rebeccavalentine
Active member
- Oct 19, 2016
- 33
I have very little knowledge about malware, virus & stuff. I run win7 professional with avast free anti virus & comodo firewall. I run other on demand scanners once a week just to check if everything is fine. But my laptop has started behaving kind of weird off late. It was faster some 5-6 months ago when i clean installed win. & also sometimes when i open google chrome i just get a blank blue screen & nothing else. these being a few of the changes that i could recall. & also as i am one who watches tv shows online, I often come across various ads which seem highly suspicious, & i have to close them before i can view the episodes. so i highly suspect that my security has been compromised.
If anyone could kindly help me out with this, I would be highly grateful. Thanks in advance.
Ive posted all the three logs from FRST & security analysis as instructed in the forum.
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 17-10-2016
Ran by Rebecca (administrator) on REBECCA-PC (19-10-2016 19:37:10)
Running from C:\Users\Rebecca\Downloads\Programs & setup files
Loaded Profiles: Rebecca (Available Profiles: Rebecca)
Platform: Windows 7 Professional Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 8 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: FRST Tutorial - How to use Farbar Recovery Scan Tool - Malware Removal Guides and Tutorials
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae-svc.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae64.exe
(Sony Corporation) C:\Program Files (x86)\Sony\VAIO Control Center\VESMgr.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Sony Corporation) C:\Program Files (x86)\Sony\VAIO Control Center\VESMgrSub.exe
(Sony Corporation) C:\Program Files (x86)\Sony\VAIO Control Center\VESMgrSub.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation) C:\Windows\SysWOW64\dllhost.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\CisTray.exe
(Microsoft Corporation) C:\Windows\SysWOW64\dllhost.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cavwp.exe
(Sony Corporation) C:\Program Files (x86)\Sony\VAIO Control Center\VESGfxMgr.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cis.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
() C:\Program Files\Intel\SUR\WILLAMETTE\ESRV\esrv_svc.exe
() C:\Users\Rebecca\Desktop\Programs\Caps.exe
() C:\Users\Rebecca\Desktop\Programs\Copy.exe
() C:\Users\Rebecca\Desktop\Programs\Copycontents.exe
() C:\Users\Rebecca\Desktop\Programs\dashlane.exe
() C:\Users\Rebecca\Desktop\Programs\Downloads.exe
() C:\Users\Rebecca\Desktop\Programs\FavSongs.exe
() C:\Users\Rebecca\Desktop\Programs\Google.exe
() C:\Users\Rebecca\Desktop\Programs\Hidemedia1.exe
() C:\Users\Rebecca\Desktop\Programs\LibreOffice.exe
() C:\Users\Rebecca\Desktop\Programs\Notepad.exe
() C:\Users\Rebecca\Desktop\Programs\Paint.exe
() C:\Users\Rebecca\Desktop\Programs\Recycle.exe
() C:\Users\Rebecca\Desktop\Programs\Song.exe
() C:\Users\Rebecca\Desktop\Programs\Text1.exe
() C:\Users\Rebecca\Desktop\Programs\Tutorial.exe
(The Document Foundation) C:\Program Files (x86)\LibreOffice 5\program\swriter.exe
(The Document Foundation) C:\Program Files (x86)\LibreOffice 5\program\soffice.exe
(The Document Foundation) C:\Program Files (x86)\LibreOffice 5\program\soffice.bin
(Dashlane, Inc.) C:\Users\Rebecca\AppData\Roaming\Dashlane\Dashlane.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
() C:\Users\Rebecca\AppData\Roaming\Dashlane\DashlanePlugin.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Tonec Inc.) C:\Program Files (x86)\Internet Download Manager\IDMan.exe
(Tonec Inc.) C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [COMODO Internet Security] => C:\Program Files\COMODO\COMODO Internet Security\cistray.exe [1610936 2016-09-14] (COMODO)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [9083840 2016-10-13] (AVAST Software)
HKLM-x32\...\Run: [Malwarebytes Anti-Exploit] => C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae.exe [2631120 2016-07-28] (Malwarebytes Corporation)
HKLM-x32\...\Run: [] => [X]
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
ShellIconOverlayIdentifiers: [ IDM Shell Extension] -> {CDC95B92-E27C-4745-A8C5-64A52A78855D} => C:\Program Files (x86)\Internet Download Manager\IDMShellExt64.dll [2015-08-14] (Tonec Inc.)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2016-08-31] (AVAST Software)
BootExecute: autocheck autochk * sdnclean64.exe
GroupPolicy: Restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 192.168.1.1
Tcpip\..\Interfaces\{C061FCE4-9BBA-4CD5-B06B-0DE55D0FD626}: [DhcpNameServer] 192.168.1.1 192.168.1.1
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page =
BHO: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files (x86)\Internet Download Manager\IDMIECC64.dll [2015-12-08] (Internet Download Manager, Tonec Inc.)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2016-08-31] (AVAST Software)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO-x32: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll [2015-12-08] (Internet Download Manager, Tonec Inc.)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2016-08-31] (AVAST Software)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
DPF: HKLM-x32 {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} hxxp://catalog.update.microsoft.com/v7/site/ClientControl/en/x86/MuCatalogWebControl.cab?1466243251918
Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2010-11-21] (Microsoft Corporation)
Filter-x32: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2010-11-21] (Microsoft Corporation)
Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2010-11-21] (Microsoft Corporation)
Filter-x32: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2010-11-21] (Microsoft Corporation)
FireFox:
========
FF DefaultProfile: keurpdol.default
FF ProfilePath: C:\Users\Rebecca\AppData\Roaming\Mozilla\Firefox\Profiles\keurpdol.default [2016-10-15]
FF Extension: (IDM integration) - C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpi [2016-06-08]
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: (Avast Online Security) - C:\Program Files\AVAST Software\Avast\WebRep\FF [2016-08-31]
FF HKLM\...\Firefox\Extensions: [sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF
FF Extension: (Avast SafePrice) - C:\Program Files\AVAST Software\Avast\SafePrice\FF [2016-08-31]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF HKLM-x32\...\Firefox\Extensions: [sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF
FF HKU\S-1-5-21-2346135004-3240251215-1620024443-1000\...\Firefox\Extensions: [mozilla_cc2@internetdownloadmanager.com] - C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpi
FF HKU\S-1-5-21-2346135004-3240251215-1620024443-1000\...\SeaMonkey\Extensions: [mozilla_cc@internetdownloadmanager.com] - C:\Users\Rebecca\AppData\Roaming\IDM\idmmzcc5
FF Extension: (IDM CC) - C:\Users\Rebecca\AppData\Roaming\IDM\idmmzcc5 [2016-10-19] [not signed]
FF HKU\S-1-5-21-2346135004-3240251215-1620024443-1000\...\SeaMonkey\Extensions: [mozilla_cc2@internetdownloadmanager.com] - C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpi
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2015-12-18] ()
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-29] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-29] (Google Inc.)
Chrome:
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\Rebecca\AppData\Local\Google\Chrome\User Data\Default [2016-10-19]
CHR Extension: (Google Slides) - C:\Users\Rebecca\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-06-18]
CHR Extension: (Queen Elsa of Arendelle - Frozen) - C:\Users\Rebecca\AppData\Local\Google\Chrome\User Data\Default\Extensions\andadcipdpeombhjneecehpogbbjomij [2016-06-18]
CHR Extension: (Google Docs) - C:\Users\Rebecca\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-06-18]
CHR Extension: (Google Drive) - C:\Users\Rebecca\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-06-18]
CHR Extension: (YouTube) - C:\Users\Rebecca\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-06-18]
CHR Extension: (Avast SafePrice) - C:\Users\Rebecca\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck [2016-09-13]
CHR Extension: (Dashlane) - C:\Users\Rebecca\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdjamakpfbbddfjaooikfcpapjohcfmg [2016-10-02]
CHR Extension: (Google Sheets) - C:\Users\Rebecca\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-06-18]
CHR Extension: (Google Docs Offline) - C:\Users\Rebecca\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-06-18]
CHR Extension: (Avast Online Security) - C:\Users\Rebecca\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2016-06-29]
CHR Extension: (IDM Integration Module) - C:\Users\Rebecca\AppData\Local\Google\Chrome\User Data\Default\Extensions\ngpampappnmepgilojfohadhhmbhlaek [2016-10-01]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Rebecca\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-06-18]
CHR Extension: (Gmail) - C:\Users\Rebecca\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-06-18]
CHR Extension: (Chrome Media Router) - C:\Users\Rebecca\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-09-24]
CHR Profile: C:\Users\Rebecca\AppData\Local\Google\Chrome\User Data\Guest Profile [2016-10-05]
CHR Profile: C:\Users\Rebecca\AppData\Local\Google\Chrome\User Data\Profile 2 [2016-10-09]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Rebecca\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-08-06]
CHR Extension: (Chrome Media Router) - C:\Users\Rebecca\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-09-28]
CHR Profile: C:\Users\Rebecca\AppData\Local\Google\Chrome\User Data\System Profile [2016-10-09]
CHR HKLM\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2016-06-09]
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2016-06-09]
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S4 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [172344 2014-07-23] (SUPERAntiSpyware.com)
S4 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2016-03-02] (Apple Inc.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [197128 2016-08-31] (AVAST Software)
R2 CmdAgent; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [5817256 2016-09-15] (COMODO)
R3 cmdvirth; C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe [2271928 2016-09-14] (COMODO)
R2 ESRV_SVC_WILLAMETTE; C:\Program Files\Intel\SUR\WILLAMETTE\ESRV\esrv_svc.exe [416408 2016-03-09] ()
R2 MbaeSvc; C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae-svc.exe [750032 2016-07-28] (Malwarebytes Corporation)
S4 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2012-01-04] ()
S4 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1738168 2014-06-24] (Safer-Networking Ltd.)
S4 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [4088608 2016-09-21] (Safer-Networking Ltd.)
S4 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2014-04-25] (Safer-Networking Ltd.)
S4 SystemUsageReportSvc_WILLAMETTE; C:\Program Files (x86)\Intel Driver Update Utility\SUR\SurSvc.exe [118424 2016-03-09] ()
S4 USER_ESRV_SVC_WILLAMETTE; C:\Program Files\Intel\SUR\WILLAMETTE\ESRV\esrv_svc.exe [416408 2016-03-09] ()
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [37656 2016-08-31] (AVAST Software)
R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [37144 2016-08-31] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [108816 2016-08-31] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [103064 2016-08-31] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [74544 2016-08-31] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [969184 2016-09-14] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [513632 2016-09-23] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [163416 2016-08-31] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [293352 2016-10-13] (AVAST Software)
R1 cmderd; C:\Windows\System32\DRIVERS\cmderd.sys [31648 2016-08-31] (COMODO)
R1 cmdGuard; C:\Windows\System32\DRIVERS\cmdguard.sys [830624 2016-08-31] (COMODO)
R1 cmdHlp; C:\Windows\System32\DRIVERS\cmdhlp.sys [56976 2016-08-31] (COMODO)
S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-11] (Broadcom Corporation)
R1 ESProtectionDriver; C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae64.sys [74984 2016-07-28] ()
R1 FNETURPX; C:\Windows\System32\drivers\FNETURPX.SYS [16648 2016-06-20] (FNet Co., Ltd.)
R1 FNETVDDA; C:\Windows\System32\drivers\FNETVDDA.SYS [37128 2016-06-20] (FNet Co., Ltd.)
U5 gobi3kserial; C:\Windows\System32\Drivers\gobi3kserial.sys [233984 2010-12-13] (QUALCOMM Incorporated)
R1 inspect; C:\Windows\System32\DRIVERS\inspect.sys [116248 2016-08-31] (COMODO)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-13] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R3 semav6msr64; C:\Windows\system32\drivers\semav6msr64.sys [21984 2016-03-09] ()
S3 TrufosAlt; C:\Windows\System32\DRIVERS\TrufosAlt.sys [390776 2016-09-30] (BitDefender S.R.L.)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-10-19 19:36 - 2016-10-19 19:37 - 00000000 ____D C:\FRST
2016-10-19 18:16 - 2016-10-19 18:16 - 00000000 ____D C:\SFCFix
2016-10-19 18:13 - 2016-10-19 18:16 - 00000000 ____D C:\Users\Rebecca\AppData\Local\niemiro
2016-10-12 22:42 - 2016-10-12 22:42 - 05548264 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2016-10-12 22:42 - 2016-10-12 22:42 - 04000488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2016-10-12 22:42 - 2016-10-12 22:42 - 03944680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2016-10-12 22:42 - 2016-10-12 22:42 - 03649536 _____ (Microsoft Corporation) C:\Windows\system32\MSVidCtl.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 03218944 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2016-10-12 22:42 - 2016-10-12 22:42 - 02291712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSVidCtl.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 01732864 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 01648128 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 01465344 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 01314112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 01251328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 01212928 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 01180160 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00976896 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00880640 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00741888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00730624 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00706280 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2016-10-12 22:42 - 2016-10-12 22:42 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00666112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00644096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00631176 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2016-10-12 22:42 - 2016-10-12 22:42 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00463872 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00419840 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00345600 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2016-10-12 22:42 - 2016-10-12 22:42 - 00316416 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2016-10-12 22:42 - 2016-10-12 22:42 - 00291328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2016-10-12 22:42 - 2016-10-12 22:42 - 00275456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00263680 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00260608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00254464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00215552 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00208896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebClnt.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00159744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2016-10-12 22:42 - 2016-10-12 22:42 - 00154856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2016-10-12 22:42 - 2016-10-12 22:42 - 00148480 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2016-10-12 22:42 - 2016-10-12 22:42 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00142336 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2016-10-12 22:42 - 2016-10-12 22:42 - 00141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2016-10-12 22:42 - 2016-10-12 22:42 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2016-10-12 22:42 - 2016-10-12 22:42 - 00108544 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00107520 _____ (Microsoft Corporation) C:\Windows\system32\adsmsext.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00106496 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dfsc.sys
2016-10-12 22:42 - 2016-10-12 22:42 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00095464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2016-10-12 22:42 - 2016-10-12 22:42 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\davclnt.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00084480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\INETRES.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00084480 _____ (Microsoft Corporation) C:\Windows\system32\INETRES.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00076800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adsmsext.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2016-10-12 22:42 - 2016-10-12 22:42 - 00063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2016-10-12 22:42 - 2016-10-12 22:42 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00059904 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2016-10-12 22:42 - 2016-10-12 22:42 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00034816 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2016-10-12 22:42 - 2016-10-12 22:42 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2016-10-12 22:42 - 2016-10-12 22:42 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2016-10-12 22:42 - 2016-10-12 22:42 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2016-10-12 22:42 - 2016-10-12 22:42 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2016-10-12 22:41 - 2016-09-13 02:47 - 00077032 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe
2016-10-12 22:41 - 2016-09-13 02:38 - 01226752 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2016-10-12 22:41 - 2016-09-09 21:24 - 01629184 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2016-10-12 22:41 - 2016-09-09 21:24 - 00586752 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2016-10-12 22:41 - 2016-09-09 21:24 - 00575488 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2016-10-12 22:41 - 2016-09-09 21:24 - 00314368 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2016-10-12 22:41 - 2016-09-09 21:24 - 00273408 _____ (Microsoft Corporation) C:\Windows\system32\centel.dll
2016-10-12 22:41 - 2016-09-09 21:24 - 00224256 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2016-10-12 22:41 - 2016-09-09 21:24 - 00129024 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2016-10-08 04:37 - 2016-10-08 04:37 - 00003142 _____ C:\Windows\System32\Tasks\HIbernate
2016-10-07 12:28 - 2016-10-07 12:28 - 00000000 ____D C:\Program Files\AutoHotkey
2016-10-07 12:15 - 2016-10-07 12:15 - 00001034 _____ C:\Users\Public\Desktop\Revo Uninstaller.lnk
2016-10-07 12:15 - 2016-10-07 12:15 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller
2016-10-07 12:15 - 2016-10-07 12:15 - 00000000 ____D C:\Program Files\VS Revo Group
2016-10-07 11:50 - 2016-10-08 12:10 - 00000512 _____ C:\Users\Rebecca\Documents\MBR.dat
2016-10-06 21:11 - 2016-10-06 21:11 - 00000000 ___HD C:\VTRoot
2016-10-05 00:45 - 2016-10-05 00:45 - 00000000 ____D C:\ProgramData\Comodo Downloader
2016-10-05 00:09 - 2016-10-05 00:13 - 00000000 ____D C:\Users\Rebecca\AppData\Roaming\Comodo
2016-10-04 23:12 - 2016-10-19 19:19 - 00016856 _____ C:\Windows\system32\Drivers\fvstore.dat
2016-10-04 23:01 - 2016-10-04 23:01 - 00001870 _____ C:\Users\Public\Desktop\COMODO Firewall.lnk
2016-10-04 23:01 - 2016-10-04 23:01 - 00000000 ____D C:\Windows\System32\Tasks\COMODO
2016-10-04 22:59 - 2016-10-04 23:07 - 00000000 ____D C:\Program Files\COMODO
2016-10-04 22:59 - 2016-10-04 23:06 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\COMODO
2016-10-04 22:58 - 2016-10-05 00:09 - 00000000 ____D C:\ProgramData\Comodo
2016-10-04 22:58 - 2016-10-04 22:58 - 00000000 ____D C:\ProgramData\Shared Space
2016-10-04 19:56 - 2016-10-04 19:56 - 00000000 ____D C:\Users\Rebecca\AppData\Local\Wokhan
2016-10-04 19:46 - 2016-10-04 19:46 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
2016-10-04 19:46 - 2016-10-04 19:46 - 00000000 ____D C:\Program Files\7-Zip
2016-10-04 00:32 - 2016-04-16 12:48 - 06517356 _____ C:\Users\Rebecca\Downloads\Saviour.mp4
2016-10-03 01:43 - 2016-10-07 12:28 - 00000000 ____D C:\Windows\ShellNew
2016-10-02 14:23 - 2016-10-02 14:24 - 00000000 ____D C:\Users\Rebecca\AppData\LocalLow\Dashlane
2016-10-02 14:20 - 2016-10-02 14:23 - 00000000 ____D C:\Users\Rebecca\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dashlane
2016-10-02 14:20 - 2016-10-02 14:23 - 00000000 ____D C:\Users\Rebecca\AppData\Roaming\Dashlane
2016-10-02 14:20 - 2016-10-02 14:23 - 00000000 ____D C:\Program Files (x86)\Dashlane
2016-10-02 14:20 - 2016-10-02 14:20 - 00000000 ____D C:\Users\Rebecca\AppData\Local\Packages
2016-10-02 12:45 - 2016-10-08 12:10 - 00004318 _____ C:\Users\Rebecca\Documents\aswMBR.txt
2016-10-01 23:23 - 2016-10-01 23:23 - 00001897 _____ C:\Users\Public\Desktop\HitmanPro.lnk
2016-10-01 23:07 - 2016-10-01 23:23 - 00000000 ____D C:\Program Files\HitmanPro
2016-10-01 22:46 - 2016-10-02 02:08 - 00000000 ____D C:\ProgramData\HitmanPro
2016-09-30 22:46 - 2016-09-30 22:46 - 00001613 _____ C:\Users\Rebecca\Desktop\BDUSBImmunizerLauncher.lnk
2016-09-30 22:31 - 2016-09-30 22:31 - 00003362 _____ C:\Windows\System32\Tasks\BDRemovalTool
2016-09-30 22:20 - 2016-09-30 22:20 - 00390776 _____ (BitDefender S.R.L.) C:\Windows\system32\Drivers\TrufosAlt.sys
2016-09-30 07:46 - 2016-09-30 07:46 - 00000000 ____D C:\Users\Rebecca\AppData\Local\fontconfig
2016-09-30 07:43 - 2016-09-30 07:43 - 00000000 ____D C:\Users\Rebecca\Documents\FormatFactory
2016-09-29 22:43 - 2016-09-29 22:43 - 00001071 _____ C:\Users\Rebecca\Desktop\Format Factory.lnk
2016-09-29 22:43 - 2016-09-29 22:43 - 00000000 ____D C:\Users\Rebecca\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FormatFactory
2016-09-29 22:42 - 2016-09-29 22:43 - 00000000 ____D C:\Program Files (x86)\FormatFactory
2016-09-25 16:24 - 2016-09-25 16:24 - 00000000 ____D C:\Users\Rebecca\AppData\Roaming\PotPlayerMini64
2016-09-25 16:20 - 2016-09-25 16:20 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Daum
2016-09-25 16:20 - 2016-09-25 16:20 - 00000000 ____D C:\Program Files\DAUM
2016-09-24 16:13 - 2016-09-24 16:22 - 00000618 __RSH C:\ProgramData\ntuser.pol
2016-09-24 15:49 - 2016-08-12 22:32 - 14632960 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2016-09-24 15:49 - 2016-08-12 22:32 - 12574720 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2016-09-24 15:49 - 2016-08-12 22:32 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll
2016-09-24 15:49 - 2016-08-12 22:32 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx
2016-09-24 15:49 - 2016-08-12 22:32 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll
2016-09-24 15:49 - 2016-08-12 22:17 - 12574208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL
2016-09-24 15:49 - 2016-08-12 22:17 - 11410432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2016-09-24 15:49 - 2016-08-12 22:01 - 00008192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\spwmp.dll
2016-09-24 15:49 - 2016-08-12 22:01 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdxm.ocx
2016-09-24 15:49 - 2016-08-12 22:01 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxmasf.dll
2016-09-24 15:49 - 2016-08-12 21:56 - 00461312 _____ (Microsoft Corporation) C:\Windows\system32\scavengeui.dll
2016-09-24 15:49 - 2016-08-06 21:01 - 02023424 _____ (Microsoft Corporation) C:\Windows\system32\WsmSvc.dll
2016-09-24 15:49 - 2016-08-06 21:01 - 00347136 _____ (Microsoft Corporation) C:\Windows\system32\WSManMigrationPlugin.dll
2016-09-24 15:49 - 2016-08-06 21:01 - 00310784 _____ (Microsoft Corporation) C:\Windows\system32\WsmWmiPl.dll
2016-09-24 15:49 - 2016-08-06 21:01 - 00182272 _____ (Microsoft Corporation) C:\Windows\system32\WsmAuto.dll
2016-09-24 15:49 - 2016-08-06 21:01 - 00054272 _____ (Microsoft Corporation) C:\Windows\system32\WsmRes.dll
2016-09-24 15:49 - 2016-08-06 21:01 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\wsmplpxy.dll
2016-09-24 15:49 - 2016-08-06 20:45 - 01178112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmSvc.dll
2016-09-24 15:49 - 2016-08-06 20:45 - 00249344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManMigrationPlugin.dll
2016-09-24 15:49 - 2016-08-06 20:45 - 00214016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmWmiPl.dll
2016-09-24 15:49 - 2016-08-06 20:45 - 00146944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmAuto.dll
2016-09-24 15:49 - 2016-08-06 20:45 - 00054272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmRes.dll
2016-09-24 15:49 - 2016-08-06 20:31 - 00266752 _____ (Microsoft Corporation) C:\Windows\system32\WSManHTTPConfig.exe
2016-09-24 15:49 - 2016-08-06 20:31 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\wsmprovhost.exe
2016-09-24 15:49 - 2016-08-06 20:23 - 00199168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManHTTPConfig.exe
2016-09-24 15:49 - 2016-08-06 20:23 - 00012288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wsmprovhost.exe
2016-09-24 15:49 - 2016-08-06 20:23 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wsmplpxy.dll
2016-09-24 15:49 - 2016-06-14 22:51 - 00094440 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mountmgr.sys
2016-09-24 15:49 - 2016-06-14 22:46 - 04121600 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2016-09-24 15:49 - 2016-06-14 22:46 - 01573888 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll
2016-09-24 15:49 - 2016-06-14 22:46 - 01483264 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2016-09-24 15:49 - 2016-06-14 22:46 - 01202176 _____ (Microsoft Corporation) C:\Windows\system32\drmv2clt.dll
2016-09-24 15:49 - 2016-06-14 22:46 - 01068544 _____ (Microsoft Corporation) C:\Windows\system32\cryptui.dll
2016-09-24 15:49 - 2016-06-14 22:46 - 00842240 _____ (Microsoft Corporation) C:\Windows\system32\blackbox.dll
2016-09-24 15:49 - 2016-06-14 22:46 - 00782848 _____ (Microsoft Corporation) C:\Windows\system32\wmdrmsdk.dll
2016-09-24 15:49 - 2016-06-14 22:46 - 00680448 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
2016-09-24 15:49 - 2016-06-14 22:46 - 00641024 _____ (Microsoft Corporation) C:\Windows\system32\msscp.dll
2016-09-24 15:49 - 2016-06-14 22:46 - 00632320 _____ (Microsoft Corporation) C:\Windows\system32\evr.dll
2016-09-24 15:49 - 2016-06-14 22:46 - 00499712 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll
2016-09-24 15:49 - 2016-06-14 22:46 - 00497664 _____ (Microsoft Corporation) C:\Windows\system32\drmmgrtn.dll
2016-09-24 15:49 - 2016-06-14 22:46 - 00440320 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll
2016-09-24 15:49 - 2016-06-14 22:46 - 00433152 _____ (Microsoft Corporation) C:\Windows\system32\mfplat.dll
2016-09-24 15:49 - 2016-06-14 22:46 - 00371712 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll
2016-09-24 15:49 - 2016-06-14 22:46 - 00325632 _____ (Microsoft Corporation) C:\Windows\system32\msnetobj.dll
2016-09-24 15:49 - 2016-06-14 22:46 - 00295936 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll
2016-09-24 15:49 - 2016-06-14 22:46 - 00284672 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll
2016-09-24 15:49 - 2016-06-14 22:46 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2016-09-24 15:49 - 2016-06-14 22:46 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll
2016-09-24 15:49 - 2016-06-14 22:46 - 00190976 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2016-09-24 15:49 - 2016-06-14 22:46 - 00187904 _____ (Microsoft Corporation) C:\Windows\system32\pcasvc.dll
2016-09-24 15:49 - 2016-06-14 22:46 - 00141824 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2016-09-24 15:49 - 2016-06-14 22:46 - 00081920 _____ (Microsoft Corporation) C:\Windows\system32\cryptsp.dll
2016-09-24 15:49 - 2016-06-14 22:46 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\pcadm.dll
2016-09-24 15:49 - 2016-06-14 22:46 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\msmmsp.dll
2016-09-24 15:49 - 2016-06-14 22:46 - 00008704 _____ (Microsoft Corporation) C:\Windows\system32\pcaevts.dll
2016-09-24 15:49 - 2016-06-14 22:46 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll
2016-09-24 15:49 - 2016-06-14 22:41 - 00663552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\PEAuth.sys
2016-09-24 15:49 - 2016-06-14 20:51 - 03209216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll
2016-09-24 15:49 - 2016-06-14 20:51 - 01329664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quartz.dll
2016-09-24 15:49 - 2016-06-14 20:51 - 01176064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2016-09-24 15:49 - 2016-06-14 20:51 - 01005056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptui.dll
2016-09-24 15:49 - 2016-06-14 20:51 - 00988160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drmv2clt.dll
2016-09-24 15:49 - 2016-06-14 20:51 - 00744960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\blackbox.dll
2016-09-24 15:49 - 2016-06-14 20:51 - 00617984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmdrmsdk.dll
2016-09-24 15:49 - 2016-06-14 20:51 - 00519680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll
2016-09-24 15:49 - 2016-06-14 20:51 - 00504320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msscp.dll
2016-09-24 15:49 - 2016-06-14 20:51 - 00489984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\evr.dll
2016-09-24 15:49 - 2016-06-14 20:51 - 00442368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AUDIOKSE.dll
2016-09-24 15:49 - 2016-06-14 20:51 - 00406016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drmmgrtn.dll
2016-09-24 15:49 - 2016-06-14 20:51 - 00374784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll
2016-09-24 15:49 - 2016-06-14 20:51 - 00354816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfplat.dll
2016-09-24 15:49 - 2016-06-14 20:51 - 00265216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msnetobj.dll
2016-09-24 15:49 - 2016-06-14 20:51 - 00195072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll
2016-09-24 15:49 - 2016-06-14 20:51 - 00179200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2016-09-24 15:49 - 2016-06-14 20:51 - 00145920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2016-09-24 15:49 - 2016-06-14 20:51 - 00106496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2016-09-24 15:49 - 2016-06-14 20:51 - 00103424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfps.dll
2016-09-24 15:49 - 2016-06-14 20:51 - 00080896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsp.dll
2016-09-24 15:49 - 2016-06-14 20:51 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mferror.dll
2016-09-24 15:49 - 2016-06-14 20:45 - 00125952 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe
2016-09-24 15:49 - 2016-06-14 20:45 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe
2016-09-24 15:49 - 2016-06-14 20:45 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe
2016-09-24 15:49 - 2016-06-14 20:35 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rrinstaller.exe
2016-09-24 15:49 - 2016-06-14 20:35 - 00023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfpmp.exe
2016-09-24 15:49 - 2016-06-14 20:30 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\pcawrk.exe
2016-09-24 15:49 - 2016-06-14 20:30 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\pcalua.exe
2016-09-24 15:24 - 2016-08-29 21:01 - 14183424 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2016-09-24 15:24 - 2016-08-29 21:01 - 01941504 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2016-09-24 15:24 - 2016-08-29 21:01 - 01867776 _____ (Microsoft Corporation) C:\Windows\system32\ExplorerFrame.dll
2016-09-24 15:24 - 2016-08-29 20:42 - 12880384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2016-09-24 15:24 - 2016-08-29 20:42 - 01806848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2016-09-24 15:24 - 2016-08-29 20:42 - 01499648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ExplorerFrame.dll
2016-09-24 15:24 - 2016-08-29 20:34 - 03229696 _____ (Microsoft Corporation) C:\Windows\explorer.exe
2016-09-24 15:24 - 2016-08-29 20:25 - 02972672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe
2016-09-24 15:24 - 2016-08-17 02:10 - 00343552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
2016-09-24 15:24 - 2016-08-17 02:10 - 00327168 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys
2016-09-24 15:24 - 2016-08-17 02:10 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys
2016-09-24 15:24 - 2016-08-17 02:10 - 00056320 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
2016-09-24 15:24 - 2016-08-17 02:10 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys
2016-09-24 15:24 - 2016-08-17 02:10 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys
2016-09-24 15:24 - 2016-08-17 02:10 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys
2016-09-23 00:25 - 2016-08-05 21:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2016-09-23 00:25 - 2016-08-05 20:43 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-10-19 19:37 - 2016-06-18 15:21 - 00000000 ____D C:\Users\Rebecca\Downloads\Programs & setup files
2016-10-19 19:09 - 2009-07-14 10:15 - 00021904 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-10-19 19:09 - 2009-07-14 10:15 - 00021904 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-10-19 19:05 - 2009-07-14 10:43 - 00924636 _____ C:\Windows\system32\PerfStringBackup.INI
2016-10-19 19:05 - 2009-07-14 08:50 - 00000000 ____D C:\Windows\inf
2016-10-19 19:04 - 2016-06-18 02:40 - 00000000 ____D C:\ProgramData\Malwarebytes Anti-Exploit
2016-10-19 18:59 - 2016-06-18 02:23 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-10-19 18:59 - 2009-07-14 10:38 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-10-19 18:53 - 2016-07-13 04:10 - 00047784 _____ C:\Users\Rebecca\Downloads\text.txt
2016-10-19 18:41 - 2016-06-18 02:23 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-10-19 18:21 - 2016-06-23 06:37 - 00000000 ____D C:\Users\Rebecca\AppData\Local\ElevatedDiagnostics
2016-10-19 17:58 - 2016-06-18 15:43 - 00000000 ____D C:\Users\Rebecca\AppData\Roaming\DMCache
2016-10-19 03:42 - 2016-06-18 02:22 - 00004180 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2016-10-15 17:06 - 2016-06-18 15:55 - 00000000 ____D C:\Users\Rebecca\AppData\Roaming\vlc
2016-10-14 17:54 - 2009-07-14 08:50 - 00000000 ____D C:\Windows\rescache
2016-10-14 03:17 - 2016-09-15 12:57 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2016-10-14 03:17 - 2016-09-15 01:05 - 00000000 ____D C:\Users\Rebecca\Desktop\mbar
2016-10-14 03:17 - 2016-06-26 23:03 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2016-10-14 02:42 - 2016-06-18 02:17 - 00109272 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys
2016-10-13 15:35 - 2016-06-18 14:43 - 00000000 ____D C:\Users\Rebecca\AppData\Local\JDownloader v2.0
2016-10-13 13:46 - 2009-07-14 08:50 - 00000000 ____D C:\Windows\system32\NDF
2016-10-13 13:30 - 2016-06-18 02:22 - 00293352 _____ (AVAST Software) C:\Windows\system32\Drivers\aswvmm.sys
2016-10-13 12:08 - 2009-07-14 10:15 - 00315760 _____ C:\Windows\system32\FNTCACHE.DAT
2016-10-13 12:06 - 2016-06-24 22:22 - 00000000 ___SD C:\Windows\system32\CompatTel
2016-10-13 12:06 - 2016-06-24 22:22 - 00000000 ____D C:\Windows\system32\appraiser
2016-10-12 22:51 - 2016-06-23 00:12 - 00000000 ____D C:\Windows\system32\MRT
2016-10-12 22:44 - 2016-06-23 00:12 - 143495576 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2016-10-07 23:29 - 2016-04-24 05:32 - 00000000 ____D C:\Users\Rebecca\Downloads\My Stuff
2016-10-06 19:46 - 2015-08-14 20:53 - 00000000 ____D C:\Users\Rebecca\Downloads\Texts
2016-10-05 00:45 - 2016-06-18 01:00 - 00069832 _____ C:\Users\Rebecca\AppData\Local\GDIPFONTCACHEV1.DAT
2016-10-05 00:44 - 2016-08-18 19:21 - 00000000 ____D C:\Windows\system32\appmgmt
2016-10-04 21:29 - 2016-06-18 01:45 - 00000000 ____D C:\Windows\System32\Tasks\Sony Corporation
2016-10-04 21:29 - 2016-06-18 01:45 - 00000000 ____D C:\Program Files\Sony
2016-10-04 01:12 - 2016-08-25 23:02 - 00000000 ____D C:\Users\Rebecca\Downloads\Pics
2016-10-04 01:09 - 2016-08-05 18:42 - 00000000 ____D C:\Users\Rebecca\Downloads\IT
2016-10-04 00:51 - 2016-06-18 02:43 - 00000000 ____D C:\Windows\pss
2016-10-04 00:35 - 2016-07-06 23:40 - 00000000 ____D C:\Users\Rebecca\Downloads\Songs & christian videos
2016-10-03 19:54 - 2016-06-18 14:36 - 00000000 ____D C:\Program Files\WinRAR
2016-10-01 19:36 - 2016-06-18 02:27 - 00003894 _____ C:\Windows\System32\Tasks\SafeZone scheduled Autoupdate 1466197035
2016-09-29 17:03 - 2009-07-14 08:50 - 00000000 ____D C:\Windows\tracing
2016-09-26 13:56 - 2016-07-03 19:43 - 00000000 ___HD C:\Program Files And Folders
2016-09-24 16:36 - 2016-09-15 15:04 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
2016-09-24 16:12 - 2009-07-14 08:50 - 00000000 ___HD C:\Windows\system32\GroupPolicy
2016-09-24 15:51 - 2009-07-14 08:50 - 00000000 ____D C:\Windows\SysWOW64\Dism
2016-09-24 15:51 - 2009-07-14 08:50 - 00000000 ____D C:\Windows\system32\Dism
2016-09-24 15:31 - 2016-06-18 02:13 - 00774404 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2016-09-23 00:33 - 2016-06-18 02:22 - 00513632 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys
2016-09-20 21:26 - 2016-09-15 14:26 - 00000000 ____D C:\Program Files\SUPERAntiSpyware
==================== Files in the root of some directories =======
2016-07-20 21:04 - 2016-07-20 21:04 - 0000057 _____ () C:\ProgramData\Ament.ini
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2016-10-15 00:43
==================== End of FRST.txt ============================
If anyone could kindly help me out with this, I would be highly grateful. Thanks in advance.
Ive posted all the three logs from FRST & security analysis as instructed in the forum.
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 17-10-2016
Ran by Rebecca (administrator) on REBECCA-PC (19-10-2016 19:37:10)
Running from C:\Users\Rebecca\Downloads\Programs & setup files
Loaded Profiles: Rebecca (Available Profiles: Rebecca)
Platform: Windows 7 Professional Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 8 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: FRST Tutorial - How to use Farbar Recovery Scan Tool - Malware Removal Guides and Tutorials
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae-svc.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae64.exe
(Sony Corporation) C:\Program Files (x86)\Sony\VAIO Control Center\VESMgr.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Sony Corporation) C:\Program Files (x86)\Sony\VAIO Control Center\VESMgrSub.exe
(Sony Corporation) C:\Program Files (x86)\Sony\VAIO Control Center\VESMgrSub.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation) C:\Windows\SysWOW64\dllhost.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\CisTray.exe
(Microsoft Corporation) C:\Windows\SysWOW64\dllhost.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cavwp.exe
(Sony Corporation) C:\Program Files (x86)\Sony\VAIO Control Center\VESGfxMgr.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cis.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
() C:\Program Files\Intel\SUR\WILLAMETTE\ESRV\esrv_svc.exe
() C:\Users\Rebecca\Desktop\Programs\Caps.exe
() C:\Users\Rebecca\Desktop\Programs\Copy.exe
() C:\Users\Rebecca\Desktop\Programs\Copycontents.exe
() C:\Users\Rebecca\Desktop\Programs\dashlane.exe
() C:\Users\Rebecca\Desktop\Programs\Downloads.exe
() C:\Users\Rebecca\Desktop\Programs\FavSongs.exe
() C:\Users\Rebecca\Desktop\Programs\Google.exe
() C:\Users\Rebecca\Desktop\Programs\Hidemedia1.exe
() C:\Users\Rebecca\Desktop\Programs\LibreOffice.exe
() C:\Users\Rebecca\Desktop\Programs\Notepad.exe
() C:\Users\Rebecca\Desktop\Programs\Paint.exe
() C:\Users\Rebecca\Desktop\Programs\Recycle.exe
() C:\Users\Rebecca\Desktop\Programs\Song.exe
() C:\Users\Rebecca\Desktop\Programs\Text1.exe
() C:\Users\Rebecca\Desktop\Programs\Tutorial.exe
(The Document Foundation) C:\Program Files (x86)\LibreOffice 5\program\swriter.exe
(The Document Foundation) C:\Program Files (x86)\LibreOffice 5\program\soffice.exe
(The Document Foundation) C:\Program Files (x86)\LibreOffice 5\program\soffice.bin
(Dashlane, Inc.) C:\Users\Rebecca\AppData\Roaming\Dashlane\Dashlane.exe
(COMODO) C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
() C:\Users\Rebecca\AppData\Roaming\Dashlane\DashlanePlugin.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Tonec Inc.) C:\Program Files (x86)\Internet Download Manager\IDMan.exe
(Tonec Inc.) C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [COMODO Internet Security] => C:\Program Files\COMODO\COMODO Internet Security\cistray.exe [1610936 2016-09-14] (COMODO)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [9083840 2016-10-13] (AVAST Software)
HKLM-x32\...\Run: [Malwarebytes Anti-Exploit] => C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae.exe [2631120 2016-07-28] (Malwarebytes Corporation)
HKLM-x32\...\Run: [] => [X]
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
ShellIconOverlayIdentifiers: [ IDM Shell Extension] -> {CDC95B92-E27C-4745-A8C5-64A52A78855D} => C:\Program Files (x86)\Internet Download Manager\IDMShellExt64.dll [2015-08-14] (Tonec Inc.)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2016-08-31] (AVAST Software)
BootExecute: autocheck autochk * sdnclean64.exe
GroupPolicy: Restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 192.168.1.1
Tcpip\..\Interfaces\{C061FCE4-9BBA-4CD5-B06B-0DE55D0FD626}: [DhcpNameServer] 192.168.1.1 192.168.1.1
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page =
BHO: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files (x86)\Internet Download Manager\IDMIECC64.dll [2015-12-08] (Internet Download Manager, Tonec Inc.)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2016-08-31] (AVAST Software)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO-x32: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll [2015-12-08] (Internet Download Manager, Tonec Inc.)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2016-08-31] (AVAST Software)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
DPF: HKLM-x32 {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} hxxp://catalog.update.microsoft.com/v7/site/ClientControl/en/x86/MuCatalogWebControl.cab?1466243251918
Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2010-11-21] (Microsoft Corporation)
Filter-x32: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2010-11-21] (Microsoft Corporation)
Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2010-11-21] (Microsoft Corporation)
Filter-x32: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2010-11-21] (Microsoft Corporation)
FireFox:
========
FF DefaultProfile: keurpdol.default
FF ProfilePath: C:\Users\Rebecca\AppData\Roaming\Mozilla\Firefox\Profiles\keurpdol.default [2016-10-15]
FF Extension: (IDM integration) - C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpi [2016-06-08]
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: (Avast Online Security) - C:\Program Files\AVAST Software\Avast\WebRep\FF [2016-08-31]
FF HKLM\...\Firefox\Extensions: [sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF
FF Extension: (Avast SafePrice) - C:\Program Files\AVAST Software\Avast\SafePrice\FF [2016-08-31]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF HKLM-x32\...\Firefox\Extensions: [sp@avast.com] - C:\Program Files\AVAST Software\Avast\SafePrice\FF
FF HKU\S-1-5-21-2346135004-3240251215-1620024443-1000\...\Firefox\Extensions: [mozilla_cc2@internetdownloadmanager.com] - C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpi
FF HKU\S-1-5-21-2346135004-3240251215-1620024443-1000\...\SeaMonkey\Extensions: [mozilla_cc@internetdownloadmanager.com] - C:\Users\Rebecca\AppData\Roaming\IDM\idmmzcc5
FF Extension: (IDM CC) - C:\Users\Rebecca\AppData\Roaming\IDM\idmmzcc5 [2016-10-19] [not signed]
FF HKU\S-1-5-21-2346135004-3240251215-1620024443-1000\...\SeaMonkey\Extensions: [mozilla_cc2@internetdownloadmanager.com] - C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpi
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2015-12-18] ()
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-29] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-29] (Google Inc.)
Chrome:
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\Rebecca\AppData\Local\Google\Chrome\User Data\Default [2016-10-19]
CHR Extension: (Google Slides) - C:\Users\Rebecca\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-06-18]
CHR Extension: (Queen Elsa of Arendelle - Frozen) - C:\Users\Rebecca\AppData\Local\Google\Chrome\User Data\Default\Extensions\andadcipdpeombhjneecehpogbbjomij [2016-06-18]
CHR Extension: (Google Docs) - C:\Users\Rebecca\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-06-18]
CHR Extension: (Google Drive) - C:\Users\Rebecca\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-06-18]
CHR Extension: (YouTube) - C:\Users\Rebecca\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-06-18]
CHR Extension: (Avast SafePrice) - C:\Users\Rebecca\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck [2016-09-13]
CHR Extension: (Dashlane) - C:\Users\Rebecca\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdjamakpfbbddfjaooikfcpapjohcfmg [2016-10-02]
CHR Extension: (Google Sheets) - C:\Users\Rebecca\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-06-18]
CHR Extension: (Google Docs Offline) - C:\Users\Rebecca\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-06-18]
CHR Extension: (Avast Online Security) - C:\Users\Rebecca\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2016-06-29]
CHR Extension: (IDM Integration Module) - C:\Users\Rebecca\AppData\Local\Google\Chrome\User Data\Default\Extensions\ngpampappnmepgilojfohadhhmbhlaek [2016-10-01]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Rebecca\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-06-18]
CHR Extension: (Gmail) - C:\Users\Rebecca\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-06-18]
CHR Extension: (Chrome Media Router) - C:\Users\Rebecca\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-09-24]
CHR Profile: C:\Users\Rebecca\AppData\Local\Google\Chrome\User Data\Guest Profile [2016-10-05]
CHR Profile: C:\Users\Rebecca\AppData\Local\Google\Chrome\User Data\Profile 2 [2016-10-09]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Rebecca\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-08-06]
CHR Extension: (Chrome Media Router) - C:\Users\Rebecca\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-09-28]
CHR Profile: C:\Users\Rebecca\AppData\Local\Google\Chrome\User Data\System Profile [2016-10-09]
CHR HKLM\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2016-06-09]
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2016-06-09]
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S4 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [172344 2014-07-23] (SUPERAntiSpyware.com)
S4 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2016-03-02] (Apple Inc.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [197128 2016-08-31] (AVAST Software)
R2 CmdAgent; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [5817256 2016-09-15] (COMODO)
R3 cmdvirth; C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe [2271928 2016-09-14] (COMODO)
R2 ESRV_SVC_WILLAMETTE; C:\Program Files\Intel\SUR\WILLAMETTE\ESRV\esrv_svc.exe [416408 2016-03-09] ()
R2 MbaeSvc; C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae-svc.exe [750032 2016-07-28] (Malwarebytes Corporation)
S4 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2012-01-04] ()
S4 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1738168 2014-06-24] (Safer-Networking Ltd.)
S4 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [4088608 2016-09-21] (Safer-Networking Ltd.)
S4 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2014-04-25] (Safer-Networking Ltd.)
S4 SystemUsageReportSvc_WILLAMETTE; C:\Program Files (x86)\Intel Driver Update Utility\SUR\SurSvc.exe [118424 2016-03-09] ()
S4 USER_ESRV_SVC_WILLAMETTE; C:\Program Files\Intel\SUR\WILLAMETTE\ESRV\esrv_svc.exe [416408 2016-03-09] ()
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [37656 2016-08-31] (AVAST Software)
R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [37144 2016-08-31] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [108816 2016-08-31] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [103064 2016-08-31] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [74544 2016-08-31] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [969184 2016-09-14] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [513632 2016-09-23] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [163416 2016-08-31] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [293352 2016-10-13] (AVAST Software)
R1 cmderd; C:\Windows\System32\DRIVERS\cmderd.sys [31648 2016-08-31] (COMODO)
R1 cmdGuard; C:\Windows\System32\DRIVERS\cmdguard.sys [830624 2016-08-31] (COMODO)
R1 cmdHlp; C:\Windows\System32\DRIVERS\cmdhlp.sys [56976 2016-08-31] (COMODO)
S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-11] (Broadcom Corporation)
R1 ESProtectionDriver; C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae64.sys [74984 2016-07-28] ()
R1 FNETURPX; C:\Windows\System32\drivers\FNETURPX.SYS [16648 2016-06-20] (FNet Co., Ltd.)
R1 FNETVDDA; C:\Windows\System32\drivers\FNETVDDA.SYS [37128 2016-06-20] (FNet Co., Ltd.)
U5 gobi3kserial; C:\Windows\System32\Drivers\gobi3kserial.sys [233984 2010-12-13] (QUALCOMM Incorporated)
R1 inspect; C:\Windows\System32\DRIVERS\inspect.sys [116248 2016-08-31] (COMODO)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-13] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R3 semav6msr64; C:\Windows\system32\drivers\semav6msr64.sys [21984 2016-03-09] ()
S3 TrufosAlt; C:\Windows\System32\DRIVERS\TrufosAlt.sys [390776 2016-09-30] (BitDefender S.R.L.)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-10-19 19:36 - 2016-10-19 19:37 - 00000000 ____D C:\FRST
2016-10-19 18:16 - 2016-10-19 18:16 - 00000000 ____D C:\SFCFix
2016-10-19 18:13 - 2016-10-19 18:16 - 00000000 ____D C:\Users\Rebecca\AppData\Local\niemiro
2016-10-12 22:42 - 2016-10-12 22:42 - 05548264 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2016-10-12 22:42 - 2016-10-12 22:42 - 04000488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2016-10-12 22:42 - 2016-10-12 22:42 - 03944680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2016-10-12 22:42 - 2016-10-12 22:42 - 03649536 _____ (Microsoft Corporation) C:\Windows\system32\MSVidCtl.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 03218944 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2016-10-12 22:42 - 2016-10-12 22:42 - 02291712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSVidCtl.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 01732864 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 01648128 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 01465344 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 01314112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 01251328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 01212928 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 01180160 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00976896 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00880640 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00741888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00730624 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00706280 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2016-10-12 22:42 - 2016-10-12 22:42 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00666112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00644096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00631176 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2016-10-12 22:42 - 2016-10-12 22:42 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00463872 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00419840 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00345600 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2016-10-12 22:42 - 2016-10-12 22:42 - 00316416 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2016-10-12 22:42 - 2016-10-12 22:42 - 00291328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2016-10-12 22:42 - 2016-10-12 22:42 - 00275456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00263680 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00260608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00254464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00215552 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00208896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebClnt.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00159744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2016-10-12 22:42 - 2016-10-12 22:42 - 00154856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2016-10-12 22:42 - 2016-10-12 22:42 - 00148480 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2016-10-12 22:42 - 2016-10-12 22:42 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00142336 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2016-10-12 22:42 - 2016-10-12 22:42 - 00141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2016-10-12 22:42 - 2016-10-12 22:42 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2016-10-12 22:42 - 2016-10-12 22:42 - 00108544 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00107520 _____ (Microsoft Corporation) C:\Windows\system32\adsmsext.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00106496 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dfsc.sys
2016-10-12 22:42 - 2016-10-12 22:42 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00095464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2016-10-12 22:42 - 2016-10-12 22:42 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\davclnt.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00084480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\INETRES.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00084480 _____ (Microsoft Corporation) C:\Windows\system32\INETRES.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00076800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adsmsext.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2016-10-12 22:42 - 2016-10-12 22:42 - 00063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2016-10-12 22:42 - 2016-10-12 22:42 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00059904 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2016-10-12 22:42 - 2016-10-12 22:42 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00034816 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2016-10-12 22:42 - 2016-10-12 22:42 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2016-10-12 22:42 - 2016-10-12 22:42 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2016-10-12 22:42 - 2016-10-12 22:42 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2016-10-12 22:42 - 2016-10-12 22:42 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2016-10-12 22:42 - 2016-10-12 22:42 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2016-10-12 22:41 - 2016-09-13 02:47 - 00077032 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe
2016-10-12 22:41 - 2016-09-13 02:38 - 01226752 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2016-10-12 22:41 - 2016-09-09 21:24 - 01629184 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2016-10-12 22:41 - 2016-09-09 21:24 - 00586752 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2016-10-12 22:41 - 2016-09-09 21:24 - 00575488 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2016-10-12 22:41 - 2016-09-09 21:24 - 00314368 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2016-10-12 22:41 - 2016-09-09 21:24 - 00273408 _____ (Microsoft Corporation) C:\Windows\system32\centel.dll
2016-10-12 22:41 - 2016-09-09 21:24 - 00224256 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2016-10-12 22:41 - 2016-09-09 21:24 - 00129024 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2016-10-08 04:37 - 2016-10-08 04:37 - 00003142 _____ C:\Windows\System32\Tasks\HIbernate
2016-10-07 12:28 - 2016-10-07 12:28 - 00000000 ____D C:\Program Files\AutoHotkey
2016-10-07 12:15 - 2016-10-07 12:15 - 00001034 _____ C:\Users\Public\Desktop\Revo Uninstaller.lnk
2016-10-07 12:15 - 2016-10-07 12:15 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller
2016-10-07 12:15 - 2016-10-07 12:15 - 00000000 ____D C:\Program Files\VS Revo Group
2016-10-07 11:50 - 2016-10-08 12:10 - 00000512 _____ C:\Users\Rebecca\Documents\MBR.dat
2016-10-06 21:11 - 2016-10-06 21:11 - 00000000 ___HD C:\VTRoot
2016-10-05 00:45 - 2016-10-05 00:45 - 00000000 ____D C:\ProgramData\Comodo Downloader
2016-10-05 00:09 - 2016-10-05 00:13 - 00000000 ____D C:\Users\Rebecca\AppData\Roaming\Comodo
2016-10-04 23:12 - 2016-10-19 19:19 - 00016856 _____ C:\Windows\system32\Drivers\fvstore.dat
2016-10-04 23:01 - 2016-10-04 23:01 - 00001870 _____ C:\Users\Public\Desktop\COMODO Firewall.lnk
2016-10-04 23:01 - 2016-10-04 23:01 - 00000000 ____D C:\Windows\System32\Tasks\COMODO
2016-10-04 22:59 - 2016-10-04 23:07 - 00000000 ____D C:\Program Files\COMODO
2016-10-04 22:59 - 2016-10-04 23:06 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\COMODO
2016-10-04 22:58 - 2016-10-05 00:09 - 00000000 ____D C:\ProgramData\Comodo
2016-10-04 22:58 - 2016-10-04 22:58 - 00000000 ____D C:\ProgramData\Shared Space
2016-10-04 19:56 - 2016-10-04 19:56 - 00000000 ____D C:\Users\Rebecca\AppData\Local\Wokhan
2016-10-04 19:46 - 2016-10-04 19:46 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
2016-10-04 19:46 - 2016-10-04 19:46 - 00000000 ____D C:\Program Files\7-Zip
2016-10-04 00:32 - 2016-04-16 12:48 - 06517356 _____ C:\Users\Rebecca\Downloads\Saviour.mp4
2016-10-03 01:43 - 2016-10-07 12:28 - 00000000 ____D C:\Windows\ShellNew
2016-10-02 14:23 - 2016-10-02 14:24 - 00000000 ____D C:\Users\Rebecca\AppData\LocalLow\Dashlane
2016-10-02 14:20 - 2016-10-02 14:23 - 00000000 ____D C:\Users\Rebecca\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dashlane
2016-10-02 14:20 - 2016-10-02 14:23 - 00000000 ____D C:\Users\Rebecca\AppData\Roaming\Dashlane
2016-10-02 14:20 - 2016-10-02 14:23 - 00000000 ____D C:\Program Files (x86)\Dashlane
2016-10-02 14:20 - 2016-10-02 14:20 - 00000000 ____D C:\Users\Rebecca\AppData\Local\Packages
2016-10-02 12:45 - 2016-10-08 12:10 - 00004318 _____ C:\Users\Rebecca\Documents\aswMBR.txt
2016-10-01 23:23 - 2016-10-01 23:23 - 00001897 _____ C:\Users\Public\Desktop\HitmanPro.lnk
2016-10-01 23:07 - 2016-10-01 23:23 - 00000000 ____D C:\Program Files\HitmanPro
2016-10-01 22:46 - 2016-10-02 02:08 - 00000000 ____D C:\ProgramData\HitmanPro
2016-09-30 22:46 - 2016-09-30 22:46 - 00001613 _____ C:\Users\Rebecca\Desktop\BDUSBImmunizerLauncher.lnk
2016-09-30 22:31 - 2016-09-30 22:31 - 00003362 _____ C:\Windows\System32\Tasks\BDRemovalTool
2016-09-30 22:20 - 2016-09-30 22:20 - 00390776 _____ (BitDefender S.R.L.) C:\Windows\system32\Drivers\TrufosAlt.sys
2016-09-30 07:46 - 2016-09-30 07:46 - 00000000 ____D C:\Users\Rebecca\AppData\Local\fontconfig
2016-09-30 07:43 - 2016-09-30 07:43 - 00000000 ____D C:\Users\Rebecca\Documents\FormatFactory
2016-09-29 22:43 - 2016-09-29 22:43 - 00001071 _____ C:\Users\Rebecca\Desktop\Format Factory.lnk
2016-09-29 22:43 - 2016-09-29 22:43 - 00000000 ____D C:\Users\Rebecca\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FormatFactory
2016-09-29 22:42 - 2016-09-29 22:43 - 00000000 ____D C:\Program Files (x86)\FormatFactory
2016-09-25 16:24 - 2016-09-25 16:24 - 00000000 ____D C:\Users\Rebecca\AppData\Roaming\PotPlayerMini64
2016-09-25 16:20 - 2016-09-25 16:20 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Daum
2016-09-25 16:20 - 2016-09-25 16:20 - 00000000 ____D C:\Program Files\DAUM
2016-09-24 16:13 - 2016-09-24 16:22 - 00000618 __RSH C:\ProgramData\ntuser.pol
2016-09-24 15:49 - 2016-08-12 22:32 - 14632960 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2016-09-24 15:49 - 2016-08-12 22:32 - 12574720 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2016-09-24 15:49 - 2016-08-12 22:32 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll
2016-09-24 15:49 - 2016-08-12 22:32 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx
2016-09-24 15:49 - 2016-08-12 22:32 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll
2016-09-24 15:49 - 2016-08-12 22:17 - 12574208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL
2016-09-24 15:49 - 2016-08-12 22:17 - 11410432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2016-09-24 15:49 - 2016-08-12 22:01 - 00008192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\spwmp.dll
2016-09-24 15:49 - 2016-08-12 22:01 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdxm.ocx
2016-09-24 15:49 - 2016-08-12 22:01 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxmasf.dll
2016-09-24 15:49 - 2016-08-12 21:56 - 00461312 _____ (Microsoft Corporation) C:\Windows\system32\scavengeui.dll
2016-09-24 15:49 - 2016-08-06 21:01 - 02023424 _____ (Microsoft Corporation) C:\Windows\system32\WsmSvc.dll
2016-09-24 15:49 - 2016-08-06 21:01 - 00347136 _____ (Microsoft Corporation) C:\Windows\system32\WSManMigrationPlugin.dll
2016-09-24 15:49 - 2016-08-06 21:01 - 00310784 _____ (Microsoft Corporation) C:\Windows\system32\WsmWmiPl.dll
2016-09-24 15:49 - 2016-08-06 21:01 - 00182272 _____ (Microsoft Corporation) C:\Windows\system32\WsmAuto.dll
2016-09-24 15:49 - 2016-08-06 21:01 - 00054272 _____ (Microsoft Corporation) C:\Windows\system32\WsmRes.dll
2016-09-24 15:49 - 2016-08-06 21:01 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\wsmplpxy.dll
2016-09-24 15:49 - 2016-08-06 20:45 - 01178112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmSvc.dll
2016-09-24 15:49 - 2016-08-06 20:45 - 00249344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManMigrationPlugin.dll
2016-09-24 15:49 - 2016-08-06 20:45 - 00214016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmWmiPl.dll
2016-09-24 15:49 - 2016-08-06 20:45 - 00146944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmAuto.dll
2016-09-24 15:49 - 2016-08-06 20:45 - 00054272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WsmRes.dll
2016-09-24 15:49 - 2016-08-06 20:31 - 00266752 _____ (Microsoft Corporation) C:\Windows\system32\WSManHTTPConfig.exe
2016-09-24 15:49 - 2016-08-06 20:31 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\wsmprovhost.exe
2016-09-24 15:49 - 2016-08-06 20:23 - 00199168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSManHTTPConfig.exe
2016-09-24 15:49 - 2016-08-06 20:23 - 00012288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wsmprovhost.exe
2016-09-24 15:49 - 2016-08-06 20:23 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wsmplpxy.dll
2016-09-24 15:49 - 2016-06-14 22:51 - 00094440 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mountmgr.sys
2016-09-24 15:49 - 2016-06-14 22:46 - 04121600 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2016-09-24 15:49 - 2016-06-14 22:46 - 01573888 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll
2016-09-24 15:49 - 2016-06-14 22:46 - 01483264 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2016-09-24 15:49 - 2016-06-14 22:46 - 01202176 _____ (Microsoft Corporation) C:\Windows\system32\drmv2clt.dll
2016-09-24 15:49 - 2016-06-14 22:46 - 01068544 _____ (Microsoft Corporation) C:\Windows\system32\cryptui.dll
2016-09-24 15:49 - 2016-06-14 22:46 - 00842240 _____ (Microsoft Corporation) C:\Windows\system32\blackbox.dll
2016-09-24 15:49 - 2016-06-14 22:46 - 00782848 _____ (Microsoft Corporation) C:\Windows\system32\wmdrmsdk.dll
2016-09-24 15:49 - 2016-06-14 22:46 - 00680448 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
2016-09-24 15:49 - 2016-06-14 22:46 - 00641024 _____ (Microsoft Corporation) C:\Windows\system32\msscp.dll
2016-09-24 15:49 - 2016-06-14 22:46 - 00632320 _____ (Microsoft Corporation) C:\Windows\system32\evr.dll
2016-09-24 15:49 - 2016-06-14 22:46 - 00499712 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll
2016-09-24 15:49 - 2016-06-14 22:46 - 00497664 _____ (Microsoft Corporation) C:\Windows\system32\drmmgrtn.dll
2016-09-24 15:49 - 2016-06-14 22:46 - 00440320 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll
2016-09-24 15:49 - 2016-06-14 22:46 - 00433152 _____ (Microsoft Corporation) C:\Windows\system32\mfplat.dll
2016-09-24 15:49 - 2016-06-14 22:46 - 00371712 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll
2016-09-24 15:49 - 2016-06-14 22:46 - 00325632 _____ (Microsoft Corporation) C:\Windows\system32\msnetobj.dll
2016-09-24 15:49 - 2016-06-14 22:46 - 00295936 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll
2016-09-24 15:49 - 2016-06-14 22:46 - 00284672 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll
2016-09-24 15:49 - 2016-06-14 22:46 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2016-09-24 15:49 - 2016-06-14 22:46 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll
2016-09-24 15:49 - 2016-06-14 22:46 - 00190976 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2016-09-24 15:49 - 2016-06-14 22:46 - 00187904 _____ (Microsoft Corporation) C:\Windows\system32\pcasvc.dll
2016-09-24 15:49 - 2016-06-14 22:46 - 00141824 _____ (Microsoft Corporation) C:\Windows\system32\cryptnet.dll
2016-09-24 15:49 - 2016-06-14 22:46 - 00081920 _____ (Microsoft Corporation) C:\Windows\system32\cryptsp.dll
2016-09-24 15:49 - 2016-06-14 22:46 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\pcadm.dll
2016-09-24 15:49 - 2016-06-14 22:46 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\msmmsp.dll
2016-09-24 15:49 - 2016-06-14 22:46 - 00008704 _____ (Microsoft Corporation) C:\Windows\system32\pcaevts.dll
2016-09-24 15:49 - 2016-06-14 22:46 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll
2016-09-24 15:49 - 2016-06-14 22:41 - 00663552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\PEAuth.sys
2016-09-24 15:49 - 2016-06-14 20:51 - 03209216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll
2016-09-24 15:49 - 2016-06-14 20:51 - 01329664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quartz.dll
2016-09-24 15:49 - 2016-06-14 20:51 - 01176064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2016-09-24 15:49 - 2016-06-14 20:51 - 01005056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptui.dll
2016-09-24 15:49 - 2016-06-14 20:51 - 00988160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drmv2clt.dll
2016-09-24 15:49 - 2016-06-14 20:51 - 00744960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\blackbox.dll
2016-09-24 15:49 - 2016-06-14 20:51 - 00617984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmdrmsdk.dll
2016-09-24 15:49 - 2016-06-14 20:51 - 00519680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll
2016-09-24 15:49 - 2016-06-14 20:51 - 00504320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msscp.dll
2016-09-24 15:49 - 2016-06-14 20:51 - 00489984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\evr.dll
2016-09-24 15:49 - 2016-06-14 20:51 - 00442368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AUDIOKSE.dll
2016-09-24 15:49 - 2016-06-14 20:51 - 00406016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drmmgrtn.dll
2016-09-24 15:49 - 2016-06-14 20:51 - 00374784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll
2016-09-24 15:49 - 2016-06-14 20:51 - 00354816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfplat.dll
2016-09-24 15:49 - 2016-06-14 20:51 - 00265216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msnetobj.dll
2016-09-24 15:49 - 2016-06-14 20:51 - 00195072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll
2016-09-24 15:49 - 2016-06-14 20:51 - 00179200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2016-09-24 15:49 - 2016-06-14 20:51 - 00145920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2016-09-24 15:49 - 2016-06-14 20:51 - 00106496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2016-09-24 15:49 - 2016-06-14 20:51 - 00103424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfps.dll
2016-09-24 15:49 - 2016-06-14 20:51 - 00080896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsp.dll
2016-09-24 15:49 - 2016-06-14 20:51 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mferror.dll
2016-09-24 15:49 - 2016-06-14 20:45 - 00125952 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe
2016-09-24 15:49 - 2016-06-14 20:45 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe
2016-09-24 15:49 - 2016-06-14 20:45 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe
2016-09-24 15:49 - 2016-06-14 20:35 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rrinstaller.exe
2016-09-24 15:49 - 2016-06-14 20:35 - 00023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfpmp.exe
2016-09-24 15:49 - 2016-06-14 20:30 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\pcawrk.exe
2016-09-24 15:49 - 2016-06-14 20:30 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\pcalua.exe
2016-09-24 15:24 - 2016-08-29 21:01 - 14183424 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2016-09-24 15:24 - 2016-08-29 21:01 - 01941504 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2016-09-24 15:24 - 2016-08-29 21:01 - 01867776 _____ (Microsoft Corporation) C:\Windows\system32\ExplorerFrame.dll
2016-09-24 15:24 - 2016-08-29 20:42 - 12880384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2016-09-24 15:24 - 2016-08-29 20:42 - 01806848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2016-09-24 15:24 - 2016-08-29 20:42 - 01499648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ExplorerFrame.dll
2016-09-24 15:24 - 2016-08-29 20:34 - 03229696 _____ (Microsoft Corporation) C:\Windows\explorer.exe
2016-09-24 15:24 - 2016-08-29 20:25 - 02972672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe
2016-09-24 15:24 - 2016-08-17 02:10 - 00343552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
2016-09-24 15:24 - 2016-08-17 02:10 - 00327168 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys
2016-09-24 15:24 - 2016-08-17 02:10 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys
2016-09-24 15:24 - 2016-08-17 02:10 - 00056320 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
2016-09-24 15:24 - 2016-08-17 02:10 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys
2016-09-24 15:24 - 2016-08-17 02:10 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys
2016-09-24 15:24 - 2016-08-17 02:10 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys
2016-09-23 00:25 - 2016-08-05 21:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2016-09-23 00:25 - 2016-08-05 20:43 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-10-19 19:37 - 2016-06-18 15:21 - 00000000 ____D C:\Users\Rebecca\Downloads\Programs & setup files
2016-10-19 19:09 - 2009-07-14 10:15 - 00021904 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-10-19 19:09 - 2009-07-14 10:15 - 00021904 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-10-19 19:05 - 2009-07-14 10:43 - 00924636 _____ C:\Windows\system32\PerfStringBackup.INI
2016-10-19 19:05 - 2009-07-14 08:50 - 00000000 ____D C:\Windows\inf
2016-10-19 19:04 - 2016-06-18 02:40 - 00000000 ____D C:\ProgramData\Malwarebytes Anti-Exploit
2016-10-19 18:59 - 2016-06-18 02:23 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-10-19 18:59 - 2009-07-14 10:38 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-10-19 18:53 - 2016-07-13 04:10 - 00047784 _____ C:\Users\Rebecca\Downloads\text.txt
2016-10-19 18:41 - 2016-06-18 02:23 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-10-19 18:21 - 2016-06-23 06:37 - 00000000 ____D C:\Users\Rebecca\AppData\Local\ElevatedDiagnostics
2016-10-19 17:58 - 2016-06-18 15:43 - 00000000 ____D C:\Users\Rebecca\AppData\Roaming\DMCache
2016-10-19 03:42 - 2016-06-18 02:22 - 00004180 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2016-10-15 17:06 - 2016-06-18 15:55 - 00000000 ____D C:\Users\Rebecca\AppData\Roaming\vlc
2016-10-14 17:54 - 2009-07-14 08:50 - 00000000 ____D C:\Windows\rescache
2016-10-14 03:17 - 2016-09-15 12:57 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2016-10-14 03:17 - 2016-09-15 01:05 - 00000000 ____D C:\Users\Rebecca\Desktop\mbar
2016-10-14 03:17 - 2016-06-26 23:03 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2016-10-14 02:42 - 2016-06-18 02:17 - 00109272 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys
2016-10-13 15:35 - 2016-06-18 14:43 - 00000000 ____D C:\Users\Rebecca\AppData\Local\JDownloader v2.0
2016-10-13 13:46 - 2009-07-14 08:50 - 00000000 ____D C:\Windows\system32\NDF
2016-10-13 13:30 - 2016-06-18 02:22 - 00293352 _____ (AVAST Software) C:\Windows\system32\Drivers\aswvmm.sys
2016-10-13 12:08 - 2009-07-14 10:15 - 00315760 _____ C:\Windows\system32\FNTCACHE.DAT
2016-10-13 12:06 - 2016-06-24 22:22 - 00000000 ___SD C:\Windows\system32\CompatTel
2016-10-13 12:06 - 2016-06-24 22:22 - 00000000 ____D C:\Windows\system32\appraiser
2016-10-12 22:51 - 2016-06-23 00:12 - 00000000 ____D C:\Windows\system32\MRT
2016-10-12 22:44 - 2016-06-23 00:12 - 143495576 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2016-10-07 23:29 - 2016-04-24 05:32 - 00000000 ____D C:\Users\Rebecca\Downloads\My Stuff
2016-10-06 19:46 - 2015-08-14 20:53 - 00000000 ____D C:\Users\Rebecca\Downloads\Texts
2016-10-05 00:45 - 2016-06-18 01:00 - 00069832 _____ C:\Users\Rebecca\AppData\Local\GDIPFONTCACHEV1.DAT
2016-10-05 00:44 - 2016-08-18 19:21 - 00000000 ____D C:\Windows\system32\appmgmt
2016-10-04 21:29 - 2016-06-18 01:45 - 00000000 ____D C:\Windows\System32\Tasks\Sony Corporation
2016-10-04 21:29 - 2016-06-18 01:45 - 00000000 ____D C:\Program Files\Sony
2016-10-04 01:12 - 2016-08-25 23:02 - 00000000 ____D C:\Users\Rebecca\Downloads\Pics
2016-10-04 01:09 - 2016-08-05 18:42 - 00000000 ____D C:\Users\Rebecca\Downloads\IT
2016-10-04 00:51 - 2016-06-18 02:43 - 00000000 ____D C:\Windows\pss
2016-10-04 00:35 - 2016-07-06 23:40 - 00000000 ____D C:\Users\Rebecca\Downloads\Songs & christian videos
2016-10-03 19:54 - 2016-06-18 14:36 - 00000000 ____D C:\Program Files\WinRAR
2016-10-01 19:36 - 2016-06-18 02:27 - 00003894 _____ C:\Windows\System32\Tasks\SafeZone scheduled Autoupdate 1466197035
2016-09-29 17:03 - 2009-07-14 08:50 - 00000000 ____D C:\Windows\tracing
2016-09-26 13:56 - 2016-07-03 19:43 - 00000000 ___HD C:\Program Files And Folders
2016-09-24 16:36 - 2016-09-15 15:04 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
2016-09-24 16:12 - 2009-07-14 08:50 - 00000000 ___HD C:\Windows\system32\GroupPolicy
2016-09-24 15:51 - 2009-07-14 08:50 - 00000000 ____D C:\Windows\SysWOW64\Dism
2016-09-24 15:51 - 2009-07-14 08:50 - 00000000 ____D C:\Windows\system32\Dism
2016-09-24 15:31 - 2016-06-18 02:13 - 00774404 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2016-09-23 00:33 - 2016-06-18 02:22 - 00513632 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys
2016-09-20 21:26 - 2016-09-15 14:26 - 00000000 ____D C:\Program Files\SUPERAntiSpyware
==================== Files in the root of some directories =======
2016-07-20 21:04 - 2016-07-20 21:04 - 0000057 _____ () C:\ProgramData\Ament.ini
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2016-10-15 00:43
==================== End of FRST.txt ============================