Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Help kmspico infected.


  • This topic is locked This topic is locked
12 replies to this topic

#1 tomjoram

tomjoram

  • Members
  • 226 posts
  • OFFLINE
  •  
  • Local time:11:08 PM

Posted 12 June 2018 - 03:59 AM

Good day sir. 

I would like to get some help removing this kmspico virus i have when i tried activating windows 10, it installed some programs and runs in google chrome opening links, it also changed my default search engine. 



BC AdBot (Login to Remove)

 


#2 tomjoram

tomjoram
  • Topic Starter

  • Members
  • 226 posts
  • OFFLINE
  •  
  • Local time:11:08 PM

Posted 12 June 2018 - 04:29 AM

It also installed System healer but i cannot remove it from the control panel



#3 tomjoram

tomjoram
  • Topic Starter

  • Members
  • 226 posts
  • OFFLINE
  •  
  • Local time:11:08 PM

Posted 12 June 2018 - 04:45 AM

found a guide here to remove system healer, i just need to make sure my laptop is clean from anything else from that kmspico



#4 nasdaq

nasdaq

  • Malware Response Team
  • 40,188 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:11:08 AM

Posted 12 June 2018 - 07:53 AM

Hello, Welcome to BleepingComputer.
I'm nasdaq and will be helping you.

If you can please print this topic it will make it easier for you to follow the instructions and complete all of the necessary steps in the order listed.
===

Please download Malwarebytes Anti-Malware from here
  • Right-click on the MBAM icon and select Run as administrator to run the tool.
  • Click Yes to accept any security warnings that may appear.
  • Once the MBAM dashboard opens, on the right detail pane click on the word "Current" under the Scan Status to update the tool database.
  • On the left menu pane click the Settings tab, and then select the Protection tab on the top.
  • Under the Scan Options, turn on the button Scan for rootkits and Scan within archives.
  • Click the Scan tab on the right detail pane, select Threat Scan and click the Start Scan button
  • Note: The scan may take some time to finish, so please be patient.
  • If potential threats are detected, ensure to checkmark all the listed items, and click the Quarantine Selected button.
  • While still on the Scan tab, click the View Report button, and in the window that opens click the Export button, select Text file (*.txt), and save the log to your Desktop.
  • The log can also be viewed by clicking the log to select it, then clicking the View Report button.
Please post the log for my review.

Note: If asked to restart the computer, please do so immediately.
===

Please download AdwCleaner by Xplode onto your Desktop.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click the Scan button and wait for the process to complete.
  • Click the LogFile button and the report will open in Notepad.
IMPORTANT
  • If you click the Clean button all items listed in the report will be removed.
If you find some false positive items or programs that you wish to keep, Close the AdwCleaner windows.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click the Scan button and wait for the process to complete.
  • Check off the element(s) you wish to keep.
  • Click on the Clean button follow the prompts.
  • A log file will automatically open after the scan has finished.
  • Please post the content of that log file with your next answer.
  • You can find the log file at C:\AdwCleanerCx.txt (x is a number).
===

Download the version of this tool for your operating system.
Farbar Recovery Scan Tool (64 bit)
Farbar Recovery Scan Tool (32 bit)
and save it to a folder on your computer's Desktop.
Double-click to run it. When the tool opens click Yes to disclaimer.
Press Scan button.
It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.
The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.

How to attach a file to your reply:
In the Reply section in the bottom of the topic Click the "more reply Options" button.
attachlogs.png

Attach the file.
Select the "Choose a File" navigate to the location of the File.
Click the file you wish to Attach.
Click Attach this file.
Click the Add reply button.
===

Please post the logs for my review.

Wait for further instructions.
==============================

#5 tomjoram

tomjoram
  • Topic Starter

  • Members
  • 226 posts
  • OFFLINE
  •  
  • Local time:11:08 PM

Posted 12 June 2018 - 08:51 AM

malwarebytes log

Attached Files

  • Attached File  mbam.txt   22.11KB   3 downloads

Edited by tomjoram, 12 June 2018 - 08:52 AM.


#6 tomjoram

tomjoram
  • Topic Starter

  • Members
  • 226 posts
  • OFFLINE
  •  
  • Local time:11:08 PM

Posted 12 June 2018 - 08:54 AM

AdwCleaner log

Attached Files



#7 tomjoram

tomjoram
  • Topic Starter

  • Members
  • 226 posts
  • OFFLINE
  •  
  • Local time:11:08 PM

Posted 12 June 2018 - 08:57 AM

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 06.06.2018 01
Ran by Tom Joram Vitor (administrator) on LAPTOP-TOM (12-06-2018 21:50:33)
Running from C:\Users\Tom Joram Vitor\Downloads
Loaded Profiles: Tom Joram Vitor (Available Profiles: Tom Joram Vitor)
Platform: Windows 10 Home Single Language Version 1709 16299.192 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki127390.inf_amd64_e1ccb879ece8f084\igfxCUIService.exe
(AMD) C:\Windows\System32\DriverStore\FileRepository\c0328911.inf_amd64_a81756cbffedb936\B328940\atiesrxx.exe
(AMD) C:\Windows\System32\DriverStore\FileRepository\c0328911.inf_amd64_a81756cbffedb936\B328940\atieclxx.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Windows ® Win 7 DDK provider) C:\Windows\System32\drivers\AdminService.exe
(McAfee, LLC) C:\Program Files\Common Files\mcafee\SystemCore\mfemms.exe
(Intel Corporation) C:\Windows\System32\Intel\DPTF\esif_uf.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Rivet Networks) C:\Program Files\Rivet Networks\SmartByte\SmartByteNetworkService.exe
(Waves Audio Ltd.) C:\Program Files\Waves\MaxxAudio\WavesSysSvc64.exe
(Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki127390.inf_amd64_e1ccb879ece8f084\IntelCpHDCPSvc.exe
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\PEF\CORE\PEFService.exe
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\modulecore\ModuleCoreService.exe
(McAfee, LLC) C:\Windows\System32\mfevtps.exe
(Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki127390.inf_amd64_e1ccb879ece8f084\IntelCpHeciSvc.exe
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\MMSSHost\MMSSHOST.exe
(McAfee, LLC) C:\Windows\System32\mfevtps.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(McAfee, LLC) C:\Program Files\Common Files\mcafee\SystemCore\mfefire.exe
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\csp\2.9.175.0\McCSPServiceHost.exe
(McAfee, Inc.) C:\Program Files (x86)\McAfee\SiteAdvisor\mcsacore.exe
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\VSCore_15_8\mcapexe.exe
(McAfee, Inc.) C:\Program Files\mcafee\mfeav\MfeAVSvc.exe
(McAfee LLC.) C:\Program Files\Common Files\mcafee\amcore\mcshield.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Intel Corporation) C:\Windows\System32\Intel\DPTF\dptf_helper.exe
(McAfee, Inc.) C:\Program Files (x86)\McAfee\SiteAdvisor\saUI.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Advanced Micro Devices, Inc.) C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe
(Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\ki127390.inf_amd64_e1ccb879ece8f084\igfxEM.exe
(Microsoft Corporation) C:\Windows\System32\CastSrv.exe
(Tonec Inc.) C:\Program Files (x86)\Internet Download Manager\IDMan.exe
(Tonec Inc.) C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\modulecore\ModuleCoreService.exe
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\platform\McUICnt.exe
(Dell Inc.) C:\Program Files\Dell\DellDataVault\DDVRulesProcessor.exe
(PC-Doctor, Inc.) C:\Program Files\Dell\SupportAssistAgent\PCDr\SupportAssist\6.0.6992.1111\DSAPI.exe
(Intel Corporation) C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
(PC-Doctor, Inc.) C:\Program Files\Dell\SupportAssistAgent\PCDr\SupportAssist\6.0.6992.1111\Phobos.exe
(Dell Inc.) C:\Program Files\Dell\SARemediation\agent\DellSupportAssistRemedationService.exe
(Dell Products, LP.) C:\Program Files (x86)\Dell Digital Delivery\DeliveryService.exe
(Dell Inc.) C:\Program Files (x86)\Dell Update\DellUpService.exe
(Intel Corporation) C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
(Dell Inc.) C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe
(Dell Inc.) C:\Program Files\Dell\DellDataVault\DDVDataCollector.exe
(Dell Inc.) C:\Program Files\Dell\DellDataVault\DDVCollectorSvcApi.exe
(Dell Inc.) C:\Program Files\Dell\DellDataVault\atiw.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(CloudBees, Inc.) C:\Program Files\Rivet Networks\SmartByte\RNDBWMService.exe
(Rivet Networks LLC) C:\Program Files\Rivet Networks\SmartByte\RNDBWM.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\platform\msm\McSmtFwk.exe
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\platform\McUICnt.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\cmd.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(McAfee, Inc.) C:\Program Files (x86)\McAfee\SiteAdvisor\McChHost.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\splwow64.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
 
==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [SecurityHealth] => C:\Program Files\WINDOWS DEFENDER\MSASCUIL.EXE [630168 2017-09-29] (Microsoft Corporation)
HKLM\...\Run: [RTHDVCPL] => C:\PROGRAM FILES\REALTEK\AUDIO\HDA\RTKNGUI64.EXE [9235944 2017-08-31] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_PushButton] => C:\PROGRAM FILES\REALTEK\AUDIO\HDA\RAVBG64.EXE [1493992 2017-08-31] (Realtek Semiconductor)
HKLM\...\Run: [WavesSvc] => C:\PROGRAM FILES\WAVES\MAXXAUDIO\WAVESSVC64.EXE [1197936 2017-08-09] (Waves Audio Ltd.)
HKLM\...\Run: [DellMobileConnectWelcome] => C:\PROGRAM FILES\DELL\DELLMOBILECONNECTDRIVERS\DELLMOBILECONNECTWELCOME.EXE [127480 2017-11-06] (Screenovate Technologies Ltd.)
HKLM\...\Run: [IAStorIcon] => C:\PROGRAM FILES\INTEL\INTEL® RAPID STORAGE TECHNOLOGY\IASTORICON.EXE [321096 2017-07-01] (Intel Corporation)
HKU\S-1-5-21-1685633152-2609128806-664276259-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3201312 2018-06-09] (Valve Corporation)
HKU\S-1-5-21-1685633152-2609128806-664276259-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [18364136 2018-05-16] (Piriform Ltd)
HKU\S-1-5-21-1685633152-2609128806-664276259-1001\...\Run: [IDMan] => C:\Program Files (x86)\Internet Download Manager\IDMan.exe [4001848 2016-12-16] (Tonec Inc.)
BootExecute: autocheck autochk * bootdelete
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Tcpip\..\Interfaces\{7ca6a780-d659-4d5f-b506-984107c3b888}: [DhcpNameServer] 192.168.8.1 192.168.8.1
Tcpip\..\Interfaces\{8f1c1dfb-df7c-4637-a0ad-e4da8945ef36}: [DhcpNameServer] 192.168.42.129
Tcpip\..\Interfaces\{e1554dba-48f1-499d-b2b4-c51673a53a4b}: [DhcpNameServer] 192.168.8.1 192.168.8.1
 
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-1685633152-2609128806-664276259-1001\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-1685633152-2609128806-664276259-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://dell17win10.msn.com/?pc=DCTE
SearchScopes: HKU\S-1-5-21-1685633152-2609128806-664276259-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
BHO: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files (x86)\Internet Download Manager\IDMIECC64.dll [2016-12-11] (Internet Download Manager, Tonec Inc.)
BHO: McAfee WebAdvisor -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll [2018-05-29] (McAfee, Inc.)
BHO-x32: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll [2016-12-11] (Internet Download Manager, Tonec Inc.)
BHO-x32: McAfee WebAdvisor -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll [2018-05-29] (McAfee, Inc.)
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll [2018-05-29] (McAfee, Inc.)
Handler-x32: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll [2018-05-29] (McAfee, Inc.)
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\mcafee\msc\McSnIePl64.dll [2018-05-08] (McAfee, Inc.)
Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\msc\McSnIePl.dll [2018-05-08] (McAfee, Inc.)
 
FireFox:
========
FF HKLM\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor\e10ssaffplg.xpi
FF Extension: (McAfee® WebAdvisor) - C:\Program Files (x86)\McAfee\SiteAdvisor\e10ssaffplg.xpi [2018-05-15]
FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor\e10ssaffplg.xpi
FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK
FF Extension: (McAfee Anti-Spam Thunderbird Extension) - C:\Program Files\McAfee\MSK [2018-06-12] [Legacy] [not signed]
FF HKU\S-1-5-21-1685633152-2609128806-664276259-1001\...\SeaMonkey\Extensions: [mozilla_cc@internetdownloadmanager.com] - C:\Users\Tom Joram Vitor\AppData\Roaming\IDM\idmmzcc5
FF Extension: (IDM CC) - C:\Users\Tom Joram Vitor\AppData\Roaming\IDM\idmmzcc5 [2018-06-12] [Legacy] [not signed]
FF HKU\S-1-5-21-1685633152-2609128806-664276259-1001\...\SeaMonkey\Extensions: [mozilla_cc2@internetdownloadmanager.com] - C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpi
FF Extension: (IDM integration) - C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpi [2016-11-16] [Legacy]
FF Plugin: @mcafee.com/MSC,version=10 -> c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL [2018-05-08] ()
FF Plugin: @videolan.org/vlc,version=3.0.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2018-05-30] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.3 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2018-05-30] (VideoLAN)
FF Plugin-x32: @mcafee.com/MSC,version=10 -> c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL [2018-05-08] ()
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.17\npGoogleUpdate3.dll [No File]
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.17\npGoogleUpdate3.dll [No File]
 
Chrome: 
=======
CHR res: Infected resources.pak (Adware script). Reinstall Chrome. <==== ATTENTION
CHR HomePage: Default -> hxxps://www.google.com/
CHR StartupUrls: Default -> "hxxp://www.google.com/","hxxp://www.linkzb.com","hxxps://www.google.com/","hxxps://www.google.com/","hxxps://www.facebook.com/"
CHR Session Restore: Default -> is enabled.
CHR Profile: C:\Users\Tom Joram Vitor\AppData\Local\Google\Chrome\User Data\Default [2018-06-12]
CHR Extension: (Slides) - C:\Users\Tom Joram Vitor\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-05-26]
CHR Extension: (Docs) - C:\Users\Tom Joram Vitor\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2018-05-26]
CHR Extension: (PowToon Presentations) - C:\Users\Tom Joram Vitor\AppData\Local\Google\Chrome\User Data\Default\Extensions\aomfhbjiekjcbeefclbidjgnikfbooem [2018-05-26]
CHR Extension: (Google Drive) - C:\Users\Tom Joram Vitor\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-05-26]
CHR Extension: (YouTube) - C:\Users\Tom Joram Vitor\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-05-26]
CHR Extension: (Adblock Plus) - C:\Users\Tom Joram Vitor\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2018-05-26]
CHR Extension: (Sheets) - C:\Users\Tom Joram Vitor\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-05-26]
CHR Extension: (McAfee® WebAdvisor) - C:\Users\Tom Joram Vitor\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2018-05-26]
CHR Extension: (Google Docs Offline) - C:\Users\Tom Joram Vitor\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-05-26]
CHR Extension: (No Name) - C:\Users\Tom Joram Vitor\AppData\Local\Google\Chrome\User Data\Default\Extensions\mafbdhjdkjnoafhfelkjpchpaepjknad [2018-06-12]
CHR Extension: (UltraSurf Security, Privacy & Unblock VPN) - C:\Users\Tom Joram Vitor\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjnbclmflcpookeapghfhapeffmpodij [2018-06-07]
CHR Extension: (IDM Integration Module) - C:\Users\Tom Joram Vitor\AppData\Local\Google\Chrome\User Data\Default\Extensions\ngpampappnmepgilojfohadhhmbhlaek [2018-06-03]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Tom Joram Vitor\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-05-26]
CHR Extension: (Gmail) - C:\Users\Tom Joram Vitor\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2018-05-26]
CHR Extension: (Chrome Media Router) - C:\Users\Tom Joram Vitor\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-06-07]
CHR HKLM\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - hxxp://clients2.google.com/service/update2/crx
CHR HKLM\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2016-12-15]
CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - hxxp://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2016-12-15]
 
==================== Services (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 AMD External Events Utility; C:\WINDOWS\System32\DriverStore\FileRepository\c0328911.inf_amd64_a81756cbffedb936\B328940\atiesrxx.exe [481656 2018-05-22] (AMD)
R2 AtherosSvc; C:\WINDOWS\system32\DRIVERS\AdminService.exe [414728 2017-11-09] (Windows ® Win 7 DDK provider)
S3 ClientAnalyticsService; C:\Program Files\Common Files\McAfee\ClientAnalytics\Legacy\McClientAnalytics.exe [1508656 2018-05-03] (McAfee, Inc.)
S3 dcpm-notify; C:\Program Files\Dell\CommandPowerManager\NotifyService.exe [312864 2017-07-21] (Dell Inc.)
R2 DDVCollectorSvcApi; C:\Program Files\Dell\DellDataVault\DDVCollectorSvcApi.exe [208792 2018-02-10] (Dell Inc.)
R2 DDVDataCollector; C:\Program Files\Dell\DellDataVault\DDVDataCollector.exe [3346320 2018-02-10] (Dell Inc.)
R2 DDVRulesProcessor; C:\Program Files\Dell\DellDataVault\DDVRulesProcessor.exe [217488 2018-02-10] (Dell Inc.)
R2 Dell Hardware Support; C:\Program Files\Dell\SupportAssistAgent\PCDr\SupportAssist\6.0.6992.1111\DSAPI.exe [930112 2018-06-01] (PC-Doctor, Inc.)
R2 Dell SupportAssist Remediation; C:\Program Files\Dell\SARemediation\agent\DellSupportAssistRemedationService.exe [119840 2017-11-04] (Dell Inc.)
R2 DellUpdate; C:\Program Files (x86)\Dell Update\DellUpService.exe [237016 2018-03-27] (Dell Inc.)
R2 esifsvc; C:\WINDOWS\system32\Intel\DPTF\esif_uf.exe [1700968 2017-05-11] (Intel Corporation)
S3 iaStorAfsService; C:\WINDOWS\IAStorAfsService\iaStorAfsService.exe [2413744 2017-07-01] (Intel Corporation)
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [17992 2017-07-01] (Intel Corporation)
S3 Intel® Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\Intel® Management Engine Components\iCLS\SocketHeciServer.exe [742704 2017-10-12] (Intel® Corporation)
S2 Intel® TPM Provisioning Service; C:\Program Files\Intel\Intel® Management Engine Components\iCLS\TPMProvisioningService.exe [668472 2017-10-12] (Intel® Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe [213648 2017-11-09] (Intel Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6541008 2018-05-03] (Malwarebytes)
R2 McAfee SiteAdvisor Service; C:\Program Files (x86)\McAfee\SiteAdvisor\McSACore.exe [604824 2018-05-29] (McAfee, Inc.)
R2 McAPExe; C:\Program Files\Common Files\McAfee\VSCore_15_8\McApExe.exe [728808 2018-05-16] (McAfee, Inc.)
S3 McAWFwk; C:\Program Files\Common Files\mcafee\actwiz\McAWFwk.exe [454560 2017-01-17] (McAfee, Inc.)
R2 mccspsvc; C:\Program Files\Common Files\McAfee\CSP\2.9.175.0\\McCSPServiceHost.exe [2141912 2018-04-06] (McAfee, Inc.)
S3 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe [359888 2018-02-23] (McAfee, LLC)
R2 mfemms; C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe [512976 2018-02-23] (McAfee, LLC)
R2 mfevtp; C:\Windows\system32\mfevtps.exe [473040 2018-02-23] (McAfee, LLC)
R2 ModuleCoreService; C:\Program Files\Common Files\McAfee\ModuleCore\ModuleCoreService.exe [1676024 2018-05-01] (McAfee, Inc.)
R2 PEFService; C:\Program Files\Common Files\McAfee\PEF\CORE\PEFService.exe [1047448 2018-05-07] (McAfee, Inc.)
R2 RNDBWM; C:\Program Files\Rivet Networks\SmartByte\RNDBWMService.exe [64184 2018-03-20] (CloudBees, Inc.)
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [324584 2017-08-31] (Realtek Semiconductor)
R2 SmartByte Network Service x64; C:\Program Files\Rivet Networks\SmartByte\SmartByteNetworkService.exe [2011848 2018-03-20] (Rivet Networks)
R2 SupportAssistAgent; C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe [43480 2018-05-11] (Dell Inc.)
S3 uSHAREitSvc; C:\Program Files (x86)\SHAREit Technologies\SHAREit\SHAREit.Service.exe [33224 2017-09-11] (SHAREit Technologies Co.Ltd)
R2 WavesSysSvc; C:\Program Files\Waves\MaxxAudio\WavesSysSvc64.exe [829816 2017-08-09] (Waves Audio Ltd.)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [355304 2017-09-29] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [105944 2017-09-29] (Microsoft Corporation)
S3 Dell.CommandPowerManager.Service; C:\Windows\system32\dllhost.exe /Processid:{25054159-1D36-49F1-AF09-8EEE935881AB}
S2 gupdate; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /svc [X]
S3 gupdatem; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /medsvc [X]
R2 OGMwOTcxMjg3M; rundll32.exe C:\WINDOWS\rucjlxzkqboopktx.lucj sqbq [X]
 
===================== Drivers (Whitelisted) ======================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S0 amdkmafd; C:\WINDOWS\System32\drivers\amdkmafd.sys [49448 2016-08-18] (Advanced Micro Devices, Inc.)
R3 amdkmdag; C:\WINDOWS\System32\DriverStore\FileRepository\c0328911.inf_amd64_a81756cbffedb936\B328940\atikmdag.sys [44682104 2018-05-22] (Advanced Micro Devices, Inc.)
R3 amdkmdap; C:\WINDOWS\System32\DriverStore\FileRepository\c0328911.inf_amd64_a81756cbffedb936\B328940\atikmpag.sys [552824 2018-05-22] (Advanced Micro Devices, Inc.)
S3 BstkDrv; C:\Program Files (x86)\BlueStacks\BstkDrv.sys [269408 2018-05-23] (Bluestack System Inc. )
R3 BtFilter; C:\WINDOWS\system32\DRIVERS\btfilter.sys [70544 2017-11-09] (Qualcomm)
S3 cfwids; C:\WINDOWS\System32\drivers\cfwids.sys [77216 2018-02-28] (McAfee, LLC)
R3 DDDriver; C:\WINDOWS\system32\drivers\DDDriver64Dcsa.sys [41608 2017-12-15] (Dell Inc.)
R3 DellProf; C:\WINDOWS\system32\drivers\DellProf.sys [41208 2017-12-15] (Dell Computer Corporation)
R3 dptf_acpi; C:\WINDOWS\System32\drivers\dptf_acpi.sys [74168 2017-05-11] (Intel Corporation)
R3 dptf_cpu; C:\WINDOWS\System32\drivers\dptf_cpu.sys [69560 2017-05-11] (Intel Corporation)
R3 esif_lf; C:\WINDOWS\system32\DRIVERS\esif_lf.sys [382392 2017-05-11] (Intel Corporation)
R1 ESProtectionDriver; C:\WINDOWS\system32\drivers\mbae64.sys [152184 2018-06-12] (Malwarebytes)
R3 HfAudio; C:\WINDOWS\system32\DRIVERS\HfAudio.sys [65008 2018-03-06] (Screenovate Technologies Ltd.)
R3 HidEventFilter; C:\WINDOWS\System32\drivers\HidEventFilter.sys [54816 2017-06-13] (Intel Corporation)
S3 HipShieldK; C:\WINDOWS\System32\drivers\HipShieldK.sys [218336 2017-10-10] (McAfee, Inc.)
R4 hitmanpro37; C:\WINDOWS\system32\drivers\hitmanpro37.sys [55232 2018-06-12] ()
S3 iaLPSS2_GPIO2; C:\WINDOWS\System32\drivers\iaLPSS2_GPIO2.sys [97912 2017-05-09] (Intel Corporation)
S3 iaStorAfs; C:\WINDOWS\System32\drivers\iaStorAfs.sys [70656 2017-07-01] (Intel Corporation)
R2 MBAMChameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [190696 2018-06-12] (Malwarebytes)
R3 MBAMFarflt; C:\WINDOWS\System32\DRIVERS\farflt.sys [112872 2018-06-12] (Malwarebytes)
R3 MBAMProtection; C:\WINDOWS\system32\DRIVERS\mbam.sys [44768 2018-06-12] (Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [253664 2018-06-12] (Malwarebytes)
R3 mfeaack; C:\WINDOWS\System32\drivers\mfeaack.sys [497568 2018-02-28] (McAfee, LLC)
R3 mfeavfk; C:\WINDOWS\System32\drivers\mfeavfk.sys [360352 2018-02-28] (McAfee, LLC)
U3 mfeavfk01; no ImagePath
S0 mfeelamk; C:\WINDOWS\System32\drivers\mfeelamk.sys [83952 2018-02-28] (McAfee, LLC)
R3 mfefirek; C:\WINDOWS\System32\drivers\mfefirek.sys [529312 2018-02-28] (McAfee, LLC)
R0 mfehidk; C:\WINDOWS\System32\drivers\mfehidk.sys [953248 2018-02-28] (McAfee, LLC)
R3 mfencbdc; C:\WINDOWS\System32\DRIVERS\mfencbdc.sys [543624 2018-04-30] (McAfee LLC.)
S3 mfencrk; C:\WINDOWS\System32\DRIVERS\mfencrk.sys [108432 2018-04-30] (McAfee LLC.)
R3 mfeplk; C:\WINDOWS\System32\drivers\mfeplk.sys [115616 2018-02-28] (McAfee, LLC)
R3 mfesapsn; C:\Program Files (x86)\McAfee\SiteAdvisor\x64\mfesapsn.sys [111608 2017-02-14] (McAfee, Inc.)
R0 mfewfpk; C:\WINDOWS\System32\drivers\mfewfpk.sys [252832 2018-02-28] (McAfee, LLC)
R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [984040 2017-06-20] (Realtek )
R3 RTSUER; C:\WINDOWS\system32\Drivers\RtsUer.sys [420832 2017-04-28] (Realsil Semiconductor Corporation)
R3 ScrHIDDriver; C:\WINDOWS\system32\DRIVERS\ScrHIDDriver.sys [58864 2018-03-06] (Screenovate Technologies Ltd.)
R2 SmbCoSvc; C:\WINDOWS\system32\DRIVERS\SmbCo10X64.sys [119528 2018-03-20] (Rivet Networks, LLC.)
S3 usbrndis6; C:\WINDOWS\System32\drivers\usb80236.sys [23040 2017-09-29] (Microsoft Corporation)
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [44608 2017-09-29] (Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [309144 2017-09-29] (Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [119192 2017-09-29] (Microsoft Corporation)
S1 prisafe; \SystemRoot\System32\drivers\prisafe.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2018-06-12 21:50 - 2018-06-12 21:51 - 000025245 _____ C:\Users\Tom Joram Vitor\Downloads\FRST.txt
2018-06-12 21:50 - 2018-06-12 21:50 - 000000000 ____D C:\FRST
2018-06-12 21:47 - 2018-06-12 21:47 - 002413056 _____ (Farbar) C:\Users\Tom Joram Vitor\Downloads\FRST64.exe
2018-06-12 19:19 - 2018-06-12 19:20 - 000000000 ____D C:\Users\Tom Joram Vitor\Desktop\Malware Removal
2018-06-12 19:17 - 2018-06-12 19:17 - 000012872 _____ (SurfRight B.V.) C:\WINDOWS\system32\bootdelete.exe
2018-06-12 19:17 - 2018-06-12 19:17 - 000000340 _____ C:\WINDOWS\system32\bootdelete.lst
2018-06-12 18:59 - 2018-06-12 18:59 - 000055232 _____ C:\WINDOWS\system32\Drivers\hitmanpro37.sys
2018-06-12 18:58 - 2018-06-12 19:19 - 000000000 ____D C:\ProgramData\HitmanPro
2018-06-12 18:53 - 2018-06-12 18:53 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
2018-06-12 18:44 - 2018-06-12 18:48 - 000000000 ____D C:\AdwCleaner
2018-06-12 18:33 - 2018-06-12 20:58 - 000103656 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys
2018-06-12 18:33 - 2018-06-12 18:50 - 000112872 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\farflt.sys
2018-06-12 18:33 - 2018-06-12 18:50 - 000044768 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
2018-06-12 18:33 - 2018-06-12 18:33 - 000190696 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MbamChameleon.sys
2018-06-12 17:57 - 2018-06-12 17:59 - 000000000 ___HD C:\$WINDOWS.~BT
2018-06-12 17:57 - 2018-06-12 17:57 - 000000000 ____D C:\Windows.old
2018-06-12 17:55 - 2018-06-12 18:50 - 000253664 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys
2018-06-12 17:55 - 2018-06-12 18:33 - 000152184 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbae64.sys
2018-06-12 17:55 - 2018-06-12 17:55 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2018-06-12 17:54 - 2018-06-12 17:54 - 000000000 ____D C:\ProgramData\Malwarebytes
2018-06-12 17:54 - 2018-06-12 17:54 - 000000000 ____D C:\Program Files\Malwarebytes
2018-06-12 17:43 - 2018-06-12 17:52 - 074288784 _____ (Malwarebytes ) C:\Users\Tom Joram Vitor\Downloads\mb3-setup-1878.1878-3.5.1.2522.exe
2018-06-12 17:37 - 2018-06-12 17:37 - 001802704 _____ (Bleeping Computer, LLC) C:\Users\Tom Joram Vitor\Downloads\iExplore.exe
2018-06-12 17:00 - 2018-06-12 20:40 - 000003606 _____ C:\WINDOWS\System32\Tasks\McAfee DAT Built in test
2018-06-12 16:11 - 2018-06-13 08:22 - 000000000 ___HD C:\$SysReset
2018-06-12 15:56 - 2018-06-12 15:56 - 000000000 ____D C:\Users\Tom Joram Vitor\AppData\Roaming\Mozilla
2018-06-12 15:54 - 2018-06-12 18:30 - 000000000 ____D C:\ProgramData\55e0cb0e-c21b-4f2d-ac71-2f3455b1b89f
2018-06-12 15:54 - 2018-06-12 15:54 - 000140800 _____ C:\Users\Tom Joram Vitor\AppData\Local\installer.dat
2018-06-12 15:54 - 2018-06-12 15:54 - 000000000 ____D C:\ProgramData\47765288-ac79-4c5b-b2c6-5c276ae6fc9c
2018-06-12 15:52 - 2018-06-12 15:55 - 000000000 ____D C:\Program Files (x86)\foldershare
2018-06-12 15:47 - 2018-06-12 15:47 - 001989120 _____ C:\WINDOWS\rucjlxzkqboopktx.lucj
2018-06-12 15:45 - 2018-06-12 18:30 - 000000000 ____D C:\Program Files (x86)\KMSPico 10.2.1 Final
2018-06-11 15:45 - 2018-06-11 15:45 - 000111046 _____ C:\WINDOWS\uninstaller.dat
2018-06-11 09:32 - 2018-06-11 09:32 - 000000000 ____D C:\Users\Tom Joram Vitor\Desktop\New folder
2018-06-07 20:03 - 2018-06-12 15:47 - 000000000 ____D C:\Users\Tom Joram Vitor\AppData\Local\Spotify
2018-06-07 20:03 - 2018-06-07 20:03 - 000001888 _____ C:\Users\Tom Joram Vitor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spotify.lnk
2018-06-07 19:51 - 2018-06-12 15:44 - 000000000 ____D C:\Users\Tom Joram Vitor\AppData\Roaming\Spotify
2018-06-07 19:38 - 2018-06-11 05:57 - 000000509 _____ C:\WINDOWS\system32\Drivers\etc\hosts.ics
2018-06-07 10:39 - 2018-06-07 10:39 - 000000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf
2018-06-07 06:29 - 2018-06-07 21:14 - 000000000 ____D C:\Users\Tom Joram Vitor\AppData\Local\Intel
2018-06-07 06:10 - 2018-06-10 17:42 - 000000000 ____D C:\Users\Tom Joram Vitor\AppData\Roaming\Videoder
2018-06-07 06:10 - 2018-06-07 06:10 - 000001906 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Videoder.lnk
2018-06-07 06:10 - 2018-06-07 06:10 - 000000000 ____D C:\Users\Tom Joram Vitor\AppData\Local\Videoder
2018-06-07 06:10 - 2018-06-07 06:10 - 000000000 ____D C:\Users\Tom Joram Vitor\AppData\Local\insight-nodejs
2018-06-07 06:10 - 2018-06-07 06:10 - 000000000 ____D C:\Users\Tom Joram Vitor\.config
2018-06-07 06:09 - 2018-06-07 06:10 - 000000000 ____D C:\Program Files\Videoder
2018-06-07 05:54 - 2018-06-07 05:54 - 000000000 ____D C:\Users\Tom Joram Vitor\AppData\Roaming\BluestacksCN
2018-06-06 19:02 - 2018-06-06 19:03 - 000000000 ____D C:\Users\Tom Joram Vitor\Desktop\Student Reader
2018-06-05 22:23 - 2018-06-12 17:06 - 000004176 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{2184C026-1EC9-470B-87FE-409060D4B389}
2018-06-05 22:18 - 2017-05-24 06:23 - 000000000 ____D C:\Users\Tom Joram Vitor\Downloads\non_cc_assessments
2018-06-03 22:18 - 2018-06-11 06:02 - 000000000 ____D C:\Users\Tom Joram Vitor\Desktop\Media and Information Literacy
2018-06-03 21:18 - 2018-06-03 21:18 - 000000000 ____D C:\Users\Tom Joram Vitor\AppData\Local\4kdownload.com
2018-06-03 20:42 - 2018-06-12 18:24 - 000000000 ____D C:\Users\Tom Joram Vitor\AppData\Roaming\DMCache
2018-06-03 20:42 - 2018-06-11 09:32 - 000000000 ____D C:\Users\Tom Joram Vitor\Downloads\Video
2018-06-03 20:42 - 2018-06-07 06:06 - 000000000 ____D C:\Users\Tom Joram Vitor\AppData\Roaming\IDM
2018-06-03 20:42 - 2018-06-07 05:25 - 000000000 ____D C:\Users\Tom Joram Vitor\Downloads\Compressed
2018-06-03 20:42 - 2018-06-03 20:43 - 000000000 ____D C:\Program Files (x86)\Internet Download Manager
2018-06-03 20:42 - 2018-06-03 20:42 - 000000000 ____D C:\Users\Tom Joram Vitor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Download Manager
2018-06-03 20:42 - 2018-06-03 20:42 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Internet Download Manager
2018-06-03 20:42 - 2018-06-03 20:42 - 000000000 ____D C:\ProgramData\IDM
2018-06-03 20:41 - 2018-06-03 20:41 - 000000000 ____D C:\Users\Tom Joram Vitor\Downloads\Internet Download Manager
2018-06-03 18:18 - 2018-06-07 10:51 - 000000000 ____D C:\Users\Tom Joram Vitor\Desktop\SHS SCIENCE PPT
2018-06-01 19:44 - 2018-06-01 19:44 - 000003144 _____ C:\WINDOWS\System32\Tasks\SmartByte Telemetry
2018-06-01 19:44 - 2018-06-01 19:44 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Rivet Networks
2018-06-01 19:44 - 2018-06-01 19:44 - 000000000 ____D C:\Program Files\Rivet Networks
2018-06-01 19:22 - 2018-06-01 19:22 - 000000000 ____D C:\WINDOWS\system32\ihvmanager
2018-06-01 13:24 - 2018-06-01 13:24 - 000000000 ____D C:\Users\Tom Joram Vitor\AppData\Roaming\PCDr
2018-06-01 11:52 - 2018-06-06 20:52 - 000004244 _____ C:\WINDOWS\System32\Tasks\Dell SupportAssistAgent AutoUpdate
2018-06-01 11:52 - 2018-06-01 11:52 - 000000000 ____D C:\ProgramData\Dell Inc
2018-06-01 07:36 - 2018-06-01 07:36 - 000000000 ____D C:\Users\Tom Joram Vitor\AppData\LocalLow\Temp
2018-05-31 10:09 - 2018-05-31 10:09 - 000000000 ____D C:\Users\Public\Documents\Steam
2018-05-31 10:01 - 2018-05-31 10:01 - 000000000 ____D C:\Users\Tom Joram Vitor\Documents\Klei
2018-05-31 10:00 - 2018-05-31 10:08 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dont Starve Together A New Reign
2018-05-31 09:59 - 2018-05-31 10:08 - 000000000 ____D C:\Program Files (x86)\Dont Starve Together A New Reign
2018-05-31 09:58 - 2018-05-31 09:58 - 000000000 ____D C:\Users\Tom Joram Vitor\AppData\Roaming\WinRAR
2018-05-31 06:33 - 2018-05-31 06:33 - 000000000 ____D C:\Users\Tom Joram Vitor\AppData\Local\RadeonSettings
2018-05-31 06:32 - 2018-05-31 06:32 - 000003074 _____ C:\WINDOWS\System32\Tasks\StartDVR
2018-05-31 06:32 - 2018-05-31 06:32 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Settings
2018-05-31 06:32 - 2018-05-31 06:32 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Problem Report Wizard
2018-05-31 06:31 - 2018-05-31 06:31 - 000000000 ____D C:\Program Files (x86)\AMD
2018-05-31 06:28 - 2018-05-31 06:28 - 000000000 ____D C:\Program Files\Common Files\ATI Technologies
2018-05-31 06:23 - 2018-05-31 06:23 - 000000000 ____D C:\Users\Tom Joram Vitor\AppData\Roaming\ATI
2018-05-31 06:23 - 2018-05-31 06:23 - 000000000 ____D C:\Users\Tom Joram Vitor\AppData\Local\ATI
2018-05-31 06:23 - 2018-05-31 06:23 - 000000000 ____D C:\ProgramData\ATI
2018-05-31 06:20 - 2018-05-31 06:20 - 000000000 ____D C:\Users\Tom Joram Vitor\AppData\Local\RadeonInstaller
2018-05-29 19:04 - 2018-05-29 19:04 - 000000000 ____D C:\Users\Tom Joram Vitor\AppData\Local\FILECACHE
2018-05-29 19:04 - 2010-06-02 04:55 - 000527192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_7.dll
2018-05-29 19:04 - 2010-06-02 04:55 - 000518488 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_7.dll
2018-05-29 19:04 - 2010-06-02 04:55 - 000239960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_7.dll
2018-05-29 19:04 - 2010-06-02 04:55 - 000176984 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_7.dll
2018-05-29 19:04 - 2010-06-02 04:55 - 000077656 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_5.dll
2018-05-29 19:04 - 2010-06-02 04:55 - 000074072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_5.dll
2018-05-29 19:04 - 2010-05-26 11:41 - 002526056 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_43.dll
2018-05-29 19:04 - 2010-05-26 11:41 - 002401112 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_43.dll
2018-05-29 19:04 - 2010-05-26 11:41 - 002106216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_43.dll
2018-05-29 19:04 - 2010-05-26 11:41 - 001998168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_43.dll
2018-05-29 19:04 - 2010-05-26 11:41 - 001907552 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dcsx_43.dll
2018-05-29 19:04 - 2010-05-26 11:41 - 001868128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dcsx_43.dll
2018-05-29 19:04 - 2010-05-26 11:41 - 000511328 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_43.dll
2018-05-29 19:04 - 2010-05-26 11:41 - 000470880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_43.dll
2018-05-29 19:04 - 2010-05-26 11:41 - 000276832 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx11_43.dll
2018-05-29 19:04 - 2010-05-26 11:41 - 000248672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx11_43.dll
2018-05-29 19:04 - 2010-02-04 10:01 - 000530776 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_6.dll
2018-05-29 19:04 - 2010-02-04 10:01 - 000528216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_6.dll
2018-05-29 19:04 - 2010-02-04 10:01 - 000238936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_6.dll
2018-05-29 19:04 - 2010-02-04 10:01 - 000176984 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_6.dll
2018-05-29 19:04 - 2010-02-04 10:01 - 000078680 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_4.dll
2018-05-29 19:04 - 2010-02-04 10:01 - 000074072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_4.dll
2018-05-29 19:04 - 2010-02-04 10:01 - 000024920 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_7.dll
2018-05-29 19:04 - 2010-02-04 10:01 - 000022360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\X3DAudio1_7.dll
2018-05-29 19:04 - 2009-09-04 17:44 - 000517960 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_5.dll
2018-05-29 19:04 - 2009-09-04 17:44 - 000515416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_5.dll
2018-05-29 19:04 - 2009-09-04 17:44 - 000238936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_5.dll
2018-05-29 19:04 - 2009-09-04 17:44 - 000176968 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_5.dll
2018-05-29 19:04 - 2009-09-04 17:44 - 000073544 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_3.dll
2018-05-29 19:04 - 2009-09-04 17:44 - 000069464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_3.dll
2018-05-29 19:04 - 2009-09-04 17:29 - 005554512 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dcsx_42.dll
2018-05-29 19:04 - 2009-09-04 17:29 - 005501792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dcsx_42.dll
2018-05-29 19:04 - 2009-09-04 17:29 - 002582888 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_42.dll
2018-05-29 19:04 - 2009-09-04 17:29 - 002475352 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_42.dll
2018-05-29 19:04 - 2009-09-04 17:29 - 001974616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_42.dll
2018-05-29 19:04 - 2009-09-04 17:29 - 001892184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_42.dll
2018-05-29 19:04 - 2009-09-04 17:29 - 000523088 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_42.dll
2018-05-29 19:04 - 2009-09-04 17:29 - 000453456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_42.dll
2018-05-29 19:04 - 2009-09-04 17:29 - 000285024 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx11_42.dll
2018-05-29 19:04 - 2009-09-04 17:29 - 000235344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx11_42.dll
2018-05-29 19:04 - 2009-03-16 14:18 - 000521560 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_4.dll
2018-05-29 19:04 - 2009-03-16 14:18 - 000517448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_4.dll
2018-05-29 19:04 - 2009-03-16 14:18 - 000235352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_4.dll
2018-05-29 19:04 - 2009-03-16 14:18 - 000174936 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_4.dll
2018-05-29 19:04 - 2009-03-16 14:18 - 000024920 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_6.dll
2018-05-29 19:04 - 2009-03-16 14:18 - 000022360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\X3DAudio1_6.dll
2018-05-29 19:04 - 2009-03-09 15:27 - 005425496 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_41.dll
2018-05-29 19:04 - 2009-03-09 15:27 - 004178264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_41.dll
2018-05-29 19:04 - 2009-03-09 15:27 - 002430312 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_41.dll
2018-05-29 19:04 - 2009-03-09 15:27 - 001846632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_41.dll
2018-05-29 19:04 - 2009-03-09 15:27 - 000520544 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_41.dll
2018-05-29 19:04 - 2009-03-09 15:27 - 000453456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_41.dll
2018-05-29 19:04 - 2008-10-27 10:04 - 000518480 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_3.dll
2018-05-29 19:04 - 2008-10-27 10:04 - 000514384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_3.dll
2018-05-29 19:04 - 2008-10-27 10:04 - 000235856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_3.dll
2018-05-29 19:04 - 2008-10-27 10:04 - 000175440 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_3.dll
2018-05-29 19:04 - 2008-10-27 10:04 - 000074576 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_2.dll
2018-05-29 19:04 - 2008-10-27 10:04 - 000070992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_2.dll
2018-05-29 19:04 - 2008-10-27 10:04 - 000025936 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_5.dll
2018-05-29 19:04 - 2008-10-27 10:04 - 000023376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\X3DAudio1_5.dll
2018-05-29 19:04 - 2008-10-15 06:22 - 005631312 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_40.dll
2018-05-29 19:04 - 2008-10-15 06:22 - 004379984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_40.dll
2018-05-29 19:04 - 2008-10-15 06:22 - 002605920 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_40.dll
2018-05-29 19:04 - 2008-10-15 06:22 - 002036576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_40.dll
2018-05-29 19:04 - 2008-10-15 06:22 - 000519000 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_40.dll
2018-05-29 19:04 - 2008-10-15 06:22 - 000452440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_40.dll
2018-05-29 19:04 - 2008-07-31 10:41 - 000238088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_2.dll
2018-05-29 19:04 - 2008-07-31 10:41 - 000177672 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_2.dll
2018-05-29 19:04 - 2008-07-31 10:41 - 000072200 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_1.dll
2018-05-29 19:04 - 2008-07-31 10:41 - 000068616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_1.dll
2018-05-29 19:04 - 2008-07-31 10:40 - 000513544 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_2.dll
2018-05-29 19:04 - 2008-07-31 10:40 - 000509448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_2.dll
2018-05-29 19:04 - 2008-07-10 11:01 - 000467984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_39.dll
2018-05-29 19:04 - 2008-07-10 11:00 - 004992520 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_39.dll
2018-05-29 19:04 - 2008-07-10 11:00 - 003851784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_39.dll
2018-05-29 19:04 - 2008-07-10 11:00 - 001942552 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_39.dll
2018-05-29 19:04 - 2008-07-10 11:00 - 001493528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_39.dll
2018-05-29 19:04 - 2008-07-10 11:00 - 000540688 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_39.dll
2018-05-29 19:04 - 2008-05-30 14:19 - 000511496 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_1.dll
2018-05-29 19:04 - 2008-05-30 14:19 - 000507400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_1.dll
2018-05-29 19:04 - 2008-05-30 14:18 - 000238088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_1.dll
2018-05-29 19:04 - 2008-05-30 14:18 - 000177672 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_1.dll
2018-05-29 19:04 - 2008-05-30 14:17 - 000068104 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_0.dll
2018-05-29 19:04 - 2008-05-30 14:17 - 000065032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_0.dll
2018-05-29 19:04 - 2008-05-30 14:17 - 000025608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\X3DAudio1_4.dll
2018-05-29 19:04 - 2008-05-30 14:16 - 000028168 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_4.dll
2018-05-29 19:04 - 2008-05-30 14:11 - 004991496 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_38.dll
2018-05-29 19:04 - 2008-05-30 14:11 - 003850760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_38.dll
2018-05-29 19:04 - 2008-05-30 14:11 - 001941528 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_38.dll
2018-05-29 19:04 - 2008-05-30 14:11 - 001491992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_38.dll
2018-05-29 19:04 - 2008-05-30 14:11 - 000540688 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_38.dll
2018-05-29 19:04 - 2008-05-30 14:11 - 000467984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_38.dll
2018-05-29 19:04 - 2008-03-05 16:04 - 000489480 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_0.dll
2018-05-29 19:04 - 2008-03-05 16:03 - 000479752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_0.dll
2018-05-29 19:04 - 2008-03-05 16:03 - 000238088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_0.dll
2018-05-29 19:04 - 2008-03-05 16:03 - 000177672 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_0.dll
2018-05-29 19:04 - 2008-03-05 16:00 - 000028168 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_3.dll
2018-05-29 19:04 - 2008-03-05 16:00 - 000025608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\X3DAudio1_3.dll
2018-05-29 19:04 - 2008-03-05 15:56 - 004910088 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_37.dll
2018-05-29 19:04 - 2008-03-05 15:56 - 003786760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_37.dll
2018-05-29 19:04 - 2008-03-05 15:56 - 001860120 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_37.dll
2018-05-29 19:04 - 2008-03-05 15:56 - 001420824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_37.dll
2018-05-29 19:04 - 2008-02-05 23:07 - 000529424 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_37.dll
2018-05-29 19:04 - 2008-02-05 23:07 - 000462864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_37.dll
2018-05-29 19:04 - 2007-10-22 03:40 - 000411656 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_10.dll
2018-05-29 19:04 - 2007-10-22 03:39 - 000267272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_10.dll
2018-05-29 19:04 - 2007-10-22 03:37 - 000021000 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_2.dll
2018-05-29 19:04 - 2007-10-22 03:37 - 000017928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\X3DAudio1_2.dll
2018-05-29 19:04 - 2007-10-12 15:14 - 005081608 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_36.dll
2018-05-29 19:04 - 2007-10-12 15:14 - 003734536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_36.dll
2018-05-29 19:04 - 2007-10-12 15:14 - 002006552 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_36.dll
2018-05-29 19:04 - 2007-10-12 15:14 - 001374232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_36.dll
2018-05-29 19:04 - 2007-10-02 09:56 - 000508264 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_36.dll
2018-05-29 19:04 - 2007-10-02 09:56 - 000444776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_36.dll
2018-05-29 19:04 - 2007-07-20 00:57 - 000411496 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_9.dll
2018-05-29 19:04 - 2007-07-20 00:57 - 000267112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_9.dll
2018-05-29 19:04 - 2007-07-19 18:14 - 005073256 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_35.dll
2018-05-29 19:04 - 2007-07-19 18:14 - 003727720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_35.dll
2018-05-29 19:04 - 2007-07-19 18:14 - 001985904 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_35.dll
2018-05-29 19:04 - 2007-07-19 18:14 - 001358192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_35.dll
2018-05-29 19:04 - 2007-07-19 18:14 - 000508264 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_35.dll
2018-05-29 19:04 - 2007-07-19 18:14 - 000444776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_35.dll
2018-05-29 19:04 - 2007-06-20 20:49 - 000409960 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_8.dll
2018-05-29 19:04 - 2007-06-20 20:46 - 000266088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_8.dll
2018-05-29 19:04 - 2007-05-16 16:45 - 004496232 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_34.dll
2018-05-29 19:04 - 2007-05-16 16:45 - 003497832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_34.dll
2018-05-29 19:04 - 2007-05-16 16:45 - 001401200 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_34.dll
2018-05-29 19:04 - 2007-05-16 16:45 - 001124720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_34.dll
2018-05-29 19:04 - 2007-05-16 16:45 - 000506728 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_34.dll
2018-05-29 19:04 - 2007-05-16 16:45 - 000443752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_34.dll
2018-05-29 19:04 - 2007-04-04 18:55 - 000403304 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_7.dll
2018-05-29 19:04 - 2007-04-04 18:55 - 000261480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_7.dll
2018-05-29 19:04 - 2007-04-04 18:54 - 000107368 _____ (Microsoft Corporation) C:\WINDOWS\system32\xinput1_3.dll
2018-05-29 19:04 - 2007-04-04 18:53 - 000081768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xinput1_3.dll
2018-05-29 19:04 - 2007-03-15 16:57 - 000506728 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_33.dll
2018-05-29 19:04 - 2007-03-15 16:57 - 000443752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_33.dll
2018-05-29 19:04 - 2007-03-12 16:42 - 004494184 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_33.dll
2018-05-29 19:04 - 2007-03-12 16:42 - 003495784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_33.dll
2018-05-29 19:04 - 2007-03-12 16:42 - 001400176 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_33.dll
2018-05-29 19:04 - 2007-03-12 16:42 - 001123696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_33.dll
2018-05-29 19:04 - 2007-03-05 12:42 - 000017688 _____ (Microsoft Corporation) C:\WINDOWS\system32\x3daudio1_1.dll
2018-05-29 19:04 - 2007-03-05 12:42 - 000015128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\x3daudio1_1.dll
2018-05-29 19:04 - 2007-01-24 15:27 - 000393576 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_6.dll
2018-05-29 19:04 - 2007-01-24 15:27 - 000255848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_6.dll
2018-05-29 19:04 - 2006-12-08 12:02 - 000251672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_5.dll
2018-05-29 19:04 - 2006-12-08 12:00 - 000390424 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_5.dll
2018-05-29 19:04 - 2006-11-29 13:06 - 004398360 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_32.dll
2018-05-29 19:04 - 2006-11-29 13:06 - 003426072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_32.dll
2018-05-29 19:04 - 2006-11-29 13:06 - 000469264 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10.dll
2018-05-29 19:04 - 2006-11-29 13:06 - 000440080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10.dll
2018-05-29 19:04 - 2006-09-28 16:05 - 003977496 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_31.dll
2018-05-29 19:04 - 2006-09-28 16:05 - 002414360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_31.dll
2018-05-29 19:04 - 2006-09-28 16:05 - 000237848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_4.dll
2018-05-29 19:04 - 2006-09-28 16:04 - 000364824 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_4.dll
2018-05-29 19:04 - 2006-07-28 09:31 - 000083736 _____ (Microsoft Corporation) C:\WINDOWS\system32\xinput1_2.dll
2018-05-29 19:04 - 2006-07-28 09:30 - 000363288 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_3.dll
2018-05-29 19:04 - 2006-07-28 09:30 - 000236824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_3.dll
2018-05-29 19:04 - 2006-07-28 09:30 - 000062744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xinput1_2.dll
2018-05-29 19:04 - 2006-05-31 07:24 - 000230168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_2.dll
2018-05-29 19:04 - 2006-05-31 07:22 - 000354072 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_2.dll
2018-05-29 19:04 - 2006-03-31 12:41 - 003927248 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_30.dll
2018-05-29 19:04 - 2006-03-31 12:40 - 002388176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_30.dll
2018-05-29 19:04 - 2006-03-31 12:40 - 000352464 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_1.dll
2018-05-29 19:04 - 2006-03-31 12:39 - 000229584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_1.dll
2018-05-29 19:04 - 2006-03-31 12:39 - 000083664 _____ (Microsoft Corporation) C:\WINDOWS\system32\xinput1_1.dll
2018-05-29 19:04 - 2006-03-31 12:39 - 000062672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xinput1_1.dll
2018-05-29 19:03 - 2006-02-03 08:43 - 003830992 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_29.dll
2018-05-29 19:03 - 2006-02-03 08:43 - 002332368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_29.dll
2018-05-29 19:03 - 2006-02-03 08:42 - 000355536 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_0.dll
2018-05-29 19:03 - 2006-02-03 08:42 - 000230096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_0.dll
2018-05-29 19:03 - 2006-02-03 08:41 - 000016592 _____ (Microsoft Corporation) C:\WINDOWS\system32\x3daudio1_0.dll
2018-05-29 19:03 - 2006-02-03 08:41 - 000014032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\x3daudio1_0.dll
2018-05-29 19:03 - 2005-12-05 18:09 - 003815120 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_28.dll
2018-05-29 19:03 - 2005-12-05 18:09 - 002323664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_28.dll
2018-05-29 19:03 - 2005-07-22 19:59 - 003807440 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_27.dll
2018-05-29 19:03 - 2005-07-22 19:59 - 002319568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_27.dll
2018-05-29 19:03 - 2005-05-26 15:34 - 003767504 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_26.dll
2018-05-29 19:03 - 2005-05-26 15:34 - 002297552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_26.dll
2018-05-29 19:03 - 2005-03-18 17:19 - 003823312 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_25.dll
2018-05-29 19:03 - 2005-03-18 17:19 - 002337488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_25.dll
2018-05-29 19:03 - 2005-02-05 19:45 - 003544272 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_24.dll
2018-05-29 19:03 - 2005-02-05 19:45 - 002222800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_24.dll
2018-05-29 16:02 - 2018-05-29 16:02 - 000000000 ____D C:\Users\Tom Joram Vitor\Documents\Custom Office Templates
2018-05-29 13:01 - 2018-05-29 13:04 - 000000000 ____D C:\WINDOWS\system32\MRT
2018-05-29 13:01 - 2018-05-29 13:01 - 141696960 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT-KB890830.exe
2018-05-29 13:01 - 2018-05-29 13:01 - 141696960 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2018-05-29 13:00 - 2018-05-29 13:00 - 000001372 _____ C:\Users\Tom Joram Vitor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\McAfee WebAdvisor.lnk
2018-05-29 12:06 - 2018-05-29 12:07 - 000000000 ____D C:\Users\Tom Joram Vitor\Downloads\Educational Videos
2018-05-29 11:09 - 2018-05-29 11:09 - 000000000 ____D C:\Users\Tom Joram Vitor\Downloads\Windows Themes
2018-05-29 11:08 - 2018-06-12 19:17 - 000000000 ____D C:\Users\Tom Joram Vitor\Downloads\Installers
2018-05-29 11:08 - 2018-06-07 09:32 - 000000000 ____D C:\Users\Tom Joram Vitor\Desktop\Teacher's Guide
2018-05-29 10:54 - 2018-06-11 10:03 - 000000000 ____D C:\Users\Tom Joram Vitor\Desktop\TJ
2018-05-29 10:53 - 2018-05-29 10:53 - 000000000 ____D C:\Users\Tom Joram Vitor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2018-05-29 10:52 - 2018-05-29 10:52 - 000000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
2018-05-27 21:35 - 2018-05-27 21:35 - 000000000 ____D C:\Users\Tom Joram Vitor\Documents\FeedbackHub
2018-05-27 13:42 - 2018-05-27 13:42 - 000000000 ____D C:\Users\Tom Joram Vitor\AppData\Local\__SHARED
2018-05-27 13:21 - 2018-06-07 06:11 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SHAREit
2018-05-27 13:21 - 2018-05-31 09:56 - 000000000 ____D C:\Users\Tom Joram Vitor\Downloads\SHAREit
2018-05-27 13:21 - 2018-05-27 13:21 - 000000000 ____D C:\Users\Tom Joram Vitor\AppData\Roaming\Umeng
2018-05-27 13:21 - 2018-05-27 13:21 - 000000000 ____D C:\Users\Tom Joram Vitor\AppData\Local\SHAREit Technologies
2018-05-27 13:21 - 2018-05-27 13:21 - 000000000 ____D C:\Program Files (x86)\SHAREit Technologies
2018-05-27 12:56 - 2018-05-27 12:56 - 000000057 _____ C:\ProgramData\Ament.ini
2018-05-27 12:56 - 2018-05-27 12:56 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP
2018-05-27 12:56 - 2018-05-27 12:56 - 000000000 ____D C:\ProgramData\HP
2018-05-27 12:56 - 2018-05-27 12:56 - 000000000 ____D C:\Program Files\HP
2018-05-27 12:56 - 2018-05-27 12:56 - 000000000 ____D C:\Program Files (x86)\HP
2018-05-27 12:45 - 2018-05-27 12:59 - 000000000 ____D C:\Users\Tom Joram Vitor\AppData\Local\HP
2018-05-27 11:01 - 2018-06-09 20:36 - 000002790 _____ C:\Users\Tom Joram Vitor\Documents\startup.txt
2018-05-27 10:59 - 2018-06-11 17:20 - 000004210 _____ C:\WINDOWS\System32\Tasks\CCleaner Update
2018-05-27 10:59 - 2018-05-27 10:59 - 000002890 _____ C:\WINDOWS\System32\Tasks\CCleanerSkipUAC
2018-05-27 10:59 - 2018-05-27 10:59 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2018-05-27 10:59 - 2018-05-27 10:59 - 000000000 ____D C:\Program Files\CCleaner
2018-05-27 10:55 - 2018-05-27 10:55 - 000000000 ___HD C:\OneDriveTemp
2018-05-27 04:14 - 2018-06-12 18:35 - 001262752 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2018-05-27 04:12 - 2018-05-27 04:12 - 000000000 _SHDL C:\Users\Default User
2018-05-27 04:12 - 2018-05-27 04:12 - 000000000 _SHDL C:\Users\All Users
2018-05-27 04:12 - 2018-05-27 04:12 - 000000000 _SHDL C:\Documents and Settings
2018-05-27 04:12 - 2017-09-29 21:41 - 002241024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2018-05-27 04:11 - 2018-06-12 18:50 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2018-05-27 04:11 - 2018-06-12 18:32 - 000000000 ____D C:\WINDOWS\System32\Tasks\McAfee
2018-05-27 04:11 - 2018-06-12 17:06 - 000003126 _____ C:\WINDOWS\System32\Tasks\McAfeeLogon
2018-05-27 04:11 - 2018-06-01 21:30 - 000003446 _____ C:\WINDOWS\System32\Tasks\McAfee Remediation (Prepare)
2018-05-27 04:11 - 2018-05-31 06:32 - 000003160 _____ C:\WINDOWS\System32\Tasks\StartCN
2018-05-27 04:11 - 2018-05-27 04:12 - 000003180 _____ C:\WINDOWS\System32\Tasks\Intel PTT EK Recertification
2018-05-27 04:11 - 2018-05-27 04:11 - 000026156 _____ C:\WINDOWS\system32\emptyregdb.dat
2018-05-27 04:11 - 2018-05-26 14:38 - 000000000 ____D C:\WINDOWS\System32\Tasks\Intel
2018-05-27 04:07 - 2018-05-27 04:07 - 000001576 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2018-05-27 04:05 - 2018-05-27 04:05 - 000000000 ____D C:\WINDOWS\system32\config\bbimigrate
2018-05-27 04:02 - 2018-05-27 04:02 - 000000000 ____D C:\ProgramData\USOShared
2018-05-27 03:57 - 2018-05-27 03:57 - 000001115 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Waves MaxxAudioPro.lnk
2018-05-27 03:57 - 2018-05-27 03:57 - 000000000 ____D C:\WINDOWS\system32\RTCOM
2018-05-27 03:57 - 2018-05-27 03:57 - 000000000 ____D C:\Program Files\Waves
2018-05-27 03:57 - 2018-05-27 03:57 - 000000000 ____D C:\Program Files (x86)\Realtek
2018-05-27 03:56 - 2018-06-07 06:30 - 000000000 ____D C:\Program Files (x86)\VulkanRT
2018-05-27 03:56 - 2018-05-27 03:57 - 000000000 ____D C:\WINDOWS\SysWOW64\RTCOM
2018-05-27 03:56 - 2018-05-27 03:56 - 000000000 ____D C:\Program Files\Realtek
2018-05-27 03:56 - 2018-05-27 03:56 - 000000000 _____ C:\WINDOWS\system32\GfxValDisplayLog.bin
2018-05-27 03:56 - 2018-03-02 10:04 - 000828216 _____ C:\WINDOWS\SysWOW64\vulkan-1.dll
2018-05-27 03:56 - 2018-03-02 10:03 - 000960312 _____ C:\WINDOWS\system32\vulkan-1.dll
2018-05-27 03:56 - 2018-03-02 10:03 - 000683832 _____ C:\WINDOWS\system32\vulkaninfo.exe
2018-05-27 03:56 - 2018-03-02 10:03 - 000575800 _____ C:\WINDOWS\SysWOW64\vulkaninfo.exe
2018-05-27 03:55 - 2018-05-27 04:06 - 000000000 ____D C:\Program Files\Intel
2018-05-27 03:55 - 2018-05-27 04:05 - 000000000 ____D C:\Intel
2018-05-27 03:54 - 2018-06-01 19:34 - 000000000 ____D C:\ProgramData\Package Cache
2018-05-27 03:54 - 2018-05-31 06:31 - 000000000 ____D C:\AMD
2018-05-27 03:54 - 2018-05-27 03:54 - 000000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_esif_umdf2_02_00_00.Wdf
2018-05-27 03:54 - 2018-05-27 03:54 - 000000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_esif_lf_01011.Wdf
2018-05-27 03:54 - 2018-05-27 03:54 - 000000000 ____D C:\WINDOWS\system32\Intel
2018-05-27 03:53 - 2018-05-31 06:32 - 000000000 ____D C:\Program Files\AMD
2018-05-27 03:52 - 2018-06-12 19:16 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2018-05-27 03:52 - 2018-06-01 15:25 - 000222888 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2018-05-27 03:52 - 2018-05-27 03:52 - 000000000 ____D C:\WINDOWS\ServiceProfiles
2018-05-27 03:18 - 2018-05-27 03:18 - 000000000 ____D C:\WINDOWS\InfusedApps
2018-05-27 03:17 - 2018-05-27 03:17 - 000008192 _____ C:\WINDOWS\system32\config\userdiff
2018-05-27 03:16 - 2018-05-27 04:06 - 000000000 ____D C:\WINDOWS\IAStorAfsService
2018-05-27 03:16 - 2018-05-27 03:16 - 000000000 ____D C:\WINDOWS\SysWOW64\sda
2018-05-27 03:16 - 2018-05-27 03:16 - 000000000 ____D C:\WINDOWS\Setup
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\SysWOW64\zu-ZA
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\SysWOW64\yo-NG
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\SysWOW64\xh-ZA
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\SysWOW64\wo-SN
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\SysWOW64\vi-VN
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\SysWOW64\uz-Latn-UZ
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\SysWOW64\ur-PK
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\SysWOW64\ug-CN
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\SysWOW64\tt-RU
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\SysWOW64\tn-ZA
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\SysWOW64\tk-TM
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\SysWOW64\ti-ET
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\SysWOW64\tg-Cyrl-TJ
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\SysWOW64\te-IN
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\SysWOW64\ta-IN
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\SysWOW64\sw-KE
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\SysWOW64\sr-Cyrl-RS
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\SysWOW64\sr-Cyrl-BA
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\SysWOW64\sq-AL
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\SysWOW64\si-LK
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\SysWOW64\sd-Arab-PK
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\SysWOW64\rw-RW
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\SysWOW64\quz-PE
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\SysWOW64\quc-Latn-GT
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\SysWOW64\prs-AF
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\SysWOW64\pa-IN
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\SysWOW64\pa-Arab-PK
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\SysWOW64\or-IN
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\SysWOW64\nso-ZA
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\SysWOW64\nn-NO
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\SysWOW64\ne-NP
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\SysWOW64\mt-MT
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\SysWOW64\mr-IN
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\SysWOW64\mn-MN
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\SysWOW64\ml-IN
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\SysWOW64\mk-MK
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\SysWOW64\mi-NZ
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\SysWOW64\lo-LA
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\SysWOW64\lb-LU
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\SysWOW64\ky-KG
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\SysWOW64\ku-Arab-IQ
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\SysWOW64\kok-IN
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\SysWOW64\kn-IN
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\SysWOW64\km-KH
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\SysWOW64\kk-KZ
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\SysWOW64\ka-GE
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\SysWOW64\is-IS
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\SysWOW64\ig-NG
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\SysWOW64\id-ID
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\SysWOW64\hy-AM
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\SysWOW64\ha-Latn-NG
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\SysWOW64\gu-IN
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\SysWOW64\gd-GB
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\SysWOW64\ga-IE
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\SysWOW64\fil-PH
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\SysWOW64\fa-IR
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\SysWOW64\cy-GB
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\SysWOW64\chr-CHER-US
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\SysWOW64\ca-ES-valencia
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\SysWOW64\bs-Latn-BA
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\SysWOW64\bn-IN
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\SysWOW64\bn-BD
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\SysWOW64\be-BY
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\SysWOW64\az-Latn-AZ
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\SysWOW64\as-IN
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\SysWOW64\am-ET
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\SysWOW64\af-ZA
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\system32\zu-ZA
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\system32\yo-NG
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\system32\xh-ZA
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\system32\wo-SN
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\system32\vi-VN
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\system32\uz-Latn-UZ
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\system32\ur-PK
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\system32\ug-CN
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\system32\tt-RU
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\system32\tn-ZA
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\system32\tk-TM
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\system32\ti-ET
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\system32\tg-Cyrl-TJ
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\system32\te-IN
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\system32\ta-IN
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\system32\sw-KE
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\system32\sr-Cyrl-RS
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\system32\sr-Cyrl-BA
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\system32\sq-AL
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\system32\si-LK
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\system32\sd-Arab-PK
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\system32\rw-RW
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\system32\quz-PE
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\system32\quc-Latn-GT
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\system32\prs-AF
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\system32\pa-IN
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\system32\pa-Arab-PK
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\system32\or-IN
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\system32\nso-ZA
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\system32\nn-NO
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\system32\ne-NP
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\system32\mt-MT
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\system32\mr-IN
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\system32\mn-MN
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\system32\ml-IN
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\system32\mk-MK
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\system32\mi-NZ
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\system32\lo-LA
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\system32\lb-LU
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\system32\ky-KG
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\system32\ku-Arab-IQ
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\system32\kok-IN
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\system32\kn-IN
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\system32\km-KH
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\system32\kk-KZ
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\system32\ka-GE
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\system32\is-IS
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\system32\ig-NG
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\system32\id-ID
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\system32\hy-AM
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\system32\ha-Latn-NG
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\system32\gu-IN
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\system32\gd-GB
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\system32\ga-IE
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\system32\fil-PH
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\system32\fa-IR
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\system32\cy-GB
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\system32\chr-CHER-US
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\system32\ca-ES-valencia
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\system32\bs-Latn-BA
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\system32\bn-IN
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\system32\bn-BD
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\system32\be-BY
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\system32\az-Latn-AZ
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\system32\as-IN
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\system32\am-ET
2018-05-27 03:14 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\system32\af-ZA
2018-05-27 03:14 - 2018-05-27 03:14 - 000000000 ____D C:\WINDOWS\SysWOW64\MailContactsCalendarSync
2018-05-27 03:14 - 2018-05-27 03:14 - 000000000 ____D C:\WINDOWS\SysWOW64\hi-IN
2018-05-27 03:14 - 2018-05-27 03:14 - 000000000 ____D C:\WINDOWS\SysWOW64\gl-ES
2018-05-27 03:14 - 2018-05-27 03:14 - 000000000 ____D C:\WINDOWS\SysWOW64\eu-ES
2018-05-27 03:14 - 2018-05-27 03:14 - 000000000 ____D C:\WINDOWS\SysWOW64\ca-ES
2018-05-27 03:14 - 2018-05-27 03:14 - 000000000 ____D C:\WINDOWS\system32\MailContactsCalendarSync
2018-05-27 03:14 - 2018-05-27 03:14 - 000000000 ____D C:\WINDOWS\system32\hi-IN
2018-05-27 03:14 - 2018-05-27 03:14 - 000000000 ____D C:\WINDOWS\system32\gl-ES
2018-05-27 03:14 - 2018-05-27 03:14 - 000000000 ____D C:\WINDOWS\system32\eu-ES
2018-05-27 03:14 - 2018-05-27 03:14 - 000000000 ____D C:\WINDOWS\system32\ca-ES
2018-05-27 03:14 - 2018-05-27 03:14 - 000000000 ____D C:\WINDOWS\OCR
2018-05-27 03:14 - 2018-05-27 03:14 - 000000000 ____D C:\Program Files\Reference Assemblies
2018-05-27 03:14 - 2018-05-27 03:14 - 000000000 ____D C:\Program Files\MSBuild
2018-05-27 03:14 - 2018-05-27 03:14 - 000000000 ____D C:\Program Files (x86)\Reference Assemblies
2018-05-27 03:14 - 2018-05-27 03:14 - 000000000 ____D C:\Program Files (x86)\MSBuild
2018-05-27 03:13 - 2018-05-27 03:13 - 000000000 ____D C:\WINDOWS\SysWOW64\winrm
2018-05-27 03:13 - 2018-05-27 03:13 - 000000000 ____D C:\WINDOWS\SysWOW64\WCN
2018-05-27 03:13 - 2018-05-27 03:13 - 000000000 ____D C:\WINDOWS\SysWOW64\sysprep
2018-05-27 03:13 - 2018-05-27 03:13 - 000000000 ____D C:\WINDOWS\SysWOW64\slmgr
2018-05-27 03:13 - 2018-05-27 03:13 - 000000000 ____D C:\WINDOWS\SysWOW64\Printing_Admin_Scripts
2018-05-27 03:13 - 2018-05-27 03:13 - 000000000 ____D C:\WINDOWS\SysWOW64\0409
2018-05-27 03:13 - 2018-05-27 03:13 - 000000000 ____D C:\WINDOWS\system32\winrm
2018-05-27 03:13 - 2018-05-27 03:13 - 000000000 ____D C:\WINDOWS\system32\WCN
2018-05-27 03:13 - 2018-05-27 03:13 - 000000000 ____D C:\WINDOWS\system32\slmgr
2018-05-27 03:13 - 2018-05-27 03:13 - 000000000 ____D C:\WINDOWS\system32\Printing_Admin_Scripts
2018-05-27 03:13 - 2018-05-27 03:13 - 000000000 ____D C:\WINDOWS\system32\0409
2018-05-27 03:13 - 2018-05-27 03:13 - 000000000 ____D C:\WINDOWS\DigitalLocker
2018-05-27 03:11 - 2018-06-06 07:24 - 000835056 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2018-05-27 03:11 - 2018-06-06 07:24 - 000179704 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2018-05-27 03:10 - 2018-06-12 19:03 - 000000000 ____D C:\WINDOWS\AppReadiness
2018-05-27 03:10 - 2018-06-12 18:20 - 000000000 ___RD C:\Program Files (x86)
2018-05-27 03:10 - 2018-06-12 17:58 - 000000000 ____D C:\WINDOWS\DeliveryOptimization
2018-05-27 03:10 - 2018-06-11 05:59 - 000000000 ____D C:\WINDOWS\system32\NDF
2018-05-27 03:10 - 2018-06-06 18:36 - 000000000 ____D C:\WINDOWS\system32\config\RegBack
2018-05-27 03:10 - 2018-06-06 17:56 - 000000000 ___HD C:\Program Files\WindowsApps
2018-05-27 03:10 - 2018-05-30 07:29 - 000000000 ____D C:\WINDOWS\rescache
2018-05-27 03:10 - 2018-05-29 19:03 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2018-05-27 03:10 - 2018-05-29 12:56 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2018-05-27 03:10 - 2018-05-29 06:55 - 000000000 ____D C:\WINDOWS\appcompat
2018-05-27 03:10 - 2018-05-27 21:29 - 000000000 ____D C:\WINDOWS\LiveKernelReports
2018-05-27 03:10 - 2018-05-27 04:12 - 000000000 ____D C:\WINDOWS\system32\WinBioDatabase
2018-05-27 03:10 - 2018-05-27 04:12 - 000000000 ____D C:\WINDOWS\system32\FxsTmp
2018-05-27 03:10 - 2018-05-27 04:06 - 000000000 ____D C:\WINDOWS\system32\spool
2018-05-27 03:10 - 2018-05-27 04:04 - 000000000 ____D C:\WINDOWS\system32\Sysprep
2018-05-27 03:10 - 2018-05-27 04:02 - 000000000 ____D C:\ProgramData\USOPrivate
2018-05-27 03:10 - 2018-05-27 04:00 - 000000000 ___RD C:\WINDOWS\PrintDialog
2018-05-27 03:10 - 2018-05-27 04:00 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2018-05-27 03:10 - 2018-05-27 03:19 - 000000000 ____D C:\WINDOWS\system32\oobe
2018-05-27 03:10 - 2018-05-27 03:18 - 000028672 _____ C:\WINDOWS\system32\config\BCD-Template
2018-05-27 03:10 - 2018-05-27 03:15 - 000000000 ___SD C:\WINDOWS\SysWOW64\F12
2018-05-27 03:10 - 2018-05-27 03:15 - 000000000 ___SD C:\WINDOWS\system32\F12
2018-05-27 03:10 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\TextInput
2018-05-27 03:10 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
2018-05-27 03:10 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2018-05-27 03:10 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\system32\WinMetadata
2018-05-27 03:10 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2018-05-27 03:10 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\system32\migwiz
2018-05-27 03:10 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\system32\Dism
2018-05-27 03:10 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\system32\appraiser
2018-05-27 03:10 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\ShellExperiences
2018-05-27 03:10 - 2018-05-27 03:15 - 000000000 ____D C:\WINDOWS\Provisioning
2018-05-27 03:10 - 2018-05-27 03:15 - 000000000 ____D C:\Program Files\Windows Defender
2018-05-27 03:10 - 2018-05-27 03:14 - 000000000 ____D C:\WINDOWS\PolicyDefinitions
2018-05-27 03:10 - 2018-05-27 03:13 - 000000000 ___SD C:\WINDOWS\SysWOW64\DiagSvcs
2018-05-27 03:10 - 2018-05-27 03:13 - 000000000 ___SD C:\WINDOWS\system32\dsc
2018-05-27 03:10 - 2018-05-27 03:13 - 000000000 ___SD C:\WINDOWS\system32\DiagSvcs
2018-05-27 03:10 - 2018-05-27 03:13 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
2018-05-27 03:10 - 2018-05-27 03:13 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
2018-05-27 03:10 - 2018-05-27 03:13 - 000000000 ____D C:\WINDOWS\SysWOW64\MUI
2018-05-27 03:10 - 2018-05-27 03:13 - 000000000 ____D C:\WINDOWS\SysWOW64\com
2018-05-27 03:10 - 2018-05-27 03:13 - 000000000 ____D C:\WINDOWS\system32\SystemResetPlatform
2018-05-27 03:10 - 2018-05-27 03:13 - 000000000 ____D C:\WINDOWS\system32\setup
2018-05-27 03:10 - 2018-05-27 03:13 - 000000000 ____D C:\WINDOWS\system32\MUI
2018-05-27 03:10 - 2018-05-27 03:13 - 000000000 ____D C:\WINDOWS\system32\com
2018-05-27 03:10 - 2018-05-27 03:13 - 000000000 ____D C:\WINDOWS\IME
2018-05-27 03:10 - 2018-05-27 03:13 - 000000000 ____D C:\WINDOWS\Help
2018-05-27 03:10 - 2018-05-27 03:13 - 000000000 ____D C:\Program Files\Windows Photo Viewer
2018-05-27 03:10 - 2018-05-27 03:13 - 000000000 ____D C:\Program Files\Common Files\system
2018-05-27 03:10 - 2018-05-27 03:13 - 000000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2018-05-27 03:10 - 2018-05-27 03:13 - 000000000 ____D C:\Program Files (x86)\Windows Defender
2018-05-27 03:10 - 2018-05-27 03:10 - 000000000 __SHD C:\Program Files\Windows Sidebar
2018-05-27 03:10 - 2018-05-27 03:10 - 000000000 __SHD C:\Program Files (x86)\Windows Sidebar
2018-05-27 03:10 - 2018-05-27 03:10 - 000000000 __RSD C:\WINDOWS\media
2018-05-27 03:10 - 2018-05-27 03:10 - 000000000 __RHD C:\Users\Public\Libraries
2018-05-27 03:10 - 2018-05-27 03:10 - 000000000 ___SD C:\WINDOWS\SysWOW64\Nui
2018-05-27 03:10 - 2018-05-27 03:10 - 000000000 ___SD C:\WINDOWS\SysWOW64\Configuration
2018-05-27 03:10 - 2018-05-27 03:10 - 000000000 ___SD C:\WINDOWS\system32\UNP
2018-05-27 03:10 - 2018-05-27 03:10 - 000000000 ___SD C:\WINDOWS\system32\Nui
2018-05-27 03:10 - 2018-05-27 03:10 - 000000000 ___SD C:\WINDOWS\system32\Configuration
2018-05-27 03:10 - 2018-05-27 03:10 - 000000000 ___SD C:\WINDOWS\Downloaded Program Files
2018-05-27 03:10 - 2018-05-27 03:10 - 000000000 ___RD C:\WINDOWS\Offline Web Pages
2018-05-27 03:10 - 2018-05-27 03:10 - 000000000 ____D C:\WINDOWS\Web
2018-05-27 03:10 - 2018-05-27 03:10 - 000000000 ____D C:\WINDOWS\Vss
2018-05-27 03:10 - 2018-05-27 03:10 - 000000000 ____D C:\WINDOWS\tracing
2018-05-27 03:10 - 2018-05-27 03:10 - 000000000 ____D C:\WINDOWS\TAPI
2018-05-27 03:10 - 2018-05-27 03:10 - 000000000 ____D C:\WINDOWS\SysWOW64\SMI
2018-05-27 03:10 - 2018-05-27 03:10 - 000000000 ____D C:\WINDOWS\SysWOW64\ras
2018-05-27 03:10 - 2018-05-27 03:10 - 000000000 ____D C:\WINDOWS\SysWOW64\NDF
2018-05-27 03:10 - 2018-05-27 03:10 - 000000000 ____D C:\WINDOWS\SysWOW64\Msdtc
2018-05-27 03:10 - 2018-05-27 03:10 - 000000000 ____D C:\WINDOWS\SysWOW64\migwiz
2018-05-27 03:10 - 2018-05-27 03:10 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed
2018-05-27 03:10 - 2018-05-27 03:10 - 000000000 ____D C:\WINDOWS\SysWOW64\Ipmi
2018-05-27 03:10 - 2018-05-27 03:10 - 000000000 ____D C:\WINDOWS\SysWOW64\InputMethod
2018-05-27 03:10 - 2018-05-27 03:10 - 000000000 ____D C:\WINDOWS\SysWOW64\inetsrv
2018-05-27 03:10 - 2018-05-27 03:10 - 000000000 ____D C:\WINDOWS\SysWOW64\IME
2018-05-27 03:10 - 2018-05-27 03:10 - 000000000 ____D C:\WINDOWS\SysWOW64\icsxml
2018-05-27 03:10 - 2018-05-27 03:10 - 000000000 ____D C:\WINDOWS\SysWOW64\GroupPolicyUsers
2018-05-27 03:10 - 2018-05-27 03:10 - 000000000 ____D C:\WINDOWS\SysWOW64\GroupPolicy
2018-05-27 03:10 - 2018-05-27 03:10 - 000000000 ____D C:\WINDOWS\SysWOW64\FxsTmp
2018-05-27 03:10 - 2018-05-27 03:10 - 000000000 ____D C:\WINDOWS\SysWOW64\downlevel
2018-05-27 03:10 - 2018-05-27 03:10 - 000000000 ____D C:\WINDOWS\SysWOW64\Bthprops
2018-05-27 03:10 - 2018-05-27 03:10 - 000000000 ____D C:\WINDOWS\SysWOW64\AppLocker
2018-05-27 03:10 - 2018-05-27 03:10 - 000000000 ____D C:\WINDOWS\SysWOW64\AdvancedInstallers
2018-05-27 03:10 - 2018-05-27 03:10 - 000000000 ____D C:\WINDOWS\SystemResources
2018-05-27 03:10 - 2018-05-27 03:10 - 000000000 ____D C:\WINDOWS\SystemApps
2018-05-27 03:10 - 2018-05-27 03:10 - 000000000 ____D C:\WINDOWS\system32\winevt
2018-05-27 03:10 - 2018-05-27 03:10 - 000000000 ____D C:\WINDOWS\system32\SecureBootUpdates
2018-05-27 03:10 - 2018-05-27 03:10 - 000000000 ____D C:\WINDOWS\system32\ras
2018-05-27 03:10 - 2018-05-27 03:10 - 000000000 ____D C:\WINDOWS\system32\ProximityToast
2018-05-27 03:10 - 2018-05-27 03:10 - 000000000 ____D C:\WINDOWS\system32\PointOfService
2018-05-27 03:10 - 2018-05-27 03:10 - 000000000 ____D C:\WINDOWS\system32\MsDtc
2018-05-27 03:10 - 2018-05-27 03:10 - 000000000 ____D C:\WINDOWS\system32\Macromed
2018-05-27 03:10 - 2018-05-27 03:10 - 000000000 ____D C:\WINDOWS\system32\Ipmi
2018-05-27 03:10 - 2018-05-27 03:10 - 000000000 ____D C:\WINDOWS\system32\InputMethod
2018-05-27 03:10 - 2018-05-27 03:10 - 000000000 ____D C:\WINDOWS\system32\inetsrv
2018-05-27 03:10 - 2018-05-27 03:10 - 000000000 ____D C:\WINDOWS\system32\IME
2018-05-27 03:10 - 2018-05-27 03:10 - 000000000 ____D C:\WINDOWS\system32\icsxml
2018-05-27 03:10 - 2018-05-27 03:10 - 000000000 ____D C:\WINDOWS\system32\ias
2018-05-27 03:10 - 2018-05-27 03:10 - 000000000 ____D C:\WINDOWS\system32\hydrogen
2018-05-27 03:10 - 2018-05-27 03:10 - 000000000 ____D C:\WINDOWS\system32\downlevel
2018-05-27 03:10 - 2018-05-27 03:10 - 000000000 ____D C:\WINDOWS\system32\DDFs
2018-05-27 03:10 - 2018-05-27 03:10 - 000000000 ____D C:\WINDOWS\system32\config\TxR
2018-05-27 03:10 - 2018-05-27 03:10 - 000000000 ____D C:\WINDOWS\system32\config\systemprofile
2018-05-27 03:10 - 2018-05-27 03:10 - 000000000 ____D C:\WINDOWS\system32\config\Journal
2018-05-27 03:10 - 2018-05-27 03:10 - 000000000 ____D C:\WINDOWS\system32\Bthprops
2018-05-27 03:10 - 2018-05-27 03:10 - 000000000 ____D C:\WINDOWS\system32\AppLocker
2018-05-27 03:10 - 2018-05-27 03:10 - 000000000 ____D C:\WINDOWS\system32\AdvancedInstallers
2018-05-27 03:10 - 2018-05-27 03:10 - 000000000 ____D C:\WINDOWS\System
2018-05-27 03:10 - 2018-05-27 03:10 - 000000000 ____D C:\WINDOWS\SKB
2018-05-27 03:10 - 2018-05-27 03:10 - 000000000 ____D C:\WINDOWS\security
2018-05-27 03:10 - 2018-05-27 03:10 - 000000000 ____D C:\WINDOWS\schemas
2018-05-27 03:10 - 2018-05-27 03:10 - 000000000 ____D C:\WINDOWS\SchCache
2018-05-27 03:10 - 2018-05-27 03:10 - 000000000 ____D C:\WINDOWS\Resources
2018-05-27 03:10 - 2018-05-27 03:10 - 000000000 ____D C:\WINDOWS\PLA
2018-05-27 03:10 - 2018-05-27 03:10 - 000000000 ____D C:\WINDOWS\Performance
2018-05-27 03:10 - 2018-05-27 03:10 - 000000000 ____D C:\WINDOWS\ModemLogs
2018-05-27 03:10 - 2018-05-27 03:10 - 000000000 ____D C:\WINDOWS\L2Schemas
2018-05-27 03:10 - 2018-05-27 03:10 - 000000000 ____D C:\WINDOWS\InputMethod
2018-05-27 03:10 - 2018-05-27 03:10 - 000000000 ____D C:\WINDOWS\Globalization
2018-05-27 03:10 - 2018-05-27 03:10 - 000000000 ____D C:\WINDOWS\GameBarPresenceWriter
2018-05-27 03:10 - 2018-05-27 03:10 - 000000000 ____D C:\WINDOWS\Cursors
2018-05-27 03:10 - 2018-05-27 03:10 - 000000000 ____D C:\WINDOWS\Branding
2018-05-27 03:10 - 2018-05-27 03:10 - 000000000 ____D C:\WINDOWS\bcastdvr
2018-05-27 03:10 - 2018-05-27 03:10 - 000000000 ____D C:\WINDOWS\addins
2018-05-27 03:10 - 2018-05-27 03:10 - 000000000 ____D C:\ProgramData\WindowsHolographicDevices
2018-05-27 03:10 - 2018-05-27 03:10 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2018-05-27 03:10 - 2018-05-27 03:10 - 000000000 ____D C:\Program Files\Windows Security
2018-05-27 03:10 - 2018-05-27 03:10 - 000000000 ____D C:\Program Files\Windows Portable Devices
2018-05-27 03:10 - 2018-05-27 03:10 - 000000000 ____D C:\Program Files\windows nt
2018-05-27 03:10 - 2018-05-27 03:10 - 000000000 ____D C:\Program Files\Windows Multimedia Platform
2018-05-27 03:10 - 2018-05-27 03:10 - 000000000 ____D C:\Program Files\Common Files\Services
2018-05-27 03:10 - 2018-05-27 03:10 - 000000000 ____D C:\Program Files (x86)\Windows Portable Devices
2018-05-27 03:10 - 2018-05-27 03:10 - 000000000 ____D C:\Program Files (x86)\windows nt
2018-05-27 03:10 - 2018-05-27 03:10 - 000000000 ____D C:\Program Files (x86)\Windows Multimedia Platform
2018-05-27 03:10 - 2018-05-27 03:08 - 000229376 _____ (Microsoft Corporation) C:\WINDOWS\system32\msclmd.dll
2018-05-27 03:10 - 2018-05-27 03:08 - 000215943 _____ C:\WINDOWS\SysWOW64\dssec.dat
2018-05-27 03:10 - 2018-05-27 03:08 - 000215943 _____ C:\WINDOWS\system32\dssec.dat
2018-05-27 03:10 - 2018-05-27 03:08 - 000208384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msclmd.dll
2018-05-27 03:10 - 2018-05-27 03:08 - 000017572 _____ C:\WINDOWS\system32\OEMDefaultAssociations.xml
2018-05-27 03:10 - 2018-05-27 03:08 - 000004096 _____ C:\WINDOWS\system32\config\VSMIDK
2018-05-27 03:10 - 2018-05-27 03:08 - 000003683 _____ C:\WINDOWS\system32\Drivers\etc\lmhosts.sam
2018-05-27 03:10 - 2018-05-27 03:08 - 000000858 _____ C:\WINDOWS\system32\DefaultQuestions.json
2018-05-27 03:10 - 2018-05-27 03:08 - 000000741 _____ C:\WINDOWS\SysWOW64\NOISE.DAT
2018-05-27 03:10 - 2018-05-27 03:08 - 000000741 _____ C:\WINDOWS\system32\NOISE.DAT
2018-05-27 03:10 - 2018-05-26 13:15 - 000000000 ____D C:\WINDOWS\Registration
2018-05-27 03:09 - 2018-06-12 19:24 - 000000000 ____D C:\WINDOWS\INF
2018-05-27 03:06 - 2018-06-09 06:23 - 000000000 ____D C:\WINDOWS\CbsTemp
2018-05-27 03:04 - 2018-06-13 08:13 - 000065536 _____ C:\WINDOWS\system32\config\SAM
2018-05-27 03:04 - 2018-06-12 18:49 - 082051072 _____ C:\WINDOWS\system32\config\SOFTWARE
2018-05-27 03:04 - 2018-06-12 18:49 - 028311552 _____ C:\WINDOWS\system32\config\SYSTEM
2018-05-27 03:04 - 2018-06-12 18:49 - 000786432 _____ C:\WINDOWS\system32\config\DEFAULT
2018-05-27 03:04 - 2018-06-12 18:49 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2018-05-27 03:04 - 2018-06-12 18:49 - 000065536 _____ C:\WINDOWS\system32\config\SECURITY
2018-05-27 03:04 - 2018-06-12 18:01 - 000000000 ____D C:\WINDOWS\Panther
2018-05-27 03:04 - 2018-06-12 16:28 - 000032768 _____ C:\WINDOWS\system32\config\ELAM
2018-05-27 03:04 - 2018-05-27 03:13 - 000000000 ____D C:\WINDOWS\servicing
2018-05-27 03:04 - 2018-05-27 03:10 - 000000000 ____D C:\WINDOWS\system32\SMI
2018-05-26 16:35 - 2018-05-26 16:35 - 000000000 ____D C:\Users\Tom Joram Vitor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2018-05-26 16:35 - 2018-05-26 16:35 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2018-05-26 16:35 - 2018-05-26 16:35 - 000000000 ____D C:\Program Files\WinRAR
2018-05-26 15:21 - 2018-05-26 15:22 - 000000000 ____D C:\Users\Tom Joram Vitor\AppData\Local\Steam
2018-05-26 15:01 - 2018-06-12 21:32 - 000000000 ____D C:\Program Files (x86)\Steam
2018-05-26 15:01 - 2018-05-26 15:01 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
2018-05-26 14:49 - 2018-05-26 14:49 - 000000000 ____D C:\Users\Tom Joram Vitor\AppData\Roaming\Waves Audio
2018-05-26 14:48 - 2018-05-04 17:37 - 000278448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Notifier.exe
2018-05-26 14:20 - 2018-05-26 14:20 - 000000000 ____D C:\Users\Tom Joram Vitor\AppData\Local\CEF
2018-05-26 14:19 - 2018-05-26 14:19 - 000001523 _____ C:\ProgramData\Microsoft\Windows\Start Menu\BlueStacks.lnk
2018-05-26 14:18 - 2018-05-26 14:19 - 000000000 ____D C:\Users\Tom Joram Vitor\AppData\Local\Bluestacks
2018-05-26 14:18 - 2018-05-26 14:19 - 000000000 ____D C:\ProgramData\BlueStacksSetup
2018-05-26 14:18 - 2018-05-26 14:19 - 000000000 ____D C:\ProgramData\BlueStacks
2018-05-26 14:18 - 2018-05-26 14:19 - 000000000 ____D C:\Program Files (x86)\BlueStacks
2018-05-26 14:17 - 2018-05-26 17:13 - 000000000 ____D C:\Users\Tom Joram Vitor\AppData\Local\PlaceholderTileLogoFolder
2018-05-26 14:12 - 2018-06-12 21:48 - 000000000 ____D C:\Users\Tom Joram Vitor\AppData\Roaming\vlc
2018-05-26 14:11 - 2018-05-26 14:11 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2018-05-26 14:11 - 2018-05-26 14:11 - 000000000 ____D C:\Program Files\VideoLAN
2018-05-26 13:48 - 2018-06-03 21:08 - 000000000 ____D C:\Users\Tom Joram Vitor\AppData\Roaming\uTorrent
2018-05-26 13:48 - 2018-05-26 13:48 - 000000888 _____ C:\Users\Tom Joram Vitor\AppData\Roaming\Microsoft\Windows\Start Menu\µTorrent.lnk
2018-05-26 13:42 - 2018-05-26 13:42 - 000000000 ____D C:\Users\Tom Joram Vitor\AppData\Roaming\Google
2018-05-26 13:40 - 2018-06-12 18:21 - 000002309 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2018-05-26 13:40 - 2018-05-26 15:41 - 000000000 ____D C:\Users\Tom Joram Vitor\AppData\Local\Google
2018-05-26 13:38 - 2018-05-26 13:39 - 000000000 ____D C:\Users\Tom Joram Vitor\AppData\Local\Comms
2018-05-26 13:38 - 2018-05-26 13:38 - 000003418 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2018-05-26 13:38 - 2018-05-26 13:38 - 000003294 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2018-05-26 13:37 - 2018-06-12 16:23 - 000000000 ____D C:\Program Files (x86)\Google
2018-05-26 13:32 - 2018-05-26 13:32 - 000000000 ____D C:\Program Files (x86)\Dell Update
2018-05-26 13:29 - 2018-05-26 13:29 - 000000000 ____D C:\Users\Tom Joram Vitor\AppData\Local\DBG
2018-05-26 13:26 - 2018-05-26 13:26 - 000000000 ____D C:\Users\Tom Joram Vitor\AppData\Roaming\Macromedia
2018-05-26 13:25 - 2018-05-26 13:25 - 000003396 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-1685633152-2609128806-664276259-1001
2018-05-26 13:24 - 2018-05-26 13:24 - 000000000 ____D C:\Users\Tom Joram Vitor\AppData\Roaming\Intel Corporation
2018-05-26 13:23 - 2018-05-27 10:55 - 000000000 ___RD C:\Users\Tom Joram Vitor\OneDrive
2018-05-26 13:23 - 2018-05-26 13:25 - 000002395 _____ C:\Users\Tom Joram Vitor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2018-05-26 13:23 - 2018-05-26 13:23 - 000000000 ____D C:\ProgramData\Microsoft OneDrive
2018-05-26 13:22 - 2018-05-26 13:22 - 000000000 ___HD C:\Users\Tom Joram Vitor\MicrosoftEdgeBackups
2018-05-26 13:22 - 2018-05-26 13:22 - 000000000 ____D C:\Users\Tom Joram Vitor\AppData\Local\MicrosoftEdge
2018-05-26 13:21 - 2018-06-12 18:50 - 000000000 __SHD C:\Users\Tom Joram Vitor\IntelGraphicsProfiles
2018-05-26 13:21 - 2018-06-01 13:23 - 000000000 ____D C:\Users\Tom Joram Vitor\AppData\Local\Packages
2018-05-26 13:21 - 2018-05-31 06:34 - 000000000 ____D C:\Users\Tom Joram Vitor\AppData\Local\AMD
2018-05-26 13:21 - 2018-05-26 13:23 - 000000000 ____D C:\Users\Tom Joram Vitor\AppData\Local\Dell
2018-05-26 13:21 - 2018-05-26 13:21 - 000000000 ___RD C:\Users\Tom Joram Vitor\3D Objects
2018-05-26 13:21 - 2018-05-26 13:21 - 000000000 ____D C:\Users\Tom Joram Vitor\AppData\Roaming\Adobe
2018-05-26 13:21 - 2018-05-26 13:21 - 000000000 ____D C:\Users\Tom Joram Vitor\AppData\Local\VirtualStore
2018-05-26 13:21 - 2018-05-26 13:21 - 000000000 ____D C:\Users\Tom Joram Vitor\AppData\Local\Publishers
2018-05-26 13:21 - 2018-05-26 13:21 - 000000000 ____D C:\Users\Tom Joram Vitor\AppData\Local\ConnectedDevicesPlatform
2018-05-26 13:20 - 2018-06-12 18:30 - 000000000 ____D C:\Users\Tom Joram Vitor
2018-05-26 13:20 - 2018-05-26 13:20 - 000000020 ___SH C:\Users\Tom Joram Vitor\ntuser.ini
2018-05-22 22:54 - 2018-05-22 22:54 - 001240952 _____ (AMD) C:\WINDOWS\system32\coinst_18.10.dll
2018-05-22 22:54 - 2018-05-22 22:54 - 001068408 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\atiadlxx.dll
2018-05-22 22:54 - 2018-05-22 22:54 - 000174960 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.dll
2018-05-22 22:54 - 2018-05-22 22:54 - 000150904 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.dll
2018-05-22 22:54 - 2018-05-22 22:54 - 000018648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\detoured.dll
2018-05-22 22:54 - 2018-05-22 22:54 - 000018648 _____ (Microsoft Corporation) C:\WINDOWS\system32\detoured.dll
2018-05-22 19:13 - 2018-05-22 19:13 - 000121392 _____ C:\WINDOWS\system32\kapp_ci.sbin
2018-05-22 19:13 - 2018-05-22 19:13 - 000117072 _____ C:\WINDOWS\system32\kapp_si.sbin
2018-05-22 19:13 - 2018-05-22 19:13 - 000034501 _____ C:\WINDOWS\system32\AMDKernelEvents.man
2018-05-16 15:25 - 2018-05-16 15:25 - 000155688 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\amdihk64.dll
2018-05-16 15:25 - 2018-05-16 15:25 - 000126848 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\amdihk32.dll
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2018-06-12 18:30 - 2018-03-06 05:48 - 000000000 ____D C:\Program Files (x86)\McAfee
2018-06-12 17:06 - 2018-03-06 05:48 - 000000000 ____D C:\Program Files\Common Files\mcafee
2018-06-12 15:49 - 2018-03-06 05:31 - 000000000 ____D C:\Program Files\Dell
2018-06-07 06:30 - 2018-03-06 05:34 - 000000000 ____D C:\ProgramData\Intel
2018-06-03 17:20 - 2018-03-06 05:31 - 000000000 ____D C:\ProgramData\PCDr
2018-06-01 19:44 - 2018-03-06 06:02 - 000000000 ____D C:\ProgramData\RivetNetworks
2018-06-01 19:24 - 2018-03-06 05:35 - 000000000 ____D C:\Program Files (x86)\Qualcomm
2018-06-01 13:23 - 2018-03-06 05:31 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell
2018-05-29 12:36 - 2018-03-06 05:48 - 000000000 ____D C:\ProgramData\McAfee
2018-05-27 11:04 - 2018-03-06 05:49 - 000000000 ____D C:\Program Files\mcafee
2018-05-27 04:11 - 2017-09-29 21:46 - 000000000 ____D C:\WINDOWS\system32\Tasks_Migrated
2018-05-27 04:06 - 2018-03-06 06:08 - 000000000 ____D C:\WINDOWS\{F32BF528-E298-4662-A0AC-7AAFF5D25CB7}
2018-05-27 04:06 - 2018-03-06 05:49 - 000000000 ____D C:\Program Files\mcafee.com
2018-05-27 04:06 - 2018-03-06 05:48 - 000000000 ____D C:\ProgramData\Dell
2018-05-27 04:06 - 2018-03-06 05:42 - 000000000 ____D C:\Program Files (x86)\Dell Digital Delivery
2018-05-27 04:06 - 2018-03-06 05:38 - 000000000 ____D C:\Program Files (x86)\ATI Technologies
2018-05-27 04:06 - 2018-03-06 05:33 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel
2018-05-27 04:06 - 2018-03-06 05:33 - 000000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2018-05-27 04:06 - 2018-03-06 05:33 - 000000000 ____D C:\Program Files (x86)\Intel
2018-05-27 04:06 - 2018-03-06 05:31 - 000000000 ____D C:\ProgramData\SupportAssist
2018-05-27 04:05 - 2018-03-06 05:48 - 000000000 ____D C:\Program Files\Common Files\av
2018-05-27 04:05 - 2018-03-06 05:20 - 000000000 ____D C:\backup
2018-05-27 04:05 - 2017-10-07 02:11 - 000000000 ____D C:\dell
2018-05-26 13:21 - 2018-03-06 05:51 - 000000000 __RHD C:\Users\Public\AccountPictures
2018-05-22 22:54 - 2018-03-06 04:41 - 003136888 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\amfrt64.dll
2018-05-22 22:54 - 2018-03-06 04:41 - 002735480 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\amfrt32.dll
2018-05-22 22:54 - 2018-03-06 04:41 - 001477496 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\atiadlxx.dll
2018-05-22 22:54 - 2018-03-06 04:41 - 001068408 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\atiadlxy.dll
2018-05-22 22:54 - 2018-03-06 04:41 - 000713080 _____ (AMD) C:\WINDOWS\system32\atieclxx.exe
2018-05-22 22:54 - 2018-03-06 04:41 - 000565624 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\Rapidfire64.dll
2018-05-22 22:54 - 2018-03-06 04:41 - 000478584 _____ C:\WINDOWS\system32\dgtrayicon.exe
2018-05-22 22:54 - 2018-03-06 04:41 - 000476536 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\Rapidfire.dll
2018-05-22 22:54 - 2018-03-06 04:41 - 000467320 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\atidemgy.dll
2018-05-22 22:54 - 2018-03-06 04:41 - 000457080 _____ C:\WINDOWS\system32\GameManager64.dll
2018-05-22 22:54 - 2018-03-06 04:41 - 000414576 _____ C:\WINDOWS\system32\atieah64.exe
2018-05-22 22:54 - 2018-03-06 04:41 - 000365432 _____ C:\WINDOWS\SysWOW64\GameManager32.dll
2018-05-22 22:54 - 2018-03-06 04:41 - 000351600 _____ C:\WINDOWS\system32\clinfo.exe
2018-05-22 22:54 - 2018-03-06 04:41 - 000334704 _____ C:\WINDOWS\SysWOW64\atieah32.exe
2018-05-22 22:54 - 2018-03-06 04:41 - 000234872 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atig6txx.dll
2018-05-22 22:54 - 2018-03-06 04:41 - 000205168 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atigktxx.dll
2018-05-22 22:54 - 2018-03-06 04:41 - 000180088 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\mantle64.dll
2018-05-22 22:54 - 2018-03-06 04:41 - 000159608 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\mantleaxl64.dll
2018-05-22 22:54 - 2018-03-06 04:41 - 000157048 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atisamu64.dll
2018-05-22 22:54 - 2018-03-06 04:41 - 000154104 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\aticfx64.dll
2018-05-22 22:54 - 2018-03-06 04:41 - 000150392 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\mantle32.dll
2018-05-22 22:54 - 2018-03-06 04:41 - 000145352 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\aticfx32.dll
2018-05-22 22:54 - 2018-03-06 04:41 - 000135032 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\mantleaxl32.dll
2018-05-22 22:54 - 2018-03-06 04:41 - 000132984 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atisamu32.dll
2018-05-22 22:54 - 2018-03-06 04:41 - 000124280 _____ (AMD) C:\WINDOWS\system32\atimuixx.dll
2018-05-22 22:54 - 2018-03-06 04:41 - 000119672 _____ C:\WINDOWS\system32\atidxx64.dll
2018-05-22 22:54 - 2018-03-06 04:41 - 000113520 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\amdxc64.dll
2018-05-22 22:54 - 2018-03-06 04:41 - 000102776 _____ C:\WINDOWS\SysWOW64\atidxx32.dll
2018-05-22 22:54 - 2018-03-06 04:41 - 000068984 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\ati2erec.dll
2018-05-22 22:54 - 2018-03-06 04:41 - 000045432 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\RapidFireServer64.dll
2018-05-22 22:54 - 2018-03-06 04:41 - 000042360 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\RapidFireServer.dll
2018-05-22 22:53 - 2018-03-06 04:41 - 000098680 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\amdxc32.dll
2018-05-22 22:53 - 2018-03-06 04:40 - 000874872 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\amdlvr64.dll
2018-05-22 22:53 - 2018-03-06 04:40 - 000702840 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\amdlvr32.dll
2018-05-22 22:53 - 2018-03-06 04:40 - 000552312 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\amdmcl64.dll
2018-05-22 22:53 - 2018-03-06 04:40 - 000445816 _____ C:\WINDOWS\system32\amdgfxinfo64.dll
2018-05-22 22:53 - 2018-03-06 04:40 - 000382328 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\amdmcl32.dll
2018-05-22 22:53 - 2018-03-06 04:40 - 000361336 _____ C:\WINDOWS\SysWOW64\amdgfxinfo32.dll
2018-05-22 22:52 - 2018-03-06 04:41 - 000121360 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\atimpc64.dll
2018-05-22 22:52 - 2018-03-06 04:41 - 000101992 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\atimpc32.dll
2018-05-22 22:52 - 2018-03-06 04:40 - 000548792 _____ C:\WINDOWS\system32\amdmiracast.dll
2018-05-22 22:52 - 2018-03-06 04:40 - 000185744 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\system32\amdhcp64.dll
2018-05-22 22:52 - 2018-03-06 04:40 - 000163880 _____ (Advanced Micro Devices, Inc.) C:\WINDOWS\SysWOW64\amdhcp32.dll
2018-05-22 22:52 - 2018-03-06 04:40 - 000130632 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\amdave64.dll
2018-05-22 22:52 - 2018-03-06 04:40 - 000121360 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\system32\amdpcom64.dll
2018-05-22 22:52 - 2018-03-06 04:40 - 000115544 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\amdave32.dll
2018-05-22 22:52 - 2018-03-06 04:40 - 000101992 _____ (Advanced Micro Devices, Inc. ) C:\WINDOWS\SysWOW64\amdpcom32.dll
2018-05-22 19:13 - 2018-03-06 04:41 - 003471376 _____ C:\WINDOWS\SysWOW64\atiumdva.cap
2018-05-22 19:13 - 2018-03-06 04:41 - 003437632 _____ C:\WINDOWS\system32\atiumd6a.cap
2018-05-22 19:13 - 2018-03-06 04:41 - 000890728 _____ C:\WINDOWS\SysWOW64\atiapfxx.blb
2018-05-22 19:13 - 2018-03-06 04:41 - 000890728 _____ C:\WINDOWS\system32\atiapfxx.blb
 
==================== Files in the root of some directories =======
 
2018-06-12 15:54 - 2018-06-12 15:54 - 000140800 _____ () C:\Users\Tom Joram Vitor\AppData\Local\installer.dat
 
Some files in TEMP:
====================
2018-06-11 06:42 - 2018-06-11 06:44 - 041465128 _____ () C:\Users\Tom Joram Vitor\AppData\Local\Temp\vlc-3.0.3-win64.exe
 
==================== Bamital & volsnap ======================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
 
LastRegBack: 2018-06-06 18:36
 
==================== End of FRST.txt ============================

Attached Files



#8 nasdaq

nasdaq

  • Malware Response Team
  • 40,188 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:11:08 AM

Posted 12 June 2018 - 12:54 PM

Hi,

Press the Windows key + r on your keyboard at the same time. This will open the RUN BOX.
Type Notepad and and click the OK key.

Please copy the entire contents of the code box below to a new file.
 
Start

CreateRestorePoint:
EmptyTemp:
CloseProcesses:


S2 gupdate; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /svc [X]
S3 gupdatem; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /medsvc [X]
R2 OGMwOTcxMjg3M; rundll32.exe C:\WINDOWS\rucjlxzkqboopktx.lucj sqbq [X]

End
Save the file as fixlist.txt in the same folder where the Farbar tool is running from.
The location is listed in the 3rd line of the Farbar log you have submitted.

Run FRST and click Fix only once and wait.

The tool will create a log (Fixlog.txt) please post it to your reply.
===

Your copy of Chrome has been compromised

Unless you did this yourself, malware has changed your Chrome version into the Development Build. Among other things this allows malware to install any extension it wants.

:step1: Remove Chrome from your Computer and reinstall a fresh copy later.

:step2: Before you remove Chrome Export your Bookmarks
Chrome will export your bookmarks as a HTML file, which you can then import into another browser.

How To: http://ccm.net/faq/31791-how-to-backup-your-google-chrome-bookmarks

:step3: If you sync you account you must remove it before you save your bookmarks etc...
Delete Your Google Chrome Browser Sync Data if you sync with other defices. <- Important ...
https://forums.malwarebytes.com/topic/214325-chrome-secure-preferences-detection-always-comes-back/

:step4: Clear your Chrome cache and cookies
https://support.google.com/chromebook/answer/183083?hl=en

:step5: Remove Chrome using the the instructions on this page.
https://support.google.com/chrome/answer/95319?hl=en

:step6: Re-install Chrome and the Bookmarks.
====

Please let me know what problem persists with this computer.

#9 tomjoram

tomjoram
  • Topic Starter

  • Members
  • 226 posts
  • OFFLINE
  •  
  • Local time:11:08 PM

Posted 13 June 2018 - 04:38 AM

im having a problem too when i woke up the mouse is not working anymore too, i tried changing batteries and plug into another computer still not functioning



#10 tomjoram

tomjoram
  • Topic Starter

  • Members
  • 226 posts
  • OFFLINE
  •  
  • Local time:11:08 PM

Posted 13 June 2018 - 04:47 AM

Fix result of Farbar Recovery Scan Tool (x64) Version: 06.06.2018 01
Ran by Tom Joram Vitor (13-06-2018 17:41:53) Run:1
Running from C:\Users\Tom Joram Vitor\Downloads
Loaded Profiles: Tom Joram Vitor (Available Profiles: Tom Joram Vitor)
Boot Mode: Normal
==============================================
 
fixlist content:
*****************
Start
 
CreateRestorePoint:
EmptyTemp:
CloseProcesses:
 
 
S2 gupdate; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /svc [X]
S3 gupdatem; "C:\Program Files (x86)\Google\Update\GoogleUpdate.exe" /medsvc [X]
R2 OGMwOTcxMjg3M; rundll32.exe C:\WINDOWS\rucjlxzkqboopktx.lucj sqbq [X]
 
End
*****************
 
Restore point was successfully created.
Processes closed successfully.
"HKLM\System\CurrentControlSet\Services\gupdate" => removed successfully
gupdate => service removed successfully
"HKLM\System\CurrentControlSet\Services\gupdatem" => removed successfully
gupdatem => service removed successfully
"HKLM\System\CurrentControlSet\Services\OGMwOTcxMjg3M" => removed successfully
OGMwOTcxMjg3M => service removed successfully
 
=========== EmptyTemp: ==========
 
BITS transfer queue => 9461760 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 48908766 B
Java, Flash, Steam htmlcache => 189775809 B
Windows/system/drivers => 20807990 B
Edge => 9741 B
Chrome => 579775036 B
Firefox => 0 B
Opera => 0 B
 
Temp, IE cache, history, cookies, recent:
Default => 6656 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 15777408 B
systemprofile32 => 0 B
LocalService => 14762 B
NetworkService => 0 B
Tom Joram Vitor => 68071714 B
 
RecycleBin => 490322582 B
EmptyTemp: => 1.3 GB temporary data Removed.
 
================================
 
 
The system needed a reboot.
 
==== End of Fixlog 17:43:41 ====


#11 tomjoram

tomjoram
  • Topic Starter

  • Members
  • 226 posts
  • OFFLINE
  •  
  • Local time:11:08 PM

Posted 13 June 2018 - 04:48 AM

do i still need to reinstall chrome? 

have you found any other unusual registry from kmspico?



#12 nasdaq

nasdaq

  • Malware Response Team
  • 40,188 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:11:08 AM

Posted 13 June 2018 - 06:46 AM

Hi,

If you still have the same problem you have reported in your first post yes re-install Chrome.

Change your mouse it may be damaged.

#13 tomjoram

tomjoram
  • Topic Starter

  • Members
  • 226 posts
  • OFFLINE
  •  
  • Local time:11:08 PM

Posted 13 June 2018 - 06:56 AM

ok  sir thank you very much for your assistance .  :clapping:


Edited by tomjoram, 13 June 2018 - 06:57 AM.





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users