Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Everything is running slow


  • This topic is locked This topic is locked
10 replies to this topic

#1 Mugga

Mugga

  • Members
  • 12 posts
  • OFFLINE
  •  
  • Local time:12:00 AM

Posted 23 September 2017 - 06:19 PM

So I just got this laptop from my brother. I was told that it has a bunch of viruses and its been slow for awhile. I was checking things out and I tried doing what I could. I also see there is a website about rubiconproject or something that keeps trying to load but not sure if its a virus.

 

Here is the logs:

 

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 23-09-2017 02
Ran by Joey (administrator) on JOEY-PC (23-09-2017 19:07:46)
Running from C:\Users\Joey\Downloads
Loaded Profiles: Joey (Available Profiles: UpdatusUser & Joey)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Creative Technology Ltd) C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Antivirus\AVGSvc.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Amazon Inc.) C:\Program Files (x86)\Amazon\Amazon1ButtonApp\Amazon1ButtonService64.Exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
(CyberDefender Corp.) C:\Program Files (x86)\CyberDefender\SchedulerService\SchedulerService.exe
(Creative Technology Ltd) C:\Windows\SysWOW64\CtHdaSvc.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Intel® Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\Jhi_service.exe
(Intel® Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(SoftThinks SAS) C:\Program Files (x86)\AlienRespawn\SftService.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
() C:\Program Files (x86)\ScreenSnapshotTool\1.1.0.11414\ScreenShotServ.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
() C:\Program Files (x86)\ScreenSnapshotTool\1.1.0.11414\ScreenSnapshot.exe
(SoftThinks - Dell) C:\Program Files (x86)\AlienRespawn\Toaster.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
() C:\Program Files (x86)\AlienRespawn\Components\Scheduler\STService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(SoftThinks - Dell) C:\Program Files (x86)\AlienRespawn\Components\DSUpdate\DSUpd.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel® Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Antivirus\avgui.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
() C:\Program Files (x86)\Alienware On-Screen Display\AlienwareOn-ScreenDisplay.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avguix.exe
(Alienware) C:\Program Files\Alienware\Command Center\AlienFusionService.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Antivirus\x64\aswidsagenta.exe
(Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
(Intel® Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
(Dell Inc.) C:\Program Files (x86)\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe
(Alienware) C:\Program Files\Alienware\Command Center\AlienFusionController.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation.) C:\Program Files (x86)\Microsoft\BingBar\7.3.124.0\SeaPort.EXE
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Alienware) C:\Program Files\Alienware\Command Center\AlienwareAlienFXController.exe
(Alienware) C:\Program Files\Alienware\Command Center\AWCCServiceController.exe
(Alienware) C:\Program Files\Alienware\Command Center\AWCCApplicationWatcher32.exe
(Alienware) C:\Program Files\Alienware\Command Center\AWCCApplicationWatcher64.exe
 
==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [IntelPROSet] => C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [4756240 2012-02-26] (Intel® Corporation)
HKLM\...\Run: [] => [X]
HKLM\...\Run: [AvgUi] => C:\Program Files (x86)\AVG\Framework\Common\avguirna.exe [239592 2017-09-14] (AVG Technologies CZ, s.r.o.)
HKLM\...\Run: [AVGUI.exe] => C:\Program Files (x86)\AVG\Antivirus\AvLaunch.exe [289248 2017-09-22] (AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-02-17] (Intel Corporation)
HKLM-x32\...\Run: [AlienwareOn-ScreenDisplay] => C:\Program Files (x86)\Alienware On-Screen Display\AlienwareOn-ScreenDisplay.exe [1546096 2011-11-03] ()
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [596504 2016-04-01] (Oracle Corporation)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-21-1979518111-4107658783-1214925503-1001\...\Run: [Chromium] => c:\users\joey\appdata\local\chromium\application\chrome.exe [828416 2017-01-23] (The Chromium Authors)
HKU\S-1-5-18\...\RunOnce: [SpUninstallDeleteDir] => rmdir /s /q "\SearchProtect"
GroupPolicy: Restriction - Chrome <==== ATTENTION
GroupPolicy\User: Restriction <==== ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
ProxyEnable: [.DEFAULT] => Proxy is enabled.
ProxyServer: [.DEFAULT] => http=127.0.0.1:53080;https=127.0.0.1:53080
Tcpip\Parameters: [DhcpNameServer] 75.75.75.75 75.75.76.76
Tcpip\Parameters: [NameServer] 82.163.143.171 82.163.142.173
Tcpip\..\Interfaces\{9CFA72D9-1DFA-47B0-9348-9B2C94035F3B}: [DhcpNameServer] 75.75.75.75 75.75.76.76
 
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617910&ResetID=131505282322592410&GUID=00000000-0000-0000-0000-000000000000
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617910&ResetID=131505282322602411&GUID=00000000-0000-0000-0000-000000000000
HKU\S-1-5-21-1979518111-4107658783-1214925503-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617910&ResetID=131505282322622412&GUID=00000000-0000-0000-0000-000000000000
HKU\S-1-5-21-1979518111-4107658783-1214925503-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://AlienwareArena.com
SearchScopes: HKLM -> DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2465} URL = 
SearchScopes: HKLM -> {2f23ab71-4ac6-41f2-a955-ea576e553146} URL = hxxps://us.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_dnldstr_16_15&param1=1&param2=f%3D4%26b%3DIE%26cc%3Dus%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1Qzu0DyE0B0E0DzytBzz0E0D0E0AtD0D0E0CtN0D0Tzu0StCyDyCtBtN1L2XzutAtFtBtDtFtDtFtDtN1L1Czu1BtAtN1L1G1B1V1N2Y1L1Qzu2StD0EyC0DyB0D0A0CtGyCzyyD0AtG0DyDtB0FtGtAtD0DtCtGtA0DyBtByDyByDzytA0DtA0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0FzyyDyD0FzzyBtAtGtCtBtCtAtGyEzzzy0BtG0B0C0C0FtGyCtAyBzyyCtCzz0CzytB0A0E2QtN0A0LzuyE%26cr%3D1845538279%26a%3Dwbf_dnldstr_16_15%26os_ver%3D6.1%26os%3DWindows%2B7%2BHome%2BPremium&p={searchTerms}
SearchScopes: HKLM -> {44A02DE0-F784-4FA5-B9D3-33C6F8ECA78A} URL = hxxps://us.search.yahoo.com/yhs/search?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_dnldstr_16_15&param1=1&param2=f%3D4%26b%3DIE%26cc%3Dus%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1Qzu0DyE0B0E0DzytBzz0E0D0E0AtD0D0E0CtN0D0Tzu0StCyDyCtBtN1L2XzutAtFtBtDtFtDtFtDtN1L1Czu1BtAtN1L1G1B1V1N2Y1L1Qzu2StD0EyC0DyB0D0A0CtGyCzyyD0AtG0DyDtB0FtGtAtD0DtCtGtA0DyBtByDyByDzytA0DtA0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0FzyyDyD0FzzyBtAtGtCtBtCtAtGyEzzzy0BtG0B0C0C0FtGyCtAyBzyyCtCzz0CzytB0A0E2QtN0A0LzuyE%26cr%3D1845538279%26a%3Dwbf_dnldstr_16_15%26os_ver%3D6.1%26os%3DWindows%2B7%2BHome%2BPremium&p={searchTerms}
SearchScopes: HKLM -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = 
SearchScopes: HKLM -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2465} URL = 
SearchScopes: HKLM-x32 -> DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2465} URL = 
SearchScopes: HKLM-x32 -> {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = 
SearchScopes: HKU\.DEFAULT -> {AC5AB133-CD93-49D2-B821-D9F3E020989E} URL = 
SearchScopes: HKU\S-1-5-21-1979518111-4107658783-1214925503-1001 -> DefaultScope {44A02DE0-F784-4FA5-B9D3-33C6F8ECA78A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
SearchScopes: HKU\S-1-5-21-1979518111-4107658783-1214925503-1001 -> {2f23ab71-4ac6-41f2-a955-ea576e553146} URL = hxxps://search.yahoo.com/search?p={searchTerms}&fr=chr-yset_ie_syc_oracle&type=orcl_default
SearchScopes: HKU\S-1-5-21-1979518111-4107658783-1214925503-1001 -> {44A02DE0-F784-4FA5-B9D3-33C6F8ECA78A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
SearchScopes: HKU\S-1-5-21-1979518111-4107658783-1214925503-1001 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = 
SearchScopes: HKU\S-1-5-21-1979518111-4107658783-1214925503-1001 -> {B3B3A6AC-74EC-BD56-BCDB-EFA4799FB9DF} URL = hxxps://www.amazon.com/gp/bit/amazonserp/ref=bit_bds-p10_serp_ie_us_display?ie=UTF8&tagbase=bds-p10&tbrId=v1_abb-channel-10_8b40eee8_1201_1401_20160411_US_ie_ds_&tag=bds-p10-serp-us-ie-20&query={searchTerms}
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-05-11] (Google Inc.)
BHO: Bing Bar Helper -> {d2ce3e00-f94a-4740-988e-03dc2f38c34f} -> C:\Program Files (x86)\Microsoft\BingBar\7.3.124.0\amd64\BingExt.dll [2013-12-16] (Microsoft Corporation.)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\ssv.dll [2016-05-11] (Oracle Corporation)
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2016-05-11] (Google Inc.)
BHO-x32: Free Download Manager -> {CC59E0F9-7E43-44FA-9FAA-8377850BF205} -> C:\Program Files (x86)\Free Download Manager\iefdm2.dll [2013-10-25] (FreeDownloadManager.ORG)
BHO-x32: Bing Bar Helper -> {d2ce3e00-f94a-4740-988e-03dc2f38c34f} -> C:\Program Files (x86)\Microsoft\BingBar\7.3.124.0\BingExt.dll [2013-12-16] (Microsoft Corporation.)
BHO-x32: No Name -> {D4027C7F-154A-4066-A1AD-4243D8127440} -> No File
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\jp2ssv.dll [2016-05-11] (Oracle Corporation)
BHO-x32: No Name -> {EF7BD87A-8024-11E2-F316-F3E56188709B} -> No File
Toolbar: HKLM - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.124.0\amd64\BingExt.dll [2013-12-16] (Microsoft Corporation.)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-05-11] (Google Inc.)
Toolbar: HKLM-x32 - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.124.0\BingExt.dll [2013-12-16] (Microsoft Corporation.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2016-05-11] (Google Inc.)
Toolbar: HKU\S-1-5-21-1979518111-4107658783-1214925503-1001 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-05-11] (Google Inc.)
Toolbar: HKU\S-1-5-21-1979518111-4107658783-1214925503-1001 -> No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} -  No File
Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\17.3.0\ViProtocol.dll No File
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
 
FireFox:
========
FF ProfilePath: C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default [2017-09-23]
FF DefaultSearchEngine: Mozilla\Firefox\Profiles\zt8k3d39.default -> YHS
FF SearchEngineOrder.1: Mozilla\Firefox\Profiles\zt8k3d39.default -> Web Search
FF SelectedSearchEngine: Mozilla\Firefox\Profiles\zt8k3d39.default -> YHS
FF Homepage: Mozilla\Firefox\Profiles\zt8k3d39.default -> hxxps://us.search.yahoo.com/yhs/web?hspart=iry&hsimp=yhs-fullyhosted_003&type=wbf_dnldstr_16_15&param1=1&param2=f%3D1%26b%3DFirefox%26cc%3Dus%26pa%3DWincy%26cd%3D2XzuyEtN2Y1L1Qzu0DyE0B0E0DzytBzz0E0D0E0AtD0D0E0CtN0D0Tzu0StCyDyCtBtN1L2XzutAtFtBtDtFtDtFtDtN1L1Czu1BtAtN1L1G1B1V1N2Y1L1Qzu2StD0EyC0DyB0D0A0CtGyCzyyD0AtG0DyDtB0FtGtAtD0DtCtGtA0DyBtByDyByDzytA0DtA0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0FzyyDyD0FzzyBtAtGtCtBtCtAtGyEzzzy0BtG0B0C0C0FtGyCtAyBzyyCtCzz0CzytB0A0E2QtN0A0LzuyE%26cr%3D1845538279%26a%3Dwbf_dnldstr_16_15%26os_ver%3D6.1%26os%3DWindows%2B7%2BHome%2BPremium
FF SearchPlugin: C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\searchplugins\Search Provided by Yahoo.xml [2016-04-11]
FF SearchPlugin: C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\searchplugins\yhs.xml [2017-09-23]
FF HKU\S-1-5-21-1979518111-4107658783-1214925503-1001\...\Firefox\Extensions: [{b64982b1-d112-42b5-b1e4-d3867c4533f8}] - C:\ProgramData\PC Performer Manager\2.2.558.177\{16cdff19-861d-48e3-a751-d99a27784753}\FirefoxExtension => not found
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\safeguard-secure-search.xml [2014-01-07]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_27_0_0_130.dll [2017-09-22] ()
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_27_0_0_130.dll [2017-09-22] ()
FF Plugin-x32: @avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin -> C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\17.3.0\\npsitesafety.dll [No File]
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-02-01] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-02-01] (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.91.2 -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\dtplugin\npDeployJava1.dll [2016-05-11] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.91.2 -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\plugin2\npjp2.dll [2016-05-11] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL [2011-04-05] (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2012-03-04] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2012-03-04] (NVIDIA Corporation)
FF Plugin-x32: @oberon-media.com/ONCAdapter -> C:\Program Files (x86)\Common Files\Oberon Media\NCAdapter\1.0.0.7\npapicomadapter.dll [2010-09-01] (Oberon-Media )
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-09-21] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-09-21] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2015-09-24] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-1979518111-4107658783-1214925503-1001: @tnt2toolbar.com/Plugin -> C:\Users\Joey\AppData\Local\TNT2\2.0.0.1194\npTNT2.dll [No File]
FF Plugin HKU\S-1-5-21-1979518111-4107658783-1214925503-1001: thehappycloud.com/HappyCloudPlugin -> C:\ProgramData\HappyCloud\Application\npHappyCloudPlugin.dll [2013-01-03] (The Happy Cloud)
StartMenuInternet: FIREFOX.EXE - firefox.exe
 
Chrome: 
=======
CHR DefaultProfile: Default
CHR HomePage: Default -> amazon.com/websearch/?ie=UTF8__PARAM__
CHR Profile: C:\Users\Joey\AppData\Local\Google\Chrome\User Data\Default [2017-09-23]
CHR Extension: (Google Drive) - C:\Users\Joey\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-12-20]
CHR Extension: (Surf Canyon) - C:\Users\Joey\AppData\Local\Google\Chrome\User Data\Default\Extensions\bcjagnifjocnddgeknajocbkkhlgibem [2014-02-09] [UpdateUrl: hxxp://www.surfcanyon.com/chrome_update.xml] <==== ATTENTION
CHR Extension: (hTab) - C:\Users\Joey\AppData\Local\Google\Chrome\User Data\Default\Extensions\elmkjjfkkchohaaoljobaffjeedcoocj [2017-09-21]
CHR Extension: (Google Docs Offline) - C:\Users\Joey\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-04-06]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Joey\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-09-22]
CHR Extension: (Chrome Media Router) - C:\Users\Joey\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-09-22]
CHR HKLM\...\Chrome\Extension: [bahkljhhdeciiaodlkppoonappfnheoi] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM\...\Chrome\Extension: [elmkjjfkkchohaaoljobaffjeedcoocj] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-1979518111-4107658783-1214925503-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [bahkljhhdeciiaodlkppoonappfnheoi] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-1979518111-4107658783-1214925503-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [elmkjjfkkchohaaoljobaffjeedcoocj] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-1979518111-4107658783-1214925503-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [ooebgdicanjhnamfmdlmlbcnkgehkkmf] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-1979518111-4107658783-1214925503-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [pbjikboenpfhbbejgkoklgkhjpfogcam] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [ajimflpekochgkclpjepklfnkhcbbcpk] - <no Path/update_url>
CHR HKLM-x32\...\Chrome\Extension: [bahkljhhdeciiaodlkppoonappfnheoi] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [bcjagnifjocnddgeknajocbkkhlgibem] - C:\Program Files (x86)\Chrome\surfcanyon.crx [2012-06-19]
CHR HKLM-x32\...\Chrome\Extension: [dedmngkbaffkenlfdcbganndoghblmap] - <no Path/update_url>
CHR HKLM-x32\...\Chrome\Extension: [ejhdkifcpnleafenajdjbeikplkooglk] - <no Path/update_url>
CHR HKLM-x32\...\Chrome\Extension: [elmkjjfkkchohaaoljobaffjeedcoocj] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [fjdbddblhompbdadaenlghkegihdcoai] - <no Path/update_url>
CHR HKLM-x32\...\Chrome\Extension: [gihfmmedoddijgnhkgfgnkeohkpbipol] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [jgjpaakpifnhoaffblomkffniknfjllm] - <no Path/update_url>
CHR HKLM-x32\...\Chrome\Extension: [jlhjpacphahiiolhpgaemifichemekjp] - <no Path/update_url>
CHR HKLM-x32\...\Chrome\Extension: [khpfgegklcpadnogmhlcklcjbfjlgeai] - <no Path/update_url>
CHR HKLM-x32\...\Chrome\Extension: [lghnoihgonbodhaobhfcjhjmndoeaaae] - <no Path/update_url>
CHR HKLM-x32\...\Chrome\Extension: [liifpfhlakkjeobbcedbhcanogdcdjpn] - C:\Users\Joey\AppData\Local\TidyNetwork.com\tidy.crx <not found>
CHR HKLM-x32\...\Chrome\Extension: [mbckjcfnjmoiinpgddefodcighgikkgn] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [poheodfamflhhhdcmjfeggbgigeefaco] - <no Path/update_url>
 
==================== Services (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 Amazon 1Button App Service; C:\Program Files (x86)\Amazon\Amazon1ButtonApp\Amazon1ButtonService64.Exe [436032 2016-02-17] (Amazon Inc.)
R2 AVG Antivirus; C:\Program Files (x86)\AVG\Antivirus\AVGSvc.exe [276328 2017-09-22] (AVG Technologies CZ, s.r.o.)
R3 avgbIDSAgent; C:\Program Files (x86)\AVG\Antivirus\x64\aswidsagenta.exe [7502936 2017-09-22] (AVG Technologies CZ, s.r.o.)
R2 avgsvc; C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe [1428656 2017-09-14] (AVG Technologies CZ, s.r.o.)
R2 CDScheduler; C:\Program Files (x86)\CyberDefender\SchedulerService\SchedulerService.exe [735352 2012-03-26] (CyberDefender Corp.)
S3 Creative ALchemy AL6 Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [79360 2012-05-12] (Creative Labs) [File not signed]
S3 Creative Audio Engine Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [79360 2012-05-12] (Creative Labs) [File not signed]
R2 CTAudSvcService; c:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe [423424 2011-10-19] (Creative Technology Ltd) [File not signed]
R2 CtHdaSvc; C:\Windows\sysWow64\CtHdaSvc.exe [122880 2012-03-27] (Creative Technology Ltd)
S2 DellDataVault; C:\Program Files\Dell\DellDataVault\DellDataVault.exe [2571352 2016-01-05] (Dell Inc.)
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [73728 2004-10-22] (Macrovision Corporation) [File not signed]
R2 jhi_service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe [161560 2012-02-01] (Intel Corporation)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [273168 2012-02-26] ()
S3 npggsvc; C:\Windows\SysWOW64\GameMon.des [5267776 2014-01-22] (INCA Internet Co., Ltd.)
R2 SupportAssistAgent; C:\Program Files (x86)\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe [31928 2016-04-22] (Dell Inc.)
R2 TheScreenSnapshotService; C:\Program Files (x86)\ScreenSnapshotTool\1.1.0.11414\ScreenShotServ.exe [152688 2016-06-07] ()
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
S2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [2669840 2012-02-26] (Intel® Corporation)
S2 vToolbarUpdater17.3.0; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\17.3.0\ToolbarUpdater.exe [X]
 
===================== Drivers (Whitelisted) ======================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R1 avgbdisk; C:\Windows\system32\drivers\avgbdiska.sys [166624 2017-09-22] (AVG Technologies CZ, s.r.o.)
R1 avgbidsdriver; C:\Windows\system32\drivers\avgbidsdrivera.sys [314128 2017-09-22] (AVG Technologies CZ, s.r.o.)
R0 avgbidsh; C:\Windows\system32\drivers\avgbidsha.sys [192584 2017-09-22] (AVG Technologies CZ, s.r.o.)
R0 avgblog; C:\Windows\system32\drivers\avgbloga.sys [336896 2017-09-22] (AVG Technologies CZ, s.r.o.)
R0 avgbuniv; C:\Windows\system32\drivers\avgbuniva.sys [51336 2017-09-22] (AVG Technologies CZ, s.r.o.)
S3 avgHwid; C:\Windows\system32\drivers\avgHwid.sys [39424 2017-09-22] (AVG Technologies CZ, s.r.o.)
R2 avgMonFlt; C:\Windows\system32\drivers\avgMonFlt.sys [140192 2017-09-22] (AVG Technologies CZ, s.r.o.)
R1 avgRdr; C:\Windows\system32\drivers\avgRdr2.sys [102792 2017-09-22] (AVG Technologies CZ, s.r.o.)
R0 avgRvrt; C:\Windows\system32\drivers\avgRvrt.sys [76832 2017-09-22] (AVG Technologies CZ, s.r.o.)
R1 avgSnx; C:\Windows\system32\drivers\avgSnx.sys [1008800 2017-09-22] (AVG Technologies CZ, s.r.o.)
R1 avgSP; C:\Windows\system32\drivers\avgSP.sys [583288 2017-09-22] (AVG Technologies CZ, s.r.o.)
R2 avgStm; C:\Windows\system32\drivers\avgStm.sys [191720 2017-09-22] (AVG Technologies CZ, s.r.o.)
R1 avgtp; C:\Windows\system32\drivers\avgtpx64.sys [46368 2013-11-12] (AVG Technologies)
R0 avgVmm; C:\Windows\system32\drivers\avgVmm.sys [353744 2017-09-22] (AVG Technologies CZ, s.r.o.)
R3 cthda; C:\Windows\System32\drivers\cthda.sys [1052760 2012-03-27] (Creative Technology Ltd)
S3 DDDriver; C:\Windows\System32\drivers\DDDriver64Dcsa.sys [32464 2015-09-11] (Dell Computer Corporation)
S3 DellProf; C:\Windows\System32\drivers\DellProf.sys [24240 2015-05-22] (Dell Computer Corporation)
R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [498512 2015-12-19] (Symantec Corporation)
R1 nvkflt; C:\Windows\System32\DRIVERS\nvkflt.sys [249152 2012-03-04] (NVIDIA Corporation)
R3 Sftfs; C:\Windows\System32\DRIVERS\Sftfswin7.sys [767648 2014-10-08] (Microsoft Corporation)
R3 Sftplay; C:\Windows\System32\DRIVERS\Sftplaywin7.sys [273576 2014-10-08] (Microsoft Corporation)
R3 Sftredir; C:\Windows\System32\DRIVERS\Sftredirwin7.sys [29864 2014-10-08] (Microsoft Corporation)
R3 Sftvol; C:\Windows\System32\DRIVERS\Sftvolwin7.sys [23208 2014-10-08] (Microsoft Corporation)
R3 ST_ACCEL; C:\Windows\System32\DRIVERS\ST_ACCEL.sys [67184 2012-01-03] (STMicroelectronics)
S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X]
S3 MBAMSwissArmy; \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2017-09-23 19:07 - 2017-09-23 19:09 - 000027634 _____ C:\Users\Joey\Downloads\FRST.txt
2017-09-23 19:07 - 2017-09-23 19:07 - 000000000 ____D C:\FRST
2017-09-23 19:06 - 2017-09-23 19:07 - 002399744 _____ (Farbar) C:\Users\Joey\Downloads\FRST64.exe
2017-09-22 23:49 - 2017-09-22 23:49 - 000000000 ____D C:\Users\Joey\AppData\Roaming\AVG
2017-09-22 23:47 - 2017-09-23 18:16 - 000004178 _____ C:\Windows\System32\Tasks\Antivirus Emergency Update
2017-09-22 23:47 - 2017-09-22 23:48 - 000191720 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgstm.sys
2017-09-22 23:47 - 2017-09-22 23:47 - 001008800 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgSnx.sys
2017-09-22 23:47 - 2017-09-22 23:47 - 000583288 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgSP.sys
2017-09-22 23:47 - 2017-09-22 23:47 - 000402608 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\avgBoot.exe
2017-09-22 23:47 - 2017-09-22 23:47 - 000353744 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgVmm.sys
2017-09-22 23:47 - 2017-09-22 23:47 - 000336896 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgbloga.sys
2017-09-22 23:47 - 2017-09-22 23:47 - 000314128 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgbidsdrivera.sys
2017-09-22 23:47 - 2017-09-22 23:47 - 000192584 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgbidsha.sys
2017-09-22 23:47 - 2017-09-22 23:47 - 000166624 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgbdiska.sys
2017-09-22 23:47 - 2017-09-22 23:47 - 000140192 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgMonFlt.sys
2017-09-22 23:47 - 2017-09-22 23:47 - 000102792 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgRdr2.sys
2017-09-22 23:47 - 2017-09-22 23:47 - 000076832 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgRvrt.sys
2017-09-22 23:47 - 2017-09-22 23:47 - 000051336 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgbuniva.sys
2017-09-22 23:47 - 2017-09-22 23:47 - 000039424 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgHwid.sys
2017-09-22 23:45 - 2017-09-22 23:45 - 000001008 _____ C:\Users\Public\Desktop\AVG.lnk
2017-09-22 23:45 - 2017-09-22 23:45 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
2017-09-22 23:44 - 2017-09-22 23:44 - 000003600 _____ C:\Windows\System32\Tasks\AVG EUpdate Task
2017-09-22 23:43 - 2017-09-22 23:45 - 000000000 ____D C:\Program Files (x86)\AVG
2017-09-22 18:21 - 2017-09-22 18:38 - 000003504 _____ C:\Windows\System32\Tasks\PCDEventLauncherTask
2017-09-22 18:21 - 2017-09-22 18:21 - 000004040 _____ C:\Windows\System32\Tasks\PCDoctorBackgroundMonitorTask
2017-09-22 18:21 - 2017-09-22 18:21 - 000003342 _____ C:\Windows\System32\Tasks\PCDDataUploadTask
2017-09-22 18:21 - 2017-09-22 18:21 - 000003216 _____ C:\Windows\System32\Tasks\SystemToolsDailyTest
2017-09-22 18:20 - 2017-09-22 18:20 - 000000000 ____D C:\ProgramData\PC-Doctor for Windows
2017-09-22 18:15 - 2017-09-22 18:15 - 000000000 ____D C:\ProgramData\PC-Doctor, Inc
2017-09-22 05:03 - 2017-09-22 05:03 - 003449304 _____ (AVG Technologies CZ, s.r.o.) C:\Users\Joey\Downloads\AVG_Protection_Free_1606 (1).exe
2017-09-22 03:10 - 2017-04-27 18:50 - 003550208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_47.dll
2017-09-22 03:10 - 2017-04-12 09:05 - 004296704 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_47.dll
2017-09-22 00:30 - 2017-09-22 00:30 - 000001044 _____ C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2017-09-22 00:21 - 2016-07-07 11:08 - 000046080 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpipreg.sys
2017-09-22 00:21 - 2016-03-16 14:50 - 000156672 _____ (Microsoft Corporation) C:\Windows\system32\mtxoci.dll
2017-09-22 00:21 - 2016-03-16 14:28 - 000176128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msorcl32.dll
2017-09-22 00:21 - 2016-03-16 14:28 - 000111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mtxoci.dll
2017-09-22 00:20 - 2017-05-03 11:34 - 000094952 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe
2017-09-22 00:20 - 2017-05-03 11:29 - 001206272 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2017-09-22 00:20 - 2017-05-03 09:05 - 001555968 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2017-09-22 00:20 - 2017-05-03 09:05 - 000620544 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2017-09-22 00:20 - 2017-05-03 09:05 - 000535552 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2017-09-22 00:20 - 2017-05-03 09:05 - 000325632 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2017-09-22 00:20 - 2017-05-03 09:05 - 000311296 _____ (Microsoft Corporation) C:\Windows\system32\centel.dll
2017-09-22 00:20 - 2017-05-03 09:05 - 000217088 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2017-09-22 00:20 - 2017-05-03 09:05 - 000127488 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2017-09-22 00:20 - 2017-03-22 22:06 - 001691136 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe
2017-09-22 00:20 - 2016-05-12 11:18 - 000090624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\olepro32.dll
2017-09-22 00:20 - 2016-05-11 13:02 - 000483840 _____ (Microsoft Corporation) C:\Windows\system32\StructuredQuery.dll
2017-09-22 00:20 - 2016-05-11 11:19 - 000363520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\StructuredQuery.dll
2017-09-22 00:20 - 2016-01-20 20:51 - 000073664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\disk.sys
2017-09-22 00:19 - 2017-08-16 10:57 - 003224576 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2017-09-22 00:19 - 2017-08-15 21:10 - 000395976 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2017-09-22 00:19 - 2017-08-15 20:25 - 000347336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2017-09-22 00:19 - 2017-08-15 10:06 - 015260160 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2017-09-22 00:19 - 2017-08-15 10:01 - 000416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2017-09-22 00:19 - 2017-08-15 10:01 - 000279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2017-09-22 00:19 - 2017-08-15 10:01 - 000076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2017-09-22 00:19 - 2017-08-15 09:58 - 013673984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2017-09-22 00:19 - 2017-08-13 14:58 - 025730560 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2017-09-22 00:19 - 2017-08-13 13:24 - 002724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2017-09-22 00:19 - 2017-08-13 13:24 - 000004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2017-09-22 00:19 - 2017-08-13 13:06 - 000066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2017-09-22 00:19 - 2017-08-13 13:05 - 000576512 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2017-09-22 00:19 - 2017-08-13 13:05 - 000417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2017-09-22 00:19 - 2017-08-13 13:05 - 000088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2017-09-22 00:19 - 2017-08-13 13:05 - 000048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2017-09-22 00:19 - 2017-08-13 13:04 - 002899968 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2017-09-22 00:19 - 2017-08-13 12:56 - 000054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2017-09-22 00:19 - 2017-08-13 12:55 - 000034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2017-09-22 00:19 - 2017-08-13 12:54 - 020269056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2017-09-22 00:19 - 2017-08-13 12:52 - 000615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2017-09-22 00:19 - 2017-08-13 12:51 - 005981696 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2017-09-22 00:19 - 2017-08-13 12:51 - 000144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2017-09-22 00:19 - 2017-08-13 12:51 - 000116224 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2017-09-22 00:19 - 2017-08-13 12:50 - 000817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2017-09-22 00:19 - 2017-08-13 12:50 - 000814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2017-09-22 00:19 - 2017-08-13 12:46 - 002724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2017-09-22 00:19 - 2017-08-13 12:41 - 000968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2017-09-22 00:19 - 2017-08-13 12:38 - 000489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2017-09-22 00:19 - 2017-08-13 12:30 - 000062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2017-09-22 00:19 - 2017-08-13 12:29 - 000499200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2017-09-22 00:19 - 2017-08-13 12:29 - 000341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2017-09-22 00:19 - 2017-08-13 12:29 - 000087552 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2017-09-22 00:19 - 2017-08-13 12:29 - 000077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2017-09-22 00:19 - 2017-08-13 12:29 - 000047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2017-09-22 00:19 - 2017-08-13 12:28 - 000064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2017-09-22 00:19 - 2017-08-13 12:27 - 000107520 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2017-09-22 00:19 - 2017-08-13 12:24 - 002291200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2017-09-22 00:19 - 2017-08-13 12:24 - 000199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2017-09-22 00:19 - 2017-08-13 12:23 - 000092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2017-09-22 00:19 - 2017-08-13 12:22 - 000047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2017-09-22 00:19 - 2017-08-13 12:21 - 000030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2017-09-22 00:19 - 2017-08-13 12:20 - 000315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2017-09-22 00:19 - 2017-08-13 12:19 - 000476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2017-09-22 00:19 - 2017-08-13 12:17 - 000663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2017-09-22 00:19 - 2017-08-13 12:17 - 000620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2017-09-22 00:19 - 2017-08-13 12:17 - 000115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2017-09-22 00:19 - 2017-08-13 12:07 - 000262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2017-09-22 00:19 - 2017-08-13 12:04 - 000807936 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2017-09-22 00:19 - 2017-08-13 12:04 - 000726528 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2017-09-22 00:19 - 2017-08-13 12:02 - 001359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2017-09-22 00:19 - 2017-08-13 12:01 - 002134528 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2017-09-22 00:19 - 2017-08-13 12:01 - 000073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2017-09-22 00:19 - 2017-08-13 12:01 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2017-09-22 00:19 - 2017-08-13 12:00 - 000091136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2017-09-22 00:19 - 2017-08-13 11:57 - 000168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2017-09-22 00:19 - 2017-08-13 11:53 - 000130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2017-09-22 00:19 - 2017-08-13 11:48 - 004547072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2017-09-22 00:19 - 2017-08-13 11:46 - 000230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2017-09-22 00:19 - 2017-08-13 11:44 - 000694784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2017-09-22 00:19 - 2017-08-13 11:43 - 002058752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2017-09-22 00:19 - 2017-08-13 11:43 - 001155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2017-09-22 00:19 - 2017-08-13 11:40 - 003241472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2017-09-22 00:19 - 2017-08-13 11:27 - 001544704 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2017-09-22 00:19 - 2017-08-13 11:18 - 000800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2017-09-22 00:19 - 2017-08-13 11:17 - 002767872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2017-09-22 00:19 - 2017-08-13 11:14 - 000710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2017-09-22 00:19 - 2017-08-13 11:13 - 001314816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2017-09-22 00:19 - 2017-08-11 02:38 - 005547752 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2017-09-22 00:19 - 2017-08-11 02:36 - 001732864 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2017-09-22 00:19 - 2017-08-11 02:35 - 002065408 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll
2017-09-22 00:19 - 2017-07-21 10:26 - 000518144 _____ C:\Windows\SysWOW64\msjetoledb40.dll
2017-09-22 00:19 - 2017-07-21 10:26 - 000290816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msjtes40.dll
2017-09-22 00:19 - 2017-07-14 11:29 - 002319872 _____ (Microsoft Corporation) C:\Windows\system32\tquery.dll
2017-09-22 00:19 - 2017-07-14 11:29 - 002222080 _____ (Microsoft Corporation) C:\Windows\system32\mssrch.dll
2017-09-22 00:19 - 2017-07-14 11:29 - 002058240 _____ (Microsoft Corporation) C:\Windows\system32\Query.dll
2017-09-22 00:19 - 2017-07-14 11:10 - 001549824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tquery.dll
2017-09-22 00:19 - 2017-07-14 11:10 - 001400320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssrch.dll
2017-09-22 00:19 - 2017-07-14 11:10 - 001363968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Query.dll
2017-09-22 00:19 - 2017-07-07 11:29 - 001143296 _____ (Microsoft Corporation) C:\Windows\system32\DXPTaskRingtone.dll
2017-09-22 00:19 - 2017-07-07 11:10 - 000973312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DXPTaskRingtone.dll
2017-09-22 00:19 - 2017-07-01 09:05 - 001311744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msjet40.dll
2017-09-22 00:19 - 2017-07-01 09:05 - 000616448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrepl40.dll
2017-09-22 00:19 - 2017-07-01 09:05 - 000475648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxbde40.dll
2017-09-22 00:19 - 2017-07-01 09:05 - 000375808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mspbde40.dll
2017-09-22 00:19 - 2017-07-01 09:05 - 000343552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrd3x40.dll
2017-09-22 00:19 - 2017-07-01 09:05 - 000339968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msexcl40.dll
2017-09-22 00:19 - 2017-07-01 09:05 - 000310272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrd2x40.dll
2017-09-22 00:19 - 2017-07-01 09:05 - 000240640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msltus40.dll
2017-09-22 00:19 - 2017-06-09 11:33 - 001680616 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2017-09-22 00:19 - 2017-05-30 00:56 - 001895656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2017-09-22 00:19 - 2017-05-12 12:25 - 001251328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2017-09-22 00:19 - 2017-05-12 11:58 - 001648128 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2017-09-22 00:19 - 2017-05-12 11:58 - 001180160 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2017-09-22 00:19 - 2017-05-10 11:29 - 003165184 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2017-09-22 00:19 - 2017-05-10 11:29 - 000192512 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2017-09-22 00:19 - 2017-05-10 11:29 - 000098816 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2017-09-22 00:19 - 2017-05-10 11:28 - 000091136 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2017-09-22 00:19 - 2017-05-10 11:14 - 002651136 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2017-09-22 00:19 - 2017-05-10 11:13 - 000709120 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2017-09-22 00:19 - 2017-05-10 11:13 - 000140288 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2017-09-22 00:19 - 2017-05-10 11:13 - 000037888 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2017-09-22 00:19 - 2017-05-10 11:13 - 000037888 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2017-09-22 00:19 - 2017-05-10 11:13 - 000036864 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2017-09-22 00:19 - 2017-05-10 11:13 - 000012288 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
2017-09-22 00:19 - 2017-05-10 11:12 - 000174080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2017-09-22 00:19 - 2017-05-10 11:00 - 000573440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2017-09-22 00:19 - 2017-05-10 11:00 - 000093696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2017-09-22 00:19 - 2017-05-10 11:00 - 000035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2017-09-22 00:19 - 2017-04-12 11:32 - 001483776 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2017-09-22 00:19 - 2017-03-03 21:27 - 001574912 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll
2017-09-22 00:19 - 2017-01-18 11:36 - 000994760 _____ (Microsoft Corporation) C:\Windows\system32\ucrtbase.dll
2017-09-22 00:19 - 2017-01-18 11:36 - 000063840 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-private-l1-1-0.dll
2017-09-22 00:19 - 2017-01-18 11:36 - 000020832 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-math-l1-1-0.dll
2017-09-22 00:19 - 2017-01-18 11:36 - 000019808 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-multibyte-l1-1-0.dll
2017-09-22 00:19 - 2017-01-18 11:36 - 000017760 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-string-l1-1-0.dll
2017-09-22 00:19 - 2017-01-18 11:36 - 000017760 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-stdio-l1-1-0.dll
2017-09-22 00:19 - 2017-01-18 11:36 - 000016224 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-runtime-l1-1-0.dll
2017-09-22 00:19 - 2017-01-18 11:36 - 000015712 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-convert-l1-1-0.dll
2017-09-22 00:19 - 2017-01-18 11:36 - 000014176 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-time-l1-1-0.dll
2017-09-22 00:19 - 2017-01-18 11:36 - 000014176 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-2-0.dll
2017-09-22 00:19 - 2017-01-18 11:36 - 000013664 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll
2017-09-22 00:19 - 2017-01-18 11:36 - 000012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-process-l1-1-0.dll
2017-09-22 00:19 - 2017-01-18 11:36 - 000012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-heap-l1-1-0.dll
2017-09-22 00:19 - 2017-01-18 11:36 - 000012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-conio-l1-1-0.dll
2017-09-22 00:19 - 2017-01-18 11:36 - 000012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-utility-l1-1-0.dll
2017-09-22 00:19 - 2017-01-18 11:36 - 000012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-locale-l1-1-0.dll
2017-09-22 00:19 - 2017-01-18 11:36 - 000012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-environment-l1-1-0.dll
2017-09-22 00:19 - 2017-01-18 11:36 - 000012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-2-0.dll
2017-09-22 00:19 - 2017-01-18 11:36 - 000012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-1.dll
2017-09-22 00:19 - 2017-01-18 11:36 - 000011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l2-1-0.dll
2017-09-22 00:19 - 2017-01-18 11:36 - 000011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-timezone-l1-1-0.dll
2017-09-22 00:19 - 2017-01-18 11:36 - 000011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l2-1-0.dll
2017-09-22 00:19 - 2017-01-18 11:36 - 000011608 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-2-0.dll
2017-09-22 00:19 - 2017-01-18 11:35 - 000922432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ucrtbase.dll
2017-09-22 00:19 - 2017-01-18 11:35 - 000066400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-private-l1-1-0.dll
2017-09-22 00:19 - 2017-01-18 11:35 - 000022368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-math-l1-1-0.dll
2017-09-22 00:19 - 2017-01-18 11:35 - 000019808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-multibyte-l1-1-0.dll
2017-09-22 00:19 - 2017-01-18 11:35 - 000017760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-string-l1-1-0.dll
2017-09-22 00:19 - 2017-01-18 11:35 - 000017760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-stdio-l1-1-0.dll
2017-09-22 00:19 - 2017-01-18 11:35 - 000016224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-runtime-l1-1-0.dll
2017-09-22 00:19 - 2017-01-18 11:35 - 000015712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-convert-l1-1-0.dll
2017-09-22 00:19 - 2017-01-18 11:35 - 000014176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-time-l1-1-0.dll
2017-09-22 00:19 - 2017-01-18 11:35 - 000014176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-2-0.dll
2017-09-22 00:19 - 2017-01-18 11:35 - 000013664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-filesystem-l1-1-0.dll
2017-09-22 00:19 - 2017-01-18 11:35 - 000012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-process-l1-1-0.dll
2017-09-22 00:19 - 2017-01-18 11:35 - 000012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-heap-l1-1-0.dll
2017-09-22 00:19 - 2017-01-18 11:35 - 000012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-conio-l1-1-0.dll
2017-09-22 00:19 - 2017-01-18 11:35 - 000012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-utility-l1-1-0.dll
2017-09-22 00:19 - 2017-01-18 11:35 - 000012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-locale-l1-1-0.dll
2017-09-22 00:19 - 2017-01-18 11:35 - 000012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-environment-l1-1-0.dll
2017-09-22 00:19 - 2017-01-18 11:35 - 000012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-2-0.dll
2017-09-22 00:19 - 2017-01-18 11:35 - 000012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-1.dll
2017-09-22 00:19 - 2017-01-18 11:35 - 000011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l2-1-0.dll
2017-09-22 00:19 - 2017-01-18 11:35 - 000011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-timezone-l1-1-0.dll
2017-09-22 00:19 - 2017-01-18 11:35 - 000011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l2-1-0.dll
2017-09-22 00:19 - 2017-01-18 11:35 - 000011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-2-0.dll
2017-09-22 00:19 - 2017-01-11 14:01 - 001887744 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2017-09-22 00:19 - 2017-01-11 13:43 - 001241088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2017-09-22 00:19 - 2016-11-09 12:33 - 003244032 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2017-09-22 00:19 - 2016-11-09 12:17 - 002365440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2017-09-22 00:19 - 2016-10-07 11:32 - 003649536 _____ (Microsoft Corporation) C:\Windows\system32\MSVidCtl.dll
2017-09-22 00:19 - 2016-10-07 11:12 - 002291712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSVidCtl.dll
2017-09-22 00:19 - 2016-09-15 10:56 - 000041984 _____ (Microsoft Corporation) C:\Windows\system32\UtcResources.dll
2017-09-22 00:19 - 2016-08-22 12:19 - 001386496 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll
2017-09-22 00:19 - 2016-08-12 13:02 - 014632960 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2017-09-22 00:19 - 2016-08-12 12:47 - 011410432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2017-09-22 00:19 - 2016-08-06 11:31 - 002023424 _____ (Microsoft Corporation) C:\Windows\system32\WsmSvc.dll
2017-09-22 00:19 - 2016-08-06 11:15 - 001178112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmSvc.dll
2017-09-22 00:19 - 2016-06-14 13:16 - 004121600 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2017-09-22 00:19 - 2016-06-14 13:16 - 001202176 _____ (Microsoft Corporation) C:\Windows\system32\drmv2clt.dll
2017-09-22 00:19 - 2016-06-14 13:16 - 000842240 _____ (Microsoft Corporation) C:\Windows\system32\blackbox.dll
2017-09-22 00:19 - 2016-06-14 11:21 - 003209216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll
2017-09-22 00:19 - 2016-06-14 11:21 - 000988160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drmv2clt.dll
2017-09-22 00:19 - 2016-06-14 11:21 - 000744960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\blackbox.dll
2017-09-22 00:18 - 2017-08-19 11:28 - 000197120 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll
2017-09-22 00:18 - 2017-08-19 11:10 - 000180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll
2017-09-22 00:18 - 2017-08-16 11:29 - 000806912 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll
2017-09-22 00:18 - 2017-08-16 11:10 - 000629760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll
2017-09-22 00:18 - 2017-08-15 11:29 - 014182400 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2017-09-22 00:18 - 2017-08-15 11:29 - 001867264 _____ (Microsoft Corporation) C:\Windows\system32\ExplorerFrame.dll
2017-09-22 00:18 - 2017-08-15 11:10 - 012880896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2017-09-22 00:18 - 2017-08-15 11:10 - 001499648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ExplorerFrame.dll
2017-09-22 00:18 - 2017-08-14 13:35 - 003203584 _____ (Microsoft Corporation) C:\Windows\system32\mmcndmgr.dll
2017-09-22 00:18 - 2017-08-14 13:35 - 002150912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mmcndmgr.dll
2017-09-22 00:18 - 2017-08-14 13:35 - 000355328 _____ (Microsoft Corporation) C:\Windows\system32\mmcbase.dll
2017-09-22 00:18 - 2017-08-14 13:35 - 000303104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mmcbase.dll
2017-09-22 00:18 - 2017-08-14 13:35 - 000172544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cic.dll
2017-09-22 00:18 - 2017-08-14 13:35 - 000131072 _____ (Microsoft Corporation) C:\Windows\system32\mmcshext.dll
2017-09-22 00:18 - 2017-08-14 13:35 - 000128512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mmcshext.dll
2017-09-22 00:18 - 2017-08-14 13:34 - 000211968 _____ (Microsoft Corporation) C:\Windows\system32\cic.dll
2017-09-22 00:18 - 2017-08-13 17:37 - 002144256 _____ (Microsoft Corporation) C:\Windows\system32\mmc.exe
2017-09-22 00:18 - 2017-08-13 17:30 - 001401344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mmc.exe
2017-09-22 00:18 - 2017-08-13 12:18 - 000152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2017-09-22 00:18 - 2017-08-11 02:42 - 000631176 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2017-09-22 00:18 - 2017-08-11 02:38 - 000706792 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2017-09-22 00:18 - 2017-08-11 02:38 - 000154856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2017-09-22 00:18 - 2017-08-11 02:38 - 000095464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2017-09-22 00:18 - 2017-08-11 02:35 - 001212928 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2017-09-22 00:18 - 2017-08-11 02:35 - 000757248 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll
2017-09-22 00:18 - 2017-08-11 02:35 - 000512000 _____ (Microsoft Corporation) C:\Windows\system32\rpcss.dll
2017-09-22 00:18 - 2017-08-11 02:35 - 000503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2017-09-22 00:18 - 2017-08-11 02:35 - 000362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2017-09-22 00:18 - 2017-08-11 02:35 - 000346112 _____ (Microsoft Corporation) C:\Windows\system32\ntprint.dll
2017-09-22 00:18 - 2017-08-11 02:35 - 000345600 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2017-09-22 00:18 - 2017-08-11 02:35 - 000313856 _____ (Microsoft Corporation) C:\Windows\system32\Wldap32.dll
2017-09-22 00:18 - 2017-08-11 02:35 - 000243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2017-09-22 00:18 - 2017-08-11 02:35 - 000215552 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2017-09-22 00:18 - 2017-08-11 02:35 - 000210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2017-09-22 00:18 - 2017-08-11 02:35 - 000190464 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll
2017-09-22 00:18 - 2017-08-11 02:35 - 000135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2017-09-22 00:18 - 2017-08-11 02:35 - 000086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2017-09-22 00:18 - 2017-08-11 02:35 - 000063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2017-09-22 00:18 - 2017-08-11 02:35 - 000050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2017-09-22 00:18 - 2017-08-11 02:35 - 000028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2017-09-22 00:18 - 2017-08-11 02:35 - 000028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2017-09-22 00:18 - 2017-08-11 02:35 - 000026112 _____ (Microsoft Corporation) C:\Windows\system32\oleres.dll
2017-09-22 00:18 - 2017-08-11 02:35 - 000026112 _____ (Microsoft Corporation) C:\Windows\system32\nsisvc.dll
2017-09-22 00:18 - 2017-08-11 02:35 - 000025600 _____ (Microsoft Corporation) C:\Windows\system32\winnsi.dll
2017-09-22 00:18 - 2017-08-11 02:35 - 000016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2017-09-22 00:18 - 2017-08-11 02:35 - 000013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2017-09-22 00:18 - 2017-08-11 02:35 - 000013312 _____ (Microsoft Corporation) C:\Windows\system32\nsi.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 001460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 001163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 000971776 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 000880640 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 000731648 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 000690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 000463872 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 000419840 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 000316928 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 000312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 000166400 _____ (Microsoft Corporation) C:\Windows\system32\inetpp.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 000146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 000123904 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 000060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 000059904 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 000044032 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 000043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 000034816 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 000022528 _____ (Microsoft Corporation) C:\Windows\system32\inetppui.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 000022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 000008704 _____ (Microsoft Corporation) C:\Windows\system32\comcat.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 000006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 000006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 000005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 000004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 000004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:24 - 004001000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2017-09-22 00:18 - 2017-08-11 02:24 - 003945704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2017-09-22 00:18 - 2017-08-11 02:21 - 001314112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2017-09-22 00:18 - 2017-08-11 02:20 - 000061952 _____ (Microsoft Corporation) C:\Windows\system32\ntprint.exe
2017-09-22 00:18 - 2017-08-11 02:20 - 000048640 _____ (Microsoft Corporation) C:\Windows\system32\wpnpinst.exe
2017-09-22 00:18 - 2017-08-11 02:19 - 001417728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 001114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000666112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000644096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000554496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000497664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000299008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntprint.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000275456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000271360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Wldap32.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000261120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000254464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcrypt.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000026112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleres.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000016384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winnsi.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000008704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nsi.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:12 - 000025088 _____ (Microsoft Corporation) C:\Windows\system32\netbtugc.exe
2017-09-22 00:18 - 2017-08-11 02:09 - 000061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntprint.exe
2017-09-22 00:18 - 2017-08-11 02:07 - 000148480 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2017-09-22 00:18 - 2017-08-11 02:07 - 000062464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2017-09-22 00:18 - 2017-08-11 02:07 - 000017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2017-09-22 00:18 - 2017-08-11 02:06 - 000064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2017-09-22 00:18 - 2017-08-11 02:03 - 000338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2017-09-22 00:18 - 2017-08-11 02:03 - 000026624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netbtugc.exe
2017-09-22 00:18 - 2017-08-11 02:02 - 000296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2017-09-22 00:18 - 2017-08-11 02:01 - 000007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comcat.dll
2017-09-22 00:18 - 2017-08-11 02:00 - 000262656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netbt.sys
2017-09-22 00:18 - 2017-08-11 02:00 - 000159744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2017-09-22 00:18 - 2017-08-11 02:00 - 000050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2017-09-22 00:18 - 2017-08-11 01:59 - 000460800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys
2017-09-22 00:18 - 2017-08-11 01:59 - 000405504 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys
2017-09-22 00:18 - 2017-08-11 01:59 - 000291328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2017-09-22 00:18 - 2017-08-11 01:59 - 000168448 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys
2017-09-22 00:18 - 2017-08-11 01:59 - 000129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2017-09-22 00:18 - 2017-08-11 01:58 - 000112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2017-09-22 00:18 - 2017-08-11 01:58 - 000030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2017-09-22 00:18 - 2017-08-11 01:58 - 000026112 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\nsiproxy.sys
2017-09-22 00:18 - 2017-08-11 01:56 - 000025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2017-09-22 00:18 - 2017-08-11 01:56 - 000014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2017-09-22 00:18 - 2017-08-11 01:56 - 000007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2017-09-22 00:18 - 2017-08-11 01:56 - 000002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2017-09-22 00:18 - 2017-08-11 01:55 - 000036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
2017-09-22 00:18 - 2017-08-11 01:55 - 000006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 01:55 - 000004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 01:55 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 01:55 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2017-09-22 00:18 - 2017-07-29 10:56 - 000117248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys
2017-09-22 00:18 - 2017-07-21 10:26 - 000409600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msexch40.dll
2017-09-22 00:18 - 2017-07-21 10:26 - 000282624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstext40.dll
2017-09-22 00:18 - 2017-07-14 11:29 - 000778240 _____ (Microsoft Corporation) C:\Windows\system32\mssvp.dll
2017-09-22 00:18 - 2017-07-14 11:29 - 000491520 _____ (Microsoft Corporation) C:\Windows\system32\mssph.dll
2017-09-22 00:18 - 2017-07-14 11:29 - 000486400 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
2017-09-22 00:18 - 2017-07-14 11:29 - 000288256 _____ (Microsoft Corporation) C:\Windows\system32\mssphtb.dll
2017-09-22 00:18 - 2017-07-14 11:29 - 000115200 _____ (Microsoft Corporation) C:\Windows\system32\mssitlb.dll
2017-09-22 00:18 - 2017-07-14 11:29 - 000099840 _____ (Microsoft Corporation) C:\Windows\system32\mssprxy.dll
2017-09-22 00:18 - 2017-07-14 11:29 - 000075264 _____ (Microsoft Corporation) C:\Windows\system32\msscntrs.dll
2017-09-22 00:18 - 2017-07-14 11:29 - 000034304 _____ (Microsoft Corporation) C:\Windows\system32\werdiagcontroller.dll
2017-09-22 00:18 - 2017-07-14 11:29 - 000014336 _____ (Microsoft Corporation) C:\Windows\system32\msshooks.dll
2017-09-22 00:18 - 2017-07-14 11:12 - 000591872 _____ (Microsoft Corporation) C:\Windows\system32\SearchIndexer.exe
2017-09-22 00:18 - 2017-07-14 11:12 - 000249856 _____ (Microsoft Corporation) C:\Windows\system32\SearchProtocolHost.exe
2017-09-22 00:18 - 2017-07-14 11:11 - 000113664 _____ (Microsoft Corporation) C:\Windows\system32\SearchFilterHost.exe
2017-09-22 00:18 - 2017-07-14 11:10 - 000666624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssvp.dll
2017-09-22 00:18 - 2017-07-14 11:10 - 000382976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll
2017-09-22 00:18 - 2017-07-14 11:10 - 000337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssph.dll
2017-09-22 00:18 - 2017-07-14 11:10 - 000197120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssphtb.dll
2017-09-22 00:18 - 2017-07-14 11:10 - 000104448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssitlb.dll
2017-09-22 00:18 - 2017-07-14 11:10 - 000059392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msscntrs.dll
2017-09-22 00:18 - 2017-07-14 11:10 - 000034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssprxy.dll
2017-09-22 00:18 - 2017-07-14 11:00 - 000427520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchIndexer.exe
2017-09-22 00:18 - 2017-07-14 11:00 - 000164352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchProtocolHost.exe
2017-09-22 00:18 - 2017-07-14 10:59 - 000086528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchFilterHost.exe
2017-09-22 00:18 - 2017-07-14 10:59 - 000009728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msshooks.dll
2017-09-22 00:18 - 2017-07-14 10:57 - 000050688 _____ (Microsoft Corporation) C:\Windows\system32\wermgr.exe
2017-09-22 00:18 - 2017-07-14 10:50 - 000054272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wermgr.exe
2017-09-22 00:18 - 2017-07-14 10:50 - 000028672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\werdiagcontroller.dll
2017-09-22 00:18 - 2017-07-08 11:34 - 000370920 _____ (Microsoft Corporation) C:\Windows\system32\clfs.sys
2017-09-22 00:18 - 2017-07-07 11:33 - 000363752 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\volmgrx.sys
2017-09-22 00:18 - 2017-07-07 11:29 - 000149504 _____ (Microsoft Corporation) C:\Windows\system32\t2embed.dll
2017-09-22 00:18 - 2017-07-07 11:11 - 000109568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\t2embed.dll
2017-09-22 00:18 - 2017-07-06 00:56 - 000119296 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bthpan.sys
2017-09-22 00:18 - 2017-07-01 09:05 - 000866816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswdat10.dll
2017-09-22 00:18 - 2017-07-01 09:05 - 000641536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswstr10.dll
2017-09-22 00:18 - 2017-07-01 09:05 - 000144896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msjint40.dll
2017-09-22 00:18 - 2017-07-01 09:05 - 000083968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msjter40.dll
2017-09-22 00:18 - 2017-06-15 16:23 - 000753664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys
2017-09-22 00:18 - 2017-06-12 18:49 - 001363456 _____ (Microsoft Corporation) C:\Windows\system32\wdc.dll
2017-09-22 00:18 - 2017-06-12 18:49 - 000594432 _____ (Microsoft Corporation) C:\Windows\system32\wvc.dll
2017-09-22 00:18 - 2017-06-12 18:49 - 000475136 _____ (Microsoft Corporation) C:\Windows\system32\sysmon.ocx
2017-09-22 00:18 - 2017-06-12 18:49 - 000058880 _____ (Microsoft Corporation) C:\Windows\system32\pdhui.dll
2017-09-22 00:18 - 2017-06-12 18:29 - 001227264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdc.dll
2017-09-22 00:18 - 2017-06-12 18:29 - 000444928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wvc.dll
2017-09-22 00:18 - 2017-06-12 18:29 - 000390144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sysmon.ocx
2017-09-22 00:18 - 2017-06-12 18:28 - 000047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pdhui.dll
2017-09-22 00:18 - 2017-06-12 18:14 - 000379392 _____ (Microsoft Corporation) C:\Windows\system32\msinfo32.exe
2017-09-22 00:18 - 2017-06-12 18:14 - 000172544 _____ (Microsoft Corporation) C:\Windows\system32\perfmon.exe
2017-09-22 00:18 - 2017-06-12 18:14 - 000103936 _____ (Microsoft Corporation) C:\Windows\system32\resmon.exe
2017-09-22 00:18 - 2017-06-12 18:06 - 000303616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msinfo32.exe
2017-09-22 00:18 - 2017-06-12 18:06 - 000157184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\perfmon.exe
2017-09-22 00:18 - 2017-06-12 18:06 - 000103424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\resmon.exe
2017-09-22 00:18 - 2017-06-02 04:10 - 000733696 _____ (Microsoft Corporation) C:\Windows\HelpPane.exe
2017-09-22 00:18 - 2017-05-30 00:56 - 000377576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys
2017-09-22 00:18 - 2017-05-30 00:56 - 000287976 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS
2017-09-22 00:18 - 2017-05-21 00:24 - 000002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2017-09-22 00:18 - 2017-05-21 00:06 - 000002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2017-09-22 00:18 - 2017-05-16 11:35 - 000986856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2017-09-22 00:18 - 2017-05-16 11:35 - 000265448 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys
2017-09-22 00:18 - 2017-05-16 11:30 - 000144384 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll
2017-09-22 00:18 - 2017-05-12 14:26 - 000382696 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2017-09-22 00:18 - 2017-05-12 14:22 - 000405504 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2017-09-22 00:18 - 2017-05-12 14:22 - 000100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2017-09-22 00:18 - 2017-05-12 14:22 - 000046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2017-09-22 00:18 - 2017-05-12 14:22 - 000041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2017-09-22 00:18 - 2017-05-12 14:22 - 000014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2017-09-22 00:18 - 2017-05-12 14:07 - 000308456 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2017-09-22 00:18 - 2017-05-12 14:03 - 000313344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2017-09-22 00:18 - 2017-05-12 14:03 - 000070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2017-09-22 00:18 - 2017-05-12 14:03 - 000025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
2017-09-22 00:18 - 2017-05-12 14:03 - 000010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
2017-09-22 00:18 - 2017-05-12 13:43 - 000034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2017-09-22 00:18 - 2017-05-10 11:33 - 000091368 _____ (Microsoft Corporation) C:\Windows\system32\MigAutoPlay.exe
2017-09-22 00:18 - 2017-05-10 11:16 - 000091368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MigAutoPlay.exe
2017-09-22 00:18 - 2017-05-10 11:00 - 000030208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2017-09-22 00:18 - 2017-05-07 11:33 - 000094440 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mountmgr.sys
2017-09-22 00:18 - 2017-05-07 11:29 - 000011264 _____ (Microsoft Corporation) C:\Windows\system32\msmmsp.dll
2017-09-22 00:18 - 2017-04-21 11:34 - 001133568 _____ (Microsoft Corporation) C:\Windows\system32\cdosys.dll
2017-09-22 00:18 - 2017-04-21 11:15 - 000805376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2017-09-22 00:18 - 2017-04-17 11:37 - 000876544 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll
2017-09-22 00:18 - 2017-04-17 11:12 - 000581632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll
2017-09-22 00:18 - 2017-04-12 11:32 - 000229376 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2017-09-22 00:18 - 2017-04-12 11:32 - 000190976 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2017-09-22 00:18 - 2017-04-12 11:32 - 000141824 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2017-09-22 00:18 - 2017-04-12 11:26 - 000179200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2017-09-22 00:18 - 2017-04-12 11:25 - 001176064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2017-09-22 00:18 - 2017-04-12 11:25 - 000145920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2017-09-22 00:18 - 2017-04-12 11:25 - 000106496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2017-09-22 00:18 - 2017-04-04 10:53 - 000496128 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2017-09-22 00:18 - 2017-03-30 11:03 - 000046080 _____ (Microsoft Corporation) C:\Windows\system32\rundll32.exe
2017-09-22 00:18 - 2017-03-30 10:58 - 000045056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
2017-09-22 00:18 - 2017-03-10 12:32 - 001389056 _____ (Microsoft Corporation) C:\Windows\system32\pla.dll
2017-09-22 00:18 - 2017-03-10 12:32 - 000300544 _____ (Microsoft Corporation) C:\Windows\system32\pdh.dll
2017-09-22 00:18 - 2017-03-10 12:20 - 001508352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pla.dll
2017-09-22 00:18 - 2017-03-10 12:20 - 000237056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pdh.dll
2017-09-22 00:18 - 2017-03-10 11:57 - 000009216 _____ (Microsoft Corporation) C:\Windows\system32\plasrv.exe
2017-09-22 00:18 - 2017-03-10 11:55 - 000205312 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fastfat.sys
2017-09-22 00:18 - 2017-03-10 11:55 - 000195584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\exfat.sys
2017-09-22 00:18 - 2017-03-07 12:30 - 000085504 _____ (Microsoft Corporation) C:\Windows\system32\asycfilt.dll
2017-09-22 00:18 - 2017-03-07 12:17 - 000067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\asycfilt.dll
2017-09-22 00:18 - 2017-03-03 21:27 - 000093696 _____ (Microsoft Corporation) C:\Windows\system32\mfmjpegdec.dll
2017-09-22 00:18 - 2017-03-03 21:14 - 001329664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quartz.dll
2017-09-22 00:18 - 2017-03-03 21:14 - 000077312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfmjpegdec.dll
2017-09-22 00:18 - 2017-02-09 12:32 - 000769536 _____ (Microsoft Corporation) C:\Windows\system32\samsrv.dll
2017-09-22 00:18 - 2017-02-09 12:32 - 000106496 _____ (Microsoft Corporation) C:\Windows\system32\samlib.dll
2017-09-22 00:18 - 2017-02-09 12:32 - 000040960 _____ (Microsoft Corporation) C:\Windows\system32\WcsPlugInService.dll
2017-09-22 00:18 - 2017-02-09 12:31 - 000625664 _____ (Microsoft Corporation) C:\Windows\system32\mscms.dll
2017-09-22 00:18 - 2017-02-09 12:31 - 000250880 _____ (Microsoft Corporation) C:\Windows\system32\icm32.dll
2017-09-22 00:18 - 2017-02-09 12:14 - 000481792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscms.dll
2017-09-22 00:18 - 2017-02-09 12:14 - 000215040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icm32.dll
2017-09-22 00:18 - 2017-02-09 12:14 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\samlib.dll
2017-09-22 00:18 - 2017-02-09 11:51 - 000032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WcsPlugInService.dll
2017-09-22 00:18 - 2017-01-13 14:00 - 000976896 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll
2017-09-22 00:18 - 2017-01-13 14:00 - 000084480 _____ (Microsoft Corporation) C:\Windows\system32\INETRES.dll
2017-09-22 00:18 - 2017-01-13 13:45 - 000741888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll
2017-09-22 00:18 - 2017-01-13 13:45 - 000084480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\INETRES.dll
2017-09-22 00:18 - 2017-01-11 14:01 - 000002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2017-09-22 00:18 - 2017-01-11 13:43 - 000002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2017-09-22 00:18 - 2016-11-21 14:12 - 000109568 _____ (Microsoft Corporation) C:\Windows\system32\hlink.dll
2017-09-22 00:18 - 2016-11-20 12:19 - 000084992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\hlink.dll
2017-09-22 00:18 - 2016-11-20 10:07 - 000467392 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2017-09-22 00:18 - 2016-11-10 12:32 - 001009152 _____ (Microsoft Corporation) C:\Windows\system32\user32.dll
2017-09-22 00:18 - 2016-11-10 12:19 - 000833024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user32.dll
2017-09-22 00:18 - 2016-11-09 12:41 - 000114408 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2017-09-22 00:18 - 2016-11-09 12:33 - 001941504 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2017-09-22 00:18 - 2016-11-09 12:33 - 000504320 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll
2017-09-22 00:18 - 2016-11-09 12:33 - 000070144 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll
2017-09-22 00:18 - 2016-11-09 12:33 - 000025088 _____ (Microsoft Corporation) C:\Windows\system32\msimsg.dll
2017-09-22 00:18 - 2016-11-09 12:17 - 001806848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2017-09-22 00:18 - 2016-11-09 12:17 - 000337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll
2017-09-22 00:18 - 2016-11-09 12:17 - 000025088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msimsg.dll
2017-09-22 00:18 - 2016-11-09 12:02 - 000128512 _____ (Microsoft Corporation) C:\Windows\system32\msiexec.exe
2017-09-22 00:18 - 2016-11-09 11:55 - 000073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msiexec.exe
2017-09-22 00:18 - 2016-10-11 11:32 - 000069120 _____ (Microsoft Corporation) C:\Windows\system32\nlsbres.dll
2017-09-22 00:18 - 2016-10-11 11:31 - 001148416 _____ (Microsoft Corporation) C:\Windows\system32\IMJP10.IME
2017-09-22 00:18 - 2016-10-11 11:31 - 001068544 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll
2017-09-22 00:18 - 2016-10-11 11:31 - 000878080 _____ (Microsoft Corporation) C:\Windows\system32\IMJP10K.DLL
2017-09-22 00:18 - 2016-10-11 11:31 - 000457216 _____ (Microsoft Corporation) C:\Windows\system32\imkr80.ime
2017-09-22 00:18 - 2016-10-11 11:31 - 000246784 _____ (Microsoft Corporation) C:\Windows\system32\input.dll
2017-09-22 00:18 - 2016-10-11 11:31 - 000176128 _____ (Microsoft Corporation) C:\Windows\system32\tintlgnt.ime
2017-09-22 00:18 - 2016-10-11 11:31 - 000175104 _____ (Microsoft Corporation) C:\Windows\system32\quick.ime
2017-09-22 00:18 - 2016-10-11 11:31 - 000175104 _____ (Microsoft Corporation) C:\Windows\system32\qintlgnt.ime
2017-09-22 00:18 - 2016-10-11 11:31 - 000175104 _____ (Microsoft Corporation) C:\Windows\system32\phon.ime
2017-09-22 00:18 - 2016-10-11 11:31 - 000175104 _____ (Microsoft Corporation) C:\Windows\system32\cintlgnt.ime
2017-09-22 00:18 - 2016-10-11 11:31 - 000175104 _____ (Microsoft Corporation) C:\Windows\system32\chajei.ime
2017-09-22 00:18 - 2016-10-11 11:31 - 000132608 _____ (Microsoft Corporation) C:\Windows\system32\pintlgnt.ime
2017-09-22 00:18 - 2016-10-11 11:18 - 001027584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IMJP10.IME
2017-09-22 00:18 - 2016-10-11 11:18 - 000829952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msctf.dll
2017-09-22 00:18 - 2016-10-11 11:18 - 000701440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IMJP10K.DLL
2017-09-22 00:18 - 2016-10-11 11:18 - 000430080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imkr80.ime
2017-09-22 00:18 - 2016-10-11 11:18 - 000202240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\input.dll
2017-09-22 00:18 - 2016-10-11 11:18 - 000126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tintlgnt.ime
2017-09-22 00:18 - 2016-10-11 11:18 - 000125952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quick.ime
2017-09-22 00:18 - 2016-10-11 11:18 - 000125952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qintlgnt.ime
2017-09-22 00:18 - 2016-10-11 11:18 - 000125952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\phon.ime
2017-09-22 00:18 - 2016-10-11 11:18 - 000125952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cintlgnt.ime
2017-09-22 00:18 - 2016-10-11 11:18 - 000125952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\chajei.ime
2017-09-22 00:18 - 2016-10-11 11:18 - 000090112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pintlgnt.ime
2017-09-22 00:18 - 2016-10-11 11:18 - 000069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlsbres.dll
2017-09-22 00:18 - 2016-10-11 10:55 - 000346112 _____ (Microsoft Corporation) C:\Windows\system32\bcdedit.exe
2017-09-22 00:18 - 2016-10-11 09:33 - 000187392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIAnimation.dll
2017-09-22 00:18 - 2016-10-11 09:18 - 000419648 _____ C:\Windows\SysWOW64\locale.nls
2017-09-22 00:18 - 2016-10-11 09:17 - 000419648 _____ C:\Windows\system32\locale.nls
2017-09-22 00:18 - 2016-10-11 09:06 - 000221184 _____ (Microsoft Corporation) C:\Windows\system32\UIAnimation.dll
2017-09-22 00:18 - 2016-10-08 09:06 - 000633296 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
2017-09-22 00:18 - 2016-10-05 10:54 - 000090112 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bowser.sys
2017-09-22 00:18 - 2016-09-12 17:08 - 000107520 _____ (Microsoft Corporation) C:\Windows\system32\adsmsext.dll
2017-09-22 00:18 - 2016-09-12 16:49 - 000076800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adsmsext.dll
2017-09-22 00:18 - 2016-09-08 16:34 - 000263680 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll
2017-09-22 00:18 - 2016-09-08 16:34 - 000208896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebClnt.dll
2017-09-22 00:18 - 2016-09-08 16:34 - 000108544 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll
2017-09-22 00:18 - 2016-09-08 16:34 - 000087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\davclnt.dll
2017-09-22 00:18 - 2016-09-08 10:55 - 000142336 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2017-09-22 00:18 - 2016-09-08 10:55 - 000106496 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dfsc.sys
2017-09-22 00:18 - 2016-08-12 13:02 - 012574720 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2017-09-22 00:18 - 2016-08-12 13:02 - 000009728 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll
2017-09-22 00:18 - 2016-08-12 13:02 - 000005120 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx
2017-09-22 00:18 - 2016-08-12 13:02 - 000005120 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll
2017-09-22 00:18 - 2016-08-12 12:47 - 012574208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL
2017-09-22 00:18 - 2016-08-12 12:31 - 000008192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\spwmp.dll
2017-09-22 00:18 - 2016-08-12 12:31 - 000004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdxm.ocx
2017-09-22 00:18 - 2016-08-12 12:31 - 000004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxmasf.dll
2017-09-22 00:18 - 2016-08-12 12:26 - 000461312 _____ (Microsoft Corporation) C:\Windows\system32\scavengeui.dll
2017-09-22 00:18 - 2016-08-06 11:31 - 000347136 _____ (Microsoft Corporation) C:\Windows\system32\WSManMigrationPlugin.dll
2017-09-22 00:18 - 2016-08-06 11:31 - 000310784 _____ (Microsoft Corporation) C:\Windows\system32\WsmWmiPl.dll
2017-09-22 00:18 - 2016-08-06 11:31 - 000182272 _____ (Microsoft Corporation) C:\Windows\system32\WsmAuto.dll
2017-09-22 00:18 - 2016-08-06 11:31 - 000054272 _____ (Microsoft Corporation) C:\Windows\system32\WsmRes.dll
2017-09-22 00:18 - 2016-08-06 11:31 - 000012800 _____ (Microsoft Corporation) C:\Windows\system32\wsmplpxy.dll
2017-09-22 00:18 - 2016-08-06 11:15 - 000249344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManMigrationPlugin.dll
2017-09-22 00:18 - 2016-08-06 11:15 - 000214016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmWmiPl.dll
2017-09-22 00:18 - 2016-08-06 11:15 - 000146944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmAuto.dll
2017-09-22 00:18 - 2016-08-06 11:15 - 000054272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmRes.dll
2017-09-22 00:18 - 2016-08-06 11:01 - 000266752 _____ (Microsoft Corporation) C:\Windows\system32\WSManHTTPConfig.exe
2017-09-22 00:18 - 2016-08-06 11:01 - 000013824 _____ (Microsoft Corporation) C:\Windows\system32\wsmprovhost.exe
2017-09-22 00:18 - 2016-08-06 10:53 - 000199168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManHTTPConfig.exe
2017-09-22 00:18 - 2016-08-06 10:53 - 000012288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wsmprovhost.exe
2017-09-22 00:18 - 2016-08-06 10:53 - 000010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wsmplpxy.dll
2017-09-22 00:18 - 2016-06-14 13:16 - 001068544 _____ (Microsoft Corporation) C:\Windows\system32\cryptui.dll
2017-09-22 00:18 - 2016-06-14 13:16 - 000782848 _____ (Microsoft Corporation) C:\Windows\system32\wmdrmsdk.dll
2017-09-22 00:18 - 2016-06-14 13:16 - 000680448 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
2017-09-22 00:18 - 2016-06-14 13:16 - 000641024 _____ (Microsoft Corporation) C:\Windows\system32\msscp.dll
2017-09-22 00:18 - 2016-06-14 13:16 - 000632320 _____ (Microsoft Corporation) C:\Windows\system32\evr.dll
2017-09-22 00:18 - 2016-06-14 13:16 - 000499712 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll
2017-09-22 00:18 - 2016-06-14 13:16 - 000497664 _____ (Microsoft Corporation) C:\Windows\system32\drmmgrtn.dll
2017-09-22 00:18 - 2016-06-14 13:16 - 000440320 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll
2017-09-22 00:18 - 2016-06-14 13:16 - 000433152 _____ (Microsoft Corporation) C:\Windows\system32\mfplat.dll
2017-09-22 00:18 - 2016-06-14 13:16 - 000371712 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll
2017-09-22 00:18 - 2016-06-14 13:16 - 000325632 _____ (Microsoft Corporation) C:\Windows\system32\msnetobj.dll
2017-09-22 00:18 - 2016-06-14 13:16 - 000295936 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll
2017-09-22 00:18 - 2016-06-14 13:16 - 000284672 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll
2017-09-22 00:18 - 2016-06-14 13:16 - 000206848 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll
2017-09-22 00:18 - 2016-06-14 13:16 - 000187904 _____ (Microsoft Corporation) C:\Windows\system32\pcasvc.dll
2017-09-22 00:18 - 2016-06-14 13:16 - 000081920 _____ (Microsoft Corporation) C:\Windows\system32\cryptsp.dll
2017-09-22 00:18 - 2016-06-14 13:16 - 000037376 _____ (Microsoft Corporation) C:\Windows\system32\pcadm.dll
2017-09-22 00:18 - 2016-06-14 13:16 - 000008704 _____ (Microsoft Corporation) C:\Windows\system32\pcaevts.dll
2017-09-22 00:18 - 2016-06-14 13:16 - 000002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll
2017-09-22 00:18 - 2016-06-14 13:11 - 000663552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\PEAuth.sys
2017-09-22 00:18 - 2016-06-14 11:21 - 001005056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptui.dll
2017-09-22 00:18 - 2016-06-14 11:21 - 000617984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmdrmsdk.dll
2017-09-22 00:18 - 2016-06-14 11:21 - 000519680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll
2017-09-22 00:18 - 2016-06-14 11:21 - 000504320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msscp.dll
2017-09-22 00:18 - 2016-06-14 11:21 - 000489984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\evr.dll
2017-09-22 00:18 - 2016-06-14 11:21 - 000442368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AUDIOKSE.dll
2017-09-22 00:18 - 2016-06-14 11:21 - 000406016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drmmgrtn.dll
2017-09-22 00:18 - 2016-06-14 11:21 - 000374784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll
2017-09-22 00:18 - 2016-06-14 11:21 - 000354816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfplat.dll
2017-09-22 00:18 - 2016-06-14 11:21 - 000265216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msnetobj.dll
2017-09-22 00:18 - 2016-06-14 11:21 - 000195072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll
2017-09-22 00:18 - 2016-06-14 11:21 - 000103424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfps.dll
2017-09-22 00:18 - 2016-06-14 11:21 - 000080896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsp.dll
2017-09-22 00:18 - 2016-06-14 11:21 - 000002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mferror.dll
2017-09-22 00:18 - 2016-06-14 11:15 - 000125952 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe
2017-09-22 00:18 - 2016-06-14 11:15 - 000055808 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe
2017-09-22 00:18 - 2016-06-14 11:15 - 000024576 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe
2017-09-22 00:18 - 2016-06-14 11:05 - 000050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rrinstaller.exe
2017-09-22 00:18 - 2016-06-14 11:05 - 000023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfpmp.exe
2017-09-22 00:18 - 2016-06-14 11:00 - 000011264 _____ (Microsoft Corporation) C:\Windows\system32\pcawrk.exe
2017-09-22 00:18 - 2016-06-14 11:00 - 000009728 _____ (Microsoft Corporation) C:\Windows\system32\pcalua.exe
2017-09-22 00:18 - 2016-05-12 09:05 - 000297984 _____ (Microsoft Corporation) C:\Windows\system32\bcryptprimitives.dll
2017-09-22 00:18 - 2016-05-12 09:04 - 000249352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcryptprimitives.dll
2017-09-22 00:16 - 2016-08-29 11:04 - 003229696 _____ (Microsoft Corporation) C:\Windows\explorer.exe
2017-09-22 00:16 - 2016-08-29 10:55 - 002972672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe
2017-09-22 00:16 - 2016-08-16 16:40 - 000343552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
2017-09-22 00:16 - 2016-08-16 16:40 - 000327168 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys
2017-09-22 00:16 - 2016-08-16 16:40 - 000099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys
2017-09-22 00:16 - 2016-08-16 16:40 - 000056320 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
2017-09-22 00:16 - 2016-08-16 16:40 - 000030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys
2017-09-22 00:16 - 2016-08-16 16:40 - 000025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys
2017-09-22 00:16 - 2016-08-16 16:40 - 000007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys
2017-09-22 00:16 - 2016-07-22 10:58 - 000142336 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe
2017-09-22 00:16 - 2016-07-22 10:51 - 000123904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\poqexec.exe
2017-09-22 00:16 - 2016-05-12 13:15 - 000105472 _____ (Microsoft Corporation) C:\Windows\system32\winipsec.dll
2017-09-22 00:16 - 2016-05-12 13:14 - 000794624 _____ (Microsoft Corporation) C:\Windows\system32\gpsvc.dll
2017-09-22 00:16 - 2016-05-12 13:14 - 000502272 _____ (Microsoft Corporation) C:\Windows\system32\IPSECSVC.DLL
2017-09-22 00:16 - 2016-05-12 13:14 - 000373760 _____ (Microsoft Corporation) C:\Windows\system32\polstore.dll
2017-09-22 00:16 - 2016-05-12 13:14 - 000096256 _____ (Microsoft Corporation) C:\Windows\system32\gpapi.dll
2017-09-22 00:16 - 2016-05-12 13:14 - 000075776 _____ (Microsoft Corporation) C:\Windows\system32\FwRemoteSvr.dll
2017-09-22 00:16 - 2016-05-12 11:18 - 000274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\polstore.dll
2017-09-22 00:16 - 2016-05-12 11:18 - 000079360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gpapi.dll
2017-09-22 00:16 - 2016-05-12 11:18 - 000070144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winipsec.dll
2017-09-22 00:16 - 2016-05-12 11:18 - 000044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FwRemoteSvr.dll
2017-09-22 00:16 - 2016-05-11 13:02 - 000444928 _____ (Microsoft Corporation) C:\Windows\system32\winhttp.dll
2017-09-22 00:16 - 2016-05-11 13:02 - 000327168 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll
2017-09-22 00:16 - 2016-05-11 13:02 - 000296448 _____ (Microsoft Corporation) C:\Windows\system32\ws2_32.dll
2017-09-22 00:16 - 2016-05-11 11:19 - 000351744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winhttp.dll
2017-09-22 00:16 - 2016-05-11 11:19 - 000231424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswsock.dll
2017-09-22 00:16 - 2016-05-11 11:19 - 000206336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ws2_32.dll
2017-09-22 00:16 - 2016-03-09 15:00 - 000396800 _____ (Microsoft Corporation) C:\Windows\system32\webio.dll
2017-09-22 00:16 - 2016-03-09 14:40 - 000316416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webio.dll
2017-09-21 22:44 - 2010-11-20 23:23 - 000345088 _____ (Microsoft Corporation) C:\Windows\system32\sethc.exe
2017-09-21 22:17 - 2017-09-21 22:17 - 000002259 _____ C:\Users\Joey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chromium.lnk
2017-09-21 22:17 - 2017-09-21 22:17 - 000002251 _____ C:\Users\Joey\Desktop\Chromium.lnk
2017-09-21 22:16 - 2017-09-22 23:52 - 000000000 ____D C:\Users\Joey\AppData\Roaming\62F94F4F-EC86-5AA2-0F38-3C59CE9DC274
2017-09-21 22:15 - 2017-09-21 22:18 - 000000000 ____D C:\Users\Joey\AppData\Local\{2D851BD9-092D-7761-64B5-528940DDAE11}
2017-09-21 22:15 - 2017-09-21 22:15 - 000001486 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HowToRemove.html.lnk
2017-09-21 21:52 - 2017-09-21 21:52 - 000000000 ____D C:\ProgramData\72a2e60f-30d1-0
2017-09-21 21:52 - 2017-09-21 21:52 - 000000000 ____D C:\ProgramData\72a2e60f-2e97-1
2017-09-21 18:59 - 2017-09-23 18:25 - 000000000 ____D C:\ProgramData\Avg
2017-09-21 18:59 - 2017-09-22 23:49 - 000000000 ____D C:\Users\Joey\AppData\Local\Avg
2017-09-21 18:59 - 2017-09-22 23:45 - 000000000 ____D C:\Users\Joey\AppData\Local\AvgSetupLog
2017-09-21 18:59 - 2017-09-21 18:59 - 003449304 _____ (AVG Technologies CZ, s.r.o.) C:\Users\Joey\Downloads\AVG_Protection_Free_1606.exe
2017-08-30 02:23 - 2017-08-30 02:23 - 000875720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr120_clr0400.dll
2017-08-30 02:23 - 2017-08-30 02:23 - 000536768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcp120_clr0400.dll
2017-08-30 02:23 - 2017-08-30 02:23 - 000028352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aspnet_counters.dll
2017-08-30 02:23 - 2017-08-30 02:23 - 000018088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr110_clr0400.dll
2017-08-30 02:23 - 2017-08-30 02:23 - 000018088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcr100_clr0400.dll
2017-08-30 02:23 - 2017-08-30 02:23 - 000018088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msvcp110_clr0400.dll
2017-08-30 01:45 - 2017-08-30 01:45 - 000869576 _____ (Microsoft Corporation) C:\Windows\system32\msvcr120_clr0400.dll
2017-08-30 01:45 - 2017-08-30 01:45 - 000678592 _____ (Microsoft Corporation) C:\Windows\system32\msvcp120_clr0400.dll
2017-08-30 01:45 - 2017-08-30 01:45 - 000029888 _____ (Microsoft Corporation) C:\Windows\system32\aspnet_counters.dll
2017-08-30 01:45 - 2017-08-30 01:45 - 000018088 _____ (Microsoft Corporation) C:\Windows\system32\msvcr110_clr0400.dll
2017-08-30 01:45 - 2017-08-30 01:45 - 000018088 _____ (Microsoft Corporation) C:\Windows\system32\msvcr100_clr0400.dll
2017-08-30 01:45 - 2017-08-30 01:45 - 000018088 _____ (Microsoft Corporation) C:\Windows\system32\msvcp110_clr0400.dll
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2017-09-23 18:49 - 2009-07-14 00:45 - 000028352 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2017-09-23 18:49 - 2009-07-14 00:45 - 000028352 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2017-09-23 18:35 - 2012-05-12 02:36 - 000000000 ____D C:\Users\UpdatusUser
2017-09-23 18:27 - 2013-06-10 18:27 - 000000282 _____ C:\Windows\Tasks\DSite.job
2017-09-23 18:26 - 2016-04-11 21:46 - 000004602 _____ C:\Windows\System32\Tasks\DistromaticSearchProtect-hourly
2017-09-23 18:26 - 2009-07-14 01:13 - 000797888 _____ C:\Windows\system32\PerfStringBackup.INI
2017-09-23 18:26 - 2009-07-13 23:20 - 000000000 ____D C:\Windows\inf
2017-09-23 18:24 - 2012-05-18 15:12 - 000000000 ____D C:\ProgramData\PCDr
2017-09-23 18:20 - 2013-06-10 18:28 - 000000450 ____H C:\Windows\Tasks\Norton Security Scan for Joey.job
2017-09-23 18:20 - 2012-05-12 03:09 - 000000000 ____D C:\Users\Default\AppData\Local\SoftThinks
2017-09-23 18:20 - 2012-05-12 03:09 - 000000000 ____D C:\Users\Default User\AppData\Local\SoftThinks
2017-09-23 18:20 - 2012-05-12 03:04 - 000000000 ____D C:\Program Files (x86)\AlienRespawn
2017-09-23 18:20 - 2009-07-14 01:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2017-09-23 18:19 - 2012-05-12 04:30 - 000000000 ____D C:\ProgramData\NVIDIA
2017-09-22 19:14 - 2012-06-08 22:37 - 000004312 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2017-09-22 19:14 - 2012-05-12 02:39 - 000803328 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2017-09-22 19:14 - 2012-05-12 02:39 - 000144896 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2017-09-22 19:14 - 2012-05-12 02:39 - 000000000 ____D C:\Windows\SysWOW64\Macromed
2017-09-22 19:14 - 2012-05-12 02:39 - 000000000 ____D C:\Windows\system32\Macromed
2017-09-22 18:39 - 2012-05-19 10:05 - 000000000 ____D C:\Users\Joey\AppData\Roaming\PCDr
2017-09-22 18:20 - 2012-05-12 03:00 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Alienware
2017-09-22 05:39 - 2009-07-13 23:20 - 000000000 ____D C:\Windows\rescache
2017-09-22 04:23 - 2009-07-14 00:45 - 000387072 _____ C:\Windows\system32\FNTCACHE.DAT
2017-09-22 04:22 - 2016-05-09 21:47 - 000000000 ____D C:\ProgramData\9b66bb7d
2017-09-22 04:19 - 2015-01-19 11:02 - 000000000 ____D C:\Windows\system32\appraiser
2017-09-22 04:19 - 2014-05-06 07:13 - 000000000 ___SD C:\Windows\system32\CompatTel
2017-09-22 04:18 - 2009-07-14 01:32 - 000000000 ____D C:\Program Files\DVD Maker
2017-09-22 04:18 - 2009-07-13 23:20 - 000000000 ____D C:\Windows\SysWOW64\migwiz
2017-09-22 04:18 - 2009-07-13 23:20 - 000000000 ____D C:\Windows\SysWOW64\Dism
2017-09-22 04:18 - 2009-07-13 23:20 - 000000000 ____D C:\Windows\system32\migwiz
2017-09-22 04:18 - 2009-07-13 23:20 - 000000000 ____D C:\Windows\system32\Dism
2017-09-22 04:18 - 2009-07-13 23:20 - 000000000 ____D C:\Windows\PolicyDefinitions
2017-09-22 03:33 - 2013-08-18 12:00 - 000000000 ____D C:\Windows\system32\MRT
2017-09-22 03:33 - 2012-07-08 10:11 - 138202976 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2017-09-22 03:04 - 2011-02-10 12:10 - 000790502 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2017-09-22 00:30 - 2012-05-16 19:17 - 000001044 _____ C:\Users\Joey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2017-09-21 22:17 - 2013-03-17 17:34 - 000000000 ____D C:\Users\Joey\AppData\Local\Chromium
2017-09-21 19:51 - 2012-07-02 09:36 - 000000000 ____D C:\Users\Joey\AppData\Local\ElevatedDiagnostics
2017-09-21 19:41 - 2016-04-11 20:35 - 000000000 ____D C:\Users\Joey\AppData\Roaming\ScreenSnapshotTool
2017-09-21 19:36 - 2013-07-27 17:32 - 000000246 _____ C:\Users\Joey\AppData\Roaming\WB.CFG
2017-09-21 18:59 - 2015-01-03 11:20 - 000004476 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2017-09-21 18:57 - 2012-09-18 18:50 - 000002197 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-09-21 18:57 - 2012-09-18 18:50 - 000002185 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2017-09-21 18:53 - 2012-05-12 02:54 - 000000000 ___HD C:\Windows\system32\WLANProfiles
2017-09-21 18:48 - 2012-09-18 18:49 - 000003330 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2017-09-21 18:48 - 2012-09-18 18:49 - 000003202 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2017-09-21 18:08 - 2015-12-19 18:55 - 000887072 _____ C:\Windows\ntbtlog.txt
2017-09-21 12:35 - 2016-07-10 21:52 - 000000000 ____D C:\ProgramData\72a2e60f-1d51-0
2017-09-21 12:35 - 2016-07-10 21:52 - 000000000 ____D C:\ProgramData\72a2e60f-1263-1
2017-09-21 12:35 - 2016-05-09 21:47 - 000000000 ____D C:\ProgramData\{178ce23e-012c-1}
2017-09-21 12:35 - 2016-05-09 21:47 - 000000000 ____D C:\ProgramData\{1212099c-312c-0}
 
==================== Files in the root of some directories =======
 
2013-07-27 17:32 - 2017-09-21 19:36 - 000000246 _____ () C:\Users\Joey\AppData\Roaming\WB.CFG
2013-12-30 15:49 - 2014-01-02 19:32 - 000000005 _____ () C:\Users\Joey\AppData\Roaming\WBPU-Q5-TTL.DAT
2013-06-15 19:30 - 2014-01-30 15:28 - 000000005 _____ () C:\Users\Joey\AppData\Roaming\WBPU-TTL.DAT
2013-03-17 17:27 - 2013-03-17 17:27 - 000000092 _____ () C:\Users\Joey\AppData\Local\fusioncache.dat
2012-10-29 00:18 - 2012-10-29 00:18 - 000033958 _____ () C:\ProgramData\uninstaller.exe
 
Files to move or delete:
====================
C:\ProgramData\uninstaller.exe
 
 
Some files in TEMP:
====================
2012-07-03 22:08 - 2012-07-03 22:08 - 003320664 _____ (Visicom Media Inc.) C:\Users\Joey\AppData\Local\Temp\air1246.exe
2012-07-03 22:08 - 2012-07-03 22:08 - 003421471 _____ () C:\Users\Joey\AppData\Local\Temp\air1AE0.exe
2012-07-03 22:08 - 2012-07-03 22:08 - 000632736 _____ (Shop To Win, LLC                                            ) C:\Users\Joey\AppData\Local\Temp\air4E51.exe
2013-03-17 09:48 - 2013-03-17 09:48 - 000358600 _____ (Ask.com) C:\Users\Joey\AppData\Local\Temp\APNStub.exe
2013-01-17 21:04 - 2013-01-17 21:04 - 000255072 _____ (AVG Technologies CZ, s.r.o.) C:\Users\Joey\AppData\Local\Temp\avguidx.dll
2012-09-28 18:05 - 2013-11-15 18:28 - 001542696 _____ (McAfee, Inc.) C:\Users\Joey\AppData\Local\Temp\contentDATs.exe
2012-07-08 10:06 - 2012-07-08 10:06 - 001074808 _____ () C:\Users\Joey\AppData\Local\Temp\del.dll
2016-01-08 08:46 - 2016-01-08 08:46 - 000211576 _____ (383 Media, Inc.) C:\Users\Joey\AppData\Local\Temp\DRHelper_installFinish.exe
2016-01-08 08:46 - 2016-01-08 08:46 - 000211576 _____ (383 Media, Inc.) C:\Users\Joey\AppData\Local\Temp\DRHelper_installStart.exe
2016-01-08 08:46 - 2016-01-08 08:46 - 000211576 _____ (383 Media, Inc.) C:\Users\Joey\AppData\Local\Temp\DRHelper_uninstallComplete.exe
2012-03-02 14:38 - 2012-03-02 14:38 - 006982752 _____ (FreeDownloadManager.ORG                                     ) C:\Users\Joey\AppData\Local\Temp\fdminst.exe
2013-01-18 17:51 - 2013-01-17 21:04 - 000935880 _____ (AVG Technologies) C:\Users\Joey\AppData\Local\Temp\GenericWndApi.dll
2015-07-31 14:46 - 2013-01-14 06:12 - 000396696 _____ (Happy Cloud, Inc.) C:\Users\Joey\AppData\Local\Temp\hcuninstaller_20150731_144605_6628.exe
2011-06-15 18:48 - 2011-06-15 18:48 - 003029824 _____ (Electronic Arts, Inc.) C:\Users\Joey\AppData\Local\Temp\installerdll9910681.dll
2011-06-15 18:48 - 2011-06-15 18:48 - 003029824 _____ (Electronic Arts, Inc.) C:\Users\Joey\AppData\Local\Temp\installerdll9917857.dll
2012-12-21 20:49 - 2012-12-17 09:55 - 001628672 _____ () C:\Users\Joey\AppData\Local\Temp\installhelper.dll
2016-06-07 23:05 - 2016-06-07 23:05 - 000759408 _____ () C:\Users\Joey\AppData\Local\Temp\InstallHelper.exe
2013-12-19 13:06 - 2013-12-19 13:06 - 000921512 _____ (Oracle Corporation) C:\Users\Joey\AppData\Local\Temp\jre-7u51-windows-i586-iftw.exe
2012-09-07 16:45 - 2012-09-07 16:45 - 000894952 _____ (Oracle Corporation) C:\Users\Joey\AppData\Local\Temp\jre-7u7-windows-i586-iftw.exe
2012-09-27 17:56 - 2012-09-27 17:56 - 000895464 _____ (Oracle Corporation) C:\Users\Joey\AppData\Local\Temp\jre-7u9-windows-i586-iftw.exe
2015-04-30 19:37 - 2015-04-30 19:37 - 000562272 _____ (Oracle Corporation) C:\Users\Joey\AppData\Local\Temp\jre-8u45-windows-au.exe
2016-04-11 21:42 - 2016-04-11 21:42 - 000736320 _____ (Oracle Corporation) C:\Users\Joey\AppData\Local\Temp\jre-8u77-windows-au.exe
2016-05-11 22:01 - 2016-05-11 22:01 - 000739904 _____ (Oracle Corporation) C:\Users\Joey\AppData\Local\Temp\jre-8u91-windows-au.exe
2013-01-17 21:04 - 2013-01-17 21:04 - 000163936 _____ () C:\Users\Joey\AppData\Local\Temp\MachineIdCreator.exe
2012-09-23 10:27 - 2012-09-23 10:27 - 000888320 _____ (McAfee, Inc.) C:\Users\Joey\AppData\Local\Temp\mssinstaller.exe
2013-01-17 21:04 - 2013-01-17 21:04 - 002985568 _____ () C:\Users\Joey\AppData\Local\Temp\oi_{6442B6C6-9B6C-4295-9CAF-B1519F431CF3}.exe
2013-06-09 22:24 - 2013-06-09 22:24 - 003238936 _____ (AVG Secure Search) C:\Users\Joey\AppData\Local\Temp\oi_{B786E7A9-4350-41AC-9F30-AFFC989C9641}.exe
2013-02-15 11:55 - 2013-02-15 11:55 - 003084368 _____ () C:\Users\Joey\AppData\Local\Temp\oi_{C4D902EB-D955-470E-80E2-281F9F0A8D5F}.exe
2013-06-10 22:12 - 2013-06-10 22:12 - 000000006 _____ () C:\Users\Joey\AppData\Local\Temp\propsys.dll
2011-06-08 16:03 - 2011-06-08 16:03 - 000336280 ____R (Microsoft Corporation) C:\Users\Joey\AppData\Local\Temp\rootsupd.exe
2012-09-29 19:53 - 2014-01-31 17:00 - 008330352 _____ (McAfee, Inc.) C:\Users\Joey\AppData\Local\Temp\SecurityScan_Release.exe
2016-04-06 21:21 - 2016-04-06 21:19 - 000381224 _____ (Splashtop Inc.) C:\Users\Joey\AppData\Local\Temp\SetupUtil.exe
2012-08-08 10:17 - 2012-08-08 10:17 - 000541696 _____ () C:\Users\Joey\AppData\Local\Temp\sqlite-3.7.2-sqlitejdbc.dll
2014-07-21 11:53 - 2014-07-21 11:53 - 000599419 _____ () C:\Users\Joey\AppData\Local\Temp\Sqlite3.dll
2012-12-21 20:49 - 2012-12-17 09:55 - 001085952 _____ () C:\Users\Joey\AppData\Local\Temp\SRAssetsHelper.dll
2012-10-12 16:47 - 2012-10-12 16:48 - 007036000 _____ (Nike) C:\Users\Joey\AppData\Local\Temp\temp0NikeConnectconnect5pcupdate.exe
2013-12-22 22:58 - 2013-12-22 22:59 - 017934352 _____ (Nike) C:\Users\Joey\AppData\Local\Temp\temp0NikeConnectconnect6pcupdate.exe
2013-01-20 10:36 - 2013-01-20 10:37 - 007116056 _____ (Nike) C:\Users\Joey\AppData\Local\Temp\temp10NikeConnectconnect5pcupdate.exe
2013-01-24 08:20 - 2013-01-24 08:20 - 007116056 _____ (Nike) C:\Users\Joey\AppData\Local\Temp\temp11NikeConnectconnect5pcupdate.exe
2013-01-29 00:04 - 2013-01-29 00:04 - 007116056 _____ (Nike) C:\Users\Joey\AppData\Local\Temp\temp12NikeConnectconnect5pcupdate.exe
2013-02-01 08:16 - 2013-02-01 08:16 - 007116056 _____ (Nike) C:\Users\Joey\AppData\Local\Temp\temp13NikeConnectconnect5pcupdate.exe
2013-02-13 08:18 - 2013-02-13 08:19 - 007116056 _____ (Nike) C:\Users\Joey\AppData\Local\Temp\temp14NikeConnectconnect5pcupdate.exe
2013-02-24 11:37 - 2013-02-24 11:37 - 007116056 _____ (Nike) C:\Users\Joey\AppData\Local\Temp\temp15NikeConnectconnect5pcupdate.exe
2013-02-25 08:36 - 2013-02-25 08:37 - 007116056 _____ (Nike) C:\Users\Joey\AppData\Local\Temp\temp16NikeConnectconnect5pcupdate.exe
2013-02-28 08:33 - 2013-02-28 08:34 - 007116056 _____ (Nike) C:\Users\Joey\AppData\Local\Temp\temp17NikeConnectconnect5pcupdate.exe
2013-03-05 11:03 - 2013-03-05 11:03 - 007116056 _____ (Nike) C:\Users\Joey\AppData\Local\Temp\temp18NikeConnectconnect5pcupdate.exe
2013-03-12 07:22 - 2013-03-12 07:22 - 007116056 _____ (Nike) C:\Users\Joey\AppData\Local\Temp\temp19NikeConnectconnect5pcupdate.exe
2012-10-27 12:12 - 2012-10-27 12:13 - 007036000 _____ (Nike) C:\Users\Joey\AppData\Local\Temp\temp1NikeConnectconnect5pcupdate.exe
2013-12-23 08:02 - 2013-12-23 08:03 - 017934352 _____ (Nike) C:\Users\Joey\AppData\Local\Temp\temp1NikeConnectconnect6pcupdate.exe
2013-03-16 11:40 - 2013-03-16 11:41 - 007116056 _____ (Nike) C:\Users\Joey\AppData\Local\Temp\temp20NikeConnectconnect5pcupdate.exe
2013-03-22 17:15 - 2013-03-22 17:16 - 007116056 _____ (Nike) C:\Users\Joey\AppData\Local\Temp\temp21NikeConnectconnect5pcupdate.exe
2013-03-31 09:37 - 2013-03-31 09:37 - 007116056 _____ (Nike) C:\Users\Joey\AppData\Local\Temp\temp22NikeConnectconnect5pcupdate.exe
2013-04-11 07:34 - 2013-04-11 07:34 - 007116056 _____ (Nike) C:\Users\Joey\AppData\Local\Temp\temp23NikeConnectconnect5pcupdate.exe
2013-05-01 07:24 - 2013-05-01 07:24 - 007116056 _____ (Nike) C:\Users\Joey\AppData\Local\Temp\temp24NikeConnectconnect5pcupdate.exe
2013-05-03 07:28 - 2013-05-03 07:29 - 007116056 _____ (Nike) C:\Users\Joey\AppData\Local\Temp\temp25NikeConnectconnect5pcupdate.exe
2013-05-09 20:08 - 2013-05-09 20:08 - 007116056 _____ (Nike) C:\Users\Joey\AppData\Local\Temp\temp26NikeConnectconnect5pcupdate.exe
2013-05-17 07:29 - 2013-05-17 07:30 - 007116056 _____ (Nike) C:\Users\Joey\AppData\Local\Temp\temp27NikeConnectconnect5pcupdate.exe
2013-05-18 09:51 - 2013-05-18 09:51 - 007116056 _____ (Nike) C:\Users\Joey\AppData\Local\Temp\temp28NikeConnectconnect5pcupdate.exe
2013-05-21 07:31 - 2013-05-21 07:31 - 007116056 _____ (Nike) C:\Users\Joey\AppData\Local\Temp\temp29NikeConnectconnect5pcupdate.exe
2012-11-05 08:21 - 2012-11-05 08:22 - 007036000 _____ (Nike) C:\Users\Joey\AppData\Local\Temp\temp2NikeConnectconnect5pcupdate.exe
2014-02-21 08:09 - 2014-02-21 08:10 - 017933920 _____ (Nike) C:\Users\Joey\AppData\Local\Temp\temp2NikeConnectconnect6pcupdate.exe
2013-11-02 07:50 - 2013-11-02 07:51 - 008133032 _____ (Nike) C:\Users\Joey\AppData\Local\Temp\temp30NikeConnectconnect5pcupdate.exe
2013-11-11 08:00 - 2013-11-11 08:00 - 008190072 _____ (Nike) C:\Users\Joey\AppData\Local\Temp\temp31NikeConnectconnect5pcupdate.exe
2012-11-20 08:07 - 2012-11-20 08:08 - 007036000 _____ (Nike) C:\Users\Joey\AppData\Local\Temp\temp3NikeConnectconnect5pcupdate.exe
2014-03-21 07:21 - 2014-03-21 07:22 - 017944824 _____ (Nike) C:\Users\Joey\AppData\Local\Temp\temp3NikeConnectconnect6pcupdate.exe
2012-11-21 08:22 - 2012-11-21 08:22 - 007036000 _____ (Nike) C:\Users\Joey\AppData\Local\Temp\temp4NikeConnectconnect5pcupdate.exe
2014-04-20 06:23 - 2014-04-20 06:24 - 017945160 _____ (Nike) C:\Users\Joey\AppData\Local\Temp\temp4NikeConnectconnect6pcupdate.exe
2012-12-08 09:53 - 2012-12-08 09:54 - 007036000 _____ (Nike) C:\Users\Joey\AppData\Local\Temp\temp5NikeConnectconnect5pcupdate.exe
2014-10-10 14:05 - 2014-10-10 14:06 - 018001232 _____ (Nike) C:\Users\Joey\AppData\Local\Temp\temp5NikeConnectconnect6pcupdate.exe
2012-12-16 09:23 - 2012-12-16 09:23 - 007116056 _____ (Nike) C:\Users\Joey\AppData\Local\Temp\temp6NikeConnectconnect5pcupdate.exe
2014-10-24 14:10 - 2014-10-24 14:11 - 018003320 _____ (Nike) C:\Users\Joey\AppData\Local\Temp\temp6NikeConnectconnect6pcupdate.exe
2012-12-19 08:24 - 2012-12-19 08:24 - 007116056 _____ (Nike) C:\Users\Joey\AppData\Local\Temp\temp7NikeConnectconnect5pcupdate.exe
2015-02-28 10:40 - 2015-02-28 10:41 - 018004536 _____ (Nike) C:\Users\Joey\AppData\Local\Temp\temp7NikeConnectconnect6pcupdate.exe
2012-12-31 11:34 - 2012-12-31 11:34 - 007116056 _____ (Nike) C:\Users\Joey\AppData\Local\Temp\temp8NikeConnectconnect5pcupdate.exe
2013-01-18 08:19 - 2013-01-18 08:19 - 007116056 _____ (Nike) C:\Users\Joey\AppData\Local\Temp\temp9NikeConnectconnect5pcupdate.exe
2013-01-18 17:51 - 2013-02-15 11:55 - 001042096 _____ () C:\Users\Joey\AppData\Local\Temp\UNINSTALL.EXE
2012-08-18 13:21 - 2012-08-08 06:43 - 000079544 _____ (Genieo Innovation Ltd.) C:\Users\Joey\AppData\Local\Temp\updater_uninstall.exe
2011-06-08 16:03 - 2011-06-08 16:03 - 005673816 _____ (Microsoft Corporation) C:\Users\Joey\AppData\Local\Temp\vcredist_x64.exe
2011-06-08 16:03 - 2011-06-08 16:03 - 004995416 _____ (Microsoft Corporation) C:\Users\Joey\AppData\Local\Temp\vcredist_x86.exe
2013-06-04 16:19 - 2013-06-04 16:19 - 000000000 _____ () C:\Users\Joey\AppData\Local\Temp\vnpxsk4z.dll
2012-04-25 12:48 - 2012-04-25 12:48 - 000401408 _____ () C:\Users\Joey\AppData\Local\Temp\wget.exe
2015-06-20 21:19 - 2015-06-20 21:19 - 000744656 _____ (Yahoo! Inc.) C:\Users\Joey\AppData\Local\Temp\ytb.exe
 
==================== Bamital & volsnap ======================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
 
LastRegBack: 2017-09-21 12:50
 
==================== End of FRST.txt ============================
 
 
 
 
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 23-09-2017 02
Ran by Joey (23-09-2017 19:10:40)
Running from C:\Users\Joey\Downloads
Windows 7 Home Premium Service Pack 1 (X64) (2012-05-16 23:15:21)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-1979518111-4107658783-1214925503-500 - Administrator - Disabled)
ASPNET (S-1-5-21-1979518111-4107658783-1214925503-1005 - Limited - Enabled)
Guest (S-1-5-21-1979518111-4107658783-1214925503-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-1979518111-4107658783-1214925503-1003 - Limited - Enabled)
Joey (S-1-5-21-1979518111-4107658783-1214925503-1001 - Administrator - Enabled) => C:\Users\Joey
UpdatusUser (S-1-5-21-1979518111-4107658783-1214925503-1000 - Limited - Enabled) => C:\Users\UpdatusUser
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: AVG Antivirus (Enabled - Up to date) {4D41356F-32AD-7C42-C820-63775EE4F413}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: AVG Antivirus (Enabled - Up to date) {F620D48B-1497-73CC-F290-58052563BEAE}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
Adobe Flash Player 27 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 27.0.0.130 - Adobe Systems Incorporated)
Adobe Flash Player 27 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 27.0.0.130 - Adobe Systems Incorporated)
Adobe Reader X (10.1.16) MUI (HKLM-x32\...\{AC76BA86-7AD7-FFFF-7B44-AA0000000001}) (Version: 10.1.16 - Adobe Systems Incorporated)
Advanced Audio FX Engine (HKLM-x32\...\Advanced Audio FX Engine) (Version: 1.12.05 - Creative Technology Ltd)
Advanced ScreenSnapshotTool 1.1.0.11414 (HKLM\...\{61FFE1F9-137D-4c31-A181-3415FCAA5946}) (Version: 1.1.0.11414 - ShenZhen Enode Techology co,.Ltd) <==== ATTENTION
AlienRespawn - Support Software (HKLM-x32\...\{A9668246-FB70-4103-A1E3-66C9BC2EFB49}) (Version: 9.4.67 - Alienware)
AlienRespawn (HKLM-x32\...\{0ED7EE95-6A97-47AA-AD73-152C08A15B04}) (Version: 9.4.67 - Alienware)
Alienware Command Center (HKLM\...\{CD4B350A-9328-4C1F-91D3-255EF2DA58FA}) (Version: 2.7.28.0 - Alienware Corp.) Hidden
Alienware Command Center (HKLM-x32\...\InstallShield_{CD4B350A-9328-4C1F-91D3-255EF2DA58FA}) (Version: 2.7.28.0 - Alienware Corp.)
Alienware On-Screen Display (HKLM-x32\...\{0D69462F-99CC-4F8D-942E-666E21CE59F8}) (Version: 0.32.1.1 - ) Hidden
Alienware On-Screen Display (HKLM-x32\...\InstallShield_{0D69462F-99CC-4F8D-942E-666E21CE59F8}) (Version: 0.32.1.1 - )
Amazon 1Button App (HKLM-x32\...\{B6DCCCD3-520D-4485-B642-FCC136CE12C3}) (Version: 2.3.4 - Amazon) Hidden <==== ATTENTION
Amazon Assistant (HKLM-x32\...\Amazon Assistant) (Version: 2.3.4 - Amazon) <==== ATTENTION
AVG (HKLM\...\{BA40B3B4-7707-437E-84FF-8C18BE5AD9B6}) (Version: 1.211.2 - AVG Technologies) Hidden
AVG AntiVirus FREE (HKLM-x32\...\AVG Antivirus) (Version: 17.6.3029 - AVG Technologies)
AVG SafeGuard toolbar (HKLM-x32\...\AVG SafeGuard toolbar) (Version: 17.3.0.49 - AVG Technologies)
Bing Bar (HKLM-x32\...\{FF6DD716-7B10-4269-9F19-FFB07AC4CD95}) (Version: 7.3.124.0 - Microsoft Corporation)
Chromium (HKLM-x32\...\{F4D21C12-A452-CD92-15D2-BD12C5526E92}) (Version:  - )
CyberDefender Framework (HKLM-x32\...\{DF4DF785-DB30-4AC0-B26A-715488DAA2CD}) (Version: 1.3.0.4371 - CyberDefender Corp.) Hidden
CyberDefender Framework (HKLM-x32\...\CyberDefender Framework) (Version: 1.3.0.4371 - CyberDefender Corp.)
DefaultTab (HKLM-x32\...\DefaultTab) (Version: 1.2.6.0 - Search Results, LLC) <==== ATTENTION
Dell Data Vault (HKLM\...\{2E55EEFD-2162-4A7D-9158-EDB0305603A6}) (Version: 4.3.7.0 - Dell Inc.) Hidden
Dell SupportAssist (HKLM\...\PC-Doctor for Windows) (Version: 2.0.6875.668 - Dell)
Dell SupportAssistAgent (HKLM-x32\...\{3ED468C2-2235-4747-90AD-A7A34F0FE70A}) (Version: 1.2.2.8 - Dell)
EMSC (HKLM-x32\...\{FEF06E73-A519-4510-8CF3-B66041B91D8A}) (Version: 0.0.0.22C - Compal Electronics, Inc.) Hidden
Extended Update (HKU\S-1-5-21-1979518111-4107658783-1214925503-1001\...\UpdaterEX) (Version:  - Extended Update) <==== ATTENTION
FMW 1 (HKLM\...\{2B66FCDA-0BD6-47CC-8EC5-C2EA02E03EB2}) (Version: 1.224.4 - AVG Technologies) Hidden
Free Download Manager 3.9.3 (HKLM-x32\...\Free Download Manager_is1) (Version:  - FreeDownloadManager.ORG)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 60.0.3112.113 - Google Inc.)
Google Toolbar for Internet Explorer (HKLM-x32\...\{18455581-E099-4BA8-BC6B-F34B2F06600C}) (Version: 1.0.0 - Google Inc.) Hidden
Google Toolbar for Internet Explorer (HKLM-x32\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.8231.2252 - Google Inc.)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.5 - Google Inc.) Hidden
Google Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.25.11 - Google Inc.) Hidden
Happy Cloud Client (HKU\S-1-5-21-1979518111-4107658783-1214925503-1001\...\HappyCloud) (Version: 1.368 - Happy Cloud, Inc.)
Integrated Webcam Live! Central (HKLM-x32\...\Integrated Webcam Live! Central) (Version: 2.00.44 - Creative Technology Ltd)
Intel® Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
Intel® Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.0.1.1399 - Intel Corporation)
Intel® Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2653 - Intel Corporation)
Intel® PROSet/Wireless for Bluetooth® + High Speed (HKLM\...\{37EC048A-81A2-452A-8D1F-3BE2018E767D}) (Version: 15.1.0.0096 - Intel Corporation)
Intel® PROSet/Wireless Software for Bluetooth® Technology (HKLM\...\{520C4DD4-2BC7-409B-BA48-E1A4F832662D}) (Version: 2.1.0.0140 - Intel Corporation)
Intel® Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 11.0.0.1032 - Intel Corporation)
Intel® USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 1.0.3.214 - Intel Corporation)
Intel® WiDi (HKLM-x32\...\{93F34C5C-ACAA-48F3-9B26-70359A117F12}) (Version: 3.0.12.0 - Intel Corporation)
Intel® Wireless Display (HKLM\...\{28EF7372-9087-4AC3-9B9F-D9751FCDF830}) (Version:  - )
Intel® PROSet/Wireless WiFi Software (HKLM\...\{E97F409F-9E1C-42A0-B72D-765A78DF3696}) (Version: 15.01.0000.0830 - Intel Corporation)
Intel® Trusted Connect Service Client (HKLM\...\{538B98C3-773F-4F20-9C66-802D104DCBE2}) (Version: 1.23.219.2 - Intel Corporation)
Java 8 Update 91 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218091F0}) (Version: 8.0.910.14 - Oracle Corporation)
JavaFX 2.1.1 (HKLM-x32\...\{1111706F-666A-4037-7777-211328764D10}) (Version: 2.1.1 - Oracle Corporation)
Microsoft .NET Framework 1.1 (HKLM-x32\...\Microsoft .NET Framework 1.1  (1033)) (Version:  - )
Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Office Click-to-Run 2010 (HKLM-x32\...\Office14.Click2Run) (Version: 14.0.6122.5000 - Microsoft Corporation)
Microsoft Office Home and Business 2010 - English (HKLM-x32\...\{90140011-0062-0409-0000-0000000FF1CE}) (Version: 14.0.6137.5006 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{820B6609-4C97-3A2B-B644-573B06A0F0CC}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation)
Mozilla Firefox 14.0.1 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 14.0.1 (x86 en-US)) (Version: 14.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 14.0.1 - Mozilla)
Nike+ Connect (HKLM-x32\...\Nike+ Connect) (Version: 6.6.32 - Nike)
Nike+ Connect (HKU\S-1-5-21-1979518111-4107658783-1214925503-1001\...\Nike+ Connect) (Version: 5.2.4 - Nike)
Norton Security Scan (HKLM-x32\...\NSS) (Version: 4.1.0.28 - Symantec Corporation)
NVIDIA 3D Vision Driver 296.16 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 296.16 - NVIDIA Corporation)
NVIDIA Graphics Driver 296.16 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 296.16 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.12.0213 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.12.0213 - NVIDIA Corporation)
NVIDIA Update 1.7.12 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 1.7.12 - NVIDIA Corporation)
OpenOffice 4.1.0 (HKLM-x32\...\{C87EF11D-36E9-479D-9898-7541EA1E8A6A}) (Version: 4.10.9764 - Apache Software Foundation)
Origin (HKLM-x32\...\Origin) (Version: 8.6.0.357 - Electronic Arts, Inc.)
Product Support 1.74.b1377 (HKLM-x32\...\SP_963508d2) (Version:  - ) <==== ATTENTION
QualxServ Service Agreement (HKLM-x32\...\{18401E1E-1E44-461A-A4B2-E48B1A727818}) (Version: 2.0.0 - Dell Inc.)
Search Protect (HKLM-x32\...\SearchProtect) (Version: 2.9.8.2 - Conduit) <==== ATTENTION
Smart PC Cleaner v3.0 (HKLM-x32\...\Smart PC Cleaner_is1) (Version: 3.0 - Avanquest Software) <==== ATTENTION
Sound Blaster Recon3Di (HKLM-x32\...\{C8AAFCDC-CD3A-40AD-9FA9-07FB70F08224}) (Version: 1.00.08 - Creative Technology Limited)
Sound Blaster Recon3Di Extras (HKLM-x32\...\{C45E715E-442E-4D82-BD46-A08A0870957C}) (Version: 1.0 - Creative Technology Limited)
Splashtop Streamer (HKLM-x32\...\{B7C5EA94-B96A-41F5-BE95-25D78B486678}) (Version: 2.6.5.4 - Splashtop Inc.)
ST Microelectronics 3 Axis Digital Accelerometer Solution (HKLM-x32\...\{9C24F411-9CA7-4A8A-91F3-F08A4A38EB31}) (Version: 4.12.0018 - ST Microelectronics)
Star Wars: The Old Republic (HKLM-x32\...\{3B11D799-48E0-48ED-BFD7-EA655676D8BB}) (Version: 1.00 - Electronic Arts, Inc.)
Strongvault Online Backup (HKLM-x32\...\{3002C8EB-2A7E-419B-B77F-5AD7E9F54A5A}) (Version: 1.0.1.0 - Strongvault) <==== ATTENTION
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 16.0.4.0 - Synaptics Incorporated)
TeamSpeak 3 Client (HKLM-x32\...\TeamSpeak 3 Client) (Version: 3.0.19 - TeamSpeak Systems GmbH)
WildStar (HKLM-x32\...\WildStar) (Version:  - NCSOFT)
Yahoo Search Set (HKLM-x32\...\Yahoo! SearchSet) (Version:  - Yahoo Inc.)
Zip Opener Packages (HKU\S-1-5-21-1979518111-4107658783-1214925503-1001\...\Zip Opener Packages) (Version:  - ) <==== ATTENTION
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
HKU\S-1-5-21-1979518111-4107658783-1214925503-1001\...\ChromeHTML: -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
ShellIconOverlayIdentifiers: [00avg] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  -> No File
ContextMenuHandlers1: [AVG] -> {472083B1-C522-11CF-8763-00608CC02F24} => C:\Program Files (x86)\AVG\Antivirus\ashShA64.dll [2017-09-22] (AVG Technologies CZ, s.r.o.)
ContextMenuHandlers3: [00avg] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  -> No File
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => C:\Windows\system32\igfxpph.dll [2012-02-14] (Intel Corporation)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\Windows\system32\nvshext.dll [2012-03-04] (NVIDIA Corporation)
ContextMenuHandlers6: [AVG] -> {472083B1-C522-11CF-8763-00608CC02F24} => C:\Program Files (x86)\AVG\Antivirus\ashShA64.dll [2017-09-22] (AVG Technologies CZ, s.r.o.)
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {01B531F6-4989-428C-BF33-604A32D9E2C1} - System32\Tasks\{7876D7AF-681B-4AA3-A783-B20A74974109} => C:\Program Files (x86)\Free Download Manager\fdm.exe [2013-10-25] (FreeDownloadManager.ORG)
Task: {02B13651-9496-4850-88E0-1EBC61F1E353} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-12-19] (Google Inc.)
Task: {0503D853-2977-4B42-9752-400397B222E0} - System32\Tasks\PCDEventLauncherTask => C:\Program Files\Alienware\SupportAssist\sessionchecker.exe [2017-09-14] (PC-Doctor, Inc.)
Task: {0C209135-B8A5-40DA-B393-660189966A08} - System32\Tasks\DistromaticUpdater-periodic => C:\Program Files (x86)\Amazon Browser Settings\updater.exe [2016-04-11] (Distromatic) <==== ATTENTION
Task: {14C13415-BFB7-4EF8-8F91-4B844B6362FD} - System32\Tasks\DistromaticSearchProtect-logon => C:\Program Files (x86)\Amazon Browser Settings\AmznSearchProtect.exe [2016-04-11] (Distromatic) <==== ATTENTION
Task: {41F4814D-0BA3-4C2B-AB5D-D774B2B29068} - System32\Tasks\DistromaticUpdater-logon => C:\Program Files (x86)\Amazon Browser Settings\updater.exe [2016-04-11] (Distromatic) <==== ATTENTION
Task: {46B9B6B3-D2A4-4E45-A192-6C54A497DDB4} - System32\Tasks\{6F4BD8B2-0FE6-4DA5-B2AE-A065C58ED6DA} => C:\Program Files (x86)\Free Download Manager\fdm.exe [2013-10-25] (FreeDownloadManager.ORG)
Task: {59DF69F3-DDB9-430D-8966-F5C837534F57} - \PC Performer Manager -> No File <==== ATTENTION
Task: {5D82BEC2-9751-4544-871A-C3EEF1978A3D} - System32\Tasks\SystemToolsDailyTest => uaclauncher.exe
Task: {616E9098-A190-4645-B31E-48E16FC4A72B} - System32\Tasks\{A2387960-277C-496E-B65E-385E77AB2BC6} => C:\Program Files (x86)\Free Download Manager\fdm.exe [2013-10-25] (FreeDownloadManager.ORG)
Task: {61E04B6F-2592-40A1-BED1-98EFD2789BDB} - System32\Tasks\Dell SupportAssistAgent AutoUpdate => C:\Program Files (x86)\Dell\SupportAssistAgent\bin\SupportAssist.exe [2016-04-22] (Dell Inc.)
Task: {7F2ED675-4C7E-4A58-9399-EC2276E545A9} - System32\Tasks\AVG EUpdate Task => avgsetupx.exe
Task: {8DC3BA54-3336-447E-852B-6E36C3595F9F} - System32\Tasks\Antivirus Emergency Update => C:\Program Files (x86)\AVG\Antivirus\AvEmUpdate.exe [2017-09-22] (AVG Technologies CZ, s.r.o.)
Task: {90087565-5195-4568-B694-EC9F8B5416B9} - System32\Tasks\{13875299-5770-4714-AA79-35427528F3AC} => C:\Users\Joey\Downloads\microsoft powerpoint 2010 setup.exe
Task: {9243FA81-3ED1-4CFC-913D-2325EE208C99} - System32\Tasks\Norton Security Scan for Joey => C:\Program Files (x86)\Norton Security Scan\Engine\4.1.0.28\Nss.exe [2014-01-27] (Symantec Corporation)
Task: {9E0F11AA-4EBE-413F-8628-7982AEA0A981} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-12-19] (Google Inc.)
Task: {A553C849-2BBC-46E5-8969-A9A2063ACD1F} - System32\Tasks\PCDoctorBackgroundMonitorTask => C:\Program Files\Alienware\SupportAssist\uaclauncher.exe [2017-09-14] (PC-Doctor, Inc.)
Task: {ACA79321-9247-4FD2-99A8-08752E3CCDB5} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-09-22] (Adobe Systems Incorporated)
Task: {B53FEADA-5DA9-4BA9-ABE6-10D14DC3608E} - System32\Tasks\{C0485AE7-9B0A-4CC0-8E15-054621A3DCD9} => C:\Program Files (x86)\Free Download Manager\fdm.exe [2013-10-25] (FreeDownloadManager.ORG)
Task: {C2F62F30-F61D-4C2D-BC58-6A1C48EFD67F} - System32\Tasks\DistromaticSearchProtect-hourly => C:\Program Files (x86)\Amazon Browser Settings\AmznSearchProtect.exe [2016-04-11] (Distromatic) <==== ATTENTION
Task: {DA3F504E-A18A-4B3F-8437-A10EA5C82110} - System32\Tasks\PCDDataUploadTask => uaclauncher.exe
Task: {ECB29AA5-CB71-4C87-B5BE-26FBE85FCB6B} - System32\Tasks\LAUNCH CDPCO => C:\Program Files (x86)\CyberDefender\PC Optimizer\CDPCO.exe
Task: {FAE1BDD3-A195-4FA6-8C6B-E73499DC9202} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2017-02-02] (Adobe Systems Incorporated)
Task: {FE1FED99-BD68-4591-8B35-6E562B5D3154} - System32\Tasks\DSite => C:\Users\Joey\AppData\Roaming\DSite\UPDATE~1\UPDATE~1.EXE <==== ATTENTION
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\Windows\Tasks\DSite.job => C:\Users\Joey\AppData\Roaming\DSite\UPDATE~1\UPDATE~1.EXE <==== ATTENTION
Task: C:\Windows\Tasks\Norton Security Scan for Joey.job => C:\PROGRA~2\NORTON~2\Engine\410~1.28\Nss.exe
 
==================== Shortcuts & WMI ========================
 
(The entries could be listed to be restored or removed.)
 
 
==================== Loaded Modules (Whitelisted) ==============
 
2016-06-07 23:06 - 2016-06-07 23:06 - 000152688 _____ () C:\Program Files (x86)\ScreenSnapshotTool\1.1.0.11414\ScreenShotServ.exe
2016-06-07 23:05 - 2016-06-07 23:05 - 001824368 _____ () C:\Program Files (x86)\ScreenSnapshotTool\1.1.0.11414\ScreenSnapshot.exe
2012-05-12 03:04 - 2012-01-26 22:49 - 002751808 ____N () C:\Program Files (x86)\AlienRespawn\COMPONENTS\SCHEDULER\STSERVICE.EXE
2011-11-03 19:01 - 2011-11-03 19:01 - 001546096 _____ () C:\Program Files (x86)\Alienware On-Screen Display\AlienwareOn-ScreenDisplay.exe
2017-09-22 23:47 - 2017-09-22 23:47 - 000068528 _____ () C:\Program Files (x86)\AVG\Antivirus\x64\module_lifetime.dll
2017-09-22 23:47 - 2017-09-22 23:47 - 000170952 _____ () c:\Program Files (x86)\AVG\Antivirus\x64\vaarclient.dll
2017-09-22 23:47 - 2017-09-22 23:47 - 000826064 _____ () C:\Program Files (x86)\AVG\Antivirus\x64\ffl2.dll
2017-09-22 23:47 - 2017-09-22 23:47 - 000287832 _____ () c:\Program Files (x86)\AVG\Antivirus\x64\StreamBack.dll
2017-09-21 18:57 - 2017-08-23 04:48 - 003824472 _____ () C:\Program Files (x86)\Google\Chrome\Application\60.0.3112.113\libglesv2.dll
2017-09-21 18:57 - 2017-08-23 04:48 - 000100184 _____ () C:\Program Files (x86)\Google\Chrome\Application\60.0.3112.113\libegl.dll
2017-09-22 23:47 - 2017-09-22 23:47 - 000060160 _____ () C:\Program Files (x86)\AVG\Antivirus\module_lifetime.dll
2017-09-22 23:47 - 2017-09-22 23:47 - 000168216 _____ () C:\Program Files (x86)\AVG\Antivirus\JsonRpcServer.dll
2017-09-22 23:47 - 2017-09-22 23:47 - 000213024 _____ () C:\Program Files (x86)\AVG\Antivirus\event_routing_rpc.dll
2017-09-22 23:47 - 2017-09-22 23:47 - 000243080 _____ () C:\Program Files (x86)\AVG\Antivirus\tasks_core.dll
2017-09-22 23:47 - 2017-09-22 23:47 - 000150688 _____ () C:\Program Files (x86)\AVG\Antivirus\network_notifications.dll
2017-09-23 18:16 - 2017-09-23 18:16 - 005899912 _____ () C:\Program Files (x86)\AVG\Antivirus\defs\17092300\algo.dll
2017-09-22 23:47 - 2017-09-22 23:47 - 000686808 _____ () C:\Program Files (x86)\AVG\Antivirus\ffl2.dll
2017-09-22 23:47 - 2017-09-22 23:47 - 000242568 _____ () C:\Program Files (x86)\AVG\Antivirus\streamback.dll
2012-03-26 15:57 - 2012-03-26 15:57 - 001074808 _____ () C:\Program Files (x86)\Common Files\CyberDefender\DEL\DEL_dll.dll
2017-09-22 23:47 - 2017-09-22 23:47 - 067109376 _____ () C:\Program Files (x86)\AVG\Antivirus\libcef.dll
2009-12-18 12:07 - 2009-12-18 12:07 - 000577536 _____ () C:\Program Files (x86)\Alienware On-Screen Display\EMSC.dll
2017-09-22 23:43 - 2017-09-22 23:43 - 048920064 _____ () C:\Program Files (x86)\AVG\UiDll\2623\libcef.dll
2017-09-22 05:04 - 2017-09-22 05:04 - 000172032 _____ () C:\Windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\f203ecbdc8e8f4f836e1627efb89f9ae\IsdiInterop.ni.dll
2012-05-12 02:55 - 2011-11-29 21:00 - 000059392 _____ () C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IsdiInterop.dll
2012-05-12 02:55 - 2012-02-01 18:44 - 001198872 _____ () C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\ACE.dll
2012-07-29 15:24 - 2012-07-13 20:17 - 002003424 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
2012-03-04 15:51 - 2012-03-04 15:51 - 000362304 _____ () C:\Program Files (x86)\NVIDIA Corporation\3D Vision\Nv3DVStreaming.dll
2016-05-11 22:03 - 2016-05-11 22:03 - 000019008 _____ () C:\Program Files (x86)\Java\jre1.8.0_91\bin\jp2native.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\sndappv2 => ""="service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SplashtopRemoteService => ""="Service"
 
==================== Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
IE trusted site: HKU\S-1-5-21-1979518111-4107658783-1214925503-1001\...\amazon.com -> hxxps://amazon.com
IE trusted site: HKU\S-1-5-21-1979518111-4107658783-1214925503-1001\...\clonewarsadventures.com -> clonewarsadventures.com
IE trusted site: HKU\S-1-5-21-1979518111-4107658783-1214925503-1001\...\freerealms.com -> freerealms.com
IE trusted site: HKU\S-1-5-21-1979518111-4107658783-1214925503-1001\...\soe.com -> soe.com
IE trusted site: HKU\S-1-5-21-1979518111-4107658783-1214925503-1001\...\sony.com -> sony.com
 
==================== Hosts content: ===============================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2009-07-13 22:34 - 2016-04-11 21:03 - 000000824 _____ C:\Windows\system32\Drivers\etc\hosts
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-1979518111-4107658783-1214925503-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Joey\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 75.75.75.75 - 75.75.76.76
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
MSCONFIG\startupreg: (default) => 
MSCONFIG\startupreg: Adobe Reader Speed Launcher => "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
MSCONFIG\startupreg: BLEServicesCtrl => C:\Program Files (x86)\Intel\Bluetooth\BleServicesCtrl.exe
MSCONFIG\startupreg: BTMTrayAgent => rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll",TrayApp
MSCONFIG\startupreg: Command Center Controllers => "C:\Program Files\Alienware\Command Center\AWCCStartupOrchestrator.exe"
MSCONFIG\startupreg: HotKeysCmds => C:\Windows\system32\hkcmd.exe
MSCONFIG\startupreg: IAStorIcon => C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
MSCONFIG\startupreg: Integrated Webcam Live! Central => "C:\Program Files (x86)\Integrated Webcam\Live! Central\WebcamInt.exe" /mode2
MSCONFIG\startupreg: Nike+ Connect => "C:\Program Files (x86)\Nike\Nike+ Connect\Nike+ Connect daemon.exe"
MSCONFIG\startupreg: NowUSeeIt Player => "C:\Program Files (x86)\NowUSeeItPlayer\NowUSeeItPlayer.exe" /autostart=1
MSCONFIG\startupreg: Persistence => C:\Windows\system32\igfxpers.exe
MSCONFIG\startupreg: Sound Blaster Recon3Di Control Panel => "c:\Program Files (x86)\Creative\Sound Blaster Recon3Di\Sound Blaster Recon3Di Control Panel\SBRcni.exe" /r
MSCONFIG\startupreg: SynTPEnh => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
MSCONFIG\startupreg: UpdReg => C:\Windows\UpdReg.EXE
MSCONFIG\startupreg: vProt => "C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe"
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [{5301C8EF-720D-4C8A-89F9-AF5AB1922725}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
FirewallRules: [{269D4DF6-AF70-48BA-A16D-D9ECCC6571FF}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
FirewallRules: [{7E98D223-4693-45A8-B258-814D1C8BCCC2}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
FirewallRules: [{70A7EB36-9E9A-44EA-9C50-48A7DD063354}] => (Allow) C:\Program Files (x86)\Intel Corporation\Intel WiDi\WiDiApp.exe
FirewallRules: [{DBB3D089-090F-47D9-B97A-C5FAF28D49C1}] => (Allow) C:\Program Files (x86)\Electronic Arts\BioWare\Star Wars - The Old Republic\swtor\retailclient\swtor.exe
FirewallRules: [{7E1794E1-7841-4A50-AB53-8C48D7A22349}] => (Allow) C:\Program Files (x86)\Electronic Arts\BioWare\Star Wars - The Old Republic\swtor\retailclient\swtor.exe
FirewallRules: [{4C0EC52B-1F77-4F7F-B2EE-B349EA4E4FD1}] => (Allow) C:\Program Files (x86)\Electronic Arts\BioWare\Star Wars - The Old Republic\swtor\retailclient\swtor.exe
FirewallRules: [{22D8EEB9-A174-428C-8C0B-A774D4CB74E7}] => (Allow) C:\Program Files (x86)\Electronic Arts\BioWare\Star Wars - The Old Republic\swtor\retailclient\swtor.exe
FirewallRules: [{7EB91939-45B8-4BA1-99AA-9C48140B2580}] => (Allow) C:\Program Files (x86)\Electronic Arts\BioWare\Star Wars - The Old Republic\launcher.exe
FirewallRules: [{14DC147E-3B56-48E1-B4C8-5F5BCF1E3BE4}] => (Allow) C:\Program Files (x86)\Electronic Arts\BioWare\Star Wars - The Old Republic\launcher.exe
FirewallRules: [{E67DC644-CBD8-47EC-ADB9-30953B995AAF}] => (Allow) C:\Program Files (x86)\Electronic Arts\BioWare\Star Wars - The Old Republic\launcher.exe
FirewallRules: [{A1DB4724-19B9-4647-B84A-8562ACB2BA15}] => (Allow) C:\Program Files (x86)\Electronic Arts\BioWare\Star Wars - The Old Republic\launcher.exe
FirewallRules: [TCP Query User{125C4FD9-7727-43E6-85FF-E13FB688A2D1}C:\program files (x86)\java\jre7\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre7\bin\javaw.exe
FirewallRules: [UDP Query User{9484D1B1-1C2C-43E5-AF3F-435B870FD8A2}C:\program files (x86)\java\jre7\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre7\bin\javaw.exe
FirewallRules: [TCP Query User{CE2DD44C-86A2-40A4-8E52-D9645BF1F1ED}C:\program files (x86)\java\jre7\bin\javaw.exe] => (Block) C:\program files (x86)\java\jre7\bin\javaw.exe
FirewallRules: [UDP Query User{75CF2FC3-8865-49C9-92CB-A1E81C8BF24D}C:\program files (x86)\java\jre7\bin\javaw.exe] => (Block) C:\program files (x86)\java\jre7\bin\javaw.exe
FirewallRules: [{71D83F0A-8E82-465B-B2B0-864C8275C845}] => (Allow) C:\Users\Joey\Documents\The War Z\WarZ.exe
FirewallRules: [{0DB2CF47-AD69-43BB-8740-6F40F6189071}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{616E3EC6-7CA3-4E3C-A4B3-74DC57B78F04}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [TCP Query User{87D3B3F1-E4CE-4C56-86F0-4EA824C1C9BB}C:\program files (x86)\steam\steamapps\common\planetside 2\planetside2.exe] => (Block) C:\program files (x86)\steam\steamapps\common\planetside 2\planetside2.exe
FirewallRules: [UDP Query User{DA543E2D-0647-43E9-942B-0A75BD0A8381}C:\program files (x86)\steam\steamapps\common\planetside 2\planetside2.exe] => (Block) C:\program files (x86)\steam\steamapps\common\planetside 2\planetside2.exe
FirewallRules: [{393B8EAB-5BDA-4115-A8CD-A6787ED1D115}] => (Allow) C:\ProgramData\Turbine\The Lord of the Rings Online\lotroclient.exe
FirewallRules: [{C9EFF3D2-1305-4C88-AE9B-1B8A70783255}] => (Allow) C:\ProgramData\Turbine\The Lord of the Rings Online\lotroclient.exe
FirewallRules: [{AAF4FE3C-6E31-4B3C-AE17-36898965AE35}] => (Allow) C:\ProgramData\Turbine\The Lord of the Rings Online\TurbineLauncher.exe
FirewallRules: [{6D5F1498-C370-4685-88CA-99D9ED80876B}] => (Allow) C:\ProgramData\Turbine\The Lord of the Rings Online\TurbineLauncher.exe
FirewallRules: [{6652218A-2C3E-4878-9AD5-FAAC64E6FCE0}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{E57CFE2E-DBE0-4CCD-AC94-35FDEBE1C066}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{EBFA86F8-07B0-468D-A894-EF1EDAC65D8D}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dont_starve\bin\dontstarve_steam.exe
FirewallRules: [{4FE08C08-84D8-40FB-B0A3-0C2FFF2AC3D4}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dont_starve\bin\dontstarve_steam.exe
FirewallRules: [{FD11116B-3795-468E-9D9A-A36298CD0923}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{FD789060-EE00-48B8-AFF7-B01B8183F624}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{D4877180-EC25-4161-A4AA-83495C7B4477}] => (Allow) C:\Nexon\Library\vindictus\appdata\en-US\NMService.exe
FirewallRules: [{0C44A75E-A2CA-4B51-A986-1990515F7F83}] => (Allow) C:\Nexon\Library\vindictus\appdata\en-US\NMService.exe
FirewallRules: [TCP Query User{F57E5599-FA77-4F07-A25E-9C1ADE2090C8}C:\program files (x86)\java\jre1.8.0_45\bin\javaw.exe] => (Block) C:\program files (x86)\java\jre1.8.0_45\bin\javaw.exe
FirewallRules: [UDP Query User{BB65DDCE-3B77-4BD0-ACE5-70512C203076}C:\program files (x86)\java\jre1.8.0_45\bin\javaw.exe] => (Block) C:\program files (x86)\java\jre1.8.0_45\bin\javaw.exe
FirewallRules: [TCP Query User{EE7C12EC-1B70-476D-A3AC-DEE0A37D5FF2}C:\program files (x86)\java\jre1.8.0_77\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_77\bin\javaw.exe
FirewallRules: [UDP Query User{39E97CFC-CC2D-421D-980A-B725B4A2596E}C:\program files (x86)\java\jre1.8.0_77\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_77\bin\javaw.exe
FirewallRules: [{2F8C8840-4D46-4913-9ABB-A5808BD589B2}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{07205FA3-B249-463E-969B-C158CCDA7BF9}] => (Allow) C:\Users\Joey\AppData\Local\Chromium\Application\chrome.exe
 
==================== Restore Points =========================
 
22-09-2017 00:15:05 Windows Update
22-09-2017 00:30:07 Windows Defender Checkpoint
22-09-2017 03:00:18 Windows Update
23-09-2017 18:16:31 Windows Update
 
==================== Faulty Device Manager Devices =============
 
Name: Microsoft Virtual WiFi Miniport Adapter #2
Description: Microsoft Virtual WiFi Miniport Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: vwifimp
Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31)
Resolution: Update the driver
 
Name: Microsoft Teredo Tunneling Adapter
Description: Microsoft Teredo Tunneling Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (09/23/2017 06:20:45 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: ZeroConfigService.exe, version: 15.1.0.2, time stamp: 0x4f4a262d
Faulting module name: MurocApi.dll, version: 15.1.0.1, time stamp: 0x4f4a2503
Exception code: 0xc0000005
Fault offset: 0x000000000002084b
Faulting process id: 0xae4
Faulting application start time: 0x01d334ba20d80227
Faulting application path: C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
Faulting module path: C:\Program Files\Intel\WiFi\bin\MurocApi.dll
Report Id: 7129340c-a0ad-11e7-a9a0-685d432149f3
 
Error: (09/23/2017 06:20:42 PM) (Source: Application Virtualization Client) (EventID: 3008) (User: )
Description: {hap=16:app=OfficeVirt 9014006204090000:tid=170}
The client was unable to connect to an Application Virtualization Server (rc 24604E0A-40000193)
 
Error: (09/23/2017 06:20:42 PM) (Source: Application Virtualization Client) (EventID: 5009) (User: )
Description: {hap=16:app=OfficeVirt 9014006204090000:tid=170}
The Application Virtualization Client could not connect to stream URL 'http://c2r.microsoft.com/EssentialsC2R/en-us/14.0.4763.1000/EssentialsC2R.en-us_14.0.6137.5006.sft' (rc 24604E0A-40000193, original rc 24604E0A-40000193).
 
Error: (09/23/2017 06:20:30 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
 
Error: (09/22/2017 11:49:29 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "C:\Program Files (x86)\AVG\Antivirus\setup\iplugins\IStats.dll".
Dependent Assembly Avast.VC110.CRT,processorArchitecture="x86",publicKeyToken="2036b14a11e83e4a",type="win32",version="11.0.60610.1" could not be found.
Please use sxstrace.exe for detailed diagnosis.
 
Error: (09/22/2017 06:40:23 PM) (Source: Dell System Detect) (EventID: 0) (User: )
Description: <Exception><Type>System.Xml.XmlException</Type><Message><![CDATA[The '/' character, hexadecimal value 0x2F, cannot be included in a name.]]></Message><Source><![CDATA[System.Xml]]></Source><StackTrace><![CDATA[   at System.Xml.XmlDocument.CheckName(String name)
   at System.Xml.XmlDocument.CreateElement(String prefix, String localName, String namespaceURI)
   at eSupport.Common.Client.Core.LastUpdatedHelper.SetLastUpdatedValue(String type, String value)]]></StackTrace><SysInfo STag="C6BCDS1" SMBIOSMajVer="2" SMBIOSMinVer="7" SMBIOSBIOSVer="A01" SMBIOSPresent="True" Rel_Date="20120208000000.000000+000" DSDVersion="" Vendor="Alienware" PName="M14xR2" Ident_Num="JOEY-PC" TimeZone="(UTC-05:00) Eastern Time (US & Canada)" OSName="Microsoft Windows 7 Home Premium"/><Method>UpdateLastUpdatedConfig</Method><HostIP>10.0.0.247</HostIP></Exception>
 
Error: (09/22/2017 06:40:23 PM) (Source: Dell System Detect) (EventID: 0) (User: )
Description: <Exception><Type>System.Xml.XmlException</Type><Message><![CDATA[The '/' character, hexadecimal value 0x2F, cannot be included in a name.]]></Message><Source><![CDATA[System.Xml]]></Source><StackTrace><![CDATA[   at System.Xml.XmlDocument.CheckName(String name)
   at System.Xml.XmlDocument.CreateElement(String prefix, String localName, String namespaceURI)
   at eSupport.Common.Client.Core.LastUpdatedHelper.SetLastUpdatedValue(String type, String value)]]></StackTrace><SysInfo STag="C6BCDS1" SMBIOSMajVer="2" SMBIOSMinVer="7" SMBIOSBIOSVer="A01" SMBIOSPresent="True" Rel_Date="20120208000000.000000+000" DSDVersion="" Vendor="Alienware" PName="M14xR2" Ident_Num="JOEY-PC" TimeZone="(UTC-05:00) Eastern Time (US & Canada)" OSName="Microsoft Windows 7 Home Premium"/><Method>UpdateLastUpdatedConfig</Method><HostIP>10.0.0.247</HostIP></Exception>
 
Error: (09/22/2017 06:15:13 PM) (Source: Dell System Detect) (EventID: 0) (User: )
Description: <Exception><Type>System.Xml.XmlException</Type><Message><![CDATA[The '/' character, hexadecimal value 0x2F, cannot be included in a name.]]></Message><Source><![CDATA[System.Xml]]></Source><StackTrace><![CDATA[   at System.Xml.XmlDocument.CheckName(String name)
   at System.Xml.XmlDocument.CreateElement(String prefix, String localName, String namespaceURI)
   at eSupport.Common.Client.Core.LastUpdatedHelper.SetLastUpdatedValue(String type, String value)]]></StackTrace><SysInfo STag="C6BCDS1" SMBIOSMajVer="2" SMBIOSMinVer="7" SMBIOSBIOSVer="A01" SMBIOSPresent="True" Rel_Date="20120208000000.000000+000" DSDVersion="" Vendor="Alienware" PName="M14xR2" Ident_Num="JOEY-PC" TimeZone="(UTC-05:00) Eastern Time (US & Canada)" OSName="Microsoft Windows 7 Home Premium"/><Method>UpdateLastUpdatedConfig</Method><HostIP>10.0.0.247</HostIP></Exception>
 
Error: (09/22/2017 06:11:51 PM) (Source: MsiInstaller) (EventID: 11706) (User: Joey-PC)
Description: Product: Dell Data Vault -- Error 1706. An installation package for the product Dell Data Vault cannot be found. Try the installation again using a valid copy of the installation package 'DDV.msi'.
 
Error: (09/22/2017 05:57:07 PM) (Source: Application Virtualization Client) (EventID: 3008) (User: )
Description: {hap=16:app=OfficeVirt 9014006204090000:tid=D64}
The client was unable to connect to an Application Virtualization Server (rc 24604E0A-40000193)
 
 
System errors:
=============
Error: (09/23/2017 06:23:45 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The NVIDIA Update Service Daemon service failed to start due to the following error: 
The service did not start due to a logon failure.
 
Error: (09/23/2017 06:23:45 PM) (Source: Service Control Manager) (EventID: 7038) (User: )
Description: The nvUpdatusService service was unable to log on as .\UpdatusUser with the currently configured password due to the following error: 
Logon failure: the specified account password has expired.
 
 
To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC).
 
Error: (09/23/2017 06:21:01 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Intel® PROSet/Wireless Zero Configuration Service service terminated unexpectedly.  It has done this 1 time(s).
 
Error: (09/23/2017 06:20:14 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The vToolbarUpdater17.3.0 service failed to start due to the following error: 
The system cannot find the file specified.
 
Error: (09/23/2017 06:19:51 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 6:18:15 PM on ‎9/‎23/‎2017 was unexpected.
 
Error: (09/22/2017 05:59:21 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The NVIDIA Update Service Daemon service failed to start due to the following error: 
The service did not start due to a logon failure.
 
Error: (09/22/2017 05:59:21 PM) (Source: Service Control Manager) (EventID: 7038) (User: )
Description: The nvUpdatusService service was unable to log on as .\UpdatusUser with the currently configured password due to the following error: 
Logon failure: the specified account password has expired.
 
 
To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC).
 
Error: (09/22/2017 05:56:38 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The vToolbarUpdater17.3.0 service failed to start due to the following error: 
The system cannot find the file specified.
 
Error: (09/22/2017 05:56:14 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 7:19:13 AM on ‎9/‎22/‎2017 was unexpected.
 
Error: (09/22/2017 04:27:29 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The NVIDIA Update Service Daemon service failed to start due to the following error: 
The service did not start due to a logon failure.
 
 
==================== Memory info =========================== 
 
Processor: Intel® Core™ i5-2450M CPU @ 2.50GHz
Percentage of memory in use: 52%
Total physical RAM: 6044.31 MB
Available physical RAM: 2872.53 MB
Total Virtual: 12086.81 MB
Available Virtual: 8829.89 MB
 
==================== Drives ================================
 
Drive c: (OS) (Fixed) (Total:446.99 GB) (Free:309.09 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 465.8 GB) (Disk ID: 15215103)
Partition 1: (Not Active) - (Size=39 MB) - (Type=DE)
Partition 2: (Active) - (Size=18.7 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=447 GB) - (Type=07 NTFS)
 
==================== End of Addition.txt ============================

 



BC AdBot (Login to Remove)

 


#2 Aura

Aura

    Bleepin' Special Ops


  • Malware Response Team
  • 19,697 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:11:00 PM

Posted 24 September 2017 - 09:36 AM

Hi Mugga :)

My name is Aura and I'll be assisting you with your malware issue. Since we'll be working together, you can call me Aura or Yoan, which is my real name, it's up to you! Now that we've broke the ice, I'll just ask you a few things during the time we'll be working together to clean your system and get it back to an operational state.
  • As you'll notice, the logs we are asking for here are quite lenghty, so it's normal for me to not reply exactly after you post them. This is because I need some time to analyse them and then act accordingly. However, I'll always reply within 24 hours, 48 hours at most if something unexpected happens
  • As long as I'm assisting you on BleepingComputer, in this thread, I'll ask you to not seek assistance anywhere else for any issue related to the system we are working on. If you have an issue, question, etc. about your computer, please ask it in this thread and I'll assist you
  • The same principle applies to any modifications you make to your system, I would like you to ask me before you do any manipulations that aren't in the instructions I posted. This is to ensure that we are operating in sync and I know exactly what's happening on your system
  • If you aren't sure about an instruction I'm giving you, ask me about it. This is to ensure that the clean-up process goes without any issue. I'll answer you and even give you more precise instructions/explanations if you need. There's no shame in asking questions here, better be safe than sorry!
  • If you don't reply to your thread within 3 days, I'll bump this thread to let you know that I'm waiting for you. If you don't reply after 5 days, it'll be closed. If you return after that period, you can send me a PM to get it unlocked and we'll continue where we left off
  • Since malware can work quickly, we want to get rid of them as fast as we can, before they make unknown changes to the system. This being said, I would appreciate if you could reply to this thread within 24 hours of me posting. This way, we'll have a good clean-up rhythm and the chances of complications will be reduced
  • I'm against any form of pirated, illegal and counterfeit software and material. So if you have any installed on your system, I'll ask you to uninstall them right now. You don't have to tell me if you indeed had some or not, I'll give you the benefit of the doubt. Plus, this would be against BleepingComputer's rules
  • In the end, you are the one asking for assistance here. So if you wish to go a different way during the clean-up, like format and reinstall Windows, you are free to do so. I would appreciate you to let me know about it first, and if you need, I can also assist you in the process
  • I would appreciate if you were to stay with me until the end, which means, until I declare your system clean. Just because your system isn't behaving weirdly anymore, or is running better than before, it doesn't mean that the infection is completely gone
    This being said, I have a full time job so sometimes it'll take longer for me to reply to you. Don't worry, you'll be my first priority as soon as I get home and have time to look at your thread
This being said, it's time to clean-up some malware, so let's get started, shall we? :)

j1Bynr2.pngMalwarebytes - Clean Mode
  • Download and install the free version of Malwarebytes
    Note: If you have Malwarebytes already installed, you don't need to install it again. Simply start from the next bullet point
  • Once Malwarebytes is installed, launch it and let it update his database. You might have to click on the little arrow by Scan Status in the middle right pane for it to do so
  • Once the database update is complete, click on the Scan tab, then select the Threat Scan button and click on Start Scan
  • Let the scan run, the time required to complete the scan depends of your system and computer specs
  • Once the scan is complete, make sure that the first checkbox at the top is checked (which will automatically check every detected item), then click on the Quarantine Selected button
    • If it asks you to restart your computer to complete the removal, do so
  • Click on Export Summary after the deletion (in the bottom-left corner) and select Copy to Clipboard. Paste the content in your next reply
RQKuhw1.pngRogueKiller
  • Download the right version of RogueKiller for your Windows version (32 or 64-bit)
  • Once done, move the executable file to your Desktop, right-click on it and select Spcusrh.pngRun as Administrator (for Windows Vista, 7, 8, 8.1 and 10 users)
  • Click on the Start Scan button in the right panel, which will bring you to another tab, and click on it again (this time it'll be in the bottom right corner)
  • Wait for the scan to complete
  • On completion, the results will be displayed
  • Check every single entry (threat found), and click on the Remove Selected button
  • On completion, the results will be displayed. Click on the Open Report button in the bottom left corner, followed by the Open TXT button (also in the bottom left corner)
  • This will open the report in Notepad. Copy/paste its content in your next reply
Your next reply(ies) should therefore contain:
  • Copy/pasted Malwarebytes clean log
  • Copy/pasted RogueKiller clean log

animinionsmalltext.gif
unite_blue.png
Security Administrator | Sysnative Windows Update Senior Analyst | Malware Hunter | @SecurityAura
My timezone UTC-05:00 (East. Coast). If I didn't reply to you within 48 hours, please send me a PM.


#3 Mugga

Mugga
  • Topic Starter

  • Members
  • 12 posts
  • OFFLINE
  •  
  • Local time:12:00 AM

Posted 26 September 2017 - 09:14 PM

Malwarebytes
www.malwarebytes.com
 
-Log Details-
Scan Date: 9/26/17
Scan Time: 4:36 PM
Log File: 6170e044-a2fa-11e7-8e9e-685d432149f3.json
Administrator: Yes
 
-Software Information-
Version: 3.2.2.2029
Components Version: 1.0.188
Update Package Version: 1.0.2893
License: Trial
 
-System Information-
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Joey-PC\Joey
 
-Scan Summary-
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 381662
Threats Detected: 546
Threats Quarantined: 537
Time Elapsed: 54 min, 9 sec
 
-Scan Options-
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Detect
PUM: Detect
 
-Scan Details-
Process: 4
PUP.Optional.ScreenSnapShotTool, C:\Program Files (x86)\ScreenSnapshotTool\1.1.0.11414\ScreenShotServ.exe, Quarantined, [206], [245713],1.0.2893
PUP.Optional.ScreenSnapShotTool, C:\Program Files (x86)\ScreenSnapshotTool\1.1.0.11414\ScreenSnapshot.exe, Quarantined, [206], [245713],1.0.2893
PUP.Optional.Amazon1Button.AppFlsh, C:\Program Files (x86)\Amazon\Amazon1ButtonApp\Amazon1ButtonService64.Exe, Quarantined, [1472], [333344],1.0.2893
PUP.Optional.ScreenSnapShotTool, C:\PROGRAM FILES (X86)\SCREENSNAPSHOTTOOL\1.1.0.11414\SCREENSHOTSERV.EXE, Quarantined, [206], [245719],1.0.2893
 
Module: 4
PUP.Optional.ScreenSnapShotTool, C:\Program Files (x86)\ScreenSnapshotTool\1.1.0.11414\ScreenShotServ.exe, Quarantined, [206], [245713],1.0.2893
PUP.Optional.ScreenSnapShotTool, C:\Program Files (x86)\ScreenSnapshotTool\1.1.0.11414\ScreenSnapshot.exe, Quarantined, [206], [245713],1.0.2893
PUP.Optional.Amazon1Button.AppFlsh, C:\Program Files (x86)\Amazon\Amazon1ButtonApp\Amazon1ButtonService64.Exe, Quarantined, [1472], [333344],1.0.2893
PUP.Optional.ScreenSnapShotTool, C:\PROGRAM FILES (X86)\SCREENSNAPSHOTTOOL\1.1.0.11414\SCREENSHOTSERV.EXE, Quarantined, [206], [245719],1.0.2893
 
Registry Key: 130
PUP.Optional.Revizer.PrxySvrRST, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\NLASVC\PARAMETERS\INTERNET\MANUALPROXIES, Quarantined, [9050], [-1],0.0.0
PUP.Optional.ScreenSnapShotTool, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{61FFE1F9-137D-4c31-A181-3415FCAA5946}, Quarantined, [206], [245713],1.0.2893
PUP.Optional.ScreenSnapShotTool, HKLM\SOFTWARE\{61FFE1F9-137D-4C31-A181-3415FCAA5946}, Quarantined, [206], [245713],1.0.2893
PUP.Optional.ScreenSnapShotTool, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\TheScreenSnapshotService, Quarantined, [206], [245713],1.0.2893
PUP.Optional.Yontoo, HKLM\SOFTWARE\POLICIES\GOOGLE\CHROME, Quarantined, [39], [-1],0.0.0
PUP.Optional.Yontoo, HKLM\SOFTWARE\WOW6432NODE\POLICIES\GOOGLE\CHROME, Quarantined, [39], [-1],0.0.0
PUP.Optional.Amazon1Button.AppFlsh, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{BAC72C85-CEC6-4B86-AF06-FA20C259FAB8}, Quarantined, [1472], [333344],1.0.2893
PUP.Optional.Amazon1Button.AppFlsh, HKLM\SOFTWARE\CLASSES\Amazon1ButtonBrowserHelper.Amazon1ButtonBHO, Quarantined, [1472], [333344],1.0.2893
PUP.Optional.Amazon1Button.AppFlsh, HKLM\SOFTWARE\CLASSES\CLSID\{BAC72C85-CEC6-4B86-AF06-FA20C259FAB8}, Quarantined, [1472], [333344],1.0.2893
PUP.Optional.Amazon1Button.AppFlsh, HKLM\SOFTWARE\CLASSES\TYPELIB\{921462B2-5269-45A2-AA8D-F8F7A3690255}, Quarantined, [1472], [333344],1.0.2893
PUP.Optional.Amazon1Button.AppFlsh, HKLM\SOFTWARE\CLASSES\INTERFACE\{FD1B7376-A344-48BD-857D-C87B4D8502EF}, Quarantined, [1472], [333344],1.0.2893
PUP.Optional.Amazon1Button.AppFlsh, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{FD1B7376-A344-48BD-857D-C87B4D8502EF}, Quarantined, [1472], [333344],1.0.2893
PUP.Optional.Amazon1Button.AppFlsh, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{FD1B7376-A344-48BD-857D-C87B4D8502EF}, Quarantined, [1472], [333344],1.0.2893
PUP.Optional.Amazon1Button.AppFlsh, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{921462B2-5269-45A2-AA8D-F8F7A3690255}, Quarantined, [1472], [333344],1.0.2893
PUP.Optional.Amazon1Button.AppFlsh, HKLM\SOFTWARE\CLASSES\WOW6432NODE\TYPELIB\{921462B2-5269-45A2-AA8D-F8F7A3690255}, Quarantined, [1472], [333344],1.0.2893
PUP.Optional.Amazon1Button.AppFlsh, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{BAC72C85-CEC6-4B86-AF06-FA20C259FAB8}, Quarantined, [1472], [333344],1.0.2893
PUP.Optional.Amazon1Button.AppFlsh, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{BAC72C85-CEC6-4B86-AF06-FA20C259FAB8}\InprocServer32, Quarantined, [1472], [333344],1.0.2893
PUP.Optional.Amazon1Button.AppFlsh, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{BAC72C85-CEC6-4B86-AF06-FA20C259FAB8}\InprocServer32, Quarantined, [1472], [333344],1.0.2893
PUP.Optional.Amazon1Button.AppFlsh, HKLM\SOFTWARE\CLASSES\CLSID\{BAC72C85-CEC6-4B86-AF06-FA20C259FAB8}\InprocServer32, Quarantined, [1472], [333344],1.0.2893
PUP.Optional.Amazon1Button.AppFlsh, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{6557DB6C-EFE1-45AC-92A6-FBB1554B7502}, Quarantined, [1472], [333344],1.0.2893
PUP.Optional.Amazon1Button.AppFlsh, HKLM\SOFTWARE\CLASSES\Amazon1ButtonRuntime.Amazon1ButtonRuntime, Quarantined, [1472], [333344],1.0.2893
PUP.Optional.Amazon1Button.AppFlsh, HKLM\SOFTWARE\CLASSES\Amazon1ButtonRuntime.AmazonRuntimeServer, Quarantined, [1472], [333344],1.0.2893
PUP.Optional.Amazon1Button.AppFlsh, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{6557DB6C-EFE1-45AC-92A6-FBB1554B7502}, Quarantined, [1472], [333344],1.0.2893
PUP.Optional.Amazon1Button.AppFlsh, HKLM\SOFTWARE\CLASSES\TYPELIB\{48DDEC26-CEC3-478E-9566-0842DAF10CEA}, Quarantined, [1472], [333344],1.0.2893
PUP.Optional.Amazon1Button.AppFlsh, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{6B7479D5-C493-40F0-99B6-BFC901980034}, Quarantined, [1472], [333344],1.0.2893
PUP.Optional.Amazon1Button.AppFlsh, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{BFF94CF8-2D3B-4B2F-BB83-3600280AFEBA}, Quarantined, [1472], [333344],1.0.2893
PUP.Optional.Amazon1Button.AppFlsh, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{6B7479D5-C493-40F0-99B6-BFC901980034}, Quarantined, [1472], [333344],1.0.2893
PUP.Optional.Amazon1Button.AppFlsh, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{BFF94CF8-2D3B-4B2F-BB83-3600280AFEBA}, Quarantined, [1472], [333344],1.0.2893
PUP.Optional.Amazon1Button.AppFlsh, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{48DDEC26-CEC3-478E-9566-0842DAF10CEA}, Quarantined, [1472], [333344],1.0.2893
PUP.Optional.Amazon1Button.AppFlsh, HKLM\SOFTWARE\CLASSES\WOW6432NODE\TYPELIB\{48DDEC26-CEC3-478E-9566-0842DAF10CEA}, Quarantined, [1472], [333344],1.0.2893
PUP.Optional.Amazon1Button.AppFlsh, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{6557DB6C-EFE1-45AC-92A6-FBB1554B7502}\InprocServer32, Quarantined, [1472], [333344],1.0.2893
PUP.Optional.Amazon1Button.AppFlsh, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{6557DB6C-EFE1-45AC-92A6-FBB1554B7502}\InprocServer32, Quarantined, [1472], [333344],1.0.2893
PUP.Optional.Amazon1Button.AppFlsh, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\Amazon 1Button App Service, Quarantined, [1472], [333344],1.0.2893
PUP.Optional.Amazon1Button.AppFlsh, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{BD6ECB00-7C4A-4F97-B425-44117F2A7AAE}, Quarantined, [1472], [333344],1.0.2893
PUP.Optional.Amazon1Button.AppFlsh, HKLM\SOFTWARE\CLASSES\AmazonAppIE.AppGateway, Quarantined, [1472], [333344],1.0.2893
PUP.Optional.Amazon1Button.AppFlsh, HKLM\SOFTWARE\CLASSES\CLSID\{BD6ECB00-7C4A-4F97-B425-44117F2A7AAE}, Quarantined, [1472], [333344],1.0.2893
PUP.Optional.Amazon1Button.AppFlsh, HKLM\SOFTWARE\CLASSES\TYPELIB\{EB2BEAEF-150C-4DE4-9D09-F16403C22769}, Quarantined, [1472], [333344],1.0.2893
PUP.Optional.Amazon1Button.AppFlsh, HKLM\SOFTWARE\CLASSES\INTERFACE\{3268A00F-D329-42E1-ABF0-E78D5656BA2A}, Quarantined, [1472], [333344],1.0.2893
PUP.Optional.Amazon1Button.AppFlsh, HKLM\SOFTWARE\CLASSES\INTERFACE\{571139B2-8D93-4B29-9AA9-496EF27D6AF8}, Quarantined, [1472], [333344],1.0.2893
PUP.Optional.Amazon1Button.AppFlsh, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{3268A00F-D329-42E1-ABF0-E78D5656BA2A}, Quarantined, [1472], [333344],1.0.2893
PUP.Optional.Amazon1Button.AppFlsh, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{571139B2-8D93-4B29-9AA9-496EF27D6AF8}, Quarantined, [1472], [333344],1.0.2893
PUP.Optional.Amazon1Button.AppFlsh, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{3268A00F-D329-42E1-ABF0-E78D5656BA2A}, Quarantined, [1472], [333344],1.0.2893
PUP.Optional.Amazon1Button.AppFlsh, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{571139B2-8D93-4B29-9AA9-496EF27D6AF8}, Quarantined, [1472], [333344],1.0.2893
PUP.Optional.Amazon1Button.AppFlsh, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{EB2BEAEF-150C-4DE4-9D09-F16403C22769}, Quarantined, [1472], [333344],1.0.2893
PUP.Optional.Amazon1Button.AppFlsh, HKLM\SOFTWARE\CLASSES\WOW6432NODE\TYPELIB\{EB2BEAEF-150C-4DE4-9D09-F16403C22769}, Quarantined, [1472], [333344],1.0.2893
PUP.Optional.Amazon1Button.AppFlsh, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{BD6ECB00-7C4A-4F97-B425-44117F2A7AAE}, Quarantined, [1472], [333344],1.0.2893
PUP.Optional.Amazon1Button.AppFlsh, HKU\S-1-5-21-1979518111-4107658783-1214925503-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{BD6ECB00-7C4A-4F97-B425-44117F2A7AAE}, Quarantined, [1472], [333344],1.0.2893
PUP.Optional.Amazon1Button.AppFlsh, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{BD6ECB00-7C4A-4F97-B425-44117F2A7AAE}\InprocServer32, Quarantined, [1472], [333344],1.0.2893
PUP.Optional.Amazon1Button.AppFlsh, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{E4ADC61E-D06A-4E0E-8582-78C809CC8450}, Quarantined, [1472], [333344],1.0.2893
PUP.Optional.Amazon1Button.AppFlsh, HKLM\SOFTWARE\CLASSES\AmazonAppIE.GadgetGateway, Quarantined, [1472], [333344],1.0.2893
PUP.Optional.Amazon1Button.AppFlsh, HKLM\SOFTWARE\CLASSES\CLSID\{E4ADC61E-D06A-4E0E-8582-78C809CC8450}, Quarantined, [1472], [333344],1.0.2893
PUP.Optional.Amazon1Button.AppFlsh, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{E4ADC61E-D06A-4E0E-8582-78C809CC8450}, Quarantined, [1472], [333344],1.0.2893
PUP.Optional.Amazon1Button.AppFlsh, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{E4ADC61E-D06A-4E0E-8582-78C809CC8450}\InprocServer32, Quarantined, [1472], [333344],1.0.2893
PUP.Optional.Amazon1Button.AppFlsh, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{BD6ECB00-7C4A-4F97-B425-44117F2A7AAE}\InprocServer32, Quarantined, [1472], [333344],1.0.2893
PUP.Optional.Amazon1Button.AppFlsh, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{E4ADC61E-D06A-4E0E-8582-78C809CC8450}\InprocServer32, Quarantined, [1472], [333344],1.0.2893
PUP.Optional.Amazon1Button.AppFlsh, HKLM\SOFTWARE\CLASSES\CLSID\{BD6ECB00-7C4A-4F97-B425-44117F2A7AAE}\InprocServer32, Quarantined, [1472], [333344],1.0.2893
PUP.Optional.Amazon1Button.AppFlsh, HKLM\SOFTWARE\CLASSES\CLSID\{E4ADC61E-D06A-4E0E-8582-78C809CC8450}\InprocServer32, Quarantined, [1472], [333344],1.0.2893
PUP.Optional.InstallCore, HKU\S-1-5-21-1979518111-4107658783-1214925503-1001\SOFTWARE\csastats, Quarantined, [2], [260986],1.0.2893
PUP.Optional.Distromatic, HKU\S-1-5-21-1979518111-4107658783-1214925503-1001\SOFTWARE\Distromatic, Quarantined, [2481], [359638],1.0.2893
PUP.Optional.InstallCore, HKU\S-1-5-21-1979518111-4107658783-1214925503-1001\SOFTWARE\ICSW1.19, Quarantined, [2], [239562],1.0.2893
PUP.Optional.OneSystemCare, HKU\S-1-5-21-1979518111-4107658783-1214925503-1001\SOFTWARE\One System Care, Quarantined, [467], [311038],1.0.2893
PUP.Optional.Amonetize, HKU\S-1-5-21-1979518111-4107658783-1214925503-1001\SOFTWARE\UpdaterEX, Quarantined, [6], [348112],1.0.2893
PUP.Optional.OneSystemCare, HKU\S-1-5-21-1979518111-4107658783-1214925503-1000\SOFTWARE\ONE SYSTEM CARE, Quarantined, [467], [241384],1.0.2893
PUP.Optional.SearchProtect, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\TRACING\cltmng_RASAPI32, Quarantined, [2066], [184777],1.0.2893
PUP.Optional.SearchProtect, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\TRACING\cltmng_RASMANCS, Quarantined, [2066], [184777],1.0.2893
PUP.Optional.DriverRestore, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\TRACING\DriverRestore_RASAPI32, Quarantined, [731], [336784],1.0.2893
PUP.Optional.DriverRestore, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\TRACING\DriverRestore_RASMANCS, Quarantined, [731], [336784],1.0.2893
PUP.Optional.TidyNetwork, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\TRACING\TNT2User_RASAPI32, Quarantined, [3619], [256466],1.0.2893
PUP.Optional.TidyNetwork, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\TRACING\TNT2User_RASMANCS, Quarantined, [3619], [256466],1.0.2893
Adware.DNSUnlocker.ACMB2, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\11598763487076930564, Quarantined, [1741], [424293],1.0.2893
PUP.Optional.SearchManager.ShrtCln, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\bahkljhhdeciiaodlkppoonappfnheoi, Quarantined, [698], [396193],1.0.2893
PUP.Optional.BetterSurf, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\dedmngkbaffkenlfdcbganndoghblmap, Quarantined, [920], [235790],1.0.2893
PUP.Optional.BetterSurf, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\poheodfamflhhhdcmjfeggbgigeefaco, Quarantined, [920], [235792],1.0.2893
PUP.Optional.DNSUnlocker.ACMB2, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\SYSTEMCERTIFICATES\ROOT\CERTIFICATES\26D9E607FFF0C58C7844B47FF8B6E079E5A2220E, Quarantined, [22], [260247],1.0.2893
PUP.Optional.CloudScout, HKLM\SOFTWARE\5da059a482fd494db3f252126fbc3d5b, Quarantined, [9749], [246387],1.0.2893
Adware.Yontoo, HKLM\SOFTWARE\Tarma Installer, Quarantined, [151], [382206],1.0.2893
PUP.Optional.DNSUnlocker.ACMB2, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{9b66bb7d}, Quarantined, [22], [260250],1.0.2893
PUP.Optional.ScreenSnapShotTool, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\TheScreenSnapshotService, Quarantined, [206], [245719],1.0.2893
PUP.Optional.DriverRestore, HKU\S-1-5-21-1979518111-4107658783-1214925503-1001\SOFTWARE\DRIVERRESTORE, Quarantined, [731], [259276],1.0.2893
PUP.Optional.SearchManager.ShrtCln, HKU\S-1-5-21-1979518111-4107658783-1214925503-1001\SOFTWARE\GOOGLE\CHROME\EXTENSIONS\bahkljhhdeciiaodlkppoonappfnheoi, Quarantined, [698], [396191],1.0.2893
PUP.Optional.ProductSetup, HKU\S-1-5-21-1979518111-4107658783-1214925503-1001\SOFTWARE\PRODUCTSETUP, Quarantined, [14123], [242047],1.0.2893
PUP.Optional.AmazonBrowserSettings, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\DistromaticSearchProtect-hourly, Quarantined, [12], [312599],1.0.2893
PUP.Optional.AmazonBrowserSettings, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\DistromaticSearchProtect-logon, Quarantined, [12], [312599],1.0.2893
PUP.Optional.AmazonBrowserSettings, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\DistromaticUpdater-logon, Quarantined, [12], [312599],1.0.2893
PUP.Optional.AmazonBrowserSettings, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\DistromaticUpdater-periodic, Quarantined, [12], [312599],1.0.2893
PUP.Optional.DigitalSites, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\DSite, Quarantined, [829], [358511],1.0.2893
PUP.Optional.USTechSupport, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\LAUNCH CDPCO, Quarantined, [1712], [336578],1.0.2893
PUP.Optional.ScreenSnapShotTool, HKLM\SOFTWARE\SCREENSNAPSHOTTOOL, Quarantined, [206], [246518],1.0.2893
PUP.Optional.DriverAgentPlus, HKU\S-1-5-21-1979518111-4107658783-1214925503-1001\SOFTWARE\ESUPPORT.COM\DriverAgent, Quarantined, [2259], [262210],1.0.2893
PUP.Optional.CloudScout, HKLM\SOFTWARE\WOW6432NODE\5da059a482fd494db3f252126fbc3d5b, Quarantined, [9749], [246387],1.0.2893
PUP.Optional.Amonetize, HKU\S-1-5-21-1979518111-4107658783-1214925503-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\UpdaterEX, Quarantined, [6], [348118],1.0.2893
PUP.Optional.SearchManager.ShrtCln, HKLM\SOFTWARE\GOOGLE\CHROME\EXTENSIONS\bahkljhhdeciiaodlkppoonappfnheoi, Quarantined, [698], [396193],1.0.2893
PUP.Optional.WinYahoo, HKU\S-1-5-21-1979518111-4107658783-1214925503-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{2F23AB71-4AC6-41F2-A955-EA576E553146}, Quarantined, [71], [182758],1.0.2893
PUP.Optional.WinYahoo, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{2f23ab71-4ac6-41f2-a955-ea576e553146}, Quarantined, [71], [182758],1.0.2893
PUP.Optional.WinYahoo, HKU\S-1-5-21-1979518111-4107658783-1214925503-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{44A02DE0-F784-4FA5-B9D3-33C6F8ECA78A}, Quarantined, [71], [182758],1.0.2893
PUP.Optional.WinYahoo, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{44A02DE0-F784-4FA5-B9D3-33C6F8ECA78A}, Quarantined, [71], [182758],1.0.2893
PUP.Optional.DNSUnlocker.ACMB2, HKLM\SOFTWARE\MICROSOFT\SYSTEMCERTIFICATES\ROOT\CERTIFICATES\26D9E607FFF0C58C7844B47FF8B6E079E5A2220E, Quarantined, [22], [260247],1.0.2893
PUP.Optional.AmazonBrowserSettings, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Amazon Assistant, Quarantined, [12], [312594],1.0.2893
PUP.Optional.ByteFence, HKLM\SOFTWARE\MICROSOFT\TRACING\ByteFence_RASAPI32, Quarantined, [626], [389038],1.0.2893
PUP.Optional.ByteFence, HKLM\SOFTWARE\MICROSOFT\TRACING\ByteFence_RASMANCS, Quarantined, [626], [389038],1.0.2893
PUP.Optional.AmazonBrowserSettings, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{0C209135-B8A5-40DA-B393-660189966A08}, Quarantined, [12], [312598],1.0.2893
PUP.Optional.AmazonBrowserSettings, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{14C13415-BFB7-4EF8-8F91-4B844B6362FD}, Quarantined, [12], [312598],1.0.2893
PUP.Optional.AmazonBrowserSettings, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{41F4814D-0BA3-4C2B-AB5D-D774B2B29068}, Quarantined, [12], [312598],1.0.2893
PUP.Optional.PCPerformer, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{59DF69F3-DDB9-430D-8966-F5C837534F57}, Quarantined, [2290], [258469],1.0.2893
PUP.Optional.AmazonBrowserSettings, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{C3D0D221-A843-47EB-903A-EC807CB6FFA9}, Quarantined, [12], [312598],1.0.2893
PUP.Optional.USTechSupport, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{ECB29AA5-CB71-4C87-B5BE-26FBE85FCB6B}, Quarantined, [1712], [336579],1.0.2893
PUP.Optional.DigitalSites, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{FE1FED99-BD68-4591-8B35-6E562B5D3154}, Quarantined, [829], [358502],1.0.2893
PUP.Optional.DNSUnlocker.ACMB2, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{E1527582-8509-4011-B922-29E3FB548882}_is1, Quarantined, [22], [260251],1.0.2893
PUP.Optional.ScreenSnapShotTool, HKLM\SOFTWARE\{61FFE1F9-137D-4C31-A181-3415FCAA5946}, Quarantined, [206], [245718],1.0.2893
PUP.Optional.ScreenSnapShotTool, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{61FFE1F9-137D-4c31-A181-3415FCAA5946}, Quarantined, [206], [245718],1.0.2893
PUP.Optional.WinYahoo, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{F4D21C12-A452-CD92-15D2-BD12C5526E92}, Quarantined, [71], [302717],1.0.2893
PUP.Optional.ASK, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\BROWSER HELPER OBJECTS\{D4027C7F-154A-4066-A1AD-4243D8127440}, Quarantined, [521], [306571],1.0.2893
PUP.Optional.ASK, HKLM\SOFTWARE\CLASSES\GenericAskToolbar.ToolbarWnd, Quarantined, [521], [306571],1.0.2893
PUP.Optional.ASK, HKLM\SOFTWARE\CLASSES\GenericAskToolbar.ToolbarWnd.1, Quarantined, [521], [306571],1.0.2893
PUP.Optional.USTechSupport, HKLM\SOFTWARE\CLASSES\TYPELIB\{7EC41441-2247-4DEC-BBFB-9E798627A17B}, Quarantined, [1712], [397953],1.0.2893
PUP.Optional.USTechSupport, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{A16AB1E1-377D-4DF2-8D8A-C9F283857DDC}, Quarantined, [1712], [397953],1.0.2893
PUP.Optional.USTechSupport, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{A16AB1E1-377D-4DF2-8D8A-C9F283857DDC}, Quarantined, [1712], [397953],1.0.2893
PUP.Optional.USTechSupport, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{7EC41441-2247-4DEC-BBFB-9E798627A17B}, Quarantined, [1712], [397953],1.0.2893
PUP.Optional.USTechSupport, HKLM\SOFTWARE\CLASSES\WOW6432NODE\TYPELIB\{7EC41441-2247-4DEC-BBFB-9E798627A17B}, Quarantined, [1712], [397953],1.0.2893
PUP.Optional.USTechSupport, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\IDriverT, Quarantined, [1712], [397953],1.0.2893
PUP.Optional.USTechSupport, HKLM\SOFTWARE\CLASSES\IDRIVERT.ROTSERVICE.1, Quarantined, [1712], [397953],1.0.2893
PUP.Optional.USTechSupport, HKLM\SOFTWARE\CLASSES\IDriverT.RotService, Quarantined, [1712], [397953],1.0.2893
PUP.Optional.USTechSupport, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{064CB054-2518-474E-B2E8-200049528C42}, Quarantined, [1712], [397953],1.0.2893
PUP.Optional.USTechSupport, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{064CB054-2518-474E-B2E8-200049528C42}, Quarantined, [1712], [397953],1.0.2893
PUP.Optional.USTechSupport, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{69869D10-3B1D-E089-CA54-8A93C86DD85D}, Quarantined, [1712], [397953],1.0.2893
PUP.Optional.USTechSupport, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{69869D10-3B1D-E089-CA54-8A93C86DD85D}, Quarantined, [1712], [397953],1.0.2893
PUP.Optional.ASK, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC}, Quarantined, [521], [327345],1.0.2893
PUP.Optional.ASK, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC}, Quarantined, [521], [327345],1.0.2893
PUP.Optional.SnapDo, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{006ee092-9658-4fd6-bd8e-a21a348e59f5}, Quarantined, [6687], [167608],1.0.2893
PUP.Optional.DataMngr.AppFlsh, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{f34c9277-6577-4dff-b2d7-7d58092f272f}, Quarantined, [9054], [169669],1.0.2893
 
Registry Value: 40
PUP.Optional.Revizer.PrxySvrRST, HKU\S-1-5-18\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS|PROXYENABLE, Removal Failed, [9050], [-1],0.0.0
PUP.Optional.Revizer.PrxySvrRST, HKU\S-1-5-19\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS|PROXYENABLE, Quarantined, [9050], [-1],0.0.0
PUP.Optional.Revizer.PrxySvrRST, HKU\S-1-5-20\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS|PROXYENABLE, Quarantined, [9050], [-1],0.0.0
PUP.Optional.Revizer.PrxySvrRST, HKU\S-1-5-21-1979518111-4107658783-1214925503-1000\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS|PROXYENABLE, Quarantined, [9050], [-1],0.0.0
PUP.Optional.Revizer.PrxySvrRST, HKU\S-1-5-21-1979518111-4107658783-1214925503-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS|PROXYENABLE, Quarantined, [9050], [-1],0.0.0
PUP.Optional.Revizer.PrxySvrRST, HKU\S-1-5-18\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS|PROXYSERVER, Removal Failed, [9050], [-1],0.0.0
PUP.Optional.Revizer.PrxySvrRST, HKU\S-1-5-18\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS|PROXYOVERRIDE, Removal Failed, [9050], [-1],0.0.0
PUP.Optional.Revizer.PrxySvrRST, HKU\S-1-5-21-1979518111-4107658783-1214925503-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS|PROXYOVERRIDE, Quarantined, [9050], [-1],0.0.0
PUP.Optional.Revizer.PrxySvrRST, HKU\.DEFAULT\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS|PROXYENABLE, Removal Failed, [9050], [-1],0.0.0
PUP.Optional.Revizer.PrxySvrRST, HKU\.DEFAULT\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS|PROXYSERVER, Removal Failed, [9050], [-1],0.0.0
PUP.Optional.Revizer.PrxySvrRST, HKU\.DEFAULT\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS|PROXYOVERRIDE, Removal Failed, [9050], [-1],0.0.0
PUP.Optional.Revizer.PrxySvrRST, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\INTERNET SETTINGS|PROXYENABLE, Quarantined, [9050], [-1],0.0.0
PUP.Optional.Amazon1Button.AppFlsh, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWS|APPINIT_DLLS, Quarantined, [1472], [-1],0.0.0
PUP.Optional.Amazon1Button.AppFlsh, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWS|APPINIT_DLLS, Quarantined, [1472], [-1],0.0.0
PUP.Optional.OneSystemCare, HKU\S-1-5-21-1979518111-4107658783-1214925503-1000\SOFTWARE\ONE SYSTEM CARE|OSID, Quarantined, [467], [241384],1.0.2893
PUP.Optional.OneSystemCare, HKU\S-1-5-21-1979518111-4107658783-1214925503-1000\SOFTWARE\ONE SYSTEM CARE|ADVERTSLINK1, Quarantined, [467], [241383],1.0.2893
PUP.Optional.OneSystemCare, HKU\S-1-5-21-1979518111-4107658783-1214925503-1000\SOFTWARE\ONE SYSTEM CARE|ADVERTSLINK2, Quarantined, [467], [241383],1.0.2893
PUP.Optional.DNSUnlocker.ACMB2, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{9b66bb7d}|1, Quarantined, [22], [260250],1.0.2893
PUP.Optional.DriverRestore, HKU\S-1-5-21-1979518111-4107658783-1214925503-1001\SOFTWARE\DRIVERRESTORE|FIRSTSCANDATETIME, Quarantined, [731], [259276],1.0.2893
PUP.Optional.NotChromeRun, HKU\S-1-5-21-1979518111-4107658783-1214925503-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|CHROMIUM, Quarantined, [1406], [391151],1.0.2893
PUP.Optional.OneSystemCare, HKU\S-1-5-21-1979518111-4107658783-1214925503-1001\SOFTWARE\ONE SYSTEM CARE|OSID, Quarantined, [467], [241384],1.0.2893
PUP.Optional.OneSystemCare, HKU\S-1-5-21-1979518111-4107658783-1214925503-1001\SOFTWARE\ONE SYSTEM CARE|ADVERTSLINK1, Quarantined, [467], [241383],1.0.2893
PUP.Optional.OneSystemCare, HKU\S-1-5-21-1979518111-4107658783-1214925503-1001\SOFTWARE\ONE SYSTEM CARE|ADVERTSLINK2, Quarantined, [467], [241383],1.0.2893
PUP.Optional.ProductSetup, HKU\S-1-5-21-1979518111-4107658783-1214925503-1001\SOFTWARE\PRODUCTSETUP|TB, Quarantined, [14123], [242047],1.0.2893
PUP.Optional.ScreenSnapShotTool, HKLM\SOFTWARE\SCREENSNAPSHOTTOOL|PARTNERID, Quarantined, [206], [246518],1.0.2893
PUP.Optional.WebBar, HKU\S-1-5-21-1979518111-4107658783-1214925503-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN\FEATURECONTROL\FEATURE_BROWSER_EMULATION|WBMAIN.EXE, Quarantined, [3659], [259463],1.0.2893
PUP.Optional.BProtector, HKU\S-1-5-21-1979518111-4107658783-1214925503-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|BPROTECTOR START PAGE, Quarantined, [4058], [251612],1.0.2893
PUP.Optional.WinYahoo, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{2f23ab71-4ac6-41f2-a955-ea576e553146}|URL, Quarantined, [71], [182758],1.0.2893
PUP.Optional.WinYahoo, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{2f23ab71-4ac6-41f2-a955-ea576e553146}|TOPRESULTURLFALLBACK, Quarantined, [71], [182758],1.0.2893
PUP.Optional.WinYahoo, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{44A02DE0-F784-4FA5-B9D3-33C6F8ECA78A}|URL, Quarantined, [71], [182758],1.0.2893
PUP.Optional.WinYahoo, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{44A02DE0-F784-4FA5-B9D3-33C6F8ECA78A}|TOPRESULTURLFALLBACK, Quarantined, [71], [182758],1.0.2893
PUP.Optional.AmazonBrowserSettings, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{0C209135-B8A5-40DA-B393-660189966A08}|PATH, Quarantined, [12], [312598],1.0.2893
PUP.Optional.AmazonBrowserSettings, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{14C13415-BFB7-4EF8-8F91-4B844B6362FD}|PATH, Quarantined, [12], [312598],1.0.2893
PUP.Optional.AmazonBrowserSettings, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{41F4814D-0BA3-4C2B-AB5D-D774B2B29068}|PATH, Quarantined, [12], [312598],1.0.2893
PUP.Optional.PCPerformer, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{59DF69F3-DDB9-430D-8966-F5C837534F57}|PATH, Quarantined, [2290], [258469],1.0.2893
PUP.Optional.AmazonBrowserSettings, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{C3D0D221-A843-47EB-903A-EC807CB6FFA9}|PATH, Quarantined, [12], [312598],1.0.2893
PUP.Optional.USTechSupport, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{ECB29AA5-CB71-4C87-B5BE-26FBE85FCB6B}|PATH, Quarantined, [1712], [336579],1.0.2893
PUP.Optional.DigitalSites, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{FE1FED99-BD68-4591-8B35-6E562B5D3154}|PATH, Quarantined, [829], [358502],1.0.2893
PUP.Optional.ScreenSnapShotTool, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{61FFE1F9-137D-4c31-A181-3415FCAA5946}|DISPLAYICON, Quarantined, [206], [245718],1.0.2893
PUP.Optional.ASK, HKU\S-1-5-21-1979518111-4107658783-1214925503-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\TOOLBAR\WEBBROWSER|{D4027C7F-154A-4066-A1AD-4243D8127440}, Quarantined, [521], [306571],1.0.2893
 
Registry Data: 10
Adware.DNSUnlocker.ACMB2, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\TCPIP\PARAMETERS|NameServer, Replaced, [1741], [-1],0.0.0
Adware.DNSUnlocker.ACMB2, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\TCPIP\PARAMETERS|DhcpNameServer, Replaced, [1741], [-1],0.0.0
Adware.DNSUnlocker.ACMB2, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\TCPIP\PARAMETERS\Interfaces\{21372DD5-1707-4FC2-B2B0-5D536379CA57}|NameServer, Replaced, [1741], [-1],0.0.0
Adware.DNSUnlocker.ACMB2, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\TCPIP\PARAMETERS\Interfaces\{21372DD5-1707-4FC2-B2B0-5D536379CA57}|DhcpNameServer, Replaced, [1741], [-1],0.0.0
Adware.DNSUnlocker.ACMB2, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\TCPIP\PARAMETERS\Interfaces\{38A7A275-2F15-4A7A-B6F9-1D051DC30B43}|NameServer, Replaced, [1741], [-1],0.0.0
Adware.DNSUnlocker.ACMB2, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\TCPIP\PARAMETERS\Interfaces\{38A7A275-2F15-4A7A-B6F9-1D051DC30B43}|DhcpNameServer, Replaced, [1741], [-1],0.0.0
Adware.DNSUnlocker.ACMB2, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\TCPIP\PARAMETERS\Interfaces\{49797B45-3BAD-4AE1-BC49-5896ED006345}|NameServer, Replaced, [1741], [-1],0.0.0
Adware.DNSUnlocker.ACMB2, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\TCPIP\PARAMETERS\Interfaces\{9CFA72D9-1DFA-47B0-9348-9B2C94035F3B}|NameServer, Replaced, [1741], [-1],0.0.0
Adware.DNSUnlocker.ACMB2, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\TCPIP\PARAMETERS\Interfaces\{9CFA72D9-1DFA-47B0-9348-9B2C94035F3B}|DhcpNameServer, Replaced, [1741], [-1],0.0.0
Trojan.DNSChanger.ACMB2, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\TCPIP\PARAMETERS|NAMESERVER, Replaced, [5679], [293494],1.0.2893
 
Data Stream: 0
(No malicious items detected)
 
Folder: 83
PUP.Optional.AdLyrics, C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Extensions\gnbcopcndefcccgdofjadnafjljgofam\1.110_0, Quarantined, [1606], [175326],1.0.2893
PUP.Optional.AdLyrics, C:\WINDOWS\SYSWOW64\CONFIG\SYSTEMPROFILE\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\EXTENSIONS\GNBCOPCNDEFCCCGDOFJADNAFJLJGOFAM, Quarantined, [1606], [175326],1.0.2893
PUP.Optional.UpdateProc, C:\Users\Joey\AppData\Roaming\UpdaterEX\UpdateProc, Quarantined, [14391], [244360],1.0.2893
PUP.Optional.UpdateProc, C:\USERS\JOEY\APPDATA\ROAMING\UpdaterEX, Quarantined, [14391], [244360],1.0.2893
PUP.Optional.WebBar, C:\WINDOWS\SYSTEM32\CONFIG\SYSTEMPROFILE\APPDATA\LOCAL\WEBBAR, Quarantined, [3659], [254551],1.0.2893
PUP.Optional.ScreenSnapShotTool, C:\Users\Joey\AppData\Roaming\ScreenSnapshotTool\dump, Quarantined, [206], [245712],1.0.2893
PUP.Optional.ScreenSnapShotTool, C:\USERS\JOEY\APPDATA\ROAMING\SCREENSNAPSHOTTOOL, Quarantined, [206], [245712],1.0.2893
PUP.Optional.ScreenSnapShotTool, C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\ScreenSnapshotTool\dump, Quarantined, [206], [245712],1.0.2893
PUP.Optional.ScreenSnapShotTool, C:\WINDOWS\SYSWOW64\CONFIG\SYSTEMPROFILE\APPDATA\ROAMING\SCREENSNAPSHOTTOOL, Quarantined, [206], [245712],1.0.2893
PUP.Optional.ScreenSnapShotTool, C:\Program Files (x86)\ScreenSnapshotTool\1.1.0.11414\EVPData, Quarantined, [206], [245713],1.0.2893
PUP.Optional.ScreenSnapShotTool, C:\Program Files (x86)\ScreenSnapshotTool\1.1.0.11414, Quarantined, [206], [245713],1.0.2893
PUP.Optional.ScreenSnapShotTool, C:\PROGRAM FILES (X86)\SCREENSNAPSHOTTOOL, Quarantined, [206], [245713],1.0.2893
PUP.Optional.Amazon1Button.AppFlsh, C:\PROGRAM FILES (X86)\AMAZON\AMAZON1BUTTONAPP, Quarantined, [1472], [333344],1.0.2893
PUP.Optional.ASK.Generic, C:\Users\Joey\AppData\Local\APN\GoogleCRXs, Quarantined, [1371], [388492],1.0.2893
PUP.Optional.ASK.Generic, C:\USERS\JOEY\APPDATA\LOCAL\APN, Quarantined, [1371], [388492],1.0.2893
PUP.Optional.Blekko, C:\USERS\JOEY\APPDATA\LOCALLOW\blekkotb_019, Quarantined, [6464], [181688],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\Dialogs\SearchProtectorRetakeoverDialog\Images, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\Dialogs\SearchProtectorBubbleDialog\images, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\Dialogs\ToolbarUntrustedAppsApprovalDialog, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\Dialogs\NewSearchProtectorDialog\images, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\Dialogs\SearchProtectorRetakeoverDialog, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\Dialogs\ToolbarFirstTimeDialog\images, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\Dialogs\SearchProtectorDialog\Images, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\Dialogs\SearchProtectorBubbleDialog, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\Dialogs\UntrustedAppApprovalDialog, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\Dialogs\UntrustedAppPendingDialog, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\Dialogs\NewSearchProtectorDialog, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\Dialogs\UntrustedAddedAppDialog, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\Dialogs\ToolbarFirstTimeDialog, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\Dialogs\SearchProtectorDialog, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\Dialogs\EngineFirstTimeDialog, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\Dialogs\DetectedAppDialog, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\Dialogs\UninstallDialog, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\Dialogs\AddedAppDialog, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\Dialogs\DefualtImages, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\Dialogs, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\radio, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\apps, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\USERS\JOEY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZT8K3D39.DEFAULT\CT3227982, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.DriverRestore, C:\PROGRAMDATA\MICROSOFT\WINDOWS\START MENU\PROGRAMS\DRIVERRESTORE, Quarantined, [731], [181974],1.0.2893
PUP.Optional.StrongVault, C:\Users\Joey\AppData\Roaming\Strongvault\Strongvault Online Backup\updates, Quarantined, [7950], [181999],1.0.2893
PUP.Optional.StrongVault, C:\Users\Joey\AppData\Roaming\Strongvault\Strongvault Online Backup, Quarantined, [7950], [181999],1.0.2893
PUP.Optional.StrongVault, C:\USERS\JOEY\APPDATA\ROAMING\STRONGVAULT, Quarantined, [7950], [181999],1.0.2893
PUP.Optional.StrongVault, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Strongvault Online Backup\Tools, Quarantined, [7950], [182000],1.0.2893
PUP.Optional.StrongVault, C:\PROGRAMDATA\MICROSOFT\WINDOWS\START MENU\PROGRAMS\STRONGVAULT ONLINE BACKUP, Quarantined, [7950], [182000],1.0.2893
PUP.Optional.ScreenSnapshot, C:\USERS\PUBLIC\DOCUMENTS\GUID\COMMON\I18N\IPCSUPDATECACHE\SCREENSNAPSHOT, Quarantined, [12188], [182049],1.0.2893
PUP.Optional.Conduit, C:\Users\Joey\AppData\LocalLow\Conduit\Community Alerts\Dialogs\AppNotificationDialog\Images\light, Quarantined, [572], [182117],1.0.2893
PUP.Optional.Conduit, C:\Users\Joey\AppData\LocalLow\Conduit\Community Alerts\Dialogs\AppNotificationDialog\Images\dark, Quarantined, [572], [182117],1.0.2893
PUP.Optional.Conduit, C:\Users\Joey\AppData\LocalLow\Conduit\Community Alerts\Dialogs\AppNotificationDialog\Images, Quarantined, [572], [182117],1.0.2893
PUP.Optional.Conduit, C:\Users\Joey\AppData\LocalLow\Conduit\Community Alerts\Dialogs\AppNotificationDialog, Quarantined, [572], [182117],1.0.2893
PUP.Optional.Conduit, C:\Users\Joey\AppData\LocalLow\Conduit\Community Alerts\LanguagePacks, Quarantined, [572], [182117],1.0.2893
PUP.Optional.Conduit, C:\Users\Joey\AppData\LocalLow\Conduit\Community Alerts\Dialogs, Quarantined, [572], [182117],1.0.2893
PUP.Optional.Conduit, C:\Users\Joey\AppData\LocalLow\Conduit\Community Alerts\Feeds, Quarantined, [572], [182117],1.0.2893
PUP.Optional.Conduit, C:\Users\Joey\AppData\LocalLow\Conduit\Community Alerts\Log, Quarantined, [572], [182117],1.0.2893
PUP.Optional.Conduit, C:\Users\Joey\AppData\LocalLow\Conduit\Community Alerts, Quarantined, [572], [182117],1.0.2893
PUP.Optional.Conduit, C:\USERS\JOEY\APPDATA\LOCALLOW\CONDUIT, Quarantined, [572], [182117],1.0.2893
PUP.Optional.AmazonBrowserSettings, C:\PROGRAM FILES (X86)\AMAZON BROWSER SETTINGS, Quarantined, [12], [312594],1.0.2893
PUP.Optional.AmazonBrowserSettings, C:\USERS\JOEY\APPDATA\LOCAL\AMAZON BROWSER SETTINGS, Quarantined, [12], [312595],1.0.2893
PUP.Optional.DigitalSites, C:\USERS\JOEY\APPDATA\ROAMING\DIGITALSITES, Quarantined, [829], [319816],1.0.2893
PUP.Optional.SearchProtect, C:\SearchProtect\ffprotect, Quarantined, [2066], [344702],1.0.2893
PUP.Optional.SearchProtect, C:\SEARCHPROTECT, Quarantined, [2066], [344702],1.0.2893
PUP.Optional.DigitalSites, C:\USERS\JOEY\APPDATA\ROAMING\DSITE, Quarantined, [829], [358489],1.0.2893
PUP.Optional.BitsInstall.BITSRST, C:\PROGRAMDATA\{1212099c-312c-0}, Quarantined, [8375], [407180],1.0.2893
PUP.Optional.BitsInstall.BITSRST, C:\PROGRAMDATA\{178ce23e-012c-1}, Quarantined, [8375], [407180],1.0.2893
PUP.Optional.BitsInstall.BITSRST, C:\PROGRAMDATA\72a2e60f-0245-1, Quarantined, [8375], [407181],1.0.2893
PUP.Optional.BitsInstall.BITSRST, C:\PROGRAMDATA\72a2e60f-09c5-0, Quarantined, [8375], [407181],1.0.2893
PUP.Optional.BitsInstall.BITSRST, C:\PROGRAMDATA\72a2e60f-1125-0, Quarantined, [8375], [407181],1.0.2893
PUP.Optional.BitsInstall.BITSRST, C:\PROGRAMDATA\72a2e60f-1263-1, Quarantined, [8375], [407181],1.0.2893
PUP.Optional.BitsInstall.BITSRST, C:\PROGRAMDATA\72a2e60f-1761-0, Quarantined, [8375], [407181],1.0.2893
PUP.Optional.BitsInstall.BITSRST, C:\PROGRAMDATA\72a2e60f-1d51-0, Quarantined, [8375], [407181],1.0.2893
PUP.Optional.BitsInstall.BITSRST, C:\PROGRAMDATA\72a2e60f-2e97-1, Quarantined, [8375], [407181],1.0.2893
PUP.Optional.BitsInstall.BITSRST, C:\PROGRAMDATA\72a2e60f-30d1-0, Quarantined, [8375], [407181],1.0.2893
PUP.Optional.BitsInstall.BITSRST, C:\PROGRAMDATA\72a2e60f-40b3-0, Quarantined, [8375], [407181],1.0.2893
PUP.Optional.BitsInstall.BITSRST, C:\PROGRAMDATA\72a2e60f-4615-0, Quarantined, [8375], [407181],1.0.2893
PUP.Optional.BitsInstall.BITSRST, C:\PROGRAMDATA\72a2e60f-49d3-1, Quarantined, [8375], [407181],1.0.2893
PUP.Optional.BitsInstall.BITSRST, C:\PROGRAMDATA\72a2e60f-4e11-1, Quarantined, [8375], [407181],1.0.2893
PUP.Optional.BitsInstall.BITSRST, C:\PROGRAMDATA\72a2e60f-5647-0, Quarantined, [8375], [407181],1.0.2893
PUP.Optional.BitsInstall.BITSRST, C:\PROGRAMDATA\72a2e60f-57a3-1, Quarantined, [8375], [407181],1.0.2893
PUP.Optional.BitsInstall.BITSRST, C:\PROGRAMDATA\aea5b97b-1c95-1, Quarantined, [8375], [407181],1.0.2893
PUP.Optional.BitsInstall.BITSRST, C:\PROGRAMDATA\aea5b97b-4285-0, Quarantined, [8375], [407181],1.0.2893
PUP.Optional.WinYahoo, C:\Users\Joey\AppData\Local\{2D851BD9-092D-7761-64B5-528940DDAE11}\HowToRemove, Quarantined, [71], [302717],1.0.2893
PUP.Optional.WinYahoo, C:\USERS\JOEY\APPDATA\LOCAL\{2D851BD9-092D-7761-64B5-528940DDAE11}, Quarantined, [71], [302717],1.0.2893
PUP.Optional.StrongVault, C:\PROGRAMDATA\STRONGVAULT ONLINE BACKUP, Quarantined, [7950], [302477],1.0.2893
 
File: 275
PUP.Optional.SnapDo, C:\USERS\JOEY\APPDATA\LOCAL\CHROMIUM\USER DATA\DEFAULT\LOCAL STORAGE\http_search.snapdo.com_0.localstorage, Quarantined, [6687], [184975],1.0.2893
PUP.Optional.SnapDo, C:\USERS\JOEY\APPDATA\LOCAL\CHROMIUM\USER DATA\DEFAULT\LOCAL STORAGE\http_search.snapdo.com_0.localstorage-journal, Quarantined, [6687], [184975],1.0.2893
PUP.Optional.SnapDo, C:\USERS\JOEY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\LOCAL STORAGE\http_search.snapdo.com_0.localstorage, Quarantined, [6687], [184976],1.0.2893
PUP.Optional.SnapDo, C:\USERS\JOEY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\LOCAL STORAGE\http_search.snapdo.com_0.localstorage-journal, Quarantined, [6687], [184976],1.0.2893
PUP.Optional.AdLyrics, C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Extensions\gnbcopcndefcccgdofjadnafjljgofam\1.110_0\background.html, Quarantined, [1606], [175326],1.0.2893
PUP.Optional.AdLyrics, C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Extensions\gnbcopcndefcccgdofjadnafjljgofam\1.110_0\background.js, Quarantined, [1606], [175326],1.0.2893
PUP.Optional.AdLyrics, C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Extensions\gnbcopcndefcccgdofjadnafjljgofam\1.110_0\contentscript.js, Quarantined, [1606], [175326],1.0.2893
PUP.Optional.AdLyrics, C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Extensions\gnbcopcndefcccgdofjadnafjljgofam\1.110_0\icon128.png, Quarantined, [1606], [175326],1.0.2893
PUP.Optional.AdLyrics, C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Extensions\gnbcopcndefcccgdofjadnafjljgofam\1.110_0\icon16.png, Quarantined, [1606], [175326],1.0.2893
PUP.Optional.AdLyrics, C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Extensions\gnbcopcndefcccgdofjadnafjljgofam\1.110_0\icon48.png, Quarantined, [1606], [175326],1.0.2893
PUP.Optional.AdLyrics, C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Google\Chrome\User Data\Default\Extensions\gnbcopcndefcccgdofjadnafjljgofam\1.110_0\manifest.json, Quarantined, [1606], [175326],1.0.2893
PUP.Optional.PricePeep, C:\USERS\JOEY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\LOCAL STORAGE\https_static.pricepeep00.pricepeep.net_0.localstorage, Quarantined, [6646], [241978],1.0.2893
PUP.Optional.PricePeep, C:\USERS\JOEY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\LOCAL STORAGE\https_static.pricepeep00.pricepeep.net_0.localstorage-journal, Quarantined, [6646], [241978],1.0.2893
PUP.Optional.UpdateProc, C:\USERS\JOEY\APPDATA\ROAMING\UpdaterEX\UPDATEPROC\prod.dat, Quarantined, [14391], [244360],1.0.2893
PUP.Optional.UpdateProc, C:\Users\Joey\AppData\Roaming\UpdaterEX\UpdateProc\config.dat, Quarantined, [14391], [244360],1.0.2893
PUP.Optional.UpdateProc, C:\Users\Joey\AppData\Roaming\UpdaterEX\UpdateProc\info.dat, Quarantined, [14391], [244360],1.0.2893
PUP.Optional.UpdateProc, C:\Users\Joey\AppData\Roaming\UpdaterEX\UpdateProc\STTL.DAT, Quarantined, [14391], [244360],1.0.2893
PUP.Optional.UpdateProc, C:\Users\Joey\AppData\Roaming\UpdaterEX\UpdateProc\TTL.DAT, Quarantined, [14391], [244360],1.0.2893
PUP.Optional.WebBar, C:\WINDOWS\SYSTEM32\CONFIG\SYSTEMPROFILE\APPDATA\LOCAL\WEBBAR\WB.LOG, Quarantined, [3659], [254551],1.0.2893
PUP.Optional.ScreenSnapShotTool, C:\USERS\JOEY\APPDATA\ROAMING\SCREENSNAPSHOTTOOL\DUMP\BUGREPORTCONFIG.INI, Quarantined, [206], [245712],1.0.2893
PUP.Optional.Revizer.PrxySvrRST, C:\USERS\JOEY\APPDATA\LOCAL\CHROMIUM\USER DATA\DEFAULT\LOCAL STORAGE\https_static.re-markit00.re-markit.co_0.localstorage, Quarantined, [9050], [253862],1.0.2893
PUP.Optional.Revizer.PrxySvrRST, C:\USERS\JOEY\APPDATA\LOCAL\CHROMIUM\USER DATA\DEFAULT\LOCAL STORAGE\https_static.re-markit00.re-markit.co_0.localstorage-journal, Quarantined, [9050], [253862],1.0.2893
PUP.Optional.ScreenSnapShotTool, C:\WINDOWS\SYSWOW64\CONFIG\SYSTEMPROFILE\APPDATA\ROAMING\SCREENSNAPSHOTTOOL\DUMP\BUGREPORTCONFIG.INI, Quarantined, [206], [245712],1.0.2893
PUP.Optional.ScreenSnapShotTool, C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\ScreenSnapshotTool\dump\allinone_[2017-9-21_16_31_16].dmp, Quarantined, [206], [245712],1.0.2893
PUP.Optional.ScreenSnapShotTool, C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\ScreenSnapshotTool\dump\allinone_[2017-9-21_16_31_16].txt, Quarantined, [206], [245712],1.0.2893
PUP.Optional.ScreenSnapShotTool, C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\ScreenSnapshotTool\dump\allinone_[2017-9-21_18_1_7].dmp, Quarantined, [206], [245712],1.0.2893
PUP.Optional.ScreenSnapShotTool, C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\ScreenSnapshotTool\dump\allinone_[2017-9-21_18_1_7].txt, Quarantined, [206], [245712],1.0.2893
PUP.Optional.ScreenSnapShotTool, C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\ScreenSnapshotTool\dump\DumpConfig.ini, Quarantined, [206], [245712],1.0.2893
PUP.Optional.UTop, C:\USERS\JOEY\APPDATA\LOCAL\CHROMIUM\USER DATA\DEFAULT\LOCAL STORAGE\https_utop.it_0.localstorage, Quarantined, [14763], [256012],1.0.2893
PUP.Optional.UTop, C:\USERS\JOEY\APPDATA\LOCAL\CHROMIUM\USER DATA\DEFAULT\LOCAL STORAGE\https_utop.it_0.localstorage-journal, Quarantined, [14763], [256012],1.0.2893
PUP.Optional.UTop, C:\USERS\JOEY\APPDATA\LOCAL\CHROMIUM\USER DATA\DEFAULT\LOCAL STORAGE\http_utop.it_0.localstorage, Quarantined, [14763], [256012],1.0.2893
PUP.Optional.UTop, C:\USERS\JOEY\APPDATA\LOCAL\CHROMIUM\USER DATA\DEFAULT\LOCAL STORAGE\http_utop.it_0.localstorage-journal, Quarantined, [14763], [256012],1.0.2893
PUP.Optional.eShopComp, C:\USERS\JOEY\APPDATA\LOCAL\CHROMIUM\USER DATA\DEFAULT\LOCAL STORAGE\https_pstatic.eshopcomp.com_0.localstorage, Quarantined, [14760], [256007],1.0.2893
PUP.Optional.eShopComp, C:\USERS\JOEY\APPDATA\LOCAL\CHROMIUM\USER DATA\DEFAULT\LOCAL STORAGE\https_pstatic.eshopcomp.com_0.localstorage-journal, Quarantined, [14760], [256007],1.0.2893
PUP.Optional.eShopComp, C:\USERS\JOEY\APPDATA\LOCAL\CHROMIUM\USER DATA\DEFAULT\LOCAL STORAGE\http_pstatic.eshopcomp.com_0.localstorage, Quarantined, [14760], [256007],1.0.2893
PUP.Optional.eShopComp, C:\USERS\JOEY\APPDATA\LOCAL\CHROMIUM\USER DATA\DEFAULT\LOCAL STORAGE\http_pstatic.eshopcomp.com_0.localstorage-journal, Quarantined, [14760], [256007],1.0.2893
PUP.Optional.ScreenSnapShotTool, C:\PROGRAM FILES (X86)\SCREENSNAPSHOTTOOL\1.1.0.11414\CrashReportModuleConf.ini, Quarantined, [206], [245713],1.0.2893
PUP.Optional.ScreenSnapShotTool, C:\Program Files (x86)\ScreenSnapshotTool\1.1.0.11414\EVPData\History.dat, Quarantined, [206], [245713],1.0.2893
PUP.Optional.ScreenSnapShotTool, C:\Program Files (x86)\ScreenSnapshotTool\1.1.0.11414\CrashReport.exe, Quarantined, [206], [245713],1.0.2893
PUP.Optional.ScreenSnapShotTool, C:\Program Files (x86)\ScreenSnapshotTool\1.1.0.11414\CrashUL.exe, Quarantined, [206], [245713],1.0.2893
PUP.Optional.ScreenSnapShotTool, C:\Program Files (x86)\ScreenSnapshotTool\1.1.0.11414\EVPConfig.ini, Quarantined, [206], [245713],1.0.2893
PUP.Optional.ScreenSnapShotTool, C:\Program Files (x86)\ScreenSnapshotTool\1.1.0.11414\EVPDR.dll, Quarantined, [206], [245713],1.0.2893
PUP.Optional.ScreenSnapShotTool, C:\Program Files (x86)\ScreenSnapshotTool\1.1.0.11414\EVPHelp.dll, Quarantined, [206], [245713],1.0.2893
PUP.Optional.ScreenSnapShotTool, C:\Program Files (x86)\ScreenSnapshotTool\1.1.0.11414\EVPKernel.dll, Quarantined, [206], [245713],1.0.2893
PUP.Optional.ScreenSnapShotTool, C:\Program Files (x86)\ScreenSnapshotTool\1.1.0.11414\EVPNet.dll, Quarantined, [206], [245713],1.0.2893
PUP.Optional.ScreenSnapShotTool, C:\Program Files (x86)\ScreenSnapshotTool\1.1.0.11414\EVPTask.dll, Quarantined, [206], [245713],1.0.2893
PUP.Optional.ScreenSnapShotTool, C:\Program Files (x86)\ScreenSnapshotTool\1.1.0.11414\InstallHelper.exe, Quarantined, [206], [245713],1.0.2893
PUP.Optional.ScreenSnapShotTool, C:\Program Files (x86)\ScreenSnapshotTool\1.1.0.11414\Language.json, Quarantined, [206], [245713],1.0.2893
PUP.Optional.ScreenSnapShotTool, C:\Program Files (x86)\ScreenSnapshotTool\1.1.0.11414\Report.exe, Quarantined, [206], [245713],1.0.2893
PUP.Optional.ScreenSnapShotTool, C:\Program Files (x86)\ScreenSnapshotTool\1.1.0.11414\ScreenShotServ.exe, Quarantined, [206], [245713],1.0.2893
PUP.Optional.ScreenSnapShotTool, C:\Program Files (x86)\ScreenSnapshotTool\1.1.0.11414\ScreenSnapshot.exe, Quarantined, [206], [245713],1.0.2893
PUP.Optional.Yontoo, C:\USERS\JOEY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\LOCAL STORAGE\http_static.coupontime00.coupontime.co_0.localstorage, Quarantined, [39], [304355],1.0.2893
PUP.Optional.Yontoo, C:\PROGRAMDATA\NTUSER.POL, Removal Failed, [39], [-1],0.0.0
PUP.Optional.Yontoo, C:\USERS\JOEY\NTUSER.POL, Quarantined, [39], [-1],0.0.0
PUP.Optional.Yontoo, C:\WINDOWS\SYSTEM32\GROUPPOLICY\USER\REGISTRY.POL, Quarantined, [39], [-1],0.0.0
PUP.Optional.Yontoo, C:\WINDOWS\SYSTEM32\GROUPPOLICY\MACHINE\REGISTRY.POL, Quarantined, [39], [-1],0.0.0
PUP.Optional.Yontoo, C:\USERS\JOEY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\LOCAL STORAGE\http_static.coupontime00.coupontime.co_0.localstorage-journal, Quarantined, [39], [304355],1.0.2893
PUP.Optional.WinYahoo, C:\PROGRAMDATA\MICROSOFT\WINDOWS\START MENU\PROGRAMS\HOWTOREMOVE.HTML.LNK, Quarantined, [71], [254335],1.0.2893
PUP.Optional.BestPriceNinja, C:\USERS\JOEY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\LOCAL STORAGE\https_pstatic.bestpriceninja.com_0.localstorage, Quarantined, [14727], [254643],1.0.2893
PUP.Optional.BestPriceNinja, C:\USERS\JOEY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\LOCAL STORAGE\https_pstatic.bestpriceninja.com_0.localstorage-journal, Quarantined, [14727], [254643],1.0.2893
PUP.Optional.BestPriceNinja, C:\USERS\JOEY\APPDATA\LOCAL\CHROMIUM\USER DATA\DEFAULT\LOCAL STORAGE\https_pstatic.bestpriceninja.com_0.localstorage, Quarantined, [14727], [254642],1.0.2893
PUP.Optional.BestPriceNinja, C:\USERS\JOEY\APPDATA\LOCAL\CHROMIUM\USER DATA\DEFAULT\LOCAL STORAGE\https_pstatic.bestpriceninja.com_0.localstorage-journal, Quarantined, [14727], [254642],1.0.2893
PUP.Optional.eShopComp, C:\USERS\JOEY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\LOCAL STORAGE\https_pstatic.eshopcomp.com_0.localstorage, Quarantined, [14760], [255829],1.0.2893
PUP.Optional.eShopComp, C:\USERS\JOEY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\LOCAL STORAGE\https_pstatic.eshopcomp.com_0.localstorage-journal, Quarantined, [14760], [255829],1.0.2893
PUP.Optional.eShopComp, C:\USERS\JOEY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\LOCAL STORAGE\http_pstatic.eshopcomp.com_0.localstorage, Quarantined, [14760], [255829],1.0.2893
PUP.Optional.eShopComp, C:\USERS\JOEY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\LOCAL STORAGE\http_pstatic.eshopcomp.com_0.localstorage-journal, Quarantined, [14760], [255829],1.0.2893
PUP.Optional.DigitalSites, C:\WINDOWS\TASKS\DSITE.JOB, Quarantined, [829], [358516],1.0.2893
PUP.Optional.HDApp, C:\USERS\JOEY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\LOCAL STORAGE\https_hdapp1008-a.akamaihd.net_0.localstorage, Quarantined, [14785], [256894],1.0.2893
PUP.Optional.HDApp, C:\USERS\JOEY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\LOCAL STORAGE\https_hdapp1008-a.akamaihd.net_0.localstorage-journal, Quarantined, [14785], [256894],1.0.2893
PUP.Optional.CrossRider, C:\USERS\JOEY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\LOCAL STORAGE\https_d19tqk5t6qcjac.cloudfront.net_0.localstorage, Quarantined, [219], [256629],1.0.2893
PUP.Optional.CrossRider, C:\USERS\JOEY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\LOCAL STORAGE\https_d19tqk5t6qcjac.cloudfront.net_0.localstorage-journal, Quarantined, [219], [256629],1.0.2893
PUP.Optional.HDApp, C:\USERS\JOEY\APPDATA\LOCAL\CHROMIUM\USER DATA\DEFAULT\LOCAL STORAGE\https_hdapp1008-a.akamaihd.net_0.localstorage, Quarantined, [14785], [256893],1.0.2893
PUP.Optional.HDApp, C:\USERS\JOEY\APPDATA\LOCAL\CHROMIUM\USER DATA\DEFAULT\LOCAL STORAGE\https_hdapp1008-a.akamaihd.net_0.localstorage-journal, Quarantined, [14785], [256893],1.0.2893
PUP.Optional.Amonetize.Gen, C:\PROGRAMDATA\72a2e60f-2e97-1\BITF1B8.tmp, Quarantined, [14807], [257931],1.0.2893
PUP.Optional.Amonetize.Gen, C:\PROGRAMDATA\72a2e60f-30d1-0\BITF458.tmp, Quarantined, [14807], [257931],1.0.2893
PUP.Optional.APNToolBar.Gen, C:\USERS\JOEY\APPDATA\LOCAL\TEMP\APNSTUB.EXE, Quarantined, [9060], [258824],1.0.2893
PUP.Optional.CrossRider, C:\USERS\JOEY\APPDATA\LOCAL\CHROMIUM\USER DATA\DEFAULT\LOCAL STORAGE\https_d19tqk5t6qcjac.cloudfront.net_0.localstorage, Quarantined, [219], [256626],1.0.2893
PUP.Optional.CrossRider, C:\USERS\JOEY\APPDATA\LOCAL\CHROMIUM\USER DATA\DEFAULT\LOCAL STORAGE\https_d19tqk5t6qcjac.cloudfront.net_0.localstorage-journal, Quarantined, [219], [256626],1.0.2893
PUP.Optional.ReMarkIt.PrxySvrRST, C:\USERS\JOEY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\LOCAL STORAGE\https_static.re-markit00.re-markit.co_0.localstorage, Quarantined, [14801], [257824],1.0.2893
PUP.Optional.ReMarkIt.PrxySvrRST, C:\USERS\JOEY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\LOCAL STORAGE\https_static.re-markit00.re-markit.co_0.localstorage-journal, Quarantined, [14801], [257824],1.0.2893
PUP.Optional.UTop, C:\USERS\JOEY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\LOCAL STORAGE\https_utop.it_0.localstorage, Quarantined, [14763], [258623],1.0.2893
PUP.Optional.UTop, C:\USERS\JOEY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\LOCAL STORAGE\https_utop.it_0.localstorage-journal, Quarantined, [14763], [258623],1.0.2893
PUP.Optional.UTop, C:\USERS\JOEY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\LOCAL STORAGE\http_utop.it_0.localstorage, Quarantined, [14763], [258623],1.0.2893
PUP.Optional.UTop, C:\USERS\JOEY\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\LOCAL STORAGE\http_utop.it_0.localstorage-journal, Quarantined, [14763], [258623],1.0.2893
PUP.Optional.USTechSupport, C:\WINDOWS\SYSTEM32\TASKS\LAUNCH CDPCO, Quarantined, [1712], [336577],1.0.2893
PUP.Optional.AmazonBrowserSettings, C:\WINDOWS\SYSTEM32\TASKS\DistromaticSearchProtect-hourly, Quarantined, [12], [312600],1.0.2893
PUP.Optional.AmazonBrowserSettings, C:\WINDOWS\SYSTEM32\TASKS\DistromaticSearchProtect-logon, Quarantined, [12], [312600],1.0.2893
PUP.Optional.AmazonBrowserSettings, C:\WINDOWS\SYSTEM32\TASKS\DistromaticUpdater-logon, Quarantined, [12], [312600],1.0.2893
PUP.Optional.Amazon1Button.AppFlsh, C:\PROGRAM FILES (X86)\AMAZON\AMAZON1BUTTONAPP\Amazon1ButtonBrowserHelper.dll, Quarantined, [1472], [333344],1.0.2893
PUP.Optional.Amazon1Button.AppFlsh, C:\Program Files (x86)\Amazon\Amazon1ButtonApp\Amazon1ButtonBrowserHelper64.dll, Quarantined, [1472], [333344],1.0.2893
PUP.Optional.Amazon1Button.AppFlsh, C:\Program Files (x86)\Amazon\Amazon1ButtonApp\Amazon1ButtonRuntime.dll, Quarantined, [1472], [333344],1.0.2893
PUP.Optional.Amazon1Button.AppFlsh, C:\Program Files (x86)\Amazon\Amazon1ButtonApp\Amazon1ButtonService64.Exe, Quarantined, [1472], [333344],1.0.2893
PUP.Optional.Amazon1Button.AppFlsh, C:\Program Files (x86)\Amazon\Amazon1ButtonApp\AmazonAppIE.dll, Quarantined, [1472], [333344],1.0.2893
PUP.Optional.Amazon1Button.AppFlsh, C:\Program Files (x86)\Amazon\Amazon1ButtonApp\AmazonAppIE64.dll, Quarantined, [1472], [333344],1.0.2893
PUP.Optional.Amazon1Button.AppFlsh, C:\Program Files (x86)\Amazon\Amazon1ButtonApp\AmazonExtIE.dll, Quarantined, [1472], [333344],1.0.2893
PUP.Optional.Amazon1Button.AppFlsh, C:\Program Files (x86)\Amazon\Amazon1ButtonApp\AmazonExtIE64.dll, Quarantined, [1472], [333344],1.0.2893
PUP.Optional.AmazonBrowserSettings, C:\WINDOWS\SYSTEM32\TASKS\DistromaticUpdater-periodic, Quarantined, [12], [312600],1.0.2893
PUP.Optional.DigitalSites, C:\WINDOWS\SYSTEM32\TASKS\DSITE, Quarantined, [829], [358521],1.0.2893
PUP.Optional.ASK.Generic, C:\USERS\JOEY\APPDATA\LOCAL\APN\GOOGLECRXS\apnorjtoolbar.crx, Quarantined, [1371], [388492],1.0.2893
PUP.Optional.ScreenSnapShotTool, C:\PROGRAM FILES (X86)\SCREENSNAPSHOTTOOL\1.1.0.11414\SCREENSHOTSERV.EXE, Quarantined, [206], [245719],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\apps\list.json, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\Dialogs\SearchProtectorDialog\Images\info.png, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\Dialogs\SearchProtectorDialog\Images\ok-on.png, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\Dialogs\SearchProtectorDialog\Images\ok.png, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\Dialogs\SearchProtectorDialog\main.html, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\Dialogs\SearchProtectorDialog\SearchProtector.css, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\Dialogs\SearchProtectorDialog\SearchProtector.js, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\Dialogs\AddedAppDialog\app-added.js, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\Dialogs\AddedAppDialog\main.html, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\Dialogs\DefualtImages\icon.png, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\Dialogs\DetectedAppDialog\app-2go.js, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\Dialogs\DetectedAppDialog\main.html, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\Dialogs\EngineFirstTimeDialog\EngineFirstTimeDialog.js, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\Dialogs\EngineFirstTimeDialog\main.html, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\Dialogs\EngineFirstTimeDialog\right-click.gif, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\Dialogs\NewSearchProtectorDialog\images\ok-button.png, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\Dialogs\NewSearchProtectorDialog\images\separation-line.png, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\Dialogs\NewSearchProtectorDialog\images\warning.png, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\Dialogs\NewSearchProtectorDialog\main.html, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\Dialogs\NewSearchProtectorDialog\SearchProtector.css, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\Dialogs\NewSearchProtectorDialog\SearchProtector.js, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\Dialogs\SearchProtectorBubbleDialog\images\information.png, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\Dialogs\SearchProtectorBubbleDialog\images\x-default-LTR.png, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\Dialogs\SearchProtectorBubbleDialog\images\x-default-RTL.png, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\Dialogs\SearchProtectorBubbleDialog\images\x-mouseover-LTR.png, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\Dialogs\SearchProtectorBubbleDialog\images\x-mouseover-RTL.png, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\Dialogs\SearchProtectorBubbleDialog\bubble.css, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\Dialogs\SearchProtectorBubbleDialog\bubble.js, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\Dialogs\SearchProtectorBubbleDialog\main.html, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\Dialogs\SearchProtectorRetakeoverDialog\Images\Icon.jpg, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\Dialogs\SearchProtectorRetakeoverDialog\Images\Icon.png, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\Dialogs\SearchProtectorRetakeoverDialog\Images\info.png, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\Dialogs\SearchProtectorRetakeoverDialog\Images\ok-on.png, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\Dialogs\SearchProtectorRetakeoverDialog\Images\ok.png, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\Dialogs\SearchProtectorRetakeoverDialog\main.html, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\Dialogs\SearchProtectorRetakeoverDialog\SearchProtectorRetakeover.css, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\Dialogs\SearchProtectorRetakeoverDialog\SearchProtectorRetakeover.js, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\Dialogs\ToolbarFirstTimeDialog\images\app-store-icon.png, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\Dialogs\ToolbarFirstTimeDialog\images\arrow.png, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\Dialogs\ToolbarFirstTimeDialog\images\divider.png, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\Dialogs\ToolbarFirstTimeDialog\images\emailNotifier.gif, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\Dialogs\ToolbarFirstTimeDialog\images\facebook.png, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\Dialogs\ToolbarFirstTimeDialog\images\radio.GIF, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\Dialogs\ToolbarFirstTimeDialog\images\Thumbs.db, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\Dialogs\ToolbarFirstTimeDialog\images\truste_welcome.GIF, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\Dialogs\ToolbarFirstTimeDialog\images\weather.GIF, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\Dialogs\ToolbarFirstTimeDialog\main.html, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\Dialogs\ToolbarFirstTimeDialog\ToolbarFirstTimeDialog.css, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\Dialogs\ToolbarFirstTimeDialog\ToolbarFirstTimeDialog.js, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\Dialogs\ToolbarUntrustedAppsApprovalDialog\main.html, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\Dialogs\ToolbarUntrustedAppsApprovalDialog\ToolbarUntrustedAppsApprovalDialog.js, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\Dialogs\UntrustedAddedAppDialog\main.html, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\Dialogs\UntrustedAddedAppDialog\UT-app-dialog-added.js, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\Dialogs\UntrustedAppApprovalDialog\main.html, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\Dialogs\UntrustedAppApprovalDialog\UT-app-dialog-needs-your-approval.js, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\Dialogs\UntrustedAppPendingDialog\main.html, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\Dialogs\UntrustedAppPendingDialog\UT-app-dialog-is-waiting.js, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\Dialogs\DialogsAPI.js, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\Dialogs\excanvas.js, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\Dialogs\generalDialogStyle.css, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\Dialogs\PIE.htc, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\Dialogs\RoundedCorners.css, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\Dialogs\RoundedCornersIE9.css, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\Dialogs\settings.js, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\Dialogs\version.txt, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\radio\IP_Media_List.xml, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\radio\Predefined_Media_List.xml, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\radio\Recent_Media_List.xml, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\radio\User_Media_List.xml, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\appsMetaData.json, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\getAppsContextMenu.xml, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\languagePack.json, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\LocalSettings.txt, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\postAppsContextMenu.xml, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\searchInNewTabData.xml, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\ServiceMap.json, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\ThirdPartyComponents.xml, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\toolbarContextMenu.xml, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\unsharedAppsContextMenu.xml, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.ConduitTB.Gen, C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\CT3227982\UserAdditionalComponents.xml, Quarantined, [11072], [181765],1.0.2893
PUP.Optional.StrongVault, C:\Users\Joey\AppData\Roaming\Strongvault\Strongvault Online Backup\updates\updates.aiu, Quarantined, [7950], [181999],1.0.2893
PUP.Optional.StrongVault, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Strongvault Online Backup\Tools\Start Backup.lnk, Quarantined, [7950], [182000],1.0.2893
PUP.Optional.StrongVault, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Strongvault Online Backup\Strongvault Online Backup.lnk, Quarantined, [7950], [182000],1.0.2893
PUP.Optional.StrongVault, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Strongvault Online Backup\Uninstall.lnk, Quarantined, [7950], [182000],1.0.2893
PUP.Optional.Conduit, C:\Users\Joey\AppData\LocalLow\Conduit\Community Alerts\Dialogs\AppNotificationDialog\Images\dark\close.png, Quarantined, [572], [182117],1.0.2893
PUP.Optional.Conduit, C:\Users\Joey\AppData\LocalLow\Conduit\Community Alerts\Dialogs\AppNotificationDialog\Images\dark\Next.png, Quarantined, [572], [182117],1.0.2893
PUP.Optional.Conduit, C:\Users\Joey\AppData\LocalLow\Conduit\Community Alerts\Dialogs\AppNotificationDialog\Images\dark\Next_hover.png, Quarantined, [572], [182117],1.0.2893
PUP.Optional.Conduit, C:\Users\Joey\AppData\LocalLow\Conduit\Community Alerts\Dialogs\AppNotificationDialog\Images\dark\powered-by.png, Quarantined, [572], [182117],1.0.2893
PUP.Optional.Conduit, C:\Users\Joey\AppData\LocalLow\Conduit\Community Alerts\Dialogs\AppNotificationDialog\Images\dark\Prev.png, Quarantined, [572], [182117],1.0.2893
PUP.Optional.Conduit, C:\Users\Joey\AppData\LocalLow\Conduit\Community Alerts\Dialogs\AppNotificationDialog\Images\dark\Prev_hover.png, Quarantined, [572], [182117],1.0.2893
PUP.Optional.Conduit, C:\Users\Joey\AppData\LocalLow\Conduit\Community Alerts\Dialogs\AppNotificationDialog\Images\dark\settings.png, Quarantined, [572], [182117],1.0.2893
PUP.Optional.Conduit, C:\Users\Joey\AppData\LocalLow\Conduit\Community Alerts\Dialogs\AppNotificationDialog\Images\light\close.png, Quarantined, [572], [182117],1.0.2893
PUP.Optional.Conduit, C:\Users\Joey\AppData\LocalLow\Conduit\Community Alerts\Dialogs\AppNotificationDialog\Images\light\Next.png, Quarantined, [572], [182117],1.0.2893
PUP.Optional.Conduit, C:\Users\Joey\AppData\LocalLow\Conduit\Community Alerts\Dialogs\AppNotificationDialog\Images\light\Next_hover.png, Quarantined, [572], [182117],1.0.2893
PUP.Optional.Conduit, C:\Users\Joey\AppData\LocalLow\Conduit\Community Alerts\Dialogs\AppNotificationDialog\Images\light\powered-by.png, Quarantined, [572], [182117],1.0.2893
PUP.Optional.Conduit, C:\Users\Joey\AppData\LocalLow\Conduit\Community Alerts\Dialogs\AppNotificationDialog\Images\light\Prev.png, Quarantined, [572], [182117],1.0.2893
PUP.Optional.Conduit, C:\Users\Joey\AppData\LocalLow\Conduit\Community Alerts\Dialogs\AppNotificationDialog\Images\light\Prev_hover.png, Quarantined, [572], [182117],1.0.2893
PUP.Optional.Conduit, C:\Users\Joey\AppData\LocalLow\Conduit\Community Alerts\Dialogs\AppNotificationDialog\Images\light\settings.png, Quarantined, [572], [182117],1.0.2893
PUP.Optional.Conduit, C:\Users\Joey\AppData\LocalLow\Conduit\Community Alerts\Dialogs\AppNotificationDialog\Images\light\Thumbs.db, Quarantined, [572], [182117],1.0.2893
PUP.Optional.Conduit, C:\Users\Joey\AppData\LocalLow\Conduit\Community Alerts\Dialogs\AppNotificationDialog\Images\close.png, Quarantined, [572], [182117],1.0.2893
PUP.Optional.Conduit, C:\Users\Joey\AppData\LocalLow\Conduit\Community Alerts\Dialogs\AppNotificationDialog\Images\like.png, Quarantined, [572], [182117],1.0.2893
PUP.Optional.Conduit, C:\Users\Joey\AppData\LocalLow\Conduit\Community Alerts\Dialogs\AppNotificationDialog\Images\Next.png, Quarantined, [572], [182117],1.0.2893
PUP.Optional.Conduit, C:\Users\Joey\AppData\LocalLow\Conduit\Community Alerts\Dialogs\AppNotificationDialog\Images\Next_hover.png, Quarantined, [572], [182117],1.0.2893
PUP.Optional.Conduit, C:\Users\Joey\AppData\LocalLow\Conduit\Community Alerts\Dialogs\AppNotificationDialog\Images\powered-by.png, Quarantined, [572], [182117],1.0.2893
PUP.Optional.Conduit, C:\Users\Joey\AppData\LocalLow\Conduit\Community Alerts\Dialogs\AppNotificationDialog\Images\Prev.png, Quarantined, [572], [182117],1.0.2893
PUP.Optional.Conduit, C:\Users\Joey\AppData\LocalLow\Conduit\Community Alerts\Dialogs\AppNotificationDialog\Images\Prev_hover.png, Quarantined, [572], [182117],1.0.2893
PUP.Optional.Conduit, C:\Users\Joey\AppData\LocalLow\Conduit\Community Alerts\Dialogs\AppNotificationDialog\Images\settings.png, Quarantined, [572], [182117],1.0.2893
PUP.Optional.Conduit, C:\Users\Joey\AppData\LocalLow\Conduit\Community Alerts\Dialogs\AppNotificationDialog\Images\Thumbs.db, Quarantined, [572], [182117],1.0.2893
PUP.Optional.Conduit, C:\Users\Joey\AppData\LocalLow\Conduit\Community Alerts\Dialogs\AppNotificationDialog\AppNotification.js, Quarantined, [572], [182117],1.0.2893
PUP.Optional.Conduit, C:\Users\Joey\AppData\LocalLow\Conduit\Community Alerts\Dialogs\AppNotificationDialog\initialNotification.html, Quarantined, [572], [182117],1.0.2893
PUP.Optional.Conduit, C:\Users\Joey\AppData\LocalLow\Conduit\Community Alerts\Dialogs\AppNotificationDialog\main.html, Quarantined, [572], [182117],1.0.2893
PUP.Optional.Conduit, C:\Users\Joey\AppData\LocalLow\Conduit\Community Alerts\Dialogs\AppNotificationDialog\NotificationDialogStyle.css, Quarantined, [572], [182117],1.0.2893
PUP.Optional.Conduit, C:\Users\Joey\AppData\LocalLow\Conduit\Community Alerts\Dialogs\AppNotificationDialog\sampleNotification.html, Quarantined, [572], [182117],1.0.2893
PUP.Optional.Conduit, C:\Users\Joey\AppData\LocalLow\Conduit\Community Alerts\Dialogs\DialogsAPI.js, Quarantined, [572], [182117],1.0.2893
PUP.Optional.Conduit, C:\Users\Joey\AppData\LocalLow\Conduit\Community Alerts\Dialogs\PIE.htc, Quarantined, [572], [182117],1.0.2893
PUP.Optional.Conduit, C:\Users\Joey\AppData\LocalLow\Conduit\Community Alerts\Dialogs\settings.js, Quarantined, [572], [182117],1.0.2893
PUP.Optional.Conduit, C:\Users\Joey\AppData\LocalLow\Conduit\Community Alerts\Dialogs\version.txt, Quarantined, [572], [182117],1.0.2893
PUP.Optional.Conduit, C:\Users\Joey\AppData\LocalLow\Conduit\Community Alerts\Feeds\http___alerts_conduit-services_com_root_1663751_1656277_US.xml, Quarantined, [572], [182117],1.0.2893
PUP.Optional.Conduit, C:\Users\Joey\AppData\LocalLow\Conduit\Community Alerts\LanguagePacks\en.xml, Quarantined, [572], [182117],1.0.2893
PUP.Optional.AmazonBrowserSettings, C:\Program Files (x86)\Amazon Browser Settings\AmznSearchProtect.exe, Delete-on-Reboot, [12], [312594],1.0.2893
PUP.Optional.AmazonBrowserSettings, C:\Program Files (x86)\Amazon Browser Settings\installer.json, Quarantined, [12], [312594],1.0.2893
PUP.Optional.AmazonBrowserSettings, C:\Program Files (x86)\Amazon Browser Settings\uninstall.ico, Quarantined, [12], [312594],1.0.2893
PUP.Optional.AmazonBrowserSettings, C:\Program Files (x86)\Amazon Browser Settings\uninstall.json, Quarantined, [12], [312594],1.0.2893
PUP.Optional.AmazonBrowserSettings, C:\Program Files (x86)\Amazon Browser Settings\uninstaller.exe, Quarantined, [12], [312594],1.0.2893
PUP.Optional.AmazonBrowserSettings, C:\Users\Joey\AppData\Local\Amazon Browser Settings\protect.json, Quarantined, [12], [312595],1.0.2893
PUP.Optional.BitsInstall.BITSRST, C:\PROGRAMDATA\APPLICATION DATA\MICROSOFT\NETWORK\DOWNLOADER\QMGR0.DAT, Delete-on-Reboot, [8375], [-1],0.0.0
PUP.Optional.BitsInstall.BITSRST, C:\PROGRAMDATA\APPLICATION DATA\MICROSOFT\NETWORK\DOWNLOADER\QMGR1.DAT, Delete-on-Reboot, [8375], [-1],0.0.0
PUP.Optional.BitsInstall.BITSRST, C:\PROGRAMDATA\MICROSOFT\NETWORK\DOWNLOADER\QMGR0.DAT, Removal Failed, [8375], [-1],0.0.0
PUP.Optional.BitsInstall.BITSRST, C:\PROGRAMDATA\MICROSOFT\NETWORK\DOWNLOADER\QMGR1.DAT, Removal Failed, [8375], [-1],0.0.0
PUP.Optional.WinYahoo, C:\USERS\JOEY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZT8K3D39.DEFAULT\SEARCHPLUGINS\SEARCH PROVIDED BY YAHOO.XML, Quarantined, [71], [302449],1.0.2893
PUP.Optional.Amonetize, C:\USERS\JOEY\APPDATA\LOCAL\TEMP\AMIPIXEL.CFG, Quarantined, [6], [302488],1.0.2893
PUP.Optional.WinYahoo, C:\USERS\JOEY\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\ZT8K3D39.DEFAULT\PREFS.JS, Replaced, [71], [303324],1.0.2893
PUP.Optional.WinYahoo, C:\USERS\JOEY\APPDATA\LOCAL\{2D851BD9-092D-7761-64B5-528940DDAE11}\HOWTOREMOVE\HOWTOREMOVE.HTML, Quarantined, [71], [302717],1.0.2893
PUP.Optional.WinYahoo, C:\Users\Joey\AppData\Local\{2D851BD9-092D-7761-64B5-528940DDAE11}\HowToRemove\chromium-min.jpg, Quarantined, [71], [302717],1.0.2893
PUP.Optional.WinYahoo, C:\Users\Joey\AppData\Local\{2D851BD9-092D-7761-64B5-528940DDAE11}\HowToRemove\control panel-min-min.JPG, Quarantined, [71], [302717],1.0.2893
PUP.Optional.WinYahoo, C:\Users\Joey\AppData\Local\{2D851BD9-092D-7761-64B5-528940DDAE11}\HowToRemove\down.png, Quarantined, [71], [302717],1.0.2893
PUP.Optional.WinYahoo, C:\Users\Joey\AppData\Local\{2D851BD9-092D-7761-64B5-528940DDAE11}\HowToRemove\ff menu.JPG, Quarantined, [71], [302717],1.0.2893
PUP.Optional.WinYahoo, C:\Users\Joey\AppData\Local\{2D851BD9-092D-7761-64B5-528940DDAE11}\HowToRemove\ff search engine-min.png, Quarantined, [71], [302717],1.0.2893
PUP.Optional.WinYahoo, C:\Users\Joey\AppData\Local\{2D851BD9-092D-7761-64B5-528940DDAE11}\HowToRemove\hp-min ff.png, Quarantined, [71], [302717],1.0.2893
PUP.Optional.WinYahoo, C:\Users\Joey\AppData\Local\{2D851BD9-092D-7761-64B5-528940DDAE11}\HowToRemove\hp-min ie.png, Quarantined, [71], [302717],1.0.2893
PUP.Optional.WinYahoo, C:\Users\Joey\AppData\Local\{2D851BD9-092D-7761-64B5-528940DDAE11}\HowToRemove\search engine.gif, Quarantined, [71], [302717],1.0.2893
PUP.Optional.WinYahoo, C:\Users\Joey\AppData\Local\{2D851BD9-092D-7761-64B5-528940DDAE11}\HowToRemove\setup pages.gif, Quarantined, [71], [302717],1.0.2893
PUP.Optional.WinYahoo, C:\Users\Joey\AppData\Local\{2D851BD9-092D-7761-64B5-528940DDAE11}\HowToRemove\sp-min.png, Quarantined, [71], [302717],1.0.2893
PUP.Optional.WinYahoo, C:\Users\Joey\AppData\Local\{2D851BD9-092D-7761-64B5-528940DDAE11}\HowToRemove\start-min.jpg, Quarantined, [71], [302717],1.0.2893
PUP.Optional.WinYahoo, C:\Users\Joey\AppData\Local\{2D851BD9-092D-7761-64B5-528940DDAE11}\HowToRemove\up.png, Quarantined, [71], [302717],1.0.2893
PUP.Optional.WinYahoo, C:\Users\Joey\AppData\Local\{2D851BD9-092D-7761-64B5-528940DDAE11}\cetocesi, Quarantined, [71], [302717],1.0.2893
PUP.Optional.WinYahoo, C:\Users\Joey\AppData\Local\{2D851BD9-092D-7761-64B5-528940DDAE11}\fosilo.cfg, Quarantined, [71], [302717],1.0.2893
PUP.Optional.WinYahoo, C:\Users\Joey\AppData\Local\{2D851BD9-092D-7761-64B5-528940DDAE11}\install.log, Quarantined, [71], [302717],1.0.2893
PUP.Optional.WinYahoo, C:\Users\Joey\AppData\Local\{2D851BD9-092D-7761-64B5-528940DDAE11}\lififata, Quarantined, [71], [302717],1.0.2893
PUP.Optional.WinYahoo, C:\Users\Joey\AppData\Local\{2D851BD9-092D-7761-64B5-528940DDAE11}\locotif.dat, Quarantined, [71], [302717],1.0.2893
PUP.Optional.WinYahoo, C:\Users\Joey\AppData\Local\{2D851BD9-092D-7761-64B5-528940DDAE11}\nimomet, Quarantined, [71], [302717],1.0.2893
PUP.Optional.WinYahoo, C:\Users\Joey\AppData\Local\{2D851BD9-092D-7761-64B5-528940DDAE11}\nosonemi.dat, Quarantined, [71], [302717],1.0.2893
PUP.Optional.WinYahoo, C:\Users\Joey\AppData\Local\{2D851BD9-092D-7761-64B5-528940DDAE11}\secoterit, Quarantined, [71], [302717],1.0.2893
PUP.Optional.WinYahoo, C:\Users\Joey\AppData\Local\{2D851BD9-092D-7761-64B5-528940DDAE11}\somedecat.dat, Quarantined, [71], [302717],1.0.2893
PUP.Optional.WinYahoo, C:\Users\Joey\AppData\Local\{2D851BD9-092D-7761-64B5-528940DDAE11}\Sqlite3.dll, Quarantined, [71], [302717],1.0.2893
PUP.Optional.WinYahoo, C:\Users\Joey\AppData\Local\{2D851BD9-092D-7761-64B5-528940DDAE11}\tonoma.dat, Quarantined, [71], [302717],1.0.2893
PUP.Optional.WinYahoo, C:\Users\Joey\AppData\Local\{2D851BD9-092D-7761-64B5-528940DDAE11}\uninst.dat, Quarantined, [71], [302717],1.0.2893
PUP.Optional.WinYahoo, C:\Users\Joey\AppData\Local\{2D851BD9-092D-7761-64B5-528940DDAE11}\uninst.exe, Quarantined, [71], [302717],1.0.2893
PUP.Optional.WinYahoo, C:\Users\Joey\AppData\Local\{2D851BD9-092D-7761-64B5-528940DDAE11}\uninstp.dat, Quarantined, [71], [302717],1.0.2893
PUP.Optional.StrongVault, C:\PROGRAMDATA\STRONGVAULT ONLINE BACKUP\CONFIG.XML, Quarantined, [7950], [302477],1.0.2893
PUP.Optional.USTechSupport, C:\PROGRAM FILES (X86)\COMMON FILES\INSTALLSHIELD\DRIVER\1050\INTEL 32\IDRIVERT.EXE, Quarantined, [1712], [397953],1.0.2893
PUP.Optional.Conduit, C:\USERS\JOEY\APPDATA\LOCAL\TEMP\CT3227982\STATISTICSSTUB.EXE, Quarantined, [572], [111936],1.0.2893
PUP.Optional.FindWide, C:\USERS\JOEY\APPDATA\LOCAL\TEMP\NSW1F32.TMP\2\FINDWIDE-TB10307.EXE, Quarantined, [7841], [105404],1.0.2893
PUP.Optional.383Media, C:\USERS\JOEY\APPDATA\LOCAL\TEMP\DRHELPER_INSTALLFINISH.EXE, Quarantined, [7294], [91517],1.0.2893
PUP.Optional.ByteFence, C:\USERS\JOEY\APPDATA\LOCAL\TEMP\TMPSEC7841726\BYTEFENCE-INSTALLER_2.1.1.6.EXE, Quarantined, [626], [389016],1.0.2893
PUP.Optional.Compete, C:\USERS\JOEY\APPDATA\LOCAL\TEMP\CHE88CF.TMP, Quarantined, [10417], [300877],1.0.2893
PUP.Optional.383Media, C:\USERS\JOEY\APPDATA\LOCAL\TEMP\DRHELPER_UNINSTALLCOMPLETE.EXE, Quarantined, [7294], [91517],1.0.2893
PUP.Optional.383Media, C:\USERS\JOEY\APPDATA\LOCAL\TEMP\DRHELPER_INSTALLSTART.EXE, Quarantined, [7294], [91517],1.0.2893
Adware.Genieo, C:\USERS\JOEY\APPDATA\LOCAL\TEMP\UPDATER_UNINSTALL.EXE, Quarantined, [2863], [372566],1.0.2893
PUP.Optional.VisicomTB, C:\USERS\JOEY\APPDATA\LOCAL\TEMP\AIR1246.EXE, Quarantined, [7719], [156433],1.0.2893
PUP.Optional.ScreenSnapShotTool, C:\USERS\JOEY\APPDATA\LOCAL\TEMP\INSTALLHELPER.EXE, Quarantined, [206], [308445],1.0.2893
PUP.Optional.CrossRider, C:\USERS\JOEY\DOWNLOADS\UPDATE.EXE, Quarantined, [219], [290482],1.0.2893
PUP.Optional.SpeedingUpMyPC, C:\USERS\JOEY\APPDATA\LOCAL\TEMP\INS5763\OPTIMIZERPRO.EXE, Quarantined, [912], [334223],1.0.2893
PUP.Optional.Conduit, C:\USERS\JOEY\APPDATA\LOCAL\TEMP\CT3227982\FFLOGIC.EXE, Quarantined, [572], [111936],1.0.2893
PUP.Optional.SpeedingUpMyPC, C:\USERS\JOEY\APPDATA\LOCAL\TEMP\IS-AA08O.TMP\OPTPROCRASH.DLL, Quarantined, [912], [334223],1.0.2893
 
Physical Sector: 0
(No malicious items detected)
 
 
(end)
 
 
 
 
 
 
RogueKiller V12.11.17.0 (x64) [Sep 25 2017] (Free) by Adlice Software
 
Operating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Started in : Normal mode
User : Joey [Administrator]
Started from : C:\Program Files\RogueKiller\RogueKiller64.exe
Mode : Delete -- Date : 09/26/2017 18:42:53 (Duration : 01:24:31)
 
¤¤¤ Processes : 0 ¤¤¤
 
¤¤¤ Registry : 62 ¤¤¤
[PUP.Gen0] (X64) HKEY_CLASSES_ROOT\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113} -> Deleted
[PUP.WebBar|PUP.Gen1] (X64) HKEY_LOCAL_MACHINE\Software\WebBar -> Deleted
[PUP.Gen1] (X86) HKEY_LOCAL_MACHINE\Software\AVG Security Toolbar -> Deleted
[PUP.Gen1] (X86) HKEY_LOCAL_MACHINE\Software\Babylon -> Deleted
[PUP.Gen1] (X86) HKEY_LOCAL_MACHINE\Software\Better Surf Plus -> Deleted
[PUP.Gen1] (X86) HKEY_LOCAL_MACHINE\Software\Better-Surf -> Deleted
[PUP.Gen1] (X86) HKEY_LOCAL_MACHINE\Software\BetterSurf -> Deleted
[PUP.Gen1] (X86) HKEY_LOCAL_MACHINE\Software\dllpop100 -> Deleted
[PUP.Gen1] (X86) HKEY_LOCAL_MACHINE\Software\iLividSRTB -> Deleted
[PUP.Gen1] (X86) HKEY_LOCAL_MACHINE\Software\InfoAtoms -> Deleted
[PUP.Gen1] (X86) HKEY_LOCAL_MACHINE\Software\SP Global -> Deleted
[PUP.Gen1] (X86) HKEY_LOCAL_MACHINE\Software\Video Player -> Deleted
[PUP.Gen1] (X86) HKEY_LOCAL_MACHINE\Software\VideoPlayerV3 -> Deleted
[PUP.Gen1] (X86) HKEY_LOCAL_MACHINE\Software\Webexp Enhanced -> Deleted
[PUP.Gen1] (X86) HKEY_LOCAL_MACHINE\Software\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0} -> Deleted
[PUP.Gen1] (X64) HKEY_USERS\.DEFAULT\Software\bProtector -> Deleted
[PUP.Gen1] (X64) HKEY_USERS\.DEFAULT\Software\GamesBar -> Deleted
[PUP.Gen1] (X86) HKEY_USERS\.DEFAULT\Software\bProtector -> Deleted
[PUP.Gen1] (X86) HKEY_USERS\.DEFAULT\Software\GamesBar -> Deleted
[PUP.Gen1] (X64) HKEY_USERS\S-1-5-21-1979518111-4107658783-1214925503-1001\Software\Cr_Installer -> Deleted
[PUP.Gen1] (X64) HKEY_USERS\S-1-5-21-1979518111-4107658783-1214925503-1001\Software\eSupport.com -> Deleted
[PUP.Gen1] (X64) HKEY_USERS\S-1-5-21-1979518111-4107658783-1214925503-1001\Software\GamesBar -> Deleted
[PUP.Gen1] (X64) HKEY_USERS\S-1-5-21-1979518111-4107658783-1214925503-1001\Software\iLivid -> Deleted
[PUP.Gen1] (X64) HKEY_USERS\S-1-5-21-1979518111-4107658783-1214925503-1001\Software\Smart PC Cleaner -> Deleted
[PUP.Gen1] (X64) HKEY_USERS\S-1-5-21-1979518111-4107658783-1214925503-1001\Software\Softonic -> Deleted
[PUP.Gen1] (X64) HKEY_USERS\S-1-5-21-1979518111-4107658783-1214925503-1001\Software\UpToDown -> Deleted
[PUP.Gen1] (X86) HKEY_USERS\S-1-5-21-1979518111-4107658783-1214925503-1001\Software\Cr_Installer -> Deleted
[PUP.Gen1] (X86) HKEY_USERS\S-1-5-21-1979518111-4107658783-1214925503-1001\Software\eSupport.com -> Deleted
[PUP.Gen1] (X86) HKEY_USERS\S-1-5-21-1979518111-4107658783-1214925503-1001\Software\GamesBar -> Deleted
[PUP.Gen1] (X86) HKEY_USERS\S-1-5-21-1979518111-4107658783-1214925503-1001\Software\iLivid -> Deleted
[PUP.Gen1] (X86) HKEY_USERS\S-1-5-21-1979518111-4107658783-1214925503-1001\Software\Smart PC Cleaner -> Deleted
[PUP.Gen1] (X86) HKEY_USERS\S-1-5-21-1979518111-4107658783-1214925503-1001\Software\Softonic -> Deleted
[PUP.Gen1] (X86) HKEY_USERS\S-1-5-21-1979518111-4107658783-1214925503-1001\Software\UpToDown -> Deleted
[PUP.Gen1] (X64) HKEY_USERS\S-1-5-18\Software\bProtector -> Deleted
[PUP.Gen1] (X64) HKEY_USERS\S-1-5-18\Software\GamesBar -> Deleted
[PUP.Gen1] (X86) HKEY_USERS\S-1-5-18\Software\bProtector -> Deleted
[PUP.Gen1] (X86) HKEY_USERS\S-1-5-18\Software\GamesBar -> Deleted
[PUP.Gen1] (X64) HKEY_USERS\S-1-5-21-1979518111-4107658783-1214925503-1001\Software\AppDataLow\Software\Freecause -> Deleted
[PUP.Gen1] (X86) HKEY_USERS\S-1-5-21-1979518111-4107658783-1214925503-1001\Software\AppDataLow\Software\Freecause -> Deleted
[PUP.DefaultTab|PUP.Gen1] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\DefaultTab -> Deleted
[PUP.Gen1] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\Search Results Toolbar -> Deleted
[PUP.SearchProtect|PUP.Gen1] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\SearchProtect -> Deleted
[PUP.Gen1] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\Smart PC Cleaner_is1 -> Deleted
[PUP.Gen1] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\Yahoo! SearchSet -> Deleted
[PUP.Gen1] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{B6DCCCD3-520D-4485-B642-FCC136CE12C3} -> Deleted
[PUP.Gen1] (X64) HKEY_USERS\S-1-5-21-1979518111-4107658783-1214925503-1001\Software\Microsoft\Windows\CurrentVersion\Uninstall\Zip Opener Packages -> Deleted
[PUP.Gen1] (X86) HKEY_USERS\S-1-5-21-1979518111-4107658783-1214925503-1001\Software\Microsoft\Windows\CurrentVersion\Uninstall\Zip Opener Packages -> Deleted
[PUP.Gen0] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EF7BD87A-8024-11E2-F316-F3E56188709B} -> Deleted
[PUP.Gen0] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NETHTTPSERVICE -> Deleted
[PUP.Gen0] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SERVICEUPDATER -> Deleted
[PUP.Gen0] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\NetHttpService -> Deleted
[PUP.Gen0] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\ServiceUpdater -> Deleted
[PUM.HomePage] (X64) HKEY_USERS\S-1-5-21-1979518111-4107658783-1214925503-1001\Software\Microsoft\Internet Explorer\Main | Default_Page_URL :
[PUM.HomePage] (X86) HKEY_USERS\S-1-5-21-1979518111-4107658783-1214925503-1001\Software\Microsoft\Internet Explorer\Main | Default_Page_URL :
[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules | {393B8EAB-5BDA-4115-A8CD-A6787ED1D115} : v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\ProgramData\Turbine\The Lord of the Rings Online\lotroclient.exe|Name=The Lord of the Rings Online| [x] -> Deleted
[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules | {C9EFF3D2-1305-4C88-AE9B-1B8A70783255} : v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\ProgramData\Turbine\The Lord of the Rings Online\lotroclient.exe|Name=The Lord of the Rings Online| [x] -> Deleted
[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules | {AAF4FE3C-6E31-4B3C-AE17-36898965AE35} : v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\ProgramData\Turbine\The Lord of the Rings Online\TurbineLauncher.exe|Name=The Lord of the Rings Online| [x] -> Deleted
[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules | {6D5F1498-C370-4685-88CA-99D9ED80876B} : v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\ProgramData\Turbine\The Lord of the Rings Online\TurbineLauncher.exe|Name=The Lord of the Rings Online| [x] -> Deleted
[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules | {393B8EAB-5BDA-4115-A8CD-A6787ED1D115} : v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\ProgramData\Turbine\The Lord of the Rings Online\lotroclient.exe|Name=The Lord of the Rings Online| [x] -> Deleted
[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules | {C9EFF3D2-1305-4C88-AE9B-1B8A70783255} : v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\ProgramData\Turbine\The Lord of the Rings Online\lotroclient.exe|Name=The Lord of the Rings Online| [x] -> Deleted
[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules | {AAF4FE3C-6E31-4B3C-AE17-36898965AE35} : v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\ProgramData\Turbine\The Lord of the Rings Online\TurbineLauncher.exe|Name=The Lord of the Rings Online| [x] -> Deleted
[Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules | {6D5F1498-C370-4685-88CA-99D9ED80876B} : v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\ProgramData\Turbine\The Lord of the Rings Online\TurbineLauncher.exe|Name=The Lord of the Rings Online| [x] -> Deleted
 
¤¤¤ Tasks : 0 ¤¤¤
 
¤¤¤ Files : 19 ¤¤¤
[PUP.Gen1][Folder] C:\ProgramData\APN -> Deleted
[PUP.Gen1][Folder] C:\ProgramData\Ask -> Deleted
[PUP.Gen1][Folder] C:\ProgramData\Ask\APN-Stub -> Deleted
[PUP.Gen1][Folder] C:\ProgramData\Babylon -> Deleted
[PUP.Gen1][Folder] C:\ProgramData\blekko toolbars -> Deleted
[PUP.BabSolution|PUP.Gen0|PUP.Gen1][Folder] C:\Users\Joey\AppData\Roaming\BabSolution -> Deleted
[PUP.Gen1][Folder] C:\Users\Joey\AppData\Roaming\Babylon -> Deleted
[PUP.Gen1][File] C:\Users\Joey\AppData\Roaming\Babylon\log_file.txt -> Deleted
[PUP.Gen1][Folder] C:\Users\Joey\AppData\Roaming\Zip Opener Packages -> Deleted
[PUP.Gen1][Folder] C:\Users\Joey\AppData\Local\AVG SafeGuard toolbar -> Deleted
[PUP.Gen1][File] C:\Users\Joey\AppData\Local\AVG SafeGuard toolbar\Chrome\Default\Preferences -> Deleted
[PUP.Gen1][File] C:\Users\Joey\AppData\Local\AVG SafeGuard toolbar\Chrome\Default\Web Data -> Deleted
[PUP.Gen1][Folder] C:\Users\Joey\AppData\Local\AVG SafeGuard toolbar\Chrome\Default -> Deleted
[PUP.Gen1][Folder] C:\Users\Joey\AppData\Local\AVG SafeGuard toolbar\Chrome -> Deleted
[Root.Wajam][File] C:\Users\Joey\AppData\Local\Temp\5258.tmp -> Deleted
[PUP.Gen1][Folder] C:\Users\Joey\AppData\Local\YSearchUtil -> Deleted
[PUP.Gen1][Folder] C:\Users\Joey\AppData\Local\YSearchUtil\CrashLogs -> Deleted
[PUP.Gen1][Folder] C:\ProgramData\APN -> ERROR [3]
[PUP.Gen1][Folder] C:\ProgramData\Ask -> ERROR [3]
[PUP.Gen1][Folder] C:\ProgramData\Babylon -> ERROR [3]
[PUP.Gen1][Folder] C:\ProgramData\blekko toolbars -> ERROR [3]
[PUP.Gen3][File] C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\safeguard-secure-search.xml -> Deleted
[PUP.Gen1][Folder] C:\Program Files (x86)\ShoppingChip -> Deleted
[PUP.Gen1][Folder] C:\Program Files (x86)\Smart PC Cleaner -> Deleted
[PUP.Gen1][File] C:\Program Files (x86)\Smart PC Cleaner\English.ini -> Deleted
[PUP.Gen1][File] C:\Program Files (x86)\Smart PC Cleaner\file_id.diz -> Deleted
[PUP.Gen1][File] C:\Program Files (x86)\Smart PC Cleaner\HomePage.url -> Deleted
[PUP.Gen1][File] C:\Program Files (x86)\Smart PC Cleaner\scan.gif -> Deleted
[PUP.Gen1][File] C:\Program Files (x86)\Smart PC Cleaner\SmartPCCleaner.chm -> Deleted
[PUP.Gen1][File] C:\Program Files (x86)\Smart PC Cleaner\SmartPCCleaner.exe -> Deleted
[PUP.Gen1][File] C:\Program Files (x86)\Smart PC Cleaner\SPCGuard.exe -> Deleted
[PUP.Gen1][File] C:\Program Files (x86)\Smart PC Cleaner\SPCLauncher.exe -> Deleted
[PUP.Gen1][File] C:\Program Files (x86)\Smart PC Cleaner\SPCReminder.exe -> Deleted
[PUP.Gen1][File] C:\Program Files (x86)\Smart PC Cleaner\SPCSchedule.exe -> Deleted
[PUP.Gen1][File] C:\Program Files (x86)\Smart PC Cleaner\SPCSmartScan.exe -> Deleted
[PUP.Gen1][File] C:\Program Files (x86)\Smart PC Cleaner\SPCUninstaller.exe -> Deleted
[PUP.Gen1][File] C:\Program Files (x86)\Smart PC Cleaner\sqlite3.dll -> Deleted
[PUP.Gen1][File] C:\Program Files (x86)\Smart PC Cleaner\Startw3i.exe -> Deleted
[PUP.Gen1][File] C:\Program Files (x86)\Smart PC Cleaner\unins000.dat -> Deleted
[PUP.Gen1][File] C:\Program Files (x86)\Smart PC Cleaner\unins000.exe -> Deleted
[PUP.Gen1][Folder] C:\Program Files (x86)\Yahoo!\yset -> Deleted
[PUP.Gen1][File] C:\Program Files (x86)\Yahoo!\yset\{68BD334A-CFE8-9547-8615-743CB0787DD2}\unset.exe -> Deleted
[PUP.Gen1][File] C:\Program Files (x86)\Yahoo!\yset\{68BD334A-CFE8-9547-8615-743CB0787DD2}\YSearchSetTool.exe -> Deleted
[PUP.Gen1][File] C:\Program Files (x86)\Yahoo!\yset\{68BD334A-CFE8-9547-8615-743CB0787DD2}\YSearchUtil.dll -> Deleted
[PUP.Gen1][File] C:\Program Files (x86)\Yahoo!\yset\{68BD334A-CFE8-9547-8615-743CB0787DD2}\YSearchUtilSvc.exe -> Deleted
[PUP.Gen1][Folder] C:\Program Files (x86)\Yahoo!\yset\{68BD334A-CFE8-9547-8615-743CB0787DD2} -> Deleted
[PUP.Firefox][File] C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\Invalidprefs.js -> Deleted
 
¤¤¤ WMI : 0 ¤¤¤
 
¤¤¤ Hosts File : 0 ¤¤¤
 
¤¤¤ Antirootkit : 0 (Driver: Loaded) ¤¤¤
 
¤¤¤ Web browsers : 4 ¤¤¤
[PUP.Gen0][Chrome:Addon] Default : Surf Canyon [bcjagnifjocnddgeknajocbkkhlgibem] -> Deleted
[PUM.SearchEngine][Firefox:Config] zt8k3d39.default : user_pref("browser.search.selectedEngine", "YHS"); -> Deleted
[PUM.SearchEngine][Firefox:Config] zt8k3d39.default : user_pref("browser.search.defaultenginename", "YHS"); -> Deleted
[PUP.Gen1|PUM.HomePage][Chrome:Config] Default [SecurePrefs] : homepage [http://isearch.fantastigames.com/0] -> Deleted
 
¤¤¤ MBR Check : ¤¤¤
+++++ PhysicalDrive0: Hitachi HTS727550A9E364 +++++
--- User ---
[MBR] 5a33a1dcff897eabb98a1e5ba332d63b
[BSP] f75a6dec4bf204802d5608f84605f2d0 : HP|VT.Unknown MBR Code
Partition table:
0 - [XXXXXX] DELL-UTIL (0xde) [VISIBLE] Offset (sectors): 63 | Size: 39 MB
1 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 81920 | Size: 19182 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
2 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 39366656 | Size: 457717 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 ... OK
User = LL2 ... OK
 


#4 Aura

Aura

    Bleepin' Special Ops


  • Malware Response Team
  • 19,697 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:11:00 PM

Posted 27 September 2017 - 06:58 AM

Good :) Now let's do a sweep with AdwCleaner and JRT.

zcMPezJ.pngAdwCleaner - Fix Mode
  • Download AdwCleaner and move it to your Desktop
  • Right-click on AdwCleaner.exe and select Spcusrh.pngRun as Administrator (for Windows Vista, 7, 8, 8.1 and 10 users)
  • Accept the EULA (I accept), then click on Scan
  • Let the scan complete. Once it's done, make sure that every item listed in the different tabs is checked and click on the Clean button. This will kill all active processes
    V7SD4El.png
  • Once the cleaning process is complete, AdwCleaner will ask to restart your computer, do it
  • After the restart, a log will open when logging in. Please copy/paste the content of that log in your next reply
iT103hr.pngJunkware Removal Tool (JRT)
  • Download Junkware Removal Tool (JRT) and move it to your Desktop
  • Right-click on JRT.exe and select Spcusrh.pngRun as Administrator (for Windows Vista, 7, 8, 8.1 and 10 users)
  • Press on any key to launch the scan and let it complete
    tLsXbWy.png
    Credits : BleepingComputer.com
  • Once the scan is complete, a log will open. Please copy/paste the content of the output log in your next reply
Your next reply(ies) should therefore contain:
  • Copy/pasted AdwCleaner clean log
  • Copy/pasted JRT log

animinionsmalltext.gif
unite_blue.png
Security Administrator | Sysnative Windows Update Senior Analyst | Malware Hunter | @SecurityAura
My timezone UTC-05:00 (East. Coast). If I didn't reply to you within 48 hours, please send me a PM.


#5 Mugga

Mugga
  • Topic Starter

  • Members
  • 12 posts
  • OFFLINE
  •  
  • Local time:12:00 AM

Posted 30 September 2017 - 08:13 AM

# AdwCleaner 7.0.2.1 - Logfile created on Thu Sep 28 22:26:50 2017
# Updated on 2017/29/08 by Malwarebytes 
# Database: 09-27-2017.1
# Running on Windows 7 Home Premium (X64)
# Mode: scan
 
***** [ Services ] *****
 
PUP.Adware.Heuristic, vToolbarUpdater17.3.0
 
 
***** [ Folders ] *****
 
PUP.Optional.Legacy, C:\Windows\System32\config\systemprofile\AppData\LocalLow\AVG SafeGuard toolbar
PUP.Optional.Legacy, C:\Windows\SysWOW64\config\systemprofile\AppData\LocalLow\AVG SafeGuard toolbar
PUP.Optional.Legacy, C:\Users\Joey\AppData\LocalLow\AVG SafeGuard toolbar
PUP.Optional.Legacy, C:\Program Files (x86)\Common Files\AVG Secure Search
PUP.Optional.Legacy, C:\Windows\System32\config\systemprofile\AppData\Local\YSearchUtil
PUP.Optional.Legacy, C:\Windows\SysWOW64\config\systemprofile\AppData\Local\YSearchUtil
PUP.Optional.Legacy, C:\Users\All Users\Documents\Guid
PUP.Optional.Legacy, C:\Users\Public\Documents\Guid
PUP.Optional.ByteFence, C:\Users\Joey\AppData\Roaming\Microsoft\Windows\Start Menu\ByteFence
PUP.Adware.Heuristic, C:\ProgramData\9b66bb7d
PUP.Adware.Heuristic, C:\ProgramData\d90ebd834be64657
 
 
***** [ Files ] *****
 
PUP.Optional.Legacy, C:\END
PUP.Optional.Legacy, C:\ProgramData\uninstaller.exe
PUP.Optional.Legacy, C:\ProgramData\Application Data\uninstaller.exe
PUP.Optional.Legacy, C:\Users\All Users\uninstaller.exe
PUP.Optional.DriverAgent, C:\Windows\System32\drivers\DRVAGENT64.SYS
 
 
***** [ DLL ] *****
 
No malicious DLLs found.
 
***** [ WMI ] *****
 
No malicious WMI found.
 
***** [ Shortcuts ] *****
 
No malicious shortcuts found.
 
***** [ Tasks ] *****
 
No malicious tasks found.
 
***** [ Registry ] *****
 
PUP.Optional.Legacy, [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\amazonbrowserapp.com
PUP.Optional.Legacy, [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\analytics.app.amazonbrowserapp.com
PUP.Optional.Legacy, [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\ask.com
PUP.Optional.Legacy, [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\blekko.com
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
PUP.Optional.Legacy, [Key] - HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{CCB69577-088B-4004-9ED8-FF5BCC83A039}
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\TypeLib\{99E29823-2F67-41C3-8AA5-6425097A771F}
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\AppID\{39CB8175-E224-4446-8746-00566302DF8D}
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\TypeLib\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921}
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\TypeLib\{D7EE8177-D51E-4F89-92B6-83EA2EC40800}
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947}
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D}
PUP.Optional.Legacy, [Key] - HKCU\Software\Classes\CLSID\{0FEB2313-F89B-4AC6-8153-84025604A06A}
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\Interface\{3137BC14-D8D7-4B67-8FFA-2E0B2E9D541B}
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\Interface\{5D3DCC39-9233-4330-94E9-DA92BE49CA1A}
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\Interface\{615FACDF-DADB-440D-AC91-8AAB0AE9E3AD}
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\Interface\{BFDE183A-C6FE-41D2-80F9-586C29210AC2}
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\Interface\{FBA8498F-B3A0-4942-A2BF-E0CB7BC7E000}
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\TypeLib\{07CAC314-E962-4F78-89AB-DD002F2490EE}
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2}
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\CLSID\{408CFAD9-8F13-4747-8EC7-770A339C7237}
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
PUP.Optional.Legacy, [Key] - HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{6F282B65-56BF-4BD1-A8B2-A4449A05863D}
PUP.Optional.Legacy, [Key] - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6F282B65-56BF-4BD1-A8B2-A4449A05863D}
PUP.Optional.Legacy, [Key] - HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{6F6A5334-78E9-4D9B-8182-8B41EA8C39EF}
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93}
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D}
PUP.Optional.Legacy, [Key] - HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8736C681-37A0-40C6-A0F0-4C083409151C}
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3}
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874}
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9}
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\CLSID\{BC9FD17D-30F6-4464-9E53-596A90AFF023}
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB}
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
PUP.Optional.Legacy, [Key] - HKCU\Software\Classes\TypeLib\{C4E09482-2C6A-44B2-8D40-ABC01B36BB9D}
PUP.Optional.Legacy, [Key] - HKU\S-1-5-21-1979518111-4107658783-1214925503-1001\Software\Classes\TypeLib\{C4E09482-2C6A-44B2-8D40-ABC01B36BB9D}
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C6FDD0C3-266A-4DC3-B459-28C697C44CDC}
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\CLSID\{CC99A798-FD3D-4AB4-969E-6071612524F9}
PUP.Optional.Legacy, [Key] - HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CC99A798-FD3D-4AB4-969E-6071612524F9}
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468}
PUP.Optional.Legacy, [Key] - HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\CLSID\{D879A501-50A7-BEFC-A4C5-32DC6E0CB208}
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\Interface\{655847A1-FA36-46ED-923B-A5CD523696EA}
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\AppID\{7F46C358-270D-4791-A579-AD1DDA1A3F7B}
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3152E1F19977892449DC968802CE8964
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\649A52D257CA5DB4EAAE8BA9EB23E467
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\3DCCCD6BD02558446B24CF1C63EC213C
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\Installer\Features\3DCCCD6BD02558446B24CF1C63EC213C
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\Installer\Products\3DCCCD6BD02558446B24CF1C63EC213C
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\Record\{2009AF2F-5786-3067-8799-B97F7832FDD6}
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\Record\{425E7597-03A2-338D-B72A-0E51FFE77A7E}
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\Record\{915BB7D5-082E-3B91-B1E0-45B5FDE01F24}
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\Record\{FB2E65F4-5687-33EF-9BBF-4E3C9C98D3B9}
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\AppID\escort.DLL
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\AppID\escortApp.DLL
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\AppID\escortEng.DLL
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\AppID\escorTlbr.DLL
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\AppID\esrv.EXE
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\AppID\GenericAskToolbar.DLL
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\AppID\ScriptHelper.EXE
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\Applications\ilividsetup.exe
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\protocols\handler\viprotocol
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\MozillaPlugins\@avg.com\AVG SiteSafety plugin,version=11.0.0.1,application\x-avg-sitesafety-plugin
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Google\Chrome\NativeMessagingHosts\avgsh
PUP.Optional.Legacy, [Value] - HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION | WeatherBug.exe
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\PROTOCOLS\handler\viprotocol
PUP.Optional.Legacy, [Value] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext | DisableAddonLoadTimePerformanceNotifications
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\AppID\Amazon1ButtonBrowserHelper.dll
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{981b174d-7733-4e7f-b89d-6545a7c21838}
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\Record\{181480C8-90AC-3430-B39A-CD121E034A1A}
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\Record\{8F54FA54-1DF8-3B20-890C-CDD95364BC95}
PUP.Optional.WeatherTool, [Key] - HKLM\SOFTWARE\DtsEncodeTools
PUP.Optional.FrostwireTB.A, [Key] - HKLM\SOFTWARE\Classes\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}
PUP.Optional.FrostwireTB.A, [Key] - HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456}
PUP.Optional.FrostwireTB.A, [Key] - HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}
PUP.Optional.FrostwireTB.A, [Key] - HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E}
PUP.Optional.BProtect, [Value] - HKCU\Software\Microsoft\Internet Explorer\TabbedBrowsing | bProtectShowTabsWelcome
PUP.Optional.SlimCleanerPlus, [Key] - HKCU\Software\Microsoft\Internet Explorer\DOMStorage\castplatform.com
PUP.Optional.SlimCleanerPlus, [Key] - HKCU\Software\Microsoft\Internet Explorer\DOMStorage\cdn.castplatform.com
PUP.Adware.Heuristic, [Key] - HKLM\SOFTWARE\Classes\Applications\iLividSetup.exe
 
 
***** [ Firefox (and derivatives) ] *****
 
No malicious Firefox entries.
 
***** [ Chromium (and derivatives) ] *****
 
No malicious Chromium entries.
 
*************************
 
 
 
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt ##########
 
 
 
 
 
 
 
 
 
 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.1.4 (07.09.2017)
Operating System: Windows 7 Home Premium x64 
Ran by Joey (Administrator) on Thu 09/28/2017 at 18:48:09.61
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
 
 
 
File System: 56 
 
Successfully deleted: C:\Users\Joey\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_bcjagnifjocnddgeknajocbkkhlgibem_0.localstorage-journal (File) 
Successfully deleted: C:\Users\Joey\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_bcjagnifjocnddgeknajocbkkhlgibem_0.localstorage (File) 
Successfully deleted: C:\Users\Joey\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_bkomkajifikmkfnjgphkjcfeepbnojok_0.localstorage-journal (File) 
Successfully deleted: C:\Users\Joey\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_bkomkajifikmkfnjgphkjcfeepbnojok_0.localstorage (File) 
Successfully deleted: C:\Users\Joey\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_fbmimoidopbghbcmdmpkjaffffmcbmbg_0.localstorage-journal (File) 
Successfully deleted: C:\Users\Joey\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_fbmimoidopbghbcmdmpkjaffffmcbmbg_0.localstorage (File) 
Successfully deleted: C:\Users\Joey\AppData\Local\stronghold_llc (Folder) 
Successfully deleted: C:\Users\Joey\Appdata\LocalLow\delta (Folder) 
Successfully deleted: C:\Users\Joey\Documents\add-in express (Folder) 
Successfully deleted: C:\Windows\system32\Tasks\PCDEventLauncherTask (Task)
Successfully deleted: C:\Windows\system32\Tasks\PCDoctorBackgroundMonitorTask (Task)
Successfully deleted: C:\Program Files (x86)\delta (Folder) 
Successfully deleted: C:\Users\Joey\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\097M6F6V (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Joey\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0PS72R2M (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Joey\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5HK752PJ (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Joey\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5HS7I3A9 (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Joey\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5O1LCD3P (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Joey\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BS46WTLX (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Joey\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EDUEB4JX (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Joey\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HQ1YRCX4 (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Joey\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JJZPE6DY (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Joey\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\K4M0J1VK (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Joey\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KB2UXYOC (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Joey\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MB33G5X2 (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Joey\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MDQ6W7NT (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Joey\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Q9ACJ59B (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Joey\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R8W8HAP2 (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Joey\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RYVCKNON (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Joey\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TQYDIGDD (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Joey\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\U67BXUH8 (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Joey\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UQV8W253 (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Joey\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UVW25CXD (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Joey\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\YIRAFCW6 (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Joey\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZIEAAQL0 (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\097M6F6V (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0PS72R2M (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5HK752PJ (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5HS7I3A9 (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5O1LCD3P (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BS46WTLX (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EDUEB4JX (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HQ1YRCX4 (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JJZPE6DY (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\K4M0J1VK (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KB2UXYOC (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MB33G5X2 (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MDQ6W7NT (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Q9ACJ59B (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R8W8HAP2 (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RYVCKNON (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TQYDIGDD (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\U67BXUH8 (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UQV8W253 (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UVW25CXD (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\YIRAFCW6 (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZIEAAQL0 (Temporary Internet Files Folder) 
 
Deleted the following from C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\prefs.js
user_pref(CommunityToolbar.ConduitHomepagesList, hxxp://search.conduit.com/?ctid=CT3227982&SearchSource=13);
user_pref(CommunityToolbar.ConduitSearchList, appbario8 Customized Web Search);
user_pref(browser.search.defaultthis.engineName, WhiteSmoke B Customized Web Search);
user_pref(browser.search.order.1, Web Search);
 
 
 
Registry: 8 
 
Successfully deleted: HKCU\Software\Google\Chrome\Extensions\ooebgdicanjhnamfmdlmlbcnkgehkkmf (Registry Key) 
Successfully deleted: HKCU\Software\Google\Chrome\Extensions\pbjikboenpfhbbejgkoklgkhjpfogcam (Registry Key) 
Successfully deleted: HKLM\Software\Google\Chrome\Extensions\bcjagnifjocnddgeknajocbkkhlgibem (Registry Key) 
Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\Search\\Default_Search_URL (Registry Value) 
Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\Search\\SearchAssistant (Registry Value) 
Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\SearchUrl\\Default (Registry Value) 
Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990} (Registry Key)
Successfully deleted: HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\SearchUrl\\Default (Registry Value) 
 
 
 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Thu 09/28/2017 at 19:05:30.94
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 


#6 Aura

Aura

    Bleepin' Special Ops


  • Malware Response Team
  • 19,697 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:11:00 PM

Posted 30 September 2017 - 09:01 AM

Good :) And finally, let's do a scan with FRST to see what's left to remove.

iO3R662.pngFarbar Recovery Scan Tool (FRST) - Scan mode
Follow the instructions below to download and execute a scan on your system with FRST, and provide the logs in your next reply.
  • Right-click on the executable and select Spcusrh.pngRun as Administrator (for Windows Vista, 7, 8, 8.1 and 10 users)
  • Accept the disclaimer by clicking on Yes, and FRST will then do a back-up of your Registry which should take a few seconds
  • Click on the Scan button
  • On completion, two message box will open, saying that the results were saved to FRST.txt and Addition.txt, then open two Notepad files
  • Copy and paste the content of both FRST.txt and Addition.txt in your next reply

animinionsmalltext.gif
unite_blue.png
Security Administrator | Sysnative Windows Update Senior Analyst | Malware Hunter | @SecurityAura
My timezone UTC-05:00 (East. Coast). If I didn't reply to you within 48 hours, please send me a PM.


#7 Mugga

Mugga
  • Topic Starter

  • Members
  • 12 posts
  • OFFLINE
  •  
  • Local time:12:00 AM

Posted 30 September 2017 - 01:27 PM

I dont see a link to download,. Could you post the link?



#8 Mugga

Mugga
  • Topic Starter

  • Members
  • 12 posts
  • OFFLINE
  •  
  • Local time:12:00 AM

Posted 30 September 2017 - 05:36 PM

I'm an idiot, I forgot I downloaded it already. Here it is:

 

 

 

 

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 29-09-2017
Ran by Joey (administrator) on JOEY-PC (30-09-2017 17:30:38)
Running from C:\Users\Joey\Downloads
Loaded Profiles: Joey (Available Profiles: UpdatusUser & Joey)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(Creative Technology Ltd) C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Antivirus\AVGSvc.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
(Intel® Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
(CyberDefender Corp.) C:\Program Files (x86)\CyberDefender\SchedulerService\SchedulerService.exe
(Creative Technology Ltd) C:\Windows\SysWOW64\CtHdaSvc.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avguix.exe
(Intel® Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Antivirus\avgui.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\Jhi_service.exe
(Intel® Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(SoftThinks SAS) C:\Program Files (x86)\AlienRespawn\SftService.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(SoftThinks - Dell) C:\Program Files (x86)\AlienRespawn\Toaster.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
() C:\Program Files (x86)\AlienRespawn\Components\Scheduler\STService.exe
(SoftThinks - Dell) C:\Program Files (x86)\AlienRespawn\Components\DSUpdate\DSUpd.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
() C:\Program Files (x86)\Alienware On-Screen Display\AlienwareOn-ScreenDisplay.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Antivirus\x64\aswidsagenta.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Alienware) C:\Program Files\Alienware\Command Center\AlienFusionService.exe
(Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
(Intel® Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
(Alienware) C:\Program Files\Alienware\Command Center\AlienFusionController.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
(Microsoft Corporation.) C:\Program Files (x86)\Microsoft\BingBar\7.3.124.0\SeaPort.EXE
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Dell Inc.) C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe
(Dell Inc.) C:\Program Files\Dell\DellDataVault\DDVRulesProcessor.exe
(Dell Inc.) C:\Program Files\Dell\DellDataVault\DDVDataCollector.exe
(Dell Inc.) C:\Program Files\Dell\DellDataVault\DDVCollectorSvcApi.exe
(Dell Inc.) C:\Program Files\Dell\DellDataVault\nvapiw.exe
(Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Oracle Corporation) C:\Users\Joey\AppData\Local\Temp\jre-8u144-windows-au.exe
(Oracle Corporation) C:\Users\Joey\AppData\Local\Temp\jds9227334.tmp\jre-8u144-windows-au.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\SysWOW64\msiexec.exe
(Oracle Corporation) C:\Program Files (x86)\Java\jre1.8.0_144\installer.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Antivirus\setup\instup.exe
 
==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [IntelPROSet] => C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [4756240 2012-02-26] (Intel® Corporation)
HKLM\...\Run: [] => [X]
HKLM\...\Run: [AvgUi] => C:\Program Files (x86)\AVG\Framework\Common\avguirna.exe [239592 2017-09-14] (AVG Technologies CZ, s.r.o.)
HKLM\...\Run: [AVGUI.exe] => C:\Program Files (x86)\AVG\Antivirus\AvLaunch.exe [289248 2017-09-22] (AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-02-17] (Intel Corporation)
HKLM-x32\...\Run: [AlienwareOn-ScreenDisplay] => C:\Program Files (x86)\Alienware On-Screen Display\AlienwareOn-ScreenDisplay.exe [1546096 2011-11-03] ()
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [596504 2016-04-01] (Oracle Corporation)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-18\...\RunOnce: [SpUninstallDeleteDir] => rmdir /s /q "\SearchProtect"
CHR HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Tcpip\Parameters: [DhcpNameServer] 75.75.75.75 75.75.76.76
Tcpip\Parameters: [NameServer] 8.8.8.8
Tcpip\..\Interfaces\{21372DD5-1707-4FC2-B2B0-5D536379CA57}: [NameServer] 8.8.8.8
Tcpip\..\Interfaces\{21372DD5-1707-4FC2-B2B0-5D536379CA57}: [DhcpNameServer] 8.8.8.8
Tcpip\..\Interfaces\{38A7A275-2F15-4A7A-B6F9-1D051DC30B43}: [NameServer] 8.8.8.8
Tcpip\..\Interfaces\{38A7A275-2F15-4A7A-B6F9-1D051DC30B43}: [DhcpNameServer] 8.8.8.8
Tcpip\..\Interfaces\{49797B45-3BAD-4AE1-BC49-5896ED006345}: [NameServer] 8.8.8.8
Tcpip\..\Interfaces\{846ee342-7039-11de-9d20-806e6f6e6963}: [NameServer] 8.8.8.8
Tcpip\..\Interfaces\{9CFA72D9-1DFA-47B0-9348-9B2C94035F3B}: [NameServer] 8.8.8.8
Tcpip\..\Interfaces\{9CFA72D9-1DFA-47B0-9348-9B2C94035F3B}: [DhcpNameServer] 75.75.75.75 75.75.76.76
 
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617910&ResetID=131505282322592410&GUID=00000000-0000-0000-0000-000000000000
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617910&ResetID=131505282322602411&GUID=00000000-0000-0000-0000-000000000000
HKU\S-1-5-21-1979518111-4107658783-1214925503-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617910&ResetID=131505282322622412&GUID=00000000-0000-0000-0000-000000000000
HKU\S-1-5-21-1979518111-4107658783-1214925503-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
SearchScopes: HKLM -> DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2465} URL = 
SearchScopes: HKLM -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = 
SearchScopes: HKLM -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2465} URL = 
SearchScopes: HKLM-x32 -> DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2465} URL = 
SearchScopes: HKU\.DEFAULT -> {AC5AB133-CD93-49D2-B821-D9F3E020989E} URL = 
SearchScopes: HKU\S-1-5-21-1979518111-4107658783-1214925503-1001 -> DefaultScope {44A02DE0-F784-4FA5-B9D3-33C6F8ECA78A} URL = 
SearchScopes: HKU\S-1-5-21-1979518111-4107658783-1214925503-1001 -> {B3B3A6AC-74EC-BD56-BCDB-EFA4799FB9DF} URL = hxxps://www.amazon.com/gp/bit/amazonserp/ref=bit_bds-p10_serp_ie_us_display?ie=UTF8&tagbase=bds-p10&tbrId=v1_abb-channel-10_8b40eee8_1201_1401_20160411_US_ie_ds_&tag=bds-p10-serp-us-ie-20&query={searchTerms}
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-05-11] (Google Inc.)
BHO: Bing Bar Helper -> {d2ce3e00-f94a-4740-988e-03dc2f38c34f} -> C:\Program Files (x86)\Microsoft\BingBar\7.3.124.0\amd64\BingExt.dll [2013-12-16] (Microsoft Corporation.)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\ssv.dll [2016-05-11] (Oracle Corporation)
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2016-05-11] (Google Inc.)
BHO-x32: Free Download Manager -> {CC59E0F9-7E43-44FA-9FAA-8377850BF205} -> C:\Program Files (x86)\Free Download Manager\iefdm2.dll [2013-10-25] (FreeDownloadManager.ORG)
BHO-x32: Bing Bar Helper -> {d2ce3e00-f94a-4740-988e-03dc2f38c34f} -> C:\Program Files (x86)\Microsoft\BingBar\7.3.124.0\BingExt.dll [2013-12-16] (Microsoft Corporation.)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\jp2ssv.dll [2016-05-11] (Oracle Corporation)
Toolbar: HKLM - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.124.0\amd64\BingExt.dll [2013-12-16] (Microsoft Corporation.)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-05-11] (Google Inc.)
Toolbar: HKLM-x32 - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.3.124.0\BingExt.dll [2013-12-16] (Microsoft Corporation.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2016-05-11] (Google Inc.)
Toolbar: HKU\S-1-5-21-1979518111-4107658783-1214925503-1001 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-05-11] (Google Inc.)
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
 
FireFox:
========
FF ProfilePath: C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default [2017-09-26]
FF Homepage: Mozilla\Firefox\Profiles\zt8k3d39.default -> user_pref("browser.startup.homepage", "hxxps://www.malwarebytes.org/restorebrowser/
FF SearchPlugin: C:\Users\Joey\AppData\Roaming\Mozilla\Firefox\Profiles\zt8k3d39.default\searchplugins\yhs.xml [2017-09-23]
FF HKU\S-1-5-21-1979518111-4107658783-1214925503-1001\...\Firefox\Extensions: [{b64982b1-d112-42b5-b1e4-d3867c4533f8}] - C:\ProgramData\PC Performer Manager\2.2.558.177\{16cdff19-861d-48e3-a751-d99a27784753}\FirefoxExtension => not found
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_27_0_0_130.dll [2017-09-22] ()
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_27_0_0_130.dll [2017-09-22] ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-02-01] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-02-01] (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.91.2 -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\dtplugin\npDeployJava1.dll [2016-05-11] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.144.2 -> C:\Program Files (x86)\Java\jre1.8.0_144\bin\plugin2\npjp2.dll [2017-09-30] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL [2011-04-05] (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2012-03-04] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2012-03-04] (NVIDIA Corporation)
FF Plugin-x32: @oberon-media.com/ONCAdapter -> C:\Program Files (x86)\Common Files\Oberon Media\NCAdapter\1.0.0.7\npapicomadapter.dll [2010-09-01] (Oberon-Media )
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-09-21] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-09-21] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2015-09-24] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-1979518111-4107658783-1214925503-1001: @tnt2toolbar.com/Plugin -> C:\Users\Joey\AppData\Local\TNT2\2.0.0.1194\npTNT2.dll [No File]
FF Plugin HKU\S-1-5-21-1979518111-4107658783-1214925503-1001: thehappycloud.com/HappyCloudPlugin -> C:\ProgramData\HappyCloud\Application\npHappyCloudPlugin.dll [2013-01-03] (The Happy Cloud)
StartMenuInternet: FIREFOX.EXE - firefox.exe
 
Chrome: 
=======
CHR DefaultProfile: Default
CHR HomePage: Default -> amazon.com/websearch/?ie=UTF8__PARAM__
CHR Profile: C:\Users\Joey\AppData\Local\Google\Chrome\User Data\Default [2017-09-30]
CHR Extension: (Google Slides) - C:\Users\Joey\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-09-26]
CHR Extension: (Google Docs) - C:\Users\Joey\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-09-26]
CHR Extension: (Google Drive) - C:\Users\Joey\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-12-20]
CHR Extension: (YouTube) - C:\Users\Joey\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-09-26]
CHR Extension: (hTab) - C:\Users\Joey\AppData\Local\Google\Chrome\User Data\Default\Extensions\elmkjjfkkchohaaoljobaffjeedcoocj [2017-09-21]
CHR Extension: (Google Sheets) - C:\Users\Joey\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-09-26]
CHR Extension: (Google Docs Offline) - C:\Users\Joey\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-04-06]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Joey\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-09-22]
CHR Extension: (Gmail) - C:\Users\Joey\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-09-26]
CHR Extension: (Chrome Media Router) - C:\Users\Joey\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-09-28]
CHR HKLM\...\Chrome\Extension: [elmkjjfkkchohaaoljobaffjeedcoocj] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-1979518111-4107658783-1214925503-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [elmkjjfkkchohaaoljobaffjeedcoocj] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [ajimflpekochgkclpjepklfnkhcbbcpk] - <no Path/update_url>
CHR HKLM-x32\...\Chrome\Extension: [ejhdkifcpnleafenajdjbeikplkooglk] - <no Path/update_url>
CHR HKLM-x32\...\Chrome\Extension: [elmkjjfkkchohaaoljobaffjeedcoocj] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [fjdbddblhompbdadaenlghkegihdcoai] - <no Path/update_url>
CHR HKLM-x32\...\Chrome\Extension: [gihfmmedoddijgnhkgfgnkeohkpbipol] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [jgjpaakpifnhoaffblomkffniknfjllm] - <no Path/update_url>
CHR HKLM-x32\...\Chrome\Extension: [jlhjpacphahiiolhpgaemifichemekjp] - <no Path/update_url>
CHR HKLM-x32\...\Chrome\Extension: [khpfgegklcpadnogmhlcklcjbfjlgeai] - <no Path/update_url>
CHR HKLM-x32\...\Chrome\Extension: [lghnoihgonbodhaobhfcjhjmndoeaaae] - <no Path/update_url>
CHR HKLM-x32\...\Chrome\Extension: [liifpfhlakkjeobbcedbhcanogdcdjpn] - C:\Users\Joey\AppData\Local\TidyNetwork.com\tidy.crx <not found>
 
==================== Services (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 AVG Antivirus; C:\Program Files (x86)\AVG\Antivirus\AVGSvc.exe [276328 2017-09-22] (AVG Technologies CZ, s.r.o.)
R3 avgbIDSAgent; C:\Program Files (x86)\AVG\Antivirus\x64\aswidsagenta.exe [7502936 2017-09-22] (AVG Technologies CZ, s.r.o.)
R2 avgsvc; C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe [1428656 2017-09-14] (AVG Technologies CZ, s.r.o.)
R2 CDScheduler; C:\Program Files (x86)\CyberDefender\SchedulerService\SchedulerService.exe [735352 2012-03-26] (CyberDefender Corp.)
S3 Creative ALchemy AL6 Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [79360 2012-05-12] (Creative Labs) [File not signed]
S3 Creative Audio Engine Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [79360 2012-05-12] (Creative Labs) [File not signed]
R2 CTAudSvcService; c:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe [423424 2011-10-19] (Creative Technology Ltd) [File not signed]
R2 CtHdaSvc; C:\Windows\sysWow64\CtHdaSvc.exe [122880 2012-03-27] (Creative Technology Ltd)
R2 DDVCollectorSvcApi; C:\Program Files\Dell\DellDataVault\DDVCollectorSvcApi.exe [208760 2017-07-27] (Dell Inc.)
R2 DDVDataCollector; C:\Program Files\Dell\DellDataVault\DDVDataCollector.exe [3294584 2017-07-27] (Dell Inc.)
R2 DDVRulesProcessor; C:\Program Files\Dell\DellDataVault\DDVRulesProcessor.exe [217464 2017-07-27] (Dell Inc.)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe [161560 2012-02-01] (Intel Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6058960 2017-08-07] (Malwarebytes)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [273168 2012-02-26] ()
S3 npggsvc; C:\Windows\SysWOW64\GameMon.des [5267776 2014-01-22] (INCA Internet Co., Ltd.)
R2 SupportAssistAgent; C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe [53208 2017-09-22] (Dell Inc.)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [2669840 2012-02-26] (Intel® Corporation)
 
===================== Drivers (Whitelisted) ======================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R1 avgbdisk; C:\Windows\system32\drivers\avgbdiska.sys [166624 2017-09-22] (AVG Technologies CZ, s.r.o.)
R1 avgbidsdriver; C:\Windows\system32\drivers\avgbidsdrivera.sys [314128 2017-09-22] (AVG Technologies CZ, s.r.o.)
R0 avgbidsh; C:\Windows\system32\drivers\avgbidsha.sys [192584 2017-09-22] (AVG Technologies CZ, s.r.o.)
R0 avgblog; C:\Windows\system32\drivers\avgbloga.sys [336896 2017-09-22] (AVG Technologies CZ, s.r.o.)
R0 avgbuniv; C:\Windows\system32\drivers\avgbuniva.sys [51336 2017-09-22] (AVG Technologies CZ, s.r.o.)
S3 avgHwid; C:\Windows\system32\drivers\avgHwid.sys [39424 2017-09-22] (AVG Technologies CZ, s.r.o.)
R2 avgMonFlt; C:\Windows\system32\drivers\avgMonFlt.sys [140192 2017-09-22] (AVG Technologies CZ, s.r.o.)
R1 avgRdr; C:\Windows\system32\drivers\avgRdr2.sys [102792 2017-09-22] (AVG Technologies CZ, s.r.o.)
R0 avgRvrt; C:\Windows\system32\drivers\avgRvrt.sys [76832 2017-09-22] (AVG Technologies CZ, s.r.o.)
R1 avgSnx; C:\Windows\system32\drivers\avgSnx.sys [1008800 2017-09-22] (AVG Technologies CZ, s.r.o.)
R1 avgSP; C:\Windows\system32\drivers\avgSP.sys [583288 2017-09-22] (AVG Technologies CZ, s.r.o.)
R2 avgStm; C:\Windows\system32\drivers\avgStm.sys [191720 2017-09-22] (AVG Technologies CZ, s.r.o.)
R1 avgtp; C:\Windows\system32\drivers\avgtpx64.sys [46368 2013-11-12] (AVG Technologies)
R0 avgVmm; C:\Windows\system32\drivers\avgVmm.sys [355856 2017-09-26] (AVG Technologies CZ, s.r.o.)
R3 cthda; C:\Windows\System32\drivers\cthda.sys [1052760 2012-03-27] (Creative Technology Ltd)
R3 DDDriver; C:\Windows\System32\drivers\DDDriver64Dcsa.sys [32960 2017-07-27] (Dell Inc.)
R3 DellProf; C:\Windows\System32\drivers\DellProf.sys [32568 2017-07-27] (Dell Computer Corporation)
R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [498512 2015-12-19] (Symantec Corporation)
R1 ESProtectionDriver; C:\Windows\system32\drivers\mbae64.sys [77440 2017-08-24] ()
R2 MBAMChameleon; C:\Windows\system32\drivers\MBAMChameleon.sys [192960 2017-09-26] (Malwarebytes)
R3 MBAMFarflt; C:\Windows\System32\DRIVERS\farflt.sys [101824 2017-09-30] (Malwarebytes)
R3 MBAMProtection; C:\Windows\system32\drivers\mbam.sys [45472 2017-09-30] (Malwarebytes)
R0 MBAMSwissArmy; C:\Windows\System32\drivers\MBAMSwissArmy.sys [253888 2017-09-30] (Malwarebytes)
R3 MBAMWebProtection; C:\Windows\system32\drivers\mwac.sys [84256 2017-09-30] (Malwarebytes)
R1 nvkflt; C:\Windows\System32\DRIVERS\nvkflt.sys [249152 2012-03-04] (NVIDIA Corporation)
R3 Sftfs; C:\Windows\System32\DRIVERS\Sftfswin7.sys [767648 2014-10-08] (Microsoft Corporation)
R3 Sftplay; C:\Windows\System32\DRIVERS\Sftplaywin7.sys [273576 2014-10-08] (Microsoft Corporation)
R3 Sftredir; C:\Windows\System32\DRIVERS\Sftredirwin7.sys [29864 2014-10-08] (Microsoft Corporation)
R3 Sftvol; C:\Windows\System32\DRIVERS\Sftvolwin7.sys [23208 2014-10-08] (Microsoft Corporation)
R3 ST_ACCEL; C:\Windows\System32\DRIVERS\ST_ACCEL.sys [67184 2012-01-03] (STMicroelectronics)
U3 TrueSight; C:\Windows\System32\drivers\TrueSight.sys [28272 2017-09-26] ()
S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2017-09-30 17:30 - 2017-09-30 17:30 - 000000000 ____D C:\Users\Joey\Downloads\FRST-OlderVersion
2017-09-30 17:09 - 2017-09-30 17:09 - 000000000 ____D C:\Windows\LastGood
2017-09-30 16:36 - 2017-09-30 16:36 - 000003792 _____ C:\Windows\System32\Tasks\Dell SupportAssistAgent AutoUpdate
2017-09-30 16:34 - 2017-09-30 16:35 - 000000000 ____D C:\ProgramData\SupportAssist
2017-09-30 16:31 - 2017-09-30 16:31 - 000003504 _____ C:\Windows\System32\Tasks\PCDEventLauncherTask
2017-09-30 14:54 - 2017-09-30 14:54 - 000297656 _____ C:\Windows\Minidump\093017-23883-01.dmp
2017-09-28 19:05 - 2017-09-28 19:05 - 000010578 _____ C:\Users\Joey\Desktop\JRT.txt
2017-09-28 18:46 - 2017-09-28 18:46 - 001790024 _____ (Malwarebytes) C:\Users\Joey\Downloads\JRT.exe
2017-09-28 18:29 - 2017-09-28 18:29 - 000011408 _____ C:\Users\Joey\Desktop\AdwCleaner[S0].txt
2017-09-28 18:17 - 2017-09-28 18:30 - 000000000 ____D C:\AdwCleaner
2017-09-28 18:17 - 2017-09-28 18:17 - 008182736 _____ (Malwarebytes) C:\Users\Joey\Downloads\AdwCleaner.exe
2017-09-26 18:42 - 2017-09-26 18:42 - 000028272 _____ C:\Windows\system32\Drivers\TrueSight.sys
2017-09-26 18:38 - 2017-09-26 18:38 - 000000000 ____D C:\ProgramData\RogueKiller
2017-09-26 18:22 - 2017-09-26 18:22 - 000000860 _____ C:\Users\Public\Desktop\RogueKiller.lnk
2017-09-26 18:22 - 2017-09-26 18:22 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RogueKiller
2017-09-26 18:21 - 2017-09-26 18:22 - 000000000 ____D C:\Program Files\RogueKiller
2017-09-26 18:19 - 2017-09-26 18:19 - 035910920 _____ (Adlice Software ) C:\Users\Joey\Downloads\setup.exe
2017-09-26 18:17 - 2017-09-26 18:17 - 000087754 _____ C:\Users\Joey\Desktop\malware report.txt
2017-09-26 17:38 - 2017-09-26 18:09 - 000000258 __RSH C:\ProgramData\ntuser.pol
2017-09-26 16:35 - 2017-09-26 16:35 - 000192960 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMChameleon.sys
2017-09-26 16:34 - 2017-09-30 14:55 - 000101824 _____ (Malwarebytes) C:\Windows\system32\Drivers\farflt.sys
2017-09-26 16:34 - 2017-09-30 14:55 - 000084256 _____ (Malwarebytes) C:\Windows\system32\Drivers\mwac.sys
2017-09-26 16:34 - 2017-09-30 14:55 - 000045472 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2017-09-26 16:33 - 2017-09-30 14:55 - 000253888 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2017-09-26 16:33 - 2017-09-26 16:33 - 000001869 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2017-09-26 16:33 - 2017-09-26 16:33 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2017-09-26 16:33 - 2017-08-24 11:27 - 000077440 _____ C:\Windows\system32\Drivers\mbae64.sys
2017-09-26 16:32 - 2017-09-26 16:32 - 000000000 ____D C:\Program Files\Malwarebytes
2017-09-26 16:29 - 2017-09-26 16:30 - 068408664 _____ (Malwarebytes ) C:\Users\Joey\Downloads\mb3-setup-1878.1878-3.2.2.2029.exe
2017-09-23 19:10 - 2017-09-23 19:11 - 000041201 _____ C:\Users\Joey\Downloads\Addition.txt
2017-09-23 19:07 - 2017-09-30 17:33 - 000024083 _____ C:\Users\Joey\Downloads\FRST.txt
2017-09-23 19:07 - 2017-09-30 17:30 - 000000000 ____D C:\FRST
2017-09-23 19:06 - 2017-09-30 17:30 - 002399744 _____ (Farbar) C:\Users\Joey\Downloads\FRST64.exe
2017-09-22 23:49 - 2017-09-22 23:49 - 000000000 ____D C:\Users\Joey\AppData\Roaming\AVG
2017-09-22 23:47 - 2017-09-26 16:30 - 000355856 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgvmm.sys
2017-09-22 23:47 - 2017-09-23 18:16 - 000004178 _____ C:\Windows\System32\Tasks\Antivirus Emergency Update
2017-09-22 23:47 - 2017-09-22 23:48 - 000191720 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgstm.sys
2017-09-22 23:47 - 2017-09-22 23:47 - 001008800 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgSnx.sys
2017-09-22 23:47 - 2017-09-22 23:47 - 000583288 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgSP.sys
2017-09-22 23:47 - 2017-09-22 23:47 - 000402608 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\avgBoot.exe
2017-09-22 23:47 - 2017-09-22 23:47 - 000336896 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgbloga.sys
2017-09-22 23:47 - 2017-09-22 23:47 - 000314128 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgbidsdrivera.sys
2017-09-22 23:47 - 2017-09-22 23:47 - 000192584 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgbidsha.sys
2017-09-22 23:47 - 2017-09-22 23:47 - 000166624 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgbdiska.sys
2017-09-22 23:47 - 2017-09-22 23:47 - 000140192 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgMonFlt.sys
2017-09-22 23:47 - 2017-09-22 23:47 - 000102792 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgRdr2.sys
2017-09-22 23:47 - 2017-09-22 23:47 - 000076832 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgRvrt.sys
2017-09-22 23:47 - 2017-09-22 23:47 - 000051336 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgbuniva.sys
2017-09-22 23:47 - 2017-09-22 23:47 - 000039424 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgHwid.sys
2017-09-22 23:45 - 2017-09-22 23:45 - 000001008 _____ C:\Users\Public\Desktop\AVG.lnk
2017-09-22 23:45 - 2017-09-22 23:45 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
2017-09-22 23:44 - 2017-09-30 14:11 - 000003600 _____ C:\Windows\System32\Tasks\AVG EUpdate Task
2017-09-22 23:43 - 2017-09-22 23:45 - 000000000 ____D C:\Program Files (x86)\AVG
2017-09-22 18:21 - 2017-09-22 18:21 - 000003342 _____ C:\Windows\System32\Tasks\PCDDataUploadTask
2017-09-22 18:21 - 2017-09-22 18:21 - 000003216 _____ C:\Windows\System32\Tasks\SystemToolsDailyTest
2017-09-22 18:20 - 2017-09-22 18:20 - 000000000 ____D C:\ProgramData\PC-Doctor for Windows
2017-09-22 18:15 - 2017-09-22 18:15 - 000000000 ____D C:\ProgramData\PC-Doctor, Inc
2017-09-22 05:03 - 2017-09-22 05:03 - 003449304 _____ (AVG Technologies CZ, s.r.o.) C:\Users\Joey\Downloads\AVG_Protection_Free_1606 (1).exe
2017-09-22 03:10 - 2017-04-27 18:50 - 003550208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_47.dll
2017-09-22 03:10 - 2017-04-12 09:05 - 004296704 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_47.dll
2017-09-22 00:30 - 2017-09-22 00:30 - 000001044 _____ C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2017-09-22 00:21 - 2016-07-07 11:08 - 000046080 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpipreg.sys
2017-09-22 00:21 - 2016-03-16 14:50 - 000156672 _____ (Microsoft Corporation) C:\Windows\system32\mtxoci.dll
2017-09-22 00:21 - 2016-03-16 14:28 - 000176128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msorcl32.dll
2017-09-22 00:21 - 2016-03-16 14:28 - 000111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mtxoci.dll
2017-09-22 00:20 - 2017-05-03 11:34 - 000094952 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe
2017-09-22 00:20 - 2017-05-03 11:29 - 001206272 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2017-09-22 00:20 - 2017-05-03 09:05 - 001555968 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2017-09-22 00:20 - 2017-05-03 09:05 - 000620544 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2017-09-22 00:20 - 2017-05-03 09:05 - 000535552 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2017-09-22 00:20 - 2017-05-03 09:05 - 000325632 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2017-09-22 00:20 - 2017-05-03 09:05 - 000311296 _____ (Microsoft Corporation) C:\Windows\system32\centel.dll
2017-09-22 00:20 - 2017-05-03 09:05 - 000217088 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2017-09-22 00:20 - 2017-05-03 09:05 - 000127488 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2017-09-22 00:20 - 2017-03-22 22:06 - 001691136 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe
2017-09-22 00:20 - 2016-05-12 11:18 - 000090624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\olepro32.dll
2017-09-22 00:20 - 2016-05-11 13:02 - 000483840 _____ (Microsoft Corporation) C:\Windows\system32\StructuredQuery.dll
2017-09-22 00:20 - 2016-05-11 11:19 - 000363520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\StructuredQuery.dll
2017-09-22 00:20 - 2016-01-20 20:51 - 000073664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\disk.sys
2017-09-22 00:19 - 2017-08-16 10:57 - 003224576 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2017-09-22 00:19 - 2017-08-15 21:10 - 000395976 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2017-09-22 00:19 - 2017-08-15 20:25 - 000347336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2017-09-22 00:19 - 2017-08-15 10:06 - 015260160 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2017-09-22 00:19 - 2017-08-15 10:01 - 000416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2017-09-22 00:19 - 2017-08-15 10:01 - 000279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2017-09-22 00:19 - 2017-08-15 10:01 - 000076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2017-09-22 00:19 - 2017-08-15 09:58 - 013673984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2017-09-22 00:19 - 2017-08-13 14:58 - 025730560 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2017-09-22 00:19 - 2017-08-13 13:24 - 002724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2017-09-22 00:19 - 2017-08-13 13:24 - 000004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2017-09-22 00:19 - 2017-08-13 13:06 - 000066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2017-09-22 00:19 - 2017-08-13 13:05 - 000576512 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2017-09-22 00:19 - 2017-08-13 13:05 - 000417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2017-09-22 00:19 - 2017-08-13 13:05 - 000088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2017-09-22 00:19 - 2017-08-13 13:05 - 000048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2017-09-22 00:19 - 2017-08-13 13:04 - 002899968 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2017-09-22 00:19 - 2017-08-13 12:56 - 000054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2017-09-22 00:19 - 2017-08-13 12:55 - 000034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2017-09-22 00:19 - 2017-08-13 12:54 - 020269056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2017-09-22 00:19 - 2017-08-13 12:52 - 000615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2017-09-22 00:19 - 2017-08-13 12:51 - 005981696 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2017-09-22 00:19 - 2017-08-13 12:51 - 000144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2017-09-22 00:19 - 2017-08-13 12:51 - 000116224 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2017-09-22 00:19 - 2017-08-13 12:50 - 000817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2017-09-22 00:19 - 2017-08-13 12:50 - 000814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2017-09-22 00:19 - 2017-08-13 12:46 - 002724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2017-09-22 00:19 - 2017-08-13 12:41 - 000968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2017-09-22 00:19 - 2017-08-13 12:38 - 000489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2017-09-22 00:19 - 2017-08-13 12:30 - 000062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2017-09-22 00:19 - 2017-08-13 12:29 - 000499200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2017-09-22 00:19 - 2017-08-13 12:29 - 000341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2017-09-22 00:19 - 2017-08-13 12:29 - 000087552 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2017-09-22 00:19 - 2017-08-13 12:29 - 000077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2017-09-22 00:19 - 2017-08-13 12:29 - 000047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2017-09-22 00:19 - 2017-08-13 12:28 - 000064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2017-09-22 00:19 - 2017-08-13 12:27 - 000107520 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2017-09-22 00:19 - 2017-08-13 12:24 - 002291200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2017-09-22 00:19 - 2017-08-13 12:24 - 000199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2017-09-22 00:19 - 2017-08-13 12:23 - 000092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2017-09-22 00:19 - 2017-08-13 12:22 - 000047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2017-09-22 00:19 - 2017-08-13 12:21 - 000030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2017-09-22 00:19 - 2017-08-13 12:20 - 000315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2017-09-22 00:19 - 2017-08-13 12:19 - 000476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2017-09-22 00:19 - 2017-08-13 12:17 - 000663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2017-09-22 00:19 - 2017-08-13 12:17 - 000620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2017-09-22 00:19 - 2017-08-13 12:17 - 000115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2017-09-22 00:19 - 2017-08-13 12:07 - 000262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2017-09-22 00:19 - 2017-08-13 12:04 - 000807936 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2017-09-22 00:19 - 2017-08-13 12:04 - 000726528 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2017-09-22 00:19 - 2017-08-13 12:02 - 001359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2017-09-22 00:19 - 2017-08-13 12:01 - 002134528 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2017-09-22 00:19 - 2017-08-13 12:01 - 000073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2017-09-22 00:19 - 2017-08-13 12:01 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2017-09-22 00:19 - 2017-08-13 12:00 - 000091136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2017-09-22 00:19 - 2017-08-13 11:57 - 000168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2017-09-22 00:19 - 2017-08-13 11:53 - 000130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2017-09-22 00:19 - 2017-08-13 11:48 - 004547072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2017-09-22 00:19 - 2017-08-13 11:46 - 000230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2017-09-22 00:19 - 2017-08-13 11:44 - 000694784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2017-09-22 00:19 - 2017-08-13 11:43 - 002058752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2017-09-22 00:19 - 2017-08-13 11:43 - 001155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2017-09-22 00:19 - 2017-08-13 11:40 - 003241472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2017-09-22 00:19 - 2017-08-13 11:27 - 001544704 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2017-09-22 00:19 - 2017-08-13 11:18 - 000800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2017-09-22 00:19 - 2017-08-13 11:17 - 002767872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2017-09-22 00:19 - 2017-08-13 11:14 - 000710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2017-09-22 00:19 - 2017-08-13 11:13 - 001314816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2017-09-22 00:19 - 2017-08-11 02:38 - 005547752 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2017-09-22 00:19 - 2017-08-11 02:36 - 001732864 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2017-09-22 00:19 - 2017-08-11 02:35 - 002065408 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll
2017-09-22 00:19 - 2017-07-21 10:26 - 000518144 _____ C:\Windows\SysWOW64\msjetoledb40.dll
2017-09-22 00:19 - 2017-07-21 10:26 - 000290816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msjtes40.dll
2017-09-22 00:19 - 2017-07-14 11:29 - 002319872 _____ (Microsoft Corporation) C:\Windows\system32\tquery.dll
2017-09-22 00:19 - 2017-07-14 11:29 - 002222080 _____ (Microsoft Corporation) C:\Windows\system32\mssrch.dll
2017-09-22 00:19 - 2017-07-14 11:29 - 002058240 _____ (Microsoft Corporation) C:\Windows\system32\Query.dll
2017-09-22 00:19 - 2017-07-14 11:10 - 001549824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tquery.dll
2017-09-22 00:19 - 2017-07-14 11:10 - 001400320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssrch.dll
2017-09-22 00:19 - 2017-07-14 11:10 - 001363968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Query.dll
2017-09-22 00:19 - 2017-07-07 11:29 - 001143296 _____ (Microsoft Corporation) C:\Windows\system32\DXPTaskRingtone.dll
2017-09-22 00:19 - 2017-07-07 11:10 - 000973312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DXPTaskRingtone.dll
2017-09-22 00:19 - 2017-07-01 09:05 - 001311744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msjet40.dll
2017-09-22 00:19 - 2017-07-01 09:05 - 000616448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrepl40.dll
2017-09-22 00:19 - 2017-07-01 09:05 - 000475648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxbde40.dll
2017-09-22 00:19 - 2017-07-01 09:05 - 000375808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mspbde40.dll
2017-09-22 00:19 - 2017-07-01 09:05 - 000343552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrd3x40.dll
2017-09-22 00:19 - 2017-07-01 09:05 - 000339968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msexcl40.dll
2017-09-22 00:19 - 2017-07-01 09:05 - 000310272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrd2x40.dll
2017-09-22 00:19 - 2017-07-01 09:05 - 000240640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msltus40.dll
2017-09-22 00:19 - 2017-06-09 11:33 - 001680616 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2017-09-22 00:19 - 2017-05-30 00:56 - 001895656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2017-09-22 00:19 - 2017-05-12 12:25 - 001251328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2017-09-22 00:19 - 2017-05-12 11:58 - 001648128 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2017-09-22 00:19 - 2017-05-12 11:58 - 001180160 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2017-09-22 00:19 - 2017-05-10 11:29 - 003165184 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2017-09-22 00:19 - 2017-05-10 11:29 - 000192512 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2017-09-22 00:19 - 2017-05-10 11:29 - 000098816 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2017-09-22 00:19 - 2017-05-10 11:28 - 000091136 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2017-09-22 00:19 - 2017-05-10 11:14 - 002651136 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2017-09-22 00:19 - 2017-05-10 11:13 - 000709120 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2017-09-22 00:19 - 2017-05-10 11:13 - 000140288 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2017-09-22 00:19 - 2017-05-10 11:13 - 000037888 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2017-09-22 00:19 - 2017-05-10 11:13 - 000037888 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2017-09-22 00:19 - 2017-05-10 11:13 - 000036864 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2017-09-22 00:19 - 2017-05-10 11:13 - 000012288 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
2017-09-22 00:19 - 2017-05-10 11:12 - 000174080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2017-09-22 00:19 - 2017-05-10 11:00 - 000573440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2017-09-22 00:19 - 2017-05-10 11:00 - 000093696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2017-09-22 00:19 - 2017-05-10 11:00 - 000035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2017-09-22 00:19 - 2017-04-12 11:32 - 001483776 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2017-09-22 00:19 - 2017-03-03 21:27 - 001574912 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll
2017-09-22 00:19 - 2017-01-18 11:36 - 000994760 _____ (Microsoft Corporation) C:\Windows\system32\ucrtbase.dll
2017-09-22 00:19 - 2017-01-18 11:36 - 000063840 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-private-l1-1-0.dll
2017-09-22 00:19 - 2017-01-18 11:36 - 000020832 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-math-l1-1-0.dll
2017-09-22 00:19 - 2017-01-18 11:36 - 000019808 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-multibyte-l1-1-0.dll
2017-09-22 00:19 - 2017-01-18 11:36 - 000017760 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-string-l1-1-0.dll
2017-09-22 00:19 - 2017-01-18 11:36 - 000017760 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-stdio-l1-1-0.dll
2017-09-22 00:19 - 2017-01-18 11:36 - 000016224 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-runtime-l1-1-0.dll
2017-09-22 00:19 - 2017-01-18 11:36 - 000015712 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-convert-l1-1-0.dll
2017-09-22 00:19 - 2017-01-18 11:36 - 000014176 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-time-l1-1-0.dll
2017-09-22 00:19 - 2017-01-18 11:36 - 000014176 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-2-0.dll
2017-09-22 00:19 - 2017-01-18 11:36 - 000013664 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll
2017-09-22 00:19 - 2017-01-18 11:36 - 000012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-process-l1-1-0.dll
2017-09-22 00:19 - 2017-01-18 11:36 - 000012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-heap-l1-1-0.dll
2017-09-22 00:19 - 2017-01-18 11:36 - 000012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-conio-l1-1-0.dll
2017-09-22 00:19 - 2017-01-18 11:36 - 000012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-utility-l1-1-0.dll
2017-09-22 00:19 - 2017-01-18 11:36 - 000012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-locale-l1-1-0.dll
2017-09-22 00:19 - 2017-01-18 11:36 - 000012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-environment-l1-1-0.dll
2017-09-22 00:19 - 2017-01-18 11:36 - 000012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-2-0.dll
2017-09-22 00:19 - 2017-01-18 11:36 - 000012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-1.dll
2017-09-22 00:19 - 2017-01-18 11:36 - 000011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l2-1-0.dll
2017-09-22 00:19 - 2017-01-18 11:36 - 000011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-timezone-l1-1-0.dll
2017-09-22 00:19 - 2017-01-18 11:36 - 000011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l2-1-0.dll
2017-09-22 00:19 - 2017-01-18 11:36 - 000011608 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-2-0.dll
2017-09-22 00:19 - 2017-01-18 11:35 - 000922432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ucrtbase.dll
2017-09-22 00:19 - 2017-01-18 11:35 - 000066400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-private-l1-1-0.dll
2017-09-22 00:19 - 2017-01-18 11:35 - 000022368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-math-l1-1-0.dll
2017-09-22 00:19 - 2017-01-18 11:35 - 000019808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-multibyte-l1-1-0.dll
2017-09-22 00:19 - 2017-01-18 11:35 - 000017760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-string-l1-1-0.dll
2017-09-22 00:19 - 2017-01-18 11:35 - 000017760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-stdio-l1-1-0.dll
2017-09-22 00:19 - 2017-01-18 11:35 - 000016224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-runtime-l1-1-0.dll
2017-09-22 00:19 - 2017-01-18 11:35 - 000015712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-convert-l1-1-0.dll
2017-09-22 00:19 - 2017-01-18 11:35 - 000014176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-time-l1-1-0.dll
2017-09-22 00:19 - 2017-01-18 11:35 - 000014176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-2-0.dll
2017-09-22 00:19 - 2017-01-18 11:35 - 000013664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-filesystem-l1-1-0.dll
2017-09-22 00:19 - 2017-01-18 11:35 - 000012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-process-l1-1-0.dll
2017-09-22 00:19 - 2017-01-18 11:35 - 000012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-heap-l1-1-0.dll
2017-09-22 00:19 - 2017-01-18 11:35 - 000012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-conio-l1-1-0.dll
2017-09-22 00:19 - 2017-01-18 11:35 - 000012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-utility-l1-1-0.dll
2017-09-22 00:19 - 2017-01-18 11:35 - 000012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-locale-l1-1-0.dll
2017-09-22 00:19 - 2017-01-18 11:35 - 000012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-environment-l1-1-0.dll
2017-09-22 00:19 - 2017-01-18 11:35 - 000012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-2-0.dll
2017-09-22 00:19 - 2017-01-18 11:35 - 000012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-1.dll
2017-09-22 00:19 - 2017-01-18 11:35 - 000011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l2-1-0.dll
2017-09-22 00:19 - 2017-01-18 11:35 - 000011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-timezone-l1-1-0.dll
2017-09-22 00:19 - 2017-01-18 11:35 - 000011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l2-1-0.dll
2017-09-22 00:19 - 2017-01-18 11:35 - 000011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-2-0.dll
2017-09-22 00:19 - 2017-01-11 14:01 - 001887744 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2017-09-22 00:19 - 2017-01-11 13:43 - 001241088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2017-09-22 00:19 - 2016-11-09 12:33 - 003244032 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2017-09-22 00:19 - 2016-11-09 12:17 - 002365440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2017-09-22 00:19 - 2016-10-07 11:32 - 003649536 _____ (Microsoft Corporation) C:\Windows\system32\MSVidCtl.dll
2017-09-22 00:19 - 2016-10-07 11:12 - 002291712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSVidCtl.dll
2017-09-22 00:19 - 2016-09-15 10:56 - 000041984 _____ (Microsoft Corporation) C:\Windows\system32\UtcResources.dll
2017-09-22 00:19 - 2016-08-22 12:19 - 001386496 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll
2017-09-22 00:19 - 2016-08-12 13:02 - 014632960 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2017-09-22 00:19 - 2016-08-12 12:47 - 011410432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2017-09-22 00:19 - 2016-08-06 11:31 - 002023424 _____ (Microsoft Corporation) C:\Windows\system32\WsmSvc.dll
2017-09-22 00:19 - 2016-08-06 11:15 - 001178112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmSvc.dll
2017-09-22 00:19 - 2016-06-14 13:16 - 004121600 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2017-09-22 00:19 - 2016-06-14 13:16 - 001202176 _____ (Microsoft Corporation) C:\Windows\system32\drmv2clt.dll
2017-09-22 00:19 - 2016-06-14 13:16 - 000842240 _____ (Microsoft Corporation) C:\Windows\system32\blackbox.dll
2017-09-22 00:19 - 2016-06-14 11:21 - 003209216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll
2017-09-22 00:19 - 2016-06-14 11:21 - 000988160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drmv2clt.dll
2017-09-22 00:19 - 2016-06-14 11:21 - 000744960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\blackbox.dll
2017-09-22 00:18 - 2017-08-19 11:28 - 000197120 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll
2017-09-22 00:18 - 2017-08-19 11:10 - 000180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll
2017-09-22 00:18 - 2017-08-16 11:29 - 000806912 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll
2017-09-22 00:18 - 2017-08-16 11:10 - 000629760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll
2017-09-22 00:18 - 2017-08-15 11:29 - 014182400 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2017-09-22 00:18 - 2017-08-15 11:29 - 001867264 _____ (Microsoft Corporation) C:\Windows\system32\ExplorerFrame.dll
2017-09-22 00:18 - 2017-08-15 11:10 - 012880896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2017-09-22 00:18 - 2017-08-15 11:10 - 001499648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ExplorerFrame.dll
2017-09-22 00:18 - 2017-08-14 13:35 - 003203584 _____ (Microsoft Corporation) C:\Windows\system32\mmcndmgr.dll
2017-09-22 00:18 - 2017-08-14 13:35 - 002150912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mmcndmgr.dll
2017-09-22 00:18 - 2017-08-14 13:35 - 000355328 _____ (Microsoft Corporation) C:\Windows\system32\mmcbase.dll
2017-09-22 00:18 - 2017-08-14 13:35 - 000303104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mmcbase.dll
2017-09-22 00:18 - 2017-08-14 13:35 - 000172544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cic.dll
2017-09-22 00:18 - 2017-08-14 13:35 - 000131072 _____ (Microsoft Corporation) C:\Windows\system32\mmcshext.dll
2017-09-22 00:18 - 2017-08-14 13:35 - 000128512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mmcshext.dll
2017-09-22 00:18 - 2017-08-14 13:34 - 000211968 _____ (Microsoft Corporation) C:\Windows\system32\cic.dll
2017-09-22 00:18 - 2017-08-13 17:37 - 002144256 _____ (Microsoft Corporation) C:\Windows\system32\mmc.exe
2017-09-22 00:18 - 2017-08-13 17:30 - 001401344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mmc.exe
2017-09-22 00:18 - 2017-08-13 12:18 - 000152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2017-09-22 00:18 - 2017-08-11 02:42 - 000631176 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2017-09-22 00:18 - 2017-08-11 02:38 - 000706792 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2017-09-22 00:18 - 2017-08-11 02:38 - 000154856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2017-09-22 00:18 - 2017-08-11 02:38 - 000095464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2017-09-22 00:18 - 2017-08-11 02:35 - 001212928 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2017-09-22 00:18 - 2017-08-11 02:35 - 000757248 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll
2017-09-22 00:18 - 2017-08-11 02:35 - 000512000 _____ (Microsoft Corporation) C:\Windows\system32\rpcss.dll
2017-09-22 00:18 - 2017-08-11 02:35 - 000503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2017-09-22 00:18 - 2017-08-11 02:35 - 000362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2017-09-22 00:18 - 2017-08-11 02:35 - 000346112 _____ (Microsoft Corporation) C:\Windows\system32\ntprint.dll
2017-09-22 00:18 - 2017-08-11 02:35 - 000345600 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2017-09-22 00:18 - 2017-08-11 02:35 - 000313856 _____ (Microsoft Corporation) C:\Windows\system32\Wldap32.dll
2017-09-22 00:18 - 2017-08-11 02:35 - 000243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2017-09-22 00:18 - 2017-08-11 02:35 - 000215552 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2017-09-22 00:18 - 2017-08-11 02:35 - 000210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2017-09-22 00:18 - 2017-08-11 02:35 - 000190464 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll
2017-09-22 00:18 - 2017-08-11 02:35 - 000135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2017-09-22 00:18 - 2017-08-11 02:35 - 000086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2017-09-22 00:18 - 2017-08-11 02:35 - 000063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2017-09-22 00:18 - 2017-08-11 02:35 - 000050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2017-09-22 00:18 - 2017-08-11 02:35 - 000028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2017-09-22 00:18 - 2017-08-11 02:35 - 000028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2017-09-22 00:18 - 2017-08-11 02:35 - 000026112 _____ (Microsoft Corporation) C:\Windows\system32\oleres.dll
2017-09-22 00:18 - 2017-08-11 02:35 - 000026112 _____ (Microsoft Corporation) C:\Windows\system32\nsisvc.dll
2017-09-22 00:18 - 2017-08-11 02:35 - 000025600 _____ (Microsoft Corporation) C:\Windows\system32\winnsi.dll
2017-09-22 00:18 - 2017-08-11 02:35 - 000016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2017-09-22 00:18 - 2017-08-11 02:35 - 000013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2017-09-22 00:18 - 2017-08-11 02:35 - 000013312 _____ (Microsoft Corporation) C:\Windows\system32\nsi.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 001460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 001163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 000971776 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 000880640 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 000731648 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 000690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 000463872 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 000419840 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 000316928 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 000312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 000166400 _____ (Microsoft Corporation) C:\Windows\system32\inetpp.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 000146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 000123904 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 000060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 000059904 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 000044032 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 000043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 000034816 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 000022528 _____ (Microsoft Corporation) C:\Windows\system32\inetppui.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 000022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 000008704 _____ (Microsoft Corporation) C:\Windows\system32\comcat.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 000006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 000006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 000005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 000004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 000004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:34 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:24 - 004001000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2017-09-22 00:18 - 2017-08-11 02:24 - 003945704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2017-09-22 00:18 - 2017-08-11 02:21 - 001314112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2017-09-22 00:18 - 2017-08-11 02:20 - 000061952 _____ (Microsoft Corporation) C:\Windows\system32\ntprint.exe
2017-09-22 00:18 - 2017-08-11 02:20 - 000048640 _____ (Microsoft Corporation) C:\Windows\system32\wpnpinst.exe
2017-09-22 00:18 - 2017-08-11 02:19 - 001417728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 001114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000666112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000644096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000554496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000497664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000299008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntprint.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000275456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000271360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Wldap32.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000261120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000254464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcrypt.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000026112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleres.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000016384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winnsi.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000008704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nsi.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:19 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 02:12 - 000025088 _____ (Microsoft Corporation) C:\Windows\system32\netbtugc.exe
2017-09-22 00:18 - 2017-08-11 02:09 - 000061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntprint.exe
2017-09-22 00:18 - 2017-08-11 02:07 - 000148480 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2017-09-22 00:18 - 2017-08-11 02:07 - 000062464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2017-09-22 00:18 - 2017-08-11 02:07 - 000017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2017-09-22 00:18 - 2017-08-11 02:06 - 000064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2017-09-22 00:18 - 2017-08-11 02:03 - 000338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2017-09-22 00:18 - 2017-08-11 02:03 - 000026624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netbtugc.exe
2017-09-22 00:18 - 2017-08-11 02:02 - 000296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2017-09-22 00:18 - 2017-08-11 02:01 - 000007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comcat.dll
2017-09-22 00:18 - 2017-08-11 02:00 - 000262656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netbt.sys
2017-09-22 00:18 - 2017-08-11 02:00 - 000159744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2017-09-22 00:18 - 2017-08-11 02:00 - 000050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2017-09-22 00:18 - 2017-08-11 01:59 - 000460800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys
2017-09-22 00:18 - 2017-08-11 01:59 - 000405504 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys
2017-09-22 00:18 - 2017-08-11 01:59 - 000291328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2017-09-22 00:18 - 2017-08-11 01:59 - 000168448 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys
2017-09-22 00:18 - 2017-08-11 01:59 - 000129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2017-09-22 00:18 - 2017-08-11 01:58 - 000112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2017-09-22 00:18 - 2017-08-11 01:58 - 000030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2017-09-22 00:18 - 2017-08-11 01:58 - 000026112 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\nsiproxy.sys
2017-09-22 00:18 - 2017-08-11 01:56 - 000025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2017-09-22 00:18 - 2017-08-11 01:56 - 000014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2017-09-22 00:18 - 2017-08-11 01:56 - 000007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2017-09-22 00:18 - 2017-08-11 01:56 - 000002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2017-09-22 00:18 - 2017-08-11 01:55 - 000036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
2017-09-22 00:18 - 2017-08-11 01:55 - 000006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 01:55 - 000004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 01:55 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2017-09-22 00:18 - 2017-08-11 01:55 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2017-09-22 00:18 - 2017-07-29 10:56 - 000117248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys
2017-09-22 00:18 - 2017-07-21 10:26 - 000409600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msexch40.dll
2017-09-22 00:18 - 2017-07-21 10:26 - 000282624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstext40.dll
2017-09-22 00:18 - 2017-07-14 11:29 - 000778240 _____ (Microsoft Corporation) C:\Windows\system32\mssvp.dll
2017-09-22 00:18 - 2017-07-14 11:29 - 000491520 _____ (Microsoft Corporation) C:\Windows\system32\mssph.dll
2017-09-22 00:18 - 2017-07-14 11:29 - 000486400 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
2017-09-22 00:18 - 2017-07-14 11:29 - 000288256 _____ (Microsoft Corporation) C:\Windows\system32\mssphtb.dll
2017-09-22 00:18 - 2017-07-14 11:29 - 000115200 _____ (Microsoft Corporation) C:\Windows\system32\mssitlb.dll
2017-09-22 00:18 - 2017-07-14 11:29 - 000099840 _____ (Microsoft Corporation) C:\Windows\system32\mssprxy.dll
2017-09-22 00:18 - 2017-07-14 11:29 - 000075264 _____ (Microsoft Corporation) C:\Windows\system32\msscntrs.dll
2017-09-22 00:18 - 2017-07-14 11:29 - 000034304 _____ (Microsoft Corporation) C:\Windows\system32\werdiagcontroller.dll
2017-09-22 00:18 - 2017-07-14 11:29 - 000014336 _____ (Microsoft Corporation) C:\Windows\system32\msshooks.dll
2017-09-22 00:18 - 2017-07-14 11:12 - 000591872 _____ (Microsoft Corporation) C:\Windows\system32\SearchIndexer.exe
2017-09-22 00:18 - 2017-07-14 11:12 - 000249856 _____ (Microsoft Corporation) C:\Windows\system32\SearchProtocolHost.exe
2017-09-22 00:18 - 2017-07-14 11:11 - 000113664 _____ (Microsoft Corporation) C:\Windows\system32\SearchFilterHost.exe
2017-09-22 00:18 - 2017-07-14 11:10 - 000666624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssvp.dll
2017-09-22 00:18 - 2017-07-14 11:10 - 000382976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll
2017-09-22 00:18 - 2017-07-14 11:10 - 000337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssph.dll
2017-09-22 00:18 - 2017-07-14 11:10 - 000197120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssphtb.dll
2017-09-22 00:18 - 2017-07-14 11:10 - 000104448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssitlb.dll
2017-09-22 00:18 - 2017-07-14 11:10 - 000059392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msscntrs.dll
2017-09-22 00:18 - 2017-07-14 11:10 - 000034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssprxy.dll
2017-09-22 00:18 - 2017-07-14 11:00 - 000427520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchIndexer.exe
2017-09-22 00:18 - 2017-07-14 11:00 - 000164352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchProtocolHost.exe
2017-09-22 00:18 - 2017-07-14 10:59 - 000086528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchFilterHost.exe
2017-09-22 00:18 - 2017-07-14 10:59 - 000009728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msshooks.dll
2017-09-22 00:18 - 2017-07-14 10:57 - 000050688 _____ (Microsoft Corporation) C:\Windows\system32\wermgr.exe
2017-09-22 00:18 - 2017-07-14 10:50 - 000054272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wermgr.exe
2017-09-22 00:18 - 2017-07-14 10:50 - 000028672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\werdiagcontroller.dll
2017-09-22 00:18 - 2017-07-08 11:34 - 000370920 _____ (Microsoft Corporation) C:\Windows\system32\clfs.sys
2017-09-22 00:18 - 2017-07-07 11:33 - 000363752 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\volmgrx.sys
2017-09-22 00:18 - 2017-07-07 11:29 - 000149504 _____ (Microsoft Corporation) C:\Windows\system32\t2embed.dll
2017-09-22 00:18 - 2017-07-07 11:11 - 000109568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\t2embed.dll
2017-09-22 00:18 - 2017-07-06 00:56 - 000119296 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bthpan.sys
2017-09-22 00:18 - 2017-07-01 09:05 - 000866816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswdat10.dll
2017-09-22 00:18 - 2017-07-01 09:05 - 000641536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswstr10.dll
2017-09-22 00:18 - 2017-07-01 09:05 - 000144896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msjint40.dll
2017-09-22 00:18 - 2017-07-01 09:05 - 000083968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msjter40.dll
2017-09-22 00:18 - 2017-06-15 16:23 - 000753664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys
2017-09-22 00:18 - 2017-06-12 18:49 - 001363456 _____ (Microsoft Corporation) C:\Windows\system32\wdc.dll
2017-09-22 00:18 - 2017-06-12 18:49 - 000594432 _____ (Microsoft Corporation) C:\Windows\system32\wvc.dll
2017-09-22 00:18 - 2017-06-12 18:49 - 000475136 _____ (Microsoft Corporation) C:\Windows\system32\sysmon.ocx
2017-09-22 00:18 - 2017-06-12 18:49 - 000058880 _____ (Microsoft Corporation) C:\Windows\system32\pdhui.dll
2017-09-22 00:18 - 2017-06-12 18:29 - 001227264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdc.dll
2017-09-22 00:18 - 2017-06-12 18:29 - 000444928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wvc.dll
2017-09-22 00:18 - 2017-06-12 18:29 - 000390144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sysmon.ocx
2017-09-22 00:18 - 2017-06-12 18:28 - 000047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pdhui.dll
2017-09-22 00:18 - 2017-06-12 18:14 - 000379392 _____ (Microsoft Corporation) C:\Windows\system32\msinfo32.exe
2017-09-22 00:18 - 2017-06-12 18:14 - 000172544 _____ (Microsoft Corporation) C:\Windows\system32\perfmon.exe
2017-09-22 00:18 - 2017-06-12 18:14 - 000103936 _____ (Microsoft Corporation) C:\Windows\system32\resmon.exe
2017-09-22 00:18 - 2017-06-12 18:06 - 000303616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msinfo32.exe
2017-09-22 00:18 - 2017-06-12 18:06 - 000157184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\perfmon.exe
2017-09-22 00:18 - 2017-06-12 18:06 - 000103424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\resmon.exe
2017-09-22 00:18 - 2017-06-02 04:10 - 000733696 _____ (Microsoft Corporation) C:\Windows\HelpPane.exe
2017-09-22 00:18 - 2017-05-30 00:56 - 000377576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys
2017-09-22 00:18 - 2017-05-30 00:56 - 000287976 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS
2017-09-22 00:18 - 2017-05-21 00:24 - 000002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2017-09-22 00:18 - 2017-05-21 00:06 - 000002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2017-09-22 00:18 - 2017-05-16 11:35 - 000986856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2017-09-22 00:18 - 2017-05-16 11:35 - 000265448 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys
2017-09-22 00:18 - 2017-05-16 11:30 - 000144384 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll
2017-09-22 00:18 - 2017-05-12 14:26 - 000382696 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2017-09-22 00:18 - 2017-05-12 14:22 - 000405504 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2017-09-22 00:18 - 2017-05-12 14:22 - 000100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2017-09-22 00:18 - 2017-05-12 14:22 - 000046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2017-09-22 00:18 - 2017-05-12 14:22 - 000041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2017-09-22 00:18 - 2017-05-12 14:22 - 000014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2017-09-22 00:18 - 2017-05-12 14:07 - 000308456 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2017-09-22 00:18 - 2017-05-12 14:03 - 000313344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2017-09-22 00:18 - 2017-05-12 14:03 - 000070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2017-09-22 00:18 - 2017-05-12 14:03 - 000025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
2017-09-22 00:18 - 2017-05-12 14:03 - 000010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
2017-09-22 00:18 - 2017-05-12 13:43 - 000034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2017-09-22 00:18 - 2017-05-10 11:33 - 000091368 _____ (Microsoft Corporation) C:\Windows\system32\MigAutoPlay.exe
2017-09-22 00:18 - 2017-05-10 11:16 - 000091368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MigAutoPlay.exe
2017-09-22 00:18 - 2017-05-10 11:00 - 000030208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2017-09-22 00:18 - 2017-05-07 11:33 - 000094440 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mountmgr.sys
2017-09-22 00:18 - 2017-05-07 11:29 - 000011264 _____ (Microsoft Corporation) C:\Windows\system32\msmmsp.dll
2017-09-22 00:18 - 2017-04-21 11:34 - 001133568 _____ (Microsoft Corporation) C:\Windows\system32\cdosys.dll
2017-09-22 00:18 - 2017-04-21 11:15 - 000805376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2017-09-22 00:18 - 2017-04-17 11:37 - 000876544 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll
2017-09-22 00:18 - 2017-04-17 11:12 - 000581632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll
2017-09-22 00:18 - 2017-04-12 11:32 - 000229376 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2017-09-22 00:18 - 2017-04-12 11:32 - 000190976 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2017-09-22 00:18 - 2017-04-12 11:32 - 000141824 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2017-09-22 00:18 - 2017-04-12 11:26 - 000179200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2017-09-22 00:18 - 2017-04-12 11:25 - 001176064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2017-09-22 00:18 - 2017-04-12 11:25 - 000145920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2017-09-22 00:18 - 2017-04-12 11:25 - 000106496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2017-09-22 00:18 - 2017-04-04 10:53 - 000496128 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2017-09-22 00:18 - 2017-03-30 11:03 - 000046080 _____ (Microsoft Corporation) C:\Windows\system32\rundll32.exe
2017-09-22 00:18 - 2017-03-30 10:58 - 000045056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
2017-09-22 00:18 - 2017-03-10 12:32 - 001389056 _____ (Microsoft Corporation) C:\Windows\system32\pla.dll
2017-09-22 00:18 - 2017-03-10 12:32 - 000300544 _____ (Microsoft Corporation) C:\Windows\system32\pdh.dll
2017-09-22 00:18 - 2017-03-10 12:20 - 001508352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pla.dll
2017-09-22 00:18 - 2017-03-10 12:20 - 000237056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pdh.dll
2017-09-22 00:18 - 2017-03-10 11:57 - 000009216 _____ (Microsoft Corporation) C:\Windows\system32\plasrv.exe
2017-09-22 00:18 - 2017-03-10 11:55 - 000205312 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fastfat.sys
2017-09-22 00:18 - 2017-03-10 11:55 - 000195584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\exfat.sys
2017-09-22 00:18 - 2017-03-07 12:30 - 000085504 _____ (Microsoft Corporation) C:\Windows\system32\asycfilt.dll
2017-09-22 00:18 - 2017-03-07 12:17 - 000067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\asycfilt.dll
2017-09-22 00:18 - 2017-03-03 21:27 - 000093696 _____ (Microsoft Corporation) C:\Windows\system32\mfmjpegdec.dll
2017-09-22 00:18 - 2017-03-03 21:14 - 001329664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quartz.dll
2017-09-22 00:18 - 2017-03-03 21:14 - 000077312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfmjpegdec.dll
2017-09-22 00:18 - 2017-02-09 12:32 - 000769536 _____ (Microsoft Corporation) C:\Windows\system32\samsrv.dll
2017-09-22 00:18 - 2017-02-09 12:32 - 000106496 _____ (Microsoft Corporation) C:\Windows\system32\samlib.dll
2017-09-22 00:18 - 2017-02-09 12:32 - 000040960 _____ (Microsoft Corporation) C:\Windows\system32\WcsPlugInService.dll
2017-09-22 00:18 - 2017-02-09 12:31 - 000625664 _____ (Microsoft Corporation) C:\Windows\system32\mscms.dll
2017-09-22 00:18 - 2017-02-09 12:31 - 000250880 _____ (Microsoft Corporation) C:\Windows\system32\icm32.dll
2017-09-22 00:18 - 2017-02-09 12:14 - 000481792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscms.dll
2017-09-22 00:18 - 2017-02-09 12:14 - 000215040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icm32.dll
2017-09-22 00:18 - 2017-02-09 12:14 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\samlib.dll
2017-09-22 00:18 - 2017-02-09 11:51 - 000032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WcsPlugInService.dll
2017-09-22 00:18 - 2017-01-13 14:00 - 000976896 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll
2017-09-22 00:18 - 2017-01-13 14:00 - 000084480 _____ (Microsoft Corporation) C:\Windows\system32\INETRES.dll
2017-09-22 00:18 - 2017-01-13 13:45 - 000741888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll
2017-09-22 00:18 - 2017-01-13 13:45 - 000084480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\INETRES.dll
2017-09-22 00:18 - 2017-01-11 14:01 - 000002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2017-09-22 00:18 - 2017-01-11 13:43 - 000002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2017-09-22 00:18 - 2016-11-21 14:12 - 000109568 _____ (Microsoft Corporation) C:\Windows\system32\hlink.dll
2017-09-22 00:18 - 2016-11-20 12:19 - 000084992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\hlink.dll
2017-09-22 00:18 - 2016-11-20 10:07 - 000467392 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2017-09-22 00:18 - 2016-11-10 12:32 - 001009152 _____ (Microsoft Corporation) C:\Windows\system32\user32.dll
2017-09-22 00:18 - 2016-11-10 12:19 - 000833024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user32.dll
2017-09-22 00:18 - 2016-11-09 12:41 - 000114408 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2017-09-22 00:18 - 2016-11-09 12:33 - 001941504 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2017-09-22 00:18 - 2016-11-09 12:33 - 000504320 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll
2017-09-22 00:18 - 2016-11-09 12:33 - 000070144 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll
2017-09-22 00:18 - 2016-11-09 12:33 - 000025088 _____ (Microsoft Corporation) C:\Windows\system32\msimsg.dll
2017-09-22 00:18 - 2016-11-09 12:17 - 001806848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2017-09-22 00:18 - 2016-11-09 12:17 - 000337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll
2017-09-22 00:18 - 2016-11-09 12:17 - 000025088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msimsg.dll
2017-09-22 00:18 - 2016-11-09 12:02 - 000128512 _____ (Microsoft Corporation) C:\Windows\system32\msiexec.exe
2017-09-22 00:18 - 2016-11-09 11:55 - 000073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msiexec.exe
2017-09-22 00:18 - 2016-10-11 11:32 - 000069120 _____ (Microsoft Corporation) C:\Windows\system32\nlsbres.dll
2017-09-22 00:18 - 2016-10-11 11:31 - 001148416 _____ (Microsoft Corporation) C:\Windows\system32\IMJP10.IME
2017-09-22 00:18 - 2016-10-11 11:31 - 001068544 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll
2017-09-22 00:18 - 2016-10-11 11:31 - 000878080 _____ (Microsoft Corporation) C:\Windows\system32\IMJP10K.DLL
2017-09-22 00:18 - 2016-10-11 11:31 - 000457216 _____ (Microsoft Corporation) C:\Windows\system32\imkr80.ime
2017-09-22 00:18 - 2016-10-11 11:31 - 000246784 _____ (Microsoft Corporation) C:\Windows\system32\input.dll
2017-09-22 00:18 - 2016-10-11 11:31 - 000176128 _____ (Microsoft Corporation) C:\Windows\system32\tintlgnt.ime
2017-09-22 00:18 - 2016-10-11 11:31 - 000175104 _____ (Microsoft Corporation) C:\Windows\system32\quick.ime
2017-09-22 00:18 - 2016-10-11 11:31 - 000175104 _____ (Microsoft Corporation) C:\Windows\system32\qintlgnt.ime
2017-09-22 00:18 - 2016-10-11 11:31 - 000175104 _____ (Microsoft Corporation) C:\Windows\system32\phon.ime
2017-09-22 00:18 - 2016-10-11 11:31 - 000175104 _____ (Microsoft Corporation) C:\Windows\system32\cintlgnt.ime
2017-09-22 00:18 - 2016-10-11 11:31 - 000175104 _____ (Microsoft Corporation) C:\Windows\system32\chajei.ime
2017-09-22 00:18 - 2016-10-11 11:31 - 000132608 _____ (Microsoft Corporation) C:\Windows\system32\pintlgnt.ime
2017-09-22 00:18 - 2016-10-11 11:18 - 001027584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IMJP10.IME
2017-09-22 00:18 - 2016-10-11 11:18 - 000829952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msctf.dll
2017-09-22 00:18 - 2016-10-11 11:18 - 000701440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IMJP10K.DLL
2017-09-22 00:18 - 2016-10-11 11:18 - 000430080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imkr80.ime
2017-09-22 00:18 - 2016-10-11 11:18 - 000202240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\input.dll
2017-09-22 00:18 - 2016-10-11 11:18 - 000126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tintlgnt.ime
2017-09-22 00:18 - 2016-10-11 11:18 - 000125952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quick.ime
2017-09-22 00:18 - 2016-10-11 11:18 - 000125952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qintlgnt.ime
2017-09-22 00:18 - 2016-10-11 11:18 - 000125952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\phon.ime
2017-09-22 00:18 - 2016-10-11 11:18 - 000125952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cintlgnt.ime
2017-09-22 00:18 - 2016-10-11 11:18 - 000125952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\chajei.ime
2017-09-22 00:18 - 2016-10-11 11:18 - 000090112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pintlgnt.ime
2017-09-22 00:18 - 2016-10-11 11:18 - 000069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlsbres.dll
2017-09-22 00:18 - 2016-10-11 10:55 - 000346112 _____ (Microsoft Corporation) C:\Windows\system32\bcdedit.exe
2017-09-22 00:18 - 2016-10-11 09:33 - 000187392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIAnimation.dll
2017-09-22 00:18 - 2016-10-11 09:18 - 000419648 _____ C:\Windows\SysWOW64\locale.nls
2017-09-22 00:18 - 2016-10-11 09:17 - 000419648 _____ C:\Windows\system32\locale.nls
2017-09-22 00:18 - 2016-10-11 09:06 - 000221184 _____ (Microsoft Corporation) C:\Windows\system32\UIAnimation.dll
2017-09-22 00:18 - 2016-10-08 09:06 - 000633296 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
2017-09-22 00:18 - 2016-10-05 10:54 - 000090112 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bowser.sys
2017-09-22 00:18 - 2016-09-12 17:08 - 000107520 _____ (Microsoft Corporation) C:\Windows\system32\adsmsext.dll
2017-09-22 00:18 - 2016-09-12 16:49 - 000076800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adsmsext.dll
2017-09-22 00:18 - 2016-09-08 16:34 - 000263680 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll
2017-09-22 00:18 - 2016-09-08 16:34 - 000208896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebClnt.dll
2017-09-22 00:18 - 2016-09-08 16:34 - 000108544 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll
2017-09-22 00:18 - 2016-09-08 16:34 - 000087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\davclnt.dll
2017-09-22 00:18 - 2016-09-08 10:55 - 000142336 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2017-09-22 00:18 - 2016-09-08 10:55 - 000106496 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dfsc.sys
2017-09-22 00:18 - 2016-08-12 13:02 - 012574720 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2017-09-22 00:18 - 2016-08-12 13:02 - 000009728 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll
2017-09-22 00:18 - 2016-08-12 13:02 - 000005120 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx
2017-09-22 00:18 - 2016-08-12 13:02 - 000005120 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll
2017-09-22 00:18 - 2016-08-12 12:47 - 012574208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL
2017-09-22 00:18 - 2016-08-12 12:31 - 000008192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\spwmp.dll
2017-09-22 00:18 - 2016-08-12 12:31 - 000004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdxm.ocx
2017-09-22 00:18 - 2016-08-12 12:31 - 000004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxmasf.dll
2017-09-22 00:18 - 2016-08-12 12:26 - 000461312 _____ (Microsoft Corporation) C:\Windows\system32\scavengeui.dll
2017-09-22 00:18 - 2016-08-06 11:31 - 000347136 _____ (Microsoft Corporation) C:\Windows\system32\WSManMigrationPlugin.dll
2017-09-22 00:18 - 2016-08-06 11:31 - 000310784 _____ (Microsoft Corporation) C:\Windows\system32\WsmWmiPl.dll
2017-09-22 00:18 - 2016-08-06 11:31 - 000182272 _____ (Microsoft Corporation) C:\Windows\system32\WsmAuto.dll
2017-09-22 00:18 - 2016-08-06 11:31 - 000054272 _____ (Microsoft Corporation) C:\Windows\system32\WsmRes.dll
2017-09-22 00:18 - 2016-08-06 11:31 - 000012800 _____ (Microsoft Corporation) C:\Windows\system32\wsmplpxy.dll
2017-09-22 00:18 - 2016-08-06 11:15 - 000249344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManMigrationPlugin.dll
2017-09-22 00:18 - 2016-08-06 11:15 - 000214016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmWmiPl.dll
2017-09-22 00:18 - 2016-08-06 11:15 - 000146944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmAuto.dll
2017-09-22 00:18 - 2016-08-06 11:15 - 000054272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmRes.dll
2017-09-22 00:18 - 2016-08-06 11:01 - 000266752 _____ (Microsoft Corporation) C:\Windows\system32\WSManHTTPConfig.exe
2017-09-22 00:18 - 2016-08-06 11:01 - 000013824 _____ (Microsoft Corporation) C:\Windows\system32\wsmprovhost.exe
2017-09-22 00:18 - 2016-08-06 10:53 - 000199168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManHTTPConfig.exe
2017-09-22 00:18 - 2016-08-06 10:53 - 000012288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wsmprovhost.exe
2017-09-22 00:18 - 2016-08-06 10:53 - 000010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wsmplpxy.dll
2017-09-22 00:18 - 2016-06-14 13:16 - 001068544 _____ (Microsoft Corporation) C:\Windows\system32\cryptui.dll
2017-09-22 00:18 - 2016-06-14 13:16 - 000782848 _____ (Microsoft Corporation) C:\Windows\system32\wmdrmsdk.dll
2017-09-22 00:18 - 2016-06-14 13:16 - 000680448 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
2017-09-22 00:18 - 2016-06-14 13:16 - 000641024 _____ (Microsoft Corporation) C:\Windows\system32\msscp.dll
2017-09-22 00:18 - 2016-06-14 13:16 - 000632320 _____ (Microsoft Corporation) C:\Windows\system32\evr.dll
2017-09-22 00:18 - 2016-06-14 13:16 - 000499712 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll
2017-09-22 00:18 - 2016-06-14 13:16 - 000497664 _____ (Microsoft Corporation) C:\Windows\system32\drmmgrtn.dll
2017-09-22 00:18 - 2016-06-14 13:16 - 000440320 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll
2017-09-22 00:18 - 2016-06-14 13:16 - 000433152 _____ (Microsoft Corporation) C:\Windows\system32\mfplat.dll
2017-09-22 00:18 - 2016-06-14 13:16 - 000371712 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll
2017-09-22 00:18 - 2016-06-14 13:16 - 000325632 _____ (Microsoft Corporation) C:\Windows\system32\msnetobj.dll
2017-09-22 00:18 - 2016-06-14 13:16 - 000295936 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll
2017-09-22 00:18 - 2016-06-14 13:16 - 000284672 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll
2017-09-22 00:18 - 2016-06-14 13:16 - 000206848 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll
2017-09-22 00:18 - 2016-06-14 13:16 - 000187904 _____ (Microsoft Corporation) C:\Windows\system32\pcasvc.dll
2017-09-22 00:18 - 2016-06-14 13:16 - 000081920 _____ (Microsoft Corporation) C:\Windows\system32\cryptsp.dll
2017-09-22 00:18 - 2016-06-14 13:16 - 000037376 _____ (Microsoft Corporation) C:\Windows\system32\pcadm.dll
2017-09-22 00:18 - 2016-06-14 13:16 - 000008704 _____ (Microsoft Corporation) C:\Windows\system32\pcaevts.dll
2017-09-22 00:18 - 2016-06-14 13:16 - 000002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll
2017-09-22 00:18 - 2016-06-14 13:11 - 000663552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\PEAuth.sys
2017-09-22 00:18 - 2016-06-14 11:21 - 001005056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptui.dll
2017-09-22 00:18 - 2016-06-14 11:21 - 000617984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmdrmsdk.dll
2017-09-22 00:18 - 2016-06-14 11:21 - 000519680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll
2017-09-22 00:18 - 2016-06-14 11:21 - 000504320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msscp.dll
2017-09-22 00:18 - 2016-06-14 11:21 - 000489984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\evr.dll
2017-09-22 00:18 - 2016-06-14 11:21 - 000442368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AUDIOKSE.dll
2017-09-22 00:18 - 2016-06-14 11:21 - 000406016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drmmgrtn.dll
2017-09-22 00:18 - 2016-06-14 11:21 - 000374784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll
2017-09-22 00:18 - 2016-06-14 11:21 - 000354816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfplat.dll
2017-09-22 00:18 - 2016-06-14 11:21 - 000265216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msnetobj.dll
2017-09-22 00:18 - 2016-06-14 11:21 - 000195072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll
2017-09-22 00:18 - 2016-06-14 11:21 - 000103424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfps.dll
2017-09-22 00:18 - 2016-06-14 11:21 - 000080896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsp.dll
2017-09-22 00:18 - 2016-06-14 11:21 - 000002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mferror.dll
2017-09-22 00:18 - 2016-06-14 11:15 - 000125952 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe
2017-09-22 00:18 - 2016-06-14 11:15 - 000055808 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe
2017-09-22 00:18 - 2016-06-14 11:15 - 000024576 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe
2017-09-22 00:18 - 2016-06-14 11:05 - 000050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rrinstaller.exe
2017-09-22 00:18 - 2016-06-14 11:05 - 000023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfpmp.exe
2017-09-22 00:18 - 2016-06-14 11:00 - 000011264 _____ (Microsoft Corporation) C:\Windows\system32\pcawrk.exe
2017-09-22 00:18 - 2016-06-14 11:00 - 000009728 _____ (Microsoft Corporation) C:\Windows\system32\pcalua.exe
2017-09-22 00:18 - 2016-05-12 09:05 - 000297984 _____ (Microsoft Corporation) C:\Windows\system32\bcryptprimitives.dll
2017-09-22 00:18 - 2016-05-12 09:04 - 000249352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcryptprimitives.dll
2017-09-22 00:16 - 2016-08-29 11:04 - 003229696 _____ (Microsoft Corporation) C:\Windows\explorer.exe
2017-09-22 00:16 - 2016-08-29 10:55 - 002972672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe
2017-09-22 00:16 - 2016-08-16 16:40 - 000343552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
2017-09-22 00:16 - 2016-08-16 16:40 - 000327168 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys
2017-09-22 00:16 - 2016-08-16 16:40 - 000099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys
2017-09-22 00:16 - 2016-08-16 16:40 - 000056320 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
2017-09-22 00:16 - 2016-08-16 16:40 - 000030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys
2017-09-22 00:16 - 2016-08-16 16:40 - 000025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys
2017-09-22 00:16 - 2016-08-16 16:40 - 000007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys
2017-09-22 00:16 - 2016-07-22 10:58 - 000142336 _____ (Microsoft Corporation) C:\Windows\system32\poqexec.exe
2017-09-22 00:16 - 2016-07-22 10:51 - 000123904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\poqexec.exe
2017-09-22 00:16 - 2016-05-12 13:15 - 000105472 _____ (Microsoft Corporation) C:\Windows\system32\winipsec.dll
2017-09-22 00:16 - 2016-05-12 13:14 - 000794624 _____ (Microsoft Corporation) C:\Windows\system32\gpsvc.dll
2017-09-22 00:16 - 2016-05-12 13:14 - 000502272 _____ (Microsoft Corporation) C:\Windows\system32\IPSECSVC.DLL
2017-09-22 00:16 - 2016-05-12 13:14 - 000373760 _____ (Microsoft Corporation) C:\Windows\system32\polstore.dll
2017-09-22 00:16 - 2016-05-12 13:14 - 000096256 _____ (Microsoft Corporation) C:\Windows\system32\gpapi.dll
2017-09-22 00:16 - 2016-05-12 13:14 - 000075776 _____ (Microsoft Corporation) C:\Windows\system32\FwRemoteSvr.dll
2017-09-22 00:16 - 2016-05-12 11:18 - 000274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\polstore.dll
2017-09-22 00:16 - 2016-05-12 11:18 - 000079360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gpapi.dll
2017-09-22 00:16 - 2016-05-12 11:18 - 000070144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winipsec.dll
2017-09-22 00:16 - 2016-05-12 11:18 - 000044032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FwRemoteSvr.dll
2017-09-22 00:16 - 2016-05-11 13:02 - 000444928 _____ (Microsoft Corporation) C:\Windows\system32\winhttp.dll
2017-09-22 00:16 - 2016-05-11 13:02 - 000327168 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll
2017-09-22 00:16 - 2016-05-11 13:02 - 000296448 _____ (Microsoft Corporation) C:\Windows\system32\ws2_32.dll
2017-09-22 00:16 - 2016-05-11 11:19 - 000351744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winhttp.dll
2017-09-22 00:16 - 2016-05-11 11:19 - 000231424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswsock.dll
2017-09-22 00:16 - 2016-05-11 11:19 - 000206336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ws2_32.dll
2017-09-22 00:16 - 2016-03-09 15:00 - 000396800 _____ (Microsoft Corporation) C:\Windows\system32\webio.dll
2017-09-22 00:16 - 2016-03-09 14:40 - 000316416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webio.dll
2017-09-21 22:44 - 2010-11-20 23:23 - 000345088 _____ (Microsoft Corporation) C:\Windows\system32\sethc.exe
2017-09-21 22:17 - 2017-09-21 22:17 - 000002259 _____ C:\Users\Joey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chromium.lnk
2017-09-21 22:17 - 2017-09-21 22:17 - 000002251 _____ C:\Users\Joey\Desktop\Chromium.lnk
2017-09-21 22:16 - 2017-09-22 23:52 - 000000000 ____D C:\Users\Joey\AppData\Roaming\62F94F4F-EC86-5AA2-0F38-3C59CE9DC274
2017-09-21 18:59 - 2017-09-23 18:25 - 000000000 ____D C:\ProgramData\Avg
2017-09-21 18:59 - 2017-09-22 23:49 - 000000000 ____D C:\Users\Joey\AppData\Local\Avg
2017-09-21 18:59 - 2017-09-22 23:45 - 000000000 ____D C:\Users\Joey\AppData\Local\AvgSetupLog
2017-09-21 18:59 - 2017-09-21 18:59 - 003449304 _____ (AVG Technologies CZ, s.r.o.) C:\Users\Joey\Downloads\AVG_Protection_Free_1606.exe
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2017-09-30 17:34 - 2014-01-23 18:32 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2017-09-30 17:30 - 2015-06-20 21:18 - 000097856 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2017-09-30 17:29 - 2012-09-23 10:26 - 000000000 ____D C:\Program Files (x86)\Java
2017-09-30 17:09 - 2016-04-11 20:46 - 000000000 __HDC C:\ProgramData\~0
2017-09-30 17:09 - 2009-07-13 23:20 - 000000000 ____D C:\Windows\inf
2017-09-30 16:34 - 2015-08-01 16:16 - 000000000 ____D C:\Program Files\Dell
2017-09-30 15:04 - 2009-07-14 00:45 - 000028352 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2017-09-30 15:04 - 2009-07-14 00:45 - 000028352 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2017-09-30 15:00 - 2009-07-14 01:13 - 000797888 _____ C:\Windows\system32\PerfStringBackup.INI
2017-09-30 14:55 - 2012-05-12 03:09 - 000000000 ____D C:\Users\Default\AppData\Local\SoftThinks
2017-09-30 14:55 - 2012-05-12 03:09 - 000000000 ____D C:\Users\Default User\AppData\Local\SoftThinks
2017-09-30 14:55 - 2012-05-12 03:04 - 000000000 ____D C:\Program Files (x86)\AlienRespawn
2017-09-30 14:54 - 2014-05-11 12:22 - 746706965 _____ C:\Windows\MEMORY.DMP
2017-09-30 14:54 - 2014-05-11 12:22 - 000000000 ____D C:\Windows\Minidump
2017-09-30 14:54 - 2012-05-12 04:30 - 000000000 ____D C:\ProgramData\NVIDIA
2017-09-30 14:54 - 2009-07-14 01:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2017-09-30 14:18 - 2011-02-10 12:10 - 000790502 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2017-09-30 14:14 - 2015-01-03 11:20 - 000004476 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2017-09-30 09:07 - 2013-06-10 18:28 - 000000450 ____H C:\Windows\Tasks\Norton Security Scan for Joey.job
2017-09-30 09:07 - 2012-05-12 02:54 - 000000000 ___HD C:\Windows\system32\WLANProfiles
2017-09-28 18:49 - 2012-08-05 16:32 - 000000000 ____D C:\Users\Joey\AppData\Local\Google
2017-09-26 22:09 - 2015-06-20 21:21 - 000000000 ____D C:\Program Files (x86)\Yahoo!
2017-09-26 18:00 - 2016-04-11 21:46 - 000000000 ____D C:\Program Files (x86)\Amazon
2017-09-26 17:37 - 2012-09-18 18:50 - 000002197 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-09-26 17:37 - 2012-09-18 18:50 - 000002185 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2017-09-26 17:34 - 2012-05-16 19:15 - 000000000 ____D C:\Users\Joey
2017-09-26 16:32 - 2015-12-19 20:03 - 000000000 ____D C:\ProgramData\Malwarebytes
2017-09-23 18:35 - 2012-05-12 02:36 - 000000000 ____D C:\Users\UpdatusUser
2017-09-23 18:24 - 2012-05-18 15:12 - 000000000 ____D C:\ProgramData\PCDr
2017-09-22 19:14 - 2012-06-08 22:37 - 000004312 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2017-09-22 19:14 - 2012-05-12 02:39 - 000803328 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2017-09-22 19:14 - 2012-05-12 02:39 - 000144896 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2017-09-22 19:14 - 2012-05-12 02:39 - 000000000 ____D C:\Windows\SysWOW64\Macromed
2017-09-22 19:14 - 2012-05-12 02:39 - 000000000 ____D C:\Windows\system32\Macromed
2017-09-22 18:39 - 2012-05-19 10:05 - 000000000 ____D C:\Users\Joey\AppData\Roaming\PCDr
2017-09-22 18:20 - 2012-05-12 03:00 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Alienware
2017-09-22 05:39 - 2009-07-13 23:20 - 000000000 ____D C:\Windows\rescache
2017-09-22 04:23 - 2009-07-14 00:45 - 000387072 _____ C:\Windows\system32\FNTCACHE.DAT
2017-09-22 04:19 - 2015-01-19 11:02 - 000000000 ____D C:\Windows\system32\appraiser
2017-09-22 04:19 - 2014-05-06 07:13 - 000000000 ___SD C:\Windows\system32\CompatTel
2017-09-22 04:18 - 2009-07-14 01:32 - 000000000 ____D C:\Program Files\DVD Maker
2017-09-22 04:18 - 2009-07-13 23:20 - 000000000 ____D C:\Windows\SysWOW64\migwiz
2017-09-22 04:18 - 2009-07-13 23:20 - 000000000 ____D C:\Windows\SysWOW64\Dism
2017-09-22 04:18 - 2009-07-13 23:20 - 000000000 ____D C:\Windows\system32\migwiz
2017-09-22 04:18 - 2009-07-13 23:20 - 000000000 ____D C:\Windows\system32\Dism
2017-09-22 04:18 - 2009-07-13 23:20 - 000000000 ____D C:\Windows\PolicyDefinitions
2017-09-22 03:33 - 2013-08-18 12:00 - 000000000 ____D C:\Windows\system32\MRT
2017-09-22 03:33 - 2012-07-08 10:11 - 138202976 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2017-09-22 00:30 - 2012-05-16 19:17 - 000001044 _____ C:\Users\Joey\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2017-09-21 22:17 - 2013-03-17 17:34 - 000000000 ____D C:\Users\Joey\AppData\Local\Chromium
2017-09-21 19:51 - 2012-07-02 09:36 - 000000000 ____D C:\Users\Joey\AppData\Local\ElevatedDiagnostics
2017-09-21 19:36 - 2013-07-27 17:32 - 000000246 _____ C:\Users\Joey\AppData\Roaming\WB.CFG
2017-09-21 18:48 - 2012-09-18 18:49 - 000003330 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2017-09-21 18:48 - 2012-09-18 18:49 - 000003202 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2017-09-21 18:08 - 2015-12-19 18:55 - 000887072 _____ C:\Windows\ntbtlog.txt
 
==================== Files in the root of some directories =======
 
2013-07-27 17:32 - 2017-09-21 19:36 - 000000246 _____ () C:\Users\Joey\AppData\Roaming\WB.CFG
2013-12-30 15:49 - 2014-01-02 19:32 - 000000005 _____ () C:\Users\Joey\AppData\Roaming\WBPU-Q5-TTL.DAT
2013-06-15 19:30 - 2014-01-30 15:28 - 000000005 _____ () C:\Users\Joey\AppData\Roaming\WBPU-TTL.DAT
2013-03-17 17:27 - 2013-03-17 17:27 - 000000092 _____ () C:\Users\Joey\AppData\Local\fusioncache.dat
 
Some files in TEMP:
====================
2012-07-03 22:08 - 2012-07-03 22:08 - 003421471 _____ () C:\Users\Joey\AppData\Local\Temp\air1AE0.exe
2012-07-03 22:08 - 2012-07-03 22:08 - 000632736 _____ (Shop To Win, LLC                                            ) C:\Users\Joey\AppData\Local\Temp\air4E51.exe
2013-01-17 21:04 - 2013-01-17 21:04 - 000255072 _____ (AVG Technologies CZ, s.r.o.) C:\Users\Joey\AppData\Local\Temp\avguidx.dll
2012-09-28 18:05 - 2013-11-15 18:28 - 001542696 _____ (McAfee, Inc.) C:\Users\Joey\AppData\Local\Temp\contentDATs.exe
2012-07-08 10:06 - 2012-07-08 10:06 - 001074808 _____ () C:\Users\Joey\AppData\Local\Temp\del.dll
2017-09-26 18:38 - 2017-08-11 02:36 - 001732864 _____ (Microsoft Corporation) C:\Users\Joey\AppData\Local\Temp\dllnt_dump.dll
2012-03-02 14:38 - 2012-03-02 14:38 - 006982752 _____ (FreeDownloadManager.ORG                                     ) C:\Users\Joey\AppData\Local\Temp\fdminst.exe
2013-01-18 17:51 - 2013-01-17 21:04 - 000935880 _____ (AVG Technologies) C:\Users\Joey\AppData\Local\Temp\GenericWndApi.dll
2015-07-31 14:46 - 2013-01-14 06:12 - 000396696 _____ (Happy Cloud, Inc.) C:\Users\Joey\AppData\Local\Temp\hcuninstaller_20150731_144605_6628.exe
2011-06-15 18:48 - 2011-06-15 18:48 - 003029824 _____ (Electronic Arts, Inc.) C:\Users\Joey\AppData\Local\Temp\installerdll9910681.dll
2011-06-15 18:48 - 2011-06-15 18:48 - 003029824 _____ (Electronic Arts, Inc.) C:\Users\Joey\AppData\Local\Temp\installerdll9917857.dll
2012-12-21 20:49 - 2012-12-17 09:55 - 001628672 _____ () C:\Users\Joey\AppData\Local\Temp\installhelper.dll
2013-12-19 13:06 - 2013-12-19 13:06 - 000921512 _____ (Oracle Corporation) C:\Users\Joey\AppData\Local\Temp\jre-7u51-windows-i586-iftw.exe
2012-09-07 16:45 - 2012-09-07 16:45 - 000894952 _____ (Oracle Corporation) C:\Users\Joey\AppData\Local\Temp\jre-7u7-windows-i586-iftw.exe
2012-09-27 17:56 - 2012-09-27 17:56 - 000895464 _____ (Oracle Corporation) C:\Users\Joey\AppData\Local\Temp\jre-7u9-windows-i586-iftw.exe
2017-09-30 17:27 - 2017-09-30 17:27 - 000740416 _____ (Oracle Corporation) C:\Users\Joey\AppData\Local\Temp\jre-8u144-windows-au.exe
2015-04-30 19:37 - 2015-04-30 19:37 - 000562272 _____ (Oracle Corporation) C:\Users\Joey\AppData\Local\Temp\jre-8u45-windows-au.exe
2016-04-11 21:42 - 2016-04-11 21:42 - 000736320 _____ (Oracle Corporation) C:\Users\Joey\AppData\Local\Temp\jre-8u77-windows-au.exe
2016-05-11 22:01 - 2016-05-11 22:01 - 000739904 _____ (Oracle Corporation) C:\Users\Joey\AppData\Local\Temp\jre-8u91-windows-au.exe
2013-01-17 21:04 - 2013-01-17 21:04 - 000163936 _____ () C:\Users\Joey\AppData\Local\Temp\MachineIdCreator.exe
2012-09-23 10:27 - 2012-09-23 10:27 - 000888320 _____ (McAfee, Inc.) C:\Users\Joey\AppData\Local\Temp\mssinstaller.exe
2013-01-17 21:04 - 2013-01-17 21:04 - 002985568 _____ () C:\Users\Joey\AppData\Local\Temp\oi_{6442B6C6-9B6C-4295-9CAF-B1519F431CF3}.exe
2013-06-09 22:24 - 2013-06-09 22:24 - 003238936 _____ (AVG Secure Search) C:\Users\Joey\AppData\Local\Temp\oi_{B786E7A9-4350-41AC-9F30-AFFC989C9641}.exe
2013-02-15 11:55 - 2013-02-15 11:55 - 003084368 _____ () C:\Users\Joey\AppData\Local\Temp\oi_{C4D902EB-D955-470E-80E2-281F9F0A8D5F}.exe
2013-06-10 22:12 - 2013-06-10 22:12 - 000000006 _____ () C:\Users\Joey\AppData\Local\Temp\propsys.dll
2011-06-08 16:03 - 2011-06-08 16:03 - 000336280 ____R (Microsoft Corporation) C:\Users\Joey\AppData\Local\Temp\rootsupd.exe
2012-09-29 19:53 - 2014-01-31 17:00 - 008330352 _____ (McAfee, Inc.) C:\Users\Joey\AppData\Local\Temp\SecurityScan_Release.exe
2016-04-06 21:21 - 2016-04-06 21:19 - 000381224 _____ (Splashtop Inc.) C:\Users\Joey\AppData\Local\Temp\SetupUtil.exe
2012-08-08 10:17 - 2012-08-08 10:17 - 000541696 _____ () C:\Users\Joey\AppData\Local\Temp\sqlite-3.7.2-sqlitejdbc.dll
2014-07-21 11:53 - 2014-07-21 11:53 - 000599419 _____ () C:\Users\Joey\AppData\Local\Temp\Sqlite3.dll
2012-12-21 20:49 - 2012-12-17 09:55 - 001085952 _____ () C:\Users\Joey\AppData\Local\Temp\SRAssetsHelper.dll
2012-10-12 16:47 - 2012-10-12 16:48 - 007036000 _____ (Nike) C:\Users\Joey\AppData\Local\Temp\temp0NikeConnectconnect5pcupdate.exe
2013-12-22 22:58 - 2013-12-22 22:59 - 017934352 _____ (Nike) C:\Users\Joey\AppData\Local\Temp\temp0NikeConnectconnect6pcupdate.exe
2013-01-20 10:36 - 2013-01-20 10:37 - 007116056 _____ (Nike) C:\Users\Joey\AppData\Local\Temp\temp10NikeConnectconnect5pcupdate.exe
2013-01-24 08:20 - 2013-01-24 08:20 - 007116056 _____ (Nike) C:\Users\Joey\AppData\Local\Temp\temp11NikeConnectconnect5pcupdate.exe
2013-01-29 00:04 - 2013-01-29 00:04 - 007116056 _____ (Nike) C:\Users\Joey\AppData\Local\Temp\temp12NikeConnectconnect5pcupdate.exe
2013-02-01 08:16 - 2013-02-01 08:16 - 007116056 _____ (Nike) C:\Users\Joey\AppData\Local\Temp\temp13NikeConnectconnect5pcupdate.exe
2013-02-13 08:18 - 2013-02-13 08:19 - 007116056 _____ (Nike) C:\Users\Joey\AppData\Local\Temp\temp14NikeConnectconnect5pcupdate.exe
2013-02-24 11:37 - 2013-02-24 11:37 - 007116056 _____ (Nike) C:\Users\Joey\AppData\Local\Temp\temp15NikeConnectconnect5pcupdate.exe
2013-02-25 08:36 - 2013-02-25 08:37 - 007116056 _____ (Nike) C:\Users\Joey\AppData\Local\Temp\temp16NikeConnectconnect5pcupdate.exe
2013-02-28 08:33 - 2013-02-28 08:34 - 007116056 _____ (Nike) C:\Users\Joey\AppData\Local\Temp\temp17NikeConnectconnect5pcupdate.exe
2013-03-05 11:03 - 2013-03-05 11:03 - 007116056 _____ (Nike) C:\Users\Joey\AppData\Local\Temp\temp18NikeConnectconnect5pcupdate.exe
2013-03-12 07:22 - 2013-03-12 07:22 - 007116056 _____ (Nike) C:\Users\Joey\AppData\Local\Temp\temp19NikeConnectconnect5pcupdate.exe
2012-10-27 12:12 - 2012-10-27 12:13 - 007036000 _____ (Nike) C:\Users\Joey\AppData\Local\Temp\temp1NikeConnectconnect5pcupdate.exe
2013-12-23 08:02 - 2013-12-23 08:03 - 017934352 _____ (Nike) C:\Users\Joey\AppData\Local\Temp\temp1NikeConnectconnect6pcupdate.exe
2013-03-16 11:40 - 2013-03-16 11:41 - 007116056 _____ (Nike) C:\Users\Joey\AppData\Local\Temp\temp20NikeConnectconnect5pcupdate.exe
2013-03-22 17:15 - 2013-03-22 17:16 - 007116056 _____ (Nike) C:\Users\Joey\AppData\Local\Temp\temp21NikeConnectconnect5pcupdate.exe
2013-03-31 09:37 - 2013-03-31 09:37 - 007116056 _____ (Nike) C:\Users\Joey\AppData\Local\Temp\temp22NikeConnectconnect5pcupdate.exe
2013-04-11 07:34 - 2013-04-11 07:34 - 007116056 _____ (Nike) C:\Users\Joey\AppData\Local\Temp\temp23NikeConnectconnect5pcupdate.exe
2013-05-01 07:24 - 2013-05-01 07:24 - 007116056 _____ (Nike) C:\Users\Joey\AppData\Local\Temp\temp24NikeConnectconnect5pcupdate.exe
2013-05-03 07:28 - 2013-05-03 07:29 - 007116056 _____ (Nike) C:\Users\Joey\AppData\Local\Temp\temp25NikeConnectconnect5pcupdate.exe
2013-05-09 20:08 - 2013-05-09 20:08 - 007116056 _____ (Nike) C:\Users\Joey\AppData\Local\Temp\temp26NikeConnectconnect5pcupdate.exe
2013-05-17 07:29 - 2013-05-17 07:30 - 007116056 _____ (Nike) C:\Users\Joey\AppData\Local\Temp\temp27NikeConnectconnect5pcupdate.exe
2013-05-18 09:51 - 2013-05-18 09:51 - 007116056 _____ (Nike) C:\Users\Joey\AppData\Local\Temp\temp28NikeConnectconnect5pcupdate.exe
2013-05-21 07:31 - 2013-05-21 07:31 - 007116056 _____ (Nike) C:\Users\Joey\AppData\Local\Temp\temp29NikeConnectconnect5pcupdate.exe
2012-11-05 08:21 - 2012-11-05 08:22 - 007036000 _____ (Nike) C:\Users\Joey\AppData\Local\Temp\temp2NikeConnectconnect5pcupdate.exe
2014-02-21 08:09 - 2014-02-21 08:10 - 017933920 _____ (Nike) C:\Users\Joey\AppData\Local\Temp\temp2NikeConnectconnect6pcupdate.exe
2013-11-02 07:50 - 2013-11-02 07:51 - 008133032 _____ (Nike) C:\Users\Joey\AppData\Local\Temp\temp30NikeConnectconnect5pcupdate.exe
2013-11-11 08:00 - 2013-11-11 08:00 - 008190072 _____ (Nike) C:\Users\Joey\AppData\Local\Temp\temp31NikeConnectconnect5pcupdate.exe
2012-11-20 08:07 - 2012-11-20 08:08 - 007036000 _____ (Nike) C:\Users\Joey\AppData\Local\Temp\temp3NikeConnectconnect5pcupdate.exe
2014-03-21 07:21 - 2014-03-21 07:22 - 017944824 _____ (Nike) C:\Users\Joey\AppData\Local\Temp\temp3NikeConnectconnect6pcupdate.exe
2012-11-21 08:22 - 2012-11-21 08:22 - 007036000 _____ (Nike) C:\Users\Joey\AppData\Local\Temp\temp4NikeConnectconnect5pcupdate.exe
2014-04-20 06:23 - 2014-04-20 06:24 - 017945160 _____ (Nike) C:\Users\Joey\AppData\Local\Temp\temp4NikeConnectconnect6pcupdate.exe
2012-12-08 09:53 - 2012-12-08 09:54 - 007036000 _____ (Nike) C:\Users\Joey\AppData\Local\Temp\temp5NikeConnectconnect5pcupdate.exe
2014-10-10 14:05 - 2014-10-10 14:06 - 018001232 _____ (Nike) C:\Users\Joey\AppData\Local\Temp\temp5NikeConnectconnect6pcupdate.exe
2012-12-16 09:23 - 2012-12-16 09:23 - 007116056 _____ (Nike) C:\Users\Joey\AppData\Local\Temp\temp6NikeConnectconnect5pcupdate.exe
2014-10-24 14:10 - 2014-10-24 14:11 - 018003320 _____ (Nike) C:\Users\Joey\AppData\Local\Temp\temp6NikeConnectconnect6pcupdate.exe
2012-12-19 08:24 - 2012-12-19 08:24 - 007116056 _____ (Nike) C:\Users\Joey\AppData\Local\Temp\temp7NikeConnectconnect5pcupdate.exe
2015-02-28 10:40 - 2015-02-28 10:41 - 018004536 _____ (Nike) C:\Users\Joey\AppData\Local\Temp\temp7NikeConnectconnect6pcupdate.exe
2012-12-31 11:34 - 2012-12-31 11:34 - 007116056 _____ (Nike) C:\Users\Joey\AppData\Local\Temp\temp8NikeConnectconnect5pcupdate.exe
2013-01-18 08:19 - 2013-01-18 08:19 - 007116056 _____ (Nike) C:\Users\Joey\AppData\Local\Temp\temp9NikeConnectconnect5pcupdate.exe
2013-01-18 17:51 - 2013-02-15 11:55 - 001042096 _____ () C:\Users\Joey\AppData\Local\Temp\UNINSTALL.EXE
2011-06-08 16:03 - 2011-06-08 16:03 - 005673816 _____ (Microsoft Corporation) C:\Users\Joey\AppData\Local\Temp\vcredist_x64.exe
2011-06-08 16:03 - 2011-06-08 16:03 - 004995416 _____ (Microsoft Corporation) C:\Users\Joey\AppData\Local\Temp\vcredist_x86.exe
2013-06-04 16:19 - 2013-06-04 16:19 - 000000000 _____ () C:\Users\Joey\AppData\Local\Temp\vnpxsk4z.dll
2012-04-25 12:48 - 2012-04-25 12:48 - 000401408 _____ () C:\Users\Joey\AppData\Local\Temp\wget.exe
2015-06-20 21:19 - 2015-06-20 21:19 - 000744656 _____ (Yahoo! Inc.) C:\Users\Joey\AppData\Local\Temp\ytb.exe
 
==================== Bamital & volsnap ======================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
 
LastRegBack: 2017-09-30 15:24
 
==================== End of FRST.txt ============================
 
 
 
 
 
 
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 29-09-2017
Ran by Joey (30-09-2017 17:34:48)
Running from C:\Users\Joey\Downloads
Windows 7 Home Premium Service Pack 1 (X64) (2012-05-16 23:15:21)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-1979518111-4107658783-1214925503-500 - Administrator - Disabled)
ASPNET (S-1-5-21-1979518111-4107658783-1214925503-1005 - Limited - Enabled)
Guest (S-1-5-21-1979518111-4107658783-1214925503-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-1979518111-4107658783-1214925503-1003 - Limited - Enabled)
Joey (S-1-5-21-1979518111-4107658783-1214925503-1001 - Administrator - Enabled) => C:\Users\Joey
UpdatusUser (S-1-5-21-1979518111-4107658783-1214925503-1000 - Limited - Enabled) => C:\Users\UpdatusUser
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Malwarebytes (Enabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B}
AV: AVG Antivirus (Enabled - Up to date) {4D41356F-32AD-7C42-C820-63775EE4F413}
AS: Malwarebytes (Enabled - Up to date) {98619B37-4FC4-67F2-1C99-EEF6D47DBD96}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: AVG Antivirus (Enabled - Up to date) {F620D48B-1497-73CC-F290-58052563BEAE}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
Adobe Flash Player 27 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 27.0.0.130 - Adobe Systems Incorporated)
Adobe Flash Player 27 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 27.0.0.130 - Adobe Systems Incorporated)
Adobe Reader X (10.1.16) MUI (HKLM-x32\...\{AC76BA86-7AD7-FFFF-7B44-AA0000000001}) (Version: 10.1.16 - Adobe Systems Incorporated)
Advanced Audio FX Engine (HKLM-x32\...\Advanced Audio FX Engine) (Version: 1.12.05 - Creative Technology Ltd)
AlienRespawn - Support Software (HKLM-x32\...\{A9668246-FB70-4103-A1E3-66C9BC2EFB49}) (Version: 9.4.67 - Alienware)
AlienRespawn (HKLM-x32\...\{0ED7EE95-6A97-47AA-AD73-152C08A15B04}) (Version: 9.4.67 - Alienware)
Alienware Command Center (HKLM\...\{CD4B350A-9328-4C1F-91D3-255EF2DA58FA}) (Version: 2.7.28.0 - Alienware Corp.) Hidden
Alienware Command Center (HKLM-x32\...\InstallShield_{CD4B350A-9328-4C1F-91D3-255EF2DA58FA}) (Version: 2.7.28.0 - Alienware Corp.)
Alienware On-Screen Display (HKLM-x32\...\{0D69462F-99CC-4F8D-942E-666E21CE59F8}) (Version: 0.32.1.1 - ) Hidden
Alienware On-Screen Display (HKLM-x32\...\InstallShield_{0D69462F-99CC-4F8D-942E-666E21CE59F8}) (Version: 0.32.1.1 - )
AVG (HKLM\...\{BA40B3B4-7707-437E-84FF-8C18BE5AD9B6}) (Version: 1.211.2 - AVG Technologies) Hidden
AVG AntiVirus FREE (HKLM-x32\...\AVG Antivirus) (Version: 17.6.3029 - AVG Technologies)
AVG SafeGuard toolbar (HKLM-x32\...\AVG SafeGuard toolbar) (Version: 17.3.0.49 - AVG Technologies)
Bing Bar (HKLM-x32\...\{FF6DD716-7B10-4269-9F19-FFB07AC4CD95}) (Version: 7.3.124.0 - Microsoft Corporation)
CyberDefender Framework (HKLM-x32\...\{DF4DF785-DB30-4AC0-B26A-715488DAA2CD}) (Version: 1.3.0.4371 - CyberDefender Corp.) Hidden
CyberDefender Framework (HKLM-x32\...\CyberDefender Framework) (Version: 1.3.0.4371 - CyberDefender Corp.)
Dell SupportAssist (HKLM\...\PC-Doctor for Windows) (Version: 2.0.6875.668 - Dell)
Dell SupportAssistAgent (HKLM\...\{18EF001B-B005-46CB-917B-112BA69ED85E}) (Version: 2.0.3.10 - Dell)
EMSC (HKLM-x32\...\{FEF06E73-A519-4510-8CF3-B66041B91D8A}) (Version: 0.0.0.22C - Compal Electronics, Inc.) Hidden
FMW 1 (HKLM\...\{2B66FCDA-0BD6-47CC-8EC5-C2EA02E03EB2}) (Version: 1.224.4 - AVG Technologies) Hidden
Free Download Manager 3.9.3 (HKLM-x32\...\Free Download Manager_is1) (Version:  - FreeDownloadManager.ORG)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 61.0.3163.100 - Google Inc.)
Google Toolbar for Internet Explorer (HKLM-x32\...\{18455581-E099-4BA8-BC6B-F34B2F06600C}) (Version: 1.0.0 - Google Inc.) Hidden
Google Toolbar for Internet Explorer (HKLM-x32\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.8231.2252 - Google Inc.)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.5 - Google Inc.) Hidden
Google Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.25.11 - Google Inc.) Hidden
Happy Cloud Client (HKU\S-1-5-21-1979518111-4107658783-1214925503-1001\...\HappyCloud) (Version: 1.368 - Happy Cloud, Inc.)
Integrated Webcam Live! Central (HKLM-x32\...\Integrated Webcam Live! Central) (Version: 2.00.44 - Creative Technology Ltd)
Intel® Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
Intel® Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.0.1.1399 - Intel Corporation)
Intel® Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2653 - Intel Corporation)
Intel® PROSet/Wireless for Bluetooth® + High Speed (HKLM\...\{37EC048A-81A2-452A-8D1F-3BE2018E767D}) (Version: 15.1.0.0096 - Intel Corporation)
Intel® PROSet/Wireless Software for Bluetooth® Technology (HKLM\...\{520C4DD4-2BC7-409B-BA48-E1A4F832662D}) (Version: 2.1.0.0140 - Intel Corporation)
Intel® Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 11.0.0.1032 - Intel Corporation)
Intel® USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 1.0.3.214 - Intel Corporation)
Intel® WiDi (HKLM-x32\...\{93F34C5C-ACAA-48F3-9B26-70359A117F12}) (Version: 3.0.12.0 - Intel Corporation)
Intel® Wireless Display (HKLM\...\{28EF7372-9087-4AC3-9B9F-D9751FCDF830}) (Version:  - )
Intel® PROSet/Wireless WiFi Software (HKLM\...\{E97F409F-9E1C-42A0-B72D-765A78DF3696}) (Version: 15.01.0000.0830 - Intel Corporation)
Intel® Trusted Connect Service Client (HKLM\...\{538B98C3-773F-4F20-9C66-802D104DCBE2}) (Version: 1.23.219.2 - Intel Corporation)
Java 8 Update 144 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180144F0}) (Version: 8.0.1440.1 - Oracle Corporation)
JavaFX 2.1.1 (HKLM-x32\...\{1111706F-666A-4037-7777-211328764D10}) (Version: 2.1.1 - Oracle Corporation)
Malwarebytes version 3.2.2.2029 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.2.2.2029 - Malwarebytes)
Microsoft .NET Framework 1.1 (HKLM-x32\...\Microsoft .NET Framework 1.1  (1033)) (Version:  - )
Microsoft .NET Framework 4.7 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.7.02053 - Microsoft Corporation)
Microsoft Office Click-to-Run 2010 (HKLM-x32\...\Office14.Click2Run) (Version: 14.0.6122.5000 - Microsoft Corporation)
Microsoft Office Home and Business 2010 - English (HKLM-x32\...\{90140011-0062-0409-0000-0000000FF1CE}) (Version: 14.0.6137.5006 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{820B6609-4C97-3A2B-B644-573B06A0F0CC}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation)
Mozilla Firefox 14.0.1 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 14.0.1 (x86 en-US)) (Version: 14.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 14.0.1 - Mozilla)
Nike+ Connect (HKLM-x32\...\Nike+ Connect) (Version: 6.6.32 - Nike)
Nike+ Connect (HKU\S-1-5-21-1979518111-4107658783-1214925503-1001\...\Nike+ Connect) (Version: 5.2.4 - Nike)
Norton Security Scan (HKLM-x32\...\NSS) (Version: 4.1.0.28 - Symantec Corporation)
NVIDIA 3D Vision Driver 296.16 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 296.16 - NVIDIA Corporation)
NVIDIA Graphics Driver 296.16 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 296.16 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.12.0213 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.12.0213 - NVIDIA Corporation)
NVIDIA Update 1.7.12 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 1.7.12 - NVIDIA Corporation)
OpenOffice 4.1.0 (HKLM-x32\...\{C87EF11D-36E9-479D-9898-7541EA1E8A6A}) (Version: 4.10.9764 - Apache Software Foundation)
Origin (HKLM-x32\...\Origin) (Version: 8.6.0.357 - Electronic Arts, Inc.)
Product Support 1.74.b1377 (HKLM-x32\...\SP_963508d2) (Version:  - ) <==== ATTENTION
QualxServ Service Agreement (HKLM-x32\...\{18401E1E-1E44-461A-A4B2-E48B1A727818}) (Version: 2.0.0 - Dell Inc.)
RogueKiller version 12.11.17.0 (HKLM\...\8B3D7924-ED89-486B-8322-E8594065D5CB_is1) (Version: 12.11.17.0 - Adlice Software)
Sound Blaster Recon3Di (HKLM-x32\...\{C8AAFCDC-CD3A-40AD-9FA9-07FB70F08224}) (Version: 1.00.08 - Creative Technology Limited)
Sound Blaster Recon3Di Extras (HKLM-x32\...\{C45E715E-442E-4D82-BD46-A08A0870957C}) (Version: 1.0 - Creative Technology Limited)
Splashtop Streamer (HKLM-x32\...\{B7C5EA94-B96A-41F5-BE95-25D78B486678}) (Version: 2.6.5.4 - Splashtop Inc.)
ST Microelectronics 3 Axis Digital Accelerometer Solution (HKLM-x32\...\{9C24F411-9CA7-4A8A-91F3-F08A4A38EB31}) (Version: 4.12.0018 - ST Microelectronics)
Star Wars: The Old Republic (HKLM-x32\...\{3B11D799-48E0-48ED-BFD7-EA655676D8BB}) (Version: 1.00 - Electronic Arts, Inc.)
Strongvault Online Backup (HKLM-x32\...\{3002C8EB-2A7E-419B-B77F-5AD7E9F54A5A}) (Version: 1.0.1.0 - Strongvault) <==== ATTENTION
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 16.0.4.0 - Synaptics Incorporated)
TeamSpeak 3 Client (HKLM-x32\...\TeamSpeak 3 Client) (Version: 3.0.19 - TeamSpeak Systems GmbH)
WildStar (HKLM-x32\...\WildStar) (Version:  - NCSOFT)
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
HKU\S-1-5-21-1979518111-4107658783-1214925503-1001\...\ChromeHTML: -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
ShellIconOverlayIdentifiers: [00avg] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  -> No File
ContextMenuHandlers1: [AVG] -> {472083B1-C522-11CF-8763-00608CC02F24} => C:\Program Files (x86)\AVG\Antivirus\ashShA64.dll [2017-09-22] (AVG Technologies CZ, s.r.o.)
ContextMenuHandlers3: [00avg] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  -> No File
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-08-30] (Malwarebytes)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => C:\Windows\system32\igfxpph.dll [2012-02-14] (Intel Corporation)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\Windows\system32\nvshext.dll [2012-03-04] (NVIDIA Corporation)
ContextMenuHandlers6: [AVG] -> {472083B1-C522-11CF-8763-00608CC02F24} => C:\Program Files (x86)\AVG\Antivirus\ashShA64.dll [2017-09-22] (AVG Technologies CZ, s.r.o.)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-08-30] (Malwarebytes)
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {01B531F6-4989-428C-BF33-604A32D9E2C1} - System32\Tasks\{7876D7AF-681B-4AA3-A783-B20A74974109} => C:\Program Files (x86)\Free Download Manager\fdm.exe [2013-10-25] (FreeDownloadManager.ORG)
Task: {02B13651-9496-4850-88E0-1EBC61F1E353} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-12-19] (Google Inc.)
Task: {46B9B6B3-D2A4-4E45-A192-6C54A497DDB4} - System32\Tasks\{6F4BD8B2-0FE6-4DA5-B2AE-A065C58ED6DA} => C:\Program Files (x86)\Free Download Manager\fdm.exe [2013-10-25] (FreeDownloadManager.ORG)
Task: {5D82BEC2-9751-4544-871A-C3EEF1978A3D} - System32\Tasks\SystemToolsDailyTest => uaclauncher.exe
Task: {616E9098-A190-4645-B31E-48E16FC4A72B} - System32\Tasks\{A2387960-277C-496E-B65E-385E77AB2BC6} => C:\Program Files (x86)\Free Download Manager\fdm.exe [2013-10-25] (FreeDownloadManager.ORG)
Task: {7F2ED675-4C7E-4A58-9399-EC2276E545A9} - System32\Tasks\AVG EUpdate Task => avgsetupx.exe
Task: {867DBBC8-5FCD-41D3-8566-C6DA733FABF3} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2017-07-19] (Adobe Systems Incorporated)
Task: {8DC3BA54-3336-447E-852B-6E36C3595F9F} - System32\Tasks\Antivirus Emergency Update => C:\Program Files (x86)\AVG\Antivirus\AvEmUpdate.exe [2017-09-22] (AVG Technologies CZ, s.r.o.)
Task: {90087565-5195-4568-B694-EC9F8B5416B9} - System32\Tasks\{13875299-5770-4714-AA79-35427528F3AC} => C:\Users\Joey\Downloads\microsoft powerpoint 2010 setup.exe
Task: {9243FA81-3ED1-4CFC-913D-2325EE208C99} - System32\Tasks\Norton Security Scan for Joey => C:\Program Files (x86)\Norton Security Scan\Engine\4.1.0.28\Nss.exe [2014-01-27] (Symantec Corporation)
Task: {9E0F11AA-4EBE-413F-8628-7982AEA0A981} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-12-19] (Google Inc.)
Task: {ACA79321-9247-4FD2-99A8-08752E3CCDB5} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-09-22] (Adobe Systems Incorporated)
Task: {B362B78B-47A1-42CE-B567-2652A4FDB87A} - System32\Tasks\PCDEventLauncherTask => C:\Program Files\Alienware\SupportAssist\sessionchecker.exe [2017-09-14] (PC-Doctor, Inc.)
Task: {B53FEADA-5DA9-4BA9-ABE6-10D14DC3608E} - System32\Tasks\{C0485AE7-9B0A-4CC0-8E15-054621A3DCD9} => C:\Program Files (x86)\Free Download Manager\fdm.exe [2013-10-25] (FreeDownloadManager.ORG)
Task: {D30614B7-686D-41E1-A8DD-022F5772725F} - System32\Tasks\Dell SupportAssistAgent AutoUpdate => C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssist.exe [2017-09-22] (Dell Inc.)
Task: {DA3F504E-A18A-4B3F-8437-A10EA5C82110} - System32\Tasks\PCDDataUploadTask => uaclauncher.exe
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\Windows\Tasks\Norton Security Scan for Joey.job => C:\PROGRA~2\NORTON~2\Engine\410~1.28\Nss.exe
 
==================== Shortcuts & WMI ========================
 
(The entries could be listed to be restored or removed.)
 
 
==================== Loaded Modules (Whitelisted) ==============
 
2017-09-26 16:33 - 2017-08-24 11:27 - 002264528 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\MwacLib.dll
2012-05-12 03:04 - 2012-01-26 22:49 - 002751808 ____N () C:\Program Files (x86)\AlienRespawn\COMPONENTS\SCHEDULER\STSERVICE.EXE
2011-11-03 19:01 - 2011-11-03 19:01 - 001546096 _____ () C:\Program Files (x86)\Alienware On-Screen Display\AlienwareOn-ScreenDisplay.exe
2017-09-22 23:47 - 2017-09-22 23:47 - 000068528 _____ () C:\Program Files (x86)\AVG\Antivirus\x64\module_lifetime.dll
2017-09-22 23:47 - 2017-09-22 23:47 - 000170952 _____ () c:\Program Files (x86)\AVG\Antivirus\x64\vaarclient.dll
2017-09-28 18:15 - 2017-09-28 18:14 - 000835344 _____ () C:\Program Files (x86)\AVG\Antivirus\x64\ffl2.dll
2017-09-22 23:47 - 2017-09-22 23:47 - 000287832 _____ () c:\Program Files (x86)\AVG\Antivirus\x64\StreamBack.dll
2017-09-26 17:36 - 2017-09-21 03:29 - 004022616 _____ () C:\Program Files (x86)\Google\Chrome\Application\61.0.3163.100\libglesv2.dll
2017-09-26 17:36 - 2017-09-21 03:29 - 000100184 _____ () C:\Program Files (x86)\Google\Chrome\Application\61.0.3163.100\libegl.dll
2017-09-22 23:47 - 2017-09-22 23:47 - 000060160 _____ () C:\Program Files (x86)\AVG\Antivirus\module_lifetime.dll
2017-09-22 23:47 - 2017-09-22 23:47 - 000168216 _____ () C:\Program Files (x86)\AVG\Antivirus\JsonRpcServer.dll
2017-09-22 23:47 - 2017-09-22 23:47 - 000213024 _____ () C:\Program Files (x86)\AVG\Antivirus\event_routing_rpc.dll
2017-09-22 23:47 - 2017-09-22 23:47 - 000243080 _____ () C:\Program Files (x86)\AVG\Antivirus\tasks_core.dll
2017-09-22 23:47 - 2017-09-22 23:47 - 000150688 _____ () C:\Program Files (x86)\AVG\Antivirus\network_notifications.dll
2017-09-28 18:10 - 2017-09-28 18:10 - 005900424 _____ () C:\Program Files (x86)\AVG\Antivirus\defs\17092800\algo.dll
2017-09-28 18:15 - 2017-09-28 18:15 - 000693528 _____ () C:\Program Files (x86)\AVG\Antivirus\ffl2.dll
2017-09-22 23:47 - 2017-09-22 23:47 - 000242568 _____ () C:\Program Files (x86)\AVG\Antivirus\streamback.dll
2012-03-26 15:57 - 2012-03-26 15:57 - 001074808 _____ () C:\Program Files (x86)\Common Files\CyberDefender\DEL\DEL_dll.dll
2017-09-22 23:43 - 2017-09-22 23:43 - 048920064 _____ () C:\Program Files (x86)\AVG\UiDll\2623\libcef.dll
2017-09-22 23:47 - 2017-09-22 23:47 - 067109376 _____ () C:\Program Files (x86)\AVG\Antivirus\libcef.dll
2009-12-18 12:07 - 2009-12-18 12:07 - 000577536 _____ () C:\Program Files (x86)\Alienware On-Screen Display\EMSC.dll
2017-09-22 05:04 - 2017-09-22 05:04 - 000172032 _____ () C:\Windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\f203ecbdc8e8f4f836e1627efb89f9ae\IsdiInterop.ni.dll
2012-05-12 02:55 - 2011-11-29 21:00 - 000059392 _____ () C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IsdiInterop.dll
2012-05-12 02:55 - 2012-02-01 18:44 - 001198872 _____ () C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\ACE.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\sndappv2 => ""="service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SplashtopRemoteService => ""="Service"
 
==================== Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
IE trusted site: HKU\S-1-5-21-1979518111-4107658783-1214925503-1001\...\amazon.com -> hxxps://amazon.com
IE trusted site: HKU\S-1-5-21-1979518111-4107658783-1214925503-1001\...\clonewarsadventures.com -> clonewarsadventures.com
IE trusted site: HKU\S-1-5-21-1979518111-4107658783-1214925503-1001\...\freerealms.com -> freerealms.com
IE trusted site: HKU\S-1-5-21-1979518111-4107658783-1214925503-1001\...\soe.com -> soe.com
IE trusted site: HKU\S-1-5-21-1979518111-4107658783-1214925503-1001\...\sony.com -> sony.com
 
==================== Hosts content: ===============================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2009-07-13 22:34 - 2016-04-11 21:03 - 000000824 _____ C:\Windows\system32\Drivers\etc\hosts
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-1979518111-4107658783-1214925503-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Joey\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 8.8.8.8
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
MSCONFIG\startupreg: (default) => 
MSCONFIG\startupreg: Adobe Reader Speed Launcher => "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
MSCONFIG\startupreg: BLEServicesCtrl => C:\Program Files (x86)\Intel\Bluetooth\BleServicesCtrl.exe
MSCONFIG\startupreg: BTMTrayAgent => rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll",TrayApp
MSCONFIG\startupreg: Command Center Controllers => "C:\Program Files\Alienware\Command Center\AWCCStartupOrchestrator.exe"
MSCONFIG\startupreg: HotKeysCmds => C:\Windows\system32\hkcmd.exe
MSCONFIG\startupreg: IAStorIcon => C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
MSCONFIG\startupreg: Integrated Webcam Live! Central => "C:\Program Files (x86)\Integrated Webcam\Live! Central\WebcamInt.exe" /mode2
MSCONFIG\startupreg: Nike+ Connect => "C:\Program Files (x86)\Nike\Nike+ Connect\Nike+ Connect daemon.exe"
MSCONFIG\startupreg: NowUSeeIt Player => "C:\Program Files (x86)\NowUSeeItPlayer\NowUSeeItPlayer.exe" /autostart=1
MSCONFIG\startupreg: Persistence => C:\Windows\system32\igfxpers.exe
MSCONFIG\startupreg: Sound Blaster Recon3Di Control Panel => "c:\Program Files (x86)\Creative\Sound Blaster Recon3Di\Sound Blaster Recon3Di Control Panel\SBRcni.exe" /r
MSCONFIG\startupreg: SynTPEnh => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
MSCONFIG\startupreg: UpdReg => C:\Windows\UpdReg.EXE
MSCONFIG\startupreg: vProt => "C:\Program Files (x86)\AVG SafeGuard toolbar\vprot.exe"
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [{5301C8EF-720D-4C8A-89F9-AF5AB1922725}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
FirewallRules: [{269D4DF6-AF70-48BA-A16D-D9ECCC6571FF}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
FirewallRules: [{7E98D223-4693-45A8-B258-814D1C8BCCC2}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
FirewallRules: [{70A7EB36-9E9A-44EA-9C50-48A7DD063354}] => (Allow) C:\Program Files (x86)\Intel Corporation\Intel WiDi\WiDiApp.exe
FirewallRules: [{DBB3D089-090F-47D9-B97A-C5FAF28D49C1}] => (Allow) C:\Program Files (x86)\Electronic Arts\BioWare\Star Wars - The Old Republic\swtor\retailclient\swtor.exe
FirewallRules: [{7E1794E1-7841-4A50-AB53-8C48D7A22349}] => (Allow) C:\Program Files (x86)\Electronic Arts\BioWare\Star Wars - The Old Republic\swtor\retailclient\swtor.exe
FirewallRules: [{4C0EC52B-1F77-4F7F-B2EE-B349EA4E4FD1}] => (Allow) C:\Program Files (x86)\Electronic Arts\BioWare\Star Wars - The Old Republic\swtor\retailclient\swtor.exe
FirewallRules: [{22D8EEB9-A174-428C-8C0B-A774D4CB74E7}] => (Allow) C:\Program Files (x86)\Electronic Arts\BioWare\Star Wars - The Old Republic\swtor\retailclient\swtor.exe
FirewallRules: [{7EB91939-45B8-4BA1-99AA-9C48140B2580}] => (Allow) C:\Program Files (x86)\Electronic Arts\BioWare\Star Wars - The Old Republic\launcher.exe
FirewallRules: [{14DC147E-3B56-48E1-B4C8-5F5BCF1E3BE4}] => (Allow) C:\Program Files (x86)\Electronic Arts\BioWare\Star Wars - The Old Republic\launcher.exe
FirewallRules: [{E67DC644-CBD8-47EC-ADB9-30953B995AAF}] => (Allow) C:\Program Files (x86)\Electronic Arts\BioWare\Star Wars - The Old Republic\launcher.exe
FirewallRules: [{A1DB4724-19B9-4647-B84A-8562ACB2BA15}] => (Allow) C:\Program Files (x86)\Electronic Arts\BioWare\Star Wars - The Old Republic\launcher.exe
FirewallRules: [TCP Query User{125C4FD9-7727-43E6-85FF-E13FB688A2D1}C:\program files (x86)\java\jre7\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre7\bin\javaw.exe
FirewallRules: [UDP Query User{9484D1B1-1C2C-43E5-AF3F-435B870FD8A2}C:\program files (x86)\java\jre7\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre7\bin\javaw.exe
FirewallRules: [TCP Query User{CE2DD44C-86A2-40A4-8E52-D9645BF1F1ED}C:\program files (x86)\java\jre7\bin\javaw.exe] => (Block) C:\program files (x86)\java\jre7\bin\javaw.exe
FirewallRules: [UDP Query User{75CF2FC3-8865-49C9-92CB-A1E81C8BF24D}C:\program files (x86)\java\jre7\bin\javaw.exe] => (Block) C:\program files (x86)\java\jre7\bin\javaw.exe
FirewallRules: [{71D83F0A-8E82-465B-B2B0-864C8275C845}] => (Allow) C:\Users\Joey\Documents\The War Z\WarZ.exe
FirewallRules: [{0DB2CF47-AD69-43BB-8740-6F40F6189071}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{616E3EC6-7CA3-4E3C-A4B3-74DC57B78F04}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [TCP Query User{87D3B3F1-E4CE-4C56-86F0-4EA824C1C9BB}C:\program files (x86)\steam\steamapps\common\planetside 2\planetside2.exe] => (Block) C:\program files (x86)\steam\steamapps\common\planetside 2\planetside2.exe
FirewallRules: [UDP Query User{DA543E2D-0647-43E9-942B-0A75BD0A8381}C:\program files (x86)\steam\steamapps\common\planetside 2\planetside2.exe] => (Block) C:\program files (x86)\steam\steamapps\common\planetside 2\planetside2.exe
FirewallRules: [{6652218A-2C3E-4878-9AD5-FAAC64E6FCE0}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{E57CFE2E-DBE0-4CCD-AC94-35FDEBE1C066}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{EBFA86F8-07B0-468D-A894-EF1EDAC65D8D}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dont_starve\bin\dontstarve_steam.exe
FirewallRules: [{4FE08C08-84D8-40FB-B0A3-0C2FFF2AC3D4}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dont_starve\bin\dontstarve_steam.exe
FirewallRules: [{FD11116B-3795-468E-9D9A-A36298CD0923}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{FD789060-EE00-48B8-AFF7-B01B8183F624}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{D4877180-EC25-4161-A4AA-83495C7B4477}] => (Allow) C:\Nexon\Library\vindictus\appdata\en-US\NMService.exe
FirewallRules: [{0C44A75E-A2CA-4B51-A986-1990515F7F83}] => (Allow) C:\Nexon\Library\vindictus\appdata\en-US\NMService.exe
FirewallRules: [TCP Query User{F57E5599-FA77-4F07-A25E-9C1ADE2090C8}C:\program files (x86)\java\jre1.8.0_45\bin\javaw.exe] => (Block) C:\program files (x86)\java\jre1.8.0_45\bin\javaw.exe
FirewallRules: [UDP Query User{BB65DDCE-3B77-4BD0-ACE5-70512C203076}C:\program files (x86)\java\jre1.8.0_45\bin\javaw.exe] => (Block) C:\program files (x86)\java\jre1.8.0_45\bin\javaw.exe
FirewallRules: [TCP Query User{EE7C12EC-1B70-476D-A3AC-DEE0A37D5FF2}C:\program files (x86)\java\jre1.8.0_77\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_77\bin\javaw.exe
FirewallRules: [UDP Query User{39E97CFC-CC2D-421D-980A-B725B4A2596E}C:\program files (x86)\java\jre1.8.0_77\bin\javaw.exe] => (Allow) C:\program files (x86)\java\jre1.8.0_77\bin\javaw.exe
FirewallRules: [{07205FA3-B249-463E-969B-C158CCDA7BF9}] => (Allow) C:\Users\Joey\AppData\Local\Chromium\Application\chrome.exe
FirewallRules: [{D548B7B7-A724-48A5-BA3C-DE08CD2B94A6}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
 
==================== Restore Points =========================
 
26-09-2017 22:16:07 Windows Update
28-09-2017 18:14:20 Windows Update
28-09-2017 18:48:15 JRT Pre-Junkware Removal
30-09-2017 14:11:16 Windows Update
 
==================== Faulty Device Manager Devices =============
 
Name: Microsoft Virtual WiFi Miniport Adapter #2
Description: Microsoft Virtual WiFi Miniport Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: vwifimp
Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31)
Resolution: Update the driver
 
Name: Microsoft Teredo Tunneling Adapter
Description: Microsoft Teredo Tunneling Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (09/30/2017 05:24:42 PM) (Source: MsiInstaller) (EventID: 1002) (User: NT AUTHORITY)
Description: Unexpected or missing value (name: 'PackageName', value: '') in key 'HKLM\Software\Classes\Installer\Products\D139E7FE48CDB174D86B8A3385904547\SourceList'
 
Error: (09/30/2017 04:36:18 PM) (Source: Dell System Detect) (EventID: 0) (User: )
Description: <Exception><Type>System.Xml.XmlException</Type><Message><![CDATA[The '/' character, hexadecimal value 0x2F, cannot be included in a name.]]></Message><Source><![CDATA[System.Xml]]></Source><StackTrace><![CDATA[   at System.Xml.XmlDocument.CheckName(String name)
   at System.Xml.XmlElement..ctor(XmlName name, Boolean empty, XmlDocument doc)
   at System.Xml.XmlDocument.CreateElement(String prefix, String localName, String namespaceURI)
   at System.Xml.XmlDocument.CreateElement(String name)
   at eSupport.Common.Client.Core.LastUpdatedHelper.SetLastUpdatedValue(String type, String value)]]></StackTrace><SysInfo STag="C6BCDS1" SMBIOSMajVer="2" SMBIOSMinVer="7" SMBIOSBIOSVer="A01" SMBIOSPresent="True" Rel_Date="20120208000000.000000+000" DSDVersion="" Vendor="Alienware" PName="M14xR2" Ident_Num="JOEY-PC" TimeZone="(UTC-05:00) Eastern Time (US & Canada)" OSName="Microsoft Windows 7 Home Premium"/><Method>UpdateLastUpdatedConfig</Method><HostIP>172.20.20.20</HostIP></Exception>
 
Error: (09/30/2017 04:36:17 PM) (Source: Dell System Detect) (EventID: 0) (User: )
Description: <Exception><Type>System.Xml.XmlException</Type><Message><![CDATA[The '/' character, hexadecimal value 0x2F, cannot be included in a name.]]></Message><Source><![CDATA[System.Xml]]></Source><StackTrace><![CDATA[   at System.Xml.XmlDocument.CheckName(String name)
   at System.Xml.XmlElement..ctor(XmlName name, Boolean empty, XmlDocument doc)
   at System.Xml.XmlDocument.CreateElement(String prefix, String localName, String namespaceURI)
   at System.Xml.XmlDocument.CreateElement(String name)
   at eSupport.Common.Client.Core.LastUpdatedHelper.SetLastUpdatedValue(String type, String value)]]></StackTrace><SysInfo STag="C6BCDS1" SMBIOSMajVer="2" SMBIOSMinVer="7" SMBIOSBIOSVer="A01" SMBIOSPresent="True" Rel_Date="20120208000000.000000+000" DSDVersion="" Vendor="Alienware" PName="M14xR2" Ident_Num="JOEY-PC" TimeZone="(UTC-05:00) Eastern Time (US & Canada)" OSName="Microsoft Windows 7 Home Premium"/><Method>UpdateLastUpdatedConfig</Method><HostIP>172.20.20.20</HostIP></Exception>
 
Error: (09/30/2017 04:35:55 PM) (Source: Dell System Detect) (EventID: 0) (User: )
Description: <Exception><Type>System.Xml.XmlException</Type><Message><![CDATA[The '/' character, hexadecimal value 0x2F, cannot be included in a name.]]></Message><Source><![CDATA[System.Xml]]></Source><StackTrace><![CDATA[   at System.Xml.XmlDocument.CheckName(String name)
   at System.Xml.XmlElement..ctor(XmlName name, Boolean empty, XmlDocument doc)
   at System.Xml.XmlDocument.CreateElement(String prefix, String localName, String namespaceURI)
   at System.Xml.XmlDocument.CreateElement(String name)
   at eSupport.Common.Client.Core.LastUpdatedHelper.SetLastUpdatedValue(String type, String value)]]></StackTrace><SysInfo STag="C6BCDS1" SMBIOSMajVer="2" SMBIOSMinVer="7" SMBIOSBIOSVer="A01" SMBIOSPresent="True" Rel_Date="20120208000000.000000+000" DSDVersion="" Vendor="Alienware" PName="M14xR2" Ident_Num="JOEY-PC" TimeZone="(UTC-05:00) Eastern Time (US & Canada)" OSName="Microsoft Windows 7 Home Premium"/><Method>UpdateLastUpdatedConfig</Method><HostIP>172.20.20.20</HostIP></Exception>
 
Error: (09/30/2017 04:35:54 PM) (Source: Dell System Detect) (EventID: 0) (User: )
Description: <Exception><Type>System.Xml.XmlException</Type><Message><![CDATA[The '/' character, hexadecimal value 0x2F, cannot be included in a name.]]></Message><Source><![CDATA[System.Xml]]></Source><StackTrace><![CDATA[   at System.Xml.XmlDocument.CheckName(String name)
   at System.Xml.XmlElement..ctor(XmlName name, Boolean empty, XmlDocument doc)
   at System.Xml.XmlDocument.CreateElement(String prefix, String localName, String namespaceURI)
   at System.Xml.XmlDocument.CreateElement(String name)
   at eSupport.Common.Client.Core.LastUpdatedHelper.SetLastUpdatedValue(String type, String value)]]></StackTrace><SysInfo STag="C6BCDS1" SMBIOSMajVer="2" SMBIOSMinVer="7" SMBIOSBIOSVer="A01" SMBIOSPresent="True" Rel_Date="20120208000000.000000+000" DSDVersion="" Vendor="Alienware" PName="M14xR2" Ident_Num="JOEY-PC" TimeZone="(UTC-05:00) Eastern Time (US & Canada)" OSName="Microsoft Windows 7 Home Premium"/><Method>UpdateLastUpdatedConfig</Method><HostIP>172.20.20.20</HostIP></Exception>
 
Error: (09/30/2017 04:33:58 PM) (Source: MsiInstaller) (EventID: 1002) (User: Joey-PC)
Description: Unexpected or missing value (name: 'PackageName', value: '') in key 'HKLM\Software\Classes\Installer\Products\D139E7FE48CDB174D86B8A3385904547\SourceList'
 
Error: (09/30/2017 02:54:46 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
 
Error: (09/30/2017 02:42:45 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
 
Error: (09/30/2017 09:07:36 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
 
Error: (09/28/2017 06:33:13 PM) (Source: Application Virtualization Client) (EventID: 3008) (User: )
Description: {hap=16:app=OfficeVirt 9014006204090000:tid=8F4}
The client was unable to connect to an Application Virtualization Server (rc 24604E0A-40000193)
 
 
System errors:
=============
Error: (09/30/2017 02:58:08 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The NVIDIA Update Service Daemon service failed to start due to the following error: 
The service did not start due to a logon failure.
 
Error: (09/30/2017 02:58:08 PM) (Source: Service Control Manager) (EventID: 7038) (User: )
Description: The nvUpdatusService service was unable to log on as .\UpdatusUser with the currently configured password due to the following error: 
Logon failure: the specified account password has expired.
 
 
To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC).
 
Error: (09/30/2017 02:54:21 PM) (Source: BugCheck) (EventID: 1001) (User: )
Description: The computer has rebooted from a bugcheck.  The bugcheck was: 0x00000101 (0x0000000000000031, 0x0000000000000000, 0xfffff880009f1180, 0x0000000000000001). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 093017-23883-01.
 
Error: (09/30/2017 02:54:17 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 2:52:30 PM on ‎9/‎30/‎2017 was unexpected.
 
Error: (09/30/2017 02:46:23 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The NVIDIA Update Service Daemon service failed to start due to the following error: 
The service did not start due to a logon failure.
 
Error: (09/30/2017 02:46:23 PM) (Source: Service Control Manager) (EventID: 7038) (User: )
Description: The nvUpdatusService service was unable to log on as .\UpdatusUser with the currently configured password due to the following error: 
Logon failure: the specified account password has expired.
 
 
To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC).
 
Error: (09/30/2017 02:43:38 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Client Virtualization Handler service failed to start due to the following error: 
The service did not respond to the start or control request in a timely fashion.
 
Error: (09/30/2017 02:43:38 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Client Virtualization Handler service to connect.
 
Error: (09/30/2017 09:10:50 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The NVIDIA Update Service Daemon service failed to start due to the following error: 
The service did not start due to a logon failure.
 
Error: (09/30/2017 09:10:50 AM) (Source: Service Control Manager) (EventID: 7038) (User: )
Description: The nvUpdatusService service was unable to log on as .\UpdatusUser with the currently configured password due to the following error: 
Logon failure: the specified account password has expired.
 
 
To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC).
 
 
==================== Memory info =========================== 
 
Processor: Intel® Core™ i5-2450M CPU @ 2.50GHz
Percentage of memory in use: 49%
Total physical RAM: 6044.31 MB
Available physical RAM: 3027.14 MB
Total Virtual: 12086.81 MB
Available Virtual: 9064.64 MB
 
==================== Drives ================================
 
Drive c: (OS) (Fixed) (Total:446.99 GB) (Free:303.93 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 465.8 GB) (Disk ID: 15215103)
Partition 1: (Not Active) - (Size=39 MB) - (Type=DE)
Partition 2: (Active) - (Size=18.7 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=447 GB) - (Type=07 NTFS)
 
==================== End of Addition.txt ============================


#9 Aura

Aura

    Bleepin' Special Ops


  • Malware Response Team
  • 19,697 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:11:00 PM

Posted 02 October 2017 - 07:34 AM

Sorry for the delay, I was busy and away this weekend. We're almost done!

warning.gifMalicious Programs Warning!

I noticed that you have malicious programs installed on your system. I'll ask you to uninstall them since uninstalling such programs before running malware removal tools will ensure a better clean-up.
  • Product Support 1.74.b1377
  • Strongvault Online Backup
If you have an issue when uninstalling a program, please let me know.

I would also uninstall AVG SafeGuard toolbar.

LdH4gmf.pngGoogle Chrome - Remove Extension/App
  • In Google Chrome, enter chrome://extensions in the address bar and press on Enter
  • In the Extensions page, uninstall these (by clicking on the little garbage can icon on their right)
    • hTab
  • If you don't see the extension listed, it means that it's installed as an App. So enter chrome://apps in the address bar and press on Enter
  • From the Apps page, look for the app, right-click on it and select Remove from Chrome
iO3R662.pngFarbar Recovery Scan Tool (FRST) - Fix mode
Follow the instructions below to execute a fix on your system using FRST, and provide the log in your next reply.
  • Download the attached fixlist.txt file, and save it on your Desktop (or wherever your FRST.exe/FRST64.exe executable is located)
  • Right-click on the FRST executable and select Spcusrh.pngRun as Administrator (for Windows Vista, 7, 8, 8.1 and 10 users)
  • Click on the Fix button
    NYA5Cbr.png
  • On completion, a message will come up saying that the fix has been completed and it'll open a log in Notepad
  • Copy and paste its content in your next reply
How's your system behaving now? Are there any other issues to address?

Attached Files


animinionsmalltext.gif
unite_blue.png
Security Administrator | Sysnative Windows Update Senior Analyst | Malware Hunter | @SecurityAura
My timezone UTC-05:00 (East. Coast). If I didn't reply to you within 48 hours, please send me a PM.


#10 Aura

Aura

    Bleepin' Special Ops


  • Malware Response Team
  • 19,697 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:11:00 PM

Posted 05 October 2017 - 09:56 AM

Hi Mugga,

Are you still with me?

animinionsmalltext.gif
unite_blue.png
Security Administrator | Sysnative Windows Update Senior Analyst | Malware Hunter | @SecurityAura
My timezone UTC-05:00 (East. Coast). If I didn't reply to you within 48 hours, please send me a PM.


#11 Aura

Aura

    Bleepin' Special Ops


  • Malware Response Team
  • 19,697 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:11:00 PM

Posted 07 October 2017 - 12:23 PM

Due to the lack of feedback, this topic is now closed.

In the event you still have problems, please send me or any Moderator a Private Message and ask them to reopen this topic within the next 5 days.

Please include a link to your topic in the Private Message. Thank you.

animinionsmalltext.gif
unite_blue.png
Security Administrator | Sysnative Windows Update Senior Analyst | Malware Hunter | @SecurityAura
My timezone UTC-05:00 (East. Coast). If I didn't reply to you within 48 hours, please send me a PM.





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users