.
 
  Date: 2017-05-27 08:40:11.832
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\l3codeca.acm because the set of per-page image hashes could not be found on the system.
 
  Date: 2017-05-27 07:10:08.556
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\l3codeca.acm because the set of per-page image hashes could not be found on the system.
 
  Date: 2017-05-27 05:10:10.695
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\l3codeca.acm because the set of per-page image hashes could not be found on the system.
 
  Date: 2017-05-27 03:40:13.354
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\l3codeca.acm because the set of per-page image hashes could not be found on the system.
 
  Date: 2017-05-27 02:40:04.218
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\l3codeca.acm because the set of per-page image hashes could not be found on the system.
 
  Date: 2017-05-27 01:40:04.006
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\l3codeca.acm because the set of per-page image hashes could not be found on the system.
 
  Date: 2017-05-27 00:40:13.248
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\l3codeca.acm because the set of per-page image hashes could not be found on the system.
 
 
==================== Memory info =========================== 
 
Processor: Intel® Core™ i7-2600 CPU @ 3.40GHz
Percentage of memory in use: 57%
Total physical RAM: 16364.46 MB
Available physical RAM: 6999.77 MB
Total Virtual: 32727.1 MB
Available Virtual: 22317.88 MB
 
==================== Drives ================================
 
Drive c: () (Fixed) (Total:465.66 GB) (Free:165.33 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 9D580A49)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=465.7 GB) - (Type=07 NTFS)
 
==================== End of Addition.txt ============================
 
 
 

Any help would be appreciated. 



BC AdBot (Login to Remove)

 


#2 TheWhiteCottage

TheWhiteCottage
  • Topic Starter

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:03:50 AM

Posted 27 May 2017 - 11:58 AM

content removed.

Edited by nasdaq, 28 May 2017 - 10:50 AM.


#3 nasdaq

nasdaq

  • Malware Response Team
  • 39,523 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:10:50 PM

Posted 28 May 2017 - 10:51 AM

Hello, Welcome to BleepingComputer.
I'm nasdaq and will be helping you.

If you can please print this topic it will make it easier for you to follow the instructions and complete all of the necessary steps in the order listed.
===

Remove this program in bold via the Control Panel > Programs > Programs and Features.
Unity Web Player (HKU\S-1-5-21-2595249627-3671955670-1608175086-1001\...\UnityWebPlayer) (Version: 4.6.2f1 - Unity Technologies ApS)
===

Press the windows key Windows_Logo_key.gif+ r on your keyboard at the same time. This will open the RUN BOX.
Type Notepad and and click the OK key.
Please copy the entire contents of the code box below to the a new file.
 
start

CreateRestorePoint:
EmptyTemp:
CloseProcesses:

(© 2015 Microsoft Corporation) C:\Users\Noga\AppData\Local\Microsoft\BingSvc\BingSvc.exe
HKU\S-1-5-21-2595249627-3671955670-1608175086-1001\...\Run: [BingSvc] => C:\Users\Noga\AppData\Local\Microsoft\BingSvc\BingSvc.exe [144008 2015-11-05] (© 2015 Microsoft Corporation)
GroupPolicy: Restriction <======= ATTENTION
GroupPolicyScripts: Restriction <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
SearchScopes: HKU\S-1-5-21-2595249627-3671955670-1608175086-1001 -> {91607fa7-3c2f-4f90-93e3-d5337a6b0ac2} URL = Playbryte-fa-verti/search/redirect/?type=default&user_id=2768d1cd-9d03-4acb-88d4-0d1cfdeb3f31&query={searchTerms}
Toolbar: HKLM - No Name - {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} -  No File
Toolbar: HKLM-x32 - No Name - {1DAC0C53-7D23-4AB3-856A-B04D98CD982A} -  No File
FF HKLM-x32\...\Firefox\Extensions: [ffpwdman@bitdefender.com] - C:\Program Files\Bitdefender\Bitdefender\Antispam32\ffpwdman => not found
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin HKU\S-1-5-21-2595249627-3671955670-1608175086-1001: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Noga\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2015-06-21] (Unity Technologies ApS)
CHR Extension: (Chrome Web Store Payments) - C:\Users\Noga\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-03-16]
CHR Extension: (Chrome Media Router) - C:\Users\Noga\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-05-18]
CHR HKU\S-1-5-21-2595249627-3671955670-1608175086-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [fcfenmboojpjinhpgggodefccipikbpd] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [bafafaommdbdmoanapkgbnemjnkllcga] - C:\Users\Noga\AppData\LocalLow\Playbryte\Chrome.crx <not found>
S3 b06bdrv; \SystemRoot\system32\DRIVERS\bxvbda.sys [X]
S0 ignis; system32\DRIVERS\ignis.sys [X]
CustomCLSID: HKU\S-1-5-21-2595249627-3671955670-1608175086-1001_Classes\CLSID\{004B49B7-11B9-5058-FF22-08DD093ADC4B}\InprocServer32 -> {1848255E-9468-D082-08B5-39E985889A47} => No File
CustomCLSID: HKU\S-1-5-21-2595249627-3671955670-1608175086-1001_Classes\CLSID\{1423F872-3F7F-4E57-B621-8B1A9D49B448}\InprocServer32 -> C:\Users\Noga\AppData\Local\Google\Update\1.3.27.5\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-2595249627-3671955670-1608175086-1001_Classes\CLSID\{590C4387-5EBD-4D46-8A84-CD0BA2EF2856}\InprocServer32 -> C:\Users\Noga\AppData\Local\Google\Update\1.3.30.3\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-2595249627-3671955670-1608175086-1001_Classes\CLSID\{59B55F04-DE14-4BB8-92FF-C4A22EF2E5F4}\InprocServer32 -> C:\Users\Noga\AppData\Local\Google\Update\1.3.31.5\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-2595249627-3671955670-1608175086-1001_Classes\CLSID\{5C8C2A98-6133-4EBA-BBCC-34D9EA01FC2E}\InprocServer32 -> C:\Users\Noga\AppData\Local\Google\Update\1.3.28.1\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-2595249627-3671955670-1608175086-1001_Classes\CLSID\{78550997-5DEF-4A8A-BAF9-D5774E87AC98}\InprocServer32 -> C:\Users\Noga\AppData\Local\Google\Update\1.3.28.13\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-2595249627-3671955670-1608175086-1001_Classes\CLSID\{793EE463-1304-471C-ADF1-68C2FFB01247}\InprocServer32 -> C:\Users\Noga\AppData\Local\Google\Update\1.3.29.5\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-2595249627-3671955670-1608175086-1001_Classes\CLSID\{8C46158B-D978-483C-A312-16EE5013BE04}\InprocServer32 -> C:\Users\Noga\AppData\Local\Google\Update\1.3.33.3\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-2595249627-3671955670-1608175086-1001_Classes\CLSID\{C3BC25C0-FCD3-4F01-AFDD-41373F017C9A}\InprocServer32 -> C:\Users\Noga\AppData\Local\Google\Update\1.3.26.9\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-2595249627-3671955670-1608175086-1001_Classes\CLSID\{CB492AF1-2CEF-4E58-BE47-471C77D0C8BA}\InprocServer32 -> C:\Users\Noga\AppData\Local\Google\Update\1.3.32.7\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-2595249627-3671955670-1608175086-1001_Classes\CLSID\{CC182BE1-84CE-4A57-B85C-FD4BBDF78CB2}\InprocServer32 -> C:\Users\Noga\AppData\Local\Google\Update\1.3.29.1\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-2595249627-3671955670-1608175086-1001_Classes\CLSID\{D0336C0B-7919-4C04-8CCE-2EBAE2ECE8C9}\InprocServer32 -> C:\Users\Noga\AppData\Local\Google\Update\1.3.25.11\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-2595249627-3671955670-1608175086-1001_Classes\CLSID\{D1EDC4F5-7F4D-4B12-906A-614ECF66DDAF}\InprocServer32 -> C:\Users\Noga\AppData\Local\Google\Update\1.3.28.15\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-2595249627-3671955670-1608175086-1001_Classes\CLSID\{DD0822FF-3A09-4BDC-B749-4B00B9115850}\InprocServer32 -> {5D06B960-9468-D082-3629-77AC85889A47} => No File
Task: {0DEE167B-38A1-4AE1-A85F-3CA41E5AC0BB} - System32\Tasks\ProgramUpdateCheck => C:\Program Files (x86)\File Type Assistant\TSAssist.exe [2012-08-10] (Trusted Software ApS) <==== ATTENTION
Task: {2F57269B-1E09-4E2D-AB1E-B0FDAC7D279C} - \Microsoft\Windows\WindowsBackup\ConfigNotification -> No File <==== ATTENTION
Task: {732F4281-B87D-4FAB-920C-B585CA8DCF4E} - \Microsoft\Windows\Windows Activation Technologies\ValidationTask -> No File <==== ATTENTION
Task: {AC4E5ACF-89F7-4220-BA21-81EE183975E2} - \Microsoft\Windows\Application Experience\AitAgent -> No File <==== ATTENTION
Task: {CEE64558-E1A7-4D9D-80A7-2001912BE5B5} - \Microsoft\Windows\MemoryDiagnostic\CorruptionDetector -> No File <==== ATTENTION
Task: {DE77C7C9-A244-4A27-9C9D-CB7B2A612333} - \Microsoft\Windows\Windows Activation Technologies\ValidationTaskDeadline -> No File <==== ATTENTION
Task: {FA2BC0A6-8D4B-458A-85C8-2B8C72487513} - \Microsoft\Windows\MemoryDiagnostic\DecompressionFailureDetector -> No File <==== ATTENTION
AlternateDataStreams: C:\Users\Benjamin\Downloads\SteamSetup.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Desktop\10. Lister Family - May presentation.pptx:com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Noga\Desktop\Lister Family Office (3.5 back up):com.dropbox.attributes [168]
AlternateDataStreams: C:\Users\Noga\Downloads\act!_pro_v16_uk_eu.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\adwcleaner.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\base-crm-outlook (1).exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\base-crm-outlook.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\bbfbstd5.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\bbflbk5.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\bitdefender_windows_324e1e66-5bf6-4362-a4ef-7cd7ed68410c.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\bitdefender_windows_5c367878-4a99-48f0-93ca-a57d4ffaec3d.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\bluescreenview_setup.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\Business-in-a-Box_SetupLP.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\ccsetup500.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\chromeinstall-7u45.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\CodeTwoOutlookSyncEN.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\cubby.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\EOTPRO_Indicator_Installer_Ninja_7p0p1000p4 (1).exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\EvaerSetup (1).exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\EvaerSetup.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\FileZilla_3.16.0_win64-setup_bundled.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\Firefox Setup Stub 31.0.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\FXCM-MT4Install (1).exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\FXCM-MT4Install.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\fxTrade.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\FXTS2Install (1).EXE:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\FXTS2Install (2).EXE:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\FXTS2Install (3).EXE:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\gbridge-20b1363-xp--setup.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\GoodSync-Setup.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\GuruAid.Connect.Client (1).exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\GuruAid.Connect.Client.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\HPSupportSolutionsFramework-12.0.30.81.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\installer_adobe_flash_player_English.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\invastglobal4setup.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\iTunes64Setup.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\KinetickSupport.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\mbam-setup-1.75.0.1300.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\NTSupport (1).exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\NTSupport (2).exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\pms-1.90.1-setup-full-x64.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\putty.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\remote (1).exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\remote (2).exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\remote (3).exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\remote(1).exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\remote.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\RepairMSITool (1).exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\RepairMSITool (2).exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\RepairMSITool.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\setup (4).exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\setup.exe:BDU [22]
AlternateDataStreams: C:\Users\Noga\Downloads\Setup.X86.en-US_O365HomePremRetail_016ca42f-ca44-4c92-b057-b482f1ce3917_TX_DB_ (1).exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\Setup.X86.en-US_O365HomePremRetail_016ca42f-ca44-4c92-b057-b482f1ce3917_TX_DB_.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\Setup.X86.en-US_O365HomePremRetail_40c5d597-cf97-4299-ad06-ba9f58514f35_TX_DB_.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\SetupImgBurn_2.5.7.0.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\SkypeSetupFull.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\SteamSetup.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\StrategyTrader (1).exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\Support-LogMeInRescue (1).exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\Support-LogMeInRescue.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\supporttool_2015 (1).exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\supporttool_2015.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\Syncables360.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\SyncBack_Setup.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\syncios.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\tallinex4setup (1).exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\tallinex4setup (2).exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\tallinex4setup.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\The_New_Bitdefender_UninstallTool (1).exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\The_New_Bitdefender_UninstallTool.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\UnityWebPlayer.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\upgr.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\UPnPTest (1).exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\UPnPTest.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\uTorrent.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\Windows-KB841290-x86-ENU.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\winrar-x64-420.exe:BDU [0]
AlternateDataStreams: C:\Users\Noga\Downloads\wlsetup-web (2).exe:BDU [0]
FirewallRules: [{8F113BD6-9A31-49C2-B082-946069B743F7}] => (Allow) C:\Program Files (x86)\File Type Assistant\TSAssist.exe[/B]
C:\Windows\System32\Tasks\ProgramUpdateCheck
C:\Program Files (x86)\File Type Assistant

End
Save the file as fixlist.txt in the same folder where the Farbar tool is running from.
The location is listed in the 3rd line of the Farbar log you have submitted.

Run FRST and click Fix only once and wait.
===

Reset Chrome...
Open Google Chrome, click on menu icon google-chrome-setting-icon.png which is located right side top of the google chrome.
 
Click "Settings" then "Show advanced settings" at the bottom of the screen.
 
Click "Reset browser settings" button.
 
Restart Chrome.
---

Your version of Java is outdated and needs to be updated to take advantage of fixes that have eliminated security vulnerabilities.

You can manually check your present version and update as recommended.
https://www.java.com/en/download/installed.jsp

Be careful not to install malware posing as Java update!
Important read this blog.
http://blog.trendmicro.com/trendlabs-security-intelligence/malware-poses-as-an-update-for-java-0-day-fix/

Quoted from the page.
"In light of the recent events surrounding Java, users must seriously consider their use of Java. Do they really need it? If yes, make sure that users follow the steps we recommended and get the security update directly from the official oracle website." at:
http://www.oracle.com/technetwork/java/javase/downloads/index.html

How to disable Java in your browsers
http://www.infoworld.com/t/web-browsers/how-disable-java-in-your-browsers-210882

If still present after these updates remove these old version(s) via the Control Panel > Programs > Programs and Features.
Java 8 Update 31 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218031F0}) (Version: 8.0.310 - Oracle Corporation)
JavaFX 2.1.1 (HKLM-x32\...\{1111706F-666A-4037-7777-211328764D10}) (Version: 2.1.1 - Oracle Corporation)
===

The tool will create a log (Fixlog.txt) please post it to your reply.
===
Let me know if the problem persists

#4 nasdaq

nasdaq

  • Malware Response Team
  • 39,523 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:10:50 PM

Posted 03 June 2017 - 08:44 AM

Are you still with me?




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users