Hello! For the past couple of weeks I’ve been getting constant “There is no internet connection” screens. The screen also states “DNS_PROBE_FINISHED_NO_INTERNET. This happens despite Local Area Connection Status shows I’m connected to the internet and I can see data flowing. One of the issue I noticed, when monitoring connection activity, is that my computer is sending much more data than receiving. This made me think that my computer might be infected. The connection break outs are getting so frequent that it’s pretty much impossible to use my desktop. I have F-Secure Virus scanner that showed no infections. I also ran Malwarebytes scan and it came up clean. Here is my FRST logs:
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 17-08-2017
Ran by Teppo (administrator) on TJ (17-08-2017 23:30:33)
Running from C:\Users\Teppo\Desktop
Loaded Profiles: Teppo (Available Profiles: Teppo & Administrator)
Platform: Windows 10 Pro Version 1511 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(F-Secure Corporation) C:\Program Files (x86)\F-Secure\Internet Security\apps\CCF_Reputation\fsorsp.exe
(F-Secure Corporation) C:\Program Files (x86)\F-Secure\Internet Security\fshoster32.exe
(F-Secure Corporation) C:\Program Files (x86)\F-Secure\Internet Security\fshoster32.exe
() C:\Program Files (x86)\PureVPN\vpnclient.exe
(F-Secure Corporation) C:\Program Files (x86)\F-Secure\Internet Security\apps\ComputerSecurity\Anti-Virus\fsgk32.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(F-Secure Corporation) C:\Program Files (x86)\F-Secure\Internet Security\apps\ComputerSecurity\Common\FSMA32.EXE
(F-Secure Corporation) C:\Program Files (x86)\F-Secure\Internet Security\apps\ComputerSecurity\Common\FSHDLL64.EXE
(F-Secure Corporation) C:\Program Files (x86)\F-Secure\Internet Security\apps\ComputerSecurity\Anti-Virus\fssm32.exe
(Microsoft Corporation) C:\Windows\SysWOW64\dllhost.exe
(F-Secure Corporation) C:\Program Files (x86)\F-Secure\Internet Security\fshoster32.exe
() C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeHost.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Google, Inc) C:\Users\Teppo\AppData\Local\Programs\Google\Google Photos Backup\Google Photos Backup.exe
() C:\Program Files (x86)\PureVPN\purevpn.exe
(Google Inc.) C:\Users\Teppo\AppData\Local\Google\Update\GoogleUpdate.exe
(Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Analog Devices, Inc.) C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe
() C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe
(Adobe Systems Inc.) C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe
(Microsoft Corporation) C:\Windows\System32\NetworkUXBroker.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\WINWORD.EXE
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Microsoft Corporation) C:\Windows\splwow64.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [Malwarebytes TrayApp] => C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe [3146704 2017-05-09] (Malwarebytes)
HKLM-x32\...\Run: [SoundMAXPnP] => C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe [1314816 2009-04-23] (Analog Devices, Inc.)
HKLM-x32\...\Run: [RemoteControl9] => C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe [87336 2010-10-01] (CyberLink Corp.)
HKLM-x32\...\Run: [PDVD9LanguageShortcut] => C:\Program Files (x86)\CyberLink\PowerDVD9\Language\Language.exe [50472 2010-09-17] (CyberLink Corp.)
HKLM-x32\...\Run: [RoxWatchTray] => C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe [240112 2010-11-25] (Sonic Solutions)
HKLM-x32\...\Run: [Desktop Disc Tool] => C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe [514544 2010-11-17] ()
HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254696 2012-01-18] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [Adobe Acrobat Speed Launcher] => C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe [41360 2015-09-24] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe [840592 2015-09-24] (Adobe Systems Inc.)
HKLM\...\Policies\Explorer: [NoPublishingWizard] 1
HKLM\...\Policies\Explorer: [NoWebServices] 1
HKU\S-1-5-21-1148200332-1382918412-2715992946-1008\...\Run: [EPSON Stylus CX7400 Series] => C:\WINDOWS\TEMP\E_S40EA.tmp [132 2016-08-03] () <==== ATTENTION
HKU\S-1-5-21-1148200332-1382918412-2715992946-1008\...\Run: [Google Update] => C:\Users\Teppo\AppData\Local\Google\Update\1.3.33.5\GoogleUpdateCore.exe [601168 2017-04-28] (Google Inc.)
HKU\S-1-5-21-1148200332-1382918412-2715992946-1008\...\Run: [Google Photos Backup] => C:\Users\Teppo\AppData\Local\Programs\Google\Google Photos Backup\Google Photos Backup.exe [3790936 2016-04-08] (Google, Inc)
HKU\S-1-5-21-1148200332-1382918412-2715992946-1008\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [27742168 2017-06-07] (Skype Technologies S.A.)
HKU\S-1-5-21-1148200332-1382918412-2715992946-1008\...\Run: [PureVPN] => autorun
Startup: C:\Users\Teppo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\PureVPN.lnk [2017-06-24]
ShortcutTarget: PureVPN.lnk -> C:\Program Files (x86)\PureVPN\purevpn.exe ()
GroupPolicy: Restriction <==== ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254
Tcpip\..\Interfaces\{92a078cd-ba36-4e4c-8fd2-42936ac9cce0}: [DhcpNameServer] 192.168.1.254
Tcpip\..\Interfaces\{e06f8e03-d367-4c2f-ac92-3da89ef1ebe5}: [DhcpNameServer] 138.99.210.3 0.0.0.0
Internet Explorer:
==================
BHO: Browsing Protection by F-Secure -> {45BBE08D-81C5-4A67-AF20-B2A077C67747} -> C:\Program Files (x86)\F-Secure\Internet Security\apps\CCF_Scanning\bin\browser\install\fs_ie_https\fs_ie_https64.dll [2017-05-11] (F-Secure Corporation)
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: No Name -> {02478D38-C3F9-4efb-9B51-7695ECA05670} -> No File
BHO-x32: Browsing Protection by F-Secure -> {45BBE08D-81C5-4A67-AF20-B2A077C67747} -> C:\Program Files (x86)\F-Secure\Internet Security\apps\CCF_Scanning\bin\browser\install\fs_ie_https\fs_ie_https.dll [2017-05-11] (F-Secure Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre6\bin\ssv.dll [2012-04-25] (Sun Microsystems, Inc.)
BHO-x32: Adobe PDF Conversion Toolbar Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2015-09-24] (Adobe Systems Incorporated)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2012-04-25] (Sun Microsystems, Inc.)
BHO-x32: SmartSelect Class -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2015-09-24] (Adobe Systems Incorporated)
Toolbar: HKLM-x32 - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2015-09-24] (Adobe Systems Incorporated)
Toolbar: HKU\S-1-5-21-1148200332-1382918412-2715992946-1008 -> No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File
FireFox:
========
FF DefaultProfile: 6x6fzu3b.default
FF ProfilePath: C:\Users\Teppo\AppData\Roaming\Mozilla\Firefox\Profiles\6x6fzu3b.default [2017-05-21]
FF Extension: (Ebates Cash Back) - C:\Users\Teppo\AppData\Roaming\Mozilla\Firefox\Profiles\6x6fzu3b.default\Extensions\{35d6291e-1d4b-f9b4-c52f-77e6410d1326}.xpi [2017-03-09]
FF HKLM\...\Firefox\Extensions: [ols@f-secure.com] - C:\Program Files (x86)\F-Secure\Internet Security\apps\CCF_Scanning\bin\browser\install\fs_firefox_https\fs_firefox_https.xpi
FF Extension: (Browsing Protection by F-Secure) - C:\Program Files (x86)\F-Secure\Internet Security\apps\CCF_Scanning\bin\browser\install\fs_firefox_https\fs_firefox_https.xpi [2017-05-11]
FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension@web2pdf.adobedotcom] - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn
FF Extension: (Adobe Acrobat - Create PDF) - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2016-05-26] [not signed]
FF HKLM-x32\...\Firefox\Extensions: [ols@f-secure.com] - C:\Program Files (x86)\F-Secure\Internet Security\apps\CCF_Scanning\bin\browser\install\fs_firefox_https\fs_firefox_https.xpi
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_26_0_0_151.dll [2017-08-08] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_26_0_0_151.dll [2017-08-08] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll [2012-02-02] (Adobe Systems, Inc.)
FF Plugin-x32: @java.com/JavaPlugin -> C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll [2012-04-25] (Sun Microsystems, Inc.)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-28] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-28] (Google Inc.)
FF Plugin-x32: Adobe Acrobat -> C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll [2015-09-24] (Adobe Systems Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-12-18] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-1148200332-1382918412-2715992946-1008: @tools.google.com/Google Update;version=3 -> C:\Users\Teppo\AppData\Local\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-28] (Google Inc.)
FF Plugin HKU\S-1-5-21-1148200332-1382918412-2715992946-1008: @tools.google.com/Google Update;version=9 -> C:\Users\Teppo\AppData\Local\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-28] (Google Inc.)
FF Plugin HKU\S-1-5-21-1148200332-1382918412-2715992946-1008: tdameritrade.com/thinkorswim -> C:\Program Files\thinkorswim\npthinkorswim.dll [2017-08-17] (TD Ameritrade)
FF Plugin HKU\S-1-5-21-1148200332-1382918412-2715992946-1008: tdameritrade.com/tossc -> C:\Program Files\thinkorswim\nptossc.dll [2017-08-17] (TD Ameritrade)
Chrome:
=======
CHR HomePage: Default -> hxxp://www.google.com
CHR Profile: C:\Users\Teppo\AppData\Local\Google\Chrome\User Data\Default [2017-08-17]
CHR Extension: (Google Slides) - C:\Users\Teppo\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-05-26]
CHR Extension: (Google Docs) - C:\Users\Teppo\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-05-26]
CHR Extension: (Google Drive) - C:\Users\Teppo\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-05-26]
CHR Extension: (YouTube) - C:\Users\Teppo\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-05-26]
CHR Extension: (Google Sheets) - C:\Users\Teppo\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-05-26]
CHR Extension: (Google Docs Offline) - C:\Users\Teppo\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-05-26]
CHR Extension: (Browsing Protection by F-Secure) - C:\Users\Teppo\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmjjnhpacphpjmnnlnccpfmhkcloaade [2016-09-07]
CHR Extension: (Ghostery) - C:\Users\Teppo\AppData\Local\Google\Chrome\User Data\Default\Extensions\mlomiejdfkolichcflejclcbmpeaniij [2017-08-10]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Teppo\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-03-08]
CHR Extension: (Gmail) - C:\Users\Teppo\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-05-26]
CHR Extension: (Chrome Media Router) - C:\Users\Teppo\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-08-08]
CHR HKLM\...\Chrome\Extension: [jmjjnhpacphpjmnnlnccpfmhkcloaade] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [jmjjnhpacphpjmnnlnccpfmhkcloaade] - hxxps://clients2.google.com/service/update2/crx
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 fshoster; C:\Program Files (x86)\F-Secure\Internet Security\fshoster32.exe [181216 2016-10-25] (F-Secure Corporation)
R3 FSMA; C:\Program Files (x86)\F-Secure\Internet Security\apps\ComputerSecurity\Common\FSMA32.EXE [218080 2016-10-26] (F-Secure Corporation)
R2 fsnethoster; C:\Program Files (x86)\F-Secure\Internet Security\fshoster32.exe [181216 2016-10-25] (F-Secure Corporation)
R2 FSORSPClient; C:\Program Files (x86)\F-Secure\Internet Security\apps\CCF_Reputation\fsorsp.exe [67640 2017-05-09] (F-Secure Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4470736 2017-05-09] (Malwarebytes)
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2009-05-14] (Hewlett-Packard) [File not signed]
S3 OpenVPNService; C:\Program Files (x86)\PureVPN\bin\openvpnserv.exe [31872 2016-12-20] (The OpenVPN Project)
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2009-05-14] (Hewlett-Packard) [File not signed]
R2 sevpnclient; C:\Program Files (x86)\PureVPN\vpnclient.exe [4838400 2016-12-20] () [File not signed]
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2016-10-25] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2017-07-29] (Microsoft Corporation)
S3 wmiApSrv; C:\WINDOWS\system32\wbem\WmiApSrv.exe [202752 2015-10-30] (Microsoft Corporation)
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R0 amdkmpfd; C:\WINDOWS\System32\drivers\amdkmpfd.sys [65248 2015-11-06] (Advanced Micro Devices, Inc.)
R1 ESProtectionDriver; C:\WINDOWS\system32\drivers\mbae64.sys [77376 2017-06-27] ()
R3 F-Secure Gatekeeper; C:\Program Files (x86)\F-Secure\Internet Security\apps\ComputerSecurity\Anti-Virus\minifilter\FSgk.sys [230552 2017-06-28] (F-Secure Corporation)
R1 F-Secure HIPS; C:\Program Files (x86)\F-Secure\Internet Security\apps\ComputerSecurity\HIPS\drivers\fshs.sys [106648 2017-06-28] (F-Secure Corporation)
R0 fsbts; C:\WINDOWS\System32\Drivers\fsbts.sys [73928 2016-07-06] ()
R3 fsni; C:\Program Files (x86)\F-Secure\Internet Security\apps\CCF_Scanning\bin\fsni64.sys [120016 2017-05-11] (F-Secure Corporation)
S3 IntcAzAudAddService; C:\WINDOWS\System32\drivers\RTDVHD64.sys [1980648 2012-04-25] (Realtek Semiconductor Corp.)
R2 MBAMChameleon; C:\WINDOWS\system32\drivers\MBAMChameleon.sys [188352 2017-08-17] (Malwarebytes)
R3 MBAMFarflt; C:\WINDOWS\system32\drivers\farflt.sys [101784 2017-08-17] (Malwarebytes)
R3 MBAMProtection; C:\WINDOWS\system32\drivers\mbam.sys [45472 2017-08-17] (Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [253856 2017-08-17] (Malwarebytes)
R3 MBAMWebProtection; C:\WINDOWS\system32\drivers\mwac.sys [93600 2017-08-17] (Malwarebytes)
R3 Neo_VPN; C:\WINDOWS\System32\drivers\neo_vpn.sys [29744 2016-12-20] (PureVPN)
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-08-17 23:30 - 2017-08-17 23:31 - 000018747 _____ C:\Users\Teppo\Desktop\FRST.txt
2017-08-17 22:40 - 2017-08-17 23:30 - 000000000 ____D C:\FRST
2017-08-17 22:39 - 2017-08-17 22:40 - 002395648 _____ (Farbar) C:\Users\Teppo\Desktop\FRST64.exe
2017-08-17 22:37 - 2017-08-17 22:37 - 001792512 _____ (Farbar) C:\Users\Teppo\Downloads\FRST (1).exe
2017-08-17 22:35 - 2017-08-17 22:35 - 001792512 _____ (Farbar) C:\Users\Teppo\Downloads\FRST.exe
2017-08-17 21:28 - 2017-08-17 22:50 - 000101784 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\farflt.sys
2017-08-17 21:28 - 2017-08-17 22:50 - 000093600 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys
2017-08-17 21:28 - 2017-08-17 22:50 - 000045472 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
2017-08-17 21:28 - 2017-08-17 22:49 - 000253856 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2017-08-17 21:28 - 2017-08-17 21:28 - 000188352 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMChameleon.sys
2017-08-17 21:27 - 2017-08-17 21:27 - 000001918 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2017-08-17 21:27 - 2017-08-17 21:27 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2017-08-17 21:27 - 2017-08-17 21:27 - 000000000 ____D C:\ProgramData\Malwarebytes
2017-08-17 21:27 - 2017-08-17 21:27 - 000000000 ____D C:\Program Files\Malwarebytes
2017-08-17 21:27 - 2017-06-27 12:06 - 000077376 _____ C:\WINDOWS\system32\Drivers\mbae64.sys
2017-08-17 21:16 - 2017-08-17 21:27 - 065033984 _____ (Malwarebytes ) C:\Users\Teppo\Downloads\mb3-setup-consumer-3.1.2.1733-1.0.160-1.0.2251.exe
2017-08-17 20:57 - 2017-08-17 20:58 - 000388608 _____ (Trend Micro Inc.) C:\Users\Teppo\Downloads\HijackThis (1).exe
2017-08-17 20:26 - 2017-08-17 20:27 - 000388608 _____ (Trend Micro Inc.) C:\Users\Teppo\Downloads\HijackThis.exe
2017-08-17 19:52 - 2017-08-17 19:52 - 000119808 _____ (Atribune.org) C:\Users\Teppo\Downloads\VundoFix.exe
2017-08-17 19:52 - 2017-08-17 19:52 - 000000000 ____D C:\VundoFix Backups
2017-08-16 19:04 - 2017-08-16 19:04 - 000000000 ____D C:\Users\Teppo\AppData\Local\purevpn
2017-08-14 20:11 - 2017-08-14 20:21 - 000000000 ____D C:\Program Files\rempl
2017-08-12 19:56 - 2017-08-12 19:56 - 001749051 _____ C:\Users\Teppo\Downloads\Examples-RevA.pdf
2017-08-12 19:53 - 2017-08-12 19:53 - 001409175 _____ C:\Users\Teppo\Downloads\Examples - Losing Trade - RevA.pdf
2017-08-12 19:52 - 2017-08-12 19:52 - 000211834 _____ C:\Users\Teppo\Downloads\John Chernicky (aka Monarch) Trade Plan.pdf
2017-08-12 19:34 - 2017-08-12 19:34 - 000912807 _____ C:\Users\Teppo\Downloads\Evolution of a Butterfly (Trader) - PDF (1).pdf
2017-08-12 19:32 - 2017-08-12 19:32 - 000912807 _____ C:\Users\Teppo\Downloads\Evolution of a Butterfly (Trader) - PDF.pdf
2017-08-12 19:32 - 2017-08-12 19:32 - 000000387 _____ C:\Users\Teppo\Downloads\0 - Readme
2017-08-09 19:16 - 2017-07-29 17:24 - 001862008 _____ C:\WINDOWS\SysWOW64\CoreUIComponents.dll
2017-08-09 19:16 - 2017-07-29 16:59 - 000922432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ucrtbase.dll
2017-08-09 19:16 - 2017-07-29 16:59 - 000302704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wevtapi.dll
2017-08-09 19:16 - 2017-07-29 14:47 - 002945648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2017-08-09 19:16 - 2017-07-29 14:47 - 000703840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe
2017-08-09 19:16 - 2017-07-29 14:35 - 000465760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncHost.exe
2017-08-09 19:16 - 2017-07-29 14:26 - 000064584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\appidapi.dll
2017-08-09 19:16 - 2017-07-29 13:26 - 000262496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerFault.exe
2017-08-09 19:16 - 2017-07-29 13:26 - 000118368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerFaultSecure.exe
2017-08-09 19:16 - 2017-07-29 13:19 - 000540280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wer.dll
2017-08-09 19:16 - 2017-07-29 13:19 - 000335248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Faultrep.dll
2017-08-09 19:16 - 2017-07-29 13:18 - 000141664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wermgr.exe
2017-08-09 19:16 - 2017-07-29 11:41 - 000994760 _____ (Microsoft Corporation) C:\WINDOWS\system32\ucrtbase.dll
2017-08-09 19:16 - 2017-07-29 10:21 - 000033280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tokenbinding.dll
2017-08-09 19:16 - 2017-07-29 10:00 - 000099840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\srpapi.dll
2017-08-09 19:16 - 2017-07-29 09:55 - 000250880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppLockerCSP.dll
2017-08-09 19:16 - 2017-07-29 09:51 - 000496640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVP9DEC.dll
2017-08-09 19:16 - 2017-07-29 09:47 - 000040448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBrokerUI.dll
2017-08-09 19:16 - 2017-07-29 09:42 - 000118112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tdx.sys
2017-08-09 19:16 - 2017-07-29 09:39 - 000092160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\IdCtrls.dll
2017-08-09 19:16 - 2017-07-29 09:34 - 000146432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWWIN.EXE
2017-08-09 19:16 - 2017-07-29 09:32 - 000260096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\apprepsync.dll
2017-08-09 19:16 - 2017-07-29 09:29 - 000190976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\apprepapi.dll
2017-08-09 19:16 - 2017-07-29 09:27 - 000282624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Search.ProtocolHandler.MAPI2.dll
2017-08-09 19:16 - 2017-07-29 09:24 - 000541184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GamePanel.exe
2017-08-09 19:16 - 2017-07-29 09:20 - 000384512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schannel.dll
2017-08-09 19:16 - 2017-07-29 09:19 - 000395264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\werui.dll
2017-08-09 19:16 - 2017-07-29 09:17 - 000250880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2017-08-09 19:16 - 2017-07-29 09:14 - 000282624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchProtocolHost.exe
2017-08-09 19:16 - 2017-07-29 09:09 - 000400896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OneDriveSettingSyncProvider.dll
2017-08-09 19:16 - 2017-07-29 09:02 - 000262144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ncryptprov.dll
2017-08-09 19:16 - 2017-07-29 09:01 - 000760320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchIndexer.exe
2017-08-09 19:16 - 2017-07-29 09:00 - 000805888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSShared.dll
2017-08-09 19:16 - 2017-07-29 08:56 - 000667648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AzureSettingSyncProvider.dll
2017-08-09 19:16 - 2017-07-29 08:51 - 000639488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll
2017-08-09 19:16 - 2017-07-29 08:39 - 004078080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbgeng.dll
2017-08-09 19:16 - 2017-07-29 08:34 - 001501184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2017-08-09 19:16 - 2017-07-29 08:33 - 000808288 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe
2017-08-09 19:16 - 2017-07-29 08:32 - 002881536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2017-08-09 19:16 - 2017-07-29 08:30 - 001984000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssrch.dll
2017-08-09 19:16 - 2017-07-29 08:06 - 006743040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll
2017-08-09 19:16 - 2017-07-29 08:06 - 005327360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
2017-08-09 19:16 - 2017-07-29 08:00 - 002604032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CertEnroll.dll
2017-08-09 19:16 - 2017-07-29 07:59 - 000339456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certcli.dll
2017-08-09 19:16 - 2017-07-29 07:50 - 002770432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll
2017-08-09 19:16 - 2017-07-29 07:21 - 002403160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2017-08-09 19:16 - 2017-07-29 07:15 - 000461824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll
2017-08-09 19:16 - 2017-07-29 04:37 - 000865792 _____ (Microsoft Corporation) C:\WINDOWS\system32\AzureSettingSyncProvider.dll
2017-08-09 19:16 - 2017-07-29 04:06 - 002573824 _____ (Microsoft Corporation) C:\WINDOWS\system32\WsmSvc.dll
2017-08-09 19:16 - 2017-07-29 04:06 - 002279936 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2017-08-09 19:16 - 2017-07-29 03:28 - 003574272 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll
2017-08-09 19:16 - 2017-07-29 03:25 - 007536128 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
2017-08-09 19:16 - 2017-07-29 03:13 - 002911744 _____ (Microsoft Corporation) C:\WINDOWS\system32\CertEnroll.dll
2017-08-09 19:16 - 2017-07-28 20:22 - 001311744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msjet40.dll
2017-08-09 19:16 - 2017-07-28 20:22 - 000866816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mswdat10.dll
2017-08-09 19:16 - 2017-07-28 20:22 - 000641536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mswstr10.dll
2017-08-09 19:16 - 2017-07-28 20:22 - 000616448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrepl40.dll
2017-08-09 19:16 - 2017-07-28 20:22 - 000518144 _____ C:\WINDOWS\SysWOW64\msjetoledb40.dll
2017-08-09 19:16 - 2017-07-28 20:22 - 000475648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxbde40.dll
2017-08-09 19:16 - 2017-07-28 20:22 - 000375808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mspbde40.dll
2017-08-09 19:16 - 2017-07-28 20:22 - 000343552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrd3x40.dll
2017-08-09 19:16 - 2017-07-28 20:22 - 000339968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msexcl40.dll
2017-08-09 19:16 - 2017-07-28 20:22 - 000310272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrd2x40.dll
2017-08-09 19:16 - 2017-07-28 20:22 - 000290816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msjtes40.dll
2017-08-09 19:16 - 2017-07-28 20:22 - 000272896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstext40.dll
2017-08-09 19:16 - 2017-07-28 20:22 - 000240640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msltus40.dll
2017-08-09 19:16 - 2017-07-28 20:22 - 000144896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msjint40.dll
2017-08-09 19:16 - 2017-07-28 20:22 - 000083968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msjter40.dll
2017-08-09 19:15 - 2017-07-29 11:31 - 002656960 _____ C:\WINDOWS\system32\CoreUIComponents.dll
2017-08-09 19:15 - 2017-07-29 11:29 - 000754664 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll
2017-08-09 19:15 - 2017-07-29 11:03 - 000853504 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadtb.dll
2017-08-09 19:15 - 2017-07-29 10:44 - 000572928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WpcWebFilter.dll
2017-08-09 19:15 - 2017-07-29 09:59 - 007463264 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2017-08-09 19:15 - 2017-07-29 09:58 - 000384864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\clfs.sys
2017-08-09 19:15 - 2017-07-29 09:46 - 000129888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecdd.sys
2017-08-09 19:15 - 2017-07-29 09:45 - 000395184 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtapi.dll
2017-08-09 19:15 - 2017-07-29 09:41 - 001637216 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2017-08-09 19:15 - 2017-07-29 09:31 - 000307200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll
2017-08-09 19:15 - 2017-07-29 09:08 - 000687616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2017-08-09 19:15 - 2017-07-29 09:01 - 001526272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2017-08-09 19:15 - 2017-07-29 08:33 - 003699280 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2017-08-09 19:15 - 2017-07-29 08:26 - 000566112 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncHost.exe
2017-08-09 19:15 - 2017-07-29 08:23 - 001540224 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll
2017-08-09 19:15 - 2017-07-29 08:23 - 000692136 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppwinob.dll
2017-08-09 19:15 - 2017-07-29 08:21 - 000161632 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
2017-08-09 19:15 - 2017-07-29 08:21 - 000146272 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\appid.sys
2017-08-09 19:15 - 2017-07-29 08:21 - 000075952 _____ (Microsoft Corporation) C:\WINDOWS\system32\appidapi.dll
2017-08-09 19:15 - 2017-07-29 08:20 - 000609056 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2017-08-09 19:15 - 2017-07-29 08:11 - 012139008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2017-08-09 19:15 - 2017-07-29 08:07 - 003661824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2017-08-09 19:15 - 2017-07-29 08:03 - 019345408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2017-08-09 19:15 - 2017-07-29 08:03 - 018672640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2017-08-09 19:15 - 2017-07-29 07:49 - 005662208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2017-08-09 19:15 - 2017-07-29 07:21 - 001089888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\http.sys
2017-08-09 19:15 - 2017-07-29 07:18 - 000388888 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpps.dll
2017-08-09 19:15 - 2017-07-29 06:26 - 000824320 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcWebFilter.dll
2017-08-09 19:15 - 2017-07-29 06:09 - 000041472 _____ (Microsoft Corporation) C:\WINDOWS\system32\tokenbinding.dll
2017-08-09 19:15 - 2017-07-29 05:50 - 000116224 _____ (Microsoft Corporation) C:\WINDOWS\system32\srpapi.dll
2017-08-09 19:15 - 2017-07-29 05:41 - 000523264 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVP9DEC.dll
2017-08-09 19:15 - 2017-07-29 05:37 - 000238592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Streaming.ps.dll
2017-08-09 19:15 - 2017-07-29 05:31 - 000143360 _____ (Microsoft Corporation) C:\WINDOWS\system32\wersvc.dll
2017-08-09 19:15 - 2017-07-29 05:28 - 000110080 _____ (Microsoft Corporation) C:\WINDOWS\system32\IdCtrls.dll
2017-08-09 19:15 - 2017-07-29 05:27 - 000096768 _____ (Microsoft Corporation) C:\WINDOWS\system32\wercplsupport.dll
2017-08-09 19:15 - 2017-07-29 05:22 - 000221696 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2017-08-09 19:15 - 2017-07-29 05:20 - 000381952 _____ (Microsoft Corporation) C:\WINDOWS\system32\apprepsync.dll
2017-08-09 19:15 - 2017-07-29 05:19 - 000689152 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll
2017-08-09 19:15 - 2017-07-29 05:17 - 000287744 _____ (Microsoft Corporation) C:\WINDOWS\system32\apprepapi.dll
2017-08-09 19:15 - 2017-07-29 05:16 - 000764928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2017-08-09 19:15 - 2017-07-29 05:09 - 000228864 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsqmcons.exe
2017-08-09 19:15 - 2017-07-29 05:05 - 000469504 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll
2017-08-09 19:15 - 2017-07-29 05:01 - 000330240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2017-08-09 19:15 - 2017-07-29 04:52 - 000515072 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneDriveSettingSyncProvider.dll
2017-08-09 19:15 - 2017-07-29 04:51 - 000784384 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2017-08-09 19:15 - 2017-07-29 04:47 - 001385472 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2017-08-09 19:15 - 2017-07-29 04:43 - 000325632 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncryptprov.dll
2017-08-09 19:15 - 2017-07-29 04:42 - 001752576 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2017-08-09 19:15 - 2017-07-29 04:41 - 001292288 _____ (Microsoft Corporation) C:\WINDOWS\system32\werconcpl.dll
2017-08-09 19:15 - 2017-07-29 04:41 - 000961536 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSShared.dll
2017-08-09 19:15 - 2017-07-29 04:39 - 001872896 _____ (Microsoft Corporation) C:\WINDOWS\system32\workfolderssvc.dll
2017-08-09 19:15 - 2017-07-29 04:37 - 001742848 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtsvc.dll
2017-08-09 19:15 - 2017-07-29 04:30 - 000822784 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll
2017-08-09 19:15 - 2017-07-29 04:17 - 003587584 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2017-08-09 19:15 - 2017-07-29 04:15 - 005123072 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbgeng.dll
2017-08-09 19:15 - 2017-07-29 04:14 - 001978880 _____ (Microsoft Corporation) C:\WINDOWS\system32\PeerDistSvc.dll
2017-08-09 19:15 - 2017-07-29 04:09 - 001729024 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2017-08-09 19:15 - 2017-07-29 04:02 - 003405312 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2017-08-09 19:15 - 2017-07-29 03:56 - 002876928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Wpc.dll
2017-08-09 19:15 - 2017-07-29 03:38 - 022376960 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2017-08-09 19:15 - 2017-07-29 03:38 - 013394432 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2017-08-09 19:15 - 2017-07-29 03:38 - 000957952 _____ (Microsoft Corporation) C:\WINDOWS\system32\IKEEXT.DLL
2017-08-09 19:15 - 2017-07-29 03:22 - 024605696 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2017-08-09 19:15 - 2017-07-29 03:15 - 006977536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2017-08-09 19:15 - 2017-07-29 03:13 - 004890624 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2017-08-09 19:15 - 2017-07-29 03:12 - 000459776 _____ (Microsoft Corporation) C:\WINDOWS\system32\certcli.dll
2017-08-09 19:15 - 2017-07-29 03:08 - 001087488 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll
2017-08-09 19:15 - 2017-07-29 03:05 - 007843840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2017-08-09 19:15 - 2017-06-17 02:12 - 022560744 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2017-08-09 19:15 - 2016-09-06 22:11 - 000057912 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsass.exe
2017-08-09 19:14 - 2017-07-29 07:48 - 000292192 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFault.exe
2017-08-09 19:14 - 2017-07-29 07:48 - 000122504 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFaultSecure.exe
2017-08-09 19:14 - 2017-07-29 07:44 - 000642008 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll
2017-08-09 19:14 - 2017-07-29 07:44 - 000380152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Faultrep.dll
2017-08-09 19:14 - 2017-07-29 07:43 - 000147808 _____ (Microsoft Corporation) C:\WINDOWS\system32\wermgr.exe
2017-08-09 19:14 - 2017-07-29 05:45 - 000353280 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppLockerCSP.dll
2017-08-09 19:14 - 2017-07-29 05:37 - 000049152 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBrokerUI.dll
2017-08-09 19:14 - 2017-07-29 05:24 - 000177152 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcdboot.exe
2017-08-09 19:14 - 2017-07-29 05:23 - 000171520 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWWIN.EXE
2017-08-09 19:14 - 2017-07-29 05:12 - 000370688 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack_win.dll
2017-08-09 19:14 - 2017-07-29 05:11 - 000715264 _____ (Microsoft Corporation) C:\WINDOWS\system32\GamePanel.exe
2017-08-09 19:14 - 2017-07-29 05:04 - 000452096 _____ (Microsoft Corporation) C:\WINDOWS\system32\werui.dll
2017-08-08 19:03 - 2017-08-08 19:03 - 000002432 _____ C:\Users\Teppo\Downloads\BOS Terminal Server (1).rdp
2017-08-08 16:50 - 2017-08-08 16:50 - 004723200 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerInstaller.exe
2017-07-23 20:23 - 2017-07-23 20:23 - 000093416 _____ C:\Users\Teppo\Desktop\BoardingPass SAS.pdf
2017-07-23 20:22 - 2017-07-23 20:22 - 000093416 _____ C:\Users\Teppo\Downloads\BoardingPass (1).pdf
2017-07-21 23:29 - 2017-07-21 23:29 - 000891256 _____ C:\Users\Teppo\Desktop\001.pdf
2017-07-21 23:28 - 2017-07-21 23:28 - 000802516 _____ C:\Users\Teppo\Desktop\005.pdf
2017-07-21 23:28 - 2017-07-21 23:28 - 000776309 _____ C:\Users\Teppo\Desktop\002.pdf
2017-07-21 23:28 - 2017-07-21 23:28 - 000737138 _____ C:\Users\Teppo\Desktop\003.pdf
2017-07-21 23:28 - 2017-07-21 23:28 - 000715074 _____ C:\Users\Teppo\Desktop\004.pdf
2017-07-19 20:24 - 2017-07-19 20:24 - 000003352 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-1148200332-1382918412-2715992946-1008
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-08-17 22:55 - 2017-06-30 17:37 - 000001126 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera Browser.lnk
2017-08-17 22:55 - 2017-05-30 22:34 - 000003944 _____ C:\WINDOWS\System32\Tasks\Opera scheduled Autoupdate 1465437342
2017-08-17 22:55 - 2016-06-08 18:54 - 000000000 ____D C:\Program Files (x86)\Opera
2017-08-17 22:48 - 2016-04-26 23:34 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2017-08-17 22:48 - 2012-04-25 12:25 - 000011764 __RSH C:\ProgramData\ntuser.pol
2017-08-17 22:47 - 2015-10-29 23:28 - 000524288 ___SH C:\WINDOWS\system32\config\BBI
2017-08-17 22:16 - 2016-07-03 21:01 - 000004142 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{53AF0094-3D5E-41EB-8625-F0C767A729C4}
2017-08-17 20:53 - 2016-05-26 12:18 - 000000000 ____D C:\Users\Teppo\AppData\Local\VirtualStore
2017-08-17 20:37 - 2015-10-30 00:24 - 000000000 ____D C:\WINDOWS\AppReadiness
2017-08-17 19:50 - 2016-06-08 18:23 - 000000000 ____D C:\Users\Teppo\AppData\Local\F-Secure
2017-08-17 19:41 - 2015-10-30 00:24 - 000000000 ____D C:\WINDOWS\system32\NDF
2017-08-17 19:29 - 2016-06-08 19:18 - 000000000 ____D C:\Users\Teppo\.thinkorswim
2017-08-17 19:29 - 2016-06-08 19:17 - 000000000 ____D C:\Program Files\thinkorswim
2017-08-17 19:21 - 2016-05-26 12:51 - 000002278 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-08-17 19:21 - 2016-05-26 12:51 - 000002266 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2017-08-17 19:14 - 2015-10-30 00:24 - 000000000 ___HD C:\Program Files\WindowsApps
2017-08-15 22:14 - 2015-10-30 00:24 - 000000000 ____D C:\WINDOWS\rescache
2017-08-15 19:54 - 2015-10-30 00:11 - 000000000 ____D C:\WINDOWS\CbsTemp
2017-08-15 18:46 - 2017-05-14 19:38 - 000000000 ____D C:\ProgramData\purevpn
2017-08-15 18:43 - 2016-05-26 12:18 - 000000000 ___RD C:\Users\Teppo\Virtual Machines
2017-08-15 18:43 - 2016-04-26 23:42 - 000000000 __RHD C:\Users\Public\AccountPictures
2017-08-14 22:02 - 2016-04-26 23:29 - 000392192 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2017-08-14 21:59 - 2015-10-30 00:24 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2017-08-14 21:59 - 2015-10-30 00:24 - 000000000 ____D C:\WINDOWS\system32\oobe
2017-08-14 21:59 - 2015-10-30 00:24 - 000000000 ____D C:\Program Files\Windows Photo Viewer
2017-08-14 21:59 - 2015-10-30 00:24 - 000000000 ____D C:\Program Files\Windows Defender
2017-08-14 21:59 - 2015-10-30 00:24 - 000000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2017-08-14 21:59 - 2015-10-30 00:24 - 000000000 ____D C:\Program Files (x86)\Windows Defender
2017-08-14 21:59 - 2015-10-30 00:21 - 000000000 ____D C:\WINDOWS\INF
2017-08-14 20:47 - 2016-06-13 22:50 - 000000000 ____D C:\WINDOWS\system32\MRT
2017-08-14 20:39 - 2012-04-25 13:26 - 140394280 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2017-08-14 20:10 - 2009-07-13 19:34 - 000000478 _____ C:\WINDOWS\win.ini
2017-08-08 16:51 - 2017-04-13 22:17 - 000004574 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player PPAPI Notifier
2017-08-08 16:50 - 2015-10-30 00:24 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed
2017-08-08 16:50 - 2015-10-30 00:24 - 000000000 ____D C:\WINDOWS\system32\Macromed
2017-08-08 16:36 - 2016-05-26 12:41 - 000004562 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task
2017-07-28 17:22 - 2016-12-16 21:51 - 000177648 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2017-07-28 17:22 - 2015-10-30 00:26 - 000835576 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2017-07-19 20:24 - 2016-06-08 09:17 - 000002373 _____ C:\Users\Teppo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2017-07-19 20:24 - 2016-06-08 09:17 - 000000000 ___RD C:\Users\Teppo\OneDrive
Files to move or delete:
====================
C:\WINDOWS\TEMP\E_S40EA.tmp
Some files in TEMP:
====================
2012-02-27 18:30 - 2012-02-27 18:30 - 008209056 _____ (Adobe Systems, Inc.) C:\Users\345cali\AppData\Local\Temp\InstallAX64.exe
2012-02-27 18:12 - 2012-02-27 18:12 - 008129184 _____ (Adobe Systems, Inc.) C:\Users\345cali\AppData\Local\Temp\InstallPlugin64.exe
2012-04-25 12:59 - 2012-04-25 12:59 - 000737280 _____ (Indigo Rose Corporation) C:\Users\345cali\AppData\Local\Temp\irsetup.exe
2012-03-21 12:56 - 2012-03-21 12:56 - 000908576 _____ (Sun Microsystems, Inc.) C:\Users\345cali\AppData\Local\Temp\jre-6u31-windows-i586-iftw-rv.exe
2012-04-25 12:46 - 2010-03-16 07:11 - 000149352 _____ (Microsoft Corporation) C:\Users\345cali\AppData\Local\Temp\ose00000.exe
2017-04-30 19:36 - 2017-04-30 19:36 - 000465920 _____ (Realtek Semiconductor Corp.) C:\Users\Teppo\AppData\Local\Temp\COMAP.EXE
2016-06-08 19:18 - 2016-06-08 19:18 - 000035680 _____ () C:\Users\Teppo\AppData\Local\Temp\i4jdel0.exe
2016-10-10 17:24 - 2017-02-20 18:50 - 030770176 _____ () C:\Users\Teppo\AppData\Local\Temp\SkypeSetup.exe
Some zero byte size files/folders:
==========================
C:\Windows\System32\kbd101c.dll
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2017-08-12 00:04
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 17-08-2017
Ran by Teppo (administrator) on TJ (17-08-2017 23:30:33)
Running from C:\Users\Teppo\Desktop
Loaded Profiles: Teppo (Available Profiles: Teppo & Administrator)
Platform: Windows 10 Pro Version 1511 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(F-Secure Corporation) C:\Program Files (x86)\F-Secure\Internet Security\apps\CCF_Reputation\fsorsp.exe
(F-Secure Corporation) C:\Program Files (x86)\F-Secure\Internet Security\fshoster32.exe
(F-Secure Corporation) C:\Program Files (x86)\F-Secure\Internet Security\fshoster32.exe
() C:\Program Files (x86)\PureVPN\vpnclient.exe
(F-Secure Corporation) C:\Program Files (x86)\F-Secure\Internet Security\apps\ComputerSecurity\Anti-Virus\fsgk32.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(F-Secure Corporation) C:\Program Files (x86)\F-Secure\Internet Security\apps\ComputerSecurity\Common\FSMA32.EXE
(F-Secure Corporation) C:\Program Files (x86)\F-Secure\Internet Security\apps\ComputerSecurity\Common\FSHDLL64.EXE
(F-Secure Corporation) C:\Program Files (x86)\F-Secure\Internet Security\apps\ComputerSecurity\Anti-Virus\fssm32.exe
(Microsoft Corporation) C:\Windows\SysWOW64\dllhost.exe
(F-Secure Corporation) C:\Program Files (x86)\F-Secure\Internet Security\fshoster32.exe
() C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeHost.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Google, Inc) C:\Users\Teppo\AppData\Local\Programs\Google\Google Photos Backup\Google Photos Backup.exe
() C:\Program Files (x86)\PureVPN\purevpn.exe
(Google Inc.) C:\Users\Teppo\AppData\Local\Google\Update\GoogleUpdate.exe
(Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Analog Devices, Inc.) C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe
() C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe
(Adobe Systems Inc.) C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe
(Microsoft Corporation) C:\Windows\System32\NetworkUXBroker.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\WINWORD.EXE
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Microsoft Corporation) C:\Windows\splwow64.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [Malwarebytes TrayApp] => C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe [3146704 2017-05-09] (Malwarebytes)
HKLM-x32\...\Run: [SoundMAXPnP] => C:\Program Files (x86)\Analog Devices\Core\smax4pnp.exe [1314816 2009-04-23] (Analog Devices, Inc.)
HKLM-x32\...\Run: [RemoteControl9] => C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe [87336 2010-10-01] (CyberLink Corp.)
HKLM-x32\...\Run: [PDVD9LanguageShortcut] => C:\Program Files (x86)\CyberLink\PowerDVD9\Language\Language.exe [50472 2010-09-17] (CyberLink Corp.)
HKLM-x32\...\Run: [RoxWatchTray] => C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe [240112 2010-11-25] (Sonic Solutions)
HKLM-x32\...\Run: [Desktop Disc Tool] => C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe [514544 2010-11-17] ()
HKLM-x32\...\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254696 2012-01-18] (Sun Microsystems, Inc.)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [Adobe Acrobat Speed Launcher] => C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe [41360 2015-09-24] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe [840592 2015-09-24] (Adobe Systems Inc.)
HKLM\...\Policies\Explorer: [NoPublishingWizard] 1
HKLM\...\Policies\Explorer: [NoWebServices] 1
HKU\S-1-5-21-1148200332-1382918412-2715992946-1008\...\Run: [EPSON Stylus CX7400 Series] => C:\WINDOWS\TEMP\E_S40EA.tmp [132 2016-08-03] () <==== ATTENTION
HKU\S-1-5-21-1148200332-1382918412-2715992946-1008\...\Run: [Google Update] => C:\Users\Teppo\AppData\Local\Google\Update\1.3.33.5\GoogleUpdateCore.exe [601168 2017-04-28] (Google Inc.)
HKU\S-1-5-21-1148200332-1382918412-2715992946-1008\...\Run: [Google Photos Backup] => C:\Users\Teppo\AppData\Local\Programs\Google\Google Photos Backup\Google Photos Backup.exe [3790936 2016-04-08] (Google, Inc)
HKU\S-1-5-21-1148200332-1382918412-2715992946-1008\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [27742168 2017-06-07] (Skype Technologies S.A.)
HKU\S-1-5-21-1148200332-1382918412-2715992946-1008\...\Run: [PureVPN] => autorun
Startup: C:\Users\Teppo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\PureVPN.lnk [2017-06-24]
ShortcutTarget: PureVPN.lnk -> C:\Program Files (x86)\PureVPN\purevpn.exe ()
GroupPolicy: Restriction <==== ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254
Tcpip\..\Interfaces\{92a078cd-ba36-4e4c-8fd2-42936ac9cce0}: [DhcpNameServer] 192.168.1.254
Tcpip\..\Interfaces\{e06f8e03-d367-4c2f-ac92-3da89ef1ebe5}: [DhcpNameServer] 138.99.210.3 0.0.0.0
Internet Explorer:
==================
BHO: Browsing Protection by F-Secure -> {45BBE08D-81C5-4A67-AF20-B2A077C67747} -> C:\Program Files (x86)\F-Secure\Internet Security\apps\CCF_Scanning\bin\browser\install\fs_ie_https\fs_ie_https64.dll [2017-05-11] (F-Secure Corporation)
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: No Name -> {02478D38-C3F9-4efb-9B51-7695ECA05670} -> No File
BHO-x32: Browsing Protection by F-Secure -> {45BBE08D-81C5-4A67-AF20-B2A077C67747} -> C:\Program Files (x86)\F-Secure\Internet Security\apps\CCF_Scanning\bin\browser\install\fs_ie_https\fs_ie_https.dll [2017-05-11] (F-Secure Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre6\bin\ssv.dll [2012-04-25] (Sun Microsystems, Inc.)
BHO-x32: Adobe PDF Conversion Toolbar Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2015-09-24] (Adobe Systems Incorporated)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2012-04-25] (Sun Microsystems, Inc.)
BHO-x32: SmartSelect Class -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2015-09-24] (Adobe Systems Incorporated)
Toolbar: HKLM-x32 - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2015-09-24] (Adobe Systems Incorporated)
Toolbar: HKU\S-1-5-21-1148200332-1382918412-2715992946-1008 -> No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File
FireFox:
========
FF DefaultProfile: 6x6fzu3b.default
FF ProfilePath: C:\Users\Teppo\AppData\Roaming\Mozilla\Firefox\Profiles\6x6fzu3b.default [2017-05-21]
FF Extension: (Ebates Cash Back) - C:\Users\Teppo\AppData\Roaming\Mozilla\Firefox\Profiles\6x6fzu3b.default\Extensions\{35d6291e-1d4b-f9b4-c52f-77e6410d1326}.xpi [2017-03-09]
FF HKLM\...\Firefox\Extensions: [ols@f-secure.com] - C:\Program Files (x86)\F-Secure\Internet Security\apps\CCF_Scanning\bin\browser\install\fs_firefox_https\fs_firefox_https.xpi
FF Extension: (Browsing Protection by F-Secure) - C:\Program Files (x86)\F-Secure\Internet Security\apps\CCF_Scanning\bin\browser\install\fs_firefox_https\fs_firefox_https.xpi [2017-05-11]
FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension@web2pdf.adobedotcom] - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn
FF Extension: (Adobe Acrobat - Create PDF) - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2016-05-26] [not signed]
FF HKLM-x32\...\Firefox\Extensions: [ols@f-secure.com] - C:\Program Files (x86)\F-Secure\Internet Security\apps\CCF_Scanning\bin\browser\install\fs_firefox_https\fs_firefox_https.xpi
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_26_0_0_151.dll [2017-08-08] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_26_0_0_151.dll [2017-08-08] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll [2012-02-02] (Adobe Systems, Inc.)
FF Plugin-x32: @java.com/JavaPlugin -> C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll [2012-04-25] (Sun Microsystems, Inc.)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-28] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-28] (Google Inc.)
FF Plugin-x32: Adobe Acrobat -> C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll [2015-09-24] (Adobe Systems Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-12-18] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-1148200332-1382918412-2715992946-1008: @tools.google.com/Google Update;version=3 -> C:\Users\Teppo\AppData\Local\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-28] (Google Inc.)
FF Plugin HKU\S-1-5-21-1148200332-1382918412-2715992946-1008: @tools.google.com/Google Update;version=9 -> C:\Users\Teppo\AppData\Local\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-28] (Google Inc.)
FF Plugin HKU\S-1-5-21-1148200332-1382918412-2715992946-1008: tdameritrade.com/thinkorswim -> C:\Program Files\thinkorswim\npthinkorswim.dll [2017-08-17] (TD Ameritrade)
FF Plugin HKU\S-1-5-21-1148200332-1382918412-2715992946-1008: tdameritrade.com/tossc -> C:\Program Files\thinkorswim\nptossc.dll [2017-08-17] (TD Ameritrade)
Chrome:
=======
CHR HomePage: Default -> hxxp://www.google.com
CHR Profile: C:\Users\Teppo\AppData\Local\Google\Chrome\User Data\Default [2017-08-17]
CHR Extension: (Google Slides) - C:\Users\Teppo\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-05-26]
CHR Extension: (Google Docs) - C:\Users\Teppo\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-05-26]
CHR Extension: (Google Drive) - C:\Users\Teppo\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-05-26]
CHR Extension: (YouTube) - C:\Users\Teppo\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-05-26]
CHR Extension: (Google Sheets) - C:\Users\Teppo\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-05-26]
CHR Extension: (Google Docs Offline) - C:\Users\Teppo\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-05-26]
CHR Extension: (Browsing Protection by F-Secure) - C:\Users\Teppo\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmjjnhpacphpjmnnlnccpfmhkcloaade [2016-09-07]
CHR Extension: (Ghostery) - C:\Users\Teppo\AppData\Local\Google\Chrome\User Data\Default\Extensions\mlomiejdfkolichcflejclcbmpeaniij [2017-08-10]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Teppo\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-03-08]
CHR Extension: (Gmail) - C:\Users\Teppo\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-05-26]
CHR Extension: (Chrome Media Router) - C:\Users\Teppo\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-08-08]
CHR HKLM\...\Chrome\Extension: [jmjjnhpacphpjmnnlnccpfmhkcloaade] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [jmjjnhpacphpjmnnlnccpfmhkcloaade] - hxxps://clients2.google.com/service/update2/crx
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 fshoster; C:\Program Files (x86)\F-Secure\Internet Security\fshoster32.exe [181216 2016-10-25] (F-Secure Corporation)
R3 FSMA; C:\Program Files (x86)\F-Secure\Internet Security\apps\ComputerSecurity\Common\FSMA32.EXE [218080 2016-10-26] (F-Secure Corporation)
R2 fsnethoster; C:\Program Files (x86)\F-Secure\Internet Security\fshoster32.exe [181216 2016-10-25] (F-Secure Corporation)
R2 FSORSPClient; C:\Program Files (x86)\F-Secure\Internet Security\apps\CCF_Reputation\fsorsp.exe [67640 2017-05-09] (F-Secure Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4470736 2017-05-09] (Malwarebytes)
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2009-05-14] (Hewlett-Packard) [File not signed]
S3 OpenVPNService; C:\Program Files (x86)\PureVPN\bin\openvpnserv.exe [31872 2016-12-20] (The OpenVPN Project)
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2009-05-14] (Hewlett-Packard) [File not signed]
R2 sevpnclient; C:\Program Files (x86)\PureVPN\vpnclient.exe [4838400 2016-12-20] () [File not signed]
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2016-10-25] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2017-07-29] (Microsoft Corporation)
S3 wmiApSrv; C:\WINDOWS\system32\wbem\WmiApSrv.exe [202752 2015-10-30] (Microsoft Corporation)
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R0 amdkmpfd; C:\WINDOWS\System32\drivers\amdkmpfd.sys [65248 2015-11-06] (Advanced Micro Devices, Inc.)
R1 ESProtectionDriver; C:\WINDOWS\system32\drivers\mbae64.sys [77376 2017-06-27] ()
R3 F-Secure Gatekeeper; C:\Program Files (x86)\F-Secure\Internet Security\apps\ComputerSecurity\Anti-Virus\minifilter\FSgk.sys [230552 2017-06-28] (F-Secure Corporation)
R1 F-Secure HIPS; C:\Program Files (x86)\F-Secure\Internet Security\apps\ComputerSecurity\HIPS\drivers\fshs.sys [106648 2017-06-28] (F-Secure Corporation)
R0 fsbts; C:\WINDOWS\System32\Drivers\fsbts.sys [73928 2016-07-06] ()
R3 fsni; C:\Program Files (x86)\F-Secure\Internet Security\apps\CCF_Scanning\bin\fsni64.sys [120016 2017-05-11] (F-Secure Corporation)
S3 IntcAzAudAddService; C:\WINDOWS\System32\drivers\RTDVHD64.sys [1980648 2012-04-25] (Realtek Semiconductor Corp.)
R2 MBAMChameleon; C:\WINDOWS\system32\drivers\MBAMChameleon.sys [188352 2017-08-17] (Malwarebytes)
R3 MBAMFarflt; C:\WINDOWS\system32\drivers\farflt.sys [101784 2017-08-17] (Malwarebytes)
R3 MBAMProtection; C:\WINDOWS\system32\drivers\mbam.sys [45472 2017-08-17] (Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [253856 2017-08-17] (Malwarebytes)
R3 MBAMWebProtection; C:\WINDOWS\system32\drivers\mwac.sys [93600 2017-08-17] (Malwarebytes)
R3 Neo_VPN; C:\WINDOWS\System32\drivers\neo_vpn.sys [29744 2016-12-20] (PureVPN)
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-08-17 23:30 - 2017-08-17 23:31 - 000018747 _____ C:\Users\Teppo\Desktop\FRST.txt
2017-08-17 22:40 - 2017-08-17 23:30 - 000000000 ____D C:\FRST
2017-08-17 22:39 - 2017-08-17 22:40 - 002395648 _____ (Farbar) C:\Users\Teppo\Desktop\FRST64.exe
2017-08-17 22:37 - 2017-08-17 22:37 - 001792512 _____ (Farbar) C:\Users\Teppo\Downloads\FRST (1).exe
2017-08-17 22:35 - 2017-08-17 22:35 - 001792512 _____ (Farbar) C:\Users\Teppo\Downloads\FRST.exe
2017-08-17 21:28 - 2017-08-17 22:50 - 000101784 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\farflt.sys
2017-08-17 21:28 - 2017-08-17 22:50 - 000093600 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys
2017-08-17 21:28 - 2017-08-17 22:50 - 000045472 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
2017-08-17 21:28 - 2017-08-17 22:49 - 000253856 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2017-08-17 21:28 - 2017-08-17 21:28 - 000188352 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMChameleon.sys
2017-08-17 21:27 - 2017-08-17 21:27 - 000001918 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2017-08-17 21:27 - 2017-08-17 21:27 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2017-08-17 21:27 - 2017-08-17 21:27 - 000000000 ____D C:\ProgramData\Malwarebytes
2017-08-17 21:27 - 2017-08-17 21:27 - 000000000 ____D C:\Program Files\Malwarebytes
2017-08-17 21:27 - 2017-06-27 12:06 - 000077376 _____ C:\WINDOWS\system32\Drivers\mbae64.sys
2017-08-17 21:16 - 2017-08-17 21:27 - 065033984 _____ (Malwarebytes ) C:\Users\Teppo\Downloads\mb3-setup-consumer-3.1.2.1733-1.0.160-1.0.2251.exe
2017-08-17 20:57 - 2017-08-17 20:58 - 000388608 _____ (Trend Micro Inc.) C:\Users\Teppo\Downloads\HijackThis (1).exe
2017-08-17 20:26 - 2017-08-17 20:27 - 000388608 _____ (Trend Micro Inc.) C:\Users\Teppo\Downloads\HijackThis.exe
2017-08-17 19:52 - 2017-08-17 19:52 - 000119808 _____ (Atribune.org) C:\Users\Teppo\Downloads\VundoFix.exe
2017-08-17 19:52 - 2017-08-17 19:52 - 000000000 ____D C:\VundoFix Backups
2017-08-16 19:04 - 2017-08-16 19:04 - 000000000 ____D C:\Users\Teppo\AppData\Local\purevpn
2017-08-14 20:11 - 2017-08-14 20:21 - 000000000 ____D C:\Program Files\rempl
2017-08-12 19:56 - 2017-08-12 19:56 - 001749051 _____ C:\Users\Teppo\Downloads\Examples-RevA.pdf
2017-08-12 19:53 - 2017-08-12 19:53 - 001409175 _____ C:\Users\Teppo\Downloads\Examples - Losing Trade - RevA.pdf
2017-08-12 19:52 - 2017-08-12 19:52 - 000211834 _____ C:\Users\Teppo\Downloads\John Chernicky (aka Monarch) Trade Plan.pdf
2017-08-12 19:34 - 2017-08-12 19:34 - 000912807 _____ C:\Users\Teppo\Downloads\Evolution of a Butterfly (Trader) - PDF (1).pdf
2017-08-12 19:32 - 2017-08-12 19:32 - 000912807 _____ C:\Users\Teppo\Downloads\Evolution of a Butterfly (Trader) - PDF.pdf
2017-08-12 19:32 - 2017-08-12 19:32 - 000000387 _____ C:\Users\Teppo\Downloads\0 - Readme
2017-08-09 19:16 - 2017-07-29 17:24 - 001862008 _____ C:\WINDOWS\SysWOW64\CoreUIComponents.dll
2017-08-09 19:16 - 2017-07-29 16:59 - 000922432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ucrtbase.dll
2017-08-09 19:16 - 2017-07-29 16:59 - 000302704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wevtapi.dll
2017-08-09 19:16 - 2017-07-29 14:47 - 002945648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2017-08-09 19:16 - 2017-07-29 14:47 - 000703840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe
2017-08-09 19:16 - 2017-07-29 14:35 - 000465760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncHost.exe
2017-08-09 19:16 - 2017-07-29 14:26 - 000064584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\appidapi.dll
2017-08-09 19:16 - 2017-07-29 13:26 - 000262496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerFault.exe
2017-08-09 19:16 - 2017-07-29 13:26 - 000118368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerFaultSecure.exe
2017-08-09 19:16 - 2017-07-29 13:19 - 000540280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wer.dll
2017-08-09 19:16 - 2017-07-29 13:19 - 000335248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Faultrep.dll
2017-08-09 19:16 - 2017-07-29 13:18 - 000141664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wermgr.exe
2017-08-09 19:16 - 2017-07-29 11:41 - 000994760 _____ (Microsoft Corporation) C:\WINDOWS\system32\ucrtbase.dll
2017-08-09 19:16 - 2017-07-29 10:21 - 000033280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tokenbinding.dll
2017-08-09 19:16 - 2017-07-29 10:00 - 000099840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\srpapi.dll
2017-08-09 19:16 - 2017-07-29 09:55 - 000250880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppLockerCSP.dll
2017-08-09 19:16 - 2017-07-29 09:51 - 000496640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVP9DEC.dll
2017-08-09 19:16 - 2017-07-29 09:47 - 000040448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBrokerUI.dll
2017-08-09 19:16 - 2017-07-29 09:42 - 000118112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tdx.sys
2017-08-09 19:16 - 2017-07-29 09:39 - 000092160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\IdCtrls.dll
2017-08-09 19:16 - 2017-07-29 09:34 - 000146432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWWIN.EXE
2017-08-09 19:16 - 2017-07-29 09:32 - 000260096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\apprepsync.dll
2017-08-09 19:16 - 2017-07-29 09:29 - 000190976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\apprepapi.dll
2017-08-09 19:16 - 2017-07-29 09:27 - 000282624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Search.ProtocolHandler.MAPI2.dll
2017-08-09 19:16 - 2017-07-29 09:24 - 000541184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GamePanel.exe
2017-08-09 19:16 - 2017-07-29 09:20 - 000384512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schannel.dll
2017-08-09 19:16 - 2017-07-29 09:19 - 000395264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\werui.dll
2017-08-09 19:16 - 2017-07-29 09:17 - 000250880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2017-08-09 19:16 - 2017-07-29 09:14 - 000282624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchProtocolHost.exe
2017-08-09 19:16 - 2017-07-29 09:09 - 000400896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OneDriveSettingSyncProvider.dll
2017-08-09 19:16 - 2017-07-29 09:02 - 000262144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ncryptprov.dll
2017-08-09 19:16 - 2017-07-29 09:01 - 000760320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchIndexer.exe
2017-08-09 19:16 - 2017-07-29 09:00 - 000805888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSShared.dll
2017-08-09 19:16 - 2017-07-29 08:56 - 000667648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AzureSettingSyncProvider.dll
2017-08-09 19:16 - 2017-07-29 08:51 - 000639488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll
2017-08-09 19:16 - 2017-07-29 08:39 - 004078080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbgeng.dll
2017-08-09 19:16 - 2017-07-29 08:34 - 001501184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2017-08-09 19:16 - 2017-07-29 08:33 - 000808288 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe
2017-08-09 19:16 - 2017-07-29 08:32 - 002881536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2017-08-09 19:16 - 2017-07-29 08:30 - 001984000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssrch.dll
2017-08-09 19:16 - 2017-07-29 08:06 - 006743040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll
2017-08-09 19:16 - 2017-07-29 08:06 - 005327360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
2017-08-09 19:16 - 2017-07-29 08:00 - 002604032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CertEnroll.dll
2017-08-09 19:16 - 2017-07-29 07:59 - 000339456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certcli.dll
2017-08-09 19:16 - 2017-07-29 07:50 - 002770432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll
2017-08-09 19:16 - 2017-07-29 07:21 - 002403160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2017-08-09 19:16 - 2017-07-29 07:15 - 000461824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll
2017-08-09 19:16 - 2017-07-29 04:37 - 000865792 _____ (Microsoft Corporation) C:\WINDOWS\system32\AzureSettingSyncProvider.dll
2017-08-09 19:16 - 2017-07-29 04:06 - 002573824 _____ (Microsoft Corporation) C:\WINDOWS\system32\WsmSvc.dll
2017-08-09 19:16 - 2017-07-29 04:06 - 002279936 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2017-08-09 19:16 - 2017-07-29 03:28 - 003574272 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll
2017-08-09 19:16 - 2017-07-29 03:25 - 007536128 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
2017-08-09 19:16 - 2017-07-29 03:13 - 002911744 _____ (Microsoft Corporation) C:\WINDOWS\system32\CertEnroll.dll
2017-08-09 19:16 - 2017-07-28 20:22 - 001311744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msjet40.dll
2017-08-09 19:16 - 2017-07-28 20:22 - 000866816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mswdat10.dll
2017-08-09 19:16 - 2017-07-28 20:22 - 000641536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mswstr10.dll
2017-08-09 19:16 - 2017-07-28 20:22 - 000616448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrepl40.dll
2017-08-09 19:16 - 2017-07-28 20:22 - 000518144 _____ C:\WINDOWS\SysWOW64\msjetoledb40.dll
2017-08-09 19:16 - 2017-07-28 20:22 - 000475648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxbde40.dll
2017-08-09 19:16 - 2017-07-28 20:22 - 000375808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mspbde40.dll
2017-08-09 19:16 - 2017-07-28 20:22 - 000343552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrd3x40.dll
2017-08-09 19:16 - 2017-07-28 20:22 - 000339968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msexcl40.dll
2017-08-09 19:16 - 2017-07-28 20:22 - 000310272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msrd2x40.dll
2017-08-09 19:16 - 2017-07-28 20:22 - 000290816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msjtes40.dll
2017-08-09 19:16 - 2017-07-28 20:22 - 000272896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstext40.dll
2017-08-09 19:16 - 2017-07-28 20:22 - 000240640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msltus40.dll
2017-08-09 19:16 - 2017-07-28 20:22 - 000144896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msjint40.dll
2017-08-09 19:16 - 2017-07-28 20:22 - 000083968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msjter40.dll
2017-08-09 19:15 - 2017-07-29 11:31 - 002656960 _____ C:\WINDOWS\system32\CoreUIComponents.dll
2017-08-09 19:15 - 2017-07-29 11:29 - 000754664 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll
2017-08-09 19:15 - 2017-07-29 11:03 - 000853504 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadtb.dll
2017-08-09 19:15 - 2017-07-29 10:44 - 000572928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WpcWebFilter.dll
2017-08-09 19:15 - 2017-07-29 09:59 - 007463264 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2017-08-09 19:15 - 2017-07-29 09:58 - 000384864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\clfs.sys
2017-08-09 19:15 - 2017-07-29 09:46 - 000129888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecdd.sys
2017-08-09 19:15 - 2017-07-29 09:45 - 000395184 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtapi.dll
2017-08-09 19:15 - 2017-07-29 09:41 - 001637216 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2017-08-09 19:15 - 2017-07-29 09:31 - 000307200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll
2017-08-09 19:15 - 2017-07-29 09:08 - 000687616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2017-08-09 19:15 - 2017-07-29 09:01 - 001526272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2017-08-09 19:15 - 2017-07-29 08:33 - 003699280 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2017-08-09 19:15 - 2017-07-29 08:26 - 000566112 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncHost.exe
2017-08-09 19:15 - 2017-07-29 08:23 - 001540224 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppobjs.dll
2017-08-09 19:15 - 2017-07-29 08:23 - 000692136 _____ (Microsoft Corporation) C:\WINDOWS\system32\sppwinob.dll
2017-08-09 19:15 - 2017-07-29 08:21 - 000161632 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
2017-08-09 19:15 - 2017-07-29 08:21 - 000146272 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\appid.sys
2017-08-09 19:15 - 2017-07-29 08:21 - 000075952 _____ (Microsoft Corporation) C:\WINDOWS\system32\appidapi.dll
2017-08-09 19:15 - 2017-07-29 08:20 - 000609056 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2017-08-09 19:15 - 2017-07-29 08:11 - 012139008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2017-08-09 19:15 - 2017-07-29 08:07 - 003661824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2017-08-09 19:15 - 2017-07-29 08:03 - 019345408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2017-08-09 19:15 - 2017-07-29 08:03 - 018672640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2017-08-09 19:15 - 2017-07-29 07:49 - 005662208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2017-08-09 19:15 - 2017-07-29 07:21 - 001089888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\http.sys
2017-08-09 19:15 - 2017-07-29 07:18 - 000388888 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpps.dll
2017-08-09 19:15 - 2017-07-29 06:26 - 000824320 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcWebFilter.dll
2017-08-09 19:15 - 2017-07-29 06:09 - 000041472 _____ (Microsoft Corporation) C:\WINDOWS\system32\tokenbinding.dll
2017-08-09 19:15 - 2017-07-29 05:50 - 000116224 _____ (Microsoft Corporation) C:\WINDOWS\system32\srpapi.dll
2017-08-09 19:15 - 2017-07-29 05:41 - 000523264 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVP9DEC.dll
2017-08-09 19:15 - 2017-07-29 05:37 - 000238592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Streaming.ps.dll
2017-08-09 19:15 - 2017-07-29 05:31 - 000143360 _____ (Microsoft Corporation) C:\WINDOWS\system32\wersvc.dll
2017-08-09 19:15 - 2017-07-29 05:28 - 000110080 _____ (Microsoft Corporation) C:\WINDOWS\system32\IdCtrls.dll
2017-08-09 19:15 - 2017-07-29 05:27 - 000096768 _____ (Microsoft Corporation) C:\WINDOWS\system32\wercplsupport.dll
2017-08-09 19:15 - 2017-07-29 05:22 - 000221696 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2017-08-09 19:15 - 2017-07-29 05:20 - 000381952 _____ (Microsoft Corporation) C:\WINDOWS\system32\apprepsync.dll
2017-08-09 19:15 - 2017-07-29 05:19 - 000689152 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll
2017-08-09 19:15 - 2017-07-29 05:17 - 000287744 _____ (Microsoft Corporation) C:\WINDOWS\system32\apprepapi.dll
2017-08-09 19:15 - 2017-07-29 05:16 - 000764928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2017-08-09 19:15 - 2017-07-29 05:09 - 000228864 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsqmcons.exe
2017-08-09 19:15 - 2017-07-29 05:05 - 000469504 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll
2017-08-09 19:15 - 2017-07-29 05:01 - 000330240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2017-08-09 19:15 - 2017-07-29 04:52 - 000515072 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneDriveSettingSyncProvider.dll
2017-08-09 19:15 - 2017-07-29 04:51 - 000784384 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2017-08-09 19:15 - 2017-07-29 04:47 - 001385472 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2017-08-09 19:15 - 2017-07-29 04:43 - 000325632 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncryptprov.dll
2017-08-09 19:15 - 2017-07-29 04:42 - 001752576 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2017-08-09 19:15 - 2017-07-29 04:41 - 001292288 _____ (Microsoft Corporation) C:\WINDOWS\system32\werconcpl.dll
2017-08-09 19:15 - 2017-07-29 04:41 - 000961536 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSShared.dll
2017-08-09 19:15 - 2017-07-29 04:39 - 001872896 _____ (Microsoft Corporation) C:\WINDOWS\system32\workfolderssvc.dll
2017-08-09 19:15 - 2017-07-29 04:37 - 001742848 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtsvc.dll
2017-08-09 19:15 - 2017-07-29 04:30 - 000822784 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll
2017-08-09 19:15 - 2017-07-29 04:17 - 003587584 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2017-08-09 19:15 - 2017-07-29 04:15 - 005123072 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbgeng.dll
2017-08-09 19:15 - 2017-07-29 04:14 - 001978880 _____ (Microsoft Corporation) C:\WINDOWS\system32\PeerDistSvc.dll
2017-08-09 19:15 - 2017-07-29 04:09 - 001729024 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2017-08-09 19:15 - 2017-07-29 04:02 - 003405312 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2017-08-09 19:15 - 2017-07-29 03:56 - 002876928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Wpc.dll
2017-08-09 19:15 - 2017-07-29 03:38 - 022376960 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2017-08-09 19:15 - 2017-07-29 03:38 - 013394432 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2017-08-09 19:15 - 2017-07-29 03:38 - 000957952 _____ (Microsoft Corporation) C:\WINDOWS\system32\IKEEXT.DLL
2017-08-09 19:15 - 2017-07-29 03:22 - 024605696 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2017-08-09 19:15 - 2017-07-29 03:15 - 006977536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2017-08-09 19:15 - 2017-07-29 03:13 - 004890624 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2017-08-09 19:15 - 2017-07-29 03:12 - 000459776 _____ (Microsoft Corporation) C:\WINDOWS\system32\certcli.dll
2017-08-09 19:15 - 2017-07-29 03:08 - 001087488 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll
2017-08-09 19:15 - 2017-07-29 03:05 - 007843840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2017-08-09 19:15 - 2017-06-17 02:12 - 022560744 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2017-08-09 19:15 - 2016-09-06 22:11 - 000057912 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsass.exe
2017-08-09 19:14 - 2017-07-29 07:48 - 000292192 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFault.exe
2017-08-09 19:14 - 2017-07-29 07:48 - 000122504 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFaultSecure.exe
2017-08-09 19:14 - 2017-07-29 07:44 - 000642008 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll
2017-08-09 19:14 - 2017-07-29 07:44 - 000380152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Faultrep.dll
2017-08-09 19:14 - 2017-07-29 07:43 - 000147808 _____ (Microsoft Corporation) C:\WINDOWS\system32\wermgr.exe
2017-08-09 19:14 - 2017-07-29 05:45 - 000353280 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppLockerCSP.dll
2017-08-09 19:14 - 2017-07-29 05:37 - 000049152 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBrokerUI.dll
2017-08-09 19:14 - 2017-07-29 05:24 - 000177152 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcdboot.exe
2017-08-09 19:14 - 2017-07-29 05:23 - 000171520 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWWIN.EXE
2017-08-09 19:14 - 2017-07-29 05:12 - 000370688 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack_win.dll
2017-08-09 19:14 - 2017-07-29 05:11 - 000715264 _____ (Microsoft Corporation) C:\WINDOWS\system32\GamePanel.exe
2017-08-09 19:14 - 2017-07-29 05:04 - 000452096 _____ (Microsoft Corporation) C:\WINDOWS\system32\werui.dll
2017-08-08 19:03 - 2017-08-08 19:03 - 000002432 _____ C:\Users\Teppo\Downloads\BOS Terminal Server (1).rdp
2017-08-08 16:50 - 2017-08-08 16:50 - 004723200 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerInstaller.exe
2017-07-23 20:23 - 2017-07-23 20:23 - 000093416 _____ C:\Users\Teppo\Desktop\BoardingPass SAS.pdf
2017-07-23 20:22 - 2017-07-23 20:22 - 000093416 _____ C:\Users\Teppo\Downloads\BoardingPass (1).pdf
2017-07-21 23:29 - 2017-07-21 23:29 - 000891256 _____ C:\Users\Teppo\Desktop\001.pdf
2017-07-21 23:28 - 2017-07-21 23:28 - 000802516 _____ C:\Users\Teppo\Desktop\005.pdf
2017-07-21 23:28 - 2017-07-21 23:28 - 000776309 _____ C:\Users\Teppo\Desktop\002.pdf
2017-07-21 23:28 - 2017-07-21 23:28 - 000737138 _____ C:\Users\Teppo\Desktop\003.pdf
2017-07-21 23:28 - 2017-07-21 23:28 - 000715074 _____ C:\Users\Teppo\Desktop\004.pdf
2017-07-19 20:24 - 2017-07-19 20:24 - 000003352 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-1148200332-1382918412-2715992946-1008
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-08-17 22:55 - 2017-06-30 17:37 - 000001126 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera Browser.lnk
2017-08-17 22:55 - 2017-05-30 22:34 - 000003944 _____ C:\WINDOWS\System32\Tasks\Opera scheduled Autoupdate 1465437342
2017-08-17 22:55 - 2016-06-08 18:54 - 000000000 ____D C:\Program Files (x86)\Opera
2017-08-17 22:48 - 2016-04-26 23:34 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2017-08-17 22:48 - 2012-04-25 12:25 - 000011764 __RSH C:\ProgramData\ntuser.pol
2017-08-17 22:47 - 2015-10-29 23:28 - 000524288 ___SH C:\WINDOWS\system32\config\BBI
2017-08-17 22:16 - 2016-07-03 21:01 - 000004142 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{53AF0094-3D5E-41EB-8625-F0C767A729C4}
2017-08-17 20:53 - 2016-05-26 12:18 - 000000000 ____D C:\Users\Teppo\AppData\Local\VirtualStore
2017-08-17 20:37 - 2015-10-30 00:24 - 000000000 ____D C:\WINDOWS\AppReadiness
2017-08-17 19:50 - 2016-06-08 18:23 - 000000000 ____D C:\Users\Teppo\AppData\Local\F-Secure
2017-08-17 19:41 - 2015-10-30 00:24 - 000000000 ____D C:\WINDOWS\system32\NDF
2017-08-17 19:29 - 2016-06-08 19:18 - 000000000 ____D C:\Users\Teppo\.thinkorswim
2017-08-17 19:29 - 2016-06-08 19:17 - 000000000 ____D C:\Program Files\thinkorswim
2017-08-17 19:21 - 2016-05-26 12:51 - 000002278 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-08-17 19:21 - 2016-05-26 12:51 - 000002266 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2017-08-17 19:14 - 2015-10-30 00:24 - 000000000 ___HD C:\Program Files\WindowsApps
2017-08-15 22:14 - 2015-10-30 00:24 - 000000000 ____D C:\WINDOWS\rescache
2017-08-15 19:54 - 2015-10-30 00:11 - 000000000 ____D C:\WINDOWS\CbsTemp
2017-08-15 18:46 - 2017-05-14 19:38 - 000000000 ____D C:\ProgramData\purevpn
2017-08-15 18:43 - 2016-05-26 12:18 - 000000000 ___RD C:\Users\Teppo\Virtual Machines
2017-08-15 18:43 - 2016-04-26 23:42 - 000000000 __RHD C:\Users\Public\AccountPictures
2017-08-14 22:02 - 2016-04-26 23:29 - 000392192 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2017-08-14 21:59 - 2015-10-30 00:24 - 000000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2017-08-14 21:59 - 2015-10-30 00:24 - 000000000 ____D C:\WINDOWS\system32\oobe
2017-08-14 21:59 - 2015-10-30 00:24 - 000000000 ____D C:\Program Files\Windows Photo Viewer
2017-08-14 21:59 - 2015-10-30 00:24 - 000000000 ____D C:\Program Files\Windows Defender
2017-08-14 21:59 - 2015-10-30 00:24 - 000000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2017-08-14 21:59 - 2015-10-30 00:24 - 000000000 ____D C:\Program Files (x86)\Windows Defender
2017-08-14 21:59 - 2015-10-30 00:21 - 000000000 ____D C:\WINDOWS\INF
2017-08-14 20:47 - 2016-06-13 22:50 - 000000000 ____D C:\WINDOWS\system32\MRT
2017-08-14 20:39 - 2012-04-25 13:26 - 140394280 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2017-08-14 20:10 - 2009-07-13 19:34 - 000000478 _____ C:\WINDOWS\win.ini
2017-08-08 16:51 - 2017-04-13 22:17 - 000004574 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player PPAPI Notifier
2017-08-08 16:50 - 2015-10-30 00:24 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed
2017-08-08 16:50 - 2015-10-30 00:24 - 000000000 ____D C:\WINDOWS\system32\Macromed
2017-08-08 16:36 - 2016-05-26 12:41 - 000004562 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task
2017-07-28 17:22 - 2016-12-16 21:51 - 000177648 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2017-07-28 17:22 - 2015-10-30 00:26 - 000835576 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2017-07-19 20:24 - 2016-06-08 09:17 - 000002373 _____ C:\Users\Teppo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2017-07-19 20:24 - 2016-06-08 09:17 - 000000000 ___RD C:\Users\Teppo\OneDrive
Files to move or delete:
====================
C:\WINDOWS\TEMP\E_S40EA.tmp
Some files in TEMP:
====================
2012-02-27 18:30 - 2012-02-27 18:30 - 008209056 _____ (Adobe Systems, Inc.) C:\Users\345cali\AppData\Local\Temp\InstallAX64.exe
2012-02-27 18:12 - 2012-02-27 18:12 - 008129184 _____ (Adobe Systems, Inc.) C:\Users\345cali\AppData\Local\Temp\InstallPlugin64.exe
2012-04-25 12:59 - 2012-04-25 12:59 - 000737280 _____ (Indigo Rose Corporation) C:\Users\345cali\AppData\Local\Temp\irsetup.exe
2012-03-21 12:56 - 2012-03-21 12:56 - 000908576 _____ (Sun Microsystems, Inc.) C:\Users\345cali\AppData\Local\Temp\jre-6u31-windows-i586-iftw-rv.exe
2012-04-25 12:46 - 2010-03-16 07:11 - 000149352 _____ (Microsoft Corporation) C:\Users\345cali\AppData\Local\Temp\ose00000.exe
2017-04-30 19:36 - 2017-04-30 19:36 - 000465920 _____ (Realtek Semiconductor Corp.) C:\Users\Teppo\AppData\Local\Temp\COMAP.EXE
2016-06-08 19:18 - 2016-06-08 19:18 - 000035680 _____ () C:\Users\Teppo\AppData\Local\Temp\i4jdel0.exe
2016-10-10 17:24 - 2017-02-20 18:50 - 030770176 _____ () C:\Users\Teppo\AppData\Local\Temp\SkypeSetup.exe
Some zero byte size files/folders:
==========================
C:\Windows\System32\kbd101c.dll
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2017-08-12 00:04