JeanO
Active member
- Apr 25, 2018
- 25
Hello.
I've moved my issue over here from the BSOD section - see that posting for description of the issue.
A new MSE full scan this morning shows nothing heinous.
Here are fresh logs as requested in your wiki:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 25.04.2018Ran by 2018Jean (26-04-2018 10:15:08)
Running from C:\Users\2018Jean\Desktop\Cooties\FRST scans
Windows 7 Home Premium Service Pack 1 (X64) (2014-05-11 04:17:47)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
2018Jean (S-1-5-21-4256033146-2562541644-1532691662-1006 - Administrator - Enabled) => C:\Users\2018Jean
Administrator (S-1-5-21-4256033146-2562541644-1532691662-500 - Administrator - Enabled) => C:\Users\Administrator
Guest (S-1-5-21-4256033146-2562541644-1532691662-501 - Administrator - Enabled)
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Microsoft Security Essentials (Enabled - Up to date) {B7ECF8CD-0188-6703-DBA4-AA65C6ACFB0A}
AS: Microsoft Security Essentials (Enabled - Up to date) {0C8D1929-27B2-688D-E114-9117BD2BB1B7}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
AC3Filter (remove only) (HKLM-x32\...\AC3Filter) (Version: - )
ACID Pro 7.0 (HKLM-x32\...\{BFA5441E-B7E6-46F5-A15D-1B74707AE93A}) (Version: 7.0.641 - Sony)
Acronis Drive Monitor (HKLM-x32\...\{706AE61D-40A4-4F50-8359-FE8F6F7FA461}) (Version: 1.0.566 - Acronis)
Adobe Acrobat 7.0 Professional - English, Français, Deutsch (HKLM-x32\...\Adobe Acrobat 7.0 Professional - English, Français, Deutsch - V) (Version: 7.0.0 - Adobe Systems)
Adobe Flash Player 13 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 13.0.0.214 - Adobe Systems Incorporated)
Adobe Flash Player 18 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 18.0.0.232 - Adobe Systems Incorporated)
Adobe Flash Player 23 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 23.0.0.162 - Adobe Systems Incorporated)
Adobe GoLive CS2 English (HKLM-x32\...\Adobe GoLive CS2 English) (Version: 8.0 - Adobe Systems)
Adobe InDesign CS2 (HKLM-x32\...\Adobe InDesign CS2 - {7F4C8163-F259-49A0-A018-2857A90578BC}) (Version: 004.000.000 - Adobe Systems Incorporated)
Adobe Photoshop CS2 (HKLM-x32\...\Adobe Photoshop CS2 - {236BB7C4-4419-42FD-0409-1E257A25E34D}) (Version: 9.0 - Adobe Systems, Inc.)
Adobe Photoshop CS5.1 (HKLM-x32\...\{9158FF30-78D7-40EF-B83E-451AC5334640}) (Version: 12.1 - Adobe Systems Incorporated)
Adobe Photoshop CS6 (HKLM-x32\...\{74EB3499-8B95-4B5C-96EB-7B342F3FD0C6}) (Version: 13.0 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.07) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.07 - Adobe Systems Incorporated)
Adobe SVG Viewer 3.0 (HKLM-x32\...\Adobe SVG Viewer) (Version: 3.0 - Adobe Systems, Inc.)
Aimersoft Video Converter Ultimate(Build 6.2.0.0) (HKLM-x32\...\Aimersoft Video Converter Ultimate_is1) (Version: 6.2.0.0 - Aimersoft Software)
Airfoil (HKLM-x32\...\Airfoil) (Version: 3.5.0 - Rogue Amoeba)
Alps Pointing-device for VAIO (HKLM\...\{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}) (Version: - ALPS ELECTRIC CO., LTD.)
ArcSoft WebCam Companion 3 (HKLM-x32\...\{DE8AAC73-6D8D-483E-96EA-CAEDDADB9079}) (Version: 3.0.21.390 - ArcSoft)
ASIO Bridge and Hi-Fi Cable (HKLM-x32\...\VB:ASIOBridge {17359A74-1236-5467}) (Version: - VB-Audio Software)
Audacity 2.0.5 (HKLM-x32\...\Audacity_is1) (Version: 2.0.5 - Audacity Team)
Avidemux 2.6 - 64bits (HKLM-x32\...\Avidemux 2.6 - 64bits (64-bit)) (Version: 2.6.8.9046 - )
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Callcentric Softphone (HKLM-x32\...\{CEA83C20-AFCB-426C-89ED-0AC90015F04B}) (Version: 2.0.4 - Callcentric)
Canon IJ Scan Utility (HKLM-x32\...\Canon_IJ_Scan_Utility) (Version: - Canon Inc.)
Canon MG2500 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG2500_series) (Version: 1.02 - Canon Inc.)
Canon MG2500 series On-screen Manual (HKLM-x32\...\Canon MG2500 series On-screen Manual) (Version: 7.6.1 - Canon Inc.)
Canon MG2500 series User Registration (HKLM-x32\...\Canon MG2500 series User Registration) (Version: - *Canon Inc.)
Canon My Printer (HKLM-x32\...\CanonMyPrinter) (Version: 3.1.0 - Canon Inc.)
CCleaner (HKLM\...\CCleaner) (Version: 4.15 - Piriform)
Cisco EAP-FAST Module (HKLM-x32\...\{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}) (Version: 2.2.14 - Cisco Systems, Inc.)
Cisco LEAP Module (HKLM-x32\...\{51C7AD07-C3F6-4635-8E8A-231306D810FE}) (Version: 1.0.19 - Cisco Systems, Inc.)
Cisco PEAP Module (HKLM-x32\...\{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}) (Version: 1.1.6 - Cisco Systems, Inc.)
Core Temp 1.1 (HKLM\...\{086D343F-8E78-4AFC-81AC-D6D414AFD8AC}_is1) (Version: 1.1 - Alcpu)
CrystalDiskInfo 7.6.0 (HKLM-x32\...\CrystalDiskInfo_is1) (Version: 7.6.0 - Crystal Dew World)
D3DX10 (HKLM-x32\...\{E09C4DB7-630C-4F06-A631-8EA7239923AF}) (Version: 15.4.2368.0902 - Microsoft) Hidden
Desktop Restore version 1.6.4 (HKLM\...\{DBD4F07A-7607-4A4F-A46C-6AA399E06E38}_is1) (Version: 1.6.4 - Jamie O'Connell)
DLNow 1.2 (HKLM-x32\...\DLNow) (Version: 1.2 - Logixoft)
DNS Leak Fix for OpenVPN version 1.2 (HKLM-x32\...\{8CFA1D01-AECD-4913-9FB8-1E8A82F47824}_is1) (Version: 1.2 - dnsleaktest.com)
Doxillion Document Converter (HKLM-x32\...\Doxillion) (Version: 2.71 - NCH Software)
Dream Aquarium (HKLM-x32\...\Dream Aquarium) (Version: - )
DVD Audio Extractor 7.2.0 (HKLM-x32\...\DVD Audio Extractor_is1) (Version: - Computer Application Studio)
DVD Decrypter (Remove Only) (HKLM-x32\...\DVD Decrypter) (Version: - )
Express Burn Disc Burning Software (HKLM-x32\...\ExpressBurn) (Version: 6.09 - NCH Software)
Fast Duplicate File Finder 4.1.0.1 (HKLM-x32\...\{AFECFED6-0A43-488F-8511-1DC6B52F31C3}_is1) (Version: 4.1.0.1 - MindGems, Inc.)
FBReader for Windows (HKLM-x32\...\FBReader for Windows) (Version: - )
FileZilla Client 3.14.0 (HKLM-x32\...\FileZilla Client) (Version: 3.14.0 - Tim Kosse)
Folder Colorizer version 1.3.3 (HKLM\...\{A133E9CD-2879-4F30-87D4-1604AFD5C5CC}_is1) (Version: 1.3.3 - Softorino)
Folder Size 3.4.0.0 (HKLM-x32\...\{2DFA85ED-588F-4CE3-A175-29E52C3804A8}_is1) (Version: 3.4.0.0 - MindGems, Inc.)
Gihosoft Free Youtube Downloader version 1.2.7.0 (HKLM-x32\...\{222ECA2E-17A6-4914-922A-BABE02869072}_is1) (Version: 1.2.7.0 - HONGKONG JIHO CO., LIMITED)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 66.0.3359.117 - Google Inc.)
Google Drive (HKLM-x32\...\{9BC95947-92FD-438B-A168-C01F9A5B7292}) (Version: 2.34.7529.6838 - Google, Inc.)
Google Talk Plugin (HKLM-x32\...\{F9B579C2-D854-300A-BE62-A09EB9D722E4}) (Version: 5.41.3.0 - Google)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.7 - Google Inc.) Hidden
Google Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.25.11 - Google Inc.) Hidden
ImgBurn (HKLM-x32\...\ImgBurn) (Version: 2.5.8.0 - LIGHTNING UK!)
InstallShield Tuner 7.0 for Adobe Acrobat (HKLM-x32\...\{E32FC3D8-D106-425E-9F9E-8BE6E2E79AC9}) (Version: 7.0 - Adobe)
IObit Unlocker (HKLM-x32\...\IObit Unlocker_is1) (Version: 1.1 - IObit)
ISO Opener (HKLM-x32\...\{CE235F00-F8CD-41AF-83D5-236D90E33BFB}_is1) (Version: - ISO Opener)
Java 8 Update 73 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218073F0}) (Version: 8.0.730.2 - Oracle Corporation)
JBidwatcher 2.5.6 (HKLM-x32\...\JBidwatcher_0) (Version: 2.5.6 - CyberFOX Software, Inc)
JBidwatcher 2.5.6 (HKLM-x32\...\JBidwatcher_1) (Version: 2.5.6 - CyberFOX Software, Inc)
LAME v3.99.3 (for Windows) (HKLM-x32\...\LAME_is1) (Version: - )
LightScribe System Software (HKLM-x32\...\{F132000C-1CBA-458F-BF2F-FD43D59410F9}) (Version: 1.18.27.10 - LightScribe)
LightScribe Template Designs - Expressions (HKLM-x32\...\{A5CC4D86-371A-4044-A7F3-C6CFCC4CA813}) (Version: 1.18.8.111 - LightScribe)
LightScribe Template Designs - Music Pack 1 (HKLM-x32\...\{4ECA4128-8B48-44A0-90E8-B93C6A69CE4B}) (Version: 1.15.0.0 - LightScribe)
LightScribe Template Labeler (HKLM-x32\...\{8A03241E-7A3C-401D-B0CE-B3096F50AE6F}) (Version: 1.18.27.10 - LightScribe)
Loan*Calculator! Plus v3.0 (HKLM-x32\...\{D1A42E6B-7D3D-4B46-AA82-659FF905CA40}_is1) (Version: 3.0 - Pine Grove Software, LLC)
Malwarebytes version 3.4.5.2467 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.4.5.2467 - Malwarebytes)
Mediatek RT2870 Wireless LAN Card (HKLM-x32\...\{28DA7D8B-F9A4-4F18-8AA0-551B1E084D0D}) (Version: 1.5.38.101 - MediatekWiFi)
Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation)
Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.8.204.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40416.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{CA8A885F-E95B-3FC6-BB91-F4D9377C7686}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Motorola Device Manager (HKLM-x32\...\{28DB8373-C1BB-444F-A427-A55585A12ED7}) (Version: 2.5.4 - Motorola Mobility)
Movie Maker (HKLM-x32\...\{38F03569-A636-4CF3-BDDE-032C8C251304}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Movie Maker (HKLM-x32\...\{DD67BE4B-7E62-4215-AFA3-F123A800A389}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Mozilla Firefox 57.0 (x64 en-US) (HKLM\...\Mozilla Firefox 57.0 (x64 en-US)) (Version: 57.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 57.0.0.6525 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
Nero 2015 (HKLM-x32\...\{763EF8DC-4CC0-47CA-BE1C-BDE731462250}) (Version: 16.0.02900 - Nero AG)
Nero Info (HKLM-x32\...\{B791E0AB-87A9-41A4-8D98-D13C2E37D928}) (Version: 16.0.1003 - Nero AG)
NETGEAR Genie (HKLM-x32\...\NETGEAR Genie) (Version: 2.4.12.00 - NETGEAR Inc.)
NexusFont 2.5 (ver 2.5.8.1582) (HKLM-x32\...\{EFEDD205-43FE-4208-B682-0937E803E19E}_is1) (Version: - xiles)
NirSoft BlueScreenView (HKLM-x32\...\NirSoft BlueScreenView) (Version: - )
NVIDIA GeForce Experience 2.1.1 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.1.1 - NVIDIA Corporation)
NVIDIA Graphics Driver 337.88 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 337.88 - NVIDIA Corporation)
NVIDIA HD Audio Driver 1.3.30.1 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.30.1 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.13.1220 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.1220 - NVIDIA Corporation)
OpenOffice 4.1.0 (HKLM-x32\...\{C87EF11D-36E9-479D-9898-7541EA1E8A6A}) (Version: 4.10.9764 - Apache Software Foundation)
PeaZip 6.5.1 (WIN64) (HKLM\...\{5A2BC38A-406C-4A5B-BF45-6991F9A05325}_is1) (Version: 6.5.1 - Giorgio Tani)
Perfect Resize 7.0.1 Professional Edition (HKLM-x32\...\{FCADA4FF-142C-42A8-B73C-0A54A7F83345}) (Version: 7.0.1 - onOne Software)
Pismo File Mount Audit Package (HKLM\...\PismoFileMountAuditPackage) (Version: - )
Prerequisite installer (HKLM-x32\...\{799AFA36-4EA5-4323-8689-74C06645A26B}) (Version: 16.0.0000 - Nero AG) Hidden
Prism Video File Converter (HKLM-x32\...\Prism) (Version: - NCH Software)
Prismatik (remove only) (HKLM-x32\...\{2175EE1B-0160-4862-9096-C522B1B99042}_is1) (Version: 5.11.1 - Woodenshark LLC)
PVSonyDll (HKLM\...\{3D3E663D-4E7E-4577-A560-7ECDDD45548A}) (Version: 1.00.0001 - NVIDIA Corporation) Hidden
QuickGamma 2.0.0.3 (HKLM-x32\...\QuickGamma_is1) (Version: - Eberhard Werle)
QuickTime Alternative 1.81 (HKLM-x32\...\QuicktimeAlt_is1) (Version: 1.81 - )
RBVirtualFolder64Inst (HKLM\...\{9D6DFAD6-09E5-445E-A4B5-A388FEEBD90D}) (Version: 1.00.0000 - Roxio, Inc.) Hidden
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6098 - Realtek Semiconductor Corp.)
REALTEK Wireless LAN Driver and Utility (HKLM-x32\...\{9C049509-055C-4CFF-A116-1D12312225EB}) (Version: 1.00.0199 - REALTEK Semiconductor Corp.)
Remote Keyboard (HKLM-x32\...\{25AF1025-095C-4AA9-A3FD-29710D3C3AE5}) (Version: 1.1.1.07060 - Sony Corporation) Hidden
Renesas Electronics USB 3.0 Host Controller Driver (HKLM-x32\...\{5442DAB8-7177-49E1-8B22-09A049EA5996}) (Version: 2.0.4.1 - Renesas Electronics Corporation) Hidden
Renesas Electronics USB 3.0 Host Controller Driver (HKLM-x32\...\InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}) (Version: 2.0.4.1 - Renesas Electronics Corporation)
River Past Audio Converter Pro (HKLM\...\Audio Converter Pro) (Version: 7.7.1 - River Past)
Roxio Creator 2011 Content (HKLM-x32\...\{9F717571-FEE8-45CD-8B03-5B2D06AD28F7}) (Version: 13.0.098 - Roxio)
Roxio Creator 2011 Pro (HKLM-x32\...\{4433FF9E-AF21-4E41-B296-4E13BF4D52F5}) (Version: 13.0 - Roxio)
Roxio PhotoShow (HKLM-x32\...\Roxio PhotoShow) (Version: 6.0 - Sonic Solutions)
SeaMonkey 2.26.1 (x86 en-US) (HKLM-x32\...\SeaMonkey 2.26.1 (x86 en-US)) (Version: 2.26.1 - Mozilla)
Serviio (HKLM\...\Serviio) (Version: - )
SHIELD Streaming (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GFExperience.NvStreamSrv) (Version: 3.1.100 - NVIDIA Corporation) Hidden
SmartSound Common Data (HKLM-x32\...\{B8A2869E-30CA-40C5-9CF8-BD7354E57EF8}) (Version: 1.1.0 - SmartSound Software Inc.) Hidden
SmartSound Common Data (HKLM-x32\...\InstallShield_{B8A2869E-30CA-40C5-9CF8-BD7354E57EF8}) (Version: 1.1.0 - SmartSound Software Inc.)
SmartSound Quicktracks 5 (HKLM-x32\...\{2F8BA3FD-1FA9-4279-B696-712ABB12F09F}) (Version: 5.1.7 - SmartSound Software Inc.) Hidden
SmartSound Quicktracks 5 (HKLM-x32\...\InstallShield_{2F8BA3FD-1FA9-4279-B696-712ABB12F09F}) (Version: 5.1.7 - SmartSound Software Inc.)
SmartWi Connection Utility (HKLM-x32\...\{9B5F85CA-90D4-4AFC-BB37-32477FD0D2B9}) (Version: 4.8.4.20090902.2130 - Sony)
SoftEther VPN Client (HKLM\...\softether_sevpnclient) (Version: 4.12.9514 - SoftEther VPN Project)
Song Surgeon 4.0.2.3 (HKLM-x32\...\{03853A8E-10F5-463D-8888-4D69C7C5VD1Z}_is1) (Version: - Todd, Michael & James, Inc.)
Sony Home Network Library (HKLM-x32\...\{9E39EA0D-38CD-4739-9E28-DEA4A1155522}) (Version: 2.0.0.07280 - Sony Corporation) Hidden
Sony Home Network Library (HKLM-x32\...\{D03D02D8-AB64-4785-A48E-5AA8B0FB8C14}) (Version: 2.0.0.07280 - Sony Corporation)
SoundLeech 1.0.3275.20306 (HKLM\...\{B5213A55-2258-4C85-B19E-5E5CA0B36F40}_is1) (Version: - MiLo Software)
SpeedFan (remove only) (HKLM-x32\...\SpeedFan) (Version: - )
SQLite_3_7_8_x64 (HKLM\...\{DD54C205-43D6-4959-B97A-E52DB4A199C7}) (Version: 3.7.8.0 - Sony Corporation) Hidden
StartupMonitor (HKLM-x32\...\{76EFAC4F-1712-401F-B2AE-590B170C9BCE}) (Version: 1.0.2.0 - Mike Lin)
StuffIt 2009 (HKLM-x32\...\{7204C956-B01F-4344-9F10-67485DBE7D15}) (Version: 13.0.0 - Smith Micro)
StuffIt Expander 2011 (HKLM\...\{6B62B973-49F5-4C51-B738-93B56A963417}) (Version: 15.0.7.2518 - Smith Micro Software, Inc.)
Switch Sound File Converter (HKLM-x32\...\Switch) (Version: 4.79 - NCH Software)
Unchecky v1.2 (HKLM-x32\...\Unchecky) (Version: 1.2 - Reason Software Company Inc.)
VAIO - Remote Keyboard (HKLM-x32\...\{7396FB15-9AB4-4B78-BDD8-24A9C15D2C65}) (Version: 1.1.0.07060 - Sony Corporation)
VAIO - Xperia Link (HKLM-x32\...\{D91558BF-D1F3-411F-AEFE-8774CB406512}) (Version: 1.4.0.15030 - Sony Corporation)
VAIO Care (HKLM\...\{6EEC3E9C-3479-42EB-B93C-E7DF7927DD82}) (Version: 8.4.4.09181 - Sony Corporation)
VAIO Care (HKLM-x32\...\{00B03993-F5A1-47B1-9C54-EC8FBDDDE17E}) (Version: 6.4.2.11150 - Sony Corporation) Hidden
VAIO Care Recovery (HKLM\...\{6ED1750E-F44F-4635-8F0D-B76B9262B7FB}) (Version: 1.1.1.13230 - Sony Corporation)
VAIO Control Center (HKLM-x32\...\{72042FA6-5609-489F-A8EA-3C2DD650F667}) (Version: 4.3.0.05310 - Sony Corporation)
VAIO Health Report (HKLM-x32\...\VAIO Health Report1.0) (Version: 1.0 - Sony Electronics)
VAIO Media plus (HKLM-x32\...\{8DE50158-80AA-4FF2-9E9F-0A7C46F71FCD}) (Version: 2.0.0.07280 - Sony Corporation)
VAIO Media plus Opening Movie (HKLM-x32\...\{6BF03C88-C06A-48DC-B9A1-FE72B24E5FA9}) (Version: 2.0.0.07030 - Sony Corporation)
VAIO Platform Update Program (HKLM-x32\...\{69DABBAD-F800-4060-9730-CCA6FFDC2D23}) (Version: 1.1.0.12290 - Sony Corporation)
VAIO Update (HKLM-x32\...\{9FF95DA2-7DA1-4228-93B7-DED7EC02B6B2}) (Version: 7.2.0.16270 - Sony Corporation)
VBCABLE, The Virtual Audio Cable (HKLM\...\VB:VBCABLE {87459874-1236-4469}) (Version: - VB-Audio Software)
VD64Inst (HKLM\...\{DB9C43F7-0B0F-4E43-9E6B-F945C71C469E}) (Version: 1.00.0000 - Roxio, Inc.) Hidden
Vegas Movie Studio HD Platinum 10.0 (HKLM-x32\...\{40AE01BE-A290-4FFB-8DAB-C624C17DC87E}) (Version: 10.0.179 - Sony)
Vegas Pro 10.0 (64-bit) (HKLM\...\{C616FD4F-11F5-11E0-A38F-0013D3D69929}) (Version: 10.0.470 - Sony)
VideoPad Video Editor (HKLM-x32\...\VideoPad) (Version: 3.24 - NCH Software)
Virtual Account Numbers (HKLM-x32\...\{0134662F-5B97-4D60-9A24-B81B6A56DEF7}) (Version: 1.0.6.0 - Citi) Hidden
Virtual Account Numbers (HKLM-x32\...\{DE700910-58F7-4D2E-B7E6-3BA2DA1B6806}) (Version: 4.0.0.2260 - Citi)
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.6 - VideoLAN)
VUx64 (HKLM\...\{A0A2BE14-D3FF-41C8-9545-4B130E3FE9A4}) (Version: 1.2.0 - Sony Corporation) Hidden
VUx86 (HKLM-x32\...\{D04F1D22-4A47-42C6-A2B9-094A7B844D9B}) (Version: 1.2.0 - Sony Corporation) Hidden
Windows Driver Package - Atheros Communications Inc. (athr) Net (02/12/2010 9.0.0.125) (HKLM\...\62D2521666DCF9EBEC983E0344A3DEE15CF2C6D3) (Version: 02/12/2010 9.0.0.125 - Atheros Communications Inc.)
Windows Driver Package - Ricoh Company MS Host Controller (04/27/2010 6.13.03.03) (HKLM\...\329BC6C693EDBAE5D333838328DDCBF99FE39773) (Version: 04/27/2010 6.13.03.03 - Ricoh Company)
Windows Driver Package - Sony Corporation (SFEP) HIDClass (11/27/2009 8.0.1.2) (HKLM\...\4E827A70BAA738C408DBDD024BCACE5085D946F1) (Version: 11/27/2009 8.0.1.2 - Sony Corporation)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation)
WizMouse v1.7.0.3 (HKLM-x32\...\WizMouse_is1) (Version: - Antibody Software)
Xiph.Org Open Codecs 0.85.17777 (HKLM-x32\...\Open Codecs) (Version: 0.85.17777 - Xiph.Org)
XperiaLinkx86 (HKLM-x32\...\{EE402ACB-8269-4E44-9CA1-D81FDC4B4545}) (Version: 1.0.0 - Sony Corporation) Hidden
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
ShellIconOverlayIdentifiers: [ GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2017-11-10] (Google)
ShellIconOverlayIdentifiers: [ GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2017-11-10] (Google)
ShellIconOverlayIdentifiers: [ GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2017-11-10] (Google)
ShellIconOverlayIdentifiers: [0WinSecurityProvider] -> {F76FA5C2-3B6A-451E-8CA5-34C8D0AE0637} => -> No File
ShellIconOverlayIdentifiers: [{4BBAAAE9-0004-4000-9AA5-1BBD98C86E9B}] -> {4BBAAAE9-0004-4000-9AA5-1BBD98C86E9B} => C:\Windows\system32\pfmshx_A1C.dll [2014-07-11] (Pismo Technic Inc.)
ShellIconOverlayIdentifiers-x32: [{4BBAAAE9-0004-4000-9AA5-1BBD98C86E9B}] -> {4BBAAAE9-0004-4000-9AA5-1BBD98C86E9B} => C:\Windows\system32\pfmshx_A1C.dll [2014-07-11] (Pismo Technic Inc.)
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => -> No File
ContextMenuHandlers1-x32: [Adobe.Acrobat.ContextMenu] -> {D25B2CAB-8A9A-4517-A9B2-CB5F68A5A802} => C:\Program Files (x86)\Adobe\Acrobat 7.0\Acrobat Elements\ContextMenu.dll [2004-12-14] (Adobe Systems Inc.)
ContextMenuHandlers1-x32: [AimersoftVideoConverterFileOpreation] -> {1AACB93E-AA97-47F1-BD02-8D2AF2815436} => C:\Windows\SysWOW64\AiCM64.dll [2013-08-23] ()
ContextMenuHandlers1-x32: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => c:\Program Files\Microsoft Security Client\shellext.dll [2015-04-30] (Microsoft Corporation)
ContextMenuHandlers1-x32: [GDContextMenu] -> {BB02B294-8425-42E5-983F-41A1FA970CD6} => C:\Program Files (x86)\Google\Drive\contextmenu64.dll [2017-11-10] (Google)
ContextMenuHandlers1-x32-x32: [StuffItContextMenuHandler] -> {8B2B7A32-7D7B-48AB-838D-70AAC410985F} => C:\Program Files (x86)\Stuffit\SxShellExtEN.dll [2008-12-19] (Smith Micro Software, Inc.)
ContextMenuHandlers1-x32-x32: [UnLockerMenu] -> {410BF280-86EF-4E0F-8279-EC5848546AD3} => C:\Program Files (x86)\IObit\IObit Unlocker\IObitUnlockerExtension.dll [2014-03-04] (IObit)
ContextMenuHandlers1-x32-x32: [{4BBAAAE9-0001-4A1C-9AA5-1BBD98C86E9B}] -> {4BBAAAE9-0001-4A1C-9AA5-1BBD98C86E9B} => C:\Windows\system32\pfmshx_A1C.dll [2014-07-11] (Pismo Technic Inc.)
ContextMenuHandlers2: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => c:\Program Files\Microsoft Security Client\shellext.dll [2015-04-30] (Microsoft Corporation)
ContextMenuHandlers2: [{4BBAAAE9-0002-4A1C-9AA5-1BBD98C86E9B}] -> {4BBAAAE9-0002-4A1C-9AA5-1BBD98C86E9B} => C:\Windows\system32\pfmshx_A1C.dll [2014-07-11] (Pismo Technic Inc.)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-03-27] (Malwarebytes)
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => -> No File
ContextMenuHandlers4: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => c:\Program Files\Microsoft Security Client\shellext.dll [2015-04-30] (Microsoft Corporation)
ContextMenuHandlers4: [FolderColorize] -> {3443FE61-F294-403D-A4A6-53E034FC9B3F} => C:\Program Files\Folder Colorizer\FolderColorShlExt.dll [2014-06-10] ()
ContextMenuHandlers4: [GDContextMenu] -> {BB02B294-8425-42E5-983F-41A1FA970CD6} => C:\Program Files (x86)\Google\Drive\contextmenu64.dll [2017-11-10] (Google)
ContextMenuHandlers4-x32: [StuffItContextMenuHandler] -> {8B2B7A32-7D7B-48AB-838D-70AAC410985F} => C:\Program Files (x86)\Stuffit\SxShellExtEN.dll [2008-12-19] (Smith Micro Software, Inc.)
ContextMenuHandlers4-x32: [UnLockerMenu] -> {410BF280-86EF-4E0F-8279-EC5848546AD3} => C:\Program Files (x86)\IObit\IObit Unlocker\IObitUnlockerExtension.dll [2014-03-04] (IObit)
ContextMenuHandlers5: [DeskMenu] -> {7E74422F-2393-11D4-98E0-444553540000} => C:\Program Files\Desktop Restore\dkticnsr.dll [2014-07-14] (Jamie O'Connell)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\Windows\system32\nvshext.dll [2014-05-19] (NVIDIA Corporation)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-03-27] (Malwarebytes)
ContextMenuHandlers6: [UnLockerMenu] -> {410BF280-86EF-4E0F-8279-EC5848546AD3} => C:\Program Files (x86)\IObit\IObit Unlocker\IObitUnlockerExtension.dll [2014-03-04] (IObit)
ContextMenuHandlers6: [{4BBAAAE9-0002-4A1C-9AA5-1BBD98C86E9B}] -> {4BBAAAE9-0002-4A1C-9AA5-1BBD98C86E9B} => C:\Windows\system32\pfmshx_A1C.dll [2014-07-11] (Pismo Technic Inc.)
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {00F7D842-030F-48FE-8D06-8D1A8EC0DFAC} - System32\Tasks\Sanipplesnipples => C:\Program Files (x86)\coordinator\coordinator.exe
Task: {02F2E36D-CE54-461C-A711-83D7C6A526A2} - System32\Tasks\SONY\SUS-BCF\Level4Daily => C:\Program Files (x86)\Sony\Setting Utility Series\WBCBatteryCare.exe [2010-07-26] (Sony Corporation)
Task: {12909958-B0B1-4E3A-A143-388DAD924286} - System32\Tasks\Sony Corporation\VAIO Care\GetPOTInfo => C:\Program Files\Sony\VAIO Care\VCSystemTray.exe [2015-08-20] (Sony Corporation)
Task: {1389A02B-E9F7-4625-8452-29315733282E} - System32\Tasks\Sony Corporation\VAIO Care\UploadPOT => C:\Program Files\Sony\VAIO Care\VCSystemTray.exe [2015-08-20] (Sony Corporation)
Task: {172C0947-0AB8-4CBB-A502-468E6D8E4112} - System32\Tasks\Sony Corporation\VAIO Care\UpdateSolution => C:\Program Files\Sony\VAIO Care\Solution.Updater.exe [2015-07-23] (Sony Corporation)
Task: {1C0D1E3A-C3E3-4827-8115-7BD8BB778650} - System32\Tasks\Sony Corporation\VAIO Care\ActiveStatusCollect => C:\Program Files\Sony\VAIO Care\VCSystemTray.exe [2015-08-20] (Sony Corporation)
Task: {3111D1B9-B867-4FF2-BCCD-6FA05999E5C2} - System32\Tasks\Sony Corporation\VAIO Care\VAIO Care => C:\Program Files\Sony\VAIO Care\VCsystray.exe [2011-02-16] (Sony Corporation)
Task: {33F3B133-5DE3-4ACF-ADC4-EE8C3FFAB152} - System32\Tasks\Sony Corporation\VAIO Update\VAIO Update => C:\Program Files\Sony\VAIO Update\VAIOUpdt.exe [2016-04-25] (Sony Corporation)
Task: {36CFE37E-9401-4318-90D2-4EC5FAEE387F} - System32\Tasks\Sony Corporation\VAIO Care\DeployCRMflag => C:\Program Files\Sony\VAIO Care\DeployCRMflag.exe [2015-02-04] (Sony Corporation)
Task: {45BADC05-BF63-4EA7-B530-5B196060609F} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-4256033146-2562541644-1532691662-1000Core1d1ab1c50e3feb1 => C:\Users\New User\AppData\Local\Google\Update\GoogleUpdate.exe
Task: {46A8BA8B-1CE2-49F1-88A7-AFEFD8DD1072} - System32\Tasks\GoogleUpdateTaskMachineCore1d1e99a24383211 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {4715A3F3-DA5C-4314-B0E6-AEE7B4002171} - System32\Tasks\Motorola Device Manager Initial Update => C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotorolaDeviceManagerUpdate.exe [2014-10-30] ()
Task: {56E4ED33-FD67-4111-AD2E-69432965D13C} - System32\Tasks\{E14845C5-AD07-455E-8AF1-87FDF860E69C} => C:\Windows\system32\pcalua.exe -a "C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma.cpl" -c Adobe Gamma
Task: {5896892F-6738-4626-9A26-98F4AA20F245} - System32\Tasks\VAIO Health Report => C:\Program Files (x86)\Sony\VAIO Health Report\VAIOHealthReport.exe [2013-06-20] (Sony Electronics)
Task: {5942F092-08C3-41C9-8568-F7010BD67E6B} - System32\Tasks\Sony Corporation\VAIO Update\Launch Application => C:\Program Files\SONY\VAIO Update\ShellExeProxy.exe [2016-03-31] (Sony Corporation)
Task: {5C1FD1BA-43C9-4FFB-B90D-DA7274C2101E} - System32\Tasks\Sony Corporation\VAIO Care\CheckSystemInfo => C:\Program Files\Sony\VAIO Care\VCSystemTray.exe [2015-08-20] (Sony Corporation)
Task: {5CE22FDF-C337-4FF1-9589-1D174EF6BA8E} - \Speedial -> No File <==== ATTENTION
Task: {633FE891-475B-499C-B85E-F3C6BEB45993} - System32\Tasks\USER_ESRV_SVC => "C:\Windows\System32\Wscript.exe" //B //NoLogo "C:\Program Files\Sony\VAIO Care\ESRV\task.vbs"
Task: {79DC2A95-1F93-417E-A28F-B99128B2DE38} - System32\Tasks\Core Temp Autostart Guest => C:\Program Files\Core Temp\Core Temp.exe [2016-06-05] ()
Task: {7A0844AA-1700-4006-B982-8FB6D0AC37EB} - System32\Tasks\Sony Corporation\VAIO Care\VCCheckIolo => C:\Program Files\Sony\VAIO Care\VCSystemTray.exe [2015-08-20] (Sony Corporation)
Task: {7EFD4D10-58C8-43AA-9467-9C5F5DF65A3E} - System32\Tasks\DLNowUpdateTask => C:\Program Files (x86)\DLNow\bin\youtube-dl.exe [2018-04-25] ()
Task: {9255924D-D507-4E08-A7A4-F494A3A78200} - System32\Tasks\{19FA1E7F-C63E-4A46-97A3-3F34BC31D6C0} => C:\Windows\system32\pcalua.exe -a C:\Users\2018Jean\Desktop\dft32_v416_b00.EXE -d C:\Users\2018Jean\Desktop
Task: {96247089-FA26-44E2-A435-C81629491635} - System32\Tasks\Motorola Device Manager Update => C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotorolaDeviceManagerUpdate.exe [2014-10-30] ()
Task: {9B66F097-A61A-4505-97F4-D136CAF3DC42} - System32\Tasks\WizMouse => C:\Program Files (x86)\WizMouse\WizMouseLaunch.exe [2013-09-22] ()
Task: {A9DC085E-8031-42FC-9286-2DC168612277} - System32\Tasks\Sony Corporation\VAIO Care\VCSelfHeal => C:\Program Files\Sony\VAIO Care\VCSystemTray.exe [2015-08-20] (Sony Corporation)
Task: {AF252B0B-E42B-4D00-BCDB-8087257A2F0B} - System32\Tasks\Sony Corporation\VAIO Care\VCOneClick => C:\Program Files\Sony\VAIO Care\VCOneClick.exe [2011-02-16] (Sony Corporation)
Task: {B6A45865-55DB-4260-8D17-9BAD8B97876F} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-06-24] (Piriform Ltd)
Task: {C1F04433-F138-496F-A132-861EA809CBE6} - System32\Tasks\Sony Corporation\VAIO Care\VCMetrics => C:\Program Files\Sony\VAIO Care\VCSystemTray.exe [2015-08-20] (Sony Corporation)
Task: {C4E2C798-680B-487D-B008-7809887D2534} - System32\Tasks\Sony Corporation\VAIO Update\VAIO Update Self Repair => C:\Program Files\Sony\VAIO Update\VUSR.exe [2016-03-31] (Sony Corporation)
Task: {CF664104-E476-4498-8903-5DC6BB8CBFC7} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {CFEFD686-64CA-4CB6-8B24-A9BC74A06F8B} - System32\Tasks\SONY\SUS-BCF\Level4Month => C:\Program Files (x86)\Sony\Setting Utility Series\WBCBatteryCare.exe [2010-07-26] (Sony Corporation)
Task: {D1983ABB-C6BA-45ED-8684-92D2239F2B29} - System32\Tasks\Core Temp Autostart New User => C:\Program Files\Core Temp\Core Temp.exe [2016-06-05] ()
Task: {D1DC2A75-83A9-4B63-A3FD-5000634057BD} - System32\Tasks\{B2B6C2B3-3D98-4570-9059-8CAE5C80B819} => C:\Windows\system32\pcalua.exe -a "C:\Program Files (x86)\QuickTime Alternative\QTSystem\quicktime.cpl"
Task: {E0781AF7-ACCE-4AD7-BE9C-6A9E065CD550} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-4256033146-2562541644-1532691662-1000UA => C:\Users\New User\AppData\Local\Google\Update\GoogleUpdate.exe
Task: {E17FC308-0BBA-4584-B370-6CF6A9D7A881} - System32\Tasks\Sony Corporation\Xperia Link\Xperia Link Logon Start => C:\Program Files (x86)\Sony\Xperia Link\Xperia Link.exe [2016-03-04] (Sony Corporation)
Task: {F38A7085-3FF2-497A-BF8B-A4DF91339F0F} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {F70FE2A2-D569-48A5-BBFA-53AEC4C1DF0A} - System32\Tasks\nipples => C:\Program Files (x86)\coordinator\coordinator.exe
Task: {F8CB3FC4-A45A-4D7D-918D-452AD83D7E94} - System32\Tasks\Sony Corporation\VAIO Care\VCRLog => C:\Program Files\Sony\VAIO Care\VCSystemTray.exe [2015-08-20] (Sony Corporation)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1cfefa3f2c4ad03.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d0001ea16c3dbf.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d04271c398541a.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d09037628ad6c3.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d0bfebbe8ed6e2.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d0e18bf9f2edac.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d0ef4ea319fbef.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d12d0428a12f73.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d15cfba1559c9f.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d1636af991dfb9.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d1ab1afe70b3f7.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4256033146-2562541644-1532691662-1000Core.job => C:\Users\New User\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4256033146-2562541644-1532691662-1000Core1d0efb33f722634.job => C:\Users\New User\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4256033146-2562541644-1532691662-1000Core1d12eecce9d9c72.job => C:\Users\New User\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4256033146-2562541644-1532691662-1000Core1d15dc7972a45f8.job => C:\Users\New User\AppData\Local\Google\Update\GoogleUpdate.exe
==================== Shortcuts & WMI ========================
(The entries could be listed to be restored or removed.)
Shortcut: C:\Users\2018Jean\Favorites\NCH Software Download Site.lnk -> hxxp://www.nchsoftware.com/index.htm
ShortcutWithArgument: C:\Users\2018Jean\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Chrome Remote Desktop.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=gbchcmhmhahfdphkhkmpfmihenigjmpp
ShortcutWithArgument: C:\Users\2018Jean\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\5d696d521de238c3\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default
==================== Loaded Modules (Whitelisted) ==============
2014-05-26 17:01 - 2014-05-19 21:25 - 000116568 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2015-09-16 08:12 - 2015-09-16 08:12 - 000043480 _____ () C:\Program Files (x86)\FileZilla FTP Client\fzshellext_64.dll
2015-04-19 11:56 - 2014-06-10 12:53 - 000137528 _____ () C:\Program Files\Folder Colorizer\FolderColorShlExt.dll
2014-07-19 19:27 - 2013-08-23 13:36 - 000721263 _____ () C:\Windows\SysWOW64\AiCM64.dll
2010-07-14 04:00 - 2010-07-14 04:00 - 000032240 _____ () C:\Program Files (x86)\Roxio\BackOnTrack\App\BService.exe
2015-03-21 04:54 - 2015-03-21 04:54 - 000327680 _____ () C:\Program Files\Serviio\bin\ServiioService.exe
2015-08-26 13:06 - 2015-08-26 13:06 - 000413336 _____ () C:\Program Files\Sony\VAIO Care\ESRV\esrv_svc.exe
2015-08-26 13:06 - 2015-08-26 13:06 - 000709272 _____ () C:\Program Files\Sony\VAIO Care\ESRV\intel_modeler.dll
2015-08-26 13:06 - 2015-08-26 13:06 - 000130712 _____ () C:\Program Files\Sony\VAIO Care\ESRV\intel_process_input.dll
2015-08-26 13:06 - 2015-08-26 13:06 - 000025752 _____ () C:\Program Files\Sony\VAIO Care\ESRV\intel_system_power_state_input.dll
2015-08-26 13:06 - 2015-08-26 13:06 - 000059544 _____ () C:\Program Files\Sony\VAIO Care\ESRV\intel_quality_and_reliability_input.dll
2015-08-26 13:06 - 2015-08-26 13:06 - 000194712 _____ () C:\Program Files\Sony\VAIO Care\ESRV\acpi_battery_input.dll
2015-08-26 13:06 - 2015-08-26 13:06 - 000159896 _____ () C:\Program Files\Sony\VAIO Care\ESRV\sema_thermal_input.dll
2015-08-26 13:06 - 2015-08-26 13:06 - 000158360 _____ () C:\Program Files\Sony\VAIO Care\ESRV\wifi_input.dll
2015-08-26 13:06 - 2015-08-26 13:06 - 000050840 _____ () C:\Program Files\Sony\VAIO Care\ESRV\devices_use_input.dll
2015-08-26 13:06 - 2015-08-26 13:06 - 000032920 _____ () C:\Program Files\Sony\VAIO Care\ESRV\intel_disktrace_input.dll
2010-07-13 21:23 - 2010-07-13 21:23 - 000084464 _____ () C:\Program Files (x86)\Roxio 2011\5.0\CPMonitor.exe
2014-05-21 18:34 - 2009-08-26 17:11 - 000017408 _____ () C:\Program Files (x86)\Sony\SmartWi Connection Utility\CCP.exe
2018-03-22 15:00 - 2018-03-22 15:00 - 003406336 _____ () C:\Users\2018Jean\AppData\Local\wmcagent\wmcagent.exe
2014-05-21 18:34 - 2009-08-26 17:11 - 000017920 _____ () C:\Program Files (x86)\Sony\SmartWi Connection Utility\ThirdPartyAppMgr.exe
2014-05-21 18:34 - 2009-08-26 17:11 - 000033792 _____ () C:\Program Files (x86)\Sony\SmartWi Connection Utility\PowerManager.exe
2018-04-25 15:15 - 2018-04-17 01:01 - 004443992 _____ () C:\Program Files (x86)\Google\Chrome\Application\66.0.3359.117\libglesv2.dll
2018-04-25 15:15 - 2018-04-17 01:01 - 000099672 _____ () C:\Program Files (x86)\Google\Chrome\Application\66.0.3359.117\libegl.dll
2010-07-14 04:00 - 2010-07-14 04:00 - 001587696 _____ () C:\Program Files (x86)\Roxio\BackOnTrack\App\BEngine.dll
2010-07-14 04:00 - 2010-07-14 04:00 - 000107504 _____ () C:\Program Files (x86)\Roxio\BackOnTrack\App\Logging.dll
2015-09-22 12:48 - 2012-11-06 09:47 - 000114688 _____ () C:\Program Files (x86)\Realtek\USB Wireless LAN Utility\EnumDevLib.dll
2014-06-25 20:33 - 2010-05-31 19:18 - 000013824 _____ () C:\Program Files (x86)\Sony\VAIO Event Service\VESBasePS.dll
2014-06-25 20:33 - 2010-05-31 19:18 - 000013312 _____ () C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSubPS.dll
2013-07-20 15:13 - 2013-07-20 15:13 - 000165480 _____ () C:\Windows\SysWOW64\AirfoilInject3.dll
2014-05-21 18:34 - 2009-08-26 17:11 - 000120320 _____ () C:\Program Files (x86)\Sony\SmartWi Connection Utility\SonyCommonLib.dll
2014-05-21 18:34 - 2009-08-26 17:11 - 000007680 _____ () C:\Program Files (x86)\Sony\SmartWi Connection Utility\DebugMsg.dll
2014-05-21 18:34 - 2009-08-26 17:11 - 000009728 _____ () C:\Program Files (x86)\Sony\SmartWi Connection Utility\Resources.dll
2014-05-21 18:34 - 2009-08-26 17:11 - 000015360 _____ () C:\Program Files (x86)\Sony\SmartWi Connection Utility\SharedInterfaces.dll
2014-05-21 18:34 - 2009-08-26 17:11 - 000018944 _____ () C:\Program Files (x86)\Sony\SmartWi Connection Utility\DictionaryLookup.dll
2014-05-21 18:34 - 2009-08-26 17:11 - 000011264 _____ () C:\Program Files (x86)\Sony\SmartWi Connection Utility\MessageXML.dll
2016-03-05 14:42 - 2016-03-05 14:42 - 047517184 _____ () C:\Users\2018Jean\AppData\Local\wmcagent\libcef.dll
2016-08-23 14:19 - 2016-08-23 14:19 - 001414144 _____ () C:\Users\2018Jean\AppData\Local\wmcagent\CrackCaptchaAPI.dll
2016-08-23 14:19 - 2016-08-23 14:19 - 000419328 _____ () C:\Users\2018Jean\AppData\Local\wmcagent\lua5.dll
2016-08-23 14:19 - 2016-08-23 14:19 - 000124928 _____ () C:\Users\2018Jean\AppData\Local\wmcagent\cjson.dll
2016-08-22 12:41 - 2016-08-22 12:41 - 000101888 _____ () C:\Users\2018Jean\AppData\Local\wmcagent\lcurl.dll
2014-05-21 18:34 - 2009-08-26 17:11 - 000081408 _____ () C:\Program Files (x86)\Sony\SmartWi Connection Utility\DevicePanel.dll
2014-05-21 18:34 - 2009-08-26 17:11 - 000005120 _____ () C:\Program Files (x86)\Sony\SmartWi Connection Utility\Kinoubi.Plugins.PluginManager.ThirdPartyApp.dll
2014-05-21 18:34 - 2009-08-26 17:11 - 000023040 _____ () C:\Program Files (x86)\Sony\SmartWi Connection Utility\Kinoubi.Plugins.PluginManager.Generic.dll
2014-05-21 18:34 - 2009-08-26 17:11 - 000027648 _____ () C:\Program Files (x86)\Sony\SmartWi Connection Utility\Kinoubi.Plugins.Plugin.BtPower.dll
2014-05-21 18:34 - 2009-08-26 17:11 - 000005120 _____ () C:\Program Files (x86)\Sony\SmartWi Connection Utility\Kinoubi.Plugins.Plugin.Generic.dll
2014-05-21 18:34 - 2009-08-26 17:11 - 000015360 _____ () C:\Program Files (x86)\Sony\SmartWi Connection Utility\Kinoubi.Plugins.Plugin.NativeWifiThirdPartyApp.dll
2014-05-21 18:34 - 2009-08-26 17:11 - 000011264 _____ () C:\Program Files (x86)\Sony\SmartWi Connection Utility\Kinoubi.Plugins.Plugin.TosBtThirdPartyApp.dll
2014-05-21 18:34 - 2009-08-26 17:11 - 000007168 _____ () C:\Program Files (x86)\Sony\SmartWi Connection Utility\Kinoubi.Plugins.Plugin.WlanPower.dll
2014-05-21 18:34 - 2009-08-26 17:11 - 000004608 _____ () C:\Program Files (x86)\Sony\SmartWi Connection Utility\Kinoubi.Plugins.PluginManager.Power.dll
2016-03-05 14:42 - 2016-03-05 14:42 - 001576960 _____ () C:\Users\2018Jean\AppData\Local\wmcagent\libglesv2.dll
2016-03-05 14:42 - 2016-03-05 14:42 - 000074752 _____ () C:\Users\2018Jean\AppData\Local\wmcagent\libegl.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
AlternateDataStreams: C:\Windows:nlsPreferences [0]
==================== Safe Mode (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\plsapp => ""="service"
==================== Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2014-09-19 15:54 - 2018-04-25 17:25 - 000002047 _____ C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 localhost
0.0.0.0 0.0.0.0 # fix for traceroute and netstat display anomaly
0.0.0.0 tracking.opencandy.com.s3.amazonaws.com
0.0.0.0 media.opencandy.com
0.0.0.0 cdn.opencandy.com
0.0.0.0 tracking.opencandy.com
0.0.0.0 api.opencandy.com
0.0.0.0 api.recommendedsw.com
0.0.0.0 rp.yefeneri2.com
0.0.0.0 os.yefeneri2.com
0.0.0.0 os2.yefeneri2.com
0.0.0.0 installer.betterinstaller.com
0.0.0.0 installer.filebulldog.com
0.0.0.0 d3oxtn1x3b8d7i.cloudfront.net
0.0.0.0 inno.bisrv.com
0.0.0.0 nsis.bisrv.com
0.0.0.0 cdn.file2desktop.com
0.0.0.0 cdn.goateastcach.us
0.0.0.0 cdn.guttastatdk.us
0.0.0.0 cdn.inskinmedia.com
0.0.0.0 cdn.insta.oibundles2.com
0.0.0.0 cdn.insta.playbryte.com
0.0.0.0 cdn.llogetfastcach.us
0.0.0.0 cdn.montiera.com
0.0.0.0 cdn.msdwnld.com
0.0.0.0 cdn.mypcbackup.com
0.0.0.0 cdn.ppdownload.com
0.0.0.0 cdn.riceateastcach.us
0.0.0.0 cdn.shyapotato.us
0.0.0.0 cdn.solimba.com
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-4256033146-2562541644-1532691662-1006\Control Panel\Desktop\\Wallpaper -> DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 1) (EnableLUA: 1)
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Acrobat Speed Launcher.lnk => C:\Windows\pss\Adobe Acrobat Speed Launcher.lnk.CommonStartup
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^SoftEther VPN Client Manager Startup.lnk => C:\Windows\pss\SoftEther VPN Client Manager Startup.lnk.CommonStartup
MSCONFIG\startupreg: Acrobat Assistant 7.0 => "C:\Program Files (x86)\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
MSCONFIG\startupreg: Acronis Scheduler2 Service => "C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe"
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: AdobeAAMUpdater-1.0 => "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
MSCONFIG\startupreg: AdobeCS6ServiceManager => "C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin
MSCONFIG\startupreg: Aimersoft Helper Compact.exe => C:\Program Files (x86)\Common Files\Aimersoft\Aimersoft Helper Compact\ASHelper.exe
MSCONFIG\startupreg: Desktop Disc Tool => "C:\Program Files (x86)\Roxio 2011\Roxio Burn\RoxioBurnLauncher.exe"
MSCONFIG\startupreg: LightScribe Control Panel => C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
MSCONFIG\startupreg: SoftEther VPN Client UI Helper => "C:\Program Files\SoftEther VPN Client\vpnclient_x64.exe" /uihelp
MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
MSCONFIG\startupreg: Virtual Account Numbers => C:\Users\NEWUSE~1\Desktop\CITIVI~1\CitiVAN.exe /lang=en_RG /dontopenmycards
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [{2CF04BE8-6CB7-426E-87E3-443822B9A514}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{C296184F-C227-4713-B174-243ABDA04E6C}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{C5C518B4-86AF-4027-987D-669619A5A3BF}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
FirewallRules: [{2D5B7835-F8DD-4027-8C30-FA0E38A820A5}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
FirewallRules: [{E0A2AA88-06EA-4DC1-985C-BEA2B91B0965}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{76D20174-CA61-42BF-957C-3182D16A2267}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [TCP Query User{E5396464-C096-44DD-9C9C-C9E70DD24C67}C:\program files\ftpwanderer.exe] => (Allow) C:\program files\ftpwanderer.exe
FirewallRules: [UDP Query User{2A565AA3-9DBC-49CA-BEA8-990BD55777CD}C:\program files\ftpwanderer.exe] => (Allow) C:\program files\ftpwanderer.exe
FirewallRules: [TCP Query User{EB90B550-47E4-40BE-99DB-56F72A70635F}C:\program files (x86)\airfoil\airfoil.exe] => (Allow) C:\program files (x86)\airfoil\airfoil.exe
FirewallRules: [UDP Query User{5BBCC7AF-5563-44DE-BAF5-04FAFC24751E}C:\program files (x86)\airfoil\airfoil.exe] => (Allow) C:\program files (x86)\airfoil\airfoil.exe
FirewallRules: [{4592994F-1A98-4637-B054-66DF68050396}] => (Block) C:\program files (x86)\airfoil\airfoil.exe
FirewallRules: [{CBE3AA6C-3F2B-49E9-81CD-37300559E7C2}] => (Block) C:\program files (x86)\airfoil\airfoil.exe
FirewallRules: [TCP Query User{395E59A3-FE0C-49FF-B30B-A65C5CD2445E}C:\program files (x86)\airfoil\airfoilspeakers.exe] => (Allow) C:\program files (x86)\airfoil\airfoilspeakers.exe
FirewallRules: [UDP Query User{7754B78D-9D14-4E9F-9142-AE33E8E5FF18}C:\program files (x86)\airfoil\airfoilspeakers.exe] => (Allow) C:\program files (x86)\airfoil\airfoilspeakers.exe
FirewallRules: [{88485275-5EA1-459F-84B5-89C2E34230D9}] => (Block) C:\program files (x86)\airfoil\airfoilspeakers.exe
FirewallRules: [{D84C9003-E681-47F2-A258-9DBC93386DE3}] => (Block) C:\program files (x86)\airfoil\airfoilspeakers.exe
FirewallRules: [{E396AD23-C425-441E-9010-CF148DB3C78C}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{6409AF99-EFD5-4489-9F55-FF78F5857EB4}] => (Allow) LPort=2869
FirewallRules: [{CA56823E-F76E-4F0C-8B76-61B4A2B97020}] => (Allow) LPort=1900
FirewallRules: [TCP Query User{7607D4FC-971D-49FD-A14B-D746D9BB5894}C:\program files (x86)\videolan\vlc\vlc.exe] => (Allow) C:\program files (x86)\videolan\vlc\vlc.exe
FirewallRules: [UDP Query User{DB641E5D-EEBC-4F32-AE79-2812B5BD92D3}C:\program files (x86)\videolan\vlc\vlc.exe] => (Allow) C:\program files (x86)\videolan\vlc\vlc.exe
FirewallRules: [{42DDB0D2-48BA-4088-8BC7-60821D32647F}] => (Allow) C:\Program Files\SoftEther VPN Client\vpncmd.exe
FirewallRules: [{930758F4-F0FA-404C-8254-4CA698743038}] => (Allow) C:\Program Files\SoftEther VPN Client\vpncmgr.exe
FirewallRules: [{EB9525D5-145F-425D-9DE4-7610E925F082}] => (Allow) C:\Program Files\SoftEther VPN Client\vpncmgr_x64.exe
FirewallRules: [{EDA9D5AB-6059-4F57-9BA7-13CFFD8EA9E3}] => (Allow) C:\Program Files\SoftEther VPN Client\vpnclient.exe
FirewallRules: [{2FC8BAB5-49F6-4954-A990-BF928D55F6D9}] => (Allow) C:\Program Files\SoftEther VPN Client\vpnclient_x64.exe
FirewallRules: [{F5C61075-AFB7-4922-9A30-34D045D98F48}] => (Allow) C:\Program Files\SoftEther VPN Client\vpncmd_x64.exe
FirewallRules: [{063EB077-C6E2-4B8B-A140-96E5E5DF9735}] => (Allow) C:\Windows\explorer.exe
FirewallRules: [{0E8CA58E-D591-41C5-B047-EED091B8D663}] => (Allow) C:\Windows\system32\rundll32.exe
FirewallRules: [TCP Query User{1BA97C60-8921-4FCB-95BB-36E4DDAF8FD2}C:\program files (x86)\netgear genie\bin\netgeargenie.exe] => (Allow) C:\program files (x86)\netgear genie\bin\netgeargenie.exe
FirewallRules: [UDP Query User{57D3F1BB-95FF-4D51-A8C6-EC5E99FE608E}C:\program files (x86)\netgear genie\bin\netgeargenie.exe] => (Allow) C:\program files (x86)\netgear genie\bin\netgeargenie.exe
FirewallRules: [{B7A616F4-11E4-4395-892E-CE63AD5D5B17}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{2453CD04-EF1E-4985-9F1A-F379B751D9B9}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{5F45E1E2-E0DE-4373-806B-880AD30688B2}] => (Allow) C:\Program Files (x86)\Realtek\USB Wireless LAN Utility\RtWLan.exe
FirewallRules: [{EB667CDB-CBE6-49BA-92BB-4CE900836A8E}] => (Allow) C:\Program Files (x86)\Realtek\USB Wireless LAN Utility\RtWLan.exe
FirewallRules: [{2544F6BE-597E-445D-9EC3-48102EB0304F}] => (Allow) LPort=1542
FirewallRules: [{E6E19DDA-3C9D-4317-9796-9E057E76DCC1}] => (Allow) LPort=1542
FirewallRules: [{748CD8B3-0360-4523-B7EF-87ED0A50323F}] => (Allow) LPort=53
FirewallRules: [{5F20B306-74DF-4363-94CF-B3E937B01E8D}] => (Allow) C:\Program Files (x86)\MediatekWiFi\Common\RaMediaServer.exe
FirewallRules: [{34393942-319F-4450-B74D-6A3D5854B9DA}] => (Allow) C:\Program Files (x86)\MediatekWiFi\Common\RaMediaServer.exe
FirewallRules: [{BA1B9B4B-E7C0-462A-A835-7558CEE2DAF2}] => (Allow) C:\Program Files (x86)\MediatekWiFi\Common\RaUI.exe
FirewallRules: [{2DB9CEAE-0E43-4EDB-9D88-97C086FF95B7}] => (Allow) LPort=67
FirewallRules: [{F18D36AD-580F-4E37-B727-7091DAA9B7F0}] => (Allow) LPort=68
FirewallRules: [{CC22FF8C-3558-4419-8161-E129054A10C2}] => (Allow) LPort=53
FirewallRules: [{4CBB465C-F887-4950-BFA1-9358262CC2F3}] => (Allow) LPort=53
FirewallRules: [{34C53CB0-FE9A-4DB6-B15F-A51E97C935B6}] => (Allow) C:\Program Files (x86)\Realtek\USB Wireless LAN Utility\Rtldhcp.exe
FirewallRules: [TCP Query User{CD93C2D2-E82D-4969-91B7-A6F303BE3235}C:\program files (x86)\callcentric\callcentric softphone\callcentric.exe] => (Allow) C:\program files (x86)\callcentric\callcentric softphone\callcentric.exe
FirewallRules: [UDP Query User{1F7EB81A-09E3-40CC-BE0F-8B6075A29B71}C:\program files (x86)\callcentric\callcentric softphone\callcentric.exe] => (Allow) C:\program files (x86)\callcentric\callcentric softphone\callcentric.exe
FirewallRules: [TCP Query User{CD029BCC-19A7-4340-B504-F18A27E184BE}C:\program files (x86)\filezilla ftp client\filezilla.exe] => (Allow) C:\program files (x86)\filezilla ftp client\filezilla.exe
FirewallRules: [UDP Query User{3DE96037-7FAD-47BB-A1B0-C59A83A0B0B5}C:\program files (x86)\filezilla ftp client\filezilla.exe] => (Allow) C:\program files (x86)\filezilla ftp client\filezilla.exe
FirewallRules: [{7B242E38-2D4F-438F-9DF9-ABA2BE340438}] => (Allow) C:\Program Files\Sony\VAIO Care\VCAgent.exe
FirewallRules: [{4DA46A1F-86C4-44BF-965B-83BD1EF1655C}] => (Allow) C:\Program Files\Sony\VAIO Care\VCAdmin.exe
FirewallRules: [{6052E95E-48ED-443C-B45E-B2F103E23ADB}] => (Allow) C:\Program Files\Sony\VAIO Care\VCSystemTray.exe
FirewallRules: [{6C8DB5CB-4FE9-4034-A8CC-74EAC8D533DA}] => (Allow) C:\Program Files\Sony\VAIO Care\VAIOShell.exe
FirewallRules: [{6FE38D40-D843-442E-8193-CF49F871B811}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{9F1A3DBB-D8D9-48A6-A4DB-F6E4D6C7EA8A}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{29204BD5-66AA-46FF-9E2B-62845C0E39B7}C:\program files\serviio\jre\bin\javaw.exe] => (Allow) C:\program files\serviio\jre\bin\javaw.exe
FirewallRules: [UDP Query User{CD709486-5A60-4707-B99B-D26172468A31}C:\program files\serviio\jre\bin\javaw.exe] => (Allow) C:\program files\serviio\jre\bin\javaw.exe
FirewallRules: [{D6089E07-8A0C-41AB-A4C9-269F3141228C}] => (Allow) C:\Program Files\Serviio\bin\ServiioService.exe
FirewallRules: [{DE333EF5-0110-46DA-A946-C3DB012799C8}] => (Allow) C:\Program Files\Serviio\bin\ServiioService.exe
FirewallRules: [{48B2AD10-3253-4D52-B0EE-A7D4A45F00EF}] => (Allow) C:\Program Files\Serviio\bin\ServiioConsole.exe
FirewallRules: [{ABD9CC4F-7124-4A2F-A409-F2BA2B646471}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{A705390D-6100-4309-ACFD-2BB825970F02}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{1992C8FE-AB9D-408D-B2C0-5CB151151523}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{2A3D0737-6132-4ECC-803F-BE512344CC55}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{6EC71A4A-289A-46B8-BA63-52B691DDD9B5}] => (Allow) C:\Program Files (x86)\Song Surgeon 4\SongSurgeon4.exe
FirewallRules: [{0E4789F4-9F90-4ABB-9FBC-E8B0BF1FE640}] => (Allow) C:\Program Files (x86)\Song Surgeon 4\SongSurgeon4reg.exe
FirewallRules: [{EAA1B54E-3D4F-4D16-9FC0-2953FA06D4A2}] => (Allow) C:\Program Files (x86)\Song Surgeon 4\MusicPad.exe
FirewallRules: [{6686CD8F-E5B1-44DD-B405-8869DA7DF07C}] => (Allow) C:\Program Files (x86)\Song Surgeon 4\BatchFileConverter.exe
FirewallRules: [{DC8A0E7B-E613-419B-A8A0-859C3A23A3CA}] => (Allow) C:\Program Files (x86)\Song Surgeon 4\SongSurgeon4.exe
FirewallRules: [{FC2AA9AA-CE8F-4F35-8308-455DDBFF0830}] => (Allow) C:\Program Files (x86)\Song Surgeon 4\SongSurgeon4reg.exe
FirewallRules: [{5800D832-8925-44D7-8D65-1DB635D72582}] => (Allow) C:\Program Files (x86)\Song Surgeon 4\MusicPad.exe
FirewallRules: [{5A0930F7-1DFE-4652-ADAD-9F34948B71C6}] => (Allow) C:\Program Files (x86)\Song Surgeon 4\BatchFileConverter.exe
FirewallRules: [{D6924CD1-DF03-4B19-AE6E-16A158F838C8}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdater.exe
FirewallRules: [{FED7BEC2-D498-452A-98FD-A5B7AF585508}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
FirewallRules: [{F20F9F2C-408D-48C1-83E7-447F20263304}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
FirewallRules: [{91A82756-D605-4CD4-960D-3B9C27D731BA}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
FirewallRules: [{2EFAC593-95AF-4FC9-9E75-75A39A653A0F}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
FirewallRules: [{F4D66D4B-D0FF-4824-B85C-E0A020ACD526}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
FirewallRules: [TCP Query User{D6BE3D14-AC0D-43D9-AD0F-DD4AF113E43C}C:\program files (x86)\netgear genie\bin\netgeargenie.exe] => (Allow) C:\program files (x86)\netgear genie\bin\netgeargenie.exe
FirewallRules: [UDP Query User{D93C0AA3-2221-4781-B763-E66056BA84F3}C:\program files (x86)\netgear genie\bin\netgeargenie.exe] => (Allow) C:\program files (x86)\netgear genie\bin\netgeargenie.exe
FirewallRules: [TCP Query User{4553BA8C-7A9A-4212-ACF7-9ED1491E883D}C:\program files (x86)\kodi\kodi.exe] => (Allow) C:\program files (x86)\kodi\kodi.exe
FirewallRules: [UDP Query User{E93C4BD1-249F-4E15-8DD6-A5D531F7FC1D}C:\program files (x86)\kodi\kodi.exe] => (Allow) C:\program files (x86)\kodi\kodi.exe
FirewallRules: [{DCAF63CE-91A7-431E-B07A-103C63097553}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{0C27EC27-5C06-4517-B565-D273A3E54232}] => (Allow) C:\Program Files (x86)\Chalice\Slighting.exe
FirewallRules: [{AA8902D0-920F-457C-88F9-511E9EB562C3}] => (Allow) C:\Program Files (x86)\Eduard\Slighting.exe
FirewallRules: [{6CD507BF-7CFA-4BD9-B5D3-201CC3F9FDBA}] => (Allow) C:\Program Files (x86)\fighter\undermining.exe
FirewallRules: [{CEE8DED6-E113-4B37-AA7C-008C57328790}] => (Allow) C:\Program Files (x86)\Eduard\undermining.exe
==================== Restore Points =========================
==================== Faulty Device Manager Devices =============
Name: Teredo Tunneling Pseudo-Interface
Description: Microsoft Teredo Tunneling Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
==================== Event log errors: =========================
Application errors:
==================
Error: (04/26/2018 10:18:02 AM) (Source: Acronis Scheduler) (EventID: 1) (User: )
Description: Scheduler is unable to run task with GUID 'E8EB23E7-2D44-49CD-BDBA-301B0BD1C9E3' because of error 2 (Failed to find the file (folder) or the key (value) in the registry.).
Error: (04/26/2018 10:18:02 AM) (Source: Acronis Scheduler) (EventID: 1) (User: )
Description: Scheduler is unable to run task with GUID 'C73DF26C-DA36-4B34-A03E-033834498780' because of error 2 (Failed to find the file (folder) or the key (value) in the registry.).
Error: (04/26/2018 10:17:01 AM) (Source: Acronis Scheduler) (EventID: 1) (User: )
Description: Scheduler is unable to run task with GUID 'C73DF26C-DA36-4B34-A03E-033834498780' because of error 2 (Failed to find the file (folder) or the key (value) in the registry.).
Error: (04/26/2018 10:16:02 AM) (Source: Acronis Scheduler) (EventID: 1) (User: )
Description: Scheduler is unable to run task with GUID 'E8EB23E7-2D44-49CD-BDBA-301B0BD1C9E3' because of error 2 (Failed to find the file (folder) or the key (value) in the registry.).
Error: (04/26/2018 10:16:01 AM) (Source: Acronis Scheduler) (EventID: 1) (User: )
Description: Scheduler is unable to run task with GUID 'C73DF26C-DA36-4B34-A03E-033834498780' because of error 2 (Failed to find the file (folder) or the key (value) in the registry.).
Error: (04/26/2018 10:15:01 AM) (Source: Acronis Scheduler) (EventID: 1) (User: )
Description: Scheduler is unable to run task with GUID 'C73DF26C-DA36-4B34-A03E-033834498780' because of error 2 (Failed to find the file (folder) or the key (value) in the registry.).
Error: (04/26/2018 10:14:02 AM) (Source: Acronis Scheduler) (EventID: 1) (User: )
Description: Scheduler is unable to run task with GUID 'E8EB23E7-2D44-49CD-BDBA-301B0BD1C9E3' because of error 2 (Failed to find the file (folder) or the key (value) in the registry.).
Error: (04/26/2018 10:14:01 AM) (Source: Acronis Scheduler) (EventID: 1) (User: )
Description: Scheduler is unable to run task with GUID 'C73DF26C-DA36-4B34-A03E-033834498780' because of error 2 (Failed to find the file (folder) or the key (value) in the registry.).
System errors:
Error: (04/26/2018 09:46:38 AM) (Source: volsnap) (EventID: 14) (User: )
Description: The shadow copies of volume C: were aborted because of an IO failure on volume C:.
Error: (04/26/2018 09:46:38 AM) (Source: Disk) (EventID: 11) (User: )
Description: The driver detected a controller error on \Device\Harddisk0\DR0.
Error: (04/26/2018 09:46:38 AM) (Source: Disk) (EventID: 11) (User: )
Description: The driver detected a controller error on \Device\Harddisk0\DR0.
Error: (04/26/2018 09:46:38 AM) (Source: Disk) (EventID: 11) (User: )
Description: The driver detected a controller error on \Device\Harddisk0\DR0.
Error: (04/26/2018 09:46:38 AM) (Source: Disk) (EventID: 11) (User: )
Description: The driver detected a controller error on \Device\Harddisk0\DR0.
Error: (04/26/2018 09:46:38 AM) (Source: Disk) (EventID: 11) (User: )
Description: The driver detected a controller error on \Device\Harddisk0\DR0.
Error: (04/26/2018 09:46:38 AM) (Source: Disk) (EventID: 11) (User: )
Description: The driver detected a controller error on \Device\Harddisk0\DR0.
Error: (04/26/2018 09:46:38 AM) (Source: Disk) (EventID: 11) (User: )
Description: The driver detected a controller error on \Device\Harddisk0\DR0.
CodeIntegrity:
===================================
Date: 2016-08-14 16:57:47.868
Description:
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\SoftwareDistribution\Download\c4154e707216b0f9ca48a8462c2fdd9e\inst\amd64_microsoft-windows-appid_31bf3856ad364e35_6.1.7601.23455_none_b5d141c3e2043820\appid.sys because the set of per-page image hashes could not be found on the system.
Date: 2016-08-14 16:57:47.572
Description:
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\SoftwareDistribution\Download\c4154e707216b0f9ca48a8462c2fdd9e\inst\amd64_microsoft-windows-appid_31bf3856ad364e35_6.1.7601.23455_none_b5d141c3e2043820\appid.sys because the set of per-page image hashes could not be found on the system.
Date: 2016-08-14 16:57:47.351
Description:
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\SoftwareDistribution\Download\c4154e707216b0f9ca48a8462c2fdd9e\inst\amd64_microsoft-windows-appid_31bf3856ad364e35_6.1.7601.23455_none_b5d141c3e2043820\appid.sys because the set of per-page image hashes could not be found on the system.
Date: 2016-08-14 16:57:47.113
Description:
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\SoftwareDistribution\Download\c4154e707216b0f9ca48a8462c2fdd9e\inst\amd64_microsoft-windows-appid_31bf3856ad364e35_6.1.7601.23455_none_b5d141c3e2043820\appid.sys because the set of per-page image hashes could not be found on the system.
Date: 2016-08-14 16:57:45.980
Description:
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\SoftwareDistribution\Download\c4154e707216b0f9ca48a8462c2fdd9e\inst\amd64_microsoft-windows-appid_31bf3856ad364e35_6.1.7601.23455_none_b5d141c3e2043820\appidapi.dll because the set of per-page image hashes could not be found on the system.
Date: 2016-08-14 16:57:45.771
Description:
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\SoftwareDistribution\Download\c4154e707216b0f9ca48a8462c2fdd9e\inst\amd64_microsoft-windows-appid_31bf3856ad364e35_6.1.7601.23455_none_b5d141c3e2043820\appidapi.dll because the set of per-page image hashes could not be found on the system.
Date: 2016-08-14 16:57:45.469
Description:
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\SoftwareDistribution\Download\c4154e707216b0f9ca48a8462c2fdd9e\inst\amd64_microsoft-windows-appid_31bf3856ad364e35_6.1.7601.23455_none_b5d141c3e2043820\appidapi.dll because the set of per-page image hashes could not be found on the system.
Date: 2016-08-14 16:57:45.215
Description:
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\SoftwareDistribution\Download\c4154e707216b0f9ca48a8462c2fdd9e\inst\amd64_microsoft-windows-appid_31bf3856ad364e35_6.1.7601.23455_none_b5d141c3e2043820\appidapi.dll because the set of per-page image hashes could not be found on the system.
==================== Memory info ===========================
Processor: Intel(R) Core(TM) i7 CPU Q 740 @ 1.73GHz
Percentage of memory in use: 45%
Total physical RAM: 8172.93 MB
Available physical RAM: 4453.06 MB
Total Virtual: 16344.03 MB
Available Virtual: 12364.25 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:465.66 GB) (Free:279.98 GB) NTFS
\\?\Volume{e0097a0f-d8c1-11e3-91fa-806e6f6e6963}\ () (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 465.8 GB) (Disk ID: 3AF72EB9)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=465.7 GB) - (Type=07 NTFS)
==================== End of Addition.txt ============================
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 25.04.2018
Ran by 2018Jean (administrator) on VAIOVPCF13UJEAN (26-04-2018 10:05:45)
Running from C:\Users\2018Jean\Desktop\Cooties\FRST scans
Loaded Profiles: 2018Jean (Available Profiles: 2018Jean & Administrator)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: FRST Tutorial - How to use Farbar Recovery Scan Tool - Malware Removal Guides and Tutorials
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(TOSHIBA CORPORATION) C:\Windows\System32\sbalwomsvc.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Acronis) C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
() C:\Program Files (x86)\Roxio\BackOnTrack\App\BService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Mediatek Inc.) C:\Program Files (x86)\MediatekWiFi\Common\RaRegistry.exe
(Mediatek Inc.) C:\Program Files (x86)\MediatekWiFi\Common\RaRegistry64.exe
(Nalpeiron Ltd.) C:\Windows\SysWOW64\nlssrv32.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Realtek Semiconductor Corp.) C:\Program Files (x86)\Realtek\USB Wireless LAN Utility\RtlService.exe
(Realtek Semiconductor Corp.) C:\Program Files (x86)\Realtek\USB Wireless LAN Utility\RtWLan.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Update\VAIOUpdt.exe
() C:\Users\2018Jean\AppData\Local\tibevus\tibevus.exe
() C:\Program Files\Serviio\bin\ServiioService.exe
() C:\Program Files\Serviio\bin\ServiioService.exe
(SoftEther VPN Project at University of Tsukuba, Japan.) C:\Program Files\SoftEther VPN Client\vpnclient_x64.exe
(Smith Micro Software, Inc.) C:\Program Files (x86)\Stuffit\ArcNameService.exe
(Reason Software Company Inc.) C:\Program Files (x86)\Unchecky\bin\unchecky_svc.exe
(Sony Corporation) C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe
(Reason Software Company Inc.) C:\Program Files (x86)\Unchecky\bin\unchecky_bg.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation) C:\Windows\SysWOW64\dllhost.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Sony Corporation) C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSub.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Update\VUAgent.exe
() C:\Program Files\Sony\VAIO Care\ESRV\esrv_svc.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint\Apoint.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint\ApMsgFwd.exe
(Sony Corporation) C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe
() C:\Program Files (x86)\Roxio 2011\5.0\CPMonitor.exe
(Adobe Systems Inc.) C:\Program Files (x86)\Adobe\Acrobat 7.0\Distillr\acrotray.exe
(ALPS) C:\Program Files\Apoint\Apvfb.exe
() C:\Program Files (x86)\Sony\SmartWi Connection Utility\CCP.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint\ApntEx.exe
() C:\Users\2018Jean\AppData\Local\wmcagent\wmcagent.exe
(Sony Corporation) C:\Program Files (x86)\Sony\SmartWi Connection Utility\SmartWi.exe
() C:\Program Files (x86)\Sony\SmartWi Connection Utility\ThirdPartyAppMgr.exe
() C:\Program Files (x86)\Sony\SmartWi Connection Utility\PowerManager.exe
() C:\Users\2018Jean\AppData\Local\wmcagent\wmcagent.exe
() C:\Users\2018Jean\AppData\Local\wmcagent\wmcagent.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Care\VCPerfService.exe
(Sony of America Corporation) C:\Program Files\Sony\VAIO Care\listener.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Power Management\SPMService.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Care\VCService.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
(Microsoft Corporation) C:\Program Files\Windows NT\Accessories\wordpad.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
() C:\Users\2018Jean\AppData\Local\tibevus\dsrhlzv.exe
() C:\Users\2018Jean\AppData\Local\tibevus\dsrhlzv.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [Apoint] => C:\Program Files\Apoint\Apoint.exe [212480 2010-08-12] (Alps Electric Co., Ltd.)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1337000 2015-04-30] (Microsoft Corporation)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [10775584 2010-08-12] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2040352 2010-08-12] (Realtek Semiconductor)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2403104 2014-07-25] (NVIDIA Corporation)
HKLM-x32\...\Run: [SmartWiHelper] => C:\Program Files (x86)\Sony\SmartWi Connection Utility\SmartWiHelper.exe [80384 2009-09-02] (Sony Electronics Corporation)
HKLM-x32\...\Run: [ISBMgr.exe] => C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe [673136 2010-05-31] (Sony Corporation)
HKLM-x32\...\Run: [RoxWatchTray] => C:\Program Files (x86)\Common Files\Roxio Shared\13.0\SharedCOM\RoxWatchTray13.exe [307184 2010-07-16] (Sonic Solutions)
HKLM-x32\...\Run: [CPMonitor] => C:\Program Files (x86)\Roxio 2011\5.0\CPMonitor.exe [84464 2010-07-13] ()
HKLM-x32\...\Run: [Acrobat Assistant 7.0] => C:\Program Files (x86)\Adobe\Acrobat 7.0\Distillr\Acrotray.exe [483328 2004-12-14] (Adobe Systems Inc.)
HKLM-x32\...\Run: [] => [X]
HKLM\...\Policies\Explorer: [HideSCAHealth] 1
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-21-4256033146-2562541644-1532691662-1006\...\Run: [strategize] => C:\Program Files (x86)\Chalice\Slighting.exe [51200 2018-04-21] ()
HKU\S-1-5-21-4256033146-2562541644-1532691662-1006\...\Run: [csm] => C:\Program Files (x86)\hinch\csm.exe [66835 2018-04-21] ()
HKU\S-1-5-21-4256033146-2562541644-1532691662-1006\...\MountPoints2: {e0097a13-d8c1-11e3-91fa-806e6f6e6963} - D:\setup.exe
HKU\S-1-5-18\...A8F59079A8D5}\localserver32: <==== ATTENTION
AppInit_DLLs-x32: AirfoilInject3.dll => C:\Windows\SysWOW64\AirfoilInject3.dll [165480 2013-07-20] ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk [2018-04-22]
BootExecute: autocheck autochk /k:C *
GroupPolicy: Restriction - Chrome <==== ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{168B82E7-9862-4EFF-BD65-019741808387}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{A05BE37B-DD10-498B-96B2-8361DB992BC6}: [DhcpNameServer] 209.18.47.61 209.18.47.62
Tcpip\..\Interfaces\{C7E88057-3F3C-4EA8-A0E0-BA3B168DF025}: [DhcpNameServer] 192.168.1.1
Internet Explorer:
==================
SearchScopes: HKLM-x32 -> DefaultScope value is missing
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO-x32: AcroIEHlprObj Class -> {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -> C:\Program Files (x86)\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2004-12-14] (Adobe Systems Incorporated)
BHO-x32: No Name -> {17424104-1444-4810-85D7-B4DA413C5A9A} -> No File
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO-x32: AcroIEToolbarHelper Class -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll [2004-12-14] (Adobe Systems Incorporated)
Toolbar: HKLM-x32 - No Name - {7A21A046-B886-4A62-9D69-EF2059B0A27B} - No File
Toolbar: HKLM-x32 - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll [2004-12-14] (Adobe Systems Incorporated)
Handler: WSAMVCUchrome - {086BD280-4613-43B5 - No File
FireFox:
========
FF DefaultProfile: eedbh3od.default
FF ProfilePath: C:\Users\2018Jean\AppData\Roaming\Mozilla\Firefox\Profiles\eedbh3od.default [2018-04-25]
FF HKLM-x32\...\Firefox\Extensions: [AMVCU@Aimersoft.com] - C:\ProgramData\Aimersoft\Video Converter Ultimate\AMVCU@Aimersoft.com
FF Extension: (Aimersoft Video Converter Ultimate) - C:\ProgramData\Aimersoft\Video Converter Ultimate\AMVCU@Aimersoft.com [2014-07-19] [Legacy] [not signed]
FF HKLM-x32\...\Firefox\Extensions: [citius@orbiscom] - C:\Users\New User\Desktop\CitiVirtualCCnumbers => not found
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_23_0_0_162.dll [2016-10-03] ()
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-16] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_23_0_0_162.dll [2016-10-03] ()
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin-x32: @Nero.com/KM -> C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL [2014-08-29] (Nero AG)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-17] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-17] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.6 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-05-08] (Adobe Systems Inc.)
FF ExtraCheck: C:\Program Files (x86)\mozilla firefox\defaults\pref\freezer-settings.js [2014-06-01] <==== ATTENTION (Points to *.cfg file)
FF ExtraCheck: C:\Program Files (x86)\mozilla firefox\mozillaFreezer.cfg [2014-06-01] <==== ATTENTION
Chrome:
=======
CHR DefaultProfile: Default
CHR HomePage: Default -> hxxp://searchab.com/?aff=7&uid=5ca14c5c-4b97-11e2-823a-00214f55a9ec
CHR StartupUrls: Default -> "hxxps://news.google.com/"
CHR Profile: C:\Users\2018Jean\AppData\Local\Google\Chrome\User Data\Default [2018-04-26]
CHR Extension: (Theme Creator) - C:\Users\2018Jean\AppData\Local\Google\Chrome\User Data\Default\Extensions\akpelnjfckgfiplcikojhomllgombffc [2018-04-13]
CHR Extension: (Docs) - C:\Users\2018Jean\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2018-04-13]
CHR Extension: (Google Drive) - C:\Users\2018Jean\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-04-13]
CHR Extension: (YouTube) - C:\Users\2018Jean\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-04-13]
CHR Extension: (Honey) - C:\Users\2018Jean\AppData\Local\Google\Chrome\User Data\Default\Extensions\bmnlcjabgnpnenekpadlanbbkooimhnj [2018-04-15]
CHR Extension: (Adblock Plus) - C:\Users\2018Jean\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2018-04-23]
CHR Extension: (uBlock Origin) - C:\Users\2018Jean\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpalhdlnbpafiamejdnhcphjbkeiagm [2018-04-23]
CHR Extension: (Always Autocomplete) - C:\Users\2018Jean\AppData\Local\Google\Chrome\User Data\Default\Extensions\djcfppnajkeijjkplclmeiddkefeaiel [2018-04-13]
CHR Extension: (Gmail Offline) - C:\Users\2018Jean\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejidjjhkpiempkbhmpbfngldlkglhimk [2018-04-13]
CHR Extension: (Show Hidden Password) - C:\Users\2018Jean\AppData\Local\Google\Chrome\User Data\Default\Extensions\enhinpoafplfmeeefjglkakjegjcakjl [2018-04-13]
CHR Extension: (ZenMate VPN - Best Cyber Security & Unblock) - C:\Users\2018Jean\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdcgdnkidjaadafnichfpabhfomcebme [2018-04-21]
CHR Extension: (Wayback Machine) - C:\Users\2018Jean\AppData\Local\Google\Chrome\User Data\Default\Extensions\fpnmgdkabkmnadcjpehmlllkndpkmiak [2018-04-13]
CHR Extension: (Chrome Remote Desktop) - C:\Users\2018Jean\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbchcmhmhahfdphkhkmpfmihenigjmpp [2018-04-13]
CHR Extension: (Google Docs Offline) - C:\Users\2018Jean\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-04-13]
CHR Extension: (The Camelizer) - C:\Users\2018Jean\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghnomdcacenbmilgjigehppbamfndblo [2018-04-13]
CHR Extension: (Protect My Choices) - C:\Users\2018Jean\AppData\Local\Google\Chrome\User Data\Default\Extensions\hdgloanjhdcenjgiafkpbehddcnonlic [2018-04-13]
CHR Extension: (PixelBlock) - C:\Users\2018Jean\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmpmfcjnflbcoidlgapblgpgbilinlem [2018-04-13]
CHR Extension: (Read Across The Aisle) - C:\Users\2018Jean\AppData\Local\Google\Chrome\User Data\Default\Extensions\knonchlbnkaddhihddlejfchjjnadmeh [2018-04-13]
CHR Extension: (Ugly Email) - C:\Users\2018Jean\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldgiafaliifpknmgofiifianlnbgflgj [2018-04-13]
CHR Extension: (Chrome Web Store Payments) - C:\Users\2018Jean\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-04-13]
CHR Extension: (Checker Plus for Gmail™) - C:\Users\2018Jean\AppData\Local\Google\Chrome\User Data\Default\Extensions\oeopbcgkkoapgobdbedcemjljbihmemj [2018-04-13]
CHR Extension: (Gmail) - C:\Users\2018Jean\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2018-04-13]
CHR Extension: (Chrome Media Router) - C:\Users\2018Jean\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-04-25]
CHR HKLM-x32\...\Chrome\Extension: [nmapfhedmiiikmeicmclonepdhjgmlcn] - C:\ProgramData\Aimersoft\Video Converter Ultimate\AMVCU@Aimersoft.com.crx [2014-07-19]
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
HKLM\SYSTEM\CurrentControlSet\Services\osvgw <==== ATTENTION (Rootkit!)
S3 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
S3 Adobe LM Service; C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [72704 2014-05-31] (Adobe Systems) [File not signed]
R2 BOT4Service; C:\Program Files (x86)\Roxio\BackOnTrack\App\BService.exe [32240 2010-07-14] ()
R2 ESRV_SVC; C:\Program Files\Sony\VAIO Care\ESRV\esrv_svc.exe [413336 2015-08-26] ()
R2 LightScribeService; C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [73728 2013-01-16] (Hewlett-Packard Company) [File not signed]
R2 MediatekRegistryWriter; C:\Program Files (x86)\MediatekWiFi\Common\RaRegistry.exe [401040 2014-07-31] (Mediatek Inc.)
R2 MediatekRegistryWriter64; C:\Program Files (x86)\MediatekWiFi\Common\RaRegistry64.exe [454288 2014-07-31] (Mediatek Inc.)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23816 2015-04-30] (Microsoft Corporation)
S3 NETGEARGenieDaemon; C:\Program Files (x86)\NETGEAR Genie\bin\NETGEARGenieDaemon64.exe [232192 2015-06-01] (NETGEAR)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [366544 2015-04-30] (Microsoft Corporation)
R2 nlsX86cc; C:\Windows\SysWOW64\nlssrv32.exe [66560 2011-02-04] (Nalpeiron Ltd.) [File not signed]
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1720608 2014-07-25] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [18956064 2014-07-25] (NVIDIA Corporation)
S2 RaMediaServer; C:\Program Files (x86)\MediatekWiFi\Common\RaMediaServer.exe [1863680 2012-07-06] (Ralink) [File not signed]
R2 RealtekCU; C:\Program Files (x86)\Realtek\USB Wireless LAN Utility\RtlService.exe [36864 2012-05-10] (Realtek Semiconductor Corp.) [File not signed]
S3 RoxMediaDB13; C:\Program Files (x86)\Common Files\Roxio Shared\13.0\SharedCOM\RoxMediaDB13.exe [1099248 2010-07-16] (Sonic Solutions)
R2 Serviio; C:\Program Files\Serviio\bin\ServiioService.exe [327680 2015-03-21] () [File not signed]
R2 SEVPNCLIENT; C:\Program Files\SoftEther VPN Client\vpnclient_x64.exe [4374072 2014-12-09] (SoftEther VPN Project at University of Tsukuba, Japan.)
S3 SOHDBSvr; C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDBSvr.exe [70952 2009-07-27] (Sony Corporation)
S3 SOHPlMgr; C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHPlMgr.exe [91432 2009-07-27] (Sony Corporation)
R2 Stuffit Archive Name Service; C:\Program Files (x86)\Stuffit\ArcNameService.exe [199000 2008-12-19] (Smith Micro Software, Inc.)
R2 Unchecky; C:\Program Files (x86)\Unchecky\bin\unchecky_svc.exe [297240 2018-04-08] (Reason Software Company Inc.)
S3 USER_ESRV_SVC; C:\Program Files\Sony\VAIO Care\ESRV\esrv_svc.exe [413336 2015-08-26] ()
R3 VUAgent; C:\Program Files\Sony\VAIO Update\vuagent.exe [1656600 2016-03-31] (Sony Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
R2 SampleCollector; "C:\Program Files\Sony\VAIO Care\VCPerfService.exe" "/service" "/sstates" "/sampleinterval=5000" "/procinterval=5" "/dllinterval=120" "/counter=\Processor(_Total)\% Processor Time:1/counter=\PhysicalDisk(_Total)\Disk Bytes/sec:1" "/counter=\Network Interface(*)\Bytes Total/sec:1" "/expandcounter=\Processor Information(*)\Processor Frequency:1" "/expandcounter=\Processor(*)\% Idle Time:1" "/expandcounter=\Processor(*)\% C1 Time:1" "/expandcounter=\Processor(*)\% C2 Time:1" "/expandcounter=\Processor(*)\% C3 Time:1" "/expandcounter=\Processor(*)\% Processor Time:1" "/directory=C:\ProgramData\Sony Corporation\VAIO Care\inteldata" <==== ATTENTION
S4 windowsmanagementservice; windowsmanagementservice [X] <==== ATTENTION
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 Apowersoft_AudioDevice; C:\Windows\System32\drivers\Apowersoft_AudioDevice.sys [31920 2014-04-09] (Wondershare)
S4 IObitUnlocker; C:\Program Files (x86)\IObit\IObit Unlocker\IObitUnlocker.sys [36944 2014-03-04] (IObit)
R1 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [253664 2018-04-25] (Malwarebytes)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [280376 2015-03-04] (Microsoft Corporation)
R1 MpKsl13d2c6a1; c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{99932F80-EB4F-4A73-82AA-A5A232627FCC}\MpKsl13d2c6a1.sys [58120 2018-04-25] (Microsoft Corporation)
R3 Neo_VPN; C:\Windows\System32\DRIVERS\Neo_0055.sys [28768 2014-12-09] (SoftEther VPN Project at University of Tsukuba, Japan.)
S3 netr28ux; C:\Windows\System32\DRIVERS\netr28ux.sys [2212496 2014-07-04] (MediaTek Inc.)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [124568 2015-03-04] (Microsoft Corporation)
R2 npf; C:\Windows\system32\drivers\npf.sys [36600 2015-10-12] (Riverbed Technology, Inc.)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [20256 2014-07-25] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [40392 2014-03-31] (NVIDIA Corporation)
R1 pfmfs_A1C; C:\Windows\System32\Drivers\pfmfs_A1C.sys [258656 2014-07-11] (Pismo Technic Inc.)
R3 SEE; C:\Windows\System32\drivers\see.sys [38240 2014-12-09] (SoftEther VPN Project at University of Tsukuba, Japan.)
R3 semav6msr64; C:\Windows\system32\drivers\semav6msr64.sys [29352 2015-10-07] ()
S3 semav6thermal64ro; C:\Windows\system32\drivers\semav6thermal64ro.sys [13792 2012-11-06] ()
S3 taphss6; C:\Windows\System32\DRIVERS\taphss6.sys [42088 2015-12-18] (Anchorfree Inc.)
R3 VBAudioHFVAIOMME; C:\Windows\System32\DRIVERS\vbaudio_hfvaio64_win7.sys [33512 2014-07-19] (Windows (R) Win 7 DDK provider)
R3 VBAudioVACMME; C:\Windows\System32\DRIVERS\vbaudio_cable64_win7.sys [41192 2013-07-11] (Windows (R) Win 7 DDK provider)
R3 WsAudio_Device; C:\Windows\System32\drivers\VirtualAudio.sys [31080 2013-03-25] (Wondershare)
S3 ALSysIO; \??\C:\Users\2018Jean\AppData\Local\Temp\ALSysIO64.sys [X] <==== ATTENTION
S3 DrvAgent64; \??\C:\Windows\SysWOW64\Drivers\DrvAgent64.SYS [X]
S3 MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [X]
R3 vzcfjm; system32\drivers\cfimps.sys [X]
S1 ZAM; \??\C:\Windows\System32\drivers\zam64.sys [X]
S1 ZAM_Guard; \??\C:\Windows\System32\drivers\zamguard64.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2018-04-26 09:01 - 2018-04-26 09:01 - 000852798 _____ C:\Users\2018Jean\Desktop\SecurityCheck.exe
2018-04-26 08:53 - 2018-04-26 08:53 - 000564350 _____ C:\Users\2018Jean\Documents\cc_20180426_085302.reg
2018-04-25 21:00 - 2018-04-25 21:00 - 000008192 _____ C:\Windows\system32\config\userdiff
2018-04-25 19:40 - 2018-04-25 19:40 - 000000089 _____ C:\Users\2018Jean\Desktop\Sysnative Forum.url
2018-04-25 18:55 - 2018-04-26 10:05 - 000000000 ____D C:\FRST
2018-04-25 18:30 - 2018-04-25 18:30 - 000001456 _____ C:\Users\2018Jean\AppData\Local\Adobe Save for Web 13.0 Prefs
2018-04-25 18:28 - 2018-04-25 18:28 - 000000000 ____D C:\Users\2018Jean\AppData\Roaming\NVIDIA
2018-04-25 18:22 - 2018-04-25 18:22 - 000000000 _____ C:\Users\2018Jean\AppData\LocalLow\QuickTime.qtp
2018-04-25 17:29 - 2018-04-25 17:29 - 000000830 _____ C:\Users\2018Jean\Desktop\NOT SEEN YET.lnk
2018-04-25 17:25 - 2018-04-25 17:25 - 000000000 ____D C:\Users\2018Jean\AppData\Local\uprstbh
2018-04-25 16:02 - 2018-04-25 17:26 - 000000000 ___HD C:\$WINDOWS.~BT
2018-04-25 16:00 - 2018-04-25 19:41 - 000000000 ____D C:\Users\2018Jean\Desktop\Cooties
2018-04-25 15:55 - 2018-04-25 15:55 - 000000000 ____D C:\Users\2018Jean\AppData\Local\dsevumr
2018-04-25 15:05 - 2018-04-25 15:05 - 000000000 ____D C:\Users\2018Jean\AppData\Local\wmodzib
2018-04-25 13:37 - 2018-04-25 13:37 - 000253664 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamswissarmy.sys
2018-04-25 13:37 - 2018-04-25 13:37 - 000193768 _____ (Malwarebytes) C:\Windows\system32\Drivers\MbamChameleon.sys
2018-04-25 13:37 - 2018-04-25 13:37 - 000093816 _____ (Malwarebytes) C:\Windows\system32\Drivers\mwac.sys
2018-04-25 13:37 - 2018-04-25 13:37 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2018-04-25 13:36 - 2018-04-25 13:36 - 000000000 ____D C:\Program Files\Malwarebytes
2018-04-25 13:36 - 2018-03-19 12:57 - 000076192 _____ C:\Windows\system32\Drivers\mbae64.sys
2018-04-25 12:28 - 2018-04-25 12:28 - 000003160 _____ C:\Windows\System32\Tasks\{19FA1E7F-C63E-4A46-97A3-3F34BC31D6C0}
2018-04-25 11:45 - 2018-04-25 11:31 - 017391963 ____N C:\EvtxAppDump.txt
2018-04-25 11:45 - 2018-04-25 11:31 - 012564416 ____N C:\EvtxSysDump.txt
2018-04-25 11:45 - 2018-04-25 11:31 - 001412796 ____N C:\MSInfo32.nfo
2018-04-25 11:45 - 2018-04-25 11:31 - 000300898 ____N C:\042318-80246-01.dmp
2018-04-25 11:45 - 2018-04-25 11:31 - 000300770 ____N C:\042318-58781-01.dmp
2018-04-25 11:45 - 2018-04-25 11:31 - 000300770 ____N C:\042318-33181-01.dmp
2018-04-25 11:45 - 2018-04-25 11:31 - 000300770 ____N C:\042318-32900-01.dmp
2018-04-25 11:45 - 2018-04-25 11:31 - 000300770 ____N C:\042218-79700-01.dmp
2018-04-25 11:45 - 2018-04-25 11:31 - 000300770 ____N C:\042218-52151-01.dmp
2018-04-25 11:45 - 2018-04-25 11:31 - 000300770 ____N C:\042218-154815-01.dmp
2018-04-25 11:45 - 2018-04-25 11:31 - 000300770 ____N C:\042218-148684-01.dmp
2018-04-25 11:45 - 2018-04-25 11:31 - 000300770 ____N C:\042118-40248-01.dmp
2018-04-25 11:45 - 2018-04-25 11:31 - 000300770 ____N C:\042118-32417-01.dmp
2018-04-25 11:45 - 2018-04-25 11:31 - 000300770 ____N C:\042118-30170-01.dmp
2018-04-25 11:45 - 2018-04-25 11:31 - 000300770 ____N C:\042118-28204-01.dmp
2018-04-25 11:45 - 2018-04-25 11:31 - 000300194 ____N C:\042318-43165-01.dmp
2018-04-25 11:45 - 2018-04-25 11:31 - 000300194 ____N C:\042218-45037-01.dmp
2018-04-25 11:45 - 2018-04-25 11:31 - 000275160 ____N C:\WERProgramData
2018-04-25 11:45 - 2018-04-25 11:31 - 000259762 ____N C:\SysList.txt
2018-04-25 11:45 - 2018-04-25 11:31 - 000197556 ____N C:\WERALL.txt
2018-04-25 11:45 - 2018-04-25 11:31 - 000177720 ____N C:\TasklistSVCHOST.txt
2018-04-25 11:45 - 2018-04-25 11:31 - 000096382 ____N C:\NetstatJcgriff2
2018-04-25 11:45 - 2018-04-25 11:31 - 000066126 ____N C:\DriverqV.txt
2018-04-25 11:45 - 2018-04-25 11:31 - 000060895 ____N C:\HKLMSoftMSWinCVUninstall.txt
2018-04-25 11:45 - 2018-04-25 11:31 - 000052704 ____N C:\DxDiagx86.txt
2018-04-25 11:45 - 2018-04-25 11:31 - 000038738 ____N C:\DriverqFo.txt
2018-04-25 11:45 - 2018-04-25 11:31 - 000016195 ____N C:\WERLocalAppData
2018-04-25 11:45 - 2018-04-25 11:31 - 000015797 ____N C:\DriverqSi.txt
2018-04-25 11:45 - 2018-04-25 11:31 - 000015699 ____N C:\NetSHLAN1.txt
2018-04-25 11:45 - 2018-04-25 11:31 - 000014138 ____N C:\Jcgriff2Log.txt
2018-04-25 11:45 - 2018-04-25 11:31 - 000013802 ____N C:\SystemInfo.txt
2018-04-25 11:45 - 2018-04-25 11:31 - 000010024 ____N C:\RAMInfo.html
2018-04-25 11:45 - 2018-04-25 11:31 - 000009566 ____N C:\HKLMSoftMSA-SInstalledComponents.txt
2018-04-25 11:45 - 2018-04-25 11:31 - 000007607 ____N C:\IPconfigAll.txt
2018-04-25 11:45 - 2018-04-25 11:31 - 000003987 ____N C:\SetEnvironmentVar.txt
2018-04-25 11:45 - 2018-04-25 11:31 - 000002199 ____N C:\KernelDumpList.txt
2018-04-25 11:45 - 2018-04-25 11:31 - 000002047 ____N C:\Hosts.txt
2018-04-25 11:45 - 2018-04-25 11:31 - 000001338 ____N C:\WMICRecoveros.txt
2018-04-25 11:45 - 2018-04-25 11:31 - 000001278 ____N C:\BSODPostingInstructions.txt
2018-04-25 11:45 - 2018-04-25 11:31 - 000001213 ____N C:\Tracert.txt
2018-04-25 11:45 - 2018-04-25 11:31 - 000000002 ____N C:\HKCUSoftMSWinCVUninstall.txt
2018-04-25 11:45 - 2018-04-25 11:31 - 000000002 ____N C:\Autoruns.txt
2018-04-25 11:45 - 2018-04-25 11:31 - 000000000 ____N C:\NetstatJcgriff2.StdErr
2018-04-24 20:51 - 2018-04-26 02:34 - 000000000 ____D C:\Users\2018Jean\AppData\Local\sictnhk
2018-04-24 20:38 - 2018-04-25 15:14 - 000000000 ____D C:\Users\2018Jean\AppData\LocalLow\Mozilla
2018-04-24 20:38 - 2018-04-24 20:38 - 000000000 ____D C:\Users\2018Jean\AppData\Roaming\Mozilla
2018-04-24 20:38 - 2018-04-24 20:38 - 000000000 ____D C:\Users\2018Jean\AppData\Local\Mozilla
2018-04-24 16:27 - 2018-04-24 16:27 - 000001245 _____ C:\Users\2018Jean\AppData\Local\recently-used.xbel
2018-04-23 19:41 - 2018-04-23 19:41 - 000000000 ____D C:\Users\2018Jean\AppData\Local\vdewzng
2018-04-23 18:13 - 2018-04-23 18:14 - 000000000 ____D C:\Users\2018Jean\AppData\Roaming\PeaZip
2018-04-23 18:06 - 2018-04-23 18:06 - 000000000 ____D C:\ProgramData\UniqueId
2018-04-23 17:39 - 2018-04-23 18:54 - 000000000 ____D C:\Program Files\Reimage
2018-04-23 17:38 - 2018-04-23 18:53 - 000000140 _____ C:\Windows\Reimage.ini
2018-04-23 17:07 - 2018-04-23 17:07 - 000000000 ____D C:\SFCFix
2018-04-23 16:29 - 2018-04-23 19:48 - 000000000 ____D C:\Users\2018Jean\AppData\Local\niemiro
2018-04-23 16:18 - 2018-04-23 16:18 - 000000000 ____D C:\Users\2018Jean\AppData\Local\sbexiwt
2018-04-23 16:14 - 2018-04-25 17:21 - 002888704 _____ (TOSHIBA CORPORATION) C:\Windows\system32\sbalwomsvc.exe
2018-04-23 16:14 - 2018-04-23 16:14 - 000142672 ____N C:\Windows\system32\Drivers\dwrpswzc.sys
2018-04-23 15:57 - 2018-04-23 16:10 - 000000000 ____D C:\ProgramData\SecTaskMan
2018-04-23 15:53 - 2018-04-23 15:53 - 000000000 ____D C:\Users\Administrator\AppData\Local\ElevatedDiagnostics
2018-04-23 15:51 - 2018-04-23 15:51 - 000000000 ___HD C:\$Windows.~WS
2018-04-23 15:45 - 2018-04-23 15:45 - 000000000 ____D C:\Users\Administrator\AppData\Local\cwclsuo
2018-04-23 15:15 - 2018-04-23 15:15 - 000000000 ____D C:\Users\New User\AppData\Local\NPE
2018-04-23 14:38 - 2018-04-23 14:43 - 000000000 ____D C:\Users\Administrator\AppData\Local\Smith Micro
2018-04-23 14:38 - 2018-04-23 14:38 - 000000000 ____D C:\Users\Administrator\Documents\My Archives
2018-04-23 14:33 - 2018-04-23 15:53 - 000000000 ____D C:\ESD
2018-04-23 14:28 - 2018-04-23 14:28 - 018617536 _____ (Microsoft Corporation) C:\Users\Administrator\Desktop\MediaCreationTool.exe
2018-04-23 13:57 - 2018-04-23 13:57 - 000000000 ____D C:\Users\Administrator\AppData\Local\usndpmr
2018-04-23 13:57 - 2018-04-23 13:57 - 000000000 ____D C:\Users\Administrator\AppData\Local\avcskld
2018-04-23 12:13 - 2018-04-23 12:13 - 000000000 ____D C:\Users\Administrator\AppData\Local\sinmlep
2018-04-23 12:13 - 2018-04-23 12:13 - 000000000 ____D C:\Users\Administrator\AppData\Local\dwenhzu
2018-04-23 11:44 - 2018-04-23 11:44 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NirSoft BlueScreenView
2018-04-23 11:43 - 2018-04-23 11:43 - 000141864 _____ C:\Users\Administrator\Desktop\bluescreenview_setup.exe
2018-04-23 11:26 - 2018-04-23 11:26 - 000000476 _____ C:\Users\Administrator\Desktop\Local Disk.lnk
2018-04-23 11:00 - 2018-04-23 11:00 - 000000000 ____D C:\Users\Administrator\AppData\Local\wenopab
2018-04-23 11:00 - 2018-04-23 11:00 - 000000000 ____D C:\Users\Administrator\AppData\Local\raaxvnu
2018-04-23 10:38 - 2018-04-23 10:38 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
2018-04-23 09:57 - 2018-04-23 09:57 - 000001380 _____ C:\Users\Administrator\Desktop\NOT SEEN YET.lnk
2018-04-23 09:57 - 2018-04-20 10:07 - 000002162 _____ C:\Users\Administrator\Desktop\$$.lnk
2018-04-23 09:56 - 2018-04-23 09:56 - 000000000 ____D C:\Users\Administrator\AppData\Local\wmcagent
2018-04-23 09:56 - 2018-04-22 17:36 - 000002057 _____ C:\Users\Administrator\Desktop\Litter.lnk
2018-04-23 09:53 - 2018-04-23 09:53 - 000001160 _____ C:\Users\Administrator\Desktop\Jean Desktop.lnk
2018-04-23 09:50 - 2018-04-23 09:50 - 000000000 ____D C:\Users\Administrator\AppData\Local\wimbrdt
2018-04-23 09:50 - 2018-04-23 09:50 - 000000000 ____D C:\Users\Administrator\AppData\Local\mbbdcor
2018-04-22 20:43 - 2018-04-22 20:43 - 000000000 ____D C:\Users\2018Jean\AppData\Local\sbizvxg
2018-04-22 20:43 - 2018-04-22 20:43 - 000000000 ____D C:\Users\2018Jean\AppData\Local\ElevatedDiagnostics
2018-04-22 20:20 - 2018-04-22 20:20 - 000000000 ____D C:\Users\2018Jean\Documents\My Archives
2018-04-22 19:55 - 2018-04-22 19:55 - 000000000 ____D C:\Users\2018Jean\AppData\Local\rabzdkn
2018-04-22 18:55 - 2018-04-22 18:55 - 000000000 ____D C:\Users\2018Jean\AppData\Local\sikzlxh
2018-04-22 17:36 - 2018-04-22 17:36 - 000002057 _____ C:\Users\2018Jean\Desktop\Litter.lnk
2018-04-22 08:06 - 2018-04-22 08:06 - 000002459 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Distiller 7.0.lnk
2018-04-22 08:06 - 2018-04-22 08:06 - 000002453 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Designer 7.0.lnk
2018-04-22 08:06 - 2018-04-22 08:06 - 000002447 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat 7.0 Professional.lnk
2018-04-22 07:24 - 2018-04-22 07:24 - 000000000 ____D C:\Users\2018Jean\AppData\Local\niorwds
2018-04-22 07:06 - 2018-04-22 07:06 - 000000000 ____D C:\Users\2018Jean\AppData\Local\atcbgmv
2018-04-21 22:32 - 2018-04-21 22:32 - 000000000 ____D C:\Users\2018Jean\AppData\Local\pwnlkcm
2018-04-21 22:15 - 2018-04-26 10:10 - 000000000 ____D C:\Users\2018Jean\AppData\Local\tibevus
2018-04-21 22:15 - 2018-04-21 22:15 - 000000000 ____D C:\Users\2018Jean\AppData\Local\coogxwm
2018-04-21 21:48 - 2018-04-21 21:48 - 000000000 ____D C:\Users\2018Jean\AppData\Local\vsbprkg
2018-04-21 21:48 - 2018-04-21 21:48 - 000000000 ____D C:\Users\2018Jean\AppData\Local\vdbznux
2018-04-21 21:42 - 2018-04-23 15:40 - 001068960 _____ C:\Windows\ntbtlog.txt
2018-04-21 21:29 - 2018-04-21 21:29 - 000000000 ____D C:\Users\2018Jean\AppData\Local\lsdzmre
2018-04-21 21:28 - 2018-04-21 21:32 - 000000000 ____D C:\Users\2018Jean\AppData\Local\spharxu
2018-04-21 20:53 - 2018-04-21 21:17 - 000000000 ____D C:\Users\2018Jean\AppData\Local\cwkvulb
2018-04-21 20:39 - 2018-04-21 21:21 - 000000000 ____D C:\Program Files (x86)\Zemana AntiMalware
2018-04-21 20:32 - 2018-04-21 20:32 - 000000000 ____D C:\Users\2018Jean\AppData\Local\Zemana
2018-04-21 20:02 - 2018-04-21 20:02 - 000000000 ____D C:\Users\2018Jean\AppData\Local\CEF
2018-04-21 20:01 - 2018-04-21 20:02 - 000000000 ____D C:\Users\2018Jean\AppData\Local\wmcagent
2018-04-21 20:01 - 2018-04-21 20:01 - 000000000 ____D C:\Users\2018Jean\AppData\Roaming\Macromedia
2018-04-21 19:58 - 2018-04-21 21:51 - 000000000 ____D C:\Users\2018Jean\AppData\Local\avnpetb
2018-04-21 19:58 - 2018-04-21 19:58 - 000000000 ____D C:\Users\2018Jean\AppData\Local\dsiexuo
2018-04-21 19:55 - 2018-04-23 15:36 - 002888704 _____ C:\Windows\SysWOW64\sbalwomsvc.exe
2018-04-21 19:50 - 2018-04-21 20:01 - 000000000 ____D C:\Users\2018Jean\AppData\Roaming\AGData
2018-04-21 19:49 - 2018-04-21 20:45 - 000000000 ____D C:\Program Files (x86)\coordinator
2018-04-21 19:49 - 2018-04-21 19:49 - 000003882 _____ C:\Windows\System32\Tasks\nipples
2018-04-21 19:49 - 2018-04-21 19:49 - 000003740 _____ C:\Windows\System32\Tasks\Sanipplesnipples
2018-04-21 19:49 - 2018-04-21 19:49 - 000000012 _____ C:\Windows\b72651245
2018-04-21 19:49 - 2018-04-21 19:49 - 000000000 ___HD C:\Program Files (x86)\hinch
2018-04-21 19:49 - 2018-04-21 19:49 - 000000000 ___HD C:\Program Files (x86)\Eduard
2018-04-21 19:49 - 2018-04-21 19:49 - 000000000 ____D C:\Windows\SysWOW64\lsebtrx
2018-04-21 19:49 - 2018-04-21 19:49 - 000000000 ____D C:\Windows\system32\lsebtrx
2018-04-21 19:49 - 2018-04-21 19:49 - 000000000 ____D C:\Users\2018Jean\AppData\Roaming\et
2018-04-21 19:49 - 2018-04-21 19:49 - 000000000 ____D C:\Program Files (x86)\fighter
2018-04-21 19:49 - 2018-04-21 19:49 - 000000000 ____D C:\Program Files (x86)\Chalice
2018-04-21 19:48 - 2018-04-21 20:44 - 000000000 ____D C:\Users\2018Jean\AppData\Local\CrashDumps
2018-04-21 19:48 - 2018-04-21 19:49 - 000000000 ____D C:\ProgramData\Arkei-{601A1EDD-2C55-4B67-98FF-D1B2BB6FD336}
2018-04-21 17:02 - 2018-04-21 17:02 - 000051200 _____ C:\Windows\nuances.exe
2018-04-21 17:02 - 2018-04-21 17:02 - 000051200 _____ C:\Users\2018Jean\AppData\Local\undermining.exe
2018-04-21 17:02 - 2018-04-21 17:02 - 000051200 _____ C:\Users\2018Jean\AppData\Local\Slighting.exe
2018-04-21 10:03 - 2018-04-22 08:06 - 000000000 ____D C:\Users\Public\Documents\Adobe PDF
2018-04-17 16:28 - 2018-04-23 18:03 - 000000000 ____D C:\Users\2018Jean\AppData\Local\Smith Micro
2018-04-16 10:40 - 2018-04-16 10:40 - 000000000 ____D C:\Users\2018Jean\AppData\Roaming\AdobeUM
2018-04-14 14:39 - 2018-04-14 14:39 - 000000000 ____D C:\Users\2018Jean\AppData\LocalLow\Adobe
2018-04-13 15:18 - 2018-04-23 20:38 - 000000000 ____D C:\Users\2018Jean\AppData\Roaming\vlc
2018-04-13 13:38 - 2018-04-20 15:51 - 000000000 ____D C:\Users\2018Jean\AppData\Roaming\deluge
2018-04-13 12:47 - 2018-04-20 10:07 - 000002162 _____ C:\Users\2018Jean\Desktop\$$.lnk
2018-04-13 12:46 - 2018-04-13 12:19 - 000746554 _____ C:\Users\2018Jean\bookmarks_4_13_18.html
2018-04-13 12:45 - 2018-04-13 12:45 - 000001952 _____ C:\Users\2018Jean\Desktop\FileCabinet.lnk
2018-04-13 12:11 - 2018-04-13 12:11 - 000000000 ____D C:\Users\2018Jean\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
2018-04-13 12:10 - 2018-04-13 12:10 - 000000000 ____D C:\Users\2018Jean\AppData\Roaming\Google
2018-04-13 12:06 - 2018-04-13 12:06 - 000003416 _____ C:\Users\2018Jean\Layout 1600 x 900 (32).dtr
2018-04-13 12:03 - 2018-04-25 18:22 - 000000000 ____D C:\Users\2018Jean\AppData\Local\VirtualStore
2018-04-13 11:51 - 2018-04-12 14:25 - 005767168 _____ C:\Users\2018Jean\ntuser (2).dat
2018-04-13 11:37 - 2014-06-25 12:28 - 000002286 ____H C:\Users\2018Jean\Documents\Default.rdp
2018-04-13 11:21 - 2018-04-22 17:36 - 000000000 ___RD C:\Users\2018Jean\FileCabinet
2018-04-13 11:21 - 2015-09-22 14:43 - 000000000 ____D C:\Users\2018Jean\DuOSShare
2018-04-13 10:58 - 2018-04-13 14:03 - 000000000 ____D C:\Users\2018Jean\.jbidwatcher
2018-04-13 10:58 - 2018-04-13 14:02 - 000000000 ____D C:\Users\2018Jean\.oracle_jre_usage
2018-04-13 10:58 - 2018-04-13 10:58 - 000000000 ____D C:\Users\2018Jean\Song Surgeon 4
2018-04-13 10:58 - 2018-04-13 10:58 - 000000000 ____D C:\Users\2018Jean\Prismatik
2018-04-13 10:58 - 2018-04-13 10:58 - 000000000 ____D C:\Users\2018Jean\.FBReader
2018-04-13 10:58 - 2018-04-13 10:58 - 000000000 ____D C:\Users\2018Jean\.cache
2018-04-13 10:58 - 2018-04-13 10:58 - 000000000 ____D C:\Users\2018Jean\.android
2018-04-13 10:58 - 2018-02-05 14:51 - 002080256 ___SH C:\Users\2018Jean\Desktop\Thumbs.db
2018-04-13 10:58 - 2018-01-24 15:13 - 000002298 _____ C:\Users\2018Jean\Desktop\Brian Desktop.lnk
2018-04-13 10:58 - 2017-08-13 11:31 - 000000476 _____ C:\Users\2018Jean\Desktop\Local Disk.lnk
2018-04-13 10:58 - 2017-07-01 20:05 - 000002303 _____ C:\Users\2018Jean\DesktopWin10Tool.txt
2018-04-13 10:58 - 2015-07-15 20:10 - 000000032 _____ C:\Users\2018Jean\.deskmetrics
2018-04-13 10:39 - 2018-04-13 12:05 - 000000000 ____D C:\Users\2018Jean\AppData\Local\NVIDIA Corporation
2018-04-13 10:38 - 2018-04-25 18:28 - 000000000 ____D C:\Users\2018Jean\AppData\Local\Adobe
2018-04-13 10:38 - 2018-04-22 08:31 - 000091136 _____ C:\Users\2018Jean\AppData\Local\GDIPFONTCACHEV1.DAT
2018-04-13 10:38 - 2018-04-13 10:38 - 000000000 ____D C:\Users\2018Jean\AppData\Roaming\Roxio
2018-04-13 10:38 - 2018-04-13 10:38 - 000000000 ____D C:\Users\2018Jean\AppData\Local\NVIDIA
2018-04-13 10:37 - 2018-04-25 18:29 - 000000000 ____D C:\Users\2018Jean\AppData\Roaming\Adobe
2018-04-13 10:37 - 2018-04-25 15:14 - 000000000 ____D C:\Users\2018Jean\AppData\Local\Google
2018-04-13 10:37 - 2018-04-23 09:53 - 000000000 ____D C:\Users\2018Jean
2018-04-13 10:37 - 2018-04-13 10:37 - 000001417 _____ C:\Users\2018Jean\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2018-04-13 10:37 - 2018-04-13 10:37 - 000000020 ___SH C:\Users\2018Jean\ntuser.ini
2018-04-13 10:37 - 2018-04-13 10:37 - 000000000 ____D C:\Users\2018Jean\AppData\Roaming\Sony Corporation
2018-04-13 10:37 - 2009-07-14 03:44 - 000000000 ____D C:\Users\2018Jean\AppData\Roaming\Media Center Programs
2018-04-13 06:45 - 2018-04-13 06:45 - 004279968 _____ (NeoSoft Tools ) C:\Users\2018Jean\AppData\Roaming\ctask.exe
2018-04-12 19:06 - 2018-04-26 09:17 - 136971704 ____C (Microsoft Corporation) C:\Windows\system32\MRT-KB890830.exe
2018-04-12 18:56 - 2018-03-22 17:17 - 000048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2018-04-12 18:56 - 2018-03-22 17:09 - 000034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2018-04-12 18:56 - 2018-03-22 17:06 - 000116224 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2018-04-12 18:56 - 2018-03-22 16:50 - 000064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2018-04-12 18:56 - 2018-03-22 16:45 - 000030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2018-04-12 18:56 - 2018-03-22 16:28 - 000091136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2018-04-12 18:56 - 2018-03-22 16:25 - 000076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2018-04-12 18:55 - 2018-03-30 22:09 - 005583040 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2018-04-12 18:55 - 2018-03-30 22:09 - 000708288 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2018-04-12 18:55 - 2018-03-30 22:09 - 000262336 _____ (Microsoft Corporation) C:\Windows\system32\hal.dll
2018-04-12 18:55 - 2018-03-30 22:09 - 000154816 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2018-04-12 18:55 - 2018-03-30 22:09 - 000095424 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2018-04-12 18:55 - 2018-03-30 21:45 - 000631640 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2018-04-12 18:55 - 2018-03-30 21:39 - 004046528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2018-04-12 18:55 - 2018-03-30 21:39 - 003958464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2018-04-12 18:55 - 2018-03-30 21:38 - 001665336 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 001461248 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 001212928 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 001163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000880640 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000731648 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000463872 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000419840 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000361984 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000345600 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000316928 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000215552 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000190464 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000123904 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000094720 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000059904 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000044032 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000034816 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000007168 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:12 - 001314064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2018-04-12 18:55 - 2018-03-30 21:09 - 001114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2018-04-12 18:55 - 2018-03-30 21:09 - 000690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2018-04-12 18:55 - 2018-03-30 21:09 - 000666112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2018-04-12 18:55 - 2018-03-30 21:09 - 000644096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2018-04-12 18:55 - 2018-03-30 21:09 - 000554496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2018-04-12 18:55 - 2018-03-30 21:09 - 000342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
2018-04-12 18:55 - 2018-03-30 21:09 - 000275456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2018-04-12 18:55 - 2018-03-30 21:09 - 000261120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2018-04-12 18:55 - 2018-03-30 21:09 - 000254464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2018-04-12 18:55 - 2018-03-30 21:09 - 000223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2018-04-12 18:55 - 2018-03-30 21:09 - 000172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2018-04-12 18:55 - 2018-03-30 21:09 - 000146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2018-04-12 18:55 - 2018-03-30 21:09 - 000141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll
2018-04-12 18:55 - 2018-03-30 21:09 - 000096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2018-04-12 18:55 - 2018-03-30 21:09 - 000082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcrypt.dll
2018-04-12 18:55 - 2018-03-30 21:09 - 000070144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2018-04-12 18:55 - 2018-03-30 21:09 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2018-04-12 18:55 - 2018-03-30 21:09 - 000050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll
2018-04-12 18:55 - 2018-03-30 21:09 - 000043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2018-04-12 18:55 - 2018-03-30 21:09 - 000022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2018-04-12 18:55 - 2018-03-30 21:09 - 000017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2018-04-12 18:55 - 2018-03-30 21:09 - 000007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2018-04-12 18:55 - 2018-03-30 21:09 - 000005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:09 - 000005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2018-04-12 18:55 - 2018-03-30 21:09 - 000004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:09 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:09 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:09 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:09 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:09 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:09 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:09 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:09 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:09 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:09 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:09 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:09 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:09 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:09 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:09 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:09 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:09 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:09 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:09 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:09 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:09 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:09 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:06 - 000148480 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2018-04-12 18:55 - 2018-03-30 21:06 - 000064512 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2018-04-12 18:55 - 2018-03-30 21:06 - 000062464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2018-04-12 18:55 - 2018-03-30 21:06 - 000017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2018-04-12 18:55 - 2018-03-30 21:03 - 000338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2018-04-12 18:55 - 2018-03-30 21:02 - 000296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2018-04-12 18:55 - 2018-03-30 21:02 - 000129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\videoprt.sys
2018-04-12 18:55 - 2018-03-30 20:59 - 000160256 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2018-04-12 18:55 - 2018-03-30 20:58 - 000291328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2018-04-12 18:55 - 2018-03-30 20:58 - 000129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2018-04-12 18:55 - 2018-03-30 20:58 - 000112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2018-04-12 18:55 - 2018-03-30 20:58 - 000030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2018-04-12 18:55 - 2018-03-30 20:51 - 000050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2018-04-12 18:55 - 2018-03-30 20:47 - 000036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
2018-04-12 18:55 - 2018-03-30 20:47 - 000025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2018-04-12 18:55 - 2018-03-30 20:47 - 000014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2018-04-12 18:55 - 2018-03-30 20:47 - 000007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2018-04-12 18:55 - 2018-03-30 20:47 - 000006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 20:47 - 000004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 20:47 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 20:47 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 20:47 - 000002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2018-04-12 18:55 - 2018-03-28 03:30 - 003225600 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2018-04-12 18:55 - 2018-03-23 14:50 - 000396952 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2018-04-12 18:55 - 2018-03-23 13:59 - 000348824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2018-04-12 18:55 - 2018-03-22 19:00 - 025742336 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2018-04-12 18:55 - 2018-03-22 17:32 - 002724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2018-04-12 18:55 - 2018-03-22 17:32 - 000004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2018-04-12 18:55 - 2018-03-22 17:26 - 020287488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2018-04-12 18:55 - 2018-03-22 17:19 - 002901504 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2018-04-12 18:55 - 2018-03-22 17:18 - 000066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2018-04-12 18:55 - 2018-03-22 17:17 - 000578048 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2018-04-12 18:55 - 2018-03-22 17:17 - 000417280 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2018-04-12 18:55 - 2018-03-22 17:17 - 000088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2018-04-12 18:55 - 2018-03-22 17:15 - 005780480 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2018-04-12 18:55 - 2018-03-22 17:10 - 000054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2018-04-12 18:55 - 2018-03-22 17:07 - 000615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2018-04-12 18:55 - 2018-03-22 17:06 - 000794112 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2018-04-12 18:55 - 2018-03-22 17:06 - 000144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2018-04-12 18:55 - 2018-03-22 17:05 - 000814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2018-04-12 18:55 - 2018-03-22 17:04 - 002724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2018-04-12 18:55 - 2018-03-22 16:58 - 000969216 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2018-04-12 18:55 - 2018-03-22 16:55 - 000489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2018-04-12 18:55 - 2018-03-22 16:52 - 000499712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2018-04-12 18:55 - 2018-03-22 16:52 - 000062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2018-04-12 18:55 - 2018-03-22 16:51 - 000341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2018-04-12 18:55 - 2018-03-22 16:51 - 000047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2018-04-12 18:55 - 2018-03-22 16:49 - 000077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2018-04-12 18:55 - 2018-03-22 16:48 - 002295296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2018-04-12 18:55 - 2018-03-22 16:48 - 000107520 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2018-04-12 18:55 - 2018-03-22 16:48 - 000087552 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2018-04-12 18:55 - 2018-03-22 16:45 - 000199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2018-04-12 18:55 - 2018-03-22 16:45 - 000047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2018-04-12 18:55 - 2018-03-22 16:44 - 000092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2018-04-12 18:55 - 2018-03-22 16:43 - 000476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2018-04-12 18:55 - 2018-03-22 16:42 - 000661504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2018-04-12 18:55 - 2018-03-22 16:42 - 000315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2018-04-12 18:55 - 2018-03-22 16:42 - 000115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2018-04-12 18:55 - 2018-03-22 16:41 - 000620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2018-04-12 18:55 - 2018-03-22 16:40 - 000152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2018-04-12 18:55 - 2018-03-22 16:33 - 000416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2018-04-12 18:55 - 2018-03-22 16:31 - 000262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2018-04-12 18:55 - 2018-03-22 16:29 - 015282688 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2018-04-12 18:55 - 2018-03-22 16:29 - 000809472 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2018-04-12 18:55 - 2018-03-22 16:29 - 000728064 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2018-04-12 18:55 - 2018-03-22 16:29 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2018-04-12 18:55 - 2018-03-22 16:28 - 000073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2018-04-12 18:55 - 2018-03-22 16:27 - 002135552 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2018-04-12 18:55 - 2018-03-22 16:27 - 001359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2018-04-12 18:55 - 2018-03-22 16:25 - 000168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2018-04-12 18:55 - 2018-03-22 16:24 - 000279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2018-04-12 18:55 - 2018-03-22 16:22 - 000130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2018-04-12 18:55 - 2018-03-22 16:21 - 004496896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2018-04-12 18:55 - 2018-03-22 16:20 - 013680128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2018-04-12 18:55 - 2018-03-22 16:17 - 000230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2018-04-12 18:55 - 2018-03-22 16:15 - 003241472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2018-04-12 18:55 - 2018-03-22 16:15 - 000696320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2018-04-12 18:55 - 2018-03-22 16:14 - 002059776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2018-04-12 18:55 - 2018-03-22 16:14 - 001155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2018-04-12 18:55 - 2018-03-22 16:04 - 001545728 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2018-04-12 18:55 - 2018-03-22 15:55 - 002767872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2018-04-12 18:55 - 2018-03-22 15:53 - 000800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2018-04-12 18:55 - 2018-03-22 15:52 - 001313792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2018-04-12 18:55 - 2018-03-22 15:51 - 000710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2018-04-12 18:55 - 2018-03-10 13:11 - 000340480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msexcl40.dll
2018-04-12 18:55 - 2018-03-09 14:18 - 000309440 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2018-04-12 18:55 - 2018-03-09 14:12 - 000383680 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2018-04-12 18:55 - 2018-03-09 14:12 - 000111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\t2embed.dll
2018-04-12 18:55 - 2018-03-09 14:12 - 000071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2018-04-12 18:55 - 2018-03-09 14:12 - 000025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
2018-04-12 18:55 - 2018-03-09 14:11 - 000010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
2018-04-12 18:55 - 2018-03-09 14:07 - 000152064 _____ (Microsoft Corporation) C:\Windows\system32\t2embed.dll
2018-04-12 18:55 - 2018-03-09 14:07 - 000100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2018-04-12 18:55 - 2018-03-09 14:07 - 000041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2018-04-12 18:55 - 2018-03-09 14:06 - 000046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2018-04-12 18:55 - 2018-03-09 14:06 - 000014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2018-04-12 18:55 - 2018-03-09 13:31 - 000034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2018-04-12 18:55 - 2018-03-06 14:13 - 000148160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\basecsp.dll
2018-04-12 18:55 - 2018-03-06 14:11 - 000184320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scksp.dll
2018-04-12 18:55 - 2018-03-06 14:11 - 000052224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wsnmp32.dll
2018-04-12 18:55 - 2018-03-06 14:10 - 000170176 _____ (Microsoft Corporation) C:\Windows\system32\basecsp.dll
2018-04-12 18:55 - 2018-03-06 14:07 - 000229376 _____ (Microsoft Corporation) C:\Windows\system32\scksp.dll
2018-04-12 18:55 - 2018-03-06 14:07 - 000067072 _____ (Microsoft Corporation) C:\Windows\system32\wsnmp32.dll
2018-04-12 18:55 - 2018-02-21 23:28 - 000217600 _____ (Microsoft Corporation) C:\Windows\system32\WinSCard.dll
2018-04-12 18:55 - 2018-02-21 23:06 - 000134656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WinSCard.dll
2018-04-12 18:55 - 2018-02-18 17:34 - 000634272 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
2018-04-12 18:55 - 2018-02-10 14:35 - 000367296 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msrpc.sys
2018-04-12 18:55 - 2018-02-10 14:35 - 000334528 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\acpi.sys
2018-04-12 18:55 - 2018-02-10 14:35 - 000185024 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\pci.sys
2018-04-12 18:55 - 2018-02-10 14:35 - 000122560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\NV_AGP.SYS
2018-04-12 18:55 - 2018-02-10 14:35 - 000068288 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\volmgr.sys
2018-04-12 18:55 - 2018-02-10 14:35 - 000064192 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ULIAGPKX.SYS
2018-04-12 18:55 - 2018-02-10 14:35 - 000063168 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\termdd.sys
2018-04-12 18:55 - 2018-02-10 14:35 - 000060608 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\AGP440.sys
2018-04-12 18:55 - 2018-02-10 14:35 - 000036032 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\vdrvroot.sys
2018-04-12 18:55 - 2018-02-10 14:35 - 000031936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mssmbios.sys
2018-04-12 18:55 - 2018-02-10 14:35 - 000023744 _____ (Microsoft Corporation) C:\Windows\system32\streamci.dll
2018-04-12 18:55 - 2018-02-10 14:35 - 000020160 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\isapnp.sys
2018-04-12 18:55 - 2018-02-10 14:35 - 000015040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msisadrv.sys
2018-04-12 18:55 - 2018-02-10 14:35 - 000012096 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\swenum.sys
2018-04-12 18:55 - 2018-02-10 14:23 - 002292224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSVidCtl.dll
2018-04-12 18:55 - 2018-02-10 14:23 - 000330240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\zipfldr.dll
2018-04-12 18:55 - 2018-02-10 14:23 - 000111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\racpldlg.dll
2018-04-12 18:55 - 2018-02-10 14:11 - 003665920 _____ (Microsoft Corporation) C:\Windows\system32\MSVidCtl.dll
2018-04-12 18:55 - 2018-02-10 14:11 - 000369664 _____ (Microsoft Corporation) C:\Windows\system32\zipfldr.dll
2018-04-12 18:55 - 2018-02-10 14:11 - 000133120 _____ (Microsoft Corporation) C:\Windows\system32\msrahc.dll
2018-04-12 18:55 - 2018-02-10 14:11 - 000119296 _____ (Microsoft Corporation) C:\Windows\system32\racpldlg.dll
2018-04-12 18:55 - 2018-02-10 13:36 - 000108032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msra.exe
2018-04-12 18:55 - 2018-02-10 13:36 - 000040960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sdchange.exe
2018-04-12 18:55 - 2018-02-10 13:36 - 000007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MsraLegacy.tlb
2018-04-12 18:55 - 2018-02-10 13:26 - 000653312 _____ (Microsoft Corporation) C:\Windows\system32\msra.exe
2018-04-12 18:55 - 2018-02-10 13:26 - 000051712 _____ (Microsoft Corporation) C:\Windows\system32\sdchange.exe
2018-04-12 18:55 - 2018-02-10 13:25 - 000014336 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\wmiacpi.sys
2018-04-12 18:55 - 2018-02-10 13:25 - 000009728 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\errdev.sys
2018-04-12 18:55 - 2018-02-10 13:25 - 000007168 _____ (Microsoft Corporation) C:\Windows\system32\MsraLegacy.tlb
2018-04-12 18:55 - 2018-02-02 14:40 - 000114368 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2018-04-12 18:55 - 2018-02-02 14:29 - 002365952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2018-04-12 18:55 - 2018-02-02 14:29 - 000337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll
2018-04-12 18:55 - 2018-02-02 14:29 - 000025088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msimsg.dll
2018-04-12 18:55 - 2018-02-02 14:28 - 001806848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2018-04-12 18:55 - 2018-02-02 14:16 - 003246080 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2018-04-12 18:55 - 2018-02-02 14:16 - 000504320 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll
2018-04-12 18:55 - 2018-02-02 14:16 - 000025088 _____ (Microsoft Corporation) C:\Windows\system32\msimsg.dll
2018-04-12 18:55 - 2018-02-02 14:14 - 001942016 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2018-04-12 18:55 - 2018-02-02 14:14 - 000070144 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll
2018-04-12 18:55 - 2018-02-02 13:46 - 000073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msiexec.exe
2018-04-12 18:55 - 2018-02-02 13:36 - 000128512 _____ (Microsoft Corporation) C:\Windows\system32\msiexec.exe
2018-04-12 18:55 - 2018-01-25 10:05 - 000995272 _____ (Microsoft Corporation) C:\Windows\system32\ucrtbase.dll
2018-04-12 18:55 - 2018-01-25 10:05 - 000063832 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-private-l1-1-0.dll
2018-04-12 18:55 - 2018-01-25 10:05 - 000020824 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-math-l1-1-0.dll
2018-04-12 18:55 - 2018-01-25 10:05 - 000019800 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-multibyte-l1-1-0.dll
2018-04-12 18:55 - 2018-01-25 10:05 - 000017752 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-string-l1-1-0.dll
2018-04-12 18:55 - 2018-01-25 10:05 - 000017752 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-stdio-l1-1-0.dll
2018-04-12 18:55 - 2018-01-25 10:05 - 000016216 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-runtime-l1-1-0.dll
2018-04-12 18:55 - 2018-01-25 10:05 - 000015704 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-convert-l1-1-0.dll
2018-04-12 18:55 - 2018-01-25 10:05 - 000014168 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-time-l1-1-0.dll
2018-04-12 18:55 - 2018-01-25 10:05 - 000014168 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-2-0.dll
2018-04-12 18:55 - 2018-01-25 10:05 - 000013656 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll
2018-04-12 18:55 - 2018-01-25 10:05 - 000012632 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-process-l1-1-0.dll
2018-04-12 18:55 - 2018-01-25 10:05 - 000012632 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-heap-l1-1-0.dll
2018-04-12 18:55 - 2018-01-25 10:05 - 000012632 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-conio-l1-1-0.dll
2018-04-12 18:55 - 2018-01-25 10:05 - 000012120 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-utility-l1-1-0.dll
2018-04-12 18:55 - 2018-01-25 10:05 - 000012120 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-locale-l1-1-0.dll
2018-04-12 18:55 - 2018-01-25 10:05 - 000012120 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-environment-l1-1-0.dll
2018-04-12 18:55 - 2018-01-25 10:05 - 000012120 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-2-0.dll
2018-04-12 18:55 - 2018-01-25 10:05 - 000012120 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-1.dll
2018-04-12 18:55 - 2018-01-25 10:05 - 000011608 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l2-1-0.dll
2018-04-12 18:55 - 2018-01-25 10:05 - 000011608 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-timezone-l1-1-0.dll
2018-04-12 18:55 - 2018-01-25 10:05 - 000011608 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l2-1-0.dll
2018-04-12 18:55 - 2018-01-25 10:05 - 000011608 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-2-0.dll
2018-04-12 18:55 - 2018-01-25 10:04 - 000922944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ucrtbase.dll
2018-04-12 18:55 - 2018-01-25 10:04 - 000066392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-private-l1-1-0.dll
2018-04-12 18:55 - 2018-01-25 10:04 - 000022360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-math-l1-1-0.dll
2018-04-12 18:55 - 2018-01-25 10:04 - 000019800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-multibyte-l1-1-0.dll
2018-04-12 18:55 - 2018-01-25 10:04 - 000017752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-string-l1-1-0.dll
2018-04-12 18:55 - 2018-01-25 10:04 - 000017752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-stdio-l1-1-0.dll
2018-04-12 18:55 - 2018-01-25 10:04 - 000016216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-runtime-l1-1-0.dll
2018-04-12 18:55 - 2018-01-25 10:04 - 000015704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-convert-l1-1-0.dll
2018-04-12 18:55 - 2018-01-25 10:04 - 000014168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-time-l1-1-0.dll
2018-04-12 18:55 - 2018-01-25 10:04 - 000014168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-2-0.dll
2018-04-12 18:55 - 2018-01-25 10:04 - 000013656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-filesystem-l1-1-0.dll
2018-04-12 18:55 - 2018-01-25 10:04 - 000012632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-process-l1-1-0.dll
2018-04-12 18:55 - 2018-01-25 10:04 - 000012632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-heap-l1-1-0.dll
2018-04-12 18:55 - 2018-01-25 10:04 - 000012632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-conio-l1-1-0.dll
2018-04-12 18:55 - 2018-01-25 10:04 - 000012120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-utility-l1-1-0.dll
2018-04-12 18:55 - 2018-01-25 10:04 - 000012120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-locale-l1-1-0.dll
2018-04-12 18:55 - 2018-01-25 10:04 - 000012120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-environment-l1-1-0.dll
2018-04-12 18:55 - 2018-01-25 10:04 - 000012120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-2-0.dll
2018-04-12 18:55 - 2018-01-25 10:04 - 000012120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-1.dll
2018-04-12 18:55 - 2018-01-25 10:04 - 000011608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l2-1-0.dll
2018-04-12 18:55 - 2018-01-25 10:04 - 000011608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-timezone-l1-1-0.dll
2018-04-12 18:55 - 2018-01-25 10:04 - 000011608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l2-1-0.dll
2018-04-12 18:55 - 2018-01-25 10:04 - 000011608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-2-0.dll
2018-04-12 18:55 - 2018-01-15 15:59 - 000002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2018-04-12 18:55 - 2018-01-15 15:40 - 000002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2018-04-12 18:55 - 2018-01-12 12:44 - 001894120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2018-04-12 18:55 - 2018-01-12 12:44 - 000377064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys
2018-04-12 18:55 - 2018-01-12 12:44 - 000371432 _____ (Microsoft Corporation) C:\Windows\system32\clfs.sys
2018-04-12 18:55 - 2018-01-12 12:44 - 000287976 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS
2018-04-12 18:55 - 2018-01-12 12:40 - 000484864 _____ (Microsoft Corporation) C:\Windows\system32\StructuredQuery.dll
2018-04-12 18:55 - 2018-01-12 12:40 - 000407040 _____ (Microsoft Corporation) C:\Windows\system32\scesrv.dll
2018-04-12 18:55 - 2018-01-12 12:27 - 004834816 _____ (Microsoft Corporation) C:\Windows\system32\xpsrchvw.exe
2018-04-12 18:55 - 2018-01-12 12:26 - 000363520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\StructuredQuery.dll
2018-04-12 18:55 - 2018-01-12 12:26 - 000308224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scesrv.dll
2018-04-12 18:55 - 2018-01-12 12:16 - 003405824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xpsrchvw.exe
2018-04-12 18:55 - 2018-01-12 12:16 - 000076288 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys
2018-04-12 18:55 - 2018-01-12 12:16 - 000030208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidusb.sys
2018-04-12 18:55 - 2018-01-12 12:15 - 000032896 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys
2018-04-12 18:55 - 2018-01-11 12:41 - 001133568 _____ (Microsoft Corporation) C:\Windows\system32\cdosys.dll
2018-04-12 18:55 - 2018-01-11 12:22 - 000805376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2018-04-12 18:55 - 2017-12-31 22:21 - 001680616 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2018-04-12 18:55 - 2017-12-31 22:21 - 000948968 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys
2018-04-12 18:55 - 2017-12-31 22:21 - 000288488 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fltMgr.sys
2018-04-12 18:55 - 2017-12-31 22:21 - 000213736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdyboost.sys
2018-04-12 18:55 - 2017-12-31 22:18 - 014183936 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2018-04-12 18:55 - 2017-12-31 22:18 - 002066432 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll
2018-04-12 18:55 - 2017-12-31 22:18 - 002004480 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2018-04-12 18:55 - 2017-12-31 22:18 - 001867776 _____ (Microsoft Corporation) C:\Windows\system32\ExplorerFrame.dll
2018-04-12 18:55 - 2017-12-31 22:18 - 001741312 _____ (Microsoft Corporation) C:\Windows\system32\sysmain.dll
2018-04-12 18:55 - 2017-12-31 22:18 - 001110528 _____ (Microsoft Corporation) C:\Windows\system32\schedsvc.dll
2018-04-12 18:55 - 2017-12-31 22:18 - 000961024 _____ (Microsoft Corporation) C:\Windows\system32\actxprxy.dll
2018-04-12 18:55 - 2017-12-31 22:18 - 000863232 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL
2018-04-12 18:55 - 2017-12-31 22:18 - 000842752 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll
2018-04-12 18:55 - 2017-12-31 22:18 - 000828928 _____ (Microsoft Corporation) C:\Windows\system32\MPSSVC.dll
2018-04-12 18:55 - 2017-12-31 22:18 - 000749568 _____ (Microsoft Corporation) C:\Windows\system32\FirewallAPI.dll
2018-04-12 18:55 - 2017-12-31 22:18 - 000705024 _____ (Microsoft Corporation) C:\Windows\system32\BFE.DLL
2018-04-12 18:55 - 2017-12-31 22:18 - 000512000 _____ (Microsoft Corporation) C:\Windows\system32\rpcss.dll
2018-04-12 18:55 - 2017-12-31 22:18 - 000473600 _____ (Microsoft Corporation) C:\Windows\system32\taskcomp.dll
2018-04-12 18:55 - 2017-12-31 22:18 - 000444928 _____ (Microsoft Corporation) C:\Windows\system32\winhttp.dll
2018-04-12 18:55 - 2017-12-31 22:18 - 000439296 _____ (Microsoft Corporation) C:\Windows\system32\p2psvc.dll
2018-04-12 18:55 - 2017-12-31 22:18 - 000366592 _____ (Microsoft Corporation) C:\Windows\system32\wcncsvc.dll
2018-04-12 18:55 - 2017-12-31 22:18 - 000327168 _____ (Microsoft Corporation) C:\Windows\system32\pnrpsvc.dll
2018-04-12 18:55 - 2017-12-31 22:18 - 000324096 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL
2018-04-12 18:55 - 2017-12-31 22:18 - 000303104 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll
2018-04-12 18:55 - 2017-12-31 22:18 - 000264704 _____ (Microsoft Corporation) C:\Windows\system32\P2P.dll
2018-04-12 18:55 - 2017-12-31 22:18 - 000223232 _____ (Microsoft Corporation) C:\Windows\system32\ncsi.dll
2018-04-12 18:55 - 2017-12-31 22:18 - 000120320 _____ (Microsoft Corporation) C:\Windows\system32\WcnApi.dll
2018-04-12 18:55 - 2017-12-31 22:18 - 000108544 _____ (Microsoft Corporation) C:\Windows\system32\icfupgd.dll
2018-04-12 18:55 - 2017-12-31 22:18 - 000101376 _____ (Microsoft Corporation) C:\Windows\system32\fdWCN.dll
2018-04-12 18:55 - 2017-12-31 22:18 - 000095744 _____ (Microsoft Corporation) C:\Windows\system32\rascfg.dll
2018-04-12 18:55 - 2017-12-31 22:18 - 000076288 _____ (Microsoft Corporation) C:\Windows\system32\rasdiag.dll
2018-04-12 18:55 - 2017-12-31 22:18 - 000070656 _____ (Microsoft Corporation) C:\Windows\system32\nlaapi.dll
2018-04-12 18:55 - 2017-12-31 22:18 - 000060928 _____ (Microsoft Corporation) C:\Windows\system32\ndptsp.tsp
2018-04-12 18:55 - 2017-12-31 22:18 - 000047104 _____ (Microsoft Corporation) C:\Windows\system32\kmddsp.tsp
2018-04-12 18:55 - 2017-12-31 22:18 - 000041472 _____ (Microsoft Corporation) C:\Windows\system32\rasmxs.dll
2018-04-12 18:55 - 2017-12-31 22:18 - 000039424 _____ (Microsoft Corporation) C:\Windows\system32\traffic.dll
2018-04-12 18:55 - 2017-12-31 22:18 - 000029696 _____ (Microsoft Corporation) C:\Windows\system32\rasser.dll
2018-04-12 18:55 - 2017-12-31 22:18 - 000026112 _____ (Microsoft Corporation) C:\Windows\system32\oleres.dll
2018-04-12 18:55 - 2017-12-31 22:18 - 000024576 _____ (Microsoft Corporation) C:\Windows\system32\WcnEapPeerProxy.dll
2018-04-12 18:55 - 2017-12-31 22:18 - 000024064 _____ (Microsoft Corporation) C:\Windows\system32\WcnEapAuthProxy.dll
2018-04-12 18:55 - 2017-12-31 22:18 - 000022528 _____ (Microsoft Corporation) C:\Windows\system32\wfapigp.dll
2018-04-12 18:55 - 2017-12-31 22:18 - 000016896 _____ (Microsoft Corporation) C:\Windows\system32\wshqos.dll
2018-04-12 18:55 - 2017-12-31 22:18 - 000013312 _____ (Microsoft Corporation) C:\Windows\system32\wshnetbs.dll
2018-04-12 18:55 - 2017-12-31 22:18 - 000008704 _____ (Microsoft Corporation) C:\Windows\system32\comcat.dll
2018-04-12 18:55 - 2017-12-31 22:18 - 000002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml6r.dll
2018-04-12 18:55 - 2017-12-31 22:04 - 000559616 _____ (Microsoft Corporation) C:\Windows\system32\spoolsv.exe
2018-04-12 18:55 - 2017-12-31 22:00 - 012880384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2018-04-12 18:55 - 2017-12-31 22:00 - 001499648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ExplorerFrame.dll
2018-04-12 18:55 - 2017-12-31 22:00 - 001417728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll
2018-04-12 18:55 - 2017-12-31 22:00 - 001390080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2018-04-12 18:55 - 2017-12-31 22:00 - 000666624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll
2018-04-12 18:55 - 2017-12-31 22:00 - 000463360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FirewallAPI.dll
2018-04-12 18:55 - 2017-12-31 22:00 - 000351744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winhttp.dll
2018-04-12 18:55 - 2017-12-31 22:00 - 000304640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\taskcomp.dll
2018-04-12 18:55 - 2017-12-31 22:00 - 000276992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wcncsvc.dll
2018-04-12 18:55 - 2017-12-31 22:00 - 000217600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\P2P.dll
2018-04-12 18:55 - 2017-12-31 22:00 - 000216576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL
2018-04-12 18:55 - 2017-12-31 22:00 - 000162304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncsi.dll
2018-04-12 18:55 - 2017-12-31 22:00 - 000081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fdWCN.dll
2018-04-12 18:55 - 2017-12-31 22:00 - 000081408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rascfg.dll
2018-04-12 18:55 - 2017-12-31 22:00 - 000061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rasdiag.dll
2018-04-12 18:55 - 2017-12-31 22:00 - 000052224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll
2018-04-12 18:55 - 2017-12-31 22:00 - 000050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ndptsp.tsp
2018-04-12 18:55 - 2017-12-31 22:00 - 000033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\traffic.dll
2018-04-12 18:55 - 2017-12-31 22:00 - 000026112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleres.dll
2018-04-12 18:55 - 2017-12-31 22:00 - 000002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6r.dll
2018-04-12 18:55 - 2017-12-31 21:59 - 000309760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\actxprxy.dll
2018-04-12 18:55 - 2017-12-31 21:55 - 000131584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\pacer.sys
2018-04-12 18:55 - 2017-12-31 21:55 - 000088576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\wanarp.sys
2018-04-12 18:55 - 2017-12-31 21:55 - 000058368 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndproxy.sys
2018-04-12 18:55 - 2017-12-31 21:55 - 000045056 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netbios.sys
2018-04-12 18:55 - 2017-12-31 21:55 - 000024064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndistapi.sys
2018-04-12 18:55 - 2017-12-31 21:54 - 000077312 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mpsdrv.sys
2018-04-12 18:55 - 2017-12-31 21:50 - 000455680 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2018-04-12 18:55 - 2017-12-31 21:43 - 000086528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WcnApi.dll
2018-04-12 18:55 - 2017-12-31 21:43 - 000038912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kmddsp.tsp
2018-04-12 18:55 - 2017-12-31 21:43 - 000033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rasmxs.dll
2018-04-12 18:55 - 2017-12-31 21:43 - 000022528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rasser.dll
2018-04-12 18:55 - 2017-12-31 21:43 - 000020480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WcnEapPeerProxy.dll
2018-04-12 18:55 - 2017-12-31 21:43 - 000019968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WcnEapAuthProxy.dll
2018-04-12 18:55 - 2017-12-31 21:43 - 000018944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wfapigp.dll
2018-04-12 18:55 - 2017-12-31 21:43 - 000013824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshqos.dll
2018-04-12 18:55 - 2017-12-31 21:42 - 000460288 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys
2018-04-12 18:55 - 2017-12-31 21:42 - 000406016 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys
2018-04-12 18:55 - 2017-12-31 21:42 - 000168448 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys
2018-04-12 18:55 - 2017-12-31 21:41 - 000754176 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys
2018-04-12 18:55 - 2017-12-31 21:41 - 000106496 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dfsc.sys
2018-04-12 18:55 - 2017-12-31 21:41 - 000007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comcat.dll
2018-04-12 18:55 - 2017-12-05 13:36 - 001484288 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2018-04-12 18:55 - 2017-12-05 13:36 - 000625664 _____ (Microsoft Corporation) C:\Windows\system32\mscms.dll
2018-04-12 18:55 - 2017-12-05 13:36 - 000250880 _____ (Microsoft Corporation) C:\Windows\system32\icm32.dll
2018-04-12 18:55 - 2017-12-05 13:36 - 000229376 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2018-04-12 18:55 - 2017-12-05 13:36 - 000190976 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2018-04-12 18:55 - 2017-12-05 13:36 - 000141824 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2018-04-12 18:55 - 2017-12-05 13:36 - 000092160 _____ (Microsoft Corporation) C:\Windows\system32\TabSvc.dll
2018-04-12 18:55 - 2017-12-05 13:36 - 000040960 _____ (Microsoft Corporation) C:\Windows\system32\WcsPlugInService.dll
2018-04-12 18:55 - 2017-12-05 13:08 - 001176576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2018-04-12 18:55 - 2017-12-05 13:08 - 000481792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscms.dll
2018-04-12 18:55 - 2017-12-05 13:08 - 000215040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icm32.dll
2018-04-12 18:55 - 2017-12-05 13:08 - 000179200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2018-04-12 18:55 - 2017-12-05 13:08 - 000145920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2018-04-12 18:55 - 2017-12-05 13:08 - 000106496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2018-04-12 18:55 - 2017-12-05 12:04 - 000404992 _____ (Microsoft Corporation) C:\Windows\system32\wisptis.exe
2018-04-12 18:55 - 2017-12-05 11:49 - 000032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WcsPlugInService.dll
2018-04-12 18:55 - 2017-11-04 11:31 - 000194048 _____ (Microsoft Corporation) C:\Windows\system32\itircl.dll
2018-04-12 18:55 - 2017-11-04 11:31 - 000170496 _____ (Microsoft Corporation) C:\Windows\system32\itss.dll
2018-04-12 18:55 - 2017-11-04 11:10 - 000158720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\itircl.dll
2018-04-12 18:55 - 2017-11-04 11:10 - 000142336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\itss.dll
2018-04-12 18:55 - 2017-11-02 12:55 - 000281600 _____ (Microsoft Corporation) C:\Windows\system32\iprtrmgr.dll
2018-04-12 18:55 - 2017-11-02 12:55 - 000138240 _____ (Microsoft Corporation) C:\Windows\system32\rtm.dll
2018-04-12 18:55 - 2017-11-02 12:55 - 000097792 _____ (Microsoft Corporation) C:\Windows\system32\mprdim.dll
2018-04-12 18:55 - 2017-11-02 12:55 - 000009728 _____ (Microsoft Corporation) C:\Windows\system32\iprtprio.dll
2018-04-12 18:55 - 2017-11-02 11:11 - 000271360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iprtrmgr.dll
2018-04-12 18:55 - 2017-11-02 11:11 - 000115200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rtm.dll
2018-04-12 18:55 - 2017-11-02 11:11 - 000075264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mprdim.dll
2018-04-12 18:55 - 2017-11-02 10:56 - 000008192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iprtprio.dll
2018-04-12 18:55 - 2017-10-17 22:06 - 000344064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
2018-04-12 18:55 - 2017-10-17 22:06 - 000327168 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys
2018-04-12 18:55 - 2017-10-17 22:06 - 000099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys
2018-04-12 18:55 - 2017-10-17 22:06 - 000056320 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
2018-04-12 18:55 - 2017-10-17 22:06 - 000030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys
2018-04-12 18:55 - 2017-10-17 22:06 - 000025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys
2018-04-12 18:55 - 2017-10-17 22:06 - 000007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys
2018-04-12 18:55 - 2017-10-16 19:04 - 001001984 _____ (Microsoft Corporation) C:\Windows\system32\gpedit.dll
2018-04-12 18:55 - 2017-10-16 18:46 - 000953344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gpedit.dll
2018-04-12 18:55 - 2017-10-11 20:55 - 014635008 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2018-04-12 18:55 - 2017-10-11 20:55 - 012574720 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2018-04-12 18:55 - 2017-10-11 20:55 - 002319872 _____ (Microsoft Corporation) C:\Windows\system32\tquery.dll
2018-04-12 18:55 - 2017-10-11 20:55 - 002222080 _____ (Microsoft Corporation) C:\Windows\system32\mssrch.dll
2018-04-12 18:55 - 2017-10-11 20:55 - 002058240 _____ (Microsoft Corporation) C:\Windows\system32\Query.dll
2018-04-12 18:55 - 2017-10-11 20:55 - 000778240 _____ (Microsoft Corporation) C:\Windows\system32\mssvp.dll
2018-04-12 18:55 - 2017-10-11 20:55 - 000491520 _____ (Microsoft Corporation) C:\Windows\system32\mssph.dll
2018-04-12 18:55 - 2017-10-11 20:55 - 000288256 _____ (Microsoft Corporation) C:\Windows\system32\mssphtb.dll
2018-04-12 18:55 - 2017-10-11 20:55 - 000115200 _____ (Microsoft Corporation) C:\Windows\system32\mssitlb.dll
2018-04-12 18:55 - 2017-10-11 20:55 - 000099840 _____ (Microsoft Corporation) C:\Windows\system32\mssprxy.dll
2018-04-12 18:55 - 2017-10-11 20:55 - 000075264 _____ (Microsoft Corporation) C:\Windows\system32\msscntrs.dll
2018-04-12 18:55 - 2017-10-11 20:55 - 000014336 _____ (Microsoft Corporation) C:\Windows\system32\msshooks.dll
2018-04-12 18:55 - 2017-10-11 20:55 - 000009728 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll
2018-04-12 18:55 - 2017-10-11 20:55 - 000005120 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx
2018-04-12 18:55 - 2017-10-11 20:55 - 000005120 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll
2018-04-12 18:55 - 2017-10-11 20:39 - 000591872 _____ (Microsoft Corporation) C:\Windows\system32\SearchIndexer.exe
2018-04-12 18:55 - 2017-10-11 20:38 - 000249856 _____ (Microsoft Corporation) C:\Windows\system32\SearchProtocolHost.exe
2018-04-12 18:55 - 2017-10-11 20:38 - 000113664 _____ (Microsoft Corporation) C:\Windows\system32\SearchFilterHost.exe
2018-04-12 18:55 - 2017-10-11 20:37 - 012574208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL
2018-04-12 18:55 - 2017-10-11 20:37 - 011410944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2018-04-12 18:55 - 2017-10-11 20:37 - 001549824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tquery.dll
2018-04-12 18:55 - 2017-10-11 20:37 - 001400320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssrch.dll
2018-04-12 18:55 - 2017-10-11 20:37 - 001363968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Query.dll
2018-04-12 18:55 - 2017-10-11 20:37 - 000666624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssvp.dll
2018-04-12 18:55 - 2017-10-11 20:37 - 000337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssph.dll
2018-04-12 18:55 - 2017-10-11 20:37 - 000197120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssphtb.dll
2018-04-12 18:55 - 2017-10-11 20:37 - 000104448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssitlb.dll
2018-04-12 18:55 - 2017-10-11 20:37 - 000059392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msscntrs.dll
2018-04-12 18:55 - 2017-10-11 20:37 - 000034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssprxy.dll
2018-04-12 18:55 - 2017-10-11 20:26 - 000427520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchIndexer.exe
2018-04-12 18:55 - 2017-10-11 20:26 - 000164352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchProtocolHost.exe
2018-04-12 18:55 - 2017-10-11 20:25 - 000086528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchFilterHost.exe
2018-04-12 18:55 - 2017-10-11 20:25 - 000009728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msshooks.dll
2018-04-12 18:55 - 2017-10-11 20:24 - 000008192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\spwmp.dll
2018-04-12 18:55 - 2017-10-11 20:24 - 000004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdxm.ocx
2018-04-12 18:55 - 2017-10-11 20:24 - 000004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxmasf.dll
2018-04-12 18:55 - 2017-10-11 20:20 - 000317440 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdbss.sys
2018-04-12 18:55 - 2017-10-11 20:20 - 000113152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\luafv.sys
2018-04-12 18:55 - 2017-09-13 11:28 - 001068544 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll
2018-04-12 18:55 - 2017-09-13 11:28 - 000886272 _____ (Microsoft Corporation) C:\Windows\system32\wlansvc.dll
2018-04-12 18:55 - 2017-09-13 11:28 - 000448512 _____ (Microsoft Corporation) C:\Windows\system32\wlansec.dll
2018-04-12 18:55 - 2017-09-13 11:28 - 000414208 _____ (Microsoft Corporation) C:\Windows\system32\wlanmsm.dll
2018-04-12 18:55 - 2017-09-13 11:28 - 000118784 _____ (Microsoft Corporation) C:\Windows\system32\wlanhlp.dll
2018-04-12 18:55 - 2017-09-13 11:28 - 000113664 _____ (Microsoft Corporation) C:\Windows\system32\wlanapi.dll
2018-04-12 18:55 - 2017-09-13 11:09 - 000830464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msctf.dll
2018-04-12 18:55 - 2017-09-13 11:09 - 000428032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlanmsm.dll
2018-04-12 18:55 - 2017-09-13 11:09 - 000392704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlansec.dll
2018-04-12 18:55 - 2017-09-13 11:09 - 000083968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlanhlp.dll
2018-04-12 18:55 - 2017-09-13 11:09 - 000080896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlanapi.dll
2018-04-12 18:55 - 2017-09-13 11:05 - 000324608 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\nwifi.sys
2018-04-12 18:55 - 2017-09-08 11:30 - 000405504 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2018-04-12 18:55 - 2017-09-08 11:10 - 000312832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2018-04-12 18:55 - 2017-09-08 10:20 - 000640512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswstr10.dll
2018-04-12 18:55 - 2017-09-08 10:20 - 000008704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msjint40.dll
2018-04-12 18:55 - 2017-09-07 11:31 - 002851328 _____ (Microsoft Corporation) C:\Windows\system32\themeui.dll
2018-04-12 18:55 - 2017-09-07 11:12 - 002755072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\themeui.dll
2018-04-12 18:55 - 2017-08-19 11:28 - 004121600 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2018-04-12 18:55 - 2017-08-19 11:28 - 000206848 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll
2018-04-12 18:55 - 2017-08-19 11:28 - 000197120 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll
2018-04-12 18:55 - 2017-08-19 11:28 - 000002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll
2018-04-12 18:55 - 2017-08-19 11:10 - 003209216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll
2018-04-12 18:55 - 2017-08-19 11:10 - 000180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll
2018-04-12 18:55 - 2017-08-19 11:10 - 000103424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfps.dll
2018-04-12 18:55 - 2017-08-19 11:10 - 000002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mferror.dll
2018-04-12 18:55 - 2017-08-19 11:08 - 000055808 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe
2018-04-12 18:55 - 2017-08-19 11:08 - 000024576 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe
2018-04-12 18:55 - 2017-08-19 10:57 - 000050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rrinstaller.exe
2018-04-12 18:55 - 2017-08-19 10:57 - 000023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfpmp.exe
2018-04-12 18:55 - 2017-08-16 11:29 - 000806912 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll
2018-04-12 18:55 - 2017-08-16 11:10 - 000629760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll
2018-04-12 18:55 - 2017-08-14 13:35 - 003203584 _____ (Microsoft Corporation) C:\Windows\system32\mmcndmgr.dll
2018-04-12 18:55 - 2017-08-14 13:35 - 002150912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mmcndmgr.dll
2018-04-12 18:55 - 2017-08-14 13:35 - 001032192 _____ (Microsoft Corporation) C:\Windows\system32\rdpcore.dll
2018-04-12 18:55 - 2017-08-14 13:35 - 000827904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpcore.dll
2018-04-12 18:55 - 2017-08-14 13:35 - 000355328 _____ (Microsoft Corporation) C:\Windows\system32\mmcbase.dll
2018-04-12 18:55 - 2017-08-14 13:35 - 000303104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mmcbase.dll
2018-04-12 18:55 - 2017-08-14 13:35 - 000172544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cic.dll
2018-04-12 18:55 - 2017-08-14 13:35 - 000131072 _____ (Microsoft Corporation) C:\Windows\system32\mmcshext.dll
2018-04-12 18:55 - 2017-08-14 13:35 - 000128512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mmcshext.dll
2018-04-12 18:55 - 2017-08-14 13:35 - 000022528 _____ (Microsoft Corporation) C:\Windows\system32\icaapi.dll
2018-04-12 18:55 - 2017-08-14 13:34 - 000211968 _____ (Microsoft Corporation) C:\Windows\system32\cic.dll
2018-04-12 18:55 - 2017-08-13 17:45 - 000040448 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
2018-04-12 18:55 - 2017-08-13 17:37 - 002144256 _____ (Microsoft Corporation) C:\Windows\system32\mmc.exe
2018-04-12 18:55 - 2017-08-13 17:30 - 001401344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mmc.exe
2018-04-12 18:55 - 2017-08-11 02:35 - 000757248 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll
2018-04-12 18:55 - 2017-08-11 02:35 - 000346112 _____ (Microsoft Corporation) C:\Windows\system32\ntprint.dll
2018-04-12 18:55 - 2017-08-11 02:35 - 000313856 _____ (Microsoft Corporation) C:\Windows\system32\Wldap32.dll
2018-04-12 18:55 - 2017-08-11 02:35 - 000026112 _____ (Microsoft Corporation) C:\Windows\system32\nsisvc.dll
2018-04-12 18:55 - 2017-08-11 02:35 - 000025600 _____ (Microsoft Corporation) C:\Windows\system32\winnsi.dll
2018-04-12 18:55 - 2017-08-11 02:35 - 000013312 _____ (Microsoft Corporation) C:\Windows\system32\nsi.dll
2018-04-12 18:55 - 2017-08-11 02:34 - 000971776 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll
2018-04-12 18:55 - 2017-08-11 02:34 - 000166400 _____ (Microsoft Corporation) C:\Windows\system32\inetpp.dll
2018-04-12 18:55 - 2017-08-11 02:34 - 000022528 _____ (Microsoft Corporation) C:\Windows\system32\inetppui.dll
2018-04-12 18:55 - 2017-08-11 02:20 - 000061952 _____ (Microsoft Corporation) C:\Windows\system32\ntprint.exe
2018-04-12 18:55 - 2017-08-11 02:20 - 000048640 _____ (Microsoft Corporation) C:\Windows\system32\wpnpinst.exe
2018-04-12 18:55 - 2017-08-11 02:19 - 000497664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll
2018-04-12 18:55 - 2017-08-11 02:19 - 000299008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntprint.dll
2018-04-12 18:55 - 2017-08-11 02:19 - 000271360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Wldap32.dll
2018-04-12 18:55 - 2017-08-11 02:19 - 000016384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winnsi.dll
2018-04-12 18:55 - 2017-08-11 02:19 - 000008704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nsi.dll
2018-04-12 18:55 - 2017-08-11 02:12 - 000025088 _____ (Microsoft Corporation) C:\Windows\system32\netbtugc.exe
2018-04-12 18:55 - 2017-08-11 02:09 - 000061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntprint.exe
2018-04-12 18:55 - 2017-08-11 02:03 - 000026624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netbtugc.exe
2018-04-12 18:55 - 2017-08-11 02:00 - 000262656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netbt.sys
2018-04-12 18:55 - 2017-08-11 01:58 - 000026112 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\nsiproxy.sys
2018-04-12 18:55 - 2017-07-29 10:56 - 000117248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys
2018-04-12 18:55 - 2017-07-21 10:26 - 000518144 _____ C:\Windows\SysWOW64\msjetoledb40.dll
2018-04-12 18:55 - 2017-07-21 10:26 - 000409600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msexch40.dll
2018-04-12 18:55 - 2017-07-21 10:26 - 000290816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msjtes40.dll
2018-04-12 18:55 - 2017-07-21 10:26 - 000282624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstext40.dll
2018-04-12 18:55 - 2017-07-14 11:29 - 000486400 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
2018-04-12 18:55 - 2017-07-14 11:29 - 000034304 _____ (Microsoft Corporation) C:\Windows\system32\werdiagcontroller.dll
2018-04-12 18:55 - 2017-07-14 11:10 - 000382976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll
2018-04-12 18:55 - 2017-07-14 10:57 - 000050688 _____ (Microsoft Corporation) C:\Windows\system32\wermgr.exe
2018-04-12 18:55 - 2017-07-14 10:50 - 000054272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wermgr.exe
2018-04-12 18:55 - 2017-07-14 10:50 - 000028672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\werdiagcontroller.dll
2018-04-12 18:55 - 2017-07-07 11:33 - 000363752 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\volmgrx.sys
2018-04-12 18:55 - 2017-07-07 11:29 - 001143296 _____ (Microsoft Corporation) C:\Windows\system32\DXPTaskRingtone.dll
2018-04-12 18:55 - 2017-07-07 11:10 - 000973312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DXPTaskRingtone.dll
2018-04-12 18:55 - 2017-07-01 09:05 - 001311744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msjet40.dll
2018-04-12 18:55 - 2017-07-01 09:05 - 000866816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswdat10.dll
2018-04-12 18:55 - 2017-07-01 09:05 - 000616448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrepl40.dll
2018-04-12 18:55 - 2017-07-01 09:05 - 000475648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxbde40.dll
2018-04-12 18:55 - 2017-07-01 09:05 - 000375808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mspbde40.dll
2018-04-12 18:55 - 2017-07-01 09:05 - 000343552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrd3x40.dll
2018-04-12 18:55 - 2017-07-01 09:05 - 000310272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrd2x40.dll
2018-04-12 18:55 - 2017-07-01 09:05 - 000240640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msltus40.dll
2018-04-12 18:55 - 2017-07-01 09:05 - 000083968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msjter40.dll
2018-04-12 18:44 - 2018-03-14 13:14 - 000135360 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe
2018-04-12 18:44 - 2018-03-14 13:09 - 000656384 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2018-04-12 18:44 - 2018-03-14 09:05 - 001993728 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe
2018-04-12 18:44 - 2018-03-14 09:05 - 001559552 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2018-04-12 18:44 - 2018-03-14 09:05 - 000739840 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2018-04-12 18:44 - 2018-03-14 09:05 - 000599552 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2018-04-12 18:44 - 2018-03-14 09:05 - 000450048 _____ (Microsoft Corporation) C:\Windows\system32\centel.dll
2018-04-12 18:44 - 2018-03-14 09:05 - 000414720 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2018-04-12 18:44 - 2018-03-14 09:05 - 000291840 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2018-04-12 18:44 - 2018-03-14 09:05 - 000237056 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2018-04-12 16:19 - 2018-04-13 09:13 - 000003634 _____ C:\Windows\System32\Tasks\WizMouse
2018-04-07 16:27 - 2018-04-07 16:27 - 000001409 _____ C:\Windows\QTFont.for
2018-04-03 16:23 - 2018-04-03 16:27 - 000000000 ____D C:\8b86d66ed5fdc1c4b784ccbf
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2018-04-26 10:11 - 2009-07-13 22:34 - 021233664 _____ C:\Windows\system32\config\HARDWARE
2018-04-26 10:06 - 2014-12-09 16:11 - 000000000 ____D C:\Program Files\SoftEther VPN Client
2018-04-26 09:15 - 2014-05-21 15:55 - 136971704 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2018-04-26 09:02 - 2009-07-14 00:45 - 000018928 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2018-04-26 09:02 - 2009-07-14 00:45 - 000018928 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2018-04-26 08:34 - 2014-07-19 19:27 - 000000000 ____D C:\ProgramData\Aimersoft Video Converter Ultimate
2018-04-26 08:27 - 2016-03-16 20:40 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Deluge
2018-04-26 08:27 - 2014-06-02 13:41 - 000000000 ____D C:\Program Files (x86)\Deluge
2018-04-25 19:19 - 2014-05-11 09:56 - 000000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2018-04-25 19:16 - 2009-07-13 23:20 - 000000000 ____D C:\Windows\inf
2018-04-25 17:31 - 2009-07-14 01:13 - 001027272 _____ C:\Windows\system32\PerfStringBackup.INI
2018-04-25 17:29 - 2016-07-21 11:22 - 000001105 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VAIO Update.lnk
2018-04-25 17:22 - 2009-07-14 01:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2018-04-25 16:49 - 2016-07-02 14:01 - 000001908 _____ C:\Windows\diagwrn.xml
2018-04-25 16:49 - 2016-07-02 14:01 - 000001908 _____ C:\Windows\diagerr.xml
2018-04-25 16:28 - 2009-07-13 23:20 - 000000000 ____D C:\Windows\registration
2018-04-25 16:18 - 2014-06-22 03:15 - 000000000 ____D C:\Users\Guest
2018-04-25 16:02 - 2014-05-11 01:07 - 000000000 ____D C:\Windows\Panther
2018-04-25 15:51 - 2015-02-19 21:06 - 000000000 ____D C:\Windows\Minidump
2018-04-25 15:51 - 2014-05-11 00:08 - 000300770 ____N C:\Windows\Minidump\042518-53586-01.dmp
2018-04-25 15:03 - 2014-05-11 00:08 - 000300898 ____N C:\Windows\Minidump\042518-50559-01.dmp
2018-04-25 14:18 - 2014-06-28 09:48 - 000000000 ____D C:\Program Files\AntiMalwareApps
2018-04-25 13:36 - 2014-05-21 23:15 - 000000000 ____D C:\ProgramData\Malwarebytes
2018-04-25 10:59 - 2014-05-22 21:27 - 000000000 ____D C:\Users\Administrator
2018-04-23 19:44 - 2009-07-14 00:45 - 005102016 _____ C:\Windows\system32\FNTCACHE.DAT
2018-04-23 19:38 - 2014-05-11 00:08 - 000300898 ____N C:\Windows\Minidump\042318-80246-01.dmp
2018-04-23 19:34 - 2009-07-13 23:20 - 000000000 ____D C:\Windows\SysWOW64\Setup
2018-04-23 19:33 - 2015-04-17 11:41 - 000000000 ____D C:\Windows\system32\appraiser
2018-04-23 19:33 - 2009-07-13 23:20 - 000000000 ____D C:\Windows\system32\Setup
2018-04-23 18:53 - 2014-06-16 15:49 - 000000000 ____D C:\ProgramData\WinZip
2018-04-23 18:25 - 2009-07-13 19:29 - 008338432 _____ (Microsoft Corporation) C:\Windows\system32\spwizimg.dll
2018-04-23 18:13 - 2015-05-23 09:32 - 000000000 ____D C:\ProgramData\Unchecky
2018-04-23 18:13 - 2014-07-02 15:25 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PeaZip
2018-04-23 18:13 - 2014-07-02 15:25 - 000000000 ____D C:\Program Files\PeaZip
2018-04-23 18:07 - 2009-07-13 22:34 - 000000477 _____ C:\Windows\win.ini
2018-04-23 15:36 - 2014-05-11 00:08 - 000300194 ____N C:\Windows\Minidump\042318-43165-01.dmp
2018-04-23 13:53 - 2014-05-11 00:08 - 000300770 ____N C:\Windows\Minidump\042318-33181-01.dmp
2018-04-23 12:43 - 2014-05-11 00:17 - 000000000 ____D C:\Users\New User
2018-04-23 12:42 - 2016-12-26 13:58 - 000000000 ____D C:\Users\New User\AppData\Roaming\Kodi
2018-04-23 12:42 - 2014-05-11 09:58 - 000000000 ____D C:\Users\New User\AppData\Roaming\Adobe
2018-04-23 12:17 - 2009-07-14 00:57 - 000001547 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2018-04-23 12:10 - 2014-05-11 00:08 - 000300770 ____N C:\Windows\Minidump\042318-58781-01.dmp
2018-04-23 10:57 - 2014-05-11 00:08 - 000300770 ____N C:\Windows\Minidump\042318-32900-01.dmp
2018-04-23 09:49 - 2014-05-22 21:28 - 000091136 _____ C:\Users\Administrator\AppData\Local\GDIPFONTCACHEV1.DAT
2018-04-22 20:36 - 2014-05-11 00:08 - 000300194 ____N C:\Windows\Minidump\042218-45037-01.dmp
2018-04-22 19:54 - 2014-05-11 00:08 - 000300770 ____N C:\Windows\Minidump\042218-52151-01.dmp
2018-04-22 18:50 - 2014-05-11 00:08 - 000300770 ____N C:\Windows\Minidump\042218-154815-01.dmp
2018-04-22 08:05 - 2014-05-22 10:47 - 000000000 ____D C:\Program Files (x86)\Adobe
2018-04-22 07:22 - 2014-05-11 00:08 - 000300770 ____N C:\Windows\Minidump\042218-79700-01.dmp
2018-04-22 07:02 - 2014-05-11 00:08 - 000300770 ____N C:\Windows\Minidump\042218-148684-01.dmp
2018-04-21 22:13 - 2014-05-11 00:08 - 000300770 ____N C:\Windows\Minidump\042118-30170-01.dmp
2018-04-21 22:09 - 2015-02-26 16:38 - 000000000 ____D C:\Windows\pss
2018-04-21 21:42 - 2014-05-11 00:08 - 000300770 ____N C:\Windows\Minidump\042118-28204-01.dmp
2018-04-21 21:36 - 2014-05-11 00:08 - 000300770 ____N C:\Windows\Minidump\042118-32417-01.dmp
2018-04-21 21:24 - 2014-05-11 00:08 - 000300770 ____N C:\Windows\Minidump\042118-40248-01.dmp
2018-04-21 20:52 - 2015-11-14 22:18 - 000054053 _____ C:\Windows\ZAM.krnl.trace
2018-04-21 20:52 - 2015-11-14 22:18 - 000053404 _____ C:\Windows\ZAM_Guard.krnl.trace
2018-04-14 16:14 - 2009-07-13 23:20 - 000000000 ____D C:\Windows\rescache
2018-04-13 16:12 - 2014-05-24 17:41 - 000000000 ____D C:\Update
2018-04-13 14:45 - 2014-05-11 07:58 - 000000021 _____ C:\Windows\Model.txt
2018-04-13 14:34 - 2014-11-16 17:58 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JBidwatcher
2018-04-13 14:34 - 2014-11-16 17:58 - 000000000 ____D C:\Program Files (x86)\CyberFOX Software
2018-04-13 09:37 - 2014-05-22 21:28 - 000000000 ____D C:\Users\Administrator\AppData\Local\Google
2018-04-12 19:06 - 2014-05-____D C:\Windows\system32\MRT
2018-04-12 16:55 - 2015-03-27 21:29 - 000028272 _____ C:\Windows\system32\Drivers\TrueSight.sys
2018-04-12 16:54 - 2015-03-27 21:29 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RogueKiller
2018-04-12 16:18 - 2009-07-14 01:09 - 000000000 ____D C:\Windows\System32\Tasks\WPD
2018-04-07 16:27 - 2015-02-27 16:44 - 000054156 ____H C:\Windows\QTFont.qfn
2018-04-04 14:18 - 2014-05-31 09:31 - 000000564 _____ C:\Windows\WORDPAD.INI
2018-04-03 16:23 - 2015-01-24 17:40 - 000000000 ____D C:\Program Files (x86)\TurboTax
2018-04-01 10:39 - 2009-07-14 01:08 - 000032646 _____ C:\Windows\Tasks\SCHEDLGU.TXT
==================== Files in the root of some directories =======
2018-04-13 11:51 - 2018-04-12 14:25 - 005767168 _____ () C:\Users\2018Jean\ntuser (2).dat
2014-05-30 23:00 - 2014-05-30 23:00 - 000001705 _____ () C:\Program Files\Add-Take-Ownership-Option.zip
2015-03-07 17:48 - 2015-03-07 17:49 - 002913497 _____ (Saru Software®) C:\Program Files\Clock.exe
2014-05-22 18:47 - 2008-03-27 19:45 - 000480768 _____ (Pablo Software Solutions) C:\Program Files\FTPWanderer.exe
2015-02-26 16:51 - 2015-02-02 14:13 - 001388274 _____ (Thisisu) C:\Program Files\JRT_NEW.exe
2008-08-10 13:09 - 2008-08-10 13:09 - 001083904 _____ (Squared 5) C:\Program Files\MPEG_Streamclip.exe
2014-09-24 16:15 - 2007-04-20 00:35 - 000118784 _____ (Jeff Key) C:\Program Files\Ruler.exe
2013-08-26 11:55 - 2013-08-26 11:55 - 007665437 _____ (SerialBox Windows) C:\Program Files\SerialBox Windows V0.1.5 Portable.exe
2014-05-22 19:35 - 2014-06-02 13:19 - 000000481 _____ () C:\Program Files\sites.xml
2015-10-25 12:11 - 2015-10-25 12:11 - 000000900 _____ () C:\Program Files (x86)\Adobe Spare dll file - Shortcut.lnk
2012-08-19 12:35 - 2012-08-19 12:35 - 000899584 _____ (Squared 5) C:\Program Files (x86)\MPEG_Streamclip.exe
2016-07-08 12:09 - 2016-07-08 16:17 - 021737496 _____ (LastPass) C:\Program Files (x86)\Common Files\lpuninstall.exe
2018-04-13 06:45 - 2018-04-13 06:45 - 004279968 _____ (NeoSoft Tools ) C:\Users\2018Jean\AppData\Roaming\ctask.exe
2018-04-25 18:30 - 2018-04-25 18:30 - 000001456 _____ () C:\Users\2018Jean\AppData\Local\Adobe Save for Web 13.0 Prefs
2018-04-24 16:27 - 2018-04-24 16:27 - 000001245 _____ () C:\Users\2018Jean\AppData\Local\recently-used.xbel
2018-04-21 17:02 - 2018-04-21 17:02 - 000051200 _____ () C:\Users\2018Jean\AppData\Local\Slighting.exe
2018-04-21 17:02 - 2018-04-21 17:02 - 000051200 _____ () C:\Users\2018Jean\AppData\Local\undermining.exe
Some files in TEMP:
====================
2018-04-13 14:45 - 2010-06-20 22:42 - 000046456 _____ (Sony Electronics, Inc) C:\Users\2018Jean\AppData\Local\Temp\GLF7121.EXE
2018-04-13 14:45 - 2003-05-02 15:13 - 000151552 _____ () C:\Users\2018Jean\AppData\Local\Temp\GLF7612.EXE
2018-04-13 14:03 - 2018-04-13 14:03 - 000116997 _____ () C:\Users\2018Jean\AppData\Local\Temp\jffi2511343256368944750.dll
2018-04-23 17:38 - 2018-04-23 17:38 - 014769392 _____ () C:\Users\2018Jean\AppData\Local\Temp\ReimagePackage.exe
2018-01-11 12:21 - 2018-01-11 12:21 - 778536164 _____ () C:\Users\2018Jean\AppData\Local\Temp\setup.dll
2018-04-22 07:18 - 2003-03-24 18:50 - 000098304 _____ (Adobe Systems Inc.) C:\Users\2018Jean\AppData\Local\Temp\UninstManager.dll
2018-04-13 14:34 - 2018-04-13 14:34 - 000503808 _____ () C:\Users\2018Jean\AppData\Local\Temp\xuninst.exe
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
C:\Windows\system32\drivers\dwrpswzc.sys -> Access Denied <======= ATTENTION
LastRegBack: 2018-04-19 14:59
==================== End of FRST.txt ============================ 21 15:55
[ P.S. I am so amazed that you are willing to provide help as volunteers. I live in a very small town and am a long way away from professional help that would be hard to afford right now. Whether or not you can walk me through resolving the problems, I am very appreciative of your effort.
I've moved my issue over here from the BSOD section - see that posting for description of the issue.
A new MSE full scan this morning shows nothing heinous.
Here are fresh logs as requested in your wiki:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 25.04.2018Ran by 2018Jean (26-04-2018 10:15:08)
Running from C:\Users\2018Jean\Desktop\Cooties\FRST scans
Windows 7 Home Premium Service Pack 1 (X64) (2014-05-11 04:17:47)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
2018Jean (S-1-5-21-4256033146-2562541644-1532691662-1006 - Administrator - Enabled) => C:\Users\2018Jean
Administrator (S-1-5-21-4256033146-2562541644-1532691662-500 - Administrator - Enabled) => C:\Users\Administrator
Guest (S-1-5-21-4256033146-2562541644-1532691662-501 - Administrator - Enabled)
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Microsoft Security Essentials (Enabled - Up to date) {B7ECF8CD-0188-6703-DBA4-AA65C6ACFB0A}
AS: Microsoft Security Essentials (Enabled - Up to date) {0C8D1929-27B2-688D-E114-9117BD2BB1B7}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
AC3Filter (remove only) (HKLM-x32\...\AC3Filter) (Version: - )
ACID Pro 7.0 (HKLM-x32\...\{BFA5441E-B7E6-46F5-A15D-1B74707AE93A}) (Version: 7.0.641 - Sony)
Acronis Drive Monitor (HKLM-x32\...\{706AE61D-40A4-4F50-8359-FE8F6F7FA461}) (Version: 1.0.566 - Acronis)
Adobe Acrobat 7.0 Professional - English, Français, Deutsch (HKLM-x32\...\Adobe Acrobat 7.0 Professional - English, Français, Deutsch - V) (Version: 7.0.0 - Adobe Systems)
Adobe Flash Player 13 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 13.0.0.214 - Adobe Systems Incorporated)
Adobe Flash Player 18 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 18.0.0.232 - Adobe Systems Incorporated)
Adobe Flash Player 23 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 23.0.0.162 - Adobe Systems Incorporated)
Adobe GoLive CS2 English (HKLM-x32\...\Adobe GoLive CS2 English) (Version: 8.0 - Adobe Systems)
Adobe InDesign CS2 (HKLM-x32\...\Adobe InDesign CS2 - {7F4C8163-F259-49A0-A018-2857A90578BC}) (Version: 004.000.000 - Adobe Systems Incorporated)
Adobe Photoshop CS2 (HKLM-x32\...\Adobe Photoshop CS2 - {236BB7C4-4419-42FD-0409-1E257A25E34D}) (Version: 9.0 - Adobe Systems, Inc.)
Adobe Photoshop CS5.1 (HKLM-x32\...\{9158FF30-78D7-40EF-B83E-451AC5334640}) (Version: 12.1 - Adobe Systems Incorporated)
Adobe Photoshop CS6 (HKLM-x32\...\{74EB3499-8B95-4B5C-96EB-7B342F3FD0C6}) (Version: 13.0 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.07) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.07 - Adobe Systems Incorporated)
Adobe SVG Viewer 3.0 (HKLM-x32\...\Adobe SVG Viewer) (Version: 3.0 - Adobe Systems, Inc.)
Aimersoft Video Converter Ultimate(Build 6.2.0.0) (HKLM-x32\...\Aimersoft Video Converter Ultimate_is1) (Version: 6.2.0.0 - Aimersoft Software)
Airfoil (HKLM-x32\...\Airfoil) (Version: 3.5.0 - Rogue Amoeba)
Alps Pointing-device for VAIO (HKLM\...\{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}) (Version: - ALPS ELECTRIC CO., LTD.)
ArcSoft WebCam Companion 3 (HKLM-x32\...\{DE8AAC73-6D8D-483E-96EA-CAEDDADB9079}) (Version: 3.0.21.390 - ArcSoft)
ASIO Bridge and Hi-Fi Cable (HKLM-x32\...\VB:ASIOBridge {17359A74-1236-5467}) (Version: - VB-Audio Software)
Audacity 2.0.5 (HKLM-x32\...\Audacity_is1) (Version: 2.0.5 - Audacity Team)
Avidemux 2.6 - 64bits (HKLM-x32\...\Avidemux 2.6 - 64bits (64-bit)) (Version: 2.6.8.9046 - )
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Callcentric Softphone (HKLM-x32\...\{CEA83C20-AFCB-426C-89ED-0AC90015F04B}) (Version: 2.0.4 - Callcentric)
Canon IJ Scan Utility (HKLM-x32\...\Canon_IJ_Scan_Utility) (Version: - Canon Inc.)
Canon MG2500 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG2500_series) (Version: 1.02 - Canon Inc.)
Canon MG2500 series On-screen Manual (HKLM-x32\...\Canon MG2500 series On-screen Manual) (Version: 7.6.1 - Canon Inc.)
Canon MG2500 series User Registration (HKLM-x32\...\Canon MG2500 series User Registration) (Version: - *Canon Inc.)
Canon My Printer (HKLM-x32\...\CanonMyPrinter) (Version: 3.1.0 - Canon Inc.)
CCleaner (HKLM\...\CCleaner) (Version: 4.15 - Piriform)
Cisco EAP-FAST Module (HKLM-x32\...\{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}) (Version: 2.2.14 - Cisco Systems, Inc.)
Cisco LEAP Module (HKLM-x32\...\{51C7AD07-C3F6-4635-8E8A-231306D810FE}) (Version: 1.0.19 - Cisco Systems, Inc.)
Cisco PEAP Module (HKLM-x32\...\{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}) (Version: 1.1.6 - Cisco Systems, Inc.)
Core Temp 1.1 (HKLM\...\{086D343F-8E78-4AFC-81AC-D6D414AFD8AC}_is1) (Version: 1.1 - Alcpu)
CrystalDiskInfo 7.6.0 (HKLM-x32\...\CrystalDiskInfo_is1) (Version: 7.6.0 - Crystal Dew World)
D3DX10 (HKLM-x32\...\{E09C4DB7-630C-4F06-A631-8EA7239923AF}) (Version: 15.4.2368.0902 - Microsoft) Hidden
Desktop Restore version 1.6.4 (HKLM\...\{DBD4F07A-7607-4A4F-A46C-6AA399E06E38}_is1) (Version: 1.6.4 - Jamie O'Connell)
DLNow 1.2 (HKLM-x32\...\DLNow) (Version: 1.2 - Logixoft)
DNS Leak Fix for OpenVPN version 1.2 (HKLM-x32\...\{8CFA1D01-AECD-4913-9FB8-1E8A82F47824}_is1) (Version: 1.2 - dnsleaktest.com)
Doxillion Document Converter (HKLM-x32\...\Doxillion) (Version: 2.71 - NCH Software)
Dream Aquarium (HKLM-x32\...\Dream Aquarium) (Version: - )
DVD Audio Extractor 7.2.0 (HKLM-x32\...\DVD Audio Extractor_is1) (Version: - Computer Application Studio)
DVD Decrypter (Remove Only) (HKLM-x32\...\DVD Decrypter) (Version: - )
Express Burn Disc Burning Software (HKLM-x32\...\ExpressBurn) (Version: 6.09 - NCH Software)
Fast Duplicate File Finder 4.1.0.1 (HKLM-x32\...\{AFECFED6-0A43-488F-8511-1DC6B52F31C3}_is1) (Version: 4.1.0.1 - MindGems, Inc.)
FBReader for Windows (HKLM-x32\...\FBReader for Windows) (Version: - )
FileZilla Client 3.14.0 (HKLM-x32\...\FileZilla Client) (Version: 3.14.0 - Tim Kosse)
Folder Colorizer version 1.3.3 (HKLM\...\{A133E9CD-2879-4F30-87D4-1604AFD5C5CC}_is1) (Version: 1.3.3 - Softorino)
Folder Size 3.4.0.0 (HKLM-x32\...\{2DFA85ED-588F-4CE3-A175-29E52C3804A8}_is1) (Version: 3.4.0.0 - MindGems, Inc.)
Gihosoft Free Youtube Downloader version 1.2.7.0 (HKLM-x32\...\{222ECA2E-17A6-4914-922A-BABE02869072}_is1) (Version: 1.2.7.0 - HONGKONG JIHO CO., LIMITED)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 66.0.3359.117 - Google Inc.)
Google Drive (HKLM-x32\...\{9BC95947-92FD-438B-A168-C01F9A5B7292}) (Version: 2.34.7529.6838 - Google, Inc.)
Google Talk Plugin (HKLM-x32\...\{F9B579C2-D854-300A-BE62-A09EB9D722E4}) (Version: 5.41.3.0 - Google)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.7 - Google Inc.) Hidden
Google Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.25.11 - Google Inc.) Hidden
ImgBurn (HKLM-x32\...\ImgBurn) (Version: 2.5.8.0 - LIGHTNING UK!)
InstallShield Tuner 7.0 for Adobe Acrobat (HKLM-x32\...\{E32FC3D8-D106-425E-9F9E-8BE6E2E79AC9}) (Version: 7.0 - Adobe)
IObit Unlocker (HKLM-x32\...\IObit Unlocker_is1) (Version: 1.1 - IObit)
ISO Opener (HKLM-x32\...\{CE235F00-F8CD-41AF-83D5-236D90E33BFB}_is1) (Version: - ISO Opener)
Java 8 Update 73 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218073F0}) (Version: 8.0.730.2 - Oracle Corporation)
JBidwatcher 2.5.6 (HKLM-x32\...\JBidwatcher_0) (Version: 2.5.6 - CyberFOX Software, Inc)
JBidwatcher 2.5.6 (HKLM-x32\...\JBidwatcher_1) (Version: 2.5.6 - CyberFOX Software, Inc)
LAME v3.99.3 (for Windows) (HKLM-x32\...\LAME_is1) (Version: - )
LightScribe System Software (HKLM-x32\...\{F132000C-1CBA-458F-BF2F-FD43D59410F9}) (Version: 1.18.27.10 - LightScribe)
LightScribe Template Designs - Expressions (HKLM-x32\...\{A5CC4D86-371A-4044-A7F3-C6CFCC4CA813}) (Version: 1.18.8.111 - LightScribe)
LightScribe Template Designs - Music Pack 1 (HKLM-x32\...\{4ECA4128-8B48-44A0-90E8-B93C6A69CE4B}) (Version: 1.15.0.0 - LightScribe)
LightScribe Template Labeler (HKLM-x32\...\{8A03241E-7A3C-401D-B0CE-B3096F50AE6F}) (Version: 1.18.27.10 - LightScribe)
Loan*Calculator! Plus v3.0 (HKLM-x32\...\{D1A42E6B-7D3D-4B46-AA82-659FF905CA40}_is1) (Version: 3.0 - Pine Grove Software, LLC)
Malwarebytes version 3.4.5.2467 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.4.5.2467 - Malwarebytes)
Mediatek RT2870 Wireless LAN Card (HKLM-x32\...\{28DA7D8B-F9A4-4F18-8AA0-551B1E084D0D}) (Version: 1.5.38.101 - MediatekWiFi)
Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation)
Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.8.204.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40416.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{CA8A885F-E95B-3FC6-BB91-F4D9377C7686}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Motorola Device Manager (HKLM-x32\...\{28DB8373-C1BB-444F-A427-A55585A12ED7}) (Version: 2.5.4 - Motorola Mobility)
Movie Maker (HKLM-x32\...\{38F03569-A636-4CF3-BDDE-032C8C251304}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Movie Maker (HKLM-x32\...\{DD67BE4B-7E62-4215-AFA3-F123A800A389}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Mozilla Firefox 57.0 (x64 en-US) (HKLM\...\Mozilla Firefox 57.0 (x64 en-US)) (Version: 57.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 57.0.0.6525 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
Nero 2015 (HKLM-x32\...\{763EF8DC-4CC0-47CA-BE1C-BDE731462250}) (Version: 16.0.02900 - Nero AG)
Nero Info (HKLM-x32\...\{B791E0AB-87A9-41A4-8D98-D13C2E37D928}) (Version: 16.0.1003 - Nero AG)
NETGEAR Genie (HKLM-x32\...\NETGEAR Genie) (Version: 2.4.12.00 - NETGEAR Inc.)
NexusFont 2.5 (ver 2.5.8.1582) (HKLM-x32\...\{EFEDD205-43FE-4208-B682-0937E803E19E}_is1) (Version: - xiles)
NirSoft BlueScreenView (HKLM-x32\...\NirSoft BlueScreenView) (Version: - )
NVIDIA GeForce Experience 2.1.1 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.1.1 - NVIDIA Corporation)
NVIDIA Graphics Driver 337.88 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 337.88 - NVIDIA Corporation)
NVIDIA HD Audio Driver 1.3.30.1 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.30.1 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.13.1220 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.1220 - NVIDIA Corporation)
OpenOffice 4.1.0 (HKLM-x32\...\{C87EF11D-36E9-479D-9898-7541EA1E8A6A}) (Version: 4.10.9764 - Apache Software Foundation)
PeaZip 6.5.1 (WIN64) (HKLM\...\{5A2BC38A-406C-4A5B-BF45-6991F9A05325}_is1) (Version: 6.5.1 - Giorgio Tani)
Perfect Resize 7.0.1 Professional Edition (HKLM-x32\...\{FCADA4FF-142C-42A8-B73C-0A54A7F83345}) (Version: 7.0.1 - onOne Software)
Pismo File Mount Audit Package (HKLM\...\PismoFileMountAuditPackage) (Version: - )
Prerequisite installer (HKLM-x32\...\{799AFA36-4EA5-4323-8689-74C06645A26B}) (Version: 16.0.0000 - Nero AG) Hidden
Prism Video File Converter (HKLM-x32\...\Prism) (Version: - NCH Software)
Prismatik (remove only) (HKLM-x32\...\{2175EE1B-0160-4862-9096-C522B1B99042}_is1) (Version: 5.11.1 - Woodenshark LLC)
PVSonyDll (HKLM\...\{3D3E663D-4E7E-4577-A560-7ECDDD45548A}) (Version: 1.00.0001 - NVIDIA Corporation) Hidden
QuickGamma 2.0.0.3 (HKLM-x32\...\QuickGamma_is1) (Version: - Eberhard Werle)
QuickTime Alternative 1.81 (HKLM-x32\...\QuicktimeAlt_is1) (Version: 1.81 - )
RBVirtualFolder64Inst (HKLM\...\{9D6DFAD6-09E5-445E-A4B5-A388FEEBD90D}) (Version: 1.00.0000 - Roxio, Inc.) Hidden
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6098 - Realtek Semiconductor Corp.)
REALTEK Wireless LAN Driver and Utility (HKLM-x32\...\{9C049509-055C-4CFF-A116-1D12312225EB}) (Version: 1.00.0199 - REALTEK Semiconductor Corp.)
Remote Keyboard (HKLM-x32\...\{25AF1025-095C-4AA9-A3FD-29710D3C3AE5}) (Version: 1.1.1.07060 - Sony Corporation) Hidden
Renesas Electronics USB 3.0 Host Controller Driver (HKLM-x32\...\{5442DAB8-7177-49E1-8B22-09A049EA5996}) (Version: 2.0.4.1 - Renesas Electronics Corporation) Hidden
Renesas Electronics USB 3.0 Host Controller Driver (HKLM-x32\...\InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}) (Version: 2.0.4.1 - Renesas Electronics Corporation)
River Past Audio Converter Pro (HKLM\...\Audio Converter Pro) (Version: 7.7.1 - River Past)
Roxio Creator 2011 Content (HKLM-x32\...\{9F717571-FEE8-45CD-8B03-5B2D06AD28F7}) (Version: 13.0.098 - Roxio)
Roxio Creator 2011 Pro (HKLM-x32\...\{4433FF9E-AF21-4E41-B296-4E13BF4D52F5}) (Version: 13.0 - Roxio)
Roxio PhotoShow (HKLM-x32\...\Roxio PhotoShow) (Version: 6.0 - Sonic Solutions)
SeaMonkey 2.26.1 (x86 en-US) (HKLM-x32\...\SeaMonkey 2.26.1 (x86 en-US)) (Version: 2.26.1 - Mozilla)
Serviio (HKLM\...\Serviio) (Version: - )
SHIELD Streaming (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GFExperience.NvStreamSrv) (Version: 3.1.100 - NVIDIA Corporation) Hidden
SmartSound Common Data (HKLM-x32\...\{B8A2869E-30CA-40C5-9CF8-BD7354E57EF8}) (Version: 1.1.0 - SmartSound Software Inc.) Hidden
SmartSound Common Data (HKLM-x32\...\InstallShield_{B8A2869E-30CA-40C5-9CF8-BD7354E57EF8}) (Version: 1.1.0 - SmartSound Software Inc.)
SmartSound Quicktracks 5 (HKLM-x32\...\{2F8BA3FD-1FA9-4279-B696-712ABB12F09F}) (Version: 5.1.7 - SmartSound Software Inc.) Hidden
SmartSound Quicktracks 5 (HKLM-x32\...\InstallShield_{2F8BA3FD-1FA9-4279-B696-712ABB12F09F}) (Version: 5.1.7 - SmartSound Software Inc.)
SmartWi Connection Utility (HKLM-x32\...\{9B5F85CA-90D4-4AFC-BB37-32477FD0D2B9}) (Version: 4.8.4.20090902.2130 - Sony)
SoftEther VPN Client (HKLM\...\softether_sevpnclient) (Version: 4.12.9514 - SoftEther VPN Project)
Song Surgeon 4.0.2.3 (HKLM-x32\...\{03853A8E-10F5-463D-8888-4D69C7C5VD1Z}_is1) (Version: - Todd, Michael & James, Inc.)
Sony Home Network Library (HKLM-x32\...\{9E39EA0D-38CD-4739-9E28-DEA4A1155522}) (Version: 2.0.0.07280 - Sony Corporation) Hidden
Sony Home Network Library (HKLM-x32\...\{D03D02D8-AB64-4785-A48E-5AA8B0FB8C14}) (Version: 2.0.0.07280 - Sony Corporation)
SoundLeech 1.0.3275.20306 (HKLM\...\{B5213A55-2258-4C85-B19E-5E5CA0B36F40}_is1) (Version: - MiLo Software)
SpeedFan (remove only) (HKLM-x32\...\SpeedFan) (Version: - )
SQLite_3_7_8_x64 (HKLM\...\{DD54C205-43D6-4959-B97A-E52DB4A199C7}) (Version: 3.7.8.0 - Sony Corporation) Hidden
StartupMonitor (HKLM-x32\...\{76EFAC4F-1712-401F-B2AE-590B170C9BCE}) (Version: 1.0.2.0 - Mike Lin)
StuffIt 2009 (HKLM-x32\...\{7204C956-B01F-4344-9F10-67485DBE7D15}) (Version: 13.0.0 - Smith Micro)
StuffIt Expander 2011 (HKLM\...\{6B62B973-49F5-4C51-B738-93B56A963417}) (Version: 15.0.7.2518 - Smith Micro Software, Inc.)
Switch Sound File Converter (HKLM-x32\...\Switch) (Version: 4.79 - NCH Software)
Unchecky v1.2 (HKLM-x32\...\Unchecky) (Version: 1.2 - Reason Software Company Inc.)
VAIO - Remote Keyboard (HKLM-x32\...\{7396FB15-9AB4-4B78-BDD8-24A9C15D2C65}) (Version: 1.1.0.07060 - Sony Corporation)
VAIO - Xperia Link (HKLM-x32\...\{D91558BF-D1F3-411F-AEFE-8774CB406512}) (Version: 1.4.0.15030 - Sony Corporation)
VAIO Care (HKLM\...\{6EEC3E9C-3479-42EB-B93C-E7DF7927DD82}) (Version: 8.4.4.09181 - Sony Corporation)
VAIO Care (HKLM-x32\...\{00B03993-F5A1-47B1-9C54-EC8FBDDDE17E}) (Version: 6.4.2.11150 - Sony Corporation) Hidden
VAIO Care Recovery (HKLM\...\{6ED1750E-F44F-4635-8F0D-B76B9262B7FB}) (Version: 1.1.1.13230 - Sony Corporation)
VAIO Control Center (HKLM-x32\...\{72042FA6-5609-489F-A8EA-3C2DD650F667}) (Version: 4.3.0.05310 - Sony Corporation)
VAIO Health Report (HKLM-x32\...\VAIO Health Report1.0) (Version: 1.0 - Sony Electronics)
VAIO Media plus (HKLM-x32\...\{8DE50158-80AA-4FF2-9E9F-0A7C46F71FCD}) (Version: 2.0.0.07280 - Sony Corporation)
VAIO Media plus Opening Movie (HKLM-x32\...\{6BF03C88-C06A-48DC-B9A1-FE72B24E5FA9}) (Version: 2.0.0.07030 - Sony Corporation)
VAIO Platform Update Program (HKLM-x32\...\{69DABBAD-F800-4060-9730-CCA6FFDC2D23}) (Version: 1.1.0.12290 - Sony Corporation)
VAIO Update (HKLM-x32\...\{9FF95DA2-7DA1-4228-93B7-DED7EC02B6B2}) (Version: 7.2.0.16270 - Sony Corporation)
VBCABLE, The Virtual Audio Cable (HKLM\...\VB:VBCABLE {87459874-1236-4469}) (Version: - VB-Audio Software)
VD64Inst (HKLM\...\{DB9C43F7-0B0F-4E43-9E6B-F945C71C469E}) (Version: 1.00.0000 - Roxio, Inc.) Hidden
Vegas Movie Studio HD Platinum 10.0 (HKLM-x32\...\{40AE01BE-A290-4FFB-8DAB-C624C17DC87E}) (Version: 10.0.179 - Sony)
Vegas Pro 10.0 (64-bit) (HKLM\...\{C616FD4F-11F5-11E0-A38F-0013D3D69929}) (Version: 10.0.470 - Sony)
VideoPad Video Editor (HKLM-x32\...\VideoPad) (Version: 3.24 - NCH Software)
Virtual Account Numbers (HKLM-x32\...\{0134662F-5B97-4D60-9A24-B81B6A56DEF7}) (Version: 1.0.6.0 - Citi) Hidden
Virtual Account Numbers (HKLM-x32\...\{DE700910-58F7-4D2E-B7E6-3BA2DA1B6806}) (Version: 4.0.0.2260 - Citi)
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.6 - VideoLAN)
VUx64 (HKLM\...\{A0A2BE14-D3FF-41C8-9545-4B130E3FE9A4}) (Version: 1.2.0 - Sony Corporation) Hidden
VUx86 (HKLM-x32\...\{D04F1D22-4A47-42C6-A2B9-094A7B844D9B}) (Version: 1.2.0 - Sony Corporation) Hidden
Windows Driver Package - Atheros Communications Inc. (athr) Net (02/12/2010 9.0.0.125) (HKLM\...\62D2521666DCF9EBEC983E0344A3DEE15CF2C6D3) (Version: 02/12/2010 9.0.0.125 - Atheros Communications Inc.)
Windows Driver Package - Ricoh Company MS Host Controller (04/27/2010 6.13.03.03) (HKLM\...\329BC6C693EDBAE5D333838328DDCBF99FE39773) (Version: 04/27/2010 6.13.03.03 - Ricoh Company)
Windows Driver Package - Sony Corporation (SFEP) HIDClass (11/27/2009 8.0.1.2) (HKLM\...\4E827A70BAA738C408DBDD024BCACE5085D946F1) (Version: 11/27/2009 8.0.1.2 - Sony Corporation)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation)
WizMouse v1.7.0.3 (HKLM-x32\...\WizMouse_is1) (Version: - Antibody Software)
Xiph.Org Open Codecs 0.85.17777 (HKLM-x32\...\Open Codecs) (Version: 0.85.17777 - Xiph.Org)
XperiaLinkx86 (HKLM-x32\...\{EE402ACB-8269-4E44-9CA1-D81FDC4B4545}) (Version: 1.0.0 - Sony Corporation) Hidden
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
ShellIconOverlayIdentifiers: [ GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2017-11-10] (Google)
ShellIconOverlayIdentifiers: [ GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2017-11-10] (Google)
ShellIconOverlayIdentifiers: [ GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2017-11-10] (Google)
ShellIconOverlayIdentifiers: [0WinSecurityProvider] -> {F76FA5C2-3B6A-451E-8CA5-34C8D0AE0637} => -> No File
ShellIconOverlayIdentifiers: [{4BBAAAE9-0004-4000-9AA5-1BBD98C86E9B}] -> {4BBAAAE9-0004-4000-9AA5-1BBD98C86E9B} => C:\Windows\system32\pfmshx_A1C.dll [2014-07-11] (Pismo Technic Inc.)
ShellIconOverlayIdentifiers-x32: [{4BBAAAE9-0004-4000-9AA5-1BBD98C86E9B}] -> {4BBAAAE9-0004-4000-9AA5-1BBD98C86E9B} => C:\Windows\system32\pfmshx_A1C.dll [2014-07-11] (Pismo Technic Inc.)
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => -> No File
ContextMenuHandlers1-x32: [Adobe.Acrobat.ContextMenu] -> {D25B2CAB-8A9A-4517-A9B2-CB5F68A5A802} => C:\Program Files (x86)\Adobe\Acrobat 7.0\Acrobat Elements\ContextMenu.dll [2004-12-14] (Adobe Systems Inc.)
ContextMenuHandlers1-x32: [AimersoftVideoConverterFileOpreation] -> {1AACB93E-AA97-47F1-BD02-8D2AF2815436} => C:\Windows\SysWOW64\AiCM64.dll [2013-08-23] ()
ContextMenuHandlers1-x32: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => c:\Program Files\Microsoft Security Client\shellext.dll [2015-04-30] (Microsoft Corporation)
ContextMenuHandlers1-x32: [GDContextMenu] -> {BB02B294-8425-42E5-983F-41A1FA970CD6} => C:\Program Files (x86)\Google\Drive\contextmenu64.dll [2017-11-10] (Google)
ContextMenuHandlers1-x32-x32: [StuffItContextMenuHandler] -> {8B2B7A32-7D7B-48AB-838D-70AAC410985F} => C:\Program Files (x86)\Stuffit\SxShellExtEN.dll [2008-12-19] (Smith Micro Software, Inc.)
ContextMenuHandlers1-x32-x32: [UnLockerMenu] -> {410BF280-86EF-4E0F-8279-EC5848546AD3} => C:\Program Files (x86)\IObit\IObit Unlocker\IObitUnlockerExtension.dll [2014-03-04] (IObit)
ContextMenuHandlers1-x32-x32: [{4BBAAAE9-0001-4A1C-9AA5-1BBD98C86E9B}] -> {4BBAAAE9-0001-4A1C-9AA5-1BBD98C86E9B} => C:\Windows\system32\pfmshx_A1C.dll [2014-07-11] (Pismo Technic Inc.)
ContextMenuHandlers2: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => c:\Program Files\Microsoft Security Client\shellext.dll [2015-04-30] (Microsoft Corporation)
ContextMenuHandlers2: [{4BBAAAE9-0002-4A1C-9AA5-1BBD98C86E9B}] -> {4BBAAAE9-0002-4A1C-9AA5-1BBD98C86E9B} => C:\Windows\system32\pfmshx_A1C.dll [2014-07-11] (Pismo Technic Inc.)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-03-27] (Malwarebytes)
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => -> No File
ContextMenuHandlers4: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => c:\Program Files\Microsoft Security Client\shellext.dll [2015-04-30] (Microsoft Corporation)
ContextMenuHandlers4: [FolderColorize] -> {3443FE61-F294-403D-A4A6-53E034FC9B3F} => C:\Program Files\Folder Colorizer\FolderColorShlExt.dll [2014-06-10] ()
ContextMenuHandlers4: [GDContextMenu] -> {BB02B294-8425-42E5-983F-41A1FA970CD6} => C:\Program Files (x86)\Google\Drive\contextmenu64.dll [2017-11-10] (Google)
ContextMenuHandlers4-x32: [StuffItContextMenuHandler] -> {8B2B7A32-7D7B-48AB-838D-70AAC410985F} => C:\Program Files (x86)\Stuffit\SxShellExtEN.dll [2008-12-19] (Smith Micro Software, Inc.)
ContextMenuHandlers4-x32: [UnLockerMenu] -> {410BF280-86EF-4E0F-8279-EC5848546AD3} => C:\Program Files (x86)\IObit\IObit Unlocker\IObitUnlockerExtension.dll [2014-03-04] (IObit)
ContextMenuHandlers5: [DeskMenu] -> {7E74422F-2393-11D4-98E0-444553540000} => C:\Program Files\Desktop Restore\dkticnsr.dll [2014-07-14] (Jamie O'Connell)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\Windows\system32\nvshext.dll [2014-05-19] (NVIDIA Corporation)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-03-27] (Malwarebytes)
ContextMenuHandlers6: [UnLockerMenu] -> {410BF280-86EF-4E0F-8279-EC5848546AD3} => C:\Program Files (x86)\IObit\IObit Unlocker\IObitUnlockerExtension.dll [2014-03-04] (IObit)
ContextMenuHandlers6: [{4BBAAAE9-0002-4A1C-9AA5-1BBD98C86E9B}] -> {4BBAAAE9-0002-4A1C-9AA5-1BBD98C86E9B} => C:\Windows\system32\pfmshx_A1C.dll [2014-07-11] (Pismo Technic Inc.)
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {00F7D842-030F-48FE-8D06-8D1A8EC0DFAC} - System32\Tasks\Sanipplesnipples => C:\Program Files (x86)\coordinator\coordinator.exe
Task: {02F2E36D-CE54-461C-A711-83D7C6A526A2} - System32\Tasks\SONY\SUS-BCF\Level4Daily => C:\Program Files (x86)\Sony\Setting Utility Series\WBCBatteryCare.exe [2010-07-26] (Sony Corporation)
Task: {12909958-B0B1-4E3A-A143-388DAD924286} - System32\Tasks\Sony Corporation\VAIO Care\GetPOTInfo => C:\Program Files\Sony\VAIO Care\VCSystemTray.exe [2015-08-20] (Sony Corporation)
Task: {1389A02B-E9F7-4625-8452-29315733282E} - System32\Tasks\Sony Corporation\VAIO Care\UploadPOT => C:\Program Files\Sony\VAIO Care\VCSystemTray.exe [2015-08-20] (Sony Corporation)
Task: {172C0947-0AB8-4CBB-A502-468E6D8E4112} - System32\Tasks\Sony Corporation\VAIO Care\UpdateSolution => C:\Program Files\Sony\VAIO Care\Solution.Updater.exe [2015-07-23] (Sony Corporation)
Task: {1C0D1E3A-C3E3-4827-8115-7BD8BB778650} - System32\Tasks\Sony Corporation\VAIO Care\ActiveStatusCollect => C:\Program Files\Sony\VAIO Care\VCSystemTray.exe [2015-08-20] (Sony Corporation)
Task: {3111D1B9-B867-4FF2-BCCD-6FA05999E5C2} - System32\Tasks\Sony Corporation\VAIO Care\VAIO Care => C:\Program Files\Sony\VAIO Care\VCsystray.exe [2011-02-16] (Sony Corporation)
Task: {33F3B133-5DE3-4ACF-ADC4-EE8C3FFAB152} - System32\Tasks\Sony Corporation\VAIO Update\VAIO Update => C:\Program Files\Sony\VAIO Update\VAIOUpdt.exe [2016-04-25] (Sony Corporation)
Task: {36CFE37E-9401-4318-90D2-4EC5FAEE387F} - System32\Tasks\Sony Corporation\VAIO Care\DeployCRMflag => C:\Program Files\Sony\VAIO Care\DeployCRMflag.exe [2015-02-04] (Sony Corporation)
Task: {45BADC05-BF63-4EA7-B530-5B196060609F} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-4256033146-2562541644-1532691662-1000Core1d1ab1c50e3feb1 => C:\Users\New User\AppData\Local\Google\Update\GoogleUpdate.exe
Task: {46A8BA8B-1CE2-49F1-88A7-AFEFD8DD1072} - System32\Tasks\GoogleUpdateTaskMachineCore1d1e99a24383211 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {4715A3F3-DA5C-4314-B0E6-AEE7B4002171} - System32\Tasks\Motorola Device Manager Initial Update => C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotorolaDeviceManagerUpdate.exe [2014-10-30] ()
Task: {56E4ED33-FD67-4111-AD2E-69432965D13C} - System32\Tasks\{E14845C5-AD07-455E-8AF1-87FDF860E69C} => C:\Windows\system32\pcalua.exe -a "C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma.cpl" -c Adobe Gamma
Task: {5896892F-6738-4626-9A26-98F4AA20F245} - System32\Tasks\VAIO Health Report => C:\Program Files (x86)\Sony\VAIO Health Report\VAIOHealthReport.exe [2013-06-20] (Sony Electronics)
Task: {5942F092-08C3-41C9-8568-F7010BD67E6B} - System32\Tasks\Sony Corporation\VAIO Update\Launch Application => C:\Program Files\SONY\VAIO Update\ShellExeProxy.exe [2016-03-31] (Sony Corporation)
Task: {5C1FD1BA-43C9-4FFB-B90D-DA7274C2101E} - System32\Tasks\Sony Corporation\VAIO Care\CheckSystemInfo => C:\Program Files\Sony\VAIO Care\VCSystemTray.exe [2015-08-20] (Sony Corporation)
Task: {5CE22FDF-C337-4FF1-9589-1D174EF6BA8E} - \Speedial -> No File <==== ATTENTION
Task: {633FE891-475B-499C-B85E-F3C6BEB45993} - System32\Tasks\USER_ESRV_SVC => "C:\Windows\System32\Wscript.exe" //B //NoLogo "C:\Program Files\Sony\VAIO Care\ESRV\task.vbs"
Task: {79DC2A95-1F93-417E-A28F-B99128B2DE38} - System32\Tasks\Core Temp Autostart Guest => C:\Program Files\Core Temp\Core Temp.exe [2016-06-05] ()
Task: {7A0844AA-1700-4006-B982-8FB6D0AC37EB} - System32\Tasks\Sony Corporation\VAIO Care\VCCheckIolo => C:\Program Files\Sony\VAIO Care\VCSystemTray.exe [2015-08-20] (Sony Corporation)
Task: {7EFD4D10-58C8-43AA-9467-9C5F5DF65A3E} - System32\Tasks\DLNowUpdateTask => C:\Program Files (x86)\DLNow\bin\youtube-dl.exe [2018-04-25] ()
Task: {9255924D-D507-4E08-A7A4-F494A3A78200} - System32\Tasks\{19FA1E7F-C63E-4A46-97A3-3F34BC31D6C0} => C:\Windows\system32\pcalua.exe -a C:\Users\2018Jean\Desktop\dft32_v416_b00.EXE -d C:\Users\2018Jean\Desktop
Task: {96247089-FA26-44E2-A435-C81629491635} - System32\Tasks\Motorola Device Manager Update => C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotorolaDeviceManagerUpdate.exe [2014-10-30] ()
Task: {9B66F097-A61A-4505-97F4-D136CAF3DC42} - System32\Tasks\WizMouse => C:\Program Files (x86)\WizMouse\WizMouseLaunch.exe [2013-09-22] ()
Task: {A9DC085E-8031-42FC-9286-2DC168612277} - System32\Tasks\Sony Corporation\VAIO Care\VCSelfHeal => C:\Program Files\Sony\VAIO Care\VCSystemTray.exe [2015-08-20] (Sony Corporation)
Task: {AF252B0B-E42B-4D00-BCDB-8087257A2F0B} - System32\Tasks\Sony Corporation\VAIO Care\VCOneClick => C:\Program Files\Sony\VAIO Care\VCOneClick.exe [2011-02-16] (Sony Corporation)
Task: {B6A45865-55DB-4260-8D17-9BAD8B97876F} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-06-24] (Piriform Ltd)
Task: {C1F04433-F138-496F-A132-861EA809CBE6} - System32\Tasks\Sony Corporation\VAIO Care\VCMetrics => C:\Program Files\Sony\VAIO Care\VCSystemTray.exe [2015-08-20] (Sony Corporation)
Task: {C4E2C798-680B-487D-B008-7809887D2534} - System32\Tasks\Sony Corporation\VAIO Update\VAIO Update Self Repair => C:\Program Files\Sony\VAIO Update\VUSR.exe [2016-03-31] (Sony Corporation)
Task: {CF664104-E476-4498-8903-5DC6BB8CBFC7} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {CFEFD686-64CA-4CB6-8B24-A9BC74A06F8B} - System32\Tasks\SONY\SUS-BCF\Level4Month => C:\Program Files (x86)\Sony\Setting Utility Series\WBCBatteryCare.exe [2010-07-26] (Sony Corporation)
Task: {D1983ABB-C6BA-45ED-8684-92D2239F2B29} - System32\Tasks\Core Temp Autostart New User => C:\Program Files\Core Temp\Core Temp.exe [2016-06-05] ()
Task: {D1DC2A75-83A9-4B63-A3FD-5000634057BD} - System32\Tasks\{B2B6C2B3-3D98-4570-9059-8CAE5C80B819} => C:\Windows\system32\pcalua.exe -a "C:\Program Files (x86)\QuickTime Alternative\QTSystem\quicktime.cpl"
Task: {E0781AF7-ACCE-4AD7-BE9C-6A9E065CD550} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-4256033146-2562541644-1532691662-1000UA => C:\Users\New User\AppData\Local\Google\Update\GoogleUpdate.exe
Task: {E17FC308-0BBA-4584-B370-6CF6A9D7A881} - System32\Tasks\Sony Corporation\Xperia Link\Xperia Link Logon Start => C:\Program Files (x86)\Sony\Xperia Link\Xperia Link.exe [2016-03-04] (Sony Corporation)
Task: {F38A7085-3FF2-497A-BF8B-A4DF91339F0F} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {F70FE2A2-D569-48A5-BBFA-53AEC4C1DF0A} - System32\Tasks\nipples => C:\Program Files (x86)\coordinator\coordinator.exe
Task: {F8CB3FC4-A45A-4D7D-918D-452AD83D7E94} - System32\Tasks\Sony Corporation\VAIO Care\VCRLog => C:\Program Files\Sony\VAIO Care\VCSystemTray.exe [2015-08-20] (Sony Corporation)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1cfefa3f2c4ad03.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d0001ea16c3dbf.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d04271c398541a.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d09037628ad6c3.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d0bfebbe8ed6e2.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d0e18bf9f2edac.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d0ef4ea319fbef.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d12d0428a12f73.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d15cfba1559c9f.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d1636af991dfb9.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d1ab1afe70b3f7.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4256033146-2562541644-1532691662-1000Core.job => C:\Users\New User\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4256033146-2562541644-1532691662-1000Core1d0efb33f722634.job => C:\Users\New User\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4256033146-2562541644-1532691662-1000Core1d12eecce9d9c72.job => C:\Users\New User\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4256033146-2562541644-1532691662-1000Core1d15dc7972a45f8.job => C:\Users\New User\AppData\Local\Google\Update\GoogleUpdate.exe
==================== Shortcuts & WMI ========================
(The entries could be listed to be restored or removed.)
Shortcut: C:\Users\2018Jean\Favorites\NCH Software Download Site.lnk -> hxxp://www.nchsoftware.com/index.htm
ShortcutWithArgument: C:\Users\2018Jean\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Chrome Remote Desktop.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=gbchcmhmhahfdphkhkmpfmihenigjmpp
ShortcutWithArgument: C:\Users\2018Jean\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\5d696d521de238c3\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default
==================== Loaded Modules (Whitelisted) ==============
2014-05-26 17:01 - 2014-05-19 21:25 - 000116568 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2015-09-16 08:12 - 2015-09-16 08:12 - 000043480 _____ () C:\Program Files (x86)\FileZilla FTP Client\fzshellext_64.dll
2015-04-19 11:56 - 2014-06-10 12:53 - 000137528 _____ () C:\Program Files\Folder Colorizer\FolderColorShlExt.dll
2014-07-19 19:27 - 2013-08-23 13:36 - 000721263 _____ () C:\Windows\SysWOW64\AiCM64.dll
2010-07-14 04:00 - 2010-07-14 04:00 - 000032240 _____ () C:\Program Files (x86)\Roxio\BackOnTrack\App\BService.exe
2015-03-21 04:54 - 2015-03-21 04:54 - 000327680 _____ () C:\Program Files\Serviio\bin\ServiioService.exe
2015-08-26 13:06 - 2015-08-26 13:06 - 000413336 _____ () C:\Program Files\Sony\VAIO Care\ESRV\esrv_svc.exe
2015-08-26 13:06 - 2015-08-26 13:06 - 000709272 _____ () C:\Program Files\Sony\VAIO Care\ESRV\intel_modeler.dll
2015-08-26 13:06 - 2015-08-26 13:06 - 000130712 _____ () C:\Program Files\Sony\VAIO Care\ESRV\intel_process_input.dll
2015-08-26 13:06 - 2015-08-26 13:06 - 000025752 _____ () C:\Program Files\Sony\VAIO Care\ESRV\intel_system_power_state_input.dll
2015-08-26 13:06 - 2015-08-26 13:06 - 000059544 _____ () C:\Program Files\Sony\VAIO Care\ESRV\intel_quality_and_reliability_input.dll
2015-08-26 13:06 - 2015-08-26 13:06 - 000194712 _____ () C:\Program Files\Sony\VAIO Care\ESRV\acpi_battery_input.dll
2015-08-26 13:06 - 2015-08-26 13:06 - 000159896 _____ () C:\Program Files\Sony\VAIO Care\ESRV\sema_thermal_input.dll
2015-08-26 13:06 - 2015-08-26 13:06 - 000158360 _____ () C:\Program Files\Sony\VAIO Care\ESRV\wifi_input.dll
2015-08-26 13:06 - 2015-08-26 13:06 - 000050840 _____ () C:\Program Files\Sony\VAIO Care\ESRV\devices_use_input.dll
2015-08-26 13:06 - 2015-08-26 13:06 - 000032920 _____ () C:\Program Files\Sony\VAIO Care\ESRV\intel_disktrace_input.dll
2010-07-13 21:23 - 2010-07-13 21:23 - 000084464 _____ () C:\Program Files (x86)\Roxio 2011\5.0\CPMonitor.exe
2014-05-21 18:34 - 2009-08-26 17:11 - 000017408 _____ () C:\Program Files (x86)\Sony\SmartWi Connection Utility\CCP.exe
2018-03-22 15:00 - 2018-03-22 15:00 - 003406336 _____ () C:\Users\2018Jean\AppData\Local\wmcagent\wmcagent.exe
2014-05-21 18:34 - 2009-08-26 17:11 - 000017920 _____ () C:\Program Files (x86)\Sony\SmartWi Connection Utility\ThirdPartyAppMgr.exe
2014-05-21 18:34 - 2009-08-26 17:11 - 000033792 _____ () C:\Program Files (x86)\Sony\SmartWi Connection Utility\PowerManager.exe
2018-04-25 15:15 - 2018-04-17 01:01 - 004443992 _____ () C:\Program Files (x86)\Google\Chrome\Application\66.0.3359.117\libglesv2.dll
2018-04-25 15:15 - 2018-04-17 01:01 - 000099672 _____ () C:\Program Files (x86)\Google\Chrome\Application\66.0.3359.117\libegl.dll
2010-07-14 04:00 - 2010-07-14 04:00 - 001587696 _____ () C:\Program Files (x86)\Roxio\BackOnTrack\App\BEngine.dll
2010-07-14 04:00 - 2010-07-14 04:00 - 000107504 _____ () C:\Program Files (x86)\Roxio\BackOnTrack\App\Logging.dll
2015-09-22 12:48 - 2012-11-06 09:47 - 000114688 _____ () C:\Program Files (x86)\Realtek\USB Wireless LAN Utility\EnumDevLib.dll
2014-06-25 20:33 - 2010-05-31 19:18 - 000013824 _____ () C:\Program Files (x86)\Sony\VAIO Event Service\VESBasePS.dll
2014-06-25 20:33 - 2010-05-31 19:18 - 000013312 _____ () C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSubPS.dll
2013-07-20 15:13 - 2013-07-20 15:13 - 000165480 _____ () C:\Windows\SysWOW64\AirfoilInject3.dll
2014-05-21 18:34 - 2009-08-26 17:11 - 000120320 _____ () C:\Program Files (x86)\Sony\SmartWi Connection Utility\SonyCommonLib.dll
2014-05-21 18:34 - 2009-08-26 17:11 - 000007680 _____ () C:\Program Files (x86)\Sony\SmartWi Connection Utility\DebugMsg.dll
2014-05-21 18:34 - 2009-08-26 17:11 - 000009728 _____ () C:\Program Files (x86)\Sony\SmartWi Connection Utility\Resources.dll
2014-05-21 18:34 - 2009-08-26 17:11 - 000015360 _____ () C:\Program Files (x86)\Sony\SmartWi Connection Utility\SharedInterfaces.dll
2014-05-21 18:34 - 2009-08-26 17:11 - 000018944 _____ () C:\Program Files (x86)\Sony\SmartWi Connection Utility\DictionaryLookup.dll
2014-05-21 18:34 - 2009-08-26 17:11 - 000011264 _____ () C:\Program Files (x86)\Sony\SmartWi Connection Utility\MessageXML.dll
2016-03-05 14:42 - 2016-03-05 14:42 - 047517184 _____ () C:\Users\2018Jean\AppData\Local\wmcagent\libcef.dll
2016-08-23 14:19 - 2016-08-23 14:19 - 001414144 _____ () C:\Users\2018Jean\AppData\Local\wmcagent\CrackCaptchaAPI.dll
2016-08-23 14:19 - 2016-08-23 14:19 - 000419328 _____ () C:\Users\2018Jean\AppData\Local\wmcagent\lua5.dll
2016-08-23 14:19 - 2016-08-23 14:19 - 000124928 _____ () C:\Users\2018Jean\AppData\Local\wmcagent\cjson.dll
2016-08-22 12:41 - 2016-08-22 12:41 - 000101888 _____ () C:\Users\2018Jean\AppData\Local\wmcagent\lcurl.dll
2014-05-21 18:34 - 2009-08-26 17:11 - 000081408 _____ () C:\Program Files (x86)\Sony\SmartWi Connection Utility\DevicePanel.dll
2014-05-21 18:34 - 2009-08-26 17:11 - 000005120 _____ () C:\Program Files (x86)\Sony\SmartWi Connection Utility\Kinoubi.Plugins.PluginManager.ThirdPartyApp.dll
2014-05-21 18:34 - 2009-08-26 17:11 - 000023040 _____ () C:\Program Files (x86)\Sony\SmartWi Connection Utility\Kinoubi.Plugins.PluginManager.Generic.dll
2014-05-21 18:34 - 2009-08-26 17:11 - 000027648 _____ () C:\Program Files (x86)\Sony\SmartWi Connection Utility\Kinoubi.Plugins.Plugin.BtPower.dll
2014-05-21 18:34 - 2009-08-26 17:11 - 000005120 _____ () C:\Program Files (x86)\Sony\SmartWi Connection Utility\Kinoubi.Plugins.Plugin.Generic.dll
2014-05-21 18:34 - 2009-08-26 17:11 - 000015360 _____ () C:\Program Files (x86)\Sony\SmartWi Connection Utility\Kinoubi.Plugins.Plugin.NativeWifiThirdPartyApp.dll
2014-05-21 18:34 - 2009-08-26 17:11 - 000011264 _____ () C:\Program Files (x86)\Sony\SmartWi Connection Utility\Kinoubi.Plugins.Plugin.TosBtThirdPartyApp.dll
2014-05-21 18:34 - 2009-08-26 17:11 - 000007168 _____ () C:\Program Files (x86)\Sony\SmartWi Connection Utility\Kinoubi.Plugins.Plugin.WlanPower.dll
2014-05-21 18:34 - 2009-08-26 17:11 - 000004608 _____ () C:\Program Files (x86)\Sony\SmartWi Connection Utility\Kinoubi.Plugins.PluginManager.Power.dll
2016-03-05 14:42 - 2016-03-05 14:42 - 001576960 _____ () C:\Users\2018Jean\AppData\Local\wmcagent\libglesv2.dll
2016-03-05 14:42 - 2016-03-05 14:42 - 000074752 _____ () C:\Users\2018Jean\AppData\Local\wmcagent\libegl.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
AlternateDataStreams: C:\Windows:nlsPreferences [0]
==================== Safe Mode (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\plsapp => ""="service"
==================== Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2014-09-19 15:54 - 2018-04-25 17:25 - 000002047 _____ C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 localhost
0.0.0.0 0.0.0.0 # fix for traceroute and netstat display anomaly
0.0.0.0 tracking.opencandy.com.s3.amazonaws.com
0.0.0.0 media.opencandy.com
0.0.0.0 cdn.opencandy.com
0.0.0.0 tracking.opencandy.com
0.0.0.0 api.opencandy.com
0.0.0.0 api.recommendedsw.com
0.0.0.0 rp.yefeneri2.com
0.0.0.0 os.yefeneri2.com
0.0.0.0 os2.yefeneri2.com
0.0.0.0 installer.betterinstaller.com
0.0.0.0 installer.filebulldog.com
0.0.0.0 d3oxtn1x3b8d7i.cloudfront.net
0.0.0.0 inno.bisrv.com
0.0.0.0 nsis.bisrv.com
0.0.0.0 cdn.file2desktop.com
0.0.0.0 cdn.goateastcach.us
0.0.0.0 cdn.guttastatdk.us
0.0.0.0 cdn.inskinmedia.com
0.0.0.0 cdn.insta.oibundles2.com
0.0.0.0 cdn.insta.playbryte.com
0.0.0.0 cdn.llogetfastcach.us
0.0.0.0 cdn.montiera.com
0.0.0.0 cdn.msdwnld.com
0.0.0.0 cdn.mypcbackup.com
0.0.0.0 cdn.ppdownload.com
0.0.0.0 cdn.riceateastcach.us
0.0.0.0 cdn.shyapotato.us
0.0.0.0 cdn.solimba.com
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-4256033146-2562541644-1532691662-1006\Control Panel\Desktop\\Wallpaper -> DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 1) (EnableLUA: 1)
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Acrobat Speed Launcher.lnk => C:\Windows\pss\Adobe Acrobat Speed Launcher.lnk.CommonStartup
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^SoftEther VPN Client Manager Startup.lnk => C:\Windows\pss\SoftEther VPN Client Manager Startup.lnk.CommonStartup
MSCONFIG\startupreg: Acrobat Assistant 7.0 => "C:\Program Files (x86)\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
MSCONFIG\startupreg: Acronis Scheduler2 Service => "C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe"
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: AdobeAAMUpdater-1.0 => "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
MSCONFIG\startupreg: AdobeCS6ServiceManager => "C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin
MSCONFIG\startupreg: Aimersoft Helper Compact.exe => C:\Program Files (x86)\Common Files\Aimersoft\Aimersoft Helper Compact\ASHelper.exe
MSCONFIG\startupreg: Desktop Disc Tool => "C:\Program Files (x86)\Roxio 2011\Roxio Burn\RoxioBurnLauncher.exe"
MSCONFIG\startupreg: LightScribe Control Panel => C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
MSCONFIG\startupreg: SoftEther VPN Client UI Helper => "C:\Program Files\SoftEther VPN Client\vpnclient_x64.exe" /uihelp
MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
MSCONFIG\startupreg: Virtual Account Numbers => C:\Users\NEWUSE~1\Desktop\CITIVI~1\CitiVAN.exe /lang=en_RG /dontopenmycards
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [{2CF04BE8-6CB7-426E-87E3-443822B9A514}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{C296184F-C227-4713-B174-243ABDA04E6C}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{C5C518B4-86AF-4027-987D-669619A5A3BF}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
FirewallRules: [{2D5B7835-F8DD-4027-8C30-FA0E38A820A5}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
FirewallRules: [{E0A2AA88-06EA-4DC1-985C-BEA2B91B0965}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{76D20174-CA61-42BF-957C-3182D16A2267}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [TCP Query User{E5396464-C096-44DD-9C9C-C9E70DD24C67}C:\program files\ftpwanderer.exe] => (Allow) C:\program files\ftpwanderer.exe
FirewallRules: [UDP Query User{2A565AA3-9DBC-49CA-BEA8-990BD55777CD}C:\program files\ftpwanderer.exe] => (Allow) C:\program files\ftpwanderer.exe
FirewallRules: [TCP Query User{EB90B550-47E4-40BE-99DB-56F72A70635F}C:\program files (x86)\airfoil\airfoil.exe] => (Allow) C:\program files (x86)\airfoil\airfoil.exe
FirewallRules: [UDP Query User{5BBCC7AF-5563-44DE-BAF5-04FAFC24751E}C:\program files (x86)\airfoil\airfoil.exe] => (Allow) C:\program files (x86)\airfoil\airfoil.exe
FirewallRules: [{4592994F-1A98-4637-B054-66DF68050396}] => (Block) C:\program files (x86)\airfoil\airfoil.exe
FirewallRules: [{CBE3AA6C-3F2B-49E9-81CD-37300559E7C2}] => (Block) C:\program files (x86)\airfoil\airfoil.exe
FirewallRules: [TCP Query User{395E59A3-FE0C-49FF-B30B-A65C5CD2445E}C:\program files (x86)\airfoil\airfoilspeakers.exe] => (Allow) C:\program files (x86)\airfoil\airfoilspeakers.exe
FirewallRules: [UDP Query User{7754B78D-9D14-4E9F-9142-AE33E8E5FF18}C:\program files (x86)\airfoil\airfoilspeakers.exe] => (Allow) C:\program files (x86)\airfoil\airfoilspeakers.exe
FirewallRules: [{88485275-5EA1-459F-84B5-89C2E34230D9}] => (Block) C:\program files (x86)\airfoil\airfoilspeakers.exe
FirewallRules: [{D84C9003-E681-47F2-A258-9DBC93386DE3}] => (Block) C:\program files (x86)\airfoil\airfoilspeakers.exe
FirewallRules: [{E396AD23-C425-441E-9010-CF148DB3C78C}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{6409AF99-EFD5-4489-9F55-FF78F5857EB4}] => (Allow) LPort=2869
FirewallRules: [{CA56823E-F76E-4F0C-8B76-61B4A2B97020}] => (Allow) LPort=1900
FirewallRules: [TCP Query User{7607D4FC-971D-49FD-A14B-D746D9BB5894}C:\program files (x86)\videolan\vlc\vlc.exe] => (Allow) C:\program files (x86)\videolan\vlc\vlc.exe
FirewallRules: [UDP Query User{DB641E5D-EEBC-4F32-AE79-2812B5BD92D3}C:\program files (x86)\videolan\vlc\vlc.exe] => (Allow) C:\program files (x86)\videolan\vlc\vlc.exe
FirewallRules: [{42DDB0D2-48BA-4088-8BC7-60821D32647F}] => (Allow) C:\Program Files\SoftEther VPN Client\vpncmd.exe
FirewallRules: [{930758F4-F0FA-404C-8254-4CA698743038}] => (Allow) C:\Program Files\SoftEther VPN Client\vpncmgr.exe
FirewallRules: [{EB9525D5-145F-425D-9DE4-7610E925F082}] => (Allow) C:\Program Files\SoftEther VPN Client\vpncmgr_x64.exe
FirewallRules: [{EDA9D5AB-6059-4F57-9BA7-13CFFD8EA9E3}] => (Allow) C:\Program Files\SoftEther VPN Client\vpnclient.exe
FirewallRules: [{2FC8BAB5-49F6-4954-A990-BF928D55F6D9}] => (Allow) C:\Program Files\SoftEther VPN Client\vpnclient_x64.exe
FirewallRules: [{F5C61075-AFB7-4922-9A30-34D045D98F48}] => (Allow) C:\Program Files\SoftEther VPN Client\vpncmd_x64.exe
FirewallRules: [{063EB077-C6E2-4B8B-A140-96E5E5DF9735}] => (Allow) C:\Windows\explorer.exe
FirewallRules: [{0E8CA58E-D591-41C5-B047-EED091B8D663}] => (Allow) C:\Windows\system32\rundll32.exe
FirewallRules: [TCP Query User{1BA97C60-8921-4FCB-95BB-36E4DDAF8FD2}C:\program files (x86)\netgear genie\bin\netgeargenie.exe] => (Allow) C:\program files (x86)\netgear genie\bin\netgeargenie.exe
FirewallRules: [UDP Query User{57D3F1BB-95FF-4D51-A8C6-EC5E99FE608E}C:\program files (x86)\netgear genie\bin\netgeargenie.exe] => (Allow) C:\program files (x86)\netgear genie\bin\netgeargenie.exe
FirewallRules: [{B7A616F4-11E4-4395-892E-CE63AD5D5B17}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{2453CD04-EF1E-4985-9F1A-F379B751D9B9}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{5F45E1E2-E0DE-4373-806B-880AD30688B2}] => (Allow) C:\Program Files (x86)\Realtek\USB Wireless LAN Utility\RtWLan.exe
FirewallRules: [{EB667CDB-CBE6-49BA-92BB-4CE900836A8E}] => (Allow) C:\Program Files (x86)\Realtek\USB Wireless LAN Utility\RtWLan.exe
FirewallRules: [{2544F6BE-597E-445D-9EC3-48102EB0304F}] => (Allow) LPort=1542
FirewallRules: [{E6E19DDA-3C9D-4317-9796-9E057E76DCC1}] => (Allow) LPort=1542
FirewallRules: [{748CD8B3-0360-4523-B7EF-87ED0A50323F}] => (Allow) LPort=53
FirewallRules: [{5F20B306-74DF-4363-94CF-B3E937B01E8D}] => (Allow) C:\Program Files (x86)\MediatekWiFi\Common\RaMediaServer.exe
FirewallRules: [{34393942-319F-4450-B74D-6A3D5854B9DA}] => (Allow) C:\Program Files (x86)\MediatekWiFi\Common\RaMediaServer.exe
FirewallRules: [{BA1B9B4B-E7C0-462A-A835-7558CEE2DAF2}] => (Allow) C:\Program Files (x86)\MediatekWiFi\Common\RaUI.exe
FirewallRules: [{2DB9CEAE-0E43-4EDB-9D88-97C086FF95B7}] => (Allow) LPort=67
FirewallRules: [{F18D36AD-580F-4E37-B727-7091DAA9B7F0}] => (Allow) LPort=68
FirewallRules: [{CC22FF8C-3558-4419-8161-E129054A10C2}] => (Allow) LPort=53
FirewallRules: [{4CBB465C-F887-4950-BFA1-9358262CC2F3}] => (Allow) LPort=53
FirewallRules: [{34C53CB0-FE9A-4DB6-B15F-A51E97C935B6}] => (Allow) C:\Program Files (x86)\Realtek\USB Wireless LAN Utility\Rtldhcp.exe
FirewallRules: [TCP Query User{CD93C2D2-E82D-4969-91B7-A6F303BE3235}C:\program files (x86)\callcentric\callcentric softphone\callcentric.exe] => (Allow) C:\program files (x86)\callcentric\callcentric softphone\callcentric.exe
FirewallRules: [UDP Query User{1F7EB81A-09E3-40CC-BE0F-8B6075A29B71}C:\program files (x86)\callcentric\callcentric softphone\callcentric.exe] => (Allow) C:\program files (x86)\callcentric\callcentric softphone\callcentric.exe
FirewallRules: [TCP Query User{CD029BCC-19A7-4340-B504-F18A27E184BE}C:\program files (x86)\filezilla ftp client\filezilla.exe] => (Allow) C:\program files (x86)\filezilla ftp client\filezilla.exe
FirewallRules: [UDP Query User{3DE96037-7FAD-47BB-A1B0-C59A83A0B0B5}C:\program files (x86)\filezilla ftp client\filezilla.exe] => (Allow) C:\program files (x86)\filezilla ftp client\filezilla.exe
FirewallRules: [{7B242E38-2D4F-438F-9DF9-ABA2BE340438}] => (Allow) C:\Program Files\Sony\VAIO Care\VCAgent.exe
FirewallRules: [{4DA46A1F-86C4-44BF-965B-83BD1EF1655C}] => (Allow) C:\Program Files\Sony\VAIO Care\VCAdmin.exe
FirewallRules: [{6052E95E-48ED-443C-B45E-B2F103E23ADB}] => (Allow) C:\Program Files\Sony\VAIO Care\VCSystemTray.exe
FirewallRules: [{6C8DB5CB-4FE9-4034-A8CC-74EAC8D533DA}] => (Allow) C:\Program Files\Sony\VAIO Care\VAIOShell.exe
FirewallRules: [{6FE38D40-D843-442E-8193-CF49F871B811}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{9F1A3DBB-D8D9-48A6-A4DB-F6E4D6C7EA8A}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{29204BD5-66AA-46FF-9E2B-62845C0E39B7}C:\program files\serviio\jre\bin\javaw.exe] => (Allow) C:\program files\serviio\jre\bin\javaw.exe
FirewallRules: [UDP Query User{CD709486-5A60-4707-B99B-D26172468A31}C:\program files\serviio\jre\bin\javaw.exe] => (Allow) C:\program files\serviio\jre\bin\javaw.exe
FirewallRules: [{D6089E07-8A0C-41AB-A4C9-269F3141228C}] => (Allow) C:\Program Files\Serviio\bin\ServiioService.exe
FirewallRules: [{DE333EF5-0110-46DA-A946-C3DB012799C8}] => (Allow) C:\Program Files\Serviio\bin\ServiioService.exe
FirewallRules: [{48B2AD10-3253-4D52-B0EE-A7D4A45F00EF}] => (Allow) C:\Program Files\Serviio\bin\ServiioConsole.exe
FirewallRules: [{ABD9CC4F-7124-4A2F-A409-F2BA2B646471}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{A705390D-6100-4309-ACFD-2BB825970F02}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{1992C8FE-AB9D-408D-B2C0-5CB151151523}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{2A3D0737-6132-4ECC-803F-BE512344CC55}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{6EC71A4A-289A-46B8-BA63-52B691DDD9B5}] => (Allow) C:\Program Files (x86)\Song Surgeon 4\SongSurgeon4.exe
FirewallRules: [{0E4789F4-9F90-4ABB-9FBC-E8B0BF1FE640}] => (Allow) C:\Program Files (x86)\Song Surgeon 4\SongSurgeon4reg.exe
FirewallRules: [{EAA1B54E-3D4F-4D16-9FC0-2953FA06D4A2}] => (Allow) C:\Program Files (x86)\Song Surgeon 4\MusicPad.exe
FirewallRules: [{6686CD8F-E5B1-44DD-B405-8869DA7DF07C}] => (Allow) C:\Program Files (x86)\Song Surgeon 4\BatchFileConverter.exe
FirewallRules: [{DC8A0E7B-E613-419B-A8A0-859C3A23A3CA}] => (Allow) C:\Program Files (x86)\Song Surgeon 4\SongSurgeon4.exe
FirewallRules: [{FC2AA9AA-CE8F-4F35-8308-455DDBFF0830}] => (Allow) C:\Program Files (x86)\Song Surgeon 4\SongSurgeon4reg.exe
FirewallRules: [{5800D832-8925-44D7-8D65-1DB635D72582}] => (Allow) C:\Program Files (x86)\Song Surgeon 4\MusicPad.exe
FirewallRules: [{5A0930F7-1DFE-4652-ADAD-9F34948B71C6}] => (Allow) C:\Program Files (x86)\Song Surgeon 4\BatchFileConverter.exe
FirewallRules: [{D6924CD1-DF03-4B19-AE6E-16A158F838C8}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdater.exe
FirewallRules: [{FED7BEC2-D498-452A-98FD-A5B7AF585508}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
FirewallRules: [{F20F9F2C-408D-48C1-83E7-447F20263304}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
FirewallRules: [{91A82756-D605-4CD4-960D-3B9C27D731BA}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
FirewallRules: [{2EFAC593-95AF-4FC9-9E75-75A39A653A0F}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
FirewallRules: [{F4D66D4B-D0FF-4824-B85C-E0A020ACD526}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
FirewallRules: [TCP Query User{D6BE3D14-AC0D-43D9-AD0F-DD4AF113E43C}C:\program files (x86)\netgear genie\bin\netgeargenie.exe] => (Allow) C:\program files (x86)\netgear genie\bin\netgeargenie.exe
FirewallRules: [UDP Query User{D93C0AA3-2221-4781-B763-E66056BA84F3}C:\program files (x86)\netgear genie\bin\netgeargenie.exe] => (Allow) C:\program files (x86)\netgear genie\bin\netgeargenie.exe
FirewallRules: [TCP Query User{4553BA8C-7A9A-4212-ACF7-9ED1491E883D}C:\program files (x86)\kodi\kodi.exe] => (Allow) C:\program files (x86)\kodi\kodi.exe
FirewallRules: [UDP Query User{E93C4BD1-249F-4E15-8DD6-A5D531F7FC1D}C:\program files (x86)\kodi\kodi.exe] => (Allow) C:\program files (x86)\kodi\kodi.exe
FirewallRules: [{DCAF63CE-91A7-431E-B07A-103C63097553}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{0C27EC27-5C06-4517-B565-D273A3E54232}] => (Allow) C:\Program Files (x86)\Chalice\Slighting.exe
FirewallRules: [{AA8902D0-920F-457C-88F9-511E9EB562C3}] => (Allow) C:\Program Files (x86)\Eduard\Slighting.exe
FirewallRules: [{6CD507BF-7CFA-4BD9-B5D3-201CC3F9FDBA}] => (Allow) C:\Program Files (x86)\fighter\undermining.exe
FirewallRules: [{CEE8DED6-E113-4B37-AA7C-008C57328790}] => (Allow) C:\Program Files (x86)\Eduard\undermining.exe
==================== Restore Points =========================
==================== Faulty Device Manager Devices =============
Name: Teredo Tunneling Pseudo-Interface
Description: Microsoft Teredo Tunneling Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
==================== Event log errors: =========================
Application errors:
==================
Error: (04/26/2018 10:18:02 AM) (Source: Acronis Scheduler) (EventID: 1) (User: )
Description: Scheduler is unable to run task with GUID 'E8EB23E7-2D44-49CD-BDBA-301B0BD1C9E3' because of error 2 (Failed to find the file (folder) or the key (value) in the registry.).
Error: (04/26/2018 10:18:02 AM) (Source: Acronis Scheduler) (EventID: 1) (User: )
Description: Scheduler is unable to run task with GUID 'C73DF26C-DA36-4B34-A03E-033834498780' because of error 2 (Failed to find the file (folder) or the key (value) in the registry.).
Error: (04/26/2018 10:17:01 AM) (Source: Acronis Scheduler) (EventID: 1) (User: )
Description: Scheduler is unable to run task with GUID 'C73DF26C-DA36-4B34-A03E-033834498780' because of error 2 (Failed to find the file (folder) or the key (value) in the registry.).
Error: (04/26/2018 10:16:02 AM) (Source: Acronis Scheduler) (EventID: 1) (User: )
Description: Scheduler is unable to run task with GUID 'E8EB23E7-2D44-49CD-BDBA-301B0BD1C9E3' because of error 2 (Failed to find the file (folder) or the key (value) in the registry.).
Error: (04/26/2018 10:16:01 AM) (Source: Acronis Scheduler) (EventID: 1) (User: )
Description: Scheduler is unable to run task with GUID 'C73DF26C-DA36-4B34-A03E-033834498780' because of error 2 (Failed to find the file (folder) or the key (value) in the registry.).
Error: (04/26/2018 10:15:01 AM) (Source: Acronis Scheduler) (EventID: 1) (User: )
Description: Scheduler is unable to run task with GUID 'C73DF26C-DA36-4B34-A03E-033834498780' because of error 2 (Failed to find the file (folder) or the key (value) in the registry.).
Error: (04/26/2018 10:14:02 AM) (Source: Acronis Scheduler) (EventID: 1) (User: )
Description: Scheduler is unable to run task with GUID 'E8EB23E7-2D44-49CD-BDBA-301B0BD1C9E3' because of error 2 (Failed to find the file (folder) or the key (value) in the registry.).
Error: (04/26/2018 10:14:01 AM) (Source: Acronis Scheduler) (EventID: 1) (User: )
Description: Scheduler is unable to run task with GUID 'C73DF26C-DA36-4B34-A03E-033834498780' because of error 2 (Failed to find the file (folder) or the key (value) in the registry.).
System errors:
Error: (04/26/2018 09:46:38 AM) (Source: volsnap) (EventID: 14) (User: )
Description: The shadow copies of volume C: were aborted because of an IO failure on volume C:.
Error: (04/26/2018 09:46:38 AM) (Source: Disk) (EventID: 11) (User: )
Description: The driver detected a controller error on \Device\Harddisk0\DR0.
Error: (04/26/2018 09:46:38 AM) (Source: Disk) (EventID: 11) (User: )
Description: The driver detected a controller error on \Device\Harddisk0\DR0.
Error: (04/26/2018 09:46:38 AM) (Source: Disk) (EventID: 11) (User: )
Description: The driver detected a controller error on \Device\Harddisk0\DR0.
Error: (04/26/2018 09:46:38 AM) (Source: Disk) (EventID: 11) (User: )
Description: The driver detected a controller error on \Device\Harddisk0\DR0.
Error: (04/26/2018 09:46:38 AM) (Source: Disk) (EventID: 11) (User: )
Description: The driver detected a controller error on \Device\Harddisk0\DR0.
Error: (04/26/2018 09:46:38 AM) (Source: Disk) (EventID: 11) (User: )
Description: The driver detected a controller error on \Device\Harddisk0\DR0.
Error: (04/26/2018 09:46:38 AM) (Source: Disk) (EventID: 11) (User: )
Description: The driver detected a controller error on \Device\Harddisk0\DR0.
CodeIntegrity:
===================================
Date: 2016-08-14 16:57:47.868
Description:
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\SoftwareDistribution\Download\c4154e707216b0f9ca48a8462c2fdd9e\inst\amd64_microsoft-windows-appid_31bf3856ad364e35_6.1.7601.23455_none_b5d141c3e2043820\appid.sys because the set of per-page image hashes could not be found on the system.
Date: 2016-08-14 16:57:47.572
Description:
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\SoftwareDistribution\Download\c4154e707216b0f9ca48a8462c2fdd9e\inst\amd64_microsoft-windows-appid_31bf3856ad364e35_6.1.7601.23455_none_b5d141c3e2043820\appid.sys because the set of per-page image hashes could not be found on the system.
Date: 2016-08-14 16:57:47.351
Description:
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\SoftwareDistribution\Download\c4154e707216b0f9ca48a8462c2fdd9e\inst\amd64_microsoft-windows-appid_31bf3856ad364e35_6.1.7601.23455_none_b5d141c3e2043820\appid.sys because the set of per-page image hashes could not be found on the system.
Date: 2016-08-14 16:57:47.113
Description:
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\SoftwareDistribution\Download\c4154e707216b0f9ca48a8462c2fdd9e\inst\amd64_microsoft-windows-appid_31bf3856ad364e35_6.1.7601.23455_none_b5d141c3e2043820\appid.sys because the set of per-page image hashes could not be found on the system.
Date: 2016-08-14 16:57:45.980
Description:
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\SoftwareDistribution\Download\c4154e707216b0f9ca48a8462c2fdd9e\inst\amd64_microsoft-windows-appid_31bf3856ad364e35_6.1.7601.23455_none_b5d141c3e2043820\appidapi.dll because the set of per-page image hashes could not be found on the system.
Date: 2016-08-14 16:57:45.771
Description:
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\SoftwareDistribution\Download\c4154e707216b0f9ca48a8462c2fdd9e\inst\amd64_microsoft-windows-appid_31bf3856ad364e35_6.1.7601.23455_none_b5d141c3e2043820\appidapi.dll because the set of per-page image hashes could not be found on the system.
Date: 2016-08-14 16:57:45.469
Description:
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\SoftwareDistribution\Download\c4154e707216b0f9ca48a8462c2fdd9e\inst\amd64_microsoft-windows-appid_31bf3856ad364e35_6.1.7601.23455_none_b5d141c3e2043820\appidapi.dll because the set of per-page image hashes could not be found on the system.
Date: 2016-08-14 16:57:45.215
Description:
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\SoftwareDistribution\Download\c4154e707216b0f9ca48a8462c2fdd9e\inst\amd64_microsoft-windows-appid_31bf3856ad364e35_6.1.7601.23455_none_b5d141c3e2043820\appidapi.dll because the set of per-page image hashes could not be found on the system.
==================== Memory info ===========================
Processor: Intel(R) Core(TM) i7 CPU Q 740 @ 1.73GHz
Percentage of memory in use: 45%
Total physical RAM: 8172.93 MB
Available physical RAM: 4453.06 MB
Total Virtual: 16344.03 MB
Available Virtual: 12364.25 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:465.66 GB) (Free:279.98 GB) NTFS
\\?\Volume{e0097a0f-d8c1-11e3-91fa-806e6f6e6963}\ () (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 465.8 GB) (Disk ID: 3AF72EB9)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=465.7 GB) - (Type=07 NTFS)
==================== End of Addition.txt ============================
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 25.04.2018
Ran by 2018Jean (administrator) on VAIOVPCF13UJEAN (26-04-2018 10:05:45)
Running from C:\Users\2018Jean\Desktop\Cooties\FRST scans
Loaded Profiles: 2018Jean (Available Profiles: 2018Jean & Administrator)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: FRST Tutorial - How to use Farbar Recovery Scan Tool - Malware Removal Guides and Tutorials
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(TOSHIBA CORPORATION) C:\Windows\System32\sbalwomsvc.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Acronis) C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
() C:\Program Files (x86)\Roxio\BackOnTrack\App\BService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Mediatek Inc.) C:\Program Files (x86)\MediatekWiFi\Common\RaRegistry.exe
(Mediatek Inc.) C:\Program Files (x86)\MediatekWiFi\Common\RaRegistry64.exe
(Nalpeiron Ltd.) C:\Windows\SysWOW64\nlssrv32.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Realtek Semiconductor Corp.) C:\Program Files (x86)\Realtek\USB Wireless LAN Utility\RtlService.exe
(Realtek Semiconductor Corp.) C:\Program Files (x86)\Realtek\USB Wireless LAN Utility\RtWLan.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Update\VAIOUpdt.exe
() C:\Users\2018Jean\AppData\Local\tibevus\tibevus.exe
() C:\Program Files\Serviio\bin\ServiioService.exe
() C:\Program Files\Serviio\bin\ServiioService.exe
(SoftEther VPN Project at University of Tsukuba, Japan.) C:\Program Files\SoftEther VPN Client\vpnclient_x64.exe
(Smith Micro Software, Inc.) C:\Program Files (x86)\Stuffit\ArcNameService.exe
(Reason Software Company Inc.) C:\Program Files (x86)\Unchecky\bin\unchecky_svc.exe
(Sony Corporation) C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe
(Reason Software Company Inc.) C:\Program Files (x86)\Unchecky\bin\unchecky_bg.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation) C:\Windows\SysWOW64\dllhost.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Sony Corporation) C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSub.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Update\VUAgent.exe
() C:\Program Files\Sony\VAIO Care\ESRV\esrv_svc.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint\Apoint.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint\ApMsgFwd.exe
(Sony Corporation) C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe
() C:\Program Files (x86)\Roxio 2011\5.0\CPMonitor.exe
(Adobe Systems Inc.) C:\Program Files (x86)\Adobe\Acrobat 7.0\Distillr\acrotray.exe
(ALPS) C:\Program Files\Apoint\Apvfb.exe
() C:\Program Files (x86)\Sony\SmartWi Connection Utility\CCP.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint\ApntEx.exe
() C:\Users\2018Jean\AppData\Local\wmcagent\wmcagent.exe
(Sony Corporation) C:\Program Files (x86)\Sony\SmartWi Connection Utility\SmartWi.exe
() C:\Program Files (x86)\Sony\SmartWi Connection Utility\ThirdPartyAppMgr.exe
() C:\Program Files (x86)\Sony\SmartWi Connection Utility\PowerManager.exe
() C:\Users\2018Jean\AppData\Local\wmcagent\wmcagent.exe
() C:\Users\2018Jean\AppData\Local\wmcagent\wmcagent.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Care\VCPerfService.exe
(Sony of America Corporation) C:\Program Files\Sony\VAIO Care\listener.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Power Management\SPMService.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Care\VCService.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
(Microsoft Corporation) C:\Program Files\Windows NT\Accessories\wordpad.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
() C:\Users\2018Jean\AppData\Local\tibevus\dsrhlzv.exe
() C:\Users\2018Jean\AppData\Local\tibevus\dsrhlzv.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [Apoint] => C:\Program Files\Apoint\Apoint.exe [212480 2010-08-12] (Alps Electric Co., Ltd.)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1337000 2015-04-30] (Microsoft Corporation)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [10775584 2010-08-12] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2040352 2010-08-12] (Realtek Semiconductor)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2403104 2014-07-25] (NVIDIA Corporation)
HKLM-x32\...\Run: [SmartWiHelper] => C:\Program Files (x86)\Sony\SmartWi Connection Utility\SmartWiHelper.exe [80384 2009-09-02] (Sony Electronics Corporation)
HKLM-x32\...\Run: [ISBMgr.exe] => C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe [673136 2010-05-31] (Sony Corporation)
HKLM-x32\...\Run: [RoxWatchTray] => C:\Program Files (x86)\Common Files\Roxio Shared\13.0\SharedCOM\RoxWatchTray13.exe [307184 2010-07-16] (Sonic Solutions)
HKLM-x32\...\Run: [CPMonitor] => C:\Program Files (x86)\Roxio 2011\5.0\CPMonitor.exe [84464 2010-07-13] ()
HKLM-x32\...\Run: [Acrobat Assistant 7.0] => C:\Program Files (x86)\Adobe\Acrobat 7.0\Distillr\Acrotray.exe [483328 2004-12-14] (Adobe Systems Inc.)
HKLM-x32\...\Run: [] => [X]
HKLM\...\Policies\Explorer: [HideSCAHealth] 1
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-21-4256033146-2562541644-1532691662-1006\...\Run: [strategize] => C:\Program Files (x86)\Chalice\Slighting.exe [51200 2018-04-21] ()
HKU\S-1-5-21-4256033146-2562541644-1532691662-1006\...\Run: [csm] => C:\Program Files (x86)\hinch\csm.exe [66835 2018-04-21] ()
HKU\S-1-5-21-4256033146-2562541644-1532691662-1006\...\MountPoints2: {e0097a13-d8c1-11e3-91fa-806e6f6e6963} - D:\setup.exe
HKU\S-1-5-18\...A8F59079A8D5}\localserver32: <==== ATTENTION
AppInit_DLLs-x32: AirfoilInject3.dll => C:\Windows\SysWOW64\AirfoilInject3.dll [165480 2013-07-20] ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk [2018-04-22]
BootExecute: autocheck autochk /k:C *
GroupPolicy: Restriction - Chrome <==== ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{168B82E7-9862-4EFF-BD65-019741808387}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{A05BE37B-DD10-498B-96B2-8361DB992BC6}: [DhcpNameServer] 209.18.47.61 209.18.47.62
Tcpip\..\Interfaces\{C7E88057-3F3C-4EA8-A0E0-BA3B168DF025}: [DhcpNameServer] 192.168.1.1
Internet Explorer:
==================
SearchScopes: HKLM-x32 -> DefaultScope value is missing
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO-x32: AcroIEHlprObj Class -> {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -> C:\Program Files (x86)\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2004-12-14] (Adobe Systems Incorporated)
BHO-x32: No Name -> {17424104-1444-4810-85D7-B4DA413C5A9A} -> No File
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO-x32: AcroIEToolbarHelper Class -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll [2004-12-14] (Adobe Systems Incorporated)
Toolbar: HKLM-x32 - No Name - {7A21A046-B886-4A62-9D69-EF2059B0A27B} - No File
Toolbar: HKLM-x32 - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll [2004-12-14] (Adobe Systems Incorporated)
Handler: WSAMVCUchrome - {086BD280-4613-43B5 - No File
FireFox:
========
FF DefaultProfile: eedbh3od.default
FF ProfilePath: C:\Users\2018Jean\AppData\Roaming\Mozilla\Firefox\Profiles\eedbh3od.default [2018-04-25]
FF HKLM-x32\...\Firefox\Extensions: [AMVCU@Aimersoft.com] - C:\ProgramData\Aimersoft\Video Converter Ultimate\AMVCU@Aimersoft.com
FF Extension: (Aimersoft Video Converter Ultimate) - C:\ProgramData\Aimersoft\Video Converter Ultimate\AMVCU@Aimersoft.com [2014-07-19] [Legacy] [not signed]
FF HKLM-x32\...\Firefox\Extensions: [citius@orbiscom] - C:\Users\New User\Desktop\CitiVirtualCCnumbers => not found
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_23_0_0_162.dll [2016-10-03] ()
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-16] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_23_0_0_162.dll [2016-10-03] ()
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40416.0\npctrl.dll [2015-04-15] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin-x32: @Nero.com/KM -> C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL [2014-08-29] (Nero AG)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-17] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-17] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.6 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-05-08] (Adobe Systems Inc.)
FF ExtraCheck: C:\Program Files (x86)\mozilla firefox\defaults\pref\freezer-settings.js [2014-06-01] <==== ATTENTION (Points to *.cfg file)
FF ExtraCheck: C:\Program Files (x86)\mozilla firefox\mozillaFreezer.cfg [2014-06-01] <==== ATTENTION
Chrome:
=======
CHR DefaultProfile: Default
CHR HomePage: Default -> hxxp://searchab.com/?aff=7&uid=5ca14c5c-4b97-11e2-823a-00214f55a9ec
CHR StartupUrls: Default -> "hxxps://news.google.com/"
CHR Profile: C:\Users\2018Jean\AppData\Local\Google\Chrome\User Data\Default [2018-04-26]
CHR Extension: (Theme Creator) - C:\Users\2018Jean\AppData\Local\Google\Chrome\User Data\Default\Extensions\akpelnjfckgfiplcikojhomllgombffc [2018-04-13]
CHR Extension: (Docs) - C:\Users\2018Jean\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2018-04-13]
CHR Extension: (Google Drive) - C:\Users\2018Jean\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-04-13]
CHR Extension: (YouTube) - C:\Users\2018Jean\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-04-13]
CHR Extension: (Honey) - C:\Users\2018Jean\AppData\Local\Google\Chrome\User Data\Default\Extensions\bmnlcjabgnpnenekpadlanbbkooimhnj [2018-04-15]
CHR Extension: (Adblock Plus) - C:\Users\2018Jean\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2018-04-23]
CHR Extension: (uBlock Origin) - C:\Users\2018Jean\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpalhdlnbpafiamejdnhcphjbkeiagm [2018-04-23]
CHR Extension: (Always Autocomplete) - C:\Users\2018Jean\AppData\Local\Google\Chrome\User Data\Default\Extensions\djcfppnajkeijjkplclmeiddkefeaiel [2018-04-13]
CHR Extension: (Gmail Offline) - C:\Users\2018Jean\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejidjjhkpiempkbhmpbfngldlkglhimk [2018-04-13]
CHR Extension: (Show Hidden Password) - C:\Users\2018Jean\AppData\Local\Google\Chrome\User Data\Default\Extensions\enhinpoafplfmeeefjglkakjegjcakjl [2018-04-13]
CHR Extension: (ZenMate VPN - Best Cyber Security & Unblock) - C:\Users\2018Jean\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdcgdnkidjaadafnichfpabhfomcebme [2018-04-21]
CHR Extension: (Wayback Machine) - C:\Users\2018Jean\AppData\Local\Google\Chrome\User Data\Default\Extensions\fpnmgdkabkmnadcjpehmlllkndpkmiak [2018-04-13]
CHR Extension: (Chrome Remote Desktop) - C:\Users\2018Jean\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbchcmhmhahfdphkhkmpfmihenigjmpp [2018-04-13]
CHR Extension: (Google Docs Offline) - C:\Users\2018Jean\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-04-13]
CHR Extension: (The Camelizer) - C:\Users\2018Jean\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghnomdcacenbmilgjigehppbamfndblo [2018-04-13]
CHR Extension: (Protect My Choices) - C:\Users\2018Jean\AppData\Local\Google\Chrome\User Data\Default\Extensions\hdgloanjhdcenjgiafkpbehddcnonlic [2018-04-13]
CHR Extension: (PixelBlock) - C:\Users\2018Jean\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmpmfcjnflbcoidlgapblgpgbilinlem [2018-04-13]
CHR Extension: (Read Across The Aisle) - C:\Users\2018Jean\AppData\Local\Google\Chrome\User Data\Default\Extensions\knonchlbnkaddhihddlejfchjjnadmeh [2018-04-13]
CHR Extension: (Ugly Email) - C:\Users\2018Jean\AppData\Local\Google\Chrome\User Data\Default\Extensions\ldgiafaliifpknmgofiifianlnbgflgj [2018-04-13]
CHR Extension: (Chrome Web Store Payments) - C:\Users\2018Jean\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-04-13]
CHR Extension: (Checker Plus for Gmail™) - C:\Users\2018Jean\AppData\Local\Google\Chrome\User Data\Default\Extensions\oeopbcgkkoapgobdbedcemjljbihmemj [2018-04-13]
CHR Extension: (Gmail) - C:\Users\2018Jean\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2018-04-13]
CHR Extension: (Chrome Media Router) - C:\Users\2018Jean\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-04-25]
CHR HKLM-x32\...\Chrome\Extension: [nmapfhedmiiikmeicmclonepdhjgmlcn] - C:\ProgramData\Aimersoft\Video Converter Ultimate\AMVCU@Aimersoft.com.crx [2014-07-19]
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
HKLM\SYSTEM\CurrentControlSet\Services\osvgw <==== ATTENTION (Rootkit!)
S3 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
S3 Adobe LM Service; C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [72704 2014-05-31] (Adobe Systems) [File not signed]
R2 BOT4Service; C:\Program Files (x86)\Roxio\BackOnTrack\App\BService.exe [32240 2010-07-14] ()
R2 ESRV_SVC; C:\Program Files\Sony\VAIO Care\ESRV\esrv_svc.exe [413336 2015-08-26] ()
R2 LightScribeService; C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe [73728 2013-01-16] (Hewlett-Packard Company) [File not signed]
R2 MediatekRegistryWriter; C:\Program Files (x86)\MediatekWiFi\Common\RaRegistry.exe [401040 2014-07-31] (Mediatek Inc.)
R2 MediatekRegistryWriter64; C:\Program Files (x86)\MediatekWiFi\Common\RaRegistry64.exe [454288 2014-07-31] (Mediatek Inc.)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23816 2015-04-30] (Microsoft Corporation)
S3 NETGEARGenieDaemon; C:\Program Files (x86)\NETGEAR Genie\bin\NETGEARGenieDaemon64.exe [232192 2015-06-01] (NETGEAR)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [366544 2015-04-30] (Microsoft Corporation)
R2 nlsX86cc; C:\Windows\SysWOW64\nlssrv32.exe [66560 2011-02-04] (Nalpeiron Ltd.) [File not signed]
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1720608 2014-07-25] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [18956064 2014-07-25] (NVIDIA Corporation)
S2 RaMediaServer; C:\Program Files (x86)\MediatekWiFi\Common\RaMediaServer.exe [1863680 2012-07-06] (Ralink) [File not signed]
R2 RealtekCU; C:\Program Files (x86)\Realtek\USB Wireless LAN Utility\RtlService.exe [36864 2012-05-10] (Realtek Semiconductor Corp.) [File not signed]
S3 RoxMediaDB13; C:\Program Files (x86)\Common Files\Roxio Shared\13.0\SharedCOM\RoxMediaDB13.exe [1099248 2010-07-16] (Sonic Solutions)
R2 Serviio; C:\Program Files\Serviio\bin\ServiioService.exe [327680 2015-03-21] () [File not signed]
R2 SEVPNCLIENT; C:\Program Files\SoftEther VPN Client\vpnclient_x64.exe [4374072 2014-12-09] (SoftEther VPN Project at University of Tsukuba, Japan.)
S3 SOHDBSvr; C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHDBSvr.exe [70952 2009-07-27] (Sony Corporation)
S3 SOHPlMgr; C:\Program Files (x86)\Common Files\Sony Shared\SOHLib\SOHPlMgr.exe [91432 2009-07-27] (Sony Corporation)
R2 Stuffit Archive Name Service; C:\Program Files (x86)\Stuffit\ArcNameService.exe [199000 2008-12-19] (Smith Micro Software, Inc.)
R2 Unchecky; C:\Program Files (x86)\Unchecky\bin\unchecky_svc.exe [297240 2018-04-08] (Reason Software Company Inc.)
S3 USER_ESRV_SVC; C:\Program Files\Sony\VAIO Care\ESRV\esrv_svc.exe [413336 2015-08-26] ()
R3 VUAgent; C:\Program Files\Sony\VAIO Update\vuagent.exe [1656600 2016-03-31] (Sony Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
R2 SampleCollector; "C:\Program Files\Sony\VAIO Care\VCPerfService.exe" "/service" "/sstates" "/sampleinterval=5000" "/procinterval=5" "/dllinterval=120" "/counter=\Processor(_Total)\% Processor Time:1/counter=\PhysicalDisk(_Total)\Disk Bytes/sec:1" "/counter=\Network Interface(*)\Bytes Total/sec:1" "/expandcounter=\Processor Information(*)\Processor Frequency:1" "/expandcounter=\Processor(*)\% Idle Time:1" "/expandcounter=\Processor(*)\% C1 Time:1" "/expandcounter=\Processor(*)\% C2 Time:1" "/expandcounter=\Processor(*)\% C3 Time:1" "/expandcounter=\Processor(*)\% Processor Time:1" "/directory=C:\ProgramData\Sony Corporation\VAIO Care\inteldata" <==== ATTENTION
S4 windowsmanagementservice; windowsmanagementservice [X] <==== ATTENTION
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 Apowersoft_AudioDevice; C:\Windows\System32\drivers\Apowersoft_AudioDevice.sys [31920 2014-04-09] (Wondershare)
S4 IObitUnlocker; C:\Program Files (x86)\IObit\IObit Unlocker\IObitUnlocker.sys [36944 2014-03-04] (IObit)
R1 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [253664 2018-04-25] (Malwarebytes)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [280376 2015-03-04] (Microsoft Corporation)
R1 MpKsl13d2c6a1; c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{99932F80-EB4F-4A73-82AA-A5A232627FCC}\MpKsl13d2c6a1.sys [58120 2018-04-25] (Microsoft Corporation)
R3 Neo_VPN; C:\Windows\System32\DRIVERS\Neo_0055.sys [28768 2014-12-09] (SoftEther VPN Project at University of Tsukuba, Japan.)
S3 netr28ux; C:\Windows\System32\DRIVERS\netr28ux.sys [2212496 2014-07-04] (MediaTek Inc.)
R2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [124568 2015-03-04] (Microsoft Corporation)
R2 npf; C:\Windows\system32\drivers\npf.sys [36600 2015-10-12] (Riverbed Technology, Inc.)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [20256 2014-07-25] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [40392 2014-03-31] (NVIDIA Corporation)
R1 pfmfs_A1C; C:\Windows\System32\Drivers\pfmfs_A1C.sys [258656 2014-07-11] (Pismo Technic Inc.)
R3 SEE; C:\Windows\System32\drivers\see.sys [38240 2014-12-09] (SoftEther VPN Project at University of Tsukuba, Japan.)
R3 semav6msr64; C:\Windows\system32\drivers\semav6msr64.sys [29352 2015-10-07] ()
S3 semav6thermal64ro; C:\Windows\system32\drivers\semav6thermal64ro.sys [13792 2012-11-06] ()
S3 taphss6; C:\Windows\System32\DRIVERS\taphss6.sys [42088 2015-12-18] (Anchorfree Inc.)
R3 VBAudioHFVAIOMME; C:\Windows\System32\DRIVERS\vbaudio_hfvaio64_win7.sys [33512 2014-07-19] (Windows (R) Win 7 DDK provider)
R3 VBAudioVACMME; C:\Windows\System32\DRIVERS\vbaudio_cable64_win7.sys [41192 2013-07-11] (Windows (R) Win 7 DDK provider)
R3 WsAudio_Device; C:\Windows\System32\drivers\VirtualAudio.sys [31080 2013-03-25] (Wondershare)
S3 ALSysIO; \??\C:\Users\2018Jean\AppData\Local\Temp\ALSysIO64.sys [X] <==== ATTENTION
S3 DrvAgent64; \??\C:\Windows\SysWOW64\Drivers\DrvAgent64.SYS [X]
S3 MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [X]
R3 vzcfjm; system32\drivers\cfimps.sys [X]
S1 ZAM; \??\C:\Windows\System32\drivers\zam64.sys [X]
S1 ZAM_Guard; \??\C:\Windows\System32\drivers\zamguard64.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2018-04-26 09:01 - 2018-04-26 09:01 - 000852798 _____ C:\Users\2018Jean\Desktop\SecurityCheck.exe
2018-04-26 08:53 - 2018-04-26 08:53 - 000564350 _____ C:\Users\2018Jean\Documents\cc_20180426_085302.reg
2018-04-25 21:00 - 2018-04-25 21:00 - 000008192 _____ C:\Windows\system32\config\userdiff
2018-04-25 19:40 - 2018-04-25 19:40 - 000000089 _____ C:\Users\2018Jean\Desktop\Sysnative Forum.url
2018-04-25 18:55 - 2018-04-26 10:05 - 000000000 ____D C:\FRST
2018-04-25 18:30 - 2018-04-25 18:30 - 000001456 _____ C:\Users\2018Jean\AppData\Local\Adobe Save for Web 13.0 Prefs
2018-04-25 18:28 - 2018-04-25 18:28 - 000000000 ____D C:\Users\2018Jean\AppData\Roaming\NVIDIA
2018-04-25 18:22 - 2018-04-25 18:22 - 000000000 _____ C:\Users\2018Jean\AppData\LocalLow\QuickTime.qtp
2018-04-25 17:29 - 2018-04-25 17:29 - 000000830 _____ C:\Users\2018Jean\Desktop\NOT SEEN YET.lnk
2018-04-25 17:25 - 2018-04-25 17:25 - 000000000 ____D C:\Users\2018Jean\AppData\Local\uprstbh
2018-04-25 16:02 - 2018-04-25 17:26 - 000000000 ___HD C:\$WINDOWS.~BT
2018-04-25 16:00 - 2018-04-25 19:41 - 000000000 ____D C:\Users\2018Jean\Desktop\Cooties
2018-04-25 15:55 - 2018-04-25 15:55 - 000000000 ____D C:\Users\2018Jean\AppData\Local\dsevumr
2018-04-25 15:05 - 2018-04-25 15:05 - 000000000 ____D C:\Users\2018Jean\AppData\Local\wmodzib
2018-04-25 13:37 - 2018-04-25 13:37 - 000253664 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamswissarmy.sys
2018-04-25 13:37 - 2018-04-25 13:37 - 000193768 _____ (Malwarebytes) C:\Windows\system32\Drivers\MbamChameleon.sys
2018-04-25 13:37 - 2018-04-25 13:37 - 000093816 _____ (Malwarebytes) C:\Windows\system32\Drivers\mwac.sys
2018-04-25 13:37 - 2018-04-25 13:37 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2018-04-25 13:36 - 2018-04-25 13:36 - 000000000 ____D C:\Program Files\Malwarebytes
2018-04-25 13:36 - 2018-03-19 12:57 - 000076192 _____ C:\Windows\system32\Drivers\mbae64.sys
2018-04-25 12:28 - 2018-04-25 12:28 - 000003160 _____ C:\Windows\System32\Tasks\{19FA1E7F-C63E-4A46-97A3-3F34BC31D6C0}
2018-04-25 11:45 - 2018-04-25 11:31 - 017391963 ____N C:\EvtxAppDump.txt
2018-04-25 11:45 - 2018-04-25 11:31 - 012564416 ____N C:\EvtxSysDump.txt
2018-04-25 11:45 - 2018-04-25 11:31 - 001412796 ____N C:\MSInfo32.nfo
2018-04-25 11:45 - 2018-04-25 11:31 - 000300898 ____N C:\042318-80246-01.dmp
2018-04-25 11:45 - 2018-04-25 11:31 - 000300770 ____N C:\042318-58781-01.dmp
2018-04-25 11:45 - 2018-04-25 11:31 - 000300770 ____N C:\042318-33181-01.dmp
2018-04-25 11:45 - 2018-04-25 11:31 - 000300770 ____N C:\042318-32900-01.dmp
2018-04-25 11:45 - 2018-04-25 11:31 - 000300770 ____N C:\042218-79700-01.dmp
2018-04-25 11:45 - 2018-04-25 11:31 - 000300770 ____N C:\042218-52151-01.dmp
2018-04-25 11:45 - 2018-04-25 11:31 - 000300770 ____N C:\042218-154815-01.dmp
2018-04-25 11:45 - 2018-04-25 11:31 - 000300770 ____N C:\042218-148684-01.dmp
2018-04-25 11:45 - 2018-04-25 11:31 - 000300770 ____N C:\042118-40248-01.dmp
2018-04-25 11:45 - 2018-04-25 11:31 - 000300770 ____N C:\042118-32417-01.dmp
2018-04-25 11:45 - 2018-04-25 11:31 - 000300770 ____N C:\042118-30170-01.dmp
2018-04-25 11:45 - 2018-04-25 11:31 - 000300770 ____N C:\042118-28204-01.dmp
2018-04-25 11:45 - 2018-04-25 11:31 - 000300194 ____N C:\042318-43165-01.dmp
2018-04-25 11:45 - 2018-04-25 11:31 - 000300194 ____N C:\042218-45037-01.dmp
2018-04-25 11:45 - 2018-04-25 11:31 - 000275160 ____N C:\WERProgramData
2018-04-25 11:45 - 2018-04-25 11:31 - 000259762 ____N C:\SysList.txt
2018-04-25 11:45 - 2018-04-25 11:31 - 000197556 ____N C:\WERALL.txt
2018-04-25 11:45 - 2018-04-25 11:31 - 000177720 ____N C:\TasklistSVCHOST.txt
2018-04-25 11:45 - 2018-04-25 11:31 - 000096382 ____N C:\NetstatJcgriff2
2018-04-25 11:45 - 2018-04-25 11:31 - 000066126 ____N C:\DriverqV.txt
2018-04-25 11:45 - 2018-04-25 11:31 - 000060895 ____N C:\HKLMSoftMSWinCVUninstall.txt
2018-04-25 11:45 - 2018-04-25 11:31 - 000052704 ____N C:\DxDiagx86.txt
2018-04-25 11:45 - 2018-04-25 11:31 - 000038738 ____N C:\DriverqFo.txt
2018-04-25 11:45 - 2018-04-25 11:31 - 000016195 ____N C:\WERLocalAppData
2018-04-25 11:45 - 2018-04-25 11:31 - 000015797 ____N C:\DriverqSi.txt
2018-04-25 11:45 - 2018-04-25 11:31 - 000015699 ____N C:\NetSHLAN1.txt
2018-04-25 11:45 - 2018-04-25 11:31 - 000014138 ____N C:\Jcgriff2Log.txt
2018-04-25 11:45 - 2018-04-25 11:31 - 000013802 ____N C:\SystemInfo.txt
2018-04-25 11:45 - 2018-04-25 11:31 - 000010024 ____N C:\RAMInfo.html
2018-04-25 11:45 - 2018-04-25 11:31 - 000009566 ____N C:\HKLMSoftMSA-SInstalledComponents.txt
2018-04-25 11:45 - 2018-04-25 11:31 - 000007607 ____N C:\IPconfigAll.txt
2018-04-25 11:45 - 2018-04-25 11:31 - 000003987 ____N C:\SetEnvironmentVar.txt
2018-04-25 11:45 - 2018-04-25 11:31 - 000002199 ____N C:\KernelDumpList.txt
2018-04-25 11:45 - 2018-04-25 11:31 - 000002047 ____N C:\Hosts.txt
2018-04-25 11:45 - 2018-04-25 11:31 - 000001338 ____N C:\WMICRecoveros.txt
2018-04-25 11:45 - 2018-04-25 11:31 - 000001278 ____N C:\BSODPostingInstructions.txt
2018-04-25 11:45 - 2018-04-25 11:31 - 000001213 ____N C:\Tracert.txt
2018-04-25 11:45 - 2018-04-25 11:31 - 000000002 ____N C:\HKCUSoftMSWinCVUninstall.txt
2018-04-25 11:45 - 2018-04-25 11:31 - 000000002 ____N C:\Autoruns.txt
2018-04-25 11:45 - 2018-04-25 11:31 - 000000000 ____N C:\NetstatJcgriff2.StdErr
2018-04-24 20:51 - 2018-04-26 02:34 - 000000000 ____D C:\Users\2018Jean\AppData\Local\sictnhk
2018-04-24 20:38 - 2018-04-25 15:14 - 000000000 ____D C:\Users\2018Jean\AppData\LocalLow\Mozilla
2018-04-24 20:38 - 2018-04-24 20:38 - 000000000 ____D C:\Users\2018Jean\AppData\Roaming\Mozilla
2018-04-24 20:38 - 2018-04-24 20:38 - 000000000 ____D C:\Users\2018Jean\AppData\Local\Mozilla
2018-04-24 16:27 - 2018-04-24 16:27 - 000001245 _____ C:\Users\2018Jean\AppData\Local\recently-used.xbel
2018-04-23 19:41 - 2018-04-23 19:41 - 000000000 ____D C:\Users\2018Jean\AppData\Local\vdewzng
2018-04-23 18:13 - 2018-04-23 18:14 - 000000000 ____D C:\Users\2018Jean\AppData\Roaming\PeaZip
2018-04-23 18:06 - 2018-04-23 18:06 - 000000000 ____D C:\ProgramData\UniqueId
2018-04-23 17:39 - 2018-04-23 18:54 - 000000000 ____D C:\Program Files\Reimage
2018-04-23 17:38 - 2018-04-23 18:53 - 000000140 _____ C:\Windows\Reimage.ini
2018-04-23 17:07 - 2018-04-23 17:07 - 000000000 ____D C:\SFCFix
2018-04-23 16:29 - 2018-04-23 19:48 - 000000000 ____D C:\Users\2018Jean\AppData\Local\niemiro
2018-04-23 16:18 - 2018-04-23 16:18 - 000000000 ____D C:\Users\2018Jean\AppData\Local\sbexiwt
2018-04-23 16:14 - 2018-04-25 17:21 - 002888704 _____ (TOSHIBA CORPORATION) C:\Windows\system32\sbalwomsvc.exe
2018-04-23 16:14 - 2018-04-23 16:14 - 000142672 ____N C:\Windows\system32\Drivers\dwrpswzc.sys
2018-04-23 15:57 - 2018-04-23 16:10 - 000000000 ____D C:\ProgramData\SecTaskMan
2018-04-23 15:53 - 2018-04-23 15:53 - 000000000 ____D C:\Users\Administrator\AppData\Local\ElevatedDiagnostics
2018-04-23 15:51 - 2018-04-23 15:51 - 000000000 ___HD C:\$Windows.~WS
2018-04-23 15:45 - 2018-04-23 15:45 - 000000000 ____D C:\Users\Administrator\AppData\Local\cwclsuo
2018-04-23 15:15 - 2018-04-23 15:15 - 000000000 ____D C:\Users\New User\AppData\Local\NPE
2018-04-23 14:38 - 2018-04-23 14:43 - 000000000 ____D C:\Users\Administrator\AppData\Local\Smith Micro
2018-04-23 14:38 - 2018-04-23 14:38 - 000000000 ____D C:\Users\Administrator\Documents\My Archives
2018-04-23 14:33 - 2018-04-23 15:53 - 000000000 ____D C:\ESD
2018-04-23 14:28 - 2018-04-23 14:28 - 018617536 _____ (Microsoft Corporation) C:\Users\Administrator\Desktop\MediaCreationTool.exe
2018-04-23 13:57 - 2018-04-23 13:57 - 000000000 ____D C:\Users\Administrator\AppData\Local\usndpmr
2018-04-23 13:57 - 2018-04-23 13:57 - 000000000 ____D C:\Users\Administrator\AppData\Local\avcskld
2018-04-23 12:13 - 2018-04-23 12:13 - 000000000 ____D C:\Users\Administrator\AppData\Local\sinmlep
2018-04-23 12:13 - 2018-04-23 12:13 - 000000000 ____D C:\Users\Administrator\AppData\Local\dwenhzu
2018-04-23 11:44 - 2018-04-23 11:44 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NirSoft BlueScreenView
2018-04-23 11:43 - 2018-04-23 11:43 - 000141864 _____ C:\Users\Administrator\Desktop\bluescreenview_setup.exe
2018-04-23 11:26 - 2018-04-23 11:26 - 000000476 _____ C:\Users\Administrator\Desktop\Local Disk.lnk
2018-04-23 11:00 - 2018-04-23 11:00 - 000000000 ____D C:\Users\Administrator\AppData\Local\wenopab
2018-04-23 11:00 - 2018-04-23 11:00 - 000000000 ____D C:\Users\Administrator\AppData\Local\raaxvnu
2018-04-23 10:38 - 2018-04-23 10:38 - 000000000 ____D C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
2018-04-23 09:57 - 2018-04-23 09:57 - 000001380 _____ C:\Users\Administrator\Desktop\NOT SEEN YET.lnk
2018-04-23 09:57 - 2018-04-20 10:07 - 000002162 _____ C:\Users\Administrator\Desktop\$$.lnk
2018-04-23 09:56 - 2018-04-23 09:56 - 000000000 ____D C:\Users\Administrator\AppData\Local\wmcagent
2018-04-23 09:56 - 2018-04-22 17:36 - 000002057 _____ C:\Users\Administrator\Desktop\Litter.lnk
2018-04-23 09:53 - 2018-04-23 09:53 - 000001160 _____ C:\Users\Administrator\Desktop\Jean Desktop.lnk
2018-04-23 09:50 - 2018-04-23 09:50 - 000000000 ____D C:\Users\Administrator\AppData\Local\wimbrdt
2018-04-23 09:50 - 2018-04-23 09:50 - 000000000 ____D C:\Users\Administrator\AppData\Local\mbbdcor
2018-04-22 20:43 - 2018-04-22 20:43 - 000000000 ____D C:\Users\2018Jean\AppData\Local\sbizvxg
2018-04-22 20:43 - 2018-04-22 20:43 - 000000000 ____D C:\Users\2018Jean\AppData\Local\ElevatedDiagnostics
2018-04-22 20:20 - 2018-04-22 20:20 - 000000000 ____D C:\Users\2018Jean\Documents\My Archives
2018-04-22 19:55 - 2018-04-22 19:55 - 000000000 ____D C:\Users\2018Jean\AppData\Local\rabzdkn
2018-04-22 18:55 - 2018-04-22 18:55 - 000000000 ____D C:\Users\2018Jean\AppData\Local\sikzlxh
2018-04-22 17:36 - 2018-04-22 17:36 - 000002057 _____ C:\Users\2018Jean\Desktop\Litter.lnk
2018-04-22 08:06 - 2018-04-22 08:06 - 000002459 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Distiller 7.0.lnk
2018-04-22 08:06 - 2018-04-22 08:06 - 000002453 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Designer 7.0.lnk
2018-04-22 08:06 - 2018-04-22 08:06 - 000002447 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat 7.0 Professional.lnk
2018-04-22 07:24 - 2018-04-22 07:24 - 000000000 ____D C:\Users\2018Jean\AppData\Local\niorwds
2018-04-22 07:06 - 2018-04-22 07:06 - 000000000 ____D C:\Users\2018Jean\AppData\Local\atcbgmv
2018-04-21 22:32 - 2018-04-21 22:32 - 000000000 ____D C:\Users\2018Jean\AppData\Local\pwnlkcm
2018-04-21 22:15 - 2018-04-26 10:10 - 000000000 ____D C:\Users\2018Jean\AppData\Local\tibevus
2018-04-21 22:15 - 2018-04-21 22:15 - 000000000 ____D C:\Users\2018Jean\AppData\Local\coogxwm
2018-04-21 21:48 - 2018-04-21 21:48 - 000000000 ____D C:\Users\2018Jean\AppData\Local\vsbprkg
2018-04-21 21:48 - 2018-04-21 21:48 - 000000000 ____D C:\Users\2018Jean\AppData\Local\vdbznux
2018-04-21 21:42 - 2018-04-23 15:40 - 001068960 _____ C:\Windows\ntbtlog.txt
2018-04-21 21:29 - 2018-04-21 21:29 - 000000000 ____D C:\Users\2018Jean\AppData\Local\lsdzmre
2018-04-21 21:28 - 2018-04-21 21:32 - 000000000 ____D C:\Users\2018Jean\AppData\Local\spharxu
2018-04-21 20:53 - 2018-04-21 21:17 - 000000000 ____D C:\Users\2018Jean\AppData\Local\cwkvulb
2018-04-21 20:39 - 2018-04-21 21:21 - 000000000 ____D C:\Program Files (x86)\Zemana AntiMalware
2018-04-21 20:32 - 2018-04-21 20:32 - 000000000 ____D C:\Users\2018Jean\AppData\Local\Zemana
2018-04-21 20:02 - 2018-04-21 20:02 - 000000000 ____D C:\Users\2018Jean\AppData\Local\CEF
2018-04-21 20:01 - 2018-04-21 20:02 - 000000000 ____D C:\Users\2018Jean\AppData\Local\wmcagent
2018-04-21 20:01 - 2018-04-21 20:01 - 000000000 ____D C:\Users\2018Jean\AppData\Roaming\Macromedia
2018-04-21 19:58 - 2018-04-21 21:51 - 000000000 ____D C:\Users\2018Jean\AppData\Local\avnpetb
2018-04-21 19:58 - 2018-04-21 19:58 - 000000000 ____D C:\Users\2018Jean\AppData\Local\dsiexuo
2018-04-21 19:55 - 2018-04-23 15:36 - 002888704 _____ C:\Windows\SysWOW64\sbalwomsvc.exe
2018-04-21 19:50 - 2018-04-21 20:01 - 000000000 ____D C:\Users\2018Jean\AppData\Roaming\AGData
2018-04-21 19:49 - 2018-04-21 20:45 - 000000000 ____D C:\Program Files (x86)\coordinator
2018-04-21 19:49 - 2018-04-21 19:49 - 000003882 _____ C:\Windows\System32\Tasks\nipples
2018-04-21 19:49 - 2018-04-21 19:49 - 000003740 _____ C:\Windows\System32\Tasks\Sanipplesnipples
2018-04-21 19:49 - 2018-04-21 19:49 - 000000012 _____ C:\Windows\b72651245
2018-04-21 19:49 - 2018-04-21 19:49 - 000000000 ___HD C:\Program Files (x86)\hinch
2018-04-21 19:49 - 2018-04-21 19:49 - 000000000 ___HD C:\Program Files (x86)\Eduard
2018-04-21 19:49 - 2018-04-21 19:49 - 000000000 ____D C:\Windows\SysWOW64\lsebtrx
2018-04-21 19:49 - 2018-04-21 19:49 - 000000000 ____D C:\Windows\system32\lsebtrx
2018-04-21 19:49 - 2018-04-21 19:49 - 000000000 ____D C:\Users\2018Jean\AppData\Roaming\et
2018-04-21 19:49 - 2018-04-21 19:49 - 000000000 ____D C:\Program Files (x86)\fighter
2018-04-21 19:49 - 2018-04-21 19:49 - 000000000 ____D C:\Program Files (x86)\Chalice
2018-04-21 19:48 - 2018-04-21 20:44 - 000000000 ____D C:\Users\2018Jean\AppData\Local\CrashDumps
2018-04-21 19:48 - 2018-04-21 19:49 - 000000000 ____D C:\ProgramData\Arkei-{601A1EDD-2C55-4B67-98FF-D1B2BB6FD336}
2018-04-21 17:02 - 2018-04-21 17:02 - 000051200 _____ C:\Windows\nuances.exe
2018-04-21 17:02 - 2018-04-21 17:02 - 000051200 _____ C:\Users\2018Jean\AppData\Local\undermining.exe
2018-04-21 17:02 - 2018-04-21 17:02 - 000051200 _____ C:\Users\2018Jean\AppData\Local\Slighting.exe
2018-04-21 10:03 - 2018-04-22 08:06 - 000000000 ____D C:\Users\Public\Documents\Adobe PDF
2018-04-17 16:28 - 2018-04-23 18:03 - 000000000 ____D C:\Users\2018Jean\AppData\Local\Smith Micro
2018-04-16 10:40 - 2018-04-16 10:40 - 000000000 ____D C:\Users\2018Jean\AppData\Roaming\AdobeUM
2018-04-14 14:39 - 2018-04-14 14:39 - 000000000 ____D C:\Users\2018Jean\AppData\LocalLow\Adobe
2018-04-13 15:18 - 2018-04-23 20:38 - 000000000 ____D C:\Users\2018Jean\AppData\Roaming\vlc
2018-04-13 13:38 - 2018-04-20 15:51 - 000000000 ____D C:\Users\2018Jean\AppData\Roaming\deluge
2018-04-13 12:47 - 2018-04-20 10:07 - 000002162 _____ C:\Users\2018Jean\Desktop\$$.lnk
2018-04-13 12:46 - 2018-04-13 12:19 - 000746554 _____ C:\Users\2018Jean\bookmarks_4_13_18.html
2018-04-13 12:45 - 2018-04-13 12:45 - 000001952 _____ C:\Users\2018Jean\Desktop\FileCabinet.lnk
2018-04-13 12:11 - 2018-04-13 12:11 - 000000000 ____D C:\Users\2018Jean\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
2018-04-13 12:10 - 2018-04-13 12:10 - 000000000 ____D C:\Users\2018Jean\AppData\Roaming\Google
2018-04-13 12:06 - 2018-04-13 12:06 - 000003416 _____ C:\Users\2018Jean\Layout 1600 x 900 (32).dtr
2018-04-13 12:03 - 2018-04-25 18:22 - 000000000 ____D C:\Users\2018Jean\AppData\Local\VirtualStore
2018-04-13 11:51 - 2018-04-12 14:25 - 005767168 _____ C:\Users\2018Jean\ntuser (2).dat
2018-04-13 11:37 - 2014-06-25 12:28 - 000002286 ____H C:\Users\2018Jean\Documents\Default.rdp
2018-04-13 11:21 - 2018-04-22 17:36 - 000000000 ___RD C:\Users\2018Jean\FileCabinet
2018-04-13 11:21 - 2015-09-22 14:43 - 000000000 ____D C:\Users\2018Jean\DuOSShare
2018-04-13 10:58 - 2018-04-13 14:03 - 000000000 ____D C:\Users\2018Jean\.jbidwatcher
2018-04-13 10:58 - 2018-04-13 14:02 - 000000000 ____D C:\Users\2018Jean\.oracle_jre_usage
2018-04-13 10:58 - 2018-04-13 10:58 - 000000000 ____D C:\Users\2018Jean\Song Surgeon 4
2018-04-13 10:58 - 2018-04-13 10:58 - 000000000 ____D C:\Users\2018Jean\Prismatik
2018-04-13 10:58 - 2018-04-13 10:58 - 000000000 ____D C:\Users\2018Jean\.FBReader
2018-04-13 10:58 - 2018-04-13 10:58 - 000000000 ____D C:\Users\2018Jean\.cache
2018-04-13 10:58 - 2018-04-13 10:58 - 000000000 ____D C:\Users\2018Jean\.android
2018-04-13 10:58 - 2018-02-05 14:51 - 002080256 ___SH C:\Users\2018Jean\Desktop\Thumbs.db
2018-04-13 10:58 - 2018-01-24 15:13 - 000002298 _____ C:\Users\2018Jean\Desktop\Brian Desktop.lnk
2018-04-13 10:58 - 2017-08-13 11:31 - 000000476 _____ C:\Users\2018Jean\Desktop\Local Disk.lnk
2018-04-13 10:58 - 2017-07-01 20:05 - 000002303 _____ C:\Users\2018Jean\DesktopWin10Tool.txt
2018-04-13 10:58 - 2015-07-15 20:10 - 000000032 _____ C:\Users\2018Jean\.deskmetrics
2018-04-13 10:39 - 2018-04-13 12:05 - 000000000 ____D C:\Users\2018Jean\AppData\Local\NVIDIA Corporation
2018-04-13 10:38 - 2018-04-25 18:28 - 000000000 ____D C:\Users\2018Jean\AppData\Local\Adobe
2018-04-13 10:38 - 2018-04-22 08:31 - 000091136 _____ C:\Users\2018Jean\AppData\Local\GDIPFONTCACHEV1.DAT
2018-04-13 10:38 - 2018-04-13 10:38 - 000000000 ____D C:\Users\2018Jean\AppData\Roaming\Roxio
2018-04-13 10:38 - 2018-04-13 10:38 - 000000000 ____D C:\Users\2018Jean\AppData\Local\NVIDIA
2018-04-13 10:37 - 2018-04-25 18:29 - 000000000 ____D C:\Users\2018Jean\AppData\Roaming\Adobe
2018-04-13 10:37 - 2018-04-25 15:14 - 000000000 ____D C:\Users\2018Jean\AppData\Local\Google
2018-04-13 10:37 - 2018-04-23 09:53 - 000000000 ____D C:\Users\2018Jean
2018-04-13 10:37 - 2018-04-13 10:37 - 000001417 _____ C:\Users\2018Jean\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2018-04-13 10:37 - 2018-04-13 10:37 - 000000020 ___SH C:\Users\2018Jean\ntuser.ini
2018-04-13 10:37 - 2018-04-13 10:37 - 000000000 ____D C:\Users\2018Jean\AppData\Roaming\Sony Corporation
2018-04-13 10:37 - 2009-07-14 03:44 - 000000000 ____D C:\Users\2018Jean\AppData\Roaming\Media Center Programs
2018-04-13 06:45 - 2018-04-13 06:45 - 004279968 _____ (NeoSoft Tools ) C:\Users\2018Jean\AppData\Roaming\ctask.exe
2018-04-12 19:06 - 2018-04-26 09:17 - 136971704 ____C (Microsoft Corporation) C:\Windows\system32\MRT-KB890830.exe
2018-04-12 18:56 - 2018-03-22 17:17 - 000048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2018-04-12 18:56 - 2018-03-22 17:09 - 000034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2018-04-12 18:56 - 2018-03-22 17:06 - 000116224 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2018-04-12 18:56 - 2018-03-22 16:50 - 000064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2018-04-12 18:56 - 2018-03-22 16:45 - 000030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2018-04-12 18:56 - 2018-03-22 16:28 - 000091136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2018-04-12 18:56 - 2018-03-22 16:25 - 000076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2018-04-12 18:55 - 2018-03-30 22:09 - 005583040 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2018-04-12 18:55 - 2018-03-30 22:09 - 000708288 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2018-04-12 18:55 - 2018-03-30 22:09 - 000262336 _____ (Microsoft Corporation) C:\Windows\system32\hal.dll
2018-04-12 18:55 - 2018-03-30 22:09 - 000154816 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2018-04-12 18:55 - 2018-03-30 22:09 - 000095424 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2018-04-12 18:55 - 2018-03-30 21:45 - 000631640 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2018-04-12 18:55 - 2018-03-30 21:39 - 004046528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2018-04-12 18:55 - 2018-03-30 21:39 - 003958464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2018-04-12 18:55 - 2018-03-30 21:38 - 001665336 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 001461248 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 001212928 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 001163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000880640 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000731648 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000463872 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000419840 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000361984 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000345600 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000316928 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000215552 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000190464 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000123904 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000094720 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000059904 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000044032 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000034816 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000007168 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:35 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:12 - 001314064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2018-04-12 18:55 - 2018-03-30 21:09 - 001114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2018-04-12 18:55 - 2018-03-30 21:09 - 000690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2018-04-12 18:55 - 2018-03-30 21:09 - 000666112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2018-04-12 18:55 - 2018-03-30 21:09 - 000644096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2018-04-12 18:55 - 2018-03-30 21:09 - 000554496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2018-04-12 18:55 - 2018-03-30 21:09 - 000342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
2018-04-12 18:55 - 2018-03-30 21:09 - 000275456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2018-04-12 18:55 - 2018-03-30 21:09 - 000261120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2018-04-12 18:55 - 2018-03-30 21:09 - 000254464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2018-04-12 18:55 - 2018-03-30 21:09 - 000223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2018-04-12 18:55 - 2018-03-30 21:09 - 000172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2018-04-12 18:55 - 2018-03-30 21:09 - 000146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2018-04-12 18:55 - 2018-03-30 21:09 - 000141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll
2018-04-12 18:55 - 2018-03-30 21:09 - 000096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2018-04-12 18:55 - 2018-03-30 21:09 - 000082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcrypt.dll
2018-04-12 18:55 - 2018-03-30 21:09 - 000070144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2018-04-12 18:55 - 2018-03-30 21:09 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2018-04-12 18:55 - 2018-03-30 21:09 - 000050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll
2018-04-12 18:55 - 2018-03-30 21:09 - 000043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2018-04-12 18:55 - 2018-03-30 21:09 - 000022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2018-04-12 18:55 - 2018-03-30 21:09 - 000017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2018-04-12 18:55 - 2018-03-30 21:09 - 000007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2018-04-12 18:55 - 2018-03-30 21:09 - 000005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:09 - 000005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2018-04-12 18:55 - 2018-03-30 21:09 - 000004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:09 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:09 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:09 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:09 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:09 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:09 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:09 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:09 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:09 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:09 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:09 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:09 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:09 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:09 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:09 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:09 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:09 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:09 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:09 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:09 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:09 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:09 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 21:06 - 000148480 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2018-04-12 18:55 - 2018-03-30 21:06 - 000064512 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2018-04-12 18:55 - 2018-03-30 21:06 - 000062464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2018-04-12 18:55 - 2018-03-30 21:06 - 000017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2018-04-12 18:55 - 2018-03-30 21:03 - 000338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2018-04-12 18:55 - 2018-03-30 21:02 - 000296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2018-04-12 18:55 - 2018-03-30 21:02 - 000129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\videoprt.sys
2018-04-12 18:55 - 2018-03-30 20:59 - 000160256 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2018-04-12 18:55 - 2018-03-30 20:58 - 000291328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2018-04-12 18:55 - 2018-03-30 20:58 - 000129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2018-04-12 18:55 - 2018-03-30 20:58 - 000112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2018-04-12 18:55 - 2018-03-30 20:58 - 000030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2018-04-12 18:55 - 2018-03-30 20:51 - 000050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2018-04-12 18:55 - 2018-03-30 20:47 - 000036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
2018-04-12 18:55 - 2018-03-30 20:47 - 000025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2018-04-12 18:55 - 2018-03-30 20:47 - 000014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2018-04-12 18:55 - 2018-03-30 20:47 - 000007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2018-04-12 18:55 - 2018-03-30 20:47 - 000006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 20:47 - 000004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 20:47 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 20:47 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2018-04-12 18:55 - 2018-03-30 20:47 - 000002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2018-04-12 18:55 - 2018-03-28 03:30 - 003225600 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2018-04-12 18:55 - 2018-03-23 14:50 - 000396952 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2018-04-12 18:55 - 2018-03-23 13:59 - 000348824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2018-04-12 18:55 - 2018-03-22 19:00 - 025742336 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2018-04-12 18:55 - 2018-03-22 17:32 - 002724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2018-04-12 18:55 - 2018-03-22 17:32 - 000004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2018-04-12 18:55 - 2018-03-22 17:26 - 020287488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2018-04-12 18:55 - 2018-03-22 17:19 - 002901504 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2018-04-12 18:55 - 2018-03-22 17:18 - 000066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2018-04-12 18:55 - 2018-03-22 17:17 - 000578048 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2018-04-12 18:55 - 2018-03-22 17:17 - 000417280 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2018-04-12 18:55 - 2018-03-22 17:17 - 000088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2018-04-12 18:55 - 2018-03-22 17:15 - 005780480 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2018-04-12 18:55 - 2018-03-22 17:10 - 000054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2018-04-12 18:55 - 2018-03-22 17:07 - 000615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2018-04-12 18:55 - 2018-03-22 17:06 - 000794112 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2018-04-12 18:55 - 2018-03-22 17:06 - 000144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2018-04-12 18:55 - 2018-03-22 17:05 - 000814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2018-04-12 18:55 - 2018-03-22 17:04 - 002724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2018-04-12 18:55 - 2018-03-22 16:58 - 000969216 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2018-04-12 18:55 - 2018-03-22 16:55 - 000489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2018-04-12 18:55 - 2018-03-22 16:52 - 000499712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2018-04-12 18:55 - 2018-03-22 16:52 - 000062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2018-04-12 18:55 - 2018-03-22 16:51 - 000341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2018-04-12 18:55 - 2018-03-22 16:51 - 000047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2018-04-12 18:55 - 2018-03-22 16:49 - 000077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2018-04-12 18:55 - 2018-03-22 16:48 - 002295296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2018-04-12 18:55 - 2018-03-22 16:48 - 000107520 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2018-04-12 18:55 - 2018-03-22 16:48 - 000087552 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2018-04-12 18:55 - 2018-03-22 16:45 - 000199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2018-04-12 18:55 - 2018-03-22 16:45 - 000047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2018-04-12 18:55 - 2018-03-22 16:44 - 000092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2018-04-12 18:55 - 2018-03-22 16:43 - 000476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2018-04-12 18:55 - 2018-03-22 16:42 - 000661504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2018-04-12 18:55 - 2018-03-22 16:42 - 000315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2018-04-12 18:55 - 2018-03-22 16:42 - 000115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2018-04-12 18:55 - 2018-03-22 16:41 - 000620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2018-04-12 18:55 - 2018-03-22 16:40 - 000152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2018-04-12 18:55 - 2018-03-22 16:33 - 000416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2018-04-12 18:55 - 2018-03-22 16:31 - 000262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2018-04-12 18:55 - 2018-03-22 16:29 - 015282688 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2018-04-12 18:55 - 2018-03-22 16:29 - 000809472 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2018-04-12 18:55 - 2018-03-22 16:29 - 000728064 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2018-04-12 18:55 - 2018-03-22 16:29 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2018-04-12 18:55 - 2018-03-22 16:28 - 000073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2018-04-12 18:55 - 2018-03-22 16:27 - 002135552 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2018-04-12 18:55 - 2018-03-22 16:27 - 001359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2018-04-12 18:55 - 2018-03-22 16:25 - 000168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2018-04-12 18:55 - 2018-03-22 16:24 - 000279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2018-04-12 18:55 - 2018-03-22 16:22 - 000130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2018-04-12 18:55 - 2018-03-22 16:21 - 004496896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2018-04-12 18:55 - 2018-03-22 16:20 - 013680128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2018-04-12 18:55 - 2018-03-22 16:17 - 000230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2018-04-12 18:55 - 2018-03-22 16:15 - 003241472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2018-04-12 18:55 - 2018-03-22 16:15 - 000696320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2018-04-12 18:55 - 2018-03-22 16:14 - 002059776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2018-04-12 18:55 - 2018-03-22 16:14 - 001155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2018-04-12 18:55 - 2018-03-22 16:04 - 001545728 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2018-04-12 18:55 - 2018-03-22 15:55 - 002767872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2018-04-12 18:55 - 2018-03-22 15:53 - 000800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2018-04-12 18:55 - 2018-03-22 15:52 - 001313792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2018-04-12 18:55 - 2018-03-22 15:51 - 000710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2018-04-12 18:55 - 2018-03-10 13:11 - 000340480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msexcl40.dll
2018-04-12 18:55 - 2018-03-09 14:18 - 000309440 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2018-04-12 18:55 - 2018-03-09 14:12 - 000383680 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2018-04-12 18:55 - 2018-03-09 14:12 - 000111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\t2embed.dll
2018-04-12 18:55 - 2018-03-09 14:12 - 000071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2018-04-12 18:55 - 2018-03-09 14:12 - 000025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
2018-04-12 18:55 - 2018-03-09 14:11 - 000010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
2018-04-12 18:55 - 2018-03-09 14:07 - 000152064 _____ (Microsoft Corporation) C:\Windows\system32\t2embed.dll
2018-04-12 18:55 - 2018-03-09 14:07 - 000100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2018-04-12 18:55 - 2018-03-09 14:07 - 000041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2018-04-12 18:55 - 2018-03-09 14:06 - 000046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2018-04-12 18:55 - 2018-03-09 14:06 - 000014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2018-04-12 18:55 - 2018-03-09 13:31 - 000034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2018-04-12 18:55 - 2018-03-06 14:13 - 000148160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\basecsp.dll
2018-04-12 18:55 - 2018-03-06 14:11 - 000184320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scksp.dll
2018-04-12 18:55 - 2018-03-06 14:11 - 000052224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wsnmp32.dll
2018-04-12 18:55 - 2018-03-06 14:10 - 000170176 _____ (Microsoft Corporation) C:\Windows\system32\basecsp.dll
2018-04-12 18:55 - 2018-03-06 14:07 - 000229376 _____ (Microsoft Corporation) C:\Windows\system32\scksp.dll
2018-04-12 18:55 - 2018-03-06 14:07 - 000067072 _____ (Microsoft Corporation) C:\Windows\system32\wsnmp32.dll
2018-04-12 18:55 - 2018-02-21 23:28 - 000217600 _____ (Microsoft Corporation) C:\Windows\system32\WinSCard.dll
2018-04-12 18:55 - 2018-02-21 23:06 - 000134656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WinSCard.dll
2018-04-12 18:55 - 2018-02-18 17:34 - 000634272 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
2018-04-12 18:55 - 2018-02-10 14:35 - 000367296 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msrpc.sys
2018-04-12 18:55 - 2018-02-10 14:35 - 000334528 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\acpi.sys
2018-04-12 18:55 - 2018-02-10 14:35 - 000185024 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\pci.sys
2018-04-12 18:55 - 2018-02-10 14:35 - 000122560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\NV_AGP.SYS
2018-04-12 18:55 - 2018-02-10 14:35 - 000068288 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\volmgr.sys
2018-04-12 18:55 - 2018-02-10 14:35 - 000064192 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ULIAGPKX.SYS
2018-04-12 18:55 - 2018-02-10 14:35 - 000063168 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\termdd.sys
2018-04-12 18:55 - 2018-02-10 14:35 - 000060608 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\AGP440.sys
2018-04-12 18:55 - 2018-02-10 14:35 - 000036032 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\vdrvroot.sys
2018-04-12 18:55 - 2018-02-10 14:35 - 000031936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mssmbios.sys
2018-04-12 18:55 - 2018-02-10 14:35 - 000023744 _____ (Microsoft Corporation) C:\Windows\system32\streamci.dll
2018-04-12 18:55 - 2018-02-10 14:35 - 000020160 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\isapnp.sys
2018-04-12 18:55 - 2018-02-10 14:35 - 000015040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msisadrv.sys
2018-04-12 18:55 - 2018-02-10 14:35 - 000012096 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\swenum.sys
2018-04-12 18:55 - 2018-02-10 14:23 - 002292224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSVidCtl.dll
2018-04-12 18:55 - 2018-02-10 14:23 - 000330240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\zipfldr.dll
2018-04-12 18:55 - 2018-02-10 14:23 - 000111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\racpldlg.dll
2018-04-12 18:55 - 2018-02-10 14:11 - 003665920 _____ (Microsoft Corporation) C:\Windows\system32\MSVidCtl.dll
2018-04-12 18:55 - 2018-02-10 14:11 - 000369664 _____ (Microsoft Corporation) C:\Windows\system32\zipfldr.dll
2018-04-12 18:55 - 2018-02-10 14:11 - 000133120 _____ (Microsoft Corporation) C:\Windows\system32\msrahc.dll
2018-04-12 18:55 - 2018-02-10 14:11 - 000119296 _____ (Microsoft Corporation) C:\Windows\system32\racpldlg.dll
2018-04-12 18:55 - 2018-02-10 13:36 - 000108032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msra.exe
2018-04-12 18:55 - 2018-02-10 13:36 - 000040960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sdchange.exe
2018-04-12 18:55 - 2018-02-10 13:36 - 000007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MsraLegacy.tlb
2018-04-12 18:55 - 2018-02-10 13:26 - 000653312 _____ (Microsoft Corporation) C:\Windows\system32\msra.exe
2018-04-12 18:55 - 2018-02-10 13:26 - 000051712 _____ (Microsoft Corporation) C:\Windows\system32\sdchange.exe
2018-04-12 18:55 - 2018-02-10 13:25 - 000014336 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\wmiacpi.sys
2018-04-12 18:55 - 2018-02-10 13:25 - 000009728 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\errdev.sys
2018-04-12 18:55 - 2018-02-10 13:25 - 000007168 _____ (Microsoft Corporation) C:\Windows\system32\MsraLegacy.tlb
2018-04-12 18:55 - 2018-02-02 14:40 - 000114368 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2018-04-12 18:55 - 2018-02-02 14:29 - 002365952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2018-04-12 18:55 - 2018-02-02 14:29 - 000337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll
2018-04-12 18:55 - 2018-02-02 14:29 - 000025088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msimsg.dll
2018-04-12 18:55 - 2018-02-02 14:28 - 001806848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2018-04-12 18:55 - 2018-02-02 14:16 - 003246080 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2018-04-12 18:55 - 2018-02-02 14:16 - 000504320 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll
2018-04-12 18:55 - 2018-02-02 14:16 - 000025088 _____ (Microsoft Corporation) C:\Windows\system32\msimsg.dll
2018-04-12 18:55 - 2018-02-02 14:14 - 001942016 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2018-04-12 18:55 - 2018-02-02 14:14 - 000070144 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll
2018-04-12 18:55 - 2018-02-02 13:46 - 000073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msiexec.exe
2018-04-12 18:55 - 2018-02-02 13:36 - 000128512 _____ (Microsoft Corporation) C:\Windows\system32\msiexec.exe
2018-04-12 18:55 - 2018-01-25 10:05 - 000995272 _____ (Microsoft Corporation) C:\Windows\system32\ucrtbase.dll
2018-04-12 18:55 - 2018-01-25 10:05 - 000063832 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-private-l1-1-0.dll
2018-04-12 18:55 - 2018-01-25 10:05 - 000020824 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-math-l1-1-0.dll
2018-04-12 18:55 - 2018-01-25 10:05 - 000019800 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-multibyte-l1-1-0.dll
2018-04-12 18:55 - 2018-01-25 10:05 - 000017752 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-string-l1-1-0.dll
2018-04-12 18:55 - 2018-01-25 10:05 - 000017752 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-stdio-l1-1-0.dll
2018-04-12 18:55 - 2018-01-25 10:05 - 000016216 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-runtime-l1-1-0.dll
2018-04-12 18:55 - 2018-01-25 10:05 - 000015704 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-convert-l1-1-0.dll
2018-04-12 18:55 - 2018-01-25 10:05 - 000014168 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-time-l1-1-0.dll
2018-04-12 18:55 - 2018-01-25 10:05 - 000014168 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-2-0.dll
2018-04-12 18:55 - 2018-01-25 10:05 - 000013656 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll
2018-04-12 18:55 - 2018-01-25 10:05 - 000012632 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-process-l1-1-0.dll
2018-04-12 18:55 - 2018-01-25 10:05 - 000012632 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-heap-l1-1-0.dll
2018-04-12 18:55 - 2018-01-25 10:05 - 000012632 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-conio-l1-1-0.dll
2018-04-12 18:55 - 2018-01-25 10:05 - 000012120 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-utility-l1-1-0.dll
2018-04-12 18:55 - 2018-01-25 10:05 - 000012120 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-locale-l1-1-0.dll
2018-04-12 18:55 - 2018-01-25 10:05 - 000012120 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-environment-l1-1-0.dll
2018-04-12 18:55 - 2018-01-25 10:05 - 000012120 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-2-0.dll
2018-04-12 18:55 - 2018-01-25 10:05 - 000012120 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-1.dll
2018-04-12 18:55 - 2018-01-25 10:05 - 000011608 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l2-1-0.dll
2018-04-12 18:55 - 2018-01-25 10:05 - 000011608 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-timezone-l1-1-0.dll
2018-04-12 18:55 - 2018-01-25 10:05 - 000011608 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l2-1-0.dll
2018-04-12 18:55 - 2018-01-25 10:05 - 000011608 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-2-0.dll
2018-04-12 18:55 - 2018-01-25 10:04 - 000922944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ucrtbase.dll
2018-04-12 18:55 - 2018-01-25 10:04 - 000066392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-private-l1-1-0.dll
2018-04-12 18:55 - 2018-01-25 10:04 - 000022360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-math-l1-1-0.dll
2018-04-12 18:55 - 2018-01-25 10:04 - 000019800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-multibyte-l1-1-0.dll
2018-04-12 18:55 - 2018-01-25 10:04 - 000017752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-string-l1-1-0.dll
2018-04-12 18:55 - 2018-01-25 10:04 - 000017752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-stdio-l1-1-0.dll
2018-04-12 18:55 - 2018-01-25 10:04 - 000016216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-runtime-l1-1-0.dll
2018-04-12 18:55 - 2018-01-25 10:04 - 000015704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-convert-l1-1-0.dll
2018-04-12 18:55 - 2018-01-25 10:04 - 000014168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-time-l1-1-0.dll
2018-04-12 18:55 - 2018-01-25 10:04 - 000014168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-2-0.dll
2018-04-12 18:55 - 2018-01-25 10:04 - 000013656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-filesystem-l1-1-0.dll
2018-04-12 18:55 - 2018-01-25 10:04 - 000012632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-process-l1-1-0.dll
2018-04-12 18:55 - 2018-01-25 10:04 - 000012632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-heap-l1-1-0.dll
2018-04-12 18:55 - 2018-01-25 10:04 - 000012632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-conio-l1-1-0.dll
2018-04-12 18:55 - 2018-01-25 10:04 - 000012120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-utility-l1-1-0.dll
2018-04-12 18:55 - 2018-01-25 10:04 - 000012120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-locale-l1-1-0.dll
2018-04-12 18:55 - 2018-01-25 10:04 - 000012120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-environment-l1-1-0.dll
2018-04-12 18:55 - 2018-01-25 10:04 - 000012120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-2-0.dll
2018-04-12 18:55 - 2018-01-25 10:04 - 000012120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-1.dll
2018-04-12 18:55 - 2018-01-25 10:04 - 000011608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l2-1-0.dll
2018-04-12 18:55 - 2018-01-25 10:04 - 000011608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-timezone-l1-1-0.dll
2018-04-12 18:55 - 2018-01-25 10:04 - 000011608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l2-1-0.dll
2018-04-12 18:55 - 2018-01-25 10:04 - 000011608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-2-0.dll
2018-04-12 18:55 - 2018-01-15 15:59 - 000002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2018-04-12 18:55 - 2018-01-15 15:40 - 000002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2018-04-12 18:55 - 2018-01-12 12:44 - 001894120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2018-04-12 18:55 - 2018-01-12 12:44 - 000377064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys
2018-04-12 18:55 - 2018-01-12 12:44 - 000371432 _____ (Microsoft Corporation) C:\Windows\system32\clfs.sys
2018-04-12 18:55 - 2018-01-12 12:44 - 000287976 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS
2018-04-12 18:55 - 2018-01-12 12:40 - 000484864 _____ (Microsoft Corporation) C:\Windows\system32\StructuredQuery.dll
2018-04-12 18:55 - 2018-01-12 12:40 - 000407040 _____ (Microsoft Corporation) C:\Windows\system32\scesrv.dll
2018-04-12 18:55 - 2018-01-12 12:27 - 004834816 _____ (Microsoft Corporation) C:\Windows\system32\xpsrchvw.exe
2018-04-12 18:55 - 2018-01-12 12:26 - 000363520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\StructuredQuery.dll
2018-04-12 18:55 - 2018-01-12 12:26 - 000308224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scesrv.dll
2018-04-12 18:55 - 2018-01-12 12:16 - 003405824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xpsrchvw.exe
2018-04-12 18:55 - 2018-01-12 12:16 - 000076288 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys
2018-04-12 18:55 - 2018-01-12 12:16 - 000030208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidusb.sys
2018-04-12 18:55 - 2018-01-12 12:15 - 000032896 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys
2018-04-12 18:55 - 2018-01-11 12:41 - 001133568 _____ (Microsoft Corporation) C:\Windows\system32\cdosys.dll
2018-04-12 18:55 - 2018-01-11 12:22 - 000805376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2018-04-12 18:55 - 2017-12-31 22:21 - 001680616 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2018-04-12 18:55 - 2017-12-31 22:21 - 000948968 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys
2018-04-12 18:55 - 2017-12-31 22:21 - 000288488 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fltMgr.sys
2018-04-12 18:55 - 2017-12-31 22:21 - 000213736 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdyboost.sys
2018-04-12 18:55 - 2017-12-31 22:18 - 014183936 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2018-04-12 18:55 - 2017-12-31 22:18 - 002066432 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll
2018-04-12 18:55 - 2017-12-31 22:18 - 002004480 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2018-04-12 18:55 - 2017-12-31 22:18 - 001867776 _____ (Microsoft Corporation) C:\Windows\system32\ExplorerFrame.dll
2018-04-12 18:55 - 2017-12-31 22:18 - 001741312 _____ (Microsoft Corporation) C:\Windows\system32\sysmain.dll
2018-04-12 18:55 - 2017-12-31 22:18 - 001110528 _____ (Microsoft Corporation) C:\Windows\system32\schedsvc.dll
2018-04-12 18:55 - 2017-12-31 22:18 - 000961024 _____ (Microsoft Corporation) C:\Windows\system32\actxprxy.dll
2018-04-12 18:55 - 2017-12-31 22:18 - 000863232 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL
2018-04-12 18:55 - 2017-12-31 22:18 - 000842752 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll
2018-04-12 18:55 - 2017-12-31 22:18 - 000828928 _____ (Microsoft Corporation) C:\Windows\system32\MPSSVC.dll
2018-04-12 18:55 - 2017-12-31 22:18 - 000749568 _____ (Microsoft Corporation) C:\Windows\system32\FirewallAPI.dll
2018-04-12 18:55 - 2017-12-31 22:18 - 000705024 _____ (Microsoft Corporation) C:\Windows\system32\BFE.DLL
2018-04-12 18:55 - 2017-12-31 22:18 - 000512000 _____ (Microsoft Corporation) C:\Windows\system32\rpcss.dll
2018-04-12 18:55 - 2017-12-31 22:18 - 000473600 _____ (Microsoft Corporation) C:\Windows\system32\taskcomp.dll
2018-04-12 18:55 - 2017-12-31 22:18 - 000444928 _____ (Microsoft Corporation) C:\Windows\system32\winhttp.dll
2018-04-12 18:55 - 2017-12-31 22:18 - 000439296 _____ (Microsoft Corporation) C:\Windows\system32\p2psvc.dll
2018-04-12 18:55 - 2017-12-31 22:18 - 000366592 _____ (Microsoft Corporation) C:\Windows\system32\wcncsvc.dll
2018-04-12 18:55 - 2017-12-31 22:18 - 000327168 _____ (Microsoft Corporation) C:\Windows\system32\pnrpsvc.dll
2018-04-12 18:55 - 2017-12-31 22:18 - 000324096 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL
2018-04-12 18:55 - 2017-12-31 22:18 - 000303104 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll
2018-04-12 18:55 - 2017-12-31 22:18 - 000264704 _____ (Microsoft Corporation) C:\Windows\system32\P2P.dll
2018-04-12 18:55 - 2017-12-31 22:18 - 000223232 _____ (Microsoft Corporation) C:\Windows\system32\ncsi.dll
2018-04-12 18:55 - 2017-12-31 22:18 - 000120320 _____ (Microsoft Corporation) C:\Windows\system32\WcnApi.dll
2018-04-12 18:55 - 2017-12-31 22:18 - 000108544 _____ (Microsoft Corporation) C:\Windows\system32\icfupgd.dll
2018-04-12 18:55 - 2017-12-31 22:18 - 000101376 _____ (Microsoft Corporation) C:\Windows\system32\fdWCN.dll
2018-04-12 18:55 - 2017-12-31 22:18 - 000095744 _____ (Microsoft Corporation) C:\Windows\system32\rascfg.dll
2018-04-12 18:55 - 2017-12-31 22:18 - 000076288 _____ (Microsoft Corporation) C:\Windows\system32\rasdiag.dll
2018-04-12 18:55 - 2017-12-31 22:18 - 000070656 _____ (Microsoft Corporation) C:\Windows\system32\nlaapi.dll
2018-04-12 18:55 - 2017-12-31 22:18 - 000060928 _____ (Microsoft Corporation) C:\Windows\system32\ndptsp.tsp
2018-04-12 18:55 - 2017-12-31 22:18 - 000047104 _____ (Microsoft Corporation) C:\Windows\system32\kmddsp.tsp
2018-04-12 18:55 - 2017-12-31 22:18 - 000041472 _____ (Microsoft Corporation) C:\Windows\system32\rasmxs.dll
2018-04-12 18:55 - 2017-12-31 22:18 - 000039424 _____ (Microsoft Corporation) C:\Windows\system32\traffic.dll
2018-04-12 18:55 - 2017-12-31 22:18 - 000029696 _____ (Microsoft Corporation) C:\Windows\system32\rasser.dll
2018-04-12 18:55 - 2017-12-31 22:18 - 000026112 _____ (Microsoft Corporation) C:\Windows\system32\oleres.dll
2018-04-12 18:55 - 2017-12-31 22:18 - 000024576 _____ (Microsoft Corporation) C:\Windows\system32\WcnEapPeerProxy.dll
2018-04-12 18:55 - 2017-12-31 22:18 - 000024064 _____ (Microsoft Corporation) C:\Windows\system32\WcnEapAuthProxy.dll
2018-04-12 18:55 - 2017-12-31 22:18 - 000022528 _____ (Microsoft Corporation) C:\Windows\system32\wfapigp.dll
2018-04-12 18:55 - 2017-12-31 22:18 - 000016896 _____ (Microsoft Corporation) C:\Windows\system32\wshqos.dll
2018-04-12 18:55 - 2017-12-31 22:18 - 000013312 _____ (Microsoft Corporation) C:\Windows\system32\wshnetbs.dll
2018-04-12 18:55 - 2017-12-31 22:18 - 000008704 _____ (Microsoft Corporation) C:\Windows\system32\comcat.dll
2018-04-12 18:55 - 2017-12-31 22:18 - 000002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml6r.dll
2018-04-12 18:55 - 2017-12-31 22:04 - 000559616 _____ (Microsoft Corporation) C:\Windows\system32\spoolsv.exe
2018-04-12 18:55 - 2017-12-31 22:00 - 012880384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2018-04-12 18:55 - 2017-12-31 22:00 - 001499648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ExplorerFrame.dll
2018-04-12 18:55 - 2017-12-31 22:00 - 001417728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll
2018-04-12 18:55 - 2017-12-31 22:00 - 001390080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2018-04-12 18:55 - 2017-12-31 22:00 - 000666624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll
2018-04-12 18:55 - 2017-12-31 22:00 - 000463360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FirewallAPI.dll
2018-04-12 18:55 - 2017-12-31 22:00 - 000351744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winhttp.dll
2018-04-12 18:55 - 2017-12-31 22:00 - 000304640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\taskcomp.dll
2018-04-12 18:55 - 2017-12-31 22:00 - 000276992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wcncsvc.dll
2018-04-12 18:55 - 2017-12-31 22:00 - 000217600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\P2P.dll
2018-04-12 18:55 - 2017-12-31 22:00 - 000216576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL
2018-04-12 18:55 - 2017-12-31 22:00 - 000162304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncsi.dll
2018-04-12 18:55 - 2017-12-31 22:00 - 000081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fdWCN.dll
2018-04-12 18:55 - 2017-12-31 22:00 - 000081408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rascfg.dll
2018-04-12 18:55 - 2017-12-31 22:00 - 000061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rasdiag.dll
2018-04-12 18:55 - 2017-12-31 22:00 - 000052224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll
2018-04-12 18:55 - 2017-12-31 22:00 - 000050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ndptsp.tsp
2018-04-12 18:55 - 2017-12-31 22:00 - 000033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\traffic.dll
2018-04-12 18:55 - 2017-12-31 22:00 - 000026112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleres.dll
2018-04-12 18:55 - 2017-12-31 22:00 - 000002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6r.dll
2018-04-12 18:55 - 2017-12-31 21:59 - 000309760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\actxprxy.dll
2018-04-12 18:55 - 2017-12-31 21:55 - 000131584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\pacer.sys
2018-04-12 18:55 - 2017-12-31 21:55 - 000088576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\wanarp.sys
2018-04-12 18:55 - 2017-12-31 21:55 - 000058368 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndproxy.sys
2018-04-12 18:55 - 2017-12-31 21:55 - 000045056 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netbios.sys
2018-04-12 18:55 - 2017-12-31 21:55 - 000024064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndistapi.sys
2018-04-12 18:55 - 2017-12-31 21:54 - 000077312 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mpsdrv.sys
2018-04-12 18:55 - 2017-12-31 21:50 - 000455680 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2018-04-12 18:55 - 2017-12-31 21:43 - 000086528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WcnApi.dll
2018-04-12 18:55 - 2017-12-31 21:43 - 000038912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kmddsp.tsp
2018-04-12 18:55 - 2017-12-31 21:43 - 000033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rasmxs.dll
2018-04-12 18:55 - 2017-12-31 21:43 - 000022528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rasser.dll
2018-04-12 18:55 - 2017-12-31 21:43 - 000020480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WcnEapPeerProxy.dll
2018-04-12 18:55 - 2017-12-31 21:43 - 000019968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WcnEapAuthProxy.dll
2018-04-12 18:55 - 2017-12-31 21:43 - 000018944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wfapigp.dll
2018-04-12 18:55 - 2017-12-31 21:43 - 000013824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wshqos.dll
2018-04-12 18:55 - 2017-12-31 21:42 - 000460288 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys
2018-04-12 18:55 - 2017-12-31 21:42 - 000406016 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys
2018-04-12 18:55 - 2017-12-31 21:42 - 000168448 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys
2018-04-12 18:55 - 2017-12-31 21:41 - 000754176 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys
2018-04-12 18:55 - 2017-12-31 21:41 - 000106496 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dfsc.sys
2018-04-12 18:55 - 2017-12-31 21:41 - 000007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comcat.dll
2018-04-12 18:55 - 2017-12-05 13:36 - 001484288 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2018-04-12 18:55 - 2017-12-05 13:36 - 000625664 _____ (Microsoft Corporation) C:\Windows\system32\mscms.dll
2018-04-12 18:55 - 2017-12-05 13:36 - 000250880 _____ (Microsoft Corporation) C:\Windows\system32\icm32.dll
2018-04-12 18:55 - 2017-12-05 13:36 - 000229376 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2018-04-12 18:55 - 2017-12-05 13:36 - 000190976 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2018-04-12 18:55 - 2017-12-05 13:36 - 000141824 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2018-04-12 18:55 - 2017-12-05 13:36 - 000092160 _____ (Microsoft Corporation) C:\Windows\system32\TabSvc.dll
2018-04-12 18:55 - 2017-12-05 13:36 - 000040960 _____ (Microsoft Corporation) C:\Windows\system32\WcsPlugInService.dll
2018-04-12 18:55 - 2017-12-05 13:08 - 001176576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2018-04-12 18:55 - 2017-12-05 13:08 - 000481792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscms.dll
2018-04-12 18:55 - 2017-12-05 13:08 - 000215040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icm32.dll
2018-04-12 18:55 - 2017-12-05 13:08 - 000179200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2018-04-12 18:55 - 2017-12-05 13:08 - 000145920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2018-04-12 18:55 - 2017-12-05 13:08 - 000106496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2018-04-12 18:55 - 2017-12-05 12:04 - 000404992 _____ (Microsoft Corporation) C:\Windows\system32\wisptis.exe
2018-04-12 18:55 - 2017-12-05 11:49 - 000032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WcsPlugInService.dll
2018-04-12 18:55 - 2017-11-04 11:31 - 000194048 _____ (Microsoft Corporation) C:\Windows\system32\itircl.dll
2018-04-12 18:55 - 2017-11-04 11:31 - 000170496 _____ (Microsoft Corporation) C:\Windows\system32\itss.dll
2018-04-12 18:55 - 2017-11-04 11:10 - 000158720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\itircl.dll
2018-04-12 18:55 - 2017-11-04 11:10 - 000142336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\itss.dll
2018-04-12 18:55 - 2017-11-02 12:55 - 000281600 _____ (Microsoft Corporation) C:\Windows\system32\iprtrmgr.dll
2018-04-12 18:55 - 2017-11-02 12:55 - 000138240 _____ (Microsoft Corporation) C:\Windows\system32\rtm.dll
2018-04-12 18:55 - 2017-11-02 12:55 - 000097792 _____ (Microsoft Corporation) C:\Windows\system32\mprdim.dll
2018-04-12 18:55 - 2017-11-02 12:55 - 000009728 _____ (Microsoft Corporation) C:\Windows\system32\iprtprio.dll
2018-04-12 18:55 - 2017-11-02 11:11 - 000271360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iprtrmgr.dll
2018-04-12 18:55 - 2017-11-02 11:11 - 000115200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rtm.dll
2018-04-12 18:55 - 2017-11-02 11:11 - 000075264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mprdim.dll
2018-04-12 18:55 - 2017-11-02 10:56 - 000008192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iprtprio.dll
2018-04-12 18:55 - 2017-10-17 22:06 - 000344064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
2018-04-12 18:55 - 2017-10-17 22:06 - 000327168 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys
2018-04-12 18:55 - 2017-10-17 22:06 - 000099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys
2018-04-12 18:55 - 2017-10-17 22:06 - 000056320 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
2018-04-12 18:55 - 2017-10-17 22:06 - 000030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys
2018-04-12 18:55 - 2017-10-17 22:06 - 000025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys
2018-04-12 18:55 - 2017-10-17 22:06 - 000007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys
2018-04-12 18:55 - 2017-10-16 19:04 - 001001984 _____ (Microsoft Corporation) C:\Windows\system32\gpedit.dll
2018-04-12 18:55 - 2017-10-16 18:46 - 000953344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gpedit.dll
2018-04-12 18:55 - 2017-10-11 20:55 - 014635008 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2018-04-12 18:55 - 2017-10-11 20:55 - 012574720 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2018-04-12 18:55 - 2017-10-11 20:55 - 002319872 _____ (Microsoft Corporation) C:\Windows\system32\tquery.dll
2018-04-12 18:55 - 2017-10-11 20:55 - 002222080 _____ (Microsoft Corporation) C:\Windows\system32\mssrch.dll
2018-04-12 18:55 - 2017-10-11 20:55 - 002058240 _____ (Microsoft Corporation) C:\Windows\system32\Query.dll
2018-04-12 18:55 - 2017-10-11 20:55 - 000778240 _____ (Microsoft Corporation) C:\Windows\system32\mssvp.dll
2018-04-12 18:55 - 2017-10-11 20:55 - 000491520 _____ (Microsoft Corporation) C:\Windows\system32\mssph.dll
2018-04-12 18:55 - 2017-10-11 20:55 - 000288256 _____ (Microsoft Corporation) C:\Windows\system32\mssphtb.dll
2018-04-12 18:55 - 2017-10-11 20:55 - 000115200 _____ (Microsoft Corporation) C:\Windows\system32\mssitlb.dll
2018-04-12 18:55 - 2017-10-11 20:55 - 000099840 _____ (Microsoft Corporation) C:\Windows\system32\mssprxy.dll
2018-04-12 18:55 - 2017-10-11 20:55 - 000075264 _____ (Microsoft Corporation) C:\Windows\system32\msscntrs.dll
2018-04-12 18:55 - 2017-10-11 20:55 - 000014336 _____ (Microsoft Corporation) C:\Windows\system32\msshooks.dll
2018-04-12 18:55 - 2017-10-11 20:55 - 000009728 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll
2018-04-12 18:55 - 2017-10-11 20:55 - 000005120 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx
2018-04-12 18:55 - 2017-10-11 20:55 - 000005120 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll
2018-04-12 18:55 - 2017-10-11 20:39 - 000591872 _____ (Microsoft Corporation) C:\Windows\system32\SearchIndexer.exe
2018-04-12 18:55 - 2017-10-11 20:38 - 000249856 _____ (Microsoft Corporation) C:\Windows\system32\SearchProtocolHost.exe
2018-04-12 18:55 - 2017-10-11 20:38 - 000113664 _____ (Microsoft Corporation) C:\Windows\system32\SearchFilterHost.exe
2018-04-12 18:55 - 2017-10-11 20:37 - 012574208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL
2018-04-12 18:55 - 2017-10-11 20:37 - 011410944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2018-04-12 18:55 - 2017-10-11 20:37 - 001549824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tquery.dll
2018-04-12 18:55 - 2017-10-11 20:37 - 001400320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssrch.dll
2018-04-12 18:55 - 2017-10-11 20:37 - 001363968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Query.dll
2018-04-12 18:55 - 2017-10-11 20:37 - 000666624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssvp.dll
2018-04-12 18:55 - 2017-10-11 20:37 - 000337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssph.dll
2018-04-12 18:55 - 2017-10-11 20:37 - 000197120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssphtb.dll
2018-04-12 18:55 - 2017-10-11 20:37 - 000104448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssitlb.dll
2018-04-12 18:55 - 2017-10-11 20:37 - 000059392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msscntrs.dll
2018-04-12 18:55 - 2017-10-11 20:37 - 000034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssprxy.dll
2018-04-12 18:55 - 2017-10-11 20:26 - 000427520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchIndexer.exe
2018-04-12 18:55 - 2017-10-11 20:26 - 000164352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchProtocolHost.exe
2018-04-12 18:55 - 2017-10-11 20:25 - 000086528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchFilterHost.exe
2018-04-12 18:55 - 2017-10-11 20:25 - 000009728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msshooks.dll
2018-04-12 18:55 - 2017-10-11 20:24 - 000008192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\spwmp.dll
2018-04-12 18:55 - 2017-10-11 20:24 - 000004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdxm.ocx
2018-04-12 18:55 - 2017-10-11 20:24 - 000004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxmasf.dll
2018-04-12 18:55 - 2017-10-11 20:20 - 000317440 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdbss.sys
2018-04-12 18:55 - 2017-10-11 20:20 - 000113152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\luafv.sys
2018-04-12 18:55 - 2017-09-13 11:28 - 001068544 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll
2018-04-12 18:55 - 2017-09-13 11:28 - 000886272 _____ (Microsoft Corporation) C:\Windows\system32\wlansvc.dll
2018-04-12 18:55 - 2017-09-13 11:28 - 000448512 _____ (Microsoft Corporation) C:\Windows\system32\wlansec.dll
2018-04-12 18:55 - 2017-09-13 11:28 - 000414208 _____ (Microsoft Corporation) C:\Windows\system32\wlanmsm.dll
2018-04-12 18:55 - 2017-09-13 11:28 - 000118784 _____ (Microsoft Corporation) C:\Windows\system32\wlanhlp.dll
2018-04-12 18:55 - 2017-09-13 11:28 - 000113664 _____ (Microsoft Corporation) C:\Windows\system32\wlanapi.dll
2018-04-12 18:55 - 2017-09-13 11:09 - 000830464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msctf.dll
2018-04-12 18:55 - 2017-09-13 11:09 - 000428032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlanmsm.dll
2018-04-12 18:55 - 2017-09-13 11:09 - 000392704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlansec.dll
2018-04-12 18:55 - 2017-09-13 11:09 - 000083968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlanhlp.dll
2018-04-12 18:55 - 2017-09-13 11:09 - 000080896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wlanapi.dll
2018-04-12 18:55 - 2017-09-13 11:05 - 000324608 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\nwifi.sys
2018-04-12 18:55 - 2017-09-08 11:30 - 000405504 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2018-04-12 18:55 - 2017-09-08 11:10 - 000312832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2018-04-12 18:55 - 2017-09-08 10:20 - 000640512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswstr10.dll
2018-04-12 18:55 - 2017-09-08 10:20 - 000008704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msjint40.dll
2018-04-12 18:55 - 2017-09-07 11:31 - 002851328 _____ (Microsoft Corporation) C:\Windows\system32\themeui.dll
2018-04-12 18:55 - 2017-09-07 11:12 - 002755072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\themeui.dll
2018-04-12 18:55 - 2017-08-19 11:28 - 004121600 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2018-04-12 18:55 - 2017-08-19 11:28 - 000206848 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll
2018-04-12 18:55 - 2017-08-19 11:28 - 000197120 _____ (Microsoft Corporation) C:\Windows\system32\shdocvw.dll
2018-04-12 18:55 - 2017-08-19 11:28 - 000002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll
2018-04-12 18:55 - 2017-08-19 11:10 - 003209216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll
2018-04-12 18:55 - 2017-08-19 11:10 - 000180224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shdocvw.dll
2018-04-12 18:55 - 2017-08-19 11:10 - 000103424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfps.dll
2018-04-12 18:55 - 2017-08-19 11:10 - 000002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mferror.dll
2018-04-12 18:55 - 2017-08-19 11:08 - 000055808 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe
2018-04-12 18:55 - 2017-08-19 11:08 - 000024576 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe
2018-04-12 18:55 - 2017-08-19 10:57 - 000050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rrinstaller.exe
2018-04-12 18:55 - 2017-08-19 10:57 - 000023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfpmp.exe
2018-04-12 18:55 - 2017-08-16 11:29 - 000806912 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll
2018-04-12 18:55 - 2017-08-16 11:10 - 000629760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll
2018-04-12 18:55 - 2017-08-14 13:35 - 003203584 _____ (Microsoft Corporation) C:\Windows\system32\mmcndmgr.dll
2018-04-12 18:55 - 2017-08-14 13:35 - 002150912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mmcndmgr.dll
2018-04-12 18:55 - 2017-08-14 13:35 - 001032192 _____ (Microsoft Corporation) C:\Windows\system32\rdpcore.dll
2018-04-12 18:55 - 2017-08-14 13:35 - 000827904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpcore.dll
2018-04-12 18:55 - 2017-08-14 13:35 - 000355328 _____ (Microsoft Corporation) C:\Windows\system32\mmcbase.dll
2018-04-12 18:55 - 2017-08-14 13:35 - 000303104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mmcbase.dll
2018-04-12 18:55 - 2017-08-14 13:35 - 000172544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cic.dll
2018-04-12 18:55 - 2017-08-14 13:35 - 000131072 _____ (Microsoft Corporation) C:\Windows\system32\mmcshext.dll
2018-04-12 18:55 - 2017-08-14 13:35 - 000128512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mmcshext.dll
2018-04-12 18:55 - 2017-08-14 13:35 - 000022528 _____ (Microsoft Corporation) C:\Windows\system32\icaapi.dll
2018-04-12 18:55 - 2017-08-14 13:34 - 000211968 _____ (Microsoft Corporation) C:\Windows\system32\cic.dll
2018-04-12 18:55 - 2017-08-13 17:45 - 000040448 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
2018-04-12 18:55 - 2017-08-13 17:37 - 002144256 _____ (Microsoft Corporation) C:\Windows\system32\mmc.exe
2018-04-12 18:55 - 2017-08-13 17:30 - 001401344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mmc.exe
2018-04-12 18:55 - 2017-08-11 02:35 - 000757248 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll
2018-04-12 18:55 - 2017-08-11 02:35 - 000346112 _____ (Microsoft Corporation) C:\Windows\system32\ntprint.dll
2018-04-12 18:55 - 2017-08-11 02:35 - 000313856 _____ (Microsoft Corporation) C:\Windows\system32\Wldap32.dll
2018-04-12 18:55 - 2017-08-11 02:35 - 000026112 _____ (Microsoft Corporation) C:\Windows\system32\nsisvc.dll
2018-04-12 18:55 - 2017-08-11 02:35 - 000025600 _____ (Microsoft Corporation) C:\Windows\system32\winnsi.dll
2018-04-12 18:55 - 2017-08-11 02:35 - 000013312 _____ (Microsoft Corporation) C:\Windows\system32\nsi.dll
2018-04-12 18:55 - 2017-08-11 02:34 - 000971776 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll
2018-04-12 18:55 - 2017-08-11 02:34 - 000166400 _____ (Microsoft Corporation) C:\Windows\system32\inetpp.dll
2018-04-12 18:55 - 2017-08-11 02:34 - 000022528 _____ (Microsoft Corporation) C:\Windows\system32\inetppui.dll
2018-04-12 18:55 - 2017-08-11 02:20 - 000061952 _____ (Microsoft Corporation) C:\Windows\system32\ntprint.exe
2018-04-12 18:55 - 2017-08-11 02:20 - 000048640 _____ (Microsoft Corporation) C:\Windows\system32\wpnpinst.exe
2018-04-12 18:55 - 2017-08-11 02:19 - 000497664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll
2018-04-12 18:55 - 2017-08-11 02:19 - 000299008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntprint.dll
2018-04-12 18:55 - 2017-08-11 02:19 - 000271360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Wldap32.dll
2018-04-12 18:55 - 2017-08-11 02:19 - 000016384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winnsi.dll
2018-04-12 18:55 - 2017-08-11 02:19 - 000008704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nsi.dll
2018-04-12 18:55 - 2017-08-11 02:12 - 000025088 _____ (Microsoft Corporation) C:\Windows\system32\netbtugc.exe
2018-04-12 18:55 - 2017-08-11 02:09 - 000061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntprint.exe
2018-04-12 18:55 - 2017-08-11 02:03 - 000026624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netbtugc.exe
2018-04-12 18:55 - 2017-08-11 02:00 - 000262656 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netbt.sys
2018-04-12 18:55 - 2017-08-11 01:58 - 000026112 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\nsiproxy.sys
2018-04-12 18:55 - 2017-07-29 10:56 - 000117248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys
2018-04-12 18:55 - 2017-07-21 10:26 - 000518144 _____ C:\Windows\SysWOW64\msjetoledb40.dll
2018-04-12 18:55 - 2017-07-21 10:26 - 000409600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msexch40.dll
2018-04-12 18:55 - 2017-07-21 10:26 - 000290816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msjtes40.dll
2018-04-12 18:55 - 2017-07-21 10:26 - 000282624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstext40.dll
2018-04-12 18:55 - 2017-07-14 11:29 - 000486400 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
2018-04-12 18:55 - 2017-07-14 11:29 - 000034304 _____ (Microsoft Corporation) C:\Windows\system32\werdiagcontroller.dll
2018-04-12 18:55 - 2017-07-14 11:10 - 000382976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll
2018-04-12 18:55 - 2017-07-14 10:57 - 000050688 _____ (Microsoft Corporation) C:\Windows\system32\wermgr.exe
2018-04-12 18:55 - 2017-07-14 10:50 - 000054272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wermgr.exe
2018-04-12 18:55 - 2017-07-14 10:50 - 000028672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\werdiagcontroller.dll
2018-04-12 18:55 - 2017-07-07 11:33 - 000363752 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\volmgrx.sys
2018-04-12 18:55 - 2017-07-07 11:29 - 001143296 _____ (Microsoft Corporation) C:\Windows\system32\DXPTaskRingtone.dll
2018-04-12 18:55 - 2017-07-07 11:10 - 000973312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DXPTaskRingtone.dll
2018-04-12 18:55 - 2017-07-01 09:05 - 001311744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msjet40.dll
2018-04-12 18:55 - 2017-07-01 09:05 - 000866816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswdat10.dll
2018-04-12 18:55 - 2017-07-01 09:05 - 000616448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrepl40.dll
2018-04-12 18:55 - 2017-07-01 09:05 - 000475648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxbde40.dll
2018-04-12 18:55 - 2017-07-01 09:05 - 000375808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mspbde40.dll
2018-04-12 18:55 - 2017-07-01 09:05 - 000343552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrd3x40.dll
2018-04-12 18:55 - 2017-07-01 09:05 - 000310272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrd2x40.dll
2018-04-12 18:55 - 2017-07-01 09:05 - 000240640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msltus40.dll
2018-04-12 18:55 - 2017-07-01 09:05 - 000083968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msjter40.dll
2018-04-12 18:44 - 2018-03-14 13:14 - 000135360 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe
2018-04-12 18:44 - 2018-03-14 13:09 - 000656384 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2018-04-12 18:44 - 2018-03-14 09:05 - 001993728 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe
2018-04-12 18:44 - 2018-03-14 09:05 - 001559552 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2018-04-12 18:44 - 2018-03-14 09:05 - 000739840 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2018-04-12 18:44 - 2018-03-14 09:05 - 000599552 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2018-04-12 18:44 - 2018-03-14 09:05 - 000450048 _____ (Microsoft Corporation) C:\Windows\system32\centel.dll
2018-04-12 18:44 - 2018-03-14 09:05 - 000414720 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2018-04-12 18:44 - 2018-03-14 09:05 - 000291840 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2018-04-12 18:44 - 2018-03-14 09:05 - 000237056 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2018-04-12 16:19 - 2018-04-13 09:13 - 000003634 _____ C:\Windows\System32\Tasks\WizMouse
2018-04-07 16:27 - 2018-04-07 16:27 - 000001409 _____ C:\Windows\QTFont.for
2018-04-03 16:23 - 2018-04-03 16:27 - 000000000 ____D C:\8b86d66ed5fdc1c4b784ccbf
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2018-04-26 10:11 - 2009-07-13 22:34 - 021233664 _____ C:\Windows\system32\config\HARDWARE
2018-04-26 10:06 - 2014-12-09 16:11 - 000000000 ____D C:\Program Files\SoftEther VPN Client
2018-04-26 09:15 - 2014-05-21 15:55 - 136971704 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2018-04-26 09:02 - 2009-07-14 00:45 - 000018928 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2018-04-26 09:02 - 2009-07-14 00:45 - 000018928 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2018-04-26 08:34 - 2014-07-19 19:27 - 000000000 ____D C:\ProgramData\Aimersoft Video Converter Ultimate
2018-04-26 08:27 - 2016-03-16 20:40 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Deluge
2018-04-26 08:27 - 2014-06-02 13:41 - 000000000 ____D C:\Program Files (x86)\Deluge
2018-04-25 19:19 - 2014-05-11 09:56 - 000000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2018-04-25 19:16 - 2009-07-13 23:20 - 000000000 ____D C:\Windows\inf
2018-04-25 17:31 - 2009-07-14 01:13 - 001027272 _____ C:\Windows\system32\PerfStringBackup.INI
2018-04-25 17:29 - 2016-07-21 11:22 - 000001105 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VAIO Update.lnk
2018-04-25 17:22 - 2009-07-14 01:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2018-04-25 16:49 - 2016-07-02 14:01 - 000001908 _____ C:\Windows\diagwrn.xml
2018-04-25 16:49 - 2016-07-02 14:01 - 000001908 _____ C:\Windows\diagerr.xml
2018-04-25 16:28 - 2009-07-13 23:20 - 000000000 ____D C:\Windows\registration
2018-04-25 16:18 - 2014-06-22 03:15 - 000000000 ____D C:\Users\Guest
2018-04-25 16:02 - 2014-05-11 01:07 - 000000000 ____D C:\Windows\Panther
2018-04-25 15:51 - 2015-02-19 21:06 - 000000000 ____D C:\Windows\Minidump
2018-04-25 15:51 - 2014-05-11 00:08 - 000300770 ____N C:\Windows\Minidump\042518-53586-01.dmp
2018-04-25 15:03 - 2014-05-11 00:08 - 000300898 ____N C:\Windows\Minidump\042518-50559-01.dmp
2018-04-25 14:18 - 2014-06-28 09:48 - 000000000 ____D C:\Program Files\AntiMalwareApps
2018-04-25 13:36 - 2014-05-21 23:15 - 000000000 ____D C:\ProgramData\Malwarebytes
2018-04-25 10:59 - 2014-05-22 21:27 - 000000000 ____D C:\Users\Administrator
2018-04-23 19:44 - 2009-07-14 00:45 - 005102016 _____ C:\Windows\system32\FNTCACHE.DAT
2018-04-23 19:38 - 2014-05-11 00:08 - 000300898 ____N C:\Windows\Minidump\042318-80246-01.dmp
2018-04-23 19:34 - 2009-07-13 23:20 - 000000000 ____D C:\Windows\SysWOW64\Setup
2018-04-23 19:33 - 2015-04-17 11:41 - 000000000 ____D C:\Windows\system32\appraiser
2018-04-23 19:33 - 2009-07-13 23:20 - 000000000 ____D C:\Windows\system32\Setup
2018-04-23 18:53 - 2014-06-16 15:49 - 000000000 ____D C:\ProgramData\WinZip
2018-04-23 18:25 - 2009-07-13 19:29 - 008338432 _____ (Microsoft Corporation) C:\Windows\system32\spwizimg.dll
2018-04-23 18:13 - 2015-05-23 09:32 - 000000000 ____D C:\ProgramData\Unchecky
2018-04-23 18:13 - 2014-07-02 15:25 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PeaZip
2018-04-23 18:13 - 2014-07-02 15:25 - 000000000 ____D C:\Program Files\PeaZip
2018-04-23 18:07 - 2009-07-13 22:34 - 000000477 _____ C:\Windows\win.ini
2018-04-23 15:36 - 2014-05-11 00:08 - 000300194 ____N C:\Windows\Minidump\042318-43165-01.dmp
2018-04-23 13:53 - 2014-05-11 00:08 - 000300770 ____N C:\Windows\Minidump\042318-33181-01.dmp
2018-04-23 12:43 - 2014-05-11 00:17 - 000000000 ____D C:\Users\New User
2018-04-23 12:42 - 2016-12-26 13:58 - 000000000 ____D C:\Users\New User\AppData\Roaming\Kodi
2018-04-23 12:42 - 2014-05-11 09:58 - 000000000 ____D C:\Users\New User\AppData\Roaming\Adobe
2018-04-23 12:17 - 2009-07-14 00:57 - 000001547 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2018-04-23 12:10 - 2014-05-11 00:08 - 000300770 ____N C:\Windows\Minidump\042318-58781-01.dmp
2018-04-23 10:57 - 2014-05-11 00:08 - 000300770 ____N C:\Windows\Minidump\042318-32900-01.dmp
2018-04-23 09:49 - 2014-05-22 21:28 - 000091136 _____ C:\Users\Administrator\AppData\Local\GDIPFONTCACHEV1.DAT
2018-04-22 20:36 - 2014-05-11 00:08 - 000300194 ____N C:\Windows\Minidump\042218-45037-01.dmp
2018-04-22 19:54 - 2014-05-11 00:08 - 000300770 ____N C:\Windows\Minidump\042218-52151-01.dmp
2018-04-22 18:50 - 2014-05-11 00:08 - 000300770 ____N C:\Windows\Minidump\042218-154815-01.dmp
2018-04-22 08:05 - 2014-05-22 10:47 - 000000000 ____D C:\Program Files (x86)\Adobe
2018-04-22 07:22 - 2014-05-11 00:08 - 000300770 ____N C:\Windows\Minidump\042218-79700-01.dmp
2018-04-22 07:02 - 2014-05-11 00:08 - 000300770 ____N C:\Windows\Minidump\042218-148684-01.dmp
2018-04-21 22:13 - 2014-05-11 00:08 - 000300770 ____N C:\Windows\Minidump\042118-30170-01.dmp
2018-04-21 22:09 - 2015-02-26 16:38 - 000000000 ____D C:\Windows\pss
2018-04-21 21:42 - 2014-05-11 00:08 - 000300770 ____N C:\Windows\Minidump\042118-28204-01.dmp
2018-04-21 21:36 - 2014-05-11 00:08 - 000300770 ____N C:\Windows\Minidump\042118-32417-01.dmp
2018-04-21 21:24 - 2014-05-11 00:08 - 000300770 ____N C:\Windows\Minidump\042118-40248-01.dmp
2018-04-21 20:52 - 2015-11-14 22:18 - 000054053 _____ C:\Windows\ZAM.krnl.trace
2018-04-21 20:52 - 2015-11-14 22:18 - 000053404 _____ C:\Windows\ZAM_Guard.krnl.trace
2018-04-14 16:14 - 2009-07-13 23:20 - 000000000 ____D C:\Windows\rescache
2018-04-13 16:12 - 2014-05-24 17:41 - 000000000 ____D C:\Update
2018-04-13 14:45 - 2014-05-11 07:58 - 000000021 _____ C:\Windows\Model.txt
2018-04-13 14:34 - 2014-11-16 17:58 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\JBidwatcher
2018-04-13 14:34 - 2014-11-16 17:58 - 000000000 ____D C:\Program Files (x86)\CyberFOX Software
2018-04-13 09:37 - 2014-05-22 21:28 - 000000000 ____D C:\Users\Administrator\AppData\Local\Google
2018-04-12 19:06 - 2014-05-____D C:\Windows\system32\MRT
2018-04-12 16:55 - 2015-03-27 21:29 - 000028272 _____ C:\Windows\system32\Drivers\TrueSight.sys
2018-04-12 16:54 - 2015-03-27 21:29 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RogueKiller
2018-04-12 16:18 - 2009-07-14 01:09 - 000000000 ____D C:\Windows\System32\Tasks\WPD
2018-04-07 16:27 - 2015-02-27 16:44 - 000054156 ____H C:\Windows\QTFont.qfn
2018-04-04 14:18 - 2014-05-31 09:31 - 000000564 _____ C:\Windows\WORDPAD.INI
2018-04-03 16:23 - 2015-01-24 17:40 - 000000000 ____D C:\Program Files (x86)\TurboTax
2018-04-01 10:39 - 2009-07-14 01:08 - 000032646 _____ C:\Windows\Tasks\SCHEDLGU.TXT
==================== Files in the root of some directories =======
2018-04-13 11:51 - 2018-04-12 14:25 - 005767168 _____ () C:\Users\2018Jean\ntuser (2).dat
2014-05-30 23:00 - 2014-05-30 23:00 - 000001705 _____ () C:\Program Files\Add-Take-Ownership-Option.zip
2015-03-07 17:48 - 2015-03-07 17:49 - 002913497 _____ (Saru Software®) C:\Program Files\Clock.exe
2014-05-22 18:47 - 2008-03-27 19:45 - 000480768 _____ (Pablo Software Solutions) C:\Program Files\FTPWanderer.exe
2015-02-26 16:51 - 2015-02-02 14:13 - 001388274 _____ (Thisisu) C:\Program Files\JRT_NEW.exe
2008-08-10 13:09 - 2008-08-10 13:09 - 001083904 _____ (Squared 5) C:\Program Files\MPEG_Streamclip.exe
2014-09-24 16:15 - 2007-04-20 00:35 - 000118784 _____ (Jeff Key) C:\Program Files\Ruler.exe
2013-08-26 11:55 - 2013-08-26 11:55 - 007665437 _____ (SerialBox Windows) C:\Program Files\SerialBox Windows V0.1.5 Portable.exe
2014-05-22 19:35 - 2014-06-02 13:19 - 000000481 _____ () C:\Program Files\sites.xml
2015-10-25 12:11 - 2015-10-25 12:11 - 000000900 _____ () C:\Program Files (x86)\Adobe Spare dll file - Shortcut.lnk
2012-08-19 12:35 - 2012-08-19 12:35 - 000899584 _____ (Squared 5) C:\Program Files (x86)\MPEG_Streamclip.exe
2016-07-08 12:09 - 2016-07-08 16:17 - 021737496 _____ (LastPass) C:\Program Files (x86)\Common Files\lpuninstall.exe
2018-04-13 06:45 - 2018-04-13 06:45 - 004279968 _____ (NeoSoft Tools ) C:\Users\2018Jean\AppData\Roaming\ctask.exe
2018-04-25 18:30 - 2018-04-25 18:30 - 000001456 _____ () C:\Users\2018Jean\AppData\Local\Adobe Save for Web 13.0 Prefs
2018-04-24 16:27 - 2018-04-24 16:27 - 000001245 _____ () C:\Users\2018Jean\AppData\Local\recently-used.xbel
2018-04-21 17:02 - 2018-04-21 17:02 - 000051200 _____ () C:\Users\2018Jean\AppData\Local\Slighting.exe
2018-04-21 17:02 - 2018-04-21 17:02 - 000051200 _____ () C:\Users\2018Jean\AppData\Local\undermining.exe
Some files in TEMP:
====================
2018-04-13 14:45 - 2010-06-20 22:42 - 000046456 _____ (Sony Electronics, Inc) C:\Users\2018Jean\AppData\Local\Temp\GLF7121.EXE
2018-04-13 14:45 - 2003-05-02 15:13 - 000151552 _____ () C:\Users\2018Jean\AppData\Local\Temp\GLF7612.EXE
2018-04-13 14:03 - 2018-04-13 14:03 - 000116997 _____ () C:\Users\2018Jean\AppData\Local\Temp\jffi2511343256368944750.dll
2018-04-23 17:38 - 2018-04-23 17:38 - 014769392 _____ () C:\Users\2018Jean\AppData\Local\Temp\ReimagePackage.exe
2018-01-11 12:21 - 2018-01-11 12:21 - 778536164 _____ () C:\Users\2018Jean\AppData\Local\Temp\setup.dll
2018-04-22 07:18 - 2003-03-24 18:50 - 000098304 _____ (Adobe Systems Inc.) C:\Users\2018Jean\AppData\Local\Temp\UninstManager.dll
2018-04-13 14:34 - 2018-04-13 14:34 - 000503808 _____ () C:\Users\2018Jean\AppData\Local\Temp\xuninst.exe
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
C:\Windows\system32\drivers\dwrpswzc.sys -> Access Denied <======= ATTENTION
LastRegBack: 2018-04-19 14:59
==================== End of FRST.txt ============================ 21 15:55
[ P.S. I am so amazed that you are willing to provide help as volunteers. I live in a very small town and am a long way away from professional help that would be hard to afford right now. Whether or not you can walk me through resolving the problems, I am very appreciative of your effort.
Last edited by a moderator: