The logs are huge, I will post them in multiple replies.
Here you go:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 19.04.2018
Ran by Admin (administrator) on ADMIN-PC (22-04-2018 08:41:40)
Running from C:\Users\Admin\Desktop
Loaded Profiles: Admin (Available Profiles: Admin)
Platform: Microsoft Windows 7 Ultimate Service Pack 1 (X86) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(AO Kaspersky Lab) C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 18.0.0\avp.exe
(BlueStack Systems, Inc.) C:\Program Files\BlueStacks\HD-LogRotatorService.exe
(BlueStack Systems, Inc.) C:\Program Files\BlueStacks\HD-UpdaterService.exe
(AO Kaspersky Lab) C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 18.0.0\avpui.exe
(Hi-Rez Studios) E:\Program Files\Hi-Rez Studios\HiPatchService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(TeamViewer GmbH) C:\Program Files\TeamViewer\TeamViewer_Service.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
(Valve Corporation) E:\heroes\Steam.exe
(Wargaming.net) C:\ProgramData\Wargaming.net\GameCenter\wgc.exe
(Dropbox, Inc.) C:\Users\Admin\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Dropbox, Inc.) C:\Users\Admin\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Dropbox, Inc.) C:\Users\Admin\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Valve Corporation) E:\heroes\bin\cef\cef.win7\steamwebhelper.exe
(Disc Soft Ltd) C:\Program Files\DAEMON Tools Pro\DiscSoftBusServicePro.exe
(Valve Corporation) E:\heroes\bin\cef\cef.win7\steamwebhelper.exe
(Valve Corporation) C:\Program Files\Common Files\Steam\SteamService.exe
(Wargaming.net) C:\ProgramData\Wargaming.net\GameCenter\dlls\wgc_watchdog.exe
(Valve Corporation) E:\heroes\bin\cef\cef.win7\steamwebhelper.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(AO Kaspersky Lab) C:\Program Files\Kaspersky Lab\Kaspersky Secure Connection 2.0\ksde.exe
(AO Kaspersky Lab) C:\Program Files\Kaspersky Lab\Kaspersky Secure Connection 2.0\ksdeui.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [12021464 2014-02-24] (Realtek Semiconductor)
HKLM\...\Run: [NvBackend] => C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe [2234144 2014-02-05] (NVIDIA Corporation)
HKLM\...\Run: [QuickTime Task] => C:\Program Files\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.)
HKU\S-1-5-21-51145358-2442092094-1609093457-1000\...\Run: [Dropbox Update] => C:\Users\Admin\AppData\Local\Dropbox\Update\DropboxUpdate.exe [143144 2016-11-05] (Dropbox, Inc.)
HKU\S-1-5-21-51145358-2442092094-1609093457-1000\...\Run: [Steam] => E:\heroes\steam.exe [3199776 2018-04-03] (Valve Corporation)
HKU\S-1-5-21-51145358-2442092094-1609093457-1000\...\Run: [Wargaming.net Game Center] => C:\ProgramData\Wargaming.net\GameCenter\wgc.exe [2121976 2018-04-02] (Wargaming.net)
HKU\S-1-5-21-51145358-2442092094-1609093457-1000\...\Run: [DAEMON Tools Pro Agent] => C:\Program Files\DAEMON Tools Pro\DTAgent.exe [3519168 2016-11-24] (Disc Soft Ltd)
HKU\S-1-5-21-51145358-2442092094-1609093457-1000\...\Run: [Web Companion] => C:\Program Files\Lavasoft\Web Companion\Application\WebCompanion.exe --minimize
HKU\S-1-5-21-51145358-2442092094-1609093457-1000\...\MountPoints2: {15aa3677-c09a-11e7-b079-001966914398} - H:\Autorun.exe
HKU\S-1-5-21-51145358-2442092094-1609093457-1000\...\MountPoints2: {4779d246-b42f-11e3-bba9-001966914398} - I:\AUTORUN.EXE
HKU\S-1-5-21-51145358-2442092094-1609093457-1000\...\MountPoints2: {ebc86d91-a8fd-11e7-a5cb-001966914398} - H:\Lenovo_Suite.exe
Startup: C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2018-04-15]
ShortcutTarget: Dropbox.lnk -> C:\Users\Admin\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{F34F7871-6B4F-4CC1-BBA9-906100AE495B}: [NameServer] 52.17.204.69,8.8.8.8
Tcpip\..\Interfaces\{F34F7871-6B4F-4CC1-BBA9-906100AE495B}: [DhcpNameServer] 192.168.1.1
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://
www.mystartsearch.com/web/?type=ds&ts=1439142943&z=c3f3e455b6cc6276b4fdf9cg1z3cft0g2zco7b0zew&from=cmi&uid=WDCXWD800BB-00JHC0_WD-WMAM9M99445894458&q={searchTerms}
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://
www.mystartsearch.com/web/?type=ds&ts=1439142943&z=c3f3e455b6cc6276b4fdf9cg1z3cft0g2zco7b0zew&from=cmi&uid=WDCXWD800BB-00JHC0_WD-WMAM9M99445894458&q={searchTerms}
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-51145358-2442092094-1609093457-1000 -> {C0C3A6C6-03BC-4195-8FCB-AEA091301353} URL = hxxps://ro.search.yahoo.com/yhs/search?hspart=lvs&hsimp=yhs-awc&type=lvs__webcompa__1_0__ya__ch_WCYID10440__180325__yaie&p={searchTerms}
BHO: Kaspersky Protection -> {0E2877D3-2641-4970-B794-A553E295428D} -> C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 18.0.0\IEExt\ie_plugin.dll [2018-04-21] (AO Kaspersky Lab)
BHO: GoodTab Class -> {1F91A9A1-01BA-4c81-863D-3BA0751E1419} -> C:\Program Files\MiuiTab\SupTab.dll => No File
BHO: BitComet Helper -> {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} -> C:\Program Files\BitComet\tools\BitCometBHO_1.5.4.11.dll [2013-11-29] (BitComet)
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_131\bin\ssv.dll [2017-04-19] (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_131\bin\jp2ssv.dll [2017-04-19] (Oracle Corporation)
Toolbar: HKLM - Kaspersky Protection Toolbar - {4853DF44-7D6B-48E9-9258-D800EEE54AF6} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 18.0.0\IEExt\ie_plugin.dll [2018-04-21] (AO Kaspersky Lab)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll [2017-04-05] (Skype Technologies)
FireFox:
========
FF DefaultProfile: i7p503c2.default-1439149941763
FF ProfilePath: C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\i7p503c2.default-1439149941763 [2018-03-29]
FF Homepage: Mozilla\Firefox\Profiles\i7p503c2.default-1439149941763 -> hxxps://ro.search.yahoo.com/yhs/web?hspart=lvs&hsimp=yhs-awc&type=lvs__webcompa__1_0__ya__hp_WCYID10440__180325__yaff
FF NewTab: Mozilla\Firefox\Profiles\i7p503c2.default-1439149941763 -> hxxps://ro.search.yahoo.com/yhs/web?hspart=lvs&hsimp=yhs-awc&type=lvs__webcompa__1_0__ya__hp_WCYID10440__180325__yaff
FF Extension: (Firebug) - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\i7p503c2.default-1439149941763\Extensions\firebug@software.joehewitt.com.xpi [2017-10-16] [Legacy]
FF Extension: (Dust-Me Selectors) - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\i7p503c2.default-1439149941763\Extensions\{3c6e1eed-a07e-4c80-9cf3-66ea0bf40b37} [2017-11-11] [Legacy]
FF SearchPlugin: C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\i7p503c2.default-1439149941763\searchplugins\yahoo-lavasoft-ff59.xml [2018-03-25]
FF ProfilePath: C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\gelmk903.dev-edition-default [2018-03-25]
FF Homepage: Mozilla\Firefox\Profiles\gelmk903.dev-edition-default -> hxxps://google.ro/
FF HKLM\...\Firefox\Extensions: [light_plugin_448EC0843447455C9DA355B3C2811D6A@kaspersky.com] - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 18.0.0\FFExt\light_plugin_firefox\addon.xpi
FF Extension: (Kaspersky Protection) - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 18.0.0\FFExt\light_plugin_firefox\addon.xpi [2018-04-21]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_29_0_0_140.dll [2018-04-15] ()
FF Plugin: @adobe.com/ShockwavePlayer -> C:\Windows\system32\Adobe\Director\np32dsw_1225195.dll [2016-09-20] (Adobe Systems, Inc.)
FF Plugin: @java.com/DTPlugin,version=11.131.2 -> C:\Program Files\Java\jre1.8.0_131\bin\dtplugin\npDeployJava1.dll [2017-04-19] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.131.2 -> C:\Program Files\Java\jre1.8.0_131\bin\plugin2\npjp2.dll [2017-04-19] (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin: @nvidia.com/3DVision -> C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll [2014-03-04] (NVIDIA Corporation)
FF Plugin: @nvidia.com/3DVisionStreaming -> C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2014-03-04] (NVIDIA Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-16] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-16] (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2018-02-12] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-51145358-2442092094-1609093457-1000: @citrixonline.com/appdetectorplugin -> C:\Users\Admin\AppData\Local\Citrix\Plugins\104\npappdetector.dll [2015-10-12] (Citrix Online)
FF Plugin HKU\S-1-5-21-51145358-2442092094-1609093457-1000: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Admin\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2015-06-13] (Unity Technologies ApS)
FF Plugin HKU\S-1-5-21-51145358-2442092094-1609093457-1000: anvisoft.com/AdblockPlugin -> C:\ProgramData\Anvisoft\Anvi Smart Defender 2\extensions\npAdblockPlugin.dll [No File]
StartMenuInternet: Firefox-CA9422711AE1A81C - C:\Program Files\Firefox Developer Edition\firefox.exe
Chrome:
=======
CHR DefaultProfile: Default
CHR HomePage: Default -> hxxp://
www.oursurfing.com/?type=hppp&ts=1439137801&z=ec21b445376a514eb0f879dgbz9c0t5g3c0m8b0ebo&from=amt&uid=WDCXWD800BB-00JHC0_WD-WMAM9M99445894458
CHR StartupUrls: Default -> "hxxps://
www.google.ro/"
CHR Profile: C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default [2018-04-22]
CHR Extension: (Google Drive) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-24]
CHR Extension: (YouTube) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-10-11]
CHR Extension: (Google Search) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-11-01]
CHR Extension: (Adobe Acrobat) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2017-06-10]
CHR Extension: (Google Docs Offline) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-17]
CHR Extension: (Black blue shards) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\hgoflmajhinnohnhkfeggflmmppiilck [2017-06-02]
CHR Extension: (Application Launcher for Drive (by Google)) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2014-11-08]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-04-03]
CHR Extension: (Gmail) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-03-29]
CHR Extension: (Chrome Media Router) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-03-25]
CHR HKLM\...\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM\...\Chrome\Extension: [lhmiofmipcpmhgihiecmpiekcacigpgb] - C:\ProgramData\Anvisoft\Anvi Smart Defender 2\extensions\chrome.crx <not found>
CHR HKLM\...\Chrome\Extension: [mchjnmdbdlkdbfliogedbnpnanfjnolk] - hxxps://chrome.google.com/webstore/detail/mchjnmdbdlkdbfliogedbnpnanfjnolk
CHR HKU\S-1-5-21-51145358-2442092094-1609093457-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [apdfllckaahabafndbhieahigkjlhalf] - C:\Users\Admin\AppData\Local\Google\Drive\apdfllckaahabafndbhieahigkjlhalf_live.crx [2014-04-13]
CHR HKU\S-1-5-21-51145358-2442092094-1609093457-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-51145358-2442092094-1609093457-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] - hxxps://clients2.google.com/service/update2/crx
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AVP18.0.0; C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 18.0.0\avp.exe [354672 2017-01-24] (AO Kaspersky Lab)
S3 BITCOMET_HELPER_SERVICE; C:\Program Files\BitComet\tools\BitCometService.exe [1296728 2013-11-29] (
www.BitComet.com)
S2 BstHdAndroidSvc; C:\Program Files\BlueStacks\HD-Service.exe [392192 2015-03-06] (BlueStack Systems, Inc.) [File not signed]
R2 BstHdLogRotatorSvc; C:\Program Files\BlueStacks\HD-LogRotatorService.exe [388824 2015-03-03] (BlueStack Systems, Inc.)
R2 BstHdUpdaterSvc; C:\Program Files\BlueStacks\HD-UpdaterService.exe [794328 2015-03-03] (BlueStack Systems, Inc.)
R3 Disc Soft Pro Bus Service; C:\Program Files\DAEMON Tools Pro\DiscSoftBusServicePro.exe [1730240 2016-11-24] (Disc Soft Ltd)
S3 EasyAntiCheat; C:\Program Files\EasyAntiCheat\EasyAntiCheat.exe [526888 2017-12-19] (EasyAntiCheat Ltd)
U2 HiPatchService; E:\Program Files\Hi-Rez Studios\HiPatchService.exe [9728 2017-09-19] (Hi-Rez Studios) [File not signed]
S3 IDriverT; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
R2 KSDE2.0.0; C:\Program Files\Kaspersky Lab\Kaspersky Secure Connection 2.0\ksde.exe [354672 2017-01-24] (AO Kaspersky Lab)
R2 NvNetworkService; C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe [1593632 2014-02-05] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [15904544 2014-02-05] (NVIDIA Corporation)
R2 TeamViewer; C:\Program Files\TeamViewer\TeamViewer_Service.exe [10945776 2017-12-15] (TeamViewer GmbH)
S2 butyjuqy; C:\Program Files\03000200-1439137894-0500-0006-000700080009\knsd860A.tmp [X] <==== ATTENTION
S2 comyninu; C:\Program Files\03000200-1439137894-0500-0006-000700080009\hnsf4A4.tmp [X] <==== ATTENTION
S2 hyverumu; C:\Program Files\03000200-1439137894-0500-0006-000700080009\jnsqECB5.tmp [X] <==== ATTENTION
S2 Mobizen plugin; C:\Program Files\RSUPPORT\MobizenService\MobizenService.exe [X]
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 acedrv11; C:\Windows\system32\drivers\acedrv11.sys [185472 2010-02-24] (Protect Software GmbH)
R2 BstHdDrv; C:\Program Files\BlueStacks\HD-Hypervisor-x86.sys [112856 2015-03-03] (BlueStack Systems)
R0 cm_km; C:\Windows\System32\DRIVERS\cm_km.sys [176864 2016-12-26] (AO Kaspersky Lab)
S3 dtlitescsibus; C:\Windows\System32\DRIVERS\dtlitescsibus.sys [26168 2017-10-31] (Disc Soft Ltd)
S3 dtliteusbbus; C:\Windows\System32\DRIVERS\dtliteusbbus.sys [40504 2017-10-31] (Disc Soft Ltd)
R3 dtproscsibus; C:\Windows\System32\DRIVERS\dtproscsibus.sys [26168 2017-11-01] (Disc Soft Ltd)
R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [165296 2016-10-01] (AO Kaspersky Lab)
R0 klbackupdisk; C:\Windows\System32\DRIVERS\klbackupdisk.sys [62184 2017-12-24] (AO Kaspersky Lab)
R1 klbackupflt; C:\Windows\System32\DRIVERS\klbackupflt.sys [98496 2018-04-21] (AO Kaspersky Lab)
R2 kldisk; C:\Windows\System32\DRIVERS\kldisk.sys [69000 2016-05-31] (AO Kaspersky Lab)
R3 klflt; C:\Windows\System32\DRIVERS\klflt.sys [164056 2018-04-21] (AO Kaspersky Lab)
R1 klhk; C:\Windows\System32\DRIVERS\klhk.sys [229592 2018-04-21] (AO Kaspersky Lab)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [835784 2018-04-21] (AO Kaspersky Lab)
R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [50888 2018-04-21] (AO Kaspersky Lab)
R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [50400 2016-12-23] (AO Kaspersky Lab)
R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [51424 2016-12-07] (AO Kaspersky Lab)
R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [45552 2017-12-24] (AO Kaspersky Lab)
R3 kltap; C:\Windows\System32\DRIVERS\kltap.sys [48056 2016-06-07] (The OpenVPN Project)
R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [75760 2017-12-24] (AO Kaspersky Lab)
R1 Klwtp; C:\Windows\System32\DRIVERS\klwtp.sys [120544 2017-12-24] (AO Kaspersky Lab)
R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [165088 2017-12-24] (AO Kaspersky Lab)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad32v.sys [34080 2013-12-27] (NVIDIA Corporation)
S3 KProcessHacker2; \??\C:\Program Files\kprocesshacker.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
S3 XDva409; \??\C:\Windows\system32\XDva409.sys [X]
S3 XDva410; \??\C:\Windows\system32\XDva410.sys [X]
S3 XDva415; \??\C:\Windows\system32\XDva415.sys [X]
S3 XDva423; \??\C:\Windows\system32\XDva423.sys [X]
S3 XDva424; \??\C:\Windows\system32\XDva424.sys [X]
S3 XDva425; \??\C:\Windows\system32\XDva425.sys [X]
S3 XDva511; \??\C:\Windows\system32\XDva511.sys [X]
S3 XDva534; \??\C:\Windows\system32\XDva534.sys [X]
S3 XDva535; \??\C:\Windows\system32\XDva535.sys [X]
S3 XDva536; \??\C:\Windows\system32\XDva536.sys [X]
S3 XDva537; \??\C:\Windows\system32\XDva537.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2018-04-22 08:41 - 2018-04-22 08:44 - 000021261 _____ C:\Users\Admin\Desktop\FRST.txt
2018-04-22 08:40 - 2018-04-22 08:41 - 000000000 ____D C:\FRST
2018-04-22 08:40 - 2018-04-22 08:40 - 000000000 ____D C:\Users\Admin\Desktop\FRST-OlderVersion
2018-04-22 08:39 - 2018-04-22 08:40 - 001764864 _____ (Farbar) C:\Users\Admin\Desktop\FRST.exe
2018-04-22 08:39 - 2018-04-22 08:39 - 001753600 _____ (Farbar) C:\Users\Admin\Downloads\FRST.exe
2018-04-21 17:08 - 2018-04-21 17:08 - 014178840 _____ (Malwarebytes Corp.) C:\Users\Admin\Downloads\mbar-1.10.3.1001.exe
2018-04-21 16:42 - 2018-04-21 16:47 - 000090479 _____ C:\Users\Admin\Downloads\avira_registry_cleaner_en.zip
2018-04-21 15:08 - 2018-04-21 15:08 - 042808440 _____ (Microsoft Corporation) C:\Users\Admin\Downloads\Windows-KB890830-V5.59 (1).exe
2018-04-21 15:07 - 2018-04-21 15:08 - 042808440 _____ (Microsoft Corporation) C:\Users\Admin\Downloads\Windows-KB890830-V5.59.exe
2018-04-21 10:30 - 2018-04-21 10:30 - 000001206 _____ C:\Users\Public\Desktop\Kaspersky Secure Connection.lnk
2018-04-21 10:30 - 2018-04-21 10:30 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Secure Connection
2018-04-21 10:28 - 2018-04-21 10:28 - 000000000 ____D C:\Program Files\Common Files\AV
2018-04-21 10:27 - 2018-04-21 10:27 - 000262144 _____ C:\Windows\system32\config\ELAM
2018-04-21 10:27 - 2018-04-21 10:27 - 000002053 _____ C:\Users\Public\Desktop\Kaspersky Anti-Virus.lnk
2018-04-21 10:27 - 2018-04-21 10:27 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Anti-Virus
2018-04-21 10:26 - 2018-04-22 08:35 - 000000000 ____D C:\ProgramData\Kaspersky Lab
2018-04-21 10:26 - 2018-04-21 10:47 - 000835784 _____ (AO Kaspersky Lab) C:\Windows\system32\Drivers\klif.sys
2018-04-21 10:26 - 2018-04-21 10:30 - 000000000 ____D C:\Program Files\Kaspersky Lab
2018-04-21 10:26 - 2018-04-21 10:26 - 000229592 _____ (AO Kaspersky Lab) C:\Windows\system32\Drivers\klhk.sys
2018-04-21 10:26 - 2018-04-21 10:26 - 000164056 _____ (AO Kaspersky Lab) C:\Windows\system32\Drivers\klflt.sys
2018-04-21 09:54 - 2018-04-21 10:21 - 000000000 ____D C:\ProgramData\Kaspersky Lab Setup Files
2018-04-21 09:49 - 2018-04-21 09:50 - 000012148 _____ C:\Users\Admin\Downloads\Kaspersky.Anti-Virus+Internet.Security+Total.Security.2017.17.0.0.611.0.1709.0-FiLELiST.torrent
2018-04-15 14:58 - 2018-03-31 04:39 - 004046528 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2018-04-15 14:58 - 2018-03-31 04:39 - 003958464 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2018-04-15 14:58 - 2018-03-31 04:39 - 000190144 _____ (Microsoft Corporation) C:\Windows\system32\halmacpi.dll
2018-04-15 14:58 - 2018-03-31 04:39 - 000190144 _____ (Microsoft Corporation) C:\Windows\system32\hal.dll
2018-04-15 14:58 - 2018-03-31 04:39 - 000137920 _____ (Microsoft Corporation) C:\Windows\system32\halacpi.dll
2018-04-15 14:58 - 2018-03-31 04:39 - 000137920 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2018-04-15 14:58 - 2018-03-31 04:39 - 000067264 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2018-04-15 14:58 - 2018-03-31 04:12 - 001310480 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2018-04-15 14:58 - 2018-03-31 04:09 - 001063424 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2018-04-15 14:58 - 2018-03-31 04:09 - 000690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2018-04-15 14:58 - 2018-03-31 04:09 - 000655360 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2018-04-15 14:58 - 2018-03-31 04:09 - 000644096 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2018-04-15 14:58 - 2018-03-31 04:09 - 000554496 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2018-04-15 14:58 - 2018-03-31 04:09 - 000400896 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2018-04-15 14:58 - 2018-03-31 04:09 - 000261120 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2018-04-15 14:58 - 2018-03-31 04:09 - 000254464 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2018-04-15 14:58 - 2018-03-31 04:09 - 000223232 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2018-04-15 14:58 - 2018-03-31 04:09 - 000172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2018-04-15 14:58 - 2018-03-31 04:09 - 000146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2018-04-15 14:58 - 2018-03-31 04:09 - 000141312 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll
2018-04-15 14:58 - 2018-03-31 04:09 - 000099840 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2018-04-15 14:58 - 2018-03-31 04:09 - 000082432 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll
2018-04-15 14:58 - 2018-03-31 04:09 - 000070144 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2018-04-15 14:58 - 2018-03-31 04:09 - 000060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2018-04-15 14:58 - 2018-03-31 04:09 - 000050688 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2018-04-15 14:58 - 2018-03-31 04:09 - 000050176 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2018-04-15 14:58 - 2018-03-31 04:09 - 000043008 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2018-04-15 14:58 - 2018-03-31 04:09 - 000038912 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2018-04-15 14:58 - 2018-03-31 04:09 - 000022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2018-04-15 14:58 - 2018-03-31 04:09 - 000017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2018-04-15 14:58 - 2018-03-31 04:09 - 000007168 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2018-04-15 14:58 - 2018-03-31 03:51 - 000097792 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2018-04-15 14:58 - 2018-03-31 03:51 - 000050688 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2018-04-15 14:58 - 2018-03-31 03:51 - 000050688 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2018-04-15 14:58 - 2018-03-31 03:51 - 000029696 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2018-04-15 14:58 - 2018-03-31 03:51 - 000016896 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2018-04-15 14:58 - 2018-03-31 03:49 - 000262656 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2018-04-15 14:58 - 2018-03-31 03:49 - 000107520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\videoprt.sys
2018-04-15 14:58 - 2018-03-31 03:47 - 000226304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2018-04-15 14:58 - 2018-03-31 03:47 - 000124928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2018-04-15 14:58 - 2018-03-31 03:47 - 000098304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2018-04-15 14:58 - 2018-03-31 03:47 - 000069632 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2018-04-15 14:58 - 2018-03-31 03:47 - 000036352 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2018-04-15 14:58 - 2018-03-31 03:47 - 000022016 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2018-04-15 14:58 - 2018-03-31 03:47 - 000015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2018-04-15 14:58 - 2018-03-28 10:18 - 002404352 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2018-04-15 14:58 - 2018-03-23 20:59 - 000348824 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2018-04-15 14:58 - 2018-03-23 00:26 - 020287488 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2018-04-15 14:58 - 2018-03-23 00:04 - 002724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2018-04-15 14:58 - 2018-03-23 00:04 - 000004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2018-04-15 14:58 - 2018-03-22 23:52 - 000499712 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2018-04-15 14:58 - 2018-03-22 23:52 - 000062464 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2018-04-15 14:58 - 2018-03-22 23:51 - 000341504 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2018-04-15 14:58 - 2018-03-22 23:51 - 000047616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2018-04-15 14:58 - 2018-03-22 23:50 - 000064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2018-04-15 14:58 - 2018-03-22 23:48 - 002295296 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2018-04-15 14:58 - 2018-03-22 23:45 - 000047104 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2018-04-15 14:58 - 2018-03-22 23:45 - 000030720 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2018-04-15 14:58 - 2018-03-22 23:43 - 000476160 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2018-04-15 14:58 - 2018-03-22 23:42 - 000661504 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2018-04-15 14:58 - 2018-03-22 23:42 - 000115712 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2018-04-15 14:58 - 2018-03-22 23:42 - 000104960 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2018-04-15 14:58 - 2018-03-22 23:41 - 000620032 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2018-04-15 14:58 - 2018-03-22 23:36 - 000668160 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2018-04-15 14:58 - 2018-03-22 23:33 - 000416256 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2018-04-15 14:58 - 2018-03-22 23:29 - 000060416 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2018-04-15 14:58 - 2018-03-22 23:28 - 000091136 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2018-04-15 14:58 - 2018-03-22 23:28 - 000073216 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2018-04-15 14:58 - 2018-03-22 23:25 - 000168960 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2018-04-15 14:58 - 2018-03-22 23:25 - 000076288 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2018-04-15 14:58 - 2018-03-22 23:24 - 000279040 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2018-04-15 14:58 - 2018-03-22 23:22 - 000130048 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2018-04-15 14:58 - 2018-03-22 23:21 - 004496896 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2018-04-15 14:58 - 2018-03-22 23:20 - 013680128 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2018-04-15 14:58 - 2018-03-22 23:17 - 000230400 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2018-04-15 14:58 - 2018-03-22 23:15 - 000696320 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2018-04-15 14:58 - 2018-03-22 23:15 - 000692224 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2018-04-15 14:58 - 2018-03-22 23:14 - 002059776 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2018-04-15 14:58 - 2018-03-22 23:14 - 001155072 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2018-04-15 14:58 - 2018-03-22 22:55 - 002767872 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2018-04-15 14:58 - 2018-03-22 22:52 - 001313792 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2018-04-15 14:58 - 2018-03-22 22:51 - 000710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2018-04-15 14:58 - 2018-03-10 20:11 - 000340480 _____ (Microsoft Corporation) C:\Windows\system32\msexcl40.dll
2018-04-15 14:58 - 2018-03-09 21:18 - 000309440 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2018-04-15 14:58 - 2018-03-09 21:12 - 000111616 _____ (Microsoft Corporation) C:\Windows\system32\t2embed.dll
2018-04-15 14:58 - 2018-03-09 21:12 - 000071680 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2018-04-15 14:58 - 2018-03-09 21:12 - 000026112 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2018-04-15 14:58 - 2018-03-09 21:11 - 000010240 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2018-04-15 14:58 - 2018-03-09 20:31 - 000034304 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2018-04-15 14:58 - 2018-03-06 21:13 - 000148160 _____ (Microsoft Corporation) C:\Windows\system32\basecsp.dll
2018-04-15 14:58 - 2018-03-06 21:11 - 000184320 _____ (Microsoft Corporation) C:\Windows\system32\scksp.dll
2018-04-15 14:58 - 2018-03-06 21:11 - 000052224 _____ (Microsoft Corporation) C:\Windows\system32\wsnmp32.dll
2018-04-15 14:58 - 2018-02-22 06:06 - 000134656 _____ (Microsoft Corporation) C:\Windows\system32\WinSCard.dll
2018-04-15 14:58 - 2018-02-19 00:34 - 000535616 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
2018-04-15 14:58 - 2018-02-10 21:49 - 000162496 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msrpc.sys
2018-04-15 14:58 - 2018-02-10 21:49 - 000154304 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\pci.sys
2018-04-15 14:58 - 2018-02-10 21:49 - 000104640 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\NV_AGP.SYS
2018-04-15 14:58 - 2018-02-10 21:49 - 000057024 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ULIAGPKX.SYS
2018-04-15 14:58 - 2018-02-10 21:49 - 000053440 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\termdd.sys
2018-04-15 14:58 - 2018-02-10 21:49 - 000052928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\volmgr.sys
2018-04-15 14:58 - 2018-02-10 21:49 - 000052928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\VIAAGP.SYS
2018-04-15 14:58 - 2018-02-10 21:49 - 000051904 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\SISAGP.SYS
2018-04-15 14:58 - 2018-02-10 21:49 - 000046272 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\isapnp.sys
2018-04-15 14:58 - 2018-02-10 21:49 - 000032448 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\vdrvroot.sys
2018-04-15 14:58 - 2018-02-10 21:49 - 000027840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mssmbios.sys
2018-04-15 14:58 - 2018-02-10 21:49 - 000021696 _____ (Microsoft Corporation) C:\Windows\system32\streamci.dll
2018-04-15 14:58 - 2018-02-10 21:49 - 000013504 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msisadrv.sys
2018-04-15 14:58 - 2018-02-10 21:49 - 000011840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\swenum.sys
2018-04-15 14:58 - 2018-02-10 21:48 - 000274624 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\acpi.sys
2018-04-15 14:58 - 2018-02-10 21:48 - 000052928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\AMDAGP.SYS
2018-04-15 14:58 - 2018-02-10 21:48 - 000052928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\AGP440.sys
2018-04-15 14:58 - 2018-02-10 21:23 - 002292224 _____ (Microsoft Corporation) C:\Windows\system32\MSVidCtl.dll
2018-04-15 14:58 - 2018-02-10 21:23 - 000330240 _____ (Microsoft Corporation) C:\Windows\system32\zipfldr.dll
2018-04-15 14:58 - 2018-02-10 21:23 - 000111616 _____ (Microsoft Corporation) C:\Windows\system32\racpldlg.dll
2018-04-15 14:58 - 2018-02-10 21:23 - 000102912 _____ (Microsoft Corporation) C:\Windows\system32\msrahc.dll
2018-04-15 14:58 - 2018-02-10 20:36 - 000537600 _____ (Microsoft Corporation) C:\Windows\system32\msra.exe
2018-04-15 14:58 - 2018-02-10 20:36 - 000040960 _____ (Microsoft Corporation) C:\Windows\system32\sdchange.exe
2018-04-15 14:58 - 2018-02-10 20:36 - 000011264 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\wmiacpi.sys
2018-04-15 14:58 - 2018-02-10 20:36 - 000007168 _____ (Microsoft Corporation) C:\Windows\system32\MsraLegacy.tlb
2018-04-15 14:58 - 2018-02-10 20:36 - 000007168 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\errdev.sys
2018-04-15 14:58 - 2018-02-02 21:54 - 000105152 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2018-04-15 14:58 - 2018-02-02 21:29 - 002365952 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2018-04-15 14:58 - 2018-02-02 21:29 - 000337408 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll
2018-04-15 14:58 - 2018-02-02 21:29 - 000025088 _____ (Microsoft Corporation) C:\Windows\system32\msimsg.dll
2018-04-15 14:58 - 2018-02-02 21:28 - 001806848 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2018-04-15 14:58 - 2018-02-02 21:28 - 000047104 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll
2018-04-15 14:58 - 2018-02-02 20:46 - 000073216 _____ (Microsoft Corporation) C:\Windows\system32\msiexec.exe
2018-04-15 14:58 - 2018-01-25 17:04 - 000922944 _____ (Microsoft Corporation) C:\Windows\system32\ucrtbase.dll
2018-04-15 14:58 - 2018-01-25 17:04 - 000066392 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-private-l1-1-0.dll
2018-04-15 14:58 - 2018-01-25 17:04 - 000022360 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-math-l1-1-0.dll
2018-04-15 14:58 - 2018-01-25 17:04 - 000019800 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-multibyte-l1-1-0.dll
2018-04-15 14:58 - 2018-01-25 17:04 - 000017752 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-string-l1-1-0.dll
2018-04-15 14:58 - 2018-01-25 17:04 - 000017752 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-stdio-l1-1-0.dll
2018-04-15 14:58 - 2018-01-25 17:04 - 000016216 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-runtime-l1-1-0.dll
2018-04-15 14:58 - 2018-01-25 17:04 - 000015704 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-convert-l1-1-0.dll
2018-04-15 14:58 - 2018-01-25 17:04 - 000014168 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-time-l1-1-0.dll
2018-04-15 14:58 - 2018-01-25 17:04 - 000014168 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-2-0.dll
2018-04-15 14:58 - 2018-01-25 17:04 - 000013656 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll
2018-04-15 14:58 - 2018-01-25 17:04 - 000012632 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-process-l1-1-0.dll
2018-04-15 14:58 - 2018-01-25 17:04 - 000012632 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-heap-l1-1-0.dll
2018-04-15 14:58 - 2018-01-25 17:04 - 000012632 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-conio-l1-1-0.dll
2018-04-15 14:58 - 2018-01-25 17:04 - 000012120 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-utility-l1-1-0.dll
2018-04-15 14:58 - 2018-01-25 17:04 - 000012120 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-locale-l1-1-0.dll
2018-04-15 14:58 - 2018-01-25 17:04 - 000012120 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-environment-l1-1-0.dll
2018-04-15 14:58 - 2018-01-25 17:04 - 000012120 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-2-0.dll
2018-04-15 14:58 - 2018-01-25 17:04 - 000012120 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-1.dll
2018-04-15 14:58 - 2018-01-25 17:04 - 000011608 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l2-1-0.dll
2018-04-15 14:58 - 2018-01-25 17:04 - 000011608 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-timezone-l1-1-0.dll
2018-04-15 14:58 - 2018-01-25 17:04 - 000011608 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l2-1-0.dll
2018-04-15 14:58 - 2018-01-25 17:04 - 000011608 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-2-0.dll
2018-04-15 14:58 - 2018-01-15 22:40 - 000002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2018-04-15 14:58 - 2018-01-12 19:26 - 000308224 _____ (Microsoft Corporation) C:\Windows\system32\scesrv.dll
2018-04-15 14:54 - 2018-03-14 20:18 - 000116928 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe
2018-04-15 14:54 - 2018-03-14 20:14 - 000535040 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2018-04-15 14:54 - 2018-03-14 16:04 - 001893376 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe
2018-04-15 14:54 - 2018-03-14 16:04 - 001319424 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2018-04-15 14:54 - 2018-03-14 16:04 - 000594944 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2018-04-15 14:54 - 2018-03-14 16:04 - 000507392 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2018-04-15 14:54 - 2018-03-14 16:04 - 000338432 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2018-04-15 14:54 - 2018-03-14 16:04 - 000338432 _____ (Microsoft Corporation) C:\Windows\system32\centel.dll
2018-04-15 14:54 - 2018-03-14 16:04 - 000238592 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2018-04-15 14:54 - 2018-03-14 16:04 - 000190976 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2018-04-15 14:21 - 2018-04-15 14:21 - 000000000 ____D C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2018-04-10 12:49 - 2018-04-10 12:50 - 014479242 _____ C:\Users\Admin\Downloads\BPMOD_More_Cakes.zip
2018-04-08 14:42 - 2018-04-08 14:42 - 007892518 _____ C:\Users\Admin\Downloads\» L.O.L Sounds «.rar
2018-04-07 17:50 - 2018-04-21 10:17 - 000000000 ____D C:\Temp
2018-04-07 17:50 - 2012-05-07 04:30 - 033810432 _____ C:\Users\Admin\Desktop\Fancy Pants Adventure World 3.exe
2018-04-07 17:49 - 2018-04-07 17:49 - 045742105 _____ C:\Users\Admin\Downloads\Fancy Pants Adventure.rar
2018-04-07 17:44 - 2018-04-07 17:44 - 009427312 _____ C:\Users\Admin\Downloads\fancy_pants_adventure_world_2 (1).swf
2018-04-07 17:42 - 2018-04-07 17:42 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SWF File Player
2018-04-07 17:42 - 2018-04-07 17:42 - 000000000 ____D C:\Program Files\SWF File Player
2018-04-07 17:41 - 2018-04-07 17:41 - 000415159 _____ (swffileplayer.com ) C:\Users\Admin\Downloads\swffileplayer_setup.exe
2018-04-07 17:40 - 2018-04-07 17:41 - 001718640 _____ C:\Users\Admin\Downloads\fancy_pants_adventure_world_1.swf
2018-04-07 17:39 - 2018-04-07 17:39 - 009427312 _____ C:\Users\Admin\Downloads\fancy_pants_adventure_world_2.swf
2018-04-07 15:07 - 2018-04-19 19:02 - 000001339 _____ C:\Users\Admin\Desktop\BadPiggies.lnk
2018-04-07 13:31 - 2018-04-07 13:31 - 000166903 _____ C:\Users\Admin\Downloads\BP-Requests3.contraptions.zip
2018-04-07 13:23 - 2018-04-07 13:23 - 014487397 _____ C:\Users\Admin\Downloads\BadPiggiesMOD.18.08.2014.zip
2018-04-07 13:09 - 2018-04-07 13:09 - 000000000 ____D C:\Users\Admin\AppData\LocalLow\Rovio
2018-04-07 13:07 - 2018-04-07 13:07 - 042551756 _____ C:\Users\Admin\Downloads\Bad Piggies Hack Islender.zip
2018-04-05 17:53 - 2018-04-05 18:02 - 000002824 _____ C:\Users\Admin\Downloads\Opening Undefeatable Chests! Drakensang Online.mp4.sfk
2018-04-05 17:53 - 2018-04-05 17:53 - 000411982 _____ C:\Users\Admin\Downloads\Opening Undefeatable Chests! Drakensang Online.mp4
2018-04-05 17:49 - 2018-04-05 17:50 - 000086888 _____ C:\Users\Admin\Downloads\Devwa - LEVEL 55!! [Finally] Drakensang Online.mp4.sfk
2018-04-05 17:49 - 2018-04-05 17:49 - 009164819 _____ C:\Users\Admin\Downloads\Devwa - LEVEL 55!! [Finally] Drakensang Online.mp4
2018-04-05 17:47 - 2018-04-05 17:48 - 000004200 _____ C:\Users\Admin\Downloads\How To Trick People You Have Lots of Money Drakensang Online.mp4.sfk
2018-04-05 17:47 - 2018-04-05 17:47 - 000195843 _____ C:\Users\Admin\Downloads\How To Trick People You Have Lots of Money Drakensang Online.mp4
2018-04-05 17:46 - 2018-04-05 17:46 - 000509847 _____ C:\Users\Admin\Downloads\Armor Comparision Drakensang Online (1).mp4
2018-04-05 17:46 - 2018-04-05 17:46 - 000004200 _____ C:\Users\Admin\Downloads\Armor Comparision Drakensang Online (1).mp4.sfk
2018-04-05 17:44 - 2018-04-05 17:44 - 000509847 _____ C:\Users\Admin\Downloads\Armor Comparision Drakensang Online.mp4
2018-04-05 17:42 - 2018-04-05 17:42 - 000004200 _____ C:\Users\Admin\Downloads\I GOT PROXIMA! Marvel Future Fight.mp4.sfk
2018-04-05 17:41 - 2018-04-05 17:41 - 001504875 _____ C:\Users\Admin\Downloads\I GOT PROXIMA! Marvel Future Fight.mp4
2018-04-05 17:37 - 2018-04-05 17:38 - 000004200 _____ C:\Users\Admin\Downloads\HAPPY NEW YEAR.mp4.sfk
2018-04-05 17:37 - 2018-04-05 17:37 - 000291376 _____ C:\Users\Admin\Downloads\HAPPY NEW YEAR.mp4
2018-04-05 17:34 - 2018-04-05 17:34 - 000683198 _____ C:\Users\Admin\Downloads\Shadow Fight 2 Beat Titan With Flame Clubs.mp4
2018-04-05 17:30 - 2018-04-05 17:30 - 000635222 _____ C:\Users\Admin\Downloads\Minecraft 1.101.111.12 How to get crazy enchantments.mp4
2018-04-05 17:27 - 2018-04-05 17:27 - 000674071 _____ C:\Users\Admin\Downloads\Drakensang Online Stellar Gold Event.mp4
2018-04-05 17:23 - 2018-04-05 17:23 - 000375925 _____ C:\Users\Admin\Downloads\Drakensang all bosses (Heredur-Medusa) (1).mp4
2018-04-05 17:22 - 2018-04-05 17:22 - 000001490 _____ C:\Users\Admin\Downloads\Drakensang all bosses (Heredur-Medusa).mp4
2018-04-04 19:54 - 2018-04-04 19:54 - 000008443 _____ C:\Users\Admin\Documents\Speedrun.lsl
2018-04-04 19:46 - 2018-04-04 19:46 - 000008442 _____ C:\Users\Admin\Documents\Layout.lsl
2018-04-04 19:42 - 2018-04-07 15:05 - 000006903 _____ C:\Users\Admin\Documents\Drakensang Online - World run.lss
2018-04-04 19:34 - 2018-04-04 19:34 - 000000911 _____ C:\Users\Admin\Desktop\LiveSplit.lnk
2018-04-04 19:30 - 2018-04-04 19:31 - 008791782 _____ C:\Users\Admin\Downloads\LiveSplit_1.7.5.zip
2018-04-03 16:57 - 2018-04-03 16:57 - 000121320 _____ C:\Users\Admin\Downloads\Crash.Time.III-SKIDROW (1).torrent
2018-04-01 16:05 - 2018-04-01 16:06 - 000000000 ____D C:\Users\Admin\AppData\Local\Temporary Projects
2018-03-31 19:07 - 2018-03-31 19:07 - 001834563 _____ C:\Users\Admin\Downloads\MTS_weerbesu_1729947_UI_Cheats_Extension_v1.10.zip
2018-03-30 15:04 - 2018-04-03 15:33 - 000001981 _____ C:\Users\Public\Desktop\Action!.lnk
2018-03-29 17:50 - 2018-03-29 17:50 - 000357269 _____ C:\Users\Admin\Downloads\Generator v2.0.117.zip
2018-03-29 17:50 - 2018-01-01 21:08 - 000393216 _____ () C:\Users\Admin\Desktop\Generator v2.0.117.exe
2018-03-29 17:48 - 2018-03-29 17:48 - 000731370 _____ C:\Users\Admin\Downloads\Woop woop (1).zip
2018-03-29 17:35 - 2018-04-19 19:05 - 000000000 ____D C:\Users\Admin\Desktop\Even More Stuff
2018-03-27 20:08 - 2018-03-27 20:08 - 000050734 _____ C:\Users\Admin\Downloads\Jazzy Note Blocks By Aaron Grooves (Animation vs. Minecraft Music).mp3.mid
2018-03-26 20:19 - 2018-03-26 20:19 - 000008719 _____ C:\Users\Admin\Downloads\5026403-AVM_Shorts_Episode_5_-_Song_4_Jazzy_Note_Blocks.mid
2018-03-26 20:18 - 2018-03-26 20:18 - 000005344 _____ C:\Users\Admin\Downloads\5024159-Jazzy_Note_Blocks.mid
2018-03-25 18:05 - 2018-03-25 18:04 - 000000954 _____ C:\Users\Admin\Desktop\SimCitySocieties.lnk
2018-03-25 12:45 - 2018-03-25 18:27 - 000000000 ____D C:\Users\Admin\Documents\SimCity Societies
2018-03-25 12:45 - 2018-03-25 12:51 - 000000000 ____D C:\ProgramData\SimCity Societies
2018-03-25 12:42 - 2018-03-25 12:42 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Electronic Arts
2018-03-25 12:18 - 2018-04-21 09:50 - 000000000 ____D C:\Users\Admin\AppData\LocalLow\uTorrent
2018-03-25 12:18 - 2018-03-25 12:18 - 000000831 _____ C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\µTorrent.lnk
2018-03-25 12:03 - 2018-03-25 12:03 - 000016511 _____ C:\Users\Admin\Downloads\Simcity.Societies.Deluxe-RELOADED.torrent