Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

I managed to get the SVCVMX Trojan virus on my computer. Help?


  • This topic is locked This topic is locked
17 replies to this topic

#1 Phiki

Phiki

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:06:29 PM

Posted 03 July 2017 - 08:42 AM

Edit: I have Windows 10, Thank you britech for moving me to the correct forum. My bad

I downloaded a program I heard was completely safe but my dumba** downloaded it from the wrong website and now I have this Trojan on my computer. I've tried everything from system restoring (which I can't do logged in normally, only through windows startup repair, but it fails everytime anyway), I've tried editing the registry but I get an error "some selected values could not be delete" or something similar. I tried disabling it from start up but it straight up won't let me, I tried deleting it from my apps data but it tells me I need permission from the account I'm logged in under in order to delete it. I've even tried using the "Reset this PC" option but that failed too. I've run windows defender virus scan, malwarebytes, adwscanner, and a few other virus scans, all of which detect it but fail to remove it. I tried file assassin on the file, but that failed. I'm out of idea. I have no idea what else to do. Can someone please help me get this da*n thing off my computer? If push comes to shove I'll just have to reinstall windows, I know but I'm trying to avoid that. Thank you to anyone willing to help.


Edited by Phiki, 03 July 2017 - 08:59 AM.
Moved from Windows 10 Support


BC AdBot (Login to Remove)

 


#2 Aura

Aura

    Bleepin' Special Ops


  • Malware Response Team
  • 19,697 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:12:29 PM

Posted 03 July 2017 - 09:28 AM

Hi Phiki :)
 
My name is Aura and I'll be assisting you with your malware issue. Since we'll be working together, you can call me Aura or Yoan, which is my real name, it's up to you! Now that we've broke the ice, I'll just ask you a few things during the time we'll be working together to clean your system and get it back to an operational state.
  • As you'll notice, the logs we are asking for here are quite lenghty, so it's normal for me to not reply exactly after you post them. This is because I need some time to analyse them and then act accordingly. However, I'll always reply within 24 hours, 48 hours at most if something unexpected happens;
  • As long as I'm assisting you on BleepingComputer, in this thread, I'll ask you to not seek assistance anywhere else for any issue related to the system we are working on. If you have an issue, question, etc. about your computer, please ask it in this thread and I'll assist you;
  • The same principle applies to any modifications you make to your system, I would like you to ask me before you do any manipulations that aren't in the instructions I posted. This is to ensure that we are operating in sync and I know exactly what's happening on your system;
  • If you aren't sure about an instruction I'm giving you, ask me about it. This is to ensure that the clean-up process goes without any issue. I'll answer you and even give you more precise instructions/explanations if you need. There's no shame in asking questions here, better be safe than sorry!;
  • If you don't reply to your thread within 3 days, I'll bump this thread to let you know that I'm waiting for you. If you don't reply after 5 days, it'll be closed. If you return after that period, you can send me a PM to get it unlocked and we'll continue where we left off;
  • Since malware can work quickly, we want to get rid of them as fast as we can, before they make unknown changes to the system. This being said, I would appreciate if you could reply to this thread within 24 hours of me posting. This way, we'll have a good clean-up rhythm and the chances of complications will be reduced;
  • I'm against any form of pirated, illegal and counterfeit software and material. So if you have any installed on your system, I'll ask you to uninstall them right now. You don't have to tell me if you indeed had some or not, I'll give you the benefit of the doubt. Plus, this would be against BleepingComputer's rules;
  • In the end, you are the one asking for assistance here. So if you wish to go a different way during the clean-up, like format and reinstall Windows, you are free to do so. I would appreciate you to let me know about it first, and if you need, I can also assist you in the process;
  • I would appreciate if you were to stay with me until the end, which means, until I declare your system clean. Just because your system isn't behaving weirdly anymore, or is running better than before, it doesn't mean that the infection is completely gone;
    This being said, I have a full time job so sometimes it'll take longer for me to reply to you. Don't worry, you'll be my first priority as soon as I get home and have time to look at your thread;
This being said, it's time to clean-up some malware, so let's get started, shall we? :)
 
Follow the instructions in the thread below. Make sure to download the MBAR linked in it. Let me know if you're not able to launch it and run a scan.
 
https://forums.malwarebytes.com/topic/198907-requested-resource-is-in-use-error-unable-to-start-malwarebytes/
 
If you manage to run a scan, delete everything it finds, and then copy/paste the content of the "mbar-log-TODAY'S-DATE.txt" log that is located in the MBAR folder here after.

animinionsmalltext.gif
unite_blue.png
Security Administrator | Sysnative Windows Update Senior Analyst | Malware Hunter | @SecurityAura
My timezone UTC-05:00 (East. Coast). If I didn't reply to you within 48 hours, please send me a PM.


#3 Phiki

Phiki
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:06:29 PM

Posted 04 July 2017 - 01:03 AM

Hi Phiki :)
 
My name is Aura and I'll be assisting you with your malware issue. Since we'll be working together, you can call me Aura or Yoan, which is my real name, it's up to you! Now that we've broke the ice, I'll just ask you a few things during the time we'll be working together to clean your system and get it back to an operational state.

  • As you'll notice, the logs we are asking for here are quite lenghty, so it's normal for me to not reply exactly after you post them. This is because I need some time to analyse them and then act accordingly. However, I'll always reply within 24 hours, 48 hours at most if something unexpected happens;
  • As long as I'm assisting you on BleepingComputer, in this thread, I'll ask you to not seek assistance anywhere else for any issue related to the system we are working on. If you have an issue, question, etc. about your computer, please ask it in this thread and I'll assist you;
  • The same principle applies to any modifications you make to your system, I would like you to ask me before you do any manipulations that aren't in the instructions I posted. This is to ensure that we are operating in sync and I know exactly what's happening on your system;
  • If you aren't sure about an instruction I'm giving you, ask me about it. This is to ensure that the clean-up process goes without any issue. I'll answer you and even give you more precise instructions/explanations if you need. There's no shame in asking questions here, better be safe than sorry!;
  • If you don't reply to your thread within 3 days, I'll bump this thread to let you know that I'm waiting for you. If you don't reply after 5 days, it'll be closed. If you return after that period, you can send me a PM to get it unlocked and we'll continue where we left off;
  • Since malware can work quickly, we want to get rid of them as fast as we can, before they make unknown changes to the system. This being said, I would appreciate if you could reply to this thread within 24 hours of me posting. This way, we'll have a good clean-up rhythm and the chances of complications will be reduced;
  • I'm against any form of pirated, illegal and counterfeit software and material. So if you have any installed on your system, I'll ask you to uninstall them right now. You don't have to tell me if you indeed had some or not, I'll give you the benefit of the doubt. Plus, this would be against BleepingComputer's rules;
  • In the end, you are the one asking for assistance here. So if you wish to go a different way during the clean-up, like format and reinstall Windows, you are free to do so. I would appreciate you to let me know about it first, and if you need, I can also assist you in the process;
  • I would appreciate if you were to stay with me until the end, which means, until I declare your system clean. Just because your system isn't behaving weirdly anymore, or is running better than before, it doesn't mean that the infection is completely gone;
    This being said, I have a full time job so sometimes it'll take longer for me to reply to you. Don't worry, you'll be my first priority as soon as I get home and have time to look at your thread;
This being said, it's time to clean-up some malware, so let's get started, shall we? :)
 
Follow the instructions in the thread below. Make sure to download the MBAR linked in it. Let me know if you're not able to launch it and run a scan.
 
https://forums.malwarebytes.com/topic/198907-requested-resource-is-in-use-error-unable-to-start-malwarebytes/
 
If you manage to run a scan, delete everything it finds, and then copy/paste the content of the "mbar-log-TODAY'S-DATE.txt" log that is located in the MBAR folder here after.

 

So ran MBAR but the log is so big I can't paste it here. It just crashes my browser. I'm going to try to upload it to google drive and then paste the link

After MBAR ran, I ran Malware bytes, and here's the log for that : https://pastebin.com/MAsvEiHF



#4 Phiki

Phiki
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:06:29 PM

Posted 04 July 2017 - 01:05 AM

 

Hi Phiki :)
 
My name is Aura and I'll be assisting you with your malware issue. Since we'll be working together, you can call me Aura or Yoan, which is my real name, it's up to you! Now that we've broke the ice, I'll just ask you a few things during the time we'll be working together to clean your system and get it back to an operational state.

  • As you'll notice, the logs we are asking for here are quite lenghty, so it's normal for me to not reply exactly after you post them. This is because I need some time to analyse them and then act accordingly. However, I'll always reply within 24 hours, 48 hours at most if something unexpected happens;
  • As long as I'm assisting you on BleepingComputer, in this thread, I'll ask you to not seek assistance anywhere else for any issue related to the system we are working on. If you have an issue, question, etc. about your computer, please ask it in this thread and I'll assist you;
  • The same principle applies to any modifications you make to your system, I would like you to ask me before you do any manipulations that aren't in the instructions I posted. This is to ensure that we are operating in sync and I know exactly what's happening on your system;
  • If you aren't sure about an instruction I'm giving you, ask me about it. This is to ensure that the clean-up process goes without any issue. I'll answer you and even give you more precise instructions/explanations if you need. There's no shame in asking questions here, better be safe than sorry!;
  • If you don't reply to your thread within 3 days, I'll bump this thread to let you know that I'm waiting for you. If you don't reply after 5 days, it'll be closed. If you return after that period, you can send me a PM to get it unlocked and we'll continue where we left off;
  • Since malware can work quickly, we want to get rid of them as fast as we can, before they make unknown changes to the system. This being said, I would appreciate if you could reply to this thread within 24 hours of me posting. This way, we'll have a good clean-up rhythm and the chances of complications will be reduced;
  • I'm against any form of pirated, illegal and counterfeit software and material. So if you have any installed on your system, I'll ask you to uninstall them right now. You don't have to tell me if you indeed had some or not, I'll give you the benefit of the doubt. Plus, this would be against BleepingComputer's rules;
  • In the end, you are the one asking for assistance here. So if you wish to go a different way during the clean-up, like format and reinstall Windows, you are free to do so. I would appreciate you to let me know about it first, and if you need, I can also assist you in the process;
  • I would appreciate if you were to stay with me until the end, which means, until I declare your system clean. Just because your system isn't behaving weirdly anymore, or is running better than before, it doesn't mean that the infection is completely gone;
    This being said, I have a full time job so sometimes it'll take longer for me to reply to you. Don't worry, you'll be my first priority as soon as I get home and have time to look at your thread;
This being said, it's time to clean-up some malware, so let's get started, shall we? :)
 
Follow the instructions in the thread below. Make sure to download the MBAR linked in it. Let me know if you're not able to launch it and run a scan.
 
https://forums.malwarebytes.com/topic/198907-requested-resource-is-in-use-error-unable-to-start-malwarebytes/
 
If you manage to run a scan, delete everything it finds, and then copy/paste the content of the "mbar-log-TODAY'S-DATE.txt" log that is located in the MBAR folder here after.

 

So ran MBAR but the log is so big I can't paste it here. It just crashes my browser. I'm going to try to upload it to google drive and then paste the link

After MBAR ran, I ran Malware bytes, and here's the log for that : https://pastebin.com/MAsvEiHF

 

https://drive.google.com/file/d/0B_J3X_IYyEfTRkVCZWwyNGNFOHM/view?usp=sharing

There's the log for MBAR. Thanks for the help.

Looking in command prompt, the Trojan APPEARS to be gone, though I understand looks can be deceiving, and further actions may need to be taken.



#5 Aura

Aura

    Bleepin' Special Ops


  • Malware Response Team
  • 19,697 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:12:29 PM

Posted 04 July 2017 - 07:25 AM

MBAR will cripple SmartService by removing most of it, and Malwarebytes will remove the rest. Though we'll still run AdwCleaner and JRT to clean up all the PUPs, Adware, etc. that were dropped on the system alongside SmartService.

zcMPezJ.pngAdwCleaner - Fix Mode
  • Download AdwCleaner and move it to your Desktop;
  • Right-click on AdwCleaner.exe and select Spcusrh.pngRun as Administrator (for Windows Vista, 7, 8, 8.1 and 10 users);
  • Accept the EULA (I accept), let the database update, then click on Scan;
  • Let the scan complete. Once it's done, make sure that every item listed in the different tabs is checked and click on the Cleaning button. This will kill all the active processes;
    MV5ejgW.png
  • Once the cleaning process is complete, AdwCleaner will ask to restart your computer, do it;
  • After the restart, a log will open when logging in. Please copy/paste the content of that log in your next reply;
iT103hr.pngJunkware Removal Tool (JRT)
  • Download Junkware Removal Tool (JRT) and move it to your Desktop;
  • Right-click on JRT.exe and select Spcusrh.pngRun as Administrator (for Windows Vista, 7, 8, 8.1 and 10 users);
  • Press on any key to launch the scan and let it complete;
    tLsXbWy.png
    Credits : BleepingComputer.com
  • Once the scan is complete, a log will open. Please copy/paste the content of the output log in your next reply;
Your next reply(ies) should therefore contain:
  • Copy/pasted AdwCleaner clean log;
  • Copy/pasted JRT log;

animinionsmalltext.gif
unite_blue.png
Security Administrator | Sysnative Windows Update Senior Analyst | Malware Hunter | @SecurityAura
My timezone UTC-05:00 (East. Coast). If I didn't reply to you within 48 hours, please send me a PM.


#6 Phiki

Phiki
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:06:29 PM

Posted 04 July 2017 - 11:14 AM

MBAR will cripple SmartService by removing most of it, and Malwarebytes will remove the rest. Though we'll still run AdwCleaner and JRT to clean up all the PUPs, Adware, etc. that were dropped on the system alongside SmartService.

zcMPezJ.pngAdwCleaner - Fix Mode

  • Download AdwCleaner and move it to your Desktop;
  • Right-click on AdwCleaner.exe and select Spcusrh.pngRun as Administrator (for Windows Vista, 7, 8, 8.1 and 10 users);
  • Accept the EULA (I accept), let the database update, then click on Scan;
  • Let the scan complete. Once it's done, make sure that every item listed in the different tabs is checked and click on the Cleaning button. This will kill all the active processes;
    MV5ejgW.png
  • Once the cleaning process is complete, AdwCleaner will ask to restart your computer, do it;
  • After the restart, a log will open when logging in. Please copy/paste the content of that log in your next reply;
iT103hr.pngJunkware Removal Tool (JRT)
  • Download Junkware Removal Tool (JRT) and move it to your Desktop;
  • Right-click on JRT.exe and select Spcusrh.pngRun as Administrator (for Windows Vista, 7, 8, 8.1 and 10 users);
  • Press on any key to launch the scan and let it complete;
    tLsXbWy.png
    Credits : BleepingComputer.com
  • Once the scan is complete, a log will open. Please copy/paste the content of the output log in your next reply;
Your next reply(ies) should therefore contain:
  • Copy/pasted AdwCleaner clean log;
  • Copy/pasted JRT log;

 

ADWCleaner:

# AdwCleaner v6.047 - Logfile created 04/07/2017 at 11:57:40
# Updated on 19/05/2017 by Malwarebytes
# Database : 2017-06-29.3 [Local]
# Operating System : Windows 10 Pro  (X64)
# Username : Phikicheli - DESKTOP
# Running from : C:\Users\Phikicheli\Desktop\AdwCleaner(1).exe
# Mode: Clean
# Support : https://www.malwarebytes.com/support



***** [ Services ] *****



***** [ Folders ] *****

[-] Folder deleted: C:\Users\Phikicheli\AppData\Local\llssoft
[-] Folder deleted: C:\Program Files\Plumbytes Software


***** [ Files ] *****



***** [ DLL ] *****



***** [ WMI ] *****



***** [ Shortcuts ] *****



***** [ Scheduled Tasks ] *****



***** [ Registry ] *****

[-] Key deleted: [x64] HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\services\Dataup
[#] Key deleted on reboot: [x64] HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\services\dataup


***** [ Web browsers ] *****



*************************

:: "Tracing" keys deleted
:: Winsock settings cleared

*************************

C:\AdwCleaner\AdwCleaner[C0].txt - [3016 Bytes] - [02/07/2017 04:17:17]
C:\AdwCleaner\AdwCleaner[C2].txt - [1121 Bytes] - [04/07/2017 11:57:40]
C:\AdwCleaner\AdwCleaner[S0].txt - [2869 Bytes] - [02/07/2017 04:14:03]
C:\AdwCleaner\AdwCleaner[S1].txt - [1497 Bytes] - [04/07/2017 11:57:16]

########## EOF - C:\AdwCleaner\AdwCleaner[C2].txt - [1340 Bytes] ##########
 

 

 

 

 

JRT:

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.1.3 (04.10.2017)
Operating System: Windows 10 Pro x64
Ran by Phikicheli (Administrator) on Tue 07/04/2017 at 12:03:51.88
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




File System: 1

Successfully deleted: C:\Users\Phikicheli\AppData\Roaming\getrighttogo (Folder)



Registry: 0





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Tue 07/04/2017 at 12:13:28.93
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 



#7 Aura

Aura

    Bleepin' Special Ops


  • Malware Response Team
  • 19,697 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:12:29 PM

Posted 04 July 2017 - 11:56 AM

Good. Now let's run a scan with FRST and look for remnants.

iO3R662.pngFarbar Recovery Scan Tool (FRST) - Scan mode
Follow the instructions below to download and execute a scan on your system with FRST, and provide the logs in your next reply.
  • Download the right version of FRST for your system:
  • Move the executable (FRST.exe or FRST64.exe) on your Desktop;
  • Right-click on the executable and select Spcusrh.pngRun as Administrator (for Windows Vista, 7, 8, 8.1 and 10 users);
  • Accept the disclaimer by clicking on Yes, and FRST will then do a back-up of your Registry which should take a few seconds;
  • Make sure the Addition.txt box is checked;
  • Click on the Scan button;
    KSJwAxg.png
  • On completion, two message box will open, saying that the results were saved to FRST.txt and Addition.txt, then open two Notepad files;
  • Copy and paste the content of both FRST.txt and Addition.txt in your next reply;

animinionsmalltext.gif
unite_blue.png
Security Administrator | Sysnative Windows Update Senior Analyst | Malware Hunter | @SecurityAura
My timezone UTC-05:00 (East. Coast). If I didn't reply to you within 48 hours, please send me a PM.


#8 Phiki

Phiki
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:06:29 PM

Posted 04 July 2017 - 12:13 PM

Good. Now let's run a scan with FRST and look for remnants.

iO3R662.pngFarbar Recovery Scan Tool (FRST) - Scan mode
Follow the instructions below to download and execute a scan on your system with FRST, and provide the logs in your next reply.

  • Download the right version of FRST for your system:
  • Move the executable (FRST.exe or FRST64.exe) on your Desktop;
  • Right-click on the executable and select Spcusrh.pngRun as Administrator (for Windows Vista, 7, 8, 8.1 and 10 users);
  • Accept the disclaimer by clicking on Yes, and FRST will then do a back-up of your Registry which should take a few seconds;
  • Make sure the Addition.txt box is checked;
  • Click on the Scan button;
    KSJwAxg.png
  • On completion, two message box will open, saying that the results were saved to FRST.txt and Addition.txt, then open two Notepad files;
  • Copy and paste the content of both FRST.txt and Addition.txt in your next reply;

 

FRST.txt

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 03-07-2017 01
Ran by Phikicheli (administrator) on DESKTOP (04-07-2017 13:03:12)
Running from C:\Users\Phikicheli\Desktop
Loaded Profiles: Phikicheli (Available Profiles: defaultuser0 & Phikicheli)
Platform: Windows 10 Pro Version 1607 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: "C:\Program Files\Waterfox\waterfox.exe" -osint -url "%1")
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Rivet Networks) C:\Program Files\Killer Networking\Network Manager\KillerService.exe
(Scarlet.Crush Productions) C:\Users\Phikicheli\Desktop\ScpServer\bin\ScpService.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
(IvoSoft) C:\Program Files\Classic Shell\ClassicStartMenu.exe
() C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.18.614.0_x64__kzf8qxf38zg5c\SkypeHost.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\ShadowPlay\nvspcaps64.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\ShadowPlay\nvsphelper64.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe
(Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
() C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.18062.12990.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
(Mozilla Corporation) C:\Program Files\Waterfox\waterfox.exe

==================== Registry (Whitelisted) ====================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [WindowsDefender] => C:\Program Files\Windows Defender\MSASCuiL.exe [631808 2017-04-27] (Microsoft Corporation)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [9037832 2016-12-05] (Realtek Semiconductor)
HKLM\...\Run: [ShadowPlay] => "C:\WINDOWS\system32\rundll32.exe" C:\WINDOWS\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [Classic Start Menu] => C:\Program Files\Classic Shell\ClassicStartMenu.exe [163800 2016-07-30] (IvoSoft)
HKLM\...\Run: [Malwarebytes TrayApp] => C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe [3146704 2017-05-09] (Malwarebytes)
HKU\S-1-5-21-1712185177-3340612968-1910388385-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3042592 2017-06-08] (Valve Corporation)
HKU\S-1-5-21-1712185177-3340612968-1910388385-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Users\Phikicheli\Documents\videoscreensaver\VideoScreensaver.scr [135680 2012-11-07] (Michael Barnathan)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 75.75.75.75 75.75.76.76
Tcpip\..\Interfaces\{371a21d2-2e17-416e-9f3d-fc6d35cbfced}: [DhcpNameServer] 75.75.75.75 75.75.76.76

Internet Explorer:
==================
BHO: ExplorerBHO Class -> {449D0D6E-2412-4E61-B68F-1CB625CD9E52} -> C:\Program Files\Classic Shell\ClassicExplorer64.dll [2016-07-30] (IvoSoft)
BHO: ClassicIEBHO Class -> {EA801577-E6AD-4BD5-8F71-4BE0154331A4} -> C:\Program Files\Classic Shell\ClassicIEDLL_64.dll [2016-07-30] (IvoSoft)
BHO-x32: ExplorerBHO Class -> {449D0D6E-2412-4E61-B68F-1CB625CD9E52} -> C:\Program Files\Classic Shell\ClassicExplorer32.dll [2016-07-30] (IvoSoft)
BHO-x32: ClassicIEBHO Class -> {EA801577-E6AD-4BD5-8F71-4BE0154331A4} -> C:\Program Files\Classic Shell\ClassicIEDLL_32.dll [2016-07-30] (IvoSoft)
Toolbar: HKLM - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer64.dll [2016-07-30] (IvoSoft)
Toolbar: HKLM-x32 - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll [2016-07-30] (IvoSoft)

FireFox:
========
FF DefaultProfile: 3b2os9s3.default
FF ProfilePath: C:\Users\Phikicheli\AppData\Roaming\Mozilla\Firefox\Profiles\3b2os9s3.default [2017-07-04]
FF NewTab: Mozilla\Firefox\Profiles\3b2os9s3.default -> file:///C:/Users/Phikicheli/Documents/startpage.rwrt-master/Index.html
FF Homepage: Mozilla\Firefox\Profiles\3b2os9s3.default -> file:///C:/Users/Phikicheli/Documents/startpage.rwrt-master/Index.html
FF NetworkProxy: Mozilla\Firefox\Profiles\3b2os9s3.default -> autoconfig_url", "data:text/plain, function FindProxyForURL(url, host) {if(isInNet(host, '192.168.0.0', '255.255.0.0')) return 'DIRECT'; \nif(host == 'us1-base.cd-n.net') return 'DIRECT'; \nif(host == 'us2-base.cd-n.net') return 'DIRECT'; \nif(host == 'us3-base.cd-n.net') return 'DIRECT'; \nif(host == 'jp1-base.cd-n.net') return 'DIRECT'; \nif(host == 'de-base.cd-n.net') return 'DIRECT'; \nif(host == 'au1-base.cd-n.net') return 'DIRECT'; \nif(host == 'ir1-base.cd-n.net') return 'DIRECT'; \nif(host == 'sg1-base.cd-n.net') return 'DIRECT'; \nif(host == 'kr1-base.cd-n.net') return 'DIRECT'; \nif(host == 'us0-base.cd-n.net') return 'DIRECT'; \nif(host == '127.0.0.1') return 'DIRECT'; \nif(host == 'localhost') return 'DIRECT'; \nif(host == 'us1-base.cd-n.net') return 'DIRECT'; \nreturn 'HTTPS gy3s4mrqguxdcnrtfyytaojdge2dsobzguztmmbq.2po.info:443';}"
FF NetworkProxy: Mozilla\Firefox\Profiles\3b2os9s3.default -> type", 0
FF Extension: (Hoxx VPN Proxy) - C:\Users\Phikicheli\AppData\Roaming\Mozilla\Firefox\Profiles\3b2os9s3.default\Extensions\@hoxx-vpn.xpi [2017-06-06]
FF Extension: (BetterTTV) - C:\Users\Phikicheli\AppData\Roaming\Mozilla\Firefox\Profiles\3b2os9s3.default\Extensions\firefox@betterttv.net.xpi [2017-01-04]
FF Extension: (FrankerFaceZ) - C:\Users\Phikicheli\AppData\Roaming\Mozilla\Firefox\Profiles\3b2os9s3.default\Extensions\jid1-snHdAu6px3p0jA@jetpack.xpi [2017-06-15]
FF Extension: (New Tab Override (browser.newtab.url replacement)) - C:\Users\Phikicheli\AppData\Roaming\Mozilla\Firefox\Profiles\3b2os9s3.default\Extensions\newtaboverride@agenedia.com.xpi [2017-02-21]
FF Extension: (Menu Wizard) - C:\Users\Phikicheli\AppData\Roaming\Mozilla\Firefox\Profiles\3b2os9s3.default\Extensions\s3menu@wizard.xpi [2017-05-31]
FF Extension: (uBlock Origin) - C:\Users\Phikicheli\AppData\Roaming\Mozilla\Firefox\Profiles\3b2os9s3.default\Extensions\uBlock0@raymondhill.net.xpi [2017-06-27]
FF Extension: (Stylish) - C:\Users\Phikicheli\AppData\Roaming\Mozilla\Firefox\Profiles\3b2os9s3.default\Extensions\{46551EC9-40F0-4e47-8E18-8E5CF550CFB8}.xpi [2016-12-14]
FF Extension: (Download Status Bar) - C:\Users\Phikicheli\AppData\Roaming\Mozilla\Firefox\Profiles\3b2os9s3.default\Extensions\{6c28e999-e900-4635-a39d-b1ec90ba0c0f}.xpi [2016-12-14]
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2016-12-29] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2016-12-29] (NVIDIA Corporation)
StartMenuInternet: Firefox-6F940AC27A98DD61 - C:\Program Files\Waterfox\waterfox.exe

Chrome:
=======
CHR Profile: C:\Users\Phikicheli\AppData\Local\Google\Chrome\User Data\Default [2017-07-01]
CHR Extension: (Google Slides) - C:\Users\Phikicheli\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-12-16]
CHR Extension: (Docs) - C:\Users\Phikicheli\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-12-16]
CHR Extension: (Google Drive) - C:\Users\Phikicheli\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-12-16]
CHR Extension: (YouTube) - C:\Users\Phikicheli\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-12-16]
CHR Extension: (Google Docs Offline) - C:\Users\Phikicheli\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-12-16]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Phikicheli\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-12-16]
CHR Extension: (Gmail) - C:\Users\Phikicheli\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-12-16]

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 Ds3Service; C:\Users\Phikicheli\Desktop\ScpServer\bin\ScpService.exe [381952 2014-03-13] (Scarlet.Crush Productions) [File not signed]
R2 Killer Service V2; C:\Program Files\Killer Networking\Network Manager\KillerService.exe [457104 2016-12-05] (Rivet Networks)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4470736 2017-05-09] (Malwarebytes)
R2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [495224 2017-06-21] (NVIDIA Corporation)
S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [495224 2017-06-21] (NVIDIA Corporation)
R2 NVDisplay.ContainerLocalSystem; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [458176 2016-12-29] (NVIDIA Corporation)
R2 NvTelemetryContainer; C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe [450168 2017-06-21] (NVIDIA Corporation)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [2889896 2016-09-15] (Microsoft Corporation)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347320 2017-04-27] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103712 2017-04-27] (Microsoft Corporation)
S2 NVIDIA Wireless Controller Service; "C:\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe" [X]

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R1 BfLwf; C:\WINDOWS\system32\DRIVERS\bwcW10x64.sys [145736 2016-09-19] (Rivet Networks, LLC.)
R3 CorsairVBusDriver; C:\WINDOWS\System32\drivers\CorsairVBusDriver.sys [45016 2017-05-16] (Corsair)
R3 CorsairVHidDriver; C:\WINDOWS\System32\drivers\CorsairVHidDriver.sys [21976 2017-05-16] (Corsair)
R1 ESProtectionDriver; C:\WINDOWS\system32\drivers\mbae64.sys [77376 2017-06-27] ()
R3 KillerEth; C:\WINDOWS\System32\drivers\e2xw10x64.sys [162120 2016-09-16] (Qualcomm Atheros, Inc.)
R2 MBAMChameleon; C:\WINDOWS\system32\drivers\MBAMChameleon.sys [188352 2017-07-04] (Malwarebytes)
R3 MBAMFarflt; C:\WINDOWS\system32\drivers\farflt.sys [101784 2017-07-04] (Malwarebytes)
R3 MBAMProtection; C:\WINDOWS\system32\drivers\mbam.sys [45472 2017-07-04] (Malwarebytes)
R0 MBAMSwissArmy; C:\WINDOWS\System32\drivers\MBAMSwissArmy.sys [253856 2017-07-04] (Malwarebytes)
R3 MBAMWebProtection; C:\WINDOWS\system32\drivers\mwac.sys [93600 2017-07-04] (Malwarebytes)
R1 MpKslb94c9352; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{2CEE67D0-2536-4CD1-9C9E-52D2AA8612DE}\MpKslb94c9352.sys [44928 2017-07-04] (Microsoft Corporation)
S3 NetAdapterCx; C:\WINDOWS\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] ()
R3 nvlddmkm; C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispiwu.inf_amd64_b67dc924fff8de6d\nvlddmkm.sys [14199224 2017-01-04] (NVIDIA Corporation)
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [30328 2017-06-21] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\WINDOWS\system32\drivers\nvvad64v.sys [48248 2017-06-21] (NVIDIA Corporation)
R3 nvvhci; C:\WINDOWS\System32\drivers\nvvhci.sys [57976 2017-06-21] (NVIDIA Corporation)
R3 ScpVBus; C:\WINDOWS\System32\drivers\ScpVBus.sys [39168 2013-05-19] (Scarlet.Crush Productions)
R3 ssdevfactory; C:\WINDOWS\System32\drivers\ssdevfactory.sys [46408 2017-06-01] (SteelSeries ApS)
R3 sshid; C:\WINDOWS\System32\drivers\sshid.sys [45904 2017-06-19] (SteelSeries ApS)
S0 WdBoot; C:\WINDOWS\System32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation)
R1 ZAM_Guard; C:\WINDOWS\System32\drivers\zamguard64.sys [203680 2017-07-01] (Zemana Ltd.)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-07-04 13:03 - 2017-07-04 13:04 - 00014332 _____ C:\Users\Phikicheli\Desktop\FRST.txt
2017-07-04 13:03 - 2017-07-04 13:03 - 00000000 ____D C:\FRST
2017-07-04 13:02 - 2017-07-04 13:02 - 02436096 _____ (Farbar) C:\Users\Phikicheli\Desktop\FRST64.exe
2017-07-04 12:13 - 2017-07-04 12:13 - 00000641 _____ C:\Users\Phikicheli\Desktop\JRT.txt
2017-07-04 12:02 - 2017-07-04 12:02 - 01663672 _____ (Malwarebytes) C:\Users\Phikicheli\Desktop\JRT.exe
2017-07-04 11:51 - 2017-07-04 11:52 - 04110280 _____ C:\Users\Phikicheli\Desktop\AdwCleaner(1).exe
2017-07-04 01:34 - 2017-07-04 01:34 - 00253856 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\77CD2542.sys
2017-07-04 01:34 - 2017-07-04 01:34 - 00188352 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMChameleon.sys
2017-07-04 01:33 - 2017-07-04 12:06 - 00093600 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys
2017-07-04 01:33 - 2017-07-04 11:59 - 00253856 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2017-07-04 01:33 - 2017-07-04 11:59 - 00101784 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\farflt.sys
2017-07-04 01:33 - 2017-07-04 11:59 - 00045472 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
2017-07-03 18:11 - 2017-07-04 01:50 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2017-07-03 18:11 - 2017-07-04 00:01 - 00000000 ____D C:\Users\Phikicheli\Desktop\mbar
2017-07-03 18:10 - 2017-07-03 18:10 - 16564750 _____ (Malwarebytes Corp.) C:\Users\Phikicheli\Downloads\mbar-1.09.4.1001.exe
2017-07-03 04:11 - 2017-07-03 04:11 - 00000000 ____D C:\$WINDOWS.~BT
2017-07-03 04:10 - 2017-07-03 04:12 - 00000000 ___HD C:\$SysReset
2017-07-02 16:41 - 2017-07-04 01:32 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2017-07-02 16:40 - 2017-07-02 16:40 - 10284816 _____ (Malwarebytes Corporation ) C:\Users\Phikicheli\Downloads\mbam-setup-1.75.0.1300.exe
2017-07-02 14:09 - 2017-07-02 14:09 - 00167034 _____ C:\Users\Phikicheli\Downloads\fileassassin-setup-1.06.exe
2017-07-02 13:00 - 2017-07-02 13:00 - 00397241 _____ C:\Users\Phikicheli\Downloads\roex.zip
2017-07-02 13:00 - 2017-07-02 13:00 - 00000000 ____D C:\Users\Phikicheli\Downloads\roex
2017-07-02 12:56 - 2016-06-28 11:41 - 00374944 _____ (Sysinternals - www.sysinternals.com) C:\WINDOWS\system32\PsExec64.exe
2017-07-02 12:30 - 2017-07-03 07:21 - 00000214 _____ C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job
2017-07-02 12:21 - 2017-07-02 12:21 - 00000000 ____D C:\WINDOWS\pss
2017-07-02 12:14 - 2017-07-02 12:41 - 00000000 ____D C:\Users\Phikicheli\Desktop\Autoruns
2017-07-02 11:51 - 2017-07-02 11:51 - 05918854 _____ C:\Users\Phikicheli\Downloads\Mpeg4watcher_1_0_4_keygen.zip
2017-07-02 04:07 - 2017-07-02 13:29 - 00006150 _____ C:\Users\Phikicheli\Desktop\Rkill.txt
2017-07-02 04:07 - 2017-07-02 04:07 - 02030536 _____ (Bleeping Computer, LLC) C:\Users\Phikicheli\Downloads\rkill.exe
2017-07-02 04:04 - 2017-07-04 11:57 - 00000000 ____D C:\AdwCleaner
2017-07-02 04:04 - 2017-07-04 01:32 - 00001912 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2017-07-02 04:04 - 2017-07-04 01:32 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2017-07-02 04:04 - 2017-06-27 12:06 - 00077376 _____ C:\WINDOWS\system32\Drivers\mbae64.sys
2017-07-02 04:03 - 2017-07-02 16:41 - 00000000 ____D C:\ProgramData\Malwarebytes
2017-07-02 04:03 - 2017-07-02 04:03 - 00000000 ____D C:\Program Files\Malwarebytes
2017-07-02 04:02 - 2017-07-02 04:02 - 04110280 _____ C:\Users\Phikicheli\Downloads\AdwCleaner.exe
2017-07-02 04:01 - 2017-07-02 04:02 - 64025992 _____ (Malwarebytes ) C:\Users\Phikicheli\Downloads\mb3-setup-1878.1878-3.1.2.1733-10139.exe
2017-07-02 02:51 - 2017-07-02 02:51 - 00003372 _____ C:\WINDOWS\System32\Tasks\{9214DA17-6D07-47E0-A3C0-86794308B628}
2017-07-02 02:50 - 2017-07-02 02:51 - 00000000 ____D C:\Program Files\UNP
2017-07-02 02:50 - 2017-07-02 02:50 - 00000000 ____D C:\WINDOWS\system32\UNP
2017-07-02 02:43 - 2017-07-02 02:43 - 00004000 _____ C:\WINDOWS\System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-07-02 02:42 - 2017-07-02 02:42 - 00004308 _____ C:\WINDOWS\System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-07-02 02:42 - 2017-07-02 02:42 - 00000000 ____D C:\WINDOWS\LastGood.Tmp
2017-07-02 02:42 - 2017-06-20 16:58 - 00001951 _____ C:\WINDOWS\NvTelemetryContainerRecovery.bat
2017-07-02 02:41 - 2017-06-21 03:07 - 00179320 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvaudcap64v.dll
2017-07-02 02:41 - 2017-06-21 03:07 - 00146552 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvaudcap32v.dll
2017-07-02 02:41 - 2017-06-21 03:07 - 00057976 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvvhci.sys
2017-07-02 02:31 - 2017-07-02 02:31 - 00000000 ____D C:\WINDOWS\Minidump
2017-07-02 02:05 - 2010-06-02 04:55 - 00527192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_7.dll
2017-07-02 02:05 - 2010-06-02 04:55 - 00518488 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_7.dll
2017-07-02 02:05 - 2010-06-02 04:55 - 00239960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_7.dll
2017-07-02 02:05 - 2010-06-02 04:55 - 00176984 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_7.dll
2017-07-02 02:05 - 2010-06-02 04:55 - 00077656 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_5.dll
2017-07-02 02:05 - 2010-06-02 04:55 - 00074072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_5.dll
2017-07-02 02:05 - 2010-05-26 11:41 - 01907552 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dcsx_43.dll
2017-07-02 02:05 - 2010-05-26 11:41 - 01868128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dcsx_43.dll
2017-07-02 02:05 - 2010-02-04 10:01 - 00530776 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_6.dll
2017-07-02 02:05 - 2010-02-04 10:01 - 00528216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_6.dll
2017-07-02 02:05 - 2010-02-04 10:01 - 00238936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_6.dll
2017-07-02 02:05 - 2010-02-04 10:01 - 00176984 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_6.dll
2017-07-02 02:05 - 2010-02-04 10:01 - 00078680 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_4.dll
2017-07-02 02:05 - 2010-02-04 10:01 - 00074072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_4.dll
2017-07-02 02:05 - 2010-02-04 10:01 - 00024920 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_7.dll
2017-07-02 02:05 - 2010-02-04 10:01 - 00022360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\X3DAudio1_7.dll
2017-07-02 02:05 - 2009-09-04 17:44 - 00517960 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_5.dll
2017-07-02 02:05 - 2009-09-04 17:44 - 00515416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_5.dll
2017-07-02 02:05 - 2009-09-04 17:44 - 00238936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_5.dll
2017-07-02 02:05 - 2009-09-04 17:44 - 00176968 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_5.dll
2017-07-02 02:05 - 2009-09-04 17:44 - 00073544 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_3.dll
2017-07-02 02:05 - 2009-09-04 17:44 - 00069464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_3.dll
2017-07-02 02:05 - 2009-09-04 17:29 - 05554512 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dcsx_42.dll
2017-07-02 02:05 - 2009-09-04 17:29 - 05501792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dcsx_42.dll
2017-07-02 02:05 - 2009-09-04 17:29 - 02582888 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_42.dll
2017-07-02 02:05 - 2009-09-04 17:29 - 02475352 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_42.dll
2017-07-02 02:05 - 2009-09-04 17:29 - 01974616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_42.dll
2017-07-02 02:05 - 2009-09-04 17:29 - 01892184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_42.dll
2017-07-02 02:05 - 2009-09-04 17:29 - 00523088 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_42.dll
2017-07-02 02:05 - 2009-09-04 17:29 - 00453456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_42.dll
2017-07-02 02:05 - 2009-09-04 17:29 - 00285024 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx11_42.dll
2017-07-02 02:05 - 2009-09-04 17:29 - 00235344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx11_42.dll
2017-07-02 02:05 - 2009-03-16 14:18 - 00521560 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_4.dll
2017-07-02 02:05 - 2009-03-16 14:18 - 00517448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_4.dll
2017-07-02 02:05 - 2009-03-16 14:18 - 00235352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_4.dll
2017-07-02 02:05 - 2009-03-16 14:18 - 00174936 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_4.dll
2017-07-02 02:05 - 2009-03-09 15:27 - 05425496 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_41.dll
2017-07-02 02:05 - 2009-03-09 15:27 - 04178264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_41.dll
2017-07-02 02:05 - 2009-03-09 15:27 - 02430312 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_41.dll
2017-07-02 02:05 - 2009-03-09 15:27 - 01846632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_41.dll
2017-07-02 02:05 - 2009-03-09 15:27 - 00520544 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_41.dll
2017-07-02 02:05 - 2009-03-09 15:27 - 00453456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_41.dll
2017-07-02 02:04 - 2009-03-16 14:18 - 00024920 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_6.dll
2017-07-02 02:04 - 2009-03-16 14:18 - 00022360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\X3DAudio1_6.dll
2017-07-02 02:04 - 2008-10-27 10:04 - 00518480 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_3.dll
2017-07-02 02:04 - 2008-10-27 10:04 - 00514384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_3.dll
2017-07-02 02:04 - 2008-10-27 10:04 - 00235856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_3.dll
2017-07-02 02:04 - 2008-10-27 10:04 - 00175440 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_3.dll
2017-07-02 02:04 - 2008-10-27 10:04 - 00074576 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_2.dll
2017-07-02 02:04 - 2008-10-27 10:04 - 00070992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_2.dll
2017-07-02 02:04 - 2008-10-27 10:04 - 00025936 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_5.dll
2017-07-02 02:04 - 2008-10-27 10:04 - 00023376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\X3DAudio1_5.dll
2017-07-02 02:04 - 2008-10-15 06:22 - 05631312 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_40.dll
2017-07-02 02:04 - 2008-10-15 06:22 - 04379984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_40.dll
2017-07-02 02:04 - 2008-10-15 06:22 - 02605920 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_40.dll
2017-07-02 02:04 - 2008-10-15 06:22 - 02036576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_40.dll
2017-07-02 02:04 - 2008-10-15 06:22 - 00519000 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_40.dll
2017-07-02 02:04 - 2008-10-15 06:22 - 00452440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_40.dll
2017-07-02 02:04 - 2008-07-31 10:41 - 00238088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_2.dll
2017-07-02 02:04 - 2008-07-31 10:41 - 00177672 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_2.dll
2017-07-02 02:04 - 2008-07-31 10:41 - 00072200 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_1.dll
2017-07-02 02:04 - 2008-07-31 10:41 - 00068616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_1.dll
2017-07-02 02:04 - 2008-07-31 10:40 - 00513544 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_2.dll
2017-07-02 02:04 - 2008-07-31 10:40 - 00509448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_2.dll
2017-07-02 02:04 - 2008-07-10 11:01 - 00467984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_39.dll
2017-07-02 02:04 - 2008-07-10 11:00 - 04992520 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_39.dll
2017-07-02 02:04 - 2008-07-10 11:00 - 03851784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_39.dll
2017-07-02 02:04 - 2008-07-10 11:00 - 01942552 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_39.dll
2017-07-02 02:04 - 2008-07-10 11:00 - 01493528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_39.dll
2017-07-02 02:04 - 2008-07-10 11:00 - 00540688 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_39.dll
2017-07-02 02:04 - 2008-05-30 14:19 - 00511496 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_1.dll
2017-07-02 02:04 - 2008-05-30 14:19 - 00507400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_1.dll
2017-07-02 02:04 - 2008-05-30 14:18 - 00238088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_1.dll
2017-07-02 02:04 - 2008-05-30 14:18 - 00177672 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_1.dll
2017-07-02 02:04 - 2008-05-30 14:17 - 00068104 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_0.dll
2017-07-02 02:04 - 2008-05-30 14:17 - 00065032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_0.dll
2017-07-02 02:04 - 2008-05-30 14:17 - 00025608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\X3DAudio1_4.dll
2017-07-02 02:04 - 2008-05-30 14:16 - 00028168 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_4.dll
2017-07-02 02:04 - 2008-05-30 14:11 - 04991496 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_38.dll
2017-07-02 02:04 - 2008-05-30 14:11 - 03850760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_38.dll
2017-07-02 02:04 - 2008-05-30 14:11 - 01941528 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_38.dll
2017-07-02 02:04 - 2008-05-30 14:11 - 01491992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_38.dll
2017-07-02 02:04 - 2008-05-30 14:11 - 00540688 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_38.dll
2017-07-02 02:04 - 2008-05-30 14:11 - 00467984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_38.dll
2017-07-02 02:04 - 2008-03-05 16:04 - 00489480 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_0.dll
2017-07-02 02:04 - 2008-03-05 16:03 - 00479752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_0.dll
2017-07-02 02:04 - 2008-03-05 16:03 - 00238088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_0.dll
2017-07-02 02:04 - 2008-03-05 16:03 - 00177672 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_0.dll
2017-07-02 02:04 - 2008-03-05 16:00 - 00028168 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_3.dll
2017-07-02 02:04 - 2008-03-05 16:00 - 00025608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\X3DAudio1_3.dll
2017-07-02 02:04 - 2008-03-05 15:56 - 04910088 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_37.dll
2017-07-02 02:04 - 2008-03-05 15:56 - 03786760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_37.dll
2017-07-02 02:04 - 2008-03-05 15:56 - 01860120 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_37.dll
2017-07-02 02:04 - 2008-03-05 15:56 - 01420824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_37.dll
2017-07-02 02:04 - 2008-02-05 23:07 - 00529424 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_37.dll
2017-07-02 02:04 - 2008-02-05 23:07 - 00462864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_37.dll
2017-07-02 02:04 - 2007-10-22 03:40 - 00411656 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_10.dll
2017-07-02 02:04 - 2007-10-22 03:39 - 00267272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_10.dll
2017-07-02 02:04 - 2007-10-22 03:37 - 00021000 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_2.dll
2017-07-02 02:04 - 2007-10-22 03:37 - 00017928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\X3DAudio1_2.dll
2017-07-02 02:04 - 2007-10-12 15:14 - 05081608 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_36.dll
2017-07-02 02:04 - 2007-10-12 15:14 - 03734536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_36.dll
2017-07-02 02:04 - 2007-10-12 15:14 - 02006552 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_36.dll
2017-07-02 02:04 - 2007-10-12 15:14 - 01374232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_36.dll
2017-07-02 02:04 - 2007-10-02 09:56 - 00508264 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_36.dll
2017-07-02 02:04 - 2007-10-02 09:56 - 00444776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_36.dll
2017-07-02 02:04 - 2007-07-20 00:57 - 00411496 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_9.dll
2017-07-02 02:04 - 2007-07-20 00:57 - 00267112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_9.dll
2017-07-02 02:04 - 2007-07-19 18:14 - 05073256 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_35.dll
2017-07-02 02:04 - 2007-07-19 18:14 - 03727720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_35.dll
2017-07-02 02:04 - 2007-07-19 18:14 - 01985904 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_35.dll
2017-07-02 02:04 - 2007-07-19 18:14 - 01358192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_35.dll
2017-07-02 02:04 - 2007-07-19 18:14 - 00508264 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_35.dll
2017-07-02 02:04 - 2007-07-19 18:14 - 00444776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_35.dll
2017-07-02 02:04 - 2007-06-20 20:49 - 00409960 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_8.dll
2017-07-02 02:04 - 2007-06-20 20:46 - 00266088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_8.dll
2017-07-02 02:04 - 2007-05-16 16:45 - 04496232 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_34.dll
2017-07-02 02:04 - 2007-05-16 16:45 - 03497832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_34.dll
2017-07-02 02:04 - 2007-05-16 16:45 - 01401200 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_34.dll
2017-07-02 02:04 - 2007-05-16 16:45 - 01124720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_34.dll
2017-07-02 02:04 - 2007-05-16 16:45 - 00506728 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_34.dll
2017-07-02 02:04 - 2007-05-16 16:45 - 00443752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_34.dll
2017-07-02 02:04 - 2007-04-04 18:55 - 00403304 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_7.dll
2017-07-02 02:04 - 2007-04-04 18:55 - 00261480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_7.dll
2017-07-02 02:04 - 2007-03-15 16:57 - 00506728 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_33.dll
2017-07-02 02:04 - 2007-03-15 16:57 - 00443752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_33.dll
2017-07-02 02:04 - 2007-03-12 16:42 - 04494184 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_33.dll
2017-07-02 02:04 - 2007-03-12 16:42 - 03495784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_33.dll
2017-07-02 02:04 - 2007-03-12 16:42 - 01400176 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_33.dll
2017-07-02 02:04 - 2007-03-12 16:42 - 01123696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_33.dll
2017-07-02 02:04 - 2007-01-24 15:27 - 00393576 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_6.dll
2017-07-02 02:04 - 2007-01-24 15:27 - 00255848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_6.dll
2017-07-02 02:04 - 2006-12-08 12:02 - 00251672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_5.dll
2017-07-02 02:04 - 2006-12-08 12:00 - 00390424 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_5.dll
2017-07-02 02:04 - 2006-11-29 13:06 - 00469264 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10.dll
2017-07-02 02:04 - 2006-11-29 13:06 - 00440080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10.dll
2017-07-02 02:03 - 2007-03-05 12:42 - 00017688 _____ (Microsoft Corporation) C:\WINDOWS\system32\x3daudio1_1.dll
2017-07-02 02:03 - 2007-03-05 12:42 - 00015128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\x3daudio1_1.dll
2017-07-02 02:03 - 2006-11-29 13:06 - 04398360 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_32.dll
2017-07-02 02:03 - 2006-11-29 13:06 - 03426072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_32.dll
2017-07-02 02:03 - 2006-09-28 16:05 - 03977496 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_31.dll
2017-07-02 02:03 - 2006-09-28 16:05 - 02414360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_31.dll
2017-07-02 02:03 - 2006-09-28 16:05 - 00237848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_4.dll
2017-07-02 02:03 - 2006-09-28 16:04 - 00364824 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_4.dll
2017-07-02 02:03 - 2006-07-28 09:31 - 00083736 _____ (Microsoft Corporation) C:\WINDOWS\system32\xinput1_2.dll
2017-07-02 02:03 - 2006-07-28 09:30 - 00363288 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_3.dll
2017-07-02 02:03 - 2006-07-28 09:30 - 00236824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_3.dll
2017-07-02 02:03 - 2006-07-28 09:30 - 00062744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xinput1_2.dll
2017-07-02 02:03 - 2006-05-31 07:24 - 00230168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_2.dll
2017-07-02 02:03 - 2006-05-31 07:22 - 00354072 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_2.dll
2017-07-02 02:03 - 2006-03-31 12:41 - 03927248 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_30.dll
2017-07-02 02:03 - 2006-03-31 12:40 - 02388176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_30.dll
2017-07-02 02:03 - 2006-03-31 12:40 - 00352464 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_1.dll
2017-07-02 02:03 - 2006-03-31 12:39 - 00229584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_1.dll
2017-07-02 02:03 - 2006-03-31 12:39 - 00083664 _____ (Microsoft Corporation) C:\WINDOWS\system32\xinput1_1.dll
2017-07-02 02:03 - 2006-03-31 12:39 - 00062672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xinput1_1.dll
2017-07-02 02:03 - 2006-02-03 08:43 - 03830992 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_29.dll
2017-07-02 02:03 - 2006-02-03 08:43 - 02332368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_29.dll
2017-07-02 02:03 - 2006-02-03 08:42 - 00355536 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_0.dll
2017-07-02 02:03 - 2006-02-03 08:42 - 00230096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_0.dll
2017-07-02 02:03 - 2006-02-03 08:41 - 00016592 _____ (Microsoft Corporation) C:\WINDOWS\system32\x3daudio1_0.dll
2017-07-02 02:03 - 2006-02-03 08:41 - 00014032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\x3daudio1_0.dll
2017-07-02 02:03 - 2005-12-05 18:09 - 03815120 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_28.dll
2017-07-02 02:03 - 2005-12-05 18:09 - 02323664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_28.dll
2017-07-02 02:03 - 2005-07-22 19:59 - 03807440 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_27.dll
2017-07-02 02:03 - 2005-07-22 19:59 - 02319568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_27.dll
2017-07-02 02:03 - 2005-05-26 15:34 - 03767504 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_26.dll
2017-07-02 02:03 - 2005-05-26 15:34 - 02297552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_26.dll
2017-07-02 02:03 - 2005-03-18 17:19 - 03823312 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_25.dll
2017-07-02 02:03 - 2005-03-18 17:19 - 02337488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_25.dll
2017-07-02 02:03 - 2005-02-05 19:45 - 03544272 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_24.dll
2017-07-02 02:03 - 2005-02-05 19:45 - 02222800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_24.dll
2017-07-02 01:59 - 2017-07-02 02:02 - 00000000 ____D C:\Users\Phikicheli\Documents\SDK
2017-07-02 01:54 - 2017-07-02 01:55 - 100271992 _____ (Microsoft Corporation) C:\Users\Phikicheli\Downloads\directx_Jun2010_redist.exe
2017-07-02 01:32 - 2017-07-02 01:33 - 00000000 ___SD C:\WINDOWS\UpdateAssistantV2
2017-07-02 00:54 - 2016-12-29 08:43 - 00133056 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvStreaming.exe
2017-07-02 00:54 - 2016-09-09 14:25 - 00269600 _____ C:\WINDOWS\SysWOW64\vulkan-1.dll
2017-07-02 00:54 - 2016-09-09 14:25 - 00261920 _____ C:\WINDOWS\system32\vulkan-1.dll
2017-07-02 00:54 - 2016-09-09 14:25 - 00110880 _____ C:\WINDOWS\SysWOW64\vulkaninfo.exe
2017-07-02 00:54 - 2016-09-09 14:24 - 00125216 _____ C:\WINDOWS\system32\vulkaninfo.exe
2017-07-02 00:53 - 2017-07-02 00:53 - 00000000 ____D C:\Program Files (x86)\VulkanRT
2017-07-02 00:43 - 2017-07-02 00:49 - 00000000 ____D C:\WINDOWS\system32\MRT
2017-07-02 00:43 - 2017-07-02 00:43 - 133627792 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2017-07-02 00:35 - 2017-07-02 00:35 - 00000218 _____ C:\Users\Phikicheli\AppData\Local\recently-used.xbel
2017-07-01 20:51 - 2017-07-04 13:03 - 00430445 _____ C:\WINDOWS\ZAM_Guard.krnl.trace
2017-07-01 20:51 - 2017-07-03 00:05 - 00054060 _____ C:\WINDOWS\ZAM.krnl.trace
2017-07-01 20:51 - 2017-07-01 20:51 - 00203680 _____ (Zemana Ltd.) C:\WINDOWS\system32\Drivers\zamguard64.sys
2017-07-01 20:50 - 2017-07-03 07:03 - 00000000 ____D C:\Program Files (x86)\Zemana AntiMalware
2017-07-01 20:49 - 2017-07-01 20:49 - 00000000 ____D C:\Users\Phikicheli\AppData\Local\Zemana
2017-07-01 20:43 - 2017-07-01 20:43 - 02030536 _____ (Bleeping Computer, LLC) C:\Users\Phikicheli\Downloads\rkill.com
2017-07-01 20:32 - 2017-07-03 23:44 - 00000000 ____D C:\Users\Phikicheli\AppData\Local\ljwrv
2017-07-01 20:32 - 2017-07-01 23:49 - 00000000 ____D C:\Users\Phikicheli\AppData\Local\mrcgeb
2017-07-01 20:31 - 2017-07-04 01:48 - 00000000 ____D C:\Program Files (x86)\KMSPico
2017-07-01 18:08 - 2017-07-01 18:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ultimate Marvel vs. Capcom 3
2017-07-01 17:54 - 2017-07-01 18:08 - 00000000 ____D C:\Program Files (x86)\Ultimate Marvel vs. Capcom 3
2017-07-01 17:45 - 2017-07-01 17:46 - 00000000 ____D C:\Program Files (x86)\ASIO4ALL v2
2017-07-01 17:43 - 2017-07-01 17:43 - 00000000 ____D C:\Program Files\Common Files\VST2
2017-07-01 17:43 - 2017-07-01 17:43 - 00000000 ____D C:\Program Files\Common Files\Propellerhead Software
2017-07-01 17:43 - 2017-07-01 17:43 - 00000000 ____D C:\Program Files (x86)\VstPlugins
2017-07-01 17:41 - 2017-07-01 21:17 - 00000000 ____D C:\Program Files\Image-Line
2017-07-01 17:41 - 2017-07-01 17:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Image-Line
2017-07-01 17:29 - 2017-07-01 21:17 - 00000000 ____D C:\Program Files (x86)\Image-Line
2017-07-01 14:15 - 2017-07-01 14:15 - 00000000 ____D C:\Users\Phikicheli\Downloads\Guitar Hero 3
2017-07-01 14:07 - 2015-09-02 15:54 - 00000000 ____D C:\Program Files (x86)\FightCade
2017-07-01 14:05 - 2017-07-01 14:05 - 01430087 _____ C:\Users\Phikicheli\Downloads\GHTCP_V2.0.4.zip
2017-07-01 14:05 - 2017-07-01 14:05 - 00000000 ____D C:\Program Files (x86)\Sigma Production Inc
2017-07-01 14:04 - 2017-07-01 14:04 - 02179856 _____ C:\Users\Phikicheli\Downloads\winrar-x64-540.exe
2017-07-01 14:04 - 2017-07-01 14:04 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2017-07-01 14:04 - 2017-07-01 14:04 - 00000000 ____D C:\Program Files\WinRAR
2017-07-01 14:03 - 2017-07-01 14:03 - 04657496 _____ (Microsoft Corporation) C:\Users\Phikicheli\Downloads\vcredist_IA64.exe
2017-07-01 14:02 - 2017-07-01 14:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Deluge
2017-07-01 14:01 - 2017-07-01 14:02 - 00000000 ____D C:\Program Files (x86)\Deluge
2017-07-01 14:01 - 2017-07-01 14:01 - 16189143 _____ (Deluge Team) C:\Users\Phikicheli\Downloads\deluge-1.3.15-win32-py2.7.exe
2017-07-01 14:00 - 2017-07-01 14:00 - 00000000 ____D C:\Users\Phikicheli\AppData\Roaming\BitTorrent
2017-07-01 13:57 - 2017-07-01 13:57 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nexus Mod Manager
2017-07-01 13:57 - 2017-07-01 13:57 - 00000000 ____D C:\Program Files\Nexus Mod Manager
2017-07-01 13:56 - 2017-07-01 13:56 - 06441096 _____ (Black Tree Gaming ) C:\Users\Phikicheli\Downloads\Nexus Mod Manager-0.63.14.exe
2017-07-01 13:55 - 2017-07-01 13:55 - 00000000 ____D C:\Program Files\OBS
2017-07-01 13:54 - 2017-07-01 13:55 - 00000000 ____D C:\Program Files (x86)\OBS
2017-07-01 13:53 - 2017-07-01 13:54 - 68582904 _____ (obsproject.com) C:\Users\Phikicheli\Downloads\OBS_0_659b_With_Browser_Installer.exe
2017-07-01 13:50 - 2017-07-01 13:50 - 00000995 _____ C:\Users\Phikicheli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Twitch.lnk
2017-07-01 13:50 - 2017-07-01 13:50 - 00000000 ____D C:\Users\Phikicheli\AppData\Roaming\Twitch
2017-07-01 05:02 - 2017-07-01 02:54 - 00565416 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2017-07-01 03:17 - 2017-07-01 13:28 - 00000000 ____D C:\Users\Phikicheli\AppData\Roaming\steelseries-engine-3-client
2017-07-01 03:17 - 2017-07-01 03:17 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SteelSeries
2017-07-01 03:15 - 2010-05-26 11:41 - 02526056 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_43.dll
2017-07-01 03:15 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_43.dll
2017-07-01 03:14 - 2017-07-01 03:14 - 00000000 ____D C:\ProgramData\SteelSeries
2017-07-01 03:14 - 2017-07-01 03:14 - 00000000 ____D C:\Program Files\SteelSeries
2017-07-01 02:53 - 2017-07-01 13:25 - 00000000 ____D C:\Users\Phikicheli\AppData\Roaming\Corsair
2017-07-01 02:53 - 2017-07-01 13:18 - 00000000 ____D C:\Users\Phikicheli\AppData\Local\Corsair
2017-07-01 02:52 - 2017-07-01 02:52 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Corsair Utility Engine
2017-07-01 02:52 - 2017-07-01 02:52 - 00000000 ____D C:\Program Files (x86)\Corsair
2017-07-01 02:48 - 2017-07-01 02:49 - 00000000 ____D C:\Users\Phikicheli\AppData\Local\Steam
2017-07-01 02:47 - 2017-07-01 02:47 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OBS Studio
2017-07-01 02:46 - 2017-07-01 02:47 - 00000000 ____D C:\Program Files (x86)\obs-studio
2017-07-01 02:45 - 2017-07-01 02:45 - 113245088 _____ (obsproject.com) C:\Users\Phikicheli\Downloads\OBS-Studio-19.0.3-Full-Installer.exe
2017-07-01 02:44 - 2007-04-04 18:54 - 00107368 _____ (Microsoft Corporation) C:\WINDOWS\system32\xinput1_3.dll
2017-07-01 02:44 - 2007-04-04 18:53 - 00081768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xinput1_3.dll
2017-07-01 02:43 - 2017-07-01 02:44 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dolphin
2017-07-01 02:43 - 2017-07-01 02:44 - 00000000 ____D C:\Program Files\Dolphin
2017-07-01 02:40 - 2017-07-01 02:40 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
2017-07-01 02:39 - 2017-07-04 12:48 - 00000000 ____D C:\Program Files (x86)\Steam
2017-07-01 02:39 - 2017-07-01 02:39 - 01446792 _____ C:\Users\Phikicheli\Downloads\SteamSetup.exe
2017-07-01 01:57 - 2017-07-01 01:57 - 00000000 ____D C:\WINDOWS\InfusedApps
2017-07-01 01:56 - 2017-07-03 04:12 - 00000000 ____D C:\Windows.old
2017-07-01 01:56 - 2017-06-30 22:25 - 00000000 ___DC C:\WINDOWS\Panther
2017-07-01 01:55 - 2017-07-01 01:55 - 00008192 _____ C:\WINDOWS\system32\config\userdiff
2017-07-01 01:55 - 2017-06-30 21:59 - 00000000 ____D C:\WINDOWS\ServiceProfiles
2017-07-01 01:53 - 2017-07-01 01:53 - 00000000 ____D C:\WINDOWS\Setup
2017-07-01 01:47 - 2017-07-01 01:47 - 00000000 ____D C:\WINDOWS\OCR
2017-07-01 01:47 - 2017-07-01 01:47 - 00000000 ____D C:\Program Files\Reference Assemblies
2017-07-01 01:47 - 2017-07-01 01:47 - 00000000 ____D C:\Program Files\MSBuild
2017-07-01 01:47 - 2017-07-01 01:47 - 00000000 ____D C:\Program Files (x86)\Reference Assemblies
2017-07-01 01:47 - 2017-07-01 01:47 - 00000000 ____D C:\Program Files (x86)\MSBuild
2017-07-01 01:46 - 2017-07-01 01:46 - 00000000 ____D C:\WINDOWS\SysWOW64\winrm
2017-07-01 01:46 - 2017-07-01 01:46 - 00000000 ____D C:\WINDOWS\SysWOW64\WCN
2017-07-01 01:45 - 2017-07-01 01:45 - 00000000 ____D C:\WINDOWS\SysWOW64\sysprep
2017-07-01 01:45 - 2017-07-01 01:45 - 00000000 ____D C:\WINDOWS\SysWOW64\slmgr
2017-07-01 01:45 - 2017-07-01 01:45 - 00000000 ____D C:\WINDOWS\SysWOW64\Printing_Admin_Scripts
2017-07-01 01:45 - 2017-07-01 01:45 - 00000000 ____D C:\WINDOWS\SysWOW64\0409
2017-07-01 01:45 - 2017-07-01 01:45 - 00000000 ____D C:\WINDOWS\system32\winrm
2017-07-01 01:45 - 2017-07-01 01:45 - 00000000 ____D C:\WINDOWS\system32\WCN
2017-07-01 01:45 - 2017-07-01 01:45 - 00000000 ____D C:\WINDOWS\system32\slmgr
2017-07-01 01:45 - 2017-07-01 01:45 - 00000000 ____D C:\WINDOWS\system32\Printing_Admin_Scripts
2017-07-01 01:45 - 2017-07-01 01:45 - 00000000 ____D C:\WINDOWS\system32\0409
2017-07-01 01:45 - 2017-07-01 01:45 - 00000000 ____D C:\WINDOWS\DigitalLocker
2017-07-01 01:40 - 2017-06-03 02:36 - 00835576 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2017-07-01 01:40 - 2017-06-03 02:36 - 00177656 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2017-07-01 01:37 - 2017-07-03 23:01 - 00000000 ____D C:\WINDOWS\rescache
2017-07-01 01:37 - 2017-07-03 18:21 - 00000000 ___HD C:\Program Files\WindowsApps
2017-07-01 01:37 - 2017-07-03 18:21 - 00000000 ____D C:\WINDOWS\AppReadiness
2017-07-01 01:37 - 2017-07-03 17:33 - 00000000 ____D C:\WINDOWS\LiveKernelReports
2017-07-01 01:37 - 2017-07-02 01:33 - 00000000 ___SD C:\WINDOWS\SysWOW64\F12
2017-07-01 01:37 - 2017-07-02 01:33 - 00000000 ____D C:\WINDOWS\SysWOW64\setup
2017-07-01 01:37 - 2017-07-02 01:33 - 00000000 ____D C:\WINDOWS\SysWOW64\oobe
2017-07-01 01:37 - 2017-07-02 01:33 - 00000000 ____D C:\WINDOWS\SysWOW64\Dism
2017-07-01 01:37 - 2017-07-02 01:32 - 00000000 ___SD C:\WINDOWS\system32\F12
2017-07-01 01:37 - 2017-07-02 01:32 - 00000000 ___SD C:\WINDOWS\system32\dsc
2017-07-01 01:37 - 2017-07-02 01:32 - 00000000 ___SD C:\WINDOWS\system32\DiagSvcs
2017-07-01 01:37 - 2017-07-02 01:32 - 00000000 ___RD C:\WINDOWS\PrintDialog
2017-07-01 01:37 - 2017-07-02 01:32 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2017-07-01 01:37 - 2017-07-02 01:32 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2017-07-01 01:37 - 2017-07-02 01:32 - 00000000 ____D C:\WINDOWS\system32\SystemResetPlatform
2017-07-01 01:37 - 2017-07-02 01:32 - 00000000 ____D C:\WINDOWS\system32\Sysprep
2017-07-01 01:37 - 2017-07-02 01:32 - 00000000 ____D C:\WINDOWS\system32\setup
2017-07-01 01:37 - 2017-07-02 01:32 - 00000000 ____D C:\WINDOWS\system32\oobe
2017-07-01 01:37 - 2017-07-02 01:32 - 00000000 ____D C:\WINDOWS\system32\migwiz
2017-07-01 01:37 - 2017-07-02 01:32 - 00000000 ____D C:\WINDOWS\system32\Dism
2017-07-01 01:37 - 2017-07-02 01:32 - 00000000 ____D C:\WINDOWS\system32\appraiser
2017-07-01 01:37 - 2017-07-02 01:32 - 00000000 ____D C:\WINDOWS\ShellExperiences
2017-07-01 01:37 - 2017-07-02 01:32 - 00000000 ____D C:\WINDOWS\Provisioning
2017-07-01 01:37 - 2017-07-02 01:32 - 00000000 ____D C:\WINDOWS\PolicyDefinitions
2017-07-01 01:37 - 2017-07-02 01:32 - 00000000 ____D C:\WINDOWS\bcastdvr
2017-07-01 01:37 - 2017-07-02 01:32 - 00000000 ____D C:\Program Files\Windows Photo Viewer
2017-07-01 01:37 - 2017-07-02 01:32 - 00000000 ____D C:\Program Files\Windows Defender Advanced Threat Protection
2017-07-01 01:37 - 2017-07-02 01:32 - 00000000 ____D C:\Program Files\Windows Defender
2017-07-01 01:37 - 2017-07-02 01:32 - 00000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2017-07-01 01:37 - 2017-07-02 01:32 - 00000000 ____D C:\Program Files (x86)\Windows Defender
2017-07-01 01:37 - 2017-07-02 01:29 - 00015425 _____ C:\WINDOWS\system32\OEMDefaultAssociations.xml
2017-07-01 01:37 - 2017-07-01 13:28 - 00000000 __RHD C:\Users\Public\Libraries
2017-07-01 01:37 - 2017-07-01 04:00 - 00000000 ____D C:\WINDOWS\appcompat
2017-07-01 01:37 - 2017-07-01 01:56 - 00028672 _____ C:\WINDOWS\system32\config\BCD-Template
2017-07-01 01:37 - 2017-07-01 01:47 - 00000000 ____D C:\WINDOWS\SystemApps
2017-07-01 01:37 - 2017-07-01 01:45 - 00000000 ___SD C:\WINDOWS\SysWOW64\DiagSvcs
2017-07-01 01:37 - 2017-07-01 01:45 - 00000000 ____D C:\WINDOWS\SysWOW64\MUI
2017-07-01 01:37 - 2017-07-01 01:45 - 00000000 ____D C:\WINDOWS\SysWOW64\Com
2017-07-01 01:37 - 2017-07-01 01:45 - 00000000 ____D C:\WINDOWS\system32\MUI
2017-07-01 01:37 - 2017-07-01 01:45 - 00000000 ____D C:\WINDOWS\system32\Com
2017-07-01 01:37 - 2017-07-01 01:45 - 00000000 ____D C:\WINDOWS\IME
2017-07-01 01:37 - 2017-07-01 01:45 - 00000000 ____D C:\Program Files\Common Files\System
2017-07-01 01:37 - 2017-07-01 01:45 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2017-07-01 01:37 - 2017-07-01 01:37 - 00000000 __SHD C:\WINDOWS\BitLockerDiscoveryVolumeContents
2017-07-01 01:37 - 2017-07-01 01:37 - 00000000 __SHD C:\Program Files\Windows Sidebar
2017-07-01 01:37 - 2017-07-01 01:37 - 00000000 __SHD C:\Program Files (x86)\Windows Sidebar
2017-07-01 01:37 - 2017-07-01 01:37 - 00000000 __RSD C:\WINDOWS\Media
2017-07-01 01:37 - 2017-07-01 01:37 - 00000000 ___SD C:\WINDOWS\SysWOW64\Nui
2017-07-01 01:37 - 2017-07-01 01:37 - 00000000 ___SD C:\WINDOWS\SysWOW64\Configuration
2017-07-01 01:37 - 2017-07-01 01:37 - 00000000 ___SD C:\WINDOWS\system32\Nui
2017-07-01 01:37 - 2017-07-01 01:37 - 00000000 ___SD C:\WINDOWS\system32\Configuration
2017-07-01 01:37 - 2017-07-01 01:37 - 00000000 ___SD C:\WINDOWS\Downloaded Program Files
2017-07-01 01:37 - 2017-07-01 01:37 - 00000000 ___RD C:\WINDOWS\Offline Web Pages
2017-07-01 01:37 - 2017-07-01 01:37 - 00000000 ___HD C:\WINDOWS\ELAMBKUP
2017-07-01 01:37 - 2017-07-01 01:37 - 00000000 ____D C:\WINDOWS\Web
2017-07-01 01:37 - 2017-07-01 01:37 - 00000000 ____D C:\WINDOWS\Vss
2017-07-01 01:37 - 2017-07-01 01:37 - 00000000 ____D C:\WINDOWS\tracing
2017-07-01 01:37 - 2017-07-01 01:37 - 00000000 ____D C:\WINDOWS\TAPI
2017-07-01 01:37 - 2017-07-01 01:37 - 00000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
2017-07-01 01:37 - 2017-07-01 01:37 - 00000000 ____D C:\WINDOWS\SysWOW64\SMI
2017-07-01 01:37 - 2017-07-01 01:37 - 00000000 ____D C:\WINDOWS\SysWOW64\ras
2017-07-01 01:37 - 2017-07-01 01:37 - 00000000 ____D C:\WINDOWS\SysWOW64\NDF
2017-07-01 01:37 - 2017-07-01 01:37 - 00000000 ____D C:\WINDOWS\SysWOW64\MsDtc
2017-07-01 01:37 - 2017-07-01 01:37 - 00000000 ____D C:\WINDOWS\SysWOW64\migwiz
2017-07-01 01:37 - 2017-07-01 01:37 - 00000000 ____D C:\WINDOWS\SysWOW64\MailContactsCalendarSync
2017-07-01 01:37 - 2017-07-01 01:37 - 00000000 ____D C:\WINDOWS\SysWOW64\Macromed
2017-07-01 01:37 - 2017-07-01 01:37 - 00000000 ____D C:\WINDOWS\SysWOW64\Ipmi
2017-07-01 01:37 - 2017-07-01 01:37 - 00000000 ____D C:\WINDOWS\SysWOW64\InputMethod
2017-07-01 01:37 - 2017-07-01 01:37 - 00000000 ____D C:\WINDOWS\SysWOW64\inetsrv
2017-07-01 01:37 - 2017-07-01 01:37 - 00000000 ____D C:\WINDOWS\SysWOW64\IME
2017-07-01 01:37 - 2017-07-01 01:37 - 00000000 ____D C:\WINDOWS\SysWOW64\icsxml
2017-07-01 01:37 - 2017-07-01 01:37 - 00000000 ____D C:\WINDOWS\SysWOW64\GroupPolicyUsers
2017-07-01 01:37 - 2017-07-01 01:37 - 00000000 ____D C:\WINDOWS\SysWOW64\GroupPolicy
2017-07-01 01:37 - 2017-07-01 01:37 - 00000000 ____D C:\WINDOWS\SysWOW64\FxsTmp
2017-07-01 01:37 - 2017-07-01 01:37 - 00000000 ____D C:\WINDOWS\SysWOW64\downlevel
2017-07-01 01:37 - 2017-07-01 01:37 - 00000000 ____D C:\WINDOWS\SysWOW64\Bthprops
2017-07-01 01:37 - 2017-07-01 01:37 - 00000000 ____D C:\WINDOWS\SysWOW64\AppLocker
2017-07-01 01:37 - 2017-07-01 01:37 - 00000000 ____D C:\WINDOWS\SysWOW64\AdvancedInstallers
2017-07-01 01:37 - 2017-07-01 01:37 - 00000000 ____D C:\WINDOWS\SystemResources
2017-07-01 01:37 - 2017-07-01 01:37 - 00000000 ____D C:\WINDOWS\system32\WinMetadata
2017-07-01 01:37 - 2017-07-01 01:37 - 00000000 ____D C:\WINDOWS\system32\winevt
2017-07-01 01:37 - 2017-07-01 01:37 - 00000000 ____D C:\WINDOWS\system32\SecureBootUpdates
2017-07-01 01:37 - 2017-07-01 01:37 - 00000000 ____D C:\WINDOWS\system32\ras
2017-07-01 01:37 - 2017-07-01 01:37 - 00000000 ____D C:\WINDOWS\system32\ProximityToast
2017-07-01 01:37 - 2017-07-01 01:37 - 00000000 ____D C:\WINDOWS\system32\PointOfService
2017-07-01 01:37 - 2017-07-01 01:37 - 00000000 ____D C:\WINDOWS\system32\MsDtc
2017-07-01 01:37 - 2017-07-01 01:37 - 00000000 ____D C:\WINDOWS\system32\MailContactsCalendarSync
2017-07-01 01:37 - 2017-07-01 01:37 - 00000000 ____D C:\WINDOWS\system32\Macromed
2017-07-01 01:37 - 2017-07-01 01:37 - 00000000 ____D C:\WINDOWS\system32\Ipmi
2017-07-01 01:37 - 2017-07-01 01:37 - 00000000 ____D C:\WINDOWS\system32\InputMethod
2017-07-01 01:37 - 2017-07-01 01:37 - 00000000 ____D C:\WINDOWS\system32\inetsrv
2017-07-01 01:37 - 2017-07-01 01:37 - 00000000 ____D C:\WINDOWS\system32\IME
2017-07-01 01:37 - 2017-07-01 01:37 - 00000000 ____D C:\WINDOWS\system32\icsxml
2017-07-01 01:37 - 2017-07-01 01:37 - 00000000 ____D C:\WINDOWS\system32\ias
2017-07-01 01:37 - 2017-07-01 01:37 - 00000000 ____D C:\WINDOWS\system32\GroupPolicyUsers
2017-07-01 01:37 - 2017-07-01 01:37 - 00000000 ____D C:\WINDOWS\system32\GroupPolicy
2017-07-01 01:37 - 2017-07-01 01:37 - 00000000 ____D C:\WINDOWS\system32\downlevel
2017-07-01 01:37 - 2017-07-01 01:37 - 00000000 ____D C:\WINDOWS\system32\DDFs
2017-07-01 01:37 - 2017-07-01 01:37 - 00000000 ____D C:\WINDOWS\system32\config\Journal
2017-07-01 01:37 - 2017-07-01 01:37 - 00000000 ____D C:\WINDOWS\system32\Bthprops
2017-07-01 01:37 - 2017-07-01 01:37 - 00000000 ____D C:\WINDOWS\system32\AppLocker
2017-07-01 01:37 - 2017-07-01 01:37 - 00000000 ____D C:\WINDOWS\system32\AdvancedInstallers
2017-07-01 01:37 - 2017-07-01 01:37 - 00000000 ____D C:\WINDOWS\System
2017-07-01 01:37 - 2017-07-01 01:37 - 00000000 ____D C:\WINDOWS\SKB
2017-07-01 01:37 - 2017-07-01 01:37 - 00000000 ____D C:\WINDOWS\security
2017-07-01 01:37 - 2017-07-01 01:37 - 00000000 ____D C:\WINDOWS\schemas
2017-07-01 01:37 - 2017-07-01 01:37 - 00000000 ____D C:\WINDOWS\SchCache
2017-07-01 01:37 - 2017-07-01 01:37 - 00000000 ____D C:\WINDOWS\Resources
2017-07-01 01:37 - 2017-07-01 01:37 - 00000000 ____D C:\WINDOWS\RemotePackages
2017-07-01 01:37 - 2017-07-01 01:37 - 00000000 ____D C:\WINDOWS\Registration
2017-07-01 01:37 - 2017-07-01 01:37 - 00000000 ____D C:\WINDOWS\PLA
2017-07-01 01:37 - 2017-07-01 01:37 - 00000000 ____D C:\WINDOWS\Performance
2017-07-01 01:37 - 2017-07-01 01:37 - 00000000 ____D C:\WINDOWS\ModemLogs
2017-07-01 01:37 - 2017-07-01 01:37 - 00000000 ____D C:\WINDOWS\L2Schemas
2017-07-01 01:37 - 2017-07-01 01:37 - 00000000 ____D C:\WINDOWS\InputMethod
2017-07-01 01:37 - 2017-07-01 01:37 - 00000000 ____D C:\WINDOWS\Globalization
2017-07-01 01:37 - 2017-07-01 01:37 - 00000000 ____D C:\WINDOWS\GameBarPresenceWriter
2017-07-01 01:37 - 2017-07-01 01:37 - 00000000 ____D C:\WINDOWS\Cursors
2017-07-01 01:37 - 2017-07-01 01:37 - 00000000 ____D C:\WINDOWS\Branding
2017-07-01 01:37 - 2017-07-01 01:37 - 00000000 ____D C:\WINDOWS\addins
2017-07-01 01:37 - 2017-07-01 01:37 - 00000000 ____D C:\ProgramData\Comms
2017-07-01 01:37 - 2017-07-01 01:37 - 00000000 ____D C:\Program Files\Windows Portable Devices
2017-07-01 01:37 - 2017-07-01 01:37 - 00000000 ____D C:\Program Files\Windows NT
2017-07-01 01:37 - 2017-07-01 01:37 - 00000000 ____D C:\Program Files\Windows Multimedia Platform
2017-07-01 01:37 - 2017-07-01 01:37 - 00000000 ____D C:\Program Files\Common Files\Services
2017-07-01 01:37 - 2017-07-01 01:37 - 00000000 ____D C:\Program Files (x86)\Windows Portable Devices
2017-07-01 01:37 - 2017-07-01 01:37 - 00000000 ____D C:\Program Files (x86)\Windows NT
2017-07-01 01:37 - 2017-07-01 01:37 - 00000000 ____D C:\Program Files (x86)\Windows Multimedia Platform
2017-07-01 01:37 - 2017-07-01 01:32 - 00231424 _____ (Microsoft Corporation) C:\WINDOWS\system32\msclmd.dll
2017-07-01 01:37 - 2017-07-01 01:32 - 00215943 _____ C:\WINDOWS\SysWOW64\dssec.dat
2017-07-01 01:37 - 2017-07-01 01:32 - 00215943 _____ C:\WINDOWS\system32\dssec.dat
2017-07-01 01:37 - 2017-07-01 01:32 - 00209408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msclmd.dll
2017-07-01 01:37 - 2017-07-01 01:32 - 00027136 _____ (Khronos Group) C:\WINDOWS\SysWOW64\opencl.dll
2017-07-01 01:37 - 2017-07-01 01:32 - 00017463 _____ C:\WINDOWS\system32\Drivers\etc\services
2017-07-01 01:37 - 2017-07-01 01:32 - 00004096 _____ C:\WINDOWS\system32\config\VSMIDK
2017-07-01 01:37 - 2017-07-01 01:32 - 00003683 _____ C:\WINDOWS\system32\Drivers\etc\lmhosts.sam
2017-07-01 01:37 - 2017-07-01 01:32 - 00001358 _____ C:\WINDOWS\system32\Drivers\etc\protocol
2017-07-01 01:37 - 2017-07-01 01:32 - 00000858 _____ C:\WINDOWS\system32\DefaultQuestions.json
2017-07-01 01:37 - 2017-07-01 01:32 - 00000741 _____ C:\WINDOWS\SysWOW64\NOISE.DAT
2017-07-01 01:37 - 2017-07-01 01:32 - 00000741 _____ C:\WINDOWS\system32\NOISE.DAT
2017-07-01 01:37 - 2017-07-01 01:32 - 00000407 _____ C:\WINDOWS\system32\Drivers\etc\networks
2017-07-01 01:37 - 2017-07-01 01:32 - 00000219 _____ C:\WINDOWS\system.ini
2017-07-01 01:37 - 2017-07-01 01:32 - 00000092 _____ C:\WINDOWS\win.ini
2017-07-01 01:37 - 2017-06-30 22:49 - 00000000 ____D C:\WINDOWS\Help
2017-07-01 01:37 - 2017-06-30 22:33 - 00000000 ____D C:\WINDOWS\system32\NDF
2017-07-01 01:37 - 2017-06-30 22:23 - 00000000 ____D C:\WINDOWS\system32\WinBioDatabase
2017-07-01 01:37 - 2017-06-30 22:19 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2017-07-01 01:37 - 2017-06-30 22:14 - 00000000 ____D C:\WINDOWS\system32\spool
2017-07-01 01:37 - 2017-06-30 22:14 - 00000000 ____D C:\WINDOWS\system32\FxsTmp
2017-07-01 01:37 - 2017-06-30 22:14 - 00000000 ____D C:\WINDOWS\CSC
2017-07-01 01:37 - 2017-06-30 22:08 - 00000000 ___RD C:\WINDOWS\MiracastView
2017-07-01 01:37 - 2017-06-30 22:02 - 00000000 ____D C:\ProgramData\USOPrivate
2017-07-01 01:33 - 2017-07-02 02:52 - 00000000 ____D C:\WINDOWS\INF
2017-07-01 01:14 - 2017-07-02 01:17 - 00000000 ____D C:\WINDOWS\CbsTemp
2017-07-01 01:05 - 2017-07-04 11:58 - 00524288 _____ C:\WINDOWS\system32\config\BBI
2017-07-01 01:05 - 2017-07-02 01:32 - 00000000 ____D C:\WINDOWS\servicing
2017-07-01 01:05 - 2017-07-01 01:37 - 00000000 ____D C:\WINDOWS\system32\SMI
2017-07-01 01:05 - 2017-06-30 22:01 - 00032768 _____ C:\WINDOWS\system32\config\ELAM
2017-06-30 23:26 - 2017-07-04 12:13 - 00000000 ____D C:\Users\Phikicheli\AppData\Local\ClassicShell
2017-06-30 23:26 - 2017-06-30 23:26 - 00000000 ____D C:\ProgramData\ClassicShell
2017-06-30 23:24 - 2017-06-30 23:24 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Classic Shell
2017-06-30 23:24 - 2017-06-30 23:24 - 00000000 ____D C:\Program Files\Classic Shell
2017-06-30 23:22 - 2017-06-30 23:22 - 07220496 _____ (IvoSoft) C:\Users\Phikicheli\Downloads\ClassicShellSetup_4_3_0.exe
2017-06-30 23:21 - 2017-07-01 13:28 - 00000000 ____D C:\Users\Phikicheli\AppData\Roaming\OBS
2017-06-30 23:21 - 2017-06-30 23:21 - 00000000 ____D C:\Users\Phikicheli\AppData\Roaming\ClassicShell
2017-06-30 23:20 - 2017-07-01 13:28 - 00000000 ____D C:\Users\Phikicheli\AppData\Roaming\AirDroid
2017-06-30 23:17 - 2017-07-01 13:27 - 00000000 ____D C:\Users\Phikicheli\AppData\Roaming\.minecraft
2017-06-30 23:15 - 2017-06-30 23:15 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
2017-06-30 23:14 - 2017-06-30 23:15 - 00000000 ____D C:\Users\Phikicheli\AppData\Roaming\Mozilla
2017-06-30 23:14 - 2017-06-30 23:14 - 00000951 _____ C:\Users\Public\Desktop\Waterfox.lnk
2017-06-30 23:14 - 2017-06-30 23:14 - 00000000 ____D C:\Users\Phikicheli\AppData\Local\Mozilla
2017-06-30 23:14 - 2017-06-30 23:14 - 00000000 ____D C:\Program Files\Waterfox
2017-06-30 23:12 - 2017-07-03 18:45 - 00000000 ____D C:\Users\Phikicheli\AppData\Local\CrashDumps
2017-06-30 23:12 - 2017-07-01 13:19 - 00000000 ____D C:\Users\Phikicheli\AppData\Local\MicrosoftEdge
2017-06-30 23:12 - 2017-06-30 23:13 - 81943152 _____ (Mozilla) C:\Users\Phikicheli\Downloads\Waterfox 54.0.0.1 Setup.exe
2017-06-30 23:07 - 2017-06-30 23:07 - 00003300 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task v2
2017-06-30 23:05 - 2017-06-30 23:05 - 00000000 ____D C:\Users\Phikicheli\AppData\Roaming\Skype
2017-06-30 22:54 - 2017-06-30 23:01 - 00000000 ____D C:\ProgramData\Killer
2017-06-30 22:54 - 2017-06-30 22:54 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Killer Networking
2017-06-30 22:54 - 2017-06-30 22:54 - 00000000 ____D C:\Program Files (x86)\InstallShield Installation Information
2017-06-30 22:53 - 2017-06-30 22:53 - 00000000 ____D C:\Program Files\Killer Networking
2017-06-30 22:52 - 2017-06-30 22:52 - 00000000 ____D C:\ProgramData\Downloaded Installations
2017-06-30 22:51 - 2017-07-02 02:42 - 00000000 ____D C:\Users\Phikicheli\AppData\Local\NVIDIA Corporation
2017-06-30 22:51 - 2017-07-02 02:24 - 00000000 ____D C:\Users\Phikicheli\AppData\Local\NVIDIA
2017-06-30 22:51 - 2017-06-30 22:51 - 00000000 ____D C:\Users\Phikicheli\AppData\Local\CEF
2017-06-30 22:51 - 2010-05-26 11:41 - 02401112 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_43.dll
2017-06-30 22:51 - 2010-05-26 11:41 - 01998168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_43.dll
2017-06-30 22:51 - 2010-05-26 11:41 - 00511328 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_43.dll
2017-06-30 22:51 - 2010-05-26 11:41 - 00470880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_43.dll
2017-06-30 22:51 - 2010-05-26 11:41 - 00276832 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx11_43.dll
2017-06-30 22:51 - 2010-05-26 11:41 - 00248672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx11_43.dll
2017-06-30 22:50 - 2017-07-02 02:43 - 00003994 _____ C:\WINDOWS\System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-06-30 22:50 - 2017-07-02 02:42 - 00003894 _____ C:\WINDOWS\System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-06-30 22:50 - 2017-07-02 02:42 - 00003866 _____ C:\WINDOWS\System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-06-30 22:50 - 2017-07-02 02:42 - 00003858 _____ C:\WINDOWS\System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-06-30 22:50 - 2017-07-02 02:42 - 00003696 _____ C:\WINDOWS\System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-06-30 22:50 - 2017-07-02 02:42 - 00003654 _____ C:\WINDOWS\System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-06-30 22:50 - 2017-07-02 00:54 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2017-06-30 22:50 - 2017-06-21 03:07 - 01903224 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspcap64.dll
2017-06-30 22:50 - 2017-06-21 03:07 - 01755256 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspbridge64.dll
2017-06-30 22:50 - 2017-06-21 03:07 - 01489528 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspcap.dll
2017-06-30 22:50 - 2017-06-21 03:07 - 01317496 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspbridge.dll
2017-06-30 22:50 - 2017-06-21 03:07 - 00121464 _____ C:\WINDOWS\system32\NvRtmpStreamer64.dll
2017-06-30 22:49 - 2016-12-29 08:44 - 06386232 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
2017-06-30 22:49 - 2016-12-29 08:44 - 02477624 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc64.dll
2017-06-30 22:49 - 2016-12-29 08:44 - 01762752 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll
2017-06-30 22:49 - 2016-12-29 08:44 - 00546752 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshext.dll
2017-06-30 22:49 - 2016-12-29 08:44 - 00392128 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmctray.dll
2017-06-30 22:49 - 2016-12-29 08:44 - 00083512 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshextr.dll
2017-06-30 22:49 - 2016-12-29 08:44 - 00069568 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll
2017-06-30 22:49 - 2016-12-19 03:26 - 07651057 _____ C:\WINDOWS\system32\nvcoproc.bin
2017-06-30 22:48 - 2017-07-04 12:49 - 00000000 ____D C:\ProgramData\NVIDIA
2017-06-30 22:48 - 2017-07-02 02:43 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2017-06-30 22:48 - 2017-07-02 02:42 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2017-06-30 22:48 - 2017-06-07 16:51 - 00001951 _____ C:\WINDOWS\NvContainerRecovery.bat
2017-06-30 22:48 - 2016-11-24 16:53 - 00213952 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.dll
2017-06-30 22:45 - 2017-07-01 13:18 - 00000000 ____D C:\Users\Phikicheli\AppData\Local\Comms
2017-06-30 22:44 - 2017-07-01 02:44 - 00000000 ____D C:\ProgramData\Package Cache
2017-06-30 22:43 - 2017-06-21 03:07 - 00048248 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvvad64v.sys
2017-06-30 22:43 - 2017-01-04 15:19 - 01604160 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvhdagenco6420103.dll
2017-06-30 22:43 - 2017-01-04 15:19 - 00221640 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvhda64v.sys
2017-06-30 22:43 - 2017-01-04 15:02 - 03977632 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll
2017-06-30 22:43 - 2017-01-04 15:02 - 03513632 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll
2017-06-30 22:43 - 2017-01-04 10:07 - 00042286 _____ C:\WINDOWS\system32\nvinfo.pb
2017-06-30 22:43 - 2016-11-24 16:53 - 01951680 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6437609.dll
2017-06-30 22:43 - 2016-11-24 16:53 - 01586744 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6437609.dll
2017-06-30 22:43 - 2016-11-24 16:53 - 00000669 _____ C:\WINDOWS\SysWOW64\nv-vk32.json
2017-06-30 22:43 - 2016-11-24 16:53 - 00000669 _____ C:\WINDOWS\system32\nv-vk64.json
2017-06-30 22:40 - 2017-07-02 02:42 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2017-06-30 22:31 - 2017-06-30 23:07 - 00002382 _____ C:\Users\Phikicheli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2017-06-30 22:29 - 2017-06-30 22:29 - 00000000 ____D C:\ProgramData\Microsoft OneDrive
2017-06-30 22:27 - 2017-06-30 22:27 - 00000000 ____D C:\Users\Phikicheli\AppData\Local\Publishers
2017-06-30 22:26 - 2017-07-01 13:27 - 00000000 ____D C:\Users\Phikicheli\AppData\Local\ConnectedDevicesPlatform
2017-06-30 22:26 - 2017-07-01 13:25 - 00000000 ____D C:\Users\Phikicheli\AppData\Roaming\Adobe
2017-06-30 22:26 - 2017-07-01 13:23 - 00000000 ____D C:\Users\Phikicheli\AppData\Local\VirtualStore
2017-06-30 22:26 - 2017-07-01 13:22 - 00000000 ____D C:\Users\Phikicheli\AppData\Local\Packages
2017-06-30 22:26 - 2017-06-30 22:26 - 00000000 ____D C:\Users\Phikicheli\AppData\Local\TileDataLayer
2017-06-30 22:25 - 2017-06-30 22:25 - 00000000 _SHDL C:\Users\Default\My Documents
2017-06-30 22:25 - 2017-06-30 22:25 - 00000000 _SHDL C:\Users\Default\Documents\My Videos
2017-06-30 22:25 - 2017-06-30 22:25 - 00000000 _SHDL C:\Users\Default\Documents\My Pictures
2017-06-30 22:25 - 2017-06-30 22:25 - 00000000 _SHDL C:\Users\Default\Documents\My Music
2017-06-30 22:25 - 2017-06-30 22:25 - 00000000 _SHDL C:\Users\Default User\Documents\My Videos
2017-06-30 22:25 - 2017-06-30 22:25 - 00000000 _SHDL C:\Users\Default User\Documents\My Pictures
2017-06-30 22:25 - 2017-06-30 22:25 - 00000000 _SHDL C:\Users\Default User\Documents\My Music
2017-06-30 22:25 - 2017-06-30 22:25 - 00000000 _SHDL C:\Users\Default User
2017-06-30 22:25 - 2017-06-30 22:25 - 00000000 _SHDL C:\Users\All Users
2017-06-30 22:23 - 2017-06-30 22:23 - 00021078 _____ C:\Users\defaultuser0\Desktop\Removed Apps.html
2017-06-30 22:21 - 2017-07-04 12:05 - 01295816 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2017-06-30 22:13 - 2017-07-02 12:17 - 00000000 ____D C:\Users\Phikicheli
2017-06-30 22:13 - 2017-07-01 13:26 - 00000000 ____D C:\Users\defaultuser0
2017-06-30 22:13 - 2017-06-30 22:13 - 00000000 _SHDL C:\Users\Phikicheli\My Documents
2017-06-30 22:13 - 2017-06-30 22:13 - 00000000 _SHDL C:\Users\Phikicheli\Documents\My Videos
2017-06-30 22:13 - 2017-06-30 22:13 - 00000000 _SHDL C:\Users\Phikicheli\Documents\My Pictures
2017-06-30 22:13 - 2017-06-30 22:13 - 00000000 _SHDL C:\Users\Phikicheli\Documents\My Music
2017-06-30 22:13 - 2017-06-30 22:13 - 00000000 _SHDL C:\Users\defaultuser0\My Documents
2017-06-30 22:13 - 2017-06-30 22:13 - 00000000 _SHDL C:\Users\defaultuser0\Documents\My Videos
2017-06-30 22:13 - 2017-06-30 22:13 - 00000000 _SHDL C:\Users\defaultuser0\Documents\My Pictures
2017-06-30 22:13 - 2017-06-30 22:13 - 00000000 _SHDL C:\Users\defaultuser0\Documents\My Music
2017-06-30 22:06 - 2017-06-30 22:06 - 00000000 ____D C:\WINDOWS\SysWOW64\RTCOM
2017-06-30 22:06 - 2017-06-30 22:06 - 00000000 ____D C:\Program Files\Realtek
2017-06-30 22:03 - 2017-04-27 21:01 - 02717184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2017-06-30 22:02 - 2017-06-30 22:02 - 00000000 ____D C:\ProgramData\USOShared
2017-06-30 22:00 - 2017-07-04 11:58 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2017-06-30 21:59 - 2017-07-04 01:30 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
2017-06-30 21:59 - 2017-07-02 01:37 - 00194192 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2017-06-30 20:21 - 2017-06-30 20:36 - 00000000 _____ C:\Users\Phikicheli\AppData\Local\Driver_LOM_8161Present.flag
2017-06-30 10:32 - 2017-06-30 10:32 - 00000000 ____D C:\NVIDIA
2017-06-29 13:30 - 2017-06-29 13:31 - 393473175 _____ C:\Users\Phikicheli\Downloads\nvidia_376.09_w1064.zip
2017-06-29 03:21 - 2017-06-29 03:22 - 173105152 _____ C:\Users\Phikicheli\Downloads\CorsairUtilityEngineSetup_2.14.67_release.msi
2017-06-27 01:59 - 2017-06-30 13:33 - 00000000 _____ C:\Recovery.txt
2017-06-26 11:50 - 2017-06-26 11:50 - 00000000 ____D C:\Users\Phikicheli\Documents\Diablo III
2017-06-25 19:45 - 2017-06-25 19:45 - 00000000 ____D C:\Users\Phikicheli\AppData\Local\oneClickRoot
2017-06-25 19:45 - 2017-06-25 19:45 - 00000000 ____D C:\Users\Phikicheli\AppData\Local\AWSToolkit
2017-06-25 19:44 - 2017-06-25 19:44 - 01036272 _____ () C:\Users\Phikicheli\Downloads\OneClickRoot.exe
2017-06-25 19:44 - 2017-06-25 19:44 - 00000000 ____D C:\Users\Phikicheli\AppData\Roaming\One Click Root
2017-06-25 19:44 - 2017-06-25 19:44 - 00000000 ____D C:\Users\Phikicheli\AppData\Local\IsolatedStorage
2017-06-25 18:05 - 2017-06-25 18:05 - 03118796 _____ C:\Users\Phikicheli\Downloads\FNVEdit 3.2-34703-3-2.7z
2017-06-25 17:07 - 2017-06-25 17:07 - 00000000 ____D C:\Users\Phikicheli\Downloads\Fallout New Vegas Redesigned 2 latest version-39218
2017-06-25 16:41 - 2017-06-25 16:44 - 141426335 _____ C:\Users\Phikicheli\Downloads\Fallout New Vegas Redesigned 2 latest version-39218.rar
2017-06-25 15:09 - 2017-06-25 15:09 - 00000000 ____D C:\Users\Phikicheli\AppData\Roaming\.mono
2017-06-25 15:09 - 2017-06-25 15:09 - 00000000 ____D C:\Users\Phikicheli\AppData\Local\Colossal Order
2017-06-25 02:08 - 2017-06-25 02:08 - 00000000 ____D C:\Users\Phikicheli\Downloads\Setlists-20170625T053934Z-041
2017-06-25 01:54 - 2017-06-25 02:01 - 1294053416 _____ C:\Users\Phikicheli\Downloads\Setlists-20170625T053934Z-041.zip
2017-06-24 23:05 - 2017-06-24 23:15 - 637505591 _____ C:\Users\Phikicheli\Downloads\New Vegas Redesigned 3 version 3.7-56312-3-7.rar
2017-06-24 23:05 - 2017-06-24 23:05 - 00700762 _____ C:\Users\Phikicheli\Downloads\nvse_5_0_beta3.7z
2017-06-24 22:21 - 2017-06-25 18:08 - 00000000 ____D C:\Users\Phikicheli\AppData\Local\FalloutNV
2017-06-24 15:12 - 2017-06-24 15:12 - 03812187 _____ C:\Users\Phikicheli\Downloads\100K!!! Ween - Ocean Man Ear Rape.ogg
2017-06-24 00:54 - 2017-02-14 06:11 - 00000000 ____D C:\Users\Phikicheli\Desktop\Ween - Ocean Man
2017-06-23 23:13 - 2017-06-23 23:20 - 1119119736 _____ C:\Users\Phikicheli\Downloads\acai28 setlist 0.1 public release.sgh
2017-06-23 20:30 - 2017-06-23 20:30 - 00000000 ____D C:\Users\Phikicheli\AppData\LocalLow\jgallant
2017-06-22 22:27 - 2017-06-22 22:27 - 00253012 _____ C:\Users\Phikicheli\Downloads\ASIO4ALL v2 Instruction Manual.pdf
2017-06-22 21:21 - 2017-06-22 21:21 - 00000000 ____D C:\Users\Phikicheli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ASIO4ALL v2
2017-06-22 21:08 - 2017-07-01 17:43 - 00002121 _____ C:\Users\Public\Desktop\FL Studio 12 (64bit).lnk
2017-06-22 21:07 - 2017-07-01 21:17 - 00000000 ____D C:\Users\Phikicheli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Image-Line
2017-06-22 21:07 - 2017-06-22 21:07 - 00000000 ____D C:\Users\Phikicheli\Documents\Image-Line
2017-06-22 21:07 - 2017-06-22 21:07 - 00000000 ____D C:\Users\Phikicheli\AppData\Roaming\Image-Line
2017-06-22 18:25 - 2017-06-22 18:25 - 01814262 _____ C:\Users\Phikicheli\Downloads\OptiFine_1.8.8_HD_U_H8.jar
2017-06-21 22:21 - 2017-06-22 19:38 - 00000000 ____D C:\Users\Phikicheli\Desktop\Song only using samples
2017-06-19 15:47 - 2017-06-19 15:47 - 01804640 _____ (Microsoft Corporation) C:\WINDOWS\system32\WdfCoInstaller01011.dll
2017-06-19 15:47 - 2017-06-19 15:47 - 00045904 _____ (SteelSeries ApS) C:\WINDOWS\system32\Drivers\sshid.sys
2017-06-16 03:33 - 2017-06-16 03:35 - 00006536 _____ C:\Users\Phikicheli\ggpofba-ng.bkp.ini
2017-06-16 03:27 - 2017-07-01 14:09 - 00001242 _____ C:\Users\Phikicheli\ggpo-ng.ini
2017-06-16 03:27 - 2017-06-20 17:40 - 00001092 _____ C:\Users\Phikicheli\Desktop\FightCade.lnk
2017-06-16 03:26 - 2017-06-16 03:26 - 24115629 _____ C:\Users\Phikicheli\Downloads\fightcade-win32-v042.2.zip
2017-06-16 03:18 - 2017-06-16 03:18 - 00000000 ____D C:\Users\Phikicheli\Documents\notproncont
2017-06-16 03:16 - 2017-06-16 03:17 - 00000000 ____D C:\Users\Phikicheli\Desktop\not porn
2017-06-13 20:11 - 2017-06-13 20:11 - 04627606 _____ C:\Users\Phikicheli\Downloads\Skrillex - Bangarang.rar
2017-06-13 20:11 - 2017-06-13 20:11 - 00000000 ____D C:\Users\Phikicheli\Downloads\Skrillex - Bangarang
2017-06-13 20:09 - 2017-06-13 20:09 - 02891779 _____ C:\Users\Phikicheli\Downloads\Bangarang.rar
2017-06-13 19:29 - 2017-06-03 06:50 - 00315744 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
2017-06-13 19:29 - 2017-06-03 06:16 - 00279904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys
2017-06-13 19:29 - 2017-06-03 06:11 - 01706488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2017-06-13 19:29 - 2017-06-03 06:09 - 02213760 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2017-06-13 19:29 - 2017-06-03 06:06 - 02048496 _____ C:\WINDOWS\SysWOW64\CoreUIComponents.dll
2017-06-13 19:29 - 2017-06-03 05:59 - 01181024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys
2017-06-13 19:29 - 2017-06-03 05:59 - 00118112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tdx.sys
2017-06-13 19:29 - 2017-06-03 05:58 - 00340832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll
2017-06-13 19:29 - 2017-06-03 05:55 - 00780640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe
2017-06-13 19:29 - 2017-06-03 05:54 - 00187232 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsd.sys
2017-06-13 19:29 - 2017-06-03 05:52 - 01021784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxPackaging.dll
2017-06-13 19:29 - 2017-06-03 05:52 - 00607072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupEngine.dll
2017-06-13 19:29 - 2017-06-03 05:52 - 00111968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupApi.dll
2017-06-13 19:29 - 2017-06-03 05:50 - 00857440 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe
2017-06-13 19:29 - 2017-06-03 05:50 - 00381792 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS
2017-06-13 19:29 - 2017-06-03 05:49 - 20967840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2017-06-13 19:29 - 2017-06-03 05:48 - 00857952 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupEngine.dll
2017-06-13 19:29 - 2017-06-03 05:48 - 00148832 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupApi.dll
2017-06-13 19:29 - 2017-06-03 05:45 - 22220864 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2017-06-13 19:29 - 2017-06-03 05:44 - 01412640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll
2017-06-13 19:29 - 2017-06-03 05:44 - 00545944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2017-06-13 19:29 - 2017-06-03 05:39 - 05686272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
2017-06-13 19:29 - 2017-06-03 05:39 - 02532192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2017-06-13 19:29 - 2017-06-03 05:33 - 00095232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataTimeUtil.dll
2017-06-13 19:29 - 2017-06-03 05:32 - 00002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tzres.dll
2017-06-13 19:29 - 2017-06-03 05:31 - 00224256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExSMime.dll
2017-06-13 19:29 - 2017-06-03 05:31 - 00037376 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
2017-06-13 19:29 - 2017-06-03 05:28 - 00285184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.BlockedShutdown.dll
2017-06-13 19:29 - 2017-06-03 05:28 - 00232448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edputil.dll
2017-06-13 19:29 - 2017-06-03 05:26 - 00231936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.LockScreen.dll
2017-06-13 19:29 - 2017-06-03 05:26 - 00100352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AuthBrokerUI.dll
2017-06-13 19:29 - 2017-06-03 05:22 - 00364544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupShim.dll
2017-06-13 19:29 - 2017-06-03 05:22 - 00327168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netcorehc.dll
2017-06-13 19:29 - 2017-06-03 05:22 - 00181760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tcpipcfg.dll
2017-06-13 19:29 - 2017-06-03 05:20 - 00755712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2017-06-13 19:29 - 2017-06-03 05:19 - 01164288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certutil.exe
2017-06-13 19:29 - 2017-06-03 05:16 - 00709120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CPFilters.dll
2017-06-13 19:29 - 2017-06-03 05:16 - 00119808 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataTimeUtil.dll
2017-06-13 19:29 - 2017-06-03 05:15 - 00886272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aadtb.dll
2017-06-13 19:29 - 2017-06-03 05:15 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\system32\musdialoghandlers.dll
2017-06-13 19:29 - 2017-06-03 05:15 - 00041472 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BasicRender.sys
2017-06-13 19:29 - 2017-06-03 05:14 - 00238592 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2017-06-13 19:29 - 2017-06-03 05:14 - 00124416 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssprxy.dll
2017-06-13 19:29 - 2017-06-03 05:14 - 00098304 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe
2017-06-13 19:29 - 2017-06-03 05:12 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fdProxy.dll
2017-06-13 19:29 - 2017-06-03 05:09 - 00441344 _____ (Microsoft Corporation) C:\WINDOWS\system32\netcorehc.dll
2017-06-13 19:29 - 2017-06-03 05:08 - 02643968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll
2017-06-13 19:29 - 2017-06-03 05:08 - 01221120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Audio.dll
2017-06-13 19:29 - 2017-06-03 05:07 - 00552960 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2017-06-13 19:29 - 2017-06-03 05:07 - 00456192 _____ (Microsoft Corporation) C:\WINDOWS\system32\puiobj.dll
2017-06-13 19:29 - 2017-06-03 05:05 - 01883648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Logon.dll
2017-06-13 19:29 - 2017-06-03 05:05 - 00295424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hnetcfg.dll
2017-06-13 19:29 - 2017-06-03 05:04 - 02006528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWrite.dll
2017-06-13 19:29 - 2017-06-03 05:04 - 00773120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchIndexer.exe
2017-06-13 19:29 - 2017-06-03 05:03 - 01988096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssrch.dll
2017-06-13 19:29 - 2017-06-03 05:02 - 02997760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2017-06-13 19:29 - 2017-06-03 04:54 - 01217024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Audio.dll
2017-06-13 19:29 - 2017-06-03 04:52 - 03403264 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll
2017-06-13 19:29 - 2017-06-03 04:51 - 00266752 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupSvc.dll
2017-06-13 19:29 - 2017-06-03 04:50 - 02538496 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssrch.dll
2017-06-13 19:29 - 2017-06-03 04:49 - 00903680 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchIndexer.exe
2017-06-13 19:29 - 2017-06-03 04:48 - 01131008 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll
2017-06-13 19:29 - 2017-06-03 04:48 - 00834048 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32spl.dll
2017-06-13 19:29 - 2017-06-03 04:48 - 00391168 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll
2017-06-13 19:29 - 2017-06-03 04:40 - 00483840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll
2017-06-13 19:29 - 2017-05-25 01:56 - 00038752 _____ (Microsoft Corporation) C:\WINDOWS\system32\OOBEUpdater.exe
2017-06-13 19:29 - 2017-03-04 02:16 - 00368128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\puiobj.dll
2017-06-13 19:29 - 2017-03-04 02:16 - 00100864 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpninprc.dll
2017-06-13 19:29 - 2016-09-07 00:53 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppointmentActivation.dll
2017-06-13 19:28 - 2017-06-03 06:50 - 00192856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aepic.dll
2017-06-13 19:28 - 2017-06-03 06:14 - 01564512 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2017-06-13 19:28 - 2017-06-03 06:14 - 01214816 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2017-06-13 19:28 - 2017-06-03 06:14 - 00629088 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2017-06-13 19:28 - 2017-06-03 06:14 - 00544096 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2017-06-13 19:28 - 2017-06-03 06:14 - 00379232 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
2017-06-13 19:28 - 2017-06-03 06:14 - 00335712 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcntel.dll
2017-06-13 19:28 - 2017-06-03 06:14 - 00334176 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2017-06-13 19:28 - 2017-06-03 06:14 - 00233824 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll
2017-06-13 19:28 - 2017-06-03 06:14 - 00136032 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2017-06-13 19:28 - 2017-06-03 06:14 - 00136024 _____ (Microsoft Corporation) C:\WINDOWS\system32\ImplatSetup.dll
2017-06-13 19:28 - 2017-06-03 06:14 - 00096608 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe
2017-06-13 19:28 - 2017-06-03 06:14 - 00034648 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCensus.exe
2017-06-13 19:28 - 2017-06-03 06:11 - 00128864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tm.sys
2017-06-13 19:28 - 2017-06-03 06:08 - 07783256 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2017-06-13 19:28 - 2017-06-03 06:01 - 02681200 _____ C:\WINDOWS\system32\CoreUIComponents.dll
2017-06-13 19:28 - 2017-06-03 05:59 - 00764392 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll
2017-06-13 19:28 - 2017-06-03 05:53 - 00404824 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll
2017-06-13 19:28 - 2017-06-03 05:51 - 02187104 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2017-06-13 19:28 - 2017-06-03 05:51 - 00402272 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2017-06-13 19:28 - 2017-06-03 05:49 - 00624048 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2017-06-13 19:28 - 2017-06-03 05:49 - 00509280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storport.sys
2017-06-13 19:28 - 2017-06-03 05:48 - 01112416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxPackaging.dll
2017-06-13 19:28 - 2017-06-03 05:48 - 01100128 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2017-06-13 19:28 - 2017-06-03 05:48 - 00989024 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2017-06-13 19:28 - 2017-06-03 05:44 - 01600624 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll
2017-06-13 19:28 - 2017-06-03 05:40 - 01566552 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll
2017-06-13 19:28 - 2017-06-03 05:40 - 00628552 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2017-06-13 19:28 - 2017-06-03 05:39 - 00455520 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe
2017-06-13 19:28 - 2017-06-03 05:23 - 00306688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll
2017-06-13 19:28 - 2017-06-03 05:22 - 07217152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2017-06-13 19:28 - 2017-06-03 05:18 - 22569984 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2017-06-13 19:28 - 2017-06-03 05:16 - 00002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzres.dll
2017-06-13 19:28 - 2017-06-03 05:15 - 19414016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2017-06-13 19:28 - 2017-06-03 05:15 - 18364928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2017-06-13 19:28 - 2017-06-03 05:14 - 00045056 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2017-06-13 19:28 - 2017-06-03 05:11 - 00353792 _____ (Microsoft Corporation) C:\WINDOWS\system32\cloudAP.dll
2017-06-13 19:28 - 2017-06-03 05:10 - 00418304 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.BlockedShutdown.dll
2017-06-13 19:28 - 2017-06-03 05:10 - 00252928 _____ (Microsoft Corporation) C:\WINDOWS\system32\edputil.dll
2017-06-13 19:28 - 2017-06-03 05:10 - 00117760 _____ (Microsoft Corporation) C:\WINDOWS\system32\AuthBrokerUI.dll
2017-06-13 19:28 - 2017-06-03 05:09 - 00489472 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupShim.dll
2017-06-13 19:28 - 2017-06-03 05:09 - 00337408 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkBindingEngineMigPlugin.dll
2017-06-13 19:28 - 2017-06-03 05:08 - 12187648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2017-06-13 19:28 - 2017-06-03 05:08 - 00691200 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll
2017-06-13 19:28 - 2017-06-03 05:08 - 00324608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.LockScreen.dll
2017-06-13 19:28 - 2017-06-03 05:08 - 00147456 _____ (Microsoft Corporation) C:\WINDOWS\system32\winsrv.dll
2017-06-13 19:28 - 2017-06-03 05:07 - 00255488 _____ (Microsoft Corporation) C:\WINDOWS\system32\HNetCfgClient.dll
2017-06-13 19:28 - 2017-06-03 05:06 - 03664384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2017-06-13 19:28 - 2017-06-03 05:06 - 00198144 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpapisrv.dll
2017-06-13 19:28 - 2017-06-03 05:04 - 06042624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2017-06-13 19:28 - 2017-06-03 05:03 - 00932864 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2017-06-13 19:28 - 2017-06-03 05:01 - 00856064 _____ (Microsoft Corporation) C:\WINDOWS\system32\efscore.dll
2017-06-13 19:28 - 2017-06-03 05:00 - 23677440 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2017-06-13 19:28 - 2017-06-03 04:58 - 00064512 _____ (Microsoft Corporation) C:\WINDOWS\system32\fdProxy.dll
2017-06-13 19:28 - 2017-06-03 04:56 - 13091840 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2017-06-13 19:28 - 2017-06-03 04:53 - 08125440 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2017-06-13 19:28 - 2017-06-03 04:52 - 02510848 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll
2017-06-13 19:28 - 2017-06-03 04:52 - 00975872 _____ (Microsoft Corporation) C:\WINDOWS\HelpPane.exe
2017-06-13 19:28 - 2017-06-03 04:52 - 00886784 _____ (Microsoft Corporation) C:\WINDOWS\system32\CPFilters.dll
2017-06-13 19:28 - 2017-06-03 04:51 - 01418240 _____ (Microsoft Corporation) C:\WINDOWS\system32\certutil.exe
2017-06-13 19:28 - 2017-06-03 04:50 - 04744704 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2017-06-13 19:28 - 2017-06-03 04:49 - 03615744 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2017-06-13 19:28 - 2017-06-03 04:49 - 02691072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll
2017-06-13 19:28 - 2017-06-03 04:49 - 02475520 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWrite.dll
2017-06-13 19:28 - 2017-06-03 04:49 - 02318848 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2017-06-13 19:28 - 2017-06-03 04:49 - 01845248 _____ (Microsoft Corporation) C:\WINDOWS\system32\FntCache.dll
2017-06-13 19:28 - 2017-06-03 04:49 - 01513472 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2017-06-13 19:28 - 2017-06-03 04:49 - 00351744 _____ (Microsoft Corporation) C:\WINDOWS\system32\hnetcfg.dll
2017-06-13 19:28 - 2017-06-03 04:48 - 01490432 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2017-06-13 19:28 - 2017-06-03 04:46 - 01121280 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadtb.dll
2017-06-13 19:28 - 2017-06-03 02:08 - 00080078 _____ C:\WINDOWS\system32\normidna.nls
2017-06-13 19:28 - 2017-03-04 02:22 - 00822784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll
2017-06-13 19:28 - 2017-03-04 02:19 - 00635904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll
2017-06-11 19:29 - 2017-06-11 19:29 - 00816752 _____ C:\Users\Phikicheli\Downloads\GH3-Plus-shfix-b2.zip
2017-06-10 00:04 - 2017-06-10 00:05 - 08224339 _____ C:\Users\Phikicheli\Downloads\Dr Wily (Theme).rar
2017-06-09 23:57 - 2017-06-09 23:57 - 00000000 ____D C:\Users\Phikicheli\Downloads\RB3_MMX1_2_Comp
2017-06-09 23:54 - 2017-06-09 23:55 - 317854619 _____ C:\Users\Phikicheli\Downloads\RB3_MMX1_2_Comp.rar
2017-06-09 21:12 - 2017-06-09 21:12 - 00033090 _____ C:\Users\Phikicheli\Downloads\115(1).chart
2017-06-09 20:57 - 2017-06-09 20:57 - 00033090 _____ C:\Users\Phikicheli\Downloads\115.chart
2017-06-09 14:54 - 2017-06-09 14:54 - 00000000 ____D C:\Users\Phikicheli\Downloads\Win 10 Pro X32 & X64
2017-06-08 15:45 - 2017-06-08 15:45 - 00000000 ____D C:\Users\Phikicheli\AppData\Local\Microsoft_Corporation
2017-06-07 19:44 - 2017-06-07 19:44 - 00933066 _____ C:\Users\Phikicheli\Downloads\JoyToKey_en.zip
2017-06-07 19:44 - 2017-06-07 19:44 - 00000000 ____D C:\Users\Phikicheli\Downloads\JoyToKey_en
2017-06-07 19:38 - 2017-06-07 19:38 - 00000000 ____D C:\Users\Phikicheli\AppData\Roaming\DS4Windows
2017-06-07 16:20 - 2017-06-07 16:20 - 00000132 _____ C:\Users\Phikicheli\AppData\Roaming\Adobe PNG Format CS6 Prefs
2017-06-07 15:35 - 2017-07-01 14:05 - 00003169 _____ C:\Users\Phikicheli\Desktop\GHTCP.lnk
2017-06-07 13:39 - 2017-06-07 13:39 - 08127110 _____ C:\Users\Phikicheli\Downloads\Dance Gavin Dance - Chucky vs The Giant Tortoise.rar
2017-06-07 13:30 - 2017-06-07 13:30 - 57020916 _____ C:\Users\Phikicheli\Downloads\Black Fretboard.rar
2017-06-05 21:57 - 2017-06-05 21:57 - 16020538 _____ C:\Users\Phikicheli\Downloads\ZONES - Default with Taps.rar
2017-06-05 17:10 - 2017-06-05 17:10 - 21198032 _____ C:\Users\Phikicheli\Downloads\Black & White Zones.rar
2017-06-05 15:52 - 2017-06-05 15:52 - 21417323 _____ C:\Users\Phikicheli\Downloads\All Blue Zones with White SP.rar
2017-06-05 14:29 - 2017-06-13 23:12 - 00000000 ____D C:\Users\Phikicheli\Documents\Audacity
2017-06-05 14:27 - 2017-06-24 15:27 - 00000000 ____D C:\Users\Phikicheli\AppData\Roaming\audacity
2017-06-05 14:27 - 2017-06-05 14:27 - 00000000 ____D C:\Users\Phikicheli\AppData\Local\Audacity
2017-06-05 14:26 - 2017-06-05 14:26 - 27113272 _____ (Audacity Team ) C:\Users\Phikicheli\Downloads\audacity-win-2.1.3.exe
2017-06-04 02:00 - 2017-06-04 02:00 - 00000000 ____D C:\Users\Public\Documents\Steam
2017-06-04 01:45 - 2017-07-01 18:08 - 00001205 _____ C:\Users\Phikicheli\Desktop\Ultimate Marvel vs. Capcom 3.lnk
2017-06-04 01:45 - 2017-06-04 01:45 - 00000000 ____D C:\Users\Phikicheli\AppData\Local\CAPCOM

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-07-04 13:01 - 2016-12-05 23:35 - 00000000 ____D C:\Users\Phikicheli\AppData\LocalLow\Mozilla
2017-07-02 02:31 - 2016-12-06 01:26 - 00400937 ____N C:\WINDOWS\Minidump\070217-48625-01.dmp
2017-07-02 01:44 - 2016-12-06 01:35 - 00000000 __RHD C:\Users\Public\AccountPictures
2017-07-02 00:17 - 2016-12-07 02:41 - 00000000 ____D C:\Users\Phikicheli\AppData\Roaming\deluge
2017-07-01 20:15 - 2016-12-25 14:15 - 00000000 ____D C:\Users\Phikicheli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2017-07-01 14:04 - 2016-12-06 03:02 - 00000000 ____D C:\Users\Phikicheli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2017-07-01 13:57 - 2016-12-18 08:45 - 00000931 _____ C:\Users\Public\Desktop\Nexus Mod Manager.lnk
2017-07-01 13:55 - 2017-01-20 23:58 - 00001008 _____ C:\Users\Phikicheli\Desktop\Open Broadcaster Software.lnk
2017-07-01 13:51 - 2017-01-22 18:53 - 00000000 ____D C:\Users\Phikicheli\AppData\Roaming\Curse Client
2017-07-01 01:25 - 2016-07-16 02:04 - 00120320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\poqexec.exe
2017-07-01 01:24 - 2016-07-16 07:41 - 00156672 _____ (Microsoft Corporation) C:\WINDOWS\system32\hidclass.sys
2017-07-01 01:24 - 2016-07-16 07:41 - 00040960 _____ (Microsoft Corporation) C:\WINDOWS\system32\hidparse.sys
2017-07-01 01:24 - 2016-07-16 07:41 - 00038400 _____ (Microsoft Corporation) C:\WINDOWS\system32\hidusb.sys
2017-07-01 01:21 - 2016-07-16 02:04 - 00142848 _____ (Microsoft Corporation) C:\WINDOWS\system32\poqexec.exe
2017-06-30 23:07 - 2016-12-06 01:37 - 00000000 ___RD C:\Users\Phikicheli\OneDrive
2017-06-30 20:07 - 2017-01-09 23:03 - 00000000 ____D C:\Users\Phikicheli\AppData\Local\ElevatedDiagnostics
2017-06-29 02:45 - 2017-01-07 15:21 - 00000000 ____D C:\Users\Phikicheli\AppData\Local\CorsairEffectsEngine
2017-06-26 11:54 - 2016-12-07 01:43 - 00000000 ____D C:\Users\Phikicheli\AppData\Local\Akamai
2017-06-26 10:01 - 2016-12-20 19:52 - 00000000 ____D C:\AirDroid
2017-06-25 21:22 - 2017-02-11 18:41 - 00000000 ____D C:\Users\Phikicheli\AppData\Local\Ubisoft Game Launcher
2017-06-25 15:36 - 2016-12-27 01:22 - 00000000 ____D C:\Users\Phikicheli\AppData\Local\Oculus
2017-06-25 02:00 - 2016-12-07 03:11 - 00000000 ____D C:\Users\Phikicheli\AppData\Local\Adobe
2017-06-24 22:21 - 2016-12-06 10:38 - 00000000 ____D C:\Users\Phikicheli\Documents\My Games
2017-06-23 22:47 - 2016-12-07 03:28 - 00001456 _____ C:\Users\Phikicheli\AppData\Local\Adobe Save for Web 13.0 Prefs
2017-06-20 17:40 - 2016-12-19 04:13 - 00001020 _____ C:\Users\Phikicheli\Desktop\osu!.lnk
2017-06-17 19:42 - 2017-05-01 16:32 - 00001329 _____ C:\Users\Phikicheli\Desktop\GH3.pie
2017-06-16 01:42 - 2016-12-05 22:04 - 00000000 ____D C:\Users\Phikicheli\Desktop\Game Folders
2017-06-16 01:40 - 2016-12-19 04:13 - 00000000 ____D C:\Users\Phikicheli\AppData\Local\osu!
2017-06-07 12:43 - 2015-05-11 09:56 - 00000000 ____D C:\Users\Phikicheli\Desktop\Emulators
2017-06-04 02:52 - 2017-05-23 17:23 - 00000000 ____D C:\Users\Phikicheli\Documents\3D Animation
2017-06-04 01:35 - 2017-06-03 23:57 - 00000000 ____D C:\Users\Phikicheli\Downloads\codex-ultimate.marvel.vs.capcom.3

==================== Files in the root of some directories =======

2017-02-27 19:20 - 2017-02-27 19:20 - 0000132 _____ () C:\Users\Phikicheli\AppData\Roaming\Adobe BMP Format CS6 Prefs
2017-06-07 16:20 - 2017-06-07 16:20 - 0000132 _____ () C:\Users\Phikicheli\AppData\Roaming\Adobe PNG Format CS6 Prefs
2017-02-13 18:28 - 2017-02-22 19:34 - 0000132 _____ () C:\Users\Phikicheli\AppData\Roaming\Adobe Targa Format CS6 Prefs
2016-12-07 03:28 - 2017-06-23 22:47 - 0001456 _____ () C:\Users\Phikicheli\AppData\Local\Adobe Save for Web 13.0 Prefs
2017-06-30 20:21 - 2017-06-30 20:36 - 0000000 _____ () C:\Users\Phikicheli\AppData\Local\Driver_LOM_8161Present.flag
2017-07-02 00:35 - 2017-07-02 00:35 - 0000218 _____ () C:\Users\Phikicheli\AppData\Local\recently-used.xbel
2017-05-17 11:32 - 2017-05-17 11:32 - 0125952 _____ () C:\Users\Phikicheli\AppData\Local\report

Some files in TEMP:
====================
2017-05-23 15:34 - 2015-01-26 07:59 - 0060296 _____ (Autodesk, Inc.) C:\Users\Phikicheli\AppData\Local\Temp\AcDeltree.exe
2017-02-11 00:06 - 2017-02-11 00:06 - 0017408 _____ () C:\Users\Phikicheli\AppData\Local\Temp\jansi-32-git-Bukkit-jenkins-CraftBukkit-173.dll
2017-02-11 03:07 - 2017-02-11 03:07 - 0017408 _____ () C:\Users\Phikicheli\AppData\Local\Temp\jansi-64-git-Bukkit-jenkins-CraftBukkit-173.dll
2017-01-20 23:08 - 2017-01-20 23:08 - 0739904 _____ (Oracle Corporation) C:\Users\Phikicheli\AppData\Local\Temp\jre-8u121-windows-au.exe
2017-05-04 17:12 - 2017-05-04 17:12 - 0739904 _____ (Oracle Corporation) C:\Users\Phikicheli\AppData\Local\Temp\jre-8u131-windows-au.exe
2017-06-24 23:00 - 2017-06-24 23:00 - 6441096 _____ (Black Tree Gaming                                           ) C:\Users\Phikicheli\AppData\Local\Temp\Nexus Mod Manager-0.63.14.exe
2017-02-23 23:22 - 2017-02-23 23:22 - 2903480 _____ () C:\Users\Phikicheli\AppData\Local\Temp\npp.7.3.2.Installer.exe
2016-12-05 23:11 - 2017-03-31 21:36 - 0754168 _____ (NVIDIA Corporation) C:\Users\Phikicheli\AppData\Local\Temp\nvSCPAPI.dll
2016-12-05 23:11 - 2017-03-31 21:36 - 0868152 _____ (NVIDIA Corporation) C:\Users\Phikicheli\AppData\Local\Temp\nvSCPAPI64.dll
2016-12-05 23:07 - 2017-03-31 21:36 - 0369208 _____ (NVIDIA Corporation) C:\Users\Phikicheli\AppData\Local\Temp\nvStInst.exe
2016-12-05 22:56 - 2016-11-17 09:42 - 1135552 _____ (NVIDIA Corporation) C:\Users\Phikicheli\AppData\Local\Temp\NvTelemetry.dll
2016-12-05 22:56 - 2017-01-05 21:10 - 0255032 _____ (NVIDIA Corporation) C:\Users\Phikicheli\AppData\Local\Temp\NvTelemetryAPI32.dll
2016-12-05 22:56 - 2017-01-05 21:10 - 0335928 _____ (NVIDIA Corporation) C:\Users\Phikicheli\AppData\Local\Temp\NvTelemetryAPI64.dll
2013-03-04 09:38 - 2013-03-04 09:38 - 9357573 _____ (Macrovision Corporation) C:\Users\Phikicheli\AppData\Local\Temp\Samsung_MonSetup.exe
2016-12-27 01:40 - 2015-01-22 11:01 - 0032768 _____ () C:\Users\Phikicheli\AppData\Local\Temp\shutdown1482817200.exe

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2017-06-30 21:58

==================== End of FRST.txt ============================


Addition.txt

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 03-07-2017 01
Ran by Phikicheli (04-07-2017 13:07:10)
Running from C:\Users\Phikicheli\Desktop
Windows 10 Pro Version 1607 (X64) (2017-07-01 02:25:32)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-1712185177-3340612968-1910388385-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-1712185177-3340612968-1910388385-503 - Limited - Disabled)
defaultuser0 (S-1-5-21-1712185177-3340612968-1910388385-1000 - Limited - Enabled) => C:\Users\defaultuser0
Guest (S-1-5-21-1712185177-3340612968-1910388385-501 - Limited - Disabled)
Phikicheli (S-1-5-21-1712185177-3340612968-1910388385-1001 - Administrator - Enabled) => C:\Users\Phikicheli

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Ansel (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Ansel) (Version: 376.09 - NVIDIA Corporation) Hidden
ASIO4ALL (HKLM-x32\...\ASIO4ALL) (Version: 2.12 - Michael Tippach)
Classic Shell (HKLM\...\{383BB30A-B4A7-4666-9A83-22CFA8640097}) (Version: 4.3.0 - IvoSoft)
Corsair Utility Engine (HKLM-x32\...\{A9114889-E4D2-4112-B461-22179C0E122C}) (Version: 2.14.67 - Corsair)
Dark Souls: Prepare to Die Edition (HKLM\...\Steam App 211420) (Version:  - FromSoftware)
Deluge 1.3.15 (HKLM-x32\...\Deluge) (Version:  - )
Dolphin (HKLM-x32\...\Dolphin) (Version: 5.0 - Dolphin Team)
Fallout: New Vegas (HKLM\...\Steam App 22380) (Version:  - Obsidian Entertainment)
FL Studio 12 (HKLM-x32\...\FL Studio 12) (Version:  - Image-Line)
FL Studio ASIO (HKLM-x32\...\FL Studio ASIO) (Version:  - Image-Line)
Guitar Hero Three Control Panel (HKLM-x32\...\{FC7CCCFB-2081-4E9D-8F6D-CAAE87267E6C}) (Version: 2.0.4 - Sigma Production Inc.)
Killer Bandwidth Control Filter Driver (HKLM\...\{0E7D4EFF-8EDD-4BBC-B28A-181E153C0A28}) (Version: 1.1.65.1138 - Rivet Networks) Hidden
Killer E220x Drivers (HKLM\...\{E62AC0FE-33FB-4567-9117-24E01F1D5624}) (Version: 1.1.65.1138 - Rivet Networks) Hidden
Killer Network Manager (HKLM\...\{E2167A24-B822-4D48-8258-E494415DE350}) (Version: 1.1.65.1138 - Rivet Networks) Hidden
Killer Performance Suite (HKLM-x32\...\{E70DB50B-10B4-46BC-9DE2-AB8B49E061EE}) (Version: 1.1.65.1138 - Rivet Networks)
Kung Fu Panda Showdown of Legendary Legends (HKLM\...\Steam App 369230) (Version:  - Vicious Cycle Software)
Lethal League (HKLM\...\Steam App 261180) (Version:  - Team Reptile)
Malwarebytes version 3.1.2.1733 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.1.2.1733 - Malwarebytes)
Microsoft OneDrive (HKU\S-1-5-21-1712185177-3340612968-1910388385-1001\...\OneDriveSetup.exe) (Version: 17.3.6917.0607 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\...\{7f51bdb9-ee21-49ee-94d6-90afc321780e}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23918 (HKLM-x32\...\{dab68466-3a7d-41a8-a5cf-415e3ff8ef71}) (Version: 14.0.23918.0 - Microsoft Corporation)
Nexus Mod Manager (HKLM\...\6af12c54-643b-4752-87d0-8335503010de_is1) (Version: 0.63.14 - Black Tree Gaming)
NVIDIA 3D Vision Controller Driver 369.04 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 369.04 - NVIDIA Corporation)
NVIDIA 3D Vision Driver 376.53 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 376.53 - NVIDIA Corporation)
NVIDIA GeForce Experience 3.7.0.81 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.7.0.81 - NVIDIA Corporation)
NVIDIA Graphics Driver 376.53 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 376.53 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.16.0318 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.16.0318 - NVIDIA Corporation)
NvNodejs (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvNodejs) (Version: 3.7.0.81 - NVIDIA Corporation) Hidden
NvTelemetry (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvTelemetry) (Version: 2.6.1.0 - NVIDIA Corporation) Hidden
NvvHci (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvvHci) (Version: 2.02.0.5 - NVIDIA Corporation) Hidden
OBS Studio (HKLM-x32\...\OBS Studio) (Version: 19.0.3 - OBS Project)
Open Broadcaster Software (HKLM-x32\...\Open Broadcaster Software) (Version:  - )
Quake (HKLM\...\Steam App 2310) (Version:  - id Software)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7960 - Realtek Semiconductor Corp.)
Rocket League (HKLM\...\Steam App 252950) (Version:  - Psyonix, Inc.)
SHIELD Streaming (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GFExperience.NvStreamSrv) (Version: 7.1.0380 - NVIDIA Corporation) Hidden
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
SteelSeries Engine 3.10.8 (HKLM\...\SteelSeries Engine 3) (Version: 3.10.8 - SteelSeries ApS)
The Elder Scrolls III: Morrowind (HKLM\...\Steam App 22320) (Version:  - Bethesda Game Studios)
Tom Clancy's Rainbow Six Siege (HKLM\...\Steam App 359550) (Version:  - Ubisoft Montreal)
Ultimate Chicken Horse (HKLM\...\Steam App 386940) (Version:  - Clever Endeavour Games)
Ultimate Marvel vs. Capcom 3 (HKLM-x32\...\Ultimate Marvel vs. Capcom 3_is1) (Version:  - )
Vulkan Run Time Libraries 1.0.26.0 (HKLM\...\VulkanRT1.0.26.0) (Version: 1.0.26.0 - LunarG, Inc.)
Waterfox 54.0.0.1 (x64 en-US) (HKLM\...\Waterfox 54.0.0.1 (x64 en-US)) (Version: 54.0.0.1 - Waterfox Ltd)
Windows 10 Update and Privacy Settings (HKLM\...\{4DFCD818-036A-4229-A67D-CF17DC461D92}) (Version: 1.0.14.0 - Microsoft Corporation)
WinRAR 5.40 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.40.0 - win.rar GmbH)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

ShellIconOverlayIdentifiers: [ShareOverlay] -> {594D4122-1F87-41E2-96C7-825FB4796516} => C:\Program Files\Classic Shell\ClassicExplorer64.dll [2016-07-30] (IvoSoft)
ShellIconOverlayIdentifiers-x32: [ShareOverlay] -> {594D4122-1F87-41E2-96C7-825FB4796516} => C:\Program Files\Classic Shell\ClassicExplorer32.dll [2016-07-30] (IvoSoft)
ContextMenuHandlers01: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2016-08-15] (Alexander Roshal)
ContextMenuHandlers01: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} =>  -> No File
ContextMenuHandlers03: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-05-09] (Malwarebytes)
ContextMenuHandlers05: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\system32\nvshext.dll [2016-12-29] (NVIDIA Corporation)
ContextMenuHandlers06: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-05-09] (Malwarebytes)
ContextMenuHandlers06: [StartMenuExt] -> {E595F05F-903F-4318-8B0A-7F633B520D2B} => C:\WINDOWS\system32\StartMenuHelper64.dll [2016-07-30] (IvoSoft)
ContextMenuHandlers06: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2016-08-15] (Alexander Roshal)
ContextMenuHandlers06: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} =>  -> No File

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {04775910-4C2B-497E-ABD7-1C68FD6F4B53} - System32\Tasks\{9214DA17-6D07-47E0-A3C0-86794308B628} => pcalua.exe -a C:\Users\Phikicheli\Desktop\ScpServer\bin\ScpService.exe -d C:\Users\Phikicheli\Desktop\ScpServer\bin
Task: {2552350E-3487-4145-883F-FEAB9C625928} - System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe [2017-06-21] (NVIDIA Corporation)
Task: {4E68D125-CA67-4087-81E5-0296E9EAE628} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [2017-06-21] (NVIDIA Corporation)
Task: {5C2E546B-07BA-4C1A-B9DD-BAF18AFFE47A} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2017-06-21] (NVIDIA Corporation)
Task: {6A7F5E70-70EC-4FB0-B3F2-8408340FB3AC} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [2017-06-21] (NVIDIA Corporation)
Task: {6C51789E-F2DE-4C93-80A1-2D49070BEB76} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [2017-06-21] (NVIDIA Corporation)
Task: {A388E512-B2E7-4BE1-8DF7-A1B0668E16B1} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2017-06-21] (NVIDIA Corporation)
Task: {C3EBE92C-49DA-4C17-BA70-36FE39EFE49C} - System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2017-06-21] (NVIDIA Corporation)
Task: {D076DF5C-6305-4C12-AC61-7BBFB3110FF7} - System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2017-06-21] (NVIDIA Corporation)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe

==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)


Shortcut: C:\Users\Phikicheli\Documents\Oculus\Doom\GZ3DoomRiftMonitor2 - Shortcut.lnk -> C:\Program Files (x86)\GZ3Doom 1.8.6_l\GZ3DoomRiftMonitor2.bat (No File)
Shortcut: C:\Users\Phikicheli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\KingsIsle Entertainment\Wizard101\Report a bug.lnk -> C:\ProgramData\KingsIsle Entertainment\Wizard101\Bin\BugReporter.bat (No File)

==================== Loaded Modules (Whitelisted) ==============

2017-07-02 04:04 - 2017-06-27 12:06 - 02260432 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\MwacLib.dll
2017-06-30 22:50 - 2017-06-21 03:07 - 01267320 _____ () C:\Program Files\NVIDIA Corporation\NvContainer\libprotobuf.dll
2016-07-16 07:42 - 2016-07-16 07:42 - 00231424 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll
2017-06-13 19:28 - 2017-06-03 06:01 - 02681200 _____ () C:\WINDOWS\System32\CoreUIComponents.dll
2017-06-30 22:49 - 2016-12-29 08:44 - 00134712 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2016-12-07 02:27 - 2016-09-07 00:56 - 00134656 _____ () C:\Windows\ShellExperiences\Windows.UI.Shell.SharedUtilities.dll
2017-03-14 15:50 - 2017-03-04 02:31 - 00474112 _____ () C:\Windows\ShellExperiences\QuickActions.dll
2017-03-14 15:51 - 2017-03-04 02:12 - 09760768 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2017-03-14 15:51 - 2017-03-04 02:05 - 01401856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2017-03-14 15:51 - 2017-03-04 02:05 - 00757248 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CSGSuggestLib.dll
2017-06-13 19:28 - 2017-06-03 04:47 - 01033216 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Actions.dll
2017-06-13 19:28 - 2017-06-03 04:47 - 02424320 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2017-06-13 19:28 - 2017-06-03 04:51 - 04853760 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2017-06-30 23:12 - 2017-06-30 23:13 - 00074752 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.18.614.0_x64__kzf8qxf38zg5c\SkypeHost.exe
2017-06-30 23:12 - 2017-06-30 23:13 - 00203264 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.18.614.0_x64__kzf8qxf38zg5c\SkypeBackgroundTasks.dll
2017-06-30 23:12 - 2017-06-30 23:13 - 43454464 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.18.614.0_x64__kzf8qxf38zg5c\SkyWrap.dll
2017-06-30 23:12 - 2017-06-30 23:13 - 02437120 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.18.614.0_x64__kzf8qxf38zg5c\skypert.dll
2017-06-30 23:14 - 2017-07-01 13:53 - 00020480 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.18062.12990.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
2017-06-30 23:14 - 2017-07-01 13:53 - 27430400 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.18062.12990.0_x64__8wekyb3d8bbwe\Microsoft.Photos.dll
2017-06-30 23:14 - 2017-07-01 13:53 - 00460288 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.18062.12990.0_x64__8wekyb3d8bbwe\Microsoft.Photos.AGM.Native.Windows.dll
2017-06-30 23:14 - 2017-07-01 13:53 - 02275328 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.18062.12990.0_x64__8wekyb3d8bbwe\MediaEngine.dll
2017-06-30 23:12 - 2017-06-30 23:13 - 03139496 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.18062.12990.0_x64__8wekyb3d8bbwe\Microsoft.UI.Xaml.dll
2017-06-30 23:14 - 2017-07-01 13:53 - 00046080 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.18062.12990.0_x64__8wekyb3d8bbwe\Microsoft.Photos.Edit.Services.dll
2017-06-30 23:14 - 2017-07-01 13:53 - 00680448 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.18062.12990.0_x64__8wekyb3d8bbwe\Microsoft.DesignCore.dll
2017-06-30 23:14 - 2017-07-01 13:53 - 00900096 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.18062.12990.0_x64__8wekyb3d8bbwe\Microsoft.RichMedia.Ink.Controls.dll
2017-06-30 23:14 - 2017-07-01 13:53 - 01062400 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.18062.12990.0_x64__8wekyb3d8bbwe\Microsoft.Sharing.dll
2016-07-16 10:37 - 2016-07-16 10:37 - 00291328 ____N () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.18062.12990.0_x64__8wekyb3d8bbwe\StoreRatingPromotion.dll
2017-06-30 22:50 - 2017-06-21 03:07 - 01040504 _____ () C:\Program Files (x86)\NVIDIA Corporation\NvContainer\libprotobuf.dll
2017-07-01 02:42 - 2017-05-16 21:54 - 00678176 _____ () C:\Program Files (x86)\Steam\SDL2.dll
2017-07-01 02:42 - 2016-08-31 21:02 - 04969248 _____ () C:\Program Files (x86)\Steam\v8.dll
2017-07-01 02:42 - 2017-06-08 01:42 - 02485536 _____ () C:\Program Files (x86)\Steam\video.dll
2017-07-01 02:42 - 2016-01-27 03:49 - 02549760 _____ () C:\Program Files (x86)\Steam\libavcodec-56.dll
2017-07-01 02:42 - 2016-01-27 03:49 - 00491008 _____ () C:\Program Files (x86)\Steam\libavformat-56.dll
2017-07-01 02:42 - 2016-01-27 03:49 - 00332800 _____ () C:\Program Files (x86)\Steam\libavresample-2.dll
2017-07-01 02:42 - 2016-01-27 03:49 - 00442880 _____ () C:\Program Files (x86)\Steam\libavutil-54.dll
2017-07-01 02:42 - 2016-01-27 03:49 - 00485888 _____ () C:\Program Files (x86)\Steam\libswscale-3.dll
2017-07-01 02:42 - 2016-08-31 21:02 - 01563936 _____ () C:\Program Files (x86)\Steam\icui18n.dll
2017-07-01 02:42 - 2016-08-31 21:02 - 01195296 _____ () C:\Program Files (x86)\Steam\icuuc.dll
2017-07-01 02:42 - 2017-06-08 01:42 - 00877856 _____ () C:\Program Files (x86)\Steam\bin\chromehtml.DLL
2017-07-01 02:42 - 2016-07-04 18:17 - 00266560 _____ () C:\Program Files (x86)\Steam\openvr_api.dll
2017-06-30 22:50 - 2017-06-21 03:06 - 66837112 _____ () C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\libcef.dll
2017-07-01 02:45 - 2017-05-08 15:45 - 69516064 _____ () C:\Program Files (x86)\Steam\bin\cef\cef.win7\libcef.dll
2017-07-01 02:45 - 2017-05-16 21:54 - 00678176 _____ () C:\Program Files (x86)\Steam\bin\cef\cef.win7\SDL2.dll
2017-07-01 02:42 - 2017-06-08 01:42 - 00385312 _____ () C:\Program Files (x86)\Steam\steam.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"

==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)

HKU\S-1-5-21-1712185177-3340612968-1910388385-1001\Software\Classes\regfile: regedit.exe "%1" <==== ATTENTION

==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2017-07-01 01:37 - 2017-07-01 01:32 - 00000824 _____ C:\WINDOWS\system32\Drivers\etc\hosts


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-1712185177-3340612968-1910388385-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Phikicheli\Downloads\lFNnyEP-japanese-scenery-wallpaper.jpg
DNS Servers: 75.75.75.75 - 75.75.76.76
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: Off)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==


==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{1E99EC98-A774-49E0-BD90-AD8860EB37A2}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
FirewallRules: [{86B3A3B0-D6EC-4E13-AF5F-6E72CEB590A2}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
FirewallRules: [{E06FA7C0-C515-4FC1-80F7-104CC45B80E3}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
FirewallRules: [{48B305F9-2707-4A93-AA08-C40A64B6EE04}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{C102493D-3F79-4CC2-8588-8E7465C4F3D6}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{059BADAF-6828-4124-8999-1E8C9F9100D1}] => (Allow) C:\Program Files\Waterfox\waterfox.exe
FirewallRules: [{1A8FD78D-2CFB-4464-9D5C-15B65BE6D45A}] => (Allow) C:\Program Files\Waterfox\waterfox.exe
FirewallRules: [{CEA2FE67-03B9-4158-862D-8F9DF20F2D63}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{082ED40F-C263-4867-BBA5-48349F89AF28}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{A8BFF70C-5A54-40C0-B2EA-660EB543E797}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [{FAB82199-5906-4293-A9CF-C8467FC1E62C}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [TCP Query User{82A99BB8-8210-48B8-95D4-4F85B78C56B8}C:\program files (x86)\fightcade\fightcade.exe] => (Allow) C:\program files (x86)\fightcade\fightcade.exe
FirewallRules: [UDP Query User{B5672E01-C0CF-431A-89B1-67A84A4EBC89}C:\program files (x86)\fightcade\fightcade.exe] => (Allow) C:\program files (x86)\fightcade\fightcade.exe
FirewallRules: [TCP Query User{62495BAF-DA4C-4BA9-B09A-F5B594F31FF0}C:\program files (x86)\deluge\deluge.exe] => (Allow) C:\program files (x86)\deluge\deluge.exe
FirewallRules: [UDP Query User{F0B53049-D569-4303-B7E6-BE25F93411A8}C:\program files (x86)\deluge\deluge.exe] => (Allow) C:\program files (x86)\deluge\deluge.exe
FirewallRules: [{0D314091-89F9-411E-B597-D478E1A17921}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Fallout New Vegas\FalloutNVLauncher.exe
FirewallRules: [{18D8FCBC-E76B-4F59-B219-E0029418CEA6}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Fallout New Vegas\FalloutNVLauncher.exe
FirewallRules: [{749AA4CC-6BC4-4F4B-843D-CA5BBA25F2FD}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Quake\Winquake.exe
FirewallRules: [{DB1980B2-5F1E-4376-8C10-1D6E525D1B0A}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Quake\Winquake.exe
FirewallRules: [{A1AC4CB9-F63D-4956-BCB1-C57BB5B2FEB5}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Quake\qwcl.exe
FirewallRules: [{844F34B7-6750-40CF-A0A0-E789098901D5}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Quake\qwcl.exe
FirewallRules: [{7557D8F1-8331-4E4F-8DC2-BAFF94DF93B1}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Quake\Glquake.exe
FirewallRules: [{C9D7D38A-CC8A-45FB-983A-3B2C6F24E89E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Quake\Glquake.exe
FirewallRules: [{9F9BFB8C-7DF5-4596-B079-F1027E2C1518}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Quake\glqwcl.exe
FirewallRules: [{1B363C8F-3169-4BCA-BC57-FC384C56148B}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Quake\glqwcl.exe
FirewallRules: [{E8CEBC9A-2E0A-485B-B8AD-A133B0048190}] => (Allow) C:\WINDOWS\system32\rundll32.exe
FirewallRules: [{EB733D2B-79FE-471C-B88D-9141F4723927}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Morrowind\Morrowind Launcher.exe
FirewallRules: [{57F8D656-3176-4F87-A03B-367450B7EACC}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Morrowind\Morrowind Launcher.exe
FirewallRules: [{CEB27089-04F4-467D-87A0-CBF4D2EACB00}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Kung Fu Panda Showdown of Legendary Legends\KFP.exe
FirewallRules: [{576D6DCA-802C-4F81-A09D-C2366266D03D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Kung Fu Panda Showdown of Legendary Legends\KFP.exe
FirewallRules: [{8020D21F-2CD6-4CE8-8CC9-A4203C7EC337}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Ultimate Chicken Horse\UltimateChickenHorse.exe
FirewallRules: [{6F5BA825-14D5-4901-82EC-2EC6B551F2C9}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Ultimate Chicken Horse\UltimateChickenHorse.exe
FirewallRules: [{E843C483-F567-4732-B471-9100D56FA9CC}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Portal 2\portal2.exe
FirewallRules: [{67BE6099-0733-45DF-BB3D-9428DC855066}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Portal 2\portal2.exe

==================== Restore Points =========================

30-06-2017 23:23:08 Installed Classic Shell
01-07-2017 20:22:06 Before Code
04-07-2017 12:04:05 JRT Pre-Junkware Removal

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (07/04/2017 12:06:26 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: DESKTOP)
Description: Activation of app Microsoft.Windows.ShellExperienceHost_cw5n1h2txyewy!App failed with error: -2144927141 See the Microsoft-Windows-TWinUI/Operational log for additional information.

Error: (07/04/2017 12:04:37 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.

Details:
AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol.

System Error:
Access is denied.
.

Error: (07/04/2017 01:33:50 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: mbamservice.exe, version: 3.1.0.479, time stamp: 0x58f6af02
Faulting module name: MwacControllerImpl.dll, version: 3.0.0.166, time stamp: 0x59395129
Exception code: 0xc0000005
Fault offset: 0x0000000000028c0a
Faulting process id: 0x1470
Faulting application start time: 0x01d2f486fdba9afb
Faulting application path: C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe
Faulting module path: C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\MwacControllerImpl.dll
Report Id: 148c57e1-b07e-4897-8c97-928d672f1292
Faulting package full name:
Faulting package-relative application ID:

Error: (07/03/2017 11:33:17 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine QueryFullProcessImageNameW.  hr = 0x80070006, The handle is invalid.
.


Operation:
   Executing Asynchronous Operation

Context:
   Current State: DoSnapshotSet

Error: (07/03/2017 11:32:33 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.

Details:
AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol.

System Error:
Access is denied.
.

Error: (07/03/2017 06:45:20 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: vmxclient.exe, version: 1.0.1.5, time stamp: 0x58f9c2ba
Faulting module name: libcef.dll, version: 3.2526.1373.0, time stamp: 0x587a0d9a
Exception code: 0xc0000005
Fault offset: 0x001f32b0
Faulting process id: 0x1200
Faulting application start time: 0x01d2f448e632d972
Faulting application path: C:\Users\Phikicheli\AppData\Local\ntuserlitelist\svcvmx\vmxclient.exe
Faulting module path: C:\Users\Phikicheli\AppData\Local\ntuserlitelist\svcvmx\libcef.dll
Report Id: 135170a9-b9d8-4130-b5b1-1b7296572888
Faulting package full name:
Faulting package-relative application ID:

Error: (07/03/2017 07:22:11 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: DESKTOP)
Description: Activation of app Microsoft.Getstarted_5.10.1441.0_x64__8wekyb3d8bbwe:App.AppX7mv0s3r0wanj0n66dy6vax24ps6avzvz.mca failed with error: -2144927149 See the Microsoft-Windows-TWinUI/Operational log for additional information.

Error: (07/03/2017 12:05:58 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3009) (User: NT AUTHORITY)
Description: Installing the performance counter strings for service WmiApRpl (WmiApRpl) failed. The first DWORD in the Data section contains the error code.

Error: (07/03/2017 12:05:58 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3003) (User: NT AUTHORITY)
Description: Unable to install counter strings because the SYSTEM\CurrentControlSet\Services\WmiApRpl\Performance key could not be opened or accessed. The first DWORD in the Data section contains the Win32 error code.

Error: (07/02/2017 02:17:52 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: DESKTOP)
Description: Activation of app Microsoft.Getstarted_5.10.1441.0_x64__8wekyb3d8bbwe:App.AppX7mv0s3r0wanj0n66dy6vax24ps6avzvz.mca failed with error: -2144927149 See the Microsoft-Windows-TWinUI/Operational log for additional information.


System errors:
=============
Error: (07/04/2017 12:46:49 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{8D8F4F83-3594-4F07-8369-FC3C3CAE4919}
 and APPID
{F72671A9-012C-4725-9D2F-2A4D32D65169}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Error: (07/04/2017 12:17:46 PM) (Source: Microsoft-Windows-Kernel-Power) (EventID: 137) (User: )
Description: 5

Error: (07/04/2017 12:17:31 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 and APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Error: (07/04/2017 12:06:26 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP)
Description: The server App did not register with DCOM within the required timeout.

Error: (07/04/2017 12:06:22 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The NVIDIA LocalSystem Container service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 6000 milliseconds: Restart the service.

Error: (07/04/2017 11:59:38 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{8D8F4F83-3594-4F07-8369-FC3C3CAE4919}
 and APPID
{F72671A9-012C-4725-9D2F-2A4D32D65169}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Error: (07/04/2017 11:57:53 AM) (Source: Service Control Manager) (EventID: 7032) (User: )
Description: The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Windows Search service, but this action failed with the following error:
An instance of the service is already running.

Error: (07/04/2017 11:57:46 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 and APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Error: (07/04/2017 11:57:23 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Windows Search service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 30000 milliseconds: Restart the service.

Error: (07/04/2017 11:57:23 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Malwarebytes Service service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 5000 milliseconds: Restart the service.


CodeIntegrity:
===================================
  Date: 2017-06-30 23:12:10.796
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\Windows\System32\nvspcap64.dll that did not meet the Store signing level requirements.

  Date: 2017-06-30 23:12:10.099
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume4\Windows\System32\nvspcap64.dll that did not meet the Store signing level requirements.


==================== Memory info ===========================

Processor: AMD FX™-6300 Six-Core Processor
Percentage of memory in use: 16%
Total physical RAM: 16332.29 MB
Available physical RAM: 13596.92 MB
Total Virtual: 19276.29 MB
Available Virtual: 16333.09 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:698.08 GB) (Free:149.13 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 698.6 GB) (Disk ID: 82A5C00C)

Partition: GPT.

==================== End of Addition.txt ============================



#9 Aura

Aura

    Bleepin' Special Ops


  • Malware Response Team
  • 19,697 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:12:29 PM

Posted 05 July 2017 - 07:08 AM

There isn't much left to remove.

iO3R662.pngFarbar Recovery Scan Tool (FRST) - Fix mode
Follow the instructions below to execute a fix on your system using FRST, and provide the log in your next reply.
  • Download the attached fixlist.txt file, and save it on your Desktop (or wherever your FRST.exe/FRST64.exe executable is located);
  • Right-click on the FRST executable and select Spcusrh.pngRun as Administrator (for Windows Vista, 7, 8, 8.1 and 10 users);
  • Click on the Fix button;
    NYA5Cbr.png
  • On completion, a message will come up saying that the fix has been completed and it'll open a log in Notepad;
  • Copy and paste its content in your next reply;
How's your system behaving now? Are there any other issues to address?

Attached Files


animinionsmalltext.gif
unite_blue.png
Security Administrator | Sysnative Windows Update Senior Analyst | Malware Hunter | @SecurityAura
My timezone UTC-05:00 (East. Coast). If I didn't reply to you within 48 hours, please send me a PM.


#10 Phiki

Phiki
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:06:29 PM

Posted 07 July 2017 - 07:30 PM

There isn't much left to remove.

iO3R662.pngFarbar Recovery Scan Tool (FRST) - Fix mode
Follow the instructions below to execute a fix on your system using FRST, and provide the log in your next reply.

  • Download the attached fixlist.txt file, and save it on your Desktop (or wherever your FRST.exe/FRST64.exe executable is located);
  • Right-click on the FRST executable and select Spcusrh.pngRun as Administrator (for Windows Vista, 7, 8, 8.1 and 10 users);
  • Click on the Fix button;
    NYA5Cbr.png
  • On completion, a message will come up saying that the fix has been completed and it'll open a log in Notepad;
  • Copy and paste its content in your next reply;
How's your system behaving now? Are there any other issues to address?

 

Computer seems fine now. Thank you so much! I completely forgot to paste the fixlog, so sorry about that. Everything seems fine now though.



#11 Aura

Aura

    Bleepin' Special Ops


  • Malware Response Team
  • 19,697 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:12:29 PM

Posted 07 July 2017 - 07:50 PM

Do you still have the fixlog.txt on your desktop, or did you delete it?

animinionsmalltext.gif
unite_blue.png
Security Administrator | Sysnative Windows Update Senior Analyst | Malware Hunter | @SecurityAura
My timezone UTC-05:00 (East. Coast). If I didn't reply to you within 48 hours, please send me a PM.


#12 Phiki

Phiki
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:06:29 PM

Posted 10 July 2017 - 07:30 AM

Do you still have the fixlog.txt on your desktop, or did you delete it?

I deleted it. :(



#13 Aura

Aura

    Bleepin' Special Ops


  • Malware Response Team
  • 19,697 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:12:29 PM

Posted 10 July 2017 - 07:31 AM

All good :)

How's your system behaving now? Are there any other issues to address?

animinionsmalltext.gif
unite_blue.png
Security Administrator | Sysnative Windows Update Senior Analyst | Malware Hunter | @SecurityAura
My timezone UTC-05:00 (East. Coast). If I didn't reply to you within 48 hours, please send me a PM.


#14 Phiki

Phiki
  • Topic Starter

  • Members
  • 9 posts
  • OFFLINE
  •  
  • Local time:06:29 PM

Posted 10 July 2017 - 07:53 AM

All good :)

How's your system behaving now? Are there any other issues to address?

Everything seems to be working perfectly fine! I've been using it the past week with no problems. I've played Quake, Watched youtube, Scrolled through Imgur, customized windows settings and everything works as it should. Thank you so much! I appreciate the help. :)



#15 Aura

Aura

    Bleepin' Special Ops


  • Malware Response Team
  • 19,697 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:12:29 PM

Posted 10 July 2017 - 07:58 AM

That's awesome, thanks for letting me know!

Since there are no signs of infection anymore in your logs, and you just told me that there are no more issues left to address, I guess we're done here. We'll wrap it up by running DelFix to delete the tools and logs that were used in this clean-up.

BWuhenj.pngDelFix
Follow the instructions below to download and execute DelFix.
  • Download DelFix and move the executable to your Desktop;
  • Right-click on DelFix.exe and select Spcusrh.pngRun as Administrator (for Windows Vista, 7, 8, 8.1 and 10 users);
  • Check the following options :
    • Activate UAC;
    • Remove disinfection tools;
    • Create registry backup;
    • Purge system restore;
    • Reset system settings;
  • Once all the options mentionned above are checked, click on Run;
  • After DelFix is done running, a log will open. Please copy/paste the content of the output log in your next reply;
Qt25440.pngTips, tricks, advice and recommendations

Now it's time to give you some tips, tricks, advice and recommendations on how to protect your system and prevent you from being infected in the future. This is where I'll explain basic security measures that you should take to protect and harden your system, and also make sure it stays as safe and secure as possible against hackers and malware. You are free to ignore the recommendations listed below, although I obviously do not recommend it. If you have any questions about one of the points covered in the speech below, feel free to ask me your questions here directly so I can answer them and guide you.

Windows Updates

Keeping Windows up to date is one of the first steps in having a safe and secure system. The Security Updates that Windows receives are meant to fix exploits and flaws in it that makes it more secure and not exploitable by hackers. In order to do that, you should always install the Security Updates, known as "Important Updates" on your Windows system. These updates are released on the second Tuesday of every month, but some are also released before if they are emergency/critical Security Updates. Let's make sure that you have all your Important Updates and Recommended Updates installed and that your Windows Updates are set to be installed automatically.Keeping your programs up-to-date

Like keeping Windows updated, keeping your installed programs up-to-date is another important step in having a safe and secure system. Outdated programs can be exploited by hackers and malware to infect a system and take it over. This is especially true today with the rise of Exploit Kits which is one of the biggest attack vectors to distribute malware. Therefore, you should always keep vulnerable programs like Adobe Flash Player, Adobe Shockwave Player, Java, Silverlight, etc. updated to their most recent version (even better, you don't have to install them if you don't use them). Programs like eLDnJfI.pngSecuniaPSI and y5YE7At.pngHeimdal Free will scan your system for outdated programs, and help you identify them, as well as update them.

Antivirus, Antimalware, Firewall and Anti-Exploit/Ransomware

Having a decent security setup (led by an Antivirus) is the most crucial step to protect a system. These programs are a layer of defence that will prevent a system from being infected, or if it somehow ends up infected, help mitigate the infection and remediate it. Ideally, you should have on your system one Antivirus (never more than one installed at the time), one Antimalware (you can install multiple of these, assuming they do not conflict with each other and the other security programs installed), one Firewall and if you wish, one Anti-Exploit and/or Anti-Ransomware (since Ransomware are currently the most dangerous threat around and it can hit anywhere). Here are a few programs worth checking out if you don't have one yet.

Note: The programs listed below are all free to use or they have some sort of trial. Some of them have a paid version that provides more features, while a lot of other good programs only have a paid version but aren't listed there (such as Kaspersky and ESET Antivirus products).

AntivirusAntimalwareFirewall
Starting in Windows Vista, the Windows Firewall greatly improved and will satisfy the needs of most users. If you do not have an Internet Suite Antivirus program (which includes a firewall) and you want to use a 3rd party firewall, you can consider the options below.
  • 7p3JzTS.pngGlassWire - Has both a free and paid version (with different packages);
  • MQIMh6k.pngWindows Firewall Control - Gives you more control over your Windows Firewall;
  • 5RXGshU.pngTinyWall - Lightweight firewall implementing the Windows Firewall and giving you more control over it;
Anti-Exploit/Anti-RansomwareWeb Browsers and Web Browsing

Web Browsers could be considered as the closest door between a malware and your system. This is where most malware goes through to infect a system, and therefore it should be the program(s) you want to secure the most. There are two ways of going about it: hardening your web browser via extensions, and having good browsing habits.

Hardening your web browser means to install extensions that will help it protect itself (and your system on the same occasion) against Exploit Kits, MiTM attacks, etc. but also you at the same time. Here are a few extensions that I recommend you to install.
  • uBlock Origin: Efficient multi-purpose blocker that is lightweight on RAM and CPU usage (Google Chrome and Mozilla Firefox, called uBlock on Opera);
  • HTTPS Everywhere: Extension that converts your HTTP (unencrypted) requests to HTTPS (encrypted) ones (Google Chrome, Mozilla Firefox and Opera);
  • Web of Trust: Website reputation, rating and review extension that will help you quickly identify bad and suspicious sites from good ones (every web browsers);
  • NoScript: NoScript is a script blocker (Java, Flash, JavaScript, etc.) for Mozilla Firefox and Firefox-based browsers (Mozilla Firefox and Firefox-based web browsers);
  • uMatrix: For advanced users, a point and click matrix-like extensions that allow you to control requests done on a webpage (based on source, destination and type) (Google Chrome, Mozilla Firefox and Opera);
  • LastPass: Secure password manager allowing you to create, manage, and use passwords you save in your LastPass account (every web browser);
As for safe browsing habits, you can find tons of guides, tutorials, articles, etc. online that will highlight the basics you need to follow (only visit websites you trust, do not click on ads, do not download files from untrusted sources, use a password manager, always verify the URL of a website and make sure it's correctly typed, etc.), and even what you can do if you want to take it a step further (create a fake email address for spam emails, browse the web in a privacy mode, etc.). Here are a few:As you can see, there are plenty of resources out there. Simply Googling "good browsing habits" or "safe browsing habits" should allow you to find a lot of them.

Other recommendations

Even if you follow every recommendation that I listed here, in the end, it's also your job to be careful when browsing the web and downloading files if you don't want to get infected. Therefore, if you use your brain (common sense) when browsing the web, downloading programs and files, etc., you have far less chances to get infected by a malware. If for example you're not sure if a website is legitimate or not, or if a file is safe to download and execute, or if a program looks "too good" to be free, I suggest you to avoid going to that website, downloading that file or using that program.

Here are a few guides, tutorials, articles, etc. that you could read in order to learn more about computer protection and security to improve your current computer protection setup but also improve your good web browsing and computer usage practices :gRvSooB.pngThe End!

And that's it! Now that you know more about how to protect your computer and secure it, you're good to go back to your online activities, but in a safe and secure way! You are also free to stay on the forums and ask for help in different topics if you ever need to. Just make sure that you post your question/issue in the right section to get the best assistance possible. And if you ever get infected again (which I hope you wont!), you can always comeback in this section to get another checkup with one of our trained malware removal member.

Do you have any questions before I close this thread? :)

animinionsmalltext.gif
unite_blue.png
Security Administrator | Sysnative Windows Update Senior Analyst | Malware Hunter | @SecurityAura
My timezone UTC-05:00 (East. Coast). If I didn't reply to you within 48 hours, please send me a PM.





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users