Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

com surrogate processes constantly running in background


  • This topic is locked This topic is locked
35 replies to this topic

#1 Dustint

Dustint

  • Members
  • 26 posts
  • OFFLINE
  •  
  • Local time:09:50 PM

Posted 27 January 2018 - 02:38 PM

Greetings,

 

I have com surrogate processes constantly running in the background taking up 13% resources even when all possible applications are shut down and not running. On a fresh reboot it goes away for a while and then starts up again (never sure when or what triggers it). Tried uninstalling things I don't need, disabling things from starting on boot-up, running virus scanner but none of these fix this. Today things got worse. Working in a basic word doc with internet explorer running in background and everything became unresponsive for long periods of time out of no where. Tried to shut down but needed to do a hard reboot to clear. After restarting & logging back on everything started up fine again and then locked up similarly after a few minutes. I can now only restart in safe mode. Not sure if the freeze-ups are related to the weird com surrogate processes running constantly but both seem to be abnormal and have never happened before until very recently. Any help / suggestions would be greatly appreciated. I ran the FRST scan and posted the log files below. Thanks in advance.

 

 
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 27.01.2018
Ran by Teschke (administrator) on XPS (27-01-2018 13:39:20)
Running from C:\Users\Teschke\Desktop
Loaded Profiles: Teschke (Available Profiles: Teschke & Admin)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Safe Mode (with Networking)
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe
(McAfee, Inc.) C:\Windows\System32\mfevtps.exe
(McAfee, Inc.) C:\Windows\System32\mfevtps.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\ModuleCore\ModuleCoreService.exe
(McAfee, Inc.) C:\Program Files\McAfee\MfeAV\MfeAVSvc.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\VSCore_15_7\mcapexe.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\ModuleCore\ModuleCoreService.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMWsc.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(McAfee LLC.) C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe
 
==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [10920552 2010-06-22] (Realtek Semiconductor)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe [283160 2010-09-13] (Intel Corporation)
HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKLM-x32\...\Run: [IndexSearch] => C:\Program Files (x86)\Nuance\PaperPort\IndexSearch.exe [46368 2010-03-09] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [PaperPort PTD] => C:\Program Files (x86)\Nuance\PaperPort\pptd40nt.exe [29984 2010-03-09] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [PPort12reminder] => "C:\Program Files (x86)\Nuance\PaperPort\Ereg\Ereg.exe" -r "C:\ProgramData\ScanSoft\PaperPort\12\Config\Ereg\Ereg.ini"
HKLM-x32\...\Run: [PDFHook] => C:\Program Files (x86)\Nuance\PDF Viewer Plus\pdfpro5hook.exe [636192 2010-03-05] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [PDF5 Registry Controller] => C:\Program Files (x86)\Nuance\PDF Viewer Plus\RegistryController.exe [62752 2010-03-05] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [ControlCenter4] => C:\Program Files (x86)\ControlCenter4\BrCcBoot.exe [143360 2012-09-06] (Brother Industries, Ltd.)
HKLM-x32\...\Run: [BrStsMon00] => C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe [3076096 2012-06-06] (Brother Industries, Ltd.)
HKU\S-1-5-21-3289118944-4034126387-1954186238-1000\...\Run: [OfficeSyncProcess] => C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE [721504 2015-09-02] (Microsoft Corporation)
HKU\S-1-5-21-3289118944-4034126387-1954186238-1000\...\Run: [ISUSPM] => C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe [222496 2009-05-05] (Acresso Corporation)
HKU\S-1-5-21-3289118944-4034126387-1954186238-1000\...\Run: [Spotify Web Helper] => C:\Users\Teschke\AppData\Roaming\Spotify\SpotifyWebHelper.exe [780688 2018-01-18] (Spotify Ltd)
HKU\S-1-5-21-3289118944-4034126387-1954186238-1000\...\Policies\system: [LogonHoursAction] 2
HKU\S-1-5-21-3289118944-4034126387-1954186238-1000\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
HKU\S-1-5-21-3289118944-4034126387-1954186238-1000\...\MountPoints2: {ecb585ac-a7d5-11e2-9d96-806e6f6e6963} - D:\autoRcd.exe
HKU\S-1-5-18\...\Run: [GarminExpressTrayApp] => C:\Program Files (x86)\Garmin\Express Tray\tray.exe [1010008 2015-04-08] (Garmin Ltd. or its subsidiaries)
HKU\S-1-5-18\...\RunOnce: [SPReview] => "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"hxxp://go.microsoft.com/fwlink/?LinkID=122915" /build:7601
Startup: C:\Users\Teschke\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk [2018-01-25]
ShortcutTarget: OneNote 2010 Screen Clipper and Launcher.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
GroupPolicy\User: Restriction <==== ATTENTION
GroupPolicyUsers\S-1-5-21-3289118944-4034126387-1954186238-1003\User: Restriction <==== ATTENTION
GroupPolicyUsers\S-1-5-21-3289118944-4034126387-1954186238-1000\User: Restriction <==== ATTENTION
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Tcpip\Parameters: [DhcpNameServer] 199.166.6.2 209.239.11.98
Tcpip\..\Interfaces\{E3D08391-DA71-4B1B-9F02-0CCEDCEF505A}: [DhcpNameServer] 199.166.6.2 209.239.11.98
 
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-3289118944-4034126387-1954186238-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.ca/
URLSearchHook: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000 - (No Name) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - No File
SearchScopes: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000 -> DefaultScope {49DABC51-C6C4-4160-8197-B334814CCCE5} URL = hxxps://search.yahoo.com/search?fr=mcafee&type=C011US91038D20130825&p={searchTerms}
SearchScopes: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000 -> {49DABC51-C6C4-4160-8197-B334814CCCE5} URL = hxxps://search.yahoo.com/search?fr=mcafee&type=C011US91038D20130825&p={searchTerms}
SearchScopes: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000 -> {49DE4C69-1A45-422D-97A4-9B692ECF5F83} URL = hxxps://search.yahoo.com/search?fr=mcafee&type=C011US0D19700101&p={searchTerms}
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-04-27] (Google Inc.)
BHO: McAfee WebAdvisor BHO -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll [2018-01-19] (McAfee, Inc.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: PlusIEEventHelper Class -> {551A852F-39A6-44A7-9C13-AFBEC9185A9D} -> C:\Program Files (x86)\Nuance\PDF Viewer Plus\Bin\PlusIEContextMenu.dll [2009-02-06] (Zeon Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\ssv.dll [2014-10-20] (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2016-04-27] (Google Inc.)
BHO-x32: McAfee WebAdvisor BHO -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll [2018-01-19] (McAfee, Inc.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\jp2ssv.dll [2014-10-20] (Oracle Corporation)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-04-27] (Google Inc.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2016-04-27] (Google Inc.)
DPF: HKLM-x32 {A2505C6C-6F17-456F-89D2-4301FBDC6EC7} hxxps://ssl.grhosp.on.ca/nortel_cacheable/iewiper.cab
DPF: HKLM-x32 {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} hxxps://join-test.webex.com/client/WBXclient-T30L10NSP13EP1-10006/webex/ieatgpc1.cab
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll [2018-01-19] (McAfee, Inc.)
Handler-x32: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll [2018-01-19] (McAfee, Inc.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\McAfee\MSC\McSnIePl64.dll [2017-07-10] (McAfee, Inc.)
Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\MSC\McSnIePl.dll [2017-07-10] (McAfee, Inc.)
 
FireFox:
========
FF DefaultProfile: gd2bren1.default
FF ProfilePath: C:\Users\Teschke\AppData\Roaming\Mozilla\Firefox\Profiles\gd2bren1.default [2017-12-01]
FF Extension: (Firefox Hotfix) - C:\Users\Teschke\AppData\Roaming\Mozilla\Firefox\Profiles\gd2bren1.default\Extensions\firefox-hotfix@mozilla.org.xpi [2016-12-08] [Legacy]
FF HKLM\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor\e10ssaffplg.xpi
FF Extension: (No Name) - C:\Program Files (x86)\McAfee\SiteAdvisor\e10ssaffplg.xpi [2017-12-07]
FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor\e10ssaffplg.xpi
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_28_0_0_137.dll [2018-01-09] ()
FF Plugin: @garmin.com/GpsControl -> C:\Program Files\Garmin GPS Plugin\npGarmin.dll [2014-03-31] (GARMIN Corp.)
FF Plugin: @mcafee.com/MSC,version=10 -> c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL [2017-07-10] ()
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin: @wacom.com/wtPlugin,version=2.1.0.7 -> C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll [2014-03-25] (Wacom)
FF Plugin: wacom.com/WacomTabletPlugin -> C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll [2014-03-25] (Wacom)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_28_0_0_137.dll [2018-01-09] ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2016-03-08] ()
FF Plugin-x32: @garmin.com/GpsControl -> C:\Program Files (x86)\Garmin GPS Plugin\npGarmin.dll [2014-03-31] (GARMIN Corp.)
FF Plugin-x32: @java.com/DTPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll [2014-10-20] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\plugin2\npjp2.dll [2014-10-20] (Oracle Corporation)
FF Plugin-x32: @mcafee.com/MSC,version=10 -> c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL [2017-07-10] ()
FF Plugin-x32: @mcafee.com/MVT -> C:\Program Files (x86)\McAfee\Supportability\MVT\NPMVTPlugin.dll [2016-03-07] (McAfee, Inc.)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll [2014-02-14] (Pando Networks)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-14] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-14] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.8 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2013-07-30] (VideoLAN)
FF Plugin-x32: @wacom.com/wtPlugin,version=2.1.0.7 -> C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll [2014-03-25] (Wacom)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2013-05-11] (Adobe Systems Inc.)
FF Plugin-x32: wacom.com/WacomTabletPlugin -> C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll [2014-03-25] (Wacom)
FF Plugin HKU\S-1-5-21-3289118944-4034126387-1954186238-1000: @hola.org/FlashPlayer -> C:\Users\Teschke\AppData\Local\Hola\firefox_hola\app\flash\NPSWF32_18_0_0_232.dll [2016-01-30] ()
FF Plugin HKU\S-1-5-21-3289118944-4034126387-1954186238-1000: @hola.org/vlc -> C:\Users\Teschke\AppData\Local\Hola\firefox_hola\app\vlc\npvlc.dll [2016-01-30] (Hola)
FF Plugin HKU\S-1-5-21-3289118944-4034126387-1954186238-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Teschke\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2015-08-21] (Unity Technologies ApS)
FF Plugin HKU\S-1-5-21-3289118944-4034126387-1954186238-1000: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [2016-01-14] ()
 
Chrome: 
=======
CHR DefaultProfile: Profile 3
CHR HomePage: Profile 3 -> hxxps://www.google.ca/
CHR StartupUrls: Profile 3 -> "hxxp://www.google.ca/"
CHR DefaultSearchURL: Profile 3 -> hxxps://search.yahoo.com/search?fr=mcafee&type=C211US0D20170114&p={searchTerms}
CHR DefaultSearchKeyword: Profile 3 -> mcafee
CHR Profile: C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default [2015-11-28]
CHR Extension: (BeGone Guerra Online) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\ahcchnfnladlkddlceegencfccjcfnjp [2013-09-19]
CHR Extension: (Plants vs. Zombies HD) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\ahdfeknjbgfbkmemaoffkebceonhcjfd [2013-09-19]
CHR Extension: (Beatlab) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\alnfdikmbdfgkcbdodjcbmedanjinmkk [2015-04-20]
CHR Extension: (Google Drive) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-20]
CHR Extension: (UJAM - Make your music.) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdiogojbmdncjdpljocafnigiokgmci [2013-09-19]
CHR Extension: (Free Running 2 3D) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakechaaagjbdhedidbfifkembmkhafl [2013-09-19]
CHR Extension: (BeGone: Last Stand HD) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\bmekbplkjhgmljmbblmhmcnocafhaink [2013-09-19]
CHR Extension: (Battlefield Heroes) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\cehdakiococlfmjcbebbkjkfjhbieknh [2013-09-21]
CHR Extension: (Rush Team) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\ecdnoeebfjlplfkljdedokbcmebojbpb [2013-10-10]
CHR Extension: (Freefall Tournament) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\encjogopgacdjlkmpdknhlfnanoihodh [2015-03-18]
CHR Extension: (Music Maker) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\epnoajccaiifhpidemmcdamilpeblipc [2014-03-27]
CHR Extension: (Google Play Music) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\fahmaaghhglfmonjliepjlchgpgfmobi [2015-11-18]
CHR Extension: (PicMonkey) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\fgdgokchhicmaiacmgegjnppjkgogdhm [2014-10-24]
CHR Extension: (SiteAdvisor) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2015-07-02]
CHR Extension: (Counter Strike Online ) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\fplklihjpkinahlihcljhnnlnhnmmhdp [2013-09-19]
CHR Extension: (Google Docs Offline) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-11-18]
CHR Extension: (Unlimited Free VPN - Hola) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkojfkhlekighikafcpjkiklfbnlmeio [2015-11-28]
CHR Extension: (Happy Wheels) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\hpljdpjoahbnnfilkiilnfdkdbfiabfc [2013-09-19]
CHR Extension: (Apocalypse City) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifkogipjfpemebgfjelkfoifapppddeh [2013-09-19]
CHR Extension: (Digital BeatMaker) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihjdooenciklfgogkejekglpoeedphmc [2014-03-27]
CHR Extension: (90`s Games) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\illbbfoihflomkbpcaaakhijinbnejom [2015-03-14]
CHR Extension: (theHunter) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\jangaedeekciafhlanphhnalogmhefmo [2013-09-19]
CHR Extension: (Super Mario Bros HD) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmhilnfngnmcnlekfgcglogafjkahoml [2013-09-19]
CHR Extension: (Eyes - The Horror Game) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\jojpkokphfnjlhbnbcilnhgnkkobkngd [2013-09-19]
CHR Extension: (Resident Evil) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\kelgpfmgciingekkpfaikcjmcomfikgp [2013-09-19]
CHR Extension: (Aqua Planet) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\kkfobnmhjmjkgojmfldhnkmfcdjjakhb [2013-09-20]
CHR Extension: (Dead Zed Zombie) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\lcdhiflblofckjcpphgcoajnebhbdpja [2013-09-19]
CHR Extension: (Counter-Strike-Online 2) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\liihamdfalaafmojcdakajejmcbnjkce [2013-09-19]
CHR Extension: (Plink) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\loeiekheegipnnbcfbfkanbbegkhjjcm [2013-09-20]
CHR Extension: (Slender Space) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkdmfheflfmedmfjolgifliincdhfgdl [2013-09-19]
CHR Extension: (Mixify) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkjlbfglfefcmkmglakdocbgnggeieno [2014-03-27]
CHR Extension: (Plants vs Zombies) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmcegpfdgcoclcdfkjahiimlikdpnina [2013-09-21]
CHR Extension: (BeGone) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndfpieflbjbdpgklkeolbmbdkfdiicfk [2015-06-27]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-07-23]
CHR Extension: (Mini Ninjas) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\oijfbknbncemokdnlboeabbcfhobechi [2013-09-19]
CHR Extension: (Battlefield Play4Free) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\oiokahphinmbmakkehgelkmpolmnbkdh [2013-09-19]
CHR Profile: C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 1 [2015-11-28]
CHR Extension: (Google Slides) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-11-28]
CHR Extension: (Google Docs) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2015-11-28]
CHR Extension: (Google Drive) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-11-28]
CHR Extension: (YouTube) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-11-28]
CHR Extension: (Google Search) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-11-28]
CHR Extension: (Google Sheets) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-11-28]
CHR Extension: (SiteAdvisor) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2015-11-28]
CHR Extension: (Google Docs Offline) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-11-28]
CHR Extension: (Unlimited Free VPN - Hola) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gkojfkhlekighikafcpjkiklfbnlmeio [2015-11-28]
CHR Extension: (Video Recorder for WeVideo) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\iaiglpeefdoagfbbfhjfbmomnfobojia [2015-11-28]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-11-28]
CHR Extension: (Gmail) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-11-28]
CHR Profile: C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 2 [2015-11-29]
CHR Extension: (Google Slides) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-11-28]
CHR Extension: (Google Docs) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\aohghmighlieiainnegkcijnfilokake [2015-11-28]
CHR Extension: (Google Drive) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-11-28]
CHR Extension: (YouTube) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-11-28]
CHR Extension: (Google Search) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-11-28]
CHR Extension: (MLG-ifier) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\dneebgdgldanagagmfhnphjelnngdcai [2015-11-28]
CHR Extension: (Google Sheets) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-11-28]
CHR Extension: (SiteAdvisor) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2015-11-28]
CHR Extension: (Google Docs Offline) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-11-28]
CHR Extension: (Read&Write for Google Chrome™) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\inoeonmfapjbbkmdafoankkfajkcphgd [2015-11-28]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-11-28]
CHR Extension: (Gmail) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-11-28]
CHR Extension: (Snapverter) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\plebojnaihkfjkkpgaemcjpnkmcpleih [2015-11-28]
CHR Profile: C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 3 [2018-01-27]
CHR Extension: (Slides) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-10-12]
CHR Extension: (Docs) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-12]
CHR Extension: (Google Drive) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-11-29]
CHR Extension: (YouTube) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-11-29]
CHR Extension: (Google Search) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-11-29]
CHR Extension: (Sheets) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-10-12]
CHR Extension: (McAfee® WebAdvisor) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2017-11-22]
CHR Extension: (Google Docs Offline) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-26]
CHR Extension: (Unlimited Free VPN - Hola) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\gkojfkhlekighikafcpjkiklfbnlmeio [2018-01-22]
CHR Extension: (Video Recorder for WeVideo) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\iaiglpeefdoagfbbfhjfbmomnfobojia [2017-12-14]
CHR Extension: (Project Viewer 365-Free) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\kmpghmkgkalhonankenfklpmdgnilapp [2016-04-07]
CHR Extension: (Cloud Drive, URL to ChromeCast™) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\mehfijocnmclokiknjjpcbddbekagnik [2015-12-25]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-08-21]
CHR Extension: (Gmail) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-11-29]
CHR Extension: (Chrome Media Router) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-01-25]
CHR Profile: C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 4 [2018-01-11]
CHR Extension: (Slides) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-01-11]
CHR Extension: (Docs) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\aohghmighlieiainnegkcijnfilokake [2018-01-11]
CHR Extension: (Google Drive) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-01-11]
CHR Extension: (YouTube) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-01-11]
CHR Extension: (Sheets) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-01-11]
CHR Extension: (McAfee® WebAdvisor) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2018-01-11]
CHR Extension: (Google Docs Offline) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-01-11]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-01-11]
CHR Extension: (Gmail) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2018-01-11]
CHR Extension: (Chrome Media Router) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-01-11]
CHR Profile: C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\System Profile [2015-11-29]
CHR HKLM\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - hxxp://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - hxxp://clients2.google.com/service/update2/crx
 
==================== Services (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S2 amdacpusrsvc; C:\Program Files\AMD\{920DEC42-4CA5-4d1d-9487-67BE645CDDFC}\amdacpusrsvc.exe [121856 2015-05-05] (Advanced Micro Devices) [File not signed]
S4 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2016-03-02] (Apple Inc.)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [6971400 2018-01-19] ()
S3 BrYNSvc; C:\Program Files (x86)\Browny02\BrYNSvc.exe [266240 2012-06-05] (Brother Industries, Ltd.) [File not signed]
S3 chromoting; C:\Program Files (x86)\Google\Chrome Remote Desktop\63.0.3239.32\remoting_host.exe [71512 2017-11-02] (Google Inc.)
S3 ClientAnalyticsService; C:\Program Files\Common Files\McAfee\ClientAnalytics\Legacy\McClientAnalytics.exe [1509680 2017-07-13] (McAfee, Inc.)
S4 Garmin Device Interaction Service; C:\Program Files (x86)\Garmin\Device Interaction Service\GarminService.exe [708616 2015-04-08] (Garmin Ltd. or its subsidiaries)
S4 lxea_device; C:\Windows\system32\lxeacoms.exe [1052328 2010-04-14] ( )
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6234056 2017-11-01] (Malwarebytes)
S2 McAfee SiteAdvisor Service; C:\Program Files (x86)\McAfee\SiteAdvisor\McSACore.exe [604312 2018-01-19] (McAfee, Inc.)
R2 McAPExe; C:\Program Files\Common Files\McAfee\VSCore_15_7\McApExe.exe [990696 2017-07-20] (McAfee, Inc.)
S2 mccspsvc; C:\Program Files\Common Files\McAfee\CSP\2.5.312.0\\McCSPServiceHost.exe [2139832 2017-05-30] (McAfee, Inc.)
R3 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe [242640 2017-06-21] (McAfee, Inc.)
R2 mfemms; C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe [394704 2017-06-21] (McAfee, Inc.)
R3 mfevtp; C:\Windows\system32\mfevtps.exe [350160 2017-06-21] (McAfee, Inc.)
R2 ModuleCoreService; C:\Program Files\Common Files\McAfee\ModuleCore\ModuleCoreService.exe [1545880 2017-06-27] (McAfee, Inc.)
S4 NETGEARGenieDaemon; C:\Program Files (x86)\NETGEAR Genie\bin\NETGEARGenieDaemon64.exe [232192 2015-06-01] (NETGEAR)
S2 PDFProFiltSrvPP; C:\Program Files (x86)\Nuance\PaperPort\PDFProFiltSrvPP.exe [144672 2010-03-09] (Nuance Communications, Inc.)
S2 PEFService; C:\Program Files\Common Files\Intel Security\PEF\CORE\PEFService.exe [1044376 2017-07-07] (Intel Security, Inc.)
S2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [66872 2015-04-21] ()
S2 PnkBstrB; C:\Windows\SysWOW64\PnkBstrB.exe [107832 2015-04-21] ()
S2 PSI_SVC_2_x64; c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe [337776 2014-04-30] (arvato digital services llc)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
S2 WTabletServicePro; C:\Program Files\Tablet\Wacom\WTabletServicePro.exe [652240 2016-07-14] (Wacom Technology, Corp.)
S2 HomeNetSvc; "C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe" /McCoreSvc [X]
S2 McBootDelayStartSvc; "C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe" /McCoreSvc [X]
S2 McMPFSvc; "C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe" /McCoreSvc [X]
S2 mcpltsvc; "C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe" /McCoreSvc [X]
S2 McProxy; "C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe" /McCoreSvc [X]
 
===================== Drivers (Whitelisted) ======================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S2 amdacpksd; C:\Windows\system32\drivers\amdacpksd.sys [297160 2015-05-05] (Advanced Micro Devices)
S3 cfwids; C:\Windows\System32\drivers\cfwids.sys [77800 2017-06-26] (McAfee, Inc.)
S3 HipShieldK; C:\Windows\System32\drivers\HipShieldK.sys [209616 2017-07-26] (McAfee, Inc.)
R0 MBAMChameleon; C:\Windows\System32\Drivers\MbamChameleon.sys [193968 2018-01-27] (Malwarebytes)
S3 MBAMFarflt; C:\Windows\System32\DRIVERS\farflt.sys [110016 2018-01-27] (Malwarebytes)
S3 MBAMProtection; C:\Windows\System32\DRIVERS\mbam.sys [46008 2018-01-27] (Malwarebytes)
R3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [253880 2018-01-27] (Malwarebytes)
S3 MBAMWebProtection; C:\Windows\System32\DRIVERS\mwac.sys [84256 2018-01-27] (Malwarebytes)
R3 mfeaack; C:\Windows\System32\drivers\mfeaack.sys [487408 2017-06-26] (McAfee, Inc.)
R3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [355312 2017-06-26] (McAfee, Inc.)
R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [506352 2017-06-26] (McAfee, Inc.)
R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [933360 2017-06-26] (McAfee, Inc.)
R3 mfencbdc; C:\Windows\System32\DRIVERS\mfencbdc.sys [504760 2017-05-31] (McAfee LLC.)
S3 mfencrk; C:\Windows\System32\DRIVERS\mfencrk.sys [108472 2017-05-31] (McAfee LLC.)
S3 mfeplk; C:\Windows\System32\drivers\mfeplk.sys [116208 2017-06-26] (McAfee, Inc.)
S3 mfesapsn; C:\Program Files (x86)\McAfee\SiteAdvisor\x64\mfesapsn.sys [111608 2017-02-14] (McAfee, Inc.)
R0 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [253424 2017-06-26] (McAfee, Inc.)
S2 NPF; C:\Windows\system32\drivers\npf.sys [35344 2015-09-29] (CACE Technologies, Inc.)
S3 pmxdrv; C:\Windows\system32\drivers\pmxdrv.sys [31152 2015-09-18] ()
S3 WacHidRouterPro; C:\Windows\System32\DRIVERS\wachidrouter.sys [102864 2016-03-02] (Wacom Technology)
S3 mfeaack01; \Device\mfeaack01.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2018-01-27 13:39 - 2018-01-27 13:40 - 000035429 _____ C:\Users\Teschke\Desktop\FRST.txt
2018-01-27 13:39 - 2018-01-27 13:39 - 000000000 ____D C:\FRST
2018-01-27 13:37 - 2018-01-27 13:28 - 002393088 _____ (Farbar) C:\Users\Teschke\Desktop\FRST64.exe
2018-01-27 13:34 - 2018-01-27 13:34 - 000253880 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamswissarmy.sys
2018-01-27 13:34 - 2018-01-27 13:34 - 000193968 _____ (Malwarebytes) C:\Windows\system32\Drivers\MbamChameleon.sys
2018-01-26 19:03 - 2018-01-26 19:03 - 000619670 _____ C:\Users\Teschke\Desktop\W415-0061_GI3600manual.pdf
2018-01-20 18:11 - 2018-01-27 12:33 - 000084256 _____ (Malwarebytes) C:\Windows\system32\Drivers\mwac.sys
2018-01-19 20:53 - 2018-01-19 20:53 - 000000000 ____D C:\Users\Teschke\AppData\Local\CrashReportClient
2018-01-19 20:18 - 2018-01-18 19:16 - 000000229 ___SH C:\Users\Public\Libraries.ini
2018-01-19 20:15 - 2018-01-19 20:15 - 000000000 ____D C:\Users\Admin\AppData\Local\NVIDIA Corporation
2018-01-19 20:05 - 2018-01-19 20:05 - 000000000 ____D C:\Users\Admin\AppData\Local\FortniteGame
2018-01-19 20:05 - 2018-01-19 20:05 - 000000000 ____D C:\Users\Admin\AppData\Local\CrashReportClient
2018-01-19 20:04 - 2018-01-19 20:04 - 000000000 ____D C:\Users\Teschke\AppData\Local\NVIDIA Corporation
2018-01-19 20:03 - 2018-01-19 20:03 - 000000000 ____D C:\Users\Teschke\AppData\Local\FortniteGame
2018-01-19 19:39 - 2018-01-19 19:39 - 000000000 ___DL C:\Users\Admin\AppData\LocalLow\PlayReady
2018-01-19 19:01 - 2018-01-19 19:02 - 000000000 ____D C:\Program Files\Epic Games
2018-01-19 18:56 - 2018-01-19 20:05 - 000000000 ____D C:\Users\Admin\AppData\Local\UnrealEngine
2018-01-19 18:56 - 2018-01-19 18:56 - 000000000 ____D C:\Users\Admin\AppData\Local\UnrealEngineLauncher
2018-01-19 18:56 - 2018-01-19 18:56 - 000000000 ____D C:\Users\Admin\AppData\Local\EpicGamesLauncher
2018-01-19 18:51 - 2018-01-19 18:51 - 032260096 _____ C:\Users\Teschke\Downloads\EpicInstaller-7.2.0-fortnite-b4c7450ecc744c899c12cef8180e72f1 (1).msi
2018-01-19 18:49 - 2018-01-19 20:03 - 000000000 ____D C:\Users\Teschke\AppData\Local\UnrealEngine
2018-01-19 18:49 - 2018-01-19 18:49 - 000000000 ____D C:\Users\Teschke\AppData\Local\UnrealEngineLauncher
2018-01-19 18:49 - 2018-01-19 18:49 - 000000000 ____D C:\Users\Teschke\AppData\Local\EpicGamesLauncher
2018-01-19 18:48 - 2018-01-19 18:48 - 000001242 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Epic Games Launcher.lnk
2018-01-19 18:48 - 2018-01-19 18:48 - 000001230 _____ C:\Users\Public\Desktop\Epic Games Launcher.lnk
2018-01-19 18:48 - 2007-04-04 18:53 - 000081768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_3.dll
2018-01-19 18:47 - 2018-01-19 18:52 - 000000000 ____D C:\ProgramData\Epic
2018-01-19 18:47 - 2018-01-19 18:47 - 000000000 ____D C:\Program Files (x86)\Epic Games
2018-01-19 18:45 - 2018-01-19 18:45 - 032260096 _____ C:\Users\Teschke\Downloads\EpicInstaller-7.2.0-fortnite-b4c7450ecc744c899c12cef8180e72f1.msi
2018-01-16 20:59 - 2018-01-16 20:59 - 000057879 _____ C:\Users\Teschke\Downloads\On_Jesus_Derrida_and_Dawkins_Rejoinder_t (1).pdf
2018-01-16 20:58 - 2018-01-16 20:58 - 000057879 _____ C:\Users\Teschke\Downloads\On_Jesus_Derrida_and_Dawkins_Rejoinder_t.pdf
2018-01-07 14:20 - 2018-01-07 14:20 - 000562772 _____ C:\Users\Teschke\Downloads\NP_EX16_2b_IsaacTeschke_1.xlsx
2018-01-07 14:02 - 2018-01-07 14:02 - 000022355 _____ C:\Users\Teschke\Downloads\NP_EX16_1b_IsaacTeschke_1.xlsx
2018-01-04 21:08 - 2017-12-31 21:21 - 005581544 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2018-01-04 21:08 - 2017-12-31 21:21 - 001680616 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2018-01-04 21:08 - 2017-12-31 21:21 - 000948968 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys
2018-01-04 21:08 - 2017-12-31 21:21 - 000708328 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2018-01-04 21:08 - 2017-12-31 21:21 - 000288488 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fltMgr.sys
2018-01-04 21:08 - 2017-12-31 21:21 - 000262376 _____ (Microsoft Corporation) C:\Windows\system32\hal.dll
2018-01-04 21:08 - 2017-12-31 21:21 - 000213736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdyboost.sys
2018-01-04 21:08 - 2017-12-31 21:21 - 000154856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2018-01-04 21:08 - 2017-12-31 21:21 - 000114408 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2018-01-04 21:08 - 2017-12-31 21:21 - 000095464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2018-01-04 21:08 - 2017-12-31 21:19 - 001665384 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 014183936 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 002066432 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 002004480 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 001942016 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 001867776 _____ (Microsoft Corporation) C:\Windows\system32\ExplorerFrame.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 001741312 _____ (Microsoft Corporation) C:\Windows\system32\sysmain.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 001460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 001212928 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 001163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 001110528 _____ (Microsoft Corporation) C:\Windows\system32\schedsvc.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000977408 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000961024 _____ (Microsoft Corporation) C:\Windows\system32\actxprxy.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000880640 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000863232 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL
2018-01-04 21:08 - 2017-12-31 21:18 - 000842752 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000828928 _____ (Microsoft Corporation) C:\Windows\system32\MPSSVC.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000749568 _____ (Microsoft Corporation) C:\Windows\system32\FirewallAPI.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000731648 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000705024 _____ (Microsoft Corporation) C:\Windows\system32\BFE.DLL
2018-01-04 21:08 - 2017-12-31 21:18 - 000690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000512000 _____ (Microsoft Corporation) C:\Windows\system32\rpcss.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000473600 _____ (Microsoft Corporation) C:\Windows\system32\taskcomp.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000463872 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000444928 _____ (Microsoft Corporation) C:\Windows\system32\winhttp.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000439296 _____ (Microsoft Corporation) C:\Windows\system32\p2psvc.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000419840 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000366592 _____ (Microsoft Corporation) C:\Windows\system32\wcncsvc.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000361984 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000345600 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000327168 _____ (Microsoft Corporation) C:\Windows\system32\pnrpsvc.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000324096 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL
2018-01-04 21:08 - 2017-12-31 21:18 - 000316928 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000303104 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000264704 _____ (Microsoft Corporation) C:\Windows\system32\P2P.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000223232 _____ (Microsoft Corporation) C:\Windows\system32\ncsi.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000215552 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000190464 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000123904 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000120320 _____ (Microsoft Corporation) C:\Windows\system32\WcnApi.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000108544 _____ (Microsoft Corporation) C:\Windows\system32\icfupgd.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000101376 _____ (Microsoft Corporation) C:\Windows\system32\fdWCN.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000095744 _____ (Microsoft Corporation) C:\Windows\system32\rascfg.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000084480 _____ (Microsoft Corporation) C:\Windows\system32\INETRES.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000076288 _____ (Microsoft Corporation) C:\Windows\system32\rasdiag.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000070656 _____ (Microsoft Corporation) C:\Windows\system32\nlaapi.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000070144 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000060928 _____ (Microsoft Corporation) C:\Windows\system32\ndptsp.tsp
2018-01-04 21:08 - 2017-12-31 21:18 - 000060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000059904 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000047104 _____ (Microsoft Corporation) C:\Windows\system32\kmddsp.tsp
2018-01-04 21:08 - 2017-12-31 21:18 - 000044032 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000041472 _____ (Microsoft Corporation) C:\Windows\system32\rasmxs.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000039424 _____ (Microsoft Corporation) C:\Windows\system32\traffic.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000034816 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000029696 _____ (Microsoft Corporation) C:\Windows\system32\rasser.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000026112 _____ (Microsoft Corporation) C:\Windows\system32\oleres.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000024576 _____ (Microsoft Corporation) C:\Windows\system32\WcnEapPeerProxy.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000024064 _____ (Microsoft Corporation) C:\Windows\system32\WcnEapAuthProxy.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000022528 _____ (Microsoft Corporation) C:\Windows\system32\wfapigp.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000016896 _____ (Microsoft Corporation) C:\Windows\system32\wshqos.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000013312 _____ (Microsoft Corporation) C:\Windows\system32\wshnetbs.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000008704 _____ (Microsoft Corporation) C:\Windows\system32\comcat.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml6r.dll
2018-01-04 21:08 - 2017-12-31 21:13 - 000631680 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2018-01-04 21:08 - 2017-12-31 21:04 - 000559616 _____ (Microsoft Corporation) C:\Windows\system32\spoolsv.exe
2018-01-04 21:08 - 2017-12-31 21:02 - 001314112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 012880384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 001499648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ExplorerFrame.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 001417728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 001390080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 001114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000741888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000666624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000666112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000554496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000463360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FirewallAPI.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000351744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winhttp.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000304640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\taskcomp.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000276992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wcncsvc.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000275456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000261120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000254464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000217600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\P2P.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000216576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL
2018-01-04 21:08 - 2017-12-31 21:00 - 000172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000162304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncsi.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000084480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\INETRES.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcrypt.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fdWCN.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000081408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rascfg.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rasdiag.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000052224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ndptsp.tsp
2018-01-04 21:08 - 2017-12-31 21:00 - 000043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\traffic.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000026112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleres.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6r.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 001806848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000644096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000309760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\actxprxy.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:55 - 000131584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\pacer.sys
2018-01-04 21:08 - 2017-12-31 20:55 - 000088576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\wanarp.sys
2018-01-04 21:08 - 2017-12-31 20:55 - 000058368 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndproxy.sys
2018-01-04 21:08 - 2017-12-31 20:55 - 000045056 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netbios.sys
2018-01-04 21:08 - 2017-12-31 20:55 - 000024064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndistapi.sys
2018-01-04 21:08 - 2017-12-31 20:54 - 004013800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2018-01-04 21:08 - 2017-12-31 20:54 - 003959016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2018-01-04 21:08 - 2017-12-31 20:54 - 000077312 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mpsdrv.sys
2018-01-04 21:08 - 2017-12-31 20:50 - 000455680 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2018-01-04 21:08 - 2017-12-31 20:49 - 000148480 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2018-01-04 21:08 - 2017-12-31 20:49 - 000064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2018-01-04 21:08 - 2017-12-31 20:49 - 000062464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2018-01-04 21:08 - 2017-12-31 20:49 - 000017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2018-01-04 21:08 - 2017-12-31 20:46 - 000338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2018-01-04 21:08 - 2017-12-31 20:45 - 000296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2018-01-04 21:08 - 2017-12-31 20:43 - 000086528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WcnApi.dll
2018-01-04 21:08 - 2017-12-31 20:43 - 000038912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kmddsp.tsp
2018-01-04 21:08 - 2017-12-31 20:43 - 000033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rasmxs.dll
2018-01-04 21:08 - 2017-12-31 20:43 - 000022528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rasser.dll
2018-01-04 21:08 - 2017-12-31 20:43 - 000020480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WcnEapPeerProxy.dll
2018-01-04 21:08 - 2017-12-31 20:43 - 000019968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WcnEapAuthProxy.dll
2018-01-04 21:08 - 2017-12-31 20:43 - 000018944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wfapigp.dll
2018-01-04 21:08 - 2017-12-31 20:43 - 000013824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshqos.dll
2018-01-04 21:08 - 2017-12-31 20:42 - 000460288 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys
2018-01-04 21:08 - 2017-12-31 20:42 - 000406016 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys
2018-01-04 21:08 - 2017-12-31 20:42 - 000168448 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys
2018-01-04 21:08 - 2017-12-31 20:42 - 000159744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2018-01-04 21:08 - 2017-12-31 20:41 - 000754176 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys
2018-01-04 21:08 - 2017-12-31 20:41 - 000291328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2018-01-04 21:08 - 2017-12-31 20:41 - 000129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2018-01-04 21:08 - 2017-12-31 20:41 - 000112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2018-01-04 21:08 - 2017-12-31 20:41 - 000106496 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dfsc.sys
2018-01-04 21:08 - 2017-12-31 20:41 - 000030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2018-01-04 21:08 - 2017-12-31 20:41 - 000007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comcat.dll
2018-01-04 21:08 - 2017-12-31 20:39 - 000050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2018-01-04 21:08 - 2017-12-31 20:36 - 000025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2018-01-04 21:08 - 2017-12-31 20:36 - 000014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2018-01-04 21:08 - 2017-12-31 20:36 - 000007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2018-01-04 21:08 - 2017-12-31 20:36 - 000002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2018-01-04 21:08 - 2017-12-31 20:35 - 000036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
2018-01-04 21:08 - 2017-12-31 20:35 - 000006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:35 - 000004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:35 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:35 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2018-01-04 21:08 - 2017-12-30 02:29 - 000395968 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2018-01-04 21:08 - 2017-12-30 01:42 - 000347328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2018-01-04 21:08 - 2017-12-29 13:39 - 020274688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2018-01-04 21:08 - 2017-12-29 13:24 - 002724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2018-01-04 21:08 - 2017-12-29 13:13 - 000499712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2018-01-04 21:08 - 2017-12-29 13:13 - 000062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2018-01-04 21:08 - 2017-12-29 13:12 - 000341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2018-01-04 21:08 - 2017-12-29 13:12 - 000047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2018-01-04 21:08 - 2017-12-29 13:11 - 000064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2018-01-04 21:08 - 2017-12-29 13:09 - 002294272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2018-01-04 21:08 - 2017-12-29 13:06 - 000047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2018-01-04 21:08 - 2017-12-29 13:06 - 000030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2018-01-04 21:08 - 2017-12-29 13:04 - 000476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2018-01-04 21:08 - 2017-12-29 13:03 - 000662528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2018-01-04 21:08 - 2017-12-29 13:03 - 000620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2018-01-04 21:08 - 2017-12-29 13:03 - 000115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2018-01-04 21:08 - 2017-12-29 12:55 - 000416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2018-01-04 21:08 - 2017-12-29 12:51 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2018-01-04 21:08 - 2017-12-29 12:50 - 000091136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2018-01-04 21:08 - 2017-12-29 12:50 - 000073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2018-01-04 21:08 - 2017-12-29 12:47 - 000168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2018-01-04 21:08 - 2017-12-29 12:47 - 000076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2018-01-04 21:08 - 2017-12-29 12:46 - 000279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2018-01-04 21:08 - 2017-12-29 12:45 - 004508160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2018-01-04 21:08 - 2017-12-29 12:44 - 000130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2018-01-04 21:08 - 2017-12-29 12:39 - 000230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2018-01-04 21:08 - 2017-12-29 12:38 - 013680128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2018-01-04 21:08 - 2017-12-29 12:38 - 000694272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2018-01-04 21:08 - 2017-12-29 12:37 - 002058752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2018-01-04 21:08 - 2017-12-29 12:36 - 001155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2018-01-04 21:08 - 2017-12-29 12:19 - 002767872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2018-01-04 21:08 - 2017-12-29 12:15 - 001313792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2018-01-04 21:08 - 2017-12-29 12:13 - 000710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2018-01-04 21:08 - 2017-12-29 04:15 - 025737728 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2018-01-04 21:08 - 2017-12-29 04:04 - 002724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2018-01-04 21:08 - 2017-12-29 04:04 - 000004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2018-01-04 21:08 - 2017-12-29 03:52 - 002900480 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2018-01-04 21:08 - 2017-12-29 03:51 - 005796352 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2018-01-04 21:08 - 2017-12-29 03:51 - 000066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2018-01-04 21:08 - 2017-12-29 03:50 - 000577024 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2018-01-04 21:08 - 2017-12-29 03:50 - 000417280 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2018-01-04 21:08 - 2017-12-29 03:50 - 000088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2018-01-04 21:08 - 2017-12-29 03:50 - 000048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2018-01-04 21:08 - 2017-12-29 03:44 - 000054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2018-01-04 21:08 - 2017-12-29 03:43 - 000034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2018-01-04 21:08 - 2017-12-29 03:40 - 000615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2018-01-04 21:08 - 2017-12-29 03:39 - 000817152 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2018-01-04 21:08 - 2017-12-29 03:39 - 000814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2018-01-04 21:08 - 2017-12-29 03:39 - 000144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2018-01-04 21:08 - 2017-12-29 03:39 - 000116224 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2018-01-04 21:08 - 2017-12-29 03:32 - 000969216 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2018-01-04 21:08 - 2017-12-29 03:28 - 000489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2018-01-04 21:08 - 2017-12-29 03:22 - 000087552 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2018-01-04 21:08 - 2017-12-29 03:22 - 000077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2018-01-04 21:08 - 2017-12-29 03:21 - 000107520 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2018-01-04 21:08 - 2017-12-29 03:18 - 000199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2018-01-04 21:08 - 2017-12-29 03:18 - 000092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2018-01-04 21:08 - 2017-12-29 03:16 - 000315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2018-01-04 21:08 - 2017-12-29 03:14 - 000152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2018-01-04 21:08 - 2017-12-29 03:05 - 000262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2018-01-04 21:08 - 2017-12-29 03:04 - 015284224 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2018-01-04 21:08 - 2017-12-29 03:03 - 000807936 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2018-01-04 21:08 - 2017-12-29 03:03 - 000726528 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2018-01-04 21:08 - 2017-12-29 03:01 - 002134528 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2018-01-04 21:08 - 2017-12-29 03:01 - 001359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2018-01-04 21:08 - 2017-12-29 02:50 - 003241472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2018-01-04 21:08 - 2017-12-29 02:39 - 001545728 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2018-01-04 21:08 - 2017-12-29 02:27 - 000800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2018-01-04 21:08 - 2017-12-21 01:27 - 000634312 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
2018-01-04 21:08 - 2017-12-13 11:31 - 000383720 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2018-01-04 21:08 - 2017-12-13 11:27 - 000100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2018-01-04 21:08 - 2017-12-13 11:27 - 000046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2018-01-04 21:08 - 2017-12-13 11:27 - 000041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2018-01-04 21:08 - 2017-12-13 11:27 - 000014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2018-01-04 21:08 - 2017-12-13 11:15 - 000309480 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2018-01-04 21:08 - 2017-12-13 11:11 - 000071168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2018-01-04 21:08 - 2017-12-13 11:11 - 000025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
2018-01-04 21:08 - 2017-12-13 11:11 - 000010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
2018-01-04 21:08 - 2017-12-13 10:50 - 000034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2018-01-04 21:08 - 2017-12-05 12:36 - 000625664 _____ (Microsoft Corporation) C:\Windows\system32\mscms.dll
2018-01-04 21:08 - 2017-12-05 12:36 - 000250880 _____ (Microsoft Corporation) C:\Windows\system32\icm32.dll
2018-01-04 21:08 - 2017-12-05 12:36 - 000040960 _____ (Microsoft Corporation) C:\Windows\system32\WcsPlugInService.dll
2018-01-04 21:08 - 2017-12-05 12:08 - 000481792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscms.dll
2018-01-04 21:08 - 2017-12-05 12:08 - 000215040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icm32.dll
2018-01-04 21:08 - 2017-12-05 10:59 - 003222528 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2018-01-04 21:08 - 2017-12-05 10:49 - 000032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WcsPlugInService.dll
2018-01-04 19:50 - 2018-01-04 19:50 - 000053941 _____ C:\Users\Teschke\Downloads\NP_PPT16_1b_IsaacTeschke_1 (1).pptx
2018-01-02 12:51 - 2018-01-02 12:51 - 000099306 _____ C:\Users\Teschke\Downloads\340906__passairmangrace__tablehit-mono-bip.wav
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2018-01-27 13:38 - 2014-05-30 15:16 - 001095222 _____ C:\Windows\ntbtlog.txt
2018-01-27 13:38 - 2009-07-14 00:13 - 000782470 _____ C:\Windows\system32\PerfStringBackup.INI
2018-01-27 13:38 - 2009-07-13 22:20 - 000000000 ____D C:\Windows\inf
2018-01-27 13:35 - 2017-12-12 04:54 - 000046008 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2018-01-27 12:41 - 2013-04-20 14:11 - 000000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2018-01-27 12:41 - 2009-07-13 23:45 - 000022656 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2018-01-27 12:41 - 2009-07-13 23:45 - 000022656 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2018-01-27 12:33 - 2017-12-12 04:53 - 000110016 _____ (Malwarebytes) C:\Windows\system32\Drivers\farflt.sys
2018-01-27 12:31 - 2009-07-14 00:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2018-01-27 11:33 - 2017-11-05 20:22 - 000001690 _____ C:\Users\Admin\Desktop\Rkill.txt
2018-01-26 19:35 - 2013-08-25 20:48 - 000000000 ____D C:\Program Files (x86)\McAfee
2018-01-26 19:34 - 2017-01-14 13:55 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
2018-01-26 19:33 - 2015-09-22 22:11 - 000065536 _____ C:\Windows\system32\spu_storage.bin
2018-01-26 15:10 - 2013-04-21 13:55 - 000000000 ____D C:\Users\Teschke\AppData\Local\CrashDumps
2018-01-25 19:53 - 2013-04-18 07:01 - 000000000 ____D C:\Users\Teschke\Documents\Outlook Files
2018-01-25 19:31 - 2013-04-18 00:03 - 000001236 __RSH C:\Users\Teschke\ntuser.pol
2018-01-25 19:31 - 2013-04-17 20:06 - 000000000 ____D C:\Users\Teschke
2018-01-25 19:14 - 2013-04-18 00:07 - 000001232 __RSH C:\Users\Admin\ntuser.pol
2018-01-25 19:14 - 2013-04-18 00:07 - 000000000 ____D C:\Users\Admin
2018-01-25 19:08 - 2009-07-13 22:20 - 000000000 ____D C:\Windows\registration
2018-01-25 13:12 - 2013-04-20 15:39 - 000000000 ____D C:\Users\Teschke\Documents\Laura
2018-01-24 15:48 - 2013-04-20 14:11 - 000002224 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2018-01-23 17:29 - 2017-07-09 12:08 - 000000000 ____D C:\Users\Teschke\AppData\Local\Spotify
2018-01-23 16:54 - 2017-07-09 12:02 - 000000000 ____D C:\Users\Teschke\AppData\Roaming\Spotify
2018-01-23 11:29 - 2013-04-20 15:50 - 000000000 ____D C:\Users\Teschke\Documents\Isaac
2018-01-23 10:57 - 2014-02-17 18:02 - 001446400 ___SH C:\Users\Teschke\Downloads\Thumbs.db
2018-01-19 18:51 - 2014-11-24 21:35 - 000000000 ____D C:\ProgramData\Package Cache
2018-01-19 03:02 - 2013-04-18 00:33 - 000775462 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2018-01-18 17:03 - 2017-11-05 20:21 - 000009216 ___SH C:\Users\Teschke\Thumbs.db
2018-01-13 06:44 - 2013-04-20 15:28 - 000000000 ____D C:\Program Files (x86)\Steam
2018-01-12 20:50 - 2013-09-28 20:10 - 000000000 ____D C:\Users\Teschke\Documents\Corel VideoStudio Pro
2018-01-10 03:19 - 2013-07-12 17:33 - 000000000 ____D C:\Windows\system32\MRT
2018-01-10 03:13 - 2017-10-12 02:11 - 129365736 ____C (Microsoft Corporation) C:\Windows\system32\MRT-KB890830.exe
2018-01-10 03:13 - 2013-04-19 08:17 - 129365736 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2018-01-09 10:40 - 2017-09-28 16:34 - 000004468 _____ C:\Windows\System32\Tasks\Adobe Flash Player PPAPI Notifier
2018-01-09 10:40 - 2013-04-19 07:28 - 000803328 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2018-01-09 10:40 - 2013-04-19 07:28 - 000144896 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2018-01-09 10:40 - 2013-04-19 07:28 - 000004312 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2018-01-09 10:40 - 2013-04-19 07:28 - 000000000 ____D C:\Windows\system32\Macromed
2018-01-09 10:40 - 2013-04-17 22:41 - 000000000 ____D C:\Windows\SysWOW64\Macromed
2018-01-05 04:11 - 2009-07-13 22:20 - 000000000 ____D C:\Windows\rescache
2018-01-05 03:21 - 2009-07-13 23:45 - 000532872 _____ C:\Windows\system32\FNTCACHE.DAT
2018-01-04 16:59 - 2009-07-13 22:20 - 000000000 ____D C:\Windows\system32\NDF
2018-01-01 00:36 - 2009-07-14 00:08 - 000032542 _____ C:\Windows\Tasks\SCHEDLGU.TXT
 
==================== Files in the root of some directories =======
 
2014-09-30 19:18 - 2015-10-05 05:49 - 000000096 _____ () C:\Users\Teschke\AppData\Roaming\LauncherSettings_live.cfg
2014-09-30 18:25 - 2015-10-05 05:33 - 000000039 _____ () C:\Users\Teschke\AppData\Roaming\TheHunterSettings_live.cfg
2014-03-06 15:07 - 2014-03-06 15:07 - 000003584 _____ () C:\Users\Teschke\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2013-12-29 20:09 - 2013-12-29 20:09 - 000000084 _____ () C:\Users\Teschke\AppData\Local\DVDPATH.TXT
 
Some files in TEMP:
====================
2016-10-15 05:44 - 2015-01-26 11:34 - 000015752 _____ (Autodesk, Inc.) C:\Users\Admin\AppData\Local\Temp\AcDeltree.exe
2017-05-26 21:46 - 2017-05-26 22:10 - 002016632 _____ (Flexera Software LLC) C:\Users\Admin\AppData\Local\Temp\FNP_ACT_InstallerCA.dll
2017-09-10 21:11 - 2017-09-10 21:12 - 000004608 _____ () C:\Users\Admin\AppData\Local\Temp\i4jdel0.exe
2016-11-16 06:28 - 2016-11-16 06:28 - 000244264 _____ (McAfee, Inc.) C:\Users\Admin\AppData\Local\Temp\McCSPInstall.dll
2015-09-22 21:36 - 2015-09-22 21:47 - 060685368 _____ () C:\Users\Admin\AppData\Local\Temp\raptrpatch.exe
2015-09-22 21:36 - 2015-09-22 21:36 - 000221632 _____ () C:\Users\Admin\AppData\Local\Temp\raptr_stub.exe
2006-05-24 12:10 - 2006-05-24 12:10 - 000455600 ____R (Macrovision Corporation) C:\Users\Admin\AppData\Local\Temp\_is897B.exe
2014-01-05 01:00 - 2014-01-05 01:00 - 000003584 _____ () C:\Users\Teschke\AppData\Local\Temp\2supyjld.dll
2013-04-27 10:50 - 2013-04-27 10:50 - 000263186 _____ () C:\Users\Teschke\AppData\Local\Temp\air97CE.exe
2013-05-25 15:00 - 2013-05-25 15:00 - 000263186 _____ () C:\Users\Teschke\AppData\Local\Temp\airAA45.exe
2014-02-15 20:01 - 2014-02-15 20:01 - 000588360 _____ (NCH Software) C:\Users\Teschke\AppData\Local\Temp\bwsetup.exe
2014-08-20 20:25 - 2014-08-20 20:25 - 003166208 _____ () C:\Users\Teschke\AppData\Local\Temp\ffmpeg19.exe
2016-01-30 23:16 - 2016-01-30 23:20 - 023334528 _____ (Hola Networks Ltd.) C:\Users\Teschke\AppData\Local\Temp\Hola-Setup-Plugin-x64-1.11.399.exe
2013-10-30 17:52 - 2013-10-30 17:52 - 001071584 _____ (Solid State Networks) C:\Users\Teschke\AppData\Local\Temp\install_flashplayer11x32ax_chra_awa_aih.exe
2013-11-28 12:24 - 2013-11-28 12:24 - 001071584 _____ (Solid State Networks) C:\Users\Teschke\AppData\Local\Temp\install_flashplayer11x32ax_gtba_chra_dy_aaa_aih.exe
2013-11-28 12:28 - 2013-11-28 12:28 - 001071584 _____ (Solid State Networks) C:\Users\Teschke\AppData\Local\Temp\install_flashplayer11x32ax_gtba_chra_dy_aaa_aih_1.exe
2013-10-08 15:36 - 2013-10-08 15:36 - 001071568 _____ (Solid State Networks) C:\Users\Teschke\AppData\Local\Temp\install_reader11_en_chra_awa_aih.exe
2014-02-25 18:48 - 2014-02-25 18:48 - 001069920 _____ (Solid State Networks) C:\Users\Teschke\AppData\Local\Temp\install_reader11_en_chra_awa_aih_1.exe
2013-05-21 21:24 - 2013-05-21 21:24 - 002137632 _____ (Solid State Networks) C:\Users\Teschke\AppData\Local\Temp\install_reader11_en_gtbp_chra_aih.exe
2013-06-26 11:56 - 2013-06-26 11:56 - 001037120 _____ (Solid State Networks) C:\Users\Teschke\AppData\Local\Temp\install_reader11_en_mssa_aaa_aih.exe
2016-09-23 19:22 - 2016-09-23 19:26 - 083528440 _____ () C:\Users\Teschke\AppData\Local\Temp\mpa03944.exe
2013-07-12 21:08 - 2013-07-12 21:08 - 004120976 _____ (Black Tree Gaming                                           ) C:\Users\Teschke\AppData\Local\Temp\Nexus%20Mod%20Manager-0.45.4.exe
2013-08-03 23:47 - 2013-08-03 23:47 - 000008192 _____ () C:\Users\Teschke\AppData\Local\Temp\odn6esre.dll
2014-08-09 20:04 - 2014-08-09 20:04 - 000518208 _____ (NCH Software) C:\Users\Teschke\AppData\Local\Temp\pixsetup.exe
2014-04-21 16:29 - 2014-04-21 16:29 - 000339544 _____ (NCH Software) C:\Users\Teschke\AppData\Local\Temp\ppsetup.exe
2014-08-20 20:23 - 2014-08-20 20:23 - 000589888 _____ (NCH Software) C:\Users\Teschke\AppData\Local\Temp\prismsetup.exe
2013-07-21 00:00 - 2013-07-21 00:00 - 000003584 _____ () C:\Users\Teschke\AppData\Local\Temp\q64mjujk.dll
2016-09-23 19:26 - 2016-09-23 19:26 - 083528440 _____ () C:\Users\Teschke\AppData\Local\Temp\Setup-Wacom.exe
2015-01-31 10:16 - 2016-04-08 14:58 - 046965376 _____ (Skype Technologies S.A.) C:\Users\Teschke\AppData\Local\Temp\SkypeSetup.exe
2014-04-21 16:27 - 2014-04-21 16:27 - 000418352 _____ (NCH Software) C:\Users\Teschke\AppData\Local\Temp\tnsetup.exe
2014-02-15 20:00 - 2014-02-15 20:00 - 000367192 _____ (NCH Software) C:\Users\Teschke\AppData\Local\Temp\twelvekeyssetup.exe
2015-10-02 15:18 - 2016-01-10 18:25 - 013110615 _____ (Acresso Software Inc.) C:\Users\Teschke\AppData\Local\Temp\ubi444B.tmp.exe
2016-01-13 16:46 - 2016-01-14 16:47 - 004004004 _____ (Acresso Software Inc.) C:\Users\Teschke\AppData\Local\Temp\ubiEDD6.tmp.exe
2014-02-15 20:00 - 2014-02-15 20:00 - 000752176 _____ (NCH Software) C:\Users\Teschke\AppData\Local\Temp\vxlsetup.exe
2014-02-15 19:59 - 2014-02-15 19:59 - 001003568 _____ (NCH Software) C:\Users\Teschke\AppData\Local\Temp\wpsetup.exe
 
==================== Bamital & volsnap ======================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
 
LastRegBack: 2018-01-18 01:44
 
==================== End of FRST.txt ============================


BC AdBot (Login to Remove)

 


#2 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 36,617 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:07:50 PM

Posted 27 January 2018 - 03:45 PM

Greetings Dustint and :welcome: to BleepingComputer's Virus/Trojan/Spyware/Malware Removal forum.

My name is Oh My! and I am here to help you! Now that we are "friends" please call me Gary.

If you would allow me to call you by your first name I would prefer to do that.

===================================================

Ground Rules:
  • First, I would like to inform you that most of us here at Bleeping Computer offer our expert assistance out of the goodness of our hearts. Please try to match our commitment to you with your patience toward us. If this was easy we would never have met.
  • Please do not run any tools or take any steps other than those I will provide for you while we work on your computer together. I need to be certain about the state of your computer in order to provide appropriate and effective steps for you to take. Most often "well intentioned" (and usually panic driven!) independent efforts can make things much worse for both of us. If at any point you would prefer to take your own steps please let me know, I will not be offended. I would be happy to focus on the many others who are waiting in line for assistance.
  • Please perform all steps in the order they are listed in each set of instructions. Some steps may be a bit complicated. If things are not clear, be sure to stop and let me know. We need to work on this together with confidence.
  • Please copy and paste all logs into your post unless directed otherwise. Please do not re-run any programs I suggest. If you encounter problems simply stop and tell me.
  • If you do not reply to your topic after 5 days we assume it has been abandoned and I will close it.
  • When your computer is clean I will alert you of such. I will also provide for you detailed information about how you can combat future infections.
  • I would like to remind you to make no further changes to your computer unless I direct you to do so.
===================================================

Now that I am assisting you, you can expect that I will be very responsive to your situation. If you are able, I would request you check this thread at least once per day so that we can try to resolve your issues effectively and efficiently. If you are going to be delayed please be considerate and post that information so that I know you are still with me. Unfortunately, there are many people waiting to be assisted and not enough of us at BleepingComputer to go around. I appreciate your understanding and diligence.

Thank you for your patience thus far. There should be an Addition.txt document on your Desktop. Please copy and past that information in a reply.
Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#3 Dustint

Dustint
  • Topic Starter

  • Members
  • 26 posts
  • OFFLINE
  •  
  • Local time:09:50 PM

Posted 27 January 2018 - 04:18 PM

Thanks Gary, You can use Dustin, my first name. Appreciate the quick reply. Sorry, I was having trouble adding the 2nd text file didn't get added to the first post. My browser is doing strange things as previously mentioned. Here it is. Also I just wanted to mention that I ran the scan in safe mode. Let me know if you need me to re-run it in normal mode.

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 27.01.2018
Ran by Teschke (27-01-2018 13:41:28)
Running from C:\Users\Teschke\Desktop
Windows 7 Home Premium Service Pack 1 (X64) (2013-04-18 01:06:13)
Boot Mode: Safe Mode (with Networking)
==========================================================
 
 
==================== Accounts: =============================
 
Admin (S-1-5-21-3289118944-4034126387-1954186238-1003 - Administrator - Enabled) => C:\Users\Admin
Administrator (S-1-5-21-3289118944-4034126387-1954186238-500 - Administrator - Disabled)
Guest (S-1-5-21-3289118944-4034126387-1954186238-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3289118944-4034126387-1954186238-1002 - Limited - Enabled)
Teschke (S-1-5-21-3289118944-4034126387-1954186238-1000 - Administrator - Enabled) => C:\Users\Teschke
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Malwarebytes (Enabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B}
AS: Malwarebytes (Enabled - Up to date) {98619B37-4FC4-67F2-1C99-EEF6D47DBD96}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov)
Ace of Spades (HKLM-x32\...\{6037B8AD-7D5B-4D50-9BCA-A586C44EEF34}) (Version: 0.75.015 - Ben Aksoy)
ACP Application (HKLM\...\{DD93B141-69A7-A8FD-6963-266D02E9C07B}) (Version: 2.15.20.0015 - Advanced Micro Devices, Inc.) Hidden
Adobe Flash Player 28 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 28.0.0.137 - Adobe Systems Incorporated)
Adobe Flash Player 28 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 28.0.0.137 - Adobe Systems Incorporated)
Adobe Flash Player 28 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 28.0.0.137 - Adobe Systems Incorporated)
Adobe Photoshop Lightroom 5.2 64-bit (HKLM\...\{54E6C675-3AD4-42E4-957F-31666ABF1603}) (Version: 5.2.1 - Adobe)
Adobe Reader XI (11.0.03) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.03 - Adobe Systems Incorporated)
AMD Catalyst Install Manager (HKLM\...\{8F62BC70-DBB4-802D-1E1E-13630D9BA4D2}) (Version: 8.0.916.0 - Advanced Micro Devices, Inc.)
ANT Drivers Installer x64 (HKLM\...\{431CE782-4C51-4996-B36F-5D98D5527538}) (Version: 2.3.4 - Garmin Ltd or its subsidiaries) Hidden
Apple Application Support (32-bit) (HKLM-x32\...\{FE5C2FAA-118D-4509-B51D-3F71CC9E1B3E}) (Version: 4.3 - Apple Inc.)
Apple Application Support (64-bit) (HKLM\...\{2937FD88-C9D6-4B82-B539-37CD0A572F42}) (Version: 4.3 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{2E4AF2A6-50EA-4260-9BA4-5E582D11879A}) (Version: 9.3.0.15 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{56EC47AA-5813-4FF6-8E75-544026FBEA83}) (Version: 2.2.0.150 - Apple Inc.)
Assassin's Creed III 1.01 (HKLM-x32\...\{9D15E813-0C26-41E7-ABC5-3EB06FF1B3CF}) (Version: 1.01 - Ubisoft)
Autodesk Configurator 360 addin (HKLM-x32\...\{563941AA-C055-4FAA-8B04-A4E024A61F7E}) (Version: 20.0.10300 - Autodesk)
Autodesk Design Review 2013 (HKLM-x32\...\{153DB567-6FF3-49AD-AC4F-86F8A3CCFDFB}) (Version: 13.0.0.82 - Autodesk, Inc.) Hidden
Autodesk Design Review 2013 (HKLM-x32\...\Autodesk Design Review 2013) (Version: 13.0.0.82 - Autodesk, Inc.)
Battle.net (HKLM-x32\...\Battle.net) (Version:  - Blizzard Entertainment)
Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
BookSmart® 3.4.9 3.4.9 (HKLM-x32\...\BookSmart® 3.4.9 3.4.9) (Version:  - Blurb, Inc)
Boris Graffiti 6 for Corel VideoStudio Pro (HKLM-x32\...\{F4310AE4-A789-4602-AA48-CFA03D73A9F4}) (Version: 6.1.0003 - Boris FX, Inc.)
Boris Graffiti 7 for Corel VideoStudio Pro X9 64-Bit (HKLM\...\{9C246583-D390-4910-B740-431F89FACC2E}) (Version: 7.0.0001 - Boris FX, Inc.)
Brother MFL-Pro Suite DCP-7065DN (HKLM-x32\...\{3ACCCFB3-7B17-4E9F-ACB0-46868FCD4487}) (Version: 1.1.3.0 - Brother Industries, Ltd.)
Call of Duty - United Offensive (HKLM-x32\...\{A662E280-64A8-4CF5-8407-13D0808602B3}) (Version: 1.00.0000 - Activision) Hidden
Call of Duty - United Offensive (HKLM-x32\...\InstallShield_{A662E280-64A8-4CF5-8407-13D0808602B3}) (Version: 1.00.0000 - Activision)
Call of Duty (HKLM-x32\...\Call of Duty) (Version:  - )
Call of Duty® 4 - Modern Warfare™ (HKLM-x32\...\{E48469CC-635E-4FD5-A122-1497C286D217}) (Version: 1.6 - Activision) Hidden
Call of Duty® 4 - Modern Warfare™ (HKLM-x32\...\InstallShield_{E48469CC-635E-4FD5-A122-1497C286D217}) (Version: 1.6 - Activision)
CameraHelperMsi (HKLM-x32\...\{15634701-BACE-4449-8B25-1567DA8C9FD3}) (Version: 13.51.815.0 - Logitech) Hidden
Chrome Remote Desktop Host (HKLM-x32\...\{D61C8E6E-A4F3-4CD8-8568-51CEB5660C89}) (Version: 63.0.3239.32 - Google Inc.)
Cisco WebEx Meetings (HKU\S-1-5-21-3289118944-4034126387-1954186238-1000\...\ActiveTouchMeetingClient) (Version:  - Cisco WebEx LLC)
Contents (HKLM-x32\...\{EE0B1766-153A-4251-A192-F8FD3D941711}) (Version: 16.1.0.45 - Corel Corporation) Hidden
Contents64 (HKLM\...\{C2D307EA-96F8-4F6E-880E-E244779D8477}) (Version: 19.5.0.35 - Corel Corporation) Hidden
Corel KPT Collection (HKLM-x32\...\{031338C0-4C21-4DAC-875B-26ACD7ADDF23}) (Version: 1.00.0000 - Corel Corporation) Hidden
Corel KPT Collection for PSPX4 (HKLM-x32\...\_{031338C0-4C21-4DAC-875B-26ACD7ADDF23}) (Version:  - Corel Corporation)
Corel Painter 13 - IPM (HKLM\...\{0B598D32-B873-4794-8F30-90C53CD562D7}) (Version: 13.1 - Corel Corporation) Hidden
Corel Painter 13 - IPM Content (HKLM\...\{9983025B-AA60-4CF3-9E6C-C48DB9CD2310}) (Version: 13.1 - Corel Corporation) Hidden
Corel Painter X3 (HKLM\...\_{EF449371-6B69-49C8-B789-76A0B0E3446B}) (Version: 13.0.1.920 - Corel Corporation)
Corel PaintShop Pro X4 (HKLM-x32\...\_{00580795-581C-4587-B9F2-37320D7AB37F}) (Version: 14.2.0.1 - Corel Corporation)
Corel PaintShop Pro X4 (HKLM-x32\...\{00AE1A2D-7BC2-4359-A0EC-E19F36E391BB}) (Version: 14.2.0.1 - Corel Corporation) Hidden
Corel PaintShop Pro X4 Ultimate Bonus Pack (HKLM-x32\...\_{45E8DDB3-8FEB-40DB-A6D7-3535392AA559}) (Version:  - Corel Corporation)
Corel PaintShop Pro X4 Ultimate Bonus Pack (HKLM-x32\...\{45E8DDB3-8FEB-40DB-A6D7-3535392AA559}) (Version: 1.00.0000 - Corel Corporation) Hidden
Corel VideoStudio Pro X6 (HKLM-x32\...\_{6688A246-F6E8-48AD-9806-8D5832E9F15D}) (Version: 16.1.0.45 - Corel Corporation)
Corel VideoStudio Ultimate X9 (HKLM-x32\...\_{EE80DAA0-0071-475C-A222-F1782888FC55}) (Version: 19.5.0.35 - Corel Corporation)
Crysis®3 (HKLM-x32\...\{4198AE83-A3C6-4C41-85C8-EC63E990696E}) (Version: 1.0.0.0 - Electronic Arts)
D3DX10 (HKLM-x32\...\{E09C4DB7-630C-4F06-A631-8EA7239923AF}) (Version: 15.4.2368.0902 - Microsoft) Hidden
DAIDE QuickStart (HKLM-x32\...\{FDE86B27-8B13-40CB-B0DA-A1CAB15C2929}) (Version: 6.0.1 - Jason van Hal)
Dell System Detect (HKU\S-1-5-21-3289118944-4034126387-1954186238-1000\...\73f463568823ebbe) (Version: 6.6.0.2 - Dell)
digiCamControl (HKLM-x32\...\{19D12628-7654-4354-A305-9AB0A3502683}) (Version: 1.2.99.12 - Duka Istvan)
Eco Materials Adviser for Autodesk Inventor 2016 (64-bit) (HKLM\...\{1A56BE00-916E-432D-A576-EB00D2FF8450}) (Version: 5.6.4.44 - Granta Design Limited)
Elevated Installer (HKLM-x32\...\{7E73C9A3-24D9-4D7F-B4C7-7E4AFE0ADCCB}) (Version: 4.0.15.0 - Garmin Ltd or its subsidiaries) Hidden
Epic Games Launcher (HKLM-x32\...\{2B6AC31A-9883-465C-AFC6-1EC5AA48F5BD}) (Version: 1.1.138.0 - Epic Games, Inc.)
Epic Games Launcher Prerequisites (x64) (HKLM\...\{66C5838F-B854-4A55-89E6-A6138747A4DF}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
erLT (HKLM-x32\...\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}) (Version: 1.20.138.34 - Logitech, Inc.) Hidden
Far Cry (HKLM-x32\...\{D6DBDC2A-E72C-4284-B6AD-6B3B61B4DABC}) (Version: 1.00.0000 - Ubisoft) Hidden
Far Cry (HKLM-x32\...\InstallShield_{D6DBDC2A-E72C-4284-B6AD-6B3B61B4DABC}) (Version: 1.00.0000 - Ubisoft)
Far Cry 2 (HKLM-x32\...\{F2835483-37F2-4123-B4FE-0E77D58447F2}) (Version: 1.03.00 - Ubisoft)
FARO LS 1.1.501.0 (64bit) (HKLM-x32\...\{8A470330-70B2-49AD-86AF-79885EF9898A}) (Version: 5.1.0.30630 - FARO Scanner Production)
FARO LS 1.1.503.3 (64bit) (HKLM-x32\...\{1C05E654-FB81-4274-BF32-292E3707701D}) (Version: 5.3.3.38662 - FARO Scanner Production)
Garmin Communicator Plugin (HKLM-x32\...\{71DBFBF2-F7EB-4268-8485-9471D83C4E66}) (Version: 4.2.0 - Garmin Ltd or its subsidiaries)
Garmin Communicator Plugin x64 (HKLM\...\{70A381F1-C161-4D61-A20C-BE12FC6777DF}) (Version: 4.2.0 - Garmin Ltd or its subsidiaries)
Garmin Express (HKLM-x32\...\{50755d67-ae60-4e47-b3d6-ce44d01b5a95}) (Version: 4.0.15.0 - Garmin Ltd or its subsidiaries)
Garmin Express (HKLM-x32\...\{9FB8EC5B-03EE-463E-8F4F-84B525B986B7}) (Version: 4.0.15.0 - Garmin Ltd or its subsidiaries) Hidden
Garmin Express Tray (HKLM-x32\...\{1D91CBB5-4CB1-4757-B0FD-2122AF8AAB9E}) (Version: 4.0.15.0 - Garmin Ltd or its subsidiaries) Hidden
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 64.0.3282.119 - Google Inc.)
Google Earth Plug-in (HKLM-x32\...\{4AB54F11-2F8C-11E3-B09F-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
Google Earth Pro (HKLM-x32\...\{ECF2E224-42F5-4E50-B58E-94CA70E85697}) (Version: 7.3.0.3832 - Google)
Google Toolbar for Internet Explorer (HKLM-x32\...\{18455581-E099-4BA8-BC6B-F34B2F06600C}) (Version: 1.0.0 - Google Inc.) Hidden
Google Toolbar for Internet Explorer (HKLM-x32\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.8231.2252 - Google Inc.)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.7 - Google Inc.) Hidden
Google Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.25.11 - Google Inc.) Hidden
Haali Media Splitter (HKLM-x32\...\HaaliMkx) (Version:  - )
ICA (HKLM-x32\...\{00580795-581C-4587-B9F2-37320D7AB37F}) (Version: 14.2.0.1 - Corel Corporation) Hidden
ICA (HKLM-x32\...\{6688A246-F6E8-48AD-9806-8D5832E9F15D}) (Version: 16.1.0.45 - Corel Corporation) Hidden
ICA (HKLM-x32\...\{EE80DAA0-0071-475C-A222-F1782888FC55}) (Version: 19.5.0.35 - Corel Corporation) Hidden
IconHandler 64 bit (HKLM\...\{4E82E2E9-668B-4F8A-814A-78E163FCDBCD}) (Version: 2.0 - Corel Corporation) Hidden
Intel® Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1118 - Intel Corporation)
Intel® Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 10.0.0.1046 - Intel Corporation)
IPM_PSP_COM (HKLM-x32\...\{00BEE329-BAAB-49FF-9B66-55E4B12B9ADD}) (Version: 14.2.0.1 - Corel Corporation) Hidden
IPM_VS_Pro (HKLM-x32\...\{CCC10E8E-7FD1-4D55-87C2-D0A5ABC0A62B}) (Version: 16.0 - Corel Corporation) Hidden
IPM_VS_Pro64 (HKLM\...\{1BD7EE90-7C52-4142-B4DD-55C4F28F9EE7}) (Version: 19.0 - Corel Corporation) Hidden
iTunes (HKLM\...\{A31C5565-90D9-4615-AE13-94D86C3836C7}) (Version: 12.3.3.17 - Apple Inc.)
Java 8 Update 25 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218025F0}) (Version: 8.0.250 - Oracle Corporation)
LAME v3.99.3 (for Windows) (HKLM-x32\...\LAME_is1) (Version:  - )
Launcher Prerequisites (x64) (HKLM-x32\...\{c6c5a357-c7ca-4a5f-9789-3bb1af579253}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
Lightworks (HKLM-x32\...\{E94DD4E4-7746-472c-AA7B-1242FED0CFC8}) (Version: 11.1.0.0 - Lightworks)
Logitech Webcam Software (HKLM-x32\...\{D40EB009-0499-459c-A8AF-C9C110766215}) (Version: 2.51 - Logitech Inc.)
Malwarebytes version 3.3.1.2183 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.3.1.2183 - Malwarebytes)
McAfee AntiVirus Plus (HKLM-x32\...\MSC) (Version: 16.0.2 - McAfee, Inc.)
McAfee Virtual Technician (HKLM-x32\...\McAfee Virtual Technician) (Version: 8.1.0.174 - McAfee, Inc.)
McAfee WebAdvisor (HKLM-x32\...\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}) (Version: 4.0.163 - McAfee, Inc.)
Medal of Honor Allied Assault (HKLM-x32\...\{0DEA94ED-915A-4834-A87E-388D012C8E02}) (Version:  - )
Medal of Honor Allied Assault™ Spearhead (HKLM-x32\...\{7914BE1E-F186-4790-B8F4-9F63C52A41C1}) (Version:  - )
Melody Assistant (HKLM-x32\...\Melody Assistant) (Version: 7.6.3i - Myriad SARL)
Microsoft .NET Framework 4.7 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.7.02053 - Microsoft Corporation)
Microsoft Access database engine 2010 (English) (HKLM\...\{90140000-00D1-0409-1000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Camera Codec Pack (HKLM\...\{D553E8CC-5C56-4B06-AC1A-A443DFF31092}) (Version: 6.3.9723.0 - Microsoft Corporation)
Microsoft Office Professional Plus 2010 (HKLM-x32\...\Office14.PROPLUSR) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50907.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729 (HKLM\...\{2DFD8316-9EF1-3210-908C-4CB61961C1AC}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{527BBE2F-1FED-3D8B-91CB-4DB0F838E69E}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\...\{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft WSE 3.0 Runtime (HKLM-x32\...\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}) (Version: 3.0.5305.0 - Microsoft Corp.)
Mixxx 2.0.0 (HKU\S-1-5-21-3289118944-4034126387-1954186238-1000\...\Mixxx (2.0.0)) (Version: 2.0.0 - The Mixxx Development Team)
Movie Maker (HKLM-x32\...\{38F03569-A636-4CF3-BDDE-032C8C251304}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Movie Maker (HKLM-x32\...\{DD67BE4B-7E62-4215-AFA3-F123A800A389}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Mozilla Firefox 43.0.1 (x86 en-US) (HKU\S-1-5-21-3289118944-4034126387-1954186238-1000\...\Mozilla Firefox 43.0.1 (x86 en-US)) (Version: 43.0.1 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation)
MyDVD Content Pack 1 (HKLM-x32\...\{ADCF7AE3-8E36-4B80-9460-66B74B56927F}) (Version: 1.00.0000 - Corel Corporation)
Myst Online: Uru Live (remove only) (HKLM-x32\...\MOUL) (Version:  - )
NETGEAR Genie (HKLM-x32\...\NETGEAR Genie) (Version: 2.4.12.00 - NETGEAR Inc.)
NewBlue Film Effects for Windows (HKLM-x32\...\NewBlue Film Effects for Windows) (Version: 3.0 - NewBlue)
Nexus Mod Manager (HKLM\...\6af12c54-643b-4752-87d0-8335503010de_is1) (Version: 0.45.2 - Black Tree Gaming)
Nik Collection (HKLM-x32\...\Nik Collection) (Version: 1.2.11 - Google)
Nuance PaperPort 12 (HKLM-x32\...\{6C0A559F-8583-4B5A-8B50-20BEE15D8E64}) (Version: 12.1.0000 - Nuance Communications, Inc.)
Nuance PDF Viewer Plus (HKLM-x32\...\{28656860-4728-433C-8AD4-D1A930437BC8}) (Version: 5.30.3290 - Nuance Communications, Inc)
NVIDIA PhysX (HKLM-x32\...\{3F5C371F-8EA2-4F25-9D3D-D0B4526E3AEA}) (Version: 9.10.0513 - NVIDIA Corporation)
Origin (HKLM-x32\...\Origin) (Version: 9.1.10.2728 - Electronic Arts, Inc.)
Painter 13 - Contentx64 (HKLM\...\{A16926CB-C4BF-4FC9-8F99-200236731FCA}) (Version: 13.1 - Corel Corporation) Hidden
Painter 13 - Core (HKLM\...\{B1EA198B-FF19-46C9-84DE-E2F3D11619ED}) (Version: 13.1 - Corel Corporation) Hidden
Painter 13 - Corex64 (HKLM\...\{DA929FB1-A118-4F6E-9AD6-729633E84805}) (Version: 13.0 - Corel Corporation) Hidden
Painter 13 - EN (HKLM\...\{61F6F8FC-C448-418E-BF14-8B272DFDD51B}) (Version: 13.1 - Corel Corporation) Hidden
Painter 13 - Setup Files (HKLM\...\{EF449371-6B69-49C8-B789-76A0B0E3446B}) (Version: 13.1 - Corel Corporation) Hidden
Pando Media Booster (HKLM-x32\...\{980A182F-E0A2-4A40-94C1-AE0C1235902E}) (Version: 2.6.0.7 - Pando Networks Inc.)
PaperPort Image Printer 64-bit (HKLM\...\{715CAACC-579B-4831-A5F4-A83A8DE3EFE2}) (Version: 1.00.0001 - Nuance Communications, Inc.)
Paradise (HKLM-x32\...\Paradise_is1) (Version:  - Ubisoft)
Pinnacle Instant DVD Recorder (HKLM-x32\...\{C1212AE3-DBB9-4365-8473-F8ABC7B06BBB}) (Version: 2.6.0.118 - Pinnacle Systems)
Pinnacle Studio 12 (HKLM-x32\...\{D041EB9E-890A-4098-8F94-51DA194AC72A}) (Version: 12.1.3.6605 - Pinnacle Systems)
Pinnacle Video Driver (HKLM\...\{6DE721A5-5E89-4D74-994C-652BB3C0672E}) (Version: 12.1.0.029 - Pinnacle Systems)
PitchPerfect Musical Instrument Tuner (HKU\S-1-5-21-3289118944-4034126387-1954186238-1000\...\PitchPerfect) (Version: 2.12 - NCH Software)
Pixillion Image Converter (HKU\S-1-5-21-3289118944-4034126387-1954186238-1000\...\Pixillion) (Version: 2.75 - NCH Software)
POW (HKLM-x32\...\{CD277B3E-8043-496E-B83B-D53186A072AB}) (Version: 1.00.0000 - Wide Games) Hidden
POW (HKLM-x32\...\InstallShield_{CD277B3E-8043-496E-B83B-D53186A072AB}) (Version: 1.00.0000 - Wide Games)
Prism Video File Converter (HKU\S-1-5-21-3289118944-4034126387-1954186238-1000\...\Prism) (Version: 2.18 - NCH Software)
proDAD Adorage 3.0 (64bit) (HKLM\...\proDAD-Adorage-3.0) (Version: 3.0.114.1 - proDAD GmbH) Hidden
proDAD Mercalli 2.0 (64bit) (HKLM\...\proDAD-Mercalli-2.0) (Version: 2.0.123 - proDAD GmbH) Hidden
proDAD Mercalli 2.0 (HKLM-x32\...\proDAD-Mercalli-2.0) (Version: 2.0.106 - proDAD GmbH) Hidden
proDAD Route 4.0 (64bit) (HKLM\...\proDAD-HeroglyphRoute-4.0) (Version: 4.0.241.1 - proDAD GmbH) Hidden
proDAD Route 4.0 (HKLM-x32\...\proDAD-HeroglyphRoute-4.0) (Version: 4.0.209.2 - proDAD GmbH) Hidden
proDAD Script 4.0 (64bit) (HKLM\...\proDAD-HeroglyphScript-4.0) (Version: 4.0.241.1 - proDAD GmbH) Hidden
proDAD Script 4.0 (HKLM-x32\...\proDAD-HeroglyphScript-4.0) (Version: 4.0.209.2 - proDAD GmbH) Hidden
proDAD Vitascene 2.0 (64bit) (HKLM\...\proDAD-Vitascene-2.0) (Version: 2.0.241 - proDAD GmbH) Hidden
proDAD Vitascene 2.0 (HKLM-x32\...\proDAD-Vitascene-2.0) (Version: 2.0.203 - proDAD GmbH) Hidden
PS3 Media Server (HKLM-x32\...\PS3 Media Server) (Version: 1.90.1 - PS3 Media Server)
PSPPContent (HKLM-x32\...\{006CAAEF-CA96-4181-AC22-FE56D61432E4}) (Version: 14.2.0.1 - Corel Corporation) Hidden
PSPPHelp (HKLM-x32\...\{00D74A7A-F7AD-4D00-ABD2-0973836292C7}) (Version: 14.2.0.1 - Corel Corporation) Hidden
PSPPro64 (HKLM\...\{0015DE8E-8D9F-403E-8E5A-4098410E6125}) (Version: 14.2.0.1 - Corel Corporation) Hidden
PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.986 - Even Balance, Inc.)
QuickTime 7 (HKLM-x32\...\{FF59BD75-466A-4D5A-AD23-AAD87C5FD44C}) (Version: 7.79.80.95 - Apple Inc.)
Raptr (HKLM-x32\...\Raptr) (Version: 5.2.3-r114633-release - Raptr, Inc)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6141 - Realtek Semiconductor Corp.)
Scansoft PDF Professional (HKLM-x32\...\{068724F8-D8BE-4B43-8DDD-B9FE9E49FD76}) (Version:  - ) Hidden
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version:  - Microsoft)
Setup (HKLM-x32\...\{00D13418-7DDF-4D3D-A237-E297B103BB6B}) (Version: 14.2.0.1 - Corel Corporation) Hidden
Setup (HKLM-x32\...\{6C6EEA9F-3998-4E0D-B91F-43CB218C715C}) (Version: 16.1.0.45 - Corel Corporation) Hidden
Setup (HKLM-x32\...\{F8B95E3C-40A0-49CE-B5F9-3861F238B9FF}) (Version: 19.5.0.35 - Corel Corporation) Hidden
Share (HKLM-x32\...\{AD7DA145-3118-4D69-BE89-D3ED1510BD15}) (Version: 16.1.0.45 - Corel Corporation) Hidden
Share64 (HKLM\...\{3008095C-B516-4A5E-8B99-F0E113C21C72}) (Version: 16.1.0.45 - Corel Corporation) Hidden
Share64 (HKLM\...\{A61EEC3A-E37C-49A5-BE61-7AEE04F1A15D}) (Version: 19.5.0.35 - Corel Corporation) Hidden
Shared C Run-time for x64 (HKLM\...\{EF79C448-6946-4D71-8134-03407888C054}) (Version: 10.0.0 - McAfee)
SketchUp 2013 (HKLM-x32\...\{B75BC01B-4586-43F8-9349-D250DB98F26F}) (Version: 13.0.4812 - Trimble Navigation Limited)
Skype™ 7.0 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.0.102 - Skype Technologies S.A.)
SmartSound Common Data (HKLM-x32\...\{B8A2869E-30CA-40C5-9CF8-BD7354E57EF8}) (Version: 1.1.0 - SmartSound Software Inc.) Hidden
SmartSound Common Data (HKLM-x32\...\InstallShield_{B8A2869E-30CA-40C5-9CF8-BD7354E57EF8}) (Version: 1.1.0 - SmartSound Software Inc.)
SmartSound Quicktracks 5 (HKLM-x32\...\{2F8BA3FD-1FA9-4279-B696-712ABB12F09F}) (Version: 5.1.6 - SmartSound Software Inc.) Hidden
SmartSound Quicktracks 5 (HKLM-x32\...\InstallShield_{2F8BA3FD-1FA9-4279-B696-712ABB12F09F}) (Version: 5.1.6 - SmartSound Software Inc.)
Spotify (HKU\S-1-5-21-3289118944-4034126387-1954186238-1000\...\Spotify) (Version: 1.0.72.117.g6bd7cc73 - Spotify AB)
StarCraft II (HKLM-x32\...\StarCraft II) (Version:  - Blizzard Entertainment)
Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation)
theHunter Launcher (HKLM-x32\...\FBDFBE7F-2DB8-47E2-B88E-32F4A2A74AA8_is1) (Version: 620 - Expansive Worlds)
Unity Web Player (HKU\S-1-5-21-3289118944-4034126387-1954186238-1000\...\UnityWebPlayer) (Version:  - Unity Technologies ApS)
Uplay (HKLM-x32\...\Uplay) (Version: 2.0 - Ubisoft)
VideoStudio MyDVD (HKLM-x32\...\{7521A578-BDF3-412C-8959-57498EBBEDD9}) (Version: 1.0.129 - Corel Corporation) Hidden
VideoStudio MyDVD (HKLM-x32\...\{91345797-EF07-41D2-85F4-BFF200B6A0A3}) (Version: 1.0 - Corel)
Visual C++ 2008 - x64 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{6DA2B636-698A-3294-BF4A-B5E11B238CDD}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation)
Visual C++ 2008 - x64 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{8CCEA24C-51AE-3B71-9092-7D0C44DDA2DF}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation)
Visual C++ 2008 - x64 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{C3A57BB3-9AA6-3F6F-9395-6C062BDD5FC4}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation)
Visual C++ 2008 - x64 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{F6F09DD8-F39B-3A16-ADB9-C9E6B56903F9}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation)
Visual C++ 2008 - x86 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{04B34E21-5BEE-3D2B-8D3D-E3E80D253F64}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation)
Visual C++ 2008 - x86 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{14866AAD-1F23-39AC-A62B-7091ED1ADE64}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation)
Visual C++ 2008 - x86 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{4B90093A-5D9C-3956-8ABB-95848BE6EFAD}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation)
Visual C++ 2008 - x86 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{B42E259C-E4D4-37F1-A1B2-EB9C4FC5A04D}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation)
VLC media player 2.0.8 (HKLM-x32\...\VLC media player) (Version: 2.0.8 - VideoLAN)
VSClassic (HKLM-x32\...\{D0096E50-D99E-4178-A988-E5192B6F6B91}) (Version: 16.1.0.45 - Corel Corporation) Hidden
VSClassic64 (HKLM\...\{99B95309-4793-43D9-8F1C-EC086FC74CB5}) (Version: 19.5.0.35 - Corel Corporation) Hidden
VSHelp (HKLM-x32\...\{D9DD0D4F-6E5A-484D-AD8C-FD3BAF5D4450}) (Version: 16.1.0.45 - Corel Corporation) Hidden
VSPro (HKLM-x32\...\{D88D7ECD-F173-4A97-96F9-2B05C5DC90DC}) (Version: 16.1.0.45 - Corel Corporation) Hidden
VSUltimate64 (HKLM\...\{3F5D769B-346B-487A-851A-A1AF147D5B39}) (Version: 19.5.0.35 - Corel Corporation) Hidden
Wacom Tablet (HKLM\...\Wacom Tablet Driver) (Version: 6.3.17-3 - Wacom Technology Corp.)
WebTablet FB Plugin 32 bit (HKLM-x32\...\Wacom WebTabletPlugin for Internet Explorer and Netscape) (Version: 2.1.0.7 - Wacom Technology Corp.)
WebTablet FB Plugin 64 bit (HKLM\...\Wacom WebTabletPlugin for Internet Explorer and Netscape) (Version: 2.1.0.7 - Wacom Technology Corp.)
Windows Driver Package - Dynastream Innovations, Inc. ANT LibUSB Drivers (04/11/2012 1.2.40.201) (HKLM\...\F9D2A789F9CFF8CEC36B544F53877C80F1F73C46) (Version: 04/11/2012 1.2.40.201 - Dynastream Innovations, Inc.)
Windows Driver Package - Silicon Labs Software (DSI_SiUSBXp_3_1) USB  (02/06/2007 3.1) (HKLM\...\D1506E0025B5A3F9EB8270FE81C1EEDD9388B8A2) (Version: 02/06/2007 3.1 - Silicon Labs Software)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation)
Windows Media Encoder 9 Series (HKLM-x32\...\Windows Media Encoder 9) (Version:  - )
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
HKU\S-1-5-21-3289118944-4034126387-1954186238-1000\...\ChromeHTML: ->  <==== ATTENTION
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{00F064D8-FEC3-48ac-B07D-39C314D1727B}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\ServiceModule.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{0215A4C0-5431-4FD0-9B06-46589B5C4939}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{048ED0E0-12CF-4C0F-9FFA-947C2FBE8C8E}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{071339A1-1946-44B2-B63E-50459B15DB86}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{073CB204-6B29-46FC-AB98-451F1D068741}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\TestServer.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{08A60FF7-BB37-44F4-9759-0ADA6C7B9CC9}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{0B38CACA-3D3C-48EA-BEB5-7D95F4F6EE15}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{0C3393F8-94F5-4B79-8C01-49A2D0CC0FE9}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{0D555CE0-304A-47A6-858B-B145209A3982}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{12545889-6D32-4424-9967-1E1D7BD1F809}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{13009989-EFB5-48C9-8BD2-943E0392BD71}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\RxAppCtrl.Ocx => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{14679E3B-C952-4998-8E13-4B1286E6DD99}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{1481B385-759A-4B00-9257-E96357563999}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{162EF0A1-5A33-46F2-ACCF-CA388B084A09}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{18A21864-E37B-42b9-9612-2C1E8C450A29}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\ServiceModule.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{1D625598-C876-4C51-8EF5-F9D8F96F62AA}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{1D6DFD6A-9E16-435A-9327-6FFEC6BA372F}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{1E5724EA-3423-4BD3-ABD6-46E650D2DC66}\InprocServer32 -> AcETransmit.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{1E8A29BA-827D-4031-A4A3-AE7999B402F6}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{1EA072EE-57FD-495E-889C-8243C3BDBDBC}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{1FD7F53F-7ED5-439C-9A77-A3821CD09E98}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{20E47D5B-529A-45BD-8E77-BF1A3064A008}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{21DB88B0-BFBF-11D4-8DE6-0010B541CAA8}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\iDrop.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{2709544A-5B24-4F9F-A5DA-CEC7297D3A4E}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{2BCA857B-A18B-4AFA-B183-CC0E49C12058}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{2C74F89E-7421-46B4-BA54-F86F1BD9F237}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{2C7D1157-7D50-4A88-9777-5EBBA3189AB8}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{2F8377FC-50C1-44EF-AB7A-8FF1BB8EA277}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\ServiceModule.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{3497C2EC-5684-4B21-AF74-F6760E0221DC}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{38C8B14E-7879-4DA9-8C3F-8CAAC359293A}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{3FC94EB5-AEBD-4f3f-A2A4-B6CE57113C01}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\RxAppDocView.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{3FCEB42C-9B98-486A-BED7-FD7F3ADB7291}\InprocServer32 -> AcETransmit.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{40770568-0D5E-49D4-BE47-BC47A4F0B0A4}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{44A52280-AE56-490D-890C-89FB7279ED6B}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{45122C53-8483-4b62-B15A-EAA9FE5FC3D5}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\ServiceModule.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{46C56738-39C6-4240-8B9B-008CCD769A84}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{47179DDE-10AC-4737-97C9-8CE5379343EA}\InprocServer32 -> AcETransmit.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{475C7B4A-6964-4F9E-9708-05A16EAC31D0}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{48270F9E-CCF6-4C79-B6FF-267C960E6425}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{48FEFCD7-5D7C-4E4A-9F11-60E69A31D4B1}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{49998808-648A-4A9C-A7A5-B1672775D9AB}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{4A756F5F-CBA4-428B-B17F-AF80C0C8502D}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{4B40437B-8972-4444-BBE3-1588FF55F203}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{4BD03680-3C0F-4501-AFF7-3D008586917F}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{4C80573A-9150-11d2-B772-0060B0F159EF}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\RxAppDocView.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{4D29B490-49B2-11D0-93C3-7E0706000000}\localserver32 -> "C:\Program Files\Autodesk\Inventor 2016\Bin\Inventor.exe" => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{4E6F2E83-E7F0-4333-9772-875EB733C820}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\RxTest.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{5544903C-2CCC-487C-91BB-F310B72A8E9B}\InprocServer32 -> AcETransmit.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{59A224A2-BEF8-4C89-96E0-83A5411ABB6C}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{622F6193-E4DD-46E6-BC66-2ED88E9FD28D}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{62FBB030-24C7-11D3-B78D-0060B0F159EF}\localserver32 -> "C:\Program Files\Autodesk\Inventor 2016\Bin\Inventor.exe" => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{644190AE-BD8F-493F-B63D-C79404AC5E07}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\ServiceModule.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{6451051B-AD22-4C6A-ACCE-013A0E1DDBC3}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{64B99FDB-1D85-447F-98C7-569DBDA723DB}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{6BCE6F6E-C050-4F39-BD98-E2743949F724}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{6F56D7C9-18DD-4C15-9FA8-C54E3610EC40}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{6FDE7A70-351B-11d6-988B-0010B57A8BB7}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\DtBridge.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{6FDE7A71-351B-11d6-988B-0010B57A8BB7}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\DtBridge.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{6FDE7A72-351B-11d6-988B-0010B57A8BB7}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\DtBridge.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{6FDE7A73-351B-11d6-988B-0010B57A8BB7}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\DtBridge.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{6FDE7A74-351B-11d6-988B-0010B57A8BB7}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\DtBridge.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{6FDE7A77-351B-11d6-988B-0010B57A8BB7}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\DtCp.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{70DBCAE8-8C2B-450C-9E1D-43E4686C6512}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{713C0E8A-5AE8-4695-B442-5ED6C4FE5C42}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{7293E009-3015-4AD3-96EC-D42C36B5FCE3}\InprocServer32 -> AcETransmit.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{72EC5CC5-88F3-45B1-A865-0A327DF58CC8}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\ServiceModule.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{72EFC580-D085-4B81-8C55-26A79E445338}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{750AEC19-2E4C-4ED9-9B9F-F9CAFCD060F3}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{794199C5-827C-41C8-8CB2-3A1EA056AF5E}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{798391FE-4AF2-4851-9DDA-1F0D70C02A9E}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{7BA16B3F-1AB3-4BD7-B959-52C4B8504EE9}\InprocServer32 -> AcInetUI.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{7C239DAB-BC87-45F3-B7B1-FCC1541A235B}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{81D07C3D-0350-11D3-B7C2-0060B0EC020B}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\RxAppCtrl.Ocx => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{834CE679-2E47-49DE-9E41-FEC87E9192EB}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{8421A29C-54B8-11D1-9837-0060B03C43C8}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\SolidObject.Dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{846217D0-8954-11D2-8DCD-0060B0C32531}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\UCxTextBtn.Ocx => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{846217D1-8954-11D2-8DCD-0060B0C32531}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\UCxTextBtn.Ocx => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{849AFB5B-D6C9-4924-A712-F7118FF9611F}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{85452F88-5071-492E-B850-2E3C586DCBD8}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{87F5CF8F-A06D-498F-A05F-E520E6B570DB}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{89F0FC31-3B1D-494B-A75B-6BD4FA527B8A}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{8AA16DFC-DFC6-4B51-8FA2-A5D812BE33BF}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{8B0E6BD9-610C-11D1-9842-0060B03C43C8}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\SolidObject.Dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{8C23B656-4E6E-4B45-9920-9617168D39A3}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\TestServer.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{8ED07FEF-E1B0-4CC3-B2BA-D354828AB952}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{988F4102-E6E3-4282-ACAC-55270827F2A8}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{9906CDFC-DB2C-4126-9422-13139B148495}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{9A21C6C5-27FC-4442-8590-575E7AFD73BB}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{9ECF83FB-23C5-43B6-83DE-93CFBDD74D4A}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{A58F47CC-FF65-4152-B0B1-666C643A5BFC}\InprocServer32 -> AcETransmit.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{A6A3D586-44CF-44C2-A92C-620BB713B4F2}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{ABBE3F83-D585-4A50-9B69-198B0F566F2E}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{AC5CECFA-F03A-41D2-A89C-704C44935941}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{B1560245-190E-4BBD-81DF-9B642D0E5325}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{B2A579E0-A797-40B1-8AEE-A8F6404719F8}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{B47196BC-D4AB-41BB-A771-543D67CFC9F5}\InprocServer32 -> AcETransmit.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{B53CEF4B-1A13-49DE-BBC5-A7100FB2F38C}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{B5EE2B68-9A23-4BCD-BB77-FEA6DFB24DD6}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{B6B5DC40-96E3-11d2-B774-0060B0F159EF}\localserver32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\Inventor.exe /Automation => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{B80687F9-FA4C-4735-9DC4-E5715F2BC698}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{B8E7214B-25CA-4116-84CB-E86FB9625B36}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\ServiceModule.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{BAE5802A-CF21-4F9C-AE04-D98F4036AC31}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{BBF6A206-CB04-479D-96AE-349E1E83319A}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{BC71DEA1-D6FB-48B8-AB06-D151C81BBCDD}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{BE54741D-E02B-4572-93D6-105AF4EDE777}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\ServiceModule.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{BF224DC3-B602-4EEE-BFE9-9E4E0AED6837}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{BF4CC07E-E9BB-40D6-873F-855B211033B9}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{C061C82C-D041-4214-BB07-B608107CEFCB}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{C2D4ACCC-A3D1-4A0A-AD59-0DD8BA3D5EE1}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{C343ED84-A129-11d3-B799-0060B0F159EF}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\RxApprenticeServer.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{C8C18F89-794D-466B-8B97-95634D9890EF}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{C8EC7647-1E79-4F13-81D7-2EED803D0D22}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{C92F8F8C-8B2C-11d4-B872-0060B0EC020B}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\DtBridge.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{CC23CA32-9892-4FBA-A108-FE31CA0F35A6}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{CD865713-70D6-4E15-BB7B-9B99AD9DEB85}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{CFEE2BAF-14F9-4D23-853D-B6E2BCC14263}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\ServiceModule.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{D56F5AB3-9C4D-4F1A-A851-A671D9FE8C22}\InprocServer32 -> AcETransmit.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{D66873EA-AAE5-41CC-8DD2-8CE3228E9F89}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{D7A1987D-4A73-11D1-9A4B-080009DCE505}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\ColorButton.Ocx => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{D7A1987E-4A73-11D1-9A4B-080009DCE505}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\ColorButton.Ocx => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{D86B6C47-11F2-4D95-B635-EA575F0892FC}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{DA1F437C-9BD9-11d4-B87C-0060B0EC020B}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\DtBridge.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{DB207560-8449-4FAF-BDC2-61676EB012D4}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{DB5D476B-3FF4-4E9D-A606-1E2B473BE571}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\AcInetUI.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{DCA7356C-FF94-4b20-AE04-7AA6A8E14117}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\ServiceModule.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{DDA9A20F-5B56-49F5-9465-CE82FC199352}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\ServiceModule.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{DE6B563C-B074-4BF1-A8A0-B3FED8703E99}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\ServiceModule.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{DE74F5AD-DA2F-429F-BAF9-850A2808D585}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{DF6525C2-6358-4B07-813D-708120C5FE1A}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{E177A457-9EAA-43C3-A3CE-84874A28F6CA}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{E1C85E9F-60B2-4007-80C3-2C5E09474C3B}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\RxInventorUtilities.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{E29F6C45-6927-4508-8F3F-34105FD3FC5F}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{E4222C78-3670-4BB1-9AD4-7D8F3E581F2D}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{E5B0515D-48D2-4F04-906D-0192ED65A2DD}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\TestServer.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{E70DE962-842A-4488-9481-1D0FD72A020F}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{E9C07CEC-7B82-49E4-BBA2-7533B88E9D64}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{EA34A0C0-5CE7-4701-A6FA-117D25CD5EBB}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{EF01D98A-747B-4522-AD70-991B90855DBF}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{F13E75B9-6AF6-49CB-80B3-6D2FF6E09932}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\ServiceModule.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{F196F03F-651A-43AF-BE34-D11942F24445}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{F2D4F4E5-EEA1-46FF-A83B-A270C92DAE4B}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\DTInterop.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{F2DB0EE3-7137-4CB0-8349-483C4FF2143A}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{F40E2FF0-4D77-40B2-9A44-A3AEECCE8EFF}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{F5522F0C-962A-48AC-9992-E81B07628F1F}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{F61064CC-DBFB-47ee-9BC8-CA5A1CBDF0DA}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\InvResc.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{F78DCF7C-043D-45FC-9D21-676FC307BA3F}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{F868EAEC-1B73-4F5E-BA73-90EBA94E75BE}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{FA62F626-EBD5-4dc5-B970-D9E81E0E20E0}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\ServiceModule.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{FA97F7A7-FD19-4D55-ABF2-CFEFFF777426}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{FB469644-3F14-4403-ACCA-6B13486FF7BD}\localserver32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\InvTXTStack.exe /Automation => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{FD51ED8A-D518-4554-B236-B6E9D234FD03}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{FD703B01-4362-423E-9BDB-91BDCB16C1C9}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\DTInterop.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{FE054BB2-AF94-40AC-88AA-2F59F7018B1D}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{FE317223-8EDE-4684-B424-E48B9EA90220}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{FE718E8F-C3AA-4F30-9103-432450CF1DA1}\InprocServer32 -> axdb.dll => No File
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2010-11-18] (Igor Pavlov)
ContextMenuHandlers1-x32: [Autodesk.DWF.ContextMenu] -> {6C18531F-CA85-45F7-8278-FF33CF0A5964} => C:\Program Files (x86)\Common Files\Autodesk Shared\DWF Common\DWFShellExtension.dll [2012-01-06] (Autodesk, Inc.)
ContextMenuHandlers1-x32: [Corel PaintShop Pro X4] -> {CA34A346-C652-4F33-8CFF-FD6A91D9D64A} => c:\Program Files (x86)\Corel\Corel PaintShop Pro X4\PSPContextMenu64.dll [2012-05-11] (Corel Software, Inc.)
ContextMenuHandlers1-x32: [McCtxMenuFrmWrk] -> {CCA9EFD3-29ED-430A-BA6D-E6BBFF0A60C2} => c:\Program Files\McAfee\MSC\McCtxMenuFrmWrk.dll [2017-07-10] (McAfee, Inc.)
ContextMenuHandlers2: [Corel PaintShop Pro X4] -> {CA34A346-C652-4F33-8CFF-FD6A91D9D64A} => c:\Program Files (x86)\Corel\Corel PaintShop Pro X4\PSPContextMenu64.dll [2012-05-11] (Corel Software, Inc.)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-11-01] (Malwarebytes)
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2010-11-18] (Igor Pavlov)
ContextMenuHandlers4: [Corel PaintShop Pro X4] -> {CA34A346-C652-4F33-8CFF-FD6A91D9D64A} => c:\Program Files (x86)\Corel\Corel PaintShop Pro X4\PSPContextMenu64.dll [2012-05-11] (Corel Software, Inc.)
ContextMenuHandlers5: [ACE] -> {5E2121EE-0300-11D4-8D3B-444553540000} => C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\atiacm64.dll [2015-05-05] (Advanced Micro Devices, Inc.)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-11-01] (Malwarebytes)
ContextMenuHandlers6: [McCtxMenuFrmWrk] -> {CCA9EFD3-29ED-430A-BA6D-E6BBFF0A60C2} => c:\Program Files\McAfee\MSC\McCtxMenuFrmWrk.dll [2017-07-10] (McAfee, Inc.)
ContextMenuHandlers6_S-1-5-21-3289118944-4034126387-1954186238-1000: [InventorMenu] -> {6FDE7A70-351B-11d6-988B-0010B57A8BB7} => C:\Program Files\Autodesk\Inventor 2016\Bin\DtBridge.dll -> No File
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {12D74CB1-D95F-4343-A23A-6763BEAA42CB} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {36B966E5-B8D6-49FF-80A1-B1B4136C751E} - System32\Tasks\GarminUpdaterTask => C:\Program Files (x86)\Garmin\Express Self Updater\ExpressSelfUpdater.exe
Task: {4678B207-E35D-4E4E-BE9C-DABD7B77A524} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2016-02-23] (Apple Inc.)
Task: {4FAD17B9-4EEB-4CAD-803C-1B43BD161CEB} - System32\Tasks\McAfeeLogon => C:\Program Files\Common Files\McAfee\Platform\McUICnt.exe [2017-05-30] (McAfee, Inc.)
Task: {722FEA3D-3848-4774-A087-454E746A904A} - System32\Tasks\McAfee\McAfee Idle Detection Task
Task: {8A289A42-417A-45DD-A36F-2F581B27307B} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_28_0_0_137_pepper.exe [2018-01-09] (Adobe Systems Incorporated)
Task: {B3C459B3-51D7-4679-82D8-96BDEB286107} - System32\Tasks\McAfee Remediation (Prepare) => C:\Program Files\Common Files\AV\McAfee VirusScan\upgrade.exe [2017-04-12] (McAfee, Inc.)
Task: {C207FBBE-E6C7-4912-AE92-66921801C453} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {D351F207-C8DE-43F2-9261-EE932A351F29} - System32\Tasks\GoogleUpdateTaskMachineUA1d0908d4088e86f => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {EC8807A2-747B-4034-AA6B-0A6DFA75F885} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2018-01-09] (Adobe Systems Incorporated)
Task: {EE2CC55D-8C31-44A8-94DC-A86099E682C2} - System32\Tasks\{16D7FACF-B0D1-48F8-9C02-E3A61932FA80} => "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" hxxp://ui.skype.com/ui/0/6.7.0.102/en/abandoninstall?page=tsProgressBar
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
 
==================== Shortcuts & WMI ========================
 
(The entries could be listed to be restored or removed.)
 
 
Shortcut: C:\Users\Teschke\Favorites\Dustin\NCH Software Download Site.lnk -> hxxp://www.nchsoftware.com/index.htm
 
ShortcutWithArgument: C:\Users\Teschke\Desktop\Games\Art & Media\VideoStudio X9 Training.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) -> www.studiobacklot.tv/videostudioX9
ShortcutWithArgument: C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Web Applications\_crx_mkdmfheflfmedmfjolgifliincdhfgdl\Slender Space.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) ->  --profile-directory=Default --app-id=mkdmfheflfmedmfjolgifliincdhfgdl
ShortcutWithArgument: C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Web Applications\_crx_jangaedeekciafhlanphhnalogmhefmo\theHunter.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) ->  --profile-directory=Default --app-id=jangaedeekciafhlanphhnalogmhefmo
ShortcutWithArgument: C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Web Applications\_crx_fplklihjpkinahlihcljhnnlnhnmmhdp\Counter Strike Online.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) ->  --profile-directory=Default --app-id=fplklihjpkinahlihcljhnnlnhnmmhdp
ShortcutWithArgument: C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Web Applications\_crx_bmekbplkjhgmljmbblmhmcnocafhaink\BeGone_ Last Stand HD.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) ->  --profile-directory=Default --app-id=bmekbplkjhgmljmbblmhmcnocafhaink
ShortcutWithArgument: C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Web Applications\_crx_alnfdikmbdfgkcbdodjcbmedanjinmkk\Beatlab.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) ->  --profile-directory=Default --app-id=alnfdikmbdfgkcbdodjcbmedanjinmkk
ShortcutWithArgument: C:\Users\Teschke\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\9501e18d7c2ab92e\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory="Profile 2"
ShortcutWithArgument: C:\Users\Teschke\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\225bb61db2f318c1\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory="Profile 3"
 
==================== Loaded Modules (Whitelisted) ==============
 
2017-06-01 14:58 - 2017-07-06 14:58 - 000595608 _____ () C:\Program Files\McAfee\MfeAV\RealProtectAMScanIf.dll
2017-06-01 14:58 - 2017-07-06 14:58 - 000584680 _____ () C:\Program Files\McAfee\MfeAV\RepairModule.dll
2013-09-05 00:17 - 2013-09-05 00:17 - 004300456 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF
2010-10-20 14:23 - 2010-10-20 14:23 - 008801632 _____ () C:\Program Files\Microsoft Office\Office14\1033\GrooveIntlResource.dll
2017-11-24 18:55 - 2017-12-12 04:53 - 002301384 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\SelfProtectionSdk.dll
2017-07-17 12:30 - 2017-07-17 12:30 - 000863744 _____ () C:\Windows\mod_frst.exe
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
AlternateDataStreams: C:\Users\Public\AppData:CSM [460]
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mbamchameleon => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMSwissArmy => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ModuleCoreService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mbamchameleon => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMSwissArmy => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcapexe => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeaack => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeaack.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeavfk => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeavfk.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefire => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfemms => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeplk => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeplk.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfetdi2k => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfetdi2k.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfevtp => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ModuleCoreService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Option => "OptionValue"="2"
 
==================== Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
IE trusted site: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000\...\dell.com -> dell.com
IE trusted site: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000\...\hola.org -> hxxp://hola.org
 
==================== Hosts content: ===============================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2009-07-13 21:34 - 2009-06-10 16:00 - 000000824 _____ C:\Windows\system32\Drivers\etc\hosts
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-3289118944-4034126387-1954186238-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Teschke\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 199.166.6.2 - 209.239.11.98
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
MSCONFIG\Services: AdobeARMservice => 2
MSCONFIG\Services: Apple Mobile Device Service => 2
MSCONFIG\Services: Garmin Device Interaction Service => 2
MSCONFIG\Services: iPod Service => 3
MSCONFIG\Services: lxea_device => 2
MSCONFIG\Services: NETGEARGenieDaemon => 3
MSCONFIG\Services: SkypeUpdate => 2
MSCONFIG\startupfolder: C:^Users^Admin^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2010 Screen Clipper and Launcher.lnk => C:\Windows\pss\OneNote 2010 Screen Clipper and Launcher.lnk.Startup
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: Akamai NetSession Interface => "C:\Users\Admin\AppData\Local\Akamai\netsession_win.exe"
MSCONFIG\startupreg: APSDaemon => "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
MSCONFIG\startupreg: Corel Update Helper => "c:\Program Files\Corel\Corel VideoStudio X9\pua.exe" /t
MSCONFIG\startupreg: fssui => "C:\Program Files (x86)\Windows Live\Family Safety\fsui.exe" -autorun
MSCONFIG\startupreg: GarminExpressTrayApp => "C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe"
MSCONFIG\startupreg: ISUSPM => C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe -scheduler
MSCONFIG\startupreg: iTunesHelper => "C:\Program Files\iTunes\iTunesHelper.exe"
MSCONFIG\startupreg: LWS => C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe -hide
MSCONFIG\startupreg: Raptr => "C:\Program Files (x86)\Raptr Inc\Raptr\raptrstub.exe" --startup
MSCONFIG\startupreg: StartCCC => "C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [{F16ECB23-8787-4B80-BA61-02E5DFB8EBCF}] => (Allow) C:\Windows\system32\lxeacoms.exe
FirewallRules: [{32F84DA2-A985-4218-8BA3-1E6EFEC4A1BB}] => (Allow) C:\Program Files (x86)\Pinnacle\Studio 12\Programs\RM.exe
FirewallRules: [{70073B3D-DB28-443F-A95D-846B197BA271}] => (Allow) C:\Program Files (x86)\Pinnacle\Studio 12\Programs\RM.exe
FirewallRules: [{AAF56D47-E704-4924-B85E-7A9E344D8A0A}] => (Allow) C:\Program Files (x86)\Pinnacle\Studio 12\Programs\Studio.exe
FirewallRules: [{E30DFCBC-0367-4E35-A307-4CCAA64F1165}] => (Allow) C:\Program Files (x86)\Pinnacle\Studio 12\Programs\Studio.exe
FirewallRules: [{789CAFB5-E298-41C2-B5F0-C0732DF3F8E3}] => (Allow) C:\Program Files (x86)\Pinnacle\Studio 12\Programs\umi.exe
FirewallRules: [{C02D669A-832C-4E6A-9558-829864F25463}] => (Allow) C:\Program Files (x86)\Pinnacle\Studio 12\Programs\umi.exe
FirewallRules: [{CF129E27-7FB6-48D9-BCE2-D463091BAEDF}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{83972B14-0AA1-4EDB-8FE9-E17058EC761F}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{46DFC88A-8ADB-4927-8684-D514B1F21923}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{08B5C287-8BD1-41AD-B820-1A9FE91F3209}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Breach\Breach.exe
FirewallRules: [{E6BB2592-510D-4A37-AF32-27B048F5EF6E}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Breach\Breach.exe
FirewallRules: [{B1DCB9FB-B224-4B2F-AB37-1C6C45EDBA83}] => (Allow) C:\Program Files (x86)\Steam\bin\steamservice.exe
FirewallRules: [{60327E3C-B0BF-455D-8B68-55C352A13F86}] => (Allow) C:\Program Files (x86)\Steam\bin\steamservice.exe
FirewallRules: [{8BE08515-A9DA-44E2-8B4C-5B863A5FCB9D}] => (Allow) C:\Program Files (x86)\Steam\bin\steamservice.exe
FirewallRules: [{583027FB-C067-45CE-81B3-CF85F9F6D9B2}] => (Allow) C:\Program Files (x86)\Steam\bin\steamservice.exe
FirewallRules: [{81C1C6D9-D3C6-43A0-8E29-EF861AE114E6}] => (Allow) C:\Program Files (x86)\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe
FirewallRules: [{56FA6971-E199-4C34-A879-B36C761D7CF1}] => (Allow) C:\Program Files (x86)\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe
FirewallRules: [{1B889BC2-A65B-4A01-8E24-273A5B660318}] => (Allow) C:\Program Files (x86)\UBISOFT\Assassin's Creed III\AC3SP.exe
FirewallRules: [{2F42C95D-B079-40E0-83CE-AE027A6C9A6F}] => (Allow) C:\Program Files (x86)\UBISOFT\Assassin's Creed III\AC3SP.exe
FirewallRules: [{8522CB95-9EFE-4A37-AF87-82E6C1DD6705}] => (Allow) C:\Program Files (x86)\UBISOFT\Assassin's Creed III\AC3MP.exe
FirewallRules: [{424DB30E-5233-4284-A693-8B4E858DAA16}] => (Allow) C:\Program Files (x86)\UBISOFT\Assassin's Creed III\AC3MP.exe
FirewallRules: [{7A861EB4-6A29-470D-912B-4A563E7AE6F7}] => (Allow) C:\Program Files (x86)\UBISOFT\Assassin's Creed III\AssassinsCreed3.exe
FirewallRules: [{2B63F9F1-4C21-4476-A80A-C8C4CEA573C8}] => (Allow) C:\Program Files (x86)\UBISOFT\Assassin's Creed III\AssassinsCreed3.exe
FirewallRules: [{FB653026-B559-4FD3-9828-40A5761DCF38}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Portal 2\portal2.exe
FirewallRules: [{44ECF51C-3A54-4861-9A4E-25E82FC6B9BB}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Portal 2\portal2.exe
FirewallRules: [{8B185093-81EA-4EF5-9BB8-D730D6CC8818}] => (Allow) C:\Program Files (x86)\Origin Games\Crysis 3\Bin32\Crysis3.exe
FirewallRules: [{8F55590B-9251-41AF-A5D8-9EAF2E8DBA24}] => (Allow) C:\Program Files (x86)\Origin Games\Crysis 3\Bin32\Crysis3.exe
FirewallRules: [{B6B2D2BA-1409-4C46-94AF-1F28FCFEA063}] => (Allow) C:\Program Files (x86)\StarCraft II\StarCraft II.exe
FirewallRules: [{5E3F7B0C-853E-49E7-9770-17AB687715B6}] => (Allow) C:\Program Files (x86)\StarCraft II\StarCraft II.exe
FirewallRules: [{D08C82D9-40F1-4664-A9F8-54CEE92A3954}] => (Allow) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
FirewallRules: [{2F80630E-EB85-4814-B7BC-8C206124D93C}] => (Allow) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
FirewallRules: [{C47E9DCF-FF13-49FD-A5D0-734E0BE00521}] => (Allow) C:\Program Files (x86)\theHunter\launcher\launcher.exe
FirewallRules: [{28C8990C-A52A-42C4-BA8D-1CD40DC43CE8}] => (Allow) C:\Program Files (x86)\theHunter\launcher\launcher.exe
FirewallRules: [{71709164-B6F2-4805-8AED-1D567AF8B96D}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Skyrim\SkyrimLauncher.exe
FirewallRules: [{95EEC40A-0EFF-447A-BA96-1DD5F4A38C05}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Skyrim\SkyrimLauncher.exe
FirewallRules: [{B558288E-5444-4364-B99F-389093101A3E}] => (Allow) C:\Program Files\Lightworks\Lightworks.exe
FirewallRules: [{F81BB928-631A-413E-898B-4ECEC619B624}] => (Allow) C:\Program Files\Lightworks\Lightworks.exe
FirewallRules: [{69CE75F1-E33F-42DC-85F9-7D176E2076E9}] => (Allow) C:\Program Files\Lightworks\ntcardvt.exe
FirewallRules: [{35ADB5EC-FEF0-41B2-8FD7-2B6163B06ACF}] => (Allow) C:\Program Files\Lightworks\ntcardvt.exe
FirewallRules: [{5D802E51-2D70-44E7-8A38-77ECEF4CC79F}] => (Allow) LPort=54925
FirewallRules: [{57298198-28C7-4134-8EE0-B517E2C6FE44}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\XCom-Enemy-Unknown\Binaries\Win32\XComGame.exe
FirewallRules: [{6159DE13-EE45-4911-B28C-8DB4F584A284}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\XCom-Enemy-Unknown\Binaries\Win32\XComGame.exe
FirewallRules: [{810F18D6-3CE1-43F1-9AC3-63041511EEE2}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{84C693B9-AEE3-4795-8165-7130A2F00058}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{02CCF350-0DBE-42BD-BFAB-0DF64DF10A13}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Team Fortress 2\hl2.exe
FirewallRules: [{FE8CAA48-E29E-44EC-9FFC-3C1945874D49}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Team Fortress 2\hl2.exe
FirewallRules: [{155E1331-C6F6-4586-B71D-833CC783B829}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{2CF8A5C6-7885-4901-A242-CF3CFDD7DC7D}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{5003C5AF-24F5-4759-AD3F-40E5648BF602}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Team Fortress 2\hl2.exe
FirewallRules: [{41EA998E-B4A6-4ED7-9191-256963A00DA1}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Team Fortress 2\hl2.exe
FirewallRules: [{72B155B7-7D16-414D-B3E7-92D341959244}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{DBE8985D-BEB3-4F04-8B14-2CFB90EDD6A7}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{99E88E28-5A6C-48BB-ADE3-EB7607181196}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{DDB7BF02-1D82-4E33-B090-A5C1664879B6}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{6984E421-BCAD-4E9D-A092-C103A0FDE4A1}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{0BE8AC0C-EE47-439C-AF37-A16BAD69A9DA}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{7D33A7E0-AF82-4C7C-BF7B-31FBFD51C52C}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{14D8F6D2-9205-4683-A37B-CA5CFA42A57A}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{F7049409-B56D-4686-93A8-11FF390C7229}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{B33040E5-F29A-4AD7-A33E-284AC16C3305}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{3C457650-44A0-4AA0-8389-D3A828ACA345}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Team Fortress 2\hl2.exe
FirewallRules: [{3DB6FA17-1D3B-437F-9D7A-ACBA9266E6DB}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Team Fortress 2\hl2.exe
FirewallRules: [{2325C2C9-0C15-4800-8C7D-F658C7FE2F00}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Team Fortress 2\hl2.exe
FirewallRules: [{545E5F7D-11D8-4E1F-A1A0-223BC753ADDC}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Team Fortress 2\hl2.exe
FirewallRules: [{B13739F0-FC71-4183-84C5-FA460F17C6B6}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.1040\Agent.exe
FirewallRules: [{34D763EF-0F01-41EF-B98D-AC336699F93E}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.1040\Agent.exe
FirewallRules: [{F49C1CFE-07C7-46DB-993A-238C1DAA027F}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2380\Agent.exe
FirewallRules: [{7AC1CA3F-4D02-4B48-AE8C-BE962C944C2C}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2380\Agent.exe
FirewallRules: [{A7D771AD-9480-4250-8920-DDEA6D1A8F4D}] => (Allow) C:\Program Files (x86)\StarCraft II\StarCraft II Public Test.exe
FirewallRules: [{EEFB70E1-9211-4B71-866B-7B0844415455}] => (Allow) C:\Program Files (x86)\StarCraft II\StarCraft II Public Test.exe
FirewallRules: [{01B75E99-AC2A-44D9-84AB-68D2E82C71AA}] => (Allow) C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
FirewallRules: [{7BE16534-A3E4-4E98-B6F2-48CA2B4BA3D0}] => (Allow) C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
FirewallRules: [{BE65226B-F667-46E5-A4E8-3C9036FC7D14}] => (Allow) C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
FirewallRules: [{0C669D17-C76D-41DF-A453-CA03F4D86CCF}] => (Allow) C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
FirewallRules: [{58732465-04C5-4EF0-80C0-EFD5391E965B}] => (Allow) C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
FirewallRules: [{E78FB3E8-57EA-49AA-B20A-EE3F70903C4C}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{47FE0346-4C48-4A50-8A77-18EA37EC9B07}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{EB77F046-CD9F-4C38-B7BF-F856EDD35F14}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{1D42B23D-921C-4E36-8B87-E2D90D0834FE}] => (Allow) LPort=2869
FirewallRules: [{0030EE09-4BAA-4E9F-A64C-F79381EFE987}] => (Allow) LPort=1900
FirewallRules: [{2A29E2C7-0BA4-483A-8F64-F52609F4A4FB}] => (Allow) C:\Program Files (x86)\Hearthstone\Hearthstone.exe
FirewallRules: [{D7A56D14-7B35-44EB-A09B-E36452560FCF}] => (Allow) C:\Program Files (x86)\Hearthstone\Hearthstone.exe
FirewallRules: [{556C1B3C-3F15-45C2-9D70-CA864CBDADE9}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2880\Agent.exe
FirewallRules: [{BE479DD9-893C-4D2F-AA5D-92D2E34946AF}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2880\Agent.exe
FirewallRules: [{7B41D613-A78E-4B35-A706-138CBF201879}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\JABIA\JaggedAllianceBIA.exe
FirewallRules: [{5CEF6981-E7B6-43D9-AF71-06491F6E4836}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\JABIA\JaggedAllianceBIA.exe
FirewallRules: [{EF58DAEF-A76C-47EA-B618-112AB60643C8}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{05CBE5C7-ACB2-46D4-9D26-0605916DB72F}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{00D1F223-C0CF-449A-A132-7618F3F6D4B9}] => (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe
FirewallRules: [{49D6483D-2FA4-48D4-89F3-6D0A21A794EB}] => (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe
FirewallRules: [{F2D3D2AE-086F-4199-81AE-4645F4CF383D}] => (Allow) C:\Program Files (x86)\UBISOFT\Far Cry 2\bin\FarCry2.exe
FirewallRules: [{C28F70F2-9FC7-476D-82E1-FF447DD35154}] => (Allow) C:\Program Files (x86)\UBISOFT\Far Cry 2\bin\FarCry2.exe
FirewallRules: [{46347C9C-4AE9-4DF5-A15C-0C2B674058C1}] => (Allow) C:\Program Files (x86)\UBISOFT\Far Cry 2\bin\FC2Launcher.exe
FirewallRules: [{89B65C34-E2D0-4987-90C6-7744EC436736}] => (Allow) C:\Program Files (x86)\UBISOFT\Far Cry 2\bin\FC2Launcher.exe
FirewallRules: [{D4FBEAC5-E679-4086-9DE4-3965604F11DA}] => (Allow) C:\Program Files (x86)\UBISOFT\Far Cry 2\bin\FC2Editor.exe
FirewallRules: [{D4C131B3-4646-4F46-9D4D-36DB2F00C7A5}] => (Allow) C:\Program Files (x86)\UBISOFT\Far Cry 2\bin\FC2Editor.exe
FirewallRules: [{5EE985CB-9EA4-4B04-BD6F-87E8DD8E7961}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{C1CFD1DC-DFC6-410F-9BB3-1A3681CA6D17}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{8AEEBC88-98FB-46C7-B479-EDF5818C072B}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{C6796B54-ACAF-4FB2-891E-36F8DCA5E6A1}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [TCP Query User{5A03840E-2B1C-4CA8-9516-B3A70A455B08}C:\program files (x86)\daide\quickstart\aiserver\aiserver.exe] => (Block) C:\program files (x86)\daide\quickstart\aiserver\aiserver.exe
FirewallRules: [UDP Query User{1080189C-898C-4245-BE92-EEAE22DAA1DD}C:\program files (x86)\daide\quickstart\aiserver\aiserver.exe] => (Block) C:\program files (x86)\daide\quickstart\aiserver\aiserver.exe
FirewallRules: [{BFC1DB99-77B5-4AC0-9464-240FCBA70894}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{881BA182-0CC1-4EA1-BE0C-E54B0436A797}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{01A5C88B-73F5-4B59-B01C-DCFCB756C85F}] => (Allow) C:\Program Files (x86)\Raptr\raptr.exe
FirewallRules: [{88AD7A8D-DFDA-4267-BE87-C2F534A45E34}] => (Allow) C:\Program Files (x86)\Raptr\raptr.exe
FirewallRules: [{5326A4A9-4F4F-4B39-8D03-C662C07A7E2B}] => (Allow) C:\Program Files (x86)\Raptr\raptr_im.exe
FirewallRules: [{07ADBAC2-B989-4F09-ACF2-8FF03CC263A6}] => (Allow) C:\Program Files (x86)\Raptr\raptr_im.exe
FirewallRules: [{B500E6F5-4E07-45DE-B0B5-8DB571C79FCC}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2cfg.exe
FirewallRules: [{EB3C113F-C0B6-4EFB-9DA7-BBED24F557F7}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2cfg.exe
FirewallRules: [{BFAA2466-2AB3-4949-8A00-5AF6CB3C3157}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{30820C6B-C2A0-4A23-9D32-72EE33068630}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{2CC22695-DA31-45BB-8966-C7F013D0D69F}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{C8E47915-3EB8-4F4C-81F0-65557EB69481}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{E00F6D8F-53E9-4771-8BDC-4BB62EB4B4F1}] => (Allow) C:\Program Files\iTunes\iTunes.exe
FirewallRules: [{256D452F-606F-4DF8-99E8-89B2AAF0C1AC}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Dirty Bomb\Binaries\Win32\ShooterGame-Win32-Shipping.exe
FirewallRules: [{3F642655-712C-4445-B6DB-35B2D6CA2493}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Dirty Bomb\Binaries\Win32\ShooterGame-Win32-Shipping.exe
FirewallRules: [{C38C6387-76A9-43F2-96FD-929D9B227CE4}] => (Allow) C:\Program Files (x86)\Raptr Inc\Raptr\raptr.exe
FirewallRules: [{91E9E38B-7E45-4B09-8F10-3F90E197E61E}] => (Allow) C:\Program Files (x86)\Raptr Inc\Raptr\raptr.exe
FirewallRules: [{AE2791DC-926C-4224-B936-4CCCD6159DD8}] => (Allow) C:\Program Files (x86)\Raptr Inc\Raptr\raptr_im.exe
FirewallRules: [{DDA14856-5CA6-4116-A154-8834570ACDDB}] => (Allow) C:\Program Files (x86)\Raptr Inc\Raptr\raptr_im.exe
FirewallRules: [TCP Query User{36F416F9-5BD2-4CF3-BD5C-FAF7440DCC03}C:\users\admin\appdata\local\akamai\netsession_win.exe] => (Allow) C:\users\admin\appdata\local\akamai\netsession_win.exe
FirewallRules: [UDP Query User{E84D30D4-10B8-462A-B495-7155F8D93547}C:\users\admin\appdata\local\akamai\netsession_win.exe] => (Allow) C:\users\admin\appdata\local\akamai\netsession_win.exe
FirewallRules: [{2EB0AEB4-F3C7-4CE7-ACEA-9E92A9457FD2}] => (Allow) C:\Program Files (x86)\McAfee\Supportability\MVT\MvtApp.exe
FirewallRules: [{B3D3FF8F-E7A2-4B4B-8293-1A71640863D3}] => (Allow) C:\Program Files (x86)\McAfee\Supportability\MVT\MvtApp.exe
FirewallRules: [{67209B8B-EF3E-414D-9C12-1BA3BBEC131B}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [{7D993D04-3A22-4717-9405-31BFD263C246}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [{18B5C50C-A5C5-4007-A6A5-4121C385EF08}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Dirty Bomb\DirtyBombLauncher.exe
FirewallRules: [{51EAC435-D1B9-47AF-9AC1-8CFE2B8E3ECC}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Dirty Bomb\DirtyBombLauncher.exe
FirewallRules: [TCP Query User{58174CC5-FF62-4FB3-965C-06C7FA8C10B9}C:\program files (x86)\starcraft ii\versions\base51149\sc2_x64.exe] => (Block) C:\program files (x86)\starcraft ii\versions\base51149\sc2_x64.exe
FirewallRules: [UDP Query User{5E8D7FC0-8562-4069-82DC-BA8D65674A71}C:\program files (x86)\starcraft ii\versions\base51149\sc2_x64.exe] => (Block) C:\program files (x86)\starcraft ii\versions\base51149\sc2_x64.exe
FirewallRules: [TCP Query User{AC30B663-D262-4232-86A1-ECF9527D3B52}C:\program files (x86)\starcraft ii\versions\base51702\sc2_x64.exe] => (Block) C:\program files (x86)\starcraft ii\versions\base51702\sc2_x64.exe
FirewallRules: [UDP Query User{EF86E717-134A-42CB-9C52-BE75AA178E84}C:\program files (x86)\starcraft ii\versions\base51702\sc2_x64.exe] => (Block) C:\program files (x86)\starcraft ii\versions\base51702\sc2_x64.exe
FirewallRules: [TCP Query User{D15692F9-2135-4005-B6C9-F8BDB276BF53}C:\program files (x86)\starcraft ii\support\sc2editor.exe] => (Block) C:\program files (x86)\starcraft ii\support\sc2editor.exe
FirewallRules: [UDP Query User{3E00FE2D-5D60-4B84-9B9D-A57BD840EDCB}C:\program files (x86)\starcraft ii\support\sc2editor.exe] => (Block) C:\program files (x86)\starcraft ii\support\sc2editor.exe
FirewallRules: [TCP Query User{2D5D6177-FA3C-4AD5-A788-BC88D5B8D392}C:\users\teschke\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\teschke\appdata\roaming\spotify\spotify.exe
FirewallRules: [UDP Query User{9CC7B4A3-0435-4270-AEE4-EA906E29B995}C:\users\teschke\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\teschke\appdata\roaming\spotify\spotify.exe
FirewallRules: [{BCE6458B-7347-4CAD-A3C5-5D36B837848A}] => (Allow) C:\Program Files (x86)\Google\Chrome Remote Desktop\63.0.3239.32\remoting_host.exe
FirewallRules: [TCP Query User{8016F667-550B-47F6-A163-A6ECC5DEFC51}C:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe
FirewallRules: [UDP Query User{4290882B-C43B-4A07-A3D5-DBF0EF281827}C:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe
FirewallRules: [TCP Query User{C84F8A5F-D20C-4E1E-8778-CE5C3E7834E9}C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe
FirewallRules: [UDP Query User{C7D11005-6FD5-413E-BD97-07843AFF24CD}C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe
FirewallRules: [TCP Query User{1D5A22B0-A2B6-4F48-85EF-3247698D1E3A}C:\program files\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe] => (Allow) C:\program files\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe
FirewallRules: [UDP Query User{1D1F93FA-574A-4942-8CD9-98A7DFADBBB6}C:\program files\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe] => (Allow) C:\program files\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe
FirewallRules: [{2834D457-F5FF-4DBE-BAAA-A4CD36B884A6}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
 
==================== Restore Points =========================
 
25-01-2018 21:55:22 Scheduled Checkpoint
 
==================== Faulty Device Manager Devices =============
 
Name: Security Processor Loader Driver
Description: Security Processor Loader Driver
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer: 
Service: spldr
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (01/27/2018 01:15:11 PM) (Source: Desktop Window Manager) (EventID: 9020) (User: )
Description: The Desktop Window Manager has encountered a fatal error (0x80070008)
 
Error: (01/27/2018 12:33:19 PM) (Source: WTabletServicePro) (EventID: 1) (User: )
Description: Event-ID 1
 
Error: (01/27/2018 12:33:13 PM) (Source: WTabletServicePro) (EventID: 1) (User: )
Description: Event-ID 1
 
Error: (01/26/2018 07:38:10 PM) (Source: WTabletServicePro) (EventID: 1) (User: )
Description: Event-ID 1
 
Error: (01/26/2018 07:38:03 PM) (Source: WTabletServicePro) (EventID: 1) (User: )
Description: Event-ID 1
 
Error: (01/26/2018 05:34:36 PM) (Source: MsiInstaller) (EventID: 1024) (User: XPS)
Description: Product: Adobe Reader XI - Update '{AC76BA86-7AD7-0000-2550-7A8C40011020}' could not be installed. Error code 1625. Windows Installer can create logs to help troubleshoot issues with installing software packages. Use the following link for instructions on turning on logging support: http://go.microsoft.com/fwlink/?LinkId=23127
 
Error: (01/26/2018 03:10:40 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: IEXPLORE.EXE, version: 11.0.9600.18894, time stamp: 0x5a467703
Faulting module name: atidxx32.dll, version: 8.17.10.621, time stamp: 0x55496920
Exception code: 0xc0000005
Fault offset: 0x0050e52a
Faulting process id: 0x208c
Faulting application start time: 0x01d396df7b136cb9
Faulting application path: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
Faulting module path: C:\Windows\system32\atidxx32.dll
Report Id: fa916211-02d4-11e8-a1ce-782bcb94ac4d
 
Error: (01/26/2018 09:00:28 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: IEXPLORE.EXE, version: 11.0.9600.18894, time stamp: 0x5a467703
Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception code: 0x4000001f
Fault offset: 0x0facf000
Faulting process id: 0x22b0
Faulting application start time: 0x01d396ad56e6843d
Faulting application path: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
Faulting module path: unknown
Report Id: 436dcff5-02a1-11e8-a1ce-782bcb94ac4d
 
Error: (01/24/2018 07:19:46 PM) (Source: MsiInstaller) (EventID: 1024) (User: XPS)
Description: Product: Adobe Reader XI - Update '{AC76BA86-7AD7-0000-2550-7A8C40011020}' could not be installed. Error code 1625. Windows Installer can create logs to help troubleshoot issues with installing software packages. Use the following link for instructions on turning on logging support: http://go.microsoft.com/fwlink/?LinkId=23127
 
Error: (01/24/2018 07:17:58 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: IEXPLORE.EXE, version: 11.0.9600.18894, time stamp: 0x5a467703
Faulting module name: atidxx32.dll, version: 8.17.10.621, time stamp: 0x55496920
Exception code: 0xc0000005
Fault offset: 0x0050e52a
Faulting process id: 0x1f50
Faulting application start time: 0x01d39570e6dcabdf
Faulting application path: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
Faulting module path: C:\Windows\system32\atidxx32.dll
Report Id: 31c291f1-0165-11e8-a1ce-782bcb94ac4d
 
 
System errors:
=============
Error: (01/27/2018 01:39:15 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error: 
The dependency service or group failed to start.
 
Error: (01/27/2018 01:39:15 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error: 
The dependency service or group failed to start.
 
Error: (01/27/2018 01:39:15 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error: 
The dependency service or group failed to start.
 
Error: (01/27/2018 01:39:15 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error: 
The dependency service or group failed to start.
 
Error: (01/27/2018 01:39:15 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error: 
The dependency service or group failed to start.
 
Error: (01/27/2018 01:39:15 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error: 
The dependency service or group failed to start.
 
Error: (01/27/2018 01:36:44 PM) (Source: DCOM) (EventID: 10005) (User: )
Description: DCOM got error "1068" attempting to start the service fdPHost with arguments "" in order to run the server:
{D3DCB472-7261-43CE-924B-0704BD730D5F}
 
Error: (01/27/2018 01:36:44 PM) (Source: DCOM) (EventID: 10005) (User: )
Description: DCOM got error "1068" attempting to start the service fdPHost with arguments "" in order to run the server:
{145B4335-FE2A-4927-A040-7C35AD3180EF}
 
Error: (01/27/2018 01:33:26 PM) (Source: DCOM) (EventID: 10005) (User: )
Description: DCOM got error "1084" attempting to start the service fsssvc with arguments "" in order to run the server:
{9A027D9F-AE6D-4116-AE94-BAB878D7EE47}
 
Error: (01/27/2018 01:31:22 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error: 
The dependency service or group failed to start.
 
 
CodeIntegrity:
===================================
  Date: 2017-09-14 03:39:35.233
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\kernel32.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-09-04 08:07:38.756
  Description: Windows is unable to verify the integrity of the file \Device\HarddiskVolume2\$Windows.~BT\Updates\Critical\8e08ca47-f6ba-409d-82de-698e324c0004\amd64_microsoft-windows-errorreportingfaults_31bf3856ad364e35_10.0.10074.1_none_f3153036f55ab3f5\werfault.exe because the signing certificate has been revoked.  Check with the publisher to see if a new signed version of the kernel module is available.
 
  Date: 2015-09-04 08:07:38.749
  Description: Windows is unable to verify the integrity of the file \Device\HarddiskVolume2\$Windows.~BT\Updates\Critical\8e08ca47-f6ba-409d-82de-698e324c0004\amd64_microsoft-windows-errorreportingfaults_31bf3856ad364e35_10.0.10074.1_none_f3153036f55ab3f5\werfault.exe because the signing certificate has been revoked.  Check with the publisher to see if a new signed version of the kernel module is available.
 
  Date: 2015-09-04 08:07:38.743
  Description: Windows is unable to verify the integrity of the file \Device\HarddiskVolume2\$Windows.~BT\Updates\Critical\8e08ca47-f6ba-409d-82de-698e324c0004\amd64_microsoft-windows-errorreportingfaults_31bf3856ad364e35_10.0.10074.1_none_f3153036f55ab3f5\werfault.exe because the signing certificate has been revoked.  Check with the publisher to see if a new signed version of the kernel module is available.
 
  Date: 2015-09-04 08:07:38.640
  Description: Windows is unable to verify the integrity of the file \Device\HarddiskVolume2\$Windows.~BT\Updates\Critical\8e08ca47-f6ba-409d-82de-698e324c0004\amd64_microsoft-windows-errorreportingcore_31bf3856ad364e35_10.0.10074.1_none_a384c5aabe759ea5\wermgr.exe because the signing certificate has been revoked.  Check with the publisher to see if a new signed version of the kernel module is available.
 
  Date: 2015-09-04 08:07:38.629
  Description: Windows is unable to verify the integrity of the file \Device\HarddiskVolume2\$Windows.~BT\Updates\Critical\8e08ca47-f6ba-409d-82de-698e324c0004\amd64_microsoft-windows-errorreportingcore_31bf3856ad364e35_10.0.10074.1_none_a384c5aabe759ea5\wermgr.exe because the signing certificate has been revoked.  Check with the publisher to see if a new signed version of the kernel module is available.
 
  Date: 2015-09-04 08:07:38.621
  Description: Windows is unable to verify the integrity of the file \Device\HarddiskVolume2\$Windows.~BT\Updates\Critical\8e08ca47-f6ba-409d-82de-698e324c0004\amd64_microsoft-windows-errorreportingcore_31bf3856ad364e35_10.0.10074.1_none_a384c5aabe759ea5\wermgr.exe because the signing certificate has been revoked.  Check with the publisher to see if a new signed version of the kernel module is available.
 
 
==================== Memory info =========================== 
 
Processor: Intel® Core™ i7-2600 CPU @ 3.40GHz
Percentage of memory in use: 13%
Total physical RAM: 12270.45 MB
Available physical RAM: 10582.8 MB
Total Virtual: 24539.06 MB
Available Virtual: 23005.75 MB
 
==================== Drives ================================
 
Drive c: () (Fixed) (Total:931.41 GB) (Free:47.48 GB) NTFS
Drive d: (PONYO) (CDROM) (Total:7.92 GB) (Free:0 GB) UDF
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: A61DA447)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=931.4 GB) - (Type=07 NTFS)
 
==================== End of Addition.txt ============================


#4 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 36,617 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:07:50 PM

Posted 27 January 2018 - 05:13 PM

Hi Dustin.

 

If you are able to run the scan in Normal Boot that would be more helpful. If you need to use multiple replies to post both reports please do so.


Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#5 Dustint

Dustint
  • Topic Starter

  • Members
  • 26 posts
  • OFFLINE
  •  
  • Local time:09:50 PM

Posted 27 January 2018 - 05:17 PM

Here you go Gary,

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 27.01.2018
Ran by Teschke (administrator) on XPS (27-01-2018 15:08:03)
Running from C:\Users\Teschke\Desktop
Loaded Profiles: Teschke (Available Profiles: Teschke & Admin)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(AMD) C:\Windows\System32\atiesrxx.exe
(Logitech Inc.) C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Wacom\WTabletServicePro.exe
(Wacom Technology) C:\Program Files\Tablet\Wacom\WacomHost.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Advanced Micro Devices) C:\Program Files\AMD\{920DEC42-4CA5-4d1d-9487-67BE645CDDFC}\amdacpusrsvc.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(McAfee, Inc.) C:\Program Files (x86)\McAfee\SiteAdvisor\mcsacore.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe
(McAfee, Inc.) C:\Windows\System32\mfevtps.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\ModuleCore\ModuleCoreService.exe
(McAfee, Inc.) C:\Windows\System32\mfevtps.exe
(Nuance Communications, Inc.) C:\Program Files (x86)\Nuance\PaperPort\PDFProFiltSrvPP.exe
(Intel Security, Inc.) C:\Program Files\Common Files\Intel Security\PEF\CORE\PEFService.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
() C:\Windows\SysWOW64\PnkBstrB.exe
(Protexis Inc.) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe
(arvato digital services llc) C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Wacom Technology) C:\Program Files\Tablet\Wacom\WacomHost.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Wacom\Wacom_TouchUser.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE
(Acresso Corporation) C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe
(Spotify Ltd) C:\Users\Teschke\AppData\Roaming\Spotify\SpotifyWebHelper.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
(Nuance Communications, Inc.) C:\Program Files (x86)\Nuance\PaperPort\pptd40nt.exe
(Nuance Communications, Inc.) C:\Program Files (x86)\Nuance\PDF Viewer Plus\pdfPro5Hook.exe
(Brother Industries, Ltd.) C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe
(Brother Industries, Ltd.) C:\Program Files (x86)\ControlCenter4\BrCtrlCntr.exe
(Brother Industries, Ltd.) C:\Program Files (x86)\ControlCenter4\BrCcUxSys.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\Platform\McUICnt.exe
(McAfee, Inc.) C:\Program Files\McAfee\MfeAV\MfeAVSvc.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\VSCore_15_7\mcapexe.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe
(Brother Industries, Ltd.) C:\Program Files (x86)\Browny02\BrYNSvc.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe
(McAfee, Inc.) C:\Program Files (x86)\McAfee\SiteAdvisor\saUI.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\ink\InputPersonalization.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.7\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.7\GoogleCrashHandler64.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\ModuleCore\ModuleCoreService.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\CSP\2.5.312.0\McCSPServiceHost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\wbem\WMIADAP.exe
(McAfee LLC.) C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
 
==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [10920552 2010-06-22] (Realtek Semiconductor)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe [283160 2010-09-13] (Intel Corporation)
HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKLM-x32\...\Run: [IndexSearch] => C:\Program Files (x86)\Nuance\PaperPort\IndexSearch.exe [46368 2010-03-09] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [PaperPort PTD] => C:\Program Files (x86)\Nuance\PaperPort\pptd40nt.exe [29984 2010-03-09] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [PPort12reminder] => "C:\Program Files (x86)\Nuance\PaperPort\Ereg\Ereg.exe" -r "C:\ProgramData\ScanSoft\PaperPort\12\Config\Ereg\Ereg.ini"
HKLM-x32\...\Run: [PDFHook] => C:\Program Files (x86)\Nuance\PDF Viewer Plus\pdfpro5hook.exe [636192 2010-03-05] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [PDF5 Registry Controller] => C:\Program Files (x86)\Nuance\PDF Viewer Plus\RegistryController.exe [62752 2010-03-05] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [ControlCenter4] => C:\Program Files (x86)\ControlCenter4\BrCcBoot.exe [143360 2012-09-06] (Brother Industries, Ltd.)
HKLM-x32\...\Run: [BrStsMon00] => C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe [3076096 2012-06-06] (Brother Industries, Ltd.)
HKU\S-1-5-21-3289118944-4034126387-1954186238-1000\...\Run: [OfficeSyncProcess] => C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE [721504 2015-09-02] (Microsoft Corporation)
HKU\S-1-5-21-3289118944-4034126387-1954186238-1000\...\Run: [ISUSPM] => C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe [222496 2009-05-05] (Acresso Corporation)
HKU\S-1-5-21-3289118944-4034126387-1954186238-1000\...\Run: [Spotify Web Helper] => C:\Users\Teschke\AppData\Roaming\Spotify\SpotifyWebHelper.exe [780688 2018-01-18] (Spotify Ltd)
HKU\S-1-5-21-3289118944-4034126387-1954186238-1000\...\Policies\system: [LogonHoursAction] 2
HKU\S-1-5-21-3289118944-4034126387-1954186238-1000\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
HKU\S-1-5-21-3289118944-4034126387-1954186238-1000\...\MountPoints2: {ecb585ac-a7d5-11e2-9d96-806e6f6e6963} - D:\autoRcd.exe
HKU\S-1-5-18\...\Run: [GarminExpressTrayApp] => C:\Program Files (x86)\Garmin\Express Tray\tray.exe [1010008 2015-04-08] (Garmin Ltd. or its subsidiaries)
HKU\S-1-5-18\...\RunOnce: [SPReview] => "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"hxxp://go.microsoft.com/fwlink/?LinkID=122915" /build:7601
Startup: C:\Users\Teschke\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk [2018-01-25]
ShortcutTarget: OneNote 2010 Screen Clipper and Launcher.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
GroupPolicy\User: Restriction <==== ATTENTION
GroupPolicyUsers\S-1-5-21-3289118944-4034126387-1954186238-1003\User: Restriction <==== ATTENTION
GroupPolicyUsers\S-1-5-21-3289118944-4034126387-1954186238-1000\User: Restriction <==== ATTENTION
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Tcpip\Parameters: [DhcpNameServer] 199.166.6.2 209.239.11.98
Tcpip\..\Interfaces\{E3D08391-DA71-4B1B-9F02-0CCEDCEF505A}: [DhcpNameServer] 199.166.6.2 209.239.11.98
 
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-3289118944-4034126387-1954186238-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.ca/
URLSearchHook: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000 - (No Name) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - No File
SearchScopes: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000 -> DefaultScope {49DABC51-C6C4-4160-8197-B334814CCCE5} URL = hxxps://search.yahoo.com/search?fr=mcafee&type=C011US91038D20130825&p={searchTerms}
SearchScopes: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000 -> {49DABC51-C6C4-4160-8197-B334814CCCE5} URL = hxxps://search.yahoo.com/search?fr=mcafee&type=C011US91038D20130825&p={searchTerms}
SearchScopes: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000 -> {49DE4C69-1A45-422D-97A4-9B692ECF5F83} URL = hxxps://search.yahoo.com/search?fr=mcafee&type=C011US0D19700101&p={searchTerms}
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-04-27] (Google Inc.)
BHO: McAfee WebAdvisor BHO -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll [2018-01-19] (McAfee, Inc.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: PlusIEEventHelper Class -> {551A852F-39A6-44A7-9C13-AFBEC9185A9D} -> C:\Program Files (x86)\Nuance\PDF Viewer Plus\Bin\PlusIEContextMenu.dll [2009-02-06] (Zeon Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\ssv.dll [2014-10-20] (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2016-04-27] (Google Inc.)
BHO-x32: McAfee WebAdvisor BHO -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll [2018-01-19] (McAfee, Inc.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\jp2ssv.dll [2014-10-20] (Oracle Corporation)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-04-27] (Google Inc.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2016-04-27] (Google Inc.)
DPF: HKLM-x32 {A2505C6C-6F17-456F-89D2-4301FBDC6EC7} hxxps://ssl.grhosp.on.ca/nortel_cacheable/iewiper.cab
DPF: HKLM-x32 {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} hxxps://join-test.webex.com/client/WBXclient-T30L10NSP13EP1-10006/webex/ieatgpc1.cab
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll [2018-01-19] (McAfee, Inc.)
Handler-x32: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll [2018-01-19] (McAfee, Inc.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\McAfee\MSC\McSnIePl64.dll [2017-07-10] (McAfee, Inc.)
Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\MSC\McSnIePl.dll [2017-07-10] (McAfee, Inc.)
 
FireFox:
========
FF DefaultProfile: gd2bren1.default
FF ProfilePath: C:\Users\Teschke\AppData\Roaming\Mozilla\Firefox\Profiles\gd2bren1.default [2017-12-01]
FF Extension: (Firefox Hotfix) - C:\Users\Teschke\AppData\Roaming\Mozilla\Firefox\Profiles\gd2bren1.default\Extensions\firefox-hotfix@mozilla.org.xpi [2016-12-08] [Legacy]
FF HKLM\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor\e10ssaffplg.xpi
FF Extension: (No Name) - C:\Program Files (x86)\McAfee\SiteAdvisor\e10ssaffplg.xpi [2017-12-07]
FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor\e10ssaffplg.xpi
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_28_0_0_137.dll [2018-01-09] ()
FF Plugin: @garmin.com/GpsControl -> C:\Program Files\Garmin GPS Plugin\npGarmin.dll [2014-03-31] (GARMIN Corp.)
FF Plugin: @mcafee.com/MSC,version=10 -> c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL [2017-07-10] ()
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin: @wacom.com/wtPlugin,version=2.1.0.7 -> C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll [2014-03-25] (Wacom)
FF Plugin: wacom.com/WacomTabletPlugin -> C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll [2014-03-25] (Wacom)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_28_0_0_137.dll [2018-01-09] ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2016-03-08] ()
FF Plugin-x32: @garmin.com/GpsControl -> C:\Program Files (x86)\Garmin GPS Plugin\npGarmin.dll [2014-03-31] (GARMIN Corp.)
FF Plugin-x32: @java.com/DTPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll [2014-10-20] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\plugin2\npjp2.dll [2014-10-20] (Oracle Corporation)
FF Plugin-x32: @mcafee.com/MSC,version=10 -> c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL [2017-07-10] ()
FF Plugin-x32: @mcafee.com/MVT -> C:\Program Files (x86)\McAfee\Supportability\MVT\NPMVTPlugin.dll [2016-03-07] (McAfee, Inc.)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll [2014-02-14] (Pando Networks)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-14] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-14] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.8 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2013-07-30] (VideoLAN)
FF Plugin-x32: @wacom.com/wtPlugin,version=2.1.0.7 -> C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll [2014-03-25] (Wacom)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2013-05-11] (Adobe Systems Inc.)
FF Plugin-x32: wacom.com/WacomTabletPlugin -> C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll [2014-03-25] (Wacom)
FF Plugin HKU\S-1-5-21-3289118944-4034126387-1954186238-1000: @hola.org/FlashPlayer -> C:\Users\Teschke\AppData\Local\Hola\firefox_hola\app\flash\NPSWF32_18_0_0_232.dll [2016-01-30] ()
FF Plugin HKU\S-1-5-21-3289118944-4034126387-1954186238-1000: @hola.org/vlc -> C:\Users\Teschke\AppData\Local\Hola\firefox_hola\app\vlc\npvlc.dll [2016-01-30] (Hola)
FF Plugin HKU\S-1-5-21-3289118944-4034126387-1954186238-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Teschke\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2015-08-21] (Unity Technologies ApS)
FF Plugin HKU\S-1-5-21-3289118944-4034126387-1954186238-1000: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [2016-01-14] ()
 
Chrome: 
=======
CHR DefaultProfile: Profile 3
CHR HomePage: Profile 3 -> hxxps://www.google.ca/
CHR StartupUrls: Profile 3 -> "hxxp://www.google.ca/"
CHR DefaultSearchURL: Profile 3 -> hxxps://search.yahoo.com/search?fr=mcafee&type=C211US0D20170114&p={searchTerms}
CHR DefaultSearchKeyword: Profile 3 -> mcafee
CHR Profile: C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default [2015-11-28]
CHR Extension: (BeGone Guerra Online) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\ahcchnfnladlkddlceegencfccjcfnjp [2013-09-19]
CHR Extension: (Plants vs. Zombies HD) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\ahdfeknjbgfbkmemaoffkebceonhcjfd [2013-09-19]
CHR Extension: (Beatlab) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\alnfdikmbdfgkcbdodjcbmedanjinmkk [2015-04-20]
CHR Extension: (Google Drive) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-20]
CHR Extension: (UJAM - Make your music.) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdiogojbmdncjdpljocafnigiokgmci [2013-09-19]
CHR Extension: (Free Running 2 3D) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakechaaagjbdhedidbfifkembmkhafl [2013-09-19]
CHR Extension: (BeGone: Last Stand HD) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\bmekbplkjhgmljmbblmhmcnocafhaink [2013-09-19]
CHR Extension: (Battlefield Heroes) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\cehdakiococlfmjcbebbkjkfjhbieknh [2013-09-21]
CHR Extension: (Rush Team) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\ecdnoeebfjlplfkljdedokbcmebojbpb [2013-10-10]
CHR Extension: (Freefall Tournament) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\encjogopgacdjlkmpdknhlfnanoihodh [2015-03-18]
CHR Extension: (Music Maker) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\epnoajccaiifhpidemmcdamilpeblipc [2014-03-27]
CHR Extension: (Google Play Music) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\fahmaaghhglfmonjliepjlchgpgfmobi [2015-11-18]
CHR Extension: (PicMonkey) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\fgdgokchhicmaiacmgegjnppjkgogdhm [2014-10-24]
CHR Extension: (SiteAdvisor) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2015-07-02]
CHR Extension: (Counter Strike Online ) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\fplklihjpkinahlihcljhnnlnhnmmhdp [2013-09-19]
CHR Extension: (Google Docs Offline) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-11-18]
CHR Extension: (Unlimited Free VPN - Hola) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkojfkhlekighikafcpjkiklfbnlmeio [2015-11-28]
CHR Extension: (Happy Wheels) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\hpljdpjoahbnnfilkiilnfdkdbfiabfc [2013-09-19]
CHR Extension: (Apocalypse City) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifkogipjfpemebgfjelkfoifapppddeh [2013-09-19]
CHR Extension: (Digital BeatMaker) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihjdooenciklfgogkejekglpoeedphmc [2014-03-27]
CHR Extension: (90`s Games) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\illbbfoihflomkbpcaaakhijinbnejom [2015-03-14]
CHR Extension: (theHunter) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\jangaedeekciafhlanphhnalogmhefmo [2013-09-19]
CHR Extension: (Super Mario Bros HD) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmhilnfngnmcnlekfgcglogafjkahoml [2013-09-19]
CHR Extension: (Eyes - The Horror Game) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\jojpkokphfnjlhbnbcilnhgnkkobkngd [2013-09-19]
CHR Extension: (Resident Evil) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\kelgpfmgciingekkpfaikcjmcomfikgp [2013-09-19]
CHR Extension: (Aqua Planet) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\kkfobnmhjmjkgojmfldhnkmfcdjjakhb [2013-09-20]
CHR Extension: (Dead Zed Zombie) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\lcdhiflblofckjcpphgcoajnebhbdpja [2013-09-19]
CHR Extension: (Counter-Strike-Online 2) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\liihamdfalaafmojcdakajejmcbnjkce [2013-09-19]
CHR Extension: (Plink) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\loeiekheegipnnbcfbfkanbbegkhjjcm [2013-09-20]
CHR Extension: (Slender Space) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkdmfheflfmedmfjolgifliincdhfgdl [2013-09-19]
CHR Extension: (Mixify) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkjlbfglfefcmkmglakdocbgnggeieno [2014-03-27]
CHR Extension: (Plants vs Zombies) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmcegpfdgcoclcdfkjahiimlikdpnina [2013-09-21]
CHR Extension: (BeGone) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndfpieflbjbdpgklkeolbmbdkfdiicfk [2015-06-27]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-07-23]
CHR Extension: (Mini Ninjas) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\oijfbknbncemokdnlboeabbcfhobechi [2013-09-19]
CHR Extension: (Battlefield Play4Free) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\oiokahphinmbmakkehgelkmpolmnbkdh [2013-09-19]
CHR Profile: C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 1 [2015-11-28]
CHR Extension: (Google Slides) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-11-28]
CHR Extension: (Google Docs) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2015-11-28]
CHR Extension: (Google Drive) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-11-28]
CHR Extension: (YouTube) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-11-28]
CHR Extension: (Google Search) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-11-28]
CHR Extension: (Google Sheets) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-11-28]
CHR Extension: (SiteAdvisor) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2015-11-28]
CHR Extension: (Google Docs Offline) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-11-28]
CHR Extension: (Unlimited Free VPN - Hola) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gkojfkhlekighikafcpjkiklfbnlmeio [2015-11-28]
CHR Extension: (Video Recorder for WeVideo) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\iaiglpeefdoagfbbfhjfbmomnfobojia [2015-11-28]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-11-28]
CHR Extension: (Gmail) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-11-28]
CHR Profile: C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 2 [2015-11-29]
CHR Extension: (Google Slides) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-11-28]
CHR Extension: (Google Docs) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\aohghmighlieiainnegkcijnfilokake [2015-11-28]
CHR Extension: (Google Drive) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-11-28]
CHR Extension: (YouTube) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-11-28]
CHR Extension: (Google Search) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-11-28]
CHR Extension: (MLG-ifier) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\dneebgdgldanagagmfhnphjelnngdcai [2015-11-28]
CHR Extension: (Google Sheets) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-11-28]
CHR Extension: (SiteAdvisor) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2015-11-28]
CHR Extension: (Google Docs Offline) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-11-28]
CHR Extension: (Read&Write for Google Chrome™) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\inoeonmfapjbbkmdafoankkfajkcphgd [2015-11-28]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-11-28]
CHR Extension: (Gmail) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-11-28]
CHR Extension: (Snapverter) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\plebojnaihkfjkkpgaemcjpnkmcpleih [2015-11-28]
CHR Profile: C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 3 [2018-01-27]
CHR Extension: (Slides) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-10-12]
CHR Extension: (Docs) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-12]
CHR Extension: (Google Drive) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-11-29]
CHR Extension: (YouTube) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-11-29]
CHR Extension: (Google Search) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-11-29]
CHR Extension: (Sheets) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-10-12]
CHR Extension: (McAfee® WebAdvisor) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2017-11-22]
CHR Extension: (Google Docs Offline) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-26]
CHR Extension: (Unlimited Free VPN - Hola) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\gkojfkhlekighikafcpjkiklfbnlmeio [2018-01-22]
CHR Extension: (Video Recorder for WeVideo) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\iaiglpeefdoagfbbfhjfbmomnfobojia [2017-12-14]
CHR Extension: (Project Viewer 365-Free) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\kmpghmkgkalhonankenfklpmdgnilapp [2016-04-07]
CHR Extension: (Cloud Drive, URL to ChromeCast™) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\mehfijocnmclokiknjjpcbddbekagnik [2015-12-25]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-08-21]
CHR Extension: (Gmail) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-11-29]
CHR Extension: (Chrome Media Router) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-01-25]
CHR Profile: C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 4 [2018-01-11]
CHR Extension: (Slides) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-01-11]
CHR Extension: (Docs) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\aohghmighlieiainnegkcijnfilokake [2018-01-11]
CHR Extension: (Google Drive) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-01-11]
CHR Extension: (YouTube) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-01-11]
CHR Extension: (Sheets) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-01-11]
CHR Extension: (McAfee® WebAdvisor) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2018-01-11]
CHR Extension: (Google Docs Offline) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-01-11]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-01-11]
CHR Extension: (Gmail) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2018-01-11]
CHR Extension: (Chrome Media Router) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-01-11]
CHR Profile: C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\System Profile [2015-11-29]
CHR HKLM\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - hxxp://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - hxxp://clients2.google.com/service/update2/crx
 
==================== Services (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 amdacpusrsvc; C:\Program Files\AMD\{920DEC42-4CA5-4d1d-9487-67BE645CDDFC}\amdacpusrsvc.exe [121856 2015-05-05] (Advanced Micro Devices) [File not signed]
S4 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2016-03-02] (Apple Inc.)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [6971400 2018-01-19] ()
R3 BrYNSvc; C:\Program Files (x86)\Browny02\BrYNSvc.exe [266240 2012-06-05] (Brother Industries, Ltd.) [File not signed]
S3 chromoting; C:\Program Files (x86)\Google\Chrome Remote Desktop\63.0.3239.32\remoting_host.exe [71512 2017-11-02] (Google Inc.)
S3 ClientAnalyticsService; C:\Program Files\Common Files\McAfee\ClientAnalytics\Legacy\McClientAnalytics.exe [1509680 2017-07-13] (McAfee, Inc.)
S4 Garmin Device Interaction Service; C:\Program Files (x86)\Garmin\Device Interaction Service\GarminService.exe [708616 2015-04-08] (Garmin Ltd. or its subsidiaries)
S4 lxea_device; C:\Windows\system32\lxeacoms.exe [1052328 2010-04-14] ( )
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6234056 2017-11-01] (Malwarebytes)
R2 McAfee SiteAdvisor Service; C:\Program Files (x86)\McAfee\SiteAdvisor\McSACore.exe [604312 2018-01-19] (McAfee, Inc.)
R2 McAPExe; C:\Program Files\Common Files\McAfee\VSCore_15_7\McApExe.exe [990696 2017-07-20] (McAfee, Inc.)
R2 mccspsvc; C:\Program Files\Common Files\McAfee\CSP\2.5.312.0\\McCSPServiceHost.exe [2139832 2017-05-30] (McAfee, Inc.)
R3 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe [242640 2017-06-21] (McAfee, Inc.)
R2 mfemms; C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe [394704 2017-06-21] (McAfee, Inc.)
R3 mfevtp; C:\Windows\system32\mfevtps.exe [350160 2017-06-21] (McAfee, Inc.)
R2 ModuleCoreService; C:\Program Files\Common Files\McAfee\ModuleCore\ModuleCoreService.exe [1545880 2017-06-27] (McAfee, Inc.)
S4 NETGEARGenieDaemon; C:\Program Files (x86)\NETGEAR Genie\bin\NETGEARGenieDaemon64.exe [232192 2015-06-01] (NETGEAR)
R2 PDFProFiltSrvPP; C:\Program Files (x86)\Nuance\PaperPort\PDFProFiltSrvPP.exe [144672 2010-03-09] (Nuance Communications, Inc.)
R2 PEFService; C:\Program Files\Common Files\Intel Security\PEF\CORE\PEFService.exe [1044376 2017-07-07] (Intel Security, Inc.)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [66872 2015-04-21] ()
R2 PnkBstrB; C:\Windows\SysWOW64\PnkBstrB.exe [107832 2015-04-21] ()
R2 PSI_SVC_2_x64; c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe [337776 2014-04-30] (arvato digital services llc)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
R2 WTabletServicePro; C:\Program Files\Tablet\Wacom\WTabletServicePro.exe [652240 2016-07-14] (Wacom Technology, Corp.)
S2 HomeNetSvc; "C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe" /McCoreSvc [X]
S2 McBootDelayStartSvc; "C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe" /McCoreSvc [X]
S2 McMPFSvc; "C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe" /McCoreSvc [X]
S2 mcpltsvc; "C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe" /McCoreSvc [X]
S2 McProxy; "C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe" /McCoreSvc [X]
 
===================== Drivers (Whitelisted) ======================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 amdacpksd; C:\Windows\system32\drivers\amdacpksd.sys [297160 2015-05-05] (Advanced Micro Devices)
S3 cfwids; C:\Windows\System32\drivers\cfwids.sys [77800 2017-06-26] (McAfee, Inc.)
R1 ESProtectionDriver; C:\Windows\system32\drivers\mbae64.sys [77432 2017-12-12] ()
S3 HipShieldK; C:\Windows\System32\drivers\HipShieldK.sys [209616 2017-07-26] (McAfee, Inc.)
R0 MBAMChameleon; C:\Windows\System32\Drivers\MbamChameleon.sys [193968 2018-01-27] (Malwarebytes)
R3 MBAMFarflt; C:\Windows\System32\DRIVERS\farflt.sys [110016 2018-01-27] (Malwarebytes)
R3 MBAMProtection; C:\Windows\System32\DRIVERS\mbam.sys [46008 2018-01-27] (Malwarebytes)
R3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [253880 2018-01-27] (Malwarebytes)
R3 MBAMWebProtection; C:\Windows\System32\DRIVERS\mwac.sys [84256 2018-01-27] (Malwarebytes)
R3 mfeaack; C:\Windows\System32\drivers\mfeaack.sys [487408 2017-06-26] (McAfee, Inc.)
R3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [355312 2017-06-26] (McAfee, Inc.)
U3 mfeavfk01; no ImagePath
R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [506352 2017-06-26] (McAfee, Inc.)
R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [933360 2017-06-26] (McAfee, Inc.)
R3 mfencbdc; C:\Windows\System32\DRIVERS\mfencbdc.sys [504760 2017-05-31] (McAfee LLC.)
S3 mfencrk; C:\Windows\System32\DRIVERS\mfencrk.sys [108472 2017-05-31] (McAfee LLC.)
R3 mfeplk; C:\Windows\System32\drivers\mfeplk.sys [116208 2017-06-26] (McAfee, Inc.)
R3 mfesapsn; C:\Program Files (x86)\McAfee\SiteAdvisor\x64\mfesapsn.sys [111608 2017-02-14] (McAfee, Inc.)
R0 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [253424 2017-06-26] (McAfee, Inc.)
R2 NPF; C:\Windows\system32\drivers\npf.sys [35344 2015-09-29] (CACE Technologies, Inc.)
S3 pmxdrv; C:\Windows\system32\drivers\pmxdrv.sys [31152 2015-09-18] ()
S3 WacHidRouterPro; C:\Windows\System32\DRIVERS\wachidrouter.sys [102864 2016-03-02] (Wacom Technology)
S3 mfeaack01; \Device\mfeaack01.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2018-01-27 15:08 - 2018-01-27 15:10 - 000038762 _____ C:\Users\Teschke\Desktop\FRST.txt
2018-01-27 13:39 - 2018-01-27 15:08 - 000000000 ____D C:\FRST
2018-01-27 13:37 - 2018-01-27 13:28 - 002393088 _____ (Farbar) C:\Users\Teschke\Desktop\FRST64.exe
2018-01-27 13:34 - 2018-01-27 15:04 - 000253880 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamswissarmy.sys
2018-01-27 13:34 - 2018-01-27 13:34 - 000193968 _____ (Malwarebytes) C:\Windows\system32\Drivers\MbamChameleon.sys
2018-01-26 19:03 - 2018-01-26 19:03 - 000619670 _____ C:\Users\Teschke\Desktop\W415-0061_GI3600manual.pdf
2018-01-20 18:11 - 2018-01-27 15:04 - 000084256 _____ (Malwarebytes) C:\Windows\system32\Drivers\mwac.sys
2018-01-19 20:53 - 2018-01-19 20:53 - 000000000 ____D C:\Users\Teschke\AppData\Local\CrashReportClient
2018-01-19 20:18 - 2018-01-18 19:16 - 000000229 ___SH C:\Users\Public\Libraries.ini
2018-01-19 20:15 - 2018-01-19 20:15 - 000000000 ____D C:\Users\Admin\AppData\Local\NVIDIA Corporation
2018-01-19 20:05 - 2018-01-19 20:05 - 000000000 ____D C:\Users\Admin\AppData\Local\FortniteGame
2018-01-19 20:05 - 2018-01-19 20:05 - 000000000 ____D C:\Users\Admin\AppData\Local\CrashReportClient
2018-01-19 20:04 - 2018-01-19 20:04 - 000000000 ____D C:\Users\Teschke\AppData\Local\NVIDIA Corporation
2018-01-19 20:03 - 2018-01-19 20:03 - 000000000 ____D C:\Users\Teschke\AppData\Local\FortniteGame
2018-01-19 19:39 - 2018-01-19 19:39 - 000000000 ___DL C:\Users\Admin\AppData\LocalLow\PlayReady
2018-01-19 19:01 - 2018-01-19 19:02 - 000000000 ____D C:\Program Files\Epic Games
2018-01-19 18:56 - 2018-01-19 20:05 - 000000000 ____D C:\Users\Admin\AppData\Local\UnrealEngine
2018-01-19 18:56 - 2018-01-19 18:56 - 000000000 ____D C:\Users\Admin\AppData\Local\UnrealEngineLauncher
2018-01-19 18:56 - 2018-01-19 18:56 - 000000000 ____D C:\Users\Admin\AppData\Local\EpicGamesLauncher
2018-01-19 18:51 - 2018-01-19 18:51 - 032260096 _____ C:\Users\Teschke\Downloads\EpicInstaller-7.2.0-fortnite-b4c7450ecc744c899c12cef8180e72f1 (1).msi
2018-01-19 18:49 - 2018-01-19 20:03 - 000000000 ____D C:\Users\Teschke\AppData\Local\UnrealEngine
2018-01-19 18:49 - 2018-01-19 18:49 - 000000000 ____D C:\Users\Teschke\AppData\Local\UnrealEngineLauncher
2018-01-19 18:49 - 2018-01-19 18:49 - 000000000 ____D C:\Users\Teschke\AppData\Local\EpicGamesLauncher
2018-01-19 18:48 - 2018-01-19 18:48 - 000001242 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Epic Games Launcher.lnk
2018-01-19 18:48 - 2018-01-19 18:48 - 000001230 _____ C:\Users\Public\Desktop\Epic Games Launcher.lnk
2018-01-19 18:48 - 2007-04-04 18:53 - 000081768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_3.dll
2018-01-19 18:47 - 2018-01-19 18:52 - 000000000 ____D C:\ProgramData\Epic
2018-01-19 18:47 - 2018-01-19 18:47 - 000000000 ____D C:\Program Files (x86)\Epic Games
2018-01-19 18:45 - 2018-01-19 18:45 - 032260096 _____ C:\Users\Teschke\Downloads\EpicInstaller-7.2.0-fortnite-b4c7450ecc744c899c12cef8180e72f1.msi
2018-01-16 20:59 - 2018-01-16 20:59 - 000057879 _____ C:\Users\Teschke\Downloads\On_Jesus_Derrida_and_Dawkins_Rejoinder_t (1).pdf
2018-01-16 20:58 - 2018-01-16 20:58 - 000057879 _____ C:\Users\Teschke\Downloads\On_Jesus_Derrida_and_Dawkins_Rejoinder_t.pdf
2018-01-07 14:20 - 2018-01-07 14:20 - 000562772 _____ C:\Users\Teschke\Downloads\NP_EX16_2b_IsaacTeschke_1.xlsx
2018-01-07 14:02 - 2018-01-07 14:02 - 000022355 _____ C:\Users\Teschke\Downloads\NP_EX16_1b_IsaacTeschke_1.xlsx
2018-01-04 21:08 - 2017-12-31 21:21 - 005581544 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2018-01-04 21:08 - 2017-12-31 21:21 - 001680616 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2018-01-04 21:08 - 2017-12-31 21:21 - 000948968 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys
2018-01-04 21:08 - 2017-12-31 21:21 - 000708328 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2018-01-04 21:08 - 2017-12-31 21:21 - 000288488 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fltMgr.sys
2018-01-04 21:08 - 2017-12-31 21:21 - 000262376 _____ (Microsoft Corporation) C:\Windows\system32\hal.dll
2018-01-04 21:08 - 2017-12-31 21:21 - 000213736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdyboost.sys
2018-01-04 21:08 - 2017-12-31 21:21 - 000154856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2018-01-04 21:08 - 2017-12-31 21:21 - 000114408 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2018-01-04 21:08 - 2017-12-31 21:21 - 000095464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2018-01-04 21:08 - 2017-12-31 21:19 - 001665384 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 014183936 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 002066432 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 002004480 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 001942016 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 001867776 _____ (Microsoft Corporation) C:\Windows\system32\ExplorerFrame.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 001741312 _____ (Microsoft Corporation) C:\Windows\system32\sysmain.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 001460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 001212928 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 001163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 001110528 _____ (Microsoft Corporation) C:\Windows\system32\schedsvc.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000977408 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000961024 _____ (Microsoft Corporation) C:\Windows\system32\actxprxy.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000880640 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000863232 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL
2018-01-04 21:08 - 2017-12-31 21:18 - 000842752 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000828928 _____ (Microsoft Corporation) C:\Windows\system32\MPSSVC.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000749568 _____ (Microsoft Corporation) C:\Windows\system32\FirewallAPI.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000731648 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000705024 _____ (Microsoft Corporation) C:\Windows\system32\BFE.DLL
2018-01-04 21:08 - 2017-12-31 21:18 - 000690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000512000 _____ (Microsoft Corporation) C:\Windows\system32\rpcss.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000473600 _____ (Microsoft Corporation) C:\Windows\system32\taskcomp.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000463872 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000444928 _____ (Microsoft Corporation) C:\Windows\system32\winhttp.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000439296 _____ (Microsoft Corporation) C:\Windows\system32\p2psvc.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000419840 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000366592 _____ (Microsoft Corporation) C:\Windows\system32\wcncsvc.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000361984 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000345600 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000327168 _____ (Microsoft Corporation) C:\Windows\system32\pnrpsvc.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000324096 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL
2018-01-04 21:08 - 2017-12-31 21:18 - 000316928 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000303104 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000264704 _____ (Microsoft Corporation) C:\Windows\system32\P2P.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000223232 _____ (Microsoft Corporation) C:\Windows\system32\ncsi.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000215552 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000190464 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000123904 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000120320 _____ (Microsoft Corporation) C:\Windows\system32\WcnApi.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000108544 _____ (Microsoft Corporation) C:\Windows\system32\icfupgd.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000101376 _____ (Microsoft Corporation) C:\Windows\system32\fdWCN.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000095744 _____ (Microsoft Corporation) C:\Windows\system32\rascfg.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000084480 _____ (Microsoft Corporation) C:\Windows\system32\INETRES.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000076288 _____ (Microsoft Corporation) C:\Windows\system32\rasdiag.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000070656 _____ (Microsoft Corporation) C:\Windows\system32\nlaapi.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000070144 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000060928 _____ (Microsoft Corporation) C:\Windows\system32\ndptsp.tsp
2018-01-04 21:08 - 2017-12-31 21:18 - 000060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000059904 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000047104 _____ (Microsoft Corporation) C:\Windows\system32\kmddsp.tsp
2018-01-04 21:08 - 2017-12-31 21:18 - 000044032 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000041472 _____ (Microsoft Corporation) C:\Windows\system32\rasmxs.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000039424 _____ (Microsoft Corporation) C:\Windows\system32\traffic.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000034816 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000029696 _____ (Microsoft Corporation) C:\Windows\system32\rasser.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000026112 _____ (Microsoft Corporation) C:\Windows\system32\oleres.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000024576 _____ (Microsoft Corporation) C:\Windows\system32\WcnEapPeerProxy.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000024064 _____ (Microsoft Corporation) C:\Windows\system32\WcnEapAuthProxy.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000022528 _____ (Microsoft Corporation) C:\Windows\system32\wfapigp.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000016896 _____ (Microsoft Corporation) C:\Windows\system32\wshqos.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000013312 _____ (Microsoft Corporation) C:\Windows\system32\wshnetbs.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000008704 _____ (Microsoft Corporation) C:\Windows\system32\comcat.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml6r.dll
2018-01-04 21:08 - 2017-12-31 21:13 - 000631680 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2018-01-04 21:08 - 2017-12-31 21:04 - 000559616 _____ (Microsoft Corporation) C:\Windows\system32\spoolsv.exe
2018-01-04 21:08 - 2017-12-31 21:02 - 001314112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 012880384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 001499648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ExplorerFrame.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 001417728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 001390080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 001114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000741888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000666624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000666112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000554496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000463360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FirewallAPI.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000351744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winhttp.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000304640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\taskcomp.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000276992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wcncsvc.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000275456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000261120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000254464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000217600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\P2P.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000216576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL
2018-01-04 21:08 - 2017-12-31 21:00 - 000172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000162304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncsi.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000084480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\INETRES.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcrypt.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fdWCN.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000081408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rascfg.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rasdiag.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000052224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ndptsp.tsp
2018-01-04 21:08 - 2017-12-31 21:00 - 000043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\traffic.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000026112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleres.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6r.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 001806848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000644096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000309760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\actxprxy.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:55 - 000131584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\pacer.sys
2018-01-04 21:08 - 2017-12-31 20:55 - 000088576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\wanarp.sys
2018-01-04 21:08 - 2017-12-31 20:55 - 000058368 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndproxy.sys
2018-01-04 21:08 - 2017-12-31 20:55 - 000045056 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netbios.sys
2018-01-04 21:08 - 2017-12-31 20:55 - 000024064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndistapi.sys
2018-01-04 21:08 - 2017-12-31 20:54 - 004013800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2018-01-04 21:08 - 2017-12-31 20:54 - 003959016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2018-01-04 21:08 - 2017-12-31 20:54 - 000077312 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mpsdrv.sys
2018-01-04 21:08 - 2017-12-31 20:50 - 000455680 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2018-01-04 21:08 - 2017-12-31 20:49 - 000148480 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2018-01-04 21:08 - 2017-12-31 20:49 - 000064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2018-01-04 21:08 - 2017-12-31 20:49 - 000062464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2018-01-04 21:08 - 2017-12-31 20:49 - 000017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2018-01-04 21:08 - 2017-12-31 20:46 - 000338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2018-01-04 21:08 - 2017-12-31 20:45 - 000296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2018-01-04 21:08 - 2017-12-31 20:43 - 000086528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WcnApi.dll
2018-01-04 21:08 - 2017-12-31 20:43 - 000038912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kmddsp.tsp
2018-01-04 21:08 - 2017-12-31 20:43 - 000033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rasmxs.dll
2018-01-04 21:08 - 2017-12-31 20:43 - 000022528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rasser.dll
2018-01-04 21:08 - 2017-12-31 20:43 - 000020480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WcnEapPeerProxy.dll
2018-01-04 21:08 - 2017-12-31 20:43 - 000019968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WcnEapAuthProxy.dll
2018-01-04 21:08 - 2017-12-31 20:43 - 000018944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wfapigp.dll
2018-01-04 21:08 - 2017-12-31 20:43 - 000013824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshqos.dll
2018-01-04 21:08 - 2017-12-31 20:42 - 000460288 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys
2018-01-04 21:08 - 2017-12-31 20:42 - 000406016 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys
2018-01-04 21:08 - 2017-12-31 20:42 - 000168448 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys
2018-01-04 21:08 - 2017-12-31 20:42 - 000159744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2018-01-04 21:08 - 2017-12-31 20:41 - 000754176 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys
2018-01-04 21:08 - 2017-12-31 20:41 - 000291328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2018-01-04 21:08 - 2017-12-31 20:41 - 000129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2018-01-04 21:08 - 2017-12-31 20:41 - 000112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2018-01-04 21:08 - 2017-12-31 20:41 - 000106496 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dfsc.sys
2018-01-04 21:08 - 2017-12-31 20:41 - 000030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2018-01-04 21:08 - 2017-12-31 20:41 - 000007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comcat.dll
2018-01-04 21:08 - 2017-12-31 20:39 - 000050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2018-01-04 21:08 - 2017-12-31 20:36 - 000025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2018-01-04 21:08 - 2017-12-31 20:36 - 000014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2018-01-04 21:08 - 2017-12-31 20:36 - 000007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2018-01-04 21:08 - 2017-12-31 20:36 - 000002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2018-01-04 21:08 - 2017-12-31 20:35 - 000036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
2018-01-04 21:08 - 2017-12-31 20:35 - 000006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:35 - 000004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:35 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:35 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2018-01-04 21:08 - 2017-12-30 02:29 - 000395968 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2018-01-04 21:08 - 2017-12-30 01:42 - 000347328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2018-01-04 21:08 - 2017-12-29 13:39 - 020274688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2018-01-04 21:08 - 2017-12-29 13:24 - 002724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2018-01-04 21:08 - 2017-12-29 13:13 - 000499712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2018-01-04 21:08 - 2017-12-29 13:13 - 000062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2018-01-04 21:08 - 2017-12-29 13:12 - 000341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2018-01-04 21:08 - 2017-12-29 13:12 - 000047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2018-01-04 21:08 - 2017-12-29 13:11 - 000064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2018-01-04 21:08 - 2017-12-29 13:09 - 002294272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2018-01-04 21:08 - 2017-12-29 13:06 - 000047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2018-01-04 21:08 - 2017-12-29 13:06 - 000030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2018-01-04 21:08 - 2017-12-29 13:04 - 000476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2018-01-04 21:08 - 2017-12-29 13:03 - 000662528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2018-01-04 21:08 - 2017-12-29 13:03 - 000620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2018-01-04 21:08 - 2017-12-29 13:03 - 000115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2018-01-04 21:08 - 2017-12-29 12:55 - 000416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2018-01-04 21:08 - 2017-12-29 12:51 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2018-01-04 21:08 - 2017-12-29 12:50 - 000091136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2018-01-04 21:08 - 2017-12-29 12:50 - 000073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2018-01-04 21:08 - 2017-12-29 12:47 - 000168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2018-01-04 21:08 - 2017-12-29 12:47 - 000076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2018-01-04 21:08 - 2017-12-29 12:46 - 000279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2018-01-04 21:08 - 2017-12-29 12:45 - 004508160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2018-01-04 21:08 - 2017-12-29 12:44 - 000130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2018-01-04 21:08 - 2017-12-29 12:39 - 000230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2018-01-04 21:08 - 2017-12-29 12:38 - 013680128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2018-01-04 21:08 - 2017-12-29 12:38 - 000694272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2018-01-04 21:08 - 2017-12-29 12:37 - 002058752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2018-01-04 21:08 - 2017-12-29 12:36 - 001155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2018-01-04 21:08 - 2017-12-29 12:19 - 002767872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2018-01-04 21:08 - 2017-12-29 12:15 - 001313792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2018-01-04 21:08 - 2017-12-29 12:13 - 000710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2018-01-04 21:08 - 2017-12-29 04:15 - 025737728 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2018-01-04 21:08 - 2017-12-29 04:04 - 002724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2018-01-04 21:08 - 2017-12-29 04:04 - 000004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2018-01-04 21:08 - 2017-12-29 03:52 - 002900480 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2018-01-04 21:08 - 2017-12-29 03:51 - 005796352 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2018-01-04 21:08 - 2017-12-29 03:51 - 000066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2018-01-04 21:08 - 2017-12-29 03:50 - 000577024 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2018-01-04 21:08 - 2017-12-29 03:50 - 000417280 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2018-01-04 21:08 - 2017-12-29 03:50 - 000088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2018-01-04 21:08 - 2017-12-29 03:50 - 000048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2018-01-04 21:08 - 2017-12-29 03:44 - 000054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2018-01-04 21:08 - 2017-12-29 03:43 - 000034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2018-01-04 21:08 - 2017-12-29 03:40 - 000615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2018-01-04 21:08 - 2017-12-29 03:39 - 000817152 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2018-01-04 21:08 - 2017-12-29 03:39 - 000814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2018-01-04 21:08 - 2017-12-29 03:39 - 000144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2018-01-04 21:08 - 2017-12-29 03:39 - 000116224 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2018-01-04 21:08 - 2017-12-29 03:32 - 000969216 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2018-01-04 21:08 - 2017-12-29 03:28 - 000489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2018-01-04 21:08 - 2017-12-29 03:22 - 000087552 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2018-01-04 21:08 - 2017-12-29 03:22 - 000077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2018-01-04 21:08 - 2017-12-29 03:21 - 000107520 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2018-01-04 21:08 - 2017-12-29 03:18 - 000199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2018-01-04 21:08 - 2017-12-29 03:18 - 000092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2018-01-04 21:08 - 2017-12-29 03:16 - 000315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2018-01-04 21:08 - 2017-12-29 03:14 - 000152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2018-01-04 21:08 - 2017-12-29 03:05 - 000262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2018-01-04 21:08 - 2017-12-29 03:04 - 015284224 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2018-01-04 21:08 - 2017-12-29 03:03 - 000807936 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2018-01-04 21:08 - 2017-12-29 03:03 - 000726528 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2018-01-04 21:08 - 2017-12-29 03:01 - 002134528 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2018-01-04 21:08 - 2017-12-29 03:01 - 001359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2018-01-04 21:08 - 2017-12-29 02:50 - 003241472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2018-01-04 21:08 - 2017-12-29 02:39 - 001545728 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2018-01-04 21:08 - 2017-12-29 02:27 - 000800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2018-01-04 21:08 - 2017-12-21 01:27 - 000634312 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
2018-01-04 21:08 - 2017-12-13 11:31 - 000383720 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2018-01-04 21:08 - 2017-12-13 11:27 - 000100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2018-01-04 21:08 - 2017-12-13 11:27 - 000046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2018-01-04 21:08 - 2017-12-13 11:27 - 000041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2018-01-04 21:08 - 2017-12-13 11:27 - 000014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2018-01-04 21:08 - 2017-12-13 11:15 - 000309480 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2018-01-04 21:08 - 2017-12-13 11:11 - 000071168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2018-01-04 21:08 - 2017-12-13 11:11 - 000025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
2018-01-04 21:08 - 2017-12-13 11:11 - 000010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
2018-01-04 21:08 - 2017-12-13 10:50 - 000034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2018-01-04 21:08 - 2017-12-05 12:36 - 000625664 _____ (Microsoft Corporation) C:\Windows\system32\mscms.dll
2018-01-04 21:08 - 2017-12-05 12:36 - 000250880 _____ (Microsoft Corporation) C:\Windows\system32\icm32.dll
2018-01-04 21:08 - 2017-12-05 12:36 - 000040960 _____ (Microsoft Corporation) C:\Windows\system32\WcsPlugInService.dll
2018-01-04 21:08 - 2017-12-05 12:08 - 000481792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscms.dll
2018-01-04 21:08 - 2017-12-05 12:08 - 000215040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icm32.dll
2018-01-04 21:08 - 2017-12-05 10:59 - 003222528 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2018-01-04 21:08 - 2017-12-05 10:49 - 000032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WcsPlugInService.dll
2018-01-04 19:50 - 2018-01-04 19:50 - 000053941 _____ C:\Users\Teschke\Downloads\NP_PPT16_1b_IsaacTeschke_1 (1).pptx
2018-01-02 12:51 - 2018-01-02 12:51 - 000099306 _____ C:\Users\Teschke\Downloads\340906__passairmangrace__tablehit-mono-bip.wav
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2018-01-27 15:09 - 2009-07-14 00:13 - 000782470 _____ C:\Windows\system32\PerfStringBackup.INI
2018-01-27 15:09 - 2009-07-13 22:20 - 000000000 ____D C:\Windows\inf
2018-01-27 15:05 - 2017-12-12 04:54 - 000046008 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2018-01-27 15:04 - 2017-12-12 04:53 - 000110016 _____ (Malwarebytes) C:\Windows\system32\Drivers\farflt.sys
2018-01-27 15:01 - 2009-07-14 00:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2018-01-27 13:43 - 2014-05-30 15:16 - 001102276 _____ C:\Windows\ntbtlog.txt
2018-01-27 12:41 - 2013-04-20 14:11 - 000000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2018-01-27 12:41 - 2009-07-13 23:45 - 000022656 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2018-01-27 12:41 - 2009-07-13 23:45 - 000022656 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2018-01-27 11:33 - 2017-11-05 20:22 - 000001690 _____ C:\Users\Admin\Desktop\Rkill.txt
2018-01-26 19:35 - 2013-08-25 20:48 - 000000000 ____D C:\Program Files (x86)\McAfee
2018-01-26 19:34 - 2017-01-14 13:55 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
2018-01-26 19:33 - 2015-09-22 22:11 - 000065536 _____ C:\Windows\system32\spu_storage.bin
2018-01-26 15:10 - 2013-04-21 13:55 - 000000000 ____D C:\Users\Teschke\AppData\Local\CrashDumps
2018-01-25 19:53 - 2013-04-18 07:01 - 000000000 ____D C:\Users\Teschke\Documents\Outlook Files
2018-01-25 19:31 - 2013-04-18 00:03 - 000001236 __RSH C:\Users\Teschke\ntuser.pol
2018-01-25 19:31 - 2013-04-17 20:06 - 000000000 ____D C:\Users\Teschke
2018-01-25 19:14 - 2013-04-18 00:07 - 000001232 __RSH C:\Users\Admin\ntuser.pol
2018-01-25 19:14 - 2013-04-18 00:07 - 000000000 ____D C:\Users\Admin
2018-01-25 19:08 - 2009-07-13 22:20 - 000000000 ____D C:\Windows\registration
2018-01-25 13:12 - 2013-04-20 15:39 - 000000000 ____D C:\Users\Teschke\Documents\Laura
2018-01-24 15:48 - 2013-04-20 14:11 - 000002224 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2018-01-23 17:29 - 2017-07-09 12:08 - 000000000 ____D C:\Users\Teschke\AppData\Local\Spotify
2018-01-23 16:54 - 2017-07-09 12:02 - 000000000 ____D C:\Users\Teschke\AppData\Roaming\Spotify
2018-01-23 11:29 - 2013-04-20 15:50 - 000000000 ____D C:\Users\Teschke\Documents\Isaac
2018-01-23 10:57 - 2014-02-17 18:02 - 001446400 ___SH C:\Users\Teschke\Downloads\Thumbs.db
2018-01-19 18:51 - 2014-11-24 21:35 - 000000000 ____D C:\ProgramData\Package Cache
2018-01-19 03:02 - 2013-04-18 00:33 - 000775462 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2018-01-18 17:03 - 2017-11-05 20:21 - 000009216 ___SH C:\Users\Teschke\Thumbs.db
2018-01-13 06:44 - 2013-04-20 15:28 - 000000000 ____D C:\Program Files (x86)\Steam
2018-01-12 20:50 - 2013-09-28 20:10 - 000000000 ____D C:\Users\Teschke\Documents\Corel VideoStudio Pro
2018-01-10 03:19 - 2013-07-12 17:33 - 000000000 ____D C:\Windows\system32\MRT
2018-01-10 03:13 - 2017-10-12 02:11 - 129365736 ____C (Microsoft Corporation) C:\Windows\system32\MRT-KB890830.exe
2018-01-10 03:13 - 2013-04-19 08:17 - 129365736 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2018-01-09 10:40 - 2017-09-28 16:34 - 000004468 _____ C:\Windows\System32\Tasks\Adobe Flash Player PPAPI Notifier
2018-01-09 10:40 - 2013-04-19 07:28 - 000803328 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2018-01-09 10:40 - 2013-04-19 07:28 - 000144896 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2018-01-09 10:40 - 2013-04-19 07:28 - 000004312 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2018-01-09 10:40 - 2013-04-19 07:28 - 000000000 ____D C:\Windows\system32\Macromed
2018-01-09 10:40 - 2013-04-17 22:41 - 000000000 ____D C:\Windows\SysWOW64\Macromed
2018-01-05 04:11 - 2009-07-13 22:20 - 000000000 ____D C:\Windows\rescache
2018-01-05 03:21 - 2009-07-13 23:45 - 000532872 _____ C:\Windows\system32\FNTCACHE.DAT
2018-01-04 16:59 - 2009-07-13 22:20 - 000000000 ____D C:\Windows\system32\NDF
2018-01-01 00:36 - 2009-07-14 00:08 - 000032542 _____ C:\Windows\Tasks\SCHEDLGU.TXT
 
==================== Files in the root of some directories =======
 
2014-09-30 19:18 - 2015-10-05 05:49 - 000000096 _____ () C:\Users\Teschke\AppData\Roaming\LauncherSettings_live.cfg
2014-09-30 18:25 - 2015-10-05 05:33 - 000000039 _____ () C:\Users\Teschke\AppData\Roaming\TheHunterSettings_live.cfg
2014-03-06 15:07 - 2014-03-06 15:07 - 000003584 _____ () C:\Users\Teschke\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2013-12-29 20:09 - 2013-12-29 20:09 - 000000084 _____ () C:\Users\Teschke\AppData\Local\DVDPATH.TXT
 
Some files in TEMP:
====================
2016-10-15 05:44 - 2015-01-26 11:34 - 000015752 _____ (Autodesk, Inc.) C:\Users\Admin\AppData\Local\Temp\AcDeltree.exe
2017-05-26 21:46 - 2017-05-26 22:10 - 002016632 _____ (Flexera Software LLC) C:\Users\Admin\AppData\Local\Temp\FNP_ACT_InstallerCA.dll
2017-09-10 21:11 - 2017-09-10 21:12 - 000004608 _____ () C:\Users\Admin\AppData\Local\Temp\i4jdel0.exe
2016-11-16 06:28 - 2016-11-16 06:28 - 000244264 _____ (McAfee, Inc.) C:\Users\Admin\AppData\Local\Temp\McCSPInstall.dll
2015-09-22 21:36 - 2015-09-22 21:47 - 060685368 _____ () C:\Users\Admin\AppData\Local\Temp\raptrpatch.exe
2015-09-22 21:36 - 2015-09-22 21:36 - 000221632 _____ () C:\Users\Admin\AppData\Local\Temp\raptr_stub.exe
2006-05-24 12:10 - 2006-05-24 12:10 - 000455600 ____R (Macrovision Corporation) C:\Users\Admin\AppData\Local\Temp\_is897B.exe
2014-01-05 01:00 - 2014-01-05 01:00 - 000003584 _____ () C:\Users\Teschke\AppData\Local\Temp\2supyjld.dll
2013-04-27 10:50 - 2013-04-27 10:50 - 000263186 _____ () C:\Users\Teschke\AppData\Local\Temp\air97CE.exe
2013-05-25 15:00 - 2013-05-25 15:00 - 000263186 _____ () C:\Users\Teschke\AppData\Local\Temp\airAA45.exe
2014-02-15 20:01 - 2014-02-15 20:01 - 000588360 _____ (NCH Software) C:\Users\Teschke\AppData\Local\Temp\bwsetup.exe
2014-08-20 20:25 - 2014-08-20 20:25 - 003166208 _____ () C:\Users\Teschke\AppData\Local\Temp\ffmpeg19.exe
2016-01-30 23:16 - 2016-01-30 23:20 - 023334528 _____ (Hola Networks Ltd.) C:\Users\Teschke\AppData\Local\Temp\Hola-Setup-Plugin-x64-1.11.399.exe
2013-10-30 17:52 - 2013-10-30 17:52 - 001071584 _____ (Solid State Networks) C:\Users\Teschke\AppData\Local\Temp\install_flashplayer11x32ax_chra_awa_aih.exe
2013-11-28 12:24 - 2013-11-28 12:24 - 001071584 _____ (Solid State Networks) C:\Users\Teschke\AppData\Local\Temp\install_flashplayer11x32ax_gtba_chra_dy_aaa_aih.exe
2013-11-28 12:28 - 2013-11-28 12:28 - 001071584 _____ (Solid State Networks) C:\Users\Teschke\AppData\Local\Temp\install_flashplayer11x32ax_gtba_chra_dy_aaa_aih_1.exe
2013-10-08 15:36 - 2013-10-08 15:36 - 001071568 _____ (Solid State Networks) C:\Users\Teschke\AppData\Local\Temp\install_reader11_en_chra_awa_aih.exe
2014-02-25 18:48 - 2014-02-25 18:48 - 001069920 _____ (Solid State Networks) C:\Users\Teschke\AppData\Local\Temp\install_reader11_en_chra_awa_aih_1.exe
2013-05-21 21:24 - 2013-05-21 21:24 - 002137632 _____ (Solid State Networks) C:\Users\Teschke\AppData\Local\Temp\install_reader11_en_gtbp_chra_aih.exe
2013-06-26 11:56 - 2013-06-26 11:56 - 001037120 _____ (Solid State Networks) C:\Users\Teschke\AppData\Local\Temp\install_reader11_en_mssa_aaa_aih.exe
2016-09-23 19:22 - 2016-09-23 19:26 - 083528440 _____ () C:\Users\Teschke\AppData\Local\Temp\mpa03944.exe
2013-07-12 21:08 - 2013-07-12 21:08 - 004120976 _____ (Black Tree Gaming                                           ) C:\Users\Teschke\AppData\Local\Temp\Nexus%20Mod%20Manager-0.45.4.exe
2013-08-03 23:47 - 2013-08-03 23:47 - 000008192 _____ () C:\Users\Teschke\AppData\Local\Temp\odn6esre.dll
2014-08-09 20:04 - 2014-08-09 20:04 - 000518208 _____ (NCH Software) C:\Users\Teschke\AppData\Local\Temp\pixsetup.exe
2014-04-21 16:29 - 2014-04-21 16:29 - 000339544 _____ (NCH Software) C:\Users\Teschke\AppData\Local\Temp\ppsetup.exe
2014-08-20 20:23 - 2014-08-20 20:23 - 000589888 _____ (NCH Software) C:\Users\Teschke\AppData\Local\Temp\prismsetup.exe
2013-07-21 00:00 - 2013-07-21 00:00 - 000003584 _____ () C:\Users\Teschke\AppData\Local\Temp\q64mjujk.dll
2016-09-23 19:26 - 2016-09-23 19:26 - 083528440 _____ () C:\Users\Teschke\AppData\Local\Temp\Setup-Wacom.exe
2015-01-31 10:16 - 2016-04-08 14:58 - 046965376 _____ (Skype Technologies S.A.) C:\Users\Teschke\AppData\Local\Temp\SkypeSetup.exe
2014-04-21 16:27 - 2014-04-21 16:27 - 000418352 _____ (NCH Software) C:\Users\Teschke\AppData\Local\Temp\tnsetup.exe
2014-02-15 20:00 - 2014-02-15 20:00 - 000367192 _____ (NCH Software) C:\Users\Teschke\AppData\Local\Temp\twelvekeyssetup.exe
2015-10-02 15:18 - 2016-01-10 18:25 - 013110615 _____ (Acresso Software Inc.) C:\Users\Teschke\AppData\Local\Temp\ubi444B.tmp.exe
2016-01-13 16:46 - 2016-01-14 16:47 - 004004004 _____ (Acresso Software Inc.) C:\Users\Teschke\AppData\Local\Temp\ubiEDD6.tmp.exe
2014-02-15 20:00 - 2014-02-15 20:00 - 000752176 _____ (NCH Software) C:\Users\Teschke\AppData\Local\Temp\vxlsetup.exe
2014-02-15 19:59 - 2014-02-15 19:59 - 001003568 _____ (NCH Software) C:\Users\Teschke\AppData\Local\Temp\wpsetup.exe
 
==================== Bamital & volsnap ======================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
 
LastRegBack: 2018-01-18 01:44
 
==================== End of FRST.txt ============================

and file #2,

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 27.01.2018
Ran by Teschke (27-01-2018 15:11:26)
Running from C:\Users\Teschke\Desktop
Windows 7 Home Premium Service Pack 1 (X64) (2013-04-18 01:06:13)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Admin (S-1-5-21-3289118944-4034126387-1954186238-1003 - Administrator - Enabled) => C:\Users\Admin
Administrator (S-1-5-21-3289118944-4034126387-1954186238-500 - Administrator - Disabled)
Guest (S-1-5-21-3289118944-4034126387-1954186238-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3289118944-4034126387-1954186238-1002 - Limited - Enabled)
Teschke (S-1-5-21-3289118944-4034126387-1954186238-1000 - Administrator - Enabled) => C:\Users\Teschke
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Malwarebytes (Enabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B}
AS: Malwarebytes (Enabled - Up to date) {98619B37-4FC4-67F2-1C99-EEF6D47DBD96}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov)
Ace of Spades (HKLM-x32\...\{6037B8AD-7D5B-4D50-9BCA-A586C44EEF34}) (Version: 0.75.015 - Ben Aksoy)
ACP Application (HKLM\...\{DD93B141-69A7-A8FD-6963-266D02E9C07B}) (Version: 2.15.20.0015 - Advanced Micro Devices, Inc.) Hidden
Adobe Flash Player 28 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 28.0.0.137 - Adobe Systems Incorporated)
Adobe Flash Player 28 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 28.0.0.137 - Adobe Systems Incorporated)
Adobe Flash Player 28 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 28.0.0.137 - Adobe Systems Incorporated)
Adobe Photoshop Lightroom 5.2 64-bit (HKLM\...\{54E6C675-3AD4-42E4-957F-31666ABF1603}) (Version: 5.2.1 - Adobe)
Adobe Reader XI (11.0.03) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.03 - Adobe Systems Incorporated)
AMD Catalyst Install Manager (HKLM\...\{8F62BC70-DBB4-802D-1E1E-13630D9BA4D2}) (Version: 8.0.916.0 - Advanced Micro Devices, Inc.)
ANT Drivers Installer x64 (HKLM\...\{431CE782-4C51-4996-B36F-5D98D5527538}) (Version: 2.3.4 - Garmin Ltd or its subsidiaries) Hidden
Apple Application Support (32-bit) (HKLM-x32\...\{FE5C2FAA-118D-4509-B51D-3F71CC9E1B3E}) (Version: 4.3 - Apple Inc.)
Apple Application Support (64-bit) (HKLM\...\{2937FD88-C9D6-4B82-B539-37CD0A572F42}) (Version: 4.3 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{2E4AF2A6-50EA-4260-9BA4-5E582D11879A}) (Version: 9.3.0.15 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{56EC47AA-5813-4FF6-8E75-544026FBEA83}) (Version: 2.2.0.150 - Apple Inc.)
Assassin's Creed III 1.01 (HKLM-x32\...\{9D15E813-0C26-41E7-ABC5-3EB06FF1B3CF}) (Version: 1.01 - Ubisoft)
Autodesk Configurator 360 addin (HKLM-x32\...\{563941AA-C055-4FAA-8B04-A4E024A61F7E}) (Version: 20.0.10300 - Autodesk)
Autodesk Design Review 2013 (HKLM-x32\...\{153DB567-6FF3-49AD-AC4F-86F8A3CCFDFB}) (Version: 13.0.0.82 - Autodesk, Inc.) Hidden
Autodesk Design Review 2013 (HKLM-x32\...\Autodesk Design Review 2013) (Version: 13.0.0.82 - Autodesk, Inc.)
Battle.net (HKLM-x32\...\Battle.net) (Version:  - Blizzard Entertainment)
Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
BookSmart® 3.4.9 3.4.9 (HKLM-x32\...\BookSmart® 3.4.9 3.4.9) (Version:  - Blurb, Inc)
Boris Graffiti 6 for Corel VideoStudio Pro (HKLM-x32\...\{F4310AE4-A789-4602-AA48-CFA03D73A9F4}) (Version: 6.1.0003 - Boris FX, Inc.)
Boris Graffiti 7 for Corel VideoStudio Pro X9 64-Bit (HKLM\...\{9C246583-D390-4910-B740-431F89FACC2E}) (Version: 7.0.0001 - Boris FX, Inc.)
Brother MFL-Pro Suite DCP-7065DN (HKLM-x32\...\{3ACCCFB3-7B17-4E9F-ACB0-46868FCD4487}) (Version: 1.1.3.0 - Brother Industries, Ltd.)
Call of Duty - United Offensive (HKLM-x32\...\{A662E280-64A8-4CF5-8407-13D0808602B3}) (Version: 1.00.0000 - Activision) Hidden
Call of Duty - United Offensive (HKLM-x32\...\InstallShield_{A662E280-64A8-4CF5-8407-13D0808602B3}) (Version: 1.00.0000 - Activision)
Call of Duty (HKLM-x32\...\Call of Duty) (Version:  - )
Call of Duty® 4 - Modern Warfare™ (HKLM-x32\...\{E48469CC-635E-4FD5-A122-1497C286D217}) (Version: 1.6 - Activision) Hidden
Call of Duty® 4 - Modern Warfare™ (HKLM-x32\...\InstallShield_{E48469CC-635E-4FD5-A122-1497C286D217}) (Version: 1.6 - Activision)
CameraHelperMsi (HKLM-x32\...\{15634701-BACE-4449-8B25-1567DA8C9FD3}) (Version: 13.51.815.0 - Logitech) Hidden
Chrome Remote Desktop Host (HKLM-x32\...\{D61C8E6E-A4F3-4CD8-8568-51CEB5660C89}) (Version: 63.0.3239.32 - Google Inc.)
Cisco WebEx Meetings (HKU\S-1-5-21-3289118944-4034126387-1954186238-1000\...\ActiveTouchMeetingClient) (Version:  - Cisco WebEx LLC)
Contents (HKLM-x32\...\{EE0B1766-153A-4251-A192-F8FD3D941711}) (Version: 16.1.0.45 - Corel Corporation) Hidden
Contents64 (HKLM\...\{C2D307EA-96F8-4F6E-880E-E244779D8477}) (Version: 19.5.0.35 - Corel Corporation) Hidden
Corel KPT Collection (HKLM-x32\...\{031338C0-4C21-4DAC-875B-26ACD7ADDF23}) (Version: 1.00.0000 - Corel Corporation) Hidden
Corel KPT Collection for PSPX4 (HKLM-x32\...\_{031338C0-4C21-4DAC-875B-26ACD7ADDF23}) (Version:  - Corel Corporation)
Corel Painter 13 - IPM (HKLM\...\{0B598D32-B873-4794-8F30-90C53CD562D7}) (Version: 13.1 - Corel Corporation) Hidden
Corel Painter 13 - IPM Content (HKLM\...\{9983025B-AA60-4CF3-9E6C-C48DB9CD2310}) (Version: 13.1 - Corel Corporation) Hidden
Corel Painter X3 (HKLM\...\_{EF449371-6B69-49C8-B789-76A0B0E3446B}) (Version: 13.0.1.920 - Corel Corporation)
Corel PaintShop Pro X4 (HKLM-x32\...\_{00580795-581C-4587-B9F2-37320D7AB37F}) (Version: 14.2.0.1 - Corel Corporation)
Corel PaintShop Pro X4 (HKLM-x32\...\{00AE1A2D-7BC2-4359-A0EC-E19F36E391BB}) (Version: 14.2.0.1 - Corel Corporation) Hidden
Corel PaintShop Pro X4 Ultimate Bonus Pack (HKLM-x32\...\_{45E8DDB3-8FEB-40DB-A6D7-3535392AA559}) (Version:  - Corel Corporation)
Corel PaintShop Pro X4 Ultimate Bonus Pack (HKLM-x32\...\{45E8DDB3-8FEB-40DB-A6D7-3535392AA559}) (Version: 1.00.0000 - Corel Corporation) Hidden
Corel VideoStudio Pro X6 (HKLM-x32\...\_{6688A246-F6E8-48AD-9806-8D5832E9F15D}) (Version: 16.1.0.45 - Corel Corporation)
Corel VideoStudio Ultimate X9 (HKLM-x32\...\_{EE80DAA0-0071-475C-A222-F1782888FC55}) (Version: 19.5.0.35 - Corel Corporation)
Crysis®3 (HKLM-x32\...\{4198AE83-A3C6-4C41-85C8-EC63E990696E}) (Version: 1.0.0.0 - Electronic Arts)
D3DX10 (HKLM-x32\...\{E09C4DB7-630C-4F06-A631-8EA7239923AF}) (Version: 15.4.2368.0902 - Microsoft) Hidden
DAIDE QuickStart (HKLM-x32\...\{FDE86B27-8B13-40CB-B0DA-A1CAB15C2929}) (Version: 6.0.1 - Jason van Hal)
Dell System Detect (HKU\S-1-5-21-3289118944-4034126387-1954186238-1000\...\73f463568823ebbe) (Version: 6.6.0.2 - Dell)
digiCamControl (HKLM-x32\...\{19D12628-7654-4354-A305-9AB0A3502683}) (Version: 1.2.99.12 - Duka Istvan)
Eco Materials Adviser for Autodesk Inventor 2016 (64-bit) (HKLM\...\{1A56BE00-916E-432D-A576-EB00D2FF8450}) (Version: 5.6.4.44 - Granta Design Limited)
Elevated Installer (HKLM-x32\...\{7E73C9A3-24D9-4D7F-B4C7-7E4AFE0ADCCB}) (Version: 4.0.15.0 - Garmin Ltd or its subsidiaries) Hidden
Epic Games Launcher (HKLM-x32\...\{2B6AC31A-9883-465C-AFC6-1EC5AA48F5BD}) (Version: 1.1.138.0 - Epic Games, Inc.)
Epic Games Launcher Prerequisites (x64) (HKLM\...\{66C5838F-B854-4A55-89E6-A6138747A4DF}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
erLT (HKLM-x32\...\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}) (Version: 1.20.138.34 - Logitech, Inc.) Hidden
Far Cry (HKLM-x32\...\{D6DBDC2A-E72C-4284-B6AD-6B3B61B4DABC}) (Version: 1.00.0000 - Ubisoft) Hidden
Far Cry (HKLM-x32\...\InstallShield_{D6DBDC2A-E72C-4284-B6AD-6B3B61B4DABC}) (Version: 1.00.0000 - Ubisoft)
Far Cry 2 (HKLM-x32\...\{F2835483-37F2-4123-B4FE-0E77D58447F2}) (Version: 1.03.00 - Ubisoft)
FARO LS 1.1.501.0 (64bit) (HKLM-x32\...\{8A470330-70B2-49AD-86AF-79885EF9898A}) (Version: 5.1.0.30630 - FARO Scanner Production)
FARO LS 1.1.503.3 (64bit) (HKLM-x32\...\{1C05E654-FB81-4274-BF32-292E3707701D}) (Version: 5.3.3.38662 - FARO Scanner Production)
Garmin Communicator Plugin (HKLM-x32\...\{71DBFBF2-F7EB-4268-8485-9471D83C4E66}) (Version: 4.2.0 - Garmin Ltd or its subsidiaries)
Garmin Communicator Plugin x64 (HKLM\...\{70A381F1-C161-4D61-A20C-BE12FC6777DF}) (Version: 4.2.0 - Garmin Ltd or its subsidiaries)
Garmin Express (HKLM-x32\...\{50755d67-ae60-4e47-b3d6-ce44d01b5a95}) (Version: 4.0.15.0 - Garmin Ltd or its subsidiaries)
Garmin Express (HKLM-x32\...\{9FB8EC5B-03EE-463E-8F4F-84B525B986B7}) (Version: 4.0.15.0 - Garmin Ltd or its subsidiaries) Hidden
Garmin Express Tray (HKLM-x32\...\{1D91CBB5-4CB1-4757-B0FD-2122AF8AAB9E}) (Version: 4.0.15.0 - Garmin Ltd or its subsidiaries) Hidden
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 64.0.3282.119 - Google Inc.)
Google Earth Plug-in (HKLM-x32\...\{4AB54F11-2F8C-11E3-B09F-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
Google Earth Pro (HKLM-x32\...\{ECF2E224-42F5-4E50-B58E-94CA70E85697}) (Version: 7.3.0.3832 - Google)
Google Toolbar for Internet Explorer (HKLM-x32\...\{18455581-E099-4BA8-BC6B-F34B2F06600C}) (Version: 1.0.0 - Google Inc.) Hidden
Google Toolbar for Internet Explorer (HKLM-x32\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.8231.2252 - Google Inc.)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.7 - Google Inc.) Hidden
Google Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.25.11 - Google Inc.) Hidden
Haali Media Splitter (HKLM-x32\...\HaaliMkx) (Version:  - )
ICA (HKLM-x32\...\{00580795-581C-4587-B9F2-37320D7AB37F}) (Version: 14.2.0.1 - Corel Corporation) Hidden
ICA (HKLM-x32\...\{6688A246-F6E8-48AD-9806-8D5832E9F15D}) (Version: 16.1.0.45 - Corel Corporation) Hidden
ICA (HKLM-x32\...\{EE80DAA0-0071-475C-A222-F1782888FC55}) (Version: 19.5.0.35 - Corel Corporation) Hidden
IconHandler 64 bit (HKLM\...\{4E82E2E9-668B-4F8A-814A-78E163FCDBCD}) (Version: 2.0 - Corel Corporation) Hidden
Intel® Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1118 - Intel Corporation)
Intel® Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 10.0.0.1046 - Intel Corporation)
IPM_PSP_COM (HKLM-x32\...\{00BEE329-BAAB-49FF-9B66-55E4B12B9ADD}) (Version: 14.2.0.1 - Corel Corporation) Hidden
IPM_VS_Pro (HKLM-x32\...\{CCC10E8E-7FD1-4D55-87C2-D0A5ABC0A62B}) (Version: 16.0 - Corel Corporation) Hidden
IPM_VS_Pro64 (HKLM\...\{1BD7EE90-7C52-4142-B4DD-55C4F28F9EE7}) (Version: 19.0 - Corel Corporation) Hidden
iTunes (HKLM\...\{A31C5565-90D9-4615-AE13-94D86C3836C7}) (Version: 12.3.3.17 - Apple Inc.)
Java 8 Update 25 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218025F0}) (Version: 8.0.250 - Oracle Corporation)
LAME v3.99.3 (for Windows) (HKLM-x32\...\LAME_is1) (Version:  - )
Launcher Prerequisites (x64) (HKLM-x32\...\{c6c5a357-c7ca-4a5f-9789-3bb1af579253}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
Lightworks (HKLM-x32\...\{E94DD4E4-7746-472c-AA7B-1242FED0CFC8}) (Version: 11.1.0.0 - Lightworks)
Logitech Webcam Software (HKLM-x32\...\{D40EB009-0499-459c-A8AF-C9C110766215}) (Version: 2.51 - Logitech Inc.)
Malwarebytes version 3.3.1.2183 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.3.1.2183 - Malwarebytes)
McAfee AntiVirus Plus (HKLM-x32\...\MSC) (Version: 16.0.2 - McAfee, Inc.)
McAfee Virtual Technician (HKLM-x32\...\McAfee Virtual Technician) (Version: 8.1.0.174 - McAfee, Inc.)
McAfee WebAdvisor (HKLM-x32\...\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}) (Version: 4.0.163 - McAfee, Inc.)
Medal of Honor Allied Assault (HKLM-x32\...\{0DEA94ED-915A-4834-A87E-388D012C8E02}) (Version:  - )
Medal of Honor Allied Assault™ Spearhead (HKLM-x32\...\{7914BE1E-F186-4790-B8F4-9F63C52A41C1}) (Version:  - )
Melody Assistant (HKLM-x32\...\Melody Assistant) (Version: 7.6.3i - Myriad SARL)
Microsoft .NET Framework 4.7 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.7.02053 - Microsoft Corporation)
Microsoft Access database engine 2010 (English) (HKLM\...\{90140000-00D1-0409-1000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Camera Codec Pack (HKLM\...\{D553E8CC-5C56-4B06-AC1A-A443DFF31092}) (Version: 6.3.9723.0 - Microsoft Corporation)
Microsoft Office Professional Plus 2010 (HKLM-x32\...\Office14.PROPLUSR) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50907.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729 (HKLM\...\{2DFD8316-9EF1-3210-908C-4CB61961C1AC}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{527BBE2F-1FED-3D8B-91CB-4DB0F838E69E}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\...\{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft WSE 3.0 Runtime (HKLM-x32\...\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}) (Version: 3.0.5305.0 - Microsoft Corp.)
Mixxx 2.0.0 (HKU\S-1-5-21-3289118944-4034126387-1954186238-1000\...\Mixxx (2.0.0)) (Version: 2.0.0 - The Mixxx Development Team)
Movie Maker (HKLM-x32\...\{38F03569-A636-4CF3-BDDE-032C8C251304}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Movie Maker (HKLM-x32\...\{DD67BE4B-7E62-4215-AFA3-F123A800A389}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Mozilla Firefox 43.0.1 (x86 en-US) (HKU\S-1-5-21-3289118944-4034126387-1954186238-1000\...\Mozilla Firefox 43.0.1 (x86 en-US)) (Version: 43.0.1 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation)
MyDVD Content Pack 1 (HKLM-x32\...\{ADCF7AE3-8E36-4B80-9460-66B74B56927F}) (Version: 1.00.0000 - Corel Corporation)
Myst Online: Uru Live (remove only) (HKLM-x32\...\MOUL) (Version:  - )
NETGEAR Genie (HKLM-x32\...\NETGEAR Genie) (Version: 2.4.12.00 - NETGEAR Inc.)
NewBlue Film Effects for Windows (HKLM-x32\...\NewBlue Film Effects for Windows) (Version: 3.0 - NewBlue)
Nexus Mod Manager (HKLM\...\6af12c54-643b-4752-87d0-8335503010de_is1) (Version: 0.45.2 - Black Tree Gaming)
Nik Collection (HKLM-x32\...\Nik Collection) (Version: 1.2.11 - Google)
Nuance PaperPort 12 (HKLM-x32\...\{6C0A559F-8583-4B5A-8B50-20BEE15D8E64}) (Version: 12.1.0000 - Nuance Communications, Inc.)
Nuance PDF Viewer Plus (HKLM-x32\...\{28656860-4728-433C-8AD4-D1A930437BC8}) (Version: 5.30.3290 - Nuance Communications, Inc)
NVIDIA PhysX (HKLM-x32\...\{3F5C371F-8EA2-4F25-9D3D-D0B4526E3AEA}) (Version: 9.10.0513 - NVIDIA Corporation)
Origin (HKLM-x32\...\Origin) (Version: 9.1.10.2728 - Electronic Arts, Inc.)
Painter 13 - Contentx64 (HKLM\...\{A16926CB-C4BF-4FC9-8F99-200236731FCA}) (Version: 13.1 - Corel Corporation) Hidden
Painter 13 - Core (HKLM\...\{B1EA198B-FF19-46C9-84DE-E2F3D11619ED}) (Version: 13.1 - Corel Corporation) Hidden
Painter 13 - Corex64 (HKLM\...\{DA929FB1-A118-4F6E-9AD6-729633E84805}) (Version: 13.0 - Corel Corporation) Hidden
Painter 13 - EN (HKLM\...\{61F6F8FC-C448-418E-BF14-8B272DFDD51B}) (Version: 13.1 - Corel Corporation) Hidden
Painter 13 - Setup Files (HKLM\...\{EF449371-6B69-49C8-B789-76A0B0E3446B}) (Version: 13.1 - Corel Corporation) Hidden
Pando Media Booster (HKLM-x32\...\{980A182F-E0A2-4A40-94C1-AE0C1235902E}) (Version: 2.6.0.7 - Pando Networks Inc.)
PaperPort Image Printer 64-bit (HKLM\...\{715CAACC-579B-4831-A5F4-A83A8DE3EFE2}) (Version: 1.00.0001 - Nuance Communications, Inc.)
Paradise (HKLM-x32\...\Paradise_is1) (Version:  - Ubisoft)
Pinnacle Instant DVD Recorder (HKLM-x32\...\{C1212AE3-DBB9-4365-8473-F8ABC7B06BBB}) (Version: 2.6.0.118 - Pinnacle Systems)
Pinnacle Studio 12 (HKLM-x32\...\{D041EB9E-890A-4098-8F94-51DA194AC72A}) (Version: 12.1.3.6605 - Pinnacle Systems)
Pinnacle Video Driver (HKLM\...\{6DE721A5-5E89-4D74-994C-652BB3C0672E}) (Version: 12.1.0.029 - Pinnacle Systems)
PitchPerfect Musical Instrument Tuner (HKU\S-1-5-21-3289118944-4034126387-1954186238-1000\...\PitchPerfect) (Version: 2.12 - NCH Software)
Pixillion Image Converter (HKU\S-1-5-21-3289118944-4034126387-1954186238-1000\...\Pixillion) (Version: 2.75 - NCH Software)
POW (HKLM-x32\...\{CD277B3E-8043-496E-B83B-D53186A072AB}) (Version: 1.00.0000 - Wide Games) Hidden
POW (HKLM-x32\...\InstallShield_{CD277B3E-8043-496E-B83B-D53186A072AB}) (Version: 1.00.0000 - Wide Games)
Prism Video File Converter (HKU\S-1-5-21-3289118944-4034126387-1954186238-1000\...\Prism) (Version: 2.18 - NCH Software)
proDAD Adorage 3.0 (64bit) (HKLM\...\proDAD-Adorage-3.0) (Version: 3.0.114.1 - proDAD GmbH) Hidden
proDAD Mercalli 2.0 (64bit) (HKLM\...\proDAD-Mercalli-2.0) (Version: 2.0.123 - proDAD GmbH) Hidden
proDAD Mercalli 2.0 (HKLM-x32\...\proDAD-Mercalli-2.0) (Version: 2.0.106 - proDAD GmbH) Hidden
proDAD Route 4.0 (64bit) (HKLM\...\proDAD-HeroglyphRoute-4.0) (Version: 4.0.241.1 - proDAD GmbH) Hidden
proDAD Route 4.0 (HKLM-x32\...\proDAD-HeroglyphRoute-4.0) (Version: 4.0.209.2 - proDAD GmbH) Hidden
proDAD Script 4.0 (64bit) (HKLM\...\proDAD-HeroglyphScript-4.0) (Version: 4.0.241.1 - proDAD GmbH) Hidden
proDAD Script 4.0 (HKLM-x32\...\proDAD-HeroglyphScript-4.0) (Version: 4.0.209.2 - proDAD GmbH) Hidden
proDAD Vitascene 2.0 (64bit) (HKLM\...\proDAD-Vitascene-2.0) (Version: 2.0.241 - proDAD GmbH) Hidden
proDAD Vitascene 2.0 (HKLM-x32\...\proDAD-Vitascene-2.0) (Version: 2.0.203 - proDAD GmbH) Hidden
PS3 Media Server (HKLM-x32\...\PS3 Media Server) (Version: 1.90.1 - PS3 Media Server)
PSPPContent (HKLM-x32\...\{006CAAEF-CA96-4181-AC22-FE56D61432E4}) (Version: 14.2.0.1 - Corel Corporation) Hidden
PSPPHelp (HKLM-x32\...\{00D74A7A-F7AD-4D00-ABD2-0973836292C7}) (Version: 14.2.0.1 - Corel Corporation) Hidden
PSPPro64 (HKLM\...\{0015DE8E-8D9F-403E-8E5A-4098410E6125}) (Version: 14.2.0.1 - Corel Corporation) Hidden
PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.986 - Even Balance, Inc.)
QuickTime 7 (HKLM-x32\...\{FF59BD75-466A-4D5A-AD23-AAD87C5FD44C}) (Version: 7.79.80.95 - Apple Inc.)
Raptr (HKLM-x32\...\Raptr) (Version: 5.2.3-r114633-release - Raptr, Inc)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6141 - Realtek Semiconductor Corp.)
Scansoft PDF Professional (HKLM-x32\...\{068724F8-D8BE-4B43-8DDD-B9FE9E49FD76}) (Version:  - ) Hidden
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version:  - Microsoft)
Setup (HKLM-x32\...\{00D13418-7DDF-4D3D-A237-E297B103BB6B}) (Version: 14.2.0.1 - Corel Corporation) Hidden
Setup (HKLM-x32\...\{6C6EEA9F-3998-4E0D-B91F-43CB218C715C}) (Version: 16.1.0.45 - Corel Corporation) Hidden
Setup (HKLM-x32\...\{F8B95E3C-40A0-49CE-B5F9-3861F238B9FF}) (Version: 19.5.0.35 - Corel Corporation) Hidden
Share (HKLM-x32\...\{AD7DA145-3118-4D69-BE89-D3ED1510BD15}) (Version: 16.1.0.45 - Corel Corporation) Hidden
Share64 (HKLM\...\{3008095C-B516-4A5E-8B99-F0E113C21C72}) (Version: 16.1.0.45 - Corel Corporation) Hidden
Share64 (HKLM\...\{A61EEC3A-E37C-49A5-BE61-7AEE04F1A15D}) (Version: 19.5.0.35 - Corel Corporation) Hidden
Shared C Run-time for x64 (HKLM\...\{EF79C448-6946-4D71-8134-03407888C054}) (Version: 10.0.0 - McAfee)
SketchUp 2013 (HKLM-x32\...\{B75BC01B-4586-43F8-9349-D250DB98F26F}) (Version: 13.0.4812 - Trimble Navigation Limited)
Skype™ 7.0 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.0.102 - Skype Technologies S.A.)
SmartSound Common Data (HKLM-x32\...\{B8A2869E-30CA-40C5-9CF8-BD7354E57EF8}) (Version: 1.1.0 - SmartSound Software Inc.) Hidden
SmartSound Common Data (HKLM-x32\...\InstallShield_{B8A2869E-30CA-40C5-9CF8-BD7354E57EF8}) (Version: 1.1.0 - SmartSound Software Inc.)
SmartSound Quicktracks 5 (HKLM-x32\...\{2F8BA3FD-1FA9-4279-B696-712ABB12F09F}) (Version: 5.1.6 - SmartSound Software Inc.) Hidden
SmartSound Quicktracks 5 (HKLM-x32\...\InstallShield_{2F8BA3FD-1FA9-4279-B696-712ABB12F09F}) (Version: 5.1.6 - SmartSound Software Inc.)
Spotify (HKU\S-1-5-21-3289118944-4034126387-1954186238-1000\...\Spotify) (Version: 1.0.72.117.g6bd7cc73 - Spotify AB)
StarCraft II (HKLM-x32\...\StarCraft II) (Version:  - Blizzard Entertainment)
Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation)
theHunter Launcher (HKLM-x32\...\FBDFBE7F-2DB8-47E2-B88E-32F4A2A74AA8_is1) (Version: 620 - Expansive Worlds)
Unity Web Player (HKU\S-1-5-21-3289118944-4034126387-1954186238-1000\...\UnityWebPlayer) (Version:  - Unity Technologies ApS)
Uplay (HKLM-x32\...\Uplay) (Version: 2.0 - Ubisoft)
VideoStudio MyDVD (HKLM-x32\...\{7521A578-BDF3-412C-8959-57498EBBEDD9}) (Version: 1.0.129 - Corel Corporation) Hidden
VideoStudio MyDVD (HKLM-x32\...\{91345797-EF07-41D2-85F4-BFF200B6A0A3}) (Version: 1.0 - Corel)
Visual C++ 2008 - x64 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{6DA2B636-698A-3294-BF4A-B5E11B238CDD}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation)
Visual C++ 2008 - x64 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{8CCEA24C-51AE-3B71-9092-7D0C44DDA2DF}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation)
Visual C++ 2008 - x64 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{C3A57BB3-9AA6-3F6F-9395-6C062BDD5FC4}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation)
Visual C++ 2008 - x64 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{F6F09DD8-F39B-3A16-ADB9-C9E6B56903F9}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation)
Visual C++ 2008 - x86 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{04B34E21-5BEE-3D2B-8D3D-E3E80D253F64}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation)
Visual C++ 2008 - x86 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{14866AAD-1F23-39AC-A62B-7091ED1ADE64}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation)
Visual C++ 2008 - x86 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{4B90093A-5D9C-3956-8ABB-95848BE6EFAD}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation)
Visual C++ 2008 - x86 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{B42E259C-E4D4-37F1-A1B2-EB9C4FC5A04D}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation)
VLC media player 2.0.8 (HKLM-x32\...\VLC media player) (Version: 2.0.8 - VideoLAN)
VSClassic (HKLM-x32\...\{D0096E50-D99E-4178-A988-E5192B6F6B91}) (Version: 16.1.0.45 - Corel Corporation) Hidden
VSClassic64 (HKLM\...\{99B95309-4793-43D9-8F1C-EC086FC74CB5}) (Version: 19.5.0.35 - Corel Corporation) Hidden
VSHelp (HKLM-x32\...\{D9DD0D4F-6E5A-484D-AD8C-FD3BAF5D4450}) (Version: 16.1.0.45 - Corel Corporation) Hidden
VSPro (HKLM-x32\...\{D88D7ECD-F173-4A97-96F9-2B05C5DC90DC}) (Version: 16.1.0.45 - Corel Corporation) Hidden
VSUltimate64 (HKLM\...\{3F5D769B-346B-487A-851A-A1AF147D5B39}) (Version: 19.5.0.35 - Corel Corporation) Hidden
Wacom Tablet (HKLM\...\Wacom Tablet Driver) (Version: 6.3.17-3 - Wacom Technology Corp.)
WebTablet FB Plugin 32 bit (HKLM-x32\...\Wacom WebTabletPlugin for Internet Explorer and Netscape) (Version: 2.1.0.7 - Wacom Technology Corp.)
WebTablet FB Plugin 64 bit (HKLM\...\Wacom WebTabletPlugin for Internet Explorer and Netscape) (Version: 2.1.0.7 - Wacom Technology Corp.)
Windows Driver Package - Dynastream Innovations, Inc. ANT LibUSB Drivers (04/11/2012 1.2.40.201) (HKLM\...\F9D2A789F9CFF8CEC36B544F53877C80F1F73C46) (Version: 04/11/2012 1.2.40.201 - Dynastream Innovations, Inc.)
Windows Driver Package - Silicon Labs Software (DSI_SiUSBXp_3_1) USB  (02/06/2007 3.1) (HKLM\...\D1506E0025B5A3F9EB8270FE81C1EEDD9388B8A2) (Version: 02/06/2007 3.1 - Silicon Labs Software)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation)
Windows Media Encoder 9 Series (HKLM-x32\...\Windows Media Encoder 9) (Version:  - )
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
HKU\S-1-5-21-3289118944-4034126387-1954186238-1000\...\ChromeHTML: ->  <==== ATTENTION
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{00F064D8-FEC3-48ac-B07D-39C314D1727B}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\ServiceModule.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{0215A4C0-5431-4FD0-9B06-46589B5C4939}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{048ED0E0-12CF-4C0F-9FFA-947C2FBE8C8E}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{071339A1-1946-44B2-B63E-50459B15DB86}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{073CB204-6B29-46FC-AB98-451F1D068741}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\TestServer.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{08A60FF7-BB37-44F4-9759-0ADA6C7B9CC9}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{0B38CACA-3D3C-48EA-BEB5-7D95F4F6EE15}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{0C3393F8-94F5-4B79-8C01-49A2D0CC0FE9}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{0D555CE0-304A-47A6-858B-B145209A3982}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{12545889-6D32-4424-9967-1E1D7BD1F809}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{13009989-EFB5-48C9-8BD2-943E0392BD71}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\RxAppCtrl.Ocx => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{14679E3B-C952-4998-8E13-4B1286E6DD99}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{1481B385-759A-4B00-9257-E96357563999}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{162EF0A1-5A33-46F2-ACCF-CA388B084A09}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{18A21864-E37B-42b9-9612-2C1E8C450A29}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\ServiceModule.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{1D625598-C876-4C51-8EF5-F9D8F96F62AA}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{1D6DFD6A-9E16-435A-9327-6FFEC6BA372F}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{1E5724EA-3423-4BD3-ABD6-46E650D2DC66}\InprocServer32 -> AcETransmit.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{1E8A29BA-827D-4031-A4A3-AE7999B402F6}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{1EA072EE-57FD-495E-889C-8243C3BDBDBC}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{1FD7F53F-7ED5-439C-9A77-A3821CD09E98}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{20E47D5B-529A-45BD-8E77-BF1A3064A008}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{21DB88B0-BFBF-11D4-8DE6-0010B541CAA8}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\iDrop.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{2709544A-5B24-4F9F-A5DA-CEC7297D3A4E}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{2BCA857B-A18B-4AFA-B183-CC0E49C12058}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{2C74F89E-7421-46B4-BA54-F86F1BD9F237}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{2C7D1157-7D50-4A88-9777-5EBBA3189AB8}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{2F8377FC-50C1-44EF-AB7A-8FF1BB8EA277}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\ServiceModule.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{3497C2EC-5684-4B21-AF74-F6760E0221DC}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{38C8B14E-7879-4DA9-8C3F-8CAAC359293A}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{3FC94EB5-AEBD-4f3f-A2A4-B6CE57113C01}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\RxAppDocView.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{3FCEB42C-9B98-486A-BED7-FD7F3ADB7291}\InprocServer32 -> AcETransmit.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{40770568-0D5E-49D4-BE47-BC47A4F0B0A4}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{44A52280-AE56-490D-890C-89FB7279ED6B}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{45122C53-8483-4b62-B15A-EAA9FE5FC3D5}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\ServiceModule.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{46C56738-39C6-4240-8B9B-008CCD769A84}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{47179DDE-10AC-4737-97C9-8CE5379343EA}\InprocServer32 -> AcETransmit.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{475C7B4A-6964-4F9E-9708-05A16EAC31D0}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{48270F9E-CCF6-4C79-B6FF-267C960E6425}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{48FEFCD7-5D7C-4E4A-9F11-60E69A31D4B1}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{49998808-648A-4A9C-A7A5-B1672775D9AB}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{4A756F5F-CBA4-428B-B17F-AF80C0C8502D}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{4B40437B-8972-4444-BBE3-1588FF55F203}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{4BD03680-3C0F-4501-AFF7-3D008586917F}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{4C80573A-9150-11d2-B772-0060B0F159EF}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\RxAppDocView.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{4D29B490-49B2-11D0-93C3-7E0706000000}\localserver32 -> "C:\Program Files\Autodesk\Inventor 2016\Bin\Inventor.exe" => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{4E6F2E83-E7F0-4333-9772-875EB733C820}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\RxTest.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{5544903C-2CCC-487C-91BB-F310B72A8E9B}\InprocServer32 -> AcETransmit.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{59A224A2-BEF8-4C89-96E0-83A5411ABB6C}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{622F6193-E4DD-46E6-BC66-2ED88E9FD28D}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{62FBB030-24C7-11D3-B78D-0060B0F159EF}\localserver32 -> "C:\Program Files\Autodesk\Inventor 2016\Bin\Inventor.exe" => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{644190AE-BD8F-493F-B63D-C79404AC5E07}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\ServiceModule.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{6451051B-AD22-4C6A-ACCE-013A0E1DDBC3}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{64B99FDB-1D85-447F-98C7-569DBDA723DB}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{6BCE6F6E-C050-4F39-BD98-E2743949F724}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{6F56D7C9-18DD-4C15-9FA8-C54E3610EC40}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{6FDE7A70-351B-11d6-988B-0010B57A8BB7}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\DtBridge.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{6FDE7A71-351B-11d6-988B-0010B57A8BB7}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\DtBridge.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{6FDE7A72-351B-11d6-988B-0010B57A8BB7}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\DtBridge.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{6FDE7A73-351B-11d6-988B-0010B57A8BB7}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\DtBridge.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{6FDE7A74-351B-11d6-988B-0010B57A8BB7}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\DtBridge.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{6FDE7A77-351B-11d6-988B-0010B57A8BB7}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\DtCp.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{70DBCAE8-8C2B-450C-9E1D-43E4686C6512}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{713C0E8A-5AE8-4695-B442-5ED6C4FE5C42}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{7293E009-3015-4AD3-96EC-D42C36B5FCE3}\InprocServer32 -> AcETransmit.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{72EC5CC5-88F3-45B1-A865-0A327DF58CC8}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\ServiceModule.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{72EFC580-D085-4B81-8C55-26A79E445338}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{750AEC19-2E4C-4ED9-9B9F-F9CAFCD060F3}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{794199C5-827C-41C8-8CB2-3A1EA056AF5E}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{798391FE-4AF2-4851-9DDA-1F0D70C02A9E}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{7BA16B3F-1AB3-4BD7-B959-52C4B8504EE9}\InprocServer32 -> AcInetUI.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{7C239DAB-BC87-45F3-B7B1-FCC1541A235B}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{81D07C3D-0350-11D3-B7C2-0060B0EC020B}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\RxAppCtrl.Ocx => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{834CE679-2E47-49DE-9E41-FEC87E9192EB}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{8421A29C-54B8-11D1-9837-0060B03C43C8}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\SolidObject.Dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{846217D0-8954-11D2-8DCD-0060B0C32531}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\UCxTextBtn.Ocx => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{846217D1-8954-11D2-8DCD-0060B0C32531}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\UCxTextBtn.Ocx => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{849AFB5B-D6C9-4924-A712-F7118FF9611F}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{85452F88-5071-492E-B850-2E3C586DCBD8}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{87F5CF8F-A06D-498F-A05F-E520E6B570DB}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{89F0FC31-3B1D-494B-A75B-6BD4FA527B8A}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{8AA16DFC-DFC6-4B51-8FA2-A5D812BE33BF}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{8B0E6BD9-610C-11D1-9842-0060B03C43C8}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\SolidObject.Dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{8C23B656-4E6E-4B45-9920-9617168D39A3}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\TestServer.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{8ED07FEF-E1B0-4CC3-B2BA-D354828AB952}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{988F4102-E6E3-4282-ACAC-55270827F2A8}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{9906CDFC-DB2C-4126-9422-13139B148495}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{9A21C6C5-27FC-4442-8590-575E7AFD73BB}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{9ECF83FB-23C5-43B6-83DE-93CFBDD74D4A}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{A58F47CC-FF65-4152-B0B1-666C643A5BFC}\InprocServer32 -> AcETransmit.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{A6A3D586-44CF-44C2-A92C-620BB713B4F2}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{ABBE3F83-D585-4A50-9B69-198B0F566F2E}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{AC5CECFA-F03A-41D2-A89C-704C44935941}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{B1560245-190E-4BBD-81DF-9B642D0E5325}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{B2A579E0-A797-40B1-8AEE-A8F6404719F8}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{B47196BC-D4AB-41BB-A771-543D67CFC9F5}\InprocServer32 -> AcETransmit.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{B53CEF4B-1A13-49DE-BBC5-A7100FB2F38C}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{B5EE2B68-9A23-4BCD-BB77-FEA6DFB24DD6}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{B6B5DC40-96E3-11d2-B774-0060B0F159EF}\localserver32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\Inventor.exe /Automation => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{B80687F9-FA4C-4735-9DC4-E5715F2BC698}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{B8E7214B-25CA-4116-84CB-E86FB9625B36}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\ServiceModule.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{BAE5802A-CF21-4F9C-AE04-D98F4036AC31}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{BBF6A206-CB04-479D-96AE-349E1E83319A}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{BC71DEA1-D6FB-48B8-AB06-D151C81BBCDD}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{BE54741D-E02B-4572-93D6-105AF4EDE777}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\ServiceModule.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{BF224DC3-B602-4EEE-BFE9-9E4E0AED6837}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{BF4CC07E-E9BB-40D6-873F-855B211033B9}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{C061C82C-D041-4214-BB07-B608107CEFCB}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{C2D4ACCC-A3D1-4A0A-AD59-0DD8BA3D5EE1}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{C343ED84-A129-11d3-B799-0060B0F159EF}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\RxApprenticeServer.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{C8C18F89-794D-466B-8B97-95634D9890EF}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{C8EC7647-1E79-4F13-81D7-2EED803D0D22}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{C92F8F8C-8B2C-11d4-B872-0060B0EC020B}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\DtBridge.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{CC23CA32-9892-4FBA-A108-FE31CA0F35A6}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{CD865713-70D6-4E15-BB7B-9B99AD9DEB85}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{CFEE2BAF-14F9-4D23-853D-B6E2BCC14263}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\ServiceModule.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{D56F5AB3-9C4D-4F1A-A851-A671D9FE8C22}\InprocServer32 -> AcETransmit.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{D66873EA-AAE5-41CC-8DD2-8CE3228E9F89}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{D7A1987D-4A73-11D1-9A4B-080009DCE505}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\ColorButton.Ocx => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{D7A1987E-4A73-11D1-9A4B-080009DCE505}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\ColorButton.Ocx => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{D86B6C47-11F2-4D95-B635-EA575F0892FC}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{DA1F437C-9BD9-11d4-B87C-0060B0EC020B}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\DtBridge.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{DB207560-8449-4FAF-BDC2-61676EB012D4}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{DB5D476B-3FF4-4E9D-A606-1E2B473BE571}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\AcInetUI.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{DCA7356C-FF94-4b20-AE04-7AA6A8E14117}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\ServiceModule.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{DDA9A20F-5B56-49F5-9465-CE82FC199352}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\ServiceModule.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{DE6B563C-B074-4BF1-A8A0-B3FED8703E99}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\ServiceModule.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{DE74F5AD-DA2F-429F-BAF9-850A2808D585}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{DF6525C2-6358-4B07-813D-708120C5FE1A}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{E177A457-9EAA-43C3-A3CE-84874A28F6CA}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{E1C85E9F-60B2-4007-80C3-2C5E09474C3B}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\RxInventorUtilities.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{E29F6C45-6927-4508-8F3F-34105FD3FC5F}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{E4222C78-3670-4BB1-9AD4-7D8F3E581F2D}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{E5B0515D-48D2-4F04-906D-0192ED65A2DD}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\TestServer.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{E70DE962-842A-4488-9481-1D0FD72A020F}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{E9C07CEC-7B82-49E4-BBA2-7533B88E9D64}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{EA34A0C0-5CE7-4701-A6FA-117D25CD5EBB}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{EF01D98A-747B-4522-AD70-991B90855DBF}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{F13E75B9-6AF6-49CB-80B3-6D2FF6E09932}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\ServiceModule.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{F196F03F-651A-43AF-BE34-D11942F24445}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{F2D4F4E5-EEA1-46FF-A83B-A270C92DAE4B}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\DTInterop.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{F2DB0EE3-7137-4CB0-8349-483C4FF2143A}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{F40E2FF0-4D77-40B2-9A44-A3AEECCE8EFF}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{F5522F0C-962A-48AC-9992-E81B07628F1F}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{F61064CC-DBFB-47ee-9BC8-CA5A1CBDF0DA}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\InvResc.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{F78DCF7C-043D-45FC-9D21-676FC307BA3F}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{F868EAEC-1B73-4F5E-BA73-90EBA94E75BE}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{FA62F626-EBD5-4dc5-B970-D9E81E0E20E0}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\ServiceModule.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{FA97F7A7-FD19-4D55-ABF2-CFEFFF777426}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{FB469644-3F14-4403-ACCA-6B13486FF7BD}\localserver32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\InvTXTStack.exe /Automation => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{FD51ED8A-D518-4554-B236-B6E9D234FD03}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{FD703B01-4362-423E-9BDB-91BDCB16C1C9}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\DTInterop.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{FE054BB2-AF94-40AC-88AA-2F59F7018B1D}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{FE317223-8EDE-4684-B424-E48B9EA90220}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{FE718E8F-C3AA-4F30-9103-432450CF1DA1}\InprocServer32 -> axdb.dll => No File
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2010-11-18] (Igor Pavlov)
ContextMenuHandlers1-x32: [Autodesk.DWF.ContextMenu] -> {6C18531F-CA85-45F7-8278-FF33CF0A5964} => C:\Program Files (x86)\Common Files\Autodesk Shared\DWF Common\DWFShellExtension.dll [2012-01-06] (Autodesk, Inc.)
ContextMenuHandlers1-x32: [Corel PaintShop Pro X4] -> {CA34A346-C652-4F33-8CFF-FD6A91D9D64A} => c:\Program Files (x86)\Corel\Corel PaintShop Pro X4\PSPContextMenu64.dll [2012-05-11] (Corel Software, Inc.)
ContextMenuHandlers1-x32: [McCtxMenuFrmWrk] -> {CCA9EFD3-29ED-430A-BA6D-E6BBFF0A60C2} => c:\Program Files\McAfee\MSC\McCtxMenuFrmWrk.dll [2017-07-10] (McAfee, Inc.)
ContextMenuHandlers2: [Corel PaintShop Pro X4] -> {CA34A346-C652-4F33-8CFF-FD6A91D9D64A} => c:\Program Files (x86)\Corel\Corel PaintShop Pro X4\PSPContextMenu64.dll [2012-05-11] (Corel Software, Inc.)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-11-01] (Malwarebytes)
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2010-11-18] (Igor Pavlov)
ContextMenuHandlers4: [Corel PaintShop Pro X4] -> {CA34A346-C652-4F33-8CFF-FD6A91D9D64A} => c:\Program Files (x86)\Corel\Corel PaintShop Pro X4\PSPContextMenu64.dll [2012-05-11] (Corel Software, Inc.)
ContextMenuHandlers5: [ACE] -> {5E2121EE-0300-11D4-8D3B-444553540000} => C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\atiacm64.dll [2015-05-05] (Advanced Micro Devices, Inc.)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-11-01] (Malwarebytes)
ContextMenuHandlers6: [McCtxMenuFrmWrk] -> {CCA9EFD3-29ED-430A-BA6D-E6BBFF0A60C2} => c:\Program Files\McAfee\MSC\McCtxMenuFrmWrk.dll [2017-07-10] (McAfee, Inc.)
ContextMenuHandlers6_S-1-5-21-3289118944-4034126387-1954186238-1000: [InventorMenu] -> {6FDE7A70-351B-11d6-988B-0010B57A8BB7} => C:\Program Files\Autodesk\Inventor 2016\Bin\DtBridge.dll -> No File
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {12D74CB1-D95F-4343-A23A-6763BEAA42CB} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {36B966E5-B8D6-49FF-80A1-B1B4136C751E} - System32\Tasks\GarminUpdaterTask => C:\Program Files (x86)\Garmin\Express Self Updater\ExpressSelfUpdater.exe
Task: {4678B207-E35D-4E4E-BE9C-DABD7B77A524} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2016-02-23] (Apple Inc.)
Task: {4FAD17B9-4EEB-4CAD-803C-1B43BD161CEB} - System32\Tasks\McAfeeLogon => C:\Program Files\Common Files\McAfee\Platform\McUICnt.exe [2017-05-30] (McAfee, Inc.)
Task: {722FEA3D-3848-4774-A087-454E746A904A} - System32\Tasks\McAfee\McAfee Idle Detection Task
Task: {8A289A42-417A-45DD-A36F-2F581B27307B} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_28_0_0_137_pepper.exe [2018-01-09] (Adobe Systems Incorporated)
Task: {B3C459B3-51D7-4679-82D8-96BDEB286107} - System32\Tasks\McAfee Remediation (Prepare) => C:\Program Files\Common Files\AV\McAfee VirusScan\upgrade.exe [2017-04-12] (McAfee, Inc.)
Task: {C207FBBE-E6C7-4912-AE92-66921801C453} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {D351F207-C8DE-43F2-9261-EE932A351F29} - System32\Tasks\GoogleUpdateTaskMachineUA1d0908d4088e86f => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {EC8807A2-747B-4034-AA6B-0A6DFA75F885} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2018-01-09] (Adobe Systems Incorporated)
Task: {EE2CC55D-8C31-44A8-94DC-A86099E682C2} - System32\Tasks\{16D7FACF-B0D1-48F8-9C02-E3A61932FA80} => "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" hxxp://ui.skype.com/ui/0/6.7.0.102/en/abandoninstall?page=tsProgressBar
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
 
==================== Shortcuts & WMI ========================
 
(The entries could be listed to be restored or removed.)
 
 
Shortcut: C:\Users\Teschke\Favorites\Dustin\NCH Software Download Site.lnk -> hxxp://www.nchsoftware.com/index.htm
 
ShortcutWithArgument: C:\Users\Teschke\Desktop\Games\Art & Media\VideoStudio X9 Training.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) -> www.studiobacklot.tv/videostudioX9
ShortcutWithArgument: C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Web Applications\_crx_mkdmfheflfmedmfjolgifliincdhfgdl\Slender Space.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) ->  --profile-directory=Default --app-id=mkdmfheflfmedmfjolgifliincdhfgdl
ShortcutWithArgument: C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Web Applications\_crx_jangaedeekciafhlanphhnalogmhefmo\theHunter.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) ->  --profile-directory=Default --app-id=jangaedeekciafhlanphhnalogmhefmo
ShortcutWithArgument: C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Web Applications\_crx_fplklihjpkinahlihcljhnnlnhnmmhdp\Counter Strike Online.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) ->  --profile-directory=Default --app-id=fplklihjpkinahlihcljhnnlnhnmmhdp
ShortcutWithArgument: C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Web Applications\_crx_bmekbplkjhgmljmbblmhmcnocafhaink\BeGone_ Last Stand HD.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) ->  --profile-directory=Default --app-id=bmekbplkjhgmljmbblmhmcnocafhaink
ShortcutWithArgument: C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Web Applications\_crx_alnfdikmbdfgkcbdodjcbmedanjinmkk\Beatlab.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) ->  --profile-directory=Default --app-id=alnfdikmbdfgkcbdodjcbmedanjinmkk
ShortcutWithArgument: C:\Users\Teschke\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\9501e18d7c2ab92e\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory="Profile 2"
ShortcutWithArgument: C:\Users\Teschke\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\225bb61db2f318c1\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory="Profile 3"
 
==================== Loaded Modules (Whitelisted) ==============
 
2013-04-18 01:51 - 2009-11-04 12:18 - 000189440 _____ () C:\Windows\system32\spool\PRTPROCS\x64\lxeadrpp.dll
2013-05-07 22:03 - 2015-04-21 20:30 - 000066872 _____ () C:\Windows\SysWOW64\PnkBstrA.exe
2013-05-07 22:03 - 2015-04-21 20:30 - 000107832 _____ () C:\Windows\SysWOW64\PnkBstrB.exe
2013-11-16 13:28 - 2005-04-21 23:36 - 000143360 ____R () C:\Windows\system32\BrSNMP64.dll
2017-11-24 18:55 - 2017-12-12 04:53 - 002358728 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\MwacLib.dll
2017-11-24 18:55 - 2017-12-12 04:53 - 002301384 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\SelfProtectionSdk.dll
2013-09-05 00:17 - 2013-09-05 00:17 - 004300456 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF
2010-10-20 14:23 - 2010-10-20 14:23 - 008801632 _____ () C:\Program Files\Microsoft Office\Office14\1033\GrooveIntlResource.dll
2016-09-23 19:08 - 2016-07-14 15:45 - 001661392 _____ () C:\Program Files\Tablet\Wacom\libxml2.dll
2017-06-01 14:58 - 2017-07-06 14:58 - 000595608 _____ () C:\Program Files\McAfee\MfeAV\RealProtectAMScanIf.dll
2017-06-01 14:58 - 2017-07-06 14:58 - 000584680 _____ () C:\Program Files\McAfee\MfeAV\RepairModule.dll
2013-11-16 13:28 - 2009-02-27 16:38 - 000139264 ____R () C:\Program Files (x86)\Brother\BrUtilities\BrLogAPI.dll
2018-01-10 03:24 - 2018-01-10 03:24 - 000169984 _____ () C:\Windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\6cf48b8836d31d28d1328f4a22e42351\IsdiInterop.ni.dll
2013-04-17 22:29 - 2010-09-13 17:28 - 000058880 _____ () C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IsdiInterop.dll
2017-07-17 12:30 - 2017-07-17 12:30 - 000863744 _____ () C:\Windows\mod_frst.exe
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
AlternateDataStreams: C:\Users\Public\AppData:CSM [460]
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mbamchameleon => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ModuleCoreService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mbamchameleon => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcapexe => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeaack => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeaack.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeavfk => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeavfk.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefire => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfemms => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeplk => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeplk.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfetdi2k => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfetdi2k.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfevtp => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ModuleCoreService => ""="Service"
 
==================== Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
IE trusted site: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000\...\dell.com -> dell.com
IE trusted site: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000\...\hola.org -> hxxp://hola.org
 
==================== Hosts content: ===============================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2009-07-13 21:34 - 2009-06-10 16:00 - 000000824 _____ C:\Windows\system32\Drivers\etc\hosts
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-3289118944-4034126387-1954186238-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Teschke\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 199.166.6.2 - 209.239.11.98
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
MSCONFIG\Services: AdobeARMservice => 2
MSCONFIG\Services: Apple Mobile Device Service => 2
MSCONFIG\Services: Garmin Device Interaction Service => 2
MSCONFIG\Services: iPod Service => 3
MSCONFIG\Services: lxea_device => 2
MSCONFIG\Services: NETGEARGenieDaemon => 3
MSCONFIG\Services: SkypeUpdate => 2
MSCONFIG\startupfolder: C:^Users^Admin^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2010 Screen Clipper and Launcher.lnk => C:\Windows\pss\OneNote 2010 Screen Clipper and Launcher.lnk.Startup
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: Akamai NetSession Interface => "C:\Users\Admin\AppData\Local\Akamai\netsession_win.exe"
MSCONFIG\startupreg: APSDaemon => "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
MSCONFIG\startupreg: Corel Update Helper => "c:\Program Files\Corel\Corel VideoStudio X9\pua.exe" /t
MSCONFIG\startupreg: fssui => "C:\Program Files (x86)\Windows Live\Family Safety\fsui.exe" -autorun
MSCONFIG\startupreg: GarminExpressTrayApp => "C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe"
MSCONFIG\startupreg: ISUSPM => C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe -scheduler
MSCONFIG\startupreg: iTunesHelper => "C:\Program Files\iTunes\iTunesHelper.exe"
MSCONFIG\startupreg: LWS => C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe -hide
MSCONFIG\startupreg: Raptr => "C:\Program Files (x86)\Raptr Inc\Raptr\raptrstub.exe" --startup
MSCONFIG\startupreg: StartCCC => "C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [{F16ECB23-8787-4B80-BA61-02E5DFB8EBCF}] => (Allow) C:\Windows\system32\lxeacoms.exe
FirewallRules: [{32F84DA2-A985-4218-8BA3-1E6EFEC4A1BB}] => (Allow) C:\Program Files (x86)\Pinnacle\Studio 12\Programs\RM.exe
FirewallRules: [{70073B3D-DB28-443F-A95D-846B197BA271}] => (Allow) C:\Program Files (x86)\Pinnacle\Studio 12\Programs\RM.exe
FirewallRules: [{AAF56D47-E704-4924-B85E-7A9E344D8A0A}] => (Allow) C:\Program Files (x86)\Pinnacle\Studio 12\Programs\Studio.exe
FirewallRules: [{E30DFCBC-0367-4E35-A307-4CCAA64F1165}] => (Allow) C:\Program Files (x86)\Pinnacle\Studio 12\Programs\Studio.exe
FirewallRules: [{789CAFB5-E298-41C2-B5F0-C0732DF3F8E3}] => (Allow) C:\Program Files (x86)\Pinnacle\Studio 12\Programs\umi.exe
FirewallRules: [{C02D669A-832C-4E6A-9558-829864F25463}] => (Allow) C:\Program Files (x86)\Pinnacle\Studio 12\Programs\umi.exe
FirewallRules: [{CF129E27-7FB6-48D9-BCE2-D463091BAEDF}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{83972B14-0AA1-4EDB-8FE9-E17058EC761F}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{46DFC88A-8ADB-4927-8684-D514B1F21923}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{08B5C287-8BD1-41AD-B820-1A9FE91F3209}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Breach\Breach.exe
FirewallRules: [{E6BB2592-510D-4A37-AF32-27B048F5EF6E}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Breach\Breach.exe
FirewallRules: [{B1DCB9FB-B224-4B2F-AB37-1C6C45EDBA83}] => (Allow) C:\Program Files (x86)\Steam\bin\steamservice.exe
FirewallRules: [{60327E3C-B0BF-455D-8B68-55C352A13F86}] => (Allow) C:\Program Files (x86)\Steam\bin\steamservice.exe
FirewallRules: [{8BE08515-A9DA-44E2-8B4C-5B863A5FCB9D}] => (Allow) C:\Program Files (x86)\Steam\bin\steamservice.exe
FirewallRules: [{583027FB-C067-45CE-81B3-CF85F9F6D9B2}] => (Allow) C:\Program Files (x86)\Steam\bin\steamservice.exe
FirewallRules: [{81C1C6D9-D3C6-43A0-8E29-EF861AE114E6}] => (Allow) C:\Program Files (x86)\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe
FirewallRules: [{56FA6971-E199-4C34-A879-B36C761D7CF1}] => (Allow) C:\Program Files (x86)\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe
FirewallRules: [{1B889BC2-A65B-4A01-8E24-273A5B660318}] => (Allow) C:\Program Files (x86)\UBISOFT\Assassin's Creed III\AC3SP.exe
FirewallRules: [{2F42C95D-B079-40E0-83CE-AE027A6C9A6F}] => (Allow) C:\Program Files (x86)\UBISOFT\Assassin's Creed III\AC3SP.exe
FirewallRules: [{8522CB95-9EFE-4A37-AF87-82E6C1DD6705}] => (Allow) C:\Program Files (x86)\UBISOFT\Assassin's Creed III\AC3MP.exe
FirewallRules: [{424DB30E-5233-4284-A693-8B4E858DAA16}] => (Allow) C:\Program Files (x86)\UBISOFT\Assassin's Creed III\AC3MP.exe
FirewallRules: [{7A861EB4-6A29-470D-912B-4A563E7AE6F7}] => (Allow) C:\Program Files (x86)\UBISOFT\Assassin's Creed III\AssassinsCreed3.exe
FirewallRules: [{2B63F9F1-4C21-4476-A80A-C8C4CEA573C8}] => (Allow) C:\Program Files (x86)\UBISOFT\Assassin's Creed III\AssassinsCreed3.exe
FirewallRules: [{FB653026-B559-4FD3-9828-40A5761DCF38}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Portal 2\portal2.exe
FirewallRules: [{44ECF51C-3A54-4861-9A4E-25E82FC6B9BB}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Portal 2\portal2.exe
FirewallRules: [{8B185093-81EA-4EF5-9BB8-D730D6CC8818}] => (Allow) C:\Program Files (x86)\Origin Games\Crysis 3\Bin32\Crysis3.exe
FirewallRules: [{8F55590B-9251-41AF-A5D8-9EAF2E8DBA24}] => (Allow) C:\Program Files (x86)\Origin Games\Crysis 3\Bin32\Crysis3.exe
FirewallRules: [{B6B2D2BA-1409-4C46-94AF-1F28FCFEA063}] => (Allow) C:\Program Files (x86)\StarCraft II\StarCraft II.exe
FirewallRules: [{5E3F7B0C-853E-49E7-9770-17AB687715B6}] => (Allow) C:\Program Files (x86)\StarCraft II\StarCraft II.exe
FirewallRules: [{D08C82D9-40F1-4664-A9F8-54CEE92A3954}] => (Allow) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
FirewallRules: [{2F80630E-EB85-4814-B7BC-8C206124D93C}] => (Allow) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
FirewallRules: [{C47E9DCF-FF13-49FD-A5D0-734E0BE00521}] => (Allow) C:\Program Files (x86)\theHunter\launcher\launcher.exe
FirewallRules: [{28C8990C-A52A-42C4-BA8D-1CD40DC43CE8}] => (Allow) C:\Program Files (x86)\theHunter\launcher\launcher.exe
FirewallRules: [{71709164-B6F2-4805-8AED-1D567AF8B96D}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Skyrim\SkyrimLauncher.exe
FirewallRules: [{95EEC40A-0EFF-447A-BA96-1DD5F4A38C05}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Skyrim\SkyrimLauncher.exe
FirewallRules: [{B558288E-5444-4364-B99F-389093101A3E}] => (Allow) C:\Program Files\Lightworks\Lightworks.exe
FirewallRules: [{F81BB928-631A-413E-898B-4ECEC619B624}] => (Allow) C:\Program Files\Lightworks\Lightworks.exe
FirewallRules: [{69CE75F1-E33F-42DC-85F9-7D176E2076E9}] => (Allow) C:\Program Files\Lightworks\ntcardvt.exe
FirewallRules: [{35ADB5EC-FEF0-41B2-8FD7-2B6163B06ACF}] => (Allow) C:\Program Files\Lightworks\ntcardvt.exe
FirewallRules: [{5D802E51-2D70-44E7-8A38-77ECEF4CC79F}] => (Allow) LPort=54925
FirewallRules: [{57298198-28C7-4134-8EE0-B517E2C6FE44}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\XCom-Enemy-Unknown\Binaries\Win32\XComGame.exe
FirewallRules: [{6159DE13-EE45-4911-B28C-8DB4F584A284}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\XCom-Enemy-Unknown\Binaries\Win32\XComGame.exe
FirewallRules: [{810F18D6-3CE1-43F1-9AC3-63041511EEE2}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{84C693B9-AEE3-4795-8165-7130A2F00058}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{02CCF350-0DBE-42BD-BFAB-0DF64DF10A13}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Team Fortress 2\hl2.exe
FirewallRules: [{FE8CAA48-E29E-44EC-9FFC-3C1945874D49}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Team Fortress 2\hl2.exe
FirewallRules: [{155E1331-C6F6-4586-B71D-833CC783B829}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{2CF8A5C6-7885-4901-A242-CF3CFDD7DC7D}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{5003C5AF-24F5-4759-AD3F-40E5648BF602}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Team Fortress 2\hl2.exe
FirewallRules: [{41EA998E-B4A6-4ED7-9191-256963A00DA1}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Team Fortress 2\hl2.exe
FirewallRules: [{72B155B7-7D16-414D-B3E7-92D341959244}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{DBE8985D-BEB3-4F04-8B14-2CFB90EDD6A7}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{99E88E28-5A6C-48BB-ADE3-EB7607181196}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{DDB7BF02-1D82-4E33-B090-A5C1664879B6}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{6984E421-BCAD-4E9D-A092-C103A0FDE4A1}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{0BE8AC0C-EE47-439C-AF37-A16BAD69A9DA}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{7D33A7E0-AF82-4C7C-BF7B-31FBFD51C52C}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{14D8F6D2-9205-4683-A37B-CA5CFA42A57A}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{F7049409-B56D-4686-93A8-11FF390C7229}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{B33040E5-F29A-4AD7-A33E-284AC16C3305}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{3C457650-44A0-4AA0-8389-D3A828ACA345}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Team Fortress 2\hl2.exe
FirewallRules: [{3DB6FA17-1D3B-437F-9D7A-ACBA9266E6DB}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Team Fortress 2\hl2.exe
FirewallRules: [{2325C2C9-0C15-4800-8C7D-F658C7FE2F00}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Team Fortress 2\hl2.exe
FirewallRules: [{545E5F7D-11D8-4E1F-A1A0-223BC753ADDC}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Team Fortress 2\hl2.exe
FirewallRules: [{B13739F0-FC71-4183-84C5-FA460F17C6B6}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.1040\Agent.exe
FirewallRules: [{34D763EF-0F01-41EF-B98D-AC336699F93E}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.1040\Agent.exe
FirewallRules: [{F49C1CFE-07C7-46DB-993A-238C1DAA027F}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2380\Agent.exe
FirewallRules: [{7AC1CA3F-4D02-4B48-AE8C-BE962C944C2C}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2380\Agent.exe
FirewallRules: [{A7D771AD-9480-4250-8920-DDEA6D1A8F4D}] => (Allow) C:\Program Files (x86)\StarCraft II\StarCraft II Public Test.exe
FirewallRules: [{EEFB70E1-9211-4B71-866B-7B0844415455}] => (Allow) C:\Program Files (x86)\StarCraft II\StarCraft II Public Test.exe
FirewallRules: [{01B75E99-AC2A-44D9-84AB-68D2E82C71AA}] => (Allow) C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
FirewallRules: [{7BE16534-A3E4-4E98-B6F2-48CA2B4BA3D0}] => (Allow) C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
FirewallRules: [{BE65226B-F667-46E5-A4E8-3C9036FC7D14}] => (Allow) C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
FirewallRules: [{0C669D17-C76D-41DF-A453-CA03F4D86CCF}] => (Allow) C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
FirewallRules: [{58732465-04C5-4EF0-80C0-EFD5391E965B}] => (Allow) C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
FirewallRules: [{E78FB3E8-57EA-49AA-B20A-EE3F70903C4C}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{47FE0346-4C48-4A50-8A77-18EA37EC9B07}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{EB77F046-CD9F-4C38-B7BF-F856EDD35F14}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{1D42B23D-921C-4E36-8B87-E2D90D0834FE}] => (Allow) LPort=2869
FirewallRules: [{0030EE09-4BAA-4E9F-A64C-F79381EFE987}] => (Allow) LPort=1900
FirewallRules: [{2A29E2C7-0BA4-483A-8F64-F52609F4A4FB}] => (Allow) C:\Program Files (x86)\Hearthstone\Hearthstone.exe
FirewallRules: [{D7A56D14-7B35-44EB-A09B-E36452560FCF}] => (Allow) C:\Program Files (x86)\Hearthstone\Hearthstone.exe
FirewallRules: [{556C1B3C-3F15-45C2-9D70-CA864CBDADE9}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2880\Agent.exe
FirewallRules: [{BE479DD9-893C-4D2F-AA5D-92D2E34946AF}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2880\Agent.exe
FirewallRules: [{7B41D613-A78E-4B35-A706-138CBF201879}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\JABIA\JaggedAllianceBIA.exe
FirewallRules: [{5CEF6981-E7B6-43D9-AF71-06491F6E4836}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\JABIA\JaggedAllianceBIA.exe
FirewallRules: [{EF58DAEF-A76C-47EA-B618-112AB60643C8}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{05CBE5C7-ACB2-46D4-9D26-0605916DB72F}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{00D1F223-C0CF-449A-A132-7618F3F6D4B9}] => (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe
FirewallRules: [{49D6483D-2FA4-48D4-89F3-6D0A21A794EB}] => (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe
FirewallRules: [{F2D3D2AE-086F-4199-81AE-4645F4CF383D}] => (Allow) C:\Program Files (x86)\UBISOFT\Far Cry 2\bin\FarCry2.exe
FirewallRules: [{C28F70F2-9FC7-476D-82E1-FF447DD35154}] => (Allow) C:\Program Files (x86)\UBISOFT\Far Cry 2\bin\FarCry2.exe
FirewallRules: [{46347C9C-4AE9-4DF5-A15C-0C2B674058C1}] => (Allow) C:\Program Files (x86)\UBISOFT\Far Cry 2\bin\FC2Launcher.exe
FirewallRules: [{89B65C34-E2D0-4987-90C6-7744EC436736}] => (Allow) C:\Program Files (x86)\UBISOFT\Far Cry 2\bin\FC2Launcher.exe
FirewallRules: [{D4FBEAC5-E679-4086-9DE4-3965604F11DA}] => (Allow) C:\Program Files (x86)\UBISOFT\Far Cry 2\bin\FC2Editor.exe
FirewallRules: [{D4C131B3-4646-4F46-9D4D-36DB2F00C7A5}] => (Allow) C:\Program Files (x86)\UBISOFT\Far Cry 2\bin\FC2Editor.exe
FirewallRules: [{5EE985CB-9EA4-4B04-BD6F-87E8DD8E7961}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{C1CFD1DC-DFC6-410F-9BB3-1A3681CA6D17}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{8AEEBC88-98FB-46C7-B479-EDF5818C072B}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{C6796B54-ACAF-4FB2-891E-36F8DCA5E6A1}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [TCP Query User{5A03840E-2B1C-4CA8-9516-B3A70A455B08}C:\program files (x86)\daide\quickstart\aiserver\aiserver.exe] => (Block) C:\program files (x86)\daide\quickstart\aiserver\aiserver.exe
FirewallRules: [UDP Query User{1080189C-898C-4245-BE92-EEAE22DAA1DD}C:\program files (x86)\daide\quickstart\aiserver\aiserver.exe] => (Block) C:\program files (x86)\daide\quickstart\aiserver\aiserver.exe
FirewallRules: [{BFC1DB99-77B5-4AC0-9464-240FCBA70894}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{881BA182-0CC1-4EA1-BE0C-E54B0436A797}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{01A5C88B-73F5-4B59-B01C-DCFCB756C85F}] => (Allow) C:\Program Files (x86)\Raptr\raptr.exe
FirewallRules: [{88AD7A8D-DFDA-4267-BE87-C2F534A45E34}] => (Allow) C:\Program Files (x86)\Raptr\raptr.exe
FirewallRules: [{5326A4A9-4F4F-4B39-8D03-C662C07A7E2B}] => (Allow) C:\Program Files (x86)\Raptr\raptr_im.exe
FirewallRules: [{07ADBAC2-B989-4F09-ACF2-8FF03CC263A6}] => (Allow) C:\Program Files (x86)\Raptr\raptr_im.exe
FirewallRules: [{B500E6F5-4E07-45DE-B0B5-8DB571C79FCC}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2cfg.exe
FirewallRules: [{EB3C113F-C0B6-4EFB-9DA7-BBED24F557F7}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2cfg.exe
FirewallRules: [{BFAA2466-2AB3-4949-8A00-5AF6CB3C3157}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{30820C6B-C2A0-4A23-9D32-72EE33068630}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{2CC22695-DA31-45BB-8966-C7F013D0D69F}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{C8E47915-3EB8-4F4C-81F0-65557EB69481}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{E00F6D8F-53E9-4771-8BDC-4BB62EB4B4F1}] => (Allow) C:\Program Files\iTunes\iTunes.exe
FirewallRules: [{256D452F-606F-4DF8-99E8-89B2AAF0C1AC}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Dirty Bomb\Binaries\Win32\ShooterGame-Win32-Shipping.exe
FirewallRules: [{3F642655-712C-4445-B6DB-35B2D6CA2493}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Dirty Bomb\Binaries\Win32\ShooterGame-Win32-Shipping.exe
FirewallRules: [{C38C6387-76A9-43F2-96FD-929D9B227CE4}] => (Allow) C:\Program Files (x86)\Raptr Inc\Raptr\raptr.exe
FirewallRules: [{91E9E38B-7E45-4B09-8F10-3F90E197E61E}] => (Allow) C:\Program Files (x86)\Raptr Inc\Raptr\raptr.exe
FirewallRules: [{AE2791DC-926C-4224-B936-4CCCD6159DD8}] => (Allow) C:\Program Files (x86)\Raptr Inc\Raptr\raptr_im.exe
FirewallRules: [{DDA14856-5CA6-4116-A154-8834570ACDDB}] => (Allow) C:\Program Files (x86)\Raptr Inc\Raptr\raptr_im.exe
FirewallRules: [TCP Query User{36F416F9-5BD2-4CF3-BD5C-FAF7440DCC03}C:\users\admin\appdata\local\akamai\netsession_win.exe] => (Allow) C:\users\admin\appdata\local\akamai\netsession_win.exe
FirewallRules: [UDP Query User{E84D30D4-10B8-462A-B495-7155F8D93547}C:\users\admin\appdata\local\akamai\netsession_win.exe] => (Allow) C:\users\admin\appdata\local\akamai\netsession_win.exe
FirewallRules: [{2EB0AEB4-F3C7-4CE7-ACEA-9E92A9457FD2}] => (Allow) C:\Program Files (x86)\McAfee\Supportability\MVT\MvtApp.exe
FirewallRules: [{B3D3FF8F-E7A2-4B4B-8293-1A71640863D3}] => (Allow) C:\Program Files (x86)\McAfee\Supportability\MVT\MvtApp.exe
FirewallRules: [{67209B8B-EF3E-414D-9C12-1BA3BBEC131B}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [{7D993D04-3A22-4717-9405-31BFD263C246}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [{18B5C50C-A5C5-4007-A6A5-4121C385EF08}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Dirty Bomb\DirtyBombLauncher.exe
FirewallRules: [{51EAC435-D1B9-47AF-9AC1-8CFE2B8E3ECC}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Dirty Bomb\DirtyBombLauncher.exe
FirewallRules: [TCP Query User{58174CC5-FF62-4FB3-965C-06C7FA8C10B9}C:\program files (x86)\starcraft ii\versions\base51149\sc2_x64.exe] => (Block) C:\program files (x86)\starcraft ii\versions\base51149\sc2_x64.exe
FirewallRules: [UDP Query User{5E8D7FC0-8562-4069-82DC-BA8D65674A71}C:\program files (x86)\starcraft ii\versions\base51149\sc2_x64.exe] => (Block) C:\program files (x86)\starcraft ii\versions\base51149\sc2_x64.exe
FirewallRules: [TCP Query User{AC30B663-D262-4232-86A1-ECF9527D3B52}C:\program files (x86)\starcraft ii\versions\base51702\sc2_x64.exe] => (Block) C:\program files (x86)\starcraft ii\versions\base51702\sc2_x64.exe
FirewallRules: [UDP Query User{EF86E717-134A-42CB-9C52-BE75AA178E84}C:\program files (x86)\starcraft ii\versions\base51702\sc2_x64.exe] => (Block) C:\program files (x86)\starcraft ii\versions\base51702\sc2_x64.exe
FirewallRules: [TCP Query User{D15692F9-2135-4005-B6C9-F8BDB276BF53}C:\program files (x86)\starcraft ii\support\sc2editor.exe] => (Block) C:\program files (x86)\starcraft ii\support\sc2editor.exe
FirewallRules: [UDP Query User{3E00FE2D-5D60-4B84-9B9D-A57BD840EDCB}C:\program files (x86)\starcraft ii\support\sc2editor.exe] => (Block) C:\program files (x86)\starcraft ii\support\sc2editor.exe
FirewallRules: [TCP Query User{2D5D6177-FA3C-4AD5-A788-BC88D5B8D392}C:\users\teschke\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\teschke\appdata\roaming\spotify\spotify.exe
FirewallRules: [UDP Query User{9CC7B4A3-0435-4270-AEE4-EA906E29B995}C:\users\teschke\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\teschke\appdata\roaming\spotify\spotify.exe
FirewallRules: [{BCE6458B-7347-4CAD-A3C5-5D36B837848A}] => (Allow) C:\Program Files (x86)\Google\Chrome Remote Desktop\63.0.3239.32\remoting_host.exe
FirewallRules: [TCP Query User{8016F667-550B-47F6-A163-A6ECC5DEFC51}C:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe
FirewallRules: [UDP Query User{4290882B-C43B-4A07-A3D5-DBF0EF281827}C:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe
FirewallRules: [TCP Query User{C84F8A5F-D20C-4E1E-8778-CE5C3E7834E9}C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe
FirewallRules: [UDP Query User{C7D11005-6FD5-413E-BD97-07843AFF24CD}C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe
FirewallRules: [TCP Query User{1D5A22B0-A2B6-4F48-85EF-3247698D1E3A}C:\program files\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe] => (Allow) C:\program files\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe
FirewallRules: [UDP Query User{1D1F93FA-574A-4942-8CD9-98A7DFADBBB6}C:\program files\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe] => (Allow) C:\program files\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe
FirewallRules: [{2834D457-F5FF-4DBE-BAAA-A4CD36B884A6}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
 
==================== Restore Points =========================
 
25-01-2018 21:55:22 Scheduled Checkpoint
 
==================== Faulty Device Manager Devices =============
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (01/27/2018 03:05:10 PM) (Source: WTabletServicePro) (EventID: 1) (User: )
Description: Event-ID 1
 
Error: (01/27/2018 03:05:03 PM) (Source: WTabletServicePro) (EventID: 1) (User: )
Description: Event-ID 1
 
Error: (01/27/2018 01:15:11 PM) (Source: Desktop Window Manager) (EventID: 9020) (User: )
Description: The Desktop Window Manager has encountered a fatal error (0x80070008)
 
Error: (01/27/2018 12:33:19 PM) (Source: WTabletServicePro) (EventID: 1) (User: )
Description: Event-ID 1
 
Error: (01/27/2018 12:33:13 PM) (Source: WTabletServicePro) (EventID: 1) (User: )
Description: Event-ID 1
 
Error: (01/26/2018 07:38:10 PM) (Source: WTabletServicePro) (EventID: 1) (User: )
Description: Event-ID 1
 
Error: (01/26/2018 07:38:03 PM) (Source: WTabletServicePro) (EventID: 1) (User: )
Description: Event-ID 1
 
Error: (01/26/2018 05:34:36 PM) (Source: MsiInstaller) (EventID: 1024) (User: XPS)
Description: Product: Adobe Reader XI - Update '{AC76BA86-7AD7-0000-2550-7A8C40011020}' could not be installed. Error code 1625. Windows Installer can create logs to help troubleshoot issues with installing software packages. Use the following link for instructions on turning on logging support: http://go.microsoft.com/fwlink/?LinkId=23127
 
Error: (01/26/2018 03:10:40 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: IEXPLORE.EXE, version: 11.0.9600.18894, time stamp: 0x5a467703
Faulting module name: atidxx32.dll, version: 8.17.10.621, time stamp: 0x55496920
Exception code: 0xc0000005
Fault offset: 0x0050e52a
Faulting process id: 0x208c
Faulting application start time: 0x01d396df7b136cb9
Faulting application path: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
Faulting module path: C:\Windows\system32\atidxx32.dll
Report Id: fa916211-02d4-11e8-a1ce-782bcb94ac4d
 
Error: (01/26/2018 09:00:28 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: IEXPLORE.EXE, version: 11.0.9600.18894, time stamp: 0x5a467703
Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception code: 0x4000001f
Fault offset: 0x0facf000
Faulting process id: 0x22b0
Faulting application start time: 0x01d396ad56e6843d
Faulting application path: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
Faulting module path: unknown
Report Id: 436dcff5-02a1-11e8-a1ce-782bcb94ac4d
 
 
System errors:
=============
Error: (01/27/2018 03:10:10 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The McAfee Platform Services service failed to start due to the following error: 
The system cannot find the file specified.
 
Error: (01/27/2018 03:10:10 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The McAfee Platform Services service failed to start due to the following error: 
The system cannot find the file specified.
 
Error: (01/27/2018 03:10:10 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The McAfee Platform Services service failed to start due to the following error: 
The system cannot find the file specified.
 
Error: (01/27/2018 03:10:10 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The McAfee Platform Services service failed to start due to the following error: 
The system cannot find the file specified.
 
Error: (01/27/2018 03:10:10 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The McAfee Platform Services service failed to start due to the following error: 
The system cannot find the file specified.
 
Error: (01/27/2018 03:10:10 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The McAfee Platform Services service failed to start due to the following error: 
The system cannot find the file specified.
 
Error: (01/27/2018 03:10:10 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The McAfee Platform Services service failed to start due to the following error: 
The system cannot find the file specified.
 
Error: (01/27/2018 03:10:10 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The McAfee Platform Services service failed to start due to the following error: 
The system cannot find the file specified.
 
Error: (01/27/2018 03:10:10 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The McAfee Platform Services service failed to start due to the following error: 
The system cannot find the file specified.
 
Error: (01/27/2018 03:10:10 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The McAfee Platform Services service failed to start due to the following error: 
The system cannot find the file specified.
 
 
CodeIntegrity:
===================================
  Date: 2017-09-14 03:39:35.233
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\kernel32.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-09-04 08:07:38.756
  Description: Windows is unable to verify the integrity of the file \Device\HarddiskVolume2\$Windows.~BT\Updates\Critical\8e08ca47-f6ba-409d-82de-698e324c0004\amd64_microsoft-windows-errorreportingfaults_31bf3856ad364e35_10.0.10074.1_none_f3153036f55ab3f5\werfault.exe because the signing certificate has been revoked.  Check with the publisher to see if a new signed version of the kernel module is available.
 
  Date: 2015-09-04 08:07:38.749
  Description: Windows is unable to verify the integrity of the file \Device\HarddiskVolume2\$Windows.~BT\Updates\Critical\8e08ca47-f6ba-409d-82de-698e324c0004\amd64_microsoft-windows-errorreportingfaults_31bf3856ad364e35_10.0.10074.1_none_f3153036f55ab3f5\werfault.exe because the signing certificate has been revoked.  Check with the publisher to see if a new signed version of the kernel module is available.
 
  Date: 2015-09-04 08:07:38.743
  Description: Windows is unable to verify the integrity of the file \Device\HarddiskVolume2\$Windows.~BT\Updates\Critical\8e08ca47-f6ba-409d-82de-698e324c0004\amd64_microsoft-windows-errorreportingfaults_31bf3856ad364e35_10.0.10074.1_none_f3153036f55ab3f5\werfault.exe because the signing certificate has been revoked.  Check with the publisher to see if a new signed version of the kernel module is available.
 
  Date: 2015-09-04 08:07:38.640
  Description: Windows is unable to verify the integrity of the file \Device\HarddiskVolume2\$Windows.~BT\Updates\Critical\8e08ca47-f6ba-409d-82de-698e324c0004\amd64_microsoft-windows-errorreportingcore_31bf3856ad364e35_10.0.10074.1_none_a384c5aabe759ea5\wermgr.exe because the signing certificate has been revoked.  Check with the publisher to see if a new signed version of the kernel module is available.
 
  Date: 2015-09-04 08:07:38.629
  Description: Windows is unable to verify the integrity of the file \Device\HarddiskVolume2\$Windows.~BT\Updates\Critical\8e08ca47-f6ba-409d-82de-698e324c0004\amd64_microsoft-windows-errorreportingcore_31bf3856ad364e35_10.0.10074.1_none_a384c5aabe759ea5\wermgr.exe because the signing certificate has been revoked.  Check with the publisher to see if a new signed version of the kernel module is available.
 
  Date: 2015-09-04 08:07:38.621
  Description: Windows is unable to verify the integrity of the file \Device\HarddiskVolume2\$Windows.~BT\Updates\Critical\8e08ca47-f6ba-409d-82de-698e324c0004\amd64_microsoft-windows-errorreportingcore_31bf3856ad364e35_10.0.10074.1_none_a384c5aabe759ea5\wermgr.exe because the signing certificate has been revoked.  Check with the publisher to see if a new signed version of the kernel module is available.
 
 
==================== Memory info =========================== 
 
Processor: Intel® Core™ i7-2600 CPU @ 3.40GHz
Percentage of memory in use: 20%
Total physical RAM: 12270.45 MB
Available physical RAM: 9749.45 MB
Total Virtual: 24539.06 MB
Available Virtual: 21965.58 MB
 
==================== Drives ================================
 
Drive c: () (Fixed) (Total:931.41 GB) (Free:47.53 GB) NTFS
Drive d: (PONYO) (CDROM) (Total:7.92 GB) (Free:0 GB) UDF
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: A61DA447)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=931.4 GB) - (Type=07 NTFS)
 
==================== End of Addition.txt ============================


#6 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 36,617 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:07:50 PM

Posted 27 January 2018 - 05:45 PM

Greetings Dustin.

Let's start with this.

===================================================

Uninstalling Programs Using Revo Uninstaller Free

--------------------

I would like to remove the below programs. We can reinstall them later if you wish.
  • Please download and install Revo Uninstaller Free
  • Right click Revo Uninstaller and select Run as administrator
  • From the list of programs double click on the listed program(s), or anything similar, to remove it (if it exists)
McAfee AntiVirus Plus
McAfee AntiVirus Plus
McAfee WebAdvisor
  • Click Yes to any warning screen that may appear
  • If presented with the program uninstall option click Uninstall
  • If asked to restart now click No
  • Under Scanning Modes select Advanced then select Scan
  • On the Found leftover Registry items window click Select All, Delete, then Yes
  • If prompted click on Next
  • On the Found leftover files and folders window click on Select all, Delete, Yes, OK on any warning screen, then Finish
===================================================

Malwarebytes AdwCleaner

-------------------
  • Please download AdwCleaner and save it on your desktop.
  • Close all open programs and browsers
  • Double click on AdwCleaner.exe, click Run, then select I agree if it appears
  • Click Scan
  • Once the scan has completed if there are threats found you will see Found 3 threats or something similar above the progress bar
  • Click each tab under Results and uncheck any items you want to keep
  • Click on Clean
  • Confirm the cleaning and rebooting of your computer by clicking OK
  • Click OK twice to finish the removal process by automatically rebooting your computer
  • Once completed an AdwCleaner document will open on your desktop
  • Copy and paste the contents in your reply
===================================================

Farbar's Recovery Scan Tool - Run Fix in Normal or Safe Mode

--------------------
  • Right click on the FRST icon and select Run as administrator
  • Highlight the below information then hit the Ctrl + C keys at the same time
Start::
CreateRestorePoint:
CloseProcesses:
URLSearchHook: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000 - (No Name) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - No File
2014-01-05 01:00 - 2014-01-05 01:00 - 000003584 _____ () C:\Users\Teschke\AppData\Local\Temp\2supyjld.dll
2013-04-27 10:50 - 2013-04-27 10:50 - 000263186 _____ () C:\Users\Teschke\AppData\Local\Temp\air97CE.exe
2013-05-25 15:00 - 2013-05-25 15:00 - 000263186 _____ () C:\Users\Teschke\AppData\Local\Temp\airAA45.exe
2016-09-23 19:22 - 2016-09-23 19:26 - 083528440 _____ () C:\Users\Teschke\AppData\Local\Temp\mpa03944.exe
2013-08-03 23:47 - 2013-08-03 23:47 - 000008192 _____ () C:\Users\Teschke\AppData\Local\Temp\odn6esre.dll
2013-07-21 00:00 - 2013-07-21 00:00 - 000003584 _____ () C:\Users\Teschke\AppData\Local\Temp\q64mjujk.dll
2015-10-02 15:18 - 2016-01-10 18:25 - 013110615 _____ (Acresso Software Inc.) C:\Users\Teschke\AppData\Local\Temp\ubi444B.tmp.exe
2016-01-13 16:46 - 2016-01-14 16:47 - 004004004 _____ (Acresso Software Inc.) C:\Users\Teschke\AppData\Local\Temp\ubiEDD6.tmp.exe
HKU\S-1-5-21-3289118944-4034126387-1954186238-1000\...\ChromeHTML: ->  <==== ATTENTION
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{00F064D8-FEC3-48ac-B07D-39C314D1727B}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\ServiceModule.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{0215A4C0-5431-4FD0-9B06-46589B5C4939}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{048ED0E0-12CF-4C0F-9FFA-947C2FBE8C8E}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{071339A1-1946-44B2-B63E-50459B15DB86}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{073CB204-6B29-46FC-AB98-451F1D068741}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\TestServer.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{08A60FF7-BB37-44F4-9759-0ADA6C7B9CC9}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{0B38CACA-3D3C-48EA-BEB5-7D95F4F6EE15}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{0C3393F8-94F5-4B79-8C01-49A2D0CC0FE9}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{0D555CE0-304A-47A6-858B-B145209A3982}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{12545889-6D32-4424-9967-1E1D7BD1F809}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{13009989-EFB5-48C9-8BD2-943E0392BD71}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\RxAppCtrl.Ocx
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{14679E3B-C952-4998-8E13-4B1286E6DD99}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{1481B385-759A-4B00-9257-E96357563999}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{162EF0A1-5A33-46F2-ACCF-CA388B084A09}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{18A21864-E37B-42b9-9612-2C1E8C450A29}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\ServiceModule.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{1D625598-C876-4C51-8EF5-F9D8F96F62AA}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{1D6DFD6A-9E16-435A-9327-6FFEC6BA372F}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{1E5724EA-3423-4BD3-ABD6-46E650D2DC66}\InprocServer32 -> AcETransmit.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{1E8A29BA-827D-4031-A4A3-AE7999B402F6}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{1EA072EE-57FD-495E-889C-8243C3BDBDBC}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{1FD7F53F-7ED5-439C-9A77-A3821CD09E98}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{20E47D5B-529A-45BD-8E77-BF1A3064A008}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{21DB88B0-BFBF-11D4-8DE6-0010B541CAA8}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\iDrop.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{2709544A-5B24-4F9F-A5DA-CEC7297D3A4E}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{2BCA857B-A18B-4AFA-B183-CC0E49C12058}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{2C74F89E-7421-46B4-BA54-F86F1BD9F237}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{2C7D1157-7D50-4A88-9777-5EBBA3189AB8}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{2F8377FC-50C1-44EF-AB7A-8FF1BB8EA277}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\ServiceModule.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{3497C2EC-5684-4B21-AF74-F6760E0221DC}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{38C8B14E-7879-4DA9-8C3F-8CAAC359293A}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{3FC94EB5-AEBD-4f3f-A2A4-B6CE57113C01}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\RxAppDocView.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{3FCEB42C-9B98-486A-BED7-FD7F3ADB7291}\InprocServer32 -> AcETransmit.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{40770568-0D5E-49D4-BE47-BC47A4F0B0A4}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{44A52280-AE56-490D-890C-89FB7279ED6B}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{45122C53-8483-4b62-B15A-EAA9FE5FC3D5}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\ServiceModule.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{46C56738-39C6-4240-8B9B-008CCD769A84}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{47179DDE-10AC-4737-97C9-8CE5379343EA}\InprocServer32 -> AcETransmit.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{475C7B4A-6964-4F9E-9708-05A16EAC31D0}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{48270F9E-CCF6-4C79-B6FF-267C960E6425}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{48FEFCD7-5D7C-4E4A-9F11-60E69A31D4B1}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{49998808-648A-4A9C-A7A5-B1672775D9AB}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{4A756F5F-CBA4-428B-B17F-AF80C0C8502D}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{4B40437B-8972-4444-BBE3-1588FF55F203}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{4BD03680-3C0F-4501-AFF7-3D008586917F}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{4C80573A-9150-11d2-B772-0060B0F159EF}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\RxAppDocView.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{4D29B490-49B2-11D0-93C3-7E0706000000}\localserver32 -> "C:\Program Files\Autodesk\Inventor 2016\Bin\Inventor.exe"
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{4E6F2E83-E7F0-4333-9772-875EB733C820}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\RxTest.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{5544903C-2CCC-487C-91BB-F310B72A8E9B}\InprocServer32 -> AcETransmit.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{59A224A2-BEF8-4C89-96E0-83A5411ABB6C}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{622F6193-E4DD-46E6-BC66-2ED88E9FD28D}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{62FBB030-24C7-11D3-B78D-0060B0F159EF}\localserver32 -> "C:\Program Files\Autodesk\Inventor 2016\Bin\Inventor.exe"
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{644190AE-BD8F-493F-B63D-C79404AC5E07}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\ServiceModule.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{6451051B-AD22-4C6A-ACCE-013A0E1DDBC3}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{64B99FDB-1D85-447F-98C7-569DBDA723DB}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{6BCE6F6E-C050-4F39-BD98-E2743949F724}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{6F56D7C9-18DD-4C15-9FA8-C54E3610EC40}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{6FDE7A70-351B-11d6-988B-0010B57A8BB7}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\DtBridge.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{6FDE7A71-351B-11d6-988B-0010B57A8BB7}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\DtBridge.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{6FDE7A72-351B-11d6-988B-0010B57A8BB7}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\DtBridge.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{6FDE7A73-351B-11d6-988B-0010B57A8BB7}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\DtBridge.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{6FDE7A74-351B-11d6-988B-0010B57A8BB7}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\DtBridge.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{6FDE7A77-351B-11d6-988B-0010B57A8BB7}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\DtCp.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{70DBCAE8-8C2B-450C-9E1D-43E4686C6512}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{713C0E8A-5AE8-4695-B442-5ED6C4FE5C42}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{7293E009-3015-4AD3-96EC-D42C36B5FCE3}\InprocServer32 -> AcETransmit.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{72EC5CC5-88F3-45B1-A865-0A327DF58CC8}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\ServiceModule.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{72EFC580-D085-4B81-8C55-26A79E445338}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{750AEC19-2E4C-4ED9-9B9F-F9CAFCD060F3}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{794199C5-827C-41C8-8CB2-3A1EA056AF5E}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{798391FE-4AF2-4851-9DDA-1F0D70C02A9E}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{7BA16B3F-1AB3-4BD7-B959-52C4B8504EE9}\InprocServer32 -> AcInetUI.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{7C239DAB-BC87-45F3-B7B1-FCC1541A235B}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{81D07C3D-0350-11D3-B7C2-0060B0EC020B}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\RxAppCtrl.Ocx
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{834CE679-2E47-49DE-9E41-FEC87E9192EB}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{8421A29C-54B8-11D1-9837-0060B03C43C8}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\SolidObject.Dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{846217D0-8954-11D2-8DCD-0060B0C32531}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\UCxTextBtn.Ocx
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{846217D1-8954-11D2-8DCD-0060B0C32531}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\UCxTextBtn.Ocx
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{849AFB5B-D6C9-4924-A712-F7118FF9611F}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{85452F88-5071-492E-B850-2E3C586DCBD8}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{87F5CF8F-A06D-498F-A05F-E520E6B570DB}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{89F0FC31-3B1D-494B-A75B-6BD4FA527B8A}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{8AA16DFC-DFC6-4B51-8FA2-A5D812BE33BF}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{8B0E6BD9-610C-11D1-9842-0060B03C43C8}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\SolidObject.Dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{8C23B656-4E6E-4B45-9920-9617168D39A3}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\TestServer.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{8ED07FEF-E1B0-4CC3-B2BA-D354828AB952}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{988F4102-E6E3-4282-ACAC-55270827F2A8}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{9906CDFC-DB2C-4126-9422-13139B148495}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{9A21C6C5-27FC-4442-8590-575E7AFD73BB}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{9ECF83FB-23C5-43B6-83DE-93CFBDD74D4A}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{A58F47CC-FF65-4152-B0B1-666C643A5BFC}\InprocServer32 -> AcETransmit.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{A6A3D586-44CF-44C2-A92C-620BB713B4F2}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{ABBE3F83-D585-4A50-9B69-198B0F566F2E}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{AC5CECFA-F03A-41D2-A89C-704C44935941}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{B1560245-190E-4BBD-81DF-9B642D0E5325}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{B2A579E0-A797-40B1-8AEE-A8F6404719F8}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{B47196BC-D4AB-41BB-A771-543D67CFC9F5}\InprocServer32 -> AcETransmit.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{B53CEF4B-1A13-49DE-BBC5-A7100FB2F38C}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{B5EE2B68-9A23-4BCD-BB77-FEA6DFB24DD6}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{B6B5DC40-96E3-11d2-B774-0060B0F159EF}\localserver32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\Inventor.exe /Automation
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{B80687F9-FA4C-4735-9DC4-E5715F2BC698}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{B8E7214B-25CA-4116-84CB-E86FB9625B36}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\ServiceModule.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{BAE5802A-CF21-4F9C-AE04-D98F4036AC31}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{BBF6A206-CB04-479D-96AE-349E1E83319A}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{BC71DEA1-D6FB-48B8-AB06-D151C81BBCDD}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{BE54741D-E02B-4572-93D6-105AF4EDE777}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\ServiceModule.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{BF224DC3-B602-4EEE-BFE9-9E4E0AED6837}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{BF4CC07E-E9BB-40D6-873F-855B211033B9}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{C061C82C-D041-4214-BB07-B608107CEFCB}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{C2D4ACCC-A3D1-4A0A-AD59-0DD8BA3D5EE1}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{C343ED84-A129-11d3-B799-0060B0F159EF}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\RxApprenticeServer.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{C8C18F89-794D-466B-8B97-95634D9890EF}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{C8EC7647-1E79-4F13-81D7-2EED803D0D22}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{C92F8F8C-8B2C-11d4-B872-0060B0EC020B}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\DtBridge.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{CC23CA32-9892-4FBA-A108-FE31CA0F35A6}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{CD865713-70D6-4E15-BB7B-9B99AD9DEB85}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{CFEE2BAF-14F9-4D23-853D-B6E2BCC14263}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\ServiceModule.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{D56F5AB3-9C4D-4F1A-A851-A671D9FE8C22}\InprocServer32 -> AcETransmit.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{D66873EA-AAE5-41CC-8DD2-8CE3228E9F89}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{D7A1987D-4A73-11D1-9A4B-080009DCE505}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\ColorButton.Ocx
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{D7A1987E-4A73-11D1-9A4B-080009DCE505}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\ColorButton.Ocx
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{D86B6C47-11F2-4D95-B635-EA575F0892FC}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{DA1F437C-9BD9-11d4-B87C-0060B0EC020B}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\DtBridge.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{DB207560-8449-4FAF-BDC2-61676EB012D4}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{DB5D476B-3FF4-4E9D-A606-1E2B473BE571}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\AcInetUI.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{DCA7356C-FF94-4b20-AE04-7AA6A8E14117}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\ServiceModule.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{DDA9A20F-5B56-49F5-9465-CE82FC199352}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\ServiceModule.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{DE6B563C-B074-4BF1-A8A0-B3FED8703E99}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\ServiceModule.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{DE74F5AD-DA2F-429F-BAF9-850A2808D585}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{DF6525C2-6358-4B07-813D-708120C5FE1A}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{E177A457-9EAA-43C3-A3CE-84874A28F6CA}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{E1C85E9F-60B2-4007-80C3-2C5E09474C3B}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\RxInventorUtilities.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{E29F6C45-6927-4508-8F3F-34105FD3FC5F}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{E4222C78-3670-4BB1-9AD4-7D8F3E581F2D}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{E5B0515D-48D2-4F04-906D-0192ED65A2DD}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\TestServer.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{E70DE962-842A-4488-9481-1D0FD72A020F}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{E9C07CEC-7B82-49E4-BBA2-7533B88E9D64}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{EA34A0C0-5CE7-4701-A6FA-117D25CD5EBB}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{EF01D98A-747B-4522-AD70-991B90855DBF}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{F13E75B9-6AF6-49CB-80B3-6D2FF6E09932}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\ServiceModule.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{F196F03F-651A-43AF-BE34-D11942F24445}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{F2D4F4E5-EEA1-46FF-A83B-A270C92DAE4B}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\DTInterop.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{F2DB0EE3-7137-4CB0-8349-483C4FF2143A}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{F40E2FF0-4D77-40B2-9A44-A3AEECCE8EFF}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{F5522F0C-962A-48AC-9992-E81B07628F1F}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{F61064CC-DBFB-47ee-9BC8-CA5A1CBDF0DA}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\InvResc.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{F78DCF7C-043D-45FC-9D21-676FC307BA3F}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{F868EAEC-1B73-4F5E-BA73-90EBA94E75BE}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{FA62F626-EBD5-4dc5-B970-D9E81E0E20E0}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\ServiceModule.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{FA97F7A7-FD19-4D55-ABF2-CFEFFF777426}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{FB469644-3F14-4403-ACCA-6B13486FF7BD}\localserver32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\InvTXTStack.exe /Automation
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{FD51ED8A-D518-4554-B236-B6E9D234FD03}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{FD703B01-4362-423E-9BDB-91BDCB16C1C9}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\DTInterop.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{FE054BB2-AF94-40AC-88AA-2F59F7018B1D}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{FE317223-8EDE-4684-B424-E48B9EA90220}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{FE718E8F-C3AA-4F30-9103-432450CF1DA1}\InprocServer32 -> axdb.dll
ContextMenuHandlers6_S-1-5-21-3289118944-4034126387-1954186238-1000: [InventorMenu] -> {6FDE7A70-351B-11d6-988B-0010B57A8BB7} => C:\Program Files\Autodesk\Inventor 2016\Bin\DtBridge.dll
emptytemp:
End::
  • Click Fix
  • When completed he tool will create a log on the desktop called Fixlog.txt. Please copy and paste the contents of the file in your reply.
===================================================

Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it. :thumbsup2:
  • McAfee uninstall?
  • AdwCleaner log
  • Fixlog
  • Update on compute performance

Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#7 Dustint

Dustint
  • Topic Starter

  • Members
  • 26 posts
  • OFFLINE
  •  
  • Local time:09:50 PM

Posted 27 January 2018 - 07:35 PM

Hi Gary, 

Did my best to run your suggestions. I used Revo Uninstaller to uninstall the 3 McAfee programs. There were some files that the uninstaller said that would be removed after restarting the computer. I assume this happened. While the programs were being uninstalled several windows kept popping up advising me not to uninstall. I killed the windows as they popped-up. AdwCleaner seemed to run fine and restarted the computer. When I ran the FRST an error popped up that read:

 

AutoIt Error

Line 19381 (File "C:\user\Teschke\Desktop\FRST64.EXE"):

Error: Variable used without being declared.

 

Everything seems to be working pretty well at this moment running in normal mode.

3 logs were created: an adwclean log, fixlog and a log named "kdvymdtevibxseqc.txt". Not sure which program created the 3rd log file but i'll attach as well

 

Here's the logs:

 

 # AdwCleaner 7.0.7.0 - Logfile created on Sat Jan 27 23:57:38 2018

# Updated on 2018/18/01 by Malwarebytes 
# Database: 01-26-2018.4
# Running on Windows 7 Home Premium (X64)
# Mode: scan
 
***** [ Services ] *****
 
No malicious services found.
 
***** [ Folders ] *****
 
PUP.Optional.Legacy, C:\Users\Teschke\AppData\Local\Hola
PUP.Optional.Legacy, C:\Users\Teschke\AppData\Roaming\Hola
PUP.Optional.Legacy, C:\Users\Teschke\AppData\Local\Temp\AirInstaller
 
 
***** [ Files ] *****
 
No malicious files found.
 
***** [ DLL ] *****
 
No malicious DLLs found.
 
***** [ WMI ] *****
 
No malicious WMI found.
 
***** [ Shortcuts ] *****
 
No malicious shortcuts found.
 
***** [ Tasks ] *****
 
No malicious tasks found.
 
***** [ Registry ] *****
 
PUP.Optional.PCOptimizerPro, [Key] - HKU\S-1-5-21-3289118944-4034126387-1954186238-1000\Software\Optimizer Pro
PUP.Optional.PCOptimizerPro, [Key] - HKCU\Software\Optimizer Pro
PUP.Optional.Legacy, [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\ak.staticimgfarm.com
PUP.Optional.Legacy, [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\ask.com
PUP.Optional.Legacy, [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\azlyrics.com
PUP.Optional.Legacy, [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\cloudfront.net
PUP.Optional.Legacy, [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\d10lpsik1i8c69.cloudfront.net
PUP.Optional.Legacy, [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\d160accw6snlyf.cloudfront.net
PUP.Optional.Legacy, [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\d16fk4ms6rqz1v.cloudfront.net
PUP.Optional.Legacy, [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\d1af033869koo7.cloudfront.net
PUP.Optional.Legacy, [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\d22j4fzzszoii2.cloudfront.net
PUP.Optional.Legacy, [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\d2m2wsoho8qq12.cloudfront.net
PUP.Optional.Legacy, [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\d3jdlwnuo8nsnr.cloudfront.net
PUP.Optional.Legacy, [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\d3l3lkinz3f56t.cloudfront.net
PUP.Optional.Legacy, [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\dotomi.com
PUP.Optional.Legacy, [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\driverupdate.net
PUP.Optional.Legacy, [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\getflightinfo.dl.tb.ask.com
PUP.Optional.Legacy, [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\metrolyrics.com
PUP.Optional.Legacy, [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\movshare.net
PUP.Optional.Legacy, [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\staticimgfarm.com
PUP.Optional.Legacy, [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\veoh.com
PUP.Optional.Legacy, [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.ask.com
PUP.Optional.Legacy, [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.azlyrics.com
PUP.Optional.Legacy, [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.metrolyrics.com
PUP.Optional.Legacy, [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.movshare.net
PUP.Optional.Legacy, [Key] - HKU\S-1-5-21-3289118944-4034126387-1954186238-1000\Software\Hola
PUP.Optional.Legacy, [Key] - HKCU\Software\Hola
PUP.Optional.Legacy, [Key] - HKCU\Software\MozillaPlugins\@hola.org\vlc
PUP.Optional.Legacy, [Key] - HKCU\Software\MozillaPlugins\@hola.org\FlashPlayer
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\MozillaPlugins\@pandonetworks.com\PandoWebPlugin
PUP.Optional.Legacy, [Key] - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\hola.org
PUP.Optional.SofTonicAssistant, [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\download-free-music.en.softonic.com
PUP.Optional.SofTonicAssistant, [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\en.softonic.com
PUP.Optional.SofTonicAssistant, [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\softonic.com
PUP.Optional.Conduit, [Key] - HKU\S-1-5-21-3289118944-4034126387-1954186238-1000\Software\Conduit
PUP.Optional.Conduit, [Key] - HKCU\Software\Conduit
 
 
***** [ Firefox (and derivatives) ] *****
 
No malicious Firefox entries.
 
***** [ Chromium (and derivatives) ] *****
 
PUP.Optional.Legacy, Plugin found: Battlefield Play4Free - 
 
/!\ Please Reset the Chrome Synchronization before cleaning the Chrome Preferences: https://support.google.com/chrome/answer/3097271 
 
 
*************************
 
 
 
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt ##########
 
Fix result of Farbar Recovery Scan Tool (x64) Version: 27.01.2018
Ran by Teschke (27-01-2018 19:06:31) Run:1
Running from C:\Users\Teschke\Desktop
Loaded Profiles: Teschke (Available Profiles: Teschke & Admin)
Boot Mode: Normal
==============================================
 
fixlist content:
*****************
CreateRestorePoint:
CloseProcesses:
URLSearchHook: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000 - (No Name) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - No File
2014-01-05 01:00 - 2014-01-05 01:00 - 000003584 _____ ()
C:\Users\Teschke\AppData\Local\Temp\2supyjld.dll
2013-04-27 10:50 - 2013-04-27 10:50 - 000263186 _____ () C:\Users\Teschke\AppData\Local\Temp\air97CE.exe
2013-05-25 15:00 - 2013-05-25 15:00 - 000263186 _____ () C:\Users\Teschke\AppData\Local\Temp\airAA45.exe
2016-09-23 19:22 - 2016-09-23 19:26 - 083528440 _____ () C:\Users\Teschke\AppData\Local\Temp\mpa03944.exe
2013-08-03 23:47 - 2013-08-03 23:47 - 000008192 _____ () C:\Users\Teschke\AppData\Local\Temp\odn6esre.dll
2013-07-21 00:00 - 2013-07-21 00:00 - 000003584 _____ () C:\Users\Teschke\AppData\Local\Temp\q64mjujk.dll
2015-10-02 15:18 - 2016-01-10 18:25 - 013110615 _____ (Acresso Software Inc.) C:\Users\Teschke\AppData\Local\Temp\ubi444B.tmp.exe
2016-01-13 16:46 - 2016-01-14 16:47 - 004004004 _____ (Acresso Software Inc.) C:\Users\Teschke\AppData\Local\Temp\ubiEDD6.tmp.exe
HKU\S-1-5-21-3289118944-4034126387-1954186238-1000\...\ChromeHTML: ->  <==== ATTENTION
CustomCLSID:
HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{00F064D8-FEC3-48ac-B07D-39C314D1727B}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\ServiceModule.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{0215A4C0-5431-4FD0-9B06-46589B5C4939}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{048ED0E0-12CF-4C0F-9FFA-947C2FBE8C8E}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{071339A1-1946-44B2-B63E-50459B15DB86}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{073CB204-6B29-46FC-AB98-451F1D068741}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\TestServer.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{08A60FF7-BB37-44F4-9759-0ADA6C7B9CC9}\InprocServer32 -> axdb.dll
CustomCLSID:
HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{0B38CACA-3D3C-48EA-BEB5-7D95F4F6EE15}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{0C3393F8-94F5-4B79-8C01-49A2D0CC0FE9}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{0D555CE0-304A-47A6-858B-B145209A3982}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{12545889-6D32-4424-9967-1E1D7BD1F809}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{13009989-EFB5-48C9-8BD2-943E0392BD71}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\RxAppCtrl.Ocx
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{14679E3B-C952-4998-8E13-4B1286E6DD99}\InprocServer32 -> axdb.dll
CustomCLSID:
HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{1481B385-759A-4B00-9257-E96357563999}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{162EF0A1-5A33-46F2-ACCF-CA388B084A09}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{18A21864-E37B-42b9-9612-2C1E8C450A29}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\ServiceModule.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{1D625598-C876-4C51-8EF5-F9D8F96F62AA}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{1D6DFD6A-9E16-435A-9327-6FFEC6BA372F}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{1E5724EA-3423-4BD3-ABD6-46E650D2DC66}\InprocServer32 -> AcETransmit.dll
CustomCLSID:
HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{1E8A29BA-827D-4031-A4A3-AE7999B402F6}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{1EA072EE-57FD-495E-889C-8243C3BDBDBC}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{1FD7F53F-7ED5-439C-9A77-A3821CD09E98}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{20E47D5B-529A-45BD-8E77-BF1A3064A008}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{21DB88B0-BFBF-11D4-8DE6-0010B541CAA8}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\iDrop.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{2709544A-5B24-4F9F-A5DA-CEC7297D3A4E}\InprocServer32 -> axdb.dll
CustomCLSID:
HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{2BCA857B-A18B-4AFA-B183-CC0E49C12058}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{2C74F89E-7421-46B4-BA54-F86F1BD9F237}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{2C7D1157-7D50-4A88-9777-5EBBA3189AB8}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{2F8377FC-50C1-44EF-AB7A-8FF1BB8EA277}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\ServiceModule.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{3497C2EC-5684-4B21-AF74-F6760E0221DC}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{38C8B14E-7879-4DA9-8C3F-8CAAC359293A}\InprocServer32 -> axdb.dll
CustomCLSID:
HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{3FC94EB5-AEBD-4f3f-A2A4-B6CE57113C01}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\RxAppDocView.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{3FCEB42C-9B98-486A-BED7-FD7F3ADB7291}\InprocServer32 -> AcETransmit.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{40770568-0D5E-49D4-BE47-BC47A4F0B0A4}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{44A52280-AE56-490D-890C-89FB7279ED6B}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{45122C53-8483-4b62-B15A-EAA9FE5FC3D5}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\ServiceModule.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{46C56738-39C6-4240-8B9B-008CCD769A84}\InprocServer32 ->
axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{47179DDE-10AC-4737-97C9-8CE5379343EA}\InprocServer32 -> AcETransmit.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{475C7B4A-6964-4F9E-9708-05A16EAC31D0}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{48270F9E-CCF6-4C79-B6FF-267C960E6425}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{48FEFCD7-5D7C-4E4A-9F11-60E69A31D4B1}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{49998808-648A-4A9C-A7A5-B1672775D9AB}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{4A756F5F-CBA4-428B-B17F-AF80C0C8502D}\InprocServer32 -> axdb.dll
CustomCLSID:
HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{4B40437B-8972-4444-BBE3-1588FF55F203}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{4BD03680-3C0F-4501-AFF7-3D008586917F}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{4C80573A-9150-11d2-B772-0060B0F159EF}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\RxAppDocView.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{4D29B490-49B2-11D0-93C3-7E0706000000}\localserver32 -> "C:\Program Files\Autodesk\Inventor 2016\Bin\Inventor.exe"
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{4E6F2E83-E7F0-4333-9772-875EB733C820}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\RxTest.dll
CustomCLSID:
HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{5544903C-2CCC-487C-91BB-F310B72A8E9B}\InprocServer32 -> AcETransmit.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{59A224A2-BEF8-4C89-96E0-83A5411ABB6C}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{622F6193-E4DD-46E6-BC66-2ED88E9FD28D}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{62FBB030-24C7-11D3-B78D-0060B0F159EF}\localserver32 -> "C:\Program Files\Autodesk\Inventor 2016\Bin\Inventor.exe"
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{644190AE-BD8F-493F-B63D-C79404AC5E07}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\ServiceModule.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{6451051B-AD22-4C6A-ACCE-013A0E1DDBC3}\InprocServer32 -> axdb.dll
CustomCLSID:
HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{64B99FDB-1D85-447F-98C7-569DBDA723DB}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{6BCE6F6E-C050-4F39-BD98-E2743949F724}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{6F56D7C9-18DD-4C15-9FA8-C54E3610EC40}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{6FDE7A70-351B-11d6-988B-0010B57A8BB7}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\DtBridge.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{6FDE7A71-351B-11d6-988B-0010B57A8BB7}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\DtBridge.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{6FDE7A72-351B-11d6-988B-0010B57A8BB7}\InprocServer32 -> C:\Program Files\Autodesk\Inventor
2016\Bin\DtBridge.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{6FDE7A73-351B-11d6-988B-0010B57A8BB7}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\DtBridge.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{6FDE7A74-351B-11d6-988B-0010B57A8BB7}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\DtBridge.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{6FDE7A77-351B-11d6-988B-0010B57A8BB7}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\DtCp.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{70DBCAE8-8C2B-450C-9E1D-43E4686C6512}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{713C0E8A-5AE8-4695-B442-5ED6C4FE5C42}\InprocServer32 -> axdb.dll
CustomCLSID:
HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{7293E009-3015-4AD3-96EC-D42C36B5FCE3}\InprocServer32 -> AcETransmit.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{72EC5CC5-88F3-45B1-A865-0A327DF58CC8}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\ServiceModule.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{72EFC580-D085-4B81-8C55-26A79E445338}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{750AEC19-2E4C-4ED9-9B9F-F9CAFCD060F3}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{794199C5-827C-41C8-8CB2-3A1EA056AF5E}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{798391FE-4AF2-4851-9DDA-1F0D70C02A9E}\InprocServer32 -> axdb.dll
CustomCLSID:
HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{7BA16B3F-1AB3-4BD7-B959-52C4B8504EE9}\InprocServer32 -> AcInetUI.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{7C239DAB-BC87-45F3-B7B1-FCC1541A235B}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{81D07C3D-0350-11D3-B7C2-0060B0EC020B}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\RxAppCtrl.Ocx
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{834CE679-2E47-49DE-9E41-FEC87E9192EB}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{8421A29C-54B8-11D1-9837-0060B03C43C8}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\SolidObject.Dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{846217D0-8954-11D2-8DCD-0060B0C32531}\InprocServer32 -> C:\Program
Files\Autodesk\Inventor 2016\Bin\UCxTextBtn.Ocx
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{846217D1-8954-11D2-8DCD-0060B0C32531}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\UCxTextBtn.Ocx
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{849AFB5B-D6C9-4924-A712-F7118FF9611F}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{85452F88-5071-492E-B850-2E3C586DCBD8}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{87F5CF8F-A06D-498F-A05F-E520E6B570DB}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{89F0FC31-3B1D-494B-A75B-6BD4FA527B8A}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{8AA16DFC-DFC6-4B51-8FA2-A5D812BE33BF}\InprocServer32 ->
axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{8B0E6BD9-610C-11D1-9842-0060B03C43C8}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\SolidObject.Dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{8C23B656-4E6E-4B45-9920-9617168D39A3}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\TestServer.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{8ED07FEF-E1B0-4CC3-B2BA-D354828AB952}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{988F4102-E6E3-4282-ACAC-55270827F2A8}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{9906CDFC-DB2C-4126-9422-13139B148495}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{9A21C6C5-27FC-4442-8590-575E7AFD73BB}\InprocServer32 ->
axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{9ECF83FB-23C5-43B6-83DE-93CFBDD74D4A}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{A58F47CC-FF65-4152-B0B1-666C643A5BFC}\InprocServer32 -> AcETransmit.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{A6A3D586-44CF-44C2-A92C-620BB713B4F2}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{ABBE3F83-D585-4A50-9B69-198B0F566F2E}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{AC5CECFA-F03A-41D2-A89C-704C44935941}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{B1560245-190E-4BBD-81DF-9B642D0E5325}\InprocServer32 -> axdb.dll
CustomCLSID:
HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{B2A579E0-A797-40B1-8AEE-A8F6404719F8}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{B47196BC-D4AB-41BB-A771-543D67CFC9F5}\InprocServer32 -> AcETransmit.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{B53CEF4B-1A13-49DE-BBC5-A7100FB2F38C}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{B5EE2B68-9A23-4BCD-BB77-FEA6DFB24DD6}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{B6B5DC40-96E3-11d2-B774-0060B0F159EF}\localserver32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\Inventor.exe /Automation
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{B80687F9-FA4C-4735-9DC4-E5715F2BC698}\InprocServer32 -> axdb.dll
CustomCLSID:
HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{B8E7214B-25CA-4116-84CB-E86FB9625B36}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\ServiceModule.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{BAE5802A-CF21-4F9C-AE04-D98F4036AC31}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{BBF6A206-CB04-479D-96AE-349E1E83319A}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{BC71DEA1-D6FB-48B8-AB06-D151C81BBCDD}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{BE54741D-E02B-4572-93D6-105AF4EDE777}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\ServiceModule.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{BF224DC3-B602-4EEE-BFE9-9E4E0AED6837}\InprocServer32 -> axdb.dll
CustomCLSID:
HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{BF4CC07E-E9BB-40D6-873F-855B211033B9}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{C061C82C-D041-4214-BB07-B608107CEFCB}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{C2D4ACCC-A3D1-4A0A-AD59-0DD8BA3D5EE1}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{C343ED84-A129-11d3-B799-0060B0F159EF}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\RxApprenticeServer.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{C8C18F89-794D-466B-8B97-95634D9890EF}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{C8EC7647-1E79-4F13-81D7-2EED803D0D22}\InprocServer32 -> axdb.dll
CustomCLSID:
HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{C92F8F8C-8B2C-11d4-B872-0060B0EC020B}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\DtBridge.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{CC23CA32-9892-4FBA-A108-FE31CA0F35A6}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{CD865713-70D6-4E15-BB7B-9B99AD9DEB85}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{CFEE2BAF-14F9-4D23-853D-B6E2BCC14263}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\ServiceModule.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{D56F5AB3-9C4D-4F1A-A851-A671D9FE8C22}\InprocServer32 -> AcETransmit.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{D66873EA-AAE5-41CC-8DD2-8CE3228E9F89}\InprocServer32 -> axdb.dll
CustomCLSID:
HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{D7A1987D-4A73-11D1-9A4B-080009DCE505}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\ColorButton.Ocx
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{D7A1987E-4A73-11D1-9A4B-080009DCE505}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\ColorButton.Ocx
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{D86B6C47-11F2-4D95-B635-EA575F0892FC}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{DA1F437C-9BD9-11d4-B87C-0060B0EC020B}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\DtBridge.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{DB207560-8449-4FAF-BDC2-61676EB012D4}\InprocServer32 -> axdb.dll
CustomCLSID:
HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{DB5D476B-3FF4-4E9D-A606-1E2B473BE571}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\AcInetUI.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{DCA7356C-FF94-4b20-AE04-7AA6A8E14117}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\ServiceModule.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{DDA9A20F-5B56-49F5-9465-CE82FC199352}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\ServiceModule.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{DE6B563C-B074-4BF1-A8A0-B3FED8703E99}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\ServiceModule.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{DE74F5AD-DA2F-429F-BAF9-850A2808D585}\InprocServer32 -> axdb.dll
CustomCLSID:
HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{DF6525C2-6358-4B07-813D-708120C5FE1A}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{E177A457-9EAA-43C3-A3CE-84874A28F6CA}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{E1C85E9F-60B2-4007-80C3-2C5E09474C3B}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\RxInventorUtilities.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{E29F6C45-6927-4508-8F3F-34105FD3FC5F}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{E4222C78-3670-4BB1-9AD4-7D8F3E581F2D}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{E5B0515D-48D2-4F04-906D-0192ED65A2DD}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\TestServer.dll
CustomCLSID:
HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{E70DE962-842A-4488-9481-1D0FD72A020F}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{E9C07CEC-7B82-49E4-BBA2-7533B88E9D64}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{EA34A0C0-5CE7-4701-A6FA-117D25CD5EBB}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{EF01D98A-747B-4522-AD70-991B90855DBF}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{F13E75B9-6AF6-49CB-80B3-6D2FF6E09932}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\ServiceModule.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{F196F03F-651A-43AF-BE34-D11942F24445}\InprocServer32 -> axdb.dll
CustomCLSID:
HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{F2D4F4E5-EEA1-46FF-A83B-A270C92DAE4B}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\DTInterop.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{F2DB0EE3-7137-4CB0-8349-483C4FF2143A}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{F40E2FF0-4D77-40B2-9A44-A3AEECCE8EFF}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{F5522F0C-962A-48AC-9992-E81B07628F1F}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{F61064CC-DBFB-47ee-9BC8-CA5A1CBDF0DA}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\InvResc.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{F78DCF7C-043D-45FC-9D21-676FC307BA3F}\InprocServer32 -> axdb.dll
CustomCLSID:
HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{F868EAEC-1B73-4F5E-BA73-90EBA94E75BE}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{FA62F626-EBD5-4dc5-B970-D9E81E0E20E0}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\ServiceModule.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{FA97F7A7-FD19-4D55-ABF2-CFEFFF777426}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{FB469644-3F14-4403-ACCA-6B13486FF7BD}\localserver32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\InvTXTStack.exe /Automation
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{FD51ED8A-D518-4554-B236-B6E9D234FD03}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{FD703B01-4362-423E-9BDB-91BDCB16C1C9}\InprocServer32 -> C:\Program
Files\Autodesk\Inventor 2016\Bin\DTInterop.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{FE054BB2-AF94-40AC-88AA-2F59F7018B1D}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{FE317223-8EDE-4684-B424-E48B9EA90220}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{FE718E8F-C3AA-4F30-9103-432450CF1DA1}\InprocServer32 -> axdb.dll
ContextMenuHandlers6_S-1-5-21-3289118944-4034126387-1954186238-1000: [InventorMenu] -> {6FDE7A70-351B-11d6-988B-0010B57A8BB7} => C:\Program Files\Autodesk\Inventor 2016\Bin\DtBridge.dll
emptytemp:
 
*****************
 
Restore point was successfully created.
Processes closed successfully.
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000\Software\Microsoft\Internet Explorer\URLSearchHooks\\{0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064}" => removed successfully
"2014-01-05 01:00 - 2014-01-05 01:00 - 000003584 _____ ()" => not found
C:\Users\Teschke\AppData\Local\Temp\2supyjld.dll => moved successfully
C:\Users\Teschke\AppData\Local\Temp\air97CE.exe => moved successfully
C:\Users\Teschke\AppData\Local\Temp\airAA45.exe => moved successfully
C:\Users\Teschke\AppData\Local\Temp\mpa03944.exe => moved successfully
C:\Users\Teschke\AppData\Local\Temp\odn6esre.dll => moved successfully
C:\Users\Teschke\AppData\Local\Temp\q64mjujk.dll => moved successfully
C:\Users\Teschke\AppData\Local\Temp\ubi444B.tmp.exe => moved successfully
C:\Users\Teschke\AppData\Local\Temp\ubiEDD6.tmp.exe => moved successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\ChromeHTML" => removed successfully
CustomCLSID: => key could not remove.: incorrect path. 
HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{00F064D8-FEC3-48ac-B07D-39C314D1727B}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\ServiceModule.dll => Error: No automatic fix found for this entry.
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{0215A4C0-5431-4FD0-9B06-46589B5C4939}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{048ED0E0-12CF-4C0F-9FFA-947C2FBE8C8E}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{071339A1-1946-44B2-B63E-50459B15DB86}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{073CB204-6B29-46FC-AB98-451F1D068741}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{08A60FF7-BB37-44F4-9759-0ADA6C7B9CC9}" => removed successfully
CustomCLSID: => key could not remove.: incorrect path. 
HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{0B38CACA-3D3C-48EA-BEB5-7D95F4F6EE15}\InprocServer32 -> axdb.dll => Error: No automatic fix found for this entry.
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{0C3393F8-94F5-4B79-8C01-49A2D0CC0FE9}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{0D555CE0-304A-47A6-858B-B145209A3982}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{12545889-6D32-4424-9967-1E1D7BD1F809}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{13009989-EFB5-48C9-8BD2-943E0392BD71}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{14679E3B-C952-4998-8E13-4B1286E6DD99}" => removed successfully
CustomCLSID: => key could not remove.: incorrect path. 
HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{1481B385-759A-4B00-9257-E96357563999}\InprocServer32 -> axdb.dll => Error: No automatic fix found for this entry.
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{162EF0A1-5A33-46F2-ACCF-CA388B084A09}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{18A21864-E37B-42b9-9612-2C1E8C450A29}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{1D625598-C876-4C51-8EF5-F9D8F96F62AA}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{1D6DFD6A-9E16-435A-9327-6FFEC6BA372F}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{1E5724EA-3423-4BD3-ABD6-46E650D2DC66}" => removed successfully
CustomCLSID: => key could not remove.: incorrect path. 
HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{1E8A29BA-827D-4031-A4A3-AE7999B402F6}\InprocServer32 -> axdb.dll => Error: No automatic fix found for this entry.
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{1EA072EE-57FD-495E-889C-8243C3BDBDBC}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{1FD7F53F-7ED5-439C-9A77-A3821CD09E98}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{20E47D5B-529A-45BD-8E77-BF1A3064A008}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{21DB88B0-BFBF-11D4-8DE6-0010B541CAA8}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{2709544A-5B24-4F9F-A5DA-CEC7297D3A4E}" => removed successfully
CustomCLSID: => key could not remove.: incorrect path. 
HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{2BCA857B-A18B-4AFA-B183-CC0E49C12058}\InprocServer32 -> axdb.dll => Error: No automatic fix found for this entry.
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{2C74F89E-7421-46B4-BA54-F86F1BD9F237}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{2C7D1157-7D50-4A88-9777-5EBBA3189AB8}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{2F8377FC-50C1-44EF-AB7A-8FF1BB8EA277}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{3497C2EC-5684-4B21-AF74-F6760E0221DC}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{38C8B14E-7879-4DA9-8C3F-8CAAC359293A}" => removed successfully
CustomCLSID: => key could not remove.: incorrect path. 
HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{3FC94EB5-AEBD-4f3f-A2A4-B6CE57113C01}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\RxAppDocView.dll => Error: No automatic fix found for this entry.
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{3FCEB42C-9B98-486A-BED7-FD7F3ADB7291}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{40770568-0D5E-49D4-BE47-BC47A4F0B0A4}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{44A52280-AE56-490D-890C-89FB7279ED6B}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{45122C53-8483-4b62-B15A-EAA9FE5FC3D5}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{46C56738-39C6-4240-8B9B-008CCD769A84}" => removed successfully
axdb.dll => Error: No automatic fix found for this entry.
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{47179DDE-10AC-4737-97C9-8CE5379343EA}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{475C7B4A-6964-4F9E-9708-05A16EAC31D0}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{48270F9E-CCF6-4C79-B6FF-267C960E6425}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{48FEFCD7-5D7C-4E4A-9F11-60E69A31D4B1}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{49998808-648A-4A9C-A7A5-B1672775D9AB}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{4A756F5F-CBA4-428B-B17F-AF80C0C8502D}" => removed successfully
CustomCLSID: => key could not remove.: incorrect path. 
HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{4B40437B-8972-4444-BBE3-1588FF55F203}\InprocServer32 -> axdb.dll => Error: No automatic fix found for this entry.
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{4BD03680-3C0F-4501-AFF7-3D008586917F}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{4C80573A-9150-11d2-B772-0060B0F159EF}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{4D29B490-49B2-11D0-93C3-7E0706000000}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{4E6F2E83-E7F0-4333-9772-875EB733C820}" => removed successfully
CustomCLSID: => key could not remove.: incorrect path. 
HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{5544903C-2CCC-487C-91BB-F310B72A8E9B}\InprocServer32 -> AcETransmit.dll => Error: No automatic fix found for this entry.
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{59A224A2-BEF8-4C89-96E0-83A5411ABB6C}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{622F6193-E4DD-46E6-BC66-2ED88E9FD28D}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{62FBB030-24C7-11D3-B78D-0060B0F159EF}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{644190AE-BD8F-493F-B63D-C79404AC5E07}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{6451051B-AD22-4C6A-ACCE-013A0E1DDBC3}" => removed successfully
CustomCLSID: => key could not remove.: incorrect path. 
HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{64B99FDB-1D85-447F-98C7-569DBDA723DB}\InprocServer32 -> axdb.dll => Error: No automatic fix found for this entry.
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{6BCE6F6E-C050-4F39-BD98-E2743949F724}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{6F56D7C9-18DD-4C15-9FA8-C54E3610EC40}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{6FDE7A70-351B-11d6-988B-0010B57A8BB7}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{6FDE7A71-351B-11d6-988B-0010B57A8BB7}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{6FDE7A72-351B-11d6-988B-0010B57A8BB7}" => removed successfully
2016\Bin\DtBridge.dll => Error: No automatic fix found for this entry.
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{6FDE7A73-351B-11d6-988B-0010B57A8BB7}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{6FDE7A74-351B-11d6-988B-0010B57A8BB7}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{6FDE7A77-351B-11d6-988B-0010B57A8BB7}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{70DBCAE8-8C2B-450C-9E1D-43E4686C6512}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{713C0E8A-5AE8-4695-B442-5ED6C4FE5C42}" => removed successfully
CustomCLSID: => key could not remove.: incorrect path. 
HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{7293E009-3015-4AD3-96EC-D42C36B5FCE3}\InprocServer32 -> AcETransmit.dll => Error: No automatic fix found for this entry.
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{72EC5CC5-88F3-45B1-A865-0A327DF58CC8}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{72EFC580-D085-4B81-8C55-26A79E445338}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{750AEC19-2E4C-4ED9-9B9F-F9CAFCD060F3}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{794199C5-827C-41C8-8CB2-3A1EA056AF5E}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{798391FE-4AF2-4851-9DDA-1F0D70C02A9E}" => removed successfully
CustomCLSID: => key could not remove.: incorrect path. 
HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{7BA16B3F-1AB3-4BD7-B959-52C4B8504EE9}\InprocServer32 -> AcInetUI.dll => Error: No automatic fix found for this entry.
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{7C239DAB-BC87-45F3-B7B1-FCC1541A235B}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{81D07C3D-0350-11D3-B7C2-0060B0EC020B}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{834CE679-2E47-49DE-9E41-FEC87E9192EB}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{8421A29C-54B8-11D1-9837-0060B03C43C8}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{846217D0-8954-11D2-8DCD-0060B0C32531}" => removed successfully
Files\Autodesk\Inventor 2016\Bin\UCxTextBtn.Ocx => Error: No automatic fix found for this entry.
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{846217D1-8954-11D2-8DCD-0060B0C32531}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{849AFB5B-D6C9-4924-A712-F7118FF9611F}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{85452F88-5071-492E-B850-2E3C586DCBD8}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{87F5CF8F-A06D-498F-A05F-E520E6B570DB}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{89F0FC31-3B1D-494B-A75B-6BD4FA527B8A}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{8AA16DFC-DFC6-4B51-8FA2-A5D812BE33BF}" => removed successfully
axdb.dll => Error: No automatic fix found for this entry.
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{8B0E6BD9-610C-11D1-9842-0060B03C43C8}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{8C23B656-4E6E-4B45-9920-9617168D39A3}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{8ED07FEF-E1B0-4CC3-B2BA-D354828AB952}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{988F4102-E6E3-4282-ACAC-55270827F2A8}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{9906CDFC-DB2C-4126-9422-13139B148495}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{9A21C6C5-27FC-4442-8590-575E7AFD73BB}" => removed successfully
axdb.dll => Error: No automatic fix found for this entry.
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{9ECF83FB-23C5-43B6-83DE-93CFBDD74D4A}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{A58F47CC-FF65-4152-B0B1-666C643A5BFC}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{A6A3D586-44CF-44C2-A92C-620BB713B4F2}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{ABBE3F83-D585-4A50-9B69-198B0F566F2E}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{AC5CECFA-F03A-41D2-A89C-704C44935941}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{B1560245-190E-4BBD-81DF-9B642D0E5325}" => removed successfully
CustomCLSID: => key could not remove.: incorrect path. 
HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{B2A579E0-A797-40B1-8AEE-A8F6404719F8}\InprocServer32 -> axdb.dll => Error: No automatic fix found for this entry.
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{B47196BC-D4AB-41BB-A771-543D67CFC9F5}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{B53CEF4B-1A13-49DE-BBC5-A7100FB2F38C}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{B5EE2B68-9A23-4BCD-BB77-FEA6DFB24DD6}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{B6B5DC40-96E3-11d2-B774-0060B0F159EF}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{B80687F9-FA4C-4735-9DC4-E5715F2BC698}" => removed successfully
CustomCLSID: => key could not remove.: incorrect path. 
HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{B8E7214B-25CA-4116-84CB-E86FB9625B36}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\ServiceModule.dll => Error: No automatic fix found for this entry.
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{BAE5802A-CF21-4F9C-AE04-D98F4036AC31}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{BBF6A206-CB04-479D-96AE-349E1E83319A}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{BC71DEA1-D6FB-48B8-AB06-D151C81BBCDD}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{BE54741D-E02B-4572-93D6-105AF4EDE777}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{BF224DC3-B602-4EEE-BFE9-9E4E0AED6837}" => removed successfully
CustomCLSID: => key could not remove.: incorrect path. 
HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{BF4CC07E-E9BB-40D6-873F-855B211033B9}\InprocServer32 -> axdb.dll => Error: No automatic fix found for this entry.
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{C061C82C-D041-4214-BB07-B608107CEFCB}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{C2D4ACCC-A3D1-4A0A-AD59-0DD8BA3D5EE1}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{C343ED84-A129-11d3-B799-0060B0F159EF}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{C8C18F89-794D-466B-8B97-95634D9890EF}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{C8EC7647-1E79-4F13-81D7-2EED803D0D22}" => removed successfully
CustomCLSID: => key could not remove.: incorrect path. 
HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{C92F8F8C-8B2C-11d4-B872-0060B0EC020B}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\DtBridge.dll => Error: No automatic fix found for this entry.
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{CC23CA32-9892-4FBA-A108-FE31CA0F35A6}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{CD865713-70D6-4E15-BB7B-9B99AD9DEB85}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{CFEE2BAF-14F9-4D23-853D-B6E2BCC14263}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{D56F5AB3-9C4D-4F1A-A851-A671D9FE8C22}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{D66873EA-AAE5-41CC-8DD2-8CE3228E9F89}" => removed successfully
CustomCLSID: => key could not remove.: incorrect path. 
HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{D7A1987D-4A73-11D1-9A4B-080009DCE505}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\ColorButton.Ocx => Error: No automatic fix found for this entry.
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{D7A1987E-4A73-11D1-9A4B-080009DCE505}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{D86B6C47-11F2-4D95-B635-EA575F0892FC}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{DA1F437C-9BD9-11d4-B87C-0060B0EC020B}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{DB207560-8449-4FAF-BDC2-61676EB012D4}" => removed successfully
CustomCLSID: => key could not remove.: incorrect path. 
HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{DB5D476B-3FF4-4E9D-A606-1E2B473BE571}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\AcInetUI.dll => Error: No automatic fix found for this entry.
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{DCA7356C-FF94-4b20-AE04-7AA6A8E14117}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{DDA9A20F-5B56-49F5-9465-CE82FC199352}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{DE6B563C-B074-4BF1-A8A0-B3FED8703E99}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{DE74F5AD-DA2F-429F-BAF9-850A2808D585}" => removed successfully
CustomCLSID: => key could not remove.: incorrect path. 
HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{DF6525C2-6358-4B07-813D-708120C5FE1A}\InprocServer32 -> axdb.dll => Error: No automatic fix found for this entry.
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{E177A457-9EAA-43C3-A3CE-84874A28F6CA}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{E1C85E9F-60B2-4007-80C3-2C5E09474C3B}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{E29F6C45-6927-4508-8F3F-34105FD3FC5F}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{E4222C78-3670-4BB1-9AD4-7D8F3E581F2D}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{E5B0515D-48D2-4F04-906D-0192ED65A2DD}" => removed successfully
CustomCLSID: => key could not remove.: incorrect path. 
HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{E70DE962-842A-4488-9481-1D0FD72A020F}\InprocServer32 -> axdb.dll => Error: No automatic fix found for this entry.
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{E9C07CEC-7B82-49E4-BBA2-7533B88E9D64}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{EA34A0C0-5CE7-4701-A6FA-117D25CD5EBB}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{EF01D98A-747B-4522-AD70-991B90855DBF}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{F13E75B9-6AF6-49CB-80B3-6D2FF6E09932}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{F196F03F-651A-43AF-BE34-D11942F24445}" => removed successfully
CustomCLSID: => key could not remove.: incorrect path. 
HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{F2D4F4E5-EEA1-46FF-A83B-A270C92DAE4B}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\DTInterop.dll => Error: No automatic fix found for this entry.
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{F2DB0EE3-7137-4CB0-8349-483C4FF2143A}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{F40E2FF0-4D77-40B2-9A44-A3AEECCE8EFF}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{F5522F0C-962A-48AC-9992-E81B07628F1F}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{F61064CC-DBFB-47ee-9BC8-CA5A1CBDF0DA}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{F78DCF7C-043D-45FC-9D21-676FC307BA3F}" => removed successfully
CustomCLSID: => key could not remove.: incorrect path. 
HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{F868EAEC-1B73-4F5E-BA73-90EBA94E75BE}\InprocServer32 -> axdb.dll => Error: No automatic fix found for this entry.
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{FA62F626-EBD5-4dc5-B970-D9E81E0E20E0}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{FA97F7A7-FD19-4D55-ABF2-CFEFFF777426}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{FB469644-3F14-4403-ACCA-6B13486FF7BD}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{FD51ED8A-D518-4554-B236-B6E9D234FD03}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{FD703B01-4362-423E-9BDB-91BDCB16C1C9}" => removed successfully
Files\Autodesk\Inventor 2016\Bin\DTInterop.dll => Error: No automatic fix found for this entry.
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{FE054BB2-AF94-40AC-88AA-2F59F7018B1D}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{FE317223-8EDE-4684-B424-E48B9EA90220}" => removed successfully
"HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{FE718E8F-C3AA-4F30-9103-432450CF1DA1}" => removed successfully
 
 
CreateRestorePoint:
CloseProcesses:
URLSearchHook: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000 - (No Name) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - No File
2014-01-05 01:00 - 2014-01-05 01:00 - 000003584 _____ ()
C:\Users\Teschke\AppData\Local\Temp\2supyjld.dll
2013-04-27 10:50 - 2013-04-27 10:50 - 000263186 _____ () C:\Users\Teschke\AppData\Local\Temp\air97CE.exe
2013-05-25 15:00 - 2013-05-25 15:00 - 000263186 _____ () C:\Users\Teschke\AppData\Local\Temp\airAA45.exe
2016-09-23 19:22 - 2016-09-23 19:26 - 083528440 _____ () C:\Users\Teschke\AppData\Local\Temp\mpa03944.exe
2013-08-03 23:47 - 2013-08-03 23:47 - 000008192 _____ () C:\Users\Teschke\AppData\Local\Temp\odn6esre.dll
2013-07-21 00:00 - 2013-07-21 00:00 - 000003584 _____ () C:\Users\Teschke\AppData\Local\Temp\q64mjujk.dll
2015-10-02 15:18 - 2016-01-10 18:25 - 013110615 _____ (Acresso Software Inc.) C:\Users\Teschke\AppData\Local\Temp\ubi444B.tmp.exe
2016-01-13 16:46 - 2016-01-14 16:47 - 004004004 _____ (Acresso Software Inc.) C:\Users\Teschke\AppData\Local\Temp\ubiEDD6.tmp.exe
HKU\S-1-5-21-3289118944-4034126387-1954186238-1000\...\ChromeHTML: ->  <==== ATTENTION
CustomCLSID:
HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{00F064D8-FEC3-48ac-B07D-39C314D1727B}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\ServiceModule.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{0215A4C0-5431-4FD0-9B06-46589B5C4939}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{048ED0E0-12CF-4C0F-9FFA-947C2FBE8C8E}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{071339A1-1946-44B2-B63E-50459B15DB86}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{073CB204-6B29-46FC-AB98-451F1D068741}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\TestServer.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{08A60FF7-BB37-44F4-9759-0ADA6C7B9CC9}\InprocServer32 -> axdb.dll
CustomCLSID:
HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{0B38CACA-3D3C-48EA-BEB5-7D95F4F6EE15}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{0C3393F8-94F5-4B79-8C01-49A2D0CC0FE9}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{0D555CE0-304A-47A6-858B-B145209A3982}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{12545889-6D32-4424-9967-1E1D7BD1F809}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{13009989-EFB5-48C9-8BD2-943E0392BD71}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\RxAppCtrl.Ocx
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{14679E3B-C952-4998-8E13-4B1286E6DD99}\InprocServer32 -> axdb.dll
CustomCLSID:
HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{1481B385-759A-4B00-9257-E96357563999}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{162EF0A1-5A33-46F2-ACCF-CA388B084A09}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{18A21864-E37B-42b9-9612-2C1E8C450A29}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\ServiceModule.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{1D625598-C876-4C51-8EF5-F9D8F96F62AA}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{1D6DFD6A-9E16-435A-9327-6FFEC6BA372F}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{1E5724EA-3423-4BD3-ABD6-46E650D2DC66}\InprocServer32 -> AcETransmit.dll
CustomCLSID:
HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{1E8A29BA-827D-4031-A4A3-AE7999B402F6}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{1EA072EE-57FD-495E-889C-8243C3BDBDBC}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{1FD7F53F-7ED5-439C-9A77-A3821CD09E98}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{20E47D5B-529A-45BD-8E77-BF1A3064A008}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{21DB88B0-BFBF-11D4-8DE6-0010B541CAA8}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\iDrop.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{2709544A-5B24-4F9F-A5DA-CEC7297D3A4E}\InprocServer32 -> axdb.dll
CustomCLSID:
HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{2BCA857B-A18B-4AFA-B183-CC0E49C12058}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{2C74F89E-7421-46B4-BA54-F86F1BD9F237}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{2C7D1157-7D50-4A88-9777-5EBBA3189AB8}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{2F8377FC-50C1-44EF-AB7A-8FF1BB8EA277}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\ServiceModule.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{3497C2EC-5684-4B21-AF74-F6760E0221DC}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{38C8B14E-7879-4DA9-8C3F-8CAAC359293A}\InprocServer32 -> axdb.dll
CustomCLSID:
HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{3FC94EB5-AEBD-4f3f-A2A4-B6CE57113C01}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\RxAppDocView.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{3FCEB42C-9B98-486A-BED7-FD7F3ADB7291}\InprocServer32 -> AcETransmit.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{40770568-0D5E-49D4-BE47-BC47A4F0B0A4}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{44A52280-AE56-490D-890C-89FB7279ED6B}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{45122C53-8483-4b62-B15A-EAA9FE5FC3D5}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\ServiceModule.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{46C56738-39C6-4240-8B9B-008CCD769A84}\InprocServer32 ->
axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{47179DDE-10AC-4737-97C9-8CE5379343EA}\InprocServer32 -> AcETransmit.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{475C7B4A-6964-4F9E-9708-05A16EAC31D0}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{48270F9E-CCF6-4C79-B6FF-267C960E6425}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{48FEFCD7-5D7C-4E4A-9F11-60E69A31D4B1}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{49998808-648A-4A9C-A7A5-B1672775D9AB}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{4A756F5F-CBA4-428B-B17F-AF80C0C8502D}\InprocServer32 -> axdb.dll
CustomCLSID:
HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{4B40437B-8972-4444-BBE3-1588FF55F203}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{4BD03680-3C0F-4501-AFF7-3D008586917F}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{4C80573A-9150-11d2-B772-0060B0F159EF}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\RxAppDocView.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{4D29B490-49B2-11D0-93C3-7E0706000000}\localserver32 -> "C:\Program Files\Autodesk\Inventor 2016\Bin\Inventor.exe"
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{4E6F2E83-E7F0-4333-9772-875EB733C820}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\RxTest.dll
CustomCLSID:
HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{5544903C-2CCC-487C-91BB-F310B72A8E9B}\InprocServer32 -> AcETransmit.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{59A224A2-BEF8-4C89-96E0-83A5411ABB6C}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{622F6193-E4DD-46E6-BC66-2ED88E9FD28D}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{62FBB030-24C7-11D3-B78D-0060B0F159EF}\localserver32 -> "C:\Program Files\Autodesk\Inventor 2016\Bin\Inventor.exe"
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{644190AE-BD8F-493F-B63D-C79404AC5E07}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\ServiceModule.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{6451051B-AD22-4C6A-ACCE-013A0E1DDBC3}\InprocServer32 -> axdb.dll
CustomCLSID:
HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{64B99FDB-1D85-447F-98C7-569DBDA723DB}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{6BCE6F6E-C050-4F39-BD98-E2743949F724}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{6F56D7C9-18DD-4C15-9FA8-C54E3610EC40}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{6FDE7A70-351B-11d6-988B-0010B57A8BB7}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\DtBridge.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{6FDE7A71-351B-11d6-988B-0010B57A8BB7}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\DtBridge.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{6FDE7A72-351B-11d6-988B-0010B57A8BB7}\InprocServer32 -> C:\Program Files\Autodesk\Inventor
2016\Bin\DtBridge.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{6FDE7A73-351B-11d6-988B-0010B57A8BB7}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\DtBridge.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{6FDE7A74-351B-11d6-988B-0010B57A8BB7}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\DtBridge.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{6FDE7A77-351B-11d6-988B-0010B57A8BB7}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\DtCp.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{70DBCAE8-8C2B-450C-9E1D-43E4686C6512}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{713C0E8A-5AE8-4695-B442-5ED6C4FE5C42}\InprocServer32 -> axdb.dll
CustomCLSID:
HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{7293E009-3015-4AD3-96EC-D42C36B5FCE3}\InprocServer32 -> AcETransmit.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{72EC5CC5-88F3-45B1-A865-0A327DF58CC8}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\ServiceModule.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{72EFC580-D085-4B81-8C55-26A79E445338}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{750AEC19-2E4C-4ED9-9B9F-F9CAFCD060F3}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{794199C5-827C-41C8-8CB2-3A1EA056AF5E}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{798391FE-4AF2-4851-9DDA-1F0D70C02A9E}\InprocServer32 -> axdb.dll
CustomCLSID:
HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{7BA16B3F-1AB3-4BD7-B959-52C4B8504EE9}\InprocServer32 -> AcInetUI.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{7C239DAB-BC87-45F3-B7B1-FCC1541A235B}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{81D07C3D-0350-11D3-B7C2-0060B0EC020B}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\RxAppCtrl.Ocx
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{834CE679-2E47-49DE-9E41-FEC87E9192EB}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{8421A29C-54B8-11D1-9837-0060B03C43C8}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\SolidObject.Dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{846217D0-8954-11D2-8DCD-0060B0C32531}\InprocServer32 -> C:\Program
Files\Autodesk\Inventor 2016\Bin\UCxTextBtn.Ocx
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{846217D1-8954-11D2-8DCD-0060B0C32531}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\UCxTextBtn.Ocx
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{849AFB5B-D6C9-4924-A712-F7118FF9611F}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{85452F88-5071-492E-B850-2E3C586DCBD8}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{87F5CF8F-A06D-498F-A05F-E520E6B570DB}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{89F0FC31-3B1D-494B-A75B-6BD4FA527B8A}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{8AA16DFC-DFC6-4B51-8FA2-A5D812BE33BF}\InprocServer32 ->
axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{8B0E6BD9-610C-11D1-9842-0060B03C43C8}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\SolidObject.Dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{8C23B656-4E6E-4B45-9920-9617168D39A3}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\TestServer.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{8ED07FEF-E1B0-4CC3-B2BA-D354828AB952}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{988F4102-E6E3-4282-ACAC-55270827F2A8}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{9906CDFC-DB2C-4126-9422-13139B148495}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{9A21C6C5-27FC-4442-8590-575E7AFD73BB}\InprocServer32 ->
axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{9ECF83FB-23C5-43B6-83DE-93CFBDD74D4A}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{A58F47CC-FF65-4152-B0B1-666C643A5BFC}\InprocServer32 -> AcETransmit.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{A6A3D586-44CF-44C2-A92C-620BB713B4F2}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{ABBE3F83-D585-4A50-9B69-198B0F566F2E}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{AC5CECFA-F03A-41D2-A89C-704C44935941}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{B1560245-190E-4BBD-81DF-9B642D0E5325}\InprocServer32 -> axdb.dll
CustomCLSID:
HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{B2A579E0-A797-40B1-8AEE-A8F6404719F8}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{B47196BC-D4AB-41BB-A771-543D67CFC9F5}\InprocServer32 -> AcETransmit.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{B53CEF4B-1A13-49DE-BBC5-A7100FB2F38C}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{B5EE2B68-9A23-4BCD-BB77-FEA6DFB24DD6}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{B6B5DC40-96E3-11d2-B774-0060B0F159EF}\localserver32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\Inventor.exe /Automation
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{B80687F9-FA4C-4735-9DC4-E5715F2BC698}\InprocServer32 -> axdb.dll
CustomCLSID:
HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{B8E7214B-25CA-4116-84CB-E86FB9625B36}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\ServiceModule.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{BAE5802A-CF21-4F9C-AE04-D98F4036AC31}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{BBF6A206-CB04-479D-96AE-349E1E83319A}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{BC71DEA1-D6FB-48B8-AB06-D151C81BBCDD}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{BE54741D-E02B-4572-93D6-105AF4EDE777}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\ServiceModule.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{BF224DC3-B602-4EEE-BFE9-9E4E0AED6837}\InprocServer32 -> axdb.dll
CustomCLSID:
HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{BF4CC07E-E9BB-40D6-873F-855B211033B9}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{C061C82C-D041-4214-BB07-B608107CEFCB}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{C2D4ACCC-A3D1-4A0A-AD59-0DD8BA3D5EE1}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{C343ED84-A129-11d3-B799-0060B0F159EF}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\RxApprenticeServer.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{C8C18F89-794D-466B-8B97-95634D9890EF}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{C8EC7647-1E79-4F13-81D7-2EED803D0D22}\InprocServer32 -> axdb.dll
CustomCLSID:
HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{C92F8F8C-8B2C-11d4-B872-0060B0EC020B}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\DtBridge.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{CC23CA32-9892-4FBA-A108-FE31CA0F35A6}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{CD865713-70D6-4E15-BB7B-9B99AD9DEB85}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{CFEE2BAF-14F9-4D23-853D-B6E2BCC14263}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\ServiceModule.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{D56F5AB3-9C4D-4F1A-A851-A671D9FE8C22}\InprocServer32 -> AcETransmit.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{D66873EA-AAE5-41CC-8DD2-8CE3228E9F89}\InprocServer32 -> axdb.dll
CustomCLSID:
HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{D7A1987D-4A73-11D1-9A4B-080009DCE505}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\ColorButton.Ocx
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{D7A1987E-4A73-11D1-9A4B-080009DCE505}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\ColorButton.Ocx
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{D86B6C47-11F2-4D95-B635-EA575F0892FC}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{DA1F437C-9BD9-11d4-B87C-0060B0EC020B}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\DtBridge.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{DB207560-8449-4FAF-BDC2-61676EB012D4}\InprocServer32 -> axdb.dll
CustomCLSID:
HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{DB5D476B-3FF4-4E9D-A606-1E2B473BE571}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\AcInetUI.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{DCA7356C-FF94-4b20-AE04-7AA6A8E14117}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\ServiceModule.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{DDA9A20F-5B56-49F5-9465-CE82FC199352}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\ServiceModule.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{DE6B563C-B074-4BF1-A8A0-B3FED8703E99}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\ServiceModule.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{DE74F5AD-DA2F-429F-BAF9-850A2808D585}\InprocServer32 -> axdb.dll
CustomCLSID:
HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{DF6525C2-6358-4B07-813D-708120C5FE1A}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{E177A457-9EAA-43C3-A3CE-84874A28F6CA}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{E1C85E9F-60B2-4007-80C3-2C5E09474C3B}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\RxInventorUtilities.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{E29F6C45-6927-4508-8F3F-34105FD3FC5F}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{E4222C78-3670-4BB1-9AD4-7D8F3E581F2D}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{E5B0515D-48D2-4F04-906D-0192ED65A2DD}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\TestServer.dll
CustomCLSID:
HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{E70DE962-842A-4488-9481-1D0FD72A020F}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{E9C07CEC-7B82-49E4-BBA2-7533B88E9D64}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{EA34A0C0-5CE7-4701-A6FA-117D25CD5EBB}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{EF01D98A-747B-4522-AD70-991B90855DBF}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{F13E75B9-6AF6-49CB-80B3-6D2FF6E09932}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\ServiceModule.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{F196F03F-651A-43AF-BE34-D11942F24445}\InprocServer32 -> axdb.dll
CustomCLSID:
HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{F2D4F4E5-EEA1-46FF-A83B-A270C92DAE4B}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\DTInterop.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{F2DB0EE3-7137-4CB0-8349-483C4FF2143A}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{F40E2FF0-4D77-40B2-9A44-A3AEECCE8EFF}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{F5522F0C-962A-48AC-9992-E81B07628F1F}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{F61064CC-DBFB-47ee-9BC8-CA5A1CBDF0DA}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\InvResc.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{F78DCF7C-043D-45FC-9D21-676FC307BA3F}\InprocServer32 -> axdb.dll
CustomCLSID:
HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{F868EAEC-1B73-4F5E-BA73-90EBA94E75BE}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{FA62F626-EBD5-4dc5-B970-D9E81E0E20E0}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\ServiceModule.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{FA97F7A7-FD19-4D55-ABF2-CFEFFF777426}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{FB469644-3F14-4403-ACCA-6B13486FF7BD}\localserver32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\InvTXTStack.exe /Automation
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{FD51ED8A-D518-4554-B236-B6E9D234FD03}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{FD703B01-4362-423E-9BDB-91BDCB16C1C9}\InprocServer32 -> C:\Program
Files\Autodesk\Inventor 2016\Bin\DTInterop.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{FE054BB2-AF94-40AC-88AA-2F59F7018B1D}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{FE317223-8EDE-4684-B424-E48B9EA90220}\InprocServer32 -> axdb.dll
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{FE718E8F-C3AA-4F30-9103-432450CF1DA1}\InprocServer32 -> axdb.dll
ContextMenuHandlers6_S-1-5-21-3289118944-4034126387-1954186238-1000: [InventorMenu] -> {6FDE7A70-351B-11d6-988B-0010B57A8BB7} => C:\Program Files\Autodesk\Inventor 2016\Bin\DtBridge.dll
emptytemp:


#8 Dustint

Dustint
  • Topic Starter

  • Members
  • 26 posts
  • OFFLINE
  •  
  • Local time:09:50 PM

Posted 27 January 2018 - 07:47 PM

Hi Gary, Its me again. Just after I sent you my last post a McAfee window popped up telling me:

 

"we are having trouble restarting real-time scanning. please restart your device to fix the problem"

 

So it looks like it didn't uninstall and its trying to reinstall itself. I wont reboot or do anything with it until I hear from you.



#9 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 36,617 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:07:50 PM

Posted 27 January 2018 - 08:24 PM

OK.

Please run another FRST scan and copy/paste both reports in your reply.
Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#10 Dustint

Dustint
  • Topic Starter

  • Members
  • 26 posts
  • OFFLINE
  •  
  • Local time:09:50 PM

Posted 27 January 2018 - 08:46 PM

OK, ran the FRST scan again. Here is the first log file:

 

 
FireFox:
========
FF DefaultProfile: gd2bren1.default
FF ProfilePath: C:\Users\Teschke\AppData\Roaming\Mozilla\Firefox\Profiles\gd2bren1.default [2017-12-01]
FF Extension: (Firefox Hotfix) - C:\Users\Teschke\AppData\Roaming\Mozilla\Firefox\Profiles\gd2bren1.default\Extensions\firefox-hotfix@mozilla.org.xpi [2016-12-08] [Legacy]
FF HKLM\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor\e10ssaffplg.xpi => not found
FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor\e10ssaffplg.xpi => not found
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_28_0_0_137.dll [2018-01-09] ()
FF Plugin: @garmin.com/GpsControl -> C:\Program Files\Garmin GPS Plugin\npGarmin.dll [2014-03-31] (GARMIN Corp.)
FF Plugin: @mcafee.com/MSC,version=10 -> c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL [2017-07-10] ()
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin: @wacom.com/wtPlugin,version=2.1.0.7 -> C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll [2014-03-25] (Wacom)
FF Plugin: wacom.com/WacomTabletPlugin -> C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll [2014-03-25] (Wacom)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_28_0_0_137.dll [2018-01-09] ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2016-03-08] ()
FF Plugin-x32: @garmin.com/GpsControl -> C:\Program Files (x86)\Garmin GPS Plugin\npGarmin.dll [2014-03-31] (GARMIN Corp.)
FF Plugin-x32: @java.com/DTPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll [2014-10-20] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\plugin2\npjp2.dll [2014-10-20] (Oracle Corporation)
FF Plugin-x32: @mcafee.com/MSC,version=10 -> c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL [2017-07-10] ()
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-14] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-14] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.8 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2013-07-30] (VideoLAN)
FF Plugin-x32: @wacom.com/wtPlugin,version=2.1.0.7 -> C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll [2014-03-25] (Wacom)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2013-05-11] (Adobe Systems Inc.)
FF Plugin-x32: wacom.com/WacomTabletPlugin -> C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll [2014-03-25] (Wacom)
FF Plugin HKU\S-1-5-21-3289118944-4034126387-1954186238-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Teschke\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2015-08-21] (Unity Technologies ApS)
FF Plugin HKU\S-1-5-21-3289118944-4034126387-1954186238-1000: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [2016-01-14] ()
 
Chrome: 
=======
CHR DefaultProfile: Profile 3
CHR HomePage: Profile 3 -> hxxps://www.google.ca/
CHR StartupUrls: Profile 3 -> "hxxp://www.google.ca/"
CHR DefaultSearchURL: Profile 3 -> hxxps://search.yahoo.com/search?fr=mcafee&type=C211US0D20170114&p={searchTerms}
CHR DefaultSearchKeyword: Profile 3 -> mcafee
CHR Profile: C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default [2018-01-27]
CHR Extension: (BeGone Guerra Online) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\ahcchnfnladlkddlceegencfccjcfnjp [2013-09-19]
CHR Extension: (Plants vs. Zombies HD) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\ahdfeknjbgfbkmemaoffkebceonhcjfd [2013-09-19]
CHR Extension: (Beatlab) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\alnfdikmbdfgkcbdodjcbmedanjinmkk [2015-04-20]
CHR Extension: (Google Drive) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-20]
CHR Extension: (UJAM - Make your music.) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdiogojbmdncjdpljocafnigiokgmci [2013-09-19]
CHR Extension: (Free Running 2 3D) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakechaaagjbdhedidbfifkembmkhafl [2013-09-19]
CHR Extension: (BeGone: Last Stand HD) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\bmekbplkjhgmljmbblmhmcnocafhaink [2013-09-19]
CHR Extension: (Battlefield Heroes) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\cehdakiococlfmjcbebbkjkfjhbieknh [2013-09-21]
CHR Extension: (Rush Team) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\ecdnoeebfjlplfkljdedokbcmebojbpb [2013-10-10]
CHR Extension: (Freefall Tournament) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\encjogopgacdjlkmpdknhlfnanoihodh [2015-03-18]
CHR Extension: (Music Maker) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\epnoajccaiifhpidemmcdamilpeblipc [2014-03-27]
CHR Extension: (Google Play Music) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\fahmaaghhglfmonjliepjlchgpgfmobi [2015-11-18]
CHR Extension: (PicMonkey) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\fgdgokchhicmaiacmgegjnppjkgogdhm [2014-10-24]
CHR Extension: (SiteAdvisor) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2015-07-02]
CHR Extension: (Counter Strike Online ) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\fplklihjpkinahlihcljhnnlnhnmmhdp [2013-09-19]
CHR Extension: (Google Docs Offline) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-11-18]
CHR Extension: (Unlimited Free VPN - Hola) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkojfkhlekighikafcpjkiklfbnlmeio [2015-11-28]
CHR Extension: (Happy Wheels) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\hpljdpjoahbnnfilkiilnfdkdbfiabfc [2013-09-19]
CHR Extension: (Apocalypse City) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifkogipjfpemebgfjelkfoifapppddeh [2013-09-19]
CHR Extension: (Digital BeatMaker) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihjdooenciklfgogkejekglpoeedphmc [2014-03-27]
CHR Extension: (90`s Games) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\illbbfoihflomkbpcaaakhijinbnejom [2015-03-14]
CHR Extension: (theHunter) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\jangaedeekciafhlanphhnalogmhefmo [2013-09-19]
CHR Extension: (Super Mario Bros HD) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmhilnfngnmcnlekfgcglogafjkahoml [2013-09-19]
CHR Extension: (Eyes - The Horror Game) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\jojpkokphfnjlhbnbcilnhgnkkobkngd [2013-09-19]
CHR Extension: (Resident Evil) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\kelgpfmgciingekkpfaikcjmcomfikgp [2013-09-19]
CHR Extension: (Aqua Planet) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\kkfobnmhjmjkgojmfldhnkmfcdjjakhb [2013-09-20]
CHR Extension: (Dead Zed Zombie) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\lcdhiflblofckjcpphgcoajnebhbdpja [2013-09-19]
CHR Extension: (Counter-Strike-Online 2) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\liihamdfalaafmojcdakajejmcbnjkce [2013-09-19]
CHR Extension: (Plink) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\loeiekheegipnnbcfbfkanbbegkhjjcm [2013-09-20]
CHR Extension: (Slender Space) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkdmfheflfmedmfjolgifliincdhfgdl [2013-09-19]
CHR Extension: (Mixify) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkjlbfglfefcmkmglakdocbgnggeieno [2014-03-27]
CHR Extension: (Plants vs Zombies) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmcegpfdgcoclcdfkjahiimlikdpnina [2013-09-21]
CHR Extension: (BeGone) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndfpieflbjbdpgklkeolbmbdkfdiicfk [2015-06-27]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-07-23]
CHR Extension: (Mini Ninjas) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\oijfbknbncemokdnlboeabbcfhobechi [2013-09-19]
CHR Extension: (Battlefield Play4Free) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\oiokahphinmbmakkehgelkmpolmnbkdh [2013-09-19]
CHR Profile: C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 1 [2015-11-28]
CHR Extension: (Google Slides) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-11-28]
CHR Extension: (Google Docs) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2015-11-28]
CHR Extension: (Google Drive) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-11-28]
CHR Extension: (YouTube) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-11-28]
CHR Extension: (Google Search) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-11-28]
CHR Extension: (Google Sheets) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-11-28]
CHR Extension: (SiteAdvisor) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2015-11-28]
CHR Extension: (Google Docs Offline) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-11-28]
CHR Extension: (Unlimited Free VPN - Hola) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gkojfkhlekighikafcpjkiklfbnlmeio [2015-11-28]
CHR Extension: (Video Recorder for WeVideo) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\iaiglpeefdoagfbbfhjfbmomnfobojia [2015-11-28]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-11-28]
CHR Extension: (Gmail) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-11-28]
CHR Profile: C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 2 [2015-11-29]
CHR Extension: (Google Slides) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-11-28]
CHR Extension: (Google Docs) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\aohghmighlieiainnegkcijnfilokake [2015-11-28]
CHR Extension: (Google Drive) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-11-28]
CHR Extension: (YouTube) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-11-28]
CHR Extension: (Google Search) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-11-28]
CHR Extension: (MLG-ifier) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\dneebgdgldanagagmfhnphjelnngdcai [2015-11-28]
CHR Extension: (Google Sheets) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-11-28]
CHR Extension: (SiteAdvisor) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2015-11-28]
CHR Extension: (Google Docs Offline) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-11-28]
CHR Extension: (Read&Write for Google Chrome™) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\inoeonmfapjbbkmdafoankkfajkcphgd [2015-11-28]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-11-28]
CHR Extension: (Gmail) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-11-28]
CHR Extension: (Snapverter) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\plebojnaihkfjkkpgaemcjpnkmcpleih [2015-11-28]
CHR Profile: C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 3 [2018-01-27]
CHR Extension: (Slides) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-10-12]
CHR Extension: (Docs) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-12]
CHR Extension: (Google Drive) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-11-29]
CHR Extension: (YouTube) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-11-29]
CHR Extension: (Google Search) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-11-29]
CHR Extension: (Sheets) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-10-12]
CHR Extension: (McAfee® WebAdvisor) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2017-11-22]
CHR Extension: (Google Docs Offline) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-26]
CHR Extension: (Unlimited Free VPN - Hola) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\gkojfkhlekighikafcpjkiklfbnlmeio [2018-01-22]
CHR Extension: (Video Recorder for WeVideo) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\iaiglpeefdoagfbbfhjfbmomnfobojia [2017-12-14]
CHR Extension: (Project Viewer 365-Free) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\kmpghmkgkalhonankenfklpmdgnilapp [2016-04-07]
CHR Extension: (Cloud Drive, URL to ChromeCast™) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\mehfijocnmclokiknjjpcbddbekagnik [2015-12-25]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-08-21]
CHR Extension: (Gmail) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-11-29]
CHR Extension: (Chrome Media Router) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-01-25]
CHR Profile: C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 4 [2018-01-11]
CHR Extension: (Slides) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-01-11]
CHR Extension: (Docs) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\aohghmighlieiainnegkcijnfilokake [2018-01-11]
CHR Extension: (Google Drive) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-01-11]
CHR Extension: (YouTube) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-01-11]
CHR Extension: (Sheets) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-01-11]
CHR Extension: (McAfee® WebAdvisor) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2018-01-11]
CHR Extension: (Google Docs Offline) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-01-11]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-01-11]
CHR Extension: (Gmail) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2018-01-11]
CHR Extension: (Chrome Media Router) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-01-11]
CHR Profile: C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\System Profile [2015-11-29]
CHR HKLM\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - hxxp://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - hxxp://clients2.google.com/service/update2/crx
 
==================== Services (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S2 amdacpusrsvc; C:\Program Files\AMD\{920DEC42-4CA5-4d1d-9487-67BE645CDDFC}\amdacpusrsvc.exe [121856 2015-05-05] (Advanced Micro Devices) [File not signed]
S4 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2016-03-02] (Apple Inc.)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [6971400 2018-01-19] ()
S3 BrYNSvc; C:\Program Files (x86)\Browny02\BrYNSvc.exe [266240 2012-06-05] (Brother Industries, Ltd.) [File not signed]
S3 chromoting; C:\Program Files (x86)\Google\Chrome Remote Desktop\63.0.3239.32\remoting_host.exe [71512 2017-11-02] (Google Inc.)
S3 ClientAnalyticsService; C:\Program Files\Common Files\McAfee\ClientAnalytics\Legacy\McClientAnalytics.exe [1509680 2017-07-13] (McAfee, Inc.)
S4 Garmin Device Interaction Service; C:\Program Files (x86)\Garmin\Device Interaction Service\GarminService.exe [708616 2015-04-08] (Garmin Ltd. or its subsidiaries)
S4 lxea_device; C:\Windows\system32\lxeacoms.exe [1052328 2010-04-14] ( )
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6234056 2017-11-01] (Malwarebytes)
S2 McAPExe; C:\Program Files\Common Files\McAfee\VSCore_15_7\McApExe.exe [990696 2017-07-20] (McAfee, Inc.)
R2 mccspsvc; C:\Program Files\Common Files\McAfee\CSP\2.5.312.0\\McCSPServiceHost.exe [2139832 2017-05-30] (McAfee, Inc.)
R3 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe [242640 2017-06-21] (McAfee, Inc.)
R2 mfemms; C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe [394704 2017-06-21] (McAfee, Inc.)
R3 mfevtp; C:\Windows\system32\mfevtps.exe [350160 2017-06-21] (McAfee, Inc.)
R2 ModuleCoreService; C:\Program Files\Common Files\McAfee\ModuleCore\ModuleCoreService.exe [1545880 2017-06-27] (McAfee, Inc.)
S4 NETGEARGenieDaemon; C:\Program Files (x86)\NETGEAR Genie\bin\NETGEARGenieDaemon64.exe [232192 2015-06-01] (NETGEAR)
S2 PDFProFiltSrvPP; C:\Program Files (x86)\Nuance\PaperPort\PDFProFiltSrvPP.exe [144672 2010-03-09] (Nuance Communications, Inc.)
R2 PEFService; C:\Program Files\Common Files\Intel Security\PEF\CORE\PEFService.exe [1044376 2017-07-07] (Intel Security, Inc.)
S2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [66872 2015-04-21] ()
S2 PnkBstrB; C:\Windows\SysWOW64\PnkBstrB.exe [107832 2015-04-21] ()
S2 PSI_SVC_2_x64; c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe [337776 2014-04-30] (arvato digital services llc)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
R2 WTabletServicePro; C:\Program Files\Tablet\Wacom\WTabletServicePro.exe [652240 2016-07-14] (Wacom Technology, Corp.)
S2 HomeNetSvc; "C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe" /McCoreSvc [X]
S2 McBootDelayStartSvc; "C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe" /McCoreSvc [X]
S2 McMPFSvc; "C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe" /McCoreSvc [X]
S2 mcpltsvc; "C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe" /McCoreSvc [X]
S2 McProxy; "C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe" /McCoreSvc [X]
 
===================== Drivers (Whitelisted) ======================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 amdacpksd; C:\Windows\system32\drivers\amdacpksd.sys [297160 2015-05-05] (Advanced Micro Devices)
S3 cfwids; C:\Windows\System32\drivers\cfwids.sys [77800 2017-06-26] (McAfee, Inc.)
R1 ESProtectionDriver; C:\Windows\system32\drivers\mbae64.sys [77432 2017-12-12] ()
S3 HipShieldK; C:\Windows\System32\drivers\HipShieldK.sys [209616 2017-07-26] (McAfee, Inc.)
R0 MBAMChameleon; C:\Windows\System32\Drivers\MbamChameleon.sys [193968 2018-01-27] (Malwarebytes)
R3 MBAMFarflt; C:\Windows\System32\DRIVERS\farflt.sys [110016 2018-01-27] (Malwarebytes)
R3 MBAMProtection; C:\Windows\System32\DRIVERS\mbam.sys [46008 2018-01-27] (Malwarebytes)
R3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [253880 2018-01-27] (Malwarebytes)
R3 MBAMWebProtection; C:\Windows\System32\DRIVERS\mwac.sys [84256 2018-01-27] (Malwarebytes)
R3 mfeaack; C:\Windows\System32\drivers\mfeaack.sys [487408 2017-06-26] (McAfee, Inc.)
R3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [355312 2017-06-26] (McAfee, Inc.)
U3 mfeavfk01; no ImagePath
R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [506352 2017-06-26] (McAfee, Inc.)
R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [933360 2017-06-26] (McAfee, Inc.)
R3 mfencbdc; C:\Windows\System32\DRIVERS\mfencbdc.sys [504760 2017-05-31] (McAfee LLC.)
S3 mfencrk; C:\Windows\System32\DRIVERS\mfencrk.sys [108472 2017-05-31] (McAfee LLC.)
R3 mfeplk; C:\Windows\System32\drivers\mfeplk.sys [116208 2017-06-26] (McAfee, Inc.)
R0 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [253424 2017-06-26] (McAfee, Inc.)
R2 NPF; C:\Windows\system32\drivers\npf.sys [35344 2015-09-29] (CACE Technologies, Inc.)
S3 pmxdrv; C:\Windows\system32\drivers\pmxdrv.sys [31152 2015-09-18] ()
S3 WacHidRouterPro; C:\Windows\System32\DRIVERS\wachidrouter.sys [102864 2016-03-02] (Wacom Technology)
S3 mfeaack01; \Device\mfeaack01.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2018-01-27 19:06 - 2018-01-27 19:07 - 000051022 _____ C:\Users\Teschke\Desktop\Fixlog.txt
2018-01-27 19:06 - 2018-01-27 19:06 - 000026318 _____ C:\Users\Teschke\Desktop\kdvymdtevibxseqc.txt
2018-01-27 18:57 - 2018-01-27 18:57 - 000005130 _____ C:\Users\Teschke\Desktop\AdwCleaner[S0].txt
2018-01-27 18:54 - 2018-01-27 18:58 - 000000000 ____D C:\AdwCleaner
2018-01-27 18:54 - 2018-01-27 18:54 - 008206624 _____ (Malwarebytes) C:\Users\Teschke\Downloads\adwcleaner_7.0.7.0.exe
2018-01-27 18:38 - 2018-01-27 18:38 - 000001034 _____ C:\Users\Public\Desktop\Revo Uninstaller.lnk
2018-01-27 18:38 - 2018-01-27 18:38 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller
2018-01-27 18:38 - 2018-01-27 18:38 - 000000000 ____D C:\Program Files\VS Revo Group
2018-01-27 18:37 - 2018-01-27 18:37 - 007189760 _____ (VS Revo Group ) C:\Users\Teschke\Downloads\revosetup.exe
2018-01-27 15:08 - 2018-01-27 20:43 - 000024504 _____ C:\Users\Teschke\Desktop\FRST.txt
2018-01-27 13:39 - 2018-01-27 19:07 - 000000000 ____D C:\FRST
2018-01-27 13:37 - 2018-01-27 13:28 - 002393088 _____ (Farbar) C:\Users\Teschke\Desktop\FRST64.exe
2018-01-27 13:34 - 2018-01-27 19:02 - 000253880 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamswissarmy.sys
2018-01-27 13:34 - 2018-01-27 13:34 - 000193968 _____ (Malwarebytes) C:\Windows\system32\Drivers\MbamChameleon.sys
2018-01-26 19:03 - 2018-01-26 19:03 - 000619670 _____ C:\Users\Teschke\Desktop\W415-0061_GI3600manual.pdf
2018-01-20 18:11 - 2018-01-27 19:02 - 000084256 _____ (Malwarebytes) C:\Windows\system32\Drivers\mwac.sys
2018-01-19 20:53 - 2018-01-19 20:53 - 000000000 ____D C:\Users\Teschke\AppData\Local\CrashReportClient
2018-01-19 20:18 - 2018-01-18 19:16 - 000000229 ___SH C:\Users\Public\Libraries.ini
2018-01-19 20:15 - 2018-01-19 20:15 - 000000000 ____D C:\Users\Admin\AppData\Local\NVIDIA Corporation
2018-01-19 20:05 - 2018-01-19 20:05 - 000000000 ____D C:\Users\Admin\AppData\Local\FortniteGame
2018-01-19 20:05 - 2018-01-19 20:05 - 000000000 ____D C:\Users\Admin\AppData\Local\CrashReportClient
2018-01-19 20:04 - 2018-01-19 20:04 - 000000000 ____D C:\Users\Teschke\AppData\Local\NVIDIA Corporation
2018-01-19 20:03 - 2018-01-19 20:03 - 000000000 ____D C:\Users\Teschke\AppData\Local\FortniteGame
2018-01-19 19:39 - 2018-01-19 19:39 - 000000000 ___DL C:\Users\Admin\AppData\LocalLow\PlayReady
2018-01-19 19:01 - 2018-01-19 19:02 - 000000000 ____D C:\Program Files\Epic Games
2018-01-19 18:56 - 2018-01-19 20:05 - 000000000 ____D C:\Users\Admin\AppData\Local\UnrealEngine
2018-01-19 18:56 - 2018-01-19 18:56 - 000000000 ____D C:\Users\Admin\AppData\Local\UnrealEngineLauncher
2018-01-19 18:56 - 2018-01-19 18:56 - 000000000 ____D C:\Users\Admin\AppData\Local\EpicGamesLauncher
2018-01-19 18:51 - 2018-01-19 18:51 - 032260096 _____ C:\Users\Teschke\Downloads\EpicInstaller-7.2.0-fortnite-b4c7450ecc744c899c12cef8180e72f1 (1).msi
2018-01-19 18:49 - 2018-01-19 20:03 - 000000000 ____D C:\Users\Teschke\AppData\Local\UnrealEngine
2018-01-19 18:49 - 2018-01-19 18:49 - 000000000 ____D C:\Users\Teschke\AppData\Local\UnrealEngineLauncher
2018-01-19 18:49 - 2018-01-19 18:49 - 000000000 ____D C:\Users\Teschke\AppData\Local\EpicGamesLauncher
2018-01-19 18:48 - 2018-01-19 18:48 - 000001242 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Epic Games Launcher.lnk
2018-01-19 18:48 - 2018-01-19 18:48 - 000001230 _____ C:\Users\Public\Desktop\Epic Games Launcher.lnk
2018-01-19 18:48 - 2007-04-04 18:53 - 000081768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_3.dll
2018-01-19 18:47 - 2018-01-19 18:52 - 000000000 ____D C:\ProgramData\Epic
2018-01-19 18:47 - 2018-01-19 18:47 - 000000000 ____D C:\Program Files (x86)\Epic Games
2018-01-19 18:45 - 2018-01-19 18:45 - 032260096 _____ C:\Users\Teschke\Downloads\EpicInstaller-7.2.0-fortnite-b4c7450ecc744c899c12cef8180e72f1.msi
2018-01-16 20:59 - 2018-01-16 20:59 - 000057879 _____ C:\Users\Teschke\Downloads\On_Jesus_Derrida_and_Dawkins_Rejoinder_t (1).pdf
2018-01-16 20:58 - 2018-01-16 20:58 - 000057879 _____ C:\Users\Teschke\Downloads\On_Jesus_Derrida_and_Dawkins_Rejoinder_t.pdf
2018-01-07 14:20 - 2018-01-07 14:20 - 000562772 _____ C:\Users\Teschke\Downloads\NP_EX16_2b_IsaacTeschke_1.xlsx
2018-01-07 14:02 - 2018-01-07 14:02 - 000022355 _____ C:\Users\Teschke\Downloads\NP_EX16_1b_IsaacTeschke_1.xlsx
2018-01-04 21:08 - 2017-12-31 21:21 - 005581544 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2018-01-04 21:08 - 2017-12-31 21:21 - 001680616 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2018-01-04 21:08 - 2017-12-31 21:21 - 000948968 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys
2018-01-04 21:08 - 2017-12-31 21:21 - 000708328 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2018-01-04 21:08 - 2017-12-31 21:21 - 000288488 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fltMgr.sys
2018-01-04 21:08 - 2017-12-31 21:21 - 000262376 _____ (Microsoft Corporation) C:\Windows\system32\hal.dll
2018-01-04 21:08 - 2017-12-31 21:21 - 000213736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdyboost.sys
2018-01-04 21:08 - 2017-12-31 21:21 - 000154856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2018-01-04 21:08 - 2017-12-31 21:21 - 000114408 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2018-01-04 21:08 - 2017-12-31 21:21 - 000095464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2018-01-04 21:08 - 2017-12-31 21:19 - 001665384 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 014183936 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 002066432 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 002004480 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 001942016 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 001867776 _____ (Microsoft Corporation) C:\Windows\system32\ExplorerFrame.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 001741312 _____ (Microsoft Corporation) C:\Windows\system32\sysmain.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 001460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 001212928 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 001163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 001110528 _____ (Microsoft Corporation) C:\Windows\system32\schedsvc.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000977408 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000961024 _____ (Microsoft Corporation) C:\Windows\system32\actxprxy.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000880640 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000863232 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL
2018-01-04 21:08 - 2017-12-31 21:18 - 000842752 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000828928 _____ (Microsoft Corporation) C:\Windows\system32\MPSSVC.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000749568 _____ (Microsoft Corporation) C:\Windows\system32\FirewallAPI.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000731648 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000705024 _____ (Microsoft Corporation) C:\Windows\system32\BFE.DLL
2018-01-04 21:08 - 2017-12-31 21:18 - 000690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000512000 _____ (Microsoft Corporation) C:\Windows\system32\rpcss.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000473600 _____ (Microsoft Corporation) C:\Windows\system32\taskcomp.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000463872 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000444928 _____ (Microsoft Corporation) C:\Windows\system32\winhttp.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000439296 _____ (Microsoft Corporation) C:\Windows\system32\p2psvc.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000419840 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000366592 _____ (Microsoft Corporation) C:\Windows\system32\wcncsvc.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000361984 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000345600 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000327168 _____ (Microsoft Corporation) C:\Windows\system32\pnrpsvc.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000324096 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL
2018-01-04 21:08 - 2017-12-31 21:18 - 000316928 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000303104 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000264704 _____ (Microsoft Corporation) C:\Windows\system32\P2P.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000223232 _____ (Microsoft Corporation) C:\Windows\system32\ncsi.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000215552 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000190464 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000123904 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000120320 _____ (Microsoft Corporation) C:\Windows\system32\WcnApi.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000108544 _____ (Microsoft Corporation) C:\Windows\system32\icfupgd.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000101376 _____ (Microsoft Corporation) C:\Windows\system32\fdWCN.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000095744 _____ (Microsoft Corporation) C:\Windows\system32\rascfg.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000084480 _____ (Microsoft Corporation) C:\Windows\system32\INETRES.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000076288 _____ (Microsoft Corporation) C:\Windows\system32\rasdiag.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000070656 _____ (Microsoft Corporation) C:\Windows\system32\nlaapi.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000070144 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000060928 _____ (Microsoft Corporation) C:\Windows\system32\ndptsp.tsp
2018-01-04 21:08 - 2017-12-31 21:18 - 000060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000059904 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000047104 _____ (Microsoft Corporation) C:\Windows\system32\kmddsp.tsp
2018-01-04 21:08 - 2017-12-31 21:18 - 000044032 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000041472 _____ (Microsoft Corporation) C:\Windows\system32\rasmxs.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000039424 _____ (Microsoft Corporation) C:\Windows\system32\traffic.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000034816 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000029696 _____ (Microsoft Corporation) C:\Windows\system32\rasser.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000026112 _____ (Microsoft Corporation) C:\Windows\system32\oleres.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000024576 _____ (Microsoft Corporation) C:\Windows\system32\WcnEapPeerProxy.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000024064 _____ (Microsoft Corporation) C:\Windows\system32\WcnEapAuthProxy.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000022528 _____ (Microsoft Corporation) C:\Windows\system32\wfapigp.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000016896 _____ (Microsoft Corporation) C:\Windows\system32\wshqos.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000013312 _____ (Microsoft Corporation) C:\Windows\system32\wshnetbs.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000008704 _____ (Microsoft Corporation) C:\Windows\system32\comcat.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml6r.dll
2018-01-04 21:08 - 2017-12-31 21:13 - 000631680 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2018-01-04 21:08 - 2017-12-31 21:04 - 000559616 _____ (Microsoft Corporation) C:\Windows\system32\spoolsv.exe
2018-01-04 21:08 - 2017-12-31 21:02 - 001314112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 012880384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 001499648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ExplorerFrame.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 001417728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 001390080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 001114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000741888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000666624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000666112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000554496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000463360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FirewallAPI.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000351744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winhttp.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000304640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\taskcomp.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000276992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wcncsvc.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000275456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000261120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000254464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000217600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\P2P.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000216576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL
2018-01-04 21:08 - 2017-12-31 21:00 - 000172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000162304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncsi.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000084480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\INETRES.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcrypt.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fdWCN.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000081408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rascfg.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rasdiag.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000052224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ndptsp.tsp
2018-01-04 21:08 - 2017-12-31 21:00 - 000043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\traffic.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000026112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleres.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6r.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 001806848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000644096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000309760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\actxprxy.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:55 - 000131584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\pacer.sys
2018-01-04 21:08 - 2017-12-31 20:55 - 000088576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\wanarp.sys
2018-01-04 21:08 - 2017-12-31 20:55 - 000058368 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndproxy.sys
2018-01-04 21:08 - 2017-12-31 20:55 - 000045056 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netbios.sys
2018-01-04 21:08 - 2017-12-31 20:55 - 000024064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndistapi.sys
2018-01-04 21:08 - 2017-12-31 20:54 - 004013800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2018-01-04 21:08 - 2017-12-31 20:54 - 003959016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2018-01-04 21:08 - 2017-12-31 20:54 - 000077312 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mpsdrv.sys
2018-01-04 21:08 - 2017-12-31 20:50 - 000455680 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2018-01-04 21:08 - 2017-12-31 20:49 - 000148480 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2018-01-04 21:08 - 2017-12-31 20:49 - 000064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2018-01-04 21:08 - 2017-12-31 20:49 - 000062464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2018-01-04 21:08 - 2017-12-31 20:49 - 000017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2018-01-04 21:08 - 2017-12-31 20:46 - 000338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2018-01-04 21:08 - 2017-12-31 20:45 - 000296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2018-01-04 21:08 - 2017-12-31 20:43 - 000086528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WcnApi.dll
2018-01-04 21:08 - 2017-12-31 20:43 - 000038912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kmddsp.tsp
2018-01-04 21:08 - 2017-12-31 20:43 - 000033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rasmxs.dll
2018-01-04 21:08 - 2017-12-31 20:43 - 000022528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rasser.dll
2018-01-04 21:08 - 2017-12-31 20:43 - 000020480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WcnEapPeerProxy.dll
2018-01-04 21:08 - 2017-12-31 20:43 - 000019968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WcnEapAuthProxy.dll
2018-01-04 21:08 - 2017-12-31 20:43 - 000018944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wfapigp.dll
2018-01-04 21:08 - 2017-12-31 20:43 - 000013824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshqos.dll
2018-01-04 21:08 - 2017-12-31 20:42 - 000460288 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys
2018-01-04 21:08 - 2017-12-31 20:42 - 000406016 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys
2018-01-04 21:08 - 2017-12-31 20:42 - 000168448 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys
2018-01-04 21:08 - 2017-12-31 20:42 - 000159744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2018-01-04 21:08 - 2017-12-31 20:41 - 000754176 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys
2018-01-04 21:08 - 2017-12-31 20:41 - 000291328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2018-01-04 21:08 - 2017-12-31 20:41 - 000129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2018-01-04 21:08 - 2017-12-31 20:41 - 000112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2018-01-04 21:08 - 2017-12-31 20:41 - 000106496 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dfsc.sys
2018-01-04 21:08 - 2017-12-31 20:41 - 000030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2018-01-04 21:08 - 2017-12-31 20:41 - 000007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comcat.dll
2018-01-04 21:08 - 2017-12-31 20:39 - 000050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2018-01-04 21:08 - 2017-12-31 20:36 - 000025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2018-01-04 21:08 - 2017-12-31 20:36 - 000014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2018-01-04 21:08 - 2017-12-31 20:36 - 000007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2018-01-04 21:08 - 2017-12-31 20:36 - 000002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2018-01-04 21:08 - 2017-12-31 20:35 - 000036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
2018-01-04 21:08 - 2017-12-31 20:35 - 000006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:35 - 000004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:35 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:35 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2018-01-04 21:08 - 2017-12-30 02:29 - 000395968 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2018-01-04 21:08 - 2017-12-30 01:42 - 000347328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2018-01-04 21:08 - 2017-12-29 13:39 - 020274688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2018-01-04 21:08 - 2017-12-29 13:24 - 002724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2018-01-04 21:08 - 2017-12-29 13:13 - 000499712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2018-01-04 21:08 - 2017-12-29 13:13 - 000062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2018-01-04 21:08 - 2017-12-29 13:12 - 000341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2018-01-04 21:08 - 2017-12-29 13:12 - 000047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2018-01-04 21:08 - 2017-12-29 13:11 - 000064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2018-01-04 21:08 - 2017-12-29 13:09 - 002294272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2018-01-04 21:08 - 2017-12-29 13:06 - 000047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2018-01-04 21:08 - 2017-12-29 13:06 - 000030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2018-01-04 21:08 - 2017-12-29 13:04 - 000476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2018-01-04 21:08 - 2017-12-29 13:03 - 000662528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2018-01-04 21:08 - 2017-12-29 13:03 - 000620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2018-01-04 21:08 - 2017-12-29 13:03 - 000115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2018-01-04 21:08 - 2017-12-29 12:55 - 000416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2018-01-04 21:08 - 2017-12-29 12:51 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2018-01-04 21:08 - 2017-12-29 12:50 - 000091136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2018-01-04 21:08 - 2017-12-29 12:50 - 000073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2018-01-04 21:08 - 2017-12-29 12:47 - 000168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2018-01-04 21:08 - 2017-12-29 12:47 - 000076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2018-01-04 21:08 - 2017-12-29 12:46 - 000279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2018-01-04 21:08 - 2017-12-29 12:45 - 004508160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2018-01-04 21:08 - 2017-12-29 12:44 - 000130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2018-01-04 21:08 - 2017-12-29 12:39 - 000230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2018-01-04 21:08 - 2017-12-29 12:38 - 013680128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2018-01-04 21:08 - 2017-12-29 12:38 - 000694272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2018-01-04 21:08 - 2017-12-29 12:37 - 002058752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2018-01-04 21:08 - 2017-12-29 12:36 - 001155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2018-01-04 21:08 - 2017-12-29 12:19 - 002767872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2018-01-04 21:08 - 2017-12-29 12:15 - 001313792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2018-01-04 21:08 - 2017-12-29 12:13 - 000710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2018-01-04 21:08 - 2017-12-29 04:15 - 025737728 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2018-01-04 21:08 - 2017-12-29 04:04 - 002724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2018-01-04 21:08 - 2017-12-29 04:04 - 000004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2018-01-04 21:08 - 2017-12-29 03:52 - 002900480 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2018-01-04 21:08 - 2017-12-29 03:51 - 005796352 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2018-01-04 21:08 - 2017-12-29 03:51 - 000066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2018-01-04 21:08 - 2017-12-29 03:50 - 000577024 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2018-01-04 21:08 - 2017-12-29 03:50 - 000417280 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2018-01-04 21:08 - 2017-12-29 03:50 - 000088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2018-01-04 21:08 - 2017-12-29 03:50 - 000048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2018-01-04 21:08 - 2017-12-29 03:44 - 000054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2018-01-04 21:08 - 2017-12-29 03:43 - 000034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2018-01-04 21:08 - 2017-12-29 03:40 - 000615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2018-01-04 21:08 - 2017-12-29 03:39 - 000817152 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2018-01-04 21:08 - 2017-12-29 03:39 - 000814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2018-01-04 21:08 - 2017-12-29 03:39 - 000144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2018-01-04 21:08 - 2017-12-29 03:39 - 000116224 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2018-01-04 21:08 - 2017-12-29 03:32 - 000969216 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2018-01-04 21:08 - 2017-12-29 03:28 - 000489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2018-01-04 21:08 - 2017-12-29 03:22 - 000087552 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2018-01-04 21:08 - 2017-12-29 03:22 - 000077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2018-01-04 21:08 - 2017-12-29 03:21 - 000107520 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2018-01-04 21:08 - 2017-12-29 03:18 - 000199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2018-01-04 21:08 - 2017-12-29 03:18 - 000092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2018-01-04 21:08 - 2017-12-29 03:16 - 000315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2018-01-04 21:08 - 2017-12-29 03:14 - 000152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2018-01-04 21:08 - 2017-12-29 03:05 - 000262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2018-01-04 21:08 - 2017-12-29 03:04 - 015284224 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2018-01-04 21:08 - 2017-12-29 03:03 - 000807936 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2018-01-04 21:08 - 2017-12-29 03:03 - 000726528 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2018-01-04 21:08 - 2017-12-29 03:01 - 002134528 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2018-01-04 21:08 - 2017-12-29 03:01 - 001359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2018-01-04 21:08 - 2017-12-29 02:50 - 003241472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2018-01-04 21:08 - 2017-12-29 02:39 - 001545728 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2018-01-04 21:08 - 2017-12-29 02:27 - 000800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2018-01-04 21:08 - 2017-12-21 01:27 - 000634312 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
2018-01-04 21:08 - 2017-12-13 11:31 - 000383720 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2018-01-04 21:08 - 2017-12-13 11:27 - 000100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2018-01-04 21:08 - 2017-12-13 11:27 - 000046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2018-01-04 21:08 - 2017-12-13 11:27 - 000041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2018-01-04 21:08 - 2017-12-13 11:27 - 000014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2018-01-04 21:08 - 2017-12-13 11:15 - 000309480 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2018-01-04 21:08 - 2017-12-13 11:11 - 000071168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2018-01-04 21:08 - 2017-12-13 11:11 - 000025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
2018-01-04 21:08 - 2017-12-13 11:11 - 000010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
2018-01-04 21:08 - 2017-12-13 10:50 - 000034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2018-01-04 21:08 - 2017-12-05 12:36 - 000625664 _____ (Microsoft Corporation) C:\Windows\system32\mscms.dll
2018-01-04 21:08 - 2017-12-05 12:36 - 000250880 _____ (Microsoft Corporation) C:\Windows\system32\icm32.dll
2018-01-04 21:08 - 2017-12-05 12:36 - 000040960 _____ (Microsoft Corporation) C:\Windows\system32\WcsPlugInService.dll
2018-01-04 21:08 - 2017-12-05 12:08 - 000481792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscms.dll
2018-01-04 21:08 - 2017-12-05 12:08 - 000215040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icm32.dll
2018-01-04 21:08 - 2017-12-05 10:59 - 003222528 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2018-01-04 21:08 - 2017-12-05 10:49 - 000032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WcsPlugInService.dll
2018-01-04 19:50 - 2018-01-04 19:50 - 000053941 _____ C:\Users\Teschke\Downloads\NP_PPT16_1b_IsaacTeschke_1 (1).pptx
2018-01-02 12:51 - 2018-01-02 12:51 - 000099306 _____ C:\Users\Teschke\Downloads\340906__passairmangrace__tablehit-mono-bip.wav
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2018-01-27 20:40 - 2013-04-20 14:11 - 000000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2018-01-27 19:17 - 2009-07-13 23:45 - 000022656 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2018-01-27 19:17 - 2009-07-13 23:45 - 000022656 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2018-01-27 19:08 - 2017-01-14 15:20 - 000000000 ____D C:\ProgramData\McAfee
2018-01-27 19:06 - 2009-07-14 00:13 - 000782470 _____ C:\Windows\system32\PerfStringBackup.INI
2018-01-27 19:06 - 2009-07-13 22:20 - 000000000 ____D C:\Windows\inf
2018-01-27 19:02 - 2017-12-12 04:54 - 000046008 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2018-01-27 19:02 - 2017-12-12 04:53 - 000110016 _____ (Malwarebytes) C:\Windows\system32\Drivers\farflt.sys
2018-01-27 18:59 - 2013-08-25 20:48 - 000000000 ____D C:\Program Files (x86)\McAfee
2018-01-27 18:59 - 2009-07-14 00:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2018-01-27 18:58 - 2015-09-22 22:11 - 000065536 _____ C:\Windows\system32\spu_storage.bin
2018-01-27 18:47 - 2017-01-14 15:39 - 000000000 ____D C:\Program Files\McAfee
2018-01-27 13:43 - 2014-05-30 15:16 - 001102276 _____ C:\Windows\ntbtlog.txt
2018-01-27 11:33 - 2017-11-05 20:22 - 000001690 _____ C:\Users\Admin\Desktop\Rkill.txt
2018-01-26 15:10 - 2013-04-21 13:55 - 000000000 ____D C:\Users\Teschke\AppData\Local\CrashDumps
2018-01-25 19:53 - 2013-04-18 07:01 - 000000000 ____D C:\Users\Teschke\Documents\Outlook Files
2018-01-25 19:31 - 2013-04-18 00:03 - 000001236 __RSH C:\Users\Teschke\ntuser.pol
2018-01-25 19:31 - 2013-04-17 20:06 - 000000000 ____D C:\Users\Teschke
2018-01-25 19:14 - 2013-04-18 00:07 - 000001232 __RSH C:\Users\Admin\ntuser.pol
2018-01-25 19:14 - 2013-04-18 00:07 - 000000000 ____D C:\Users\Admin
2018-01-25 19:08 - 2009-07-13 22:20 - 000000000 ____D C:\Windows\registration
2018-01-25 13:12 - 2013-04-20 15:39 - 000000000 ____D C:\Users\Teschke\Documents\Laura
2018-01-24 15:48 - 2013-04-20 14:11 - 000002224 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2018-01-23 17:29 - 2017-07-09 12:08 - 000000000 ____D C:\Users\Teschke\AppData\Local\Spotify
2018-01-23 16:54 - 2017-07-09 12:02 - 000000000 ____D C:\Users\Teschke\AppData\Roaming\Spotify
2018-01-23 11:29 - 2013-04-20 15:50 - 000000000 ____D C:\Users\Teschke\Documents\Isaac
2018-01-23 10:57 - 2014-02-17 18:02 - 001446400 ___SH C:\Users\Teschke\Downloads\Thumbs.db
2018-01-19 18:51 - 2014-11-24 21:35 - 000000000 ____D C:\ProgramData\Package Cache
2018-01-19 03:02 - 2013-04-18 00:33 - 000775462 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2018-01-18 17:03 - 2017-11-05 20:21 - 000009216 ___SH C:\Users\Teschke\Thumbs.db
2018-01-13 06:44 - 2013-04-20 15:28 - 000000000 ____D C:\Program Files (x86)\Steam
2018-01-12 20:50 - 2013-09-28 20:10 - 000000000 ____D C:\Users\Teschke\Documents\Corel VideoStudio Pro
2018-01-10 03:19 - 2013-07-12 17:33 - 000000000 ____D C:\Windows\system32\MRT
2018-01-10 03:13 - 2017-10-12 02:11 - 129365736 ____C (Microsoft Corporation) C:\Windows\system32\MRT-KB890830.exe
2018-01-10 03:13 - 2013-04-19 08:17 - 129365736 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2018-01-09 10:40 - 2017-09-28 16:34 - 000004468 _____ C:\Windows\System32\Tasks\Adobe Flash Player PPAPI Notifier
2018-01-09 10:40 - 2013-04-19 07:28 - 000803328 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2018-01-09 10:40 - 2013-04-19 07:28 - 000144896 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2018-01-09 10:40 - 2013-04-19 07:28 - 000004312 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2018-01-09 10:40 - 2013-04-19 07:28 - 000000000 ____D C:\Windows\system32\Macromed
2018-01-09 10:40 - 2013-04-17 22:41 - 000000000 ____D C:\Windows\SysWOW64\Macromed
2018-01-05 04:11 - 2009-07-13 22:20 - 000000000 ____D C:\Windows\rescache
2018-01-05 03:21 - 2009-07-13 23:45 - 000532872 _____ C:\Windows\system32\FNTCACHE.DAT
2018-01-04 16:59 - 2009-07-13 22:20 - 000000000 ____D C:\Windows\system32\NDF
2018-01-01 00:36 - 2009-07-14 00:08 - 000032542 _____ C:\Windows\Tasks\SCHEDLGU.TXT
 
==================== Files in the root of some directories =======
 
2014-09-30 19:18 - 2015-10-05 05:49 - 000000096 _____ () C:\Users\Teschke\AppData\Roaming\LauncherSettings_live.cfg
2014-09-30 18:25 - 2015-10-05 05:33 - 000000039 _____ () C:\Users\Teschke\AppData\Roaming\TheHunterSettings_live.cfg
2014-03-06 15:07 - 2014-03-06 15:07 - 000003584 _____ () C:\Users\Teschke\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2013-12-29 20:09 - 2013-12-29 20:09 - 000000084 _____ () C:\Users\Teschke\AppData\Local\DVDPATH.TXT
 
Some files in TEMP:
====================
2016-10-15 05:44 - 2015-01-26 11:34 - 000015752 _____ (Autodesk, Inc.) C:\Users\Admin\AppData\Local\Temp\AcDeltree.exe
2017-05-26 21:46 - 2017-05-26 22:10 - 002016632 _____ (Flexera Software LLC) C:\Users\Admin\AppData\Local\Temp\FNP_ACT_InstallerCA.dll
2017-09-10 21:11 - 2017-09-10 21:12 - 000004608 _____ () C:\Users\Admin\AppData\Local\Temp\i4jdel0.exe
2016-11-16 06:28 - 2016-11-16 06:28 - 000244264 _____ (McAfee, Inc.) C:\Users\Admin\AppData\Local\Temp\McCSPInstall.dll
2015-09-22 21:36 - 2015-09-22 21:47 - 060685368 _____ () C:\Users\Admin\AppData\Local\Temp\raptrpatch.exe
2015-09-22 21:36 - 2015-09-22 21:36 - 000221632 _____ () C:\Users\Admin\AppData\Local\Temp\raptr_stub.exe
2006-05-24 12:10 - 2006-05-24 12:10 - 000455600 ____R (Macrovision Corporation) C:\Users\Admin\AppData\Local\Temp\_is897B.exe
2014-02-15 20:01 - 2014-02-15 20:01 - 000588360 _____ (NCH Software) C:\Users\Teschke\AppData\Local\Temp\bwsetup.exe
2014-08-20 20:25 - 2014-08-20 20:25 - 003166208 _____ () C:\Users\Teschke\AppData\Local\Temp\ffmpeg19.exe
2016-01-30 23:16 - 2016-01-30 23:20 - 023334528 _____ (Hola Networks Ltd.) C:\Users\Teschke\AppData\Local\Temp\Hola-Setup-Plugin-x64-1.11.399.exe
2013-10-30 17:52 - 2013-10-30 17:52 - 001071584 _____ (Solid State Networks) C:\Users\Teschke\AppData\Local\Temp\install_flashplayer11x32ax_chra_awa_aih.exe
2013-11-28 12:24 - 2013-11-28 12:24 - 001071584 _____ (Solid State Networks) C:\Users\Teschke\AppData\Local\Temp\install_flashplayer11x32ax_gtba_chra_dy_aaa_aih.exe
2013-11-28 12:28 - 2013-11-28 12:28 - 001071584 _____ (Solid State Networks) C:\Users\Teschke\AppData\Local\Temp\install_flashplayer11x32ax_gtba_chra_dy_aaa_aih_1.exe
2013-10-08 15:36 - 2013-10-08 15:36 - 001071568 _____ (Solid State Networks) C:\Users\Teschke\AppData\Local\Temp\install_reader11_en_chra_awa_aih.exe
2014-02-25 18:48 - 2014-02-25 18:48 - 001069920 _____ (Solid State Networks) C:\Users\Teschke\AppData\Local\Temp\install_reader11_en_chra_awa_aih_1.exe
2013-05-21 21:24 - 2013-05-21 21:24 - 002137632 _____ (Solid State Networks) C:\Users\Teschke\AppData\Local\Temp\install_reader11_en_gtbp_chra_aih.exe
2013-06-26 11:56 - 2013-06-26 11:56 - 001037120 _____ (Solid State Networks) C:\Users\Teschke\AppData\Local\Temp\install_reader11_en_mssa_aaa_aih.exe
2013-07-12 21:08 - 2013-07-12 21:08 - 004120976 _____ (Black Tree Gaming                                           ) C:\Users\Teschke\AppData\Local\Temp\Nexus%20Mod%20Manager-0.45.4.exe
2014-08-09 20:04 - 2014-08-09 20:04 - 000518208 _____ (NCH Software) C:\Users\Teschke\AppData\Local\Temp\pixsetup.exe
2014-04-21 16:29 - 2014-04-21 16:29 - 000339544 _____ (NCH Software) C:\Users\Teschke\AppData\Local\Temp\ppsetup.exe
2014-08-20 20:23 - 2014-08-20 20:23 - 000589888 _____ (NCH Software) C:\Users\Teschke\AppData\Local\Temp\prismsetup.exe
2016-09-23 19:26 - 2016-09-23 19:26 - 083528440 _____ () C:\Users\Teschke\AppData\Local\Temp\Setup-Wacom.exe
2015-01-31 10:16 - 2016-04-08 14:58 - 046965376 _____ (Skype Technologies S.A.) C:\Users\Teschke\AppData\Local\Temp\SkypeSetup.exe
2014-04-21 16:27 - 2014-04-21 16:27 - 000418352 _____ (NCH Software) C:\Users\Teschke\AppData\Local\Temp\tnsetup.exe
2014-02-15 20:00 - 2014-02-15 20:00 - 000367192 _____ (NCH Software) C:\Users\Teschke\AppData\Local\Temp\twelvekeyssetup.exe
2014-02-15 20:00 - 2014-02-15 20:00 - 000752176 _____ (NCH Software) C:\Users\Teschke\AppData\Local\Temp\vxlsetup.exe
2014-02-15 19:59 - 2014-02-15 19:59 - 001003568 _____ (NCH Software) C:\Users\Teschke\AppData\Local\Temp\wpsetup.exe
 
==================== Bamital & volsnap ======================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
 
LastRegBack: 2018-01-18 01:44
 
==================== End of FRST.txt ============================


#11 Dustint

Dustint
  • Topic Starter

  • Members
  • 26 posts
  • OFFLINE
  •  
  • Local time:09:50 PM

Posted 27 January 2018 - 08:48 PM

and here is the 2nd log file:

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 27.01.2018
Ran by Teschke (27-01-2018 20:44:11)
Running from C:\Users\Teschke\Desktop
Windows 7 Home Premium Service Pack 1 (X64) (2013-04-18 01:06:13)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Admin (S-1-5-21-3289118944-4034126387-1954186238-1003 - Administrator - Enabled) => C:\Users\Admin
Administrator (S-1-5-21-3289118944-4034126387-1954186238-500 - Administrator - Disabled)
Guest (S-1-5-21-3289118944-4034126387-1954186238-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3289118944-4034126387-1954186238-1002 - Limited - Enabled)
Teschke (S-1-5-21-3289118944-4034126387-1954186238-1000 - Administrator - Enabled) => C:\Users\Teschke
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Malwarebytes (Enabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B}
AS: Malwarebytes (Enabled - Up to date) {98619B37-4FC4-67F2-1C99-EEF6D47DBD96}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov)
Ace of Spades (HKLM-x32\...\{6037B8AD-7D5B-4D50-9BCA-A586C44EEF34}) (Version: 0.75.015 - Ben Aksoy)
ACP Application (HKLM\...\{DD93B141-69A7-A8FD-6963-266D02E9C07B}) (Version: 2.15.20.0015 - Advanced Micro Devices, Inc.) Hidden
Adobe Flash Player 28 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 28.0.0.137 - Adobe Systems Incorporated)
Adobe Flash Player 28 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 28.0.0.137 - Adobe Systems Incorporated)
Adobe Flash Player 28 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 28.0.0.137 - Adobe Systems Incorporated)
Adobe Photoshop Lightroom 5.2 64-bit (HKLM\...\{54E6C675-3AD4-42E4-957F-31666ABF1603}) (Version: 5.2.1 - Adobe)
Adobe Reader XI (11.0.03) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.03 - Adobe Systems Incorporated)
AMD Catalyst Install Manager (HKLM\...\{8F62BC70-DBB4-802D-1E1E-13630D9BA4D2}) (Version: 8.0.916.0 - Advanced Micro Devices, Inc.)
ANT Drivers Installer x64 (HKLM\...\{431CE782-4C51-4996-B36F-5D98D5527538}) (Version: 2.3.4 - Garmin Ltd or its subsidiaries) Hidden
Apple Application Support (32-bit) (HKLM-x32\...\{FE5C2FAA-118D-4509-B51D-3F71CC9E1B3E}) (Version: 4.3 - Apple Inc.)
Apple Application Support (64-bit) (HKLM\...\{2937FD88-C9D6-4B82-B539-37CD0A572F42}) (Version: 4.3 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{2E4AF2A6-50EA-4260-9BA4-5E582D11879A}) (Version: 9.3.0.15 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{56EC47AA-5813-4FF6-8E75-544026FBEA83}) (Version: 2.2.0.150 - Apple Inc.)
Assassin's Creed III 1.01 (HKLM-x32\...\{9D15E813-0C26-41E7-ABC5-3EB06FF1B3CF}) (Version: 1.01 - Ubisoft)
Autodesk Configurator 360 addin (HKLM-x32\...\{563941AA-C055-4FAA-8B04-A4E024A61F7E}) (Version: 20.0.10300 - Autodesk)
Autodesk Design Review 2013 (HKLM-x32\...\{153DB567-6FF3-49AD-AC4F-86F8A3CCFDFB}) (Version: 13.0.0.82 - Autodesk, Inc.) Hidden
Autodesk Design Review 2013 (HKLM-x32\...\Autodesk Design Review 2013) (Version: 13.0.0.82 - Autodesk, Inc.)
Battle.net (HKLM-x32\...\Battle.net) (Version:  - Blizzard Entertainment)
Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
BookSmart® 3.4.9 3.4.9 (HKLM-x32\...\BookSmart® 3.4.9 3.4.9) (Version:  - Blurb, Inc)
Boris Graffiti 6 for Corel VideoStudio Pro (HKLM-x32\...\{F4310AE4-A789-4602-AA48-CFA03D73A9F4}) (Version: 6.1.0003 - Boris FX, Inc.)
Boris Graffiti 7 for Corel VideoStudio Pro X9 64-Bit (HKLM\...\{9C246583-D390-4910-B740-431F89FACC2E}) (Version: 7.0.0001 - Boris FX, Inc.)
Brother MFL-Pro Suite DCP-7065DN (HKLM-x32\...\{3ACCCFB3-7B17-4E9F-ACB0-46868FCD4487}) (Version: 1.1.3.0 - Brother Industries, Ltd.)
Call of Duty - United Offensive (HKLM-x32\...\{A662E280-64A8-4CF5-8407-13D0808602B3}) (Version: 1.00.0000 - Activision) Hidden
Call of Duty - United Offensive (HKLM-x32\...\InstallShield_{A662E280-64A8-4CF5-8407-13D0808602B3}) (Version: 1.00.0000 - Activision)
Call of Duty (HKLM-x32\...\Call of Duty) (Version:  - )
Call of Duty® 4 - Modern Warfare™ (HKLM-x32\...\{E48469CC-635E-4FD5-A122-1497C286D217}) (Version: 1.6 - Activision) Hidden
Call of Duty® 4 - Modern Warfare™ (HKLM-x32\...\InstallShield_{E48469CC-635E-4FD5-A122-1497C286D217}) (Version: 1.6 - Activision)
CameraHelperMsi (HKLM-x32\...\{15634701-BACE-4449-8B25-1567DA8C9FD3}) (Version: 13.51.815.0 - Logitech) Hidden
Chrome Remote Desktop Host (HKLM-x32\...\{D61C8E6E-A4F3-4CD8-8568-51CEB5660C89}) (Version: 63.0.3239.32 - Google Inc.)
Cisco WebEx Meetings (HKU\S-1-5-21-3289118944-4034126387-1954186238-1000\...\ActiveTouchMeetingClient) (Version:  - Cisco WebEx LLC)
Contents (HKLM-x32\...\{EE0B1766-153A-4251-A192-F8FD3D941711}) (Version: 16.1.0.45 - Corel Corporation) Hidden
Contents64 (HKLM\...\{C2D307EA-96F8-4F6E-880E-E244779D8477}) (Version: 19.5.0.35 - Corel Corporation) Hidden
Corel KPT Collection (HKLM-x32\...\{031338C0-4C21-4DAC-875B-26ACD7ADDF23}) (Version: 1.00.0000 - Corel Corporation) Hidden
Corel KPT Collection for PSPX4 (HKLM-x32\...\_{031338C0-4C21-4DAC-875B-26ACD7ADDF23}) (Version:  - Corel Corporation)
Corel Painter 13 - IPM (HKLM\...\{0B598D32-B873-4794-8F30-90C53CD562D7}) (Version: 13.1 - Corel Corporation) Hidden
Corel Painter 13 - IPM Content (HKLM\...\{9983025B-AA60-4CF3-9E6C-C48DB9CD2310}) (Version: 13.1 - Corel Corporation) Hidden
Corel Painter X3 (HKLM\...\_{EF449371-6B69-49C8-B789-76A0B0E3446B}) (Version: 13.0.1.920 - Corel Corporation)
Corel PaintShop Pro X4 (HKLM-x32\...\_{00580795-581C-4587-B9F2-37320D7AB37F}) (Version: 14.2.0.1 - Corel Corporation)
Corel PaintShop Pro X4 (HKLM-x32\...\{00AE1A2D-7BC2-4359-A0EC-E19F36E391BB}) (Version: 14.2.0.1 - Corel Corporation) Hidden
Corel PaintShop Pro X4 Ultimate Bonus Pack (HKLM-x32\...\_{45E8DDB3-8FEB-40DB-A6D7-3535392AA559}) (Version:  - Corel Corporation)
Corel PaintShop Pro X4 Ultimate Bonus Pack (HKLM-x32\...\{45E8DDB3-8FEB-40DB-A6D7-3535392AA559}) (Version: 1.00.0000 - Corel Corporation) Hidden
Corel VideoStudio Pro X6 (HKLM-x32\...\_{6688A246-F6E8-48AD-9806-8D5832E9F15D}) (Version: 16.1.0.45 - Corel Corporation)
Corel VideoStudio Ultimate X9 (HKLM-x32\...\_{EE80DAA0-0071-475C-A222-F1782888FC55}) (Version: 19.5.0.35 - Corel Corporation)
Crysis®3 (HKLM-x32\...\{4198AE83-A3C6-4C41-85C8-EC63E990696E}) (Version: 1.0.0.0 - Electronic Arts)
D3DX10 (HKLM-x32\...\{E09C4DB7-630C-4F06-A631-8EA7239923AF}) (Version: 15.4.2368.0902 - Microsoft) Hidden
DAIDE QuickStart (HKLM-x32\...\{FDE86B27-8B13-40CB-B0DA-A1CAB15C2929}) (Version: 6.0.1 - Jason van Hal)
Dell System Detect (HKU\S-1-5-21-3289118944-4034126387-1954186238-1000\...\73f463568823ebbe) (Version: 6.6.0.2 - Dell)
digiCamControl (HKLM-x32\...\{19D12628-7654-4354-A305-9AB0A3502683}) (Version: 1.2.99.12 - Duka Istvan)
Eco Materials Adviser for Autodesk Inventor 2016 (64-bit) (HKLM\...\{1A56BE00-916E-432D-A576-EB00D2FF8450}) (Version: 5.6.4.44 - Granta Design Limited)
Elevated Installer (HKLM-x32\...\{7E73C9A3-24D9-4D7F-B4C7-7E4AFE0ADCCB}) (Version: 4.0.15.0 - Garmin Ltd or its subsidiaries) Hidden
Epic Games Launcher (HKLM-x32\...\{2B6AC31A-9883-465C-AFC6-1EC5AA48F5BD}) (Version: 1.1.138.0 - Epic Games, Inc.)
Epic Games Launcher Prerequisites (x64) (HKLM\...\{66C5838F-B854-4A55-89E6-A6138747A4DF}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
erLT (HKLM-x32\...\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}) (Version: 1.20.138.34 - Logitech, Inc.) Hidden
Far Cry (HKLM-x32\...\{D6DBDC2A-E72C-4284-B6AD-6B3B61B4DABC}) (Version: 1.00.0000 - Ubisoft) Hidden
Far Cry (HKLM-x32\...\InstallShield_{D6DBDC2A-E72C-4284-B6AD-6B3B61B4DABC}) (Version: 1.00.0000 - Ubisoft)
Far Cry 2 (HKLM-x32\...\{F2835483-37F2-4123-B4FE-0E77D58447F2}) (Version: 1.03.00 - Ubisoft)
FARO LS 1.1.501.0 (64bit) (HKLM-x32\...\{8A470330-70B2-49AD-86AF-79885EF9898A}) (Version: 5.1.0.30630 - FARO Scanner Production)
FARO LS 1.1.503.3 (64bit) (HKLM-x32\...\{1C05E654-FB81-4274-BF32-292E3707701D}) (Version: 5.3.3.38662 - FARO Scanner Production)
Garmin Communicator Plugin (HKLM-x32\...\{71DBFBF2-F7EB-4268-8485-9471D83C4E66}) (Version: 4.2.0 - Garmin Ltd or its subsidiaries)
Garmin Communicator Plugin x64 (HKLM\...\{70A381F1-C161-4D61-A20C-BE12FC6777DF}) (Version: 4.2.0 - Garmin Ltd or its subsidiaries)
Garmin Express (HKLM-x32\...\{50755d67-ae60-4e47-b3d6-ce44d01b5a95}) (Version: 4.0.15.0 - Garmin Ltd or its subsidiaries)
Garmin Express (HKLM-x32\...\{9FB8EC5B-03EE-463E-8F4F-84B525B986B7}) (Version: 4.0.15.0 - Garmin Ltd or its subsidiaries) Hidden
Garmin Express Tray (HKLM-x32\...\{1D91CBB5-4CB1-4757-B0FD-2122AF8AAB9E}) (Version: 4.0.15.0 - Garmin Ltd or its subsidiaries) Hidden
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 64.0.3282.119 - Google Inc.)
Google Earth Plug-in (HKLM-x32\...\{4AB54F11-2F8C-11E3-B09F-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
Google Earth Pro (HKLM-x32\...\{ECF2E224-42F5-4E50-B58E-94CA70E85697}) (Version: 7.3.0.3832 - Google)
Google Toolbar for Internet Explorer (HKLM-x32\...\{18455581-E099-4BA8-BC6B-F34B2F06600C}) (Version: 1.0.0 - Google Inc.) Hidden
Google Toolbar for Internet Explorer (HKLM-x32\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.8231.2252 - Google Inc.)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.7 - Google Inc.) Hidden
Google Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.25.11 - Google Inc.) Hidden
Haali Media Splitter (HKLM-x32\...\HaaliMkx) (Version:  - )
ICA (HKLM-x32\...\{00580795-581C-4587-B9F2-37320D7AB37F}) (Version: 14.2.0.1 - Corel Corporation) Hidden
ICA (HKLM-x32\...\{6688A246-F6E8-48AD-9806-8D5832E9F15D}) (Version: 16.1.0.45 - Corel Corporation) Hidden
ICA (HKLM-x32\...\{EE80DAA0-0071-475C-A222-F1782888FC55}) (Version: 19.5.0.35 - Corel Corporation) Hidden
IconHandler 64 bit (HKLM\...\{4E82E2E9-668B-4F8A-814A-78E163FCDBCD}) (Version: 2.0 - Corel Corporation) Hidden
Intel® Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1118 - Intel Corporation)
Intel® Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 10.0.0.1046 - Intel Corporation)
IPM_PSP_COM (HKLM-x32\...\{00BEE329-BAAB-49FF-9B66-55E4B12B9ADD}) (Version: 14.2.0.1 - Corel Corporation) Hidden
IPM_VS_Pro (HKLM-x32\...\{CCC10E8E-7FD1-4D55-87C2-D0A5ABC0A62B}) (Version: 16.0 - Corel Corporation) Hidden
IPM_VS_Pro64 (HKLM\...\{1BD7EE90-7C52-4142-B4DD-55C4F28F9EE7}) (Version: 19.0 - Corel Corporation) Hidden
iTunes (HKLM\...\{A31C5565-90D9-4615-AE13-94D86C3836C7}) (Version: 12.3.3.17 - Apple Inc.)
Java 8 Update 25 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218025F0}) (Version: 8.0.250 - Oracle Corporation)
LAME v3.99.3 (for Windows) (HKLM-x32\...\LAME_is1) (Version:  - )
Launcher Prerequisites (x64) (HKLM-x32\...\{c6c5a357-c7ca-4a5f-9789-3bb1af579253}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
Lightworks (HKLM-x32\...\{E94DD4E4-7746-472c-AA7B-1242FED0CFC8}) (Version: 11.1.0.0 - Lightworks)
Logitech Webcam Software (HKLM-x32\...\{D40EB009-0499-459c-A8AF-C9C110766215}) (Version: 2.51 - Logitech Inc.)
Malwarebytes version 3.3.1.2183 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.3.1.2183 - Malwarebytes)
Medal of Honor Allied Assault (HKLM-x32\...\{0DEA94ED-915A-4834-A87E-388D012C8E02}) (Version:  - )
Medal of Honor Allied Assault™ Spearhead (HKLM-x32\...\{7914BE1E-F186-4790-B8F4-9F63C52A41C1}) (Version:  - )
Melody Assistant (HKLM-x32\...\Melody Assistant) (Version: 7.6.3i - Myriad SARL)
Microsoft .NET Framework 4.7 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.7.02053 - Microsoft Corporation)
Microsoft Access database engine 2010 (English) (HKLM\...\{90140000-00D1-0409-1000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Camera Codec Pack (HKLM\...\{D553E8CC-5C56-4B06-AC1A-A443DFF31092}) (Version: 6.3.9723.0 - Microsoft Corporation)
Microsoft Office Professional Plus 2010 (HKLM-x32\...\Office14.PROPLUSR) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50907.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729 (HKLM\...\{2DFD8316-9EF1-3210-908C-4CB61961C1AC}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{527BBE2F-1FED-3D8B-91CB-4DB0F838E69E}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\...\{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft WSE 3.0 Runtime (HKLM-x32\...\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}) (Version: 3.0.5305.0 - Microsoft Corp.)
Mixxx 2.0.0 (HKU\S-1-5-21-3289118944-4034126387-1954186238-1000\...\Mixxx (2.0.0)) (Version: 2.0.0 - The Mixxx Development Team)
Movie Maker (HKLM-x32\...\{38F03569-A636-4CF3-BDDE-032C8C251304}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Movie Maker (HKLM-x32\...\{DD67BE4B-7E62-4215-AFA3-F123A800A389}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Mozilla Firefox 43.0.1 (x86 en-US) (HKU\S-1-5-21-3289118944-4034126387-1954186238-1000\...\Mozilla Firefox 43.0.1 (x86 en-US)) (Version: 43.0.1 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation)
MyDVD Content Pack 1 (HKLM-x32\...\{ADCF7AE3-8E36-4B80-9460-66B74B56927F}) (Version: 1.00.0000 - Corel Corporation)
Myst Online: Uru Live (remove only) (HKLM-x32\...\MOUL) (Version:  - )
NETGEAR Genie (HKLM-x32\...\NETGEAR Genie) (Version: 2.4.12.00 - NETGEAR Inc.)
NewBlue Film Effects for Windows (HKLM-x32\...\NewBlue Film Effects for Windows) (Version: 3.0 - NewBlue)
Nexus Mod Manager (HKLM\...\6af12c54-643b-4752-87d0-8335503010de_is1) (Version: 0.45.2 - Black Tree Gaming)
Nik Collection (HKLM-x32\...\Nik Collection) (Version: 1.2.11 - Google)
Nuance PaperPort 12 (HKLM-x32\...\{6C0A559F-8583-4B5A-8B50-20BEE15D8E64}) (Version: 12.1.0000 - Nuance Communications, Inc.)
Nuance PDF Viewer Plus (HKLM-x32\...\{28656860-4728-433C-8AD4-D1A930437BC8}) (Version: 5.30.3290 - Nuance Communications, Inc)
NVIDIA PhysX (HKLM-x32\...\{3F5C371F-8EA2-4F25-9D3D-D0B4526E3AEA}) (Version: 9.10.0513 - NVIDIA Corporation)
Origin (HKLM-x32\...\Origin) (Version: 9.1.10.2728 - Electronic Arts, Inc.)
Painter 13 - Contentx64 (HKLM\...\{A16926CB-C4BF-4FC9-8F99-200236731FCA}) (Version: 13.1 - Corel Corporation) Hidden
Painter 13 - Core (HKLM\...\{B1EA198B-FF19-46C9-84DE-E2F3D11619ED}) (Version: 13.1 - Corel Corporation) Hidden
Painter 13 - Corex64 (HKLM\...\{DA929FB1-A118-4F6E-9AD6-729633E84805}) (Version: 13.0 - Corel Corporation) Hidden
Painter 13 - EN (HKLM\...\{61F6F8FC-C448-418E-BF14-8B272DFDD51B}) (Version: 13.1 - Corel Corporation) Hidden
Painter 13 - Setup Files (HKLM\...\{EF449371-6B69-49C8-B789-76A0B0E3446B}) (Version: 13.1 - Corel Corporation) Hidden
Pando Media Booster (HKLM-x32\...\{980A182F-E0A2-4A40-94C1-AE0C1235902E}) (Version: 2.6.0.7 - Pando Networks Inc.)
PaperPort Image Printer 64-bit (HKLM\...\{715CAACC-579B-4831-A5F4-A83A8DE3EFE2}) (Version: 1.00.0001 - Nuance Communications, Inc.)
Paradise (HKLM-x32\...\Paradise_is1) (Version:  - Ubisoft)
Pinnacle Instant DVD Recorder (HKLM-x32\...\{C1212AE3-DBB9-4365-8473-F8ABC7B06BBB}) (Version: 2.6.0.118 - Pinnacle Systems)
Pinnacle Studio 12 (HKLM-x32\...\{D041EB9E-890A-4098-8F94-51DA194AC72A}) (Version: 12.1.3.6605 - Pinnacle Systems)
Pinnacle Video Driver (HKLM\...\{6DE721A5-5E89-4D74-994C-652BB3C0672E}) (Version: 12.1.0.029 - Pinnacle Systems)
PitchPerfect Musical Instrument Tuner (HKU\S-1-5-21-3289118944-4034126387-1954186238-1000\...\PitchPerfect) (Version: 2.12 - NCH Software)
Pixillion Image Converter (HKU\S-1-5-21-3289118944-4034126387-1954186238-1000\...\Pixillion) (Version: 2.75 - NCH Software)
POW (HKLM-x32\...\{CD277B3E-8043-496E-B83B-D53186A072AB}) (Version: 1.00.0000 - Wide Games) Hidden
POW (HKLM-x32\...\InstallShield_{CD277B3E-8043-496E-B83B-D53186A072AB}) (Version: 1.00.0000 - Wide Games)
Prism Video File Converter (HKU\S-1-5-21-3289118944-4034126387-1954186238-1000\...\Prism) (Version: 2.18 - NCH Software)
proDAD Adorage 3.0 (64bit) (HKLM\...\proDAD-Adorage-3.0) (Version: 3.0.114.1 - proDAD GmbH) Hidden
proDAD Mercalli 2.0 (64bit) (HKLM\...\proDAD-Mercalli-2.0) (Version: 2.0.123 - proDAD GmbH) Hidden
proDAD Mercalli 2.0 (HKLM-x32\...\proDAD-Mercalli-2.0) (Version: 2.0.106 - proDAD GmbH) Hidden
proDAD Route 4.0 (64bit) (HKLM\...\proDAD-HeroglyphRoute-4.0) (Version: 4.0.241.1 - proDAD GmbH) Hidden
proDAD Route 4.0 (HKLM-x32\...\proDAD-HeroglyphRoute-4.0) (Version: 4.0.209.2 - proDAD GmbH) Hidden
proDAD Script 4.0 (64bit) (HKLM\...\proDAD-HeroglyphScript-4.0) (Version: 4.0.241.1 - proDAD GmbH) Hidden
proDAD Script 4.0 (HKLM-x32\...\proDAD-HeroglyphScript-4.0) (Version: 4.0.209.2 - proDAD GmbH) Hidden
proDAD Vitascene 2.0 (64bit) (HKLM\...\proDAD-Vitascene-2.0) (Version: 2.0.241 - proDAD GmbH) Hidden
proDAD Vitascene 2.0 (HKLM-x32\...\proDAD-Vitascene-2.0) (Version: 2.0.203 - proDAD GmbH) Hidden
PS3 Media Server (HKLM-x32\...\PS3 Media Server) (Version: 1.90.1 - PS3 Media Server)
PSPPContent (HKLM-x32\...\{006CAAEF-CA96-4181-AC22-FE56D61432E4}) (Version: 14.2.0.1 - Corel Corporation) Hidden
PSPPHelp (HKLM-x32\...\{00D74A7A-F7AD-4D00-ABD2-0973836292C7}) (Version: 14.2.0.1 - Corel Corporation) Hidden
PSPPro64 (HKLM\...\{0015DE8E-8D9F-403E-8E5A-4098410E6125}) (Version: 14.2.0.1 - Corel Corporation) Hidden
PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.986 - Even Balance, Inc.)
QuickTime 7 (HKLM-x32\...\{FF59BD75-466A-4D5A-AD23-AAD87C5FD44C}) (Version: 7.79.80.95 - Apple Inc.)
Raptr (HKLM-x32\...\Raptr) (Version: 5.2.3-r114633-release - Raptr, Inc)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6141 - Realtek Semiconductor Corp.)
Revo Uninstaller 2.0.4 (HKLM\...\{A28DBDA2-3CC7-4ADC-8BFE-66D7743C6C97}_is1) (Version: 2.0.4 - VS Revo Group, Ltd.)
Scansoft PDF Professional (HKLM-x32\...\{068724F8-D8BE-4B43-8DDD-B9FE9E49FD76}) (Version:  - ) Hidden
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version:  - Microsoft)
Setup (HKLM-x32\...\{00D13418-7DDF-4D3D-A237-E297B103BB6B}) (Version: 14.2.0.1 - Corel Corporation) Hidden
Setup (HKLM-x32\...\{6C6EEA9F-3998-4E0D-B91F-43CB218C715C}) (Version: 16.1.0.45 - Corel Corporation) Hidden
Setup (HKLM-x32\...\{F8B95E3C-40A0-49CE-B5F9-3861F238B9FF}) (Version: 19.5.0.35 - Corel Corporation) Hidden
Share (HKLM-x32\...\{AD7DA145-3118-4D69-BE89-D3ED1510BD15}) (Version: 16.1.0.45 - Corel Corporation) Hidden
Share64 (HKLM\...\{3008095C-B516-4A5E-8B99-F0E113C21C72}) (Version: 16.1.0.45 - Corel Corporation) Hidden
Share64 (HKLM\...\{A61EEC3A-E37C-49A5-BE61-7AEE04F1A15D}) (Version: 19.5.0.35 - Corel Corporation) Hidden
Shared C Run-time for x64 (HKLM\...\{EF79C448-6946-4D71-8134-03407888C054}) (Version: 10.0.0 - McAfee)
SketchUp 2013 (HKLM-x32\...\{B75BC01B-4586-43F8-9349-D250DB98F26F}) (Version: 13.0.4812 - Trimble Navigation Limited)
Skype™ 7.0 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.0.102 - Skype Technologies S.A.)
SmartSound Common Data (HKLM-x32\...\{B8A2869E-30CA-40C5-9CF8-BD7354E57EF8}) (Version: 1.1.0 - SmartSound Software Inc.) Hidden
SmartSound Common Data (HKLM-x32\...\InstallShield_{B8A2869E-30CA-40C5-9CF8-BD7354E57EF8}) (Version: 1.1.0 - SmartSound Software Inc.)
SmartSound Quicktracks 5 (HKLM-x32\...\{2F8BA3FD-1FA9-4279-B696-712ABB12F09F}) (Version: 5.1.6 - SmartSound Software Inc.) Hidden
SmartSound Quicktracks 5 (HKLM-x32\...\InstallShield_{2F8BA3FD-1FA9-4279-B696-712ABB12F09F}) (Version: 5.1.6 - SmartSound Software Inc.)
Spotify (HKU\S-1-5-21-3289118944-4034126387-1954186238-1000\...\Spotify) (Version: 1.0.72.117.g6bd7cc73 - Spotify AB)
StarCraft II (HKLM-x32\...\StarCraft II) (Version:  - Blizzard Entertainment)
Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation)
theHunter Launcher (HKLM-x32\...\FBDFBE7F-2DB8-47E2-B88E-32F4A2A74AA8_is1) (Version: 620 - Expansive Worlds)
Unity Web Player (HKU\S-1-5-21-3289118944-4034126387-1954186238-1000\...\UnityWebPlayer) (Version:  - Unity Technologies ApS)
Uplay (HKLM-x32\...\Uplay) (Version: 2.0 - Ubisoft)
VideoStudio MyDVD (HKLM-x32\...\{7521A578-BDF3-412C-8959-57498EBBEDD9}) (Version: 1.0.129 - Corel Corporation) Hidden
VideoStudio MyDVD (HKLM-x32\...\{91345797-EF07-41D2-85F4-BFF200B6A0A3}) (Version: 1.0 - Corel)
Visual C++ 2008 - x64 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{6DA2B636-698A-3294-BF4A-B5E11B238CDD}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation)
Visual C++ 2008 - x64 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{8CCEA24C-51AE-3B71-9092-7D0C44DDA2DF}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation)
Visual C++ 2008 - x64 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{C3A57BB3-9AA6-3F6F-9395-6C062BDD5FC4}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation)
Visual C++ 2008 - x64 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{F6F09DD8-F39B-3A16-ADB9-C9E6B56903F9}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation)
Visual C++ 2008 - x86 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{04B34E21-5BEE-3D2B-8D3D-E3E80D253F64}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation)
Visual C++ 2008 - x86 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{14866AAD-1F23-39AC-A62B-7091ED1ADE64}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation)
Visual C++ 2008 - x86 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{4B90093A-5D9C-3956-8ABB-95848BE6EFAD}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation)
Visual C++ 2008 - x86 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{B42E259C-E4D4-37F1-A1B2-EB9C4FC5A04D}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation)
VLC media player 2.0.8 (HKLM-x32\...\VLC media player) (Version: 2.0.8 - VideoLAN)
VSClassic (HKLM-x32\...\{D0096E50-D99E-4178-A988-E5192B6F6B91}) (Version: 16.1.0.45 - Corel Corporation) Hidden
VSClassic64 (HKLM\...\{99B95309-4793-43D9-8F1C-EC086FC74CB5}) (Version: 19.5.0.35 - Corel Corporation) Hidden
VSHelp (HKLM-x32\...\{D9DD0D4F-6E5A-484D-AD8C-FD3BAF5D4450}) (Version: 16.1.0.45 - Corel Corporation) Hidden
VSPro (HKLM-x32\...\{D88D7ECD-F173-4A97-96F9-2B05C5DC90DC}) (Version: 16.1.0.45 - Corel Corporation) Hidden
VSUltimate64 (HKLM\...\{3F5D769B-346B-487A-851A-A1AF147D5B39}) (Version: 19.5.0.35 - Corel Corporation) Hidden
Wacom Tablet (HKLM\...\Wacom Tablet Driver) (Version: 6.3.17-3 - Wacom Technology Corp.)
WebTablet FB Plugin 32 bit (HKLM-x32\...\Wacom WebTabletPlugin for Internet Explorer and Netscape) (Version: 2.1.0.7 - Wacom Technology Corp.)
WebTablet FB Plugin 64 bit (HKLM\...\Wacom WebTabletPlugin for Internet Explorer and Netscape) (Version: 2.1.0.7 - Wacom Technology Corp.)
Windows Driver Package - Dynastream Innovations, Inc. ANT LibUSB Drivers (04/11/2012 1.2.40.201) (HKLM\...\F9D2A789F9CFF8CEC36B544F53877C80F1F73C46) (Version: 04/11/2012 1.2.40.201 - Dynastream Innovations, Inc.)
Windows Driver Package - Silicon Labs Software (DSI_SiUSBXp_3_1) USB  (02/06/2007 3.1) (HKLM\...\D1506E0025B5A3F9EB8270FE81C1EEDD9388B8A2) (Version: 02/06/2007 3.1 - Silicon Labs Software)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation)
Windows Media Encoder 9 Series (HKLM-x32\...\Windows Media Encoder 9) (Version:  - )
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{00F064D8-FEC3-48ac-B07D-39C314D1727B}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\ServiceModule.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{0B38CACA-3D3C-48EA-BEB5-7D95F4F6EE15}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{1481B385-759A-4B00-9257-E96357563999}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{1E8A29BA-827D-4031-A4A3-AE7999B402F6}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{2BCA857B-A18B-4AFA-B183-CC0E49C12058}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{3FC94EB5-AEBD-4f3f-A2A4-B6CE57113C01}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\RxAppDocView.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{4B40437B-8972-4444-BBE3-1588FF55F203}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{5544903C-2CCC-487C-91BB-F310B72A8E9B}\InprocServer32 -> AcETransmit.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{64B99FDB-1D85-447F-98C7-569DBDA723DB}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{7293E009-3015-4AD3-96EC-D42C36B5FCE3}\InprocServer32 -> AcETransmit.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{7BA16B3F-1AB3-4BD7-B959-52C4B8504EE9}\InprocServer32 -> AcInetUI.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{B2A579E0-A797-40B1-8AEE-A8F6404719F8}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{B8E7214B-25CA-4116-84CB-E86FB9625B36}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\ServiceModule.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{BF4CC07E-E9BB-40D6-873F-855B211033B9}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{C92F8F8C-8B2C-11d4-B872-0060B0EC020B}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\DtBridge.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{D7A1987D-4A73-11D1-9A4B-080009DCE505}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\ColorButton.Ocx => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{DB5D476B-3FF4-4E9D-A606-1E2B473BE571}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\AcInetUI.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{DF6525C2-6358-4B07-813D-708120C5FE1A}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{E70DE962-842A-4488-9481-1D0FD72A020F}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{F2D4F4E5-EEA1-46FF-A83B-A270C92DAE4B}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\DTInterop.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{F868EAEC-1B73-4F5E-BA73-90EBA94E75BE}\InprocServer32 -> axdb.dll => No File
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2010-11-18] (Igor Pavlov)
ContextMenuHandlers1-x32: [Autodesk.DWF.ContextMenu] -> {6C18531F-CA85-45F7-8278-FF33CF0A5964} => C:\Program Files (x86)\Common Files\Autodesk Shared\DWF Common\DWFShellExtension.dll [2012-01-06] (Autodesk, Inc.)
ContextMenuHandlers1-x32: [Corel PaintShop Pro X4] -> {CA34A346-C652-4F33-8CFF-FD6A91D9D64A} => c:\Program Files (x86)\Corel\Corel PaintShop Pro X4\PSPContextMenu64.dll [2012-05-11] (Corel Software, Inc.)
ContextMenuHandlers1-x32: [McCtxMenuFrmWrk] -> {CCA9EFD3-29ED-430A-BA6D-E6BBFF0A60C2} => c:\Program Files\McAfee\MSC\McCtxMenuFrmWrk.dll [2017-07-10] (McAfee, Inc.)
ContextMenuHandlers2: [Corel PaintShop Pro X4] -> {CA34A346-C652-4F33-8CFF-FD6A91D9D64A} => c:\Program Files (x86)\Corel\Corel PaintShop Pro X4\PSPContextMenu64.dll [2012-05-11] (Corel Software, Inc.)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-11-01] (Malwarebytes)
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2010-11-18] (Igor Pavlov)
ContextMenuHandlers4: [Corel PaintShop Pro X4] -> {CA34A346-C652-4F33-8CFF-FD6A91D9D64A} => c:\Program Files (x86)\Corel\Corel PaintShop Pro X4\PSPContextMenu64.dll [2012-05-11] (Corel Software, Inc.)
ContextMenuHandlers5: [ACE] -> {5E2121EE-0300-11D4-8D3B-444553540000} => C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\atiacm64.dll [2015-05-05] (Advanced Micro Devices, Inc.)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-11-01] (Malwarebytes)
ContextMenuHandlers6: [McCtxMenuFrmWrk] -> {CCA9EFD3-29ED-430A-BA6D-E6BBFF0A60C2} => c:\Program Files\McAfee\MSC\McCtxMenuFrmWrk.dll [2017-07-10] (McAfee, Inc.)
ContextMenuHandlers6_S-1-5-21-3289118944-4034126387-1954186238-1000: [InventorMenu] -> {6FDE7A70-351B-11d6-988B-0010B57A8BB7} =>  -> No File
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {12D74CB1-D95F-4343-A23A-6763BEAA42CB} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {36B966E5-B8D6-49FF-80A1-B1B4136C751E} - System32\Tasks\GarminUpdaterTask => C:\Program Files (x86)\Garmin\Express Self Updater\ExpressSelfUpdater.exe
Task: {4678B207-E35D-4E4E-BE9C-DABD7B77A524} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2016-02-23] (Apple Inc.)
Task: {4FAD17B9-4EEB-4CAD-803C-1B43BD161CEB} - \McAfeeLogon -> No File <==== ATTENTION
Task: {722FEA3D-3848-4774-A087-454E746A904A} - System32\Tasks\McAfee\McAfee Idle Detection Task
Task: {8A289A42-417A-45DD-A36F-2F581B27307B} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_28_0_0_137_pepper.exe [2018-01-09] (Adobe Systems Incorporated)
Task: {B3C459B3-51D7-4679-82D8-96BDEB286107} - \McAfee Remediation (Prepare) -> No File <==== ATTENTION
Task: {C207FBBE-E6C7-4912-AE92-66921801C453} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {D351F207-C8DE-43F2-9261-EE932A351F29} - System32\Tasks\GoogleUpdateTaskMachineUA1d0908d4088e86f => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {EC8807A2-747B-4034-AA6B-0A6DFA75F885} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2018-01-09] (Adobe Systems Incorporated)
Task: {EE2CC55D-8C31-44A8-94DC-A86099E682C2} - System32\Tasks\{16D7FACF-B0D1-48F8-9C02-E3A61932FA80} => "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" hxxp://ui.skype.com/ui/0/6.7.0.102/en/abandoninstall?page=tsProgressBar
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
 
==================== Shortcuts & WMI ========================
 
(The entries could be listed to be restored or removed.)
 
 
Shortcut: C:\Users\Teschke\Favorites\Dustin\NCH Software Download Site.lnk -> hxxp://www.nchsoftware.com/index.htm
 
ShortcutWithArgument: C:\Users\Teschke\Desktop\Games\Art & Media\VideoStudio X9 Training.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) -> www.studiobacklot.tv/videostudioX9
ShortcutWithArgument: C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Web Applications\_crx_mkdmfheflfmedmfjolgifliincdhfgdl\Slender Space.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) ->  --profile-directory=Default --app-id=mkdmfheflfmedmfjolgifliincdhfgdl
ShortcutWithArgument: C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Web Applications\_crx_jangaedeekciafhlanphhnalogmhefmo\theHunter.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) ->  --profile-directory=Default --app-id=jangaedeekciafhlanphhnalogmhefmo
ShortcutWithArgument: C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Web Applications\_crx_fplklihjpkinahlihcljhnnlnhnmmhdp\Counter Strike Online.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) ->  --profile-directory=Default --app-id=fplklihjpkinahlihcljhnnlnhnmmhdp
ShortcutWithArgument: C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Web Applications\_crx_bmekbplkjhgmljmbblmhmcnocafhaink\BeGone_ Last Stand HD.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) ->  --profile-directory=Default --app-id=bmekbplkjhgmljmbblmhmcnocafhaink
ShortcutWithArgument: C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Web Applications\_crx_alnfdikmbdfgkcbdodjcbmedanjinmkk\Beatlab.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) ->  --profile-directory=Default --app-id=alnfdikmbdfgkcbdodjcbmedanjinmkk
ShortcutWithArgument: C:\Users\Teschke\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\9501e18d7c2ab92e\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory="Profile 2"
ShortcutWithArgument: C:\Users\Teschke\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\225bb61db2f318c1\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory="Profile 3"
 
==================== Loaded Modules (Whitelisted) ==============
 
2013-04-18 01:51 - 2009-11-04 12:18 - 000189440 _____ () C:\Windows\system32\spool\PRTPROCS\x64\lxeadrpp.dll
2013-09-05 00:17 - 2013-09-05 00:17 - 004300456 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF
2010-10-20 14:23 - 2010-10-20 14:23 - 008801632 _____ () C:\Program Files\Microsoft Office\Office14\1033\GrooveIntlResource.dll
2013-11-16 13:28 - 2005-04-21 23:36 - 000143360 ____R () C:\Windows\system32\BrSNMP64.dll
2017-11-24 18:55 - 2017-12-12 04:53 - 002358728 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\MwacLib.dll
2017-11-24 18:55 - 2017-12-12 04:53 - 002301384 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\SelfProtectionSdk.dll
2016-09-23 19:08 - 2016-07-14 15:45 - 001661392 _____ () C:\Program Files\Tablet\Wacom\libxml2.dll
2017-06-01 14:58 - 2017-07-06 14:58 - 000595608 _____ () C:\Program Files\McAfee\MfeAV\RealProtectAMScanIf.dll
2017-06-01 14:58 - 2017-07-06 14:58 - 000584680 _____ () C:\Program Files\McAfee\MfeAV\RepairModule.dll
2018-01-24 15:48 - 2018-01-24 02:48 - 004433752 _____ () C:\Program Files (x86)\Google\Chrome\Application\64.0.3282.119\libglesv2.dll
2018-01-24 15:48 - 2018-01-24 02:48 - 000099672 _____ () C:\Program Files (x86)\Google\Chrome\Application\64.0.3282.119\libegl.dll
2017-07-17 12:30 - 2017-07-17 12:30 - 000863744 _____ () C:\Windows\mod_frst.exe
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
AlternateDataStreams: C:\Users\Public\AppData:CSM [460]
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mbamchameleon => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ModuleCoreService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mbamchameleon => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcapexe => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeaack => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeaack.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeavfk => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeavfk.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefire => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfemms => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeplk => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeplk.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfetdi2k => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfetdi2k.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfevtp => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ModuleCoreService => ""="Service"
 
==================== Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
IE trusted site: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000\...\dell.com -> dell.com
 
==================== Hosts content: ===============================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2009-07-13 21:34 - 2009-06-10 16:00 - 000000824 _____ C:\Windows\system32\Drivers\etc\hosts
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-3289118944-4034126387-1954186238-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Teschke\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 199.166.6.2 - 209.239.11.98
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
MSCONFIG\Services: AdobeARMservice => 2
MSCONFIG\Services: Apple Mobile Device Service => 2
MSCONFIG\Services: Garmin Device Interaction Service => 2
MSCONFIG\Services: iPod Service => 3
MSCONFIG\Services: lxea_device => 2
MSCONFIG\Services: NETGEARGenieDaemon => 3
MSCONFIG\Services: SkypeUpdate => 2
MSCONFIG\startupfolder: C:^Users^Admin^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2010 Screen Clipper and Launcher.lnk => C:\Windows\pss\OneNote 2010 Screen Clipper and Launcher.lnk.Startup
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: Akamai NetSession Interface => "C:\Users\Admin\AppData\Local\Akamai\netsession_win.exe"
MSCONFIG\startupreg: APSDaemon => "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
MSCONFIG\startupreg: Corel Update Helper => "c:\Program Files\Corel\Corel VideoStudio X9\pua.exe" /t
MSCONFIG\startupreg: fssui => "C:\Program Files (x86)\Windows Live\Family Safety\fsui.exe" -autorun
MSCONFIG\startupreg: GarminExpressTrayApp => "C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe"
MSCONFIG\startupreg: ISUSPM => C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe -scheduler
MSCONFIG\startupreg: iTunesHelper => "C:\Program Files\iTunes\iTunesHelper.exe"
MSCONFIG\startupreg: LWS => C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe -hide
MSCONFIG\startupreg: Raptr => "C:\Program Files (x86)\Raptr Inc\Raptr\raptrstub.exe" --startup
MSCONFIG\startupreg: StartCCC => "C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [{F16ECB23-8787-4B80-BA61-02E5DFB8EBCF}] => (Allow) C:\Windows\system32\lxeacoms.exe
FirewallRules: [{32F84DA2-A985-4218-8BA3-1E6EFEC4A1BB}] => (Allow) C:\Program Files (x86)\Pinnacle\Studio 12\Programs\RM.exe
FirewallRules: [{70073B3D-DB28-443F-A95D-846B197BA271}] => (Allow) C:\Program Files (x86)\Pinnacle\Studio 12\Programs\RM.exe
FirewallRules: [{AAF56D47-E704-4924-B85E-7A9E344D8A0A}] => (Allow) C:\Program Files (x86)\Pinnacle\Studio 12\Programs\Studio.exe
FirewallRules: [{E30DFCBC-0367-4E35-A307-4CCAA64F1165}] => (Allow) C:\Program Files (x86)\Pinnacle\Studio 12\Programs\Studio.exe
FirewallRules: [{789CAFB5-E298-41C2-B5F0-C0732DF3F8E3}] => (Allow) C:\Program Files (x86)\Pinnacle\Studio 12\Programs\umi.exe
FirewallRules: [{C02D669A-832C-4E6A-9558-829864F25463}] => (Allow) C:\Program Files (x86)\Pinnacle\Studio 12\Programs\umi.exe
FirewallRules: [{CF129E27-7FB6-48D9-BCE2-D463091BAEDF}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{83972B14-0AA1-4EDB-8FE9-E17058EC761F}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{46DFC88A-8ADB-4927-8684-D514B1F21923}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{08B5C287-8BD1-41AD-B820-1A9FE91F3209}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Breach\Breach.exe
FirewallRules: [{E6BB2592-510D-4A37-AF32-27B048F5EF6E}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Breach\Breach.exe
FirewallRules: [{B1DCB9FB-B224-4B2F-AB37-1C6C45EDBA83}] => (Allow) C:\Program Files (x86)\Steam\bin\steamservice.exe
FirewallRules: [{60327E3C-B0BF-455D-8B68-55C352A13F86}] => (Allow) C:\Program Files (x86)\Steam\bin\steamservice.exe
FirewallRules: [{8BE08515-A9DA-44E2-8B4C-5B863A5FCB9D}] => (Allow) C:\Program Files (x86)\Steam\bin\steamservice.exe
FirewallRules: [{583027FB-C067-45CE-81B3-CF85F9F6D9B2}] => (Allow) C:\Program Files (x86)\Steam\bin\steamservice.exe
FirewallRules: [{81C1C6D9-D3C6-43A0-8E29-EF861AE114E6}] => (Allow) C:\Program Files (x86)\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe
FirewallRules: [{56FA6971-E199-4C34-A879-B36C761D7CF1}] => (Allow) C:\Program Files (x86)\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe
FirewallRules: [{1B889BC2-A65B-4A01-8E24-273A5B660318}] => (Allow) C:\Program Files (x86)\UBISOFT\Assassin's Creed III\AC3SP.exe
FirewallRules: [{2F42C95D-B079-40E0-83CE-AE027A6C9A6F}] => (Allow) C:\Program Files (x86)\UBISOFT\Assassin's Creed III\AC3SP.exe
FirewallRules: [{8522CB95-9EFE-4A37-AF87-82E6C1DD6705}] => (Allow) C:\Program Files (x86)\UBISOFT\Assassin's Creed III\AC3MP.exe
FirewallRules: [{424DB30E-5233-4284-A693-8B4E858DAA16}] => (Allow) C:\Program Files (x86)\UBISOFT\Assassin's Creed III\AC3MP.exe
FirewallRules: [{7A861EB4-6A29-470D-912B-4A563E7AE6F7}] => (Allow) C:\Program Files (x86)\UBISOFT\Assassin's Creed III\AssassinsCreed3.exe
FirewallRules: [{2B63F9F1-4C21-4476-A80A-C8C4CEA573C8}] => (Allow) C:\Program Files (x86)\UBISOFT\Assassin's Creed III\AssassinsCreed3.exe
FirewallRules: [{FB653026-B559-4FD3-9828-40A5761DCF38}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Portal 2\portal2.exe
FirewallRules: [{44ECF51C-3A54-4861-9A4E-25E82FC6B9BB}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Portal 2\portal2.exe
FirewallRules: [{8B185093-81EA-4EF5-9BB8-D730D6CC8818}] => (Allow) C:\Program Files (x86)\Origin Games\Crysis 3\Bin32\Crysis3.exe
FirewallRules: [{8F55590B-9251-41AF-A5D8-9EAF2E8DBA24}] => (Allow) C:\Program Files (x86)\Origin Games\Crysis 3\Bin32\Crysis3.exe
FirewallRules: [{B6B2D2BA-1409-4C46-94AF-1F28FCFEA063}] => (Allow) C:\Program Files (x86)\StarCraft II\StarCraft II.exe
FirewallRules: [{5E3F7B0C-853E-49E7-9770-17AB687715B6}] => (Allow) C:\Program Files (x86)\StarCraft II\StarCraft II.exe
FirewallRules: [{D08C82D9-40F1-4664-A9F8-54CEE92A3954}] => (Allow) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
FirewallRules: [{2F80630E-EB85-4814-B7BC-8C206124D93C}] => (Allow) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
FirewallRules: [{C47E9DCF-FF13-49FD-A5D0-734E0BE00521}] => (Allow) C:\Program Files (x86)\theHunter\launcher\launcher.exe
FirewallRules: [{28C8990C-A52A-42C4-BA8D-1CD40DC43CE8}] => (Allow) C:\Program Files (x86)\theHunter\launcher\launcher.exe
FirewallRules: [{71709164-B6F2-4805-8AED-1D567AF8B96D}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Skyrim\SkyrimLauncher.exe
FirewallRules: [{95EEC40A-0EFF-447A-BA96-1DD5F4A38C05}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Skyrim\SkyrimLauncher.exe
FirewallRules: [{B558288E-5444-4364-B99F-389093101A3E}] => (Allow) C:\Program Files\Lightworks\Lightworks.exe
FirewallRules: [{F81BB928-631A-413E-898B-4ECEC619B624}] => (Allow) C:\Program Files\Lightworks\Lightworks.exe
FirewallRules: [{69CE75F1-E33F-42DC-85F9-7D176E2076E9}] => (Allow) C:\Program Files\Lightworks\ntcardvt.exe
FirewallRules: [{35ADB5EC-FEF0-41B2-8FD7-2B6163B06ACF}] => (Allow) C:\Program Files\Lightworks\ntcardvt.exe
FirewallRules: [{5D802E51-2D70-44E7-8A38-77ECEF4CC79F}] => (Allow) LPort=54925
FirewallRules: [{57298198-28C7-4134-8EE0-B517E2C6FE44}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\XCom-Enemy-Unknown\Binaries\Win32\XComGame.exe
FirewallRules: [{6159DE13-EE45-4911-B28C-8DB4F584A284}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\XCom-Enemy-Unknown\Binaries\Win32\XComGame.exe
FirewallRules: [{810F18D6-3CE1-43F1-9AC3-63041511EEE2}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{84C693B9-AEE3-4795-8165-7130A2F00058}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{02CCF350-0DBE-42BD-BFAB-0DF64DF10A13}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Team Fortress 2\hl2.exe
FirewallRules: [{FE8CAA48-E29E-44EC-9FFC-3C1945874D49}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Team Fortress 2\hl2.exe
FirewallRules: [{155E1331-C6F6-4586-B71D-833CC783B829}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{2CF8A5C6-7885-4901-A242-CF3CFDD7DC7D}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{5003C5AF-24F5-4759-AD3F-40E5648BF602}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Team Fortress 2\hl2.exe
FirewallRules: [{41EA998E-B4A6-4ED7-9191-256963A00DA1}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Team Fortress 2\hl2.exe
FirewallRules: [{72B155B7-7D16-414D-B3E7-92D341959244}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{DBE8985D-BEB3-4F04-8B14-2CFB90EDD6A7}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{99E88E28-5A6C-48BB-ADE3-EB7607181196}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{DDB7BF02-1D82-4E33-B090-A5C1664879B6}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{6984E421-BCAD-4E9D-A092-C103A0FDE4A1}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{0BE8AC0C-EE47-439C-AF37-A16BAD69A9DA}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{7D33A7E0-AF82-4C7C-BF7B-31FBFD51C52C}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{14D8F6D2-9205-4683-A37B-CA5CFA42A57A}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{F7049409-B56D-4686-93A8-11FF390C7229}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{B33040E5-F29A-4AD7-A33E-284AC16C3305}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{3C457650-44A0-4AA0-8389-D3A828ACA345}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Team Fortress 2\hl2.exe
FirewallRules: [{3DB6FA17-1D3B-437F-9D7A-ACBA9266E6DB}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Team Fortress 2\hl2.exe
FirewallRules: [{2325C2C9-0C15-4800-8C7D-F658C7FE2F00}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Team Fortress 2\hl2.exe
FirewallRules: [{545E5F7D-11D8-4E1F-A1A0-223BC753ADDC}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Team Fortress 2\hl2.exe
FirewallRules: [{B13739F0-FC71-4183-84C5-FA460F17C6B6}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.1040\Agent.exe
FirewallRules: [{34D763EF-0F01-41EF-B98D-AC336699F93E}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.1040\Agent.exe
FirewallRules: [{F49C1CFE-07C7-46DB-993A-238C1DAA027F}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2380\Agent.exe
FirewallRules: [{7AC1CA3F-4D02-4B48-AE8C-BE962C944C2C}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2380\Agent.exe
FirewallRules: [{A7D771AD-9480-4250-8920-DDEA6D1A8F4D}] => (Allow) C:\Program Files (x86)\StarCraft II\StarCraft II Public Test.exe
FirewallRules: [{EEFB70E1-9211-4B71-866B-7B0844415455}] => (Allow) C:\Program Files (x86)\StarCraft II\StarCraft II Public Test.exe
FirewallRules: [{01B75E99-AC2A-44D9-84AB-68D2E82C71AA}] => (Allow) C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
FirewallRules: [{7BE16534-A3E4-4E98-B6F2-48CA2B4BA3D0}] => (Allow) C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
FirewallRules: [{BE65226B-F667-46E5-A4E8-3C9036FC7D14}] => (Allow) C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
FirewallRules: [{0C669D17-C76D-41DF-A453-CA03F4D86CCF}] => (Allow) C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
FirewallRules: [{58732465-04C5-4EF0-80C0-EFD5391E965B}] => (Allow) C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
FirewallRules: [{E78FB3E8-57EA-49AA-B20A-EE3F70903C4C}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{47FE0346-4C48-4A50-8A77-18EA37EC9B07}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{EB77F046-CD9F-4C38-B7BF-F856EDD35F14}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{1D42B23D-921C-4E36-8B87-E2D90D0834FE}] => (Allow) LPort=2869
FirewallRules: [{0030EE09-4BAA-4E9F-A64C-F79381EFE987}] => (Allow) LPort=1900
FirewallRules: [{2A29E2C7-0BA4-483A-8F64-F52609F4A4FB}] => (Allow) C:\Program Files (x86)\Hearthstone\Hearthstone.exe
FirewallRules: [{D7A56D14-7B35-44EB-A09B-E36452560FCF}] => (Allow) C:\Program Files (x86)\Hearthstone\Hearthstone.exe
FirewallRules: [{556C1B3C-3F15-45C2-9D70-CA864CBDADE9}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2880\Agent.exe
FirewallRules: [{BE479DD9-893C-4D2F-AA5D-92D2E34946AF}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2880\Agent.exe
FirewallRules: [{7B41D613-A78E-4B35-A706-138CBF201879}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\JABIA\JaggedAllianceBIA.exe
FirewallRules: [{5CEF6981-E7B6-43D9-AF71-06491F6E4836}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\JABIA\JaggedAllianceBIA.exe
FirewallRules: [{EF58DAEF-A76C-47EA-B618-112AB60643C8}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{05CBE5C7-ACB2-46D4-9D26-0605916DB72F}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{00D1F223-C0CF-449A-A132-7618F3F6D4B9}] => (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe
FirewallRules: [{49D6483D-2FA4-48D4-89F3-6D0A21A794EB}] => (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe
FirewallRules: [{F2D3D2AE-086F-4199-81AE-4645F4CF383D}] => (Allow) C:\Program Files (x86)\UBISOFT\Far Cry 2\bin\FarCry2.exe
FirewallRules: [{C28F70F2-9FC7-476D-82E1-FF447DD35154}] => (Allow) C:\Program Files (x86)\UBISOFT\Far Cry 2\bin\FarCry2.exe
FirewallRules: [{46347C9C-4AE9-4DF5-A15C-0C2B674058C1}] => (Allow) C:\Program Files (x86)\UBISOFT\Far Cry 2\bin\FC2Launcher.exe
FirewallRules: [{89B65C34-E2D0-4987-90C6-7744EC436736}] => (Allow) C:\Program Files (x86)\UBISOFT\Far Cry 2\bin\FC2Launcher.exe
FirewallRules: [{D4FBEAC5-E679-4086-9DE4-3965604F11DA}] => (Allow) C:\Program Files (x86)\UBISOFT\Far Cry 2\bin\FC2Editor.exe
FirewallRules: [{D4C131B3-4646-4F46-9D4D-36DB2F00C7A5}] => (Allow) C:\Program Files (x86)\UBISOFT\Far Cry 2\bin\FC2Editor.exe
FirewallRules: [{5EE985CB-9EA4-4B04-BD6F-87E8DD8E7961}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{C1CFD1DC-DFC6-410F-9BB3-1A3681CA6D17}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{8AEEBC88-98FB-46C7-B479-EDF5818C072B}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{C6796B54-ACAF-4FB2-891E-36F8DCA5E6A1}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [TCP Query User{5A03840E-2B1C-4CA8-9516-B3A70A455B08}C:\program files (x86)\daide\quickstart\aiserver\aiserver.exe] => (Block) C:\program files (x86)\daide\quickstart\aiserver\aiserver.exe
FirewallRules: [UDP Query User{1080189C-898C-4245-BE92-EEAE22DAA1DD}C:\program files (x86)\daide\quickstart\aiserver\aiserver.exe] => (Block) C:\program files (x86)\daide\quickstart\aiserver\aiserver.exe
FirewallRules: [{BFC1DB99-77B5-4AC0-9464-240FCBA70894}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{881BA182-0CC1-4EA1-BE0C-E54B0436A797}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{01A5C88B-73F5-4B59-B01C-DCFCB756C85F}] => (Allow) C:\Program Files (x86)\Raptr\raptr.exe
FirewallRules: [{88AD7A8D-DFDA-4267-BE87-C2F534A45E34}] => (Allow) C:\Program Files (x86)\Raptr\raptr.exe
FirewallRules: [{5326A4A9-4F4F-4B39-8D03-C662C07A7E2B}] => (Allow) C:\Program Files (x86)\Raptr\raptr_im.exe
FirewallRules: [{07ADBAC2-B989-4F09-ACF2-8FF03CC263A6}] => (Allow) C:\Program Files (x86)\Raptr\raptr_im.exe
FirewallRules: [{B500E6F5-4E07-45DE-B0B5-8DB571C79FCC}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2cfg.exe
FirewallRules: [{EB3C113F-C0B6-4EFB-9DA7-BBED24F557F7}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2cfg.exe
FirewallRules: [{BFAA2466-2AB3-4949-8A00-5AF6CB3C3157}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{30820C6B-C2A0-4A23-9D32-72EE33068630}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{2CC22695-DA31-45BB-8966-C7F013D0D69F}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{C8E47915-3EB8-4F4C-81F0-65557EB69481}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{E00F6D8F-53E9-4771-8BDC-4BB62EB4B4F1}] => (Allow) C:\Program Files\iTunes\iTunes.exe
FirewallRules: [{256D452F-606F-4DF8-99E8-89B2AAF0C1AC}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Dirty Bomb\Binaries\Win32\ShooterGame-Win32-Shipping.exe
FirewallRules: [{3F642655-712C-4445-B6DB-35B2D6CA2493}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Dirty Bomb\Binaries\Win32\ShooterGame-Win32-Shipping.exe
FirewallRules: [{C38C6387-76A9-43F2-96FD-929D9B227CE4}] => (Allow) C:\Program Files (x86)\Raptr Inc\Raptr\raptr.exe
FirewallRules: [{91E9E38B-7E45-4B09-8F10-3F90E197E61E}] => (Allow) C:\Program Files (x86)\Raptr Inc\Raptr\raptr.exe
FirewallRules: [{AE2791DC-926C-4224-B936-4CCCD6159DD8}] => (Allow) C:\Program Files (x86)\Raptr Inc\Raptr\raptr_im.exe
FirewallRules: [{DDA14856-5CA6-4116-A154-8834570ACDDB}] => (Allow) C:\Program Files (x86)\Raptr Inc\Raptr\raptr_im.exe
FirewallRules: [TCP Query User{36F416F9-5BD2-4CF3-BD5C-FAF7440DCC03}C:\users\admin\appdata\local\akamai\netsession_win.exe] => (Allow) C:\users\admin\appdata\local\akamai\netsession_win.exe
FirewallRules: [UDP Query User{E84D30D4-10B8-462A-B495-7155F8D93547}C:\users\admin\appdata\local\akamai\netsession_win.exe] => (Allow) C:\users\admin\appdata\local\akamai\netsession_win.exe
FirewallRules: [{67209B8B-EF3E-414D-9C12-1BA3BBEC131B}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [{7D993D04-3A22-4717-9405-31BFD263C246}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [{18B5C50C-A5C5-4007-A6A5-4121C385EF08}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Dirty Bomb\DirtyBombLauncher.exe
FirewallRules: [{51EAC435-D1B9-47AF-9AC1-8CFE2B8E3ECC}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Dirty Bomb\DirtyBombLauncher.exe
FirewallRules: [TCP Query User{58174CC5-FF62-4FB3-965C-06C7FA8C10B9}C:\program files (x86)\starcraft ii\versions\base51149\sc2_x64.exe] => (Block) C:\program files (x86)\starcraft ii\versions\base51149\sc2_x64.exe
FirewallRules: [UDP Query User{5E8D7FC0-8562-4069-82DC-BA8D65674A71}C:\program files (x86)\starcraft ii\versions\base51149\sc2_x64.exe] => (Block) C:\program files (x86)\starcraft ii\versions\base51149\sc2_x64.exe
FirewallRules: [TCP Query User{AC30B663-D262-4232-86A1-ECF9527D3B52}C:\program files (x86)\starcraft ii\versions\base51702\sc2_x64.exe] => (Block) C:\program files (x86)\starcraft ii\versions\base51702\sc2_x64.exe
FirewallRules: [UDP Query User{EF86E717-134A-42CB-9C52-BE75AA178E84}C:\program files (x86)\starcraft ii\versions\base51702\sc2_x64.exe] => (Block) C:\program files (x86)\starcraft ii\versions\base51702\sc2_x64.exe
FirewallRules: [TCP Query User{D15692F9-2135-4005-B6C9-F8BDB276BF53}C:\program files (x86)\starcraft ii\support\sc2editor.exe] => (Block) C:\program files (x86)\starcraft ii\support\sc2editor.exe
FirewallRules: [UDP Query User{3E00FE2D-5D60-4B84-9B9D-A57BD840EDCB}C:\program files (x86)\starcraft ii\support\sc2editor.exe] => (Block) C:\program files (x86)\starcraft ii\support\sc2editor.exe
FirewallRules: [TCP Query User{2D5D6177-FA3C-4AD5-A788-BC88D5B8D392}C:\users\teschke\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\teschke\appdata\roaming\spotify\spotify.exe
FirewallRules: [UDP Query User{9CC7B4A3-0435-4270-AEE4-EA906E29B995}C:\users\teschke\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\teschke\appdata\roaming\spotify\spotify.exe
FirewallRules: [{BCE6458B-7347-4CAD-A3C5-5D36B837848A}] => (Allow) C:\Program Files (x86)\Google\Chrome Remote Desktop\63.0.3239.32\remoting_host.exe
FirewallRules: [TCP Query User{8016F667-550B-47F6-A163-A6ECC5DEFC51}C:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe
FirewallRules: [UDP Query User{4290882B-C43B-4A07-A3D5-DBF0EF281827}C:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe
FirewallRules: [TCP Query User{C84F8A5F-D20C-4E1E-8778-CE5C3E7834E9}C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe
FirewallRules: [UDP Query User{C7D11005-6FD5-413E-BD97-07843AFF24CD}C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe
FirewallRules: [TCP Query User{1D5A22B0-A2B6-4F48-85EF-3247698D1E3A}C:\program files\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe] => (Allow) C:\program files\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe
FirewallRules: [UDP Query User{1D1F93FA-574A-4942-8CD9-98A7DFADBBB6}C:\program files\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe] => (Allow) C:\program files\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe
FirewallRules: [{2834D457-F5FF-4DBE-BAAA-A4CD36B884A6}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
 
==================== Restore Points =========================
 
25-01-2018 21:55:22 Scheduled Checkpoint
27-01-2018 18:40:44 Revo Uninstaller's restore point - McAfee AntiVirus Plus
27-01-2018 18:48:48 Revo Uninstaller's restore point - McAfee Virtual Technician
27-01-2018 18:49:32 Revo Uninstaller's restore point - McAfee Virtual Technician
27-01-2018 18:50:57 Revo Uninstaller's restore point - McAfee WebAdvisor
27-01-2018 19:07:10 Restore Point Created by FRST
 
==================== Faulty Device Manager Devices =============
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (01/27/2018 07:06:50 PM) (Source: VSS) (EventID: 8194) (User: )
Description: Volume Shadow Copy Service error: Unexpected error querying for the IVssWriterCallback interface.  hr = 0x80070005, Access is denied.
.
This is often caused by incorrect security settings in either the writer or requestor process.
 
 
Operation:
   Gathering Writer Data
 
Context:
   Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220}
   Writer Name: System Writer
   Writer Instance ID: {08c0e60e-7ecd-42fc-8361-cf10a6256403}
 
Error: (01/27/2018 07:02:52 PM) (Source: WTabletServicePro) (EventID: 1) (User: )
Description: Event-ID 1
 
Error: (01/27/2018 07:02:46 PM) (Source: WTabletServicePro) (EventID: 1) (User: )
Description: Event-ID 1
 
Error: (01/27/2018 06:40:39 PM) (Source: VSS) (EventID: 8194) (User: )
Description: Volume Shadow Copy Service error: Unexpected error querying for the IVssWriterCallback interface.  hr = 0x80070005, Access is denied.
.
This is often caused by incorrect security settings in either the writer or requestor process.
 
 
Operation:
   Gathering Writer Data
 
Context:
   Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220}
   Writer Name: System Writer
   Writer Instance ID: {57ca24a8-467d-4f41-8463-9857ac0ffaa9}
 
Error: (01/27/2018 03:05:10 PM) (Source: WTabletServicePro) (EventID: 1) (User: )
Description: Event-ID 1
 
Error: (01/27/2018 03:05:03 PM) (Source: WTabletServicePro) (EventID: 1) (User: )
Description: Event-ID 1
 
Error: (01/27/2018 01:15:11 PM) (Source: Desktop Window Manager) (EventID: 9020) (User: )
Description: The Desktop Window Manager has encountered a fatal error (0x80070008)
 
Error: (01/27/2018 12:33:19 PM) (Source: WTabletServicePro) (EventID: 1) (User: )
Description: Event-ID 1
 
Error: (01/27/2018 12:33:13 PM) (Source: WTabletServicePro) (EventID: 1) (User: )
Description: Event-ID 1
 
Error: (01/26/2018 07:38:10 PM) (Source: WTabletServicePro) (EventID: 1) (User: )
Description: Event-ID 1
 
 
System errors:
=============
Error: (01/27/2018 08:28:41 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The McAfee Platform Services service failed to start due to the following error: 
The system cannot find the file specified.
 
Error: (01/27/2018 08:28:41 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The McAfee Platform Services service failed to start due to the following error: 
The system cannot find the file specified.
 
Error: (01/27/2018 08:28:41 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The McAfee Platform Services service failed to start due to the following error: 
The system cannot find the file specified.
 
Error: (01/27/2018 08:28:41 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The McAfee Platform Services service failed to start due to the following error: 
The system cannot find the file specified.
 
Error: (01/27/2018 08:28:41 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The McAfee Platform Services service failed to start due to the following error: 
The system cannot find the file specified.
 
Error: (01/27/2018 08:28:41 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The McAfee Platform Services service failed to start due to the following error: 
The system cannot find the file specified.
 
Error: (01/27/2018 08:28:41 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The McAfee Platform Services service failed to start due to the following error: 
The system cannot find the file specified.
 
Error: (01/27/2018 08:28:41 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The McAfee Platform Services service failed to start due to the following error: 
The system cannot find the file specified.
 
Error: (01/27/2018 08:28:41 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The McAfee Platform Services service failed to start due to the following error: 
The system cannot find the file specified.
 
Error: (01/27/2018 08:28:41 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The McAfee Platform Services service failed to start due to the following error: 
The system cannot find the file specified.
 
 
CodeIntegrity:
===================================
  Date: 2017-09-14 03:39:35.233
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\kernel32.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-09-04 08:07:38.756
  Description: Windows is unable to verify the integrity of the file \Device\HarddiskVolume2\$Windows.~BT\Updates\Critical\8e08ca47-f6ba-409d-82de-698e324c0004\amd64_microsoft-windows-errorreportingfaults_31bf3856ad364e35_10.0.10074.1_none_f3153036f55ab3f5\werfault.exe because the signing certificate has been revoked.  Check with the publisher to see if a new signed version of the kernel module is available.
 
  Date: 2015-09-04 08:07:38.749
  Description: Windows is unable to verify the integrity of the file \Device\HarddiskVolume2\$Windows.~BT\Updates\Critical\8e08ca47-f6ba-409d-82de-698e324c0004\amd64_microsoft-windows-errorreportingfaults_31bf3856ad364e35_10.0.10074.1_none_f3153036f55ab3f5\werfault.exe because the signing certificate has been revoked.  Check with the publisher to see if a new signed version of the kernel module is available.
 
  Date: 2015-09-04 08:07:38.743
  Description: Windows is unable to verify the integrity of the file \Device\HarddiskVolume2\$Windows.~BT\Updates\Critical\8e08ca47-f6ba-409d-82de-698e324c0004\amd64_microsoft-windows-errorreportingfaults_31bf3856ad364e35_10.0.10074.1_none_f3153036f55ab3f5\werfault.exe because the signing certificate has been revoked.  Check with the publisher to see if a new signed version of the kernel module is available.
 
  Date: 2015-09-04 08:07:38.640
  Description: Windows is unable to verify the integrity of the file \Device\HarddiskVolume2\$Windows.~BT\Updates\Critical\8e08ca47-f6ba-409d-82de-698e324c0004\amd64_microsoft-windows-errorreportingcore_31bf3856ad364e35_10.0.10074.1_none_a384c5aabe759ea5\wermgr.exe because the signing certificate has been revoked.  Check with the publisher to see if a new signed version of the kernel module is available.
 
  Date: 2015-09-04 08:07:38.629
  Description: Windows is unable to verify the integrity of the file \Device\HarddiskVolume2\$Windows.~BT\Updates\Critical\8e08ca47-f6ba-409d-82de-698e324c0004\amd64_microsoft-windows-errorreportingcore_31bf3856ad364e35_10.0.10074.1_none_a384c5aabe759ea5\wermgr.exe because the signing certificate has been revoked.  Check with the publisher to see if a new signed version of the kernel module is available.
 
  Date: 2015-09-04 08:07:38.621
  Description: Windows is unable to verify the integrity of the file \Device\HarddiskVolume2\$Windows.~BT\Updates\Critical\8e08ca47-f6ba-409d-82de-698e324c0004\amd64_microsoft-windows-errorreportingcore_31bf3856ad364e35_10.0.10074.1_none_a384c5aabe759ea5\wermgr.exe because the signing certificate has been revoked.  Check with the publisher to see if a new signed version of the kernel module is available.
 
 
==================== Memory info =========================== 
 
Processor: Intel® Core™ i7-2600 CPU @ 3.40GHz
Percentage of memory in use: 26%
Total physical RAM: 12270.45 MB
Available physical RAM: 9061.42 MB
Total Virtual: 24539.06 MB
Available Virtual: 21330.94 MB
 
==================== Drives ================================
 
Drive c: () (Fixed) (Total:931.41 GB) (Free:46.39 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: A61DA447)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=931.4 GB) - (Type=07 NTFS)
 
==================== End of Addition.txt ============================


#12 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 36,617 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:07:50 PM

Posted 27 January 2018 - 08:49 PM

Looks like the FRST.txt report got cut off on the top. Is there more to it?

Edited by Oh My!, 27 January 2018 - 08:49 PM.

Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#13 Dustint

Dustint
  • Topic Starter

  • Members
  • 26 posts
  • OFFLINE
  •  
  • Local time:09:50 PM

Posted 27 January 2018 - 08:52 PM

Strange. That was all that was in the file. I'll delete those txt files and try running the scan again.



#14 Dustint

Dustint
  • Topic Starter

  • Members
  • 26 posts
  • OFFLINE
  •  
  • Local time:09:50 PM

Posted 27 January 2018 - 08:57 PM

Looks like it worked better this time. This time I closed my browser and the McAfee pop-up window before running. Maybe that's what did it. Here's the first file:

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 27.01.2018
Ran by Teschke (administrator) on XPS (27-01-2018 20:53:00)
Running from C:\Users\Teschke\Desktop
Loaded Profiles: Teschke (Available Profiles: Teschke & Admin)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe
(McAfee, Inc.) C:\Windows\System32\mfevtps.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\ModuleCore\ModuleCoreService.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\ModuleCore\ModuleCoreService.exe
(McAfee, Inc.) C:\Windows\System32\mfevtps.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\CSP\2.5.312.0\McCSPServiceHost.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Wacom\WTabletServicePro.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Wacom\Wacom_TabletUser.exe
(Wacom Technology) C:\Program Files\Tablet\Wacom\WacomHost.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Wacom\Wacom_TouchUser.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
(Intel Security, Inc.) C:\Program Files\Common Files\Intel Security\PEF\CORE\PEFService.exe
(McAfee, Inc.) C:\Program Files\McAfee\MfeAV\MfeAVSvc.exe
(McAfee, Inc.) C:\Program Files\McAfee\MfeAV\McVsShld.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\Platform\McUICnt.exe
(McAfee LLC.) C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe
 
==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [10920552 2010-06-22] (Realtek Semiconductor)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe [283160 2010-09-13] (Intel Corporation)
HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKLM-x32\...\Run: [IndexSearch] => C:\Program Files (x86)\Nuance\PaperPort\IndexSearch.exe [46368 2010-03-09] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [PaperPort PTD] => C:\Program Files (x86)\Nuance\PaperPort\pptd40nt.exe [29984 2010-03-09] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [PPort12reminder] => "C:\Program Files (x86)\Nuance\PaperPort\Ereg\Ereg.exe" -r "C:\ProgramData\ScanSoft\PaperPort\12\Config\Ereg\Ereg.ini"
HKLM-x32\...\Run: [PDFHook] => C:\Program Files (x86)\Nuance\PDF Viewer Plus\pdfpro5hook.exe [636192 2010-03-05] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [PDF5 Registry Controller] => C:\Program Files (x86)\Nuance\PDF Viewer Plus\RegistryController.exe [62752 2010-03-05] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [ControlCenter4] => C:\Program Files (x86)\ControlCenter4\BrCcBoot.exe [143360 2012-09-06] (Brother Industries, Ltd.)
HKLM-x32\...\Run: [BrStsMon00] => C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe [3076096 2012-06-06] (Brother Industries, Ltd.)
HKU\S-1-5-21-3289118944-4034126387-1954186238-1000\...\Run: [OfficeSyncProcess] => C:\Program Files (x86)\Microsoft Office\Office14\MSOSYNC.EXE [721504 2015-09-02] (Microsoft Corporation)
HKU\S-1-5-21-3289118944-4034126387-1954186238-1000\...\Run: [ISUSPM] => C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe [222496 2009-05-05] (Acresso Corporation)
HKU\S-1-5-21-3289118944-4034126387-1954186238-1000\...\Run: [Spotify Web Helper] => C:\Users\Teschke\AppData\Roaming\Spotify\SpotifyWebHelper.exe [780688 2018-01-18] (Spotify Ltd)
HKU\S-1-5-21-3289118944-4034126387-1954186238-1000\...\Policies\system: [LogonHoursAction] 2
HKU\S-1-5-21-3289118944-4034126387-1954186238-1000\...\Policies\system: [DontDisplayLogonHoursWarnings] 1
HKU\S-1-5-21-3289118944-4034126387-1954186238-1000\...\MountPoints2: {ecb585ac-a7d5-11e2-9d96-806e6f6e6963} - D:\autoRcd.exe
HKU\S-1-5-18\...\Run: [GarminExpressTrayApp] => C:\Program Files (x86)\Garmin\Express Tray\tray.exe [1010008 2015-04-08] (Garmin Ltd. or its subsidiaries)
HKU\S-1-5-18\...\RunOnce: [SPReview] => "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"hxxp://go.microsoft.com/fwlink/?LinkID=122915" /build:7601
Startup: C:\Users\Teschke\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk [2018-01-25]
ShortcutTarget: OneNote 2010 Screen Clipper and Launcher.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
GroupPolicy\User: Restriction <==== ATTENTION
GroupPolicyUsers\S-1-5-21-3289118944-4034126387-1954186238-1003\User: Restriction <==== ATTENTION
GroupPolicyUsers\S-1-5-21-3289118944-4034126387-1954186238-1000\User: Restriction <==== ATTENTION
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Tcpip\Parameters: [DhcpNameServer] 199.166.6.2 209.239.11.98
Tcpip\..\Interfaces\{E3D08391-DA71-4B1B-9F02-0CCEDCEF505A}: [DhcpNameServer] 199.166.6.2 209.239.11.98
 
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-3289118944-4034126387-1954186238-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.ca/
SearchScopes: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000 -> DefaultScope {49DABC51-C6C4-4160-8197-B334814CCCE5} URL = hxxps://search.yahoo.com/search?fr=mcafee&type=C011US91038D20130825&p={searchTerms}
SearchScopes: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000 -> {49DABC51-C6C4-4160-8197-B334814CCCE5} URL = hxxps://search.yahoo.com/search?fr=mcafee&type=C011US91038D20130825&p={searchTerms}
SearchScopes: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000 -> {49DE4C69-1A45-422D-97A4-9B692ECF5F83} URL = hxxps://search.yahoo.com/search?fr=mcafee&type=C011US0D19700101&p={searchTerms}
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-04-27] (Google Inc.)
BHO: McAfee WebAdvisor BHO -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> c:\PROGRA~2\mcafee\SITEAD~1\x64\mcieplg.dll => No File
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: PlusIEEventHelper Class -> {551A852F-39A6-44A7-9C13-AFBEC9185A9D} -> C:\Program Files (x86)\Nuance\PDF Viewer Plus\Bin\PlusIEContextMenu.dll [2009-02-06] (Zeon Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\ssv.dll [2014-10-20] (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2016-04-27] (Google Inc.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\jp2ssv.dll [2014-10-20] (Oracle Corporation)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-04-27] (Google Inc.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2016-04-27] (Google Inc.)
DPF: HKLM-x32 {A2505C6C-6F17-456F-89D2-4301FBDC6EC7} hxxps://ssl.grhosp.on.ca/nortel_cacheable/iewiper.cab
DPF: HKLM-x32 {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} hxxps://join-test.webex.com/client/WBXclient-T30L10NSP13EP1-10006/webex/ieatgpc1.cab
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\McAfee\MSC\McSnIePl64.dll [2017-07-10] (McAfee, Inc.)
Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\MSC\McSnIePl.dll [2017-07-10] (McAfee, Inc.)
 
FireFox:
========
FF DefaultProfile: gd2bren1.default
FF ProfilePath: C:\Users\Teschke\AppData\Roaming\Mozilla\Firefox\Profiles\gd2bren1.default [2017-12-01]
FF Extension: (Firefox Hotfix) - C:\Users\Teschke\AppData\Roaming\Mozilla\Firefox\Profiles\gd2bren1.default\Extensions\firefox-hotfix@mozilla.org.xpi [2016-12-08] [Legacy]
FF HKLM\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor\e10ssaffplg.xpi => not found
FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor\e10ssaffplg.xpi => not found
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_28_0_0_137.dll [2018-01-09] ()
FF Plugin: @garmin.com/GpsControl -> C:\Program Files\Garmin GPS Plugin\npGarmin.dll [2014-03-31] (GARMIN Corp.)
FF Plugin: @mcafee.com/MSC,version=10 -> c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL [2017-07-10] ()
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin: @wacom.com/wtPlugin,version=2.1.0.7 -> C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll [2014-03-25] (Wacom)
FF Plugin: wacom.com/WacomTabletPlugin -> C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll [2014-03-25] (Wacom)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_28_0_0_137.dll [2018-01-09] ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2016-03-08] ()
FF Plugin-x32: @garmin.com/GpsControl -> C:\Program Files (x86)\Garmin GPS Plugin\npGarmin.dll [2014-03-31] (GARMIN Corp.)
FF Plugin-x32: @java.com/DTPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll [2014-10-20] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\plugin2\npjp2.dll [2014-10-20] (Oracle Corporation)
FF Plugin-x32: @mcafee.com/MSC,version=10 -> c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL [2017-07-10] ()
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-14] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-14] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.8 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2013-07-30] (VideoLAN)
FF Plugin-x32: @wacom.com/wtPlugin,version=2.1.0.7 -> C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll [2014-03-25] (Wacom)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2013-05-11] (Adobe Systems Inc.)
FF Plugin-x32: wacom.com/WacomTabletPlugin -> C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll [2014-03-25] (Wacom)
FF Plugin HKU\S-1-5-21-3289118944-4034126387-1954186238-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Teschke\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2015-08-21] (Unity Technologies ApS)
FF Plugin HKU\S-1-5-21-3289118944-4034126387-1954186238-1000: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [2016-01-14] ()
 
Chrome: 
=======
CHR DefaultProfile: Profile 3
CHR HomePage: Profile 3 -> hxxps://www.google.ca/
CHR StartupUrls: Profile 3 -> "hxxp://www.google.ca/"
CHR DefaultSearchURL: Profile 3 -> hxxps://search.yahoo.com/search?fr=mcafee&type=C211US0D20170114&p={searchTerms}
CHR DefaultSearchKeyword: Profile 3 -> mcafee
CHR Profile: C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default [2018-01-27]
CHR Extension: (BeGone Guerra Online) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\ahcchnfnladlkddlceegencfccjcfnjp [2013-09-19]
CHR Extension: (Plants vs. Zombies HD) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\ahdfeknjbgfbkmemaoffkebceonhcjfd [2013-09-19]
CHR Extension: (Beatlab) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\alnfdikmbdfgkcbdodjcbmedanjinmkk [2015-04-20]
CHR Extension: (Google Drive) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-20]
CHR Extension: (UJAM - Make your music.) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdiogojbmdncjdpljocafnigiokgmci [2013-09-19]
CHR Extension: (Free Running 2 3D) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\bakechaaagjbdhedidbfifkembmkhafl [2013-09-19]
CHR Extension: (BeGone: Last Stand HD) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\bmekbplkjhgmljmbblmhmcnocafhaink [2013-09-19]
CHR Extension: (Battlefield Heroes) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\cehdakiococlfmjcbebbkjkfjhbieknh [2013-09-21]
CHR Extension: (Rush Team) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\ecdnoeebfjlplfkljdedokbcmebojbpb [2013-10-10]
CHR Extension: (Freefall Tournament) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\encjogopgacdjlkmpdknhlfnanoihodh [2015-03-18]
CHR Extension: (Music Maker) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\epnoajccaiifhpidemmcdamilpeblipc [2014-03-27]
CHR Extension: (Google Play Music) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\fahmaaghhglfmonjliepjlchgpgfmobi [2015-11-18]
CHR Extension: (PicMonkey) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\fgdgokchhicmaiacmgegjnppjkgogdhm [2014-10-24]
CHR Extension: (SiteAdvisor) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2015-07-02]
CHR Extension: (Counter Strike Online ) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\fplklihjpkinahlihcljhnnlnhnmmhdp [2013-09-19]
CHR Extension: (Google Docs Offline) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-11-18]
CHR Extension: (Unlimited Free VPN - Hola) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkojfkhlekighikafcpjkiklfbnlmeio [2015-11-28]
CHR Extension: (Happy Wheels) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\hpljdpjoahbnnfilkiilnfdkdbfiabfc [2013-09-19]
CHR Extension: (Apocalypse City) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifkogipjfpemebgfjelkfoifapppddeh [2013-09-19]
CHR Extension: (Digital BeatMaker) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihjdooenciklfgogkejekglpoeedphmc [2014-03-27]
CHR Extension: (90`s Games) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\illbbfoihflomkbpcaaakhijinbnejom [2015-03-14]
CHR Extension: (theHunter) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\jangaedeekciafhlanphhnalogmhefmo [2013-09-19]
CHR Extension: (Super Mario Bros HD) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmhilnfngnmcnlekfgcglogafjkahoml [2013-09-19]
CHR Extension: (Eyes - The Horror Game) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\jojpkokphfnjlhbnbcilnhgnkkobkngd [2013-09-19]
CHR Extension: (Resident Evil) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\kelgpfmgciingekkpfaikcjmcomfikgp [2013-09-19]
CHR Extension: (Aqua Planet) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\kkfobnmhjmjkgojmfldhnkmfcdjjakhb [2013-09-20]
CHR Extension: (Dead Zed Zombie) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\lcdhiflblofckjcpphgcoajnebhbdpja [2013-09-19]
CHR Extension: (Counter-Strike-Online 2) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\liihamdfalaafmojcdakajejmcbnjkce [2013-09-19]
CHR Extension: (Plink) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\loeiekheegipnnbcfbfkanbbegkhjjcm [2013-09-20]
CHR Extension: (Slender Space) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkdmfheflfmedmfjolgifliincdhfgdl [2013-09-19]
CHR Extension: (Mixify) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkjlbfglfefcmkmglakdocbgnggeieno [2014-03-27]
CHR Extension: (Plants vs Zombies) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmcegpfdgcoclcdfkjahiimlikdpnina [2013-09-21]
CHR Extension: (BeGone) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndfpieflbjbdpgklkeolbmbdkfdiicfk [2015-06-27]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-07-23]
CHR Extension: (Mini Ninjas) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\oijfbknbncemokdnlboeabbcfhobechi [2013-09-19]
CHR Extension: (Battlefield Play4Free) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Extensions\oiokahphinmbmakkehgelkmpolmnbkdh [2013-09-19]
CHR Profile: C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 1 [2015-11-28]
CHR Extension: (Google Slides) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-11-28]
CHR Extension: (Google Docs) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2015-11-28]
CHR Extension: (Google Drive) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-11-28]
CHR Extension: (YouTube) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-11-28]
CHR Extension: (Google Search) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-11-28]
CHR Extension: (Google Sheets) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-11-28]
CHR Extension: (SiteAdvisor) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2015-11-28]
CHR Extension: (Google Docs Offline) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-11-28]
CHR Extension: (Unlimited Free VPN - Hola) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gkojfkhlekighikafcpjkiklfbnlmeio [2015-11-28]
CHR Extension: (Video Recorder for WeVideo) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\iaiglpeefdoagfbbfhjfbmomnfobojia [2015-11-28]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-11-28]
CHR Extension: (Gmail) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-11-28]
CHR Profile: C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 2 [2015-11-29]
CHR Extension: (Google Slides) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-11-28]
CHR Extension: (Google Docs) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\aohghmighlieiainnegkcijnfilokake [2015-11-28]
CHR Extension: (Google Drive) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-11-28]
CHR Extension: (YouTube) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-11-28]
CHR Extension: (Google Search) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-11-28]
CHR Extension: (MLG-ifier) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\dneebgdgldanagagmfhnphjelnngdcai [2015-11-28]
CHR Extension: (Google Sheets) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-11-28]
CHR Extension: (SiteAdvisor) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2015-11-28]
CHR Extension: (Google Docs Offline) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-11-28]
CHR Extension: (Read&Write for Google Chrome™) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\inoeonmfapjbbkmdafoankkfajkcphgd [2015-11-28]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-11-28]
CHR Extension: (Gmail) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-11-28]
CHR Extension: (Snapverter) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\plebojnaihkfjkkpgaemcjpnkmcpleih [2015-11-28]
CHR Profile: C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 3 [2018-01-27]
CHR Extension: (Slides) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-10-12]
CHR Extension: (Docs) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-12]
CHR Extension: (Google Drive) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-11-29]
CHR Extension: (YouTube) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-11-29]
CHR Extension: (Google Search) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-11-29]
CHR Extension: (Sheets) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-10-12]
CHR Extension: (McAfee® WebAdvisor) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2017-11-22]
CHR Extension: (Google Docs Offline) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-26]
CHR Extension: (Unlimited Free VPN - Hola) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\gkojfkhlekighikafcpjkiklfbnlmeio [2018-01-22]
CHR Extension: (Video Recorder for WeVideo) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\iaiglpeefdoagfbbfhjfbmomnfobojia [2017-12-14]
CHR Extension: (Project Viewer 365-Free) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\kmpghmkgkalhonankenfklpmdgnilapp [2016-04-07]
CHR Extension: (Cloud Drive, URL to ChromeCast™) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\mehfijocnmclokiknjjpcbddbekagnik [2015-12-25]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-08-21]
CHR Extension: (Gmail) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-11-29]
CHR Extension: (Chrome Media Router) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-01-25]
CHR Profile: C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 4 [2018-01-11]
CHR Extension: (Slides) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-01-11]
CHR Extension: (Docs) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\aohghmighlieiainnegkcijnfilokake [2018-01-11]
CHR Extension: (Google Drive) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-01-11]
CHR Extension: (YouTube) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-01-11]
CHR Extension: (Sheets) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-01-11]
CHR Extension: (McAfee® WebAdvisor) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2018-01-11]
CHR Extension: (Google Docs Offline) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-01-11]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-01-11]
CHR Extension: (Gmail) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2018-01-11]
CHR Extension: (Chrome Media Router) - C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-01-11]
CHR Profile: C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\System Profile [2015-11-29]
CHR HKLM\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - hxxp://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - hxxp://clients2.google.com/service/update2/crx
 
==================== Services (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S2 amdacpusrsvc; C:\Program Files\AMD\{920DEC42-4CA5-4d1d-9487-67BE645CDDFC}\amdacpusrsvc.exe [121856 2015-05-05] (Advanced Micro Devices) [File not signed]
S4 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2016-03-02] (Apple Inc.)
S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [6971400 2018-01-19] ()
S3 BrYNSvc; C:\Program Files (x86)\Browny02\BrYNSvc.exe [266240 2012-06-05] (Brother Industries, Ltd.) [File not signed]
S3 chromoting; C:\Program Files (x86)\Google\Chrome Remote Desktop\63.0.3239.32\remoting_host.exe [71512 2017-11-02] (Google Inc.)
S3 ClientAnalyticsService; C:\Program Files\Common Files\McAfee\ClientAnalytics\Legacy\McClientAnalytics.exe [1509680 2017-07-13] (McAfee, Inc.)
S4 Garmin Device Interaction Service; C:\Program Files (x86)\Garmin\Device Interaction Service\GarminService.exe [708616 2015-04-08] (Garmin Ltd. or its subsidiaries)
S4 lxea_device; C:\Windows\system32\lxeacoms.exe [1052328 2010-04-14] ( )
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6234056 2017-11-01] (Malwarebytes)
S2 McAPExe; C:\Program Files\Common Files\McAfee\VSCore_15_7\McApExe.exe [990696 2017-07-20] (McAfee, Inc.)
R2 mccspsvc; C:\Program Files\Common Files\McAfee\CSP\2.5.312.0\\McCSPServiceHost.exe [2139832 2017-05-30] (McAfee, Inc.)
R3 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe [242640 2017-06-21] (McAfee, Inc.)
R2 mfemms; C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe [394704 2017-06-21] (McAfee, Inc.)
R3 mfevtp; C:\Windows\system32\mfevtps.exe [350160 2017-06-21] (McAfee, Inc.)
R2 ModuleCoreService; C:\Program Files\Common Files\McAfee\ModuleCore\ModuleCoreService.exe [1545880 2017-06-27] (McAfee, Inc.)
S4 NETGEARGenieDaemon; C:\Program Files (x86)\NETGEAR Genie\bin\NETGEARGenieDaemon64.exe [232192 2015-06-01] (NETGEAR)
S2 PDFProFiltSrvPP; C:\Program Files (x86)\Nuance\PaperPort\PDFProFiltSrvPP.exe [144672 2010-03-09] (Nuance Communications, Inc.)
R2 PEFService; C:\Program Files\Common Files\Intel Security\PEF\CORE\PEFService.exe [1044376 2017-07-07] (Intel Security, Inc.)
S2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [66872 2015-04-21] ()
S2 PnkBstrB; C:\Windows\SysWOW64\PnkBstrB.exe [107832 2015-04-21] ()
S2 PSI_SVC_2_x64; c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe [337776 2014-04-30] (arvato digital services llc)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
R2 WTabletServicePro; C:\Program Files\Tablet\Wacom\WTabletServicePro.exe [652240 2016-07-14] (Wacom Technology, Corp.)
S2 HomeNetSvc; "C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe" /McCoreSvc [X]
S2 McBootDelayStartSvc; "C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe" /McCoreSvc [X]
S2 McMPFSvc; "C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe" /McCoreSvc [X]
S2 mcpltsvc; "C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe" /McCoreSvc [X]
S2 McProxy; "C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe" /McCoreSvc [X]
 
===================== Drivers (Whitelisted) ======================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 amdacpksd; C:\Windows\system32\drivers\amdacpksd.sys [297160 2015-05-05] (Advanced Micro Devices)
S3 cfwids; C:\Windows\System32\drivers\cfwids.sys [77800 2017-06-26] (McAfee, Inc.)
R1 ESProtectionDriver; C:\Windows\system32\drivers\mbae64.sys [77432 2017-12-12] ()
S3 HipShieldK; C:\Windows\System32\drivers\HipShieldK.sys [209616 2017-07-26] (McAfee, Inc.)
R0 MBAMChameleon; C:\Windows\System32\Drivers\MbamChameleon.sys [193968 2018-01-27] (Malwarebytes)
R3 MBAMFarflt; C:\Windows\System32\DRIVERS\farflt.sys [110016 2018-01-27] (Malwarebytes)
R3 MBAMProtection; C:\Windows\System32\DRIVERS\mbam.sys [46008 2018-01-27] (Malwarebytes)
R3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [253880 2018-01-27] (Malwarebytes)
R3 MBAMWebProtection; C:\Windows\System32\DRIVERS\mwac.sys [84256 2018-01-27] (Malwarebytes)
R3 mfeaack; C:\Windows\System32\drivers\mfeaack.sys [487408 2017-06-26] (McAfee, Inc.)
R3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [355312 2017-06-26] (McAfee, Inc.)
U3 mfeavfk01; no ImagePath
R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [506352 2017-06-26] (McAfee, Inc.)
R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [933360 2017-06-26] (McAfee, Inc.)
R3 mfencbdc; C:\Windows\System32\DRIVERS\mfencbdc.sys [504760 2017-05-31] (McAfee LLC.)
S3 mfencrk; C:\Windows\System32\DRIVERS\mfencrk.sys [108472 2017-05-31] (McAfee LLC.)
R3 mfeplk; C:\Windows\System32\drivers\mfeplk.sys [116208 2017-06-26] (McAfee, Inc.)
R0 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [253424 2017-06-26] (McAfee, Inc.)
R2 NPF; C:\Windows\system32\drivers\npf.sys [35344 2015-09-29] (CACE Technologies, Inc.)
S3 pmxdrv; C:\Windows\system32\drivers\pmxdrv.sys [31152 2015-09-18] ()
S3 WacHidRouterPro; C:\Windows\System32\DRIVERS\wachidrouter.sys [102864 2016-03-02] (Wacom Technology)
S3 mfeaack01; \Device\mfeaack01.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2018-01-27 20:53 - 2018-01-27 20:53 - 000034791 _____ C:\Users\Teschke\Desktop\FRST.txt
2018-01-27 19:06 - 2018-01-27 19:07 - 000051022 _____ C:\Users\Teschke\Desktop\Fixlog.txt
2018-01-27 19:06 - 2018-01-27 19:06 - 000026318 _____ C:\Users\Teschke\Desktop\kdvymdtevibxseqc.txt
2018-01-27 18:57 - 2018-01-27 18:57 - 000005130 _____ C:\Users\Teschke\Desktop\AdwCleaner[S0].txt
2018-01-27 18:54 - 2018-01-27 18:58 - 000000000 ____D C:\AdwCleaner
2018-01-27 18:54 - 2018-01-27 18:54 - 008206624 _____ (Malwarebytes) C:\Users\Teschke\Downloads\adwcleaner_7.0.7.0.exe
2018-01-27 18:38 - 2018-01-27 18:38 - 000001034 _____ C:\Users\Public\Desktop\Revo Uninstaller.lnk
2018-01-27 18:38 - 2018-01-27 18:38 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller
2018-01-27 18:38 - 2018-01-27 18:38 - 000000000 ____D C:\Program Files\VS Revo Group
2018-01-27 18:37 - 2018-01-27 18:37 - 007189760 _____ (VS Revo Group ) C:\Users\Teschke\Downloads\revosetup.exe
2018-01-27 13:39 - 2018-01-27 20:53 - 000000000 ____D C:\FRST
2018-01-27 13:37 - 2018-01-27 13:28 - 002393088 _____ (Farbar) C:\Users\Teschke\Desktop\FRST64.exe
2018-01-27 13:34 - 2018-01-27 19:02 - 000253880 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamswissarmy.sys
2018-01-27 13:34 - 2018-01-27 13:34 - 000193968 _____ (Malwarebytes) C:\Windows\system32\Drivers\MbamChameleon.sys
2018-01-26 19:03 - 2018-01-26 19:03 - 000619670 _____ C:\Users\Teschke\Desktop\W415-0061_GI3600manual.pdf
2018-01-20 18:11 - 2018-01-27 19:02 - 000084256 _____ (Malwarebytes) C:\Windows\system32\Drivers\mwac.sys
2018-01-19 20:53 - 2018-01-19 20:53 - 000000000 ____D C:\Users\Teschke\AppData\Local\CrashReportClient
2018-01-19 20:18 - 2018-01-18 19:16 - 000000229 ___SH C:\Users\Public\Libraries.ini
2018-01-19 20:15 - 2018-01-19 20:15 - 000000000 ____D C:\Users\Admin\AppData\Local\NVIDIA Corporation
2018-01-19 20:05 - 2018-01-19 20:05 - 000000000 ____D C:\Users\Admin\AppData\Local\FortniteGame
2018-01-19 20:05 - 2018-01-19 20:05 - 000000000 ____D C:\Users\Admin\AppData\Local\CrashReportClient
2018-01-19 20:04 - 2018-01-19 20:04 - 000000000 ____D C:\Users\Teschke\AppData\Local\NVIDIA Corporation
2018-01-19 20:03 - 2018-01-19 20:03 - 000000000 ____D C:\Users\Teschke\AppData\Local\FortniteGame
2018-01-19 19:39 - 2018-01-19 19:39 - 000000000 ___DL C:\Users\Admin\AppData\LocalLow\PlayReady
2018-01-19 19:01 - 2018-01-19 19:02 - 000000000 ____D C:\Program Files\Epic Games
2018-01-19 18:56 - 2018-01-19 20:05 - 000000000 ____D C:\Users\Admin\AppData\Local\UnrealEngine
2018-01-19 18:56 - 2018-01-19 18:56 - 000000000 ____D C:\Users\Admin\AppData\Local\UnrealEngineLauncher
2018-01-19 18:56 - 2018-01-19 18:56 - 000000000 ____D C:\Users\Admin\AppData\Local\EpicGamesLauncher
2018-01-19 18:51 - 2018-01-19 18:51 - 032260096 _____ C:\Users\Teschke\Downloads\EpicInstaller-7.2.0-fortnite-b4c7450ecc744c899c12cef8180e72f1 (1).msi
2018-01-19 18:49 - 2018-01-19 20:03 - 000000000 ____D C:\Users\Teschke\AppData\Local\UnrealEngine
2018-01-19 18:49 - 2018-01-19 18:49 - 000000000 ____D C:\Users\Teschke\AppData\Local\UnrealEngineLauncher
2018-01-19 18:49 - 2018-01-19 18:49 - 000000000 ____D C:\Users\Teschke\AppData\Local\EpicGamesLauncher
2018-01-19 18:48 - 2018-01-19 18:48 - 000001242 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Epic Games Launcher.lnk
2018-01-19 18:48 - 2018-01-19 18:48 - 000001230 _____ C:\Users\Public\Desktop\Epic Games Launcher.lnk
2018-01-19 18:48 - 2007-04-04 18:53 - 000081768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_3.dll
2018-01-19 18:47 - 2018-01-19 18:52 - 000000000 ____D C:\ProgramData\Epic
2018-01-19 18:47 - 2018-01-19 18:47 - 000000000 ____D C:\Program Files (x86)\Epic Games
2018-01-19 18:45 - 2018-01-19 18:45 - 032260096 _____ C:\Users\Teschke\Downloads\EpicInstaller-7.2.0-fortnite-b4c7450ecc744c899c12cef8180e72f1.msi
2018-01-16 20:59 - 2018-01-16 20:59 - 000057879 _____ C:\Users\Teschke\Downloads\On_Jesus_Derrida_and_Dawkins_Rejoinder_t (1).pdf
2018-01-16 20:58 - 2018-01-16 20:58 - 000057879 _____ C:\Users\Teschke\Downloads\On_Jesus_Derrida_and_Dawkins_Rejoinder_t.pdf
2018-01-07 14:20 - 2018-01-07 14:20 - 000562772 _____ C:\Users\Teschke\Downloads\NP_EX16_2b_IsaacTeschke_1.xlsx
2018-01-07 14:02 - 2018-01-07 14:02 - 000022355 _____ C:\Users\Teschke\Downloads\NP_EX16_1b_IsaacTeschke_1.xlsx
2018-01-04 21:08 - 2017-12-31 21:21 - 005581544 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2018-01-04 21:08 - 2017-12-31 21:21 - 001680616 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2018-01-04 21:08 - 2017-12-31 21:21 - 000948968 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys
2018-01-04 21:08 - 2017-12-31 21:21 - 000708328 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2018-01-04 21:08 - 2017-12-31 21:21 - 000288488 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fltMgr.sys
2018-01-04 21:08 - 2017-12-31 21:21 - 000262376 _____ (Microsoft Corporation) C:\Windows\system32\hal.dll
2018-01-04 21:08 - 2017-12-31 21:21 - 000213736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdyboost.sys
2018-01-04 21:08 - 2017-12-31 21:21 - 000154856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2018-01-04 21:08 - 2017-12-31 21:21 - 000114408 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2018-01-04 21:08 - 2017-12-31 21:21 - 000095464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2018-01-04 21:08 - 2017-12-31 21:19 - 001665384 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 014183936 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 002066432 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 002004480 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 001942016 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 001867776 _____ (Microsoft Corporation) C:\Windows\system32\ExplorerFrame.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 001741312 _____ (Microsoft Corporation) C:\Windows\system32\sysmain.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 001460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 001212928 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 001163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 001110528 _____ (Microsoft Corporation) C:\Windows\system32\schedsvc.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000977408 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000961024 _____ (Microsoft Corporation) C:\Windows\system32\actxprxy.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000880640 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000863232 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL
2018-01-04 21:08 - 2017-12-31 21:18 - 000842752 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000828928 _____ (Microsoft Corporation) C:\Windows\system32\MPSSVC.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000749568 _____ (Microsoft Corporation) C:\Windows\system32\FirewallAPI.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000731648 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000705024 _____ (Microsoft Corporation) C:\Windows\system32\BFE.DLL
2018-01-04 21:08 - 2017-12-31 21:18 - 000690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000512000 _____ (Microsoft Corporation) C:\Windows\system32\rpcss.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000473600 _____ (Microsoft Corporation) C:\Windows\system32\taskcomp.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000463872 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000444928 _____ (Microsoft Corporation) C:\Windows\system32\winhttp.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000439296 _____ (Microsoft Corporation) C:\Windows\system32\p2psvc.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000419840 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000366592 _____ (Microsoft Corporation) C:\Windows\system32\wcncsvc.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000361984 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000345600 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000327168 _____ (Microsoft Corporation) C:\Windows\system32\pnrpsvc.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000324096 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL
2018-01-04 21:08 - 2017-12-31 21:18 - 000316928 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000303104 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000264704 _____ (Microsoft Corporation) C:\Windows\system32\P2P.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000223232 _____ (Microsoft Corporation) C:\Windows\system32\ncsi.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000215552 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000190464 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000123904 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000120320 _____ (Microsoft Corporation) C:\Windows\system32\WcnApi.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000108544 _____ (Microsoft Corporation) C:\Windows\system32\icfupgd.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000101376 _____ (Microsoft Corporation) C:\Windows\system32\fdWCN.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000095744 _____ (Microsoft Corporation) C:\Windows\system32\rascfg.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000084480 _____ (Microsoft Corporation) C:\Windows\system32\INETRES.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000076288 _____ (Microsoft Corporation) C:\Windows\system32\rasdiag.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000070656 _____ (Microsoft Corporation) C:\Windows\system32\nlaapi.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000070144 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000060928 _____ (Microsoft Corporation) C:\Windows\system32\ndptsp.tsp
2018-01-04 21:08 - 2017-12-31 21:18 - 000060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000059904 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000047104 _____ (Microsoft Corporation) C:\Windows\system32\kmddsp.tsp
2018-01-04 21:08 - 2017-12-31 21:18 - 000044032 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000041472 _____ (Microsoft Corporation) C:\Windows\system32\rasmxs.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000039424 _____ (Microsoft Corporation) C:\Windows\system32\traffic.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000034816 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000029696 _____ (Microsoft Corporation) C:\Windows\system32\rasser.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000026112 _____ (Microsoft Corporation) C:\Windows\system32\oleres.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000024576 _____ (Microsoft Corporation) C:\Windows\system32\WcnEapPeerProxy.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000024064 _____ (Microsoft Corporation) C:\Windows\system32\WcnEapAuthProxy.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000022528 _____ (Microsoft Corporation) C:\Windows\system32\wfapigp.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000016896 _____ (Microsoft Corporation) C:\Windows\system32\wshqos.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000013312 _____ (Microsoft Corporation) C:\Windows\system32\wshnetbs.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000008704 _____ (Microsoft Corporation) C:\Windows\system32\comcat.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 21:18 - 000002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml6r.dll
2018-01-04 21:08 - 2017-12-31 21:13 - 000631680 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2018-01-04 21:08 - 2017-12-31 21:04 - 000559616 _____ (Microsoft Corporation) C:\Windows\system32\spoolsv.exe
2018-01-04 21:08 - 2017-12-31 21:02 - 001314112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 012880384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 001499648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ExplorerFrame.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 001417728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 001390080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 001114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000741888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000666624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000666112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000554496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000463360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FirewallAPI.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000351744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winhttp.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000304640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\taskcomp.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000276992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wcncsvc.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000275456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000261120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000254464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000217600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\P2P.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000216576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL
2018-01-04 21:08 - 2017-12-31 21:00 - 000172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000162304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncsi.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000084480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\INETRES.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcrypt.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fdWCN.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000081408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rascfg.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rasdiag.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000052224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ndptsp.tsp
2018-01-04 21:08 - 2017-12-31 21:00 - 000043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\traffic.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000026112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleres.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2018-01-04 21:08 - 2017-12-31 21:00 - 000002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6r.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 001806848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000644096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000309760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\actxprxy.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:59 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:55 - 000131584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\pacer.sys
2018-01-04 21:08 - 2017-12-31 20:55 - 000088576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\wanarp.sys
2018-01-04 21:08 - 2017-12-31 20:55 - 000058368 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndproxy.sys
2018-01-04 21:08 - 2017-12-31 20:55 - 000045056 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netbios.sys
2018-01-04 21:08 - 2017-12-31 20:55 - 000024064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndistapi.sys
2018-01-04 21:08 - 2017-12-31 20:54 - 004013800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2018-01-04 21:08 - 2017-12-31 20:54 - 003959016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2018-01-04 21:08 - 2017-12-31 20:54 - 000077312 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mpsdrv.sys
2018-01-04 21:08 - 2017-12-31 20:50 - 000455680 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2018-01-04 21:08 - 2017-12-31 20:49 - 000148480 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2018-01-04 21:08 - 2017-12-31 20:49 - 000064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2018-01-04 21:08 - 2017-12-31 20:49 - 000062464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2018-01-04 21:08 - 2017-12-31 20:49 - 000017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2018-01-04 21:08 - 2017-12-31 20:46 - 000338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2018-01-04 21:08 - 2017-12-31 20:45 - 000296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2018-01-04 21:08 - 2017-12-31 20:43 - 000086528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WcnApi.dll
2018-01-04 21:08 - 2017-12-31 20:43 - 000038912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kmddsp.tsp
2018-01-04 21:08 - 2017-12-31 20:43 - 000033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rasmxs.dll
2018-01-04 21:08 - 2017-12-31 20:43 - 000022528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rasser.dll
2018-01-04 21:08 - 2017-12-31 20:43 - 000020480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WcnEapPeerProxy.dll
2018-01-04 21:08 - 2017-12-31 20:43 - 000019968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WcnEapAuthProxy.dll
2018-01-04 21:08 - 2017-12-31 20:43 - 000018944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wfapigp.dll
2018-01-04 21:08 - 2017-12-31 20:43 - 000013824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshqos.dll
2018-01-04 21:08 - 2017-12-31 20:42 - 000460288 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys
2018-01-04 21:08 - 2017-12-31 20:42 - 000406016 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys
2018-01-04 21:08 - 2017-12-31 20:42 - 000168448 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys
2018-01-04 21:08 - 2017-12-31 20:42 - 000159744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2018-01-04 21:08 - 2017-12-31 20:41 - 000754176 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys
2018-01-04 21:08 - 2017-12-31 20:41 - 000291328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2018-01-04 21:08 - 2017-12-31 20:41 - 000129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2018-01-04 21:08 - 2017-12-31 20:41 - 000112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2018-01-04 21:08 - 2017-12-31 20:41 - 000106496 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dfsc.sys
2018-01-04 21:08 - 2017-12-31 20:41 - 000030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2018-01-04 21:08 - 2017-12-31 20:41 - 000007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comcat.dll
2018-01-04 21:08 - 2017-12-31 20:39 - 000050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2018-01-04 21:08 - 2017-12-31 20:36 - 000025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2018-01-04 21:08 - 2017-12-31 20:36 - 000014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2018-01-04 21:08 - 2017-12-31 20:36 - 000007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2018-01-04 21:08 - 2017-12-31 20:36 - 000002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2018-01-04 21:08 - 2017-12-31 20:35 - 000036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
2018-01-04 21:08 - 2017-12-31 20:35 - 000006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:35 - 000004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:35 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2018-01-04 21:08 - 2017-12-31 20:35 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2018-01-04 21:08 - 2017-12-30 02:29 - 000395968 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2018-01-04 21:08 - 2017-12-30 01:42 - 000347328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2018-01-04 21:08 - 2017-12-29 13:39 - 020274688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2018-01-04 21:08 - 2017-12-29 13:24 - 002724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2018-01-04 21:08 - 2017-12-29 13:13 - 000499712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2018-01-04 21:08 - 2017-12-29 13:13 - 000062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2018-01-04 21:08 - 2017-12-29 13:12 - 000341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2018-01-04 21:08 - 2017-12-29 13:12 - 000047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2018-01-04 21:08 - 2017-12-29 13:11 - 000064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2018-01-04 21:08 - 2017-12-29 13:09 - 002294272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2018-01-04 21:08 - 2017-12-29 13:06 - 000047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2018-01-04 21:08 - 2017-12-29 13:06 - 000030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2018-01-04 21:08 - 2017-12-29 13:04 - 000476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2018-01-04 21:08 - 2017-12-29 13:03 - 000662528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2018-01-04 21:08 - 2017-12-29 13:03 - 000620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2018-01-04 21:08 - 2017-12-29 13:03 - 000115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2018-01-04 21:08 - 2017-12-29 12:55 - 000416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2018-01-04 21:08 - 2017-12-29 12:51 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2018-01-04 21:08 - 2017-12-29 12:50 - 000091136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2018-01-04 21:08 - 2017-12-29 12:50 - 000073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2018-01-04 21:08 - 2017-12-29 12:47 - 000168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2018-01-04 21:08 - 2017-12-29 12:47 - 000076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2018-01-04 21:08 - 2017-12-29 12:46 - 000279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2018-01-04 21:08 - 2017-12-29 12:45 - 004508160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2018-01-04 21:08 - 2017-12-29 12:44 - 000130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2018-01-04 21:08 - 2017-12-29 12:39 - 000230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2018-01-04 21:08 - 2017-12-29 12:38 - 013680128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2018-01-04 21:08 - 2017-12-29 12:38 - 000694272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2018-01-04 21:08 - 2017-12-29 12:37 - 002058752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2018-01-04 21:08 - 2017-12-29 12:36 - 001155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2018-01-04 21:08 - 2017-12-29 12:19 - 002767872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2018-01-04 21:08 - 2017-12-29 12:15 - 001313792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2018-01-04 21:08 - 2017-12-29 12:13 - 000710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2018-01-04 21:08 - 2017-12-29 04:15 - 025737728 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2018-01-04 21:08 - 2017-12-29 04:04 - 002724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2018-01-04 21:08 - 2017-12-29 04:04 - 000004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2018-01-04 21:08 - 2017-12-29 03:52 - 002900480 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2018-01-04 21:08 - 2017-12-29 03:51 - 005796352 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2018-01-04 21:08 - 2017-12-29 03:51 - 000066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2018-01-04 21:08 - 2017-12-29 03:50 - 000577024 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2018-01-04 21:08 - 2017-12-29 03:50 - 000417280 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2018-01-04 21:08 - 2017-12-29 03:50 - 000088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2018-01-04 21:08 - 2017-12-29 03:50 - 000048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2018-01-04 21:08 - 2017-12-29 03:44 - 000054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2018-01-04 21:08 - 2017-12-29 03:43 - 000034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2018-01-04 21:08 - 2017-12-29 03:40 - 000615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2018-01-04 21:08 - 2017-12-29 03:39 - 000817152 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2018-01-04 21:08 - 2017-12-29 03:39 - 000814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2018-01-04 21:08 - 2017-12-29 03:39 - 000144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2018-01-04 21:08 - 2017-12-29 03:39 - 000116224 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2018-01-04 21:08 - 2017-12-29 03:32 - 000969216 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2018-01-04 21:08 - 2017-12-29 03:28 - 000489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2018-01-04 21:08 - 2017-12-29 03:22 - 000087552 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2018-01-04 21:08 - 2017-12-29 03:22 - 000077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2018-01-04 21:08 - 2017-12-29 03:21 - 000107520 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2018-01-04 21:08 - 2017-12-29 03:18 - 000199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2018-01-04 21:08 - 2017-12-29 03:18 - 000092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2018-01-04 21:08 - 2017-12-29 03:16 - 000315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2018-01-04 21:08 - 2017-12-29 03:14 - 000152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2018-01-04 21:08 - 2017-12-29 03:05 - 000262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2018-01-04 21:08 - 2017-12-29 03:04 - 015284224 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2018-01-04 21:08 - 2017-12-29 03:03 - 000807936 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2018-01-04 21:08 - 2017-12-29 03:03 - 000726528 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2018-01-04 21:08 - 2017-12-29 03:01 - 002134528 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2018-01-04 21:08 - 2017-12-29 03:01 - 001359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2018-01-04 21:08 - 2017-12-29 02:50 - 003241472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2018-01-04 21:08 - 2017-12-29 02:39 - 001545728 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2018-01-04 21:08 - 2017-12-29 02:27 - 000800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2018-01-04 21:08 - 2017-12-21 01:27 - 000634312 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
2018-01-04 21:08 - 2017-12-13 11:31 - 000383720 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2018-01-04 21:08 - 2017-12-13 11:27 - 000100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2018-01-04 21:08 - 2017-12-13 11:27 - 000046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2018-01-04 21:08 - 2017-12-13 11:27 - 000041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2018-01-04 21:08 - 2017-12-13 11:27 - 000014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2018-01-04 21:08 - 2017-12-13 11:15 - 000309480 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2018-01-04 21:08 - 2017-12-13 11:11 - 000071168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2018-01-04 21:08 - 2017-12-13 11:11 - 000025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
2018-01-04 21:08 - 2017-12-13 11:11 - 000010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
2018-01-04 21:08 - 2017-12-13 10:50 - 000034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2018-01-04 21:08 - 2017-12-05 12:36 - 000625664 _____ (Microsoft Corporation) C:\Windows\system32\mscms.dll
2018-01-04 21:08 - 2017-12-05 12:36 - 000250880 _____ (Microsoft Corporation) C:\Windows\system32\icm32.dll
2018-01-04 21:08 - 2017-12-05 12:36 - 000040960 _____ (Microsoft Corporation) C:\Windows\system32\WcsPlugInService.dll
2018-01-04 21:08 - 2017-12-05 12:08 - 000481792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscms.dll
2018-01-04 21:08 - 2017-12-05 12:08 - 000215040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icm32.dll
2018-01-04 21:08 - 2017-12-05 10:59 - 003222528 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2018-01-04 21:08 - 2017-12-05 10:49 - 000032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WcsPlugInService.dll
2018-01-04 19:50 - 2018-01-04 19:50 - 000053941 _____ C:\Users\Teschke\Downloads\NP_PPT16_1b_IsaacTeschke_1 (1).pptx
2018-01-02 12:51 - 2018-01-02 12:51 - 000099306 _____ C:\Users\Teschke\Downloads\340906__passairmangrace__tablehit-mono-bip.wav
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2018-01-27 20:40 - 2013-04-20 14:11 - 000000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2018-01-27 19:17 - 2009-07-13 23:45 - 000022656 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2018-01-27 19:17 - 2009-07-13 23:45 - 000022656 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2018-01-27 19:08 - 2017-01-14 15:20 - 000000000 ____D C:\ProgramData\McAfee
2018-01-27 19:06 - 2009-07-14 00:13 - 000782470 _____ C:\Windows\system32\PerfStringBackup.INI
2018-01-27 19:06 - 2009-07-13 22:20 - 000000000 ____D C:\Windows\inf
2018-01-27 19:02 - 2017-12-12 04:54 - 000046008 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2018-01-27 19:02 - 2017-12-12 04:53 - 000110016 _____ (Malwarebytes) C:\Windows\system32\Drivers\farflt.sys
2018-01-27 18:59 - 2013-08-25 20:48 - 000000000 ____D C:\Program Files (x86)\McAfee
2018-01-27 18:59 - 2009-07-14 00:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2018-01-27 18:58 - 2015-09-22 22:11 - 000065536 _____ C:\Windows\system32\spu_storage.bin
2018-01-27 18:47 - 2017-01-14 15:39 - 000000000 ____D C:\Program Files\McAfee
2018-01-27 13:43 - 2014-05-30 15:16 - 001102276 _____ C:\Windows\ntbtlog.txt
2018-01-27 11:33 - 2017-11-05 20:22 - 000001690 _____ C:\Users\Admin\Desktop\Rkill.txt
2018-01-26 15:10 - 2013-04-21 13:55 - 000000000 ____D C:\Users\Teschke\AppData\Local\CrashDumps
2018-01-25 19:53 - 2013-04-18 07:01 - 000000000 ____D C:\Users\Teschke\Documents\Outlook Files
2018-01-25 19:31 - 2013-04-18 00:03 - 000001236 __RSH C:\Users\Teschke\ntuser.pol
2018-01-25 19:31 - 2013-04-17 20:06 - 000000000 ____D C:\Users\Teschke
2018-01-25 19:14 - 2013-04-18 00:07 - 000001232 __RSH C:\Users\Admin\ntuser.pol
2018-01-25 19:14 - 2013-04-18 00:07 - 000000000 ____D C:\Users\Admin
2018-01-25 19:08 - 2009-07-13 22:20 - 000000000 ____D C:\Windows\registration
2018-01-25 13:12 - 2013-04-20 15:39 - 000000000 ____D C:\Users\Teschke\Documents\Laura
2018-01-24 15:48 - 2013-04-20 14:11 - 000002224 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2018-01-23 17:29 - 2017-07-09 12:08 - 000000000 ____D C:\Users\Teschke\AppData\Local\Spotify
2018-01-23 16:54 - 2017-07-09 12:02 - 000000000 ____D C:\Users\Teschke\AppData\Roaming\Spotify
2018-01-23 11:29 - 2013-04-20 15:50 - 000000000 ____D C:\Users\Teschke\Documents\Isaac
2018-01-23 10:57 - 2014-02-17 18:02 - 001446400 ___SH C:\Users\Teschke\Downloads\Thumbs.db
2018-01-19 18:51 - 2014-11-24 21:35 - 000000000 ____D C:\ProgramData\Package Cache
2018-01-19 03:02 - 2013-04-18 00:33 - 000775462 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2018-01-18 17:03 - 2017-11-05 20:21 - 000009216 ___SH C:\Users\Teschke\Thumbs.db
2018-01-13 06:44 - 2013-04-20 15:28 - 000000000 ____D C:\Program Files (x86)\Steam
2018-01-12 20:50 - 2013-09-28 20:10 - 000000000 ____D C:\Users\Teschke\Documents\Corel VideoStudio Pro
2018-01-10 03:19 - 2013-07-12 17:33 - 000000000 ____D C:\Windows\system32\MRT
2018-01-10 03:13 - 2017-10-12 02:11 - 129365736 ____C (Microsoft Corporation) C:\Windows\system32\MRT-KB890830.exe
2018-01-10 03:13 - 2013-04-19 08:17 - 129365736 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2018-01-09 10:40 - 2017-09-28 16:34 - 000004468 _____ C:\Windows\System32\Tasks\Adobe Flash Player PPAPI Notifier
2018-01-09 10:40 - 2013-04-19 07:28 - 000803328 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2018-01-09 10:40 - 2013-04-19 07:28 - 000144896 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2018-01-09 10:40 - 2013-04-19 07:28 - 000004312 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2018-01-09 10:40 - 2013-04-19 07:28 - 000000000 ____D C:\Windows\system32\Macromed
2018-01-09 10:40 - 2013-04-17 22:41 - 000000000 ____D C:\Windows\SysWOW64\Macromed
2018-01-05 04:11 - 2009-07-13 22:20 - 000000000 ____D C:\Windows\rescache
2018-01-05 03:21 - 2009-07-13 23:45 - 000532872 _____ C:\Windows\system32\FNTCACHE.DAT
2018-01-04 16:59 - 2009-07-13 22:20 - 000000000 ____D C:\Windows\system32\NDF
2018-01-01 00:36 - 2009-07-14 00:08 - 000032542 _____ C:\Windows\Tasks\SCHEDLGU.TXT
 
==================== Files in the root of some directories =======
 
2014-09-30 19:18 - 2015-10-05 05:49 - 000000096 _____ () C:\Users\Teschke\AppData\Roaming\LauncherSettings_live.cfg
2014-09-30 18:25 - 2015-10-05 05:33 - 000000039 _____ () C:\Users\Teschke\AppData\Roaming\TheHunterSettings_live.cfg
2014-03-06 15:07 - 2014-03-06 15:07 - 000003584 _____ () C:\Users\Teschke\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2013-12-29 20:09 - 2013-12-29 20:09 - 000000084 _____ () C:\Users\Teschke\AppData\Local\DVDPATH.TXT
 
Some files in TEMP:
====================
2016-10-15 05:44 - 2015-01-26 11:34 - 000015752 _____ (Autodesk, Inc.) C:\Users\Admin\AppData\Local\Temp\AcDeltree.exe
2017-05-26 21:46 - 2017-05-26 22:10 - 002016632 _____ (Flexera Software LLC) C:\Users\Admin\AppData\Local\Temp\FNP_ACT_InstallerCA.dll
2017-09-10 21:11 - 2017-09-10 21:12 - 000004608 _____ () C:\Users\Admin\AppData\Local\Temp\i4jdel0.exe
2016-11-16 06:28 - 2016-11-16 06:28 - 000244264 _____ (McAfee, Inc.) C:\Users\Admin\AppData\Local\Temp\McCSPInstall.dll
2015-09-22 21:36 - 2015-09-22 21:47 - 060685368 _____ () C:\Users\Admin\AppData\Local\Temp\raptrpatch.exe
2015-09-22 21:36 - 2015-09-22 21:36 - 000221632 _____ () C:\Users\Admin\AppData\Local\Temp\raptr_stub.exe
2006-05-24 12:10 - 2006-05-24 12:10 - 000455600 ____R (Macrovision Corporation) C:\Users\Admin\AppData\Local\Temp\_is897B.exe
2014-02-15 20:01 - 2014-02-15 20:01 - 000588360 _____ (NCH Software) C:\Users\Teschke\AppData\Local\Temp\bwsetup.exe
2014-08-20 20:25 - 2014-08-20 20:25 - 003166208 _____ () C:\Users\Teschke\AppData\Local\Temp\ffmpeg19.exe
2016-01-30 23:16 - 2016-01-30 23:20 - 023334528 _____ (Hola Networks Ltd.) C:\Users\Teschke\AppData\Local\Temp\Hola-Setup-Plugin-x64-1.11.399.exe
2013-10-30 17:52 - 2013-10-30 17:52 - 001071584 _____ (Solid State Networks) C:\Users\Teschke\AppData\Local\Temp\install_flashplayer11x32ax_chra_awa_aih.exe
2013-11-28 12:24 - 2013-11-28 12:24 - 001071584 _____ (Solid State Networks) C:\Users\Teschke\AppData\Local\Temp\install_flashplayer11x32ax_gtba_chra_dy_aaa_aih.exe
2013-11-28 12:28 - 2013-11-28 12:28 - 001071584 _____ (Solid State Networks) C:\Users\Teschke\AppData\Local\Temp\install_flashplayer11x32ax_gtba_chra_dy_aaa_aih_1.exe
2013-10-08 15:36 - 2013-10-08 15:36 - 001071568 _____ (Solid State Networks) C:\Users\Teschke\AppData\Local\Temp\install_reader11_en_chra_awa_aih.exe
2014-02-25 18:48 - 2014-02-25 18:48 - 001069920 _____ (Solid State Networks) C:\Users\Teschke\AppData\Local\Temp\install_reader11_en_chra_awa_aih_1.exe
2013-05-21 21:24 - 2013-05-21 21:24 - 002137632 _____ (Solid State Networks) C:\Users\Teschke\AppData\Local\Temp\install_reader11_en_gtbp_chra_aih.exe
2013-06-26 11:56 - 2013-06-26 11:56 - 001037120 _____ (Solid State Networks) C:\Users\Teschke\AppData\Local\Temp\install_reader11_en_mssa_aaa_aih.exe
2013-07-12 21:08 - 2013-07-12 21:08 - 004120976 _____ (Black Tree Gaming                                           ) C:\Users\Teschke\AppData\Local\Temp\Nexus%20Mod%20Manager-0.45.4.exe
2014-08-09 20:04 - 2014-08-09 20:04 - 000518208 _____ (NCH Software) C:\Users\Teschke\AppData\Local\Temp\pixsetup.exe
2014-04-21 16:29 - 2014-04-21 16:29 - 000339544 _____ (NCH Software) C:\Users\Teschke\AppData\Local\Temp\ppsetup.exe
2014-08-20 20:23 - 2014-08-20 20:23 - 000589888 _____ (NCH Software) C:\Users\Teschke\AppData\Local\Temp\prismsetup.exe
2016-09-23 19:26 - 2016-09-23 19:26 - 083528440 _____ () C:\Users\Teschke\AppData\Local\Temp\Setup-Wacom.exe
2015-01-31 10:16 - 2016-04-08 14:58 - 046965376 _____ (Skype Technologies S.A.) C:\Users\Teschke\AppData\Local\Temp\SkypeSetup.exe
2014-04-21 16:27 - 2014-04-21 16:27 - 000418352 _____ (NCH Software) C:\Users\Teschke\AppData\Local\Temp\tnsetup.exe
2014-02-15 20:00 - 2014-02-15 20:00 - 000367192 _____ (NCH Software) C:\Users\Teschke\AppData\Local\Temp\twelvekeyssetup.exe
2014-02-15 20:00 - 2014-02-15 20:00 - 000752176 _____ (NCH Software) C:\Users\Teschke\AppData\Local\Temp\vxlsetup.exe
2014-02-15 19:59 - 2014-02-15 19:59 - 001003568 _____ (NCH Software) C:\Users\Teschke\AppData\Local\Temp\wpsetup.exe
 
==================== Bamital & volsnap ======================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
 
LastRegBack: 2018-01-18 01:44
 
==================== End of FRST.txt ============================

and the 2nd file:

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 27.01.2018
Ran by Teschke (27-01-2018 20:53:21)
Running from C:\Users\Teschke\Desktop
Windows 7 Home Premium Service Pack 1 (X64) (2013-04-18 01:06:13)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Admin (S-1-5-21-3289118944-4034126387-1954186238-1003 - Administrator - Enabled) => C:\Users\Admin
Administrator (S-1-5-21-3289118944-4034126387-1954186238-500 - Administrator - Disabled)
Guest (S-1-5-21-3289118944-4034126387-1954186238-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3289118944-4034126387-1954186238-1002 - Limited - Enabled)
Teschke (S-1-5-21-3289118944-4034126387-1954186238-1000 - Administrator - Enabled) => C:\Users\Teschke
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Malwarebytes (Enabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B}
AS: Malwarebytes (Enabled - Up to date) {98619B37-4FC4-67F2-1C99-EEF6D47DBD96}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov)
Ace of Spades (HKLM-x32\...\{6037B8AD-7D5B-4D50-9BCA-A586C44EEF34}) (Version: 0.75.015 - Ben Aksoy)
ACP Application (HKLM\...\{DD93B141-69A7-A8FD-6963-266D02E9C07B}) (Version: 2.15.20.0015 - Advanced Micro Devices, Inc.) Hidden
Adobe Flash Player 28 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 28.0.0.137 - Adobe Systems Incorporated)
Adobe Flash Player 28 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 28.0.0.137 - Adobe Systems Incorporated)
Adobe Flash Player 28 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 28.0.0.137 - Adobe Systems Incorporated)
Adobe Photoshop Lightroom 5.2 64-bit (HKLM\...\{54E6C675-3AD4-42E4-957F-31666ABF1603}) (Version: 5.2.1 - Adobe)
Adobe Reader XI (11.0.03) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.03 - Adobe Systems Incorporated)
AMD Catalyst Install Manager (HKLM\...\{8F62BC70-DBB4-802D-1E1E-13630D9BA4D2}) (Version: 8.0.916.0 - Advanced Micro Devices, Inc.)
ANT Drivers Installer x64 (HKLM\...\{431CE782-4C51-4996-B36F-5D98D5527538}) (Version: 2.3.4 - Garmin Ltd or its subsidiaries) Hidden
Apple Application Support (32-bit) (HKLM-x32\...\{FE5C2FAA-118D-4509-B51D-3F71CC9E1B3E}) (Version: 4.3 - Apple Inc.)
Apple Application Support (64-bit) (HKLM\...\{2937FD88-C9D6-4B82-B539-37CD0A572F42}) (Version: 4.3 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{2E4AF2A6-50EA-4260-9BA4-5E582D11879A}) (Version: 9.3.0.15 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{56EC47AA-5813-4FF6-8E75-544026FBEA83}) (Version: 2.2.0.150 - Apple Inc.)
Assassin's Creed III 1.01 (HKLM-x32\...\{9D15E813-0C26-41E7-ABC5-3EB06FF1B3CF}) (Version: 1.01 - Ubisoft)
Autodesk Configurator 360 addin (HKLM-x32\...\{563941AA-C055-4FAA-8B04-A4E024A61F7E}) (Version: 20.0.10300 - Autodesk)
Autodesk Design Review 2013 (HKLM-x32\...\{153DB567-6FF3-49AD-AC4F-86F8A3CCFDFB}) (Version: 13.0.0.82 - Autodesk, Inc.) Hidden
Autodesk Design Review 2013 (HKLM-x32\...\Autodesk Design Review 2013) (Version: 13.0.0.82 - Autodesk, Inc.)
Battle.net (HKLM-x32\...\Battle.net) (Version:  - Blizzard Entertainment)
Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
BookSmart® 3.4.9 3.4.9 (HKLM-x32\...\BookSmart® 3.4.9 3.4.9) (Version:  - Blurb, Inc)
Boris Graffiti 6 for Corel VideoStudio Pro (HKLM-x32\...\{F4310AE4-A789-4602-AA48-CFA03D73A9F4}) (Version: 6.1.0003 - Boris FX, Inc.)
Boris Graffiti 7 for Corel VideoStudio Pro X9 64-Bit (HKLM\...\{9C246583-D390-4910-B740-431F89FACC2E}) (Version: 7.0.0001 - Boris FX, Inc.)
Brother MFL-Pro Suite DCP-7065DN (HKLM-x32\...\{3ACCCFB3-7B17-4E9F-ACB0-46868FCD4487}) (Version: 1.1.3.0 - Brother Industries, Ltd.)
Call of Duty - United Offensive (HKLM-x32\...\{A662E280-64A8-4CF5-8407-13D0808602B3}) (Version: 1.00.0000 - Activision) Hidden
Call of Duty - United Offensive (HKLM-x32\...\InstallShield_{A662E280-64A8-4CF5-8407-13D0808602B3}) (Version: 1.00.0000 - Activision)
Call of Duty (HKLM-x32\...\Call of Duty) (Version:  - )
Call of Duty® 4 - Modern Warfare™ (HKLM-x32\...\{E48469CC-635E-4FD5-A122-1497C286D217}) (Version: 1.6 - Activision) Hidden
Call of Duty® 4 - Modern Warfare™ (HKLM-x32\...\InstallShield_{E48469CC-635E-4FD5-A122-1497C286D217}) (Version: 1.6 - Activision)
CameraHelperMsi (HKLM-x32\...\{15634701-BACE-4449-8B25-1567DA8C9FD3}) (Version: 13.51.815.0 - Logitech) Hidden
Chrome Remote Desktop Host (HKLM-x32\...\{D61C8E6E-A4F3-4CD8-8568-51CEB5660C89}) (Version: 63.0.3239.32 - Google Inc.)
Cisco WebEx Meetings (HKU\S-1-5-21-3289118944-4034126387-1954186238-1000\...\ActiveTouchMeetingClient) (Version:  - Cisco WebEx LLC)
Contents (HKLM-x32\...\{EE0B1766-153A-4251-A192-F8FD3D941711}) (Version: 16.1.0.45 - Corel Corporation) Hidden
Contents64 (HKLM\...\{C2D307EA-96F8-4F6E-880E-E244779D8477}) (Version: 19.5.0.35 - Corel Corporation) Hidden
Corel KPT Collection (HKLM-x32\...\{031338C0-4C21-4DAC-875B-26ACD7ADDF23}) (Version: 1.00.0000 - Corel Corporation) Hidden
Corel KPT Collection for PSPX4 (HKLM-x32\...\_{031338C0-4C21-4DAC-875B-26ACD7ADDF23}) (Version:  - Corel Corporation)
Corel Painter 13 - IPM (HKLM\...\{0B598D32-B873-4794-8F30-90C53CD562D7}) (Version: 13.1 - Corel Corporation) Hidden
Corel Painter 13 - IPM Content (HKLM\...\{9983025B-AA60-4CF3-9E6C-C48DB9CD2310}) (Version: 13.1 - Corel Corporation) Hidden
Corel Painter X3 (HKLM\...\_{EF449371-6B69-49C8-B789-76A0B0E3446B}) (Version: 13.0.1.920 - Corel Corporation)
Corel PaintShop Pro X4 (HKLM-x32\...\_{00580795-581C-4587-B9F2-37320D7AB37F}) (Version: 14.2.0.1 - Corel Corporation)
Corel PaintShop Pro X4 (HKLM-x32\...\{00AE1A2D-7BC2-4359-A0EC-E19F36E391BB}) (Version: 14.2.0.1 - Corel Corporation) Hidden
Corel PaintShop Pro X4 Ultimate Bonus Pack (HKLM-x32\...\_{45E8DDB3-8FEB-40DB-A6D7-3535392AA559}) (Version:  - Corel Corporation)
Corel PaintShop Pro X4 Ultimate Bonus Pack (HKLM-x32\...\{45E8DDB3-8FEB-40DB-A6D7-3535392AA559}) (Version: 1.00.0000 - Corel Corporation) Hidden
Corel VideoStudio Pro X6 (HKLM-x32\...\_{6688A246-F6E8-48AD-9806-8D5832E9F15D}) (Version: 16.1.0.45 - Corel Corporation)
Corel VideoStudio Ultimate X9 (HKLM-x32\...\_{EE80DAA0-0071-475C-A222-F1782888FC55}) (Version: 19.5.0.35 - Corel Corporation)
Crysis®3 (HKLM-x32\...\{4198AE83-A3C6-4C41-85C8-EC63E990696E}) (Version: 1.0.0.0 - Electronic Arts)
D3DX10 (HKLM-x32\...\{E09C4DB7-630C-4F06-A631-8EA7239923AF}) (Version: 15.4.2368.0902 - Microsoft) Hidden
DAIDE QuickStart (HKLM-x32\...\{FDE86B27-8B13-40CB-B0DA-A1CAB15C2929}) (Version: 6.0.1 - Jason van Hal)
Dell System Detect (HKU\S-1-5-21-3289118944-4034126387-1954186238-1000\...\73f463568823ebbe) (Version: 6.6.0.2 - Dell)
digiCamControl (HKLM-x32\...\{19D12628-7654-4354-A305-9AB0A3502683}) (Version: 1.2.99.12 - Duka Istvan)
Eco Materials Adviser for Autodesk Inventor 2016 (64-bit) (HKLM\...\{1A56BE00-916E-432D-A576-EB00D2FF8450}) (Version: 5.6.4.44 - Granta Design Limited)
Elevated Installer (HKLM-x32\...\{7E73C9A3-24D9-4D7F-B4C7-7E4AFE0ADCCB}) (Version: 4.0.15.0 - Garmin Ltd or its subsidiaries) Hidden
Epic Games Launcher (HKLM-x32\...\{2B6AC31A-9883-465C-AFC6-1EC5AA48F5BD}) (Version: 1.1.138.0 - Epic Games, Inc.)
Epic Games Launcher Prerequisites (x64) (HKLM\...\{66C5838F-B854-4A55-89E6-A6138747A4DF}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
erLT (HKLM-x32\...\{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}) (Version: 1.20.138.34 - Logitech, Inc.) Hidden
Far Cry (HKLM-x32\...\{D6DBDC2A-E72C-4284-B6AD-6B3B61B4DABC}) (Version: 1.00.0000 - Ubisoft) Hidden
Far Cry (HKLM-x32\...\InstallShield_{D6DBDC2A-E72C-4284-B6AD-6B3B61B4DABC}) (Version: 1.00.0000 - Ubisoft)
Far Cry 2 (HKLM-x32\...\{F2835483-37F2-4123-B4FE-0E77D58447F2}) (Version: 1.03.00 - Ubisoft)
FARO LS 1.1.501.0 (64bit) (HKLM-x32\...\{8A470330-70B2-49AD-86AF-79885EF9898A}) (Version: 5.1.0.30630 - FARO Scanner Production)
FARO LS 1.1.503.3 (64bit) (HKLM-x32\...\{1C05E654-FB81-4274-BF32-292E3707701D}) (Version: 5.3.3.38662 - FARO Scanner Production)
Garmin Communicator Plugin (HKLM-x32\...\{71DBFBF2-F7EB-4268-8485-9471D83C4E66}) (Version: 4.2.0 - Garmin Ltd or its subsidiaries)
Garmin Communicator Plugin x64 (HKLM\...\{70A381F1-C161-4D61-A20C-BE12FC6777DF}) (Version: 4.2.0 - Garmin Ltd or its subsidiaries)
Garmin Express (HKLM-x32\...\{50755d67-ae60-4e47-b3d6-ce44d01b5a95}) (Version: 4.0.15.0 - Garmin Ltd or its subsidiaries)
Garmin Express (HKLM-x32\...\{9FB8EC5B-03EE-463E-8F4F-84B525B986B7}) (Version: 4.0.15.0 - Garmin Ltd or its subsidiaries) Hidden
Garmin Express Tray (HKLM-x32\...\{1D91CBB5-4CB1-4757-B0FD-2122AF8AAB9E}) (Version: 4.0.15.0 - Garmin Ltd or its subsidiaries) Hidden
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 64.0.3282.119 - Google Inc.)
Google Earth Plug-in (HKLM-x32\...\{4AB54F11-2F8C-11E3-B09F-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
Google Earth Pro (HKLM-x32\...\{ECF2E224-42F5-4E50-B58E-94CA70E85697}) (Version: 7.3.0.3832 - Google)
Google Toolbar for Internet Explorer (HKLM-x32\...\{18455581-E099-4BA8-BC6B-F34B2F06600C}) (Version: 1.0.0 - Google Inc.) Hidden
Google Toolbar for Internet Explorer (HKLM-x32\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.8231.2252 - Google Inc.)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.7 - Google Inc.) Hidden
Google Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.25.11 - Google Inc.) Hidden
Haali Media Splitter (HKLM-x32\...\HaaliMkx) (Version:  - )
ICA (HKLM-x32\...\{00580795-581C-4587-B9F2-37320D7AB37F}) (Version: 14.2.0.1 - Corel Corporation) Hidden
ICA (HKLM-x32\...\{6688A246-F6E8-48AD-9806-8D5832E9F15D}) (Version: 16.1.0.45 - Corel Corporation) Hidden
ICA (HKLM-x32\...\{EE80DAA0-0071-475C-A222-F1782888FC55}) (Version: 19.5.0.35 - Corel Corporation) Hidden
IconHandler 64 bit (HKLM\...\{4E82E2E9-668B-4F8A-814A-78E163FCDBCD}) (Version: 2.0 - Corel Corporation) Hidden
Intel® Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1118 - Intel Corporation)
Intel® Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 10.0.0.1046 - Intel Corporation)
IPM_PSP_COM (HKLM-x32\...\{00BEE329-BAAB-49FF-9B66-55E4B12B9ADD}) (Version: 14.2.0.1 - Corel Corporation) Hidden
IPM_VS_Pro (HKLM-x32\...\{CCC10E8E-7FD1-4D55-87C2-D0A5ABC0A62B}) (Version: 16.0 - Corel Corporation) Hidden
IPM_VS_Pro64 (HKLM\...\{1BD7EE90-7C52-4142-B4DD-55C4F28F9EE7}) (Version: 19.0 - Corel Corporation) Hidden
iTunes (HKLM\...\{A31C5565-90D9-4615-AE13-94D86C3836C7}) (Version: 12.3.3.17 - Apple Inc.)
Java 8 Update 25 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218025F0}) (Version: 8.0.250 - Oracle Corporation)
LAME v3.99.3 (for Windows) (HKLM-x32\...\LAME_is1) (Version:  - )
Launcher Prerequisites (x64) (HKLM-x32\...\{c6c5a357-c7ca-4a5f-9789-3bb1af579253}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
Lightworks (HKLM-x32\...\{E94DD4E4-7746-472c-AA7B-1242FED0CFC8}) (Version: 11.1.0.0 - Lightworks)
Logitech Webcam Software (HKLM-x32\...\{D40EB009-0499-459c-A8AF-C9C110766215}) (Version: 2.51 - Logitech Inc.)
Malwarebytes version 3.3.1.2183 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.3.1.2183 - Malwarebytes)
Medal of Honor Allied Assault (HKLM-x32\...\{0DEA94ED-915A-4834-A87E-388D012C8E02}) (Version:  - )
Medal of Honor Allied Assault™ Spearhead (HKLM-x32\...\{7914BE1E-F186-4790-B8F4-9F63C52A41C1}) (Version:  - )
Melody Assistant (HKLM-x32\...\Melody Assistant) (Version: 7.6.3i - Myriad SARL)
Microsoft .NET Framework 4.7 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.7.02053 - Microsoft Corporation)
Microsoft Access database engine 2010 (English) (HKLM\...\{90140000-00D1-0409-1000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Camera Codec Pack (HKLM\...\{D553E8CC-5C56-4B06-AC1A-A443DFF31092}) (Version: 6.3.9723.0 - Microsoft Corporation)
Microsoft Office Professional Plus 2010 (HKLM-x32\...\Office14.PROPLUSR) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50907.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729 (HKLM\...\{2DFD8316-9EF1-3210-908C-4CB61961C1AC}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{527BBE2F-1FED-3D8B-91CB-4DB0F838E69E}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\...\{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft WSE 3.0 Runtime (HKLM-x32\...\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}) (Version: 3.0.5305.0 - Microsoft Corp.)
Mixxx 2.0.0 (HKU\S-1-5-21-3289118944-4034126387-1954186238-1000\...\Mixxx (2.0.0)) (Version: 2.0.0 - The Mixxx Development Team)
Movie Maker (HKLM-x32\...\{38F03569-A636-4CF3-BDDE-032C8C251304}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Movie Maker (HKLM-x32\...\{DD67BE4B-7E62-4215-AFA3-F123A800A389}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Mozilla Firefox 43.0.1 (x86 en-US) (HKU\S-1-5-21-3289118944-4034126387-1954186238-1000\...\Mozilla Firefox 43.0.1 (x86 en-US)) (Version: 43.0.1 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation)
MyDVD Content Pack 1 (HKLM-x32\...\{ADCF7AE3-8E36-4B80-9460-66B74B56927F}) (Version: 1.00.0000 - Corel Corporation)
Myst Online: Uru Live (remove only) (HKLM-x32\...\MOUL) (Version:  - )
NETGEAR Genie (HKLM-x32\...\NETGEAR Genie) (Version: 2.4.12.00 - NETGEAR Inc.)
NewBlue Film Effects for Windows (HKLM-x32\...\NewBlue Film Effects for Windows) (Version: 3.0 - NewBlue)
Nexus Mod Manager (HKLM\...\6af12c54-643b-4752-87d0-8335503010de_is1) (Version: 0.45.2 - Black Tree Gaming)
Nik Collection (HKLM-x32\...\Nik Collection) (Version: 1.2.11 - Google)
Nuance PaperPort 12 (HKLM-x32\...\{6C0A559F-8583-4B5A-8B50-20BEE15D8E64}) (Version: 12.1.0000 - Nuance Communications, Inc.)
Nuance PDF Viewer Plus (HKLM-x32\...\{28656860-4728-433C-8AD4-D1A930437BC8}) (Version: 5.30.3290 - Nuance Communications, Inc)
NVIDIA PhysX (HKLM-x32\...\{3F5C371F-8EA2-4F25-9D3D-D0B4526E3AEA}) (Version: 9.10.0513 - NVIDIA Corporation)
Origin (HKLM-x32\...\Origin) (Version: 9.1.10.2728 - Electronic Arts, Inc.)
Painter 13 - Contentx64 (HKLM\...\{A16926CB-C4BF-4FC9-8F99-200236731FCA}) (Version: 13.1 - Corel Corporation) Hidden
Painter 13 - Core (HKLM\...\{B1EA198B-FF19-46C9-84DE-E2F3D11619ED}) (Version: 13.1 - Corel Corporation) Hidden
Painter 13 - Corex64 (HKLM\...\{DA929FB1-A118-4F6E-9AD6-729633E84805}) (Version: 13.0 - Corel Corporation) Hidden
Painter 13 - EN (HKLM\...\{61F6F8FC-C448-418E-BF14-8B272DFDD51B}) (Version: 13.1 - Corel Corporation) Hidden
Painter 13 - Setup Files (HKLM\...\{EF449371-6B69-49C8-B789-76A0B0E3446B}) (Version: 13.1 - Corel Corporation) Hidden
Pando Media Booster (HKLM-x32\...\{980A182F-E0A2-4A40-94C1-AE0C1235902E}) (Version: 2.6.0.7 - Pando Networks Inc.)
PaperPort Image Printer 64-bit (HKLM\...\{715CAACC-579B-4831-A5F4-A83A8DE3EFE2}) (Version: 1.00.0001 - Nuance Communications, Inc.)
Paradise (HKLM-x32\...\Paradise_is1) (Version:  - Ubisoft)
Pinnacle Instant DVD Recorder (HKLM-x32\...\{C1212AE3-DBB9-4365-8473-F8ABC7B06BBB}) (Version: 2.6.0.118 - Pinnacle Systems)
Pinnacle Studio 12 (HKLM-x32\...\{D041EB9E-890A-4098-8F94-51DA194AC72A}) (Version: 12.1.3.6605 - Pinnacle Systems)
Pinnacle Video Driver (HKLM\...\{6DE721A5-5E89-4D74-994C-652BB3C0672E}) (Version: 12.1.0.029 - Pinnacle Systems)
PitchPerfect Musical Instrument Tuner (HKU\S-1-5-21-3289118944-4034126387-1954186238-1000\...\PitchPerfect) (Version: 2.12 - NCH Software)
Pixillion Image Converter (HKU\S-1-5-21-3289118944-4034126387-1954186238-1000\...\Pixillion) (Version: 2.75 - NCH Software)
POW (HKLM-x32\...\{CD277B3E-8043-496E-B83B-D53186A072AB}) (Version: 1.00.0000 - Wide Games) Hidden
POW (HKLM-x32\...\InstallShield_{CD277B3E-8043-496E-B83B-D53186A072AB}) (Version: 1.00.0000 - Wide Games)
Prism Video File Converter (HKU\S-1-5-21-3289118944-4034126387-1954186238-1000\...\Prism) (Version: 2.18 - NCH Software)
proDAD Adorage 3.0 (64bit) (HKLM\...\proDAD-Adorage-3.0) (Version: 3.0.114.1 - proDAD GmbH) Hidden
proDAD Mercalli 2.0 (64bit) (HKLM\...\proDAD-Mercalli-2.0) (Version: 2.0.123 - proDAD GmbH) Hidden
proDAD Mercalli 2.0 (HKLM-x32\...\proDAD-Mercalli-2.0) (Version: 2.0.106 - proDAD GmbH) Hidden
proDAD Route 4.0 (64bit) (HKLM\...\proDAD-HeroglyphRoute-4.0) (Version: 4.0.241.1 - proDAD GmbH) Hidden
proDAD Route 4.0 (HKLM-x32\...\proDAD-HeroglyphRoute-4.0) (Version: 4.0.209.2 - proDAD GmbH) Hidden
proDAD Script 4.0 (64bit) (HKLM\...\proDAD-HeroglyphScript-4.0) (Version: 4.0.241.1 - proDAD GmbH) Hidden
proDAD Script 4.0 (HKLM-x32\...\proDAD-HeroglyphScript-4.0) (Version: 4.0.209.2 - proDAD GmbH) Hidden
proDAD Vitascene 2.0 (64bit) (HKLM\...\proDAD-Vitascene-2.0) (Version: 2.0.241 - proDAD GmbH) Hidden
proDAD Vitascene 2.0 (HKLM-x32\...\proDAD-Vitascene-2.0) (Version: 2.0.203 - proDAD GmbH) Hidden
PS3 Media Server (HKLM-x32\...\PS3 Media Server) (Version: 1.90.1 - PS3 Media Server)
PSPPContent (HKLM-x32\...\{006CAAEF-CA96-4181-AC22-FE56D61432E4}) (Version: 14.2.0.1 - Corel Corporation) Hidden
PSPPHelp (HKLM-x32\...\{00D74A7A-F7AD-4D00-ABD2-0973836292C7}) (Version: 14.2.0.1 - Corel Corporation) Hidden
PSPPro64 (HKLM\...\{0015DE8E-8D9F-403E-8E5A-4098410E6125}) (Version: 14.2.0.1 - Corel Corporation) Hidden
PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.986 - Even Balance, Inc.)
QuickTime 7 (HKLM-x32\...\{FF59BD75-466A-4D5A-AD23-AAD87C5FD44C}) (Version: 7.79.80.95 - Apple Inc.)
Raptr (HKLM-x32\...\Raptr) (Version: 5.2.3-r114633-release - Raptr, Inc)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6141 - Realtek Semiconductor Corp.)
Revo Uninstaller 2.0.4 (HKLM\...\{A28DBDA2-3CC7-4ADC-8BFE-66D7743C6C97}_is1) (Version: 2.0.4 - VS Revo Group, Ltd.)
Scansoft PDF Professional (HKLM-x32\...\{068724F8-D8BE-4B43-8DDD-B9FE9E49FD76}) (Version:  - ) Hidden
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version:  - Microsoft)
Setup (HKLM-x32\...\{00D13418-7DDF-4D3D-A237-E297B103BB6B}) (Version: 14.2.0.1 - Corel Corporation) Hidden
Setup (HKLM-x32\...\{6C6EEA9F-3998-4E0D-B91F-43CB218C715C}) (Version: 16.1.0.45 - Corel Corporation) Hidden
Setup (HKLM-x32\...\{F8B95E3C-40A0-49CE-B5F9-3861F238B9FF}) (Version: 19.5.0.35 - Corel Corporation) Hidden
Share (HKLM-x32\...\{AD7DA145-3118-4D69-BE89-D3ED1510BD15}) (Version: 16.1.0.45 - Corel Corporation) Hidden
Share64 (HKLM\...\{3008095C-B516-4A5E-8B99-F0E113C21C72}) (Version: 16.1.0.45 - Corel Corporation) Hidden
Share64 (HKLM\...\{A61EEC3A-E37C-49A5-BE61-7AEE04F1A15D}) (Version: 19.5.0.35 - Corel Corporation) Hidden
Shared C Run-time for x64 (HKLM\...\{EF79C448-6946-4D71-8134-03407888C054}) (Version: 10.0.0 - McAfee)
SketchUp 2013 (HKLM-x32\...\{B75BC01B-4586-43F8-9349-D250DB98F26F}) (Version: 13.0.4812 - Trimble Navigation Limited)
Skype™ 7.0 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.0.102 - Skype Technologies S.A.)
SmartSound Common Data (HKLM-x32\...\{B8A2869E-30CA-40C5-9CF8-BD7354E57EF8}) (Version: 1.1.0 - SmartSound Software Inc.) Hidden
SmartSound Common Data (HKLM-x32\...\InstallShield_{B8A2869E-30CA-40C5-9CF8-BD7354E57EF8}) (Version: 1.1.0 - SmartSound Software Inc.)
SmartSound Quicktracks 5 (HKLM-x32\...\{2F8BA3FD-1FA9-4279-B696-712ABB12F09F}) (Version: 5.1.6 - SmartSound Software Inc.) Hidden
SmartSound Quicktracks 5 (HKLM-x32\...\InstallShield_{2F8BA3FD-1FA9-4279-B696-712ABB12F09F}) (Version: 5.1.6 - SmartSound Software Inc.)
Spotify (HKU\S-1-5-21-3289118944-4034126387-1954186238-1000\...\Spotify) (Version: 1.0.72.117.g6bd7cc73 - Spotify AB)
StarCraft II (HKLM-x32\...\StarCraft II) (Version:  - Blizzard Entertainment)
Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation)
theHunter Launcher (HKLM-x32\...\FBDFBE7F-2DB8-47E2-B88E-32F4A2A74AA8_is1) (Version: 620 - Expansive Worlds)
Unity Web Player (HKU\S-1-5-21-3289118944-4034126387-1954186238-1000\...\UnityWebPlayer) (Version:  - Unity Technologies ApS)
Uplay (HKLM-x32\...\Uplay) (Version: 2.0 - Ubisoft)
VideoStudio MyDVD (HKLM-x32\...\{7521A578-BDF3-412C-8959-57498EBBEDD9}) (Version: 1.0.129 - Corel Corporation) Hidden
VideoStudio MyDVD (HKLM-x32\...\{91345797-EF07-41D2-85F4-BFF200B6A0A3}) (Version: 1.0 - Corel)
Visual C++ 2008 - x64 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{6DA2B636-698A-3294-BF4A-B5E11B238CDD}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation)
Visual C++ 2008 - x64 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{8CCEA24C-51AE-3B71-9092-7D0C44DDA2DF}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation)
Visual C++ 2008 - x64 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{C3A57BB3-9AA6-3F6F-9395-6C062BDD5FC4}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation)
Visual C++ 2008 - x64 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{F6F09DD8-F39B-3A16-ADB9-C9E6B56903F9}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation)
Visual C++ 2008 - x86 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{04B34E21-5BEE-3D2B-8D3D-E3E80D253F64}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation)
Visual C++ 2008 - x86 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{14866AAD-1F23-39AC-A62B-7091ED1ADE64}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation)
Visual C++ 2008 - x86 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{4B90093A-5D9C-3956-8ABB-95848BE6EFAD}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation)
Visual C++ 2008 - x86 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{B42E259C-E4D4-37F1-A1B2-EB9C4FC5A04D}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation)
VLC media player 2.0.8 (HKLM-x32\...\VLC media player) (Version: 2.0.8 - VideoLAN)
VSClassic (HKLM-x32\...\{D0096E50-D99E-4178-A988-E5192B6F6B91}) (Version: 16.1.0.45 - Corel Corporation) Hidden
VSClassic64 (HKLM\...\{99B95309-4793-43D9-8F1C-EC086FC74CB5}) (Version: 19.5.0.35 - Corel Corporation) Hidden
VSHelp (HKLM-x32\...\{D9DD0D4F-6E5A-484D-AD8C-FD3BAF5D4450}) (Version: 16.1.0.45 - Corel Corporation) Hidden
VSPro (HKLM-x32\...\{D88D7ECD-F173-4A97-96F9-2B05C5DC90DC}) (Version: 16.1.0.45 - Corel Corporation) Hidden
VSUltimate64 (HKLM\...\{3F5D769B-346B-487A-851A-A1AF147D5B39}) (Version: 19.5.0.35 - Corel Corporation) Hidden
Wacom Tablet (HKLM\...\Wacom Tablet Driver) (Version: 6.3.17-3 - Wacom Technology Corp.)
WebTablet FB Plugin 32 bit (HKLM-x32\...\Wacom WebTabletPlugin for Internet Explorer and Netscape) (Version: 2.1.0.7 - Wacom Technology Corp.)
WebTablet FB Plugin 64 bit (HKLM\...\Wacom WebTabletPlugin for Internet Explorer and Netscape) (Version: 2.1.0.7 - Wacom Technology Corp.)
Windows Driver Package - Dynastream Innovations, Inc. ANT LibUSB Drivers (04/11/2012 1.2.40.201) (HKLM\...\F9D2A789F9CFF8CEC36B544F53877C80F1F73C46) (Version: 04/11/2012 1.2.40.201 - Dynastream Innovations, Inc.)
Windows Driver Package - Silicon Labs Software (DSI_SiUSBXp_3_1) USB  (02/06/2007 3.1) (HKLM\...\D1506E0025B5A3F9EB8270FE81C1EEDD9388B8A2) (Version: 02/06/2007 3.1 - Silicon Labs Software)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation)
Windows Media Encoder 9 Series (HKLM-x32\...\Windows Media Encoder 9) (Version:  - )
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{00F064D8-FEC3-48ac-B07D-39C314D1727B}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\ServiceModule.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{0B38CACA-3D3C-48EA-BEB5-7D95F4F6EE15}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{1481B385-759A-4B00-9257-E96357563999}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{1E8A29BA-827D-4031-A4A3-AE7999B402F6}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{2BCA857B-A18B-4AFA-B183-CC0E49C12058}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{3FC94EB5-AEBD-4f3f-A2A4-B6CE57113C01}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\RxAppDocView.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{4B40437B-8972-4444-BBE3-1588FF55F203}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{5544903C-2CCC-487C-91BB-F310B72A8E9B}\InprocServer32 -> AcETransmit.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{64B99FDB-1D85-447F-98C7-569DBDA723DB}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{7293E009-3015-4AD3-96EC-D42C36B5FCE3}\InprocServer32 -> AcETransmit.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{7BA16B3F-1AB3-4BD7-B959-52C4B8504EE9}\InprocServer32 -> AcInetUI.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{B2A579E0-A797-40B1-8AEE-A8F6404719F8}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{B8E7214B-25CA-4116-84CB-E86FB9625B36}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\ServiceModule.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{BF4CC07E-E9BB-40D6-873F-855B211033B9}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{C92F8F8C-8B2C-11d4-B872-0060B0EC020B}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\DtBridge.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{D7A1987D-4A73-11D1-9A4B-080009DCE505}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\ColorButton.Ocx => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{DB5D476B-3FF4-4E9D-A606-1E2B473BE571}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\AcInetUI.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{DF6525C2-6358-4B07-813D-708120C5FE1A}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{E70DE962-842A-4488-9481-1D0FD72A020F}\InprocServer32 -> axdb.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{F2D4F4E5-EEA1-46FF-A83B-A270C92DAE4B}\InprocServer32 -> C:\Program Files\Autodesk\Inventor 2016\Bin\DTInterop.dll => No File
CustomCLSID: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000_Classes\CLSID\{F868EAEC-1B73-4F5E-BA73-90EBA94E75BE}\InprocServer32 -> axdb.dll => No File
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2010-11-18] (Igor Pavlov)
ContextMenuHandlers1-x32: [Autodesk.DWF.ContextMenu] -> {6C18531F-CA85-45F7-8278-FF33CF0A5964} => C:\Program Files (x86)\Common Files\Autodesk Shared\DWF Common\DWFShellExtension.dll [2012-01-06] (Autodesk, Inc.)
ContextMenuHandlers1-x32: [Corel PaintShop Pro X4] -> {CA34A346-C652-4F33-8CFF-FD6A91D9D64A} => c:\Program Files (x86)\Corel\Corel PaintShop Pro X4\PSPContextMenu64.dll [2012-05-11] (Corel Software, Inc.)
ContextMenuHandlers1-x32: [McCtxMenuFrmWrk] -> {CCA9EFD3-29ED-430A-BA6D-E6BBFF0A60C2} => c:\Program Files\McAfee\MSC\McCtxMenuFrmWrk.dll [2017-07-10] (McAfee, Inc.)
ContextMenuHandlers2: [Corel PaintShop Pro X4] -> {CA34A346-C652-4F33-8CFF-FD6A91D9D64A} => c:\Program Files (x86)\Corel\Corel PaintShop Pro X4\PSPContextMenu64.dll [2012-05-11] (Corel Software, Inc.)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-11-01] (Malwarebytes)
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2010-11-18] (Igor Pavlov)
ContextMenuHandlers4: [Corel PaintShop Pro X4] -> {CA34A346-C652-4F33-8CFF-FD6A91D9D64A} => c:\Program Files (x86)\Corel\Corel PaintShop Pro X4\PSPContextMenu64.dll [2012-05-11] (Corel Software, Inc.)
ContextMenuHandlers5: [ACE] -> {5E2121EE-0300-11D4-8D3B-444553540000} => C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\atiacm64.dll [2015-05-05] (Advanced Micro Devices, Inc.)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-11-01] (Malwarebytes)
ContextMenuHandlers6: [McCtxMenuFrmWrk] -> {CCA9EFD3-29ED-430A-BA6D-E6BBFF0A60C2} => c:\Program Files\McAfee\MSC\McCtxMenuFrmWrk.dll [2017-07-10] (McAfee, Inc.)
ContextMenuHandlers6_S-1-5-21-3289118944-4034126387-1954186238-1000: [InventorMenu] -> {6FDE7A70-351B-11d6-988B-0010B57A8BB7} =>  -> No File
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {12D74CB1-D95F-4343-A23A-6763BEAA42CB} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {36B966E5-B8D6-49FF-80A1-B1B4136C751E} - System32\Tasks\GarminUpdaterTask => C:\Program Files (x86)\Garmin\Express Self Updater\ExpressSelfUpdater.exe
Task: {4678B207-E35D-4E4E-BE9C-DABD7B77A524} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2016-02-23] (Apple Inc.)
Task: {4FAD17B9-4EEB-4CAD-803C-1B43BD161CEB} - \McAfeeLogon -> No File <==== ATTENTION
Task: {722FEA3D-3848-4774-A087-454E746A904A} - System32\Tasks\McAfee\McAfee Idle Detection Task
Task: {8A289A42-417A-45DD-A36F-2F581B27307B} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_28_0_0_137_pepper.exe [2018-01-09] (Adobe Systems Incorporated)
Task: {B3C459B3-51D7-4679-82D8-96BDEB286107} - \McAfee Remediation (Prepare) -> No File <==== ATTENTION
Task: {C207FBBE-E6C7-4912-AE92-66921801C453} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {D351F207-C8DE-43F2-9261-EE932A351F29} - System32\Tasks\GoogleUpdateTaskMachineUA1d0908d4088e86f => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {EC8807A2-747B-4034-AA6B-0A6DFA75F885} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2018-01-09] (Adobe Systems Incorporated)
Task: {EE2CC55D-8C31-44A8-94DC-A86099E682C2} - System32\Tasks\{16D7FACF-B0D1-48F8-9C02-E3A61932FA80} => "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" hxxp://ui.skype.com/ui/0/6.7.0.102/en/abandoninstall?page=tsProgressBar
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
 
==================== Shortcuts & WMI ========================
 
(The entries could be listed to be restored or removed.)
 
 
Shortcut: C:\Users\Teschke\Favorites\Dustin\NCH Software Download Site.lnk -> hxxp://www.nchsoftware.com/index.htm
 
ShortcutWithArgument: C:\Users\Teschke\Desktop\Games\Art & Media\VideoStudio X9 Training.lnk -> C:\Program Files (x86)\Internet Explorer\iexplore.exe (Microsoft Corporation) -> www.studiobacklot.tv/videostudioX9
ShortcutWithArgument: C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Web Applications\_crx_mkdmfheflfmedmfjolgifliincdhfgdl\Slender Space.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) ->  --profile-directory=Default --app-id=mkdmfheflfmedmfjolgifliincdhfgdl
ShortcutWithArgument: C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Web Applications\_crx_jangaedeekciafhlanphhnalogmhefmo\theHunter.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) ->  --profile-directory=Default --app-id=jangaedeekciafhlanphhnalogmhefmo
ShortcutWithArgument: C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Web Applications\_crx_fplklihjpkinahlihcljhnnlnhnmmhdp\Counter Strike Online.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) ->  --profile-directory=Default --app-id=fplklihjpkinahlihcljhnnlnhnmmhdp
ShortcutWithArgument: C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Web Applications\_crx_bmekbplkjhgmljmbblmhmcnocafhaink\BeGone_ Last Stand HD.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) ->  --profile-directory=Default --app-id=bmekbplkjhgmljmbblmhmcnocafhaink
ShortcutWithArgument: C:\Users\Teschke\AppData\Local\Google\Chrome\User Data\Default\Web Applications\_crx_alnfdikmbdfgkcbdodjcbmedanjinmkk\Beatlab.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) ->  --profile-directory=Default --app-id=alnfdikmbdfgkcbdodjcbmedanjinmkk
ShortcutWithArgument: C:\Users\Teschke\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\9501e18d7c2ab92e\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory="Profile 2"
ShortcutWithArgument: C:\Users\Teschke\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\225bb61db2f318c1\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory="Profile 3"
 
==================== Loaded Modules (Whitelisted) ==============
 
2013-04-18 01:51 - 2009-11-04 12:18 - 000189440 _____ () C:\Windows\system32\spool\PRTPROCS\x64\lxeadrpp.dll
2013-09-05 00:17 - 2013-09-05 00:17 - 004300456 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF
2010-10-20 14:23 - 2010-10-20 14:23 - 008801632 _____ () C:\Program Files\Microsoft Office\Office14\1033\GrooveIntlResource.dll
2013-11-16 13:28 - 2005-04-21 23:36 - 000143360 ____R () C:\Windows\system32\BrSNMP64.dll
2017-11-24 18:55 - 2017-12-12 04:53 - 002358728 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\MwacLib.dll
2017-11-24 18:55 - 2017-12-12 04:53 - 002301384 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\SelfProtectionSdk.dll
2016-09-23 19:08 - 2016-07-14 15:45 - 001661392 _____ () C:\Program Files\Tablet\Wacom\libxml2.dll
2017-06-01 14:58 - 2017-07-06 14:58 - 000595608 _____ () C:\Program Files\McAfee\MfeAV\RealProtectAMScanIf.dll
2017-06-01 14:58 - 2017-07-06 14:58 - 000584680 _____ () C:\Program Files\McAfee\MfeAV\RepairModule.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
AlternateDataStreams: C:\Users\Public\AppData:CSM [460]
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mbamchameleon => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ModuleCoreService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mbamchameleon => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcapexe => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeaack => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeaack.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeavfk => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeavfk.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefire => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfemms => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeplk => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeplk.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfetdi2k => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfetdi2k.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfevtp => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ModuleCoreService => ""="Service"
 
==================== Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
IE trusted site: HKU\S-1-5-21-3289118944-4034126387-1954186238-1000\...\dell.com -> dell.com
 
==================== Hosts content: ===============================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2009-07-13 21:34 - 2009-06-10 16:00 - 000000824 _____ C:\Windows\system32\Drivers\etc\hosts
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-3289118944-4034126387-1954186238-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Teschke\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 199.166.6.2 - 209.239.11.98
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
MSCONFIG\Services: AdobeARMservice => 2
MSCONFIG\Services: Apple Mobile Device Service => 2
MSCONFIG\Services: Garmin Device Interaction Service => 2
MSCONFIG\Services: iPod Service => 3
MSCONFIG\Services: lxea_device => 2
MSCONFIG\Services: NETGEARGenieDaemon => 3
MSCONFIG\Services: SkypeUpdate => 2
MSCONFIG\startupfolder: C:^Users^Admin^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2010 Screen Clipper and Launcher.lnk => C:\Windows\pss\OneNote 2010 Screen Clipper and Launcher.lnk.Startup
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: Akamai NetSession Interface => "C:\Users\Admin\AppData\Local\Akamai\netsession_win.exe"
MSCONFIG\startupreg: APSDaemon => "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
MSCONFIG\startupreg: Corel Update Helper => "c:\Program Files\Corel\Corel VideoStudio X9\pua.exe" /t
MSCONFIG\startupreg: fssui => "C:\Program Files (x86)\Windows Live\Family Safety\fsui.exe" -autorun
MSCONFIG\startupreg: GarminExpressTrayApp => "C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe"
MSCONFIG\startupreg: ISUSPM => C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe -scheduler
MSCONFIG\startupreg: iTunesHelper => "C:\Program Files\iTunes\iTunesHelper.exe"
MSCONFIG\startupreg: LWS => C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe -hide
MSCONFIG\startupreg: Raptr => "C:\Program Files (x86)\Raptr Inc\Raptr\raptrstub.exe" --startup
MSCONFIG\startupreg: StartCCC => "C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [{F16ECB23-8787-4B80-BA61-02E5DFB8EBCF}] => (Allow) C:\Windows\system32\lxeacoms.exe
FirewallRules: [{32F84DA2-A985-4218-8BA3-1E6EFEC4A1BB}] => (Allow) C:\Program Files (x86)\Pinnacle\Studio 12\Programs\RM.exe
FirewallRules: [{70073B3D-DB28-443F-A95D-846B197BA271}] => (Allow) C:\Program Files (x86)\Pinnacle\Studio 12\Programs\RM.exe
FirewallRules: [{AAF56D47-E704-4924-B85E-7A9E344D8A0A}] => (Allow) C:\Program Files (x86)\Pinnacle\Studio 12\Programs\Studio.exe
FirewallRules: [{E30DFCBC-0367-4E35-A307-4CCAA64F1165}] => (Allow) C:\Program Files (x86)\Pinnacle\Studio 12\Programs\Studio.exe
FirewallRules: [{789CAFB5-E298-41C2-B5F0-C0732DF3F8E3}] => (Allow) C:\Program Files (x86)\Pinnacle\Studio 12\Programs\umi.exe
FirewallRules: [{C02D669A-832C-4E6A-9558-829864F25463}] => (Allow) C:\Program Files (x86)\Pinnacle\Studio 12\Programs\umi.exe
FirewallRules: [{CF129E27-7FB6-48D9-BCE2-D463091BAEDF}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{83972B14-0AA1-4EDB-8FE9-E17058EC761F}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{46DFC88A-8ADB-4927-8684-D514B1F21923}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{08B5C287-8BD1-41AD-B820-1A9FE91F3209}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Breach\Breach.exe
FirewallRules: [{E6BB2592-510D-4A37-AF32-27B048F5EF6E}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Breach\Breach.exe
FirewallRules: [{B1DCB9FB-B224-4B2F-AB37-1C6C45EDBA83}] => (Allow) C:\Program Files (x86)\Steam\bin\steamservice.exe
FirewallRules: [{60327E3C-B0BF-455D-8B68-55C352A13F86}] => (Allow) C:\Program Files (x86)\Steam\bin\steamservice.exe
FirewallRules: [{8BE08515-A9DA-44E2-8B4C-5B863A5FCB9D}] => (Allow) C:\Program Files (x86)\Steam\bin\steamservice.exe
FirewallRules: [{583027FB-C067-45CE-81B3-CF85F9F6D9B2}] => (Allow) C:\Program Files (x86)\Steam\bin\steamservice.exe
FirewallRules: [{81C1C6D9-D3C6-43A0-8E29-EF861AE114E6}] => (Allow) C:\Program Files (x86)\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe
FirewallRules: [{56FA6971-E199-4C34-A879-B36C761D7CF1}] => (Allow) C:\Program Files (x86)\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe
FirewallRules: [{1B889BC2-A65B-4A01-8E24-273A5B660318}] => (Allow) C:\Program Files (x86)\UBISOFT\Assassin's Creed III\AC3SP.exe
FirewallRules: [{2F42C95D-B079-40E0-83CE-AE027A6C9A6F}] => (Allow) C:\Program Files (x86)\UBISOFT\Assassin's Creed III\AC3SP.exe
FirewallRules: [{8522CB95-9EFE-4A37-AF87-82E6C1DD6705}] => (Allow) C:\Program Files (x86)\UBISOFT\Assassin's Creed III\AC3MP.exe
FirewallRules: [{424DB30E-5233-4284-A693-8B4E858DAA16}] => (Allow) C:\Program Files (x86)\UBISOFT\Assassin's Creed III\AC3MP.exe
FirewallRules: [{7A861EB4-6A29-470D-912B-4A563E7AE6F7}] => (Allow) C:\Program Files (x86)\UBISOFT\Assassin's Creed III\AssassinsCreed3.exe
FirewallRules: [{2B63F9F1-4C21-4476-A80A-C8C4CEA573C8}] => (Allow) C:\Program Files (x86)\UBISOFT\Assassin's Creed III\AssassinsCreed3.exe
FirewallRules: [{FB653026-B559-4FD3-9828-40A5761DCF38}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Portal 2\portal2.exe
FirewallRules: [{44ECF51C-3A54-4861-9A4E-25E82FC6B9BB}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Portal 2\portal2.exe
FirewallRules: [{8B185093-81EA-4EF5-9BB8-D730D6CC8818}] => (Allow) C:\Program Files (x86)\Origin Games\Crysis 3\Bin32\Crysis3.exe
FirewallRules: [{8F55590B-9251-41AF-A5D8-9EAF2E8DBA24}] => (Allow) C:\Program Files (x86)\Origin Games\Crysis 3\Bin32\Crysis3.exe
FirewallRules: [{B6B2D2BA-1409-4C46-94AF-1F28FCFEA063}] => (Allow) C:\Program Files (x86)\StarCraft II\StarCraft II.exe
FirewallRules: [{5E3F7B0C-853E-49E7-9770-17AB687715B6}] => (Allow) C:\Program Files (x86)\StarCraft II\StarCraft II.exe
FirewallRules: [{D08C82D9-40F1-4664-A9F8-54CEE92A3954}] => (Allow) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
FirewallRules: [{2F80630E-EB85-4814-B7BC-8C206124D93C}] => (Allow) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
FirewallRules: [{C47E9DCF-FF13-49FD-A5D0-734E0BE00521}] => (Allow) C:\Program Files (x86)\theHunter\launcher\launcher.exe
FirewallRules: [{28C8990C-A52A-42C4-BA8D-1CD40DC43CE8}] => (Allow) C:\Program Files (x86)\theHunter\launcher\launcher.exe
FirewallRules: [{71709164-B6F2-4805-8AED-1D567AF8B96D}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Skyrim\SkyrimLauncher.exe
FirewallRules: [{95EEC40A-0EFF-447A-BA96-1DD5F4A38C05}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Skyrim\SkyrimLauncher.exe
FirewallRules: [{B558288E-5444-4364-B99F-389093101A3E}] => (Allow) C:\Program Files\Lightworks\Lightworks.exe
FirewallRules: [{F81BB928-631A-413E-898B-4ECEC619B624}] => (Allow) C:\Program Files\Lightworks\Lightworks.exe
FirewallRules: [{69CE75F1-E33F-42DC-85F9-7D176E2076E9}] => (Allow) C:\Program Files\Lightworks\ntcardvt.exe
FirewallRules: [{35ADB5EC-FEF0-41B2-8FD7-2B6163B06ACF}] => (Allow) C:\Program Files\Lightworks\ntcardvt.exe
FirewallRules: [{5D802E51-2D70-44E7-8A38-77ECEF4CC79F}] => (Allow) LPort=54925
FirewallRules: [{57298198-28C7-4134-8EE0-B517E2C6FE44}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\XCom-Enemy-Unknown\Binaries\Win32\XComGame.exe
FirewallRules: [{6159DE13-EE45-4911-B28C-8DB4F584A284}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\XCom-Enemy-Unknown\Binaries\Win32\XComGame.exe
FirewallRules: [{810F18D6-3CE1-43F1-9AC3-63041511EEE2}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{84C693B9-AEE3-4795-8165-7130A2F00058}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{02CCF350-0DBE-42BD-BFAB-0DF64DF10A13}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Team Fortress 2\hl2.exe
FirewallRules: [{FE8CAA48-E29E-44EC-9FFC-3C1945874D49}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Team Fortress 2\hl2.exe
FirewallRules: [{155E1331-C6F6-4586-B71D-833CC783B829}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{2CF8A5C6-7885-4901-A242-CF3CFDD7DC7D}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{5003C5AF-24F5-4759-AD3F-40E5648BF602}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Team Fortress 2\hl2.exe
FirewallRules: [{41EA998E-B4A6-4ED7-9191-256963A00DA1}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Team Fortress 2\hl2.exe
FirewallRules: [{72B155B7-7D16-414D-B3E7-92D341959244}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{DBE8985D-BEB3-4F04-8B14-2CFB90EDD6A7}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{99E88E28-5A6C-48BB-ADE3-EB7607181196}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{DDB7BF02-1D82-4E33-B090-A5C1664879B6}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{6984E421-BCAD-4E9D-A092-C103A0FDE4A1}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{0BE8AC0C-EE47-439C-AF37-A16BAD69A9DA}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{7D33A7E0-AF82-4C7C-BF7B-31FBFD51C52C}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{14D8F6D2-9205-4683-A37B-CA5CFA42A57A}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{F7049409-B56D-4686-93A8-11FF390C7229}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{B33040E5-F29A-4AD7-A33E-284AC16C3305}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{3C457650-44A0-4AA0-8389-D3A828ACA345}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Team Fortress 2\hl2.exe
FirewallRules: [{3DB6FA17-1D3B-437F-9D7A-ACBA9266E6DB}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Team Fortress 2\hl2.exe
FirewallRules: [{2325C2C9-0C15-4800-8C7D-F658C7FE2F00}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Team Fortress 2\hl2.exe
FirewallRules: [{545E5F7D-11D8-4E1F-A1A0-223BC753ADDC}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Team Fortress 2\hl2.exe
FirewallRules: [{B13739F0-FC71-4183-84C5-FA460F17C6B6}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.1040\Agent.exe
FirewallRules: [{34D763EF-0F01-41EF-B98D-AC336699F93E}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.1040\Agent.exe
FirewallRules: [{F49C1CFE-07C7-46DB-993A-238C1DAA027F}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2380\Agent.exe
FirewallRules: [{7AC1CA3F-4D02-4B48-AE8C-BE962C944C2C}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2380\Agent.exe
FirewallRules: [{A7D771AD-9480-4250-8920-DDEA6D1A8F4D}] => (Allow) C:\Program Files (x86)\StarCraft II\StarCraft II Public Test.exe
FirewallRules: [{EEFB70E1-9211-4B71-866B-7B0844415455}] => (Allow) C:\Program Files (x86)\StarCraft II\StarCraft II Public Test.exe
FirewallRules: [{01B75E99-AC2A-44D9-84AB-68D2E82C71AA}] => (Allow) C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
FirewallRules: [{7BE16534-A3E4-4E98-B6F2-48CA2B4BA3D0}] => (Allow) C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
FirewallRules: [{BE65226B-F667-46E5-A4E8-3C9036FC7D14}] => (Allow) C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
FirewallRules: [{0C669D17-C76D-41DF-A453-CA03F4D86CCF}] => (Allow) C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
FirewallRules: [{58732465-04C5-4EF0-80C0-EFD5391E965B}] => (Allow) C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe
FirewallRules: [{E78FB3E8-57EA-49AA-B20A-EE3F70903C4C}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{47FE0346-4C48-4A50-8A77-18EA37EC9B07}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\dota.exe
FirewallRules: [{EB77F046-CD9F-4C38-B7BF-F856EDD35F14}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{1D42B23D-921C-4E36-8B87-E2D90D0834FE}] => (Allow) LPort=2869
FirewallRules: [{0030EE09-4BAA-4E9F-A64C-F79381EFE987}] => (Allow) LPort=1900
FirewallRules: [{2A29E2C7-0BA4-483A-8F64-F52609F4A4FB}] => (Allow) C:\Program Files (x86)\Hearthstone\Hearthstone.exe
FirewallRules: [{D7A56D14-7B35-44EB-A09B-E36452560FCF}] => (Allow) C:\Program Files (x86)\Hearthstone\Hearthstone.exe
FirewallRules: [{556C1B3C-3F15-45C2-9D70-CA864CBDADE9}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2880\Agent.exe
FirewallRules: [{BE479DD9-893C-4D2F-AA5D-92D2E34946AF}] => (Allow) C:\ProgramData\Battle.net\Agent\Agent.2880\Agent.exe
FirewallRules: [{7B41D613-A78E-4B35-A706-138CBF201879}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\JABIA\JaggedAllianceBIA.exe
FirewallRules: [{5CEF6981-E7B6-43D9-AF71-06491F6E4836}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\JABIA\JaggedAllianceBIA.exe
FirewallRules: [{EF58DAEF-A76C-47EA-B618-112AB60643C8}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{05CBE5C7-ACB2-46D4-9D26-0605916DB72F}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{00D1F223-C0CF-449A-A132-7618F3F6D4B9}] => (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe
FirewallRules: [{49D6483D-2FA4-48D4-89F3-6D0A21A794EB}] => (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe
FirewallRules: [{F2D3D2AE-086F-4199-81AE-4645F4CF383D}] => (Allow) C:\Program Files (x86)\UBISOFT\Far Cry 2\bin\FarCry2.exe
FirewallRules: [{C28F70F2-9FC7-476D-82E1-FF447DD35154}] => (Allow) C:\Program Files (x86)\UBISOFT\Far Cry 2\bin\FarCry2.exe
FirewallRules: [{46347C9C-4AE9-4DF5-A15C-0C2B674058C1}] => (Allow) C:\Program Files (x86)\UBISOFT\Far Cry 2\bin\FC2Launcher.exe
FirewallRules: [{89B65C34-E2D0-4987-90C6-7744EC436736}] => (Allow) C:\Program Files (x86)\UBISOFT\Far Cry 2\bin\FC2Launcher.exe
FirewallRules: [{D4FBEAC5-E679-4086-9DE4-3965604F11DA}] => (Allow) C:\Program Files (x86)\UBISOFT\Far Cry 2\bin\FC2Editor.exe
FirewallRules: [{D4C131B3-4646-4F46-9D4D-36DB2F00C7A5}] => (Allow) C:\Program Files (x86)\UBISOFT\Far Cry 2\bin\FC2Editor.exe
FirewallRules: [{5EE985CB-9EA4-4B04-BD6F-87E8DD8E7961}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{C1CFD1DC-DFC6-410F-9BB3-1A3681CA6D17}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{8AEEBC88-98FB-46C7-B479-EDF5818C072B}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{C6796B54-ACAF-4FB2-891E-36F8DCA5E6A1}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [TCP Query User{5A03840E-2B1C-4CA8-9516-B3A70A455B08}C:\program files (x86)\daide\quickstart\aiserver\aiserver.exe] => (Block) C:\program files (x86)\daide\quickstart\aiserver\aiserver.exe
FirewallRules: [UDP Query User{1080189C-898C-4245-BE92-EEAE22DAA1DD}C:\program files (x86)\daide\quickstart\aiserver\aiserver.exe] => (Block) C:\program files (x86)\daide\quickstart\aiserver\aiserver.exe
FirewallRules: [{BFC1DB99-77B5-4AC0-9464-240FCBA70894}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{881BA182-0CC1-4EA1-BE0C-E54B0436A797}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2.exe
FirewallRules: [{01A5C88B-73F5-4B59-B01C-DCFCB756C85F}] => (Allow) C:\Program Files (x86)\Raptr\raptr.exe
FirewallRules: [{88AD7A8D-DFDA-4267-BE87-C2F534A45E34}] => (Allow) C:\Program Files (x86)\Raptr\raptr.exe
FirewallRules: [{5326A4A9-4F4F-4B39-8D03-C662C07A7E2B}] => (Allow) C:\Program Files (x86)\Raptr\raptr_im.exe
FirewallRules: [{07ADBAC2-B989-4F09-ACF2-8FF03CC263A6}] => (Allow) C:\Program Files (x86)\Raptr\raptr_im.exe
FirewallRules: [{B500E6F5-4E07-45DE-B0B5-8DB571C79FCC}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2cfg.exe
FirewallRules: [{EB3C113F-C0B6-4EFB-9DA7-BBED24F557F7}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\dota 2 beta\game\bin\win64\dota2cfg.exe
FirewallRules: [{BFAA2466-2AB3-4949-8A00-5AF6CB3C3157}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{30820C6B-C2A0-4A23-9D32-72EE33068630}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{2CC22695-DA31-45BB-8966-C7F013D0D69F}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{C8E47915-3EB8-4F4C-81F0-65557EB69481}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{E00F6D8F-53E9-4771-8BDC-4BB62EB4B4F1}] => (Allow) C:\Program Files\iTunes\iTunes.exe
FirewallRules: [{256D452F-606F-4DF8-99E8-89B2AAF0C1AC}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Dirty Bomb\Binaries\Win32\ShooterGame-Win32-Shipping.exe
FirewallRules: [{3F642655-712C-4445-B6DB-35B2D6CA2493}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Dirty Bomb\Binaries\Win32\ShooterGame-Win32-Shipping.exe
FirewallRules: [{C38C6387-76A9-43F2-96FD-929D9B227CE4}] => (Allow) C:\Program Files (x86)\Raptr Inc\Raptr\raptr.exe
FirewallRules: [{91E9E38B-7E45-4B09-8F10-3F90E197E61E}] => (Allow) C:\Program Files (x86)\Raptr Inc\Raptr\raptr.exe
FirewallRules: [{AE2791DC-926C-4224-B936-4CCCD6159DD8}] => (Allow) C:\Program Files (x86)\Raptr Inc\Raptr\raptr_im.exe
FirewallRules: [{DDA14856-5CA6-4116-A154-8834570ACDDB}] => (Allow) C:\Program Files (x86)\Raptr Inc\Raptr\raptr_im.exe
FirewallRules: [TCP Query User{36F416F9-5BD2-4CF3-BD5C-FAF7440DCC03}C:\users\admin\appdata\local\akamai\netsession_win.exe] => (Allow) C:\users\admin\appdata\local\akamai\netsession_win.exe
FirewallRules: [UDP Query User{E84D30D4-10B8-462A-B495-7155F8D93547}C:\users\admin\appdata\local\akamai\netsession_win.exe] => (Allow) C:\users\admin\appdata\local\akamai\netsession_win.exe
FirewallRules: [{67209B8B-EF3E-414D-9C12-1BA3BBEC131B}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [{7D993D04-3A22-4717-9405-31BFD263C246}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [{18B5C50C-A5C5-4007-A6A5-4121C385EF08}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Dirty Bomb\DirtyBombLauncher.exe
FirewallRules: [{51EAC435-D1B9-47AF-9AC1-8CFE2B8E3ECC}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Dirty Bomb\DirtyBombLauncher.exe
FirewallRules: [TCP Query User{58174CC5-FF62-4FB3-965C-06C7FA8C10B9}C:\program files (x86)\starcraft ii\versions\base51149\sc2_x64.exe] => (Block) C:\program files (x86)\starcraft ii\versions\base51149\sc2_x64.exe
FirewallRules: [UDP Query User{5E8D7FC0-8562-4069-82DC-BA8D65674A71}C:\program files (x86)\starcraft ii\versions\base51149\sc2_x64.exe] => (Block) C:\program files (x86)\starcraft ii\versions\base51149\sc2_x64.exe
FirewallRules: [TCP Query User{AC30B663-D262-4232-86A1-ECF9527D3B52}C:\program files (x86)\starcraft ii\versions\base51702\sc2_x64.exe] => (Block) C:\program files (x86)\starcraft ii\versions\base51702\sc2_x64.exe
FirewallRules: [UDP Query User{EF86E717-134A-42CB-9C52-BE75AA178E84}C:\program files (x86)\starcraft ii\versions\base51702\sc2_x64.exe] => (Block) C:\program files (x86)\starcraft ii\versions\base51702\sc2_x64.exe
FirewallRules: [TCP Query User{D15692F9-2135-4005-B6C9-F8BDB276BF53}C:\program files (x86)\starcraft ii\support\sc2editor.exe] => (Block) C:\program files (x86)\starcraft ii\support\sc2editor.exe
FirewallRules: [UDP Query User{3E00FE2D-5D60-4B84-9B9D-A57BD840EDCB}C:\program files (x86)\starcraft ii\support\sc2editor.exe] => (Block) C:\program files (x86)\starcraft ii\support\sc2editor.exe
FirewallRules: [TCP Query User{2D5D6177-FA3C-4AD5-A788-BC88D5B8D392}C:\users\teschke\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\teschke\appdata\roaming\spotify\spotify.exe
FirewallRules: [UDP Query User{9CC7B4A3-0435-4270-AEE4-EA906E29B995}C:\users\teschke\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\teschke\appdata\roaming\spotify\spotify.exe
FirewallRules: [{BCE6458B-7347-4CAD-A3C5-5D36B837848A}] => (Allow) C:\Program Files (x86)\Google\Chrome Remote Desktop\63.0.3239.32\remoting_host.exe
FirewallRules: [TCP Query User{8016F667-550B-47F6-A163-A6ECC5DEFC51}C:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe
FirewallRules: [UDP Query User{4290882B-C43B-4A07-A3D5-DBF0EF281827}C:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe
FirewallRules: [TCP Query User{C84F8A5F-D20C-4E1E-8778-CE5C3E7834E9}C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe
FirewallRules: [UDP Query User{C7D11005-6FD5-413E-BD97-07843AFF24CD}C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) C:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe
FirewallRules: [TCP Query User{1D5A22B0-A2B6-4F48-85EF-3247698D1E3A}C:\program files\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe] => (Allow) C:\program files\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe
FirewallRules: [UDP Query User{1D1F93FA-574A-4942-8CD9-98A7DFADBBB6}C:\program files\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe] => (Allow) C:\program files\epic games\fortnite\fortnitegame\binaries\win64\fortniteclient-win64-shipping.exe
FirewallRules: [{2834D457-F5FF-4DBE-BAAA-A4CD36B884A6}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
 
==================== Restore Points =========================
 
25-01-2018 21:55:22 Scheduled Checkpoint
27-01-2018 18:40:44 Revo Uninstaller's restore point - McAfee AntiVirus Plus
27-01-2018 18:48:48 Revo Uninstaller's restore point - McAfee Virtual Technician
27-01-2018 18:49:32 Revo Uninstaller's restore point - McAfee Virtual Technician
27-01-2018 18:50:57 Revo Uninstaller's restore point - McAfee WebAdvisor
27-01-2018 19:07:10 Restore Point Created by FRST
 
==================== Faulty Device Manager Devices =============
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (01/27/2018 07:06:50 PM) (Source: VSS) (EventID: 8194) (User: )
Description: Volume Shadow Copy Service error: Unexpected error querying for the IVssWriterCallback interface.  hr = 0x80070005, Access is denied.
.
This is often caused by incorrect security settings in either the writer or requestor process.
 
 
Operation:
   Gathering Writer Data
 
Context:
   Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220}
   Writer Name: System Writer
   Writer Instance ID: {08c0e60e-7ecd-42fc-8361-cf10a6256403}
 
Error: (01/27/2018 07:02:52 PM) (Source: WTabletServicePro) (EventID: 1) (User: )
Description: Event-ID 1
 
Error: (01/27/2018 07:02:46 PM) (Source: WTabletServicePro) (EventID: 1) (User: )
Description: Event-ID 1
 
Error: (01/27/2018 06:40:39 PM) (Source: VSS) (EventID: 8194) (User: )
Description: Volume Shadow Copy Service error: Unexpected error querying for the IVssWriterCallback interface.  hr = 0x80070005, Access is denied.
.
This is often caused by incorrect security settings in either the writer or requestor process.
 
 
Operation:
   Gathering Writer Data
 
Context:
   Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220}
   Writer Name: System Writer
   Writer Instance ID: {57ca24a8-467d-4f41-8463-9857ac0ffaa9}
 
Error: (01/27/2018 03:05:10 PM) (Source: WTabletServicePro) (EventID: 1) (User: )
Description: Event-ID 1
 
Error: (01/27/2018 03:05:03 PM) (Source: WTabletServicePro) (EventID: 1) (User: )
Description: Event-ID 1
 
Error: (01/27/2018 01:15:11 PM) (Source: Desktop Window Manager) (EventID: 9020) (User: )
Description: The Desktop Window Manager has encountered a fatal error (0x80070008)
 
Error: (01/27/2018 12:33:19 PM) (Source: WTabletServicePro) (EventID: 1) (User: )
Description: Event-ID 1
 
Error: (01/27/2018 12:33:13 PM) (Source: WTabletServicePro) (EventID: 1) (User: )
Description: Event-ID 1
 
Error: (01/26/2018 07:38:10 PM) (Source: WTabletServicePro) (EventID: 1) (User: )
Description: Event-ID 1
 
 
System errors:
=============
Error: (01/27/2018 08:48:41 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The McAfee Platform Services service failed to start due to the following error: 
The system cannot find the file specified.
 
Error: (01/27/2018 08:48:41 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The McAfee Platform Services service failed to start due to the following error: 
The system cannot find the file specified.
 
Error: (01/27/2018 08:48:41 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The McAfee Platform Services service failed to start due to the following error: 
The system cannot find the file specified.
 
Error: (01/27/2018 08:48:41 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The McAfee Platform Services service failed to start due to the following error: 
The system cannot find the file specified.
 
Error: (01/27/2018 08:48:41 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The McAfee Platform Services service failed to start due to the following error: 
The system cannot find the file specified.
 
Error: (01/27/2018 08:48:41 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The McAfee Platform Services service failed to start due to the following error: 
The system cannot find the file specified.
 
Error: (01/27/2018 08:48:41 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The McAfee Platform Services service failed to start due to the following error: 
The system cannot find the file specified.
 
Error: (01/27/2018 08:48:41 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The McAfee Platform Services service failed to start due to the following error: 
The system cannot find the file specified.
 
Error: (01/27/2018 08:48:41 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The McAfee Platform Services service failed to start due to the following error: 
The system cannot find the file specified.
 
Error: (01/27/2018 08:48:41 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The McAfee Platform Services service failed to start due to the following error: 
The system cannot find the file specified.
 
 
CodeIntegrity:
===================================
  Date: 2017-09-14 03:39:35.233
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\kernel32.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2015-09-04 08:07:38.756
  Description: Windows is unable to verify the integrity of the file \Device\HarddiskVolume2\$Windows.~BT\Updates\Critical\8e08ca47-f6ba-409d-82de-698e324c0004\amd64_microsoft-windows-errorreportingfaults_31bf3856ad364e35_10.0.10074.1_none_f3153036f55ab3f5\werfault.exe because the signing certificate has been revoked.  Check with the publisher to see if a new signed version of the kernel module is available.
 
  Date: 2015-09-04 08:07:38.749
  Description: Windows is unable to verify the integrity of the file \Device\HarddiskVolume2\$Windows.~BT\Updates\Critical\8e08ca47-f6ba-409d-82de-698e324c0004\amd64_microsoft-windows-errorreportingfaults_31bf3856ad364e35_10.0.10074.1_none_f3153036f55ab3f5\werfault.exe because the signing certificate has been revoked.  Check with the publisher to see if a new signed version of the kernel module is available.
 
  Date: 2015-09-04 08:07:38.743
  Description: Windows is unable to verify the integrity of the file \Device\HarddiskVolume2\$Windows.~BT\Updates\Critical\8e08ca47-f6ba-409d-82de-698e324c0004\amd64_microsoft-windows-errorreportingfaults_31bf3856ad364e35_10.0.10074.1_none_f3153036f55ab3f5\werfault.exe because the signing certificate has been revoked.  Check with the publisher to see if a new signed version of the kernel module is available.
 
  Date: 2015-09-04 08:07:38.640
  Description: Windows is unable to verify the integrity of the file \Device\HarddiskVolume2\$Windows.~BT\Updates\Critical\8e08ca47-f6ba-409d-82de-698e324c0004\amd64_microsoft-windows-errorreportingcore_31bf3856ad364e35_10.0.10074.1_none_a384c5aabe759ea5\wermgr.exe because the signing certificate has been revoked.  Check with the publisher to see if a new signed version of the kernel module is available.
 
  Date: 2015-09-04 08:07:38.629
  Description: Windows is unable to verify the integrity of the file \Device\HarddiskVolume2\$Windows.~BT\Updates\Critical\8e08ca47-f6ba-409d-82de-698e324c0004\amd64_microsoft-windows-errorreportingcore_31bf3856ad364e35_10.0.10074.1_none_a384c5aabe759ea5\wermgr.exe because the signing certificate has been revoked.  Check with the publisher to see if a new signed version of the kernel module is available.
 
  Date: 2015-09-04 08:07:38.621
  Description: Windows is unable to verify the integrity of the file \Device\HarddiskVolume2\$Windows.~BT\Updates\Critical\8e08ca47-f6ba-409d-82de-698e324c0004\amd64_microsoft-windows-errorreportingcore_31bf3856ad364e35_10.0.10074.1_none_a384c5aabe759ea5\wermgr.exe because the signing certificate has been revoked.  Check with the publisher to see if a new signed version of the kernel module is available.
 
 
==================== Memory info =========================== 
 
Processor: Intel® Core™ i7-2600 CPU @ 3.40GHz
Percentage of memory in use: 21%
Total physical RAM: 12270.45 MB
Available physical RAM: 9588.64 MB
Total Virtual: 24539.06 MB
Available Virtual: 21979.56 MB
 
==================== Drives ================================
 
Drive c: () (Fixed) (Total:931.41 GB) (Free:46.39 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: A61DA447)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=931.4 GB) - (Type=07 NTFS)
 
==================== End of Addition.txt ============================


#15 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 36,617 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:07:50 PM

Posted 27 January 2018 - 09:24 PM

Thank you for the extra work and your patience.

Please do this.

===================================================

Farbar's Recovery Scan Tool - Run Fix in Normal or Safe Mode Using Attached File

--------------------
  • Please download Attached File  fixlist.txt   25.95KB   4 downloads and save it in the same location as FRST.exe (example, Desktop, USB device) <<< Important
  • Launch FRST and press the Fix button just once and wait, the program will automatically launch fixlist.txt.
  • The tool will create a log called Fixlog.txt. Please copy and paste the contents of the file in your reply.
===================================================

Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it. :thumbsup2:
  • Fixlog
  • Update on computer performance

Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."