Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Avast reports JS:ScriptPE-inf [Trj] in Yahoo.com


  • This topic is locked This topic is locked
2 replies to this topic

#1 Glenski

Glenski

  • Members
  • 44 posts
  • OFFLINE
  •  
  • Local time:08:05 PM

Posted 13 September 2017 - 06:03 AM

Starting about 3-4 weeks ago, I began getting the following Avast alert whenever I clicked on a yahoo.com news article headline.

 

Thread secured

We've safely aborted connection on www.yahoo.com because it was infected with JS:ScriptPE-inf [Trj].

More threats may be lurking!

(scan my PC) 

 

Details show:

Thread name   JS:ScriptPE-inf [Trj]

Severity   (minimal sign on the bar scale)

URL   https://www.yahoo.com/_td_remote

Process   C:\Program Files\Mozilla Firefox\firefox.exe

Detected by Web Shield

Status Connection aborted

 

I don't click the scan button. I just X out of the warning. I have not lost any Yahoo connection and can just proceed with the news story.

This appears whether I view Yahoo.com in Firefox or IE, but not in Chrome. It does not show up when viewing yahoo.co.jp (I live in Japan.)

 

I run Avast scans every Saturday, same with Superantispyware. Avast never finds a virus. Superantispyware finds 800-1200 cookies.

I run both only after updating them.

My Windows Update is set to automatic.

 

I have an NEC LaVie laptop with Japanese OS (I live in Japan).

Windows 7

I never use Internet Explorer. Only Firefox.

My computer is run through a home wifi system, not on any multi-user network.

I have AdBlock running.

 

I reported this in the Security forum, and I did the following.

Removed Superantispyware.

Ran CCleaner, Malwarebytes, AdwCleaner, and Junkware Removal Tool.

I unchecked AdBlock's Filter preferences for Allow some non-intrusive advertisements.

 

Ran Security Check, but after downloading the Security Check program, I had problems.

Double clicked, and allowed the first security check.

Then it seemed to start doing something normal, but it stopped with an error message that I could send to Microsoft or not. Since the messages were in Japanese, I didn't proceed.

 

I posted CCleaner's 3 following lists:

Tools --> Startup --> Windows Startups and Scheduled Tasks

tools --> Uninstall --> List of programs to remove.

 

Finally, I disabled the following:

Startups: Use CCleaner by clicking on each item and choosing Disable on the right.

Yes    HKLM:Run    DelaypluginInstall        C:\ProgramData\Wondershare\Video Converter Ultimate\DelayPluginI.exe

Yes    HKLM:Run    IgfxTray    Intel Corporation    C:\Windows\system32\igfxtray.exe
Yes    HKLM:Run    IJNetworkScannerSelectorEX    CANON INC.    C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe /FORCE

Yes    HKLM:Run    iTunesHelper    Apple Inc.    "C:\Program Files\iTunes\iTunesHelper.exe"

Yes    HKLM:Run    SunJavaUpdateSched    Oracle Corporation    "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"

 

Tasks: Use CCleaner by clicking on each item and choosing Disable on the right.

Yes    Task    CCleanerSkipUAC    Piriform Ltd    "C:\Program Files\CCleaner\CCleaner.exe" $(Arg0)
Yes    Task    DropboxUpdateTaskMachineCore    Dropbox, Inc.    C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe /c
Yes    Task    DropboxUpdateTaskMachineUA    Dropbox, Inc.    C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe /ua /installsource scheduler

Yes    Task    GoogleUpdateTaskMachineUA    Google Inc.    C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
Yes    Task    SafeZone scheduled Autoupdate 1493474078    Avast Software    C:\Program Files\AVAST Software\SZBrowser\launcher.exe --scheduledautoupdate $(Arg0)
Yes    Task    {55973317-C0A1-49AE-97AA-288DB64AD968}    Microsoft Corporation    C:\Windows\system32\pcalua.exe -a C:\Users\Owner\Desktop\classic_doom_3.1.3.1.exe -d C:\Users\Owner\Desktop
Yes    Task    {F696468E-206D-410E-8C92-2CDAC8FD084A}    Microsoft Corporation    C:\Windows\system32\pcalua.exe -a C:\Users\Owner\Downloads\wlsetup-web(4).exe -d C:\Users\Owner\Downloads

 

Uninstall these programs:

Free Windows Cleanup Tool        2017/07/09

 

Virtually immediately after a reboot, the problem reappeared, so I was told to come here and provide the synopsis above.

(Edit: I forgot something. I also ran Farbar Recovery Scan tool. Here are the 2 logs.

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 12-09-2017
Ran by Owner (administrator) on OWNER-PC (13-09-2017 19:39:17)
Running from C:\Users\Owner\Desktop
Loaded Profiles: Owner (Available Profiles: Owner)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: 日本語 (日本)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Dropbox, Inc.) C:\Windows\System32\DbxSvc.exe
(DigiOn) C:\Program Files (x86)\DigiOn\DiXiM Digital TV\DMRService.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\IME14\SHARED\IMEDICTUPDATE.EXE
(Sony Corporation) C:\Program Files (x86)\Sony\NFC Proxy Service\bin\NFCProxyService.exe
(NEC Corporation, NEC Personal Products, Ltd.) C:\Windows\SysWOW64\NTMETER.exe
(O2Micro International) C:\Windows\System32\drivers\o2flash.exe
(Texim Corporation.) C:\Program Files (x86)\JustSystems\PersonalShelter\TxVDrvSvc.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(NEC Corporation, NEC Personal Products, Ltd.) C:\Program Files\EcoViewer\ecomonsv.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(AVAST Software s.r.o.) C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe
(Microsoft Corporation) C:\Windows\ehome\mcupdate.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\IME14\SHARED\IMECMNT.EXE
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\Apoint.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\ApMsgFwd.exe
(NEC Corporation, NEC Personal Products, Ltd.) C:\Program Files\NECMFK\necmfk.exe
(NEC Corporation, NEC Personal Products, Ltd.) C:\Program Files\DispSw\DispSw.exe
(NEC Corporation, NEC Personal Products, Ltd.) C:\Program Files\NECBatt\nbSched.exe
(ALPS) C:\Program Files\Apoint2K\Apvfb.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\ApntEx.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint2K\HidFind.exe
(NEC Corporation, NEC Personal Products, Ltd.) C:\Program Files\NPSpeed\NPSpeed.exe
(NEC Corporation, NEC Personal Products, Ltd.) C:\Program Files\EcoViewer\ecoviewerd.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Logicool, Inc.) C:\Program Files\SetPointP\SetPoint.exe
(Intel Corporation) C:\Windows\System32\GfxUI.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvLaunch.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(NEC Corporation / NEC Personal Products, Ltd.) C:\Program Files (x86)\Softnavi\ImgLnch.exe
(Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
(Logicool, Inc.) C:\Program Files\Common Files\Logishrd\KHAL3\KHALMNPR.exe
(NEC Personal Computers,Ltd.) C:\Program Files (x86)\NEC\SmartUpdate\reservesu.exe
(Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
(Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
(Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\IME14\SHARED\IMECMNT.EXE
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\sdclt.exe
(NEC Corporation, NEC Personal Products, Ltd.) C:\Program Files\AVDm\AVDm.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe

==================== Registry (Whitelisted) ====================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [Apoint] => C:\Program Files\Apoint2K\Apoint.exe [280576 2010-03-18] (Alps Electric Co., Ltd.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [10144288 2010-04-06] (Realtek Semiconductor)
HKLM\...\Run: [NECMFK] => C:\Program Files\necmfk\necmfk.exe [154496 2010-04-26] (NEC Corporation, NEC Personal Products, Ltd.)
HKLM\...\Run: [DispSw] => C:\Program Files\DispSw\DispSw.exe [54592 2009-02-27] (NEC Corporation, NEC Personal Products, Ltd.)
HKLM\...\Run: [NECBatt] => C:\Program Files\NECBatt\nbSched.exe [318344 2010-05-07] (NEC Corporation, NEC Personal Products, Ltd.)
HKLM\...\Run: [IME14 JPN Setup] => C:\Program Files\Common Files\Microsoft Shared\IME14\SHARED\IMEKLMG.EXE [110776 2015-10-13] (Microsoft Corporation)
HKLM\...\Run: [AVDM] => C:\Program Files\AVDm\AVDm.exe [824192 2010-06-25] (NEC Corporation, NEC Personal Products, Ltd.)
HKLM\...\Run: [NPSpeed] => C:\Program Files\NPSpeed\NPSpeed.exe [2572680 2010-05-07] (NEC Corporation, NEC Personal Products, Ltd.)
HKLM\...\Run: [ECOViewer] => C:\Program Files\EcoViewer\ecoviewerd.exe [68488 2010-06-23] (NEC Corporation, NEC Personal Products, Ltd.)
HKLM\...\Run: [EvtMgr6] => C:\Program Files\SetPointP\SetPoint.exe [1609296 2010-05-19] (Logicool, Inc.)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [239856 2017-09-02] (AVAST Software)
HKLM-x32\...\Run: [SoftNavi] => C:\Program Files (x86)\Softnavi\ImgLnch.exe [681344 2010-06-08] (NEC Corporation / NEC Personal Products, Ltd.)
HKLM-x32\...\Run: [NUSB3MON] => C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-04-27] (Renesas Electronics Corporation)
HKLM-x32\...\Run: [IME14 JPN Setup] => C:\Program Files (x86)\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXE [81080 2015-10-13] (Microsoft Corporation)
HKLM-x32\...\Run: [SmartUpdate] => C:\Program Files (x86)\NEC\SmartUpdate\reservesu.exe [206920 2011-10-17] (NEC Personal Computers,Ltd.)
HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [3487032 2017-09-06] (Dropbox, Inc.)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-18\...\Run: [Copy] => "C:\Users\Owner\AppData\Roaming\Copy\CopyAgent.exe"
HKU\S-1-5-18\...\Run: [KSS] => "C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan\kss.exe" autorun
HKU\S-1-5-18\...\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [301568 2014-02-07] (Microsoft Corporation)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.3.1
Tcpip\..\Interfaces\{45C25C0A-FE0B-4B70-9CA7-1675D66B3B40}: [DhcpNameServer] 192.168.11.1
Tcpip\..\Interfaces\{B40651D5-ED6B-48DA-8178-36C727167477}: [DhcpNameServer] 192.168.3.1

Internet Explorer:
==================
HKU\S-1-5-21-2412369854-1432032030-2929281642-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yahoo.co.jp/
SearchScopes: HKLM-x32 -> DefaultScope value is missing
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_144\bin\ssv.dll [2017-07-28] (Oracle Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2017-09-02] (AVAST Software)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_144\bin\jp2ssv.dll [2017-07-28] (Oracle Corporation)
BHO-x32: Wondershare Video Converter Ultimate 7.1.0 -> {451C804F-C205-4F03-B48E-537EC94937BF} -> C:\PROGRA~3\WONDER~1\VIDEOC~1\WSBROW~1.DLL => No File
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_144\bin\ssv.dll [2017-07-28] (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2017-09-02] (AVAST Software)
BHO-x32: Microsoft アカウント サインイン ヘルパー -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: No Name -> {B69F34DD-F0F9-42DC-9EDD-957187DA688D} -> No File
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_144\bin\jp2ssv.dll [2017-07-28] (Oracle Corporation)
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} -  No File
Toolbar: HKU\S-1-5-21-2412369854-1432032030-2929281642-1000 -> No Name - {AEF44653-C059-42CB-A5B7-41C640DA4A67} -  No File
DPF: HKLM {AA570693-00E2-4907-B6F1-60A1199B030C} hxxps://juniper.net/dana-cached/sc/JuniperSetupClient64.cab
DPF: HKLM-x32 {F27237D7-93C8-44C2-AC6E-D6057B9A918F} hxxps://juniper.net/dana-cached/sc/JuniperSetupClient.cab
Handler: WSWSVCUchrome - {1CA93FF0-A218-44F1 -  No File

FireFox:
========
FF DefaultProfile: ehcmom1z.default-1398562197452
FF ProfilePath: C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\ehcmom1z.default-1398562197452 [2017-09-13]
FF NewTab: Mozilla\Firefox\Profiles\ehcmom1z.default-1398562197452 -> hxxps://www.amazon.co.jp/gp/bit/amazonserp/ref=bit_bds-p10_serp_ff_jp_display?ie=UTF8&tagbase=bds-p10&tbrId=v1_abb-channel-10_a56c688c_1201_1401_20160724_JP_ff_nt_
FF SearchEngineOrder.1: Mozilla\Firefox\Profiles\ehcmom1z.default-1398562197452 -> Amazon
FF Homepage: Mozilla\Firefox\Profiles\ehcmom1z.default-1398562197452 -> hxxps://www.yahoo.co.jp/
FF Extension: (Google Scholar Button) - C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\ehcmom1z.default-1398562197452\Extensions\button@scholar.google.com.xpi [2016-08-17]
FF Extension: (New Tab Override) - C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\ehcmom1z.default-1398562197452\Extensions\newtaboverride@agenedia.com.xpi [2017-08-26]
FF Extension: (Avast SafePrice) - C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\ehcmom1z.default-1398562197452\Extensions\sp@avast.com.xpi [2017-08-24]
FF Extension: (Avast Online Security) - C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\ehcmom1z.default-1398562197452\Extensions\wrc@avast.com.xpi [2017-08-18]
FF Extension: (Adblock Plus) - C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\ehcmom1z.default-1398562197452\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2017-06-08]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_27_0_0_130.dll [2017-09-12] ()
FF Plugin: @java.com/DTPlugin,version=11.144.2 -> C:\Program Files\Java\jre1.8.0_144\bin\dtplugin\npDeployJava1.dll [2017-07-28] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.144.2 -> C:\Program Files\Java\jre1.8.0_144\bin\plugin2\npjp2.dll [2017-07-28] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_27_0_0_130.dll [2017-09-12] ()
FF Plugin-x32: @java.com/DTPlugin,version=11.144.2 -> C:\Program Files (x86)\Java\jre1.8.0_144\bin\dtplugin\npDeployJava1.dll [2017-07-28] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.144.2 -> C:\Program Files (x86)\Java\jre1.8.0_144\bin\plugin2\npjp2.dll [2017-07-28] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2013-02-05] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-29] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-29] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-08-01] (Adobe Systems Inc.)
FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\itms.js [2017-07-05]

Chrome:
=======
CHR DefaultProfile: Default
CHR HomePage: Default -> hxxp://www.google.com/
CHR StartupUrls: Default -> "hxxp://www.yahoo.co.jp/"
CHR Profile: C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default [2017-09-11]
CHR Extension: (Google ドキュメント) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-03-28]
CHR Extension: (Google ドライブ) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-26]
CHR Extension: (YouTube) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-10-26]
CHR Extension: (Google Search) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-26]
CHR Extension: (Avast SafePrice) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck [2017-09-11]
CHR Extension: (Google オフライン ドキュメント) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-04-24]
CHR Extension: (Skype) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2017-08-20]
CHR Extension: (Chrome ウェブストア決済) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-09-11]
CHR Extension: (Gmail) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-03-28]
CHR Extension: (Chrome Media Router) - C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-08-20]
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - hxxps://clients2.google.com/service/update2/crx

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2017-04-03] (Apple Inc.)
R3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [7452288 2017-09-02] (AVAST Software s.r.o.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [275208 2017-09-02] (AVAST Software)
S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-03-15] (Dropbox, Inc.)
S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-03-15] (Dropbox, Inc.)
R2 DbxSvc; C:\Windows\system32\DbxSvc.exe [49992 2017-09-06] (Dropbox, Inc.)
S3 DiXiM Digital TV Service; C:\Program Files (x86)\DigiOn\DiXiM Digital TV\Service\DoDMCService.exe [44368 2010-03-27] (DigiOn, Inc.)
R2 DMRService; C:\Program Files (x86)\DigiOn\DiXiM Digital TV\DMRService.exe [67920 2010-05-25] (DigiOn)
R2 ecomonsv; C:\Program Files\EcoViewer\ecomonsv.exe [158088 2010-06-23] (NEC Corporation, NEC Personal Products, Ltd.)
R2 ImeDictUpdateService; C:\Program Files\Common Files\Microsoft Shared\IME14\SHARED\IMEDICTUPDATE.EXE [83312 2010-10-20] (Microsoft Corporation)
R2 NFCProxyService; C:\Program Files (x86)\Sony\NFC Proxy Service\bin\NFCProxyService.exe [474624 2012-09-19] (Sony Corporation) [File not signed]
R2 NT Meter; C:\Windows\SYSWOW64\NTMETER.exe [106936 2009-06-12] (NEC Corporation, NEC Personal Products, Ltd.)
R2 TxVDrvSvc; C:\Program Files (x86)\JustSystems\PersonalShelter\TxVDrvSvc.exe [55832 2008-10-28] (Texim Corporation.)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
R2 ホームネットワークサーバー powered by DiXiM; C:\Program Files (x86)\DigiOn\DiXiM Media Server\dms_sync_svc.exe [107856 2010-10-04] ()

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R1 A2DDA; C:\EEK\RUN\a2ddax64.sys [26176 2014-03-07] (Emsisoft GmbH)
R1 aswbidsdriver; C:\Windows\system32\drivers\aswbidsdrivera.sys [320528 2017-09-02] (AVAST Software s.r.o.)
R0 aswbidsh; C:\Windows\system32\drivers\aswbidsha.sys [198976 2017-09-02] (AVAST Software s.r.o.)
R0 aswblog; C:\Windows\system32\drivers\aswbloga.sys [343296 2017-09-02] (AVAST Software s.r.o.)
R0 aswbuniv; C:\Windows\system32\drivers\aswbuniva.sys [57736 2017-09-02] (AVAST Software s.r.o.)
S3 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [47016 2017-09-02] (AVAST Software)
R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [41832 2017-09-02] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [147784 2017-09-02] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [110376 2017-09-02] (AVAST Software)
R0 aswRvrt; C:\Windows\system32\drivers\aswRvrt.sys [84416 2017-09-02] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1016384 2017-09-02] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [590880 2017-09-02] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [199312 2017-09-02] (AVAST Software)
R0 aswVmm; C:\Windows\system32\drivers\aswVmm.sys [361336 2017-09-02] (AVAST Software)
S3 cleanhlp; C:\EEK\Run\cleanhlp64.sys [57024 2014-03-07] (Emsisoft GmbH)
R1 DiximDd; C:\Windows\System32\DRIVERS\diximdd.sys [18704 2009-07-08] (Windows ® Win 7 DDK provider)
R0 flyfs; C:\Windows\System32\DRIVERS\flyfs.sys [54408 2010-03-03] (NEC Corporation, NEC Personal Products)
R1 MFKGTKEY; C:\Windows\system32\drivers\mfkgtkey.sys [20480 2008-12-09] (©NEC Corporation, NEC Personal Products, Ltd.)
R3 necbatt; C:\Windows\system32\drivers\necbatt.sys [11776 2009-07-22] (NEC Corporation, NEC Personal Products, Ltd.)
R3 Nececfilter; C:\Windows\system32\drivers\nececfil.sys [13312 2009-07-15] (NEC Corporation, NEC Personal Products, Ltd.)
R3 O2SDGRDR; C:\Windows\system32\drivers\o2sdgx64.sys [51048 2010-04-08] (O2Micro )
R3 Ps2Led; C:\Windows\system32\drivers\Ps2Led.sys [11776 2008-12-09] (NEC Corporation, NEC Personal Products, Ltd.)
R1 Ps2LedIF; C:\Windows\system32\drivers\ps2ledif.sys [9728 2008-12-11] (NEC Corporation, NEC Personal Products, Ltd.)
U5 regi; C:\Windows\System32\Drivers\regi.sys [14112 2007-04-17] (InterVideo)
R3 sonyfelicaportm; C:\Windows\System32\Drivers\sonyfelicaportm.sys [42048 2012-03-29] (Sony Corporation)
R3 sonyrcs956c; C:\Windows\System32\Drivers\sonyrcs956c.sys [64232 2010-08-26] (Sony Corporation)
R3 sonyrcs956f; C:\Windows\System32\Drivers\sonyrcs956f.sys [275304 2012-05-19] (Sony Corporation)
R1 TIMERSET; C:\Windows\System32\drivers\timerset.sys [13384 2009-09-19] (NEC Corporation, NEC Personal Products, Ltd.)
R1 TxVDrv; C:\Windows\System32\Drivers\TxVDrv.sys [36640 2007-01-15] (Texim Corporation)
S3 dbx; system32\DRIVERS\dbx.sys [X]
S3 NPF; system32\drivers\NPF.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-09-13 19:39 - 2017-09-13 19:42 - 000021451 _____ C:\Users\Owner\Desktop\FRST.txt
2017-09-13 19:39 - 2017-09-13 19:39 - 000000000 ____D C:\Users\Owner\Desktop\FRST-OlderVersion
2017-09-13 19:38 - 2017-09-13 19:39 - 000000000 ____D C:\FRST
2017-09-13 19:38 - 2017-09-13 19:38 - 000000000 ____D C:\ProgramData\SWCUTemp
2017-09-13 07:01 - 2017-08-20 00:28 - 000197120 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll
2017-09-13 07:01 - 2017-08-20 00:10 - 000180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll
2017-09-13 07:01 - 2017-08-17 00:29 - 000806912 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll
2017-09-13 07:01 - 2017-08-17 00:10 - 000629760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll
2017-09-13 07:01 - 2017-08-16 23:57 - 003224576 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2017-09-13 07:01 - 2017-08-16 10:10 - 000395976 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2017-09-13 07:01 - 2017-08-16 09:25 - 000347336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2017-09-13 07:01 - 2017-08-16 00:29 - 014182400 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2017-09-13 07:01 - 2017-08-16 00:29 - 001867264 _____ (Microsoft Corporation) C:\Windows\system32\ExplorerFrame.dll
2017-09-13 07:01 - 2017-08-16 00:10 - 012880896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2017-09-13 07:01 - 2017-08-16 00:10 - 001499648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ExplorerFrame.dll
2017-09-13 07:01 - 2017-08-15 23:06 - 015260160 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2017-09-13 07:01 - 2017-08-15 23:01 - 000416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2017-09-13 07:01 - 2017-08-15 23:01 - 000279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2017-09-13 07:01 - 2017-08-15 23:01 - 000076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2017-09-13 07:01 - 2017-08-15 22:58 - 013673984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2017-09-13 07:01 - 2017-08-15 02:35 - 003203584 _____ (Microsoft Corporation) C:\Windows\system32\mmcndmgr.dll
2017-09-13 07:01 - 2017-08-15 02:35 - 002150912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mmcndmgr.dll
2017-09-13 07:01 - 2017-08-15 02:35 - 000355328 _____ (Microsoft Corporation) C:\Windows\system32\mmcbase.dll
2017-09-13 07:01 - 2017-08-15 02:35 - 000303104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mmcbase.dll
2017-09-13 07:01 - 2017-08-15 02:35 - 000172544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cic.dll
2017-09-13 07:01 - 2017-08-15 02:35 - 000131072 _____ (Microsoft Corporation) C:\Windows\system32\mmcshext.dll
2017-09-13 07:01 - 2017-08-15 02:35 - 000128512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mmcshext.dll
2017-09-13 07:01 - 2017-08-15 02:34 - 000211968 _____ (Microsoft Corporation) C:\Windows\system32\cic.dll
2017-09-13 07:01 - 2017-08-14 06:37 - 002144256 _____ (Microsoft Corporation) C:\Windows\system32\mmc.exe
2017-09-13 07:01 - 2017-08-14 06:30 - 001401344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mmc.exe
2017-09-13 07:01 - 2017-08-14 03:58 - 025730560 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2017-09-13 07:01 - 2017-08-14 02:24 - 002724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2017-09-13 07:01 - 2017-08-14 02:24 - 000004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2017-09-13 07:01 - 2017-08-14 02:06 - 000066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2017-09-13 07:01 - 2017-08-14 02:05 - 000576512 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2017-09-13 07:01 - 2017-08-14 02:05 - 000417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2017-09-13 07:01 - 2017-08-14 02:05 - 000088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2017-09-13 07:01 - 2017-08-14 02:05 - 000048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2017-09-13 07:01 - 2017-08-14 02:04 - 002899968 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2017-09-13 07:01 - 2017-08-14 01:56 - 000054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2017-09-13 07:01 - 2017-08-14 01:55 - 000034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2017-09-13 07:01 - 2017-08-14 01:54 - 020269056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2017-09-13 07:01 - 2017-08-14 01:52 - 000615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2017-09-13 07:01 - 2017-08-14 01:51 - 005981696 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2017-09-13 07:01 - 2017-08-14 01:51 - 000144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2017-09-13 07:01 - 2017-08-14 01:51 - 000116224 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2017-09-13 07:01 - 2017-08-14 01:50 - 000817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2017-09-13 07:01 - 2017-08-14 01:50 - 000814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2017-09-13 07:01 - 2017-08-14 01:46 - 002724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2017-09-13 07:01 - 2017-08-14 01:41 - 000968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2017-09-13 07:01 - 2017-08-14 01:38 - 000489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2017-09-13 07:01 - 2017-08-14 01:30 - 000062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2017-09-13 07:01 - 2017-08-14 01:29 - 000499200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2017-09-13 07:01 - 2017-08-14 01:29 - 000341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2017-09-13 07:01 - 2017-08-14 01:29 - 000087552 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2017-09-13 07:01 - 2017-08-14 01:29 - 000077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2017-09-13 07:01 - 2017-08-14 01:29 - 000047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2017-09-13 07:01 - 2017-08-14 01:28 - 000064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2017-09-13 07:01 - 2017-08-14 01:27 - 000107520 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2017-09-13 07:01 - 2017-08-14 01:24 - 002291200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2017-09-13 07:01 - 2017-08-14 01:24 - 000199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2017-09-13 07:01 - 2017-08-14 01:23 - 000092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2017-09-13 07:01 - 2017-08-14 01:22 - 000047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2017-09-13 07:01 - 2017-08-14 01:21 - 000030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2017-09-13 07:01 - 2017-08-14 01:20 - 000315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2017-09-13 07:01 - 2017-08-14 01:19 - 000476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2017-09-13 07:01 - 2017-08-14 01:18 - 000152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2017-09-13 07:01 - 2017-08-14 01:17 - 000663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2017-09-13 07:01 - 2017-08-14 01:17 - 000620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2017-09-13 07:01 - 2017-08-14 01:17 - 000115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2017-09-13 07:01 - 2017-08-14 01:07 - 000262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2017-09-13 07:01 - 2017-08-14 01:04 - 000807936 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2017-09-13 07:01 - 2017-08-14 01:04 - 000726528 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2017-09-13 07:01 - 2017-08-14 01:02 - 001359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2017-09-13 07:01 - 2017-08-14 01:01 - 002134528 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2017-09-13 07:01 - 2017-08-14 01:01 - 000073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2017-09-13 07:01 - 2017-08-14 01:01 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2017-09-13 07:01 - 2017-08-14 01:00 - 000091136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2017-09-13 07:01 - 2017-08-14 00:57 - 000168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2017-09-13 07:01 - 2017-08-14 00:53 - 000130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2017-09-13 07:01 - 2017-08-14 00:48 - 004547072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2017-09-13 07:01 - 2017-08-14 00:46 - 000230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2017-09-13 07:01 - 2017-08-14 00:44 - 000694784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2017-09-13 07:01 - 2017-08-14 00:43 - 002058752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2017-09-13 07:01 - 2017-08-14 00:43 - 001155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2017-09-13 07:01 - 2017-08-14 00:40 - 003241472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2017-09-13 07:01 - 2017-08-14 00:27 - 001544704 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2017-09-13 07:01 - 2017-08-14 00:18 - 000800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2017-09-13 07:01 - 2017-08-14 00:17 - 002767872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2017-09-13 07:01 - 2017-08-14 00:14 - 000710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2017-09-13 07:01 - 2017-08-14 00:13 - 001314816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2017-09-13 07:01 - 2017-08-11 15:42 - 000631176 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2017-09-13 07:01 - 2017-08-11 15:38 - 005547752 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2017-09-13 07:01 - 2017-08-11 15:38 - 000706792 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2017-09-13 07:01 - 2017-08-11 15:38 - 000154856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2017-09-13 07:01 - 2017-08-11 15:38 - 000095464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2017-09-13 07:01 - 2017-08-11 15:36 - 001732864 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2017-09-13 07:01 - 2017-08-11 15:35 - 002065408 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll
2017-09-13 07:01 - 2017-08-11 15:35 - 001212928 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2017-09-13 07:01 - 2017-08-11 15:35 - 000757248 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll
2017-09-13 07:01 - 2017-08-11 15:35 - 000512000 _____ (Microsoft Corporation) C:\Windows\system32\rpcss.dll
2017-09-13 07:01 - 2017-08-11 15:35 - 000503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2017-09-13 07:01 - 2017-08-11 15:35 - 000362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2017-09-13 07:01 - 2017-08-11 15:35 - 000346112 _____ (Microsoft Corporation) C:\Windows\system32\ntprint.dll
2017-09-13 07:01 - 2017-08-11 15:35 - 000345600 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2017-09-13 07:01 - 2017-08-11 15:35 - 000313856 _____ (Microsoft Corporation) C:\Windows\system32\Wldap32.dll
2017-09-13 07:01 - 2017-08-11 15:35 - 000243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2017-09-13 07:01 - 2017-08-11 15:35 - 000215552 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2017-09-13 07:01 - 2017-08-11 15:35 - 000210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2017-09-13 07:01 - 2017-08-11 15:35 - 000190464 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll
2017-09-13 07:01 - 2017-08-11 15:35 - 000135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2017-09-13 07:01 - 2017-08-11 15:35 - 000086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2017-09-13 07:01 - 2017-08-11 15:35 - 000028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2017-09-13 07:01 - 2017-08-11 15:35 - 000028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2017-09-13 07:01 - 2017-08-11 15:35 - 000026112 _____ (Microsoft Corporation) C:\Windows\system32\nsisvc.dll
2017-09-13 07:01 - 2017-08-11 15:35 - 000025600 _____ (Microsoft Corporation) C:\Windows\system32\winnsi.dll
2017-09-13 07:01 - 2017-08-11 15:35 - 000013312 _____ (Microsoft Corporation) C:\Windows\system32\nsi.dll
2017-09-13 07:01 - 2017-08-11 15:34 - 001460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2017-09-13 07:01 - 2017-08-11 15:34 - 001163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2017-09-13 07:01 - 2017-08-11 15:34 - 000971776 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll
2017-09-13 07:01 - 2017-08-11 15:34 - 000880640 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2017-09-13 07:01 - 2017-08-11 15:34 - 000731648 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2017-09-13 07:01 - 2017-08-11 15:34 - 000463872 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2017-09-13 07:01 - 2017-08-11 15:34 - 000419840 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2017-09-13 07:01 - 2017-08-11 15:34 - 000316928 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2017-09-13 07:01 - 2017-08-11 15:34 - 000312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2017-09-13 07:01 - 2017-08-11 15:34 - 000166400 _____ (Microsoft Corporation) C:\Windows\system32\inetpp.dll
2017-09-13 07:01 - 2017-08-11 15:34 - 000123904 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll
2017-09-13 07:01 - 2017-08-11 15:34 - 000044032 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2017-09-13 07:01 - 2017-08-11 15:34 - 000043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2017-09-13 07:01 - 2017-08-11 15:34 - 000022528 _____ (Microsoft Corporation) C:\Windows\system32\inetppui.dll
2017-09-13 07:01 - 2017-08-11 15:24 - 004001000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2017-09-13 07:01 - 2017-08-11 15:24 - 003945704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2017-09-13 07:01 - 2017-08-11 15:21 - 001314112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2017-09-13 07:01 - 2017-08-11 15:20 - 000061952 _____ (Microsoft Corporation) C:\Windows\system32\ntprint.exe
2017-09-13 07:01 - 2017-08-11 15:19 - 001417728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll
2017-09-13 07:01 - 2017-08-11 15:19 - 000666112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2017-09-13 07:01 - 2017-08-11 15:19 - 000644096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2017-09-13 07:01 - 2017-08-11 15:19 - 000554496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2017-09-13 07:01 - 2017-08-11 15:19 - 000497664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll
2017-09-13 07:01 - 2017-08-11 15:19 - 000342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
2017-09-13 07:01 - 2017-08-11 15:19 - 000299008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntprint.dll
2017-09-13 07:01 - 2017-08-11 15:19 - 000275456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2017-09-13 07:01 - 2017-08-11 15:19 - 000271360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Wldap32.dll
2017-09-13 07:01 - 2017-08-11 15:19 - 000261120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2017-09-13 07:01 - 2017-08-11 15:19 - 000254464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2017-09-13 07:01 - 2017-08-11 15:19 - 000223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2017-09-13 07:01 - 2017-08-11 15:19 - 000172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2017-09-13 07:01 - 2017-08-11 15:19 - 000096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2017-09-13 07:01 - 2017-08-11 15:19 - 000065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2017-09-13 07:01 - 2017-08-11 15:19 - 000016384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winnsi.dll
2017-09-13 07:01 - 2017-08-11 15:19 - 000008704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nsi.dll
2017-09-13 07:01 - 2017-08-11 15:12 - 000025088 _____ (Microsoft Corporation) C:\Windows\system32\netbtugc.exe
2017-09-13 07:01 - 2017-08-11 15:09 - 000061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntprint.exe
2017-09-13 07:01 - 2017-08-11 15:07 - 000062464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2017-09-13 07:01 - 2017-08-11 15:03 - 000338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2017-09-13 07:01 - 2017-08-11 15:03 - 000026624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netbtugc.exe
2017-09-13 07:01 - 2017-08-11 15:00 - 000262656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netbt.sys
2017-09-13 07:01 - 2017-08-11 15:00 - 000159744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2017-09-13 07:01 - 2017-08-11 14:59 - 000460800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys
2017-09-13 07:01 - 2017-08-11 14:59 - 000405504 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys
2017-09-13 07:01 - 2017-08-11 14:59 - 000291328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2017-09-13 07:01 - 2017-08-11 14:59 - 000168448 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys
2017-09-13 07:01 - 2017-08-11 14:59 - 000129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2017-09-13 07:01 - 2017-08-11 14:58 - 000112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2017-09-13 07:01 - 2017-08-11 14:58 - 000030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2017-09-13 07:01 - 2017-08-11 14:58 - 000026112 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\nsiproxy.sys
2017-09-13 07:01 - 2017-07-08 00:29 - 001143296 _____ (Microsoft Corporation) C:\Windows\system32\DXPTaskRingtone.dll
2017-09-13 07:01 - 2017-07-08 00:10 - 000973312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DXPTaskRingtone.dll
2017-09-13 07:00 - 2017-08-11 15:35 - 000063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2017-09-13 07:00 - 2017-08-11 15:35 - 000050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2017-09-13 07:00 - 2017-08-11 15:35 - 000026112 _____ (Microsoft Corporation) C:\Windows\system32\oleres.dll
2017-09-13 07:00 - 2017-08-11 15:35 - 000016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2017-09-13 07:00 - 2017-08-11 15:35 - 000013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2017-09-13 07:00 - 2017-08-11 15:34 - 000690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2017-09-13 07:00 - 2017-08-11 15:34 - 000146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2017-09-13 07:00 - 2017-08-11 15:34 - 000060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2017-09-13 07:00 - 2017-08-11 15:34 - 000059904 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2017-09-13 07:00 - 2017-08-11 15:34 - 000034816 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2017-09-13 07:00 - 2017-08-11 15:34 - 000022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2017-09-13 07:00 - 2017-08-11 15:34 - 000008704 _____ (Microsoft Corporation) C:\Windows\system32\comcat.dll
2017-09-13 07:00 - 2017-08-11 15:34 - 000006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2017-09-13 07:00 - 2017-08-11 15:34 - 000006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2017-09-13 07:00 - 2017-08-11 15:34 - 000005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2017-09-13 07:00 - 2017-08-11 15:34 - 000004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2017-09-13 07:00 - 2017-08-11 15:34 - 000004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2017-09-13 07:00 - 2017-08-11 15:34 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2017-09-13 07:00 - 2017-08-11 15:34 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2017-09-13 07:00 - 2017-08-11 15:34 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2017-09-13 07:00 - 2017-08-11 15:34 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2017-09-13 07:00 - 2017-08-11 15:34 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2017-09-13 07:00 - 2017-08-11 15:34 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2017-09-13 07:00 - 2017-08-11 15:34 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2017-09-13 07:00 - 2017-08-11 15:34 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2017-09-13 07:00 - 2017-08-11 15:34 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2017-09-13 07:00 - 2017-08-11 15:34 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2017-09-13 07:00 - 2017-08-11 15:34 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2017-09-13 07:00 - 2017-08-11 15:34 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2017-09-13 07:00 - 2017-08-11 15:34 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2017-09-13 07:00 - 2017-08-11 15:34 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2017-09-13 07:00 - 2017-08-11 15:34 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2017-09-13 07:00 - 2017-08-11 15:34 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2017-09-13 07:00 - 2017-08-11 15:34 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2017-09-13 07:00 - 2017-08-11 15:34 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2017-09-13 07:00 - 2017-08-11 15:34 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2017-09-13 07:00 - 2017-08-11 15:34 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2017-09-13 07:00 - 2017-08-11 15:34 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2017-09-13 07:00 - 2017-08-11 15:34 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2017-09-13 07:00 - 2017-08-11 15:34 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2017-09-13 07:00 - 2017-08-11 15:34 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2017-09-13 07:00 - 2017-08-11 15:20 - 000048640 _____ (Microsoft Corporation) C:\Windows\system32\wpnpinst.exe
2017-09-13 07:00 - 2017-08-11 15:19 - 001114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2017-09-13 07:00 - 2017-08-11 15:19 - 000690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2017-09-13 07:00 - 2017-08-11 15:19 - 000146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2017-09-13 07:00 - 2017-08-11 15:19 - 000141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll
2017-09-13 07:00 - 2017-08-11 15:19 - 000082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcrypt.dll
2017-09-13 07:00 - 2017-08-11 15:19 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2017-09-13 07:00 - 2017-08-11 15:19 - 000050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll
2017-09-13 07:00 - 2017-08-11 15:19 - 000043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2017-09-13 07:00 - 2017-08-11 15:19 - 000026112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleres.dll
2017-09-13 07:00 - 2017-08-11 15:19 - 000022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2017-09-13 07:00 - 2017-08-11 15:19 - 000017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2017-09-13 07:00 - 2017-08-11 15:19 - 000006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2017-09-13 07:00 - 2017-08-11 15:19 - 000005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2017-09-13 07:00 - 2017-08-11 15:19 - 000005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2017-09-13 07:00 - 2017-08-11 15:19 - 000004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2017-09-13 07:00 - 2017-08-11 15:19 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2017-09-13 07:00 - 2017-08-11 15:19 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2017-09-13 07:00 - 2017-08-11 15:19 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2017-09-13 07:00 - 2017-08-11 15:19 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2017-09-13 07:00 - 2017-08-11 15:19 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2017-09-13 07:00 - 2017-08-11 15:19 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2017-09-13 07:00 - 2017-08-11 15:19 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2017-09-13 07:00 - 2017-08-11 15:19 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2017-09-13 07:00 - 2017-08-11 15:19 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2017-09-13 07:00 - 2017-08-11 15:19 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2017-09-13 07:00 - 2017-08-11 15:19 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2017-09-13 07:00 - 2017-08-11 15:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2017-09-13 07:00 - 2017-08-11 15:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2017-09-13 07:00 - 2017-08-11 15:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2017-09-13 07:00 - 2017-08-11 15:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2017-09-13 07:00 - 2017-08-11 15:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2017-09-13 07:00 - 2017-08-11 15:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2017-09-13 07:00 - 2017-08-11 15:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2017-09-13 07:00 - 2017-08-11 15:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2017-09-13 07:00 - 2017-08-11 15:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2017-09-13 07:00 - 2017-08-11 15:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2017-09-13 07:00 - 2017-08-11 15:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2017-09-13 07:00 - 2017-08-11 15:07 - 000148480 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2017-09-13 07:00 - 2017-08-11 15:07 - 000017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2017-09-13 07:00 - 2017-08-11 15:06 - 000064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2017-09-13 07:00 - 2017-08-11 15:02 - 000296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2017-09-13 07:00 - 2017-08-11 15:01 - 000007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comcat.dll
2017-09-13 07:00 - 2017-08-11 15:00 - 000050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2017-09-13 07:00 - 2017-08-11 14:56 - 000025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2017-09-13 07:00 - 2017-08-11 14:56 - 000014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2017-09-13 07:00 - 2017-08-11 14:56 - 000007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2017-09-13 07:00 - 2017-08-11 14:56 - 000002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2017-09-13 07:00 - 2017-08-11 14:55 - 000036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
2017-09-13 07:00 - 2017-08-11 14:55 - 000006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2017-09-13 07:00 - 2017-08-11 14:55 - 000004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2017-09-13 07:00 - 2017-08-11 14:55 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2017-09-13 07:00 - 2017-08-11 14:55 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2017-09-12 20:46 - 2017-09-13 19:39 - 002397184 _____ (Farbar) C:\Users\Owner\Desktop\FRST64.exe
2017-09-11 20:28 - 2017-09-11 20:28 - 000000000 ____D C:\Users\Owner\Desktop\V-Check scores 2014
2017-09-11 20:27 - 2017-09-11 20:27 - 000000000 ____D C:\Users\Owner\Desktop\temp pics
2017-09-10 15:50 - 2017-09-10 15:50 - 001032185 _____ C:\Users\Owner\Downloads\23.1tlt.pdf
2017-09-10 15:48 - 2017-09-10 15:48 - 001348271 _____ C:\Users\Owner\Downloads\888.pdf
2017-09-10 15:47 - 2017-09-10 15:47 - 000213215 _____ C:\Users\Owner\Downloads\EJ1099400.pdf
2017-09-10 10:20 - 2017-09-10 10:20 - 008182736 _____ (Malwarebytes) C:\Users\Owner\Downloads\AdwCleaner.exe
2017-09-09 17:07 - 2017-09-09 17:07 - 000383177 _____ C:\Users\Owner\Downloads\Project Work in the Japanese University Classroom _ JALT Publications.pdf
2017-09-09 17:05 - 2017-09-09 17:05 - 001634966 _____ C:\Users\Owner\Downloads\15 projectworkforselectfaculties.pdf
2017-09-09 17:04 - 2017-09-09 17:04 - 000953678 _____ C:\Users\Owner\Downloads\30 ProjectworkHokkaido.pdf
2017-09-09 16:04 - 2017-09-09 19:47 - 000655783 _____ C:\Users\Owner\Downloads\23.3tlt.pdf
2017-09-09 15:53 - 2017-09-09 15:53 - 002384723 _____ C:\Users\Owner\Downloads\March_2008_EBook.pdf
2017-09-09 07:43 - 2017-09-09 07:43 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox
2017-09-06 19:43 - 2017-09-07 19:58 - 000000000 ____D C:\Users\Owner\Desktop\Sept newsletter
2017-09-06 19:29 - 2017-09-06 19:29 - 000045672 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-dev.sys
2017-09-06 19:29 - 2017-09-06 19:29 - 000045640 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-stable.sys
2017-09-06 19:29 - 2017-09-06 19:29 - 000045640 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-canary.sys
2017-09-04 23:08 - 2017-09-04 23:08 - 000558352 _____ C:\Users\Owner\Downloads\The KJ Method, A Technique for Analyzing Dada Derived from Japanese Ethnology.pdf
2017-09-04 23:06 - 2017-09-04 23:06 - 000393831 _____ C:\Users\Owner\Downloads\403.pdf
2017-09-04 22:14 - 2017-09-04 22:14 - 000826897 _____ C:\Users\Owner\Downloads\nistspecialpublication800-30r1.pdf
2017-09-04 21:20 - 2017-09-04 21:20 - 001154870 _____ C:\Users\Owner\Downloads\BRAIN CT 2017 Flyer.pdf
2017-09-04 21:19 - 2017-09-04 21:19 - 000984205 _____ C:\Users\Owner\Downloads\August 2017.pdf
2017-09-03 21:47 - 2017-09-03 21:47 - 000143972 _____ C:\Users\Owner\Downloads\first-page-pdf.pdf
2017-09-03 21:44 - 2017-09-03 21:44 - 000316905 _____ C:\Users\Owner\Downloads\Hinds-Neeley-Cramton-Language-2013.pdf
2017-09-03 21:41 - 2017-09-03 21:41 - 008895529 _____ C:\Users\Owner\Downloads\management.pdf
2017-09-03 20:21 - 2017-09-03 20:21 - 000001722 _____ C:\Users\Public\Desktop\iTunes.lnk
2017-09-03 20:21 - 2017-09-03 20:21 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2017-09-03 20:19 - 2017-09-03 20:21 - 000000000 ____D C:\Program Files\iTunes
2017-09-03 20:19 - 2017-09-03 20:19 - 000000000 ____D C:\Program Files\iPod
2017-09-03 13:51 - 2017-09-03 13:51 - 000181297 _____ C:\Users\Owner\Downloads\2009_04.pdf
2017-09-03 13:35 - 2017-09-03 13:35 - 001480750 _____ C:\Users\Owner\Downloads\pansig2014handbook.pdf
2017-09-03 13:34 - 2017-09-03 13:34 - 006172645 _____ C:\Users\Owner\Downloads\gile-newsletter-89-nov.pdf
2017-09-03 11:45 - 2017-09-03 11:45 - 000277509 _____ C:\Users\Owner\Downloads\Saeko Ujiie Bz English in Japan.edited.pdf
2017-09-03 10:47 - 2017-09-03 10:48 - 007886801 _____ C:\Users\Owner\Downloads\The Cow That Stole Christmas_ Framing the First U.S. Mad Cow Cris.pdf
2017-09-03 10:42 - 2017-09-03 10:42 - 000038589 _____ C:\Users\Owner\Downloads\27_POULSEN.pdf
2017-09-03 10:39 - 2017-09-03 10:39 - 000156024 _____ C:\Users\Owner\Downloads\Framing of Mad Cow Media Coverage.pdf
2017-09-02 21:40 - 2017-09-02 21:40 - 000158330 _____ C:\Users\Owner\Downloads\Margerum_JPER.pdf
2017-09-02 21:38 - 2017-09-02 21:38 - 001849697 _____ C:\Users\Owner\Downloads\ED287636.pdf
2017-09-02 20:46 - 2017-09-02 20:46 - 000150790 _____ C:\Users\Owner\Downloads\2005-4-07.pdf
2017-09-02 17:12 - 2017-09-02 17:12 - 000249535 _____ C:\Users\Owner\Downloads\iw7.pdf
2017-09-02 17:06 - 2017-09-02 17:06 - 000210681 _____ C:\Users\Owner\Downloads\p5259.pdf
2017-09-02 17:04 - 2017-09-02 17:12 - 000000000 ____D C:\Users\Owner\Desktop\ITIN renewal
2017-09-02 16:53 - 2017-09-02 16:53 - 003877351 _____ C:\Users\Owner\Downloads\p1915.pdf
2017-09-02 16:51 - 2017-09-02 16:51 - 000093880 _____ C:\Users\Owner\Downloads\fw7.pdf
2017-09-02 14:52 - 2017-09-02 14:52 - 000401488 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2017-08-27 22:07 - 2017-08-27 22:07 - 000159216 _____ C:\Users\Owner\Downloads\SSRN-id837064.pdf
2017-08-27 13:45 - 2017-08-27 13:45 - 000000000 _____ C:\Users\Owner\Downloads\10.1.1.824.4278.pdf
2017-08-27 13:04 - 2017-08-27 13:04 - 000067917 _____ C:\Users\Owner\Downloads\HA1000622.pdf
2017-08-27 11:36 - 2017-08-27 11:36 - 000560118 _____ C:\Users\Owner\Downloads\J-243_Satou.pdf
2017-08-27 11:31 - 2017-08-27 11:31 - 000713429 _____ C:\Users\Owner\Downloads\03mbp5.pdf
2017-08-27 11:30 - 2017-08-27 11:30 - 000307526 _____ C:\Users\Owner\Downloads\07mbp12.pdf
2017-08-27 11:05 - 2017-08-27 11:05 - 000404792 _____ C:\Users\Owner\Downloads\livestock-poultry-ma-03-01-2002.pdf
2017-08-27 11:04 - 2017-08-27 11:04 - 000144721 _____ C:\Users\Owner\Downloads\Econ55.PDF
2017-08-26 21:53 - 2017-08-26 21:53 - 000753652 _____ C:\Users\Owner\Downloads\Arnstein_ladder_1969.pdf
2017-08-26 21:51 - 2017-08-26 21:51 - 000628612 _____ C:\Users\Owner\Downloads\ESCALERA_ARNSTEIN_1969.pdf
2017-08-26 12:02 - 2016-08-23 04:20 - 000332512 _____ (Trend Micro Inc.) C:\Windows\system32\Drivers\tmcomm.sys
2017-08-26 08:58 - 2017-08-26 19:59 - 000000000 ____D C:\Program Files\Mozilla Firefox
2017-08-25 22:07 - 2017-08-25 22:07 - 001244640 _____ C:\Users\Owner\Downloads\IRGC_WP_No_1_Risk_Governance__reprinted_version_.pdf
2017-08-25 21:56 - 2017-08-25 22:12 - 004094076 _____ C:\Users\Owner\Downloads\Risk_Communication_and_Natural_Hazards.pdf
2017-08-25 20:13 - 2017-08-25 20:13 - 000312235 _____ C:\Users\Owner\Downloads\Speed-reading-whole.pdf
2017-08-25 07:45 - 2017-08-25 07:47 - 000000000 ____D C:\7a4f2bbe8f78417885e61a
2017-08-24 07:48 - 2017-08-24 07:50 - 000000000 ____D C:\6b9b97e709964268857beb54
2017-08-23 07:40 - 2017-08-23 07:41 - 000000000 ____D C:\227a38ce7babefb1feb4e4
2017-08-23 01:55 - 2017-09-06 19:29 - 000049992 _____ (Dropbox, Inc.) C:\Windows\system32\DbxSvc.exe

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-09-13 19:42 - 2009-07-14 13:45 - 000015568 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2017-09-13 19:42 - 2009-07-14 13:45 - 000015568 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2017-09-13 19:39 - 2014-02-08 16:56 - 000000000 ____D C:\ProgramData\smartupdate
2017-09-13 19:35 - 2009-07-14 14:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2017-09-13 19:35 - 2009-07-14 13:45 - 000536360 _____ C:\Windows\system32\FNTCACHE.DAT
2017-09-13 08:00 - 2014-02-06 13:52 - 000000000 ____D C:\Windows\system32\MRT
2017-09-13 07:54 - 2014-02-06 13:52 - 138202976 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2017-09-13 07:53 - 2009-07-14 11:34 - 000000478 _____ C:\Windows\win.ini
2017-09-13 07:47 - 2014-02-07 15:42 - 001292534 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2017-09-13 07:47 - 2009-07-14 19:49 - 000411314 _____ C:\Windows\system32\perfh011.dat
2017-09-13 07:47 - 2009-07-14 19:49 - 000122328 _____ C:\Windows\system32\perfc011.dat
2017-09-13 07:47 - 2009-07-14 14:13 - 001292534 _____ C:\Windows\system32\PerfStringBackup.INI
2017-09-13 07:47 - 2009-07-14 12:20 - 000000000 ____D C:\Windows\inf
2017-09-12 20:48 - 2014-02-08 17:15 - 000803328 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2017-09-12 20:48 - 2014-02-08 17:15 - 000144896 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2017-09-12 20:48 - 2014-02-08 17:15 - 000004108 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2017-09-12 20:48 - 2014-02-08 17:15 - 000000000 ____D C:\Windows\system32\Macromed
2017-09-12 20:48 - 2010-09-21 09:13 - 000000000 ____D C:\Windows\SysWOW64\Macromed
2017-09-10 23:10 - 2016-03-15 05:17 - 000000684 _____ C:\Windows\Tasks\DropboxUpdateTaskMachineUA.job
2017-09-10 23:10 - 2016-03-15 05:17 - 000000680 _____ C:\Windows\Tasks\DropboxUpdateTaskMachineCore.job
2017-09-10 23:08 - 2017-07-09 11:31 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free Windows Cleanup Tool
2017-09-10 23:08 - 2017-07-09 11:31 - 000000000 ____D C:\Program Files (x86)\Free Windows Cleanup Tool
2017-09-10 23:07 - 2017-04-29 22:54 - 000003890 _____ C:\Windows\System32\Tasks\SafeZone scheduled Autoupdate 1493474078
2017-09-10 23:07 - 2015-08-27 20:42 - 000003142 _____ C:\Windows\System32\Tasks\{55973317-C0A1-49AE-97AA-288DB64AD968}
2017-09-10 23:07 - 2014-04-03 07:46 - 000003124 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2017-09-10 23:07 - 2014-02-09 16:06 - 000003138 _____ C:\Windows\System32\Tasks\{F696468E-206D-410E-8C92-2CDAC8FD084A}
2017-09-10 23:06 - 2016-09-04 17:31 - 000002792 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC
2017-09-10 23:06 - 2016-03-15 05:17 - 000003692 _____ C:\Windows\System32\Tasks\DropboxUpdateTaskMachineUA
2017-09-10 23:06 - 2016-03-15 05:17 - 000003440 _____ C:\Windows\System32\Tasks\DropboxUpdateTaskMachineCore
2017-09-10 20:56 - 2014-04-05 16:31 - 000000000 ____D C:\Users\Owner\AppData\Local\CrashDumps
2017-09-10 20:48 - 2014-03-08 18:17 - 000000000 ____D C:\AdwCleaner
2017-09-10 10:43 - 2014-07-27 16:52 - 000192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2017-09-10 10:42 - 2008-04-13 19:12 - 000102912 _____ (Microsoft Corporation) C:\Program Files (x86)\clipbrd.exe
2017-09-09 15:52 - 2014-03-06 21:06 - 000000000 ____D C:\Users\Owner\AppData\Local\CutePDF Writer
2017-09-09 07:43 - 2016-03-15 05:17 - 000000000 ____D C:\Program Files (x86)\Dropbox
2017-09-06 19:43 - 2017-08-09 06:37 - 000000000 ____D C:\Users\Owner\Desktop\August newsletter
2017-09-05 23:52 - 2017-03-16 06:59 - 000000000 ___RD C:\Program Files (x86)\Skype
2017-09-05 23:52 - 2014-07-18 23:07 - 000000000 ____D C:\ProgramData\Skype
2017-09-02 20:27 - 2015-12-03 22:48 - 000000000 ____D C:\Program Files\Common Files\AV
2017-09-02 14:52 - 2017-04-29 22:51 - 000590880 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2017-09-02 14:52 - 2017-04-29 22:51 - 000361336 _____ (AVAST Software) C:\Windows\system32\Drivers\aswVmm.sys
2017-09-02 14:52 - 2017-04-29 22:51 - 000199312 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2017-09-02 14:52 - 2017-04-29 22:51 - 000147784 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2017-09-02 14:52 - 2017-04-29 22:51 - 000110376 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2017-09-02 14:52 - 2017-04-29 22:51 - 000084416 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys
2017-09-02 14:52 - 2017-04-29 22:51 - 000047016 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHwid.sys
2017-09-02 14:52 - 2017-04-29 22:51 - 000003914 _____ C:\Windows\System32\Tasks\Avast Emergency Update
2017-09-02 14:51 - 2017-04-29 22:53 - 000041832 _____ (AVAST Software) C:\Windows\system32\Drivers\aswKbd.sys
2017-09-02 14:51 - 2017-04-29 22:51 - 001016384 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2017-09-02 14:51 - 2017-04-29 22:51 - 000343296 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbloga.sys
2017-09-02 14:51 - 2017-04-29 22:51 - 000320528 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbidsdrivera.sys
2017-09-02 14:51 - 2017-04-29 22:51 - 000198976 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbidsha.sys
2017-09-02 14:51 - 2017-04-29 22:51 - 000057736 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbuniva.sys
2017-08-30 23:11 - 2016-03-22 21:22 - 000002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2017-08-29 06:46 - 2014-04-03 07:47 - 000002190 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-08-27 15:28 - 2014-02-09 17:12 - 000000000 ___RD C:\Users\Owner\Dropbox
2017-08-27 11:35 - 2017-04-30 17:05 - 000757998 _____ C:\Users\Owner\Downloads\bridging.pdf
2017-08-26 19:59 - 2017-04-11 20:48 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2017-08-26 12:20 - 2017-03-04 16:29 - 000000010 _____ C:\Users\Owner\AppData\Local\sponge.last.runtime.cache
2017-08-26 12:02 - 2017-03-04 16:14 - 002527376 _____ (Trend Micro Inc.) C:\Users\Owner\Downloads\HousecallLauncher64.exe
2017-08-26 09:29 - 2016-11-17 06:49 - 000000000 ____D C:\Users\Owner\AppData\LocalLow\Mozilla
2017-08-23 19:22 - 2009-07-14 14:08 - 000032592 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2017-08-22 16:54 - 2014-01-18 09:17 - 000000000 ____D C:\Users\Owner

==================== Files in the root of some directories =======

2008-04-13 19:12 - 2017-09-10 10:42 - 000102912 _____ (Microsoft Corporation) C:\Program Files (x86)\clipbrd.exe
2017-03-04 16:37 - 2017-07-30 13:00 - 002103318 _____ () C:\Users\Owner\AppData\Local\ars.cache
2017-03-04 16:39 - 2017-07-30 13:01 - 001097585 _____ () C:\Users\Owner\AppData\Local\census.cache
2017-03-04 16:14 - 2017-03-04 16:14 - 000000036 _____ () C:\Users\Owner\AppData\Local\housecall.guid.cache
2017-07-15 14:46 - 2017-07-15 14:46 - 000003364 _____ () C:\Users\Owner\AppData\Local\recently-used.xbel
2017-03-04 16:29 - 2017-08-26 12:20 - 000000010 _____ () C:\Users\Owner\AppData\Local\sponge.last.runtime.cache
2014-01-18 12:44 - 2015-10-30 21:37 - 000001890 ___SH () C:\ProgramData\KGyGaAvL.sys
2014-08-09 13:17 - 2017-09-12 20:11 - 000028130 ____H () C:\ProgramData\necbatt_error.log
2014-02-06 10:48 - 2014-02-06 15:42 - 000036398 ____H () C:\ProgramData\necbatt_progress.log

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2017-09-10 09:20

==================== End of FRST.txt ============================

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 12-09-2017
Ran by Owner (13-09-2017 19:43:57)
Running from C:\Users\Owner\Desktop
Windows 7 Home Premium Service Pack 1 (X64) (2014-01-18 00:17:09)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-2412369854-1432032030-2929281642-500 - Administrator - Disabled)
Guest (S-1-5-21-2412369854-1432032030-2929281642-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-2412369854-1432032030-2929281642-1002 - Limited - Enabled)
Owner (S-1-5-21-2412369854-1432032030-2929281642-1000 - Administrator - Enabled) => C:\Users\Owner

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Avast Antivirus (Enabled - Up to date) {8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Avast Antivirus (Enabled - Up to date) {35C973AA-9ABB-D3CA-B100-B0DC0E5F2402}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 17.012.20098 - Adobe Systems Incorporated)
Adobe Flash Player 27 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 27.0.0.130 - Adobe Systems Incorporated)
Adobe Flash Player 27 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 27.0.0.130 - Adobe Systems Incorporated)
Apple Application Support(32 ビット) (HKLM-x32\...\{D2FE6376-E549-4F63-A2C5-CA24DA035DE4}) (Version: 5.6 - Apple Inc.)
Apple Application Support(64 ビット) (HKLM\...\{BB109E24-EE90-485B-A28B-ADDEFB40540B}) (Version: 5.6 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{0A596141-97D5-45FA-9281-98DFAF48D579}) (Version: 10.3.2.3 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{52D87F32-70E4-4348-8148-C0B9F35B1314}) (Version: 2.3.0.177 - Apple Inc.)
Audacity 2.0.5 (HKLM-x32\...\Audacity_is1) (Version: 2.0.5 - Audacity Team)
Avast Free Antivirus (HKLM-x32\...\Avast Antivirus) (Version: 17.6.2310 - AVAST Software)
Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
Canon IJ Network Scanner Selector EX (HKLM-x32\...\Canon_IJ_Network_Scanner_Selector_EX) (Version:  - )
Canon IJ Network Tool (HKLM-x32\...\Canon_IJ_Network_UTILITY) (Version: 3.1.1 - Canon Inc.)
Canon MG6200 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG6200_series) (Version:  - Canon Inc.)
Canon MP Navigator EX 5.0 (HKLM-x32\...\MP Navigator EX 5.0) (Version:  - )
CCleaner (HKLM\...\CCleaner) (Version: 5.28 - Piriform)
CutePDF Writer 3.0 (HKLM\...\CutePDF Writer Installation) (Version:  3.0 - CutePDF.com)
D3DX10 (HKLM-x32\...\{E09C4DB7-630C-4F06-A631-8EA7239923AF}) (Version: 15.4.2368.0902 - Microsoft) Hidden
Dropbox (HKLM-x32\...\Dropbox) (Version: 34.4.20 - Dropbox, Inc.)
Dropbox Update Helper (HKLM-x32\...\{099218A5-A723-43DC-8DB5-6173656A1E94}) (Version: 1.3.59.1 - Dropbox, Inc.) Hidden
ECOモード設定ツール (HKLM\...\{1D2AF0E5-3B07-4B0F-98BD-03F0918BC367}) (Version: 1.0.0 - NEC Corporation, NEC Personal Products, Ltd.)
Extended Asian Language font pack for Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-2530-0000-AC0F074E4100}) (Version: 15.007.20033 - Adobe Systems Incorporated)
Finale NotePad 2012J (HKLM-x32\...\Finale NotePad 2012J) (Version: 2012..r2.0 - MakeMusic)
FlyFolder (HKLM-x32\...\{8062EDFE-6020-4C47-8E69-61D2AB68B7CC}) (Version: 3.0.0.14 - NEC Corporation, NEC Personal Products, Ltd.)
GIMP 2.8.22 (HKLM\...\GIMP-2_is1) (Version: 2.8.22 - The GIMP Team)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 60.0.3112.113 - Google Inc.)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.5 - Google Inc.) Hidden
Google Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.25.11 - Google Inc.) Hidden
inSSIDer (HKLM-x32\...\{65A5E87D-7A3F-4819-807D-B86990D5F369}) (Version: 2.1.6 - MetaGeek)
Intel® Graphics Media Accelerator Driver (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2202 - Intel Corporation)
iTunes (HKLM\...\{02F95875-9527-49CC-B32F-970ADAEBD1EF}) (Version: 12.6.2.20 - Apple Inc.)
Java 8 Update 144 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F64180144F0}) (Version: 8.0.1440.1 - Oracle Corporation)
Java 8 Update 144 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180144F0}) (Version: 8.0.1440.1 - Oracle Corporation)
Juniper Networks, Inc. Setup Client (HKU\S-1-5-21-2412369854-1432032030-2929281642-1000\...\Juniper_Setup_Client) (Version: 7.3.10.42895 - Juniper Networks, Inc.)
Juniper Networks, Inc. Setup Client 64-bit Activex Control (HKLM\...\Juniper_Setup_Client Activex Control) (Version: 2.1.1.1 - Juniper Networks, Inc.)
Juniper Networks, Inc. Setup Client Activex Control (HKLM-x32\...\Juniper_Setup_Client Activex Control) (Version: 2.1.1.1 - Juniper Networks, Inc.)
Junk Mail filter update (HKLM-x32\...\{F6F30C28-38AA-4DBA-AE0B-7E30238E61BB}) (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
LAME v3.99.3 (for Windows) (HKLM-x32\...\LAME_is1) (Version:  - )
Malwarebytes Anti-Malware version 2.2.1.1043 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes)
Media Go (HKLM-x32\...\{60CDD65B-61AD-4BE4-BEA8-BB2D15534D4B}) (Version: 3.2.191 - Sony)
Media Go Video Playback Engine 2.20.107.05220 (HKLM-x32\...\{7348D0F2-3DAC-0BE7-4E7C-64844D2E3CA9}) (Version: 2.20.107.05220 - Sony)
Microsoft .NET Framework 4.7 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.7.02053 - Microsoft Corporation)
Microsoft .NET Framework 4.7 (日本語) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1041) (Version: 4.7.02053 - Microsoft Corporation)
Microsoft Office 2010 (HKLM-x32\...\Office14.EssentialsR) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Office ナビ 2010 (HKLM\...\{95140000-011C-0411-1000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50907.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729 (HKLM\...\{A96702F7-EFC8-3EED-BE46-22C809D4EBE5}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{402ED4A1-8F5B-387A-8688-997ABF58B8F2}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\...\{90ffcee5-8608-4e94-8c18-a4feb4f83fb8}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation)
Microsoft Visual J# 2.0 Redistributable Package (HKLM-x32\...\Microsoft Visual J# 2.0 Redistributable Package) (Version:  - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - 日本語 (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - JPN) (Version: 10.0.50903 - Microsoft Corporation)
Movie Maker (HKLM-x32\...\{1823A9EA-B44D-42F5-947C-EFDC7980D975}) (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Movie Maker (HKLM-x32\...\{45898170-E68C-4F02-AA35-C2186BF347A3}) (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Movie Maker (HKLM-x32\...\{B39A6825-EA20-43EA-AB2D-A6BC0298D9A1}) (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Mozilla Firefox 55.0.3 (x64 en-US) (HKLM\...\Mozilla Firefox 55.0.3 (x64 en-US)) (Version: 55.0.3 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 53.0 - Mozilla)
MP3 Skype recorder (HKLM-x32\...\{50ECFF83-64B5-4485-87BC-4355C549159C}) (Version: 4.24.1.0 - Domit LTD)
MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2721691) (HKLM-x32\...\{355B5AC0-CEEE-42C5-AD4D-7F3CFD806C36}) (Version: 4.30.2114.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB973685) (HKLM-x32\...\{859DFA95-E4A6-48CD-B88E-A3E483E89B44}) (Version: 4.30.2107.0 - Microsoft Corporation)
NFC Port Software (HKLM-x32\...\{1FCD587F-ACBF-41BF-8CFF-4FDC99330037}) (Version: 5.3.3.1 - Sony Corporation)
NX PAD Driver (HKLM\...\{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}) (Version: 7.105.909.703 - NEC)
O2Micro Flash Memory Card Windows Driver (HKLM\...\{A93B901A-5215-4CA8-84A2-EDE54AE51F3D}) (Version: 2.0.21 - O2Micro International LTD.) Hidden
One-Touch Start Button Settings(1.18.1031) (HKLM\...\{B346E012-7EDD-4149-9949-AB367D2E36C9}) (Version: 1.18.1031 - NEC Corporation, NEC Personal Products, Ltd.) Hidden
One-Touch Start Button Settings(1.18.1033) (HKLM\...\{61DFBB13-722D-4A42-9B32-4E22A42964A8}) (Version: 1.18.1033 - NEC Corporation, NEC Personal Products, Ltd.) Hidden
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6083 - Realtek Semiconductor Corp.)
Renesas Electronics USB 3.0 Host Controller Driver (HKLM-x32\...\{5442DAB8-7177-49E1-8B22-09A049EA5996}) (Version: 2.0.4.0 - Renesas Electronics Corporation) Hidden
SafeZone Stable 4.58.2552.909 (HKLM-x32\...\SafeZone 4.58.2552.909) (Version: 4.58.2552.909 - Avast Software) Hidden
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{91140000-0013-0000-0000-0000000FF1CE}_Office14.EssentialsR_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version:  - Microsoft)
SetPoint 6.1 (HKLM\...\SP6) (Version: 6.10.65 - )
SFCard Viewer 2 (HKLM-x32\...\{AEFF5C47-5FB7-4080-8FB1-EF5601FFE336}) (Version: 2.4.1.2 - Sony Corporation)
Skype Click to Call (HKLM-x32\...\{873F8E7C-10E6-449F-BD7E-5FBA7C8E1C9B}) (Version: 8.5.0.9167 - Microsoft Corporation)
Skype™ 7.40 (HKLM-x32\...\{3B7E914A-93D5-4A29-92BB-AF8C3F66C431}) (Version: 7.40.103 - Skype Technologies S.A.)
Smart Update (HKLM-x32\...\{EA65772D-1999-462B-BFC0-480A9515ABCC}) (Version: 1.0.4.7 - NECパーソナルコンピュータ株式会社)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3508.0205 - Microsoft Corporation)
おすすめメニューガジェット (HKLM\...\{7A60C521-D2CC-431B-BC09-63B4FA8B77D1}) (Version: 1.0.0 - NEC Corporation, NEC Personal Products, Ltd.) Hidden
かざして転送 [スケジュール] (HKLM-x32\...\{E87192D3-079F-4A1A-9B00-BB7D235DDD37}) (Version: 1.0.1.0 - 株式会社ジャストシステム)
かざして転送 [テキスト] (HKLM-x32\...\{A54765FD-C13F-4C1E-A391-B9145238E64B}) (Version: 1.0.1.3 - 株式会社ジャストシステム)
かざして転送 [画像] (HKLM-x32\...\{0235E420-1EB2-4EF8-ACE9-8692C123A169}) (Version: 1.0.1.1 - 株式会社ジャストシステム)
シンプルログオン (HKLM-x32\...\{E171C361-7760-4D52-A6A4-6D22D8735689}) (Version: 1.0.6.4 - 株式会社ジャストシステム)
スクリーンセーバーロック2 (HKLM-x32\...\{5E862EC5-40B2-4A7E-A87D-B504E141318A}) (Version: 2.2.1.2 - 株式会社ジャストシステム)
ディスプレイの切り換え (HKLM\...\{2DC6DE6F-ABAF-410D-B0A9-C67117E60EC7}) (Version: 1.0.0 - NEC Corporation, NEC Personal Products, Ltd.)
デ辞蔵 PC (HKLM-x32\...\{5E43C43D-B34C-43D0-A7A1-A86D80128792}) (Version: 1.30.0000 - イースト株式会社)
パーソナルシェルター (HKLM-x32\...\{AD650226-3335-45BB-9640-D8C973366A1A}) (Version: 1.2.1.2 - 株式会社ジャストシステム)
パソらく設定 (HKLM-x32\...\{36B9B35F-4468-44FE-9845-F8F746214EF5}) (Version: 3.0.0 - NEC corporation, NEC personal Products, Ltd.)
バックアップ・ユーティリティ (HKLM-x32\...\{BC1D9138-3401-4DE0-BAE4-384E6E7755C1}) (Version: 1.0.6 - NEC Corporation, NEC Personal Products, Ltd.)
バッテリ・リフレッシュ&診断ツール (HKLM\...\{B3806CF1-829E-4280-BC3E-1636035908FD}) (Version: 1.8.0 - NEC Corporation, NEC Personal Products, Ltd.)
ぱっと観スライドショー (HKLM-x32\...\{88EC93C9-D3D7-4371-AA2D-84386E1ED9D1}) (Version: 1.0.0.0 - NEC Corporation, NEC Personal Products, Ltd.)
パワーオフUSB充電の設定 (HKLM\...\{DFA0E609-8481-4E32-828E-7311E4936F99}) (Version: 2.4.0 - NEC Corporation, NEC Personal Products, Ltd.) Hidden
フォト ギャラリー (HKLM-x32\...\{92B24D5E-827C-4FF3-A604-BD603FE3A34F}) (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
ホームネットワークサーバー powered by DiXiM (HKLM-x32\...\{8D3447EE-A34C-438C-815B-178F771B1556}) (Version: 3.20 - DigiOn)
ホームネットワークプレーヤー powered by DiXiM (HKLM-x32\...\{BB7DD54A-B72D-4E38-A9CB-05A912D4450F}) (Version: 1.3.0.5 - DigiOn)
ワンタッチスタートボタンの設定(9.18.1011) (HKLM\...\{487D044D-6426-4FD4-A521-1CF9456E7DB2}) (Version: 9.18.1011 - NEC Corporation, NEC Personal Products, Ltd.) Hidden
再セットアップディスク作成ツール (HKLM-x32\...\{0FAEDF91-929A-42B2-874C-E599CE1CEB78}) (Version: 2.0.0 - NEC Corporation, NEC Personal Products, Ltd.)
彩りの設定 (HKLM\...\{9C3DDA32-8035-4C84-9422-E2796F24B193}) (Version: 1.3.0 - NEC Corporation, NEC Personal Products, Ltd.) Hidden
彩りの設定 (HKLM\...\AVDm) (Version:  - NEC Corporation, NEC Personal Products, Ltd.)
消費電力の表示 (HKLM\...\{01F84262-DBC2-4B4D-8C4A-1C82D2CD88AA}) (Version: 1.1.0 - NEC Corporation, NEC Personal Products, Ltd.)
筆ぐるめ Ver.17 (HKLM-x32\...\{0F3EF57F-D82E-4668-A199-6E7D13E85413}) (Version: 17.00.0000 - 富士ソフト株式会社)
筆まめ Ver.25 ベーシック (HKLM-x32\...\{A04C74B6-33B8-407A-A7D2-1E96557A94CC}) (Version: 25.06.1913.0 - 販売元:株式会社筆まめ 開発元:株式会社モーリン)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

ShellIconOverlayIdentifiers: [   DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.18.0.dll [2017-09-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.18.0.dll [2017-09-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.18.0.dll [2017-09-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.18.0.dll [2017-09-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.18.0.dll [2017-09-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.18.0.dll [2017-09-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.18.0.dll [2017-09-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.18.0.dll [2017-09-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.18.0.dll [2017-09-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.18.0.dll [2017-09-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-09-02] (AVAST Software)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-09-02] (AVAST Software)
ShellIconOverlayIdentifiers: [FFShell] -> {4DCF34C0-76B1-4589-BA10-D87C7C3D8D50} => C:\Program Files\FlyFolder\FFShell.dll [2009-09-14] (NEC Corporation, NEC Personal Products)
ShellIconOverlayIdentifiers-x32: [   DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.18.0.dll [2017-09-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.18.0.dll [2017-09-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.18.0.dll [2017-09-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.18.0.dll [2017-09-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.18.0.dll [2017-09-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.18.0.dll [2017-09-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.18.0.dll [2017-09-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.18.0.dll [2017-09-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.18.0.dll [2017-09-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.18.0.dll [2017-09-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.18.0.dll [2017-09-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.18.0.dll [2017-09-06] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.18.0.dll [2017-09-06] (Dropbox, Inc.)
ContextMenuHandlers1: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-09-02] (AVAST Software)
ContextMenuHandlers1: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.18.0.dll [2017-09-06] (Dropbox, Inc.)
ContextMenuHandlers1: [WondershareVideoConverterFileOpreation] -> {FEB746CA-95C2-485F-B386-C30D4E56D22E} => C:\Windows\SysWOW64\WSCM64.dll -> No File
ContextMenuHandlers3: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-09-02] (AVAST Software)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamext.dll [2016-03-10] (Malwarebytes)
ContextMenuHandlers4: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.18.0.dll [2017-09-06] (Dropbox, Inc.)
ContextMenuHandlers5: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.18.0.dll [2017-09-06] (Dropbox, Inc.)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => C:\Windows\system32\igfxpph.dll [2014-02-08] (Intel Corporation)
ContextMenuHandlers6: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-09-02] (AVAST Software)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamext.dll [2016-03-10] (Malwarebytes)

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {0517484D-E1BA-463F-B5F2-6C071A75E50C} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe
Task: {06F0B5BC-0231-47EA-BF66-ABD3FCF5098A} - System32\Tasks\{55973317-C0A1-49AE-97AA-288DB64AD968} => C:\Windows\system32\pcalua.exe -a C:\Users\Owner\Desktop\classic_doom_3.1.3.1.exe -d C:\Users\Owner\Desktop
Task: {0A25D8AD-1345-49A9-B0F7-9BDB8409C091} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2017-02-14] (Apple Inc.)
Task: {2652FD6F-0EA5-4AB3-A86F-A1014799758C} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2016-03-15] (Dropbox, Inc.)
Task: {4E88CAFB-A2B5-4F28-98A5-C27A1CDCA599} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2016-03-15] (Dropbox, Inc.)
Task: {688DF6F4-4116-404F-B70E-25265DC51044} - System32\Tasks\{F696468E-206D-410E-8C92-2CDAC8FD084A} => C:\Windows\system32\pcalua.exe -a C:\Users\Owner\Downloads\wlsetup-web(4).exe -d C:\Users\Owner\Downloads
Task: {A07B65B4-8FC5-4B78-A5D6-9C479789A867} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.)
Task: {A86B0755-E274-48B6-88BF-35AB90F26B05} - System32\Tasks\Avast Emergency Update => C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe [2017-09-02] (AVAST Software)
Task: {ADFC623F-4AD9-492C-8061-12FBC5719089} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2017-07-19] (Adobe Systems Incorporated)
Task: {BE25233F-1B94-4977-9086-BBE2C3D1F1A5} - System32\Tasks\SafeZone scheduled Autoupdate 1493474078 => C:\Program Files\AVAST Software\SZBrowser\launcher.exe [2017-08-04] (Avast Software)
Task: {D6C93CB3-9CFC-4750-B071-463E76004158} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2017-03-04] (Piriform Ltd)
Task: {E0292299-AF65-4B02-98BE-0169CF0F302B} - System32\Tasks\ノートン セキュリティスキャン for Owner => C:\PROGRA~2\NORTON~2\Engine\462~1.17\Nss.exe
Task: {E3FBE616-B382-4DCA-A2CE-D16F74788454} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.)
Task: {FDD6288E-05B9-4AA5-9730-CC8F4936FCD7} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-09-12] (Adobe Systems Incorporated)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\Windows\Tasks\DropboxUpdateTaskMachineCore.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
Task: C:\Windows\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe

==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)


==================== Loaded Modules (Whitelisted) ==============

2014-03-06 21:05 - 2013-10-23 15:24 - 000087600 _____ () C:\Windows\System32\cpwmon64.dll
2017-07-13 20:50 - 2017-07-13 20:50 - 001354040 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2016-11-17 01:28 - 2016-11-17 01:28 - 000092472 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2010-05-07 16:36 - 2010-05-07 16:36 - 000150528 _____ () C:\Program Files\EcoViewer\EcoLevel.dll
2017-09-02 14:51 - 2017-09-02 14:51 - 000067408 _____ () C:\Program Files\AVAST Software\Avast\x64\module_lifetime.dll
2017-09-02 14:51 - 2017-09-02 14:51 - 000169832 _____ () c:\Program Files\AVAST Software\Avast\x64\vaarclient.dll
2017-09-02 14:51 - 2017-09-02 14:51 - 000824944 _____ () C:\Program Files\AVAST Software\Avast\x64\ffl2.dll
2017-09-02 14:51 - 2017-09-02 14:51 - 000286712 _____ () c:\Program Files\AVAST Software\Avast\x64\StreamBack.dll
2009-12-16 14:19 - 2009-12-16 14:19 - 000830976 _____ () C:\Program Files\NECMFK\OSDIMG.DLL
2017-09-02 14:51 - 2017-09-02 14:51 - 000059040 _____ () C:\Program Files\AVAST Software\Avast\module_lifetime.dll
2017-09-02 14:51 - 2017-09-02 14:51 - 000167096 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
2017-09-02 14:51 - 2017-09-02 14:51 - 000211904 _____ () C:\Program Files\AVAST Software\Avast\event_routing_rpc.dll
2017-09-02 14:51 - 2017-09-02 14:51 - 000241960 _____ () C:\Program Files\AVAST Software\Avast\tasks_core.dll
2017-09-02 14:51 - 2017-09-02 14:51 - 000149568 _____ () C:\Program Files\AVAST Software\Avast\network_notifications.dll
2017-09-13 00:12 - 2017-09-13 00:12 - 005901864 _____ () C:\Program Files\AVAST Software\Avast\defs\17091212\algo.dll
2017-09-02 14:51 - 2017-09-02 14:51 - 000685688 _____ () C:\Program Files\AVAST Software\Avast\ffl2.dll
2017-09-02 14:51 - 2017-09-02 14:51 - 000241448 _____ () C:\Program Files\AVAST Software\Avast\streamback.dll
2010-09-21 10:35 - 2010-01-18 12:18 - 000069632 ____N () C:\Program Files (x86)\DigiOn\DiXiM Digital TV\dixim_mrd.dll
2010-09-21 10:35 - 2010-01-18 12:17 - 000147456 ____N () C:\Program Files (x86)\DigiOn\DiXiM Digital TV\dixim_av.dll
2010-09-21 10:35 - 2009-08-01 03:34 - 000151552 ____N () C:\Program Files (x86)\DigiOn\DiXiM Digital TV\dixim_upnp.dll
2010-09-21 10:35 - 2009-06-25 21:21 - 000032768 ____N () C:\Program Files (x86)\DigiOn\DiXiM Digital TV\dixim_char_util.dll
2010-09-21 10:35 - 2009-06-25 21:21 - 000135168 ____N () C:\Program Files (x86)\DigiOn\DiXiM Digital TV\dixim_util.dll
2010-09-21 10:35 - 2009-06-25 21:21 - 000151552 ____N () C:\Program Files (x86)\DigiOn\DiXiM Digital TV\libexpat.dll
2010-09-21 10:35 - 2009-06-25 21:21 - 000180224 ____N () C:\Program Files (x86)\DigiOn\DiXiM Digital TV\uchardet.dll
2010-09-21 10:35 - 2009-06-25 21:21 - 001443212 ____N () C:\Program Files (x86)\DigiOn\DiXiM Digital TV\iconv.dll
2013-09-05 00:14 - 2013-09-05 00:14 - 004300456 _____ () C:\Program Files (x86)\Common Files\Microsoft Shared\office14\Cultures\office.odf
2017-07-02 12:21 - 2017-07-02 12:21 - 067109376 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2017-09-02 14:51 - 2017-09-02 14:51 - 000233768 _____ () C:\Program Files\AVAST Software\Avast\gaming_mode_ui.dll
2017-09-09 07:42 - 2017-09-06 19:29 - 000771392 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox_watchdog.dll
2017-09-09 07:42 - 2017-09-06 19:29 - 001804608 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox_crashpad.dll
2017-08-24 06:51 - 2017-09-06 19:29 - 000100296 _____ () C:\Program Files (x86)\Dropbox\Client\_ctypes.pyd
2017-08-24 06:51 - 2017-09-06 19:29 - 000018888 _____ () C:\Program Files (x86)\Dropbox\Client\select.pyd
2017-08-24 06:51 - 2017-09-06 19:34 - 000020800 _____ () C:\Program Files (x86)\Dropbox\Client\tornado.speedups.pyd
2017-08-24 06:51 - 2017-09-06 19:29 - 000035792 _____ () C:\Program Files (x86)\Dropbox\Client\_multiprocessing.pyd
2017-09-09 07:42 - 2017-09-06 19:31 - 000021848 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._constant_time.pyd
2017-08-24 06:51 - 2017-09-06 19:29 - 000125904 _____ () C:\Program Files (x86)\Dropbox\Client\_cffi_backend.pyd
2017-08-24 06:51 - 2017-09-06 19:29 - 000694224 _____ () C:\Program Files (x86)\Dropbox\Client\unicodedata.pyd
2017-09-09 07:42 - 2017-09-06 19:31 - 001862992 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._openssl.pyd
2017-09-09 07:42 - 2017-09-06 19:31 - 000022864 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._padding.pyd
2017-09-09 07:42 - 2017-09-06 19:29 - 000145864 _____ () C:\Program Files (x86)\Dropbox\Client\pyexpat.pyd
2017-09-09 07:42 - 2017-09-06 19:29 - 000116688 _____ () C:\Program Files (x86)\Dropbox\Client\pywintypes27.dll
2017-08-24 06:51 - 2017-09-06 19:29 - 000105928 _____ () C:\Program Files (x86)\Dropbox\Client\win32api.pyd
2017-08-24 06:51 - 2017-09-06 19:34 - 000022864 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.crt.compiled._winffi_crt.pyd
2017-09-09 07:42 - 2017-09-06 19:32 - 000062784 _____ () C:\Program Files (x86)\Dropbox\Client\psutil._psutil_windows.pyd
2017-08-24 06:51 - 2017-09-06 19:29 - 000024528 _____ () C:\Program Files (x86)\Dropbox\Client\win32event.pyd
2017-09-09 07:42 - 2017-09-06 19:32 - 000040248 _____ () C:\Program Files (x86)\Dropbox\Client\fastpath.pyd
2017-09-09 07:42 - 2017-09-06 19:29 - 000020936 _____ () C:\Program Files (x86)\Dropbox\Client\mmapfile.pyd
2017-08-24 06:51 - 2017-09-06 19:29 - 000124880 _____ () C:\Program Files (x86)\Dropbox\Client\win32file.pyd
2017-08-24 06:51 - 2017-09-06 19:29 - 000116176 _____ () C:\Program Files (x86)\Dropbox\Client\win32security.pyd
2017-09-09 07:42 - 2017-09-06 19:29 - 000392656 _____ () C:\Program Files (x86)\Dropbox\Client\pythoncom27.dll
2017-08-24 06:51 - 2017-09-06 19:34 - 000392512 _____ () C:\Program Files (x86)\Dropbox\Client\win32com.shell.shell.pyd
2017-08-24 06:51 - 2017-09-06 19:34 - 000026456 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.kernel32.compiled._winffi_kernel32.pyd
2017-08-24 06:51 - 2017-09-06 19:29 - 000024016 _____ () C:\Program Files (x86)\Dropbox\Client\win32clipboard.pyd
2017-08-24 06:51 - 2017-09-06 19:29 - 000175560 _____ () C:\Program Files (x86)\Dropbox\Client\win32gui.pyd
2017-08-24 06:51 - 2017-09-06 19:29 - 000030160 _____ () C:\Program Files (x86)\Dropbox\Client\win32pipe.pyd
2017-08-24 06:51 - 2017-09-06 19:29 - 000043472 _____ () C:\Program Files (x86)\Dropbox\Client\win32process.pyd
2017-08-24 06:51 - 2017-09-06 19:29 - 000048592 _____ () C:\Program Files (x86)\Dropbox\Client\win32service.pyd
2017-08-24 06:51 - 2017-09-06 19:29 - 000057808 _____ () C:\Program Files (x86)\Dropbox\Client\win32evtlog.pyd
2017-09-09 07:42 - 2017-09-06 19:31 - 000022336 _____ () C:\Program Files (x86)\Dropbox\Client\cpuid.compiled._cpuid.pyd
2017-09-09 07:42 - 2017-09-06 19:35 - 000023368 _____ () C:\Program Files (x86)\Dropbox\Client\winshell.compiled._winshell.pyd
2017-08-24 06:51 - 2017-09-06 19:34 - 000082264 _____ () C:\Program Files (x86)\Dropbox\Client\winenumhandles.compiled._WinEnumHandles.pyd
2017-08-24 06:51 - 2017-09-06 19:35 - 000025432 _____ () C:\Program Files (x86)\Dropbox\Client\winscreenshot.compiled._CaptureScreenshot.pyd
2017-08-24 06:51 - 2017-09-06 19:29 - 000028616 _____ () C:\Program Files (x86)\Dropbox\Client\win32ts.pyd
2017-08-24 06:51 - 2017-09-06 19:29 - 000024016 _____ () C:\Program Files (x86)\Dropbox\Client\win32profile.pyd
2017-09-09 07:42 - 2017-09-06 19:32 - 001826104 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtCore.pyd
2017-08-24 06:51 - 2017-09-06 19:29 - 000083912 _____ () C:\Program Files (x86)\Dropbox\Client\sip.pyd
2017-09-09 07:42 - 2017-09-06 19:32 - 001972024 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtGui.pyd
2017-09-09 07:42 - 2017-09-06 19:32 - 003928896 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWidgets.pyd
2017-09-09 07:42 - 2017-09-06 19:32 - 000171336 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebEngineWidgets.pyd
2017-09-09 07:42 - 2017-09-06 19:32 - 000042816 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebChannel.pyd
2017-09-09 07:42 - 2017-09-06 19:32 - 000531264 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtNetwork.pyd
2017-09-09 07:42 - 2017-09-06 19:32 - 000133432 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebKit.pyd
2017-09-09 07:42 - 2017-09-06 19:32 - 000224064 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebKitWidgets.pyd
2017-09-09 07:42 - 2017-09-06 19:32 - 000207680 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtPrintSupport.pyd
2017-08-24 06:51 - 2017-09-06 19:29 - 000060880 _____ () C:\Program Files (x86)\Dropbox\Client\win32print.pyd
2017-08-24 06:51 - 2017-09-06 19:35 - 000054608 _____ () C:\Program Files (x86)\Dropbox\Client\winrpcserver.compiled._RPCServer.pyd
2017-08-24 06:51 - 2017-09-06 19:35 - 000022864 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.user32.compiled._winffi_user32.pyd
2017-08-24 06:51 - 2017-09-06 19:34 - 000022872 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.iphlpapi.compiled._winffi_iphlpapi.pyd
2017-08-24 06:51 - 2017-09-06 19:35 - 000021848 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.winerror.compiled._winffi_winerror.pyd
2017-08-24 06:51 - 2017-09-06 19:35 - 000022872 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.wininet.compiled._winffi_wininet.pyd
2017-09-09 07:42 - 2017-09-06 19:31 - 000027488 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox.infinite.win.compiled._driverinstallation.pyd
2017-08-24 06:51 - 2017-09-06 19:29 - 000349128 _____ () C:\Program Files (x86)\Dropbox\Client\winxpgui.pyd
2017-08-24 06:51 - 2017-09-06 19:35 - 000023896 _____ () C:\Program Files (x86)\Dropbox\Client\winverifysignature.compiled._VerifySignature.pyd
2017-09-09 07:42 - 2017-09-06 19:32 - 000025936 _____ () C:\Program Files (x86)\Dropbox\Client\librsyncffi.compiled._librsyncffi.pyd
2017-09-09 07:42 - 2017-09-06 19:29 - 000036296 _____ () C:\Program Files (x86)\Dropbox\Client\librsync.dll
2017-09-09 07:42 - 2017-09-06 19:31 - 000181056 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox_sqlite_ext.DLL
2017-08-24 06:51 - 2017-09-06 19:34 - 000030536 _____ () C:\Program Files (x86)\Dropbox\Client\wind3d11.compiled._wind3d11.pyd
2017-09-09 07:42 - 2017-09-06 19:32 - 000024368 _____ () C:\Program Files (x86)\Dropbox\Client\libEGL.dll
2017-09-09 07:42 - 2017-09-06 19:32 - 001637688 _____ () C:\Program Files (x86)\Dropbox\Client\libGLESv2.dll
2017-08-24 06:51 - 2017-09-06 19:35 - 000026456 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.winhttp.compiled._winffi_winhttp.pyd
2017-08-24 06:51 - 2017-09-06 19:34 - 000023368 _____ () C:\Program Files (x86)\Dropbox\Client\wincrashpad.compiled._Crashpad.pyd
2017-09-09 07:42 - 2017-09-06 19:32 - 000546104 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtQuick.pyd
2017-09-09 07:42 - 2017-09-06 19:32 - 000357688 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtQml.pyd
2010-09-21 10:26 - 2010-10-04 19:30 - 000107856 _____ () C:\Program Files (x86)\DigiOn\DiXiM Media Server\dms_sync_svc.exe
2010-09-21 10:26 - 2009-07-02 20:04 - 000020480 _____ () C:\Program Files (x86)\DigiOn\DiXiM Media Server\dixim_crawler.dll
2010-09-21 10:26 - 2008-08-27 00:34 - 000061440 _____ () C:\Program Files (x86)\DigiOn\DiXiM Media Server\scew.dll
2010-09-21 10:26 - 2008-07-28 21:42 - 000151552 _____ () C:\Program Files (x86)\DigiOn\DiXiM Media Server\libexpat.dll
2010-09-21 10:26 - 2009-07-29 17:59 - 000159744 _____ () C:\Program Files (x86)\DigiOn\DiXiM Media Server\dixim_util.dll
2010-09-21 10:26 - 2009-05-23 00:55 - 000937984 _____ () C:\Program Files (x86)\DigiOn\DiXiM Media Server\libxml2.dll
2010-09-21 10:26 - 2010-04-23 15:18 - 000159744 _____ () C:\Program Files (x86)\DigiOn\DiXiM Media Server\dixim_upnp.dll
2010-09-21 10:26 - 2009-07-29 17:59 - 000032768 _____ () C:\Program Files (x86)\DigiOn\DiXiM Media Server\dixim_char_util.dll
2010-09-21 10:26 - 2009-05-23 00:55 - 000180224 _____ () C:\Program Files (x86)\DigiOn\DiXiM Media Server\uchardet.dll
2010-09-21 10:26 - 2008-07-28 21:42 - 001443212 _____ () C:\Program Files (x86)\DigiOn\DiXiM Media Server\iconv.dll
2010-09-21 10:26 - 2009-05-25 19:47 - 000167936 _____ () C:\Program Files (x86)\DigiOn\DiXiM Media Server\dixim_av.dll
2010-09-21 10:26 - 2009-05-25 19:47 - 000028672 _____ () C:\Program Files (x86)\DigiOn\DiXiM Media Server\dixim_metadata.dll
2010-09-21 10:26 - 2010-01-21 20:41 - 000024576 _____ () C:\Program Files (x86)\DigiOn\DiXiM Media Server\dixim_metadata_cached_jpeg_populator.dll
2010-09-21 10:26 - 2010-10-04 19:30 - 000118784 _____ () C:\Program Files (x86)\DigiOn\DiXiM Media Server\dixim_media_jpeg.dll
2010-09-21 10:26 - 2008-07-28 21:42 - 000307962 _____ () C:\Program Files (x86)\DigiOn\DiXiM Media Server\libexif.dll
2010-09-21 10:26 - 2009-05-25 19:47 - 000053248 _____ () C:\Program Files (x86)\DigiOn\DiXiM Media Server\dixim_media.dll
2010-09-21 10:26 - 2010-04-13 17:49 - 000028672 _____ () C:\Program Files (x86)\DigiOn\DiXiM Media Server\dixim_metadata_common_populator.dll
2010-09-21 10:26 - 2010-04-13 17:49 - 000024576 _____ () C:\Program Files (x86)\DigiOn\DiXiM Media Server\dixim_metadata_jpeg_populator.dll
2010-09-21 10:26 - 2010-10-04 19:30 - 000135168 _____ () C:\Program Files (x86)\DigiOn\DiXiM Media Server\dixim_msd.dll
2010-09-21 10:26 - 2009-07-29 17:59 - 000049152 _____ () C:\Program Files (x86)\DigiOn\DiXiM Media Server\dixim_crawler_fs.dll
2010-09-21 10:26 - 2009-05-25 19:47 - 000024576 _____ () C:\Program Files (x86)\DigiOn\DiXiM Media Server\dixim_playlist.dll
2010-09-21 10:26 - 2010-10-04 19:30 - 000032768 _____ () C:\Program Files (x86)\DigiOn\DiXiM Media Server\dixim_msd_wm_file_transporter.dll
2010-09-21 10:26 - 2010-10-04 19:30 - 000032768 _____ () C:\Program Files (x86)\DigiOn\DiXiM Media Server\dixim_msd_file_transporter.dll
2010-09-21 10:26 - 2009-05-25 19:47 - 000020480 _____ () C:\Program Files (x86)\DigiOn\DiXiM Media Server\dixim_metadata_wm_file_populator.dll
2010-09-21 10:26 - 2009-06-29 16:35 - 000057344 _____ () C:\Program Files (x86)\DigiOn\DiXiM Media Server\dixim_media_wm.dll
2010-09-21 10:26 - 2009-05-25 19:47 - 000028672 _____ () C:\Program Files (x86)\DigiOn\DiXiM Media Server\dixim_media_bmp.dll
2010-09-21 10:26 - 2009-05-25 19:47 - 000024576 _____ () C:\Program Files (x86)\DigiOn\DiXiM Media Server\dixim_media_gif.dll
2010-09-21 10:26 - 2009-05-25 19:47 - 000028672 _____ () C:\Program Files (x86)\DigiOn\DiXiM Media Server\dixim_media_png.dll
2010-09-21 10:26 - 2009-05-23 00:55 - 000122880 _____ () C:\Program Files (x86)\DigiOn\DiXiM Media Server\libpng.dll
2010-09-21 10:26 - 2008-07-28 21:42 - 000073728 _____ () C:\Program Files (x86)\DigiOn\DiXiM Media Server\zlib.dll
2010-09-21 10:26 - 2010-10-04 19:30 - 000032768 _____ () C:\Program Files (x86)\DigiOn\DiXiM Media Server\dixim_msd_thumbnail_transporter.dll
2010-09-21 10:26 - 2009-07-29 17:59 - 000020480 _____ () C:\Program Files (x86)\DigiOn\DiXiM Media Server\dixim_device_configuration.dll
2010-09-21 10:26 - 2009-07-29 17:59 - 000028672 _____ () C:\Program Files (x86)\DigiOn\DiXiM Media Server\dixim_device_manager.dll
2010-09-21 10:26 - 2009-06-29 16:35 - 000020480 _____ () C:\Program Files (x86)\DigiOn\DiXiM Media Server\dixim_metadata_jpeg_thumbnail_populator.dll
2010-09-21 10:26 - 2009-05-25 19:47 - 000020480 _____ () C:\Program Files (x86)\DigiOn\DiXiM Media Server\dixim_metadata_wm_thumbnail_populator.dll
2010-09-21 10:26 - 2009-05-25 19:47 - 000020480 _____ () C:\Program Files (x86)\DigiOn\DiXiM Media Server\dixim_metadata_mp3_thumbnail_populator.dll
2010-09-21 10:26 - 2010-05-24 19:21 - 000045056 _____ () C:\Program Files (x86)\DigiOn\DiXiM Media Server\dixim_media_mp3.dll
2010-09-21 10:26 - 2010-01-12 12:53 - 000020480 _____ () C:\Program Files (x86)\DigiOn\DiXiM Media Server\dixim_metadata_mp4_thumbnail_populator.dll
2010-09-21 10:26 - 2010-10-04 19:30 - 000065536 _____ () C:\Program Files (x86)\DigiOn\DiXiM Media Server\dixim_media_mp4.dll
2010-09-21 10:26 - 2009-05-25 19:47 - 000020480 _____ () C:\Program Files (x86)\DigiOn\DiXiM Media Server\dixim_metadata_wm_post_populator.dll
2010-09-21 10:26 - 2009-06-29 16:35 - 000024576 _____ () C:\Program Files (x86)\DigiOn\DiXiM Media Server\dixim_metadata_thumbnail_populator.dll
2010-09-21 10:26 - 2009-05-25 19:47 - 000024576 _____ () C:\Program Files (x86)\DigiOn\DiXiM Media Server\dixim_register_sqlite.dll
2010-09-21 10:26 - 2009-07-29 17:59 - 000024576 _____ () C:\Program Files (x86)\DigiOn\DiXiM Media Server\dixim_rdb_sqlite.dll
2010-09-21 10:26 - 2009-05-23 00:55 - 000499246 _____ () C:\Program Files (x86)\DigiOn\DiXiM Media Server\sqlite3.dll
2010-09-21 10:26 - 2009-07-02 20:04 - 000020480 _____ () C:\Program Files (x86)\DigiOn\DiXiM Media Server\dixim_media_detector.dll
2010-09-21 10:26 - 2009-05-25 19:47 - 000020480 _____ () C:\Program Files (x86)\DigiOn\DiXiM Media Server\dixim_metadata_lpcm_file_populator.dll
2010-09-21 10:26 - 2010-10-04 19:30 - 000020480 _____ () C:\Program Files (x86)\DigiOn\DiXiM Media Server\dixim_metadata_mpeg_file_populator.dll
2010-09-21 10:26 - 2010-10-04 19:30 - 000045056 _____ () C:\Program Files (x86)\DigiOn\DiXiM Media Server\dixim_msd_mpeg_file_transporter.dll
2010-09-21 10:26 - 2009-06-29 16:35 - 000024576 _____ () C:\Program Files (x86)\DigiOn\DiXiM Media Server\dixim_metadata_album_art_populator.dll
2010-09-21 10:26 - 2009-05-25 19:47 - 000020480 _____ () C:\Program Files (x86)\DigiOn\DiXiM Media Server\dixim_metadata_lpcm_populator.dll
2010-09-21 10:26 - 2009-05-25 19:47 - 000024576 _____ () C:\Program Files (x86)\DigiOn\DiXiM Media Server\dixim_media_tiff.dll
2010-09-21 10:26 - 2008-07-28 21:42 - 000495741 _____ () C:\Program Files (x86)\DigiOn\DiXiM Media Server\libtiff.dll
2010-09-21 10:26 - 2009-05-25 19:47 - 000024576 _____ () C:\Program Files (x86)\DigiOn\DiXiM Media Server\dixim_media_ogg.dll
2010-09-21 10:26 - 2008-09-29 15:07 - 000151552 _____ () C:\Program Files (x86)\DigiOn\DiXiM Media Server\libtremor.dll
2010-09-21 10:26 - 2009-05-25 19:47 - 000020480 _____ () C:\Program Files (x86)\DigiOn\DiXiM Media Server\dixim_media_lpcm.dll
2010-09-21 10:26 - 2009-07-29 17:59 - 000131072 _____ () C:\Program Files (x86)\DigiOn\DiXiM Media Server\dixim_media_mpeg.dll
2010-09-21 10:26 - 2009-05-25 19:47 - 000024576 _____ () C:\Program Files (x86)\DigiOn\DiXiM Media Server\dixim_media_avi.dll
2010-09-21 10:26 - 2009-05-25 19:47 - 000024576 _____ () C:\Program Files (x86)\DigiOn\DiXiM Media Server\dixim_media_wav.dll
2010-09-21 10:26 - 2009-07-29 17:59 - 000155648 _____ () C:\Program Files (x86)\DigiOn\DiXiM Media Server\dixim_cdsrdb_sqlite.dll
2010-09-21 10:26 - 2010-10-04 19:30 - 000028672 _____ () C:\Program Files (x86)\DigiOn\DiXiM Media Server\dixim_msd_lpcm_transporter.dll
2010-09-21 10:26 - 2010-10-04 19:30 - 000032768 _____ () C:\Program Files (x86)\DigiOn\DiXiM Media Server\dixim_msd_jpeg_transporter.dll
2010-09-21 10:26 - 2010-10-04 19:30 - 000028672 _____ () C:\Program Files (x86)\DigiOn\DiXiM Media Server\dixim_msd_lpcm_file_transporter.dll
2010-09-21 10:26 - 2009-07-29 17:59 - 000049152 _____ () C:\Program Files (x86)\DigiOn\DiXiM Media Server\dixim_access_control.dll
2010-09-21 10:26 - 2009-05-25 19:47 - 000024576 _____ () C:\Program Files (x86)\DigiOn\DiXiM Media Server\dixim_printer.dll
2010-09-21 10:26 - 2009-07-29 17:59 - 000094208 _____ () C:\Program Files (x86)\DigiOn\DiXiM Media Server\plugin\service\media_server_tool.dll
2010-09-21 10:26 - 2009-06-11 20:30 - 000028672 _____ () C:\Program Files (x86)\DigiOn\DiXiM Media Server\plugin\transporter\svi_transporter_nec.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp.sys => ""="Driver"

==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 11:34 - 2009-06-11 06:00 - 000000824 _____ C:\Windows\system32\Drivers\etc\hosts


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-2412369854-1432032030-2929281642-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.3.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

MSCONFIG\startupreg: CCleaner Monitoring => "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
MSCONFIG\startupreg: DelaypluginInstall => C:\ProgramData\Wondershare\Video Converter Ultimate\DelayPluginI.exe
MSCONFIG\startupreg: IgfxTray => C:\Windows\system32\igfxtray.exe
MSCONFIG\startupreg: IJNetworkScannerSelectorEX => C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe /FORCE
MSCONFIG\startupreg: iTunesHelper => "C:\Program Files\iTunes\iTunesHelper.exe"
MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
MSCONFIG\startupreg: SUPERAntiSpyware => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
MSCONFIG\startupreg: Wondershare Helper Compact.exe => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{CB3F52E3-E2AD-4DE4-8676-0E91AE87F969}] => (Allow) C:\Program Files (x86)\Faith\NFRMPCViewer\NFRMPCViewer.exe
FirewallRules: [{FF21810B-FAB4-41DF-BA0A-089EA8ECB8E0}] => (Allow) C:\Program Files (x86)\Faith\NFRMPCViewer\NFRMPCViewer.exe
FirewallRules: [{931A4D11-611B-4E2D-B287-5BF1A89BE4DC}] => (Allow) C:\Program Files (x86)\Faith\NFRMPCViewer\plugins\NFRMMoviePlayer\NFRMMoviePlayer.exe
FirewallRules: [{AA0A38F7-8D62-41FA-AF62-02FD5003D030}] => (Allow) C:\Program Files (x86)\Faith\NFRMPCViewer\plugins\NFRMMoviePlayer\NFRMMoviePlayer.exe
FirewallRules: [{460C4D70-7ECC-4B29-A96E-C8999C1C9FEB}] => (Allow) C:\Program Files (x86)\Faith\NFRMPCViewer\NFRMUpdater.exe
FirewallRules: [{1ACCF730-A520-4975-9F0C-3C6EA80A1996}] => (Allow) C:\Program Files (x86)\Faith\NFRMPCViewer\NFRMUpdater.exe
FirewallRules: [{B433C8B7-1FF6-4BE4-89C7-515AC8F88D87}] => (Allow) c:\Program Files (x86)\NEC\PRCP\prtctrl.exe
FirewallRules: [{13AD7368-9E76-4EC4-B4B7-9EAE8694502C}] => (Allow) c:\Program Files (x86)\NEC\PRCP\prtctrl.exe
FirewallRules: [{1A9E6361-60F0-4AEC-8488-8D9F695764AE}] => (Allow) C:\Program Files (x86)\DigiOn\DiXiM Media Server\dms_sync_svc.exe
FirewallRules: [{FFF90CD5-C889-499A-A87A-C07E406E95BE}] => (Allow) C:\Program Files (x86)\DigiOn\DiXiM Digital TV\DiXiM Digital TV.exe
FirewallRules: [{0BFFA7F7-3840-4985-9F4B-842411FB7B75}] => (Allow) C:\Program Files (x86)\DigiOn\DiXiM Digital TV\DiXiM Digital TV.exe
FirewallRules: [{3E5E81C1-8A74-4C30-9826-ED6FF56FB0C3}] => (Allow) C:\Program Files (x86)\DigiOn\DiXiM Digital TV\DiXiM4_Loader.exe
FirewallRules: [{3D773228-185A-431F-A936-57D1C3939542}] => (Allow) C:\Program Files (x86)\DigiOn\DiXiM Digital TV\DiXiM4_Loader.exe
FirewallRules: [{E59B38DD-4A4D-45DD-A34B-821244FAB0DF}] => (Allow) C:\Program Files (x86)\DigiOn\DiXiM Digital TV\DMRService.exe
FirewallRules: [{F0EA8ED1-BEB4-4E5F-A47F-103DB9140650}] => (Allow) C:\Program Files (x86)\DigiOn\DiXiM Digital TV\DMRService.exe
FirewallRules: [{4961DA00-C245-4C75-B661-A6DF8579043D}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{0551B4A2-E51A-4FF5-A396-4D161AF9511C}] => (Allow) LPort=2869
FirewallRules: [{05EAFB05-F3FA-4A8F-9B0E-410F61B1C3C1}] => (Allow) LPort=1900
FirewallRules: [TCP Query User{26BB823F-0CCE-4858-A24A-E05774EFA10B}C:\users\owner\appdata\roaming\dropbox\bin\dropbox.exe] => (Allow) C:\users\owner\appdata\roaming\dropbox\bin\dropbox.exe
FirewallRules: [UDP Query User{A69DD093-7CC6-4A7E-AD6F-3F031B3ED9B5}C:\users\owner\appdata\roaming\dropbox\bin\dropbox.exe] => (Allow) C:\users\owner\appdata\roaming\dropbox\bin\dropbox.exe
FirewallRules: [{8EBFC264-D642-419A-B381-808EAC65B27C}] => (Allow) C:\Program Files\AVAST Software\Avast\ng\vbox\aswFe.exe
FirewallRules: [{57D2CCA9-932A-4680-87D1-53DAFABDB59D}] => (Allow) C:\Program Files\AVAST Software\Avast\ng\vbox\aswFe.exe
FirewallRules: [{5744FFF6-88B3-4E41-95EF-624EFDF11B25}] => (Allow) C:\Users\Owner\AppData\Local\Temp\nswD28C.tmp\CnetInstaller-10661456.exe
FirewallRules: [{2D54BF80-C42A-435D-96B0-66FDA688C72C}] => (Allow) C:\Users\Owner\AppData\Local\Temp\nswD28C.tmp\CnetInstaller-10661456.exe
FirewallRules: [{3BA0033C-1850-41F9-AD44-A2E1728708E9}] => (Allow) C:\Users\Owner\AppData\Local\Temp\nshD02B.tmp\CnetInstaller-10661456.exe
FirewallRules: [{A4F1F5C8-A79D-4600-80A8-39B2BE6AC6BA}] => (Allow) C:\Users\Owner\AppData\Local\Temp\nshD02B.tmp\CnetInstaller-10661456.exe
FirewallRules: [{D7CF6FF0-0B3B-4665-B896-F149BD0760F5}] => (Allow) C:\Users\Owner\AppData\Local\Temp\nse9954.tmp\Installer-75984982.exe
FirewallRules: [{1E52DD3E-E7C9-4440-824A-BA911837F2CD}] => (Allow) C:\Users\Owner\AppData\Local\Temp\nse9954.tmp\Installer-75984982.exe
FirewallRules: [{2C8334E6-36EC-44B1-89C1-5A60713B0FA8}] => (Allow) C:\Users\Owner\AppData\Local\Temp\nsh3813.tmp\Installer-75338071.exe
FirewallRules: [{474644EB-C8C1-4C12-BD9D-9BEC833FAA73}] => (Allow) C:\Users\Owner\AppData\Local\Temp\nsh3813.tmp\Installer-75338071.exe
FirewallRules: [{C18CB8CF-F038-4A33-B5D5-03EFFE3AE4A7}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{99086BB3-136C-43B2-8A39-D5B47F4E740C}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{EF7FF7F5-B413-40B5-AE3E-8EF758CDDB62}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{D49F6CD5-C4C1-4B13-838A-451DCF9C1769}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{33E587F7-FA78-41AA-9BA5-3D4551BD9897}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{00846D1E-B76A-4217-893C-20B779682A43}] => (Allow) C:\Program Files (x86)\Trend Micro\DRScanner\sdk\TmDrMon.exe
FirewallRules: [TCP Query User{E0CE4CCD-08A0-48A5-B17C-8A49535991EC}C:\program files (x86)\trend micro\drscanner\nmap\nmap.exe] => (Block) C:\program files (x86)\trend micro\drscanner\nmap\nmap.exe
FirewallRules: [UDP Query User{86CA4D0F-8425-438C-8AC5-0FADB98C5DDF}C:\program files (x86)\trend micro\drscanner\nmap\nmap.exe] => (Block) C:\program files (x86)\trend micro\drscanner\nmap\nmap.exe
FirewallRules: [{85C3E591-4591-416C-85E8-7F2BC60849D7}] => (Allow) C:\Program Files (x86)\Trend Micro\DRScanner\sdk\TmDrMon.exe
FirewallRules: [{DA3FEAE5-262B-4B96-833E-A2C39D418979}] => (Allow) C:\Program Files (x86)\Trend Micro\DRScanner\sdk\TmDrMon.exe
FirewallRules: [{3588528A-C09A-44F9-93C1-10EB704168D4}] => (Allow) C:\Program Files (x86)\Trend Micro\DRScanner\sdk\TmDrMon.exe
FirewallRules: [{2E8D594F-4D5A-454C-8B35-30D4BCB774AE}] => (Allow) C:\Program Files (x86)\Trend Micro\DRScanner\sdk\TmDrMon.exe
FirewallRules: [{75F38206-EBFD-44FA-AB72-0AA6BD7131B0}] => (Allow) C:\Program Files (x86)\Trend Micro\DRScanner\sdk\TmDrMon.exe
FirewallRules: [{E68B3D8B-7722-48FA-A220-9623031A135A}] => (Allow) C:\Program Files (x86)\Trend Micro\DRScanner\sdk\TmDrMon.exe
FirewallRules: [{76C74324-EF72-40CB-BB1D-1CE873F05095}] => (Allow) C:\Program Files (x86)\Trend Micro\DRScanner\nmap\nmap.exe
FirewallRules: [{EDE5E8E6-DA77-4033-B185-B9472817CBD4}] => (Allow) C:\Program Files (x86)\Trend Micro\DRScanner\sdk\TmDrMon.exe
FirewallRules: [{BB5A09F5-A7AA-4F9E-A7DF-2237F507A2CC}] => (Allow) C:\Program Files (x86)\Trend Micro\DRScanner\sdk\TmDrMon.exe
FirewallRules: [{DA5FDB15-677F-4DC1-A8AB-C7EBCE6B4103}] => (Allow) C:\Program Files (x86)\Trend Micro\DRScanner\sdk\TmDrMon.exe
FirewallRules: [{F46E4584-C553-4C69-933D-FCF017967623}] => (Allow) C:\Program Files (x86)\Trend Micro\DRScanner\sdk\TmDrMon.exe
FirewallRules: [{C254A170-2FDE-4044-84D4-CCA5BF2D5E2F}] => (Allow) C:\Program Files (x86)\Trend Micro\DRScanner\sdk\TmDrMon.exe
FirewallRules: [{12EFCA5A-48BF-42CC-AC11-0C600FD00886}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{1717405C-A081-414B-88D4-1B866D25A27F}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{ECC7D8DC-7F83-49FB-AB73-F3957F8E79B0}C:\program files\mozilla firefox\firefox.exe] => (Block) C:\program files\mozilla firefox\firefox.exe
FirewallRules: [UDP Query User{19F05B98-7ED0-4638-B458-AE7A89784156}C:\program files\mozilla firefox\firefox.exe] => (Block) C:\program files\mozilla firefox\firefox.exe
FirewallRules: [{241B8820-8728-4DA2-B96B-995460711AA0}] => (Allow) C:\Program Files\AVAST Software\SZBrowser\4.58.2552.909\SZBrowser.exe
FirewallRules: [{F5727CE7-6E81-4A50-A719-8F233B596E99}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{46CAEDE1-D322-4752-A7BE-E362B58DC5C1}] => (Allow) C:\Program Files\AVAST Software\SZBrowser\4.58.2552.909_0\SZBrowser.exe
FirewallRules: [{64E70832-095E-488C-B6CA-814204B8E77F}] => (Allow) C:\Program Files\iTunes\iTunes.exe
FirewallRules: [{BB4674FB-B9B9-46DD-8027-DB6F018C2DCD}] => (Allow) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe

==================== Restore Points =========================

29-03-2017 08:29:42 Windows Update
08-04-2017 15:35:01 スケジュールされたチェックポイント
11-04-2017 20:11:00 インストールされている DirectX
11-04-2017 20:11:39 インストールされている DirectX
11-04-2017 20:12:20 インストールされている DirectX
11-04-2017 20:14:32 インストールされている DirectX
11-04-2017 20:14:46 インストールされている DirectX
11-04-2017 20:15:10 インストールされている DirectX
13-04-2017 01:01:21 Windows Update
14-04-2017 00:00:48 Windows Update
22-04-2017 13:05:54 スケジュールされたチェックポイント
29-04-2017 14:28:05 スケジュールされたチェックポイント
29-04-2017 22:39:18 Windows Update
09-05-2017 22:05:34 スケジュールされたチェックポイント
10-05-2017 07:47:04 Windows Update
11-05-2017 01:11:22 Windows Update
24-05-2017 01:06:04 Windows Update
02-06-2017 19:43:58 スケジュールされたチェックポイント
10-06-2017 10:57:53 スケジュールされたチェックポイント
15-06-2017 00:36:39 Windows Update
24-06-2017 17:21:37 スケジュールされたチェックポイント
02-07-2017 12:48:39 スケジュールされたチェックポイント
12-07-2017 18:44:17 Windows Update
22-07-2017 13:24:14 スケジュールされたチェックポイント
28-07-2017 18:40:22 Windows Update
06-08-2017 10:24:20 スケジュールされたチェックポイント
10-08-2017 00:32:00 Windows Update
17-08-2017 21:51:49 スケジュールされたチェックポイント
23-08-2017 07:39:57 Windows Update
24-08-2017 01:34:52 Windows Update
24-08-2017 07:47:51 Windows Update
25-08-2017 01:26:39 Windows Update
25-08-2017 07:44:59 Windows Update
26-08-2017 00:36:02 Windows Update
27-08-2017 01:36:58 Windows Update
03-09-2017 11:28:20 スケジュールされたチェックポイント
10-09-2017 10:51:27 JRT Pre-Junkware Removal
13-09-2017 07:44:06 Windows Update

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (09/10/2017 08:56:24 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: 障害が発生しているアプリケーション名: SecurityCheck.exe、バージョン: 1.4.0.0、タイム スタンプ: 0x4fc33fc1
障害が発生しているモジュール名: ntdll.dll、バージョン: 6.1.7601.23864、タイム スタンプ: 0x595fa490
例外コード: 0xc0000374
障害オフセット: 0x000ce8fb
障害が発生しているプロセス ID: 0x1818
障害が発生しているアプリケーションの開始時刻: 0x01d32a2bd3a7f4d6
障害が発生しているアプリケーション パス: C:\Users\Owner\Desktop\SecurityCheck.exe
障害が発生しているモジュール パス: C:\Windows\SysWOW64\ntdll.dll
レポート ID: 1162c7f8-961f-11e7-9110-267c8f273280

Error: (09/10/2017 08:56:11 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: 障害が発生しているアプリケーション名: SecurityCheck.exe、バージョン: 1.4.0.0、タイム スタンプ: 0x4fc33fc1
障害が発生しているモジュール名: ntdll.dll、バージョン: 6.1.7601.23864、タイム スタンプ: 0x595fa490
例外コード: 0xc0000374
障害オフセット: 0x000ce8fb
障害が発生しているプロセス ID: 0x1940
障害が発生しているアプリケーションの開始時刻: 0x01d32a2bcbaff98b
障害が発生しているアプリケーション パス: C:\Users\Owner\Desktop\SecurityCheck.exe
障害が発生しているモジュール パス: C:\Windows\SysWOW64\ntdll.dll
レポート ID: 096d2e0d-961f-11e7-9110-267c8f273280

Error: (09/10/2017 08:54:21 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: 障害が発生しているアプリケーション名: SecurityCheck.exe、バージョン: 1.4.0.0、タイム スタンプ: 0x4fc33fc1
障害が発生しているモジュール名: ntdll.dll、バージョン: 6.1.7601.23864、タイム スタンプ: 0x595fa490
例外コード: 0xc0000374
障害オフセット: 0x000ce8fb
障害が発生しているプロセス ID: 0x10ec
障害が発生しているアプリケーションの開始時刻: 0x01d32a2b89c7dff5
障害が発生しているアプリケーション パス: C:\Users\Owner\Desktop\SecurityCheck.exe
障害が発生しているモジュール パス: C:\Windows\SysWOW64\ntdll.dll
レポート ID: c7f75685-961e-11e7-9110-267c8f273280

Error: (09/07/2017 07:57:28 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: プログラム Explorer.EXE バージョン 6.1.7601.23537 は Windows との対話を停止し、終了しました。問題に関する詳細な情報があるかどうかを確認するには、アクション センター コントロール パネルで、問題の履歴をクリックしてください。

プロセス ID: 5d8

開始時刻: 01d327c752a3d948

終了時刻: 0

アプリケーション パス: C:\Windows\Explorer.EXE

レポート ID: 4bb96fea-93bb-11e7-b208-000d5eefdee2

Error: (09/04/2017 08:08:42 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: 障害が発生しているアプリケーション名: EXCEL.EXE、バージョン: 14.0.7183.5000、タイム スタンプ: 0x59450c3c
障害が発生しているモジュール名: EXCEL.EXE、バージョン: 14.0.7183.5000、タイム スタンプ: 0x59450c3c
例外コード: 0xc0000005
障害オフセット: 0x00197a5a
障害が発生しているプロセス ID: 0x15b4
障害が発生しているアプリケーションの開始時刻: 0x01d3256e266ff609
障害が発生しているアプリケーション パス: C:\PROGRA~2\MICROS~2\Office14\EXCEL.EXE
障害が発生しているモジュール パス: C:\PROGRA~2\MICROS~2\Office14\EXCEL.EXE
レポート ID: 68dce015-9161-11e7-b106-267c8f273280

Error: (09/02/2017 08:29:46 PM) (Source: Windows Search Service) (EventID: 7010) (User: )
Description: インデックスを初期化できませんでした。

詳細:
    コンテンツ インデックス カタログが破損しています。  (HRESULT : 0xc0041801) (0xc0041801)

Error: (09/02/2017 08:29:46 PM) (Source: Windows Search Service) (EventID: 3058) (User: )
Description: アプリケーションを初期化できませんでした。

コンテキスト: Windows アプリケーション

詳細:
    コンテンツ インデックス カタログが破損しています。  (HRESULT : 0xc0041801) (0xc0041801)

Error: (09/02/2017 08:29:46 PM) (Source: Windows Search Service) (EventID: 3028) (User: )
Description: Gatherer オブジェクトを初期化できませんでした。

コンテキスト: Windows アプリケーション、 SystemIndex カタログ

詳細:
    コンテンツ インデックス カタログが破損しています。  (HRESULT : 0xc0041801) (0xc0041801)

Error: (09/02/2017 08:29:46 PM) (Source: Windows Search Service) (EventID: 3029) (User: )
Description: <Search.TripoliIndexer> のプラグインを初期化できませんでした。

コンテキスト: Windows アプリケーション、 SystemIndex カタログ

詳細:
    要素が見つかりません。  (HRESULT : 0x80070490) (0x80070490)

Error: (09/02/2017 08:29:35 PM) (Source: Windows Search Service) (EventID: 3029) (User: )
Description: <Search.JetPropStore> のプラグインを初期化できませんでした。

コンテキスト: Windows アプリケーション、 SystemIndex カタログ

詳細:
    コンテンツ インデックス カタログが破損しています。  (HRESULT : 0xc0041801) (0xc0041801)


System errors:
=============
Error: (09/13/2017 06:41:47 AM) (Source: iaStor) (EventID: 9) (User: )
Description: デバイス \Device\Ide\iaStor0 はタイムアウト期間内に応答しませんでした。

Error: (09/11/2017 08:13:37 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: サーバー {4EB61BAC-A3B6-4760-9581-655041EF4D69} は、必要なタイムアウト期間内に DCOM に登録しませんでした。

Error: (09/11/2017 08:13:07 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Dropbox アップデート サービス (dbupdate) サービスを、次のエラーが原因で開始できませんでした:
そのサービスは指定時間内に開始要求または制御要求に応答しませんでした。

Error: (09/11/2017 08:13:07 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Dropbox アップデート サービス (dbupdate) サービスの接続を待機中にタイムアウト (30000 ミリ秒) になりました。

Error: (09/11/2017 06:42:19 AM) (Source: iaStor) (EventID: 9) (User: )
Description: デバイス \Device\Ide\iaStor0 はタイムアウト期間内に応答しませんでした。

Error: (09/10/2017 08:41:20 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: ホームネットワークサーバー powered by DiXiM サービスは予期せぬ原因により終了しました。このサービスの強制終了は 1 回目です。

Error: (09/10/2017 08:41:20 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Office Software Protection Platform サービスは予期せぬ原因により終了しました。このサービスの強制終了は 1 回目です。

Error: (09/10/2017 08:41:20 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: Intel® Management & Security Application User Notification Service サービスは予期せぬ原因により終了しました。このサービスの強制終了は 1 回目です。

Error: (09/10/2017 08:41:20 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: iPod サービス サービスは予期せぬ原因により終了しました。このサービスの強制終了は 1 回目です。

Error: (09/10/2017 08:41:20 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Windows Live ID Sign-in Assistant サービスは予期せぬ原因により終了しました。このサービスの終了は 1 回目です。次の修正操作が 10000 ミリ秒以内に実行されます: サービスの再開。


CodeIntegrity:
===================================
  Date: 2016-09-10 07:43:22.792
  Description: ページごとのイメージ ハッシュ セットをシステム上で検出できなかったため、コードの整合性ではファイル \Device\HarddiskVolume2\Windows\System32\drivers\aswKbd.sys のイメージの整合性を検証できません。

  Date: 2016-09-10 07:43:22.309
  Description: ページごとのイメージ ハッシュ セットをシステム上で検出できなかったため、コードの整合性ではファイル \Device\HarddiskVolume2\Windows\System32\drivers\aswSnx.sys のイメージの整合性を検証できません。

  Date: 2016-09-09 21:01:49.652
  Description: ページごとのイメージ ハッシュ セットをシステム上で検出できなかったため、コードの整合性ではファイル \Device\HarddiskVolume2\Windows\System32\drivers\aswKbd.sys のイメージの整合性を検証できません。

  Date: 2016-09-09 21:01:49.184
  Description: ページごとのイメージ ハッシュ セットをシステム上で検出できなかったため、コードの整合性ではファイル \Device\HarddiskVolume2\Windows\System32\drivers\aswSnx.sys のイメージの整合性を検証できません。

  Date: 2016-09-09 06:40:54.153
  Description: ページごとのイメージ ハッシュ セットをシステム上で検出できなかったため、コードの整合性ではファイル \Device\HarddiskVolume2\Windows\System32\drivers\aswKbd.sys のイメージの整合性を検証できません。

  Date: 2016-09-09 06:40:53.685
  Description: ページごとのイメージ ハッシュ セットをシステム上で検出できなかったため、コードの整合性ではファイル \Device\HarddiskVolume2\Windows\System32\drivers\aswSnx.sys のイメージの整合性を検証できません。

  Date: 2016-09-08 19:33:50.109
  Description: ページごとのイメージ ハッシュ セットをシステム上で検出できなかったため、コードの整合性ではファイル \Device\HarddiskVolume2\Windows\System32\drivers\aswKbd.sys のイメージの整合性を検証できません。

  Date: 2016-09-08 19:33:49.813
  Description: ページごとのイメージ ハッシュ セットをシステム上で検出できなかったため、コードの整合性ではファイル \Device\HarddiskVolume2\Windows\System32\drivers\aswSnx.sys のイメージの整合性を検証できません。

  Date: 2016-09-08 06:37:44.351
  Description: ページごとのイメージ ハッシュ セットをシステム上で検出できなかったため、コードの整合性ではファイル \Device\HarddiskVolume2\Windows\System32\drivers\aswKbd.sys のイメージの整合性を検証できません。

  Date: 2016-09-08 06:37:43.072
  Description: ページごとのイメージ ハッシュ セットをシステム上で検出できなかったため、コードの整合性ではファイル \Device\HarddiskVolume2\Windows\System32\drivers\aswSnx.sys のイメージの整合性を検証できません。


==================== Memory info ===========================

Processor: Intel® Core™ i5 CPU M 460 @ 2.53GHz
Percentage of memory in use: 57%
Total physical RAM: 3890.67 MB
Available physical RAM: 1641.93 MB
Total Virtual: 7779.53 MB
Available Virtual: 5629.04 MB

==================== Drives ================================

Drive c: (Windows 7) (Fixed) (Total:516.79 GB) (Free:290.69 GB) NTFS ==>[system with boot components (obtained from drive)]
Drive d: () (Fixed) (Total:65.19 GB) (Free:65.02 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 596.2 GB) (Disk ID: C5DC075B)
Partition 1: (Active) - (Size=1.9 GB) - (Type=27)
Partition 2: (Not Active) - (Size=516.8 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=65.2 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=12.3 GB) - (Type=27)

==================== End of Addition.txt ============================

 

What is next? Thanks in advance.


Edited by Glenski, 13 September 2017 - 06:40 AM.


BC AdBot (Login to Remove)

 


#2 HelpBot

HelpBot

    Bleepin' Binary Bot


  • Bots
  • 12,699 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:07:05 AM

Posted 18 September 2017 - 06:05 AM

Hello and welcome to Bleeping Computer!

I am HelpBot: an automated program designed to help the Bleeping Computer Staff better assist you! This message contains very important information, so please read through all of it before doing anything.

We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.

To help Bleeping Computer better assist you please perform the following steps:

***************************************************

step1.gif In order to continue receiving help at BleepingComputer.com, YOU MUST tell me if you still need help or if your issue has already been resolved on your own or through another resource! To tell me this, please click on the following link and follow the instructions there.

CLICK THIS LINK >>> https://www.bleepingcomputer.com/logreply/657154 <<< CLICK THIS LINK



If you no longer need help, then all you needed to do was the previous instructions of telling me so. You can skip the rest of this post. If you do need help please continue with Step 2 below.

***************************************************

step2.gifIf you still need help, I would like you to post a Reply to this topic (click the "Add Reply" button in the lower right hand of this page). In that reply, please include the following information:

  • If you have not done so already, include a clear description of the problems you're having, along with any steps you may have performed so far.
  • A new FRST log. For your convenience, you will find the instructions for generating these logs repeated at the bottom of this post.
    • Please do this even if you have previously posted logs for us.
    • If you were unable to produce the logs originally please try once more.
    • If you are unable to create a log please provide detailed information about your installed Windows Operating System including the Version, Edition and if it is a 32bit or a 64bit system.
    • If you are unsure about any of these characteristics just post what you can and we will guide you.
  • Please tell us if you have your original Windows CD/DVD available.
  • Upon completing the above steps and posting a reply, another staff member will review your topic and do their best to resolve your issues.

Thank you for your patience, and again sorry for the delay.

***************************************************

We need to see some information about what is happening in your machine. Please perform the following scan again:

  • Download FRST by Farbar from the following link if you no longer have it available and save it to your destop.

    FRST Download Link

  • When you go to the above page, there will be 32-bit and 64-bit downloads available. Please click on the appropriate one for your version of Windows. If you are unsure as to whether your Windows is 32-bit or 64-bit, please see this tutorial.
  • Double click on the FRST icon and allow it to run.
  • Agree to the usage agreement and FRST will open. Do not make any changes and click on the Scan button.
  • Notepad will open with the results.
  • Post the new logs as explained in the prep guide.
  • Close the program window, and delete the program from your desktop.


As I am just a silly little program running on the BleepingComputer.com servers, please do not send me private messages as I do not know how to read and reply to them! Thanks!

#3 HelpBot

HelpBot

    Bleepin' Binary Bot


  • Bots
  • 12,699 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:07:05 AM

Posted 21 September 2017 - 07:31 PM

You have stated that you no longer need help with this issue, therefore I am closing this topic. If that is not the case and you need or wish to continue with this topic, please send any Moderator a Personal Message (PM) that you would like this topic re-opened.

As I am just a silly little program running on the BleepingComputer.com servers, please do not send me private messages as I do not know how to read and reply to them! Thanks!





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users