Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

SystemaRew problem


  • This topic is locked This topic is locked
5 replies to this topic

#1 armone

armone

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:04:40 PM

Posted 23 June 2018 - 08:18 PM

Hello.

I downloaded some app from internet tonight and after that my security defender stopped. I fix that but I still have a problems on my PC. In my C; I have folder SystemaRew and I can't delete it. When I run my chrome there is some websites and sometimes my pc run chrome alone. I don't know what to do anymore and biggest problem for me is that I don't know how much my pc is under virus.

Please sorry for my bad english, and help asap if you can.



BC AdBot (Login to Remove)

 


#2 armone

armone
  • Topic Starter

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:04:40 PM

Posted 23 June 2018 - 09:27 PM

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 20.06.2018
Ran by PC (administrator) on ARMIN (24-06-2018 04:18:04)
Running from C:\Users\PC\Desktop
Loaded Profiles: PC (Available Profiles: PC)
Platform: Windows 10 Enterprise Version 1803 17134.112 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_daa5fd44d52a5762\igfxCUIService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome Remote Desktop\68.0.3440.11\remoting_host.exe
(Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_daa5fd44d52a5762\IntelCpHDCPSvc.exe
(Nitro PDF Software) C:\Program Files\Nitro\Pro 10\NitroPDFDriverService10x64.exe
() C:\Program Files\Nitro\Pro 10\Nitro_UpdateService.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(DEVGURU Co., LTD.) C:\Program Files\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe
(Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_daa5fd44d52a5762\IntelCpHeciSvc.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome Remote Desktop\68.0.3440.11\remoting_host.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\igdlh64.inf_amd64_daa5fd44d52a5762\igfxEM.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.LockApp_cw5n1h2txyewy\LockApp.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.17\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.17\GoogleCrashHandler64.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
() C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.18041.14611.0_x64__8wekyb3d8bbwe\Video.UI.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
() C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.209.0_x64__kzf8qxf38zg5c\SkypeHost.exe
(Telegram Messenger LLP) D:\Users\PC\AppData\Roaming\Telegram Desktop\Telegram.exe
(Skillbrains) C:\Program Files (x86)\Skillbrains\lightshot\5.4.0.35\Lightshot.exe
() C:\Program Files (x86)\Genesis\GX69 Mouse\Monitor.exe
(Microsoft Corporation) C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Microsoft Corporation) C:\Windows\System32\Taskmgr.exe
(PortableApps.com) D:\Users\PC\Desktop\FirefoxPortable\FirefoxPortable.exe
(Mozilla Corporation) D:\Users\PC\Desktop\FirefoxPortable\App\Firefox64\firefox.exe
(Mozilla Corporation) D:\Users\PC\Desktop\FirefoxPortable\App\Firefox64\firefox.exe
(Mozilla Corporation) D:\Users\PC\Desktop\FirefoxPortable\App\Firefox64\firefox.exe
(Mozilla Corporation) D:\Users\PC\Desktop\FirefoxPortable\App\Firefox64\firefox.exe
(Mozilla Corporation) D:\Users\PC\Desktop\FirefoxPortable\App\Firefox64\firefox.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\SecHealthUI.exe
(Microsoft Corporation) C:\Windows\regedit.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
() C:\Windows\Temp\g2268.tmp.exe
(Mozilla Corporation) D:\Users\PC\Desktop\FirefoxPortable\App\Firefox64\firefox.exe
(Mozilla Corporation) D:\Users\PC\Desktop\FirefoxPortable\App\Firefox64\firefox.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [638872 2018-04-12] (Microsoft Corporation)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [9235936 2017-08-10] (Realtek Semiconductor)
HKLM\...\Run: [rundll32] => C:\WINDOWS\system32\rundll32.exe "C:\Program Files\ThePake\ThePake.dll",qCclkRLrhW
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [648728 2017-08-03] (Oracle Corporation)
HKLM-x32\...\Run: [Lightshot] => C:\Program Files (x86)\Skillbrains\lightshot\Lightshot.exe [225944 2017-04-11] ()
HKLM-x32\...\Run: [Genesis mouse] => C:\Program Files (x86)\Genesis\GX69 Mouse\Monitor.exe [495616 2015-10-08] ()
HKLM Group Policy restriction on software: %systemroot%\system32\mrt.exe <==== ATTENTION
HKLM\ DisallowedCertificates: 03D22C9C66915D58C88912B64C1F984B8344EF09 (Comodo Security Solutions) <==== ATTENTION
HKLM\ DisallowedCertificates: 0F684EC1163281085C6AF20528878103ACEFCAAB (F-Secure Corporation) <==== ATTENTION
HKLM\ DisallowedCertificates: 1667908C9E22EFBD0590E088715CC74BE4C60884 (FRISK Software International/F-Prot) <==== ATTENTION
HKLM\ DisallowedCertificates: 18DEA4EFA93B06AE997D234411F3FD72A677EECE (Bitdefender SRL) <==== ATTENTION
HKLM\ DisallowedCertificates: 2026D13756EB0DB753DF26CB3B7EEBE3E70BB2CF (G DATA Software AG) <==== ATTENTION
HKLM\ DisallowedCertificates: 249BDA38A611CD746A132FA2AF995A2D3C941264 (Malwarebytes Corporation) <==== ATTENTION
HKLM\ DisallowedCertificates: 31AC96A6C17C425222C46D55C3CCA6BA12E54DAF (Symantec Corporation) <==== ATTENTION
HKLM\ DisallowedCertificates: 331E2046A1CCA7BFEF766724394BE6112B4CA3F7 (Trend Micro) <==== ATTENTION
HKLM\ DisallowedCertificates: 3353EA609334A9F23A701B9159E30CB6C22D4C59 (Webroot Inc.) <==== ATTENTION
HKLM\ DisallowedCertificates: 373C33726722D3A5D1EDD1F1585D5D25B39BEA1A (SUPERAntiSpyware.com) <==== ATTENTION
HKLM\ DisallowedCertificates: 3850EDD77CC74EC9F4829AE406BBF9C21E0DA87F (Kaspersky Lab) <==== ATTENTION
HKLM\ DisallowedCertificates: 3D496FA682E65FC122351EC29B55AB94F3BB03FC (AVG Technologies CZ) <==== ATTENTION
HKLM\ DisallowedCertificates: 4243A03DB4C3C15149CEA8B38EEA1DA4F26BD159 (PC Tools) <==== ATTENTION
HKLM\ DisallowedCertificates: 42727E052C0C2E1B35AB53E1005FD9EDC9DE8F01 (K7 Computing Pvt Ltd) <==== ATTENTION
HKLM\ DisallowedCertificates: 4420C99742DF11DD0795BC15B7B0ABF090DC84DF (Doctor Web Ltd.) <==== ATTENTION
HKLM\ DisallowedCertificates: 4C0AF5719009B7C9D85C5EAEDFA3B7F090FE5FFF (Emsisoft Ltd) <==== ATTENTION
HKLM\ DisallowedCertificates: 5240AB5B05D11B37900AC7712A3C6AE42F377C8C (Check Point Software Technologies Ltd.) <==== ATTENTION
HKLM\ DisallowedCertificates: 5DD3D41810F28B2A13E9A004E6412061E28FA48D (Emsisoft Ltd) <==== ATTENTION
HKLM\ DisallowedCertificates: 7457A3793086DBB58B3858D6476889E3311E550E (K7 Computing Pvt Ltd) <==== ATTENTION
HKLM\ DisallowedCertificates: 76A9295EF4343E12DFC5FE05DC57227C1AB00D29 (BullGuard Ltd) <==== ATTENTION
HKLM\ DisallowedCertificates: 775B373B33B9D15B58BC02B184704332B97C3CAF (McAfee) <==== ATTENTION
HKLM\ DisallowedCertificates: 872CD334B7E7B3C3D1C6114CD6B221026D505EAB (Comodo Security Solutions) <==== ATTENTION
HKLM\ DisallowedCertificates: 88AD5DFE24126872B33175D1778687B642323ACF (McAfee) <==== ATTENTION
HKLM\ DisallowedCertificates: 9132E8B079D080E01D52631690BE18EBC2347C1E (Adaware Software) <==== ATTENTION
HKLM\ DisallowedCertificates: 982D98951CF3C0CA2A02814D474A976CBFF6BDB1 (Safer Networking Ltd.) <==== ATTENTION
HKLM\ DisallowedCertificates: 9A08641F7C5F2CCA0888388BE3E5DBDDAAA3B361 (Webroot Inc.) <==== ATTENTION
HKLM\ DisallowedCertificates: 9C43F665E690AB4D486D4717B456C5554D4BCEB5 (ThreatTrack Security) <==== ATTENTION
HKLM\ DisallowedCertificates: 9E3F95577B37C74CA2F70C1E1859E798B7FC6B13 (CURIOLAB S.M.B.A.) <==== ATTENTION
HKLM\ DisallowedCertificates: A1F8DCB086E461E2ABB4B46ADCFA0B48C58B6E99 (Avira Operations GmbH & Co. KG) <==== ATTENTION
HKLM\ DisallowedCertificates: A5341949ABE1407DD7BF7DFE75460D9608FBC309 (BullGuard Ltd) <==== ATTENTION
HKLM\ DisallowedCertificates: A59CC32724DD07A6FC33F7806945481A2D13CA2F (ESET) <==== ATTENTION
HKLM\ DisallowedCertificates: AB7E760DA2485EA9EF5A6EEE7647748D4BA6B947 (AVG Technologies CZ) <==== ATTENTION
HKLM\ DisallowedCertificates: AD4C5429E10F4FF6C01840C20ABA344D7401209F (Avast Antivirus/Software) <==== ATTENTION
HKLM\ DisallowedCertificates: AD96BB64BA36379D2E354660780C2067B81DA2E0 (Symantec Corporation) <==== ATTENTION
HKLM\ DisallowedCertificates: B8EBF0E696AF77F51C96DB4D044586E2F4F8FD84 (Malwarebytes Corporation) <==== ATTENTION
HKLM\ DisallowedCertificates: CDC37C22FE9272D8F2610206AD397A45040326B8 (Trend Micro) <==== ATTENTION
HKLM\ DisallowedCertificates: D3F78D747E7C5D6D3AE8ABFDDA7522BFB4CBD598 (Kaspersky Lab) <==== ATTENTION
HKLM\ DisallowedCertificates: DB303C9B61282DE525DC754A535CA2D6A9BD3D87 (ThreatTrack Security) <==== ATTENTION
HKLM\ DisallowedCertificates: DB77E5CFEC34459146748B667C97B185619251BA (Avast Antivirus/Software) <==== ATTENTION
HKLM\ DisallowedCertificates: E22240E837B52E691C71DF248F12D27F96441C00 (Total Defense, Inc.) <==== ATTENTION
HKLM\ DisallowedCertificates: E513EAB8610CFFD7C87E00BCA15C23AAB407FCEF (AVG Technologies CZ) <==== ATTENTION
HKLM\ DisallowedCertificates: ED841A61C0F76025598421BC1B00E24189E68D54 (Bitdefender SRL) <==== ATTENTION
HKLM\ DisallowedCertificates: F83099622B4A9F72CB5081F742164AD1B8D048C9 (ESET) <==== ATTENTION
HKLM\ DisallowedCertificates: FBB42F089AF2D570F2BF6F493D107A3255A9BB1A (Panda Security S.L) <==== ATTENTION
HKLM\ DisallowedCertificates: FFFA650F2CB2ABC0D80527B524DD3F9FC172C138 (Doctor Web Ltd.) <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-19\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518144 2018-04-12] (Microsoft Corporation)
HKU\S-1-5-20\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [518144 2018-04-12] (Microsoft Corporation)
HKU\S-1-5-21-1124267341-3267589977-3522073591-1001\...\Run: [Viber] => C:\Users\PC\AppData\Local\Viber\Viber.exe [40238664 2018-06-14] (Viber Media S.à r.l.)
HKU\S-1-5-21-1124267341-3267589977-3522073591-1001\...\Run: [Steam] => D:\Program Files (x86)\Steam\steam.exe [3201312 2018-06-09] (Valve Corporation)
HKU\S-1-5-21-1124267341-3267589977-3522073591-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [27831240 2018-03-13] (Skype Technologies S.A.)
HKU\S-1-5-21-1124267341-3267589977-3522073591-1001\...\Run: [G2H#IX_beG.exe] => C:\Program Files\Windows Defender\6VBV3CEGVXD5ML22D7VOR\G2H#IX_beG.exe
Startup: C:\Users\PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Telegram.lnk [2018-01-20]
ShortcutTarget: Telegram.lnk -> D:\Users\PC\AppData\Roaming\Telegram Desktop\Telegram.exe (Telegram Messenger LLP)
GroupPolicy: Restriction ? <==== ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 77.77.192.20 94.140.66.194
Tcpip\..\Interfaces\{9f117ec6-d59b-4003-ba3d-681fc502c08a}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{bc043349-60b0-4416-b2fa-1aac07c43390}: [DhcpNameServer] 77.77.192.20 94.140.66.194

Internet Explorer:
==================
HKU\S-1-5-21-1124267341-3267589977-3522073591-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxps://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBEQo0lOCwIxrzs2Rcb6iYl3j4dOu7u7ZVVj6CTrV6VEEwTax0qJLJ-obz-CfNubpE3-8jvxmFnunkdbGiGlYLcxbmJlxOkzbgTSApiAt3yUNzDL5ckeEkx59k838gpC4oyhbU7Ndg3mA0DXs9wjkWQU5e4Gc83lIUmiziTano8KyLK3KVd86kHoXHSU20,&q={searchTerms}
HKU\S-1-5-21-1124267341-3267589977-3522073591-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://%66%65%65%64.%68%65%6C%70%65%72%62%61%72.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBEQo0lOCwIxrzs2Rcb6iYl3j4dOu7u7ZVVj6CTrV6VEEwTax0qJLJ-obz-CfNubpE3-8jvxmFnunkdbGiGlYLcxbmJlxOkzbgTRIz9n6OMOm5d6QyiOsOzogdpGBiHiBvU60LaP4ay8s1xcWht871vzS4cVWe_eQ27ZW-Wk2EAIcDrBTf7v7iprA06nDA,
SearchScopes: HKLM-x32 -> DefaultScope {ielnksrch} URL =
SearchScopes: HKLM-x32 -> ielnksrch URL = hxxps://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBEQo0lOCwIxrzs2Rcb6iYl3j4dOu7u7ZVVj6CTrV6VEEwTax0qJLJ-obz-CfNubpE3-8jvxmFnunkdbGiGlYLcxbmJlxOkzbgTSApiAt3yUNzDL5ckeEkx59k838gpC4oyhbU7Ndg3mA0DXs9wjkWQU5e4Gc83lIUmiziTano8KyLK3KVd86kHoXHSU20,&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1124267341-3267589977-3522073591-1001 -> DefaultScope {ielnksrch} URL = hxxps://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBEQo0lOCwIxrzs2Rcb6iYl3j4dOu7u7ZVVj6CTrV6VEEwTax0qJLJ-obz-CfNubpE3-8jvxmFnunkdbGiGlYLcxbmJlxOkzbgTSApiAt3yUNzDL5ckeEkx59k838gpC4oyhbU7Ndg3mA0DXs9wjkWQU5e4Gc83lIUmiziTano8KyLK3KVd86kHoXHSU20,&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1124267341-3267589977-3522073591-1001 -> {C0C3A6C6-03BC-4195-8FCB-AEA091301353} URL = hxxps://search.yahoo.com/yhs/search?hspart=lvs&hsimp=yhs-awc&type=lvs__webcompa__1_0__ya__ch_WCYID10454__180117__yaie&p={searchTerms}
SearchScopes: HKU\S-1-5-21-1124267341-3267589977-3522073591-1001 -> {ielnksrch} URL = hxxps://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBEQo0lOCwIxrzs2Rcb6iYl3j4dOu7u7ZVVj6CTrV6VEEwTax0qJLJ-obz-CfNubpE3-8jvxmFnunkdbGiGlYLcxbmJlxOkzbgTSApiAt3yUNzDL5ckeEkx59k838gpC4oyhbU7Ndg3mA0DXs9wjkWQU5e4Gc83lIUmiziTano8KyLK3KVd86kHoXHSU20,&q={searchTerms}
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2018-06-17] (Microsoft Corporation)
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre-9\bin\ssv.dll => No File
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre-9\bin\jp2ssv.dll [2017-10-09] (Oracle Corporation)
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll [2018-04-30] (Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-06-01] (Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-06-01] (Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-06-01] (Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-06-01] (Microsoft Corporation)

Edge:
======
Edge HomeButtonPage: HKU\S-1-5-21-1124267341-3267589977-3522073591-1001 -> about:tabs

FireFox:
========
FF Plugin: @java.com/DTPlugin,version=12.0.0.0 -> C:\Program Files\Java\jre-9\bin\dtplugin\npDeployJava1.dll [2017-10-09] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=12.0.0.0 -> C:\Program Files\Java\jre-9\bin\plugin2\npjp2.dll [2017-10-09] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2018-04-04] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2018-03-03] (Microsoft Corporation)
FF Plugin-x32: @nitropdf.com/NitroPDF -> C:\Program Files (x86)\Nitro\Pro 10\npnitromozilla.dll [2015-05-06] (Nitro PDF)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2017-07-19] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2017-07-19] (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-05-17] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-05-17] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-08-01] (Adobe Systems Inc.)

Chrome:
=======
CHR Profile: C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default [2018-06-24]
CHR Extension: (Google Translate) - C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb [2018-01-18]
CHR Extension: (Slides) - C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-01-17]
CHR Extension: (Magic Actions for YouTube™) - C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\abjcfabbhafbcdfjoecdgepllmpfceif [2018-06-11]
CHR Extension: (BP Proxy Switcher) - C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aehcnjhffkonkdjckpapbpgommjkcmpl [2018-01-18]
CHR Extension: (Docs) - C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2018-01-17]
CHR Extension: (Google Drive) - C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-10-09]
CHR Extension: (Ledger Manager) - C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\beimhnaefocolcplfimocfiaiefpkgbf [2018-03-12]
CHR Extension: (YouTube) - C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-10-09]
CHR Extension: (Adblock Plus) - C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2018-05-21]
CHR Extension: (Sheets) - C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-01-17]
CHR Extension: (Authy Chrome Extension) - C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\fhgenkpocbhhddlgkjnfghpjanffonno [2018-01-18]
CHR Extension: (Authy) - C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\gaedmjdfmmahhbjefcbgaolhhanlaolb [2018-06-11]
CHR Extension: (Chrome Remote Desktop) - C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbchcmhmhahfdphkhkmpfmihenigjmpp [2018-01-17]
CHR Extension: (Google Docs Offline) - C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-10-09]
CHR Extension: (AdBlock) - C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2018-06-17]
CHR Extension: (Flash Control) - C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\hdgadgplbbdjlbjgdociahdlmbglfeen [2018-01-18]
CHR Extension: (Ledger Wallet Ethereum) - C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmlhkialjkaldndjnlcdfdphcgeadkkm [2018-03-30]
CHR Extension: (Cryptonite by MetaCert ) - C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\keghdcpemohlojlglbiegihkljkgnige [2018-06-24]
CHR Extension: (Google Keep Chrome Extension) - C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\lpcaedmchfhocbbapmcbpinfpgnhiddi [2018-06-24]
CHR Extension: (Chrome Web Store Payments) - C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-04-04]
CHR Extension: (Gmail) - C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-10-09]
CHR Extension: (Chrome Media Router) - C:\Users\PC\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-06-24]
CHR Profile: C:\Users\PC\AppData\Local\Google\Chrome\User Data\System Profile [2018-06-24]

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [6893704 2018-06-23] ()
R2 chromoting; C:\Program Files (x86)\Google\Chrome Remote Desktop\68.0.3440.11\remoting_host.exe [72536 2018-05-31] (Google Inc.)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [8654504 2018-06-12] (Microsoft Corporation)
S3 EasyAntiCheat; C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe [777856 2018-06-23] (EasyAntiCheat Ltd)
R2 NitroDriverReadSpool10; C:\Program Files\Nitro\Pro 10\NitroPDFDriverService10x64.exe [324760 2015-05-06] (Nitro PDF Software)
R2 NitroUpdateService; C:\Program Files\Nitro\Pro 10\Nitro_UpdateService.exe [418968 2015-05-06] ()
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [4737448 2018-04-12] (Microsoft Corporation)
S4 ssh-agent; C:\WINDOWS\System32\OpenSSH\ssh-agent.exe [495616 2018-03-10] ()
R2 ss_conn_service; C:\Program Files\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe [752224 2017-01-16] (DEVGURU Co., LTD.)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.16.17656.18052-0\NisSrv.exe [4682552 2018-05-30] (Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.16.17656.18052-0\MsMpEng.exe [101096 2018-05-30] (Microsoft Corporation)
R2 NVDisplay.ContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" -r -p 30000
S3 SystemUpdate64; no ImagePath <==== ATTENTION

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [604160 2018-04-12] (Realtek )
S3 WdBoot; C:\WINDOWS\system32\drivers\wd\WdBoot.sys [46072 2018-05-30] (Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\wd\WdFilter.sys [313384 2018-05-30] (Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [61992 2018-05-30] (Microsoft Corporation)
R3 XSplit_Dummy; C:\WINDOWS\system32\drivers\xspltspk.sys [26200 2016-06-15] (SplitmediaLabs Limited)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2018-06-24 12:56 - 2018-06-24 03:27 - 098566144 _____ C:\WINDOWS\system32\config\SOFTWARE
2018-06-24 12:53 - 2018-06-24 12:56 - 000000000 ____D C:\WINDOWS\Microsoft Antimalware
2018-06-24 04:18 - 2018-06-24 04:18 - 000023409 _____ C:\Users\PC\Desktop\FRST.txt
2018-06-24 04:17 - 2018-06-24 04:18 - 000000000 ____D C:\FRST
2018-06-24 04:16 - 2018-06-24 04:16 - 002412544 _____ (Farbar) C:\Users\PC\Desktop\FRST64.exe
2018-06-24 03:31 - 2018-06-24 03:31 - 000000000 ____D C:\Users\PC\AppData\LocalLow\Mozilla
2018-06-24 03:00 - 2018-06-24 04:10 - 000000000 ____D C:\ProgramData\SystemaRev
2018-06-24 02:56 - 2018-06-24 02:56 - 000016788 _____ C:\WINDOWS\System32\Tasks\ThePake-dll
2018-06-24 02:24 - 2018-06-24 02:24 - 000016780 _____ C:\WINDOWS\System32\Tasks\ThePake
2018-06-24 02:12 - 2018-06-24 04:00 - 000000410 __RSH C:\ProgramData\ntuser.pol
2018-06-24 02:12 - 2018-06-24 03:28 - 000003892 _____ C:\WINDOWS\System32\Tasks\Update_4.0.10
2018-06-24 02:12 - 2018-06-24 03:28 - 000003878 _____ C:\WINDOWS\System32\Tasks\MainPMgr
2018-06-24 02:12 - 2018-06-24 03:26 - 000000000 ____D C:\Program Files (x86)\Microsoft Toolkit Final
2018-06-24 02:12 - 2018-06-24 03:26 - 000000000 ____D C:\Program Files (x86)\foldershare
2018-06-24 02:12 - 2018-06-24 03:26 - 000000000 ____D C:\Program Files (x86)\FastDataX
2018-06-24 02:12 - 2018-06-24 02:36 - 000000000 ____D C:\ProgramData\PrefsSecure
2018-06-24 02:12 - 2018-06-24 02:36 - 000000000 ____D C:\ProgramData\Logic Cramble
2018-06-24 02:12 - 2018-06-24 02:24 - 000929792 _____ C:\Users\PC\AppData\Local\sham.db
2018-06-24 02:12 - 2018-06-24 02:24 - 000016080 _____ C:\Users\PC\AppData\Local\InstallationConfiguration.xml
2018-06-24 02:12 - 2018-06-24 02:16 - 000000000 ____D C:\ProgramData\Subair
2018-06-24 02:12 - 2018-06-24 02:12 - 007629312 _____ C:\Users\PC\AppData\Local\agent.dat
2018-06-24 02:12 - 2018-06-24 02:12 - 001988493 _____ C:\Users\PC\AppData\Local\Ranity.tst
2018-06-24 02:12 - 2018-06-24 02:12 - 001895382 _____ C:\Users\PC\AppData\Local\Xxx-lax.bin
2018-06-24 02:12 - 2018-06-24 02:12 - 001810944 _____ (TODO: <Company name>) C:\Users\PC\AppData\Local\Ranity.exe
2018-06-24 02:12 - 2018-06-24 02:12 - 000278511 _____ C:\Users\PC\AppData\Local\Ap-Kix.bin
2018-06-24 02:12 - 2018-06-24 02:12 - 000140800 _____ C:\Users\PC\AppData\Local\installer.dat
2018-06-24 02:12 - 2018-06-24 02:12 - 000126464 _____ C:\Users\PC\AppData\Local\noah.dat
2018-06-24 02:12 - 2018-06-24 02:12 - 000070896 _____ C:\Users\PC\AppData\Local\Config.xml
2018-06-24 02:12 - 2018-06-24 02:12 - 000018432 _____ C:\Users\PC\AppData\Local\Main.dat
2018-06-24 02:12 - 2018-06-24 02:12 - 000016910 _____ C:\WINDOWS\System32\Tasks\Accent Online Paintings 2007
2018-06-24 02:12 - 2018-06-24 02:12 - 000015610 _____ C:\WINDOWS\SysWOW64\findit.xml
2018-06-24 02:12 - 2018-06-24 02:12 - 000005568 _____ C:\Users\PC\AppData\Local\md.xml
2018-06-24 02:12 - 2018-06-24 02:12 - 000003586 _____ C:\WINDOWS\System32\Tasks\PPI Update
2018-06-24 02:12 - 2018-06-24 02:12 - 000003366 _____ C:\WINDOWS\System32\Tasks\RestoreRevTask
2018-06-24 02:12 - 2018-06-24 02:12 - 000000000 ____D C:\Users\PC\AppData\Roaming\FastDataX
2018-06-24 02:12 - 2018-06-24 02:12 - 000000000 ____D C:\ProgramData\Subairs
2018-06-24 02:12 - 2018-06-24 02:12 - 000000000 ____D C:\Program Files\SystemaRev
2018-06-24 00:21 - 2018-06-24 00:21 - 000000000 ____D C:\Users\PC\AppData\Local\TslGame
2018-06-24 00:21 - 2018-06-24 00:21 - 000000000 ____D C:\Users\PC\AppData\Local\NVIDIA Corporation
2018-06-23 23:40 - 2018-06-23 23:40 - 000000222 _____ C:\Users\PC\Desktop\PLAYERUNKNOWN'S BATTLEGROUNDS.url
2018-06-21 01:31 - 2018-06-21 01:31 - 000000000 ____D C:\Users\PC\AppData\Local\Viber
2018-06-19 23:37 - 2018-06-24 03:31 - 000000000 ____D C:\Users\PC\AppData\Roaming\Mozilla
2018-06-16 21:18 - 2018-06-16 21:18 - 000000164 ____H C:\Program Files\Common Files\restore_rev.bat
2018-06-13 13:29 - 2018-06-08 21:07 - 002266520 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVEntSubsystems64.dll
2018-06-13 13:29 - 2018-06-08 21:07 - 000506184 _____ (Microsoft Corporation) C:\WINDOWS\system32\systemreset.exe
2018-06-13 13:29 - 2018-06-08 21:07 - 000183712 _____ (Microsoft Corporation) C:\WINDOWS\system32\mavinject.exe
2018-06-13 13:29 - 2018-06-08 21:07 - 000040864 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVClientPS.dll
2018-06-13 13:29 - 2018-06-08 21:07 - 000019872 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVTerminator.dll
2018-06-13 13:29 - 2018-06-08 21:05 - 000094112 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpudd.dll
2018-06-13 13:29 - 2018-06-08 21:02 - 004527680 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppsvc.exe
2018-06-13 13:29 - 2018-06-08 21:02 - 001634808 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll
2018-06-13 13:29 - 2018-06-08 21:02 - 000661160 _____ (Microsoft Corporation) C:\WINDOWS\system32\GenValObj.exe
2018-06-13 13:29 - 2018-06-08 21:01 - 002395056 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMVCORE.DLL
2018-06-13 13:29 - 2018-06-08 21:01 - 001046944 _____ (Microsoft Corporation) C:\WINDOWS\system32\ReAgent.dll
2018-06-13 13:29 - 2018-06-08 20:48 - 000064000 _____ (Microsoft Corporation) C:\WINDOWS\system32\iemigplugin.dll
2018-06-13 13:29 - 2018-06-08 20:47 - 000144384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxdav.sys
2018-06-13 13:29 - 2018-06-08 20:46 - 000584192 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIRibbonRes.dll
2018-06-13 13:29 - 2018-06-08 20:45 - 012712448 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2018-06-13 13:29 - 2018-06-08 20:45 - 004392448 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2018-06-13 13:29 - 2018-06-08 20:45 - 001560576 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdt.exe
2018-06-13 13:29 - 2018-06-08 20:45 - 000808960 _____ C:\WINDOWS\system32\MBR2GPT.EXE
2018-06-13 13:29 - 2018-06-08 20:44 - 001121792 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSWorkspace.dll
2018-06-13 13:29 - 2018-06-08 20:44 - 000625152 _____ (Microsoft Corporation) C:\WINDOWS\system32\BootMenuUX.dll
2018-06-13 13:29 - 2018-06-08 20:44 - 000340992 _____ (Microsoft Corporation) C:\WINDOWS\system32\AcGenral.dll
2018-06-13 13:29 - 2018-06-08 20:44 - 000285184 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidcredprov.dll
2018-06-13 13:29 - 2018-06-08 20:43 - 003640832 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstsc.exe
2018-06-13 13:29 - 2018-06-08 20:43 - 002922496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll
2018-06-13 13:29 - 2018-06-08 20:43 - 001719808 _____ (Microsoft Corporation) C:\WINDOWS\system32\dui70.dll
2018-06-13 13:29 - 2018-06-08 20:43 - 001659904 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsPrint.dll
2018-06-13 13:29 - 2018-06-08 20:43 - 001543680 _____ (Microsoft Corporation) C:\WINDOWS\system32\msdtctm.dll
2018-06-13 13:29 - 2018-06-08 20:43 - 001364992 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvruserservice.dll
2018-06-13 13:29 - 2018-06-08 20:43 - 000392192 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2018-06-13 13:29 - 2018-06-08 20:42 - 003999232 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIRibbon.dll
2018-06-13 13:29 - 2018-06-08 20:42 - 003653120 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2018-06-13 13:29 - 2018-06-08 20:42 - 002084864 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2018-06-13 13:29 - 2018-06-08 20:42 - 001605632 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcorets.dll
2018-06-13 13:29 - 2018-06-08 20:42 - 000800256 _____ (Microsoft Corporation) C:\WINDOWS\system32\pwcreator.exe
2018-06-13 13:29 - 2018-06-08 20:42 - 000503296 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppcext.dll
2018-06-13 13:29 - 2018-06-08 20:42 - 000463872 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpshell.exe
2018-06-13 13:29 - 2018-06-08 20:42 - 000327168 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpinit.exe
2018-06-13 13:29 - 2018-06-08 20:41 - 002019840 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngine.dll
2018-06-13 13:29 - 2018-06-08 20:41 - 001180672 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll
2018-06-13 13:29 - 2018-06-08 20:41 - 000878080 _____ (Microsoft Corporation) C:\WINDOWS\system32\CPFilters.dll
2018-06-13 13:29 - 2018-06-08 20:41 - 000758272 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2018-06-13 13:29 - 2018-06-08 20:41 - 000577024 _____ (Microsoft Corporation) C:\WINDOWS\system32\SppExtComObj.Exe
2018-06-13 13:29 - 2018-06-08 20:41 - 000182272 _____ (Microsoft Corporation) C:\WINDOWS\system32\easwrt.dll
2018-06-13 13:29 - 2018-06-08 20:40 - 000465920 _____ (Microsoft Corporation) C:\WINDOWS\system32\DXP.dll
2018-06-13 13:29 - 2018-06-08 19:07 - 000148896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mavinject.exe
2018-06-13 13:29 - 2018-06-08 19:06 - 001539488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppVEntSubsystems32.dll
2018-06-13 13:29 - 2018-06-08 19:04 - 001454024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll
2018-06-13 13:29 - 2018-06-08 18:58 - 002206544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMVCORE.DLL
2018-06-13 13:29 - 2018-06-08 18:58 - 000917408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ReAgent.dll
2018-06-13 13:29 - 2018-06-08 18:51 - 011903488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2018-06-13 13:29 - 2018-06-08 18:50 - 001508352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msdt.exe
2018-06-13 13:29 - 2018-06-08 18:48 - 000668672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2018-06-13 13:29 - 2018-06-08 18:48 - 000344064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2018-06-13 13:29 - 2018-06-08 18:47 - 003492864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIRibbon.dll
2018-06-13 13:29 - 2018-06-08 18:47 - 002895872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2018-06-13 13:29 - 2018-06-08 18:47 - 001462784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dui70.dll
2018-06-13 13:29 - 2018-06-08 18:47 - 001032704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsPrint.dll
2018-06-13 13:29 - 2018-06-08 18:47 - 000703488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CPFilters.dll
2018-06-13 13:29 - 2018-06-08 18:47 - 000231936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlidcredprov.dll
2018-06-13 13:29 - 2018-06-08 18:46 - 003444224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstsc.exe
2018-06-13 13:29 - 2018-06-08 18:46 - 002016256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2018-06-13 13:29 - 2018-06-08 18:46 - 000908288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TSWorkspace.dll
2018-06-13 13:29 - 2018-06-08 18:45 - 002401280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AcGenral.dll
2018-06-13 13:29 - 2018-06-08 18:06 - 000976384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Spectrum.exe
2018-06-13 13:29 - 2018-06-08 18:05 - 001008640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.MixedRealityCapture.dll
2018-06-13 13:29 - 2018-06-08 18:05 - 000944640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Mirage.Internal.dll
2018-06-13 13:29 - 2018-06-08 16:00 - 000868864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.MixedRealityCapture.dll
2018-06-13 13:29 - 2018-06-08 16:00 - 000658432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Mirage.Internal.dll
2018-06-13 13:29 - 2018-06-08 12:38 - 005821544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d10warp.dll
2018-06-13 13:29 - 2018-06-08 12:37 - 002417840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11.dll
2018-06-13 13:29 - 2018-06-08 12:35 - 001613200 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3D12.dll
2018-06-13 13:29 - 2018-06-08 12:35 - 000613144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxgi.dll
2018-06-13 13:29 - 2018-06-08 12:34 - 001299056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3D12.dll
2018-06-13 13:29 - 2018-06-08 12:34 - 000748512 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll
2018-06-13 13:29 - 2018-06-08 12:31 - 007900984 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d10warp.dll
2018-06-13 13:29 - 2018-06-08 12:31 - 003180176 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11.dll
2018-06-13 13:29 - 2018-06-08 12:31 - 000029600 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\uefi.sys
2018-06-13 13:29 - 2018-06-08 12:30 - 000705440 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vhdmp.sys
2018-06-13 13:29 - 2018-06-08 11:34 - 001140576 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2018-06-13 13:29 - 2018-06-08 11:34 - 000983016 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2018-06-13 13:29 - 2018-06-08 11:33 - 001213368 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipUp.exe
2018-06-13 13:29 - 2018-06-08 11:33 - 001034632 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApplyTrustOffline.exe
2018-06-13 13:29 - 2018-06-08 11:33 - 000272296 _____ (Microsoft Corporation) C:\WINDOWS\system32\SgrmEnclave.dll
2018-06-13 13:29 - 2018-06-08 11:33 - 000269224 _____ (Microsoft Corporation) C:\WINDOWS\system32\SgrmEnclave_secure.dll
2018-06-13 13:29 - 2018-06-08 11:31 - 001174432 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2018-06-13 13:29 - 2018-06-08 11:31 - 001012640 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2018-06-13 13:29 - 2018-06-08 11:31 - 000226720 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Ucx01000.sys
2018-06-13 13:29 - 2018-06-08 11:30 - 009148320 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2018-06-13 13:29 - 2018-06-08 11:30 - 003296896 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll
2018-06-13 13:29 - 2018-06-08 11:30 - 001798552 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll
2018-06-13 13:29 - 2018-06-08 11:30 - 001363632 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinTypes.dll
2018-06-13 13:29 - 2018-06-08 11:30 - 001063328 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
2018-06-13 13:29 - 2018-06-08 11:30 - 001017080 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2adec.dll
2018-06-13 13:29 - 2018-06-08 11:30 - 000723360 _____ (Microsoft Corporation) C:\WINDOWS\system32\wimgapi.dll
2018-06-13 13:29 - 2018-06-08 11:30 - 000722808 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll
2018-06-13 13:29 - 2018-06-08 11:30 - 000709824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2018-06-13 13:29 - 2018-06-08 11:30 - 000567184 _____ (Microsoft Corporation) C:\WINDOWS\system32\tcblaunch.exe
2018-06-13 13:29 - 2018-06-08 11:30 - 000565152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBHUB3.SYS
2018-06-13 13:29 - 2018-06-08 11:30 - 000527264 _____ (Microsoft Corporation) C:\WINDOWS\system32\wimserv.exe
2018-06-13 13:29 - 2018-06-08 11:30 - 000491328 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll
2018-06-13 13:29 - 2018-06-08 11:30 - 000194456 _____ (Microsoft Corporation) C:\WINDOWS\system32\skci.dll
2018-06-13 13:29 - 2018-06-08 11:30 - 000170912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
2018-06-13 13:29 - 2018-06-08 11:30 - 000137568 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcrypt.dll
2018-06-13 13:29 - 2018-06-08 11:30 - 000134584 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.dll
2018-06-13 13:29 - 2018-06-08 11:29 - 007520000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2018-06-13 13:29 - 2018-06-08 11:29 - 006817384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2018-06-13 13:29 - 2018-06-08 11:29 - 004970360 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepository.dll
2018-06-13 13:29 - 2018-06-08 11:29 - 004403280 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2018-06-13 13:29 - 2018-06-08 11:29 - 003283408 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreUIComponents.dll
2018-06-13 13:29 - 2018-06-08 11:29 - 002836384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2018-06-13 13:29 - 2018-06-08 11:29 - 002753048 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2018-06-13 13:29 - 2018-06-08 11:29 - 002590400 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMVDECOD.DLL
2018-06-13 13:29 - 2018-06-08 11:29 - 002570712 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2018-06-13 13:29 - 2018-06-08 11:29 - 002564984 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll
2018-06-13 13:29 - 2018-06-08 11:29 - 002546592 _____ (Microsoft Corporation) C:\WINDOWS\system32\UpdateAgent.dll
2018-06-13 13:29 - 2018-06-08 11:29 - 002462272 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6.dll
2018-06-13 13:29 - 2018-06-08 11:29 - 002422688 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
2018-06-13 13:29 - 2018-06-08 11:29 - 002371392 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll
2018-06-13 13:29 - 2018-06-08 11:29 - 001946328 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2018-06-13 13:29 - 2018-06-08 11:29 - 001934400 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
2018-06-13 13:29 - 2018-06-08 11:29 - 001921952 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\refs.sys
2018-06-13 13:29 - 2018-06-08 11:29 - 001792808 _____ (Microsoft Corporation) C:\WINDOWS\system32\propsys.dll
2018-06-13 13:29 - 2018-06-08 11:29 - 001784584 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfasfsrcsnk.dll
2018-06-13 13:29 - 2018-06-08 11:29 - 001611592 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfnetsrc.dll
2018-06-13 13:29 - 2018-06-08 11:29 - 001457136 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2018-06-13 13:29 - 2018-06-08 11:29 - 001364184 _____ (Microsoft Corporation) C:\WINDOWS\system32\webservices.dll
2018-06-13 13:29 - 2018-06-08 11:29 - 001288816 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll
2018-06-13 13:29 - 2018-06-08 11:29 - 001258288 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2018-06-13 13:29 - 2018-06-08 11:29 - 001209800 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2018-06-13 13:29 - 2018-06-08 11:29 - 001190152 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcrt4.dll
2018-06-13 13:29 - 2018-06-08 11:29 - 001150416 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVP9DEC.dll
2018-06-13 13:29 - 2018-06-08 11:29 - 001148808 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
2018-06-13 13:29 - 2018-06-08 11:29 - 001112608 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfds.dll
2018-06-13 13:29 - 2018-06-08 11:29 - 001097648 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvproc.dll
2018-06-13 13:29 - 2018-06-08 11:29 - 001026976 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\http.sys
2018-06-13 13:29 - 2018-06-08 11:29 - 000945568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\refsv1.sys
2018-06-13 13:29 - 2018-06-08 11:29 - 000885880 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll
2018-06-13 13:29 - 2018-06-08 11:29 - 000792992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2018-06-13 13:29 - 2018-06-08 11:29 - 000678840 _____ (Microsoft Corporation) C:\WINDOWS\system32\SHCore.dll
2018-06-13 13:29 - 2018-06-08 11:29 - 000659096 _____ (Microsoft Corporation) C:\WINDOWS\system32\StateRepository.Core.dll
2018-06-13 13:29 - 2018-06-08 11:29 - 000594128 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
2018-06-13 13:29 - 2018-06-08 11:29 - 000416144 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSAudDecMFT.dll
2018-06-13 13:29 - 2018-06-08 11:29 - 000413824 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll
2018-06-13 13:29 - 2018-06-08 11:29 - 000413088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2018-06-13 13:29 - 2018-06-08 11:29 - 000375712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\msrpc.sys
2018-06-13 13:29 - 2018-06-08 11:29 - 000313592 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsensorgroup.dll
2018-06-13 13:29 - 2018-06-08 11:29 - 000266656 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll
2018-06-13 13:29 - 2018-06-08 11:29 - 000260896 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
2018-06-13 13:29 - 2018-06-08 11:29 - 000164768 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wfplwfs.sys
2018-06-13 13:29 - 2018-06-08 11:29 - 000158720 _____ (Microsoft Corporation) C:\WINDOWS\system32\vertdll.dll
2018-06-13 13:29 - 2018-06-08 11:29 - 000084288 _____ (Microsoft Corporation) C:\WINDOWS\system32\LanguageOverlayUtil.dll
2018-06-13 13:29 - 2018-06-08 11:29 - 000057960 _____ (Microsoft Corporation) C:\WINDOWS\system32\kernel.appcore.dll
2018-06-13 13:29 - 2018-06-08 11:13 - 025846784 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2018-06-13 13:29 - 2018-06-08 11:12 - 000861616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2adec.dll
2018-06-13 13:29 - 2018-06-08 11:12 - 000786176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rpcrt4.dll
2018-06-13 13:29 - 2018-06-08 11:11 - 001461744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.appcore.dll
2018-06-13 13:29 - 2018-06-08 11:11 - 000550616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf.dll
2018-06-13 13:29 - 2018-06-08 11:10 - 002479272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll
2018-06-13 13:29 - 2018-06-08 11:10 - 002331584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2vdec.dll
2018-06-13 13:29 - 2018-06-08 11:10 - 002307336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMVDECOD.DLL
2018-06-13 13:29 - 2018-06-08 11:10 - 001988072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml6.dll
2018-06-13 13:29 - 2018-06-08 11:10 - 001397200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVP9DEC.dll
2018-06-13 13:29 - 2018-06-08 11:10 - 001011992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
2018-06-13 13:29 - 2018-06-08 11:10 - 000880152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinTypes.dll
2018-06-13 13:29 - 2018-06-08 11:10 - 000457152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSAudDecMFT.dll
2018-06-13 13:29 - 2018-06-08 11:10 - 000097176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcrypt.dll
2018-06-13 13:29 - 2018-06-08 11:09 - 006569960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2018-06-13 13:29 - 2018-06-08 11:09 - 006527064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
2018-06-13 13:29 - 2018-06-08 11:09 - 004788512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2018-06-13 13:29 - 2018-06-08 11:09 - 004469832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepository.dll
2018-06-13 13:29 - 2018-06-08 11:09 - 002535552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll
2018-06-13 13:29 - 2018-06-08 11:09 - 002486992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreUIComponents.dll
2018-06-13 13:29 - 2018-06-08 11:09 - 002242216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2018-06-13 13:29 - 2018-06-08 11:09 - 001980872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2018-06-13 13:29 - 2018-06-08 11:09 - 001805776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioEng.dll
2018-06-13 13:29 - 2018-06-08 11:09 - 001709720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfnetsrc.dll
2018-06-13 13:29 - 2018-06-08 11:09 - 001620880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2018-06-13 13:29 - 2018-06-08 11:09 - 001584128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\propsys.dll
2018-06-13 13:29 - 2018-06-08 11:09 - 001380200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfasfsrcsnk.dll
2018-06-13 13:29 - 2018-06-08 11:09 - 001129648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvproc.dll
2018-06-13 13:29 - 2018-06-08 11:09 - 001077504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webservices.dll
2018-06-13 13:29 - 2018-06-08 11:09 - 001020168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll
2018-06-13 13:29 - 2018-06-08 11:09 - 000988136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll
2018-06-13 13:29 - 2018-06-08 11:09 - 000770160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfds.dll
2018-06-13 13:29 - 2018-06-08 11:09 - 000607648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wimgapi.dll
2018-06-13 13:29 - 2018-06-08 11:09 - 000568720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryPS.dll
2018-06-13 13:29 - 2018-06-08 11:09 - 000567144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll
2018-06-13 13:29 - 2018-06-08 11:09 - 000553248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SHCore.dll
2018-06-13 13:29 - 2018-06-08 11:09 - 000356960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcryptprimitives.dll
2018-06-13 13:29 - 2018-06-08 11:09 - 000064648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LanguageOverlayUtil.dll
2018-06-13 13:29 - 2018-06-08 11:09 - 000050208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kernel.appcore.dll
2018-06-13 13:29 - 2018-06-08 11:04 - 004706816 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdp.dll
2018-06-13 13:29 - 2018-06-08 11:03 - 022005760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2018-06-13 13:29 - 2018-06-08 11:03 - 000906752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Globalization.PhoneNumberFormatting.dll
2018-06-13 13:29 - 2018-06-08 11:03 - 000185344 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallServiceTasks.dll
2018-06-13 13:29 - 2018-06-08 11:03 - 000038400 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryCore.dll
2018-06-13 13:29 - 2018-06-08 11:03 - 000032256 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mskssrv.sys
2018-06-13 13:29 - 2018-06-08 11:02 - 022713856 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2018-06-13 13:29 - 2018-06-08 11:02 - 000096768 _____ (Microsoft Corporation) C:\WINDOWS\system32\usoapi.dll
2018-06-13 13:29 - 2018-06-08 11:02 - 000059904 _____ (Microsoft Corporation) C:\WINDOWS\system32\edpnotify.exe
2018-06-13 13:29 - 2018-06-08 11:02 - 000035840 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBrokerCookies.exe
2018-06-13 13:29 - 2018-06-08 11:01 - 004563456 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
2018-06-13 13:29 - 2018-06-08 11:01 - 002961408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cdp.dll
2018-06-13 13:29 - 2018-06-08 11:01 - 000342528 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserexport.exe
2018-06-13 13:29 - 2018-06-08 11:01 - 000295424 _____ (Microsoft Corporation) C:\WINDOWS\system32\FSClient.dll
2018-06-13 13:29 - 2018-06-08 11:01 - 000294912 _____ (Microsoft Corporation) C:\WINDOWS\system32\TDLMigration.dll
2018-06-13 13:29 - 2018-06-08 11:01 - 000209408 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXApplicabilityBlob.dll
2018-06-13 13:29 - 2018-06-08 11:01 - 000182272 _____ (Microsoft Corporation) C:\WINDOWS\system32\BitLockerCsp.dll
2018-06-13 13:29 - 2018-06-08 11:01 - 000046080 _____ (Microsoft Corporation) C:\WINDOWS\system32\tbauth.dll
2018-06-13 13:29 - 2018-06-08 11:01 - 000046080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidparse.sys
2018-06-13 13:29 - 2018-06-08 11:00 - 019404288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2018-06-13 13:29 - 2018-06-08 11:00 - 004372992 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeContent.dll
2018-06-13 13:29 - 2018-06-08 11:00 - 003320320 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2018-06-13 13:29 - 2018-06-08 11:00 - 001285120 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Maps.dll
2018-06-13 13:29 - 2018-06-08 11:00 - 000329216 _____ (Microsoft Corporation) C:\WINDOWS\system32\credprovs.dll
2018-06-13 13:29 - 2018-06-08 11:00 - 000275456 _____ (Microsoft Corporation) C:\WINDOWS\system32\SIHClient.exe
2018-06-13 13:29 - 2018-06-08 11:00 - 000149504 _____ (Microsoft Corporation) C:\WINDOWS\system32\dssvc.dll
2018-06-13 13:29 - 2018-06-08 11:00 - 000100864 _____ (Microsoft Corporation) C:\WINDOWS\system32\CapabilityAccessManagerClient.dll
2018-06-13 13:29 - 2018-06-08 11:00 - 000075776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mpsdrv.sys
2018-06-13 13:29 - 2018-06-08 10:59 - 006032384 _____ (Microsoft Corporation) C:\WINDOWS\system32\d2d1.dll
2018-06-13 13:29 - 2018-06-08 10:59 - 004867072 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2018-06-13 13:29 - 2018-06-08 10:59 - 003392512 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2018-06-13 13:29 - 2018-06-08 10:59 - 001767936 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2018-06-13 13:29 - 2018-06-08 10:59 - 001318400 _____ (Microsoft Corporation) C:\WINDOWS\system32\ISM.dll
2018-06-13 13:29 - 2018-06-08 10:59 - 000983040 _____ (Microsoft Corporation) C:\WINDOWS\system32\wbiosrvc.dll
2018-06-13 13:29 - 2018-06-08 10:59 - 000673792 _____ (Microsoft Corporation) C:\WINDOWS\system32\FrameServer.dll
2018-06-13 13:29 - 2018-06-08 10:59 - 000564736 _____ (Microsoft Corporation) C:\WINDOWS\system32\daxexec.dll
2018-06-13 13:29 - 2018-06-08 10:59 - 000456704 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDEServer.exe
2018-06-13 13:29 - 2018-06-08 10:59 - 000177152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.StateRepositoryUpgrade.dll
2018-06-13 13:29 - 2018-06-08 10:59 - 000174080 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhosdeployment.dll
2018-06-13 13:29 - 2018-06-08 10:58 - 007581696 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2018-06-13 13:29 - 2018-06-08 10:58 - 003712512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2018-06-13 13:29 - 2018-06-08 10:58 - 001676800 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreShell.dll
2018-06-13 13:29 - 2018-06-08 10:58 - 000898560 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcWebFilter.dll
2018-06-13 13:29 - 2018-06-08 10:58 - 000894464 _____ (Microsoft Corporation) C:\WINDOWS\system32\webplatstorageserver.dll
2018-06-13 13:29 - 2018-06-08 10:58 - 000813568 _____ (Microsoft Corporation) C:\WINDOWS\system32\EdgeManager.dll
2018-06-13 13:29 - 2018-06-08 10:58 - 000781824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdiWiFi.sys
2018-06-13 13:29 - 2018-06-08 10:58 - 000266752 _____ (Microsoft Corporation) C:\WINDOWS\system32\CapabilityAccessManager.dll
2018-06-13 13:29 - 2018-06-08 10:58 - 000239104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FSClient.dll
2018-06-13 13:29 - 2018-06-08 10:58 - 000029184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBrokerCookies.exe
2018-06-13 13:29 - 2018-06-08 10:57 - 003348992 _____ (Microsoft Corporation) C:\WINDOWS\system32\msftedit.dll
2018-06-13 13:29 - 2018-06-08 10:57 - 002172416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2018-06-13 13:29 - 2018-06-08 10:57 - 001708544 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSPhotography.dll
2018-06-13 13:29 - 2018-06-08 10:57 - 001485312 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallService.dll
2018-06-13 13:29 - 2018-06-08 10:57 - 000483328 _____ (Microsoft Corporation) C:\WINDOWS\system32\RTMediaFrame.dll
2018-06-13 13:29 - 2018-06-08 10:57 - 000401920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ks.sys
2018-06-13 13:29 - 2018-06-08 10:57 - 000310272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wincorlib.dll
2018-06-13 13:29 - 2018-06-08 10:57 - 000150016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.StateRepositoryUpgrade.dll
2018-06-13 13:29 - 2018-06-08 10:57 - 000038400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tbauth.dll
2018-06-13 13:29 - 2018-06-08 10:56 - 005780992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2018-06-13 13:29 - 2018-06-08 10:56 - 005307392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1.dll
2018-06-13 13:29 - 2018-06-08 10:56 - 004336128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
2018-06-13 13:29 - 2018-06-08 10:56 - 003293696 _____ (Microsoft Corporation) C:\WINDOWS\system32\esent.dll
2018-06-13 13:29 - 2018-06-08 10:56 - 002902016 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2018-06-13 13:29 - 2018-06-08 10:56 - 002900480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2018-06-13 13:29 - 2018-06-08 10:56 - 002364928 _____ (Microsoft Corporation) C:\WINDOWS\system32\OpcServices.dll
2018-06-13 13:29 - 2018-06-08 10:56 - 001804288 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2018-06-13 13:29 - 2018-06-08 10:56 - 001550848 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
2018-06-13 13:29 - 2018-06-08 10:56 - 001395200 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll
2018-06-13 13:29 - 2018-06-08 10:56 - 001361408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSPhotography.dll
2018-06-13 13:29 - 2018-06-08 10:56 - 000916480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll
2018-06-13 13:29 - 2018-06-08 10:56 - 000908800 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSMPEG2ENC.DLL
2018-06-13 13:29 - 2018-06-08 10:56 - 000871424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.BackgroundMediaPlayback.dll
2018-06-13 13:29 - 2018-06-08 10:56 - 000869376 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Playback.BackgroundMediaPlayer.dll
2018-06-13 13:29 - 2018-06-08 10:56 - 000858112 _____ (Microsoft Corporation) C:\WINDOWS\system32\FlightSettings.dll
2018-06-13 13:29 - 2018-06-08 10:56 - 000715776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.dll
2018-06-13 13:29 - 2018-06-08 10:56 - 000684544 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2018-06-13 13:29 - 2018-06-08 10:56 - 000615424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EdgeManager.dll
2018-06-13 13:29 - 2018-06-08 10:56 - 000466432 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll
2018-06-13 13:29 - 2018-06-08 10:56 - 000389632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\daxexec.dll
2018-06-13 13:29 - 2018-06-08 10:56 - 000331264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgeIso.dll
2018-06-13 13:29 - 2018-06-08 10:56 - 000264704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\credprovs.dll
2018-06-13 13:29 - 2018-06-08 10:55 - 003441152 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2018-06-13 13:29 - 2018-06-08 10:55 - 002248192 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidsvc.dll
2018-06-13 13:29 - 2018-06-08 10:55 - 002236928 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2018-06-13 13:29 - 2018-06-08 10:55 - 002061824 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll
2018-06-13 13:29 - 2018-06-08 10:55 - 001854976 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtsvc.dll
2018-06-13 13:29 - 2018-06-08 10:55 - 001371648 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocore.dll
2018-06-13 13:29 - 2018-06-08 10:55 - 001242112 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmkvsrcsnk.dll
2018-06-13 13:29 - 2018-06-08 10:55 - 001192448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Maps.dll
2018-06-13 13:29 - 2018-06-08 10:55 - 001171968 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncCore.dll
2018-06-13 13:29 - 2018-06-08 10:55 - 001160192 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcss.dll
2018-06-13 13:29 - 2018-06-08 10:55 - 001070080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Streaming.dll
2018-06-13 13:29 - 2018-06-08 10:55 - 001033728 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll
2018-06-13 13:29 - 2018-06-08 10:55 - 000932352 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasmans.dll
2018-06-13 13:29 - 2018-06-08 10:55 - 000849408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Playback.MediaPlayer.dll
2018-06-13 13:29 - 2018-06-08 10:55 - 000778752 _____ (Microsoft Corporation) C:\WINDOWS\system32\BFE.DLL
2018-06-13 13:29 - 2018-06-08 10:55 - 000776192 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2018-06-13 13:29 - 2018-06-08 10:55 - 000667648 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppReadiness.dll
2018-06-13 13:29 - 2018-06-08 10:55 - 000652800 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActivationManager.dll
2018-06-13 13:29 - 2018-06-08 10:55 - 000630784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Playback.MediaPlayer.dll
2018-06-13 13:29 - 2018-06-08 10:55 - 000578560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webplatstorageserver.dll
2018-06-13 13:29 - 2018-06-08 10:55 - 000401920 _____ (Microsoft Corporation) C:\WINDOWS\system32\rascustom.dll
2018-06-13 13:29 - 2018-06-08 10:54 - 003016192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2018-06-13 13:29 - 2018-06-08 10:54 - 002789376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msftedit.dll
2018-06-13 13:29 - 2018-06-08 10:54 - 001627136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2018-06-13 13:29 - 2018-06-08 10:54 - 001586176 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2018-06-13 13:29 - 2018-06-08 10:54 - 001348096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OpcServices.dll
2018-06-13 13:29 - 2018-06-08 10:54 - 001128448 _____ (Microsoft Corporation) C:\WINDOWS\system32\MbaeApiPublic.dll
2018-06-13 13:29 - 2018-06-08 10:54 - 000999936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll
2018-06-13 13:29 - 2018-06-08 10:54 - 000950272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncCore.dll
2018-06-13 13:29 - 2018-06-08 10:54 - 000857088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSMPEG2ENC.DLL
2018-06-13 13:29 - 2018-06-08 10:54 - 000842240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmkvsrcsnk.dll
2018-06-13 13:29 - 2018-06-08 10:54 - 000729088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FlightSettings.dll
2018-06-13 13:29 - 2018-06-08 10:54 - 000646656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Playback.BackgroundMediaPlayer.dll
2018-06-13 13:29 - 2018-06-08 10:54 - 000619520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WpcWebFilter.dll
2018-06-13 13:29 - 2018-06-08 10:54 - 000593408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.dll
2018-06-13 13:29 - 2018-06-08 10:54 - 000505344 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgeIso.dll
2018-06-13 13:29 - 2018-06-08 10:54 - 000375808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RTMediaFrame.dll
2018-06-13 13:29 - 2018-06-08 10:54 - 000251904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msIso.dll
2018-06-13 13:29 - 2018-06-08 10:54 - 000208384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSAC3ENC.DLL
2018-06-13 13:29 - 2018-06-08 10:53 - 001675264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll
2018-06-13 13:29 - 2018-06-08 10:53 - 001466368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2018-06-13 13:29 - 2018-06-08 10:53 - 001108992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallService.dll
2018-06-13 13:29 - 2018-06-08 10:53 - 000873472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Streaming.dll
2018-06-13 13:29 - 2018-06-08 10:53 - 000677888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Web.Core.dll
2018-06-13 13:29 - 2018-06-08 10:53 - 000669696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2018-06-13 13:29 - 2018-06-08 10:53 - 000648192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.BackgroundMediaPlayback.dll
2018-06-13 13:29 - 2018-06-08 10:53 - 000528384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActivationManager.dll
2018-06-13 13:29 - 2018-06-08 09:41 - 000001310 _____ C:\WINDOWS\system32\tcbres.wim
2018-06-13 13:29 - 2018-06-06 20:57 - 003733320 _____ C:\WINDOWS\system32\Windows.Mirage.dll
2018-06-13 13:29 - 2018-06-06 06:20 - 002841312 _____ C:\WINDOWS\SysWOW64\Windows.Mirage.dll
2018-06-13 13:29 - 2018-06-02 01:24 - 000713376 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVideoDSP.dll
2018-06-13 13:29 - 2018-06-02 00:54 - 001825792 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.CloudStore.dll
2018-06-13 13:29 - 2018-05-25 05:24 - 000340480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msexcl40.dll
2018-06-13 13:29 - 2018-05-20 21:45 - 000308408 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2018-06-13 13:29 - 2018-05-20 21:43 - 021389360 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2018-06-13 13:29 - 2018-05-20 21:42 - 001649760 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d9.dll
2018-06-13 13:29 - 2018-05-20 21:42 - 000759192 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicensingWinRT.dll
2018-06-13 13:29 - 2018-05-20 21:26 - 000486912 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasplap.dll
2018-06-13 13:29 - 2018-05-20 21:23 - 004070400 _____ (Microsoft Corporation) C:\WINDOWS\system32\msi.dll
2018-06-13 13:29 - 2018-05-20 21:23 - 000947712 _____ (Microsoft Corporation) C:\WINDOWS\system32\mmsys.cpl
2018-06-13 13:29 - 2018-05-20 21:23 - 000899072 _____ (Microsoft Corporation) C:\WINDOWS\system32\uDWM.dll
2018-06-13 13:29 - 2018-05-20 21:22 - 001665024 _____ (Microsoft Corporation) C:\WINDOWS\system32\comsvcs.dll
2018-06-13 13:29 - 2018-05-20 21:22 - 001292288 _____ (Microsoft Corporation) C:\WINDOWS\system32\GamePanel.exe
2018-06-13 13:29 - 2018-05-20 21:22 - 000941056 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasdlg.dll
2018-06-13 13:29 - 2018-05-20 21:22 - 000804352 _____ (Microsoft Corporation) C:\WINDOWS\system32\SndVolSSO.dll
2018-06-13 13:29 - 2018-05-20 20:20 - 000022936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hvsicontainerservice.dll
2018-06-13 13:29 - 2018-05-20 20:15 - 000653208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicensingWinRT.dll
2018-06-13 13:29 - 2018-05-20 20:14 - 020383712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2018-06-13 13:29 - 2018-05-20 20:14 - 001490144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d9.dll
2018-06-13 13:29 - 2018-05-20 20:02 - 000461312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasplap.dll
2018-06-13 13:29 - 2018-05-20 20:00 - 000864768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mmsys.cpl
2018-06-13 13:29 - 2018-05-20 19:59 - 000863232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasdlg.dll
2018-06-13 13:29 - 2018-05-20 19:59 - 000747520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SndVolSSO.dll
2018-06-13 13:29 - 2018-05-20 18:59 - 023862784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Hydrogen.dll
2018-06-13 13:29 - 2018-05-20 18:45 - 001271296 _____ (Microsoft Corporation) C:\WINDOWS\system32\HoloSI.PCShell.dll
2018-06-13 13:29 - 2018-05-20 18:39 - 000788480 _____ (Microsoft Corporation) C:\WINDOWS\system32\DHolographicDisplay.dll
2018-06-13 13:29 - 2018-05-20 18:35 - 000677376 _____ (Microsoft Corporation) C:\WINDOWS\system32\HeadTrackerStorage.dll
2018-06-13 13:29 - 2018-05-20 18:34 - 000238592 _____ (Microsoft Corporation) C:\WINDOWS\system32\HoloShellRuntime.dll
2018-06-13 13:29 - 2018-05-20 16:54 - 000184320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\HoloShellRuntime.dll
2018-06-13 13:29 - 2018-05-20 14:33 - 000105368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\stornvme.sys
2018-06-13 13:29 - 2018-05-20 13:53 - 002178136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2018-06-13 13:29 - 2018-05-20 13:53 - 001947808 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll
2018-06-13 13:29 - 2018-05-20 13:53 - 001017088 _____ (Microsoft Corporation) C:\WINDOWS\system32\DolbyDecMFT.dll
2018-06-13 13:29 - 2018-05-20 13:53 - 001012408 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfreadwrite.dll
2018-06-13 13:29 - 2018-05-20 13:53 - 000131232 _____ (Microsoft Corporation) C:\WINDOWS\system32\rmclient.dll
2018-06-13 13:29 - 2018-05-20 13:53 - 000088472 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\crashdmp.sys
2018-06-13 13:29 - 2018-05-20 13:52 - 007436632 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2018-06-13 13:29 - 2018-05-20 13:52 - 000735560 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll
2018-06-13 13:29 - 2018-05-20 13:52 - 000347704 _____ (Microsoft Corporation) C:\WINDOWS\system32\wintrust.dll
2018-06-13 13:29 - 2018-05-20 13:52 - 000130456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hvsocket.sys
2018-06-13 13:29 - 2018-05-20 13:52 - 000089984 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompPkgSup.dll
2018-06-13 13:29 - 2018-05-20 13:34 - 016592384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2018-06-13 13:29 - 2018-05-20 13:34 - 000861096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DolbyDecMFT.dll
2018-06-13 13:29 - 2018-05-20 13:33 - 001665920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll
2018-06-13 13:29 - 2018-05-20 13:33 - 000101288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rmclient.dll
2018-06-13 13:29 - 2018-05-20 13:32 - 006044104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2018-06-13 13:29 - 2018-05-20 13:32 - 001559368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll
2018-06-13 13:29 - 2018-05-20 13:32 - 001034096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfreadwrite.dll
2018-06-13 13:29 - 2018-05-20 13:32 - 000560488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll
2018-06-13 13:29 - 2018-05-20 13:32 - 000286200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wintrust.dll
2018-06-13 13:29 - 2018-05-20 13:32 - 000077040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CompPkgSup.dll
2018-06-13 13:29 - 2018-05-20 13:31 - 001456640 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcDesktopMonSvc.dll
2018-06-13 13:29 - 2018-05-20 13:30 - 008188928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2018-06-13 13:29 - 2018-05-20 13:28 - 000119296 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataTimeUtil.dll
2018-06-13 13:29 - 2018-05-20 13:28 - 000111616 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppHostRegistrationVerifier.exe
2018-06-13 13:29 - 2018-05-20 13:28 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzres.dll
2018-06-13 13:29 - 2018-05-20 13:27 - 000344576 _____ (Microsoft Corporation) C:\WINDOWS\system32\RasMediaManager.dll
2018-06-13 13:29 - 2018-05-20 13:27 - 000109568 _____ (Microsoft Corporation) C:\WINDOWS\system32\ApiSetHost.AppExecutionAlias.dll
2018-06-13 13:29 - 2018-05-20 13:26 - 003392512 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll
2018-06-13 13:29 - 2018-05-20 13:26 - 001307648 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVPXENC.dll
2018-06-13 13:29 - 2018-05-20 13:26 - 000356352 _____ (Microsoft Corporation) C:\WINDOWS\system32\dafWfdProvider.dll
2018-06-13 13:29 - 2018-05-20 13:26 - 000266752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srvnet.sys
2018-06-13 13:29 - 2018-05-20 13:26 - 000236032 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtutil.exe
2018-06-13 13:29 - 2018-05-20 13:26 - 000154112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2018-06-13 13:29 - 2018-05-20 13:26 - 000098816 _____ (Microsoft Corporation) C:\WINDOWS\system32\TelephonyInteractiveUser.dll
2018-06-13 13:29 - 2018-05-20 13:26 - 000033792 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSHEIF.dll
2018-06-13 13:29 - 2018-05-20 13:25 - 000835584 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneService.dll
2018-06-13 13:29 - 2018-05-20 13:25 - 000384000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Phoneutil.dll
2018-06-13 13:29 - 2018-05-20 13:24 - 000726528 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll
2018-06-13 13:29 - 2018-05-20 13:24 - 000625152 _____ (Microsoft Corporation) C:\WINDOWS\system32\PsmServiceExtHost.dll
2018-06-13 13:29 - 2018-05-20 13:24 - 000234496 _____ (Microsoft Corporation) C:\WINDOWS\system32\DolbyMATEnc.dll
2018-06-13 13:29 - 2018-05-20 13:23 - 013873152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2018-06-13 13:29 - 2018-05-20 13:23 - 005951488 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbgeng.dll
2018-06-13 13:29 - 2018-05-20 13:23 - 002366976 _____ (Microsoft Corporation) C:\WINDOWS\system32\WebRuntimeManager.dll
2018-06-13 13:29 - 2018-05-20 13:23 - 000933376 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasapi32.dll
2018-06-13 13:29 - 2018-05-20 13:23 - 000847360 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll
2018-06-13 13:29 - 2018-05-20 13:21 - 001371136 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadtb.dll
2018-06-13 13:29 - 2018-05-20 13:21 - 001303040 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.Vpn.dll
2018-06-13 13:29 - 2018-05-20 13:21 - 001210880 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnapps.dll
2018-06-13 13:29 - 2018-05-20 13:21 - 000960512 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll
2018-06-13 13:29 - 2018-05-20 13:21 - 000783360 _____ (Microsoft Corporation) C:\WINDOWS\system32\DolbyHrtfEnc.dll
2018-06-13 13:29 - 2018-05-20 13:17 - 002699776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll
2018-06-13 13:29 - 2018-05-20 13:16 - 006661120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
2018-06-13 13:29 - 2018-05-20 13:16 - 000094720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataTimeUtil.dll
2018-06-13 13:29 - 2018-05-20 13:16 - 000081920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ApiSetHost.AppExecutionAlias.dll
2018-06-13 13:29 - 2018-05-20 13:16 - 000002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tzres.dll
2018-06-13 13:29 - 2018-05-20 13:15 - 000142848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallServiceTasks.dll
2018-06-13 13:29 - 2018-05-20 13:15 - 000026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSHEIF.dll
2018-06-13 13:29 - 2018-05-20 13:14 - 001295360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVPXENC.dll
2018-06-13 13:29 - 2018-05-20 13:14 - 000167936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wevtutil.exe
2018-06-13 13:29 - 2018-05-20 13:13 - 004929024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbgeng.dll
2018-06-13 13:29 - 2018-05-20 13:13 - 000317440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Phoneutil.dll
2018-06-13 13:29 - 2018-05-20 13:12 - 000992768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.Vpn.dll
2018-06-13 13:29 - 2018-05-20 13:12 - 000860160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasapi32.dll
2018-06-13 13:29 - 2018-05-20 13:11 - 001036288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aadtb.dll
2018-06-13 13:29 - 2018-05-20 13:11 - 001005568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wpnapps.dll
2018-06-13 13:29 - 2018-05-20 10:26 - 000018716 _____ C:\WINDOWS\system32\srms-apr.dat
2018-06-13 13:29 - 2018-05-18 19:08 - 000018716 _____ C:\WINDOWS\SysWOW64\srms-apr.dat
2018-06-11 17:45 - 2018-06-11 17:45 - 000001579 _____ C:\Users\PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FirefoxPortable.lnk
2018-06-11 17:34 - 2018-06-11 17:34 - 000001238 _____ C:\Users\Public\Desktop\XSplit Broadcaster.lnk
2018-06-11 17:34 - 2018-06-11 17:34 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XSplit
2018-06-08 23:46 - 2018-06-08 23:46 - 000000165 ____H C:\Users\PC\Desktop\~$old accs.xlsx
2018-06-06 11:51 - 2018-06-24 03:37 - 000000000 ___HD C:\Users\PC\MicrosoftEdgeBackups
2018-05-25 07:16 - 2018-05-25 07:17 - 000000000 ____D C:\WINDOWS\system32\config\bbimigrate
2018-05-25 07:15 - 2018-05-25 07:16 - 000000000 ____D C:\WINDOWS\ServiceProfiles
2018-05-25 07:15 - 2018-05-25 07:15 - 000008192 _____ C:\WINDOWS\system32\config\userdiff
2018-05-25 07:14 - 2018-05-25 07:14 - 019525120 _____ (Microsoft Corporation) C:\WINDOWS\system32\HologramCompositor.dll
2018-05-25 07:14 - 2018-05-25 07:14 - 013570560 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll
2018-05-25 07:14 - 2018-05-25 07:14 - 012500992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll
2018-05-25 07:14 - 2018-05-25 07:14 - 008623104 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
2018-05-25 07:14 - 2018-05-25 07:14 - 007987712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll
2018-05-25 07:14 - 2018-05-25 07:14 - 003086336 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2018-05-25 07:14 - 2018-05-25 07:14 - 001953280 _____ C:\WINDOWS\system32\rdpnano.dll
2018-05-25 07:14 - 2018-05-25 07:14 - 001855488 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml3.dll
2018-05-25 07:14 - 2018-05-25 07:14 - 001585664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml3.dll
2018-05-25 07:14 - 2018-05-25 07:14 - 001565592 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxPackaging.dll
2018-05-25 07:14 - 2018-05-25 07:14 - 001534976 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2018-05-25 07:14 - 2018-05-25 07:14 - 001426328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxPackaging.dll
2018-05-25 07:14 - 2018-05-25 07:14 - 001421312 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpbase.dll
2018-05-25 07:14 - 2018-05-25 07:14 - 001380864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comsvcs.dll
2018-05-25 07:14 - 2018-05-25 07:14 - 001235968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpbase.dll
2018-05-25 07:14 - 2018-05-25 07:14 - 000917504 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2018-05-25 07:14 - 2018-05-25 07:14 - 000836608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2018-05-25 07:14 - 2018-05-25 07:14 - 000826776 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVClient.exe
2018-05-25 07:14 - 2018-05-25 07:14 - 000788216 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleaut32.dll
2018-05-25 07:14 - 2018-05-25 07:14 - 000776880 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll
2018-05-25 07:14 - 2018-05-25 07:14 - 000749976 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVReporting.dll
2018-05-25 07:14 - 2018-05-25 07:14 - 000695296 _____ (Microsoft Corporation) C:\WINDOWS\system32\hhctrl.ocx
2018-05-25 07:14 - 2018-05-25 07:14 - 000665320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wer.dll
2018-05-25 07:14 - 2018-05-25 07:14 - 000652184 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVPublishing.dll
2018-05-25 07:14 - 2018-05-25 07:14 - 000613376 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.rs4.dll
2018-05-25 07:14 - 2018-05-25 07:14 - 000606448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleaut32.dll
2018-05-25 07:14 - 2018-05-25 07:14 - 000604568 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe
2018-05-25 07:14 - 2018-05-25 07:14 - 000596480 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatehandlers.dll
2018-05-25 07:14 - 2018-05-25 07:14 - 000585728 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.rs3.dll
2018-05-25 07:14 - 2018-05-25 07:14 - 000581120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hhctrl.ocx
2018-05-25 07:14 - 2018-05-25 07:14 - 000561664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll
2018-05-25 07:14 - 2018-05-25 07:14 - 000553984 _____ (Microsoft Corporation) C:\WINDOWS\system32\PerceptionSimulationExtensions.dll
2018-05-25 07:14 - 2018-05-25 07:14 - 000543744 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2018-05-25 07:14 - 2018-05-25 07:14 - 000524800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2018-05-25 07:14 - 2018-05-25 07:14 - 000494488 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFault.exe
2018-05-25 07:14 - 2018-05-25 07:14 - 000474624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.rs2.dll
2018-05-25 07:14 - 2018-05-25 07:14 - 000473496 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcntel.dll
2018-05-25 07:14 - 2018-05-25 07:14 - 000444416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.rs1.dll
2018-05-25 07:14 - 2018-05-25 07:14 - 000434584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerFault.exe
2018-05-25 07:14 - 2018-05-25 07:14 - 000399768 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppVScripting.dll
2018-05-25 07:14 - 2018-05-25 07:14 - 000382872 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\clfs.sys
2018-05-25 07:14 - 2018-05-25 07:14 - 000288256 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.th.dll
2018-05-25 07:14 - 2018-05-25 07:14 - 000256000 _____ (Microsoft Corporation) C:\WINDOWS\system32\MixedReality.Broker.dll
2018-05-25 07:14 - 2018-05-25 07:14 - 000241664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.win81.dll
2018-05-25 07:14 - 2018-05-25 07:14 - 000171520 _____ (Microsoft Corporation) C:\WINDOWS\system32\itss.dll
2018-05-25 07:14 - 2018-05-25 07:14 - 000159744 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Cortana.Analog.dll
2018-05-25 07:14 - 2018-05-25 07:14 - 000150528 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedPCCSP.dll
2018-05-25 07:14 - 2018-05-25 07:14 - 000150016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\itss.dll
2018-05-25 07:14 - 2018-05-25 07:14 - 000144384 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssprxy.dll
2018-05-25 07:14 - 2018-05-25 07:14 - 000143360 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSpkg.dll
2018-05-25 07:14 - 2018-05-25 07:14 - 000142336 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.win8rtm.dll
2018-05-25 07:14 - 2018-05-25 07:14 - 000117760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TSpkg.dll
2018-05-25 07:14 - 2018-05-25 07:14 - 000046592 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcimage.dll
2018-05-25 07:14 - 2018-05-25 07:14 - 000023552 _____ (Microsoft Corporation) C:\WINDOWS\system32\credssp.dll
2018-05-25 07:14 - 2018-05-25 07:14 - 000019968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\credssp.dll
2018-05-25 07:13 - 2018-05-25 07:13 - 004492288 _____ (Microsoft Corporation) C:\WINDOWS\system32\xpsrchvw.exe
2018-05-25 07:13 - 2018-05-25 07:13 - 003398144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xpsrchvw.exe
2018-05-25 07:13 - 2018-05-25 07:13 - 001166520 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationNative_v0300.dll
2018-05-25 07:13 - 2018-05-25 07:13 - 000925696 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsFilt.dll
2018-05-25 07:13 - 2018-05-25 07:13 - 000778936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationNative_v0300.dll
2018-05-25 07:13 - 2018-05-25 07:13 - 000575488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsFilt.dll
2018-05-25 07:13 - 2018-05-25 07:13 - 000124624 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll
2018-05-25 07:13 - 2018-05-25 07:13 - 000103120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2018-05-25 07:13 - 2018-05-25 07:13 - 000100352 _____ (Microsoft Corporation) C:\WINDOWS\system32\XPSSHHDR.dll
2018-05-25 07:13 - 2018-05-25 07:13 - 000082432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XPSSHHDR.dll
2018-05-25 07:13 - 2018-05-25 07:13 - 000076060 _____ C:\WINDOWS\SysWOW64\xpsrchvw.xml
2018-05-25 07:13 - 2018-05-25 07:13 - 000076060 _____ C:\WINDOWS\system32\xpsrchvw.xml
2018-05-25 07:13 - 2018-05-25 07:13 - 000035456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TsWpfWrp.exe
2018-05-25 07:13 - 2018-05-25 07:13 - 000035456 _____ (Microsoft Corporation) C:\WINDOWS\system32\TsWpfWrp.exe
2018-05-25 07:13 - 2018-05-25 07:13 - 000000000 ____D C:\Program Files\Reference Assemblies
2018-05-25 07:13 - 2018-05-25 07:13 - 000000000 ____D C:\Program Files\MSBuild
2018-05-25 07:13 - 2018-05-25 07:13 - 000000000 ____D C:\Program Files (x86)\Reference Assemblies
2018-05-25 07:13 - 2018-05-25 07:13 - 000000000 ____D C:\Program Files (x86)\MSBuild
2018-05-25 00:02 - 2018-06-24 02:12 - 000000000 ____D C:\Users\PC\AppData\Local\D3DSCache

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2018-06-24 04:07 - 2017-10-09 13:52 - 000000000 ____D C:\Users\PC\AppData\Roaming\Skype
2018-06-24 03:48 - 2018-04-12 01:38 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2018-06-24 03:39 - 2017-10-09 12:20 - 000002260 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2018-06-24 03:34 - 2018-05-24 21:25 - 000838560 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2018-06-24 03:34 - 2018-04-12 01:36 - 000000000 ____D C:\WINDOWS\INF
2018-06-24 03:31 - 2018-01-29 23:20 - 000000000 ____D C:\Users\PC\AppData\Local\Mozilla
2018-06-24 03:28 - 2018-05-24 21:22 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2018-06-24 03:28 - 2018-04-12 01:38 - 000000000 ____D C:\WINDOWS\AppReadiness
2018-06-24 03:28 - 2018-01-17 07:07 - 000000000 __SHD C:\Users\PC\IntelGraphicsProfiles
2018-06-24 03:28 - 2017-10-09 13:54 - 000000000 ____D C:\ProgramData\NVIDIA
2018-06-24 03:27 - 2018-04-11 23:04 - 000786432 _____ C:\WINDOWS\system32\config\BBI
2018-06-24 02:29 - 2018-04-12 01:38 - 000000000 ___RD C:\Program Files\Windows Defender
2018-06-24 02:24 - 2018-01-17 23:50 - 000000000 ___RD C:\Users\PC\3D Objects
2018-06-24 02:24 - 2017-10-09 21:24 - 000000000 __RHD C:\Users\Public\AccountPictures
2018-06-24 02:23 - 2018-05-24 21:18 - 000403008 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2018-06-24 02:23 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\SysWOW64\zu-ZA
2018-06-24 02:23 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\SysWOW64\yo-NG
2018-06-24 02:23 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\SysWOW64\xh-ZA
2018-06-24 02:23 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\SysWOW64\wo-SN
2018-06-24 02:23 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\SysWOW64\uz-Latn-UZ
2018-06-24 02:23 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\SysWOW64\tn-ZA
2018-06-24 02:23 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\SysWOW64\ti-ET
2018-06-24 02:23 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\SysWOW64\tg-Cyrl-TJ
2018-06-24 02:23 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\SysWOW64\sr-Cyrl-RS
2018-06-24 02:23 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\SysWOW64\sr-Cyrl-BA
2018-06-24 02:23 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\SysWOW64\sd-Arab-PK
2018-06-24 02:23 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\SysWOW64\rw-RW
2018-06-24 02:23 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\SysWOW64\quc-Latn-GT
2018-06-24 02:23 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\SysWOW64\pa-Arab-PK
2018-06-24 02:23 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\SysWOW64\nso-ZA
2018-06-24 02:23 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\SysWOW64\ku-Arab-IQ
2018-06-24 02:23 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\SysWOW64\ig-NG
2018-06-24 02:23 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\SysWOW64\ha-Latn-NG
2018-06-24 02:23 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\SysWOW64\chr-CHER-US
2018-06-24 02:23 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\SysWOW64\ca-ES-valencia
2018-06-24 02:23 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\SysWOW64\bs-Latn-BA
2018-06-24 02:23 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\SysWOW64\az-Latn-AZ
2018-06-24 02:23 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\system32\zu-ZA
2018-06-24 02:23 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\system32\yo-NG
2018-06-24 02:23 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\system32\xh-ZA
2018-06-24 02:23 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\system32\wo-SN
2018-06-24 02:23 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\system32\uz-Latn-UZ
2018-06-24 02:23 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\system32\tn-ZA
2018-06-24 02:23 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\system32\ti-ET
2018-06-24 02:23 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\system32\tg-Cyrl-TJ
2018-06-24 02:23 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\system32\sr-Cyrl-RS
2018-06-24 02:23 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\system32\sr-Cyrl-BA
2018-06-24 02:23 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\system32\sd-Arab-PK
2018-06-24 02:23 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\system32\rw-RW
2018-06-24 02:23 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\system32\quc-Latn-GT
2018-06-24 02:23 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\system32\pa-Arab-PK
2018-06-24 02:23 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\system32\nso-ZA
2018-06-24 02:23 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\system32\ku-Arab-IQ
2018-06-24 02:23 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\system32\ig-NG
2018-06-24 02:23 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\system32\ha-Latn-NG
2018-06-24 02:23 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\system32\chr-CHER-US
2018-06-24 02:23 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\system32\ca-ES-valencia
2018-06-24 02:23 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\system32\bs-Latn-BA
2018-06-24 02:23 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\system32\az-Latn-AZ
2018-06-24 02:23 - 2018-04-12 01:38 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2018-06-24 02:23 - 2018-04-12 01:38 - 000000000 ____D C:\WINDOWS\TextInput
2018-06-24 02:23 - 2018-04-12 01:38 - 000000000 ____D C:\WINDOWS\SysWOW64\setup
2018-06-24 02:23 - 2018-04-12 01:38 - 000000000 ____D C:\WINDOWS\SysWOW64\oobe
2018-06-24 02:23 - 2018-04-12 01:38 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2018-06-24 02:23 - 2018-04-12 01:38 - 000000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2018-06-24 02:23 - 2018-04-12 01:38 - 000000000 ____D C:\WINDOWS\system32\SystemResetPlatform
2018-06-24 02:23 - 2018-04-12 01:38 - 000000000 ____D C:\WINDOWS\system32\setup
2018-06-24 02:23 - 2018-04-12 01:38 - 000000000 ____D C:\WINDOWS\system32\oobe
2018-06-24 02:23 - 2018-04-12 01:38 - 000000000 ____D C:\WINDOWS\system32\appraiser
2018-06-24 02:23 - 2018-04-12 01:38 - 000000000 ____D C:\WINDOWS\ShellExperiences
2018-06-24 02:23 - 2018-04-12 01:38 - 000000000 ____D C:\WINDOWS\bcastdvr
2018-06-24 02:23 - 2018-04-12 01:38 - 000000000 ____D C:\Program Files\Windows Photo Viewer
2018-06-24 02:23 - 2018-04-12 01:38 - 000000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2018-06-24 02:23 - 2018-04-11 23:04 - 000000000 ____D C:\WINDOWS\system32\Dism
2018-06-24 02:22 - 2018-05-24 21:19 - 000000000 ____D C:\Users\PC
2018-06-24 02:12 - 2017-10-09 12:20 - 000002307 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2018-06-24 02:12 - 2017-03-18 23:03 - 000000000 ___HD C:\WINDOWS\system32\GroupPolicy
2018-06-24 01:53 - 2018-01-18 06:52 - 000000000 ____D C:\Users\PC\Documents\ViberDownloads
2018-06-24 01:52 - 2018-05-24 21:18 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2018-06-24 01:04 - 2017-10-09 12:23 - 000000000 ____D C:\Program Files (x86)\Microsoft Office
2018-06-24 00:26 - 2018-01-17 16:36 - 000013473 _____ C:\Users\PC\Desktop\old accs.xlsx
2018-06-24 00:26 - 2017-10-09 13:51 - 000000000 ____D C:\ProgramData\Package Cache
2018-06-24 00:25 - 2018-05-09 23:40 - 000000000 ____D C:\Users\PC\AppData\Roaming\obs-studio
2018-06-24 00:21 - 2018-05-07 16:09 - 000000000 ____D C:\Users\PC\AppData\Local\UnrealEngine
2018-06-23 23:40 - 2018-01-17 16:35 - 000000000 ____D C:\Users\PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2018-06-23 06:00 - 2018-05-24 21:22 - 000003352 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-1124267341-3267589977-3522073591-1001
2018-06-23 06:00 - 2018-05-24 21:19 - 000002393 _____ C:\Users\PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2018-06-23 06:00 - 2017-10-09 12:18 - 000000000 ___RD C:\Users\PC\OneDrive
2018-06-21 14:06 - 2018-04-12 01:38 - 000000000 ___HD C:\Program Files\WindowsApps
2018-06-21 02:32 - 2018-01-18 06:52 - 000000000 ____D C:\Users\PC\AppData\Roaming\ViberPC
2018-06-21 00:04 - 2018-01-17 16:36 - 000104425 _____ C:\Users\PC\Desktop\paypal.xlsx
2018-06-20 00:09 - 2018-01-17 16:07 - 000000000 ____D C:\Users\PC\Desktop\Nepotrebno
2018-06-15 22:25 - 2018-01-17 23:45 - 000000000 ____D C:\Users\PC\AppData\Local\Packages
2018-06-13 13:31 - 2018-01-17 06:34 - 000000000 ____D C:\WINDOWS\system32\MRT
2018-06-13 13:30 - 2018-04-12 01:30 - 000000000 ____D C:\WINDOWS\CbsTemp
2018-06-13 13:30 - 2018-01-17 06:34 - 133315992 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT-KB890830.exe
2018-06-13 13:30 - 2018-01-17 06:34 - 133315992 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2018-06-11 17:45 - 2018-01-17 16:16 - 000001405 _____ C:\Users\PC\Desktop\FirefoxPortable.lnk
2018-06-08 05:22 - 2018-05-24 21:22 - 000004574 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player PPAPI Notifier
2018-06-08 05:22 - 2018-05-24 21:22 - 000004422 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2018-06-08 05:22 - 2018-04-12 01:38 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed
2018-06-08 05:22 - 2018-04-12 01:38 - 000000000 ____D C:\WINDOWS\system32\Macromed
2018-06-06 11:51 - 2017-10-09 13:54 - 000000000 ____D C:\Users\PC\AppData\Local\MicrosoftEdge
2018-06-06 01:29 - 2018-04-12 01:41 - 000835056 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2018-06-06 01:29 - 2018-04-12 01:41 - 000179704 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2018-05-30 21:32 - 2018-03-01 02:15 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2018-05-25 07:17 - 2018-05-21 01:28 - 000000000 ____D C:\ProgramData\regid.1995-08.com.techsmith
2018-05-25 07:17 - 2018-05-21 01:28 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TechSmith
2018-05-25 07:17 - 2018-05-09 23:40 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OBS Studio
2018-05-25 07:17 - 2018-04-12 01:41 - 000000000 ____D C:\WINDOWS\Setup
2018-05-25 07:17 - 2018-04-12 01:38 - 000028672 _____ C:\WINDOWS\system32\config\BCD-Template
2018-05-25 07:17 - 2018-04-12 01:38 - 000000000 __RHD C:\Users\Public\Libraries
2018-05-25 07:17 - 2018-04-12 01:38 - 000000000 ____D C:\WINDOWS\system32\WinBioDatabase
2018-05-25 07:17 - 2018-04-12 01:38 - 000000000 ____D C:\WINDOWS\system32\spool
2018-05-25 07:17 - 2018-04-12 01:38 - 000000000 ____D C:\WINDOWS\Help
2018-05-25 07:17 - 2018-04-12 01:38 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2018-05-25 07:17 - 2018-01-19 23:56 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
2018-05-25 07:17 - 2018-01-17 19:12 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lightshot
2018-05-25 07:17 - 2018-01-17 17:03 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Speccy
2018-05-25 07:17 - 2018-01-17 16:54 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BitPay
2018-05-25 07:17 - 2018-01-17 16:45 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kutools for Excel
2018-05-25 07:17 - 2018-01-17 16:40 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinHTTrack
2018-05-25 07:17 - 2018-01-17 16:18 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
2018-05-25 07:17 - 2018-01-17 16:07 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PhotoScape
2018-05-25 07:17 - 2018-01-17 07:07 - 000000000 ____D C:\Program Files\Intel
2018-05-25 07:17 - 2017-10-09 13:54 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2018-05-25 07:17 - 2017-10-09 13:53 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\K-Lite Codec Pack
2018-05-25 07:17 - 2017-10-09 13:52 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2018-05-25 07:17 - 2017-10-09 12:27 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2016 Tools
2018-05-25 07:17 - 2017-10-09 12:22 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2018-05-25 07:17 - 2017-09-29 15:46 - 000000000 ____D C:\WINDOWS\system32\Tasks_Migrated
2018-05-25 07:16 - 2018-03-20 01:13 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Genesis
2018-05-25 07:16 - 2018-01-17 16:40 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft
2018-05-25 07:16 - 2018-01-17 16:21 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung
2018-05-25 07:16 - 2018-01-17 06:20 - 000000000 ____D C:\Program Files\Realtek
2018-05-25 07:16 - 2017-10-09 13:59 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Unigine
2018-05-25 07:16 - 2017-10-09 13:56 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2018-05-25 07:16 - 2017-10-09 12:21 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Webteh
2018-05-25 07:14 - 2018-04-12 11:37 - 000000000 ____D C:\WINDOWS\Containers
2018-05-25 07:14 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\SysWOW64\vi-VN
2018-05-25 07:14 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\SysWOW64\ur-PK
2018-05-25 07:14 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\SysWOW64\ug-CN
2018-05-25 07:14 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\SysWOW64\tt-RU
2018-05-25 07:14 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\SysWOW64\tk-TM
2018-05-25 07:14 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\SysWOW64\te-IN
2018-05-25 07:14 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\SysWOW64\ta-IN
2018-05-25 07:14 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\SysWOW64\sw-KE
2018-05-25 07:14 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\SysWOW64\sq-AL
2018-05-25 07:14 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\SysWOW64\si-LK
2018-05-25 07:14 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\SysWOW64\quz-PE
2018-05-25 07:14 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\SysWOW64\prs-AF
2018-05-25 07:14 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\SysWOW64\pa-IN
2018-05-25 07:14 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\SysWOW64\or-IN
2018-05-25 07:14 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\SysWOW64\nn-NO
2018-05-25 07:14 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\SysWOW64\ne-NP
2018-05-25 07:14 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\SysWOW64\mt-MT
2018-05-25 07:14 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\SysWOW64\mr-IN
2018-05-25 07:14 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\SysWOW64\mn-MN
2018-05-25 07:14 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\SysWOW64\ml-IN
2018-05-25 07:14 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\SysWOW64\mk-MK
2018-05-25 07:14 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\SysWOW64\mi-NZ
2018-05-25 07:14 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\SysWOW64\lo-LA
2018-05-25 07:14 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\SysWOW64\lb-LU
2018-05-25 07:14 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\SysWOW64\ky-KG
2018-05-25 07:14 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\SysWOW64\kok-IN
2018-05-25 07:14 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\SysWOW64\kn-IN
2018-05-25 07:14 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\SysWOW64\km-KH
2018-05-25 07:14 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\SysWOW64\kk-KZ
2018-05-25 07:14 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\SysWOW64\ka-GE
2018-05-25 07:14 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\SysWOW64\is-IS
2018-05-25 07:14 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\SysWOW64\id-ID
2018-05-25 07:14 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\SysWOW64\hy-AM
2018-05-25 07:14 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\SysWOW64\gu-IN
2018-05-25 07:14 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\SysWOW64\gd-GB
2018-05-25 07:14 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\SysWOW64\ga-IE
2018-05-25 07:14 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\SysWOW64\fil-PH
2018-05-25 07:14 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\SysWOW64\fa-IR
2018-05-25 07:14 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\SysWOW64\cy-GB
2018-05-25 07:14 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\SysWOW64\bn-IN
2018-05-25 07:14 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\SysWOW64\bn-BD
2018-05-25 07:14 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\SysWOW64\be-BY
2018-05-25 07:14 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\SysWOW64\as-IN
2018-05-25 07:14 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\SysWOW64\am-ET
2018-05-25 07:14 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\SysWOW64\af-ZA
2018-05-25 07:14 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\system32\vi-VN
2018-05-25 07:14 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\system32\ur-PK
2018-05-25 07:14 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\system32\ug-CN
2018-05-25 07:14 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\system32\tt-RU
2018-05-25 07:14 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\system32\tk-TM
2018-05-25 07:14 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\system32\te-IN
2018-05-25 07:14 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\system32\sw-KE
2018-05-25 07:14 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\system32\sq-AL
2018-05-25 07:14 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\system32\quz-PE
2018-05-25 07:14 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\system32\prs-AF
2018-05-25 07:14 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\system32\pa-IN
2018-05-25 07:14 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\system32\or-IN
2018-05-25 07:14 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\system32\nn-NO
2018-05-25 07:14 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\system32\ne-NP
2018-05-25 07:14 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\system32\mt-MT
2018-05-25 07:14 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\system32\mr-IN
2018-05-25 07:14 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\system32\mn-MN
2018-05-25 07:14 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\system32\ml-IN
2018-05-25 07:14 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\system32\mk-MK
2018-05-25 07:14 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\system32\mi-NZ
2018-05-25 07:14 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\system32\lo-LA
2018-05-25 07:14 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\system32\lb-LU
2018-05-25 07:14 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\system32\ky-KG
2018-05-25 07:14 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\system32\kok-IN
2018-05-25 07:14 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\system32\kn-IN
2018-05-25 07:14 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\system32\km-KH
2018-05-25 07:14 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\system32\kk-KZ
2018-05-25 07:14 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\system32\ka-GE
2018-05-25 07:14 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\system32\is-IS
2018-05-25 07:14 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\system32\id-ID
2018-05-25 07:14 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\system32\hy-AM
2018-05-25 07:14 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\system32\gu-IN
2018-05-25 07:14 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\system32\gd-GB
2018-05-25 07:14 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\system32\ga-IE
2018-05-25 07:14 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\system32\fil-PH
2018-05-25 07:14 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\system32\fa-IR
2018-05-25 07:14 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\system32\cy-GB
2018-05-25 07:14 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\system32\bn-IN
2018-05-25 07:14 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\system32\bn-BD
2018-05-25 07:14 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\system32\be-BY
2018-05-25 07:14 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\system32\as-IN
2018-05-25 07:14 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\system32\af-ZA
2018-05-25 07:14 - 2018-04-12 01:38 - 000000000 ____D C:\WINDOWS\system32\ta-in
2018-05-25 07:14 - 2018-04-12 01:38 - 000000000 ____D C:\WINDOWS\system32\si-lk
2018-05-25 07:14 - 2018-04-12 01:38 - 000000000 ____D C:\WINDOWS\system32\am-et
2018-05-25 07:14 - 2018-04-12 01:38 - 000000000 ____D C:\WINDOWS\Provisioning
2018-05-25 07:13 - 2018-04-12 11:19 - 000000000 ____D C:\WINDOWS\OCR
2018-05-25 07:13 - 2018-04-12 01:38 - 000000000 ____D C:\WINDOWS\SysWOW64\lv-LV
2018-05-25 07:13 - 2018-04-12 01:38 - 000000000 ____D C:\WINDOWS\SysWOW64\lt-LT
2018-05-25 07:13 - 2018-04-12 01:38 - 000000000 ____D C:\WINDOWS\SysWOW64\et-EE
2018-05-25 07:13 - 2018-04-12 01:38 - 000000000 ____D C:\WINDOWS\SysWOW64\es-MX
2018-05-25 07:13 - 2018-04-12 01:38 - 000000000 ____D C:\WINDOWS\SysWOW64\en-GB
2018-05-25 07:13 - 2018-04-12 01:38 - 000000000 ____D C:\WINDOWS\system32\lv-LV
2018-05-25 07:13 - 2018-04-12 01:38 - 000000000 ____D C:\WINDOWS\system32\lt-LT
2018-05-25 07:13 - 2018-04-12 01:38 - 000000000 ____D C:\WINDOWS\system32\et-EE
2018-05-25 07:13 - 2018-04-12 01:38 - 000000000 ____D C:\WINDOWS\system32\es-MX
2018-05-25 07:13 - 2018-04-12 01:38 - 000000000 ____D C:\WINDOWS\system32\en-GB
2018-05-25 03:39 - 2018-04-12 01:38 - 000000000 ____D C:\WINDOWS\appcompat

==================== Files in the root of some directories =======

2017-11-20 16:08 - 2017-11-20 16:08 - 000000000 _____ () C:\Program Files (x86)\GUTEB5C.tmp
2018-06-16 21:18 - 2018-06-16 21:18 - 000000164 ____H () C:\Program Files\Common Files\restore_rev.bat
2018-06-24 02:12 - 2018-06-24 02:12 - 007629312 _____ () C:\Users\PC\AppData\Local\agent.dat
2018-06-24 02:12 - 2018-06-24 02:12 - 000278511 _____ () C:\Users\PC\AppData\Local\Ap-Kix.bin
2018-06-24 02:12 - 2018-06-24 02:12 - 000070896 _____ () C:\Users\PC\AppData\Local\Config.xml
2017-10-09 14:01 - 2018-01-18 23:59 - 001065984 _____ () C:\Users\PC\AppData\Local\file__0.localstorage
2018-06-24 02:12 - 2018-06-24 02:24 - 000016080 _____ () C:\Users\PC\AppData\Local\InstallationConfiguration.xml
2018-06-24 02:12 - 2018-06-24 02:12 - 000140800 _____ () C:\Users\PC\AppData\Local\installer.dat
2018-06-24 02:12 - 2018-06-24 02:12 - 000018432 _____ () C:\Users\PC\AppData\Local\Main.dat
2018-06-24 02:12 - 2018-06-24 02:12 - 000005568 _____ () C:\Users\PC\AppData\Local\md.xml
2018-06-24 02:12 - 2018-06-24 02:12 - 000126464 _____ () C:\Users\PC\AppData\Local\noah.dat
2018-06-24 02:12 - 2018-06-24 02:12 - 001810944 _____ (TODO: <Company name>) C:\Users\PC\AppData\Local\Ranity.exe
2018-06-24 02:12 - 2018-06-24 02:12 - 001988493 _____ () C:\Users\PC\AppData\Local\Ranity.tst
2018-06-24 02:12 - 2018-06-24 02:24 - 000929792 _____ () C:\Users\PC\AppData\Local\sham.db
2018-06-24 02:12 - 2018-06-24 02:12 - 000032038 _____ () C:\Users\PC\AppData\Local\uninstall_temp.ico
2018-01-17 19:12 - 2018-01-17 19:12 - 000000003 _____ () C:\Users\PC\AppData\Local\updater.log
2018-01-17 19:12 - 2018-01-17 19:12 - 000000425 _____ () C:\Users\PC\AppData\Local\UserProducts.xml
2018-06-24 02:12 - 2018-06-24 02:12 - 001895382 _____ () C:\Users\PC\AppData\Local\Xxx-lax.bin

Some files in TEMP:
====================
2018-06-24 00:21 - 2018-06-24 00:27 - 000000000 _____ () C:\Users\PC\AppData\Local\Temp\00e481b5e22dbe1f649fcddd505d3eb7.dll
2018-06-24 00:21 - 2018-06-24 00:27 - 000000017 _____ () C:\Users\PC\AppData\Local\Temp\ca99da99a7fd840fc9d5bcfb712cffd4.dll

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2018-05-24 21:18

==================== End of FRST.txt ============================


Additional scan result of Farbar Recovery Scan Tool (x64) Version: 20.06.2018
Ran by PC (24-06-2018 04:18:20)
Running from C:\Users\PC\Desktop
Windows 10 Enterprise Version 1803 17134.112 (X64) (2018-05-24 19:23:00)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-1124267341-3267589977-3522073591-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-1124267341-3267589977-3522073591-503 - Limited - Disabled)
Guest (S-1-5-21-1124267341-3267589977-3522073591-501 - Limited - Disabled)
PC (S-1-5-21-1124267341-3267589977-3522073591-1001 - Administrator - Enabled) => C:\Users\PC
WDAGUtilityAccount (S-1-5-21-1124267341-3267589977-3522073591-504 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

µTorrent (HKU\S-1-5-21-1124267341-3267589977-3522073591-1001\...\uTorrent) (Version: 3.5.1.44332 - BitTorrent Inc.)
7-Zip 17.01 beta (x64) (HKLM\...\7-Zip) (Version: 17.01 beta - Igor Pavlov)
Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 17.012.20093 - Adobe Systems Incorporated)
Adobe Flash Player 30 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 30.0.0.113 - Adobe Systems Incorporated)
Ansel (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Ansel) (Version: 384.94 - NVIDIA Corporation) Hidden
BitPay version 3.14.0 (HKLM-x32\...\2d1002d7-ee34-4f60-bd29-0c871ba0c195_is1) (Version: 3.14.0 - BitPay)
BS.Player PRO (HKLM-x32\...\BSPlayerp) (Version: 2.70.1080 - AB Team, d.o.o.)
Camtasia Studio 8 (HKLM-x32\...\{904AC0F0-F69E-467E-A719-B083940F608A}) (Version: 8.5.2.1999 - TechSmith Corporation)
Chrome Remote Desktop Host (HKLM-x32\...\{BB81EEBD-7942-4796-8556-0B84A6235C99}) (Version: 68.0.3440.11 - Google Inc.)
Delta 1.0.0 (only current user) (HKU\S-1-5-21-1124267341-3267589977-3522073591-1001\...\0161ecdc-2041-5655-9e4e-ee442fb322e0) (Version: 1.0.0 - Opus Labs NV)
Epic Games Launcher Prerequisites (x64) (HKLM\...\{66C5838F-B854-4A55-89E6-A6138747A4DF}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
Genesis GX69 Mouse Driver (HKLM-x32\...\{D63627FB-D99B-4A91-80EA-18558AE4788E}) (Version:  - )
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 67.0.3396.87 - Google Inc.)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.17 - Google Inc.) Hidden
Heaven Benchmark version 4.0 (HKLM-x32\...\Unigine Heaven Benchmark (Basic Edition)_is1) (Version: 4.0 - Unigine Corp.)
Intel® Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 23.20.16.4901 - Intel Corporation)
IrfanView 4.44 (64-bit) (HKLM\...\IrfanView64) (Version: 4.44 - Irfan Skiljan)
Java 9 (64-bit) (HKLM\...\{DA69628A-2608-5BA9-8749-1EE90CB29D95}) (Version: 9.0.0.0 - Oracle Corporation)
K-Lite Mega Codec Pack 13.5.5 (HKLM-x32\...\KLiteCodecPack_is1) (Version: 13.5.5 - KLCP)
Kutools for Excel 16.50 (HKLM-x32\...\{A095BA43-4A97-4D55-8E25-A0BC46F10765}_is1) (Version: 16.50 - Addin Technology Inc.)
Launcher Prerequisites (x64) (HKLM-x32\...\{c6c5a357-c7ca-4a5f-9789-3bb1af579253}) (Version: 1.0.0.0 - Epic Games, Inc.) Hidden
Lightshot-5.4.0.35 (HKLM-x32\...\{30A5B3C9-2084-4063-A32A-628A98DE512B}_is1) (Version: 5.4.0.35 - Skillbrains)
Microsoft Office Professional Plus 2016 - en-us (HKLM\...\ProPlusRetail - en-us) (Version: 16.0.9330.2124 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-1124267341-3267589977-3522073591-1001\...\OneDriveSetup.exe) (Version: 18.091.0506.0007 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2017 Redistributable (x64) - 14.10.25008 (HKLM-x32\...\{f1e7e313-06df-4c56-96a9-99fdfd149c51}) (Version: 14.10.25008.0 - Microsoft Corporation)
Microsoft Visual C++ 2017 Redistributable (x86) - 14.10.25008 (HKLM-x32\...\{c239cea1-d49e-4e16-8e87-8c055765f7ec}) (Version: 14.10.25008.0 - Microsoft Corporation)
Nitro Pro 10 (HKLM\...\{C78478E6-8206-470E-B843-0204995371C6}) (Version: 10.5.1.17 - Nitro)
NVIDIA 3D Vision Driver 384.94 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 384.94 - NVIDIA Corporation)
NVIDIA Graphics Driver 384.94 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 384.94 - NVIDIA Corporation)
NVIDIA HD Audio Driver 1.3.34.27 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.27 - NVIDIA Corporation)
OBS Studio (HKLM-x32\...\OBS Studio) (Version: 21.1.0 - OBS Project)
Office 16 Click-to-Run Extensibility Component (HKLM-x32\...\{90160000-008C-0000-0000-0000000FF1CE}) (Version: 16.0.9330.2124 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Extensibility Component 64-bit Registration (HKLM\...\{90160000-00DD-0000-1000-0000000FF1CE}) (Version: 16.0.9330.2124 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-008F-0000-1000-0000000FF1CE}) (Version: 16.0.9330.2124 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM-x32\...\{90160000-008C-0409-0000-0000000FF1CE}) (Version: 16.0.9330.2124 - Microsoft Corporation) Hidden
PhotoScape (HKLM-x32\...\PhotoScape) (Version:  - )
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.8228 - Realtek Semiconductor Corp.)
Samsung SideSync (HKLM-x32\...\Samsung SideSync) (Version: 4.7.5.235 - Samsung Electronics Co., Ltd.)
Samsung USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.63.0 - Samsung Electronics Co., Ltd.)
Skype™ 7.41 (HKLM-x32\...\{3B7E914A-93D5-4A29-92BB-AF8C3F66C431}) (Version: 7.41.101 - Skype Technologies S.A.)
Speccy (HKLM\...\Speccy) (Version: 1.31 - Piriform)
Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
Telegram Desktop version 1.3.7 (HKU\S-1-5-21-1124267341-3267589977-3522073591-1001\...\{53F49750-6209-4FBF-9CA8-7A333C87D1ED}_is1) (Version: 1.3.7 - Telegram Messenger LLP)
Update for Windows 10 for x64-based Systems (KB4023057) (HKLM\...\{1F3E59DD-7DCE-4103-9528-57DA43134312}) (Version: 2.9.0.0 - Microsoft Corporation)
Viber (HKLM-x32\...\{E24B538B-12B9-4C7B-AE61-3C8A8A95BB75}) (Version: 7.9.5.8 - Viber Media Inc.) Hidden
Viber (HKU\S-1-5-21-1124267341-3267589977-3522073591-1001\...\{d238ef1a-5d58-4630-88bd-a257a12084b3}) (Version: 7.9.5.8 - Viber Media Inc.)
Vulkan Run Time Libraries 1.0.42.1 (HKLM\...\VulkanRT1.0.42.1) (Version: 1.0.42.1 - LunarG, Inc.)
Vulkan Run Time Libraries 1.0.61.0 (HKLM\...\VulkanRT1.0.61.0) (Version: 1.0.61.0 - LunarG, Inc.) Hidden
Vulkan Run Time Libraries 1.0.61.0 (HKLM\...\VulkanRT1.0.61.0-2) (Version: 1.0.61.0 - LunarG, Inc.) Hidden
Vulkan Run Time Libraries 1.0.61.0 (HKLM\...\VulkanRT1.0.61.0-3) (Version: 1.0.61.0 - LunarG, Inc.) Hidden
WhatsApp (HKU\S-1-5-21-1124267341-3267589977-3522073591-1001\...\WhatsApp) (Version: 0.2.8505 - WhatsApp)
WinHTTrack Website Copier 3.49-2 (x64) (HKLM\...\WinHTTrack Website Copier_is1) (Version: 3.49.2 - HTTrack)
WinRAR 5.50 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.50.0 - win.rar GmbH)
Winrar Activator version 1.2 (HKLM-x32\...\{AE0B3F2A-EB65-4D01-A3E1-6D879C6AAF2A}_is1) (Version: 1.2 - Rarlab)
XSplit Broadcaster (HKLM-x32\...\{481300DD-9FB3-48F5-908A-35CB27C5C501}) (Version: 3.3.1805.0302 - SplitmediaLabs)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  -> No File
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2017-08-28] (Igor Pavlov)
ContextMenuHandlers1: [NP8ShellExtension] -> {9C4B85B8-956C-49BF-9BA5-101384E562B2} => C:\Program Files\Nitro\Pro 10\NPShellExtension.dll [2015-05-06] (Nitro PDF)
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2017-08-12] (Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2017-08-12] (Alexander Roshal)
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2017-08-28] (Igor Pavlov)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} =>  -> No File
ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\WINDOWS\System32\DriverStore\FileRepository\igdlh64.inf_amd64_daa5fd44d52a5762\igfxDTCM.dll [2018-01-03] (Intel Corporation)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\WINDOWS\system32\nvshext.dll [2017-07-19] (NVIDIA Corporation)
ContextMenuHandlers6: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2017-08-28] (Igor Pavlov)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2017-08-12] (Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2017-08-12] (Alexander Roshal)

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {1581A11A-3EBC-4B1F-BB4F-D68A81122481} - System32\Tasks\ThePake => C:\WINDOWS\system32\rundll32.exe "C:\Program Files\ThePake\ThePake.dll",qCclkRLrhW <==== ATTENTION
Task: {292D0B9E-43FA-4E91-92AE-1AEDF03BE33B} - System32\Tasks\MainPMgr => powershell -ExecutionPolicy ByPass -File pm.ps1
Task: {58373BBA-DC0C-4DEA-BD63-C079E4B613C9} - System32\Tasks\JavaUpdateSched => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2017-08-03] (Oracle Corporation)
Task: {623D48D9-157E-4185-9E56-786B6B3008AA} - System32\Tasks\RestoreRevTask => C:\Program Files\Common Files\restore_rev.bat [2018-06-16] () <==== ATTENTION
Task: {65B85F6F-35B3-4459-A179-28255D5B7B25} - System32\Tasks\Microsoft\Windows\HelloFace\FODCleanupTask => C:\WINDOWS\System32\WinBioPlugIns\FaceFodUninstaller.exe [2018-04-12] ()
Task: {6A87BBDA-50A5-4697-AA36-CE4C24D7FDDB} - System32\Tasks\update-S-1-5-21-1124267341-3267589977-3522073591-1001 => C:\Program Files (x86)\Skillbrains\Updater\Updater.exe [2017-04-12] (TODO: <Company name>)
Task: {70E079D2-68AA-43B2-873E-AE5AA0E0E672} - System32\Tasks\S-1-5-21-1124267341-3267589977-3522073591-1001\DataSenseLiveTileTask => C:\WINDOWS\System32\DataUsageLiveTileTask.exe [2018-04-12] (Microsoft Corporation)
Task: {80E1BA5F-E7EC-46AE-97AF-880456E25604} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2018-06-12] (Microsoft Corporation)
Task: {8A154FBB-3202-4167-8D5A-0D64DD0FC789} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2018-06-08] (Adobe Systems Incorporated)
Task: {91A74A30-7B76-423F-8595-B58C7F1EFE8C} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashUtil32_30_0_0_113_pepper.exe [2018-06-08] (Adobe Systems Incorporated)
Task: {91F8B013-4D72-465F-ADB6-5899B920F962} - System32\Tasks\ThePake-dll => C:\WINDOWS\system32\rundll32.exe "C:\Program Files\ThePake\ThePake.dll",qCclkRLrhW
Task: {92D555A0-9229-42CA-BA74-BB1A695FAA8A} - System32\Tasks\Microsoft\Office\OfficeOsfInstaller => C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX86\Microsoft Shared\Office16\osfinstaller.exe [2018-06-17] (Microsoft Corporation)
Task: {9574EB88-B82B-48CB-9CCC-32E3870128ED} - System32\Tasks\KMSAutoNet => C:\ProgramData\KMSAutoS\KMSAuto Net.exe [2017-06-24] (MSFree Inc.)
Task: {99230EBF-E981-4A9B-A5A1-AD43A5ED487D} - System32\Tasks\Update_4.0.10 => C:\Program Files\SystemaRev\RevServicesX\SystemUpdate64x.exe
Task: {998BCCF7-10E3-4283-BD1D-9F69D45B1184} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-10-09] (Google Inc.)
Task: {A9A73D32-1DF7-44F7-B837-64068C48B490} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2018-02-09] (Adobe Systems Incorporated)
Task: {B74A0E32-AD8B-460B-9DE2-7449D70784BC} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerRegistration => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2018-06-17] (Microsoft Corporation)
Task: {C1CBE3B3-186E-4D9E-9F7C-8E9F579812B0} - System32\Tasks\PPI Update => C:\WINDOWS\explorer.exe "hxxp://windowsdefender.club/warning/download.php?mn=5623" <==== ATTENTION
Task: {C2BC616C-8A09-4629-B50A-1407BA457A30} - System32\Tasks\update-sys => C:\Program Files (x86)\Skillbrains\Updater\Updater.exe [2017-04-12] (TODO: <Company name>)
Task: {C4F113B5-6F41-40BE-9C78-2C945E9E7E32} - System32\Tasks\Accent Online Paintings 2007 => C:\WINDOWS\system32\rundll32.exe "C:\Program Files\Accent Online Paintings 2007\Accent Online Paintings 2007.dll",kTiiGdcCqPyt <==== ATTENTION
Task: {CD2B1877-6913-420B-935F-33C61E1107EF} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2018-06-12] (Microsoft Corporation)
Task: {D1D81221-D914-4882-9A10-453FCDDB0075} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2018-06-17] (Microsoft Corporation)
Task: {D2AB7D2F-0E16-4767-A978-A55C3B043760} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-10-09] (Google Inc.)
Task: {D67E0FE2-21D7-4ADB-A2D8-857FECAB998C} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerLogon => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2018-06-17] (Microsoft Corporation)
Task: {F66265F1-88E6-4A90-9DB2-C6496A4F6D46} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2018-06-17] (Microsoft Corporation)
Task: {FE1ADAD0-25E8-44FB-AFC6-1D9FB43D285E} - System32\Tasks\Microsoft\Windows\SoftwareProtectionPlatform\SvcTrigger

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\WINDOWS\Tasks\update-S-1-5-21-1124267341-3267589977-3522073591-1001.job => C:\Program Files (x86)\Skillbrains\Updater\Updater.exe
Task: C:\WINDOWS\Tasks\update-sys.job => C:\Program Files (x86)\Skillbrains\Updater\Updater.exe

==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)


ShortcutWithArgument: C:\Users\PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Authy.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) ->  --profile-directory=Default --app-id=gaedmjdfmmahhbjefcbgaolhhanlaolb
ShortcutWithArgument: C:\Users\PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Chrome Remote Desktop.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) ->  --profile-directory=Default --app-id=gbchcmhmhahfdphkhkmpfmihenigjmpp
ShortcutWithArgument: C:\Users\PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Ledger Manager.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) ->  --profile-directory=Default --app-id=beimhnaefocolcplfimocfiaiefpkgbf
ShortcutWithArgument: C:\Users\PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Ledger Wallet Ethereum.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) ->  --profile-directory=Default --app-id=hmlhkialjkaldndjnlcdfdphcgeadkkm
ShortcutWithArgument: C:\Users\PC\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> %SNP%
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> %SNP%

==================== Loaded Modules (Whitelisted) ==============

2015-05-06 05:23 - 2015-05-06 05:23 - 000418968 _____ () c:\program files\nitro\pro 10\nitro_updateservice.exe
2015-05-06 05:23 - 2015-05-06 05:23 - 002543768 _____ () c:\program files\nitro\pro 10\Nitro_KissMetrics.dll
2018-04-12 01:34 - 2018-04-12 01:34 - 000491744 _____ () C:\WINDOWS\SYSTEM32\inputhost.dll
2018-04-12 01:34 - 2018-04-12 01:34 - 000472064 _____ () C:\Windows\ShellExperiences\TileControl.dll
2018-04-12 01:34 - 2018-04-12 01:34 - 002759168 _____ () C:\Windows\ShellComponents\TaskFlowUI.dll
2018-06-13 13:29 - 2018-06-08 10:56 - 002185216 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2018-05-26 23:24 - 2018-05-26 23:24 - 027118080 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.18041.14611.0_x64__8wekyb3d8bbwe\Video.UI.exe
2018-05-26 23:24 - 2018-05-26 23:24 - 000306176 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.18041.14611.0_x64__8wekyb3d8bbwe\SharedUI.dll
2018-05-26 23:24 - 2018-05-26 23:24 - 006748672 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.18041.14611.0_x64__8wekyb3d8bbwe\EntCommon.dll
2018-01-17 06:47 - 2018-01-17 06:48 - 003553704 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.18041.14611.0_x64__8wekyb3d8bbwe\Microsoft.UI.Xaml.dll
2018-05-26 23:24 - 2018-05-26 23:24 - 009358848 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.18041.14611.0_x64__8wekyb3d8bbwe\EntPlat.dll
2018-05-22 21:25 - 2018-05-22 21:26 - 000086528 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.209.0_x64__kzf8qxf38zg5c\SkypeHost.exe
2018-05-22 21:25 - 2018-05-22 21:26 - 000195072 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.209.0_x64__kzf8qxf38zg5c\SkypeBackgroundTasks.dll
2018-05-22 21:25 - 2018-05-22 21:26 - 022374400 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.209.0_x64__kzf8qxf38zg5c\SkyWrap.dll
2018-05-22 21:25 - 2018-05-22 21:26 - 002610176 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.209.0_x64__kzf8qxf38zg5c\skypert.dll
2018-05-22 21:25 - 2018-05-22 21:25 - 000654848 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.1815.209.0_x64__kzf8qxf38zg5c\RtmMvrUap.dll
2018-03-20 01:13 - 2015-10-08 11:01 - 000495616 _____ () C:\Program Files (x86)\Genesis\GX69 Mouse\Monitor.exe
2018-04-12 01:34 - 2018-04-12 01:34 - 005471232 _____ () C:\Windows\SystemApps\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\SecHealthUIDataModel.dll
2018-04-12 01:34 - 2018-04-12 01:34 - 000047616 _____ () C:\Windows\SystemApps\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\SecHealthUITelemetry.dll
2018-06-13 13:29 - 2018-05-20 13:22 - 005082112 _____ () C:\Windows\SystemApps\Microsoft.Windows.SecHealthUI_cw5n1h2txyewy\SecHealthUIViewModels.dll
2018-06-24 02:12 - 2015-06-01 19:58 - 004956160 _____ () C:\Program Files\Accent Online Paintings 2007\Accent Online Paintings 2007.dll
2018-06-24 02:57 - 2018-06-24 03:28 - 000972288 _____ () C:\WINDOWS\TEMP\g2268.tmp.exe
2017-09-27 07:22 - 2017-09-27 07:22 - 001984000 ____R () C:\Program Files (x86)\Skype\Phone\skypert.dll
2018-03-20 01:13 - 2012-06-09 08:38 - 000057344 _____ () C:\Program Files (x86)\Genesis\GX69 Mouse\lan.dll
2018-03-20 01:13 - 2012-09-13 13:34 - 000061440 _____ () C:\Program Files (x86)\Genesis\GX69 Mouse\hiddriver.dll
2018-06-24 03:31 - 2018-06-24 03:31 - 000011776 _____ () C:\Users\PC\AppData\Local\Temp\nswD6E0.tmp\System.dll
2018-06-24 03:31 - 2018-06-24 03:31 - 000029696 _____ () C:\Users\PC\AppData\Local\Temp\nswD6E0.tmp\registry.dll
2018-06-24 03:31 - 2018-06-24 03:31 - 000008704 _____ () C:\Users\PC\AppData\Local\Temp\nswD6E0.tmp\newadvsplash.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)

IE trusted site: HKU\S-1-5-21-1124267341-3267589977-3522073591-1001\...\localhost -> localhost
IE trusted site: HKU\S-1-5-21-1124267341-3267589977-3522073591-1001\...\webcompanion.com -> hxxp://webcompanion.com

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2017-03-18 23:03 - 2018-06-24 02:57 - 000009256 _____ C:\WINDOWS\system32\Drivers\etc\hosts

127.0.0.1    gf.tools.avast.com
127.0.0.1    pair.ff.avast.com
127.0.0.1    ipm-provider.ff.avast.com
127.0.0.1    ipm-provider.ff.avast.com
127.0.0.1    ipm-provider.ff.avast.com
127.0.0.1    id.avast.com
127.0.0.1    s5355946.iavs9x.u.avast.com
127.0.0.1    s5355946.ivps9x.u.avast.com
127.0.0.1    s5355946.ivps9tiny.u.avast.com
127.0.0.1    s5355946.vpsnitro.u.avast.com
127.0.0.1    s5355946.vpsnitrotiny.u.avast.com
127.0.0.1    s5355946.iavs5x.u.avast.com
127.0.0.1    v7.stats.avast.com
127.0.0.1    v7.stats.avast.com
127.0.0.1    v7event.stats.avast.com
127.0.0.1    sm00.avast.com
127.0.0.1    submit5.avast.com
127.0.0.1    geoip.avast.com
127.0.0.1    l2932126.iavs9x.u.avast.com
127.0.0.1    l2932126.ivps9x.u.avast.com
127.0.0.1    l2932126.ivps9tiny.u.avast.com
127.0.0.1    l2932126.vpsnitro.u.avast.com
127.0.0.1    l2932126.vpsnitrotiny.u.avast.com
127.0.0.1    l2932126.iavs5x.u.avast.com
127.0.0.1    v7.stats.avast.com
127.0.0.1    v7.stats.avast.com
127.0.0.1    v7event.stats.avast.com
127.0.0.1    sm00.avast.com
127.0.0.1    submit5.avast.com
127.0.0.1    geoip.avast.com

There are 211 more lines.


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-1124267341-3267589977-3522073591-1001\Control Panel\Desktop\\Wallpaper -> d:\net job\wallpapers\dark_background_line_surface_65896_1920x1080.jpg
DNS Servers: 77.77.192.20 - 94.140.66.194
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: )
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

HKLM\...\StartupApproved\Run: => "SecurityHealth"
HKLM\...\StartupApproved\Run: => "HotKeysCmds"
HKLM\...\StartupApproved\Run: => "IgfxTray"
HKLM\...\StartupApproved\Run: => "Persistence"
HKLM\...\StartupApproved\Run32: => "SunJavaUpdateSched"
HKU\S-1-5-21-1124267341-3267589977-3522073591-1001\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-1124267341-3267589977-3522073591-1001\...\StartupApproved\Run: => "Steam"
HKU\S-1-5-21-1124267341-3267589977-3522073591-1001\...\StartupApproved\Run: => "Viber"

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{4C791528-4583-45B7-86D8-2560C1456E80}] => (Allow) LPort=8317
FirewallRules: [UDP Query User{072F0464-7403-4EC4-9097-24BE3CCC8802}D:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) D:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe
FirewallRules: [TCP Query User{8AE0F7FC-9B3A-4655-9037-275A5FE1649B}D:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe] => (Allow) D:\program files (x86)\epic games\launcher\portal\binaries\win64\epicgameslauncher.exe
FirewallRules: [UDP Query User{AB7D41F0-9103-4422-92CD-2F7564F249BB}D:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe] => (Allow) D:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe
FirewallRules: [TCP Query User{0140B29F-0F2E-4C8C-BC1D-4D70E16CC80E}D:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe] => (Allow) D:\program files (x86)\epic games\launcher\portal\binaries\win32\epicgameslauncher.exe
FirewallRules: [{6B1FD013-965B-477B-B8C9-55AA7FB5BF0C}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe
FirewallRules: [{5619D889-73F2-4B51-9B24-8B6B2520DA20}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe
FirewallRules: [{32C1F708-BAD5-437D-BA70-8FA99365BA77}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe
FirewallRules: [{149DF902-D5D9-42F7-9356-19FC98F9C7B6}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe
FirewallRules: [UDP Query User{1794F392-8C9D-4A08-BA49-1CAB1E989E9F}D:\program files (x86)\steam\steamapps\common\insurgency2\insurgency.exe] => (Allow) D:\program files (x86)\steam\steamapps\common\insurgency2\insurgency.exe
FirewallRules: [TCP Query User{40A88D4F-7A5E-4FA4-B9C3-40DC3B8AFB0C}D:\program files (x86)\steam\steamapps\common\insurgency2\insurgency.exe] => (Allow) D:\program files (x86)\steam\steamapps\common\insurgency2\insurgency.exe
FirewallRules: [{0FCFEBDE-5FC5-4E51-839B-D69BBA55BD47}] => (Allow) D:\Program Files (x86)\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe
FirewallRules: [{117EA259-4903-4512-9609-CE46A934F017}] => (Allow) D:\Program Files (x86)\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe
FirewallRules: [{142F733C-C137-4396-A97B-AFB7DB01DE62}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe
FirewallRules: [UDP Query User{20E7CA27-2E84-4FEF-8FBB-E7A5A7D94E40}D:\program files (x86)\samsung\sidesync4\sidesync.exe] => (Allow) D:\program files (x86)\samsung\sidesync4\sidesync.exe
FirewallRules: [TCP Query User{BD0B0BBD-3BA8-472E-A446-21FA9E48225A}D:\program files (x86)\samsung\sidesync4\sidesync.exe] => (Allow) D:\program files (x86)\samsung\sidesync4\sidesync.exe
FirewallRules: [{181D16D4-C2CF-4E56-9994-BF8AD8EA178F}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{8F6D5D4A-F775-459F-87AF-21CB5DB738B1}] => (Allow) D:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{A6827CD7-A18D-424D-A750-02CF9117D125}] => (Allow) D:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{27EE0733-3EA7-4E32-BA28-83F046001F17}] => (Allow) D:\Program Files (x86)\Samsung\SideSync4\SideSync.exe
FirewallRules: [{CE428D6E-F0FC-4208-9BB9-A270B83110BD}] => (Allow) D:\Program Files (x86)\Samsung\SideSync4\SideSync.exe
FirewallRules: [{8154A17D-08E7-4DAA-AD3B-1206A2C829E1}] => (Allow) D:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [{106961F4-DD6E-4617-80EA-81AB6EEA1DBD}] => (Allow) D:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [{C979E3CD-574D-4B4E-AD5B-A31D29E3F63A}] => (Allow) C:\Users\PC\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{A0A6BC7B-A7F4-45B3-8EC2-BF459E329421}] => (Allow) C:\Users\PC\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{BB6A3096-081B-491A-A9D6-969ED3954379}] => (Allow) D:\Program Files (x86)\Steam\steamapps\common\insurgency2\insurgency_BE.exe
FirewallRules: [{30B9A295-ECCD-43CC-91E8-9144C0E34492}] => (Allow) D:\Program Files (x86)\Steam\steamapps\common\insurgency2\insurgency_BE.exe
FirewallRules: [{998FBCA3-A6AB-4918-B805-6653DFCD0137}] => (Allow) C:\Program Files (x86)\SplitmediaLabs\XSplit Broadcaster\x64\XSplit.Core.exe
FirewallRules: [{E0832D43-C4C4-4863-8F5F-543FC1A005EC}] => (Allow) C:\Program Files (x86)\SplitmediaLabs\XSplit Broadcaster\x64\XSplit.cam.exe
FirewallRules: [{D8D80334-434A-4CCA-99B1-EAE9E80CEF7E}] => (Allow) C:\Program Files (x86)\SplitmediaLabs\XSplit Broadcaster\x64\XSplit.Core.exe
FirewallRules: [{5543E4A2-6245-4D47-AE8D-E778B792A447}] => (Allow) C:\Program Files (x86)\SplitmediaLabs\XSplit Broadcaster\x64\XSplit.cam.exe
FirewallRules: [{C013C6CA-CF75-4659-A825-120195343208}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{B2F24A06-D058-4D45-A99A-F3DA32DC064A}] => (Allow) C:\Program Files (x86)\Google\Chrome Remote Desktop\68.0.3440.11\remoting_host.exe
FirewallRules: [{E61A2464-E62F-40FB-B38C-DFB8A79DF6DA}] => (Allow) D:\Program Files (x86)\Steam\steamapps\common\PUBG\TslGame\Binaries\Win64\TslGame_BE.exe
FirewallRules: [{A60038E2-07F1-45DC-AC18-E785DC0C2405}] => (Allow) D:\Program Files (x86)\Steam\steamapps\common\PUBG\TslGame\Binaries\Win64\TslGame_BE.exe
FirewallRules: [TCP Query User{26ECA247-65EF-4026-8B31-0752DBA9D18F}D:\program files (x86)\steam\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe] => (Allow) D:\program files (x86)\steam\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe
FirewallRules: [UDP Query User{6BF0AE90-84B1-4BC7-A845-342C894ADF0A}D:\program files (x86)\steam\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe] => (Allow) D:\program files (x86)\steam\steamapps\common\pubg\tslgame\binaries\win64\tslgame.exe
FirewallRules: [{A9418D03-AA22-474C-BA90-379B00D03323}] => (Allow) C:\WINDOWS\system32\rundll32.exe
FirewallRules: [{F2723361-14BA-4AC3-ABFE-611D4A5D093A}] => (Allow) C:\Windows\System32\rundll32.exe
FirewallRules: [{D374EE8D-FF28-458C-BEAB-8332CB3407EA}] => (Allow) C:\Windows\System32\rundll32.exe

==================== Restore Points =========================

08-06-2018 20:04:57 Windows Update
11-06-2018 17:34:26 Installed XSplit Broadcaster
24-06-2018 00:20:48 Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215
24-06-2018 00:20:55 Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24215

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (06/24/2018 04:00:50 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: g79F2.tmp.exe, version: 0.0.0.0, time stamp: 0x5b00c9dc
Faulting module name: g79F2.tmp.exe, version: 0.0.0.0, time stamp: 0x5b00c9dc
Exception code: 0xc0000409
Fault offset: 0x000000000000686c
Faulting process id: 0x28f4
Faulting application start time: 0x01d40b5f185e981c
Faulting application path: C:\WINDOWS\TEMP\g79F2.tmp.exe
Faulting module path: C:\WINDOWS\TEMP\g79F2.tmp.exe
Report Id: b5487947-48c2-4341-acc2-67cd5bb954be
Faulting package full name:
Faulting package-relative application ID:

Error: (06/24/2018 03:29:17 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: g79F2.tmp.exe, version: 0.0.0.0, time stamp: 0x5b00c9dc
Faulting module name: g79F2.tmp.exe, version: 0.0.0.0, time stamp: 0x5b00c9dc
Exception code: 0xc0000409
Fault offset: 0x000000000000686c
Faulting process id: 0x2bdc
Faulting application start time: 0x01d40b5aaf7f8c97
Faulting application path: C:\WINDOWS\TEMP\g79F2.tmp.exe
Faulting module path: C:\WINDOWS\TEMP\g79F2.tmp.exe
Report Id: 26af8c39-a224-4581-8a74-63de8fe0df00
Faulting package full name:
Faulting package-relative application ID:

Error: (06/24/2018 03:28:38 AM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: License Activation (slui.exe) failed with the following error code:
hr=0x8007007B
Command-line arguments:
RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=73111121-5638-40f6-bc11-f1d7b0d64300;NotificationInterval=1440;Trigger=NetworkAvailable

Error: (06/24/2018 03:28:38 AM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: License Activation (slui.exe) failed with the following error code:
hr=0x8007007B
Command-line arguments:
RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=73111121-5638-40f6-bc11-f1d7b0d64300;NotificationInterval=1440;Trigger=UserLogon;SessionId=1

Error: (06/24/2018 03:28:29 AM) (Source: SideBySide) (EventID: 78) (User: )
Description: Activation context generation failed for "D:\Program Files (x86)\Samsung\SideSync4\SideSync.exe".Error in manifest or policy file "" on line .
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17134.112_none_fb3f961b30681c12.manifest.
Component 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.17134.112_none_42ecccf244e44518.manifest.

Error: (06/24/2018 02:57:32 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: g79F2.tmp.exe, version: 0.0.0.0, time stamp: 0x5b00c9dc
Faulting module name: g79F2.tmp.exe, version: 0.0.0.0, time stamp: 0x5b00c9dc
Exception code: 0xc0000409
Fault offset: 0x000000000000686c
Faulting process id: 0x2aac
Faulting application start time: 0x01d40b56402ef8d7
Faulting application path: C:\WINDOWS\TEMP\g79F2.tmp.exe
Faulting module path: C:\WINDOWS\TEMP\g79F2.tmp.exe
Report Id: f1ddec3b-0e58-45f7-995b-16899c5c4e55
Faulting package full name:
Faulting package-relative application ID:

Error: (06/24/2018 02:56:50 AM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: License Activation (slui.exe) failed with the following error code:
hr=0x8007007B
Command-line arguments:
RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=73111121-5638-40f6-bc11-f1d7b0d64300;NotificationInterval=1440;Trigger=UserLogon;SessionId=1

Error: (06/24/2018 02:56:49 AM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: License Activation (slui.exe) failed with the following error code:
hr=0x8007007B
Command-line arguments:
RuleId=502ff3ba-669a-4674-bbb1-601f34a3b968;Action=AutoActivateSilent;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=73111121-5638-40f6-bc11-f1d7b0d64300;NotificationInterval=1440;Trigger=UserLogon;SessionId=1


System errors:
=============
Error: (06/24/2018 03:41:49 AM) (Source: DCOM) (EventID: 10016) (User: ARMIN)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 and APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 to the user ARMIN\PC SID (S-1-5-21-1124267341-3267589977-3522073591-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Error: (06/24/2018 03:41:38 AM) (Source: DCOM) (EventID: 10016) (User: ARMIN)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 and APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 to the user ARMIN\PC SID (S-1-5-21-1124267341-3267589977-3522073591-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Error: (06/24/2018 03:41:23 AM) (Source: DCOM) (EventID: 10016) (User: ARMIN)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 and APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 to the user ARMIN\PC SID (S-1-5-21-1124267341-3267589977-3522073591-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Error: (06/24/2018 03:41:04 AM) (Source: DCOM) (EventID: 10016) (User: ARMIN)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 and APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 to the user ARMIN\PC SID (S-1-5-21-1124267341-3267589977-3522073591-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Error: (06/24/2018 03:40:54 AM) (Source: DCOM) (EventID: 10016) (User: ARMIN)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 and APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 to the user ARMIN\PC SID (S-1-5-21-1124267341-3267589977-3522073591-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Error: (06/24/2018 03:40:49 AM) (Source: DCOM) (EventID: 10016) (User: ARMIN)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 and APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 to the user ARMIN\PC SID (S-1-5-21-1124267341-3267589977-3522073591-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Error: (06/24/2018 03:40:03 AM) (Source: DCOM) (EventID: 10016) (User: ARMIN)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 and APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 to the user ARMIN\PC SID (S-1-5-21-1124267341-3267589977-3522073591-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Error: (06/24/2018 03:39:50 AM) (Source: DCOM) (EventID: 10016) (User: ARMIN)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 and APPID
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 to the user ARMIN\PC SID (S-1-5-21-1124267341-3267589977-3522073591-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.


Windows Defender:
===================================
Date: 2018-06-24 03:32:50.080
Description:
Windows Defender Antivirus has detected malware or other potentially unwanted software.
For more information please see the following:
https://go.microsoft.com/fwlink/?linkid=37020&name=Trojan:Win32/Occamy.C&threatid=2147726780&enterprise=0
Name: Trojan:Win32/Occamy.C
ID: 2147726780
Severity: Severe
Category: Trojan
Path: file:_C:\Program Files\SystemaRev\RevServicesX\app.exe
Detection Origin: Local machine
Detection Type: FastPath
Detection Source: User
Process Name: Unknown
Signature Version: AV: 1.269.1851.0, AS: 1.269.1851.0, NIS: 1.269.1851.0
Engine Version: AM: 1.1.14901.4, NIS: 1.1.14901.4

Date: 2018-06-24 03:32:49.705
Description:
Windows Defender Antivirus has detected malware or other potentially unwanted software.
For more information please see the following:
https://go.microsoft.com/fwlink/?linkid=37020&name=Trojan:Win32/Occamy.C&threatid=2147726780&enterprise=0
Name: Trojan:Win32/Occamy.C
ID: 2147726780
Severity: Severe
Category: Trojan
Path: file:_C:\Program Files\SystemaRev\RevServicesX\app.exe;process:_pid:13280,ProcessStart:131742773318469075;regkey:_HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\\JServicesManager;regkey:_HKLM\SOFTWARE\Wow6432Node\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\\JServicesManager;runkey:_HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\\JServicesManager;runkey:_HKLM\SOFTWARE\Wow6432Node\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\\JServicesManager
Detection Origin: Local machine
Detection Type: FastPath
Detection Source: System
Process Name: C:\Program Files\SystemaRev\RevServicesX\app.exe
Signature Version: AV: 1.269.1851.0, AS: 1.269.1851.0, NIS: 1.269.1851.0
Engine Version: AM: 1.1.14901.4, NIS: 1.1.14901.4

Date: 2018-06-24 03:32:49.224
Description:
Windows Defender Antivirus has detected malware or other potentially unwanted software.
For more information please see the following:
https://go.microsoft.com/fwlink/?linkid=37020&name=Trojan:Win32/Occamy.C&threatid=2147726780&enterprise=0
Name: Trojan:Win32/Occamy.C
ID: 2147726780
Severity: Severe
Category: Trojan
Path: file:_C:\Program Files\SystemaRev\RevServicesX\app.exe
Detection Origin: Local machine
Detection Type: FastPath
Detection Source: User
Process Name: Unknown
Signature Version: AV: 1.269.1851.0, AS: 1.269.1851.0, NIS: 1.269.1851.0
Engine Version: AM: 1.1.14901.4, NIS: 1.1.14901.4

Date: 2018-06-24 03:32:30.540
Description:
Windows Defender Antivirus has detected malware or other potentially unwanted software.
For more information please see the following:
https://go.microsoft.com/fwlink/?linkid=37020&name=Trojan:Win32/Occamy.C&threatid=2147726780&enterprise=0
Name: Trojan:Win32/Occamy.C
ID: 2147726780
Severity: Severe
Category: Trojan
Path: file:_C:\Program Files\SystemaRev\RevServicesX\app.exe;process:_pid:13280,ProcessStart:131742773318469075
Detection Origin: Local machine
Detection Type: FastPath
Detection Source: System
Process Name: C:\Program Files\SystemaRev\RevServicesX\app.exe
Signature Version: AV: 1.269.1851.0, AS: 1.269.1851.0, NIS: 1.269.1851.0
Engine Version: AM: 1.1.14901.4, NIS: 1.1.14901.4

Date: 2018-06-24 03:27:13.676
Description:
Windows Defender Antivirus scan has been stopped before completion.
Scan ID: {4B129B6F-03B5-4CAA-8197-E19360F15AC1}
Scan Type: Antimalware
Scan Parameters: Quick Scan

==================== Memory info ===========================

Processor: Intel® Core™ i7-8700 CPU @ 3.20GHz
Percentage of memory in use: 22%
Total physical RAM: 16263.32 MB
Available physical RAM: 12531.09 MB
Total Virtual: 18695.32 MB
Available Virtual: 15053.96 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:222.62 GB) (Free:180.43 GB) NTFS
Drive d: () (Fixed) (Total:931.51 GB) (Free:877.37 GB) NTFS

\\?\Volume{2bd2c32a-0000-0000-0000-100000000000}\ (System Reserved) (Fixed) (Total:0.49 GB) (Free:0.46 GB) NTFS
\\?\Volume{2bd2c32a-0000-0000-0000-40c737000000}\ () (Fixed) (Total:0.46 GB) (Free:0.08 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 223.6 GB) (Disk ID: 2BD2C32A)
Partition 1: (Active) - (Size=500 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=222.6 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=467 MB) - (Type=27)

========================================================
Disk: 1 (MBR Code: Windows 7/8/10) (Size: 931.5 GB) (Disk ID: F7D9F504)
Partition 1: (Not Active) - (Size=931.5 GB) - (Type=07 NTFS)

==================== End of Addition.txt ============================



#3 nasdaq

nasdaq

  • Malware Response Team
  • 39,954 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:10:40 AM

Posted 24 June 2018 - 08:06 AM

Hello, Welcome to BleepingComputer.
I'm nasdaq and will be helping you.

If you can please print this topic it will make it easier for you to follow the instructions and complete all of the necessary steps in the order listed.
===

Your infection was that of a Trojan Bitcoin Miner.

===

Press the Windows key + r on your keyboard at the same time. This will open the RUN BOX.
Type Notepad and and click the OK key.

Please copy the entire contents of the code box below to a new file.
 
Start

CreateRestorePoint:
CloseProcesses:

() C:\Windows\Temp\g2268.tmp.exe
HKLM\...\Run: [rundll32] => C:\WINDOWS\system32\rundll32.exe "C:\Program Files\ThePake\ThePake.dll",qCclkRLrhW
HKLM Group Policy restriction on software: %systemroot%\system32\mrt.exe <==== ATTENTION
HKLM\ DisallowedCertificates: 03D22C9C66915D58C88912B64C1F984B8344EF09 (Comodo Security Solutions) <==== ATTENTION
HKLM\ DisallowedCertificates: 0F684EC1163281085C6AF20528878103ACEFCAAB (F-Secure Corporation) <==== ATTENTION
HKLM\ DisallowedCertificates: 1667908C9E22EFBD0590E088715CC74BE4C60884 (FRISK Software International/F-Prot) <==== ATTENTION
HKLM\ DisallowedCertificates: 18DEA4EFA93B06AE997D234411F3FD72A677EECE (Bitdefender SRL) <==== ATTENTION
HKLM\ DisallowedCertificates: 2026D13756EB0DB753DF26CB3B7EEBE3E70BB2CF (G DATA Software AG) <==== ATTENTION
HKLM\ DisallowedCertificates: 249BDA38A611CD746A132FA2AF995A2D3C941264 (Malwarebytes Corporation) <==== ATTENTION
HKLM\ DisallowedCertificates: 31AC96A6C17C425222C46D55C3CCA6BA12E54DAF (Symantec Corporation) <==== ATTENTION
HKLM\ DisallowedCertificates: 331E2046A1CCA7BFEF766724394BE6112B4CA3F7 (Trend Micro) <==== ATTENTION
HKLM\ DisallowedCertificates: 3353EA609334A9F23A701B9159E30CB6C22D4C59 (Webroot Inc.) <==== ATTENTION
HKLM\ DisallowedCertificates: 373C33726722D3A5D1EDD1F1585D5D25B39BEA1A (SUPERAntiSpyware.com) <==== ATTENTION
HKLM\ DisallowedCertificates: 3850EDD77CC74EC9F4829AE406BBF9C21E0DA87F (Kaspersky Lab) <==== ATTENTION
HKLM\ DisallowedCertificates: 3D496FA682E65FC122351EC29B55AB94F3BB03FC (AVG Technologies CZ) <==== ATTENTION
HKLM\ DisallowedCertificates: 4243A03DB4C3C15149CEA8B38EEA1DA4F26BD159 (PC Tools) <==== ATTENTION
HKLM\ DisallowedCertificates: 42727E052C0C2E1B35AB53E1005FD9EDC9DE8F01 (K7 Computing Pvt Ltd) <==== ATTENTION
HKLM\ DisallowedCertificates: 4420C99742DF11DD0795BC15B7B0ABF090DC84DF (Doctor Web Ltd.) <==== ATTENTION
HKLM\ DisallowedCertificates: 4C0AF5719009B7C9D85C5EAEDFA3B7F090FE5FFF (Emsisoft Ltd) <==== ATTENTION
HKLM\ DisallowedCertificates: 5240AB5B05D11B37900AC7712A3C6AE42F377C8C (Check Point Software Technologies Ltd.) <==== ATTENTION
HKLM\ DisallowedCertificates: 5DD3D41810F28B2A13E9A004E6412061E28FA48D (Emsisoft Ltd) <==== ATTENTION
HKLM\ DisallowedCertificates: 7457A3793086DBB58B3858D6476889E3311E550E (K7 Computing Pvt Ltd) <==== ATTENTION
HKLM\ DisallowedCertificates: 76A9295EF4343E12DFC5FE05DC57227C1AB00D29 (BullGuard Ltd) <==== ATTENTION
HKLM\ DisallowedCertificates: 775B373B33B9D15B58BC02B184704332B97C3CAF (McAfee) <==== ATTENTION
HKLM\ DisallowedCertificates: 872CD334B7E7B3C3D1C6114CD6B221026D505EAB (Comodo Security Solutions) <==== ATTENTION
HKLM\ DisallowedCertificates: 88AD5DFE24126872B33175D1778687B642323ACF (McAfee) <==== ATTENTION
HKLM\ DisallowedCertificates: 9132E8B079D080E01D52631690BE18EBC2347C1E (Adaware Software) <==== ATTENTION
HKLM\ DisallowedCertificates: 982D98951CF3C0CA2A02814D474A976CBFF6BDB1 (Safer Networking Ltd.) <==== ATTENTION
HKLM\ DisallowedCertificates: 9A08641F7C5F2CCA0888388BE3E5DBDDAAA3B361 (Webroot Inc.) <==== ATTENTION
HKLM\ DisallowedCertificates: 9C43F665E690AB4D486D4717B456C5554D4BCEB5 (ThreatTrack Security) <==== ATTENTION
HKLM\ DisallowedCertificates: 9E3F95577B37C74CA2F70C1E1859E798B7FC6B13 (CURIOLAB S.M.B.A.) <==== ATTENTION
HKLM\ DisallowedCertificates: A1F8DCB086E461E2ABB4B46ADCFA0B48C58B6E99 (Avira Operations GmbH & Co. KG) <==== ATTENTION
HKLM\ DisallowedCertificates: A5341949ABE1407DD7BF7DFE75460D9608FBC309 (BullGuard Ltd) <==== ATTENTION
HKLM\ DisallowedCertificates: A59CC32724DD07A6FC33F7806945481A2D13CA2F (ESET) <==== ATTENTION
HKLM\ DisallowedCertificates: AB7E760DA2485EA9EF5A6EEE7647748D4BA6B947 (AVG Technologies CZ) <==== ATTENTION
HKLM\ DisallowedCertificates: AD4C5429E10F4FF6C01840C20ABA344D7401209F (Avast Antivirus/Software) <==== ATTENTION
HKLM\ DisallowedCertificates: AD96BB64BA36379D2E354660780C2067B81DA2E0 (Symantec Corporation) <==== ATTENTION
HKLM\ DisallowedCertificates: B8EBF0E696AF77F51C96DB4D044586E2F4F8FD84 (Malwarebytes Corporation) <==== ATTENTION
HKLM\ DisallowedCertificates: CDC37C22FE9272D8F2610206AD397A45040326B8 (Trend Micro) <==== ATTENTION
HKLM\ DisallowedCertificates: D3F78D747E7C5D6D3AE8ABFDDA7522BFB4CBD598 (Kaspersky Lab) <==== ATTENTION
HKLM\ DisallowedCertificates: DB303C9B61282DE525DC754A535CA2D6A9BD3D87 (ThreatTrack Security) <==== ATTENTION
HKLM\ DisallowedCertificates: DB77E5CFEC34459146748B667C97B185619251BA (Avast Antivirus/Software) <==== ATTENTION
HKLM\ DisallowedCertificates: E22240E837B52E691C71DF248F12D27F96441C00 (Total Defense, Inc.) <==== ATTENTION
HKLM\ DisallowedCertificates: E513EAB8610CFFD7C87E00BCA15C23AAB407FCEF (AVG Technologies CZ) <==== ATTENTION
HKLM\ DisallowedCertificates: ED841A61C0F76025598421BC1B00E24189E68D54 (Bitdefender SRL) <==== ATTENTION
HKLM\ DisallowedCertificates: F83099622B4A9F72CB5081F742164AD1B8D048C9 (ESET) <==== ATTENTION
HKLM\ DisallowedCertificates: FBB42F089AF2D570F2BF6F493D107A3255A9BB1A (Panda Security S.L) <==== ATTENTION
HKLM\ DisallowedCertificates: FFFA650F2CB2ABC0D80527B524DD3F9FC172C138 (Doctor Web Ltd.) <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-21-1124267341-3267589977-3522073591-1001\...\Run: [G2H#IX_beG.exe] => C:\Program Files\Windows Defender\6VBV3CEGVXD5ML22D7VOR\G2H#IX_beG.exe
HKU\S-1-5-21-1124267341-3267589977-3522073591-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxps://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBEQo0lOCwIxrzs2Rcb6iYl3j4dOu7u7ZVVj6CTrV6VEEwTax0qJLJ-obz-CfNubpE3-8jvxmFnunkdbGiGlYLcxbmJlxOkzbgTSApiAt3yUNzDL5ckeEkx59k838gpC4oyhbU7Ndg3mA0DXs9wjkWQU5e4Gc83lIUmiziTano8KyLK3KVd86kHoXHSU20,&q={searchTerms}
HKU\S-1-5-21-1124267341-3267589977-3522073591-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://%66%65%65%64.%68%65%6C%70%65%72%62%61%72.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBEQo0lOCwIxrzs2Rcb6iYl3j4dOu7u7ZVVj6CTrV6VEEwTax0qJLJ-obz-CfNubpE3-8jvxmFnunkdbGiGlYLcxbmJlxOkzbgTRIz9n6OMOm5d6QyiOsOzogdpGBiHiBvU60LaP4ay8s1xcWht871vzS4cVWe_eQ27ZW-Wk2EAIcDrBTf7v7iprA06nDA,
SearchScopes: HKLM-x32 -> DefaultScope {ielnksrch} URL =
SearchScopes: HKLM-x32 -> ielnksrch URL = hxxps://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBEQo0lOCwIxrzs2Rcb6iYl3j4dOu7u7ZVVj6CTrV6VEEwTax0qJLJ-obz-CfNubpE3-8jvxmFnunkdbGiGlYLcxbmJlxOkzbgTSApiAt3yUNzDL5ckeEkx59k838gpC4oyhbU7Ndg3mA0DXs9wjkWQU5e4Gc83lIUmiziTano8KyLK3KVd86kHoXHSU20,&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1124267341-3267589977-3522073591-1001 -> DefaultScope {ielnksrch} URL = hxxps://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBEQo0lOCwIxrzs2Rcb6iYl3j4dOu7u7ZVVj6CTrV6VEEwTax0qJLJ-obz-CfNubpE3-8jvxmFnunkdbGiGlYLcxbmJlxOkzbgTSApiAt3yUNzDL5ckeEkx59k838gpC4oyhbU7Ndg3mA0DXs9wjkWQU5e4Gc83lIUmiziTano8KyLK3KVd86kHoXHSU20,&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1124267341-3267589977-3522073591-1001 -> {C0C3A6C6-03BC-4195-8FCB-AEA091301353} URL = hxxps://search.yahoo.com/yhs/search?hspart=lvs&hsimp=yhs-awc&type=lvs__webcompa__1_0__ya__ch_WCYID10454__180117__yaie&p={searchTerms}
SearchScopes: HKU\S-1-5-21-1124267341-3267589977-3522073591-1001 -> {ielnksrch} URL = hxxps://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBEQo0lOCwIxrzs2Rcb6iYl3j4dOu7u7ZVVj6CTrV6VEEwTax0qJLJ-obz-CfNubpE3-8jvxmFnunkdbGiGlYLcxbmJlxOkzbgTSApiAt3yUNzDL5ckeEkx59k838gpC4oyhbU7Ndg3mA0DXs9wjkWQU5e4Gc83lIUmiziTano8KyLK3KVd86kHoXHSU20,&q={searchTerms}
S3 SystemUpdate64; no ImagePath <==== ATTENTION

Task: {1581A11A-3EBC-4B1F-BB4F-D68A81122481} - System32\Tasks\ThePake => C:\WINDOWS\system32\rundll32.exe "C:\Program Files\ThePake\ThePake.dll",qCclkRLrhW <==== ATTENTION
Task: {292D0B9E-43FA-4E91-92AE-1AEDF03BE33B} - System32\Tasks\MainPMgr => powershell -ExecutionPolicy ByPass -File pm.ps1
Task: {623D48D9-157E-4185-9E56-786B6B3008AA} - System32\Tasks\RestoreRevTask => C:\Program Files\Common Files\restore_rev.bat [2018-06-16] () <==== ATTENTION
Task: {91F8B013-4D72-465F-ADB6-5899B920F962} - System32\Tasks\ThePake-dll => C:\WINDOWS\system32\rundll32.exe "C:\Program Files\ThePake\ThePake.dll",qCclkRLrhW
Task: {9574EB88-B82B-48CB-9CCC-32E3870128ED} - System32\Tasks\KMSAutoNet => C:\ProgramData\KMSAutoS\KMSAuto Net.exe [2017-06-24] (MSFree Inc.)
Task: {99230EBF-E981-4A9B-A5A1-AD43A5ED487D} - System32\Tasks\Update_4.0.10 => C:\Program Files\SystemaRev\RevServicesX\SystemUpdate64x.exe
Task: {C1CBE3B3-186E-4D9E-9F7C-8E9F579812B0} - System32\Tasks\PPI Update => C:\WINDOWS\explorer.exe "hxxp://windowsdefender.club/warning/download.php?mn=5623" <==== ATTENTION
Task: {C4F113B5-6F41-40BE-9C78-2C945E9E7E32} - System32\Tasks\Accent Online Paintings 2007 => C:\WINDOWS\system32\rundll32.exe "C:\Program Files\Accent Online Paintings 2007\Accent Online Paintings 2007.dll",kTiiGdcCqPyt <==== ATTENTION

C:\Windows\System32\Tasks\ThePake => C:\WINDOWS\system32\rundll32.exe
C:\Windows\System32\Tasks\MainPMgr => powershell -ExecutionPolicy ByPass -File pm.ps1
C:\Windows\System32\Tasks\RestoreRevTask
C:\Windows\System32\Tasks\ThePake-dll
C:\Windows\System32\Tasks\KMSAutoNet
C:\Windows\System32\Tasks\Update_4.0.10 => C:\Program Files\SystemaRev\RevServicesX\SystemUpdate64x.exe
C:\Windows\System32\Tasks\PPI Update
C:\Windows\System32\Tasks\Accent Online Paintings 2007

C:\Windows\Temp\g2268.tmp.exe
C:\Users\PC\AppData\Local\Temp\nswD6E0.tmp\System.dll
C:\Users\PC\AppData\Local\Temp\nswD6E0.tmp\registry.dll
C:\Users\PC\AppData\Local\Temp\nswD6E0.tmp\newadvsplash.dll
C:\Program Files\Common Files\restore_rev.bat
C:\ProgramData\KMSAutoS\KMSAuto Net.exe
C:\Program Files\SystemaRev

Reboot:

End
Save the file as fixlist.txt in the same folder where the Farbar tool is running from.
The location is listed in the 3rd line of the Farbar log you have submitted.

Run FRST and click Fix only once and wait.

The tool will create a log (Fixlog.txt) please post it to your reply.
===

Please download Malwarebytes Anti-Malware from here
  • Right-click on the MBAM icon and select Run as administrator to run the tool.
  • Click Yes to accept any security warnings that may appear.
  • Once the MBAM dashboard opens, on the right detail pane click on the word "Current" under the Scan Status to update the tool database.
  • On the left menu pane click the Settings tab, and then select the Protection tab on the top.
  • Under the Scan Options, turn on the button Scan for rootkits and Scan within archives.
  • Click the Scan tab on the right detail pane, select Threat Scan and click the Start Scan button
  • Note: The scan may take some time to finish, so please be patient.
  • If potential threats are detected, ensure to checkmark all the listed items, and click the Quarantine Selected button.
  • While still on the Scan tab, click the View Report button, and in the window that opens click the Export button, select Text file (*.txt), and save the log to your Desktop.
  • The log can also be viewed by clicking the log to select it, then clicking the View Report button.
Please post the log for my review.

Note: If asked to restart the computer, please do so immediately.
===

Please post the logs and let me know what problem persists with this computer.

#4 armone

armone
  • Topic Starter

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:04:40 PM

Posted 24 June 2018 - 08:24 AM

Fix result of Farbar Recovery Scan Tool (x64) Version: 20.06.2018
Ran by PC (24-06-2018 15:10:17) Run:1
Running from C:\Users\PC\Desktop
Loaded Profiles: PC (Available Profiles: PC)
Boot Mode: Normal
==============================================

fixlist content:
*****************
Start

CreateRestorePoint:
CloseProcesses:

() C:\Windows\Temp\g2268.tmp.exe
HKLM\...\Run: [rundll32] => C:\WINDOWS\system32\rundll32.exe "C:\Program Files\ThePake\ThePake.dll",qCclkRLrhW
HKLM Group Policy restriction on software: %systemroot%\system32\mrt.exe <==== ATTENTION
HKLM\ DisallowedCertificates: 03D22C9C66915D58C88912B64C1F984B8344EF09 (Comodo Security Solutions) <==== ATTENTION
HKLM\ DisallowedCertificates: 0F684EC1163281085C6AF20528878103ACEFCAAB (F-Secure Corporation) <==== ATTENTION
HKLM\ DisallowedCertificates: 1667908C9E22EFBD0590E088715CC74BE4C60884 (FRISK Software International/F-Prot) <==== ATTENTION
HKLM\ DisallowedCertificates: 18DEA4EFA93B06AE997D234411F3FD72A677EECE (Bitdefender SRL) <==== ATTENTION
HKLM\ DisallowedCertificates: 2026D13756EB0DB753DF26CB3B7EEBE3E70BB2CF (G DATA Software AG) <==== ATTENTION
HKLM\ DisallowedCertificates: 249BDA38A611CD746A132FA2AF995A2D3C941264 (Malwarebytes Corporation) <==== ATTENTION
HKLM\ DisallowedCertificates: 31AC96A6C17C425222C46D55C3CCA6BA12E54DAF (Symantec Corporation) <==== ATTENTION
HKLM\ DisallowedCertificates: 331E2046A1CCA7BFEF766724394BE6112B4CA3F7 (Trend Micro) <==== ATTENTION
HKLM\ DisallowedCertificates: 3353EA609334A9F23A701B9159E30CB6C22D4C59 (Webroot Inc.) <==== ATTENTION
HKLM\ DisallowedCertificates: 373C33726722D3A5D1EDD1F1585D5D25B39BEA1A (SUPERAntiSpyware.com) <==== ATTENTION
HKLM\ DisallowedCertificates: 3850EDD77CC74EC9F4829AE406BBF9C21E0DA87F (Kaspersky Lab) <==== ATTENTION
HKLM\ DisallowedCertificates: 3D496FA682E65FC122351EC29B55AB94F3BB03FC (AVG Technologies CZ) <==== ATTENTION
HKLM\ DisallowedCertificates: 4243A03DB4C3C15149CEA8B38EEA1DA4F26BD159 (PC Tools) <==== ATTENTION
HKLM\ DisallowedCertificates: 42727E052C0C2E1B35AB53E1005FD9EDC9DE8F01 (K7 Computing Pvt Ltd) <==== ATTENTION
HKLM\ DisallowedCertificates: 4420C99742DF11DD0795BC15B7B0ABF090DC84DF (Doctor Web Ltd.) <==== ATTENTION
HKLM\ DisallowedCertificates: 4C0AF5719009B7C9D85C5EAEDFA3B7F090FE5FFF (Emsisoft Ltd) <==== ATTENTION
HKLM\ DisallowedCertificates: 5240AB5B05D11B37900AC7712A3C6AE42F377C8C (Check Point Software Technologies Ltd.) <==== ATTENTION
HKLM\ DisallowedCertificates: 5DD3D41810F28B2A13E9A004E6412061E28FA48D (Emsisoft Ltd) <==== ATTENTION
HKLM\ DisallowedCertificates: 7457A3793086DBB58B3858D6476889E3311E550E (K7 Computing Pvt Ltd) <==== ATTENTION
HKLM\ DisallowedCertificates: 76A9295EF4343E12DFC5FE05DC57227C1AB00D29 (BullGuard Ltd) <==== ATTENTION
HKLM\ DisallowedCertificates: 775B373B33B9D15B58BC02B184704332B97C3CAF (McAfee) <==== ATTENTION
HKLM\ DisallowedCertificates: 872CD334B7E7B3C3D1C6114CD6B221026D505EAB (Comodo Security Solutions) <==== ATTENTION
HKLM\ DisallowedCertificates: 88AD5DFE24126872B33175D1778687B642323ACF (McAfee) <==== ATTENTION
HKLM\ DisallowedCertificates: 9132E8B079D080E01D52631690BE18EBC2347C1E (Adaware Software) <==== ATTENTION
HKLM\ DisallowedCertificates: 982D98951CF3C0CA2A02814D474A976CBFF6BDB1 (Safer Networking Ltd.) <==== ATTENTION
HKLM\ DisallowedCertificates: 9A08641F7C5F2CCA0888388BE3E5DBDDAAA3B361 (Webroot Inc.) <==== ATTENTION
HKLM\ DisallowedCertificates: 9C43F665E690AB4D486D4717B456C5554D4BCEB5 (ThreatTrack Security) <==== ATTENTION
HKLM\ DisallowedCertificates: 9E3F95577B37C74CA2F70C1E1859E798B7FC6B13 (CURIOLAB S.M.B.A.) <==== ATTENTION
HKLM\ DisallowedCertificates: A1F8DCB086E461E2ABB4B46ADCFA0B48C58B6E99 (Avira Operations GmbH & Co. KG) <==== ATTENTION
HKLM\ DisallowedCertificates: A5341949ABE1407DD7BF7DFE75460D9608FBC309 (BullGuard Ltd) <==== ATTENTION
HKLM\ DisallowedCertificates: A59CC32724DD07A6FC33F7806945481A2D13CA2F (ESET) <==== ATTENTION
HKLM\ DisallowedCertificates: AB7E760DA2485EA9EF5A6EEE7647748D4BA6B947 (AVG Technologies CZ) <==== ATTENTION
HKLM\ DisallowedCertificates: AD4C5429E10F4FF6C01840C20ABA344D7401209F (Avast Antivirus/Software) <==== ATTENTION
HKLM\ DisallowedCertificates: AD96BB64BA36379D2E354660780C2067B81DA2E0 (Symantec Corporation) <==== ATTENTION
HKLM\ DisallowedCertificates: B8EBF0E696AF77F51C96DB4D044586E2F4F8FD84 (Malwarebytes Corporation) <==== ATTENTION
HKLM\ DisallowedCertificates: CDC37C22FE9272D8F2610206AD397A45040326B8 (Trend Micro) <==== ATTENTION
HKLM\ DisallowedCertificates: D3F78D747E7C5D6D3AE8ABFDDA7522BFB4CBD598 (Kaspersky Lab) <==== ATTENTION
HKLM\ DisallowedCertificates: DB303C9B61282DE525DC754A535CA2D6A9BD3D87 (ThreatTrack Security) <==== ATTENTION
HKLM\ DisallowedCertificates: DB77E5CFEC34459146748B667C97B185619251BA (Avast Antivirus/Software) <==== ATTENTION
HKLM\ DisallowedCertificates: E22240E837B52E691C71DF248F12D27F96441C00 (Total Defense, Inc.) <==== ATTENTION
HKLM\ DisallowedCertificates: E513EAB8610CFFD7C87E00BCA15C23AAB407FCEF (AVG Technologies CZ) <==== ATTENTION
HKLM\ DisallowedCertificates: ED841A61C0F76025598421BC1B00E24189E68D54 (Bitdefender SRL) <==== ATTENTION
HKLM\ DisallowedCertificates: F83099622B4A9F72CB5081F742164AD1B8D048C9 (ESET) <==== ATTENTION
HKLM\ DisallowedCertificates: FBB42F089AF2D570F2BF6F493D107A3255A9BB1A (Panda Security S.L) <==== ATTENTION
HKLM\ DisallowedCertificates: FFFA650F2CB2ABC0D80527B524DD3F9FC172C138 (Doctor Web Ltd.) <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-21-1124267341-3267589977-3522073591-1001\...\Run: [G2H#IX_beG.exe] => C:\Program Files\Windows Defender\6VBV3CEGVXD5ML22D7VOR\G2H#IX_beG.exe
HKU\S-1-5-21-1124267341-3267589977-3522073591-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxps://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBEQo0lOCwIxrzs2Rcb6iYl3j4dOu7u7ZVVj6CTrV6VEEwTax0qJLJ-obz-CfNubpE3-8jvxmFnunkdbGiGlYLcxbmJlxOkzbgTSApiAt3yUNzDL5ckeEkx59k838gpC4oyhbU7Ndg3mA0DXs9wjkWQU5e4Gc83lIUmiziTano8KyLK3KVd86kHoXHSU20,&q={searchTerms}
HKU\S-1-5-21-1124267341-3267589977-3522073591-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://%66%65%65%64.%68%65%6C%70%65%72%62%61%72.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBEQo0lOCwIxrzs2Rcb6iYl3j4dOu7u7ZVVj6CTrV6VEEwTax0qJLJ-obz-CfNubpE3-8jvxmFnunkdbGiGlYLcxbmJlxOkzbgTRIz9n6OMOm5d6QyiOsOzogdpGBiHiBvU60LaP4ay8s1xcWht871vzS4cVWe_eQ27ZW-Wk2EAIcDrBTf7v7iprA06nDA,
SearchScopes: HKLM-x32 -> DefaultScope {ielnksrch} URL =
SearchScopes: HKLM-x32 -> ielnksrch URL = hxxps://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBEQo0lOCwIxrzs2Rcb6iYl3j4dOu7u7ZVVj6CTrV6VEEwTax0qJLJ-obz-CfNubpE3-8jvxmFnunkdbGiGlYLcxbmJlxOkzbgTSApiAt3yUNzDL5ckeEkx59k838gpC4oyhbU7Ndg3mA0DXs9wjkWQU5e4Gc83lIUmiziTano8KyLK3KVd86kHoXHSU20,&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1124267341-3267589977-3522073591-1001 -> DefaultScope {ielnksrch} URL = hxxps://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBEQo0lOCwIxrzs2Rcb6iYl3j4dOu7u7ZVVj6CTrV6VEEwTax0qJLJ-obz-CfNubpE3-8jvxmFnunkdbGiGlYLcxbmJlxOkzbgTSApiAt3yUNzDL5ckeEkx59k838gpC4oyhbU7Ndg3mA0DXs9wjkWQU5e4Gc83lIUmiziTano8KyLK3KVd86kHoXHSU20,&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1124267341-3267589977-3522073591-1001 -> {C0C3A6C6-03BC-4195-8FCB-AEA091301353} URL = hxxps://search.yahoo.com/yhs/search?hspart=lvs&hsimp=yhs-awc&type=lvs__webcompa__1_0__ya__ch_WCYID10454__180117__yaie&p={searchTerms}
SearchScopes: HKU\S-1-5-21-1124267341-3267589977-3522073591-1001 -> {ielnksrch} URL = hxxps://%66%65%65%64.%73%6F%6E%69%63-%73%65%61%72%63%68.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBEQo0lOCwIxrzs2Rcb6iYl3j4dOu7u7ZVVj6CTrV6VEEwTax0qJLJ-obz-CfNubpE3-8jvxmFnunkdbGiGlYLcxbmJlxOkzbgTSApiAt3yUNzDL5ckeEkx59k838gpC4oyhbU7Ndg3mA0DXs9wjkWQU5e4Gc83lIUmiziTano8KyLK3KVd86kHoXHSU20,&q={searchTerms}
S3 SystemUpdate64; no ImagePath <==== ATTENTION

Task: {1581A11A-3EBC-4B1F-BB4F-D68A81122481} - System32\Tasks\ThePake => C:\WINDOWS\system32\rundll32.exe "C:\Program Files\ThePake\ThePake.dll",qCclkRLrhW <==== ATTENTION
Task: {292D0B9E-43FA-4E91-92AE-1AEDF03BE33B} - System32\Tasks\MainPMgr => powershell -ExecutionPolicy ByPass -File pm.ps1
Task: {623D48D9-157E-4185-9E56-786B6B3008AA} - System32\Tasks\RestoreRevTask => C:\Program Files\Common Files\restore_rev.bat [2018-06-16] () <==== ATTENTION
Task: {91F8B013-4D72-465F-ADB6-5899B920F962} - System32\Tasks\ThePake-dll => C:\WINDOWS\system32\rundll32.exe "C:\Program Files\ThePake\ThePake.dll",qCclkRLrhW
Task: {9574EB88-B82B-48CB-9CCC-32E3870128ED} - System32\Tasks\KMSAutoNet => C:\ProgramData\KMSAutoS\KMSAuto Net.exe [2017-06-24] (MSFree Inc.)
Task: {99230EBF-E981-4A9B-A5A1-AD43A5ED487D} - System32\Tasks\Update_4.0.10 => C:\Program Files\SystemaRev\RevServicesX\SystemUpdate64x.exe
Task: {C1CBE3B3-186E-4D9E-9F7C-8E9F579812B0} - System32\Tasks\PPI Update => C:\WINDOWS\explorer.exe "hxxp://windowsdefender.club/warning/download.php?mn=5623" <==== ATTENTION
Task: {C4F113B5-6F41-40BE-9C78-2C945E9E7E32} - System32\Tasks\Accent Online Paintings 2007 => C:\WINDOWS\system32\rundll32.exe "C:\Program Files\Accent Online Paintings 2007\Accent Online Paintings 2007.dll",kTiiGdcCqPyt <==== ATTENTION

C:\Windows\System32\Tasks\ThePake => C:\WINDOWS\system32\rundll32.exe
C:\Windows\System32\Tasks\MainPMgr => powershell -ExecutionPolicy ByPass -File pm.ps1
C:\Windows\System32\Tasks\RestoreRevTask
C:\Windows\System32\Tasks\ThePake-dll
C:\Windows\System32\Tasks\KMSAutoNet
C:\Windows\System32\Tasks\Update_4.0.10 => C:\Program Files\SystemaRev\RevServicesX\SystemUpdate64x.exe
C:\Windows\System32\Tasks\PPI Update
C:\Windows\System32\Tasks\Accent Online Paintings 2007

C:\Windows\Temp\g2268.tmp.exe
C:\Users\PC\AppData\Local\Temp\nswD6E0.tmp\System.dll
C:\Users\PC\AppData\Local\Temp\nswD6E0.tmp\registry.dll
C:\Users\PC\AppData\Local\Temp\nswD6E0.tmp\newadvsplash.dll
C:\Program Files\Common Files\restore_rev.bat
C:\ProgramData\KMSAutoS\KMSAuto Net.exe
C:\Program Files\SystemaRev

Reboot:

End
*****************

Restore point was successfully created.
Processes closed successfully.
C:\Windows\Temp\g2268.tmp.exe => Could not close process
"HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\rundll32" => removed successfully
HKLM Group Policy restriction on software: %systemroot%\system32\mrt.exe <==== ATTENTION => restored successfully
"HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\03D22C9C66915D58C88912B64C1F984B8344EF09" => removed successfully
"HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\0F684EC1163281085C6AF20528878103ACEFCAAB" => removed successfully
"HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\1667908C9E22EFBD0590E088715CC74BE4C60884" => removed successfully
"HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\18DEA4EFA93B06AE997D234411F3FD72A677EECE" => removed successfully
"HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\2026D13756EB0DB753DF26CB3B7EEBE3E70BB2CF" => removed successfully
"HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\249BDA38A611CD746A132FA2AF995A2D3C941264" => removed successfully
"HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\31AC96A6C17C425222C46D55C3CCA6BA12E54DAF" => removed successfully
"HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\331E2046A1CCA7BFEF766724394BE6112B4CA3F7" => removed successfully
"HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\3353EA609334A9F23A701B9159E30CB6C22D4C59" => removed successfully
"HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\373C33726722D3A5D1EDD1F1585D5D25B39BEA1A" => removed successfully
"HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\3850EDD77CC74EC9F4829AE406BBF9C21E0DA87F" => removed successfully
"HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\3D496FA682E65FC122351EC29B55AB94F3BB03FC" => removed successfully
"HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\4243A03DB4C3C15149CEA8B38EEA1DA4F26BD159" => removed successfully
"HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\42727E052C0C2E1B35AB53E1005FD9EDC9DE8F01" => removed successfully
"HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\4420C99742DF11DD0795BC15B7B0ABF090DC84DF" => removed successfully
"HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\4C0AF5719009B7C9D85C5EAEDFA3B7F090FE5FFF" => removed successfully
"HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\5240AB5B05D11B37900AC7712A3C6AE42F377C8C" => removed successfully
"HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\5DD3D41810F28B2A13E9A004E6412061E28FA48D" => removed successfully
"HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\7457A3793086DBB58B3858D6476889E3311E550E" => removed successfully
"HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\76A9295EF4343E12DFC5FE05DC57227C1AB00D29" => removed successfully
"HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\775B373B33B9D15B58BC02B184704332B97C3CAF" => removed successfully
"HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\872CD334B7E7B3C3D1C6114CD6B221026D505EAB" => removed successfully
"HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\88AD5DFE24126872B33175D1778687B642323ACF" => removed successfully
"HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\9132E8B079D080E01D52631690BE18EBC2347C1E" => removed successfully
"HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\982D98951CF3C0CA2A02814D474A976CBFF6BDB1" => removed successfully
"HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\9A08641F7C5F2CCA0888388BE3E5DBDDAAA3B361" => removed successfully
"HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\9C43F665E690AB4D486D4717B456C5554D4BCEB5" => removed successfully
"HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\9E3F95577B37C74CA2F70C1E1859E798B7FC6B13" => removed successfully
"HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\A1F8DCB086E461E2ABB4B46ADCFA0B48C58B6E99" => removed successfully
"HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\A5341949ABE1407DD7BF7DFE75460D9608FBC309" => removed successfully
"HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\A59CC32724DD07A6FC33F7806945481A2D13CA2F" => removed successfully
"HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\AB7E760DA2485EA9EF5A6EEE7647748D4BA6B947" => removed successfully
"HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\AD4C5429E10F4FF6C01840C20ABA344D7401209F" => removed successfully
"HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\AD96BB64BA36379D2E354660780C2067B81DA2E0" => removed successfully
"HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\B8EBF0E696AF77F51C96DB4D044586E2F4F8FD84" => removed successfully
"HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\CDC37C22FE9272D8F2610206AD397A45040326B8" => removed successfully
"HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\D3F78D747E7C5D6D3AE8ABFDDA7522BFB4CBD598" => removed successfully
"HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\DB303C9B61282DE525DC754A535CA2D6A9BD3D87" => removed successfully
"HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\DB77E5CFEC34459146748B667C97B185619251BA" => removed successfully
"HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\E22240E837B52E691C71DF248F12D27F96441C00" => removed successfully
"HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\E513EAB8610CFFD7C87E00BCA15C23AAB407FCEF" => removed successfully
"HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\ED841A61C0F76025598421BC1B00E24189E68D54" => removed successfully
"HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\F83099622B4A9F72CB5081F742164AD1B8D048C9" => removed successfully
"HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\FBB42F089AF2D570F2BF6F493D107A3255A9BB1A" => removed successfully
"HKLM\Software\Microsoft\SystemCertificates\Disallowed\Certificates\FFFA650F2CB2ABC0D80527B524DD3F9FC172C138" => removed successfully
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender => could not remove, key could be protected
"HKU\S-1-5-21-1124267341-3267589977-3522073591-1001\Software\Microsoft\Windows\CurrentVersion\Run\\G2H#IX_beG.exe" => removed successfully
HKU\S-1-5-21-1124267341-3267589977-3522073591-1001\Software\Microsoft\Internet Explorer\Main\\Search Page => value restored successfully
HKU\S-1-5-21-1124267341-3267589977-3522073591-1001\Software\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\ielnksrch" => removed successfully
HKLM\Software\Wow6432Node\Classes\CLSID\ielnksrch => not found
"HKU\S-1-5-21-1124267341-3267589977-3522073591-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope" => removed successfully
"HKU\S-1-5-21-1124267341-3267589977-3522073591-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{C0C3A6C6-03BC-4195-8FCB-AEA091301353}" => removed successfully
HKLM\Software\Classes\CLSID\{C0C3A6C6-03BC-4195-8FCB-AEA091301353} => not found
"HKU\S-1-5-21-1124267341-3267589977-3522073591-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{ielnksrch}" => removed successfully
HKLM\Software\Classes\CLSID\{ielnksrch} => not found
"HKLM\System\CurrentControlSet\Services\SystemUpdate64" => removed successfully
SystemUpdate64 => service removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{1581A11A-3EBC-4B1F-BB4F-D68A81122481}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1581A11A-3EBC-4B1F-BB4F-D68A81122481}" => removed successfully
C:\WINDOWS\System32\Tasks\ThePake => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ThePake" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{292D0B9E-43FA-4E91-92AE-1AEDF03BE33B}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{292D0B9E-43FA-4E91-92AE-1AEDF03BE33B}" => removed successfully
C:\WINDOWS\System32\Tasks\MainPMgr => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\MainPMgr" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{623D48D9-157E-4185-9E56-786B6B3008AA}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{623D48D9-157E-4185-9E56-786B6B3008AA}" => removed successfully
C:\WINDOWS\System32\Tasks\RestoreRevTask => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\RestoreRevTask" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{91F8B013-4D72-465F-ADB6-5899B920F962}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{91F8B013-4D72-465F-ADB6-5899B920F962}" => removed successfully
C:\WINDOWS\System32\Tasks\ThePake-dll => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ThePake-dll" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{9574EB88-B82B-48CB-9CCC-32E3870128ED}" => removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9574EB88-B82B-48CB-9CCC-32E3870128ED} => not found
"C:\WINDOWS\System32\Tasks\KMSAutoNet" => not found
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\KMSAutoNet => not found
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{99230EBF-E981-4A9B-A5A1-AD43A5ED487D}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{99230EBF-E981-4A9B-A5A1-AD43A5ED487D}" => removed successfully
C:\WINDOWS\System32\Tasks\Update_4.0.10 => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Update_4.0.10" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{C1CBE3B3-186E-4D9E-9F7C-8E9F579812B0}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C1CBE3B3-186E-4D9E-9F7C-8E9F579812B0}" => removed successfully
C:\WINDOWS\System32\Tasks\PPI Update => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\PPI Update" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Boot\{C4F113B5-6F41-40BE-9C78-2C945E9E7E32}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C4F113B5-6F41-40BE-9C78-2C945E9E7E32}" => removed successfully
C:\WINDOWS\System32\Tasks\Accent Online Paintings 2007 => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Accent Online Paintings 2007" => removed successfully
"C:\Windows\System32\Tasks\ThePake => C:\WINDOWS\system32\rundll32.exe" => not found
"C:\Windows\System32\Tasks\MainPMgr => powershell -ExecutionPolicy ByPass -File pm.ps1" => not found
"C:\Windows\System32\Tasks\RestoreRevTask" => not found
"C:\Windows\System32\Tasks\ThePake-dll" => not found
"C:\Windows\System32\Tasks\KMSAutoNet" => not found
"C:\Windows\System32\Tasks\Update_4.0.10 => C:\Program Files\SystemaRev\RevServicesX\SystemUpdate64x.exe" => not found
"C:\Windows\System32\Tasks\PPI Update" => not found
"C:\Windows\System32\Tasks\Accent Online Paintings 2007" => not found
C:\Windows\Temp\g2268.tmp.exe => moved successfully
C:\Users\PC\AppData\Local\Temp\nswD6E0.tmp\System.dll => moved successfully
C:\Users\PC\AppData\Local\Temp\nswD6E0.tmp\registry.dll => moved successfully
C:\Users\PC\AppData\Local\Temp\nswD6E0.tmp\newadvsplash.dll => moved successfully
C:\Program Files\Common Files\restore_rev.bat => moved successfully
"C:\ProgramData\KMSAutoS\KMSAuto Net.exe" => not found
C:\Program Files\SystemaRev => moved successfully

Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 24-06-2018 15:11:48)


Result of scheduled keys to remove after reboot:

HKLM\SOFTWARE\Policies\Microsoft\Windows Defender => could not remove, key could be protected

==== End of Fixlog 15:11:48 ====


Malwarebytes
www.malwarebytes.com

-Log Details-
Scan Date: 6/24/18
Scan Time: 3:16 PM
Log File: cb1ed2a4-77b0-11e8-ab98-e0d55e0e6402.json
Administrator: Yes

-Software Information-
Version: 3.5.1.2522
Components Version: 1.0.374
Update Package Version: 1.0.5611
License: Trial

-System Information-
OS: Windows 10 (Build 17134.112)
CPU: x64
File System: NTFS
User: ARMIN\PC

-Scan Summary-
Scan Type: Threat Scan
Scan Initiated By: Manual
Result: Completed
Objects Scanned: 329921
Threats Detected: 83
Threats Quarantined: 83
Time Elapsed: 2 min, 41 sec

-Scan Options-
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Detect
PUM: Detect

-Scan Details-
Process: 0
(No malicious items detected)

Module: 0
(No malicious items detected)

Registry Key: 9
Adware.FastDataX, HKU\S-1-5-21-1124267341-3267589977-3522073591-1001\SOFTWARE\FastDataX, Quarantined, [3938], [484533],1.0.5611
Adware.Linkury.ACMB1, HKU\S-1-5-21-1124267341-3267589977-3522073591-1001\SOFTWARE\mtSubair, Quarantined, [672], [361549],1.0.5611
Adware.OtherSearch, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\TRACING\starter_RASAPI32, Quarantined, [6177], [474059],1.0.5611
Adware.OtherSearch, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\TRACING\starter_RASMANCS, Quarantined, [6177], [474059],1.0.5611
Adware.Linkury.ACMB1, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\TRACING\Subair_RASAPI32, Quarantined, [672], [361547],1.0.5611
Adware.Linkury.ACMB1, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\TRACING\Subair_RASMANCS, Quarantined, [672], [361547],1.0.5611
PUP.Optional.Linkury.ACMB1, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\EVENTLOG\APPLICATION\Application Hosting, Quarantined, [690], [259928],1.0.5611
Adware.Linkury.ACMB1, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SILENTPROCESSEXIT\Subair.exe, Quarantined, [672], [361541],1.0.5611
Adware.Linkury.ACMB1, HKLM\SOFTWARE\WOW6432NODE\mtSubair, Quarantined, [672], [361551],1.0.5611

Registry Value: 6
PUP.Optional.Linkury.ACMB1, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWS|APPINIT_DLLS, Quarantined, [690], [-1],0.0.0
PUP.Optional.Linkury.ACMB1, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS NT\CURRENTVERSION\WINDOWS|APPINIT_DLLS, Quarantined, [690], [-1],0.0.0
PUP.Optional.Linkury.ACMB1, HKU\S-1-5-21-1124267341-3267589977-3522073591-1001\ENVIRONMENT|SNF, Quarantined, [690], [-1],0.0.0
PUP.Optional.Linkury.ACMB1, HKU\S-1-5-21-1124267341-3267589977-3522073591-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHURL|DEFAULT, Quarantined, [690], [259988],1.0.5611
PUP.Optional.Linkury.ACMB1, HKU\S-1-5-21-1124267341-3267589977-3522073591-1001\ENVIRONMENT|SNP, Quarantined, [690], [259518],1.0.5611
PUP.Optional.Linkury.ACMB1, HKU\S-1-5-21-1124267341-3267589977-3522073591-1001\ENVIRONMENT|SNF, Quarantined, [690], [259517],1.0.5611

Registry Data: 3
PUP.Optional.Linkury.ACMB1, HKU\S-1-5-21-1124267341-3267589977-3522073591-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|SEARCH BAR, Replaced, [690], [293485],1.0.5611
PUP.Optional.Linkury.ACMB1, HKU\S-1-5-21-1124267341-3267589977-3522073591-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|SEARCHASSISTANT, Replaced, [690], [293485],1.0.5611
PUP.Optional.Linkury.ACMB1, HKU\S-1-5-21-1124267341-3267589977-3522073591-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCH|DEFAULT_SEARCH_URL, Replaced, [690], [293486],1.0.5611

Data Stream: 0
(No malicious items detected)

Folder: 12
Adware.FastDataX.EncJob, C:\PROGRAM FILES (X86)\FASTDATAX, Quarantined, [2065], [407194],1.0.5611
Adware.FastDataX, C:\Users\PC\AppData\Roaming\FastDataX\log, Quarantined, [3938], [509538],1.0.5611
Adware.FastDataX, C:\USERS\PC\APPDATA\ROAMING\FASTDATAX, Quarantined, [3938], [509538],1.0.5611
Adware.Linkury.ACMB1, C:\PROGRAMDATA\SUBAIR, Quarantined, [672], [361534],1.0.5611
Adware.Linkury, C:\PROGRAMDATA\PREFSSECURE, Quarantined, [1092], [377396],1.0.5611
Adware.Linkury, C:\ProgramData\Logic Cramble\X64, Quarantined, [1092], [431817],1.0.5611
Adware.Linkury, C:\ProgramData\Logic Cramble\X86, Quarantined, [1092], [431817],1.0.5611
Adware.Linkury, C:\PROGRAMDATA\LOGIC CRAMBLE, Quarantined, [1092], [431817],1.0.5611
Trojan.Agent, C:\PROGRAMDATA\SYSTEMAREV, Quarantined, [389], [522358],1.0.5611
PUP.Optional.BundleInstaller, C:\USERS\PC\APPDATA\LOCAL\TEMP\1078456453, Quarantined, [400], [463480],1.0.5611
PUP.Optional.BundleInstaller, C:\USERS\PC\APPDATA\LOCAL\TEMP\1078456453, Quarantined, [400], [463480],1.0.5611
PUP.Optional.Linkury.Generic, C:\PROGRAMDATA\SUBAIRS, Quarantined, [224], [380106],1.0.5611

File: 53
PUP.Optional.Linkury.ACMB1, C:\WINDOWS\SYSWOW64\FINDIT.XML, Quarantined, [690], [259512],1.0.5611
Adware.Linkury.Generic, C:\USERS\PC\APPDATA\LOCAL\UNINSTALL_TEMP.ICO, Quarantined, [3750], [404862],1.0.5611
Adware.Linkury.Generic, C:\USERS\PC\APPDATA\LOCAL\Ranity.tst, Quarantined, [3750], [404871],1.0.5611
Adware.Linkury.Generic, C:\USERS\PC\APPDATA\LOCAL\NOAH.DAT, Quarantined, [3750], [404865],1.0.5611
Adware.Linkury.Generic, C:\USERS\PC\APPDATA\LOCAL\MD.XML, Quarantined, [3750], [404866],1.0.5611
Adware.Linkury.Generic, C:\USERS\PC\APPDATA\LOCAL\AGENT.DAT, Quarantined, [3750], [404872],1.0.5611
Adware.FastDataX.EncJob, C:\PROGRAM FILES (X86)\FASTDATAX\UNINS000.DAT, Quarantined, [2065], [407194],1.0.5611
Adware.FastDataX.EncJob, C:\Program Files (x86)\FastDataX\unins000.exe, Quarantined, [2065], [407194],1.0.5611
Adware.Linkury.Generic, C:\USERS\PC\APPDATA\LOCAL\MAIN.DAT, Quarantined, [3750], [442900],1.0.5611
Adware.FastDataX, C:\USERS\PC\APPDATA\ROAMING\FASTDATAX\LOG\20180624i-0212.log, Quarantined, [3938], [509538],1.0.5611
Adware.Linkury.Generic, C:\WINDOWS\SYSWOW64\CONFIG\SYSTEMPROFILE\APPDATA\LOCAL\SHAM.DB, Quarantined, [3750], [516189],1.0.5611
Adware.Linkury.Generic, C:\USERS\PC\APPDATA\LOCAL\SHAM.DB, Quarantined, [3750], [516191],1.0.5611
Adware.Linkury.ACMB1, C:\ProgramData\Subair\Lamgosing.dll, Quarantined, [672], [361534],1.0.5611
Adware.Linkury, C:\ProgramData\PrefsSecure\Nettrans.exe.config, Quarantined, [1092], [377396],1.0.5611
Adware.Linkury, C:\ProgramData\PrefsSecure\prefs.xml, Quarantined, [1092], [377396],1.0.5611
Adware.Linkury, C:\ProgramData\Logic Cramble\X64\SQLite.Interop.dll, Quarantined, [1092], [431817],1.0.5611
Adware.Linkury, C:\ProgramData\Logic Cramble\X86\SQLite.Interop.dll, Quarantined, [1092], [431817],1.0.5611
Adware.Linkury, C:\ProgramData\Logic Cramble\Config.json, Quarantined, [1092], [431817],1.0.5611
Adware.Linkury, C:\ProgramData\Logic Cramble\set.exe.config, Quarantined, [1092], [431817],1.0.5611
Adware.Linkury, C:\ProgramData\Logic Cramble\System.Data.SQLite.dll, Quarantined, [1092], [431817],1.0.5611
Adware.Linkury, C:\ProgramData\Logic Cramble\System.Data.SQLite.Linq.dll, Quarantined, [1092], [431817],1.0.5611
Adware.Linkury, C:\ProgramData\Logic Cramble\System.Data.SQLite.xml, Quarantined, [1092], [431817],1.0.5611
PUP.Optional.BundleInstaller, C:\USERS\PC\APPDATA\LOCAL\TEMP\1078456453\ic-0.11ee5ed5453764.exe, Delete-on-Reboot, [400], [463480],1.0.5611
PUP.Optional.BundleInstaller, C:\Users\PC\AppData\Local\Temp\1078456453\dlreport, Quarantined, [400], [463480],1.0.5611
PUP.Optional.BundleInstaller, C:\Users\PC\AppData\Local\Temp\1078456453\ic-0.99af4ba38259b8.exe, Quarantined, [400], [463480],1.0.5611
PUP.Optional.BundleInstaller, C:\USERS\PC\APPDATA\LOCAL\TEMP\1078456453\ic-0.99af4ba38259b8.exe, Quarantined, [400], [463480],1.0.5611
PUP.Optional.BundleInstaller, C:\Users\PC\AppData\Local\Temp\1078456453\dlreport, Quarantined, [400], [463480],1.0.5611
PUP.Optional.BundleInstaller, C:\Users\PC\AppData\Local\Temp\1078456453\ic-0.11ee5ed5453764.exe, Delete-on-Reboot, [400], [463480],1.0.5611
PUP.Optional.Linkury.Generic, C:\PROGRAMDATA\SUBAIRS\FF.HP, Quarantined, [224], [380106],1.0.5611
PUP.Optional.Linkury.Generic, C:\ProgramData\Subairs\ff.NT, Quarantined, [224], [380106],1.0.5611
PUP.Optional.Linkury.Generic, C:\ProgramData\Subairs\snp.sc, Quarantined, [224], [380106],1.0.5611
Adware.Linkury.TskLnk, C:\USERS\PC\APPDATA\LOCAL\INSTALLATIONCONFIGURATION.XML, Quarantined, [14241], [444923],1.0.5611
Adware.Linkury.TskLnk, C:\WINDOWS\SYSWOW64\CONFIG\SYSTEMPROFILE\APPDATA\LOCAL\INSTALLATIONCONFIGURATION.XML, Quarantined, [14241], [444922],1.0.5611
Adware.Linkury.Generic, C:\USERS\PC\APPDATA\LOCAL\CONFIG.XML, Quarantined, [3750], [404859],1.0.5611
Adware.Wdfload.TskLnk, C:\PROGRAM FILES\ACCENT ONLINE PAINTINGS 2007\ACCENT ONLINE PAINTINGS 2007.DLL, Quarantined, [10808], [520698],1.0.5611
Adware.Wdfload.TskLnk, C:\PROGRAM FILES\THEPAKE\THEPAKE.DLL, Quarantined, [10808], [520698],1.0.5611
Adware.Adposhel, C:\USERS\PC\APPDATA\LOCAL\TEMP\FKWYW0CS.3Q0\DATA.EXE, Quarantined, [456], [526942],1.0.5611
Trojan.BitCoinMiner, C:\USERS\PC\APPDATA\LOCAL\TEMP\L5CB5DML.PVG\MSERVICESX.EXE, Delete-on-Reboot, [525], [533758],1.0.5611
Adware.Linkury, C:\USERS\PC\APPDATA\LOCAL\TEMP\RARSFX0\LOGICHANDLER.EXE, Quarantined, [1092], [504848],1.0.5611
Trojan.BitCoinMiner, C:\USERS\PC\APPDATA\LOCAL\TEMP\IA2ORHDZ.GMD\MSERVICESX.EXE, Delete-on-Reboot, [525], [533758],1.0.5611
Trojan.Wdfload, C:\WINDOWS\TEMP\G79F2.TMP.EXE, Quarantined, [6178], [483347],1.0.5611
Adware.Tuto4PC.Generic, C:\USERS\PC\APPDATA\LOCAL\TEMP\0O8WA4GHCG\0O8W.EXE, Quarantined, [3715], [533379],1.0.5611
Adware.Linkury, C:\USERS\PC\APPDATA\LOCAL\TEMP\JDGY24IE.MBW\STARTER.EXE, Delete-on-Reboot, [1092], [475745],1.0.5611
Adware.Tuto4PC.Generic, C:\USERS\PC\APPDATA\LOCAL\TEMP\12K54ZZ4JB\12K5.EXE, Quarantined, [3715], [533379],1.0.5611
Adware.Linkury, C:\USERS\PC\APPDATA\LOCAL\TEMP\PLLNY0KE.3QW\STARTER.EXE, Delete-on-Reboot, [1092], [475745],1.0.5611
Trojan.BitCoinMiner, C:\WINDOWS\TEMP\NTCDYBVYOA.EXE, Quarantined, [525], [533758],1.0.5611
Trojan.BitCoinMiner, C:\USERS\PC\APPDATA\LOCAL\TEMP\V3UTAJGO.IKJ\MSERVICESX.EXE, Delete-on-Reboot, [525], [533758],1.0.5611
Adware.Linkury, C:\USERS\PC\APPDATA\LOCAL\TEMP\JMLUQ1KJ.S4P\STARTER.EXE, Delete-on-Reboot, [1092], [475745],1.0.5611
Adware.Adposhel, C:\USERS\PC\APPDATA\LOCAL\TEMP\MZBMTXO0.J51\DATA.EXE, Quarantined, [456], [526942],1.0.5611
PUP.Optional.Linkury.Generic, C:\USERS\PC\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Sync Data\SyncData.sqlite3, Replaced, [224], [454805],1.0.5611
PUP.Optional.Linkury.Generic, C:\USERS\PC\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Web Data, Replaced, [224], [454805],1.0.5611
Adware.Linkury, C:\USERS\PC\APPDATA\LOCAL\RANITY.EXE, Delete-on-Reboot, [1092], [475745],1.0.5611
PUP.Optional.SonicSearch, C:\USERS\PC\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\Default\Web Data, Replaced, [341], [519968],1.0.5611

Physical Sector: 0
(No malicious items detected)

WMI: 0
(No malicious items detected)


(end)



#5 armone

armone
  • Topic Starter

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:04:40 PM

Posted 24 June 2018 - 08:25 AM

Thanks a lot for this, In my Program files there is no SystemaRav anymore. What you think is my PC safe now?



#6 nasdaq

nasdaq

  • Malware Response Team
  • 39,954 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:10:40 AM

Posted 24 June 2018 - 01:09 PM

Hi,

Looking good.

If all is well.

To learn more about how to protect yourself while on the internet read this little guide best security practices keep safe.
http://www.bleepingcomputer.com/forums/t/407147/answers-to-common-security-questions-best-practices/


https://www.bleepingcomputer.com/tutorials/keep-your-computer-safe-online/
Simple and easy ways to keep your computer safe and secure on the Internet.
===




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users