Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 11-07-2017
Ran by ChristopherAubert (administrator) on CHRISTOPHERPC (11-07-2017 19:39:29)
Running from C:\Users\Christopher\Desktop
Loaded Profiles: ChristopherAubert (Available Profiles: ChristopherAubert)
Platform: Windows 10 Pro Version 1703 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
() C:\Program Files (x86)\ASUS\AXSP\1.01.02\atkexComSvc.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome Remote Desktop\59.0.3071.47\remoting_host.exe
(LogMeIn, Inc.) C:\Program Files (x86)\LogMeIn Hamachi\x64\LMIGuardianSvc.exe
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\x64\hamachi-2.exe
(Broadcom Corporation.) C:\Windows\System32\BtwRSupportService.exe
() C:\Windows\System32\PnkBstrA.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
(Razer Inc.) C:\Program Files (x86)\Razer Chroma SDK\bin\RzSDKServer.exe
(Electronic Arts) C:\Program Files (x86)\Origin\OriginWebHelperService.exe
(Razer Inc.) C:\Program Files (x86)\Razer Chroma SDK\bin\RzSDKService.exe
() C:\Windows\runSW.exe
() C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Realtek) C:\Windows\SwUSB.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome Remote Desktop\59.0.3071.47\remoting_host.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_w32.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_x64.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler64.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
() C:\Program Files (x86)\puush\puush.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\ShadowPlay\nvspcaps64.exe
(Spotify Ltd) C:\Users\Christopher\AppData\Roaming\Spotify\SpotifyWebHelper.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\ShadowPlay\nvsphelper64.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe
(Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\OFFICE15\CSISYNCCLIENT.EXE
(Google) C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(Disc Soft Ltd) C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Google Inc.) C:\Users\Christopher\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Christopher\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Christopher\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Christopher\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Christopher\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Christopher\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Christopher\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Christopher\AppData\Local\Google\Chrome\Application\chrome.exe
(Wondershare) C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office\Office15\ONENOTEM.EXE
() C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.18.614.0_x64__kzf8qxf38zg5c\SkypeHost.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
() C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2017.18062.13720.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
() C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.17054.14711.0_x64__8wekyb3d8bbwe\Video.UI.exe
(Google Inc.) C:\Users\Christopher\AppData\Local\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\Taskmgr.exe
(Google Inc.) C:\Users\Christopher\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Christopher\AppData\Local\Google\Chrome\Application\chrome.exe
(Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
(Google Inc.) C:\Users\Christopher\AppData\Local\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [629152 2017-03-18] (Microsoft Corporation)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8492800 2015-06-24] (Realtek Semiconductor)
HKLM\...\Run: [ShadowPlay] => "C:\Windows\system32\rundll32.exe" C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [322472 2015-06-23] (Intel Corporation)
HKLM-x32\...\Run: [Razer Synapse] => C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe [596640 2017-04-13] (Razer Inc.)
HKLM-x32\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2087264 2014-09-11] (Wondershare)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2017-03-15] (Oracle Corporation)
HKLM-x32\...\Run: [cpx] => "C:\Users\Christopher\AppData\Local\ntuserlitelist\cpx\cpx.exe" -starup <==== ATTENTION
HKLM-x32\...\Run: [svcvmx] => C:\Users\Christopher\AppData\Local\ntuserlitelist\svcvmx\svcvmx.exe [884224 2017-04-21] ()
HKLM-x32\...\Run: [LogMeIn Hamachi Ui] => C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [5885352 2017-06-29] (LogMeIn Inc.)
HKU\S-1-5-21-3319825686-2643767977-2016650390-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3062048 2017-07-06] (Valve Corporation)
HKU\S-1-5-21-3319825686-2643767977-2016650390-1001\...\Run: [puush] => C:\Program Files (x86)\puush\puush.exe [568904 2015-06-27] ()
HKU\S-1-5-21-3319825686-2643767977-2016650390-1001\...\Run: [Spotify Web Helper] => C:\Users\Christopher\AppData\Roaming\Spotify\SpotifyWebHelper.exe [1560176 2017-06-16] (Spotify Ltd)
HKU\S-1-5-21-3319825686-2643767977-2016650390-1001\...\Run: [GoogleDriveSync] => C:\Program Files (x86)\Google\Drive\googledrivesync.exe [23819304 2017-03-21] (Google)
HKU\S-1-5-21-3319825686-2643767977-2016650390-1001\...\Run: [DAEMON Tools Lite Automount] => C:\Program Files\DAEMON Tools Lite\DTAgent.exe [4299968 2016-06-22] (Disc Soft Ltd)
HKU\S-1-5-21-3319825686-2643767977-2016650390-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [27716568 2017-05-04] (Skype Technologies S.A.)
HKU\S-1-5-21-3319825686-2643767977-2016650390-1001\...\Run: [Google Update] => C:\Users\Christopher\AppData\Local\Google\Update\1.3.33.5\GoogleUpdateCore.exe [601168 2017-07-10] (Google Inc.)
HKU\S-1-5-21-3319825686-2643767977-2016650390-1001\...\Run: [GoogleChromeAutoLaunch_D3EE6E7DA0645F6660E47697F62AE98F] => C:\Users\Christopher\AppData\Local\Google\Chrome\Application\chrome.exe [1197912 2017-06-22] (Google Inc.)
HKU\S-1-5-21-3319825686-2643767977-2016650390-1001\...\MountPoints2: {e3eead84-1858-11e5-825a-fcaa1445223f} - "F:\WD Drive Unlock.exe" autoplay=true
Startup: C:\Users\Christopher\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Send to OneNote.lnk [2017-04-26]
ShortcutTarget: Send to OneNote.lnk -> C:\Program Files\Microsoft Office\Office15\ONENOTEM.EXE (Microsoft Corporation)
GroupPolicy: Restriction <==== ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
ProxyEnable: [.DEFAULT] => Proxy is enabled.
ProxyServer: [.DEFAULT] => 127.0.0.1:8003
ProxyEnable: [S-1-5-19] => Proxy is enabled.
ProxyServer: [S-1-5-19] => 127.0.0.1:8003
ProxyEnable: [S-1-5-20] => Proxy is enabled.
ProxyServer: [S-1-5-20] => 127.0.0.1:8003
ProxyServer: [S-1-5-21-3319825686-2643767977-2016650390-1001] => 127.0.0.1:8003
Hosts: 37.139.50.192
www.gstatic.com
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{032803e0-8e3d-4074-a603-13ce2fa6be1f}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{0e7e2cbf-86ca-44b6-b78b-34cd497e6b20}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{2ec9c44c-b42e-42ee-b564-0a3a66d30bda}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{401984dc-3453-4b14-8465-91d94fd40f52}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{83a64d07-af5e-4ba9-bfca-81ea87f11111}: [DhcpNameServer] 192.168.0.1
Tcpip\..\Interfaces\{d69afc5f-c2e7-42a4-9c58-5c7adbe54b90}: [DhcpNameServer] 192.168.0.1
Internet Explorer:
==================
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2017-02-23] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_131\bin\ssv.dll [2017-04-30] (Oracle Corporation)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2017-02-23] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_131\bin\jp2ssv.dll [2017-04-30] (Oracle Corporation)
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2016-05-17] (Microsoft Corporation)
FireFox:
========
FF DefaultProfile: 6wg7kf84.default
FF ProfilePath: C:\Users\Christopher\AppData\Roaming\Mozilla\Firefox\Profiles\6wg7kf84.default [2017-07-10]
FF Homepage: Mozilla\Firefox\Profiles\6wg7kf84.default -> msn.com
FF Extension: (Avira Browser Safety) - C:\Users\Christopher\AppData\Roaming\Mozilla\Firefox\Profiles\6wg7kf84.default\Extensions\abs@avira.com [2017-06-07]
FF Extension: (Chrome Store Foxified) - C:\Users\Christopher\AppData\Roaming\Mozilla\Firefox\Profiles\6wg7kf84.default\Extensions\Chrome-Store-Foxified@jetpack.xpi [2016-11-09]
FF Extension: (Twitch Now) - C:\Users\Christopher\AppData\Roaming\Mozilla\Firefox\Profiles\6wg7kf84.default\Extensions\jid1-jwVSihNsgAw5jA@jetpack.xpi [2016-10-30]
FF Extension: (FrankerFaceZ) - C:\Users\Christopher\AppData\Roaming\Mozilla\Firefox\Profiles\6wg7kf84.default\Extensions\jid1-snHdAu6px3p0jA@jetpack.xpi [2016-11-19]
FF Extension: (Adblock Plus) - C:\Users\Christopher\AppData\Roaming\Mozilla\Firefox\Profiles\6wg7kf84.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-11-23]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_26_0_0_137.dll [2017-07-11] ()
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~1\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.2.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-04-16] (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_26_0_0_137.dll [2017-07-11] ()
FF Plugin-x32: @esn/esnlaunch,version=2.3.0 -> C:\Program Files (x86)\Battlelog Web Plugins\2.3.0\npesnlaunch.dll [2013-09-16] (ESN Social Software AB)
FF Plugin-x32: @java.com/DTPlugin,version=11.131.2 -> C:\Program Files (x86)\Java\jre1.8.0_131\bin\dtplugin\npDeployJava1.dll [2017-04-30] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.131.2 -> C:\Program Files (x86)\Java\jre1.8.0_131\bin\plugin2\npjp2.dll [2017-04-30] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL [2014-01-21] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-27] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-27] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-04-04] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-3319825686-2643767977-2016650390-1001: @citrixonline.com/appdetectorplugin -> C:\Users\Christopher\AppData\Local\Citrix\Plugins\104\npappdetector.dll [2016-08-30] (Citrix Online)
FF Plugin HKU\S-1-5-21-3319825686-2643767977-2016650390-1001: @tools.google.com/Google Update;version=3 -> C:\Users\Christopher\AppData\Local\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-07-10] (Google Inc.)
FF Plugin HKU\S-1-5-21-3319825686-2643767977-2016650390-1001: @tools.google.com/Google Update;version=9 -> C:\Users\Christopher\AppData\Local\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-07-10] (Google Inc.)
FF Plugin HKU\S-1-5-21-3319825686-2643767977-2016650390-1001: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Christopher\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2015-08-18] (Unity Technologies ApS)
FF Plugin HKU\S-1-5-21-3319825686-2643767977-2016650390-1001: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [2017-06-19] ()
Chrome:
=======
CHR HomePage: Default -> hxxps://
www.youtube.com/feed/subscriptions
CHR StartupUrls: Default -> "hxxp://msn.com/"
CHR Profile: C:\Users\Christopher\AppData\Local\Google\Chrome\User Data\Default [2017-07-11]
CHR Extension: (Google Translate) - C:\Users\Christopher\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb [2017-07-10]
CHR Extension: (Google Slides) - C:\Users\Christopher\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-07-10]
CHR Extension: (BetterTTV) - C:\Users\Christopher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ajopnjidmegmdimjlfnijceegpefgped [2017-07-10]
CHR Extension: (Google Docs) - C:\Users\Christopher\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-07-10]
CHR Extension: (Google Drive) - C:\Users\Christopher\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-07-10]
CHR Extension: (YouTube) - C:\Users\Christopher\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-07-10]
CHR Extension: (Adobe Acrobat) - C:\Users\Christopher\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2017-07-10]
CHR Extension: (Google Sheets) - C:\Users\Christopher\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-07-10]
CHR Extension: (Google Docs Offline) - C:\Users\Christopher\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-07-10]
CHR Extension: (AdBlock) - C:\Users\Christopher\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2017-07-10]
CHR Extension: (Kappa Everywhere - Global Twitch Emotes) - C:\Users\Christopher\AppData\Local\Google\Chrome\User Data\Default\Extensions\jafkphjeboadjffjfcigcdfdilpcacod [2017-07-10]
CHR Extension: (Auto HD For YouTube™) - C:\Users\Christopher\AppData\Local\Google\Chrome\User Data\Default\Extensions\koiaokdomkpjdgniimnkhgbilbjgpeak [2017-07-10]
CHR Extension: (Google Play) - C:\Users\Christopher\AppData\Local\Google\Chrome\User Data\Default\Extensions\komhbcfkdcgmcdoenjcjheifdiabikfi [2017-07-10]
CHR Extension: (Application Launcher for Drive (by Google)) - C:\Users\Christopher\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2017-07-10]
CHR Extension: (Google Play Books) - C:\Users\Christopher\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmimngoggfoobjdlefbcabngfnmieonb [2017-07-10]
CHR Extension: (Tom's Hardware - My Threads) - C:\Users\Christopher\AppData\Local\Google\Chrome\User Data\Default\Extensions\nddbmgcnelmmhlfibkmfnhnfeccaliip [2017-07-10]
CHR Extension: (Twitch Now) - C:\Users\Christopher\AppData\Local\Google\Chrome\User Data\Default\Extensions\nlmbdmpjmlijibeockamioakdpmhjnpk [2017-07-10]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Christopher\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-07-10]
CHR Extension: (Gmail) - C:\Users\Christopher\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-07-10]
CHR Extension: (Chrome Media Router) - C:\Users\Christopher\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-07-10]
CHR HKLM\...\Chrome\Extension: [ccbpbkebodcjkknkfkpmfeciinhidaeh] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-3319825686-2643767977-2016650390-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [ccbpbkebodcjkknkfkpmfeciinhidaeh] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
Opera:
=======
StartMenuInternet: (HKLM) OperaStable - C:\Program Files\Opera\Launcher.exe
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
"drmkpro64" => service could not be unlocked. <==== ATTENTION
R2 asComSvc; C:\Program Files (x86)\ASUS\AXSP\1.01.02\atkexComSvc.exe [936728 2013-07-03] ()
R2 BcmBtRSupport; C:\WINDOWS\system32\BtwRSupportService.exe [2297104 2015-10-12] (Broadcom Corporation.)
R2 chromoting; C:\Program Files (x86)\Google\Chrome Remote Desktop\59.0.3071.47\remoting_host.exe [71512 2017-05-09] (Google Inc.)
S2 Dataup; C:\Users\Christopher\AppData\Local\ntuserlitelist\dataup\dataup.exe [77824 2017-01-05] () [File not signed] <==== ATTENTION
R3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe [1467072 2016-06-22] (Disc Soft Ltd)
R2 Hamachi2Svc; C:\Program Files (x86)\LogMeIn Hamachi\x64\hamachi-2.exe [3418024 2017-06-29] (LogMeIn Inc.)
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [18856 2015-06-23] (Intel Corporation)
R2 igfxCUIService2.0.0.0; C:\Windows\system32\igfxCUIService.exe [373744 2016-11-01] (Intel Corporation)
R2 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn Hamachi\x64\LMIGuardianSvc.exe [419248 2016-05-27] (LogMeIn, Inc.)
R2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [495224 2017-06-21] (NVIDIA Corporation)
S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [495224 2017-06-21] (NVIDIA Corporation)
R2 NVDisplay.ContainerLocalSystem; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [462968 2017-06-07] (NVIDIA Corporation)
R2 NvTelemetryContainer; C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe [450168 2017-06-21] (NVIDIA Corporation)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [2168208 2017-06-15] (Electronic Arts)
R2 Origin Web Helper Service; C:\Program Files (x86)\Origin\OriginWebHelperService.exe [3148184 2017-06-15] (Electronic Arts)
R2 PnkBstrA; C:\Windows\system32\PnkBstrA.exe [76152 2015-12-05] ()
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2015-12-03] ()
R2 Razer Chroma SDK Server; C:\Program Files (x86)\Razer Chroma SDK\bin\RzSDKServer.exe [401024 2017-06-16] (Razer Inc.)
R2 Razer Chroma SDK Service; C:\Program Files (x86)\Razer Chroma SDK\bin\RzSDKService.exe [178824 2017-06-16] (Razer Inc.)
R2 Razer Game Scanner Service; C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe [189264 2016-09-24] ()
R2 RunSwUSB; C:\Windows\runSW.exe [44760 2014-12-12] ()
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [3913064 2017-07-03] (Microsoft Corporation)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [10885360 2017-05-31] (TeamViewer GmbH)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [342264 2017-03-18] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [102816 2017-06-20] (Microsoft Corporation)
S2 windowsmanagementservice; C:\Users\Christopher\AppData\Local\lqylpia\ykvvg\ct.exe [689664 2017-05-30] () [File not signed] <==== ATTENTION
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [15232 2013-07-03] ()
S3 bcbtums; C:\Windows\system32\drivers\bcbtums.sys [227144 2015-10-12] (Broadcom Corporation.)
S3 CMUSBDAC; C:\Windows\system32\DRIVERS\CMUSBDAC.sys [3778592 2015-11-26] (C-MEDIA)
S3 cpuz141; C:\Users\Christopher\AppData\Local\Temp\cpuz141\cpuz141_x64.sys [46400 2017-06-19] (CPUID) <==== ATTENTION
S3 dg_ssudbus; C:\Windows\system32\DRIVERS\ssudbus.sys [131712 2016-09-05] (Samsung Electronics Co., Ltd.)
R3 dtlitescsibus; C:\Windows\System32\drivers\dtlitescsibus.sys [30264 2016-07-11] (Disc Soft Ltd)
R3 dtliteusbbus; C:\Windows\System32\drivers\dtliteusbbus.sys [47672 2016-07-11] (Disc Soft Ltd)
S3 Hamachi; C:\Windows\System32\drivers\Hamdrv.sys [45680 2016-04-05] (LogMeIn Inc.)
R1 HWiNFO32; C:\WINDOWS\SysWOW64\drivers\HWiNFO64A.SYS [27552 2017-06-23] (REALiX(tm))
R3 nvlddmkm; C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_2d81f3535ced17c6\nvlddmkm.sys [14461344 2017-06-08] (NVIDIA Corporation)
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [30328 2017-06-21] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [48248 2017-06-21] (NVIDIA Corporation)
R3 nvvhci; C:\Windows\System32\drivers\nvvhci.sys [57792 2017-06-07] (NVIDIA Corporation)
S3 ptun0901; C:\Windows\System32\drivers\ptun0901.sys [27136 2016-04-21] (The OpenVPN Project)
R0 pwdrvio; C:\Windows\System32\pwdrvio.sys [19152 2013-09-30] ()
S3 pwdspio; C:\Windows\system32\pwdspio.sys [12504 2013-09-30] ()
R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [887552 2015-07-14] (Realtek )
S3 RTCore64; C:\Program Files (x86)\MSI Afterburner\RTCore64.sys [14024 2016-10-24] ()
R3 RtlWlanu; C:\Windows\System32\drivers\rtwlanu.sys [4635352 2015-07-03] (Realtek Semiconductor Corporation )
R3 rzendpt; C:\Windows\System32\drivers\rzendpt.sys [51736 2016-06-23] (Razer Inc)
R2 rzpmgrk; C:\WINDOWS\system32\drivers\rzpmgrk.sys [44144 2016-09-16] (Razer, Inc.)
R2 rzpnk; C:\WINDOWS\system32\drivers\rzpnk.sys [137840 2016-09-07] (Razer, Inc.)
S3 rzvkeyboard; C:\Windows\System32\drivers\rzvkeyboard.sys [43032 2016-04-08] (Razer Inc)
S3 SDFRd; C:\Windows\System32\drivers\SDFRd.sys [31128 2017-03-18] ()
S3 ssudmdm; C:\Windows\system32\DRIVERS\ssudmdm.sys [165504 2016-09-05] (Samsung Electronics Co., Ltd.)
U3 TrueSight; C:\Windows\System32\drivers\TrueSight.sys [28272 2017-07-11] ()
S3 VBAudioVACMME; C:\Windows\system32\DRIVERS\vbaudio_cable64_win7.sys [41192 2014-09-02] (Windows (R) Win 7 DDK provider)
S3 VBAudioVMVAIOMME; C:\Windows\system32\DRIVERS\vbaudio_vmvaio64_win7.sys [41192 2017-04-16] (Windows (R) Win 7 DDK provider)
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44632 2017-03-18] (Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [294816 2017-03-18] (Microsoft Corporation)
S3 wdm_usb; C:\Windows\system32\DRIVERS\usb2ser.sys [151184 2016-07-15] (MBB)
R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [121248 2017-03-18] (Microsoft Corporation)
S3 XtuAcpiDriver; C:\Windows\System32\drivers\XtuAcpiDriver.sys [63840 2015-07-10] (Intel Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-07-11 19:38 - 2017-07-11 19:38 - 02435584 _____ (Farbar) C:\Users\Christopher\Desktop\FRST64.exe
2017-07-11 19:34 - 2017-07-11 19:34 - 05766464 _____ (Zemana Ltd. ) C:\Users\Christopher\Desktop\eXplorer.exe
2017-07-11 19:30 - 2017-07-11 19:30 - 00004300 _____ C:\Users\Christopher\Desktop\Rkill.txt
2017-07-11 19:28 - 2017-07-11 19:28 - 02030536 _____ (Bleeping Computer, LLC) C:\Users\Christopher\Desktop\iExplore.exe
2017-07-11 18:20 - 2017-07-11 18:20 - 00003287 _____ C:\Users\Christopher\Desktop\AdwCleaner[C6].txt
2017-07-11 18:19 - 2017-07-11 18:19 - 00000000 ____D C:\Users\Christopher\AppData\Local\llssoft
2017-07-11 18:02 - 2017-07-11 18:02 - 00003397 _____ C:\Users\Christopher\Desktop\AdwCleaner Pre-Clean Log.txt
2017-07-11 17:30 - 2017-07-11 17:30 - 00000000 ___HD C:\OneDriveTemp
2017-07-11 17:28 - 2017-07-11 17:28 - 00034028 _____ C:\Users\Christopher\Desktop\rk_1796.tmp.txt
2017-07-11 16:39 - 2017-07-11 16:39 - 00028272 _____ C:\Windows\system32\Drivers\TrueSight.sys
2017-07-11 16:38 - 2017-07-11 16:38 - 00000000 ____D C:\ProgramData\RogueKiller
2017-07-11 16:38 - 2017-07-11 16:38 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RogueKiller
2017-07-11 16:38 - 2017-07-11 16:38 - 00000000 ____D C:\Program Files\RogueKiller
2017-07-11 12:59 - 2017-07-07 09:00 - 00947712 _____ (Microsoft Corporation) C:\Windows\system32\HoloSI.PCShell.dll
2017-07-11 12:59 - 2017-07-07 02:27 - 01147288 _____ (Microsoft Corporation) C:\Windows\system32\hvix64.exe
2017-07-11 12:59 - 2017-07-07 02:27 - 01024928 _____ (Microsoft Corporation) C:\Windows\system32\hvax64.exe
2017-07-11 12:59 - 2017-07-07 02:27 - 00965024 _____ (Microsoft Corporation) C:\Windows\system32\hvloader.efi
2017-07-11 12:59 - 2017-07-07 02:27 - 00821664 _____ (Microsoft Corporation) C:\Windows\system32\hvloader.exe
2017-07-11 12:59 - 2017-07-07 02:27 - 00750560 _____ (Microsoft Corporation) C:\Windows\system32\fontdrvhost.exe
2017-07-11 12:59 - 2017-07-07 02:26 - 01065104 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2017-07-11 12:59 - 2017-07-07 02:25 - 00899824 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe
2017-07-11 12:59 - 2017-07-07 02:24 - 00117664 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\pdc.sys
2017-07-11 12:59 - 2017-07-07 02:23 - 02399728 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2017-07-11 12:59 - 2017-07-07 02:22 - 08318880 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2017-07-11 12:59 - 2017-07-07 02:22 - 01186464 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
2017-07-11 12:59 - 2017-07-07 02:22 - 00119384 _____ (Microsoft Corporation) C:\Windows\system32\dmcmnutils.dll
2017-07-11 12:59 - 2017-07-07 02:21 - 32688336 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecsRaw.dll
2017-07-11 12:59 - 2017-07-07 02:21 - 02969880 _____ (Microsoft Corporation) C:\Windows\system32\CoreUIComponents.dll
2017-07-11 12:59 - 2017-07-07 02:20 - 02021680 _____ (Microsoft Corporation) C:\Windows\system32\wmpmde.dll
2017-07-11 12:59 - 2017-07-07 02:20 - 00923040 _____ (Microsoft Corporation) C:\Windows\system32\CoreMessaging.dll
2017-07-11 12:59 - 2017-07-07 02:20 - 00519584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys
2017-07-11 12:59 - 2017-07-07 02:20 - 00382368 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\clfs.sys
2017-07-11 12:59 - 2017-07-07 02:17 - 01017760 _____ (Microsoft Corporation) C:\Windows\system32\SecConfig.efi
2017-07-11 12:59 - 2017-07-07 02:15 - 02444696 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2017-07-11 12:59 - 2017-07-07 02:14 - 07325584 _____ (Microsoft Corporation) C:\Windows\system32\windows.storage.dll
2017-07-11 12:59 - 2017-07-07 02:14 - 05477088 _____ (Microsoft Corporation) C:\Windows\system32\OneCoreUAPCommonProxyStub.dll
2017-07-11 12:59 - 2017-07-07 02:14 - 01760264 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2017-07-11 12:59 - 2017-07-07 02:14 - 01171032 _____ (Microsoft Corporation) C:\Windows\system32\dcomp.dll
2017-07-11 12:59 - 2017-07-07 02:13 - 00872472 _____ (Microsoft Corporation) C:\Windows\system32\ClipSVC.dll
2017-07-11 12:59 - 2017-07-07 02:13 - 00554392 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBHUB3.SYS
2017-07-11 12:59 - 2017-07-07 02:13 - 00336320 _____ (Microsoft Corporation) C:\Windows\system32\SecurityHealthService.exe
2017-07-11 12:59 - 2017-07-07 02:13 - 00147800 _____ (Microsoft Corporation) C:\Windows\system32\Clipc.dll
2017-07-11 12:59 - 2017-07-07 02:12 - 00411040 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2017-07-11 12:59 - 2017-07-07 02:12 - 00318232 _____ (Microsoft Corporation) C:\Windows\system32\wininit.exe
2017-07-11 12:59 - 2017-07-07 02:12 - 00228256 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2017-07-11 12:59 - 2017-07-07 02:11 - 07904784 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Protection.PlayReady.dll
2017-07-11 12:59 - 2017-07-07 02:11 - 00094624 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll
2017-07-11 12:59 - 2017-07-07 02:10 - 21353208 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2017-07-11 12:59 - 2017-07-07 02:10 - 01670496 _____ (Microsoft Corporation) C:\Windows\system32\winmde.dll
2017-07-11 12:59 - 2017-07-07 02:10 - 01337848 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll
2017-07-11 12:59 - 2017-07-07 02:10 - 01325968 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll
2017-07-11 12:59 - 2017-07-07 02:10 - 00372128 _____ (Microsoft Corporation) C:\Windows\system32\CloudExperienceHost.dll
2017-07-11 12:59 - 2017-07-07 02:10 - 00254168 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll
2017-07-11 12:59 - 2017-07-07 02:09 - 00041376 _____ (Microsoft Corporation) C:\Windows\system32\wininitext.dll
2017-07-11 12:59 - 2017-07-07 02:08 - 02229152 _____ (Microsoft Corporation) C:\Windows\system32\AppVEntSubsystems64.dll
2017-07-11 12:59 - 2017-07-07 02:08 - 01854880 _____ (Microsoft Corporation) C:\Windows\system32\AppVEntVirtualization.dll
2017-07-11 12:59 - 2017-07-07 02:08 - 01693600 _____ (Microsoft Corporation) C:\Windows\system32\AppVIntegration.dll
2017-07-11 12:59 - 2017-07-07 02:08 - 01458584 _____ (Microsoft Corporation) C:\Windows\system32\AppVEntSubsystemController.dll
2017-07-11 12:59 - 2017-07-07 02:08 - 01100704 _____ (Microsoft Corporation) C:\Windows\system32\AppVPolicy.dll
2017-07-11 12:59 - 2017-07-07 02:08 - 00992672 _____ (Microsoft Corporation) C:\Windows\system32\AppVManifest.dll
2017-07-11 12:59 - 2017-07-07 02:08 - 00848280 _____ (Microsoft Corporation) C:\Windows\system32\AppVOrchestration.dll
2017-07-11 12:59 - 2017-07-07 02:08 - 00846752 _____ (Microsoft Corporation) C:\Windows\system32\AppVClient.exe
2017-07-11 12:59 - 2017-07-07 02:08 - 00844704 _____ (Microsoft Corporation) C:\Windows\system32\AppVEntStreamingManager.dll
2017-07-11 12:59 - 2017-07-07 02:08 - 00774560 _____ (Microsoft Corporation) C:\Windows\system32\AppVReporting.dll
2017-07-11 12:59 - 2017-07-07 02:08 - 00699808 _____ (Microsoft Corporation) C:\Windows\system32\AppVCatalog.dll
2017-07-11 12:59 - 2017-07-07 02:08 - 00672672 _____ (Microsoft Corporation) C:\Windows\system32\AppVPublishing.dll
2017-07-11 12:59 - 2017-07-07 02:08 - 00506776 _____ (Microsoft Corporation) C:\Windows\system32\TransportDSA.dll
2017-07-11 12:59 - 2017-07-07 02:08 - 00399264 _____ (Microsoft Corporation) C:\Windows\system32\AppVScripting.dll
2017-07-11 12:59 - 2017-07-07 02:07 - 01106848 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys
2017-07-11 12:59 - 2017-07-07 02:07 - 00058488 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2017-07-11 12:59 - 2017-07-07 01:57 - 00626528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontdrvhost.exe
2017-07-11 12:59 - 2017-07-07 01:57 - 00125344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dwmapi.dll
2017-07-11 12:59 - 2017-07-07 01:40 - 23677440 _____ (Microsoft Corporation) C:\Windows\system32\edgehtml.dll
2017-07-11 12:59 - 2017-07-07 01:39 - 01839872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2017-07-11 12:59 - 2017-07-07 01:39 - 00096128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dmcmnutils.dll
2017-07-11 12:59 - 2017-07-07 01:37 - 31652264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecsRaw.dll
2017-07-11 12:59 - 2017-07-07 01:37 - 02259760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CoreUIComponents.dll
2017-07-11 12:59 - 2017-07-07 01:37 - 01339352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmpmde.dll
2017-07-11 12:59 - 2017-07-07 01:31 - 05820984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\windows.storage.dll
2017-07-11 12:59 - 2017-07-07 01:31 - 01518088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2017-07-11 12:59 - 2017-07-07 01:31 - 00129184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2017-07-11 12:59 - 2017-07-07 01:30 - 02165752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2017-07-11 12:59 - 2017-07-07 01:30 - 00949920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dcomp.dll
2017-07-11 12:59 - 2017-07-07 01:30 - 00750496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WWAHost.exe
2017-07-11 12:59 - 2017-07-07 01:29 - 00349600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2017-07-11 12:59 - 2017-07-07 01:29 - 00123520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Clipc.dll
2017-07-11 12:59 - 2017-07-07 01:27 - 06759512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Protection.PlayReady.dll
2017-07-11 12:59 - 2017-07-07 01:27 - 03670016 _____ (Microsoft Corporation) C:\Windows\system32\win32kfull.sys
2017-07-11 12:59 - 2017-07-07 01:27 - 01640448 _____ (Microsoft Corporation) C:\Windows\system32\GdiPlus.dll
2017-07-11 12:59 - 2017-07-07 01:27 - 01050624 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.dll
2017-07-11 12:59 - 2017-07-07 01:27 - 00859136 _____ (Microsoft Corporation) C:\Windows\system32\uDWM.dll
2017-07-11 12:59 - 2017-07-07 01:27 - 00577024 _____ (Microsoft Corporation) C:\Windows\system32\duser.dll
2017-07-11 12:59 - 2017-07-07 01:27 - 00557568 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2017-07-11 12:59 - 2017-07-07 01:27 - 00443392 _____ (Microsoft Corporation) C:\Windows\system32\PerceptionSimulationExtensions.dll
2017-07-11 12:59 - 2017-07-07 01:27 - 00360960 _____ (Microsoft Corporation) C:\Windows\system32\ConhostV2.dll
2017-07-11 12:59 - 2017-07-07 01:26 - 20373408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2017-07-11 12:59 - 2017-07-07 01:26 - 17364992 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.dll
2017-07-11 12:59 - 2017-07-07 01:26 - 01529384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winmde.dll
2017-07-11 12:59 - 2017-07-07 01:26 - 01195240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll
2017-07-11 12:59 - 2017-07-07 01:26 - 00988168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll
2017-07-11 12:59 - 2017-07-07 01:25 - 02199552 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.Resources.dll
2017-07-11 12:59 - 2017-07-07 01:25 - 00035232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininitext.dll
2017-07-11 12:59 - 2017-07-07 01:24 - 01517472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppVEntSubsystems32.dll
2017-07-11 12:59 - 2017-07-07 01:24 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\officecsp.dll
2017-07-11 12:59 - 2017-07-07 01:23 - 00583160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CoreMessaging.dll
2017-07-11 12:59 - 2017-07-07 01:23 - 00113152 _____ (Microsoft Corporation) C:\Windows\system32\wuuhosdeployment.dll
2017-07-11 12:59 - 2017-07-07 01:23 - 00110592 _____ (Microsoft Corporation) C:\Windows\system32\Chakradiag.dll
2017-07-11 12:59 - 2017-07-07 01:23 - 00095232 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2017-07-11 12:59 - 2017-07-07 01:23 - 00029696 _____ (Microsoft Corporation) C:\Windows\system32\eapprovp.dll
2017-07-11 12:59 - 2017-07-07 01:22 - 07931392 _____ (Microsoft Corporation) C:\Windows\system32\twinui.dll
2017-07-11 12:59 - 2017-07-07 01:22 - 00520704 _____ (Microsoft Corporation) C:\Windows\system32\daxexec.dll
2017-07-11 12:59 - 2017-07-07 01:21 - 00096256 _____ (Microsoft Corporation) C:\Windows\system32\ActiveSyncCsp.dll
2017-07-11 12:59 - 2017-07-07 01:21 - 00064512 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2017-07-11 12:59 - 2017-07-07 01:20 - 23681536 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2017-07-11 12:59 - 2017-07-07 01:20 - 08331264 _____ (Microsoft Corporation) C:\Windows\system32\BingMaps.dll
2017-07-11 12:59 - 2017-07-07 01:20 - 00175616 _____ (Microsoft Corporation) C:\Windows\system32\prntvpt.dll
2017-07-11 12:59 - 2017-07-07 01:19 - 07149056 _____ (Microsoft Corporation) C:\Windows\system32\mos.dll
2017-07-11 12:59 - 2017-07-07 01:19 - 00527360 _____ (Microsoft Corporation) C:\Windows\system32\aadcloudap.dll
2017-07-11 12:59 - 2017-07-07 01:19 - 00256000 _____ (Microsoft Corporation) C:\Windows\system32\domgmt.dll
2017-07-11 12:59 - 2017-07-07 01:19 - 00165888 _____ (Microsoft Corporation) C:\Windows\system32\storewuauth.dll
2017-07-11 12:59 - 2017-07-07 01:19 - 00137216 _____ (Microsoft Corporation) C:\Windows\system32\raschap.dll
2017-07-11 12:59 - 2017-07-07 01:18 - 07336448 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Data.Pdf.dll
2017-07-11 12:59 - 2017-07-07 01:18 - 00563712 _____ (Microsoft Corporation) C:\Windows\system32\DevicePairing.dll
2017-07-11 12:59 - 2017-07-07 01:18 - 00548864 _____ (Microsoft Corporation) C:\Windows\system32\SensorService.dll
2017-07-11 12:59 - 2017-07-07 01:18 - 00353280 _____ (Microsoft Corporation) C:\Windows\system32\Wldap32.dll
2017-07-11 12:59 - 2017-07-07 01:18 - 00274944 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecsExt.dll
2017-07-11 12:59 - 2017-07-07 01:17 - 01878016 _____ (Microsoft Corporation) C:\Windows\system32\AzureSettingSyncProvider.dll
2017-07-11 12:59 - 2017-07-07 01:17 - 01260544 _____ (Microsoft Corporation) C:\Windows\system32\GamePanel.exe
2017-07-11 12:59 - 2017-07-07 01:17 - 00692736 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2017-07-11 12:59 - 2017-07-07 01:17 - 00588800 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2017-07-11 12:59 - 2017-07-07 01:17 - 00536064 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Internal.Management.dll
2017-07-11 12:59 - 2017-07-07 01:17 - 00422400 _____ (Microsoft Corporation) C:\Windows\system32\WpAXHolder.dll
2017-07-11 12:59 - 2017-07-07 01:17 - 00229888 _____ (Microsoft Corporation) C:\Windows\system32\SIHClient.exe
2017-07-11 12:59 - 2017-07-07 01:16 - 12786176 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2017-07-11 12:59 - 2017-07-07 01:16 - 00925696 _____ (Microsoft Corporation) C:\Windows\system32\WpcWebFilter.dll
2017-07-11 12:59 - 2017-07-07 01:16 - 00545792 _____ (Microsoft Corporation) C:\Windows\system32\winspool.drv
2017-07-11 12:59 - 2017-07-07 01:15 - 08238080 _____ (Microsoft Corporation) C:\Windows\system32\Chakra.dll
2017-07-11 12:59 - 2017-07-07 01:15 - 00922112 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2017-07-11 12:59 - 2017-07-07 01:14 - 08211968 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2017-07-11 12:59 - 2017-07-07 01:14 - 03784704 _____ (Microsoft Corporation) C:\Windows\system32\MapRouter.dll
2017-07-11 12:59 - 2017-07-07 01:14 - 02956800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32kfull.sys
2017-07-11 12:59 - 2017-07-07 01:14 - 01802240 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2017-07-11 12:59 - 2017-07-07 01:14 - 01448960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\GdiPlus.dll
2017-07-11 12:59 - 2017-07-07 01:14 - 00790016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.dll
2017-07-11 12:59 - 2017-07-07 01:14 - 00570880 _____ (Microsoft Corporation) C:\Windows\system32\PhotoScreensaver.scr
2017-07-11 12:59 - 2017-07-07 01:14 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\rastls.dll
2017-07-11 12:59 - 2017-07-07 01:13 - 13839872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.dll
2017-07-11 12:59 - 2017-07-07 01:13 - 05892096 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2017-07-11 12:59 - 2017-07-07 01:13 - 00840192 _____ (Microsoft Corporation) C:\Windows\system32\fveapi.dll
2017-07-11 12:59 - 2017-07-07 01:12 - 04730880 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2017-07-11 12:59 - 2017-07-07 01:12 - 03307008 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2017-07-11 12:59 - 2017-07-07 01:12 - 02499584 _____ (Microsoft Corporation) C:\Windows\system32\twinui.pcshell.dll
2017-07-11 12:59 - 2017-07-07 01:12 - 02199552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.Resources.dll
2017-07-11 12:59 - 2017-07-07 01:12 - 02055168 _____ (Microsoft Corporation) C:\Windows\system32\win32kbase.sys
2017-07-11 12:59 - 2017-07-07 01:12 - 01713664 _____ (Microsoft Corporation)