Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Computer sluggish-cannot not delete or uninstall files or power down


  • This topic is locked This topic is locked
2 replies to this topic

#1 larry1956

larry1956

  • Members
  • 34 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Urbana, OH
  • Local time:11:26 PM

Posted 30 May 2017 - 10:29 AM

Attached File  Addition.txt   41.4KB   0 downloadsFarbar scan tool freezes up when scanning shortcuts reports program not responding.  Here is what Farbar reports so far:

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 28-05-2017
Ran by JanLar (administrator) on HAL9000-PC (30-05-2017 10:21:38)
Running from C:\Users\JanLar\Desktop
Loaded Profiles: JanLar (Available Profiles: JanLar & DefaultAppPool)
Platform: Windows 10 Pro Version 1511 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(Logitech, Inc.) C:\Program Files\Common Files\logishrd\Bluetooth\LBTServ.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® ME FW Recovery Agent\bin\Bootstrap.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® ME FW Recovery Agent\bin\ismagent.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Samsung) C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\AllShareFrameworkManagerDMS.exe
(ABBYY) C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe
(Schneider Electric) C:\Program Files (x86)\APC\PowerChute Personal Edition\mainserv.exe
(Seiko Epson Corporation) C:\Windows\System32\escsvc64.exe
(CinemaNow, Inc.) C:\Program Files (x86)\CinemaNow\CinemaNow Media Manager\CinemaNowSvc.exe
() C:\Program Files (x86)\Roxio\BackOnTrack\Disaster Recovery\SaibSVC.exe
(Rockwell Automation, Inc.) C:\Program Files (x86)\Common Files\Rockwell\FTSysDiagSvcHost.exe
(SafeNet Inc.) C:\Windows\System32\hasplms.exe
(McAfee, Inc.) C:\Windows\System32\mfevtps.exe
(Tanuki Software, Ltd.) C:\Program Files (x86)\i2p\I2Psvc.exe
(SEIKO EPSON CORPORATION) C:\Program Files\EPSON\EpsonCustomerResearchParticipation\EPCP.exe
(Intel® Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
() C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe
(LeapFrog Enterprises, Inc.) C:\Program Files (x86)\LeapFrog\LeapFrog Connect\CommandService.exe
(Rockwell Automation, Inc.) C:\Program Files (x86)\Common Files\Rockwell\RdcyHost.exe
(Rockwell Automation, Inc.) C:\Program Files (x86)\Common Files\Rockwell\NmspHost.exe
(Rockwell Automation Inc.) C:\Program Files (x86)\Common Files\Rockwell\RNADiagnosticsSrv.exe
(Intel Security, Inc.) C:\Program Files\Common Files\Intel Security\PEF\CORE\PEFService.exe
(Microsoft Corporation) C:\Windows\System32\mqsvc.exe
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\SystemCore\mfemms.exe
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\ModuleCore\ModuleCoreService.exe
(Copyright 2013 SAMSUNG) C:\Program Files\Samsung\Samsung Link\Samsung Link.exe
(SoftThinks SAS) C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe
(Skype Technologies) C:\Program Files (x86)\Skype\Updater\Updater.exe
(Rockwell Automation, Inc.) C:\Program Files (x86)\Common Files\Rockwell\RsvcHost.exe
(Atheros) C:\Program Files (x86)\Dell Wireless\Ath_WlanAgent.exe
(Atheros) C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\Ath_CoexAgent.exe
(Samsung) C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\AllShareFrameworkDMS.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Copyright 2013 SAMSUNG) C:\Program Files\Samsung\Samsung Link\Samsung Link.exe
(Schneider Electric) C:\Program Files (x86)\APC\PowerChute Personal Edition\dataserv.exe
(Rockwell Automation, Inc.) C:\Program Files (x86)\Common Files\Rockwell\EventServer.exe
(McAfee, Inc.) C:\Windows\System32\mfevtps.exe
(Atheros Commnucations) C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\AthBtTray.exe
(Oracle Corporation) C:\ProgramData\Oracle\Java\javapath_target_757593\java.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Rockwell Automation, Inc.) C:\Program Files (x86)\Common Files\Rockwell\EventClientMultiplexer.exe
(Rockwell Automation, Inc.) C:\Program Files (x86)\Common Files\Rockwell\RnaDirServer.exe
(Rockwell Automation, Inc.) C:\Program Files (x86)\Common Files\Rockwell\RNADirMultiplexor.exe
(Microsoft Corporation) C:\Windows\System32\alg.exe
(Microsoft Corporation) C:\Windows\System32\drvinst.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\SystemCore\mfefire.exe
(SoftThinks - Dell) C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe
(SoftThinks - Dell) C:\Program Files (x86)\Dell DataSafe Local Backup\Toaster.exe
(Copyright 2013 SAMSUNG) C:\Program Files\Samsung\Samsung Link\Samsung Link Tray Agent.exe
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\Platform\McSvcHost\McSvHost.exe
() C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe
(Logitech, Inc.) C:\Program Files\Logitech\SetPointP\SetPoint.exe
(Logitech, Inc.) C:\Program Files\Logitech\SetPointP\LBTWiz.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_w32.exe
(SoftThinks) C:\Program Files (x86)\Dell DataSafe Local Backup\SetMUILanguage.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_x64.exe
(Logitech Inc.) C:\Program Files (x86)\Logitech\Vid HD\Vid.exe

==================== Registry (Whitelisted) ====================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8512760 2015-08-04] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1411320 2015-08-04] (Realtek Semiconductor)
HKLM\...\Run: [AthBtTray] => C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\AthBtTray.exe [800416 2011-12-29] (Atheros Commnucations)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [472984 2013-09-25] (Adobe Systems Incorporated)
HKLM\...\Run: [Samsung Link] => C:\Program Files\Samsung\Samsung Link\Samsung Link Tray Agent.exe [607584 2015-03-18] (Copyright 2013 SAMSUNG)
HKLM\...\Run: [EvtMgr6] => C:\Program Files\Logitech\SetPointP\SetPoint.exe [3113592 2015-08-25] (Logitech, Inc.)
HKLM\...\Run: [Bluetooth Connection Assistant] => LBTWIZ.EXE -silent
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-02-17] (Intel Corporation)
HKLM-x32\...\Run: [ShwiconXP9106] => C:\Program Files (x86)\Multimedia Card Reader(9106)\ShwiconXP9106.exe [237568 2010-03-10] (Alcor Micro Corp.)
HKLM-x32\...\Run: [mcui_exe] => C:\Program Files\McAfee.com\Agent\mcagent.exe [557344 2017-04-17] (McAfee, Inc.)
HKLM-x32\...\Run: [Adobe Acrobat Speed Launcher] => C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe [44128 2013-05-08] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe [642664 2013-05-08] (Adobe Systems Inc.)
HKLM-x32\...\Run: [LWS] => C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe [205336 2011-11-11] (Logitech Inc.)
HKLM-x32\...\Run: [RoxWatchTray] => C:\Program Files (x86)\Common Files\Roxio Shared\12.0\SharedCOM\RoxWatchTray12.exe [240112 2009-07-24] (Sonic Solutions)
HKLM-x32\...\Run: [CPMonitor] => C:\Program Files (x86)\Roxio 2010\5.0\CPMonitor.exe [84464 2009-07-21] ()
HKLM-x32\...\Run: [Desktop Disc Tool] => C:\Program Files (x86)\Roxio 2010\Roxio Burn\RoxioBurnLauncher.exe [494064 2009-06-23] ()
HKLM-x32\...\Run: [Monitor] => C:\Program Files (x86)\LeapFrog\LeapFrog Connect\Monitor.exe [118272 2014-07-11] (LeapFrog Enterprises, Inc.)
HKLM-x32\...\Run: [ScanSnap WIA Service Checker] => C:\Windows\SSDriver\fi5110\SsWiaChecker.exe [86016 2009-09-30] (PFU LIMITED)
HKLM-x32\...\Run: [AgentMonitor] => C:\Program Files (x86)\VTech\DownloadManager\System\AgentMonitor.exe [391040 2013-06-20] ()
HKLM-x32\...\Run: [FUFAXRCV] => C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXRCV.exe [653352 2017-03-02] (SEIKO EPSON CORPORATION)
HKLM-x32\...\Run: [FUFAXSTM] => C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe [862248 2017-03-02] (SEIKO EPSON CORPORATION)
HKLM-x32\...\Run: [LTCM Client] => C:\Program Files (x86)\LTCM Client\ltcmClient.exe [2756864 2011-04-07] (Leader Technologies Inc.)
HKLM-x32\...\Run: [Adobe Creative Cloud] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2237328 2013-11-05] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [UsbCipHelper] => C:\Program Files (x86)\Rockwell Automation\UsbCipDriver\UsbCipHelper\UsbCipHelper.exe [434176 2011-10-18] (Rockwell Automation, Inc.)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [AllShareAgent] => C:\Program Files (x86)\Samsung\AllShare\AllShareAgent.exe [285072 2012-03-01] (Samsung Electronics Co., Ltd.)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [767176 2015-08-21] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [Display] => C:\Program Files (x86)\APC\PowerChute Personal Edition\DataCollectionLauncher.exe [284024 2012-01-24] (Schneider Electric)
HKLM-x32\...\Run: [Avira SystrayStartTrigger] => "C:\Program Files (x86)\Avira\Launcher\Avira.SystrayStartTrigger.exe"
HKLM-x32\...\Run: [EEventManager] => C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe [1087184 2016-01-20] (SEIKO EPSON CORPORATION)
HKLM-x32\...\Run: [SoundTouch Music Server] => C:\Program Files (x86)\SoundTouch\SoundTouchMusicServer\SoundTouch Music Server.lnk [2193 2017-04-28] ()
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2017-03-15] (Oracle Corporation)
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
HKU\S-1-5-21-1949060236-814623403-1790243873-1000\...\Run: [Logitech Vid] => C:\Program Files (x86)\Logitech\Vid HD\Vid.exe [6129496 2011-01-12] (Logitech Inc.)
HKU\S-1-5-21-1949060236-814623403-1790243873-1000\...\Run: [CAHeadless] => C:\Program Files (x86)\Adobe\Elements 11 Organizer\CAHeadless\ElementsAutoAnalyzer.exe [840784 2012-09-23] (Adobe Systems Incorporated)
HKU\S-1-5-21-1949060236-814623403-1790243873-1000\...\Run: [Google Update] => C:\Users\JanLar\AppData\Local\Google\Update\1.3.33.5\GoogleUpdateCore.exe [601168 2017-04-28] (Google Inc.)
HKU\S-1-5-21-1949060236-814623403-1790243873-1000\...\Run: [QuickenScheduledUpdates] => C:\Program Files (x86)\Quicken\bagent.exe [77248 2016-04-12] (Intuit Inc.)
HKU\S-1-5-21-1949060236-814623403-1790243873-1000\...\Run: [EPLTarget\P0000000000000001] => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YATIKDE.EXE [298560 2013-09-12] (SEIKO EPSON CORPORATION)
HKU\S-1-5-21-1949060236-814623403-1790243873-1000\...\Run: [RoboForm] => C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe [110376 2017-04-19] (Siber Systems)
HKU\S-1-5-21-1949060236-814623403-1790243873-1000\...\Run: [EPLTarget\P0000000000000000] => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YATIKDE.EXE [298560 2013-09-12] (SEIKO EPSON CORPORATION)
HKU\S-1-5-21-1949060236-814623403-1790243873-1000\...\RunOnce: [Uninstall C:\Users\JanLar\AppData\Local\Microsoft\OneDrive\17.3.6281.1202_1\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\JanLar\AppData\Local\Microsoft\OneDrive\17.3.6281.1202_1\amd64"
HKU\S-1-5-18\...\Run: [EPLTarget\P0000000000000000] => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YATIIUE.EXE [283232 2012-02-28] (SEIKO EPSON CORPORATION)
ShellIconOverlayIdentifiers: [ AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll [2013-10-16] ()
ShellIconOverlayIdentifiers: [ AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll [2013-10-16] ()
ShellIconOverlayIdentifiers: [ AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll [2013-10-16] ()
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  -> No File
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  -> No File
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\APC UPS Status.lnk [2016-03-14]
ShortcutTarget: APC UPS Status.lnk -> C:\Program Files (x86)\APC\PowerChute Personal Edition\Display.exe (Schneider Electric)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\CardMinder Viewer.lnk [2012-10-01]
ShortcutTarget: CardMinder Viewer.lnk -> C:\Program Files (x86)\PFU\ScanSnap\CardMinder\CardLauncher.exe (PFU LIMITED)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Conversion to PDF with ScanSnap Organizer.lnk [2013-03-20]
ShortcutTarget: Conversion to PDF with ScanSnap Organizer.lnk -> C:\Program Files (x86)\PFU\ScanSnap\Organizer\PfuSsOrgOcrChk.exe (PFU LIMITED)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2017-05-24]
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.11.561\SSScheduler.exe (McAfee, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ScanSnap Manager.lnk [2013-03-28]
ShortcutTarget: ScanSnap Manager.lnk -> C:\Program Files (x86)\PFU\ScanSnap\Driver\PfuSsMon.exe (PFU LIMITED)
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

ProxyServer: [S-1-5-21-1949060236-814623403-1790243873-1000] => http=127.0.0.1:4444;https=127.0.0.1:4445
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 209.18.47.61 209.18.47.62
Tcpip\..\Interfaces\{0C3DFCD4-940A-45F4-B90D-2853CC94F22A}: [DhcpNameServer] 8.8.8.8 8.8.4.4
Tcpip\..\Interfaces\{1307b17c-24f1-458a-8bce-8f158e96b1f2}: [DhcpNameServer] 209.222.18.222 209.222.18.218
Tcpip\..\Interfaces\{2fc00daf-03c4-4a1e-a41d-c34fd78f67a9}: [DhcpNameServer] 209.18.47.61 209.18.47.62
Tcpip\..\Interfaces\{98f6215d-beac-4f36-9c27-6ed24f183f9e}: [DhcpNameServer] 209.18.47.61 209.18.47.62

Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-1949060236-814623403-1790243873-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-1949060236-814623403-1790243873-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-1949060236-814623403-1790243873-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.com/?gws_rd=ssl
SearchScopes: HKLM -> DefaultScope {3BE5F7D1-E755-403B-A190-4D9348671630} URL =
SearchScopes: HKLM -> {5e7797ae-5ca1-4b50-95d8-97e746340487} URL = hxxp://www.bing.com/search?q={searchTerms}&form=DLCDF8&pc=MDDR&src=IE-SearchBox
SearchScopes: HKLM-x32 -> DefaultScope {3BE5F7D1-E755-403B-A190-4D9348671630} URL =
SearchScopes: HKLM-x32 -> {5e7797ae-5ca1-4b50-95d8-97e746340487} URL = hxxp://www.bing.com/search?q={searchTerms}&form=DLCDF8&pc=MDDR&src=IE-SearchBox
SearchScopes: HKU\.DEFAULT -> DefaultScope {3BE5F7D1-E755-403B-A190-4D9348671630} URL = hxxp://www.bing.com/search?q={searchTerms}&form=DLCDF8&pc=MDDR&src=IE-SearchBox
SearchScopes: HKU\.DEFAULT -> {3BE5F7D1-E755-403B-A190-4D9348671630} URL = hxxp://www.bing.com/search?q={searchTerms}&form=DLCDF8&pc=MDDR&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-1949060236-814623403-1790243873-1000 -> DefaultScope {A99F3C38-B642-4C66-9CDD-6C7843B96F16} URL = hxxps://search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=715483&p={searchTerms}
SearchScopes: HKU\S-1-5-21-1949060236-814623403-1790243873-1000 -> {3BE5F7D1-E755-403B-A190-4D9348671630} URL =
SearchScopes: HKU\S-1-5-21-1949060236-814623403-1790243873-1000 -> {5e7797ae-5ca1-4b50-95d8-97e746340487} URL =
SearchScopes: HKU\S-1-5-21-1949060236-814623403-1790243873-1000 -> {83C74302-D737-4E56-9D3F-C55F4D917B18} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-1949060236-814623403-1790243873-1000 -> {A99F3C38-B642-4C66-9CDD-6C7843B96F16} URL = hxxps://search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=715483&p={searchTerms}
BHO: RoboForm Toolbar Helper -> {724d43a9-0d85-11d4-9908-00400523e39a} -> C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll [2017-04-19] (Siber Systems Inc.)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-12-15] (Google Inc.)
BHO: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll [2015-08-25] (Logitech, Inc.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: E-Web Print -> {201CF130-E29C-4E5C-A73F-CD197DEFA6AE} -> C:\Program Files (x86)\Epson Software\E-Web Print\ewps_tb.dll [2014-11-27] (SEIKO EPSON CORPORATION)
BHO-x32: RoboForm Toolbar Helper -> {724d43a9-0d85-11d4-9908-00400523e39a} -> C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll [2017-04-19] (Siber Systems Inc.)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_131\bin\ssv.dll [2017-05-11] (Oracle Corporation)
BHO-x32: CIESpeechBHO Class -> {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} -> C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\IEPlugIn.dll [2011-12-29] (Atheros Commnucations)
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2016-12-15] (Google Inc.)
BHO-x32: Adobe PDF Conversion Toolbar Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2013-05-08] (Adobe Systems Incorporated)
BHO-x32: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll [2015-08-25] (Logitech, Inc.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_131\bin\jp2ssv.dll [2017-05-11] (Oracle Corporation)
BHO-x32: SmartSelect Class -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2013-05-08] (Adobe Systems Incorporated)
Toolbar: HKLM - &RoboForm Toolbar - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll [2017-04-19] (Siber Systems Inc.)
Toolbar: HKLM - Vuze Remote Toolbar - {05478A66-EDB6-4A22-A870-A5987F80A7DA} - C:\Program Files (x86)\Vuze Remote Toolbar\IE\8.6\vuzeToolbarIE64.dll No File
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-12-15] (Google Inc.)
Toolbar: HKLM-x32 - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2013-05-08] (Adobe Systems Incorporated)
Toolbar: HKLM-x32 - &RoboForm Toolbar - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll [2017-04-19] (Siber Systems Inc.)
Toolbar: HKLM-x32 - E-Web Print - {201CF130-E29C-4E5C-A73F-CD197DEFA6AE} - C:\Program Files (x86)\Epson Software\E-Web Print\ewps_tb.dll [2014-11-27] (SEIKO EPSON CORPORATION)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2016-12-15] (Google Inc.)
Toolbar: HKU\.DEFAULT -> No Name - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} -  No File
Toolbar: HKU\.DEFAULT -> No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} -  No File
Toolbar: HKU\.DEFAULT -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-12-15] (Google Inc.)
Toolbar: HKU\.DEFAULT -> &RoboForm Toolbar - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll [2017-04-19] (Siber Systems Inc.)
Toolbar: HKU\S-1-5-21-1949060236-814623403-1790243873-1000 -> No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} -  No File
Toolbar: HKU\S-1-5-21-1949060236-814623403-1790243873-1000 -> No Name - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} -  No File
Toolbar: HKU\S-1-5-21-1949060236-814623403-1790243873-1000 -> &RoboForm Toolbar - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll [2017-04-19] (Siber Systems Inc.)
DPF: HKLM-x32 {17492023-C23A-453E-A040-C7C580BBF700} hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
DPF: HKLM-x32 {FFAD8DA9-ED41-494D-AC8E-63D861D0A733} hxxps://download.rockwellautomation.com/plugins/rockwell.cab
Handler-x32: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files (x86)\Belarc\BelarcAdvisor\System\BAVoilaX.dll [2016-01-04] (Belarc, Inc.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2017-01-01] (Skype Technologies)
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\mcafee\MSC\McSnIePl64.dll [2017-04-17] (McAfee, Inc.)
Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\MSC\McSnIePl.dll [2017-04-17] (McAfee, Inc.)

FireFox:
========
FF ProfilePath: C:\Users\JanLar\AppData\Roaming\Mozilla\Firefox\Profiles\ou0umi33.default [2017-05-24]
FF SelectedSearchEngine: Mozilla\Firefox\Profiles\ou0umi33.default -> Palikan
FF NetworkProxy: Mozilla\Firefox\Profiles\ou0umi33.default -> http_port", 4444
FF DefaultSearchEngine: Mozilla\Firefox\Profiles\ou0umi33.default -> Palikan
FF NewTab: Mozilla\Firefox\Profiles\ou0umi33.default -> about:newtab
FF NetworkProxy: Mozilla\Firefox\Profiles\ou0umi33.default -> http", "127.0.0.1"
FF NetworkProxy: Mozilla\Firefox\Profiles\ou0umi33.default -> socks_version", 4
FF NetworkProxy: Mozilla\Firefox\Profiles\ou0umi33.default -> ssl", "172.0.0.1"
FF NetworkProxy: Mozilla\Firefox\Profiles\ou0umi33.default -> ssl_port", 4445
FF NetworkProxy: Mozilla\Firefox\Profiles\ou0umi33.default -> type", 0
FF Homepage: Mozilla\Firefox\Profiles\ou0umi33.default -> hxxps://www.malwarebytes.org/restorebrowser//?f=1&a=plk_coinisre_17_02&cd=2XzuyEtN2Y1L1Qzu0EtDtDyC0EyCyB0FtAyCtBtB0DtAtA0FtN0D0Tzu0StCzzyEtDtN1L2XzutAtFtByEtFtCtAtFyDyEtN1L1Czu1ByCtN1L1G1B1V1N2Y1L1Qzu2StByDtBtAyDtAtD0CtGtA0FyDyCtGtBzz0FtBtGtDyBtAyBtGyB0BtCtCtBzztC0A0A0FyD0A2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0EtD0F0FyBtDtCtAtG0DtByCzytGyE0F0AtBtG0A0BtAtBtGtBtCtBzy0BtD0CyByBtDyCzz2QtN0A0LzutB&cr=1791041131&ir=
FF Keyword.URL: Mozilla\Firefox\Profiles\ou0umi33.default -> user_pref("keyword.URL", true);
FF HKLM-x32\...\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt
FF Extension: (Logitech SetPoint) - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt [2016-08-21] [not signed]
FF HKLM-x32\...\Firefox\Extensions: [e-webprint@epson.com] - C:\Program Files (x86)\Epson Software\E-Web Print\Firefox Add-on
FF Extension: (E-Web Print) - C:\Program Files (x86)\Epson Software\E-Web Print\Firefox Add-on [2016-05-11] [not signed]
FF HKLM-x32\...\Firefox\Extensions: [{22119944-ED35-4ab1-910B-E619EA06A115}] - C:\Program Files (x86)\Siber Systems\AI RoboForm\Firefox\roboform.xpi
FF Extension: (RoboForm Toolbar) - C:\Program Files (x86)\Siber Systems\AI RoboForm\Firefox\roboform.xpi [2017-04-19]
FF HKU\S-1-5-21-1949060236-814623403-1790243873-1000\...\Firefox\Extensions: [{22119944-ED35-4ab1-910B-E619EA06A115}] - C:\Program Files (x86)\Siber Systems\AI RoboForm\Firefox\roboform.xpi
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_25_0_0_171.dll [2017-05-10] ()
FF Plugin: @mcafee.com/MSC,version=10 -> c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL [2017-04-17] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50906.0\npctrl.dll [2017-03-09] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2013-11-05] (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_25_0_0_171.dll [2017-05-10] ()
FF Plugin-x32: @java.com/DTPlugin,version=11.131.2 -> C:\Program Files (x86)\Java\jre1.8.0_131\bin\dtplugin\npDeployJava1.dll [2017-05-11] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.131.2 -> C:\Program Files (x86)\Java\jre1.8.0_131\bin\plugin2\npjp2.dll [2017-05-11] (Oracle Corporation)
FF Plugin-x32: @mcafee.com/MSC,version=10 -> c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL [2017-04-17] ()
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\npctrl.dll [2017-03-09] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin-x32: @nosltd.com/getPlus+®,version=2.0.7.35 -> C:\Program Files (x86)\NOS\bin\nprockwell.dll [2013-08-12] (NOS Microsystems Ltd.)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-28] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-28] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.0 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: Adobe Acrobat -> C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Air\nppdf32.dll [2013-05-08] (Adobe Systems Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-04-04] (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2013-11-05] (Adobe Systems)
FF Plugin HKU\S-1-5-21-1949060236-814623403-1790243873-1000: @talk.google.com/GoogleTalkPlugin -> C:\Users\JanLar\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll [2015-12-08] (Google)
FF Plugin HKU\S-1-5-21-1949060236-814623403-1790243873-1000: @talk.google.com/O1DPlugin -> C:\Users\JanLar\AppData\Roaming\Mozilla\plugins\npo1d.dll [2015-12-08] (Google)
FF Plugin HKU\S-1-5-21-1949060236-814623403-1790243873-1000: @tools.google.com/Google Update;version=3 -> C:\Users\JanLar\AppData\Local\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-28] (Google Inc.)
FF Plugin HKU\S-1-5-21-1949060236-814623403-1790243873-1000: @tools.google.com/Google Update;version=9 -> C:\Users\JanLar\AppData\Local\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-28] (Google Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\JanLar\AppData\Roaming\mozilla\plugins\npgoogletalk.dll [2015-12-08] (Google)
FF Plugin ProgramFiles/Appdata: C:\Users\JanLar\AppData\Roaming\mozilla\plugins\npo1d.dll [2015-12-08] (Google)

Chrome:
=======
CHR DefaultProfile: Default
CHR HomePage: Default -> hxxps://www.google.com//?type=715483&fr=yo-yhp-ch
CHR StartupUrls: Default -> "hxxps://search.yahoo.com/?type=715483&fr=yo-yhp-ch",null,null,null,null,null,"hxxp://start.roboform.com"
CHR NewTab: Default ->  Active:"chrome-extension://jdcikeehjpacoeddlgdhkcnkcmcchegc/ntp/newtab.html"
CHR Profile: C:\Users\JanLar\AppData\Local\Google\Chrome\User Data\Default [2017-05-29]
CHR Extension: (Google Drive) - C:\Users\JanLar\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-08-21]
CHR Extension: (YouTube) - C:\Users\JanLar\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-24]
CHR Extension: (Google Search) - C:\Users\JanLar\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2016-02-20]
CHR Extension: (Logitech Smooth Scrolling) - C:\Users\JanLar\AppData\Local\Google\Chrome\User Data\Default\Extensions\dkpejdfnpdkhifgbancbammdijojoffk [2015-04-01]
CHR Extension: (Google Docs Offline) - C:\Users\JanLar\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-08-21]
CHR Extension: (New Tab Helper 52) - C:\Users\JanLar\AppData\Local\Google\Chrome\User Data\Default\Extensions\jdcikeehjpacoeddlgdhkcnkcmcchegc [2016-05-21]
CHR Extension: (Shopping Assistant 52) - C:\Users\JanLar\AppData\Local\Google\Chrome\User Data\Default\Extensions\jnaommnffgbanfoeolebgkjikdjhpkfn [2016-05-21]
CHR Extension: (Skype) - C:\Users\JanLar\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2017-04-10]
CHR Extension: (Chrome Web Store Payments) - C:\Users\JanLar\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-04-10]
CHR Extension: (Gmail) - C:\Users\JanLar\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-04-01]
CHR Extension: (Chrome Media Router) - C:\Users\JanLar\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-04-10]
CHR Extension: (RoboForm Password Manager) - C:\Users\JanLar\AppData\Local\Google\Chrome\User Data\Default\Extensions\pnlccmojcmeohlpggmfnbbiapkmbliob [2017-05-29]
CHR HKLM\...\Chrome\Extension: [pnlccmojcmeohlpggmfnbbiapkmbliob] - C:\Program Files (x86)\Siber Systems\AI RoboForm\Chrome\rf-chrome.crx [2014-04-19]
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [pnlccmojcmeohlpggmfnbbiapkmbliob] - C:\Program Files (x86)\Siber Systems\AI RoboForm\Chrome\rf-chrome.crx [2014-04-19]

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 9734BF6A-2DCD-40f0-BAB0-5AAFEEBE1269; C:\Program Files (x86)\Roxio\BackOnTrack\Disaster Recovery\SaibSVC.exe [457200 2009-06-02] ()
R2 ABBYY.Licensing.FineReader.Sprint.9.0; C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [759048 2009-05-14] (ABBYY)
U2 AdobeActiveFileMonitor11.0; C:\Program Files (x86)\Adobe\Elements 11 Organizer\PhotoshopElementsFileAgent.exe [171600 2012-09-23] (Adobe Systems Incorporated)
R2 AllShare Framework DMS; C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\AllShareFrameworkManagerDMS.exe [404360 2013-12-21] (Samsung) [File not signed]
R2 APC Data Service; C:\Program Files (x86)\APC\PowerChute Personal Edition\dataserv.exe [21880 2012-01-24] (Schneider Electric)
R2 APC UPS Service; C:\Program Files (x86)\APC\PowerChute Personal Edition\mainserv.exe [705912 2012-01-24] (Schneider Electric)
S3 ClientAnalyticsService; C:\Program Files\Common Files\McAfee\ClientAnalytics\Legacy\McClientAnalytics.exe [1752992 2017-03-29] (Intel Security)
S2 Dell Customer Connect; C:\Program Files (x86)\Dell Customer Connect\DCCService.exe [130936 2016-12-21] (Dell Inc.)
S2 DellDataVault; C:\Program Files\Dell\DellDataVault\DellDataVault.exe [2572024 2016-06-23] (Dell Inc.)
S2 DellUpdate; C:\Program Files (x86)\Dell Update\DellUpService.exe [237272 2015-08-27] (Dell Inc.)
S3 dnWhoDisp; C:\Program Files (x86)\Rockwell Software\RSLINX\dnwhodisp.exe [167936 2012-10-31] (Rockwell Automation, Inc.) [File not signed]
R2 EpsonCustomerResearchParticipation; C:\Program Files\EPSON\EpsonCustomerResearchParticipation\EPCP.exe [677880 2017-05-29] (SEIKO EPSON CORPORATION)
R2 EpsonScanSvc; C:\WINDOWS\system32\EscSvc64.exe [144560 2012-05-17] (Seiko Epson Corporation)
S3 FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [651720 2012-09-30] (Macrovision Europe Ltd.) [File not signed]
R2 FTSysDiagSvcHost; C:\Program Files (x86)\Common Files\Rockwell\FTSysDiagSvcHost.exe [69120 2012-12-17] (Rockwell Automation, Inc.) [File not signed]
R2 hasplms; C:\Windows\system32\hasplms.exe [4412872 2012-08-22] (SafeNet Inc.)
R2 HomeNetSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [641520 2017-02-22] (McAfee, Inc.)
R2 i2p; C:\Program Files (x86)\i2p\I2Psvc.exe [384000 2013-04-01] (Tanuki Software, Ltd.) [File not signed]
S3 ImDskSvc; C:\Windows\system32\imdsksvc.exe [11264 2011-03-11] (Olof Lagerkvist) [File not signed]
R2 Intel® ME Service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe [128280 2012-01-21] ()
R2 LeapFrog Connect Device Service; C:\Program Files (x86)\LeapFrog\LeapFrog Connect\CommandService.exe [7241728 2014-07-11] (LeapFrog Enterprises, Inc.) [File not signed]
S3 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4470736 2017-05-09] (Malwarebytes)
R2 McAPExe; C:\Program Files\Common Files\McAfee\VSCore_15_6\McApExe.exe [994312 2017-04-04] (McAfee, Inc.)
R2 McBootDelayStartSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [641520 2017-02-22] (McAfee, Inc.)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.11.561\McCHSvc.exe [404368 2017-05-16] (McAfee, Inc.)
R2 mccspsvc; C:\Program Files\Common Files\McAfee\CSP\2.3.322.0\\McCSPServiceHost.exe [2054080 2017-02-28] (McAfee, Inc.)
R2 McNaiAnn; C:\Program Files\Common Files\mcafee\Platform\McSvcHost\McSvHost.exe [641520 2017-02-22] (McAfee, Inc.)
S3 McODS; C:\Program Files\mcafee\VirusScan\mcods.exe [1344472 2017-02-24] (McAfee, Inc.)
R2 mcpltsvc; C:\Program Files\Common Files\mcafee\Platform\McSvcHost\McSvHost.exe [641520 2017-02-22] (McAfee, Inc.)
U2 McProxy; C:\Program Files\Common Files\mcafee\Platform\McSvcHost\McSvHost.exe [641520 2017-02-22] (McAfee, Inc.)
R3 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [241040 2017-01-18] (McAfee, Inc.)
R2 mfemms; C:\Program Files\Common Files\McAfee\SystemCore\\mfemms.exe [385112 2017-01-18] (McAfee, Inc.)
R3 mfevtp; C:\WINDOWS\system32\mfevtps.exe [343792 2017-01-18] (McAfee, Inc.)
R2 ModuleCoreService; C:\Program Files\Common Files\McAfee\ModuleCore\ModuleCoreService.exe [1551512 2017-02-26] (McAfee, Inc.)
R2 PEFService; C:\Program Files\Common Files\Intel Security\PEF\CORE\PEFService.exe [1104304 2016-11-15] (Intel Security, Inc.)
S3 RSLinx; C:\Program Files (x86)\Rockwell Software\RSLinx\RSLINX.EXE [3272224 2013-01-19] (Rockwell Automation, Inc.)
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [312056 2015-08-04] (Realtek Semiconductor)
R2 Samsung Link Service; C:\Program Files\Samsung\Samsung Link\Samsung Link.exe [616288 2015-03-18] (Copyright 2013 SAMSUNG)
S2 SupportAssistAgent; C:\Program Files (x86)\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe [32728 2017-04-25] (Dell Inc.)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [5702416 2015-09-11] (TeamViewer GmbH)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2016-10-25] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2017-04-27] (Microsoft Corporation)
R2 ZAtheros Bt&Wlan Coex Agent; C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\Ath_CoexAgent.exe [158880 2011-12-29] (Atheros) [File not signed]
R2 ZAtheros Wlan Agent; C:\Program Files (x86)\Dell Wireless\Ath_WlanAgent.exe [76960 2011-12-26] (Atheros) [File not signed]
S2 Avira.ServiceHost; "C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe" [X]
S2 AviraPhantomVPN; "C:\Program Files (x86)\Avira\VPN\Avira.VpnService.exe" [X]

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 androidusb; C:\WINDOWS\System32\Drivers\androidusb.sys [31744 2009-09-15] (Google Inc)
S3 aswTap; C:\WINDOWS\System32\drivers\aswTap.sys [44640 2017-01-14] (The OpenVPN Project)
R3 athr; C:\WINDOWS\System32\drivers\athw10x.sys [4318760 2015-12-10] (Qualcomm Atheros Communications, Inc.)
R3 AtiHDAudioService; C:\WINDOWS\system32\drivers\AtihdWT6.sys [102912 2015-05-28] (Advanced Micro Devices)
S3 AWEAlloc; C:\WINDOWS\System32\DRIVERS\awealloc.sys [17360 2011-03-11] (Olof Lagerkvist)
S3 cfwids; C:\WINDOWS\System32\drivers\cfwids.sys [88464 2017-01-20] (McAfee, Inc.)
S3 DDDriver; C:\WINDOWS\system32\drivers\DDDriver64Dcsa.sys [23760 2015-01-30] (Dell Computer Corporation)
S3 DellProf; C:\WINDOWS\system32\drivers\DellProf.sys [24240 2015-05-22] (Dell Computer Corporation)
S2 hardlock; C:\Windows\system32\drivers\hardlock.sys [321536 2011-09-28] (SafeNet Inc.)
R2 ImDisk; C:\WINDOWS\System32\DRIVERS\imdisk.sys [34776 2011-03-11] (Olof Lagerkvist)
R3 mfeaack; C:\WINDOWS\System32\drivers\mfeaack.sys [487184 2017-01-20] (McAfee, Inc.)
R3 mfeavfk; C:\WINDOWS\System32\drivers\mfeavfk.sys [366328 2017-01-20] (McAfee, Inc.)
S0 mfeelamk; C:\WINDOWS\System32\drivers\mfeelamk.sys [85048 2017-04-03] (McAfee, Inc.)
R3 mfefirek; C:\WINDOWS\System32\drivers\mfefirek.sys [518704 2017-01-20] (McAfee, Inc.)
R0 mfehidk; C:\WINDOWS\System32\drivers\mfehidk.sys [923640 2017-01-20] (McAfee, Inc.)
R3 mfencbdc; C:\WINDOWS\system32\DRIVERS\mfencbdc.sys [498648 2017-01-19] (McAfee, Inc.)
S3 mfencrk; C:\WINDOWS\system32\DRIVERS\mfencrk.sys [109320 2017-01-19] (McAfee, Inc.)
R3 mfeplk; C:\WINDOWS\System32\drivers\mfeplk.sys [110256 2017-01-20] (McAfee, Inc.)
R0 mfewfpk; C:\WINDOWS\System32\drivers\mfewfpk.sys [254800 2017-01-20] (McAfee, Inc.)
R0 PxHlpa64; C:\WINDOWS\System32\Drivers\PxHlpa64.sys [56336 2012-08-10] (Corel Corporation)
S3 qcusbser; C:\WINDOWS\system32\DRIVERS\qcusbser.sys [242688 2013-01-15] (QUALCOMM Incorporated)
S3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [589824 2015-10-30] (Realtek                                            )
S3 usbrndis6; C:\WINDOWS\System32\drivers\usb80236.sys [23040 2015-10-30] (Microsoft Corporation)
R1 VirtualBackplane; C:\WINDOWS\System32\drivers\VirtualBackplane.sys [51200 2011-06-02] (Rockwell Automation)
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation)
U1 aswbdisk; no ImagePath
S3 aswHdsKe; \??\C:\WINDOWS\system32\drivers\aswHdsKe.sys [X]
U3 idsvc; no ImagePath

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-05-30 10:22 - 2017-05-30 10:22 - 00000000 ___HD C:\OneDriveTemp
2017-05-30 08:51 - 2017-05-30 08:51 - 00000000 ____D C:\$SysReset
2017-05-30 08:27 - 2017-05-30 08:50 - 00042392 _____ C:\Users\JanLar\Desktop\Addition.txt
2017-05-30 08:25 - 2017-05-30 10:21 - 00041941 _____ C:\Users\JanLar\Desktop\FRST.txt
2017-05-29 22:31 - 2017-05-29 22:32 - 00042394 _____ C:\Users\JanLar\Downloads\Addition.txt
2017-05-29 22:30 - 2017-05-29 22:31 - 00080548 _____ C:\Users\JanLar\Downloads\FRST.txt
2017-05-29 22:30 - 2017-05-29 22:30 - 00000000 ____D C:\FRST
2017-05-29 22:25 - 2017-05-29 22:30 - 02429952 _____ (Farbar) C:\Users\JanLar\Downloads\FRST64.exe
2017-05-29 22:22 - 2017-05-30 08:25 - 02429952 _____ (Farbar) C:\Users\JanLar\Desktop\FRST64.exe
2017-05-29 18:55 - 2017-05-29 18:55 - 00001914 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2017-05-29 18:55 - 2017-05-29 18:55 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2017-05-29 18:55 - 2017-05-29 18:55 - 00000000 ____D C:\Program Files\Malwarebytes
2017-05-29 18:55 - 2017-05-09 16:37 - 00077440 _____ C:\WINDOWS\system32\Drivers\mbae64.sys
2017-05-29 15:07 - 2017-05-30 08:23 - 00004034 _____ C:\WINDOWS\System32\Tasks\Intel Security DAT Reputation (AMCore) periodic endpoint safety pulse
2017-05-29 13:27 - 2017-05-29 13:27 - 00004222 _____ C:\WINDOWS\System32\Tasks\Intel Security DAT Reputation (AMCore) Post DAT update endpoint safety pulse
2017-05-24 17:40 - 2017-05-24 17:40 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus
2017-05-24 17:40 - 2017-05-24 17:40 - 00000000 ____D C:\ProgramData\McAfee Security Scan
2017-05-21 19:21 - 2017-05-21 19:21 - 13089219 _____ C:\Users\JanLar\Documents\Freelance Marketing Handbook - Antonio V1.pdf
2017-05-14 21:07 - 2017-05-14 21:07 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YTD Video Downloader
2017-05-11 20:39 - 2017-05-11 20:39 - 04170170 _____ C:\Users\JanLar\Documents\840206110031_use.pdf
2017-05-11 00:15 - 2017-05-11 00:15 - 00647991 _____ C:\Users\JanLar\Documents\Portable AC.pdf
2017-05-09 19:30 - 2017-04-27 23:59 - 01862000 _____ C:\WINDOWS\SysWOW64\CoreUIComponents.dll
2017-05-09 19:30 - 2017-04-27 23:59 - 00602256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleaut32.dll
2017-05-09 19:30 - 2017-04-27 23:31 - 00808288 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe
2017-05-09 19:30 - 2017-04-27 23:25 - 06536248 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppsvc.exe
2017-05-09 19:30 - 2017-04-27 23:04 - 00881664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll
2017-05-09 19:30 - 2017-04-27 22:57 - 01813408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll
2017-05-09 19:30 - 2017-04-27 22:57 - 00959144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll
2017-05-09 19:30 - 2017-04-27 22:56 - 02945648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2017-05-09 19:30 - 2017-04-27 22:56 - 00703840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe
2017-05-09 19:30 - 2017-04-27 22:53 - 00465760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncHost.exe
2017-05-09 19:30 - 2017-04-27 22:52 - 05240448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2017-05-09 19:30 - 2017-04-27 22:45 - 01536600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\crypt32.dll
2017-05-09 19:30 - 2017-04-27 22:19 - 01370224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32.dll
2017-05-09 19:30 - 2017-04-27 22:16 - 00190464 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2017-05-09 19:30 - 2017-04-27 22:06 - 00059392 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe
2017-05-09 19:30 - 2017-04-27 21:59 - 00379392 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocore.dll
2017-05-09 19:30 - 2017-04-27 21:58 - 00412160 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2017-05-09 19:30 - 2017-04-27 21:50 - 00089088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\olepro32.dll
2017-05-09 19:30 - 2017-04-27 21:39 - 00025600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\odbcconf.dll
2017-05-09 19:30 - 2017-04-27 21:35 - 00689152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv2.sys
2017-05-09 19:30 - 2017-04-27 21:35 - 00407552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv.sys
2017-05-09 19:30 - 2017-04-27 21:23 - 00381952 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll
2017-05-09 19:30 - 2017-04-27 21:21 - 00256512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\unimdm.tsp
2017-05-09 19:30 - 2017-04-27 21:21 - 00205312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oemlicense.dll
2017-05-09 19:30 - 2017-04-27 21:19 - 00865792 _____ (Microsoft Corporation) C:\WINDOWS\system32\AzureSettingSyncProvider.dll
2017-05-09 19:30 - 2017-04-27 21:19 - 00269312 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatehandlers.dll
2017-05-09 19:30 - 2017-04-27 21:15 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\IdCtrls.dll
2017-05-09 19:30 - 2017-04-27 21:11 - 00260096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\apprepsync.dll
2017-05-09 19:30 - 2017-04-27 21:10 - 00190464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\apprepapi.dll
2017-05-09 19:30 - 2017-04-27 21:07 - 00541184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GamePanel.exe
2017-05-09 19:30 - 2017-04-27 21:04 - 00386048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schannel.dll
2017-05-09 19:30 - 2017-04-27 21:01 - 00250880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2017-05-09 19:30 - 2017-04-27 20:57 - 00153088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSSync.dll
2017-05-09 19:30 - 2017-04-27 20:55 - 00501760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2017-05-09 19:30 - 2017-04-27 20:55 - 00400896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OneDriveSettingSyncProvider.dll
2017-05-09 19:30 - 2017-04-27 20:51 - 02280960 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2017-05-09 19:30 - 2017-04-27 20:49 - 00805888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSShared.dll
2017-05-09 19:30 - 2017-04-27 20:47 - 03695104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_47.dll
2017-05-09 19:30 - 2017-04-27 20:47 - 00667648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AzureSettingSyncProvider.dll
2017-05-09 19:30 - 2017-04-27 20:46 - 00207872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\licensingdiag.exe
2017-05-09 19:30 - 2017-04-27 20:32 - 04078080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbgeng.dll
2017-05-09 19:30 - 2017-04-27 20:25 - 01501184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2017-05-09 19:30 - 2017-04-27 20:22 - 04412928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExplorerFrame.dll
2017-05-09 19:30 - 2017-04-27 20:22 - 02878976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2017-05-09 19:30 - 2017-04-27 20:21 - 13018112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2017-05-09 19:30 - 2017-04-27 20:20 - 01556992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OpcServices.dll
2017-05-09 19:30 - 2017-04-27 20:19 - 06296064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mos.dll
2017-05-09 19:30 - 2017-04-27 20:06 - 04404736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Search.dll
2017-05-09 19:30 - 2017-04-27 20:04 - 02911744 _____ (Microsoft Corporation) C:\WINDOWS\system32\CertEnroll.dll
2017-05-09 19:30 - 2017-04-27 19:58 - 00821248 _____ (Microsoft Corporation) C:\WINDOWS\system32\fvewiz.dll
2017-05-09 19:30 - 2017-04-27 19:57 - 02604032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CertEnroll.dll
2017-05-09 19:30 - 2017-04-27 19:55 - 00339456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certcli.dll
2017-05-09 19:30 - 2017-04-27 19:29 - 00461824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll
2017-05-09 19:29 - 2017-04-28 00:32 - 01030416 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2017-05-09 19:29 - 2017-04-28 00:30 - 07465816 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2017-05-09 19:29 - 2017-04-28 00:30 - 02656960 _____ C:\WINDOWS\system32\CoreUIComponents.dll
2017-05-09 19:29 - 2017-04-28 00:30 - 01997840 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2017-05-09 19:29 - 2017-04-28 00:30 - 01317640 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2017-05-09 19:29 - 2017-04-28 00:30 - 01098640 _____ (Microsoft Corporation) C:\WINDOWS\system32\MrmCoreR.dll
2017-05-09 19:29 - 2017-04-28 00:30 - 00800080 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleaut32.dll
2017-05-09 19:29 - 2017-04-28 00:27 - 00754664 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll
2017-05-09 19:29 - 2017-04-28 00:08 - 03449168 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSService.dll
2017-05-09 19:29 - 2017-04-27 23:59 - 01558280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2017-05-09 19:29 - 2017-04-27 23:38 - 01060432 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll
2017-05-09 19:29 - 2017-04-27 23:32 - 02608912 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll
2017-05-09 19:29 - 2017-04-27 23:32 - 01323272 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll
2017-05-09 19:29 - 2017-04-27 23:31 - 03699280 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2017-05-09 19:29 - 2017-04-27 23:31 - 00026464 _____ (Microsoft Corporation) C:\WINDOWS\system32\browser_broker.exe
2017-05-09 19:29 - 2017-04-27 23:28 - 22560744 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2017-05-09 19:29 - 2017-04-27 23:28 - 00566104 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncHost.exe
2017-05-09 19:29 - 2017-04-27 23:27 - 06604992 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2017-05-09 19:29 - 2017-04-27 23:26 - 01540224 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll
2017-05-09 19:29 - 2017-04-27 23:26 - 00692136 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppwinob.dll
2017-05-09 19:29 - 2017-04-27 23:24 - 01128104 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipUp.exe
2017-05-09 19:29 - 2017-04-27 23:24 - 00625000 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipSVC.dll
2017-05-09 19:29 - 2017-04-27 23:23 - 00609056 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2017-05-09 19:29 - 2017-04-27 23:20 - 01848584 _____ (Microsoft Corporation) C:\WINDOWS\system32\crypt32.dll
2017-05-09 19:29 - 2017-04-27 22:53 - 01987424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2017-05-09 19:29 - 2017-04-27 22:52 - 01594928 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32.dll
2017-05-09 19:29 - 2017-04-27 22:31 - 00084480 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpudd.dll
2017-05-09 19:29 - 2017-04-27 22:24 - 00824320 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcWebFilter.dll
2017-05-09 19:29 - 2017-04-27 22:23 - 00068608 _____ (Microsoft Corporation) C:\WINDOWS\system32\fdProxy.dll
2017-05-09 19:29 - 2017-04-27 22:22 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\system32\odbcconf.dll
2017-05-09 19:29 - 2017-04-27 22:15 - 00088064 _____ (Microsoft Corporation) C:\WINDOWS\system32\tdc.ocx
2017-05-09 19:29 - 2017-04-27 22:13 - 00584704 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIRibbonRes.dll
2017-05-09 19:29 - 2017-04-27 22:11 - 00119296 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieetwcollector.exe
2017-05-09 19:29 - 2017-04-27 22:05 - 00091648 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll
2017-05-09 19:29 - 2017-04-27 22:03 - 00297472 _____ (Microsoft Corporation) C:\WINDOWS\system32\unimdm.tsp
2017-05-09 19:29 - 2017-04-27 22:02 - 00285184 _____ (Microsoft Corporation) C:\WINDOWS\system32\oemlicense.dll
2017-05-09 19:29 - 2017-04-27 22:01 - 00238592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Streaming.ps.dll
2017-05-09 19:29 - 2017-04-27 21:55 - 00291328 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll
2017-05-09 19:29 - 2017-04-27 21:55 - 00145920 _____ (Microsoft Corporation) C:\WINDOWS\system32\iepeers.dll
2017-05-09 19:29 - 2017-04-27 21:55 - 00110080 _____ (Microsoft Corporation) C:\WINDOWS\system32\IdCtrls.dll
2017-05-09 19:29 - 2017-04-27 21:54 - 00195584 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpapisrv.dll
2017-05-09 19:29 - 2017-04-27 21:53 - 00198144 _____ (Microsoft Corporation) C:\WINDOWS\system32\winsrv.dll
2017-05-09 19:29 - 2017-04-27 21:53 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2017-05-09 19:29 - 2017-04-27 21:52 - 00221696 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2017-05-09 19:29 - 2017-04-27 21:51 - 00381952 _____ (Microsoft Corporation) C:\WINDOWS\system32\apprepsync.dll
2017-05-09 19:29 - 2017-04-27 21:51 - 00200192 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUDFPlatform.dll
2017-05-09 19:29 - 2017-04-27 21:50 - 00689152 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll
2017-05-09 19:29 - 2017-04-27 21:49 - 00287744 _____ (Microsoft Corporation) C:\WINDOWS\system32\apprepapi.dll
2017-05-09 19:29 - 2017-04-27 21:46 - 00383488 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2017-05-09 19:29 - 2017-04-27 21:45 - 00715776 _____ (Microsoft Corporation) C:\WINDOWS\system32\GamePanel.exe
2017-05-09 19:29 - 2017-04-27 21:41 - 00472576 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll
2017-05-09 19:29 - 2017-04-27 21:40 - 00572928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WpcWebFilter.dll
2017-05-09 19:29 - 2017-04-27 21:38 - 00602112 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptui.dll
2017-05-09 19:29 - 2017-04-27 21:38 - 00330240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2017-05-09 19:29 - 2017-04-27 21:33 - 00183808 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSSync.dll
2017-05-09 19:29 - 2017-04-27 21:32 - 02125312 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Bluetooth.dll
2017-05-09 19:29 - 2017-04-27 21:32 - 00073728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tdc.ocx
2017-05-09 19:29 - 2017-04-27 21:31 - 00784384 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2017-05-09 19:29 - 2017-04-27 21:31 - 00584704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIRibbonRes.dll
2017-05-09 19:29 - 2017-04-27 21:31 - 00515072 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneDriveSettingSyncProvider.dll
2017-05-09 19:29 - 2017-04-27 21:31 - 00262144 _____ (Microsoft Corporation) C:\WINDOWS\system32\webcheck.dll
2017-05-09 19:29 - 2017-04-27 21:30 - 00602624 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2017-05-09 19:29 - 2017-04-27 21:29 - 02127872 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2017-05-09 19:29 - 2017-04-27 21:28 - 01386496 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2017-05-09 19:29 - 2017-04-27 21:28 - 00905728 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcss.dll
2017-05-09 19:29 - 2017-04-27 21:26 - 00853504 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadtb.dll
2017-05-09 19:29 - 2017-04-27 21:24 - 01752576 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2017-05-09 19:29 - 2017-04-27 21:23 - 00961536 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSShared.dll
2017-05-09 19:29 - 2017-04-27 21:20 - 04456448 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_47.dll
2017-05-09 19:29 - 2017-04-27 21:19 - 00236032 _____ (Microsoft Corporation) C:\WINDOWS\system32\licensingdiag.exe
2017-05-09 19:29 - 2017-04-27 21:15 - 00268800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll
2017-05-09 19:29 - 2017-04-27 21:15 - 00128000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iepeers.dll
2017-05-09 19:29 - 2017-04-27 21:13 - 00083456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll
2017-05-09 19:29 - 2017-04-27 21:11 - 00307200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll
2017-05-09 19:29 - 2017-04-27 21:07 - 00335872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2017-05-09 19:29 - 2017-04-27 21:03 - 03586048 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2017-05-09 19:29 - 2017-04-27 21:03 - 02610176 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll
2017-05-09 19:29 - 2017-04-27 21:00 - 05123072 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbgeng.dll
2017-05-09 19:29 - 2017-04-27 20:56 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webcheck.dll
2017-05-09 19:29 - 2017-04-27 20:55 - 00687616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2017-05-09 19:29 - 2017-04-27 20:54 - 02050560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2017-05-09 19:29 - 2017-04-27 20:53 - 01729536 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2017-05-09 19:29 - 2017-04-27 20:50 - 01526272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2017-05-09 19:29 - 2017-04-27 20:47 - 04826624 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExplorerFrame.dll
2017-05-09 19:29 - 2017-04-27 20:47 - 03404800 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2017-05-09 19:29 - 2017-04-27 20:44 - 07977984 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll
2017-05-09 19:29 - 2017-04-27 20:43 - 02055680 _____ (Microsoft Corporation) C:\WINDOWS\system32\OpcServices.dll
2017-05-09 19:29 - 2017-04-27 20:36 - 16985600 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2017-05-09 19:29 - 2017-04-27 20:35 - 03585536 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsThresholdAdminFlowUI.dll
2017-05-09 19:29 - 2017-04-27 20:27 - 01388032 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2017-05-09 19:29 - 2017-04-27 20:25 - 00957952 _____ (Microsoft Corporation) C:\WINDOWS\system32\IKEEXT.DLL
2017-05-09 19:29 - 2017-04-27 20:16 - 22375424 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2017-05-09 19:29 - 2017-04-27 20:12 - 04889600 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2017-05-09 19:29 - 2017-04-27 20:11 - 06312448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Search.dll
2017-05-09 19:29 - 2017-04-27 20:09 - 13393920 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2017-05-09 19:29 - 2017-04-27 20:08 - 03993600 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2017-05-09 19:29 - 2017-04-27 20:06 - 12139008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2017-05-09 19:29 - 2017-04-27 20:05 - 24605184 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2017-05-09 19:29 - 2017-04-27 20:04 - 19344896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2017-05-09 19:29 - 2017-04-27 20:04 - 03660288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2017-05-09 19:29 - 2017-04-27 20:04 - 00459776 _____ (Microsoft Corporation) C:\WINDOWS\system32\certcli.dll
2017-05-09 19:29 - 2017-04-27 20:03 - 18673152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2017-05-09 19:29 - 2017-04-27 19:57 - 04171264 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcorets.dll
2017-05-09 19:29 - 2017-04-27 19:53 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\system32\wksprtPS.dll
2017-05-09 19:29 - 2017-04-27 19:50 - 07853568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2017-05-09 19:29 - 2017-04-27 19:47 - 05670912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2017-05-09 19:29 - 2017-04-27 19:45 - 01087488 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll
2017-05-03 16:43 - 2017-05-03 16:43 - 11084751 _____ C:\Users\JanLar\Documents\kx-tge260_mul_omphone.pdf
2017-05-03 11:49 - 2017-05-03 11:49 - 00000000 ____D C:\ProgramData\SupportAssistAgent
2017-04-30 10:02 - 2017-04-30 10:02 - 00002207 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Belarc Advisor.lnk
2017-04-30 10:02 - 2017-04-30 10:02 - 00002195 _____ C:\Users\Public\Desktop\Belarc Advisor.lnk
2017-04-30 10:02 - 2017-04-30 10:02 - 00000000 ____D C:\Program Files (x86)\Belarc

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-05-30 10:25 - 2015-12-16 09:53 - 01011572 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2017-05-30 10:25 - 2015-10-30 03:21 - 00000000 ____D C:\WINDOWS\INF
2017-05-30 10:23 - 2013-04-01 00:04 - 00000000 ____D C:\Program Files (x86)\i2p
2017-05-30 10:22 - 2015-09-23 23:38 - 00000000 ___RD C:\Users\JanLar\OneDrive
2017-05-30 10:21 - 2015-12-16 10:05 - 00000000 ____D C:\Users\Default\AppData\Local\SoftThinks
2017-05-30 10:21 - 2015-12-16 10:05 - 00000000 ____D C:\Users\Default User\AppData\Local\SoftThinks
2017-05-30 10:21 - 2012-06-13 18:54 - 00000000 ____D C:\Program Files (x86)\Dell DataSafe Local Backup
2017-05-30 10:20 - 2015-03-08 18:17 - 00000000 ____D C:\Program Files (x86)\TeamViewer
2017-05-30 10:20 - 2014-06-06 22:52 - 00000374 _____ C:\WINDOWS\system32\Drivers\etc\hosts.ics
2017-05-30 10:20 - 2012-11-13 19:22 - 00000894 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2017-05-30 10:19 - 2015-12-16 10:21 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2017-05-30 10:19 - 2012-06-13 18:48 - 00000828 _____ C:\WINDOWS\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job
2017-05-30 09:14 - 2017-04-13 17:14 - 00000941 _____ C:\WINDOWS\Tasks\EPSON WF-3640 Series Update {D042F190-4C35-4B21-BA70-4271F8C782B7}.job
2017-05-30 09:14 - 2017-04-13 17:14 - 00000755 _____ C:\WINDOWS\Tasks\EPSON WF-3640 Series Invitation {D042F190-4C35-4B21-BA70-4271F8C782B7}.job
2017-05-30 09:02 - 2017-04-28 21:02 - 00000941 _____ C:\WINDOWS\Tasks\EPSON WF-3640 Series Update {84DC0834-2CD0-41C2-8250-2D541D7A37B1}.job
2017-05-30 09:02 - 2017-04-28 21:02 - 00000755 _____ C:\WINDOWS\Tasks\EPSON WF-3640 Series Invitation {84DC0834-2CD0-41C2-8250-2D541D7A37B1}.job
2017-05-30 08:47 - 2012-10-01 15:34 - 00000000 ____D C:\Users\JanLar\AppData\Local\CrashDumps
2017-05-30 08:25 - 2015-09-23 23:24 - 00004158 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{8CB184FC-B82B-44D2-8611-DA114F42895D}
2017-05-30 08:25 - 2013-05-20 22:12 - 00000000 ____D C:\ProgramData\boost_interprocess
2017-05-30 08:24 - 2014-08-17 23:00 - 00251832 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2017-05-30 08:23 - 2012-09-30 22:02 - 00000000 ____D C:\Users\JanLar\AppData\Local\Adobe
2017-05-29 22:50 - 2015-12-16 12:42 - 00000000 ___DC C:\WINDOWS\Panther
2017-05-29 21:33 - 2012-09-30 20:29 - 00000000 ____D C:\Users\JanLar\Documents\Outlook Files
2017-05-29 19:12 - 2015-12-16 09:54 - 00000000 ____D C:\Users\JanLar
2017-05-29 19:00 - 2014-10-19 09:49 - 00000860 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1949060236-814623403-1790243873-1000Core1cfeba38a718c08.job
2017-05-29 18:55 - 2013-01-18 20:29 - 00000000 ____D C:\ProgramData\Malwarebytes
2017-05-29 18:53 - 2015-10-30 03:24 - 00000000 ____D C:\WINDOWS\AppReadiness
2017-05-29 18:37 - 2015-10-30 02:28 - 00786432 ___SH C:\WINDOWS\system32\config\BBI
2017-05-29 18:16 - 2012-10-03 19:14 - 00000000 ____D C:\WINDOWS\system32\appmgmt
2017-05-29 17:17 - 2014-01-01 00:03 - 00000000 ____D C:\Program Files (x86)\McAfee
2017-05-29 17:15 - 2015-10-30 03:24 - 00000000 ____D C:\WINDOWS\ModemLogs
2017-05-29 13:27 - 2015-10-30 02:28 - 00032768 ___SH C:\WINDOWS\system32\config\ELAM
2017-05-29 13:24 - 2015-10-30 03:24 - 00000000 ____D C:\WINDOWS\system32\NDF
2017-05-29 08:24 - 2012-10-01 07:33 - 00000000 ____D C:\Users\JanLar\AppData\Roaming\Roxio
2017-05-29 08:24 - 2012-10-01 07:22 - 00000000 ____D C:\ProgramData\Roxio
2017-05-28 18:38 - 2012-06-13 18:48 - 00000830 _____ C:\WINDOWS\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job
2017-05-28 09:54 - 2014-07-18 20:44 - 00000860 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1949060236-814623403-1790243873-1000Core.job
2017-05-27 23:24 - 2015-10-30 03:24 - 00000000 ___HD C:\Program Files\WindowsApps
2017-05-27 02:11 - 2014-11-13 19:55 - 00000860 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1949060236-814623403-1790243873-1000Core1cfff9d42bcb571.job
2017-05-25 10:09 - 2017-04-15 20:06 - 00003126 _____ C:\WINDOWS\System32\Tasks\McAfeeLogon
2017-05-25 10:09 - 2017-04-15 20:06 - 00000000 ____D C:\WINDOWS\System32\Tasks\McAfee
2017-05-25 10:09 - 2015-10-30 03:24 - 00000000 ___HD C:\WINDOWS\ELAMBKUP
2017-05-25 10:09 - 2012-06-13 19:04 - 00000000 ____D C:\Program Files\Common Files\mcafee
2017-05-24 17:40 - 2015-11-10 23:19 - 00000000 ____D C:\Program Files\McAfee Security Scan
2017-05-24 17:40 - 2013-11-20 20:25 - 00002011 _____ C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk
2017-05-23 13:32 - 2013-08-15 02:06 - 00000000 ____D C:\WINDOWS\system32\MRT
2017-05-23 13:29 - 2012-10-02 23:06 - 132223576 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2017-05-20 13:48 - 2012-11-22 01:16 - 00000000 ____D C:\Program Files (x86)\Java
2017-05-19 18:50 - 2015-02-10 14:04 - 00000000 ____D C:\Program Files\Dell
2017-05-15 21:48 - 2012-11-13 19:23 - 00002274 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-05-15 21:48 - 2012-11-13 19:23 - 00002262 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2017-05-14 21:07 - 2012-12-08 15:57 - 00001364 _____ C:\Users\Public\Desktop\YTD Video Downloader.lnk
2017-05-14 21:07 - 2012-12-08 15:57 - 00000000 ____D C:\ProgramData\YTD Video Downloader
2017-05-11 15:14 - 2015-10-30 03:24 - 00000000 ____D C:\WINDOWS\rescache
2017-05-11 07:16 - 2015-03-20 07:14 - 00097856 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll
2017-05-11 07:16 - 2015-03-20 07:14 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2017-05-10 21:08 - 2015-10-30 03:24 - 00000000 ____D C:\WINDOWS\SysWOW64\Macromed
2017-05-10 21:08 - 2015-10-30 03:24 - 00000000 ____D C:\WINDOWS\system32\Macromed
2017-05-10 09:01 - 2015-09-10 01:44 - 00000000 __RHD C:\Users\Public\AccountPictures
2017-05-10 09:01 - 2012-09-30 17:07 - 00000000 ___RD C:\Users\JanLar\Virtual Machines
2017-05-10 03:35 - 2015-12-16 09:44 - 00496256 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2017-05-10 03:31 - 2015-10-30 03:24 - 00000000 ___SD C:\WINDOWS\SysWOW64\F12
2017-05-10 03:31 - 2015-10-30 03:24 - 00000000 ___SD C:\WINDOWS\system32\F12
2017-05-10 03:31 - 2015-10-30 03:24 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2017-05-10 03:31 - 2015-10-30 03:24 - 00000000 ____D C:\WINDOWS\PolicyDefinitions
2017-05-10 03:31 - 2015-10-30 03:24 - 00000000 ____D C:\Program Files\Windows Photo Viewer
2017-05-10 03:31 - 2015-10-30 03:24 - 00000000 ____D C:\Program Files\Windows Defender
2017-05-10 03:31 - 2015-10-30 03:24 - 00000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2017-05-10 03:31 - 2015-10-30 03:24 - 00000000 ____D C:\Program Files (x86)\Windows Defender
2017-05-09 23:01 - 2015-09-23 23:01 - 00000000 ____D C:\Users\JanLar\AppData\Local\Packages
2017-05-09 21:16 - 2015-10-30 03:11 - 00000000 ____D C:\WINDOWS\CbsTemp
2017-05-06 16:03 - 2014-12-25 13:05 - 00004562 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task
2017-05-02 20:53 - 2014-09-07 21:32 - 00000000 ____D C:\ProgramData\PCDr

==================== Files in the root of some directories =======

2013-02-14 21:42 - 2015-06-13 18:37 - 0001057 _____ () C:\Users\JanLar\AppData\Roaming\vso_ts_preview.xml
2013-05-10 20:37 - 2013-11-12 09:15 - 0000789 _____ () C:\Users\JanLar\AppData\Local\cookies.ini
2014-06-08 00:12 - 2014-07-27 17:04 - 0005120 _____ () C:\Users\JanLar\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2013-03-27 17:52 - 2017-04-02 19:38 - 0007642 _____ () C:\Users\JanLar\AppData\Local\Resmon.ResmonCfg
2012-10-13 22:33 - 2012-10-13 22:55 - 0340268 _____ () C:\Users\JanLar\AppData\Local\rx_image32.Cache
2015-12-16 09:47 - 2015-12-16 09:47 - 0000000 ____H () C:\ProgramData\DP45977C.lfl

Files to move or delete:
====================
C:\Users\JanLar\en_res.dll
C:\Users\JanLar\es_res.dll
C:\Users\JanLar\fr_res.dll
C:\Users\JanLar\grm_res.dll
C:\Users\JanLar\it_res.dll
C:\Users\JanLar\jp_res.dll
C:\Users\JanLar\mfc80u.dll
C:\Users\JanLar\msvcr80.dll
C:\Users\JanLar\PCPE Setup.exe
C:\Users\JanLar\pt_res.dll
C:\Users\JanLar\ResourceReader.dll
C:\Users\JanLar\ru_res.dll
C:\Users\JanLar\zh_res.dll

Some files in TEMP:
====================
2016-04-27 04:02 - 2016-04-27 04:02 - 0000000 _____ () C:\Users\JanLar\AppData\Local\Temp\GUR6EAA.exe
2016-07-31 10:48 - 2016-07-31 10:48 - 0741440 _____ (Oracle Corporation) C:\Users\JanLar\AppData\Local\Temp\jre-8u101-windows-au.exe
2016-11-06 14:12 - 2016-11-06 14:12 - 0737856 _____ (Oracle Corporation) C:\Users\JanLar\AppData\Local\Temp\jre-8u111-windows-au.exe
2017-03-04 10:32 - 2017-03-04 10:32 - 0739904 _____ (Oracle Corporation) C:\Users\JanLar\AppData\Local\Temp\jre-8u121-windows-au.exe
2017-05-11 07:14 - 2017-05-11 07:14 - 0739904 _____ (Oracle Corporation) C:\Users\JanLar\AppData\Local\Temp\jre-8u131-windows-au.exe
2015-12-17 01:15 - 2015-12-17 01:15 - 0585824 _____ (Oracle Corporation) C:\Users\JanLar\AppData\Local\Temp\jre-8u66-windows-au.exe
2016-03-03 11:56 - 2016-03-03 11:56 - 0736352 _____ (Oracle Corporation) C:\Users\JanLar\AppData\Local\Temp\jre-8u73-windows-au.exe
2016-03-28 19:54 - 2016-03-28 19:54 - 0736320 _____ (Oracle Corporation) C:\Users\JanLar\AppData\Local\Temp\jre-8u77-windows-au.exe
2016-05-11 17:02 - 2016-05-11 17:02 - 0739904 _____ (Oracle Corporation) C:\Users\JanLar\AppData\Local\Temp\jre-8u91-windows-au.exe
2017-02-28 05:10 - 2017-02-28 05:10 - 0244264 _____ (McAfee, Inc.) C:\Users\JanLar\AppData\Local\Temp\McCSPInstall.dll
2016-01-30 20:15 - 2017-01-27 21:09 - 21319576 _____ (Siber Systems) C:\Users\JanLar\AppData\Local\Temp\RoboForm-Setup.exe
2017-01-14 20:50 - 2017-01-14 20:50 - 6503984 _____ (Microsoft Corporation) C:\Users\JanLar\AppData\Local\Temp\vcredist_x86.exe
2017-03-15 22:18 - 2017-03-15 22:18 - 14456872 _____ (Microsoft Corporation) C:\Users\JanLar\AppData\Local\Temp\vc_redist.x86.exe
2017-04-13 16:57 - 2006-05-24 15:10 - 0455600 ____R (Macrovision Corporation) C:\Users\JanLar\AppData\Local\Temp\_is37E6.exe
2017-04-13 13:05 - 2006-05-24 15:10 - 0455600 ____R (Macrovision Corporation) C:\Users\JanLar\AppData\Local\Temp\_isE604.exe
2016-04-05 23:29 - 2016-04-05 23:29 - 2547800 _____ (Google Inc.) C:\Users\JanLar\AppData\Local\Temp\{3FEAA32B-5A76-41EE-95F4-C824A95292DA}-49.0.2623.112_49.0.2623.110_chrome_updater.exe
2016-02-09 01:12 - 2016-02-09 01:12 - 2519960 _____ (Google Inc.) C:\Users\JanLar\AppData\Local\Temp\{4F1ECC9C-FCEB-4E43-940C-6556E90CAAAB}-48.0.2564.109_48.0.2564.103_chrome_updater.exe
2016-06-15 06:18 - 2016-06-15 06:18 - 2698328 _____ (Google Inc.) C:\Users\JanLar\AppData\Local\Temp\{58C02BD2-69EC-4225-B719-0BD998AD6B9D}-51.0.2704.103_51.0.2704.84_chrome_updater.exe
2016-02-02 20:47 - 2016-02-02 20:47 - 0852560 _____ () C:\Users\JanLar\AppData\Local\Temp\{AF4117B4-81E4-49AA-96FC-38D61122539E}-48.0.2564.103_48.0.2564.97_chrome_updater_3stage.exe
2016-02-18 01:42 - 2016-02-18 01:42 - 0879512 _____ (Google Inc.) C:\Users\JanLar\AppData\Local\Temp\{D36CE3E8-304A-4BB3-B3D8-EF698F382A9A}-48.0.2564.116_48.0.2564.109_chrome_updater.exe
2016-01-20 13:58 - 2016-01-20 13:58 - 0987728 _____ (Google Inc.) C:\Users\JanLar\AppData\Local\Temp\{D93AA117-EC7F-4938-BF10-5D23D6C4E31E}-GoogleUpdateSetup.exe
2015-12-17 17:30 - 2015-12-17 17:30 - 0532312 _____ (Google Inc.) C:\Users\JanLar\AppData\Local\Temp\{F23C3847-8802-40DE-BDB2-60C0C330DCA2}-GoogleToolbarInstaller_updater_signed.exe

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed

 

 



BC AdBot (Login to Remove)

 


#2 larry1956

larry1956
  • Topic Starter

  • Members
  • 34 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Urbana, OH
  • Local time:11:26 PM

Posted 30 May 2017 - 10:31 AM

Farbar scan tool appears to freeze up when scanning shortcuts(program not responding) but here is what is reported so far.

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 28-05-2017
Ran by JanLar (administrator) on HAL9000-PC (30-05-2017 10:21:38)
Running from C:\Users\JanLar\Desktop
Loaded Profiles: JanLar (Available Profiles: JanLar & DefaultAppPool)
Platform: Windows 10 Pro Version 1511 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(Logitech, Inc.) C:\Program Files\Common Files\logishrd\Bluetooth\LBTServ.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® ME FW Recovery Agent\bin\Bootstrap.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® ME FW Recovery Agent\bin\ismagent.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Samsung) C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\AllShareFrameworkManagerDMS.exe
(ABBYY) C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe
(Schneider Electric) C:\Program Files (x86)\APC\PowerChute Personal Edition\mainserv.exe
(Seiko Epson Corporation) C:\Windows\System32\escsvc64.exe
(CinemaNow, Inc.) C:\Program Files (x86)\CinemaNow\CinemaNow Media Manager\CinemaNowSvc.exe
() C:\Program Files (x86)\Roxio\BackOnTrack\Disaster Recovery\SaibSVC.exe
(Rockwell Automation, Inc.) C:\Program Files (x86)\Common Files\Rockwell\FTSysDiagSvcHost.exe
(SafeNet Inc.) C:\Windows\System32\hasplms.exe
(McAfee, Inc.) C:\Windows\System32\mfevtps.exe
(Tanuki Software, Ltd.) C:\Program Files (x86)\i2p\I2Psvc.exe
(SEIKO EPSON CORPORATION) C:\Program Files\EPSON\EpsonCustomerResearchParticipation\EPCP.exe
(Intel® Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
() C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe
(LeapFrog Enterprises, Inc.) C:\Program Files (x86)\LeapFrog\LeapFrog Connect\CommandService.exe
(Rockwell Automation, Inc.) C:\Program Files (x86)\Common Files\Rockwell\RdcyHost.exe
(Rockwell Automation, Inc.) C:\Program Files (x86)\Common Files\Rockwell\NmspHost.exe
(Rockwell Automation Inc.) C:\Program Files (x86)\Common Files\Rockwell\RNADiagnosticsSrv.exe
(Intel Security, Inc.) C:\Program Files\Common Files\Intel Security\PEF\CORE\PEFService.exe
(Microsoft Corporation) C:\Windows\System32\mqsvc.exe
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\SystemCore\mfemms.exe
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\ModuleCore\ModuleCoreService.exe
(Copyright 2013 SAMSUNG) C:\Program Files\Samsung\Samsung Link\Samsung Link.exe
(SoftThinks SAS) C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe
(Skype Technologies) C:\Program Files (x86)\Skype\Updater\Updater.exe
(Rockwell Automation, Inc.) C:\Program Files (x86)\Common Files\Rockwell\RsvcHost.exe
(Atheros) C:\Program Files (x86)\Dell Wireless\Ath_WlanAgent.exe
(Atheros) C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\Ath_CoexAgent.exe
(Samsung) C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\AllShareFrameworkDMS.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Copyright 2013 SAMSUNG) C:\Program Files\Samsung\Samsung Link\Samsung Link.exe
(Schneider Electric) C:\Program Files (x86)\APC\PowerChute Personal Edition\dataserv.exe
(Rockwell Automation, Inc.) C:\Program Files (x86)\Common Files\Rockwell\EventServer.exe
(McAfee, Inc.) C:\Windows\System32\mfevtps.exe
(Atheros Commnucations) C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\AthBtTray.exe
(Oracle Corporation) C:\ProgramData\Oracle\Java\javapath_target_757593\java.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Rockwell Automation, Inc.) C:\Program Files (x86)\Common Files\Rockwell\EventClientMultiplexer.exe
(Rockwell Automation, Inc.) C:\Program Files (x86)\Common Files\Rockwell\RnaDirServer.exe
(Rockwell Automation, Inc.) C:\Program Files (x86)\Common Files\Rockwell\RNADirMultiplexor.exe
(Microsoft Corporation) C:\Windows\System32\alg.exe
(Microsoft Corporation) C:\Windows\System32\drvinst.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\SystemCore\mfefire.exe
(SoftThinks - Dell) C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe
(SoftThinks - Dell) C:\Program Files (x86)\Dell DataSafe Local Backup\Toaster.exe
(Copyright 2013 SAMSUNG) C:\Program Files\Samsung\Samsung Link\Samsung Link Tray Agent.exe
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\Platform\McSvcHost\McSvHost.exe
() C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe
(Logitech, Inc.) C:\Program Files\Logitech\SetPointP\SetPoint.exe
(Logitech, Inc.) C:\Program Files\Logitech\SetPointP\LBTWiz.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_w32.exe
(SoftThinks) C:\Program Files (x86)\Dell DataSafe Local Backup\SetMUILanguage.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_x64.exe
(Logitech Inc.) C:\Program Files (x86)\Logitech\Vid HD\Vid.exe

==================== Registry (Whitelisted) ====================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8512760 2015-08-04] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1411320 2015-08-04] (Realtek Semiconductor)
HKLM\...\Run: [AthBtTray] => C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\AthBtTray.exe [800416 2011-12-29] (Atheros Commnucations)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [472984 2013-09-25] (Adobe Systems Incorporated)
HKLM\...\Run: [Samsung Link] => C:\Program Files\Samsung\Samsung Link\Samsung Link Tray Agent.exe [607584 2015-03-18] (Copyright 2013 SAMSUNG)
HKLM\...\Run: [EvtMgr6] => C:\Program Files\Logitech\SetPointP\SetPoint.exe [3113592 2015-08-25] (Logitech, Inc.)
HKLM\...\Run: [Bluetooth Connection Assistant] => LBTWIZ.EXE -silent
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-02-17] (Intel Corporation)
HKLM-x32\...\Run: [ShwiconXP9106] => C:\Program Files (x86)\Multimedia Card Reader(9106)\ShwiconXP9106.exe [237568 2010-03-10] (Alcor Micro Corp.)
HKLM-x32\...\Run: [mcui_exe] => C:\Program Files\McAfee.com\Agent\mcagent.exe [557344 2017-04-17] (McAfee, Inc.)
HKLM-x32\...\Run: [Adobe Acrobat Speed Launcher] => C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe [44128 2013-05-08] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe [642664 2013-05-08] (Adobe Systems Inc.)
HKLM-x32\...\Run: [LWS] => C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe [205336 2011-11-11] (Logitech Inc.)
HKLM-x32\...\Run: [RoxWatchTray] => C:\Program Files (x86)\Common Files\Roxio Shared\12.0\SharedCOM\RoxWatchTray12.exe [240112 2009-07-24] (Sonic Solutions)
HKLM-x32\...\Run: [CPMonitor] => C:\Program Files (x86)\Roxio 2010\5.0\CPMonitor.exe [84464 2009-07-21] ()
HKLM-x32\...\Run: [Desktop Disc Tool] => C:\Program Files (x86)\Roxio 2010\Roxio Burn\RoxioBurnLauncher.exe [494064 2009-06-23] ()
HKLM-x32\...\Run: [Monitor] => C:\Program Files (x86)\LeapFrog\LeapFrog Connect\Monitor.exe [118272 2014-07-11] (LeapFrog Enterprises, Inc.)
HKLM-x32\...\Run: [ScanSnap WIA Service Checker] => C:\Windows\SSDriver\fi5110\SsWiaChecker.exe [86016 2009-09-30] (PFU LIMITED)
HKLM-x32\...\Run: [AgentMonitor] => C:\Program Files (x86)\VTech\DownloadManager\System\AgentMonitor.exe [391040 2013-06-20] ()
HKLM-x32\...\Run: [FUFAXRCV] => C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXRCV.exe [653352 2017-03-02] (SEIKO EPSON CORPORATION)
HKLM-x32\...\Run: [FUFAXSTM] => C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe [862248 2017-03-02] (SEIKO EPSON CORPORATION)
HKLM-x32\...\Run: [LTCM Client] => C:\Program Files (x86)\LTCM Client\ltcmClient.exe [2756864 2011-04-07] (Leader Technologies Inc.)
HKLM-x32\...\Run: [Adobe Creative Cloud] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2237328 2013-11-05] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [UsbCipHelper] => C:\Program Files (x86)\Rockwell Automation\UsbCipDriver\UsbCipHelper\UsbCipHelper.exe [434176 2011-10-18] (Rockwell Automation, Inc.)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [AllShareAgent] => C:\Program Files (x86)\Samsung\AllShare\AllShareAgent.exe [285072 2012-03-01] (Samsung Electronics Co., Ltd.)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [767176 2015-08-21] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [Display] => C:\Program Files (x86)\APC\PowerChute Personal Edition\DataCollectionLauncher.exe [284024 2012-01-24] (Schneider Electric)
HKLM-x32\...\Run: [Avira SystrayStartTrigger] => "C:\Program Files (x86)\Avira\Launcher\Avira.SystrayStartTrigger.exe"
HKLM-x32\...\Run: [EEventManager] => C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe [1087184 2016-01-20] (SEIKO EPSON CORPORATION)
HKLM-x32\...\Run: [SoundTouch Music Server] => C:\Program Files (x86)\SoundTouch\SoundTouchMusicServer\SoundTouch Music Server.lnk [2193 2017-04-28] ()
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2017-03-15] (Oracle Corporation)
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
HKU\S-1-5-21-1949060236-814623403-1790243873-1000\...\Run: [Logitech Vid] => C:\Program Files (x86)\Logitech\Vid HD\Vid.exe [6129496 2011-01-12] (Logitech Inc.)
HKU\S-1-5-21-1949060236-814623403-1790243873-1000\...\Run: [CAHeadless] => C:\Program Files (x86)\Adobe\Elements 11 Organizer\CAHeadless\ElementsAutoAnalyzer.exe [840784 2012-09-23] (Adobe Systems Incorporated)
HKU\S-1-5-21-1949060236-814623403-1790243873-1000\...\Run: [Google Update] => C:\Users\JanLar\AppData\Local\Google\Update\1.3.33.5\GoogleUpdateCore.exe [601168 2017-04-28] (Google Inc.)
HKU\S-1-5-21-1949060236-814623403-1790243873-1000\...\Run: [QuickenScheduledUpdates] => C:\Program Files (x86)\Quicken\bagent.exe [77248 2016-04-12] (Intuit Inc.)
HKU\S-1-5-21-1949060236-814623403-1790243873-1000\...\Run: [EPLTarget\P0000000000000001] => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YATIKDE.EXE [298560 2013-09-12] (SEIKO EPSON CORPORATION)
HKU\S-1-5-21-1949060236-814623403-1790243873-1000\...\Run: [RoboForm] => C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe [110376 2017-04-19] (Siber Systems)
HKU\S-1-5-21-1949060236-814623403-1790243873-1000\...\Run: [EPLTarget\P0000000000000000] => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YATIKDE.EXE [298560 2013-09-12] (SEIKO EPSON CORPORATION)
HKU\S-1-5-21-1949060236-814623403-1790243873-1000\...\RunOnce: [Uninstall C:\Users\JanLar\AppData\Local\Microsoft\OneDrive\17.3.6281.1202_1\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\JanLar\AppData\Local\Microsoft\OneDrive\17.3.6281.1202_1\amd64"
HKU\S-1-5-18\...\Run: [EPLTarget\P0000000000000000] => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YATIIUE.EXE [283232 2012-02-28] (SEIKO EPSON CORPORATION)
ShellIconOverlayIdentifiers: [ AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll [2013-10-16] ()
ShellIconOverlayIdentifiers: [ AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll [2013-10-16] ()
ShellIconOverlayIdentifiers: [ AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync_x64.dll [2013-10-16] ()
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  -> No File
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  -> No File
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\APC UPS Status.lnk [2016-03-14]
ShortcutTarget: APC UPS Status.lnk -> C:\Program Files (x86)\APC\PowerChute Personal Edition\Display.exe (Schneider Electric)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\CardMinder Viewer.lnk [2012-10-01]
ShortcutTarget: CardMinder Viewer.lnk -> C:\Program Files (x86)\PFU\ScanSnap\CardMinder\CardLauncher.exe (PFU LIMITED)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Conversion to PDF with ScanSnap Organizer.lnk [2013-03-20]
ShortcutTarget: Conversion to PDF with ScanSnap Organizer.lnk -> C:\Program Files (x86)\PFU\ScanSnap\Organizer\PfuSsOrgOcrChk.exe (PFU LIMITED)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2017-05-24]
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.11.561\SSScheduler.exe (McAfee, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ScanSnap Manager.lnk [2013-03-28]
ShortcutTarget: ScanSnap Manager.lnk -> C:\Program Files (x86)\PFU\ScanSnap\Driver\PfuSsMon.exe (PFU LIMITED)
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

ProxyServer: [S-1-5-21-1949060236-814623403-1790243873-1000] => http=127.0.0.1:4444;https=127.0.0.1:4445
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 209.18.47.61 209.18.47.62
Tcpip\..\Interfaces\{0C3DFCD4-940A-45F4-B90D-2853CC94F22A}: [DhcpNameServer] 8.8.8.8 8.8.4.4
Tcpip\..\Interfaces\{1307b17c-24f1-458a-8bce-8f158e96b1f2}: [DhcpNameServer] 209.222.18.222 209.222.18.218
Tcpip\..\Interfaces\{2fc00daf-03c4-4a1e-a41d-c34fd78f67a9}: [DhcpNameServer] 209.18.47.61 209.18.47.62
Tcpip\..\Interfaces\{98f6215d-beac-4f36-9c27-6ed24f183f9e}: [DhcpNameServer] 209.18.47.61 209.18.47.62

Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-1949060236-814623403-1790243873-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-1949060236-814623403-1790243873-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-1949060236-814623403-1790243873-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.com/?gws_rd=ssl
SearchScopes: HKLM -> DefaultScope {3BE5F7D1-E755-403B-A190-4D9348671630} URL =
SearchScopes: HKLM -> {5e7797ae-5ca1-4b50-95d8-97e746340487} URL = hxxp://www.bing.com/search?q={searchTerms}&form=DLCDF8&pc=MDDR&src=IE-SearchBox
SearchScopes: HKLM-x32 -> DefaultScope {3BE5F7D1-E755-403B-A190-4D9348671630} URL =
SearchScopes: HKLM-x32 -> {5e7797ae-5ca1-4b50-95d8-97e746340487} URL = hxxp://www.bing.com/search?q={searchTerms}&form=DLCDF8&pc=MDDR&src=IE-SearchBox
SearchScopes: HKU\.DEFAULT -> DefaultScope {3BE5F7D1-E755-403B-A190-4D9348671630} URL = hxxp://www.bing.com/search?q={searchTerms}&form=DLCDF8&pc=MDDR&src=IE-SearchBox
SearchScopes: HKU\.DEFAULT -> {3BE5F7D1-E755-403B-A190-4D9348671630} URL = hxxp://www.bing.com/search?q={searchTerms}&form=DLCDF8&pc=MDDR&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-1949060236-814623403-1790243873-1000 -> DefaultScope {A99F3C38-B642-4C66-9CDD-6C7843B96F16} URL = hxxps://search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=715483&p={searchTerms}
SearchScopes: HKU\S-1-5-21-1949060236-814623403-1790243873-1000 -> {3BE5F7D1-E755-403B-A190-4D9348671630} URL =
SearchScopes: HKU\S-1-5-21-1949060236-814623403-1790243873-1000 -> {5e7797ae-5ca1-4b50-95d8-97e746340487} URL =
SearchScopes: HKU\S-1-5-21-1949060236-814623403-1790243873-1000 -> {83C74302-D737-4E56-9D3F-C55F4D917B18} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-1949060236-814623403-1790243873-1000 -> {A99F3C38-B642-4C66-9CDD-6C7843B96F16} URL = hxxps://search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=715483&p={searchTerms}
BHO: RoboForm Toolbar Helper -> {724d43a9-0d85-11d4-9908-00400523e39a} -> C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll [2017-04-19] (Siber Systems Inc.)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-12-15] (Google Inc.)
BHO: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll [2015-08-25] (Logitech, Inc.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: E-Web Print -> {201CF130-E29C-4E5C-A73F-CD197DEFA6AE} -> C:\Program Files (x86)\Epson Software\E-Web Print\ewps_tb.dll [2014-11-27] (SEIKO EPSON CORPORATION)
BHO-x32: RoboForm Toolbar Helper -> {724d43a9-0d85-11d4-9908-00400523e39a} -> C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll [2017-04-19] (Siber Systems Inc.)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_131\bin\ssv.dll [2017-05-11] (Oracle Corporation)
BHO-x32: CIESpeechBHO Class -> {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} -> C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\IEPlugIn.dll [2011-12-29] (Atheros Commnucations)
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2016-12-15] (Google Inc.)
BHO-x32: Adobe PDF Conversion Toolbar Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2013-05-08] (Adobe Systems Incorporated)
BHO-x32: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll [2015-08-25] (Logitech, Inc.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_131\bin\jp2ssv.dll [2017-05-11] (Oracle Corporation)
BHO-x32: SmartSelect Class -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2013-05-08] (Adobe Systems Incorporated)
Toolbar: HKLM - &RoboForm Toolbar - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll [2017-04-19] (Siber Systems Inc.)
Toolbar: HKLM - Vuze Remote Toolbar - {05478A66-EDB6-4A22-A870-A5987F80A7DA} - C:\Program Files (x86)\Vuze Remote Toolbar\IE\8.6\vuzeToolbarIE64.dll No File
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-12-15] (Google Inc.)
Toolbar: HKLM-x32 - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2013-05-08] (Adobe Systems Incorporated)
Toolbar: HKLM-x32 - &RoboForm Toolbar - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll [2017-04-19] (Siber Systems Inc.)
Toolbar: HKLM-x32 - E-Web Print - {201CF130-E29C-4E5C-A73F-CD197DEFA6AE} - C:\Program Files (x86)\Epson Software\E-Web Print\ewps_tb.dll [2014-11-27] (SEIKO EPSON CORPORATION)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2016-12-15] (Google Inc.)
Toolbar: HKU\.DEFAULT -> No Name - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} -  No File
Toolbar: HKU\.DEFAULT -> No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} -  No File
Toolbar: HKU\.DEFAULT -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-12-15] (Google Inc.)
Toolbar: HKU\.DEFAULT -> &RoboForm Toolbar - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll [2017-04-19] (Siber Systems Inc.)
Toolbar: HKU\S-1-5-21-1949060236-814623403-1790243873-1000 -> No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} -  No File
Toolbar: HKU\S-1-5-21-1949060236-814623403-1790243873-1000 -> No Name - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} -  No File
Toolbar: HKU\S-1-5-21-1949060236-814623403-1790243873-1000 -> &RoboForm Toolbar - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll [2017-04-19] (Siber Systems Inc.)
DPF: HKLM-x32 {17492023-C23A-453E-A040-C7C580BBF700} hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
DPF: HKLM-x32 {FFAD8DA9-ED41-494D-AC8E-63D861D0A733} hxxps://download.rockwellautomation.com/plugins/rockwell.cab
Handler-x32: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files (x86)\Belarc\BelarcAdvisor\System\BAVoilaX.dll [2016-01-04] (Belarc, Inc.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2017-01-01] (Skype Technologies)
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\mcafee\MSC\McSnIePl64.dll [2017-04-17] (McAfee, Inc.)
Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\MSC\McSnIePl.dll [2017-04-17] (McAfee, Inc.)

FireFox:
========
FF ProfilePath: C:\Users\JanLar\AppData\Roaming\Mozilla\Firefox\Profiles\ou0umi33.default [2017-05-24]
FF SelectedSearchEngine: Mozilla\Firefox\Profiles\ou0umi33.default -> Palikan
FF NetworkProxy: Mozilla\Firefox\Profiles\ou0umi33.default -> http_port", 4444
FF DefaultSearchEngine: Mozilla\Firefox\Profiles\ou0umi33.default -> Palikan
FF NewTab: Mozilla\Firefox\Profiles\ou0umi33.default -> about:newtab
FF NetworkProxy: Mozilla\Firefox\Profiles\ou0umi33.default -> http", "127.0.0.1"
FF NetworkProxy: Mozilla\Firefox\Profiles\ou0umi33.default -> socks_version", 4
FF NetworkProxy: Mozilla\Firefox\Profiles\ou0umi33.default -> ssl", "172.0.0.1"
FF NetworkProxy: Mozilla\Firefox\Profiles\ou0umi33.default -> ssl_port", 4445
FF NetworkProxy: Mozilla\Firefox\Profiles\ou0umi33.default -> type", 0
FF Homepage: Mozilla\Firefox\Profiles\ou0umi33.default -> hxxps://www.malwarebytes.org/restorebrowser//?f=1&a=plk_coinisre_17_02&cd=2XzuyEtN2Y1L1Qzu0EtDtDyC0EyCyB0FtAyCtBtB0DtAtA0FtN0D0Tzu0StCzzyEtDtN1L2XzutAtFtByEtFtCtAtFyDyEtN1L1Czu1ByCtN1L1G1B1V1N2Y1L1Qzu2StByDtBtAyDtAtD0CtGtA0FyDyCtGtBzz0FtBtGtDyBtAyBtGyB0BtCtCtBzztC0A0A0FyD0A2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0EtD0F0FyBtDtCtAtG0DtByCzytGyE0F0AtBtG0A0BtAtBtGtBtCtBzy0BtD0CyByBtDyCzz2QtN0A0LzutB&cr=1791041131&ir=
FF Keyword.URL: Mozilla\Firefox\Profiles\ou0umi33.default -> user_pref("keyword.URL", true);
FF HKLM-x32\...\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt
FF Extension: (Logitech SetPoint) - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt [2016-08-21] [not signed]
FF HKLM-x32\...\Firefox\Extensions: [e-webprint@epson.com] - C:\Program Files (x86)\Epson Software\E-Web Print\Firefox Add-on
FF Extension: (E-Web Print) - C:\Program Files (x86)\Epson Software\E-Web Print\Firefox Add-on [2016-05-11] [not signed]
FF HKLM-x32\...\Firefox\Extensions: [{22119944-ED35-4ab1-910B-E619EA06A115}] - C:\Program Files (x86)\Siber Systems\AI RoboForm\Firefox\roboform.xpi
FF Extension: (RoboForm Toolbar) - C:\Program Files (x86)\Siber Systems\AI RoboForm\Firefox\roboform.xpi [2017-04-19]
FF HKU\S-1-5-21-1949060236-814623403-1790243873-1000\...\Firefox\Extensions: [{22119944-ED35-4ab1-910B-E619EA06A115}] - C:\Program Files (x86)\Siber Systems\AI RoboForm\Firefox\roboform.xpi
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_25_0_0_171.dll [2017-05-10] ()
FF Plugin: @mcafee.com/MSC,version=10 -> c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL [2017-04-17] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50906.0\npctrl.dll [2017-03-09] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2013-11-05] (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_25_0_0_171.dll [2017-05-10] ()
FF Plugin-x32: @java.com/DTPlugin,version=11.131.2 -> C:\Program Files (x86)\Java\jre1.8.0_131\bin\dtplugin\npDeployJava1.dll [2017-05-11] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.131.2 -> C:\Program Files (x86)\Java\jre1.8.0_131\bin\plugin2\npjp2.dll [2017-05-11] (Oracle Corporation)
FF Plugin-x32: @mcafee.com/MSC,version=10 -> c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL [2017-04-17] ()
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\npctrl.dll [2017-03-09] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin-x32: @nosltd.com/getPlus+®,version=2.0.7.35 -> C:\Program Files (x86)\NOS\bin\nprockwell.dll [2013-08-12] (NOS Microsystems Ltd.)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-28] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-28] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.0 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: Adobe Acrobat -> C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Air\nppdf32.dll [2013-05-08] (Adobe Systems Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-04-04] (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2013-11-05] (Adobe Systems)
FF Plugin HKU\S-1-5-21-1949060236-814623403-1790243873-1000: @talk.google.com/GoogleTalkPlugin -> C:\Users\JanLar\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll [2015-12-08] (Google)
FF Plugin HKU\S-1-5-21-1949060236-814623403-1790243873-1000: @talk.google.com/O1DPlugin -> C:\Users\JanLar\AppData\Roaming\Mozilla\plugins\npo1d.dll [2015-12-08] (Google)
FF Plugin HKU\S-1-5-21-1949060236-814623403-1790243873-1000: @tools.google.com/Google Update;version=3 -> C:\Users\JanLar\AppData\Local\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-28] (Google Inc.)
FF Plugin HKU\S-1-5-21-1949060236-814623403-1790243873-1000: @tools.google.com/Google Update;version=9 -> C:\Users\JanLar\AppData\Local\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-28] (Google Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\JanLar\AppData\Roaming\mozilla\plugins\npgoogletalk.dll [2015-12-08] (Google)
FF Plugin ProgramFiles/Appdata: C:\Users\JanLar\AppData\Roaming\mozilla\plugins\npo1d.dll [2015-12-08] (Google)

Chrome:
=======
CHR DefaultProfile: Default
CHR HomePage: Default -> hxxps://www.google.com//?type=715483&fr=yo-yhp-ch
CHR StartupUrls: Default -> "hxxps://search.yahoo.com/?type=715483&fr=yo-yhp-ch",null,null,null,null,null,"hxxp://start.roboform.com"
CHR NewTab: Default ->  Active:"chrome-extension://jdcikeehjpacoeddlgdhkcnkcmcchegc/ntp/newtab.html"
CHR Profile: C:\Users\JanLar\AppData\Local\Google\Chrome\User Data\Default [2017-05-29]
CHR Extension: (Google Drive) - C:\Users\JanLar\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-08-21]
CHR Extension: (YouTube) - C:\Users\JanLar\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-24]
CHR Extension: (Google Search) - C:\Users\JanLar\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2016-02-20]
CHR Extension: (Logitech Smooth Scrolling) - C:\Users\JanLar\AppData\Local\Google\Chrome\User Data\Default\Extensions\dkpejdfnpdkhifgbancbammdijojoffk [2015-04-01]
CHR Extension: (Google Docs Offline) - C:\Users\JanLar\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-08-21]
CHR Extension: (New Tab Helper 52) - C:\Users\JanLar\AppData\Local\Google\Chrome\User Data\Default\Extensions\jdcikeehjpacoeddlgdhkcnkcmcchegc [2016-05-21]
CHR Extension: (Shopping Assistant 52) - C:\Users\JanLar\AppData\Local\Google\Chrome\User Data\Default\Extensions\jnaommnffgbanfoeolebgkjikdjhpkfn [2016-05-21]
CHR Extension: (Skype) - C:\Users\JanLar\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2017-04-10]
CHR Extension: (Chrome Web Store Payments) - C:\Users\JanLar\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-04-10]
CHR Extension: (Gmail) - C:\Users\JanLar\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-04-01]
CHR Extension: (Chrome Media Router) - C:\Users\JanLar\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-04-10]
CHR Extension: (RoboForm Password Manager) - C:\Users\JanLar\AppData\Local\Google\Chrome\User Data\Default\Extensions\pnlccmojcmeohlpggmfnbbiapkmbliob [2017-05-29]
CHR HKLM\...\Chrome\Extension: [pnlccmojcmeohlpggmfnbbiapkmbliob] - C:\Program Files (x86)\Siber Systems\AI RoboForm\Chrome\rf-chrome.crx [2014-04-19]
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [pnlccmojcmeohlpggmfnbbiapkmbliob] - C:\Program Files (x86)\Siber Systems\AI RoboForm\Chrome\rf-chrome.crx [2014-04-19]

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 9734BF6A-2DCD-40f0-BAB0-5AAFEEBE1269; C:\Program Files (x86)\Roxio\BackOnTrack\Disaster Recovery\SaibSVC.exe [457200 2009-06-02] ()
R2 ABBYY.Licensing.FineReader.Sprint.9.0; C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [759048 2009-05-14] (ABBYY)
U2 AdobeActiveFileMonitor11.0; C:\Program Files (x86)\Adobe\Elements 11 Organizer\PhotoshopElementsFileAgent.exe [171600 2012-09-23] (Adobe Systems Incorporated)
R2 AllShare Framework DMS; C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\AllShareFrameworkManagerDMS.exe [404360 2013-12-21] (Samsung) [File not signed]
R2 APC Data Service; C:\Program Files (x86)\APC\PowerChute Personal Edition\dataserv.exe [21880 2012-01-24] (Schneider Electric)
R2 APC UPS Service; C:\Program Files (x86)\APC\PowerChute Personal Edition\mainserv.exe [705912 2012-01-24] (Schneider Electric)
S3 ClientAnalyticsService; C:\Program Files\Common Files\McAfee\ClientAnalytics\Legacy\McClientAnalytics.exe [1752992 2017-03-29] (Intel Security)
S2 Dell Customer Connect; C:\Program Files (x86)\Dell Customer Connect\DCCService.exe [130936 2016-12-21] (Dell Inc.)
S2 DellDataVault; C:\Program Files\Dell\DellDataVault\DellDataVault.exe [2572024 2016-06-23] (Dell Inc.)
S2 DellUpdate; C:\Program Files (x86)\Dell Update\DellUpService.exe [237272 2015-08-27] (Dell Inc.)
S3 dnWhoDisp; C:\Program Files (x86)\Rockwell Software\RSLINX\dnwhodisp.exe [167936 2012-10-31] (Rockwell Automation, Inc.) [File not signed]
R2 EpsonCustomerResearchParticipation; C:\Program Files\EPSON\EpsonCustomerResearchParticipation\EPCP.exe [677880 2017-05-29] (SEIKO EPSON CORPORATION)
R2 EpsonScanSvc; C:\WINDOWS\system32\EscSvc64.exe [144560 2012-05-17] (Seiko Epson Corporation)
S3 FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [651720 2012-09-30] (Macrovision Europe Ltd.) [File not signed]
R2 FTSysDiagSvcHost; C:\Program Files (x86)\Common Files\Rockwell\FTSysDiagSvcHost.exe [69120 2012-12-17] (Rockwell Automation, Inc.) [File not signed]
R2 hasplms; C:\Windows\system32\hasplms.exe [4412872 2012-08-22] (SafeNet Inc.)
R2 HomeNetSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [641520 2017-02-22] (McAfee, Inc.)
R2 i2p; C:\Program Files (x86)\i2p\I2Psvc.exe [384000 2013-04-01] (Tanuki Software, Ltd.) [File not signed]
S3 ImDskSvc; C:\Windows\system32\imdsksvc.exe [11264 2011-03-11] (Olof Lagerkvist) [File not signed]
R2 Intel® ME Service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe [128280 2012-01-21] ()
R2 LeapFrog Connect Device Service; C:\Program Files (x86)\LeapFrog\LeapFrog Connect\CommandService.exe [7241728 2014-07-11] (LeapFrog Enterprises, Inc.) [File not signed]
S3 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4470736 2017-05-09] (Malwarebytes)
R2 McAPExe; C:\Program Files\Common Files\McAfee\VSCore_15_6\McApExe.exe [994312 2017-04-04] (McAfee, Inc.)
R2 McBootDelayStartSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [641520 2017-02-22] (McAfee, Inc.)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.11.561\McCHSvc.exe [404368 2017-05-16] (McAfee, Inc.)
R2 mccspsvc; C:\Program Files\Common Files\McAfee\CSP\2.3.322.0\\McCSPServiceHost.exe [2054080 2017-02-28] (McAfee, Inc.)
R2 McNaiAnn; C:\Program Files\Common Files\mcafee\Platform\McSvcHost\McSvHost.exe [641520 2017-02-22] (McAfee, Inc.)
S3 McODS; C:\Program Files\mcafee\VirusScan\mcods.exe [1344472 2017-02-24] (McAfee, Inc.)
R2 mcpltsvc; C:\Program Files\Common Files\mcafee\Platform\McSvcHost\McSvHost.exe [641520 2017-02-22] (McAfee, Inc.)
U2 McProxy; C:\Program Files\Common Files\mcafee\Platform\McSvcHost\McSvHost.exe [641520 2017-02-22] (McAfee, Inc.)
R3 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [241040 2017-01-18] (McAfee, Inc.)
R2 mfemms; C:\Program Files\Common Files\McAfee\SystemCore\\mfemms.exe [385112 2017-01-18] (McAfee, Inc.)
R3 mfevtp; C:\WINDOWS\system32\mfevtps.exe [343792 2017-01-18] (McAfee, Inc.)
R2 ModuleCoreService; C:\Program Files\Common Files\McAfee\ModuleCore\ModuleCoreService.exe [1551512 2017-02-26] (McAfee, Inc.)
R2 PEFService; C:\Program Files\Common Files\Intel Security\PEF\CORE\PEFService.exe [1104304 2016-11-15] (Intel Security, Inc.)
S3 RSLinx; C:\Program Files (x86)\Rockwell Software\RSLinx\RSLINX.EXE [3272224 2013-01-19] (Rockwell Automation, Inc.)
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [312056 2015-08-04] (Realtek Semiconductor)
R2 Samsung Link Service; C:\Program Files\Samsung\Samsung Link\Samsung Link.exe [616288 2015-03-18] (Copyright 2013 SAMSUNG)
S2 SupportAssistAgent; C:\Program Files (x86)\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe [32728 2017-04-25] (Dell Inc.)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [5702416 2015-09-11] (TeamViewer GmbH)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2016-10-25] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2017-04-27] (Microsoft Corporation)
R2 ZAtheros Bt&Wlan Coex Agent; C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\Ath_CoexAgent.exe [158880 2011-12-29] (Atheros) [File not signed]
R2 ZAtheros Wlan Agent; C:\Program Files (x86)\Dell Wireless\Ath_WlanAgent.exe [76960 2011-12-26] (Atheros) [File not signed]
S2 Avira.ServiceHost; "C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe" [X]
S2 AviraPhantomVPN; "C:\Program Files (x86)\Avira\VPN\Avira.VpnService.exe" [X]

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 androidusb; C:\WINDOWS\System32\Drivers\androidusb.sys [31744 2009-09-15] (Google Inc)
S3 aswTap; C:\WINDOWS\System32\drivers\aswTap.sys [44640 2017-01-14] (The OpenVPN Project)
R3 athr; C:\WINDOWS\System32\drivers\athw10x.sys [4318760 2015-12-10] (Qualcomm Atheros Communications, Inc.)
R3 AtiHDAudioService; C:\WINDOWS\system32\drivers\AtihdWT6.sys [102912 2015-05-28] (Advanced Micro Devices)
S3 AWEAlloc; C:\WINDOWS\System32\DRIVERS\awealloc.sys [17360 2011-03-11] (Olof Lagerkvist)
S3 cfwids; C:\WINDOWS\System32\drivers\cfwids.sys [88464 2017-01-20] (McAfee, Inc.)
S3 DDDriver; C:\WINDOWS\system32\drivers\DDDriver64Dcsa.sys [23760 2015-01-30] (Dell Computer Corporation)
S3 DellProf; C:\WINDOWS\system32\drivers\DellProf.sys [24240 2015-05-22] (Dell Computer Corporation)
S2 hardlock; C:\Windows\system32\drivers\hardlock.sys [321536 2011-09-28] (SafeNet Inc.)
R2 ImDisk; C:\WINDOWS\System32\DRIVERS\imdisk.sys [34776 2011-03-11] (Olof Lagerkvist)
R3 mfeaack; C:\WINDOWS\System32\drivers\mfeaack.sys [487184 2017-01-20] (McAfee, Inc.)
R3 mfeavfk; C:\WINDOWS\System32\drivers\mfeavfk.sys [366328 2017-01-20] (McAfee, Inc.)
S0 mfeelamk; C:\WINDOWS\System32\drivers\mfeelamk.sys [85048 2017-04-03] (McAfee, Inc.)
R3 mfefirek; C:\WINDOWS\System32\drivers\mfefirek.sys [518704 2017-01-20] (McAfee, Inc.)
R0 mfehidk; C:\WINDOWS\System32\drivers\mfehidk.sys [923640 2017-01-20] (McAfee, Inc.)
R3 mfencbdc; C:\WINDOWS\system32\DRIVERS\mfencbdc.sys [498648 2017-01-19] (McAfee, Inc.)
S3 mfencrk; C:\WINDOWS\system32\DRIVERS\mfencrk.sys [109320 2017-01-19] (McAfee, Inc.)
R3 mfeplk; C:\WINDOWS\System32\drivers\mfeplk.sys [110256 2017-01-20] (McAfee, Inc.)
R0 mfewfpk; C:\WINDOWS\System32\drivers\mfewfpk.sys [254800 2017-01-20] (McAfee, Inc.)
R0 PxHlpa64; C:\WINDOWS\System32\Drivers\PxHlpa64.sys [56336 2012-08-10] (Corel Corporation)
S3 qcusbser; C:\WINDOWS\system32\DRIVERS\qcusbser.sys [242688 2013-01-15] (QUALCOMM Incorporated)
S3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [589824 2015-10-30] (Realtek                                            )
S3 usbrndis6; C:\WINDOWS\System32\drivers\usb80236.sys [23040 2015-10-30] (Microsoft Corporation)
R1 VirtualBackplane; C:\WINDOWS\System32\drivers\VirtualBackplane.sys [51200 2011-06-02] (Rockwell Automation)
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation)
U1 aswbdisk; no ImagePath
S3 aswHdsKe; \??\C:\WINDOWS\system32\drivers\aswHdsKe.sys [X]
U3 idsvc; no ImagePath

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-05-30 10:22 - 2017-05-30 10:22 - 00000000 ___HD C:\OneDriveTemp
2017-05-30 08:51 - 2017-05-30 08:51 - 00000000 ____D C:\$SysReset
2017-05-30 08:27 - 2017-05-30 08:50 - 00042392 _____ C:\Users\JanLar\Desktop\Addition.txt
2017-05-30 08:25 - 2017-05-30 10:21 - 00041941 _____ C:\Users\JanLar\Desktop\FRST.txt
2017-05-29 22:31 - 2017-05-29 22:32 - 00042394 _____ C:\Users\JanLar\Downloads\Addition.txt
2017-05-29 22:30 - 2017-05-29 22:31 - 00080548 _____ C:\Users\JanLar\Downloads\FRST.txt
2017-05-29 22:30 - 2017-05-29 22:30 - 00000000 ____D C:\FRST
2017-05-29 22:25 - 2017-05-29 22:30 - 02429952 _____ (Farbar) C:\Users\JanLar\Downloads\FRST64.exe
2017-05-29 22:22 - 2017-05-30 08:25 - 02429952 _____ (Farbar) C:\Users\JanLar\Desktop\FRST64.exe
2017-05-29 18:55 - 2017-05-29 18:55 - 00001914 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2017-05-29 18:55 - 2017-05-29 18:55 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2017-05-29 18:55 - 2017-05-29 18:55 - 00000000 ____D C:\Program Files\Malwarebytes
2017-05-29 18:55 - 2017-05-09 16:37 - 00077440 _____ C:\WINDOWS\system32\Drivers\mbae64.sys
2017-05-29 15:07 - 2017-05-30 08:23 - 00004034 _____ C:\WINDOWS\System32\Tasks\Intel Security DAT Reputation (AMCore) periodic endpoint safety pulse
2017-05-29 13:27 - 2017-05-29 13:27 - 00004222 _____ C:\WINDOWS\System32\Tasks\Intel Security DAT Reputation (AMCore) Post DAT update endpoint safety pulse
2017-05-24 17:40 - 2017-05-24 17:40 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus
2017-05-24 17:40 - 2017-05-24 17:40 - 00000000 ____D C:\ProgramData\McAfee Security Scan
2017-05-21 19:21 - 2017-05-21 19:21 - 13089219 _____ C:\Users\JanLar\Documents\Freelance Marketing Handbook - Antonio V1.pdf
2017-05-14 21:07 - 2017-05-14 21:07 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YTD Video Downloader
2017-05-11 20:39 - 2017-05-11 20:39 - 04170170 _____ C:\Users\JanLar\Documents\840206110031_use.pdf
2017-05-11 00:15 - 2017-05-11 00:15 - 00647991 _____ C:\Users\JanLar\Documents\Portable AC.pdf
2017-05-09 19:30 - 2017-04-27 23:59 - 01862000 _____ C:\WINDOWS\SysWOW64\CoreUIComponents.dll
2017-05-09 19:30 - 2017-04-27 23:59 - 00602256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleaut32.dll
2017-05-09 19:30 - 2017-04-27 23:31 - 00808288 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe
2017-05-09 19:30 - 2017-04-27 23:25 - 06536248 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppsvc.exe
2017-05-09 19:30 - 2017-04-27 23:04 - 00881664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll
2017-05-09 19:30 - 2017-04-27 22:57 - 01813408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll
2017-05-09 19:30 - 2017-04-27 22:57 - 00959144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll
2017-05-09 19:30 - 2017-04-27 22:56 - 02945648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2017-05-09 19:30 - 2017-04-27 22:56 - 00703840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe
2017-05-09 19:30 - 2017-04-27 22:53 - 00465760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncHost.exe
2017-05-09 19:30 - 2017-04-27 22:52 - 05240448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2017-05-09 19:30 - 2017-04-27 22:45 - 01536600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\crypt32.dll
2017-05-09 19:30 - 2017-04-27 22:19 - 01370224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32.dll
2017-05-09 19:30 - 2017-04-27 22:16 - 00190464 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2017-05-09 19:30 - 2017-04-27 22:06 - 00059392 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe
2017-05-09 19:30 - 2017-04-27 21:59 - 00379392 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocore.dll
2017-05-09 19:30 - 2017-04-27 21:58 - 00412160 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2017-05-09 19:30 - 2017-04-27 21:50 - 00089088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\olepro32.dll
2017-05-09 19:30 - 2017-04-27 21:39 - 00025600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\odbcconf.dll
2017-05-09 19:30 - 2017-04-27 21:35 - 00689152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv2.sys
2017-05-09 19:30 - 2017-04-27 21:35 - 00407552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv.sys
2017-05-09 19:30 - 2017-04-27 21:23 - 00381952 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll
2017-05-09 19:30 - 2017-04-27 21:21 - 00256512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\unimdm.tsp
2017-05-09 19:30 - 2017-04-27 21:21 - 00205312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oemlicense.dll
2017-05-09 19:30 - 2017-04-27 21:19 - 00865792 _____ (Microsoft Corporation) C:\WINDOWS\system32\AzureSettingSyncProvider.dll
2017-05-09 19:30 - 2017-04-27 21:19 - 00269312 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatehandlers.dll
2017-05-09 19:30 - 2017-04-27 21:15 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\IdCtrls.dll
2017-05-09 19:30 - 2017-04-27 21:11 - 00260096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\apprepsync.dll
2017-05-09 19:30 - 2017-04-27 21:10 - 00190464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\apprepapi.dll
2017-05-09 19:30 - 2017-04-27 21:07 - 00541184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GamePanel.exe
2017-05-09 19:30 - 2017-04-27 21:04 - 00386048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schannel.dll
2017-05-09 19:30 - 2017-04-27 21:01 - 00250880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2017-05-09 19:30 - 2017-04-27 20:57 - 00153088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSSync.dll
2017-05-09 19:30 - 2017-04-27 20:55 - 00501760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2017-05-09 19:30 - 2017-04-27 20:55 - 00400896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OneDriveSettingSyncProvider.dll
2017-05-09 19:30 - 2017-04-27 20:51 - 02280960 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2017-05-09 19:30 - 2017-04-27 20:49 - 00805888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSShared.dll
2017-05-09 19:30 - 2017-04-27 20:47 - 03695104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_47.dll
2017-05-09 19:30 - 2017-04-27 20:47 - 00667648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AzureSettingSyncProvider.dll
2017-05-09 19:30 - 2017-04-27 20:46 - 00207872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\licensingdiag.exe
2017-05-09 19:30 - 2017-04-27 20:32 - 04078080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbgeng.dll
2017-05-09 19:30 - 2017-04-27 20:25 - 01501184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2017-05-09 19:30 - 2017-04-27 20:22 - 04412928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExplorerFrame.dll
2017-05-09 19:30 - 2017-04-27 20:22 - 02878976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2017-05-09 19:30 - 2017-04-27 20:21 - 13018112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2017-05-09 19:30 - 2017-04-27 20:20 - 01556992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OpcServices.dll
2017-05-09 19:30 - 2017-04-27 20:19 - 06296064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mos.dll
2017-05-09 19:30 - 2017-04-27 20:06 - 04404736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Search.dll
2017-05-09 19:30 - 2017-04-27 20:04 - 02911744 _____ (Microsoft Corporation) C:\WINDOWS\system32\CertEnroll.dll
2017-05-09 19:30 - 2017-04-27 19:58 - 00821248 _____ (Microsoft Corporation) C:\WINDOWS\system32\fvewiz.dll
2017-05-09 19:30 - 2017-04-27 19:57 - 02604032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CertEnroll.dll
2017-05-09 19:30 - 2017-04-27 19:55 - 00339456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certcli.dll
2017-05-09 19:30 - 2017-04-27 19:29 - 00461824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll
2017-05-09 19:29 - 2017-04-28 00:32 - 01030416 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2017-05-09 19:29 - 2017-04-28 00:30 - 07465816 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2017-05-09 19:29 - 2017-04-28 00:30 - 02656960 _____ C:\WINDOWS\system32\CoreUIComponents.dll
2017-05-09 19:29 - 2017-04-28 00:30 - 01997840 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2017-05-09 19:29 - 2017-04-28 00:30 - 01317640 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2017-05-09 19:29 - 2017-04-28 00:30 - 01098640 _____ (Microsoft Corporation) C:\WINDOWS\system32\MrmCoreR.dll
2017-05-09 19:29 - 2017-04-28 00:30 - 00800080 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleaut32.dll
2017-05-09 19:29 - 2017-04-28 00:27 - 00754664 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll
2017-05-09 19:29 - 2017-04-28 00:08 - 03449168 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSService.dll
2017-05-09 19:29 - 2017-04-27 23:59 - 01558280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2017-05-09 19:29 - 2017-04-27 23:38 - 01060432 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll
2017-05-09 19:29 - 2017-04-27 23:32 - 02608912 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll
2017-05-09 19:29 - 2017-04-27 23:32 - 01323272 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll
2017-05-09 19:29 - 2017-04-27 23:31 - 03699280 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2017-05-09 19:29 - 2017-04-27 23:31 - 00026464 _____ (Microsoft Corporation) C:\WINDOWS\system32\browser_broker.exe
2017-05-09 19:29 - 2017-04-27 23:28 - 22560744 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2017-05-09 19:29 - 2017-04-27 23:28 - 00566104 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncHost.exe
2017-05-09 19:29 - 2017-04-27 23:27 - 06604992 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2017-05-09 19:29 - 2017-04-27 23:26 - 01540224 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll
2017-05-09 19:29 - 2017-04-27 23:26 - 00692136 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppwinob.dll
2017-05-09 19:29 - 2017-04-27 23:24 - 01128104 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipUp.exe
2017-05-09 19:29 - 2017-04-27 23:24 - 00625000 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipSVC.dll
2017-05-09 19:29 - 2017-04-27 23:23 - 00609056 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2017-05-09 19:29 - 2017-04-27 23:20 - 01848584 _____ (Microsoft Corporation) C:\WINDOWS\system32\crypt32.dll
2017-05-09 19:29 - 2017-04-27 22:53 - 01987424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2017-05-09 19:29 - 2017-04-27 22:52 - 01594928 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32.dll
2017-05-09 19:29 - 2017-04-27 22:31 - 00084480 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpudd.dll
2017-05-09 19:29 - 2017-04-27 22:24 - 00824320 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcWebFilter.dll
2017-05-09 19:29 - 2017-04-27 22:23 - 00068608 _____ (Microsoft Corporation) C:\WINDOWS\system32\fdProxy.dll
2017-05-09 19:29 - 2017-04-27 22:22 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\system32\odbcconf.dll
2017-05-09 19:29 - 2017-04-27 22:15 - 00088064 _____ (Microsoft Corporation) C:\WINDOWS\system32\tdc.ocx
2017-05-09 19:29 - 2017-04-27 22:13 - 00584704 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIRibbonRes.dll
2017-05-09 19:29 - 2017-04-27 22:11 - 00119296 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieetwcollector.exe
2017-05-09 19:29 - 2017-04-27 22:05 - 00091648 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll
2017-05-09 19:29 - 2017-04-27 22:03 - 00297472 _____ (Microsoft Corporation) C:\WINDOWS\system32\unimdm.tsp
2017-05-09 19:29 - 2017-04-27 22:02 - 00285184 _____ (Microsoft Corporation) C:\WINDOWS\system32\oemlicense.dll
2017-05-09 19:29 - 2017-04-27 22:01 - 00238592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Streaming.ps.dll
2017-05-09 19:29 - 2017-04-27 21:55 - 00291328 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll
2017-05-09 19:29 - 2017-04-27 21:55 - 00145920 _____ (Microsoft Corporation) C:\WINDOWS\system32\iepeers.dll
2017-05-09 19:29 - 2017-04-27 21:55 - 00110080 _____ (Microsoft Corporation) C:\WINDOWS\system32\IdCtrls.dll
2017-05-09 19:29 - 2017-04-27 21:54 - 00195584 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpapisrv.dll
2017-05-09 19:29 - 2017-04-27 21:53 - 00198144 _____ (Microsoft Corporation) C:\WINDOWS\system32\winsrv.dll
2017-05-09 19:29 - 2017-04-27 21:53 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2017-05-09 19:29 - 2017-04-27 21:52 - 00221696 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2017-05-09 19:29 - 2017-04-27 21:51 - 00381952 _____ (Microsoft Corporation) C:\WINDOWS\system32\apprepsync.dll
2017-05-09 19:29 - 2017-04-27 21:51 - 00200192 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUDFPlatform.dll
2017-05-09 19:29 - 2017-04-27 21:50 - 00689152 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll
2017-05-09 19:29 - 2017-04-27 21:49 - 00287744 _____ (Microsoft Corporation) C:\WINDOWS\system32\apprepapi.dll
2017-05-09 19:29 - 2017-04-27 21:46 - 00383488 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2017-05-09 19:29 - 2017-04-27 21:45 - 00715776 _____ (Microsoft Corporation) C:\WINDOWS\system32\GamePanel.exe
2017-05-09 19:29 - 2017-04-27 21:41 - 00472576 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll
2017-05-09 19:29 - 2017-04-27 21:40 - 00572928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WpcWebFilter.dll
2017-05-09 19:29 - 2017-04-27 21:38 - 00602112 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptui.dll
2017-05-09 19:29 - 2017-04-27 21:38 - 00330240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2017-05-09 19:29 - 2017-04-27 21:33 - 00183808 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSSync.dll
2017-05-09 19:29 - 2017-04-27 21:32 - 02125312 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Bluetooth.dll
2017-05-09 19:29 - 2017-04-27 21:32 - 00073728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tdc.ocx
2017-05-09 19:29 - 2017-04-27 21:31 - 00784384 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2017-05-09 19:29 - 2017-04-27 21:31 - 00584704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIRibbonRes.dll
2017-05-09 19:29 - 2017-04-27 21:31 - 00515072 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneDriveSettingSyncProvider.dll
2017-05-09 19:29 - 2017-04-27 21:31 - 00262144 _____ (Microsoft Corporation) C:\WINDOWS\system32\webcheck.dll
2017-05-09 19:29 - 2017-04-27 21:30 - 00602624 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2017-05-09 19:29 - 2017-04-27 21:29 - 02127872 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2017-05-09 19:29 - 2017-04-27 21:28 - 01386496 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2017-05-09 19:29 - 2017-04-27 21:28 - 00905728 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcss.dll
2017-05-09 19:29 - 2017-04-27 21:26 - 00853504 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadtb.dll
2017-05-09 19:29 - 2017-04-27 21:24 - 01752576 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2017-05-09 19:29 - 2017-04-27 21:23 - 00961536 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSShared.dll
2017-05-09 19:29 - 2017-04-27 21:20 - 04456448 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_47.dll
2017-05-09 19:29 - 2017-04-27 21:19 - 00236032 _____ (Microsoft Corporation) C:\WINDOWS\system32\licensingdiag.exe
2017-05-09 19:29 - 2017-04-27 21:15 - 00268800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll
2017-05-09 19:29 - 2017-04-27 21:15 - 00128000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iepeers.dll
2017-05-09 19:29 - 2017-04-27 21:13 - 00083456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll
2017-05-09 19:29 - 2017-04-27 21:11 - 00307200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll
2017-05-09 19:29 - 2017-04-27 21:07 - 00335872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2017-05-09 19:29 - 2017-04-27 21:03 - 03586048 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2017-05-09 19:29 - 2017-04-27 21:03 - 02610176 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll
2017-05-09 19:29 - 2017-04-27 21:00 - 05123072 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbgeng.dll
2017-05-09 19:29 - 2017-04-27 20:56 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webcheck.dll
2017-05-09 19:29 - 2017-04-27 20:55 - 00687616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2017-05-09 19:29 - 2017-04-27 20:54 - 02050560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2017-05-09 19:29 - 2017-04-27 20:53 - 01729536 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2017-05-09 19:29 - 2017-04-27 20:50 - 01526272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2017-05-09 19:29 - 2017-04-27 20:47 - 04826624 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExplorerFrame.dll
2017-05-09 19:29 - 2017-04-27 20:47 - 03404800 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2017-05-09 19:29 - 2017-04-27 20:44 - 07977984 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll
2017-05-09 19:29 - 2017-04-27 20:43 - 02055680 _____ (Microsoft Corporation) C:\WINDOWS\system32\OpcServices.dll
2017-05-09 19:29 - 2017-04-27 20:36 - 16985600 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2017-05-09 19:29 - 2017-04-27 20:35 - 03585536 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsThresholdAdminFlowUI.dll
2017-05-09 19:29 - 2017-04-27 20:27 - 01388032 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2017-05-09 19:29 - 2017-04-27 20:25 - 00957952 _____ (Microsoft Corporation) C:\WINDOWS\system32\IKEEXT.DLL
2017-05-09 19:29 - 2017-04-27 20:16 - 22375424 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2017-05-09 19:29 - 2017-04-27 20:12 - 04889600 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2017-05-09 19:29 - 2017-04-27 20:11 - 06312448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Search.dll
2017-05-09 19:29 - 2017-04-27 20:09 - 13393920 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2017-05-09 19:29 - 2017-04-27 20:08 - 03993600 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2017-05-09 19:29 - 2017-04-27 20:06 - 12139008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2017-05-09 19:29 - 2017-04-27 20:05 - 24605184 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2017-05-09 19:29 - 2017-04-27 20:04 - 19344896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2017-05-09 19:29 - 2017-04-27 20:04 - 03660288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2017-05-09 19:29 - 2017-04-27 20:04 - 00459776 _____ (Microsoft Corporation) C:\WINDOWS\system32\certcli.dll
2017-05-09 19:29 - 2017-04-27 20:03 - 18673152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2017-05-09 19:29 - 2017-04-27 19:57 - 04171264 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcorets.dll
2017-05-09 19:29 - 2017-04-27 19:53 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\system32\wksprtPS.dll
2017-05-09 19:29 - 2017-04-27 19:50 - 07853568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2017-05-09 19:29 - 2017-04-27 19:47 - 05670912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2017-05-09 19:29 - 2017-04-27 19:45 - 01087488 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll
2017-05-03 16:43 - 2017-05-03 16:43 - 11084751 _____ C:\Users\JanLar\Documents\kx-tge260_mul_omphone.pdf
2017-05-03 11:49 - 2017-05-03 11:49 - 00000000 ____D C:\ProgramData\SupportAssistAgent
2017-04-30 10:02 - 2017-04-30 10:02 - 00002207 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Belarc Advisor.lnk
2017-04-30 10:02 - 2017-04-30 10:02 - 00002195 _____ C:\Users\Public\Desktop\Belarc Advisor.lnk
2017-04-30 10:02 - 2017-04-30 10:02 - 00000000 ____D C:\Program Files (x86)\Belarc

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-05-30 10:25 - 2015-12-16 09:53 - 01011572 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2017-05-30 10:25 - 2015-10-30 03:21 - 00000000 ____D C:\WINDOWS\INF
2017-05-30 10:23 - 2013-04-01 00:04 - 00000000 ____D C:\Program Files (x86)\i2p
2017-05-30 10:22 - 2015-09-23 23:38 - 00000000 ___RD C:\Users\JanLar\OneDrive
2017-05-30 10:21 - 2015-12-16 10:05 - 00000000 ____D C:\Users\Default\AppData\Local\SoftThinks
2017-05-30 10:21 - 2015-12-16 10:05 - 00000000 ____D C:\Users\Default User\AppData\Local\SoftThinks
2017-05-30 10:21 - 2012-06-13 18:54 - 00000000 ____D C:\Program Files (x86)\Dell DataSafe Local Backup
2017-05-30 10:20 - 2015-03-08 18:17 - 00000000 ____D C:\Program Files (x86)\TeamViewer
2017-05-30 10:20 - 2014-06-06 22:52 - 00000374 _____ C:\WINDOWS\system32\Drivers\etc\hosts.ics
2017-05-30 10:20 - 2012-11-13 19:22 - 00000894 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2017-05-30 10:19 - 2015-12-16 10:21 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2017-05-30 10:19 - 2012-06-13 18:48 - 00000828 _____ C:\WINDOWS\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job
2017-05-30 09:14 - 2017-04-13 17:14 - 00000941 _____ C:\WINDOWS\Tasks\EPSON WF-3640 Series Update {D042F190-4C35-4B21-BA70-4271F8C782B7}.job
2017-05-30 09:14 - 2017-04-13 17:14 - 00000755 _____ C:\WINDOWS\Tasks\EPSON WF-3640 Series Invitation {D042F190-4C35-4B21-BA70-4271F8C782B7}.job
2017-05-30 09:02 - 2017-04-28 21:02 - 00000941 _____ C:\WINDOWS\Tasks\EPSON WF-3640 Series Update {84DC0834-2CD0-41C2-8250-2D541D7A37B1}.job
2017-05-30 09:02 - 2017-04-28 21:02 - 00000755 _____ C:\WINDOWS\Tasks\EPSON WF-3640 Series Invitation {84DC0834-2CD0-41C2-8250-2D541D7A37B1}.job
2017-05-30 08:47 - 2012-10-01 15:34 - 00000000 ____D C:\Users\JanLar\AppData\Local\CrashDumps
2017-05-30 08:25 - 2015-09-23 23:24 - 00004158 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{8CB184FC-B82B-44D2-8611-DA114F42895D}
2017-05-30 08:25 - 2013-05-20 22:12 - 00000000 ____D C:\ProgramData\boost_interprocess
2017-05-30 08:24 - 2014-08-17 23:00 - 00251832 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2017-05-30 08:23 - 2012-09-30 22:02 - 00000000 ____D C:\Users\JanLar\AppData\Local\Adobe
2017-05-29 22:50 - 2015-12-16 12:42 - 00000000 ___DC C:\WINDOWS\Panther
2017-05-29 21:33 - 2012-09-30 20:29 - 00000000 ____D C:\Users\JanLar\Documents\Outlook Files
2017-05-29 19:12 - 2015-12-16 09:54 - 00000000 ____D C:\Users\JanLar
2017-05-29 19:00 - 2014-10-19 09:49 - 00000860 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1949060236-814623403-1790243873-1000Core1cfeba38a718c08.job
2017-05-29 18:55 - 2013-01-18 20:29 - 00000000 ____D C:\ProgramData\Malwarebytes
2017-05-29 18:53 - 2015-10-30 03:24 - 00000000 ____D C:\WINDOWS\AppReadiness
2017-05-29 18:37 - 2015-10-30 02:28 - 00786432 ___SH C:\WINDOWS\system32\config\BBI
2017-05-29 18:16 - 2012-10-03 19:14 - 00000000 ____D C:\WINDOWS\system32\appmgmt
2017-05-29 17:17 - 2014-01-01 00:03 - 00000000 ____D C:\Program Files (x86)\McAfee
2017-05-29 17:15 - 2015-10-30 03:24 - 00000000 ____D C:\WINDOWS\ModemLogs
2017-05-29 13:27 - 2015-10-30 02:28 - 00032768 ___SH C:\WINDOWS\system32\config\ELAM
2017-05-29 13:24 - 2015-10-30 03:24 - 00000000 ____D C:\WINDOWS\system32\NDF
2017-05-29 08:24 - 2012-10-01 07:33 - 00000000 ____D C:\Users\JanLar\AppData\Roaming\Roxio
2017-05-29 08:24 - 2012-10-01 07:22 - 00000000 ____D C:\ProgramData\Roxio
2017-05-28 18:38 - 2012-06-13 18:48 - 00000830 _____ C:\WINDOWS\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job
2017-05-28 09:54 - 2014-07-18 20:44 - 00000860 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1949060236-814623403-1790243873-1000Core.job
2017-05-27 23:24 - 2015-10-30 03:24 - 00000000 ___HD C:\Program Files\WindowsApps
2017-05-27 02:11 - 2014-11-13 19:55 - 00000860 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1949060236-814623403-1790243873-1000Core1cfff9d42bcb571.job
2017-05-25 10:09 - 2017-04-15 20:06 - 00003126 _____ C:\WINDOWS\System32\Tasks\McAfeeLogon
2017-05-25 10:09 - 2017-04-15 20:06 - 00000000 ____D C:\WINDOWS\System32\Tasks\McAfee
2017-05-25 10:09 - 2015-10-30 03:24 - 00000000 ___HD C:\WINDOWS\ELAMBKUP
2017-05-25 10:09 - 2012-06-13 19:04 - 00000000 ____D C:\Program Files\Common Files\mcafee
2017-05-24 17:40 - 2015-11-10 23:19 - 00000000 ____D C:\Program Files\McAfee Security Scan
2017-05-24 17:40 - 2013-11-20 20:25 - 00002011 _____ C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk
2017-05-23 13:32 - 2013-08-15 02:06 - 00000000 ____D C:\WINDOWS\system32\MRT
2017-05-23 13:29 - 2012-10-02 23:06 - 132223576 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2017-05-20 13:48 - 2012-11-22 01:16 - 00000000 ____D C:\Program Files (x86)\Java
2017-05-19 18:50 - 2015-02-10 14:04 - 00000000 ____D C:\Program Files\Dell
2017-05-15 21:48 - 2012-11-13 19:23 - 00002274 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-05-15 21:48 - 2012-11-13 19:23 - 00002262 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2017-05-14 21:07 - 2012-12-08 15:57 - 00001364 _____ C:\Users\Public\Desktop\YTD Video Downloader.lnk
2017-05-14 21:07 - 2012-12-08 15:57 - 00000000 ____D C:\ProgramData\YTD Video Downloader
2017-05-11 15:14 - 2015-10-30 03:24 - 00000000 ____D C:\WINDOWS\rescache
2017-05-11 07:16 - 2015-03-20 07:14 - 00097856 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll
2017-05-11 07:16 - 2015-03-20 07:14 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2017-05-10 21:08 - 2015-10-30 03:24 - 00000000 ____D C:\WINDOWS\SysWOW64\Macromed
2017-05-10 21:08 - 2015-10-30 03:24 - 00000000 ____D C:\WINDOWS\system32\Macromed
2017-05-10 09:01 - 2015-09-10 01:44 - 00000000 __RHD C:\Users\Public\AccountPictures
2017-05-10 09:01 - 2012-09-30 17:07 - 00000000 ___RD C:\Users\JanLar\Virtual Machines
2017-05-10 03:35 - 2015-12-16 09:44 - 00496256 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2017-05-10 03:31 - 2015-10-30 03:24 - 00000000 ___SD C:\WINDOWS\SysWOW64\F12
2017-05-10 03:31 - 2015-10-30 03:24 - 00000000 ___SD C:\WINDOWS\system32\F12
2017-05-10 03:31 - 2015-10-30 03:24 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2017-05-10 03:31 - 2015-10-30 03:24 - 00000000 ____D C:\WINDOWS\PolicyDefinitions
2017-05-10 03:31 - 2015-10-30 03:24 - 00000000 ____D C:\Program Files\Windows Photo Viewer
2017-05-10 03:31 - 2015-10-30 03:24 - 00000000 ____D C:\Program Files\Windows Defender
2017-05-10 03:31 - 2015-10-30 03:24 - 00000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2017-05-10 03:31 - 2015-10-30 03:24 - 00000000 ____D C:\Program Files (x86)\Windows Defender
2017-05-09 23:01 - 2015-09-23 23:01 - 00000000 ____D C:\Users\JanLar\AppData\Local\Packages
2017-05-09 21:16 - 2015-10-30 03:11 - 00000000 ____D C:\WINDOWS\CbsTemp
2017-05-06 16:03 - 2014-12-25 13:05 - 00004562 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task
2017-05-02 20:53 - 2014-09-07 21:32 - 00000000 ____D C:\ProgramData\PCDr

==================== Files in the root of some directories =======

2013-02-14 21:42 - 2015-06-13 18:37 - 0001057 _____ () C:\Users\JanLar\AppData\Roaming\vso_ts_preview.xml
2013-05-10 20:37 - 2013-11-12 09:15 - 0000789 _____ () C:\Users\JanLar\AppData\Local\cookies.ini
2014-06-08 00:12 - 2014-07-27 17:04 - 0005120 _____ () C:\Users\JanLar\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2013-03-27 17:52 - 2017-04-02 19:38 - 0007642 _____ () C:\Users\JanLar\AppData\Local\Resmon.ResmonCfg
2012-10-13 22:33 - 2012-10-13 22:55 - 0340268 _____ () C:\Users\JanLar\AppData\Local\rx_image32.Cache
2015-12-16 09:47 - 2015-12-16 09:47 - 0000000 ____H () C:\ProgramData\DP45977C.lfl

Files to move or delete:
====================
C:\Users\JanLar\en_res.dll
C:\Users\JanLar\es_res.dll
C:\Users\JanLar\fr_res.dll
C:\Users\JanLar\grm_res.dll
C:\Users\JanLar\it_res.dll
C:\Users\JanLar\jp_res.dll
C:\Users\JanLar\mfc80u.dll
C:\Users\JanLar\msvcr80.dll
C:\Users\JanLar\PCPE Setup.exe
C:\Users\JanLar\pt_res.dll
C:\Users\JanLar\ResourceReader.dll
C:\Users\JanLar\ru_res.dll
C:\Users\JanLar\zh_res.dll

Some files in TEMP:
====================
2016-04-27 04:02 - 2016-04-27 04:02 - 0000000 _____ () C:\Users\JanLar\AppData\Local\Temp\GUR6EAA.exe
2016-07-31 10:48 - 2016-07-31 10:48 - 0741440 _____ (Oracle Corporation) C:\Users\JanLar\AppData\Local\Temp\jre-8u101-windows-au.exe
2016-11-06 14:12 - 2016-11-06 14:12 - 0737856 _____ (Oracle Corporation) C:\Users\JanLar\AppData\Local\Temp\jre-8u111-windows-au.exe
2017-03-04 10:32 - 2017-03-04 10:32 - 0739904 _____ (Oracle Corporation) C:\Users\JanLar\AppData\Local\Temp\jre-8u121-windows-au.exe
2017-05-11 07:14 - 2017-05-11 07:14 - 0739904 _____ (Oracle Corporation) C:\Users\JanLar\AppData\Local\Temp\jre-8u131-windows-au.exe
2015-12-17 01:15 - 2015-12-17 01:15 - 0585824 _____ (Oracle Corporation) C:\Users\JanLar\AppData\Local\Temp\jre-8u66-windows-au.exe
2016-03-03 11:56 - 2016-03-03 11:56 - 0736352 _____ (Oracle Corporation) C:\Users\JanLar\AppData\Local\Temp\jre-8u73-windows-au.exe
2016-03-28 19:54 - 2016-03-28 19:54 - 0736320 _____ (Oracle Corporation) C:\Users\JanLar\AppData\Local\Temp\jre-8u77-windows-au.exe
2016-05-11 17:02 - 2016-05-11 17:02 - 0739904 _____ (Oracle Corporation) C:\Users\JanLar\AppData\Local\Temp\jre-8u91-windows-au.exe
2017-02-28 05:10 - 2017-02-28 05:10 - 0244264 _____ (McAfee, Inc.) C:\Users\JanLar\AppData\Local\Temp\McCSPInstall.dll
2016-01-30 20:15 - 2017-01-27 21:09 - 21319576 _____ (Siber Systems) C:\Users\JanLar\AppData\Local\Temp\RoboForm-Setup.exe
2017-01-14 20:50 - 2017-01-14 20:50 - 6503984 _____ (Microsoft Corporation) C:\Users\JanLar\AppData\Local\Temp\vcredist_x86.exe
2017-03-15 22:18 - 2017-03-15 22:18 - 14456872 _____ (Microsoft Corporation) C:\Users\JanLar\AppData\Local\Temp\vc_redist.x86.exe
2017-04-13 16:57 - 2006-05-24 15:10 - 0455600 ____R (Macrovision Corporation) C:\Users\JanLar\AppData\Local\Temp\_is37E6.exe
2017-04-13 13:05 - 2006-05-24 15:10 - 0455600 ____R (Macrovision Corporation) C:\Users\JanLar\AppData\Local\Temp\_isE604.exe
2016-04-05 23:29 - 2016-04-05 23:29 - 2547800 _____ (Google Inc.) C:\Users\JanLar\AppData\Local\Temp\{3FEAA32B-5A76-41EE-95F4-C824A95292DA}-49.0.2623.112_49.0.2623.110_chrome_updater.exe
2016-02-09 01:12 - 2016-02-09 01:12 - 2519960 _____ (Google Inc.) C:\Users\JanLar\AppData\Local\Temp\{4F1ECC9C-FCEB-4E43-940C-6556E90CAAAB}-48.0.2564.109_48.0.2564.103_chrome_updater.exe
2016-06-15 06:18 - 2016-06-15 06:18 - 2698328 _____ (Google Inc.) C:\Users\JanLar\AppData\Local\Temp\{58C02BD2-69EC-4225-B719-0BD998AD6B9D}-51.0.2704.103_51.0.2704.84_chrome_updater.exe
2016-02-02 20:47 - 2016-02-02 20:47 - 0852560 _____ () C:\Users\JanLar\AppData\Local\Temp\{AF4117B4-81E4-49AA-96FC-38D61122539E}-48.0.2564.103_48.0.2564.97_chrome_updater_3stage.exe
2016-02-18 01:42 - 2016-02-18 01:42 - 0879512 _____ (Google Inc.) C:\Users\JanLar\AppData\Local\Temp\{D36CE3E8-304A-4BB3-B3D8-EF698F382A9A}-48.0.2564.116_48.0.2564.109_chrome_updater.exe
2016-01-20 13:58 - 2016-01-20 13:58 - 0987728 _____ (Google Inc.) C:\Users\JanLar\AppData\Local\Temp\{D93AA117-EC7F-4938-BF10-5D23D6C4E31E}-GoogleUpdateSetup.exe
2015-12-17 17:30 - 2015-12-17 17:30 - 0532312 _____ (Google Inc.) C:\Users\JanLar\AppData\Local\Temp\{F23C3847-8802-40DE-BDB2-60C0C330DCA2}-GoogleToolbarInstaller_updater_signed.exe

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signedAttached File  Addition.txt   41.4KB   3 downloads



#3 Jo*

Jo*

  • Malware Response Team
  • 3,416 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Germany
  • Local time:05:26 AM

Posted 30 May 2017 - 10:39 AM

double post,

go on here https://www.bleepingcomputer.com/forums/t/648120/computer-sluggish-cannot-not-delete-or-uninstall-files/#entry4250604

Graduate of the WTT Classroom
Cheers,
Jo
If I have been helping you, and I have not replied to your latest post in 36 hours please send me a PM.





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users