Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Bitcoin.Miner removal help


  • This topic is locked This topic is locked
21 replies to this topic

#1 MrJackSTARR

MrJackSTARR

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:03:43 PM

Posted 29 January 2018 - 08:32 PM

I have been trying to remove Bitcoin.Miner for about 3 days now with no success. Malwarebytes finds roughly 10 instances which get quarantined and deleted after restart but they reinstall themselves. During startup/reboot my laptop "repairs" a file which leads me to believe that this is how it keeps reinstalling. There is a program that cannot be uninstalled (Anonymizer gadget) and my browser redirects to extension.citypage.today which leads me to bing search.

 

Any assistance would be greatly appreciated.

 

FRST Results:

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 27.01.2018
Ran by Jack (administrator) on JACK-LAPTOP (29-01-2018 20:11:57)
Running from C:\Users\Jack\Downloads
Loaded Profiles: Jack &  (Available Profiles: Jack & steph)
Platform: Windows 10 Home Version 1709 16299.192 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
 
 
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 27.01.2018
Ran by Jack (29-01-2018 20:14:57)
Running from C:\Users\Jack\Downloads
Windows 10 Home Version 1709 16299.192 (X64) (2017-11-17 06:37:37)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-2592302959-4100768495-3643388182-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-2592302959-4100768495-3643388182-503 - Limited - Disabled)
Guest (S-1-5-21-2592302959-4100768495-3643388182-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-2592302959-4100768495-3643388182-1006 - Limited - Enabled)
Jack (S-1-5-21-2592302959-4100768495-3643388182-1001 - Administrator - Enabled) => C:\Users\Jack
steph (S-1-5-21-2592302959-4100768495-3643388182-1002 - Limited - Enabled) => C:\Users\steph
WDAGUtilityAccount (S-1-5-21-2592302959-4100768495-3643388182-504 - Limited - Disabled)
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
µTorrent (HKU\S-1-5-21-2592302959-4100768495-3643388182-1001\...\uTorrent) (Version: 3.4.8.42449 - BitTorrent Inc.)
µTorrent (HKU\S-1-5-21-2592302959-4100768495-3643388182-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\uTorrent) (Version: 3.4.8.42449 - BitTorrent Inc.)
µTorrent (HKU\S-1-5-21-2592302959-4100768495-3643388182-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\uTorrent) (Version: 3.4.5.41372 - BitTorrent Inc.)
7-Zip 16.04 (x64) (HKLM\...\7-Zip) (Version: 16.04 - Igor Pavlov)
7-Zip 17.01 beta (HKLM-x32\...\7-Zip) (Version: 17.01 beta - Igor Pavlov)
A360 Desktop (HKLM\...\{7758802D-9486-4883-9927-CCAC366A3BA4}) (Version: 7.3.6.1809 - Autodesk)
ACA & MEP 2017 Object Enabler (HKLM\...\{28B89EEF-0004-0000-5102-CF3F3A09B77D}) (Version: 7.9.45.0 - Autodesk) Hidden
ACAD Private (HKLM\...\{28B89EEF-0001-0000-3102-CF3F3A09B77D}) (Version: 21.0.52.0 - Autodesk) Hidden
AccuLoad (HKLM-x32\...\{DE57ED3D-F271-43A7-BC1C-183F6C247480}) (Version: 17.3.5 - Adtek Software)
Adobe Flash Player 28 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 28.0.0.137 - Adobe Systems Incorporated)
Adobe Flash Player 28 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 28.0.0.137 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.23) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.23 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.2 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.2.1.171 - Adobe Systems, Inc.)
Apple Application Support (32-bit) (HKLM-x32\...\{D811A40A-9791-497C-B9DC-2D89C8E95EA1}) (Version: 6.1 - Apple Inc.)
Apple Application Support (64-bit) (HKLM\...\{8B47B514-F5D2-4E0D-B951-6E250618A7CD}) (Version: 6.1 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{31A0B634-BCF4-4D3F-8336-87FEACFEE142}) (Version: 11.0.1.2 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{C1BBFD2A-BCDD-45B3-8C0B-66BD434970A8}) (Version: 2.4.8.1 - Apple Inc.)
ASUS Live Update (HKLM-x32\...\{FA540E67-095C-4A1B-97BA-4D547DEC9AF4}) (Version: 3.3.4 - ASUS)
ASUS Screen Saver (HKLM-x32\...\{0FBEEDF8-30FA-4FA3-B31F-C9C7E7E8DFA2}) (Version: 1.0.3 - ASUS)
ASUS Smart Gesture (HKLM-x32\...\{4D3286A6-F6AB-498A-82A4-E4F040529F3D}) (Version: 4.0.18 - ASUS)
ASUS Splendid Video Enhancement Technology (HKLM-x32\...\{0969AF05-4FF6-4C00-9406-43599238DE0D}) (Version: 3.01.0003 - ASUS)
ASUS USB Charger Plus (HKLM-x32\...\{A859E3E5-C62F-4BFA-AF1D-2B95E03166AF}) (Version: 3.1.9 - ASUS)
ATK Package (HKLM-x32\...\{AB5C933E-5C7D-4D30-B314-9C83A49B94BE}) (Version: 1.0.0036 - ASUS)
AutoCAD 2017 - English (HKLM\...\{28B89EEF-0001-0409-2102-CF3F3A09B77D}) (Version: 21.0.52.0 - Autodesk) Hidden
AutoCAD 2017 (HKLM\...\{28B89EEF-0001-0000-0102-CF3F3A09B77D}) (Version: 21.0.52.0 - Autodesk) Hidden
AutoCAD 2017 Help - English (HKLM\...\{28B89EEF-0034-0409-0100-CF3F3A09B77D}) (Version: 21.0.52.0 - Autodesk) Hidden
AutoCAD 2017 Language Pack - English (HKLM\...\{28B89EEF-0001-0409-1102-CF3F3A09B77D}) (Version: 21.0.52.0 - Autodesk) Hidden
Autodesk Advanced Material Library Image Library 2017 (HKLM-x32\...\{8ED2ED41-4455-449D-993C-751C039089B9}) (Version: 15.11.3.0 - Autodesk)
Autodesk App Manager 2016-2017 (HKLM-x32\...\{C0954809-F5DC-426C-847E-8409DE14E4C0}) (Version: 2.2.0 - Autodesk)
Autodesk AutoCAD 2017 - English (HKLM\...\AutoCAD 2017 - English) (Version: 21.0.52.0 - Autodesk)
Autodesk AutoCAD 2017 Help - English (HKLM\...\AutoCAD 2017 Help - English) (Version: 21.0.52.0 - Autodesk)
Autodesk AutoCAD Performance Feedback Tool 1.2.5 (HKLM-x32\...\{8600F844-9AA5-412E-B6F2-F9C6CBCFD268}) (Version: 1.2.5.0 - Autodesk)
Autodesk BIM 360 Glue AutoCAD 2017 Add-in 64 bit (HKLM\...\{276A67E0-71EB-4827-B5F7-2ACF02BC1A5B}) (Version: 4.37.6853 - Autodesk)
Autodesk Desktop App (HKLM-x32\...\Autodesk Desktop App) (Version: 7.0.6.378 - Autodesk)
Autodesk Featured Apps 2016-2017 (HKLM-x32\...\{27C15055-713B-4D0E-881F-19598A2DFD59}) (Version: 2.2.0 - Autodesk)
Autodesk License Service (x64) - 3.1 (HKLM\...\{EB6FE58F-8576-4272-BB9C-6B47D9EDFA4D}) (Version: 3.1.26.0 - Autodesk)
Autodesk Material Library 2017 (HKLM-x32\...\{8FB9F735-D64C-4991-8D91-4CDDAB1ABDEE}) (Version: 15.11.3.0 - Autodesk)
Autodesk Material Library Base Resolution Image Library 2017 (HKLM-x32\...\{3FBFBC43-9882-43FA-B979-2D53896747B3}) (Version: 15.11.3.0 - Autodesk)
Autodesk ReCap 360 (HKLM\...\{5F0F7049-0000-1033-0102-73A6DA3D7FA6}) (Version: 3.0.0.52 - Autodesk) Hidden
Autodesk ReCap 360 (HKLM\...\Autodesk ReCap 360) (Version: 3.0.0.52 - Autodesk)
Backup and Sync from Google (HKLM-x32\...\{908DB568-E5FA-40C7-A2AA-AB340190858B}) (Version: 3.38.7642.3857 - Google, Inc.)
Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
CCleaner (HKLM\...\CCleaner) (Version: 5.39 - Piriform)
Chrome Remote Desktop Host (HKLM-x32\...\{D61C8E6E-A4F3-4CD8-8568-51CEB5660C89}) (Version: 63.0.3239.32 - Google Inc.)
Cisco EAP-FAST Module (HKLM-x32\...\{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}) (Version: 2.2.14 - Cisco Systems, Inc.)
Cisco LEAP Module (HKLM-x32\...\{AF312B06-5C5C-468E-89B3-BE6DE2645722}) (Version: 1.0.19 - Cisco Systems, Inc.)
Cisco PEAP Module (HKLM-x32\...\{0A4EF0E6-A912-4CDE-A7F3-6E56E7C13A2F}) (Version: 1.1.6 - Cisco Systems, Inc.)
D3DX10 (HKLM-x32\...\{E09C4DB7-630C-4F06-A631-8EA7239923AF}) (Version: 15.4.2368.0902 - Microsoft) Hidden
Data Lifeguard Diagnostic for Windows 1.31 (HKLM-x32\...\{519C4DB6-B53B-4F5C-8297-89B2BE949FA5}_is1) (Version:  - Western Digital Corporation)
Defraggler (HKLM\...\Defraggler) (Version: 2.21 - Piriform)
Device Setup (HKLM-x32\...\{1F07F2C7-596F-4F34-B805-2C61A3E50E5A}) (Version: 1.0.18 - ASUSTek Computer Inc.)
E-Sys 3.27.1 (build 44813) (HKLM-x32\...\E-Sys_is1) (Version: 3.27.1 - ESG GmbH)
E-Sys Launcher Premium (HKLM-x32\...\{13F1264F-CE62-4295-80A0-8A7C0A5AF7A7}) (Version: 2.4.3.85 - TokenMaster)
Etcher 1.2.1 (only current user) (HKU\S-1-5-21-2592302959-4100768495-3643388182-1001\...\573339af-d9e1-5dd3-804c-e0162fac1f41) (Version: 1.2.1 - Resin Inc.)
Etcher 1.2.1 (only current user) (HKU\S-1-5-21-2592302959-4100768495-3643388182-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\573339af-d9e1-5dd3-804c-e0162fac1f41) (Version: 1.2.1 - Resin Inc.)
EZ CD Audio Converter (HKLM-x32\...\EZ CD Audio Converter) (Version: 5.1.1 - Poikosoft)
FARO LS 1.1.505.0 (64bit) (HKLM-x32\...\{8834451B-6209-4E02-9EF4-4EF9E3C1F70F}) (Version: 5.5.0.44203 - FARO Scanner Production)
GeoComply Autoupdate (HKLM-x32\...\{6341D55F-4754-4485-9745-974ED5FC9BA4}) (Version: 1.0.0.0 - GeoComply) Hidden
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 63.0.3239.132 - Google Inc.)
Google Photos Backup (HKU\S-1-5-21-2592302959-4100768495-3643388182-1001\...\Google Photos Backup) (Version: 1.1.2.13 - Google, Inc.)
Google Photos Backup (HKU\S-1-5-21-2592302959-4100768495-3643388182-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Google Photos Backup) (Version: 1.1.2.13 - Google, Inc.)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.7 - Google Inc.) Hidden
Google Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 2.1.2.7 - Google Inc.) Hidden
HP Deskjet 1510 series Basic Device Software (HKLM\...\{D17E60E8-478A-4D4A-8147-21D481B5CA55}) (Version: 32.2.188.47710 - Hewlett-Packard Co.)
HP Deskjet 1510 series Help (HKLM-x32\...\{2E25FCEB-EFCB-4696-AA01-D3CBAC721831}) (Version: 30.0.0 - Hewlett Packard)
HP LaserJet Professional P1100-P1560-P1600 Series (HKLM\...\HP LaserJet Professional P1100-P1560-P1600 Series) (Version:  - )
HP Photo Creations (HKLM-x32\...\HP Photo Creations) (Version: 1.0.0.7702 - HP)
HP Support Assistant (HKLM-x32\...\{79C54A05-F146-4EA0-8A70-D4EFE6181E52}) (Version: 8.5.37.19 - Hewlett-Packard Company)
HP Support Solutions Framework (HKLM-x32\...\{55065080-504F-43BB-BE00-36B80D7D39A5}) (Version: 12.8.47.1 - Hewlett-Packard Company)
HP Touchpoint Analytics Client (HKLM\...\{E5FB98E0-0784-44F0-8CEC-95CD4690C43F}) (Version: 4.0.2.1439 - HP Inc.)
HP Update (HKLM-x32\...\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
hppLaserJetService (HKLM-x32\...\{D371F551-0DB9-4CEC-844B-4C90CE91EA0B}) (Version: 001.001.0.0 - Hewlett-Packard) Hidden
hppP1100P1560P1600SeriesLaserJetService (HKLM-x32\...\{0E448256-D515-4C3E-A5BE-0A7B76CED5D4}) (Version: 001.001.0.0 - Hewlett-Packard) Hidden
hppusgP1100P1560P1600Series (HKLM-x32\...\{853F464A-B2B8-404E-BA3E-B98FF6862C41}) (Version: 1.0.0.1 - Hewlett-Packard) Hidden
HPSSupply (HKLM-x32\...\{7902E313-FF0F-4493-ACB1-A8147B78DCD0}) (Version: 2.1.1.0000 - Hewlett Packard Development Company L.P.)
Intel® Dynamic Platform and Thermal Framework (HKLM-x32\...\FFD10ECE-F715-4a86-9BD8-F6F47DA5DA1C) (Version: 7.1.0.2105 - Intel Corporation)
Intel® Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.6.0.1038 - Intel Corporation)
Intel® Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 20.19.15.4549 - Intel Corporation)
ISOburn (HKLM-x32\...\ISOburn) (Version:  - )
iTunes (HKLM\...\{F2517A28-8CB8-4206-B86C-5EDD4EA26682}) (Version: 12.7.1.14 - Apple Inc.)
Java 8 Update 161 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180161F0}) (Version: 8.0.1610.12 - Oracle Corporation)
Kodi (HKU\S-1-5-21-2592302959-4100768495-3643388182-1001\...\Kodi) (Version:  - XBMC-Foundation)
Kodi (HKU\S-1-5-21-2592302959-4100768495-3643388182-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Kodi) (Version:  - XBMC-Foundation)
LibreOffice 5.4 Help Pack (English (United States)) (HKLM-x32\...\{F257FC9E-6C97-4136-B723-AF5B4318008C}) (Version: 5.4.1.2 - The Document Foundation)
Macrium Reflect Free Edition (HKLM\...\{595B8A7B-253D-4A4E-95C2-A823EDDD5496}) (Version: 6.3.1745 - Paramount Software (UK) Ltd.) Hidden
Macrium Reflect Free Edition (HKLM\...\MacriumReflect) (Version: 6.3 - Paramount Software (UK) Ltd.)
Malwarebytes version 3.2.2.2018 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.2.2.2018 - Malwarebytes)
MarketResearch (HKLM-x32\...\{175F0111-2968-4935-8F70-33108C6A4DE3}) (Version: 130.0.374.000 - Hewlett-Packard) Hidden
Microsoft Office Professional Plus 2016 - en-us (HKLM\...\ProPlusRetail - en-us) (Version: 16.0.8827.2148 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-2592302959-4100768495-3643388182-1001\...\OneDriveSetup.exe) (Version: 17.3.7131.1115 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-2592302959-4100768495-3643388182-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\OneDriveSetup.exe) (Version: 17.3.7131.1115 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-2592302959-4100768495-3643388182-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\OneDriveSetup.exe) (Version: 17.3.7131.1115 - Microsoft Corporation)
Microsoft Setup Bootstrapper 16.0.4266.1001 (HKLM-x32\...\Microsoft Setup Bootstrapper 16.0.4266.1001) (Version: 16.0.4266.1001 - Microsoft Setup Bootstrapper)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23026 (HKLM-x32\...\{e46eca4f-393b-40df-9f49-076faf788d83}) (Version: 14.0.23026.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
MotoHelper MergeModules (HKLM-x32\...\{94CAC2F1-C856-47F4-AF24-65A1E75AEDB9}) (Version: 1.2.0 - Motorola) Hidden
Movie Maker (HKLM-x32\...\{38F03569-A636-4CF3-BDDE-032C8C251304}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Movie Maker (HKLM-x32\...\{DD67BE4B-7E62-4215-AFA3-F123A800A389}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Mozilla Firefox 57.0.4 (x64 en-US) (HKLM\...\Mozilla Firefox 57.0.4 (x64 en-US)) (Version: 57.0.4 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 57.0.4.6577 - Mozilla)
MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
MultiFileRenamer 1.0.17.126 (HKLM-x32\...\MultiFileRenamer) (Version: 1.0.17.126 - P23 Software)
NETGEAR Genie (HKLM-x32\...\NETGEAR Genie) (Version: 2.4.48.00 - NETGEAR Inc.)
Notepad++ (32-bit x86) (HKLM-x32\...\Notepad++) (Version: 7.5.1 - Notepad++ Team)
Office 16 Click-to-Run Extensibility Component (HKLM-x32\...\{90160000-008C-0000-0000-0000000FF1CE}) (Version: 16.0.8827.2148 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Extensibility Component 64-bit Registration (HKLM\...\{90160000-00DD-0000-1000-0000000FF1CE}) (Version: 16.0.8827.2148 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-008F-0000-1000-0000000FF1CE}) (Version: 16.0.8827.2148 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM-x32\...\{90160000-008C-0409-0000-0000000FF1CE}) (Version: 16.0.8827.2148 - Microsoft Corporation) Hidden
PdaNet+ for Android 4.19 (HKLM-x32\...\PdaNet_is1) (Version:  - June Fabrics Technology Inc)
PDFill PDF Editor Professional (HKLM\...\{D1399216-81B2-457C-A0F7-73B9A2EF6902}) (Version: 14.0 - PlotSoft LLC)
Player Location Check (HKLM-x32\...\{24BDE5F7-123E-4DC4-B00A-730FDD36D82C}) (Version: 3.0.2.10 - GeoComply)
Player Location Check (HKLM-x32\...\{F0753064-8D66-41A7-9F23-7691290387BF}) (Version: 3.0.2.10,3.0.4.3 - GeoComply)
PowerISO (HKLM-x32\...\PowerISO) (Version: 7.0 - Power Software Ltd)
Qualcomm Atheros Bluetooth Suite (64) (HKLM\...\{A84A4FB1-D703-48DB-89E0-68B6499D2801}) (Version: 8.0.1.326 - Qualcomm Atheros Communications)
Qualcomm Atheros Client Installation Program (HKLM-x32\...\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 10.0 - Qualcomm Atheros)
Radmin Viewer 3.5.1 (HKLM-x32\...\{56F8FD35-F124-4131-9B41-272D8424EF35}) (Version: 3.51.1.0000 - Famatech)
Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 10.0.15063.31235 - Realtek Semiconductor Corp.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.33.529.2014 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7224 - Realtek Semiconductor Corp.)
Realtek PCI-E Wireless LAN Driver (HKLM-x32\...\InstallShield_{70714FB7-4084-4202-A599-2D5935DECB67}) (Version: Drv_3.00.0014 - REALTEK Semiconductor Corp.)
RomCenter 3.7.1 (HKLM-x32\...\romcenter_is1) (Version: 3.7.1 - Eric Bole-Feysot)
SD Card Formatter (HKLM-x32\...\{10C16E01-F739-4093-89A7-E570589FA0F6}) (Version: 5.0.0 - SD Association)
SDFormatter (HKLM-x32\...\{179324FF-7B16-4BA8-9836-055CAAEE4F08}) (Version: 4.0.0 - SD Association)
SeaTools for Windows 1.4.0.5 (HKLM-x32\...\SeaTools for Windows) (Version: 1.4.0.5 - Seagate Technology)
SketchUp Import 2016-2017 (HKLM-x32\...\{063925DB-9D8C-48E2-8F04-1B7038B6C783}) (Version: 2.2.0 - Autodesk)
SoftEther VPN Client (HKLM\...\softether_sevpnclient) (Version: 4.22.9634 - SoftEther VPN Project)
swMSM (HKLM-x32\...\{612C34C7-5E90-47D8-9B5C-0F717DD82726}) (Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
TeamViewer 13 (HKLM-x32\...\TeamViewer) (Version: 13.0.6447 - TeamViewer)
TomTom HOME (HKLM-x32\...\{0E778C56-3A87-497E-BEF0-EF0D3EE4871C}) (Version: 2.10.3 - TomTom)
UnHackMe 9.50 (HKLM-x32\...\UnHackMe_is1) (Version:  - Greatis Software, LLC.)
Update Installer for WildTangent Games App (HKLM-x32\...\{2FA94A64-C84E-49d1-97DD-7BF06C7BBFB2}.WildTangent Games App) (Version:  - WildTangent) Hidden
Visual MP3 (HKLM-x32\...\Visual MP3) (Version:  - )
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.6 - VideoLAN)
WebStorage (HKLM-x32\...\WebStorage) (Version: 2.1.11.399 - ASUS Cloud Corporation)
WhatsApp (HKU\S-1-5-21-2592302959-4100768495-3643388182-1001\...\WhatsApp) (Version: 0.2.5863 - WhatsApp)
WhatsApp (HKU\S-1-5-21-2592302959-4100768495-3643388182-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\WhatsApp) (Version: 0.2.5863 - WhatsApp)
WildTangent Games App (HKLM-x32\...\{70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-asus) (Version: 4.0.11.14 - WildTangent)
Win32DiskImager version 1.0.0 (HKLM-x32\...\{3DFFA293-DF2C-4B23-92E5-3433BDC310E1}}_is1) (Version: 1.0.0 - ImageWriter Developers)
Windows Driver Package - ASUS (ATP) Mouse  (03/17/2014 1.0.0.207) (HKLM\...\AA2CC56D4BBEE037DC99871F5F6551133D2A0CC3) (Version: 03/17/2014 1.0.0.207 - ASUS)
Windows Essentials Codec Pack 5.0 (HKLM-x32\...\Windows Essentials Codec Pack) (Version: 5.0 - Windows Essentials Codec Pack)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation)
WinFlash (HKLM-x32\...\{8F21291E-0444-4B1D-B9F9-4370A73E346D}) (Version: 2.42.0 - ASUS)
WinSCP 5.11.2 (HKLM-x32\...\winscp3_is1) (Version: 5.11.2 - Martin Prikryl)
Wondershare Helper Compact 2.5.2 (HKLM-x32\...\{5363CE84-5F09-48A1-8B6C-6BB590FFEDF2}_is1) (Version: 2.5.2 - Wondershare)
Wondershare PDFelement 6 Pro(Build 6.3.5) (HKLM-x32\...\{B026557A-EF19-4812-8A79-B30F94AA0A78}_is1) (Version: 6.3.5.2806 - Wondershare Software Co.,Ltd.)
Xilisoft DVD Creator (HKLM-x32\...\Xilisoft DVD Creator) (Version: 7.1.3.20130417 - Xilisoft)
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-2592302959-4100768495-3643388182-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0_Classes\CLSID\{0D327DA6-B4DF-4842-B833-2CFF84F0948F}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2017\acad.exe (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2592302959-4100768495-3643388182-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0_Classes\CLSID\{720DB9AF-D62C-4ED0-A377-429C22312852}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2017\acad.exe (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2592302959-4100768495-3643388182-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0_Classes\CLSID\{91A41FCC-BC02-42D8-A36E-0D27FF9BFFC8}\InprocServer32 -> C:\Users\Jack\AppData\Local\Google\Update\1.3.33.7\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-2592302959-4100768495-3643388182-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0_Classes\CLSID\{E2C40589-DE61-11ce-BAE0-0020AF6D7005}\InprocServer32 -> C:\Program Files\Autodesk\AutoCAD 2017\en-US\acadficn.dll (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2592302959-4100768495-3643388182-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\Jack\AppData\Local\Google\Update\1.3.33.7\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-2592302959-4100768495-3643388182-1001_Classes\CLSID\{0D327DA6-B4DF-4842-B833-2CFF84F0948F}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2017\acad.exe (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2592302959-4100768495-3643388182-1001_Classes\CLSID\{720DB9AF-D62C-4ED0-A377-429C22312852}\localserver32 -> C:\Program Files\Autodesk\AutoCAD 2017\acad.exe (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2592302959-4100768495-3643388182-1001_Classes\CLSID\{91A41FCC-BC02-42D8-A36E-0D27FF9BFFC8}\InprocServer32 -> C:\Users\Jack\AppData\Local\Google\Update\1.3.33.7\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-2592302959-4100768495-3643388182-1001_Classes\CLSID\{E2C40589-DE61-11ce-BAE0-0020AF6D7005}\InprocServer32 -> C:\Program Files\Autodesk\AutoCAD 2017\en-US\acadficn.dll (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-2592302959-4100768495-3643388182-1001_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\Jack\AppData\Local\Google\Update\1.3.33.7\psuser_64.dll (Google Inc.)
ShellIconOverlayIdentifiers: [  GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2017-11-20] (Google)
ShellIconOverlayIdentifiers: [  GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2017-11-20] (Google)
ShellIconOverlayIdentifiers: [  GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2017-11-20] (Google)
ShellIconOverlayIdentifiers: [!AsusWSShellExt_B] -> {6D4133E5-0742-4ADC-8A8C-9303440F7191} => C:\Program Files (x86)\Common Files\AWS\2.1.11.399\ASUSWSShellExt64.dll [2013-06-25] (ASUS Cloud Corporation.)
ShellIconOverlayIdentifiers: [!AsusWSShellExt_O] -> {64174815-8D98-4CE6-8646-4C039977D809} => C:\Program Files (x86)\Common Files\AWS\2.1.11.399\ASUSWSShellExt64.dll [2013-06-25] (ASUS Cloud Corporation.)
ShellIconOverlayIdentifiers: [!AsusWSShellExt_U] -> {1C5AB7B1-0B38-4EC4-9093-7FD277E2AF4E} => C:\Program Files (x86)\Common Files\AWS\2.1.11.399\ASUSWSShellExt64.dll [2013-06-25] (ASUS Cloud Corporation.)
ShellIconOverlayIdentifiers: [AutoCAD Digital Signatures Icon Overlay Handler] -> {36A21736-36C2-4C11-8ACB-D4136F2B57BD} => C:\WINDOWS\system32\AcSignIcon.dll [2016-02-06] (Autodesk, Inc.)
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2016-10-04] (Igor Pavlov)
ContextMenuHandlers1: [AcShellExtension.AcContextMenuHandler] -> {2E7A2C6C-B938-40a4-BA1C-C7EC982DC202} => C:\Program Files\Common Files\Autodesk Shared\AcShellEx\AcShellExtension.dll [2016-02-06] (Autodesk)
ContextMenuHandlers1: [ANotepad++64] -> {B298D29A-A6ED-11DE-BA8C-A68E55D89593} => C:\Program Files (x86)\Notepad++\NppShell_06.dll [2017-08-28] ()
ContextMenuHandlers1: [DefragglerShellExtension] -> {4380C993-0C43-4E02-9A7A-0D40B6EA7590} => C:\Program Files\Defraggler\DefragglerShell64.dll [2016-03-08] (Piriform Ltd)
ContextMenuHandlers1: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => C:\ProgramData\Microsoft\Windows Defender\platform\4.12.17007.18011-0\ShellExt.dll [2017-09-29] (Microsoft Corporation)
ContextMenuHandlers1: [EzCd] -> {E46D6DC6-9707-43a9-BDBB-0BDBDD096F90} => C:\Program Files\EZ CD Audio Converter\ezcd64.dll [2016-01-01] (Poikosoft)
ContextMenuHandlers1: [GDContextMenu] -> {BB02B294-8425-42E5-983F-41A1FA970CD6} => C:\Program Files (x86)\Google\Drive\contextmenu64.dll [2017-11-20] (Google)
ContextMenuHandlers1: [PowerISO] -> {967B2D40-8B7D-4127-9049-61EA0C2C6DCE} => C:\Program Files\PowerISO\PWRISOSH.DLL [2017-10-23] (Power Software Ltd)
ContextMenuHandlers1: [ReflectShellExt] -> {DEBB9B79-B3DD-47F4-9E5C-EA6975BAB611} => C:\Program Files\Macrium\Reflect\RContextMenu.dll [2015-10-12] (Paramount Software UK Ltd)
ContextMenuHandlers2: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => C:\ProgramData\Microsoft\Windows Defender\platform\4.12.17007.18011-0\ShellExt.dll [2017-09-29] (Microsoft Corporation)
ContextMenuHandlers2: [ReflectShellExt] -> {DEBB9B79-B3DD-47F4-9E5C-EA6975BAB611} => C:\Program Files\Macrium\Reflect\RContextMenu.dll [2015-10-12] (Paramount Software UK Ltd)
ContextMenuHandlers3: [BackupContextMenuExtension] -> {b1b96b20-da1d-4a3c-92c1-7229b32f2326} => C:\WINDOWS\system32\mscoree.dll [2017-09-29] (Microsoft Corporation)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-08-21] (Malwarebytes)
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2016-10-04] (Igor Pavlov)
ContextMenuHandlers4: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => C:\ProgramData\Microsoft\Windows Defender\platform\4.12.17007.18011-0\ShellExt.dll [2017-09-29] (Microsoft Corporation)
ContextMenuHandlers4: [EzCd] -> {E46D6DC6-9707-43a9-BDBB-0BDBDD096F90} => C:\Program Files\EZ CD Audio Converter\ezcd64.dll [2016-01-01] (Poikosoft)
ContextMenuHandlers4: [GDContextMenu] -> {BB02B294-8425-42E5-983F-41A1FA970CD6} => C:\Program Files (x86)\Google\Drive\contextmenu64.dll [2017-11-20] (Google)
ContextMenuHandlers4: [PowerISO] -> {967B2D40-8B7D-4127-9049-61EA0C2C6DCE} => C:\Program Files\PowerISO\PWRISOSH.DLL [2017-10-23] (Power Software Ltd)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} =>  -> No File
ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\WINDOWS\system32\igfxDTCM.dll [2016-11-30] (Intel Corporation)
ContextMenuHandlers6: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2016-10-04] (Igor Pavlov)
ContextMenuHandlers6: [DefragglerShellExtension] -> {4380C993-0C43-4E02-9A7A-0D40B6EA7590} => C:\Program Files\Defraggler\DefragglerShell64.dll [2016-03-08] (Piriform Ltd)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-08-21] (Malwarebytes)
ContextMenuHandlers6: [PowerISO] -> {967B2D40-8B7D-4127-9049-61EA0C2C6DCE} => C:\Program Files\PowerISO\PWRISOSH.DLL [2017-10-23] (Power Software Ltd)
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {077B0D98-23B4-412B-98D8-1AB3EA433F7D} - System32\Tasks\UnHackMe Task Scheduler => C:\Program Files (x86)\UnHackMe\hackmon.exe [2018-01-03] (Greatis Software)
Task: {08CE30F1-D799-460C-8BC9-C8D1AF8024BE} - System32\Tasks\ASUS Splendid ACMON => C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [2014-04-02] (ASUS)
Task: {0AB11E09-8DE9-42BF-A9D0-E5DDB5A11071} - System32\Tasks\ATK Package 36D18D69AFC3 => C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\SimAppExec.exe [2014-01-14] (ASUSTek Computer Inc.)
Task: {0C6774F1-2FCE-4F34-A88D-89EA189ED55E} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2018-01-19] (Microsoft Corporation)
Task: {0D2A124F-2F67-4FE7-A491-7BEC19826A69} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2018-01-09] (Piriform Ltd)
Task: {0F346326-7834-4B8E-BAB6-FA9713F32D29} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance => C:\ProgramData\Microsoft\Windows Defender\platform\4.12.17007.18011-0\MpCmdRun.exe [2018-01-19] (Microsoft Corporation)
Task: {14100209-72E1-44B6-9B34-BCA245137F07} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-10-15] (Google Inc.)
Task: {144B37C3-A878-4E36-ACA6-F0681C5229BB} - System32\Tasks\GC Remove old autoupdate => cmd.exe /c rd /S /Q "C:\Program Files (x86)\GeoComply\Update"
Task: {15EA5062-993A-4C65-9AF8-60E64B8693E5} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION
Task: {2551F7A2-78B8-4B6E-B220-8C9E56A9BCA3} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2017-11-08] (HP Inc.)
Task: {2F8FB623-B403-467B-BF34-5DBE1B2A59DA} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {308CA19C-B507-4DAC-83D5-0A3148FEF478} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Cleanup => C:\ProgramData\Microsoft\Windows Defender\platform\4.12.17007.18011-0\MpCmdRun.exe [2018-01-19] (Microsoft Corporation)
Task: {352652ED-AFCF-40C9-875D-7B1D96D09647} - System32\Tasks\RTKCPL => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2014-04-10] (Realtek Semiconductor)
Task: {352E6CA0-7314-4DF4-89C4-682368D80D57} - System32\Tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join => C:\WINDOWS\System32\AutoWorkplace.exe
Task: {3C8E4E09-5B37-48FC-8703-7C25665D8F19} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2017-09-27] (HP Inc.)
Task: {3F841645-FB5A-4F98-B56F-DE405EDE3787} - System32\Tasks\RtHDVBg => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2014-04-15] (Realtek Semiconductor)
Task: {424654AE-7B87-42DC-A58D-AA82592BCE2B} - System32\Tasks\ASUS USB Charger Plus => C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe [2014-03-27] (ASUSTek Computer Inc.)
Task: {4E455AC5-A801-40EF-A02D-1662C737F823} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2018-01-19] (Microsoft Corporation)
Task: {4EA2E5F6-63B7-43D8-AC7D-D8E32DC3CDD5} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSFReport.exe [2017-06-22] (HP Inc.)
Task: {51349902-96C6-4C6F-BC7D-5175E97102BC} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater - Resources => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [2017-09-20] (HP Inc.)
Task: {520661E9-A720-46BE-943D-FCAFD8BAAC23} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Verification => C:\ProgramData\Microsoft\Windows Defender\platform\4.12.17007.18011-0\MpCmdRun.exe [2018-01-19] (Microsoft Corporation)
Task: {5276F1E8-FCB0-4749-847D-6BFC60E63028} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-10-15] (Google Inc.)
Task: {5749435D-F6EC-445D-9224-7E8EE9B84824} - System32\Tasks\GeoComply Update Task => C:\Program Files (x86)\GeoComply\\PlayerLocationCheck\Update\GeoComplyUpdate.exe [2017-07-10] (GeoComply)
Task: {60C911B6-54EC-4057-B5FF-408533F4FE7E} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Product Configurator => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\ProductConfig.exe [2017-10-11] (HP Inc.)
Task: {646D72F7-E74B-4D58-BD45-4CEB0E52F867} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {670FBBDA-358D-40D2-BCFF-83BB6F18183B} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_28_0_0_137_pepper.exe [2018-01-15] (Adobe Systems Incorporated)
Task: {7C5324AA-EE23-4D42-8C4F-83DA0BEB2BD5} - System32\Tasks\Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan => C:\ProgramData\Microsoft\Windows Defender\platform\4.12.17007.18011-0\MpCmdRun.exe [2018-01-19] (Microsoft Corporation)
Task: {8904211C-F884-40A3-AA2D-CCCD1F0A68E9} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2017-07-24] (Apple Inc.)
Task: {8FD33090-66BE-485F-AE82-9BA852758CF9} - System32\Tasks\HPCeeScheduleForJack => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2015-06-16] (Hewlett-Packard)
Task: {9542573A-9612-45DE-90A7-FAA61F35A460} - System32\Tasks\Hewlett-Packard\HP Active Health\HP Active Health Scan (HPSA) => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPActiveHealth\ActiveHealth.exe [2017-11-20] ()
Task: {95885F37-FDBB-4AF3-8D3C-C55D8D68C13A} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {9C5AE8F2-EAB7-4E6A-B902-CBA33F663894} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {A5BFC8C6-4183-422E-91D0-32F999081F2E} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [2017-09-20] (HP Inc.)
Task: {B24BB295-3155-4BCC-8005-BFBA34106B62} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {BD71C9B2-C40B-44E1-9A8B-CCA925BCE3D5} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [2018-01-09] (Piriform Ltd)
Task: {C1AA9627-E598-4A35-AEB2-356016A3D2CA} - \ASUS\ASUS Product Register Service -> No File <==== ATTENTION
Task: {C1B12940-9374-476B-9FFB-A658A3A14E6A} - System32\Tasks\CreateExplorerShellUnelevatedTask => C:\WINDOWS\explorer.exe /NOUACCHECK
Task: {C1C64C6B-2955-4D2A-9D92-82CDD682A18A} - System32\Tasks\ASUS Live Update2 => C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe [2015-03-23] (ASUSTeK Computer Inc.)
Task: {C7778CC5-1E25-406B-A460-B28990465EE8} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2018-01-15] (Microsoft Corporation)
Task: {C8AA07E9-3FA2-47F6-B031-B8A0ECF60A02} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2017-09-27] (HP Inc.)
Task: {CA78B19F-7326-421A-B06B-D7CF95C146B2} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2592302959-4100768495-3643388182-1001UA => C:\Users\Jack\AppData\Local\Google\Update\GoogleUpdate.exe [2016-12-04] (Google Inc.)
Task: {D743F787-3855-4CBB-A5F5-F82D43CB5BAC} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_CN3BQ17P63 => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2017-11-08] (HP Inc.)
Task: {DABC8751-FBDF-4368-92DD-F6EDB07CDF68} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerLogon => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2018-01-19] (Microsoft Corporation)
Task: {DBB6F3B2-EB5A-4494-8411-7080D64C0219} - System32\Tasks\ASUS Smart Gesture Launcher => C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLauncher.exe [2017-03-09] (AsusTek)
Task: {DF299936-C06B-4CD3-B238-838479598A91} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2017-09-27] (Adobe Systems Incorporated)
Task: {E46A3B90-D8BB-4ED1-8502-34CA66C19BFE} - System32\Tasks\ASUS Live Update1 => C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe [2015-03-23] (ASUSTeK Computer Inc.)
Task: {E7E08B26-55FD-4E1F-980C-80F4B483FF4A} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2592302959-4100768495-3643388182-1001Core => C:\Users\Jack\AppData\Local\Google\Update\GoogleUpdate.exe [2016-12-04] (Google Inc.)
Task: {E853B0DA-23C2-4C6A-B51D-E09601D89798} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2018-01-15] (Microsoft Corporation)
Task: {EA3E6FF2-26D7-449E-9BBD-127EB6E3C0D7} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2018-01-15] (Adobe Systems Incorporated)
Task: {F524EEF8-45A8-4CD7-9E8F-3B0D150FF0CB} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2018-01-15] (Microsoft Corporation)
Task: {FE4F586D-7E8E-4059-8325-630B3C5FBEDC} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerRegistration => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2018-01-19] (Microsoft Corporation)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe
Task: C:\WINDOWS\Tasks\HPCeeScheduleForJack.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe
 
==================== Shortcuts & WMI ========================
 
(The entries could be listed to be restored or removed.)
 
 
ShortcutWithArgument: C:\Users\Jack\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Chrome Remote Desktop.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) ->  --profile-directory=Default --app-id=gbchcmhmhahfdphkhkmpfmihenigjmpp
 
==================== Loaded Modules (Whitelisted) ==============
 
2017-09-29 08:41 - 2017-09-29 08:41 - 000184432 _____ () C:\WINDOWS\SYSTEM32\inputhost.dll
2016-01-14 11:34 - 2012-08-31 15:03 - 000288768 _____ () C:\WINDOWS\System32\HP1100LM.DLL
2016-01-14 11:34 - 2012-08-31 15:02 - 000074240 _____ () C:\WINDOWS\system32\spool\PRTPROCS\x64\HP1100PP.DLL
2016-11-23 21:54 - 2017-11-09 12:24 - 000020208 _____ () C:\WINDOWS\system32\spool\PRTPROCS\x64\TeamViewer_PrintProcessor.dll
2016-11-30 21:57 - 2016-11-30 21:57 - 000401888 _____ () C:\WINDOWS\system32\igfxTray.exe
2017-11-20 15:27 - 2017-11-20 15:27 - 041061856 _____ () C:\Program Files (x86)\Google\Drive\googledrivesync.exe
2017-07-04 01:48 - 2017-07-04 01:48 - 000081904 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\genie2_tray.exe
2017-07-10 20:41 - 2018-01-19 16:17 - 008934568 _____ () C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\1033\GrooveIntlResource.dll
2017-08-28 19:43 - 2017-08-28 19:43 - 000230064 _____ () C:\Program Files (x86)\Notepad++\NppShell_06.dll
2017-12-11 13:57 - 2017-11-26 07:23 - 011044864 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2017-12-11 13:57 - 2017-11-26 07:01 - 001804288 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2017-07-13 15:45 - 2017-10-10 17:54 - 002289096 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\SelfProtectionSdk.dll
2018-01-09 12:06 - 2018-01-03 04:20 - 002873688 _____ () C:\Program Files (x86)\Google\Chrome\Application\63.0.3239.132\swiftshader\libglesv2.dll
2018-01-09 12:06 - 2018-01-03 04:20 - 000137048 _____ () C:\Program Files (x86)\Google\Chrome\Application\63.0.3239.132\swiftshader\libegl.dll
2017-08-08 23:29 - 2017-06-15 09:16 - 000061944 _____ () C:\Program Files (x86)\Autodesk\Autodesk Desktop App\QtSolutions_Service-head.dll
2017-08-08 23:29 - 2017-06-15 09:15 - 000110584 _____ () C:\Program Files (x86)\Autodesk\Autodesk Desktop App\qjson0.dll
2014-04-02 17:46 - 2014-04-02 17:46 - 000018992 _____ () C:\Program Files (x86)\ASUS\Splendid\AMDColorEnhance.dll
2014-04-02 17:46 - 2014-04-02 17:46 - 000037936 _____ () C:\Program Files (x86)\ASUS\Splendid\DetectDisplayDC.dll
2014-04-02 17:46 - 2014-04-02 17:46 - 000117248 _____ () C:\Program Files (x86)\ASUS\Splendid\CCTAdjust.dll
2014-04-02 17:46 - 2014-04-02 17:46 - 000020528 _____ () C:\Program Files (x86)\ASUS\Splendid\AMDRegammaAndGamut.dll
2014-12-21 11:07 - 2014-12-21 11:07 - 000119822 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\libgcc_s_dw2-1.dll
2014-12-21 11:07 - 2014-12-21 11:07 - 001026062 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\libstdc++-6.dll
2017-12-01 01:18 - 2017-12-01 01:18 - 000650240 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\Genie.dll
2017-11-08 22:22 - 2017-11-08 22:22 - 001685504 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\SvtNetworkTool.dll
2017-08-03 02:08 - 2017-08-03 02:08 - 000168448 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\GeniePlugin_Airprint.dll
2017-08-03 02:08 - 2017-08-03 02:08 - 000590848 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\GeniePlugin_Internet.dll
2017-11-08 22:21 - 2017-11-08 22:21 - 006886400 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\GeniePlugin_Map.dll
2016-02-26 05:07 - 2016-02-26 05:07 - 000049152 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\QRCode.dll
2016-08-15 03:28 - 2016-08-15 03:28 - 001125888 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\qwt.dll
2017-08-03 02:18 - 2017-08-03 02:18 - 002976768 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\GeniePlugin_MyMedia.dll
2012-06-27 17:23 - 2012-06-27 17:23 - 000111616 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\libvlc.dll
2012-06-27 17:23 - 2012-06-27 17:23 - 002285056 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\libvlccore.dll
2017-12-01 01:48 - 2017-12-01 01:48 - 000910848 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\GeniePlugin_NetworkProblem.dll
2016-02-22 03:25 - 2016-02-22 03:25 - 000116224 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\DragonNetTool.dll
2017-11-08 22:22 - 2017-11-08 22:22 - 001241600 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\GeniePlugin_ParentalControl.dll
2017-11-09 22:38 - 2017-11-09 22:38 - 011869184 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\GeniePlugin_Resource.dll
2017-11-08 22:22 - 2017-11-08 22:22 - 002569728 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\GeniePlugin_RouterConfiguration.dll
2017-11-08 22:31 - 2017-11-08 22:31 - 000246784 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\GeniePlugin_Statistics.dll
2017-11-08 22:22 - 2017-11-08 22:22 - 000849408 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\GeniePlugin_Ui.dll
2017-08-03 02:12 - 2017-08-03 02:12 - 000414720 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\GeniePlugin_Wireless.dll
2016-01-14 21:06 - 2016-01-14 21:06 - 000057344 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\DiagnosePlugin.dll
2016-03-02 23:17 - 2016-03-02 23:17 - 000146944 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\DiagnoseDll.dll
2015-08-24 03:41 - 2015-08-24 03:41 - 002360622 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\drivers\libntgr_api.dll
2016-03-02 23:17 - 2016-03-02 23:17 - 000072192 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\SVTUtils.dll
2016-03-02 23:17 - 2016-03-02 23:17 - 000074752 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\NetcardApi.dll
2016-03-02 23:17 - 2016-03-02 23:17 - 000136704 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\airprintdll.dll
2012-06-27 17:23 - 2012-06-27 17:23 - 000219648 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\plugins\access\libdshow_plugin.dll
2012-06-27 17:23 - 2012-06-27 17:23 - 000049664 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\plugins\audio_output\libaout_directx_plugin.dll
2012-06-27 17:23 - 2012-06-27 17:23 - 000051200 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\plugins\audio_output\libwaveout_plugin.dll
2012-06-27 17:23 - 2012-06-27 17:23 - 000070144 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\plugins\video_output\libdirectx_plugin.dll
2012-06-27 17:23 - 2012-06-27 17:23 - 000037376 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\plugins\mmxext\libmemcpymmxext_plugin.dll
2012-06-27 17:23 - 2012-06-27 17:23 - 000051200 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\plugins\control\libhotkeys_plugin.dll
2017-10-30 01:12 - 2017-10-30 01:12 - 000633344 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\InnerPlugin_Update.dll
2017-08-03 02:12 - 2017-08-03 02:12 - 000433664 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\InnerPlugin_WirelessExport.dll
2016-01-14 21:23 - 2016-01-14 21:23 - 000026112 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\WSetupApiPlugin.dll
2016-04-12 01:13 - 2016-04-12 01:13 - 000067072 _____ () C:\Program Files (x86)\NETGEAR Genie\bin\WSetupDll.dll
2018-01-29 18:38 - 2018-01-29 18:38 - 000088064 _____ () C:\Users\Jack\AppData\Local\Temp\_MEI91682\_ctypes.pyd
2018-01-29 18:38 - 2018-01-29 18:38 - 000919552 _____ () C:\Users\Jack\AppData\Local\Temp\_MEI91682\_hashlib.pyd
2018-01-29 18:38 - 2018-01-29 18:38 - 000098816 _____ () C:\Users\Jack\AppData\Local\Temp\_MEI91682\win32api.pyd
2018-01-29 18:38 - 2018-01-29 18:38 - 000110080 _____ () C:\Users\Jack\AppData\Local\Temp\_MEI91682\pywintypes27.dll
2018-01-29 18:38 - 2018-01-29 18:38 - 000364544 _____ () C:\Users\Jack\AppData\Local\Temp\_MEI91682\pythoncom27.dll
2018-01-29 18:38 - 2018-01-29 18:38 - 000686080 _____ () C:\Users\Jack\AppData\Local\Temp\_MEI91682\unicodedata.pyd
2018-01-29 18:38 - 2018-01-29 18:38 - 000320512 _____ () C:\Users\Jack\AppData\Local\Temp\_MEI91682\win32com.shell.shell.pyd
2018-01-29 18:38 - 2018-01-29 18:38 - 001177088 _____ () C:\Users\Jack\AppData\Local\Temp\_MEI91682\wx._core_.pyd
2018-01-29 18:38 - 2018-01-29 18:38 - 000806912 _____ () C:\Users\Jack\AppData\Local\Temp\_MEI91682\wx._gdi_.pyd
2018-01-29 18:38 - 2018-01-29 18:38 - 000816640 _____ () C:\Users\Jack\AppData\Local\Temp\_MEI91682\wx._windows_.pyd
2018-01-29 18:38 - 2018-01-29 18:38 - 001067520 _____ () C:\Users\Jack\AppData\Local\Temp\_MEI91682\wx._controls_.pyd
2018-01-29 18:38 - 2018-01-29 18:38 - 000733696 _____ () C:\Users\Jack\AppData\Local\Temp\_MEI91682\wx._misc_.pyd
2018-01-29 18:38 - 2018-01-29 18:38 - 000736256 _____ () C:\Users\Jack\AppData\Local\Temp\_MEI91682\pysqlite2._sqlite.pyd
2018-01-29 18:38 - 2018-01-29 18:38 - 000119808 _____ () C:\Users\Jack\AppData\Local\Temp\_MEI91682\win32file.pyd
2018-01-29 18:38 - 2018-01-29 18:38 - 000108544 _____ () C:\Users\Jack\AppData\Local\Temp\_MEI91682\win32security.pyd
2018-01-29 18:38 - 2018-01-29 18:38 - 000007168 _____ () C:\Users\Jack\AppData\Local\Temp\_MEI91682\hashobjs_ext.pyd
2018-01-29 18:38 - 2018-01-29 18:38 - 000017920 _____ () C:\Users\Jack\AppData\Local\Temp\_MEI91682\thumbnails_ext.pyd
2018-01-29 18:38 - 2018-01-29 18:38 - 000082432 _____ () C:\Users\Jack\AppData\Local\Temp\_MEI91682\usb_ext.pyd
2018-01-29 18:38 - 2018-01-29 18:38 - 000013824 _____ () C:\Users\Jack\AppData\Local\Temp\_MEI91682\common.time34.pyd
2018-01-29 18:38 - 2018-01-29 18:38 - 000018432 _____ () C:\Users\Jack\AppData\Local\Temp\_MEI91682\win32event.pyd
2018-01-29 18:38 - 2018-01-29 18:38 - 000027648 _____ () C:\Users\Jack\AppData\Local\Temp\_MEI91682\windows.conditional.pyd
2018-01-29 18:38 - 2018-01-29 18:38 - 000017408 _____ () C:\Users\Jack\AppData\Local\Temp\_MEI91682\windows.winwrap.pyd
2018-01-29 18:38 - 2018-01-29 18:38 - 000089088 _____ () C:\Users\Jack\AppData\Local\Temp\_MEI91682\windows.volumes.pyd
2018-01-29 18:38 - 2018-01-29 18:38 - 000167936 _____ () C:\Users\Jack\AppData\Local\Temp\_MEI91682\win32gui.pyd
2018-01-29 18:38 - 2018-01-29 18:38 - 000046080 _____ () C:\Users\Jack\AppData\Local\Temp\_MEI91682\_socket.pyd
2018-01-29 18:38 - 2018-01-29 18:38 - 001311744 _____ () C:\Users\Jack\AppData\Local\Temp\_MEI91682\_ssl.pyd
2018-01-29 18:38 - 2018-01-29 18:38 - 000129536 _____ () C:\Users\Jack\AppData\Local\Temp\_MEI91682\_elementtree.pyd
2018-01-29 18:38 - 2018-01-29 18:38 - 000127488 _____ () C:\Users\Jack\AppData\Local\Temp\_MEI91682\pyexpat.pyd
2018-01-29 18:38 - 2018-01-29 18:38 - 000038912 _____ () C:\Users\Jack\AppData\Local\Temp\_MEI91682\win32inet.pyd
2018-01-29 18:38 - 2018-01-29 18:38 - 000077824 _____ () C:\Users\Jack\AppData\Local\Temp\_MEI91682\wx._html2.pyd
2018-01-29 18:38 - 2018-01-29 18:38 - 000036864 _____ () C:\Users\Jack\AppData\Local\Temp\_MEI91682\_psutil_windows.pyd
2018-01-29 18:38 - 2018-01-29 18:38 - 000524248 _____ () C:\Users\Jack\AppData\Local\Temp\_MEI91682\windows._lib_cacheinvalidation.pyd
2018-01-29 18:38 - 2018-01-29 18:38 - 000011264 _____ () C:\Users\Jack\AppData\Local\Temp\_MEI91682\win32crypt.pyd
2018-01-29 18:38 - 2018-01-29 18:38 - 000218624 _____ () C:\Users\Jack\AppData\Local\Temp\_MEI91682\PIL._imaging.pyd
2018-01-29 18:38 - 2018-01-29 18:38 - 000027648 _____ () C:\Users\Jack\AppData\Local\Temp\_MEI91682\_multiprocessing.pyd
2018-01-29 18:38 - 2018-01-29 18:38 - 000020480 _____ () C:\Users\Jack\AppData\Local\Temp\_MEI91682\_yappi.pyd
2018-01-29 18:38 - 2018-01-29 18:38 - 000035840 _____ () C:\Users\Jack\AppData\Local\Temp\_MEI91682\win32process.pyd
2018-01-29 18:38 - 2018-01-29 18:38 - 000024064 _____ () C:\Users\Jack\AppData\Local\Temp\_MEI91682\win32pipe.pyd
2018-01-29 18:38 - 2018-01-29 18:38 - 000010240 _____ () C:\Users\Jack\AppData\Local\Temp\_MEI91682\select.pyd
2018-01-29 18:38 - 2018-01-29 18:38 - 000025600 _____ () C:\Users\Jack\AppData\Local\Temp\_MEI91682\win32pdh.pyd
2018-01-29 18:38 - 2018-01-29 18:38 - 000059392 _____ () C:\Users\Jack\AppData\Local\Temp\_MEI91682\windows.device_monitor.pyd
2018-01-29 18:38 - 2018-01-29 18:38 - 000017408 _____ () C:\Users\Jack\AppData\Local\Temp\_MEI91682\win32profile.pyd
2018-01-29 18:38 - 2018-01-29 18:38 - 000022528 _____ () C:\Users\Jack\AppData\Local\Temp\_MEI91682\win32ts.pyd
2018-01-29 18:40 - 2018-01-29 18:40 - 000088064 _____ () C:\Users\Jack\AppData\Local\Temp\_MEI98642\_ctypes.pyd
2018-01-29 18:40 - 2018-01-29 18:40 - 000919552 _____ () C:\Users\Jack\AppData\Local\Temp\_MEI98642\_hashlib.pyd
2018-01-29 18:40 - 2018-01-29 18:40 - 000098816 _____ () C:\Users\Jack\AppData\Local\Temp\_MEI98642\win32api.pyd
2018-01-29 18:40 - 2018-01-29 18:40 - 000110080 _____ () C:\Users\Jack\AppData\Local\Temp\_MEI98642\pywintypes27.dll
2018-01-29 18:40 - 2018-01-29 18:40 - 000364544 _____ () C:\Users\Jack\AppData\Local\Temp\_MEI98642\pythoncom27.dll
2018-01-29 18:40 - 2018-01-29 18:40 - 000686080 _____ () C:\Users\Jack\AppData\Local\Temp\_MEI98642\unicodedata.pyd
2018-01-29 18:40 - 2018-01-29 18:40 - 000320512 _____ () C:\Users\Jack\AppData\Local\Temp\_MEI98642\win32com.shell.shell.pyd
2018-01-29 18:40 - 2018-01-29 18:40 - 001177088 _____ () C:\Users\Jack\AppData\Local\Temp\_MEI98642\wx._core_.pyd
2018-01-29 18:40 - 2018-01-29 18:40 - 000806912 _____ () C:\Users\Jack\AppData\Local\Temp\_MEI98642\wx._gdi_.pyd
2018-01-29 18:40 - 2018-01-29 18:40 - 000816640 _____ () C:\Users\Jack\AppData\Local\Temp\_MEI98642\wx._windows_.pyd
2018-01-29 18:40 - 2018-01-29 18:40 - 001067520 _____ () C:\Users\Jack\AppData\Local\Temp\_MEI98642\wx._controls_.pyd
2018-01-29 18:40 - 2018-01-29 18:40 - 000733696 _____ () C:\Users\Jack\AppData\Local\Temp\_MEI98642\wx._misc_.pyd
2018-01-29 18:40 - 2018-01-29 18:40 - 000736256 _____ () C:\Users\Jack\AppData\Local\Temp\_MEI98642\pysqlite2._sqlite.pyd
2018-01-29 18:40 - 2018-01-29 18:40 - 000119808 _____ () C:\Users\Jack\AppData\Local\Temp\_MEI98642\win32file.pyd
2018-01-29 18:40 - 2018-01-29 18:40 - 000108544 _____ () C:\Users\Jack\AppData\Local\Temp\_MEI98642\win32security.pyd
2018-01-29 18:40 - 2018-01-29 18:40 - 000007168 _____ () C:\Users\Jack\AppData\Local\Temp\_MEI98642\hashobjs_ext.pyd
2018-01-29 18:40 - 2018-01-29 18:40 - 000017920 _____ () C:\Users\Jack\AppData\Local\Temp\_MEI98642\thumbnails_ext.pyd
2018-01-29 18:40 - 2018-01-29 18:40 - 000082432 _____ () C:\Users\Jack\AppData\Local\Temp\_MEI98642\usb_ext.pyd
2018-01-29 18:40 - 2018-01-29 18:40 - 000013824 _____ () C:\Users\Jack\AppData\Local\Temp\_MEI98642\common.time34.pyd
2018-01-29 18:40 - 2018-01-29 18:40 - 000018432 _____ () C:\Users\Jack\AppData\Local\Temp\_MEI98642\win32event.pyd
2018-01-29 18:40 - 2018-01-29 18:40 - 000027648 _____ () C:\Users\Jack\AppData\Local\Temp\_MEI98642\windows.conditional.pyd
2018-01-29 18:40 - 2018-01-29 18:40 - 000017408 _____ () C:\Users\Jack\AppData\Local\Temp\_MEI98642\windows.winwrap.pyd
2018-01-29 18:40 - 2018-01-29 18:40 - 000089088 _____ () C:\Users\Jack\AppData\Local\Temp\_MEI98642\windows.volumes.pyd
2018-01-29 18:40 - 2018-01-29 18:40 - 000167936 _____ () C:\Users\Jack\AppData\Local\Temp\_MEI98642\win32gui.pyd
2018-01-29 18:40 - 2018-01-29 18:40 - 000046080 _____ () C:\Users\Jack\AppData\Local\Temp\_MEI98642\_socket.pyd
2018-01-29 18:40 - 2018-01-29 18:40 - 001311744 _____ () C:\Users\Jack\AppData\Local\Temp\_MEI98642\_ssl.pyd
2018-01-29 18:40 - 2018-01-29 18:40 - 000129536 _____ () C:\Users\Jack\AppData\Local\Temp\_MEI98642\_elementtree.pyd
2018-01-29 18:40 - 2018-01-29 18:40 - 000127488 _____ () C:\Users\Jack\AppData\Local\Temp\_MEI98642\pyexpat.pyd
2018-01-29 18:40 - 2018-01-29 18:40 - 000038912 _____ () C:\Users\Jack\AppData\Local\Temp\_MEI98642\win32inet.pyd
2018-01-29 18:40 - 2018-01-29 18:40 - 000077824 _____ () C:\Users\Jack\AppData\Local\Temp\_MEI98642\wx._html2.pyd
2018-01-29 18:40 - 2018-01-29 18:40 - 000036864 _____ () C:\Users\Jack\AppData\Local\Temp\_MEI98642\_psutil_windows.pyd
2018-01-29 18:40 - 2018-01-29 18:40 - 000524248 _____ () C:\Users\Jack\AppData\Local\Temp\_MEI98642\windows._lib_cacheinvalidation.pyd
2018-01-29 18:40 - 2018-01-29 18:40 - 000011264 _____ () C:\Users\Jack\AppData\Local\Temp\_MEI98642\win32crypt.pyd
2018-01-29 18:40 - 2018-01-29 18:40 - 000218624 _____ () C:\Users\Jack\AppData\Local\Temp\_MEI98642\PIL._imaging.pyd
2018-01-29 18:40 - 2018-01-29 18:40 - 000027648 _____ () C:\Users\Jack\AppData\Local\Temp\_MEI98642\_multiprocessing.pyd
2018-01-29 18:40 - 2018-01-29 18:40 - 000020480 _____ () C:\Users\Jack\AppData\Local\Temp\_MEI98642\_yappi.pyd
2018-01-29 18:40 - 2018-01-29 18:40 - 000035840 _____ () C:\Users\Jack\AppData\Local\Temp\_MEI98642\win32process.pyd
2018-01-29 18:40 - 2018-01-29 18:40 - 000024064 _____ () C:\Users\Jack\AppData\Local\Temp\_MEI98642\win32pipe.pyd
2018-01-29 18:40 - 2018-01-29 18:40 - 000010240 _____ () C:\Users\Jack\AppData\Local\Temp\_MEI98642\select.pyd
2018-01-29 18:40 - 2018-01-29 18:40 - 000025600 _____ () C:\Users\Jack\AppData\Local\Temp\_MEI98642\win32pdh.pyd
2018-01-29 18:40 - 2018-01-29 18:40 - 000059392 _____ () C:\Users\Jack\AppData\Local\Temp\_MEI98642\windows.device_monitor.pyd
2018-01-29 18:40 - 2018-01-29 18:40 - 000017408 _____ () C:\Users\Jack\AppData\Local\Temp\_MEI98642\win32profile.pyd
2018-01-29 18:40 - 2018-01-29 18:40 - 000022528 _____ () C:\Users\Jack\AppData\Local\Temp\_MEI98642\win32ts.pyd
2014-12-14 00:31 - 2013-10-23 16:44 - 001242584 _____ () C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\ACE.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
AlternateDataStreams: C:\ProgramData\TEMP:3E7908F7 [131]
AlternateDataStreams: C:\ProgramData\TEMP:ADAB671B [133]
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
 
==================== Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
HKU\S-1-5-21-2592302959-4100768495-3643388182-1001\Software\Classes\.scr: AutoCADScriptFile => 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
IE trusted site: HKU\S-1-5-21-2592302959-4100768495-3643388182-1001\...\malafe.net -> hxxp://www.malafe.net
IE trusted site: HKU\S-1-5-21-2592302959-4100768495-3643388182-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\malafe.net -> hxxp://www.malafe.net
 
==================== Hosts content: ==========================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2013-08-22 08:25 - 2018-01-29 18:45 - 000007217 _____ C:\WINDOWS\system32\Drivers\etc\hosts
 
127.0.0.1 cpm.paneladmin.pro
127.0.0.1 publisher.hmdiadmingate.xyz
127.0.0.1 hmdicrewtracksystem.xyz
127.0.0.1 mydownloaddomain.com
127.0.0.1 linkmate.space
127.0.0.1 space1.adminpressure.space
127.0.0.1 trackpressure.website
127.0.0.1 doctorlink.space
127.0.0.1 plugpackdownload.net
127.0.0.1 texttotalk.org
127.0.0.1 gambling577.xyz
127.0.0.1 htagdownload.space
127.0.0.1 mybcnmonetize.com
127.0.0.1 360devtraking.website
127.0.0.1 dscdn.pw
127.0.0.1 bcnmonetize.go2affise.com
127.0.0.1 beautifllink.xyz
0.0.0.0 12finance.com
0.0.0.0 12kotov.ru
0.0.0.0 144.76.201.175
0.0.0.0 1dnscontrol.com
0.0.0.0 adsrvr.org
0.0.0.0 adsymptotic.com
0.0.0.0 advertising.com
0.0.0.0 akisho.ru
0.0.0.0 altocloudmedia.com
0.0.0.0 amtomil.ru
0.0.0.0 appchucklegift.com
0.0.0.0 asedownloadgate.com
0.0.0.0 atwola.com
 
There are 229 more lines.
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-19-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Windows\img0.jpg
HKU\S-1-5-20-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\Windows\img0.jpg
HKU\S-1-5-21-2592302959-4100768495-3643388182-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Jack\AppData\Local\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\LocalState\PhotosAppBackground\{6d23df3e-9cdd-4661-9212-351053f012c6}.jpg
HKU\S-1-5-21-2592302959-4100768495-3643388182-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Control Panel\Desktop\\Wallpaper -> C:\Users\Jack\AppData\Local\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\LocalState\PhotosAppBackground\{6d23df3e-9cdd-4661-9212-351053f012c6}.jpg
HKU\S-1-5-21-2592302959-4100768495-3643388182-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Control Panel\Desktop\\Wallpaper -> C:\Users\steph\AppData\Local\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\LocalState\PhotosAppBackground\{9841d69d-26b2-4b8e-86ee-c1770246faf1}.jpg
DNS Servers: 8.8.8.8
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: RequireAdmin)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
HKLM\...\StartupApproved\Run: => "TrayMonitor.exe"
HKLM\...\StartupApproved\Run: => "Acronis Scheduler2 Service"
HKLM\...\StartupApproved\Run: => "iTunesHelper"
HKLM\...\StartupApproved\Run32: => "WebStorage"
HKLM\...\StartupApproved\Run32: => "BackupAndRecoveryMonitor.exe"
HKLM\...\StartupApproved\Run32: => "AcronisTibMounterMonitor"
HKLM\...\StartupApproved\Run32: => "Autodesk Desktop App"
HKU\S-1-5-21-2592302959-4100768495-3643388182-1001\...\StartupApproved\StartupFolder: => "PdaNet Desktop.lnk"
HKU\S-1-5-21-2592302959-4100768495-3643388182-1001\...\StartupApproved\StartupFolder: => "Send to OneNote.lnk"
HKU\S-1-5-21-2592302959-4100768495-3643388182-1001\...\StartupApproved\Run: => "CCleaner Monitoring"
HKU\S-1-5-21-2592302959-4100768495-3643388182-1001\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-2592302959-4100768495-3643388182-1001\...\StartupApproved\Run: => "AirDroid 3"
HKU\S-1-5-21-2592302959-4100768495-3643388182-1001\...\StartupApproved\Run: => "Autodesk Sync"
HKU\S-1-5-21-2592302959-4100768495-3643388182-1001\...\StartupApproved\Run: => "RecoveryHost"
HKU\S-1-5-21-2592302959-4100768495-3643388182-1001\...\StartupApproved\Run: => "overriding"
HKU\S-1-5-21-2592302959-4100768495-3643388182-1001\...\StartupApproved\Run: => "proactively"
HKU\S-1-5-21-2592302959-4100768495-3643388182-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\StartupApproved\StartupFolder: => "PdaNet Desktop.lnk"
HKU\S-1-5-21-2592302959-4100768495-3643388182-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\StartupApproved\StartupFolder: => "Send to OneNote.lnk"
HKU\S-1-5-21-2592302959-4100768495-3643388182-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\StartupApproved\Run: => "CCleaner Monitoring"
HKU\S-1-5-21-2592302959-4100768495-3643388182-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-2592302959-4100768495-3643388182-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\StartupApproved\Run: => "AirDroid 3"
HKU\S-1-5-21-2592302959-4100768495-3643388182-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\StartupApproved\Run: => "Autodesk Sync"
HKU\S-1-5-21-2592302959-4100768495-3643388182-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\StartupApproved\Run: => "RecoveryHost"
HKU\S-1-5-21-2592302959-4100768495-3643388182-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\StartupApproved\Run: => "overriding"
HKU\S-1-5-21-2592302959-4100768495-3643388182-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\StartupApproved\Run: => "proactively"
HKU\S-1-5-21-2592302959-4100768495-3643388182-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\StartupApproved\Run: => "uTorrent"
HKU\S-1-5-21-2592302959-4100768495-3643388182-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\StartupApproved\Run: => "OneDrive"
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [{73FC6DF4-B7B4-4A57-9E65-0FF5C20398A4}] => (Allow) C:\Program Files\iTunes\iTunes.exe
FirewallRules: [{4855DA81-0286-460F-A43A-60083C8C3E06}] => (Allow) C:\Program Files (x86)\Google\Chrome Remote Desktop\63.0.3239.32\remoting_host.exe
FirewallRules: [UDP Query User{940E4A6B-8982-478F-8DEC-A53BC10EA4AE}C:\program files (x86)\netgear genie\bin\netgeargenie.exe] => (Allow) C:\program files (x86)\netgear genie\bin\netgeargenie.exe
FirewallRules: [TCP Query User{B7BE1272-3734-475E-B7AB-AC4AC48110FD}C:\program files (x86)\netgear genie\bin\netgeargenie.exe] => (Allow) C:\program files (x86)\netgear genie\bin\netgeargenie.exe
FirewallRules: [TCP Query User{B84CF56E-0ECE-430F-9FB3-8083BB4D5CF0}C:\program files\itunes\itunes.exe] => (Allow) C:\program files\itunes\itunes.exe
FirewallRules: [{98921ED5-92EA-4066-B418-F67D55E6EBC4}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe
FirewallRules: [{B76C54E5-2B83-48F3-8BA2-D00FCC25A8F7}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe
FirewallRules: [{9093C993-6487-4DDA-811B-73FB486AF3D6}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe
FirewallRules: [{19B9DA55-8CB4-461F-B56E-E5DB4DBC27D2}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe
FirewallRules: [{A62D8705-8515-417B-8913-AC7879E01F98}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe
FirewallRules: [{18FCAFCD-2F65-47C4-BBEE-49DD6DF71495}] => (Allow) C:\Users\Jack\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{7E600F69-D2A9-440C-84B1-1DAA7172D3DE}] => (Allow) C:\Users\Jack\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{5F4F2BDA-2C1B-41D3-8B5F-2590D434E261}] => (Allow) C:\Users\Jack\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{54693836-C7E5-4BA5-96BE-EB95F01C8652}] => (Allow) C:\Users\Jack\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{1A4A2BC1-5069-4370-BFED-07082E6F367E}] => (Allow) C:\Users\Jack\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{7116FE87-132D-4119-964A-1C6DE5F78D5B}] => (Allow) C:\Users\Jack\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{FD0348C6-13CD-466E-9932-4E746AFACA61}] => (Allow) C:\Program Files\SoftEther VPN Client\vpnclient_x64.exe
FirewallRules: [{4C968CEE-38EB-41D6-80C0-80430348BDAA}] => (Allow) C:\Program Files\SoftEther VPN Client\vpnclient.exe
FirewallRules: [{794AD423-B1BA-492C-9828-FA8393CE1727}] => (Allow) C:\Program Files\SoftEther VPN Client\vpncmd_x64.exe
FirewallRules: [{4A35F9CA-FB41-455F-AA6F-0BBE545C9582}] => (Allow) C:\Program Files\SoftEther VPN Client\vpncmd.exe
FirewallRules: [{F7052B9E-60AB-4A06-ACB6-84609E7AC83D}] => (Allow) C:\Program Files\SoftEther VPN Client\vpncmgr_x64.exe
FirewallRules: [{83EA5728-C5B6-4862-BE5E-2379FFE394C2}] => (Allow) C:\Program Files\SoftEther VPN Client\vpncmgr.exe
FirewallRules: [{4125668B-190C-4047-A862-A20499CE1013}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{92368EBB-BBFF-402E-88FF-561975882B7B}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{B99DB742-D966-437A-AF8F-B90DB1204DC1}] => (Allow) C:\Program Files\iTunes\iTunes.exe
FirewallRules: [{5C2E8C7D-8BED-4E63-9D2C-D6461430D376}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{545FBC24-F792-4E9C-B8D6-4DCA8ABEAD3A}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{27C2C7EE-42E2-400E-B54D-129B9B803318}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{783C277F-649A-4ED2-B11E-41A89E85D876}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{A69B40CB-0A96-405A-9E9A-DEA5E8A54681}] => (Allow) C:\Program Files\HP\HP Deskjet 1510 series\Bin\HPNetworkCommunicatorCom.exe
FirewallRules: [{BE78FE1A-FBBA-439B-A043-8E61796B7192}] => (Allow) C:\Program Files\HP\HP Deskjet 1510 series\Bin\USBSetup.exe
FirewallRules: [{076C1A82-7D46-4725-858D-9904E1BB3706}] => (Allow) C:\Users\steph\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{698B6020-160F-4DA7-AE5C-C37DAEEADC24}] => (Allow) C:\Users\steph\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{FC03DAAB-7CE3-4F52-8BB3-86141AB4E5F4}] => (Allow) C:\Users\steph\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{87633B9B-933A-4BBE-9863-F045D57457FA}] => (Allow) C:\Users\steph\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{EADD3BA4-BAA7-43F7-A49A-700C7E299ECA}] => (Allow) C:\Users\steph\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{BAB918C6-3449-4113-BED1-E28AF4AB9C21}] => (Allow) C:\Users\steph\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{F5A3F3BB-9BBD-4BD6-AF86-7F56081EFA8A}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{2FF64816-A9E0-4E3A-B19C-B6755B10A45B}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{C95B947A-D785-4161-A7F6-B99A8024C50A}C:\program files (x86)\kodi\kodi.exe] => (Allow) C:\program files (x86)\kodi\kodi.exe
FirewallRules: [UDP Query User{CB80FAED-516A-4135-8DC7-DD94FBC20B34}C:\program files (x86)\kodi\kodi.exe] => (Allow) C:\program files (x86)\kodi\kodi.exe
FirewallRules: [{E03C3742-24D0-4FB9-B9AD-E3010B977714}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{DAB02EEB-B0D8-40ED-84E8-3F9004421C0F}] => (Allow) LPort=2869
FirewallRules: [{CEAC0EF0-CA61-43CA-B454-072C2C169639}] => (Allow) LPort=1900
FirewallRules: [TCP Query User{F110F2F2-2B14-4017-9BBE-F106EE80E463}C:\ec-apps\esg\e-sys\jre\bin\javaw.exe] => (Allow) C:\ec-apps\esg\e-sys\jre\bin\javaw.exe
FirewallRules: [UDP Query User{0AFEB7DD-9A80-4B8C-9556-20E863507A88}C:\ec-apps\esg\e-sys\jre\bin\javaw.exe] => (Allow) C:\ec-apps\esg\e-sys\jre\bin\javaw.exe
FirewallRules: [TCP Query User{ADFE5426-1BFE-4487-A070-CBD5A6327411}C:\ec-apps\esg\e-sys\jre\bin\javaw.exe] => (Allow) C:\ec-apps\esg\e-sys\jre\bin\javaw.exe
FirewallRules: [UDP Query User{0FBA96BC-C1B7-428C-989C-12001D500391}C:\ec-apps\esg\e-sys\jre\bin\javaw.exe] => (Allow) C:\ec-apps\esg\e-sys\jre\bin\javaw.exe
FirewallRules: [{8874FB22-6F3B-46BF-BA6B-9EA734D2BE9C}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{39F4844F-AF34-4239-9639-9DA89D1E9825}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{91D2BF47-2A76-4832-BE4D-96A655767419}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{8C024241-827C-4F02-A344-44471A08C823}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{7080DAFF-30B4-410D-BE2C-9CF1C9C9FF33}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{4833A446-F1CC-4A72-B031-5822EB7EF580}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{EED71CAA-1740-4A06-B701-EAE8609DA636}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{45F64694-0416-4AC7-92E4-EF3ED2645F27}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{A6C57522-1F3E-4306-BCC9-8ED3ECAFB634}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{54E85FDE-F80E-4776-A28A-2F85B2BBEAFC}] => (Allow) C:\Program Files (x86)\Mass\gunny.exe
FirewallRules: [{73266288-9BE7-4127-8724-4232166A230D}] => (Allow) C:\Program Files (x86)\Mass\knudsen.exe
FirewallRules: [{625A1EAF-5448-4EF2-8B70-BAB10381B646}] => (Allow) 㩃停潲牧浡䘠汩獥⠠㡸⤶啜浮汥整杤敲湯屹湕敭瑬摥牧潥祮攮數
FirewallRules: [{BB09826D-8D7A-4A9E-B56A-D3F7113F404C}] => (Allow) 㩃停潲牧浡䘠汩獥⠠㡸⤶啜浮汥整杤敲湯屹湕敭瑬摥牧潥祮⹟硥e
FirewallRules: [{0B34C903-C826-4F77-80E0-3ACF8CFEA82E}] => (Block) C:\Program Files (x86)\VideoLAN\VLC\vlc.exe
FirewallRules: [{E62CB541-105E-4F60-91AC-5A8A84F5FE85}] => (Block) C:\Windows\SysWOW64\attrib.exe
FirewallRules: [{C8B696C9-19F1-410E-BC31-8BA3DA2B8E5A}] => (Block) C:\Program Files\Windows Defender\MsMpEng.exe
FirewallRules: [{4FC13D05-4286-4B12-BFA0-DA3A74CECED1}] => (Block) C:\Windows\notepad.exe
FirewallRules: [{3F4AAAEF-2B6B-43E7-9385-F1BF99056992}] => (Block) C:\Windows\System32\calc.exe
FirewallRules: [{431E4307-F8B0-4339-9038-F1FCD25626D1}] => (Block) C:\Windows\SysWOW64\regsvr32.exe
FirewallRules: [{2739818B-CBD7-438B-BA88-AA88BD01AE6A}] => (Block) C:\Windows\SysWOW64\rundll32.exe
FirewallRules: [{32D92854-B930-4012-B5F8-1B74C9066121}] => (Block) C:\Windows\SysWOW64\svchost.exe
FirewallRules: [{70BA5E98-302D-43AB-8022-498E5D7E22D7}] => (Block) C:\Windows\System32\wbem\WmiPrvSE.exe
FirewallRules: [{DBC210EF-9B32-46A7-89BD-38C22B25D05B}] => (Block) C:\Windows\servicing\TrustedInstaller.exe
FirewallRules: [{62FF3D18-2048-4E41-ABD4-4AC848EEFE33}] => (Block) C:\Windows\System32\GameBarPresenceWriter.exe
FirewallRules: [{354CD4A2-F335-4A56-9E80-0E3297029272}] => (Block) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
FirewallRules: [{DE5AEE66-8DD6-4314-933D-50F0C7EAFA1E}] => (Block) C:\Windows\System32\regsvr32.exe
FirewallRules: [{B29921A9-4B7E-4AA9-8BFB-653FBCCBDCC7}] => (Block) C:\Users\Jack\AppData\Roaming\AGData\bin\proxycheck.exe
FirewallRules: [{831D7306-003C-4049-B72C-3DE0A7B97E47}] => (Block) C:\Users\steph\AppData\Local\Google\Chrome\User Data\SwReporter\24.137.203\software_reporter_tool.exe
FirewallRules: [{76330535-F8E0-428D-869A-7F0C32BB468E}] => (Block) C:\Disk\securedisk.exe
FirewallRules: [{70EC17FD-91DF-413E-B418-926A424335C6}] => (Block) C:\Windows\rss\csrss.exe
FirewallRules: [TCP Query User{095274DD-910D-4413-84BF-4C7968D3FFB4}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [UDP Query User{EFB03183-0F65-480C-8124-A4AB866930D8}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [{85B34758-97A3-4a63-832A-9825D8777935}}] => (Allow) C:\Program Files (x86)\UnHackMe\wu.exe
FirewallRules: [{9187CF69-6824-487d-A9F0-AFF5C2C29BA9}}] => (Allow) C:\Program Files (x86)\UnHackMe\wu.exe
FirewallRules: [{85B34758-97A3-4a63-832A-9825D8777934}}] => (Allow) C:\Program Files (x86)\UnHackMe\regruninfo.exe
FirewallRules: [{9187CF69-6824-487d-A9F0-AFF5C2C29BA8}}] => (Allow) C:\Program Files (x86)\UnHackMe\regruninfo.exe
FirewallRules: [{98F7BCCF-C440-4CAC-8C83-BA976E61E65C}] => (Allow) C:\Program Files (x86)\UnHackMe\RegRunInfo.exe
FirewallRules: [{D07899E0-7EC6-4EC3-AE14-2EAC4BF52119}] => (Allow) C:\Program Files (x86)\UnHackMe\RegRunInfo.exe
FirewallRules: [{23A3931B-6324-4F75-BED5-2D17A1751D80}] => (Allow) C:\Program Files (x86)\UnHackMe\wu.exe
FirewallRules: [{8A147BCE-58E8-45F3-A5B4-5CF4B759A87F}] => (Allow) C:\Program Files (x86)\UnHackMe\wu.exe
 
==================== Restore Points =========================
 
27-01-2018 21:37:51 Scheduled Checkpoint
 
==================== Faulty Device Manager Devices =============
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (01/29/2018 06:42:41 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program explorer.exe version 10.0.16299.192 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.
 
Process ID: 1924
 
Start Time: 01d39959d7c2555a
 
Termination Time: 0
 
Application Path: C:\Windows\explorer.exe
 
Report Id: bcfc0bcb-2a43-4b25-b9a7-7e6ea8bb4f48
 
Faulting package full name: 
 
Faulting package-relative application ID:
 
Error: (01/29/2018 06:40:30 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: LockApp.exe, version: 10.0.16299.15, time stamp: 0x59cda938
Faulting module name: LockApp.exe, version: 10.0.16299.15, time stamp: 0x59cda938
Exception code: 0xc0000005
Fault offset: 0x0000000000017120
Faulting process id: 0x1f9c
Faulting application start time: 0x01d3995a891c9457
Faulting application path: C:\Windows\SystemApps\Microsoft.LockApp_cw5n1h2txyewy\LockApp.exe
Faulting module path: C:\Windows\SystemApps\Microsoft.LockApp_cw5n1h2txyewy\LockApp.exe
Report Id: 3786d5da-440c-41f0-a6c7-bacbab6572e2
Faulting package full name: Microsoft.LockApp_10.0.16299.15_neutral__cw5n1h2txyewy
Faulting package-relative application ID: WindowsDefaultLockScreen
 
Error: (01/29/2018 06:39:53 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: mDNSCoreReceiveResponse: Unexpected conflict discarding   19 9.0.168.192.in-addr.arpa. PTR Jack-Laptop.local.
 
Error: (01/29/2018 06:39:53 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: mDNSCoreReceiveResponse: Received from 192.168.0.9:5353   21 9.0.168.192.in-addr.arpa. PTR Jack-Laptop-2.local.
 
Error: (01/28/2018 11:57:37 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: mbam.exe, version: 3.0.0.1169, time stamp: 0x599723f1
Faulting module name: Qt5Core.dll, version: 5.6.2.0, time stamp: 0x594d4411
Exception code: 0xc0000005
Fault offset: 0x001a9fd6
Faulting process id: 0x24e0
Faulting application start time: 0x01d398588717228a
Faulting application path: C:\Program Files\Malwarebytes\Anti-Malware\mbam.exe
Faulting module path: C:\Program Files\Malwarebytes\Anti-Malware\Qt5Core.dll
Report Id: 708e1902-d13a-4835-8e33-1f3ee2daf994
Faulting package full name: 
Faulting package-relative application ID:
 
Error: (01/28/2018 11:53:38 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: mbamservice.exe, version: 3.1.0.556, time stamp: 0x5988c3f1
Faulting module name: mbamservice.exe, version: 3.1.0.556, time stamp: 0x5988c3f1
Exception code: 0xc0000005
Fault offset: 0x00000000001b6596
Faulting process id: 0x2554
Faulting application start time: 0x01d398588a323473
Faulting application path: C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe
Faulting module path: C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe
Report Id: 1dcfabe3-847e-4964-ac93-8db6a5abef2c
Faulting package full name: 
Faulting package-relative application ID:
 
Error: (01/28/2018 11:52:10 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: mDNSCoreReceiveResponse: Unexpected conflict discarding   19 6.0.168.192.in-addr.arpa. PTR Jack-Laptop.local.
 
Error: (01/28/2018 11:52:10 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: mDNSCoreReceiveResponse: Received from 192.168.0.6:5353   21 6.0.168.192.in-addr.arpa. PTR Jack-Laptop-2.local.
 
Error: (01/28/2018 07:52:42 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: mDNSCoreReceiveResponse: Unexpected conflict discarding   19 1.2.9.A.9.2.3.A.1.A.B.0.E.6.4.3.0.0.0.0.0.0.0.0.0.0.0.0.0.8.E.F.ip6.arpa. PTR Jack-Laptop.local.
 
Error: (01/28/2018 07:52:42 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: mDNSCoreReceiveResponse: Received from 192.168.0.6:5353   21 1.2.9.A.9.2.3.A.1.A.B.0.E.6.4.3.0.0.0.0.0.0.0.0.0.0.0.0.0.8.E.F.ip6.arpa. PTR Jack-Laptop-2.local.
 
 
System errors:
=============
Error: (01/29/2018 08:06:14 PM) (Source: Disk) (EventID: 11) (User: )
Description: The driver detected a controller error on \Device\Harddisk0\DR0.
 
Error: (01/29/2018 08:06:14 PM) (Source: Disk) (EventID: 11) (User: )
Description: The driver detected a controller error on \Device\Harddisk0\DR0.
 
Error: (01/29/2018 08:06:14 PM) (Source: Disk) (EventID: 11) (User: )
Description: The driver detected a controller error on \Device\Harddisk0\DR0.
 
Error: (01/29/2018 08:06:14 PM) (Source: Disk) (EventID: 11) (User: )
Description: The driver detected a controller error on \Device\Harddisk0\DR0.
 
Error: (01/29/2018 08:06:14 PM) (Source: Disk) (EventID: 11) (User: )
Description: The driver detected a controller error on \Device\Harddisk0\DR0.
 
Error: (01/29/2018 08:06:14 PM) (Source: Disk) (EventID: 11) (User: )
Description: The driver detected a controller error on \Device\Harddisk0\DR0.
 
Error: (01/29/2018 08:06:14 PM) (Source: Disk) (EventID: 11) (User: )
Description: The driver detected a controller error on \Device\Harddisk0\DR0.
 
Error: (01/29/2018 08:06:14 PM) (Source: Disk) (EventID: 11) (User: )
Description: The driver detected a controller error on \Device\Harddisk0\DR0.
 
Error: (01/29/2018 08:06:14 PM) (Source: Disk) (EventID: 11) (User: )
Description: The driver detected a controller error on \Device\Harddisk0\DR0.
 
Error: (01/29/2018 08:06:14 PM) (Source: Disk) (EventID: 11) (User: )
Description: The driver detected a controller error on \Device\Harddisk0\DR0.
 
 
CodeIntegrity:
===================================
  Date: 2018-01-29 19:44:10.074
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Microsoft signing level requirements.
 
  Date: 2018-01-29 19:44:10.070
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Microsoft signing level requirements.
 
  Date: 2018-01-29 18:50:03.498
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Microsoft signing level requirements.
 
  Date: 2018-01-29 18:50:03.494
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Microsoft signing level requirements.
 
  Date: 2018-01-29 18:45:42.444
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Microsoft signing level requirements.
 
  Date: 2018-01-29 18:45:42.440
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Microsoft signing level requirements.
 
  Date: 2018-01-29 18:45:38.076
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Microsoft signing level requirements.
 
  Date: 2018-01-29 18:45:38.072
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Microsoft signing level requirements.
 
  Date: 2018-01-29 18:45:02.387
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Microsoft signing level requirements.
 
  Date: 2018-01-29 18:45:02.382
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Microsoft signing level requirements.
 
 
==================== Memory info =========================== 
 
Processor: Intel® Core™ i5-4210U CPU @ 1.70GHz
Percentage of memory in use: 54%
Total physical RAM: 6027.65 MB
Available physical RAM: 2749.14 MB
Total Virtual: 12171.65 MB
Available Virtual: 8914.21 MB
 
==================== Drives ================================
 
Drive c: (OS) (Fixed) (Total:910.4 GB) (Free:543.64 GB) NTFS ==>[system with boot components (obtained from drive)]
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: 802C889E)
 
Partition: GPT.
 
==================== End of Addition.txt ============================
 
(TOSHIBA CORPORATION) C:\Windows\System32\vdhkexasvc.exe
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome Remote Desktop\63.0.3239.32\remoting_host.exe
(TomTom) C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe
(SoftEther VPN Project at University of Tsukuba, Japan.) C:\Program Files\SoftEther VPN Client\vpnclient_x64.exe
(Autodesk Inc.) C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AdAppMgrSvc.exe
(Paramount Software UK Ltd) C:\Program Files\Macrium\Common\MacriumService.exe
(HP) C:\Windows\System32\HPSIsvc.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Intel Corporation) C:\Windows\System32\DptfPolicyLpmService.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(Intel Corporation) C:\Windows\System32\DptfPolicyConfigTDPService.exe
(Intel Corporation) C:\Windows\System32\DptfParticipantProcessorService.exe
(Intel Corporation) C:\Windows\System32\DptfPolicyCriticalService.exe
(Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome Remote Desktop\63.0.3239.32\remoting_host.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe
(ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
(Greatis Software) C:\Program Files (x86)\UnHackMe\hackmon.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
() C:\Windows\System32\igfxTray.exe
() C:\Users\Jack\AppData\Local\atmibgl\atmibgl.exe
() C:\Users\Jack\AppData\Local\wimxehg\dsapwgt.exe
(Microsoft Corporation) C:\Windows\System32\Speech_OneCore\common\SpeechRuntime.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(WildTangent) C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe
(HP Inc.) C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.7\GoogleCrashHandler.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.7\GoogleCrashHandler64.exe
(SoftEther VPN Project at University of Tsukuba, Japan.) C:\Program Files\SoftEther VPN Client\vpnclient_x64.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_w32.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_x64.exe
(Intel Corporation) C:\Windows\System32\DptfPolicyLpmServiceHelper.exe
() C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(TomTom) C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe
(NETGEAR Inc.) C:\Program Files (x86)\NETGEAR Genie\bin\NETGEARGenie.exe
(SoftEther VPN Project at University of Tsukuba, Japan.) C:\Program Files\SoftEther VPN Client\vpncmgr_x64.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
() C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(Microsoft Corporation) C:\Windows\splwow64.exe
() C:\Program Files (x86)\Google\Drive\googledrivesync.exe
() C:\Program Files (x86)\NETGEAR Genie\bin\genie2_tray.exe
() C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPCenter.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPHelper.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Malwarebytes Corp.) C:\Users\Jack\Downloads\mbar-1.10.3.1001.exe
(Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
(Malwarebytes Corporation) C:\Users\Jack\Desktop\mbar\mbar.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
() C:\Users\Jack\AppData\Local\atmibgl\avbwncd.exe
() C:\Users\Jack\AppData\Local\atmibgl\avbwncd.exe
() C:\Users\Jack\AppData\Local\atmibgl\avbwncd.exe
() C:\Users\Jack\AppData\Local\atmibgl\avbwncd.exe
 
==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [630168 2017-09-29] (Microsoft Corporation)
HKLM\...\Run: [SoftEther VPN Client UI Helper] => C:\Program Files\SoftEther VPN Client\vpnclient_x64.exe [5248456 2017-06-29] (SoftEther VPN Project at University of Tsukuba, Japan.)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [297784 2017-10-20] (Apple Inc.)
HKLM\...\Run: [DptfPolicyLpmServiceHelper] => C:\WINDOWS\system32\DptfPolicyLpmServiceHelper.exe [114048 2013-10-17] (Intel Corporation)
HKLM-x32\...\Run: [WebStorage] => C:\Program Files (x86)\ASUS\WebStorage\2.1.11.399\ASUSWSLoader.exe [63296 2014-08-20] ()
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM-x32\...\Run: [HPUsageTrackingLEDM] => "C:\Program Files (x86)\HP\HP UT LEDM\bin\hppusg.exe" "C:\Program Files (x86)\HP\HP UT LEDM\"
HKLM-x32\...\Run: [Autodesk Desktop App] => C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AutodeskDesktopApp.exe [704424 2017-06-15] (Autodesk, Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2017-12-19] (Oracle Corporation)
HKLM\...\Policies\Explorer\Run: [BtvStack] => C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-21-2592302959-4100768495-3643388182-1001\...\Run: [Google Update] => C:\Users\Jack\AppData\Local\Google\Update\1.3.33.7\GoogleUpdateCore.exe [601680 2017-11-14] (Google Inc.)
HKU\S-1-5-21-2592302959-4100768495-3643388182-1001\...\Run: [Autodesk Sync] => C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe [1283096 2016-10-10] (Autodesk, Inc.)
HKU\S-1-5-21-2592302959-4100768495-3643388182-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [10257872 2018-01-09] (Piriform Ltd)
HKU\S-1-5-21-2592302959-4100768495-3643388182-1001\...\Run: [GoogleDriveSync] => C:\Program Files (x86)\Google\Drive\googledrivesync.exe [41061856 2017-11-20] ()
HKU\S-1-5-21-2592302959-4100768495-3643388182-1001\...\Run: [TomTomHOME.exe] => C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe [254840 2017-12-18] (TomTom)
HKU\S-1-5-21-2592302959-4100768495-3643388182-1001\...\Run: [NETGEARGenie] => C:\Program Files (x86)\NETGEAR Genie\bin\NETGEARGenie.exe [612336 2017-07-04] (NETGEAR Inc.)
HKU\S-1-5-21-2592302959-4100768495-3643388182-1001\...\Policies\Explorer: [] 
HKU\S-1-5-21-2592302959-4100768495-3643388182-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [Google Update] => C:\Users\Jack\AppData\Local\Google\Update\1.3.33.7\GoogleUpdateCore.exe [601680 2017-11-14] (Google Inc.)
HKU\S-1-5-21-2592302959-4100768495-3643388182-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [Autodesk Sync] => C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe [1283096 2016-10-10] (Autodesk, Inc.)
HKU\S-1-5-21-2592302959-4100768495-3643388182-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [10257872 2018-01-09] (Piriform Ltd)
HKU\S-1-5-21-2592302959-4100768495-3643388182-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [GoogleDriveSync] => C:\Program Files (x86)\Google\Drive\googledrivesync.exe [41061856 2017-11-20] ()
HKU\S-1-5-21-2592302959-4100768495-3643388182-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [TomTomHOME.exe] => C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe [254840 2017-12-18] (TomTom)
HKU\S-1-5-21-2592302959-4100768495-3643388182-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [NETGEARGenie] => C:\Program Files (x86)\NETGEAR Genie\bin\NETGEARGenie.exe [612336 2017-07-04] (NETGEAR Inc.)
HKU\S-1-5-21-2592302959-4100768495-3643388182-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Policies\Explorer: [] 
HKU\S-1-5-21-2592302959-4100768495-3643388182-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Run: [uTorrent] => C:\Users\steph\AppData\Roaming\uTorrent\uTorrent.exe [2026520 2016-01-09] (BitTorrent Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SoftEther VPN Client Manager Startup.lnk [2017-06-29]
ShortcutTarget: SoftEther VPN Client Manager Startup.lnk -> C:\Program Files\SoftEther VPN Client\vpncmgr_x64.exe (SoftEther VPN Project at University of Tsukuba, Japan.)
Startup: C:\Users\Jack\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Monitor Ink Alerts - HP Deskjet 1510 series.lnk [2018-01-29]
ShortcutTarget: Monitor Ink Alerts - HP Deskjet 1510 series.lnk -> C:\Program Files\HP\HP Deskjet 1510 series\Bin\HPStatusBL.dll (Hewlett-Packard Co.)
Startup: C:\Users\Jack\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\PdaNet Desktop.lnk [2017-01-18]
ShortcutTarget: PdaNet Desktop.lnk -> C:\Program Files (x86)\PdaNet for Android\PdaNetPC.exe ()
Startup: C:\Users\Jack\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Send to OneNote.lnk [2017-04-06]
ShortcutTarget: Send to OneNote.lnk -> C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE (Microsoft Corporation)
BootExecute: autocheck autochk * Partizan
GroupPolicy: Restriction <==== ATTENTION
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 75.114.81.1 209.18.47.61 75.114.81.2
Tcpip\..\Interfaces\{1a3c6e9c-be1b-405c-ac3f-356fb3805c01}: [DhcpNameServer] 8.8.8.8
Tcpip\..\Interfaces\{1d5b4b4c-5b2d-4023-a952-de4ef30cd91c}: [DhcpNameServer] 8.8.8.8
Tcpip\..\Interfaces\{887671a0-cb5c-11e7-805b-806e6f6e6963}: [NameServer] 8.8.8.8
Tcpip\..\Interfaces\{ad359bfc-5864-4fea-89c1-ca74c850c971}: [DhcpNameServer] 172.20.10.1
Tcpip\..\Interfaces\{C866D6E9-77B9-48B3-9F65-3C09B10BEEBC}: [NameServer] 8.8.8.8
Tcpip\..\Interfaces\{dd286b07-686a-4c55-9b1f-608c951cf41e}: [NameServer] 8.8.8.8
Tcpip\..\Interfaces\{dd286b07-686a-4c55-9b1f-608c951cf41e}: [DhcpNameServer] 75.114.81.1 209.18.47.61 75.114.81.2
Tcpip\..\Interfaces\{f2f6d513-82d3-448d-a072-ac32ee0240d9}: [DhcpNameServer] 8.8.8.8
Tcpip\..\Interfaces\{fef64767-51fe-4011-a6ec-2832ccba2877}: [DhcpNameServer] 10.0.0.1
 
Internet Explorer:
==================
HKU\S-1-5-21-2592302959-4100768495-3643388182-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
HKU\S-1-5-21-2592302959-4100768495-3643388182-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
HKU\S-1-5-21-2592302959-4100768495-3643388182-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
HKU\S-1-5-21-2592302959-4100768495-3643388182-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
HKU\S-1-5-21-2592302959-4100768495-3643388182-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617910&ResetID=131614960202570952&GUID=B919FCCE-F7DF-4D0B-9F6D-2C4985B30994
HKU\S-1-5-21-2592302959-4100768495-3643388182-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://asus13.msn.com/?pc=ASJB
SearchScopes: HKU\S-1-5-21-2592302959-4100768495-3643388182-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-2592302959-4100768495-3643388182-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-2592302959-4100768495-3643388182-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-2592302959-4100768495-3643388182-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-2592302959-4100768495-3643388182-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-2592302959-4100768495-3643388182-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2018-01-19] (Microsoft Corporation)
BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL [2018-01-19] (Microsoft Corporation)
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll [2018-01-19] (Microsoft Corporation)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_161\bin\ssv.dll [2018-01-22] (Oracle Corporation)
BHO-x32: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\Office16\GROOVEEX.DLL [2018-01-19] (Microsoft Corporation)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_161\bin\jp2ssv.dll [2018-01-22] (Oracle Corporation)
DPF: HKLM-x32 {166B1BCA-3F9C-11CF-8075-444553540000} hxxps://fpdownload.macromedia.com/pub/shockwave/cabs/director/sw.cab
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-01-19] (Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-01-19] (Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-01-19] (Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-01-19] (Microsoft Corporation)
 
FireFox:
========
FF ProfilePath: C:\Users\Jack\AppData\Roaming\TomTom\HOME\Profiles\6wrq57wk.default [2018-01-22]
FF Extension: (Map status indicator) - C:\Program Files (x86)\TomTom HOME 2\xul\extensions\MapShare-status@tomtom.com [2018-01-22] [Legacy] [not signed]
FF ProfilePath: C:\Users\Jack\AppData\Roaming\Mozilla\Firefox\Profiles\gw8bwnqt.default [2018-01-27]
FF Homepage: Mozilla\Firefox\Profiles\gw8bwnqt.default -> about:blank
FF Extension: (AdBlock) - C:\Users\Jack\AppData\Roaming\Mozilla\Firefox\Profiles\gw8bwnqt.default\Extensions\jid1-NIfFY2CA8fy1tg@jetpack.xpi [2017-11-16]
FF Extension: (Adblock Plus) - C:\Users\Jack\AppData\Roaming\Mozilla\Firefox\Profiles\gw8bwnqt.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2017-12-18]
FF HKLM-x32\...\Firefox\Extensions: [quickprint@hp.com] - C:\Program Files (x86)\Hewlett-Packard\SmartPrint\QPExtension
FF Extension: (SmartPrintButton) - C:\Program Files (x86)\Hewlett-Packard\SmartPrint\QPExtension [2011-01-26] [Legacy] [not signed]
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_28_0_0_137.dll [2018-01-15] ()
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_28_0_0_137.dll [2018-01-15] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\WINDOWS\SysWOW64\Adobe\Director\np32dsw_1221171.dll [2015-10-19] (Adobe Systems, Inc.)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-10-23] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-10-23] (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.161.2 -> C:\Program Files (x86)\Java\jre1.8.0_161\bin\dtplugin\npDeployJava1.dll [2018-01-22] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.161.2 -> C:\Program Files (x86)\Java\jre1.8.0_161\bin\plugin2\npjp2.dll [2018-01-22] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2018-01-19] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2018-01-19] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-14] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-14] (Google Inc.)
FF Plugin-x32: @ums.geocomply.com/GeoComply Update;version=3 -> C:\Program Files (x86)\GeoComply\Update\2.1.2.7\npGoogleUpdate3.dll [2015-10-19] (GeoComply Inc.)
FF Plugin-x32: @ums.geocomply.com/GeoComply Update;version=9 -> C:\Program Files (x86)\GeoComply\Update\2.1.2.7\npGoogleUpdate3.dll [2015-10-19] (GeoComply Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.6 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll [2013-08-05] ()
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2017-11-01] (Adobe Systems Inc.)
FF Plugin-x32: geocomply.com/player_location_check -> C:\Program Files (x86)\GeoComply\PlayerLocationCheck\Application\npapi\npplayer_location_check.dll [2017-07-10] (GeoComply)
FF Plugin HKU\S-1-5-21-2592302959-4100768495-3643388182-1001: @tools.google.com/Google Update;version=3 -> C:\Users\Jack\AppData\Local\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-14] (Google Inc.)
FF Plugin HKU\S-1-5-21-2592302959-4100768495-3643388182-1001: @tools.google.com/Google Update;version=9 -> C:\Users\Jack\AppData\Local\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-14] (Google Inc.)
FF Plugin HKU\S-1-5-21-2592302959-4100768495-3643388182-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0: @tools.google.com/Google Update;version=3 -> C:\Users\Jack\AppData\Local\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-14] (Google Inc.)
FF Plugin HKU\S-1-5-21-2592302959-4100768495-3643388182-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0: @tools.google.com/Google Update;version=9 -> C:\Users\Jack\AppData\Local\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-14] (Google Inc.)
 
Chrome: 
=======
CHR DefaultProfile: Default
CHR DefaultSearchURL: Default -> hxxps://search.yahoo.com/search?p={searchTerms}&fr=yset_chr_syc_oracle&type=default
CHR DefaultSearchKeyword: Default -> Yahoo
CHR DefaultSuggestURL: Default -> hxxps://search.yahoo.com/sugg/ie?output=fxjson&command={searchTerms}&nResults=10
CHR Profile: C:\Users\Jack\AppData\Local\Google\Chrome\User Data\Default [2018-01-29]
CHR Extension: (Slides) - C:\Users\Jack\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-01-29]
CHR Extension: (Docs) - C:\Users\Jack\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2018-01-29]
CHR Extension: (Google Drive) - C:\Users\Jack\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-01-29]
CHR Extension: (YouTube) - C:\Users\Jack\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-01-29]
CHR Extension: (Yahoo Partner) - C:\Users\Jack\AppData\Local\Google\Chrome\User Data\Default\Extensions\commhkacjheiacaopdonmodahaoadoln [2018-01-29]
CHR Extension: (Sheets) - C:\Users\Jack\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-01-29]
CHR Extension: (Google Docs Offline) - C:\Users\Jack\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-01-29]
CHR Extension: (Application Launcher for Drive (by Google)) - C:\Users\Jack\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2018-01-29]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Jack\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-01-29]
CHR Extension: (Gmail) - C:\Users\Jack\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2018-01-29]
CHR Extension: (Chrome Media Router) - C:\Users\Jack\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-01-29]
CHR Profile: C:\Users\Jack\AppData\Local\Google\Chrome\User Data\Profile 1 [2018-01-27]
CHR Extension: (Google Slides) - C:\Users\Jack\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-10-15]
CHR Extension: (Google Docs) - C:\Users\Jack\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2015-10-15]
CHR Extension: (Google Drive) - C:\Users\Jack\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-15]
CHR Extension: (YouTube) - C:\Users\Jack\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-10-15]
CHR Extension: (Google Search) - C:\Users\Jack\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-15]
CHR Extension: (Google Sheets) - C:\Users\Jack\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-10-15]
CHR Extension: (Google Docs Offline) - C:\Users\Jack\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-10-15]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Jack\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-10-15]
CHR Extension: (Gmail) - C:\Users\Jack\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-10-15]
CHR Profile: C:\Users\Jack\AppData\Local\Google\Chrome\User Data\System Profile [2018-01-27]
CHR HKU\S-1-5-21-2592302959-4100768495-3643388182-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-2592302959-4100768495-3643388182-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [commhkacjheiacaopdonmodahaoadoln] - hxxps://clients2.google.com/service/update2/crx
 
==================== Services (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
HKLM\SYSTEM\CurrentControlSet\Services\ntveglwx <==== ATTENTION (Rootkit!)
 
R2 AdAppMgrSvc; C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AdAppMgrSvc.exe [1353208 2017-06-15] (Autodesk Inc.)
S3 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2017-10-11] (Apple Inc.)
R2 chromoting; C:\Program Files (x86)\Google\Chrome Remote Desktop\63.0.3239.32\remoting_host.exe [71512 2017-11-02] (Google Inc.)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [7780528 2018-01-15] (Microsoft Corporation)
R2 DptfParticipantProcessorService; C:\WINDOWS\system32\DptfParticipantProcessorService.exe [117704 2013-10-17] (Intel Corporation)
R2 DptfPolicyConfigTDPService; C:\WINDOWS\system32\DptfPolicyConfigTDPService.exe [116680 2013-10-17] (Intel Corporation)
R2 DptfPolicyCriticalService; C:\WINDOWS\system32\DptfPolicyCriticalService.exe [148160 2013-10-17] (Intel Corporation)
R2 DptfPolicyLpmService; C:\WINDOWS\system32\DptfPolicyLpmService.exe [126952 2013-10-17] (Intel Corporation)
R2 GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [227904 2014-04-24] (WildTangent)
S2 HP LaserJet Service; C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe [136704 2009-06-24] (HP) [File not signed]
R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [332144 2017-11-21] (HP Inc.)
S2 HPTouchpointAnalyticsService; C:\Program Files\HP\HP Touchpoint Analytics Client\TouchpointAnalyticsClientService.exe [332216 2017-11-26] (HP Inc.)
R2 igfxCUIService2.0.0.0; C:\WINDOWS\system32\igfxCUIService.exe [373728 2016-11-30] (Intel Corporation)
S3 Intel® Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [827392 2013-09-02] (Intel® Corporation) [File not signed]
R2 Intel® ME Service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe [131544 2013-10-23] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe [169432 2013-10-23] (Intel Corporation)
R2 MacriumService; C:\Program Files\Macrium\Common\MacriumService.exe [3878728 2017-02-25] (Paramount Software UK Ltd)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6058960 2017-08-21] (Malwarebytes)
S3 NETGEARGenieDaemon; C:\Program Files (x86)\NETGEAR Genie\bin\NETGEARGenieDaemon64.exe [233456 2017-07-04] (NETGEAR)
R2 SEVPNCLIENT; C:\Program Files\SoftEther VPN Client\vpnclient_x64.exe [5248456 2017-06-29] (SoftEther VPN Project at University of Tsukuba, Japan.)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [10945776 2017-12-15] (TeamViewer GmbH)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.12.17007.18011-0\NisSrv.exe [356168 2018-01-19] (Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.12.17007.18011-0\MsMpEng.exe [105792 2018-01-19] (Microsoft Corporation)
R2 ZAtheros Bt and Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [323584 2014-06-17] (Atheros) [File not signed]
 
===================== Drivers (Whitelisted) ======================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R3 1267B2ED; C:\WINDOWS\system32\drivers\1267B2ED.sys [255928 2018-01-29] (Malwarebytes)
R3 AsusTP; C:\WINDOWS\System32\drivers\AsusTP.sys [128024 2017-03-09] (ASUS Corporation)
S3 DFX11_1; C:\WINDOWS\system32\drivers\dfx11_1x64.sys [28008 2012-12-13] (Windows ® Win 7 DDK provider)
S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus.sys [131712 2016-09-05] (Samsung Electronics Co., Ltd.)
R3 DptfDevDram; C:\WINDOWS\system32\DRIVERS\DptfDevDram.sys [145640 2013-10-17] (Intel Corporation)
R3 DptfDevPch; C:\WINDOWS\system32\DRIVERS\DptfDevPch.sys [116752 2013-10-17] (Intel Corporation)
R3 DptfDevProc; C:\WINDOWS\system32\DRIVERS\DptfDevProc.sys [289744 2013-10-17] (Intel Corporation)
R3 DptfManager; C:\WINDOWS\system32\DRIVERS\DptfManager.sys [494296 2013-10-17] (Intel Corporation)
R3 kbfiltr; C:\WINDOWS\System32\drivers\kbfiltr.sys [17280 2012-08-05] ( )
R3 mbamchameleon; C:\WINDOWS\system32\drivers\mbamchameleon.sys [192952 2018-01-29] (Malwarebytes)
R0 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [252232 2018-01-29] (Malwarebytes)
R3 MEIx64; C:\WINDOWS\system32\DRIVERS\TeeDriverx64.sys [99288 2013-10-23] (Intel Corporation)
S0 mfeelamk; C:\WINDOWS\System32\drivers\mfeelamk.sys [82072 2015-08-10] (McAfee, Inc.)
S3 mvusbews; C:\WINDOWS\System32\Drivers\mvusbews.sys [20480 2012-09-26] (Marvell Semiconductor, Inc.)
R3 Neo_VPN; C:\WINDOWS\System32\drivers\Neo6_x64_VPN.sys [38216 2017-06-29] (SoftEther Corporation)
R2 NPF; C:\WINDOWS\system32\drivers\npf.sys [35344 2017-12-27] (CACE Technologies, Inc.)
U0 Partizan; C:\Windows\SysWOW64\drivers\Partizan.sys [40304 2018-01-27] (Greatis Software)
R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [895256 2015-07-07] (Realtek )
R3 RTSUER; C:\WINDOWS\system32\Drivers\RtsUer.sys [420832 2017-04-06] (Realsil Semiconductor Corporation)
S3 RvNetMP60; C:\WINDOWS\System32\drivers\RvNetMP60.sys [72112 2017-07-21] (Famatech Corp.)
R1 SeLow; C:\WINDOWS\system32\DRIVERS\SeLow_x64.sys [51024 2017-06-29] (SoftEther Corporation)
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [165504 2016-09-05] (Samsung Electronics Co., Ltd.)
R1 UimBus; C:\WINDOWS\System32\drivers\UimBus.sys [102664 2014-10-29] ()
R1 Uim_DEVIM; C:\WINDOWS\System32\drivers\uim_devim.sys [25992 2014-10-29] ()
R1 Uim_IM; C:\WINDOWS\System32\drivers\uim_im.sys [700680 2014-10-29] ()
S3 WdBoot; C:\WINDOWS\system32\drivers\wd\WdBoot.sys [46072 2018-01-19] (Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\wd\WdFilter.sys [288848 2018-01-19] (Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [129616 2018-01-19] (Microsoft Corporation)
R3 ilorvy; system32\drivers\oruybe.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2018-01-29 20:11 - 2018-01-29 20:13 - 000033409 _____ C:\Users\Jack\Downloads\FRST.txt
2018-01-29 20:11 - 2018-01-29 20:11 - 000000000 ____D C:\FRST
2018-01-29 20:09 - 2018-01-29 20:09 - 002393088 _____ (Farbar) C:\Users\Jack\Downloads\FRST64.exe
2018-01-29 19:53 - 2018-01-29 19:53 - 036430896 _____ (Adlice Software ) C:\Users\Jack\Downloads\RogueKiller_setup.exe
2018-01-29 19:48 - 2018-01-29 19:48 - 000255928 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\1267B2ED.sys
2018-01-29 19:47 - 2018-01-29 19:50 - 000000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2018-01-29 19:46 - 2018-01-29 19:46 - 000000000 ____D C:\Users\Jack\Desktop\mbar
2018-01-29 19:44 - 2018-01-29 19:44 - 014178840 _____ (Malwarebytes Corp.) C:\Users\Jack\Downloads\mbar-1.10.3.1001.exe
2018-01-29 18:50 - 2018-01-29 18:50 - 000252232 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys
2018-01-28 11:58 - 2018-01-28 11:58 - 000142672 ____N C:\WINDOWS\system32\Drivers\vsslpsvy.sys
2018-01-27 23:10 - 2018-01-27 23:10 - 000040304 _____ (Greatis Software) C:\WINDOWS\SysWOW64\Drivers\Partizan.sys
2018-01-27 23:02 - 2018-01-29 18:33 - 000000254 _____ C:\WINDOWS\SysWOW64\PARTIZAN.TXT
2018-01-27 22:55 - 2018-01-27 23:21 - 000000000 ____D C:\@RestoreQuarantine
2018-01-27 19:35 - 2018-01-27 19:35 - 000000000 ____D C:\ProgramData\RegRun
2018-01-27 19:33 - 2018-01-29 18:41 - 000000000 ____D C:\Users\Jack\Documents\RegRun2
2018-01-27 19:33 - 2018-01-29 18:39 - 000000000 ____D C:\Users\Public\Documents\regruninfo
2018-01-27 19:33 - 2018-01-27 19:36 - 000000000 ____D C:\Program Files (x86)\UnHackMe
2018-01-27 19:33 - 2018-01-27 19:33 - 000003410 _____ C:\WINDOWS\System32\Tasks\UnHackMe Task Scheduler
2018-01-27 19:33 - 2018-01-27 19:33 - 000001082 _____ C:\Users\Jack\Desktop\UnHackMe.lnk
2018-01-27 19:33 - 2018-01-27 19:33 - 000000002 RSHOT C:\WINDOWS\winstart.bat
2018-01-27 19:33 - 2018-01-27 19:33 - 000000002 RSHOT C:\WINDOWS\SysWOW64\CONFIG.NT
2018-01-27 19:33 - 2018-01-27 19:33 - 000000002 RSHOT C:\WINDOWS\SysWOW64\AUTOEXEC.NT
2018-01-27 19:33 - 2018-01-27 19:33 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UnHackMe
2018-01-27 19:33 - 2018-01-26 19:40 - 000001320 _____ C:\WINDOWS\system32\Drivers\etc\hosts.old
2018-01-27 19:33 - 2017-12-13 17:47 - 000014984 _____ (Greatis Software, LLC.) C:\WINDOWS\SysWOW64\Drivers\UnHackMeDrv.sys
2018-01-27 19:33 - 2015-12-28 11:32 - 000049968 _____ (Greatis Software) C:\WINDOWS\system32\partizan.exe
2018-01-27 18:42 - 2018-01-27 18:42 - 000007690 _____ C:\Users\Jack\Documents\cc_20180127_184201.reg
2018-01-27 18:33 - 2018-01-27 23:14 - 000000214 _____ C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job
2018-01-27 18:31 - 2018-01-27 19:10 - 000000000 ____D C:\WINDOWS\pss
2018-01-27 01:04 - 2018-01-27 01:04 - 000027358 _____ C:\Users\Jack\Documents\cc_20180127_010416.reg
2018-01-26 22:38 - 2018-01-26 22:38 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2018-01-26 22:09 - 2018-01-26 22:09 - 000000000 ____D C:\Program Files (x86)\QzeHcYPJTlaRogMtwuR
2018-01-26 22:09 - 2018-01-26 22:09 - 000000000 ____D C:\Program Files (x86)\CRzlyHUwXjzU2
2018-01-26 22:09 - 2018-01-26 22:09 - 000000000 ____D C:\Program Files (x86)\abmzSTWtfatSC
2018-01-26 22:08 - 2018-01-27 22:55 - 000000000 ____D C:\Disk
2018-01-26 22:08 - 2018-01-26 22:48 - 000624664 _____ C:\WINDOWS\system32\NETUTILS2016.del
2018-01-26 22:08 - 2018-01-26 22:08 - 000014040 _____ C:\WINDOWS\system32\Drivers\NETUTILS2016.del
2018-01-26 22:08 - 2018-01-26 22:08 - 000000000 ____D C:\WINDOWS\system32\sstmp
2018-01-26 22:08 - 2018-01-26 22:08 - 000000000 ____D C:\Windat
2018-01-26 22:08 - 2018-01-26 22:08 - 000000000 ____D C:\Users\Jack\AppData\Roaming\1n0acejoj3w
2018-01-26 22:08 - 2018-01-26 22:08 - 000000000 ____D C:\Program Files (x86)\ELYwNrqgcQUn
2018-01-26 22:07 - 2018-01-27 22:55 - 000000000 ____D C:\WINDOWS\SysWOW64\NVDIADISPLAY
2018-01-26 22:07 - 2018-01-26 22:09 - 000000000 ____D C:\Program Files (x86)\rPUXzMQWU
2018-01-26 22:07 - 2018-01-26 22:08 - 001377280 _____ C:\WINDOWS\WINDEFENDER.EXE.del
2018-01-26 22:07 - 2018-01-26 22:07 - 000000103 _____ C:\WINDOWS\SysWOW64\del.bat
2018-01-26 22:07 - 2018-01-26 22:07 - 000000000 _RSHD C:\RecoveryLog
2018-01-26 22:07 - 2018-01-26 22:07 - 000000000 ____D C:\Program Files (x86)\repository
2018-01-26 19:41 - 2018-01-27 23:17 - 000000000 ____D C:\WINDOWS\System32\Tasks\System
2018-01-26 19:38 - 2018-01-29 19:05 - 000000000 ____D C:\Users\Jack\AppData\Local\scitmvo
2018-01-26 19:34 - 2018-01-29 20:11 - 000000000 ____D C:\Users\Jack\AppData\Local\atmibgl
2018-01-26 19:34 - 2018-01-26 19:37 - 000000000 ____D C:\Users\Jack\AppData\Local\wimxehg
2018-01-26 19:33 - 2018-01-29 18:33 - 002888704 _____ (TOSHIBA CORPORATION) C:\WINDOWS\system32\vdhkexasvc.exe
2018-01-26 19:33 - 2018-01-26 19:33 - 000000000 ____D C:\WINDOWS\SysWOW64\dsektwl
2018-01-26 19:33 - 2018-01-26 19:33 - 000000000 ____D C:\WINDOWS\system32\dsektwl
2018-01-26 19:32 - 2018-01-26 19:32 - 000000020 _____ C:\WINDOWS\b17766592
2018-01-26 19:32 - 2018-01-26 19:32 - 000000000 ____D C:\Users\Jack\AppData\Roaming\et
2018-01-26 19:31 - 2018-01-26 19:31 - 000000000 ___HD C:\Program Files (x86)\ventilators
2018-01-26 19:31 - 2018-01-26 19:31 - 000000000 ____D C:\Program Files (x86)\uninterruptable
2018-01-26 19:30 - 2018-01-26 19:30 - 000000000 ___HD C:\Program Files (x86)\Mass
2018-01-26 19:19 - 2018-01-26 19:19 - 000860160 _____ C:\WINDOWS\efee4b7794bddd58ee45bcdb44294b82.dll
2018-01-26 19:16 - 2018-01-26 19:16 - 000000000 ____D C:\Users\Jack\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AnonymizerGadget
2018-01-26 18:45 - 2018-01-26 18:45 - 000000000 ____D C:\Users\Jack\AppData\Local\DFX
2018-01-26 18:25 - 2018-01-26 18:25 - 000000000 ____D C:\Users\WDAGUtilityAccount\AppData\Roaming\vlc
2018-01-26 18:25 - 2018-01-26 18:25 - 000000000 ____D C:\Users\WDAGUtilityAccount
2018-01-26 18:25 - 2018-01-26 18:25 - 000000000 ____D C:\Users\steph\AppData\Roaming\vlc
2018-01-26 18:25 - 2018-01-26 18:25 - 000000000 ____D C:\Users\HomeGroupUser$\AppData\Roaming\vlc
2018-01-26 18:25 - 2018-01-26 18:25 - 000000000 ____D C:\Users\HomeGroupUser$
2018-01-26 18:25 - 2018-01-26 18:25 - 000000000 ____D C:\Users\Guest\AppData\Roaming\vlc
2018-01-26 18:25 - 2018-01-26 18:25 - 000000000 ____D C:\Users\Guest
2018-01-26 18:25 - 2018-01-26 18:25 - 000000000 ____D C:\Users\DefaultAccount\AppData\Roaming\vlc
2018-01-26 18:25 - 2018-01-26 18:25 - 000000000 ____D C:\Users\DefaultAccount
2018-01-26 18:25 - 2018-01-26 18:25 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\vlc
2018-01-26 18:25 - 2018-01-26 18:25 - 000000000 ____D C:\Users\Administrator
2018-01-26 17:58 - 2018-01-26 17:58 - 000011264 _____ C:\Users\Jack\AppData\Local\knudsen.exe
2018-01-26 17:58 - 2018-01-26 17:58 - 000010752 _____ C:\WINDOWS\bingley.exe
2018-01-26 17:58 - 2018-01-26 17:58 - 000010752 _____ C:\Users\Jack\AppData\Local\gunny.exe
2018-01-26 06:26 - 2018-01-26 06:26 - 000710656 _____ C:\WINDOWS\6a911afd6370c5dffeabbc69535591cc.exe
2018-01-26 06:26 - 2018-01-26 06:26 - 000035754 _____ C:\WINDOWS\uninstaller.dat
2018-01-26 06:26 - 2018-01-26 06:26 - 000014040 _____ C:\WINDOWS\system32\Drivers\194b204a839f28feaade11c964338f7d.sys
2018-01-24 15:22 - 2018-01-26 10:20 - 000000189 _____ C:\Users\Jack\Desktop\Lords.txt
2018-01-23 11:45 - 2018-01-23 11:45 - 000000000 ____D C:\ProgramData\Wondershare
2018-01-23 11:35 - 2017-10-19 10:17 - 000271360 _____ (Wondershare Software) C:\WINDOWS\system32\WSPDFelementMonitor.dll
2018-01-23 11:34 - 2018-01-23 11:34 - 000000000 ____D C:\Users\Jack\AppData\Local\Wondershare
2018-01-23 11:31 - 2018-01-23 12:35 - 000000000 ____D C:\Users\Jack\AppData\Roaming\Wondershare
2018-01-23 11:31 - 2018-01-23 11:31 - 000000000 ____D C:\ProgramData\PDFelement 6 Pro
2018-01-23 11:31 - 2018-01-23 11:31 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wondershare
2018-01-23 11:31 - 2018-01-23 11:31 - 000000000 ____D C:\Program Files (x86)\Wondershare
2018-01-23 11:30 - 2018-01-23 11:35 - 000000000 ____D C:\Users\Public\Documents\Wondershare
2018-01-23 11:06 - 2018-01-23 11:06 - 000166960 _____ C:\Users\Jack\Desktop\bookbag.pdf
2018-01-22 22:08 - 2018-01-22 22:09 - 000000000 ____D C:\Users\Jack\Desktop\2017 Tax
2018-01-22 20:03 - 2018-01-22 20:03 - 000193220 _____ C:\Users\Jack\Desktop\Un Emp.pdf
2018-01-22 11:50 - 2018-01-22 11:50 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TomTom
2018-01-22 11:42 - 2018-01-22 11:53 - 000000000 ____D C:\Users\Jack\Documents\Outlook Files
2018-01-21 17:57 - 2018-01-21 17:57 - 000000000 ____D C:\Users\steph\AppData\Local\EZ CD Audio Converter
2018-01-19 17:23 - 2018-01-19 17:23 - 000000824 _____ C:\Users\Jack\Documents\cc_20180119_172318.reg
2018-01-18 23:14 - 2018-01-18 23:14 - 000007658 _____ C:\Users\Jack\Documents\cc_20180118_231433.reg
2018-01-16 18:47 - 2018-01-16 18:47 - 000006628 _____ C:\Users\steph\Downloads\Martinez S.pdf
2018-01-10 11:05 - 2018-01-22 11:41 - 000000000 ____D C:\Users\Jack\Desktop\New Expense Reports
2018-01-07 13:23 - 2018-01-07 13:25 - 000000000 ____D C:\Users\Jack\Desktop\4Sale
2018-01-06 20:29 - 2018-01-06 20:29 - 000000594 _____ C:\Users\Jack\Documents\cc_20180106_202904.reg
2018-01-05 14:35 - 2018-01-05 14:35 - 000005408 _____ C:\Users\Jack\Documents\cc_20180105_143520.reg
2018-01-04 21:37 - 2018-01-01 06:25 - 000344576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgeIso.dll
2018-01-04 21:37 - 2018-01-01 06:24 - 000202240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxAllUserStore.dll
2018-01-04 21:37 - 2018-01-01 06:20 - 018917888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2018-01-04 21:37 - 2018-01-01 06:19 - 000369152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msIso.dll
2018-01-04 21:37 - 2018-01-01 06:17 - 000559104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll
2018-01-04 21:37 - 2018-01-01 06:16 - 000463360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2018-01-04 21:36 - 2018-01-01 12:15 - 000956416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Spectrum.exe
2018-01-04 21:36 - 2018-01-01 07:51 - 001414784 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2018-01-04 21:36 - 2018-01-01 07:51 - 001209240 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2018-01-04 21:36 - 2018-01-01 07:51 - 001055128 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2018-01-04 21:36 - 2018-01-01 07:51 - 000059800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bam.sys
2018-01-04 21:36 - 2018-01-01 07:50 - 005905752 _____ (Microsoft Corporation) C:\WINDOWS\system32\StartTileData.dll
2018-01-04 21:36 - 2018-01-01 07:50 - 000780464 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2018-01-04 21:36 - 2018-01-01 07:49 - 008605080 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2018-01-04 21:36 - 2018-01-01 07:49 - 000319352 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64.dll
2018-01-04 21:36 - 2018-01-01 07:48 - 007831760 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d10warp.dll
2018-01-04 21:36 - 2018-01-01 07:48 - 001954048 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2018-01-04 21:36 - 2018-01-01 07:47 - 000082840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\volmgr.sys
2018-01-04 21:36 - 2018-01-01 07:46 - 002709704 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2018-01-04 21:36 - 2018-01-01 07:46 - 000471960 _____ (Microsoft Corporation) C:\WINDOWS\system32\hal.dll
2018-01-04 21:36 - 2018-01-01 07:45 - 002395032 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
2018-01-04 21:36 - 2018-01-01 07:45 - 001277848 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys
2018-01-04 21:36 - 2018-01-01 07:45 - 000398744 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fltMgr.sys
2018-01-04 21:36 - 2018-01-01 07:42 - 000571288 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\spaceport.sys
2018-01-04 21:36 - 2018-01-01 07:42 - 000184984 _____ (Microsoft Corporation) C:\WINDOWS\system32\sspicli.dll
2018-01-04 21:36 - 2018-01-01 07:41 - 007676296 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2018-01-04 21:36 - 2018-01-01 07:41 - 000559512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storport.sys
2018-01-04 21:36 - 2018-01-01 07:40 - 001206680 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2018-01-04 21:36 - 2018-01-01 07:39 - 000902416 _____ (Microsoft Corporation) C:\WINDOWS\system32\winhttp.dll
2018-01-04 21:36 - 2018-01-01 07:39 - 000677784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2018-01-04 21:36 - 2018-01-01 07:39 - 000362904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pci.sys
2018-01-04 21:36 - 2018-01-01 07:39 - 000129432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hvsocket.sys
2018-01-04 21:36 - 2018-01-01 07:38 - 003904808 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2018-01-04 21:36 - 2018-01-01 07:38 - 000519152 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthService.exe
2018-01-04 21:36 - 2018-01-01 07:37 - 001426664 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
2018-01-04 21:36 - 2018-01-01 07:36 - 000374032 _____ (Microsoft Corporation) C:\WINDOWS\system32\vac.exe
2018-01-04 21:36 - 2018-01-01 07:36 - 000166296 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\partmgr.sys
2018-01-04 21:36 - 2018-01-01 07:35 - 001170008 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2018-01-04 21:36 - 2018-01-01 07:34 - 007385088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2018-01-04 21:36 - 2018-01-01 07:33 - 000603920 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
2018-01-04 21:36 - 2018-01-01 07:32 - 004481240 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2018-01-04 21:36 - 2018-01-01 07:27 - 000713624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vhdmp.sys
2018-01-04 21:36 - 2018-01-01 07:26 - 000428952 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdbss.sys
2018-01-04 21:36 - 2018-01-01 07:25 - 000615768 _____ (Microsoft Corporation) C:\WINDOWS\system32\services.exe
2018-01-04 21:36 - 2018-01-01 07:25 - 000147864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wcifs.sys
2018-01-04 21:36 - 2018-01-01 07:23 - 021352144 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2018-01-04 21:36 - 2018-01-01 07:03 - 000650328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2018-01-04 21:36 - 2018-01-01 07:03 - 000123512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sspicli.dll
2018-01-04 21:36 - 2018-01-01 06:53 - 001615712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2018-01-04 21:36 - 2018-01-01 06:46 - 003485392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2018-01-04 21:36 - 2018-01-01 06:45 - 006092152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2018-01-04 21:36 - 2018-01-01 06:45 - 005615968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d10warp.dll
2018-01-04 21:36 - 2018-01-01 06:45 - 002192624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2018-01-04 21:36 - 2018-01-01 06:43 - 020286120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2018-01-04 21:36 - 2018-01-01 06:42 - 006479552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2018-01-04 21:36 - 2018-01-01 06:42 - 004644912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2018-01-04 21:36 - 2018-01-01 06:42 - 001246432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioEng.dll
2018-01-04 21:36 - 2018-01-01 06:42 - 000982528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
2018-01-04 21:36 - 2018-01-01 06:37 - 025247232 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2018-01-04 21:36 - 2018-01-01 06:34 - 000703568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winhttp.dll
2018-01-04 21:36 - 2018-01-01 06:25 - 002905600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2018-01-04 21:36 - 2018-01-01 06:25 - 001008640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallService.dll
2018-01-04 21:36 - 2018-01-01 06:25 - 000097792 _____ C:\WINDOWS\system32\runexehelper.exe
2018-01-04 21:36 - 2018-01-01 06:24 - 003668480 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2018-01-04 21:36 - 2018-01-01 06:23 - 001313792 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallService.dll
2018-01-04 21:36 - 2018-01-01 06:23 - 000536576 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgeIso.dll
2018-01-04 21:36 - 2018-01-01 06:23 - 000250368 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxAllUserStore.dll
2018-01-04 21:36 - 2018-01-01 06:21 - 000192512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\netvsc.sys
2018-01-04 21:36 - 2018-01-01 06:20 - 019337216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2018-01-04 21:36 - 2018-01-01 06:20 - 000204288 _____ (Microsoft Corporation) C:\WINDOWS\system32\provisioningcsp.dll
2018-01-04 21:36 - 2018-01-01 06:19 - 008014848 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2018-01-04 21:36 - 2018-01-01 06:19 - 000461312 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansec.dll
2018-01-04 21:36 - 2018-01-01 06:19 - 000450048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TileDataRepository.dll
2018-01-04 21:36 - 2018-01-01 06:19 - 000365568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll
2018-01-04 21:36 - 2018-01-01 06:19 - 000334848 _____ (Microsoft Corporation) C:\WINDOWS\system32\dusmsvc.dll
2018-01-04 21:36 - 2018-01-01 06:19 - 000073216 _____ (Microsoft Corporation) C:\WINDOWS\system32\provtool.exe
2018-01-04 21:36 - 2018-01-01 06:18 - 000432640 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll
2018-01-04 21:36 - 2018-01-01 06:18 - 000431616 _____ (Microsoft Corporation) C:\WINDOWS\system32\msIso.dll
2018-01-04 21:36 - 2018-01-01 06:18 - 000427008 _____ (Microsoft Corporation) C:\WINDOWS\system32\provhandlers.dll
2018-01-04 21:36 - 2018-01-01 06:18 - 000374784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FirewallAPI.dll
2018-01-04 21:36 - 2018-01-01 06:18 - 000261632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll
2018-01-04 21:36 - 2018-01-01 06:17 - 011923968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2018-01-04 21:36 - 2018-01-01 06:17 - 006564864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
2018-01-04 21:36 - 2018-01-01 06:17 - 000708096 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll
2018-01-04 21:36 - 2018-01-01 06:17 - 000568832 _____ (Microsoft Corporation) C:\WINDOWS\system32\TileDataRepository.dll
2018-01-04 21:36 - 2018-01-01 06:17 - 000542208 _____ (Microsoft Corporation) C:\WINDOWS\system32\FirewallAPI.dll
2018-01-04 21:36 - 2018-01-01 06:16 - 005833216 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbgeng.dll
2018-01-04 21:36 - 2018-01-01 06:16 - 003676672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2018-01-04 21:36 - 2018-01-01 06:16 - 000815616 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll
2018-01-04 21:36 - 2018-01-01 06:16 - 000812544 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll
2018-01-04 21:36 - 2018-01-01 06:16 - 000720896 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll
2018-01-04 21:36 - 2018-01-01 06:16 - 000664576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2018-01-04 21:36 - 2018-01-01 06:16 - 000594944 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2018-01-04 21:36 - 2018-01-01 06:15 - 012687872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll
2018-01-04 21:36 - 2018-01-01 06:15 - 006029312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2018-01-04 21:36 - 2018-01-01 06:15 - 000588800 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll
2018-01-04 21:36 - 2018-01-01 06:14 - 023655936 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2018-01-04 21:36 - 2018-01-01 06:14 - 002465280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2018-01-04 21:36 - 2018-01-01 06:14 - 001495040 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
2018-01-04 21:36 - 2018-01-01 06:13 - 013657600 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll
2018-01-04 21:36 - 2018-01-01 06:13 - 012830208 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2018-01-04 21:36 - 2018-01-01 06:13 - 003121664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Bluetooth.Profiles.Gatt.dll
2018-01-04 21:36 - 2018-01-01 06:13 - 002869760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2018-01-04 21:36 - 2018-01-01 06:13 - 001559552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2018-01-04 21:36 - 2018-01-01 06:12 - 002633216 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2018-01-04 21:36 - 2018-01-01 06:12 - 002208768 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2018-01-04 21:36 - 2018-01-01 06:12 - 001547776 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2018-01-04 21:36 - 2018-01-01 06:12 - 001424896 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
2018-01-04 21:36 - 2018-01-01 06:11 - 008108544 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2018-01-04 21:36 - 2018-01-01 06:11 - 004748288 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2018-01-04 21:36 - 2018-01-01 06:11 - 003334144 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2018-01-04 21:36 - 2018-01-01 06:11 - 003165696 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2018-01-04 21:36 - 2018-01-01 06:11 - 002859520 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2018-01-04 21:36 - 2018-01-01 06:11 - 001822208 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2018-01-04 21:36 - 2018-01-01 06:11 - 001231872 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll
2018-01-04 21:36 - 2018-01-01 06:11 - 000880640 _____ (Microsoft Corporation) C:\WINDOWS\system32\schedsvc.dll
2018-01-04 21:36 - 2018-01-01 06:11 - 000812032 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2018-01-04 21:36 - 2018-01-01 06:09 - 001487872 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2018-01-04 21:36 - 2018-01-01 06:09 - 000925184 _____ (Microsoft Corporation) C:\WINDOWS\system32\MPSSVC.dll
2018-01-04 21:36 - 2018-01-01 06:08 - 000726016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv2.sys
2018-01-04 21:36 - 2018-01-01 06:08 - 000685056 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2018-01-04 21:36 - 2018-01-01 06:08 - 000424448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv.sys
2018-01-04 21:36 - 2018-01-01 06:05 - 002510848 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngine.dll
2018-01-04 21:36 - 2018-01-01 06:05 - 001160704 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll
2018-01-04 21:35 - 2018-01-01 07:54 - 000924648 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2018-01-04 21:35 - 2018-01-01 07:53 - 001090984 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2018-01-04 21:35 - 2018-01-01 07:52 - 000066712 _____ (Microsoft Corporation) C:\WINDOWS\system32\iumcrypt.dll
2018-01-04 21:35 - 2018-01-01 07:51 - 000191816 _____ (Microsoft Corporation) C:\WINDOWS\system32\skci.dll
2018-01-04 21:35 - 2018-01-01 07:50 - 000479912 _____ (Microsoft Corporation) C:\WINDOWS\system32\ucrtbase_enclave.dll
2018-01-04 21:35 - 2018-01-01 07:50 - 000077208 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.dll
2018-01-04 21:35 - 2018-01-01 07:49 - 000599448 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe
2018-01-04 21:35 - 2018-01-01 07:49 - 000292376 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscapi.dll
2018-01-04 21:35 - 2018-01-01 07:48 - 000382360 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
2018-01-04 21:35 - 2018-01-01 07:47 - 000649304 _____ (Microsoft Corporation) C:\WINDOWS\system32\advapi32.dll
2018-01-04 21:35 - 2018-01-01 07:46 - 000898216 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll
2018-01-04 21:35 - 2018-01-01 07:46 - 000733592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\acpi.sys
2018-01-04 21:35 - 2018-01-01 07:43 - 001173576 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcrt4.dll
2018-01-04 21:35 - 2018-01-01 07:43 - 000367336 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Storage.ApplicationData.dll
2018-01-04 21:35 - 2018-01-01 07:43 - 000062872 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fsdepends.sys
2018-01-04 21:35 - 2018-01-01 07:42 - 001029016 _____ (Microsoft Corporation) C:\WINDOWS\system32\efscore.dll
2018-01-04 21:35 - 2018-01-01 07:42 - 000494488 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcasvc.dll
2018-01-04 21:35 - 2018-01-01 07:42 - 000109976 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vmbus.sys
2018-01-04 21:35 - 2018-01-01 07:41 - 000549552 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWanAPI.dll
2018-01-04 21:35 - 2018-01-01 07:39 - 000508264 _____ (Microsoft Corporation) C:\WINDOWS\system32\systemreset.exe
2018-01-04 21:35 - 2018-01-01 07:38 - 000727448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fvevol.sys
2018-01-04 21:35 - 2018-01-01 07:38 - 000103320 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\stornvme.sys
2018-01-04 21:35 - 2018-01-01 07:38 - 000038808 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Diskdump.sys
2018-01-04 21:35 - 2018-01-01 07:37 - 000461720 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifitask.exe
2018-01-04 21:35 - 2018-01-01 07:36 - 000413888 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll
2018-01-04 21:35 - 2018-01-01 07:36 - 000113560 _____ (Microsoft Corporation) C:\WINDOWS\system32\icfupgd.dll
2018-01-04 21:35 - 2018-01-01 07:36 - 000057752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\netbios.sys
2018-01-04 21:35 - 2018-01-01 07:35 - 000075160 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthProxyStub.dll
2018-01-04 21:35 - 2018-01-01 07:34 - 001336344 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll
2018-01-04 21:35 - 2018-01-01 07:34 - 000260896 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
2018-01-04 21:35 - 2018-01-01 07:34 - 000087384 _____ (Microsoft Corporation) C:\WINDOWS\system32\remoteaudioendpoint.dll
2018-01-04 21:35 - 2018-01-01 07:33 - 002773400 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2018-01-04 21:35 - 2018-01-01 07:32 - 000617304 _____ (Microsoft Corporation) C:\WINDOWS\system32\TextInputFramework.dll
2018-01-04 21:35 - 2018-01-01 07:27 - 000163736 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wfplwfs.sys
2018-01-04 21:35 - 2018-01-01 07:26 - 000081304 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vmbkmcl.sys
2018-01-04 21:35 - 2018-01-01 07:21 - 001103768 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\http.sys
2018-01-04 21:35 - 2018-01-01 07:21 - 000614296 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\afd.sys
2018-01-04 21:35 - 2018-01-01 07:06 - 000311192 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
2018-01-04 21:35 - 2018-01-01 07:03 - 000777904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rpcrt4.dll
2018-01-04 21:35 - 2018-01-01 07:03 - 000566664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll
2018-01-04 21:35 - 2018-01-01 06:49 - 000481464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\advapi32.dll
2018-01-04 21:35 - 2018-01-01 06:49 - 000258808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscapi.dll
2018-01-04 21:35 - 2018-01-01 06:46 - 000289816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Storage.ApplicationData.dll
2018-01-04 21:35 - 2018-01-01 06:45 - 000450928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWanAPI.dll
2018-01-04 21:35 - 2018-01-01 06:42 - 001003152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll
2018-01-04 21:35 - 2018-01-01 06:42 - 000386424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AUDIOKSE.dll
2018-01-04 21:35 - 2018-01-01 06:42 - 000129184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfps.dll
2018-01-04 21:35 - 2018-01-01 06:42 - 000074992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\remoteaudioendpoint.dll
2018-01-04 21:35 - 2018-01-01 06:25 - 000475648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieui.dll
2018-01-04 21:35 - 2018-01-01 06:24 - 000240640 _____ (Microsoft Corporation) C:\WINDOWS\system32\AboutSettingsHandlers.dll
2018-01-04 21:35 - 2018-01-01 06:24 - 000096256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontsub.dll
2018-01-04 21:35 - 2018-01-01 06:24 - 000038912 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
2018-01-04 21:35 - 2018-01-01 06:23 - 000561152 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieui.dll
2018-01-04 21:35 - 2018-01-01 06:23 - 000385024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cldflt.sys
2018-01-04 21:35 - 2018-01-01 06:23 - 000232960 _____ (Microsoft Corporation) C:\WINDOWS\system32\convertvhd.exe
2018-01-04 21:35 - 2018-01-01 06:23 - 000121344 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontsub.dll
2018-01-04 21:35 - 2018-01-01 06:23 - 000080384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vmbkmclr.sys
2018-01-04 21:35 - 2018-01-01 06:23 - 000047104 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2018-01-04 21:35 - 2018-01-01 06:22 - 000031744 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Management.Provisioning.ProxyStub.dll
2018-01-04 21:35 - 2018-01-01 06:22 - 000025600 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Dumpstorport.sys
2018-01-04 21:35 - 2018-01-01 06:22 - 000017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\VmApplicationHealthMonitorProxy.dll
2018-01-04 21:35 - 2018-01-01 06:21 - 000268288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll
2018-01-04 21:35 - 2018-01-01 06:21 - 000233984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppLockerCSP.dll
2018-01-04 21:35 - 2018-01-01 06:21 - 000133632 _____ (Microsoft Corporation) C:\WINDOWS\system32\wificonnapi.dll
2018-01-04 21:35 - 2018-01-01 06:21 - 000097280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WcnApi.dll
2018-01-04 21:35 - 2018-01-01 06:21 - 000097280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\raspptp.sys
2018-01-04 21:35 - 2018-01-01 06:21 - 000080896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wanarp.sys
2018-01-04 21:35 - 2018-01-01 06:21 - 000062976 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndproxy.sys
2018-01-04 21:35 - 2018-01-01 06:20 - 000524288 _____ (Microsoft Corporation) C:\WINDOWS\system32\daxexec.dll
2018-01-04 21:35 - 2018-01-01 06:20 - 000459776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webplatstorageserver.dll
2018-01-04 21:35 - 2018-01-01 06:20 - 000397824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtmsft.dll
2018-01-04 21:35 - 2018-01-01 06:20 - 000225792 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\winnat.sys
2018-01-04 21:35 - 2018-01-01 06:20 - 000215552 _____ (Microsoft Corporation) C:\WINDOWS\system32\fwpolicyiomgr.dll
2018-01-04 21:35 - 2018-01-01 06:20 - 000212992 _____ (Microsoft Corporation) C:\WINDOWS\system32\container.dll
2018-01-04 21:35 - 2018-01-01 06:20 - 000186368 _____ (Microsoft Corporation) C:\WINDOWS\system32\ACPBackgroundManagerPolicy.dll
2018-01-04 21:35 - 2018-01-01 06:20 - 000175616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fwpolicyiomgr.dll
2018-01-04 21:35 - 2018-01-01 06:20 - 000134656 _____ (Microsoft Corporation) C:\WINDOWS\system32\WcnApi.dll
2018-01-04 21:35 - 2018-01-01 06:20 - 000133632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iepeers.dll
2018-01-04 21:35 - 2018-01-01 06:20 - 000104960 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasauto.dll
2018-01-04 21:35 - 2018-01-01 06:20 - 000082432 _____ (Microsoft Corporation) C:\WINDOWS\system32\SCardDlg.dll
2018-01-04 21:35 - 2018-01-01 06:20 - 000043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\RfxVmt.sys
2018-01-04 21:35 - 2018-01-01 06:20 - 000035328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\nshhttp.dll
2018-01-04 21:35 - 2018-01-01 06:19 - 000795136 _____ (Microsoft Corporation) C:\WINDOWS\system32\NaturalAuth.dll
2018-01-04 21:35 - 2018-01-01 06:19 - 000675328 _____ (Microsoft Corporation) C:\WINDOWS\system32\webplatstorageserver.dll
2018-01-04 21:35 - 2018-01-01 06:19 - 000430080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Bluetooth.dll
2018-01-04 21:35 - 2018-01-01 06:19 - 000416768 _____ (Microsoft Corporation) C:\WINDOWS\system32\html.iec
2018-01-04 21:35 - 2018-01-01 06:19 - 000366080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\daxexec.dll
2018-01-04 21:35 - 2018-01-01 06:19 - 000340480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\html.iec
2018-01-04 21:35 - 2018-01-01 06:19 - 000316928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\netbt.sys
2018-01-04 21:35 - 2018-01-01 06:19 - 000188416 _____ (Microsoft Corporation) C:\WINDOWS\system32\PimIndexMaintenance.dll
2018-01-04 21:35 - 2018-01-01 06:19 - 000174592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\P2P.dll
2018-01-04 21:35 - 2018-01-01 06:19 - 000149504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\container.dll
2018-01-04 21:35 - 2018-01-01 06:19 - 000142848 _____ (Microsoft Corporation) C:\WINDOWS\system32\iepeers.dll
2018-01-04 21:35 - 2018-01-01 06:19 - 000097792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msoert2.dll
2018-01-04 21:35 - 2018-01-01 06:19 - 000093696 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2018-01-04 21:35 - 2018-01-01 06:19 - 000079872 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlaapi.dll
2018-01-04 21:35 - 2018-01-01 06:19 - 000063488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\nlaapi.dll
2018-01-04 21:35 - 2018-01-01 06:19 - 000043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\nshhttp.dll
2018-01-04 21:35 - 2018-01-01 06:18 - 000748032 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneProviders.dll
2018-01-04 21:35 - 2018-01-01 06:18 - 000699904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CPFilters.dll
2018-01-04 21:35 - 2018-01-01 06:18 - 000588800 _____ (Microsoft Corporation) C:\WINDOWS\system32\SmsRouterSvc.dll
2018-01-04 21:35 - 2018-01-01 06:18 - 000465920 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcncsvc.dll
2018-01-04 21:35 - 2018-01-01 06:18 - 000436224 _____ (Microsoft Corporation) C:\WINDOWS\system32\PsmServiceExtHost.dll
2018-01-04 21:35 - 2018-01-01 06:18 - 000425984 _____ (Microsoft Corporation) C:\WINDOWS\system32\vmrdvcore.dll
2018-01-04 21:35 - 2018-01-01 06:18 - 000391168 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2018-01-04 21:35 - 2018-01-01 06:18 - 000380928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EncDec.dll
2018-01-04 21:35 - 2018-01-01 06:18 - 000369664 _____ (Microsoft Corporation) C:\WINDOWS\system32\APHostService.dll
2018-01-04 21:35 - 2018-01-01 06:18 - 000343040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2018-01-04 21:35 - 2018-01-01 06:18 - 000336896 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppLockerCSP.dll
2018-01-04 21:35 - 2018-01-01 06:18 - 000276480 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll
2018-01-04 21:35 - 2018-01-01 06:18 - 000259072 _____ (Microsoft Corporation) C:\WINDOWS\system32\SCardSvr.dll
2018-01-04 21:35 - 2018-01-01 06:18 - 000210944 _____ (Microsoft Corporation) C:\WINDOWS\system32\P2P.dll
2018-01-04 21:35 - 2018-01-01 06:18 - 000144896 _____ (Microsoft Corporation) C:\WINDOWS\system32\appinfo.dll
2018-01-04 21:35 - 2018-01-01 06:18 - 000082944 _____ (Microsoft Corporation) C:\WINDOWS\system32\provdatastore.dll
2018-01-04 21:35 - 2018-01-01 06:17 - 001485312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpserverbase.dll
2018-01-04 21:35 - 2018-01-01 06:17 - 000791552 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneService.dll
2018-01-04 21:35 - 2018-01-01 06:17 - 000616960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Bluetooth.dll
2018-01-04 21:35 - 2018-01-01 06:17 - 000594432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Web.Core.dll
2018-01-04 21:35 - 2018-01-01 06:17 - 000555520 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorService.dll
2018-01-04 21:35 - 2018-01-01 06:17 - 000456704 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtmsft.dll
2018-01-04 21:35 - 2018-01-01 06:17 - 000423936 _____ (Microsoft Corporation) C:\WINDOWS\system32\p2psvc.dll
2018-01-04 21:35 - 2018-01-01 06:17 - 000341504 _____ (Microsoft Corporation) C:\WINDOWS\system32\pnrpsvc.dll
2018-01-04 21:35 - 2018-01-01 06:17 - 000228352 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2018-01-04 21:35 - 2018-01-01 06:17 - 000112640 _____ (Microsoft Corporation) C:\WINDOWS\system32\msoert2.dll
2018-01-04 21:35 - 2018-01-01 06:16 - 004839424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbgeng.dll
2018-01-04 21:35 - 2018-01-01 06:16 - 000966656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Unistore.dll
2018-01-04 21:35 - 2018-01-01 06:16 - 000956928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpbase.dll
2018-01-04 21:35 - 2018-01-01 06:16 - 000831488 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll
2018-01-04 21:35 - 2018-01-01 06:16 - 000668160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2018-01-04 21:35 - 2018-01-01 06:16 - 000624128 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncController.dll
2018-01-04 21:35 - 2018-01-01 06:16 - 000401920 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncsi.dll
2018-01-04 21:35 - 2018-01-01 06:16 - 000235008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webcheck.dll
2018-01-04 21:35 - 2018-01-01 06:16 - 000086528 _____ (Microsoft Corporation) C:\WINDOWS\system32\cldapi.dll
2018-01-04 21:35 - 2018-01-01 06:16 - 000076288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cldapi.dll
2018-01-04 21:35 - 2018-01-01 06:15 - 002349568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputService.dll
2018-01-04 21:35 - 2018-01-01 06:15 - 001657856 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpserverbase.dll
2018-01-04 21:35 - 2018-01-01 06:15 - 001245184 _____ (Microsoft Corporation) C:\WINDOWS\system32\Unistore.dll
2018-01-04 21:35 - 2018-01-01 06:15 - 000970240 _____ (Microsoft Corporation) C:\WINDOWS\system32\sysmain.dll
2018-01-04 21:35 - 2018-01-01 06:15 - 000951808 _____ (Microsoft Corporation) C:\WINDOWS\system32\usermgr.dll
2018-01-04 21:35 - 2018-01-01 06:15 - 000756736 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2018-01-04 21:35 - 2018-01-01 06:15 - 000434176 _____ (Microsoft Corporation) C:\WINDOWS\system32\EncDec.dll
2018-01-04 21:35 - 2018-01-01 06:15 - 000366080 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlasvc.dll
2018-01-04 21:35 - 2018-01-01 06:15 - 000258560 _____ (Microsoft Corporation) C:\WINDOWS\system32\webcheck.dll
2018-01-04 21:35 - 2018-01-01 06:14 - 001097728 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpbase.dll
2018-01-04 21:35 - 2018-01-01 06:14 - 001003008 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll
2018-01-04 21:35 - 2018-01-01 06:14 - 000985600 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll
2018-01-04 21:35 - 2018-01-01 06:14 - 000917504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll
2018-01-04 21:35 - 2018-01-01 06:14 - 000870912 _____ (Microsoft Corporation) C:\WINDOWS\system32\CPFilters.dll
2018-01-04 21:35 - 2018-01-01 06:13 - 002013184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2018-01-04 21:35 - 2018-01-01 06:13 - 001474560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2018-01-04 21:35 - 2018-01-01 06:13 - 000897024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcomm.dll
2018-01-04 21:35 - 2018-01-01 06:12 - 001573376 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataService.dll
2018-01-04 21:35 - 2018-01-01 06:12 - 000760320 _____ (Microsoft Corporation) C:\WINDOWS\system32\spoolsv.exe
2018-01-04 21:35 - 2018-01-01 06:12 - 000464384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Core.TextInput.dll
2018-01-04 21:35 - 2018-01-01 06:11 - 002082304 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2018-01-04 21:35 - 2018-01-01 06:11 - 001816576 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtsvc.dll
2018-01-04 21:35 - 2018-01-01 06:11 - 001597952 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2018-01-04 21:35 - 2018-01-01 06:11 - 001343488 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifinetworkmanager.dll
2018-01-04 21:35 - 2018-01-01 06:11 - 000715776 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
2018-01-04 21:35 - 2018-01-01 06:10 - 003126272 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll
2018-01-04 21:35 - 2018-01-01 06:10 - 002528256 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll
2018-01-04 21:35 - 2018-01-01 06:10 - 000012800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscproxystub.dll
2018-01-04 21:35 - 2018-01-01 06:09 - 000666624 _____ (Microsoft Corporation) C:\WINDOWS\system32\DbgModel.dll
2018-01-04 21:35 - 2018-01-01 06:09 - 000599552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll
2018-01-04 21:35 - 2018-01-01 06:08 - 000963072 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll
2018-01-04 21:35 - 2018-01-01 06:08 - 000505344 _____ (Microsoft Corporation) C:\WINDOWS\system32\taskcomp.dll
2018-01-04 21:35 - 2018-01-01 06:06 - 000018944 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscproxystub.dll
2018-01-04 21:35 - 2018-01-01 06:05 - 000050176 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcalua.exe
2018-01-03 14:55 - 2018-01-03 14:55 - 000000000 ____D C:\Users\steph\AppData\Local\Apple
2018-01-01 19:34 - 2018-01-01 19:34 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kodi
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2018-01-29 19:48 - 2015-10-16 18:40 - 000000000 ____D C:\ProgramData\Malwarebytes
2018-01-29 19:46 - 2017-09-02 02:06 - 000192952 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMChameleon.sys
2018-01-29 18:46 - 2017-09-29 08:46 - 000000000 ____D C:\WINDOWS\DeliveryOptimization
2018-01-29 18:45 - 2017-09-29 08:46 - 000000000 ___HD C:\Program Files\WindowsApps
2018-01-29 18:45 - 2017-09-29 08:46 - 000000000 ____D C:\WINDOWS\AppReadiness
2018-01-29 18:44 - 2015-10-14 21:52 - 000000093 _____ C:\Users\Jack\AppData\Roaming\sp_data.sys
2018-01-29 18:42 - 2017-11-24 17:28 - 000000000 ____D C:\ProgramData\ASUS Smart Gesture
2018-01-29 18:40 - 2017-10-03 17:05 - 000000000 ____D C:\Users\Jack\AppData\Local\NETGEARGenie
2018-01-29 18:40 - 2017-03-29 09:21 - 000000000 ___RD C:\Users\Jack\Google Drive
2018-01-29 18:38 - 2017-06-29 18:11 - 000000000 ____D C:\Program Files\SoftEther VPN Client
2018-01-29 18:35 - 2017-06-02 10:21 - 000000180 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2018-01-29 18:35 - 2015-10-14 21:49 - 000000000 __SHD C:\Users\Jack\IntelGraphicsProfiles
2018-01-29 18:34 - 2017-11-17 01:32 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2018-01-28 11:58 - 2017-09-29 03:45 - 025165824 _____ C:\WINDOWS\system32\config\HARDWARE
2018-01-28 11:58 - 2017-09-29 03:45 - 001048576 _____ C:\WINDOWS\system32\config\BBI
2018-01-28 11:48 - 2017-11-17 01:00 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2018-01-27 23:17 - 2017-11-17 01:32 - 000000000 ____D C:\WINDOWS\System32\Tasks\ASUS
2018-01-27 19:19 - 2017-11-17 01:32 - 000004212 _____ C:\WINDOWS\System32\Tasks\CCleaner Update
2018-01-27 18:39 - 2017-09-02 02:05 - 000002099 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2018-01-27 18:31 - 2017-11-17 01:06 - 000000000 ____D C:\Users\Jack
2018-01-27 18:23 - 2016-04-03 13:55 - 000000000 ____D C:\Program Files (x86)\TeamViewer
2018-01-26 23:02 - 2016-04-03 13:55 - 000000000 ____D C:\Users\Jack\AppData\Roaming\TeamViewer
2018-01-26 23:02 - 2016-01-09 20:54 - 000000000 ____D C:\Users\Jack\AppData\Roaming\uTorrent
2018-01-26 23:01 - 2017-09-29 08:46 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2018-01-26 23:01 - 2017-09-29 08:44 - 000000000 ____D C:\WINDOWS\INF
2018-01-26 22:53 - 2017-11-17 01:31 - 001190370 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2018-01-26 22:36 - 2017-03-07 18:18 - 000000352 _____ C:\WINDOWS\Tasks\HPCeeScheduleForJack.job
2018-01-26 22:18 - 2017-11-17 01:09 - 000000000 ____D C:\Users\Jack\AppData\Local\Packages
2018-01-26 22:14 - 2015-10-18 19:32 - 000001234 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2018-01-26 22:14 - 2015-10-15 09:24 - 000002274 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2018-01-26 19:32 - 2017-02-24 16:22 - 000000000 ____D C:\Users\Jack\AppData\LocalLow\Mozilla
2018-01-25 22:51 - 2016-12-02 22:00 - 000001912 _____ C:\Users\Jack\Desktop\Kodi.lnk
2018-01-25 22:51 - 2016-11-20 00:30 - 000000000 ____D C:\Users\Jack\AppData\Roaming\Kodi
2018-01-24 16:01 - 2017-11-17 01:32 - 000003240 _____ C:\WINDOWS\System32\Tasks\HPCeeScheduleForJack
2018-01-24 13:36 - 2015-10-16 18:59 - 000548000 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2018-01-23 11:39 - 2017-11-17 01:00 - 000505840 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2018-01-23 11:35 - 2017-09-29 08:46 - 000000000 ____D C:\WINDOWS\system32\FxsTmp
2018-01-23 11:34 - 2014-10-02 15:33 - 000000000 ____D C:\ProgramData\Package Cache
2018-01-22 22:05 - 2016-12-02 19:41 - 000000000 ____D C:\Users\Jack\AppData\Local\Windows Live
2018-01-22 19:57 - 2015-10-19 21:54 - 000000000 ____D C:\ProgramData\Oracle
2018-01-22 19:56 - 2016-10-23 21:49 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2018-01-22 19:56 - 2015-10-19 21:54 - 000000000 ____D C:\Program Files (x86)\Java
2018-01-22 19:54 - 2016-10-23 21:49 - 000097344 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll
2018-01-22 11:50 - 2017-12-26 16:26 - 000000000 ____D C:\Program Files (x86)\TomTom HOME 2
2018-01-22 11:46 - 2015-10-15 23:45 - 000000000 ____D C:\Users\Jack\AppData\Local\Downloaded Installations
2018-01-21 20:22 - 2017-09-29 08:37 - 000000000 ____D C:\WINDOWS\CbsTemp
2018-01-21 20:18 - 2017-11-17 01:32 - 000004160 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{CDA7FC31-4313-41B6-86A9-6144DA1867D5}
2018-01-21 19:54 - 2015-10-15 22:24 - 000000093 _____ C:\Users\steph\AppData\Roaming\sp_data.sys
2018-01-21 17:57 - 2016-06-03 09:43 - 000000000 ____D C:\ProgramData\TEMP
2018-01-21 16:38 - 2015-10-15 22:21 - 000000000 __SHD C:\Users\steph\IntelGraphicsProfiles
2018-01-19 17:50 - 2017-12-20 11:13 - 000000325 _____ C:\Users\Jack\Desktop\bitcoin.txt
2018-01-19 16:20 - 2017-09-29 08:46 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2018-01-19 16:18 - 2014-10-02 15:30 - 000000000 ____D C:\Program Files (x86)\Microsoft Office
2018-01-18 23:11 - 2017-12-06 18:28 - 000000000 ____D C:\WINDOWS\Minidump
2018-01-18 23:10 - 2017-08-16 17:37 - 000000865 _____ C:\Users\Public\Desktop\CCleaner.lnk
2018-01-18 21:54 - 2017-06-28 07:50 - 000000000 ____D C:\Program Files (x86)\Mozilla Firefox
2018-01-18 21:54 - 2015-10-18 19:32 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2018-01-18 19:50 - 2017-12-20 21:53 - 000000000 ____D C:\Users\Jack\Desktop\PRINT
2018-01-16 20:39 - 2017-11-17 01:32 - 000003370 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2592302959-4100768495-3643388182-1002
2018-01-16 20:39 - 2015-10-15 22:25 - 000002412 _____ C:\Users\steph\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2018-01-16 20:39 - 2015-10-15 22:25 - 000000000 ___RD C:\Users\steph\OneDrive
2018-01-15 19:17 - 2015-10-16 18:46 - 000000000 ____D C:\WINDOWS\system32\MRT
2018-01-15 19:12 - 2017-10-10 17:42 - 129365736 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT-KB890830.exe
2018-01-15 19:12 - 2015-10-16 18:46 - 129365736 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2018-01-15 19:10 - 2017-11-17 01:32 - 000004542 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player PPAPI Notifier
2018-01-15 19:10 - 2017-09-29 08:46 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed
2018-01-15 19:10 - 2017-09-29 08:46 - 000000000 ____D C:\WINDOWS\system32\Macromed
2018-01-11 19:32 - 2017-09-29 08:46 - 000000000 ____D C:\WINDOWS\rescache
2018-01-11 18:30 - 2017-11-17 01:08 - 000000000 ____D C:\Users\steph\AppData\Local\Packages
2018-01-11 18:27 - 2017-11-27 18:10 - 000000000 ___RD C:\Users\steph\3D Objects
2018-01-11 18:27 - 2015-09-10 00:42 - 000000000 __RHD C:\Users\Public\AccountPictures
2018-01-11 14:04 - 2017-09-04 11:25 - 000000000 ____D C:\Users\Jack\AppData\Local\ElevatedDiagnostics
2018-01-10 09:45 - 2017-11-17 01:32 - 000003368 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2592302959-4100768495-3643388182-1001
2018-01-10 09:44 - 2017-07-10 20:50 - 000002409 _____ C:\Users\Jack\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2018-01-10 09:44 - 2015-10-14 21:54 - 000000000 ___RD C:\Users\Jack\OneDrive
2018-01-08 19:11 - 2017-11-17 14:18 - 000000000 ___RD C:\Users\Jack\3D Objects
2018-01-08 19:04 - 2017-09-29 08:46 - 000000000 ___SD C:\WINDOWS\SysWOW64\F12
2018-01-08 19:04 - 2017-09-29 08:46 - 000000000 ___SD C:\WINDOWS\system32\F12
2018-01-08 19:04 - 2017-09-29 08:46 - 000000000 ____D C:\WINDOWS\TextInput
2018-01-08 19:04 - 2017-09-29 08:46 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2018-01-08 19:04 - 2017-09-29 08:46 - 000000000 ____D C:\WINDOWS\system32\oobe
2018-01-08 19:04 - 2017-09-29 08:46 - 000000000 ____D C:\WINDOWS\system32\migwiz
2018-01-08 19:04 - 2017-09-29 08:46 - 000000000 ____D C:\WINDOWS\system32\appraiser
2018-01-08 19:04 - 2017-09-29 03:45 - 000000000 ____D C:\WINDOWS\system32\Dism
2018-01-08 19:03 - 2017-09-29 08:46 - 000000000 ____D C:\WINDOWS\Provisioning
2018-01-05 14:30 - 2017-06-22 09:38 - 000009877 _____ C:\Users\Jack\Desktop\Jaguar.xlsx
2018-01-04 21:41 - 2017-09-29 08:41 - 000403968 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpAXHolder.dll
2018-01-04 21:40 - 2017-09-29 08:41 - 000140800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2018-01-04 21:40 - 2017-09-29 08:41 - 000106496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll
2018-01-02 18:27 - 2017-11-27 18:11 - 000000000 ____D C:\Users\steph\AppData\Local\PackageStaging
2018-01-01 19:34 - 2016-11-20 00:28 - 000000000 ____D C:\Program Files (x86)\Kodi
2017-12-30 04:06 - 2017-09-29 08:46 - 000000000 ____D C:\WINDOWS\system32\NDF
 
==================== Files in the root of some directories =======
 
2016-06-07 19:37 - 2016-06-07 19:37 - 000128512 _____ () C:\Users\Jack\AppData\Roaming\Installer.dat
2015-10-14 21:52 - 2018-01-29 18:44 - 000000093 _____ () C:\Users\Jack\AppData\Roaming\sp_data.sys
2016-11-11 20:07 - 2017-12-03 21:57 - 000000600 _____ () C:\Users\Jack\AppData\Roaming\winscp.rnd
2018-01-26 17:58 - 2018-01-26 17:58 - 000010752 _____ () C:\Users\Jack\AppData\Local\gunny.exe
2018-01-26 17:58 - 2018-01-26 17:58 - 000011264 _____ () C:\Users\Jack\AppData\Local\knudsen.exe
2017-12-03 22:04 - 2017-12-03 22:04 - 000000600 _____ () C:\Users\Jack\AppData\Local\PUTTY.RND
 
Some files in TEMP:
====================
2018-01-26 19:41 - 2017-08-19 15:49 - 002294496 _____ () C:\Users\Jack\AppData\Local\Temp\asacpiex.dll
2018-01-26 19:38 - 2018-01-26 19:38 - 000594944 _____ (The OpenSSL Project, http://www.openssl.org/) C:\Users\Jack\AppData\Local\Temp\libeay32.dll
2018-01-26 19:41 - 2017-08-19 15:49 - 001154560 _____ () C:\Users\Jack\AppData\Local\Temp\screen.exe
2018-01-26 19:38 - 2018-01-26 19:38 - 000152576 _____ (The OpenSSL Project, http://www.openssl.org/) C:\Users\Jack\AppData\Local\Temp\ssleay32.dll
2018-01-26 22:16 - 2018-01-26 19:39 - 000099888 _____ () C:\Users\Jack\AppData\Local\Temp\Uninstall.exe
 
==================== Bamital & volsnap ======================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
C:\WINDOWS\system32\drivers\vsslpsvy.sys -> Access Denied <======= ATTENTION
 
LastRegBack: 2018-01-25 23:33
 
==================== End of FRST.txt ============================

Edited by MrJackSTARR, 29 January 2018 - 08:52 PM.


BC AdBot (Login to Remove)

 


#2 Aura

Aura

    Bleepin' Special Ops


  • Malware Response Team
  • 19,596 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:04:43 PM

Posted 30 January 2018 - 08:08 AM

Hi MrJackSTARR :)

My name is Aura and I'll be assisting you with your malware issue. Since we'll be working together, you can call me Aura or Yoan, which is my real name, it's up to you! Now that we've broke the ice, I'll just ask you a few things during the time we'll be working together to clean your system and get it back to an operational state.
  • As you'll notice, the logs we are asking for here are quite lenghty, so it's normal for me to not reply exactly after you post them. This is because I need some time to analyse them and then act accordingly. However, I'll always reply within 24 hours, 48 hours at most if something unexpected happens
  • As long as I'm assisting you on BleepingComputer, in this thread, I'll ask you to not seek assistance anywhere else for any issue related to the system we are working on. If you have an issue, question, etc. about your computer, please ask it in this thread and I'll assist you
  • The same principle applies to any modifications you make to your system, I would like you to ask me before you do any manipulations that aren't in the instructions I posted. This is to ensure that we are operating in sync and I know exactly what's happening on your system
  • If you aren't sure about an instruction I'm giving you, ask me about it. This is to ensure that the clean-up process goes without any issue. I'll answer you and even give you more precise instructions/explanations if you need. There's no shame in asking questions here, better be safe than sorry!
  • If you don't reply to your thread within 3 days, I'll bump this thread to let you know that I'm waiting for you. If you don't reply after 5 days, it'll be closed. If you return after that period, you can send me a PM to get it unlocked and we'll continue where we left off
  • Since malware can work quickly, we want to get rid of them as fast as we can, before they make unknown changes to the system. This being said, I would appreciate if you could reply to this thread within 24 hours of me posting. This way, we'll have a good clean-up rhythm and the chances of complications will be reduced
  • I'm against any form of pirated, illegal and counterfeit software and material. So if you have any installed on your system, I'll ask you to uninstall them right now. You don't have to tell me if you indeed had some or not, I'll give you the benefit of the doubt. Plus, this would be against BleepingComputer's rules
  • In the end, you are the one asking for assistance here. So if you wish to go a different way during the clean-up, like format and reinstall Windows, you are free to do so. I would appreciate you to let me know about it first, and if you need, I can also assist you in the process
  • I would appreciate if you were to stay with me until the end, which means, until I declare your system clean. Just because your system isn't behaving weirdly anymore, or is running better than before, it doesn't mean that the infection is completely gone
    This being said, I have a full time job so sometimes it'll take longer for me to reply to you. Don't worry, you'll be my first priority as soon as I get home and have time to look at your thread
This being said, it's time to clean-up some malware, so let's get started, shall we? :)

iO3R662.pngFarbar Recovery Scan Tool (FRST) - Fix mode
Follow the instructions below to execute a fix on your system using FRST, and provide the log in your next reply.
  • Right-click on the FRST executable and select Spcusrh.pngRun as Administrator (for Windows Vista, 7, 8, 8.1 and 10 users)
  • Copy/paste the following inside the text area:
    Start::
    CMD: bcdedit.exe /set {bootmgr} displaybootmenu yes
    CMD: bcdedit.exe /set {default} recoveryenabled yes
    End::
    
  • Click on the Fix button
    NYA5Cbr.png
  • On completion, a message will come up saying that the fix has been completed and it'll open a log in Notepad
  • Copy and paste its content in your next reply

unite_blue.png
Security Administrator | Sysnative Windows Update Senior Analyst | Malware Hunter | @SecurityAura
My timezone UTC-05:00 (East. Coast). If I didn't reply to you within 48 hours, please send me a PM.


#3 MrJackSTARR

MrJackSTARR
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:03:43 PM

Posted 30 January 2018 - 08:31 AM

Good morning Aura. I appreciate you assisting me with this issue.

 

Here are the results:

 

Fix result of Farbar Recovery Scan Tool (x64) Version: 27.01.2018
Ran by Jack (30-01-2018 08:21:01) Run:1
Running from C:\Users\Jack\Downloads
Loaded Profiles: Jack (Available Profiles: Jack & steph)
Boot Mode: Normal
==============================================
 
fixlist content:
*****************
CMD: bcdedit.exe /set {bootmgr} displaybootmenu yes
CMD: bcdedit.exe /set {default} recoveryenabled yes
 
*****************
 
 
========= bcdedit.exe /set {bootmgr} displaybootmenu yes =========
 
The operation completed successfully.
 
========= End of CMD: =========
 
 
========= bcdedit.exe /set {default} recoveryenabled yes =========
 
The operation completed successfully.
 
========= End of CMD: =========
 
 
==== End of Fixlog 08:21:01 ====


#4 Aura

Aura

    Bleepin' Special Ops


  • Malware Response Team
  • 19,596 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:04:43 PM

Posted 30 January 2018 - 08:42 AM

For the next part, you'll need to download the FRST executable a clean computer, and move them on your USB Flash Drive. That USB can only be inserted in the infected computer if it is either shutdown, or in the Windows RE. Otherwise, the infection will mess with the files on the USB and you'll have to restart.

iO3R662.pngFarbar Recovery Scan Tool (FRST) - Recovery Environment Scan
Follow the instructions below to download and execute a scan on your system with FRST from the Recovery Environment, and provide the logs in your next reply.

Item(s) required:
  • USB Flash Drive (size depend on if you have to create a USB Recovery or Installation media)
  • Another computer (clean of infection)
  • CD/DVD (optional: only needed if you need to create a Recovery or Installation media and your USB Flash Drive is too small)
Preparing the USB Flash Drive
  • Download the right version of FRST for your system from a clean computer:
    • FRST 32-bit
    • FRST 64-bit
      Note: Only the right version will run on your system, the other will throw an error message. So if you don't know what your system's version is, simply download both of them, and the one that works is the one you should be using.
  • Move the executable (FRST.exe or FRST64.exe) on your USB Flash Drive
Boot in the Recovery Environment
  • To enter the Recovery Environment with Windows Vista and Windows 7, follow the instructions below:
    • Restart the computer
    • Once you've seen your BIOS splashscreen (the computer manufacturer logo), tap the F8 key repeatedly until the Advanced Boot Options menu appears
    • Use the arrow keys to select Repair your computer, and press on Enter
    • Select your keyboard layout (US, French, etc.) and click on Next
    • Click on Command Prompt to open the command prompt
      Note: If you can't access the Recovery Environment using the F8 method above, you'll need to create a Windows installation or repair media. It can be made on the computer itself or another one running the same version of Windows as the one you plan to use it on. For more information, check out this tutorial on SevenForums.
  • To enter the Recovery Environment with Windows 8 or Windows 8.1, follow the instructions in this tutorial on EightForums
    Note: If you can't access the Recovery Environment using the method above, you'll need to create a Windows installation or repair media. It can be made on the computer itself or another one running the same version of Windows as the one you plan to use it on. For more information, check out this tutorial.
  • To enter the Recovery Environment with Windows 10, follow the instructions in this tutorial on TenForums
    Note: If you can't access the Recovery Environment using the method above, you'll need to create a Windows installation or repair media. It can be made on the computer itself or another one running the same version of Windows as the one you plan to use it on. For more information, check out this tutorial on TenForums.
  • Once in the Windows RE, plug the USB Flash Drive in the computer
Once in the command prompt
  • In the command prompt, type notepad and press on Enter
  • Notepad will open. Click on the File menu and select Open
  • Click on Computer/This PC, find the letter for your USB Flash Drive, then close the window and Notepad
  • In the command prompt, type e:\frst.exe (for the x64 version, type e:\frst64.exe and press on Enter
  • Note: Replace the letter e with the drive letter of your USB Flash Drive
  • FRST will open
  • Click on Yes to accept the disclaimer
  • Click on the Scan button and wait for the scan to complete
  • A log called FRST.txt will be saved on your USB Flash Drive. Attach it in your next reply

unite_blue.png
Security Administrator | Sysnative Windows Update Senior Analyst | Malware Hunter | @SecurityAura
My timezone UTC-05:00 (East. Coast). If I didn't reply to you within 48 hours, please send me a PM.


#5 Aura

Aura

    Bleepin' Special Ops


  • Malware Response Team
  • 19,596 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:04:43 PM

Posted 02 February 2018 - 08:49 AM

Hi MrJackSTARR,

Are you still with me?

unite_blue.png
Security Administrator | Sysnative Windows Update Senior Analyst | Malware Hunter | @SecurityAura
My timezone UTC-05:00 (East. Coast). If I didn't reply to you within 48 hours, please send me a PM.


#6 MrJackSTARR

MrJackSTARR
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:03:43 PM

Posted 03 February 2018 - 12:51 PM

Hi MrJackSTARR,

Are you still with me?

Yes my apologies, I am traveling and not always near wifi or a second computer


Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 27.01.2018
Ran by Jack (administrator) on JACK-LAPTOP (03-02-2018 12:18:34)
Running from C:\Users\Jack\AppData\Local\Temp
Loaded Profiles: Jack (Available Profiles: Jack & steph)
Platform: Windows 10 Home Version 1709 16299.192 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Safe Mode (minimal)
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(TOSHIBA CORPORATION) C:\Windows\System32\vdhkexasvc.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\HelpPane.exe
(Microsoft Corporation) C:\Windows\System32\Speech_OneCore\common\SpeechRuntime.exe
() C:\Users\Jack\AppData\Local\atmibgl\atmibgl.exe
() C:\Users\Jack\AppData\Local\wimxehg\dsapwgt.exe
() C:\Users\Jack\AppData\Local\atmibgl\avbwncd.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Farbar) C:\Users\Jack\AppData\Local\Temp\246C.tmp.exe
 
==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [630168 2017-09-29] (Microsoft Corporation)
HKLM\...\Run: [SoftEther VPN Client UI Helper] => C:\Program Files\SoftEther VPN Client\vpnclient_x64.exe [5248456 2017-06-29] (SoftEther VPN Project at University of Tsukuba, Japan.)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [297784 2017-10-20] (Apple Inc.)
HKLM\...\Run: [DptfPolicyLpmServiceHelper] => C:\WINDOWS\system32\DptfPolicyLpmServiceHelper.exe [114048 2013-10-17] (Intel Corporation)
HKLM-x32\...\Run: [WebStorage] => C:\Program Files (x86)\ASUS\WebStorage\2.1.11.399\ASUSWSLoader.exe [63296 2014-08-20] ()
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM-x32\...\Run: [HPUsageTrackingLEDM] => "C:\Program Files (x86)\HP\HP UT LEDM\bin\hppusg.exe" "C:\Program Files (x86)\HP\HP UT LEDM\"
HKLM-x32\...\Run: [Autodesk Desktop App] => C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AutodeskDesktopApp.exe [704424 2017-06-15] (Autodesk, Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2017-12-19] (Oracle Corporation)
HKLM-x32\...\Run: [DFX] => C:\Program Files (x86)\DFX\DFX.exe [1282008 2015-02-27] ()
HKLM\...\Policies\Explorer\Run: [BtvStack] => C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-21-2592302959-4100768495-3643388182-1001\...\Run: [Google Update] => C:\Users\Jack\AppData\Local\Google\Update\1.3.33.7\GoogleUpdateCore.exe [601680 2017-11-14] (Google Inc.)
HKU\S-1-5-21-2592302959-4100768495-3643388182-1001\...\Run: [Autodesk Sync] => C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe [1283096 2016-10-10] (Autodesk, Inc.)
HKU\S-1-5-21-2592302959-4100768495-3643388182-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [10257872 2018-01-09] (Piriform Ltd)
HKU\S-1-5-21-2592302959-4100768495-3643388182-1001\...\Run: [GoogleDriveSync] => C:\Program Files (x86)\Google\Drive\googledrivesync.exe [41061856 2017-11-20] ()
HKU\S-1-5-21-2592302959-4100768495-3643388182-1001\...\Run: [TomTomHOME.exe] => C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe [254840 2017-12-18] (TomTom)
HKU\S-1-5-21-2592302959-4100768495-3643388182-1001\...\Run: [NETGEARGenie] => C:\Program Files (x86)\NETGEAR Genie\bin\NETGEARGenie.exe [612336 2017-07-04] (NETGEAR Inc.)
HKU\S-1-5-21-2592302959-4100768495-3643388182-1001\...\RunOnce: [Application Restart #0] => C:\Windows\System32\Taskmgr.exe [1312504 2017-09-29] (Microsoft Corporation)
HKU\S-1-5-21-2592302959-4100768495-3643388182-1001\...\Policies\Explorer: [] 
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SoftEther VPN Client Manager Startup.lnk [2017-06-29]
ShortcutTarget: SoftEther VPN Client Manager Startup.lnk -> C:\Program Files\SoftEther VPN Client\vpncmgr_x64.exe (SoftEther VPN Project at University of Tsukuba, Japan.)
Startup: C:\Users\Jack\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Monitor Ink Alerts - HP Deskjet 1510 series.lnk [2018-02-03]
ShortcutTarget: Monitor Ink Alerts - HP Deskjet 1510 series.lnk -> C:\Program Files\HP\HP Deskjet 1510 series\Bin\HPStatusBL.dll (Hewlett-Packard Co.)
Startup: C:\Users\Jack\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\PdaNet Desktop.lnk [2017-01-18]
ShortcutTarget: PdaNet Desktop.lnk -> C:\Program Files (x86)\PdaNet for Android\PdaNetPC.exe ()
Startup: C:\Users\Jack\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Send to OneNote.lnk [2017-04-06]
ShortcutTarget: Send to OneNote.lnk -> C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE (Microsoft Corporation)
BootExecute: autocheck autochk * Partizan
GroupPolicy: Restriction <==== ATTENTION
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 75.114.81.1 209.18.47.61 75.114.81.2
Tcpip\..\Interfaces\{1a3c6e9c-be1b-405c-ac3f-356fb3805c01}: [DhcpNameServer] 8.8.8.8
Tcpip\..\Interfaces\{1d5b4b4c-5b2d-4023-a952-de4ef30cd91c}: [DhcpNameServer] 8.8.8.8
Tcpip\..\Interfaces\{887671a0-cb5c-11e7-805b-806e6f6e6963}: [NameServer] 8.8.8.8
Tcpip\..\Interfaces\{ad359bfc-5864-4fea-89c1-ca74c850c971}: [DhcpNameServer] 172.20.10.1
Tcpip\..\Interfaces\{C866D6E9-77B9-48B3-9F65-3C09B10BEEBC}: [NameServer] 8.8.8.8
Tcpip\..\Interfaces\{dd286b07-686a-4c55-9b1f-608c951cf41e}: [NameServer] 8.8.8.8
Tcpip\..\Interfaces\{dd286b07-686a-4c55-9b1f-608c951cf41e}: [DhcpNameServer] 75.114.81.1 209.18.47.61 75.114.81.2
Tcpip\..\Interfaces\{f2f6d513-82d3-448d-a072-ac32ee0240d9}: [DhcpNameServer] 8.8.8.8
Tcpip\..\Interfaces\{fef64767-51fe-4011-a6ec-2832ccba2877}: [DhcpNameServer] 10.0.0.1
 
Internet Explorer:
==================
HKU\S-1-5-21-2592302959-4100768495-3643388182-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
HKU\S-1-5-21-2592302959-4100768495-3643388182-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
SearchScopes: HKU\S-1-5-21-2592302959-4100768495-3643388182-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-2592302959-4100768495-3643388182-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2018-01-19] (Microsoft Corporation)
BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL [2018-01-19] (Microsoft Corporation)
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll [2018-01-19] (Microsoft Corporation)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_161\bin\ssv.dll [2018-01-22] (Oracle Corporation)
BHO-x32: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\Office16\GROOVEEX.DLL [2018-01-19] (Microsoft Corporation)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_161\bin\jp2ssv.dll [2018-01-22] (Oracle Corporation)
DPF: HKLM-x32 {166B1BCA-3F9C-11CF-8075-444553540000} hxxps://fpdownload.macromedia.com/pub/shockwave/cabs/director/sw.cab
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-01-19] (Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-01-19] (Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-01-19] (Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-01-19] (Microsoft Corporation)
 
FireFox:
========
FF ProfilePath: C:\Users\Jack\AppData\Roaming\TomTom\HOME\Profiles\6wrq57wk.default [2018-01-22]
FF Extension: (Map status indicator) - C:\Program Files (x86)\TomTom HOME 2\xul\extensions\MapShare-status@tomtom.com [2018-01-22] [Legacy] [not signed]
FF ProfilePath: C:\Users\Jack\AppData\Roaming\Mozilla\Firefox\Profiles\gw8bwnqt.default [2018-02-02]
FF Homepage: Mozilla\Firefox\Profiles\gw8bwnqt.default -> about:blank
FF Extension: (AdBlock) - C:\Users\Jack\AppData\Roaming\Mozilla\Firefox\Profiles\gw8bwnqt.default\Extensions\jid1-NIfFY2CA8fy1tg@jetpack.xpi [2017-11-16]
FF Extension: (Adblock Plus) - C:\Users\Jack\AppData\Roaming\Mozilla\Firefox\Profiles\gw8bwnqt.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2017-12-18]
FF HKLM-x32\...\Firefox\Extensions: [quickprint@hp.com] - C:\Program Files (x86)\Hewlett-Packard\SmartPrint\QPExtension
FF Extension: (SmartPrintButton) - C:\Program Files (x86)\Hewlett-Packard\SmartPrint\QPExtension [2011-01-26] [Legacy] [not signed]
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_28_0_0_137.dll [2018-01-15] ()
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_28_0_0_137.dll [2018-01-15] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\WINDOWS\SysWOW64\Adobe\Director\np32dsw_1221171.dll [2015-10-19] (Adobe Systems, Inc.)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-10-23] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-10-23] (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.161.2 -> C:\Program Files (x86)\Java\jre1.8.0_161\bin\dtplugin\npDeployJava1.dll [2018-01-22] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.161.2 -> C:\Program Files (x86)\Java\jre1.8.0_161\bin\plugin2\npjp2.dll [2018-01-22] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2018-01-19] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2018-01-19] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-14] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-14] (Google Inc.)
FF Plugin-x32: @ums.geocomply.com/GeoComply Update;version=3 -> C:\Program Files (x86)\GeoComply\Update\2.1.2.7\npGoogleUpdate3.dll [2015-10-19] (GeoComply Inc.)
FF Plugin-x32: @ums.geocomply.com/GeoComply Update;version=9 -> C:\Program Files (x86)\GeoComply\Update\2.1.2.7\npGoogleUpdate3.dll [2015-10-19] (GeoComply Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.6 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll [2013-08-05] ()
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2017-11-01] (Adobe Systems Inc.)
FF Plugin-x32: geocomply.com/player_location_check -> C:\Program Files (x86)\GeoComply\PlayerLocationCheck\Application\npapi\npplayer_location_check.dll [2017-07-10] (GeoComply)
FF Plugin HKU\S-1-5-21-2592302959-4100768495-3643388182-1001: @tools.google.com/Google Update;version=3 -> C:\Users\Jack\AppData\Local\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-14] (Google Inc.)
FF Plugin HKU\S-1-5-21-2592302959-4100768495-3643388182-1001: @tools.google.com/Google Update;version=9 -> C:\Users\Jack\AppData\Local\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-14] (Google Inc.)
 
Chrome: 
=======
CHR DefaultProfile: Default
CHR DefaultSearchURL: Default -> hxxps://search.yahoo.com/search?p={searchTerms}&fr=yset_chr_syc_oracle&type=default
CHR DefaultSearchKeyword: Default -> Yahoo
CHR DefaultSuggestURL: Default -> hxxps://search.yahoo.com/sugg/ie?output=fxjson&command={searchTerms}&nResults=10
CHR Profile: C:\Users\Jack\AppData\Local\Google\Chrome\User Data\Default [2018-02-01]
CHR Extension: (Slides) - C:\Users\Jack\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-01-29]
CHR Extension: (Docs) - C:\Users\Jack\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2018-01-29]
CHR Extension: (Google Drive) - C:\Users\Jack\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-01-29]
CHR Extension: (YouTube) - C:\Users\Jack\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-01-29]
CHR Extension: (Block Site: Website Blocker for Chrome™) - C:\Users\Jack\AppData\Local\Google\Chrome\User Data\Default\Extensions\eiimnmioipafcokbfikbljfdeojpcgbh [2018-01-31]
CHR Extension: (Sheets) - C:\Users\Jack\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-01-29]
CHR Extension: (Google Docs Offline) - C:\Users\Jack\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-01-29]
CHR Extension: (Application Launcher for Drive (by Google)) - C:\Users\Jack\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2018-01-29]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Jack\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-01-29]
CHR Extension: (Gmail) - C:\Users\Jack\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2018-01-29]
CHR Extension: (Chrome Media Router) - C:\Users\Jack\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-01-29]
CHR Profile: C:\Users\Jack\AppData\Local\Google\Chrome\User Data\Profile 1 [2018-01-27]
CHR Extension: (Google Slides) - C:\Users\Jack\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-10-15]
CHR Extension: (Google Docs) - C:\Users\Jack\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2015-10-15]
CHR Extension: (Google Drive) - C:\Users\Jack\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-15]
CHR Extension: (YouTube) - C:\Users\Jack\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-10-15]
CHR Extension: (Google Search) - C:\Users\Jack\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-15]
CHR Extension: (Google Sheets) - C:\Users\Jack\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-10-15]
CHR Extension: (Google Docs Offline) - C:\Users\Jack\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-10-15]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Jack\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-10-15]
CHR Extension: (Gmail) - C:\Users\Jack\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-10-15]
CHR Profile: C:\Users\Jack\AppData\Local\Google\Chrome\User Data\System Profile [2018-01-27]
CHR HKU\S-1-5-21-2592302959-4100768495-3643388182-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [commhkacjheiacaopdonmodahaoadoln] - hxxps://clients2.google.com/service/update2/crx
 
==================== Services (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
HKLM\SYSTEM\CurrentControlSet\Services\ntveglwx <==== ATTENTION (Rootkit!)
 
S2 AdAppMgrSvc; C:\Program Files (x86)\Autodesk\Autodesk Desktop App\AdAppMgrSvc.exe [1353208 2017-06-15] (Autodesk Inc.)
S3 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2017-10-11] (Apple Inc.)
S2 chromoting; C:\Program Files (x86)\Google\Chrome Remote Desktop\63.0.3239.32\remoting_host.exe [71512 2017-11-02] (Google Inc.)
S2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [7780528 2018-01-15] (Microsoft Corporation)
S2 DptfParticipantProcessorService; C:\WINDOWS\system32\DptfParticipantProcessorService.exe [117704 2013-10-17] (Intel Corporation)
S2 DptfPolicyConfigTDPService; C:\WINDOWS\system32\DptfPolicyConfigTDPService.exe [116680 2013-10-17] (Intel Corporation)
S2 DptfPolicyCriticalService; C:\WINDOWS\system32\DptfPolicyCriticalService.exe [148160 2013-10-17] (Intel Corporation)
S2 DptfPolicyLpmService; C:\WINDOWS\system32\DptfPolicyLpmService.exe [126952 2013-10-17] (Intel Corporation)
S2 GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [227904 2014-04-24] (WildTangent)
S2 HP LaserJet Service; C:\Program Files (x86)\HP\HPLaserJetService\HPLaserJetService.exe [136704 2009-06-24] (HP) [File not signed]
S2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [332144 2017-11-21] (HP Inc.)
S2 HPTouchpointAnalyticsService; C:\Program Files\HP\HP Touchpoint Analytics Client\TouchpointAnalyticsClientService.exe [332216 2017-11-26] (HP Inc.)
S2 igfxCUIService2.0.0.0; C:\WINDOWS\system32\igfxCUIService.exe [373728 2016-11-30] (Intel Corporation)
S3 Intel® Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [827392 2013-09-02] (Intel® Corporation) [File not signed]
S2 Intel® ME Service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe [131544 2013-10-23] (Intel Corporation)
S2 jhi_service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe [169432 2013-10-23] (Intel Corporation)
S2 MacriumService; C:\Program Files\Macrium\Common\MacriumService.exe [3878728 2017-02-25] (Paramount Software UK Ltd)
S3 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6058960 2017-08-21] (Malwarebytes)
S3 NETGEARGenieDaemon; C:\Program Files (x86)\NETGEAR Genie\bin\NETGEARGenieDaemon64.exe [233456 2017-07-04] (NETGEAR)
S2 SEVPNCLIENT; C:\Program Files\SoftEther VPN Client\vpnclient_x64.exe [5248456 2017-06-29] (SoftEther VPN Project at University of Tsukuba, Japan.)
S2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [10945776 2017-12-15] (TeamViewer GmbH)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.12.17007.18011-0\NisSrv.exe [356168 2018-01-19] (Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.12.17007.18011-0\MsMpEng.exe [105792 2018-01-19] (Microsoft Corporation)
S2 ZAtheros Bt and Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [323584 2014-06-17] (Atheros) [File not signed]
 
===================== Drivers (Whitelisted) ======================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R3 AsusTP; C:\WINDOWS\System32\drivers\AsusTP.sys [128024 2017-03-09] (ASUS Corporation)
S3 DFX11_1; C:\WINDOWS\system32\drivers\dfx11_1x64.sys [28008 2012-12-13] (Windows ® Win 7 DDK provider)
S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus.sys [131712 2016-09-05] (Samsung Electronics Co., Ltd.)
S3 DptfDevDram; C:\WINDOWS\system32\DRIVERS\DptfDevDram.sys [145640 2013-10-17] (Intel Corporation)
S3 DptfDevPch; C:\WINDOWS\system32\DRIVERS\DptfDevPch.sys [116752 2013-10-17] (Intel Corporation)
S3 DptfDevProc; C:\WINDOWS\system32\DRIVERS\DptfDevProc.sys [289744 2013-10-17] (Intel Corporation)
S3 DptfManager; C:\WINDOWS\system32\DRIVERS\DptfManager.sys [494296 2013-10-17] (Intel Corporation)
R3 kbfiltr; C:\WINDOWS\System32\drivers\kbfiltr.sys [17280 2012-08-05] ( )
R3 MEIx64; C:\WINDOWS\system32\DRIVERS\TeeDriverx64.sys [99288 2013-10-23] (Intel Corporation)
S0 mfeelamk; C:\WINDOWS\System32\drivers\mfeelamk.sys [82072 2015-08-10] (McAfee, Inc.)
S3 mvusbews; C:\WINDOWS\System32\Drivers\mvusbews.sys [20480 2012-09-26] (Marvell Semiconductor, Inc.)
S3 Neo_VPN; C:\WINDOWS\System32\drivers\Neo6_x64_VPN.sys [38216 2017-06-29] (SoftEther Corporation)
S2 NPF; C:\WINDOWS\system32\drivers\npf.sys [35344 2017-12-27] (CACE Technologies, Inc.)
U0 Partizan; C:\Windows\SysWOW64\drivers\Partizan.sys [40304 2018-01-27] (Greatis Software)
S3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [895256 2015-07-07] (Realtek )
R3 RTSUER; C:\WINDOWS\system32\Drivers\RtsUer.sys [420832 2017-04-06] (Realsil Semiconductor Corporation)
S3 RvNetMP60; C:\WINDOWS\System32\drivers\RvNetMP60.sys [72112 2017-07-21] (Famatech Corp.)
S1 SeLow; C:\WINDOWS\system32\DRIVERS\SeLow_x64.sys [51024 2017-06-29] (SoftEther Corporation)
S3 ssudmdm; C:\WINDOWS\system32\DRIVERS\ssudmdm.sys [165504 2016-09-05] (Samsung Electronics Co., Ltd.)
S1 UimBus; C:\WINDOWS\System32\drivers\UimBus.sys [102664 2014-10-29] ()
S1 Uim_DEVIM; C:\WINDOWS\System32\drivers\uim_devim.sys [25992 2014-10-29] ()
S1 Uim_IM; C:\WINDOWS\System32\drivers\uim_im.sys [700680 2014-10-29] ()
S3 WdBoot; C:\WINDOWS\system32\drivers\wd\WdBoot.sys [46072 2018-01-19] (Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\wd\WdFilter.sys [288848 2018-01-19] (Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [129616 2018-01-19] (Microsoft Corporation)
S1 msidntfs; system32\drivers\msidntfs.sys [X]
S3 xadhkn; system32\drivers\dgknqt.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2018-02-03 12:08 - 2018-02-03 12:17 - 000258114 _____ C:\WINDOWS\ntbtlog.txt
2018-02-03 12:07 - 2018-02-03 12:07 - 000142672 ____N C:\WINDOWS\system32\Drivers\vsssvybf.sys
2018-02-01 23:16 - 2018-02-01 23:16 - 000001082 _____ C:\Users\Jack\Desktop\UnHackMe.lnk
2018-02-01 11:19 - 2018-02-01 11:19 - 000000785 _____ C:\Users\Jack\Desktop\stocks.txt
2018-02-01 11:06 - 2018-02-01 23:03 - 000000648 _____ C:\WINDOWS\Tasks\G2MUploadTask-S-1-5-21-2592302959-4100768495-3643388182-1001.job
2018-02-01 11:06 - 2018-02-01 23:03 - 000000552 _____ C:\WINDOWS\Tasks\G2MUpdateTask-S-1-5-21-2592302959-4100768495-3643388182-1001.job
2018-02-01 11:06 - 2018-02-01 11:06 - 000003808 _____ C:\WINDOWS\System32\Tasks\G2MUploadTask-S-1-5-21-2592302959-4100768495-3643388182-1001
2018-02-01 11:06 - 2018-02-01 11:06 - 000003712 _____ C:\WINDOWS\System32\Tasks\G2MUpdateTask-S-1-5-21-2592302959-4100768495-3643388182-1001
2018-02-01 11:06 - 2018-02-01 11:06 - 000000000 ____D C:\Users\Jack\AppData\Local\GoToMeeting
2018-02-01 11:05 - 2018-02-01 11:05 - 000000000 ____D C:\Users\Jack\AppData\Local\GoTo Opener
2018-01-30 22:41 - 2018-01-30 22:41 - 000001722 _____ C:\Users\Public\Desktop\DFX.lnk
2018-01-30 22:41 - 2018-01-30 22:41 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DFX Audio Enhancer
2018-01-30 22:41 - 2018-01-30 22:41 - 000000000 ____D C:\Program Files (x86)\DFX
2018-01-30 22:40 - 2018-01-30 22:40 - 004863240 _____ (Power Technology) C:\Users\Jack\Downloads\dfx11Setup_11-400 (1).exe
2018-01-30 22:39 - 2018-01-30 22:40 - 004863240 _____ (Power Technology) C:\Users\Jack\Downloads\dfx11Setup_11-400.exe
2018-01-30 08:21 - 2018-01-30 08:21 - 000000769 _____ C:\Users\Jack\Downloads\Fixlog.txt
2018-01-29 20:48 - 2018-01-29 20:48 - 000000000 ____D C:\Users\Jack\AppData\Roaming\Radmin
2018-01-29 20:14 - 2018-01-29 20:16 - 000083889 _____ C:\Users\Jack\Downloads\Addition.txt
2018-01-29 20:11 - 2018-02-03 12:18 - 000000000 ____D C:\FRST
2018-01-29 20:11 - 2018-01-29 20:16 - 000088062 _____ C:\Users\Jack\Downloads\FRST.txt
2018-01-29 20:09 - 2018-01-29 20:09 - 002393088 _____ (Farbar) C:\Users\Jack\Downloads\FRST64.exe
2018-01-29 19:53 - 2018-01-29 19:53 - 036430896 _____ (Adlice Software ) C:\Users\Jack\Downloads\RogueKiller_setup.exe
2018-01-29 19:48 - 2018-01-29 19:48 - 000255928 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\1267B2ED.sys
2018-01-29 19:47 - 2018-01-30 08:18 - 000000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2018-01-29 19:46 - 2018-01-30 08:18 - 000000000 ____D C:\Users\Jack\Desktop\mbar
2018-01-29 19:44 - 2018-01-29 19:44 - 014178840 _____ (Malwarebytes Corp.) C:\Users\Jack\Downloads\mbar-1.10.3.1001.exe
2018-01-27 23:10 - 2018-01-27 23:10 - 000040304 _____ (Greatis Software) C:\WINDOWS\SysWOW64\Drivers\Partizan.sys
2018-01-27 23:02 - 2018-02-03 12:08 - 000000250 _____ C:\WINDOWS\SysWOW64\PARTIZAN.TXT
2018-01-27 22:55 - 2018-01-27 23:21 - 000000000 ____D C:\@RestoreQuarantine
2018-01-27 19:35 - 2018-02-01 23:18 - 000000000 ____D C:\ProgramData\RegRun
2018-01-27 19:33 - 2018-02-01 23:43 - 000000000 ____D C:\Users\Jack\Documents\RegRun2
2018-01-27 19:33 - 2018-02-01 23:19 - 000000000 ____D C:\Users\Public\Documents\regruninfo
2018-01-27 19:33 - 2018-02-01 23:16 - 000003410 _____ C:\WINDOWS\System32\Tasks\UnHackMe Task Scheduler
2018-01-27 19:33 - 2018-02-01 23:16 - 000000002 RSHOT C:\WINDOWS\winstart.bat
2018-01-27 19:33 - 2018-02-01 23:16 - 000000002 RSHOT C:\WINDOWS\SysWOW64\CONFIG.NT
2018-01-27 19:33 - 2018-02-01 23:16 - 000000002 RSHOT C:\WINDOWS\SysWOW64\AUTOEXEC.NT
2018-01-27 19:33 - 2018-02-01 23:16 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UnHackMe
2018-01-27 19:33 - 2018-02-01 23:16 - 000000000 ____D C:\Program Files (x86)\UnHackMe
2018-01-27 19:33 - 2018-01-26 19:40 - 000001320 _____ C:\WINDOWS\system32\Drivers\etc\hosts.old
2018-01-27 19:33 - 2017-12-13 17:47 - 000014984 _____ (Greatis Software, LLC.) C:\WINDOWS\SysWOW64\Drivers\UnHackMeDrv.sys
2018-01-27 19:33 - 2015-12-28 11:32 - 000049968 _____ (Greatis Software) C:\WINDOWS\system32\partizan.exe
2018-01-27 18:42 - 2018-01-27 18:42 - 000007690 _____ C:\Users\Jack\Documents\cc_20180127_184201.reg
2018-01-27 18:33 - 2018-02-03 12:09 - 000000214 _____ C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job
2018-01-27 18:31 - 2018-01-27 19:10 - 000000000 ____D C:\WINDOWS\pss
2018-01-27 01:04 - 2018-01-27 01:04 - 000027358 _____ C:\Users\Jack\Documents\cc_20180127_010416.reg
2018-01-26 22:38 - 2018-01-26 22:38 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2018-01-26 22:09 - 2018-01-26 22:09 - 000000000 ____D C:\Program Files (x86)\QzeHcYPJTlaRogMtwuR
2018-01-26 22:09 - 2018-01-26 22:09 - 000000000 ____D C:\Program Files (x86)\CRzlyHUwXjzU2
2018-01-26 22:09 - 2018-01-26 22:09 - 000000000 ____D C:\Program Files (x86)\abmzSTWtfatSC
2018-01-26 22:08 - 2018-01-27 22:55 - 000000000 ____D C:\Disk
2018-01-26 22:08 - 2018-01-26 22:48 - 000624664 _____ C:\WINDOWS\system32\NETUTILS2016.del
2018-01-26 22:08 - 2018-01-26 22:08 - 000014040 _____ C:\WINDOWS\system32\Drivers\NETUTILS2016.del
2018-01-26 22:08 - 2018-01-26 22:08 - 000000000 ____D C:\WINDOWS\system32\sstmp
2018-01-26 22:08 - 2018-01-26 22:08 - 000000000 ____D C:\Windat
2018-01-26 22:08 - 2018-01-26 22:08 - 000000000 ____D C:\Users\Jack\AppData\Roaming\1n0acejoj3w
2018-01-26 22:08 - 2018-01-26 22:08 - 000000000 ____D C:\Program Files (x86)\ELYwNrqgcQUn
2018-01-26 22:07 - 2018-01-27 22:55 - 000000000 ____D C:\WINDOWS\SysWOW64\NVDIADISPLAY
2018-01-26 22:07 - 2018-01-26 22:09 - 000000000 ____D C:\Program Files (x86)\rPUXzMQWU
2018-01-26 22:07 - 2018-01-26 22:08 - 001377280 _____ C:\WINDOWS\WINDEFENDER.EXE.del
2018-01-26 22:07 - 2018-01-26 22:07 - 000000103 _____ C:\WINDOWS\SysWOW64\del.bat
2018-01-26 22:07 - 2018-01-26 22:07 - 000000000 _RSHD C:\RecoveryLog
2018-01-26 22:07 - 2018-01-26 22:07 - 000000000 ____D C:\Program Files (x86)\repository
2018-01-26 19:41 - 2018-01-27 23:17 - 000000000 ____D C:\WINDOWS\System32\Tasks\System
2018-01-26 19:38 - 2018-01-31 01:20 - 000000000 ____D C:\Users\Jack\AppData\Local\scitmvo
2018-01-26 19:34 - 2018-02-03 12:11 - 000000000 ____D C:\Users\Jack\AppData\Local\atmibgl
2018-01-26 19:34 - 2018-01-26 19:37 - 000000000 ____D C:\Users\Jack\AppData\Local\wimxehg
2018-01-26 19:33 - 2018-02-03 12:08 - 002888704 _____ (TOSHIBA CORPORATION) C:\WINDOWS\system32\vdhkexasvc.exe
2018-01-26 19:33 - 2018-01-26 19:33 - 000000000 ____D C:\WINDOWS\SysWOW64\dsektwl
2018-01-26 19:33 - 2018-01-26 19:33 - 000000000 ____D C:\WINDOWS\system32\dsektwl
2018-01-26 19:32 - 2018-01-26 19:32 - 000000020 _____ C:\WINDOWS\b17766592
2018-01-26 19:32 - 2018-01-26 19:32 - 000000000 ____D C:\Users\Jack\AppData\Roaming\et
2018-01-26 19:31 - 2018-01-26 19:31 - 000000000 ___HD C:\Program Files (x86)\ventilators
2018-01-26 19:31 - 2018-01-26 19:31 - 000000000 ____D C:\Program Files (x86)\uninterruptable
2018-01-26 19:30 - 2018-01-26 19:30 - 000000000 ___HD C:\Program Files (x86)\Mass
2018-01-26 19:19 - 2018-01-26 19:19 - 000860160 _____ C:\WINDOWS\efee4b7794bddd58ee45bcdb44294b82.dll
2018-01-26 19:16 - 2018-01-26 19:16 - 000000000 ____D C:\Users\Jack\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AnonymizerGadget
2018-01-26 18:45 - 2018-01-26 18:45 - 000000000 ____D C:\Users\Jack\AppData\Local\DFX
2018-01-26 18:25 - 2018-01-26 18:25 - 000000000 ____D C:\Users\WDAGUtilityAccount\AppData\Roaming\vlc
2018-01-26 18:25 - 2018-01-26 18:25 - 000000000 ____D C:\Users\WDAGUtilityAccount
2018-01-26 18:25 - 2018-01-26 18:25 - 000000000 ____D C:\Users\steph\AppData\Roaming\vlc
2018-01-26 18:25 - 2018-01-26 18:25 - 000000000 ____D C:\Users\HomeGroupUser$\AppData\Roaming\vlc
2018-01-26 18:25 - 2018-01-26 18:25 - 000000000 ____D C:\Users\HomeGroupUser$
2018-01-26 18:25 - 2018-01-26 18:25 - 000000000 ____D C:\Users\Guest\AppData\Roaming\vlc
2018-01-26 18:25 - 2018-01-26 18:25 - 000000000 ____D C:\Users\Guest
2018-01-26 18:25 - 2018-01-26 18:25 - 000000000 ____D C:\Users\DefaultAccount\AppData\Roaming\vlc
2018-01-26 18:25 - 2018-01-26 18:25 - 000000000 ____D C:\Users\DefaultAccount
2018-01-26 18:25 - 2018-01-26 18:25 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\vlc
2018-01-26 18:25 - 2018-01-26 18:25 - 000000000 ____D C:\Users\Administrator
2018-01-26 17:58 - 2018-01-26 17:58 - 000011264 _____ C:\Users\Jack\AppData\Local\knudsen.exe
2018-01-26 17:58 - 2018-01-26 17:58 - 000010752 _____ C:\WINDOWS\bingley.exe
2018-01-26 17:58 - 2018-01-26 17:58 - 000010752 _____ C:\Users\Jack\AppData\Local\gunny.exe
2018-01-26 06:26 - 2018-01-26 06:26 - 000710656 _____ C:\WINDOWS\6a911afd6370c5dffeabbc69535591cc.exe
2018-01-26 06:26 - 2018-01-26 06:26 - 000035754 _____ C:\WINDOWS\uninstaller.dat
2018-01-26 06:26 - 2018-01-26 06:26 - 000014040 _____ C:\WINDOWS\system32\Drivers\194b204a839f28feaade11c964338f7d.sys
2018-01-24 15:22 - 2018-01-26 10:20 - 000000189 _____ C:\Users\Jack\Desktop\Lords.txt
2018-01-23 11:45 - 2018-01-23 11:45 - 000000000 ____D C:\ProgramData\Wondershare
2018-01-23 11:35 - 2017-10-19 10:17 - 000271360 _____ (Wondershare Software) C:\WINDOWS\system32\WSPDFelementMonitor.dll
2018-01-23 11:34 - 2018-01-23 11:34 - 000000000 ____D C:\Users\Jack\AppData\Local\Wondershare
2018-01-23 11:31 - 2018-01-23 12:35 - 000000000 ____D C:\Users\Jack\AppData\Roaming\Wondershare
2018-01-23 11:31 - 2018-01-23 11:31 - 000000000 ____D C:\ProgramData\PDFelement 6 Pro
2018-01-23 11:31 - 2018-01-23 11:31 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wondershare
2018-01-23 11:31 - 2018-01-23 11:31 - 000000000 ____D C:\Program Files (x86)\Wondershare
2018-01-23 11:30 - 2018-01-23 11:35 - 000000000 ____D C:\Users\Public\Documents\Wondershare
2018-01-23 11:06 - 2018-01-23 11:06 - 000166960 _____ C:\Users\Jack\Desktop\bookbag.pdf
2018-01-22 22:08 - 2018-01-22 22:09 - 000000000 ____D C:\Users\Jack\Desktop\2017 Tax
2018-01-22 20:03 - 2018-01-22 20:03 - 000193220 _____ C:\Users\Jack\Desktop\Un Emp.pdf
2018-01-22 11:50 - 2018-01-22 11:50 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TomTom
2018-01-22 11:42 - 2018-01-22 11:53 - 000000000 ____D C:\Users\Jack\Documents\Outlook Files
2018-01-21 17:57 - 2018-01-21 17:57 - 000000000 ____D C:\Users\steph\AppData\Local\EZ CD Audio Converter
2018-01-19 17:23 - 2018-01-19 17:23 - 000000824 _____ C:\Users\Jack\Documents\cc_20180119_172318.reg
2018-01-18 23:14 - 2018-01-18 23:14 - 000007658 _____ C:\Users\Jack\Documents\cc_20180118_231433.reg
2018-01-16 18:47 - 2018-01-16 18:47 - 000006628 _____ C:\Users\steph\Downloads\Martinez S.pdf
2018-01-10 11:05 - 2018-01-22 11:41 - 000000000 ____D C:\Users\Jack\Desktop\New Expense Reports
2018-01-07 13:23 - 2018-01-07 13:25 - 000000000 ____D C:\Users\Jack\Desktop\4Sale
2018-01-06 20:29 - 2018-01-06 20:29 - 000000594 _____ C:\Users\Jack\Documents\cc_20180106_202904.reg
2018-01-05 14:35 - 2018-01-05 14:35 - 000005408 _____ C:\Users\Jack\Documents\cc_20180105_143520.reg
2018-01-04 21:37 - 2018-01-01 06:25 - 000344576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgeIso.dll
2018-01-04 21:37 - 2018-01-01 06:24 - 000202240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxAllUserStore.dll
2018-01-04 21:37 - 2018-01-01 06:20 - 018917888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2018-01-04 21:37 - 2018-01-01 06:19 - 000369152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msIso.dll
2018-01-04 21:37 - 2018-01-01 06:17 - 000559104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll
2018-01-04 21:37 - 2018-01-01 06:16 - 000463360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2018-01-04 21:36 - 2018-01-01 12:15 - 000956416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Spectrum.exe
2018-01-04 21:36 - 2018-01-01 07:51 - 001414784 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2018-01-04 21:36 - 2018-01-01 07:51 - 001209240 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2018-01-04 21:36 - 2018-01-01 07:51 - 001055128 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2018-01-04 21:36 - 2018-01-01 07:51 - 000059800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bam.sys
2018-01-04 21:36 - 2018-01-01 07:50 - 005905752 _____ (Microsoft Corporation) C:\WINDOWS\system32\StartTileData.dll
2018-01-04 21:36 - 2018-01-01 07:50 - 000780464 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2018-01-04 21:36 - 2018-01-01 07:49 - 008605080 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2018-01-04 21:36 - 2018-01-01 07:49 - 000319352 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64.dll
2018-01-04 21:36 - 2018-01-01 07:48 - 007831760 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d10warp.dll
2018-01-04 21:36 - 2018-01-01 07:48 - 001954048 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2018-01-04 21:36 - 2018-01-01 07:47 - 000082840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\volmgr.sys
2018-01-04 21:36 - 2018-01-01 07:46 - 002709704 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2018-01-04 21:36 - 2018-01-01 07:46 - 000471960 _____ (Microsoft Corporation) C:\WINDOWS\system32\hal.dll
2018-01-04 21:36 - 2018-01-01 07:45 - 002395032 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
2018-01-04 21:36 - 2018-01-01 07:45 - 001277848 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys
2018-01-04 21:36 - 2018-01-01 07:45 - 000398744 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fltMgr.sys
2018-01-04 21:36 - 2018-01-01 07:42 - 000571288 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\spaceport.sys
2018-01-04 21:36 - 2018-01-01 07:42 - 000184984 _____ (Microsoft Corporation) C:\WINDOWS\system32\sspicli.dll
2018-01-04 21:36 - 2018-01-01 07:41 - 007676296 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2018-01-04 21:36 - 2018-01-01 07:41 - 000559512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storport.sys
2018-01-04 21:36 - 2018-01-01 07:40 - 001206680 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2018-01-04 21:36 - 2018-01-01 07:39 - 000902416 _____ (Microsoft Corporation) C:\WINDOWS\system32\winhttp.dll
2018-01-04 21:36 - 2018-01-01 07:39 - 000677784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2018-01-04 21:36 - 2018-01-01 07:39 - 000362904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pci.sys
2018-01-04 21:36 - 2018-01-01 07:39 - 000129432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hvsocket.sys
2018-01-04 21:36 - 2018-01-01 07:38 - 003904808 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2018-01-04 21:36 - 2018-01-01 07:38 - 000519152 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthService.exe
2018-01-04 21:36 - 2018-01-01 07:37 - 001426664 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
2018-01-04 21:36 - 2018-01-01 07:36 - 000374032 _____ (Microsoft Corporation) C:\WINDOWS\system32\vac.exe
2018-01-04 21:36 - 2018-01-01 07:36 - 000166296 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\partmgr.sys
2018-01-04 21:36 - 2018-01-01 07:35 - 001170008 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2018-01-04 21:36 - 2018-01-01 07:34 - 007385088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2018-01-04 21:36 - 2018-01-01 07:33 - 000603920 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
2018-01-04 21:36 - 2018-01-01 07:32 - 004481240 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2018-01-04 21:36 - 2018-01-01 07:27 - 000713624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vhdmp.sys
2018-01-04 21:36 - 2018-01-01 07:26 - 000428952 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdbss.sys
2018-01-04 21:36 - 2018-01-01 07:25 - 000615768 _____ (Microsoft Corporation) C:\WINDOWS\system32\services.exe
2018-01-04 21:36 - 2018-01-01 07:25 - 000147864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wcifs.sys
2018-01-04 21:36 - 2018-01-01 07:23 - 021352144 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2018-01-04 21:36 - 2018-01-01 07:03 - 000650328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2018-01-04 21:36 - 2018-01-01 07:03 - 000123512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sspicli.dll
2018-01-04 21:36 - 2018-01-01 06:53 - 001615712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2018-01-04 21:36 - 2018-01-01 06:46 - 003485392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2018-01-04 21:36 - 2018-01-01 06:45 - 006092152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2018-01-04 21:36 - 2018-01-01 06:45 - 005615968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d10warp.dll
2018-01-04 21:36 - 2018-01-01 06:45 - 002192624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2018-01-04 21:36 - 2018-01-01 06:43 - 020286120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2018-01-04 21:36 - 2018-01-01 06:42 - 006479552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2018-01-04 21:36 - 2018-01-01 06:42 - 004644912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2018-01-04 21:36 - 2018-01-01 06:42 - 001246432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioEng.dll
2018-01-04 21:36 - 2018-01-01 06:42 - 000982528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
2018-01-04 21:36 - 2018-01-01 06:37 - 025247232 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2018-01-04 21:36 - 2018-01-01 06:34 - 000703568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winhttp.dll
2018-01-04 21:36 - 2018-01-01 06:25 - 002905600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2018-01-04 21:36 - 2018-01-01 06:25 - 001008640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallService.dll
2018-01-04 21:36 - 2018-01-01 06:25 - 000097792 _____ C:\WINDOWS\system32\runexehelper.exe
2018-01-04 21:36 - 2018-01-01 06:24 - 003668480 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2018-01-04 21:36 - 2018-01-01 06:23 - 001313792 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallService.dll
2018-01-04 21:36 - 2018-01-01 06:23 - 000536576 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgeIso.dll
2018-01-04 21:36 - 2018-01-01 06:23 - 000250368 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxAllUserStore.dll
2018-01-04 21:36 - 2018-01-01 06:21 - 000192512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\netvsc.sys
2018-01-04 21:36 - 2018-01-01 06:20 - 019337216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2018-01-04 21:36 - 2018-01-01 06:20 - 000204288 _____ (Microsoft Corporation) C:\WINDOWS\system32\provisioningcsp.dll
2018-01-04 21:36 - 2018-01-01 06:19 - 008014848 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2018-01-04 21:36 - 2018-01-01 06:19 - 000461312 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansec.dll
2018-01-04 21:36 - 2018-01-01 06:19 - 000450048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TileDataRepository.dll
2018-01-04 21:36 - 2018-01-01 06:19 - 000365568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll
2018-01-04 21:36 - 2018-01-01 06:19 - 000334848 _____ (Microsoft Corporation) C:\WINDOWS\system32\dusmsvc.dll
2018-01-04 21:36 - 2018-01-01 06:19 - 000073216 _____ (Microsoft Corporation) C:\WINDOWS\system32\provtool.exe
2018-01-04 21:36 - 2018-01-01 06:18 - 000432640 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll
2018-01-04 21:36 - 2018-01-01 06:18 - 000431616 _____ (Microsoft Corporation) C:\WINDOWS\system32\msIso.dll
2018-01-04 21:36 - 2018-01-01 06:18 - 000427008 _____ (Microsoft Corporation) C:\WINDOWS\system32\provhandlers.dll
2018-01-04 21:36 - 2018-01-01 06:18 - 000374784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FirewallAPI.dll
2018-01-04 21:36 - 2018-01-01 06:18 - 000261632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll
2018-01-04 21:36 - 2018-01-01 06:17 - 011923968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2018-01-04 21:36 - 2018-01-01 06:17 - 006564864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
2018-01-04 21:36 - 2018-01-01 06:17 - 000708096 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll
2018-01-04 21:36 - 2018-01-01 06:17 - 000568832 _____ (Microsoft Corporation) C:\WINDOWS\system32\TileDataRepository.dll
2018-01-04 21:36 - 2018-01-01 06:17 - 000542208 _____ (Microsoft Corporation) C:\WINDOWS\system32\FirewallAPI.dll
2018-01-04 21:36 - 2018-01-01 06:16 - 005833216 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbgeng.dll
2018-01-04 21:36 - 2018-01-01 06:16 - 003676672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2018-01-04 21:36 - 2018-01-01 06:16 - 000815616 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll
2018-01-04 21:36 - 2018-01-01 06:16 - 000812544 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll
2018-01-04 21:36 - 2018-01-01 06:16 - 000720896 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll
2018-01-04 21:36 - 2018-01-01 06:16 - 000664576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2018-01-04 21:36 - 2018-01-01 06:16 - 000594944 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2018-01-04 21:36 - 2018-01-01 06:15 - 012687872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll
2018-01-04 21:36 - 2018-01-01 06:15 - 006029312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2018-01-04 21:36 - 2018-01-01 06:15 - 000588800 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll
2018-01-04 21:36 - 2018-01-01 06:14 - 023655936 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2018-01-04 21:36 - 2018-01-01 06:14 - 002465280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2018-01-04 21:36 - 2018-01-01 06:14 - 001495040 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
2018-01-04 21:36 - 2018-01-01 06:13 - 013657600 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll
2018-01-04 21:36 - 2018-01-01 06:13 - 012830208 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2018-01-04 21:36 - 2018-01-01 06:13 - 003121664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Bluetooth.Profiles.Gatt.dll
2018-01-04 21:36 - 2018-01-01 06:13 - 002869760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2018-01-04 21:36 - 2018-01-01 06:13 - 001559552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2018-01-04 21:36 - 2018-01-01 06:12 - 002633216 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2018-01-04 21:36 - 2018-01-01 06:12 - 002208768 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2018-01-04 21:36 - 2018-01-01 06:12 - 001547776 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2018-01-04 21:36 - 2018-01-01 06:12 - 001424896 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
2018-01-04 21:36 - 2018-01-01 06:11 - 008108544 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2018-01-04 21:36 - 2018-01-01 06:11 - 004748288 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2018-01-04 21:36 - 2018-01-01 06:11 - 003334144 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2018-01-04 21:36 - 2018-01-01 06:11 - 003165696 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2018-01-04 21:36 - 2018-01-01 06:11 - 002859520 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2018-01-04 21:36 - 2018-01-01 06:11 - 001822208 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2018-01-04 21:36 - 2018-01-01 06:11 - 001231872 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll
2018-01-04 21:36 - 2018-01-01 06:11 - 000880640 _____ (Microsoft Corporation) C:\WINDOWS\system32\schedsvc.dll
2018-01-04 21:36 - 2018-01-01 06:11 - 000812032 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2018-01-04 21:36 - 2018-01-01 06:09 - 001487872 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2018-01-04 21:36 - 2018-01-01 06:09 - 000925184 _____ (Microsoft Corporation) C:\WINDOWS\system32\MPSSVC.dll
2018-01-04 21:36 - 2018-01-01 06:08 - 000726016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv2.sys
2018-01-04 21:36 - 2018-01-01 06:08 - 000685056 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2018-01-04 21:36 - 2018-01-01 06:08 - 000424448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv.sys
2018-01-04 21:36 - 2018-01-01 06:05 - 002510848 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngine.dll
2018-01-04 21:36 - 2018-01-01 06:05 - 001160704 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll
2018-01-04 21:35 - 2018-01-01 07:54 - 000924648 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2018-01-04 21:35 - 2018-01-01 07:53 - 001090984 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2018-01-04 21:35 - 2018-01-01 07:52 - 000066712 _____ (Microsoft Corporation) C:\WINDOWS\system32\iumcrypt.dll
2018-01-04 21:35 - 2018-01-01 07:51 - 000191816 _____ (Microsoft Corporation) C:\WINDOWS\system32\skci.dll
2018-01-04 21:35 - 2018-01-01 07:50 - 000479912 _____ (Microsoft Corporation) C:\WINDOWS\system32\ucrtbase_enclave.dll
2018-01-04 21:35 - 2018-01-01 07:50 - 000077208 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.dll
2018-01-04 21:35 - 2018-01-01 07:49 - 000599448 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe
2018-01-04 21:35 - 2018-01-01 07:49 - 000292376 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscapi.dll
2018-01-04 21:35 - 2018-01-01 07:48 - 000382360 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
2018-01-04 21:35 - 2018-01-01 07:47 - 000649304 _____ (Microsoft Corporation) C:\WINDOWS\system32\advapi32.dll
2018-01-04 21:35 - 2018-01-01 07:46 - 000898216 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll
2018-01-04 21:35 - 2018-01-01 07:46 - 000733592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\acpi.sys
2018-01-04 21:35 - 2018-01-01 07:43 - 001173576 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcrt4.dll
2018-01-04 21:35 - 2018-01-01 07:43 - 000367336 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Storage.ApplicationData.dll
2018-01-04 21:35 - 2018-01-01 07:43 - 000062872 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fsdepends.sys
2018-01-04 21:35 - 2018-01-01 07:42 - 001029016 _____ (Microsoft Corporation) C:\WINDOWS\system32\efscore.dll
2018-01-04 21:35 - 2018-01-01 07:42 - 000494488 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcasvc.dll
2018-01-04 21:35 - 2018-01-01 07:42 - 000109976 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vmbus.sys
2018-01-04 21:35 - 2018-01-01 07:41 - 000549552 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWanAPI.dll
2018-01-04 21:35 - 2018-01-01 07:39 - 000508264 _____ (Microsoft Corporation) C:\WINDOWS\system32\systemreset.exe
2018-01-04 21:35 - 2018-01-01 07:38 - 000727448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fvevol.sys
2018-01-04 21:35 - 2018-01-01 07:38 - 000103320 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\stornvme.sys
2018-01-04 21:35 - 2018-01-01 07:38 - 000038808 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Diskdump.sys
2018-01-04 21:35 - 2018-01-01 07:37 - 000461720 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifitask.exe
2018-01-04 21:35 - 2018-01-01 07:36 - 000413888 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll
2018-01-04 21:35 - 2018-01-01 07:36 - 000113560 _____ (Microsoft Corporation) C:\WINDOWS\system32\icfupgd.dll
2018-01-04 21:35 - 2018-01-01 07:36 - 000057752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\netbios.sys
2018-01-04 21:35 - 2018-01-01 07:35 - 000075160 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthProxyStub.dll
2018-01-04 21:35 - 2018-01-01 07:34 - 001336344 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll
2018-01-04 21:35 - 2018-01-01 07:34 - 000260896 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
2018-01-04 21:35 - 2018-01-01 07:34 - 000087384 _____ (Microsoft Corporation) C:\WINDOWS\system32\remoteaudioendpoint.dll
2018-01-04 21:35 - 2018-01-01 07:33 - 002773400 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2018-01-04 21:35 - 2018-01-01 07:32 - 000617304 _____ (Microsoft Corporation) C:\WINDOWS\system32\TextInputFramework.dll
2018-01-04 21:35 - 2018-01-01 07:27 - 000163736 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wfplwfs.sys
2018-01-04 21:35 - 2018-01-01 07:26 - 000081304 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vmbkmcl.sys
2018-01-04 21:35 - 2018-01-01 07:21 - 001103768 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\http.sys
2018-01-04 21:35 - 2018-01-01 07:21 - 000614296 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\afd.sys
2018-01-04 21:35 - 2018-01-01 07:06 - 000311192 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
2018-01-04 21:35 - 2018-01-01 07:03 - 000777904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rpcrt4.dll
2018-01-04 21:35 - 2018-01-01 07:03 - 000566664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll
2018-01-04 21:35 - 2018-01-01 06:49 - 000481464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\advapi32.dll
2018-01-04 21:35 - 2018-01-01 06:49 - 000258808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscapi.dll
2018-01-04 21:35 - 2018-01-01 06:46 - 000289816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Storage.ApplicationData.dll
2018-01-04 21:35 - 2018-01-01 06:45 - 000450928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWanAPI.dll
2018-01-04 21:35 - 2018-01-01 06:42 - 001003152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll
2018-01-04 21:35 - 2018-01-01 06:42 - 000386424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AUDIOKSE.dll
2018-01-04 21:35 - 2018-01-01 06:42 - 000129184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfps.dll
2018-01-04 21:35 - 2018-01-01 06:42 - 000074992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\remoteaudioendpoint.dll
2018-01-04 21:35 - 2018-01-01 06:25 - 000475648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieui.dll
2018-01-04 21:35 - 2018-01-01 06:24 - 000240640 _____ (Microsoft Corporation) C:\WINDOWS\system32\AboutSettingsHandlers.dll
2018-01-04 21:35 - 2018-01-01 06:24 - 000096256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontsub.dll
2018-01-04 21:35 - 2018-01-01 06:24 - 000038912 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
2018-01-04 21:35 - 2018-01-01 06:23 - 000561152 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieui.dll
2018-01-04 21:35 - 2018-01-01 06:23 - 000385024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cldflt.sys
2018-01-04 21:35 - 2018-01-01 06:23 - 000232960 _____ (Microsoft Corporation) C:\WINDOWS\system32\convertvhd.exe
2018-01-04 21:35 - 2018-01-01 06:23 - 000121344 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontsub.dll
2018-01-04 21:35 - 2018-01-01 06:23 - 000080384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vmbkmclr.sys
2018-01-04 21:35 - 2018-01-01 06:23 - 000047104 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2018-01-04 21:35 - 2018-01-01 06:22 - 000031744 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Management.Provisioning.ProxyStub.dll
2018-01-04 21:35 - 2018-01-01 06:22 - 000025600 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Dumpstorport.sys
2018-01-04 21:35 - 2018-01-01 06:22 - 000017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\VmApplicationHealthMonitorProxy.dll
2018-01-04 21:35 - 2018-01-01 06:21 - 000268288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll
2018-01-04 21:35 - 2018-01-01 06:21 - 000233984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppLockerCSP.dll
2018-01-04 21:35 - 2018-01-01 06:21 - 000133632 _____ (Microsoft Corporation) C:\WINDOWS\system32\wificonnapi.dll
2018-01-04 21:35 - 2018-01-01 06:21 - 000097280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WcnApi.dll
2018-01-04 21:35 - 2018-01-01 06:21 - 000097280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\raspptp.sys
2018-01-04 21:35 - 2018-01-01 06:21 - 000080896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wanarp.sys
2018-01-04 21:35 - 2018-01-01 06:21 - 000062976 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndproxy.sys
2018-01-04 21:35 - 2018-01-01 06:20 - 000524288 _____ (Microsoft Corporation) C:\WINDOWS\system32\daxexec.dll
2018-01-04 21:35 - 2018-01-01 06:20 - 000459776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webplatstorageserver.dll
2018-01-04 21:35 - 2018-01-01 06:20 - 000397824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtmsft.dll
2018-01-04 21:35 - 2018-01-01 06:20 - 000225792 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\winnat.sys
2018-01-04 21:35 - 2018-01-01 06:20 - 000215552 _____ (Microsoft Corporation) C:\WINDOWS\system32\fwpolicyiomgr.dll
2018-01-04 21:35 - 2018-01-01 06:20 - 000212992 _____ (Microsoft Corporation) C:\WINDOWS\system32\container.dll
2018-01-04 21:35 - 2018-01-01 06:20 - 000186368 _____ (Microsoft Corporation) C:\WINDOWS\system32\ACPBackgroundManagerPolicy.dll
2018-01-04 21:35 - 2018-01-01 06:20 - 000175616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fwpolicyiomgr.dll
2018-01-04 21:35 - 2018-01-01 06:20 - 000134656 _____ (Microsoft Corporation) C:\WINDOWS\system32\WcnApi.dll
2018-01-04 21:35 - 2018-01-01 06:20 - 000133632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iepeers.dll
2018-01-04 21:35 - 2018-01-01 06:20 - 000104960 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasauto.dll
2018-01-04 21:35 - 2018-01-01 06:20 - 000082432 _____ (Microsoft Corporation) C:\WINDOWS\system32\SCardDlg.dll
2018-01-04 21:35 - 2018-01-01 06:20 - 000043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\RfxVmt.sys
2018-01-04 21:35 - 2018-01-01 06:20 - 000035328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\nshhttp.dll
2018-01-04 21:35 - 2018-01-01 06:19 - 000795136 _____ (Microsoft Corporation) C:\WINDOWS\system32\NaturalAuth.dll
2018-01-04 21:35 - 2018-01-01 06:19 - 000675328 _____ (Microsoft Corporation) C:\WINDOWS\system32\webplatstorageserver.dll
2018-01-04 21:35 - 2018-01-01 06:19 - 000430080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Bluetooth.dll
2018-01-04 21:35 - 2018-01-01 06:19 - 000416768 _____ (Microsoft Corporation) C:\WINDOWS\system32\html.iec
2018-01-04 21:35 - 2018-01-01 06:19 - 000366080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\daxexec.dll
2018-01-04 21:35 - 2018-01-01 06:19 - 000340480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\html.iec
2018-01-04 21:35 - 2018-01-01 06:19 - 000316928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\netbt.sys
2018-01-04 21:35 - 2018-01-01 06:19 - 000188416 _____ (Microsoft Corporation) C:\WINDOWS\system32\PimIndexMaintenance.dll
2018-01-04 21:35 - 2018-01-01 06:19 - 000174592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\P2P.dll
2018-01-04 21:35 - 2018-01-01 06:19 - 000149504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\container.dll
2018-01-04 21:35 - 2018-01-01 06:19 - 000142848 _____ (Microsoft Corporation) C:\WINDOWS\system32\iepeers.dll
2018-01-04 21:35 - 2018-01-01 06:19 - 000097792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msoert2.dll
2018-01-04 21:35 - 2018-01-01 06:19 - 000093696 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2018-01-04 21:35 - 2018-01-01 06:19 - 000079872 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlaapi.dll
2018-01-04 21:35 - 2018-01-01 06:19 - 000063488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\nlaapi.dll
2018-01-04 21:35 - 2018-01-01 06:19 - 000043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\nshhttp.dll
2018-01-04 21:35 - 2018-01-01 06:18 - 000748032 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneProviders.dll
2018-01-04 21:35 - 2018-01-01 06:18 - 000699904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CPFilters.dll
2018-01-04 21:35 - 2018-01-01 06:18 - 000588800 _____ (Microsoft Corporation) C:\WINDOWS\system32\SmsRouterSvc.dll
2018-01-04 21:35 - 2018-01-01 06:18 - 000465920 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcncsvc.dll
2018-01-04 21:35 - 2018-01-01 06:18 - 000436224 _____ (Microsoft Corporation) C:\WINDOWS\system32\PsmServiceExtHost.dll
2018-01-04 21:35 - 2018-01-01 06:18 - 000425984 _____ (Microsoft Corporation) C:\WINDOWS\system32\vmrdvcore.dll
2018-01-04 21:35 - 2018-01-01 06:18 - 000391168 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2018-01-04 21:35 - 2018-01-01 06:18 - 000380928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EncDec.dll
2018-01-04 21:35 - 2018-01-01 06:18 - 000369664 _____ (Microsoft Corporation) C:\WINDOWS\system32\APHostService.dll
2018-01-04 21:35 - 2018-01-01 06:18 - 000343040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2018-01-04 21:35 - 2018-01-01 06:18 - 000336896 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppLockerCSP.dll
2018-01-04 21:35 - 2018-01-01 06:18 - 000276480 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll
2018-01-04 21:35 - 2018-01-01 06:18 - 000259072 _____ (Microsoft Corporation) C:\WINDOWS\system32\SCardSvr.dll
2018-01-04 21:35 - 2018-01-01 06:18 - 000210944 _____ (Microsoft Corporation) C:\WINDOWS\system32\P2P.dll
2018-01-04 21:35 - 2018-01-01 06:18 - 000144896 _____ (Microsoft Corporation) C:\WINDOWS\system32\appinfo.dll
2018-01-04 21:35 - 2018-01-01 06:18 - 000082944 _____ (Microsoft Corporation) C:\WINDOWS\system32\provdatastore.dll
2018-01-04 21:35 - 2018-01-01 06:17 - 001485312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpserverbase.dll
2018-01-04 21:35 - 2018-01-01 06:17 - 000791552 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneService.dll
2018-01-04 21:35 - 2018-01-01 06:17 - 000616960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Bluetooth.dll
2018-01-04 21:35 - 2018-01-01 06:17 - 000594432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Web.Core.dll
2018-01-04 21:35 - 2018-01-01 06:17 - 000555520 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorService.dll
2018-01-04 21:35 - 2018-01-01 06:17 - 000456704 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtmsft.dll
2018-01-04 21:35 - 2018-01-01 06:17 - 000423936 _____ (Microsoft Corporation) C:\WINDOWS\system32\p2psvc.dll
2018-01-04 21:35 - 2018-01-01 06:17 - 000341504 _____ (Microsoft Corporation) C:\WINDOWS\system32\pnrpsvc.dll
2018-01-04 21:35 - 2018-01-01 06:17 - 000228352 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2018-01-04 21:35 - 2018-01-01 06:17 - 000112640 _____ (Microsoft Corporation) C:\WINDOWS\system32\msoert2.dll
2018-01-04 21:35 - 2018-01-01 06:16 - 004839424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbgeng.dll
2018-01-04 21:35 - 2018-01-01 06:16 - 000966656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Unistore.dll
2018-01-04 21:35 - 2018-01-01 06:16 - 000956928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpbase.dll
2018-01-04 21:35 - 2018-01-01 06:16 - 000831488 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll
2018-01-04 21:35 - 2018-01-01 06:16 - 000668160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2018-01-04 21:35 - 2018-01-01 06:16 - 000624128 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncController.dll
2018-01-04 21:35 - 2018-01-01 06:16 - 000401920 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncsi.dll
2018-01-04 21:35 - 2018-01-01 06:16 - 000235008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webcheck.dll
2018-01-04 21:35 - 2018-01-01 06:16 - 000086528 _____ (Microsoft Corporation) C:\WINDOWS\system32\cldapi.dll
2018-01-04 21:35 - 2018-01-01 06:16 - 000076288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cldapi.dll
2018-01-04 21:35 - 2018-01-01 06:15 - 002349568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputService.dll
2018-01-04 21:35 - 2018-01-01 06:15 - 001657856 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpserverbase.dll
2018-01-04 21:35 - 2018-01-01 06:15 - 001245184 _____ (Microsoft Corporation) C:\WINDOWS\system32\Unistore.dll
2018-01-04 21:35 - 2018-01-01 06:15 - 000970240 _____ (Microsoft Corporation) C:\WINDOWS\system32\sysmain.dll
2018-01-04 21:35 - 2018-01-01 06:15 - 000951808 _____ (Microsoft Corporation) C:\WINDOWS\system32\usermgr.dll
2018-01-04 21:35 - 2018-01-01 06:15 - 000756736 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2018-01-04 21:35 - 2018-01-01 06:15 - 000434176 _____ (Microsoft Corporation) C:\WINDOWS\system32\EncDec.dll
2018-01-04 21:35 - 2018-01-01 06:15 - 000366080 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlasvc.dll
2018-01-04 21:35 - 2018-01-01 06:15 - 000258560 _____ (Microsoft Corporation) C:\WINDOWS\system32\webcheck.dll
2018-01-04 21:35 - 2018-01-01 06:14 - 001097728 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpbase.dll
2018-01-04 21:35 - 2018-01-01 06:14 - 001003008 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll
2018-01-04 21:35 - 2018-01-01 06:14 - 000985600 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll
2018-01-04 21:35 - 2018-01-01 06:14 - 000917504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll
2018-01-04 21:35 - 2018-01-01 06:14 - 000870912 _____ (Microsoft Corporation) C:\WINDOWS\system32\CPFilters.dll
2018-01-04 21:35 - 2018-01-01 06:13 - 002013184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2018-01-04 21:35 - 2018-01-01 06:13 - 001474560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2018-01-04 21:35 - 2018-01-01 06:13 - 000897024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcomm.dll
2018-01-04 21:35 - 2018-01-01 06:12 - 001573376 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataService.dll
2018-01-04 21:35 - 2018-01-01 06:12 - 000760320 _____ (Microsoft Corporation) C:\WINDOWS\system32\spoolsv.exe
2018-01-04 21:35 - 2018-01-01 06:12 - 000464384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Core.TextInput.dll
2018-01-04 21:35 - 2018-01-01 06:11 - 002082304 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2018-01-04 21:35 - 2018-01-01 06:11 - 001816576 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtsvc.dll
2018-01-04 21:35 - 2018-01-01 06:11 - 001597952 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2018-01-04 21:35 - 2018-01-01 06:11 - 001343488 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifinetworkmanager.dll
2018-01-04 21:35 - 2018-01-01 06:11 - 000715776 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
2018-01-04 21:35 - 2018-01-01 06:10 - 003126272 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll
2018-01-04 21:35 - 2018-01-01 06:10 - 002528256 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll
2018-01-04 21:35 - 2018-01-01 06:10 - 000012800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscproxystub.dll
2018-01-04 21:35 - 2018-01-01 06:09 - 000666624 _____ (Microsoft Corporation) C:\WINDOWS\system32\DbgModel.dll
2018-01-04 21:35 - 2018-01-01 06:09 - 000599552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll
2018-01-04 21:35 - 2018-01-01 06:08 - 000963072 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll
2018-01-04 21:35 - 2018-01-01 06:08 - 000505344 _____ (Microsoft Corporation) C:\WINDOWS\system32\taskcomp.dll
2018-01-04 21:35 - 2018-01-01 06:06 - 000018944 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscproxystub.dll
2018-01-04 21:35 - 2018-01-01 06:05 - 000050176 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcalua.exe
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2018-02-03 12:07 - 2017-11-17 01:32 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2018-02-03 12:07 - 2017-09-29 03:45 - 024903680 _____ C:\WINDOWS\system32\config\HARDWARE
2018-02-03 12:07 - 2017-09-29 03:45 - 001048576 _____ C:\WINDOWS\system32\config\BBI
2018-02-03 12:05 - 2017-06-29 18:11 - 000000000 ____D C:\Program Files\SoftEther VPN Client
2018-02-03 12:05 - 2017-03-29 09:21 - 000000000 ___RD C:\Users\Jack\Google Drive
2018-02-03 12:01 - 2017-06-02 10:21 - 000000180 _____ C:\WINDOWS\system32\{A6D608F0-0BDE-491A-97AE-5C4B05D86E01}.bat
2018-02-03 12:01 - 2015-10-14 21:49 - 000000000 __SHD C:\Users\Jack\IntelGraphicsProfiles
2018-02-02 03:11 - 2017-11-17 01:00 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2018-02-02 00:10 - 2017-02-24 16:22 - 000000000 ____D C:\Users\Jack\AppData\LocalLow\Mozilla
2018-02-01 23:12 - 2017-11-24 17:28 - 000000000 ____D C:\ProgramData\ASUS Smart Gesture
2018-02-01 23:12 - 2015-10-14 21:52 - 000000093 _____ C:\Users\Jack\AppData\Roaming\sp_data.sys
2018-02-01 23:02 - 2017-06-28 07:50 - 000000000 ____D C:\Program Files (x86)\Mozilla Firefox
2018-02-01 23:02 - 2015-10-18 19:32 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2018-02-01 12:24 - 2015-10-18 19:32 - 000001234 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2018-02-01 09:57 - 2017-09-29 08:46 - 000000000 ____D C:\WINDOWS\DeliveryOptimization
2018-02-01 09:56 - 2017-11-17 01:32 - 000003368 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2592302959-4100768495-3643388182-1001
2018-02-01 09:56 - 2017-09-29 08:46 - 000000000 ___HD C:\Program Files\WindowsApps
2018-02-01 09:56 - 2017-09-29 08:46 - 000000000 ____D C:\WINDOWS\AppReadiness
2018-02-01 09:56 - 2017-07-10 20:50 - 000002409 _____ C:\Users\Jack\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2018-02-01 09:56 - 2015-10-14 21:54 - 000000000 ___RD C:\Users\Jack\OneDrive
2018-01-30 22:41 - 2017-09-29 08:44 - 000000000 ____D C:\WINDOWS\INF
2018-01-30 20:12 - 2017-10-03 17:05 - 000000000 ____D C:\Users\Jack\AppData\Local\NETGEARGenie
2018-01-30 20:11 - 2016-04-03 13:55 - 000000000 ____D C:\Users\Jack\AppData\Roaming\TeamViewer
2018-01-30 20:06 - 2017-03-07 18:18 - 000000352 _____ C:\WINDOWS\Tasks\HPCeeScheduleForJack.job
2018-01-29 22:01 - 2017-11-17 01:32 - 000003240 _____ C:\WINDOWS\System32\Tasks\HPCeeScheduleForJack
2018-01-29 19:48 - 2015-10-16 18:40 - 000000000 ____D C:\ProgramData\Malwarebytes
2018-01-29 19:46 - 2017-09-02 02:06 - 000192952 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMChameleon.sys
2018-01-27 23:17 - 2017-11-17 01:32 - 000000000 ____D C:\WINDOWS\System32\Tasks\ASUS
2018-01-27 19:19 - 2017-11-17 01:32 - 000004212 _____ C:\WINDOWS\System32\Tasks\CCleaner Update
2018-01-27 18:39 - 2017-09-02 02:05 - 000002099 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2018-01-27 18:31 - 2017-11-17 01:06 - 000000000 ____D C:\Users\Jack
2018-01-27 18:23 - 2016-04-03 13:55 - 000000000 ____D C:\Program Files (x86)\TeamViewer
2018-01-26 23:02 - 2016-01-09 20:54 - 000000000 ____D C:\Users\Jack\AppData\Roaming\uTorrent
2018-01-26 23:01 - 2017-09-29 08:46 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2018-01-26 22:53 - 2017-11-17 01:31 - 001190370 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2018-01-26 22:18 - 2017-11-17 01:09 - 000000000 ____D C:\Users\Jack\AppData\Local\Packages
2018-01-26 22:14 - 2015-10-15 09:24 - 000002274 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2018-01-25 22:51 - 2016-12-02 22:00 - 000001912 _____ C:\Users\Jack\Desktop\Kodi.lnk
2018-01-25 22:51 - 2016-11-20 00:30 - 000000000 ____D C:\Users\Jack\AppData\Roaming\Kodi
2018-01-24 13:36 - 2015-10-16 18:59 - 000548000 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2018-01-23 11:39 - 2017-11-17 01:00 - 000505840 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2018-01-23 11:35 - 2017-09-29 08:46 - 000000000 ____D C:\WINDOWS\system32\FxsTmp
2018-01-23 11:34 - 2014-10-02 15:33 - 000000000 ____D C:\ProgramData\Package Cache
2018-01-22 22:05 - 2016-12-02 19:41 - 000000000 ____D C:\Users\Jack\AppData\Local\Windows Live
2018-01-22 19:57 - 2015-10-19 21:54 - 000000000 ____D C:\ProgramData\Oracle
2018-01-22 19:56 - 2016-10-23 21:49 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2018-01-22 19:56 - 2015-10-19 21:54 - 000000000 ____D C:\Program Files (x86)\Java
2018-01-22 19:54 - 2016-10-23 21:49 - 000097344 _____ (Oracle Corporation) C:\WINDOWS\SysWOW64\WindowsAccessBridge-32.dll
2018-01-22 11:50 - 2017-12-26 16:26 - 000000000 ____D C:\Program Files (x86)\TomTom HOME 2
2018-01-22 11:46 - 2015-10-15 23:45 - 000000000 ____D C:\Users\Jack\AppData\Local\Downloaded Installations
2018-01-21 20:22 - 2017-09-29 08:37 - 000000000 ____D C:\WINDOWS\CbsTemp
2018-01-21 20:18 - 2017-11-17 01:32 - 000004160 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{CDA7FC31-4313-41B6-86A9-6144DA1867D5}
2018-01-21 19:54 - 2015-10-15 22:24 - 000000093 _____ C:\Users\steph\AppData\Roaming\sp_data.sys
2018-01-21 17:57 - 2016-06-03 09:43 - 000000000 ____D C:\ProgramData\TEMP
2018-01-21 16:38 - 2015-10-15 22:21 - 000000000 __SHD C:\Users\steph\IntelGraphicsProfiles
2018-01-19 17:50 - 2017-12-20 11:13 - 000000325 _____ C:\Users\Jack\Desktop\bitcoin.txt
2018-01-19 16:20 - 2017-09-29 08:46 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2018-01-19 16:18 - 2014-10-02 15:30 - 000000000 ____D C:\Program Files (x86)\Microsoft Office
2018-01-18 23:11 - 2017-12-06 18:28 - 000000000 ____D C:\WINDOWS\Minidump
2018-01-18 23:10 - 2017-08-16 17:37 - 000000865 _____ C:\Users\Public\Desktop\CCleaner.lnk
2018-01-18 19:50 - 2017-12-20 21:53 - 000000000 ____D C:\Users\Jack\Desktop\PRINT
2018-01-16 20:39 - 2017-11-17 01:32 - 000003370 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-2592302959-4100768495-3643388182-1002
2018-01-16 20:39 - 2015-10-15 22:25 - 000002412 _____ C:\Users\steph\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2018-01-16 20:39 - 2015-10-15 22:25 - 000000000 ___RD C:\Users\steph\OneDrive
2018-01-15 19:17 - 2015-10-16 18:46 - 000000000 ____D C:\WINDOWS\system32\MRT
2018-01-15 19:12 - 2017-10-10 17:42 - 129365736 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT-KB890830.exe
2018-01-15 19:12 - 2015-10-16 18:46 - 129365736 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2018-01-15 19:10 - 2017-11-17 01:32 - 000004542 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player PPAPI Notifier
2018-01-15 19:10 - 2017-09-29 08:46 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed
2018-01-15 19:10 - 2017-09-29 08:46 - 000000000 ____D C:\WINDOWS\system32\Macromed
2018-01-11 19:32 - 2017-09-29 08:46 - 000000000 ____D C:\WINDOWS\rescache
2018-01-11 18:30 - 2017-11-17 01:08 - 000000000 ____D C:\Users\steph\AppData\Local\Packages
2018-01-11 18:27 - 2017-11-27 18:10 - 000000000 ___RD C:\Users\steph\3D Objects
2018-01-11 18:27 - 2015-09-10 00:42 - 000000000 __RHD C:\Users\Public\AccountPictures
2018-01-11 14:04 - 2017-09-04 11:25 - 000000000 ____D C:\Users\Jack\AppData\Local\ElevatedDiagnostics
2018-01-08 19:11 - 2017-11-17 14:18 - 000000000 ___RD C:\Users\Jack\3D Objects
2018-01-08 19:04 - 2017-09-29 08:46 - 000000000 ___SD C:\WINDOWS\SysWOW64\F12
2018-01-08 19:04 - 2017-09-29 08:46 - 000000000 ___SD C:\WINDOWS\system32\F12
2018-01-08 19:04 - 2017-09-29 08:46 - 000000000 ____D C:\WINDOWS\TextInput
2018-01-08 19:04 - 2017-09-29 08:46 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2018-01-08 19:04 - 2017-09-29 08:46 - 000000000 ____D C:\WINDOWS\system32\oobe
2018-01-08 19:04 - 2017-09-29 08:46 - 000000000 ____D C:\WINDOWS\system32\migwiz
2018-01-08 19:04 - 2017-09-29 08:46 - 000000000 ____D C:\WINDOWS\system32\appraiser
2018-01-08 19:04 - 2017-09-29 03:45 - 000000000 ____D C:\WINDOWS\system32\Dism
2018-01-08 19:03 - 2017-09-29 08:46 - 000000000 ____D C:\WINDOWS\Provisioning
2018-01-05 14:30 - 2017-06-22 09:38 - 000009877 _____ C:\Users\Jack\Desktop\Jaguar.xlsx
2018-01-04 21:41 - 2017-09-29 08:41 - 000403968 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpAXHolder.dll
2018-01-04 21:40 - 2017-09-29 08:41 - 000140800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2018-01-04 21:40 - 2017-09-29 08:41 - 000106496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll
 
==================== Files in the root of some directories =======
 
2016-06-07 19:37 - 2016-06-07 19:37 - 000128512 _____ () C:\Users\Jack\AppData\Roaming\Installer.dat
2015-10-14 21:52 - 2018-02-01 23:12 - 000000093 _____ () C:\Users\Jack\AppData\Roaming\sp_data.sys
2016-11-11 20:07 - 2017-12-03 21:57 - 000000600 _____ () C:\Users\Jack\AppData\Roaming\winscp.rnd
2018-01-26 17:58 - 2018-01-26 17:58 - 000010752 _____ () C:\Users\Jack\AppData\Local\gunny.exe
2018-01-26 17:58 - 2018-01-26 17:58 - 000011264 _____ () C:\Users\Jack\AppData\Local\knudsen.exe
2017-12-03 22:04 - 2017-12-03 22:04 - 000000600 _____ () C:\Users\Jack\AppData\Local\PUTTY.RND
 
Some files in TEMP:
====================
2018-02-03 12:13 - 2018-02-03 12:13 - 002393088 _____ (Farbar) C:\Users\Jack\AppData\Local\Temp\246C.tmp.exe
2018-01-26 19:41 - 2017-08-19 15:49 - 002294496 _____ () C:\Users\Jack\AppData\Local\Temp\asacpiex.dll
2018-01-26 19:38 - 2018-01-26 19:38 - 000594944 _____ (The OpenSSL Project, http://www.openssl.org/) C:\Users\Jack\AppData\Local\Temp\libeay32.dll
2018-01-26 19:41 - 2017-08-19 15:49 - 001154560 _____ () C:\Users\Jack\AppData\Local\Temp\screen.exe
2018-01-26 19:38 - 2018-01-26 19:38 - 000152576 _____ (The OpenSSL Project, http://www.openssl.org/) C:\Users\Jack\AppData\Local\Temp\ssleay32.dll
2018-01-26 22:16 - 2018-01-26 19:39 - 000099888 _____ () C:\Users\Jack\AppData\Local\Temp\Uninstall.exe
 
==================== Bamital & volsnap ======================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
C:\WINDOWS\system32\drivers\vsssvybf.sys -> Access Denied <======= ATTENTION
 
LastRegBack: 2018-01-25 23:33
 
==================== End of FRST.txt ============================


#7 Aura

Aura

    Bleepin' Special Ops


  • Malware Response Team
  • 19,596 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:04:43 PM

Posted 04 February 2018 - 04:36 PM

This FRST scan wasn't ran from the Windows RE. Follow the instructions in the post I gave, there are links to tutorials showing you how to access the Windows RE depending on your Windows version.
Boot Mode: Safe Mode (minimal)

unite_blue.png
Security Administrator | Sysnative Windows Update Senior Analyst | Malware Hunter | @SecurityAura
My timezone UTC-05:00 (East. Coast). If I didn't reply to you within 48 hours, please send me a PM.


#8 MrJackSTARR

MrJackSTARR
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:03:43 PM

Posted 05 February 2018 - 05:00 PM

Hello Aura,

 

I was not able to get into Windows RE. When attempting to go through all the listed options to enter the recovery I was always met with a warning stating:

 

Recovery

Your PC/Device needs to be repaired

A required device isn't connected or can't be accessed.

Error code: 0xc000000f

 

You'll need to use recovery tools. If you don't have any installation media (like a disc or USB device), contact your PC administrator or PC/Device manufacturer.

 

I also tried to create a recovery cd (create system repair disc) and bootable USB (recovery media creator) using the information provided in the link you shared but have been met with failure.

 

Repair Disc error:

Insert Windows installation disc

The files needed to create a system repair disc were not found on this computer. You can still create a system repair disc if you have a Windows installation disc.

 

USB error:

We can't create a recovery drive on this PC

Some required files are missing. To troubleshoot problems when your PC can't start, use your Windows installation disc or media.

 

As you would imagine this laptop did not come with an installation disc.

 

Can you suggest another course of action please?



#9 Aura

Aura

    Bleepin' Special Ops


  • Malware Response Team
  • 19,596 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:04:43 PM

Posted 06 February 2018 - 08:42 AM

Sadly, this infection can only be removed from the Windows RE, so we'll need to find a way to access it.

Since you're running Windows 10, create an installation media for it using your USB Flash Drive.

http://www.thewindowsclub.com/windows-10-media-creation-tool-create-installation-media-upgrade

unite_blue.png
Security Administrator | Sysnative Windows Update Senior Analyst | Malware Hunter | @SecurityAura
My timezone UTC-05:00 (East. Coast). If I didn't reply to you within 48 hours, please send me a PM.


#10 MrJackSTARR

MrJackSTARR
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:03:43 PM

Posted 06 February 2018 - 10:02 AM

Sadly, this infection can only be removed from the Windows RE, so we'll need to find a way to access it.

Since you're running Windows 10, create an installation media for it using your USB Flash Drive.

http://www.thewindowsclub.com/windows-10-media-creation-tool-create-installation-media-upgrade

 

 

Hello Aura,

 

Can this be done from the troubled laptop or must I use a second laptop/computer?



#11 Aura

Aura

    Bleepin' Special Ops


  • Malware Response Team
  • 19,596 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:04:43 PM

Posted 06 February 2018 - 11:47 AM

You can try from the infected laptop, but I had a lot of users who weren't able to create it from their infected system when they tried. So a second laptop/computer that is clean would be a better choice.

unite_blue.png
Security Administrator | Sysnative Windows Update Senior Analyst | Malware Hunter | @SecurityAura
My timezone UTC-05:00 (East. Coast). If I didn't reply to you within 48 hours, please send me a PM.


#12 MrJackSTARR

MrJackSTARR
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:03:43 PM

Posted 07 February 2018 - 10:39 PM

Hello Aura,

 

Would it possible to continue this late next week? I will be traveling to a country with little to no internet and want to make sure this issue is not closed.

 

Thank you,

Jack



#13 Aura

Aura

    Bleepin' Special Ops


  • Malware Response Team
  • 19,596 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:04:43 PM

Posted 08 February 2018 - 10:53 AM

All good, I'll be waiting for your return :)

unite_blue.png
Security Administrator | Sysnative Windows Update Senior Analyst | Malware Hunter | @SecurityAura
My timezone UTC-05:00 (East. Coast). If I didn't reply to you within 48 hours, please send me a PM.


#14 MrJackSTARR

MrJackSTARR
  • Topic Starter

  • Members
  • 10 posts
  • OFFLINE
  •  
  • Local time:03:43 PM

Posted 15 February 2018 - 12:23 PM

All good, I'll be waiting for your return :)

 

Good afternoon Aura,

 

Thank you for your patience and leaving this open. I returned yesterday afternoon and borrowed a second laptop to with the same version of windows to create a bootable usb (since the borrowed laptop does not have a cd drive). I have been trying to get the infected laptop to boot from usb but the option never appears no matter which option I use. 

 

Should I check to see if I can change a setting in the Bios?

 

Thank you,

Jack



#15 Aura

Aura

    Bleepin' Special Ops


  • Malware Response Team
  • 19,596 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:04:43 PM

Posted 15 February 2018 - 07:17 PM

How far can you get when you try to boot from the USB? What options do you have?

unite_blue.png
Security Administrator | Sysnative Windows Update Senior Analyst | Malware Hunter | @SecurityAura
My timezone UTC-05:00 (East. Coast). If I didn't reply to you within 48 hours, please send me a PM.





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users