TechSpot

System 32 Bad Image problem FRST scan Log (FRST + Addition)

By Chris Waters
Jan 11, 2016
  1. Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:10-01-2015 01
    Ran by Chris (administrator) on CHRISTOPHERS (10-01-2016 19:00:29)
    Running from C:\Users\Chris\Downloads
    Loaded Profiles: Chris (Available Profiles: Chris)
    Platform: Windows 10 Home Version 1511 (X64) Language: English (United States)
    Internet Explorer Version 11 (Default browser: Edge)
    Boot Mode: Normal
    Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

    ==================== Processes (Whitelisted) =================

    (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

    (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
    (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
    (Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
    () C:\MSI\Smart Utilities\SuperRAIDSvc.exe
    (Eastman Kodak Company) C:\Program Files (x86)\Kodak\AiO\Center\EKAiOHostService.exe
    (Realtek) C:\Program Files (x86)\REALTEK\11n USB Wireless LAN Utility\RtlService.exe
    (Razer Inc.) C:\Program Files (x86)\Razer\Razer Cortex\RzKLService.exe
    (Eastman Kodak Company) C:\Program Files (x86)\Kodak\AiO\StatusMonitor\EKPrinterSDK.exe
    (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
    (White Sky, Inc.) C:\Program Files (x86)\Constant Guard Protection Suite\IDVaultSvc.exe
    () C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe
    () C:\Program Files (x86)\MSI\Command Center\MSIControlService.exe
    (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
    () C:\Program Files (x86)\NETGEAR\WNDA3100v2\WifiSvc.exe
    (Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
    (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
    (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    (AOMEI Tech Co., Ltd.) C:\Program Files (x86)\AOMEI Backupper Professional Edition 2.2\ABService.exe
    (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
    (Qualcomm Atheros) C:\Program Files\Qualcomm Atheros\Network Manager\KillerService.exe
    (MSI) C:\Program Files (x86)\MSI\Fast Boot\FastBootService.exe
    (MICRO-STAR INTERNATIONAL CO., LTD.) C:\Program Files (x86)\MSI\MSITrigger\MSI_Trigger_Service.exe
    (Micro-Star International) C:\Program Files (x86)\MSI\Live Update\MSI_LiveUpdate_Service.exe
    (MSI) C:\Program Files (x86)\MSI\Super Charger\ChargeService.exe
    (Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
    (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.29.1\GoogleCrashHandler.exe
    (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.29.1\GoogleCrashHandler64.exe
    (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
    (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
    (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
    () C:\Program Files (x86)\MSI\Command Center\CPU\MSICPUService.exe
    (MSI CO.,LTD.) C:\Program Files (x86)\MSI\Command Center\CPU\CPU_Ratio\CPU_Ratio.exe
    (Realtek Semiconductor Corp.) C:\Program Files (x86)\REALTEK\11n USB Wireless LAN Utility\RtWLan.exe
    (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
    () C:\Program Files (x86)\Avg Secure Update\AVG-Secure-Search-Update_0414c.exe
    (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
    (Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
    (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
    (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
    (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
    (Microsoft Corporation) C:\Windows\System32\rundll32.exe
    () C:\Users\Chris\AppData\Roaming\SWClient\swclient.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Spotify Ltd) C:\Users\Chris\AppData\Roaming\Spotify\SpotifyWebHelper.exe
    (Flux Software LLC) C:\Users\Chris\AppData\Local\FluxSoftware\Flux\flux.exe
    (Creative Technology Ltd) C:\Program Files (x86)\Creative\Sound Blaster Cinema\Sound Blaster Cinema\SBCinema.exe
    (MSI) C:\Program Files (x86)\MSI\Super Charger\Super Charger.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    () C:\Program Files\Qualcomm Atheros\Network Manager\NetworkManager.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Microsoft Corporation) C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonX86\Microsoft Shared\OFFICE15\CSISYNCCLIENT.EXE
    (Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
    () C:\Users\Chris\AppData\Roaming\Dashlane\DashlanePlugin.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    () C:\Program Files\WindowsApps\Microsoft.Messaging_2.12.15004.0_x86__8wekyb3d8bbwe\SkypeHost.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Microsoft Corporation) C:\Windows\System32\WWAHost.exe
    () C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.1601.36020.0_x64__8wekyb3d8bbwe\Calculator.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
    (Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
    (Valve Corporation) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
    (Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
    (Valve Corporation) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
    (Valve Corporation) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
    (Valve Corporation) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
    (Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
    (Microsoft Corporation) C:\Program Files\Windows Defender\MSASCui.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe


    ==================== Registry (Whitelisted) ===========================

    (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

    HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8492800 2015-06-24] (Realtek Semiconductor)
    HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
    HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2655520 2015-10-11] (NVIDIA Corporation)
    HKLM\...\Run: [ShadowPlay] => C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\nvspcap64.dll,ShadowPlayOnSystemStart
    HKLM\...\Run: [MBCfg64] => C:\WINDOWS\system32\RunDLL32.exe C:\WINDOWS\system32\MBCfg64.dll,RunDLLEntry MBCfg64
    HKLM-x32\...\Run: [LWS] => C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe [204136 2012-09-12] (Logitech Inc.)
    HKLM-x32\...\Run: [PWRISOVM.EXE] => C:\Program Files (x86)\PowerISO\PWRISOVM.EXE [337432 2013-07-21] (Power Software Ltd)
    HKLM-x32\...\Run: [amd_dc_opt] => C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe [77824 2008-07-22] (AMD)
    HKLM-x32\...\Run: [] => [X]
    HKLM-x32\...\Run: [Razer Synapse] => C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe [585048 2014-05-31] (Razer Inc.)
    HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.)
    HKLM-x32\...\Run: [Sound Blaster Cinema] => C:\Program Files (x86)\Creative\Sound Blaster Cinema\Sound Blaster Cinema\SBCinema.exe [711680 2013-08-16] (Creative Technology Ltd)
    HKLM-x32\...\Run: [UpdReg] => C:\WINDOWS\UpdReg.EXE
    HKLM-x32\...\Run: [Super Charger] => C:\Program Files (x86)\MSI\Super Charger\Super Charger.exe [1047536 2014-04-08] (MSI)
    HKLM-x32\...\Run: [Fast Boot] => C:\Program Files (x86)\MSI\Fast Boot\StartFastBoot.exe [764472 2012-09-19] ()
    HKLM-x32\...\Run: [Command Center] => C:\Program Files (x86)\MSI\Command Center\StartCommandCenter.exe [814064 2014-04-02] ()
    HKLM-x32\...\Run: [Live Update] => C:\Program Files (x86)\MSI\Live Update\StartLiveUpdate.exe [579056 2014-03-28] (Micro-Star International)
    HKLM-x32\...\Run: [EKStatusMonitor] => C:\Program Files (x86)\Kodak\AiO\StatusMonitor\EKStatusMonitor.exe [2750840 2013-12-11] (Eastman Kodak Company)
    HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [157480 2014-10-15] (Apple Inc.)
    HKLM-x32\...\Run: [ospd_us_738] => [X]
    HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [334896 2015-06-08] (Oracle Corporation)
    HKU\S-1-5-21-905238947-2220377667-1876713056-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\Steam.exe [3013712 2015-12-14] (Valve Corporation)
    HKU\S-1-5-21-905238947-2220377667-1876713056-1001\...\Run: [ooVoo.exe] => C:\Program Files (x86)\ooVoo\oovoo.exe [35239488 2013-06-20] (ooVoo LLC)
    HKU\S-1-5-21-905238947-2220377667-1876713056-1001\...\Run: [SWClient] => C:\Users\Chris\AppData\Roaming\SWClient\swclient.exe [6257664 2013-02-09] ()
    HKU\S-1-5-21-905238947-2220377667-1876713056-1001\...\Run: [AVG-Secure-Search-Update_0414c] => C:\Program Files (x86)\Avg Secure Update\AVG-Secure-Search-Update_0414c.exe [2725912 2014-04-21] ()
    HKU\S-1-5-21-905238947-2220377667-1876713056-1001\...\Run: [Dashlane] => C:\Users\Chris\AppData\Roaming\Dashlane\Dashlane.exe [227712 2015-10-23] ()
    HKU\S-1-5-21-905238947-2220377667-1876713056-1001\...\Run: [uTorrent] => C:\Users\Chris\AppData\Roaming\uTorrent\uTorrent.exe [1329744 2014-08-05] (BitTorrent Inc.)
    HKU\S-1-5-21-905238947-2220377667-1876713056-1001\...\Run: [DashlanePlugin] => C:\Users\Chris\AppData\Roaming\Dashlane\DashlanePlugin.exe [285568 2015-10-23] ()
    HKU\S-1-5-21-905238947-2220377667-1876713056-1001\...\Run: [GalaxyClient] => C:\Program Files (x86)\GalaxyClient\GalaxyClient.exe [7247416 2015-07-17] (GOG.com)
    HKU\S-1-5-21-905238947-2220377667-1876713056-1001\...\Run: [Spotify Web Helper] => C:\Users\Chris\AppData\Roaming\Spotify\SpotifyWebHelper.exe [2346096 2015-12-16] (Spotify Ltd)
    HKU\S-1-5-21-905238947-2220377667-1876713056-1001\...\Run: [Spotify] => C:\Users\Chris\AppData\Roaming\Spotify\Spotify.exe [8387696 2015-12-16] (Spotify Ltd)
    HKU\S-1-5-21-905238947-2220377667-1876713056-1001\...\Run: [f.lux] => C:\Users\Chris\AppData\Local\FluxSoftware\Flux\flux.exe [1017224 2013-10-23] (Flux Software LLC)
    HKU\S-1-5-21-905238947-2220377667-1876713056-1001\...\RunOnce: [Uninstall C:\Users\Chris\AppData\Local\Microsoft\OneDrive\17.3.6201.1019_1\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Chris\AppData\Local\Microsoft\OneDrive\17.3.6201.1019_1\amd64"
    HKU\S-1-5-21-905238947-2220377667-1876713056-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\Ribbons.scr [149504 2015-10-30] (Microsoft Corporation)
    AppInit_DLLs: C:\PROGRA~2\KEYCRY~1\KE6D28~1.DLL => C:\Program Files (x86)\KeyCryptSDK\KeyCrypt64(2).dll [88376 2013-07-24] (Zemana Ltd.)
    ShellIconOverlayIdentifiers: [ GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2015-11-04] (Google)
    ShellIconOverlayIdentifiers: [ GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2015-11-04] (Google)
    ShellIconOverlayIdentifiers: [ GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2015-11-04] (Google)
    ShellIconOverlayIdentifiers: [###MegaShellExtPending] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => C:\Users\Chris\AppData\Local\MEGAsync\ShellExtX64.dll [2014-05-01] ()
    ShellIconOverlayIdentifiers: [###MegaShellExtSynced] -> {05B38830-F4E9-4329-978B-1DD28605D202} => C:\Users\Chris\AppData\Local\MEGAsync\ShellExtX64.dll [2014-05-01] ()
    ShellIconOverlayIdentifiers: [###MegaShellExtSyncing] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => C:\Users\Chris\AppData\Local\MEGAsync\ShellExtX64.dll [2014-05-01] ()
    ShellIconOverlayIdentifiers-x32: [ SkyDrivePro1 (ErrorConflict)] -> {8BA85C75-763B-4103-94EB-9470F12FE0F7} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2015-12-15] (Microsoft Corporation)
    ShellIconOverlayIdentifiers-x32: [ SkyDrivePro2 (SyncInProgress)] -> {CD55129A-B1A1-438E-A425-CEBC7DC684EE} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2015-12-15] (Microsoft Corporation)
    ShellIconOverlayIdentifiers-x32: [ SkyDrivePro3 (InSync)] -> {E768CD3B-BDDC-436D-9C13-E1B39CA257B1} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2015-12-15] (Microsoft Corporation)
    ShellIconOverlayIdentifiers-x32: [###MegaShellExtPending] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => C:\Users\Chris\AppData\Local\MEGAsync\ShellExtX32.dll [2014-05-01] ()
    ShellIconOverlayIdentifiers-x32: [###MegaShellExtSynced] -> {05B38830-F4E9-4329-978B-1DD28605D202} => C:\Users\Chris\AppData\Local\MEGAsync\ShellExtX32.dll [2014-05-01] ()
    ShellIconOverlayIdentifiers-x32: [###MegaShellExtSyncing] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => C:\Users\Chris\AppData\Local\MEGAsync\ShellExtX32.dll [2014-05-01] ()
    Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Constant Guard.lnk [2013-10-24]
    ShortcutTarget: Constant Guard.lnk -> C:\Program Files (x86)\Constant Guard Protection Suite\IDVault.exe (White Sky, Inc.)
    Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Killer Network Manager.lnk [2014-09-06]
    ShortcutTarget: Killer Network Manager.lnk -> C:\Windows\Installer\{4692B750-DE88-4DCF-9163-745AF5604B24}\NetworkManager.exe_130C27D738F34C89BDDF21BCFD74B56D.exe (Flexera Software LLC)
    Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\NETGEAR WNDA3100v2 Genie.lnk [2013-06-20]
    ShortcutTarget: NETGEAR WNDA3100v2 Genie.lnk -> C:\Program Files (x86)\NETGEAR\WNDA3100v2\WNDA3100v2.exe ()
    Startup: C:\Users\Chris\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\GameStop Now.lnk [2013-09-01]
    ShortcutTarget: GameStop Now.lnk -> C:\Program Files (x86)\GameStop App\Now\GameStopNow.exe (GameStop Corp.)
    Startup: C:\Users\Chris\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MEGAsync.lnk [2015-07-22]
    ShortcutTarget: MEGAsync.lnk -> C:\Users\Chris\AppData\Local\MEGAsync\MEGAsync.exe (Mega Limited)

    ==================== Internet (Whitelisted) ====================

    (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

    Tcpip\Parameters: [DhcpNameServer] 75.75.75.75 75.75.76.76
    Tcpip\..\Interfaces\{efe8e331-10e7-4c7b-8281-b54d8c8fd35f}: [DhcpNameServer] 75.75.75.75 75.75.76.76

    Internet Explorer:
    ==================
    HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://start.mysearchdial.com/?f=1&a=frg01_14_25_ch&cd=2XzuyEtN2Y1L1Qzu0BzzzyyByD0AtBtAtBzzzztBzy0BtDyEtN0D0Tzu0SzzzyzytN1L2XzutBtFtBtCtFyEtFtCtN1L1CzutCyEtBzytDyD1V1RtN1L1G1B1V1N2Y1L1Qzu2SyC0AtC0EtD0F0DtCtGyEtBzy0CtGyBtBzz0CtGtAyBzztAtGyC0D0F0FyC0B0F0FyBtAyDzy2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyEyC0DyD0C0EtDtBtGyDtD0F0CtGtAyEzzzytGyC0A0AtDtGyEyDyE0FzytC0AtD0E0DyDzz2QtN1B1L1H1Ezu1O2U1M1B&cr=1435966762&ir=
    HKU\S-1-5-21-905238947-2220377667-1876713056-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://t.msn.com/
    SearchScopes: HKLM -> {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL =
    SearchScopes: HKLM -> {77AA745B-F4F8-45DA-9B14-61D2D95054C8} URL =
    SearchScopes: HKU\S-1-5-21-905238947-2220377667-1876713056-1001 -> DefaultScope {3BD44F0E-0596-4008-AEE0-45D47E3A8F0E} URL = hxxp://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=frg01_14_25_ch&cd=2XzuyEtN2Y1L1Qzu0BzzzyyByD0AtBtAtBzzzztBzy0BtDyEtN0D0Tzu0SzzzyzytN1L2XzutBtFtBtCtFyEtFtCtN1L1CzutCyEtBzytDyD1V1RtN1L1G1B1V1N2Y1L1Qzu2SyC0AtC0EtD0F0DtCtGyEtBzy0CtGyBtBzz0CtGtAyBzztAtGyC0D0F0FyC0B0F0FyBtAyDzy2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyEyC0DyD0C0EtDtBtGyDtD0F0CtGtAyEzzzytGyC0A0AtDtGyEyDyE0FzytC0AtD0E0DyDzz2QtN1B1L1H1Ezu1O2U1M1B&cr=1435966762&ir=
    SearchScopes: HKU\S-1-5-21-905238947-2220377667-1876713056-1001 -> {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = hxxp://www.trovi.com/Results.aspx?gd=&ctid=CT3323128&octid=EB_ORIGINAL_CTID&ISID=M52CF5026-3AFE-4666-8F5F-AC78D1B243C0&SearchSource=58&CUI=&UM=8&UP=SPB266FE4C-8A81-40AF-A35C-639960EDD6A2&q={searchTerms}&SSPV=
    SearchScopes: HKU\S-1-5-21-905238947-2220377667-1876713056-1001 -> {3BD44F0E-0596-4008-AEE0-45D47E3A8F0E} URL = hxxp://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=frg01_14_25_ch&cd=2XzuyEtN2Y1L1Qzu0BzzzyyByD0AtBtAtBzzzztBzy0BtDyEtN0D0Tzu0SzzzyzytN1L2XzutBtFtBtCtFyEtFtCtN1L1CzutCyEtBzytDyD1V1RtN1L1G1B1V1N2Y1L1Qzu2SyC0AtC0EtD0F0DtCtGyEtBzy0CtGyBtBzz0CtGtAyBzztAtGyC0D0F0FyC0B0F0FyBtAyDzy2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyEyC0DyD0C0EtDtBtGyDtD0F0CtGtAyEzzzytGyC0A0AtDtGyEyDyE0FzytC0AtD0E0DyDzz2QtN1B1L1H1Ezu1O2U1M1B&cr=1435966762&ir=
    SearchScopes: HKU\S-1-5-21-905238947-2220377667-1876713056-1001 -> {77AA745B-F4F8-45DA-9B14-61D2D95054C8} URL = hxxp://search.xfinity.com/?cat=web&con=toolbar&cid=xfstart_tech_search&q={searchTerms}
    SearchScopes: HKU\S-1-5-21-905238947-2220377667-1876713056-1001 -> {944DD3A0-792B-4828-AB6C-5C063459D00C} URL = hxxp://search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=617686&p={searchTerms}
    BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2015-12-15] (Microsoft Corporation)
    BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_51\bin\ssv.dll [2015-07-26] (Oracle Corporation)
    BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2015-12-15] (Microsoft Corporation)
    BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_51\bin\jp2ssv.dll [2015-07-26] (Oracle Corporation)
    BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll [2015-12-15] (Microsoft Corporation)
    BHO-x32: XFINITY Toolbar -> {4b9bcce8-a70b-402a-a7e1-db96831ee26f} -> C:\Program Files (x86)\xfin_portal\comcastdx.dll [2013-01-30] ()
    BHO-x32: Constant Guard Protection Suite -> {B84CDBE7-1B46-494B-A188-01D4C52DEB61} -> C:\ProgramData\White Sky, Inc\ID Vault\IEBHO1.13.820.2\NativeBHO.dll [2013-08-20] (WhiteSky)
    BHO-x32: Updater For XFIN_PORTAL -> {bb46be07-13eb-4c49-b0f0-fc78b9ea4983} -> C:\Program Files (x86)\xfin_portal\auxi\comcastAu.dll [2013-01-30] (Visicom Media)
    BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2015-12-15] (Microsoft Corporation)
    Toolbar: HKLM-x32 - XFINITY Toolbar - {4b9bcce8-a70b-402a-a7e1-db96831ee26f} - C:\Program Files (x86)\xfin_portal\comcastdx.dll [2013-01-30] ()
    Toolbar: HKLM-x32 - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
    Toolbar: HKU\S-1-5-21-905238947-2220377667-1876713056-1001 -> No Name - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No File
    Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL [2015-07-22] (Microsoft Corporation)
    Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)

    FireFox:
    ========
    FF ProfilePath: C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\mshnp4wc.default
    FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_20_0_0_267.dll [2015-12-29] ()
    FF Plugin: @java.com/DTPlugin,version=10.25.2 -> C:\WINDOWS\system32\npDeployJava1.dll [2013-06-20] (Oracle Corporation)
    FF Plugin: @java.com/JavaPlugin,version=11.51.2 -> C:\Program Files\Java\jre1.8.0_51\bin\plugin2\npjp2.dll [2015-07-26] (Oracle Corporation)
    FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.41105.0\npctrl.dll [2015-11-04] ( Microsoft Corporation)
    FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_20_0_0_267.dll [2015-12-29] ()
    FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-02-18] ()
    FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 -> C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll [2011-11-03] (ESN Social Software AB)
    FF Plugin-x32: @esn/esnlaunch,version=2.3.0 -> C:\Program Files (x86)\Battlelog Web Plugins\2.3.0\npesnlaunch.dll [2013-09-25] (ESN Social Software AB)
    FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2013-10-07] (Google)
    FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2014-02-19] (Intel Corporation)
    FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2014-02-19] (Intel Corporation)
    FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2015-11-03] (Microsoft Corporation)
    FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.41105.0\npctrl.dll [2015-11-04] ( Microsoft Corporation)
    FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [2013-07-10] (Microsoft Corporation)
    FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2015-11-05] (NVIDIA Corporation)
    FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2015-11-05] (NVIDIA Corporation)
    FF Plugin-x32: @raidcall.en/RCplugin -> C:\Users\Chris\AppData\Roaming\raidcall\plugins\nprcplugin.dll [2013-03-30] (Raidcall)
    FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-03] (Google Inc.)
    FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-03] (Google Inc.)
    FF Plugin HKU\S-1-5-21-905238947-2220377667-1876713056-1001: @doubletwist.com/NPPodcast -> C:\Program Files (x86)\Common Files\doubleTwist\NPPodcast.dll [No File]
    FF Plugin HKU\S-1-5-21-905238947-2220377667-1876713056-1001: @onlive.com/OnLiveGameClientDetector,version=1.0.0 -> C:\Program Files (x86)\OnLive\Plugin\npolgdet.dll [2013-12-02] (OnLive)

    Chrome:
    =======
    CHR HomePage: Profile 4 -> hxxp://www.search.ask.com/?gct=hp
    CHR StartupUrls: Profile 4 -> "hxxp://www.google.com/ig/redirectdomain?brand=TSND&bmod=TSND","hxxp://start.mysearchdial.com/?f=1&a=frg01_14_25_ch&cd=2XzuyEtN2Y1L1Qzu0BzzzyyByD0AtBtAtBzzzztBzy0BtDyEtN0D0Tzu0SzzzyzytN1L2XzutBtFtBtCtFyEtFtCtN1L1CzutCyEtBzytDyD1V1RtN1L1G1B1V1N2Y1L1Qzu2SyC0AtC0EtD0F0DtCtGyEtBzy0CtGyBtBzz0CtGtAyBzztAtGyC0D0F0FyC0B0F0FyBtAyDzy2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyEyC0DyD0C0EtDtBtGyDtD0F0CtGtAyEzzzytGyC0A0AtDtGyEyDyE0FzytC0AtD0E0DyDzz2QtN1B1L1H1Ezu1O2U1M1B&cr=1435966762&ir=","hxxp://www.google.com"
    CHR Session Restore: Profile 4 -> is enabled.
    CHR Profile: C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Default
    CHR Profile: C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Profile 4
    CHR Extension: (BetterTTV) - C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\ajopnjidmegmdimjlfnijceegpefgped [2015-07-23]
    CHR Extension: (Google Docs) - C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\aohghmighlieiainnegkcijnfilokake [2015-07-23]
    CHR Extension: (Google Drive) - C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-21]
    CHR Extension: (MEGA) - C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\bigefpfhnfcobdlfbedofhhaibnlghod [2015-12-22]
    CHR Extension: (YouTube) - C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-24]
    CHR Extension: (Adblock Plus) - C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2016-01-05]
    CHR Extension: (Google Search) - C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-26]
    CHR Extension: (Dashlane) - C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\fdjamakpfbbddfjaooikfcpapjohcfmg [2015-12-20]
    CHR Extension: (Google Docs Offline) - C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-11-17]
    CHR Extension: (AdBlock) - C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2016-01-08]
    CHR Extension: (ooVoo Video Chat) - C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\nimgeceabhadboepjjddfhepideeilej [2014-04-16]
    CHR Extension: (Chrome Web Store Payments) - C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-07-23]
    CHR Extension: (Gmail) - C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-07-23]
    CHR HKLM\...\Chrome\Extension: [hkhkiakolggnnicallabhkobalpeplpi] - <no Path/update_url>
    CHR HKLM\...\Chrome\Extension: [pflphaooapbgpeakohlggbpidpppgdff] - hxxps://clients2.google.com/service/update2/crx
    CHR HKU\S-1-5-21-905238947-2220377667-1876713056-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [pflphaooapbgpeakohlggbpidpppgdff] - hxxps://clients2.google.com/service/update2/crx
    CHR HKLM-x32\...\Chrome\Extension: [hglljpndoeopcpehilglkbnincooinnb] - C:\Users\Chris\AppData\Local\Flvto Plugin for Google Chrome\the_extension.crx [2013-08-30]
    CHR HKLM-x32\...\Chrome\Extension: [hkhkiakolggnnicallabhkobalpeplpi] - <no Path/update_url>
    CHR HKLM-x32\...\Chrome\Extension: [pflphaooapbgpeakohlggbpidpppgdff] - hxxps://clients2.google.com/service/update2/crx

    ==================== Services (Whitelisted) ========================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    R2 Backupper Service; C:\Program Files (x86)\AOMEI Backupper Professional Edition 2.2\ABService.exe [29912 2014-12-24] (AOMEI Tech Co., Ltd.)
    S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [49152 2013-09-22] () [File not signed]
    R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2802360 2015-11-24] (Microsoft Corporation)
    S3 GalaxyClientService; C:\Program Files (x86)\GalaxyClient\GalaxyClientService.exe [1718840 2015-07-17] (GOG.com)
    S3 GalaxyCommunication; C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe [6677048 2015-07-02] (GOG.com)
    R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1156384 2015-10-11] (NVIDIA Corporation)
    R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [24888 2015-07-26] (Hewlett-Packard Company)
    S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [887232 2014-01-31] (Intel(R) Corporation)
    R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [154584 2014-02-19] (Intel Corporation)
    S3 MSIBIOSData_CC; C:\Program Files (x86)\MSI\Command Center\BIOSData\MSIBIOSDataService.exe [2101248 2014-03-24] (MSI) [File not signed]
    S3 MSIClock_CC; C:\Program Files (x86)\MSI\Command Center\ClockGen\MSIClockService.exe [313856 2014-03-26] () [File not signed]
    S3 MSICOMM_CC; C:\Program Files (x86)\MSI\Command Center\MSICommService.exe [2117120 2014-03-24] () [File not signed]
    R3 MSICPU_CC; C:\Program Files (x86)\MSI\Command Center\CPU\MSICPUService.exe [4115456 2014-03-31] () [File not signed]
    R2 MSICTL_CC; C:\Program Files (x86)\MSI\Command Center\MSIControlService.exe [1990144 2014-04-02] () [File not signed]
    S3 MSIDDR_CC; C:\Program Files (x86)\MSI\Command Center\DDR\MSIDDRService.exe [2235904 2014-03-26] () [File not signed]
    S3 MSISaveLoad_CC; C:\Program Files (x86)\MSI\Command Center\MSISaveLoadService.exe [3957760 2014-03-24] () [File not signed]
    S3 MSISuperIO_CC; C:\Program Files (x86)\MSI\Command Center\SuperIO\MSISuperIOService.exe [540672 2014-03-24] () [File not signed]
    S3 MSIWMI_CC; C:\Program Files (x86)\MSI\Command Center\MSIWMIService.exe [183296 2014-03-24] () [File not signed]
    R2 MSI_FastBoot; C:\Program Files (x86)\MSI\Fast Boot\FastBootService.exe [103992 2012-10-26] (MSI)
    R2 MSI_LiveUpdate_Service; C:\Program Files (x86)\MSI\Live Update\MSI_LiveUpdate_Service.exe [83952 2014-03-27] (Micro-Star International)
    R2 MSI_SuperCharger; C:\Program Files (x86)\MSI\Super Charger\ChargeService.exe [162800 2014-03-17] (MSI)
    R2 MSI_Trigger_Service; C:\Program Files (x86)\MSI\MSITrigger\MSI_Trigger_Service.exe [30240 2013-09-26] (MICRO-STAR INTERNATIONAL CO., LTD.)
    R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1873696 2015-10-11] (NVIDIA Corporation)
    R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [5568288 2015-10-11] (NVIDIA Corporation)
    S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2078216 2015-10-08] (Electronic Arts)
    R2 Qualcomm Atheros Killer Service V2; C:\Program Files\Qualcomm Atheros\Network Manager\KillerService.exe [344576 2014-04-17] (Qualcomm Atheros) [File not signed]
    R2 Razer Game Scanner Service; C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe [187048 2015-06-23] ()
    R2 Realtek11nSU; C:\Program Files (x86)\REALTEK\11n USB Wireless LAN Utility\RtlService.exe [45056 2010-01-21] (Realtek) [File not signed]
    R2 RzKLService; C:\Program Files (x86)\Razer\Razer Cortex\RzKLService.exe [129168 2015-07-14] (Razer Inc.)
    R2 SuperRAIDSvc; C:\MSI\Smart Utilities\SuperRAIDSvc.exe [24048 2014-04-03] ()
    R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2015-10-30] (Microsoft Corporation)
    R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-10-30] (Microsoft Corporation)
    R2 WSWNDA3100v2; C:\Program Files (x86)\NETGEAR\WNDA3100v2\WifiSvc.exe [303360 2011-12-14] ()

    ===================== Drivers (Whitelisted) ==========================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    R0 ambakdrv; C:\Windows\System32\ambakdrv.sys [30648 2013-05-07] () [File not signed]
    R2 ammntdrv; C:\WINDOWS\system32\ammntdrv.sys [151480 2013-05-07] () [File not signed]
    R2 amwrtdrv; C:\WINDOWS\system32\amwrtdrv.sys [17848 2013-02-06] () [File not signed]
    R1 AntiLog32; C:\Windows\system32\drivers\AntiLog64.sys [49240 2013-10-24] (Zemana Ltd.)
    R1 BfLwf; C:\Windows\system32\DRIVERS\bwcW8x64.sys [82608 2014-04-10] (Qualcomm Atheros, Inc.)
    R2 iocbios2; C:\Program Files (x86)\Intel\Extreme Tuning Utility\Drivers\IocDriver\64bit\iocbios2.sys [28912 2014-02-18] (Intel Corporation)
    R3 ISCT; C:\Windows\System32\drivers\ISCTD.sys [44744 2014-05-27] ()
    R3 Ke2200; C:\Windows\System32\drivers\e22w8x64.sys [130224 2014-03-27] (Qualcomm Atheros, Inc.)
    R3 keycrypt; C:\Windows\System32\DRIVERS\KeyCrypt64.sys [25056 2013-07-24] (Zemana Ltd.)
    R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [129312 2014-09-30] (Intel Corporation)
    R1 MpKsl84b48713; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{948181E9-8D83-4C49-9619-CBBC4C32C728}\MpKsl84b48713.sys [44928 2016-01-10] (Microsoft Corporation)
    S3 NPF; C:\Windows\system32\DRIVERS\npf.sys [47632 2010-02-03] (CACE Technologies, Inc.)
    S3 NTIOLib_1_0_4; C:\Program Files (x86)\MSI\Live Update\NTIOLib_X64.sys [14136 2010-10-22] (MSI)
    S3 NTIOLib_MSIClock_CC; C:\Program Files (x86)\MSI\Command Center\ClockGen\NTIOLib_X64.sys [13368 2012-11-20] (MSI)
    S3 NTIOLib_MSICOMM_CC; C:\Program Files (x86)\MSI\Command Center\NTIOLib_X64.sys [13368 2012-11-19] (MSI)
    R3 NTIOLib_MSICPU_CC; C:\Program Files (x86)\MSI\Command Center\CPU\NTIOLib_X64.sys [13368 2012-11-20] (MSI)
    S3 NTIOLib_MSIDDR_CC; C:\Program Files (x86)\MSI\Command Center\DDR\NTIOLib_X64.sys [13368 2012-11-26] (MSI)
    S3 NTIOLib_MSIFrequency_CC; C:\Program Files (x86)\MSI\Command Center\ClockGen\CPU_Frequency\NTIOLib_X64.sys [13368 2012-11-20] (MSI)
    R3 NTIOLib_MSIRatio_CC; C:\Program Files (x86)\MSI\Command Center\CPU\CPU_Ratio\NTIOLib_X64.sys [13368 2012-11-20] (MSI)
    S3 NTIOLib_MSISMB_CC; C:\Program Files (x86)\MSI\Command Center\SMBus\NTIOLib_X64.sys [13368 2012-11-19] (MSI)
    R3 NTIOLib_MSISuperIO_CC; C:\Program Files (x86)\MSI\Command Center\SuperIO\NTIOLib_X64.sys [13368 2012-11-19] (MSI)
    R3 NTIOLib_MSI_RAID; C:\MSI\Smart Utilities\NTIOLib_X64.sys [13808 2014-03-17] (MSI)
    R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [20768 2015-10-11] (NVIDIA Corporation)
    R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [50472 2015-08-10] (NVIDIA Corporation)
    S3 RZMAELSTROMVADService; C:\Windows\system32\drivers\RzMaelstromVAD.sys [32768 2014-05-23] (Windows (R) Win 7 DDK provider)
    R2 rzpmgrk; C:\WINDOWS\system32\drivers\rzpmgrk.sys [37184 2015-06-12] (Razer, Inc.)
    S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation)
    R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation)
    R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation)
    R3 XtuAcpiDriver; C:\Windows\System32\drivers\XtuAcpiDriver.sys [63840 2015-06-06] (Intel Corporation)
    R1 {572f484b-455f-44b0-9d6a-da3ad2071365}w64; C:\Windows\System32\drivers\{572f484b-455f-44b0-9d6a-da3ad2071365}w64.sys [61120 2014-04-24] (StdLib)
    R1 {646e947e-f0e6-4d0e-b21e-d62ca97183e2}Gw64; C:\Windows\System32\drivers\{646e947e-f0e6-4d0e-b21e-d62ca97183e2}Gw64.sys [61120 2014-07-08] (StdLib)

    ==================== NetSvcs (Whitelisted) ===================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


    ==================== One Month Created files and folders ========

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2016-01-10 19:00 - 2016-01-10 19:01 - 00036294 _____ C:\Users\Chris\Downloads\FRST.txt
    2016-01-10 19:00 - 2016-01-10 19:00 - 00000000 ____D C:\FRST
    2016-01-10 18:59 - 2016-01-10 19:00 - 02370560 _____ (Farbar) C:\Users\Chris\Downloads\FRST64.exe
    2016-01-10 18:53 - 2016-01-10 18:53 - 00001124 _____ C:\Users\Public\Desktop\GOG Galaxy.lnk
    2016-01-10 18:51 - 2016-01-10 18:53 - 72416536 _____ (GOG.com ) C:\Users\Chris\Downloads\setup_galaxy_1.0.6.31.0 (1).exe
    2016-01-10 18:44 - 2016-01-10 18:46 - 104417712 _____ (GOG.com ) C:\Users\Chris\Downloads\setup_galaxy_1.1.5.28.exe
    2016-01-08 22:34 - 2016-01-08 22:34 - 00000000 ___HD C:\OneDriveTemp
    2016-01-02 13:41 - 2016-01-02 13:41 - 00000000 ____D C:\Users\Chris\Documents\KoeiTecmo
    2015-12-29 04:24 - 2015-12-29 04:24 - 09479872 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerInstaller.exe
    2015-12-28 18:43 - 2015-12-28 18:44 - 00000000 ____D C:\c88103d685bb1b7a0d
    2015-12-20 17:54 - 2015-12-20 18:17 - 00000000 ____D C:\Users\Chris\Desktop\power point template
    2015-12-20 17:53 - 2015-12-20 17:53 - 00203278 _____ C:\Users\Chris\Downloads\2218_chemical_experiment.zip
    2015-12-18 22:25 - 2015-12-31 19:06 - 00000000 ____D C:\Users\Chris\Desktop\music folder for CD
    2015-12-17 18:11 - 2015-12-06 23:57 - 00973664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll
    2015-12-17 18:11 - 2015-12-06 23:55 - 01281376 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll
    2015-12-17 18:11 - 2015-12-06 23:49 - 00412512 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifitask.exe
    2015-12-17 18:11 - 2015-12-06 23:48 - 02544256 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
    2015-12-17 18:11 - 2015-12-06 23:48 - 02180136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
    2015-12-17 18:11 - 2015-12-06 23:48 - 01299504 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfnetsrc.dll
    2015-12-17 18:11 - 2015-12-06 23:48 - 01155944 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfasfsrcsnk.dll
    2015-12-17 18:11 - 2015-12-06 23:48 - 01118208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfnetsrc.dll
    2015-12-17 18:11 - 2015-12-06 23:48 - 01092456 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll
    2015-12-17 18:11 - 2015-12-06 23:48 - 01065080 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll
    2015-12-17 18:11 - 2015-12-06 23:48 - 01020096 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsrcsnk.dll
    2015-12-17 18:11 - 2015-12-06 23:48 - 00983464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfasfsrcsnk.dll
    2015-12-17 18:11 - 2015-12-06 23:48 - 00884256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll
    2015-12-17 18:11 - 2015-12-06 23:48 - 00823264 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll
    2015-12-17 18:11 - 2015-12-06 23:48 - 00794888 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfds.dll
    2015-12-17 18:11 - 2015-12-06 23:48 - 00696160 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupEngine.dll
    2015-12-17 18:11 - 2015-12-06 23:48 - 00670928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfds.dll
    2015-12-17 18:11 - 2015-12-06 23:48 - 00526856 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfreadwrite.dll
    2015-12-17 18:11 - 2015-12-06 23:48 - 00502112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupEngine.dll
    2015-12-17 18:11 - 2015-12-06 23:48 - 00498448 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFCaptureEngine.dll
    2015-12-17 18:11 - 2015-12-06 23:48 - 00462760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfreadwrite.dll
    2015-12-17 18:11 - 2015-12-06 23:48 - 00450904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFCaptureEngine.dll
    2015-12-17 18:11 - 2015-12-06 23:48 - 00337840 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFPlay.dll
    2015-12-17 18:11 - 2015-12-06 23:48 - 00289248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFPlay.dll
    2015-12-17 18:11 - 2015-12-06 23:48 - 00245848 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
    2015-12-17 18:11 - 2015-12-06 23:48 - 00115040 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupApi.dll
    2015-12-17 18:11 - 2015-12-06 23:48 - 00084832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupApi.dll
    2015-12-17 18:11 - 2015-12-06 23:47 - 00925064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll
    2015-12-17 18:11 - 2015-12-06 23:47 - 00898184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsrcsnk.dll
    2015-12-17 18:11 - 2015-12-06 23:47 - 00716928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll
    2015-12-17 18:11 - 2015-12-06 23:47 - 00116720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfps.dll
    2015-12-17 18:11 - 2015-12-06 23:46 - 03671888 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
    2015-12-17 18:11 - 2015-12-06 23:46 - 02919320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
    2015-12-17 18:11 - 2015-12-06 23:45 - 00264544 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContentDeliveryManager.Utilities.dll
    2015-12-17 18:11 - 2015-12-06 23:15 - 01035776 _____ (Microsoft Corporation) C:\WINDOWS\system32\XboxNetApiSvc.dll
    2015-12-17 18:11 - 2015-12-06 23:15 - 00075776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.XboxLive.ProxyStub.dll
    2015-12-17 18:11 - 2015-12-06 23:10 - 00824320 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcWebFilter.dll
    2015-12-17 18:11 - 2015-12-06 23:09 - 00133120 _____ (Microsoft Corporation) C:\WINDOWS\system32\flvprophandler.dll
    2015-12-17 18:11 - 2015-12-06 23:09 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanagerprecheck.dll
    2015-12-17 18:11 - 2015-12-06 23:09 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorageUsage.dll
    2015-12-17 18:11 - 2015-12-06 23:07 - 16984064 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
    2015-12-17 18:11 - 2015-12-06 23:07 - 00134656 _____ (Microsoft Corporation) C:\WINDOWS\system32\wificonnapi.dll
    2015-12-17 18:11 - 2015-12-06 23:07 - 00077312 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProvPluginEng.dll
    2015-12-17 18:11 - 2015-12-06 23:06 - 00572928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WpcWebFilter.dll
    2015-12-17 18:11 - 2015-12-06 23:06 - 00231936 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCore.dll
    2015-12-17 18:11 - 2015-12-06 23:06 - 00199168 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe
    2015-12-17 18:11 - 2015-12-06 23:05 - 00192000 _____ (Microsoft Corporation) C:\WINDOWS\system32\provisioningcsp.dll
    2015-12-17 18:11 - 2015-12-06 23:05 - 00036864 _____ (Microsoft Corporation) C:\WINDOWS\system32\BackgroundTransferHost.exe
    2015-12-17 18:11 - 2015-12-06 23:04 - 00066560 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshost.dll
    2015-12-17 18:11 - 2015-12-06 23:04 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\system32\provtool.exe
    2015-12-17 18:11 - 2015-12-06 23:03 - 13017600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
    2015-12-17 18:11 - 2015-12-06 23:02 - 00269824 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshostcore.dll
    2015-12-17 18:11 - 2015-12-06 23:02 - 00161280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgent.exe
    2015-12-17 18:11 - 2015-12-06 23:01 - 00543232 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll
    2015-12-17 18:11 - 2015-12-06 23:01 - 00034304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BackgroundTransferHost.exe
    2015-12-17 18:11 - 2015-12-06 23:00 - 00618496 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll
    2015-12-17 18:11 - 2015-12-06 23:00 - 00323072 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSFlacDecoder.dll
    2015-12-17 18:11 - 2015-12-06 23:00 - 00210432 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmcsp.dll
    2015-12-17 18:11 - 2015-12-06 23:00 - 00203776 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupSvc.dll
    2015-12-17 18:11 - 2015-12-06 22:59 - 00558080 _____ (Microsoft Corporation) C:\WINDOWS\system32\MBMediaManager.dll
    2015-12-17 18:11 - 2015-12-06 22:59 - 00292352 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll
    2015-12-17 18:11 - 2015-12-06 22:59 - 00286208 _____ (Microsoft Corporation) C:\WINDOWS\system32\provhandlers.dll
    2015-12-17 18:11 - 2015-12-06 22:59 - 00165376 _____ (Microsoft Corporation) C:\WINDOWS\system32\provdatastore.dll
    2015-12-17 18:11 - 2015-12-06 22:58 - 24601600 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
    2015-12-17 18:11 - 2015-12-06 22:58 - 00459776 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapConfiguration.dll
    2015-12-17 18:11 - 2015-12-06 22:57 - 00409088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StoreAgent.dll
    2015-12-17 18:11 - 2015-12-06 22:57 - 00387072 _____ (Microsoft Corporation) C:\WINDOWS\system32\qdvd.dll
    2015-12-17 18:11 - 2015-12-06 22:57 - 00270848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSFlacDecoder.dll
    2015-12-17 18:11 - 2015-12-06 22:56 - 00607232 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmsvc.dll
    2015-12-17 18:11 - 2015-12-06 22:56 - 00497152 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmkvsrcsnk.dll
    2015-12-17 18:11 - 2015-12-06 22:55 - 07979008 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll
    2015-12-17 18:11 - 2015-12-06 22:55 - 00346112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapConfiguration.dll
    2015-12-17 18:11 - 2015-12-06 22:54 - 00850432 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll
    2015-12-17 18:11 - 2015-12-06 22:54 - 00569856 _____ (Microsoft Corporation)
    C:\WINDOWS\SysWOW64\qdvd.dll
    2015-12-17 18:11 - 2015-12-06 22:53 - 19339264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
    2015-12-17 18:11 - 2015-12-06 22:53 - 00381952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmkvsrcsnk.dll
    2015-12-17 18:11 - 2015-12-06 22:51 - 01318912 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifinetworkmanager.dll
    2015-12-17 18:11 - 2015-12-06 22:51 - 00223232 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapibase.dll
    2015-12-17 18:11 - 2015-12-06 22:50 - 01131520 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Audio.dll
    2015-12-17 18:11 - 2015-12-06 22:49 - 01105920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Audio.dll
    2015-12-17 18:11 - 2015-12-06 22:48 - 06297088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mos.dll
    2015-12-17 18:11 - 2015-12-06 22:47 - 03428864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
    2015-12-17 18:11 - 2015-12-06 22:45 - 02582016 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
    2015-12-17 18:11 - 2015-12-06 22:45 - 00900608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.BackgroundTransfer.dll
    2015-12-17 18:11 - 2015-12-06 22:45 - 00683008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.BackgroundTransfer.dll
    2015-12-17 18:11 - 2015-12-06 22:44 - 02796032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
    2015-12-17 18:11 - 2015-12-06 22:43 - 02598400 _____ (Microsoft Corporation)
     
  2. Chris Waters

    Chris Waters TS Rookie Topic Starter Posts: 23

    C:\WINDOWS\system32\NetworkMobileSettings.dll
    2015-12-17 18:11 - 2015-12-06 22:43 - 00931328 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSMPEG2ENC.DLL
    2015-12-17 18:11 - 2015-12-06 22:41 - 02061824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
    2015-12-17 18:11 - 2015-12-06 22:40 - 03593216 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
    2015-12-17 18:11 - 2015-12-06 22:40 - 01995776 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActiveSyncProvider.dll
    2015-12-17 18:11 - 2015-12-06 22:40 - 01706496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActiveSyncProvider.dll
    2015-12-17 18:11 - 2015-12-06 22:39 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll
    2015-12-17 18:11 - 2015-12-06 22:38 - 00871936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSMPEG2ENC.DLL
    2015-12-17 18:11 - 2015-12-06 22:33 - 00375296 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDEServer.exe
    2015-12-17 18:11 - 2015-12-06 22:32 - 00126464 _____ (Microsoft Corporation) C:\WINDOWS\system32\dialserver.dll
    2015-12-12 15:30 - 2015-12-12 15:30 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
    2015-12-11 23:03 - 2015-12-11 23:03 - 00000000 ____D C:\Users\Chris\AppData\Local\ActiveSync
    2015-12-11 22:54 - 2015-12-11 22:54 - 00000020 ___SH C:\Users\Chris\ntuser.ini
    2015-12-11 13:47 - 2015-12-11 12:00 - 00000000 ___DC C:\WINDOWS\Panther
    2015-12-11 13:44 - 2015-12-11 13:44 - 00000000 ____D C:\Windows.old
    2015-12-11 13:43 - 2015-12-11 13:43 - 22572632 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 22393856 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 21125408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 18678272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 13381120 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 12125184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 11545088 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 09918976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 07476576 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
    2015-12-11 13:43 - 2015-12-11 13:43 - 07199232 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 06572032 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanmm.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 05202944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 03993600 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 03355136 _____ (Microsoft Corporation) C:\WINDOWS\system32\msftedit.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 02843136 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdp.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 02772584 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 02756096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.tlb
    2015-12-11 13:43 - 2015-12-11 13:43 - 02756096 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.tlb
    2015-12-11 13:43 - 2015-12-11 13:43 - 02680320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msftedit.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 02653816 _____ C:\WINDOWS\system32\CoreUIComponents.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 02647552 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 02624512 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 02444288 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 02352128 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 02280448 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 02185840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 02155008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 02152800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
    2015-12-11 13:43 - 2015-12-11 13:43 - 02126848 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
    2015-12-11 13:43 - 2015-12-11 13:43 - 02121216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 02049024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
    2015-12-11 13:43 - 2015-12-11 13:43 - 02001408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.appcore.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 01944576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputService.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 01860096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cdp.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 01859448 _____ C:\WINDOWS\SysWOW64\CoreUIComponents.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 01817160 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 01814528 _____ (Microsoft Corporation) C:\WINDOWS\system32\pnidui.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 01734656 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 01717248 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 01713664 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRHInproc.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 01648640 _____ (Microsoft Corporation) C:\WINDOWS\system32\comsvcs.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 01540768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 01505280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 01467392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GdiPlus.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 01443328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRHInproc.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 01399224 _____ (Microsoft Corporation) C:\WINDOWS\system32\user32.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 01395200 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 01393664 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
    2015-12-11 13:43 - 2015-12-11 13:43 - 01387008 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 01337240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 01328128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comsvcs.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 01268736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Resources.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 01268736 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 01223168 _____ (Microsoft Corporation) C:\WINDOWS\system32\Unistore.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 01212928 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 01139200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 01063424 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 01056256 _____ (Microsoft Corporation) C:\WINDOWS\system32\JpMapControl.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 01042432 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingOnlineServices.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00988160 _____ (Microsoft Corporation) C:\WINDOWS\system32\NMAA.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00969728 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00957440 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00948224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Unistore.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00948224 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblAuthManager.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00938496 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlCore.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00912384 _____ (Microsoft Corporation) C:\WINDOWS\system32\usermgr.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00911648 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcomp.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00870400 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00870400 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00809312 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe
    2015-12-11 13:43 - 2015-12-11 13:43 - 00803840 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\JpMapControl.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00795840 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00793600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRH.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00791552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00784896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NMAA.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00783360 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00711680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapControlCore.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00709120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingOnlineServices.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00704352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe
    2015-12-11 13:43 - 2015-12-11 13:43 - 00704000 _____ (Microsoft Corporation) C:\WINDOWS\system32\CellularAPI.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00698208 _____ (Microsoft Corporation) C:\WINDOWS\system32\wimgapi.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00697856 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToManager.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00686592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00675064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dcomp.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00674816 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00647168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00638464 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00630632 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
    2015-12-11 13:43 - 2015-12-11 13:43 - 00623616 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneProviders.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00604928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
    2015-12-11 13:43 - 2015-12-11 13:43 - 00604672 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00589312 _____ (Microsoft Corporation) C:\WINDOWS\system32\MbaeApi.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00586208 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00586080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wimgapi.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00578912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\afd.sys
    2015-12-11 13:43 - 2015-12-11 13:43 - 00540752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
    2015-12-11 13:43 - 2015-12-11 13:43 - 00538632 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWanAPI.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00536768 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00523776 _____ (Microsoft Corporation) C:\WINDOWS\system32\catsrvut.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00523616 _____ (Microsoft Corporation) C:\WINDOWS\system32\wimserv.exe
    2015-12-11 13:43 - 2015-12-11 13:43 - 00517632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToManager.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00517632 _____ (Microsoft Corporation) C:\WINDOWS\system32\winspool.drv
    2015-12-11 13:43 - 2015-12-11 13:43 - 00516544 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00515584 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00511320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00503296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00490496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00470528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MbaeApi.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00465920 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanconn.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00458752 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToDevice.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00454056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioEng.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00450560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Bluetooth.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00440160 _____ (Microsoft Corporation) C:\WINDOWS\system32\services.exe
    2015-12-11 13:43 - 2015-12-11 13:43 - 00431232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWanAPI.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00421888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LogonController.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00416768 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenrollengine.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00415744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\catsrvut.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00414720 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.exe
    2015-12-11 13:43 - 2015-12-11 13:43 - 00408128 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00405048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00400896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winspool.drv
    2015-12-11 13:43 - 2015-12-11 13:43 - 00382464 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00369912 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
    2015-12-11 13:43 - 2015-12-11 13:43 - 00366224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AUDIOKSE.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00365568 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00345600 _____ (Microsoft Corporation) C:\WINDOWS\system32\TextInputFramework.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00342016 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorService.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00340480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToDevice.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00334848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00334736 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanager.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00334336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcastdvr.exe
    2015-12-11 13:43 - 2015-12-11 13:43 - 00320000 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptngc.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00315904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Bluetooth.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00303104 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00296488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\policymanager.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00286720 _____ (Microsoft Corporation) C:\WINDOWS\system32\deviceaccess.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00275456 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00264192 _____ (Nokia) C:\WINDOWS\system32\NmaDirect.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00248832 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserMgrProxy.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00245760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TextInputFramework.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00241664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cryptngc.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00227840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\deviceaccess.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00220672 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
    2015-12-11 13:43 - 2015-12-11 13:43 - 00205824 _____ (Nokia) C:\WINDOWS\SysWOW64\NmaDirect.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00204800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft-Windows-AppModelExecEvents.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00182784 _____ (Microsoft Corporation)
    C:\WINDOWS\system32\shutdownux.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00175616 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00168960 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmmigrator.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00166912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserMgrProxy.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00163328 _____ (Microsoft Corporation) C:\WINDOWS\system32\provops.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00162304 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringservice.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00162304 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCensus.exe
    2015-12-11 13:43 - 2015-12-11 13:43 - 00161632 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
    2015-12-11 13:43 - 2015-12-11 13:43 - 00160768 _____ (Microsoft Corporation) C:\WINDOWS\system32\enrollmentapi.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00157184 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcertinst.exe
    2015-12-11 13:43 - 2015-12-11 13:43 - 00147968 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rmcast.sys
    2015-12-11 13:43 - 2015-12-11 13:43 - 00138240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ETWCoreUIComponentsResources.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00138240 _____ (Microsoft Corporation) C:\WINDOWS\system32\ETWCoreUIComponentsResources.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00133632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Core.TextInput.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00122368 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCsp.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00119808 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsBtSvc.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00118624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tdx.sys
    2015-12-11 13:43 - 2015-12-11 13:43 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontsub.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00117248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\capimg.sys
    2015-12-11 13:43 - 2015-12-11 13:43 - 00115200 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
    2015-12-11 13:43 - 2015-12-11 13:43 - 00114688 _____ (Microsoft Corporation) C:\WINDOWS\system32\offlinelsa.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00110592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Microsoft-Windows-MapControls.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00110592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft-Windows-MapControls.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00110032 _____ (Microsoft Corporation) C:\WINDOWS\system32\EncDump.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00108544 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputLocaleManager.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00100864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\offlinelsa.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00095072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdstor.sys
    2015-12-11 13:43 - 2015-12-11 13:43 - 00093696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontsub.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00092352 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsNativeApi.V2.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00089600 _____ (Microsoft Corporation) C:\WINDOWS\system32\NFCProvisioningPlugin.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00089088 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsCSP.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00088392 _____ (Microsoft Corporation) C:\WINDOWS\system32\remoteaudioendpoint.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzautoupdate.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00086528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapsBtSvc.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00086528 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppCapture.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00083456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputLocaleManager.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00080600 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwapi.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00078336 _____ (Microsoft Corporation) C:\WINDOWS\system32\BarcodeProvisioningPlugin.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00075264 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanprotdim.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00075264 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditBufferTestHook.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00074240 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssign32.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00073728 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwancfg.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00073360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\remoteaudioendpoint.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00072704 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosStorage.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00070656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppCapture.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00070656 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblAuthManagerProxy.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininetlui.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00066560 _____ (Microsoft Corporation) C:\WINDOWS\system32\iesetup.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininetlui.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00064000 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosHostClient.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00064000 _____ (Microsoft Corporation) C:\WINDOWS\system32\ihvrilproxy.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00063528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wwapi.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00060928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssign32.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00060928 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblAuthTokenBrokerExt.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00059904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EditBufferTestHook.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00058408 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsNativeApi.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosStorage.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosResource.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosResource.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00055808 _____ (Microsoft Corporation) C:\WINDOWS\system32\rilproxy.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00052736 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringclient.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00052736 _____ (Microsoft Corporation) C:\WINDOWS\system32\RemovableMediaProvisioningPlugin.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\Wwanpref.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00051680 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsUtilsV2.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00049152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XblAuthTokenBrokerExt.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00048640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosHostClient.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00045568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jsproxy.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00045568 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00044032 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsplib.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00043520 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.proxy.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00042496 _____ (Microsoft Corporation) C:\WINDOWS\system32\mapstoasttask.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00041984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XblAuthManagerProxy.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00037376 _____ (Microsoft Corporation) C:\WINDOWS\system32\LaunchWinApp.exe
    2015-12-11 13:43 - 2015-12-11 13:43 - 00037376 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00036352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCoreRes.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00036352 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCoreRes.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00035680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wimmount.sys
    2015-12-11 13:43 - 2015-12-11 13:43 - 00035656 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfpmp.exe
    2015-12-11 13:43 - 2015-12-11 13:43 - 00034304 _____ (Microsoft Corporation) C:\WINDOWS\system32\iernonce.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00032256 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups2.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00032040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfpmp.exe
    2015-12-11 13:43 - 2015-12-11 13:43 - 00030720 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringconfigsp.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00029696 _____ (Microsoft Corporation)
     
  3. Chris Waters

    Chris Waters TS Rookie Topic Starter Posts: 23

    C:\WINDOWS\SysWOW64\LaunchWinApp.exe
    2015-12-11 13:43 - 2015-12-11 13:43 - 00028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\WordBreakers.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\mapsupdatetask.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00028160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Management.Provisioning.ProxyStub.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00028160 _____ (Microsoft Corporation) C:\WINDOWS\system32\nativemap.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcastdvr.proxy.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00026408 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
    2015-12-11 13:43 - 2015-12-11 13:43 - 00024064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WordBreakers.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00018944 _____ (Microsoft Corporation) C:\WINDOWS\system32\wshrm.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\IcsEntitlementHost.exe
    2015-12-11 13:43 - 2015-12-11 13:43 - 00014336 _____ (Microsoft Corporation) C:\WINDOWS\system32\dciman32.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsBtSvcProxy.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00011776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dciman32.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Microsoft-Windows-MosTrace.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft-Windows-MosTrace.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00009728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Microsoft-Windows-MosHost.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00009728 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft-Windows-MosHost.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00007680 _____ (Microsoft Corporation) C:\WINDOWS\system32\readingviewresources.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00003072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapControlStringsRes.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00003072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\lpk.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00003072 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlStringsRes.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 00003072 _____ (Microsoft Corporation) C:\WINDOWS\system32\lpk.dll
    2015-12-11 13:41 - 2015-10-29 22:43 - 06238720 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsLexicons000c.dll
    2015-12-11 13:41 - 2015-10-29 22:41 - 06238720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsLexicons000c.dll
    2015-12-11 13:41 - 2015-10-29 22:30 - 02354176 _____ (Microsoft Corporation) C:\WINDOWS\system32\NlsData000c.dll
    2015-12-11 13:41 - 2015-10-29 22:27 - 02268672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NlsData000c.dll
    2015-12-11 13:40 - 2015-12-11 13:40 - 00008192 _____ C:\WINDOWS\system32\config\userdiff
    2015-12-11 13:37 - 2015-12-11 13:37 - 00000000 ____D C:\Program Files\Reference Assemblies
    2015-12-11 13:37 - 2015-12-11 13:37 - 00000000 ____D C:\Program Files\MSBuild
    2015-12-11 13:37 - 2015-12-11 13:37 - 00000000 ____D C:\Program Files (x86)\Reference Assemblies
    2015-12-11 13:37 - 2015-12-11 13:37 - 00000000 ____D C:\Program Files (x86)\MSBuild
    2015-12-11 13:37 - 2015-10-23 20:47 - 00778936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationNative_v0300.dll
    2015-12-11 13:37 - 2015-10-23 20:47 - 00103120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
    2015-12-11 13:37 - 2015-10-23 20:47 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TsWpfWrp.exe
    2015-12-11 13:37 - 2015-10-23 20:46 - 01166520 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationNative_v0300.dll
    2015-12-11 13:37 - 2015-10-23 20:46 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\system32\TsWpfWrp.exe
    2015-12-11 13:37 - 2015-10-23 20:45 - 00124624 _____ (Microsoft Corporation)
    C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll
    2015-12-11 11:28 - 2015-12-11 11:28 - 00000000 _SHDL C:\Users\Default\My Documents
    2015-12-11 11:28 - 2015-12-11 11:28 - 00000000 _SHDL C:\Users\Default\Documents\My Videos
    2015-12-11 11:28 - 2015-12-11 11:28 - 00000000 _SHDL C:\Users\Default\Documents\My Pictures
    2015-12-11 11:28 - 2015-12-11 11:28 - 00000000 _SHDL C:\Users\Default\Documents\My Music
    2015-12-11 11:28 - 2015-12-11 11:28 - 00000000 _SHDL C:\Users\Default User\Documents\My Videos
    2015-12-11 11:28 - 2015-12-11 11:28 - 00000000 _SHDL C:\Users\Default User\Documents\My Pictures
    2015-12-11 11:28 - 2015-12-11 11:28 - 00000000 _SHDL C:\Users\Default User\Documents\My Music
    2015-12-11 11:19 - 2016-01-06 20:13 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
    2015-12-11 11:07 - 2015-12-11 11:07 - 00001576 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
    2015-12-11 11:07 - 2015-12-11 11:07 - 00000000 ____D C:\Users\Default\AppData\Roaming\Temp
    2015-12-11 11:07 - 2015-12-11 11:07 - 00000000 ____D C:\Users\Default\AppData\Roaming\KODAK AiO Home Center569090879
    2015-12-11 11:07 - 2015-12-11 11:07 - 00000000 ____D C:\Users\Default\AppData\Local\Google
    2015-12-11 11:07 - 2015-12-11 11:07 - 00000000 ____D C:\Users\Default\AppData\Local\Eastman_Kodak_Company
    2015-12-11 11:07 - 2015-12-11 11:07 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Temp
    2015-12-11 11:07 - 2015-12-11 11:07 - 00000000 ____D C:\Users\Default User\AppData\Roaming\KODAK AiO Home Center569090879
    2015-12-11 11:07 - 2015-12-11 11:07 - 00000000 ____D C:\Users\Default User\AppData\Local\Google
    2015-12-11 11:07 - 2015-12-11 11:07 - 00000000 ____D C:\Users\Default User\AppData\Local\Eastman_Kodak_Company
    2015-12-11 11:02 - 2015-12-11 11:11 - 00000000 ____D C:\WINDOWS\system32\config\bbimigrate
    2015-12-11 10:58 - 2016-01-04 23:10 - 00000000 ____D C:\Users\Chris
    2015-12-11 10:58 - 2015-12-11 10:58 - 00000000 _SHDL C:\Users\Chris\My Documents
    2015-12-11 10:58 - 2015-12-11 10:58 - 00000000 _SHDL C:\Users\Chris\Documents\My Videos
    2015-12-11 10:58 - 2015-12-11 10:58 - 00000000 _SHDL C:\Users\Chris\Documents\My Pictures
    2015-12-11 10:58 - 2015-12-11 10:58 - 00000000 _SHDL C:\Users\Chris\Documents\My Music
    2015-12-11 10:55 - 2016-01-06 20:13 - 00000000 ____D C:\ProgramData\NVIDIA
    2015-12-11 10:55 - 2015-12-11 11:02 - 00000000 ____D C:\Program Files\Common Files\logishrd
    2015-12-11 10:55 - 2015-12-11 10:55 - 00000000 ____D C:\WINDOWS\SysWOW64\RTCOM
    2015-12-11 10:55 - 2015-12-11 10:55 - 00000000 ____D C:\Program Files\Realtek
    2015-12-11 10:54 - 2015-12-11 11:03 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
    2015-12-11 10:54 - 2015-12-11 11:03 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
    2015-12-11 10:54 - 2015-12-11 11:02 - 00000000 ____D C:\Program Files\NVIDIA Corporation
    2015-12-11 10:54 - 2015-12-11 10:54 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_TeeDriverx64_01011.Wdf
    2015-12-11 10:54 - 2015-11-05 10:08 - 06358648 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
    2015-12-11 10:54 - 2015-11-05 10:08 - 02983216 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc64.dll
    2015-12-11 10:54 - 2015-11-05 10:08 - 02554672 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll
    2015-12-11 10:54 - 2015-11-05 10:08 - 00938616 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvvsvc.exe
    2015-12-11 10:54 - 2015-11-05 10:08 - 00385328 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmctray.dll
    2015-12-11 10:54 - 2015-11-05 10:08 - 00062584 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll
    2015-12-11 10:54 - 2015-10-28 08:49 - 06027430 _____ C:\WINDOWS\system32\nvcoproc.bin
    2015-12-11 10:51 - 2015-10-30 02:17 - 02718208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
    2015-12-11 10:48 - 2015-12-11 11:12 - 00349792 _____ C:\WINDOWS\system32\FNTCACHE.DAT

    ==================== One Month Modified files and folders ========

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2016-01-10 19:00 - 2015-10-30 01:28 - 00000000 ____D C:\Windows
    2016-01-10 18:56 - 2013-06-20 19:31 - 00000000 ____D C:\Users\Chris\AppData\Roaming\Skype
    2016-01-10 18:55 - 2014-04-14 14:07 - 00004160 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{909DD475-84FF-494B-8E45-735181543A4E}
    2016-01-10 18:53 - 2015-08-10 01:19 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GOG.com
    2016-01-10 18:53 - 2015-08-10 01:19 - 00000000 ____D C:\Program Files (x86)\GalaxyClient
    2016-01-10 18:24 - 2013-09-02 17:57 - 00000830 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
    2016-01-09 23:02 - 2015-10-30 02:24 - 00000000 ____D C:\WINDOWS\AppReadiness
    2016-01-09 22:34 - 2013-06-24 20:56 - 00000000 ____D C:\ProgramData\Kodak
    2016-01-09 17:13 - 2015-09-05 20:23 - 00000000 ____D C:\Users\Chris\AppData\Local\Spotify
    2016-01-09 17:10 - 2013-06-20 20:37 - 00000000 ____D C:\Program Files (x86)\Steam
    2016-01-09 13:00 - 2015-09-05 20:23 - 00000000 ____D C:\Users\Chris\AppData\Roaming\Spotify
    2016-01-08 22:39 - 2015-10-30 02:24 - 00000000 ___HD C:\Program Files\WindowsApps
    2016-01-08 22:34 - 2014-04-21 18:19 - 00000400 _____ C:\WINDOWS\Tasks\AVG-Secure-Search-Update_0414c_rmv.job
    2016-01-08 22:34 - 2014-04-21 18:19 - 00000400 _____ C:\WINDOWS\Tasks\AVG-Secure-Search-Update_0414c_rel.job
    2016-01-08 22:34 - 2013-12-24 15:00 - 00000000 __RDO C:\Users\Chris\SkyDrive
    2016-01-06 20:19 - 2015-10-30 02:21 - 00000000 ____D C:\WINDOWS\INF
    2016-01-06 20:19 - 2015-08-13 06:31 - 00879220 _____ C:\WINDOWS\system32\PerfStringBackup.INI
    2016-01-05 22:40 - 2015-10-30 01:28 - 01048576 ___SH C:\WINDOWS\system32\config\BBI
    2016-01-05 18:44 - 2015-10-30 02:11 - 00000000 ____D C:\WINDOWS\CbsTemp
    2016-01-02 20:40 - 2015-10-30 02:26 - 00826872 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
    2016-01-02 20:40 - 2015-10-30 02:26 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
    2016-01-02 13:59 - 2012-12-04 14:59 - 00000000 ____D C:\Users\Chris\AppData\Local\Packages
    2016-01-02 13:53 - 2015-01-30 23:00 - 00013943 _____ C:\Users\Chris\Downloads\FTBLauncherLog.txt
    2016-01-02 13:53 - 2015-01-30 23:00 - 00000068 _____ C:\Users\Chris\Downloads\MinecraftLog.txt
    2016-01-01 12:36 - 2015-11-18 14:37 - 00000931 _____ C:\Users\Public\Desktop\Nexus Mod Manager.lnk
    2016-01-01 12:36 - 2015-11-18 14:37 - 00000000 ____D C:\Program Files\Nexus Mod Manager
    2016-01-01 12:21 - 2015-07-26 11:21 - 00000000 ____D C:\Users\Chris\Downloads\FTBInfinity
    2016-01-01 12:21 - 2014-08-15 22:46 - 00000000 ____D C:\Users\Chris\AppData\Local\ftblauncher
    2015-12-30 17:15 - 2014-01-07 22:19 - 00000000 ____D C:\Users\Chris\Documents\youtubetomp3.org
    2015-12-30 15:13 - 2012-12-28 16:31 - 00000000 ____D C:\Users\Chris\Documents\Square Enix
    2015-12-29 12:05 - 2013-12-24 13:00 - 00001274 _____ C:\Users\Chris\Desktop\Uplay.lnk
    2015-12-29 04:24 - 2013-09-02 17:57 - 00003816 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
    2015-12-20 00:43 - 2013-11-11 17:57 - 00000000 ____D C:\Users\Chris\AppData\Roaming\TS3Client
    2015-12-19 22:00 - 2013-07-05 12:01 - 00000000 ____D C:\Users\Chris\AppData\Local\Arma 3
    2015-12-18 03:30 - 2015-10-30 02:24 - 00000000 ____D C:\WINDOWS\system32\appraiser
    2015-12-18 03:30 - 2015-10-30 02:24 - 00000000 ____D C:\WINDOWS\Provisioning
    2015-12-18 03:30 - 2015-10-30 02:24 - 00000000 ____D C:\WINDOWS\bcastdvr
    2015-12-16 15:26 - 2015-07-23 09:37 - 00002260 _____ C:\Users\Public\Desktop\Google Chrome.lnk
    2015-12-15 20:22 - 2015-10-30 02:24 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
    2015-12-15 20:21 - 2013-06-21 20:14 - 00000000 ____D C:\Program Files\Microsoft Office 15
    2015-12-14 18:33 - 2015-08-13 17:12 - 00002405 _____ C:\Users\Chris\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
    2015-12-12 22:48 - 2015-09-16 14:24 - 00000000 ___RD C:\Users\Chris\3D Objects
    2015-12-12 03:45 - 2015-10-30 02:24 - 00000000 ____D C:\WINDOWS\appcompat
    2015-12-11 23:04 - 2015-10-30 02:24 - 00000000 ___RD C:\WINDOWS\DevicesFlow
    2015-12-11 22:58 - 2015-10-30 02:24 - 00000000 ___RD C:\WINDOWS\PrintDialog
    2015-12-11 22:58 - 2015-10-30 02:24 - 00000000 ___RD C:\WINDOWS\MiracastView
    2015-12-11 22:58 - 2015-10-30 02:24 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel
    2015-12-11 22:54 - 2015-08-13 17:06 - 00000000 __RHD C:\Users\Public\AccountPictures
    2015-12-11 13:47 - 2015-10-30 02:24 - 00028672 _____ C:\WINDOWS\system32\config\BCD-Template
    2015-12-11 13:44 - 2015-10-30 02:24 - 00000000 ____D C:\WINDOWS\system32\SystemResetPlatform
    2015-12-11 13:44 - 2015-10-30 01:28 - 00000000 ____D C:\WINDOWS\SysWOW64\Dism
    2015-12-11 13:44 - 2015-10-30 01:28 - 00000000 ____D C:\WINDOWS\system32\Dism
    2015-12-11 11:28 - 2015-10-30 02:24 - 00000000 ____D C:\WINDOWS\system32\WinBioDatabase
    2015-12-11 11:27 - 2015-10-30 02:24 - 00000000 ____D C:\WINDOWS\Registration
    2015-12-11 11:27 - 2015-10-30 01:28 - 00032768 ___SH C:\WINDOWS\system32\config\ELAM
    2015-12-11 11:27 - 2013-12-24 14:25 - 00019053 _____ C:\WINDOWS\diagwrn.xml
    2015-12-11 11:27 - 2013-12-24 14:25 - 00019053 _____ C:\WINDOWS\diagerr.xml
    2015-12-11 11:24 - 2015-10-30 02:24 - 00000000 ____D C:\WINDOWS\rescache
    2015-12-11 11:19 - 2014-04-29 14:48 - 00002372 _____ C:\WINDOWS\System32\Tasks\{9464F175-373C-477C-8831-D8CF33DDE712}
    2015-12-11 11:19 - 2014-04-21 18:19 - 00002208 _____ C:\WINDOWS\System32\Tasks\AVG-Secure-Search-Update_0414c_rmv
    2015-12-11 11:19 - 2014-04-21 18:19 - 00002206 _____ C:\WINDOWS\System32\Tasks\AVG-Secure-Search-Update_0414c_rel
    2015-12-11 11:19 - 2013-12-24 14:47 - 00022840 _____ C:\WINDOWS\system32\emptyregdb.dat
    2015-12-11 11:19 - 2013-12-23 10:40 - 00002268 _____ C:\WINDOWS\System32\Tasks\{4D56C402-4B79-4A2B-95EF-FE1034AB0702}
    2015-12-11 11:19 - 2013-08-02 16:25 - 00002296 _____ C:\WINDOWS\System32\Tasks\{24F190A2-8311-4B5B-BB2A-33313F397938}
    2015-12-11 11:19 - 2013-08-02 16:20 - 00002282 _____ C:\WINDOWS\System32\Tasks\{338D639B-F43C-4196-B5E4-5515837EA181}
    2015-12-11 11:19 - 2013-08-02 16:16 - 00002284 _____ C:\WINDOWS\System32\Tasks\{61A30D71-B4AB-47F7-ABAF-734ACEB8153E}
    2015-12-11 11:19 - 2013-07-13 20:23 - 00002476 _____ C:\WINDOWS\System32\Tasks\Razer_Game_Booster_AutoUpdate
    2015-12-11 11:19 - 2013-06-20 19:25 - 00003444 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
    2015-12-11 11:19 - 2013-06-20 19:25 - 00003220 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
    2015-12-11 11:19 - 2013-06-19 21:08 - 00002938 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-905238947-2220377667-1876713056-1001
    2015-12-11 11:18 - 2015-10-30 02:24 - 00000000 __RHD C:\Users\Public\Libraries
    2015-12-11 11:11 - 2015-11-13 14:28 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\The Witcher® 3 - Wild Hunt [GOG.com]
    2015-12-11 11:11 - 2015-10-16 20:24 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client
    2015-12-11 11:11 - 2015-10-15 19:31 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AudibleManager
    2015-12-11 11:11 - 2015-10-13 20:46 - 00000000 ____D C:\Users\Chris\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Flux
    2015-12-11 11:11 - 2015-10-12 18:17 - 00000000 ____D C:\Users\Chris\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Warface Launcher
    2015-12-11 11:11 - 2015-10-09 14:22 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\STAR WARS Battlefront Beta
    2015-12-11 11:11 - 2015-08-10 01:15 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Playfire
    2015-12-11 11:11 - 2015-08-09 11:36 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ArmA3Sync
    2015-12-11 11:11 - 2015-07-23 10:05 - 00000000 ____D C:\Users\Chris\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ARMA 3 Launcher By Head
    2015-12-11 11:11 - 2015-07-22 22:20 - 00000000 ____D C:\Users\Chris\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MEGAsync
    2015-12-11 11:11 - 2015-01-18 21:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AOMEI Backupper Professional Edition 2.2
    2015-12-11 11:11 - 2015-01-18 20:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
    2015-12-11 11:11 - 2015-01-15 10:39 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCGLauncher
    2015-12-11 11:11 - 2014-12-23 20:54 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
    2015-12-11 11:11 - 2014-08-24 22:12 - 00000000 ____D C:\Users\Chris\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dashlane
    2015-12-11 11:11 - 2014-08-16 01:27 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MSI Intel Extreme Tuning Utility
    2015-12-11 11:11 - 2014-08-16 01:26 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
    2015-12-11 11:11 - 2014-08-16 01:15 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Creative
    2015-12-11 11:11 - 2014-07-22 21:47 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
    2015-12-11 11:11 - 2014-06-16 14:27 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive
    2015-12-11 11:11 - 2014-04-25 20:31 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Notepad++
    2015-12-11 11:11 - 2014-04-23 14:58 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mount&Blade
    2015-12-11 11:11 - 2014-04-16 21:04 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
    2015-12-11 11:11 - 2014-04-16 20:24 - 00000000 ____D C:\Users\Chris\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Flvto Youtube Downloader
    2015-12-11 11:11 - 2014-03-15 17:09 - 00000000 ____D C:\Users\Chris\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GameFly
    2015-12-11 11:11 - 2014-03-03 20:01 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
    2015-12-11 11:11 - 2014-02-17 02:15 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
    2015-12-11 11:11 - 2014-01-22 15:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mass Effect 3
    2015-12-11 11:11 - 2014-01-18 19:11 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SimCity™
    2015-12-11 11:11 - 2014-01-12 11:23 - 00000000 ____D C:\Users\Chris\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Third Age - Total War 3.0 (Part 2of2)
    2015-12-11 11:11 - 2014-01-12 00:48 - 00000000 ____D C:\Users\Chris\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Third Age - Total War 3.0 (Part 1of2)
    2015-12-11 11:11 - 2014-01-07 22:16 - 00000000 ____D C:\Users\Chris\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\youtubetomp3.org
    2015-12-11 11:11 - 2013-12-24 13:00 - 00000000 ____D C:\Users\Chris\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ubisoft
    2015-12-11 11:11 - 2013-11-11 16:28 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cyberduck
    2015-12-11 11:11 - 2013-09-22 08:43 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dotjosh Studios
    2015-12-11 11:11 - 2013-09-04 19:33 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kodak
    2015-12-11 11:11 - 2013-08-22 16:35 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mount&Blade Warband
    2015-12-11 11:11 - 2013-08-19 22:04 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GameStop
    2015-12-11 11:11 - 2013-08-09 16:22 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerISO
    2015-12-11 11:11 - 2013-07-25 19:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Games for Windows Marketplace
    2015-12-11 11:11 - 2013-07-18 15:00 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logitech
    2015-12-11 11:11 - 2013-07-12 20:55 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
    2015-12-11 11:11 - 2013-07-12 18:53 - 00000000 ____D C:\Users\Chris\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\EVGA Precision X
    2015-12-11 11:11 - 2013-06-24 21:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PrintProjects
    2015-12-11 11:11 - 2013-06-21 11:40 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FileZilla FTP Client
    2015-12-11 11:11 - 2013-06-20 21:16 - 00000000 ____D C:\Users\Chris\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
    2015-12-11 11:11 - 2013-06-20 21:16 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
    2015-12-11 11:11 - 2013-06-20 20:37 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
    2015-12-11 11:11 - 2013-06-20 20:22 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Origin
    2015-12-11 11:11 - 2013-06-20 20:18 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RaidCall
    2015-12-11 11:11 - 2013-06-20 17:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NETGEAR WNDA3100v2 Genie
    2015-12-11 11:11 - 2013-06-19 20:53 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\REALTEK 11n USB Wireless LAN Utility
    2015-12-11 11:07 - 2015-07-10 04:05 - 00000000 ____D C:\Users\Default.migrated
    2015-12-11 11:04 - 2015-10-30 02:24 - 00000000 ____D C:\WINDOWS\SysWOW64\migwiz
    2015-12-11 11:04 - 2015-10-30 02:24 - 00000000 ____D C:\WINDOWS\SysWOW64\IME
    2015-12-11 11:04 - 2015-10-30 02:24 - 00000000 ____D C:\WINDOWS\system32\spool
    2015-12-11 11:04 - 2015-10-30 02:24 - 00000000 ____D C:\WINDOWS\system32\oobe
    2015-12-11 11:04 - 2015-10-30 02:24 - 00000000 ____D C:\WINDOWS\system32\NDF
    2015-12-11 11:04 - 2015-10-30 02:24 - 00000000 ____D C:\WINDOWS\system32\InputMethod
    2015-12-11 11:04 - 2015-10-30 02:24 - 00000000 ____D C:\WINDOWS\system32\IME
    2015-12-11 11:04 - 2014-01-15 22:05 - 00000000 ____D C:\WINDOWS\SysWOW64\SearchProtect
    2015-12-11 11:04 - 2013-09-04 19:32 - 00000000 ____D C:\WINDOWS\SysWOW64\kodak
    2015-12-11 11:04 - 2013-09-04 19:31 - 00000000 ____D C:\WINDOWS\SysWOW64\spool
    2015-12-11 11:04 - 2013-08-22 10:36 - 00000000 ____D C:\WINDOWS\system32\WindowsInternal.Inbox.Shared
    2015-12-11 11:04 - 2013-08-22 10:36 - 00000000 ____D C:\WINDOWS\system32\WindowsInternal.Inbox.Media.Shared
    2015-12-11 11:04 - 2013-07-24 19:19 - 00000000 ____D C:\WINDOWS\SysWOW64\xlive
    2015-12-11 11:04 - 2013-06-24 21:04 - 00000000 ____D C:\WINDOWS\system32\kodak
    2015-12-11 11:04 - 2013-06-21 06:27 - 00000000 ____D C:\WINDOWS\SysWOW64\ZALSDK_uninst
    2015-12-11 11:03 - 2015-12-10 19:11 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
    2015-12-11 11:03 - 2015-10-30 04:03 - 00000000 ____D C:\WINDOWS\OCR
    2015-12-11 11:03 - 2015-10-30 02:24 - 00000000 ___RD C:\WINDOWS\PurchaseDialog
    2015-12-11 11:03 - 2015-10-30 02:24 - 00000000 ____D C:\WINDOWS\Resources
    2015-12-11 11:03 - 2015-10-30 02:24 - 00000000 ____D C:\WINDOWS\LiveKernelReports
    2015-12-11 11:03 - 2015-10-30 02:24 - 00000000 ____D C:\WINDOWS\InputMethod
    2015-12-11 11:03 - 2015-10-30 02:24 - 00000000 ____D C:\ProgramData\USOPrivate
    2015-12-11 11:03 - 2015-07-22 22:33 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Kits
    2015-12-11 11:03 - 2014-09-06 18:56 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Qualcomm Atheros
    2015-12-11 11:03 - 2014-08-16 01:20 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MSI
    2015-12-11 11:03 - 2013-12-14 21:20 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OnLive
    2015-12-11 11:03 - 2013-08-22 10:36 - 00000000 ____D C:\WINDOWS\ADFS
    2015-12-11 11:03 - 2013-08-20 16:55 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Paradox Interactive
    2015-12-11 11:03 - 2013-08-02 16:06 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bohemia Interactive
    2015-12-11 11:03 - 2013-07-11 21:48 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ooVoo
    2015-12-11 11:03 - 2013-06-20 20:23 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Razer
    2015-12-11 11:02 - 2015-10-30 02:24 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
    2015-12-11 11:02 - 2014-08-16 00:57 - 00000000 ____D C:\Program Files\Intel
    2015-12-11 11:01 - 2013-08-02 16:06 - 00000000 ____D C:\Users\Chris\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bohemia Interactive
    2015-12-11 10:58 - 2015-10-30 01:28 - 00000000 ____D C:\WINDOWS\system32\Sysprep
    2015-12-11 10:54 - 2015-10-30 02:24 - 00000000 ____D C:\WINDOWS\Help
    2015-12-11 10:48 - 2015-10-30 04:13 - 00000000 ____D C:\WINDOWS\ServiceProfiles
    2015-12-11 10:15 - 2015-10-30 04:42 - 00000000 ___HD C:\$WINDOWS.~BT

    ==================== Files in the root of some directories =======

    2013-07-23 11:04 - 2011-07-19 02:37 - 0003262 _____ () C:\Program Files (x86)\Falco.ico
    2013-07-23 11:04 - 2011-07-19 03:05 - 0000046 _____ () C:\Program Files (x86)\Falco.url
    2014-06-17 20:20 - 2014-07-19 00:23 - 0000090 _____ () C:\Users\Chris\AppData\Roaming\WB.CFG
    2013-11-11 14:52 - 2014-09-06 17:12 - 0000600 _____ () C:\Users\Chris\AppData\Roaming\winscp.rnd
    2013-06-24 21:05 - 2013-09-04 19:34 - 0000236 _____ () C:\Users\Chris\AppData\Local\LaunchHomeCenter.log
    2015-08-19 19:46 - 2015-11-10 00:12 - 0007602 _____ () C:\Users\Chris\AppData\Local\resmon.resmoncfg
    2015-01-24 14:36 - 2015-01-24 14:36 - 0000000 _____ () C:\Users\Chris\AppData\Local\{1C9D2A21-6106-4C53-AB79-60959E2BB4A5}

    Some files in TEMP:
    ====================
    C:\Users\Chris\AppData\Local\Temp\jshortcut-6364520680213824196.dll
    C:\Users\Chris\AppData\Local\Temp\jshortcut-8997663281635068146.dll
    C:\Users\Chris\AppData\Local\Temp\Nexus Mod Manager-0.61.4.exe


    ==================== Bamital & volsnap =================

    (There is no automatic fix for files that do not pass verification.)

    C:\WINDOWS\system32\winlogon.exe => File is digitally signed
    C:\WINDOWS\system32\wininit.exe => File is digitally signed
    C:\WINDOWS\explorer.exe => File is digitally signed
    C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
    C:\WINDOWS\system32\svchost.exe => File is digitally signed
    C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
    C:\WINDOWS\system32\services.exe => File is digitally signed
    C:\WINDOWS\system32\User32.dll => File is digitally signed
    C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
    C:\WINDOWS\system32\userinit.exe => File is digitally signed
    C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
    C:\WINDOWS\system32\rpcss.dll => File is digitally signed
    C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
    C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
    C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed


    LastRegBack: 2016-01-04 22:21

    ==================== End of FRST.txt ============================
     
  4. Chris Waters

    Chris Waters TS Rookie Topic Starter Posts: 23

    Additional scan result of Farbar Recovery Scan Tool (x64) Version:10-01-2015 01
    Ran by Chris (2016-01-10 19:02:03)
    Running from C:\Users\Chris\Downloads
    Windows 10 Home (X64) (2015-12-11 16:28:25)
    Boot Mode: Normal
    ==========================================================


    ==================== Accounts: =============================

    Administrator (S-1-5-21-905238947-2220377667-1876713056-500 - Administrator - Disabled)
    Chris (S-1-5-21-905238947-2220377667-1876713056-1001 - Administrator - Enabled) => C:\Users\Chris
    DefaultAccount (S-1-5-21-905238947-2220377667-1876713056-503 - Limited - Disabled)
    Guest (S-1-5-21-905238947-2220377667-1876713056-501 - Limited - Disabled)
    HomeGroupUser$ (S-1-5-21-905238947-2220377667-1876713056-1004 - Limited - Enabled)

    ==================== Security Center ========================

    (If an entry is included in the fixlist, it will be removed.)

    AV: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

    ==================== Installed Programs ======================

    (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

    µTorrent (HKU\S-1-5-21-905238947-2220377667-1876713056-1001\...\uTorrent) (Version: 3.4.2.32239 - BitTorrent Inc.)
    7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov)
    Adobe Flash Player 20 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 20.0.0.267 - Adobe Systems Incorporated)
    aioprnt (Version: 5.3.1.0 - Eastman Kodak Company) Hidden
    aioscnnr (x32 Version: 5.8.10.0 - Your Company Name) Hidden
    aioscnnr (x32 Version: 7.6.13.10 - Your Company Name) Hidden
    AntiLogger SDK version 1.6.6.247 (HKLM-x32\...\{4D46DE30-49FE-4043-99F7-D7E8C06175E0}_is1) (Version: 1.6.6.247 - Zemana Ltd.)
    AOMEI Backupper Professional Edition 2.2 (HKLM-x32\...\{A83692F5-3E9B-4E95-9E7E-B5DF55E6C09D}_is1) (Version: - AOMEI Technology Co., Ltd.)
    Apple Application Support (HKLM-x32\...\{83CAF0DE-8D3B-4C37-A631-2B8F16EC3031}) (Version: 3.1 - Apple Inc.)
    Apple Mobile Device Support (HKLM\...\{BDD99690-3541-4619-9D2A-3CDDB3E15F9E}) (Version: 8.0.5.6 - Apple Inc.)
    Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
    Application Compatibility Toolkit (Version: 8.100.26641 - Microsoft) Hidden
    Arma 3 (HKLM-x32\...\Steam App 107410) (Version: - Bohemia Interactive)
    ARMA 3 Launcher By Head (HKLM-x32\...\ARMA 3 Launcher By Head) (Version: 1.0.0.0 - Whoopshop Studios)
    ArmA3Sync 1.4.63 (HKLM-x32\...\{F097E7D7-D093-4394-9EED-43AFCCD12B7A}_is1) (Version: 1.4.63 - The [S.o.E] team)
    Assessments on Client (x32 Version: 8.100.26866 - Microsoft) Hidden
    AudibleManager (HKLM-x32\...\AudibleManager) (Version: 40.31391936.-1342176847.0 - Audible, Inc.)
    BattlEye for OA Uninstall (HKLM-x32\...\BattlEye for OA) (Version: - )
    C4USelfUpdater (x32 Version: 1.00.0000 - Your Company Name) Hidden
    CameraHelperMsi (x32 Version: 13.51.815.0 - Logitech) Hidden
    CCGLauncher version 0.0.0.7 (HKLM-x32\...\{78D51CE5-799C-4FCA-9635-6F61E19EA5E3}_is1) (Version: 0.0.0.7 - Custom Combat Gaming)
    center (x32 Version: 7.8.0.0 - Eastman Kodak Company) Hidden
    Command Center (HKLM-x32\...\{85A2564E-9ED9-448A-91E4-B9211EE58A08}_is1) (Version: 1.0.0.59 - MSI)
    Constant Guard Protection Suite (HKLM-x32\...\ID Vault) (Version: 1.13.820.2 - Comcast)
    Cyberduck 4.4 (13577) (HKLM-x32\...\Cyberduck) (Version: 4.4 (13577) - )
    DarthMod Empire (HKLM-x32\...\DarthMod Empire8.0 Platinum) (Version: 8.0 Platinum - )
    Dashlane (HKU\S-1-5-21-905238947-2220377667-1876713056-1001\...\Dashlane) (Version: 3.5.2.94565 - Dashlane SAS)
    DayZ Commander (HKLM-x32\...\{0170930E-68D6-4E85-88B2-82761CDE1F94}) (Version: 0.92.69 - Dotjosh Studios)
    Dual-Core Optimizer (HKLM-x32\...\{9FD6F1A8-5550-46AF-8509-271DF0E768B5}) (Version: 1.1.4.0169 - AMD)
    erLT (x32 Version: 1.20.138.34 - Logitech, Inc.) Hidden
    ESN Sonar (HKLM-x32\...\ESN Sonar-0.70.4) (Version: 0.70.4 - ESN Social Software AB)
    essentials (x32 Version: 7.8.0.0 - Eastman Kodak Company) Hidden
    EVGA Precision X 4.1.0 (HKLM-x32\...\PrecisionX) (Version: 4.1.0 - EVGA Corporation)
    f.lux (HKU\S-1-5-21-905238947-2220377667-1876713056-1001\...\Flux) (Version: - )
    Fallout 4 (HKLM-x32\...\Steam App 377160) (Version: - Bethesda Game Studios)
    Far Cry 3 (HKLM-x32\...\{E3B9C5A9-BD7A-4B56-B754-FAEA7DD6FA88}) (Version: 1.05 - Ubisoft)
    Fast Boot (HKLM-x32\...\{0F212E7A-65EB-4668-A8D7-749026A64F8E}_is1) (Version: 1.0.1.1 - MSI)
    ffdshow [rev 2527] [2008-12-19] (HKLM-x32\...\ffdshow_is1) (Version: 1.0 - )
    FileZilla Client 3.9.0.5 (HKLM-x32\...\FileZilla Client) (Version: 3.9.0.5 - Tim Kosse)
    Flvto Youtube Downloader (HKLM-x32\...\Flvto Youtube Downloader) (Version: 0.5.9 - Hotger)
    GameFly Download Manager (HKU\S-1-5-21-905238947-2220377667-1876713056-1001\...\7998bdbe8c95db7f) (Version: 1.0.0.98 - GameFly)
    GameStop App (HKLM-x32\...\GameStop App) (Version: 4.00 - GameStop)
    GameStop App (x32 Version: 4.00 - GameStop) Hidden
    GECK - New Vegas Edition (HKLM-x32\...\Steam App 22480) (Version: - )
    Ghost Recon Phantoms - EU (HKU\S-1-5-21-905238947-2220377667-1876713056-1001\...\d8be6c3f847d7d92) (Version: 1.36.1803.1 - Ubisoft)
    GOG Galaxy (HKLM-x32\...\{7258BA11-600C-430E-A759-27E2C691A335}_is1) (Version: - GOG.com)
    Google Chrome (HKLM-x32\...\Google Chrome) (Version: 47.0.2526.106 - Google Inc.)
    Google Drive (HKLM-x32\...\{1C3D2F92-D25E-4D98-B810-3F3B0857BF26}) (Version: 1.26.0707.2863 - Google, Inc.)
    Google Earth (HKLM-x32\...\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
    Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
    Google Update Helper (x32 Version: 1.3.29.1 - Google Inc.) Hidden
    HP Support Solutions Framework (HKLM-x32\...\{F6A11738-3EE4-4573-AEA5-6CD5D491C167}) (Version: 12.0.30.81 - Hewlett-Packard Company)
    Intel(R) Chipset Device Software (x32 Version: 10.0.20 - Intel(R) Corporation) Hidden
    Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 10.0.0.1168 - Intel Corporation)
    Intel(R) Smart Connect Technology (HKLM\...\{08B90A20-95D3-4725-84B9-AF6553E06C4F}) (Version: 5.0.10.2850 - Intel Corporation)
    Intel® Watchdog Timer Driver (Intel® WDT) (HKLM-x32\...\{3FD0C489-0F02-481a-A3E1-9754CD396761}) (Version: - Intel Corporation)
    Intel® Watchdog Timer Driver (Intel® WDT) (HKLM-x32\...\3FD0C489-0F02-481a-A3E1-9754CD396761) (Version: - Intel Corporation)
    iTunes (HKLM\...\{2ABBBD91-91E5-4AD7-929A-FE15D1DC0576}) (Version: 12.0.1.26 - Apple Inc.)
    Java 8 Update 51 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86418051F0}) (Version: 8.0.510 - Oracle Corporation)
    Kits Configuration Installer (x32 Version: 8.100.25984 - Microsoft) Hidden
    Kodak AIO Printer (Version: 7.8.1.0 - Eastman Kodak Company) Hidden
    KODAK AiO Software (HKLM-x32\...\{E0F274B7-592B-4669-8FB8-8D9825A09858}) (Version: 7.8.5.2 - Eastman Kodak Company)
    ksDIP (x32 Version: 3.20.0000.0001 - Eastman Kodak Company) Hidden
    Live Update (HKLM-x32\...\{4F46CF54-47D2-41F4-B230-B0954C544420}}_is1) (Version: 6.0.004 - MSI)
    Logitech Webcam Software (HKLM-x32\...\{D40EB009-0499-459c-A8AF-C9C110766215}) (Version: 2.80 - Logitech Inc.)
    Mad Max (HKLM-x32\...\Steam App 234140) (Version: - Avalanche Studios)
    Mass Effect™ 3 (HKLM-x32\...\{534A31BD-20F4-46b0-85CE-09778379663C}) (Version: 1.05.0.0 - Electronic Arts)
    Medieval II: Total War Kingdoms (HKLM-x32\...\Steam App 4780) (Version: - The Creative Assembly)
    MEGAsync (HKLM-x32\...\MEGAsync) (Version: - Mega Limited)
    Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation)
    Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{832D9DE0-8AFC-4689-9819-4DBBDEBD3E4F}) (Version: 3.5.92.0 - Microsoft Corporation)
    Microsoft Games for Windows Marketplace (HKLM-x32\...\{4CB0307C-565E-4441-86BE-0DF2E4FB828C}) (Version: 3.5.50.0 - Microsoft Corporation)
    Microsoft Office Professional Plus 2013 - en-us (HKLM\...\ProPlusRetail - en-us) (Version: 15.0.4779.1002 - Microsoft Corporation)
    Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.41105.0 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (HKLM\...\{350AA351-21FA-3270-8B7A-835434E766AD}) (Version: 9.0.21022 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
    Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
    Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
    Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\...\{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation)
    Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
    Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
    Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
    Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
    Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
    Mount & Blade: Warband (HKLM-x32\...\Mount & Blade: Warband) (Version: - GameStop)
    Mount & Blade: With Fire & Sword (HKLM-x32\...\Mount & Blade: With Fire & Sword) (Version: - GameStop)
    Mount&Blade Warband (HKLM-x32\...\Mount&Blade Warband) (Version: - )
    MSI Intel Extreme Tuning Utility (HKLM-x32\...\{fbd55c4e-e884-4210-a79b-5f158834b133}) (Version: 4.4.0.103 - Intel Corporation)
    MSI Intel Extreme Tuning Utility (x32 Version: 4.4.0.103 - Intel Corporation) Hidden
    MSI Super Charger (HKLM-x32\...\{7CDF10DD-A9B5-4DA3-AB95-E193248D4369}_is1) (Version: 1.2.025 - MSI)
    NETGEAR WNDA3100v2 wireless USB 2.0 adapter (HKLM-x32\...\{3C7839E7-21F4-49E0-B4D5-AC8ED818CCB0}) (Version: 1.03.000 - NETGEAR)
    Nexus Mod Manager (HKLM\...\6af12c54-643b-4752-87d0-8335503010de_is1) (Version: 0.61.4 - Black Tree Gaming)
    Notepad++ (HKLM-x32\...\Notepad++) (Version: 6.5.5 - Notepad++ Team)
    NVIDIA 3D Vision Controller Driver 352.65 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 352.65 - NVIDIA Corporation)
    NVIDIA 3D Vision Driver 358.91 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 358.91 - NVIDIA Corporation)
    NVIDIA GeForce Experience 2.5.15.54 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.5.15.54 - NVIDIA Corporation)
    NVIDIA Graphics Driver 358.91 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 358.91 - NVIDIA Corporation)
    NVIDIA HD Audio Driver 1.3.34.4 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.4 - NVIDIA Corporation)
    NVIDIA Miracast Virtual Audio 353.30 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Miracast.VirtualAudio) (Version: 353.30 - NVIDIA Corporation)
    NVIDIA PhysX System Software 9.15.0428 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.15.0428 - NVIDIA Corporation)
    ocr (x32 Version: 6.2.3.50 - Eastman Kodak Company) Hidden
    Office 15 Click-to-Run Extensibility Component (x32 Version: 15.0.4779.1002 - Microsoft Corporation) Hidden
    Office 15 Click-to-Run Licensing Component (Version: 15.0.4779.1002 - Microsoft Corporation) Hidden
    Office 15 Click-to-Run Localization Component (x32 Version: 15.0.4779.1002 - Microsoft Corporation) Hidden
    OnLive (HKLM-x32\...\OnLive) (Version: - OnLive)
    ooVoo (HKLM-x32\...\{FAA7F8FF-3C05-4A61-8F14-D8A6E9ED6623}) (Version: 3.5.9041 - ooVoo LLC.)
    OpenAL (HKLM-x32\...\OpenAL) (Version: - )
    Origin (HKLM-x32\...\Origin) (Version: 9.2.1.4399 - Electronic Arts, Inc.)
    Playfire (HKLM-x32\...\{6b69b0a4-05aa-4ee8-a108-0ebb857ecba4}) (Version: 0.0.72.0 - Playfire)
    Playfire (x32 Version: 0.0.72.0 - Playfire) Hidden
    PowerISO (HKLM-x32\...\PowerISO) (Version: 5.7 - Power Software Ltd)
    PreReq (x32 Version: 6.2.4.0 - Eastman Kodak Company) Hidden
    PrintProjects (HKLM-x32\...\PrintProjects) (Version: 1.0.0.9282 - RocketLife Inc.)
    PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.993 - Even Balance, Inc.)
    Qualcomm Atheros Bandwidth Control Filter Driver (Version: 1.1.42.1045 - Qualcomm Atheros) Hidden
    Qualcomm Atheros Killer E220x Drivers (Version: 1.1.42.1045 - Qualcomm Atheros) Hidden
    Qualcomm Atheros Killer Network Manager Suite (HKLM-x32\...\{E70DB50B-10B4-46BC-9DE2-AB8B49E061EE}) (Version: 1.1.42.1045 - Qualcomm Atheros)
    Qualcomm Atheros Network Manager (Version: 1.1.42.1045 - Qualcomm Atheros) Hidden
    QuickTime 7 (HKLM-x32\...\{111EE7DF-FC45-40C7-98A7-753AC46B12FB}) (Version: 7.75.80.95 - Apple Inc.)
    RaidCall (HKLM-x32\...\RaidCall) (Version: 7.2.4-1.0.7299.14 - raidcall.com)
    Rainbow Six Siege - Closed Beta (HKLM-x32\...\Uplay Install 1001) (Version: - Ubisoft)
    Razer Cortex (HKLM-x32\...\Razer Cortex_is1) (Version: 6.0.29.0 - Razer Inc.)
    Razer Synapse 2.0 (HKLM-x32\...\{0D78BEE2-F8FF-4498-AF1A-3FF81CED8AC6}) (Version: 1.18.13 - Razer Inc.)
    Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7535 - Realtek Semiconductor Corp.)
    REALTEK Wireless LAN Driver and Utility (HKLM-x32\...\{9C049499-055C-4a0c-A916-1D8CA1FF45EB}) (Version: 1.00.0150 - REALTEK Semiconductor Corp.)
    resident evil 4 / biohazard 4 (HKLM-x32\...\Steam App 254700) (Version: - Capcom)
    Rockstar Games Social Club (HKLM-x32\...\Rockstar Games Social Club) (Version: 1.1.0.6 - Rockstar Games)
    SHIELD Streaming (Version: 4.1.500 - NVIDIA Corporation) Hidden
    SHIELD Wireless Controller Driver (Version: 2.5.15.54 - NVIDIA Corporation) Hidden
    SimCity™ (HKLM-x32\...\{F70FDE4B-8F86-4eb6-8C8E-636EC89F6419}) (Version: 4.0.86.0859 - Electronic Arts)
    SimCity™ Limited Edition (HKLM-x32\...\SimCity™ Limited Edition) (Version: - GameStop)
    Skype™ 7.16 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.16.102 - Skype Technologies S.A.)
    Smart Utilities (HKLM-x32\...\{009E5DF2-3F97-480B-89DA-F2D5E672E14A}_is1) (Version: 2.0.0.04 - MSI)
    Sound Blaster Cinema (HKLM-x32\...\{8801CA65-921A-4CCC-9D63-879D1D0BAA97}) (Version: 1.00.05 - Creative Technology Limited)
    Spotify (HKU\S-1-5-21-905238947-2220377667-1876713056-1001\...\Spotify) (Version: 1.0.20.94.g8f8543b3 - Spotify AB)
    STAR WARS™ Battlefront™ Beta (HKLM-x32\...\{8A863B64-C9BE-4203-9ED7-92981CF690D3}) (Version: 1.0.4.9084 - Electronic Arts)
    Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation)
    SWClient (HKU\S-1-5-21-905238947-2220377667-1876713056-1001\...\SWClient) (Version: 12 - )
    System Requirements Lab (HKLM-x32\...\{FAB9454C-6A8D-4031-9652-8B1B1D561456}) (Version: 6.0.7.0 - Husdawg, LLC)
     
  5. Chris Waters

    Chris Waters TS Rookie Topic Starter Posts: 23

    System Requirements Lab CYRI (HKLM-x32\...\{E362724E-9320-4946-AF34-874E7B6B2927}) (Version: 6.0.7.0 - Husdawg, LLC)
    TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.18 - TeamSpeak Systems GmbH)
    TeamViewer 8 (HKLM-x32\...\TeamViewer 8) (Version: 8.0.19617 - TeamViewer)
    The Witcher 3 - Wild Hunt (HKLM-x32\...\1207664643_is1) (Version: 1.0.11.0 - GOG.com)
    Third Age - Total War 3.0 (Part 1of2) (HKU\S-1-5-21-905238947-2220377667-1876713056-1001\...\Third Age - Total War 3.0 (Part 1of2)) (Version: - )
    Third Age - Total War 3.0 (Part 2of2) (HKU\S-1-5-21-905238947-2220377667-1876713056-1001\...\Third Age - Total War 3.0 (Part 2of2)) (Version: - )
    Tom Clancy's Ghost Recon Future Soldier (HKLM-x32\...\{6D87CAD9-9B94-4421-A439-B25F8DE14575}) (Version: 1.8 - Ubisoft)
    Tom Clancy's Rainbow Six Siege (HKLM-x32\...\Steam App 359550) (Version: - Ubisoft Montreal)
    Tom Clancy's Splinter Cell Conviction (HKLM-x32\...\{6D8DDB4A-C263-40DE-BA16-AFDAD159D59A}) (Version: 1.04.000 - Ubisoft)
    Tom Clancy's Splinter Cell® Blacklist™ (HKLM-x32\...\{A6356F2F-D3E1-4D83-9AA2-72871DD0C298}) (Version: 1.03 - Ubisoft)
    Toolkit Documentation (x32 Version: 8.100.26866 - Microsoft) Hidden
    Total War: ATTILA (HKLM-x32\...\Steam App 325610) (Version: - Creative Assembly)
    Total War: ROME II - Emperor Edition (HKLM-x32\...\Steam App 214950) (Version: - Creative Assembly)
    Total War: SHOGUN 2 (HKLM-x32\...\Steam App 34330) (Version: - The Creative Assembly)
    Uplay (HKLM-x32\...\Uplay) (Version: 13.0 - Ubisoft)
    VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0 - DivX, Inc) Hidden
    VGA Boost (HKLM-x32\...\{809ACFAE-9A4D-4C60-9223-D8B615CD8CBA}}_is1) (Version: 1.0.0.7 - MSI)
    Warface Launcher (Beta) (HKLM-x32\...\{28D1723C-31C4-4A83-9799-DFFB3739026D}) (Version: 1.0.0 - Crytek GmbH)
    Windows Assessment and Deployment Kit for Windows 8.1 (HKLM-x32\...\{e9e06304-a604-434b-b35f-d9beb94dc06d}) (Version: 8.100.26866 - Microsoft Corporation)
    WinRAR 4.20 (64-bit) (HKLM\...\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH)
    WinSCP 5.1.7 (HKLM-x32\...\winscp3_is1) (Version: 5.1.7 - Martin Prikryl)
    WPT Redistributables (x32 Version: 8.100.26866 - Microsoft) Hidden
    WPTx64 (x32 Version: 8.100.26837 - Microsoft) Hidden
    XFINITY Toolbar (HKLM-x32\...\xfin_portal) (Version: 4.0.0.23 - )

    ==================== Custom CLSID (Whitelisted): ==========================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    CustomCLSID: HKU\S-1-5-21-905238947-2220377667-1876713056-1001_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\Chris\AppData\Local\Microsoft\OneDrive\17.3.6281.1202\FileCoAuth.exe (Microsoft Corporation)

    ==================== Scheduled Tasks (Whitelisted) =============

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    Task: {08237936-FDCA-468B-B1F4-DD11E236043E} - System32\Tasks\GenericSettingsHandler\Windows-Credentials\RetrySyncTask_for_S-1-5-21-905238947-2220377667-1876713056-1001
    Task: {0CFE2E40-6A97-48C5-9F38-DE82315CF1B0} - System32\Tasks\Microsoft\Windows\UPnP\UPnPHostConfig => config upnphost start= auto
    Task: {1DD8FD4F-000B-4AE4-93D3-47194D05F82D} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.)
    Task: {3B955F3F-3903-464D-A25C-5C0F10CCB56B} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office 15\root\Office15\msoia.exe [2015-10-27] (Microsoft Corporation)
    Task: {55A3DED3-A14A-44A6-8D79-E08F702D03A1} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2015-10-13] (Microsoft Corporation)
    Task: {55F310C8-8D48-4D80-95A9-3153D44BB31A} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2015-12-09] (Microsoft Corporation)
    Task: {7A4ADBC2-99A4-403B-B888-421D3663623A} - System32\Tasks\AVG-Secure-Search-Update_0414c_rmv => C:\Program Files (x86)\Avg Secure Update\AVG-Secure-Search-Update_0414c.exe [2014-04-21] ()
    Task: {835AAF6E-E334-4D3D-9AC3-03C171B90452} - System32\Tasks\{24F190A2-8311-4B5B-BB2A-33313F397938} => pcalua.exe -a "C:\Users\Chris\Downloads\dotnetfx3setup (1).exe" -d C:\Users\Chris\Downloads
    Task: {8FC16075-C313-4DDC-B2DE-25320B556CDA} - System32\Tasks\{61A30D71-B4AB-47F7-ABAF-734ACEB8153E} => pcalua.exe -a C:\Users\Chris\Downloads\dotnetfx3setup.exe -d C:\Users\Chris\Downloads
    Task: {A34DDB05-9BE8-4FF3-9EBA-7841042E77AF} - \CCleanerSkipUAC -> No File <==== ATTENTION
    Task: {AA51978B-A90B-4A16-AF5A-AC139D834A22} - System32\Tasks\Razer_Game_Booster_AutoUpdate => C:\Program Files (x86)\Razer\Razer Game Booster\AutoUpdate.exe
    Task: {AD15EADE-B78E-4C86-BB52-38C5734148F7} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2015-10-13] (Microsoft Corporation)
    Task: {B6C59A53-638D-4361-9637-ED142E8D2F0E} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office 15\root\Office15\msoia.exe [2015-10-27] (Microsoft Corporation)
    Task: {CA88B156-0748-4553-8C86-62E11B8BB011} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-12-29] (Adobe Systems Incorporated)
    Task: {CD8E5FD8-3B3B-4005-B9E7-E8A44CFD0B52} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.)
    Task: {D0560D47-7FDB-4C65-B83C-3CB199CE31DB} - System32\Tasks\{4D56C402-4B79-4A2B-95EF-FE1034AB0702} => pcalua.exe -a C:\Users\Chris\AppData\Local\GreatArcadeHits\GAHUninstaller.exe
    Task: {E125A420-0021-430D-B5B2-27B680995785} - System32\Tasks\{9464F175-373C-477C-8831-D8CF33DDE712} => pcalua.exe -a "C:\ProgramData\Package Cache\{62340a00-1b99-4a03-9efc-765636e35146}\Wallpaper_Changer_IM_Setup.exe" -c /uninstall
    Task: {EA61B3DD-2973-4159-8A45-7F825E77CFB6} - System32\Tasks\AVG-Secure-Search-Update_0414c_rel => C:\Program Files (x86)\Avg Secure Update\AVG-Secure-Search-Update_0414c.exe [2014-04-21] ()
    Task: {FFBF7BEF-253F-4714-BBDE-F582765F763B} - System32\Tasks\{338D639B-F43C-4196-B5E4-5515837EA181} => pcalua.exe -a C:\Users\Chris\Downloads\dotnetfx3_x64.exe -d C:\Users\Chris\Downloads

    (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

    Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
    Task: C:\WINDOWS\Tasks\AVG-Secure-Search-Update_0414c_rel.job => C:\Program Files (x86)\Avg Secure Update\AVG-Secure-Search-Update_0414c.exe
    Task: C:\WINDOWS\Tasks\AVG-Secure-Search-Update_0414c_rmv.job => C:\Program Files (x86)\Avg Secure Update\AVG-Secure-Search-Update_0414c.exe
    Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

    ==================== Shortcuts =============================

    (The entries could be listed to be restored or removed.)

    ==================== Loaded Modules (Whitelisted) ==============

    2014-03-19 14:12 - 2015-10-13 04:34 - 00105640 _____ () C:\Program Files\Microsoft Office 15\ClientX64\ApiClient.dll
    2014-08-16 01:26 - 2014-04-03 14:22 - 00024048 _____ () C:\MSI\Smart Utilities\SuperRAIDSvc.exe
    2015-06-23 14:11 - 2015-06-23 14:11 - 00187048 _____ () C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe
    2014-08-16 01:26 - 2014-04-02 09:47 - 01990144 _____ () C:\Program Files (x86)\MSI\Command Center\MSIControlService.exe
    2013-06-20 17:03 - 2011-12-14 16:53 - 00303360 _____ () C:\Program Files (x86)\NETGEAR\WNDA3100v2\WifiSvc.exe
    2015-10-30 02:18 - 2015-10-30 02:18 - 00185856 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll
    2015-12-11 10:54 - 2015-11-05 10:08 - 00116344 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
    2014-08-16 01:26 - 2014-03-31 14:24 - 04115456 _____ () C:\Program Files (x86)\MSI\Command Center\CPU\MSICPUService.exe
    2015-12-11 13:43 - 2015-12-11 13:43 - 02653816 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
    2015-12-11 13:43 - 2015-12-11 13:43 - 02653816 _____ () C:\WINDOWS\System32\CoreUIComponents.dll
    2015-10-27 14:37 - 2015-09-01 11:04 - 08901184 _____ () C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\1033\GrooveIntlResource.dll
    2014-05-01 09:13 - 2014-05-01 09:13 - 00470016 _____ () C:\Users\Chris\AppData\Local\MEGAsync\ShellExtX64.dll
    2014-05-01 14:29 - 2014-05-01 14:29 - 00098304 _____ () C:\Program Files (x86)\FileZilla FTP Client\fzshellext_64.dll
    2012-06-18 10:24 - 2012-06-18 10:24 - 00222720 _____ () C:\Program Files (x86)\Notepad++\NppShell_05.dll
    2015-12-17 18:11 - 2015-12-06 23:14 - 00093696 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\Windows.UI.Shell.SharedUtilities.dll
    2015-12-17 18:11 - 2015-12-06 23:00 - 00472064 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll
    2014-04-21 18:19 - 2014-04-21 18:19 - 02725912 _____ () C:\Program Files (x86)\Avg Secure Update\AVG-Secure-Search-Update_0414c.exe
    2015-12-17 18:11 - 2015-12-06 22:37 - 07992832 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
    2015-12-17 18:11 - 2015-12-06 22:33 - 00591360 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
    2015-12-17 18:11 - 2015-12-06 22:34 - 02483200 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
    2015-12-17 18:11 - 2015-12-06 22:36 - 04089856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
    2014-08-16 01:15 - 2012-11-01 10:23 - 00089600 _____ () C:\WINDOWS\SYSTEM32\CmdRtr64.DLL
    2014-08-16 01:15 - 2012-11-01 10:21 - 00325120 _____ () C:\WINDOWS\SYSTEM32\APOMgr64.DLL
    2013-02-09 14:21 - 2013-02-09 14:21 - 06257664 _____ () C:\Users\Chris\AppData\Roaming\SWClient\swclient.exe
    2014-04-17 10:02 - 2014-04-17 10:02 - 00300544 _____ () C:\Program Files\Qualcomm Atheros\Network Manager\NetworkManager.exe
    2014-08-24 22:12 - 2015-10-23 07:40 - 00285568 _____ () C:\Users\Chris\AppData\Roaming\Dashlane\DashlanePlugin.exe
    2015-12-17 13:02 - 2015-12-17 13:02 - 00144384 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.12.15004.0_x86__8wekyb3d8bbwe\SkypeHost.exe
    2016-01-08 22:39 - 2016-01-08 22:39 - 03746816 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.1601.36020.0_x64__8wekyb3d8bbwe\Calculator.exe
    2015-12-14 18:38 - 2015-12-14 18:39 - 00258560 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.1601.36020.0_x64__8wekyb3d8bbwe\StoreRatingPromotion.dll
    2014-08-16 01:26 - 2014-04-03 14:19 - 01712128 _____ () C:\MSI\Smart Utilities\SuperRAIDExt.DLL
    2013-06-20 17:03 - 2011-12-14 09:22 - 00368640 _____ () C:\Program Files (x86)\NETGEAR\WNDA3100v2\WifiLib.dll
    2014-10-11 13:06 - 2014-10-11 13:06 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
    2014-10-11 13:05 - 2014-10-11 13:05 - 01044776 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
    2015-01-18 21:03 - 2014-12-24 18:15 - 00270040 _____ () C:\Program Files (x86)\AOMEI Backupper Professional Edition 2.2\UiLogic.dll
    2015-01-18 21:03 - 2014-12-24 18:15 - 00278232 _____ () C:\Program Files (x86)\AOMEI Backupper Professional Edition 2.2\Comn.dll
    2015-01-18 21:03 - 2014-12-24 18:15 - 00229080 _____ () C:\Program Files (x86)\AOMEI Backupper Professional Edition 2.2\diskmgr.dll
    2015-01-18 21:03 - 2014-12-24 18:15 - 00343768 _____ () C:\Program Files (x86)\AOMEI Backupper Professional Edition 2.2\ImgFile.dll
    2015-01-18 21:03 - 2014-12-24 18:15 - 00118488 _____ () C:\Program Files (x86)\AOMEI Backupper Professional Edition 2.2\FuncLogic.dll
    2015-01-18 21:03 - 2014-12-24 18:15 - 00028376 _____ () C:\Program Files (x86)\AOMEI Backupper Professional Edition 2.2\Encrypt.dll
    2015-01-18 21:03 - 2014-12-24 18:15 - 00483032 _____ () C:\Program Files (x86)\AOMEI Backupper Professional Edition 2.2\EnumFolder.dll
    2015-01-18 21:03 - 2014-12-24 18:15 - 00073432 _____ () C:\Program Files (x86)\AOMEI Backupper Professional Edition 2.2\Compress.dll
    2015-01-18 21:03 - 2014-12-24 18:15 - 00098008 _____ () C:\Program Files (x86)\AOMEI Backupper Professional Edition 2.2\BrLog.dll
    2015-01-18 21:03 - 2014-12-24 18:15 - 00077528 _____ () C:\Program Files (x86)\AOMEI Backupper Professional Edition 2.2\Ldm.dll
    2015-01-18 21:03 - 2014-12-24 18:15 - 00061144 _____ () C:\Program Files (x86)\AOMEI Backupper Professional Edition 2.2\Device.dll
    2015-01-18 21:03 - 2014-12-24 18:15 - 00265944 _____ () C:\Program Files (x86)\AOMEI Backupper Professional Edition 2.2\BrFat.dll
    2015-01-18 21:03 - 2014-12-24 18:15 - 00384728 _____ () C:\Program Files (x86)\AOMEI Backupper Professional Edition 2.2\BrNtfs.dll
    2015-01-18 21:03 - 2014-12-24 18:15 - 00241368 _____ () C:\Program Files (x86)\AOMEI Backupper Professional Edition 2.2\Clone.dll
    2015-01-18 21:03 - 2014-12-24 18:15 - 00102104 _____ () C:\Program Files (x86)\AOMEI Backupper Professional Edition 2.2\Backup.dll
    2015-01-18 21:03 - 2014-12-24 18:15 - 00151256 _____ () C:\Program Files (x86)\AOMEI Backupper Professional Edition 2.2\FlBackup.dll
    2015-01-18 21:03 - 2013-01-17 17:38 - 02403504 _____ () C:\Program Files (x86)\AOMEI Backupper Professional Edition 2.2\QtCore4.dll
    2015-01-18 21:03 - 2014-12-24 18:15 - 00102104 _____ () C:\Program Files (x86)\AOMEI Backupper Professional Edition 2.2\BrVol.dll
    2015-01-18 21:03 - 2014-12-24 18:15 - 00253656 _____ () C:\Program Files (x86)\AOMEI Backupper Professional Edition 2.2\GptBcd.dll
    2014-02-19 17:51 - 2014-02-19 17:51 - 01241560 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll
    2013-06-19 20:24 - 2009-12-09 20:20 - 00126976 _____ () C:\Program Files (x86)\REALTEK\11n USB Wireless LAN Utility\EnumDevLib.dll
    2015-07-26 13:01 - 2015-10-11 22:05 - 00013088 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll
    2014-09-06 11:44 - 2014-09-06 11:44 - 00035328 _____ () C:\Program Files (x86)\FileZilla FTP Client\fzshellext.dll
    2014-05-24 11:41 - 2014-05-24 11:41 - 00091648 _____ () C:\Program Files (x86)\FileZilla FTP Client\libgcc_s_sjlj-1.dll
    2014-05-24 11:41 - 2014-05-24 11:41 - 00892416 _____ () C:\Program Files (x86)\FileZilla FTP Client\libstdc++-6.dll
    2015-10-27 14:37 - 2015-09-01 07:25 - 08901184 _____ () C:\Program Files\Microsoft Office 15\root\Office15\1033\GrooveIntlResource.dll
    2014-05-01 09:15 - 2014-05-01 09:15 - 00463360 _____ () C:\Users\Chris\AppData\Local\MEGAsync\ShellExtX32.dll
    2015-12-16 15:26 - 2015-12-10 22:54 - 01583432 _____ () C:\Program Files (x86)\Google\Chrome\Application\47.0.2526.106\libglesv2.dll
    2015-12-16 15:26 - 2015-12-10 22:54 - 00081224 _____ () C:\Program Files (x86)\Google\Chrome\Application\47.0.2526.106\libegl.dll
    2014-11-16 22:41 - 2014-11-16 22:41 - 00316576 _____ () C:\Program Files\Microsoft Office 15\Root\VFS\ProgramFilesCommonX86\Microsoft Shared\OFFICE15\AppVIsvStream32.dll
    2015-10-23 07:39 - 2015-10-23 07:39 - 05762944 _____ () C:\Users\Chris\AppData\Roaming\Dashlane\3.5.2.94565\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\components\KWData.3.5.2.94565.dll
    2015-10-23 07:39 - 2015-10-23 07:39 - 00443264 _____ () C:\Users\Chris\AppData\Roaming\Dashlane\3.5.2.94565\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\components\KWUtils.3.5.2.94565.dll
    2015-10-23 07:39 - 2015-10-23 07:39 - 00422784 _____ () C:\Users\Chris\AppData\Roaming\Dashlane\3.5.2.94565\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\components\KWDebug.3.5.2.94565.dll
    2015-10-23 07:39 - 2015-10-23 07:39 - 31264640 _____ () C:\Users\Chris\AppData\Roaming\Dashlane\3.5.2.94565\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\components\KWExternLib.3.5.2.94565.dll
    2015-10-23 07:39 - 2015-10-23 07:39 - 00339328 _____ () C:\Users\Chris\AppData\Roaming\Dashlane\3.5.2.94565\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\components\KWDebugDll_win32.3.5.2.94565.dll
    2015-10-23 07:39 - 2015-10-23 07:39 - 13234048 _____ () C:\Users\Chris\AppData\Roaming\Dashlane\3.5.2.94565\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\components\KWMainLib.3.5.2.94565.dll
    2015-10-23 07:39 - 2015-10-23 07:39 - 00276352 _____ () C:\Users\Chris\AppData\Roaming\Dashlane\3.5.2.94565\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\components\KWMainLib_win.3.5.2.94565.dll
    2015-10-23 07:39 - 2015-10-23 07:39 - 02073472 _____ () C:\Users\Chris\AppData\Roaming\Dashlane\3.5.2.94565\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\components\KWMainLibData.3.5.2.94565.dll
    2015-10-23 07:39 - 2015-10-23 07:39 - 00338304 _____ () C:\Users\Chris\AppData\Roaming\Dashlane\3.5.2.94565\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\components\Kwift_DP.3.5.2.94565.dll
    2015-12-24 16:32 - 2015-12-24 07:46 - 16792256 _____ () C:\Users\Chris\AppData\Local\Google\Chrome\User Data\PepperFlash\20.0.0.267\pepflashplayer.dll
    2015-12-17 13:02 - 2015-12-17 13:02 - 00141312 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.12.15004.0_x86__8wekyb3d8bbwe\SkypeBackgroundTasks.dll
    2015-12-17 13:02 - 2015-12-17 13:02 - 21845504 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.12.15004.0_x86__8wekyb3d8bbwe\SkyWrap.dll
    2015-11-25 20:18 - 2015-11-25 20:18 - 00147136 ____R () C:\Program Files (x86)\Skype\Phone\ssScreenVVS2.dll
    2013-05-06 16:05 - 2015-11-10 14:55 - 00778752 _____ () C:\Program Files (x86)\Steam\SDL2.dll
    2015-01-26 20:30 - 2015-07-03 11:12 - 04962816 _____ () C:\Program Files (x86)\Steam\v8.dll
    2014-05-22 21:00 - 2015-12-14 15:01 - 02547280 _____ () C:\Program Files (x86)\Steam\video.dll
    2014-08-28 17:41 - 2015-09-23 19:33 - 02549248 _____ () C:\Program Files (x86)\Steam\libavcodec-56.dll
    2014-08-28 17:41 - 2015-09-23 19:33 - 00491008 _____ () C:\Program Files (x86)\Steam\libavformat-56.dll
    2014-08-28 17:41 - 2015-09-23 19:33 - 00332800 _____ () C:\Program Files (x86)\Steam\libavresample-2.dll
    2014-08-28 17:41 - 2015-09-23 19:33 - 00442880 _____ () C:\Program Files (x86)\Steam\libavutil-54.dll
    2014-08-28 17:41 - 2015-09-23 19:33 - 00485888 _____ () C:\Program Files (x86)\Steam\libswscale-3.dll
    2015-01-26 20:30 - 2015-07-03 11:12 - 01556992 _____ () C:\Program Files (x86)\Steam\icui18n.dll
    2015-01-26 20:30 - 2015-07-03 11:12 - 01187840 _____ () C:\Program Files (x86)\Steam\icuuc.dll
    2013-06-06 13:06 - 2015-12-14 15:01 - 00804432 _____ () C:\Program Files (x86)\Steam\bin\chromehtml.DLL
    2015-07-22 21:58 - 2015-11-03 17:00 - 00201728 _____ () C:\Program Files (x86)\Steam\bin\openvr_api.dll
    2013-03-26 15:16 - 2015-11-16 19:31 - 47846176 _____ () C:\Program Files (x86)\Steam\bin\libcef.dll
    2015-01-26 20:30 - 2015-09-24 18:56 - 00119208 _____ () C:\Program Files (x86)\Steam\winh264.dll

    ==================== Alternate Data Streams (Whitelisted) =========

    (If an entry is included in the fixlist, only the ADS will be removed.)


    ==================== Safe Mode (Whitelisted) ===================

    (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


    ==================== EXE Association (Whitelisted) ===============

    (If an entry is included in the fixlist, the registry item will be restored to default or removed.)


    ==================== Internet Explorer trusted/restricted ===============

    (If an entry is included in the fixlist, it will be removed from the registry.)

    IE trusted site: HKU\S-1-5-21-905238947-2220377667-1876713056-1001\...\clonewarsadventures.com -> clonewarsadventures.com
    IE trusted site: HKU\S-1-5-21-905238947-2220377667-1876713056-1001\...\freerealms.com -> freerealms.com
    IE trusted site: HKU\S-1-5-21-905238947-2220377667-1876713056-1001\...\soe.com -> soe.com
    IE trusted site: HKU\S-1-5-21-905238947-2220377667-1876713056-1001\...\sony.com -> sony.com

    ==================== Hosts content: ===============================

    (If needed Hosts: directive could be included in the fixlist to reset Hosts.)

    2013-08-22 08:25 - 2013-08-22 08:25 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts


    ==================== Other Areas ============================

    (Currently there is no automatic fix for this section.)

    HKU\S-1-5-21-905238947-2220377667-1876713056-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Chris\AppData\Local\Microsoft\Windows\Themes\RoamedThemeFiles\DesktopBackground\fog.jpg
    DNS Servers: 75.75.75.75 - 75.75.76.76
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
    Windows Firewall is enabled.

    ==================== MSCONFIG/TASK MANAGER disabled items ==

    (Currently there is no automatic fix for this section.)

    HKLM\...\StartupApproved\StartupFolder: => "NETGEAR WNDA3100v2 Genie.lnk"
    HKLM\...\StartupApproved\Run: => "Logitech Download Assistant"
    HKLM\...\StartupApproved\Run: => "Nvtmru"
    HKLM\...\StartupApproved\Run: => "EKIJ5000StatusMonitor"
    HKLM\...\StartupApproved\Run: => "NvBackend"
    HKLM\...\StartupApproved\Run32: => "Conime"
    HKLM\...\StartupApproved\Run32: => "SunJavaUpdateSched"
    HKLM\...\StartupApproved\Run32: => "EKStatusMonitor"
    HKLM\...\StartupApproved\Run32: => "vProt"
    HKLM\...\StartupApproved\Run32: => "LWS"
    HKLM\...\StartupApproved\Run32: => "PWRISOVM.EXE"
    HKLM\...\StartupApproved\Run32: => "APSDaemon"
    HKLM\...\StartupApproved\Run32: => "iTunesHelper"
    HKLM\...\StartupApproved\Run32: => "amd_dc_opt"
    HKLM\...\StartupApproved\Run32: => "UpdReg"
    HKLM\...\StartupApproved\Run32: => "QuickTime Task"
    HKLM\...\StartupApproved\Run32: => "Razer Synapse"
    HKLM\...\StartupApproved\Run32: => "Command Center"
    HKLM\...\StartupApproved\Run32: => "Fast Boot"
    HKLM\...\StartupApproved\Run32: => "Live Update"
    HKU\S-1-5-21-905238947-2220377667-1876713056-1001\...\StartupApproved\StartupFolder: => "GameStop Now.lnk"
    HKU\S-1-5-21-905238947-2220377667-1876713056-1001\...\StartupApproved\StartupFolder: => "MEGAsync.lnk"
    HKU\S-1-5-21-905238947-2220377667-1876713056-1001\...\StartupApproved\Run: => "uTorrent"
    HKU\S-1-5-21-905238947-2220377667-1876713056-1001\...\StartupApproved\Run: => "ooVoo.exe"
    HKU\S-1-5-21-905238947-2220377667-1876713056-1001\...\StartupApproved\Run: => "Steam"
    HKU\S-1-5-21-905238947-2220377667-1876713056-1001\...\StartupApproved\Run: => "SearchProtection"
    HKU\S-1-5-21-905238947-2220377667-1876713056-1001\...\StartupApproved\Run: => "AVG-Secure-Search-Update_0414c"
    HKU\S-1-5-21-905238947-2220377667-1876713056-1001\...\StartupApproved\Run: => "Wallpaper Changer"
    HKU\S-1-5-21-905238947-2220377667-1876713056-1001\...\StartupApproved\Run: => "Dashlane"
    HKU\S-1-5-21-905238947-2220377667-1876713056-1001\...\StartupApproved\Run: => "DashlanePlugin"

    ==================== FirewallRules (Whitelisted) ===============
     
  6. Chris Waters

    Chris Waters TS Rookie Topic Starter Posts: 23

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
    FirewallRules: [{C2444A84-3249-432F-8461-FC97A79838D4}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\UcMapi.exe
    FirewallRules: [{D6053A8C-C673-47D3-9519-39BB7514816C}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\UcMapi.exe
    FirewallRules: [{DD3C0B4B-0C6A-494E-8002-0207653B7A08}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\Lync.exe
    FirewallRules: [{2B9D3974-2829-495B-AA84-3FF203D62198}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\Lync.exe
    FirewallRules: [{81AA013F-E291-4B62-940F-9D231ED66043}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Fallout 4\Fallout4Launcher.exe
    FirewallRules: [{5BB01ABB-9391-4AF1-B1ED-70E56FD9B67D}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Fallout 4\Fallout4Launcher.exe
    FirewallRules: [{CB190078-286A-4660-BD8E-509C1B0A2563}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Warface\live\nw.exe
    FirewallRules: [{E19CE973-967C-4445-B37E-66A257ABDCA1}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Warface\live\nw.exe
    FirewallRules: [{86F1EAE3-669D-4C61-83DB-94126835E699}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Resident Evil 4\Bin32\bio4.exe
    FirewallRules: [{DCA82765-146E-4720-AEFD-ED9499BA0EDF}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Resident Evil 4\Bin32\bio4.exe
    FirewallRules: [{AF489431-45B1-456E-9D7C-45FA7F5BD128}] => (Allow) C:\Program Files (x86)\Origin Games\STAR WARS Battlefront Beta\starwarsbattlefront.exe
    FirewallRules: [{974E933F-413C-4A94-BB22-D0A51D0E4CE9}] => (Allow) C:\Program Files (x86)\Origin Games\STAR WARS Battlefront Beta\starwarsbattlefront.exe
    FirewallRules: [{B635DFAE-89DD-4BC7-AF74-22B9DB255F7D}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\games\Rainbow Six Siege - Closed Beta\RainbowSix.exe
    FirewallRules: [{956A046E-F15C-4D2C-9E9E-EAFED4651BAB}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\games\Rainbow Six Siege - Closed Beta\RainbowSix.exe
    FirewallRules: [{0589CE67-91BB-4594-96FB-E8BA513EF3F5}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Total War Rome II\launcher\launcher.exe
    FirewallRules: [{12C04F82-7E57-41B7-9766-1922E7DD694C}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Total War Rome II\launcher\launcher.exe
    FirewallRules: [UDP Query User{E5720613-4FD1-4E27-AF66-DCD27015A0E7}C:\users\chris\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\chris\appdata\roaming\spotify\spotify.exe
    FirewallRules: [TCP Query User{B1057F37-B7D6-4F42-83B0-753AC75AF288}C:\users\chris\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\chris\appdata\roaming\spotify\spotify.exe
    FirewallRules: [{AED18FE0-3981-43E0-9595-4719072988C7}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Mad Max\MadMax.exe
    FirewallRules: [{CFAC31AC-80F6-4C64-8C15-E7354683C9FA}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Mad Max\MadMax.exe
    FirewallRules: [{BECC1CB0-941E-401C-B849-4CB7A4FF8832}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Total War SHOGUN 2\benchmarks\benchmark_specify_properties.bat
    FirewallRules: [{6C1ECCBD-BE38-4747-AB7E-606DCC0FF0E9}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Total War SHOGUN 2\benchmarks\benchmark_specify_properties.bat
    FirewallRules: [{F2D6084B-7419-4DEB-8E3E-AE711013EFA1}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Total War SHOGUN 2\benchmarks\benchmark_specify_properties.bat
    FirewallRules: [{5B57547F-690F-4A22-9D9D-8E822673C27D}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Total War SHOGUN 2\benchmarks\benchmark_specify_properties.bat
    FirewallRules: [{3DD985DF-C6EB-4085-868E-CCF42778D8CF}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Total War SHOGUN 2\benchmarks\benchmark_current_settings.bat
    FirewallRules: [{CC4194C2-3FF7-40A9-A9EC-D5E61B4A04D7}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Total War SHOGUN 2\benchmarks\benchmark_current_settings.bat
    FirewallRules: [{8E6AE480-881C-41B2-A5A1-BC3C3BC82C0C}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Total War SHOGUN 2\benchmarks\benchmark_specify_properties.bat
    FirewallRules: [{063DCA45-BE14-4C04-A5D4-98C4919034EB}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Total War SHOGUN 2\benchmarks\benchmark_specify_properties.bat
    FirewallRules: [{DD5FD2E0-F8DE-47B3-91C7-3F7BC6317575}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Total War SHOGUN 2\benchmarks\benchmark_specify_properties.bat
    FirewallRules: [{E3607C5E-83C8-4A70-BE6A-0A4FB9BF8E4D}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Total War SHOGUN 2\benchmarks\benchmark_specify_properties.bat
    FirewallRules: [{36C82123-9059-45E7-93F2-8542E5E7E115}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Total War SHOGUN 2\data\encyclopedia\how_to_play.html
    FirewallRules: [{3060155C-7751-40E6-B839-06CC83CB58F7}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Total War SHOGUN 2\data\encyclopedia\how_to_play.html
    FirewallRules: [{C93EAB00-C2B2-4B51-B3E7-7D7EC0C5A473}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Total War SHOGUN 2\Shogun2.exe
    FirewallRules: [{5E47C453-2C2F-45AE-915D-0662586BD070}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Total War SHOGUN 2\Shogun2.exe
    FirewallRules: [{41D7A284-7B6D-4B64-8F2F-55CADB4007AB}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Total War SHOGUN 2\benchmarks\benchmark_specify_properties.bat
    FirewallRules: [{0499D82F-B5B6-441E-8AD8-52CDB8D7EA82}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Total War SHOGUN 2\benchmarks\benchmark_specify_properties.bat
    FirewallRules: [{3AB63DA7-481B-4556-82A2-66DABCAB62A9}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Total War SHOGUN 2\benchmarks\benchmark_specify_properties.bat
    FirewallRules: [{4CA43FAD-E45C-4105-9432-2BE74592C893}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Total War SHOGUN 2\benchmarks\benchmark_specify_properties.bat
    FirewallRules: [{88518BF2-B2FB-44F9-B9AD-006BC6F2A507}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Total War SHOGUN 2\benchmarks\benchmark_current_settings.bat
    FirewallRules: [{D9495AD8-BEC4-451B-A5ED-AF5CC71AC481}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Total War SHOGUN 2\benchmarks\benchmark_current_settings.bat
    FirewallRules: [{64439ABB-57FE-467A-908D-FB2CB655AD71}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Total War SHOGUN 2\benchmarks\benchmark_specify_properties.bat
    FirewallRules: [{7E5CDF23-5DB7-41BF-823F-1019EB207810}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Total War SHOGUN 2\benchmarks\benchmark_specify_properties.bat
    FirewallRules: [{80FD30B3-B70C-442E-BC44-E894A5D91F6C}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Total War SHOGUN 2\benchmarks\benchmark_specify_properties.bat
    FirewallRules: [{52369FE7-04AE-4E14-AEFC-BB5D6C339B40}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Total War SHOGUN 2\benchmarks\benchmark_specify_properties.bat
    FirewallRules: [{EF479D46-591F-4027-911F-967C5332736F}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Total War SHOGUN 2\data\encyclopedia\how_to_play.html
    FirewallRules: [{E0943870-7A9A-41C5-A75D-A60ACCF4215E}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Total War SHOGUN 2\data\encyclopedia\how_to_play.html
    FirewallRules: [{A7F40E46-6674-41E4-AB53-994DAEB17180}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Total War SHOGUN 2\Shogun2.exe
    FirewallRules: [{FED3D078-E550-4668-8761-B5169948C98A}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Total War SHOGUN 2\Shogun2.exe
    FirewallRules: [UDP Query User{608B67B3-7854-4E18-AE94-4A14427F3D5E}C:\program files (x86)\ubisoft\assassin's creed iii\ac3sp.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed iii\ac3sp.exe
    FirewallRules: [TCP Query User{D6884485-5F9A-4ED0-8029-4297029604C4}C:\program files (x86)\ubisoft\assassin's creed iii\ac3sp.exe] => (Allow) C:\program files (x86)\ubisoft\assassin's creed iii\ac3sp.exe
    FirewallRules: [{2C81A9D0-2807-466C-BE3C-1E566DB7877C}] => (Allow) C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\SonarHost.exe
    FirewallRules: [{16330334-077D-452A-9994-3F3973DE82D0}] => (Allow) C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\SonarHost.exe
    FirewallRules: [UDP Query User{F2793F80-DA75-4CDE-B708-E3F947FF4349}C:\program files (x86)\steam\steamapps\common\war thunder\aces.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\war thunder\aces.exe
    FirewallRules: [TCP Query User{F05993D5-27AC-43D9-A151-1D5382593621}C:\program files (x86)\steam\steamapps\common\war thunder\aces.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\war thunder\aces.exe
    FirewallRules: [UDP Query User{66209EFB-2F14-4BE5-83A2-E74E990DC540}C:\program files (x86)\origin games\battlefield 3\bf3.exe] => (Allow) C:\program files (x86)\origin games\battlefield 3\bf3.exe
    FirewallRules: [TCP Query User{CD848B4A-7491-4E13-91FC-70AEA7B975B3}C:\program files (x86)\origin games\battlefield 3\bf3.exe] => (Allow) C:\program files (x86)\origin games\battlefield 3\bf3.exe
    FirewallRules: [{74D4B32D-2DCE-49EC-B47D-B0ED2F3C3272}] => (Allow) C:\ProgramData\Kodak\Installer\Setup.exe
    FirewallRules: [{8F754ED7-08BB-4162-9AEE-7A98B5284A10}] => (Allow) C:\ProgramData\Kodak\Installer\Setup.exe
    FirewallRules: [{C6DEF23C-97FF-4CF7-B226-B57AC71971F2}] => (Allow) C:\Program Files (x86)\Kodak\AiO\Firmware\KodakAiOUpdater.exe
    FirewallRules: [{380B224A-4184-41CC-85B1-A5F02766E87F}] => (Allow) C:\Program Files (x86)\Kodak\AiO\Firmware\KodakAiOUpdater.exe
    FirewallRules: [{BA239C7B-227E-4D85-800B-90A646BB465D}] => (Allow) C:\Program Files (x86)\Kodak\AiO\Center\NetworkPrinterDiscovery.exe
    FirewallRules: [{DF466CE8-B13D-4FB8-B6EC-C2178FF90648}] => (Allow) C:\Program Files (x86)\Kodak\AiO\Center\NetworkPrinterDiscovery.exe
    FirewallRules: [{C77C46EC-F2DE-4A5F-8113-2D29D696BB15}] => (Allow) C:\Program Files (x86)\Kodak\AiO\Center\Kodak.Statistics.exe
    FirewallRules: [{DA7DA3DB-8E33-4C96-B3C9-A275530A4248}] => (Allow) C:\Program Files (x86)\Kodak\AiO\Center\Kodak.Statistics.exe
    FirewallRules: [{CAA63175-DE92-4CCF-878B-EA56DCDF51BD}] => (Allow) C:\Program Files (x86)\Kodak\AiO\Center\AiOHomeCenter.exe
    FirewallRules: [{5E51EF3D-C279-4B39-8580-63EA7D6AF0B8}] => (Allow) C:\Program Files (x86)\Kodak\AiO\Center\AiOHomeCenter.exe
    FirewallRules: [UDP Query User{1FF73884-5314-4AA8-ABC9-949DC97D846D}C:\program files (x86)\steam\steamapps\common\total war rome ii\rome2.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\total war rome ii\rome2.exe
    FirewallRules: [TCP Query User{2C169E58-709F-4A9F-80B8-799453B333BE}C:\program files (x86)\steam\steamapps\common\total war rome ii\rome2.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\total war rome ii\rome2.exe
    FirewallRules: [UDP Query User{89629C97-5DBE-47F1-BD4F-93952D4BA566}C:\program files (x86)\ubisoft\tom clancy's splinter cell® blacklist™\src\system\blacklist_dx11_game.exe] => (Allow) C:\program files (x86)\ubisoft\tom clancy's splinter cell® blacklist™\src\system\blacklist_dx11_game.exe
    FirewallRules: [TCP Query User{E9FC9156-C320-414D-BA24-99A194EEA3F4}C:\program files (x86)\ubisoft\tom clancy's splinter cell® blacklist™\src\system\blacklist_dx11_game.exe] => (Allow) C:\program files (x86)\ubisoft\tom clancy's splinter cell® blacklist™\src\system\blacklist_dx11_game.exe
    FirewallRules: [UDP Query User{54AAE74E-26B5-4606-AC8F-E1120B52D428}C:\program files (x86)\steam\steam.exe] => (Allow) C:\program files (x86)\steam\steam.exe
    FirewallRules: [TCP Query User{7CA75B9D-E7B8-45EB-B2E1-C77A3F7DA003}C:\program files (x86)\steam\steam.exe] => (Allow) C:\program files (x86)\steam\steam.exe
    FirewallRules: [UDP Query User{D14948E5-93C1-4E10-9E31-9A09688CB55F}C:\program files (x86)\mount&blade warband\mb_warband.exe] => (Block) C:\program files (x86)\mount&blade warband\mb_warband.exe
    FirewallRules: [TCP Query User{F3B16498-0E93-46DB-BD51-51D3D9C36DC7}C:\program files (x86)\mount&blade warband\mb_warband.exe] => (Block) C:\program files (x86)\mount&blade warband\mb_warband.exe
    FirewallRules: [{14D5B4E8-B8DD-49CB-A42B-885B46092D20}] => (Allow) LPort=5353
    FirewallRules: [UDP Query User{25A3A978-4AA4-4469-A857-A1EF3BAD98DB}C:\program files\java\jre7\bin\javaw.exe] => (Allow) C:\program files\java\jre7\bin\javaw.exe
    FirewallRules: [TCP Query User{9D3D9F98-A006-4CA4-9FD4-4F96800D2D14}C:\program files\java\jre7\bin\javaw.exe] => (Allow) C:\program files\java\jre7\bin\javaw.exe
    FirewallRules: [UDP Query User{ED0730D2-1916-4019-B59B-98B757FA0385}C:\program files (x86)\mount&blade warband\mb_warband.exe] => (Block) C:\program files (x86)\mount&blade warband\mb_warband.exe
    FirewallRules: [TCP Query User{6F777D46-7EEB-4F5C-ABA6-F1C4CB31BC96}C:\program files (x86)\mount&blade warband\mb_warband.exe] => (Block) C:\program files (x86)\mount&blade warband\mb_warband.exe
    FirewallRules: [UDP Query User{A417E023-12CA-4243-8C06-4AF923CDC1DA}C:\program files (x86)\paradox interactive\mount and blade warband\mb_warband.exe] => (Allow) C:\program files (x86)\paradox interactive\mount and blade warband\mb_warband.exe
    FirewallRules: [TCP Query User{4B1B30DA-1189-41D6-9ED0-A7BF90310D49}C:\program files (x86)\paradox interactive\mount and blade warband\mb_warband.exe] => (Allow) C:\program files (x86)\paradox interactive\mount and blade warband\mb_warband.exe
    FirewallRules: [{A2FF38AB-F627-4FA7-A2C0-032F0F870297}] => (Allow) C:\Program Files (x86)\Ubisoft\Tom Clancy's Splinter Cell® Blacklist™\src\SYSTEM\gu.exe
    FirewallRules: [{C00C91C8-994D-4050-BE57-9292BB01E3B9}] => (Allow) C:\Program Files (x86)\Ubisoft\Tom Clancy's Splinter Cell® Blacklist™\src\SYSTEM\gu.exe
    FirewallRules: [{4FC32BF8-BDF8-4EE3-A7AA-C3FE1CF5152D}] => (Allow) C:\Program Files (x86)\Ubisoft\Tom Clancy's Splinter Cell® Blacklist™\src\SYSTEM\Blacklist_DX11_game.exe
    FirewallRules: [{3AB8AA10-832E-41A2-B890-84C0E5EE6C6A}] => (Allow) C:\Program Files (x86)\Ubisoft\Tom Clancy's Splinter Cell® Blacklist™\src\SYSTEM\Blacklist_DX11_game.exe
    FirewallRules: [{67A30873-5A50-4DF2-A7A3-F975A7B8E0D9}] => (Allow) C:\Program Files (x86)\Ubisoft\Tom Clancy's Splinter Cell® Blacklist™\src\SYSTEM\Blacklist_game.exe
    FirewallRules: [{FF8E1904-D8A6-45D6-8AB0-21073341F6DB}] => (Allow) C:\Program Files (x86)\Ubisoft\Tom Clancy's Splinter Cell® Blacklist™\src\SYSTEM\Blacklist_game.exe
    FirewallRules: [{61DA36C5-28F7-48E0-8E18-9653F88638ED}] => (Allow) C:\Program Files (x86)\Ubisoft\Tom Clancy's Splinter Cell® Blacklist™\Blacklist_Launcher.exe
    FirewallRules: [{76BAD1A4-A245-4D7D-A009-97CFB2E28A2A}] => (Allow) C:\Program Files (x86)\Ubisoft\Tom Clancy's Splinter Cell® Blacklist™\Blacklist_Launcher.exe
    FirewallRules: [{6172DC8D-CECA-417F-BF6C-D15DF6A385E3}] => (Allow) C:\Users\Chris\AppData\Roaming\uTorrent\uTorrent.exe
    FirewallRules: [{A54FC398-35FB-4929-83A0-8DF2FEAFBE6F}] => (Allow) C:\Users\Chris\AppData\Roaming\uTorrent\uTorrent.exe
    FirewallRules: [{C09B8F37-3A51-4B59-A2C6-6348DC89B245}] => (Allow) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
    FirewallRules: [{71C79ECE-5806-4C58-B5B3-406B29CC9D88}] => (Allow) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
    FirewallRules: [{B4354546-719B-4B34-908A-7B10DE24685E}] => (Allow) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe
    FirewallRules: [{46855259-CC62-4CB4-920E-AC61F4A91BA7}] => (Allow) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe
    FirewallRules: [{82096440-A3E1-4D28-B7AB-CCAECDCA770C}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Fallout New Vegas\Geck.exe
    FirewallRules: [{4DCC5C52-FC66-49B1-89BD-1FDCE112F029}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Fallout New Vegas\Geck.exe
    FirewallRules: [{DF1E4CAF-103F-4812-B397-8DB29B94C242}] => (Allow) C:\Program Files (x86)\Ubisoft\Tom Clancy's Splinter Cell Conviction\src\system\gu.exe
    FirewallRules: [{019AD0EB-F299-4797-A506-08A51057565B}] => (Allow) C:\Program Files (x86)\Ubisoft\Tom Clancy's Splinter Cell Conviction\src\system\gu.exe
    FirewallRules: [{D7E04CAC-6663-4920-B2B4-C7A9380D3A0E}] => (Allow) C:\Program Files (x86)\Ubisoft\Tom Clancy's Splinter Cell Conviction\src\system\conviction_game.exe
    FirewallRules: [{B0D8D584-9981-4EDF-8D51-8E317E2F5B1C}] => (Allow) C:\Program Files (x86)\Ubisoft\Tom Clancy's Splinter Cell Conviction\src\system\conviction_game.exe
    FirewallRules: [{C017705F-35D9-4D78-9806-5BDDC3D02E98}] => (Allow) C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\SonarHost.exe
    FirewallRules: [{FA474F61-7BD2-48BF-8F11-C6D7614ECFBA}] => (Allow) C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\SonarHost.exe
    FirewallRules: [{597CDF39-96AB-4817-BCC1-81CAAE931417}] => (Allow) C:\ProgramData\Kodak\Installer\Setup.exe
    FirewallRules: [{9FE834B8-793E-4AD3-B9BC-F795E0196C81}] => (Allow) C:\ProgramData\Kodak\Installer\Setup.exe
    FirewallRules: [{EB71F7D8-A457-4F32-86D6-B6F4D086997E}] => (Allow) C:\Program Files (x86)\Kodak\AiO\Firmware\KodakAiOUpdater.exe
    FirewallRules: [{91BDF467-81E7-4AA1-B5E2-87CC355DEA08}] => (Allow) C:\Program Files (x86)\Kodak\AiO\Firmware\KodakAiOUpdater.exe
    FirewallRules: [{D42C3210-0FF5-41CD-83BF-257531CFC99D}] => (Allow) C:\Program Files (x86)\Kodak\AiO\Center\NetworkPrinterDiscovery.exe
    FirewallRules: [{BC4063FF-D703-434F-9EE8-F39290E0F6DC}] => (Allow) C:\Program Files (x86)\Kodak\AiO\Center\NetworkPrinterDiscovery.exe
    FirewallRules: [{9FF7091F-C909-4E5E-AFCA-415C695E5E7E}] => (Allow) C:\Program Files (x86)\Kodak\AiO\Center\Kodak.Statistics.exe
    FirewallRules: [{DE6231EA-02A3-40A1-9A86-2ABA905C8258}] => (Allow) C:\Program Files (x86)\Kodak\AiO\Center\Kodak.Statistics.exe
    FirewallRules: [{399A06CE-FE6A-4FE7-8DDA-57CEA5AFE550}] => (Allow) C:\Program Files (x86)\Kodak\AiO\Center\AiOHomeCenter.exe
    FirewallRules: [{56A9514B-9C6A-44C0-BE95-3D2ACB28ABF7}] => (Allow) C:\Program Files (x86)\Kodak\AiO\Center\AiOHomeCenter.exe
    FirewallRules: [{A06961BD-16CA-4ED3-A0F2-146D72F63BA9}] => (Allow) LPort=5353
    FirewallRules: [{C7ACB166-FA96-4D8E-A957-171A9330C490}] => (Allow) LPort=9322
    FirewallRules: [{420F3A8C-5264-4883-BA61-069F4DE50143}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
    FirewallRules: [{69765621-55AB-4017-86EF-82C6F713F785}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
    FirewallRules: [UDP Query User{71D43794-1AF2-4827-BF50-E69E80D17C06}C:\program files\java\jre7\bin\javaw.exe] => (Allow) C:\program files\java\jre7\bin\javaw.exe
    FirewallRules: [TCP Query User{4E33DB0A-586B-473F-BACA-5AE756AC25A5}C:\program files\java\jre7\bin\javaw.exe] => (Allow) C:\program files\java\jre7\bin\javaw.exe
    FirewallRules: [{BB869A9E-7468-42DC-9B06-F1938CD73E19}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
    FirewallRules: [{56376A20-A167-4EC2-A799-9C5A5149EB54}] => (Allow) LPort=53
    FirewallRules: [{0A8A37FF-F65A-4B59-A6A6-581E66115F31}] => (Allow) LPort=1542
    FirewallRules: [{A0487D4D-4A7E-44CA-A2D0-266543FD8A41}] => (Allow) LPort=1542
    FirewallRules: [{EB0FC35D-4E13-43E8-BA17-AC31CC501C88}] => (Allow) C:\Program Files (x86)\REALTEK\11n USB Wireless LAN Utility\RtWLan.exe
    FirewallRules: [{D525DEDF-7153-4D32-A2DB-4F1134BA8424}] => (Allow) C:\Program Files (x86)\REALTEK\11n USB Wireless LAN Utility\RtWLan.exe
    FirewallRules: [{3BC7551B-1E9E-40B7-99A2-5F153DAE83A2}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
    FirewallRules: [{C0E224D7-2755-40F2-91EB-FD94EC354223}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
    FirewallRules: [{45973727-F8D0-4105-924B-488E6D0A9F0B}] => (Allow) C:\Program Files (x86)\Origin Games\Mass Effect 3\Binaries\Win32\MassEffect3.exe
    FirewallRules: [{C856B84B-CA99-479E-82BD-7D3DD3310D3F}] => (Allow) C:\Program Files (x86)\Origin Games\Mass Effect 3\Binaries\Win32\MassEffect3.exe
    FirewallRules: [TCP Query User{78A41B22-64D4-4260-8567-67935F4C7E97}C:\program files (x86)\steam\steamapps\common\fallout 3 goty\fallout3.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\fallout 3 goty\fallout3.exe
    FirewallRules: [UDP Query User{AA8C05E2-82D4-4727-8EDE-E084098D581C}C:\program files (x86)\steam\steamapps\common\fallout 3 goty\fallout3.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\fallout 3 goty\fallout3.exe
    FirewallRules: [{A919691F-DAE5-462A-A7AD-1BC8146A234B}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\outlook.exe
    FirewallRules: [{4FDBEB5E-9CF4-47FA-9607-566A8591D83A}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
    FirewallRules: [{C26B4723-C385-40F4-BE1F-162217D28C28}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
    FirewallRules: [{E7A8274E-0A6F-43F9-B2B3-FEA42D7A54E5}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
    FirewallRules: [{2CE9EB73-114E-4483-9DB6-45BB004B84A6}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
    FirewallRules: [{5F36E3A6-0BA5-48D0-B181-30379221360F}] => (Allow) C:\Program Files (x86)\Ubisoft\FarCry 3\bin\farcry3.exe
    FirewallRules: [{0996B1C0-022F-4117-A168-2C1086761F57}] => (Allow) C:\Program Files (x86)\Ubisoft\FarCry 3\bin\farcry3.exe
    FirewallRules: [{0D0594EF-CA46-4D5E-8776-131CD8F9D485}] => (Allow) C:\Program Files (x86)\Ubisoft\FarCry 3\bin\farcry3_d3d11.exe
    FirewallRules: [{309FD2A9-C722-4506-AECE-38642726953D}] => (Allow) C:\Program Files (x86)\Ubisoft\FarCry 3\bin\farcry3_d3d11.exe
    FirewallRules: [{CB0CC088-0CFE-4196-A420-38157ABF8085}] => (Allow) C:\Program Files (x86)\Ubisoft\FarCry 3\bin\FC3Updater.exe
    FirewallRules: [{EB440816-05DF-46FE-83B0-176FF3A412C2}] => (Allow) C:\Program Files (x86)\Ubisoft\FarCry 3\bin\FC3Updater.exe
    FirewallRules: [{9522F96A-8084-4A1C-8F74-4AE09ED7FE6F}] => (Allow) C:\Program Files (x86)\Ubisoft\FarCry 3\bin\FC3Editor.exe
    FirewallRules: [{81882FC9-F12D-4200-88D5-BB424EE230DF}] => (Allow) C:\Program Files (x86)\Ubisoft\FarCry 3\bin\FC3Editor.exe
    FirewallRules: [{C0D3D39D-329C-4EAF-B9FA-DDB347942872}] => (Allow) C:\Program Files (x86)\Ubisoft\Tom Clancy's Ghost Recon Future Soldier\Future Soldier.exe
    FirewallRules: [{9BBB1BAA-043D-4AAC-8005-C687F9230787}] => (Allow) C:\Program Files (x86)\Ubisoft\Tom Clancy's Ghost Recon Future Soldier\Future Soldier.exe
    FirewallRules: [{BBD7F359-661E-44D8-9A90-C2A1581FA150}] => (Allow) C:\Program Files (x86)\Ubisoft\Tom Clancy's Ghost Recon Future Soldier\gu.exe
    FirewallRules: [{16A747A7-9566-4CD0-97E7-5E5B0194BB1D}] => (Allow) C:\Program Files (x86)\Ubisoft\Tom Clancy's Ghost Recon Future Soldier\gu.exe
    FirewallRules: [{4D40C564-B1A4-44E7-8332-C2172240D227}] => (Allow) C:\Program Files (x86)\Ubisoft\Tom Clancy's Ghost Recon Future Soldier\Future Soldier DX11.exe
    FirewallRules: [{FAEB462F-B1DF-4FF4-BEBA-B2B20EF937A0}] => (Allow) C:\Program Files (x86)\Ubisoft\Tom Clancy's Ghost Recon Future Soldier\Future Soldier DX11.exe
    FirewallRules: [{BCF53851-B11B-49C9-8104-DDE38869BD41}] => (Allow) C:\Program Files (x86)\Ubisoft\Tom Clancy's Ghost Recon Future Soldier\Future Soldier DX9.exe
    FirewallRules: [{154E0950-89DF-4F69-9571-5A9D626D1EBD}] => (Allow) C:\Program Files (x86)\Ubisoft\Tom Clancy's Ghost Recon Future Soldier\Future Soldier DX9.exe
    FirewallRules: [{36D8BD7F-3E0D-461C-AA13-C90991657AE7}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
    FirewallRules: [{35800AFA-EA93-4225-82B9-34FE3BE57091}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
    FirewallRules: [{69B24D6E-C287-49C5-A1C3-FAB205BCE9F9}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
    FirewallRules: [{D8CBB6ED-D88A-4E0E-AAED-80748B973819}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
    FirewallRules: [TCP Query User{1E7A5BDB-B785-4BB8-BB14-F7A44A7AE553}C:\program files (x86)\ubisoft\tom clancy's ghost recon future soldier\future soldier dx11.exe] => (Allow) C:\program files (x86)\ubisoft\tom clancy's ghost recon future soldier\future soldier dx11.exe
    FirewallRules: [UDP Query User{BE563449-FC9E-49CD-91A5-F26E2DF4AAB7}C:\program files (x86)\ubisoft\tom clancy's ghost recon future soldier\future soldier dx11.exe] => (Allow) C:\program files (x86)\ubisoft\tom clancy's ghost recon future soldier\future soldier dx11.exe
    FirewallRules: [{49176DA5-35CD-4973-A036-E18CFE23A976}] => (Allow) C:\Program Files (x86)\Origin Games\SimCity\SimCity\SimCity.exe
    FirewallRules: [{F4FD983A-FD73-40A7-BB97-97545D29021F}] => (Allow) C:\Program Files (x86)\Origin Games\SimCity\SimCity\SimCity.exe
    FirewallRules: [{397792AD-4216-4660-A3AA-A3173284AC4A}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
    FirewallRules: [{D7EC3CFA-19BF-40BC-A685-2A7F9849AE80}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
    FirewallRules: [{845783BA-5642-48AF-9DAC-84808D5EFC89}] => (Allow) C:\Program Files (x86)\Intel\Extreme Tuning Utility\Client\PerfTune.exe
    FirewallRules: [{D66BD5D8-E518-4B28-90AD-8847BD1C0887}] => (Allow) C:\Program Files (x86)\Origin Games\SimCity\SimCity\SimCity.exe
    FirewallRules: [{27A95D76-4AB1-420F-B00E-605B7F35A7A8}] => (Allow) C:\Program Files (x86)\Origin Games\SimCity\SimCity\SimCity.exe
    FirewallRules: [TCP Query User{6CF0EA83-575A-4D9B-9865-9534D40AD320}C:\users\chris\appdata\local\apps\2.0\jm6c0yvg.bb7\j63p5jvq.gwq\laun...app_59711684aa47878d_0001.0024_2e804a728bdd6950\launcher.exe] => (Allow) C:\users\chris\appdata\local\apps\2.0\jm6c0yvg.bb7\j63p5jvq.gwq\laun...app_59711684aa47878d_0001.0024_2e804a728bdd6950\launcher.exe
    FirewallRules: [UDP Query User{5A65112B-0322-4493-9D3F-CE0DAC12E02C}C:\users\chris\appdata\local\apps\2.0\jm6c0yvg.bb7\j63p5jvq.gwq\laun...app_59711684aa47878d_0001.0024_2e804a728bdd6950\launcher.exe] => (Allow) C:\users\chris\appdata\local\apps\2.0\jm6c0yvg.bb7\j63p5jvq.gwq\laun...app_59711684aa47878d_0001.0024_2e804a728bdd6950\launcher.exe
    FirewallRules: [TCP Query User{859111D5-2521-4937-B597-E8A74CF73CFC}C:\ubisoft\ghost recon phantoms\pdc-live\ghostreconphantoms.exe] => (Allow) C:\ubisoft\ghost recon phantoms\pdc-live\ghostreconphantoms.exe
    FirewallRules: [UDP Query User{3916C60A-918C-4785-816F-B5E8F5D55E29}C:\ubisoft\ghost recon phantoms\pdc-live\ghostreconphantoms.exe] => (Allow) C:\ubisoft\ghost recon phantoms\pdc-live\ghostreconphantoms.exe
    FirewallRules: [TCP Query User{BE94605C-43E1-4124-B041-1FE99B2B32AE}C:\program files (x86)\cyberduck\cyberduck.exe] => (Allow) C:\program files (x86)\cyberduck\cyberduck.exe
    FirewallRules: [UDP Query User{E227E5F7-A2ED-40DD-AEC1-0810AF9F3A57}C:\program files (x86)\cyberduck\cyberduck.exe] => (Allow) C:\program files (x86)\cyberduck\cyberduck.exe
    FirewallRules: [{80122108-CFEB-4EE7-8C98-5ED58C68FD86}] => (Allow) LPort=9322
    FirewallRules: [{0A8831C1-E231-426D-939F-B82803E7BDB1}] => (Allow) C:\Program Files (x86)\iTunes\iTunes.exe
    FirewallRules: [{9AB47BC0-681B-43A6-9D56-5C2119D84E98}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Total War Rome II\launcher\launcher.exe
    FirewallRules: [{3D5833DE-2F52-46FF-8EB8-A91EEEC2C7B5}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Total War Rome II\launcher\launcher.exe
    FirewallRules: [{A8F96559-0BB7-4F77-BDBE-E64F4279341F}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Arma 3\arma3.exe
    FirewallRules: [{A8D4E394-A6FB-4008-84CF-39FBC3B69E0B}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Arma 3\arma3.exe
    FirewallRules: [{0177A6CD-113A-40D1-B6F5-8426B859BAF2}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Arma 3\arma3launcher.exe
    FirewallRules: [{A4253C30-0452-4C5C-9745-655154304D84}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Arma 3\arma3launcher.exe
    FirewallRules: [{B5F548CE-B368-4E6E-AADF-6F67FE357812}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    FirewallRules: [TCP Query User{69834A90-7194-4CBB-AE41-723C77D50D09}C:\program files (x86)\steam\steamapps\common\total war attila\attila.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\total war attila\attila.exe
    FirewallRules: [UDP Query User{ABD92743-C910-4A67-9187-422C4B011C39}C:\program files (x86)\steam\steamapps\common\total war attila\attila.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\total war attila\attila.exe
    FirewallRules: [{64E4F727-53EC-4736-B0DA-8553B5B42546}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
    FirewallRules: [{401C40DD-3569-46B1-923B-FF44F082AAC6}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
    FirewallRules: [{BA5DF235-96C4-4A3F-A931-62CB94C62FCA}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
    FirewallRules: [{D63BC928-C62C-4AA9-BAC0-6C867961D537}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
    FirewallRules: [{7556C4A4-02AA-4EE6-800F-E068E5ED2786}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
    FirewallRules: [TCP Query User{39C1311F-6754-4723-99B1-E077CE3D00AD}C:\program files (x86)\steam\steamapps\common\total war rome ii\rome2.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\total war rome ii\rome2.exe
    FirewallRules: [UDP Query User{FDEE9A1D-2FAB-4B12-851B-AFF123A6006F}C:\program files (x86)\steam\steamapps\common\total war rome ii\rome2.exe] => (Allow) C:\program files (x86)\steam\steamapps\common\total war rome ii\rome2.exe
    FirewallRules: [TCP Query User{3FE0E9FC-B83E-4225-9C03-546035BF6CDB}C:\program files\java\jre1.8.0_51\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_51\bin\javaw.exe
    FirewallRules: [UDP Query User{BCD1C059-14F3-4C1D-AE54-7F8ACEEAB2D5}C:\program files\java\jre1.8.0_51\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_51\bin\javaw.exe
    FirewallRules: [{6E0A8596-3867-424E-8364-3F54F4DA45DD}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Total War Attila\launcher\launcher.exe
    FirewallRules: [{3D21F2B7-5C5B-476C-ACF5-DEE1A04E67F4}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Total War Attila\launcher\launcher.exe
    FirewallRules: [{4811774D-6375-4E2E-B6B1-D63FB7DE2BB4}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    FirewallRules: [{9B15C502-6B7B-4B11-96E1-FD40589180CF}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Tom Clancy's Rainbow Six Siege\RainbowSix.exe
    FirewallRules: [{01CC074E-F692-40C8-9B20-23F472F2C539}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Tom Clancy's Rainbow Six Siege\RainbowSix.exe
     
  7. Chris Waters

    Chris Waters TS Rookie Topic Starter Posts: 23

    ==================== Restore Points =========================

    27-12-2015 16:22:25 Scheduled Checkpoint
    05-01-2016 18:44:12 Windows Update
    10-01-2016 18:46:50 Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030

    ==================== Faulty Device Manager Devices =============


    ==================== Event log errors: =========================

    Application errors:
    ==================
    Error: (01/10/2016 06:47:05 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
    Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.

    Details:
    AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol.

    System Error:
    Access is denied.
    .

    Error: (01/06/2016 08:13:45 PM) (Source: Perflib) (EventID: 1023) (User: )
    Description: rdyboost4

    Error: (01/06/2016 08:13:45 PM) (Source: Perflib) (EventID: 1008) (User: )
    Description: BITSC:\Windows\System32\bitsperf.dll4

    Error: (01/06/2016 08:13:26 PM) (Source: Application Error) (EventID: 1000) (User: )
    Description: Faulting application name: MSICPUService.exe, version: 0.0.0.0, time stamp: 0x53391841
    Faulting module name: MSICPUService.exe, version: 0.0.0.0, time stamp: 0x53391841
    Exception code: 0xc0000005
    Fault offset: 0x00014616
    Faulting process id: 0x109c
    Faulting application start time: 0xMSICPUService.exe0
    Faulting application path: MSICPUService.exe1
    Faulting module path: MSICPUService.exe2
    Report Id: MSICPUService.exe3
    Faulting package full name: MSICPUService.exe4
    Faulting package-relative application ID: MSICPUService.exe5

    Error: (01/05/2016 06:44:22 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
    Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.

    Details:
    AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol.

    System Error:
    Access is denied.
    .

    Error: (01/04/2016 08:49:12 PM) (Source: Perflib) (EventID: 1023) (User: )
    Description: rdyboost4

    Error: (01/04/2016 08:49:12 PM) (Source: Perflib) (EventID: 1008) (User: )
    Description: BITSC:\Windows\System32\bitsperf.dll4

    Error: (01/01/2016 11:20:46 AM) (Source: Perflib) (EventID: 1023) (User: )
    Description: rdyboost4

    Error: (01/01/2016 11:20:45 AM) (Source: Perflib) (EventID: 1008) (User: )
    Description: BITSC:\Windows\System32\bitsperf.dll4

    Error: (12/30/2015 01:39:37 PM) (Source: Perflib) (EventID: 1023) (User: )
    Description: rdyboost4


    System errors:
    =============
    Error: (01/08/2016 10:37:01 PM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY)
    Description: {784E29F4-5EBE-4279-9948-1E8FE941646D}

    Error: (01/07/2016 10:51:38 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
    Description: The User Data Access_a2e6fb service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service.

    Error: (01/07/2016 10:51:38 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
    Description: The User Data Storage_a2e6fb service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service.

    Error: (01/07/2016 10:51:38 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
    Description: The Contact Data_a2e6fb service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service.

    Error: (01/07/2016 10:51:38 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
    Description: The Sync Host_a2e6fb service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service.

    Error: (01/07/2016 10:51:37 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
    Description: application-specificLocalActivation{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)UnavailableUnavailable

    Error: (01/07/2016 07:01:36 PM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY)
    Description: {784E29F4-5EBE-4279-9948-1E8FE941646D}

    Error: (01/06/2016 10:31:49 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
    Description: The User Data Access_54f9e service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service.

    Error: (01/06/2016 10:31:49 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
    Description: The User Data Storage_54f9e service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service.

    Error: (01/06/2016 10:31:49 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
    Description: The Contact Data_54f9e service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service.


    CodeIntegrity:
    ===================================
    Date: 2016-01-09 16:30:22.770
    Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

    Date: 2016-01-09 16:30:22.716
    Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

    Date: 2016-01-09 16:30:10.406
    Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

    Date: 2016-01-09 16:30:10.351
    Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

    Date: 2016-01-09 01:11:32.691
    Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

    Date: 2016-01-09 01:11:32.636
    Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

    Date: 2016-01-09 01:11:16.381
    Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

    Date: 2016-01-09 01:11:16.307
    Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

    Date: 2016-01-08 22:37:42.300
    Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

    Date: 2016-01-06 20:20:07.897
    Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.


    ==================== Memory info ===========================

    Processor: Intel(R) Core(TM) i5-4690K CPU @ 3.50GHz
    Percentage of memory in use: 67%
    Total physical RAM: 16333.32 MB
    Available physical RAM: 5377.35 MB
    Total Virtual: 21709.32 MB
    Available Virtual: 9056.11 MB

    ==================== Drives ================================

    Drive c: () (Fixed) (Total:930.73 GB) (Free:245.19 GB) NTFS

    ==================== MBR & Partition Table ==================

    ========================================================
    Disk: 0 (Size: 1863 GB) (Disk ID: 0FE3CF68)
    Partition 1: (Active) - (Size=345 MB) - (Type=07 NTFS)
    Partition 2: (Not Active) - (Size=930.7 GB) - (Type=07 NTFS)
    Partition 3: (Not Active) - (Size=450 MB) - (Type=27)

    ==================== End of Addition.txt ============================
     
  8. Broni

    Broni Malware Annihilator Posts: 52,897   +344

    Welcome aboard [​IMG]

    Please, observe following rules:
    • Read all of my instructions very carefully. Your mistakes during cleaning process may have very serious consequences, like unbootable computer.
    • If you're stuck, or you're not sure about certain step, always ask before doing anything else.
    • Please refrain from running any tools, fixes or applying any changes to your computer other than those I suggest.
    • Never run more than one scan at a time.
    • Keep updating me regarding your computer behavior, good, or bad.
    • The cleaning process, once started, has to be completed. Even if your computer appears to act better, it may still be infected. Once the computer is totally clean, I'll certainly let you know.
    • If you leave the topic without explanation in the middle of a cleaning process, you may not be eligible to receive any more help in malware removal forum.
    • I close my topics if you have not replied in 5 days. If you need more time, simply let me know. If I closed your topic and you need it to be reopened, simply PM me.

    =================================

    [​IMG] Download RogueKiller from one of the following links and save it to your Desktop:

    Link 1
    Link 2
    • Close all the running programs
    • Windows Vista/7/8 users: right click on RogueKiller.exe, click Run as Administrator
    • Otherwise just double-click on RogueKiller.exe
    • Pre-scan will start. Let it finish.
    • Click on SCAN button.
    • Wait until the Status box shows Scan Finished
    • Click on Delete.
    • Wait until the Status box shows Deleting Finished.
    • Click on Report and copy/paste the content of the Notepad into your next reply.
    • RKreport.txt could also be found on your desktop.
    • If more than one log is produced post all logs.
    • If RogueKiller has been blocked, do not hesitate to try a few times more. If really won't run, rename it to winlogon.exe (or winlogon.com) and try again
    [​IMG] Please download Malwarebytes Anti-Malware (MBAM) to your desktop.
    NOTE. If you already have MBAM 2.0 installed scroll down.
    • Double-click mbam-setup-2.0.0.1000.exe and follow the prompts to install the program.
    • At the end, be sure a checkmark is placed next to the following:
    • Launch Malwarebytes Anti-Malware
    • A 14 day trial of the Premium features is pre-selected. You may deselect this if you wish, and it will not diminish the scanning and removal capabilities of the program.
    • Click Finish.
    • On the Dashboard, click the 'Update Now >>' link
    • After the update completes, click the 'Scan Now >>' button.
    • Or, on the Dashboard, click the Scan Now >> button.
    • If an update is available, click the Update Now button.
    • A Threat Scan will begin.
    • When the scan is complete, if there have been detections, click Apply Actions to allow MBAM to clean what was detected.
    • In most cases, a restart will be required.
    • Wait for the prompt to restart the computer to appear, then click on Yes.
    If you already have MBAM 2.0 installed:
    • On the Dashboard, click the 'Update Now >>' link
    • After the update completes, click the 'Scan Now >>' button.
    • Or, on the Dashboard, click the Scan Now >> button.
    • If an update is available, click the Update Now button.
    • A Threat Scan will begin.
    • When the scan is complete, if there have been detections, click Apply Actions to allow MBAM to clean what was detected.
    • In most cases, a restart will be required.
    • Wait for the prompt to restart the computer to appear, then click on Yes.
    How to get logs:
    (Export log to save as txt)
    • After the restart once you are back at your desktop, open MBAM once more.
    • Click on the History tab > Application Logs.
    • Double click on the Scan Log which shows the Date and time of the scan just performed.
    • Click 'Export'.
    • Click 'Text file (*.txt)'
    • In the Save File dialog box which appears, click on Desktop.
    • In the File name: box type a name for your scan log.
    • A message box named 'File Saved' should appear stating "Your file has been successfully exported".
    • Click Ok
    • Attach that saved log to your next reply.
    (Copy to clipboard for pasting into forum replies or tickets)
    • After the restart once you are back at your desktop, open MBAM once more.
    • Click on the History tab > Application Logs.
    • Double click on the Scan Log which shows the Date and time of the scan just performed.
    • Click 'Copy to Clipboard'
    • Paste the contents of the clipboard into your reply.
    [​IMG] Please download AdwCleaner by Xplode onto your desktop.
    • Close all open programs and internet browsers.
    • Double click on adwcleaner.exe to run the tool.
    • Click on Scan button.
    • When the scan has finished click on Clean button.
    • Your computer will be rebooted automatically. A text file will open after the restart.
    • Please post the contents of that logfile with your next reply.
    • You can find the logfile at C:\AdwCleaner[S1].txt as well.
    [​IMG] Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Post the contents of JRT.txt into your next message.
     
  9. Chris Waters

    Chris Waters TS Rookie Topic Starter Posts: 23

    RogueKiller V11.0.7.0 [Jan 11 2016] (Free) by Adlice Software
    mail : http://www.adlice.com/contact/
    Feedback : http://forum.adlice.com
    Website : http://www.adlice.com/software/roguekiller/
    Blog : http://www.adlice.com

    Operating System : Windows 10 (10.0.10586) 64 bits version
    Started in : Normal mode
    User : Chris [Administrator]
    Started from : C:\Users\Chris\Downloads\RogueKiller.exe
    Mode : Delete -- Date : 01/12/2016 20:23:35

    ¤¤¤ Processes : 0 ¤¤¤

    ¤¤¤ Registry : 12 ¤¤¤
    [PUP] (X64) HKEY_LOCAL_MACHINE\Software\Partner -> Not selected
    [PUP] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\###MegaShellExtPending | (default) : {056D528D-CE28-4194-9BA3-BA2E9197FF8C} (C:\Users\Chris\AppData\Local\MEGAsync\ShellExtX64.dll) -> Not selected
    [PUP] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\###MegaShellExtSynced | (default) : {05B38830-F4E9-4329-978B-1DD28605D202} (C:\Users\Chris\AppData\Local\MEGAsync\ShellExtX64.dll) -> Not selected
    [PUP] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\###MegaShellExtSyncing | (default) : {0596C850-7BDD-4C9D-AFDF-873BE6890637} (C:\Users\Chris\AppData\Local\MEGAsync\ShellExtX64.dll) -> Not selected
    [PUP] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\###MegaShellExtPending | (default) : {056D528D-CE28-4194-9BA3-BA2E9197FF8C} (C:\Users\Chris\AppData\Local\MEGAsync\ShellExtX64.dll) -> Not selected
    [PUP] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\###MegaShellExtSynced | (default) : {05B38830-F4E9-4329-978B-1DD28605D202} (C:\Users\Chris\AppData\Local\MEGAsync\ShellExtX64.dll) -> Not selected
    [PUP] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\###MegaShellExtSyncing | (default) : {0596C850-7BDD-4C9D-AFDF-873BE6890637} (C:\Users\Chris\AppData\Local\MEGAsync\ShellExtX64.dll) -> Not selected
    [PUP] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4b9bcce8-a70b-402a-a7e1-db96831ee26f} -> Not selected
    [PUP] (X86) HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar | {4b9bcce8-a70b-402a-a7e1-db96831ee26f} : XFINITY Toolbar -> Not selected
    [PUP] (X64) HKEY_USERS\S-1-5-21-905238947-2220377667-1876713056-1001\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser | {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} : -> Not selected
    [PUP] (X86) HKEY_USERS\S-1-5-21-905238947-2220377667-1876713056-1001\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser | {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} : -> Not selected
    [PUM.HomePage] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main | Start Page : http://start.mysearchdial.com/?f=1&...DyDzz2QtN1B1L1H1Ezu1O2U1M1B&cr=1435966762&ir= -> Not selected

    ¤¤¤ Tasks : 0 ¤¤¤

    ¤¤¤ Files : 7 ¤¤¤
    [Hidden.ADS][Stream] C:\Windows\System32:Win32App_1 -> Deleted
    [PUP][File] C:\Users\Chris\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Flvto Youtube Downloader\Flvto Youtube Downloader.lnk [LNK@] C:\Users\Chris\AppData\Local\FLVTOY~1\FLVTOY~1.EXE -> Deleted
    [PUP][Folder] C:\Users\Chris\AppData\Local\Flvto Youtube Downloader -> Deleted
    [PUP][File] C:\Users\Chris\AppData\Local\Flvto Youtube Downloader\CommonControls.dll -> Deleted
    [PUP][File] C:\Users\Chris\AppData\Local\Flvto Youtube Downloader\CommonUtils.dll -> Deleted
    [PUP][File] C:\Users\Chris\AppData\Local\Flvto Youtube Downloader\de-DE\CommonControls.resources.dll -> Deleted
    [PUP][File] C:\Users\Chris\AppData\Local\Flvto Youtube Downloader\de-DE\FlvtoYoutubeDownloader.resources.dll -> Deleted
    [PUP][Folder] C:\Users\Chris\AppData\Local\Flvto Youtube Downloader\de-DE -> Deleted
    [PUP][File] C:\Users\Chris\AppData\Local\Flvto Youtube Downloader\DirectShowLib-2008.dll -> Deleted
    [PUP][File] C:\Users\Chris\AppData\Local\Flvto Youtube Downloader\DownloadManager.dll -> Deleted
    [PUP][File] C:\Users\Chris\AppData\Local\Flvto Youtube Downloader\en-US\CommonControls.resources.dll -> Deleted
    [PUP][File] C:\Users\Chris\AppData\Local\Flvto Youtube Downloader\en-US\FlvtoYoutubeDownloader.resources.dll -> Deleted
    [PUP][Folder] C:\Users\Chris\AppData\Local\Flvto Youtube Downloader\en-US -> Deleted
    [PUP][File] C:\Users\Chris\AppData\Local\Flvto Youtube Downloader\FFmpeg\ffmpeg.exe -> Deleted
    [PUP][Folder] C:\Users\Chris\AppData\Local\Flvto Youtube Downloader\FFmpeg -> Deleted
    [PUP][File] C:\Users\Chris\AppData\Local\Flvto Youtube Downloader\flvto 128x128 v2.ico -> Deleted
    [PUP][File] C:\Users\Chris\AppData\Local\Flvto Youtube Downloader\FlvtoYoutubeDownloader.exe -> Deleted
    [PUP][File] C:\Users\Chris\AppData\Local\Flvto Youtube Downloader\FlvtoYoutubeDownloader.exe.config -> Deleted
    [PUP][File] C:\Users\Chris\AppData\Local\Flvto Youtube Downloader\ICSharpCode.SharpZipLib.dll -> Deleted
    [PUP][File] C:\Users\Chris\AppData\Local\Flvto Youtube Downloader\Id3Lib.dll -> Deleted
    [PUP][File] C:\Users\Chris\AppData\Local\Flvto Youtube Downloader\it-IT\CommonControls.resources.dll -> Deleted
    [PUP][File] C:\Users\Chris\AppData\Local\Flvto Youtube Downloader\it-IT\FlvtoYoutubeDownloader.resources.dll -> Deleted
    [PUP][Folder] C:\Users\Chris\AppData\Local\Flvto Youtube Downloader\it-IT -> Deleted
    [PUP][File] C:\Users\Chris\AppData\Local\Flvto Youtube Downloader\MarkedUp (NET40).dll -> Deleted
    [PUP][File] C:\Users\Chris\AppData\Local\Flvto Youtube Downloader\MediaLibrary.dll -> Deleted
    [PUP][File] C:\Users\Chris\AppData\Local\Flvto Youtube Downloader\Mp3Lib.dll -> Deleted
    [PUP][File] C:\Users\Chris\AppData\Local\Flvto Youtube Downloader\msvcp100.dll -> Deleted
    [PUP][File] C:\Users\Chris\AppData\Local\Flvto Youtube Downloader\msvcr100.dll -> Deleted
    [PUP][File] C:\Users\Chris\AppData\Local\Flvto Youtube Downloader\Newtonsoft.Json.dll -> Deleted
    [PUP][File] C:\Users\Chris\AppData\Local\Flvto Youtube Downloader\pt-PT\CommonControls.resources.dll -> Deleted
    [PUP][File] C:\Users\Chris\AppData\Local\Flvto Youtube Downloader\pt-PT\FlvtoYoutubeDownloader.resources.dll -> Deleted
    [PUP][Folder] C:\Users\Chris\AppData\Local\Flvto Youtube Downloader\pt-PT -> Deleted
    [PUP][File] C:\Users\Chris\AppData\Local\Flvto Youtube Downloader\rtmpdump\rtmpdump.exe -> Deleted
    [PUP][Folder] C:\Users\Chris\AppData\Local\Flvto Youtube Downloader\rtmpdump -> Deleted
    [PUP][File] C:\Users\Chris\AppData\Local\Flvto Youtube Downloader\setup.exe -> Deleted
    [PUP][File] C:\Users\Chris\AppData\Local\Flvto Youtube Downloader\UninstallFlvtoYoutubeDownloader.exe -> Deleted
    [PUP][File] C:\Users\Chris\AppData\Local\Flvto Youtube Downloader\VideoHostsExtractor.dll -> Deleted
    [PUP][File] C:\Users\Chris\AppData\Local\Flvto Youtube Downloader\WpfLocalization.dll -> Deleted
    [PUP][File] C:\Users\Chris\AppData\Local\Flvto Youtube Downloader\Xceed.Wpf.Toolkit.dll -> Deleted
    [PUP][File] C:\Users\Chris\AppData\Local\Flvto Youtube Downloader\YoutubeExtractor.dll -> Deleted
    [PUP][Folder] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E} -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\GameStopApp_setup.dat -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\GameStopApp_setup.exe -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\GameStopApp_setup.lnk -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\GameStopApp_setup.msi -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\GameStopApp_setup.par -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\GameStopApp_setup.res -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\instance.dat -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\mia.lib -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\1001D268\AF6861CC\impulse_images.ini -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\1001D268\AF6861CC\impulse_logic.ini -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\1001D268\AF6861CC\impulse_main.ini -> Deleted
    [PUP][Folder] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\1001D268\AF6861CC -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\1001D268\CBEFC624\1c.xml -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\1001D268\CBEFC624\2kg.xml -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\1001D268\CBEFC624\activision.xml -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\1001D268\CBEFC624\akella.xml -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\1001D268\CBEFC624\alawar.xml -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\1001D268\CBEFC624\amd.xml -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\1001D268\CBEFC624\apogee.xml -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\1001D268\CBEFC624\atari.xml -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\1001D268\CBEFC624\auran.xml -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\1001D268\CBEFC624\avg.xml -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\1001D268\CBEFC624\bethesda.xml -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\1001D268\CBEFC624\blitzgames.xml -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\1001D268\CBEFC624\bohemia.xml -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\1001D268\CBEFC624\capcom.xml -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\1001D268\CBEFC624\cdp.xml -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\1001D268\CBEFC624\cdv.xml -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\1001D268\CBEFC624\cinemaware.xml -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\1001D268\CBEFC624\clearcrown.xml -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\1001D268\CBEFC624\corel.xml -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\1001D268\CBEFC624\cyan.xml -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\1001D268\CBEFC624\cypron.xml -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\1001D268\CBEFC624\d3p.xml -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\1001D268\CBEFC624\digironin.xml -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\1001D268\CBEFC624\dreamcatch.xml -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\1001D268\CBEFC624\drengin.xml -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\1001D268\CBEFC624\ea.xml -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\1001D268\CBEFC624\eidos.xml -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\1001D268\CBEFC624\enl.xml -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\1001D268\CBEFC624\epic.xml -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\1001D268\CBEFC624\focushome.xml -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\1001D268\CBEFC624\freestuff.xml -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\1001D268\CBEFC624\futurem.xml -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\1001D268\CBEFC624\gamehouse.xml -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\1001D268\CBEFC624\gsoft.xml -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\1001D268\CBEFC624\hothead.xml -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\1001D268\CBEFC624\iceberg.xml -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\1001D268\CBEFC624\ignition.xml -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\1001D268\CBEFC624\impulse.xml -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\1001D268\CBEFC624\indies.xml -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\1001D268\CBEFC624\interplay.xml -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\1001D268\CBEFC624\iolo.xml -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\1001D268\CBEFC624\isv.xml -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\1001D268\CBEFC624\kalypso.xml -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\1001D268\CBEFC624\light.xml -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\1001D268\CBEFC624\meridian4.xml -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\1001D268\CBEFC624\merscom.xml -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\1001D268\CBEFC624\microids.xml -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\1001D268\CBEFC624\mumbojumbo.xml -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\1001D268\CBEFC624\muzzylane.xml -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\1001D268\CBEFC624\MyColors.xml -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\1001D268\CBEFC624\myoffice.xml -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\1001D268\CBEFC624\n3vgames.xml -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\1001D268\CBEFC624\namco.xml -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\1001D268\CBEFC624\ncsoft.xml -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\1001D268\CBEFC624\networks.xml -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\1001D268\CBEFC624\nival.xml -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\1001D268\CBEFC624\oddworld.xml -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\1001D268\CBEFC624\odnt.xml -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\1001D268\CBEFC624\paradox.xml -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\1001D268\CBEFC624\playrix.xml -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\1001D268\CBEFC624\popcap.xml -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\1001D268\CBEFC624\positech.xml -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\1001D268\CBEFC624\prima.xml -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\1001D268\CBEFC624\railsimulator.xml -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\1001D268\CBEFC624\rlx.xml -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\1001D268\CBEFC624\sap.xml -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\1001D268\CBEFC624\sds.xml -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\1001D268\CBEFC624\sega.xml -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\1001D268\CBEFC624\servers.xml -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\1001D268\CBEFC624\siber.xml -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\1001D268\CBEFC624\snowball.xml -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\1001D268\CBEFC624\squarenix.xml -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\1001D268\CBEFC624\stratfirst.xml -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\1001D268\CBEFC624\tdesk.xml -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\1001D268\CBEFC624\thq.xml -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\1001D268\CBEFC624\threedonkeys.xml -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\1001D268\CBEFC624\tiltedm.xml -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\1001D268\CBEFC624\timegate.xml -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\1001D268\CBEFC624\topware.xml -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\1001D268\CBEFC624\trion.xml -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\1001D268\CBEFC624\trisynergy.xml -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\1001D268\CBEFC624\viva.xml -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\1001D268\CBEFC624\wargaming.xml -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\1001D268\CBEFC624\warner.xml -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\1001D268\CBEFC624\wastelands.xml -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\1001D268\CBEFC624\wc.xml -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\1001D268\CBEFC624\zallag.xml -> Deleted
    [PUP][Folder] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\1001D268\CBEFC624 -> Deleted
    [PUP][Folder] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\1001D268 -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\8AE63621\Sd.Irc.resources.dll -> Deleted
    [PUP][Folder] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\8AE63621 -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\B3410A2A\app.dat -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\B3410A2A\avcodec-53.dll -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\B3410A2A\avformat-53.dll -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\B3410A2A\avutil-51.dll -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\B3410A2A\chrome.pak -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\B3410A2A\d3dcompiler_43.dll -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\B3410A2A\d3dx9_43.dll -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\B3410A2A\GameStopApp.exe -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\B3410A2A\icudt.dll -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\B3410A2A\ImpulseSelfRefresh.exe -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\B3410A2A\ImpulseSelfRefresh.exe.config -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\B3410A2A\libcef.dll -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\B3410A2A\libEGL.dll -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\B3410A2A\libGLESv2.dll -> Deleted
    [PUP][Folder] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\B3410A2A -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\C46F2D9E\7z.dll -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\C46F2D9E\7za.exe -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\C46F2D9E\7zip_license.txt -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\C46F2D9E\7zxr.dll -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\C46F2D9E\Activate.exe -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\C46F2D9E\AxInterop.ShockwaveFlashObjects.dll -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\C46F2D9E\CleanGSA.exe -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\C46F2D9E\CleanGSA.exe.config -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\C46F2D9E\Console.dll -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\C46F2D9E\DeElevator.dll -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\C46F2D9E\DeElevator64.dll -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\C46F2D9E\eula.txt -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\C46F2D9E\Gibraltar.Agent.dll -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\C46F2D9E\Gibraltar.Packager.exe -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\C46F2D9E\GSAMini.exe -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\C46F2D9E\GSANative.exe -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\C46F2D9E\GSANative.exe.config -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\C46F2D9E\GSANative.XmlSerializers.dll -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\C46F2D9E\ICSharpCode.SharpZipLib.dll -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\C46F2D9E\ImpulseSelfRefresh.exe.config -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\C46F2D9E\Interop.IWshRuntimeLibrary.dll -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\C46F2D9E\Interop.ShockwaveFlashObjects.dll -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\C46F2D9E\IptNetApi.dll -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\C46F2D9E\Microsoft.WindowsAPICodePack.dll -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\C46F2D9E\Microsoft.WindowsAPICodePack.Shell.dll -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\C46F2D9E\MyDock.Util.dll -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\C46F2D9E\Newtonsoft.Json.dll -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\C46F2D9E\readme.txt -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\C46F2D9E\Sd.Central.Archive.dll -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\C46F2D9E\sd.central.cvp.server.dll -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\C46F2D9E\sd.central.cvp.server.XmlSerializers.dll -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\C46F2D9E\Sd.Common.dll -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\C46F2D9E\Sd.Common.XmlSerializers.dll -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\C46F2D9E\Sd.dll -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\C46F2D9E\Sd.InstallManager.dll -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\C46F2D9E\Sd.Irc.dll -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\C46F2D9E\Sd.UI.dll -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\C46F2D9E\Sd.Uninstall.dll -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\C46F2D9E\Sd.Web.dll -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\C46F2D9E\Sd.Zip.dll -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\C46F2D9E\sdsfresp.txt -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\C46F2D9E\Stardock.Central.Security.dll -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\C46F2D9E\StardockCentralDSkin.dll -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\C46F2D9E\TestResult.xml -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\C46F2D9E\UninstHelper.exe -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\C46F2D9E\VDialog.dll -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\C46F2D9E\VistaBridgeLibrary.dll -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\C46F2D9E\WBOCXLib.dll -> Deleted
    [PUP][Folder] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\C46F2D9E -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\D9B8C55E\am.pak -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\D9B8C55E\ar.pak -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\D9B8C55E\bg.pak -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\D9B8C55E\bn.pak -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\D9B8C55E\ca.pak -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\D9B8C55E\cs.pak -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\D9B8C55E\da.pak -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\D9B8C55E\de.pak -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\D9B8C55E\el.pak -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\D9B8C55E\en-GB.pak -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\D9B8C55E\en-US.pak -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\D9B8C55E\es-419.pak -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\D9B8C55E\es.pak -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\D9B8C55E\et.pak -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\D9B8C55E\fa.pak -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\D9B8C55E\fi.pak -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\D9B8C55E\fil.pak -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\D9B8C55E\fr.pak -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\D9B8C55E\gu.pak -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\D9B8C55E\he.pak -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\D9B8C55E\hi.pak -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\D9B8C55E\hr.pak -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\D9B8C55E\hu.pak -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\D9B8C55E\id.pak -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\D9B8C55E\it.pak -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\D9B8C55E\ja.pak -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\D9B8C55E\kn.pak -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\D9B8C55E\ko.pak -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\D9B8C55E\lt.pak -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\D9B8C55E\lv.pak -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\D9B8C55E\ml.pak -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\D9B8C55E\mr.pak -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\D9B8C55E\nb.pak -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\D9B8C55E\nl.pak -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\D9B8C55E\pl.pak -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\D9B8C55E\pt-BR.pak -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\D9B8C55E\pt-PT.pak -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\D9B8C55E\ro.pak -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\D9B8C55E\ru.pak -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\D9B8C55E\sk.pak -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\D9B8C55E\sl.pak -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\D9B8C55E\sr.pak -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\D9B8C55E\sv.pak -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\D9B8C55E\sw.pak -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\D9B8C55E\ta.pak -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\D9B8C55E\te.pak -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\D9B8C55E\th.pak -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\D9B8C55E\tr.pak -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\D9B8C55E\uk.pak -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\D9B8C55E\vi.pak -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\D9B8C55E\zh-CN.pak -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\D9B8C55E\zh-TW.pak -> Deleted
    [PUP][Folder] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\D9B8C55E -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\FED94973\about.png -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\FED94973\btn_buynow_down.png -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\FED94973\btn_buynow_over.png -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\FED94973\btn_buynow_up.png -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\FED94973\btn_close_down.png -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\FED94973\btn_close_over.png -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\FED94973\btn_close_up.png -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\FED94973\frame.png -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\FED94973\GameStopNow.exe -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\FED94973\GSLogo.png -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\FED94973\icon_update.ico -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\FED94973\imp_bottom.png -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\FED94973\imp_top.png -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\FED94973\SDSecurity.dll -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\FED94973\shadow1.png -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\FED94973\shadow2.png -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\FED94973\Slider_Arrows.png -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\FED94973\Slider_Arrows2.png -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\FED94973\Slider_Arrows2_down.png -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\FED94973\Slider_Arrows2_over.png -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\FED94973\Slider_Arrows_down.png -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\FED94973\Slider_Arrows_over.png -> Deleted
    [PUP][Folder] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513\FED94973 -> Deleted
    [PUP][Folder] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\33760513 -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\mIDEFunc.dll\mEXEFunc.dll -> Deleted
    [PUP][Folder] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\mIDEFunc.dll -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\mMSI.dll\mMSIExec.dll -> Deleted
    [PUP][Folder] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\mMSI.dll -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE\{1983A45A-60BF-4D72-937F-E9C44B18E38E} -> Deleted
    [PUP][Folder] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\OFFLINE -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\setup.bmp -> Deleted
    [PUP][File] C:\ProgramData\{1983A45A-60BF-4D72-937F-E9C44B18E38E}\{EA450D5D-95EA-4FD0-B8B0-6D8E68FBE2C7} -> Deleted
    [PUP][Folder] C:\Program Files (x86)\predm -> Deleted
    [PUP][Folder] C:\Program Files (x86)\WinZip Registry Optimizer -> Deleted
    [PUP][Folder] C:\Program Files (x86)\xfin_portal -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\as_guid.dat -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\auxi\comcastAu.dll -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\auxi\config.xml -> Deleted
    [PUP][Folder] C:\Program Files (x86)\xfin_portal\auxi -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\content\ads.js -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\content\antispyware.js -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\content\blocked.html -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\content\custom.js -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\content\download.html -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\content\email.js -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\content\games.js -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\content\lib\about.xml -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\content\lib\ads.js -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\content\lib\antispyware.js -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\content\lib\custom.js -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\content\lib\dtxpanel.xul -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\content\lib\dtxpaneltransparent.xul -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\content\lib\dtxpanelwin.xul -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\content\lib\dtxprefwin.xul -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\content\lib\dtxtransparentwin.xul -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\content\lib\dtxwin.xul -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\content\lib\email.js -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\content\lib\emailnotifierproviders.xml -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\content\lib\external.js -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\content\lib\games.js -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\content\lib\login.js -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\content\lib\neterror.xhtml -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\content\lib\nsDragAndDrop.js -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\content\lib\preferences.js -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\content\lib\rsspreview.html -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\content\lib\rsswin.xml -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\content\lib\rsswin.xsl -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\content\lib\tv.js -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\content\lib\webinspector.js -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\content\lib\wmpstreamer.html -> Deleted
    [PUP][Folder] C:\Program Files (x86)\xfin_portal\chrome\content\lib -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\content\login.js -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\content\modules\datastore.jsm -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\content\modules\nsDragAndDrop.js -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\content\modules\welcome.jsm -> Deleted
    [PUP][Folder] C:\Program Files (x86)\xfin_portal\chrome\content\modules -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\content\neterror.xhtml -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\content\newtab\images\btn-search-x.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\content\newtab\images\btn-search-xover.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\content\newtab\images\btn_search.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\content\newtab\images\bullet.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\content\newtab\images\field_bg.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\content\newtab\images\google-enhanced.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\content\newtab\images\google_enhanced.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\content\newtab\images\logo-about.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\content\newtab\images\logo-xfinity.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\content\newtab\images\logo_comcast_toolbar.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\content\newtab\images\logo_xfinity_toolbar.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\content\newtab\images\magnifier-x.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\content\newtab\images\powered_by_yahoo.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\content\newtab\images\yahoo_search.gif -> Deleted
    [PUP][Folder] C:\Program Files (x86)\xfin_portal\chrome\content\newtab\images -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\content\newtab\newtab.html -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\content\newtab\newtab_mystart.html -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\content\newtab\newtab_yahoo.html -> Deleted
    [PUP][Folder] C:\Program Files (x86)\xfin_portal\chrome\content\newtab -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\content\preferences.js -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\content\preferences.xml -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\content\siteinfo.html -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\content\template.xml -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\content\toolbar.htm -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\content\toolbar.xul -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\content\tv.html -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\content\tv.js -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\content\vmncode.js -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\content\vmnrsswin.xml -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\content\webinspector.js -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\content\websiteinspectorpref.html -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\content\welcome.xml -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\content\widgets\net.vmn.www.Comcast.Coupons\bg-rounded.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\content\widgets\net.vmn.www.Comcast.Coupons\bg-save.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\content\widgets\net.vmn.www.Comcast.Coupons\bg.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\content\widgets\net.vmn.www.Comcast.Coupons\btn-getcoupon.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\content\widgets\net.vmn.www.Comcast.Coupons\btn-wide-close-over.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\content\widgets\net.vmn.www.Comcast.Coupons\btn-wide-close.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\content\widgets\net.vmn.www.Comcast.Coupons\comcast_logo.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\content\widgets\net.vmn.www.Comcast.Coupons\coupon-activated.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\content\widgets\net.vmn.www.Comcast.Coupons\couponTooltip.js -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\content\widgets\net.vmn.www.Comcast.Coupons\dialog.css -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\content\widgets\net.vmn.www.Comcast.Coupons\ico-coupon.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\content\widgets\net.vmn.www.Comcast.Coupons\ico-dollar.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\content\widgets\net.vmn.www.Comcast.Coupons\jquery-1.3.2.min.js -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\content\widgets\net.vmn.www.Comcast.Coupons\jquery.autocomplete.min.js -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\content\widgets\net.vmn.www.Comcast.Coupons\jquery.contextMenu.css -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\content\widgets\net.vmn.www.Comcast.Coupons\jquery.contextMenu.js -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\content\widgets\net.vmn.www.Comcast.Coupons\page_white_copy.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\content\widgets\net.vmn.www.Comcast.Coupons\panel.html -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\content\widgets\net.vmn.www.Comcast.Coupons\placeholder-logo.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\content\widgets\net.vmn.www.Comcast.Coupons\widget.js -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\content\widgets\net.vmn.www.Comcast.Coupons\widget.xml -> Deleted
    [PUP][Folder] C:\Program Files (x86)\xfin_portal\chrome\content\widgets\net.vmn.www.Comcast.Coupons -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\content\widgets\net.vmn.www.Comcast.Weather\widget.js -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\content\widgets\net.vmn.www.Comcast.Weather\widget.jsw -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\content\widgets\net.vmn.www.Comcast.Weather\widget.xml -> Deleted
    [PUP][Folder] C:\Program Files (x86)\xfin_portal\chrome\content\widgets\net.vmn.www.Comcast.Weather -> Deleted
    [PUP][Folder] C:\Program Files (x86)\xfin_portal\chrome\content\widgets -> Deleted
    [PUP][Folder] C:\Program Files (x86)\xfin_portal\chrome\content -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\data\dynamicElements\vmntoolbar.xsl -> Deleted
    [PUP][Folder] C:\Program Files (x86)\xfin_portal\chrome\data\dynamicElements -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\data\rss\rss.xml -> Deleted
    [PUP][Folder] C:\Program Files (x86)\xfin_portal\chrome\data\rss -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\data\search\engines.xml -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\data\search\engines_mystart.xml -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\data\search\engines_yahoo.xml -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\data\search\search.xsl -> Deleted
    [PUP][Folder] C:\Program Files (x86)\xfin_portal\chrome\data\search -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\data\weather\icons.xml -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\data\weather\weatherZip.xml -> Deleted
    [PUP][Folder] C:\Program Files (x86)\xfin_portal\chrome\data\weather -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\data\websiteinspector\wimap.xml -> Deleted
    [PUP][Folder] C:\Program Files (x86)\xfin_portal\chrome\data\websiteinspector -> Deleted
    [PUP][Folder] C:\Program Files (x86)\xfin_portal\chrome\data -> Deleted
     
  10. Chris Waters

    Chris Waters TS Rookie Topic Starter Posts: 23

    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\16x16.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\16x16_png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\about.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\about_logo.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\antispy.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\autos.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\babylon_logo.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\bluelite.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\bluesky.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\btn-cancel-over.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\btn-cancel.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\btn-close.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\btn-play.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\btn-search-over.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\btn-search.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\btn-seeepisodes.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\btn-settings-over.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\btn-settings.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\btn-widgets-over.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\btn-widgets.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\btn_accessthistime.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\btn_alwaysaccess.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\btn_alwaysblock.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\btn_exit.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\btn_sendreport.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\btn_settings.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\button-down-back-ff.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\button-down-back.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\button-down-left.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\button-down-right.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\button-down-splitter.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\button-drop-back.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\button-drop-left.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\button-drop-right.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\button-drop-splitter.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\button-hover-back-ff.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\button-hover-back.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\button-hover-left.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\button-hover-right.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\button-hover-splitter.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\ca.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\channels.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\comcast_logoftr.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\comcast_logotop.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\custom.css -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\desktop_weather.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\dictionary.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\divider.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\downloadcom.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\dtxlogo.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\email.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\email_on.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\entertainment.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\facebook.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\fancast.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\favbtn001.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\favbtn002.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\favbtn003.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\favbtn004.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\favbtn005.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\favbtn006.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\favbtn007.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\favbtn008.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\favbtn009.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\favbtn010.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\favbtn011.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\favbtn012.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\features.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\finance.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\games.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\games2.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\graphna.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\graphred0.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\graphred0_5.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\graphred1.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\graphred1_5.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\graphred2.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\graphred2_5.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\graphred3.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\graphred3_5.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\graphred4.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\graphred4_5.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\graphred5.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\graphredna.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\grey.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\help.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\help.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\helpsearch_16_16.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\help_gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\ico-film-alert.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\ico-shield.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\icons_download.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\icons_freegames.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\icons_mygames.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\icons_searchgames.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\icons_trivia.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\ico_ask.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\ico_security.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\ico_tophelp.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\ico_tophelpdark.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\ico_tophelpdark_wbg.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\images.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\images_png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\installer-bg-agreement.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\installer-bg-middle.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\installer-btn-finish-over.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\installer-btn-finish.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\installer-home.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\installer-search.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\installer-suggestions.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\add-over.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\add.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\alexabutton.css -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\aol.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\arrow-dn.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\arrow-right-disabled.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\arrow-right.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\arrow-up.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\bg-btn-divider.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\bg-btn-end.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\bg-btn-mdl.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\bg-btn-mdl_ff.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\bg-btn-start.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\bg-btnover-divider.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\bg-btnover-end.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\bg-btnover-mdl.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\bg-btnover-mdl_ff.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\bg-btnover-start.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\blank.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\btn-widgets-over.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\btn-widgets.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\btnback-down-vista.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\btnback-vista.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\btnleft-down-vista.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\btnleft-vista.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\btnright-down-vista.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\btnright-vista.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\btn_slider.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\button-splitter-down-vista.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\button-splitter-vista.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\button-splitter.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\checkmark.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\chevron.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\collapse.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\comcast.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\debugbar\debug.html -> Deleted
    [PUP][Folder] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\debugbar -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\dtx-test.css -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\dtx.css -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\edit-back-hot.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\edit-back.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\embarq.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\expand.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\fast.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\found.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\gmail.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\gripper.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\highlight.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\highlight_blue.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\highlight_cyan.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\highlight_lime.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\highlight_magenta.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\highlight_yellow.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\hotmail.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\ico-check.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\imap.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\lastsearch-thumb-back.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\launchers.css -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\loadingMid.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\lock.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\logo-separator.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\mailcom.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\menuitem-splitter.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\menuitemback-down-vista.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\menuitemback-vista.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\menuitemleft-down-vista.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\menuitemleft-vista.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\menuitemleft.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\menuitemright-down-vista.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\menuitemright-vista.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\menu_bg-basic.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\menu_separator_bar.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\menu_separator_white.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\minus.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\modify.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\move.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\movetarget.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\newsitem.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\css\ie-only.css -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\css\ie7-only.css -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\css\panels.css -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\css\popupAbout.css -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\css\popupGames.css -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\css\popupRSS.css -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\css\popupWidgets.css -> Deleted
    [PUP][Folder] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\css -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\default\css\dialog.css -> Deleted
    [PUP][Folder] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\default\css -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\default\images\bg.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\default\images\btn-close-over.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\default\images\btn-close.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\default\images\btn-search.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\default\images\btn-wide-close-over.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\default\images\btn-wide-close.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\default\images\default.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\default\images\footer-short-left.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\default\images\footer-short-middle.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\default\images\footer-short-right.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\default\images\tab-off-l.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\default\images\tab-off-r.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\default\images\tab-on-l.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\default\images\tab-on-r.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\default\images\titlebar-left.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\default\images\titlebar-middle.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\default\images\titlebar-right.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\default\images\transparent.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\default\images\ttlbar-left.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\default\images\ttlbar-mdl.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\default\images\ttlbar-right.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\default\images\win-btm-left.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\default\images\win-btm-mdl.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\default\images\win-btm-right-resize.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\default\images\win-btm-right.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\default\images\win-left.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\default\images\win-right.png -> Deleted
    [PUP][Folder] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\default\images -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\default\main.html -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\default\scripts\defscript.js -> Deleted
    [PUP][Folder] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\default\scripts -> Deleted
    [PUP][Folder] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\default -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\footer.htm -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\gamecategory.xsl -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\gameData.js -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\gameList.xsl -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\games.xsl -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\gametype.xsl -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\ajax-loader.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\apps-bg-gradient-grid.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\apps-hover.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\appsfeatured-bg-gradient-grid.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\arrow-dn.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\arrow-down-white.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\arrow-left.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\arrow-right.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\arrow-sml-drop.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\arrow-sml.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\arrow-up.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\arrowr-bluew5.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\bg-aboutbox.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\bg-btnover.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\bg-pnl520x390.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\bg-scrollbar-thumb-y.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\bg-scrollbar-track-y.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\bg-scrollbar-trackend-y.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\btn-add-over.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\btn-add.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\btn-addtoolbar-left-over.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\btn-addtoolbar-left.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\btn-addtoolbar-right.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\btn-back.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\btn-close-grey-over.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\btn-close-grey.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\btn-close-greyover.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\btn-close-over.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\btn-close.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\btn-dark-left22-over.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\btn-dark-left22.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\btn-dark-middle22-over.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\btn-dark-middle22.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\btn-dark-right22-over.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\btn-dark-right22.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\btn-drag.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\btn-install.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\btn-launch-over.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\btn-launch.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\btn-mdl-over.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\btn-mdl.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\btn-moredetails.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\btn-next-over.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\btn-next.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\btn-play-left-over.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\btn-play-left.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\btn-previous-over.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\btn-previous.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\btn-right-over.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\btn-search-pnlbtm-over.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\btn-search-pnlbtm.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\btn-try-left-over.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\btn-try-left.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\bullet-orange.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\categories-bg-gradient-grid.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\featured-bg-btm-gradient.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\footer-short-left.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\footer-short-middle.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\footer-short-right.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\gamethumb-on.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\gamethumb2-over.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\ico-box-next.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\ico-calendar.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\ico-dollar.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\ico-download.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\ico-info-over.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\ico-info.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\ico-joystick24.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\ico-news24.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\ico-play.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\ico-pref-over.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\ico-pref.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\ico-tags.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\ico-user-monitor.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\icon-Add.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\icon-download.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\icon-Info.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\icon-play.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\icon-shop.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\left-menu-hover.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\menul-bgon.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\menul-bgover.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\panel-botm-noscroll.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\scroll-bg-206.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\scroll-bg.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\scroll-topwin.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\scrollb-disable.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\scrollb-down.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\scrollb-over.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\scrollb.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\scrollt-disable.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\scrollt-down.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\scrollt-over.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\scrollt.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\searchbox-pnlbtm.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\searchbox.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\searchboxlite.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\searchboxlite_end.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\shadow-leftmenu.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\sprite-dropdown.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\star.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\star_blank.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\star_x_grey.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\star_x_orange.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\titlebar-left.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\titlebar-middle.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\titlebar-right.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\topbar-inside-gradient.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\TRUSTe_about.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\view-detailed-on.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\view-detailed-over.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\view-thumb-on.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\view-thumb-over.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\widgets-square-16px.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\widgets-square-24px.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\widgets.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\win-bottom-middleglow.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\win-left-bottomglow.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\win-left-middleglow.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\win-left-topglow.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\win-right-bottomglow.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\win-right-middleglow.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\win-right-topglow.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images\win-top-middleglow.png -> Deleted
    [PUP][Folder] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\images -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\initHTML.html -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\js\default.js -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\js\jquery.js -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\js\jquery.tinyscrollbar.js -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\js\jquery.tinyscrollbar.min.js -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\js\jquery.uniform.min.js -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\js\jquery.url.js -> Deleted
    [PUP][Folder] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\js -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\popupGames.html -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\popupHTML.html -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\popupRSS.html -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\popupWidgets.html -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels\scroll.png -> Deleted
    [PUP][Folder] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\panels -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\plus.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\pop.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\radio\css\manager.css -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\radio\css\slider.css -> Deleted
    [PUP][Folder] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\radio\css -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\radio\images\bg-pnl.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\radio\images\btn-close-grey.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\radio\images\btn-close-greyover.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\radio\images\collapsed_button.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\radio\images\expanded_button.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\radio\images\ico-playstation-down.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\radio\images\ico-playstation-over.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\radio\images\ico-playstation.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\radio\images\ico-radio.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\radio\images\music-note.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\radio\images\radio-btn-pause-on.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\radio\images\radio-btn-pause.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\radio\images\radio-btn-play-on.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\radio\images\radio-btn-play.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\radio\images\radio-eq-bg.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\radio\images\radio-eq-buffer.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\radio\images\radio-eq-busy.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\radio\images\radio-eq-off.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\radio\images\radio-eq-on.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\radio\images\radio-eq-warning.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\radio\images\radio-options-design-on.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\radio\images\radio-options-design.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\radio\images\radio-options-on.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\radio\images\radio-options.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\radio\images\radio-volume-0.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\radio\images\radio-volume-1.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\radio\images\radio-volume-2.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\radio\images\radio-volume-3.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\radio\images\radio-volume-mute.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\radio\images\scrollbar-handle.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\radio\images\scrollbar-track.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\radio\images\slider.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\radio\images\slideron.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\radio\images\track.png -> Deleted
    [PUP][Folder] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\radio\images -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\radio\managerpanel.html -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\radio\volumeslider.html -> Deleted
    [PUP][Folder] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\radio -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\radio.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\rank0.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\rank0_5.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\rank1.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\rank1_5.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\rank2.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\rank2_5.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\rank3.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\rank3_5.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\rank4.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\rank4_5.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\rank5.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\rankna.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\reload.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\remove-over.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\remove.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\rename.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\resize-box.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\rss.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\rsschannelback.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\RSSLogo.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\rsstabdivider.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\scroll-left.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\scroll-right.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\search-go.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\search.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\separator.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\text-ellipsis.xml -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\throbber.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\toolbarsplitter.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\transparent_1px.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\uwa\border_02.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\uwa\border_03.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\uwa\border_04.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\uwa\border_06.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\uwa\border_07.png -> Deleted
     
  11. Chris Waters

    Chris Waters TS Rookie Topic Starter Posts: 23

    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\uwa\border_08.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\uwa\border_09.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\uwa\border_10.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\uwa\border_11.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\uwa\border_12.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\uwa\border_13.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\uwa\border_14.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\uwa\border_15.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\uwa\border_16.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\uwa\border_18.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\uwa\border_19.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\uwa\border_20.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\uwa\border_21.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\uwa\btn-close-grey.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\uwa\btn-close-greyover.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\uwa\close-hot.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\uwa\close-normal.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\uwa\loadingMid.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\uwa\paneltemplate.html -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\uwa\proxy.html -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\uwa\template.html -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\uwa\template.xml -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\uwa\templateFF.html -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\uwa\throbber.gif -> Deleted
    [PUP][Folder] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\uwa -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\weatherbutton\icons\cond999.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\weatherbutton\icons\icons.xml -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\weatherbutton\icons\na-s.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\weatherbutton\icons\na-t.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\weatherbutton\icons\na.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\weatherbutton\icons\weather.png -> Deleted
    [PUP][Folder] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\weatherbutton\icons -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\weatherbutton\panels\images\add.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\weatherbutton\panels\images\arrowr-bluew5.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\weatherbutton\panels\images\bg-pnl.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\weatherbutton\panels\images\bg-pnl520x350.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\weatherbutton\panels\images\bg-pnl520x350blue-whitebg.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\weatherbutton\panels\images\bg-pnl520x350blue.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\weatherbutton\panels\images\box-check.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\weatherbutton\panels\images\box-uncheck.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\weatherbutton\panels\images\btn-close-grey.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\weatherbutton\panels\images\btn-close-greyover.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\weatherbutton\panels\images\btn-delete.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\weatherbutton\panels\images\btn-search-pnlbtm-over.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\weatherbutton\panels\images\btn-search-pnlbtm.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\weatherbutton\panels\images\btnarrow-next-off.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\weatherbutton\panels\images\btnarrow-next.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\weatherbutton\panels\images\btnarrow-previous-off.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\weatherbutton\panels\images\btnarrow-previous.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\weatherbutton\panels\images\ico-check.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\weatherbutton\panels\images\ico-hotandhumid-s.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\weatherbutton\panels\images\ico-hotandhumid.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\weatherbutton\panels\images\options-weather.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\weatherbutton\panels\images\over-blue.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\weatherbutton\panels\images\over-orange.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\weatherbutton\panels\images\powered-by-weatherbug.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\weatherbutton\panels\images\powered-by-weatherbug2.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\weatherbutton\panels\images\radio-checked.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\weatherbutton\panels\images\radio-unchecked.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\weatherbutton\panels\images\searchbox-pnlbtm.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\weatherbutton\panels\images\weather-contour.png -> Deleted
    [PUP][Folder] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\weatherbutton\panels\images -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\weatherbutton\panels\popupWeather.css -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\weatherbutton\panels\popupWeather.html -> Deleted
    [PUP][Folder] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\weatherbutton\panels -> Deleted
    [PUP][Folder] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\weatherbutton -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\weatherbutton.css -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\websiteinspector-highrisk-user.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\websiteinspector-highrisk.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\websiteinspector-lowrisk.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\websiteinspector-norating.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\websiteinspector-verified-user.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\websiteinspector-verified.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\websiteinspector-verifying.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lib\yahoo.png -> Deleted
    [PUP][Folder] C:\Program Files (x86)\xfin_portal\chrome\skin\lib -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\lichen.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\logo-about.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\logo-old.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\logo-over.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\logo-popup.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\logo-separator.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\logo-xfinity-over.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\logo-xfinity.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\logo.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\logo_ca20px.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\logo_comcast_toolbar.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\logo_xfinity_toolbar.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\mail.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\mainbutton_png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\menuback-hot.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\menuback.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\menuseparatorback.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\minus.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\modify-save.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\modify.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\modifyhot.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\movies.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\music.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\music.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\my_account.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\namespacetoolbar.css -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\news.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\news.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\news_gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\nomail.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\ondemand.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\options\options-main.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\options\options-search.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\options\options-weather.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\options\options-weather.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\options\options-websiteinspector.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\options\options-widgets.png -> Deleted
    [PUP][Folder] C:\Program Files (x86)\xfin_portal\chrome\skin\options -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\options-mail.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\options-main.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\options-search.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\orange.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\panel-search-over.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\panel-search.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\pixsy.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\plus.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\powered_by_ca.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\ppcbully.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\progress-bar-indeterminate.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\protect-id.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\p_yahoo.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\relatedlinks.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\relationships.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\rss-collapse.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\rss-delete.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\rss-expand.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\rss-feed.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\rss-folder-remove.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\rss-folder-rename.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\rss-folder.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\rss-found.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\rss-reload.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\rss-subscribe.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\rss.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\rssback.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\rsstopback.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\sd_icon.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\search-over.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\search.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\searchbar\searchbar-background-left.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\searchbar\searchbar-background-middle.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\searchbar\searchbar-background-right.png -> Deleted
    [PUP][Folder] C:\Program Files (x86)\xfin_portal\chrome\skin\searchbar -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\search_site.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\search_site_png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\security.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\settings.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\shield_checked.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\shield_scan.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\shopping.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\shopping.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\shopping_gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\sign_in.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\sign_off.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\siteinfo.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\sitesearch_16_16.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\skin-bluelite.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\skin-bluesky.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\skin-grey.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\skin-lichen.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\skin-orange.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\skin-yellow.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\skin.xml -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\sports.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\spyware2.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\tab_bg.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\tab_nominate.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\tab_nominate_off.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\tab_reportfraud.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\tab_reportfraud_off.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\tab_sitereport.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\tab_sitereport_off.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\technorati.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\throbber.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\toolbarsplitter.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\translate.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\travel.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\TRUSTe_about.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\tv-alert.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\tv.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\tv.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\tvlisting.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\video.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\video_png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\vmn.css -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\vmn.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\voice.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\weather\0.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\weather\1.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\weather\10.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\weather\11.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\weather\12.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\weather\13.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\weather\14.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\weather\15.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\weather\16.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\weather\17.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\weather\18.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\weather\19.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\weather\2.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\weather\20.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\weather\21.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\weather\22.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\weather\23.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\weather\24.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\weather\25.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\weather\26.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\weather\27.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\weather\28.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\weather\29.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\weather\3.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\weather\30.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\weather\31.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\weather\32.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\weather\33.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\weather\34.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\weather\35.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\weather\36.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\weather\37.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\weather\38.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\weather\39.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\weather\4.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\weather\40.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\weather\41.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\weather\42.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\weather\43.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\weather\44.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\weather\45.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\weather\46.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\weather\47.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\weather\5.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\weather\6.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\weather\7.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\weather\8.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\weather\9.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\weather\na.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\weather\throbber.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\weather\weather.png -> Deleted
    [PUP][Folder] C:\Program Files (x86)\xfin_portal\chrome\skin\weather -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\web.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\webinspector-highrisk-user.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\webinspector-highrisk.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\webinspector-lowrisk.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\webinspector-norating.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\webinspector-verified-user.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\webinspector-verified.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\webinspector-verifying.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\websearch.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\websearch_16_16.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\websearch_png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\websiteinspector-highrisk.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\wi16.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\wikipedia.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\xfinity_bg.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\xfinity_ftr.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\xfinity_logoftr.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\xfinity_logotop.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\xftv.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\XF_16x16_Favicon.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\XF_16x16_Favicon_png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\yahoosearch.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\yellow.gif -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\youtube.png -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\chrome\skin\zoom.png -> Deleted
    [PUP][Folder] C:\Program Files (x86)\xfin_portal\chrome\skin -> Deleted
    [PUP][Folder] C:\Program Files (x86)\xfin_portal\chrome -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\CIDCoreLight.dll -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\CIDGlobalLight.exe -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\CIDGlobalLightPS.dll -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\comcastdx.dll -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\comcasttb.dll -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\components\windowmediator.js -> Deleted
    [PUP][Folder] C:\Program Files (x86)\xfin_portal\components -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\dtuser.exe -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\dtxcid.dll -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\ffHelper.exe -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\install.ico -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\manifest.xml -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\search.ico -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\toolbar.xml -> Deleted
    [PUP][File] C:\Program Files (x86)\xfin_portal\uninstall.exe -> Deleted

    ¤¤¤ Hosts File : 0 ¤¤¤

    ¤¤¤ Antirootkit : 0 (Driver: Not loaded [0xc000036b]) ¤¤¤

    ¤¤¤ Web browsers : 0 ¤¤¤

    ¤¤¤ MBR Check : ¤¤¤
    +++++ PhysicalDrive0: TOSHIBA DT01ACA200 +++++
    --- User ---
    [MBR] 7712648cf182118509e48f0399112921
    [BSP] 005035d078a3ee53580af2407d965b74 : Windows Vista/7/8|VT.Unknown MBR Code
    Partition table:
    0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 63 | Size: 345 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
    1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 706860 | Size: 953072 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
    2 - [XXXXXX] ACER (0x27) [VISIBLE] Offset (sectors): 1952600064 | Size: 450 MB
    User = LL1 ... OK
    User = LL2 ... OK
     
  12. Chris Waters

    Chris Waters TS Rookie Topic Starter Posts: 23

    Malwarebytes Anti-Malware
    www.malwarebytes.org

    Scan Date: 1/12/2016
    Scan Time: 8:39 PM
    Logfile: first MAMB scan.txt
    Administrator: Yes

    Version: 2.2.0.1024
    Malware Database: v2016.01.13.01
    Rootkit Database: v2016.01.09.01
    License: Trial
    Malware Protection: Enabled
    Malicious Website Protection: Enabled
    Self-protection: Disabled

    OS: Windows 10
    CPU: x64
    File System: NTFS
    User: Chris

    Scan Type: Threat Scan
    Result: Completed
    Objects Scanned: 383769
    Time Elapsed: 16 min, 44 sec

    Memory: Enabled
    Startup: Enabled
    Filesystem: Enabled
    Archives: Enabled
    Rootkits: Disabled
    Heuristics: Enabled
    PUP: Enabled
    PUM: Enabled

    Processes: 0
    (No malicious items detected)

    Modules: 0
    (No malicious items detected)

    Registry Keys: 21
    PUP.Optional.BrowseFox, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\{572f484b-455f-44b0-9d6a-da3ad2071365}w64, Quarantined, [80a54decfd9c95a1e5358747f21235cb],
    PUP.Optional.BrowseFox, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\{646e947e-f0e6-4d0e-b21e-d62ca97183e2}Gw64, Quarantined, [ba6bc178eaaffa3c33e7894506fe48b8],
    PUP.Optional.WebSteroids, HKLM\SOFTWARE\CLASSES\CLSID\{051E9166-B275-4683-907B-372FAE22BC7C}, Quarantined, [131254e545541e182be2babec24025db],
    PUP.Optional.WebSteroids, HKLM\SOFTWARE\WOW6432NODE\CLASSES\CLSID\{051E9166-B275-4683-907B-372FAE22BC7C}, Quarantined, [131254e545541e182be2babec24025db],
    PUP.Optional.WebSteroids, HKLM\SOFTWARE\CLASSES\WOW6432NODE\CLSID\{051E9166-B275-4683-907B-372FAE22BC7C}, Quarantined, [131254e545541e182be2babec24025db],
    PUP.Optional.SearchProtect.AppFlsh, HKU\S-1-5-21-905238947-2220377667-1876713056-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}, Quarantined, [a28370c92178dd59bbcbaad7986af60a],
    PUP.Optional.SearchProtect.AppFlsh, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}, Quarantined, [a28370c92178dd59bbcbaad7986af60a],
    PUP.Optional.MySearchDial, HKU\S-1-5-21-905238947-2220377667-1876713056-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{77AA745B-F4F8-45DA-9B14-61D2D95054C8}, Quarantined, [77aeb3869cfd73c30b29c1b4e41ea45c],
    PUP.Optional.MySearchDial, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{77AA745B-F4F8-45DA-9B14-61D2D95054C8}, Quarantined, [77aeb3869cfd73c30b29c1b4e41ea45c],
    PUP.Optional.TopArcadeHits, HKU\S-1-5-21-905238947-2220377667-1876713056-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\STATS\{CF190686-9E72-403C-B99D-682ABDB63C5B}, Quarantined, [f82d5bdee2b7989eb3d241360bf76898],
    PUP.Optional.VMNToolBar, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\PREAPPROVED\{CCB24E92-62C4-4C53-95D2-65F9EED476BC}, Quarantined, [5bcae1583e5bde584b97f384e71b8779],
    PUP.Optional.MySearchDial, HKLM\SOFTWARE\GOOGLE\CHROME\EXTENSIONS\pflphaooapbgpeakohlggbpidpppgdff, Quarantined, [fd2805342b6ec96dac2d05c2986be020],
    PUP.Optional.MyStartToolbar, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{62155D33-3CE2-401E-8967-5A270628A3D5}, Quarantined, [a97cff3a673271c5b38810bda35ff808],
    PUP.Optional.MySearchDial, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\pflphaooapbgpeakohlggbpidpppgdff, Quarantined, [0322f8419cfdf145a930626515ee04fc],
    PUP.Optional.Tuto4PC, HKLM\SOFTWARE\WOW6432NODE\TUTORIALS, Quarantined, [42e3f346762396a08e73a13ca65d1ae6],
    PUP.Optional.InstallCore, HKU\S-1-5-21-905238947-2220377667-1876713056-1001\SOFTWARE\InstallCore, Quarantined, [a580fa3f0c8d171f48be437ba65d9e62],
    PUP.Optional.Tuto4PC, HKU\S-1-5-21-905238947-2220377667-1876713056-1001\SOFTWARE\TutoTag, Quarantined, [a67f0831cdccca6c738af3e937cc7f81],
    PUP.Optional.ViewPassword, HKU\S-1-5-21-905238947-2220377667-1876713056-1001\SOFTWARE\APPDATALOW\SOFTWARE\ViewPassword, Quarantined, [bb6a8aaf05948aac99f9518d38cb30d0],
    PUP.Optional.MySearchDial, HKU\S-1-5-21-905238947-2220377667-1876713056-1001\SOFTWARE\GOOGLE\CHROME\EXTENSIONS\pflphaooapbgpeakohlggbpidpppgdff, Quarantined, [ae77f247dfba6fc70bc84c7bee15b24e],
    PUP.Optional.MySearchDial, HKU\S-1-5-21-905238947-2220377667-1876713056-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E}, Quarantined, [e0453009c7d267cf6b6a7750e91adb25],
    PUP.Optional.Spigot, HKU\S-1-5-21-905238947-2220377667-1876713056-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{944DD3A0-792B-4828-AB6C-5C063459D00C}, Quarantined, [cb5ae356bddce55179e10ec9b25135cb],

    Registry Values: 12
    PUP.Optional.MyStartToolbar, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY\{62155D33-3CE2-401E-8967-5A270628A3D5}|AppPath, C:\Program Files (x86)\mystarttb, Quarantined, [a97cff3a673271c5b38810bda35ff808]
    PUP.Optional.MySearchDial, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\LOW RIGHTS\ELEVATIONPOLICY|AppPath, C:\Program Files (x86)\Mysearchdial\1.8.29.0\, Quarantined, [7ca98faa49509d99bd1da324c83bf30d]
    PUP.Optional.OneSoftPerDay, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|ospd_us_738, Quarantined, [959052e787126dc923786c5dff0428d8],
    PUP.Optional.Tuto4PC, HKLM\SOFTWARE\WOW6432NODE\TUTORIALS|HostGUID, A0113EE1-91E8-43BB-B5E9-93628D6D5BFD, Quarantined, [42e3f346762396a08e73a13ca65d1ae6]
    PUP.Optional.Trovi, HKU\S-1-5-21-905238947-2220377667-1876713056-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}|URL, http://www.trovi.com/Results.aspx?g...-40AF-A35C-639960EDD6A2&q={searchTerms}&SSPV=, Quarantined, [f233a7922079f24404939745fb08fd03]
    PUP.Optional.Conduit, HKU\S-1-5-21-905238947-2220377667-1876713056-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}|SuggestionsURL_JSON, http://suggest.search.conduit.com/CSuggestJson.ashx?prefix={searchTerms}, Quarantined, [67bea9908e0b87af29f5e0cc857e5ba5]
    PUP.Optional.MySearchDial, HKU\S-1-5-21-905238947-2220377667-1876713056-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E}|URL, http://start.mysearchdial.com/resul...DyDzz2QtN1B1L1H1Ezu1O2U1M1B&cr=1435966762&ir=, Quarantined, [e0453009c7d267cf6b6a7750e91adb25]
    PUP.Optional.MySearchDial, HKU\S-1-5-21-905238947-2220377667-1876713056-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E}|TopResultURLFallback, http://start.mysearchdial.com/resul...DyDzz2QtN1B1L1H1Ezu1O2U1M1B&cr=1435966762&ir=, Quarantined, [cd5881b84653a19525b0d8ef847fb54b]
    PUP.Optional.MySearchDial, HKU\S-1-5-21-905238947-2220377667-1876713056-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E}|FaviconPath, C:\Program Files (x86)\Mysearchdial\1.8.29.0\FavIcon.ico, Quarantined, [b0753bfec7d2eb4b14c1cff89f64758b]
    PUP.Optional.MySearchDial, HKU\S-1-5-21-905238947-2220377667-1876713056-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E}, Mysearchdial, Quarantined, [a1843ffab3e604320acbcafd818241bf]
    PUP.Optional.MySearchDial, HKU\S-1-5-21-905238947-2220377667-1876713056-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E}|DisplayName, Mysearchdial, Quarantined, [7ca9be7b148567cf8f46d5f243c0ae52]
    PUP.Optional.Spigot, HKU\S-1-5-21-905238947-2220377667-1876713056-1001\SOFTWARE\MICROSOFT\INTERNET EXPLORER\SEARCHSCOPES\{944DD3A0-792B-4828-AB6C-5C063459D00C}|URL, http://search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=617686&p={searchTerms}, Quarantined, [cb5ae356bddce55179e10ec9b25135cb]

    Registry Data: 1
    PUP.Optional.MySearchDial, HKLM\SOFTWARE\MICROSOFT\INTERNET EXPLORER\MAIN|Start Page, http://start.mysearchdial.com/?f=1&...DyDzz2QtN1B1L1H1Ezu1O2U1M1B&cr=1435966762&ir=, Good: (www.google.com), Bad: (http://start.mysearchdial.com/?f=1&...B1L1H1Ezu1O2U1M1B&cr=1435966762&ir=),Replaced,[988d5cdda5f4181ea2cc0e9fe71d55ab]

    Folders: 4
    PUP.Optional.APNToolBar.Gen, C:\ProgramData\APN\APN-Stub, Quarantined, [fc29d6631f7ad5612a2d9ef818ea9b65],
    PUP.Optional.GreatArcadeHits, C:\Users\Chris\AppData\Local\GreatArcadeHits, Quarantined, [b1742c0d1a7f0b2be68787235ba753ad],
    PUP.Optional.SearchProtect.AppFlsh, C:\Windows\SysWOW64\SearchProtect, Quarantined, [62c366d3f9a0c86eed4db213dd25b44c],
    PUP.Optional.SearchProtect.AppFlsh, C:\Windows\SysWOW64\SearchProtect\Logs, Quarantined, [62c366d3f9a0c86eed4db213dd25b44c],

    Files: 8
    PUP.Optional.BrowseFox, C:\Windows\System32\drivers\{572f484b-455f-44b0-9d6a-da3ad2071365}w64.sys, Delete-on-Reboot, [80a54decfd9c95a1e5358747f21235cb],
    PUP.Optional.BrowseFox, C:\Windows\System32\drivers\{646e947e-f0e6-4d0e-b21e-d62ca97183e2}Gw64.sys, Delete-on-Reboot, [ba6bc178eaaffa3c33e7894506fe48b8],
    PUP.Optional.APNToolBar, C:\Users\Chris\Documents\APNSetup.exe, Quarantined, [b86de8518e0bf93d088565ca768b24dc],
    Trojan.Crypt.MSIL, C:\Users\Chris\Downloads\Unconfirmed 879568.crdownload, Quarantined, [061f7fbaa9f02d09a13ce69417eada26],
    PUP.Optional.DownloadAssistant, C:\Users\Chris\Downloads\Windows Live Movie Maker.exe, Quarantined, [77aee059b3e612244c23cc0833cd04fc],
    PUP.Optional.MyStartTB.ShrtCln, C:\Users\Chris\AppData\Local\Flvto Plugin for Google Chrome\Launcher.exe, Quarantined, [26fff2477e1b47ef849cd9d17b8531cf],
    PUP.Optional.MySpeedDial, C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_pflphaooapbgpeakohlggbpidpppgdff_0.localstorage, Quarantined, [ab7aea4fcbced561ffe7e1e6d3305aa6],
    PUP.Optional.GreatArcadeHits, C:\Users\Chris\AppData\Local\GreatArcadeHits\GAHUninstaller.exe, Quarantined, [b1742c0d1a7f0b2be68787235ba753ad],

    Physical Sectors: 0
    (No malicious items detected)


    (end)
     
  13. Chris Waters

    Chris Waters TS Rookie Topic Starter Posts: 23

    # AdwCleaner v5.029 - Logfile created 12/01/2016 at 21:26:19
    # Updated 11/01/2016 by Xplode
    # Database : 2016-01-12.1 [Server]
    # Operating system : Windows 10 Home (x64)
    # Username : Chris - CHRISTOPHERS
    # Running from : C:\Users\Chris\Downloads\adwcleaner_5.029.exe
    # Option : Cleaning
    # Support : http://toolslib.net/forum

    ***** [ Services ] *****


    ***** [ Folders ] *****

    [-] Folder Deleted : C:\ProgramData\apn
    [-] Folder Deleted : C:\Users\Chris\AppData\Local\eSupport.com
    [-] Folder Deleted : C:\Users\Chris\AppData\Local\PackageAware
    [-] Folder Deleted : C:\Users\Chris\AppData\LocalLow\comcasttb
    [-] Folder Deleted : C:\Users\Chris\AppData\LocalLow\xfin_portal
    [-] Folder Deleted : C:\Users\Chris\AppData\Roaming\download Manager

    ***** [ Files ] *****

    [-] File Deleted : C:\END
    [-] File Deleted : C:\WINDOWS\SysNative\roboot64.exe

    ***** [ DLLs ] *****


    ***** [ Shortcuts ] *****


    ***** [ Scheduled tasks ] *****

    [-] Task Deleted : AVG-Secure-Search-Update_0414c_rel
    [-] Task Deleted : AVG-Secure-Search-Update_0414c_rmv
    [-] Task Deleted : AVG-Secure-Search-Update_0414c_rel
    [-] Task Deleted : AVG-Secure-Search-Update_0414c_rmv

    ***** [ Registry ] *****

    [-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\ScriptHelper.EXE
    [-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\{49BC4DD1-0E69-4611-9164-0009538C5E46}
    [-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB}
    [-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{0214A12B-C5A3-437F-A6F3-068ABCD8C85E}
    [-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{08635077-8829-49E2-B338-C968817EB460}
    [-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
    [-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{20A3F109-F7C1-47B4-8098-8E654B264B1D}
    [-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4B9BCCE8-A70B-402A-A7E1-DB96831EE26F}
    [-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
    [-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{8C7478AB-3155-463E-936F-55F91F0F10D0}
    [-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{96DD9437-5D20-4EFB-BF52-A4A605A4E0AA}
    [-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{9E1B65EE-A131-42B4-94CA-847505E2F611}
    [-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468}
    [-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
    [-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A2970C7C-8392-4E6F-8B51-B763CF38E13C}
    [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{0214A12B-C5A3-437F-A6F3-068ABCD8C85E}
    [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
    [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
    [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{96DD9437-5D20-4EFB-BF52-A4A605A4E0AA}
    [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
    [-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
    [-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{07CAC314-E962-4F78-89AB-DD002F2490EE}
    [-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{4A11A6BD-7880-49BD-92D4-6F09D0BD3250}
    [-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{68DE31F7-43FF-4EE2-B88B-10665016970D}
    [-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
    [-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{A2D733A7-73B0-4C6B-B0C7-06A432950B66}
    [-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4B9BCCE8-A70B-402A-A7E1-DB96831EE26F}
    [-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4B9BCCE8-A70B-402A-A7E1-DB96831EE26F}
    [-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706}
    [-] Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A2159D33-3CE2-401B-8967-1B270628A311}
    [-] Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{4B9BCCE8-A70B-402A-A7E1-DB96831EE26F}]
    [-] Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}]
    [-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{5A4E3A41-FA55-4BDA-AED7-CEBE6E7BCB52}
    [-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{A2970C7C-8392-4E6F-8B51-B763CF38E13C}
    [-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{0214A12B-C5A3-437F-A6F3-068ABCD8C85E}
    [-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
    [-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{4E6354DE-9115-4AEE-BD21-C46C3E8A49DB}
    [-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{96DD9437-5D20-4EFB-BF52-A4A605A4E0AA}
    [-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
    [-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{FC073BDA-C115-4A1D-9DF9-9B5C461482E5}
    [-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{49BC4DD1-0E69-4611-9164-0009538C5E46}
    [-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A2159D33-3CE2-401B-8967-1B270628A311}
    [-] Key Deleted : HKCU\Software\Conduit
    [-] Key Deleted : HKCU\Software\eSupport.com
    [-] Key Deleted : HKCU\Software\usyndication.com
    [-] Key Deleted : HKCU\Software\USyndication
    [-] Key Deleted : HKCU\Software\AppDataLow\Software\xfin_portal
    [-] Key Deleted : HKLM\SOFTWARE\Trymedia Systems
    [-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\xfin_portal
    [-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\superfish.com
    [-] Key Deleted : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.superfish.com

    ***** [ Web browsers ] *****


    *************************

    :: "Tracing" keys removed
    :: Winsock settings cleared

    ########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [5884 bytes] ##########
     
  14. Chris Waters

    Chris Waters TS Rookie Topic Starter Posts: 23

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    Junkware Removal Tool (JRT) by Malwarebytes
    Version: 8.0.2 (01.06.2016)
    Operating System: Windows 10 Home x64
    Ran by Chris (Administrator) on Tue 01/12/2016 at 21:39:26.45
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




    File System: 4

    Successfully deleted: C:\Users\Chris\AppData\Local\crashrpt (Folder)
    Successfully deleted: C:\Users\Chris\AppData\Roaming\nico mak computing (Folder)
    Successfully deleted: C:\Users\Chris\AppData\Roaming\wyupdate au (Folder)
    Successfully deleted: C:\Users\Chris\Documents\add-in express (Folder)



    Registry: 0





    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    Scan was completed on Tue 01/12/2016 at 21:41:11.07
    End of JRT log
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
     
  15. Broni

    Broni Malware Annihilator Posts: 52,897   +344

    Re-run Farbar Recovery Scan Tool (FRST/FRST64) you ran at the very beginning of this topic.

    • Double click to run it.
    • Make sure you checkmark Addition.txt box.
    • Press Scan button.
    • Scan will create two logs, FRST.txt and Addition.txt in the same directory the tool is run. Please copy and paste them to your reply.
     
  16. Chris Waters

    Chris Waters TS Rookie Topic Starter Posts: 23

    Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:10-01-2015 01
    Ran by Chris (administrator) on CHRISTOPHERS (13-01-2016 22:12:58)
    Running from C:\Users\Chris\Downloads
    Loaded Profiles: Chris (Available Profiles: Chris)
    Platform: Windows 10 Home Version 1511 (X64) Language: English (United States)
    Internet Explorer Version 11 (Default browser: Edge)
    Boot Mode: Normal
    Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

    ==================== Processes (Whitelisted) =================

    (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

    (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
    (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
    (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
    (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
    (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    (Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
    (Realtek) C:\Program Files (x86)\REALTEK\11n USB Wireless LAN Utility\RtlService.exe
    (Razer Inc.) C:\Program Files (x86)\Razer\Razer Cortex\RzKLService.exe
    () C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe
    (Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
    (Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
    () C:\MSI\Smart Utilities\SuperRAIDSvc.exe
    (Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
    (Eastman Kodak Company) C:\Program Files (x86)\Kodak\AiO\Center\EKAiOHostService.exe
    (AOMEI Tech Co., Ltd.) C:\Program Files (x86)\AOMEI Backupper Professional Edition 2.2\ABService.exe
    (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
    (Eastman Kodak Company) C:\Program Files (x86)\Kodak\AiO\StatusMonitor\EKPrinterSDK.exe
    (White Sky, Inc.) C:\Program Files (x86)\Constant Guard Protection Suite\IDVaultSvc.exe
    (MSI) C:\Program Files (x86)\MSI\Fast Boot\FastBootService.exe
    (MSI) C:\Program Files (x86)\MSI\Super Charger\ChargeService.exe
    () C:\Program Files (x86)\MSI\Command Center\MSIControlService.exe
    () C:\Program Files (x86)\NETGEAR\WNDA3100v2\WifiSvc.exe
    (MICRO-STAR INTERNATIONAL CO., LTD.) C:\Program Files (x86)\MSI\MSITrigger\MSI_Trigger_Service.exe
    (Micro-Star International) C:\Program Files (x86)\MSI\Live Update\MSI_LiveUpdate_Service.exe
    (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
    (Qualcomm Atheros) C:\Program Files\Qualcomm Atheros\Network Manager\KillerService.exe
    (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
    (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
    () C:\Program Files (x86)\MSI\Command Center\CPU\MSICPUService.exe
    (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
    (MSI CO.,LTD.) C:\Program Files (x86)\MSI\Command Center\CPU\CPU_Ratio\CPU_Ratio.exe
    (Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
    (Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
    (Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
    (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe
    (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.29.1\GoogleCrashHandler.exe
    (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.29.1\GoogleCrashHandler64.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
    (Malwarebytes) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
    () C:\Program Files\WindowsApps\Microsoft.Messaging_2.12.15004.0_x86__8wekyb3d8bbwe\SkypeHost.exe
    (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
    (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
    (Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
    (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
    (Realtek Semiconductor Corp.) C:\Program Files (x86)\REALTEK\11n USB Wireless LAN Utility\RtWLan.exe
    (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
    (Microsoft Corporation) C:\Windows\System32\rundll32.exe
    () C:\Users\Chris\AppData\Roaming\SWClient\swclient.exe
    (Spotify Ltd) C:\Users\Chris\AppData\Roaming\Spotify\SpotifyWebHelper.exe
    (Flux Software LLC) C:\Users\Chris\AppData\Local\FluxSoftware\Flux\flux.exe
    (Microsoft Corporation) C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonX86\Microsoft Shared\OFFICE15\CSISYNCCLIENT.EXE
    (Microsoft Corporation) C:\Program Files\Microsoft Office 15\root\office15\MSOSYNC.EXE
    (Creative Technology Ltd) C:\Program Files (x86)\Creative\Sound Blaster Cinema\Sound Blaster Cinema\SBCinema.exe
    () C:\Program Files\Qualcomm Atheros\Network Manager\NetworkManager.exe
    (MSI) C:\Program Files (x86)\MSI\Super Charger\Super Charger.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe
    () C:\Users\Chris\AppData\Roaming\Dashlane\DashlanePlugin.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.6525.42271.0_x64__8wekyb3d8bbwe\HxTsr.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe


    ==================== Registry (Whitelisted) ===========================

    (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

    HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8492800 2015-06-24] (Realtek Semiconductor)
    HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
    HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2655520 2015-10-11] (NVIDIA Corporation)
    HKLM\...\Run: [ShadowPlay] => C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\nvspcap64.dll,ShadowPlayOnSystemStart
    HKLM\...\Run: [MBCfg64] => C:\WINDOWS\system32\RunDLL32.exe C:\WINDOWS\system32\MBCfg64.dll,RunDLLEntry MBCfg64
    HKLM-x32\...\Run: [LWS] => C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe [204136 2012-09-12] (Logitech Inc.)
    HKLM-x32\...\Run: [PWRISOVM.EXE] => C:\Program Files (x86)\PowerISO\PWRISOVM.EXE [337432 2013-07-21] (Power Software Ltd)
    HKLM-x32\...\Run: [amd_dc_opt] => C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe [77824 2008-07-22] (AMD)
    HKLM-x32\...\Run: [] => [X]
    HKLM-x32\...\Run: [Razer Synapse] => C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe [585048 2014-05-31] (Razer Inc.)
    HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.)
    HKLM-x32\...\Run: [Sound Blaster Cinema] => C:\Program Files (x86)\Creative\Sound Blaster Cinema\Sound Blaster Cinema\SBCinema.exe [711680 2013-08-16] (Creative Technology Ltd)
    HKLM-x32\...\Run: [UpdReg] => C:\WINDOWS\UpdReg.EXE
    HKLM-x32\...\Run: [Super Charger] => C:\Program Files (x86)\MSI\Super Charger\Super Charger.exe [1047536 2014-04-08] (MSI)
    HKLM-x32\...\Run: [Fast Boot] => C:\Program Files (x86)\MSI\Fast Boot\StartFastBoot.exe [764472 2012-09-19] ()
    HKLM-x32\...\Run: [Command Center] => C:\Program Files (x86)\MSI\Command Center\StartCommandCenter.exe [814064 2014-04-02] ()
    HKLM-x32\...\Run: [Live Update] => C:\Program Files (x86)\MSI\Live Update\StartLiveUpdate.exe [579056 2014-03-28] (Micro-Star International)
    HKLM-x32\...\Run: [EKStatusMonitor] => C:\Program Files (x86)\Kodak\AiO\StatusMonitor\EKStatusMonitor.exe [2750840 2013-12-11] (Eastman Kodak Company)
    HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [157480 2014-10-15] (Apple Inc.)
    HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [334896 2015-06-08] (Oracle Corporation)
    HKU\S-1-5-21-905238947-2220377667-1876713056-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\Steam.exe [3013712 2015-12-14] (Valve Corporation)
    HKU\S-1-5-21-905238947-2220377667-1876713056-1001\...\Run: [ooVoo.exe] => C:\Program Files (x86)\ooVoo\oovoo.exe [35239488 2013-06-20] (ooVoo LLC)
    HKU\S-1-5-21-905238947-2220377667-1876713056-1001\...\Run: [SWClient] => C:\Users\Chris\AppData\Roaming\SWClient\swclient.exe [6257664 2013-02-09] ()
    HKU\S-1-5-21-905238947-2220377667-1876713056-1001\...\Run: [AVG-Secure-Search-Update_0414c] => C:\Program Files (x86)\Avg Secure Update\AVG-Secure-Search-Update_0414c.exe [2725912 2014-04-21] ()
    HKU\S-1-5-21-905238947-2220377667-1876713056-1001\...\Run: [Dashlane] => C:\Users\Chris\AppData\Roaming\Dashlane\Dashlane.exe [227712 2015-10-23] ()
    HKU\S-1-5-21-905238947-2220377667-1876713056-1001\...\Run: [uTorrent] => C:\Users\Chris\AppData\Roaming\uTorrent\uTorrent.exe [1329744 2014-08-05] (BitTorrent Inc.)
    HKU\S-1-5-21-905238947-2220377667-1876713056-1001\...\Run: [DashlanePlugin] => C:\Users\Chris\AppData\Roaming\Dashlane\DashlanePlugin.exe [285568 2015-10-23] ()
    HKU\S-1-5-21-905238947-2220377667-1876713056-1001\...\Run: [GalaxyClient] => C:\Program Files (x86)\GalaxyClient\GalaxyClient.exe [7247416 2015-07-17] (GOG.com)
    HKU\S-1-5-21-905238947-2220377667-1876713056-1001\...\Run: [Spotify Web Helper] => C:\Users\Chris\AppData\Roaming\Spotify\SpotifyWebHelper.exe [2346096 2015-12-16] (Spotify Ltd)
    HKU\S-1-5-21-905238947-2220377667-1876713056-1001\...\Run: [Spotify] => C:\Users\Chris\AppData\Roaming\Spotify\Spotify.exe [8387696 2015-12-16] (Spotify Ltd)
    HKU\S-1-5-21-905238947-2220377667-1876713056-1001\...\Run: [f.lux] => C:\Users\Chris\AppData\Local\FluxSoftware\Flux\flux.exe [1017224 2013-10-23] (Flux Software LLC)
    HKU\S-1-5-21-905238947-2220377667-1876713056-1001\...\RunOnce: [Uninstall C:\Users\Chris\AppData\Local\Microsoft\OneDrive\17.3.6201.1019_1\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Chris\AppData\Local\Microsoft\OneDrive\17.3.6201.1019_1\amd64"
    HKU\S-1-5-21-905238947-2220377667-1876713056-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\Ribbons.scr [149504 2015-10-30] (Microsoft Corporation)
    ShellIconOverlayIdentifiers: [ GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2015-11-04] (Google)
    ShellIconOverlayIdentifiers: [ GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2015-11-04] (Google)
    ShellIconOverlayIdentifiers: [ GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2015-11-04] (Google)
    ShellIconOverlayIdentifiers: [###MegaShellExtPending] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => C:\Users\Chris\AppData\Local\MEGAsync\ShellExtX64.dll [2014-05-01] ()
    ShellIconOverlayIdentifiers: [###MegaShellExtSynced] -> {05B38830-F4E9-4329-978B-1DD28605D202} => C:\Users\Chris\AppData\Local\MEGAsync\ShellExtX64.dll [2014-05-01] ()
    ShellIconOverlayIdentifiers: [###MegaShellExtSyncing] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => C:\Users\Chris\AppData\Local\MEGAsync\ShellExtX64.dll [2014-05-01] ()
    ShellIconOverlayIdentifiers-x32: [ SkyDrivePro1 (ErrorConflict)] -> {8BA85C75-763B-4103-94EB-9470F12FE0F7} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2015-12-15] (Microsoft Corporation)
    ShellIconOverlayIdentifiers-x32: [ SkyDrivePro2 (SyncInProgress)] -> {CD55129A-B1A1-438E-A425-CEBC7DC684EE} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2015-12-15] (Microsoft Corporation)
    ShellIconOverlayIdentifiers-x32: [ SkyDrivePro3 (InSync)] -> {E768CD3B-BDDC-436D-9C13-E1B39CA257B1} => C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2015-12-15] (Microsoft Corporation)
    ShellIconOverlayIdentifiers-x32: [###MegaShellExtPending] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => C:\Users\Chris\AppData\Local\MEGAsync\ShellExtX32.dll [2014-05-01] ()
    ShellIconOverlayIdentifiers-x32: [###MegaShellExtSynced] -> {05B38830-F4E9-4329-978B-1DD28605D202} => C:\Users\Chris\AppData\Local\MEGAsync\ShellExtX32.dll [2014-05-01] ()
    ShellIconOverlayIdentifiers-x32: [###MegaShellExtSyncing] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => C:\Users\Chris\AppData\Local\MEGAsync\ShellExtX32.dll [2014-05-01] ()
    Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Constant Guard.lnk [2016-01-12]
    ShortcutTarget: Constant Guard.lnk -> C:\Program Files (x86)\Constant Guard Protection Suite\IDVault.exe (White Sky, Inc.)
    Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Killer Network Manager.lnk [2016-01-12]
    ShortcutTarget: Killer Network Manager.lnk -> C:\Windows\Installer\{4692B750-DE88-4DCF-9163-745AF5604B24}\NetworkManager.exe_130C27D738F34C89BDDF21BCFD74B56D.exe (Flexera Software LLC)
    Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\NETGEAR WNDA3100v2 Genie.lnk [2016-01-12]
    ShortcutTarget: NETGEAR WNDA3100v2 Genie.lnk -> C:\Program Files (x86)\NETGEAR\WNDA3100v2\WNDA3100v2.exe ()
    Startup: C:\Users\Chris\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\GameStop Now.lnk [2016-01-12]
    ShortcutTarget: GameStop Now.lnk -> C:\Program Files (x86)\GameStop App\Now\GameStopNow.exe (GameStop Corp.)
    Startup: C:\Users\Chris\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MEGAsync.lnk [2016-01-12]
    ShortcutTarget: MEGAsync.lnk -> C:\Users\Chris\AppData\Local\MEGAsync\MEGAsync.exe (Mega Limited)

    ==================== Internet (Whitelisted) ====================

    (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

    Tcpip\Parameters: [DhcpNameServer] 75.75.75.75 75.75.76.76
    Tcpip\..\Interfaces\{efe8e331-10e7-4c7b-8281-b54d8c8fd35f}: [DhcpNameServer] 75.75.75.75 75.75.76.76

    Internet Explorer:
    ==================
    HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
    HKU\S-1-5-21-905238947-2220377667-1876713056-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://t.msn.com/
    SearchScopes: HKU\S-1-5-21-905238947-2220377667-1876713056-1001 -> DefaultScope {3BD44F0E-0596-4008-AEE0-45D47E3A8F0E} URL =
    BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2015-12-15] (Microsoft Corporation)
    BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_51\bin\ssv.dll [2015-07-26] (Oracle Corporation)
    BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2015-12-15] (Microsoft Corporation)
    BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_51\bin\jp2ssv.dll [2015-07-26] (Oracle Corporation)
    BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll [2015-12-15] (Microsoft Corporation)
    BHO-x32: Constant Guard Protection Suite -> {B84CDBE7-1B46-494B-A188-01D4C52DEB61} -> C:\ProgramData\White Sky, Inc\ID Vault\IEBHO1.13.820.2\NativeBHO.dll [2013-08-20] (WhiteSky)
    BHO-x32: Updater For XFIN_PORTAL -> {bb46be07-13eb-4c49-b0f0-fc78b9ea4983} -> C:\Program Files (x86)\xfin_portal\auxi\comcastAu.dll => No File
    BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2015-12-15] (Microsoft Corporation)
    Toolbar: HKLM-x32 - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
    Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL [2015-07-22] (Microsoft Corporation)
    Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)

    FireFox:
    ========
    FF ProfilePath: C:\Users\Chris\AppData\Roaming\Mozilla\Firefox\Profiles\mshnp4wc.default
    FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_20_0_0_267.dll [2015-12-29] ()
    FF Plugin: @java.com/DTPlugin,version=10.25.2 -> C:\WINDOWS\system32\npDeployJava1.dll [2013-06-20] (Oracle Corporation)
    FF Plugin: @java.com/JavaPlugin,version=11.51.2 -> C:\Program Files\Java\jre1.8.0_51\bin\plugin2\npjp2.dll [2015-07-26] (Oracle Corporation)
    FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-11] ( Microsoft Corporation)
    FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_20_0_0_267.dll [2015-12-29] ()
    FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2014-02-18] ()
    FF Plugin-x32: @esn.me/esnsonar,version=0.70.4 -> C:\Program Files (x86)\Battlelog Web Plugins\Sonar\0.70.4\npesnsonar.dll [2011-11-03] (ESN Social Software AB)
    FF Plugin-x32: @esn/esnlaunch,version=2.3.0 -> C:\Program Files (x86)\Battlelog Web Plugins\2.3.0\npesnlaunch.dll [2013-09-25] (ESN Social Software AB)
    FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2013-10-07] (Google)
    FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2014-02-19] (Intel Corporation)
    FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2014-02-19] (Intel Corporation)
    FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2015-11-03] (Microsoft Corporation)
    FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-11] ( Microsoft Corporation)
    FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [2013-07-10] (Microsoft Corporation)
    FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2015-11-05] (NVIDIA Corporation)
    FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2015-11-05] (NVIDIA Corporation)
    FF Plugin-x32: @raidcall.en/RCplugin -> C:\Users\Chris\AppData\Roaming\raidcall\plugins\nprcplugin.dll [2013-03-30] (Raidcall)
    FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-03] (Google Inc.)
    FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-03] (Google Inc.)
    FF Plugin HKU\S-1-5-21-905238947-2220377667-1876713056-1001: @doubletwist.com/NPPodcast -> C:\Program Files (x86)\Common Files\doubleTwist\NPPodcast.dll [No File]
    FF Plugin HKU\S-1-5-21-905238947-2220377667-1876713056-1001: @onlive.com/OnLiveGameClientDetector,version=1.0.0 -> C:\Program Files (x86)\OnLive\Plugin\npolgdet.dll [2013-12-02] (OnLive)

    Chrome:
    =======
    CHR HomePage: Profile 4 -> hxxp://www.search.ask.com/?gct=hp
    CHR StartupUrls: Profile 4 -> "hxxp://www.google.com/ig/redirectdomain?brand=TSND&bmod=TSND","hxxp://start.mysearchdial.com/?f=1&a=frg01_14_25_ch&cd=2XzuyEtN2Y1L1Qzu0BzzzyyByD0AtBtAtBzzzztBzy0BtDyEtN0D0Tzu0SzzzyzytN1L2XzutBtFtBtCtFyEtFtCtN1L1CzutCyEtBzytDyD1V1RtN1L1G1B1V1N2Y1L1Qzu2SyC0AtC0EtD0F0DtCtGyEtBzy0CtGyBtBzz0CtGtAyBzztAtGyC0D0F0FyC0B0F0FyBtAyDzy2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyEyC0DyD0C0EtDtBtGyDtD0F0CtGtAyEzzzytGyC0A0AtDtGyEyDyE0FzytC0AtD0E0DyDzz2QtN1B1L1H1Ezu1O2U1M1B&cr=1435966762&ir=","hxxp://www.google.com"
    CHR Session Restore: Profile 4 -> is enabled.
    CHR Profile: C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Default
    CHR Profile: C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Profile 4
    CHR Extension: (BetterTTV) - C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\ajopnjidmegmdimjlfnijceegpefgped [2015-07-23]
    CHR Extension: (Google Docs) - C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\aohghmighlieiainnegkcijnfilokake [2015-07-23]
    CHR Extension: (Google Drive) - C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-21]
    CHR Extension: (MEGA) - C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\bigefpfhnfcobdlfbedofhhaibnlghod [2016-01-12]
    CHR Extension: (YouTube) - C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-24]
    CHR Extension: (Adblock Plus) - C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2016-01-05]
    CHR Extension: (Google Search) - C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-26]
    CHR Extension: (Dashlane) - C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\fdjamakpfbbddfjaooikfcpapjohcfmg [2015-12-20]
    CHR Extension: (Google Docs Offline) - C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-11-17]
    CHR Extension: (AdBlock) - C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2016-01-08]
    CHR Extension: (Google Dictionary (by Google)) - C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\mgijmajocgfcbeboacabfgobmjgjcoja [2016-01-12]
    CHR Extension: (ooVoo Video Chat) - C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\nimgeceabhadboepjjddfhepideeilej [2014-04-16]
    CHR Extension: (Chrome Web Store Payments) - C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-07-23]
    CHR Extension: (Enhanced Steam) - C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\okadibdjfemgnhjiembecghcbfknbfhg [2016-01-12]
    CHR Extension: (Gmail) - C:\Users\Chris\AppData\Local\Google\Chrome\User Data\Profile 4\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-07-23]
    CHR HKLM\...\Chrome\Extension: [hkhkiakolggnnicallabhkobalpeplpi] - <no Path/update_url>
    CHR HKLM-x32\...\Chrome\Extension: [hglljpndoeopcpehilglkbnincooinnb] - C:\Users\Chris\AppData\Local\Flvto Plugin for Google Chrome\the_extension.crx [2013-08-30]
    CHR HKLM-x32\...\Chrome\Extension: [hkhkiakolggnnicallabhkobalpeplpi] - <no Path/update_url>

    ==================== Services (Whitelisted) ========================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    R2 Backupper Service; C:\Program Files (x86)\AOMEI Backupper Professional Edition 2.2\ABService.exe [29912 2014-12-24] (AOMEI Tech Co., Ltd.)
    S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [49152 2013-09-22] () [File not signed]
    R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2802360 2015-11-24] (Microsoft Corporation)
    S3 GalaxyClientService; C:\Program Files (x86)\GalaxyClient\GalaxyClientService.exe [1718840 2015-07-17] (GOG.com)
    S3 GalaxyCommunication; C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe [6677048 2015-07-02] (GOG.com)
    R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1156384 2015-10-11] (NVIDIA Corporation)
    R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [24888 2015-07-26] (Hewlett-Packard Company)
    S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [887232 2014-01-31] (Intel(R) Corporation)
    R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [154584 2014-02-19] (Intel Corporation)
    R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1513784 2015-10-05] (Malwarebytes)
    R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
    S3 MSIBIOSData_CC; C:\Program Files (x86)\MSI\Command Center\BIOSData\MSIBIOSDataService.exe [2101248 2014-03-24] (MSI) [File not signed]
    S3 MSIClock_CC; C:\Program Files (x86)\MSI\Command Center\ClockGen\MSIClockService.exe [313856 2014-03-26] () [File not signed]
    S3 MSICOMM_CC; C:\Program Files (x86)\MSI\Command Center\MSICommService.exe [2117120 2014-03-24] () [File not signed]
    R3 MSICPU_CC; C:\Program Files (x86)\MSI\Command Center\CPU\MSICPUService.exe [4115456 2014-03-31] () [File not signed]
    R2 MSICTL_CC; C:\Program Files (x86)\MSI\Command Center\MSIControlService.exe [1990144 2014-04-02] () [File not signed]
    S3 MSIDDR_CC; C:\Program Files (x86)\MSI\Command Center\DDR\MSIDDRService.exe [2235904 2014-03-26] () [File not signed]
    S3 MSISaveLoad_CC; C:\Program Files (x86)\MSI\Command Center\MSISaveLoadService.exe [3957760 2014-03-24] () [File not signed]
    S3 MSISMB_CC; C:\Program Files (x86)\MSI\Command Center\SMBus\MSISMBService.exe [183808 2014-03-26] () [File not signed]
    S3 MSISuperIO_CC; C:\Program Files (x86)\MSI\Command Center\SuperIO\MSISuperIOService.exe [540672 2014-03-24] () [File not signed]
    S3 MSIWMI_CC; C:\Program Files (x86)\MSI\Command Center\MSIWMIService.exe [183296 2014-03-24] () [File not signed]
    R2 MSI_FastBoot; C:\Program Files (x86)\MSI\Fast Boot\FastBootService.exe [103992 2012-10-26] (MSI)
    R2 MSI_LiveUpdate_Service; C:\Program Files (x86)\MSI\Live Update\MSI_LiveUpdate_Service.exe [83952 2014-03-27] (Micro-Star International)
    R2 MSI_SuperCharger; C:\Program Files (x86)\MSI\Super Charger\ChargeService.exe [162800 2014-03-17] (MSI)
    R2 MSI_Trigger_Service; C:\Program Files (x86)\MSI\MSITrigger\MSI_Trigger_Service.exe [30240 2013-09-26] (MICRO-STAR INTERNATIONAL CO., LTD.)
    R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1873696 2015-10-11] (NVIDIA Corporation)
    R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [5568288 2015-10-11] (NVIDIA Corporation)
    S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2078216 2015-10-08] (Electronic Arts)
    R2 Qualcomm Atheros Killer Service V2; C:\Program Files\Qualcomm Atheros\Network Manager\KillerService.exe [344576 2014-04-17] (Qualcomm Atheros) [File not signed]
    R2 Razer Game Scanner Service; C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe [187048 2015-06-23] ()
    R2 Realtek11nSU; C:\Program Files (x86)\REALTEK\11n USB Wireless LAN Utility\RtlService.exe [45056 2010-01-21] (Realtek) [File not signed]
    R2 RzKLService; C:\Program Files (x86)\Razer\Razer Cortex\RzKLService.exe [129168 2015-07-14] (Razer Inc.)
    R2 SuperRAIDSvc; C:\MSI\Smart Utilities\SuperRAIDSvc.exe [24048 2014-04-03] ()
    R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2015-10-30] (Microsoft Corporation)
    R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-10-30] (Microsoft Corporation)
    R2 WSWNDA3100v2; C:\Program Files (x86)\NETGEAR\WNDA3100v2\WifiSvc.exe [303360 2011-12-14] ()

    ===================== Drivers (Whitelisted) ==========================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    R0 ambakdrv; C:\Windows\System32\ambakdrv.sys [30648 2013-05-07] () [File not signed]
    R2 ammntdrv; C:\WINDOWS\system32\ammntdrv.sys [151480 2013-05-07] () [File not signed]
    R2 amwrtdrv; C:\WINDOWS\system32\amwrtdrv.sys [17848 2013-02-06] () [File not signed]
    R1 AntiLog32; C:\Windows\system32\drivers\AntiLog64.sys [49240 2013-10-24] (Zemana Ltd.)
    R1 BfLwf; C:\Windows\system32\DRIVERS\bwcW8x64.sys [82608 2014-04-10] (Qualcomm Atheros, Inc.)
    R2 iocbios2; C:\Program Files (x86)\Intel\Extreme Tuning Utility\Drivers\IocDriver\64bit\iocbios2.sys [28912 2014-02-18] (Intel Corporation)
    R3 ISCT; C:\Windows\System32\drivers\ISCTD.sys [44744 2014-05-27] ()
    R3 Ke2200; C:\Windows\System32\drivers\e22w8x64.sys [130224 2014-03-27] (Qualcomm Atheros, Inc.)
    R3 keycrypt; C:\Windows\System32\DRIVERS\KeyCrypt64.sys [25056 2013-07-24] (Zemana Ltd.)
    R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2015-10-05] (Malwarebytes)
    R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [192216 2016-01-13] (Malwarebytes)
    R3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2015-10-05] (Malwarebytes Corporation)
    R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [129312 2014-09-30] (Intel Corporation)
    R1 MpKsl67098b0a; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{E75C8A67-A636-44D1-A9F1-A1CFA41C74EE}\MpKsl67098b0a.sys [44928 2016-01-13] (Microsoft Corporation)
    S3 NPF; C:\Windows\system32\DRIVERS\npf.sys [47632 2010-02-03] (CACE Technologies, Inc.)
    R3 NTIOLib_1_0_3; C:\Program Files (x86)\MSI\Super Charger\NTIOLib_X64.sys [13368 2012-10-25] (MSI)
    S3 NTIOLib_1_0_4; C:\Program Files (x86)\MSI\Live Update\NTIOLib_X64.sys [14136 2010-10-22] (MSI)
    R3 NTIOLib_FastBoot; C:\Program Files (x86)\MSI\Fast Boot\NTIOLib_X64.sys [13368 2012-10-26] (MSI)
    S3 NTIOLib_MSIClock_CC; C:\Program Files (x86)\MSI\Command Center\ClockGen\NTIOLib_X64.sys [13368 2012-11-20] (MSI)
    S3 NTIOLib_MSICOMM_CC; C:\Program Files (x86)\MSI\Command Center\NTIOLib_X64.sys [13368 2012-11-19] (MSI)
    R3 NTIOLib_MSICPU_CC; C:\Program Files (x86)\MSI\Command Center\CPU\NTIOLib_X64.sys [13368 2012-11-20] (MSI)
    S3 NTIOLib_MSIDDR_CC; C:\Program Files (x86)\MSI\Command Center\DDR\NTIOLib_X64.sys [13368 2012-11-26] (MSI)
    S3 NTIOLib_MSIFrequency_CC; C:\Program Files (x86)\MSI\Command Center\ClockGen\CPU_Frequency\NTIOLib_X64.sys [13368 2012-11-20] (MSI)
    R3 NTIOLib_MSIRatio_CC; C:\Program Files (x86)\MSI\Command Center\CPU\CPU_Ratio\NTIOLib_X64.sys [13368 2012-11-20] (MSI)
    S3 NTIOLib_MSISMB_CC; C:\Program Files (x86)\MSI\Command Center\SMBus\NTIOLib_X64.sys [13368 2012-11-19] (MSI)
    S3 NTIOLib_MSISuperIO_CC; C:\Program Files (x86)\MSI\Command Center\SuperIO\NTIOLib_X64.sys [13368 2012-11-19] (MSI)
    R3 NTIOLib_MSI_RAID; C:\MSI\Smart Utilities\NTIOLib_X64.sys [13808 2014-03-17] (MSI)
    R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [20768 2015-10-11] (NVIDIA Corporation)
    R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [50472 2015-08-10] (NVIDIA Corporation)
    S3 RZMAELSTROMVADService; C:\Windows\system32\drivers\RzMaelstromVAD.sys [32768 2014-05-23] (Windows (R) Win 7 DDK provider)
    R2 rzpmgrk; C:\WINDOWS\system32\drivers\rzpmgrk.sys [37184 2015-06-12] (Razer, Inc.)
    U3 TrueSight; C:\Windows\System32\drivers\TrueSight.sys [30848 2016-01-12] ()
    S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation)
    R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation)
    R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation)
    R3 XtuAcpiDriver; C:\Windows\System32\drivers\XtuAcpiDriver.sys [63840 2015-06-06] (Intel Corporation)

    ==================== NetSvcs (Whitelisted) ===================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


    ==================== One Month Created files and folders ========

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2016-01-13 22:12 - 2016-01-13 22:13 - 00033631 _____ C:\Users\Chris\Downloads\FRST.txt
    2016-01-12 21:41 - 2016-01-12 21:41 - 00000858 _____ C:\Users\Chris\Desktop\JRT.txt
    2016-01-12 21:38 - 2016-01-12 21:39 - 01600184 _____ (Malwarebytes) C:\Users\Chris\Downloads\JRT.exe
    2016-01-12 21:18 - 2016-01-12 21:26 - 00000000 ____D C:\AdwCleaner
    2016-01-12 21:16 - 2016-01-12 21:18 - 01754112 _____ C:\Users\Chris\Downloads\adwcleaner_5.029.exe
    2016-01-12 21:15 - 2016-01-12 21:15 - 00011102 _____ C:\Users\Chris\Desktop\first MAMB scan.txt
    2016-01-12 21:08 - 2016-01-12 21:11 - 20844104 _____ C:\Users\Chris\Downloads\RogueKiller (1).exe
    2016-01-12 21:07 - 2016-01-12 21:07 - 00000000 ___HD C:\OneDriveTemp
    2016-01-12 20:38 - 2016-01-13 22:04 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
    2016-01-12 20:37 - 2016-01-12 21:08 - 00001165 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
    2016-01-12 20:36 - 2016-01-12 20:37 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
    2016-01-12 20:36 - 2016-01-12 20:36 - 22908888 _____ (Malwarebytes ) C:\Users\Chris\Downloads\mbam-setup-2.2.0.1024.exe
    2016-01-12 20:36 - 2016-01-12 20:36 - 00000000 ____D C:\ProgramData\Malwarebytes
    2016-01-12 20:36 - 2015-10-05 09:50 - 00109272 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
    2016-01-12 20:36 - 2015-10-05 09:50 - 00064216 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
    2016-01-12 20:36 - 2015-10-05 09:50 - 00025816 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
    2016-01-12 20:30 - 2016-01-12 20:30 - 00239682 _____ C:\Users\Chris\Desktop\report.txt
    2016-01-12 19:48 - 2016-01-12 21:08 - 00030848 _____ C:\WINDOWS\system32\Drivers\TrueSight.sys
    2016-01-12 19:48 - 2016-01-12 19:48 - 00000000 ____D C:\ProgramData\RogueKiller
    2016-01-12 19:22 - 2016-01-12 19:48 - 20844104 _____ C:\Users\Chris\Downloads\RogueKiller.exe
    2016-01-12 18:15 - 2016-01-04 21:51 - 07477600 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
    2016-01-12 18:15 - 2016-01-04 21:51 - 01317640 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
    2016-01-12 18:15 - 2016-01-04 21:51 - 01141496 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
    2016-01-12 18:15 - 2016-01-04 21:50 - 01173344 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
    2016-01-12 18:15 - 2016-01-04 21:50 - 00713568 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
    2016-01-12 18:15 - 2016-01-04 21:50 - 00671472 _____ (Microsoft Corporation) C:\WINDOWS\system32\advapi32.dll
    2016-01-12 18:15 - 2016-01-04 21:49 - 00513888 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
    2016-01-12 18:15 - 2016-01-04 21:48 - 00499432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\advapi32.dll
    2016-01-12 18:15 - 2016-01-04 21:45 - 02587696 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6.dll
    2016-01-12 18:15 - 2016-01-04 21:42 - 02026736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml6.dll
    2016-01-12 18:15 - 2016-01-04 21:37 - 02544256 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
    2016-01-12 18:15 - 2016-01-04 21:37 - 01299504 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfnetsrc.dll
    2016-01-12 18:15 - 2016-01-04 21:37 - 00858952 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfnetcore.dll
    2016-01-12 18:15 - 2016-01-04 21:37 - 00848160 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
    2016-01-12 18:15 - 2016-01-04 21:37 - 00785088 _____ (Microsoft Corporation) C:\WINDOWS\system32\evr.dll
    2016-01-12 18:15 - 2016-01-04 21:37 - 00245840 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
    2016-01-12 18:15 - 2016-01-04 21:37 - 00234504 _____ (Microsoft Corporation) C:\WINDOWS\system32\mftranscode.dll
    2016-01-12 18:15 - 2016-01-04 21:36 - 00808800 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe
    2016-01-12 18:15 - 2016-01-04 21:33 - 02180128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
    2016-01-12 18:15 - 2016-01-04 21:33 - 01118208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfnetsrc.dll
    2016-01-12 18:15 - 2016-01-04 21:33 - 00709688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll
    2016-01-12 18:15 - 2016-01-04 21:33 - 00701384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfnetcore.dll
    2016-01-12 18:15 - 2016-01-04 21:33 - 00652312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\evr.dll
    2016-01-12 18:15 - 2016-01-04 21:33 - 00208176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mftranscode.dll
    2016-01-12 18:15 - 2016-01-04 21:33 - 00116728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfps.dll
    2016-01-12 18:15 - 2016-01-04 21:31 - 00703840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe
    2016-01-12 18:15 - 2016-01-04 21:27 - 01594408 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32.dll
    2016-01-12 18:15 - 2016-01-04 21:24 - 00796352 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
    2016-01-12 18:15 - 2016-01-04 21:23 - 01804664 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMALFXGFXDSP.dll
    2016-01-12 18:15 - 2016-01-04 21:23 - 01309376 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
    2016-01-12 18:15 - 2016-01-04 21:23 - 00786696 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMADMOD.DLL
    2016-01-12 18:15 - 2016-01-04 21:23 - 00119320 _____ (Microsoft Corporation) C:\WINDOWS\system32\MP3DMOD.DLL
    2016-01-12 18:15 - 2016-01-04 21:21 - 01371792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32.dll
    2016-01-12 18:15 - 2016-01-04 21:17 - 00695752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMADMOD.DLL
    2016-01-12 18:15 - 2016-01-04 21:16 - 00100160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MP3DMOD.DLL
    2016-01-12 18:15 - 2016-01-04 20:59 - 22393856 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
    2016-01-12 18:15 - 2016-01-04 20:57 - 16986112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
    2016-01-12 18:15 - 2016-01-04 20:57 - 00076288 _____ (Microsoft Corporation) C:\WINDOWS\system32\RMSRoamingSecurity.dll
    2016-01-12 18:15 - 2016-01-04 20:57 - 00043520 _____ (Microsoft Corporation) C:\WINDOWS\system32\usermgrcli.dll
    2016-01-12 18:15 - 2016-01-04 20:56 - 00145920 _____ (Microsoft Corporation) C:\WINDOWS\system32\omadmclient.exe
    2016-01-12 18:15 - 2016-01-04 20:54 - 00162816 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCensus.exe
    2016-01-12 18:15 - 2016-01-04 20:53 - 00148992 _____ (Microsoft Corporation) C:\WINDOWS\system32\wshom.ocx
    2016-01-12 18:15 - 2016-01-04 20:52 - 00210432 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll
    2016-01-12 18:15 - 2016-01-04 20:51 - 00472576 _____ (Microsoft Corporation) C:\WINDOWS\system32\DscCore.dll
    2016-01-12 18:15 - 2016-01-04 20:51 - 00248832 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserMgrProxy.dll
    2016-01-12 18:15 - 2016-01-04 20:50 - 00644096 _____ (Microsoft Corporation) C:\WINDOWS\system32\uReFS.dll
    2016-01-12 18:15 - 2016-01-04 20:50 - 00638464 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
    2016-01-12 18:15 - 2016-01-04 20:50 - 00208896 _____ (Microsoft Corporation) C:\WINDOWS\system32\storewuauth.dll
    2016-01-12 18:15 - 2016-01-04 20:49 - 13018624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
    2016-01-12 18:15 - 2016-01-04 20:49 - 01582080 _____ (Microsoft Corporation) C:\WINDOWS\system32\aitstatic.exe
    2016-01-12 18:15 - 2016-01-04 20:49 - 01255936 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMSPDMOE.DLL
    2016-01-12 18:15 - 2016-01-04 20:49 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
    2016-01-12 18:15 - 2016-01-04 20:49 - 00749056 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneService.dll
    2016-01-12 18:15 - 2016-01-04 20:49 - 00167936 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProximityCommon.dll
    2016-01-12 18:15 - 2016-01-04 20:48 - 01009152 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMSPDMOD.DLL
    2016-01-12 18:15 - 2016-01-04 20:48 - 00387072 _____ (Microsoft Corporation) C:\WINDOWS\system32\qdvd.dll
    2016-01-12 18:15 - 2016-01-04 20:48 - 00034816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\usermgrcli.dll
    2016-01-12 18:15 - 2016-01-04 20:47 - 00628736 _____ (Microsoft Corporation) C:\WINDOWS\system32\MessagingDataModel2.dll
    2016-01-12 18:15 - 2016-01-04 20:47 - 00479232 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll
    2016-01-12 18:15 - 2016-01-04 20:47 - 00305664 _____ (Microsoft Corporation) C:\WINDOWS\system32\ksproxy.ax
    2016-01-12 18:15 - 2016-01-04 20:45 - 00678912 _____ (Microsoft Corporation) C:\WINDOWS\system32\qedit.dll
    2016-01-12 18:15 - 2016-01-04 20:45 - 00275968 _____ (Microsoft Corporation) C:\WINDOWS\system32\facecredentialprovider.dll
    2016-01-12 18:15 - 2016-01-04 20:44 - 00125440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wshom.ocx
    2016-01-12 18:15 - 2016-01-04 20:43 - 00912384 _____ (Microsoft Corporation) C:\WINDOWS\system32\usermgr.dll
    2016-01-12 18:15 - 2016-01-04 20:43 - 00604672 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
    2016-01-12 18:15 - 2016-01-04 20:43 - 00584704 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
    2016-01-12 18:15 - 2016-01-04 20:42 - 00166912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserMgrProxy.dll
    2016-01-12 18:15 - 2016-01-04 20:41 - 18677760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
    2016-01-12 18:15 - 2016-01-04 20:41 - 01070080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMSPDMOE.DLL
    2016-01-12 18:15 - 2016-01-04 20:41 - 00558592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\uReFS.dll
    2016-01-12 18:15 - 2016-01-04 20:40 - 00890880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMSPDMOD.DLL
    2016-01-12 18:15 - 2016-01-04 20:40 - 00123392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ProximityCommon.dll
    2016-01-12 18:15 - 2016-01-04 20:39 - 03428864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
    2016-01-12 18:15 - 2016-01-04 20:39 - 00569856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\qdvd.dll
    2016-01-12 18:15 - 2016-01-04 20:39 - 00498176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MessagingDataModel2.dll
    2016-01-12 18:15 - 2016-01-04 20:39 - 00235008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ksproxy.ax
    2016-01-12 18:15 - 2016-01-04 20:38 - 00389120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schannel.dll
    2016-01-12 18:15 - 2016-01-04 20:36 - 00573440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\qedit.dll
    2016-01-12 18:15 - 2016-01-04 20:36 - 00503296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
    2016-01-12 18:15 - 2016-01-04 20:33 - 01674240 _____ (Microsoft Corporation) C:\WINDOWS\system32\quartz.dll
    2016-01-12 18:15 - 2016-01-04 20:30 - 02796032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
    2016-01-12 18:15 - 2016-01-04 20:30 - 02280448 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
    2016-01-12 18:15 - 2016-01-04 20:29 - 03667456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
    2016-01-12 18:15 - 2016-01-04 20:28 - 07826432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
    2016-01-12 18:15 - 2016-01-04 20:28 - 04894720 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
    2016-01-12 18:15 - 2016-01-04 20:28 - 01542656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\quartz.dll
    2016-01-12 18:15 - 2016-01-04 20:25 - 05660160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
    2016-01-11 18:36 - 2016-01-11 18:41 - 100271992 _____ (Microsoft Corporation) C:\Users\Chris\Downloads\directx_Jun2010_redist.exe
    2016-01-10 19:02 - 2016-01-10 19:03 - 00080391 _____ C:\Users\Chris\Desktop\Addition.txt
    2016-01-10 19:00 - 2016-01-13 22:12 - 00000000 ____D C:\FRST
    2016-01-10 19:00 - 2016-01-10 19:03 - 00102589 _____ C:\Users\Chris\Desktop\FRST.txt
    2016-01-10 18:59 - 2016-01-10 19:00 - 02370560 _____ (Farbar) C:\Users\Chris\Downloads\FRST64.exe
    2016-01-10 18:53 - 2016-01-12 21:08 - 00001118 _____ C:\Users\Public\Desktop\GOG Galaxy.lnk
    2016-01-10 18:51 - 2016-01-10 18:53 - 72416536 _____ (GOG.com ) C:\Users\Chris\Downloads\setup_galaxy_1.0.6.31.0 (1).exe
    2016-01-10 18:44 - 2016-01-10 18:46 - 104417712 _____ (GOG.com ) C:\Users\Chris\Downloads\setup_galaxy_1.1.5.28.exe
    2016-01-02 13:41 - 2016-01-02 13:41 - 00000000 ____D C:\Users\Chris\Documents\KoeiTecmo
    2015-12-29 04:24 - 2015-12-29 04:24 - 09479872 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerInstaller.exe
    2015-12-28 18:43 - 2015-12-28 18:44 - 00000000 ____D C:\c88103d685bb1b7a0d
    2015-12-20 17:54 - 2016-01-11 18:42 - 00000000 ____D C:\Users\Chris\Desktop\power point template
    2015-12-20 17:53 - 2015-12-20 17:53 - 00203278 _____ C:\Users\Chris\Downloads\2218_chemical_experiment.zip
    2015-12-18 22:25 - 2015-12-31 19:06 - 00000000 ____D C:\Users\Chris\Desktop\music folder for CD
    2015-12-17 18:11 - 2015-12-06 23:57 - 00973664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll
    2015-12-17 18:11 - 2015-12-06 23:55 - 01281376 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll
     
  17. Chris Waters

    Chris Waters TS Rookie Topic Starter Posts: 23

    2015-12-17 18:11 - 2015-12-06 23:49 - 00412512 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifitask.exe
    2015-12-17 18:11 - 2015-12-06 23:48 - 01155944 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfasfsrcsnk.dll
    2015-12-17 18:11 - 2015-12-06 23:48 - 01092456 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll
    2015-12-17 18:11 - 2015-12-06 23:48 - 01065080 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll
    2015-12-17 18:11 - 2015-12-06 23:48 - 01020096 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsrcsnk.dll
    2015-12-17 18:11 - 2015-12-06 23:48 - 00983464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfasfsrcsnk.dll
    2015-12-17 18:11 - 2015-12-06 23:48 - 00884256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll
    2015-12-17 18:11 - 2015-12-06 23:48 - 00823264 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll
    2015-12-17 18:11 - 2015-12-06 23:48 - 00794888 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfds.dll
    2015-12-17 18:11 - 2015-12-06 23:48 - 00696160 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupEngine.dll
    2015-12-17 18:11 - 2015-12-06 23:48 - 00670928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfds.dll
    2015-12-17 18:11 - 2015-12-06 23:48 - 00526856 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfreadwrite.dll
    2015-12-17 18:11 - 2015-12-06 23:48 - 00502112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupEngine.dll
    2015-12-17 18:11 - 2015-12-06 23:48 - 00498448 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFCaptureEngine.dll
    2015-12-17 18:11 - 2015-12-06 23:48 - 00462760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfreadwrite.dll
    2015-12-17 18:11 - 2015-12-06 23:48 - 00450904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFCaptureEngine.dll
    2015-12-17 18:11 - 2015-12-06 23:48 - 00337840 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFPlay.dll
    2015-12-17 18:11 - 2015-12-06 23:48 - 00289248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFPlay.dll
    2015-12-17 18:11 - 2015-12-06 23:48 - 00115040 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupApi.dll
    2015-12-17 18:11 - 2015-12-06 23:48 - 00084832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupApi.dll
    2015-12-17 18:11 - 2015-12-06 23:47 - 00925064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll
    2015-12-17 18:11 - 2015-12-06 23:47 - 00898184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsrcsnk.dll
    2015-12-17 18:11 - 2015-12-06 23:47 - 00716928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll
    2015-12-17 18:11 - 2015-12-06 23:46 - 03671888 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
    2015-12-17 18:11 - 2015-12-06 23:46 - 02919320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
    2015-12-17 18:11 - 2015-12-06 23:45 - 00264544 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContentDeliveryManager.Utilities.dll
    2015-12-17 18:11 - 2015-12-06 23:15 - 01035776 _____ (Microsoft Corporation) C:\WINDOWS\system32\XboxNetApiSvc.dll
    2015-12-17 18:11 - 2015-12-06 23:15 - 00075776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.XboxLive.ProxyStub.dll
    2015-12-17 18:11 - 2015-12-06 23:10 - 00824320 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcWebFilter.dll
    2015-12-17 18:11 - 2015-12-06 23:09 - 00133120 _____ (Microsoft Corporation) C:\WINDOWS\system32\flvprophandler.dll
    2015-12-17 18:11 - 2015-12-06 23:09 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanagerprecheck.dll
    2015-12-17 18:11 - 2015-12-06 23:09 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorageUsage.dll
    2015-12-17 18:11 - 2015-12-06 23:07 - 00134656 _____ (Microsoft Corporation) C:\WINDOWS\system32\wificonnapi.dll
    2015-12-17 18:11 - 2015-12-06 23:07 - 00077312 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProvPluginEng.dll
    2015-12-17 18:11 - 2015-12-06 23:06 - 00572928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WpcWebFilter.dll
    2015-12-17 18:11 - 2015-12-06 23:06 - 00231936 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCore.dll
    2015-12-17 18:11 - 2015-12-06 23:06 - 00199168 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe
    2015-12-17 18:11 - 2015-12-06 23:05 - 00192000 _____ (Microsoft Corporation) C:\WINDOWS\system32\provisioningcsp.dll
    2015-12-17 18:11 - 2015-12-06 23:05 - 00036864 _____ (Microsoft Corporation) C:\WINDOWS\system32\BackgroundTransferHost.exe
    2015-12-17 18:11 - 2015-12-06 23:04 - 00066560 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshost.dll
    2015-12-17 18:11 - 2015-12-06 23:04 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\system32\provtool.exe
    2015-12-17 18:11 - 2015-12-06 23:02 - 00269824 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshostcore.dll
    2015-12-17 18:11 - 2015-12-06 23:02 - 00161280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgent.exe
    2015-12-17 18:11 - 2015-12-06 23:01 - 00543232 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll
    2015-12-17 18:11 - 2015-12-06 23:01 - 00034304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BackgroundTransferHost.exe
    2015-12-17 18:11 - 2015-12-06 23:00 - 00618496 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll
    2015-12-17 18:11 - 2015-12-06 23:00 - 00323072 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSFlacDecoder.dll
    2015-12-17 18:11 - 2015-12-06 23:00 - 00210432 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmcsp.dll
    2015-12-17 18:11 - 2015-12-06 23:00 - 00203776 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupSvc.dll
    2015-12-17 18:11 - 2015-12-06 22:59 - 00558080 _____ (Microsoft Corporation) C:\WINDOWS\system32\MBMediaManager.dll
    2015-12-17 18:11 - 2015-12-06 22:59 - 00292352 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll
    2015-12-17 18:11 - 2015-12-06 22:59 - 00286208 _____ (Microsoft Corporation) C:\WINDOWS\system32\provhandlers.dll
    2015-12-17 18:11 - 2015-12-06 22:59 - 00165376 _____ (Microsoft Corporation) C:\WINDOWS\system32\provdatastore.dll
    2015-12-17 18:11 - 2015-12-06 22:58 - 24601600 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
    2015-12-17 18:11 - 2015-12-06 22:58 - 00459776 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapConfiguration.dll
    2015-12-17 18:11 - 2015-12-06 22:57 - 00409088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StoreAgent.dll
    2015-12-17 18:11 - 2015-12-06 22:57 - 00270848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSFlacDecoder.dll
    2015-12-17 18:11 - 2015-12-06 22:56 - 00607232 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmsvc.dll
    2015-12-17 18:11 - 2015-12-06 22:56 - 00497152 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmkvsrcsnk.dll
    2015-12-17 18:11 - 2015-12-06 22:55 - 07979008 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll
    2015-12-17 18:11 - 2015-12-06 22:55 - 00346112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapConfiguration.dll
    2015-12-17 18:11 - 2015-12-06 22:54 - 00850432 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll
    2015-12-17 18:11 - 2015-12-06 22:53 - 19339264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
    2015-12-17 18:11 - 2015-12-06 22:53 - 00381952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmkvsrcsnk.dll
    2015-12-17 18:11 - 2015-12-06 22:51 - 01318912 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifinetworkmanager.dll
    2015-12-17 18:11 - 2015-12-06 22:51 - 00223232 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapibase.dll
    2015-12-17 18:11 - 2015-12-06 22:50 - 01131520 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Audio.dll
    2015-12-17 18:11 - 2015-12-06 22:49 - 01105920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Audio.dll
    2015-12-17 18:11 - 2015-12-06 22:48 - 06297088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mos.dll
    2015-12-17 18:11 - 2015-12-06 22:45 - 02582016 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
    2015-12-17 18:11 - 2015-12-06 22:45 - 00900608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.BackgroundTransfer.dll
    2015-12-17 18:11 - 2015-12-06 22:45 - 00683008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.BackgroundTransfer.dll
    2015-12-17 18:11 - 2015-12-06 22:43 - 02598400 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll
    2015-12-17 18:11 - 2015-12-06 22:43 - 00931328 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSMPEG2ENC.DLL
    2015-12-17 18:11 - 2015-12-06 22:41 - 02061824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
    2015-12-17 18:11 - 2015-12-06 22:40 - 03593216 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
    2015-12-17 18:11 - 2015-12-06 22:40 - 01995776 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActiveSyncProvider.dll
    2015-12-17 18:11 - 2015-12-06 22:40 - 01706496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActiveSyncProvider.dll
    2015-12-17 18:11 - 2015-12-06 22:39 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll
    2015-12-17 18:11 - 2015-12-06 22:38 - 00871936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSMPEG2ENC.DLL
    2015-12-17 18:11 - 2015-12-06 22:33 - 00375296 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDEServer.exe
    2015-12-17 18:11 - 2015-12-06 22:32 - 00126464 _____ (Microsoft Corporation) C:\WINDOWS\system32\dialserver.dll

    ==================== One Month Modified files and folders ========

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2016-01-13 22:05 - 2015-09-05 20:23 - 00000000 ____D C:\Users\Chris\AppData\Roaming\Spotify
    2016-01-13 22:05 - 2015-09-05 20:23 - 00000000 ____D C:\Users\Chris\AppData\Local\Spotify
    2016-01-13 22:05 - 2013-06-24 20:56 - 00000000 ____D C:\ProgramData\Kodak
    2016-01-13 22:04 - 2013-12-24 15:00 - 00000000 __RDO C:\Users\Chris\SkyDrive
    2016-01-13 21:44 - 2015-10-30 02:21 - 00000000 ____D C:\WINDOWS\INF
    2016-01-13 21:44 - 2015-08-13 06:31 - 00879220 _____ C:\WINDOWS\system32\PerfStringBackup.INI
    2016-01-13 21:42 - 2015-10-30 02:24 - 00000000 ____D C:\WINDOWS\AppReadiness
    2016-01-13 21:39 - 2015-12-11 11:19 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
    2016-01-13 21:39 - 2015-12-11 10:55 - 00000000 ____D C:\ProgramData\NVIDIA
    2016-01-12 22:35 - 2014-04-14 14:07 - 00004160 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{909DD475-84FF-494B-8E45-735181543A4E}
    2016-01-12 22:24 - 2013-09-02 17:57 - 00000830 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
    2016-01-12 21:27 - 2015-10-30 01:28 - 01048576 ___SH C:\WINDOWS\system32\config\BBI
    2016-01-12 21:08 - 2015-12-11 11:07 - 00001540 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
    2016-01-12 21:08 - 2015-11-18 14:37 - 00000969 _____ C:\Users\Public\Desktop\Nexus Mod Manager.lnk
    2016-01-12 21:08 - 2015-11-10 00:06 - 00002200 _____ C:\Users\Public\Desktop\3D Vision Photo Viewer.lnk
    2016-01-12 21:08 - 2015-11-08 21:06 - 00001023 _____ C:\Users\Chris\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Optional Features.lnk
    2016-01-12 21:08 - 2015-10-16 20:24 - 00001046 _____ C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk
    2016-01-12 21:08 - 2015-09-05 20:23 - 00001898 _____ C:\Users\Chris\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spotify.lnk
    2016-01-12 21:08 - 2015-08-21 21:44 - 00002634 _____ C:\Users\Public\Desktop\Skype.lnk
    2016-01-12 21:08 - 2015-08-13 17:12 - 00002403 _____ C:\Users\Chris\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
    2016-01-12 21:08 - 2015-08-10 01:15 - 00000931 _____ C:\Users\Public\Desktop\Playfire.lnk
    2016-01-12 21:08 - 2015-08-09 11:36 - 00001025 _____ C:\Users\Public\Desktop\ArmA3Sync.lnk
    2016-01-12 21:08 - 2015-07-23 09:37 - 00002254 _____ C:\Users\Public\Desktop\Google Chrome.lnk
    2016-01-12 21:08 - 2015-01-18 21:03 - 00001244 _____ C:\Users\Public\Desktop\AOMEI Backupper Professional Edition 2.2.lnk
    2016-01-12 21:08 - 2014-12-23 20:51 - 00002523 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
    2016-01-12 21:08 - 2014-11-17 15:14 - 00002170 _____ C:\Users\Public\Desktop\KODAK AiO Home Center.lnk
    2016-01-12 21:08 - 2014-11-17 15:13 - 00002089 _____ C:\Users\Public\Desktop\Get CleanPrint.lnk
    2016-01-12 21:08 - 2014-09-10 14:44 - 00001262 _____ C:\Users\Public\Desktop\Razer Cortex.lnk
    2016-01-12 21:08 - 2014-09-06 18:56 - 00002793 _____ C:\Users\Public\Desktop\Killer Network Manager.lnk
    2016-01-12 21:08 - 2014-06-16 14:27 - 00002071 _____ C:\Users\Public\Desktop\Google Slides.lnk
    2016-01-12 21:08 - 2014-06-16 14:27 - 00002071 _____ C:\Users\Public\Desktop\Google Sheets.lnk
    2016-01-12 21:08 - 2014-06-16 14:27 - 00002067 _____ C:\Users\Public\Desktop\Google Docs.lnk
    2016-01-12 21:08 - 2014-03-03 20:01 - 00002226 _____ C:\Users\Public\Desktop\Google Earth.lnk
    2016-01-12 21:08 - 2013-12-14 21:20 - 00001843 _____ C:\Users\Public\Desktop\OnLive.lnk
    2016-01-12 21:08 - 2013-11-11 16:28 - 00001013 _____ C:\Users\Public\Desktop\Cyberduck.lnk
    2016-01-12 21:08 - 2013-11-11 14:47 - 00001029 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinSCP.lnk
    2016-01-12 21:08 - 2013-08-19 22:04 - 00001047 _____ C:\Users\Public\Desktop\GameStop App.lnk
    2016-01-12 21:08 - 2013-07-27 19:24 - 00001162 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 8.lnk
    2016-01-12 21:08 - 2013-07-27 19:24 - 00001156 _____ C:\Users\Public\Desktop\TeamViewer 8.lnk
    2016-01-12 21:08 - 2013-07-12 21:06 - 00001444 _____ C:\Users\Public\Desktop\GeForce Experience.lnk
    2016-01-12 21:08 - 2013-07-11 21:48 - 00001851 _____ C:\Users\Public\Desktop\ooVoo.lnk
    2016-01-12 21:08 - 2013-06-24 21:02 - 00001940 _____ C:\Users\Public\Desktop\PrintProjects.lnk
    2016-01-12 21:08 - 2013-06-21 11:40 - 00002006 _____ C:\Users\Public\Desktop\FileZilla Client.lnk
    2016-01-12 21:08 - 2013-06-21 06:26 - 00002137 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Constant Guard.lnk
    2016-01-12 21:08 - 2013-06-21 06:26 - 00002131 _____ C:\Users\Public\Desktop\Constant Guard.lnk
    2016-01-12 21:08 - 2013-06-20 20:37 - 00000911 _____ C:\Users\Public\Desktop\Steam.lnk
    2016-01-12 21:07 - 2015-09-05 20:23 - 00001892 _____ C:\Users\Chris\Desktop\Spotify.lnk
    2016-01-12 21:07 - 2015-08-20 17:27 - 00001369 _____ C:\Users\Chris\Desktop\Norton Installation Files.lnk
    2016-01-12 21:07 - 2015-07-22 22:20 - 00001102 _____ C:\Users\Chris\Desktop\MEGAsync.lnk
    2016-01-12 21:07 - 2014-08-24 22:12 - 00001998 _____ C:\Users\Chris\Desktop\Dashlane.lnk
    2016-01-12 21:07 - 2014-05-15 13:40 - 00001563 _____ C:\Users\Chris\Desktop\Warband Battle Sizer.lnk
    2016-01-12 21:07 - 2014-04-26 21:34 - 00001871 _____ C:\Users\Chris\Desktop\IronLauncher - Shortcut.lnk
    2016-01-12 21:07 - 2014-04-25 20:31 - 00001065 _____ C:\Users\Chris\Desktop\Notepad++.lnk
    2016-01-12 21:07 - 2014-04-24 00:26 - 00001585 _____ C:\Users\Chris\Desktop\mb_warband - Shortcut.lnk
    2016-01-12 21:07 - 2014-04-23 14:58 - 00001055 _____ C:\Users\Chris\Desktop\Mount&Blade.lnk
    2016-01-12 21:07 - 2013-12-24 13:00 - 00001274 _____ C:\Users\Chris\Desktop\Uplay.lnk
    2016-01-12 21:07 - 2013-08-09 16:17 - 00000793 _____ C:\Users\Chris\AppData\Roaming\Microsoft\Windows\Start Menu\µTorrent.lnk
    2016-01-12 21:07 - 2013-06-20 20:18 - 00001031 _____ C:\Users\Chris\AppData\Roaming\Microsoft\Windows\Start Menu\RaidCall.lnk
    2016-01-12 21:07 - 2013-06-20 20:18 - 00001007 _____ C:\Users\Chris\Desktop\RaidCall.lnk
    2016-01-12 20:59 - 2015-10-30 02:11 - 00000000 ____D C:\WINDOWS\CbsTemp
    2016-01-12 20:59 - 2014-02-17 02:15 - 00000000 ____D C:\Program Files\Microsoft Silverlight
    2016-01-12 20:59 - 2014-02-17 02:15 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
    2016-01-12 20:58 - 2015-10-30 02:24 - 00000000 ____D C:\WINDOWS\system32\appraiser
    2016-01-12 20:57 - 2013-06-20 20:37 - 00000000 ____D C:\Program Files (x86)\Steam
    2016-01-12 20:56 - 2014-02-26 16:07 - 00000000 ____D C:\Users\Chris\AppData\Local\Flvto Plugin for Google Chrome
    2016-01-12 20:55 - 2013-06-20 19:31 - 00000000 ____D C:\Users\Chris\AppData\Roaming\Skype
    2016-01-12 20:23 - 2014-04-16 20:24 - 00000000 ____D C:\Users\Chris\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Flvto Youtube Downloader
    2016-01-12 18:42 - 2015-10-30 02:24 - 00000000 ___HD C:\Program Files\WindowsApps
    2016-01-12 18:18 - 2013-09-30 16:22 - 00000000 ____D C:\ProgramData\Package Cache
    2016-01-12 18:17 - 2014-02-17 02:15 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
    2016-01-11 18:27 - 2013-06-20 19:31 - 00000000 ____D C:\ProgramData\Skype
    2016-01-10 20:31 - 2012-12-04 14:59 - 00000000 ____D C:\Users\Chris\AppData\Local\Packages
    2016-01-10 19:02 - 2015-10-30 01:28 - 00000000 ____D C:\Windows
    2016-01-10 18:53 - 2015-08-10 01:19 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GOG.com
    2016-01-10 18:53 - 2015-08-10 01:19 - 00000000 ____D C:\Program Files (x86)\GalaxyClient
    2016-01-04 23:10 - 2015-12-11 10:58 - 00000000 ____D C:\Users\Chris
    2016-01-02 20:40 - 2015-10-30 02:26 - 00826872 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
    2016-01-02 20:40 - 2015-10-30 02:26 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
    2016-01-02 13:53 - 2015-01-30 23:00 - 00013943 _____ C:\Users\Chris\Downloads\FTBLauncherLog.txt
    2016-01-02 13:53 - 2015-01-30 23:00 - 00000068 _____ C:\Users\Chris\Downloads\MinecraftLog.txt
    2016-01-01 12:36 - 2015-11-18 14:37 - 00000000 ____D C:\Program Files\Nexus Mod Manager
    2016-01-01 12:21 - 2015-07-26 11:21 - 00000000 ____D C:\Users\Chris\Downloads\FTBInfinity
    2016-01-01 12:21 - 2014-08-15 22:46 - 00000000 ____D C:\Users\Chris\AppData\Local\ftblauncher
    2015-12-30 17:15 - 2014-01-07 22:19 - 00000000 ____D C:\Users\Chris\Documents\youtubetomp3.org
    2015-12-30 15:13 - 2012-12-28 16:31 - 00000000 ____D C:\Users\Chris\Documents\Square Enix
    2015-12-29 04:24 - 2013-09-02 17:57 - 00003816 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
    2015-12-20 00:43 - 2013-11-11 17:57 - 00000000 ____D C:\Users\Chris\AppData\Roaming\TS3Client
    2015-12-19 22:00 - 2013-07-05 12:01 - 00000000 ____D C:\Users\Chris\AppData\Local\Arma 3
    2015-12-18 03:30 - 2015-10-30 02:24 - 00000000 ____D C:\WINDOWS\Provisioning
    2015-12-18 03:30 - 2015-10-30 02:24 - 00000000 ____D C:\WINDOWS\bcastdvr
    2015-12-15 20:22 - 2015-10-30 02:24 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
    2015-12-15 20:21 - 2013-06-21 20:14 - 00000000 ____D C:\Program Files\Microsoft Office 15

    ==================== Files in the root of some directories =======

    2013-07-23 11:04 - 2011-07-19 02:37 - 0003262 _____ () C:\Program Files (x86)\Falco.ico
    2013-07-23 11:04 - 2011-07-19 03:05 - 0000046 _____ () C:\Program Files (x86)\Falco.url
    2014-06-17 20:20 - 2014-07-19 00:23 - 0000090 _____ () C:\Users\Chris\AppData\Roaming\WB.CFG
    2013-11-11 14:52 - 2014-09-06 17:12 - 0000600 _____ () C:\Users\Chris\AppData\Roaming\winscp.rnd
    2013-06-24 21:05 - 2013-09-04 19:34 - 0000236 _____ () C:\Users\Chris\AppData\Local\LaunchHomeCenter.log
    2015-08-19 19:46 - 2015-11-10 00:12 - 0007602 _____ () C:\Users\Chris\AppData\Local\resmon.resmoncfg
    2015-01-24 14:36 - 2015-01-24 14:36 - 0000000 _____ () C:\Users\Chris\AppData\Local\{1C9D2A21-6106-4C53-AB79-60959E2BB4A5}

    Some files in TEMP:
    ====================
    C:\Users\Chris\AppData\Local\Temp\dllnt_dump.dll
    C:\Users\Chris\AppData\Local\Temp\jshortcut-6364520680213824196.dll
    C:\Users\Chris\AppData\Local\Temp\jshortcut-8997663281635068146.dll
    C:\Users\Chris\AppData\Local\Temp\Nexus Mod Manager-0.61.4.exe
    C:\Users\Chris\AppData\Local\Temp\sqlite3.dll


    ==================== Bamital & volsnap =================

    (There is no automatic fix for files that do not pass verification.)

    C:\WINDOWS\system32\winlogon.exe => File is digitally signed
    C:\WINDOWS\system32\wininit.exe => File is digitally signed
    C:\WINDOWS\explorer.exe => File is digitally signed
    C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
    C:\WINDOWS\system32\svchost.exe => File is digitally signed
    C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
    C:\WINDOWS\system32\services.exe => File is digitally signed
    C:\WINDOWS\system32\User32.dll => File is digitally signed
    C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
    C:\WINDOWS\system32\userinit.exe => File is digitally signed
    C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
    C:\WINDOWS\system32\rpcss.dll => File is digitally signed
    C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
    C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
    C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed


    LastRegBack: 2016-01-04 22:21

    ==================== End of FRST.txt ============================
     
  18. Chris Waters

    Chris Waters TS Rookie Topic Starter Posts: 23

    Additional scan result of Farbar Recovery Scan Tool (x64) Version:10-01-2015 01
    Ran by Chris (2016-01-13 22:13:39)
    Running from C:\Users\Chris\Downloads
    Windows 10 Home (X64) (2015-12-11 16:28:25)
    Boot Mode: Normal
    ==========================================================


    ==================== Accounts: =============================

    Administrator (S-1-5-21-905238947-2220377667-1876713056-500 - Administrator - Disabled)
    Chris (S-1-5-21-905238947-2220377667-1876713056-1001 - Administrator - Enabled) => C:\Users\Chris
    DefaultAccount (S-1-5-21-905238947-2220377667-1876713056-503 - Limited - Disabled)
    Guest (S-1-5-21-905238947-2220377667-1876713056-501 - Limited - Disabled)
    HomeGroupUser$ (S-1-5-21-905238947-2220377667-1876713056-1004 - Limited - Enabled)

    ==================== Security Center ========================

    (If an entry is included in the fixlist, it will be removed.)

    AV: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

    ==================== Installed Programs ======================

    (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

    µTorrent (HKU\S-1-5-21-905238947-2220377667-1876713056-1001\...\uTorrent) (Version: 3.4.2.32239 - BitTorrent Inc.)
    7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov)
    Adobe Flash Player 20 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 20.0.0.267 - Adobe Systems Incorporated)
    aioprnt (Version: 5.3.1.0 - Eastman Kodak Company) Hidden
    aioscnnr (x32 Version: 5.8.10.0 - Your Company Name) Hidden
    aioscnnr (x32 Version: 7.6.13.10 - Your Company Name) Hidden
    AntiLogger SDK version 1.6.6.247 (HKLM-x32\...\{4D46DE30-49FE-4043-99F7-D7E8C06175E0}_is1) (Version: 1.6.6.247 - Zemana Ltd.)
    AOMEI Backupper Professional Edition 2.2 (HKLM-x32\...\{A83692F5-3E9B-4E95-9E7E-B5DF55E6C09D}_is1) (Version: - AOMEI Technology Co., Ltd.)
    Apple Application Support (HKLM-x32\...\{83CAF0DE-8D3B-4C37-A631-2B8F16EC3031}) (Version: 3.1 - Apple Inc.)
    Apple Mobile Device Support (HKLM\...\{BDD99690-3541-4619-9D2A-3CDDB3E15F9E}) (Version: 8.0.5.6 - Apple Inc.)
    Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
    Application Compatibility Toolkit (Version: 8.100.26641 - Microsoft) Hidden
    Arma 3 (HKLM-x32\...\Steam App 107410) (Version: - Bohemia Interactive)
    ARMA 3 Launcher By Head (HKLM-x32\...\ARMA 3 Launcher By Head) (Version: 1.0.0.0 - Whoopshop Studios)
    ArmA3Sync 1.4.63 (HKLM-x32\...\{F097E7D7-D093-4394-9EED-43AFCCD12B7A}_is1) (Version: 1.4.63 - The [S.o.E] team)
    Assessments on Client (x32 Version: 8.100.26866 - Microsoft) Hidden
    AudibleManager (HKLM-x32\...\AudibleManager) (Version: 40.31391936.-1342176847.0 - Audible, Inc.)
    BattlEye for OA Uninstall (HKLM-x32\...\BattlEye for OA) (Version: - )
    C4USelfUpdater (x32 Version: 1.00.0000 - Your Company Name) Hidden
    CameraHelperMsi (x32 Version: 13.51.815.0 - Logitech) Hidden
    CCGLauncher version 0.0.0.7 (HKLM-x32\...\{78D51CE5-799C-4FCA-9635-6F61E19EA5E3}_is1) (Version: 0.0.0.7 - Custom Combat Gaming)
    center (x32 Version: 7.8.0.0 - Eastman Kodak Company) Hidden
    Command Center (HKLM-x32\...\{85A2564E-9ED9-448A-91E4-B9211EE58A08}_is1) (Version: 1.0.0.59 - MSI)
    Constant Guard Protection Suite (HKLM-x32\...\ID Vault) (Version: 1.13.820.2 - Comcast)
    Cyberduck 4.4 (13577) (HKLM-x32\...\Cyberduck) (Version: 4.4 (13577) - )
    DarthMod Empire (HKLM-x32\...\DarthMod Empire8.0 Platinum) (Version: 8.0 Platinum - )
    Dashlane (HKU\S-1-5-21-905238947-2220377667-1876713056-1001\...\Dashlane) (Version: 3.5.2.94565 - Dashlane SAS)
    DayZ Commander (HKLM-x32\...\{0170930E-68D6-4E85-88B2-82761CDE1F94}) (Version: 0.92.69 - Dotjosh Studios)
    Dual-Core Optimizer (HKLM-x32\...\{9FD6F1A8-5550-46AF-8509-271DF0E768B5}) (Version: 1.1.4.0169 - AMD)
    erLT (x32 Version: 1.20.138.34 - Logitech, Inc.) Hidden
    ESN Sonar (HKLM-x32\...\ESN Sonar-0.70.4) (Version: 0.70.4 - ESN Social Software AB)
    essentials (x32 Version: 7.8.0.0 - Eastman Kodak Company) Hidden
    EVGA Precision X 4.1.0 (HKLM-x32\...\PrecisionX) (Version: 4.1.0 - EVGA Corporation)
    f.lux (HKU\S-1-5-21-905238947-2220377667-1876713056-1001\...\Flux) (Version: - )
    Fallout 4 (HKLM-x32\...\Steam App 377160) (Version: - Bethesda Game Studios)
    Far Cry 3 (HKLM-x32\...\{E3B9C5A9-BD7A-4B56-B754-FAEA7DD6FA88}) (Version: 1.05 - Ubisoft)
    Fast Boot (HKLM-x32\...\{0F212E7A-65EB-4668-A8D7-749026A64F8E}_is1) (Version: 1.0.1.1 - MSI)
    ffdshow [rev 2527] [2008-12-19] (HKLM-x32\...\ffdshow_is1) (Version: 1.0 - )
    FileZilla Client 3.9.0.5 (HKLM-x32\...\FileZilla Client) (Version: 3.9.0.5 - Tim Kosse)
    Flvto Youtube Downloader (HKLM-x32\...\Flvto Youtube Downloader) (Version: 0.5.9 - Hotger)
    GameFly Download Manager (HKU\S-1-5-21-905238947-2220377667-1876713056-1001\...\7998bdbe8c95db7f) (Version: 1.0.0.98 - GameFly)
    GameStop App (HKLM-x32\...\GameStop App) (Version: 4.00 - GameStop)
    GameStop App (x32 Version: 4.00 - GameStop) Hidden
    GECK - New Vegas Edition (HKLM-x32\...\Steam App 22480) (Version: - )
    Ghost Recon Phantoms - EU (HKU\S-1-5-21-905238947-2220377667-1876713056-1001\...\d8be6c3f847d7d92) (Version: 1.36.1803.1 - Ubisoft)
    GOG Galaxy (HKLM-x32\...\{7258BA11-600C-430E-A759-27E2C691A335}_is1) (Version: - GOG.com)
    Google Chrome (HKLM-x32\...\Google Chrome) (Version: 47.0.2526.106 - Google Inc.)
    Google Drive (HKLM-x32\...\{1C3D2F92-D25E-4D98-B810-3F3B0857BF26}) (Version: 1.26.0707.2863 - Google, Inc.)
    Google Earth (HKLM-x32\...\{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
    Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
    Google Update Helper (x32 Version: 1.3.29.1 - Google Inc.) Hidden
    HP Support Solutions Framework (HKLM-x32\...\{F6A11738-3EE4-4573-AEA5-6CD5D491C167}) (Version: 12.0.30.81 - Hewlett-Packard Company)
    Intel(R) Chipset Device Software (x32 Version: 10.0.20 - Intel(R) Corporation) Hidden
    Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 10.0.0.1168 - Intel Corporation)
    Intel(R) Smart Connect Technology (HKLM\...\{08B90A20-95D3-4725-84B9-AF6553E06C4F}) (Version: 5.0.10.2850 - Intel Corporation)
    Intel® Watchdog Timer Driver (Intel® WDT) (HKLM-x32\...\{3FD0C489-0F02-481a-A3E1-9754CD396761}) (Version: - Intel Corporation)
    Intel® Watchdog Timer Driver (Intel® WDT) (HKLM-x32\...\3FD0C489-0F02-481a-A3E1-9754CD396761) (Version: - Intel Corporation)
    iTunes (HKLM\...\{2ABBBD91-91E5-4AD7-929A-FE15D1DC0576}) (Version: 12.0.1.26 - Apple Inc.)
    Java 8 Update 51 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86418051F0}) (Version: 8.0.510 - Oracle Corporation)
    Kits Configuration Installer (x32 Version: 8.100.25984 - Microsoft) Hidden
    Kodak AIO Printer (Version: 7.8.1.0 - Eastman Kodak Company) Hidden
    KODAK AiO Software (HKLM-x32\...\{E0F274B7-592B-4669-8FB8-8D9825A09858}) (Version: 7.8.5.2 - Eastman Kodak Company)
    ksDIP (x32 Version: 3.20.0000.0001 - Eastman Kodak Company) Hidden
    Live Update (HKLM-x32\...\{4F46CF54-47D2-41F4-B230-B0954C544420}}_is1) (Version: 6.0.004 - MSI)
    Logitech Webcam Software (HKLM-x32\...\{D40EB009-0499-459c-A8AF-C9C110766215}) (Version: 2.80 - Logitech Inc.)
    Mad Max (HKLM-x32\...\Steam App 234140) (Version: - Avalanche Studios)
    Malwarebytes Anti-Malware version 2.2.0.1024 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes)
    Mass Effect™ 3 (HKLM-x32\...\{534A31BD-20F4-46b0-85CE-09778379663C}) (Version: 1.05.0.0 - Electronic Arts)
    Medieval II: Total War Kingdoms (HKLM-x32\...\Steam App 4780) (Version: - The Creative Assembly)
    MEGAsync (HKLM-x32\...\MEGAsync) (Version: - Mega Limited)
    Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation)
    Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{832D9DE0-8AFC-4689-9819-4DBBDEBD3E4F}) (Version: 3.5.92.0 - Microsoft Corporation)
    Microsoft Games for Windows Marketplace (HKLM-x32\...\{4CB0307C-565E-4441-86BE-0DF2E4FB828C}) (Version: 3.5.50.0 - Microsoft Corporation)
    Microsoft Office Professional Plus 2013 - en-us (HKLM\...\ProPlusRetail - en-us) (Version: 15.0.4779.1002 - Microsoft Corporation)
    Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.41212.0 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (HKLM\...\{350AA351-21FA-3270-8B7A-835434E766AD}) (Version: 9.0.21022 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
    Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
    Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
    Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
    Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
    Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
    Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
    Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
    Mount & Blade: Warband (HKLM-x32\...\Mount & Blade: Warband) (Version: - GameStop)
    Mount & Blade: With Fire & Sword (HKLM-x32\...\Mount & Blade: With Fire & Sword) (Version: - GameStop)
    Mount&Blade Warband (HKLM-x32\...\Mount&Blade Warband) (Version: - )
    MSI Intel Extreme Tuning Utility (HKLM-x32\...\{fbd55c4e-e884-4210-a79b-5f158834b133}) (Version: 4.4.0.103 - Intel Corporation)
    MSI Intel Extreme Tuning Utility (x32 Version: 4.4.0.103 - Intel Corporation) Hidden
    MSI Super Charger (HKLM-x32\...\{7CDF10DD-A9B5-4DA3-AB95-E193248D4369}_is1) (Version: 1.2.025 - MSI)
    NETGEAR WNDA3100v2 wireless USB 2.0 adapter (HKLM-x32\...\{3C7839E7-21F4-49E0-B4D5-AC8ED818CCB0}) (Version: 1.03.000 - NETGEAR)
    Nexus Mod Manager (HKLM\...\6af12c54-643b-4752-87d0-8335503010de_is1) (Version: 0.61.4 - Black Tree Gaming)
    Notepad++ (HKLM-x32\...\Notepad++) (Version: 6.5.5 - Notepad++ Team)
    NVIDIA 3D Vision Controller Driver 352.65 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 352.65 - NVIDIA Corporation)
    NVIDIA 3D Vision Driver 358.91 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 358.91 - NVIDIA Corporation)
    NVIDIA GeForce Experience 2.5.15.54 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.5.15.54 - NVIDIA Corporation)
    NVIDIA Graphics Driver 358.91 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 358.91 - NVIDIA Corporation)
    NVIDIA HD Audio Driver 1.3.34.4 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.4 - NVIDIA Corporation)
    NVIDIA Miracast Virtual Audio 353.30 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Miracast.VirtualAudio) (Version: 353.30 - NVIDIA Corporation)
    NVIDIA PhysX System Software 9.15.0428 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.15.0428 - NVIDIA Corporation)
    ocr (x32 Version: 6.2.3.50 - Eastman Kodak Company) Hidden
    Office 15 Click-to-Run Extensibility Component (x32 Version: 15.0.4779.1002 - Microsoft Corporation) Hidden
    Office 15 Click-to-Run Licensing Component (Version: 15.0.4779.1002 - Microsoft Corporation) Hidden
    Office 15 Click-to-Run Localization Component (x32 Version: 15.0.4779.1002 - Microsoft Corporation) Hidden
    OnLive (HKLM-x32\...\OnLive) (Version: - OnLive)
    ooVoo (HKLM-x32\...\{FAA7F8FF-3C05-4A61-8F14-D8A6E9ED6623}) (Version: 3.5.9041 - ooVoo LLC.)
    OpenAL (HKLM-x32\...\OpenAL) (Version: - )
    Origin (HKLM-x32\...\Origin) (Version: 9.2.1.4399 - Electronic Arts, Inc.)
    Playfire (HKLM-x32\...\{6b69b0a4-05aa-4ee8-a108-0ebb857ecba4}) (Version: 0.0.72.0 - Playfire)
    Playfire (x32 Version: 0.0.72.0 - Playfire) Hidden
    PowerISO (HKLM-x32\...\PowerISO) (Version: 5.7 - Power Software Ltd)
    PreReq (x32 Version: 6.2.4.0 - Eastman Kodak Company) Hidden
    PrintProjects (HKLM-x32\...\PrintProjects) (Version: 1.0.0.9282 - RocketLife Inc.)
    PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.993 - Even Balance, Inc.)
    Qualcomm Atheros Bandwidth Control Filter Driver (Version: 1.1.42.1045 - Qualcomm Atheros) Hidden
    Qualcomm Atheros Killer E220x Drivers (Version: 1.1.42.1045 - Qualcomm Atheros) Hidden
    Qualcomm Atheros Killer Network Manager Suite (HKLM-x32\...\{E70DB50B-10B4-46BC-9DE2-AB8B49E061EE}) (Version: 1.1.42.1045 - Qualcomm Atheros)
    Qualcomm Atheros Network Manager (Version: 1.1.42.1045 - Qualcomm Atheros) Hidden
    QuickTime 7 (HKLM-x32\...\{111EE7DF-FC45-40C7-98A7-753AC46B12FB}) (Version: 7.75.80.95 - Apple Inc.)
    RaidCall (HKLM-x32\...\RaidCall) (Version: 7.2.4-1.0.7299.14 - raidcall.com)
    Rainbow Six Siege - Closed Beta (HKLM-x32\...\Uplay Install 1001) (Version: - Ubisoft)
    Razer Cortex (HKLM-x32\...\Razer Cortex_is1) (Version: 6.0.29.0 - Razer Inc.)
    Razer Synapse 2.0 (HKLM-x32\...\{0D78BEE2-F8FF-4498-AF1A-3FF81CED8AC6}) (Version: 1.18.13 - Razer Inc.)
    Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7535 - Realtek Semiconductor Corp.)
    REALTEK Wireless LAN Driver and Utility (HKLM-x32\...\{9C049499-055C-4a0c-A916-1D8CA1FF45EB}) (Version: 1.00.0150 - REALTEK Semiconductor Corp.)
    resident evil 4 / biohazard 4 (HKLM-x32\...\Steam App 254700) (Version: - Capcom)
    Rockstar Games Social Club (HKLM-x32\...\Rockstar Games Social Club) (Version: 1.1.0.6 - Rockstar Games)
    SHIELD Streaming (Version: 4.1.500 - NVIDIA Corporation) Hidden
    SHIELD Wireless Controller Driver (Version: 2.5.15.54 - NVIDIA Corporation) Hidden
    SimCity™ (HKLM-x32\...\{F70FDE4B-8F86-4eb6-8C8E-636EC89F6419}) (Version: 4.0.86.0859 - Electronic Arts)
    SimCity™ Limited Edition (HKLM-x32\...\SimCity™ Limited Edition) (Version: - GameStop)
    Skype™ 7.17 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.17.105 - Skype Technologies S.A.)
    Smart Utilities (HKLM-x32\...\{009E5DF2-3F97-480B-89DA-F2D5E672E14A}_is1) (Version: 2.0.0.04 - MSI)
    Sound Blaster Cinema (HKLM-x32\...\{8801CA65-921A-4CCC-9D63-879D1D0BAA97}) (Version: 1.00.05 - Creative Technology Limited)
    Spotify (HKU\S-1-5-21-905238947-2220377667-1876713056-1001\...\Spotify) (Version: 1.0.20.94.g8f8543b3 - Spotify AB)
    STAR WARS™ Battlefront™ Beta (HKLM-x32\...\{8A863B64-C9BE-4203-9ED7-92981CF690D3}) (Version: 1.0.4.9084 - Electronic Arts)
    Steam (HKLM-x32\...\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation)
    SWClient (HKU\S-1-5-21-905238947-2220377667-1876713056-1001\...\SWClient) (Version: 12 - )
    System Requirements Lab (HKLM-x32\...\{FAB9454C-6A8D-4031-9652-8B1B1D561456}) (Version: 6.0.7.0 - Husdawg, LLC)
    System Requirements Lab CYRI (HKLM-x32\...\{E362724E-9320-4946-AF34-874E7B6B2927}) (Version: 6.0.7.0 - Husdawg, LLC)
    TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.18 - TeamSpeak Systems GmbH)
    TeamViewer 8 (HKLM-x32\...\TeamViewer 8) (Version: 8.0.19617 - TeamViewer)
    The Witcher 3 - Wild Hunt (HKLM-x32\...\1207664643_is1) (Version: 1.0.11.0 - GOG.com)
    Third Age - Total War 3.0 (Part 1of2) (HKU\S-1-5-21-905238947-2220377667-1876713056-1001\...\Third Age - Total War 3.0 (Part 1of2)) (Version: - )
    Third Age - Total War 3.0 (Part 2of2) (HKU\S-1-5-21-905238947-2220377667-1876713056-1001\...\Third Age - Total War 3.0 (Part 2of2)) (Version: - )
    Tom Clancy's Ghost Recon Future Soldier (HKLM-x32\...\{6D87CAD9-9B94-4421-A439-B25F8DE14575}) (Version: 1.8 - Ubisoft)
    Tom Clancy's Rainbow Six Siege (HKLM-x32\...\Steam App 359550) (Version: - Ubisoft Montreal)
    Tom Clancy's Splinter Cell Conviction (HKLM-x32\...\{6D8DDB4A-C263-40DE-BA16-AFDAD159D59A}) (Version: 1.04.000 - Ubisoft)
    Tom Clancy's Splinter Cell® Blacklist™ (HKLM-x32\...\{A6356F2F-D3E1-4D83-9AA2-72871DD0C298}) (Version: 1.03 - Ubisoft)
    Toolkit Documentation (x32 Version: 8.100.26866 - Microsoft) Hidden
    Total War: ATTILA (HKLM-x32\...\Steam App 325610) (Version: - Creative Assembly)
    Total War: ROME II - Emperor Edition (HKLM-x32\...\Steam App 214950) (Version: - Creative Assembly)
    Total War: SHOGUN 2 (HKLM-x32\...\Steam App 34330) (Version: - The Creative Assembly)
    Uplay (HKLM-x32\...\Uplay) (Version: 13.0 - Ubisoft)
    VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0 - DivX, Inc) Hidden
    VGA Boost (HKLM-x32\...\{809ACFAE-9A4D-4C60-9223-D8B615CD8CBA}}_is1) (Version: 1.0.0.7 - MSI)
    Warface Launcher (Beta) (HKLM-x32\...\{28D1723C-31C4-4A83-9799-DFFB3739026D}) (Version: 1.0.0 - Crytek GmbH)
    Windows Assessment and Deployment Kit for Windows 8.1 (HKLM-x32\...\{e9e06304-a604-434b-b35f-d9beb94dc06d}) (Version: 8.100.26866 - Microsoft Corporation)
    WinRAR 4.20 (64-bit) (HKLM\...\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH)
    WinSCP 5.1.7 (HKLM-x32\...\winscp3_is1) (Version: 5.1.7 - Martin Prikryl)
    WPT Redistributables (x32 Version: 8.100.26866 - Microsoft) Hidden
    WPTx64 (x32 Version: 8.100.26837 - Microsoft) Hidden

    ==================== Custom CLSID (Whitelisted): ==========================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    CustomCLSID: HKU\S-1-5-21-905238947-2220377667-1876713056-1001_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\Chris\AppData\Local\Microsoft\OneDrive\17.3.6281.1202\FileCoAuth.exe (Microsoft Corporation)

    ==================== Scheduled Tasks (Whitelisted) =============

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    Task: {08237936-FDCA-468B-B1F4-DD11E236043E} - System32\Tasks\GenericSettingsHandler\Windows-Credentials\RetrySyncTask_for_S-1-5-21-905238947-2220377667-1876713056-1001
    Task: {0CFE2E40-6A97-48C5-9F38-DE82315CF1B0} - System32\Tasks\Microsoft\Windows\UPnP\UPnPHostConfig => config upnphost start= auto
    Task: {1DD8FD4F-000B-4AE4-93D3-47194D05F82D} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.)
    Task: {3500B991-070A-421E-A57A-993472AD5DD3} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2015-12-09] (Microsoft Corporation)
    Task: {3B955F3F-3903-464D-A25C-5C0F10CCB56B} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office 15\root\Office15\msoia.exe [2015-10-27] (Microsoft Corporation)
    Task: {55A3DED3-A14A-44A6-8D79-E08F702D03A1} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2015-10-13] (Microsoft Corporation)
    Task: {835AAF6E-E334-4D3D-9AC3-03C171B90452} - System32\Tasks\{24F190A2-8311-4B5B-BB2A-33313F397938} => pcalua.exe -a "C:\Users\Chris\Downloads\dotnetfx3setup (1).exe" -d C:\Users\Chris\Downloads
    Task: {8FC16075-C313-4DDC-B2DE-25320B556CDA} - System32\Tasks\{61A30D71-B4AB-47F7-ABAF-734ACEB8153E} => pcalua.exe -a C:\Users\Chris\Downloads\dotnetfx3setup.exe -d C:\Users\Chris\Downloads
    Task: {A34DDB05-9BE8-4FF3-9EBA-7841042E77AF} - \CCleanerSkipUAC -> No File <==== ATTENTION
    Task: {AA51978B-A90B-4A16-AF5A-AC139D834A22} - System32\Tasks\Razer_Game_Booster_AutoUpdate => C:\Program Files (x86)\Razer\Razer Game Booster\AutoUpdate.exe
    Task: {AD15EADE-B78E-4C86-BB52-38C5734148F7} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2015-10-13] (Microsoft Corporation)
    Task: {B6C59A53-638D-4361-9637-ED142E8D2F0E} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office 15\root\Office15\msoia.exe [2015-10-27] (Microsoft Corporation)
    Task: {CA88B156-0748-4553-8C86-62E11B8BB011} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-12-29] (Adobe Systems Incorporated)
    Task: {CD8E5FD8-3B3B-4005-B9E7-E8A44CFD0B52} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.)
    Task: {D0560D47-7FDB-4C65-B83C-3CB199CE31DB} - System32\Tasks\{4D56C402-4B79-4A2B-95EF-FE1034AB0702} => pcalua.exe -a C:\Users\Chris\AppData\Local\GreatArcadeHits\GAHUninstaller.exe
    Task: {E125A420-0021-430D-B5B2-27B680995785} - System32\Tasks\{9464F175-373C-477C-8831-D8CF33DDE712} => pcalua.exe -a "C:\ProgramData\Package Cache\{62340a00-1b99-4a03-9efc-765636e35146}\Wallpaper_Changer_IM_Setup.exe" -c /uninstall
    Task: {FFBF7BEF-253F-4714-BBDE-F582765F763B} - System32\Tasks\{338D639B-F43C-4196-B5E4-5515837EA181} => pcalua.exe -a C:\Users\Chris\Downloads\dotnetfx3_x64.exe -d C:\Users\Chris\Downloads

    (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

    Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
    Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

    ==================== Shortcuts =============================

    (The entries could be listed to be restored or removed.)

    ==================== Loaded Modules (Whitelisted) ==============

    2015-10-30 02:18 - 2015-10-30 02:18 - 00185856 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll
    2015-12-11 10:54 - 2015-11-05 10:08 - 00116344 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
    2014-03-19 14:12 - 2015-10-13 04:34 - 00105640 _____ () C:\Program Files\Microsoft Office 15\ClientX64\ApiClient.dll
    2015-06-23 14:11 - 2015-06-23 14:11 - 00187048 _____ () C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe
    2014-08-16 01:26 - 2014-04-03 14:22 - 00024048 _____ () C:\MSI\Smart Utilities\SuperRAIDSvc.exe
    2014-08-16 01:26 - 2014-04-02 09:47 - 01990144 _____ () C:\Program Files (x86)\MSI\Command Center\MSIControlService.exe
    2013-06-20 17:03 - 2011-12-14 16:53 - 00303360 _____ () C:\Program Files (x86)\NETGEAR\WNDA3100v2\WifiSvc.exe
    2014-08-16 01:26 - 2014-03-31 14:24 - 04115456 _____ () C:\Program Files (x86)\MSI\Command Center\CPU\MSICPUService.exe
    2015-12-11 13:43 - 2015-12-11 13:43 - 02653816 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
    2015-12-17 13:02 - 2015-12-17 13:02 - 00144384 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.12.15004.0_x86__8wekyb3d8bbwe\SkypeHost.exe
    2015-12-11 13:43 - 2015-12-11 13:43 - 02653816 _____ () C:\WINDOWS\System32\CoreUIComponents.dll
    2015-10-27 14:37 - 2015-09-01 11:04 - 08901184 _____ () C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\1033\GrooveIntlResource.dll
    2014-05-01 09:13 - 2014-05-01 09:13 - 00470016 _____ () C:\Users\Chris\AppData\Local\MEGAsync\ShellExtX64.dll
    2014-05-01 14:29 - 2014-05-01 14:29 - 00098304 _____ () C:\Program Files (x86)\FileZilla FTP Client\fzshellext_64.dll
    2015-12-17 18:11 - 2015-12-06 23:14 - 00093696 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\Windows.UI.Shell.SharedUtilities.dll
    2015-12-17 18:11 - 2015-12-06 23:00 - 00472064 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll
    2016-01-12 18:15 - 2016-01-04 20:29 - 07992832 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
    2016-01-12 18:15 - 2016-01-04 20:23 - 00591360 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
    2016-01-12 18:15 - 2016-01-04 20:24 - 02483200 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
    2016-01-12 18:15 - 2016-01-04 20:26 - 04089856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
    2014-08-16 01:15 - 2012-11-01 10:23 - 00089600 _____ () C:\WINDOWS\SYSTEM32\CmdRtr64.DLL
    2014-08-16 01:15 - 2012-11-01 10:21 - 00325120 _____ () C:\WINDOWS\SYSTEM32\APOMgr64.DLL
    2013-02-09 14:21 - 2013-02-09 14:21 - 06257664 _____ () C:\Users\Chris\AppData\Roaming\SWClient\swclient.exe
    2014-04-17 10:02 - 2014-04-17 10:02 - 00300544 _____ () C:\Program Files\Qualcomm Atheros\Network Manager\NetworkManager.exe
    2014-08-24 22:12 - 2015-10-23 07:40 - 00285568 _____ () C:\Users\Chris\AppData\Roaming\Dashlane\DashlanePlugin.exe
    2014-10-11 13:06 - 2014-10-11 13:06 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
    2014-10-11 13:05 - 2014-10-11 13:05 - 01044776 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
    2014-08-16 01:26 - 2014-04-03 14:19 - 01712128 _____ () C:\MSI\Smart Utilities\SuperRAIDExt.DLL
    2015-01-18 21:03 - 2014-12-24 18:15 - 00270040 _____ () C:\Program Files (x86)\AOMEI Backupper Professional Edition 2.2\UiLogic.dll
    2015-01-18 21:03 - 2014-12-24 18:15 - 00229080 _____ () C:\Program Files (x86)\AOMEI Backupper Professional Edition 2.2\diskmgr.dll
    2015-01-18 21:03 - 2014-12-24 18:15 - 00278232 _____ () C:\Program Files (x86)\AOMEI Backupper Professional Edition 2.2\Comn.dll
    2015-01-18 21:03 - 2014-12-24 18:15 - 00118488 _____ () C:\Program Files (x86)\AOMEI Backupper Professional Edition 2.2\FuncLogic.dll
    2015-01-18 21:03 - 2014-12-24 18:15 - 00343768 _____ () C:\Program Files (x86)\AOMEI Backupper Professional Edition 2.2\ImgFile.dll
    2015-01-18 21:03 - 2014-12-24 18:15 - 00028376 _____ () C:\Program Files (x86)\AOMEI Backupper Professional Edition 2.2\Encrypt.dll
    2015-01-18 21:03 - 2014-12-24 18:15 - 00483032 _____ () C:\Program Files (x86)\AOMEI Backupper Professional Edition 2.2\EnumFolder.dll
    2015-01-18 21:03 - 2014-12-24 18:15 - 00073432 _____ () C:\Program Files (x86)\AOMEI Backupper Professional Edition 2.2\Compress.dll
    2015-01-18 21:03 - 2014-12-24 18:15 - 00098008 _____ () C:\Program Files (x86)\AOMEI Backupper Professional Edition 2.2\BrLog.dll
    2015-01-18 21:03 - 2014-12-24 18:15 - 00077528 _____ () C:\Program Files (x86)\AOMEI Backupper Professional Edition 2.2\Ldm.dll
    2015-01-18 21:03 - 2014-12-24 18:15 - 00061144 _____ () C:\Program Files (x86)\AOMEI Backupper Professional Edition 2.2\Device.dll
    2015-01-18 21:03 - 2014-12-24 18:15 - 00265944 _____ () C:\Program Files (x86)\AOMEI Backupper Professional Edition 2.2\BrFat.dll
    2015-01-18 21:03 - 2014-12-24 18:15 - 00384728 _____ () C:\Program Files (x86)\AOMEI Backupper Professional Edition 2.2\BrNtfs.dll
    2015-01-18 21:03 - 2014-12-24 18:15 - 00241368 _____ () C:\Program Files (x86)\AOMEI Backupper Professional Edition 2.2\Clone.dll
    2015-01-18 21:03 - 2014-12-24 18:15 - 00102104 _____ () C:\Program Files (x86)\AOMEI Backupper Professional Edition 2.2\Backup.dll
    2015-01-18 21:03 - 2014-12-24 18:15 - 00151256 _____ () C:\Program Files (x86)\AOMEI Backupper Professional Edition 2.2\FlBackup.dll
    2015-01-18 21:03 - 2013-01-17 17:38 - 02403504 _____ () C:\Program Files (x86)\AOMEI Backupper Professional Edition 2.2\QtCore4.dll
    2015-01-18 21:03 - 2014-12-24 18:15 - 00102104 _____ () C:\Program Files (x86)\AOMEI Backupper Professional Edition 2.2\BrVol.dll
    2015-01-18 21:03 - 2014-12-24 18:15 - 00253656 _____ () C:\Program Files (x86)\AOMEI Backupper Professional Edition 2.2\GptBcd.dll
    2013-06-20 17:03 - 2011-12-14 09:22 - 00368640 _____ () C:\Program Files (x86)\NETGEAR\WNDA3100v2\WifiLib.dll
    2014-02-19 17:51 - 2014-02-19 17:51 - 01241560 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll
    2015-10-27 14:37 - 2015-09-01 07:25 - 08901184 _____ () C:\Program Files\Microsoft Office 15\root\Office15\1033\GrooveIntlResource.dll
    2014-05-01 09:15 - 2014-05-01 09:15 - 00463360 _____ () C:\Users\Chris\AppData\Local\MEGAsync\ShellExtX32.dll
    2015-12-17 13:02 - 2015-12-17 13:02 - 00141312 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.12.15004.0_x86__8wekyb3d8bbwe\SkypeBackgroundTasks.dll
    2015-12-17 13:02 - 2015-12-17 13:02 - 21845504 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.12.15004.0_x86__8wekyb3d8bbwe\SkyWrap.dll
    2015-07-26 13:01 - 2015-10-11 22:05 - 00013088 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll
    2013-06-19 20:24 - 2009-12-09 20:20 - 00126976 _____ () C:\Program Files (x86)\REALTEK\11n USB Wireless LAN Utility\EnumDevLib.dll
    2014-11-16 22:41 - 2014-11-16 22:41 - 00316576 _____ () C:\Program Files\Microsoft Office 15\Root\VFS\ProgramFilesCommonX86\Microsoft Shared\OFFICE15\AppVIsvStream32.dll
    2014-11-16 22:40 - 2014-11-16 22:40 - 00316576 _____ () C:\Program Files\Microsoft Office 15\Root\Office15\AppVIsvStream32.dll
    2014-09-06 11:44 - 2014-09-06 11:44 - 00035328 _____ () C:\Program Files (x86)\FileZilla FTP Client\fzshellext.dll
    2014-05-24 11:41 - 2014-05-24 11:41 - 00091648 _____ () C:\Program Files (x86)\FileZilla FTP Client\libgcc_s_sjlj-1.dll
    2014-05-24 11:41 - 2014-05-24 11:41 - 00892416 _____ () C:\Program Files (x86)\FileZilla FTP Client\libstdc++-6.dll
    2015-12-16 15:26 - 2015-12-10 22:54 - 01583432 _____ () C:\Program Files (x86)\Google\Chrome\Application\47.0.2526.106\libglesv2.dll
    2015-12-16 15:26 - 2015-12-10 22:54 - 00081224 _____ () C:\Program Files (x86)\Google\Chrome\Application\47.0.2526.106\libegl.dll
    2015-10-23 07:39 - 2015-10-23 07:39 - 05762944 _____ () C:\Users\Chris\AppData\Roaming\Dashlane\3.5.2.94565\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\components\KWData.3.5.2.94565.dll
    2015-10-23 07:39 - 2015-10-23 07:39 - 00443264 _____ () C:\Users\Chris\AppData\Roaming\Dashlane\3.5.2.94565\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\components\KWUtils.3.5.2.94565.dll
    2015-10-23 07:39 - 2015-10-23 07:39 - 31264640 _____ () C:\Users\Chris\AppData\Roaming\Dashlane\3.5.2.94565\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\components\KWExternLib.3.5.2.94565.dll
    2015-10-23 07:39 - 2015-10-23 07:39 - 00422784 _____ () C:\Users\Chris\AppData\Roaming\Dashlane\3.5.2.94565\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\components\KWDebug.3.5.2.94565.dll
    2015-10-23 07:39 - 2015-10-23 07:39 - 00339328 _____ () C:\Users\Chris\AppData\Roaming\Dashlane\3.5.2.94565\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\components\KWDebugDll_win32.3.5.2.94565.dll
    2015-10-23 07:39 - 2015-10-23 07:39 - 13234048 _____ () C:\Users\Chris\AppData\Roaming\Dashlane\3.5.2.94565\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\components\KWMainLib.3.5.2.94565.dll
    2015-10-23 07:39 - 2015-10-23 07:39 - 00276352 _____ () C:\Users\Chris\AppData\Roaming\Dashlane\3.5.2.94565\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\components\KWMainLib_win.3.5.2.94565.dll
    2015-10-23 07:39 - 2015-10-23 07:39 - 02073472 _____ () C:\Users\Chris\AppData\Roaming\Dashlane\3.5.2.94565\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\components\KWMainLibData.3.5.2.94565.dll
    2015-10-23 07:39 - 2015-10-23 07:39 - 00338304 _____ () C:\Users\Chris\AppData\Roaming\Dashlane\3.5.2.94565\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\components\Kwift_DP.3.5.2.94565.dll
    2015-12-24 16:32 - 2015-12-24 07:46 - 16792256 _____ () C:\Users\Chris\AppData\Local\Google\Chrome\User Data\PepperFlash\20.0.0.267\pepflashplayer.dll

    ==================== Alternate Data Streams (Whitelisted) =========

    (If an entry is included in the fixlist, only the ADS will be removed.)


    ==================== Safe Mode (Whitelisted) ===================

    (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


    ==================== EXE Association (Whitelisted) ===============

    (If an entry is included in the fixlist, the registry item will be restored to default or removed.)


    ==================== Internet Explorer trusted/restricted ===============

    (If an entry is included in the fixlist, it will be removed from the registry.)

    IE trusted site: HKU\S-1-5-21-905238947-2220377667-1876713056-1001\...\clonewarsadventures.com -> clonewarsadventures.com
    IE trusted site: HKU\S-1-5-21-905238947-2220377667-1876713056-1001\...\freerealms.com -> freerealms.com
    IE trusted site: HKU\S-1-5-21-905238947-2220377667-1876713056-1001\...\soe.com -> soe.com
    IE trusted site: HKU\S-1-5-21-905238947-2220377667-1876713056-1001\...\sony.com -> sony.com

    ==================== Hosts content: ===============================

    (If needed Hosts: directive could be included in the fixlist to reset Hosts.)

    2013-08-22 08:25 - 2013-08-22 08:25 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts


    ==================== Other Areas ============================

    (Currently there is no automatic fix for this section.)

    HKU\S-1-5-21-905238947-2220377667-1876713056-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Chris\AppData\Local\Microsoft\Windows\Themes\RoamedThemeFiles\DesktopBackground\fog.jpg
    DNS Servers: 75.75.75.75 - 75.75.76.76
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
    Windows Firewall is enabled.

    ==================== MSCONFIG/TASK MANAGER disabled items ==

    (Currently there is no automatic fix for this section.)

    HKLM\...\StartupApproved\StartupFolder: => "NETGEAR WNDA3100v2 Genie.lnk"
    HKLM\...\StartupApproved\Run: => "Logitech Download Assistant"
    HKLM\...\StartupApproved\Run: => "Nvtmru"
    HKLM\...\StartupApproved\Run: => "EKIJ5000StatusMonitor"
    HKLM\...\StartupApproved\Run: => "NvBackend"
    HKLM\...\StartupApproved\Run32: => "Conime"
    HKLM\...\StartupApproved\Run32: => "SunJavaUpdateSched"
    HKLM\...\StartupApproved\Run32: => "EKStatusMonitor"
    HKLM\...\StartupApproved\Run32: => "vProt"
    HKLM\...\StartupApproved\Run32: => "LWS"
    HKLM\...\StartupApproved\Run32: => "PWRISOVM.EXE"
    HKLM\...\StartupApproved\Run32: => "APSDaemon"
    HKLM\...\StartupApproved\Run32: => "iTunesHelper"
    HKLM\...\StartupApproved\Run32: => "amd_dc_opt"
    HKLM\...\StartupApproved\Run32: => "UpdReg"
    HKLM\...\StartupApproved\Run32: => "QuickTime Task"
    HKLM\...\StartupApproved\Run32: => "Razer Synapse"
    HKLM\...\StartupApproved\Run32: => "Command Center"
    HKLM\...\StartupApproved\Run32: => "Fast Boot"
    HKLM\...\StartupApproved\Run32: => "Live Update"
    HKU\S-1-5-21-905238947-2220377667-1876713056-1001\...\StartupApproved\StartupFolder: => "GameStop Now.lnk"
    HKU\S-1-5-21-905238947-2220377667-1876713056-1001\...\StartupApproved\StartupFolder: => "MEGAsync.lnk"
    HKU\S-1-5-21-905238947-2220377667-1876713056-1001\...\StartupApproved\Run: => "uTorrent"
    HKU\S-1-5-21-905238947-2220377667-1876713056-1001\...\StartupApproved\Run: => "ooVoo.exe"
    HKU\S-1-5-21-905238947-2220377667-1876713056-1001\...\StartupApproved\Run: => "Steam"
    HKU\S-1-5-21-905238947-2220377667-1876713056-1001\...\StartupApproved\Run: => "SearchProtection"
    HKU\S-1-5-21-905238947-2220377667-1876713056-1001\...\StartupApproved\Run: => "AVG-Secure-Search-Update_0414c"
    HKU\S-1-5-21-905238947-2220377667-1876713056-1001\...\StartupApproved\Run: => "Wallpaper Changer"
    HKU\S-1-5-21-905238947-2220377667-1876713056-1001\...\StartupApproved\Run: => "Dashlane"
    HKU\S-1-5-21-905238947-2220377667-1876713056-1001\...\StartupApproved\Run: => "DashlanePlugin"

    ==================== FirewallRules (Whitelisted) ===============

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
    FirewallRules: [{C2444A84-3249-432F-8461-FC97A79838D4}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\UcMapi.exe
    FirewallRules: [{D6053A8C-C673-47D3-9519-39BB7514816C}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\UcMapi.exe
    FirewallRules: [{DD3C0B4B-0C6A-494E-8002-0207653B7A08}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\Lync.exe
    FirewallRules: [{2B9D3974-2829-495B-AA84-3FF203D62198}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\Lync.exe
    FirewallRules: [{81AA013F-E291-4B62-940F-9D231ED66043}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Fallout 4\Fallout4Launcher.exe
    FirewallRules: [{5BB01ABB-9391-4AF1-B1ED-70E56FD9B67D}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Fallout 4\Fallout4Launcher.exe
    FirewallRules: [{CB190078-286A-4660-BD8E-509C1B0A2563}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Warface\live\nw.exe
    FirewallRules: [{E19CE973-967C-4445-B37E-66A257ABDCA1}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Warface\live\nw.exe
    FirewallRules: [{86F1EAE3-669D-4C61-83DB-94126835E699}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Resident Evil 4\Bin32\bio4.exe
    FirewallRules: [{DCA82765-146E-4720-AEFD-ED9499BA0EDF}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Resident Evil 4\Bin32\bio4.exe
    FirewallRules: [{AF489431-45B1-456E-9D7C-45FA7F5BD128}] => (Allow) C:\Program Files (x86)\Origin Games\STAR WARS Battlefront Beta\starwarsbattlefront.exe
    FirewallRules: [{974E933F-413C-4A94-BB22-D0A51D0E4CE9}] => (Allow) C:\Program Files (x86)\Origin Games\STAR WARS Battlefront Beta\starwarsbattlefront.exe
    FirewallRules: [{B635DFAE-89DD-4BC7-AF74-22B9DB255F7D}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\games\Rainbow Six Siege - Closed Beta\RainbowSix.exe
    FirewallRules: [{956A046E-F15C-4D2C-9E9E-EAFED4651BAB}] => (Allow) C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\games\Rainbow Six Siege - Closed Beta\RainbowSix.exe
    FirewallRules: [{0589CE67-91BB-4594-96FB-E8BA513EF3F5}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Total War Rome II\launcher\launcher.exe
    FirewallRules: [{12C04F82-7E57-41B7-9766-1922E7DD694C}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Total War Rome II\launcher\launcher.exe
    FirewallRules: [UDP Query User{E5720613-4FD1-4E27-AF66-DCD27015A0E7}C:\users\chris\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\chris\appdata\roaming\spotify\spotify.exe
    FirewallRules: [TCP Query User{B1057F37-B7D6-4F42-83B0-753AC75AF288}C:\users\chris\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\chris\appdata\roaming\spotify\spotify.exe
    FirewallRules: [{AED18FE0-3981-43E0-9595-4719072988C7}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Mad Max\MadMax.exe
    FirewallRules: [{CFAC31AC-80F6-4C64-8C15-E7354683C9FA}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Mad Max\MadMax.exe
    FirewallRules: [{BECC1CB0-941E-401C-B849-4CB7A4FF8832}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Total War SHOGUN 2\benchmarks\benchmark_specify_properties.bat
    FirewallRules: [{6C1ECCBD-BE38-4747-AB7E-606DCC0FF0E9}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Total War SHOGUN 2\benchmarks\benchmark_specify_properties.bat
    FirewallRules: [{F2D6084B-7419-4DEB-8E3E-AE711013EFA1}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Total War SHOGUN 2\benchmarks\benchmark_specify_properties.bat
    FirewallRules: [{5B57547F-690F-4A22-9D9D-8E822673C27D}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Total War SHOGUN 2\benchmarks\benchmark_specify_properties.bat
    FirewallRules: [{3DD985DF-C6EB-4085-868E-CCF42778D8CF}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Total War SHOGUN 2\benchmarks\benchmark_current_settings.bat
    FirewallRules: [{CC4194C2-3FF7-40A9-A9EC-D5E61B4A04D7}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Total War SHOGUN 2\benchmarks\benchmark_current_settings.bat
    FirewallRules: [{8E6AE480-881C-41B2-A5A1-BC3C3BC82C0C}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Total War SHOGUN 2\benchmarks\benchmark_specify_properties.bat
     
  19. Broni

    Broni Malware Annihilator Posts: 52,897   +344

    Download attached fixlist.txt file and save it to the Desktop.
    NOTE. It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work.

    NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

    Run FRST(FRST64) and press the Fix button just once and wait.
    The tool will make a log on the Desktop (Fixlog.txt). Please post it to your reply.
     

    Attached Files:

  20. Chris Waters

    Chris Waters TS Rookie Topic Starter Posts: 23

    Fix result of Farbar Recovery Scan Tool (x64) Version:10-01-2015 01
    Ran by Chris (2016-01-14 18:33:38) Run:1
    Running from C:\Users\Chris\Desktop
    Loaded Profiles: Chris (Available Profiles: Chris)
    Boot Mode: Normal
    ==============================================

    fixlist content:
    *****************
    HKLM-x32\...\Run: [] => [X]
    HKLM-x32\...\Run: [UpdReg] => C:\WINDOWS\UpdReg.EXE
    BHO-x32: Updater For XFIN_PORTAL -> {bb46be07-13eb-4c49-b0f0-fc78b9ea4983} -> C:\Program Files (x86)\xfin_portal\auxi\comcastAu.dll => No File
    Toolbar: HKLM-x32 - No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
    FF Plugin HKU\S-1-5-21-905238947-2220377667-1876713056-1001: @doubletwist.com/NPPodcast -> C:\Program Files (x86)\Common Files\doubleTwist\NPPodcast.dll [No File]
    CHR HomePage: Profile 4 -> hxxp://www.search.ask.com/?gct=hp
    CHR StartupUrls: Profile 4 -> "hxxp://www.google.com/ig/redirectdomain?brand=TSND&bmod=TSND","hxxp://start.mysearchdial.com/?f=1&a=frg01_14_25_ch&cd=2XzuyEtN2Y1L1Qzu0BzzzyyByD0AtBtAtBzzzztBzy0BtDyEtN0D0Tzu0SzzzyzytN1L2XzutBtFtBtCtFyEtFtCtN1L1CzutCyEtBzytDyD1V1RtN1L1G1B1V1N2Y1L1Qzu2SyC0AtC0EtD0F0DtCtGyEtBzy0CtGyBtBzz0CtGtAyBzztAtGyC0D0F0FyC0B0F0FyBtAyDzy2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyEyC0DyD0C0EtDtBtGyDtD0F0CtGtAyEzzzytGyC0A0AtDtGyEyDyE0FzytC0AtD0E0DyDzz2QtN1B1L1H1Ezu1O2U1M1B&cr=1435966762&ir=","hxxp://www.google.com"
    CHR HKLM\...\Chrome\Extension: [hkhkiakolggnnicallabhkobalpeplpi] - <no Path/update_url>
    CHR HKLM-x32\...\Chrome\Extension: [hkhkiakolggnnicallabhkobalpeplpi] - <no Path/update_url>
    2013-07-23 11:04 - 2011-07-19 02:37 - 0003262 _____ () C:\Program Files (x86)\Falco.ico
    2013-07-23 11:04 - 2011-07-19 03:05 - 0000046 _____ () C:\Program Files (x86)\Falco.url
    2014-06-17 20:20 - 2014-07-19 00:23 - 0000090 _____ () C:\Users\Chris\AppData\Roaming\WB.CFG
    2013-11-11 14:52 - 2014-09-06 17:12 - 0000600 _____ () C:\Users\Chris\AppData\Roaming\winscp.rnd
    2013-06-24 21:05 - 2013-09-04 19:34 - 0000236 _____ () C:\Users\Chris\AppData\Local\LaunchHomeCenter.log
    2015-08-19 19:46 - 2015-11-10 00:12 - 0007602 _____ () C:\Users\Chris\AppData\Local\resmon.resmoncfg
    2015-01-24 14:36 - 2015-01-24 14:36 - 0000000 _____ () C:\Users\Chris\AppData\Local\{1C9D2A21-6106-4C53-AB79-60959E2BB4A5}
    C:\Users\Chris\AppData\Local\Temp\dllnt_dump.dll
    C:\Users\Chris\AppData\Local\Temp\jshortcut-6364520680213824196.dll
    C:\Users\Chris\AppData\Local\Temp\jshortcut-8997663281635068146.dll
    C:\Users\Chris\AppData\Local\Temp\Nexus Mod Manager-0.61.4.exe
    C:\Users\Chris\AppData\Local\Temp\sqlite3.dll
    Task: {A34DDB05-9BE8-4FF3-9EBA-7841042E77AF} - \CCleanerSkipUAC -> No File <==== ATTENTION

    *****************

    HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => value removed successfully
    HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\UpdReg => value removed successfully
    "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{bb46be07-13eb-4c49-b0f0-fc78b9ea4983}" => key removed successfully
    "HKCR\Wow6432Node\CLSID\{bb46be07-13eb-4c49-b0f0-fc78b9ea4983}" => key removed successfully
    HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar\\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} => value removed successfully
    "HKCR\Wow6432Node\CLSID\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}" => key removed successfully
    "HKU\S-1-5-21-905238947-2220377667-1876713056-1001\Software\MozillaPlugins\@doubletwist.com/NPPodcast" => key removed successfully
    C:\Program Files (x86)\Common Files\doubleTwist\NPPodcast.dll => not found.
    Chrome HomePage => removed successfully
    Chrome StartupUrls => removed successfully
    "HKLM\SOFTWARE\Google\Chrome\Extensions\hkhkiakolggnnicallabhkobalpeplpi" => key removed successfully
    "HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\hkhkiakolggnnicallabhkobalpeplpi" => key removed successfully
    C:\Program Files (x86)\Falco.ico => moved successfully
    C:\Program Files (x86)\Falco.url => moved successfully
    C:\Users\Chris\AppData\Roaming\WB.CFG => moved successfully
    C:\Users\Chris\AppData\Roaming\winscp.rnd => moved successfully
    C:\Users\Chris\AppData\Local\LaunchHomeCenter.log => moved successfully
    C:\Users\Chris\AppData\Local\resmon.resmoncfg => moved successfully
    C:\Users\Chris\AppData\Local\{1C9D2A21-6106-4C53-AB79-60959E2BB4A5} => moved successfully
    C:\Users\Chris\AppData\Local\Temp\dllnt_dump.dll => moved successfully
    C:\Users\Chris\AppData\Local\Temp\jshortcut-6364520680213824196.dll => moved successfully
    C:\Users\Chris\AppData\Local\Temp\jshortcut-8997663281635068146.dll => moved successfully
    C:\Users\Chris\AppData\Local\Temp\Nexus Mod Manager-0.61.4.exe => moved successfully
    C:\Users\Chris\AppData\Local\Temp\sqlite3.dll => moved successfully
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A34DDB05-9BE8-4FF3-9EBA-7841042E77AF}" => key removed successfully
    "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A34DDB05-9BE8-4FF3-9EBA-7841042E77AF}" => key removed successfully
    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\CCleanerSkipUAC => key not found.

    ==== End of Fixlog 18:33:40 ====
     
  21. Broni

    Broni Malware Annihilator Posts: 52,897   +344

    Last scans...

    [​IMG] Download Security Check from here or here and save it to your Desktop.
    • Double-click SecurityCheck.exe
    • Follow the onscreen instructions inside of the black box.
    • A Notepad document should open automatically called checkup.txt; please post the contents of that document.

    NOTE 1. If one of your security applications (e.g., third-party firewall) requests permission to allow DIG.EXE access the Internet, allow it to do so.
    NOTE 2. SecurityCheck may produce some false warning(s), so leave the results reading to me.
    NOTE 3. If you receive UNSUPPORTED OPERATING SYSTEM! ABORTED! message restart computer and Security Check should run


    [​IMG] Please download Farbar Service Scanner (FSS) and run it on the computer with the issue.
    Make sure the following options are checked:
    • Internet Services
    • Windows Firewall
    • System Restore
    • Security Center
    • Windows Update
    • Windows Defender
    • Other Services

    Press "Scan".
    It will create a log (FSS.txt) in the same directory the tool is run.
    Please copy and paste the log to your reply.


    [​IMG] Download Temp File Cleaner (TFC)
    Alternate download: http://www.itxassociates.com/OT-Tools/TFC.exe
    • Double click on TFC.exe to run the program.
    • Click on Start button to begin cleaning process.
    • TFC will close all running programs, and it may ask you to restart computer.


    [​IMG] Download Sophos Free Virus Removal Tool and save it to your desktop.
    • Double click the icon and select Run
    • Click Next
    • Select I accept the terms in this license agreement, then click Next twice
    • Click Install
    • Click Finish to launch the program
    • Once the virus database has been updated click Start Scanning
    • If any threats are found click Details, then View log file... (bottom left hand corner)
    • Copy and paste the results in your reply
    • Close the Notepad document, close the Threat Details screen, then click Start cleanup
    • Click Exit to close the program
     
  22. Chris Waters

    Chris Waters TS Rookie Topic Starter Posts: 23

    Hi, sorry for the delay. been very busy and dont like to do scans like these idle. I will finish the scans tomorrow or monday. thanks for the help again and patience
     
  23. Broni

    Broni Malware Annihilator Posts: 52,897   +344

  24. Chris Waters

    Chris Waters TS Rookie Topic Starter Posts: 23

    Results of screen317's Security Check version 1.009
    x64 (UAC is enabled)
    Internet Explorer 11
    ``````````````Antivirus/Firewall Check:``````````````
    Windows Firewall Enabled!
    Windows Defender
    WMI entry may not exist for antivirus; attempting automatic update.
    `````````Anti-malware/Other Utilities Check:`````````
    Java version 32-bit out of Date!
    Adobe Flash Player 20.0.0.267
    Google Chrome (47.0.2526.106)
    Google Chrome (47.0.2526.111)
    ````````Process Check: objlist.exe by Laurent````````
    Windows Defender MSMpEng.exe
    Malwarebytes Anti-Malware mbamservice.exe
    Malwarebytes Anti-Malware mbam.exe
    Malwarebytes Anti-Malware mbamscheduler.exe
    Windows Defender MpCmdRun.exe
    `````````````````System Health check`````````````````
    Total Fragmentation on Drive C: %
    ````````````````````End of Log``````````````````````
     
  25. Chris Waters

    Chris Waters TS Rookie Topic Starter Posts: 23

    Farbar Service Scanner Version: 03-01-2016
    Ran by Chris (administrator) on 18-01-2016 at 22:46:06
    Running from "C:\Users\Chris\Downloads"
    Microsoft Windows 10 Home (X64)
    Boot Mode: Normal
    ****************************************************************

    Internet Services:
    ============

    Connection Status:
    ==============
    Localhost is accessible.
    LAN connected.
    Attempt to access Google IP returned error. Google IP is unreachable
    Google.com is accessible.
    Yahoo.com is accessible.


    Windows Firewall:
    =============

    Firewall Disabled Policy:
    ==================


    System Restore:
    ============

    System Restore Policy:
    ========================


    Security Center:
    ============


    Windows Update:
    ============

    Windows Autoupdate Disabled Policy:
    ============================


    Windows Defender:
    ==============

    Other Services:
    ==============


    File Check:
    ========
    C:\Windows\System32\nsisvc.dll => File is digitally signed
    C:\Windows\System32\drivers\nsiproxy.sys => File is digitally signed
    C:\Windows\System32\drivers\afd.sys => File is digitally signed
    C:\Windows\System32\drivers\tdx.sys => File is digitally signed
    C:\Windows\System32\Drivers\tcpip.sys => File is digitally signed
    C:\Windows\System32\dnsrslvr.dll => File is digitally signed
    C:\Windows\System32\mpssvc.dll => File is digitally signed
    C:\Windows\System32\bfe.dll => File is digitally signed
    C:\Windows\System32\drivers\mpsdrv.sys => File is digitally signed
    C:\Windows\System32\SDRSVC.dll => File is digitally signed
    C:\Windows\System32\vssvc.exe => File is digitally signed
    C:\Windows\System32\wscsvc.dll => File is digitally signed
    C:\Windows\System32\wbem\WMIsvc.dll => File is digitally signed
    C:\Windows\System32\wuaueng.dll => File is digitally signed
    C:\Windows\System32\qmgr.dll => File is digitally signed
    C:\Windows\System32\es.dll => File is digitally signed
    C:\Windows\System32\cryptsvc.dll => File is digitally signed
    C:\Program Files\Windows Defender\MpSvc.dll => File is digitally signed
    C:\Windows\System32\ipnathlp.dll => File is digitally signed
    C:\Windows\System32\iphlpsvc.dll => File is digitally signed
    C:\Windows\System32\svchost.exe => File is digitally signed
    C:\Windows\System32\rpcss.dll => File is digitally signed


    **** End of log ****
     

Similar Topics

Add New Comment

You need to be a member to leave a comment. Join thousands of tech enthusiasts and participate.
TechSpot Account You may also...