# Running from : C:\Users\editor\Desktop\tron\resources\stage_9_manual_tools\AdwCleaner v6.0.4.7.exe
No malicious services found.
No malicious DLLs found.
No malicious keys found.
No infected shortcut found.
No malicious task found.
No malicious registry entries found.
No malicious Firefox based browser items found.
Chrome pref Found: [C:\Users\editor\AppData\Local\Google\Chrome\User Data\Default\Web data] - ask.com
Chrome pref Found: [C:\Users\editor\AppData\Local\Google\Chrome\User Data\Default\Web data] - aol.com
Chrome pref Found: [C:\Users\IUSR_Servs\AppData\Local\Google\Chrome\User Data\Default\Web data] - aol.com
Chrome pref Found: [C:\Users\IUSR_Servs\AppData\Local\Google\Chrome\User Data\Default\Web data] - ask.com
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 25-06-2017 01
Ran by editor (administrator) on AVID4 (26-06-2017 20:03:37)
Running from C:\Users\editor\Downloads
Loaded Profiles: editor & Administrator (Available Profiles: user & editor & Default & IUSR_Servs & Administrator)
Platform: Windows 7 Professional Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
() C:\Windows\System32\nvwmi64.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvscpapisvr.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Wacom\WTabletServicePro.exe
(Autodesk Inc.) C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AdAppMgrSvc.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe
(Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
(AJA Video Systems, Inc.) C:\Program Files\AJA\windows\Applications\ajadaemon.exe
(Avid Technology, Inc.) C:\Program Files\Avid\Editor Transcode\TranscodeService\AvidEditorDbEngine.exe
(Avid Technology, Inc.) C:\Program Files\Avid\Editor Transcode\TranscodeService\AvidEditorDbEngine.exe
(Avid Technology, Inc.) C:\Program Files\Avid\Editor Transcode\TranscodeService\rnc-central\AvidEditorTranscodeStatus.exe
(Avid Technology, Inc.) C:\Program Files\Avid\Editor Transcode\TranscodeService\rnc-central\AvidEditorTranscodeStatus.exe
(Avid) C:\Program Files\Avid\ISIS Client\Utilities\Benchmark Utility\BenchmarkAgent.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe
() C:\Program Files\Telestream\Episode 7\bin\tseas.exe
() C:\Windows\System32\nvwmi64.exe
() C:\Program Files\Telestream\Episode 7\bin\tsecps.exe
() C:\Program Files\Telestream\Episode 7\bin\tseioss.exe
() C:\Program Files\Telestream\Episode 7\bin\tsejrs.exe
() C:\Program Files\Telestream\Episode 7\bin\tsens.exe
() C:\Program Files\Telestream\Episode 7\bin\tsexrs.exe
(Intel Corporation) C:\Windows\System32\IPROSetMonitor.exe
(PACE Anti-Piracy, Inc.) C:\Program Files (x86)\Common Files\PACE\Services\LicenseServices\LDSvc.exe
() C:\Program Files\Telestream\Episode 7\bin\EpisodeClientProxy.exe
() C:\Program Files\Telestream\Episode 7\bin\EpisodeJSONRPCServer.exe
() C:\Program Files\Telestream\Episode 7\bin\EpisodeXMLRPCServer.exe
() C:\Program Files\Telestream\Episode 7\bin\EpisodeNode.exe
() C:\Program Files\Telestream\Episode 7\bin\EpisodeIOServer.exe
() C:\Program Files\Telestream\Episode 7\bin\EpisodeAssistant.exe
(PDF Complete Inc) C:\Program Files (x86)\PDF Complete\pdfsvc.exe
(Protexis Inc.) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
(Samsung Electronics Co., Ltd.) C:\Windows\System32\RAPID\SamsungRapidSvc.exe
(Microsoft Corporation) C:\Windows\System32\wisptis.exe
(SafeNet, Inc.) C:\Program Files (x86)\Common Files\SafeNet Sentinel\Sentinel Keys Server\sntlkeyssrvr.exe
(SafeNet, Inc) C:\Program Files (x86)\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe
(SafeNet, Inc.) C:\Program Files (x86)\Common Files\SafeNet Sentinel\Sentinel Security Runtime\sntlsrtsrvr.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(Avid Technology, Inc.) C:\Program Files\Avid\Editor Transcode\TranscodeService\AvidEditorMSE.exe
(Avid Technology, Inc.) C:\Program Files\Avid\Editor Transcode\TranscodeService\AvidEditorMSE.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Microsoft Corporation) C:\Windows\System32\wisptis.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Wacom\Wacom_TabletUser.exe
(Wacom Technology) C:\Program Files\Tablet\Wacom\WacomHost.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Wacom\Wacom_TouchUser.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe
(Microsoft Corporation) C:\Program Files\Microsoft Device Center\itype.exe
(Microsoft Corporation) C:\Program Files\Microsoft Device Center\ipoint.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\RAPID\CacheFilter\SamsungRapidApp.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe
(Adobe Systems Inc.) C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\acrotray.exe
(Autodesk, Inc.) C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AutodeskDesktopApp.exe
(Avid Technology, Inc.) C:\Program Files\Avid\Application Manager\AvidApplicationManager.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe
(Autodesk) C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AcWebBrowser\acwebbrowser.exe
(Avid Technology, Inc.) C:\Program Files\Avid\Avid Media Composer\AvidBackgroundServicesManager.exe
(Slack Technologies) C:\Users\editor\AppData\Local\slack\app-2.6.3\slack.exe
(Avid) C:\Program Files\Avid\ISIS Client\Client Manager\ISISClientManager.exe
(Realtime Soft Ltd) C:\Program Files\UltraMon\UltraMon.exe
(Autodesk) C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AcWebBrowser\acwebbrowser.exe
(Realtime Soft Ltd) C:\Program Files\UltraMon\UltraMonTaskbar.exe
(Autodesk) C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AcWebBrowser\acwebbrowser.exe
(Slack Technologies) C:\Users\editor\AppData\Local\slack\app-2.6.3\slack.exe
(Realtime Soft Ltd) C:\Program Files (x86)\Common Files\Realtime Soft\RTSHookInterop\x32\RTSHookInterop.exe
(Slack Technologies) C:\Users\editor\AppData\Local\slack\app-2.6.3\slack.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\HEX\Adobe CEF Helper.exe
(Slack Technologies) C:\Users\editor\AppData\Local\slack\app-2.6.3\slack.exe
() C:\Program Files\Avid\Application Manager\QtWebEngineProcess.exe
(Avid Technology, Inc.) C:\Program Files\Avid\Application Manager\AvidAppManHelper.exe
(Slack Technologies) C:\Users\editor\AppData\Local\slack\app-2.6.3\slack.exe
() C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\CCXProcess.exe
(Node.js) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\libs\node.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\CCLibrary.exe
(Node.js) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\libs\node.exe
(Samsung Electronics Co. Ltd.) C:\Program Files (x86)\Samsung\Samsung Magician\SamsungMagician.exe
(Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\IMSS\PrivacyIconClient.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
(InterVideo) C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe
(Tweaking.com) C:\Program Files (x86)\Tweaking.com\Windows Repair (All in One)\WR_Tray_Icon.exe
(Realtime Soft Ltd) C:\Program Files\UltraMon\UltraMonUiAcc.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome Remote Desktop\59.0.3071.47\remoting_host.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome Remote Desktop\59.0.3071.47\remoting_host.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbam.exe
(Realtime Soft Ltd) C:\Program Files (x86)\Common Files\Realtime Soft\RTSHookInterop\x32\RTSHookInterop.exe
(Adobe Systems Incorporated) C:\Program Files\Adobe\Adobe InDesign CC 2017\InDesign.exe
(Adobe Systems Incorporated) C:\Program Files\Adobe\Adobe InDesign CC 2017\Resources\CEP\CEPHtmlEngine\CEPHtmlEngine.exe
(Adobe Systems Incorporated) C:\Program Files\Adobe\Adobe InDesign CC 2017\Resources\CEP\CEPHtmlEngine\CEPHtmlEngine.exe
(Adobe Systems Incorporated) C:\Program Files\Adobe\Adobe InDesign CC 2017\Resources\CEP\CEPHtmlEngine\CEPHtmlEngine.exe
(Adobe Systems Incorporated) C:\Program Files\Adobe\Adobe InDesign CC 2017\Resources\CEP\CEPHtmlEngine\CEPHtmlEngine.exe
(Adobe Systems Incorporated) C:\Program Files\Adobe\Adobe InDesign CC 2017\Resources\CEP\CEPHtmlEngine\CEPHtmlEngine.exe
(Adobe Systems Incorporated) C:\Program Files\Adobe\Adobe InDesign CC 2017\Resources\CEP\CEPHtmlEngine\CEPHtmlEngine.exe
(Adobe Systems Incorporated) C:\Program Files\Adobe\Adobe InDesign CC 2017\Resources\CEP\CEPHtmlEngine\CEPHtmlEngine.exe
(Adobe Systems Incorporated) C:\Program Files\Adobe\Adobe InDesign CC 2017\Resources\CEP\CEPHtmlEngine\CEPHtmlEngine.exe
(Adobe Systems Incorporated) C:\Program Files\Adobe\Adobe InDesign CC 2017\Resources\CEP\CEPHtmlEngine\CEPHtmlEngine.exe
(Microsoft Corporation) C:\Windows\System32\prevhost.exe
(Microsoft Corporation) C:\Windows\SysWOW64\prevhost.exe
(Microsoft Corporation) C:\Windows\System32\taskmgr.exe
(Microsoft Corporation) C:\Windows\System32\cmd.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12681320 2011-09-06] (Realtek Semiconductor)
HKLM\...\Run: [HPSYSDRV] => C:\Program Files (x86)\Hewlett-Packard\HP Odometer\HPSYSDRV.EXE [62768 2008-11-20] (Hewlett-Packard)
HKLM\...\Run: [IntelliType Pro] => c:\Program Files\Microsoft Device Center\itype.exe [1464928 2012-06-26] (Microsoft Corporation)
HKLM\...\Run: [IntelliPoint] => c:\Program Files\Microsoft Device Center\ipoint.exe [2004584 2012-06-26] (Microsoft Corporation)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [508128 2016-07-01] (Adobe Systems Incorporated)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1353680 2016-11-14] (Microsoft Corporation)
HKLM\...\Run: [nwiz] => C:\Program Files\NVIDIA Corporation\nview\nwiz.exe [2098232 2016-08-25] ()
HKLM\...\Run: [Malwarebytes TrayApp] => C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe [3146704 2017-05-09] (Malwarebytes)
HKLM\...\Run: [SamsungRapidApp] => C:\Program Files (x86)\Samsung\RAPID\CacheFilter\SamsungRapidApp.exe [123800 2016-11-18] (Samsung Electronics Co., Ltd.)
HKLM-x32\...\Run: [IMSS] => C:\Program Files (x86)\Intel\Intel® Management Engine Components\IMSS\PIconStartup.exe [112408 2011-11-30] (Intel Corporation)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.)
HKLM-x32\...\Run: [Adobe Creative Cloud] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2406496 2017-06-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2015-08-06] (Apple Inc.)
HKLM-x32\...\Run: [iSkysoft Helper Compact.exe] => C:\Program Files (x86)\Common Files\iSkysoft\iSkysoft Helper Compact\ISHelper.exe [2131856 2016-06-20] (iSkySoft)
HKLM-x32\...\Run: [DelaypluginInstall] => C:\ProgramData\iSkysoft\iTube Studio\DelayPluginI.exe [1960288 2014-09-19] ()
HKLM-x32\...\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Acrotray.exe [1870928 2017-04-04] (Adobe Systems Inc.)
HKLM-x32\...\Run: [PDF Complete] => C:\Program Files (x86)\PDF Complete\pdfsty.exe [1193728 2017-02-15] (PDF Complete Inc)
HKLM-x32\...\Run: [Autodesk Desktop App] => C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AutodeskDesktopApp.exe [704424 2017-03-10] (Autodesk, Inc.)
HKU\S-1-5-21-3225783554-34173836-2973484787-1001\...\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-3225783554-34173836-2973484787-1001\...\Run: [Adobe Acrobat Synchronizer] => C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe [886352 2017-04-04] (Adobe Systems Incorporated)
HKU\S-1-5-21-3225783554-34173836-2973484787-1001\...\Run: [com.squirrel.slack.slack] => "C:\Users\editor\AppData\Local\slack\Update.exe" --processStart "slack.exe" --process-start-args "--startup"
HKU\S-1-5-21-3225783554-34173836-2973484787-1001\...\Run: [Akamai NetSession Interface] => "C:\Users\editor\AppData\Local\Akamai\netsession_win.exe"
IFEO\Magnify.exe: [Debugger] cmd.exe
IFEO\sethc.exe: [Debugger] C:\Windows\vpnplugins\servicing\ibhost.exe
ShellIconOverlayIdentifiers: [ AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2017-05-26] ()
ShellIconOverlayIdentifiers: [ AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2017-05-26] ()
ShellIconOverlayIdentifiers: [ AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2017-05-26] ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Aja Firmware Updater.lnk [2015-11-16]
ShortcutTarget: Aja Firmware Updater.lnk -> C:\Program Files\AJA\windows\Firmware\ajaflash.exe ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Avid Application Manager.lnk [2016-12-22]
ShortcutTarget: Avid Application Manager.lnk -> C:\Windows\Installer\{99E377DB-D2D0-44A5-8533-AA8BE1381644}\NewShortcut1_E1E0FF1FC1474601A40EFEF248F11D43.exe (Flexera Software LLC)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Avid Background Services Manager.lnk [2016-12-23]
ShortcutTarget: Avid Background Services Manager.lnk -> C:\Windows\Installer\{95EB1E9C-F759-4427-8EEE-F96C48541A06}\NewShortcut1_4CE83F107C544E87A6F35E0E551E78CA.exe (Flexera Software LLC)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ISIS Client Manager.lnk [2015-12-08]
ShortcutTarget: ISIS Client Manager.lnk -> C:\Program Files\Avid\ISIS Client\Client Manager\ISISClientManager.exe (Avid)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\UltraMon.lnk [2015-07-23]
ShortcutTarget: UltraMon.lnk -> C:\Windows\Installer\{D4E62D29-31A1-4938-8CB7-7D275C1AEAC6}\IcoUltraMon.ico ()
GroupPolicy: Restriction <==== ATTENTION
GroupPolicy\User: Restriction <==== ATTENTION
GroupPolicyScripts: Restriction <==== ATTENTION
GroupPolicyScripts\User: Restriction <==== ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Winsock: Catalog5 08 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL => No File
Winsock: Catalog5 09 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL => No File
Winsock: Catalog5-x64 08 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL => No File
Winsock: Catalog5-x64 09 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL => No File
Tcpip\Parameters: [DhcpNameServer] 209.18.47.62 209.18.47.61
Tcpip\..\Interfaces\{0C06085B-51F9-4B6A-8F35-4A6E4F6EB3FC}: [DhcpNameServer] 209.18.47.62 209.18.47.61
Tcpip\..\Interfaces\{AF626FD6-E522-47E2-83CE-48AD0E00D527}: [NameServer] 223.5.5.5,8.8.8.8
Internet Explorer:
==================
HKU\S-1-5-21-3225783554-34173836-2973484787-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.msn.com/HPCOM/19
HKU\S-1-5-21-3225783554-34173836-2973484787-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.msn.com/HPCOM/19
HKU\S-1-5-21-3225783554-34173836-2973484787-500\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.msn.com/HPCOM/19
HKU\S-1-5-21-3225783554-34173836-2973484787-500\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.msn.com/HPCOM/19
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-3225783554-34173836-2973484787-500 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=CMDTDF&pc=CMDTDF&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-3225783554-34173836-2973484787-500 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=CMDTDF&pc=CMDTDF&src=IE-SearchBox
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2017-06-18] (Microsoft Corporation)
BHO: Adobe Acrobat Create PDF Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\x64\AcroIEFavStub.dll [2016-12-23] (Adobe Systems Incorporated)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\URLREDIR.DLL [2017-06-18] (Microsoft Corporation)
BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL [2017-06-18] (Microsoft Corporation)
BHO: Adobe Acrobat Create PDF from Selection -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\x64\AcroIEFavStub.dll [2016-12-23] (Adobe Systems Incorporated)
BHO-x32: iSkysoft iTube Studio 4.2.0 -> {1A6B6AD0-2735-498F-834C-AFCEA37847C2} -> C:\ProgramData\iSkysoft\iTube Studio\WSBrowserAppMgr.dll [2014-09-19] (Wondershare)
BHO-x32: Adobe Acrobat Create PDF Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll [2016-12-23] (Adobe Systems Incorporated)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\root\Office16\URLREDIR.DLL [2017-06-18] (Microsoft Corporation)
BHO-x32: Adobe Acrobat Create PDF from Selection -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll [2016-12-23] (Adobe Systems Incorporated)
Toolbar: HKLM - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\x64\AcroIEFavStub.dll [2016-12-23] (Adobe Systems Incorporated)
Toolbar: HKLM-x32 - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll [2016-12-23] (Adobe Systems Incorporated)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-06-18] (Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-06-18] (Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-06-18] (Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-06-18] (Microsoft Corporation)
Handler: WSISAllmytubechrome - {4724F5AF-4E6D-41CA - No File
FireFox:
========
FF DefaultProfile: p0snnc5x.default
FF ProfilePath: C:\Users\editor\AppData\Roaming\Mozilla\Firefox\Profiles\p0snnc5x.default [2017-06-20]
FF Extension: (Youtube Unblocker Remediation) - C:\Users\editor\AppData\Roaming\Mozilla\Firefox\Profiles\p0snnc5x.default\features\{24a06145-a6d5-4e79-a30d-3b00074039bf}\malware-remediation@mozilla.org.xpi [2017-06-12]
FF HKLM-x32\...\Firefox\Extensions: [ISAllmytube@iSkysoft.com] - C:\ProgramData\iSkysoft\iTube Studio\ISAllmytube@iSkysoft.com
FF Extension: (iSkysoft iTube Studio) - C:\ProgramData\iSkysoft\iTube Studio\ISAllmytube@iSkysoft.com [2015-11-24] [not signed]
FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension.15@web2pdf.adobedotcom] - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn
FF Extension: (Adobe Acrobat DC - Create PDF) - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn [2017-04-13]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_26_0_0_131.dll [2017-06-16] ()
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @wacom.com/wtPlugin,version=2.1.0.7 -> C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll [2014-03-25] (Wacom)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2017-06-04] (Adobe Systems)
FF Plugin: wacom.com/WacomTabletPlugin -> C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll [2014-03-25] (Wacom)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_26_0_0_131.dll [2017-06-16] ()
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2017-05-26] (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2016-08-25] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2016-08-25] (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-27] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-27] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin-x32: @wacom.com/wtPlugin,version=2.1.0.7 -> C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll [2014-03-25] (Wacom)
FF Plugin-x32: Adobe Acrobat -> C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2017-04-04] (Adobe Systems Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2013-05-11] (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2017-06-04] (Adobe Systems)
FF Plugin-x32: wacom.com/WacomTabletPlugin -> C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll [2014-03-25] (Wacom)
FF Plugin HKU\S-1-5-21-3225783554-34173836-2973484787-1001: @asperasoft.com/AsperaConnect -> C:\Users\editor\AppData\Local\Programs\Aspera\Aspera Connect\lib\3.6.1\npasperaweb_3.6.1.111228.dll [2015-09-11] (Aspera, Inc. )
FF Plugin HKU\S-1-5-21-3225783554-34173836-2973484787-1001: signiant.com/SigniantTransfer -> C:\Users\editor\AppData\Roaming\SigniantInc\SigniantTransfer\5.4.3.70626\npSigniantTransfer.dll [2015-05-08] (Signiant Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\browser\plugins\npatgpc.dll [2016-06-16] (Cisco WebEx LLC)
FF Plugin ProgramFiles/Appdata: C:\Users\editor\AppData\Roaming\mozilla\plugins\npatgpc.dll [2016-06-16] (Cisco WebEx LLC)
Chrome:
=======
CHR DefaultProfile: Default
CHR HomePage: Default -> hxxp://www.google.com/
CHR Profile: C:\Users\editor\AppData\Local\Google\Chrome\User Data\Default [2017-06-26]
CHR Extension: (Google Slides) - C:\Users\editor\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-04-17]
CHR Extension: (Google Docs) - C:\Users\editor\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-04-17]
CHR Extension: (Google Drive) - C:\Users\editor\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-23]
CHR Extension: (YouTube) - C:\Users\editor\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-26]
CHR Extension: (uBlock Origin) - C:\Users\editor\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpalhdlnbpafiamejdnhcphjbkeiagm [2017-06-22]
CHR Extension: (Image Downloader) - C:\Users\editor\AppData\Local\Google\Chrome\User Data\Default\Extensions\cnpniohnfphhjihaiiggeabnkjhpaldj [2017-05-04]
CHR Extension: (Google Search) - C:\Users\editor\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-27]
CHR Extension: (Frame by Frame for YouTube™) - C:\Users\editor\AppData\Local\Google\Chrome\User Data\Default\Extensions\elkadbdicdciddfkdpmaolomehalghio [2016-01-04]
CHR Extension: (Google Sheets) - C:\Users\editor\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-04-17]
CHR Extension: (Chrome Remote Desktop) - C:\Users\editor\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbchcmhmhahfdphkhkmpfmihenigjmpp [2017-06-12]
CHR Extension: (Google Docs Offline) - C:\Users\editor\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-17]
CHR Extension: (WhatFont) - C:\Users\editor\AppData\Local\Google\Chrome\User Data\Default\Extensions\jabopobgcpjmedljpbcaablpmlmfcogm [2017-05-08]
CHR Extension: (Reddit Enhancement Suite) - C:\Users\editor\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbmfpngjjgdllneeigpgjifpgocmfgmb [2017-06-22]
CHR Extension: (Chrome Web Store Payments) - C:\Users\editor\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-03-13]
CHR Extension: (Mercury Reader) - C:\Users\editor\AppData\Local\Google\Chrome\User Data\Default\Extensions\oknpjjbmpnndlpmnhmekjpocelpnlfdi [2017-04-26]
CHR Extension: (Gmail) - C:\Users\editor\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-04-17]
CHR Extension: (Chrome Media Router) - C:\Users\editor\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-05-12]
CHR Profile: C:\Users\editor\AppData\Local\Google\Chrome\User Data\Guest Profile [2017-04-25]
CHR Profile: C:\Users\editor\AppData\Local\Google\Chrome\User Data\System Profile [2016-06-29]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AdAppMgrSvc; C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AdAppMgrSvc.exe [1309176 2017-03-10] (Autodesk Inc.)
R2 AdobeUpdateService; C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [814688 2017-06-04] (Adobe Systems Incorporated)
R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2246256 2017-05-18] (Adobe Systems, Incorporated)
R2 AJA Service; C:\Program Files\AJA\windows\Applications\ajadaemon.exe [1649152 2015-11-05] (AJA Video Systems, Inc.) [File not signed]
S3 Avid DMF Service; C:\Program Files\Avid\Editor Transcode\Dynamic Media Files\DMFService.exe [661768 2016-09-01] (Avid Technology, Inc.)
R2 Avid Editor Broker; C:\Program Files\Avid\Editor Transcode\TranscodeService\AvidEditorMSE.exe [662280 2016-09-01] (Avid Technology, Inc.)
R2 Avid Editor Db Engine; C:\Program Files\Avid\Editor Transcode\TranscodeService\AvidEditorDbEngine.exe [661768 2016-09-01] (Avid Technology, Inc.)
S3 Avid Editor Transcode Service; C:\Program Files\Avid\Editor Transcode\TranscodeService\AvidEditorTranscode.exe [662280 2016-09-01] (Avid Technology, Inc.)
R2 Avid Editor Transcode Status; C:\Program Files\Avid\Editor Transcode\TranscodeService\rnc-central\AvidEditorTranscodeStatus.exe [297736 2016-09-01] (Avid Technology, Inc.)
R2 Avid ISIS Benchmark Agent; C:\Program Files\Avid\ISIS Client\Utilities\Benchmark Utility\BenchmarkAgent.exe [4160000 2015-11-13] (Avid) [File not signed]
S2 AvidFosFS; C:\Windows\system32\AvidFos_Service.exe [17554944 2015-11-13] (Avid) [File not signed]
R2 chromoting; C:\Program Files (x86)\Google\Chrome Remote Desktop\59.0.3071.47\remoting_host.exe [71512 2017-05-09] (Google Inc.)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [4122816 2017-06-10] (Microsoft Corporation)
R2 Episode Assistant Service; C:\Program Files\Telestream\Episode 7\bin\tseas.exe [6656 2015-11-09] () [File not signed]
R2 Episode Client Proxy Service; C:\Program Files\Telestream\Episode 7\bin\tsecps.exe [6656 2015-11-09] () [File not signed]
R2 Episode IOserver Service; C:\Program Files\Telestream\Episode 7\bin\tseioss.exe [6144 2015-11-09] () [File not signed]
R2 Episode JSON-RPC Service; C:\Program Files\Telestream\Episode 7\bin\tsejrs.exe [6656 2015-11-09] () [File not signed]
R2 Episode Node Service; C:\Program Files\Telestream\Episode 7\bin\tsens.exe [8192 2015-11-09] () [File not signed]
R2 Episode XML-RPC Service; C:\Program Files\Telestream\Episode 7\bin\tsexrs.exe [6656 2015-11-09] () [File not signed]
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4470736 2017-05-09] (Malwarebytes)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [119864 2016-11-14] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [361816 2016-11-14] (Microsoft Corporation)
R2 NVWMI; C:\Windows\system32\nvwmi64.exe [2693448 2014-09-12] ()
R2 pdfcDispatcher; C:\Program Files (x86)\PDF Complete\pdfsvc.exe [1719552 2017-02-15] (PDF Complete Inc)
R2 SamsungRapidSvc; C:\Windows\System32\RAPID\SamsungRapidSvc.exe [29080 2016-11-18] (Samsung Electronics Co., Ltd.)
R2 SentinelKeysServer; C:\Program Files (x86)\Common Files\SafeNet Sentinel\Sentinel Keys Server\sntlkeyssrvr.exe [376832 2013-01-09] (SafeNet, Inc.) [File not signed]
R2 SentinelProtectionServer; C:\Program Files (x86)\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe [1259872 2013-01-09] (SafeNet, Inc)
R2 SentinelSecurityRuntime; C:\Program Files (x86)\Common Files\SafeNet Sentinel\Sentinel Security Runtime\sntlsrtsrvr.exe [293216 2013-01-09] (SafeNet, Inc.)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
R2 WTabletServicePro; C:\Program Files\Tablet\Wacom\WTabletServicePro.exe [675272 2017-05-31] (Wacom Technology, Corp.)
S4 TermService; %ProgramFiles%\RDP Wrapper\rdpwrap.dll [X]
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AvidFos; C:\Windows\System32\Drivers\AvidFos.sys [755944 2015-11-13] (Avid)
R2 AvidFosLog; C:\Windows\System32\Drivers\AvidFosLog.sys [29416 2015-11-13] (Avid)
R2 AvidFosShell; C:\Windows\System32\Drivers\AvidFosShell.sys [17640 2015-11-13] (Avid)
R3 bomebus; C:\Windows\System32\DRIVERS\bomebus.sys [34376 2010-10-13] (Bome Software)
S3 bomemidi; C:\Windows\System32\drivers\bomemidi.sys [30792 2010-10-13] (Bome Software)
R2 fsdk-wrap; C:\Windows\System32\Drivers\fsdk-wrap.sys [417000 2015-11-13] (OSR Open Systems Resource, Inc.)
S3 hitmanpro37; C:\Windows\system32\drivers\hitmanpro37.sys [43664 2015-04-10] ()
R1 HWiNFO32; C:\Windows\system32\drivers\HWiNFO64A.SYS [27552 2017-04-04] (REALiX)
R0 iaStorF; C:\Windows\System32\drivers\iaStorF.sys [24496 2012-03-15] (Intel Corporation)
R0 iaStorS; C:\Windows\System32\drivers\iaStorS.sys [639408 2012-03-31] (Intel Corporation)
S3 IFCoEMP; C:\Windows\system32\drivers\ifM60x64.sys [348944 2012-03-09] (Intel® Corporation)
S3 IFCoEVB; C:\Windows\system32\drivers\ifP60X64.sys [70928 2012-03-09] (Intel® Corporation)
R0 MBAMSwissArmy; C:\Windows\System32\drivers\MBAMSwissArmy.sys [252832 2017-06-26] (Malwarebytes)
S3 MBAMWebProtection; C:\Windows\system32\drivers\mwac.sys [84256 2017-05-19] (Malwarebytes)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [295000 2016-08-25] (Microsoft Corporation)
R1 MpKsle1ee7f24; c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{58EFF581-175A-4A8E-88CC-F42150744E30}\MpKsle1ee7f24.sys [44928 2017-06-26] (Microsoft Corporation)
R3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [135928 2016-08-25] (Microsoft Corporation)
R3 NTV2_64; C:\Windows\System32\DRIVERS\ntv2_64.sys [160024 2015-11-05] (AJA Video Systems Inc.)
R0 PxHlpa64; C:\Windows\System32\Drivers\PxHlpa64.sys [56336 2012-06-22] (Corel Corporation)
R0 SamsungRapidDiskFltr; C:\Windows\System32\DRIVERS\SamsungRapidDiskFltr.sys [272792 2016-11-18] (Samsung Electronics Co., Ltd.)
R0 SamsungRapidFSFltr; C:\Windows\System32\DRIVERS\SamsungRapidFSFltr.sys [111512 2016-11-18] (Samsung Electronics Co., Ltd.)
R2 Sentinel64; C:\Windows\System32\Drivers\Sentinel64.sys [145448 2009-09-17] (SafeNet, Inc.)
S3 SIVDriver; C:\Windows\system32\Drivers\SIVX64.sys [171664 2016-07-14] (Ray Hinchliffe)
R3 SNTUSB64; C:\Windows\System32\DRIVERS\SNTUSB64.SYS [63568 2012-12-11] (SafeNet, Inc.)
R3 USA19H; C:\Windows\System32\DRIVERS\USA19Hx64.sys [740096 2007-10-30] (Keyspan)
R3 USA19HP; C:\Windows\System32\DRIVERS\USA19Hx64p.SYS [35840 2007-10-23] (Keyspan)
R3 WacHidRouterPro; C:\Windows\System32\DRIVERS\wachidrouter.sys [122512 2017-04-28] (Wacom Technology)
R3 WsAudio_Device; C:\Windows\System32\drivers\VirtualAudio.sys [31080 2013-09-03] (Wondershare)
R2 WskTrans; C:\Windows\System32\Drivers\WskTrans.sys [34024 2015-11-13] (Avid)
S3 Xena2_64; C:\Windows\System32\DRIVERS\Kona3_64.sys [308480 2012-09-10] (AJA Video Systems Inc.) [File not signed]
U4 NIC1394; no ImagePath
U4 NVIDIA Performance Driver Service; no ImagePath
S3 PTSimBus; system32\DRIVERS\PTSimBus.sys [X]
S3 PTSimHid; system32\DRIVERS\PTSimHid.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-06-26 20:03 - 2017-06-26 20:03 - 00036798 _____ C:\Users\editor\Downloads\FRST.txt
2017-06-26 20:03 - 2017-06-26 20:03 - 00000000 ____D C:\FRST
2017-06-26 20:02 - 2017-06-26 20:02 - 02441216 _____ (Farbar) C:\Users\editor\Downloads\FRST64.exe
2017-06-26 19:54 - 2017-06-26 19:54 - 00000000 ____D C:\Users\editor\Desktop\rkill
2017-06-26 11:57 - 2017-06-26 11:57 - 35489760 _____ (Adlice Software ) C:\Users\editor\Downloads\setup (1).exe
2017-06-26 11:18 - 2017-06-26 11:18 - 00000000 ___HD C:\OneDriveTemp
2017-06-26 11:15 - 2017-06-26 11:15 - 00000000 ____D C:\Windows\system32\RAPID
2017-06-26 11:15 - 2016-11-18 19:04 - 00272792 _____ (Samsung Electronics Co., Ltd.) C:\Windows\system32\Drivers\SamsungRapidDiskFltr.sys
2017-06-23 17:37 - 2017-06-23 17:37 - 00003142 _____ C:\Windows\System32\Tasks\Process Explorer-AVID4-editor
2017-06-23 17:05 - 2017-06-23 17:05 - 02724512 _____ (Sysinternals - www.sysinternals.com) C:\Users\editor\Downloads\procexp.exe
2017-06-23 16:43 - 2017-06-23 16:43 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign59df863cd635d885
2017-06-23 15:50 - 2017-06-23 15:50 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign8d8121701ba66570
2017-06-23 15:50 - 2017-06-23 15:50 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign52e3c77a20748e79
2017-06-23 15:48 - 2017-06-23 15:48 - 01514603 _____ C:\Users\editor\Downloads\FXConsoleInstaller_1.0.1_Win_2017.zip
2017-06-23 15:46 - 2017-06-23 15:46 - 00089844 _____ C:\Users\editor\Downloads\Comp2Clip2.zip
2017-06-23 15:44 - 2017-06-23 15:44 - 00001077 _____ C:\Users\Public\Desktop\Boris RED 5 (64 Bit).lnk
2017-06-23 15:44 - 2017-06-23 15:44 - 00000000 ____D C:\Users\Public\Documents\Lightworks
2017-06-23 15:43 - 2017-06-23 15:43 - 240190485 _____ C:\Users\editor\Downloads\SFX-20170623T194015Z-001.zip
2017-06-23 15:42 - 2017-06-23 15:42 - 00000000 ____D C:\Users\editor\Downloads\boris
2017-06-23 15:35 - 2017-06-23 15:35 - 00001179 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Media Encoder CC 2017.lnk
2017-06-23 14:40 - 2017-06-23 14:40 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign9166cc43c6cb6144
2017-06-23 14:19 - 2017-06-23 14:19 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign46564856646d2f2f
2017-06-23 14:18 - 2017-06-23 14:18 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign1a94ce88808d4a7b
2017-06-23 13:50 - 2017-06-23 13:50 - 00000804 __RSH C:\Users\editor\ntuser.pol
2017-06-23 13:10 - 2017-06-23 13:10 - 00001277 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe After Effects CC 2017.lnk
2017-06-23 12:45 - 2017-06-23 12:45 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsignb8037e97948ee1a6
2017-06-23 12:45 - 2017-06-23 12:45 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign7804bb806808d832
2017-06-23 12:44 - 2017-06-23 12:44 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsigne08c37701e2a0ee4
2017-06-23 12:43 - 2017-06-23 12:43 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign580f3bea265f8649
2017-06-23 11:51 - 2017-06-26 11:59 - 00028272 _____ C:\Windows\system32\Drivers\TrueSight.sys
2017-06-23 11:51 - 2017-06-26 11:58 - 00000897 _____ C:\Users\Public\Desktop\RogueKiller.lnk
2017-06-23 11:51 - 2017-06-26 11:58 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RogueKiller
2017-06-23 11:51 - 2017-06-26 11:58 - 00000000 ____D C:\Program Files\RogueKiller
2017-06-23 11:51 - 2017-06-23 12:32 - 00000000 ____D C:\ProgramData\RogueKiller
2017-06-23 11:48 - 2017-06-23 11:49 - 35438416 _____ (Adlice Software ) C:\Users\editor\Downloads\RogueKiller_setup_ref3.exe
2017-06-23 11:29 - 2017-06-23 11:47 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2017-06-23 11:28 - 2017-06-23 11:47 - 00000000 ____D C:\Users\editor\Desktop\mbar
2017-06-23 11:27 - 2017-06-23 11:28 - 16563352 _____ (Malwarebytes Corp.) C:\Users\editor\Downloads\mbar-1.09.3.1001.exe
2017-06-22 21:59 - 2017-06-22 21:59 - 00000000 ____D C:\TDSSKiller_Quarantine
2017-06-22 21:55 - 2016-07-14 03:14 - 00171664 _____ (Ray Hinchliffe) C:\Windows\system32\Drivers\SIVX64.sys
2017-06-22 21:49 - 2017-06-10 13:36 - 00000000 ____D C:\Users\editor\Desktop\integrity_verification
2017-06-22 21:49 - 2017-06-10 13:08 - 00000000 ____D C:\Users\editor\Desktop\tron
2017-06-22 21:41 - 2017-06-22 21:48 - 659787891 _____ (Igor Pavlov) C:\Users\editor\Desktop\Tron v10.1.0 (2017-06-10).exe
2017-06-22 20:20 - 2017-06-22 20:20 - 02030536 _____ (Bleeping Computer, LLC) C:\Users\editor\Downloads\rkill.exe
2017-06-22 20:12 - 2017-06-22 20:12 - 34790450 _____ C:\Users\editor\Downloads\windows6.1-kb4012212-x64_2decefaa02e2058dcd965702509a992d8c4e92b3.msu
2017-06-22 19:32 - 2017-06-22 19:32 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsigne31135abea56a536
2017-06-22 19:32 - 2017-06-22 19:32 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign2437faf4446c147c
2017-06-22 16:51 - 2017-06-22 16:51 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign096855595bc7753f
2017-06-22 16:50 - 2017-06-22 16:50 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign2a8de0a70e9934da
2017-06-22 14:31 - 2017-06-22 14:31 - 00000000 ____D C:\Program Files\Red Giant
2017-06-22 14:31 - 2017-05-10 19:56 - 15353856 _____ (Red Giant LLC) C:\Windows\system32\UniChooser.dll
2017-06-22 14:31 - 2017-05-10 19:56 - 13179904 _____ (Red Giant Software) C:\Windows\system32\Gpu_Shader_Engine_x64.dll
2017-06-22 14:31 - 2017-05-10 19:56 - 05528064 _____ (Noesis Technologies) C:\Windows\system32\Noesis.dll
2017-06-22 12:07 - 2017-06-22 12:07 - 00001167 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Premiere Pro CC 2017.lnk
2017-06-22 12:03 - 2017-06-22 12:03 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign3118c32baeebc941
2017-06-22 12:02 - 2017-06-22 12:02 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign698bbaaed98fc862
2017-06-19 17:39 - 2017-06-19 17:39 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign7fff0c43db9851b3
2017-06-19 17:38 - 2017-06-19 17:38 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign39bf399261bc6fd2
2017-06-19 17:37 - 2017-06-19 17:37 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign7acb5c62f5b628d3
2017-06-19 17:26 - 2017-06-19 17:26 - 00002880 _____ C:\Users\editor\Documents\FCP Translation Results 2017-06-19 17-26.txt
2017-06-19 17:26 - 2017-06-19 17:26 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign42389bfcb5552074
2017-06-19 17:26 - 2017-06-19 17:26 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign1e86a872dea4c587
2017-06-19 16:32 - 2017-06-19 17:23 - 00000000 ____D C:\Users\editor\Desktop\aaf
2017-06-16 21:21 - 2017-06-16 21:24 - 355934860 _____ C:\Users\editor\Downloads\OEXT.zip
2017-06-16 20:07 - 2017-06-16 20:07 - 08455478 _____ C:\Users\editor\Downloads\drive-download-20170617T000720Z-001.zip
2017-06-16 14:54 - 2017-06-16 14:54 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign74b22a34557fd6a6
2017-06-16 14:52 - 2017-06-16 14:52 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsigncad245026e30a186
2017-06-16 14:52 - 2017-06-16 14:52 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign5c962276e3fa74ab
2017-06-14 19:47 - 2017-06-14 19:47 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign4f1768933266bbd0
2017-06-14 19:32 - 2017-06-14 19:32 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsigncf9ed271a4570a7f
2017-06-14 19:32 - 2017-06-14 19:32 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign3a81c8a21e40e00c
2017-06-13 20:57 - 2017-06-02 04:28 - 02317824 _____ (Microsoft Corporation) C:\Windows\system32\tquery.dll
2017-06-13 20:57 - 2017-06-02 04:28 - 02222080 _____ (Microsoft Corporation) C:\Windows\system32\mssrch.dll
2017-06-13 20:57 - 2017-06-02 04:28 - 00778240 _____ (Microsoft Corporation) C:\Windows\system32\mssvp.dll
2017-06-13 20:57 - 2017-06-02 04:28 - 00491520 _____ (Microsoft Corporation) C:\Windows\system32\mssph.dll
2017-06-13 20:57 - 2017-06-02 04:28 - 00288256 _____ (Microsoft Corporation) C:\Windows\system32\mssphtb.dll
2017-06-13 20:57 - 2017-06-02 04:28 - 00115200 _____ (Microsoft Corporation) C:\Windows\system32\mssitlb.dll
2017-06-13 20:57 - 2017-06-02 04:28 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\mssprxy.dll
2017-06-13 20:57 - 2017-06-02 04:28 - 00075264 _____ (Microsoft Corporation) C:\Windows\system32\msscntrs.dll
2017-06-13 20:57 - 2017-06-02 04:28 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\msshooks.dll
2017-06-13 20:57 - 2017-06-02 04:11 - 00591872 _____ (Microsoft Corporation) C:\Windows\system32\SearchIndexer.exe
2017-06-13 20:57 - 2017-06-02 04:11 - 00249856 _____ (Microsoft Corporation) C:\Windows\system32\SearchProtocolHost.exe
2017-06-13 20:57 - 2017-06-02 04:10 - 00733696 _____ (Microsoft Corporation) C:\Windows\HelpPane.exe
2017-06-13 20:57 - 2017-06-02 04:10 - 00113664 _____ (Microsoft Corporation) C:\Windows\system32\SearchFilterHost.exe
2017-06-13 20:57 - 2017-06-02 04:09 - 01549824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tquery.dll
2017-06-13 20:57 - 2017-06-02 04:09 - 01400320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssrch.dll
2017-06-13 20:57 - 2017-06-02 04:09 - 00666624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssvp.dll
2017-06-13 20:57 - 2017-06-02 04:09 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssph.dll
2017-06-13 20:57 - 2017-06-02 04:09 - 00197120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssphtb.dll
2017-06-13 20:57 - 2017-06-02 04:09 - 00104448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssitlb.dll
2017-06-13 20:57 - 2017-06-02 04:09 - 00059392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msscntrs.dll
2017-06-13 20:57 - 2017-06-02 04:09 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssprxy.dll
2017-06-13 20:57 - 2017-06-02 03:58 - 00427520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchIndexer.exe
2017-06-13 20:57 - 2017-06-02 03:58 - 00164352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchProtocolHost.exe
2017-06-13 20:57 - 2017-06-02 03:57 - 00086528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchFilterHost.exe
2017-06-13 20:57 - 2017-06-02 03:57 - 00009728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msshooks.dll
2017-06-13 20:57 - 2017-05-21 00:28 - 00154856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2017-06-13 20:57 - 2017-05-21 00:28 - 00095464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2017-06-13 20:57 - 2017-05-21 00:24 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2017-06-13 20:57 - 2017-05-21 00:24 - 01212928 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2017-06-13 20:57 - 2017-05-21 00:24 - 00730624 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2017-06-13 20:57 - 2017-05-21 00:24 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2017-06-13 20:57 - 2017-05-21 00:24 - 00463872 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2017-06-13 20:57 - 2017-05-21 00:24 - 00345600 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2017-06-13 20:57 - 2017-05-21 00:24 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2017-06-13 20:57 - 2017-05-21 00:24 - 00312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2017-06-13 20:57 - 2017-05-21 00:24 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2017-06-13 20:57 - 2017-05-21 00:24 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll
2017-06-13 20:57 - 2017-05-21 00:24 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2017-06-13 20:57 - 2017-05-21 00:24 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2017-06-13 20:57 - 2017-05-21 00:24 - 00123904 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll
2017-06-13 20:57 - 2017-05-21 00:24 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2017-06-13 20:57 - 2017-05-21 00:24 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2017-06-13 20:57 - 2017-05-21 00:24 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2017-06-13 20:57 - 2017-05-21 00:24 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2017-06-13 20:57 - 2017-05-21 00:24 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2017-06-13 20:57 - 2017-05-21 00:24 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2017-06-13 20:57 - 2017-05-21 00:06 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2017-06-13 20:57 - 2017-05-21 00:06 - 00666112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2017-06-13 20:57 - 2017-05-21 00:06 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2017-06-13 20:57 - 2017-05-21 00:06 - 00342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
2017-06-13 20:57 - 2017-05-21 00:06 - 00261120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2017-06-13 20:57 - 2017-05-21 00:06 - 00254464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2017-06-13 20:57 - 2017-05-21 00:06 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2017-06-13 20:57 - 2017-05-21 00:06 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2017-06-13 20:57 - 2017-05-21 00:06 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2017-06-13 20:57 - 2017-05-21 00:06 - 00141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll
2017-06-13 20:57 - 2017-05-21 00:06 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2017-06-13 20:57 - 2017-05-21 00:06 - 00082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcrypt.dll
2017-06-13 20:57 - 2017-05-21 00:06 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2017-06-13 20:57 - 2017-05-21 00:06 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2017-06-13 20:57 - 2017-05-21 00:06 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2017-06-13 20:57 - 2017-05-21 00:06 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2017-06-13 20:57 - 2017-05-20 23:55 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2017-06-13 20:57 - 2017-05-20 23:48 - 00291328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2017-06-13 20:57 - 2017-05-20 23:48 - 00159744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2017-06-13 20:57 - 2017-05-20 23:48 - 00129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2017-06-13 20:57 - 2017-05-20 23:47 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2017-06-13 20:57 - 2017-05-20 23:46 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2017-06-13 20:57 - 2017-05-20 23:42 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
2017-06-13 20:57 - 2017-05-16 14:19 - 00394448 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2017-06-13 20:57 - 2017-05-16 13:35 - 00346320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2017-06-13 20:57 - 2017-05-14 16:46 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2017-06-13 20:57 - 2017-05-14 16:46 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2017-06-13 20:57 - 2017-05-14 16:28 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2017-06-13 20:57 - 2017-05-14 16:27 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2017-06-13 20:57 - 2017-05-14 16:27 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2017-06-13 20:57 - 2017-05-14 16:27 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2017-06-13 20:57 - 2017-05-14 16:26 - 00576512 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2017-06-13 20:57 - 2017-05-14 16:24 - 02899456 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2017-06-13 20:57 - 2017-05-14 16:19 - 25738752 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2017-06-13 20:57 - 2017-05-14 16:17 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2017-06-13 20:57 - 2017-05-14 16:16 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2017-06-13 20:57 - 2017-05-14 16:12 - 00615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2017-06-13 20:57 - 2017-05-14 16:10 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2017-06-13 20:57 - 2017-05-14 16:10 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2017-06-13 20:57 - 2017-05-14 16:10 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2017-06-13 20:57 - 2017-05-14 16:10 - 00116224 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2017-06-13 20:57 - 2017-05-14 16:01 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2017-06-13 20:57 - 2017-05-14 15:57 - 00489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2017-06-13 20:57 - 2017-05-14 15:55 - 05975040 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2017-06-13 20:57 - 2017-05-14 15:48 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2017-06-13 20:57 - 2017-05-14 15:47 - 00087552 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2017-06-13 20:57 - 2017-05-14 15:46 - 00107520 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2017-06-13 20:57 - 2017-05-14 15:42 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2017-06-13 20:57 - 2017-05-14 15:41 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2017-06-13 20:57 - 2017-05-14 15:38 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2017-06-13 20:57 - 2017-05-14 15:37 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2017-06-13 20:57 - 2017-05-14 15:36 - 00152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2017-06-13 20:57 - 2017-05-14 15:23 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2017-06-13 20:57 - 2017-05-14 15:23 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2017-06-13 20:57 - 2017-05-14 15:22 - 00499200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2017-06-13 20:57 - 2017-05-14 15:22 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2017-06-13 20:57 - 2017-05-14 15:22 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2017-06-13 20:57 - 2017-05-14 15:21 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2017-06-13 20:57 - 2017-05-14 15:20 - 00725504 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2017-06-13 20:57 - 2017-05-14 15:19 - 00806912 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2017-06-13 20:57 - 2017-05-14 15:18 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2017-06-13 20:57 - 2017-05-14 15:17 - 02132992 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2017-06-13 20:57 - 2017-05-14 15:16 - 02290176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2017-06-13 20:57 - 2017-05-14 15:15 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2017-06-13 20:57 - 2017-05-14 15:14 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2017-06-13 20:57 - 2017-05-14 15:12 - 00476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2017-06-13 20:57 - 2017-05-14 15:11 - 20274688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2017-06-13 20:57 - 2017-05-14 15:11 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2017-06-13 20:57 - 2017-05-14 15:10 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2017-06-13 20:57 - 2017-05-14 15:10 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2017-06-13 20:57 - 2017-05-14 15:02 - 00416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2017-06-13 20:57 - 2017-05-14 14:57 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2017-06-13 20:57 - 2017-05-14 14:57 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2017-06-13 20:57 - 2017-05-14 14:56 - 00091136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2017-06-13 20:57 - 2017-05-14 14:54 - 15252992 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2017-06-13 20:57 - 2017-05-14 14:53 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2017-06-13 20:57 - 2017-05-14 14:52 - 03240960 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2017-06-13 20:57 - 2017-05-14 14:52 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2017-06-13 20:57 - 2017-05-14 14:50 - 00279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2017-06-13 20:57 - 2017-05-14 14:49 - 00130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2017-06-13 20:57 - 2017-05-14 14:44 - 04549120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2017-06-13 20:57 - 2017-05-14 14:42 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2017-06-13 20:57 - 2017-05-14 14:40 - 00693248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2017-06-13 20:57 - 2017-05-14 14:39 - 02057216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2017-06-13 20:57 - 2017-05-14 14:38 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2017-06-13 20:57 - 2017-05-14 14:37 - 01544704 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2017-06-13 20:57 - 2017-05-14 14:30 - 13664768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2017-06-13 20:57 - 2017-05-14 14:27 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2017-06-13 20:57 - 2017-05-14 14:15 - 02767872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2017-06-13 20:57 - 2017-05-14 14:11 - 01314816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2017-06-13 20:57 - 2017-05-14 14:11 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2017-06-13 20:57 - 2017-05-12 14:27 - 00631176 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2017-06-13 20:57 - 2017-05-12 14:26 - 05547752 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2017-06-13 20:57 - 2017-05-12 14:26 - 00706792 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2017-06-13 20:57 - 2017-05-12 14:26 - 00382696 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2017-06-13 20:57 - 2017-05-12 14:24 - 01732864 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00880640 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00806912 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00419840 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00405504 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00215552 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00059904 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00034816 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:07 - 04001000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2017-06-13 20:57 - 2017-05-12 14:07 - 03945704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2017-06-13 20:57 - 2017-05-12 14:07 - 00308456 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2017-06-13 20:57 - 2017-05-12 14:04 - 01314112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00644096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00629760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00313344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00275456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 13:55 - 00148480 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2017-06-13 20:57 - 2017-05-12 13:54 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2017-06-13 20:57 - 2017-05-12 13:54 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2017-06-13 20:57 - 2017-05-12 13:52 - 03222528 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2017-06-13 20:57 - 2017-05-12 13:51 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2017-06-13 20:57 - 2017-05-12 13:50 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2017-06-13 20:57 - 2017-05-12 13:46 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2017-06-13 20:57 - 2017-05-12 13:43 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2017-06-13 20:57 - 2017-05-12 13:41 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2017-06-13 20:57 - 2017-05-12 13:41 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2017-06-13 20:57 - 2017-05-12 13:41 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2017-06-13 20:57 - 2017-05-12 13:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2017-06-13 20:57 - 2017-05-12 13:40 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 13:40 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 13:40 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 13:40 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 12:25 - 01251328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2017-06-13 20:57 - 2017-05-12 11:58 - 01648128 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2017-06-13 20:57 - 2017-05-12 11:58 - 01180160 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2017-06-13 20:57 - 2017-05-10 11:33 - 00091368 _____ (Microsoft Corporation) C:\Windows\system32\MigAutoPlay.exe
2017-06-13 20:57 - 2017-05-10 11:29 - 14183936 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2017-06-13 20:57 - 2017-05-10 11:29 - 03165184 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2017-06-13 20:57 - 2017-05-10 11:29 - 01867776 _____ (Microsoft Corporation) C:\Windows\system32\ExplorerFrame.dll
2017-06-13 20:57 - 2017-05-10 11:29 - 00192512 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2017-06-13 20:57 - 2017-05-10 11:29 - 00098816 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2017-06-13 20:57 - 2017-05-10 11:28 - 00091136 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2017-06-13 20:57 - 2017-05-10 11:16 - 00091368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MigAutoPlay.exe
2017-06-13 20:57 - 2017-05-10 11:14 - 02651136 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2017-06-13 20:57 - 2017-05-10 11:13 - 00709120 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2017-06-13 20:57 - 2017-05-10 11:13 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2017-06-13 20:57 - 2017-05-10 11:13 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2017-06-13 20:57 - 2017-05-10 11:13 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2017-06-13 20:57 - 2017-05-10 11:13 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2017-06-13 20:57 - 2017-05-10 11:13 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
2017-06-13 20:57 - 2017-05-10 11:12 - 12880896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2017-06-13 20:57 - 2017-05-10 11:12 - 01499648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ExplorerFrame.dll
2017-06-13 20:57 - 2017-05-10 11:12 - 00174080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2017-06-13 20:57 - 2017-05-10 11:00 - 00573440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2017-06-13 20:57 - 2017-05-10 11:00 - 00093696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2017-06-13 20:57 - 2017-05-10 11:00 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2017-06-13 20:57 - 2017-05-10 11:00 - 00030208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2017-06-13 20:57 - 2017-05-10 10:52 - 00117248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys
2017-06-13 20:57 - 2017-05-09 11:30 - 00757248 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll
2017-06-13 20:57 - 2017-05-09 11:29 - 00970240 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll
2017-06-13 20:57 - 2017-05-09 11:15 - 00071680 _____ C:\Windows\system32\PrintBrmUi.exe
2017-06-13 20:57 - 2017-05-09 11:11 - 00497664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll
2017-06-13 20:57 - 2017-05-07 11:33 - 00094440 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mountmgr.sys
2017-06-13 20:57 - 2017-05-07 11:29 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\msmmsp.dll
2017-06-13 20:57 - 2017-04-27 18:50 - 03550208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_47.dll
2017-06-13 20:57 - 2017-04-12 09:05 - 04296704 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_47.dll
2017-06-13 20:57 - 2017-03-30 11:03 - 00046080 _____ (Microsoft Corporation) C:\Windows\system32\rundll32.exe
2017-06-13 20:57 - 2017-03-30 10:58 - 00045056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
2017-06-13 19:03 - 2017-06-13 19:03 - 14976971 _____ C:\Users\editor\Downloads\nablet_XAVC_XDCAM_AMA_Plugin_Win_4.0.3.1146.zip
2017-06-13 19:03 - 2017-06-13 19:03 - 00000000 ____D C:\Users\editor\Downloads\nablet_XAVC_XDCAM_AMA_Plugin_Win_4.0.3.1146
2017-06-13 16:36 - 2017-06-13 16:36 - 00000000 ____D C:\Users\editor\AppData\Local\RzStats
2017-06-13 16:34 - 2017-06-13 16:34 - 00214174 _____ C:\Users\editor\Downloads\WindowsFirewall.diagcab
2017-06-13 16:32 - 2017-06-13 19:12 - 00000000 ____D C:\Users\editor\AppData\Local\Razer
2017-06-13 16:31 - 2017-06-13 19:13 - 00000000 ____D C:\ProgramData\Razer
2017-06-13 16:31 - 2017-06-13 19:13 - 00000000 ____D C:\Program Files (x86)\Razer
2017-06-13 15:27 - 2017-06-13 15:27 - 152572041 _____ C:\Users\editor\Downloads\windows6.1-kb4012215-x64_a777b8c251dcd8378ecdafa81aefbe7f9009c72b.msu
2017-06-13 15:13 - 2017-06-13 15:14 - 22908488 _____ (Philipp Schmieder Medien ) C:\Users\editor\Downloads\clipgrab-3.6.5-cgorg.exe
2017-06-13 15:01 - 2017-06-13 15:04 - 22738504 _____ (Razer Inc.) C:\Users\editor\Downloads\Razer_Synapse_Framework_V2.20.15.1104.exe
2017-06-12 18:32 - 2017-06-12 18:32 - 668212825 _____ C:\Users\editor\Desktop\ STRINGOUT PART 2.Copy.01.mov
2017-06-12 15:45 - 2017-06-12 15:45 - 00476169 _____ C:\Users\editor\Downloads\_Shoot_Checklist.xlsx
2017-06-12 14:27 - 2017-06-12 14:27 - 00000000 ____D C:\Users\editor\Downloads\GIFM_550_1-FILE_20170611192144
2017-06-11 21:31 - 2017-06-11 21:31 - 01933312 _____ C:\Users\editor\Downloads\061017_GROUP (1).aaf
2017-06-11 21:31 - 2017-06-11 21:31 - 00160812 _____ C:\Users\editor\Downloads\GIFM_550_1-FILE_20170611192144.zip
2017-06-11 21:30 - 2017-06-11 21:30 - 01933312 _____ C:\Users\editor\Downloads\061017_GROUP.aaf
2017-06-11 21:30 - 2017-06-11 21:30 - 01933312 _____ C:\Users\editor\Desktop\061017_GROUP.aaf
2017-06-11 19:21 - 2017-06-11 21:32 - 02342912 _____ C:\Users\editor\Desktop\061017_GROUP_MULTIGROUPED.aaf
2017-06-09 18:13 - 2017-06-20 16:28 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2017-06-08 20:23 - 2017-06-08 20:51 - 561908852 _____ C:\Users\editor\Desktop\052617_PB_OPEN1_1.mov
2017-06-08 18:43 - 2017-06-08 18:43 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign8188b830f2e1781d
2017-06-08 18:43 - 2017-06-08 18:43 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign311dc0be15a4e8e5
2017-06-08 16:17 - 2017-06-08 16:40 - 127564968 _____ C:\Users\editor\Desktop\TC.mov
2017-06-08 15:47 - 2017-06-08 16:09 - 111227757 _____ C:\Users\editor\Desktop\aa.mov
2017-06-08 12:50 - 2017-06-08 12:50 - 00001200 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Creative Cloud.lnk
2017-06-08 12:50 - 2017-06-08 12:50 - 00001188 _____ C:\Users\Public\Desktop\Adobe Creative Cloud.lnk
2017-06-08 11:05 - 2017-06-08 11:26 - 480804911 _____ C:\Users\editor\Desktop\22.09.mov
2017-06-08 11:00 - 2017-06-08 11:00 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsigna7c314ae638759b9
2017-06-08 11:00 - 2017-06-08 11:00 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign2fb759c9a750f030
2017-06-07 17:29 - 2017-05-18 13:30 - 130804461 ____N C:\Users\editor\Downloads\on 2017-05-18 at 15.09.mov
2017-06-07 17:25 - 2017-06-07 17:26 - 445301618 _____ C:\Users\editor\Downloads\drive-download-20170607T212436Z-001.zip
2017-06-07 17:25 - 2017-06-07 17:25 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsigndb08791fe2be7fb7
2017-06-07 17:25 - 2017-06-07 17:25 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign5120056e2d3f6cf7
2017-06-06 19:38 - 2017-06-06 19:38 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsignb8bd1562439c1688
2017-06-06 19:38 - 2017-06-06 19:38 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign70bab4a592232106
2017-06-06 12:51 - 2017-06-06 12:51 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wacom Tablet
2017-06-06 12:50 - 2017-06-06 12:50 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_wachidrouter_01011.Wdf
2017-06-06 12:50 - 2017-04-28 19:21 - 01804688 _____ (Microsoft Corporation) C:\Windows\system32\wdfcoinstaller01011.dll
2017-06-06 12:44 - 2017-06-06 12:44 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign9d8c4ca872eb95de
2017-06-06 12:44 - 2017-06-06 12:44 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign53ce6cdf44591021
2017-06-05 23:03 - 2017-06-06 12:25 - 00000000 ____D C:\Windows\IDOOYHNU
2017-06-05 17:04 - 2017-06-05 17:04 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsignffec44d35fb075e6
2017-06-05 17:04 - 2017-06-05 17:04 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsignf2951e3a4706ff43
2017-06-05 13:35 - 2017-06-05 13:35 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign8efc206c9568d7e7
2017-06-05 13:35 - 2017-06-05 13:35 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign344177af01f77b6a
2017-06-05 13:32 - 2017-06-05 13:32 - 145489330 _____ C:\Users\editor\Downloads\Jn 2017-05-04 at 22.09.mp4
2017-06-02 17:47 - 2017-06-02 17:47 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign18d15afce032f9ec
2017-06-02 17:47 - 2017-06-02 17:47 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign0c3094db0023a0c2
2017-06-02 15:16 - 2017-06-02 15:16 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsigneb50552d959030ba
2017-06-02 15:16 - 2017-06-02 15:16 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsignab937861b2dd6e19
2017-06-02 11:14 - 2017-06-02 11:14 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign486b309143e2c9ce
2017-06-02 11:07 - 2017-06-02 11:07 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign40b65fdb06015e17
2017-06-01 15:43 - 2017-06-01 16:16 - 640577372 _____ C:\Users\editor\Desktop\052617_PB_OPEN1.mov
2017-06-01 15:36 - 2017-06-01 15:36 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign2636f19498bb69c7
2017-06-01 15:35 - 2017-06-01 15:35 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsignd1ee8985c8597430
2017-06-01 15:09 - 2017-06-01 15:09 - 00001128 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Audition CC 2017.lnk
2017-06-01 15:08 - 2017-06-01 15:08 - 00001401 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Character Animator CC (Beta).lnk
2017-06-01 14:59 - 2017-06-01 14:59 - 00000000 ____D C:\Users\Public\Documents\AdobeInstalledCodecs
2017-06-01 14:58 - 2017-06-01 14:58 - 00001075 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe InDesign CC 2017.lnk
2017-06-01 14:52 - 2017-06-01 14:52 - 00002518 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Illustrator CC 2017.lnk
2017-06-01 14:50 - 2017-06-01 14:50 - 00001087 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CC 2017.lnk
2017-05-31 18:56 - 2017-05-31 18:56 - 00000000 ____D C:\Users\editor\Desktop\PLAY
2017-05-31 17:50 - 2017-05-31 17:50 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsignbcccae36e8f69123
2017-05-31 17:50 - 2017-05-31 17:50 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign6fa84344c147947f
2017-05-31 16:28 - 2017-05-31 16:28 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign98aba0ddda2d877d
2017-05-31 15:50 - 2017-05-31 15:50 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsigndd976a5083857c53
2017-05-31 15:50 - 2017-05-31 15:50 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign09d92304c42262d5
2017-05-31 11:58 - 2017-05-31 11:58 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsignca966863f82ec9c2
2017-05-31 11:58 - 2017-05-31 11:58 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign78066cb4858ef548
2017-05-31 11:58 - 2017-05-31 11:58 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign7138097e40fe4c8a
2017-05-30 19:23 - 2017-05-30 19:23 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign576844d639f135e5
2017-05-30 19:22 - 2017-05-30 19:22 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsigncc830bda13fc19ec
2017-05-30 19:22 - 2017-05-30 19:22 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign5c1d5a2798cd59c4
2017-05-30 17:59 - 2017-05-30 18:00 - 360581235 _____ C:\Users\editor\Downloads\111-lc-57348.mp4
2017-05-30 17:58 - 2017-05-30 17:58 - 00007447 _____ C:\Users\editor\Downloads\200-UN-40-36.mp4
2017-05-30 17:57 - 2017-05-30 17:57 - 61407442 _____ C:\Users\editor\Downloads\200-UN-38-29.mp4
2017-05-30 17:56 - 2017-05-30 17:57 - 431108924 _____ C:\Users\editor\Downloads\111-lc-58014.mp4
2017-05-30 17:56 - 2017-05-30 17:57 - 364720910 _____ C:\Users\editor\Downloads\330-dvic-34396.mp4
2017-05-30 17:55 - 2017-05-30 17:55 - 60868166 _____ C:\Users\editor\Downloads\34214.mp4
2017-05-30 17:55 - 2017-05-30 17:55 - 51541755 _____ C:\Users\editor\Downloads\30872.mp4
2017-05-30 17:52 - 2017-05-30 17:53 - 04752307 _____ C:\Users\editor\Downloads\30872.wmv
2017-05-30 17:52 - 2017-05-30 17:53 - 04746531 _____ C:\Users\editor\Downloads\34214.wmv
2017-05-30 17:14 - 2017-05-30 17:14 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsignf0783ad8c7e43533
2017-05-30 17:14 - 2017-05-30 17:14 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign4aacd883bb4ec32f
2017-05-30 17:14 - 2017-05-30 17:14 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign2234c07328d335de
2017-05-30 14:08 - 2017-05-30 14:08 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign1740179615a96708
2017-05-30 14:07 - 2017-05-30 14:07 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsigne03e683af7771134
2017-05-30 14:07 - 2017-05-30 14:07 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsigna289f46184532d96
2017-05-30 12:00 - 2017-05-30 12:00 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung Magician
2017-05-30 11:32 - 2017-05-30 11:32 - 00000672 _____ C:\Users\editor\Downloads\ulogviewer (3).jnlp
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-06-26 19:54 - 2017-05-12 13:50 - 00005106 _____ C:\Users\editor\Desktop\Rkill.txt
2017-06-26 19:50 - 2014-10-14 18:18 - 00000000 ____D C:\Windows\System32\Tasks\Event Viewer Tasks
2017-06-26 19:16 - 2013-06-14 16:34 - 00000000 ____D C:\Users\Public\Documents\Avid Media Composer
2017-06-26 17:41 - 2014-10-31 18:12 - 00000033 _____ C:\Users\editor\AppData\Roaming\AdobeWLCMCache.dat
2017-06-26 15:57 - 2014-10-27 18:22 - 00000000 ___RD C:\Users\editor\Creative Cloud Files
2017-06-26 13:20 - 2009-07-14 00:45 - 00027568 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2017-06-26 13:20 - 2009-07-14 00:45 - 00027568 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2017-06-26 12:18 - 2012-09-11 21:42 - 00000000 ____D C:\ProgramData\PDFC
2017-06-26 11:29 - 2015-04-17 14:54 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2017-06-26 11:27 - 2013-06-14 15:24 - 00000000 ____D C:\Users\editor\AppData\Local\Adobe
2017-06-26 11:22 - 2009-07-14 01:13 - 00793850 _____ C:\Windows\system32\PerfStringBackup.INI
2017-06-26 11:22 - 2009-07-13 23:20 - 00000000 ____D C:\Windows\inf
2017-06-26 11:18 - 2016-08-09 11:09 - 00000000 ____D C:\Users\editor\AppData\Roaming\Slack
2017-06-26 11:18 - 2014-10-14 15:01 - 00000000 ___RD C:\Users\editor\OneDrive
2017-06-26 11:17 - 2014-10-22 17:31 - 00252832 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2017-06-26 11:17 - 2013-07-01 13:19 - 00000000 ____D C:\Users\editor\AppData\Local\Aja
2017-06-26 11:17 - 2013-06-14 15:36 - 00000000 ____D C:\ProgramData\PACE
2017-06-26 11:17 - 2012-09-24 11:01 - 00000000 ____D C:\ProgramData\NVIDIA
2017-06-26 11:17 - 2009-07-14 01:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2017-06-26 11:15 - 2015-10-27 12:29 - 00000000 ____D C:\Program Files (x86)\Samsung
2017-06-23 19:05 - 2013-07-02 12:54 - 00000000 ____D C:\Users\Public\Documents\Shared Avid Projects
2017-06-23 18:12 - 2013-07-01 13:32 - 00000000 ____D C:\Users\editor\AppData\Local\BorisFX
2017-06-23 15:44 - 2014-10-14 15:19 - 00000000 ____D C:\Program Files\Adobe
2017-06-23 15:44 - 2013-07-01 13:30 - 00000000 ____D C:\Program Files\Boris FX, Inc
2017-06-23 14:13 - 2017-05-12 14:11 - 00004726 __RSH C:\ProgramData\ntuser.pol
2017-06-23 13:50 - 2013-06-14 11:48 - 00000000 ____D C:\Users\editor
2017-06-23 12:45 - 2015-11-23 21:01 - 00000000 ____D C:\Users\editor\AppData\Local\CrashDumps
2017-06-23 11:29 - 2014-10-22 17:30 - 00000000 ____D C:\ProgramData\Malwarebytes
2017-06-23 11:28 - 2017-05-12 13:51 - 00109272 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMChameleon.sys
2017-06-23 11:18 - 2015-11-04 13:32 - 00000000 ____D C:\Windows\pss
2017-06-22 23:22 - 2013-07-03 10:30 - 00000193 _____ C:\Windows\WORDPAD.INI
2017-06-22 16:53 - 2015-03-09 16:03 - 00000000 ____D C:\Users\editor\AppData\Roaming\Aescripts
2017-06-22 14:25 - 2015-08-24 14:57 - 00000000 ____D C:\ProgramData\rgt
2017-06-22 12:07 - 2016-02-11 22:42 - 00000000 ____D C:\Users\Public\Documents\Adobe
2017-06-22 10:18 - 2014-10-14 15:01 - 00002154 _____ C:\Users\editor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft OneDrive.lnk
2017-06-20 16:27 - 2015-11-24 13:19 - 00000000 ____D C:\ProgramData\xml_param
2017-06-20 14:57 - 2016-01-21 14:26 - 00000600 _____ C:\Users\editor\AppData\Local\PUTTY.RND
2017-06-20 14:45 - 2009-07-13 23:20 - 00000000 ____D C:\Windows\system32\NDF
2017-06-20 14:44 - 2015-01-14 12:06 - 00000000 ____D C:\Users\editor\AppData\Roaming\vlc
2017-06-19 16:41 - 2012-09-11 21:39 - 00000000 ____D C:\Program Files (x86)\Microsoft Office
2017-06-18 03:54 - 2014-10-14 14:57 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2017-06-16 21:21 - 2016-06-24 17:20 - 00000000 ____D C:\Users\editor\Desktop\junk
2017-06-16 18:23 - 2014-09-30 10:29 - 00000000 ____D C:\Users\editor\Desktop\post docs
2017-06-16 10:10 - 2016-12-13 12:45 - 00004312 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2017-06-16 10:10 - 2013-06-14 15:24 - 00803328 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2017-06-16 10:10 - 2013-06-14 15:24 - 00144896 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2017-06-16 10:10 - 2013-06-14 15:24 - 00000000 ____D C:\Windows\SysWOW64\Macromed
2017-06-16 10:10 - 2013-06-14 15:24 - 00000000 ____D C:\Windows\system32\Macromed
2017-06-14 04:01 - 2009-07-13 23:20 - 00000000 ____D C:\Windows\rescache
2017-06-14 03:24 - 2009-07-14 00:45 - 07472912 _____ C:\Windows\system32\FNTCACHE.DAT
2017-06-14 03:21 - 2009-07-13 23:20 - 00000000 ____D C:\Windows\SysWOW64\migwiz
2017-06-14 03:21 - 2009-07-13 23:20 - 00000000 ____D C:\Windows\system32\migwiz
2017-06-14 03:05 - 2014-10-14 18:38 - 00000000 ____D C:\Windows\system32\MRT
2017-06-14 03:02 - 2012-09-24 11:18 - 133627792 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2017-06-13 16:49 - 2016-08-09 11:09 - 00000000 ____D C:\Users\editor\AppData\Local\slack
2017-06-13 16:48 - 2016-08-09 11:09 - 00002124 _____ C:\Users\editor\Desktop\Slack.lnk
2017-06-13 16:48 - 2016-08-09 11:09 - 00000000 ____D C:\Users\editor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Slack Technologies
2017-06-13 16:48 - 2016-08-09 11:09 - 00000000 ____D C:\Users\editor\AppData\Local\SquirrelTemp
2017-06-13 16:45 - 2015-09-30 18:30 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2017-06-13 16:38 - 2014-10-06 18:38 - 00000000 ____D C:\Users\editor\AppData\Local\ElevatedDiagnostics
2017-06-08 12:50 - 2013-06-14 15:28 - 00000000 ____D C:\Users\editor\AppData\Roaming\Adobe
2017-06-08 12:50 - 2013-06-14 15:24 - 00000000 ____D C:\Program Files (x86)\Adobe
2017-06-06 19:39 - 2017-05-26 14:22 - 00000000 ____D C:\Users\editor\Desktop\PLAY
2017-06-06 12:50 - 2017-05-15 11:26 - 00000000 ____D C:\Program Files\Tablet
2017-06-06 12:44 - 2017-05-12 13:51 - 00077376 _____ C:\Windows\system32\Drivers\mbae64.sys
2017-06-06 05:32 - 2015-04-17 14:53 - 00000000 ____D C:\Program Files (x86)\Google
2017-06-01 14:58 - 2014-10-15 12:23 - 00000000 ____D C:\Program Files\Common Files\Adobe
2017-06-01 14:50 - 2014-10-16 11:42 - 00000000 ____D C:\Users\editor\Documents\Adobe
2017-05-31 13:38 - 2017-05-15 11:26 - 02275784 _____ (Wacom Technology, Corp.) C:\Windows\system32\Wacom_Tablet.dll
2017-05-31 13:38 - 2017-05-15 11:26 - 02268616 _____ (Wacom Technology, Corp.) C:\Windows\system32\Wacom_Touch_Tablet.dll
2017-05-31 13:38 - 2017-05-15 11:26 - 02174408 _____ (Wacom Technology, Corp.) C:\Windows\system32\WacomMT.dll
2017-05-31 13:38 - 2017-05-15 11:26 - 02112456 _____ (Wacom Technology, Corp.) C:\Windows\system32\Wintab32.dll
2017-05-31 13:38 - 2017-05-15 11:26 - 01788360 _____ (Wacom Technology, Corp.) C:\Windows\SysWOW64\Wacom_Tablet.dll
2017-05-31 13:38 - 2017-05-15 11:26 - 01781704 _____ (Wacom Technology, Corp.) C:\Windows\SysWOW64\Wacom_Touch_Tablet.dll
2017-05-31 13:38 - 2017-05-15 11:26 - 01673160 _____ (Wacom Technology, Corp.) C:\Windows\SysWOW64\WacomMT.dll
2017-05-31 13:38 - 2017-05-15 11:26 - 01632712 _____ (Wacom Technology, Corp.) C:\Windows\SysWOW64\Wintab32.dll
2017-05-30 16:45 - 2010-11-20 23:27 - 00565416 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2017-05-30 12:00 - 2015-11-04 11:55 - 00003268 _____ C:\Windows\System32\Tasks\SamsungMagician
2017-05-30 12:00 - 2015-11-04 11:14 - 00000000 ____D C:\ProgramData\Samsung
2017-05-30 12:00 - 2013-06-14 11:49 - 00001415 _____ C:\Users\editor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
==================== Files in the root of some directories =======
2014-10-31 18:12 - 2017-06-26 17:41 - 0000033 _____ () C:\Users\editor\AppData\Roaming\AdobeWLCMCache.dat
2015-02-23 19:50 - 2015-04-15 18:15 - 0000020 _____ () C:\Users\editor\AppData\Roaming\appdataFr3.bin
2015-10-13 19:40 - 2016-12-22 21:01 - 2111970 _____ () C:\Users\editor\AppData\Roaming\AvidApplicationManager_Install.log
2015-12-08 15:05 - 2015-12-08 15:05 - 0353038 _____ () C:\Users\editor\AppData\Roaming\CodecsPE_Install.log
2013-07-02 12:53 - 2013-07-02 12:56 - 13619600 _____ () C:\Users\editor\AppData\Roaming\MediaComposer_Install.log
2015-11-11 12:23 - 2015-11-11 12:23 - 0000600 _____ () C:\Users\editor\AppData\Roaming\winscp.rnd
2016-01-06 12:10 - 2016-01-06 18:19 - 0001456 _____ () C:\Users\editor\AppData\Local\Adobe Save for Web 13.0 Prefs
2016-01-21 14:26 - 2017-06-20 14:57 - 0000600 _____ () C:\Users\editor\AppData\Local\PUTTY.RND
2016-08-02 16:02 - 2016-08-02 16:02 - 0000218 _____ () C:\Users\editor\AppData\Local\recently-used.xbel
2015-03-04 14:24 - 2015-06-23 13:47 - 0007615 _____ () C:\Users\editor\AppData\Local\Resmon.ResmonCfg
Some files in TEMP:
====================
2016-05-05 13:42 - 2016-05-05 13:42 - 0152576 _____ () C:\Users\Administrator\AppData\Local\Temp\ext8871732758372805741.dll
2017-05-08 14:55 - 2017-01-18 04:50 - 0066472 _____ (Autodesk, Inc.) C:\Users\editor\AppData\Local\Temp\AcDeltree.exe
2017-06-23 11:51 - 2017-05-12 14:24 - 1732864 _____ (Microsoft Corporation) C:\Users\editor\AppData\Local\Temp\dllnt_dump.dll
2017-05-30 11:58 - 2017-05-30 11:58 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext1071487924470329686.dll
2016-09-08 14:12 - 2016-09-08 14:12 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext1078468819121090448.dll
2016-06-14 18:16 - 2016-06-14 18:16 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext1151835630057534668.dll
2015-11-16 16:24 - 2015-11-16 16:24 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext1183072325384774792.dll
2016-04-25 11:43 - 2016-04-25 11:43 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext1217413707317785236.dll
2016-03-14 16:54 - 2016-03-14 16:54 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext1319343702278081390.dll
2016-03-01 11:12 - 2016-03-01 11:12 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext1387032249583585987.dll
2016-04-01 10:25 - 2016-04-01 10:25 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext1390342959179133597.dll
2015-10-27 16:50 - 2015-10-27 16:50 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext1419658529081465959.dll
2015-10-27 10:30 - 2015-10-27 10:30 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext1430040114018611508.dll
2016-02-02 11:31 - 2016-02-02 11:31 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext1451832224755727541.dll
2017-01-11 13:07 - 2017-01-11 13:07 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext1509040781484176864.dll
2016-11-22 18:00 - 2016-11-22 18:00 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext1532003059987200971.dll
2016-12-15 13:38 - 2016-12-15 13:38 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext1533866195946092447.dll
2015-11-03 14:47 - 2015-11-03 14:47 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext154963228241822771.dll
2017-03-13 10:50 - 2017-03-13 10:50 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext1594388969696702898.dll
2016-02-25 12:41 - 2016-02-25 12:41 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext1706922428930719831.dll
2016-06-13 17:18 - 2016-06-13 17:18 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext1745706080785882248.dll
2016-08-02 13:16 - 2016-08-02 13:16 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext1770292877771680394.dll
2015-11-04 13:55 - 2015-11-04 13:55 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext1777408809831878958.dll
2016-12-23 11:26 - 2016-12-23 11:26 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext1797973998412743155.dll
2017-04-26 11:40 - 2017-04-26 11:40 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext1835306018527623051.dll
2017-06-19 16:26 - 2017-06-19 16:26 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext1889932346085638654.dll
2017-01-16 20:05 - 2017-01-16 20:05 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext1918484350215632423.dll
2017-05-15 11:25 - 2017-05-15 11:25 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext1921189100945833120.dll
2015-11-03 16:17 - 2015-11-03 16:17 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext2015770576046837310.dll
2016-12-01 14:06 - 2016-12-01 14:06 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext2133207907494036539.dll
2016-01-14 14:18 - 2016-01-14 14:18 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext2188325394909681814.dll
2016-06-06 10:10 - 2016-06-06 10:10 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext2376083175270374129.dll
2015-11-04 14:20 - 2015-11-04 14:20 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext2450965989854188459.dll
2017-05-10 13:28 - 2017-05-10 13:28 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext2549769600700938267.dll
2017-04-04 10:50 - 2017-04-04 10:50 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext2555866350480271609.dll
2017-01-17 17:38 - 2017-01-17 17:38 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext2679883320681407791.dll
2016-08-09 19:30 - 2016-08-09 19:30 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext2810383528727013082.dll
2016-02-05 17:20 - 2016-02-05 17:20 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext2812800208508467693.dll
2016-01-06 11:15 - 2016-01-06 11:15 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext2816016548880804213.dll
2015-12-14 13:40 - 2015-12-14 13:40 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext2836181816555615984.dll
2016-02-03 12:33 - 2016-02-03 12:33 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext2841381247710961653.dll
2015-11-04 16:33 - 2015-11-04 16:33 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext28417744230615292.dll
2017-06-06 12:56 - 2017-06-06 12:56 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext2875394656732631058.dll
2015-11-03 17:24 - 2015-11-03 17:24 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext2945307420508375877.dll
2015-11-03 21:09 - 2015-11-03 21:09 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext298511638111692833.dll
2016-11-30 15:18 - 2016-11-30 15:18 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext3047513954222222625.dll
2017-05-30 12:05 - 2017-05-30 12:05 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext3103501216984548210.dll
2017-06-06 12:41 - 2017-06-06 12:41 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext3119408804341771850.dll
2016-03-21 18:28 - 2016-03-21 18:28 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext3129859925905625542.dll
2015-11-04 12:14 - 2015-11-04 12:14 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext3215048347423473342.dll
2016-04-25 11:14 - 2016-04-25 11:14 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext327318349396438176.dll
2016-09-21 13:41 - 2016-09-21 13:41 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext3427369275572865229.dll
2015-11-19 12:16 - 2015-11-19 12:16 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext3432699624731639579.dll
2015-11-11 18:08 - 2015-11-11 18:08 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext3521498136178136464.dll
2016-08-10 21:33 - 2016-08-10 21:33 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext3547067461674825408.dll
2015-12-08 16:13 - 2015-12-08 16:13 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext3582601109642843821.dll
2016-07-19 16:58 - 2016-07-19 16:58 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext3632959286059685073.dll
2015-11-03 19:37 - 2015-11-03 19:37 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext3645369261435154005.dll
2015-11-04 13:45 - 2015-11-04 13:45 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext3728811933459157360.dll
2016-06-16 11:05 - 2016-06-16 11:05 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext376236734589993489.dll
2016-02-03 11:49 - 2016-02-03 11:49 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext3771783614819832373.dll
2016-01-19 13:09 - 2016-01-19 13:09 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext3831253954092960870.dll
2016-04-25 12:39 - 2016-04-25 12:39 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext3862766590378271749.dll
2016-02-03 11:59 - 2016-02-03 11:59 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext3880650978277736067.dll
2017-04-25 12:02 - 2017-04-25 12:02 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext3999035706403893609.dll
2015-12-04 11:45 - 2015-12-04 11:45 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext4148438026613017429.dll
2015-11-05 19:42 - 2015-11-05 19:42 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext421443006028540122.dll
2016-12-23 12:16 - 2016-12-23 12:16 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext4221036965169206932.dll
2016-12-05 20:50 - 2016-12-05 20:50 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext4333134748289330705.dll
2016-08-08 10:31 - 2016-08-08 10:31 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext4360345261882433226.dll
2016-08-10 17:12 - 2016-08-10 17:12 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext4396334001153822999.dll
2015-11-03 19:55 - 2015-11-03 19:55 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext4519509575656148328.dll
2015-12-11 13:11 - 2015-12-11 13:11 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext457642066180944725.dll
2015-11-30 17:51 - 2015-11-30 17:51 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext4678183524347596554.dll
2016-02-25 19:46 - 2016-02-25 19:46 - 0152576 ____N () C:\Users\editor\AppData\Local\Temp\ext488632496472135802.dll
2016-06-21 17:28 - 2016-06-21 17:28 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext4898600658738648022.dll
2017-04-26 18:43 - 2017-04-26 18:43 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext492206926580749312.dll
2017-06-13 16:49 - 2017-06-13 16:49 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext4983239252163645349.dll
2016-06-06 10:38 - 2016-06-06 10:38 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext4999928916769366800.dll
2016-12-13 12:42 - 2016-12-13 12:42 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext5036039854860822260.dll
2017-06-22 20:19 - 2017-06-22 20:19 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext5114781696799636751.dll
2016-03-04 20:12 - 2016-03-04 20:12 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext5139767144321286239.dll
2015-11-03 20:56 - 2015-11-03 20:56 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext5268417348436910702.dll
2017-01-27 05:54 - 2017-01-27 05:54 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext5286416144301495535.dll
2016-02-10 19:13 - 2016-02-10 19:13 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext5325854032330694098.dll
2017-06-19 17:45 - 2017-06-19 17:45 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext5342494215139559920.dll
2017-05-12 13:25 - 2017-05-12 13:25 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext5415927987645624840.dll
2015-12-09 19:26 - 2015-12-09 19:26 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext5456793605759750676.dll
2016-09-20 11:52 - 2016-09-20 11:52 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext5495596744398337494.dll
2016-01-28 20:34 - 2016-01-28 20:34 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext5519742628931322407.dll
2017-01-11 18:18 - 2017-01-11 18:18 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext5670253913556597081.dll
2017-01-27 06:04 - 2017-01-27 06:04 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext5695242686685089691.dll
2016-08-11 10:30 - 2016-08-11 10:30 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext5702430998017351286.dll
2016-09-30 13:33 - 2016-09-30 13:33 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext5721296887814790852.dll
2017-03-16 19:52 - 2017-03-16 19:52 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext5764401674546283438.dll
2017-06-23 14:40 - 2017-06-23 14:40 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext5774309492370009115.dll
2016-06-06 10:29 - 2016-06-06 10:29 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext577628823710051129.dll
2015-12-16 14:00 - 2015-12-16 14:00 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext589574615576507970.dll
2015-11-03 15:51 - 2015-11-03 15:51 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext5959308617025665169.dll
2016-06-17 10:50 - 2016-06-17 10:50 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext6147291925437994748.dll
2017-05-04 11:26 - 2017-05-04 11:26 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext61563072621552275.dll
2017-01-27 06:09 - 2017-01-27 06:09 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext6243305647609277638.dll
2015-11-24 11:15 - 2015-11-24 11:15 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext6264000069752568423.dll
2015-12-08 14:12 - 2015-12-08 14:12 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext6314329431092767208.dll
2017-05-12 14:15 - 2017-05-12 14:15 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext6326619680611514628.dll
2015-11-04 16:22 - 2015-11-04 16:22 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext6400257663228438677.dll
2016-04-25 11:08 - 2016-04-25 11:08 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext6405883880151987112.dll
2017-06-23 11:22 - 2017-06-23 11:22 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext6417672052045847144.dll
2017-04-27 12:04 - 2017-04-27 12:04 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext6450205877007966145.dll
2016-12-05 20:53 - 2016-12-05 20:53 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext6472259147865921929.dll
2017-04-10 12:36 - 2017-04-10 12:36 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext6545057915716711808.dll
2017-06-23 17:45 - 2017-06-23 17:45 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext6549777930575442372.dll
2016-12-22 21:02 - 2016-12-22 21:02 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext6574600315598065418.dll
2017-05-15 11:13 - 2017-05-15 11:13 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext6585627935289460830.dll
2017-06-06 12:52 - 2017-06-06 12:52 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext6629143606079133350.dll
2017-06-26 10:49 - 2017-06-26 10:49 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext6742382297477849267.dll
2016-02-25 11:37 - 2016-02-25 11:37 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext6835678782052956182.dll
2017-03-16 12:47 - 2017-03-16 12:47 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext688801886005781476.dll
2017-05-08 15:12 - 2017-05-08 15:12 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext7020022486612609402.dll
2015-10-27 10:42 - 2015-10-27 10:42 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext7066506078704847800.dll
2017-05-31 19:00 - 2017-05-31 19:00 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext707327277462235932.dll
2017-01-11 13:16 - 2017-01-11 13:16 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext7087696774860597994.dll
2015-11-04 13:30 - 2015-11-04 13:30 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext7144637721176901402.dll
2015-11-04 11:51 - 2015-11-04 11:51 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext7162592043594236485.dll
2017-01-11 21:26 - 2017-01-11 21:26 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext7211004424563206126.dll
2016-10-02 18:15 - 2016-10-02 18:15 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext7226956485726737268.dll
2017-06-06 12:25 - 2017-06-06 12:25 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext7229050651829048800.dll
2015-11-16 16:18 - 2015-11-16 16:18 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext7284758257686008523.dll
2015-12-08 16:08 - 2015-12-08 16:08 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext7294562210174342260.dll
2016-03-21 18:42 - 2016-03-21 18:42 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext7314094202278723315.dll
2016-03-09 14:10 - 2016-03-09 14:10 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext7347878871495292381.dll
2015-11-04 20:05 - 2015-11-04 20:05 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext7355951439687241441.dll
2016-01-20 13:02 - 2016-01-20 13:02 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext7365291522788142033.dll
2015-11-03 21:20 - 2015-11-03 21:20 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext7461020531561011148.dll
2017-06-14 10:39 - 2017-06-14 10:39 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext7469781079091889311.dll
2015-11-04 14:14 - 2015-11-04 14:14 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext749037931539721548.dll
2016-07-06 14:56 - 2016-07-06 14:56 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext7511071368232514677.dll
2017-04-27 12:36 - 2017-04-27 12:36 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext7610947742062987460.dll
2017-05-15 11:31 - 2017-05-15 11:31 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext7750742442214766394.dll
2015-11-04 14:40 - 2015-11-04 14:40 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext7788321599172764575.dll
2015-11-03 21:00 - 2015-11-03 21:00 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext7858416737919149772.dll
2017-04-05 11:14 - 2017-04-05 11:14 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext7866096943424427212.dll
2015-12-08 15:12 - 2015-12-08 15:12 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext7868478401755576745.dll
2016-02-25 11:42 - 2016-02-25 11:42 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext7952234657673263324.dll
2017-06-13 20:10 - 2017-06-13 20:10 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext8002046139409601734.dll
2017-01-27 05:59 - 2017-01-27 05:59 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext8058507083610037645.dll
2016-10-13 13:45 - 2016-10-13 13:45 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext806304567866090803.dll
2017-06-22 23:09 - 2017-06-22 23:09 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext8063051266009376708.dll
2016-07-06 15:38 - 2016-07-06 15:38 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext8063493851403517550.dll
2016-07-22 10:03 - 2016-07-22 10:03 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext806734091584293028.dll
2015-11-04 11:56 - 2015-11-04 11:56 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext8077446043908712965.dll
2016-03-18 16:31 - 2016-03-18 16:31 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext8080963830776677325.dll
2016-02-04 18:59 - 2016-02-04 18:59 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext8087831062423633985.dll
2017-04-17 11:08 - 2017-04-17 11:08 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext8136299661620296143.dll
2016-01-19 17:51 - 2016-01-19 17:51 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext8170218790396946275.dll
2016-09-18 19:13 - 2016-09-18 19:13 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext8232130495925374245.dll
2017-05-10 14:55 - 2017-05-10 14:55 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext8243045330470464255.dll
2016-12-15 18:24 - 2016-12-15 18:24 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext8287949911228513018.dll
2017-04-27 12:19 - 2017-04-27 12:19 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext8340037726148203461.dll
2017-02-21 11:04 - 2017-02-21 11:04 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext8342026742723814026.dll
2015-11-16 17:47 - 2015-11-16 17:47 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext8343189618411644959.dll
2015-11-04 14:02 - 2015-11-04 14:02 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext8344530914611328271.dll
2016-02-19 20:50 - 2016-02-19 20:50 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext8349521810803979349.dll
2015-12-08 15:04 - 2015-12-08 15:04 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext8406687461669924022.dll
2016-02-11 21:42 - 2016-02-11 21:42 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext8407409975011528703.dll
2015-11-04 13:49 - 2015-11-04 13:49 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext842836194662834067.dll
2015-12-02 17:11 - 2015-12-02 17:11 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext8476675325550759173.dll
2016-02-09 16:35 - 2016-02-09 16:35 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext8490449391639332834.dll
2017-01-11 13:21 - 2017-01-11 13:21 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext8495405909675811418.dll
2016-10-24 11:49 - 2016-10-24 11:50 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext8517292786496721413.dll
2017-06-23 12:55 - 2017-06-23 12:55 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext8618033682931287079.dll
2015-11-04 13:25 - 2015-11-04 13:25 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext8710206098169181479.dll
2016-01-05 12:50 - 2016-01-05 12:50 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext8781960756706951459.dll
2016-06-29 14:18 - 2016-06-29 14:18 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext8807036427242350904.dll
2016-09-27 15:56 - 2016-09-27 15:56 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext8935767832256560257.dll
2016-03-31 11:51 - 2016-03-31 11:51 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext8955451639592371649.dll
2017-01-11 21:16 - 2017-01-11 21:16 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext8962216957799883270.dll
2017-06-26 11:19 - 2017-06-26 11:19 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext8969235745113472060.dll
2016-01-15 20:40 - 2016-01-15 20:40 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext8994269622742200888.dll
2016-04-15 16:32 - 2016-04-15 16:32 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext9056070732631085523.dll
2017-04-25 11:34 - 2017-04-25 11:34 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext9213865936583327090.dll
2017-02-22 14:46 - 2017-02-22 14:46 - 2903480 _____ () C:\Users\editor\AppData\Local\Temp\npp.7.3.2.Installer.exe
2016-11-23 23:47 - 2016-11-23 23:47 - 14700056 _____ (Samsung Electronics ) C:\Users\editor\AppData\Local\Temp\Samsung_Magician_Installer.exe
2015-12-08 14:33 - 2015-05-28 15:23 - 1162776 _____ (proDAD GmbH) C:\Users\editor\AppData\Local\Temp\uninstall.exe
2016-06-24 15:05 - 2016-06-24 15:05 - 30533688 _____ () C:\Users\editor\AppData\Local\Temp\vlc-2.2.4-win32.exe
Some zero byte size files/folders:
==========================
C:\Windows\System32\.exe
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2017-06-22 00:36
==================== End of FRST.txt ============================