Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

SVC miner, trojan


  • This topic is locked This topic is locked
20 replies to this topic

#1 rm540

rm540

  • Members
  • 13 posts
  • OFFLINE
  •  
  • Local time:06:14 PM

Posted 05 July 2017 - 01:32 PM

Hi, I recently removed a bunch of bad stuff via MBAM, MBR, MSE, etc. and I'm trying to see if I'm still at risk/clean everything completely.

 

Here's the dds.txt:

 

DDS (Ver_2012-11-20.01) - NTFS_AMD64 
Internet Explorer: 11.0.9600.18698
Run by editor at 14:13:12 on 2017-07-05
Microsoft Windows 7 Professional   6.1.7601.1.1252.1.1033.18.24500.15520 [GMT -4:00]
.
AV: Microsoft Security Essentials *Enabled/Updated* {71A27EC9-3DA6-45FC-60A7-004F623C6189}
SP: Microsoft Security Essentials *Enabled/Updated* {CAC39F2D-1B9C-4A72-5A17-3B3D19BB2B34}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvwmi64.exe
C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvscpapisvr.exe
C:\Windows\system32\svchost.exe -k RPCSS
c:\Program Files\Microsoft Security Client\MsMpEng.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
C:\Program Files\Tablet\Wacom\WTabletServicePro.exe
C:\Program Files\Tablet\Wacom\WacomHost.exe
C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\System32\spoolsv.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe
C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
C:\Program Files\AJA\windows\Applications\ajadaemon.exe
C:\Program Files\Avid\Editor Transcode\TranscodeService\AvidEditorDbEngine.exe
C:\Program Files\Avid\Editor Transcode\TranscodeService\AvidEditorDbEngine.exe
C:\Program Files\Avid\Editor Transcode\TranscodeService\rnc-central\AvidEditorTranscodeStatus.exe
C:\Program Files\Avid\Editor Transcode\TranscodeService\rnc-central\AvidEditorTranscodeStatus.exe
C:\Program Files\Avid\ISIS Client\Utilities\Benchmark Utility\BenchmarkAgent.exe
C:\Windows\system32\AvidFos_Service.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files (x86)\Google\Chrome Remote Desktop\59.0.3071.47\remoting_host.exe
C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe
C:\Program Files (x86)\Google\Chrome Remote Desktop\59.0.3071.47\remoting_host.exe
C:\Windows\System32\svchost.exe -k utcsvc
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\IProsetMonitor.exe
C:\Program Files (x86)\Common Files\PACE\Services\LicenseServices\LDSvc.exe
C:\Program Files (x86)\PDF Complete\pdfsvc.exe
C:\Windows\system32\RAPID\SamsungRapidSvc.exe
C:\Program Files (x86)\Common Files\SafeNet Sentinel\Sentinel Keys Server\sntlkeyssrvr.exe
C:\Program Files (x86)\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe
C:\Program Files (x86)\Common Files\SafeNet Sentinel\Sentinel Security Runtime\sntlsrtsrvr.exe
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe
C:\Program Files\Avid\Editor Transcode\TranscodeService\AvidEditorMSE.exe
C:\Program Files\Avid\Editor Transcode\TranscodeService\AvidEditorMSE.exe
C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
c:\Program Files\Microsoft Security Client\NisSrv.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe
C:\Windows\system32\nvwmi64.exe
C:\Windows\SYSTEM32\WISPTIS.EXE
C:\Windows\system32\taskhost.exe
C:\Windows\SYSTEM32\WISPTIS.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Tablet\Wacom\Wacom_TabletUser.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\Dwm.exe
C:\Program Files\Tablet\Wacom\WacomHost.exe
C:\Windows\Explorer.EXE
C:\USERS\EDITOR\DOWNLOADS\PROCEXP.EXE
C:\Program Files\Tablet\Wacom\Wacom_TouchUser.exe
C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files\Microsoft Device Center\itype.exe
C:\Program Files\Microsoft Device Center\ipoint.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
C:\Program Files (x86)\Samsung\RAPID\CacheFilter\SamsungRapidApp.exe
C:\Program Files\Tablet\Wacom\32\WacomDesktopCenter.exe
C:\Users\editor\AppData\Local\Microsoft\OneDrive\OneDrive.exe
C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\acrotray.exe
C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AutodeskDesktopApp.exe
C:\Program Files\Avid\Application Manager\AvidApplicationManager.exe
C:\Program Files (x86)\Autodesk\Autodesk Desktop App\acwebbrowser\acwebbrowser.exe
C:\Users\editor\AppData\Local\slack\app-2.6.3\slack.exe
C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe
C:\Program Files\Avid\Avid Media Composer\AvidBackgroundServicesManager.exe
C:\Program Files\Avid\ISIS Client\Client Manager\ISISClientManager.exe
C:\Program Files\UltraMon\UltraMon.exe
C:\Program Files (x86)\Autodesk\Autodesk Desktop App\acwebbrowser\acwebbrowser.exe
C:\Program Files\UltraMon\UltraMonTaskbar.exe
C:\Program Files (x86)\Autodesk\Autodesk Desktop App\acwebbrowser\acwebbrowser.exe
C:\Program Files (x86)\Common Files\Realtime Soft\RTSHookInterop\x32\RTSHookInterop.exe
C:\Users\editor\AppData\Local\slack\app-2.6.3\slack.exe
C:\Users\editor\AppData\Local\slack\app-2.6.3\slack.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Users\editor\AppData\Local\slack\app-2.6.3\slack.exe
C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe
C:\Program Files\Avid\Application Manager\QtWebEngineProcess.exe
C:\Program Files\Avid\Application Manager\AvidAppManHelper.exe
C:\Users\editor\AppData\Local\slack\app-2.6.3\slack.exe
C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe
C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\CCXProcess.exe
C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\libs\node.exe
C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\CCLibrary.exe
C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\libs\node.exe
C:\Program Files (x86)\Samsung\Samsung Magician\SamsungMagician.exe
C:\Windows\sysWOW64\wbem\wmiprvse.exe
C:\Users\editor\AppData\Local\Temp\PROCEXP64.exe
C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
C:\Program Files (x86)\Intel\Intel® Management Engine Components\IMSS\PrivacyIconClient.exe
C:\Program Files (x86)\Tweaking.com\Windows Repair (All in One)\WR_Tray_Icon.exe
C:\Windows\system32\prevhost.exe
C:\Windows\SysWOW64\prevhost.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files\UltraMon\UltraMonUiAcc.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Windows\system32\mmc.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe
C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\HEX\Adobe CEF Helper.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\Adobe Installer.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Common Files\Realtime Soft\RTSHookInterop\x32\RTSHookInterop.exe
C:\Program Files\Adobe\Adobe After Effects CC 2017\Support Files\AfterFX.exe
C:\Program Files\Adobe\Adobe After Effects CC 2017\Support Files\32\dynamiclinkmanager.exe
C:\Program Files\Adobe\Adobe After Effects CC 2017\Support Files\32\Adobe QT32 Server.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Windows\system32\mmc.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Notepad++\notepad++.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\editor\Downloads\FSS.exe
C:\Windows\system32\svchost.exe -k SDRSVC
C:\Windows\system32\vssvc.exe
C:\Windows\SysWOW64\notepad.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Windows\system32\mmc.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Users\editor\Downloads\HijackThis.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Windows\system32\taskeng.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
mWinlogon: Userinit = userinit.exe,
BHO: iSkysoft iTube Studio 4.2.0: {1A6B6AD0-2735-498F-834C-AFCEA37847C2} - C:\ProgramData\iSkysoft\iTube Studio\WSBrowserAppMgr.dll
BHO: Adobe Acrobat Create PDF Helper: {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll
BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\root\Office16\URLREDIR.DLL
BHO: Adobe Acrobat Create PDF from Selection: {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll
TB: Adobe Acrobat Create PDF Toolbar: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll
uRun: [AdobeBridge] <no file>
mRun: [IMSS] "C:\Program Files (x86)\Intel\Intel® Management Engine Components\IMSS\PIconStartup.exe"
mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
mRun: [Adobe Creative Cloud] "C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe" --showwindow=false --onOSstartup=true
mRun: [iSkysoft Helper Compact.exe] C:\Program Files (x86)\Common Files\iSkysoft\iSkysoft Helper Compact\ISHelper.exe
mRun: [DelaypluginInstall] C:\ProgramData\iSkysoft\iTube Studio\DelayPluginI.exe
mRun: [Acrobat Assistant 8.0] "C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Acrotray.exe"
mRun: [PDF Complete] C:\Program Files (x86)\PDF Complete\pdfsty.exe
mRun: [Autodesk Desktop App] "C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AutodeskDesktopApp.exe" -tray
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\AJAFIR~1.LNK - C:\Program Files\AJA\windows\Firmware\ajaflash.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\Avid Application Manager.lnk - C:\Windows\Installer\{99E377DB-D2D0-44A5-8533-AA8BE1381644}\NewShortcut1_E1E0FF1FC1474601A40EFEF248F11D43.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\Avid Background Services Manager.lnk - C:\Windows\Installer\{95EB1E9C-F759-4427-8EEE-F96C48541A06}\NewShortcut1_4CE83F107C544E87A6F35E0E551E78CA.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\ISIS Client Manager.lnk - C:\Program Files\Avid\ISIS Client\Client Manager\ISISClientManager.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\UltraMon.lnk - C:\Windows\Installer\{D4E62D29-31A1-4938-8CB7-7D275C1AEAC6}\IcoUltraMon.ico
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
uPolicies-DisallowRun: 1 = mstsc.exe
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
IE: E&xport to Microsoft Excel - C:\Program Files (x86)\Microsoft Office\Root\Office16\EXCEL.EXE/3000
IE: Se&nd to OneNote - C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnIE.dll/105
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIELinkedNotes.dll
TCP: NameServer = 8.8.8.8 8.8.4.4
TCP: Interfaces\{0C06085B-51F9-4B6A-8F35-4A6E4F6EB3FC} : DHCPNameServer = 8.8.8.8 8.8.4.4
TCP: Interfaces\{AF626FD6-E522-47E2-83CE-48AD0E00D527} : NameServer = 223.5.5.5,8.8.8.8
Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL
Handler: WSISAllmytubechrome - {4724F5AF-4E6D-41CA - <orphaned>
SSODL: WebCheck - <orphaned>
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\58.0.3029.81\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level
mASetup: {AC76BA86-0000-0000-7760-7E8A45000000} - "C:\Windows\SysWOW64\Rundll32.exe" "C:\Program Files (x86)\Adobe\Acrobat DC\Esl\Aiod.dll",CreateAcroUserSettings
x64-BHO: Lync Browser Helper: {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll
x64-BHO: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.8.0_131\bin\ssv.dll
x64-BHO: Adobe Acrobat Create PDF Helper: {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\x64\AcroIEFavStub.dll
x64-BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesX64\Microsoft Office\Office16\URLREDIR.DLL
x64-BHO: Microsoft OneDrive for Business Browser Helper: {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL
x64-BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre1.8.0_131\bin\jp2ssv.dll
x64-BHO: Adobe Acrobat Create PDF from Selection: {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\x64\AcroIEFavStub.dll
x64-TB: Adobe Acrobat Create PDF Toolbar: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\x64\AcroIEFavStub.dll
x64-Run: [RTHDVCPL] "C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" -s
x64-Run: [HPSYSDRV] C:\Program Files (x86)\Hewlett-Packard\HP Odometer\HPSYSDRV.EXE
x64-Run: [IntelliType Pro] "c:\Program Files\Microsoft Device Center\itype.exe"
x64-Run: [IntelliPoint] "c:\Program Files\Microsoft Device Center\ipoint.exe"
x64-Run: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
x64-Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
x64-Run: [nwiz] "C:\Program Files\NVIDIA Corporation\nview\nwiz.exe" /installquiet
x64-Run: [Malwarebytes TrayApp] C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe
x64-Run: [SamsungRapidApp] C:\Program Files (x86)\Samsung\RAPID\CacheFilter\SamsungRapidApp.exe
x64-Run: [ZAM] "C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe" /minimized
x64-IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesX64\Microsoft Office\Office16\ONBttnIE.dll
x64-IE: {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll
x64-IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesX64\Microsoft Office\Office16\ONBttnIELinkedNotes.dll
x64-Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - <orphaned>
x64-Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - <orphaned>
x64-Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - <orphaned>
x64-Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - <orphaned>
x64-Handler: WSISAllmytubechrome - {4724F5AF-4E6D-41CA - <orphaned>
x64-SSODL: WebCheck - <orphaned>
x64-mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\59.0.3071.115\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\editor\AppData\Roaming\Mozilla\Firefox\Profiles\p0snnc5x.default\
FF - plugin: C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll
FF - plugin: C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll
FF - plugin: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll
FF - plugin: C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
FF - plugin: C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll
FF - plugin: C:\Users\editor\AppData\Local\Programs\Aspera\Aspera Connect\lib\3.6.1\npasperaweb_3.6.1.111228.dll
FF - plugin: C:\Users\editor\AppData\Local\Programs\Aspera\Aspera Connect\lib\3.6.1\npasperaweb64_3.6.1.111228.dll
FF - plugin: C:\Users\editor\AppData\Roaming\SigniantInc\SigniantTransfer\5.4.3.70626\npSigniantTransfer.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_26_0_0_131.dll
.
============= SERVICES / DRIVERS ===============
.
R0 iaStorA;iaStorA;C:\Windows\System32\drivers\iaStorA.sys [2012-3-15 567216]
R0 iaStorF;iaStorF;C:\Windows\System32\drivers\iaStorF.sys [2012-3-15 24496]
R0 iaStorS;iaStorS;C:\Windows\System32\drivers\iaStorS.sys [2012-3-31 639408]
R0 MpFilter;Microsoft Malware Protection Driver;C:\Windows\System32\drivers\MpFilter.sys [2016-8-25 295000]
R0 PxHlpa64;PxHlpa64;C:\Windows\System32\drivers\PxHlpa64.sys [2012-9-11 56336]
R0 SamsungRapidDiskFltr;SAMSUNG RAPID Mode Disk Filter Driver;C:\Windows\System32\drivers\SamsungRapidDiskFltr.sys [2017-6-26 272792]
R0 SamsungRapidFSFltr;SamsungRapidFSFltr;C:\Windows\System32\drivers\SamsungRapidFSFltr.sys [2016-11-18 111512]
R1 HWiNFO32;HWiNFO32/64 Kernel Driver;C:\Windows\System32\drivers\HWiNFO64A.SYS [2017-4-4 27552]
R1 MpKsl2da25a2b;MpKsl2da25a2b;C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{1E6E9F38-450D-463B-8200-50E1C8FED5A9}\MpKsl2da25a2b.sys [2017-7-5 44928]
R1 ZAM;ZAM Helper Driver;C:\Windows\System32\drivers\zam64.sys [2017-7-3 203680]
R1 ZAM_Guard;ZAM Guard Driver;C:\Windows\System32\drivers\zamguard64.sys [2017-7-3 203680]
R2 AdobeUpdateService;AdobeUpdateService;C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [2017-6-4 814688]
R2 AGSService;Adobe Genuine Software Integrity Service;C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2015-9-4 2246256]
R2 AJA Service;AJA Device Service;C:\Program Files\AJA\windows\Applications\ajadaemon.exe [2015-11-5 1649152]
R2 Avid Editor Broker;Avid Editor Broker;C:\Program Files\Avid\Editor Transcode\TranscodeService\AvidEditorMSE.exe [2016-9-1 662280]
R2 Avid Editor Db Engine;Avid Editor Db Engine;C:\Program Files\Avid\Editor Transcode\TranscodeService\AvidEditorDbEngine.exe [2016-9-1 661768]
R2 Avid Editor Transcode Status;Avid Editor Transcode Status;C:\Program Files\Avid\Editor Transcode\TranscodeService\rnc-central\AvidEditorTranscodeStatus.exe [2016-9-1 297736]
R2 Avid ISIS Benchmark Agent;Avid ISIS Benchmark Agent;C:\Program Files\Avid\ISIS Client\Utilities\Benchmark Utility\BenchmarkAgent.exe [2015-11-13 4160000]
R2 AvidFos;AvidFos;C:\Windows\System32\drivers\AvidFos.sys [2015-11-13 755944]
R2 AvidFosFS;Avid Fos FS;C:\Windows\System32\AvidFos_Service.exe [2015-11-13 17554944]
R2 AvidFosLog;AvidFosLog;C:\Windows\System32\drivers\AvidFosLog.sys [2015-11-13 29416]
R2 AvidFosShell;AvidFosShell;C:\Windows\System32\drivers\AvidFosShell.sys [2015-11-13 17640]
R2 chromoting;Chrome Remote Desktop Service;C:\Program Files (x86)\Google\Chrome Remote Desktop\59.0.3071.47\remoting_host.exe [2017-5-9 71512]
R2 ClickToRunSvc;Microsoft Office ClickToRun Service;C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [2015-12-6 4122816]
R2 cvhsvc;Client Virtualization Handler;C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE [2015-3-18 822496]
R2 DiagTrack;Diagnostics Tracking Service;C:\Windows\System32\svchost.exe -k utcsvc [2009-7-13 27136]
R2 fsdk-wrap;fsdk-wrap;C:\Windows\System32\drivers\fsdk-wrap.sys [2015-11-13 417000]
R2 Intel® PROSet Monitoring Service;Intel® PROSet Monitoring Service;C:\Windows\System32\IPROSetMonitor.exe [2012-9-11 189608]
R2 MBAMService;Malwarebytes Service;C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe [2017-5-12 4470736]
R2 NVWMI;NVIDIA WMI Provider;C:\Windows\System32\nvwmi64.exe [2015-10-13 2693448]
R2 PaceLicenseDServices;PACE License Services;C:\Program Files (x86)\Common Files\PACE\Services\LicenseServices\LDSvc.exe [2015-8-10 19552672]
R2 pdfcDispatcher;PDF Document Manager;C:\Program Files (x86)\PDF Complete\pdfsvc.exe [2017-4-4 1719552]
R2 RtkAudioService;Realtek Audio Service;C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [2015-7-3 303360]
R2 SamsungRapidSvc;Samsung RAPID Mode Service;system32\RAPID\SamsungRapidSvc.exe --> system32\RAPID\SamsungRapidSvc.exe [?]
R2 Sentinel64;Sentinel64;C:\Windows\System32\drivers\sentinel64.sys [2013-6-14 145448]
R2 SentinelKeysServer;Sentinel Keys Server;C:\Program Files (x86)\Common Files\SafeNet Sentinel\Sentinel Keys Server\sntlkeyssrvr.exe [2013-1-9 376832]
R2 SentinelSecurityRuntime;Sentinel Security Runtime;C:\Program Files (x86)\Common Files\SafeNet Sentinel\Sentinel Security Runtime\sntlsrtsrvr.exe [2013-1-9 293216]
R2 sftlist;Application Virtualization Client;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2014-10-8 534184]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvscpapisvr.exe [2016-9-8 424384]
R2 UltraMonUtility;UltraMon Utility Driver;C:\Program Files (x86)\Common Files\Realtime Soft\UltraMonMirrorDrv\x64\UltraMonUtility.sys [2012-8-24 20512]
R2 UNS;Intel® Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2012-9-11 2656536]
R2 WskTrans;WskTrans;C:\Windows\System32\drivers\WskTrans.sys [2015-11-13 34024]
R2 WTabletServicePro;Wacom Professional Service;C:\Program Files\Tablet\Wacom\WTabletServicePro.exe [2017-5-15 675272]
R2 ZAMSvc;ZAM Controller Service;C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe [2017-7-3 15546512]
R3 bomebus;Bome's Virtual MIDI Port Bus Service;C:\Windows\System32\drivers\bomebus.sys [2015-3-3 34376]
R3 MBAMSwissArmy;MBAMSwissArmy;C:\Windows\System32\drivers\MBAMSwissArmy.sys [2014-10-22 252832]
R3 NisDrv;Microsoft Network Inspection System;C:\Windows\System32\drivers\NisDrvWFP.sys [2014-7-17 135928]
R3 NisSrv;Microsoft Network Inspection;C:\Program Files\Microsoft Security Client\NisSrv.exe [2016-11-14 361816]
R3 NTV2_64;NTV2_64;C:\Windows\System32\drivers\ntv2_64.sys [2015-11-5 160024]
R3 Sftfs;Sftfs;C:\Windows\System32\drivers\Sftfslh.sys [2014-10-8 766632]
R3 Sftplay;Sftplay;C:\Windows\System32\drivers\Sftplaylh.sys [2014-10-8 273576]
R3 Sftredir;Sftredir;C:\Windows\System32\drivers\Sftredirlh.sys [2014-10-8 29352]
R3 Sftvol;Sftvol;C:\Windows\System32\drivers\Sftvollh.sys [2014-10-8 23208]
R3 sftvsa;Application Virtualization Service Agent;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2014-10-8 211104]
R3 SNTUSB64;SafeNet USB SuperPro/UltraPro/HardwareKey;C:\Windows\System32\drivers\SNTUSB64.SYS [2012-12-11 63568]
R3 tihub3;TI USB3 Hub Service;C:\Windows\System32\drivers\tihub3.sys [2012-5-2 136512]
R3 tixhci;TI XHCI Service;C:\Windows\System32\drivers\tixhci.sys [2012-5-2 413504]
R3 USA19H;USA19H;C:\Windows\System32\drivers\USA19Hx64.sys [2013-7-1 740096]
R3 USA19HP;USA19HP;C:\Windows\System32\drivers\USA19Hx64p.sys [2013-7-1 35840]
R3 WacHidRouterPro;Wacom Hid Router Pro;C:\Windows\System32\drivers\wachidrouter.sys [2017-5-15 122512]
R3 wacomrouterfilter;Wacom Router Filter Driver;C:\Windows\System32\drivers\wacomrouterfilter.sys [2017-5-15 24040]
R3 WsAudio_Device;WsAudio_Device;C:\Windows\System32\drivers\VirtualAudio.sys [2015-11-20 31080]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2017-3-26 105096]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2017-3-26 125064]
S3 AdAppMgrSvc;Autodesk Desktop App Service;C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AdAppMgrSvc.exe [2017-5-8 1309176]
S3 Avid DMF Service;Avid DMF Service;C:\Program Files\Avid\Editor Transcode\Dynamic Media Files\DMFService.exe [2016-9-1 661768]
S3 Avid Editor Transcode Service;Avid Editor Transcode;C:\Program Files\Avid\Editor Transcode\TranscodeService\AvidEditorTranscode.exe [2016-9-1 662280]
S3 bomemidi;Bome's Virtual MIDI Port;C:\Windows\System32\drivers\bomemidi.sys [2015-3-3 30792]
S3 dmvsc;dmvsc;C:\Windows\System32\drivers\dmvsc.sys [2010-11-21 71168]
S3 FlexNet Licensing Service 64;FlexNet Licensing Service 64;C:\Program Files\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService64.exe [2017-5-8 1591264]
S3 hidkmdf;KMDF Driver;C:\Windows\System32\drivers\hidkmdf.sys [2015-4-21 13776]
S3 hitmanpro37;HitmanPro 3.7 Support Driver;C:\Windows\System32\drivers\hitmanpro37.sys [2015-4-10 43664]
S3 IEEtwCollectorService;Internet Explorer ETW Collector Service;C:\Windows\System32\ieetwcollector.exe [2017-6-13 116224]
S3 IFCoEMP;IFCoEMP;C:\Windows\System32\drivers\ifM60x64.sys [2012-3-9 348944]
S3 IFCoEVB;IFCoEVB;C:\Windows\System32\drivers\ifP60x64.sys [2012-3-9 70928]
S3 MBAMWebProtection;MBAMWebProtection;C:\Windows\System32\drivers\mwac.sys [2017-5-12 84256]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys [2014-10-14 19456]
S3 SIVDriver;SIV Kernel Driver;C:\Windows\System32\drivers\SIVX64.sys [2017-6-22 171664]
S3 StorSvc;Storage Service;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-13 27136]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2014-10-14 56832]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2014-10-14 30208]
S3 WacHidRouter;Wacom Hid Router;C:\Windows\System32\drivers\wachidrouter.sys [2017-5-15 122512]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2012-9-24 1255736]
S3 Xena2_64;Xena2_64;C:\Windows\System32\drivers\Kona3_64.sys [2012-9-10 308480]
.
=============== File Associations ===============
.
FileExt: .txt: Applications\notepad++.exe="C:\Program Files (x86)\Notepad++\notepad++.exe" "%1" [UserChoice]
.
=============== Created Last 30 ================
.
2017-07-05 15:12:12 -------- d--h--w- C:\OneDriveTemp
2017-07-05 15:11:02 44928 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{1E6E9F38-450D-463B-8200-50E1C8FED5A9}\MpKsl2da25a2b.sys
2017-07-05 15:00:46 -------- d-----w- C:\Users\editor\AppData\Local\Tempzxpsign7c83395fc1fd24fa
2017-07-05 15:00:40 -------- d-----w- C:\Users\editor\AppData\Local\Tempzxpsign81646452ea9fa4c8
2017-07-05 14:57:11 13120896 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{1E6E9F38-450D-463B-8200-50E1C8FED5A9}\mpengine.dll
2017-07-04 23:24:35 13120896 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2017-07-03 22:12:04 203680 ----a-w- C:\Windows\System32\drivers\zamguard64.sys
2017-07-03 22:12:04 203680 ----a-w- C:\Windows\System32\drivers\zam64.sys
2017-07-03 22:12:00 -------- d-----w- C:\Program Files (x86)\Zemana AntiMalware
2017-07-03 22:11:50 -------- d-----w- C:\Users\editor\AppData\Local\Zemana
2017-06-29 22:18:55 -------- d-----w- C:\OMFI MediaFiles
2017-06-29 21:52:23 -------- d-----w- C:\Users\editor\AppData\Local\Tempzxpsignfcf0406f42433c16
2017-06-29 21:45:59 -------- d-----w- C:\Users\editor\AppData\Local\Tempzxpsigna2dc30cfb3e36c82
2017-06-28 22:32:03 -------- d-----w- C:\Users\editor\AppData\Local\Tempzxpsignd8c7a391d8bde7cf
2017-06-28 22:32:03 -------- d-----w- C:\Users\editor\AppData\Local\Tempzxpsign82f4209082d28e87
2017-06-28 18:10:12 -------- d-----w- C:\Users\editor\AppData\Local\Tempzxpsign4c8b9d2c26409d6c
2017-06-28 18:00:22 -------- d-----w- C:\Users\editor\AppData\Local\Tempzxpsign2620624ac41a9c29
2017-06-28 17:55:17 -------- d-----w- C:\Users\editor\AppData\Local\Tempzxpsign1050c69c2f1e1551
2017-06-28 17:55:06 -------- d-----w- C:\Users\editor\AppData\Local\Tempzxpsign92351176f4a0c25d
2017-06-28 16:26:14 -------- d-----w- C:\Users\editor\AppData\Local\Tempzxpsignbd1562b69a2cbba1
2017-06-28 16:26:05 -------- d-----w- C:\Users\editor\AppData\Local\Tempzxpsign56c4b069f8611556
2017-06-28 16:08:00 -------- d-----w- C:\Users\editor\AppData\Local\Tempzxpsign59c736854248e7d5
2017-06-28 16:07:46 -------- d-----w- C:\Users\editor\AppData\Local\Tempzxpsign873d7f0aa6448692
2017-06-28 16:07:18 -------- d-----w- C:\Users\editor\AppData\Local\Tempzxpsign402db1a6a9d0239a
2017-06-28 16:06:30 -------- d-----w- C:\Users\editor\AppData\Local\Tempzxpsign798b4bcae726990d
2017-06-28 15:46:39 -------- d-----w- C:\Users\editor\AppData\Local\Tempzxpsigna14579408789d71e
2017-06-28 15:46:24 -------- d-----w- C:\Users\editor\AppData\Local\Tempzxpsignaa6d4e8c808ab4aa
2017-06-28 04:27:27 -------- d-----w- C:\Users\editor\AppData\Local\Tempzxpsignecaa014faa7033f9
2017-06-28 04:27:16 -------- d-----w- C:\Users\editor\AppData\Local\Tempzxpsign1fb67cc458f9bb49
2017-06-28 02:58:02 -------- d-----w- C:\Users\editor\AppData\Local\ESET
2017-06-28 02:26:31 -------- d-----w- C:\Users\editor\AppData\Local\Tempzxpsign526aa6bb30139f35
2017-06-28 01:51:26 -------- d-----w- C:\Users\editor\AppData\Local\Tempzxpsign9ee2c53123c7e984
2017-06-28 01:51:26 -------- d-----w- C:\Users\editor\AppData\Local\Tempzxpsign57109ca7a64f7072
2017-06-28 00:35:11 -------- d-----w- C:\Users\editor\AppData\Local\ElevatedDiagnostics
2017-06-28 00:26:18 -------- d-----w- C:\Users\editor\AppData\Local\Tempzxpsignbe1402676d78233f
2017-06-27 17:07:26 7168 ----a-w- C:\Windows\System32\kbdgeoqw.dll
2017-06-27 17:07:26 7168 ----a-w- C:\Windows\System32\KBDAZEL.DLL
2017-06-27 17:07:26 6656 ----a-w- C:\Windows\SysWow64\kbdgeoqw.dll
2017-06-27 17:07:26 6656 ----a-w- C:\Windows\SysWow64\KBDAZEL.DLL
2017-06-27 14:24:08 -------- d-----w- C:\c762d7dd37c4f912b273435ccac836f9
2017-06-27 14:23:02 110144 ----a-w- C:\Windows\System32\WindowsAccessBridge-64.dll
2017-06-27 14:22:50 -------- d-----w- C:\ProgramData\Oracle
2017-06-27 04:13:48 -------- d-sh--w- C:\$RECYCLE.BIN
2017-06-27 03:43:53 -------- d-----w- C:\ProgramData\Sophos
2017-06-27 00:03:25 -------- d-----w- C:\FRST
2017-06-26 15:15:17 272792 ----a-w- C:\Windows\System32\drivers\SamsungRapidDiskFltr.sys
2017-06-26 15:15:16 -------- d-----w- C:\Windows\System32\RAPID
2017-06-23 20:43:21 -------- d-----w- C:\Users\editor\AppData\Local\Tempzxpsign59df863cd635d885
2017-06-23 19:50:52 -------- d-----w- C:\Users\editor\AppData\Local\Tempzxpsign52e3c77a20748e79
2017-06-23 19:50:35 -------- d-----w- C:\Users\editor\AppData\Local\Tempzxpsign8d8121701ba66570
2017-06-23 18:40:42 -------- d-----w- C:\Users\editor\AppData\Local\Tempzxpsign9166cc43c6cb6144
2017-06-23 18:19:53 -------- d-----w- C:\Users\editor\AppData\Local\Tempzxpsign46564856646d2f2f
2017-06-23 18:18:38 -------- d-----w- C:\Users\editor\AppData\Local\Tempzxpsign1a94ce88808d4a7b
2017-06-23 16:45:43 -------- d-----w- C:\Users\editor\AppData\Local\Tempzxpsign7804bb806808d832
2017-06-23 16:45:30 -------- d-----w- C:\Users\editor\AppData\Local\Tempzxpsignb8037e97948ee1a6
2017-06-23 16:44:47 -------- d-----w- C:\Users\editor\AppData\Local\Tempzxpsigne08c37701e2a0ee4
2017-06-23 16:43:59 -------- d-----w- C:\Users\editor\AppData\Local\Tempzxpsign580f3bea265f8649
2017-06-23 15:51:56 28272 ----a-w- C:\Windows\System32\drivers\TrueSight.sys
2017-06-23 15:51:10 -------- d-----w- C:\ProgramData\RogueKiller
2017-06-23 15:51:02 -------- d-----w- C:\Program Files\RogueKiller
2017-06-23 15:29:17 -------- d-----w- C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2017-06-23 01:59:02 -------- d-----w- C:\TDSSKiller_Quarantine
2017-06-23 01:55:02 171664 ----a-w- C:\Windows\System32\drivers\SIVX64.sys
2017-06-23 01:41:46 -------- d-----w- C:\Logs
2017-06-22 23:32:50 -------- d-----w- C:\Users\editor\AppData\Local\Tempzxpsigne31135abea56a536
2017-06-22 23:32:29 -------- d-----w- C:\Users\editor\AppData\Local\Tempzxpsign2437faf4446c147c
2017-06-22 20:51:04 -------- d-----w- C:\Users\editor\AppData\Local\Tempzxpsign096855595bc7753f
2017-06-22 20:50:26 -------- d-----w- C:\Users\editor\AppData\Local\Tempzxpsign2a8de0a70e9934da
2017-06-22 18:31:55 5528064 ----a-w- C:\Windows\System32\Noesis.dll
2017-06-22 18:31:55 15353856 ----a-w- C:\Windows\System32\UniChooser.dll
2017-06-22 18:31:54 13179904 ----a-w- C:\Windows\System32\Gpu_Shader_Engine_x64.dll
2017-06-22 18:31:46 -------- d-----w- C:\Program Files\Red Giant
2017-06-22 16:03:32 -------- d-----w- C:\Users\editor\AppData\Local\Tempzxpsign3118c32baeebc941
2017-06-22 16:02:20 -------- d-----w- C:\Users\editor\AppData\Local\Tempzxpsign698bbaaed98fc862
2017-06-19 21:39:38 -------- d-----w- C:\Users\editor\AppData\Local\Tempzxpsign7fff0c43db9851b3
2017-06-19 21:38:44 -------- d-----w- C:\Users\editor\AppData\Local\Tempzxpsign39bf399261bc6fd2
2017-06-19 21:37:07 -------- d-----w- C:\Users\editor\AppData\Local\Tempzxpsign7acb5c62f5b628d3
2017-06-19 21:26:36 -------- d-----w- C:\Users\editor\AppData\Local\Tempzxpsign1e86a872dea4c587
2017-06-19 21:26:19 -------- d-----w- C:\Users\editor\AppData\Local\Tempzxpsign42389bfcb5552074
2017-06-16 18:54:33 -------- d-----w- C:\Users\editor\AppData\Local\Tempzxpsign74b22a34557fd6a6
2017-06-16 18:52:43 -------- d-----w- C:\Users\editor\AppData\Local\Tempzxpsigncad245026e30a186
2017-06-16 18:52:43 -------- d-----w- C:\Users\editor\AppData\Local\Tempzxpsign5c962276e3fa74ab
2017-06-14 23:47:46 -------- d-----w- C:\Users\editor\AppData\Local\Tempzxpsign4f1768933266bbd0
2017-06-14 23:32:02 -------- d-----w- C:\Users\editor\AppData\Local\Tempzxpsigncf9ed271a4570a7f
2017-06-14 23:32:01 -------- d-----w- C:\Users\editor\AppData\Local\Tempzxpsign3a81c8a21e40e00c
2017-06-13 20:36:34 -------- d-----w- C:\Users\editor\AppData\Local\RzStats
2017-06-13 20:32:06 -------- d-----w- C:\Users\editor\AppData\Local\Razer
2017-06-10 17:06:34 1078240 ----a-w- C:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{D1064B32-DBD8-457E-A57A-47EBB43B959A}\gapaengine.dll
2017-06-10 16:32:12 207048 ----a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
2017-06-08 22:43:25 -------- d-----w- C:\Users\editor\AppData\Local\Tempzxpsign8188b830f2e1781d
2017-06-08 22:43:12 -------- d-----w- C:\Users\editor\AppData\Local\Tempzxpsign311dc0be15a4e8e5
2017-06-08 15:00:44 -------- d-----w- C:\Users\editor\AppData\Local\Tempzxpsigna7c314ae638759b9
2017-06-08 15:00:29 -------- d-----w- C:\Users\editor\AppData\Local\Tempzxpsign2fb759c9a750f030
2017-06-07 21:25:16 -------- d-----w- C:\Users\editor\AppData\Local\Tempzxpsigndb08791fe2be7fb7
2017-06-07 21:25:02 -------- d-----w- C:\Users\editor\AppData\Local\Tempzxpsign5120056e2d3f6cf7
2017-06-06 23:38:22 -------- d-----w- C:\Users\editor\AppData\Local\Tempzxpsignb8bd1562439c1688
2017-06-06 23:38:07 -------- d-----w- C:\Users\editor\AppData\Local\Tempzxpsign70bab4a592232106
2017-06-06 16:50:41 1804688 ----a-w- C:\Windows\System32\wdfcoinstaller01011.dll
2017-06-06 16:44:18 -------- d-----w- C:\Users\editor\AppData\Local\Tempzxpsign53ce6cdf44591021
2017-06-06 16:44:05 -------- d-----w- C:\Users\editor\AppData\Local\Tempzxpsign9d8c4ca872eb95de
2017-06-06 03:03:44 -------- d-----w- C:\Windows\IDOOYHNU
2017-06-05 21:04:58 -------- d-----w- C:\Users\editor\AppData\Local\Tempzxpsignf2951e3a4706ff43
2017-06-05 21:04:41 -------- d-----w- C:\Users\editor\AppData\Local\Tempzxpsignffec44d35fb075e6
.
==================== Find3M  ====================
.
2017-07-05 15:11:06 252832 ----a-w- C:\Windows\System32\drivers\MBAMSwissArmy.sys
2017-07-03 22:49:29 109272 ----a-w- C:\Windows\System32\drivers\MBAMChameleon.sys
2017-06-19 23:10:33 2724864 ----a-w- C:\Windows\System32\mshtml.tlb
2017-06-19 22:21:13 2724864 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2017-06-16 15:29:21 2319872 ----a-w- C:\Windows\System32\tquery.dll
2017-06-16 15:29:13 99840 ----a-w- C:\Windows\System32\mssprxy.dll
2017-06-16 15:29:13 778240 ----a-w- C:\Windows\System32\mssvp.dll
2017-06-16 15:29:13 75264 ----a-w- C:\Windows\System32\msscntrs.dll
2017-06-16 15:29:13 491520 ----a-w- C:\Windows\System32\mssph.dll
2017-06-16 15:29:13 288256 ----a-w- C:\Windows\System32\mssphtb.dll
2017-06-16 15:29:13 2222080 ----a-w- C:\Windows\System32\mssrch.dll
2017-06-16 15:29:13 14336 ----a-w- C:\Windows\System32\msshooks.dll
2017-06-16 15:29:13 115200 ----a-w- C:\Windows\System32\mssitlb.dll
2017-06-16 15:13:05 591872 ----a-w- C:\Windows\System32\SearchIndexer.exe
2017-06-16 15:12:51 249856 ----a-w- C:\Windows\System32\SearchProtocolHost.exe
2017-06-16 15:11:59 113664 ----a-w- C:\Windows\System32\SearchFilterHost.exe
2017-06-16 15:11:48 1549312 ----a-w- C:\Windows\SysWow64\tquery.dll
2017-06-16 15:11:40 666624 ----a-w- C:\Windows\SysWow64\mssvp.dll
2017-06-16 15:11:40 59392 ----a-w- C:\Windows\SysWow64\msscntrs.dll
2017-06-16 15:11:40 34816 ----a-w- C:\Windows\SysWow64\mssprxy.dll
2017-06-16 15:11:40 337408 ----a-w- C:\Windows\SysWow64\mssph.dll
2017-06-16 15:11:40 197120 ----a-w- C:\Windows\SysWow64\mssphtb.dll
2017-06-16 15:11:40 1400320 ----a-w- C:\Windows\SysWow64\mssrch.dll
2017-06-16 15:11:40 104448 ----a-w- C:\Windows\SysWow64\mssitlb.dll
2017-06-16 15:00:19 427520 ----a-w- C:\Windows\SysWow64\SearchIndexer.exe
2017-06-16 15:00:10 164352 ----a-w- C:\Windows\SysWow64\SearchProtocolHost.exe
2017-06-16 14:59:32 86528 ----a-w- C:\Windows\SysWow64\SearchFilterHost.exe
2017-06-16 14:59:18 9728 ----a-w- C:\Windows\SysWow64\msshooks.dll
2017-06-16 14:10:09 803328 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2017-06-16 14:10:09 144896 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2017-06-06 16:44:47 77376 ----a-w- C:\Windows\System32\drivers\mbae64.sys
2017-06-02 08:10:16 733696 ----a-w- C:\Windows\HelpPane.exe
2017-05-31 17:38:16 2275784 ----a-w- C:\Windows\System32\Wacom_Tablet.dll
2017-05-31 17:38:16 2268616 ----a-w- C:\Windows\System32\Wacom_Touch_Tablet.dll
2017-05-31 17:38:16 2174408 ----a-w- C:\Windows\System32\WacomMT.dll
2017-05-31 17:38:16 2112456 ----a-w- C:\Windows\System32\Wintab32.dll
2017-05-31 17:38:15 1781704 ----a-w- C:\Windows\SysWow64\Wacom_Touch_Tablet.dll
2017-05-31 17:38:15 1632712 ----a-w- C:\Windows\SysWow64\Wintab32.dll
2017-05-31 17:38:14 1788360 ----a-w- C:\Windows\SysWow64\Wacom_Tablet.dll
2017-05-31 17:38:14 1673160 ----a-w- C:\Windows\SysWow64\WacomMT.dll
2017-05-30 20:45:51 565416 ----a-w- C:\Windows\System32\MpSigStub.exe
2017-05-21 04:28:29 95464 ----a-w- C:\Windows\System32\drivers\ksecdd.sys
2017-05-21 04:28:29 154856 ----a-w- C:\Windows\System32\drivers\ksecpkg.sys
2017-05-21 04:06:34 96768 ----a-w- C:\Windows\SysWow64\sspicli.dll
2017-05-21 03:55:25 64000 ----a-w- C:\Windows\System32\auditpol.exe
2017-05-21 03:48:54 159744 ----a-w- C:\Windows\System32\drivers\mrxsmb.sys
2017-05-21 03:48:19 291328 ----a-w- C:\Windows\System32\drivers\mrxsmb10.sys
2017-05-21 03:48:17 129536 ----a-w- C:\Windows\System32\drivers\mrxsmb20.sys
2017-05-21 03:47:36 30720 ----a-w- C:\Windows\System32\lsass.exe
2017-05-21 03:46:34 50176 ----a-w- C:\Windows\SysWow64\auditpol.exe
2017-05-21 03:42:24 36352 ----a-w- C:\Windows\SysWow64\cryptbase.dll
2017-05-19 09:44:51 84256 ----a-w- C:\Windows\System32\drivers\mwac.sys
2017-05-16 15:35:16 986856 ----a-w- C:\Windows\System32\drivers\dxgkrnl.sys
2017-05-16 15:35:16 265448 ----a-w- C:\Windows\System32\drivers\dxgmms1.sys
2017-05-16 15:30:57 144384 ----a-w- C:\Windows\System32\cdd.dll
2017-05-16 15:30:56 309760 ----a-w- C:\Windows\apppatch\AppPatch64\AcGenral.dll
2017-05-16 15:12:23 2560 ----a-w- C:\Windows\apppatch\AcRes.dll
2017-05-16 15:12:23 2179072 ----a-w- C:\Windows\apppatch\AcGenral.dll
2017-05-15 15:29:41 113592 ----a-w- C:\Windows\System32\drivers\farflt.sys
2017-05-15 15:29:40 43968 ----a-w- C:\Windows\System32\drivers\mbam.sys
2017-05-14 20:46:38 4096 ----a-w- C:\Windows\System32\ieetwcollectorres.dll
2017-05-14 20:28:46 66560 ----a-w- C:\Windows\System32\iesetup.dll
2017-05-14 20:27:37 48640 ----a-w- C:\Windows\System32\ieetwproxystub.dll
2017-05-14 20:27:27 417792 ----a-w- C:\Windows\System32\html.iec
2017-05-14 20:27:02 88064 ----a-w- C:\Windows\System32\MshtmlDac.dll
2017-05-14 20:26:51 576512 ----a-w- C:\Windows\System32\vbscript.dll
2017-05-14 20:10:55 116224 ----a-w- C:\Windows\System32\ieetwcollector.exe
2017-05-14 20:10:54 144384 ----a-w- C:\Windows\System32\ieUnatt.exe
2017-05-14 20:10:34 814080 ----a-w- C:\Windows\System32\jscript9diag.dll
2017-05-14 20:01:39 968704 ----a-w- C:\Windows\System32\MsSpellCheckingFacility.exe
2017-05-14 19:55:35 5975040 ----a-w- C:\Windows\System32\jscript9.dll
2017-05-14 19:48:14 77824 ----a-w- C:\Windows\System32\JavaScriptCollectionAgent.dll
2017-05-14 19:47:32 87552 ----a-w- C:\Windows\System32\tdc.ocx
2017-05-14 19:23:12 62464 ----a-w- C:\Windows\SysWow64\iesetup.dll
2017-05-14 19:22:36 499200 ----a-w- C:\Windows\SysWow64\vbscript.dll
2017-05-14 19:22:26 47616 ----a-w- C:\Windows\SysWow64\ieetwproxystub.dll
2017-05-14 19:22:10 341504 ----a-w- C:\Windows\SysWow64\html.iec
2017-05-14 19:21:04 64000 ----a-w- C:\Windows\SysWow64\MshtmlDac.dll
2017-05-14 19:18:33 1359360 ----a-w- C:\Windows\System32\mshtmlmedia.dll
2017-05-14 19:17:59 2132992 ----a-w- C:\Windows\System32\inetcpl.cpl
2017-05-14 19:11:03 115712 ----a-w- C:\Windows\SysWow64\ieUnatt.exe
2017-05-14 19:10:43 620032 ----a-w- C:\Windows\SysWow64\jscript9diag.dll
2017-05-14 18:57:57 60416 ----a-w- C:\Windows\SysWow64\JavaScriptCollectionAgent.dll
2017-05-14 18:57:09 73216 ----a-w- C:\Windows\SysWow64\tdc.ocx
2017-05-14 18:52:12 3240960 ----a-w- C:\Windows\System32\wininet.dll
2017-05-14 18:44:07 4549120 ----a-w- C:\Windows\SysWow64\jscript9.dll
2017-05-14 18:39:09 2057216 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
2017-05-14 18:38:51 1155072 ----a-w- C:\Windows\SysWow64\mshtmlmedia.dll
2017-05-14 18:15:06 2767872 ----a-w- C:\Windows\SysWow64\wininet.dll
2017-05-12 18:27:25 631176 ----a-w- C:\Windows\System32\winresume.efi
2017-05-12 18:26:17 706792 ----a-w- C:\Windows\System32\winload.efi
2017-05-12 18:26:16 5547752 ----a-w- C:\Windows\System32\ntoskrnl.exe
2017-05-12 18:26:13 382696 ----a-w- C:\Windows\System32\atmfd.dll
2017-05-12 18:24:12 1732864 ----a-w- C:\Windows\System32\ntdll.dll
2017-05-12 18:07:05 4001000 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2017-05-12 18:07:05 3945704 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe
2017-05-12 18:07:02 308456 ----a-w- C:\Windows\SysWow64\atmfd.dll
2017-05-12 18:04:45 1314112 ----a-w- C:\Windows\SysWow64\ntdll.dll
2017-05-12 17:55:00 148480 ----a-w- C:\Windows\System32\appidpolicyconverter.exe
2017-05-12 17:54:55 17920 ----a-w- C:\Windows\System32\appidcertstorecheck.exe
.
============= FINISH: 14:13:27.84 ===============
 


BC AdBot (Login to Remove)

 


#2 Jo*

Jo*

  • Malware Response Team
  • 3,293 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Germany
  • Local time:12:14 AM

Posted 05 July 2017 - 02:27 PM

:welcome: to BleepingComputer.

Hi there,

my name is Jo and I will help you with your computer problems.


Please follow these guidelines:
  • Read and follow the instructions in the sequence they are posted.
  • print or copy & save instructions.
  • back up all your private data / music / important files on another (external) drive before using our tools.
  • Do not install / uninstall any applications, unless otherwise instructed.
  • Use only that tools you have been instructed to use.
  • Copy and Paste the log files inside your post, unless otherwise instructed.
  • Ask for clarification, if you have any questions.
  • Stay with this topic til you get the all clean post.
  • My first language is not english. So please do not use slang or idioms. It could be hard for me to read. Thanks for your understanding.

***


:step1: Please download Security Analysis by Rocket Grannie from here
  • Save it to your Desktop.
  • Close your security software to avoid potential conflicts.
  • Double click RGSA.exe
  • Click OK on the copyright-disclaimer
  • When finished, a Notepad window will open with the results of the scan.
  • The log named SALog.txt can also be found on the Desktop or in the same folder from where the tool is run if installed elsewhere.
  • Please copy and paste the contents of that log in this topic.
  • Note:
If you get a Warning from Windows about running the program, click on More info and then click Run Anyway to run it even though Windows says it might put your PC at risk.
 

***


:step2: Please download Malwarebytes Anti-Rootkit and save it to your desktop.
  • Be sure to print out and follow the instructions provided on that same page.
  • Caution: This is a beta version so please be sure to read the disclaimer and back up all your data before using.
  • Double click on downloaded file. OK self extracting prompt.
  • MBAR will start. Click in the introduction screen "next" to continue.
  • Click in the following screen "Update" to obtain the latest malware definitions.
  • Once the update is complete select "Next" and click "Scan".
With some infections, you may see two messages boxes.
  • 'Could not load protection driver'. Click 'OK'.
  • 'Could not load DDA driver'. Click 'Yes' to this message, to allow the driver to load after a restart. Allow the computer to restart. Continue with the rest of these instructions.
  • If malware is found - do not press the Clean up button, please go to the MBAR folder and then copy/paste the contents of the MBAR-log-***.txt file to your next reply.
  • If there is no malware found, please let me know as well.

***


:step3: Please download AdwCleaner by Xplode and save to your Desktop.
Double-click AdwCleaner.exe
Vista / Windows 7/8/10 users right-click and select Run As Administrator.
  • Click on the Scan button.
  • AdwCleaner will begin...be patient as the scan may take some time to complete.
  • After the scan has finished, click on the Logfile button...a logfile (AdwCleaner[R0].txt) will open in Notepad for review.
  • The contents of the log file may be confusing. Unless you see a program name that you know should not be removed, don't worry about it.
    If you see an entry you want to keep, let me know about it.
  • Copy and paste the contents of that logfile in your next reply.
  • A copy of all logfiles are saved in the C:\AdwCleaner folder which was created when running the tool.

***


:step4: Please download Farbar Recovery Scan Tool and save it to your Desktop.

Note: You need to run the version compatible with your system. If you are not sure which version applies to your system, download both of them and try to run them. Only one of them will run on your system, that will be the right version.
  • Right-click FRST then click "Run as administrator" (XP users: click run after receipt of Windows Security Warning - Open File).
  • When the tool opens, click Yes to disclaimer.
  • Press the Scan button.
  • When finished, it will produce a log called FRST.txt in the same directory the tool was run from.
  • Please copy and paste the log in your next reply.
Note 2: The first time the tool is run it generates another log (Addition.txt - also located in the same directory the tool was run from). Please also paste that, along with the FRST.txt into your next reply.

---

Graduate of the WTT Classroom
Cheers,
Jo
If I have been helping you, and I have not replied to your latest post in 36 hours please send me a PM.


#3 rm540

rm540
  • Topic Starter

  • Members
  • 13 posts
  • OFFLINE
  •  
  • Local time:06:14 PM

Posted 05 July 2017 - 03:05 PM

Hi Jo, thanks for your help. Please note I believe I have had an unauthorized user remoting into this machine, and removed a few viruses over time. I've since installed a hardware firewall. I am not sure where the other users came from - I, "editor" am the only user account created by myself and actively used. I believe some are legit and created by some of my software, but I am suspicious of the IUSR accounts. 
 
Result of Security Analysis by Rocket Grannie (x86) Updated: 28th June, 2017
Running from:C:\Users\editor\Downloads (15:31:52 - 07/05/2017)
***---------------------------------------------------------***
Microsoft Windows 7 Professional X64 Service Pack 1
UAC is Enabled
Internet Explorer 11
Default Browser: Google Chrome
***------------Antivirus - Antispyware - Firewall-----------***
Microsoft Security Essentials (Enabled - up to Date)
Microsoft Security Essentials (Enabled - up to Date)
Windows Defender (Disabled - Not up to Date)
Windows Firewall (Disabled)
No other Firewall Installed
***-------Security Programs - Browsers - Miscellaneous------***
Adobe Flash Player 26 NPAPI (26.0.0.131)
Adobe Flash Player 26 ActiveX (26.0.0.131)
Adobe Reader XI (11.0.03) ==> is out of Date
CCleaner (5.11) ==> is out of Date
Google Chrome (59.0.3071.115)
Java (1.6.0.60)
Malwarebytes (3.1.2.1733)
Microsoft Security Essentials (4.10.209.0)
Microsoft Silverlight (5.1.50907.0)
Mozilla Firefox (47.0.2) ==> is out of Date
 
***----------------Analysis Complete-------------------------***
 
 
 
 
 
 
 
 
 
 
 
 
 
# AdwCleaner v6.047 - Logfile created 05/07/2017 at 15:12:10
# Updated on 19/05/2017 by Malwarebytes
# Database : 2017-07-05.1 [Server]
# Operating System : Windows 7 Professional Service Pack 1 (X64)
# Username : editor - AVID4
# Running from : C:\Users\editor\Desktop\tron\resources\stage_9_manual_tools\AdwCleaner v6.0.4.7.exe
# Mode: Scan
 
 
 
***** [ Services ] *****
 
No malicious services found.
 
 
***** [ Folders ] *****
 
Folder Found:  C:\Users\editor\Desktop\Dig Deep
 
 
***** [ Files ] *****
 
File Found:  C:\Users\editor\Downloads\vcdrom.sys
 
 
***** [ DLL ] *****
 
No malicious DLLs found.
 
 
***** [ WMI ] *****
 
No malicious keys found.
 
 
***** [ Shortcuts ] *****
 
No infected shortcut found.
 
 
***** [ Scheduled Tasks ] *****
 
No malicious task found.
 
 
***** [ Registry ] *****
 
No malicious registry entries found.
 
 
***** [ Web browsers ] *****
 
No malicious Firefox based browser items found.
Chrome pref Found:  [C:\Users\editor\AppData\Local\Google\Chrome\User Data\Default\Web data] - ask.com
Chrome pref Found:  [C:\Users\editor\AppData\Local\Google\Chrome\User Data\Default\Web data] - aol.com
Chrome pref Found:  [C:\Users\IUSR_Servs\AppData\Local\Google\Chrome\User Data\Default\Web data] - aol.com
Chrome pref Found:  [C:\Users\IUSR_Servs\AppData\Local\Google\Chrome\User Data\Default\Web data] - ask.com
 
[!] You may need to disable the Chrome synchronization from your Google account in order to fully remove the malicious preferences. Please consult this Google help: https://support.google.com/chrome/answer/3097271?hl=en [!]
 
 
*************************
 
C:\AdwCleaner\AdwCleaner[S0].txt - [1696 Bytes] - [05/07/2017 15:12:10]
 
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [1769 Bytes] ##########
 
 
 
 
 
 
 
 
 
NOTE: I ran this the other day, but can run it again if you need a new one. 
 
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 25-06-2017 01
Ran by editor (administrator) on AVID4 (26-06-2017 20:03:37)
Running from C:\Users\editor\Downloads
Loaded Profiles: editor & Administrator (Available Profiles: user & editor & Default & IUSR_Servs & Administrator)
Platform: Windows 7 Professional Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
() C:\Windows\System32\nvwmi64.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvscpapisvr.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Wacom\WTabletServicePro.exe
(Autodesk Inc.) C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AdAppMgrSvc.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe
(Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
(AJA Video Systems, Inc.) C:\Program Files\AJA\windows\Applications\ajadaemon.exe
(Avid Technology, Inc.) C:\Program Files\Avid\Editor Transcode\TranscodeService\AvidEditorDbEngine.exe
(Avid Technology, Inc.) C:\Program Files\Avid\Editor Transcode\TranscodeService\AvidEditorDbEngine.exe
(Avid Technology, Inc.) C:\Program Files\Avid\Editor Transcode\TranscodeService\rnc-central\AvidEditorTranscodeStatus.exe
(Avid Technology, Inc.) C:\Program Files\Avid\Editor Transcode\TranscodeService\rnc-central\AvidEditorTranscodeStatus.exe
(Avid) C:\Program Files\Avid\ISIS Client\Utilities\Benchmark Utility\BenchmarkAgent.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe
() C:\Program Files\Telestream\Episode 7\bin\tseas.exe
() C:\Windows\System32\nvwmi64.exe
() C:\Program Files\Telestream\Episode 7\bin\tsecps.exe
() C:\Program Files\Telestream\Episode 7\bin\tseioss.exe
() C:\Program Files\Telestream\Episode 7\bin\tsejrs.exe
() C:\Program Files\Telestream\Episode 7\bin\tsens.exe
() C:\Program Files\Telestream\Episode 7\bin\tsexrs.exe
(Intel Corporation) C:\Windows\System32\IPROSetMonitor.exe
(PACE Anti-Piracy, Inc.) C:\Program Files (x86)\Common Files\PACE\Services\LicenseServices\LDSvc.exe
() C:\Program Files\Telestream\Episode 7\bin\EpisodeClientProxy.exe
() C:\Program Files\Telestream\Episode 7\bin\EpisodeJSONRPCServer.exe
() C:\Program Files\Telestream\Episode 7\bin\EpisodeXMLRPCServer.exe
() C:\Program Files\Telestream\Episode 7\bin\EpisodeNode.exe
() C:\Program Files\Telestream\Episode 7\bin\EpisodeIOServer.exe
() C:\Program Files\Telestream\Episode 7\bin\EpisodeAssistant.exe
(PDF Complete Inc) C:\Program Files (x86)\PDF Complete\pdfsvc.exe
(Protexis Inc.) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
(Samsung Electronics Co., Ltd.) C:\Windows\System32\RAPID\SamsungRapidSvc.exe
(Microsoft Corporation) C:\Windows\System32\wisptis.exe
(SafeNet, Inc.) C:\Program Files (x86)\Common Files\SafeNet Sentinel\Sentinel Keys Server\sntlkeyssrvr.exe
(SafeNet, Inc) C:\Program Files (x86)\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe
(SafeNet, Inc.) C:\Program Files (x86)\Common Files\SafeNet Sentinel\Sentinel Security Runtime\sntlsrtsrvr.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(Avid Technology, Inc.) C:\Program Files\Avid\Editor Transcode\TranscodeService\AvidEditorMSE.exe
(Avid Technology, Inc.) C:\Program Files\Avid\Editor Transcode\TranscodeService\AvidEditorMSE.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Microsoft Corporation) C:\Windows\System32\wisptis.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Wacom\Wacom_TabletUser.exe
(Wacom Technology) C:\Program Files\Tablet\Wacom\WacomHost.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Wacom\Wacom_TouchUser.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Hewlett-Packard) C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe
(Microsoft Corporation) C:\Program Files\Microsoft Device Center\itype.exe
(Microsoft Corporation) C:\Program Files\Microsoft Device Center\ipoint.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\RAPID\CacheFilter\SamsungRapidApp.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe
(Adobe Systems Inc.) C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\acrotray.exe
(Autodesk, Inc.) C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AutodeskDesktopApp.exe
(Avid Technology, Inc.) C:\Program Files\Avid\Application Manager\AvidApplicationManager.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe
(Autodesk) C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AcWebBrowser\acwebbrowser.exe
(Avid Technology, Inc.) C:\Program Files\Avid\Avid Media Composer\AvidBackgroundServicesManager.exe
(Slack Technologies) C:\Users\editor\AppData\Local\slack\app-2.6.3\slack.exe
(Avid) C:\Program Files\Avid\ISIS Client\Client Manager\ISISClientManager.exe
(Realtime Soft Ltd) C:\Program Files\UltraMon\UltraMon.exe
(Autodesk) C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AcWebBrowser\acwebbrowser.exe
(Realtime Soft Ltd) C:\Program Files\UltraMon\UltraMonTaskbar.exe
(Autodesk) C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AcWebBrowser\acwebbrowser.exe
(Slack Technologies) C:\Users\editor\AppData\Local\slack\app-2.6.3\slack.exe
(Realtime Soft Ltd) C:\Program Files (x86)\Common Files\Realtime Soft\RTSHookInterop\x32\RTSHookInterop.exe
(Slack Technologies) C:\Users\editor\AppData\Local\slack\app-2.6.3\slack.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ADS\Adobe Desktop Service.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\HEX\Adobe CEF Helper.exe
(Slack Technologies) C:\Users\editor\AppData\Local\slack\app-2.6.3\slack.exe
() C:\Program Files\Avid\Application Manager\QtWebEngineProcess.exe
(Avid Technology, Inc.) C:\Program Files\Avid\Application Manager\AvidAppManHelper.exe
(Slack Technologies) C:\Users\editor\AppData\Local\slack\app-2.6.3\slack.exe
() C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\CCXProcess.exe
(Node.js) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\libs\node.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\CCLibrary.exe
(Node.js) C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\libs\node.exe
(Samsung Electronics Co. Ltd.) C:\Program Files (x86)\Samsung\Samsung Magician\SamsungMagician.exe
(Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\IMSS\PrivacyIconClient.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
(InterVideo) C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe
(Tweaking.com) C:\Program Files (x86)\Tweaking.com\Windows Repair (All in One)\WR_Tray_Icon.exe
(Realtime Soft Ltd) C:\Program Files\UltraMon\UltraMonUiAcc.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome Remote Desktop\59.0.3071.47\remoting_host.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome Remote Desktop\59.0.3071.47\remoting_host.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbam.exe
(Realtime Soft Ltd) C:\Program Files (x86)\Common Files\Realtime Soft\RTSHookInterop\x32\RTSHookInterop.exe
(Adobe Systems Incorporated) C:\Program Files\Adobe\Adobe InDesign CC 2017\InDesign.exe
(Adobe Systems Incorporated) C:\Program Files\Adobe\Adobe InDesign CC 2017\Resources\CEP\CEPHtmlEngine\CEPHtmlEngine.exe
(Adobe Systems Incorporated) C:\Program Files\Adobe\Adobe InDesign CC 2017\Resources\CEP\CEPHtmlEngine\CEPHtmlEngine.exe
(Adobe Systems Incorporated) C:\Program Files\Adobe\Adobe InDesign CC 2017\Resources\CEP\CEPHtmlEngine\CEPHtmlEngine.exe
(Adobe Systems Incorporated) C:\Program Files\Adobe\Adobe InDesign CC 2017\Resources\CEP\CEPHtmlEngine\CEPHtmlEngine.exe
(Adobe Systems Incorporated) C:\Program Files\Adobe\Adobe InDesign CC 2017\Resources\CEP\CEPHtmlEngine\CEPHtmlEngine.exe
(Adobe Systems Incorporated) C:\Program Files\Adobe\Adobe InDesign CC 2017\Resources\CEP\CEPHtmlEngine\CEPHtmlEngine.exe
(Adobe Systems Incorporated) C:\Program Files\Adobe\Adobe InDesign CC 2017\Resources\CEP\CEPHtmlEngine\CEPHtmlEngine.exe
(Adobe Systems Incorporated) C:\Program Files\Adobe\Adobe InDesign CC 2017\Resources\CEP\CEPHtmlEngine\CEPHtmlEngine.exe
(Adobe Systems Incorporated) C:\Program Files\Adobe\Adobe InDesign CC 2017\Resources\CEP\CEPHtmlEngine\CEPHtmlEngine.exe
(Microsoft Corporation) C:\Windows\System32\prevhost.exe
(Microsoft Corporation) C:\Windows\SysWOW64\prevhost.exe
(Microsoft Corporation) C:\Windows\System32\taskmgr.exe
(Microsoft Corporation) C:\Windows\System32\cmd.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
 
==================== Registry (Whitelisted) ====================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12681320 2011-09-06] (Realtek Semiconductor)
HKLM\...\Run: [HPSYSDRV] => C:\Program Files (x86)\Hewlett-Packard\HP Odometer\HPSYSDRV.EXE [62768 2008-11-20] (Hewlett-Packard)
HKLM\...\Run: [IntelliType Pro] => c:\Program Files\Microsoft Device Center\itype.exe [1464928 2012-06-26] (Microsoft Corporation)
HKLM\...\Run: [IntelliPoint] => c:\Program Files\Microsoft Device Center\ipoint.exe [2004584 2012-06-26] (Microsoft Corporation)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [508128 2016-07-01] (Adobe Systems Incorporated)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1353680 2016-11-14] (Microsoft Corporation)
HKLM\...\Run: [nwiz] => C:\Program Files\NVIDIA Corporation\nview\nwiz.exe [2098232 2016-08-25] ()
HKLM\...\Run: [Malwarebytes TrayApp] => C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe [3146704 2017-05-09] (Malwarebytes)
HKLM\...\Run: [SamsungRapidApp] => C:\Program Files (x86)\Samsung\RAPID\CacheFilter\SamsungRapidApp.exe [123800 2016-11-18] (Samsung Electronics Co., Ltd.)
HKLM-x32\...\Run: [IMSS] => C:\Program Files (x86)\Intel\Intel® Management Engine Components\IMSS\PIconStartup.exe [112408 2011-11-30] (Intel Corporation)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.)
HKLM-x32\...\Run: [Adobe Creative Cloud] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2406496 2017-06-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2015-08-06] (Apple Inc.)
HKLM-x32\...\Run: [iSkysoft Helper Compact.exe] => C:\Program Files (x86)\Common Files\iSkysoft\iSkysoft Helper Compact\ISHelper.exe [2131856 2016-06-20] (iSkySoft)
HKLM-x32\...\Run: [DelaypluginInstall] => C:\ProgramData\iSkysoft\iTube Studio\DelayPluginI.exe [1960288 2014-09-19] ()
HKLM-x32\...\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Acrotray.exe [1870928 2017-04-04] (Adobe Systems Inc.)
HKLM-x32\...\Run: [PDF Complete] => C:\Program Files (x86)\PDF Complete\pdfsty.exe [1193728 2017-02-15] (PDF Complete Inc)
HKLM-x32\...\Run: [Autodesk Desktop App] => C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AutodeskDesktopApp.exe [704424 2017-03-10] (Autodesk, Inc.)
HKU\S-1-5-21-3225783554-34173836-2973484787-1001\...\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-3225783554-34173836-2973484787-1001\...\Run: [Adobe Acrobat Synchronizer] => C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe [886352 2017-04-04] (Adobe Systems Incorporated)
HKU\S-1-5-21-3225783554-34173836-2973484787-1001\...\Run: [com.squirrel.slack.slack] => "C:\Users\editor\AppData\Local\slack\Update.exe" --processStart "slack.exe" --process-start-args "--startup"
HKU\S-1-5-21-3225783554-34173836-2973484787-1001\...\Run: [Akamai NetSession Interface] => "C:\Users\editor\AppData\Local\Akamai\netsession_win.exe"
IFEO\Magnify.exe: [Debugger] cmd.exe
IFEO\sethc.exe: [Debugger] C:\Windows\vpnplugins\servicing\ibhost.exe
ShellIconOverlayIdentifiers: [ AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2017-05-26] ()
ShellIconOverlayIdentifiers: [ AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2017-05-26] ()
ShellIconOverlayIdentifiers: [ AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2017-05-26] ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Aja Firmware Updater.lnk [2015-11-16]
ShortcutTarget: Aja Firmware Updater.lnk -> C:\Program Files\AJA\windows\Firmware\ajaflash.exe ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Avid Application Manager.lnk [2016-12-22]
ShortcutTarget: Avid Application Manager.lnk -> C:\Windows\Installer\{99E377DB-D2D0-44A5-8533-AA8BE1381644}\NewShortcut1_E1E0FF1FC1474601A40EFEF248F11D43.exe (Flexera Software LLC)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Avid Background Services Manager.lnk [2016-12-23]
ShortcutTarget: Avid Background Services Manager.lnk -> C:\Windows\Installer\{95EB1E9C-F759-4427-8EEE-F96C48541A06}\NewShortcut1_4CE83F107C544E87A6F35E0E551E78CA.exe (Flexera Software LLC)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ISIS Client Manager.lnk [2015-12-08]
ShortcutTarget: ISIS Client Manager.lnk -> C:\Program Files\Avid\ISIS Client\Client Manager\ISISClientManager.exe (Avid)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\UltraMon.lnk [2015-07-23]
ShortcutTarget: UltraMon.lnk -> C:\Windows\Installer\{D4E62D29-31A1-4938-8CB7-7D275C1AEAC6}\IcoUltraMon.ico ()
GroupPolicy: Restriction <==== ATTENTION
GroupPolicy\User: Restriction <==== ATTENTION
GroupPolicyScripts: Restriction <==== ATTENTION
GroupPolicyScripts\User: Restriction <==== ATTENTION
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Winsock: Catalog5 08 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL => No File 
Winsock: Catalog5 09 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL => No File 
Winsock: Catalog5-x64 08 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL => No File 
Winsock: Catalog5-x64 09 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL => No File 
Tcpip\Parameters: [DhcpNameServer] 209.18.47.62 209.18.47.61
Tcpip\..\Interfaces\{0C06085B-51F9-4B6A-8F35-4A6E4F6EB3FC}: [DhcpNameServer] 209.18.47.62 209.18.47.61
Tcpip\..\Interfaces\{AF626FD6-E522-47E2-83CE-48AD0E00D527}: [NameServer] 223.5.5.5,8.8.8.8
 
Internet Explorer:
==================
HKU\S-1-5-21-3225783554-34173836-2973484787-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.msn.com/HPCOM/19
HKU\S-1-5-21-3225783554-34173836-2973484787-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.msn.com/HPCOM/19
HKU\S-1-5-21-3225783554-34173836-2973484787-500\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.msn.com/HPCOM/19
HKU\S-1-5-21-3225783554-34173836-2973484787-500\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.msn.com/HPCOM/19
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-3225783554-34173836-2973484787-500 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=CMDTDF&pc=CMDTDF&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-3225783554-34173836-2973484787-500 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=CMDTDF&pc=CMDTDF&src=IE-SearchBox
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2017-06-18] (Microsoft Corporation)
BHO: Adobe Acrobat Create PDF Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\x64\AcroIEFavStub.dll [2016-12-23] (Adobe Systems Incorporated)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\URLREDIR.DLL [2017-06-18] (Microsoft Corporation)
BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL [2017-06-18] (Microsoft Corporation)
BHO: Adobe Acrobat Create PDF from Selection -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\x64\AcroIEFavStub.dll [2016-12-23] (Adobe Systems Incorporated)
BHO-x32: iSkysoft iTube Studio 4.2.0 -> {1A6B6AD0-2735-498F-834C-AFCEA37847C2} -> C:\ProgramData\iSkysoft\iTube Studio\WSBrowserAppMgr.dll [2014-09-19] (Wondershare)
BHO-x32: Adobe Acrobat Create PDF Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll [2016-12-23] (Adobe Systems Incorporated)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\root\Office16\URLREDIR.DLL [2017-06-18] (Microsoft Corporation)
BHO-x32: Adobe Acrobat Create PDF from Selection -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll [2016-12-23] (Adobe Systems Incorporated)
Toolbar: HKLM - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\x64\AcroIEFavStub.dll [2016-12-23] (Adobe Systems Incorporated)
Toolbar: HKLM-x32 - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll [2016-12-23] (Adobe Systems Incorporated)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-06-18] (Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-06-18] (Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-06-18] (Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-06-18] (Microsoft Corporation)
Handler: WSISAllmytubechrome - {4724F5AF-4E6D-41CA -  No File
 
FireFox:
========
FF DefaultProfile: p0snnc5x.default
FF ProfilePath: C:\Users\editor\AppData\Roaming\Mozilla\Firefox\Profiles\p0snnc5x.default [2017-06-20]
FF Extension: (Youtube Unblocker Remediation) - C:\Users\editor\AppData\Roaming\Mozilla\Firefox\Profiles\p0snnc5x.default\features\{24a06145-a6d5-4e79-a30d-3b00074039bf}\malware-remediation@mozilla.org.xpi [2017-06-12]
FF HKLM-x32\...\Firefox\Extensions: [ISAllmytube@iSkysoft.com] - C:\ProgramData\iSkysoft\iTube Studio\ISAllmytube@iSkysoft.com
FF Extension: (iSkysoft iTube Studio) - C:\ProgramData\iSkysoft\iTube Studio\ISAllmytube@iSkysoft.com [2015-11-24] [not signed]
FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension.15@web2pdf.adobedotcom] - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn
FF Extension: (Adobe Acrobat DC - Create PDF) - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn [2017-04-13]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_26_0_0_131.dll [2017-06-16] ()
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @wacom.com/wtPlugin,version=2.1.0.7 -> C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll [2014-03-25] (Wacom)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2017-06-04] (Adobe Systems)
FF Plugin: wacom.com/WacomTabletPlugin -> C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll [2014-03-25] (Wacom)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_26_0_0_131.dll [2017-06-16] ()
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2017-05-26] (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2016-08-25] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2016-08-25] (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-27] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-27] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin-x32: @wacom.com/wtPlugin,version=2.1.0.7 -> C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll [2014-03-25] (Wacom)
FF Plugin-x32: Adobe Acrobat -> C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2017-04-04] (Adobe Systems Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2013-05-11] (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2017-06-04] (Adobe Systems)
FF Plugin-x32: wacom.com/WacomTabletPlugin -> C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll [2014-03-25] (Wacom)
FF Plugin HKU\S-1-5-21-3225783554-34173836-2973484787-1001: @asperasoft.com/AsperaConnect -> C:\Users\editor\AppData\Local\Programs\Aspera\Aspera Connect\lib\3.6.1\npasperaweb_3.6.1.111228.dll [2015-09-11] (Aspera, Inc. )
FF Plugin HKU\S-1-5-21-3225783554-34173836-2973484787-1001: signiant.com/SigniantTransfer -> C:\Users\editor\AppData\Roaming\SigniantInc\SigniantTransfer\5.4.3.70626\npSigniantTransfer.dll [2015-05-08] (Signiant Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\browser\plugins\npatgpc.dll [2016-06-16] (Cisco WebEx LLC)
FF Plugin ProgramFiles/Appdata: C:\Users\editor\AppData\Roaming\mozilla\plugins\npatgpc.dll [2016-06-16] (Cisco WebEx LLC)
 
Chrome: 
=======
CHR DefaultProfile: Default
CHR HomePage: Default -> hxxp://www.google.com/
CHR Profile: C:\Users\editor\AppData\Local\Google\Chrome\User Data\Default [2017-06-26]
CHR Extension: (Google Slides) - C:\Users\editor\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-04-17]
CHR Extension: (Google Docs) - C:\Users\editor\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-04-17]
CHR Extension: (Google Drive) - C:\Users\editor\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-23]
CHR Extension: (YouTube) - C:\Users\editor\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-26]
CHR Extension: (uBlock Origin) - C:\Users\editor\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpalhdlnbpafiamejdnhcphjbkeiagm [2017-06-22]
CHR Extension: (Image Downloader) - C:\Users\editor\AppData\Local\Google\Chrome\User Data\Default\Extensions\cnpniohnfphhjihaiiggeabnkjhpaldj [2017-05-04]
CHR Extension: (Google Search) - C:\Users\editor\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-27]
CHR Extension: (Frame by Frame for YouTube™) - C:\Users\editor\AppData\Local\Google\Chrome\User Data\Default\Extensions\elkadbdicdciddfkdpmaolomehalghio [2016-01-04]
CHR Extension: (Google Sheets) - C:\Users\editor\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-04-17]
CHR Extension: (Chrome Remote Desktop) - C:\Users\editor\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbchcmhmhahfdphkhkmpfmihenigjmpp [2017-06-12]
CHR Extension: (Google Docs Offline) - C:\Users\editor\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-17]
CHR Extension: (WhatFont) - C:\Users\editor\AppData\Local\Google\Chrome\User Data\Default\Extensions\jabopobgcpjmedljpbcaablpmlmfcogm [2017-05-08]
CHR Extension: (Reddit Enhancement Suite) - C:\Users\editor\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbmfpngjjgdllneeigpgjifpgocmfgmb [2017-06-22]
CHR Extension: (Chrome Web Store Payments) - C:\Users\editor\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-03-13]
CHR Extension: (Mercury Reader) - C:\Users\editor\AppData\Local\Google\Chrome\User Data\Default\Extensions\oknpjjbmpnndlpmnhmekjpocelpnlfdi [2017-04-26]
CHR Extension: (Gmail) - C:\Users\editor\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-04-17]
CHR Extension: (Chrome Media Router) - C:\Users\editor\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-05-12]
CHR Profile: C:\Users\editor\AppData\Local\Google\Chrome\User Data\Guest Profile [2017-04-25]
CHR Profile: C:\Users\editor\AppData\Local\Google\Chrome\User Data\System Profile [2016-06-29]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
 
==================== Services (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 AdAppMgrSvc; C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AdAppMgrSvc.exe [1309176 2017-03-10] (Autodesk Inc.)
R2 AdobeUpdateService; C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [814688 2017-06-04] (Adobe Systems Incorporated)
R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2246256 2017-05-18] (Adobe Systems, Incorporated)
R2 AJA Service; C:\Program Files\AJA\windows\Applications\ajadaemon.exe [1649152 2015-11-05] (AJA Video Systems, Inc.) [File not signed]
S3 Avid DMF Service; C:\Program Files\Avid\Editor Transcode\Dynamic Media Files\DMFService.exe [661768 2016-09-01] (Avid Technology, Inc.)
R2 Avid Editor Broker; C:\Program Files\Avid\Editor Transcode\TranscodeService\AvidEditorMSE.exe [662280 2016-09-01] (Avid Technology, Inc.)
R2 Avid Editor Db Engine; C:\Program Files\Avid\Editor Transcode\TranscodeService\AvidEditorDbEngine.exe [661768 2016-09-01] (Avid Technology, Inc.)
S3 Avid Editor Transcode Service; C:\Program Files\Avid\Editor Transcode\TranscodeService\AvidEditorTranscode.exe [662280 2016-09-01] (Avid Technology, Inc.)
R2 Avid Editor Transcode Status; C:\Program Files\Avid\Editor Transcode\TranscodeService\rnc-central\AvidEditorTranscodeStatus.exe [297736 2016-09-01] (Avid Technology, Inc.)
R2 Avid ISIS Benchmark Agent; C:\Program Files\Avid\ISIS Client\Utilities\Benchmark Utility\BenchmarkAgent.exe [4160000 2015-11-13] (Avid) [File not signed]
S2 AvidFosFS; C:\Windows\system32\AvidFos_Service.exe [17554944 2015-11-13] (Avid) [File not signed]
R2 chromoting; C:\Program Files (x86)\Google\Chrome Remote Desktop\59.0.3071.47\remoting_host.exe [71512 2017-05-09] (Google Inc.)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [4122816 2017-06-10] (Microsoft Corporation)
R2 Episode Assistant Service; C:\Program Files\Telestream\Episode 7\bin\tseas.exe [6656 2015-11-09] () [File not signed]
R2 Episode Client Proxy Service; C:\Program Files\Telestream\Episode 7\bin\tsecps.exe [6656 2015-11-09] () [File not signed]
R2 Episode IOserver Service; C:\Program Files\Telestream\Episode 7\bin\tseioss.exe [6144 2015-11-09] () [File not signed]
R2 Episode JSON-RPC Service; C:\Program Files\Telestream\Episode 7\bin\tsejrs.exe [6656 2015-11-09] () [File not signed]
R2 Episode Node Service; C:\Program Files\Telestream\Episode 7\bin\tsens.exe [8192 2015-11-09] () [File not signed]
R2 Episode XML-RPC Service; C:\Program Files\Telestream\Episode 7\bin\tsexrs.exe [6656 2015-11-09] () [File not signed]
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4470736 2017-05-09] (Malwarebytes)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [119864 2016-11-14] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [361816 2016-11-14] (Microsoft Corporation)
R2 NVWMI; C:\Windows\system32\nvwmi64.exe [2693448 2014-09-12] ()
R2 pdfcDispatcher; C:\Program Files (x86)\PDF Complete\pdfsvc.exe [1719552 2017-02-15] (PDF Complete Inc)
R2 SamsungRapidSvc; C:\Windows\System32\RAPID\SamsungRapidSvc.exe [29080 2016-11-18] (Samsung Electronics Co., Ltd.)
R2 SentinelKeysServer; C:\Program Files (x86)\Common Files\SafeNet Sentinel\Sentinel Keys Server\sntlkeyssrvr.exe [376832 2013-01-09] (SafeNet, Inc.) [File not signed]
R2 SentinelProtectionServer; C:\Program Files (x86)\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe [1259872 2013-01-09] (SafeNet, Inc)
R2 SentinelSecurityRuntime; C:\Program Files (x86)\Common Files\SafeNet Sentinel\Sentinel Security Runtime\sntlsrtsrvr.exe [293216 2013-01-09] (SafeNet, Inc.)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
R2 WTabletServicePro; C:\Program Files\Tablet\Wacom\WTabletServicePro.exe [675272 2017-05-31] (Wacom Technology, Corp.)
S4 TermService; %ProgramFiles%\RDP Wrapper\rdpwrap.dll [X]
 
===================== Drivers (Whitelisted) ======================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 AvidFos; C:\Windows\System32\Drivers\AvidFos.sys [755944 2015-11-13] (Avid)
R2 AvidFosLog; C:\Windows\System32\Drivers\AvidFosLog.sys [29416 2015-11-13] (Avid)
R2 AvidFosShell; C:\Windows\System32\Drivers\AvidFosShell.sys [17640 2015-11-13] (Avid)
R3 bomebus; C:\Windows\System32\DRIVERS\bomebus.sys [34376 2010-10-13] (Bome Software)
S3 bomemidi; C:\Windows\System32\drivers\bomemidi.sys [30792 2010-10-13] (Bome Software)
R2 fsdk-wrap; C:\Windows\System32\Drivers\fsdk-wrap.sys [417000 2015-11-13] (OSR Open Systems Resource, Inc.)
S3 hitmanpro37; C:\Windows\system32\drivers\hitmanpro37.sys [43664 2015-04-10] ()
R1 HWiNFO32; C:\Windows\system32\drivers\HWiNFO64A.SYS [27552 2017-04-04] (REALiX™)
R0 iaStorF; C:\Windows\System32\drivers\iaStorF.sys [24496 2012-03-15] (Intel Corporation)
R0 iaStorS; C:\Windows\System32\drivers\iaStorS.sys [639408 2012-03-31] (Intel Corporation)
S3 IFCoEMP; C:\Windows\system32\drivers\ifM60x64.sys [348944 2012-03-09] (Intel® Corporation)
S3 IFCoEVB; C:\Windows\system32\drivers\ifP60X64.sys [70928 2012-03-09] (Intel® Corporation)
R0 MBAMSwissArmy; C:\Windows\System32\drivers\MBAMSwissArmy.sys [252832 2017-06-26] (Malwarebytes)
S3 MBAMWebProtection; C:\Windows\system32\drivers\mwac.sys [84256 2017-05-19] (Malwarebytes)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [295000 2016-08-25] (Microsoft Corporation)
R1 MpKsle1ee7f24; c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{58EFF581-175A-4A8E-88CC-F42150744E30}\MpKsle1ee7f24.sys [44928 2017-06-26] (Microsoft Corporation)
R3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [135928 2016-08-25] (Microsoft Corporation)
R3 NTV2_64; C:\Windows\System32\DRIVERS\ntv2_64.sys [160024 2015-11-05] (AJA Video Systems Inc.)
R0 PxHlpa64; C:\Windows\System32\Drivers\PxHlpa64.sys [56336 2012-06-22] (Corel Corporation)
R0 SamsungRapidDiskFltr; C:\Windows\System32\DRIVERS\SamsungRapidDiskFltr.sys [272792 2016-11-18] (Samsung Electronics Co., Ltd.)
R0 SamsungRapidFSFltr; C:\Windows\System32\DRIVERS\SamsungRapidFSFltr.sys [111512 2016-11-18] (Samsung Electronics Co., Ltd.)
R2 Sentinel64; C:\Windows\System32\Drivers\Sentinel64.sys [145448 2009-09-17] (SafeNet, Inc.)
S3 SIVDriver; C:\Windows\system32\Drivers\SIVX64.sys [171664 2016-07-14] (Ray Hinchliffe)
R3 SNTUSB64; C:\Windows\System32\DRIVERS\SNTUSB64.SYS [63568 2012-12-11] (SafeNet, Inc.)
R3 USA19H; C:\Windows\System32\DRIVERS\USA19Hx64.sys [740096 2007-10-30] (Keyspan)
R3 USA19HP; C:\Windows\System32\DRIVERS\USA19Hx64p.SYS [35840 2007-10-23] (Keyspan)
R3 WacHidRouterPro; C:\Windows\System32\DRIVERS\wachidrouter.sys [122512 2017-04-28] (Wacom Technology)
R3 WsAudio_Device; C:\Windows\System32\drivers\VirtualAudio.sys [31080 2013-09-03] (Wondershare)
R2 WskTrans; C:\Windows\System32\Drivers\WskTrans.sys [34024 2015-11-13] (Avid)
S3 Xena2_64; C:\Windows\System32\DRIVERS\Kona3_64.sys [308480 2012-09-10] (AJA Video Systems Inc.) [File not signed]
U4 NIC1394; no ImagePath
U4 NVIDIA Performance Driver Service; no ImagePath
S3 PTSimBus; system32\DRIVERS\PTSimBus.sys [X]
S3 PTSimHid; system32\DRIVERS\PTSimHid.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2017-06-26 20:03 - 2017-06-26 20:03 - 00036798 _____ C:\Users\editor\Downloads\FRST.txt
2017-06-26 20:03 - 2017-06-26 20:03 - 00000000 ____D C:\FRST
2017-06-26 20:02 - 2017-06-26 20:02 - 02441216 _____ (Farbar) C:\Users\editor\Downloads\FRST64.exe
2017-06-26 19:54 - 2017-06-26 19:54 - 00000000 ____D C:\Users\editor\Desktop\rkill
2017-06-26 11:57 - 2017-06-26 11:57 - 35489760 _____ (Adlice Software ) C:\Users\editor\Downloads\setup (1).exe
2017-06-26 11:18 - 2017-06-26 11:18 - 00000000 ___HD C:\OneDriveTemp
2017-06-26 11:15 - 2017-06-26 11:15 - 00000000 ____D C:\Windows\system32\RAPID
2017-06-26 11:15 - 2016-11-18 19:04 - 00272792 _____ (Samsung Electronics Co., Ltd.) C:\Windows\system32\Drivers\SamsungRapidDiskFltr.sys
2017-06-23 17:37 - 2017-06-23 17:37 - 00003142 _____ C:\Windows\System32\Tasks\Process Explorer-AVID4-editor
2017-06-23 17:05 - 2017-06-23 17:05 - 02724512 _____ (Sysinternals - www.sysinternals.com) C:\Users\editor\Downloads\procexp.exe
2017-06-23 16:43 - 2017-06-23 16:43 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign59df863cd635d885
2017-06-23 15:50 - 2017-06-23 15:50 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign8d8121701ba66570
2017-06-23 15:50 - 2017-06-23 15:50 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign52e3c77a20748e79
2017-06-23 15:48 - 2017-06-23 15:48 - 01514603 _____ C:\Users\editor\Downloads\FXConsoleInstaller_1.0.1_Win_2017.zip
2017-06-23 15:46 - 2017-06-23 15:46 - 00089844 _____ C:\Users\editor\Downloads\Comp2Clip2.zip
2017-06-23 15:44 - 2017-06-23 15:44 - 00001077 _____ C:\Users\Public\Desktop\Boris RED 5 (64 Bit).lnk
2017-06-23 15:44 - 2017-06-23 15:44 - 00000000 ____D C:\Users\Public\Documents\Lightworks
2017-06-23 15:43 - 2017-06-23 15:43 - 240190485 _____ C:\Users\editor\Downloads\SFX-20170623T194015Z-001.zip
2017-06-23 15:42 - 2017-06-23 15:42 - 00000000 ____D C:\Users\editor\Downloads\boris
2017-06-23 15:35 - 2017-06-23 15:35 - 00001179 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Media Encoder CC 2017.lnk
2017-06-23 14:40 - 2017-06-23 14:40 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign9166cc43c6cb6144
2017-06-23 14:19 - 2017-06-23 14:19 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign46564856646d2f2f
2017-06-23 14:18 - 2017-06-23 14:18 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign1a94ce88808d4a7b
2017-06-23 13:50 - 2017-06-23 13:50 - 00000804 __RSH C:\Users\editor\ntuser.pol
2017-06-23 13:10 - 2017-06-23 13:10 - 00001277 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe After Effects CC 2017.lnk
2017-06-23 12:45 - 2017-06-23 12:45 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsignb8037e97948ee1a6
2017-06-23 12:45 - 2017-06-23 12:45 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign7804bb806808d832
2017-06-23 12:44 - 2017-06-23 12:44 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsigne08c37701e2a0ee4
2017-06-23 12:43 - 2017-06-23 12:43 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign580f3bea265f8649
2017-06-23 11:51 - 2017-06-26 11:59 - 00028272 _____ C:\Windows\system32\Drivers\TrueSight.sys
2017-06-23 11:51 - 2017-06-26 11:58 - 00000897 _____ C:\Users\Public\Desktop\RogueKiller.lnk
2017-06-23 11:51 - 2017-06-26 11:58 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RogueKiller
2017-06-23 11:51 - 2017-06-26 11:58 - 00000000 ____D C:\Program Files\RogueKiller
2017-06-23 11:51 - 2017-06-23 12:32 - 00000000 ____D C:\ProgramData\RogueKiller
2017-06-23 11:48 - 2017-06-23 11:49 - 35438416 _____ (Adlice Software ) C:\Users\editor\Downloads\RogueKiller_setup_ref3.exe
2017-06-23 11:29 - 2017-06-23 11:47 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2017-06-23 11:28 - 2017-06-23 11:47 - 00000000 ____D C:\Users\editor\Desktop\mbar
2017-06-23 11:27 - 2017-06-23 11:28 - 16563352 _____ (Malwarebytes Corp.) C:\Users\editor\Downloads\mbar-1.09.3.1001.exe
2017-06-22 21:59 - 2017-06-22 21:59 - 00000000 ____D C:\TDSSKiller_Quarantine
2017-06-22 21:55 - 2016-07-14 03:14 - 00171664 _____ (Ray Hinchliffe) C:\Windows\system32\Drivers\SIVX64.sys
2017-06-22 21:49 - 2017-06-10 13:36 - 00000000 ____D C:\Users\editor\Desktop\integrity_verification
2017-06-22 21:49 - 2017-06-10 13:08 - 00000000 ____D C:\Users\editor\Desktop\tron
2017-06-22 21:41 - 2017-06-22 21:48 - 659787891 _____ (Igor Pavlov) C:\Users\editor\Desktop\Tron v10.1.0 (2017-06-10).exe
2017-06-22 20:20 - 2017-06-22 20:20 - 02030536 _____ (Bleeping Computer, LLC) C:\Users\editor\Downloads\rkill.exe
2017-06-22 20:12 - 2017-06-22 20:12 - 34790450 _____ C:\Users\editor\Downloads\windows6.1-kb4012212-x64_2decefaa02e2058dcd965702509a992d8c4e92b3.msu
2017-06-22 19:32 - 2017-06-22 19:32 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsigne31135abea56a536
2017-06-22 19:32 - 2017-06-22 19:32 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign2437faf4446c147c
2017-06-22 16:51 - 2017-06-22 16:51 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign096855595bc7753f
2017-06-22 16:50 - 2017-06-22 16:50 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign2a8de0a70e9934da
2017-06-22 14:31 - 2017-06-22 14:31 - 00000000 ____D C:\Program Files\Red Giant
2017-06-22 14:31 - 2017-05-10 19:56 - 15353856 _____ (Red Giant LLC) C:\Windows\system32\UniChooser.dll
2017-06-22 14:31 - 2017-05-10 19:56 - 13179904 _____ (Red Giant Software) C:\Windows\system32\Gpu_Shader_Engine_x64.dll
2017-06-22 14:31 - 2017-05-10 19:56 - 05528064 _____ (Noesis Technologies) C:\Windows\system32\Noesis.dll
 
2017-06-22 12:07 - 2017-06-22 12:07 - 00001167 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Premiere Pro CC 2017.lnk
2017-06-22 12:03 - 2017-06-22 12:03 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign3118c32baeebc941
2017-06-22 12:02 - 2017-06-22 12:02 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign698bbaaed98fc862
2017-06-19 17:39 - 2017-06-19 17:39 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign7fff0c43db9851b3
2017-06-19 17:38 - 2017-06-19 17:38 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign39bf399261bc6fd2
2017-06-19 17:37 - 2017-06-19 17:37 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign7acb5c62f5b628d3
2017-06-19 17:26 - 2017-06-19 17:26 - 00002880 _____ C:\Users\editor\Documents\FCP Translation Results 2017-06-19 17-26.txt
2017-06-19 17:26 - 2017-06-19 17:26 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign42389bfcb5552074
2017-06-19 17:26 - 2017-06-19 17:26 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign1e86a872dea4c587
2017-06-19 16:32 - 2017-06-19 17:23 - 00000000 ____D C:\Users\editor\Desktop\aaf
2017-06-16 21:21 - 2017-06-16 21:24 - 355934860 _____ C:\Users\editor\Downloads\OEXT.zip
2017-06-16 20:07 - 2017-06-16 20:07 - 08455478 _____ C:\Users\editor\Downloads\drive-download-20170617T000720Z-001.zip
2017-06-16 14:54 - 2017-06-16 14:54 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign74b22a34557fd6a6
2017-06-16 14:52 - 2017-06-16 14:52 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsigncad245026e30a186
2017-06-16 14:52 - 2017-06-16 14:52 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign5c962276e3fa74ab
2017-06-14 19:47 - 2017-06-14 19:47 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign4f1768933266bbd0
2017-06-14 19:32 - 2017-06-14 19:32 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsigncf9ed271a4570a7f
2017-06-14 19:32 - 2017-06-14 19:32 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign3a81c8a21e40e00c
2017-06-13 20:57 - 2017-06-02 04:28 - 02317824 _____ (Microsoft Corporation) C:\Windows\system32\tquery.dll
2017-06-13 20:57 - 2017-06-02 04:28 - 02222080 _____ (Microsoft Corporation) C:\Windows\system32\mssrch.dll
2017-06-13 20:57 - 2017-06-02 04:28 - 00778240 _____ (Microsoft Corporation) C:\Windows\system32\mssvp.dll
2017-06-13 20:57 - 2017-06-02 04:28 - 00491520 _____ (Microsoft Corporation) C:\Windows\system32\mssph.dll
2017-06-13 20:57 - 2017-06-02 04:28 - 00288256 _____ (Microsoft Corporation) C:\Windows\system32\mssphtb.dll
2017-06-13 20:57 - 2017-06-02 04:28 - 00115200 _____ (Microsoft Corporation) C:\Windows\system32\mssitlb.dll
2017-06-13 20:57 - 2017-06-02 04:28 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\mssprxy.dll
2017-06-13 20:57 - 2017-06-02 04:28 - 00075264 _____ (Microsoft Corporation) C:\Windows\system32\msscntrs.dll
2017-06-13 20:57 - 2017-06-02 04:28 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\msshooks.dll
2017-06-13 20:57 - 2017-06-02 04:11 - 00591872 _____ (Microsoft Corporation) C:\Windows\system32\SearchIndexer.exe
2017-06-13 20:57 - 2017-06-02 04:11 - 00249856 _____ (Microsoft Corporation) C:\Windows\system32\SearchProtocolHost.exe
2017-06-13 20:57 - 2017-06-02 04:10 - 00733696 _____ (Microsoft Corporation) C:\Windows\HelpPane.exe
2017-06-13 20:57 - 2017-06-02 04:10 - 00113664 _____ (Microsoft Corporation) C:\Windows\system32\SearchFilterHost.exe
2017-06-13 20:57 - 2017-06-02 04:09 - 01549824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tquery.dll
2017-06-13 20:57 - 2017-06-02 04:09 - 01400320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssrch.dll
2017-06-13 20:57 - 2017-06-02 04:09 - 00666624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssvp.dll
2017-06-13 20:57 - 2017-06-02 04:09 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssph.dll
2017-06-13 20:57 - 2017-06-02 04:09 - 00197120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssphtb.dll
2017-06-13 20:57 - 2017-06-02 04:09 - 00104448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssitlb.dll
2017-06-13 20:57 - 2017-06-02 04:09 - 00059392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msscntrs.dll
2017-06-13 20:57 - 2017-06-02 04:09 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssprxy.dll
2017-06-13 20:57 - 2017-06-02 03:58 - 00427520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchIndexer.exe
2017-06-13 20:57 - 2017-06-02 03:58 - 00164352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchProtocolHost.exe
2017-06-13 20:57 - 2017-06-02 03:57 - 00086528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchFilterHost.exe
2017-06-13 20:57 - 2017-06-02 03:57 - 00009728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msshooks.dll
2017-06-13 20:57 - 2017-05-21 00:28 - 00154856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2017-06-13 20:57 - 2017-05-21 00:28 - 00095464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2017-06-13 20:57 - 2017-05-21 00:24 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2017-06-13 20:57 - 2017-05-21 00:24 - 01212928 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2017-06-13 20:57 - 2017-05-21 00:24 - 00730624 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2017-06-13 20:57 - 2017-05-21 00:24 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2017-06-13 20:57 - 2017-05-21 00:24 - 00463872 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2017-06-13 20:57 - 2017-05-21 00:24 - 00345600 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2017-06-13 20:57 - 2017-05-21 00:24 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2017-06-13 20:57 - 2017-05-21 00:24 - 00312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2017-06-13 20:57 - 2017-05-21 00:24 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2017-06-13 20:57 - 2017-05-21 00:24 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll
2017-06-13 20:57 - 2017-05-21 00:24 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2017-06-13 20:57 - 2017-05-21 00:24 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2017-06-13 20:57 - 2017-05-21 00:24 - 00123904 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll
2017-06-13 20:57 - 2017-05-21 00:24 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2017-06-13 20:57 - 2017-05-21 00:24 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2017-06-13 20:57 - 2017-05-21 00:24 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2017-06-13 20:57 - 2017-05-21 00:24 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2017-06-13 20:57 - 2017-05-21 00:24 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2017-06-13 20:57 - 2017-05-21 00:24 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2017-06-13 20:57 - 2017-05-21 00:06 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2017-06-13 20:57 - 2017-05-21 00:06 - 00666112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2017-06-13 20:57 - 2017-05-21 00:06 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2017-06-13 20:57 - 2017-05-21 00:06 - 00342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
2017-06-13 20:57 - 2017-05-21 00:06 - 00261120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2017-06-13 20:57 - 2017-05-21 00:06 - 00254464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2017-06-13 20:57 - 2017-05-21 00:06 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2017-06-13 20:57 - 2017-05-21 00:06 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2017-06-13 20:57 - 2017-05-21 00:06 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2017-06-13 20:57 - 2017-05-21 00:06 - 00141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll
2017-06-13 20:57 - 2017-05-21 00:06 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2017-06-13 20:57 - 2017-05-21 00:06 - 00082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcrypt.dll
2017-06-13 20:57 - 2017-05-21 00:06 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2017-06-13 20:57 - 2017-05-21 00:06 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2017-06-13 20:57 - 2017-05-21 00:06 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2017-06-13 20:57 - 2017-05-21 00:06 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2017-06-13 20:57 - 2017-05-20 23:55 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2017-06-13 20:57 - 2017-05-20 23:48 - 00291328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2017-06-13 20:57 - 2017-05-20 23:48 - 00159744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2017-06-13 20:57 - 2017-05-20 23:48 - 00129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2017-06-13 20:57 - 2017-05-20 23:47 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2017-06-13 20:57 - 2017-05-20 23:46 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2017-06-13 20:57 - 2017-05-20 23:42 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
2017-06-13 20:57 - 2017-05-16 14:19 - 00394448 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2017-06-13 20:57 - 2017-05-16 13:35 - 00346320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2017-06-13 20:57 - 2017-05-14 16:46 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2017-06-13 20:57 - 2017-05-14 16:46 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2017-06-13 20:57 - 2017-05-14 16:28 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2017-06-13 20:57 - 2017-05-14 16:27 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2017-06-13 20:57 - 2017-05-14 16:27 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2017-06-13 20:57 - 2017-05-14 16:27 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2017-06-13 20:57 - 2017-05-14 16:26 - 00576512 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2017-06-13 20:57 - 2017-05-14 16:24 - 02899456 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2017-06-13 20:57 - 2017-05-14 16:19 - 25738752 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2017-06-13 20:57 - 2017-05-14 16:17 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2017-06-13 20:57 - 2017-05-14 16:16 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2017-06-13 20:57 - 2017-05-14 16:12 - 00615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2017-06-13 20:57 - 2017-05-14 16:10 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2017-06-13 20:57 - 2017-05-14 16:10 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2017-06-13 20:57 - 2017-05-14 16:10 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2017-06-13 20:57 - 2017-05-14 16:10 - 00116224 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2017-06-13 20:57 - 2017-05-14 16:01 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2017-06-13 20:57 - 2017-05-14 15:57 - 00489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2017-06-13 20:57 - 2017-05-14 15:55 - 05975040 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2017-06-13 20:57 - 2017-05-14 15:48 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2017-06-13 20:57 - 2017-05-14 15:47 - 00087552 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2017-06-13 20:57 - 2017-05-14 15:46 - 00107520 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2017-06-13 20:57 - 2017-05-14 15:42 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2017-06-13 20:57 - 2017-05-14 15:41 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2017-06-13 20:57 - 2017-05-14 15:38 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2017-06-13 20:57 - 2017-05-14 15:37 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2017-06-13 20:57 - 2017-05-14 15:36 - 00152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2017-06-13 20:57 - 2017-05-14 15:23 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2017-06-13 20:57 - 2017-05-14 15:23 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2017-06-13 20:57 - 2017-05-14 15:22 - 00499200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2017-06-13 20:57 - 2017-05-14 15:22 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2017-06-13 20:57 - 2017-05-14 15:22 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2017-06-13 20:57 - 2017-05-14 15:21 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2017-06-13 20:57 - 2017-05-14 15:20 - 00725504 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2017-06-13 20:57 - 2017-05-14 15:19 - 00806912 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2017-06-13 20:57 - 2017-05-14 15:18 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2017-06-13 20:57 - 2017-05-14 15:17 - 02132992 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2017-06-13 20:57 - 2017-05-14 15:16 - 02290176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2017-06-13 20:57 - 2017-05-14 15:15 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2017-06-13 20:57 - 2017-05-14 15:14 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2017-06-13 20:57 - 2017-05-14 15:12 - 00476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2017-06-13 20:57 - 2017-05-14 15:11 - 20274688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2017-06-13 20:57 - 2017-05-14 15:11 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2017-06-13 20:57 - 2017-05-14 15:10 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2017-06-13 20:57 - 2017-05-14 15:10 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2017-06-13 20:57 - 2017-05-14 15:02 - 00416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2017-06-13 20:57 - 2017-05-14 14:57 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2017-06-13 20:57 - 2017-05-14 14:57 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2017-06-13 20:57 - 2017-05-14 14:56 - 00091136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2017-06-13 20:57 - 2017-05-14 14:54 - 15252992 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2017-06-13 20:57 - 2017-05-14 14:53 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2017-06-13 20:57 - 2017-05-14 14:52 - 03240960 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2017-06-13 20:57 - 2017-05-14 14:52 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2017-06-13 20:57 - 2017-05-14 14:50 - 00279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2017-06-13 20:57 - 2017-05-14 14:49 - 00130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2017-06-13 20:57 - 2017-05-14 14:44 - 04549120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2017-06-13 20:57 - 2017-05-14 14:42 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2017-06-13 20:57 - 2017-05-14 14:40 - 00693248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2017-06-13 20:57 - 2017-05-14 14:39 - 02057216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2017-06-13 20:57 - 2017-05-14 14:38 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2017-06-13 20:57 - 2017-05-14 14:37 - 01544704 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2017-06-13 20:57 - 2017-05-14 14:30 - 13664768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2017-06-13 20:57 - 2017-05-14 14:27 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2017-06-13 20:57 - 2017-05-14 14:15 - 02767872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2017-06-13 20:57 - 2017-05-14 14:11 - 01314816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2017-06-13 20:57 - 2017-05-14 14:11 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2017-06-13 20:57 - 2017-05-12 14:27 - 00631176 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2017-06-13 20:57 - 2017-05-12 14:26 - 05547752 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2017-06-13 20:57 - 2017-05-12 14:26 - 00706792 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2017-06-13 20:57 - 2017-05-12 14:26 - 00382696 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2017-06-13 20:57 - 2017-05-12 14:24 - 01732864 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00880640 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00806912 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00419840 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00405504 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00215552 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00059904 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00034816 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:07 - 04001000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2017-06-13 20:57 - 2017-05-12 14:07 - 03945704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2017-06-13 20:57 - 2017-05-12 14:07 - 00308456 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2017-06-13 20:57 - 2017-05-12 14:04 - 01314112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00644096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00629760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00313344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00275456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 13:55 - 00148480 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2017-06-13 20:57 - 2017-05-12 13:54 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2017-06-13 20:57 - 2017-05-12 13:54 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2017-06-13 20:57 - 2017-05-12 13:52 - 03222528 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2017-06-13 20:57 - 2017-05-12 13:51 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2017-06-13 20:57 - 2017-05-12 13:50 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2017-06-13 20:57 - 2017-05-12 13:46 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2017-06-13 20:57 - 2017-05-12 13:43 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2017-06-13 20:57 - 2017-05-12 13:41 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2017-06-13 20:57 - 2017-05-12 13:41 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2017-06-13 20:57 - 2017-05-12 13:41 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2017-06-13 20:57 - 2017-05-12 13:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2017-06-13 20:57 - 2017-05-12 13:40 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 13:40 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 13:40 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 13:40 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 12:25 - 01251328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2017-06-13 20:57 - 2017-05-12 11:58 - 01648128 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2017-06-13 20:57 - 2017-05-12 11:58 - 01180160 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2017-06-13 20:57 - 2017-05-10 11:33 - 00091368 _____ (Microsoft Corporation) C:\Windows\system32\MigAutoPlay.exe
2017-06-13 20:57 - 2017-05-10 11:29 - 14183936 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2017-06-13 20:57 - 2017-05-10 11:29 - 03165184 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2017-06-13 20:57 - 2017-05-10 11:29 - 01867776 _____ (Microsoft Corporation) C:\Windows\system32\ExplorerFrame.dll
2017-06-13 20:57 - 2017-05-10 11:29 - 00192512 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2017-06-13 20:57 - 2017-05-10 11:29 - 00098816 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2017-06-13 20:57 - 2017-05-10 11:28 - 00091136 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2017-06-13 20:57 - 2017-05-10 11:16 - 00091368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MigAutoPlay.exe
2017-06-13 20:57 - 2017-05-10 11:14 - 02651136 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2017-06-13 20:57 - 2017-05-10 11:13 - 00709120 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2017-06-13 20:57 - 2017-05-10 11:13 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2017-06-13 20:57 - 2017-05-10 11:13 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2017-06-13 20:57 - 2017-05-10 11:13 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2017-06-13 20:57 - 2017-05-10 11:13 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2017-06-13 20:57 - 2017-05-10 11:13 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
2017-06-13 20:57 - 2017-05-10 11:12 - 12880896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2017-06-13 20:57 - 2017-05-10 11:12 - 01499648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ExplorerFrame.dll
2017-06-13 20:57 - 2017-05-10 11:12 - 00174080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2017-06-13 20:57 - 2017-05-10 11:00 - 00573440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2017-06-13 20:57 - 2017-05-10 11:00 - 00093696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2017-06-13 20:57 - 2017-05-10 11:00 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2017-06-13 20:57 - 2017-05-10 11:00 - 00030208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2017-06-13 20:57 - 2017-05-10 10:52 - 00117248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys
2017-06-13 20:57 - 2017-05-09 11:30 - 00757248 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll
2017-06-13 20:57 - 2017-05-09 11:29 - 00970240 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll
2017-06-13 20:57 - 2017-05-09 11:15 - 00071680 _____ C:\Windows\system32\PrintBrmUi.exe
2017-06-13 20:57 - 2017-05-09 11:11 - 00497664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll
2017-06-13 20:57 - 2017-05-07 11:33 - 00094440 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mountmgr.sys
2017-06-13 20:57 - 2017-05-07 11:29 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\msmmsp.dll
2017-06-13 20:57 - 2017-04-27 18:50 - 03550208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_47.dll
2017-06-13 20:57 - 2017-04-12 09:05 - 04296704 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_47.dll
2017-06-13 20:57 - 2017-03-30 11:03 - 00046080 _____ (Microsoft Corporation) C:\Windows\system32\rundll32.exe
2017-06-13 20:57 - 2017-03-30 10:58 - 00045056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
2017-06-13 19:03 - 2017-06-13 19:03 - 14976971 _____ C:\Users\editor\Downloads\nablet_XAVC_XDCAM_AMA_Plugin_Win_4.0.3.1146.zip
2017-06-13 19:03 - 2017-06-13 19:03 - 00000000 ____D C:\Users\editor\Downloads\nablet_XAVC_XDCAM_AMA_Plugin_Win_4.0.3.1146
2017-06-13 16:36 - 2017-06-13 16:36 - 00000000 ____D C:\Users\editor\AppData\Local\RzStats
2017-06-13 16:34 - 2017-06-13 16:34 - 00214174 _____ C:\Users\editor\Downloads\WindowsFirewall.diagcab
2017-06-13 16:32 - 2017-06-13 19:12 - 00000000 ____D C:\Users\editor\AppData\Local\Razer
2017-06-13 16:31 - 2017-06-13 19:13 - 00000000 ____D C:\ProgramData\Razer
2017-06-13 16:31 - 2017-06-13 19:13 - 00000000 ____D C:\Program Files (x86)\Razer
2017-06-13 15:27 - 2017-06-13 15:27 - 152572041 _____ C:\Users\editor\Downloads\windows6.1-kb4012215-x64_a777b8c251dcd8378ecdafa81aefbe7f9009c72b.msu
2017-06-13 15:13 - 2017-06-13 15:14 - 22908488 _____ (Philipp Schmieder Medien ) C:\Users\editor\Downloads\clipgrab-3.6.5-cgorg.exe
2017-06-13 15:01 - 2017-06-13 15:04 - 22738504 _____ (Razer Inc.) C:\Users\editor\Downloads\Razer_Synapse_Framework_V2.20.15.1104.exe
2017-06-12 18:32 - 2017-06-12 18:32 - 668212825 _____ C:\Users\editor\Desktop\ STRINGOUT PART 2.Copy.01.mov
2017-06-12 15:45 - 2017-06-12 15:45 - 00476169 _____ C:\Users\editor\Downloads\_Shoot_Checklist.xlsx
2017-06-12 14:27 - 2017-06-12 14:27 - 00000000 ____D C:\Users\editor\Downloads\GIFM_550_1-FILE_20170611192144
2017-06-11 21:31 - 2017-06-11 21:31 - 01933312 _____ C:\Users\editor\Downloads\061017_GROUP (1).aaf
2017-06-11 21:31 - 2017-06-11 21:31 - 00160812 _____ C:\Users\editor\Downloads\GIFM_550_1-FILE_20170611192144.zip
2017-06-11 21:30 - 2017-06-11 21:30 - 01933312 _____ C:\Users\editor\Downloads\061017_GROUP.aaf
2017-06-11 21:30 - 2017-06-11 21:30 - 01933312 _____ C:\Users\editor\Desktop\061017_GROUP.aaf
2017-06-11 19:21 - 2017-06-11 21:32 - 02342912 _____ C:\Users\editor\Desktop\061017_GROUP_MULTIGROUPED.aaf
2017-06-09 18:13 - 2017-06-20 16:28 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2017-06-08 20:23 - 2017-06-08 20:51 - 561908852 _____ C:\Users\editor\Desktop\052617_PB_OPEN1_1.mov
2017-06-08 18:43 - 2017-06-08 18:43 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign8188b830f2e1781d
2017-06-08 18:43 - 2017-06-08 18:43 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign311dc0be15a4e8e5
2017-06-08 16:17 - 2017-06-08 16:40 - 127564968 _____ C:\Users\editor\Desktop\TC.mov
2017-06-08 15:47 - 2017-06-08 16:09 - 111227757 _____ C:\Users\editor\Desktop\aa.mov
2017-06-08 12:50 - 2017-06-08 12:50 - 00001200 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Creative Cloud.lnk
2017-06-08 12:50 - 2017-06-08 12:50 - 00001188 _____ C:\Users\Public\Desktop\Adobe Creative Cloud.lnk
2017-06-08 11:05 - 2017-06-08 11:26 - 480804911 _____ C:\Users\editor\Desktop\22.09.mov
2017-06-08 11:00 - 2017-06-08 11:00 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsigna7c314ae638759b9
2017-06-08 11:00 - 2017-06-08 11:00 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign2fb759c9a750f030
2017-06-07 17:29 - 2017-05-18 13:30 - 130804461 ____N C:\Users\editor\Downloads\on 2017-05-18 at 15.09.mov
2017-06-07 17:25 - 2017-06-07 17:26 - 445301618 _____ C:\Users\editor\Downloads\drive-download-20170607T212436Z-001.zip
2017-06-07 17:25 - 2017-06-07 17:25 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsigndb08791fe2be7fb7
2017-06-07 17:25 - 2017-06-07 17:25 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign5120056e2d3f6cf7
2017-06-06 19:38 - 2017-06-06 19:38 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsignb8bd1562439c1688
2017-06-06 19:38 - 2017-06-06 19:38 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign70bab4a592232106
2017-06-06 12:51 - 2017-06-06 12:51 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wacom Tablet
2017-06-06 12:50 - 2017-06-06 12:50 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_wachidrouter_01011.Wdf
2017-06-06 12:50 - 2017-04-28 19:21 - 01804688 _____ (Microsoft Corporation) C:\Windows\system32\wdfcoinstaller01011.dll
2017-06-06 12:44 - 2017-06-06 12:44 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign9d8c4ca872eb95de
2017-06-06 12:44 - 2017-06-06 12:44 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign53ce6cdf44591021
2017-06-05 23:03 - 2017-06-06 12:25 - 00000000 ____D C:\Windows\IDOOYHNU
2017-06-05 17:04 - 2017-06-05 17:04 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsignffec44d35fb075e6
2017-06-05 17:04 - 2017-06-05 17:04 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsignf2951e3a4706ff43
2017-06-05 13:35 - 2017-06-05 13:35 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign8efc206c9568d7e7
2017-06-05 13:35 - 2017-06-05 13:35 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign344177af01f77b6a
2017-06-05 13:32 - 2017-06-05 13:32 - 145489330 _____ C:\Users\editor\Downloads\Jn 2017-05-04 at 22.09.mp4
2017-06-02 17:47 - 2017-06-02 17:47 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign18d15afce032f9ec
2017-06-02 17:47 - 2017-06-02 17:47 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign0c3094db0023a0c2
2017-06-02 15:16 - 2017-06-02 15:16 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsigneb50552d959030ba
2017-06-02 15:16 - 2017-06-02 15:16 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsignab937861b2dd6e19
2017-06-02 11:14 - 2017-06-02 11:14 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign486b309143e2c9ce
2017-06-02 11:07 - 2017-06-02 11:07 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign40b65fdb06015e17
2017-06-01 15:43 - 2017-06-01 16:16 - 640577372 _____ C:\Users\editor\Desktop\052617_PB_OPEN1.mov
2017-06-01 15:36 - 2017-06-01 15:36 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign2636f19498bb69c7
2017-06-01 15:35 - 2017-06-01 15:35 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsignd1ee8985c8597430
2017-06-01 15:09 - 2017-06-01 15:09 - 00001128 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Audition CC 2017.lnk
2017-06-01 15:08 - 2017-06-01 15:08 - 00001401 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Character Animator CC (Beta).lnk
2017-06-01 14:59 - 2017-06-01 14:59 - 00000000 ____D C:\Users\Public\Documents\AdobeInstalledCodecs
2017-06-01 14:58 - 2017-06-01 14:58 - 00001075 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe InDesign CC 2017.lnk
2017-06-01 14:52 - 2017-06-01 14:52 - 00002518 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Illustrator CC 2017.lnk
2017-06-01 14:50 - 2017-06-01 14:50 - 00001087 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CC 2017.lnk
2017-05-31 18:56 - 2017-05-31 18:56 - 00000000 ____D C:\Users\editor\Desktop\PLAY
2017-05-31 17:50 - 2017-05-31 17:50 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsignbcccae36e8f69123
2017-05-31 17:50 - 2017-05-31 17:50 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign6fa84344c147947f
2017-05-31 16:28 - 2017-05-31 16:28 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign98aba0ddda2d877d
2017-05-31 15:50 - 2017-05-31 15:50 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsigndd976a5083857c53
2017-05-31 15:50 - 2017-05-31 15:50 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign09d92304c42262d5
2017-05-31 11:58 - 2017-05-31 11:58 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsignca966863f82ec9c2
2017-05-31 11:58 - 2017-05-31 11:58 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign78066cb4858ef548
2017-05-31 11:58 - 2017-05-31 11:58 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign7138097e40fe4c8a
2017-05-30 19:23 - 2017-05-30 19:23 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign576844d639f135e5
2017-05-30 19:22 - 2017-05-30 19:22 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsigncc830bda13fc19ec
2017-05-30 19:22 - 2017-05-30 19:22 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign5c1d5a2798cd59c4
2017-05-30 17:59 - 2017-05-30 18:00 - 360581235 _____ C:\Users\editor\Downloads\111-lc-57348.mp4
2017-05-30 17:58 - 2017-05-30 17:58 - 00007447 _____ C:\Users\editor\Downloads\200-UN-40-36.mp4
2017-05-30 17:57 - 2017-05-30 17:57 - 61407442 _____ C:\Users\editor\Downloads\200-UN-38-29.mp4
2017-05-30 17:56 - 2017-05-30 17:57 - 431108924 _____ C:\Users\editor\Downloads\111-lc-58014.mp4
2017-05-30 17:56 - 2017-05-30 17:57 - 364720910 _____ C:\Users\editor\Downloads\330-dvic-34396.mp4
2017-05-30 17:55 - 2017-05-30 17:55 - 60868166 _____ C:\Users\editor\Downloads\34214.mp4
2017-05-30 17:55 - 2017-05-30 17:55 - 51541755 _____ C:\Users\editor\Downloads\30872.mp4
2017-05-30 17:52 - 2017-05-30 17:53 - 04752307 _____ C:\Users\editor\Downloads\30872.wmv
2017-05-30 17:52 - 2017-05-30 17:53 - 04746531 _____ C:\Users\editor\Downloads\34214.wmv
2017-05-30 17:14 - 2017-05-30 17:14 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsignf0783ad8c7e43533
2017-05-30 17:14 - 2017-05-30 17:14 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign4aacd883bb4ec32f
2017-05-30 17:14 - 2017-05-30 17:14 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign2234c07328d335de
2017-05-30 14:08 - 2017-05-30 14:08 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign1740179615a96708
2017-05-30 14:07 - 2017-05-30 14:07 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsigne03e683af7771134
2017-05-30 14:07 - 2017-05-30 14:07 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsigna289f46184532d96
2017-05-30 12:00 - 2017-05-30 12:00 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung Magician
2017-05-30 11:32 - 2017-05-30 11:32 - 00000672 _____ C:\Users\editor\Downloads\ulogviewer (3).jnlp
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2017-06-26 19:54 - 2017-05-12 13:50 - 00005106 _____ C:\Users\editor\Desktop\Rkill.txt
2017-06-26 19:50 - 2014-10-14 18:18 - 00000000 ____D C:\Windows\System32\Tasks\Event Viewer Tasks
2017-06-26 19:16 - 2013-06-14 16:34 - 00000000 ____D C:\Users\Public\Documents\Avid Media Composer
2017-06-26 17:41 - 2014-10-31 18:12 - 00000033 _____ C:\Users\editor\AppData\Roaming\AdobeWLCMCache.dat
2017-06-26 15:57 - 2014-10-27 18:22 - 00000000 ___RD C:\Users\editor\Creative Cloud Files
2017-06-26 13:20 - 2009-07-14 00:45 - 00027568 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2017-06-26 13:20 - 2009-07-14 00:45 - 00027568 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2017-06-26 12:18 - 2012-09-11 21:42 - 00000000 ____D C:\ProgramData\PDFC
2017-06-26 11:29 - 2015-04-17 14:54 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2017-06-26 11:27 - 2013-06-14 15:24 - 00000000 ____D C:\Users\editor\AppData\Local\Adobe
2017-06-26 11:22 - 2009-07-14 01:13 - 00793850 _____ C:\Windows\system32\PerfStringBackup.INI
2017-06-26 11:22 - 2009-07-13 23:20 - 00000000 ____D C:\Windows\inf
2017-06-26 11:18 - 2016-08-09 11:09 - 00000000 ____D C:\Users\editor\AppData\Roaming\Slack
2017-06-26 11:18 - 2014-10-14 15:01 - 00000000 ___RD C:\Users\editor\OneDrive
2017-06-26 11:17 - 2014-10-22 17:31 - 00252832 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2017-06-26 11:17 - 2013-07-01 13:19 - 00000000 ____D C:\Users\editor\AppData\Local\Aja
2017-06-26 11:17 - 2013-06-14 15:36 - 00000000 ____D C:\ProgramData\PACE
2017-06-26 11:17 - 2012-09-24 11:01 - 00000000 ____D C:\ProgramData\NVIDIA
2017-06-26 11:17 - 2009-07-14 01:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2017-06-26 11:15 - 2015-10-27 12:29 - 00000000 ____D C:\Program Files (x86)\Samsung
2017-06-23 19:05 - 2013-07-02 12:54 - 00000000 ____D C:\Users\Public\Documents\Shared Avid Projects
2017-06-23 18:12 - 2013-07-01 13:32 - 00000000 ____D C:\Users\editor\AppData\Local\BorisFX
2017-06-23 15:44 - 2014-10-14 15:19 - 00000000 ____D C:\Program Files\Adobe
2017-06-23 15:44 - 2013-07-01 13:30 - 00000000 ____D C:\Program Files\Boris FX, Inc
2017-06-23 14:13 - 2017-05-12 14:11 - 00004726 __RSH C:\ProgramData\ntuser.pol
2017-06-23 13:50 - 2013-06-14 11:48 - 00000000 ____D C:\Users\editor
2017-06-23 12:45 - 2015-11-23 21:01 - 00000000 ____D C:\Users\editor\AppData\Local\CrashDumps
2017-06-23 11:29 - 2014-10-22 17:30 - 00000000 ____D C:\ProgramData\Malwarebytes
2017-06-23 11:28 - 2017-05-12 13:51 - 00109272 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMChameleon.sys
2017-06-23 11:18 - 2015-11-04 13:32 - 00000000 ____D C:\Windows\pss
2017-06-22 23:22 - 2013-07-03 10:30 - 00000193 _____ C:\Windows\WORDPAD.INI
2017-06-22 16:53 - 2015-03-09 16:03 - 00000000 ____D C:\Users\editor\AppData\Roaming\Aescripts
2017-06-22 14:25 - 2015-08-24 14:57 - 00000000 ____D C:\ProgramData\rgt
2017-06-22 12:07 - 2016-02-11 22:42 - 00000000 ____D C:\Users\Public\Documents\Adobe
2017-06-22 10:18 - 2014-10-14 15:01 - 00002154 _____ C:\Users\editor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft OneDrive.lnk
2017-06-20 16:27 - 2015-11-24 13:19 - 00000000 ____D C:\ProgramData\xml_param
2017-06-20 14:57 - 2016-01-21 14:26 - 00000600 _____ C:\Users\editor\AppData\Local\PUTTY.RND
2017-06-20 14:45 - 2009-07-13 23:20 - 00000000 ____D C:\Windows\system32\NDF
2017-06-20 14:44 - 2015-01-14 12:06 - 00000000 ____D C:\Users\editor\AppData\Roaming\vlc
2017-06-19 16:41 - 2012-09-11 21:39 - 00000000 ____D C:\Program Files (x86)\Microsoft Office
2017-06-18 03:54 - 2014-10-14 14:57 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2017-06-16 21:21 - 2016-06-24 17:20 - 00000000 ____D C:\Users\editor\Desktop\junk
2017-06-16 18:23 - 2014-09-30 10:29 - 00000000 ____D C:\Users\editor\Desktop\post docs
2017-06-16 10:10 - 2016-12-13 12:45 - 00004312 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2017-06-16 10:10 - 2013-06-14 15:24 - 00803328 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2017-06-16 10:10 - 2013-06-14 15:24 - 00144896 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2017-06-16 10:10 - 2013-06-14 15:24 - 00000000 ____D C:\Windows\SysWOW64\Macromed
2017-06-16 10:10 - 2013-06-14 15:24 - 00000000 ____D C:\Windows\system32\Macromed
2017-06-14 04:01 - 2009-07-13 23:20 - 00000000 ____D C:\Windows\rescache
2017-06-14 03:24 - 2009-07-14 00:45 - 07472912 _____ C:\Windows\system32\FNTCACHE.DAT
2017-06-14 03:21 - 2009-07-13 23:20 - 00000000 ____D C:\Windows\SysWOW64\migwiz
2017-06-14 03:21 - 2009-07-13 23:20 - 00000000 ____D C:\Windows\system32\migwiz
2017-06-14 03:05 - 2014-10-14 18:38 - 00000000 ____D C:\Windows\system32\MRT
2017-06-14 03:02 - 2012-09-24 11:18 - 133627792 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2017-06-13 16:49 - 2016-08-09 11:09 - 00000000 ____D C:\Users\editor\AppData\Local\slack
2017-06-13 16:48 - 2016-08-09 11:09 - 00002124 _____ C:\Users\editor\Desktop\Slack.lnk
2017-06-13 16:48 - 2016-08-09 11:09 - 00000000 ____D C:\Users\editor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Slack Technologies
2017-06-13 16:48 - 2016-08-09 11:09 - 00000000 ____D C:\Users\editor\AppData\Local\SquirrelTemp
2017-06-13 16:45 - 2015-09-30 18:30 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2017-06-13 16:38 - 2014-10-06 18:38 - 00000000 ____D C:\Users\editor\AppData\Local\ElevatedDiagnostics
2017-06-08 12:50 - 2013-06-14 15:28 - 00000000 ____D C:\Users\editor\AppData\Roaming\Adobe
2017-06-08 12:50 - 2013-06-14 15:24 - 00000000 ____D C:\Program Files (x86)\Adobe
2017-06-06 19:39 - 2017-05-26 14:22 - 00000000 ____D C:\Users\editor\Desktop\PLAY
2017-06-06 12:50 - 2017-05-15 11:26 - 00000000 ____D C:\Program Files\Tablet
2017-06-06 12:44 - 2017-05-12 13:51 - 00077376 _____ C:\Windows\system32\Drivers\mbae64.sys
2017-06-06 05:32 - 2015-04-17 14:53 - 00000000 ____D C:\Program Files (x86)\Google
2017-06-01 14:58 - 2014-10-15 12:23 - 00000000 ____D C:\Program Files\Common Files\Adobe
2017-06-01 14:50 - 2014-10-16 11:42 - 00000000 ____D C:\Users\editor\Documents\Adobe
2017-05-31 13:38 - 2017-05-15 11:26 - 02275784 _____ (Wacom Technology, Corp.) C:\Windows\system32\Wacom_Tablet.dll
2017-05-31 13:38 - 2017-05-15 11:26 - 02268616 _____ (Wacom Technology, Corp.) C:\Windows\system32\Wacom_Touch_Tablet.dll
2017-05-31 13:38 - 2017-05-15 11:26 - 02174408 _____ (Wacom Technology, Corp.) C:\Windows\system32\WacomMT.dll
2017-05-31 13:38 - 2017-05-15 11:26 - 02112456 _____ (Wacom Technology, Corp.) C:\Windows\system32\Wintab32.dll
2017-05-31 13:38 - 2017-05-15 11:26 - 01788360 _____ (Wacom Technology, Corp.) C:\Windows\SysWOW64\Wacom_Tablet.dll
2017-05-31 13:38 - 2017-05-15 11:26 - 01781704 _____ (Wacom Technology, Corp.) C:\Windows\SysWOW64\Wacom_Touch_Tablet.dll
2017-05-31 13:38 - 2017-05-15 11:26 - 01673160 _____ (Wacom Technology, Corp.) C:\Windows\SysWOW64\WacomMT.dll
2017-05-31 13:38 - 2017-05-15 11:26 - 01632712 _____ (Wacom Technology, Corp.) C:\Windows\SysWOW64\Wintab32.dll
2017-05-30 16:45 - 2010-11-20 23:27 - 00565416 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2017-05-30 12:00 - 2015-11-04 11:55 - 00003268 _____ C:\Windows\System32\Tasks\SamsungMagician
2017-05-30 12:00 - 2015-11-04 11:14 - 00000000 ____D C:\ProgramData\Samsung
2017-05-30 12:00 - 2013-06-14 11:49 - 00001415 _____ C:\Users\editor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
 
==================== Files in the root of some directories =======
 
2014-10-31 18:12 - 2017-06-26 17:41 - 0000033 _____ () C:\Users\editor\AppData\Roaming\AdobeWLCMCache.dat
2015-02-23 19:50 - 2015-04-15 18:15 - 0000020 _____ () C:\Users\editor\AppData\Roaming\appdataFr3.bin
2015-10-13 19:40 - 2016-12-22 21:01 - 2111970 _____ () C:\Users\editor\AppData\Roaming\AvidApplicationManager_Install.log
2015-12-08 15:05 - 2015-12-08 15:05 - 0353038 _____ () C:\Users\editor\AppData\Roaming\CodecsPE_Install.log
2013-07-02 12:53 - 2013-07-02 12:56 - 13619600 _____ () C:\Users\editor\AppData\Roaming\MediaComposer_Install.log
2015-11-11 12:23 - 2015-11-11 12:23 - 0000600 _____ () C:\Users\editor\AppData\Roaming\winscp.rnd
2016-01-06 12:10 - 2016-01-06 18:19 - 0001456 _____ () C:\Users\editor\AppData\Local\Adobe Save for Web 13.0 Prefs
2016-01-21 14:26 - 2017-06-20 14:57 - 0000600 _____ () C:\Users\editor\AppData\Local\PUTTY.RND
2016-08-02 16:02 - 2016-08-02 16:02 - 0000218 _____ () C:\Users\editor\AppData\Local\recently-used.xbel
2015-03-04 14:24 - 2015-06-23 13:47 - 0007615 _____ () C:\Users\editor\AppData\Local\Resmon.ResmonCfg
 
Some files in TEMP:
====================
2016-05-05 13:42 - 2016-05-05 13:42 - 0152576 _____ () C:\Users\Administrator\AppData\Local\Temp\ext8871732758372805741.dll
2017-05-08 14:55 - 2017-01-18 04:50 - 0066472 _____ (Autodesk, Inc.) C:\Users\editor\AppData\Local\Temp\AcDeltree.exe
2017-06-23 11:51 - 2017-05-12 14:24 - 1732864 _____ (Microsoft Corporation) C:\Users\editor\AppData\Local\Temp\dllnt_dump.dll
2017-05-30 11:58 - 2017-05-30 11:58 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext1071487924470329686.dll
2016-09-08 14:12 - 2016-09-08 14:12 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext1078468819121090448.dll
2016-06-14 18:16 - 2016-06-14 18:16 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext1151835630057534668.dll
2015-11-16 16:24 - 2015-11-16 16:24 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext1183072325384774792.dll
2016-04-25 11:43 - 2016-04-25 11:43 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext1217413707317785236.dll
2016-03-14 16:54 - 2016-03-14 16:54 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext1319343702278081390.dll
2016-03-01 11:12 - 2016-03-01 11:12 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext1387032249583585987.dll
2016-04-01 10:25 - 2016-04-01 10:25 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext1390342959179133597.dll
2015-10-27 16:50 - 2015-10-27 16:50 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext1419658529081465959.dll
2015-10-27 10:30 - 2015-10-27 10:30 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext1430040114018611508.dll
2016-02-02 11:31 - 2016-02-02 11:31 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext1451832224755727541.dll
2017-01-11 13:07 - 2017-01-11 13:07 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext1509040781484176864.dll
2016-11-22 18:00 - 2016-11-22 18:00 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext1532003059987200971.dll
2016-12-15 13:38 - 2016-12-15 13:38 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext1533866195946092447.dll
2015-11-03 14:47 - 2015-11-03 14:47 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext154963228241822771.dll
2017-03-13 10:50 - 2017-03-13 10:50 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext1594388969696702898.dll
2016-02-25 12:41 - 2016-02-25 12:41 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext1706922428930719831.dll
2016-06-13 17:18 - 2016-06-13 17:18 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext1745706080785882248.dll
2016-08-02 13:16 - 2016-08-02 13:16 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext1770292877771680394.dll
2015-11-04 13:55 - 2015-11-04 13:55 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext1777408809831878958.dll
2016-12-23 11:26 - 2016-12-23 11:26 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext1797973998412743155.dll
2017-04-26 11:40 - 2017-04-26 11:40 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext1835306018527623051.dll
2017-06-19 16:26 - 2017-06-19 16:26 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext1889932346085638654.dll
2017-01-16 20:05 - 2017-01-16 20:05 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext1918484350215632423.dll
2017-05-15 11:25 - 2017-05-15 11:25 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext1921189100945833120.dll
2015-11-03 16:17 - 2015-11-03 16:17 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext2015770576046837310.dll
2016-12-01 14:06 - 2016-12-01 14:06 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext2133207907494036539.dll
2016-01-14 14:18 - 2016-01-14 14:18 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext2188325394909681814.dll
2016-06-06 10:10 - 2016-06-06 10:10 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext2376083175270374129.dll
2015-11-04 14:20 - 2015-11-04 14:20 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext2450965989854188459.dll
2017-05-10 13:28 - 2017-05-10 13:28 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext2549769600700938267.dll
2017-04-04 10:50 - 2017-04-04 10:50 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext2555866350480271609.dll
2017-01-17 17:38 - 2017-01-17 17:38 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext2679883320681407791.dll
2016-08-09 19:30 - 2016-08-09 19:30 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext2810383528727013082.dll
2016-02-05 17:20 - 2016-02-05 17:20 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext2812800208508467693.dll
2016-01-06 11:15 - 2016-01-06 11:15 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext2816016548880804213.dll
2015-12-14 13:40 - 2015-12-14 13:40 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext2836181816555615984.dll
2016-02-03 12:33 - 2016-02-03 12:33 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext2841381247710961653.dll
2015-11-04 16:33 - 2015-11-04 16:33 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext28417744230615292.dll
2017-06-06 12:56 - 2017-06-06 12:56 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext2875394656732631058.dll
2015-11-03 17:24 - 2015-11-03 17:24 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext2945307420508375877.dll
2015-11-03 21:09 - 2015-11-03 21:09 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext298511638111692833.dll
2016-11-30 15:18 - 2016-11-30 15:18 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext3047513954222222625.dll
2017-05-30 12:05 - 2017-05-30 12:05 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext3103501216984548210.dll
2017-06-06 12:41 - 2017-06-06 12:41 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext3119408804341771850.dll
2016-03-21 18:28 - 2016-03-21 18:28 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext3129859925905625542.dll
2015-11-04 12:14 - 2015-11-04 12:14 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext3215048347423473342.dll
2016-04-25 11:14 - 2016-04-25 11:14 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext327318349396438176.dll
2016-09-21 13:41 - 2016-09-21 13:41 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext3427369275572865229.dll
2015-11-19 12:16 - 2015-11-19 12:16 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext3432699624731639579.dll
2015-11-11 18:08 - 2015-11-11 18:08 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext3521498136178136464.dll
2016-08-10 21:33 - 2016-08-10 21:33 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext3547067461674825408.dll
2015-12-08 16:13 - 2015-12-08 16:13 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext3582601109642843821.dll
2016-07-19 16:58 - 2016-07-19 16:58 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext3632959286059685073.dll
2015-11-03 19:37 - 2015-11-03 19:37 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext3645369261435154005.dll
2015-11-04 13:45 - 2015-11-04 13:45 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext3728811933459157360.dll
2016-06-16 11:05 - 2016-06-16 11:05 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext376236734589993489.dll
2016-02-03 11:49 - 2016-02-03 11:49 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext3771783614819832373.dll
2016-01-19 13:09 - 2016-01-19 13:09 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext3831253954092960870.dll
2016-04-25 12:39 - 2016-04-25 12:39 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext3862766590378271749.dll
2016-02-03 11:59 - 2016-02-03 11:59 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext3880650978277736067.dll
2017-04-25 12:02 - 2017-04-25 12:02 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext3999035706403893609.dll
2015-12-04 11:45 - 2015-12-04 11:45 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext4148438026613017429.dll
2015-11-05 19:42 - 2015-11-05 19:42 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext421443006028540122.dll
2016-12-23 12:16 - 2016-12-23 12:16 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext4221036965169206932.dll
2016-12-05 20:50 - 2016-12-05 20:50 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext4333134748289330705.dll
2016-08-08 10:31 - 2016-08-08 10:31 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext4360345261882433226.dll
2016-08-10 17:12 - 2016-08-10 17:12 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext4396334001153822999.dll
2015-11-03 19:55 - 2015-11-03 19:55 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext4519509575656148328.dll
2015-12-11 13:11 - 2015-12-11 13:11 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext457642066180944725.dll
2015-11-30 17:51 - 2015-11-30 17:51 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext4678183524347596554.dll
2016-02-25 19:46 - 2016-02-25 19:46 - 0152576 ____N () C:\Users\editor\AppData\Local\Temp\ext488632496472135802.dll
2016-06-21 17:28 - 2016-06-21 17:28 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext4898600658738648022.dll
2017-04-26 18:43 - 2017-04-26 18:43 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext492206926580749312.dll
2017-06-13 16:49 - 2017-06-13 16:49 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext4983239252163645349.dll
2016-06-06 10:38 - 2016-06-06 10:38 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext4999928916769366800.dll
2016-12-13 12:42 - 2016-12-13 12:42 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext5036039854860822260.dll
2017-06-22 20:19 - 2017-06-22 20:19 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext5114781696799636751.dll
2016-03-04 20:12 - 2016-03-04 20:12 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext5139767144321286239.dll
2015-11-03 20:56 - 2015-11-03 20:56 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext5268417348436910702.dll
2017-01-27 05:54 - 2017-01-27 05:54 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext5286416144301495535.dll
2016-02-10 19:13 - 2016-02-10 19:13 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext5325854032330694098.dll
2017-06-19 17:45 - 2017-06-19 17:45 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext5342494215139559920.dll
2017-05-12 13:25 - 2017-05-12 13:25 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext5415927987645624840.dll
2015-12-09 19:26 - 2015-12-09 19:26 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext5456793605759750676.dll
2016-09-20 11:52 - 2016-09-20 11:52 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext5495596744398337494.dll
2016-01-28 20:34 - 2016-01-28 20:34 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext5519742628931322407.dll
2017-01-11 18:18 - 2017-01-11 18:18 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext5670253913556597081.dll
2017-01-27 06:04 - 2017-01-27 06:04 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext5695242686685089691.dll
2016-08-11 10:30 - 2016-08-11 10:30 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext5702430998017351286.dll
2016-09-30 13:33 - 2016-09-30 13:33 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext5721296887814790852.dll
2017-03-16 19:52 - 2017-03-16 19:52 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext5764401674546283438.dll
2017-06-23 14:40 - 2017-06-23 14:40 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext5774309492370009115.dll
2016-06-06 10:29 - 2016-06-06 10:29 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext577628823710051129.dll
2015-12-16 14:00 - 2015-12-16 14:00 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext589574615576507970.dll
2015-11-03 15:51 - 2015-11-03 15:51 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext5959308617025665169.dll
2016-06-17 10:50 - 2016-06-17 10:50 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext6147291925437994748.dll
2017-05-04 11:26 - 2017-05-04 11:26 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext61563072621552275.dll
2017-01-27 06:09 - 2017-01-27 06:09 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext6243305647609277638.dll
2015-11-24 11:15 - 2015-11-24 11:15 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext6264000069752568423.dll
2015-12-08 14:12 - 2015-12-08 14:12 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext6314329431092767208.dll
2017-05-12 14:15 - 2017-05-12 14:15 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext6326619680611514628.dll
2015-11-04 16:22 - 2015-11-04 16:22 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext6400257663228438677.dll
2016-04-25 11:08 - 2016-04-25 11:08 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext6405883880151987112.dll
2017-06-23 11:22 - 2017-06-23 11:22 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext6417672052045847144.dll
2017-04-27 12:04 - 2017-04-27 12:04 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext6450205877007966145.dll
2016-12-05 20:53 - 2016-12-05 20:53 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext6472259147865921929.dll
2017-04-10 12:36 - 2017-04-10 12:36 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext6545057915716711808.dll
2017-06-23 17:45 - 2017-06-23 17:45 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext6549777930575442372.dll
2016-12-22 21:02 - 2016-12-22 21:02 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext6574600315598065418.dll
2017-05-15 11:13 - 2017-05-15 11:13 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext6585627935289460830.dll
2017-06-06 12:52 - 2017-06-06 12:52 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext6629143606079133350.dll
2017-06-26 10:49 - 2017-06-26 10:49 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext6742382297477849267.dll
2016-02-25 11:37 - 2016-02-25 11:37 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext6835678782052956182.dll
2017-03-16 12:47 - 2017-03-16 12:47 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext688801886005781476.dll
2017-05-08 15:12 - 2017-05-08 15:12 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext7020022486612609402.dll
2015-10-27 10:42 - 2015-10-27 10:42 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext7066506078704847800.dll
2017-05-31 19:00 - 2017-05-31 19:00 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext707327277462235932.dll
2017-01-11 13:16 - 2017-01-11 13:16 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext7087696774860597994.dll
2015-11-04 13:30 - 2015-11-04 13:30 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext7144637721176901402.dll
2015-11-04 11:51 - 2015-11-04 11:51 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext7162592043594236485.dll
2017-01-11 21:26 - 2017-01-11 21:26 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext7211004424563206126.dll
2016-10-02 18:15 - 2016-10-02 18:15 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext7226956485726737268.dll
2017-06-06 12:25 - 2017-06-06 12:25 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext7229050651829048800.dll
2015-11-16 16:18 - 2015-11-16 16:18 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext7284758257686008523.dll
2015-12-08 16:08 - 2015-12-08 16:08 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext7294562210174342260.dll
2016-03-21 18:42 - 2016-03-21 18:42 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext7314094202278723315.dll
2016-03-09 14:10 - 2016-03-09 14:10 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext7347878871495292381.dll
2015-11-04 20:05 - 2015-11-04 20:05 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext7355951439687241441.dll
2016-01-20 13:02 - 2016-01-20 13:02 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext7365291522788142033.dll
2015-11-03 21:20 - 2015-11-03 21:20 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext7461020531561011148.dll
2017-06-14 10:39 - 2017-06-14 10:39 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext7469781079091889311.dll
2015-11-04 14:14 - 2015-11-04 14:14 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext749037931539721548.dll
2016-07-06 14:56 - 2016-07-06 14:56 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext7511071368232514677.dll
2017-04-27 12:36 - 2017-04-27 12:36 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext7610947742062987460.dll
2017-05-15 11:31 - 2017-05-15 11:31 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext7750742442214766394.dll
2015-11-04 14:40 - 2015-11-04 14:40 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext7788321599172764575.dll
2015-11-03 21:00 - 2015-11-03 21:00 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext7858416737919149772.dll
2017-04-05 11:14 - 2017-04-05 11:14 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext7866096943424427212.dll
2015-12-08 15:12 - 2015-12-08 15:12 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext7868478401755576745.dll
2016-02-25 11:42 - 2016-02-25 11:42 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext7952234657673263324.dll
2017-06-13 20:10 - 2017-06-13 20:10 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext8002046139409601734.dll
2017-01-27 05:59 - 2017-01-27 05:59 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext8058507083610037645.dll
2016-10-13 13:45 - 2016-10-13 13:45 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext806304567866090803.dll
2017-06-22 23:09 - 2017-06-22 23:09 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext8063051266009376708.dll
2016-07-06 15:38 - 2016-07-06 15:38 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext8063493851403517550.dll
2016-07-22 10:03 - 2016-07-22 10:03 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext806734091584293028.dll
2015-11-04 11:56 - 2015-11-04 11:56 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext8077446043908712965.dll
2016-03-18 16:31 - 2016-03-18 16:31 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext8080963830776677325.dll
2016-02-04 18:59 - 2016-02-04 18:59 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext8087831062423633985.dll
2017-04-17 11:08 - 2017-04-17 11:08 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext8136299661620296143.dll
2016-01-19 17:51 - 2016-01-19 17:51 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext8170218790396946275.dll
2016-09-18 19:13 - 2016-09-18 19:13 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext8232130495925374245.dll
2017-05-10 14:55 - 2017-05-10 14:55 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext8243045330470464255.dll
2016-12-15 18:24 - 2016-12-15 18:24 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext8287949911228513018.dll
2017-04-27 12:19 - 2017-04-27 12:19 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext8340037726148203461.dll
2017-02-21 11:04 - 2017-02-21 11:04 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext8342026742723814026.dll
2015-11-16 17:47 - 2015-11-16 17:47 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext8343189618411644959.dll
2015-11-04 14:02 - 2015-11-04 14:02 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext8344530914611328271.dll
2016-02-19 20:50 - 2016-02-19 20:50 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext8349521810803979349.dll
2015-12-08 15:04 - 2015-12-08 15:04 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext8406687461669924022.dll
2016-02-11 21:42 - 2016-02-11 21:42 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext8407409975011528703.dll
2015-11-04 13:49 - 2015-11-04 13:49 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext842836194662834067.dll
2015-12-02 17:11 - 2015-12-02 17:11 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext8476675325550759173.dll
2016-02-09 16:35 - 2016-02-09 16:35 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext8490449391639332834.dll
2017-01-11 13:21 - 2017-01-11 13:21 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext8495405909675811418.dll
2016-10-24 11:49 - 2016-10-24 11:50 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext8517292786496721413.dll
2017-06-23 12:55 - 2017-06-23 12:55 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext8618033682931287079.dll
2015-11-04 13:25 - 2015-11-04 13:25 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext8710206098169181479.dll
2016-01-05 12:50 - 2016-01-05 12:50 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext8781960756706951459.dll
2016-06-29 14:18 - 2016-06-29 14:18 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext8807036427242350904.dll
2016-09-27 15:56 - 2016-09-27 15:56 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext8935767832256560257.dll
2016-03-31 11:51 - 2016-03-31 11:51 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext8955451639592371649.dll
2017-01-11 21:16 - 2017-01-11 21:16 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext8962216957799883270.dll
2017-06-26 11:19 - 2017-06-26 11:19 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext8969235745113472060.dll
2016-01-15 20:40 - 2016-01-15 20:40 - 0110592 _____ () C:\Users\editor\AppData\Local\Temp\ext8994269622742200888.dll
2016-04-15 16:32 - 2016-04-15 16:32 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext9056070732631085523.dll
2017-04-25 11:34 - 2017-04-25 11:34 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext9213865936583327090.dll
2017-02-22 14:46 - 2017-02-22 14:46 - 2903480 _____ () C:\Users\editor\AppData\Local\Temp\npp.7.3.2.Installer.exe
2016-11-23 23:47 - 2016-11-23 23:47 - 14700056 _____ (Samsung Electronics                                         ) C:\Users\editor\AppData\Local\Temp\Samsung_Magician_Installer.exe
2015-12-08 14:33 - 2015-05-28 15:23 - 1162776 _____ (proDAD GmbH) C:\Users\editor\AppData\Local\Temp\uninstall.exe
2016-06-24 15:05 - 2016-06-24 15:05 - 30533688 _____ () C:\Users\editor\AppData\Local\Temp\vlc-2.2.4-win32.exe
 
Some zero byte size files/folders:
==========================
C:\Windows\System32\.exe
 
==================== Bamital & volsnap ======================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
 
LastRegBack: 2017-06-22 00:36
 
==================== End of FRST.txt ============================
 
 
 
 

Edited by rm540, 05 July 2017 - 03:16 PM.


#4 rm540

rm540
  • Topic Starter

  • Members
  • 13 posts
  • OFFLINE
  •  
  • Local time:06:14 PM

Posted 05 July 2017 - 03:07 PM

 
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 25-06-2017 01
Ran by editor (26-06-2017 20:04:10)
Running from C:\Users\editor\Downloads
Windows 7 Professional Service Pack 1 (X64) (2013-06-14 15:48:05)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
28A160AA3B364589BE10 (S-1-5-21-3225783554-34173836-2973484787-1011 - Limited - Enabled)
Administrator (S-1-5-21-3225783554-34173836-2973484787-500 - Administrator - Enabled) => C:\Users\Administrator
ASP.NET2 (S-1-5-21-3225783554-34173836-2973484787-1012 - Limited - Enabled)
ASPNET (S-1-5-21-3225783554-34173836-2973484787-1005 - Limited - Enabled)
Default (S-1-5-21-3225783554-34173836-2973484787-1013 - Administrator - Enabled) => C:\Users\Default.AVID4
editor (S-1-5-21-3225783554-34173836-2973484787-1001 - Administrator - Enabled) => C:\Users\editor
Guest (S-1-5-21-3225783554-34173836-2973484787-501 - Limited - Disabled)
iusr_serv (S-1-5-21-3225783554-34173836-2973484787-1015 - Administrator - Disabled)
IUSR_Servs (S-1-5-21-3225783554-34173836-2973484787-1014 - Administrator - Disabled) => C:\Users\IUSR_Servs
user (S-1-5-21-3225783554-34173836-2973484787-1000 - Administrator - Disabled) => C:\Users\user
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Microsoft Security Essentials (Enabled - Up to date) {71A27EC9-3DA6-45FC-60A7-004F623C6189}
AS: Microsoft Security Essentials (Enabled - Up to date) {CAC39F2D-1B9C-4A72-5A17-3B3D19BB2B34}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov)
Adobe Acrobat DC (HKLM-x32\...\{AC76BA86-1033-FFFF-7760-0C0F074E4100}) (Version: 17.009.20044 - Adobe Systems Incorporated)
Adobe Acrobat XI Pro (HKLM-x32\...\{23D3F585-AE29-4670-8E3E-64A0EFB29240}) (Version: 11.0 - Adobe Systems Incorporated)
Adobe After Effects CC 2014 (HKLM-x32\...\{2B22C750-5C3B-4738-B621-BA786AC7A494}) (Version: 13.0.0 - Adobe Systems Incorporated)
Adobe After Effects CC 2015 (HKLM-x32\...\{147EC100-14BE-45EF-AB42-35BAEE7D02F0}) (Version: 13.5.0 - Adobe Systems Incorporated)
Adobe After Effects CC 2017 (HKLM-x32\...\AEFT_14_2_1) (Version: 14.2.1 - Adobe Systems Incorporated)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 14.0.0.178 - Adobe Systems Incorporated)
Adobe Audition CC 2017 (HKLM-x32\...\AUDT_10_1_1) (Version: 10.1.1 - Adobe Systems Incorporated)
Adobe Bridge CC 2017 (HKLM-x32\...\KBRG_7_0) (Version: 7.0 - Adobe Systems Incorporated)
Adobe Character Animator CC (Beta) (HKLM-x32\...\ANMLBETA_1_0_6) (Version: 1.0.6 - Adobe Systems Incorporated)
Adobe Creative Cloud (HKLM-x32\...\Adobe Creative Cloud) (Version: 4.1.1.202 - Adobe Systems Incorporated)
Adobe Flash Player 26 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 26.0.0.131 - Adobe Systems Incorporated)
Adobe Flash Player 26 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 26.0.0.131 - Adobe Systems Incorporated)
Adobe Illustrator CC 2017 (HKLM-x32\...\ILST_21_1_0) (Version: 21.1.0 - Adobe Systems Incorporated)
Adobe InDesign CC 2017 (HKLM-x32\...\IDSN_12_1_0) (Version: 12.1.0 - Adobe Systems Incorporated)
Adobe Lightroom (HKLM-x32\...\{8048A5DF-8A70-5BE1-954B-E0FDE1BD0D0D}) (Version: 6.8 - Adobe Systems Incorporated)
Adobe Media Encoder CC 2014 (HKLM-x32\...\{663DEEEF-EF34-4DCB-8687-73A7AA146E02}) (Version: 8.0.0 - Adobe Systems Incorporated)
Adobe Media Encoder CC 2015 (HKLM-x32\...\{0FAC7130-BEC5-47A5-8813-1D339B8326ED}) (Version: 9.0.0 - Adobe Systems Incorporated)
Adobe Media Encoder CC 2017 (HKLM-x32\...\AME_11_1_2) (Version: 11.1.2 - Adobe Systems Incorporated)
Adobe Photoshop CC 2015.5 (HKLM-x32\...\PHSP_17_0_1) (Version: 17.0.1 - Adobe Systems Incorporated)
Adobe Photoshop CC 2017 (HKLM-x32\...\PHSP_18_1_1) (Version: 18.1.1 - Adobe Systems Incorporated)
Adobe Premiere Pro CC 2017 (HKLM-x32\...\PPRO_11_1_2) (Version: 11.1.2 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.03) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.03 - Adobe Systems Incorporated)
Adobe® Content Viewer (HKLM-x32\...\com.adobe.dmp.contentviewer) (Version: 3.4.3 - Adobe Systems, Incorporated)
AJA Adobe Win 12.3.7-x64 (HKLM\...\{92CAB133-E990-49AF-906D-652F4B9949F2}) (Version: 12.3.7 - AJA)
AJA ControlRoom 12.3.7-x64 (HKLM\...\{B0126CCD-F5D8-4DBB-AB9E-9A6D2C5B273F}) (Version: 12.3.7 - AJA)
AJA OpenIo Plug-in 12.3.7 (HKLM\...\{45672CDA-C35F-496E-9C15-0C684BAF566A}) (Version: 12.3.7 - AJA)
AJA Retail Installer 12.3.7-x64 (HKLM-x32\...\{c3aa5500-bf86-4ff0-ad33-16d3970fbf17}) (Version: 12.3.7 - AJA)
AJA Win Drivers 12.3.7-x64 (HKLM\...\{3520B7AF-BDA2-4D34-ACD7-C755989A3D8A}) (Version: 12.3.7 - AJA)
AJA Wirecast Plugin 12.3.7-x64 (HKLM\...\{276B90FA-77CB-4F27-9AC9-19FD97BA89F2}) (Version: 12.3.7 - AJA)
AnalogExif (HKLM-x32\...\AnalogExif) (Version: 0.0.4.1 - C-41 Bytes)
Ansel (Version: 372.70 - NVIDIA Corporation) Hidden
Apple Application Support (HKLM-x32\...\{46F044A5-CE8B-4196-984E-5BD6525E361D}) (Version: 2.3.6 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Aspera Connect 3.6.1.111228 (HKU\S-1-5-21-3225783554-34173836-2973484787-1001\...\Aspera Connect 3.6.1.111228) (Version: 3.6.1.111228 - © Copyright IBM Corp. 2014)
Aspera Connect 3.6.1.111228 (x32 Version: 3.6.1.111228 - © Copyright IBM Corp. 2014) Hidden
ASPI Repair (HKLM-x32\...\ASPI Repair) (Version:  - )
Autodesk 3ds Max 2018 (HKLM\...\Autodesk 3ds Max 2018) (Version: 20.0.0.966 - Autodesk)
Autodesk 3ds Max 2018 (Version: 20.0.0.966 - Autodesk) Hidden
Autodesk Advanced Material Library Image Library 2018 (HKLM-x32\...\{177AD7F6-9C77-4E50-BA53-B7259C5F282D}) (Version: 16.11.1.0 - Autodesk)
Autodesk Backburner 2018.0 (HKLM-x32\...\{0038F5AA-8482-4BB2-8A28-3FEA1D58D78A}) (Version: 18.0.0.0 - Autodesk)
Autodesk Certificate Package  (x64) - 5.1.4 (HKLM\...\{79D5E475-5EAB-4474-84F5-BD612337A175}) (Version: 5.1.4.100 - Autodesk)
Autodesk Civil View for 3ds Max 2018 64-bit (HKLM\...\{51C8EDF7-FFDA-430A-8B5E-1895FF14ACB7}) (Version: 20.0.0.0 - Autodesk)
Autodesk Desktop App (HKLM-x32\...\Autodesk Desktop App) (Version: 7.0.5.154 - Autodesk)
Autodesk Inventor Server Engine for 3ds Max 2018 (HKLM\...\{1984E20A-184B-4073-87F4-6755F3EE5769}) (Version: 20.0 - Autodesk)
Autodesk License Service (x64) - 5.1.4 (HKLM\...\{3609A8D9-FC0C-4C9B-9F58-0B1D1A4FE556}) (Version: 5.1.4.0 - Autodesk)
Autodesk Material Library 2018 (HKLM-x32\...\{7847611E-92E9-4917-B395-71C91D523104}) (Version: 16.11.1.0 - Autodesk)
Autodesk Material Library Base Resolution Image Library 2018 (HKLM-x32\...\{FCDED119-A969-4E48-8A32-D21AD6B03253}) (Version: 16.11.1.0 - Autodesk)
Autodesk Material Library Medium Resolution Image Library 2018 (HKLM-x32\...\{6EC5DA32-D02D-47D4-A3C4-988C1BC1A5FE}) (Version: 16.11.1.0 - Autodesk)
Autodesk Revit Interoperability for 3ds Max 2018 (HKLM\...\Autodesk Revit Interoperability for 3ds Max 2018) (Version: 18.0.0.412 - Autodesk)
Autodesk Revit Interoperability for 3ds Max 2018 (Version: 18.0.0.412 - Autodesk) Hidden
Autodesk SketchBook (HKLM\...\{E616AD44-B585-4460-9EBA-037B311F16EB}) (Version: 8.11.0000 - Autodesk)
Avid Application Manager (HKLM\...\{99E377DB-D2D0-44A5-8533-AA8BE1381644}) (Version: 2.5.12.13645 - Avid Technology, Inc.)
Avid Codecs PE (HKLM-x32\...\{22B25A58-6F1A-431B-82D9-38E56E05540A}) (Version: 2.5.1.38635 - Avid Technology, Inc.)
Avid DVD by Sonic (HKLM-x32\...\{353073E8-1185-4823-8F3A-A1F4AF6DD2CD}) (Version: 6.4.4 - Avid Technology)
Avid FX (64 Bit) (HKLM\...\{BE3248BC-8197-4B3F-AECA-CEE8E0FAED60}) (Version: 6.2.0 - Boris FX, Inc.)
Avid ISIS Client (HKLM\...\{2D892249-BB1D-46C7-98DF-73437484D05E}) (Version: 4.7.7.16070 - Avid)
Avid License Control (HKLM-x32\...\{F187D064-F101-4E95-8D05-4027809AA0F8}) (Version: 3.0.1 - Avid Technology, Inc.)
Avid Media Composer (HKLM\...\{95EB1E9C-F759-4427-8EEE-F96C48541A06}) (Version: 8.6.3.43955 - Avid Technology)
bl (x32 Version: 1.0.0 - Your Company Name) Hidden
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Boris RED 5 (64 Bit) CE (HKLM\...\{B7C36745-A262-4898-8E63-A884271E6DB9}) (Version: 5.6.0003 - Boris FX, Inc.)
Bulk Rename Utility 2.7.1.3 (HKLM\...\Bulk Rename Utility_is1) (Version:  - TGRMN Software)
CCleaner (HKLM\...\CCleaner) (Version: 5.11 - Piriform)
Chrome Remote Desktop Host (HKLM-x32\...\{BAF2702F-FB88-48E4-A305-588DB8FDD834}) (Version: 59.0.3071.47 - Google Inc.)
CINEMA 4D 16.050 (HKLM\...\MAXON8B6F11F9) (Version: 16.050 - MAXON Computer GmbH)
Cisco WebEx Meetings (HKLM-x32\...\ActiveTouchMeetingClient) (Version:  - Cisco WebEx LLC)
Color Suite v11.1.4 (HKLM-x32\...\{99487911-8011-42BC-B594-8B02BFD32B1D}_is1) (Version: 11.1.4 - Red Giant, LLC)
Corel WinDVD (HKLM-x32\...\{5C1F18D2-F6B7-4242-B803-B5A78648185D}) (Version: 10.0.6.369 - Corel Inc.)
CryptoPrevent (HKLM-x32\...\{5C5B24E7-4694-4049-A222-CCE7D3FAC63F}_is1) (Version:  - Foolish IT LLC)
DaVinci Resolve (HKLM\...\{2E7A93F9-2275-4EA1-A03F-4EB7EB573E7D}) (Version: 12.3.1001 - Blackmagic Design)
DirectX 9 Runtime (x32 Version: 1.00.0000 - Sonic Solutions) Hidden
Effects Suite v11.1.7 (HKLM-x32\...\{4DD8EE5E-F571-4EC8-9526-E7C62FE39B19}_is1) (Version: 11.1.7 - Red Giant, LLC)
Episode 7.0 (HKLM\...\{EF6132B9-F6CB-4679-A0E3-19B6EAB5CBA8}) (Version: 7.0.0.7204 - Telestream)
Eye Scream Factory Sampler Pack for Boris RED and Avid FX 64-Bit (HKLM\...\{E699A1D9-359D-46E4-BD82-F0C46D8F3A67}) (Version: 1.00.0000 - Boris FX, Inc.)
FileZilla Client 3.14.1 (HKLM-x32\...\FileZilla Client) (Version: 3.14.1 - Tim Kosse)
Flicker Free (HKLM\...\Flicker Free AVX2) (Version: 1.1.2 - Digital Anarchy, Inc.)
GenArts Sapphire Plug-ins 7.08 for Avid AVX Products (HKLM\...\GenArts Sapphire Plug-ins for Avid AVX_v6_is1) (Version:  - )
GenArts Sapphire Plug-ins 7.09 for After Effects and Compatible (HKLM\...\GenArts Sapphire AE_is1) (Version:  - )
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 58.0.3029.110 - Google Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.33.5 - Google Inc.) Hidden
HP Odometer (HKLM-x32\...\{B8AC1A89-FFD1-4F97-8051-E505A160F562}) (Version: 2.10.0000 - Hewlett-Packard)
HP Performance Advisor (HKLM-x32\...\{C6B87001-37EC-461E-AFE5-BECE03C47743}) (Version: 1.4.3926 - Hewlett-Packard Company)
HP Support Information (HKLM-x32\...\{B2B7B1C8-7C8B-476C-BE2C-049731C55992}) (Version: 11.00.0001 - Hewlett-Packard)
HP Vision Hardware Diagnostics (HKLM\...\{D79A02E9-6713-4335-9668-AAC7474C0C0E}) (Version: 2.12.1.0 - Hewlett-Packard)
HWiNFO64 Version 5.50 (HKLM\...\HWiNFO64_is1) (Version: 5.50 - Martin Malík - REALiX)
HxD Hex Editor version 1.7.7.0 (HKLM-x32\...\HxD Hex Editor_is1) (Version: 1.7.7.0 - Maël Hörz)
Inkscape 0.91 (HKLM\...\{81922150-317E-4BB0-A31D-FF1C14F707C5}) (Version: 0.91 - inkscape.org)
Intel® C++ Redistributables on Intel® 64 (HKLM-x32\...\{F70BCE36-25F2-4475-A918-6209B3D85BF3}) (Version: 15.0.179 - Intel Corporation)
Intel® Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
Intel® Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.1.21.1134 - Intel Corporation)
Intel® Network Connections 16.8.45.1 (HKLM\...\PROSetDX) (Version: 16.8.45.1 - Intel)
iSkysoft iTube Studio(Build 4.2.2.0) (HKLM-x32\...\iSkysoft iTube Studio_is1) (Version: 4.2.2.0 - iSkysoft Software)
iZotope Insight (HKLM-x32\...\iZotope Insight_is1) (Version: 1.04 - iZotope, Inc.)
iZotope RX 5 (HKLM-x32\...\iZotope RX 5_is1) (Version: 5.01 - iZotope, Inc.)
iZotope RX Loudness Control (HKLM-x32\...\iZotope RX Loudness Control_is1) (Version: 1.01 - iZotope, Inc.)
Java™ SE Runtime Environment 6 Update 6 (HKLM\...\{6448F0A8-6813-11D6-A77B-00B0D0160060}) (Version: 1.6.0.60 - ##ID_STRING_COMPANY_NAME##)
Keyspan USB Serial Adapter (HKLM-x32\...\{2E97DE76-851A-48AA-A0D6-665860FAD9CA}) (Version: 3.7.2 - Keyspan)
Malwarebytes version 3.1.2.1733 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.1.2.1733 - Malwarebytes)
MAXtoA for 3ds Max 2018 (HKLM\...\{471069C7-09E2-4289-8EB7-852237FD867E}) (Version: 1.0.712.0 - Solid Angle)
MediaInfo 0.7.89 (HKLM\...\MediaInfo) (Version: 0.7.89 - MediaArea.net)
MediaShuttlePlugin-v5.4 (HKLM-x32\...\{6B104C5D-6724-4779-B3D7-636C4E4033E8}) (Version: 5.4.3.70626 - Signiant Inc.)
MediaShuttlePlugin-v5.4 (HKLM-x32\...\{B0861461-F97C-4630-A406-3179C86267B6}) (Version: 5.4.2.68759 - Signiant Inc.)
Microsoft .NET Framework 1.1 (HKLM-x32\...\{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}) (Version: 1.1.4322 - Microsoft)
Microsoft .NET Framework 4.6.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.6.01055 - Microsoft Corporation)
Microsoft Mouse and Keyboard Center (HKLM\...\Microsoft Mouse and Keyboard Center) (Version: 1.1.500.0 - Microsoft Corporation)
Microsoft Office 365 - en-us (HKLM\...\O365HomePremRetail - en-us) (Version: 16.0.8201.2102 - Microsoft Corporation)
Microsoft Office Click-to-Run 2010 (HKLM-x32\...\Office14.Click2Run) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Starter 2010 - English (HKLM-x32\...\{90140011-0066-0409-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-3225783554-34173836-2973484787-1001\...\OneDriveSetup.exe) (Version: 17.3.6917.0607 - Microsoft Corporation)
Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.10.209.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6E8E85E8-CE4B-4FF5-91F7-04999C9FAE6A}) (Version: 8.0.50727.42 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729 (HKLM\...\{2DFD8316-9EF1-3210-908C-4CB61961C1AC}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{527BBE2F-1FED-3D8B-91CB-4DB0F838E69E}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24212 (HKLM-x32\...\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}) (Version: 14.0.24212.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24212 (HKLM-x32\...\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}) (Version: 14.0.24212.0 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Mozilla Firefox 46.0.1 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 46.0.1 (x86 en-US)) (Version: 46.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 46.0.1.5966 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
nablet XAVC XDCAM AMA Plug-In 4.0.3 (HKLM\...\{8AC11C50-D4A8-4053-8645-C037E05A90EA}_is1) (Version: 4.0.3.1146 - nablet GmbH)
NewBlue Titler Pro 2 for Avid (HKLM-x32\...\NewBlue Titler Pro 2 for Avid) (Version: 1.0 - NewBlue)
NewBlue Titler Pro 2.5 for Avid (HKLM-x32\...\NewBlue Titler Pro 2.5 for Avid) (Version: 1.0 - NewBlue)
NewBlue Titler Pro 4 (HKLM-x32\...\NewBlue Titler Pro 4) (Version: 1.0 - NewBlue)
Nik Collection (HKLM-x32\...\Nik Collection) (Version: 1.2.11 - Google)
Notepad++ (32-bit x86) (HKLM-x32\...\Notepad++) (Version: 7.3.2 - Notepad++ Team)
NVIDIA 3D Vision Controller Driver 369.04 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 369.04 - NVIDIA Corporation)
NVIDIA 3D Vision Driver 372.70 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 372.70 - NVIDIA Corporation)
NVIDIA Graphics Driver 372.70 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 372.70 - NVIDIA Corporation)
NVIDIA HD Audio Driver 1.3.34.15 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.15 - NVIDIA Corporation)
NVIDIA mental ray and IRay feature plugins for 3ds Max 2018 (HKLM\...\{C76BBD60-09DB-43B3-B5B0-BF00C80B500C}) (Version: 19.0.0.0 - Autodesk)
NVIDIA nView 148.03 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NView) (Version: 148.03 - NVIDIA Corporation)
NVIDIA WMI 2.18.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVWMI) (Version: 2.18.0 - NVIDIA Corporation)
Office 16 Click-to-Run Extensibility Component (x32 Version: 16.0.8201.2102 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Extensibility Component 64-bit Registration (Version: 16.0.8201.2102 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (Version: 16.0.8201.2102 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (x32 Version: 16.0.8201.2075 - Microsoft Corporation) Hidden
ON1 Effects 10 (HKLM\...\ON1 Effects 10 PE) (Version: 10.5.2 - ON1)
PACE License Support Win64 (HKLM-x32\...\InstallShield_{83E92696-D92D-4c7e-B094-0BE853B191FE}) (Version: 2.5.2.1034 - PACE Anti-Piracy, Inc.)
PACE License Support Win64 (Version: 2.5.2.1034 - PACE Anti-Piracy, Inc.) Hidden
PDF Complete Corporate Edition (HKLM-x32\...\PDF Complete) (Version: 4.2.11 - PDF Complete, Inc)
ph (x32 Version: 1.0.0 - Your Company Name) Hidden
QuickTime 7 (HKLM-x32\...\{80CEEB1E-0A6C-45B9-A312-37A1D25FDEBC}) (Version: 7.78.80.95 - Apple Inc.)
RAPID Mode (Version: 1.0.0.97 - Samsung Electronics Co., Ltd.) Hidden
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6449 - Realtek Semiconductor Corp.)
Red Giant Link (HKLM-x32\...\{10F82E5B-B611-4C65-8F29-666A9EC5680A}_is1) (Version: 1.9.7.36 - Red Giant, LLC)
RogueKiller version 12.11.4.0 (HKLM\...\8B3D7924-ED89-486B-8322-E8594065D5CB_is1) (Version: 12.11.4.0 - Adlice Software)
Roxio Creator Business (HKLM-x32\...\{537BF16E-7412-448C-95D8-846E85A1D817}) (Version: 10.3.56.24 - Roxio)
Samsung Data Migration (HKLM-x32\...\{3B304604-0BF5-488E-AB95-F2F2E31206F3}) (Version: 3.0 - Samsung)
Samsung Magician (HKLM-x32\...\{29AE3F9F-7158-4ca7-B1ED-28A73ECDB215}_is1) (Version: 5.0.0.790 - Samsung Electronics)
Sentinel Protection Installer 7.6.6 (HKLM-x32\...\{8C2218AC-D1B1-4530-9E67-15164E0E52AB}) (Version: 7.6.6 - SafeNet, Inc.)
ShareMouse v2.0.56 (HKLM-x32\...\ShareMouse_is1) (Version: 2.0.56 - Bartels Media GmbH)
Shooter Suite v12.3.2 (HKLM-x32\...\{7DFC5E36-8CC9-4EC5-9C24-A3770A669E3F}_is1) (Version: 12.3.2 - Red Giant, LLC)
Silicon Laboratories CP210x USB to UART Bridge (Driver Removal) (HKLM-x32\...\SLABCOMM&10C4&EA60) (Version:  - )
Slack (HKU\S-1-5-21-3225783554-34173836-2973484787-1001\...\slack) (Version: 2.6.3 - Slack Technologies)
Sonic CinePlayer Decoder Pack (x32 Version: 4.3.0 - Sonic Solutions) Hidden
Sorenson Squeeze (HKLM-x32\...\{AD11F61E-604D-4B15-8FC3-E587224CA3DE}) (Version: 10.1.0 - Sorenson Media)
Trapcode Suite v12.1.5 (HKLM-x32\...\{DFD2DC6B-C634-4C1C-81CC-5EF852E71CEE}_is1) (Version: 12.1.5 - Red Giant, LLC)
Tweaking.com - Windows Repair (HKLM-x32\...\Tweaking.com - Windows Repair) (Version: 3.6.2 - Tweaking.com)
UltraMon (HKLM\...\{D4E62D29-31A1-4938-8CB7-7D275C1AEAC6}) (Version: 3.3.0 - Realtime Soft Ltd)
Universe (HKLM\...\Universe Premium_is1) (Version: 2.1 CE - Team V.R)
VD64Inst (Version: 1.00.0000 - Roxio, Inc.) Hidden
VideoCopilot Element 3D v2.2.2 CE for After Effects (HKLM\...\Element 3D CE for After Effects_is1) (Version: 2.2.2 - Team V.R)
Visual C++ 64-bit Redistributables (HKLM-x32\...\InstallShield_{5B0E60DB-7741-412F-88B3-E6975D30D019}) (Version: 1.1.0.0929 - PACE Anti-Piracy, Inc.)
Visual C++ Redistributables (HKLM-x32\...\InstallShield_{C2AF7B2D-7018-414B-9B8B-D3C9F3BED04F}) (Version: 1.1.0.0929 - PACE Anti-Piracy, Inc.)
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.4 - VideoLAN)
Vulkan Run Time Libraries 1.0.11.1 (HKLM\...\VulkanRT1.0.11.1) (Version: 1.0.11.1 - LunarG, Inc.)
Wacom Tablet (HKLM\...\Wacom Tablet Driver) (Version: 6.3.22-6 - Wacom Technology Corp.)
WaveAgent (HKLM-x32\...\InstallShield_{053C7D32-3566-452B-9A37-D42B4F4C5379}) (Version: 1.20 - Sound Devices LLC)
WaveAgent (x32 Version: 1.20 - Sound Devices LLC) Hidden
WebShot (HKLM-x32\...\WebShot) (Version: 1.9.3.0 - Nathan Moinvaziri)
WebTablet FB Plugin 32 bit (HKLM-x32\...\Wacom WebTabletPlugin for Internet Explorer and Netscape) (Version: 2.1.0.7 - Wacom Technology Corp.)
WebTablet FB Plugin 64 bit (HKLM\...\Wacom WebTabletPlugin for Internet Explorer and Netscape) (Version: 2.1.0.7 - Wacom Technology Corp.)
WinDirStat 1.1.2 (HKU\S-1-5-21-3225783554-34173836-2973484787-1001\...\WinDirStat) (Version:  - )
Windows Driver Package - Graphics Tablet (WinUsb) USBDevice  (04/10/2014 8.33.30.0) (HKLM\...\142118DF51345EA02D2B1583E102C8FB95FD6D52) (Version: 04/10/2014 8.33.30.0 - Graphics Tablet)
WinRAR 5.30 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.30.0 - win.rar GmbH)
WinSCP 5.5.6 (HKLM-x32\...\winscp3_is1) (Version: 5.5.6 - Martin Prikryl)
Winsent Messenger 2.7.43 (HKLM-x32\...\Winsent Messenger_is1) (Version:  - Winsent Lab, hxxp://www.winsentmessenger.com)
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-3225783554-34173836-2973484787-1001_Classes\CLSID\{04A9E854-6F47-4F37-8A10-F896717F0329}\InprocServer32 -> C:\Users\editor\AppData\Local\Programs\Aspera\Aspera Connect\lib\3.6.1\npasperaweb64_3.6.1.111228.dll (Aspera, Inc. )
CustomCLSID: HKU\S-1-5-21-3225783554-34173836-2973484787-1001_Classes\CLSID\{073CB204-6B29-46FC-AB98-451F1D068741}\InprocServer32 -> C:\Program Files\Autodesk\3ds Max 2018\Inventor Server\Bin\TestServer.dll => No File
CustomCLSID: HKU\S-1-5-21-3225783554-34173836-2973484787-1001_Classes\CLSID\{162C6FB5-44D3-435B-903D-E613FA093FB5}\InprocServer32 -> C:\Users\editor\AppData\Local\Microsoft\OneDrive\17.3.6917.0607\amd64\FileCoAuthLib64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3225783554-34173836-2973484787-1001_Classes\CLSID\{869C14C8-1830-491F-B575-5F9AB40D2B42}\InprocServer32 -> C:\Program Files\MediaInfo\MediaInfo_InfoTip.dll (MediaArea.net)
CustomCLSID: HKU\S-1-5-21-3225783554-34173836-2973484787-1001_Classes\CLSID\{8C23B656-4E6E-4B45-9920-9617168D39A3}\InprocServer32 -> C:\Program Files\Autodesk\3ds Max 2018\Inventor Server\Bin\TestServer.dll => No File
CustomCLSID: HKU\S-1-5-21-3225783554-34173836-2973484787-1001_Classes\CLSID\{AD17B774-7F87-4141-BB9C-2AEE3841DC4E}\InprocServer32 -> C:\Users\editor\AppData\Local\Programs\Aspera\Aspera Connect\lib\3.6.1\npasperaweb64_3.6.1.111228.dll (Aspera, Inc. )
CustomCLSID: HKU\S-1-5-21-3225783554-34173836-2973484787-1001_Classes\CLSID\{E5B0515D-48D2-4F04-906D-0192ED65A2DD}\InprocServer32 -> C:\Program Files\Autodesk\3ds Max 2018\Inventor Server\Bin\TestServer.dll => No File
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {0DDA5EE2-D2E0-4ADE-BD48-1F32CA6DCD5C} - System32\Tasks\Process Explorer-AVID4-editor => C:\USERS\EDITOR\DOWNLOADS\PROCEXP.EXE [2017-06-23] (Sysinternals - www.sysinternals.com)
Task: {0EF41E0A-8599-47EC-B451-1F87CB5EA921} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2017-06-10] (Microsoft Corporation)
Task: {107F5220-5785-403C-B9D4-93FAC6E58E53} - System32\Tasks\{5246180D-17E9-44E7-B00B-84603AA4681C} => pcalua.exe -a C:\Users\editor\Downloads\aspichk.exe -d C:\Users\editor\Downloads
Task: {2A8E6DF7-4314-4C90-884B-CF825BE88B20} - System32\Tasks\{0EFF27C7-A00F-43B5-9BBB-3DA9480AFE18} => pcalua.exe -a "C:\Users\editor\Downloads\uclogiDriver 8 D20141212D20141211\Driver 8 D20141212D20141211\SETUP.EXE" -d "C:\Users\editor\Downloads\uclogiDriver 8 D20141212D20141211\Driver 8 D20141212D20141211"
Task: {2FF4CDC8-6D6F-48CF-9ABC-5CCD21277501} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-06-16] (Adobe Systems Incorporated)
Task: {3ECECB5E-2933-4B06-AACA-ABD72C29A8AB} - System32\Tasks\SamsungMagician => C:\Program Files (x86)\Samsung\Samsung Magician\SamsungMagician.exe [2016-11-23] (Samsung Electronics Co. Ltd.)
Task: {44C2B487-AE8E-444A-B9C5-D0415C9520F0} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-10-19] (Piriform Ltd)
Task: {4806DB2F-018D-4702-8C41-B3A4362CB64E} - System32\Tasks\Tweaking.com - Windows Repair Tray Icon => C:\Program Files (x86)\Tweaking.com\Windows Repair (All in One)\WR_Tray_Icon.exe [2015-03-11] (Tweaking.com)
Task: {5168BB0B-AFDB-4097-9422-D8692D7CFCEE} - System32\Tasks\{965FFC45-B3DE-4D68-BD13-E3D80302944E} => C:\Users\editor\Downloads\aspi_471a2 (1).exe [2014-10-27] ()
Task: {5A01A823-37CF-4176-81B8-6EF634EBB666} - System32\Tasks\GoogleUpdateTaskMachineCore1d15d7ca0fb01c1 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-04-17] (Google Inc.)
Task: {5A15F73D-212E-4ECC-BDD3-0AAF25F2172C} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerLogon => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2017-06-18] ()
Task: {5B8C7C78-D71A-404B-95AE-97BC06F12E7A} - System32\Tasks\{D7E4CE96-FB2C-4FB6-936E-5B9ADBF2CCD9} => pcalua.exe -a C:\Windows\SetupX32.EXE -c  /@SetupExt\Tablet
Task: {5E7853F5-DF7E-407E-ABAB-75795A6BD212} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerRegistration => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2017-06-18] ()
Task: {6169620B-D1E2-41F2-A717-C1EBD74F3C7E} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2017-04-25] (Adobe Systems Incorporated)
Task: {6FF82184-9BD1-4EC4-B0FA-5D61DA48FC03} - System32\Tasks\Microsoft_Hardware_Launch_devicecenter_exe => c:\Program Files\Microsoft Device Center\devicecenter.exe [2012-06-26] (Microsoft)
Task: {796FF54A-AE71-4FAD-9030-4C96266B5F51} - System32\Tasks\{53C8661A-82EF-4B48-BED6-4C1DC4A568A5} => C:\Users\editor\Downloads\aspi_471a2 (1).exe [2014-10-27] ()
Task: {7F73A9E3-5BC5-4AC8-B7F9-146A83F424B5} - System32\Tasks\{F5B0534F-1BB1-4ED1-A5E0-84F87BA35513} => C:\Users\editor\Downloads\drivers\MONOPRICE10594\Setup.exe [2013-08-29] ()
Task: {8E1EEBCE-440E-420F-BF4D-8F847FB96F21} - System32\Tasks\Microsoft_Hardware_Launch_itype_exe => c:\Program Files\Microsoft Device Center\itype.exe [2012-06-26] (Microsoft Corporation)
Task: {9580FB16-4879-4944-981A-ED5D591B8A68} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-04-17] (Google Inc.)
Task: {A518FE1D-5DFB-4D2F-BDF0-1932AB8171C4} - System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe => c:\Program Files\Microsoft Device Center\ipoint.exe [2012-06-26] (Microsoft Corporation)
Task: {ABBCDB46-A194-4C19-9F56-B2928D0265E3} - System32\Tasks\{71141076-B9FD-48ED-BB23-76DDA19B0BB2} => pcalua.exe -a C:\Windows\SetupX32.EXE -c  /@SetupExt\Tablet
Task: {ACDF5689-926F-4E8B-9F42-3318F2C394C7} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16\OLicenseHeartbeat.exe [2017-06-18] (Microsoft Corporation)
Task: {C7167073-F427-4B00-BE8F-24FBFC91E542} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2017-06-10] (Microsoft Corporation)
Task: {DB877B83-36FD-4C40-B4A1-781E71BEC92F} - System32\Tasks\Microsoft\Microsoft Antimalware\Microsoft Antimalware Scheduled Scan => c:\Program Files\Microsoft Security Client\\MpCmdRun.exe [2016-11-14] (Microsoft Corporation)
Task: {E4C66C6F-514F-43C0-BEF3-C748CA73ABAB} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-04-17] (Google Inc.)
Task: {ECE3BD73-146A-4415-BC6C-9FBFE09C994A} - System32\Tasks\AdobeAAMUpdater-1.0-AVID4-editor => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2016-07-01] (Adobe Systems Incorporated)
Task: {FDE60256-B011-48D7-9E6B-4043CB205F7C} - System32\Tasks\Red Giant Link => C:\Program Files (x86)\Red Giant Link\Red Giant Link.exe [2015-12-15] ()
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\Windows\Tasks\AdobeAAMUpdater-1.0-AVID4-Administrator.job => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe
Task: C:\Windows\Tasks\AdobeAAMUpdater-1.0-AVID4-editor.job => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
 
==================== Shortcuts & WMI ========================
 
(The entries could be listed to be restored or removed.)
 
 
ShortcutWithArgument: C:\Users\editor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Chrome Remote Desktop.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) ->  --profile-directory=Default --app-id=gbchcmhmhahfdphkhkmpfmihenigjmpp
 
==================== Loaded Modules (Whitelisted) ==============
 
2015-10-13 18:57 - 2014-09-12 07:56 - 02693448 _____ () C:\Windows\system32\nvwmi64.exe
2015-08-12 16:15 - 2015-08-12 16:15 - 07803392 _____ () c:\program files\avid\editor transcode\transcodeservice\jre\bin\server\jvm.dll
2015-11-09 08:37 - 2015-11-09 08:37 - 00006656 _____ () C:\Program Files\Telestream\Episode 7\bin\tseas.exe
2015-11-09 08:39 - 2015-11-09 08:39 - 00006656 _____ () C:\Program Files\Telestream\Episode 7\bin\tsecps.exe
2015-11-09 08:38 - 2015-11-09 08:38 - 00006144 _____ () C:\Program Files\Telestream\Episode 7\bin\tseioss.exe
2015-11-09 08:41 - 2015-11-09 08:41 - 00006656 _____ () C:\Program Files\Telestream\Episode 7\bin\tsejrs.exe
2015-11-09 08:38 - 2015-11-09 08:38 - 00008192 _____ () C:\Program Files\Telestream\Episode 7\bin\tsens.exe
2015-11-09 08:40 - 2015-11-09 08:40 - 00006656 _____ () C:\Program Files\Telestream\Episode 7\bin\tsexrs.exe
2015-11-09 08:36 - 2015-11-09 08:36 - 01325056 _____ () C:\Program Files\Telestream\Episode 7\bin\EpisodeClientProxy.exe
2015-11-09 08:36 - 2015-11-09 08:36 - 00397824 _____ () C:\Program Files\Telestream\Episode 7\bin\tsclientutil.dll
2015-11-09 08:36 - 2015-11-09 08:36 - 00257536 _____ () C:\Program Files\Telestream\Episode 7\bin\tscapi.dll
2015-11-09 08:36 - 2015-11-09 08:36 - 00249344 _____ () C:\Program Files\Telestream\Episode 7\bin\tsworkflow.dll
2015-11-09 08:36 - 2015-11-09 08:36 - 02664960 _____ () C:\Program Files\Telestream\Episode 7\bin\tscore.dll
2015-11-09 08:36 - 2015-11-09 08:36 - 00383488 _____ () C:\Program Files\Telestream\Episode 7\bin\tsbase.dll
2015-11-09 08:36 - 2015-11-09 08:36 - 00346112 _____ () C:\Program Files\Telestream\Episode 7\bin\tsnet.dll
2015-11-09 08:36 - 2015-11-09 08:36 - 00394752 _____ () C:\Program Files\Telestream\Episode 7\bin\EpisodeJSONRPCServer.exe
2015-11-09 08:36 - 2015-11-09 08:36 - 00475136 _____ () C:\Program Files\Telestream\Episode 7\bin\EpisodeXMLRPCServer.exe
2015-11-09 08:36 - 2015-11-09 08:36 - 01879552 _____ () C:\Program Files\Telestream\Episode 7\bin\EpisodeNode.exe
2015-11-09 08:36 - 2015-11-09 08:36 - 01344000 _____ () C:\Program Files\Telestream\Episode 7\bin\libxml2.dll
2015-11-09 08:36 - 2015-11-09 08:36 - 00077824 _____ () C:\Program Files\Telestream\Episode 7\bin\zlib1.dll
2015-11-09 08:36 - 2015-11-09 08:36 - 00684544 _____ () C:\Program Files\Telestream\Episode 7\bin\EpisodeIOServer.exe
2015-11-09 08:36 - 2015-11-09 08:36 - 01164288 _____ () C:\Program Files\Telestream\Episode 7\bin\EpisodeAssistant.exe
2015-11-09 08:36 - 2015-11-09 08:36 - 00813056 _____ () C:\Program Files\Telestream\Episode 7\bin\tsencode.dll
2015-11-09 08:36 - 2015-11-09 08:36 - 01641472 _____ () C:\Program Files\Telestream\Episode 7\bin\sys.dll
2015-11-09 08:36 - 2015-11-09 08:36 - 01735680 _____ () C:\Program Files\Telestream\Episode 7\bin\cm.dll
2015-11-09 08:36 - 2015-11-09 08:36 - 00064512 _____ () C:\Program Files\Telestream\Episode 7\bin\pw.dll
2015-11-09 08:36 - 2015-11-09 08:36 - 00146944 _____ () C:\Program Files\Telestream\Episode 7\bin\pwcore.dll
2015-11-09 08:36 - 2015-11-09 08:36 - 00025600 _____ () C:\Program Files\Telestream\Episode 7\bin\pwreport.dll
2017-05-26 03:18 - 2017-05-26 03:18 - 00492112 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll
2016-02-19 21:07 - 2017-06-18 03:51 - 08931008 _____ () C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\1033\GrooveIntlResource.dll
2015-10-16 06:02 - 2015-10-16 06:02 - 00043480 _____ () C:\Program Files\FileZilla FTP Client\fzshellext_64.dll
2017-02-12 18:31 - 2017-02-12 18:31 - 00230064 _____ () C:\Program Files (x86)\Notepad++\NppShell_06.dll
2017-05-15 11:26 - 2017-05-31 13:38 - 01658312 _____ () C:\Program Files\Tablet\Wacom\libxml2.dll
2016-09-01 19:18 - 2016-09-01 19:18 - 31302408 _____ () C:\Program Files\Avid\Avid Media Composer\il.dll
2016-09-01 19:18 - 2016-09-01 19:18 - 07266056 _____ () C:\Program Files\Avid\Avid Media Composer\ml.dll
2016-09-01 19:18 - 2016-09-01 19:18 - 04166920 _____ () C:\Program Files\Avid\Avid Media Composer\gk.dll
2016-09-01 19:18 - 2016-09-01 19:18 - 00403720 _____ () C:\Program Files\Avid\Avid Media Composer\mt.dll
2016-09-01 19:18 - 2016-09-01 19:18 - 04398344 _____ () C:\Program Files\Avid\Avid Media Composer\ilgpu.dll
2017-06-13 16:48 - 2017-06-13 16:48 - 02141184 _____ () C:\Users\editor\AppData\Local\slack\app-2.6.3\ffmpeg.dll
2017-06-13 16:48 - 2017-06-13 16:48 - 00211968 _____ () \\?\C:\Users\editor\AppData\Local\slack\app-2.6.3\resources\app.asar.unpacked\node_modules\nslog\build\Release\nslog.node
2017-06-13 16:48 - 2017-06-13 16:48 - 02551808 _____ () C:\Users\editor\AppData\Local\slack\app-2.6.3\libglesv2.dll
2017-06-13 16:48 - 2017-06-13 16:48 - 00093184 _____ () C:\Users\editor\AppData\Local\slack\app-2.6.3\libegl.dll
2017-06-13 16:48 - 2017-06-13 16:48 - 00089088 _____ () \\?\C:\Users\editor\AppData\Local\slack\app-2.6.3\resources\app.asar.unpacked\node_modules\@paulcbetts\system-idle-time\build\Release\system_idle_time.node
2016-12-07 12:13 - 2016-12-07 12:13 - 00012288 _____ () C:\Program Files\Avid\Application Manager\QtWebEngineProcess.exe
2015-08-12 17:15 - 2015-08-12 17:15 - 07803392 _____ () c:\program files\avid\application manager\jre\bin\server\jvm.dll
2017-06-26 11:19 - 2016-11-01 11:11 - 00017408 _____ () C:\Users\editor\AppData\Local\Temp\AppMan_jetty-TEMP\webapp\resources\FTF_JNI.dll
2017-06-26 11:19 - 2017-06-26 11:19 - 00152576 _____ () C:\Users\editor\AppData\Local\Temp\ext8969235745113472060.dll
2017-06-13 16:48 - 2017-06-13 16:48 - 00086528 _____ () \\?\C:\Users\editor\AppData\Local\slack\app-2.6.3\resources\app.asar.unpacked\node_modules\windows-quiet-hours\build\Release\quiethours.node
2017-06-13 16:48 - 2017-06-13 16:48 - 00412160 _____ () \\?\C:\Users\editor\AppData\Local\slack\app-2.6.3\resources\app.asar.unpacked\node_modules\@slack\slack-calls\build\Release\slack-calls.node
2017-06-13 16:48 - 2017-06-13 16:48 - 07493120 _____ () \\?\C:\Users\editor\AppData\Local\slack\app-2.6.3\resources\app.asar.unpacked\node_modules\@slack\slack-calls\build\Release\CallsCore.dll
2017-06-13 16:48 - 2017-06-13 16:48 - 01484288 _____ () \\?\C:\Users\editor\AppData\Local\slack\app-2.6.3\resources\app.asar.unpacked\node_modules\@slack\slack-calls\build\Release\boringssl.dll
2017-06-13 16:48 - 2017-06-13 16:48 - 00223744 _____ () \\?\C:\Users\editor\AppData\Local\slack\app-2.6.3\resources\app.asar.unpacked\node_modules\@slack\slack-calls\build\Release\protobuf_lite.dll
2017-06-13 16:48 - 2017-06-13 16:48 - 00482816 _____ () \\?\C:\Users\editor\AppData\Local\slack\app-2.6.3\resources\app.asar.unpacked\node_modules\@paulcbetts\spellchecker\build\Release\spellchecker.node
2017-06-13 16:48 - 2017-06-13 16:48 - 00156672 _____ () \\?\C:\Users\editor\AppData\Local\slack\app-2.6.3\resources\app.asar.unpacked\node_modules\keyboard-layout\build\Release\keyboard-layout-manager.node
2017-05-15 02:38 - 2017-05-15 02:38 - 34957896 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSync\CoreSync.exe
2017-03-16 10:15 - 2017-03-16 10:15 - 00108648 _____ () C:\Program Files\Adobe\Adobe InDesign CC 2017\ASLSupport.dll
2017-03-16 10:15 - 2017-03-16 10:15 - 01385064 _____ () C:\Program Files\Adobe\Adobe InDesign CC 2017\typekitC4.dll
2017-03-16 10:15 - 2017-03-16 10:15 - 02032232 _____ () C:\Program Files\Adobe\Adobe InDesign CC 2017\ZXPSignLib-minimal.dll
2017-03-16 10:15 - 2017-03-16 10:15 - 00448104 _____ () C:\Program Files\Adobe\Adobe InDesign CC 2017\ASKLib.dll
2017-03-16 10:15 - 2017-03-16 10:15 - 01263720 _____ () C:\Program Files\Adobe\Adobe InDesign CC 2017\AdobeGesture.dll
2017-03-16 10:15 - 2017-03-16 10:15 - 00368744 _____ () C:\Program Files\Adobe\Adobe InDesign CC 2017\AdamLib.dll
2017-03-16 10:15 - 2017-03-16 10:15 - 01327208 _____ () C:\Program Files\Adobe\Adobe InDesign CC 2017\ADBE_AGMFL.dll
2017-03-16 10:15 - 2017-03-16 10:15 - 00074856 _____ () C:\Program Files\Adobe\Adobe InDesign CC 2017\unihan.dll
2017-03-16 10:15 - 2017-03-16 10:15 - 57918568 _____ () C:\Program Files\Adobe\Adobe InDesign CC 2017\Resources\CEP\CEPHtmlEngine\libcef.dll
2017-03-16 10:15 - 2017-03-16 10:15 - 01899112 _____ () C:\Program Files\Adobe\Adobe InDesign CC 2017\Resources\CEP\CEPHtmlEngine\libglesv2.dll
2017-03-16 10:15 - 2017-03-16 10:15 - 00093288 _____ () C:\Program Files\Adobe\Adobe InDesign CC 2017\Resources\CEP\CEPHtmlEngine\libegl.dll
2017-05-16 01:03 - 2017-05-09 05:13 - 03767640 _____ () C:\Program Files (x86)\Google\Chrome\Application\58.0.3029.110\libglesv2.dll
2017-05-16 01:03 - 2017-05-09 05:13 - 00100696 _____ () C:\Program Files (x86)\Google\Chrome\Application\58.0.3029.110\libegl.dll
2017-05-08 14:40 - 2017-03-10 06:48 - 00061944 _____ () C:\Program Files (x86)\Autodesk\Autodesk Desktop App\QtSolutions_Service-head.dll
2017-05-08 14:40 - 2017-03-10 06:48 - 00110584 _____ () C:\Program Files (x86)\Autodesk\Autodesk Desktop App\qjson0.dll
2017-06-04 07:19 - 2017-06-04 07:19 - 52051552 _____ () C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\CEF\libcef.dll
2017-05-08 14:40 - 2015-11-05 08:07 - 00052224 _____ () C:\Program Files (x86)\Autodesk\Autodesk Desktop App\qoauth_Ad_1.dll
2017-05-08 14:40 - 2015-11-05 08:07 - 00742400 _____ () C:\Program Files (x86)\Autodesk\Autodesk Desktop App\qca_Ad_2.dll
2017-05-08 14:40 - 2015-11-05 08:07 - 00195584 _____ () C:\Program Files (x86)\Autodesk\Autodesk Desktop App\qjson_Ad_0.dll
2017-05-08 14:40 - 2013-09-23 13:52 - 00043912 _____ () C:\Program Files (x86)\Autodesk\Autodesk Desktop App\QtSolutions_MFCMigrationFramework_Ad_2.dll
2017-05-08 14:40 - 2017-03-10 06:21 - 00279976 _____ () C:\Program Files (x86)\Autodesk\Autodesk Desktop App\en-US\AdWingManRes.dll
2017-05-08 14:40 - 2015-09-08 02:31 - 40640808 _____ () C:\Program Files (x86)\Autodesk\Autodesk Desktop App\acwebbrowser\libcef.dll
2017-05-08 14:40 - 2014-09-02 20:29 - 00912384 _____ () C:\Program Files (x86)\Autodesk\Autodesk Desktop App\acwebbrowser\libglesv2.dll
2017-05-08 14:40 - 2014-09-02 20:29 - 00134144 _____ () C:\Program Files (x86)\Autodesk\Autodesk Desktop App\acwebbrowser\libegl.dll
2017-05-08 14:40 - 2014-09-02 20:29 - 00950272 _____ () C:\Program Files (x86)\Autodesk\Autodesk Desktop App\acwebbrowser\ffmpegsumo.dll
2015-10-16 06:02 - 2015-10-16 06:02 - 00039384 _____ () C:\Program Files\FileZilla FTP Client\fzshellext.dll
2017-05-30 01:39 - 2017-05-30 01:39 - 00118272 _____ () \\?\C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\js\node_modules\fs-ext\build\Release\fs-ext.node
2017-05-30 01:39 - 2017-05-30 01:39 - 00214528 _____ () \\?\C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\js\node_modules\node-vulcanjs\build\Release\VulcanJS.node
2017-05-30 01:38 - 2017-05-30 01:38 - 00117248 _____ () \\?\C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\js\node_modules\ref\build\Release\binding.node
2017-05-30 01:39 - 2017-05-30 01:39 - 00125952 _____ () \\?\C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\js\node_modules\ffi\build\Release\ffi_bindings.node
2017-06-04 07:47 - 2017-06-04 07:47 - 00110688 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\js\node_modules\node-ProxyResolver\build\Release\ProxyResolverWin7.dll
2017-05-30 01:39 - 2017-05-30 01:39 - 00086528 _____ () \\?\C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCXProcess\js\node_modules\idle-gc\build\Release\idle-gc.node
2017-05-19 23:49 - 2017-05-19 23:49 - 00118272 _____ () \\?\C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\js\node_modules\fs-ext\build\Release\fs-ext.node
2017-05-19 23:49 - 2017-05-19 23:49 - 00117760 _____ () \\?\C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\js\node_modules\ref\build\Release\binding.node
2017-05-19 23:49 - 2017-05-19 23:49 - 00125440 _____ () \\?\C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\js\node_modules\ffi\build\Release\ffi_bindings.node
2017-05-19 23:50 - 2017-05-19 23:50 - 00214528 _____ () \\?\C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\js\node_modules\node-vulcanjs\build\Release\VulcanJS.node
2017-06-04 07:43 - 2017-06-04 07:43 - 00110688 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\js\node_modules\node-ProxyResolver\build\Release\ProxyResolverWin7.dll
2017-05-19 23:49 - 2017-05-19 23:49 - 00098816 _____ () \\?\C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\js\node_modules\bufferutil\build\Release\bufferutil.node
2017-05-19 23:50 - 2017-05-19 23:50 - 00086528 _____ () \\?\C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CCLibrary\js\node_modules\idle-gc\build\Release\idle-gc.node
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
AlternateDataStreams: C:\ProgramData\Microsoft:0LzQmy2yLXIkuOxWrd [1910]
AlternateDataStreams: C:\ProgramData\Microsoft:kcBk6PcxHyvHjtR8 [2314]
AlternateDataStreams: C:\ProgramData\Microsoft:lIp54pnOEvBhOzqQjZpz2nn [2310]
AlternateDataStreams: C:\ProgramData\Microsoft:Ocomea4gZtY3lSOUf5iphCE [2038]
AlternateDataStreams: C:\ProgramData\Microsoft:v3g4yepAVzDTtez7meXIUiueJ [1956]
AlternateDataStreams: C:\ProgramData\Microsoft:Xm9UIZv3H4zTt7eqpuDLw7zIg [2260]
AlternateDataStreams: C:\ProgramData\PACE:B90686C2DDD4C048 [217]
AlternateDataStreams: C:\Users\editor\Cookies:EOqXQzoQSm4Yr9HXggRR4KKY [1930]
AlternateDataStreams: C:\Users\editor\Downloads\PICKUPS1.avb:BINSTATE_RSRC [131074]
AlternateDataStreams: C:\Users\editor\Downloads\TrueLife_FullScreenCredits_CreditCrunch.avb:BINSTATE_RSRC [131074]
AlternateDataStreams: C:\Users\editor\AppData\Local\Temporary Internet Files:KXXPwIqcZrAoHR5V6MIVZYrg [2354]
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\74966351.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppXSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BFE => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BITS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ClipSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMSwissArmy => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MpsSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\msiserver => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SharedAccess => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vss => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WSService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\74966351.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\AppXSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\BITS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ClipSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMSwissArmy => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\msiserver => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\vss => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WSService => ""="Service"
 
==================== Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
 
==================== Hosts content: ===============================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2009-07-13 22:34 - 2015-11-04 16:14 - 00000855 _____ C:\Windows\system32\Drivers\etc\hosts
 
127.0.0.1       localhost
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-3225783554-34173836-2973484787-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\editor\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
HKU\S-1-5-21-3225783554-34173836-2973484787-500\Control Panel\Desktop\\Wallpaper -> C:\Windows\BGInfo.bmp
DNS Servers: 223.5.5.5 - 8.8.8.8
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 2) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [SPPSVC-In-TCP-NoScope] => (Allow) %SystemRoot%\system32\sppsvc.exe
FirewallRules: [SPPSVC-In-TCP] => (Allow) %SystemRoot%\system32\sppsvc.exe
FirewallRules: [RemoteAssistance-PnrpSvc-UDP-In-EdgeScope-Active] => (Block) %systemroot%\system32\svchost.exe
FirewallRules: [RemoteAssistance-SSDPSrv-In-TCP-Active] => (Block) %SystemRoot%\system32\svchost.exe
FirewallRules: [RemoteAssistance-SSDPSrv-In-UDP-Active] => (Block) %SystemRoot%\system32\svchost.exe
FirewallRules: [RemoteAssistance-In-TCP-EdgeScope-Active] => (Block) %SystemRoot%\system32\msra.exe
FirewallRules: [RemoteAssistance-DCOM-In-TCP-NoScope-Active] => (Block) %SystemRoot%\system32\svchost.exe
FirewallRules: [RemoteAssistance-RAServer-In-TCP-NoScope-Active] => (Block) %SystemRoot%\system32\raserver.exe
FirewallRules: [RemoteAssistance-PnrpSvc-UDP-In-EdgeScope] => (Block) %systemroot%\system32\svchost.exe
FirewallRules: [RemoteAssistance-In-TCP-EdgeScope] => (Block) %SystemRoot%\system32\msra.exe
FirewallRules: [{9B6A2586-F0AB-48CB-878E-1A6C2000D9AF}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe
FirewallRules: [TCP Query User{2C488D4F-A675-4832-853F-8FEF66C4B594}C:\program files\avid\isis client\client manager\isisclientmanager.exe] => (Allow) C:\program files\avid\isis client\client manager\isisclientmanager.exe
FirewallRules: [UDP Query User{6DF6029E-154C-4FB8-9B45-8831203EFCB1}C:\program files\avid\isis client\client manager\isisclientmanager.exe] => (Allow) C:\program files\avid\isis client\client manager\isisclientmanager.exe
FirewallRules: [TCP Query User{1967308B-3F51-4509-8A4F-5390912CA74B}C:\program files\avid\application manager\avidapplicationmanager.exe] => (Allow) C:\program files\avid\application manager\avidapplicationmanager.exe
FirewallRules: [UDP Query User{3BE96BB9-C69D-478C-9089-C0BE822C15EB}C:\program files\avid\application manager\avidapplicationmanager.exe] => (Allow) C:\program files\avid\application manager\avidapplicationmanager.exe
FirewallRules: [TCP Query User{204239F4-7F02-4DD8-BDA5-BF4B85370105}C:\program files\avid\application manager\avidappmanhelper.exe] => (Allow) C:\program files\avid\application manager\avidappmanhelper.exe
FirewallRules: [UDP Query User{DFC04E97-9E31-43E7-82AE-EACE469AE657}C:\program files\avid\application manager\avidappmanhelper.exe] => (Allow) C:\program files\avid\application manager\avidappmanhelper.exe
FirewallRules: [TCP Query User{B193B375-6183-4ABA-AF3F-8F8201613AF5}C:\program files (x86)\google\chrome\application\chrome.exe] => (Allow) C:\program files (x86)\google\chrome\application\chrome.exe
FirewallRules: [UDP Query User{330B848E-1632-4674-A135-CB38DF5FE133}C:\program files (x86)\google\chrome\application\chrome.exe] => (Allow) C:\program files (x86)\google\chrome\application\chrome.exe
FirewallRules: [TCP Query User{195B8285-BCF0-4D13-9EBD-7887319FC856}C:\program files\adobe\adobe after effects cc 2017\support files\afterfx.exe] => (Allow) C:\program files\adobe\adobe after effects cc 2017\support files\afterfx.exe
FirewallRules: [UDP Query User{BDF17BDE-DD71-4860-BB71-6DDCEEE4960D}C:\program files\adobe\adobe after effects cc 2017\support files\afterfx.exe] => (Allow) C:\program files\adobe\adobe after effects cc 2017\support files\afterfx.exe
FirewallRules: [TCP Query User{84484BEA-0A5E-47B6-A368-B8155D3192C4}C:\program files\avid\avid media composer\avidmediacomposer.exe] => (Allow) C:\program files\avid\avid media composer\avidmediacomposer.exe
FirewallRules: [UDP Query User{A27DBAAC-18F9-4492-9CF2-376B7874EADE}C:\program files\avid\avid media composer\avidmediacomposer.exe] => (Allow) C:\program files\avid\avid media composer\avidmediacomposer.exe
FirewallRules: [{52D9026E-06B7-408C-9C8D-D7AF02E7E7C0}] => (Block) %SystemRoot%\system32\raserver.exe
FirewallRules: [{3C4F6AB9-5B34-4267-858E-1DA392BFAC90}] => (Block) %SystemRoot%\system32\raserver.exe
FirewallRules: [{EBCEF1CA-26D6-4F1F-B888-9CCFD5A246A4}] => (Allow) %ProgramFiles%\Avid\Avid Media Composer\AvidMediaComposer.exe
 
==================== Restore Points =========================
 
23-06-2017 15:43:55 Installed Boris RED 5 (64 Bit) CE.
26-06-2017 10:46:46 Windows Update
26-06-2017 11:15:05 RAPID
 
==================== Faulty Device Manager Devices =============
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (06/26/2017 07:33:43 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program AvidMediaComposer.exe version 8.6.3.43955 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
 
Process ID: 4948
 
Start Time: 01d2eed232b06595
 
Termination Time: 34
 
Application Path: C:\Program Files\Avid\Avid Media Composer\AvidMediaComposer.exe
 
Report Id: dbd02b69-5ac7-11e7-b3ed-6c3be50dbb03
 
Error: (06/26/2017 11:28:43 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "C:\Program Files\Common Files\Autodesk Shared\Revit Interoperability 2018\Rx\AdskFaroConverter.exe".
Dependent Assembly FARO.LS,processorArchitecture="amd64",publicKeyToken="1d23f5635ba800ab",type="Win32",version="1.1.504.2" could not be found.
Please use sxstrace.exe for detailed diagnosis.
 
Error: (06/26/2017 11:27:51 AM) (Source: CVHSVC) (EventID: 100) (User: )
Description: Information only.
(Patch task for {90140011-0066-0409-0000-0000000FF1CE}): DownloadLatest Failed: HTTP status 403: The client does not have sufficient access rights to the requested server object.
 
Error: (06/26/2017 11:17:51 AM) (Source: Application Virtualization Client) (EventID: 3008) (User: )
Description: {hap=11:app=OfficeVirt 9014006604090000:tid=1950}
The client was unable to connect to an Application Virtualization Server (rc 24604E0A-40000193)
 
Error: (06/26/2017 11:17:51 AM) (Source: Application Virtualization Client) (EventID: 5009) (User: )
Description: {hap=11:app=OfficeVirt 9014006604090000:tid=1950}
The Application Virtualization Client could not connect to stream URL 'http://c2r.microsoft.com/ConsumerC2R/en-us/14.0.4763.1000/ConsumerC2R.en-us_14.0.4763.1000.sft' (rc 24604E0A-40000193, original rc 24604E0A-40000193).
 
Error: (06/23/2017 09:48:24 PM) (Source: AvidFosPerf) (EventID: 2005) (User: )
Description: Unable to read the "First Counter" value 
under the AvidFos\Performance key.
Status code returned in data. Has LODCTR
been run?
 
Error: (06/23/2017 05:53:25 PM) (Source: CVHSVC) (EventID: 100) (User: )
Description: Information only.
(Patch task for {90140011-0066-0409-0000-0000000FF1CE}): DownloadLatest Failed: HTTP status 403: The client does not have sufficient access rights to the requested server object.
 
Error: (06/23/2017 05:43:14 PM) (Source: Application Virtualization Client) (EventID: 3008) (User: )
Description: {hap=11:app=OfficeVirt 9014006604090000:tid=1930}
The client was unable to connect to an Application Virtualization Server (rc 24604E0A-40000193)
 
Error: (06/23/2017 05:43:14 PM) (Source: Application Virtualization Client) (EventID: 5009) (User: )
Description: {hap=11:app=OfficeVirt 9014006604090000:tid=1930}
The Application Virtualization Client could not connect to stream URL 'http://c2r.microsoft.com/ConsumerC2R/en-us/14.0.4763.1000/ConsumerC2R.en-us_14.0.4763.1000.sft' (rc 24604E0A-40000193, original rc 24604E0A-40000193).
 
Error: (06/23/2017 05:00:19 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: 604: DNSServiceQueryRecord      AVID4._episode-node._tcp.local. (TXT)
 
 
System errors:
=============
Error: (06/26/2017 07:54:43 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Avid Fos FS service terminated unexpectedly.  It has done this 1 time(s).
 
Error: (06/26/2017 11:24:40 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Chrome Remote Desktop Service service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 60000 milliseconds: Restart the service.
 
Error: (06/26/2017 11:18:27 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Peer Networking Grouping service depends on the Peer Name Resolution Protocol service which failed to start because of the following error: 
%%-2140993535
 
Error: (06/26/2017 11:18:27 AM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The Peer Name Resolution Protocol service terminated with the following error: 
%%-2140993535
 
Error: (06/26/2017 11:18:27 AM) (Source: PNRPSvc) (EventID: 102) (User: )
Description: The Peer Name Resolution Protocol cloud did not start because the creation of the default identity failed with error code: 0x80630801.
 
Error: (06/26/2017 11:17:25 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the NVIDIA Display Driver Service service to connect.
 
Error: (06/26/2017 11:15:56 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Peer Networking Grouping service depends on the Peer Name Resolution Protocol service which failed to start because of the following error: 
%%-2140993535
 
Error: (06/26/2017 11:15:56 AM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The Peer Name Resolution Protocol service terminated with the following error: 
%%-2140993535
 
Error: (06/26/2017 10:48:09 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Peer Networking Grouping service depends on the Peer Name Resolution Protocol service which failed to start because of the following error: 
%%-2140993535
 
Error: (06/26/2017 10:48:09 AM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The Peer Name Resolution Protocol service terminated with the following error: 
%%-2140993535
 
 
CodeIntegrity:
===================================
  Date: 2017-05-11 13:52:44.866
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\l3codeca.acm because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-10-16 15:15:17.573
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\l3codeca.acm because the set of per-page image hashes could not be found on the system.
 
  Date: 2013-06-17 07:42:46.421
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\l3codeca.acm because the set of per-page image hashes could not be found on the system.
 
  Date: 2013-06-14 17:29:48.328
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\l3codeca.acm because the set of per-page image hashes could not be found on the system.
 
  Date: 2013-06-14 17:01:00.590
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\l3codeca.acm because the set of per-page image hashes could not be found on the system.
 
  Date: 2013-06-14 16:17:21.451
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\l3codeca.acm because the set of per-page image hashes could not be found on the system.
 
  Date: 2013-06-14 16:11:07.312
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\l3codeca.acm because the set of per-page image hashes could not be found on the system.
 
  Date: 2013-06-14 15:24:34.421
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\l3codeca.acm because the set of per-page image hashes could not be found on the system.
 
  Date: 2013-06-14 15:00:47.719
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\l3codeca.acm because the set of per-page image hashes could not be found on the system.
 
 
==================== Memory info =========================== 
 
Processor: Intel® Xeon® CPU E5-1650 0 @ 3.20GHz
Percentage of memory in use: 50%
Total physical RAM: 24499.58 MB
Available physical RAM: 12122.75 MB
Total Virtual: 48997.34 MB
Available Virtual: 37437.01 MB
 
==================== Drives ================================
 
Drive c: (OS) (Fixed) (Total:465.66 GB) (Free:103.89 GB) NTFS
Drive d: (MONOPRICE10594) (CDROM) (Total:0.02 GB) (Free:0 GB) CDFS
Drive s: (Project) (Network) (Total:25 GB) (Free:23.74 GB) AVIDFOS
Drive t: (Media) (Network) (Total:1600 GB) (Free:121.81 GB) AVIDFOS
Drive u: (Development_Renders) (Network) (Total:55 GB) (Free:0.9 GB) AVIDFOS
Drive v: (Development_Projects) (Network) (Total:100 GB) (Free:22.77 GB) AVIDFOS
Drive w: (Development_Media3) (Network) (Total:1500 GB) (Free:68.34 GB) AVIDFOS
Drive x: (Development_Media2) (Network) (Total:750 GB) (Free:26.04 GB) AVIDFOS
Drive y: (Development_Media) (Network) (Total:3965 GB) (Free:10.41 GB) AVIDFOS
Drive z: (Development_Exports) (Network) (Total:40 GB) (Free:11.33 GB) AVIDFOS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (Size: 465.8 GB) (Disk ID: B068F196)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=465.7 GB) - (Type=07 NTFS)
 
==================== End of Addition.txt ============================

Malwarebytes Anti-Rootkit BETA 1.9.3.1001
www.malwarebytes.org
 
Database version:
  main:    v2017.07.05.05
  rootkit: v2017.05.27.01
 
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 11.0.9600.18697
editor :: AVID4 [administrator]
 
7/5/2017 3:37:59 PM
mbar-log-2017-07-05 (15-37-59).txt
 
Scan type: Quick scan
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken
Scan options disabled: 
Objects scanned: 466179
Time elapsed: 12 minute(s), 11 second(s)
 
Memory Processes Detected: 0
(No malicious items detected)
 
Memory Modules Detected: 0
(No malicious items detected)
 
Registry Keys Detected: 0
(No malicious items detected)
 
Registry Values Detected: 0
(No malicious items detected)
 
Registry Data Items Detected: 0
(No malicious items detected)
 
Folders Detected: 0
(No malicious items detected)
 
Files Detected: 0
(No malicious items detected)
 
Physical Sectors Detected: 0
(No malicious items detected)
 
(end)

Edited by rm540, 05 July 2017 - 03:19 PM.


#5 Jo*

Jo*

  • Malware Response Team
  • 3,293 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Germany
  • Local time:12:14 AM

Posted 05 July 2017 - 04:33 PM

Hello,

:step1: Run Malwarebytes Anti-Rootkit again: Double click mbar.exe to run the tool.
Vista / Windows 7/8/10 users right-click and select Run As Administrator.
  • Scan your system for malware
  • If malware is found, click on the Cleanup button to remove any threats and reboot if prompted to do so.
  • Wait while the system shuts down and the cleanup process is performed.
  • then please go to the MBAR folder and then copy/paste the contents of the MBAR-log-***.txt file to your next reply.
  • If there is no malware found, please let me know as well.

***


:step2: Double click on AdwCleaner.exe to run the tool again.
Vista / Windows 7/8/10 users right-click and select Run As Administrator.
  • Click on the Scan button.
  • AdwCleaner will begin...be patient as the scan may take some time to complete.
  • After the scan has finished, click on the Clean button.
  • Press OK when asked to close all programs and follow the onscreen prompts.
  • Press OK again to allow AdwCleaner to restart the computer and complete the removal process.
  • After rebooting, a logfile report (AdwCleaner[C#].txt) will open automatically (where the largest value of # represents the most recent report).
  • Copy and paste the contents of that logfile in your next reply.
  • A copy of that logfile will also be saved in the C:\AdwCleaner folder.

***


:step3: Please download Junkware Removal Tool from HERE and save it to your desktop.
Shutdown your antivirus to avoid any potential conflicts.
Double click JRT.exe to run the tool.
Vista / Windows 7/8/10 users right-click and select Run As Administrator.
  • JRT will begin to backup your registry and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, the log JRT.txt is saved on your desktop and will automatically open.
Enable your antivirus!
Post the contents of JRT.txt into your next reply.


***


:step4: How the computer is running now?


***


:step5: FRST / FSRT64: run it again.
  • Right-click FRST / FSRT64 then click "Run as administrator" (XP users: click run after receipt of Windows Security Warning - Open File).
  • When the tool opens, click Yes to disclaimer.
  • Put a check into the boxes next to Addition.txt and Shortcut.txt. Then press the Scan button.
  • When finished, it will produce logs called FRST.txt, Shortcut.txt and Addition.txt in the same directory the tool was run from.
  • Please copy and paste both logs in your next reply.
---------

Graduate of the WTT Classroom
Cheers,
Jo
If I have been helping you, and I have not replied to your latest post in 36 hours please send me a PM.


#6 rm540

rm540
  • Topic Starter

  • Members
  • 13 posts
  • OFFLINE
  •  
  • Local time:06:14 PM

Posted 05 July 2017 - 06:53 PM

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.1.3 (04.10.2017)
Operating System: Windows 7 Professional x64 
Ran by editor (Administrator) on Wed 07/05/2017 at 19:37:28.29
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
 
 
 
File System: 8 
 
Successfully deleted: C:\Users\editor\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5ULI4W42 (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\editor\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BQVHCGOY (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\editor\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BR0EETQL (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\editor\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PF4SLRQJ (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5ULI4W42 (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BQVHCGOY (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BR0EETQL (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PF4SLRQJ (Temporary Internet Files Folder) 
 
 
 
Registry: 0 
 
 
 
 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Wed 07/05/2017 at 19:38:59.62
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
 
Users shortcut scan result (x64) Version: 05-07-2017
Ran by editor (05-07-2017 19:50:03)
Running from C:\Users\editor\Downloads
Boot Mode: Normal
 
==================== Shortcuts =============================
 
(The entries could be listed to be restored or removed.)
 
 
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Inkscape 0.91\Inkscape Homepage.lnk -> hxxp://www.inkscape.org
 
 
Shortcut: C:\Users\Administrator\Links\Creative Cloud Files.lnk -> C:\Users\Administrator\Creative Cloud Files ()
Shortcut: C:\Users\Administrator\Links\Desktop.lnk -> C:\Users\Administrator\Desktop ()
Shortcut: C:\Users\Administrator\Links\Downloads.lnk -> C:\Users\Administrator\Downloads ()
Shortcut: C:\Users\Administrator\Links\RecentPlaces.lnk -> [::{22877A6D-37A1-461A-91B0-DBDA5AAEBC99}]
Shortcut: C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
Shortcut: C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance\Help.lnk -> C:\Windows\System32\shell32.dll (Microsoft Corporation)
Shortcut: C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation)
Shortcut: C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Notepad.lnk -> C:\Windows\System32\notepad.exe (Microsoft Corporation)
Shortcut: C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Run.lnk -> C:\Windows\System32\shell32.dll (Microsoft Corporation)
Shortcut: C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Windows Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation)
Shortcut: C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\computer.lnk -> C:\Windows\System32\imageres.dll (Microsoft Corporation)
Shortcut: C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Control Panel.lnk -> C:\Windows\System32\imageres.dll (Microsoft Corporation)
Shortcut: C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Private Character Editor.lnk -> C:\Windows\System32\eudcedit.exe (Microsoft Corporation)
Shortcut: C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Magnify.lnk -> C:\Windows\System32\Magnify.exe (Microsoft Corporation)
Shortcut: C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Narrator.lnk -> C:\Windows\System32\Narrator.exe (Microsoft Corporation)
Shortcut: C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\On-Screen Keyboard.lnk -> C:\Windows\System32\osk.exe (Microsoft Corporation)
Shortcut: C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
Shortcut: C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
Shortcut: C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -> C:\Windows\System32\imageres.dll (Microsoft Corporation)
Shortcut: C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -> C:\Windows\explorer.exe (Microsoft Corporation)
Shortcut: C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
Shortcut: C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
Shortcut: C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Access 2016.lnk -> C:\Program Files (x86)\Microsoft Office\root\Office16\MSACCESS.EXE (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat DC.lnk -> C:\Windows\Installer\{AC76BA86-1033-FFFF-7760-0C0F074E4100}\_SC_Acrobat.ico (Flexera Software LLC)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat Distiller DC.lnk -> C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\acrodist.exe (Adobe Systems Incorporated.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe After Effects CC 2014.lnk -> C:\Program Files\Adobe\Adobe After Effects CC 2014\Support Files\AfterFX.exe (Adobe Systems Incorporated)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe After Effects CC 2015.lnk -> C:\Program Files\Adobe\Adobe After Effects CC 2015\Support Files\AfterFX.exe (Adobe Systems Incorporated)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe After Effects CC 2017.lnk -> C:\Program Files\Adobe\Adobe After Effects CC 2017\Support Files\AfterFX.exe (Adobe Systems Incorporated)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Audition CC 2017.lnk -> C:\Program Files\Adobe\Adobe Audition CC 2017\Adobe Audition CC.exe (Adobe Systems Incorporated)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Bridge CC 2017.lnk -> C:\Program Files\Adobe\Adobe Bridge CC 2017\Bridge.exe (Adobe Systems Incorporated)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Character Animator (Preview).lnk -> C:\Program Files\Adobe\Adobe Character Animator (Preview)\Support Files\Character Animator.exe (Adobe Systems Incorporated)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Character Animator CC (Beta).lnk -> C:\Program Files\Adobe\Adobe Character Animator CC (Beta)\Support Files\Character Animator.exe (Adobe Systems Incorporated)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Content Viewer.lnk -> C:\Program Files (x86)\Adobe\Adobe Content Viewer\Adobe Content Viewer.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Creative Cloud.lnk -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe (Adobe Systems Incorporated)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Illustrator CC 2017.lnk -> C:\Program Files\Adobe\Adobe Illustrator CC 2017\Support Files\Contents\Windows\Illustrator.exe (Adobe Systems Inc.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe InDesign CC 2017.lnk -> C:\Program Files\Adobe\Adobe InDesign CC 2017\InDesign.exe (Adobe Systems Incorporated)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Lightroom.lnk -> C:\Program Files\Adobe\Adobe Lightroom\lightroom.exe (Adobe Systems)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Media Encoder CC 2014.lnk -> C:\Program Files\Adobe\Adobe Media Encoder CC 2014\Adobe Media Encoder.exe (Adobe Systems Incorporated)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Media Encoder CC 2015.lnk -> C:\Program Files\Adobe\Adobe Media Encoder CC 2015\Adobe Media Encoder.exe (Adobe Systems Incorporated)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Media Encoder CC 2017.lnk -> C:\Program Files\Adobe\Adobe Media Encoder CC 2017\Adobe Media Encoder.exe (Adobe Systems Incorporated)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CC 2015.5.lnk -> C:\Program Files\Adobe\Adobe Photoshop CC 2015.5\Photoshop.exe (Adobe Systems, Incorporated)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CC 2017.lnk -> C:\Program Files\Adobe\Adobe Photoshop CC 2017\Photoshop.exe (Adobe Systems, Incorporated)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Premiere Pro CC 2017.lnk -> C:\Program Files\Adobe\Adobe Premiere Pro CC 2017\Adobe Premiere Pro.exe (Adobe Systems Incorporated)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk -> C:\Windows\Installer\{AC76BA86-7AD7-1033-7B44-AB0000000001}\SC_Reader.ico ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk -> C:\Windows\Installer\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}\AppleSoftwareUpdateIco.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel 2016.lnk -> C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iLok License Manager.lnk -> C:\Program Files (x86)\iLok License Manager\iLok License Manager.exe (PACE Anti-Piracy, Inc.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk -> C:\Windows\ehome\ehshell.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk -> C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk -> C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote 2016.lnk -> C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTE.EXE (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook 2016.lnk -> C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint 2016.lnk -> C:\Program Files (x86)\Microsoft Office\root\Office16\POWERPNT.EXE (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Publisher 2016.lnk -> C:\Program Files (x86)\Microsoft Office\root\Office16\MSPUB.EXE (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UltraMon.lnk -> C:\Windows\Installer\{D4E62D29-31A1-4938-8CB7-7D275C1AEAC6}\IcoUltraMon.ico ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Anytime Upgrade.lnk -> C:\Windows\System32\WindowsAnytimeUpgradeUI.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk -> C:\Program Files\DVD Maker\DVDMaker.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Fax and Scan.lnk -> C:\Windows\System32\WFS.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinSCP.lnk -> C:\Program Files (x86)\WinSCP\WinSCP.exe (Martin Prikryl)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Word 2016.lnk -> C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XPS Viewer.lnk -> C:\Windows\System32\xpsrchvw.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Zemana AntiMalware\Zemana AntiMalware.lnk -> C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe (Copyright 2017.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Winsent Messenger\Winsent Messenger Web Site.lnk -> C:\Program Files (x86)\Winsent Messenger\homepage.URL ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Winsent Messenger\Winsent Messenger.lnk -> C:\Program Files (x86)\Winsent Messenger\winsent.exe (Winsent Lab)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR\Console RAR manual.lnk -> C:\Program Files\WinRAR\Rar.txt ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR\What is new in the latest version.lnk -> C:\Program Files\WinRAR\WhatsNew.txt ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR\WinRAR help.lnk -> C:\Program Files\WinRAR\WinRAR.chm ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR\WinRAR.lnk -> C:\Program Files\WinRAR\WinRAR.exe (Alexander Roshal)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinDirStat\Help (ENG).lnk -> C:\Program Files (x86)\WinDirStat\windirstat.chm ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinDirStat\Uninstall WinDirStat.lnk -> C:\Program Files (x86)\WinDirStat\Uninstall.exe (WDS Team)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinDirStat\WinDirStat.lnk -> C:\Program Files (x86)\WinDirStat\windirstat.exe (Seifert)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wacom Tablet\Wacom Desktop Center.lnk -> C:\Program Files\Tablet\Wacom\32\WacomDesktopCenter.exe (Wacom Technology, Corp.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wacom Tablet\Wacom Display Settings.lnk -> C:\Program Files\Tablet\Wacom\32\LCDSettings.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wacom Tablet\Wacom Tablet Preference File Utility.lnk -> C:\Program Files\Tablet\Wacom\32\PrefUtil.exe (Wacom Technology, Corp.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wacom Tablet\Wacom Tablet Properties.lnk -> C:\Program Files\Tablet\Wacom\Professional_CPL.exe (Wacom Technology, Corp.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN\Documentation.lnk -> C:\Program Files (x86)\VideoLAN\VLC\Documentation.url ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN\Release Notes.lnk -> C:\Program Files (x86)\VideoLAN\VLC\NEWS.txt ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN\VideoLAN Website.lnk -> C:\Program Files (x86)\VideoLAN\VLC\VideoLAN Website.url ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN\VLC media player.lnk -> C:\Program Files (x86)\VideoLAN\VLC\vlc.exe (VideoLAN)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tweaking.com\Windows Repair (All in One)\Open Windows Repair (WR) Tray Icon.lnk -> C:\Program Files (x86)\Tweaking.com\Windows Repair (All in One)\WR_Tray_Icon.exe (Tweaking.com)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tweaking.com\Windows Repair (All in One)\Tweaking.com - Registry Backup.lnk -> C:\Program Files (x86)\Tweaking.com\Windows Repair (All in One)\files\registry_backup_tool\TweakingRegistryBackup.exe (Tweaking.com)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tweaking.com\Windows Repair (All in One)\Tweaking.com - Windows Repair.lnk -> C:\Program Files (x86)\Tweaking.com\Windows Repair (All in One)\Repair_Windows.exe (Tweaking.com)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Aja Firmware Updater.lnk -> C:\Program Files\AJA\windows\Firmware\ajaflash.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Avid Background Services Manager.lnk -> C:\Windows\Installer\{95EB1E9C-F759-4427-8EEE-F96C48541A06}\NewShortcut1_4CE83F107C544E87A6F35E0E551E78CA.exe (Flexera Software LLC)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ISIS Client Manager.lnk -> C:\Program Files\Avid\ISIS Client\Client Manager\ISISClientManager.exe (Avid)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sound Devices\Wave Agent Beta\Wave Agent Beta.lnk -> C:\Windows\Installer\{053C7D32-3566-452B-9A37-D42B4F4C5379}\WaveAgent.exe_2AC7127DE83E4104BBD94FB6A9842EFA.exe (Acresso Software Inc.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sorenson Media\Sorenson Squeeze.lnk -> C:\Program Files (x86)\Sorenson Media\Sorenson Squeeze\squeeze.exe (Sorenson Media Inc.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sorenson Media\Sorenson Squeeze\Read Me.lnk -> C:\Program Files (x86)\Sorenson Media\Sorenson Squeeze\Readme.txt ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sorenson Media\Sorenson Squeeze\Sorenson Squeeze.lnk -> C:\Program Files (x86)\Sorenson Media\Sorenson Squeeze\squeeze.exe (Sorenson Media Inc.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sorenson Media\Sorenson Squeeze\Squeeze Help.lnk -> C:\Program Files (x86)\Sorenson Media\Sorenson Squeeze\Help\SqueezeHelp.pdf ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ShareMouse\Launch ShareMouse.lnk -> C:\Program Files (x86)\ShareMouse\ShareMouse.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung Magician\Samsung Magician.lnk -> C:\Program Files (x86)\Samsung\Samsung Magician\SamsungMagician.exe (Samsung Electronics Co. Ltd.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung Magician\Uninstall Samsung Magician.lnk -> C:\Program Files (x86)\Samsung\Samsung Magician\unins000.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung\Data Migration\Data Migration.lnk -> C:\Program Files (x86)\Samsung\Samsung Data Migration\Data Migration.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RogueKiller\RogueKiller.lnk -> C:\Program Files\RogueKiller\RogueKiller64.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Red Giant\PluralEyes.lnk -> C:\Program Files (x86)\Red Giant\PluralEyes\PE3W.exe (Red Giant LLC)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Red Giant\Red Giant Link.lnk -> C:\Program Files (x86)\Red Giant Link\Red Giant Link.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Red Giant\Uninstall Color Suite.lnk -> C:\Program Files (x86)\Red Giant\unins002.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Red Giant\Uninstall Effects Suite.lnk -> C:\ProgramData\RedGiant\EffectsSuite\unins000.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Red Giant\Uninstall Magic Bullet Suite.lnk -> C:\Program Files (x86)\Red Giant\unins002.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Red Giant\Uninstall Shooter Suite.lnk -> C:\Program Files (x86)\Red Giant\unins000.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Red Giant\Uninstall Trapcode Suite.lnk -> C:\Program Files (x86)\Red Giant\unins001.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime\About QuickTime.lnk -> C:\Windows\Installer\{FF59BD75-466A-4D5A-AD23-AAD87C5FD44C}\RichText.ico ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime\QuickTime Player.lnk -> C:\Windows\Installer\{FF59BD75-466A-4D5A-AD23-AAD87C5FD44C}\QTPlayer.ico ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF Complete\PDF Complete.lnk -> C:\Program Files (x86)\PDF Complete\pdfvista.exe (PDF Complete Inc)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ON1\ON1 Effects 10\ON1 Effects 10.lnk -> C:\Program Files\ON1\ON1 Effects 10\ON1 Effects 10.exe (ON1, Inc.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation\3D Vision\3D Vision Photo Viewer.lnk -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvstview.exe (NVIDIA Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Notepad++\Notepad++.lnk -> C:\Program Files (x86)\Notepad++\notepad++.exe (Don HO don.h@free.fr)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NewBlue\NewBlue Application Manager.lnk -> C:\Program Files\NewBlueFX\Common\ApplicationManager64.exe (NewBlue, Inc)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NewBlue\NewBlue Titler Pro 4\Uninstall Titler Pro 4.lnk -> C:\Program Files\NewBlueFX\uninstallers\Uninstall Titler Pro 4.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NewBlue\NewBlue Titler Pro 2.5 for Avid\Uninstall Titler Pro 2.5 for Avid.lnk -> C:\Program Files\NewBlueFX\uninstallers\Uninstall Titler Pro 2.5 for Avid.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NewBlue\NewBlue Titler Pro 2 for Avid\Uninstall Titler Pro 2 for Avid.lnk -> C:\Program Files\NewBlueFX\uninstallers\Uninstall Titler Pro 2 for Avid.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight\Microsoft Silverlight.lnk -> C:\Program Files\Microsoft Silverlight\5.1.50907.0\Silverlight.Configuration.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2016 Tools\Office 2016 Language Preferences.lnk -> C:\Program Files (x86)\Microsoft Office\root\Office16\SETLANG.EXE (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Mouse and Keyboard Center\Microsoft Mouse and Keyboard Center.lnk -> c:\Windows\Installer\{AEF6C676-D7A2-4487-BD4B-1BED17B229B5}\DeviceCenter.ico ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MAXON\CINEMA 4D TeamRender Client.lnk -> C:\Program Files\MAXON\CINEMA 4D R16\CINEMA 4D TeamRender Client.exe (MAXON Computer GmbH)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MAXON\CINEMA 4D TeamRender Server.lnk -> C:\Program Files\MAXON\CINEMA 4D R16\CINEMA 4D TeamRender Server.exe (MAXON Computer GmbH)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MAXON\CINEMA 4D.lnk -> C:\Program Files\MAXON\CINEMA 4D R16\CINEMA 4D.exe (MAXON Computer GmbH)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MAXON\Commandline.lnk -> C:\Program Files\MAXON\CINEMA 4D R16\Commandline.exe (MAXON Computer GmbH)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes\Malwarebytes.lnk -> C:\Program Files\Malwarebytes\Anti-Malware\mbam.exe (Malwarebytes)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes\Uninstall Malwarebytes.lnk -> C:\Program Files\Malwarebytes\Anti-Malware\unins000.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance\Create Recovery Disc.lnk -> C:\Windows\System32\recdisc.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance\Remote Assistance.lnk -> C:\Windows\System32\msra.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Keyspan USB Serial Adapter\Keyspan Serial Assistant.lnk -> C:\Program Files (x86)\Keyspan\USB Serial Adapter\K19HAsst.exe (Keyspan)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Configure Java.lnk -> C:\Program Files\Java\jre1.8.0_131\bin\javacpl.exe (Oracle Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iZotope\RX Loudness Control\iZotope RX Loudness Control Help PDF.lnk -> C:\Users\editor\Documents\iZotope\RX Loudness Control\RX Loudness Control Help.pdf ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iZotope\RX Loudness Control\Uninstall iZotope RX Loudness Control.lnk -> C:\Program Files (x86)\iZotope\RX Loudness Control\unins000.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iZotope\RX Loudness Control\Visit iZotope.lnk -> C:\Program Files (x86)\iZotope\RX Loudness Control\izotope.url ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iZotope\RX 5 Audio Editor\iZotope RX 5 Audio Editor (32-bit).lnk -> C:\Program Files (x86)\iZotope\RX 5 Audio Editor\win32\iZotope RX 5.exe (iZotope, Inc.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iZotope\RX 5 Audio Editor\iZotope RX 5 Audio Editor.lnk -> C:\Program Files (x86)\iZotope\RX 5 Audio Editor\win64\iZotope RX 5.exe (iZotope, Inc.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iZotope\RX 5 Audio Editor\Readme.lnk -> C:\Program Files (x86)\iZotope\RX 5 Audio Editor\Readme_en.rtf ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iZotope\RX 5 Audio Editor\Uninstall iZotope RX 5.lnk -> C:\Program Files (x86)\iZotope\RX 5 Audio Editor\unins000.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iZotope\RX 5 Audio Editor\Visit iZotope.lnk -> C:\Program Files (x86)\iZotope\RX 5 Audio Editor\izotope.url ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iZotope\Insight\iZotope Insight Help PDF.lnk -> C:\Program Files (x86)\iZotope\Insight\iZInsight_en.pdf ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iZotope\Insight\Readme.lnk -> C:\Program Files (x86)\iZotope\Insight\Readme_en.rtf ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iZotope\Insight\Uninstall iZotope Insight.lnk -> C:\Program Files (x86)\iZotope\Insight\unins000.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iZotope\Insight\Visit iZotope.lnk -> C:\Program Files (x86)\iZotope\Insight\izotope.url ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iSkysoft\iTube Studio\Homepage.lnk -> C:\Program Files (x86)\iSkysoft\iTube Studio\AllMyTube.url ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iSkysoft\iTube Studio\How to Use.lnk -> C:\Program Files (x86)\iSkysoft\iTube Studio\AllMyTubeHelp.url ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iSkysoft\iTube Studio\iSkysoft iTube Studio   .lnk -> C:\Program Files (x86)\iSkysoft\iTube Studio\ISAllMyTubeSplash.exe (iSkysoft Software)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iSkysoft\iTube Studio\iSkysoft Video Recorder.lnk -> C:\Program Files (x86)\iSkysoft\iTube Studio\ScreenCapture.exe (Wondershare Software)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iSkysoft\iTube Studio\Order Online.lnk -> C:\Program Files (x86)\iSkysoft\iTube Studio\AllMyTubeOrder.url ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iSkysoft\iTube Studio\Uninstall iSkysoft iTube Studio.lnk -> C:\Program Files (x86)\iSkysoft\iTube Studio\unins000.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel\Intel Control Center.lnk -> C:\Program Files (x86)\Intel\Intel Control Center\IntelControlCenter.exe (Intel Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel\Intel® Management Engine Components\Intel® Management and Security Status.lnk -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\IMSS\PrivacyIconClient.exe (Intel Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Inkscape 0.91\Inkscape 0.91.lnk -> C:\Program Files\Inkscape\inkscape.exe (inkscape.org)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HxD Hex Editor\Changelog.lnk -> C:\Program Files (x86)\HxD\changelog.txt ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HxD Hex Editor\HxD.lnk -> C:\Program Files (x86)\HxD\HxD.exe (Maël Hörz)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HxD Hex Editor\License.lnk -> C:\Program Files (x86)\HxD\license.txt ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HxD Hex Editor\Readme.lnk -> C:\Program Files (x86)\HxD\readme.txt ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HWiNFO64\HWiNFO64 Program.lnk -> C:\Program Files\HWiNFO64\HWiNFO64.EXE (REALiX)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP\HP Cool Tools.lnk -> C:\Program Files\Hewlett-Packard\HPCT\HP Cool Tools.htm ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP\HP Performance Advisor.lnk -> c:\Windows\Installer\{C6B87001-37EC-461E-AFE5-BECE03C47743}\_0DC15A49601A11037EAA7E.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GenArts Sapphire AVX\Sapphire AVX Online Help (HTML).lnk -> C:\Program Files (x86)\GenArts\SapphireAVX\docs\intro.html ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GenArts Sapphire AVX\Sapphire AVX Online Help (PDF).lnk -> C:\Program Files (x86)\GenArts\SapphireAVX\docs\Sapphire-Users-Guide-AVX.pdf ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GenArts Sapphire AVX\Sapphire Flare Designer.lnk -> C:\Program Files (x86)\GenArts\SapphireAVX\flare-editor\flare_editor.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GenArts Sapphire AVX\Uninstall Sapphire AVX.lnk -> C:\Program Files (x86)\GenArts\SapphireAVX\unins000.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GenArts Sapphire AE\Sapphire AE Online Help (HTML).lnk -> C:\Program Files (x86)\GenArts\SapphireAE\docs\intro.html ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GenArts Sapphire AE\Sapphire AE Online Help (PDF).lnk -> C:\Program Files (x86)\GenArts\SapphireAE\docs\Sapphire-Users-Guide-AE.pdf ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GenArts Sapphire AE\Sapphire Flare Designer.lnk -> C:\Program Files (x86)\GenArts\SapphireAE\flare-editor\flare_editor.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GenArts Sapphire AE\Uninstall Sapphire AE.lnk -> C:\Program Files (x86)\GenArts\SapphireAE\unins000.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games\GameExplorer.lnk -> C:\Windows\System32\gameux.dll (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Foolish IT\CryptoPrevent\CryptoPrevent.lnk -> C:\Program Files (x86)\Foolish IT\CryptoPrevent\CryptoPrevent.exe (Foolish IT LLC)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Foolish IT\CryptoPrevent\Uninstall CryptoPrevent.lnk -> C:\Program Files (x86)\Foolish IT\CryptoPrevent\unins000.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Flicker Free AVX2 1.1.2\Uninstall.lnk -> C:\Program Files\Avid\AVX2_Plug-ins\Digital Anarchy\Flicker Free AVX2 1.1.2\Uninstall.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileZilla FTP Client\FileZilla.lnk -> C:\Program Files\FileZilla FTP Client\filezilla.exe (FileZilla Project)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileZilla FTP Client\Uninstall.lnk -> C:\Program Files\FileZilla FTP Client\uninstall.exe (Tim Kosse)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DiskInternals\DiskInternals ZIP Repair\DiskInternals ZIP Repair.lnk -> C:\Program Files (x86)\DiskInternals\ZipRepair\ZipRepair.exe (DiskInternals Research)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DiskInternals\DiskInternals ZIP Repair\Uninstall.lnk -> C:\Program Files (x86)\DiskInternals\ZipRepair\Uninstall.exe (DiskInternals Research)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner\CCleaner.lnk -> C:\Program Files\CCleaner\CCleaner64.exe (Piriform Ltd)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bulk Rename Utility\Bulk Rename Utility.lnk -> C:\Program Files\Bulk Rename Utility\Bulk Rename Utility.exe (TGRMN Software)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bulk Rename Utility\Help File.lnk -> C:\Program Files\Bulk Rename Utility\Bulk Rename Utility.chm ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Boris RED 5\Boris RED 5 (64 Bit).lnk -> C:\Program Files\Boris FX, Inc\Boris RED 5\BorisRed5 Engine.exe (Boris FX)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Boris RED 5\Boris RED 5 Release Notes.lnk -> C:\Program Files\Boris FX, Inc\Release Notes.htm ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avid FX\Avid FX (64 Bit).lnk -> C:\Program Files\Avid FX\Avid FX 6\AvidFX6 Engine.exe (Boris FX)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avid FX\Release Notes.lnk -> C:\Program Files\Avid FX\Release Notes.htm ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avid\Application Manager.lnk -> C:\Windows\Installer\{99E377DB-D2D0-44A5-8533-AA8BE1381644}\NewShortcut1_F28DD94D49E14A45BA4555FED813A78D.exe (Flexera Software LLC)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avid\Media Composer.lnk -> C:\Windows\Installer\{95EB1E9C-F759-4427-8EEE-F96C48541A06}\NewShortcut2_0F6B4D689FBF4F8ABC2D4C6A315CB336.exe (Flexera Software LLC)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avid\Utilities\Avid License Control.lnk -> C:\Windows\Installer\{F187D064-F101-4E95-8D05-4027809AA0F8}\NewShortcut1_D1D572C6FCBA4504ACB2148585EE63D6.exe (Flexera Software LLC)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avid\ISIS Client\Benchmark Utility.lnk -> C:\Program Files\Avid\ISIS Client\Utilities\Benchmark Utility\BenchmarkUtility.exe (Avid)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avid\ISIS Client\ISIS Client Manager.lnk -> C:\Program Files\Avid\ISIS Client\Client Manager\ISISClientManager.exe (Avid)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avid\ISIS Client\ISIS Log Utility.lnk -> C:\Program Files\Avid\ISIS Client\Utilities\ISISLogUtility.exe (Avid)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avid\ISIS Client\ISIS Profiler.lnk -> C:\Program Files\Avid\ISIS Client\Profiler\Profiler.exe (Avid)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avid\ISIS Client\Path Diag.lnk -> C:\Program Files\Avid\ISIS Client\PathDiag.exe (Avid)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avid\Avid DVD by Sonic\Avid DVD by Sonic.lnk -> C:\Program Files (x86)\Avid\Avid DVD by Sonic\Avid DVD by Sonic.exe (Sonic Solutions)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avid\Avid DVD by Sonic\Documentation\Help.lnk -> C:\Program Files (x86)\Avid\Avid DVD by Sonic\Documentation\Avid DVD by Sonic Help.chm ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avid\Avid DVD by Sonic\Documentation\Readme.lnk -> C:\Program Files (x86)\Avid\Avid DVD by Sonic\Documentation\Avid DVD by Sonic Readme.pdf ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autodesk\Uninstall Tool.lnk -> C:\Program Files (x86)\Common Files\Autodesk Shared\Uninstall Tool\R1\UninstallTool.exe (Autodesk, Inc.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autodesk\Autodesk SketchBook\SketchBook.lnk -> C:\Program Files\Autodesk\SketchBook\SketchBook.exe (Autodesk Inc)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autodesk\Autodesk Desktop App\Autodesk Desktop App.lnk -> C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AutodeskDesktopApp.exe (Autodesk, Inc.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autodesk\Autodesk Backburner 2018.0\Manager.lnk -> C:\Program Files (x86)\Autodesk\Backburner\MANAGER.exe (Autodesk, Inc.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autodesk\Autodesk Backburner 2018.0\Monitor.lnk -> C:\Program Files (x86)\Autodesk\Backburner\monitor.exe (Autodesk, Inc.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autodesk\Autodesk Backburner 2018.0\Server.lnk -> C:\Program Files (x86)\Autodesk\Backburner\server.exe (Autodesk, Inc.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autodesk\Autodesk 3ds Max 2018\3ds Max 2018.lnk -> C:\Program Files\Autodesk\3ds Max 2018\3dsmax.exe (Autodesk, Inc.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autodesk\Autodesk 3ds Max 2018\MaxFind.lnk -> C:\Program Files\Autodesk\3ds Max 2018\MaxFind.exe (Autodesk, Inc.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AnalogExif\AnalogExif.lnk -> C:\Program Files (x86)\AnalogExif\AnalogExif.exe (C-41 Bytes)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AnalogExif\Uninstall.lnk -> C:\Program Files (x86)\AnalogExif\uninst.exe ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AJA\AJA ControlPanel.lnk -> C:\Program Files\AJA\windows\Applications\AJA ControlPanel.exe (AJA Video Systems, Inc.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AJA\AJA ControlRoom.lnk -> C:\Program Files\AJA\windows\Applications\AJA ControlRoom.exe (AJA Video Systems, Inc.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AJA\AJA Multi-Channel Config.lnk -> C:\Program Files\AJA\windows\Applications\AJA Multi-Channel Config.exe (AJA Video Systems, Inc.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AJA\AJA System Test.lnk -> C:\Program Files\AJA\windows\Applications\AJA System Test.exe (AJA Video Systems, Inc.)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AJA\Documentation\AJA Adobe Manual.lnk -> C:\Program Files\AJA\windows\Documentation\AJA_AdobeWinPlugins_Manual.pdf ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AJA\Documentation\AJA Wirecast QuickStart Guide.lnk -> C:\Program Files\AJA\windows\Documentation\AJA_Wirecast_Plugin_QuickStart.pdf ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AJA\Documentation\Driver ReleaseNotes.lnk -> C:\Program Files\AJA\windows\Documentation\AJA_WinDrivers_ReleaseNotes.pdf ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AJA\Documentation\IoXT and Io4K Manual.lnk -> C:\Program Files\AJA\windows\Documentation\IoXT and Io4K Manual.pdf ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AJA\Documentation\KONA Manual.lnk -> C:\Program Files\AJA\windows\Documentation\KONA PC Manual.pdf ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Component Services.lnk -> C:\Windows\System32\comexp.msc ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Data Sources (ODBC).lnk -> C:\Windows\System32\odbcad32.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\iSCSI Initiator.lnk -> C:\Windows\System32\iscsicpl.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Memory Diagnostics Tool.lnk -> C:\Windows\System32\MdSched.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Microsoft .NET Framework 1.1 Configuration.lnk -> C:\Windows\Microsoft.NET\Framework\v1.1.4322\mscorcfg.msc ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Microsoft .NET Framework 1.1 Wizards.lnk -> C:\Windows\Microsoft.NET\Framework\v1.1.4322\ConfigWizards.exe ( )
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Print Management.lnk -> C:\Windows\System32\printmanagement.msc ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk -> C:\Windows\System32\services.msc ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\System Configuration.lnk -> C:\Windows\System32\msconfig.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Windows Firewall with Advanced Security.lnk -> C:\Windows\System32\WF.msc ()
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Calculator.lnk -> C:\Windows\System32\calc.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\displayswitch.lnk -> C:\Windows\System32\displayswitch.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\NetworkProjection.lnk -> C:\Windows\System32\NetProj.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Paint.lnk -> C:\Windows\System32\mspaint.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Remote Desktop Connection.lnk -> C:\Windows\System32\mstsc.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Snipping Tool.lnk -> C:\Windows\System32\SnippingTool.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Sound Recorder.lnk -> C:\Windows\System32\SoundRecorder.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Sticky Notes.lnk -> C:\Windows\System32\StikyNot.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Sync Center.lnk -> C:\Windows\System32\mobsync.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Wordpad.lnk -> C:\Program Files\Windows NT\Accessories\wordpad.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell (x86).lnk -> C:\Windows\SysWOW64\Windowspowershell\v1.0\powershell.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell ISE (x86).lnk -> C:\Windows\SysWOW64\WindowsPowerShell\v1.0\PowerShell_ISE.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell ISE.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\PowerShell_ISE.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Windows PowerShell\Windows PowerShell.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Character Map.lnk -> C:\Windows\System32\charmap.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\dfrgui.lnk -> C:\Windows\System32\dfrgui.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Disk Cleanup.lnk -> C:\Windows\System32\cleanmgr.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\System Information.lnk -> C:\Windows\System32\msinfo32.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\System Restore.lnk -> C:\Windows\System32\rstrui.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Windows Easy Transfer Reports.lnk -> C:\Windows\System32\migwiz\PostMig.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Windows Easy Transfer.lnk -> C:\Windows\System32\migwiz\migwiz.exe (Microsoft Corporation)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip\7-Zip File Manager.lnk -> C:\Program Files\7-Zip\7zFM.exe (Igor Pavlov)
Shortcut: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip\7-Zip Help.lnk -> C:\Program Files\7-Zip\7-zip.chm ()
Shortcut: C:\Users\Default\Links\OneDrive.lnk -> C:\Program Files (x86)\Microsoft OneDrive\OneDriveSetup.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance\Help.lnk -> C:\Windows\System32\shell32.dll (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Notepad.lnk -> C:\Windows\System32\notepad.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Run.lnk -> C:\Windows\System32\shell32.dll (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Windows Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\computer.lnk -> C:\Windows\System32\imageres.dll (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Control Panel.lnk -> C:\Windows\System32\imageres.dll (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Private Character Editor.lnk -> C:\Windows\System32\eudcedit.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Magnify.lnk -> C:\Windows\System32\Magnify.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Narrator.lnk -> C:\Windows\System32\Narrator.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\On-Screen Keyboard.lnk -> C:\Windows\System32\osk.exe (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -> C:\Windows\System32\imageres.dll (Microsoft Corporation)
Shortcut: C:\Users\Default\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -> C:\Windows\explorer.exe (Microsoft Corporation)
Shortcut: C:\Users\Default.AVID4\Links\Desktop.lnk -> C:\Users\editor\Desktop ()
Shortcut: C:\Users\Default.AVID4\Links\Downloads.lnk -> C:\Users\editor\Downloads ()
Shortcut: C:\Users\Default.AVID4\Links\OneDrive.lnk -> C:\Program Files (x86)\Microsoft OneDrive\OneDriveSetup.exe (Microsoft Corporation)
Shortcut: C:\Users\Default.AVID4\Links\RecentPlaces.lnk -> [::{22877A6D-37A1-461A-91B0-DBDA5AAEBC99}]
Shortcut: C:\Users\Default.AVID4\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
Shortcut: C:\Users\Default.AVID4\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance\Help.lnk -> C:\Windows\System32\shell32.dll (Microsoft Corporation)
Shortcut: C:\Users\Default.AVID4\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation)
Shortcut: C:\Users\Default.AVID4\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Notepad.lnk -> C:\Windows\System32\notepad.exe (Microsoft Corporation)
Shortcut: C:\Users\Default.AVID4\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Run.lnk -> C:\Windows\System32\shell32.dll (Microsoft Corporation)
Shortcut: C:\Users\Default.AVID4\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Windows Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation)
Shortcut: C:\Users\Default.AVID4\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\computer.lnk -> C:\Windows\System32\imageres.dll (Microsoft Corporation)
Shortcut: C:\Users\Default.AVID4\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Control Panel.lnk -> C:\Windows\System32\imageres.dll (Microsoft Corporation)
Shortcut: C:\Users\Default.AVID4\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Private Character Editor.lnk -> C:\Windows\System32\eudcedit.exe (Microsoft Corporation)
Shortcut: C:\Users\Default.AVID4\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Magnify.lnk -> C:\Windows\System32\Magnify.exe (Microsoft Corporation)
Shortcut: C:\Users\Default.AVID4\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Narrator.lnk -> C:\Windows\System32\Narrator.exe (Microsoft Corporation)
Shortcut: C:\Users\Default.AVID4\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\On-Screen Keyboard.lnk -> C:\Windows\System32\osk.exe (Microsoft Corporation)
Shortcut: C:\Users\Default.AVID4\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
Shortcut: C:\Users\Default.AVID4\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -> C:\Windows\System32\imageres.dll (Microsoft Corporation)
Shortcut: C:\Users\Default.AVID4\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -> C:\Windows\explorer.exe (Microsoft Corporation)
Shortcut: C:\Users\Default.AVID4\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
Shortcut: C:\Users\Default.AVID4\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
Shortcut: C:\Users\Default.AVID4\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation)
Shortcut: C:\Users\editor\Links\Creative Cloud Files.lnk -> C:\Users\editor\Creative Cloud Files ()
Shortcut: C:\Users\editor\Links\Desktop.lnk -> C:\Users\editor\Desktop ()
Shortcut: C:\Users\editor\Links\Downloads.lnk -> C:\Users\editor\Downloads ()
Shortcut: C:\Users\editor\Links\OneDrive.lnk -> C:\Users\editor\OneDrive ()
Shortcut: C:\Users\editor\Links\PITCHES.lnk -> C:\Users\editor\Creative Cloud Files\PITCHES ()
Shortcut: C:\Users\editor\Links\RecentPlaces.lnk -> [::{22877A6D-37A1-461A-91B0-DBDA5AAEBC99}]
Shortcut: C:\Users\editor\Downloads\Creative Cloud Files.lnk -> C:\Users\editor\Creative Cloud Files ()
Shortcut: C:\Users\editor\Documents\Adobe\After Effects CC 2017\User Presets\(Adobe).lnk -> C:\Program Files\Adobe\Adobe After Effects CC 2017\Support Files\Presets ()
Shortcut: C:\Users\editor\Documents\Adobe\After Effects CC 2015\User Presets\(Adobe).lnk -> C:\Program Files\Adobe\Adobe After Effects CC 2015\Support Files\Presets ()
Shortcut: C:\Users\editor\Desktop\Downloads.lnk -> C:\Users\editor\Downloads ()
Shortcut: C:\Users\editor\Desktop\Resolve.lnk -> C:\Program Files\Blackmagic Design\DaVinci Resolve\Resolve.exe (Blackmagic Design Pty. Ltd.)
Shortcut: C:\Users\editor\Desktop\Slack.lnk -> C:\Users\editor\AppData\Local\slack\slack.exe (Slack Technologies)
Shortcut: C:\Users\editor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
Shortcut: C:\Users\editor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MediaInfo.lnk -> C:\Program Files\MediaInfo\MediaInfo.exe (MediaArea.net)
Shortcut: C:\Users\editor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft OneDrive.lnk -> C:\Users\editor\AppData\Local\Microsoft\OneDrive\OneDrive.exe (Microsoft Corporation)
Shortcut: C:\Users\editor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR\Console RAR manual.lnk -> C:\Program Files\WinRAR\Rar.txt ()
Shortcut: C:\Users\editor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR\What is new in the latest version.lnk -> C:\Program Files\WinRAR\WhatsNew.txt ()
Shortcut: C:\Users\editor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR\WinRAR help.lnk -> C:\Program Files\WinRAR\WinRAR.chm ()
Shortcut: C:\Users\editor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR\WinRAR.lnk -> C:\Program Files\WinRAR\WinRAR.exe (Alexander Roshal)
Shortcut: C:\Users\editor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WebShot\WebShot (CEF).lnk -> C:\Program Files (x86)\WebShot\cef\webshotcef.exe (Nathan Moinvaziri)
Shortcut: C:\Users\editor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WebShot\WebShot (IE).lnk -> C:\Program Files (x86)\WebShot\webshot.exe (Nathan Moinvaziri)
Shortcut: C:\Users\editor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WebShot\WebShot (IE64).lnk -> C:\Program Files (x86)\WebShot\webshot64.exe (Nathan Moinvaziri)
Shortcut: C:\Users\editor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WebShot\WebShot Change Log.lnk -> C:\Program Files (x86)\WebShot\changelog.txt ()
Shortcut: C:\Users\editor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WebShot\WebShot Command Line (CEF).lnk -> C:\Program Files (x86)\WebShot\cef\webshotcefcmd.exe (Nathan Moinvaziri)
Shortcut: C:\Users\editor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WebShot\WebShot Command Line (IE).lnk -> C:\Program Files (x86)\WebShot\webshotcmd.exe (Nathan Moinvaziri)
Shortcut: C:\Users\editor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WebShot\WebShot Command Line (IE64).lnk -> C:\Program Files (x86)\WebShot\webshotcmd64.exe (Nathan Moinvaziri)
Shortcut: C:\Users\editor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WebShot\WebShot Examples.lnk -> C:\Program Files (x86)\WebShot\example ()
Shortcut: C:\Users\editor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WebShot\WebShot Homepage.lnk -> C:\Program Files (x86)\WebShot\webshot.htm ()
Shortcut: C:\Users\editor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WebShot\WebShot Uninstall.lnk -> C:\Program Files (x86)\WebShot\uninstall.exe (Nathan Moinvaziri)
Shortcut: C:\Users\editor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Slack Technologies\Slack.lnk -> C:\Users\editor\AppData\Local\slack\slack.exe (Slack Technologies)
Shortcut: C:\Users\editor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance\Help.lnk -> C:\Windows\System32\shell32.dll (Microsoft Corporation)
Shortcut: C:\Users\editor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Blackmagic Design\DaVinci Resolve\Resolve.lnk -> C:\Program Files\Blackmagic Design\DaVinci Resolve\Resolve.exe (Blackmagic Design Pty. Ltd.)
Shortcut: C:\Users\editor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aspera\Aspera Connect.lnk -> C:\Users\editor\AppData\Local\Programs\Aspera\Aspera Connect\bin\asperaconnect.exe (Aspera, Inc., an IBM Company)
Shortcut: C:\Users\editor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation)
Shortcut: C:\Users\editor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Notepad.lnk -> C:\Windows\System32\notepad.exe (Microsoft Corporation)
Shortcut: C:\Users\editor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Run.lnk -> C:\Windows\System32\shell32.dll (Microsoft Corporation)
Shortcut: C:\Users\editor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Windows Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation)
Shortcut: C:\Users\editor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\computer.lnk -> C:\Windows\System32\imageres.dll (Microsoft Corporation)
Shortcut: C:\Users\editor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Control Panel.lnk -> C:\Windows\System32\imageres.dll (Microsoft Corporation)
Shortcut: C:\Users\editor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Private Character Editor.lnk -> C:\Windows\System32\eudcedit.exe (Microsoft Corporation)
Shortcut: C:\Users\editor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Magnify.lnk -> C:\Windows\System32\Magnify.exe (Microsoft Corporation)
Shortcut: C:\Users\editor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Narrator.lnk -> C:\Windows\System32\Narrator.exe (Microsoft Corporation)
Shortcut: C:\Users\editor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\On-Screen Keyboard.lnk -> C:\Windows\System32\osk.exe (Microsoft Corporation)
Shortcut: C:\Users\editor\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
Shortcut: C:\Users\editor\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\HxD.lnk -> C:\Program Files (x86)\HxD\HxD.exe (Maël Hörz)
Shortcut: C:\Users\editor\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\iSkysoft iTube Studio.lnk -> C:\Program Files (x86)\iSkysoft\iTube Studio\AllMyTube.exe (iSkySoft Software)
Shortcut: C:\Users\editor\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation)
Shortcut: C:\Users\editor\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -> C:\Windows\System32\imageres.dll (Microsoft Corporation)
Shortcut: C:\Users\editor\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\SketchBook.lnk -> C:\Program Files\Autodesk\SketchBook\SketchBook.exe (Autodesk Inc)
Shortcut: C:\Users\editor\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -> C:\Windows\explorer.exe (Microsoft Corporation)
Shortcut: C:\Users\editor\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Adobe After Effects CC 2017.lnk -> C:\Program Files\Adobe\Adobe After Effects CC 2017\Support Files\AfterFX.exe (Adobe Systems Incorporated)
Shortcut: C:\Users\editor\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Adobe Illustrator CC 2017.lnk -> C:\Program Files\Adobe\Adobe Illustrator CC 2017\Support Files\Contents\Windows\Illustrator.exe (Adobe Systems Inc.)
Shortcut: C:\Users\editor\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Adobe InDesign CC 2017.lnk -> C:\Program Files\Adobe\Adobe InDesign CC 2017\InDesign.exe (Adobe Systems Incorporated)
Shortcut: C:\Users\editor\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Adobe Media Encoder CC 2017.lnk -> C:\Program Files\Adobe\Adobe Media Encoder CC 2017\Adobe Media Encoder.exe (Adobe Systems Incorporated)
Shortcut: C:\Users\editor\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Adobe Photoshop CC 2017.lnk -> C:\Program Files\Adobe\Adobe Photoshop CC 2017\Photoshop.exe (Adobe Systems, Incorporated)
Shortcut: C:\Users\editor\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Avid Media Composer.lnk -> C:\Windows\Installer\{95EB1E9C-F759-4427-8EEE-F96C48541A06}\NewShortcut1_39394C1D6529475F8B3DDBAB6701C1B2.exe (Flexera Software LLC)
Shortcut: C:\Users\editor\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
Shortcut: C:\Users\editor\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\MPEG Streamclip.lnk -> C:\Users\editor\Downloads\MPEG_Streamclip.exe (Squared 5)
Shortcut: C:\Users\editor\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Notepad++.lnk -> C:\Program Files (x86)\Notepad++\notepad++.exe (Don HO don.h@free.fr)
Shortcut: C:\Users\editor\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation)
Shortcut: C:\Users\editor\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Task Manager.lnk -> C:\Windows\System32\taskmgr.exe (Microsoft Corporation)
Shortcut: C:\Users\editor\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\9d91276b0be3e46b\pinned.lnk -> HelpPane.exe
Shortcut: C:\Users\editor\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\7e4dca80246863e3\pinned.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation)
Shortcut: C:\Users\IUSR_Servs\Links\Desktop.lnk -> C:\Users\IUSR_Servs\Desktop ()
Shortcut: C:\Users\IUSR_Servs\Links\Downloads.lnk -> C:\Users\IUSR_Servs\Downloads ()
Shortcut: C:\Users\IUSR_Servs\Links\OneDrive.lnk -> C:\Program Files (x86)\Microsoft OneDrive\OneDriveSetup.exe (Microsoft Corporation)
Shortcut: C:\Users\IUSR_Servs\Links\RecentPlaces.lnk -> [::{22877A6D-37A1-461A-91B0-DBDA5AAEBC99}]
Shortcut: C:\Users\IUSR_Servs\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
Shortcut: C:\Users\IUSR_Servs\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance\Help.lnk -> C:\Windows\System32\shell32.dll (Microsoft Corporation)
Shortcut: C:\Users\IUSR_Servs\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation)
Shortcut: C:\Users\IUSR_Servs\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Notepad.lnk -> C:\Windows\System32\notepad.exe (Microsoft Corporation)
Shortcut: C:\Users\IUSR_Servs\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Run.lnk -> C:\Windows\System32\shell32.dll (Microsoft Corporation)
Shortcut: C:\Users\IUSR_Servs\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Windows Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation)
Shortcut: C:\Users\IUSR_Servs\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\computer.lnk -> C:\Windows\System32\imageres.dll (Microsoft Corporation)
Shortcut: C:\Users\IUSR_Servs\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Control Panel.lnk -> C:\Windows\System32\imageres.dll (Microsoft Corporation)
Shortcut: C:\Users\IUSR_Servs\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Private Character Editor.lnk -> C:\Windows\System32\eudcedit.exe (Microsoft Corporation)
Shortcut: C:\Users\IUSR_Servs\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Magnify.lnk -> C:\Windows\System32\Magnify.exe (Microsoft Corporation)
Shortcut: C:\Users\IUSR_Servs\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Narrator.lnk -> C:\Windows\System32\Narrator.exe (Microsoft Corporation)
Shortcut: C:\Users\IUSR_Servs\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\On-Screen Keyboard.lnk -> C:\Windows\System32\osk.exe (Microsoft Corporation)
Shortcut: C:\Users\IUSR_Servs\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
Shortcut: C:\Users\IUSR_Servs\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -> C:\Windows\System32\imageres.dll (Microsoft Corporation)
Shortcut: C:\Users\IUSR_Servs\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -> C:\Windows\explorer.exe (Microsoft Corporation)
Shortcut: C:\Users\IUSR_Servs\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
Shortcut: C:\Users\IUSR_Servs\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
Shortcut: C:\Users\IUSR_Servs\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation)
Shortcut: C:\Users\Public\Desktop\3ds Max 2018.lnk -> C:\Program Files\Autodesk\3ds Max 2018\3dsmax.exe (Autodesk, Inc.)
Shortcut: C:\Users\Public\Desktop\Adobe Acrobat DC.lnk -> C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Acrobat.exe (Adobe Systems Incorporated)
Shortcut: C:\Users\Public\Desktop\Adobe Creative Cloud.lnk -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe (Adobe Systems Incorporated)
Shortcut: C:\Users\Public\Desktop\Autodesk Desktop App.lnk -> C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AutodeskDesktopApp.exe (Autodesk, Inc.)
Shortcut: C:\Users\Public\Desktop\Avid Media Composer.lnk -> C:\Windows\Installer\{95EB1E9C-F759-4427-8EEE-F96C48541A06}\NewShortcut1_39394C1D6529475F8B3DDBAB6701C1B2.exe (Flexera Software LLC)
Shortcut: C:\Users\Public\Desktop\Boris RED 5 (64 Bit).lnk -> C:\Program Files\Boris FX, Inc\Boris RED 5\BorisRed5 Engine.exe (Boris FX)
Shortcut: C:\Users\Public\Desktop\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
Shortcut: C:\Users\Public\Desktop\iLok License Manager.lnk -> C:\Program Files (x86)\iLok License Manager\iLok License Manager.exe (PACE Anti-Piracy, Inc.)
Shortcut: C:\Users\Public\Desktop\Inkscape 0.91.lnk -> C:\Program Files\Inkscape\inkscape.exe (inkscape.org)
Shortcut: C:\Users\Public\Desktop\Malwarebytes.lnk -> C:\Program Files\Malwarebytes\Anti-Malware\mbam.exe (Malwarebytes)
Shortcut: C:\Users\Public\Desktop\NewBlue Titler Pro 4 Standalone.lnk -> C:\Program Files\NewBlueFX\Titler\TitlerStandalone.exe ()
Shortcut: C:\Users\Public\Desktop\NewBlue Titler Pro Standalone.lnk -> C:\Program Files\NewBlueFX\Titler\TitlerStandalone.exe ()
Shortcut: C:\Users\Public\Desktop\RogueKiller.lnk -> C:\Program Files\RogueKiller\RogueKiller64.exe ()
Shortcut: C:\Users\Public\Desktop\Sorenson Squeeze.lnk -> C:\Program Files (x86)\Sorenson Media\Sorenson Squeeze\squeeze.exe (Sorenson Media Inc.)
Shortcut: C:\Users\Public\Desktop\VLC media player.lnk -> C:\Program Files (x86)\VideoLAN\VLC\vlc.exe (VideoLAN)
Shortcut: C:\Users\Public\Desktop\Zemana AntiMalware.lnk -> C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe (Copyright 2017.)
Shortcut: C:\Users\user\Links\Desktop.lnk -> C:\Users\user\Desktop ()
Shortcut: C:\Users\user\Links\Downloads.lnk -> C:\Users\user\Downloads ()
Shortcut: C:\Users\user\Links\RecentPlaces.lnk -> [::{22877A6D-37A1-461A-91B0-DBDA5AAEBC99}]
Shortcut: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
Shortcut: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation)
Shortcut: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance\Help.lnk -> C:\Windows\System32\shell32.dll (Microsoft Corporation)
Shortcut: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Command Prompt.lnk -> C:\Windows\System32\cmd.exe (Microsoft Corporation)
Shortcut: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Notepad.lnk -> C:\Windows\System32\notepad.exe (Microsoft Corporation)
Shortcut: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Run.lnk -> C:\Windows\System32\shell32.dll (Microsoft Corporation)
Shortcut: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Windows Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation)
Shortcut: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\computer.lnk -> C:\Windows\System32\imageres.dll (Microsoft Corporation)
Shortcut: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Control Panel.lnk -> C:\Windows\System32\imageres.dll (Microsoft Corporation)
Shortcut: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Private Character Editor.lnk -> C:\Windows\System32\eudcedit.exe (Microsoft Corporation)
Shortcut: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Magnify.lnk -> C:\Windows\System32\Magnify.exe (Microsoft Corporation)
Shortcut: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Narrator.lnk -> C:\Windows\System32\Narrator.exe (Microsoft Corporation)
Shortcut: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\On-Screen Keyboard.lnk -> C:\Windows\System32\osk.exe (Microsoft Corporation)
Shortcut: C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk -> C:\Windows\System32\imageres.dll (Microsoft Corporation)
Shortcut: C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk -> C:\Windows\explorer.exe (Microsoft Corporation)
Shortcut: C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation)
Shortcut: C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Explorer.lnk -> C:\Windows\explorer.exe (Microsoft Corporation)
 
 
ShortcutWithArgument: C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) ->  -extoff
ShortcutWithArgument: C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Ease of Access.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.EaseOfAccessCenter
ShortcutWithArgument: C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\SendTo\Fax Recipient.lnk -> C:\Windows\System32\WFS.exe (Microsoft Corporation) -> /SendTo
ShortcutWithArgument: C:\Users\Administrator\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Media Player.lnk -> C:\Program Files (x86)\Windows Media Player\wmplayer.exe (Microsoft Corporation) -> /prefetch:1
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Default Programs.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.DefaultPrograms
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Windows Update.lnk -> C:\Windows\System32\wuapp.exe (Microsoft Corporation) -> startmenu
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk -> C:\Program Files (x86)\Windows Media Player\wmplayer.exe (Microsoft Corporation) -> /prefetch:1
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN\VLC media player - reset preferences and cache files.lnk -> C:\Program Files (x86)\VideoLAN\VLC\vlc.exe (VideoLAN) -> --reset-config --reset-plugins-cache vlc://quit
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN\VLC media player skinned.lnk -> C:\Program Files (x86)\VideoLAN\VLC\vlc.exe (VideoLAN) -> -Iskins
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tweaking.com\Windows Repair (All in One)\Uninstall Tweaking.com - Windows Repair.lnk -> C:\Program Files (x86)\Tweaking.com\Windows Repair (All in One)\uninstall.exe (Indigo Rose Corporation) -> "/U:C:\Program Files (x86)\Tweaking.com\Windows Repair (All in One)\Uninstall\uninstall.xml"
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Avid Application Manager.lnk -> C:\Windows\Installer\{99E377DB-D2D0-44A5-8533-AA8BE1381644}\NewShortcut1_E1E0FF1FC1474601A40EFEF248F11D43.exe (Flexera Software LLC) -> --trayonly
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\UltraMon.lnk -> C:\Windows\Installer\{D4E62D29-31A1-4938-8CB7-7D275C1AEAC6}\IcoUltraMon.ico () -> /auto
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sound Devices\Wave Agent Beta\Uninstall Wave Agent Beta.lnk -> C:\Program Files (x86)\InstallShield Installation Information\{053C7D32-3566-452B-9A37-D42B4F4C5379}\setup.exe (Sound Devices LLC                                            ) -> -runfromtemp
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime\Uninstall QuickTime.lnk -> C:\Windows\SysWOW64\msiexec.exe (Microsoft Corporation) -> /i {FF59BD75-466A-4D5A-AD23-AAD87C5FD44C} /qf
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation\3D Vision\3D Vision preview pack 1.lnk -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvstlink.exe (NVIDIA Corporation) -> /show
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation\3D Vision\Disable 3D Vision.lnk -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvstlink.exe (NVIDIA Corporation) -> /disable
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation\3D Vision\Enable 3D Vision.lnk -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvstlink.exe (NVIDIA Corporation) -> /enable
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Starter (English)\Microsoft Excel Starter 2010.lnk -> C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVH.EXE (Microsoft Corporation) -> "Microsoft Excel Starter 2010 9014006604090000"
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Starter (English)\Microsoft Word Starter 2010.lnk -> C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVH.EXE (Microsoft Corporation) -> "Microsoft Word Starter 2010 9014006604090000"
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Starter (English)\Microsoft Office 2010 Tools\Microsoft Clip Organizer.lnk -> C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVH.EXE (Microsoft Corporation) -> "Microsoft Clip Organizer 9014006604090000"
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Starter (English)\Microsoft Office 2010 Tools\Microsoft Office 2010 Upload Center.lnk -> C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVH.EXE (Microsoft Corporation) -> "Microsoft Office 2010 Upload Center 9014006604090000"
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Starter (English)\Microsoft Office 2010 Tools\Microsoft Office Picture Manager.lnk -> C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVH.EXE (Microsoft Corporation) -> "Microsoft Office Picture Manager 9014006604090000"
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Starter (English)\Microsoft Office 2010 Tools\Microsoft Office Starter To-Go Device Manager 2010.lnk -> C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVH.EXE (Microsoft Corporation) -> "Microsoft Office Starter To-Go Device Manager 2010 9014006604090000"
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2016 Tools\Office 2016 Upload Center.lnk -> C:\Program Files (x86)\Microsoft Office\root\client\AppVLP.exe (Microsoft Corporation) -> "C:\Program Files (x86)\Microsoft Office\Root\Office16\MSOUC.EXE"
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance\Backup and Restore Center.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.BackupAndRestore
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\About Java.lnk -> C:\Program Files\Java\jre1.8.0_131\bin\javacpl.exe (Oracle Corporation) -> -tab about
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Check For Updates.lnk -> C:\Program Files\Java\jre1.8.0_131\bin\javacpl.exe (Oracle Corporation) -> -tab update
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel\Install Intel Rapid Storage Technology.lnk -> C:\SWSETUP\DRV\Storage\Intel\iRSTSCU\3.1.0.1085\QuickLnk.exe (Hewlett-Packard Company) -> -exec /T:"c:\SWSETUP\DRV\Storage\Intel\iRSTSCU\3.1.0.1085\RSTe_SETUP\RSTe_3.1.0.1085_PV.exe" /L:"C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel\Install Intel Rapid Storage Technology.lnk"
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP Help and Support\WSG.lnk -> C:\SWSETUP\HP Documentation\eDocLauncher.exe (Hewlett-Packard) -> P004KCB2 WSG
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP Help and Support\HP User Manuals\SCG.lnk -> C:\SWSETUP\HP Documentation\eDocLauncher.exe (Hewlett-Packard) -> P004JZB2 SCG
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP Help and Support\HP User Manuals\SRI.lnk -> C:\SWSETUP\HP Documentation\eDocLauncher.exe (Hewlett-Packard) -> P004JZB2 SRI
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP Help and Support\HP User Manuals\UG.lnk -> C:\SWSETUP\HP Documentation\eDocLauncher.exe (Hewlett-Packard) -> P004JZB2 UG
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP\Install HP Power Assistant.lnk -> C:\SWSETUP\APP\Applications\HP\HPPA\2.0\src\QuickLnk.exe (Hewlett-Packard Company) -> -exec /T:"c:\SWSETUP\APP\Applications\HP\HPPA\2.0\src\HPPA_Setup.exe" /L:"C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP\Install HP Power Assistant.lnk"
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP\Install HP Remote Graphics Software.lnk -> C:\SWSETUP\APP\Applications\HP\RGS\5.4.7\src\QuickLnk.exe (Hewlett-Packard Company) -> -exec /T:"c:\SWSETUP\APP\Applications\HP\RGS\5.4.7\src\RGSInstall.vbs" /L:"C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP\Install HP Remote Graphics Software.lnk"
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GenArts Sapphire AVX\Check for Sapphire AVX Updates.lnk -> C:\Program Files (x86)\GenArts\SapphireAVX\genarts-frontend.exe (GenArts, Inc.) -> --update
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GenArts Sapphire AVX\Install Sapphire AVX RLM License.lnk -> C:\Windows\System32\notepad.exe (Microsoft Corporation) -> C:\Program Files (x86)\GenArts\rlm\SapphireAVX.lic
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GenArts Sapphire AVX\Install Sapphire AVX Serial Number.lnk -> C:\Program Files (x86)\GenArts\SapphireAVX\genarts-frontend.exe (GenArts, Inc.) -> -license-install
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GenArts Sapphire AE\Check for Sapphire AE Updates.lnk -> C:\Program Files (x86)\GenArts\SapphireAE\genarts-frontend.exe (GenArts, Inc.) -> --update
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GenArts Sapphire AE\Install Sapphire AE RLM License.lnk -> C:\Windows\System32\notepad.exe (Microsoft Corporation) -> C:\Program Files (x86)\GenArts\rlm\SapphireAE.lic
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GenArts Sapphire AE\Install Sapphire AE Serial Number.lnk -> C:\Program Files (x86)\GenArts\SapphireAE\genarts-frontend.exe (GenArts, Inc.) -> -license-install
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avid\Media Composer Documentation (PDF).lnk -> C:\Windows\explorer.exe (Microsoft Corporation) -> C:\Program Files\Avid\Avid Media Composer\OnlineLibrary\DOCS\
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autodesk\Autodesk 3ds Max 2018\3ds Max 2018 - Brazilian Portuguese.lnk -> C:\Program Files\Autodesk\3ds Max 2018\3dsmax.exe (Autodesk, Inc.) -> /Language=PTB
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autodesk\Autodesk 3ds Max 2018\3ds Max 2018 - English.lnk -> C:\Program Files\Autodesk\3ds Max 2018\3dsmax.exe (Autodesk, Inc.) -> /Language=ENU
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autodesk\Autodesk 3ds Max 2018\3ds Max 2018 - French.lnk -> C:\Program Files\Autodesk\3ds Max 2018\3dsmax.exe (Autodesk, Inc.) -> /Language=FRA
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autodesk\Autodesk 3ds Max 2018\3ds Max 2018 - German.lnk -> C:\Program Files\Autodesk\3ds Max 2018\3dsmax.exe (Autodesk, Inc.) -> /Language=DEU
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autodesk\Autodesk 3ds Max 2018\3ds Max 2018 - Japanese.lnk -> C:\Program Files\Autodesk\3ds Max 2018\3dsmax.exe (Autodesk, Inc.) -> /Language=JPN
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autodesk\Autodesk 3ds Max 2018\3ds Max 2018 - Korean.lnk -> C:\Program Files\Autodesk\3ds Max 2018\3dsmax.exe (Autodesk, Inc.) -> /Language=KOR
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autodesk\Autodesk 3ds Max 2018\3ds Max 2018 - Simplified Chinese.lnk -> C:\Program Files\Autodesk\3ds Max 2018\3dsmax.exe (Autodesk, Inc.) -> /Language=CHS
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autodesk\Autodesk 3ds Max 2018\Change Graphics Mode.lnk -> C:\Program Files\Autodesk\3ds Max 2018\3dsmax.exe (Autodesk, Inc.) -> -h
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autodesk\Autodesk 3ds Max 2018\License Transfer Utility - 3ds Max 2018.lnk -> C:\Program Files\Common Files\Autodesk Shared\AdLM\R14\LTU.exe (Autodesk, Inc.) -> 128J1 2018.0.0.F -d SA -l en_US
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Computer Management.lnk -> C:\Windows\System32\compmgmt.msc () -> /s
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Event Viewer.lnk -> C:\Windows\System32\eventvwr.msc () -> /s
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Performance Monitor.lnk -> C:\Windows\System32\perfmon.msc () -> /s
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Security Configuration Management.lnk -> C:\Windows\System32\secpol.msc () -> /s
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Task Scheduler.lnk -> C:\Windows\System32\taskschd.msc () -> /s
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\Windows PowerShell Modules.lnk -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe (Microsoft Corporation) -> -NoExit -ImportSystemModules
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Mobility Center.lnk -> C:\Windows\System32\mblctr.exe (Microsoft Corporation) -> /open
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Welcome Center.lnk -> C:\Windows\System32\rundll32.exe (Microsoft Corporation) -> %SystemRoot%\system32\OobeFldr.dll,ShowWelcomeCenter LaunchedBy_StartMenuShortcut
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Resource Monitor.lnk -> C:\Windows\System32\perfmon.exe (Microsoft Corporation) -> /res
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Task Scheduler.lnk -> C:\Windows\System32\taskschd.msc () -> /s
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Speech Recognition.lnk -> C:\Windows\Speech\Common\sapisvr.exe (Microsoft Corporation) -> -SpeechUX
ShortcutWithArgument: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Ease of Access.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.EaseOfAccessCenter
ShortcutWithArgument: C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo\Fax Recipient.lnk -> C:\Windows\System32\WFS.exe (Microsoft Corporation) -> /SendTo
ShortcutWithArgument: C:\Users\Default.AVID4\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) ->  -extoff
ShortcutWithArgument: C:\Users\Default.AVID4\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Ease of Access.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.EaseOfAccessCenter
ShortcutWithArgument: C:\Users\Default.AVID4\AppData\Roaming\Microsoft\Windows\SendTo\Fax Recipient.lnk -> C:\Windows\System32\WFS.exe (Microsoft Corporation) -> /SendTo
ShortcutWithArgument: C:\Users\Default.AVID4\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Media Player.lnk -> C:\Program Files (x86)\Windows Media Player\wmplayer.exe (Microsoft Corporation) -> /prefetch:1
ShortcutWithArgument: C:\Users\editor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Chrome Remote Desktop.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) ->  --profile-directory=Default --app-id=gbchcmhmhahfdphkhkmpfmihenigjmpp
ShortcutWithArgument: C:\Users\editor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Aspera\Uninstall Aspera Connect.lnk -> C:\Windows\System32\msiexec.exe (Microsoft Corporation) -> /I {EC793CAC-7C41-4817-BA98-7E481A79F9CF}
ShortcutWithArgument: C:\Users\editor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) ->  -extoff
ShortcutWithArgument: C:\Users\editor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Ease of Access.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.EaseOfAccessCenter
ShortcutWithArgument: C:\Users\editor\AppData\Roaming\Microsoft\Windows\SendTo\Fax Recipient.lnk -> C:\Windows\System32\WFS.exe (Microsoft Corporation) -> /SendTo
ShortcutWithArgument: C:\Users\editor\AppData\Roaming\Microsoft\Windows\SendTo\WinSCP (for upload).lnk -> C:\Program Files (x86)\WinSCP\WinSCP.exe (Martin Prikryl) -> /upload
ShortcutWithArgument: C:\Users\IUSR_Servs\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) ->  -extoff
ShortcutWithArgument: C:\Users\IUSR_Servs\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Ease of Access.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.EaseOfAccessCenter
ShortcutWithArgument: C:\Users\IUSR_Servs\AppData\Roaming\Microsoft\Windows\SendTo\Fax Recipient.lnk -> C:\Windows\System32\WFS.exe (Microsoft Corporation) -> /SendTo
ShortcutWithArgument: C:\Users\IUSR_Servs\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Media Player.lnk -> C:\Program Files (x86)\Windows Media Player\wmplayer.exe (Microsoft Corporation) -> /prefetch:1
ShortcutWithArgument: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) ->  -extoff
ShortcutWithArgument: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Ease of Access.lnk -> C:\Windows\System32\control.exe (Microsoft Corporation) -> /name Microsoft.EaseOfAccessCenter
ShortcutWithArgument: C:\Users\user\AppData\Roaming\Microsoft\Windows\SendTo\Fax Recipient.lnk -> C:\Windows\System32\WFS.exe (Microsoft Corporation) -> /SendTo
ShortcutWithArgument: C:\Users\user\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Media Player.lnk -> C:\Program Files (x86)\Windows Media Player\wmplayer.exe (Microsoft Corporation) -> /prefetch:1
 
 
InternetURL: C:\Users\Administrator\Favorites\Links for United States\GobiernoUSA.gov.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=129792
InternetURL: C:\Users\Administrator\Favorites\Links for United States\USA.gov.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=129791
InternetURL: C:\Users\Administrator\Favorites\Links\Suggested Sites.url -> URL: hxxps://ieonline.microsoft.com/#ieslice
InternetURL: C:\Users\Administrator\Favorites\Links\Web Slice Gallery.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=121315
InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Get Help.url -> URL: hxxp://java.com/help
InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java\Visit Java.com.url -> URL: hxxp://java.com/
InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HxD Hex Editor\Website.url -> URL: hxxp://mh-nexus.de/hxd/
InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Foolish IT\www.foolibleep.com.url -> URL: hxxp://www.foolibleep.com
InternetURL: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner\CCleaner Homepage.url -> URL: hxxp://www.piriform.com/ccleaner
InternetURL: C:\Users\Default.AVID4\Favorites\Links for United States\GobiernoUSA.gov.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=129792
InternetURL: C:\Users\Default.AVID4\Favorites\Links for United States\USA.gov.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=129791
InternetURL: C:\Users\Default.AVID4\Favorites\Links\Web Slice Gallery.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=121315
InternetURL: C:\Users\editor\OneDrive\Documents\ryan's Notebook.url -> URL: hxxps://onedrive.live.com/redir.aspx?cid=f4dba149944a2544&resid=F4DBA149944A2544!400&type=3
InternetURL: C:\Users\editor\Favorites\Links for United States\GobiernoUSA.gov.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=129792
InternetURL: C:\Users\editor\Favorites\Links for United States\USA.gov.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=129791
InternetURL: C:\Users\editor\Favorites\Links\Suggested Sites.url -> URL: hxxps://ieonline.microsoft.com/#ieslice
InternetURL: C:\Users\editor\Downloads\V_Airport_Departure_Board_381\shareAE.com.URL -> URL: hxxp://shareae.com/
InternetURL: C:\Users\editor\Downloads\sdae093\Stardust_Windows_v0.9.3\Open support ticket.url -> URL: hxxp://aescripts.com/contact/?direct=1&sku=SLS-SUL
InternetURL: C:\Users\editor\Downloads\sdae093\Stardust_Windows_v0.9.3\Stardust Online User Guide.url -> URL: hxxps://www.superluminal.tv/tutorial
InternetURL: C:\Users\editor\Downloads\10201327-20-particular-presets-magic-pack\10201327-20-particular-presets-magic-pack\Please Visit here shareAE.com.URL -> URL: hxxp://shareae.com/after-effects-project/
InternetURL: C:\Users\editor\Downloads\10201327-20-particular-presets-magic-pack\10201327-20-particular-presets-magic-pack\VIP AE PROJECT.URL -> URL: hxxp://shareae.com/vip-ae-project/
InternetURL: C:\Users\editor\Desktop\AETVN.url -> URL: hxxps://post.aetvn.com/?u=Punched_in_the_Head_Productions&p=jG5YeKiw9N
InternetURL: C:\Users\IUSR_Servs\Favorites\Links for United States\GobiernoUSA.gov.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=129792
InternetURL: C:\Users\IUSR_Servs\Favorites\Links for United States\USA.gov.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=129791
InternetURL: C:\Users\IUSR_Servs\Favorites\Links\Web Slice Gallery.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=121315
InternetURL: C:\Users\user\Favorites\Links for United States\GobiernoUSA.gov.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=129792
InternetURL: C:\Users\user\Favorites\Links for United States\USA.gov.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=129791
InternetURL: C:\Users\user\Favorites\Links\Web Slice Gallery.url -> URL: hxxp://go.microsoft.com/fwlink/?LinkId=121315
 
==================== End of Shortcut.txt =============================
 

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 05-07-2017
Ran by editor (05-07-2017 19:49:52)
Running from C:\Users\editor\Downloads
Windows 7 Professional Service Pack 1 (X64) (2013-06-14 15:48:05)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
28A160AA3B364589BE10 (S-1-5-21-3225783554-34173836-2973484787-1011 - Limited - Enabled)
Administrator (S-1-5-21-3225783554-34173836-2973484787-500 - Administrator - Enabled) => C:\Users\Administrator
ASP.NET2 (S-1-5-21-3225783554-34173836-2973484787-1012 - Limited - Enabled)
ASPNET (S-1-5-21-3225783554-34173836-2973484787-1005 - Limited - Enabled)
Default (S-1-5-21-3225783554-34173836-2973484787-1013 - Administrator - Enabled) => C:\Users\Default.AVID4
editor (S-1-5-21-3225783554-34173836-2973484787-1001 - Administrator - Enabled) => C:\Users\editor
Guest (S-1-5-21-3225783554-34173836-2973484787-501 - Limited - Disabled)
iusr_serv (S-1-5-21-3225783554-34173836-2973484787-1015 - Administrator - Disabled)
IUSR_Servs (S-1-5-21-3225783554-34173836-2973484787-1014 - Administrator - Disabled) => C:\Users\IUSR_Servs
user (S-1-5-21-3225783554-34173836-2973484787-1000 - Administrator - Disabled) => C:\Users\user
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Microsoft Security Essentials (Disabled - Up to date) {71A27EC9-3DA6-45FC-60A7-004F623C6189}
AS: Microsoft Security Essentials (Disabled - Up to date) {CAC39F2D-1B9C-4A72-5A17-3B3D19BB2B34}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
7-Zip 16.04 (x64 edition) (HKLM\...\{23170F69-40C1-2702-1604-000001000000}) (Version: 16.04.00.0 - Igor Pavlov)
Adobe Acrobat DC (HKLM-x32\...\{AC76BA86-1033-FFFF-7760-0C0F074E4100}) (Version: 17.009.20044 - Adobe Systems Incorporated)
Adobe Acrobat XI Pro (HKLM-x32\...\{23D3F585-AE29-4670-8E3E-64A0EFB29240}) (Version: 11.0 - Adobe Systems Incorporated)
Adobe After Effects CC 2014 (HKLM-x32\...\{2B22C750-5C3B-4738-B621-BA786AC7A494}) (Version: 13.0.0 - Adobe Systems Incorporated)
Adobe After Effects CC 2015 (HKLM-x32\...\{147EC100-14BE-45EF-AB42-35BAEE7D02F0}) (Version: 13.5.0 - Adobe Systems Incorporated)
Adobe After Effects CC 2017 (HKLM-x32\...\AEFT_14_2_1) (Version: 14.2.1 - Adobe Systems Incorporated)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 14.0.0.178 - Adobe Systems Incorporated)
Adobe Audition CC 2017 (HKLM-x32\...\AUDT_10_1_1) (Version: 10.1.1 - Adobe Systems Incorporated)
Adobe Bridge CC 2017 (HKLM-x32\...\KBRG_7_0) (Version: 7.0 - Adobe Systems Incorporated)
Adobe Character Animator CC (Beta) (HKLM-x32\...\ANMLBETA_1_0_6) (Version: 1.0.6 - Adobe Systems Incorporated)
Adobe Creative Cloud (HKLM-x32\...\Adobe Creative Cloud) (Version: 4.1.1.202 - Adobe Systems Incorporated)
Adobe Flash Player 26 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 26.0.0.131 - Adobe Systems Incorporated)
Adobe Flash Player 26 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 26.0.0.131 - Adobe Systems Incorporated)
Adobe Illustrator CC 2017 (HKLM-x32\...\ILST_21_1_0) (Version: 21.1.0 - Adobe Systems Incorporated)
Adobe InDesign CC 2017 (HKLM-x32\...\IDSN_12_1_0) (Version: 12.1.0 - Adobe Systems Incorporated)
Adobe Lightroom (HKLM-x32\...\{8048A5DF-8A70-5BE1-954B-E0FDE1BD0D0D}) (Version: 6.10.1 - Adobe Systems Incorporated)
Adobe Media Encoder CC 2014 (HKLM-x32\...\{663DEEEF-EF34-4DCB-8687-73A7AA146E02}) (Version: 8.0.0 - Adobe Systems Incorporated)
Adobe Media Encoder CC 2015 (HKLM-x32\...\{0FAC7130-BEC5-47A5-8813-1D339B8326ED}) (Version: 9.0.0 - Adobe Systems Incorporated)
Adobe Media Encoder CC 2017 (HKLM-x32\...\AME_11_1_2) (Version: 11.1.2 - Adobe Systems Incorporated)
Adobe Photoshop CC 2015.5 (HKLM-x32\...\PHSP_17_0_1) (Version: 17.0.1 - Adobe Systems Incorporated)
Adobe Photoshop CC 2017 (HKLM-x32\...\PHSP_18_1_1) (Version: 18.1.1 - Adobe Systems Incorporated)
Adobe Premiere Pro CC 2017 (HKLM-x32\...\PPRO_11_1_2) (Version: 11.1.2 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.03) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.03 - Adobe Systems Incorporated)
Adobe® Content Viewer (HKLM-x32\...\com.adobe.dmp.contentviewer) (Version: 3.4.3 - Adobe Systems, Incorporated)
AJA Adobe Win 12.3.7-x64 (HKLM\...\{92CAB133-E990-49AF-906D-652F4B9949F2}) (Version: 12.3.7 - AJA)
AJA ControlRoom 12.3.7-x64 (HKLM\...\{B0126CCD-F5D8-4DBB-AB9E-9A6D2C5B273F}) (Version: 12.3.7 - AJA)
AJA OpenIo Plug-in 12.3.7 (HKLM\...\{45672CDA-C35F-496E-9C15-0C684BAF566A}) (Version: 12.3.7 - AJA)
AJA Retail Installer 12.3.7-x64 (HKLM-x32\...\{c3aa5500-bf86-4ff0-ad33-16d3970fbf17}) (Version: 12.3.7 - AJA)
AJA Win Drivers 12.3.7-x64 (HKLM\...\{3520B7AF-BDA2-4D34-ACD7-C755989A3D8A}) (Version: 12.3.7 - AJA)
AJA Wirecast Plugin 12.3.7-x64 (HKLM\...\{276B90FA-77CB-4F27-9AC9-19FD97BA89F2}) (Version: 12.3.7 - AJA)
AnalogExif (HKLM-x32\...\AnalogExif) (Version: 0.0.4.1 - C-41 Bytes)
Ansel (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Ansel) (Version: 372.70 - NVIDIA Corporation) Hidden
Apple Application Support (HKLM-x32\...\{46F044A5-CE8B-4196-984E-5BD6525E361D}) (Version: 2.3.6 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Aspera Connect 3.6.1.111228 (HKLM-x32\...\{EC793CAC-7C41-4817-BA98-7E481A79F9CF}) (Version: 3.6.1.111228 - © Copyright IBM Corp. 2014) Hidden
Aspera Connect 3.6.1.111228 (HKU\S-1-5-21-3225783554-34173836-2973484787-1001\...\Aspera Connect 3.6.1.111228) (Version: 3.6.1.111228 - © Copyright IBM Corp. 2014)
ASPI Repair (HKLM-x32\...\ASPI Repair) (Version:  - )
Autodesk 3ds Max 2018 (HKLM\...\{52B37EC7-D836-0410-0764-3C24BCED2010}) (Version: 20.0.0.966 - Autodesk) Hidden
Autodesk 3ds Max 2018 (HKLM\...\Autodesk 3ds Max 2018) (Version: 20.0.0.966 - Autodesk)
Autodesk Advanced Material Library Image Library 2018 (HKLM-x32\...\{177AD7F6-9C77-4E50-BA53-B7259C5F282D}) (Version: 16.11.1.0 - Autodesk)
Autodesk Backburner 2018.0 (HKLM-x32\...\{0038F5AA-8482-4BB2-8A28-3FEA1D58D78A}) (Version: 18.0.0.0 - Autodesk)
Autodesk Certificate Package  (x64) - 5.1.4 (HKLM\...\{79D5E475-5EAB-4474-84F5-BD612337A175}) (Version: 5.1.4.100 - Autodesk)
Autodesk Civil View for 3ds Max 2018 64-bit (HKLM\...\{51C8EDF7-FFDA-430A-8B5E-1895FF14ACB7}) (Version: 20.0.0.0 - Autodesk)
Autodesk Desktop App (HKLM-x32\...\Autodesk Desktop App) (Version: 7.0.5.154 - Autodesk)
Autodesk Inventor Server Engine for 3ds Max 2018 (HKLM\...\{1984E20A-184B-4073-87F4-6755F3EE5769}) (Version: 20.0 - Autodesk)
Autodesk License Service (x64) - 5.1.4 (HKLM\...\{3609A8D9-FC0C-4C9B-9F58-0B1D1A4FE556}) (Version: 5.1.4.0 - Autodesk)
Autodesk Material Library 2018 (HKLM-x32\...\{7847611E-92E9-4917-B395-71C91D523104}) (Version: 16.11.1.0 - Autodesk)
Autodesk Material Library Base Resolution Image Library 2018 (HKLM-x32\...\{FCDED119-A969-4E48-8A32-D21AD6B03253}) (Version: 16.11.1.0 - Autodesk)
Autodesk Material Library Medium Resolution Image Library 2018 (HKLM-x32\...\{6EC5DA32-D02D-47D4-A3C4-988C1BC1A5FE}) (Version: 16.11.1.0 - Autodesk)
Autodesk Revit Interoperability for 3ds Max 2018 (HKLM\...\{0BB716E0-1800-0610-0000-097DC2F354DF}) (Version: 18.0.0.412 - Autodesk) Hidden
Autodesk Revit Interoperability for 3ds Max 2018 (HKLM\...\Autodesk Revit Interoperability for 3ds Max 2018) (Version: 18.0.0.412 - Autodesk)
Autodesk SketchBook (HKLM\...\{E616AD44-B585-4460-9EBA-037B311F16EB}) (Version: 8.11.0000 - Autodesk)
Avid Application Manager (HKLM\...\{99E377DB-D2D0-44A5-8533-AA8BE1381644}) (Version: 2.5.12.13645 - Avid Technology, Inc.)
Avid Codecs PE (HKLM-x32\...\{22B25A58-6F1A-431B-82D9-38E56E05540A}) (Version: 2.5.1.38635 - Avid Technology, Inc.)
Avid DVD by Sonic (HKLM-x32\...\{353073E8-1185-4823-8F3A-A1F4AF6DD2CD}) (Version: 6.4.4 - Avid Technology)
Avid FX (64 Bit) (HKLM\...\{BE3248BC-8197-4B3F-AECA-CEE8E0FAED60}) (Version: 6.2.0 - Boris FX, Inc.)
Avid ISIS Client (HKLM\...\{2D892249-BB1D-46C7-98DF-73437484D05E}) (Version: 4.7.7.16070 - Avid)
Avid License Control (HKLM-x32\...\{F187D064-F101-4E95-8D05-4027809AA0F8}) (Version: 3.0.1 - Avid Technology, Inc.)
Avid Media Composer (HKLM\...\{95EB1E9C-F759-4427-8EEE-F96C48541A06}) (Version: 8.6.3.43955 - Avid Technology)
bl (HKLM-x32\...\{2A075BB4-E976-4278-BF3F-E5C6945D84C0}) (Version: 1.0.0 - Your Company Name) Hidden
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Boris RED 5 (64 Bit) CE (HKLM\...\{B7C36745-A262-4898-8E63-A884271E6DB9}) (Version: 5.6.0003 - Boris FX, Inc.)
Bulk Rename Utility 2.7.1.3 (HKLM\...\Bulk Rename Utility_is1) (Version:  - TGRMN Software)
CCleaner (HKLM\...\CCleaner) (Version: 5.11 - Piriform)
Chrome Remote Desktop Host (HKLM-x32\...\{BAF2702F-FB88-48E4-A305-588DB8FDD834}) (Version: 59.0.3071.47 - Google Inc.)
CINEMA 4D 16.050 (HKLM\...\MAXON8B6F11F9) (Version: 16.050 - MAXON Computer GmbH)
Color Suite v11.1.4 (HKLM-x32\...\{99487911-8011-42BC-B594-8B02BFD32B1D}_is1) (Version: 11.1.4 - Red Giant, LLC)
CryptoPrevent (HKLM-x32\...\{5C5B24E7-4694-4049-A222-CCE7D3FAC63F}_is1) (Version:  - Foolish IT LLC)
DaVinci Resolve (HKLM\...\{2E7A93F9-2275-4EA1-A03F-4EB7EB573E7D}) (Version: 12.3.1001 - Blackmagic Design)
DirectX 9 Runtime (HKLM-x32\...\{AF9E97C1-7431-426D-A8D5-ABE40995C0B1}) (Version: 1.00.0000 - Sonic Solutions) Hidden
Effects Suite v11.1.7 (HKLM-x32\...\{4DD8EE5E-F571-4EC8-9526-E7C62FE39B19}_is1) (Version: 11.1.7 - Red Giant, LLC)
Eye Scream Factory Sampler Pack for Boris RED and Avid FX 64-Bit (HKLM\...\{E699A1D9-359D-46E4-BD82-F0C46D8F3A67}) (Version: 1.00.0000 - Boris FX, Inc.)
FileZilla Client 3.14.1 (HKLM-x32\...\FileZilla Client) (Version: 3.14.1 - Tim Kosse)
Flicker Free (HKLM\...\Flicker Free AVX2) (Version: 1.1.2 - Digital Anarchy, Inc.)
GenArts Sapphire Plug-ins 7.08 for Avid AVX Products (HKLM\...\GenArts Sapphire Plug-ins for Avid AVX_v6_is1) (Version:  - )
GenArts Sapphire Plug-ins 7.09 for After Effects and Compatible (HKLM\...\GenArts Sapphire AE_is1) (Version:  - )
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 59.0.3071.115 - Google Inc.)
HP Performance Advisor (HKLM-x32\...\{C6B87001-37EC-461E-AFE5-BECE03C47743}) (Version: 1.4.3926 - Hewlett-Packard Company)
HWiNFO64 Version 5.50 (HKLM\...\HWiNFO64_is1) (Version: 5.50 - Martin Malík - REALiX)
HxD Hex Editor version 1.7.7.0 (HKLM-x32\...\HxD Hex Editor_is1) (Version: 1.7.7.0 - Maël Hörz)
Inkscape 0.91 (HKLM\...\{81922150-317E-4BB0-A31D-FF1C14F707C5}) (Version: 0.91 - inkscape.org)
Intel® C++ Redistributables on Intel® 64 (HKLM-x32\...\{F70BCE36-25F2-4475-A918-6209B3D85BF3}) (Version: 15.0.179 - Intel Corporation)
Intel® Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
Intel® Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.1.21.1134 - Intel Corporation)
Intel® Network Connections 16.8.45.1 (HKLM\...\PROSetDX) (Version: 16.8.45.1 - Intel)
iSkysoft iTube Studio(Build 4.2.2.0) (HKLM-x32\...\iSkysoft iTube Studio_is1) (Version: 4.2.2.0 - iSkysoft Software)
iZotope Insight (HKLM-x32\...\iZotope Insight_is1) (Version: 1.04 - iZotope, Inc.)
iZotope RX 5 (HKLM-x32\...\iZotope RX 5_is1) (Version: 5.01 - iZotope, Inc.)
iZotope RX Loudness Control (HKLM-x32\...\iZotope RX Loudness Control_is1) (Version: 1.01 - iZotope, Inc.)
Java 8 Update 131 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F64180131F0}) (Version: 8.0.1310.11 - Oracle Corporation)
Java™ SE Runtime Environment 6 Update 6 (HKLM\...\{6448F0A8-6813-11D6-A77B-00B0D0160060}) (Version: 1.6.0.60 - ##ID_STRING_COMPANY_NAME##)
Keyspan USB Serial Adapter (HKLM-x32\...\{2E97DE76-851A-48AA-A0D6-665860FAD9CA}) (Version: 3.7.2 - Keyspan)
Malwarebytes version 3.1.2.1733 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.1.2.1733 - Malwarebytes)
MAXtoA for 3ds Max 2018 (HKLM\...\{471069C7-09E2-4289-8EB7-852237FD867E}) (Version: 1.0.712.0 - Solid Angle)
MediaInfo 0.7.89 (HKLM\...\MediaInfo) (Version: 0.7.89 - MediaArea.net)
MediaShuttlePlugin-v5.4 (HKLM-x32\...\{6B104C5D-6724-4779-B3D7-636C4E4033E8}) (Version: 5.4.3.70626 - Signiant Inc.)
MediaShuttlePlugin-v5.4 (HKLM-x32\...\{B0861461-F97C-4630-A406-3179C86267B6}) (Version: 5.4.2.68759 - Signiant Inc.)
Microsoft .NET Framework 1.1 (HKLM-x32\...\{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}) (Version: 1.1.4322 - Microsoft)
Microsoft .NET Framework 4.6.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.6.01055 - Microsoft Corporation)
Microsoft Mouse and Keyboard Center (HKLM\...\Microsoft Mouse and Keyboard Center) (Version: 1.1.500.0 - Microsoft Corporation)
Microsoft Office 365 - en-us (HKLM\...\O365HomePremRetail - en-us) (Version: 16.0.8229.2073 - Microsoft Corporation)
Microsoft Office Click-to-Run 2010 (HKLM-x32\...\Office14.Click2Run) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Starter 2010 - English (HKLM-x32\...\{90140011-0066-0409-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-3225783554-34173836-2973484787-1001\...\OneDriveSetup.exe) (Version: 17.3.6917.0607 - Microsoft Corporation)
Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.10.209.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50907.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6E8E85E8-CE4B-4FF5-91F7-04999C9FAE6A}) (Version: 8.0.50727.42 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729 (HKLM\...\{2DFD8316-9EF1-3210-908C-4CB61961C1AC}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{527BBE2F-1FED-3D8B-91CB-4DB0F838E69E}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24215 (HKLM-x32\...\{d992c12e-cab2-426f-bde3-fb8c53950b0d}) (Version: 14.0.24215.1 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24212 (HKLM-x32\...\{462f63a8-6347-4894-a1b3-dbfe3a4c981d}) (Version: 14.0.24212.0 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Mozilla Firefox 47.0.2 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 47.0.2 (x86 en-US)) (Version: 47.0.2 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 47.0.2.6148 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
nablet XAVC XDCAM AMA Plug-In 4.0.3 (HKLM\...\{8AC11C50-D4A8-4053-8645-C037E05A90EA}_is1) (Version: 4.0.3.1146 - nablet GmbH)
NewBlue Titler Pro 2 for Avid (HKLM-x32\...\NewBlue Titler Pro 2 for Avid) (Version: 1.0 - NewBlue)
NewBlue Titler Pro 2.5 for Avid (HKLM-x32\...\NewBlue Titler Pro 2.5 for Avid) (Version: 1.0 - NewBlue)
NewBlue Titler Pro 4 (HKLM-x32\...\NewBlue Titler Pro 4) (Version: 1.0 - NewBlue)
Nik Collection (HKLM-x32\...\Nik Collection) (Version: 1.2.11 - Google)
Notepad++ (32-bit x86) (HKLM-x32\...\Notepad++) (Version: 7.3.2 - Notepad++ Team)
NVIDIA 3D Vision Controller Driver 369.04 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 369.04 - NVIDIA Corporation)
NVIDIA 3D Vision Driver 372.70 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 372.70 - NVIDIA Corporation)
NVIDIA Graphics Driver 372.70 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 372.70 - NVIDIA Corporation)
NVIDIA HD Audio Driver 1.3.34.15 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.15 - NVIDIA Corporation)
NVIDIA mental ray and IRay feature plugins for 3ds Max 2018 (HKLM\...\{C76BBD60-09DB-43B3-B5B0-BF00C80B500C}) (Version: 19.0.0.0 - Autodesk)
NVIDIA nView 148.03 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NView) (Version: 148.03 - NVIDIA Corporation)
NVIDIA WMI 2.18.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVWMI) (Version: 2.18.0 - NVIDIA Corporation)
Office 16 Click-to-Run Extensibility Component (HKLM-x32\...\{90160000-008C-0000-0000-0000000FF1CE}) (Version: 16.0.8229.2073 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Extensibility Component 64-bit Registration (HKLM\...\{90160000-00DD-0000-1000-0000000FF1CE}) (Version: 16.0.8229.2073 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-008F-0000-1000-0000000FF1CE}) (Version: 16.0.8229.2073 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM-x32\...\{90160000-008C-0409-0000-0000000FF1CE}) (Version: 16.0.8201.2075 - Microsoft Corporation) Hidden
ON1 Effects 10 (HKLM\...\ON1 Effects 10 PE) (Version: 10.5.2 - ON1)
PACE License Support Win64 (HKLM\...\{83E92696-D92D-4c7e-B094-0BE853B191FE}) (Version: 2.5.2.1034 - PACE Anti-Piracy, Inc.) Hidden
PACE License Support Win64 (HKLM-x32\...\InstallShield_{83E92696-D92D-4c7e-B094-0BE853B191FE}) (Version: 2.5.2.1034 - PACE Anti-Piracy, Inc.)
PDF Complete Corporate Edition (HKLM-x32\...\PDF Complete) (Version: 4.2.11 - PDF Complete, Inc)
ph (HKLM-x32\...\{185F9795-9663-4F13-9EF9-307A282ADB5A}) (Version: 1.0.0 - Your Company Name) Hidden
QuickTime 7 (HKLM-x32\...\{FF59BD75-466A-4D5A-AD23-AAD87C5FD44C}) (Version: 7.79.80.95 - Apple Inc.)
RAPID Mode (HKLM\...\{4B94C023-022A-4271-A1D6-744ABE74D220}) (Version: 1.0.0.97 - Samsung Electronics Co., Ltd.) Hidden
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7548 - Realtek Semiconductor Corp.)
Red Giant Link (HKLM-x32\...\{10F82E5B-B611-4C65-8F29-666A9EC5680A}_is1) (Version: 1.9.7.36 - Red Giant, LLC)
RogueKiller version 12.11.4.0 (HKLM\...\8B3D7924-ED89-486B-8322-E8594065D5CB_is1) (Version: 12.11.4.0 - Adlice Software)
Rowbyte Plexus 3.1.0 CE (HKLM\...\Plexus_is1) (Version: 3.1.0 - Team V.R)
Roxio Creator Business (HKLM-x32\...\{537BF16E-7412-448C-95D8-846E85A1D817}) (Version: 10.3.56.24 - Roxio)
Samsung Data Migration (HKLM-x32\...\{3B304604-0BF5-488E-AB95-F2F2E31206F3}) (Version: 3.0 - Samsung)
Samsung Magician (HKLM-x32\...\{29AE3F9F-7158-4ca7-B1ED-28A73ECDB215}_is1) (Version: 5.0.0.790 - Samsung Electronics)
Sentinel Protection Installer 7.6.6 (HKLM-x32\...\{8C2218AC-D1B1-4530-9E67-15164E0E52AB}) (Version: 7.6.6 - SafeNet, Inc.)
ShareMouse v2.0.56 (HKLM-x32\...\ShareMouse_is1) (Version: 2.0.56 - Bartels Media GmbH)
Shooter Suite v12.3.2 (HKLM-x32\...\{7DFC5E36-8CC9-4EC5-9C24-A3770A669E3F}_is1) (Version: 12.3.2 - Red Giant, LLC)
Silicon Laboratories CP210x USB to UART Bridge (Driver Removal) (HKLM-x32\...\SLABCOMM&10C4&EA60) (Version:  - )
Slack (HKU\S-1-5-21-3225783554-34173836-2973484787-1001\...\slack) (Version: 2.6.3 - Slack Technologies)
Sorenson Squeeze (HKLM-x32\...\{AD11F61E-604D-4B15-8FC3-E587224CA3DE}) (Version: 10.1.0 - Sorenson Media)
Trapcode Suite v12.1.5 (HKLM-x32\...\{DFD2DC6B-C634-4C1C-81CC-5EF852E71CEE}_is1) (Version: 12.1.5 - Red Giant, LLC)
Tweaking.com - Windows Repair (HKLM-x32\...\Tweaking.com - Windows Repair) (Version: 3.6.2 - Tweaking.com)
UltraMon (HKLM\...\{D4E62D29-31A1-4938-8CB7-7D275C1AEAC6}) (Version: 3.3.0 - Realtime Soft Ltd)
Universe (HKLM\...\Universe Premium_is1) (Version: 2.1 CE - Team V.R)
VD64Inst (HKLM\...\{DB9C43F7-0B0F-4E43-9E6B-F945C71C469E}) (Version: 1.00.0000 - Roxio, Inc.) Hidden
VideoCopilot Element 3D v2.2.2 CE for After Effects (HKLM\...\Element 3D CE for After Effects_is1) (Version: 2.2.2 - Team V.R)
Visual C++ 64-bit Redistributables (HKLM-x32\...\InstallShield_{5B0E60DB-7741-412F-88B3-E6975D30D019}) (Version: 1.1.0.0929 - PACE Anti-Piracy, Inc.)
Visual C++ Redistributables (HKLM-x32\...\InstallShield_{C2AF7B2D-7018-414B-9B8B-D3C9F3BED04F}) (Version: 1.1.0.0929 - PACE Anti-Piracy, Inc.)
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.4 - VideoLAN)
Vulkan Run Time Libraries 1.0.11.1 (HKLM\...\VulkanRT1.0.11.1) (Version: 1.0.11.1 - LunarG, Inc.)
Wacom Tablet (HKLM\...\Wacom Tablet Driver) (Version: 6.3.22-6 - Wacom Technology Corp.)
WaveAgent (HKLM-x32\...\{053C7D32-3566-452B-9A37-D42B4F4C5379}) (Version: 1.20 - Sound Devices LLC) Hidden
WaveAgent (HKLM-x32\...\InstallShield_{053C7D32-3566-452B-9A37-D42B4F4C5379}) (Version: 1.20 - Sound Devices LLC)
WebShot (HKLM-x32\...\WebShot) (Version: 1.9.3.0 - Nathan Moinvaziri)
WebTablet FB Plugin 32 bit (HKLM-x32\...\Wacom WebTabletPlugin for Internet Explorer and Netscape) (Version: 2.1.0.7 - Wacom Technology Corp.)
WebTablet FB Plugin 64 bit (HKLM\...\Wacom WebTabletPlugin for Internet Explorer and Netscape) (Version: 2.1.0.7 - Wacom Technology Corp.)
WinDirStat 1.1.2 (HKU\S-1-5-21-3225783554-34173836-2973484787-1001\...\WinDirStat) (Version:  - )
Windows Driver Package - Graphics Tablet (WinUsb) USBDevice  (04/10/2014 8.33.30.0) (HKLM\...\142118DF51345EA02D2B1583E102C8FB95FD6D52) (Version: 04/10/2014 8.33.30.0 - Graphics Tablet)
WinRAR 5.30 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.30.0 - win.rar GmbH)
WinSCP 5.5.6 (HKLM-x32\...\winscp3_is1) (Version: 5.5.6 - Martin Prikryl)
Winsent Messenger 2.7.43 (HKLM-x32\...\Winsent Messenger_is1) (Version:  - Winsent Lab, hxxp://www.winsentmessenger.com)
Zemana AntiMalware (HKLM-x32\...\{8F0CD7D1-42F3-4195-95CD-833578D45057}_is1) (Version: 2.74.0.76 - Zemana Ltd.)
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-3225783554-34173836-2973484787-1001_Classes\CLSID\{04A9E854-6F47-4F37-8A10-F896717F0329}\InprocServer32 -> C:\Users\editor\AppData\Local\Programs\Aspera\Aspera Connect\lib\3.6.1\npasperaweb64_3.6.1.111228.dll (Aspera, Inc. )
CustomCLSID: HKU\S-1-5-21-3225783554-34173836-2973484787-1001_Classes\CLSID\{073CB204-6B29-46FC-AB98-451F1D068741}\InprocServer32 -> C:\Program Files\Autodesk\3ds Max 2018\Inventor Server\Bin\TestServer.dll => No File
CustomCLSID: HKU\S-1-5-21-3225783554-34173836-2973484787-1001_Classes\CLSID\{162C6FB5-44D3-435B-903D-E613FA093FB5}\InprocServer32 -> C:\Users\editor\AppData\Local\Microsoft\OneDrive\17.3.6917.0607\amd64\FileCoAuthLib64.dll (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-3225783554-34173836-2973484787-1001_Classes\CLSID\{869C14C8-1830-491F-B575-5F9AB40D2B42}\InprocServer32 -> C:\Program Files\MediaInfo\MediaInfo_InfoTip.dll (MediaArea.net)
CustomCLSID: HKU\S-1-5-21-3225783554-34173836-2973484787-1001_Classes\CLSID\{8C23B656-4E6E-4B45-9920-9617168D39A3}\InprocServer32 -> C:\Program Files\Autodesk\3ds Max 2018\Inventor Server\Bin\TestServer.dll => No File
CustomCLSID: HKU\S-1-5-21-3225783554-34173836-2973484787-1001_Classes\CLSID\{AD17B774-7F87-4141-BB9C-2AEE3841DC4E}\InprocServer32 -> C:\Users\editor\AppData\Local\Programs\Aspera\Aspera Connect\lib\3.6.1\npasperaweb64_3.6.1.111228.dll (Aspera, Inc. )
CustomCLSID: HKU\S-1-5-21-3225783554-34173836-2973484787-1001_Classes\CLSID\{E5B0515D-48D2-4F04-906D-0192ED65A2DD}\InprocServer32 -> C:\Program Files\Autodesk\3ds Max 2018\Inventor Server\Bin\TestServer.dll => No File
ShellIconOverlayIdentifiers: [ AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2017-05-26] ()
ShellIconOverlayIdentifiers: [ AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2017-05-26] ()
ShellIconOverlayIdentifiers: [ AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2017-05-26] ()
ContextMenuHandlers01: [2.0 Zemana AntiMalware] -> {6ABB1C11-E261-4CEA-BBB5-3836225689DD} => C:\Program Files (x86)\Zemana AntiMalware\ZAMShellExt64.dll [2017-07-03] ()
ContextMenuHandlers01: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2016-10-04] (Igor Pavlov)
ContextMenuHandlers01: [AccExt] -> {2A118EB5-5797-4F5E-8B3D-F4ECBA3C98E4} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2017-05-26] ()
ContextMenuHandlers01: [Adobe.Acrobat.ContextMenu] -> {A6595CD1-BF77-430A-A452-18696685F7C7} => C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat Elements\ContextMenuShim64.dll [2015-03-17] (Adobe Systems Inc.)
ContextMenuHandlers01: [ANotepad++64] -> {B298D29A-A6ED-11DE-BA8C-A68E55D89593} => C:\Program Files (x86)\Notepad++\NppShell_06.dll [2017-02-12] ()
ContextMenuHandlers01: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => c:\Program Files\Microsoft Security Client\shellext.dll [2016-11-14] (Microsoft Corporation)
ContextMenuHandlers01: [RXDCExtSvr] -> {0FB82570-BB2D-23D3-8D3B-AC2F34F1FA3C} => c:\Program Files\Roxio\Virtual Drive 10\DC_ShellExt64.dll [2009-06-11] (Sonic Solutions)
ContextMenuHandlers01: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2015-11-18] (Alexander Roshal)
ContextMenuHandlers01: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} =>  -> No File
ContextMenuHandlers02: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => c:\Program Files\Microsoft Security Client\shellext.dll [2016-11-14] (Microsoft Corporation)
ContextMenuHandlers02: [RXDCExtSvr] -> {0FB82570-BB2D-23D3-8D3B-AC2F34F1FA3C} => c:\Program Files\Roxio\Virtual Drive 10\DC_ShellExt64.dll [2009-06-11] (Sonic Solutions)
ContextMenuHandlers03: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-05-09] (Malwarebytes)
ContextMenuHandlers04: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2016-10-04] (Igor Pavlov)
ContextMenuHandlers04: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => c:\Program Files\Microsoft Security Client\shellext.dll [2016-11-14] (Microsoft Corporation)
ContextMenuHandlers04: [MSSE] -> {0365FE2C-F183-4091-AC82-BFC39FB75C49} =>  -> No File
ContextMenuHandlers05: [00nView] -> {1E9B04FB-F9E5-4718-997B-B8DA88302A48} => C:\Program Files\NVIDIA Corporation\nview\nvshell.dll [2016-08-25] ()
ContextMenuHandlers05: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\Windows\system32\nvshext.dll [2016-08-25] (NVIDIA Corporation)
ContextMenuHandlers06: [2.0 Zemana AntiMalware] -> {6ABB1C11-E261-4CEA-BBB5-3836225689DD} => C:\Program Files (x86)\Zemana AntiMalware\ZAMShellExt64.dll [2017-07-03] ()
ContextMenuHandlers06: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2016-10-04] (Igor Pavlov)
ContextMenuHandlers06: [AccExt] -> {2A118EB5-5797-4F5E-8B3D-F4ECBA3C98E4} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2017-05-26] ()
ContextMenuHandlers06: [Adobe.Acrobat.ContextMenu] -> {A6595CD1-BF77-430A-A452-18696685F7C7} => C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat Elements\ContextMenuShim64.dll [2015-03-17] (Adobe Systems Inc.)
ContextMenuHandlers06: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-05-09] (Malwarebytes)
ContextMenuHandlers06: [RXDCExtSvr] -> {0FB82570-BB2D-23D3-8D3B-AC2F34F1FA3C} => c:\Program Files\Roxio\Virtual Drive 10\DC_ShellExt64.dll [2009-06-11] (Sonic Solutions)
ContextMenuHandlers06: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2015-11-18] (Alexander Roshal)
ContextMenuHandlers06: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} =>  -> No File
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {0DDA5EE2-D2E0-4ADE-BD48-1F32CA6DCD5C} - System32\Tasks\Process Explorer-AVID4-editor => C:\USERS\EDITOR\DOWNLOADS\PROCEXP.EXE [2017-06-23] (Sysinternals - www.sysinternals.com)
Task: {107F5220-5785-403C-B9D4-93FAC6E58E53} - System32\Tasks\{5246180D-17E9-44E7-B00B-84603AA4681C} => pcalua.exe -a C:\Users\editor\Downloads\aspichk.exe -d C:\Users\editor\Downloads
Task: {2A8E6DF7-4314-4C90-884B-CF825BE88B20} - System32\Tasks\{0EFF27C7-A00F-43B5-9BBB-3DA9480AFE18} => pcalua.exe -a "C:\Users\editor\Downloads\uclogiDriver 8 D20141212D20141211\Driver 8 D20141212D20141211\SETUP.EXE" -d "C:\Users\editor\Downloads\uclogiDriver 8 D20141212D20141211\Driver 8 D20141212D20141211"
Task: {2FF4CDC8-6D6F-48CF-9ABC-5CCD21277501} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-06-16] (Adobe Systems Incorporated)
Task: {3ECECB5E-2933-4B06-AACA-ABD72C29A8AB} - System32\Tasks\SamsungMagician => C:\Program Files (x86)\Samsung\Samsung Magician\SamsungMagician.exe [2016-11-23] (Samsung Electronics Co. Ltd.)
Task: {44C2B487-AE8E-444A-B9C5-D0415C9520F0} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-10-19] (Piriform Ltd)
Task: {4806DB2F-018D-4702-8C41-B3A4362CB64E} - System32\Tasks\Tweaking.com - Windows Repair Tray Icon => C:\Program Files (x86)\Tweaking.com\Windows Repair (All in One)\WR_Tray_Icon.exe [2015-03-11] (Tweaking.com)
Task: {4EEE1D6D-C16D-45BB-BBCC-C9CD69459C31} - System32\Tasks\{C028CBEA-D7B3-449B-816B-03FF97DFFDED} => pcalua.exe -a C:\Users\editor\Desktop\tron\resources\stage_4_repair\msi_cleanup\msizap.exe -d C:\Users\editor\Desktop\tron\resources\stage_4_repair\msi_cleanup
Task: {5168BB0B-AFDB-4097-9422-D8692D7CFCEE} - System32\Tasks\{965FFC45-B3DE-4D68-BD13-E3D80302944E} => C:\Users\editor\Downloads\aspi_471a2 (1).exe [2014-10-27] ()
Task: {5A01A823-37CF-4176-81B8-6EF634EBB666} - System32\Tasks\GoogleUpdateTaskMachineCore1d15d7ca0fb01c1 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-04-17] (Google Inc.)
Task: {5B8C7C78-D71A-404B-95AE-97BC06F12E7A} - System32\Tasks\{D7E4CE96-FB2C-4FB6-936E-5B9ADBF2CCD9} => pcalua.exe -a C:\Windows\SetupX32.EXE -c  /@SetupExt\Tablet
Task: {6169620B-D1E2-41F2-A717-C1EBD74F3C7E} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2017-04-25] (Adobe Systems Incorporated)
Task: {6FF82184-9BD1-4EC4-B0FA-5D61DA48FC03} - System32\Tasks\Microsoft_Hardware_Launch_devicecenter_exe => c:\Program Files\Microsoft Device Center\devicecenter.exe [2012-06-26] (Microsoft)
Task: {756DAEA3-1375-409E-ADDE-4700464B69E4} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerRegistration => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2017-07-05] ()
Task: {796FF54A-AE71-4FAD-9030-4C96266B5F51} - System32\Tasks\{53C8661A-82EF-4B48-BED6-4C1DC4A568A5} => C:\Users\editor\Downloads\aspi_471a2 (1).exe [2014-10-27] ()
Task: {7F73A9E3-5BC5-4AC8-B7F9-146A83F424B5} - System32\Tasks\{F5B0534F-1BB1-4ED1-A5E0-84F87BA35513} => C:\Users\editor\Downloads\drivers\MONOPRICE10594\Setup.exe [2013-08-29] ()
Task: {8E1EEBCE-440E-420F-BF4D-8F847FB96F21} - System32\Tasks\Microsoft_Hardware_Launch_itype_exe => c:\Program Files\Microsoft Device Center\itype.exe [2012-06-26] (Microsoft Corporation)
Task: {9580FB16-4879-4944-981A-ED5D591B8A68} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-04-17] (Google Inc.)
Task: {A518FE1D-5DFB-4D2F-BDF0-1932AB8171C4} - System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe => c:\Program Files\Microsoft Device Center\ipoint.exe [2012-06-26] (Microsoft Corporation)
Task: {ABBCDB46-A194-4C19-9F56-B2928D0265E3} - System32\Tasks\{71141076-B9FD-48ED-BB23-76DDA19B0BB2} => pcalua.exe -a C:\Windows\SetupX32.EXE -c  /@SetupExt\Tablet
Task: {ACDF5689-926F-4E8B-9F42-3318F2C394C7} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16\OLicenseHeartbeat.exe [2017-07-05] (Microsoft Corporation)
Task: {C218716E-3783-4AAA-B397-073C820897B0} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2017-06-23] (Microsoft Corporation)
Task: {E0DCFC1D-A0B3-43FB-BCB0-EDA36075A28E} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2017-06-23] (Microsoft Corporation)
Task: {E4C66C6F-514F-43C0-BEF3-C748CA73ABAB} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-04-17] (Google Inc.)
Task: {ECE3BD73-146A-4415-BC6C-9FBFE09C994A} - System32\Tasks\AdobeAAMUpdater-1.0-AVID4-editor => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2016-07-01] (Adobe Systems Incorporated)
Task: {F49ED4E1-89A3-4002-A69E-BCCB391854E0} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerLogon => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2017-07-05] ()
Task: {FDE60256-B011-48D7-9E6B-4043CB205F7C} - System32\Tasks\Red Giant Link => C:\Program Files (x86)\Red Giant Link\Red Giant Link.exe [2015-12-15] ()
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\Windows\Tasks\AdobeAAMUpdater-1.0-AVID4-Administrator.job => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe
Task: C:\Windows\Tasks\AdobeAAMUpdater-1.0-AVID4-editor.job => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
 
==================== Shortcuts & WMI ========================
 
(The entries could be listed to be restored or removed.)
 
 
ShortcutWithArgument: C:\Users\editor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Chrome Remote Desktop.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) ->  --profile-directory=Default --app-id=gbchcmhmhahfdphkhkmpfmihenigjmpp
 
==================== Loaded Modules (Whitelisted) ==============
 
2015-08-12 16:15 - 2015-08-12 16:15 - 07803392 _____ () c:\program files\avid\editor transcode\transcodeservice\jre\bin\server\jvm.dll
2016-09-01 19:18 - 2016-09-01 19:18 - 31302408 _____ () C:\Program Files\Avid\Avid Media Composer\il.dll
2016-09-01 19:18 - 2016-09-01 19:18 - 07266056 _____ () C:\Program Files\Avid\Avid Media Composer\ml.dll
2016-09-01 19:18 - 2016-09-01 19:18 - 04166920 _____ () C:\Program Files\Avid\Avid Media Composer\gk.dll
2016-09-01 19:18 - 2016-09-01 19:18 - 00403720 _____ () C:\Program Files\Avid\Avid Media Composer\mt.dll
2016-09-01 19:18 - 2016-09-01 19:18 - 04398344 _____ () C:\Program Files\Avid\Avid Media Composer\ilgpu.dll
2017-05-26 03:18 - 2017-05-26 03:18 - 00492112 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll
2016-02-19 21:07 - 2017-07-05 16:15 - 08932040 _____ () C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\1033\GrooveIntlResource.dll
2017-07-05 19:27 - 2017-07-05 19:27 - 04110280 _____ () C:\Users\editor\Desktop\AdwCleaner.exe
2017-05-15 11:26 - 2017-05-31 13:38 - 01658312 _____ () C:\Program Files\Tablet\Wacom\libxml2.dll
2015-10-16 06:02 - 2015-10-16 06:02 - 00043480 _____ () C:\Program Files\FileZilla FTP Client\fzshellext_64.dll
2017-02-12 18:31 - 2017-02-12 18:31 - 00230064 _____ () C:\Program Files (x86)\Notepad++\NppShell_06.dll
2017-07-03 18:12 - 2017-07-03 18:12 - 00155504 _____ () C:\Program Files (x86)\Zemana AntiMalware\ZAMShellExt64.dll
2017-06-27 22:02 - 2017-06-22 23:21 - 03807064 _____ () C:\Program Files (x86)\Google\Chrome\Application\59.0.3071.115\libglesv2.dll
2017-06-27 22:02 - 2017-06-22 23:21 - 00100184 _____ () C:\Program Files (x86)\Google\Chrome\Application\59.0.3071.115\libegl.dll
2017-02-12 18:31 - 2017-02-12 18:31 - 00021680 _____ () C:\Program Files (x86)\Notepad++\plugins\NppExport.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
AlternateDataStreams: C:\ProgramData\Microsoft:0LzQmy2yLXIkuOxWrd [1910]
AlternateDataStreams: C:\ProgramData\Microsoft:kcBk6PcxHyvHjtR8 [2314]
AlternateDataStreams: C:\ProgramData\Microsoft:lIp54pnOEvBhOzqQjZpz2nn [2310]
AlternateDataStreams: C:\ProgramData\Microsoft:Ocomea4gZtY3lSOUf5iphCE [2038]
AlternateDataStreams: C:\ProgramData\Microsoft:v3g4yepAVzDTtez7meXIUiueJ [1956]
AlternateDataStreams: C:\ProgramData\Microsoft:Xm9UIZv3H4zTt7eqpuDLw7zIg [2260]
AlternateDataStreams: C:\ProgramData\PACE:B90686C2DDD4C048 [217]
AlternateDataStreams: C:\Users\editor\Cookies:EOqXQzoQSm4Yr9HXggRR4KKY [1930]
AlternateDataStreams: C:\Users\editor\Downloads\PICKUPS1.avb:BINSTATE_RSRC [131074]
AlternateDataStreams: C:\Users\editor\Downloads\TrueLife_FullScreenCredits_CreditCrunch.avb:BINSTATE_RSRC [131074]
AlternateDataStreams: C:\Users\editor\AppData\Local\Temporary Internet Files:KXXPwIqcZrAoHR5V6MIVZYrg [2354]
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\74966351.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\91848786.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppXSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BFE => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BITS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ClipSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MpsSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\msiserver => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SharedAccess => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vss => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WSService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\74966351.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\91848786.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\AppXSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\BITS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ClipSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\msiserver => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\vss => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WSService => ""="Service"
 
==================== Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
 
==================== Hosts content: ===============================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2009-07-13 22:34 - 2015-11-04 16:14 - 00000855 _____ C:\Windows\system32\Drivers\etc\hosts
 
127.0.0.1       localhost
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-3225783554-34173836-2973484787-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\editor\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
HKU\S-1-5-21-3225783554-34173836-2973484787-500\Control Panel\Desktop\\Wallpaper -> C:\Windows\BGInfo.bmp
DNS Servers: 8.8.8.8 - 8.8.4.4
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 2) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is disabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [SPPSVC-In-TCP-NoScope] => (Allow) %SystemRoot%\system32\sppsvc.exe
FirewallRules: [SPPSVC-In-TCP] => (Allow) %SystemRoot%\system32\sppsvc.exe
FirewallRules: [RemoteAssistance-PnrpSvc-UDP-In-EdgeScope-Active] => (Block) %systemroot%\system32\svchost.exe
FirewallRules: [RemoteAssistance-SSDPSrv-In-TCP-Active] => (Block) %SystemRoot%\system32\svchost.exe
FirewallRules: [RemoteAssistance-SSDPSrv-In-UDP-Active] => (Block) %SystemRoot%\system32\svchost.exe
FirewallRules: [RemoteAssistance-In-TCP-EdgeScope-Active] => (Block) %SystemRoot%\system32\msra.exe
FirewallRules: [RemoteAssistance-DCOM-In-TCP-NoScope-Active] => (Block) %SystemRoot%\system32\svchost.exe
FirewallRules: [RemoteAssistance-RAServer-In-TCP-NoScope-Active] => (Block) %SystemRoot%\system32\raserver.exe
FirewallRules: [RemoteAssistance-PnrpSvc-UDP-In-EdgeScope] => (Block) %systemroot%\system32\svchost.exe
FirewallRules: [RemoteAssistance-In-TCP-EdgeScope] => (Block) %SystemRoot%\system32\msra.exe
FirewallRules: [{9B6A2586-F0AB-48CB-878E-1A6C2000D9AF}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe
FirewallRules: [TCP Query User{2C488D4F-A675-4832-853F-8FEF66C4B594}C:\program files\avid\isis client\client manager\isisclientmanager.exe] => (Allow) C:\program files\avid\isis client\client manager\isisclientmanager.exe
FirewallRules: [UDP Query User{6DF6029E-154C-4FB8-9B45-8831203EFCB1}C:\program files\avid\isis client\client manager\isisclientmanager.exe] => (Allow) C:\program files\avid\isis client\client manager\isisclientmanager.exe
FirewallRules: [TCP Query User{1967308B-3F51-4509-8A4F-5390912CA74B}C:\program files\avid\application manager\avidapplicationmanager.exe] => (Allow) C:\program files\avid\application manager\avidapplicationmanager.exe
FirewallRules: [UDP Query User{3BE96BB9-C69D-478C-9089-C0BE822C15EB}C:\program files\avid\application manager\avidapplicationmanager.exe] => (Allow) C:\program files\avid\application manager\avidapplicationmanager.exe
FirewallRules: [TCP Query User{204239F4-7F02-4DD8-BDA5-BF4B85370105}C:\program files\avid\application manager\avidappmanhelper.exe] => (Allow) C:\program files\avid\application manager\avidappmanhelper.exe
FirewallRules: [UDP Query User{DFC04E97-9E31-43E7-82AE-EACE469AE657}C:\program files\avid\application manager\avidappmanhelper.exe] => (Allow) C:\program files\avid\application manager\avidappmanhelper.exe
FirewallRules: [TCP Query User{B193B375-6183-4ABA-AF3F-8F8201613AF5}C:\program files (x86)\google\chrome\application\chrome.exe] => (Allow) C:\program files (x86)\google\chrome\application\chrome.exe
FirewallRules: [UDP Query User{330B848E-1632-4674-A135-CB38DF5FE133}C:\program files (x86)\google\chrome\application\chrome.exe] => (Allow) C:\program files (x86)\google\chrome\application\chrome.exe
FirewallRules: [TCP Query User{195B8285-BCF0-4D13-9EBD-7887319FC856}C:\program files\adobe\adobe after effects cc 2017\support files\afterfx.exe] => (Allow) C:\program files\adobe\adobe after effects cc 2017\support files\afterfx.exe
FirewallRules: [UDP Query User{BDF17BDE-DD71-4860-BB71-6DDCEEE4960D}C:\program files\adobe\adobe after effects cc 2017\support files\afterfx.exe] => (Allow) C:\program files\adobe\adobe after effects cc 2017\support files\afterfx.exe
FirewallRules: [TCP Query User{84484BEA-0A5E-47B6-A368-B8155D3192C4}C:\program files\avid\avid media composer\avidmediacomposer.exe] => (Allow) C:\program files\avid\avid media composer\avidmediacomposer.exe
FirewallRules: [UDP Query User{A27DBAAC-18F9-4492-9CF2-376B7874EADE}C:\program files\avid\avid media composer\avidmediacomposer.exe] => (Allow) C:\program files\avid\avid media composer\avidmediacomposer.exe
FirewallRules: [{52D9026E-06B7-408C-9C8D-D7AF02E7E7C0}] => (Block) %SystemRoot%\system32\raserver.exe
FirewallRules: [{3C4F6AB9-5B34-4267-858E-1DA392BFAC90}] => (Block) %SystemRoot%\system32\raserver.exe
FirewallRules: [{EBCEF1CA-26D6-4F1F-B888-9CCFD5A246A4}] => (Allow) %ProgramFiles%\Avid\Avid Media Composer\AvidMediaComposer.exe
FirewallRules: [{2F0646A4-9999-4E02-8CF7-C90BF83B438D}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{3363E09E-6730-40A9-8523-5676FDB8FFBE}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{4921A2E3-C965-46FF-A8F7-1E5321505693}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
 
==================== Restore Points =========================
 
29-06-2017 10:12:19 Windows Update
03-07-2017 10:17:31 Windows Update
03-07-2017 17:03:06 Removed Episode 7.0
05-07-2017 10:56:39 Windows Update
05-07-2017 11:08:23 Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24215
05-07-2017 11:08:35 Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24212
05-07-2017 12:02:09 Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24215
05-07-2017 15:07:21 JRT Pre-Junkware Removal
05-07-2017 17:26:19 Windows Modules Installer
05-07-2017 19:37:28 JRT Pre-Junkware Removal
 
==================== Faulty Device Manager Devices =============
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (07/05/2017 07:47:08 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: notepad++.exe, version: 7.3.2.0, time stamp: 0x58a0deef
Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception code: 0xc000041d
Fault offset: 0x74704f69
Faulting process id: 0x209c
Faulting application start time: 0x01d2f5c904c65437
Faulting application path: C:\Program Files (x86)\Notepad++\notepad++.exe
Faulting module path: unknown
Report Id: 41210c00-61dc-11e7-8252-6c3be50dbb03
 
Error: (07/05/2017 07:40:14 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: regedit.exe, version: 6.1.7600.16385, time stamp: 0x4a5bc2cc
Faulting module name: RTSUltraMonHook.dll_unloaded, version: 0.0.0.0, time stamp: 0x54fb3459
Exception code: 0xc0000005
Fault offset: 0x000000005c03b00c
Faulting process id: 0x438
Faulting application start time: 0x01d2f5d07aac644e
Faulting application path: C:\Windows\regedit.exe
Faulting module path: RTSUltraMonHook.dll
Report Id: 4ac02247-61db-11e7-8252-6c3be50dbb03
 
Error: (07/05/2017 07:40:08 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: msseces.exe, version: 4.10.209.0, time stamp: 0x582a94bb
Faulting module name: RTSUltraMonHook.dll_unloaded, version: 0.0.0.0, time stamp: 0x54fb3459
Exception code: 0xc0000005
Fault offset: 0x000000005c03b00c
Faulting process id: 0x1e9c
Faulting application start time: 0x01d2f5c90212e9e7
Faulting application path: C:\Program Files\Microsoft Security Client\msseces.exe
Faulting module path: RTSUltraMonHook.dll
Report Id: 47214315-61db-11e7-8252-6c3be50dbb03
 
Error: (07/05/2017 07:40:04 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: Explorer.EXE, version: 6.1.7601.23537, time stamp: 0x57c44efe
Faulting module name: RTSUltraMonHook.dll_unloaded, version: 0.0.0.0, time stamp: 0x54fb3459
Exception code: 0xc0000005
Fault offset: 0x000000005c03b00c
Faulting process id: 0x1db4
Faulting application start time: 0x01d2f5c8ffbd0a46
Faulting application path: C:\Windows\Explorer.EXE
Faulting module path: RTSUltraMonHook.dll
Report Id: 44683360-61db-11e7-8252-6c3be50dbb03
 
Error: (07/05/2017 03:10:28 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: notepad.exe, version: 6.1.7601.18917, time stamp: 0x559ea6ff
Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception code: 0xc000041d
Fault offset: 0x74a94f69
Faulting process id: 0x311c
Faulting application start time: 0x01d2f5af026f30f4
Faulting application path: C:\Windows\SysWOW64\notepad.exe
Faulting module path: unknown
Report Id: 9abda2c7-61b5-11e7-a8c7-6c3be50dbb03
 
Error: (07/05/2017 03:09:50 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: notepad++.exe, version: 7.3.2.0, time stamp: 0x58a0deef
Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception code: 0xc000041d
Fault offset: 0x74a94f69
Faulting process id: 0x2bd4
Faulting application start time: 0x01d2f5aa482d6cff
Faulting application path: C:\Program Files (x86)\Notepad++\notepad++.exe
Faulting module path: unknown
Report Id: 847cbf0d-61b5-11e7-a8c7-6c3be50dbb03
 
Error: (07/05/2017 03:09:44 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: msseces.exe, version: 4.10.209.0, time stamp: 0x582a94bb
Faulting module name: RTSUltraMonHook.dll_unloaded, version: 0.0.0.0, time stamp: 0x54fb3459
Exception code: 0xc0000005
Fault offset: 0x0000000050e1b00c
Faulting process id: 0x1ca8
Faulting application start time: 0x01d2f5a1106dbf2c
Faulting application path: C:\Program Files\Microsoft Security Client\msseces.exe
Faulting module path: RTSUltraMonHook.dll
Report Id: 80fa1ad4-61b5-11e7-a8c7-6c3be50dbb03
 
Error: (07/05/2017 03:09:38 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: Explorer.EXE, version: 6.1.7601.23537, time stamp: 0x57c44efe
Faulting module name: RTSUltraMonHook.dll_unloaded, version: 0.0.0.0, time stamp: 0x54fb3459
Exception code: 0xc0000005
Fault offset: 0x0000000050e1b00c
Faulting process id: 0xf34
Faulting application start time: 0x01d2f5a10fbf2d1e
Faulting application path: C:\Windows\Explorer.EXE
Faulting module path: RTSUltraMonHook.dll
Report Id: 7d51c59f-61b5-11e7-a8c7-6c3be50dbb03
 
Error: (07/05/2017 04:44:38 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "C:\Program Files\Common Files\Autodesk Shared\Revit Interoperability 2018\Rx\AdskFaroConverter.exe".
Dependent Assembly FARO.LS,processorArchitecture="amd64",publicKeyToken="1d23f5635ba800ab",type="Win32",version="1.1.504.2" could not be found.
Please use sxstrace.exe for detailed diagnosis.
 
Error: (07/04/2017 03:43:47 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "C:\Program Files\Common Files\Autodesk Shared\Revit Interoperability 2018\Rx\AdskFaroConverter.exe".
Dependent Assembly FARO.LS,processorArchitecture="amd64",publicKeyToken="1d23f5635ba800ab",type="Win32",version="1.1.504.2" could not be found.
Please use sxstrace.exe for detailed diagnosis.
 
 
System errors:
=============
Error: (07/05/2017 07:37:39 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The NVIDIA WMI Provider service terminated unexpectedly.  It has done this 1 time(s).
 
Error: (07/05/2017 04:00:35 PM) (Source: BROWSER) (EventID: 8032) (User: )
Description: The browser service has failed to retrieve the backup list too many times on transport \Device\NetBT_Tcpip_{AF626FD6-E522-47E2-83CE-48AD0E00D527}.
The backup browser is stopping.
 
Error: (07/05/2017 03:57:23 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the NVIDIA Display Driver Service service to connect.
 
Error: (07/05/2017 03:54:28 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Application Virtualization Client service terminated unexpectedly.  It has done this 1 time(s).
 
Error: (07/05/2017 03:54:25 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Wacom Professional Service service terminated unexpectedly.  It has done this 1 time(s).
 
Error: (07/05/2017 03:54:25 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Intel® Management and Security Application User Notification Service service terminated unexpectedly.  It has done this 1 time(s).
 
Error: (07/05/2017 03:54:25 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Windows Media Player Network Sharing Service service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 30000 milliseconds: Restart the service.
 
Error: (07/05/2017 03:54:25 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Client Virtualization Handler service terminated unexpectedly.  It has done this 1 time(s).
 
Error: (07/05/2017 03:54:24 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Avid Editor Broker service terminated unexpectedly.  It has done this 1 time(s).
 
Error: (07/05/2017 03:54:24 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The ZAM Controller Service service terminated unexpectedly.  It has done this 1 time(s).
 
 
CodeIntegrity:
===================================
  Date: 2017-05-11 13:52:44.866
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\l3codeca.acm because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-10-16 15:15:17.573
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\l3codeca.acm because the set of per-page image hashes could not be found on the system.
 
  Date: 2013-06-17 07:42:46.421
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\l3codeca.acm because the set of per-page image hashes could not be found on the system.
 
  Date: 2013-06-14 17:29:48.328
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\l3codeca.acm because the set of per-page image hashes could not be found on the system.
 
  Date: 2013-06-14 17:01:00.590
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\l3codeca.acm because the set of per-page image hashes could not be found on the system.
 
  Date: 2013-06-14 16:17:21.451
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\l3codeca.acm because the set of per-page image hashes could not be found on the system.
 
  Date: 2013-06-14 16:11:07.312
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\l3codeca.acm because the set of per-page image hashes could not be found on the system.
 
  Date: 2013-06-14 15:24:34.421
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\l3codeca.acm because the set of per-page image hashes could not be found on the system.
 
  Date: 2013-06-14 15:00:47.719
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\l3codeca.acm because the set of per-page image hashes could not be found on the system.
 
 
==================== Memory info =========================== 
 
Processor: Intel® Xeon® CPU E5-1650 0 @ 3.20GHz
Percentage of memory in use: 27%
Total physical RAM: 24499.58 MB
Available physical RAM: 17796.63 MB
Total Virtual: 48997.34 MB
Available Virtual: 40521.15 MB
 
==================== Drives ================================
 
Drive c: (OS) (Fixed) (Total:465.66 GB) (Free:124.19 GB) NTFS
Drive d: (MONOPRICE10594) (CDROM) (Total:0.02 GB) (Free:0 GB) CDFS
Drive z: (Development_Media3) (Network) (Total:1600 GB) (Free:0 GB) AVIDFOS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (Size: 465.8 GB) (Disk ID: B068F196)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=465.7 GB) - (Type=07 NTFS)
 
==================== End of Addition.txt ============================


#7 rm540

rm540
  • Topic Starter

  • Members
  • 13 posts
  • OFFLINE
  •  
  • Local time:06:14 PM

Posted 05 July 2017 - 06:55 PM

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 05-07-2017
Ran by editor (administrator) on AVID4 (05-07-2017 19:49:30)
Running from C:\Users\editor\Downloads
Loaded Profiles: editor & Administrator (Available Profiles: user & editor & Default & IUSR_Servs & Administrator)
Platform: Windows 7 Professional Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvscpapisvr.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe
(Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
(AJA Video Systems, Inc.) C:\Program Files\AJA\windows\Applications\ajadaemon.exe
(Avid Technology, Inc.) C:\Program Files\Avid\Editor Transcode\TranscodeService\AvidEditorDbEngine.exe
(Avid Technology, Inc.) C:\Program Files\Avid\Editor Transcode\TranscodeService\AvidEditorDbEngine.exe
(Avid Technology, Inc.) C:\Program Files\Avid\Editor Transcode\TranscodeService\rnc-central\AvidEditorTranscodeStatus.exe
(Avid Technology, Inc.) C:\Program Files\Avid\Editor Transcode\TranscodeService\rnc-central\AvidEditorTranscodeStatus.exe
(Avid) C:\Program Files\Avid\ISIS Client\Utilities\Benchmark Utility\BenchmarkAgent.exe
(Avid) C:\Windows\System32\AvidFos_Service.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome Remote Desktop\59.0.3071.47\remoting_host.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome Remote Desktop\59.0.3071.47\remoting_host.exe
(Intel Corporation) C:\Windows\System32\IPROSetMonitor.exe
(PACE Anti-Piracy, Inc.) C:\Program Files (x86)\Common Files\PACE\Services\LicenseServices\LDSvc.exe
(PDF Complete Inc) C:\Program Files (x86)\PDF Complete\pdfsvc.exe
(Samsung Electronics Co., Ltd.) C:\Windows\System32\RAPID\SamsungRapidSvc.exe
(SafeNet, Inc.) C:\Program Files (x86)\Common Files\SafeNet Sentinel\Sentinel Keys Server\sntlkeyssrvr.exe
(SafeNet, Inc) C:\Program Files (x86)\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe
(SafeNet, Inc.) C:\Program Files (x86)\Common Files\SafeNet Sentinel\Sentinel Security Runtime\sntlsrtsrvr.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(Copyright 2017.) C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe
(Avid Technology, Inc.) C:\Program Files\Avid\Editor Transcode\TranscodeService\AvidEditorMSE.exe
(Avid Technology, Inc.) C:\Program Files\Avid\Editor Transcode\TranscodeService\AvidEditorMSE.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
(Sysinternals - www.sysinternals.com) C:\Users\editor\Downloads\procexp.exe
(Avid Technology, Inc.) C:\Program Files\Avid\Avid Media Composer\AvidBackgroundServicesManager.exe
(Don HO don.h@free.fr) C:\Program Files (x86)\Notepad++\notepad++.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler64.exe
(Sysinternals - www.sysinternals.com) C:\Users\editor\AppData\Local\Temp\PROCEXP64.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
(Microsoft Corporation) C:\Windows\System32\UI0Detect.exe
() C:\Users\editor\Desktop\AdwCleaner.exe
(Malwarebytes) C:\Users\editor\Downloads\JRT.exe
(Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
(Microsoft Corporation) C:\Windows\System32\wisptis.exe
(Microsoft Corporation) C:\Windows\System32\wisptis.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Wacom\WTabletServicePro.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Wacom\Wacom_TabletUser.exe
(Wacom Technology) C:\Program Files\Tablet\Wacom\WacomHost.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Wacom\Wacom_TouchUser.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Wacom\32\WacomDesktopCenter.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Microsoft Corporation) C:\Windows\regedit.exe
(Microsoft Corporation) C:\Windows\System32\taskmgr.exe
(Microsoft Corporation) C:\Windows\SysWOW64\WerFault.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Farbar) C:\Users\editor\Downloads\FRST64 (1).exe
 
==================== Registry (Whitelisted) ====================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [14062848 2015-07-03] (Realtek Semiconductor)
HKLM\...\Run: [HPSYSDRV] => C:\Program Files (x86)\Hewlett-Packard\HP Odometer\HPSYSDRV.EXE
HKLM\...\Run: [IntelliType Pro] => c:\Program Files\Microsoft Device Center\itype.exe [1464928 2012-06-26] (Microsoft Corporation)
HKLM\...\Run: [IntelliPoint] => c:\Program Files\Microsoft Device Center\ipoint.exe [2004584 2012-06-26] (Microsoft Corporation)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [508128 2016-07-01] (Adobe Systems Incorporated)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1353680 2016-11-14] (Microsoft Corporation)
HKLM\...\Run: [nwiz] => C:\Program Files\NVIDIA Corporation\nview\nwiz.exe [2098232 2016-08-25] ()
HKLM\...\Run: [Malwarebytes TrayApp] => C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe [3146704 2017-05-09] (Malwarebytes)
HKLM\...\Run: [SamsungRapidApp] => C:\Program Files (x86)\Samsung\RAPID\CacheFilter\SamsungRapidApp.exe [123800 2016-11-18] (Samsung Electronics Co., Ltd.)
HKLM\...\Run: [ZAM] => C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe [15546512 2017-06-19] (Copyright 2017.)
HKLM-x32\...\Run: [IMSS] => C:\Program Files (x86)\Intel\Intel® Management Engine Components\IMSS\PIconStartup.exe [112408 2011-11-30] (Intel Corporation)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.)
HKLM-x32\...\Run: [Adobe Creative Cloud] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2406496 2017-06-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Acrotray.exe [1870928 2017-04-04] (Adobe Systems Inc.)
HKLM-x32\...\Run: [PDF Complete] => C:\Program Files (x86)\PDF Complete\pdfsty.exe [1193728 2017-02-15] (PDF Complete Inc)
HKLM-x32\...\Run: [Autodesk Desktop App] => C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AutodeskDesktopApp.exe [704424 2017-03-10] (Autodesk, Inc.)
HKU\S-1-5-19\...\Run: [Sidebar] => %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\S-1-5-20\...\Run: [Sidebar] => %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\S-1-5-21-3225783554-34173836-2973484787-1001\...\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-3225783554-34173836-2973484787-1001\...\Run: [Adobe Acrobat Synchronizer] => C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe [886352 2017-04-04] (Adobe Systems Incorporated)
HKU\S-1-5-21-3225783554-34173836-2973484787-1001\...\Run: [com.squirrel.slack.slack] => "C:\Users\editor\AppData\Local\slack\Update.exe" --processStart "slack.exe" --process-start-args "--startup"
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Aja Firmware Updater.lnk [2015-11-16]
ShortcutTarget: Aja Firmware Updater.lnk -> C:\Program Files\AJA\windows\Firmware\ajaflash.exe ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Avid Application Manager.lnk [2016-12-22]
ShortcutTarget: Avid Application Manager.lnk -> C:\Windows\Installer\{99E377DB-D2D0-44A5-8533-AA8BE1381644}\NewShortcut1_E1E0FF1FC1474601A40EFEF248F11D43.exe (Flexera Software LLC)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Avid Background Services Manager.lnk [2016-12-23]
ShortcutTarget: Avid Background Services Manager.lnk -> C:\Windows\Installer\{95EB1E9C-F759-4427-8EEE-F96C48541A06}\NewShortcut1_4CE83F107C544E87A6F35E0E551E78CA.exe (Flexera Software LLC)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ISIS Client Manager.lnk [2015-12-08]
ShortcutTarget: ISIS Client Manager.lnk -> C:\Program Files\Avid\ISIS Client\Client Manager\ISISClientManager.exe (Avid)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\UltraMon.lnk [2015-07-23]
ShortcutTarget: UltraMon.lnk -> C:\Windows\Installer\{D4E62D29-31A1-4938-8CB7-7D275C1AEAC6}\IcoUltraMon.ico ()
GroupPolicy: Restriction <==== ATTENTION
GroupPolicy\User: Restriction <==== ATTENTION
GroupPolicyScripts: Restriction <==== ATTENTION
GroupPolicyScripts\User: Restriction <==== ATTENTION
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Winsock: Catalog5 08 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL => No File 
Winsock: Catalog5-x64 08 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL => No File 
Winsock: Catalog5-x64 09 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL => No File 
Tcpip\Parameters: [DhcpNameServer] 8.8.8.8 8.8.4.4
Tcpip\..\Interfaces\{0C06085B-51F9-4B6A-8F35-4A6E4F6EB3FC}: [DhcpNameServer] 8.8.8.8 8.8.4.4
 
Internet Explorer:
==================
HKU\S-1-5-21-3225783554-34173836-2973484787-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.msn.com/HPCOM/19
HKU\S-1-5-21-3225783554-34173836-2973484787-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.msn.com/HPCOM/19
HKU\S-1-5-21-3225783554-34173836-2973484787-500\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.msn.com/HPCOM/19
HKU\S-1-5-21-3225783554-34173836-2973484787-500\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.msn.com/HPCOM/19
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-3225783554-34173836-2973484787-500 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=CMDTDF&pc=CMDTDF&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-3225783554-34173836-2973484787-500 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=CMDTDF&pc=CMDTDF&src=IE-SearchBox
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2017-07-05] (Microsoft Corporation)
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_131\bin\ssv.dll [2017-06-27] (Oracle Corporation)
BHO: Adobe Acrobat Create PDF Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\x64\AcroIEFavStub.dll [2016-12-23] (Adobe Systems Incorporated)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\URLREDIR.DLL [2017-07-05] (Microsoft Corporation)
BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL [2017-07-05] (Microsoft Corporation)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_131\bin\jp2ssv.dll [2017-06-27] (Oracle Corporation)
BHO: Adobe Acrobat Create PDF from Selection -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\x64\AcroIEFavStub.dll [2016-12-23] (Adobe Systems Incorporated)
BHO-x32: Adobe Acrobat Create PDF Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll [2016-12-23] (Adobe Systems Incorporated)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\root\Office16\URLREDIR.DLL [2017-07-05] (Microsoft Corporation)
BHO-x32: Adobe Acrobat Create PDF from Selection -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll [2016-12-23] (Adobe Systems Incorporated)
Toolbar: HKLM - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\x64\AcroIEFavStub.dll [2016-12-23] (Adobe Systems Incorporated)
Toolbar: HKLM-x32 - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\DC\AcroIEFavStub.dll [2016-12-23] (Adobe Systems Incorporated)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-07-05] (Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-07-05] (Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-07-05] (Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-07-05] (Microsoft Corporation)
 
FireFox:
========
FF DefaultProfile: p0snnc5x.default
FF ProfilePath: C:\Users\editor\AppData\Roaming\Mozilla\Firefox\Profiles\p0snnc5x.default [2017-07-05]
FF HKLM-x32\...\Firefox\Extensions: [ISAllmytube@iSkysoft.com] - C:\ProgramData\iSkysoft\iTube Studio\ISAllmytube@iSkysoft.com
FF Extension: (iSkysoft iTube Studio) - C:\ProgramData\iSkysoft\iTube Studio\ISAllmytube@iSkysoft.com [2015-11-24] [not signed]
FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension.15@web2pdf.adobedotcom] - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn
FF Extension: (Adobe Acrobat DC - Create PDF) - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn [2017-04-13]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_26_0_0_131.dll [2017-06-16] ()
FF Plugin: @java.com/DTPlugin,version=11.131.2 -> C:\Program Files\Java\jre1.8.0_131\bin\dtplugin\npDeployJava1.dll [2017-06-27] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.131.2 -> C:\Program Files\Java\jre1.8.0_131\bin\plugin2\npjp2.dll [2017-06-27] (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin: @wacom.com/wtPlugin,version=2.1.0.7 -> C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll [2014-03-25] (Wacom)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2017-06-04] (Adobe Systems)
FF Plugin: wacom.com/WacomTabletPlugin -> C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll [2014-03-25] (Wacom)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_26_0_0_131.dll [2017-06-16] ()
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2017-05-26] (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2016-08-25] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2016-08-25] (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-27] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-27] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin-x32: @wacom.com/wtPlugin,version=2.1.0.7 -> C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll [2014-03-25] (Wacom)
FF Plugin-x32: Adobe Acrobat -> C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2017-04-04] (Adobe Systems Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2013-05-11] (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2017-06-04] (Adobe Systems)
FF Plugin-x32: wacom.com/WacomTabletPlugin -> C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll [2014-03-25] (Wacom)
FF Plugin HKU\S-1-5-21-3225783554-34173836-2973484787-1001: @asperasoft.com/AsperaConnect -> C:\Users\editor\AppData\Local\Programs\Aspera\Aspera Connect\lib\3.6.1\npasperaweb_3.6.1.111228.dll [2015-09-11] (Aspera, Inc. )
FF Plugin HKU\S-1-5-21-3225783554-34173836-2973484787-1001: signiant.com/SigniantTransfer -> C:\Users\editor\AppData\Roaming\SigniantInc\SigniantTransfer\5.4.3.70626\npSigniantTransfer.dll [2015-05-08] (Signiant Inc.)
 
Chrome: 
=======
CHR DefaultProfile: Default
CHR HomePage: Default -> hxxp://www.google.com/
CHR Profile: C:\Users\editor\AppData\Local\Google\Chrome\User Data\Default [2017-07-05]
CHR Extension: (Google Slides) - C:\Users\editor\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-04-17]
CHR Extension: (Google Docs) - C:\Users\editor\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-04-17]
CHR Extension: (Google Drive) - C:\Users\editor\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-23]
CHR Extension: (YouTube) - C:\Users\editor\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-26]
CHR Extension: (uBlock Origin) - C:\Users\editor\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpalhdlnbpafiamejdnhcphjbkeiagm [2017-06-22]
CHR Extension: (Image Downloader) - C:\Users\editor\AppData\Local\Google\Chrome\User Data\Default\Extensions\cnpniohnfphhjihaiiggeabnkjhpaldj [2017-05-04]
CHR Extension: (Google Search) - C:\Users\editor\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-27]
CHR Extension: (Frame by Frame for YouTube™) - C:\Users\editor\AppData\Local\Google\Chrome\User Data\Default\Extensions\elkadbdicdciddfkdpmaolomehalghio [2017-06-28]
CHR Extension: (Google Sheets) - C:\Users\editor\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-04-17]
CHR Extension: (Chrome Remote Desktop) - C:\Users\editor\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbchcmhmhahfdphkhkmpfmihenigjmpp [2017-06-12]
CHR Extension: (Google Docs Offline) - C:\Users\editor\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-17]
CHR Extension: (WhatFont) - C:\Users\editor\AppData\Local\Google\Chrome\User Data\Default\Extensions\jabopobgcpjmedljpbcaablpmlmfcogm [2017-05-08]
CHR Extension: (Reddit Enhancement Suite) - C:\Users\editor\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbmfpngjjgdllneeigpgjifpgocmfgmb [2017-06-22]
CHR Extension: (Chrome Web Store Payments) - C:\Users\editor\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-03-13]
CHR Extension: (Mercury Reader) - C:\Users\editor\AppData\Local\Google\Chrome\User Data\Default\Extensions\oknpjjbmpnndlpmnhmekjpocelpnlfdi [2017-04-26]
CHR Extension: (Gmail) - C:\Users\editor\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-04-17]
CHR Extension: (Chrome Media Router) - C:\Users\editor\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-06-28]
CHR Profile: C:\Users\editor\AppData\Local\Google\Chrome\User Data\Guest Profile [2017-06-26]
CHR Profile: C:\Users\editor\AppData\Local\Google\Chrome\User Data\System Profile [2017-06-26]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
 
==================== Services (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S3 AdAppMgrSvc; C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AdAppMgrSvc.exe [1309176 2017-03-10] (Autodesk Inc.)
R2 AdobeUpdateService; C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [814688 2017-06-04] (Adobe Systems Incorporated)
R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2246256 2017-05-18] (Adobe Systems, Incorporated)
R2 AJA Service; C:\Program Files\AJA\windows\Applications\ajadaemon.exe [1649152 2015-11-05] (AJA Video Systems, Inc.) [File not signed]
S3 Avid DMF Service; C:\Program Files\Avid\Editor Transcode\Dynamic Media Files\DMFService.exe [661768 2016-09-01] (Avid Technology, Inc.)
R2 Avid Editor Broker; C:\Program Files\Avid\Editor Transcode\TranscodeService\AvidEditorMSE.exe [662280 2016-09-01] (Avid Technology, Inc.)
R2 Avid Editor Db Engine; C:\Program Files\Avid\Editor Transcode\TranscodeService\AvidEditorDbEngine.exe [661768 2016-09-01] (Avid Technology, Inc.)
S3 Avid Editor Transcode Service; C:\Program Files\Avid\Editor Transcode\TranscodeService\AvidEditorTranscode.exe [662280 2016-09-01] (Avid Technology, Inc.)
R2 Avid Editor Transcode Status; C:\Program Files\Avid\Editor Transcode\TranscodeService\rnc-central\AvidEditorTranscodeStatus.exe [297736 2016-09-01] (Avid Technology, Inc.)
R2 Avid ISIS Benchmark Agent; C:\Program Files\Avid\ISIS Client\Utilities\Benchmark Utility\BenchmarkAgent.exe [4160000 2015-11-13] (Avid) [File not signed]
R2 AvidFosFS; C:\Windows\system32\AvidFos_Service.exe [17554944 2015-11-13] (Avid) [File not signed]
R2 chromoting; C:\Program Files (x86)\Google\Chrome Remote Desktop\59.0.3071.47\remoting_host.exe [71512 2017-05-09] (Google Inc.)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [4411592 2017-06-23] (Microsoft Corporation)
S2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4470736 2017-05-09] (Malwarebytes)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [119864 2016-11-14] (Microsoft Corporation)
S3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [361816 2016-11-14] (Microsoft Corporation)
S2 NVWMI; C:\Windows\system32\nvwmi64.exe [2693448 2014-09-12] ()
R2 pdfcDispatcher; C:\Program Files (x86)\PDF Complete\pdfsvc.exe [1719552 2017-02-15] (PDF Complete Inc)
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [303360 2015-07-03] (Realtek Semiconductor)
R2 SamsungRapidSvc; C:\Windows\System32\RAPID\SamsungRapidSvc.exe [29080 2016-11-18] (Samsung Electronics Co., Ltd.)
R2 SentinelKeysServer; C:\Program Files (x86)\Common Files\SafeNet Sentinel\Sentinel Keys Server\sntlkeyssrvr.exe [376832 2013-01-09] (SafeNet, Inc.) [File not signed]
R2 SentinelProtectionServer; C:\Program Files (x86)\Common Files\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe [1259872 2013-01-09] (SafeNet, Inc)
R2 SentinelSecurityRuntime; C:\Program Files (x86)\Common Files\SafeNet Sentinel\Sentinel Security Runtime\sntlsrtsrvr.exe [293216 2013-01-09] (SafeNet, Inc.)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
R2 WTabletServicePro; C:\Program Files\Tablet\Wacom\WTabletServicePro.exe [675272 2017-05-31] (Wacom Technology, Corp.)
R2 ZAMSvc; C:\Program Files (x86)\Zemana AntiMalware\ZAM.exe [15546512 2017-06-19] (Copyright 2017.)
S4 TermService; %ProgramFiles%\RDP Wrapper\rdpwrap.dll [X]
 
===================== Drivers (Whitelisted) ======================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 AvidFos; C:\Windows\System32\Drivers\AvidFos.sys [755944 2015-11-13] (Avid)
R2 AvidFosLog; C:\Windows\System32\Drivers\AvidFosLog.sys [29416 2015-11-13] (Avid)
R2 AvidFosShell; C:\Windows\System32\Drivers\AvidFosShell.sys [17640 2015-11-13] (Avid)
R3 bomebus; C:\Windows\System32\DRIVERS\bomebus.sys [34376 2010-10-13] (Bome Software)
S3 bomemidi; C:\Windows\System32\drivers\bomemidi.sys [30792 2010-10-13] (Bome Software)
R2 fsdk-wrap; C:\Windows\System32\Drivers\fsdk-wrap.sys [417000 2015-11-13] (OSR Open Systems Resource, Inc.)
S3 hitmanpro37; C:\Windows\system32\drivers\hitmanpro37.sys [43664 2015-04-10] ()
R1 HWiNFO32; C:\Windows\system32\drivers\HWiNFO64A.SYS [27552 2017-04-04] (REALiX™)
R0 iaStorF; C:\Windows\System32\drivers\iaStorF.sys [24496 2012-03-15] (Intel Corporation)
R0 iaStorS; C:\Windows\System32\drivers\iaStorS.sys [639408 2012-03-31] (Intel Corporation)
S3 IFCoEMP; C:\Windows\system32\drivers\ifM60x64.sys [348944 2012-03-09] (Intel® Corporation)
S3 IFCoEVB; C:\Windows\system32\drivers\ifP60X64.sys [70928 2012-03-09] (Intel® Corporation)
S3 MBAMWebProtection; C:\Windows\system32\drivers\mwac.sys [84256 2017-05-19] (Malwarebytes)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [295000 2016-08-25] (Microsoft Corporation)
S3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [135928 2016-08-25] (Microsoft Corporation)
R3 NTV2_64; C:\Windows\System32\DRIVERS\ntv2_64.sys [160024 2015-11-05] (AJA Video Systems Inc.)
R0 PxHlpa64; C:\Windows\System32\Drivers\PxHlpa64.sys [56336 2012-06-22] (Corel Corporation)
R0 SamsungRapidDiskFltr; C:\Windows\System32\DRIVERS\SamsungRapidDiskFltr.sys [272792 2016-11-18] (Samsung Electronics Co., Ltd.)
R0 SamsungRapidFSFltr; C:\Windows\System32\DRIVERS\SamsungRapidFSFltr.sys [111512 2016-11-18] (Samsung Electronics Co., Ltd.)
R2 Sentinel64; C:\Windows\System32\Drivers\Sentinel64.sys [145448 2009-09-17] (SafeNet, Inc.)
S3 SIVDriver; C:\Windows\system32\Drivers\SIVX64.sys [171664 2016-07-14] (Ray Hinchliffe)
R3 SNTUSB64; C:\Windows\System32\DRIVERS\SNTUSB64.SYS [63568 2012-12-11] (SafeNet, Inc.)
R3 USA19H; C:\Windows\System32\DRIVERS\USA19Hx64.sys [740096 2007-10-30] (Keyspan)
R3 USA19HP; C:\Windows\System32\DRIVERS\USA19Hx64p.SYS [35840 2007-10-23] (Keyspan)
R3 WacHidRouterPro; C:\Windows\System32\DRIVERS\wachidrouter.sys [122512 2017-04-28] (Wacom Technology)
R3 WsAudio_Device; C:\Windows\System32\drivers\VirtualAudio.sys [31080 2013-09-03] (Wondershare)
R2 WskTrans; C:\Windows\System32\Drivers\WskTrans.sys [34024 2015-11-13] (Avid)
S3 Xena2_64; C:\Windows\System32\DRIVERS\Kona3_64.sys [308480 2012-09-10] (AJA Video Systems Inc.) [File not signed]
R1 ZAM; C:\Windows\System32\drivers\zam64.sys [203680 2017-07-03] (Zemana Ltd.)
R1 ZAM_Guard; C:\Windows\System32\drivers\zamguard64.sys [203680 2017-07-03] (Zemana Ltd.)
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2017-07-05 19:48 - 2017-07-05 19:48 - 02436608 _____ (Farbar) C:\Users\editor\Downloads\FRST64 (1).exe
2017-07-05 19:27 - 2017-07-05 19:27 - 04110280 _____ C:\Users\editor\Desktop\AdwCleaner.exe
2017-07-05 16:16 - 2017-07-05 16:17 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2017-07-05 15:33 - 2017-07-05 15:33 - 16563352 _____ (Malwarebytes Corp.) C:\Users\editor\Downloads\mbar-1.09.3.1001 (1).exe
2017-07-05 15:31 - 2017-07-05 15:31 - 00899584 _____ C:\Users\editor\Downloads\RGSA.exe
2017-07-05 15:31 - 2017-07-05 15:31 - 00001110 _____ C:\Users\editor\Downloads\SALog.txt
2017-07-05 15:28 - 2017-07-05 15:30 - 149632778 _____ C:\Users\editor\Downloads\windows6.1-kb3212646-x64_a94cf69326099fb121cdd7daf9dfc558f740afb8 (1).msu
2017-07-05 15:26 - 2017-07-05 15:27 - 91827447 _____ C:\Users\editor\Downloads\windows6.1-kb3212646-x86_1852348a302cd587278400e936e2daf0321dc05d.msu
2017-07-05 15:25 - 2017-07-05 15:26 - 149632778 _____ C:\Users\editor\Downloads\windows6.1-kb3212646-x64_a94cf69326099fb121cdd7daf9dfc558f740afb8.msu
2017-07-05 15:08 - 2017-07-05 19:38 - 00001879 _____ C:\Users\editor\Desktop\JRT.txt
2017-07-05 15:06 - 2017-07-05 15:07 - 01663672 _____ (Malwarebytes) C:\Users\editor\Downloads\JRT.exe
2017-07-05 15:00 - 2017-07-05 15:00 - 00000000 ____D C:\Users\editor\Downloads\backups
2017-07-05 14:54 - 2017-07-05 15:02 - 3029491653 _____ C:\Users\editor\Downloads\C0001.MP4
2017-07-05 14:50 - 2017-07-05 14:50 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsigned7f088c377563d7
2017-07-05 14:50 - 2017-07-05 14:50 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsignbbce91eac4515c3b
2017-07-05 14:12 - 2017-07-05 14:12 - 00688992 ____R (Swearware) C:\Users\editor\Downloads\dds.exe
2017-07-05 13:48 - 2017-07-05 13:48 - 00388608 _____ (Trend Micro Inc.) C:\Users\editor\Downloads\HijackThis.exe
2017-07-05 12:17 - 2017-07-05 12:17 - 00528106 _____ C:\Users\editor\Downloads\Silent Runners.vbs
2017-07-05 12:17 - 2017-07-05 12:17 - 00126884 _____ C:\Users\editor\Downloads\Startup Programs (AVID4) 2017-07-05 12.17.15.txt
2017-07-05 12:11 - 2017-07-05 12:11 - 00000000 ____D C:\Users\editor\AppData\LocalLow\Sun
2017-07-05 12:03 - 2017-07-05 12:03 - 01005568 _____ (Microsoft Corporation) C:\Users\editor\Downloads\dotNetFx45_Full_setup (2).exe
2017-07-05 12:01 - 2017-07-05 12:01 - 01005568 _____ (Microsoft Corporation) C:\Users\editor\Downloads\dotNetFx45_Full_setup (1).exe
2017-07-05 11:12 - 2017-07-05 11:12 - 00000000 ___HD C:\OneDriveTemp
2017-07-05 11:00 - 2017-07-05 11:00 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign81646452ea9fa4c8
2017-07-05 11:00 - 2017-07-05 11:00 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign7c83395fc1fd24fa
2017-07-05 10:56 - 2017-06-19 19:14 - 25731584 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2017-07-05 10:56 - 2017-06-19 19:10 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2017-07-05 10:56 - 2017-06-19 18:43 - 00615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2017-07-05 10:56 - 2017-06-19 18:21 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2017-07-05 10:56 - 2017-06-19 18:09 - 20270592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2017-07-05 10:56 - 2017-06-19 18:00 - 00476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2017-07-05 10:56 - 2017-06-19 17:50 - 15252480 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2017-07-05 10:56 - 2017-06-19 17:29 - 13664256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2017-07-05 10:56 - 2017-06-16 11:29 - 02319872 _____ (Microsoft Corporation) C:\Windows\system32\tquery.dll
2017-07-05 10:56 - 2017-06-16 11:29 - 02222080 _____ (Microsoft Corporation) C:\Windows\system32\mssrch.dll
2017-07-05 10:56 - 2017-06-16 11:29 - 00778240 _____ (Microsoft Corporation) C:\Windows\system32\mssvp.dll
2017-07-05 10:56 - 2017-06-16 11:29 - 00491520 _____ (Microsoft Corporation) C:\Windows\system32\mssph.dll
2017-07-05 10:56 - 2017-06-16 11:29 - 00288256 _____ (Microsoft Corporation) C:\Windows\system32\mssphtb.dll
2017-07-05 10:56 - 2017-06-16 11:29 - 00115200 _____ (Microsoft Corporation) C:\Windows\system32\mssitlb.dll
2017-07-05 10:56 - 2017-06-16 11:29 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\mssprxy.dll
2017-07-05 10:56 - 2017-06-16 11:29 - 00075264 _____ (Microsoft Corporation) C:\Windows\system32\msscntrs.dll
2017-07-05 10:56 - 2017-06-16 11:29 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\msshooks.dll
2017-07-05 10:56 - 2017-06-16 11:13 - 00591872 _____ (Microsoft Corporation) C:\Windows\system32\SearchIndexer.exe
2017-07-05 10:56 - 2017-06-16 11:12 - 00249856 _____ (Microsoft Corporation) C:\Windows\system32\SearchProtocolHost.exe
2017-07-05 10:56 - 2017-06-16 11:11 - 01549312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tquery.dll
2017-07-05 10:56 - 2017-06-16 11:11 - 01400320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssrch.dll
2017-07-05 10:56 - 2017-06-16 11:11 - 00666624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssvp.dll
2017-07-05 10:56 - 2017-06-16 11:11 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssph.dll
2017-07-05 10:56 - 2017-06-16 11:11 - 00197120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssphtb.dll
2017-07-05 10:56 - 2017-06-16 11:11 - 00113664 _____ (Microsoft Corporation) C:\Windows\system32\SearchFilterHost.exe
2017-07-05 10:56 - 2017-06-16 11:11 - 00104448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssitlb.dll
2017-07-05 10:56 - 2017-06-16 11:11 - 00059392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msscntrs.dll
2017-07-05 10:56 - 2017-06-16 11:11 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssprxy.dll
2017-07-05 10:56 - 2017-06-16 11:00 - 00427520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchIndexer.exe
2017-07-05 10:56 - 2017-06-16 11:00 - 00164352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchProtocolHost.exe
2017-07-05 10:56 - 2017-06-16 10:59 - 00086528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchFilterHost.exe
2017-07-05 10:56 - 2017-06-16 10:59 - 00009728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msshooks.dll
2017-07-05 10:56 - 2017-05-21 00:24 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2017-07-05 10:56 - 2017-05-21 00:06 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2017-07-05 10:56 - 2017-05-16 11:35 - 00986856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2017-07-05 10:56 - 2017-05-16 11:35 - 00265448 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys
2017-07-05 10:56 - 2017-05-16 11:30 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll
2017-07-03 18:45 - 2017-07-05 12:51 - 00002885 _____ C:\Users\editor\Downloads\FSS.txt
2017-07-03 18:45 - 2017-07-03 18:45 - 00899584 _____ (Farbar) C:\Users\editor\Downloads\FSS.exe
2017-07-03 18:41 - 2017-07-03 18:41 - 00852798 _____ C:\Users\editor\Downloads\SecurityCheck.exe
2017-07-03 18:34 - 2017-07-03 18:34 - 00458395 _____ C:\Users\editor\Downloads\WinObj.zip
2017-07-03 18:12 - 2017-07-05 19:49 - 01175783 _____ C:\Windows\ZAM.krnl.trace
2017-07-03 18:12 - 2017-07-05 19:48 - 01782062 _____ C:\Windows\ZAM_Guard.krnl.trace
2017-07-03 18:12 - 2017-07-03 18:12 - 00203680 _____ (Zemana Ltd.) C:\Windows\system32\Drivers\zamguard64.sys
2017-07-03 18:12 - 2017-07-03 18:12 - 00203680 _____ (Zemana Ltd.) C:\Windows\system32\Drivers\zam64.sys
2017-07-03 18:12 - 2017-07-03 18:12 - 00001191 _____ C:\Users\Public\Desktop\Zemana AntiMalware.lnk
2017-07-03 18:12 - 2017-07-03 18:12 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Zemana AntiMalware
2017-07-03 18:12 - 2017-07-03 18:12 - 00000000 ____D C:\Program Files (x86)\Zemana AntiMalware
2017-07-03 18:11 - 2017-07-03 18:11 - 06589840 _____ (Zemana Ltd. ) C:\Users\editor\Downloads\Zemana.AntiMalware.Setup.exe
2017-07-03 18:11 - 2017-07-03 18:11 - 00000000 ____D C:\Users\editor\AppData\Local\Zemana
2017-07-03 18:04 - 2017-07-03 18:11 - 00230692 _____ C:\TDSSKiller.3.1.0.12_03.07.2017_18.04.07_log.txt
2017-07-03 17:28 - 2017-07-03 17:28 - 00291606 _____ C:\Users\editor\Downloads\TCPView.zip
2017-06-29 18:18 - 2017-06-29 19:21 - 00000000 ____D C:\OMFI MediaFiles
2017-06-29 17:52 - 2017-06-29 17:52 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsignfcf0406f42433c16
2017-06-29 17:45 - 2017-06-29 17:45 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsigna2dc30cfb3e36c82
2017-06-29 10:11 - 2017-06-29 10:11 - 49284629 _____ C:\Users\editor\Downloads\windows6.1-kb4022722-x64_ee5b5fae02d1c48dbd94beaff4d3ee4fe3cd2ac2.msu
2017-06-28 18:32 - 2017-06-28 18:32 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsignd8c7a391d8bde7cf
2017-06-28 18:32 - 2017-06-28 18:32 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign82f4209082d28e87
2017-06-28 17:08 - 2017-06-28 17:08 - 00000000 ____D C:\Users\editor\Downloads\SMALLHD LUTS
2017-06-28 17:07 - 2017-06-28 17:07 - 02541738 _____ C:\Users\editor\Downloads\smallhd_movielooks.zip
2017-06-28 16:54 - 2017-06-28 16:54 - 00116348 _____ C:\Users\editor\Desktop\SUMMARY.txt
2017-06-28 14:10 - 2017-06-28 14:10 - 00013212 _____ C:\Users\editor\Documents\FCP Translation Results 2017-06-28 14-10.txt
2017-06-28 14:10 - 2017-06-28 14:10 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign4c8b9d2c26409d6c
2017-06-28 14:00 - 2017-06-28 14:00 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign2620624ac41a9c29
2017-06-28 13:55 - 2017-06-28 13:55 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign92351176f4a0c25d
2017-06-28 13:55 - 2017-06-28 13:55 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign1050c69c2f1e1551
2017-06-28 12:26 - 2017-06-28 12:26 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsignbd1562b69a2cbba1
2017-06-28 12:26 - 2017-06-28 12:26 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign56c4b069f8611556
2017-06-28 12:08 - 2017-06-28 12:08 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign59c736854248e7d5
2017-06-28 12:07 - 2017-06-28 12:07 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign873d7f0aa6448692
2017-06-28 12:07 - 2017-06-28 12:07 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign402db1a6a9d0239a
2017-06-28 12:06 - 2017-06-28 12:06 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign798b4bcae726990d
2017-06-28 11:46 - 2017-06-28 11:46 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsignaa6d4e8c808ab4aa
2017-06-28 11:46 - 2017-06-28 11:46 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsigna14579408789d71e
2017-06-28 02:22 - 2017-06-28 02:22 - 00001630 _____ C:\Users\editor\Documents\SCK.txt
2017-06-28 00:27 - 2017-06-28 00:27 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsignecaa014faa7033f9
2017-06-28 00:27 - 2017-06-28 00:27 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign1fb67cc458f9bb49
2017-06-27 23:29 - 2017-06-27 23:29 - 31048683 _____ C:\Users\editor\Downloads\tweaking.com_windows_repair_aio.zip
2017-06-27 23:28 - 2017-06-27 23:28 - 32713504 _____ (Tweaking.com) C:\Users\editor\Downloads\tweaking.com_windows_repair_aio_setup.exe
2017-06-27 22:58 - 2017-06-27 22:58 - 00000000 ____D C:\Users\editor\AppData\Local\ESET
2017-06-27 22:57 - 2017-06-27 22:57 - 06754944 _____ (ESET spol. s r.o.) C:\Users\editor\Downloads\esetonlinescanner_enu.exe
2017-06-27 22:50 - 2017-06-27 22:50 - 00090042 _____ C:\Users\editor\Downloads\MTB.txt
2017-06-27 22:48 - 2017-06-27 22:48 - 00892416 _____ (Farbar) C:\Users\editor\Downloads\MiniToolBox.exe
2017-06-27 22:26 - 2017-06-27 22:26 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign526aa6bb30139f35
2017-06-27 21:58 - 2017-06-27 21:58 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
2017-06-27 21:57 - 2017-06-27 21:57 - 41896256 _____ (Apple Inc.) C:\Users\editor\Downloads\QuickTimeInstaller (1).exe
2017-06-27 21:51 - 2017-06-27 21:51 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign9ee2c53123c7e984
2017-06-27 21:51 - 2017-06-27 21:51 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign57109ca7a64f7072
2017-06-27 20:56 - 2017-06-27 20:56 - 00000000 ____H C:\Users\editor\Documents\Default.rdp
2017-06-27 20:35 - 2017-06-27 20:55 - 00000000 ____D C:\Users\editor\AppData\Local\ElevatedDiagnostics
2017-06-27 20:26 - 2017-06-27 20:26 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsignbe1402676d78233f
2017-06-27 14:47 - 2017-06-27 14:47 - 01844025 _____ C:\Users\editor\Downloads\KP+student+Manslaughter+Fairhaven.pdf
2017-06-27 13:16 - 2017-06-28 11:41 - 07429392 _____ C:\Windows\system32\FNTCACHE.DAT
2017-06-27 13:09 - 2017-06-27 13:09 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2017-06-27 13:08 - 2017-06-27 13:08 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2017-06-27 13:08 - 2017-06-27 13:08 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2017-06-27 13:08 - 2017-05-03 11:34 - 00094952 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe
2017-06-27 13:08 - 2017-05-03 11:29 - 01206272 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2017-06-27 13:08 - 2017-05-03 09:05 - 01555968 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2017-06-27 13:08 - 2017-05-03 09:05 - 00620544 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2017-06-27 13:08 - 2017-05-03 09:05 - 00535552 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2017-06-27 13:08 - 2017-05-03 09:05 - 00325632 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2017-06-27 13:08 - 2017-05-03 09:05 - 00311296 _____ (Microsoft Corporation) C:\Windows\system32\centel.dll
2017-06-27 13:08 - 2017-05-03 09:05 - 00217088 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2017-06-27 13:08 - 2017-05-03 09:05 - 00127488 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2017-06-27 13:08 - 2017-03-22 22:06 - 01691136 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe
2017-06-27 13:08 - 2015-08-05 13:56 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\icaapi.dll
2017-06-27 13:08 - 2015-08-05 13:06 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
2017-06-27 13:07 - 2015-12-16 14:53 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\kbdgeoqw.dll
2017-06-27 13:07 - 2015-12-16 14:53 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDAZEL.DLL
2017-06-27 13:07 - 2015-12-16 14:53 - 00007168 _____ (Microsoft Corporation) C:\Windows\system32\KBDAZE.DLL
2017-06-27 13:07 - 2015-12-16 14:48 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDAZE.DLL
2017-06-27 13:07 - 2015-12-16 14:48 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kbdgeoqw.dll
2017-06-27 13:07 - 2015-12-16 14:48 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDAZEL.DLL
2017-06-27 10:25 - 2017-06-28 00:27 - 00188984 _____ C:\Users\editor\AppData\Local\GDIPFONTCACHEV1.DAT
2017-06-27 10:24 - 2017-06-27 10:25 - 00000000 ____D C:\c762d7dd37c4f912b273435ccac836f9
2017-06-27 10:24 - 2017-06-27 10:24 - 04385303 _____ C:\Users\editor\Desktop\FixDotNet20170627142421128.cab
2017-06-27 10:23 - 2017-06-27 10:23 - 00003280 _____ C:\Windows\System32\Tasks\{C028CBEA-D7B3-449B-816B-03FF97DFFDED}
2017-06-27 10:23 - 2017-06-27 10:23 - 00000000 ____D C:\Users\editor\AppData\Roaming\Sun
2017-06-27 10:23 - 2017-06-27 10:23 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2017-06-27 10:23 - 2017-06-27 10:22 - 00110144 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll
2017-06-27 10:22 - 2017-06-27 10:22 - 00000000 ____D C:\ProgramData\Oracle
2017-06-27 10:22 - 2017-06-27 10:22 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
2017-06-27 10:22 - 2017-06-27 10:22 - 00000000 ____D C:\Program Files\7-Zip
2017-06-26 23:43 - 2017-06-26 23:43 - 00000000 ____D C:\ProgramData\Sophos
2017-06-26 20:30 - 2017-06-26 20:30 - 04922400 _____ (AO Kaspersky Lab) C:\Users\editor\Downloads\tdsskiller (1).exe
2017-06-26 20:26 - 2017-07-05 14:13 - 00045530 _____ C:\Users\editor\Desktop\dds.txt
2017-06-26 20:26 - 2017-07-05 14:13 - 00008991 _____ C:\Users\editor\Desktop\attach.txt
2017-06-26 20:26 - 2017-06-26 20:26 - 00688992 ____R (Swearware) C:\Users\editor\Downloads\dds.scr
2017-06-26 20:04 - 2017-06-26 20:04 - 00063472 _____ C:\Users\editor\Downloads\Addition.txt
2017-06-26 20:03 - 2017-07-05 19:49 - 00031687 _____ C:\Users\editor\Downloads\FRST.txt
2017-06-26 20:03 - 2017-07-05 19:49 - 00000000 ____D C:\FRST
2017-06-26 20:02 - 2017-06-26 20:02 - 02441216 _____ (Farbar) C:\Users\editor\Downloads\FRST64.exe
2017-06-26 19:54 - 2017-06-26 19:54 - 00000000 ____D C:\Users\editor\Desktop\rkill
2017-06-26 11:57 - 2017-06-26 11:57 - 35489760 _____ (Adlice Software ) C:\Users\editor\Downloads\setup (1).exe
2017-06-26 11:15 - 2017-06-26 11:15 - 00000000 ____D C:\Windows\system32\RAPID
2017-06-26 11:15 - 2016-11-18 19:04 - 00272792 _____ (Samsung Electronics Co., Ltd.) C:\Windows\system32\Drivers\SamsungRapidDiskFltr.sys
2017-06-23 20:16 - 2017-06-23 20:57 - 00000000 ____D C:\Users\editor\Desktop\CLOSING ARGUMENT EXPORTS
2017-06-23 17:37 - 2017-06-23 17:37 - 00003142 _____ C:\Windows\System32\Tasks\Process Explorer-AVID4-editor
2017-06-23 17:05 - 2017-06-23 17:05 - 02724512 _____ (Sysinternals - www.sysinternals.com) C:\Users\editor\Downloads\procexp.exe
2017-06-23 16:43 - 2017-06-23 16:43 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign59df863cd635d885
2017-06-23 15:50 - 2017-06-23 15:50 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign8d8121701ba66570
2017-06-23 15:50 - 2017-06-23 15:50 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign52e3c77a20748e79
2017-06-23 15:48 - 2017-06-23 15:48 - 01514603 _____ C:\Users\editor\Downloads\FXConsoleInstaller_1.0.1_Win_2017.zip
2017-06-23 15:46 - 2017-06-23 15:46 - 00089844 _____ C:\Users\editor\Downloads\Comp2Clip2.zip
2017-06-23 15:44 - 2017-06-23 15:44 - 00001077 _____ C:\Users\Public\Desktop\Boris RED 5 (64 Bit).lnk
2017-06-23 15:44 - 2017-06-23 15:44 - 00000000 ____D C:\Users\Public\Documents\Lightworks
2017-06-23 15:44 - 2017-06-23 15:44 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Boris RED 5
2017-06-23 15:43 - 2017-06-23 15:43 - 240190485 _____ C:\Users\editor\Downloads\SFX-20170623T194015Z-001.zip
2017-06-23 15:42 - 2017-06-23 15:42 - 00000000 ____D C:\Users\editor\Downloads\boris
2017-06-23 15:35 - 2017-06-23 15:35 - 00001179 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Media Encoder CC 2017.lnk
2017-06-23 14:40 - 2017-06-23 14:40 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign9166cc43c6cb6144
2017-06-23 14:19 - 2017-06-23 14:19 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign46564856646d2f2f
2017-06-23 14:18 - 2017-06-23 14:18 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign1a94ce88808d4a7b
2017-06-23 13:50 - 2017-06-23 13:50 - 00000804 __RSH C:\Users\editor\ntuser.pol
2017-06-23 13:10 - 2017-07-05 11:44 - 00001430 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe After Effects CC 2017.lnk
2017-06-23 12:45 - 2017-06-23 12:45 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsignb8037e97948ee1a6
2017-06-23 12:45 - 2017-06-23 12:45 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign7804bb806808d832
2017-06-23 12:44 - 2017-06-23 12:44 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsigne08c37701e2a0ee4
2017-06-23 12:43 - 2017-06-23 12:43 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign580f3bea265f8649
2017-06-23 11:51 - 2017-06-26 11:59 - 00028272 _____ C:\Windows\system32\Drivers\TrueSight.sys
2017-06-23 11:51 - 2017-06-26 11:58 - 00000897 _____ C:\Users\Public\Desktop\RogueKiller.lnk
2017-06-23 11:51 - 2017-06-26 11:58 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RogueKiller
2017-06-23 11:51 - 2017-06-26 11:58 - 00000000 ____D C:\Program Files\RogueKiller
2017-06-23 11:51 - 2017-06-23 12:32 - 00000000 ____D C:\ProgramData\RogueKiller
2017-06-23 11:48 - 2017-06-23 11:49 - 35438416 _____ (Adlice Software ) C:\Users\editor\Downloads\RogueKiller_setup_ref3.exe
2017-06-23 11:29 - 2017-07-05 18:51 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2017-06-23 11:28 - 2017-07-05 18:51 - 00000000 ____D C:\Users\editor\Desktop\mbar
2017-06-23 11:27 - 2017-06-23 11:28 - 16563352 _____ (Malwarebytes Corp.) C:\Users\editor\Downloads\mbar-1.09.3.1001.exe
2017-06-22 21:59 - 2017-06-22 21:59 - 00000000 ____D C:\TDSSKiller_Quarantine
2017-06-22 21:55 - 2016-07-14 03:14 - 00171664 _____ (Ray Hinchliffe) C:\Windows\system32\Drivers\SIVX64.sys
2017-06-22 21:49 - 2017-06-10 13:36 - 00000000 ____D C:\Users\editor\Desktop\integrity_verification
2017-06-22 21:49 - 2017-06-10 13:08 - 00000000 ____D C:\Users\editor\Desktop\tron
2017-06-22 21:41 - 2017-06-22 21:48 - 659787891 _____ (Igor Pavlov) C:\Users\editor\Desktop\Tron v10.1.0 (2017-06-10).exe
2017-06-22 20:12 - 2017-06-22 20:12 - 34790450 _____ C:\Users\editor\Downloads\windows6.1-kb4012212-x64_2decefaa02e2058dcd965702509a992d8c4e92b3.msu
2017-06-22 20:00 - 2017-06-22 20:00 - 15049603 _____ C:\Users\editor\Downloads\hou-16.0.504.rar
2017-06-22 19:56 - 2017-06-22 19:57 - 99926979 _____ C:\Users\editor\Downloads\GenArts.Sapphire.AE.v9.0.2.CE (1).rar
2017-06-22 19:56 - 2017-06-22 19:57 - 116407801 _____ C:\Users\editor\Downloads\Boris.RED.v5.6.0.CE.7z.002
2017-06-22 19:55 - 2017-06-22 19:56 - 157286400 _____ C:\Users\editor\Downloads\Boris.RED.v5.6.0.CE.7z.001
2017-06-22 19:45 - 2017-06-22 19:52 - 734003200 _____ C:\Users\editor\Downloads\19672582-vh-particular-presets-magic-pack-ii.part1.rar
2017-06-22 19:44 - 2017-06-22 19:46 - 17827814 _____ C:\Users\editor\Downloads\Rowbyte.Plexus.v3.1.0.CE.rar
2017-06-22 19:32 - 2017-06-22 19:32 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsigne31135abea56a536
2017-06-22 19:32 - 2017-06-22 19:32 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign2437faf4446c147c
2017-06-22 16:51 - 2017-06-22 16:51 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign096855595bc7753f
2017-06-22 16:50 - 2017-06-22 16:50 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign2a8de0a70e9934da
2017-06-22 14:31 - 2017-06-22 14:31 - 00000000 ____D C:\Program Files\Red Giant
2017-06-22 14:31 - 2017-05-10 19:56 - 15353856 _____ (Red Giant LLC) C:\Windows\system32\UniChooser.dll
2017-06-22 14:31 - 2017-05-10 19:56 - 13179904 _____ (Red Giant Software) C:\Windows\system32\Gpu_Shader_Engine_x64.dll
2017-06-22 14:31 - 2017-05-10 19:56 - 05528064 _____ (Noesis Technologies) C:\Windows\system32\Noesis.dll
2017-06-22 14:07 - 2017-06-22 14:10 - 269211572 _____ C:\Users\editor\Downloads\Videocopilot - Element 3D v2.2.2 Build 2155 WIN RePack by pooshock.zip
2017-06-22 14:04 - 2017-06-22 14:05 - 82412411 _____ C:\Users\editor\Downloads\RedGiant.Universe.v2.1.CE.part5.rar
2017-06-22 14:04 - 2017-06-22 14:05 - 199229440 _____ C:\Users\editor\Downloads\RedGiant.Universe.v2.1.CE.part4.rar
2017-06-22 14:04 - 2017-06-22 14:05 - 199229440 _____ C:\Users\editor\Downloads\RedGiant.Universe.v2.1.CE.part3.rar
2017-06-22 14:03 - 2017-06-22 14:05 - 199229440 _____ C:\Users\editor\Downloads\RedGiant.Universe.v2.1.CE.part2.rar
2017-06-22 14:02 - 2017-06-08 21:15 - 00000000 ____D C:\Users\editor\Downloads\RedGiant.Universe.v2.1.CE
2017-06-22 13:57 - 2017-06-22 14:10 - 63339722 _____ C:\Users\editor\Downloads\sd096w.rar
2017-06-22 13:52 - 2017-06-22 13:52 - 00190366 _____ C:\Users\editor\Downloads\Transformer 1_monter.zip
2017-06-22 13:51 - 2017-06-22 13:51 - 00397652 _____ C:\Users\editor\Downloads\gridguide_v1_0_0_monter.zip
2017-06-22 13:50 - 2017-06-22 13:52 - 199229440 _____ C:\Users\editor\Downloads\RedGiant.Universe.v2.1.CE.part1.rar
2017-06-22 13:48 - 2017-06-22 13:49 - 03310107 _____ C:\Users\editor\Downloads\AfterCodecs.v1.1.1Win.zip
2017-06-22 13:48 - 2017-06-22 13:48 - 02436880 _____ C:\Users\editor\Downloads\smartselector_v1.0_monter.zip
2017-06-22 13:47 - 2017-06-22 16:34 - 204847694 _____ C:\Users\editor\Downloads\AE2017.zip
2017-06-22 13:47 - 2017-06-22 13:47 - 50980774 _____ C:\Users\editor\Downloads\18280881-3d-ph0t0-maker-the-script.rar
2017-06-22 13:46 - 2017-06-22 13:46 - 00360899 _____ C:\Users\editor\Downloads\Tool Launcher 1.3.0.rar
2017-06-22 13:45 - 2017-06-22 13:45 - 02400562 _____ C:\Users\editor\Downloads\Font_Previewer_v1.0_Win.ZIP
2017-06-22 13:45 - 2017-06-22 13:45 - 00993950 _____ C:\Users\editor\Downloads\autocircularmotion_v1.0_monter.zip
2017-06-22 13:44 - 2017-06-22 13:44 - 00571880 _____ C:\Users\editor\Downloads\LongShadow_v1.13_Win.zip
2017-06-22 13:44 - 2017-06-22 13:44 - 00107936 _____ C:\Users\editor\Downloads\Wind_v1.00.rar
2017-06-22 13:43 - 2017-06-22 13:43 - 00170224 _____ C:\Users\editor\Downloads\monkeybars_v1.04_monter.zip
2017-06-22 12:07 - 2017-06-28 00:27 - 00001320 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Premiere Pro CC 2017.lnk
2017-06-22 12:03 - 2017-06-22 12:03 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign3118c32baeebc941
2017-06-22 12:02 - 2017-06-22 12:02 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign698bbaaed98fc862
2017-06-20 16:28 - 2017-07-03 10:26 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2017-06-19 17:39 - 2017-06-19 17:39 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign7fff0c43db9851b3
2017-06-19 17:38 - 2017-06-19 17:38 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign39bf399261bc6fd2
2017-06-19 17:37 - 2017-06-19 17:37 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign7acb5c62f5b628d3
2017-06-19 17:26 - 2017-06-19 17:26 - 00002880 _____ C:\Users\editor\Documents\FCP Translation Results 2017-06-19 17-26.txt
2017-06-19 17:26 - 2017-06-19 17:26 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign42389bfcb5552074
2017-06-19 17:26 - 2017-06-19 17:26 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign1e86a872dea4c587
2017-06-19 16:32 - 2017-06-19 17:23 - 00000000 ____D C:\Users\editor\Desktop\aaf_sza
2017-06-16 21:21 - 2017-06-16 21:24 - 355934860 _____ C:\Users\editor\Downloads\Oxygen - Closing Arguments EXT.zip
2017-06-16 20:07 - 2017-06-16 20:07 - 08455478 _____ C:\Users\editor\Downloads\drive-download-20170617T000720Z-001.zip
2017-06-16 17:31 - 2017-06-16 17:31 - 00140129 _____ C:\Users\editor\Desktop\Skylar Nemetz Trial Prosecution Closing Argument 02-23-16
2017-06-16 17:31 - 2017-06-16 17:31 - 00056793 _____ C:\Users\editor\Desktop\Skylar Nemetz Trial Defense Closing Argument 02-23-16
2017-06-16 17:30 - 2017-06-16 17:30 - 00091678 _____ C:\Users\editor\Downloads\[DownSub.com] Skylar Nemetz Trial Defense Closing Argument 02-23-16.srt
2017-06-16 17:00 - 2017-06-16 17:31 - 00140129 _____ C:\Users\editor\Downloads\[DownSub.com] Skylar Nemetz Trial Prosecution Closing Argument 02-23-16.srt
2017-06-16 16:29 - 2017-06-16 16:30 - 157128578 _____ C:\Users\editor\Downloads\Skylar Nemetz Trial Defense Closing Argument.mov
2017-06-16 16:18 - 2017-06-16 16:20 - 365155208 _____ C:\Users\editor\Downloads\Skylar Nemetz Trial Prosecution Closing Argument.mov
2017-06-16 14:54 - 2017-06-16 14:54 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign74b22a34557fd6a6
2017-06-16 14:52 - 2017-06-16 14:52 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsigncad245026e30a186
2017-06-16 14:52 - 2017-06-16 14:52 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign5c962276e3fa74ab
2017-06-15 14:30 - 2017-06-15 14:55 - 00044446 _____ C:\Users\editor\Downloads\[DownSub.com] COLLEEN MCKERNAN TRIAL - CLOSING ARGUMENTS - PART 2.srt
2017-06-15 14:30 - 2017-06-15 14:55 - 00027282 _____ C:\Users\editor\Downloads\[DownSub.com] COLLEEN MCKERNAN TRIAL - CLOSING ARGUMENTS - PART 1.srt
2017-06-14 19:47 - 2017-06-14 19:47 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign4f1768933266bbd0
2017-06-14 19:32 - 2017-06-14 19:32 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsigncf9ed271a4570a7f
2017-06-14 19:32 - 2017-06-14 19:32 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign3a81c8a21e40e00c
2017-06-13 20:57 - 2017-06-02 04:10 - 00733696 _____ (Microsoft Corporation) C:\Windows\HelpPane.exe
2017-06-13 20:57 - 2017-05-21 00:28 - 00154856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2017-06-13 20:57 - 2017-05-21 00:28 - 00095464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2017-06-13 20:57 - 2017-05-21 00:24 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2017-06-13 20:57 - 2017-05-21 00:24 - 01212928 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2017-06-13 20:57 - 2017-05-21 00:24 - 00730624 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2017-06-13 20:57 - 2017-05-21 00:24 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2017-06-13 20:57 - 2017-05-21 00:24 - 00463872 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2017-06-13 20:57 - 2017-05-21 00:24 - 00345600 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2017-06-13 20:57 - 2017-05-21 00:24 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2017-06-13 20:57 - 2017-05-21 00:24 - 00312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2017-06-13 20:57 - 2017-05-21 00:24 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2017-06-13 20:57 - 2017-05-21 00:24 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll
2017-06-13 20:57 - 2017-05-21 00:24 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2017-06-13 20:57 - 2017-05-21 00:24 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2017-06-13 20:57 - 2017-05-21 00:24 - 00123904 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll
2017-06-13 20:57 - 2017-05-21 00:24 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2017-06-13 20:57 - 2017-05-21 00:24 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2017-06-13 20:57 - 2017-05-21 00:24 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2017-06-13 20:57 - 2017-05-21 00:24 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2017-06-13 20:57 - 2017-05-21 00:24 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2017-06-13 20:57 - 2017-05-21 00:24 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2017-06-13 20:57 - 2017-05-21 00:06 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2017-06-13 20:57 - 2017-05-21 00:06 - 00666112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2017-06-13 20:57 - 2017-05-21 00:06 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2017-06-13 20:57 - 2017-05-21 00:06 - 00342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
2017-06-13 20:57 - 2017-05-21 00:06 - 00261120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2017-06-13 20:57 - 2017-05-21 00:06 - 00254464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2017-06-13 20:57 - 2017-05-21 00:06 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2017-06-13 20:57 - 2017-05-21 00:06 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2017-06-13 20:57 - 2017-05-21 00:06 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2017-06-13 20:57 - 2017-05-21 00:06 - 00141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll
2017-06-13 20:57 - 2017-05-21 00:06 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2017-06-13 20:57 - 2017-05-21 00:06 - 00082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcrypt.dll
2017-06-13 20:57 - 2017-05-21 00:06 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2017-06-13 20:57 - 2017-05-21 00:06 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2017-06-13 20:57 - 2017-05-21 00:06 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2017-06-13 20:57 - 2017-05-21 00:06 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2017-06-13 20:57 - 2017-05-20 23:55 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2017-06-13 20:57 - 2017-05-20 23:48 - 00291328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2017-06-13 20:57 - 2017-05-20 23:48 - 00159744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2017-06-13 20:57 - 2017-05-20 23:48 - 00129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2017-06-13 20:57 - 2017-05-20 23:47 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2017-06-13 20:57 - 2017-05-20 23:46 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2017-06-13 20:57 - 2017-05-20 23:42 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
2017-06-13 20:57 - 2017-05-16 14:19 - 00394448 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2017-06-13 20:57 - 2017-05-16 13:35 - 00346320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2017-06-13 20:57 - 2017-05-14 16:46 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2017-06-13 20:57 - 2017-05-14 16:28 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2017-06-13 20:57 - 2017-05-14 16:27 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2017-06-13 20:57 - 2017-05-14 16:27 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2017-06-13 20:57 - 2017-05-14 16:27 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2017-06-13 20:57 - 2017-05-14 16:26 - 00576512 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2017-06-13 20:57 - 2017-05-14 16:24 - 02899456 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2017-06-13 20:57 - 2017-05-14 16:17 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2017-06-13 20:57 - 2017-05-14 16:16 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2017-06-13 20:57 - 2017-05-14 16:10 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2017-06-13 20:57 - 2017-05-14 16:10 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2017-06-13 20:57 - 2017-05-14 16:10 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2017-06-13 20:57 - 2017-05-14 16:10 - 00116224 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2017-06-13 20:57 - 2017-05-14 16:01 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2017-06-13 20:57 - 2017-05-14 15:57 - 00489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2017-06-13 20:57 - 2017-05-14 15:55 - 05975040 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2017-06-13 20:57 - 2017-05-14 15:48 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2017-06-13 20:57 - 2017-05-14 15:47 - 00087552 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2017-06-13 20:57 - 2017-05-14 15:46 - 00107520 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2017-06-13 20:57 - 2017-05-14 15:42 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2017-06-13 20:57 - 2017-05-14 15:41 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2017-06-13 20:57 - 2017-05-14 15:38 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2017-06-13 20:57 - 2017-05-14 15:36 - 00152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2017-06-13 20:57 - 2017-05-14 15:23 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2017-06-13 20:57 - 2017-05-14 15:23 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2017-06-13 20:57 - 2017-05-14 15:22 - 00499200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2017-06-13 20:57 - 2017-05-14 15:22 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2017-06-13 20:57 - 2017-05-14 15:22 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2017-06-13 20:57 - 2017-05-14 15:21 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2017-06-13 20:57 - 2017-05-14 15:20 - 00725504 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2017-06-13 20:57 - 2017-05-14 15:19 - 00806912 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2017-06-13 20:57 - 2017-05-14 15:18 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2017-06-13 20:57 - 2017-05-14 15:17 - 02132992 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2017-06-13 20:57 - 2017-05-14 15:16 - 02290176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2017-06-13 20:57 - 2017-05-14 15:15 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2017-06-13 20:57 - 2017-05-14 15:14 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2017-06-13 20:57 - 2017-05-14 15:11 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2017-06-13 20:57 - 2017-05-14 15:10 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2017-06-13 20:57 - 2017-05-14 15:10 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2017-06-13 20:57 - 2017-05-14 15:02 - 00416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2017-06-13 20:57 - 2017-05-14 14:57 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2017-06-13 20:57 - 2017-05-14 14:57 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2017-06-13 20:57 - 2017-05-14 14:56 - 00091136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2017-06-13 20:57 - 2017-05-14 14:53 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2017-06-13 20:57 - 2017-05-14 14:52 - 03240960 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2017-06-13 20:57 - 2017-05-14 14:52 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2017-06-13 20:57 - 2017-05-14 14:50 - 00279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2017-06-13 20:57 - 2017-05-14 14:49 - 00130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2017-06-13 20:57 - 2017-05-14 14:44 - 04549120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2017-06-13 20:57 - 2017-05-14 14:42 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2017-06-13 20:57 - 2017-05-14 14:40 - 00693248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2017-06-13 20:57 - 2017-05-14 14:39 - 02057216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2017-06-13 20:57 - 2017-05-14 14:38 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2017-06-13 20:57 - 2017-05-14 14:37 - 01544704 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2017-06-13 20:57 - 2017-05-14 14:27 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2017-06-13 20:57 - 2017-05-14 14:15 - 02767872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2017-06-13 20:57 - 2017-05-14 14:11 - 01314816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2017-06-13 20:57 - 2017-05-14 14:11 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2017-06-13 20:57 - 2017-05-12 14:27 - 00631176 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2017-06-13 20:57 - 2017-05-12 14:26 - 05547752 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2017-06-13 20:57 - 2017-05-12 14:26 - 00706792 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2017-06-13 20:57 - 2017-05-12 14:26 - 00382696 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2017-06-13 20:57 - 2017-05-12 14:24 - 01732864 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00880640 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00806912 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00419840 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00405504 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00215552 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00059904 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00034816 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:22 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:07 - 04001000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2017-06-13 20:57 - 2017-05-12 14:07 - 03945704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2017-06-13 20:57 - 2017-05-12 14:07 - 00308456 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2017-06-13 20:57 - 2017-05-12 14:04 - 01314112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00644096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00629760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00313344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00275456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00004608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00003584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00003584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00003584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00003584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00003584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00003584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00003072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00003072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00003072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00003072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00003072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00003072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00003072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00003072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00003072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00003072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 14:03 - 00003072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 13:55 - 00148480 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2017-06-13 20:57 - 2017-05-12 13:54 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2017-06-13 20:57 - 2017-05-12 13:54 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2017-06-13 20:57 - 2017-05-12 13:52 - 03222528 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2017-06-13 20:57 - 2017-05-12 13:51 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2017-06-13 20:57 - 2017-05-12 13:50 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2017-06-13 20:57 - 2017-05-12 13:46 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2017-06-13 20:57 - 2017-05-12 13:43 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2017-06-13 20:57 - 2017-05-12 13:41 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2017-06-13 20:57 - 2017-05-12 13:41 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2017-06-13 20:57 - 2017-05-12 13:41 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2017-06-13 20:57 - 2017-05-12 13:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2017-06-13 20:57 - 2017-05-12 13:40 - 00006144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 13:40 - 00004608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 13:40 - 00003584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 13:40 - 00003072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2017-06-13 20:57 - 2017-05-12 12:25 - 01251328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2017-06-13 20:57 - 2017-05-12 11:58 - 01648128 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2017-06-13 20:57 - 2017-05-12 11:58 - 01180160 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2017-06-13 20:57 - 2017-05-10 11:33 - 00091368 _____ (Microsoft Corporation) C:\Windows\system32\MigAutoPlay.exe
2017-06-13 20:57 - 2017-05-10 11:29 - 14183936 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2017-06-13 20:57 - 2017-05-10 11:29 - 03165184 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2017-06-13 20:57 - 2017-05-10 11:29 - 01867776 _____ (Microsoft Corporation) C:\Windows\system32\ExplorerFrame.dll
2017-06-13 20:57 - 2017-05-10 11:29 - 00192512 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2017-06-13 20:57 - 2017-05-10 11:29 - 00098816 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2017-06-13 20:57 - 2017-05-10 11:28 - 00091136 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2017-06-13 20:57 - 2017-05-10 11:16 - 00091368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MigAutoPlay.exe
2017-06-13 20:57 - 2017-05-10 11:14 - 02651136 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2017-06-13 20:57 - 2017-05-10 11:13 - 00709120 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2017-06-13 20:57 - 2017-05-10 11:13 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2017-06-13 20:57 - 2017-05-10 11:13 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2017-06-13 20:57 - 2017-05-10 11:13 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2017-06-13 20:57 - 2017-05-10 11:13 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2017-06-13 20:57 - 2017-05-10 11:13 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
2017-06-13 20:57 - 2017-05-10 11:12 - 12880896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2017-06-13 20:57 - 2017-05-10 11:12 - 01499648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ExplorerFrame.dll
2017-06-13 20:57 - 2017-05-10 11:12 - 00174080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2017-06-13 20:57 - 2017-05-10 11:00 - 00573440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2017-06-13 20:57 - 2017-05-10 11:00 - 00093696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2017-06-13 20:57 - 2017-05-10 11:00 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2017-06-13 20:57 - 2017-05-10 11:00 - 00030208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2017-06-13 20:57 - 2017-05-10 10:52 - 00117248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys
2017-06-13 20:57 - 2017-05-09 11:30 - 00757248 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll
2017-06-13 20:57 - 2017-05-09 11:29 - 00970240 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll
2017-06-13 20:57 - 2017-05-09 11:15 - 00071680 _____ C:\Windows\system32\PrintBrmUi.exe
2017-06-13 20:57 - 2017-05-09 11:11 - 00497664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll
2017-06-13 20:57 - 2017-05-07 11:33 - 00094440 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mountmgr.sys
2017-06-13 20:57 - 2017-05-07 11:29 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\msmmsp.dll
2017-06-13 20:57 - 2017-04-27 18:50 - 03550208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_47.dll
2017-06-13 20:57 - 2017-04-12 09:05 - 04296704 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_47.dll
2017-06-13 20:57 - 2017-03-30 11:03 - 00046080 _____ (Microsoft Corporation) C:\Windows\system32\rundll32.exe
2017-06-13 20:57 - 2017-03-30 10:58 - 00045056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
2017-06-13 19:03 - 2017-06-13 19:03 - 14976971 _____ C:\Users\editor\Downloads\nablet_XAVC_XDCAM_AMA_Plugin_Win_4.0.3.1146.zip
2017-06-13 19:03 - 2017-06-13 19:03 - 00000000 ____D C:\Users\editor\Downloads\nablet_XAVC_XDCAM_AMA_Plugin_Win_4.0.3.1146
2017-06-13 16:36 - 2017-06-13 16:36 - 00000000 ____D C:\Users\editor\AppData\Local\RzStats
2017-06-13 16:34 - 2017-06-13 16:34 - 00214174 _____ C:\Users\editor\Downloads\WindowsFirewall.diagcab
2017-06-13 16:32 - 2017-06-13 19:12 - 00000000 ____D C:\Users\editor\AppData\Local\Razer
2017-06-13 16:31 - 2017-06-13 19:13 - 00000000 ____D C:\ProgramData\Razer
2017-06-13 16:31 - 2017-06-13 19:13 - 00000000 ____D C:\Program Files (x86)\Razer
2017-06-13 15:27 - 2017-06-13 15:27 - 152572041 _____ C:\Users\editor\Downloads\windows6.1-kb4012215-x64_a777b8c251dcd8378ecdafa81aefbe7f9009c72b.msu
2017-06-13 15:01 - 2017-06-13 15:04 - 22738504 _____ (Razer Inc.) C:\Users\editor\Downloads\Razer_Synapse_Framework_V2.20.15.1104.exe
2017-06-12 18:32 - 2017-06-12 18:32 - 668212825 _____ C:\Users\editor\Desktop\SZA STRINGOUT PART 2.Copy.01.mov
2017-06-12 15:45 - 2017-06-12 15:45 - 00476169 _____ C:\Users\editor\Downloads\PITH_Shoot_Checklist.xlsx
2017-06-12 14:27 - 2017-06-12 14:27 - 00000000 ____D C:\Users\editor\Downloads\GIFM_550_1-FILE_20170611192144
2017-06-11 21:31 - 2017-06-11 21:31 - 01933312 _____ C:\Users\editor\Downloads\061017_sza_GROUP (1).aaf
2017-06-11 21:31 - 2017-06-11 21:31 - 00160812 _____ C:\Users\editor\Downloads\GIFM_550_1-FILE_20170611192144.zip
2017-06-11 21:30 - 2017-06-11 21:30 - 01933312 _____ C:\Users\editor\Desktop\061017_sza_GROUP.aaf
2017-06-11 19:21 - 2017-06-11 21:32 - 02342912 _____ C:\Users\editor\Desktop\061017_sza_GROUP_MULTIGROUPED.aaf
2017-06-08 20:23 - 2017-06-08 20:51 - 561908852 _____ C:\Users\editor\Desktop\052617_PB_OPEN1_1.mov
2017-06-08 18:43 - 2017-06-08 18:43 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign8188b830f2e1781d
2017-06-08 18:43 - 2017-06-08 18:43 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign311dc0be15a4e8e5
2017-06-08 16:17 - 2017-06-08 16:40 - 127564968 _____ C:\Users\editor\Desktop\CHRISTINA LOVDAL GIL-TC.mov
2017-06-08 15:47 - 2017-06-08 16:09 - 111227757 _____ C:\Users\editor\Desktop\CHRISTINA LOVDAL GIL.mov
2017-06-08 12:50 - 2017-06-08 12:50 - 00001200 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Creative Cloud.lnk
2017-06-08 12:50 - 2017-06-08 12:50 - 00001188 _____ C:\Users\Public\Desktop\Adobe Creative Cloud.lnk
2017-06-08 11:05 - 2017-06-08 11:26 - 480804911 _____ C:\Users\editor\Desktop\Javier Gil Buendia on 2017-05-04 at 22.09.mov
2017-06-08 11:00 - 2017-06-08 11:00 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsigna7c314ae638759b9
2017-06-08 11:00 - 2017-06-08 11:00 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign2fb759c9a750f030
2017-06-07 17:29 - 2017-05-18 13:30 - 130804461 _____ C:\Users\editor\Downloads\Amber Batura on 2017-05-18 at 15.09.mov
2017-06-07 17:25 - 2017-06-07 17:26 - 445301618 _____ C:\Users\editor\Downloads\drive-download-20170607T212436Z-001.zip
2017-06-07 17:25 - 2017-06-07 17:25 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsigndb08791fe2be7fb7
2017-06-07 17:25 - 2017-06-07 17:25 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign5120056e2d3f6cf7
2017-06-06 19:38 - 2017-06-06 19:38 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsignb8bd1562439c1688
2017-06-06 19:38 - 2017-06-06 19:38 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign70bab4a592232106
2017-06-06 13:14 - 2017-06-06 13:14 - 02244229 _____ C:\Users\editor\Downloads\041117_mech_additional_info2.pdf
2017-06-06 13:12 - 2017-03-22 18:32 - 10141251 _____ C:\Users\editor\Desktop\032217_MECHATRONICAcasting_format.pdf
2017-06-06 12:51 - 2017-06-06 12:51 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wacom Tablet
2017-06-06 12:50 - 2017-06-06 12:50 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_wachidrouter_01011.Wdf
2017-06-06 12:50 - 2017-04-28 19:21 - 01804688 _____ (Microsoft Corporation) C:\Windows\system32\wdfcoinstaller01011.dll
2017-06-06 12:44 - 2017-06-06 12:44 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign9d8c4ca872eb95de
2017-06-06 12:44 - 2017-06-06 12:44 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign53ce6cdf44591021
2017-06-05 23:03 - 2017-06-06 12:25 - 00000000 ____D C:\Windows\IDOOYHNU
2017-06-05 17:04 - 2017-06-05 17:04 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsignffec44d35fb075e6
2017-06-05 17:04 - 2017-06-05 17:04 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsignf2951e3a4706ff43
2017-06-05 13:35 - 2017-06-05 13:35 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign8efc206c9568d7e7
2017-06-05 13:35 - 2017-06-05 13:35 - 00000000 ____D C:\Users\editor\AppData\Local\Tempzxpsign344177af01f77b6a
2017-06-05 13:32 - 2017-06-05 13:32 - 145489330 _____ C:\Users\editor\Downloads\Javier Gil Buendia on 2017-05-04 at 22.09.mp4
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2017-07-05 19:37 - 2016-08-09 11:09 - 00000000 ____D C:\Users\editor\AppData\Roaming\Slack
2017-07-05 19:37 - 2014-10-14 15:01 - 00000000 ___RD C:\Users\editor\OneDrive
2017-07-05 19:29 - 2015-04-15 18:04 - 00000000 ____D C:\AdwCleaner
2017-07-05 19:10 - 2015-01-14 12:06 - 00000000 ____D C:\Users\editor\AppData\Roaming\vlc
2017-07-05 18:02 - 2014-10-22 17:31 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2017-07-05 18:01 - 2017-05-12 13:51 - 00109272 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMChameleon.sys
2017-07-05 17:26 - 2009-07-14 01:32 - 00000000 ____D C:\Program Files\Windows Sidebar
2017-07-05 16:57 - 2012-09-11 21:42 - 00000000 ____D C:\ProgramData\PDFC
2017-07-05 16:17 - 2012-09-11 21:39 - 00000000 ____D C:\Program Files (x86)\Microsoft Office
2017-07-05 16:05 - 2009-07-14 00:45 - 00027568 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2017-07-05 16:05 - 2009-07-14 00:45 - 00027568 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2017-07-05 16:01 - 2009-07-14 01:13 - 00793850 _____ C:\Windows\system32\PerfStringBackup.INI
2017-07-05 16:01 - 2009-07-13 23:20 - 00000000 ____D C:\Windows\inf
2017-07-05 15:58 - 2015-04-17 14:54 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2017-07-05 15:58 - 2014-10-27 18:22 - 00000000 ___RD C:\Users\editor\Creative Cloud Files
2017-07-05 15:58 - 2013-06-14 15:24 - 00000000 ____D C:\Users\editor\AppData\Local\Adobe
2017-07-05 15:57 - 2013-07-01 13:19 - 00000000 ____D C:\Users\editor\AppData\Local\Aja
2017-07-05 15:57 - 2013-06-14 15:36 - 00000000 ____D C:\ProgramData\PACE
2017-07-05 15:57 - 2012-09-24 11:01 - 00000000 ____D C:\ProgramData\NVIDIA
2017-07-05 15:57 - 2009-07-14 01:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2017-07-05 13:48 - 2013-06-14 11:48 - 00000000 ____D C:\Users\editor\AppData\Local\VirtualStore
2017-07-05 11:55 - 2014-10-15 12:23 - 00000000 ____D C:\Program Files\Common Files\Adobe
2017-07-05 11:27 - 2009-07-13 23:20 - 00000000 ____D C:\Windows\system32\NDF
2017-07-05 11:08 - 2016-01-26 13:28 - 00000000 ___HD C:\ProgramData\RWBYTE
2017-07-05 11:08 - 2014-10-14 15:10 - 00000000 ____D C:\ProgramData\Package Cache
2017-07-05 10:57 - 2012-09-11 21:28 - 00000000 ____D C:\Windows\SysWOW64\RTCOM
2017-07-03 19:13 - 2015-09-30 18:30 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2017-07-03 19:11 - 2014-09-30 10:29 - 00000000 ____D C:\Users\editor\Desktop\post docs
2017-07-03 18:12 - 2013-06-14 11:48 - 00000000 ____D C:\Users\editor
2017-07-03 17:01 - 2013-06-14 16:34 - 00000000 ____D C:\Users\Public\Documents\Avid Media Composer
2017-07-03 14:35 - 2017-06-01 14:59 - 00000000 ____D C:\Users\Public\Documents\AdobeInstalledCodecs
2017-06-28 17:08 - 2016-11-10 15:53 - 00000000 ____D C:\Users\editor\Downloads\__MACOSX
2017-06-28 16:54 - 2013-07-03 10:30 - 00000193 _____ C:\Windows\WORDPAD.INI
2017-06-28 14:00 - 2017-06-01 15:09 - 00001281 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Audition CC 2017.lnk
2017-06-28 02:22 - 2017-04-27 09:30 - 00000000 ____D C:\SysData
2017-06-28 02:22 - 2017-04-16 17:34 - 00000000 ____D C:\Users\Default.AVID4\Desktop\RDP Watcher
2017-06-28 02:22 - 2017-04-16 17:32 - 00000000 ____D C:\Users\Default.AVID4\Desktop\RDP Admin Restore
2017-06-27 22:08 - 2017-01-03 19:30 - 00000000 ____D C:\Users\editor\AppData\Roaming\Notepad++
2017-06-27 22:02 - 2015-04-17 14:54 - 00002230 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-06-27 22:02 - 2015-04-17 14:54 - 00002218 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2017-06-27 21:58 - 2013-06-25 09:42 - 00000000 ____D C:\ProgramData\Apple Computer
2017-06-27 21:58 - 2013-06-25 09:42 - 00000000 ____D C:\Program Files (x86)\QuickTime
2017-06-27 13:15 - 2014-12-11 04:25 - 00000000 ____D C:\Windows\system32\appraiser
2017-06-27 13:10 - 2011-02-11 16:29 - 00770504 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2017-06-27 10:22 - 2013-06-14 15:31 - 00000000 ____D C:\Program Files\Java
2017-06-26 23:36 - 2015-11-23 21:01 - 00000000 ____D C:\Users\editor\AppData\Local\CrashDumps
2017-06-26 21:30 - 2012-09-11 21:33 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP Help and Support
2017-06-26 21:30 - 2012-09-11 21:33 - 00000000 ____D C:\ProgramData\Hewlett-Packard
2017-06-26 21:30 - 2012-09-11 21:32 - 00000000 ____D C:\Program Files (x86)\Hewlett-Packard
2017-06-26 21:28 - 2014-10-27 17:06 - 00000000 ____D C:\Users\editor\Downloads\settings
2017-06-26 21:26 - 2017-01-19 16:08 - 00000000 ____D C:\Users\editor\Downloads\Warm Wipe
2017-06-26 21:26 - 2016-10-11 14:01 - 00000000 ____D C:\Users\editor\Downloads\photoshop_brushes
2017-06-26 21:26 - 2014-10-27 17:10 - 00000000 ____D C:\Users\editor\Downloads\ddu
2017-06-26 21:25 - 2017-05-12 18:05 - 00000000 ____D C:\Users\editor\Downloads\TRON
2017-06-26 21:25 - 2016-11-22 17:51 - 00000000 ____D C:\Users\editor\Downloads\RED GIANT PRESENTS
2017-06-26 21:25 - 2016-11-17 17:11 - 00000000 ____D C:\Users\editor\Downloads\Sci-Fi-Biohazard-Model
2017-06-26 21:25 - 2015-12-14 14:23 - 00000000 ____D C:\Users\editor\Downloads\Interview Mag
2017-06-26 21:24 - 2017-01-16 21:45 - 00000000 ____D C:\Users\editor\Downloads\Free-C4D-3D-Model-Modern-Wind-Tunnel
2017-06-26 21:24 - 2016-08-25 15:46 - 00000000 ____D C:\Users\editor\Downloads\20 Stardust Ps Brushes abr-2
2017-06-26 21:24 - 2016-08-12 11:17 - 00000000 ____D C:\Users\editor\Downloads\160812FINAL
2017-06-26 21:24 - 2016-07-20 14:19 - 00000000 ____D C:\Users\editor\Downloads\Cheltenham
2017-06-26 21:24 - 2016-07-20 14:19 - 00000000 ____D C:\Users\editor\Downloads\BauerTopic
2017-06-26 21:24 - 2015-04-03 18:20 - 00000000 ____D C:\Users\editor\Downloads\Fwd- AEPs for GFX - Fonts
2017-06-26 21:20 - 2016-12-23 19:37 - 00000000 ____D C:\Users\editor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Eyescream Factory Presets Sampler Pack
2017-06-26 21:20 - 2015-08-26 19:28 - 00000000 ____D C:\Users\editor\AppData\Local\Microsoft Help
2017-06-26 21:20 - 2015-01-29 16:39 - 00000000 ____D C:\Users\editor\AppData\Roaming\FileZilla
2017-06-26 21:20 - 2014-09-19 12:54 - 00000000 ____D C:\Users\editor\AppData\Roaming\TeamViewer
2017-06-26 21:20 - 2014-09-19 12:00 - 00000000 ____D C:\Program Files (x86)\TeamViewer
2017-06-26 21:20 - 2013-10-10 13:46 - 00000000 ____D C:\Windows\Minidump
2017-06-26 21:20 - 2013-06-25 09:41 - 00000000 ____D C:\ProgramData\Apple
2017-06-26 21:20 - 2011-02-11 16:13 - 00000000 ____D C:\Windows\Panther
2017-06-26 21:19 - 2012-09-24 10:57 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2017-06-26 19:54 - 2017-05-12 13:50 - 00005106 _____ C:\Users\editor\Desktop\Rkill.txt
2017-06-26 19:50 - 2014-10-14 18:18 - 00000000 ____D C:\Windows\System32\Tasks\Event Viewer Tasks
2017-06-26 17:41 - 2014-10-31 18:12 - 00000033 _____ C:\Users\editor\AppData\Roaming\AdobeWLCMCache.dat
2017-06-26 11:15 - 2015-10-27 12:29 - 00000000 ____D C:\Program Files (x86)\Samsung
2017-06-23 19:05 - 2013-07-02 12:54 - 00000000 ____D C:\Users\Public\Documents\Shared Avid Projects
2017-06-23 18:12 - 2013-07-01 13:32 - 00000000 ____D C:\Users\editor\AppData\Local\BorisFX
2017-06-23 15:44 - 2014-10-14 15:19 - 00000000 ____D C:\Program Files\Adobe
2017-06-23 15:44 - 2013-07-01 13:30 - 00000000 ____D C:\Program Files\Boris FX, Inc
2017-06-23 14:13 - 2017-05-12 14:11 - 00004726 __RSH C:\ProgramData\ntuser.pol
2017-06-23 11:29 - 2014-10-22 17:30 - 00000000 ____D C:\ProgramData\Malwarebytes
2017-06-23 11:18 - 2015-11-04 13:32 - 00000000 ____D C:\Windows\pss
2017-06-22 16:53 - 2015-03-09 16:03 - 00000000 ____D C:\Users\editor\AppData\Roaming\Aescripts
2017-06-22 16:50 - 2017-01-17 12:58 - 00000000 ____D C:\ProgramData\aescripts
2017-06-22 14:33 - 2014-11-04 16:57 - 00000000 ____D C:\ProgramData\Red Giant
2017-06-22 14:25 - 2015-08-24 14:57 - 00000000 ____D C:\ProgramData\rgt
2017-06-22 12:07 - 2016-02-11 22:42 - 00000000 ____D C:\Users\Public\Documents\Adobe
2017-06-22 10:18 - 2014-10-14 15:01 - 00002154 _____ C:\Users\editor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft OneDrive.lnk
2017-06-20 16:27 - 2015-11-24 13:19 - 00000000 ____D C:\ProgramData\xml_param
2017-06-20 14:57 - 2016-01-21 14:26 - 00000600 _____ C:\Users\editor\AppData\Local\PUTTY.RND
2017-06-16 21:21 - 2016-06-24 17:20 - 00000000 ____D C:\Users\editor\Desktop\junk
2017-06-16 10:10 - 2016-12-13 12:45 - 00004312 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2017-06-16 10:10 - 2013-06-14 15:24 - 00803328 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2017-06-16 10:10 - 2013-06-14 15:24 - 00144896 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2017-06-16 10:10 - 2013-06-14 15:24 - 00000000 ____D C:\Windows\SysWOW64\Macromed
2017-06-16 10:10 - 2013-06-14 15:24 - 00000000 ____D C:\Windows\system32\Macromed
2017-06-14 04:01 - 2009-07-13 23:20 - 00000000 ____D C:\Windows\rescache
2017-06-14 03:21 - 2009-07-13 23:20 - 00000000 ____D C:\Windows\SysWOW64\migwiz
2017-06-14 03:21 - 2009-07-13 23:20 - 00000000 ____D C:\Windows\system32\migwiz
2017-06-14 03:05 - 2014-10-14 18:38 - 00000000 ____D C:\Windows\system32\MRT
2017-06-14 03:02 - 2012-09-24 11:18 - 133627792 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2017-06-13 16:49 - 2016-08-09 11:09 - 00000000 ____D C:\Users\editor\AppData\Local\slack
2017-06-13 16:48 - 2016-08-09 11:09 - 00002124 _____ C:\Users\editor\Desktop\Slack.lnk
2017-06-13 16:48 - 2016-08-09 11:09 - 00000000 ____D C:\Users\editor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Slack Technologies
2017-06-13 16:48 - 2016-08-09 11:09 - 00000000 ____D C:\Users\editor\AppData\Local\SquirrelTemp
2017-06-08 12:50 - 2013-06-14 15:28 - 00000000 ____D C:\Users\editor\AppData\Roaming\Adobe
2017-06-08 12:50 - 2013-06-14 15:24 - 00000000 ____D C:\Program Files (x86)\Adobe
2017-06-06 19:39 - 2017-05-26 14:22 - 00000000 ____D C:\Users\editor\Desktop\PLAYBOY2
2017-06-06 12:50 - 2017-05-15 11:26 - 00000000 ____D C:\Program Files\Tablet
2017-06-06 12:44 - 2017-05-12 13:51 - 00077376 _____ C:\Windows\system32\Drivers\mbae64.sys
2017-06-06 05:32 - 2015-04-17 14:53 - 00000000 ____D C:\Program Files (x86)\Google
 
==================== Files in the root of some directories =======
 
2014-10-31 18:12 - 2017-06-26 17:41 - 0000033 _____ () C:\Users\editor\AppData\Roaming\AdobeWLCMCache.dat
2015-10-13 19:40 - 2016-12-22 21:01 - 2111970 _____ () C:\Users\editor\AppData\Roaming\AvidApplicationManager_Install.log
2015-12-08 15:05 - 2015-12-08 15:05 - 0353038 _____ () C:\Users\editor\AppData\Roaming\CodecsPE_Install.log
2013-07-02 12:53 - 2013-07-02 12:56 - 13619600 _____ () C:\Users\editor\AppData\Roaming\MediaComposer_Install.log
2015-11-11 12:23 - 2015-11-11 12:23 - 0000600 _____ () C:\Users\editor\AppData\Roaming\winscp.rnd
2016-01-06 12:10 - 2016-01-06 18:19 - 0001456 _____ () C:\Users\editor\AppData\Local\Adobe Save for Web 13.0 Prefs
2016-01-21 14:26 - 2017-06-20 14:57 - 0000600 _____ () C:\Users\editor\AppData\Local\PUTTY.RND
2016-08-02 16:02 - 2016-08-02 16:02 - 0000218 _____ () C:\Users\editor\AppData\Local\recently-used.xbel
2015-03-04 14:24 - 2015-06-23 13:47 - 0007615 _____ () C:\Users\editor\AppData\Local\Resmon.ResmonCfg
 
Some files in TEMP:
====================
2017-06-27 13:21 - 2017-06-27 13:21 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext1027697961600061628.dll
2017-06-29 17:07 - 2017-06-29 17:07 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext1258149424519446074.dll
2017-07-05 11:12 - 2017-07-05 11:12 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext2697837497018625878.dll
2017-07-03 19:15 - 2017-07-03 19:15 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext3251087211178117268.dll
2017-07-05 15:59 - 2017-07-05 15:59 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext5607273401511965068.dll
2017-07-03 10:06 - 2017-07-03 10:06 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext620865008930991640.dll
2017-06-28 11:43 - 2017-06-28 11:43 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext7393589978457771912.dll
2017-06-27 21:39 - 2017-06-27 21:39 - 0152576 _____ () C:\Users\editor\AppData\Local\Temp\ext8605042541235625311.dll
2017-07-05 11:12 - 2017-07-05 15:59 - 1458856 _____ (Sysinternals - www.sysinternals.com) C:\Users\editor\AppData\Local\Temp\PROCEXP64.exe
 
Some zero byte size files/folders:
==========================
C:\Windows\System32\.exe
 
==================== Bamital & volsnap ======================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
 
LastRegBack: 2017-07-02 00:03
 
==================== End of FRST.txt ============================


#8 rm540

rm540
  • Topic Starter

  • Members
  • 13 posts
  • OFFLINE
  •  
  • Local time:06:14 PM

Posted 05 July 2017 - 07:03 PM

# AdwCleaner v6.047 - Logfile created 05/07/2017 at 19:29:07
# Updated on 19/05/2017 by Malwarebytes
# Database : 2017-07-05.1 [Local]
# Operating System : Windows 7 Professional Service Pack 1 (X64)
# Username : editor - AVID4
# Running from : C:\Users\editor\Desktop\AdwCleaner.exe
# Mode: Scan
 
 
 
***** [ Services ] *****
 
No malicious services found.
 
 
***** [ Folders ] *****
 
Folder Found:  C:\Users\editor\Desktop\Dig Deep
 
 
***** [ Files ] *****
 
No malicious files found.
 
 
***** [ DLL ] *****
 
No malicious DLLs found.
 
 
***** [ WMI ] *****
 
No malicious keys found.
 
 
***** [ Shortcuts ] *****
 
No infected shortcut found.
 
 
***** [ Scheduled Tasks ] *****
 
No malicious task found.
 
 
***** [ Registry ] *****
 
No malicious registry entries found.
 
 
***** [ Web browsers ] *****
 
No malicious Firefox based browser items found.
No malicious Chromium based browser items found.
 
*************************
 
C:\AdwCleaner\AdwCleaner[C0].txt - [1709 Bytes] - [05/07/2017 15:54:27]
C:\AdwCleaner\AdwCleaner[S0].txt - [1848 Bytes] - [05/07/2017 15:12:10]
C:\AdwCleaner\AdwCleaner[S1].txt - [1169 Bytes] - [05/07/2017 19:29:07]
 
########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [1242 Bytes] ##########


#9 rm540

rm540
  • Topic Starter

  • Members
  • 13 posts
  • OFFLINE
  •  
  • Local time:06:14 PM

Posted 05 July 2017 - 07:22 PM

I'm not sure why  C:\Users\editor\Desktop\Dig Deep is being flagged, I don't see anything other than video files and video editing project files. I have hidden files turned on. Mbar didn't find anything.

 

I manually discovered the culprit of at least some of the unauthorized remote access. I'm not sure how this user got there, if it's safe to delete, etc.

 

C:\Users\Default.AVID4\Desktop\

C:\Users\Default.AVID4\Desktop\RDP Admin Restore

C:\Users\Default.AVID4\Desktop\RDP Admin Restore\02_disable_NLA.reg

C:\Users\Default.AVID4\Desktop\RDP Admin Restore\reset_p.bat

C:\Users\Default.AVID4\Desktop\RDP Admin Restore\Your ID.txt

C:\Users\Default.AVID4\Desktop\RDP Watcher

C:\Users\Default.AVID4\Desktop\RDP Watcher\disable_UI0Detect.bat

C:\Users\Default.AVID4\Desktop\RDP Watcher\disable_win_Firewall.bat

C:\Users\Default.AVID4\Desktop\RDP Watcher\Your ID.txt

C:\Users\Default.AVID4\Desktop\UniversalTermsrvPatch_20090425

C:\Users\Default.AVID4\Desktop\UniversalTermsrvPatch_20090425\Readme.txt

C:\Users\Default.AVID4\Desktop\UniversalTermsrvPatch_20090425\vista.reg

C:\Users\Default.AVID4\Desktop\UniversalTermsrvPatch_20090425\xp.reg

C:\Users\Default.AVID4\Desktop\GoogleChromePortable_57.0.2987.133_online.paf.exe

 

 

I read the contents of each file and reversed most of the changes. Unfortunately these files are not malware alone, and are therefore not detected, but obviously they have enabled remote execution of code by enabling unrestricted terminal service access. I'm hoping the hardware firewall will block this in the future, but how can I be sure? 

 

reset_p.bat I don't know how to prevent - I will PM the full code if you like. It essentially can give the remote user admin privs - I believe it's the first step into compromising further. 

 

The main part of the code gives the remote user admin privileges through a .vbs script and deletes evidence of doing so. This second part enables sticky keys to enable an exploit, but I'm not sure what to do about this as I couldn't find these registry entries:

 

REG ADD "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sethc.exe" /v Debugger /t REG_SZ /d "C:\Windows\PreInstall\uddi.exe"



#10 rm540

rm540
  • Topic Starter

  • Members
  • 13 posts
  • OFFLINE
  •  
  • Local time:06:14 PM

Posted 05 July 2017 - 07:31 PM

Actually, at least some of the suspicious programs were detected by another scanner, unfortunately I've been running a lot of them so I don't remember which one generated this log file "SCK.txt". It was possibly esetonlinescanner.

 

Here are the contents of that log:

 

C:\SysData\acnon.exe a variant of Win64/BitCoinMiner.AX potentially unsafe application
C:\TDSSKiller_Quarantine\22.06.2017_21.58.29\uds0000\svc0000\tsk0000.dta a variant of Generik.MXGVNQB trojan
C:\Users\Default.AVID4\Desktop\RDP Admin Restore\01_RDP Admin Restore.exe a variant of Win32/Packed.Themida.AJO trojan
C:\Users\Default.AVID4\Desktop\RDP Watcher\01_RDP Watcher.exe a variant of Win32/Packed.Themida.AJO trojan
C:\Users\editor\Downloads\c.exe Win32/Bundled.Toolbar.Google.D potentially unsafe application
C:\Users\editor\Downloads\ccsetup511.exe Win32/Bundled.Toolbar.Google.D potentially unsafe application


#11 Jo*

Jo*

  • Malware Response Team
  • 3,293 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Germany
  • Local time:12:14 AM

Posted 06 July 2017 - 01:45 AM

I'm not sure why  C:\Users\editor\Desktop\Dig Deep is being flagged, I don't see anything other than video files and video editing project files. I have hidden files turned on. Mbar didn't find anything.
 
I manually discovered the culprit of at least some of the unauthorized remote access. I'm not sure how this user got there, if it's safe to delete, etc.
 
C:\Users\Default.AVID4\Desktop\
C:\Users\Default.AVID4\Desktop\RDP Admin Restore
C:\Users\Default.AVID4\Desktop\RDP Admin Restore\02_disable_NLA.reg
C:\Users\Default.AVID4\Desktop\RDP Admin Restore\reset_p.bat
C:\Users\Default.AVID4\Desktop\RDP Admin Restore\Your ID.txt
C:\Users\Default.AVID4\Desktop\RDP Watcher
C:\Users\Default.AVID4\Desktop\RDP Watcher\disable_UI0Detect.bat
C:\Users\Default.AVID4\Desktop\RDP Watcher\disable_win_Firewall.bat
C:\Users\Default.AVID4\Desktop\RDP Watcher\Your ID.txt
C:\Users\Default.AVID4\Desktop\UniversalTermsrvPatch_20090425
C:\Users\Default.AVID4\Desktop\UniversalTermsrvPatch_20090425\Readme.txt
C:\Users\Default.AVID4\Desktop\UniversalTermsrvPatch_20090425\vista.reg
C:\Users\Default.AVID4\Desktop\UniversalTermsrvPatch_20090425\xp.reg
C:\Users\Default.AVID4\Desktop\GoogleChromePortable_57.0.2987.133_online.paf.exe
 
 
I read the contents of each file and reversed most of the changes. Unfortunately these files are not malware alone, and are therefore not detected, but obviously they have enabled remote execution of code by enabling unrestricted terminal service access. I'm hoping the hardware firewall will block this in the future, but how can I be sure? 
 
reset_p.bat I don't know how to prevent - I will PM the full code if you like. It essentially can give the remote user admin privs - I believe it's the first step into compromising further. 
 
The main part of the code gives the remote user admin privileges through a .vbs script and deletes evidence of doing so. This second part enables sticky keys to enable an exploit, but I'm not sure what to do about this as I couldn't find these registry entries:
 
REG ADD "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\sethc.exe" /v Debugger /t REG_SZ /d "C:\Windows\PreInstall\uddi.exe"

If you are sure, that this user profile is created by malware, you can delete it:
https://support.asperasoft.com/hc/en-us/articles/216127438-How-to-delete-Windows-user-profiles

---


I noticed that you have Potentially Unwanted Programs (PUPs) installed on your system.
I'll ask you to uninstall them since uninstalling such programs before running more malware removal tools will ensure a better clean-up.
Go to Start > Control Panel, double-click on Add/Remove Programs or Programs and Features in Vista / Windows 7/8/10 and remove:


iSkysoft iTube Studio

---

Open notepad. Please copy the contents of the code box below. To do this highlight the contents of the box and right click on it. Paste this into the open notepad.
Save it in the same location as / FSRT / FSRT64 (usually your desktop) as fixlist.txt
 
Start
CreateRestorePoint:
CloseProcesses:
HKU\S-1-5-21-3225783554-34173836-2973484787-1001\...\Run: [AdobeBridge] => [X]
GroupPolicy: Restriction <==== ATTENTION
GroupPolicy\User: Restriction <==== ATTENTION
GroupPolicyScripts: Restriction <==== ATTENTION
GroupPolicyScripts\User: Restriction <==== ATTENTION
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-3225783554-34173836-2973484787-500 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=CMDTDF&pc=CMDTDF&src=IE-SearchBox
FF HKLM-x32\...\Firefox\Extensions: [ISAllmytube@iSkysoft.com] - C:\ProgramData\iSkysoft\iTube Studio\ISAllmytube@iSkysoft.com
FF Extension: (iSkysoft iTube Studio) - C:\ProgramData\iSkysoft\iTube Studio\ISAllmytube@iSkysoft.com [2015-11-24] [not signed]
CHR Extension: (Chrome Media Router) - C:\Users\editor\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-06-28]
S4 TermService; %ProgramFiles%\RDP Wrapper\rdpwrap.dll [X]
2017-07-05 12:17 - 2017-07-05 12:17 - 00528106 _____ C:\Users\editor\Downloads\Silent Runners.vbs
CustomCLSID: HKU\S-1-5-21-3225783554-34173836-2973484787-1001_Classes\CLSID\{073CB204-6B29-46FC-AB98-451F1D068741}\InprocServer32 -> C:\Program Files\Autodesk\3ds Max 2018\Inventor Server\Bin\TestServer.dll => No File
CustomCLSID: HKU\S-1-5-21-3225783554-34173836-2973484787-1001_Classes\CLSID\{8C23B656-4E6E-4B45-9920-9617168D39A3}\InprocServer32 -> C:\Program Files\Autodesk\3ds Max 2018\Inventor Server\Bin\TestServer.dll => No File
CustomCLSID: HKU\S-1-5-21-3225783554-34173836-2973484787-1001_Classes\CLSID\{E5B0515D-48D2-4F04-906D-0192ED65A2DD}\InprocServer32 -> C:\Program Files\Autodesk\3ds Max 2018\Inventor Server\Bin\TestServer.dll => No File
ContextMenuHandlers01: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} =>  -> No File
ContextMenuHandlers04: [MSSE] -> {0365FE2C-F183-4091-AC82-BFC39FB75C49} =>  -> No File
ContextMenuHandlers06: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} =>  -> No File
AlternateDataStreams: C:\ProgramData\Microsoft:0LzQmy2yLXIkuOxWrd [1910]
AlternateDataStreams: C:\ProgramData\Microsoft:kcBk6PcxHyvHjtR8 [2314]
AlternateDataStreams: C:\ProgramData\Microsoft:lIp54pnOEvBhOzqQjZpz2nn [2310]
AlternateDataStreams: C:\ProgramData\Microsoft:Ocomea4gZtY3lSOUf5iphCE [2038]
AlternateDataStreams: C:\ProgramData\Microsoft:v3g4yepAVzDTtez7meXIUiueJ [1956]
AlternateDataStreams: C:\ProgramData\Microsoft:Xm9UIZv3H4zTt7eqpuDLw7zIg [2260]
AlternateDataStreams: C:\ProgramData\PACE:B90686C2DDD4C048 [217]
AlternateDataStreams: C:\Users\editor\Cookies:EOqXQzoQSm4Yr9HXggRR4KKY [1930]
AlternateDataStreams: C:\Users\editor\Downloads\PICKUPS1.avb:BINSTATE_RSRC [131074]
AlternateDataStreams: C:\Users\editor\Downloads\TrueLife_FullScreenCredits_CreditCrunch.avb:BINSTATE_RSRC [131074]
AlternateDataStreams: C:\Users\editor\AppData\Local\Temporary Internet Files:KXXPwIqcZrAoHR5V6MIVZYrg [2354]
End

NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

Run FRST / FSRT64 again as Administrator like we did before but this time press the Fix button just once and wait.

The tool will make a log (Fixlog.txt) please post it to your reply.


How the computer is running now?

Graduate of the WTT Classroom
Cheers,
Jo
If I have been helping you, and I have not replied to your latest post in 36 hours please send me a PM.


#12 rm540

rm540
  • Topic Starter

  • Members
  • 13 posts
  • OFFLINE
  •  
  • Local time:06:14 PM

Posted 06 July 2017 - 11:55 AM

 
Thank you for the script. Here is the log, I ran it after removing the iskysoft program.
 
 
 
Fix result of Farbar Recovery Scan Tool (x64) Version: 05-07-2017
Ran by editor (06-07-2017 12:47:08) Run:1
Running from C:\Users\editor\Desktop
Loaded Profiles: editor & Administrator (Available Profiles: user & editor & Default & IUSR_Servs & Administrator)
Boot Mode: Normal
==============================================
 
fixlist content:
*****************
Start
CreateRestorePoint:
CloseProcesses:
HKU\S-1-5-21-3225783554-34173836-2973484787-1001\...\Run: [AdobeBridge] => [X]
GroupPolicy: Restriction <==== ATTENTION
GroupPolicy\User: Restriction <==== ATTENTION
GroupPolicyScripts: Restriction <==== ATTENTION
GroupPolicyScripts\User: Restriction <==== ATTENTION
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-3225783554-34173836-2973484787-500 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=CMDTDF&pc=CMDTDF&src=IE-SearchBox
FF HKLM-x32\...\Firefox\Extensions: [ISAllmytube@iSkysoft.com] - C:\ProgramData\iSkysoft\iTube Studio\ISAllmytube@iSkysoft.com
FF Extension: (iSkysoft iTube Studio) - C:\ProgramData\iSkysoft\iTube Studio\ISAllmytube@iSkysoft.com [2015-11-24] [not signed]
CHR Extension: (Chrome Media Router) - C:\Users\editor\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-06-28]
S4 TermService; %ProgramFiles%\RDP Wrapper\rdpwrap.dll [X]
2017-07-05 12:17 - 2017-07-05 12:17 - 00528106 _____ C:\Users\editor\Downloads\Silent Runners.vbs
CustomCLSID: HKU\S-1-5-21-3225783554-34173836-2973484787-1001_Classes\CLSID\{073CB204-6B29-46FC-AB98-451F1D068741}\InprocServer32 -> C:\Program Files\Autodesk\3ds Max 2018\Inventor Server\Bin\TestServer.dll => No File
CustomCLSID: HKU\S-1-5-21-3225783554-34173836-2973484787-1001_Classes\CLSID\{8C23B656-4E6E-4B45-9920-9617168D39A3}\InprocServer32 -> C:\Program Files\Autodesk\3ds Max 2018\Inventor Server\Bin\TestServer.dll => No File
CustomCLSID: HKU\S-1-5-21-3225783554-34173836-2973484787-1001_Classes\CLSID\{E5B0515D-48D2-4F04-906D-0192ED65A2DD}\InprocServer32 -> C:\Program Files\Autodesk\3ds Max 2018\Inventor Server\Bin\TestServer.dll => No File
ContextMenuHandlers01: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} =>  -> No File
ContextMenuHandlers04: [MSSE] -> {0365FE2C-F183-4091-AC82-BFC39FB75C49} =>  -> No File
ContextMenuHandlers06: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} =>  -> No File
AlternateDataStreams: C:\ProgramData\Microsoft:0LzQmy2yLXIkuOxWrd [1910]
AlternateDataStreams: C:\ProgramData\Microsoft:kcBk6PcxHyvHjtR8 [2314]
AlternateDataStreams: C:\ProgramData\Microsoft:lIp54pnOEvBhOzqQjZpz2nn [2310]
AlternateDataStreams: C:\ProgramData\Microsoft:Ocomea4gZtY3lSOUf5iphCE [2038]
AlternateDataStreams: C:\ProgramData\Microsoft:v3g4yepAVzDTtez7meXIUiueJ [1956]
AlternateDataStreams: C:\ProgramData\Microsoft:Xm9UIZv3H4zTt7eqpuDLw7zIg [2260]
AlternateDataStreams: C:\ProgramData\PACE:B90686C2DDD4C048 [217]
AlternateDataStreams: C:\Users\editor\Cookies:EOqXQzoQSm4Yr9HXggRR4KKY [1930]
AlternateDataStreams: C:\Users\editor\Downloads\PICKUPS1.avb:BINSTATE_RSRC [131074]
AlternateDataStreams: C:\Users\editor\Downloads\TrueLife_FullScreenCredits_CreditCrunch.avb:BINSTATE_RSRC [131074]
AlternateDataStreams: C:\Users\editor\AppData\Local\Temporary Internet Files:KXXPwIqcZrAoHR5V6MIVZYrg [2354]
End
*****************
 
Restore point was successfully created.
Processes closed successfully.
HKU\S-1-5-21-3225783554-34173836-2973484787-1001\Software\Microsoft\Windows\CurrentVersion\Run\\AdobeBridge => value removed successfully
C:\Windows\system32\GroupPolicy\Machine => moved successfully
C:\Windows\system32\GroupPolicy\GPT.ini => moved successfully
C:\Windows\system32\GroupPolicy\User => moved successfully
"C:\Windows\system32\GroupPolicy\Machine" => not found.
"C:\Windows\system32\GroupPolicy\User" => not found.
HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully
HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully
HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully
HKU\S-1-5-21-3225783554-34173836-2973484787-500\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully
HKLM\Software\Wow6432Node\Mozilla\Firefox\Extensions\\ISAllmytube@iSkysoft.com => value not found.
C:\ProgramData\iSkysoft\iTube Studio\ISAllmytube@iSkysoft.com => not found.
HKLM\System\CurrentControlSet\Services\TermService => key removed successfully
TermService => service removed successfully
C:\Users\editor\Downloads\Silent Runners.vbs => moved successfully
HKU\S-1-5-21-3225783554-34173836-2973484787-1001_Classes\CLSID\{073CB204-6B29-46FC-AB98-451F1D068741} => key removed successfully
HKU\S-1-5-21-3225783554-34173836-2973484787-1001_Classes\CLSID\{8C23B656-4E6E-4B45-9920-9617168D39A3} => key removed successfully
HKU\S-1-5-21-3225783554-34173836-2973484787-1001_Classes\CLSID\{E5B0515D-48D2-4F04-906D-0192ED65A2DD} => key removed successfully
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\WinRAR32 => key removed successfully
HKLM\Software\Classes\CLSID\{B41DB860-8EE4-11D2-9906-E49FADC173CA} => key not found. 
HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers\MSSE => key removed successfully
HKLM\Software\Classes\CLSID\{0365FE2C-F183-4091-AC82-BFC39FB75C49} => key not found. 
HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\WinRAR32 => key removed successfully
HKLM\Software\Classes\CLSID\{B41DB860-8EE4-11D2-9906-E49FADC173CA} => key not found. 
C:\ProgramData\Microsoft => ":0LzQmy2yLXIkuOxWrd" ADS removed successfully.
C:\ProgramData\Microsoft => ":kcBk6PcxHyvHjtR8" ADS removed successfully.
C:\ProgramData\Microsoft => ":lIp54pnOEvBhOzqQjZpz2nn" ADS removed successfully.
C:\ProgramData\Microsoft => ":Ocomea4gZtY3lSOUf5iphCE" ADS removed successfully.
C:\ProgramData\Microsoft => ":v3g4yepAVzDTtez7meXIUiueJ" ADS removed successfully.
C:\ProgramData\Microsoft => ":Xm9UIZv3H4zTt7eqpuDLw7zIg" ADS removed successfully.
C:\ProgramData\PACE => ":B90686C2DDD4C048" ADS removed successfully.
C:\Users\editor\Cookies => ":EOqXQzoQSm4Yr9HXggRR4KKY" ADS removed successfully.
C:\Users\editor\Downloads\PICKUPS1.avb => ":BINSTATE_RSRC" ADS removed successfully.
C:\Users\editor\Downloads\TrueLife_FullScreenCredits_CreditCrunch.avb => ":BINSTATE_RSRC" ADS removed successfully.
C:\Users\editor\AppData\Local\Temporary Internet Files => ":KXXPwIqcZrAoHR5V6MIVZYrg" ADS removed successfully.
 
 
The system needed a reboot.
 
==== End of Fixlog 12:47:21 ====
 
 
 
I haven't experienced really any issues this whole time, which is probably by design so I couldn't detect any of the virus' actions. I did experience some lowered performance while using After Effects, but it's quite possible it's unrelated. 

Was termservice removed completely? I never use it and it seems like a major security issue. Thanks for your help! Let me know if there's anything else I can run to make sure this problem is gone completely. 

Edited by rm540, 06 July 2017 - 11:57 AM.


#13 rm540

rm540
  • Topic Starter

  • Members
  • 13 posts
  • OFFLINE
  •  
  • Local time:06:14 PM

Posted 06 July 2017 - 12:00 PM

Also, I'm not certain that the users IUSR_Servs and Default.AVID4 (where I found the remote exploits) were created by the malware, but I did not create them. Can I still delete them? Their C:\Users folders were created at the exact same time, but only IUSR_Servs is listed in the "User Profiles" section of system properties. 


Edited by rm540, 06 July 2017 - 12:04 PM.


#14 Jo*

Jo*

  • Malware Response Team
  • 3,293 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Germany
  • Local time:12:14 AM

Posted 06 July 2017 - 12:20 PM

A restore point was created, when the fixlist ran.

So if you delete the two suspect user profiles, worst case some installed software needs them and you have to re-install some things.

But make sure, that you do still have another computer administrator profile, before deleting user profiles!

---

:step1: Please download and run the following tool to help allow other programs to run. (courtesy of BleepingComputer.com)
There are 5 different versions. If one of them won't run then download and try to run the other one.
Vista and Win7/8/10 users need to right click and choose Run as Administrator
You only need to get one of them to run, not all of them.Do not reboot your computer after running rkill as the malware programs will start again.


---


:step2: Malwarebytes' Anti-Malware
If this program is already installed: Skip the installation and run only the scan!
Download and install: Please download Malwarebytes Anti-Malware to your desktop.
  • Double-click mb3-setup-1878.1878-3.4.5.2467.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to the following:
    • Launch Malwarebytes Anti-Malware
    • A 14 day trial of the Premium features is pre-selected. You may deselect this if you wish, and it will not diminish the scanning and removal capabilities of the program.
  • Click Finish.
  • On the Dashboard, click the 'Update Now >>' link
  • After the update completes, click the 'Scan Now >>' button.
  • Or, on the Dashboard, click the Scan Now >> button.
  • If an update is available, click the Update Now button.
  • A Threat Scan will begin.
  • When the scan is complete, if there have been detections, click Apply Actions to allow MBAM to clean what was detected.
  • In most cases, a restart will be required.
  • Wait for the prompt to restart the computer to appear, then click on Yes.
How to get logs: (Export log to save as txt)
  • After the restart once you are back at your desktop, open MBAM once more.
  • Click on the History tab > Application Logs.
  • Double click on the scan log which shows the Date and time of the scan just performed.
  • Click 'Export'.
  • Click 'Text file (*.txt)'
  • In the Save File dialog box which appears, click on Desktop.
  • In the File name: box type a name for your scan log.
  • A message box named 'File Saved' should appear stating "Your file has been successfully exported".
  • Click Ok
  • Attach that saved log to your next reply.
(Copy to clipboard for pasting into forum replies or tickets)
  • After the restart once you are back at your desktop, open MBAM once more.
  • Click on the History tab > Application Logs.
  • Double click on the scan log which shows the Date and time of the scan just performed.
  • Click 'Copy to Clipboard'
  • Paste the contents of the clipboard into your reply.

---


:step3:
ZN3USrZ.png Emsisoft Emergency Kit
  • Click here to download Emsisoft Emergency Kit. The download will automatically start after a moment.
  • Save EmsisoftEmergencyKit.exe to your Desktop.
  • Double click on EmsisoftEmergencyKit.exe (Windows Vista/7/8 users: Accept UAC warning if it is enabled). A screen like this will appear:
    dQVDkTW.png
  • Leave everything as it is, then click Extract. This will unpack Emsisoft Emergency Kit to the EEK folder located in the root drive (usually C:\).
  • Once the extraction is done, an icon qwL1Upn.png will appear on your Desktop. Double click it to start Emsisoft Emergency Kit.
  • Wait for Emsisoft Emergency Kit to finish loading signatures. A screen like this should appear:
    yEgPemv.png
  • Choose Yes, then wait for EEK to finish updating.
  • Choose Malware Scan under the Scan button. When EEK asks to activate PUP detection, choose Yes.
  • Wait for the scan to finish.
    RUeRoi4.png
  • If EEK detects something, all detected items will be displayed. Place a checkmark before everything, then choose Quarantine Selected.
  • If Emsisoft Emergency Kit asks to reboot, please do so immediately.
  • The scan log is located in Logs -> Scan Logs. Click on the entry of the latest scan, choose Export and save the report on your Desktop.
    P7FSALs.png
  • Please Copy and Paste the contents of the scan log in your next reply.

***


:step4: How the computer is running now?


***


Graduate of the WTT Classroom
Cheers,
Jo
If I have been helping you, and I have not replied to your latest post in 36 hours please send me a PM.


#15 rm540

rm540
  • Topic Starter

  • Members
  • 13 posts
  • OFFLINE
  •  
  • Local time:06:14 PM

Posted 06 July 2017 - 02:49 PM

Malwarebytes
www.malwarebytes.com
 
-Log Details-
Scan Date: 7/6/17
Scan Time: 2:50 PM
Log File: 
Administrator: Yes
 
-Software Information-
Version: 3.1.2.1733
Components Version: 1.0.141
Update Package Version: 1.0.2305
License: Free
 
-System Information-
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: AVID4\editor
 
-Scan Summary-
Scan Type: Custom Scan
Result: Completed
Objects Scanned: 713599
Threats Detected: 0
(No malicious items detected)
Threats Quarantined: 0
(No malicious items detected)
Time Elapsed: 33 min, 45 sec
 
-Scan Options-
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
 
-Scan Details-
Process: 0
(No malicious items detected)
 
Module: 0
(No malicious items detected)
 
Registry Key: 0
(No malicious items detected)
 
Registry Value: 0
(No malicious items detected)
 
Registry Data: 0
(No malicious items detected)
 
Data Stream: 0
(No malicious items detected)
 
Folder: 0
(No malicious items detected)
 
File: 0
(No malicious items detected)
 
Physical Sector: 0
(No malicious items detected)
 
 
(end)
 
 
 
 
 
Emsisoft Emergency Kit - Version 2017.6
Scan log
 
Date Scan Method Objects Scanned Objects Detected Duration Type Computer Name
7/6/2017 3:33:37 PM Malware 100630 0 0:00:43 Manual scan AVID4
 
 
 
Computer seems to be running ok, I'll be doing some work soon and will see if there are any performance gains. 

Edited by rm540, 06 July 2017 - 03:12 PM.





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users