Solved Malware/Virus Problem

BefuddledB

Posts: 53   +0
Hi!
A KMS activator might have installed something I don't know. I initially had Microsoft security essentials and it's not updating to catch anything. I couldn't install any antivirus as everything kept coming up with errors or ending up in crashes. I was finally able to download and install the free avast on safemode with networking (it didn't install properly first, I did it again after switching to administrator account and it seems fine). It hadn't catch anything though and I still get crashes when I try to download bitdefender. When I try to install AVG, either nothing happens or I get error code for internet connection (screenshot attached). What should I do?
 

Attachments

  • Screenshot 2017-11-06 13.57.02.png
    Screenshot 2017-11-06 13.57.02.png
    925 KB · Views: 0
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 02-11-2017
Ran by Personal (administrator) on HP (06-11-2017 16:56:14)
Running from C:\Users\Personal\Desktop
Loaded Profiles: Personal (Available Profiles: Personal)
Platform: Windows 7 Professional Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Hewlett-Packard Company) C:\Windows\System32\hpservice.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Dropbox, Inc.) C:\Windows\System32\DbxSvc.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler64.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Nero AG) C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Nero AG) C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe
(Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
(Nero AG) C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(HP Inc.) C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
() C:\Program Files\qBittorrent\qbittorrent.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1281512 2013-01-27] (Microsoft Corporation)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [253344 2017-11-03] (AVAST Software)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [336384 2011-03-15] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [3567928 2017-11-01] (Dropbox, Inc.)
HKLM-x32\...\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [4174464 2017-05-23] (Safer-Networking Ltd.)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
HKU\S-1-5-21-3766277524-2784970969-2751085713-1000\...\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] => C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe [153136 2007-03-12] (Nero AG)
HKU\S-1-5-21-3766277524-2784970969-2751085713-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [27832272 2017-08-25] (Skype Technologies S.A.)
BootExecute: autocheck autochk * sdnclean64.exe

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.10.1
Tcpip\..\Interfaces\{6B8B91B0-9F9B-4CA8-AE14-69358B1D80FF}: [DhcpNameServer] 192.168.0.254
Tcpip\..\Interfaces\{FFE957F8-0C5C-40E2-982E-59417CB3D7AA}: [DhcpNameServer] 192.168.10.1

Internet Explorer:
==================
HKU\S-1-5-21-3766277524-2784970969-2751085713-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/?ocid=iehp
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2017-11-03] (AVAST Software)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2017-11-03] (Google Inc.)
BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [2017-09-27] (HP Inc.)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2017-11-03] (AVAST Software)
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2017-11-03] (Google Inc.)
BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2017-09-27] (HP Inc.)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2017-11-03] (Google Inc.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2017-11-03] (Google Inc.)

FireFox:
========
FF DefaultProfile: 9qofch10.default
FF ProfilePath: C:\Users\Personal\AppData\Roaming\Mozilla\Firefox\Profiles\9qofch10.default [2017-11-06]
FF Extension: (Avast SafePrice) - C:\Users\Personal\AppData\Roaming\Mozilla\Firefox\Profiles\9qofch10.default\Extensions\sp@avast.com.xpi [2017-11-03]
FF Extension: (Avast Online Security) - C:\Users\Personal\AppData\Roaming\Mozilla\Firefox\Profiles\9qofch10.default\Extensions\wrc@avast.com.xpi [2017-11-03]
FF Plugin: @videolan.org/vlc,version=2.2.6 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-10-27] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-10-27] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-06-30] (Adobe Systems Inc.)

Chrome:
=======
CHR HomePage: Default -> hxxp://www.google.com/
CHR StartupUrls: Default -> "hxxp://www.gmail.com/","hxxp://www.bbc.co.uk/","hxxp://www.sudantribune.com/"
CHR Profile: C:\Users\Personal\AppData\Local\Google\Chrome\User Data\Default [2017-11-06]
CHR Extension: (Slides) - C:\Users\Personal\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-10-27]
CHR Extension: (TheFreeDictionary.com Extension) - C:\Users\Personal\AppData\Local\Google\Chrome\User Data\Default\Extensions\afgabimphpgkjochcoogplolgpcagmap [2017-10-27]
CHR Extension: (Docs) - C:\Users\Personal\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-27]
CHR Extension: (Google Drive) - C:\Users\Personal\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-10-27]
CHR Extension: (YouTube) - C:\Users\Personal\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-10-27]
CHR Extension: (Adblock Plus) - C:\Users\Personal\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2017-10-27]
CHR Extension: (Avast SafePrice) - C:\Users\Personal\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck [2017-11-06]
CHR Extension: (Sheets) - C:\Users\Personal\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-10-27]
CHR Extension: (Google Docs Offline) - C:\Users\Personal\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-10-27]
CHR Extension: (AdBlock) - C:\Users\Personal\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2017-10-27]
CHR Extension: (Google Calendar (by Google)) - C:\Users\Personal\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmbgaklkmjakoegficnlkhebmhkjfich [2017-10-27]
CHR Extension: (Avast Online Security) - C:\Users\Personal\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2017-11-06]
CHR Extension: (Kindle Cloud Reader) - C:\Users\Personal\AppData\Local\Google\Chrome\User Data\Default\Extensions\icdipabjmbhpdkjaihfjoikhjjeneebd [2017-10-27]
CHR Extension: (Google Keep Chrome Extension) - C:\Users\Personal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lpcaedmchfhocbbapmcbpinfpgnhiddi [2017-10-27]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Personal\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-10-27]
CHR Extension: (Gmail) - C:\Users\Personal\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-10-27]
CHR Extension: (Chrome Media Router) - C:\Users\Personal\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-10-27]
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - hxxps://clients2.google.com/service/update2/crx

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [7446024 2017-11-03] (AVAST Software s.r.o.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [281416 2017-11-03] (AVAST Software)
S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2017-10-31] (Dropbox, Inc.)
S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2017-10-31] (Dropbox, Inc.)
R2 DbxSvc; C:\Windows\system32\DbxSvc.exe [51016 2017-11-01] (Dropbox, Inc.)
S3 hpqcaslwmiex; C:\Program Files (x86)\HP\Shared\hpqwmiex.exe [1031704 2016-06-03] (HP)
R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [323952 2017-09-27] (HP Inc.)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6058960 2017-08-07] (Malwarebytes)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [22056 2013-01-27] (Microsoft Corporation)
S3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [379360 2013-01-27] (Microsoft Corporation)
R3 NMIndexingService; C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe [271920 2007-03-12] (Nero AG)
S2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1776864 2017-05-23] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2131760 2017-05-23] (Safer-Networking Ltd.)
S2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [233936 2017-05-23] (Safer-Networking Ltd.)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-14] (Microsoft Corporation)

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 aswbidsdriver; C:\Windows\system32\drivers\aswbidsdrivera.sys [321032 2017-11-03] (AVAST Software s.r.o.)
S3 aswbidsh; C:\Windows\system32\drivers\aswbidsha.sys [198976 2017-11-03] (AVAST Software s.r.o.)
S3 aswblog; C:\Windows\system32\drivers\aswbloga.sys [343288 2017-11-03] (AVAST Software s.r.o.)
S3 aswbuniv; C:\Windows\system32\drivers\aswbuniva.sys [57736 2017-11-03] (AVAST Software s.r.o.)
S3 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [47008 2017-11-03] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [147776 2017-11-03] (AVAST Software)
S3 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [110376 2017-11-03] (AVAST Software)
R0 aswRvrt; C:\Windows\system32\drivers\aswRvrt.sys [84416 2017-11-03] (AVAST Software)
S3 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1029872 2017-11-03] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [587168 2017-11-03] (AVAST Software)
S3 aswStm; C:\Windows\system32\drivers\aswStm.sys [201352 2017-11-03] (AVAST Software)
S3 aswVmm; C:\Windows\system32\drivers\aswVmm.sys [363440 2017-11-03] (AVAST Software)
R1 ESProtectionDriver; C:\Windows\system32\drivers\mbae64.sys [77440 2017-10-04] ()
R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [30960 2015-05-29] (Intel Corporation)
R3 int0800; C:\Windows\System32\DRIVERS\flashud.sys [51712 2009-09-09] (Intel Corporation)
R2 MBAMChameleon; C:\Windows\System32\Drivers\MbamChameleon.sys [192952 2017-11-02] (Malwarebytes)
R3 MBAMFarflt; C:\Windows\System32\DRIVERS\farflt.sys [110016 2017-11-06] (Malwarebytes)
R3 MBAMProtection; C:\Windows\System32\DRIVERS\mbam.sys [45504 2017-11-06] (Malwarebytes)
R3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [252232 2017-11-06] (Malwarebytes)
R3 MBAMWebProtection; C:\Windows\System32\DRIVERS\mwac.sys [84256 2017-11-06] (Malwarebytes)
R3 MEIx64; C:\Windows\System32\DRIVERS\TeeDriverx64.sys [180480 2015-10-08] (Intel Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [230320 2013-01-20] (Microsoft Corporation)
S3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [130008 2013-01-20] (Microsoft Corporation)
S3 ptun0901; C:\Windows\System32\DRIVERS\ptun0901.sys [27136 2014-08-08] (The OpenVPN Project)
U3 aswbdisk; no ImagePath

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-11-06 16:56 - 2017-11-06 16:56 - 000016927 _____ C:\Users\Personal\Desktop\FRST.txt
2017-11-06 12:40 - 2017-11-06 16:56 - 000000000 ____D C:\FRST
2017-11-06 12:39 - 2017-11-06 12:39 - 002403328 _____ (Farbar) C:\Users\Personal\Desktop\FRST64.exe
2017-11-06 12:30 - 2017-11-06 12:30 - 000030401 _____ C:\ProgramData\agent.uninstall.1509960634.bdinstall.bin
2017-11-06 11:51 - 2017-11-06 11:51 - 000262144 _____ C:\Windows\Minidump\110617-15350-01.dmp
2017-11-06 11:28 - 2017-11-06 11:28 - 000030914 _____ C:\ProgramData\agent.update.1509956921.bdinstall.bin
2017-11-06 11:25 - 2017-11-06 11:25 - 000000000 ____D C:\ProgramData\SWCUTemp
2017-11-03 02:13 - 2017-11-03 02:13 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2017-11-03 02:12 - 2017-11-03 02:13 - 000000000 ___RD C:\Program Files (x86)\Skype
2017-11-03 02:01 - 2017-11-03 02:01 - 000003914 _____ C:\Windows\System32\Tasks\Avast Emergency Update
2017-11-03 02:01 - 2017-11-03 01:44 - 000401488 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2017-11-03 01:55 - 2017-11-03 01:55 - 000000000 ____D C:\ProgramData\Google
2017-11-03 01:55 - 2017-11-03 01:55 - 000000000 ____D C:\Program Files\Google
2017-11-03 01:46 - 2017-11-03 01:46 - 000000000 ____D C:\Users\Personal\AppData\Roaming\AVAST Software
2017-11-03 01:46 - 2017-11-03 01:46 - 000000000 ____D C:\Users\Personal\AppData\Local\CEF
2017-11-03 01:45 - 2017-11-03 02:02 - 000001924 _____ C:\Users\Public\Desktop\Avast Free Antivirus.lnk
2017-11-03 01:45 - 2017-11-03 01:45 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
2017-11-03 01:44 - 2017-11-03 02:02 - 001029872 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsnx.sys
2017-11-03 01:44 - 2017-11-03 02:00 - 001020536 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsnx.sys.150966374037707
2017-11-03 01:44 - 2017-11-03 01:44 - 000587168 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2017-11-03 01:44 - 2017-11-03 01:44 - 000363440 _____ (AVAST Software) C:\Windows\system32\Drivers\aswVmm.sys
2017-11-03 01:44 - 2017-11-03 01:44 - 000201352 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2017-11-03 01:44 - 2017-11-03 01:44 - 000147776 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2017-11-03 01:44 - 2017-11-03 01:44 - 000110376 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2017-11-03 01:44 - 2017-11-03 01:44 - 000084416 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys
2017-11-03 01:44 - 2017-11-03 01:44 - 000047008 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHwid.sys
2017-11-03 01:44 - 2017-11-03 01:43 - 000343288 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbloga.sys
2017-11-03 01:44 - 2017-11-03 01:43 - 000321032 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbidsdrivera.sys
2017-11-03 01:44 - 2017-11-03 01:43 - 000198976 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbidsha.sys
2017-11-03 01:44 - 2017-11-03 01:43 - 000057736 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbuniva.sys
2017-11-03 01:09 - 2017-11-03 01:09 - 000000000 ____D C:\Users\Personal\AppData\Local\ElevatedDiagnostics
2017-11-03 00:40 - 2017-11-03 00:40 - 000262144 _____ C:\Windows\Minidump\110317-20186-01.dmp
2017-11-03 00:04 - 2017-11-03 00:04 - 000000000 ____D C:\Program Files\Bitdefender Antivirus Free
2017-11-02 23:40 - 2017-11-02 23:40 - 000262144 _____ C:\Windows\Minidump\110217-20560-01.dmp
2017-11-02 23:06 - 2017-11-02 23:06 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox
2017-11-02 21:12 - 2017-11-02 21:12 - 000262144 _____ C:\Windows\Minidump\110217-17222-01.dmp
2017-11-02 20:29 - 2017-11-06 11:51 - 000000000 ____D C:\Windows\Minidump
2017-11-02 20:29 - 2017-11-03 01:06 - 000251432 _____ C:\Windows\ntbtlog.txt
2017-11-02 20:29 - 2017-11-02 20:29 - 000262144 _____ C:\Windows\Minidump\110217-18969-01.dmp
2017-11-02 20:28 - 2017-11-06 11:51 - 582671372 _____ C:\Windows\MEMORY.DMP
2017-11-02 20:16 - 2017-11-02 20:16 - 000000000 ____D C:\Users\Personal\AppData\Roaming\Adobe
2017-11-02 20:00 - 2013-10-14 18:00 - 000028368 _____ (Microsoft Corporation) C:\Windows\system32\IEUDINIT.EXE
2017-11-02 19:56 - 2017-11-02 19:56 - 019607040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2017-11-02 19:56 - 2017-11-02 19:56 - 012829696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2017-11-02 19:56 - 2017-11-02 19:56 - 004305920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2017-11-02 19:56 - 2017-11-02 19:56 - 002724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2017-11-02 19:56 - 2017-11-02 19:56 - 002278912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2017-11-02 19:56 - 2017-11-02 19:56 - 002052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2017-11-02 19:56 - 2017-11-02 19:56 - 001950720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2017-11-02 19:56 - 2017-11-02 19:56 - 001309696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2017-11-02 19:56 - 2017-11-02 19:56 - 001155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2017-11-02 19:56 - 2017-11-02 19:56 - 000940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2017-11-02 19:56 - 2017-11-02 19:56 - 000710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2017-11-02 19:56 - 2017-11-02 19:56 - 000689152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2017-11-02 19:56 - 2017-11-02 19:56 - 000664064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2017-11-02 19:56 - 2017-11-02 19:56 - 000645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll
2017-11-02 19:56 - 2017-11-02 19:56 - 000620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2017-11-02 19:56 - 2017-11-02 19:56 - 000616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat
2017-11-02 19:56 - 2017-11-02 19:56 - 000503808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2017-11-02 19:56 - 2017-11-02 19:56 - 000478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2017-11-02 19:56 - 2017-11-02 19:56 - 000418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2017-11-02 19:56 - 2017-11-02 19:56 - 000342728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2017-11-02 19:56 - 2017-11-02 19:56 - 000341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2017-11-02 19:56 - 2017-11-02 19:56 - 000285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2017-11-02 19:56 - 2017-11-02 19:56 - 000235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll
2017-11-02 19:56 - 2017-11-02 19:56 - 000233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2017-11-02 19:56 - 2017-11-02 19:56 - 000208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2017-11-02 19:56 - 2017-11-02 19:56 - 000194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll
2017-11-02 19:56 - 2017-11-02 19:56 - 000182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll
2017-11-02 19:56 - 2017-11-02 19:56 - 000168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2017-11-02 19:56 - 2017-11-02 19:56 - 000151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe
2017-11-02 19:56 - 2017-11-02 19:56 - 000139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe
2017-11-02 19:56 - 2017-11-02 19:56 - 000127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2017-11-02 19:56 - 2017-11-02 19:56 - 000116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2017-11-02 19:56 - 2017-11-02 19:56 - 000115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2017-11-02 19:56 - 2017-11-02 19:56 - 000111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll
2017-11-02 19:56 - 2017-11-02 19:56 - 000086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2017-11-02 19:56 - 2017-11-02 19:56 - 000083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2017-11-02 19:56 - 2017-11-02 19:56 - 000076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2017-11-02 19:56 - 2017-11-02 19:56 - 000074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe
2017-11-02 19:56 - 2017-11-02 19:56 - 000071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2017-11-02 19:56 - 2017-11-02 19:56 - 000069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll
2017-11-02 19:56 - 2017-11-02 19:56 - 000064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2017-11-02 19:56 - 2017-11-02 19:56 - 000062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2017-11-02 19:56 - 2017-11-02 19:56 - 000062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2017-11-02 19:56 - 2017-11-02 19:56 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2017-11-02 19:56 - 2017-11-02 19:56 - 000056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll
2017-11-02 19:56 - 2017-11-02 19:56 - 000048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll
2017-11-02 19:56 - 2017-11-02 19:56 - 000047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2017-11-02 19:56 - 2017-11-02 19:56 - 000047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2017-11-02 19:56 - 2017-11-02 19:56 - 000043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2017-11-02 19:56 - 2017-11-02 19:56 - 000036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll
2017-11-02 19:56 - 2017-11-02 19:56 - 000030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2017-11-02 19:56 - 2017-11-02 19:56 - 000024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2017-11-02 19:56 - 2017-11-02 19:56 - 000013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2017-11-02 19:56 - 2017-11-02 19:56 - 000012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2017-11-02 19:55 - 2017-11-02 19:55 - 024917504 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2017-11-02 19:55 - 2017-11-02 19:55 - 014404096 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2017-11-02 19:55 - 2017-11-02 19:55 - 006026240 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2017-11-02 19:55 - 2017-11-02 19:55 - 002885632 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2017-11-02 19:55 - 2017-11-02 19:55 - 002724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2017-11-02 19:55 - 2017-11-02 19:55 - 002426880 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2017-11-02 19:55 - 2017-11-02 19:55 - 002125824 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2017-11-02 19:55 - 2017-11-02 19:55 - 001545728 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2017-11-02 19:55 - 2017-11-02 19:55 - 001359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2017-11-02 19:55 - 2017-11-02 19:55 - 000942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll
2017-11-02 19:55 - 2017-11-02 19:55 - 000816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2017-11-02 19:55 - 2017-11-02 19:55 - 000814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2017-11-02 19:55 - 2017-11-02 19:55 - 000801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2017-11-02 19:55 - 2017-11-02 19:55 - 000800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2017-11-02 19:55 - 2017-11-02 19:55 - 000720384 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2017-11-02 19:55 - 2017-11-02 19:55 - 000633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2017-11-02 19:55 - 2017-11-02 19:55 - 000616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2017-11-02 19:55 - 2017-11-02 19:55 - 000584192 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2017-11-02 19:55 - 2017-11-02 19:55 - 000490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2017-11-02 19:55 - 2017-11-02 19:55 - 000417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2017-11-02 19:55 - 2017-11-02 19:55 - 000389840 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2017-11-02 19:55 - 2017-11-02 19:55 - 000316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2017-11-02 19:55 - 2017-11-02 19:55 - 000247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2017-11-02 19:55 - 2017-11-02 19:55 - 000243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2017-11-02 19:55 - 2017-11-02 19:55 - 000235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2017-11-02 19:55 - 2017-11-02 19:55 - 000199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2017-11-02 19:55 - 2017-11-02 19:55 - 000167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2017-11-02 19:55 - 2017-11-02 19:55 - 000147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2017-11-02 19:55 - 2017-11-02 19:55 - 000144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2017-11-02 19:55 - 2017-11-02 19:55 - 000143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2017-11-02 19:55 - 2017-11-02 19:55 - 000135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2017-11-02 19:55 - 2017-11-02 19:55 - 000131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2017-11-02 19:55 - 2017-11-02 19:55 - 000114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2017-11-02 19:55 - 2017-11-02 19:55 - 000105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2017-11-02 19:55 - 2017-11-02 19:55 - 000101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2017-11-02 19:55 - 2017-11-02 19:55 - 000092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2017-11-02 19:55 - 2017-11-02 19:55 - 000090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2017-11-02 19:55 - 2017-11-02 19:55 - 000088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2017-11-02 19:55 - 2017-11-02 19:55 - 000086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2017-11-02 19:55 - 2017-11-02 19:55 - 000081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2017-11-02 19:55 - 2017-11-02 19:55 - 000077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2017-11-02 19:55 - 2017-11-02 19:55 - 000077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2017-11-02 19:55 - 2017-11-02 19:55 - 000066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2017-11-02 19:55 - 2017-11-02 19:55 - 000062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2017-11-02 19:55 - 2017-11-02 19:55 - 000054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2017-11-02 19:55 - 2017-11-02 19:55 - 000052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2017-11-02 19:55 - 2017-11-02 19:55 - 000048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2017-11-02 19:55 - 2017-11-02 19:55 - 000048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2017-11-02 19:55 - 2017-11-02 19:55 - 000048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2017-11-02 19:55 - 2017-11-02 19:55 - 000034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2017-11-02 19:55 - 2017-11-02 19:55 - 000030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2017-11-02 19:55 - 2017-11-02 19:55 - 000013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2017-11-02 19:55 - 2017-11-02 19:55 - 000013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2017-11-02 19:55 - 2017-11-02 19:55 - 000004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 005549504 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2017-11-02 19:54 - 2017-11-02 19:54 - 003969472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2017-11-02 19:54 - 2017-11-02 19:54 - 003914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2017-11-02 19:54 - 2017-11-02 19:54 - 001903552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
 
2017-11-02 19:54 - 2017-11-02 19:54 - 001732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 001292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 001161216 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 001114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000878080 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000859648 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000640512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000619520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2017-11-02 19:54 - 2017-11-02 19:54 - 000424448 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000376688 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys
2017-11-02 19:54 - 2017-11-02 19:54 - 000362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2017-11-02 19:54 - 2017-11-02 19:54 - 000327168 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000288088 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS
2017-11-02 19:54 - 2017-11-02 19:54 - 000274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000231424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswsock.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2017-11-02 19:54 - 2017-11-02 19:54 - 000068608 _____ (Microsoft Corporation) C:\Windows\system32\taskhost.exe
2017-11-02 19:54 - 2017-11-02 19:54 - 000043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2017-11-02 19:54 - 2017-11-02 19:54 - 000016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2017-11-02 19:54 - 2017-11-02 19:54 - 000006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2017-11-02 19:51 - 2017-11-02 19:51 - 003928064 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 003419136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 002776576 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 002565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 002284544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 001988096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 001682432 _____ (Microsoft Corporation) C:\Windows\system32\XpsPrint.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 001643520 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 001424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 001247744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 001238528 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 001230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 001175552 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 001158144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsPrint.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 001080832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 000648192 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 000604160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10level9.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 000522752 _____ (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 000465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 000417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 000364544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 000363008 _____ (Microsoft Corporation) C:\Windows\system32\dxgi.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 000333312 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 000296960 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 000293376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxgi.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 000249856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1core.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 000245248 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecsExt.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 000221184 _____ (Microsoft Corporation) C:\Windows\system32\UIAnimation.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 000220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10core.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 000207872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecsExt.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 000194560 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 000187392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIAnimation.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 000161792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 000010752 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l1-1-0.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 000010752 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 000009728 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 000009728 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 000005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 000005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-ole32-l1-1-0.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 000005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 000005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-user32-l1-1-0.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-version-l1-1-0.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shell32-l1-1-0.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 000002560 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-normaliz-l1-1-0.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 000002560 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2017-11-02 19:49 - 2017-11-02 19:49 - 001887232 _____ (Microsoft Corporation) C:\Windows\system32\d3d11.dll
2017-11-02 19:49 - 2017-11-02 19:49 - 001505280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll
2017-11-02 17:34 - 2017-11-02 17:34 - 000000000 ____D C:\Windows\System32\Tasks\Safer-Networking
2017-11-02 17:33 - 2017-11-02 17:52 - 000000000 ____D C:\ProgramData\Spybot - Search & Destroy
2017-11-02 17:33 - 2017-11-02 17:41 - 000000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
2017-11-02 17:33 - 2017-11-02 17:33 - 000001397 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk
2017-11-02 17:33 - 2017-11-02 17:33 - 000001385 _____ C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
2017-11-02 17:33 - 2017-11-02 17:33 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
2017-11-02 17:33 - 2017-05-23 09:22 - 000032240 _____ (Safer-Networking Ltd.) C:\Windows\system32\sdnclean64.exe
2017-11-02 17:27 - 2017-11-02 17:31 - 051725936 _____ (Safer-Networking Ltd. ) C:\Users\Personal\Downloads\spybotsd-2.6.46.exe
2017-11-02 17:06 - 2017-11-06 16:54 - 000084256 _____ (Malwarebytes) C:\Windows\system32\Drivers\mwac.sys
2017-11-02 17:06 - 2017-11-06 11:53 - 000252232 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamswissarmy.sys
2017-11-02 17:06 - 2017-11-06 11:53 - 000110016 _____ (Malwarebytes) C:\Windows\system32\Drivers\farflt.sys
2017-11-02 17:06 - 2017-11-06 11:53 - 000045504 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2017-11-02 17:06 - 2017-11-02 17:06 - 000192952 _____ (Malwarebytes) C:\Windows\system32\Drivers\MbamChameleon.sys
2017-11-02 17:05 - 2017-11-02 17:05 - 000001869 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2017-11-02 17:05 - 2017-11-02 17:05 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2017-11-02 17:05 - 2017-11-02 17:05 - 000000000 ____D C:\ProgramData\Malwarebytes
2017-11-02 17:05 - 2017-11-02 17:05 - 000000000 ____D C:\Program Files\Malwarebytes
2017-11-02 17:05 - 2017-10-04 13:15 - 000077440 _____ C:\Windows\system32\Drivers\mbae64.sys
2017-11-02 16:59 - 2017-11-02 17:04 - 071535032 _____ (Malwarebytes ) C:\Users\Personal\Downloads\mb3-setup-consumer-3.2.2.2029-1.0.212-1.0.2951.exe
2017-11-02 16:54 - 2017-11-02 16:54 - 000000000 ____D C:\ProgramData\KMSAuto
2017-11-02 16:27 - 2017-11-02 16:27 - 000000000 ____D C:\Users\Personal\AppData\Local\AvgSetupLog
2017-11-02 16:27 - 2017-11-02 16:27 - 000000000 ____D C:\Users\Personal\AppData\Local\Avg
2017-11-02 16:27 - 2017-11-02 16:27 - 000000000 ____D C:\ProgramData\Avg
2017-11-02 16:25 - 2017-11-02 16:25 - 003449304 _____ (AVG Technologies CZ, s.r.o.) C:\Users\Personal\Downloads\AVG_Protection_Free_1606.exe
2017-11-02 16:21 - 2017-11-02 19:44 - 055915216 _____ (Microsoft Corporation) C:\Users\Personal\Downloads\IE11-Windows6.1-x64-en-us.exe
2017-11-02 15:06 - 2017-11-06 12:30 - 000000000 ____D C:\Program Files\Bitdefender Agent
2017-11-02 15:06 - 2017-11-02 15:06 - 000048371 _____ C:\ProgramData\agent.1509624401.bdinstall.bin
2017-11-02 15:06 - 2017-11-02 15:06 - 000000000 ____D C:\ProgramData\Bitdefender Agent
2017-11-02 15:05 - 2017-11-02 15:06 - 009932672 _____ C:\Users\Personal\Downloads\bitdefender_online.exe
2017-11-02 14:42 - 2017-11-02 14:43 - 007161304 _____ (AVAST Software) C:\Users\Personal\Downloads\avast_free_antivirus_setup_online.exe
2017-11-02 14:24 - 2017-11-02 14:24 - 000000000 ____D C:\Program Files\AVAST Software
2017-11-02 14:06 - 2017-11-06 12:09 - 000000000 ____D C:\ProgramData\AVAST Software
2017-11-02 14:01 - 2014-08-08 19:31 - 000027136 _____ (The OpenVPN Project) C:\Windows\system32\Drivers\ptun0901.sys
2017-11-02 13:49 - 2017-11-02 16:56 - 000000000 ____D C:\Users\Personal\AppData\Local\MSfree Inc
2017-11-02 13:33 - 2015-07-18 16:08 - 000984448 _____ (Microsoft Corporation) C:\Windows\system32\ucrtbase.dll
2017-11-02 13:33 - 2015-07-18 16:08 - 000901264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ucrtbase.dll
2017-11-02 13:33 - 2015-07-18 16:08 - 000066400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-private-l1-1-0.dll
2017-11-02 13:33 - 2015-07-18 16:08 - 000063840 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-private-l1-1-0.dll
2017-11-02 13:33 - 2015-07-18 16:08 - 000022368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-math-l1-1-0.dll
2017-11-02 13:33 - 2015-07-18 16:08 - 000020832 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-math-l1-1-0.dll
2017-11-02 13:33 - 2015-07-18 16:08 - 000019808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-multibyte-l1-1-0.dll
2017-11-02 13:33 - 2015-07-18 16:08 - 000019808 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-multibyte-l1-1-0.dll
2017-11-02 13:33 - 2015-07-18 16:08 - 000017760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-string-l1-1-0.dll
2017-11-02 13:33 - 2015-07-18 16:08 - 000017760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-stdio-l1-1-0.dll
2017-11-02 13:33 - 2015-07-18 16:08 - 000017760 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-string-l1-1-0.dll
2017-11-02 13:33 - 2015-07-18 16:08 - 000017760 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-stdio-l1-1-0.dll
2017-11-02 13:33 - 2015-07-18 16:08 - 000016224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-runtime-l1-1-0.dll
2017-11-02 13:33 - 2015-07-18 16:08 - 000016224 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-runtime-l1-1-0.dll
2017-11-02 13:33 - 2015-07-18 16:08 - 000015712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-convert-l1-1-0.dll
2017-11-02 13:33 - 2015-07-18 16:08 - 000015712 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-convert-l1-1-0.dll
2017-11-02 13:33 - 2015-07-18 16:08 - 000014176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-time-l1-1-0.dll
2017-11-02 13:33 - 2015-07-18 16:08 - 000014176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-2-0.dll
2017-11-02 13:33 - 2015-07-18 16:08 - 000014176 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-time-l1-1-0.dll
2017-11-02 13:33 - 2015-07-18 16:08 - 000014176 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-2-0.dll
2017-11-02 13:33 - 2015-07-18 16:08 - 000013664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-filesystem-l1-1-0.dll
2017-11-02 13:33 - 2015-07-18 16:08 - 000013664 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll
2017-11-02 13:33 - 2015-07-18 16:08 - 000012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-process-l1-1-0.dll
2017-11-02 13:33 - 2015-07-18 16:08 - 000012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-heap-l1-1-0.dll
2017-11-02 13:33 - 2015-07-18 16:08 - 000012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-conio-l1-1-0.dll
2017-11-02 13:33 - 2015-07-18 16:08 - 000012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-process-l1-1-0.dll
2017-11-02 13:33 - 2015-07-18 16:08 - 000012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-heap-l1-1-0.dll
2017-11-02 13:33 - 2015-07-18 16:08 - 000012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-conio-l1-1-0.dll
2017-11-02 13:33 - 2015-07-18 16:08 - 000012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-utility-l1-1-0.dll
2017-11-02 13:33 - 2015-07-18 16:08 - 000012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-locale-l1-1-0.dll
2017-11-02 13:33 - 2015-07-18 16:08 - 000012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-environment-l1-1-0.dll
2017-11-02 13:33 - 2015-07-18 16:08 - 000012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-2-0.dll
2017-11-02 13:33 - 2015-07-18 16:08 - 000012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-1.dll
2017-11-02 13:33 - 2015-07-18 16:08 - 000012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-utility-l1-1-0.dll
2017-11-02 13:33 - 2015-07-18 16:08 - 000012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-locale-l1-1-0.dll
2017-11-02 13:33 - 2015-07-18 16:08 - 000012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-environment-l1-1-0.dll
2017-11-02 13:33 - 2015-07-18 16:08 - 000012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-2-0.dll
2017-11-02 13:33 - 2015-07-18 16:08 - 000012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-1.dll
2017-11-02 13:33 - 2015-07-18 16:08 - 000011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-eventing-provider-l1-1-0.dll
2017-11-02 13:33 - 2015-07-18 16:08 - 000011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l2-1-0.dll
2017-11-02 13:33 - 2015-07-18 16:08 - 000011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-timezone-l1-1-0.dll
2017-11-02 13:33 - 2015-07-18 16:08 - 000011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l2-1-0.dll
2017-11-02 13:33 - 2015-07-18 16:08 - 000011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-2-0.dll
2017-11-02 13:33 - 2015-07-18 16:08 - 000011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-eventing-provider-l1-1-0.dll
2017-11-02 13:33 - 2015-07-18 16:08 - 000011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l2-1-0.dll
2017-11-02 13:33 - 2015-07-18 16:08 - 000011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-timezone-l1-1-0.dll
2017-11-02 13:33 - 2015-07-18 16:08 - 000011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l2-1-0.dll
2017-11-02 13:33 - 2015-07-18 16:08 - 000011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-2-0.dll
2017-11-02 13:32 - 2017-11-02 13:32 - 000002167 _____ C:\Users\Personal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft OneDrive.lnk
2017-11-02 13:32 - 2017-11-02 13:32 - 000002106 _____ C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft OneDrive.lnk
2017-11-02 13:32 - 2017-11-02 13:32 - 000002106 _____ C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft OneDrive.lnk
2017-11-02 13:32 - 2017-11-02 13:32 - 000000000 ___RD C:\Users\Personal\OneDrive
2017-11-02 13:32 - 2017-11-02 13:32 - 000000000 ____D C:\ProgramData\Microsoft OneDrive
2017-11-02 13:32 - 2017-11-02 13:32 - 000000000 ____D C:\Program Files (x86)\Microsoft OneDrive
2017-11-02 13:25 - 2017-11-02 13:25 - 000000000 ____D C:\Windows\System32\Tasks\OfficeSoftwareProtectionPlatform
2017-11-02 13:08 - 2017-11-02 13:08 - 000000000 ____D C:\Users\Personal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2017-11-02 13:08 - 2017-11-02 13:08 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2017-11-02 13:08 - 2017-11-02 13:08 - 000000000 ____D C:\Program Files (x86)\WinRAR
2017-11-02 13:04 - 2017-11-02 13:04 - 001987408 _____ C:\Users\Personal\Downloads\wrar550.exe
2017-11-01 14:58 - 2017-11-01 14:58 - 000051016 _____ (Dropbox, Inc.) C:\Windows\system32\DbxSvc.exe
2017-11-01 14:58 - 2017-11-01 14:58 - 000045672 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-dev.sys
2017-11-01 14:58 - 2017-11-01 14:58 - 000045640 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-stable.sys
2017-11-01 14:58 - 2017-11-01 14:58 - 000045640 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-canary.sys
2017-10-31 16:23 - 2017-10-31 16:25 - 000000000 ___RD C:\Users\Personal\Dropbox
2017-10-31 16:23 - 2017-10-31 16:23 - 000001232 _____ C:\Users\Personal\Desktop\Dropbox.lnk
2017-10-31 16:17 - 2017-10-31 16:17 - 000000000 ____D C:\Users\Personal\AppData\Roaming\Dropbox
2017-10-31 16:11 - 2017-11-06 16:49 - 000000912 _____ C:\Windows\Tasks\DropboxUpdateTaskMachineUA.job
2017-10-31 16:11 - 2017-11-06 16:49 - 000000908 _____ C:\Windows\Tasks\DropboxUpdateTaskMachineCore.job
2017-10-31 16:11 - 2017-11-02 23:07 - 000000000 ____D C:\Program Files (x86)\Dropbox
2017-10-31 16:11 - 2017-11-01 22:47 - 000000000 ____D C:\Users\Personal\AppData\Local\Dropbox
2017-10-31 16:11 - 2017-10-31 16:11 - 000690080 _____ (Dropbox, Inc.) C:\Users\Personal\Downloads\DropboxInstaller.exe
2017-10-31 16:11 - 2017-10-31 16:11 - 000003908 _____ C:\Windows\System32\Tasks\DropboxUpdateTaskMachineUA
2017-10-31 16:11 - 2017-10-31 16:11 - 000003656 _____ C:\Windows\System32\Tasks\DropboxUpdateTaskMachineCore
2017-10-31 16:11 - 2017-10-31 16:11 - 000000000 ____D C:\ProgramData\Dropbox
2017-10-30 23:12 - 2017-10-30 23:12 - 000000000 ____D C:\Users\Personal\AppData\Roaming\dvdcss
2017-10-27 18:57 - 2017-11-06 11:52 - 000000344 _____ C:\Windows\Tasks\HPCeeScheduleForPersonal.job
2017-10-27 18:57 - 2017-11-06 11:48 - 000003204 _____ C:\Windows\System32\Tasks\HPCeeScheduleForPersonal
2017-10-27 18:57 - 2017-10-27 18:57 - 000000000 ____D C:\Users\Personal\AppData\Local\HP_Inc
2017-10-27 18:52 - 2017-10-27 18:52 - 000000000 ____D C:\Users\Personal\AppData\Roaming\Hewlett-Packard
2017-10-27 18:48 - 2017-10-27 18:48 - 000002233 _____ C:\Users\Public\Desktop\HP Support Assistant.lnk
2017-10-27 18:48 - 2017-10-27 18:48 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP Help and Support
2017-10-27 18:46 - 2017-10-28 12:43 - 000000000 ____D C:\ProgramData\Hewlett-Packard
2017-10-27 18:46 - 2017-10-27 18:46 - 000000000 ____D C:\System.sav
2017-10-27 18:46 - 2017-10-27 18:46 - 000000000 ____D C:\ProgramData\HP Inc
2017-10-27 18:45 - 2017-10-28 12:43 - 000000000 ____D C:\Windows\System32\Tasks\Hewlett-Packard
2017-10-27 18:45 - 2017-10-27 18:52 - 000000000 ____D C:\Users\Personal\AppData\Local\Hewlett-Packard
2017-10-27 18:45 - 2017-10-27 18:45 - 000000000 ____D C:\Users\Personal\AppData\Roaming\hpqLog
2017-10-27 18:45 - 2017-10-27 18:45 - 000000000 ____D C:\Program Files (x86)\HP
2017-10-27 18:44 - 2017-10-27 18:46 - 000000000 ____D C:\Program Files (x86)\Hewlett-Packard
2017-10-27 18:44 - 2017-10-27 18:44 - 000000000 ____D C:\swsetup
2017-10-27 18:40 - 2017-10-27 18:44 - 035357824 _____ (HP Inc. ) C:\Users\Personal\Downloads\sp82049.exe
2017-10-27 16:25 - 2017-10-27 16:25 - 000000000 ____D C:\Users\Personal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Python 3.5
2017-10-27 16:25 - 2017-10-27 16:25 - 000000000 ____D C:\Users\Personal\AppData\Local\Package Cache
2017-10-27 16:18 - 2017-11-06 16:48 - 000000000 ____D C:\Users\Personal\AppData\Roaming\qBittorrent
2017-10-27 16:18 - 2017-10-27 16:26 - 000000000 ____D C:\Users\Personal\AppData\Local\qBittorrent
2017-10-27 16:18 - 2017-10-27 16:18 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\qBittorrent
2017-10-27 16:18 - 2017-10-27 16:18 - 000000000 ____D C:\Program Files\qBittorrent
2017-10-27 16:14 - 2017-10-27 16:15 - 019756156 _____ (The qBittorrent project) C:\Users\Personal\Downloads\qbittorrent_3.3.16_x64_setup.exe
2017-10-27 15:58 - 2017-10-27 15:58 - 000000836 _____ C:\Users\Personal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Start Tor Browser.lnk
2017-10-27 15:58 - 2017-10-27 15:58 - 000000788 _____ C:\Users\Personal\Desktop\Start Tor Browser.lnk
2017-10-27 15:58 - 2017-10-27 15:58 - 000000000 ____D C:\Users\Personal\Desktop\Tor Browser
2017-10-27 15:53 - 2017-10-27 15:53 - 001005568 _____ (Microsoft Corporation) C:\Users\Personal\Downloads\dotNetFx45_Full_setup.exe
2017-10-27 15:51 - 2017-10-27 15:57 - 053739632 _____ C:\Users\Personal\Downloads\torbrowser-install-7.5a6_en-US.exe
2017-10-27 15:43 - 2017-10-27 15:43 - 000000000 ____D C:\Users\Personal\.swt
2017-10-27 15:42 - 2017-10-27 20:58 - 000000000 ____D C:\Users\Personal\AppData\Roaming\Azureus
2017-10-27 15:40 - 2017-10-27 15:40 - 000000000 ____D C:\ProgramData\Oracle
2017-10-27 15:38 - 2017-10-27 15:38 - 000091808 _____ (Azureus Software, Inc.) C:\Users\Personal\Downloads\VuzeBittorrentClientInstaller.exe
2017-10-27 15:24 - 2017-10-27 15:25 - 000000000 ____D C:\Program Files (x86)\CrystalDiskInfo
2017-10-27 15:24 - 2017-10-27 15:24 - 000001206 _____ C:\Users\Personal\Desktop\CrystalDiskInfo.lnk
2017-10-27 15:24 - 2017-10-27 15:24 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CrystalDiskInfo
2017-10-27 15:23 - 2017-10-27 15:24 - 003928200 _____ (Crystal Dew World ) C:\Users\Personal\Downloads\CrystalDiskInfo7_1_1.exe
2017-10-27 15:07 - 2017-10-27 15:07 - 000002273 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-10-27 15:07 - 2017-10-27 15:07 - 000002261 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2017-10-27 15:07 - 2017-10-27 15:07 - 000000000 ____D C:\Users\Personal\AppData\Roaming\Google
2017-10-27 15:03 - 2017-11-03 01:55 - 000000000 ____D C:\Program Files (x86)\Google
2017-10-27 15:03 - 2017-10-31 15:28 - 000000000 ____D C:\Users\Personal\AppData\Local\Google
2017-10-27 15:03 - 2017-10-27 15:03 - 000003330 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2017-10-27 15:03 - 2017-10-27 15:03 - 000003202 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2017-10-27 15:02 - 2017-11-02 21:09 - 000000000 ____D C:\Users\Personal\AppData\Local\Deployment
2017-10-27 15:02 - 2017-10-27 15:02 - 000000000 ____D C:\Users\Personal\AppData\Local\Apps\2.0
2017-10-27 14:54 - 2017-10-27 14:54 - 000000000 ____D C:\ProgramData\Microsoft Toolkit
2017-10-27 02:40 - 2017-10-26 15:53 - 000000000 ____D C:\Windows\Panther
2017-10-27 01:45 - 2017-10-27 01:45 - 000001345 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
2017-10-27 01:45 - 2017-10-27 01:45 - 000001326 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
2017-10-26 17:21 - 2017-10-26 17:21 - 000000000 ____D C:\Users\Personal\AppData\Roaming\ATI
2017-10-26 17:21 - 2017-10-26 17:21 - 000000000 ____D C:\Users\Personal\AppData\Local\ATI
2017-10-26 17:21 - 2017-10-26 17:21 - 000000000 ____D C:\ProgramData\ATI
2017-10-26 17:19 - 2017-10-26 17:19 - 000000000 ____D C:\Program Files\Common Files\Intel
2017-10-26 17:18 - 2017-10-26 17:18 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Catalyst Control Center
2017-10-26 17:17 - 2017-10-26 17:17 - 000000000 _____ C:\Windows\ativpsrm.bin
2017-10-26 17:17 - 2011-01-12 22:03 - 000003155 _____ C:\Windows\SysWOW64\atipblup.dat
2017-10-26 17:17 - 2011-01-12 22:03 - 000003155 _____ C:\Windows\system32\atipblup.dat
2017-10-26 17:15 - 2017-10-26 17:18 - 000000000 ____D C:\Program Files\ATI Technologies
2017-10-26 17:15 - 2017-10-26 17:17 - 000000000 ____D C:\Program Files (x86)\ATI Technologies
2017-10-26 17:15 - 2017-10-26 17:15 - 000000000 ____D C:\Users\Personal\AppData\Roaming\DRPNPS
2017-10-26 17:14 - 2017-10-26 17:14 - 000000000 ____D C:\Users\Personal\AppData\Local\Ahead
2017-10-26 17:14 - 2017-10-26 17:14 - 000000000 ____D C:\Program Files\ATI
2017-10-26 17:12 - 2011-01-27 20:29 - 000013476 _____ C:\Windows\system32\iglhxs64.vp
2017-10-26 17:12 - 2011-01-27 20:15 - 000509976 _____ (Intel Corporation) C:\Windows\system32\igfxsrvc.exe
2017-10-26 17:12 - 2011-01-27 20:15 - 000418328 _____ (Intel Corporation) C:\Windows\system32\igfxpers.exe
2017-10-26 17:12 - 2011-01-27 20:15 - 000239128 _____ (Intel Corporation) C:\Windows\system32\igfxext.exe
2017-10-26 17:12 - 2011-01-27 20:15 - 000167960 _____ (Intel Corporation) C:\Windows\system32\igfxtray.exe
2017-10-26 17:12 - 2011-01-27 19:55 - 000960940 _____ C:\Windows\SysWOW64\igkrng600.bin
2017-10-26 17:12 - 2011-01-27 19:55 - 000960940 _____ C:\Windows\system32\igkrng600.bin
2017-10-26 17:12 - 2011-01-27 19:55 - 000213332 _____ C:\Windows\SysWOW64\igfcg600m.bin
2017-10-26 17:12 - 2011-01-27 19:55 - 000213332 _____ C:\Windows\system32\igfcg600m.bin
2017-10-26 17:12 - 2011-01-27 19:48 - 000575488 _____ (Intel Corporation) C:\Windows\SysWOW64\igdumdx32.dll
2017-10-26 17:12 - 2011-01-27 19:25 - 000287232 _____ (Intel Corporation) C:\Windows\system32\igfxrfra.lrc
2017-10-26 17:12 - 2011-01-27 19:25 - 000287232 _____ (Intel Corporation) C:\Windows\system32\igfxresn.lrc
2017-10-26 17:12 - 2011-01-27 19:25 - 000287232 _____ (Intel Corporation) C:\Windows\system32\igfxrell.lrc
2017-10-26 17:12 - 2011-01-27 19:25 - 000286720 _____ (Intel Corporation) C:\Windows\system32\igfxrsky.lrc
2017-10-26 17:12 - 2011-01-27 19:25 - 000286720 _____ (Intel Corporation) C:\Windows\system32\igfxrrus.lrc
2017-10-26 17:12 - 2011-01-27 19:25 - 000286720 _____ (Intel Corporation) C:\Windows\system32\igfxrrom.lrc
2017-10-26 17:12 - 2011-01-27 19:25 - 000286720 _____ (Intel Corporation) C:\Windows\system32\igfxrptg.lrc
2017-10-26 17:12 - 2011-01-27 19:25 - 000286720 _____ (Intel Corporation) C:\Windows\system32\igfxrplk.lrc
2017-10-26 17:12 - 2011-01-27 19:25 - 000286720 _____ (Intel Corporation) C:\Windows\system32\igfxrnld.lrc
2017-10-26 17:12 - 2011-01-27 19:25 - 000286720 _____ (Intel Corporation) C:\Windows\system32\igfxrita.lrc
2017-10-26 17:12 - 2011-01-27 19:25 - 000286720 _____ (Intel Corporation) C:\Windows\system32\igfxrhrv.lrc
2017-10-26 17:12 - 2011-01-27 19:25 - 000286720 _____ (Intel Corporation) C:\Windows\system32\igfxrdeu.lrc
2017-10-26 17:12 - 2011-01-27 19:25 - 000286720 _____ (Intel Corporation) C:\Windows\system32\igfxrcsy.lrc
2017-10-26 17:12 - 2011-01-27 19:25 - 000286208 _____ (Intel Corporation) C:\Windows\system32\igfxrtrk.lrc
2017-10-26 17:12 - 2011-01-27 19:25 - 000286208 _____ (Intel Corporation) C:\Windows\system32\igfxrsve.lrc
2017-10-26 17:12 - 2011-01-27 19:25 - 000286208 _____ (Intel Corporation) C:\Windows\system32\igfxrslv.lrc
2017-10-26 17:12 - 2011-01-27 19:25 - 000286208 _____ (Intel Corporation) C:\Windows\system32\igfxrptb.lrc
2017-10-26 17:12 - 2011-01-27 19:25 - 000286208 _____ (Intel Corporation) C:\Windows\system32\igfxrnor.lrc
2017-10-26 17:12 - 2011-01-27 19:25 - 000286208 _____ (Intel Corporation) C:\Windows\system32\igfxrhun.lrc
2017-10-26 17:12 - 2011-01-27 19:25 - 000286208 _____ (Intel Corporation) C:\Windows\system32\igfxrfin.lrc
2017-10-26 17:12 - 2011-01-27 19:25 - 000285696 _____ (Intel Corporation) C:\Windows\system32\igfxrtha.lrc
2017-10-26 17:12 - 2011-01-27 19:25 - 000285696 _____ (Intel Corporation) C:\Windows\system32\igfxrdan.lrc
2017-10-26 17:12 - 2011-01-27 19:25 - 000285184 _____ (Intel Corporation) C:\Windows\system32\igfxrheb.lrc
2017-10-26 17:12 - 2011-01-27 19:25 - 000285184 _____ (Intel Corporation) C:\Windows\system32\igfxrara.lrc
2017-10-26 17:12 - 2011-01-27 19:25 - 000283648 _____ (Intel Corporation) C:\Windows\system32\igfxrjpn.lrc
2017-10-26 17:12 - 2011-01-27 19:25 - 000283136 _____ (Intel Corporation) C:\Windows\system32\igfxrkor.lrc
2017-10-26 17:12 - 2011-01-27 19:25 - 000282624 _____ (Intel Corporation) C:\Windows\system32\igfxrcht.lrc
2017-10-26 17:12 - 2011-01-27 19:25 - 000282624 _____ (Intel Corporation) C:\Windows\system32\igfxrchs.lrc
2017-10-26 17:12 - 2011-01-27 19:25 - 000126976 _____ (Intel Corporation) C:\Windows\system32\igfxcpl.cpl
2017-10-26 17:12 - 2011-01-27 19:24 - 000380928 _____ (Intel Corporation) C:\Windows\system32\igfxTMM.dll
2017-10-26 17:12 - 2011-01-27 19:24 - 000335872 _____ (Intel Corporation) C:\Windows\system32\igfxpph.dll
2017-10-26 17:12 - 2011-01-27 19:24 - 000028672 _____ (Intel Corporation) C:\Windows\system32\igfxexps.dll
2017-10-26 17:12 - 2011-01-27 19:23 - 000004096 _____ ( ) C:\Windows\system32\IGFXDEVLib.dll
2017-10-26 17:12 - 2011-01-27 19:22 - 000285696 _____ (Intel Corporation) C:\Windows\system32\igfxrenu.lrc
2017-10-26 17:12 - 2011-01-27 19:22 - 000142336 _____ (Intel Corporation) C:\Windows\system32\igfxdo.dll
2017-10-26 17:12 - 2011-01-27 19:18 - 000024576 _____ (Intel Corporation) C:\Windows\SysWOW64\igfxexps32.dll
2017-10-26 17:12 - 2011-01-27 19:17 - 000288768 _____ (Intel Corporation) C:\Windows\SysWOW64\igfxdv32.dll
2017-10-26 17:12 - 2011-01-27 19:11 - 001991936 _____ C:\Windows\system32\iglhxa64.cpa
2017-10-26 17:12 - 2011-01-27 19:11 - 000368640 _____ (Intel Corporation) C:\Windows\SysWOW64\iglhsip32.dll
2017-10-26 17:12 - 2011-01-27 19:11 - 000364032 _____ (Intel Corporation) C:\Windows\system32\iglhsip64.dll
2017-10-26 17:12 - 2011-01-27 19:11 - 000142848 _____ (Intel Corporation) C:\Windows\SysWOW64\igfxcmrt32.dll
2017-10-26 17:12 - 2011-01-27 19:11 - 000122368 _____ (Intel Corporation) C:\Windows\system32\igfxcmrt64.dll
2017-10-26 17:12 - 2011-01-27 19:11 - 000095744 _____ (Intel Corporation) C:\Windows\system32\iglhcp64.dll
2017-10-26 17:12 - 2011-01-27 19:11 - 000086528 _____ (Intel Corporation) C:\Windows\SysWOW64\iglhcp32.dll
2017-10-26 17:12 - 2011-01-27 19:11 - 000060254 _____ C:\Windows\system32\iglhxg64.vp
2017-10-26 17:12 - 2011-01-27 19:11 - 000060226 _____ C:\Windows\system32\iglhxc64.vp
2017-10-26 17:12 - 2011-01-27 19:11 - 000060015 _____ C:\Windows\system32\iglhxo64.vp
2017-10-26 17:12 - 2011-01-27 19:11 - 000001090 _____ C:\Windows\system32\iglhxa64.vp
 
2017-10-26 17:11 - 2017-10-26 17:11 - 000000000 ____D C:\ProgramData\CyberLink
2017-10-26 17:11 - 2011-03-15 21:28 - 009259520 _____ (ATI Technologies Inc.) C:\Windows\system32\Drivers\atikmdag.sys
2017-10-26 17:11 - 2011-03-15 21:26 - 022518272 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atio6axx.dll
2017-10-26 17:11 - 2011-03-15 21:06 - 017397248 _____ (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\atioglxx.dll
2017-10-26 17:11 - 2011-03-15 21:02 - 000680960 _____ (ATI Technologies Inc. ) C:\Windows\SysWOW64\aticfx32.dll
2017-10-26 17:11 - 2011-03-15 21:02 - 000152384 _____ C:\Windows\system32\atiapfxx.blb
2017-10-26 17:11 - 2011-03-15 21:02 - 000143360 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atiapfxx.exe
2017-10-26 17:11 - 2011-03-15 21:01 - 000796160 _____ (ATI Technologies Inc. ) C:\Windows\system32\aticfx64.dll
2017-10-26 17:11 - 2011-03-15 20:59 - 000480256 _____ (AMD) C:\Windows\system32\atieclxx.exe
2017-10-26 17:11 - 2011-03-15 20:59 - 000462848 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\ATIDEMGX.dll
2017-10-26 17:11 - 2011-03-15 20:58 - 000203776 _____ (AMD) C:\Windows\system32\atiesrxx.exe
2017-10-26 17:11 - 2011-03-15 20:57 - 000423424 _____ (ATI Technologies, Inc.) C:\Windows\system32\atipdl64.dll
2017-10-26 17:11 - 2011-03-15 20:57 - 000356352 _____ (ATI Technologies, Inc.) C:\Windows\SysWOW64\atipdlxx.dll
2017-10-26 17:11 - 2011-03-15 20:57 - 000278528 _____ (ATI Technologies, Inc.) C:\Windows\SysWOW64\Oemdspif.dll
2017-10-26 17:11 - 2011-03-15 20:57 - 000120320 _____ (AMD) C:\Windows\system32\atitmm64.dll
2017-10-26 17:11 - 2011-03-15 20:56 - 000059392 _____ (ATI Technologies, Inc.) C:\Windows\system32\atiedu64.dll
2017-10-26 17:11 - 2011-03-15 20:56 - 000043520 _____ (ATI Technologies, Inc.) C:\Windows\SysWOW64\ati2edxx.dll
2017-10-26 17:11 - 2011-03-15 20:56 - 000016384 _____ (AMD) C:\Windows\system32\atimuixx.dll
2017-10-26 17:11 - 2011-03-15 20:54 - 004277760 _____ (ATI Technologies Inc. ) C:\Windows\SysWOW64\atidxx32.dll
2017-10-26 17:11 - 2011-03-15 20:46 - 005044224 _____ (ATI Technologies Inc. ) C:\Windows\system32\atidxx64.dll
2017-10-26 17:11 - 2011-03-15 20:39 - 007025152 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\aticaldd64.dll
2017-10-26 17:11 - 2011-03-15 20:39 - 000051200 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\aticalrt64.dll
2017-10-26 17:11 - 2011-03-15 20:39 - 000046080 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticalrt.dll
2017-10-26 17:11 - 2011-03-15 20:39 - 000044544 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\aticalcl64.dll
2017-10-26 17:11 - 2011-03-15 20:39 - 000044032 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticalcl.dll
2017-10-26 17:11 - 2011-03-15 20:38 - 005619200 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticaldd.dll
2017-10-26 17:11 - 2011-03-15 20:37 - 004294656 _____ (ATI Technologies Inc. ) C:\Windows\SysWOW64\atiumdag.dll
2017-10-26 17:11 - 2011-03-15 20:35 - 003239936 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiumd6a.dll
2017-10-26 17:11 - 2011-03-15 20:35 - 001912832 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiumdmv.dll
2017-10-26 17:11 - 2011-03-15 20:35 - 001208320 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiumd6v.dll
2017-10-26 17:11 - 2011-03-15 20:32 - 000788800 _____ C:\Windows\system32\atiumd6a.cap
2017-10-26 17:11 - 2011-03-15 20:31 - 005438976 _____ (ATI Technologies Inc. ) C:\Windows\system32\atiumd64.dll
2017-10-26 17:11 - 2011-03-15 20:31 - 000058880 _____ (AMD) C:\Windows\system32\coinst.dll
2017-10-26 17:11 - 2011-03-15 20:28 - 003471872 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiumdva.dll
2017-10-26 17:11 - 2011-03-15 20:27 - 000788800 _____ C:\Windows\SysWOW64\atiumdva.cap
2017-10-26 17:11 - 2011-03-15 20:25 - 000360448 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atiadlxx.dll
2017-10-26 17:11 - 2011-03-15 20:25 - 000258048 _____ (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\atiadlxy.dll
2017-10-26 17:11 - 2011-03-15 20:25 - 000014848 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atig6pxx.dll
2017-10-26 17:11 - 2011-03-15 20:24 - 000301056 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\Drivers\atikmpag.sys
2017-10-26 17:11 - 2011-03-15 20:24 - 000039936 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiuxp64.dll
2017-10-26 17:11 - 2011-03-15 20:24 - 000039936 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atig6txx.dll
2017-10-26 17:11 - 2011-03-15 20:24 - 000032768 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atigktxx.dll
2017-10-26 17:11 - 2011-03-15 20:24 - 000012800 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiglpxx.dll
2017-10-26 17:11 - 2011-03-15 20:23 - 000053248 _____ (ATI Technologies Inc.) C:\Windows\system32\Drivers\ati2erec.dll
2017-10-26 17:11 - 2011-03-15 20:23 - 000038400 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiu9p64.dll
2017-10-26 17:11 - 2011-03-15 20:23 - 000031232 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiuxpag.dll
2017-10-26 17:11 - 2011-03-15 20:23 - 000028672 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiu9pag.dll
2017-10-26 17:11 - 2011-03-15 20:16 - 000053760 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atimpc64.dll
2017-10-26 17:11 - 2011-03-15 20:16 - 000053760 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\amdpcom64.dll
2017-10-26 17:11 - 2011-03-15 20:16 - 000052736 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atimpc32.dll
2017-10-26 17:11 - 2011-03-15 20:16 - 000052736 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\amdpcom32.dll
2017-10-26 17:11 - 2011-02-02 04:01 - 000227586 _____ C:\Windows\system32\atiicdxx.dat
2017-10-26 17:11 - 2011-01-27 20:15 - 004368920 _____ (Intel Corporation) C:\Windows\system32\GfxUI.exe
2017-10-26 17:11 - 2011-01-27 20:15 - 000391704 _____ (Intel Corporation) C:\Windows\system32\hkcmd.exe
2017-10-26 17:11 - 2011-01-27 20:15 - 000179736 _____ C:\Windows\system32\difx64.exe
2017-10-26 17:11 - 2011-01-27 19:57 - 012273408 _____ (Intel Corporation) C:\Windows\system32\Drivers\igdpmd64.sys
2017-10-26 17:11 - 2011-01-27 19:57 - 012273408 _____ (Intel Corporation) C:\Windows\system32\Drivers\igdkmd64.sys
2017-10-26 17:11 - 2011-01-27 19:57 - 007470080 _____ (Intel Corporation) C:\Windows\system32\igdumd64.dll
2017-10-26 17:11 - 2011-01-27 19:55 - 000145804 _____ C:\Windows\SysWOW64\igcompkrng600.bin
2017-10-26 17:11 - 2011-01-27 19:55 - 000145804 _____ C:\Windows\system32\igcompkrng600.bin
2017-10-26 17:11 - 2011-01-27 19:51 - 005689344 _____ (Intel Corporation) C:\Windows\SysWOW64\igdumd32.dll
2017-10-26 17:11 - 2011-01-27 19:47 - 007386112 _____ (Intel Corporation) C:\Windows\system32\igd10umd64.dll
2017-10-26 17:11 - 2011-01-27 19:44 - 006068224 _____ (Intel Corporation) C:\Windows\SysWOW64\igd10umd32.dll
2017-10-26 17:11 - 2011-01-27 19:38 - 019591680 _____ (Intel Corporation) C:\Windows\system32\ig4icd64.dll
2017-10-26 17:11 - 2011-01-27 19:30 - 014292992 _____ (Intel Corporation) C:\Windows\SysWOW64\ig4icd32.dll
2017-10-26 17:11 - 2011-01-27 19:26 - 000208335 _____ C:\Windows\system32\Gfxres.th-TH.resources
2017-10-26 17:11 - 2011-01-27 19:26 - 000135119 _____ C:\Windows\system32\Gfxres.ro-RO.resources
2017-10-26 17:11 - 2011-01-27 19:26 - 000133868 _____ C:\Windows\system32\Gfxres.tr-TR.resources
2017-10-26 17:11 - 2011-01-27 19:26 - 000132422 _____ C:\Windows\system32\Gfxres.sv-SE.resources
2017-10-26 17:11 - 2011-01-27 19:26 - 000130414 _____ C:\Windows\system32\Gfxres.hr-HR.resources
2017-10-26 17:11 - 2011-01-27 19:26 - 000127599 _____ C:\Windows\system32\Gfxres.sl-SI.resources
2017-10-26 17:11 - 2011-01-27 19:26 - 000116413 _____ C:\Windows\system32\Gfxres.zh-TW.resources
2017-10-26 17:11 - 2011-01-27 19:26 - 000115195 _____ C:\Windows\system32\Gfxres.zh-CN.resources
2017-10-26 17:11 - 2011-01-27 19:25 - 000195681 _____ C:\Windows\system32\Gfxres.el-GR.resources
2017-10-26 17:11 - 2011-01-27 19:25 - 000180246 _____ C:\Windows\system32\Gfxres.ru-RU.resources
2017-10-26 17:11 - 2011-01-27 19:25 - 000154366 _____ C:\Windows\system32\Gfxres.ar-SA.resources
2017-10-26 17:11 - 2011-01-27 19:25 - 000151350 _____ C:\Windows\system32\Gfxres.ja-JP.resources
2017-10-26 17:11 - 2011-01-27 19:25 - 000147392 _____ C:\Windows\system32\Gfxres.he-IL.resources
2017-10-26 17:11 - 2011-01-27 19:25 - 000138635 _____ C:\Windows\system32\Gfxres.it-IT.resources
2017-10-26 17:11 - 2011-01-27 19:25 - 000137000 _____ C:\Windows\system32\Gfxres.ko-KR.resources
2017-10-26 17:11 - 2011-01-27 19:25 - 000136226 _____ C:\Windows\system32\Gfxres.de-DE.resources
2017-10-26 17:11 - 2011-01-27 19:25 - 000136172 _____ C:\Windows\system32\Gfxres.es-ES.resources
2017-10-26 17:11 - 2011-01-27 19:25 - 000134081 _____ C:\Windows\system32\Gfxres.fr-FR.resources
2017-10-26 17:11 - 2011-01-27 19:25 - 000133321 _____ C:\Windows\system32\Gfxres.pt-BR.resources
2017-10-26 17:11 - 2011-01-27 19:25 - 000132876 _____ C:\Windows\system32\Gfxres.nl-NL.resources
2017-10-26 17:11 - 2011-01-27 19:25 - 000132861 _____ C:\Windows\system32\Gfxres.hu-HU.resources
2017-10-26 17:11 - 2011-01-27 19:25 - 000132299 _____ C:\Windows\system32\Gfxres.pt-PT.resources
2017-10-26 17:11 - 2011-01-27 19:25 - 000131897 _____ C:\Windows\system32\Gfxres.cs-CZ.resources
2017-10-26 17:11 - 2011-01-27 19:25 - 000131711 _____ C:\Windows\system32\Gfxres.pl-PL.resources
2017-10-26 17:11 - 2011-01-27 19:25 - 000131456 _____ C:\Windows\system32\Gfxres.fi-FI.resources
2017-10-26 17:11 - 2011-01-27 19:25 - 000131290 _____ C:\Windows\system32\Gfxres.sk-SK.resources
2017-10-26 17:11 - 2011-01-27 19:25 - 000127367 _____ C:\Windows\system32\Gfxres.nb-NO.resources
2017-10-26 17:11 - 2011-01-27 19:25 - 000127109 _____ C:\Windows\system32\Gfxres.da-DK.resources
2017-10-26 17:11 - 2011-01-27 19:25 - 000122646 _____ C:\Windows\system32\Gfxres.en-US.resources
2017-10-26 17:11 - 2011-01-27 19:23 - 000144896 _____ (Intel Corporation) C:\Windows\system32\gfxSrvc.dll
2017-10-26 17:11 - 2011-01-27 19:15 - 000000151 _____ C:\Windows\system32\GfxUI.exe.config
2017-10-26 17:11 - 2011-01-14 23:00 - 000030831 _____ C:\Windows\atiogl.xml
2017-10-26 17:11 - 2011-01-13 09:03 - 000003155 _____ C:\Windows\SysWOW64\atipblag.dat
2017-10-26 17:11 - 2011-01-13 09:03 - 000003155 _____ C:\Windows\system32\atipblag.dat
2017-10-26 17:11 - 2010-10-15 12:28 - 000317440 _____ (Intel(R) Corporation) C:\Windows\system32\Drivers\IntcDAud.sys
2017-10-26 17:11 - 2010-10-15 12:27 - 000014848 _____ (Intel(R) Corporation) C:\Windows\system32\IntcDAuC.dll
2017-10-26 17:11 - 2009-05-12 04:35 - 000118784 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atibtmon.exe
2017-10-26 17:10 - 2017-11-02 14:06 - 000109752 _____ C:\Users\Personal\AppData\Local\GDIPFONTCACHEV1.DAT
2017-10-26 17:10 - 2017-10-26 17:10 - 000001945 _____ C:\Windows\epplauncher.mif
2017-10-26 17:10 - 2017-10-26 17:10 - 000001145 _____ C:\Users\Personal\Desktop\CyberLink YouCam.lnk
2017-10-26 17:09 - 2017-10-27 18:48 - 000000000 ____D C:\Program Files (x86)\InstallShield Installation Information
2017-10-26 17:09 - 2017-10-26 17:11 - 000000000 ____D C:\Users\Personal\Documents\YouCam
2017-10-26 17:09 - 2017-10-26 17:09 - 000002117 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
2017-10-26 17:09 - 2017-10-26 17:09 - 000000000 ____D C:\Users\Personal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink YouCam
2017-10-26 17:09 - 2017-10-26 17:09 - 000000000 ____D C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink YouCam
2017-10-26 17:09 - 2017-10-26 17:09 - 000000000 ____D C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink YouCam
2017-10-26 17:09 - 2017-10-26 17:09 - 000000000 ____D C:\Program Files\Microsoft Security Client
2017-10-26 17:09 - 2017-10-26 17:09 - 000000000 ____D C:\Program Files (x86)\Microsoft Security Client
2017-10-26 17:08 - 2017-10-26 17:09 - 000000000 ____D C:\Program Files (x86)\CyberLink
2017-10-26 17:01 - 2017-11-03 02:28 - 000000000 ____D C:\Program Files (x86)\Microsoft Office
2017-10-26 17:01 - 2017-10-26 17:01 - 000000000 ____D C:\Users\Personal\AppData\Local\Microsoft Help
2017-10-26 17:00 - 2017-11-06 16:52 - 000000000 ____D C:\Users\Personal\AppData\Roaming\Skype
2017-10-26 17:00 - 2017-11-03 02:13 - 000002697 _____ C:\Users\Public\Desktop\Skype.lnk
2017-10-26 17:00 - 2017-11-03 02:13 - 000000000 ____D C:\ProgramData\Skype
2017-10-26 17:00 - 2017-10-26 17:00 - 000000000 ____D C:\Users\Personal\Tracing
2017-10-26 16:56 - 2017-10-27 16:26 - 000000000 ____D C:\ProgramData\Package Cache
2017-10-26 16:55 - 2017-11-03 02:30 - 000000000 ____D C:\Users\Personal\AppData\LocalLow\Mozilla
2017-10-26 16:55 - 2017-10-26 16:55 - 000000936 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2017-10-26 16:55 - 2017-10-26 16:55 - 000000924 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2017-10-26 16:55 - 2017-10-26 16:55 - 000000000 ____D C:\Users\Personal\AppData\Roaming\Mozilla
2017-10-26 16:55 - 2017-10-26 16:55 - 000000000 ____D C:\Users\Personal\AppData\Local\Mozilla
2017-10-26 16:55 - 2017-10-26 16:55 - 000000000 ____D C:\Program Files\Mozilla Firefox
2017-10-26 16:55 - 2017-10-26 16:55 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2017-10-26 16:54 - 2017-10-26 16:54 - 000002746 _____ C:\Users\Public\Desktop\Nero StartSmart.lnk
2017-10-26 16:54 - 2017-10-26 16:54 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero 7 Ultra Edition
2017-10-26 16:53 - 2017-10-27 14:56 - 000000000 ____D C:\Users\Personal\AppData\Roaming\Ahead
2017-10-26 16:53 - 2017-10-26 16:53 - 000000000 ____D C:\ProgramData\Nero
2017-10-26 16:53 - 2017-10-26 16:53 - 000000000 ____D C:\Program Files (x86)\Nero
2017-10-26 16:52 - 2006-03-31 12:40 - 002388176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_30.dll
2017-10-26 16:52 - 2005-12-05 18:09 - 002323664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_28.dll
2017-10-26 16:47 - 2017-10-26 16:47 - 003306652 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2017-10-26 16:44 - 2017-11-03 02:02 - 000004476 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2017-10-26 16:43 - 2017-11-03 01:12 - 000000000 ____D C:\Users\Personal\AppData\Roaming\vlc
2017-10-26 16:43 - 2017-10-26 16:43 - 000002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2017-10-26 16:43 - 2017-10-26 16:43 - 000002047 _____ C:\Users\Public\Desktop\Acrobat Reader DC.lnk
2017-10-26 16:43 - 2017-10-26 16:43 - 000000871 _____ C:\Users\Public\Desktop\VLC media player.lnk
2017-10-26 16:43 - 2017-10-26 16:43 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2017-10-26 16:43 - 2017-10-26 16:43 - 000000000 ____D C:\Program Files\VideoLAN
2017-10-26 16:43 - 2017-10-26 16:43 - 000000000 ____D C:\Program Files (x86)\Adobe
2017-10-26 16:42 - 2017-10-27 14:49 - 000000000 ____D C:\ProgramData\Adobe
2017-10-26 16:35 - 2017-10-26 16:35 - 000000000 ____D C:\Program Files\Common Files\ATI Technologies
2017-10-26 16:35 - 2017-10-26 16:35 - 000000000 ____D C:\Program Files\AMD
2017-10-26 16:34 - 2015-10-09 21:27 - 000161304 _____ C:\Windows\system32\hsa-thunk64.dll
2017-10-26 16:34 - 2015-10-09 21:27 - 000151576 _____ C:\Windows\SysWOW64\hsa-thunk.dll
2017-10-26 16:34 - 2015-10-09 21:27 - 000151056 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\mantle64.dll
2017-10-26 16:34 - 2015-10-09 21:27 - 000126480 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\mantle32.dll
2017-10-26 16:34 - 2015-10-09 21:27 - 000117776 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\mantleaxl64.dll
2017-10-26 16:34 - 2015-10-09 21:27 - 000098320 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\mantleaxl32.dll
2017-10-26 16:34 - 2015-10-09 21:26 - 000873488 _____ (AMD) C:\Windows\system32\coinst_15.20.dll
2017-10-26 16:34 - 2015-10-09 21:26 - 000012816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\detoured.dll
2017-10-26 16:34 - 2015-10-09 21:26 - 000012816 _____ (Microsoft Corporation) C:\Windows\system32\detoured.dll
2017-10-26 16:34 - 2015-10-09 21:24 - 000451096 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atidemgy.dll
2017-10-26 16:34 - 2015-10-09 21:24 - 000099344 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiglpxx.dll
2017-10-26 16:34 - 2015-10-09 21:23 - 047794200 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\amdocl64.dll
2017-10-26 16:34 - 2015-10-09 21:23 - 000943128 _____ (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\atiadlxx.dll
2017-10-26 16:34 - 2015-10-09 21:23 - 000061976 _____ C:\Windows\system32\amdverag.dll
2017-10-26 16:34 - 2015-10-09 21:22 - 027544592 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\amdocl12cl64.dll
2017-10-26 16:34 - 2015-10-09 21:22 - 022327320 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\amdocl12cl.dll
2017-10-26 16:34 - 2015-10-09 21:21 - 039720976 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\amdocl.dll
2017-10-26 16:34 - 2015-10-09 21:21 - 006354456 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\amdmantle64.dll
2017-10-26 16:34 - 2015-10-09 21:21 - 000059416 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\amdmmcl6.dll
2017-10-26 16:34 - 2015-10-09 21:21 - 000047128 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\amdmmcl.dll
2017-10-26 16:34 - 2015-10-09 21:20 - 005138456 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\amdmantle32.dll
2017-10-26 16:34 - 2015-10-09 21:20 - 000305400 _____ (Advanced Micro Devices) C:\Windows\system32\Drivers\amdacpksd.sys
2017-10-26 16:34 - 2015-10-09 21:20 - 000073752 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll
2017-10-26 16:34 - 2015-10-09 21:20 - 000068112 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll
2017-10-26 16:34 - 2015-10-09 18:27 - 000662480 _____ C:\Windows\SysWOW64\atiapfxx.blb
2017-10-26 16:34 - 2015-10-09 18:27 - 000322868 _____ C:\Windows\system32\ativvaxy_vi.dat
2017-10-26 16:34 - 2015-10-09 18:27 - 000321200 _____ C:\Windows\system32\ativvaxy_vi_nd.dat
2017-10-26 16:34 - 2015-10-09 18:27 - 000255808 _____ C:\Windows\system32\ativvaxy_cz_nd.dat
2017-10-26 16:34 - 2015-10-09 18:27 - 000250884 _____ C:\Windows\system32\ativvaxy_FJ.dat
2017-10-26 16:34 - 2015-10-09 18:27 - 000249088 _____ C:\Windows\system32\ativvaxy_FJ_nd.dat
2017-10-26 16:34 - 2015-10-09 18:27 - 000234420 _____ C:\Windows\system32\ativvaxy_cik.dat
2017-10-26 16:34 - 2015-10-09 18:27 - 000232752 _____ C:\Windows\system32\ativvaxy_cik_nd.dat
2017-10-26 16:34 - 2015-10-09 18:27 - 000204952 _____ C:\Windows\SysWOW64\ativvsvl.dat
2017-10-26 16:34 - 2015-10-09 18:27 - 000204952 _____ C:\Windows\system32\ativvsvl.dat
2017-10-26 16:34 - 2015-10-09 18:27 - 000177344 _____ C:\Windows\system32\ativce03.dat
2017-10-26 16:34 - 2015-10-09 18:27 - 000157144 _____ C:\Windows\SysWOW64\ativvsva.dat
2017-10-26 16:34 - 2015-10-09 18:27 - 000157144 _____ C:\Windows\system32\ativvsva.dat
2017-10-26 16:34 - 2015-10-09 18:27 - 000100816 _____ C:\Windows\system32\ativce02.dat
2017-10-26 16:34 - 2015-10-09 18:27 - 000020790 _____ C:\Windows\SysWOW64\ativvsnl.dat
2017-10-26 16:34 - 2015-10-09 18:27 - 000020790 _____ C:\Windows\system32\ativvsnl.dat
2017-10-26 16:34 - 2015-10-09 18:27 - 000000025 _____ C:\Windows\SysWOW64\ativvsny.dat
2017-10-26 16:34 - 2015-10-09 18:27 - 000000025 _____ C:\Windows\system32\ativvsny.dat
2017-10-26 16:34 - 2015-10-09 18:26 - 000842001 _____ C:\Windows\system32\amdicdxx.dat
2017-10-26 16:34 - 2015-10-09 18:26 - 000175648 _____ C:\Windows\system32\amde31a.dat
2017-10-26 16:33 - 2015-10-09 21:26 - 000243728 _____ C:\Windows\system32\clinfo.exe
2017-10-26 16:33 - 2015-10-09 21:20 - 000237584 _____ C:\Windows\system32\amdgfxinfo64.dll
2017-10-26 16:33 - 2015-10-09 21:20 - 000209936 _____ C:\Windows\SysWOW64\amdgfxinfo32.dll
2017-10-26 16:32 - 2015-10-09 21:25 - 000341520 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\ATIODE.exe
2017-10-26 16:32 - 2015-10-09 21:25 - 000059920 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\ATIODCLI.exe
2017-10-26 16:32 - 2015-10-09 21:24 - 000219160 _____ C:\Windows\system32\atieah64.exe
2017-10-26 16:32 - 2015-10-09 21:24 - 000198168 _____ C:\Windows\SysWOW64\atieah32.exe
2017-10-26 16:32 - 2015-10-09 21:21 - 001196072 _____ C:\Windows\system32\amdocl_as64.exe
2017-10-26 16:32 - 2015-10-09 21:21 - 001070632 _____ C:\Windows\system32\amdocl_ld64.exe
2017-10-26 16:32 - 2015-10-09 21:21 - 001004072 _____ C:\Windows\SysWOW64\amdocl_as32.exe
2017-10-26 16:32 - 2015-10-09 21:21 - 000807464 _____ C:\Windows\SysWOW64\amdocl_ld32.exe
2017-10-26 16:24 - 2017-10-26 16:24 - 000000000 ____H C:\Windows\system32\Drivers\MsftWdf_Kernel_01011_Coinstaller_Critical.Wdf
2017-10-26 16:24 - 2017-10-26 16:24 - 000000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_WinUSB_01009.Wdf
2017-10-26 16:24 - 2017-10-26 16:24 - 000000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_TeeDriverx64_01011.Wdf
2017-10-26 16:24 - 2017-10-26 16:24 - 000000000 ____D C:\Windows\SysWOW64\sda
2017-10-26 16:24 - 2012-09-24 12:40 - 000043840 _____ (Hewlett-Packard Company) C:\Windows\system32\Drivers\Accelerometer.sys
2017-10-26 16:24 - 2012-09-24 12:40 - 000031040 _____ (Hewlett-Packard Company) C:\Windows\system32\Drivers\hpdskflt.sys
2017-10-26 16:24 - 2012-07-26 07:55 - 000785512 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys
2017-10-26 16:24 - 2012-07-26 07:55 - 000054376 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdfLdr.sys
2017-10-26 16:24 - 2012-07-26 05:36 - 000009728 _____ (Microsoft Corporation) C:\Windows\system32\Wdfres.dll
2017-10-26 16:24 - 2012-06-02 17:35 - 000000003 _____ C:\Windows\system32\Drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
2017-10-26 16:23 - 2015-10-08 22:15 - 000180480 _____ (Intel Corporation) C:\Windows\system32\Drivers\TeeDriverx64.sys
2017-10-26 16:23 - 2015-05-04 10:06 - 011531536 _____ (Intel Corporation) C:\Windows\system32\Drivers\NETwsw00.sys
2017-10-26 16:23 - 2013-07-09 20:53 - 001002728 _____ (Microsoft Corporation) C:\Windows\system32\WinUSBCoInstaller2.dll
2017-10-26 16:23 - 2012-09-24 12:40 - 000031040 _____ (Hewlett-Packard Company) C:\Windows\system32\hpservice.exe
2017-10-26 16:23 - 2012-09-24 12:40 - 000021312 _____ (Hewlett-Packard Company) C:\Windows\system32\accelerometerdll.DLL
2017-10-26 16:23 - 2012-09-24 12:40 - 000018240 _____ (Hewlett-Packard Company) C:\Windows\system32\HPMDPCoInst12.dll
2017-10-26 16:23 - 2012-08-03 06:51 - 001721576 _____ (Microsoft Corporation) C:\Windows\system32\WdfCoInstaller01009.dll
2017-10-26 16:22 - 2015-10-16 11:26 - 000367320 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\Drivers\RtsPStor.sys
2017-10-26 16:22 - 2014-10-20 17:50 - 000083160 _____ (Realtek Semiconductor.) C:\Windows\system32\RtCRX64.dll
2017-10-26 16:22 - 2014-01-27 13:39 - 009890008 _____ (Realtek Semiconductor Corp.) C:\Windows\SysWOW64\RsCRIcon.dll
2017-10-26 16:22 - 2012-08-17 11:57 - 001795952 _____ (Microsoft Corporation) C:\Windows\system32\WdfCoInstaller01011.dll
2017-10-26 16:18 - 2017-10-26 16:41 - 000000000 ____D C:\Users\Personal\AppData\Roaming\DRPSu
2017-10-26 16:13 - 2017-10-26 17:19 - 000000000 ____D C:\Program Files (x86)\Intel
2017-10-26 16:13 - 2017-10-26 16:13 - 000000000 ____D C:\Intel
2017-10-26 16:13 - 2012-08-27 18:39 - 000226696 _____ (Renesas Electronics Corporation) C:\Windows\system32\Drivers\nusb3xhc.sys
2017-10-26 16:13 - 2012-08-27 18:39 - 000107912 _____ (Renesas Electronics Corporation) C:\Windows\system32\Drivers\nusb3hub.sys
2017-10-26 16:13 - 2011-12-26 08:38 - 000081920 _____ (Renesas Electronics Corporation) C:\Windows\system32\nusb3co3.dll
2017-10-26 16:12 - 2015-06-04 22:20 - 000116224 _____ (Intel Corporation) C:\Windows\system32\igfxCoIn_v4229.dll
2017-10-26 16:12 - 2015-05-26 20:50 - 003511296 _____ (Intel Corporation) C:\Windows\system32\igfxcmjit64.dll
2017-10-26 16:12 - 2015-05-26 20:50 - 003121152 _____ (Intel Corporation) C:\Windows\SysWOW64\igfxcmjit32.dll
2017-10-26 16:12 - 2015-05-26 20:50 - 000575488 _____ (Intel Corporation) C:\Windows\system32\igfx11cmrt64.dll
2017-10-26 16:12 - 2015-05-26 20:50 - 000542720 _____ (Intel Corporation) C:\Windows\SysWOW64\igfx11cmrt32.dll
2017-10-26 16:12 - 2015-05-26 20:50 - 000059104 _____ C:\Windows\system32\iglhxc64_dev.vp
2017-10-26 16:12 - 2015-05-26 20:50 - 000058796 _____ C:\Windows\system32\iglhxg64_dev.vp
2017-10-26 16:12 - 2015-05-26 20:50 - 000058109 _____ C:\Windows\system32\iglhxo64_dev.vp
2017-10-26 16:12 - 2011-01-27 19:24 - 000062464 _____ (Intel Corporation) C:\Windows\system32\igfxsrvc.dll
2017-10-26 16:12 - 2011-01-27 19:23 - 000385024 _____ (Intel Corporation) C:\Windows\system32\igfxdev.dll
2017-10-26 16:12 - 2011-01-27 19:22 - 009014784 _____ (Intel Corporation) C:\Windows\system32\igfxress.dll
2017-10-26 16:11 - 2015-05-26 20:53 - 000101376 _____ C:\Windows\system32\igdde64.dll
2017-10-26 16:11 - 2015-05-26 20:53 - 000081408 _____ C:\Windows\SysWOW64\igdde32.dll
2017-10-26 16:11 - 2015-05-26 20:50 - 000094208 _____ C:\Windows\system32\IccLibDll_x64.dll
2017-10-26 16:11 - 2011-01-27 19:23 - 000109056 _____ (Intel Corporation) C:\Windows\system32\hccutils.dll
2017-10-26 16:10 - 2015-06-04 22:21 - 000280680 _____ (Intel Corporation) C:\Windows\SysWOW64\IntelCpHeciSvc.exe
2017-10-26 16:10 - 2015-05-29 17:05 - 000646408 _____ (Intel Corporation) C:\Windows\system32\Drivers\iaStorA.sys
2017-10-26 16:10 - 2015-05-29 17:05 - 000030960 _____ (Intel Corporation) C:\Windows\system32\Drivers\iaStorF.sys
2017-10-26 16:10 - 2015-05-26 20:50 - 000963452 _____ C:\Windows\SysWOW64\igcodeckrng600.bin
2017-10-26 16:10 - 2015-05-26 20:50 - 000963452 _____ C:\Windows\system32\igcodeckrng600.bin
2017-10-26 16:10 - 2015-05-26 20:50 - 000272928 _____ C:\Windows\SysWOW64\igvpkrng600.bin
2017-10-26 16:10 - 2015-05-26 20:50 - 000272928 _____ C:\Windows\system32\igvpkrng600.bin
2017-10-26 16:04 - 2014-06-22 17:57 - 000095096 _____ (TOSHIBA CORPORATION) C:\Windows\system32\Drivers\tosrfusb.sys
2017-10-26 16:04 - 2009-09-09 12:23 - 000051712 _____ (Intel Corporation) C:\Windows\system32\Drivers\flashud.sys
2017-10-26 16:04 - 2009-06-18 20:42 - 000040832 _____ (TOSHIBA CORPORATION.) C:\Windows\system32\Drivers\TosBtCi.dll
2017-10-26 16:00 - 2014-01-08 19:23 - 000898264 _____ (Realtek ) C:\Windows\system32\Drivers\Rt64win7.sys
2017-10-26 16:00 - 2014-01-08 19:23 - 000107552 _____ (Realtek Semiconductor Corporation) C:\Windows\system32\RTNUninst64.dll
2017-10-26 16:00 - 2014-01-08 19:23 - 000073800 _____ (Realtek Semiconductor Corporation) C:\Windows\system32\RtNicProp64.dll
2017-10-26 15:54 - 2017-11-02 20:16 - 000001419 _____ C:\Users\Personal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2017-10-26 15:53 - 2017-11-02 13:32 - 000000000 ____D C:\Users\Personal
2017-10-26 15:53 - 2017-10-26 15:53 - 000000020 ___SH C:\Users\Personal\ntuser.ini
2017-10-26 15:53 - 2017-10-26 15:53 - 000000000 ____D C:\Users\Personal\AppData\Local\VirtualStore
2017-10-26 15:53 - 2010-11-21 10:16 - 000000000 ____D C:\Users\Personal\AppData\Roaming\Media Center Programs

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-11-06 16:52 - 2009-07-14 08:13 - 000781298 _____ C:\Windows\system32\PerfStringBackup.INI
2017-11-06 16:52 - 2009-07-14 06:20 - 000000000 ____D C:\Windows\inf
2017-11-06 11:59 - 2009-07-14 07:45 - 000016944 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2017-11-06 11:59 - 2009-07-14 07:45 - 000016944 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2017-11-06 11:52 - 2009-07-14 08:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2017-11-03 02:27 - 2009-07-14 06:20 - 000000000 ____D C:\Program Files\Common Files\Microsoft Shared
2017-11-02 22:59 - 2009-07-14 06:20 - 000000000 ____D C:\Windows\rescache
2017-11-02 20:08 - 2009-07-14 07:45 - 000445200 _____ C:\Windows\system32\FNTCACHE.DAT
2017-11-02 20:01 - 2009-07-14 06:20 - 000000000 ____D C:\Windows\PolicyDefinitions
2017-11-02 18:28 - 2009-07-14 06:20 - 000000000 ____D C:\Windows\system32\NDF
2017-11-02 13:54 - 2010-11-21 10:17 - 000000000 ____D C:\Windows\ShellNew
2017-11-02 13:54 - 2009-07-14 08:32 - 000000000 ____D C:\Program Files (x86)\MSBuild
2017-10-28 12:38 - 2009-07-14 08:09 - 000000000 ____D C:\Windows\System32\Tasks\WPD
2017-10-27 19:54 - 2010-11-21 10:17 - 000000000 ____D C:\Program Files\Windows Journal
2017-10-27 19:54 - 2009-07-14 08:32 - 000000000 ____D C:\Program Files\Windows Sidebar
2017-10-27 19:54 - 2009-07-14 08:32 - 000000000 ____D C:\Program Files\Windows Photo Viewer
2017-10-27 19:54 - 2009-07-14 08:32 - 000000000 ____D C:\Program Files\Windows Defender
2017-10-27 19:54 - 2009-07-14 08:32 - 000000000 ____D C:\Program Files (x86)\Windows Sidebar
2017-10-27 19:54 - 2009-07-14 08:32 - 000000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2017-10-27 19:54 - 2009-07-14 06:20 - 000000000 ____D C:\Program Files\Common Files\System
2017-10-27 19:53 - 2010-11-21 10:06 - 000000000 ____D C:\Windows\SysWOW64\winrm
2017-10-27 19:53 - 2010-11-21 10:06 - 000000000 ____D C:\Windows\SysWOW64\WCN
2017-10-27 19:53 - 2010-11-21 10:06 - 000000000 ____D C:\Windows\SysWOW64\sysprep
2017-10-27 19:53 - 2010-11-21 10:06 - 000000000 ____D C:\Windows\SysWOW64\slmgr
2017-10-27 19:53 - 2010-11-21 10:06 - 000000000 ____D C:\Windows\SysWOW64\Printing_Admin_Scripts
2017-10-27 19:53 - 2010-11-21 10:06 - 000000000 ____D C:\Windows\system32\winrm
2017-10-27 19:53 - 2010-11-21 10:06 - 000000000 ____D C:\Windows\system32\WCN
2017-10-27 19:53 - 2010-11-21 10:06 - 000000000 ____D C:\Windows\system32\slmgr
2017-10-27 19:53 - 2010-11-21 10:06 - 000000000 ____D C:\Windows\system32\Printing_Admin_Scripts
2017-10-27 19:53 - 2009-07-14 08:32 - 000000000 ____D C:\Program Files (x86)\Windows Defender
2017-10-27 19:53 - 2009-07-14 06:20 - 000000000 ____D C:\Windows\SysWOW64\Setup
2017-10-27 19:53 - 2009-07-14 06:20 - 000000000 ____D C:\Windows\SysWOW64\oobe
2017-10-27 19:53 - 2009-07-14 06:20 - 000000000 ____D C:\Windows\SysWOW64\MUI
2017-10-27 19:53 - 2009-07-14 06:20 - 000000000 ____D C:\Windows\SysWOW64\migwiz
2017-10-27 19:53 - 2009-07-14 06:20 - 000000000 ____D C:\Windows\SysWOW64\Dism
2017-10-27 19:53 - 2009-07-14 06:20 - 000000000 ____D C:\Windows\SysWOW64\com
2017-10-27 19:53 - 2009-07-14 06:20 - 000000000 ____D C:\Windows\system32\sysprep
2017-10-27 19:53 - 2009-07-14 06:20 - 000000000 ____D C:\Windows\system32\Setup
2017-10-27 19:53 - 2009-07-14 06:20 - 000000000 ____D C:\Windows\system32\oobe
2017-10-27 19:53 - 2009-07-14 06:20 - 000000000 ____D C:\Windows\system32\MUI
2017-10-27 19:53 - 2009-07-14 06:20 - 000000000 ____D C:\Windows\system32\migwiz
2017-10-27 19:53 - 2009-07-14 06:20 - 000000000 ____D C:\Windows\system32\Dism
2017-10-27 19:53 - 2009-07-14 06:20 - 000000000 ____D C:\Windows\system32\com
2017-10-27 19:53 - 2009-07-14 06:20 - 000000000 ____D C:\Windows\servicing
2017-10-27 19:52 - 2009-07-14 06:20 - 000000000 ____D C:\Windows\IME
2017-10-27 18:48 - 2009-07-14 06:20 - 000000000 ____D C:\Windows\Help
2017-10-27 14:59 - 2009-07-14 06:20 - 000000000 __RHD C:\Users\Public\Libraries
2017-10-27 02:40 - 2009-07-14 08:32 - 000028672 _____ C:\Windows\system32\config\BCD-Template
2017-10-27 01:41 - 2010-11-21 10:17 - 000000000 ____D C:\Windows\CSC
2017-10-26 17:01 - 2009-07-14 05:34 - 000000478 _____ C:\Windows\win.ini

==================== Files in the root of some directories =======

2017-11-02 15:06 - 2017-11-02 15:06 - 000048371 _____ () C:\ProgramData\agent.1509624401.bdinstall.bin
2017-11-06 12:30 - 2017-11-06 12:30 - 000030401 _____ () C:\ProgramData\agent.uninstall.1509960634.bdinstall.bin
2017-11-06 11:28 - 2017-11-06 11:28 - 000030914 _____ () C:\ProgramData\agent.update.1509956921.bdinstall.bin

Some files in TEMP:
====================
2017-11-06 12:29 - 2017-11-06 12:29 - 000079904 _____ () C:\Users\Personal\AppData\Local\Temp\i4jdel0.exe

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2017-11-01 23:49

==================== End of FRST.txt ============================
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 02-11-2017
Ran by Personal (06-11-2017 16:57:20)
Running from C:\Users\Personal\Desktop
Windows 7 Professional Service Pack 1 (X64) (2017-10-26 12:53:30)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-3766277524-2784970969-2751085713-500 - Administrator - Disabled)
Guest (S-1-5-21-3766277524-2784970969-2751085713-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3766277524-2784970969-2751085713-1002 - Limited - Enabled)
Personal (S-1-5-21-3766277524-2784970969-2751085713-1000 - Administrator - Enabled) => C:\Users\Personal

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Avast Antivirus (Disabled - Up to date) {8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF}
AV: Microsoft Security Essentials (Enabled - Out of date) {3F839487-C7A2-C958-E30C-E2825BA31FB5}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Microsoft Security Essentials (Enabled - Out of date) {84E27563-E198-C6D6-D9BC-D9F020245508}
AS: Avast Antivirus (Disabled - Up to date) {35C973AA-9ABB-D3CA-B100-B0DC0E5F2402}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 15.017.20050 - Adobe Systems Incorporated)
ATI Catalyst Install Manager (HKLM\...\{DA0D8FDA-D538-1145-8BA2-6F22C4EB4F75}) (Version: 3.0.816.0 - ATI Technologies, Inc.)
Avast Free Antivirus (HKLM-x32\...\Avast Antivirus) (Version: 17.7.2314 - AVAST Software)
CrystalDiskInfo 7.1.1 (HKLM-x32\...\CrystalDiskInfo_is1) (Version: 7.1.1 - Crystal Dew World)
CyberLink YouCam (HKLM-x32\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 2.0.1519 - CyberLink Corp.)
Dropbox (HKLM-x32\...\Dropbox) (Version: 38.4.27 - Dropbox, Inc.)
Dropbox Update Helper (HKLM-x32\...\{099218A5-A723-43DC-8DB5-6173656A1E94}) (Version: 1.3.65.1 - Dropbox, Inc.) Hidden
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 62.0.3202.75 - Google Inc.)
Google Toolbar for Internet Explorer (HKLM-x32\...\{18455581-E099-4BA8-BC6B-F34B2F06600C}) (Version: 1.0.0 - Google Inc.) Hidden
Google Toolbar for Internet Explorer (HKLM-x32\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.8231.2252 - Google Inc.)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.5 - Google Inc.) Hidden
HP Support Assistant (HKLM-x32\...\{4AAC4B07-77EF-4BCF-88DC-D24E4DE683E8}) (Version: 8.5.37.19 - HP Inc.)
HP Support Solutions Framework (HKLM-x32\...\{63F82052-C045-4F97-A3CA-C41D2CCA1FFA}) (Version: 12.8.37.11 - HP Inc.)
Intel(R) Display Audio Driver (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 6.14.00.3074 - Intel Corporation)
Malwarebytes version 3.2.2.2029 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.2.2.2029 - Malwarebytes)
Microsoft .NET Framework 4.5 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50709 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-3766277524-2784970969-2751085713-1000\...\OneDriveSetup.exe) (Version: 17.3.4604.0120 - Microsoft Corporation)
Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.2.223.1 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23026 (HKLM-x32\...\{e46eca4f-393b-40df-9f49-076faf788d83}) (Version: 14.0.23026.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23026 (HKLM-x32\...\{74d0e5db-b326-4dae-a6b2-445b9de1836e}) (Version: 14.0.23026.0 - Microsoft Corporation)
Mozilla Firefox 52.0 (x64 en-US) (HKLM\...\Mozilla Firefox 52.0 (x64 en-US)) (Version: 52.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 52.0 - Mozilla)
Nero 7 Ultra Edition (HKLM-x32\...\{43FFE159-3199-4188-A1CD-629166AD1033}) (Version: 7.02.6445 - Nero AG)
PX Profile Update (HKLM-x32\...\{1C34B2AF-0D61-1784-8BC8-219F969BEFD6}) (Version: 1.00.1. - AMD) Hidden
Python 3.5.2 (32-bit) (HKU\S-1-5-21-3766277524-2784970969-2751085713-1000\...\{cf72a2ab-2f1d-49fd-a0d7-1065e6357e1e}) (Version: 3.5.2150.0 - Python Software Foundation)
Python 3.5.2 Core Interpreter (32-bit) (HKLM-x32\...\{EB0611B2-7F10-4D97-BCF2-DCAAB1199498}) (Version: 3.5.2150.0 - Python Software Foundation) Hidden
Python 3.5.2 Development Libraries (32-bit) (HKLM-x32\...\{5DB2183B-62D3-407F-BBC1-EAD2F36283FA}) (Version: 3.5.2150.0 - Python Software Foundation) Hidden
Python 3.5.2 Documentation (32-bit) (HKLM-x32\...\{1FBA5182-78DD-4940-9F06-96E5042B7061}) (Version: 3.5.2150.0 - Python Software Foundation) Hidden
Python 3.5.2 Executables (32-bit) (HKLM-x32\...\{33B10015-A9B1-4210-B50A-26C6443979B0}) (Version: 3.5.2150.0 - Python Software Foundation) Hidden
Python 3.5.2 pip Bootstrap (32-bit) (HKLM-x32\...\{9ADF9987-3327-48C6-91B3-B10900366491}) (Version: 3.5.2150.0 - Python Software Foundation) Hidden
Python 3.5.2 Standard Library (32-bit) (HKLM-x32\...\{FCBB04F4-D2CF-4F55-BE92-B3898696B318}) (Version: 3.5.2150.0 - Python Software Foundation) Hidden
Python 3.5.2 Tcl/Tk Support (32-bit) (HKLM-x32\...\{C1153533-FDC4-4922-892D-B71810F69566}) (Version: 3.5.2150.0 - Python Software Foundation) Hidden
Python 3.5.2 Test Suite (32-bit) (HKLM-x32\...\{9D50A6D7-410A-4469-87B7-35FA84CBD479}) (Version: 3.5.2150.0 - Python Software Foundation) Hidden
Python 3.5.2 Utility Scripts (32-bit) (HKLM-x32\...\{E6DEBF43-7ACF-4E88-9BBF-9B5945683281}) (Version: 3.5.2150.0 - Python Software Foundation) Hidden
Python Launcher (HKLM-x32\...\{963ECCDD-F09F-4C24-9367-8B5D748AA7C8}) (Version: 3.5.2121.0 - Python Software Foundation)
qBittorrent 3.3.16 (HKLM-x32\...\qBittorrent) (Version: 3.3.16 - The qBittorrent project)
Skype™ 7.40 (HKLM-x32\...\{3B7E914A-93D5-4A29-92BB-AF8C3F66C431}) (Version: 7.40.103 - Skype Technologies S.A.)
Spybot - Search & Destroy (HKLM-x32\...\{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1) (Version: 2.6.46 - Safer-Networking Ltd.)
VLC media player (HKLM\...\VLC media player) (Version: 2.2.6 - VideoLAN)
WinRAR archiver (HKLM-x32\...\WinRAR archiver) (Version: - )

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

ShellIconOverlayIdentifiers: [ DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2017-11-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2017-11-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2017-11-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2017-11-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2017-11-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2017-11-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2017-11-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2017-11-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2017-11-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2017-11-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-11-03] (AVAST Software)
ShellIconOverlayIdentifiers-x32: [ DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2017-11-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2017-11-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2017-11-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2017-11-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2017-11-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2017-11-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2017-11-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2017-11-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2017-11-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2017-11-01] (Dropbox, Inc.)
ContextMenuHandlers1: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-11-03] (AVAST Software)
ContextMenuHandlers1-x32: [Cover Designer] -> {73FCA462-9BD5-4065-A73F-A8E5F6904EF7} => C:\Program Files (x86)\Nero\Nero 7\Nero CoverDesigner\CoverEdExtension.dll [2007-02-28] (Nero AG)
ContextMenuHandlers1-x32: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2017-11-01] (Dropbox, Inc.)
ContextMenuHandlers1-x32: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => c:\Program Files\Microsoft Security Client\shellext.dll [2013-01-27] (Microsoft Corporation)
ContextMenuHandlers1-x32: [SDECon32] -> {44176360-2BBF-4EC1-93CE-384B8681A0BC} => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDECon64.dll [2017-05-23] (Safer-Networking Ltd.)
ContextMenuHandlers1-x32: [SDECon64] -> {44176360-2BBF-4EC1-93CE-384B8681A0BC} => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDECon64.dll [2017-05-23] (Safer-Networking Ltd.)
ContextMenuHandlers1-x32: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext64.dll [2005-06-07] ()
ContextMenuHandlers1-x32-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext.dll [2006-07-03] ()
ContextMenuHandlers2: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => c:\Program Files\Microsoft Security Client\shellext.dll [2013-01-27] (Microsoft Corporation)
ContextMenuHandlers3: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-11-03] (AVAST Software)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-08-30] (Malwarebytes)
ContextMenuHandlers4: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2017-11-01] (Dropbox, Inc.)
ContextMenuHandlers4: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => c:\Program Files\Microsoft Security Client\shellext.dll [2013-01-27] (Microsoft Corporation)
ContextMenuHandlers4: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext64.dll [2005-06-07] ()
ContextMenuHandlers4-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext.dll [2006-07-03] ()
ContextMenuHandlers5: [ACE] -> {5E2121EE-0300-11D4-8D3B-444553540000} => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\atiacm64.dll [2011-03-15] (Advanced Micro Devices, Inc.)
ContextMenuHandlers5: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2017-11-01] (Dropbox, Inc.)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => C:\Windows\system32\igfxpph.dll [2011-01-27] (Intel Corporation)
ContextMenuHandlers6: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-11-03] (AVAST Software)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-08-30] (Malwarebytes)
ContextMenuHandlers6: [SDECon32] -> {44176360-2BBF-4EC1-93CE-384B8681A0BC} => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDECon64.dll [2017-05-23] (Safer-Networking Ltd.)
ContextMenuHandlers6: [SDECon64] -> {44176360-2BBF-4EC1-93CE-384B8681A0BC} => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDECon64.dll [2017-05-23] (Safer-Networking Ltd.)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext64.dll [2005-06-07] ()
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext.dll [2006-07-03] ()

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {11FE57DC-FB70-4BDB-A0D5-F2B3F9823B08} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe [2017-05-23] (Safer-Networking Ltd.)
Task: {2349899B-F223-4E7D-B72A-B1B10B98F275} - System32\Tasks\HPCeeScheduleForPersonal => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2016-06-24] (HP Inc.)
Task: {24975BB3-483A-4206-B830-E35D6F775712} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2017-09-27] (HP Inc.)
Task: {3DE04FDF-33D0-411D-BAF5-F66A40CBA6DE} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSFReport.exe [2017-09-27] (HP Inc.)
Task: {758987D2-C8A1-468D-8F9D-F52E67A3799A} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2017-09-27] (HP Inc.)
Task: {7987ED90-E824-42B0-A9A9-A31B25226401} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Product Configurator => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\ProductConfig.exe [2017-10-11] (HP Inc.)
Task: {94A02B21-B4CB-4A60-8ABA-7B28FED6C1F2} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe [2017-05-23] (Safer-Networking Ltd.)
Task: {BEC2C0AC-A564-46E5-92D8-2923641B3031} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2017-09-27] (HP Inc.)
Task: {BF5A7ACF-A8BD-47C5-979C-F56AAF33C1D9} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2017-10-31] (Dropbox, Inc.)
Task: {C12A0A05-440C-4C93-B883-F92A09C4A642} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe [2017-05-23] (Safer-Networking Ltd.)
Task: {C4E168C0-72A9-4DA8-8178-446A2925792E} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [2017-09-27] (HP Inc.)
Task: {C70C6C6D-7504-408F-BBAE-42F26BABB359} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-10-27] (Google Inc.)
Task: {D4239F68-BE7B-4AF3-940E-3DCD882663F0} - System32\Tasks\Avast Emergency Update => C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe [2017-11-03] (AVAST Software)
Task: {D6C6FA7A-B0F2-4291-8C1E-BCDA680E83C4} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2017-10-31] (Dropbox, Inc.)
Task: {D8881422-CDE4-4DBC-9168-ED981F73AF17} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-10-27] (Google Inc.)
Task: {F6F1F239-6DFB-4DA7-897D-D6A96F7B28C2} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2017-07-19] (Adobe Systems Incorporated)
Task: {FE53B6E5-CB2B-4762-A2DF-49B25C05EA37} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2017-09-27] (HP Inc.)
Task: {FFC474F9-AAF4-458F-9968-8AEF8E2C8267} - System32\Tasks\Hewlett-Packard\HP Active Health\HP Active Health Scan (HPSA) => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPActiveHealth\ActiveHealth.exe [2017-09-27] (HP Inc.)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\Windows\Tasks\DropboxUpdateTaskMachineCore.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
Task: C:\Windows\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
Task: C:\Windows\Tasks\HPCeeScheduleForPersonal.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe

==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)


==================== Loaded Modules (Whitelisted) ==============

2017-11-02 13:08 - 2005-06-07 12:26 - 000043008 _____ () C:\Program Files (x86)\WinRAR\rarext64.dll
2017-11-02 17:05 - 2017-10-04 13:15 - 002289096 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\SelfProtectionSdk.dll
2017-11-02 17:05 - 2017-10-04 13:15 - 002358728 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\MwacLib.dll
2017-10-26 16:11 - 2015-05-26 20:50 - 000094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2011-03-14 14:21 - 2011-03-14 14:21 - 000016384 _____ () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Branding\Branding.dll
2011-03-15 09:57 - 2011-03-15 09:57 - 000243712 _____ () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll
2017-09-07 19:42 - 2017-09-07 19:42 - 022629888 _____ () C:\Program Files\qBittorrent\qbittorrent.exe
2017-11-03 01:44 - 2017-11-03 01:44 - 000067408 _____ () C:\Program Files\AVAST Software\Avast\x64\module_lifetime.dll
2017-10-27 15:07 - 2017-10-26 09:30 - 004135768 _____ () C:\Program Files (x86)\Google\Chrome\Application\62.0.3202.75\libglesv2.dll
2017-10-27 15:07 - 2017-10-26 09:30 - 000100184 _____ () C:\Program Files (x86)\Google\Chrome\Application\62.0.3202.75\libegl.dll
2017-10-27 16:44 - 2017-10-23 12:14 - 031229440 _____ () C:\Users\Personal\AppData\Local\Google\Chrome\User Data\PepperFlash\27.0.0.183\pepflashplayer.dll
2017-11-03 01:44 - 2017-11-03 01:44 - 000059040 _____ () C:\Program Files\AVAST Software\Avast\module_lifetime.dll
2017-11-03 01:44 - 2017-11-03 01:44 - 000167096 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
2017-11-03 01:44 - 2017-11-03 01:44 - 000217088 _____ () C:\Program Files\AVAST Software\Avast\event_routing_rpc.dll
2017-11-03 01:44 - 2017-11-03 01:44 - 000244584 _____ () C:\Program Files\AVAST Software\Avast\tasks_core.dll
2017-11-03 01:44 - 2017-11-03 01:44 - 000151104 _____ () C:\Program Files\AVAST Software\Avast\network_notifications.dll
2017-11-06 11:26 - 2017-11-06 11:26 - 005882552 _____ () C:\Program Files\AVAST Software\Avast\defs\17110500\algo.dll
2017-11-03 02:00 - 2017-11-03 02:02 - 000703336 _____ () C:\Program Files\AVAST Software\Avast\ffl2.dll
2017-11-03 01:44 - 2017-11-03 01:44 - 000241448 _____ () C:\Program Files\AVAST Software\Avast\streamback.dll
2017-11-06 16:49 - 2017-11-06 16:49 - 005882552 _____ () C:\Program Files\AVAST Software\Avast\defs\17110600\algo.dll
2017-11-02 17:33 - 2016-09-13 14:00 - 000109400 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlThirdParty150.bpl
2017-11-02 17:33 - 2016-09-13 14:00 - 000416600 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\DEC150.bpl
2017-11-02 17:33 - 2016-09-13 14:00 - 000167768 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlFileFormats150.bpl
2017-08-17 16:51 - 2017-08-17 16:51 - 001993184 ____R () C:\Program Files (x86)\Skype\Phone\skypert.dll
2017-11-02 23:06 - 2017-11-01 14:58 - 000724288 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox_watchdog.dll
2017-11-02 23:06 - 2017-11-01 14:58 - 002002752 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox_crashpad.dll
2017-11-02 23:06 - 2017-11-01 14:57 - 000100296 _____ () C:\Program Files (x86)\Dropbox\Client\_ctypes.pyd
2017-11-02 23:06 - 2017-11-01 14:57 - 000018888 _____ () C:\Program Files (x86)\Dropbox\Client\select.pyd
2017-11-02 23:06 - 2017-11-01 15:01 - 000020800 _____ () C:\Program Files (x86)\Dropbox\Client\tornado.speedups.pyd
2017-11-02 23:06 - 2017-11-01 14:57 - 000035792 _____ () C:\Program Files (x86)\Dropbox\Client\_multiprocessing.pyd
2017-11-02 23:06 - 2017-11-01 14:57 - 000694224 _____ () C:\Program Files (x86)\Dropbox\Client\unicodedata.pyd
2017-11-02 23:06 - 2017-11-01 15:01 - 000021848 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._constant_time.pyd
2017-11-02 23:06 - 2017-11-01 14:57 - 000130512 _____ () C:\Program Files (x86)\Dropbox\Client\_cffi_backend.pyd
2017-11-02 23:06 - 2017-11-01 15:01 - 001856848 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._openssl.pyd
2017-11-02 23:06 - 2017-11-01 15:01 - 000022864 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._padding.pyd
2017-11-02 23:06 - 2017-11-01 14:57 - 000145864 _____ () C:\Program Files (x86)\Dropbox\Client\pyexpat.pyd
2017-11-02 23:06 - 2017-11-01 14:58 - 000116688 _____ () C:\Program Files (x86)\Dropbox\Client\pywintypes27.dll
2017-11-02 23:06 - 2017-11-01 14:57 - 000105928 _____ () C:\Program Files (x86)\Dropbox\Client\win32api.pyd
2017-11-02 23:06 - 2017-11-01 15:01 - 000022864 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.crt.compiled._winffi_crt.pyd
2017-11-02 23:06 - 2017-11-01 15:01 - 000062784 _____ () C:\Program Files (x86)\Dropbox\Client\psutil._psutil_windows.pyd
2017-11-02 23:06 - 2017-11-01 14:57 - 000024528 _____ () C:\Program Files (x86)\Dropbox\Client\win32event.pyd
2017-11-02 23:06 - 2017-11-01 15:01 - 000040248 _____ () C:\Program Files (x86)\Dropbox\Client\fastpath.pyd
2017-11-02 23:06 - 2017-11-01 14:57 - 000020936 _____ () C:\Program Files (x86)\Dropbox\Client\mmapfile.pyd
2017-11-02 23:06 - 2017-11-01 14:57 - 000124880 _____ () C:\Program Files (x86)\Dropbox\Client\win32file.pyd
2017-11-02 23:06 - 2017-11-01 14:57 - 000116176 _____ () C:\Program Files (x86)\Dropbox\Client\win32security.pyd
2017-11-02 23:06 - 2017-11-01 14:58 - 000392656 _____ () C:\Program Files (x86)\Dropbox\Client\pythoncom27.dll
2017-11-02 23:06 - 2017-11-01 15:01 - 000392512 _____ () C:\Program Files (x86)\Dropbox\Client\win32com.shell.shell.pyd
2017-11-02 23:06 - 2017-11-01 15:01 - 000026456 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.kernel32.compiled._winffi_kernel32.pyd
2017-11-02 23:06 - 2017-11-01 14:57 - 000024016 _____ () C:\Program Files (x86)\Dropbox\Client\win32clipboard.pyd
2017-11-02 23:06 - 2017-11-01 14:57 - 000175560 _____ () C:\Program Files (x86)\Dropbox\Client\win32gui.pyd
2017-11-02 23:06 - 2017-11-01 14:57 - 000030160 _____ () C:\Program Files (x86)\Dropbox\Client\win32pipe.pyd
2017-11-02 23:06 - 2017-11-01 14:57 - 000043472 _____ () C:\Program Files (x86)\Dropbox\Client\win32process.pyd
2017-11-02 23:06 - 2017-11-01 14:57 - 000026056 _____ () C:\Program Files (x86)\Dropbox\Client\win32job.pyd
2017-11-02 23:06 - 2017-11-01 14:57 - 000048592 _____ () C:\Program Files (x86)\Dropbox\Client\win32service.pyd
2017-11-02 23:06 - 2017-11-01 14:57 - 000057808 _____ () C:\Program Files (x86)\Dropbox\Client\win32evtlog.pyd
2017-11-02 23:06 - 2017-11-01 15:01 - 000021824 _____ () C:\Program Files (x86)\Dropbox\Client\cpuid.compiled._cpuid.pyd
2017-11-02 23:06 - 2017-11-01 15:01 - 000023368 _____ () C:\Program Files (x86)\Dropbox\Client\winshell.compiled._winshell.pyd
2017-11-02 23:06 - 2017-11-01 15:01 - 000022856 _____ () C:\Program Files (x86)\Dropbox\Client\crashpad.compiled._Crashpad.pyd
2017-11-02 23:06 - 2017-11-01 15:01 - 000066392 _____ () C:\Program Files (x86)\Dropbox\Client\winenumhandles.compiled._WinEnumHandles.pyd
2017-11-02 23:06 - 2017-11-01 15:01 - 001796920 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtCore.pyd
2017-11-02 23:06 - 2017-11-01 14:57 - 000084424 _____ () C:\Program Files (x86)\Dropbox\Client\sip.pyd
2017-11-02 23:06 - 2017-11-01 15:01 - 001956152 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtGui.pyd
2017-11-02 23:06 - 2017-11-01 15:01 - 003859264 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWidgets.pyd
2017-11-02 23:06 - 2017-11-01 15:01 - 000154440 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebEngineWidgets.pyd
2017-11-02 23:06 - 2017-11-01 15:01 - 000521024 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtNetwork.pyd
2017-11-02 23:06 - 2017-11-01 15:01 - 000050496 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebEngineCore.pyd
2017-11-02 23:06 - 2017-11-01 15:01 - 000042304 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebChannel.pyd
2017-11-02 23:06 - 2017-11-01 15:01 - 000131384 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebKit.pyd
2017-11-02 23:06 - 2017-11-01 15:01 - 000218944 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebKitWidgets.pyd
2017-11-02 23:06 - 2017-11-01 15:01 - 000204096 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtPrintSupport.pyd
2017-11-02 23:06 - 2017-11-01 15:01 - 000025432 _____ () C:\Program Files (x86)\Dropbox\Client\winscreenshot.compiled._CaptureScreenshot.pyd
2017-11-02 23:06 - 2017-11-01 14:57 - 000060880 _____ () C:\Program Files (x86)\Dropbox\Client\win32print.pyd
2017-11-02 23:06 - 2017-11-01 15:01 - 000054608 _____ () C:\Program Files (x86)\Dropbox\Client\winrpcserver.compiled._RPCServer.pyd
2017-11-02 23:06 - 2017-11-01 14:57 - 000024016 _____ () C:\Program Files (x86)\Dropbox\Client\win32profile.pyd
2017-11-02 23:06 - 2017-11-01 15:01 - 000022864 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.user32.compiled._winffi_user32.pyd
2017-11-02 23:06 - 2017-11-01 14:57 - 000028616 _____ () C:\Program Files (x86)\Dropbox\Client\win32ts.pyd
2017-11-02 23:06 - 2017-11-01 15:01 - 000022360 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.iphlpapi.compiled._winffi_iphlpapi.pyd
2017-11-02 23:06 - 2017-11-01 15:01 - 000021848 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.winerror.compiled._winffi_winerror.pyd
2017-11-02 23:06 - 2017-11-01 15:01 - 000022360 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.wininet.compiled._winffi_wininet.pyd
2017-11-02 23:06 - 2017-11-01 15:01 - 000027488 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox.infinite.win.compiled._driverinstallation.pyd
2017-11-02 23:06 - 2017-11-01 14:57 - 000349128 _____ () C:\Program Files (x86)\Dropbox\Client\winxpgui.pyd
2017-11-02 23:06 - 2017-11-01 15:01 - 000023896 _____ () C:\Program Files (x86)\Dropbox\Client\winverifysignature.compiled._VerifySignature.pyd
2017-11-02 23:06 - 2017-11-01 15:01 - 000025424 _____ () C:\Program Files (x86)\Dropbox\Client\librsyncffi.compiled._librsyncffi.pyd
2017-11-02 23:06 - 2017-11-01 14:58 - 000036296 _____ () C:\Program Files (x86)\Dropbox\Client\librsync.dll
2017-11-02 23:06 - 2017-11-01 15:01 - 000181056 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox_sqlite_ext.DLL
2017-11-02 23:06 - 2017-11-01 15:01 - 000030536 _____ () C:\Program Files (x86)\Dropbox\Client\wind3d11.compiled._wind3d11.pyd
2017-11-02 23:06 - 2017-11-01 15:01 - 000024368 _____ () C:\Program Files (x86)\Dropbox\Client\libEGL.DLL
2017-11-02 23:06 - 2017-11-01 15:01 - 001638200 _____ () C:\Program Files (x86)\Dropbox\Client\libGLESv2.dll
2017-11-02 23:06 - 2017-11-01 15:01 - 000026456 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.winhttp.compiled._winffi_winhttp.pyd
2017-11-02 23:06 - 2017-11-01 15:01 - 000545080 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtQuick.pyd
2017-11-02 23:06 - 2017-11-01 15:01 - 000359224 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtQml.pyd
2017-11-02 23:06 - 2017-11-01 15:01 - 000038208 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebEngine.pyd
2017-11-03 01:44 - 2017-11-03 01:44 - 067109376 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2017-11-03 01:43 - 2017-11-03 01:43 - 000234280 _____ () C:\Program Files\AVAST Software\Avast\gaming_mode_ui.dll
 
==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\Users\Personal\Desktop\Screenshot 2017-11-06 13.57.02.png:com.dropbox.attributes [168]

==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"

==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 05:34 - 2009-06-11 00:00 - 000000824 _____ C:\Windows\system32\Drivers\etc\hosts


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-3766277524-2784970969-2751085713-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Personal\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.10.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

MSCONFIG\startupreg: GrooveMonitor => "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
MSCONFIG\startupreg: Skype => "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
MSCONFIG\startupreg: UCam_Menu => "C:\Program Files (x86)\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\YouCam" update "Software\CyberLink\YouCam\2.0"

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [SPPSVC-In-TCP] => (Allow) %SystemRoot%\system32\sppsvc.exe
FirewallRules: [SPPSVC-In-TCP-NoScope] => (Allow) %SystemRoot%\system32\sppsvc.exe
FirewallRules: [{26EBFE29-4801-4D1D-B607-5CC7F729C9F8}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{16298A24-C654-4450-8AAE-E2B5EBB4CD29}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{B76D13BA-193F-4DFF-9503-6E0773E27E20}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{52811C57-8711-450F-96B4-D0CD644BF8B2}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{AD4272E3-C3D4-4455-8AF0-250445969411}] => (Allow) C:\Program Files\Vuze\Azureus.exe
FirewallRules: [{D074B2E7-8D2D-45E0-8350-2A89D78735B1}] => (Allow) C:\Program Files\Vuze\Azureus.exe
FirewallRules: [{A4E632F6-D4A8-4233-A787-276A6C03218D}] => (Allow) C:\Program Files\qBittorrent\qbittorrent.exe
FirewallRules: [{3C2B13ED-B55A-43C8-87BA-FE0A14A618D9}] => (Allow) C:\Program Files\qBittorrent\qbittorrent.exe
FirewallRules: [{DB039F57-CCB9-4949-8525-FBD8B46C430C}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe
FirewallRules: [{684304AF-A9F0-40AA-A7FC-ECB47CC50876}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe
FirewallRules: [{5811275A-9EAD-4699-A046-D0DF414A0A6E}] => (Allow) C:\Users\Personal\AppData\Local\Microsoft\OneDrive\OneDrive.exe
FirewallRules: [{EF62CDB2-3263-43BD-B804-8D16BB94A2B3}] => (Allow) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe] => Enabled:Spybot - Search & Destroy tray access
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe] => Enabled:Spybot-S&D 2 Scanner Service
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe] => Enabled:Spybot-S&D 2 Updater
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe] => Enabled:Spybot-S&D 2 Background update service

==================== Restore Points =========================

26-10-2017 16:59:44 Installed Skype™ 7.34
26-10-2017 17:00:53 Installed Microsoft Office Enterprise 2007
26-10-2017 17:07:59 Installed YouCam
26-10-2017 17:11:28 Windows Update
27-10-2017 16:24:47 Python 3.5.2 (32-bit)
27-10-2017 18:45:19 Installed HP Support Assistant
27-10-2017 18:46:56 Windows Modules Installer
27-10-2017 18:47:19 Windows Modules Installer
27-10-2017 19:47:40 Language Pack Removal
02-11-2017 13:32:47 Windows Update
02-11-2017 13:50:45 Removed Microsoft Office Enterprise 2007
02-11-2017 14:05:28 Device Driver Package Install: TAP Provider V9 for Private Tunnel Network adapters
02-11-2017 19:48:43 Windows Modules Installer

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (11/06/2017 04:49:56 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 4107) (User: )
Description: Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.
.

Error: (11/06/2017 04:49:56 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 4107) (User: )
Description: Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.
.

Error: (11/06/2017 04:49:56 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 4107) (User: )
Description: Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.
.

Error: (11/06/2017 04:49:56 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 4107) (User: )
Description: Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.
.

Error: (11/06/2017 04:49:56 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 4107) (User: )
Description: Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.
.

Error: (11/06/2017 04:49:56 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 4107) (User: )
Description: Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.
.

Error: (11/06/2017 04:49:07 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 4107) (User: )
Description: Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.
.

Error: (11/06/2017 04:49:07 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 4107) (User: )
Description: Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.
.

Error: (11/06/2017 04:49:07 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 4107) (User: )
Description: Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.
.

Error: (11/06/2017 04:48:52 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 4107) (User: )
Description: Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.
.


System errors:
=============
Error: (11/06/2017 02:12:12 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: Microsoft Antimalware has encountered an error trying to update signatures.

New Signature Version:

Previous Signature Version: 0.0.0.0

Update Source: Microsoft Malware Protection Center

Update Stage: Search

Source Path: http://go.microsoft.com/fwlink/?Lin...0.0&prod=EDB4FA23-53B8-4AFA-8C5D-99752CCA7094

Signature Type: Network Inspection System

Update Type: Full

User: NT AUTHORITY\NETWORK SERVICE

Current Engine Version:

Previous Engine Version: 0.0.0.0

Error code: 0x80072ee2

Error description: The operation timed out

Error: (11/06/2017 02:11:35 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: Microsoft Antimalware has encountered an error trying to update signatures.

New Signature Version:

Previous Signature Version: 1.253.1085.0

Update Source: Microsoft Malware Protection Center

Update Stage: Search

Source Path: http://go.microsoft.com/fwlink/?Lin...5.0&prod=EDB4FA23-53B8-4AFA-8C5D-99752CCA7094

Signature Type: AntiSpyware

Update Type: Full

User: NT AUTHORITY\NETWORK SERVICE

Current Engine Version:

Previous Engine Version: 1.1.14202.0

Error code: 0x80072ee2

Error description: The operation timed out

Error: (11/06/2017 02:11:35 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: Microsoft Antimalware has encountered an error trying to update signatures.

New Signature Version:

Previous Signature Version: 1.253.1085.0

Update Source: Microsoft Malware Protection Center

Update Stage: Search

Source Path: http://go.microsoft.com/fwlink/?Lin...5.0&prod=EDB4FA23-53B8-4AFA-8C5D-99752CCA7094

Signature Type: AntiVirus

Update Type: Full

User: NT AUTHORITY\NETWORK SERVICE

Current Engine Version:

Previous Engine Version: 1.1.14202.0

Error code: 0x80072ee2

Error description: The operation timed out

Error: (11/06/2017 02:10:55 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: Microsoft Antimalware has encountered an error trying to update signatures.

New Signature Version:

Previous Signature Version: 1.253.1085.0

Update Source: Microsoft Update Server

Update Stage: Search

Source Path: http://www.microsoft.com

Signature Type: AntiVirus

Update Type: Full

User: NT AUTHORITY\SYSTEM

Current Engine Version:

Previous Engine Version: 1.1.14202.0

Error code: 0x80072efe

Error description: The connection with the server was terminated abnormally

Error: (11/06/2017 01:44:00 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: Microsoft Antimalware has encountered an error trying to update signatures.

New Signature Version:

Previous Signature Version: 0.0.0.0

Update Source: Microsoft Malware Protection Center

Update Stage: Search

Source Path: http://go.microsoft.com/fwlink/?Lin...0.0&prod=EDB4FA23-53B8-4AFA-8C5D-99752CCA7094

Signature Type: Network Inspection System

Update Type: Full

User: HP\Personal

Current Engine Version:

Previous Engine Version: 0.0.0.0

Error code: 0x80072ee2

Error description: The operation timed out

Error: (11/06/2017 01:43:25 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: Microsoft Antimalware has encountered an error trying to update signatures.

New Signature Version:

Previous Signature Version: 1.253.1085.0

Update Source: Microsoft Malware Protection Center

Update Stage: Search

Source Path: http://go.microsoft.com/fwlink/?Lin...5.0&prod=EDB4FA23-53B8-4AFA-8C5D-99752CCA7094

Signature Type: AntiSpyware

Update Type: Full

User: HP\Personal

Current Engine Version:

Previous Engine Version: 1.1.14202.0

Error code: 0x80072ee2

Error description: The operation timed out

Error: (11/06/2017 01:43:25 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: Microsoft Antimalware has encountered an error trying to update signatures.

New Signature Version:

Previous Signature Version: 1.253.1085.0

Update Source: Microsoft Malware Protection Center

Update Stage: Search

Source Path: http://go.microsoft.com/fwlink/?Lin...5.0&prod=EDB4FA23-53B8-4AFA-8C5D-99752CCA7094

Signature Type: AntiVirus

Update Type: Full

User: HP\Personal

Current Engine Version:

Previous Engine Version: 1.1.14202.0

Error code: 0x80072ee2

Error description: The operation timed out

Error: (11/06/2017 01:42:48 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: Microsoft Antimalware has encountered an error trying to update signatures.

New Signature Version:

Previous Signature Version: 1.253.1085.0

Update Source: Microsoft Update Server

Update Stage: Search

Source Path: http://www.microsoft.com

Signature Type: AntiVirus

Update Type: Full

User: NT AUTHORITY\SYSTEM

Current Engine Version:

Previous Engine Version: 1.1.14202.0

Error code: 0x80072efe

Error description: The connection with the server was terminated abnormally

Error: (11/06/2017 12:24:37 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: Microsoft Antimalware has encountered an error trying to update signatures.

New Signature Version:

Previous Signature Version: 0.0.0.0

Update Source: Microsoft Malware Protection Center

Update Stage: Search

Source Path: http://go.microsoft.com/fwlink/?Lin...0.0&prod=EDB4FA23-53B8-4AFA-8C5D-99752CCA7094

Signature Type: Network Inspection System

Update Type: Full

User: NT AUTHORITY\NETWORK SERVICE

Current Engine Version:

Previous Engine Version: 0.0.0.0

Error code: 0x80072ee2

Error description: The operation timed out

Error: (11/06/2017 12:24:01 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: Microsoft Antimalware has encountered an error trying to update signatures.

New Signature Version:

Previous Signature Version: 1.253.1085.0

Update Source: Microsoft Malware Protection Center

Update Stage: Search

Source Path: http://go.microsoft.com/fwlink/?Lin...5.0&prod=EDB4FA23-53B8-4AFA-8C5D-99752CCA7094

Signature Type: AntiSpyware

Update Type: Full

User: NT AUTHORITY\NETWORK SERVICE

Current Engine Version:

Previous Engine Version: 1.1.14202.0

Error code: 0x80072ee2

Error description: The operation timed out


CodeIntegrity:
===================================
Date: 2017-11-06 16:56:51.859
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe because the set of per-page image hashes could not be found on the system.

Date: 2017-11-06 16:56:51.836
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe because the set of per-page image hashes could not be found on the system.

Date: 2017-11-06 16:56:51.792
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe because the set of per-page image hashes could not be found on the system.

Date: 2017-11-06 16:56:51.763
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe because the set of per-page image hashes could not be found on the system.

Date: 2017-11-06 15:00:54.898
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe because the set of per-page image hashes could not be found on the system.

Date: 2017-11-06 15:00:54.874
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe because the set of per-page image hashes could not be found on the system.

Date: 2017-11-06 15:00:54.840
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe because the set of per-page image hashes could not be found on the system.

Date: 2017-11-06 15:00:54.711
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe because the set of per-page image hashes could not be found on the system.

Date: 2017-11-06 12:41:29.496
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe because the set of per-page image hashes could not be found on the system.

Date: 2017-11-06 12:41:29.468
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe because the set of per-page image hashes could not be found on the system.


==================== Memory info ===========================

Processor: Intel(R) Core(TM) i7-2670QM CPU @ 2.20GHz
Percentage of memory in use: 72%
Total physical RAM: 6091.86 MB
Available physical RAM: 1695.44 MB
Total Virtual: 12181.9 MB
Available Virtual: 6907.02 MB

==================== Drives ================================

Drive c: (OS) (Fixed) (Total:292.87 GB) (Free:249.04 GB) NTFS
Drive d: (DATA) (Fixed) (Total:638.54 GB) (Free:638.4 GB) NTFS
Drive f: (My Passport-Bini) (Fixed) (Total:931.51 GB) (Free:143.81 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 3C7E929E)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=292.9 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=638.5 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (MBR Code: Windows XP) (Size: 931.5 GB) (Disk ID: 0002846E)
Partition 1: (Not Active) - (Size=931.5 GB) - (Type=07 NTFS)

==================== End of Addition.txt ============================
 
Welcome aboard

Please, observe following rules:
  • Read all of my instructions very carefully. Your mistakes during cleaning process may have very serious consequences, like unbootable computer.
  • If you're stuck, or you're not sure about certain step, always ask before doing anything else.
  • Please refrain from running any tools, fixes or applying any changes to your computer other than those I suggest.
  • Never run more than one scan at a time.
  • Keep updating me regarding your computer behavior, good, or bad.
  • The cleaning process, once started, has to be completed. Even if your computer appears to act better, it may still be infected. Once the computer is totally clean, I'll certainly let you know.
  • If you leave the topic without explanation in the middle of a cleaning process, you may not be eligible to receive any more help in malware removal forum.
  • I close my topics if you have not replied in 5 days. If you need more time, simply let me know. If I closed your topic and you need it to be reopened, simply PM me.

==============================================

You already have two AV programs installed:

AV: Avast Antivirus (Disabled - Up to date) {8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF}
AV: Microsoft Security Essentials (Enabled - Out of date) {3F839487-C7A2-C958-E30C-E2825BA31FB5}

so why are you trying to install third one.

If you prefer to use AVG instead you have to uninstall those two.
 
I only had Microsoft Security Essentials initially and it wouldn't update. Every attempt at downloading and installing an additional AV was in my view fought off. Although the Avast seems to run fine, I was just using the AVG or Bitdefender installation process to see if the same problem exists.
 
In that case uninstall Microsoft Security Essentials.

Then...

redtarget.gif
Download RogueKiller from one of the following links and save it to your Desktop:

Link 1
Link 2
  • Close all the running programs
  • Double click on downloaded setup.exe file to install the program.
  • Click on Start Scan button.
  • Click on another Start Scan button.
  • Wait until the Status box shows Scan Finished
  • Click on Remove Selected.
  • Wait until the Status box shows Deleting Finished.
  • Click on Report and copy/paste the content of the Notepad into your next reply.
  • RKreport.txt could also be found on your desktop.
  • If more than one log is produced post all logs.
redtarget.gif
Please download Malwarebytes to your desktop.
  • Double-click mb3-setup-consumer-{version}.exe and follow the prompts to install the program.
  • Then click Finish.
  • Once the program has fully updated, select Scan Now on the Dashboard. Or select the Threat Scan from the Scan menu.
  • If another update of the definitions is available, it will be implemented before the rest of the scanning procedure.
  • When the scan is complete, make sure that all Threats are selected, and click Remove Selected.
  • Restart your computer when prompted to do so.
  • The Scan log is available throughout History ->Application logs. Please post it contents in your next reply.
redtarget.gif
Please download AdwCleaner by Xplode and save to your Desktop.
  • Double click on AdwCleaner.exe to run the tool.
    Vista/Windows 7/8/10 users right-click and select Run As Administrator
  • The tool will start to update the database if one is required.
  • Click on the Scan button.
  • AdwCleaner will begin...be patient as the scan may take some time to complete.
  • After the scan has finished, click on the Logfile button.
  • A window will open which lists the logs of your scans.
  • Click on the Scan tab.
  • Double-click the most recent scan which will be at the top of the list....the log will appear.
  • Review the results...see note below
  • After reviewing the log, click on the Clean button.
  • Press OK when asked to close all programs and follow the onscreen prompts.
  • Press OK again to allow AdwCleaner to restart the computer and complete the removal process.
  • After rebooting, a logfile report (AdwCleaner[CX].txt) will open automatically (where the largest value of X represents the most recent report).
  • To open a Cleaning log, launch AdwareClearer, click on the Logfile button, click on the Cleaning tab and double-click the log at the top of the list.
  • Copy and paste the contents of AdwCleaner[CX].txt in your next reply.
  • A copy of all logfiles are saved to C:\AdwCleaner.
-- Note: The contents of the AdwCleaner log file may be confusing. Unless you see a program name or entry that you recognize and know should not be removed, don't worry about it. If you see an entry you want to keep, return to AdwCleaner before cleaning...all detected items will be listed (and checked) in each tab. Click on and uncheck any items you want to keep.
 
Hi Broni, thanks for your reply.

I already have Malwarebytes installed. Should it be uninstalled and reinstalled again?
 
RogueKiller V12.11.23.0 (x64) [Nov 6 2017] (Free) by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : https://forum.adlice.com
Website : http://www.adlice.com/download/roguekiller/
Blog : http://www.adlice.com

Operating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Started in : Normal mode
User : Personal [Administrator]
Started from : C:\Program Files\RogueKiller\RogueKiller64.exe
Mode : Delete -- Date : 11/08/2017 05:02:55 (Duration : 00:17:20)
Switches : -refid

¤¤¤ Processes : 0 ¤¤¤

¤¤¤ Registry : 8 ¤¤¤
[PUP.DriverPack] (X64) HKEY_LOCAL_MACHINE\Software\drpsu -> Not selected
[PUP.DriverPack] (X86) HKEY_LOCAL_MACHINE\Software\drpsu -> Not selected
[PUP.DriverPack] (X64) HKEY_USERS\S-1-5-21-3766277524-2784970969-2751085713-1000\Software\drpsu -> Not selected
[PUP.DriverPack] (X86) HKEY_USERS\S-1-5-21-3766277524-2784970969-2751085713-1000\Software\drpsu -> Not selected
[PUM.SearchPage] (X64) HKEY_USERS\S-1-5-21-3766277524-2784970969-2751085713-1000\Software\Microsoft\Internet Explorer\Main | Search Bar : Preserve -> Not selected
[PUM.SearchPage] (X86) HKEY_USERS\S-1-5-21-3766277524-2784970969-2751085713-1000\Software\Microsoft\Internet Explorer\Main | Search Bar : Preserve -> Not selected
[PUM.StartMenu] (X64) HKEY_USERS\S-1-5-21-3766277524-2784970969-2751085713-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyGames : 0 -> Not selected
[PUM.StartMenu] (X86) HKEY_USERS\S-1-5-21-3766277524-2784970969-2751085713-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyGames : 0 -> Not selected

¤¤¤ Tasks : 0 ¤¤¤

¤¤¤ Files : 3 ¤¤¤
[PUP.HackTool][Folder] C:\ProgramData\KMSAuto -> Deleted
[PUP.DriverPack][Folder] C:\Users\Personal\AppData\Roaming\DRPSu -> Deleted
[PUP.DriverPack][File] C:\Users\Personal\AppData\Roaming\DRPSu\diagnostics\soft -> Deleted
[PUP.DriverPack][Folder] C:\Users\Personal\AppData\Roaming\DRPSu\diagnostics -> Deleted
[PUP.DriverPack][Folder] C:\Users\Personal\AppData\Roaming\DRPSu\DRIVERS -> Deleted
[PUP.DriverPack][File] C:\Users\Personal\AppData\Roaming\DRPSu\dumpchk\dbgeng.dll -> Deleted
[PUP.DriverPack][File] C:\Users\Personal\AppData\Roaming\DRPSu\dumpchk\dbghelp.dll -> Deleted
[PUP.DriverPack][File] C:\Users\Personal\AppData\Roaming\DRPSu\dumpchk\dumpchk.exe -> Deleted
[PUP.DriverPack][File] C:\Users\Personal\AppData\Roaming\DRPSu\dumpchk\dumpchk.zip -> Deleted
[PUP.DriverPack][File] C:\Users\Personal\AppData\Roaming\DRPSu\dumpchk\triage\pooltag.txt -> Deleted
[PUP.DriverPack][File] C:\Users\Personal\AppData\Roaming\DRPSu\dumpchk\triage\triage.ini -> Deleted
[PUP.DriverPack][Folder] C:\Users\Personal\AppData\Roaming\DRPSu\dumpchk\triage -> Deleted
[PUP.DriverPack][File] C:\Users\Personal\AppData\Roaming\DRPSu\dumpchk\winext\ext.dll -> Deleted
[PUP.DriverPack][Folder] C:\Users\Personal\AppData\Roaming\DRPSu\dumpchk\winext -> Deleted
[PUP.DriverPack][Folder] C:\Users\Personal\AppData\Roaming\DRPSu\dumpchk -> Deleted
[PUP.DriverPack][Folder] C:\Users\Personal\AppData\Roaming\DRPSu\events -> Deleted
[PUP.DriverPack][File] C:\Users\Personal\AppData\Roaming\DRPSu\Internet\WifiInterface.txt -> Deleted
[PUP.DriverPack][Folder] C:\Users\Personal\AppData\Roaming\DRPSu\Internet -> Deleted
[PUP.DriverPack][File] C:\Users\Personal\AppData\Roaming\DRPSu\Logs\log___2017-10-26-16-18-33.html -> Deleted
[PUP.DriverPack][File] C:\Users\Personal\AppData\Roaming\DRPSu\Logs\log___2017-10-26-16-30-46.html -> Deleted
[PUP.DriverPack][File] C:\Users\Personal\AppData\Roaming\DRPSu\Logs\log___2017-10-26-16-39-33.html -> Deleted
[PUP.DriverPack][Folder] C:\Users\Personal\AppData\Roaming\DRPSu\Logs -> Deleted
[PUP.DriverPack][Folder] C:\Users\Personal\AppData\Roaming\DRPSu\PROGRAMS -> Deleted
[PUP.DriverPack][File] C:\Users\Personal\AppData\Roaming\DRPSu\snapshots\DriverPack_Snapshot_20171026_164042.zip -> Deleted
[PUP.DriverPack][Folder] C:\Users\Personal\AppData\Roaming\DRPSu\snapshots -> Deleted
[PUP.DriverPack][File] C:\Users\Personal\AppData\Roaming\DRPSu\temp\delorean_error_1837.log -> Deleted
[PUP.DriverPack][File] C:\Users\Personal\AppData\Roaming\DRPSu\temp\delorean_error_52873.log -> Deleted
[PUP.DriverPack][File] C:\Users\Personal\AppData\Roaming\DRPSu\temp\delorean_error_70057.log -> Deleted
[PUP.DriverPack][File] C:\Users\Personal\AppData\Roaming\DRPSu\temp\delorean_input_1837.log -> Deleted
[PUP.DriverPack][File] C:\Users\Personal\AppData\Roaming\DRPSu\temp\delorean_input_52873.log -> Deleted
[PUP.DriverPack][File] C:\Users\Personal\AppData\Roaming\DRPSu\temp\delorean_input_70057.log -> Deleted
[PUP.DriverPack][File] C:\Users\Personal\AppData\Roaming\DRPSu\temp\delorean_output_1837.log -> Deleted
[PUP.DriverPack][File] C:\Users\Personal\AppData\Roaming\DRPSu\temp\delorean_output_52873.log -> Deleted
[PUP.DriverPack][File] C:\Users\Personal\AppData\Roaming\DRPSu\temp\delorean_output_70057.log -> Deleted
[PUP.DriverPack][File] C:\Users\Personal\AppData\Roaming\DRPSu\temp\ps.j98imjb0.ailsg.ps1 -> Deleted
[PUP.DriverPack][File] C:\Users\Personal\AppData\Roaming\DRPSu\temp\ps.j98imjbw.53k26.cmd.txt -> Deleted
[PUP.DriverPack][File] C:\Users\Personal\AppData\Roaming\DRPSu\temp\ps.j98imjbw.53k26.stderr.log -> Deleted
[PUP.DriverPack][File] C:\Users\Personal\AppData\Roaming\DRPSu\temp\ps.j98imjbw.53k26.stdout.log -> Deleted
[PUP.DriverPack][File] C:\Users\Personal\AppData\Roaming\DRPSu\temp\unzipping_undefined.txt -> Deleted
[PUP.DriverPack][File] C:\Users\Personal\AppData\Roaming\DRPSu\temp\wget_finished_38565.txt -> Deleted
[PUP.DriverPack][File] C:\Users\Personal\AppData\Roaming\DRPSu\temp\wget_log_38565.log -> Deleted
[PUP.DriverPack][Folder] C:\Users\Personal\AppData\Roaming\DRPSu\temp -> Deleted
[PUP.HackTool][Folder] C:\ProgramData\KMSAuto -> ERROR [3]

¤¤¤ WMI : 0 ¤¤¤

¤¤¤ Hosts File : 0 ¤¤¤

¤¤¤ Antirootkit : 0 (Driver: Loaded) ¤¤¤

¤¤¤ Web browsers : 1 ¤¤¤
[PUM.HomePage][Chrome:Config] Default [SecurePrefs] : session.startup_urls [http://www.gmail.com/|http://www.bbc.co.uk/|http://www.sudantribune.com/] -> Not selected

¤¤¤ MBR Check : ¤¤¤
+++++ PhysicalDrive0: TOSHIBA HDWJ110 SCSI Disk Device +++++
--- User ---
[MBR] 5058d3554fe2b69cb3cb9cfa40749380
[BSP] eb6342f3132c34565c8a9f3717f80eb6 : Windows Vista/7/8|VT.Unknown MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 100 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 206848 | Size: 299899 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
2 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 614400000 | Size: 653868 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 ... OK
User = LL2 ... OK
 
Malwarebytes
www.malwarebytes.com

-Log Details-
Scan Date: 11/8/17
Scan Time: 5:42 AM
Log File: 7ab46801-c42e-11e7-b912-ac7289c252c1.json
Administrator: Yes

-Software Information-
Version: 3.2.2.2029
Components Version: 1.0.212
Update Package Version: 1.0.3202
License: Trial

-System Information-
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: HP\Personal

-Scan Summary-
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 313071
Threats Detected: 3
Threats Quarantined: 3
Time Elapsed: 3 min, 9 sec

-Scan Options-
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Detect
PUM: Detect

-Scan Details-
Process: 0
(No malicious items detected)

Module: 0
(No malicious items detected)

Registry Key: 0
(No malicious items detected)

Registry Value: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Data Stream: 0
(No malicious items detected)

Folder: 0
(No malicious items detected)

File: 3
PUP.Optional.ASK, C:\USERS\PERSONAL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\Web Data, Replaced, [527], [454827],1.0.3202
PUP.Optional.Conduit, C:\USERS\PERSONAL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\Web Data, Replaced, [579], [454832],1.0.3202
PUP.Optional.Conduit, C:\USERS\PERSONAL\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\Web Data, Replaced, [579], [454832],1.0.3202

Physical Sector: 0
(No malicious items detected)


(end)
 
Computer crashed after I finished running Malwarebytes for the first time after Rougekiller. I was looking for other options apart from "quarantine" as it happened. I had to run it again and have quarantined the treats.
 
# AdwCleaner 7.0.4.0 - Logfile created on Wed Nov 08 03:28:53 2017
# Updated on 2017/27/10 by Malwarebytes
# Running on Windows 7 Professional (X64)
# Mode: clean
# Support: https://www.malwarebytes.com/support

***** [ Services ] *****

No malicious services deleted.

***** [ Folders ] *****

No malicious folders deleted.

***** [ Files ] *****

No malicious files deleted.

***** [ DLL ] *****

No malicious DLLs cleaned.

***** [ WMI ] *****

No malicious WMI cleaned.

***** [ Shortcuts ] *****

No malicious shortcuts cleaned.

***** [ Tasks ] *****

No malicious tasks deleted.

***** [ Registry ] *****

Deleted: [Key] - HKLM\SOFTWARE\drpsu
Deleted: [Key] - HKU\S-1-5-21-3766277524-2784970969-2751085713-1000\Software\drpsu
Deleted: [Key] - HKCU\Software\drpsu


***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries deleted.

***** [ Chromium (and derivatives) ] *****

SearchProvider deleted: azlyrics.com - azlyrics.com
SearchProvider deleted: Ask Search - ask search
SearchProvider deleted: Ask - ask.com
SearchProvider deleted: Conduit Search - conduit.search


*************************

::Tracing keys deleted
::Winsock settings cleared
::Additional Actions: 0



*************************

C:/AdwCleaner/AdwCleaner[S0].txt - [1505 B] - [2017/11/8 3:4:58]


########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt ##########
 
# AdwCleaner 7.0.4.0 - Logfile created on Wed Nov 08 03:04:58 2017
# Updated on 2017/27/10 by Malwarebytes
# Database: 11-07-2017.2
# Running on Windows 7 Professional (X64)
# Mode: scan
# Support: https://www.malwarebytes.com/support

***** [ Services ] *****

No malicious services found.

***** [ Folders ] *****

No malicious folders found.

***** [ Files ] *****

No malicious files found.

***** [ DLL ] *****

No malicious DLLs found.

***** [ WMI ] *****

No malicious WMI found.

***** [ Shortcuts ] *****

No malicious shortcuts found.

***** [ Tasks ] *****

No malicious tasks found.

***** [ Registry ] *****

PUP.Optional.DriverPack, [Key] - HKLM\SOFTWARE\drpsu
PUP.Optional.DriverPack, [Key] - HKU\S-1-5-21-3766277524-2784970969-2751085713-1000\Software\drpsu
PUP.Optional.DriverPack, [Key] - HKCU\Software\drpsu


***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries.

***** [ Chromium (and derivatives) ] *****

PUP.Optional.Legacy, SearchProvider found: azlyrics.com - azlyrics.com
PUP.Optional.Legacy, SearchProvider found: Ask Search - ask search
PUP.Optional.Legacy, SearchProvider found: Ask - ask.com
PUP.Optional.Legacy, SearchProvider found: Conduit Search - conduit.search

/!\ Please Reset the Chrome Synchronization before cleaning the Chrome Preferences: https://support.google.com/chrome/answer/3097271


*************************



########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt ##########
 
Please download ComboFix from Here, Here or Here to your Desktop.

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
  • Never rename Combofix unless instructed.
  • Close any open browsers.
  • Very Important! Temporarily disable your anti-virus and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
  • Close any open browsers.
  • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
  • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
  • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
    If the connection is not there use restore point you created prior to running Combofix.
  • Double click on combofix.exe & follow the prompts.

  • NOTE1. If Combofix asks you to install Recovery Console, please allow it.
    NOTE 2. If Combofix asks you to update the program, always do so.
  • When finished, it will produce a report for you.
  • Please post the "C:\ComboFix.txt"
**Note 1: Do not mouseclick combofix's window while it's running. That may cause it to stall
**Note 2 for AVG and CA Internet Security (Total Defense Internet Security) users: ComboFix will not run until AVG/CA Internet Security is uninstalled as a protective measure against the anti-virus. This is because AVG/CA Internet Security "falsely" detects ComboFix (or its embedded files) as a threat and may remove them resulting in the tool not working correctly which in turn can cause "unpredictable results". Since AVG/CA Internet Security cannot be effectively disabled before running ComboFix, the author recommends you to uninstall AVG/CA Internet Security first.
Use AppRemover to uninstall it: https://www.techspot.com/downloads/5514-appremover.html
We can reinstall it when we're done with CF.
**Note 3: If you receive an error Illegal operation attempted on a registery key that has been marked for deletion, restart computer to fix the issue.
**Note 4: Some infections may take some significant time to be cured. As long as your computer clock is running Combofix is still working. Be patient.


Make sure, you re-enable your security programs, when you're done with Combofix.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

NOTE.
If, for some reason, Combofix refuses to run, try the following...

Delete Combofix file, download fresh one, but rename combofix.exe to your_name.exe BEFORE saving it to your desktop.
Do NOT run it yet.
Download Rkill (courtesy of BleepingComputer.com) to your desktop.
There are 2 different versions. If one of them won't run then download and try to run the other one.
You only need to get one of these to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.

rKill.exe: http://www.bleepingcomputer.com/download/rkill/dl/10/
iExplore.exe (renamed rKill.exe): http://www.bleepingcomputer.com/download/rkill/dl/11/

Restart computer in safe mode

  • Double-click on the Rkill desktop icon to run the tool.
  • If using Windows Vista, 7 or 8 right-click on it and choose Run As Administrator.
  • A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
  • If not, delete the file, then download and use the one provided in Link 2.
  • Do not reboot until instructed.
  • If the tool does not run from any of the links provided, please let me know.

When the scan is done Notepad will open with rKill.txt log.
NOTE. rKill.txt log will also be present on your desktop.

Once you've gotten one of them to run, immediately run your_name.exe by double clicking on it.

IF you had to run rKill post BOTH logs, rKill.txt and Combofix.txt.
 
ComboFix 17-10-17.01 - Personal 11/09/2017 10:52:38.1.8 - x64
Microsoft Windows 7 Professional 6.1.7601.1.1252.1.1033.18.6092.4352 [GMT 3:00]
Running from: c:\users\Personal\Desktop\ComboFix.exe
AV: Avast Antivirus *Disabled/Updated* {8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF}
AV: Malwarebytes *Disabled/Updated* {23007AD3-69FE-687C-2629-D584AFFAF72B}
SP: Avast Antivirus *Disabled/Updated* {35C973AA-9ABB-D3CA-B100-B0DC0E5F2402}
SP: Malwarebytes *Disabled/Updated* {98619B37-4FC4-67F2-1C99-EEF6D47DBD96}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\security\logs\scecomp.log
c:\windows\wininit.ini
.
.
((((((((((((((((((((((((( Files Created from 2017-10-09 to 2017-11-09 )))))))))))))))))))))))))))))))
.
.
2017-11-09 07:56 . 2017-11-09 07:56 -------- d-----w- c:\users\Default\AppData\Local\temp
2017-11-09 07:48 . 2017-11-09 07:48 -------- d-----w- c:\programdata\SWCUTemp
2017-11-08 03:01 . 2017-11-09 07:42 -------- d-----w- C:\AdwCleaner
2017-11-08 02:02 . 2017-11-08 02:02 28272 ----a-w- c:\windows\system32\drivers\TrueSight.sys
2017-11-08 02:01 . 2017-11-08 02:31 -------- d-----w- c:\programdata\RogueKiller
2017-11-08 02:00 . 2017-11-08 02:01 -------- d-----w- c:\program files\RogueKiller
2017-11-08 01:54 . 2017-11-08 01:54 30402 ----a-w- c:\programdata\agent.uninstall.1510106092.bdinstall.bin
2017-11-06 17:45 . 2017-11-06 17:45 48896 ----a-w- c:\programdata\agent.1509990317.bdinstall.bin
2017-11-06 09:40 . 2017-11-06 13:57 -------- d-----w- C:\FRST
2017-11-02 23:13 . 2017-11-02 23:13 -------- d-----w- c:\program files (x86)\Common Files\Skype
2017-11-02 23:12 . 2017-11-02 23:13 -------- d-----r- c:\program files (x86)\Skype
2017-11-02 23:01 . 2017-11-02 22:44 401488 ----a-w- c:\windows\system32\aswBoot.exe
2017-11-02 22:55 . 2017-11-02 22:55 -------- d-----w- c:\program files\Google
2017-11-02 22:44 . 2017-11-02 22:44 201352 ----a-w- c:\windows\system32\drivers\aswStm.sys
2017-11-02 22:44 . 2017-11-02 22:44 587168 ----a-w- c:\windows\system32\drivers\aswSP.sys
2017-11-02 22:44 . 2017-11-02 22:44 363440 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2017-11-02 22:44 . 2017-11-02 22:44 84416 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2017-11-02 22:44 . 2017-11-02 22:44 47008 ----a-w- c:\windows\system32\drivers\aswHwid.sys
2017-11-02 22:44 . 2017-11-02 22:44 147776 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2017-11-02 22:44 . 2017-11-02 23:02 1029872 ----a-w- c:\windows\system32\drivers\aswsnx.sys
2017-11-02 22:44 . 2017-11-02 22:44 110376 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2017-11-02 22:44 . 2017-11-02 22:43 57736 ----a-w- c:\windows\system32\drivers\aswbuniva.sys
2017-11-02 22:44 . 2017-11-02 22:43 343288 ----a-w- c:\windows\system32\drivers\aswbloga.sys
2017-11-02 22:44 . 2017-11-02 22:43 198976 ----a-w- c:\windows\system32\drivers\aswbidsha.sys
2017-11-02 22:44 . 2017-11-02 22:43 321032 ----a-w- c:\windows\system32\drivers\aswbidsdrivera.sys
2017-11-02 21:04 . 2017-11-02 21:04 -------- d-----w- c:\program files\Bitdefender Antivirus Free
2017-11-02 17:00 . 2013-10-14 15:00 28368 ----a-w- c:\windows\system32\IEUDINIT.EXE
2017-11-02 16:55 . 2017-11-02 16:55 950784 ----a-w- c:\program files\Internet Explorer\iedvtool.dll
2017-11-02 16:54 . 2017-11-02 16:54 878080 ----a-w- c:\windows\system32\advapi32.dll
2017-11-02 16:51 . 2017-11-02 16:51 9728 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2017-11-02 16:49 . 2017-11-02 16:49 1887232 ----a-w- c:\windows\system32\d3d11.dll
2017-11-02 16:49 . 2017-11-02 16:49 1505280 ----a-w- c:\windows\SysWow64\d3d11.dll
2017-11-02 14:33 . 2017-11-09 07:02 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2017-11-02 14:33 . 2017-11-09 07:06 -------- d-----w- c:\program files (x86)\Spybot - Search & Destroy 2
2017-11-02 14:05 . 2017-10-04 10:15 77440 ----a-w- c:\windows\system32\drivers\mbae64.sys
2017-11-02 14:05 . 2017-11-02 14:05 -------- d-----w- c:\programdata\Malwarebytes
2017-11-02 14:05 . 2017-11-02 14:05 -------- d-----w- c:\program files\Malwarebytes
2017-11-02 13:27 . 2017-11-02 13:27 -------- d--h--w- c:\programdata\Common Files
2017-11-02 13:27 . 2017-11-02 13:27 -------- d-----w- c:\programdata\Avg
2017-11-02 12:06 . 2017-11-02 12:06 -------- d-----w- c:\programdata\Bitdefender Agent
2017-11-02 11:24 . 2017-11-02 11:24 -------- d-----w- c:\program files\AVAST Software
2017-11-02 11:06 . 2017-11-06 09:09 -------- d-----w- c:\programdata\AVAST Software
2017-11-02 11:01 . 2014-08-08 16:31 27136 ----a-w- c:\windows\system32\drivers\ptun0901.sys
2017-11-02 10:32 . 2017-11-02 10:32 -------- d-----w- c:\program files (x86)\Microsoft OneDrive
2017-11-02 10:32 . 2017-11-02 10:32 -------- d-----w- c:\programdata\Microsoft OneDrive
2017-11-02 10:24 . 2017-11-02 10:24 859760 ------w- c:\programdata\Microsoft\ClickToRun\{9AC08E99-230B-47e8-9721-4577B7F124EA}\integrator.exe
2017-11-01 11:58 . 2017-11-01 11:58 51016 ----a-w- c:\windows\system32\DbxSvc.exe
2017-11-01 11:58 . 2017-11-01 11:58 45672 ----a-w- c:\windows\system32\drivers\dbx-dev.sys
2017-11-01 11:58 . 2017-11-01 11:58 45640 ----a-w- c:\windows\system32\drivers\dbx-stable.sys
2017-11-01 11:58 . 2017-11-01 11:58 45640 ----a-w- c:\windows\system32\drivers\dbx-canary.sys
2017-10-31 13:11 . 2017-11-02 20:07 -------- d-----w- c:\program files (x86)\Dropbox
2017-10-31 13:11 . 2017-10-31 13:11 -------- d-----w- c:\programdata\Dropbox
2017-10-27 15:46 . 2017-10-27 15:46 -------- d-----w- c:\programdata\HP Inc
2017-10-27 15:46 . 2017-10-27 15:46 -------- d-----w- C:\System.sav
2017-10-27 15:46 . 2017-10-28 09:43 -------- d-----w- c:\programdata\Hewlett-Packard
2017-10-27 15:45 . 2017-10-27 15:45 -------- d-----w- c:\program files (x86)\HP
2017-10-27 15:44 . 2017-10-27 15:46 -------- d-----w- c:\program files (x86)\Hewlett-Packard
2017-10-27 15:44 . 2017-10-27 15:44 -------- d-----w- C:\swsetup
2017-10-27 13:18 . 2017-10-27 13:18 -------- d-----w- c:\program files\qBittorrent
2017-10-27 12:40 . 2017-10-27 12:40 -------- d-----w- c:\programdata\Oracle
2017-10-27 12:24 . 2017-10-27 12:25 -------- d-----w- c:\program files (x86)\CrystalDiskInfo
2017-10-27 12:03 . 2017-11-02 22:55 -------- d-----w- c:\program files (x86)\Google
2017-10-27 11:54 . 2017-10-27 11:54 -------- d-----w- c:\programdata\Microsoft Toolkit
2017-10-26 23:40 . 2017-10-26 12:53 -------- d-----w- c:\windows\Panther
2017-10-26 23:40 . 2017-10-26 23:40 -------- d-----w- c:\windows\system32\OEM
2017-10-26 14:21 . 2017-10-26 14:21 -------- d-----w- c:\programdata\ATI
2017-10-26 14:19 . 2017-10-26 14:19 -------- d-----w- c:\program files\Common Files\Intel
2017-10-26 14:19 . 2017-10-26 14:19 -------- d-----w- c:\program files (x86)\Common Files\Intel
2017-10-26 14:17 . 2017-10-26 14:17 0 ----a-w- c:\windows\ativpsrm.bin
2017-10-26 14:15 . 2017-10-26 14:17 -------- d-----w- c:\program files (x86)\ATI Technologies
2017-10-26 14:15 . 2017-10-26 14:18 -------- d-----w- c:\program files\ATI Technologies
2017-10-26 14:14 . 2017-10-26 14:14 -------- d-----w- c:\program files\ATI
2017-10-26 14:11 . 2011-01-27 16:57 7470080 ----a-w- c:\windows\system32\igdumd64.dll
2017-10-26 14:09 . 2017-10-27 15:48 -------- d-----w- c:\program files (x86)\InstallShield Installation Information
2017-10-26 14:08 . 2017-10-26 14:09 -------- d-----w- c:\program files (x86)\CyberLink
2017-10-26 14:01 . 2017-11-02 10:55 -------- d-----w- c:\programdata\Microsoft Help
2017-10-26 14:00 . 2017-11-02 23:13 -------- d-----w- c:\programdata\Skype
2017-10-26 13:56 . 2017-10-27 13:26 -------- d-----w- c:\programdata\Package Cache
2017-10-26 13:55 . 2017-10-26 13:55 -------- d-----w- c:\program files (x86)\Mozilla Maintenance Service
2017-10-26 13:55 . 2017-10-26 13:55 -------- d-----w- c:\program files\Mozilla Firefox
2017-10-26 13:53 . 2017-10-26 13:53 -------- d-----w- c:\program files (x86)\Common Files\Ahead
2017-10-26 13:53 . 2017-10-26 13:53 -------- d-----w- c:\programdata\Nero
2017-10-26 13:53 . 2017-10-26 13:53 -------- d-----w- c:\program files (x86)\Nero
2017-10-26 13:46 . 2017-11-02 23:26 -------- d-----w- c:\program files (x86)\Microsoft.NET
2017-10-26 13:43 . 2017-10-26 13:43 -------- d-----w- c:\program files (x86)\Common Files\Adobe
2017-10-26 13:43 . 2017-10-26 13:43 -------- d-----w- c:\program files\VideoLAN
2017-10-26 13:42 . 2017-11-08 01:55 -------- d-sh--w- c:\windows\Installer
2017-10-26 13:35 . 2017-10-26 13:35 -------- d-----w- c:\program files\Common Files\ATI Technologies
2017-10-26 13:35 . 2017-10-26 13:35 -------- d-----w- c:\program files\AMD
2017-10-26 13:33 . 2015-10-09 18:20 237584 ----a-w- c:\windows\system32\amdgfxinfo64.dll
2017-10-26 13:33 . 2015-10-09 18:20 209936 ----a-w- c:\windows\SysWow64\amdgfxinfo32.dll
2017-10-26 13:33 . 2015-10-09 18:26 243728 ----a-w- c:\windows\system32\clinfo.exe
2017-10-26 13:32 . 2015-10-09 18:25 59920 ----a-w- c:\windows\system32\ATIODCLI.exe
2017-10-26 13:32 . 2015-10-09 18:25 341520 ----a-w- c:\windows\system32\ATIODE.exe
2017-10-26 13:32 . 2015-10-09 18:24 219160 ----a-w- c:\windows\system32\atieah64.exe
2017-10-26 13:32 . 2015-10-09 18:24 198168 ----a-w- c:\windows\SysWow64\atieah32.exe
2017-10-26 13:32 . 2015-10-09 18:21 1070632 ----a-w- c:\windows\system32\amdocl_ld64.exe
2017-10-26 13:32 . 2015-10-09 18:21 807464 ----a-w- c:\windows\SysWow64\amdocl_ld32.exe
2017-10-26 13:32 . 2015-10-09 18:21 1196072 ----a-w- c:\windows\system32\amdocl_as64.exe
2017-10-26 13:32 . 2015-10-09 18:21 1004072 ----a-w- c:\windows\SysWow64\amdocl_as32.exe
2017-10-26 13:24 . 2012-07-26 04:55 785512 ----a-w- c:\windows\system32\drivers\Wdf01000.sys
2017-10-26 13:24 . 2012-07-26 04:55 54376 ----a-w- c:\windows\system32\drivers\WdfLdr.sys
2017-10-26 13:24 . 2012-07-26 04:47 2560 ----a-w- c:\windows\system32\drivers\en-US\wdf01000.sys.mui
2017-10-26 13:24 . 2012-07-26 02:36 9728 ----a-w- c:\windows\system32\Wdfres.dll
2017-10-26 13:24 . 2017-10-26 13:24 -------- d-----w- c:\windows\SysWow64\sda
2017-10-26 13:24 . 2012-09-24 09:40 43840 ----a-w- c:\windows\system32\drivers\Accelerometer.sys
2017-10-26 13:24 . 2012-09-24 09:40 31040 ----a-w- c:\windows\system32\drivers\hpdskflt.sys
2017-10-26 13:23 . 2012-09-24 09:40 21312 ----a-w- c:\windows\system32\accelerometerdll.DLL
2017-10-26 13:23 . 2012-09-24 09:40 18240 ----a-w- c:\windows\system32\HPMDPCoInst12.dll
2017-10-26 13:23 . 2012-09-24 09:40 31040 ----a-w- c:\windows\system32\hpservice.exe
2017-10-26 13:23 . 2013-07-09 17:53 1002728 ----a-w- c:\windows\system32\WinUSBCoInstaller2.dll
2017-10-26 13:23 . 2012-08-03 03:51 1721576 ----a-w- c:\windows\system32\WdfCoInstaller01009.dll
2017-10-26 13:23 . 2015-05-04 07:06 11531536 ----a-w- c:\windows\system32\drivers\NETwsw00.sys
2017-10-26 13:23 . 2015-10-08 19:15 180480 ----a-w- c:\windows\system32\drivers\TeeDriverx64.sys
2017-10-26 13:22 . 2012-08-17 08:57 1795952 ----a-w- c:\windows\system32\WdfCoInstaller01011.dll
2017-10-26 13:22 . 2015-10-16 08:26 367320 ----a-w- c:\windows\system32\drivers\RtsPStor.sys
2017-10-26 13:22 . 2014-10-20 14:50 83160 ----a-w- c:\windows\system32\RtCRX64.dll
2017-10-26 13:22 . 2014-01-27 10:39 9890008 ----a-w- c:\windows\SysWow64\RsCRIcon.dll
2017-10-26 13:13 . 2012-08-27 15:39 226696 ----a-w- c:\windows\system32\drivers\nusb3xhc.sys
2017-10-26 13:13 . 2012-08-27 15:39 107912 ----a-w- c:\windows\system32\drivers\nusb3hub.sys
2017-10-26 13:13 . 2011-12-26 05:38 81920 ----a-w- c:\windows\system32\nusb3co3.dll
2017-10-26 13:13 . 2017-10-26 14:19 -------- d-----w- c:\program files (x86)\Intel
2017-10-26 13:13 . 2017-10-26 13:13 -------- d-----w- C:\Intel
2017-10-26 13:12 . 2015-06-04 19:20 116224 ----a-w- c:\windows\system32\igfxCoIn_v4229.dll
2017-10-26 13:12 . 2011-01-27 16:24 62464 ----a-w- c:\windows\system32\igfxsrvc.dll
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2017-11-02 16:54 . 2017-11-02 16:54 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2017-09-27 06:19 . 2017-10-27 15:48 23280 ----a-w- c:\windows\help\OEM\Scripts\checkMui.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ DropboxExt01]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2017-11-01 11:44 289096 ----a-w- c:\program files (x86)\Dropbox\Client\DropboxExt.19.0.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ DropboxExt02]
@="{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}]
2017-11-01 11:44 289096 ----a-w- c:\program files (x86)\Dropbox\Client\DropboxExt.19.0.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ DropboxExt03]
@="{FB314EE1-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EE1-A251-47B7-93E1-CDD82E34AF8B}]
2017-11-01 11:44 289096 ----a-w- c:\program files (x86)\Dropbox\Client\DropboxExt.19.0.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ DropboxExt04]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2017-11-01 11:44 289096 ----a-w- c:\program files (x86)\Dropbox\Client\DropboxExt.19.0.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ DropboxExt05]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2017-11-01 11:44 289096 ----a-w- c:\program files (x86)\Dropbox\Client\DropboxExt.19.0.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ DropboxExt06]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2017-11-01 11:44 289096 ----a-w- c:\program files (x86)\Dropbox\Client\DropboxExt.19.0.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ DropboxExt07]
@="{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}]
2017-11-01 11:44 289096 ----a-w- c:\program files (x86)\Dropbox\Client\DropboxExt.19.0.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ DropboxExt08]
@="{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}]
2017-11-01 11:44 289096 ----a-w- c:\program files (x86)\Dropbox\Client\DropboxExt.19.0.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ DropboxExt09]
@="{FB314EE2-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EE2-A251-47B7-93E1-CDD82E34AF8B}]
2017-11-01 11:44 289096 ----a-w- c:\program files (x86)\Dropbox\Client\DropboxExt.19.0.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ DropboxExt10]
@="{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}]
2017-11-01 11:44 289096 ----a-w- c:\program files (x86)\Dropbox\Client\DropboxExt.19.0.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ OneDrive1]
@="{BBACC218-34EA-4666-9D7A-C78F2274A524}"
[HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}]
2017-11-02 10:32 329376 ----a-w- c:\users\Personal\AppData\Local\Microsoft\OneDrive\17.3.4604.0120\FileSyncShell.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ OneDrive2]
@="{5AB7172C-9C11-405C-8DD5-AF20F3606282}"
[HKEY_CLASSES_ROOT\CLSID\{5AB7172C-9C11-405C-8DD5-AF20F3606282}]
2017-11-02 10:32 329376 ----a-w- c:\users\Personal\AppData\Local\Microsoft\OneDrive\17.3.4604.0120\FileSyncShell.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ OneDrive3]
@="{A78ED123-AB77-406B-9962-2A5D9D2F7F30}"
[HKEY_CLASSES_ROOT\CLSID\{A78ED123-AB77-406B-9962-2A5D9D2F7F30}]
2017-11-02 10:32 329376 ----a-w- c:\users\Personal\AppData\Local\Microsoft\OneDrive\17.3.4604.0120\FileSyncShell.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ OneDrive4]
@="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}"
[HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}]
2017-11-02 10:32 329376 ----a-w- c:\users\Personal\AppData\Local\Microsoft\OneDrive\17.3.4604.0120\FileSyncShell.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ OneDrive5]
@="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}"
[HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}]
2017-11-02 10:32 329376 ----a-w- c:\users\Personal\AppData\Local\Microsoft\OneDrive\17.3.4604.0120\FileSyncShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-03-12 153136]
"Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2017-08-25 27832272]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2011-03-15 336384]
"Dropbox"="c:\program files (x86)\Dropbox\Client\Dropbox.exe" [2017-11-01 3567928]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0\0sdnclean64.exe
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService]
@="Service"
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 dbupdate;Dropbox Update Service (dbupdate);c:\program files (x86)\Dropbox\Update\DropboxUpdate.exe;c:\program files (x86)\Dropbox\Update\DropboxUpdate.exe [x]
R2 MBAMService;Malwarebytes Service;c:\program files\Malwarebytes\Anti-Malware\mbamservice.exe;c:\program files\Malwarebytes\Anti-Malware\mbamservice.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 amdhub30;AMD USB 3.0 Hub Driver;c:\windows\system32\drivers\amdhub30.sys;c:\windows\SYSNATIVE\drivers\amdhub30.sys [x]
R3 amdxhc;AMD USB 3.0 Host Controller Driver;c:\windows\system32\drivers\amdxhc.sys;c:\windows\SYSNATIVE\drivers\amdxhc.sys [x]
R3 aswbIDSAgent;aswbIDSAgent;c:\program files\AVAST Software\Avast\x64\aswidsagenta.exe;c:\program files\AVAST Software\Avast\x64\aswidsagenta.exe [x]
R3 aswHwid;aswHwid;c:\windows\system32\drivers\aswHwid.sys;c:\windows\SYSNATIVE\drivers\aswHwid.sys [x]
R3 dbupdatem;Dropbox Update Service (dbupdatem);c:\program files (x86)\Dropbox\Update\DropboxUpdate.exe;c:\program files (x86)\Dropbox\Update\DropboxUpdate.exe [x]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x]
R3 hpqcaslwmiex;HP CASL Framework Service;c:\program files (x86)\HP\Shared\hpqwmiex.exe;c:\program files (x86)\HP\Shared\hpqwmiex.exe [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 ptun0901;TAP Adapter V9 for Private Tunnel;c:\windows\system32\DRIVERS\ptun0901.sys;c:\windows\SYSNATIVE\DRIVERS\ptun0901.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
S0 aswbidsh;aswbidsh;c:\windows\\SystemRoot\system32\drivers\aswbidsha.sys;c:\windows\\SystemRoot\system32\drivers\aswbidsha.sys [x]
S0 aswblog;aswblog;c:\windows\\SystemRoot\system32\drivers\aswbloga.sys;c:\windows\\SystemRoot\system32\drivers\aswbloga.sys [x]
S0 aswbuniv;aswbuniv;c:\windows\\SystemRoot\system32\drivers\aswbuniva.sys;c:\windows\\SystemRoot\system32\drivers\aswbuniva.sys [x]
S0 aswRvrt;aswRvrt;c:\windows\\SystemRoot\system32\drivers\aswRvrt.sys;c:\windows\\SystemRoot\system32\drivers\aswRvrt.sys [x]
S0 aswVmm;aswVmm;c:\windows\\SystemRoot\system32\drivers\aswVmm.sys;c:\windows\\SystemRoot\system32\drivers\aswVmm.sys [x]
S0 iaStorA;iaStorA;c:\windows\system32\DRIVERS\iaStorA.sys;c:\windows\SYSNATIVE\DRIVERS\iaStorA.sys [x]
S0 iaStorF;iaStorF;c:\windows\system32\DRIVERS\iaStorF.sys;c:\windows\SYSNATIVE\DRIVERS\iaStorF.sys [x]
S1 aswbidsdriver;aswbidsdriver;c:\windows\system32\drivers\aswbidsdrivera.sys;c:\windows\SYSNATIVE\drivers\aswbidsdrivera.sys [x]
S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys;c:\windows\SYSNATIVE\drivers\aswSnx.sys [x]
S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys;c:\windows\SYSNATIVE\drivers\aswSP.sys [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x]
S2 aswStm;aswStm;c:\windows\system32\drivers\aswStm.sys;c:\windows\SYSNATIVE\drivers\aswStm.sys [x]
S2 DbxSvc;DbxSvc;c:\windows\system32\DbxSvc.exe;c:\windows\SYSNATIVE\DbxSvc.exe [x]
S2 hpsrv;HP Service;c:\windows\system32\Hpservice.exe;c:\windows\SYSNATIVE\Hpservice.exe [x]
S2 HPSupportSolutionsFrameworkService;HP Support Solutions Framework Service;c:\program files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe;c:\program files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [x]
S3 int0800;Intel 28F320C3 Flash Update Device Driver v6.4;c:\windows\system32\DRIVERS\flashud.sys;c:\windows\SYSNATIVE\DRIVERS\flashud.sys [x]
S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x]
S3 intelkmd;intelkmd;c:\windows\system32\DRIVERS\igdpmd64.sys;c:\windows\SYSNATIVE\DRIVERS\igdpmd64.sys [x]
S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\nusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\nusb3hub.sys [x]
S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\nusb3xhc.sys;c:\windows\SYSNATIVE\DRIVERS\nusb3xhc.sys [x]
S3 RSPCIESTOR;Realtek PCIE CardReader Driver;c:\windows\system32\DRIVERS\RtsPStor.sys;c:\windows\SYSNATIVE\DRIVERS\RtsPStor.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\drivers\usbfilter.sys;c:\windows\SYSNATIVE\drivers\usbfilter.sys [x]
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - ESPROTECTIONDRIVER
*NewlyCreated* - MBAMFARFLT
*NewlyCreated* - MBAMPROTECTION
*NewlyCreated* - MBAMSWISSARMY
*Deregistered* - ESProtectionDriver
*Deregistered* - MBAMFarflt
*Deregistered* - MBAMProtection
*Deregistered* - MBAMSwissArmy
.
Contents of the 'Scheduled Tasks' folder
.
2017-11-09 c:\windows\Tasks\DropboxUpdateTaskMachineCore.job
- c:\program files (x86)\Dropbox\Update\DropboxUpdate.exe [2017-10-31 13:11]
.
2017-11-09 c:\windows\Tasks\DropboxUpdateTaskMachineUA.job
- c:\program files (x86)\Dropbox\Update\DropboxUpdate.exe [2017-10-31 13:11]
.
2017-11-06 c:\windows\Tasks\HPCeeScheduleForPersonal.job
- c:\program files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2016-06-24 15:09]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ DropboxExt01]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2017-11-01 11:44 337224 ----a-w- c:\program files (x86)\Dropbox\Client\DropboxExt64.19.0.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ DropboxExt02]
@="{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}]
2017-11-01 11:44 337224 ----a-w- c:\program files (x86)\Dropbox\Client\DropboxExt64.19.0.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ DropboxExt03]
@="{FB314EE1-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EE1-A251-47B7-93E1-CDD82E34AF8B}]
2017-11-01 11:44 337224 ----a-w- c:\program files (x86)\Dropbox\Client\DropboxExt64.19.0.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ DropboxExt04]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2017-11-01 11:44 337224 ----a-w- c:\program files (x86)\Dropbox\Client\DropboxExt64.19.0.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ DropboxExt05]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2017-11-01 11:44 337224 ----a-w- c:\program files (x86)\Dropbox\Client\DropboxExt64.19.0.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ DropboxExt06]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2017-11-01 11:44 337224 ----a-w- c:\program files (x86)\Dropbox\Client\DropboxExt64.19.0.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ DropboxExt07]
@="{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}]
2017-11-01 11:44 337224 ----a-w- c:\program files (x86)\Dropbox\Client\DropboxExt64.19.0.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ DropboxExt08]
@="{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}]
2017-11-01 11:44 337224 ----a-w- c:\program files (x86)\Dropbox\Client\DropboxExt64.19.0.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ DropboxExt09]
@="{FB314EE2-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EE2-A251-47B7-93E1-CDD82E34AF8B}]
2017-11-01 11:44 337224 ----a-w- c:\program files (x86)\Dropbox\Client\DropboxExt64.19.0.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ DropboxExt10]
@="{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}]
2017-11-01 11:44 337224 ----a-w- c:\program files (x86)\Dropbox\Client\DropboxExt64.19.0.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ OneDrive1]
@="{BBACC218-34EA-4666-9D7A-C78F2274A524}"
[HKEY_CLASSES_ROOT\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}]
2017-11-02 10:32 358064 ----a-w- c:\users\Personal\AppData\Local\Microsoft\OneDrive\17.3.4604.0120\amd64\FileSyncShell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ OneDrive2]
@="{5AB7172C-9C11-405C-8DD5-AF20F3606282}"
[HKEY_CLASSES_ROOT\CLSID\{5AB7172C-9C11-405C-8DD5-AF20F3606282}]
2017-11-02 10:32 358064 ----a-w- c:\users\Personal\AppData\Local\Microsoft\OneDrive\17.3.4604.0120\amd64\FileSyncShell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ OneDrive3]
@="{A78ED123-AB77-406B-9962-2A5D9D2F7F30}"
[HKEY_CLASSES_ROOT\CLSID\{A78ED123-AB77-406B-9962-2A5D9D2F7F30}]
2017-11-02 10:32 358064 ----a-w- c:\users\Personal\AppData\Local\Microsoft\OneDrive\17.3.4604.0120\amd64\FileSyncShell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ OneDrive4]
@="{F241C880-6982-4CE5-8CF7-7085BA96DA5A}"
[HKEY_CLASSES_ROOT\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}]
2017-11-02 10:32 358064 ----a-w- c:\users\Personal\AppData\Local\Microsoft\OneDrive\17.3.4604.0120\amd64\FileSyncShell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ OneDrive5]
@="{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}"
[HKEY_CLASSES_ROOT\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}]
2017-11-02 10:32 358064 ----a-w- c:\users\Personal\AppData\Local\Microsoft\OneDrive\17.3.4604.0120\amd64\FileSyncShell64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00asw]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2017-11-02 22:44 1789648 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-01-27 167960]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-01-27 391704]
"Persistence"="c:\windows\system32\igfxpers.exe" [2011-01-27 418328]
"AvastUI.exe"="c:\program files\AVAST Software\Avast\AvLaunch.exe" [2017-11-02 253344]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
TCP: DhcpNameServer = 192.168.10.1
FF - ProfilePath - c:\users\Personal\AppData\Roaming\Mozilla\Firefox\Profiles\9qofch10.default\
.
- - - - ORPHANS REMOVED - - - -
.
AddRemove-{4AAC4B07-77EF-4BCF-88DC-D24E4DE683E8} - c:\program files (x86)\InstallShield Installation Information\{4AAC4B07-77EF-4BCF-88DC-D24E4DE683E8}\setup.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2017-11-09 10:58:13
ComboFix-quarantined-files.txt 2017-11-09 07:58
.
Pre-Run: 270,978,846,720 bytes free
Post-Run: 270,564,102,144 bytes free
.
- - End Of File - - 52B8743F3E12C8EDBAAC6A8FDF40A59D
A36C5E4F47E84449FF07ED3517B43A31
 
Re-run Farbar Recovery Scan Tool (FRST/FRST64) you ran at the very beginning of this topic.

  • Double click to run it.
  • Make sure you checkmark Addition.txt box.
  • Press Scan button.
  • Scan will create two logs, FRST.txt and Addition.txt in the same directory the tool is run. Please copy and paste them to your reply.
 
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 02-11-2017
Ran by Personal (administrator) on HP (10-11-2017 05:22:15)
Running from C:\Users\Personal\Desktop
Loaded Profiles: Personal (Available Profiles: Personal)
Platform: Windows 7 Professional Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AMD) C:\Windows\System32\atiesrxx.exe
(Hewlett-Packard Company) C:\Windows\System32\hpservice.exe
(AMD) C:\Windows\System32\atieclxx.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Dropbox, Inc.) C:\Windows\System32\DbxSvc.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler64.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Nero AG) C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Nero AG) C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe
(Nero AG) C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
(Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
(Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(HP Inc.) C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(AVAST Software s.r.o.) C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe
(Microsoft Corporation) C:\Windows\System32\dinotify.exe
(Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [253344 2017-11-03] (AVAST Software)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [336384 2011-03-15] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [3567928 2017-11-01] (Dropbox, Inc.)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-21-3766277524-2784970969-2751085713-1000\...\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] => C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe [153136 2007-03-12] (Nero AG)
HKU\S-1-5-21-3766277524-2784970969-2751085713-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [27832272 2017-08-25] (Skype Technologies S.A.)
BootExecute: autocheck autochk * sdnclean64.exe

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.10.1
Tcpip\..\Interfaces\{6B8B91B0-9F9B-4CA8-AE14-69358B1D80FF}: [DhcpNameServer] 192.168.0.254
Tcpip\..\Interfaces\{FFE957F8-0C5C-40E2-982E-59417CB3D7AA}: [DhcpNameServer] 192.168.10.1

Internet Explorer:
==================
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-3766277524-2784970969-2751085713-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2017-11-03] (AVAST Software)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2017-11-03] (Google Inc.)
BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [2017-09-27] (HP Inc.)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2017-11-03] (AVAST Software)
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2017-11-03] (Google Inc.)
BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2017-09-27] (HP Inc.)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2017-11-03] (Google Inc.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2017-11-03] (Google Inc.)

FireFox:
========
FF DefaultProfile: 9qofch10.default
FF ProfilePath: C:\Users\Personal\AppData\Roaming\Mozilla\Firefox\Profiles\9qofch10.default [2017-11-09]
FF Extension: (Avast SafePrice) - C:\Users\Personal\AppData\Roaming\Mozilla\Firefox\Profiles\9qofch10.default\Extensions\sp@avast.com.xpi [2017-11-03]
FF Extension: (Avast Online Security) - C:\Users\Personal\AppData\Roaming\Mozilla\Firefox\Profiles\9qofch10.default\Extensions\wrc@avast.com.xpi [2017-11-06]
FF Plugin: @videolan.org/vlc,version=2.2.6 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-10-27] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-10-27] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-06-30] (Adobe Systems Inc.)

Chrome:
=======
CHR HomePage: Default -> hxxp://www.google.com/
CHR StartupUrls: Default -> "hxxp://www.gmail.com/","hxxp://www.bbc.co.uk/","hxxp://www.sudantribune.com/"
CHR Profile: C:\Users\Personal\AppData\Local\Google\Chrome\User Data\Default [2017-11-10]
CHR Extension: (Slides) - C:\Users\Personal\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-10-27]
CHR Extension: (TheFreeDictionary.com Extension) - C:\Users\Personal\AppData\Local\Google\Chrome\User Data\Default\Extensions\afgabimphpgkjochcoogplolgpcagmap [2017-10-27]
CHR Extension: (Docs) - C:\Users\Personal\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-27]
CHR Extension: (Google Drive) - C:\Users\Personal\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-10-27]
CHR Extension: (YouTube) - C:\Users\Personal\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-10-27]
CHR Extension: (Adblock Plus) - C:\Users\Personal\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2017-10-27]
CHR Extension: (Avast SafePrice) - C:\Users\Personal\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck [2017-11-06]
CHR Extension: (Sheets) - C:\Users\Personal\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-10-27]
CHR Extension: (Google Docs Offline) - C:\Users\Personal\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-10-27]
CHR Extension: (AdBlock) - C:\Users\Personal\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2017-11-09]
CHR Extension: (Google Calendar (by Google)) - C:\Users\Personal\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmbgaklkmjakoegficnlkhebmhkjfich [2017-10-27]
CHR Extension: (Avast Online Security) - C:\Users\Personal\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2017-11-06]
CHR Extension: (Kindle Cloud Reader) - C:\Users\Personal\AppData\Local\Google\Chrome\User Data\Default\Extensions\icdipabjmbhpdkjaihfjoikhjjeneebd [2017-10-27]
CHR Extension: (Google Keep Chrome Extension) - C:\Users\Personal\AppData\Local\Google\Chrome\User Data\Default\Extensions\lpcaedmchfhocbbapmcbpinfpgnhiddi [2017-10-27]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Personal\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-10-27]
CHR Extension: (Gmail) - C:\Users\Personal\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-10-27]
CHR Extension: (Chrome Media Router) - C:\Users\Personal\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-10-27]
CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - hxxps://clients2.google.com/service/update2/crx

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [7446024 2017-11-03] (AVAST Software s.r.o.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [281416 2017-11-03] (AVAST Software)
S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2017-10-31] (Dropbox, Inc.)
S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2017-10-31] (Dropbox, Inc.)
R2 DbxSvc; C:\Windows\system32\DbxSvc.exe [51016 2017-11-01] (Dropbox, Inc.)
S3 hpqcaslwmiex; C:\Program Files (x86)\HP\Shared\hpqwmiex.exe [1031704 2016-06-03] (HP)
R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [323952 2017-09-27] (HP Inc.)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6058960 2017-08-07] (Malwarebytes)
R3 NMIndexingService; C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe [271920 2007-03-12] (Nero AG)
S2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-14] (Microsoft Corporation)

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R1 aswbidsdriver; C:\Windows\system32\drivers\aswbidsdrivera.sys [321032 2017-11-03] (AVAST Software s.r.o.)
R0 aswbidsh; C:\Windows\system32\drivers\aswbidsha.sys [198976 2017-11-03] (AVAST Software s.r.o.)
R0 aswblog; C:\Windows\system32\drivers\aswbloga.sys [343288 2017-11-03] (AVAST Software s.r.o.)
R0 aswbuniv; C:\Windows\system32\drivers\aswbuniva.sys [57736 2017-11-03] (AVAST Software s.r.o.)
S3 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [47008 2017-11-03] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [147776 2017-11-03] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [110376 2017-11-03] (AVAST Software)
R0 aswRvrt; C:\Windows\system32\drivers\aswRvrt.sys [84416 2017-11-03] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1029872 2017-11-03] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [587168 2017-11-03] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [201352 2017-11-03] (AVAST Software)
R0 aswVmm; C:\Windows\system32\drivers\aswVmm.sys [363440 2017-11-03] (AVAST Software)
R1 ESProtectionDriver; C:\Windows\system32\drivers\mbae64.sys [77440 2017-10-04] ()
R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [30960 2015-05-29] (Intel Corporation)
R3 int0800; C:\Windows\System32\DRIVERS\flashud.sys [51712 2009-09-09] (Intel Corporation)
R2 MBAMChameleon; C:\Windows\System32\Drivers\MbamChameleon.sys [192952 2017-11-09] (Malwarebytes)
R3 MBAMFarflt; C:\Windows\System32\DRIVERS\farflt.sys [110016 2017-11-09] (Malwarebytes)
R3 MBAMProtection; C:\Windows\System32\DRIVERS\mbam.sys [45504 2017-11-09] (Malwarebytes)
R3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [252232 2017-11-09] (Malwarebytes)
R3 MBAMWebProtection; C:\Windows\System32\DRIVERS\mwac.sys [84256 2017-11-10] (Malwarebytes)
R3 MEIx64; C:\Windows\System32\DRIVERS\TeeDriverx64.sys [180480 2015-10-08] (Intel Corporation)
S3 ptun0901; C:\Windows\System32\DRIVERS\ptun0901.sys [27136 2014-08-08] (The OpenVPN Project)
U1 aswbdisk; no ImagePath
U3 catchme; \??\C:\ComboFix\catchme.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-11-09 11:15 - 2017-11-10 05:21 - 000084256 _____ (Malwarebytes) C:\Windows\system32\Drivers\mwac.sys
2017-11-09 11:15 - 2017-11-09 11:15 - 000110016 _____ (Malwarebytes) C:\Windows\system32\Drivers\farflt.sys
2017-11-09 11:12 - 2017-11-09 11:12 - 000252232 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamswissarmy.sys
2017-11-09 11:12 - 2017-11-09 11:12 - 000192952 _____ (Malwarebytes) C:\Windows\system32\Drivers\MbamChameleon.sys
2017-11-09 11:12 - 2017-11-09 11:12 - 000045504 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2017-11-09 10:58 - 2017-11-09 10:58 - 000031413 _____ C:\ComboFix.txt
2017-11-09 10:51 - 2011-06-26 09:45 - 000256000 _____ C:\Windows\PEV.exe
2017-11-09 10:51 - 2010-11-07 20:20 - 000208896 _____ C:\Windows\MBR.exe
2017-11-09 10:51 - 2009-04-20 07:56 - 000060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2017-11-09 10:51 - 2000-08-31 03:00 - 000518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2017-11-09 10:51 - 2000-08-31 03:00 - 000406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2017-11-09 10:51 - 2000-08-31 03:00 - 000098816 _____ C:\Windows\sed.exe
2017-11-09 10:51 - 2000-08-31 03:00 - 000080412 _____ C:\Windows\grep.exe
2017-11-09 10:51 - 2000-08-31 03:00 - 000068096 _____ C:\Windows\zip.exe
2017-11-09 10:50 - 2017-11-09 10:58 - 000000000 ____D C:\Qoobox
2017-11-09 10:50 - 2017-11-09 10:57 - 000000000 ____D C:\Windows\erdnt
2017-11-09 10:48 - 2017-11-09 10:48 - 000000000 ____D C:\ProgramData\SWCUTemp
2017-11-09 08:54 - 2017-11-09 08:54 - 005660403 ____R (Swearware) C:\Users\Personal\Desktop\ComboFix.exe
2017-11-08 06:01 - 2017-11-09 10:42 - 000000000 ____D C:\AdwCleaner
2017-11-08 06:00 - 2017-11-08 06:00 - 008261584 _____ (Malwarebytes) C:\Users\Personal\Desktop\AdwCleaner.exe
2017-11-08 05:40 - 2017-11-08 05:40 - 000262144 _____ C:\Windows\Minidump\110817-18236-01.dmp
2017-11-08 05:38 - 2017-11-08 05:49 - 000000000 ___SD C:\Users\Personal\AppData\LocalLow\Temp
2017-11-08 05:02 - 2017-11-08 05:02 - 000028272 _____ C:\Windows\system32\Drivers\TrueSight.sys
2017-11-08 05:01 - 2017-11-08 05:31 - 000000000 ____D C:\ProgramData\RogueKiller
2017-11-08 05:01 - 2017-11-08 05:01 - 000000860 _____ C:\Users\Public\Desktop\RogueKiller.lnk
2017-11-08 05:00 - 2017-11-08 05:01 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RogueKiller
2017-11-08 05:00 - 2017-11-08 05:01 - 000000000 ____D C:\Program Files\RogueKiller
2017-11-08 04:54 - 2017-11-08 04:54 - 000030402 _____ C:\ProgramData\agent.uninstall.1510106092.bdinstall.bin
2017-11-08 04:53 - 2017-11-08 04:54 - 036135784 _____ (Adlice Software ) C:\Users\Personal\Desktop\RogueKiller_setup_ref3.exe
2017-11-06 20:55 - 2017-11-06 20:55 - 009932672 _____ C:\Users\Personal\Downloads\bitdefender_online(1).exe
2017-11-06 20:45 - 2017-11-06 20:45 - 000048896 _____ C:\ProgramData\agent.1509990317.bdinstall.bin
2017-11-06 16:57 - 2017-11-06 16:57 - 000051601 _____ C:\Users\Personal\Desktop\Addition.txt
2017-11-06 16:56 - 2017-11-10 05:23 - 000015099 _____ C:\Users\Personal\Desktop\FRST.txt
2017-11-06 12:40 - 2017-11-10 05:22 - 000000000 ____D C:\FRST
2017-11-06 12:39 - 2017-11-06 12:39 - 002403328 _____ (Farbar) C:\Users\Personal\Desktop\FRST64.exe
2017-11-06 11:51 - 2017-11-06 11:51 - 000262144 _____ C:\Windows\Minidump\110617-15350-01.dmp
2017-11-03 02:13 - 2017-11-03 02:13 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2017-11-03 02:12 - 2017-11-03 02:13 - 000000000 ___RD C:\Program Files (x86)\Skype
2017-11-03 02:01 - 2017-11-10 05:19 - 000004172 _____ C:\Windows\System32\Tasks\Avast Emergency Update
2017-11-03 02:01 - 2017-11-03 01:44 - 000401488 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2017-11-03 01:55 - 2017-11-03 01:55 - 000000000 ____D C:\ProgramData\Google
2017-11-03 01:55 - 2017-11-03 01:55 - 000000000 ____D C:\Program Files\Google
2017-11-03 01:46 - 2017-11-03 01:46 - 000000000 ____D C:\Users\Personal\AppData\Roaming\AVAST Software
2017-11-03 01:46 - 2017-11-03 01:46 - 000000000 ____D C:\Users\Personal\AppData\Local\CEF
2017-11-03 01:45 - 2017-11-03 02:02 - 000001924 _____ C:\Users\Public\Desktop\Avast Free Antivirus.lnk
2017-11-03 01:45 - 2017-11-03 01:45 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
2017-11-03 01:44 - 2017-11-03 02:02 - 001029872 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsnx.sys
2017-11-03 01:44 - 2017-11-03 02:00 - 001020536 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsnx.sys.150966374037707
2017-11-03 01:44 - 2017-11-03 01:44 - 000587168 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2017-11-03 01:44 - 2017-11-03 01:44 - 000363440 _____ (AVAST Software) C:\Windows\system32\Drivers\aswVmm.sys
2017-11-03 01:44 - 2017-11-03 01:44 - 000201352 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2017-11-03 01:44 - 2017-11-03 01:44 - 000147776 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2017-11-03 01:44 - 2017-11-03 01:44 - 000110376 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2017-11-03 01:44 - 2017-11-03 01:44 - 000084416 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys
2017-11-03 01:44 - 2017-11-03 01:44 - 000047008 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHwid.sys
2017-11-03 01:44 - 2017-11-03 01:43 - 000343288 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbloga.sys
2017-11-03 01:44 - 2017-11-03 01:43 - 000321032 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbidsdrivera.sys
2017-11-03 01:44 - 2017-11-03 01:43 - 000198976 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbidsha.sys
2017-11-03 01:44 - 2017-11-03 01:43 - 000057736 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbuniva.sys
2017-11-03 01:09 - 2017-11-09 11:38 - 000000000 ____D C:\Users\Personal\AppData\Local\ElevatedDiagnostics
2017-11-03 00:40 - 2017-11-03 00:40 - 000262144 _____ C:\Windows\Minidump\110317-20186-01.dmp
2017-11-03 00:04 - 2017-11-03 00:04 - 000000000 ____D C:\Program Files\Bitdefender Antivirus Free
2017-11-02 23:40 - 2017-11-02 23:40 - 000262144 _____ C:\Windows\Minidump\110217-20560-01.dmp
2017-11-02 23:06 - 2017-11-02 23:06 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox
2017-11-02 21:12 - 2017-11-02 21:12 - 000262144 _____ C:\Windows\Minidump\110217-17222-01.dmp
2017-11-02 20:29 - 2017-11-08 05:40 - 000000000 ____D C:\Windows\Minidump
2017-11-02 20:29 - 2017-11-06 20:31 - 000597662 _____ C:\Windows\ntbtlog.txt
2017-11-02 20:29 - 2017-11-02 20:29 - 000262144 _____ C:\Windows\Minidump\110217-18969-01.dmp
2017-11-02 20:28 - 2017-11-08 05:40 - 536318126 _____ C:\Windows\MEMORY.DMP
2017-11-02 20:16 - 2017-11-02 20:16 - 000000000 ____D C:\Users\Personal\AppData\Roaming\Adobe
2017-11-02 20:00 - 2013-10-14 18:00 - 000028368 _____ (Microsoft Corporation) C:\Windows\system32\IEUDINIT.EXE
2017-11-02 19:56 - 2017-11-02 19:56 - 019607040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2017-11-02 19:56 - 2017-11-02 19:56 - 012829696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2017-11-02 19:56 - 2017-11-02 19:56 - 004305920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2017-11-02 19:56 - 2017-11-02 19:56 - 002724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2017-11-02 19:56 - 2017-11-02 19:56 - 002278912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2017-11-02 19:56 - 2017-11-02 19:56 - 002052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2017-11-02 19:56 - 2017-11-02 19:56 - 001950720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2017-11-02 19:56 - 2017-11-02 19:56 - 001309696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2017-11-02 19:56 - 2017-11-02 19:56 - 001155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2017-11-02 19:56 - 2017-11-02 19:56 - 000940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2017-11-02 19:56 - 2017-11-02 19:56 - 000710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2017-11-02 19:56 - 2017-11-02 19:56 - 000689152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2017-11-02 19:56 - 2017-11-02 19:56 - 000664064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2017-11-02 19:56 - 2017-11-02 19:56 - 000645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll
2017-11-02 19:56 - 2017-11-02 19:56 - 000620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2017-11-02 19:56 - 2017-11-02 19:56 - 000616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat
2017-11-02 19:56 - 2017-11-02 19:56 - 000503808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2017-11-02 19:56 - 2017-11-02 19:56 - 000478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2017-11-02 19:56 - 2017-11-02 19:56 - 000418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2017-11-02 19:56 - 2017-11-02 19:56 - 000342728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2017-11-02 19:56 - 2017-11-02 19:56 - 000341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2017-11-02 19:56 - 2017-11-02 19:56 - 000285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2017-11-02 19:56 - 2017-11-02 19:56 - 000235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll
2017-11-02 19:56 - 2017-11-02 19:56 - 000233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2017-11-02 19:56 - 2017-11-02 19:56 - 000208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2017-11-02 19:56 - 2017-11-02 19:56 - 000194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll
2017-11-02 19:56 - 2017-11-02 19:56 - 000182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll
2017-11-02 19:56 - 2017-11-02 19:56 - 000168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2017-11-02 19:56 - 2017-11-02 19:56 - 000151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe
2017-11-02 19:56 - 2017-11-02 19:56 - 000139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe
2017-11-02 19:56 - 2017-11-02 19:56 - 000127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2017-11-02 19:56 - 2017-11-02 19:56 - 000116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll
2017-11-02 19:56 - 2017-11-02 19:56 - 000115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2017-11-02 19:56 - 2017-11-02 19:56 - 000111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll
2017-11-02 19:56 - 2017-11-02 19:56 - 000086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2017-11-02 19:56 - 2017-11-02 19:56 - 000083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2017-11-02 19:56 - 2017-11-02 19:56 - 000076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2017-11-02 19:56 - 2017-11-02 19:56 - 000074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe
2017-11-02 19:56 - 2017-11-02 19:56 - 000071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2017-11-02 19:56 - 2017-11-02 19:56 - 000069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll
2017-11-02 19:56 - 2017-11-02 19:56 - 000064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2017-11-02 19:56 - 2017-11-02 19:56 - 000062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2017-11-02 19:56 - 2017-11-02 19:56 - 000062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2017-11-02 19:56 - 2017-11-02 19:56 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2017-11-02 19:56 - 2017-11-02 19:56 - 000056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll
2017-11-02 19:56 - 2017-11-02 19:56 - 000048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll
2017-11-02 19:56 - 2017-11-02 19:56 - 000047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2017-11-02 19:56 - 2017-11-02 19:56 - 000047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2017-11-02 19:56 - 2017-11-02 19:56 - 000043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2017-11-02 19:56 - 2017-11-02 19:56 - 000036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll
2017-11-02 19:56 - 2017-11-02 19:56 - 000030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2017-11-02 19:56 - 2017-11-02 19:56 - 000024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll
2017-11-02 19:56 - 2017-11-02 19:56 - 000013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2017-11-02 19:56 - 2017-11-02 19:56 - 000012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2017-11-02 19:55 - 2017-11-02 19:55 - 024917504 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2017-11-02 19:55 - 2017-11-02 19:55 - 014404096 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2017-11-02 19:55 - 2017-11-02 19:55 - 006026240 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2017-11-02 19:55 - 2017-11-02 19:55 - 002885632 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2017-11-02 19:55 - 2017-11-02 19:55 - 002724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2017-11-02 19:55 - 2017-11-02 19:55 - 002426880 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2017-11-02 19:55 - 2017-11-02 19:55 - 002125824 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2017-11-02 19:55 - 2017-11-02 19:55 - 001545728 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2017-11-02 19:55 - 2017-11-02 19:55 - 001359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2017-11-02 19:55 - 2017-11-02 19:55 - 000942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll
2017-11-02 19:55 - 2017-11-02 19:55 - 000816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2017-11-02 19:55 - 2017-11-02 19:55 - 000814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2017-11-02 19:55 - 2017-11-02 19:55 - 000801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2017-11-02 19:55 - 2017-11-02 19:55 - 000800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2017-11-02 19:55 - 2017-11-02 19:55 - 000720384 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2017-11-02 19:55 - 2017-11-02 19:55 - 000633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2017-11-02 19:55 - 2017-11-02 19:55 - 000616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2017-11-02 19:55 - 2017-11-02 19:55 - 000584192 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2017-11-02 19:55 - 2017-11-02 19:55 - 000490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2017-11-02 19:55 - 2017-11-02 19:55 - 000417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2017-11-02 19:55 - 2017-11-02 19:55 - 000389840 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2017-11-02 19:55 - 2017-11-02 19:55 - 000316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2017-11-02 19:55 - 2017-11-02 19:55 - 000247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2017-11-02 19:55 - 2017-11-02 19:55 - 000243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2017-11-02 19:55 - 2017-11-02 19:55 - 000235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2017-11-02 19:55 - 2017-11-02 19:55 - 000199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2017-11-02 19:55 - 2017-11-02 19:55 - 000167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2017-11-02 19:55 - 2017-11-02 19:55 - 000147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2017-11-02 19:55 - 2017-11-02 19:55 - 000144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2017-11-02 19:55 - 2017-11-02 19:55 - 000143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2017-11-02 19:55 - 2017-11-02 19:55 - 000135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2017-11-02 19:55 - 2017-11-02 19:55 - 000131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2017-11-02 19:55 - 2017-11-02 19:55 - 000114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2017-11-02 19:55 - 2017-11-02 19:55 - 000105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2017-11-02 19:55 - 2017-11-02 19:55 - 000101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2017-11-02 19:55 - 2017-11-02 19:55 - 000092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2017-11-02 19:55 - 2017-11-02 19:55 - 000090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2017-11-02 19:55 - 2017-11-02 19:55 - 000088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2017-11-02 19:55 - 2017-11-02 19:55 - 000086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2017-11-02 19:55 - 2017-11-02 19:55 - 000081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2017-11-02 19:55 - 2017-11-02 19:55 - 000077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2017-11-02 19:55 - 2017-11-02 19:55 - 000077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2017-11-02 19:55 - 2017-11-02 19:55 - 000066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2017-11-02 19:55 - 2017-11-02 19:55 - 000062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2017-11-02 19:55 - 2017-11-02 19:55 - 000054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2017-11-02 19:55 - 2017-11-02 19:55 - 000052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2017-11-02 19:55 - 2017-11-02 19:55 - 000048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2017-11-02 19:55 - 2017-11-02 19:55 - 000048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2017-11-02 19:55 - 2017-11-02 19:55 - 000048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2017-11-02 19:55 - 2017-11-02 19:55 - 000034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2017-11-02 19:55 - 2017-11-02 19:55 - 000030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2017-11-02 19:55 - 2017-11-02 19:55 - 000013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2017-11-02 19:55 - 2017-11-02 19:55 - 000013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2017-11-02 19:55 - 2017-11-02 19:55 - 000004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 005549504 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2017-11-02 19:54 - 2017-11-02 19:54 - 003969472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2017-11-02 19:54 - 2017-11-02 19:54 - 003914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2017-11-02 19:54 - 2017-11-02 19:54 - 001903552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2017-11-02 19:54 - 2017-11-02 19:54 - 001732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 001292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 001161216 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 001114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000878080 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000859648 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000640512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000619520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2017-11-02 19:54 - 2017-11-02 19:54 - 000424448 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000376688 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys
2017-11-02 19:54 - 2017-11-02 19:54 - 000362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2017-11-02 19:54 - 2017-11-02 19:54 - 000327168 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000288088 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS
2017-11-02 19:54 - 2017-11-02 19:54 - 000274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000231424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswsock.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2017-11-02 19:54 - 2017-11-02 19:54 - 000068608 _____ (Microsoft Corporation) C:\Windows\system32\taskhost.exe
2017-11-02 19:54 - 2017-11-02 19:54 - 000043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2017-11-02 19:54 - 2017-11-02 19:54 - 000016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2017-11-02 19:54 - 2017-11-02 19:54 - 000006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
 
2017-11-02 19:54 - 2017-11-02 19:54 - 000004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2017-11-02 19:54 - 2017-11-02 19:54 - 000002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2017-11-02 19:51 - 2017-11-02 19:51 - 003928064 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 003419136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 002776576 _____ (Microsoft Corporation) C:\Windows\system32\msmpeg2vdec.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 002565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 002284544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msmpeg2vdec.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 001988096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 001682432 _____ (Microsoft Corporation) C:\Windows\system32\XpsPrint.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 001643520 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 001424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 001247744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 001238528 _____ (Microsoft Corporation) C:\Windows\system32\d3d10.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 001230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 001175552 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 001158144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsPrint.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 001080832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 000648192 _____ (Microsoft Corporation) C:\Windows\system32\d3d10level9.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 000604160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10level9.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 000522752 _____ (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 000465920 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 000417792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMPhoto.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 000364544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 000363008 _____ (Microsoft Corporation) C:\Windows\system32\dxgi.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 000333312 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1core.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 000296960 _____ (Microsoft Corporation) C:\Windows\system32\d3d10core.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 000293376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxgi.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 000249856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1core.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 000245248 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecsExt.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 000221184 _____ (Microsoft Corporation) C:\Windows\system32\UIAnimation.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 000220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10core.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 000207872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecsExt.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 000194560 _____ (Microsoft Corporation) C:\Windows\system32\d3d10_1.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 000187392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIAnimation.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 000161792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10_1.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 000010752 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l1-1-0.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 000010752 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 000009728 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 000009728 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 000005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 000005632 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-ole32-l1-1-0.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 000005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 000005632 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-user32-l1-1-0.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-advapi32-l2-1-0.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-version-l1-1-0.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-shell32-l1-1-0.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 000002560 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-downlevel-normaliz-l1-1-0.dll
2017-11-02 19:51 - 2017-11-02 19:51 - 000002560 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2017-11-02 19:49 - 2017-11-02 19:49 - 001887232 _____ (Microsoft Corporation) C:\Windows\system32\d3d11.dll
2017-11-02 19:49 - 2017-11-02 19:49 - 001505280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll
2017-11-02 17:34 - 2017-11-02 17:34 - 000000000 ____D C:\Windows\System32\Tasks\Safer-Networking
2017-11-02 17:33 - 2017-11-09 10:06 - 000000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
2017-11-02 17:33 - 2017-11-09 10:02 - 000000000 ____D C:\ProgramData\Spybot - Search & Destroy
2017-11-02 17:27 - 2017-11-02 17:31 - 051725936 _____ (Safer-Networking Ltd. ) C:\Users\Personal\Downloads\spybotsd-2.6.46.exe
2017-11-02 17:05 - 2017-11-02 17:05 - 000001869 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2017-11-02 17:05 - 2017-11-02 17:05 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2017-11-02 17:05 - 2017-11-02 17:05 - 000000000 ____D C:\ProgramData\Malwarebytes
2017-11-02 17:05 - 2017-11-02 17:05 - 000000000 ____D C:\Program Files\Malwarebytes
2017-11-02 17:05 - 2017-10-04 13:15 - 000077440 _____ C:\Windows\system32\Drivers\mbae64.sys
2017-11-02 16:59 - 2017-11-02 17:04 - 071535032 _____ (Malwarebytes ) C:\Users\Personal\Downloads\mb3-setup-consumer-3.2.2.2029-1.0.212-1.0.2951.exe
2017-11-02 16:27 - 2017-11-02 16:27 - 000000000 ____D C:\Users\Personal\AppData\Local\AvgSetupLog
2017-11-02 16:27 - 2017-11-02 16:27 - 000000000 ____D C:\Users\Personal\AppData\Local\Avg
2017-11-02 16:27 - 2017-11-02 16:27 - 000000000 ____D C:\ProgramData\Avg
2017-11-02 16:25 - 2017-11-02 16:25 - 003449304 _____ (AVG Technologies CZ, s.r.o.) C:\Users\Personal\Downloads\AVG_Protection_Free_1606.exe
2017-11-02 16:21 - 2017-11-02 19:44 - 055915216 _____ (Microsoft Corporation) C:\Users\Personal\Downloads\IE11-Windows6.1-x64-en-us.exe
2017-11-02 15:06 - 2017-11-02 15:06 - 000000000 ____D C:\ProgramData\Bitdefender Agent
2017-11-02 15:05 - 2017-11-02 15:06 - 009932672 _____ C:\Users\Personal\Downloads\bitdefender_online.exe
2017-11-02 14:42 - 2017-11-02 14:43 - 007161304 _____ (AVAST Software) C:\Users\Personal\Downloads\avast_free_antivirus_setup_online.exe
2017-11-02 14:24 - 2017-11-02 14:24 - 000000000 ____D C:\Program Files\AVAST Software
2017-11-02 14:06 - 2017-11-06 12:09 - 000000000 ____D C:\ProgramData\AVAST Software
2017-11-02 14:01 - 2014-08-08 19:31 - 000027136 _____ (The OpenVPN Project) C:\Windows\system32\Drivers\ptun0901.sys
2017-11-02 13:49 - 2017-11-02 16:56 - 000000000 ____D C:\Users\Personal\AppData\Local\MSfree Inc
2017-11-02 13:33 - 2015-07-18 16:08 - 000984448 _____ (Microsoft Corporation) C:\Windows\system32\ucrtbase.dll
2017-11-02 13:33 - 2015-07-18 16:08 - 000901264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ucrtbase.dll
2017-11-02 13:33 - 2015-07-18 16:08 - 000066400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-private-l1-1-0.dll
2017-11-02 13:33 - 2015-07-18 16:08 - 000063840 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-private-l1-1-0.dll
2017-11-02 13:33 - 2015-07-18 16:08 - 000022368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-math-l1-1-0.dll
2017-11-02 13:33 - 2015-07-18 16:08 - 000020832 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-math-l1-1-0.dll
2017-11-02 13:33 - 2015-07-18 16:08 - 000019808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-multibyte-l1-1-0.dll
2017-11-02 13:33 - 2015-07-18 16:08 - 000019808 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-multibyte-l1-1-0.dll
2017-11-02 13:33 - 2015-07-18 16:08 - 000017760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-string-l1-1-0.dll
2017-11-02 13:33 - 2015-07-18 16:08 - 000017760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-stdio-l1-1-0.dll
2017-11-02 13:33 - 2015-07-18 16:08 - 000017760 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-string-l1-1-0.dll
2017-11-02 13:33 - 2015-07-18 16:08 - 000017760 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-stdio-l1-1-0.dll
2017-11-02 13:33 - 2015-07-18 16:08 - 000016224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-runtime-l1-1-0.dll
2017-11-02 13:33 - 2015-07-18 16:08 - 000016224 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-runtime-l1-1-0.dll
2017-11-02 13:33 - 2015-07-18 16:08 - 000015712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-convert-l1-1-0.dll
2017-11-02 13:33 - 2015-07-18 16:08 - 000015712 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-convert-l1-1-0.dll
2017-11-02 13:33 - 2015-07-18 16:08 - 000014176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-time-l1-1-0.dll
2017-11-02 13:33 - 2015-07-18 16:08 - 000014176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-2-0.dll
2017-11-02 13:33 - 2015-07-18 16:08 - 000014176 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-time-l1-1-0.dll
2017-11-02 13:33 - 2015-07-18 16:08 - 000014176 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-2-0.dll
2017-11-02 13:33 - 2015-07-18 16:08 - 000013664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-filesystem-l1-1-0.dll
2017-11-02 13:33 - 2015-07-18 16:08 - 000013664 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll
2017-11-02 13:33 - 2015-07-18 16:08 - 000012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-process-l1-1-0.dll
2017-11-02 13:33 - 2015-07-18 16:08 - 000012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-heap-l1-1-0.dll
2017-11-02 13:33 - 2015-07-18 16:08 - 000012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-conio-l1-1-0.dll
2017-11-02 13:33 - 2015-07-18 16:08 - 000012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-process-l1-1-0.dll
2017-11-02 13:33 - 2015-07-18 16:08 - 000012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-heap-l1-1-0.dll
2017-11-02 13:33 - 2015-07-18 16:08 - 000012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-conio-l1-1-0.dll
2017-11-02 13:33 - 2015-07-18 16:08 - 000012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-utility-l1-1-0.dll
2017-11-02 13:33 - 2015-07-18 16:08 - 000012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-locale-l1-1-0.dll
2017-11-02 13:33 - 2015-07-18 16:08 - 000012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-environment-l1-1-0.dll
2017-11-02 13:33 - 2015-07-18 16:08 - 000012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-2-0.dll
2017-11-02 13:33 - 2015-07-18 16:08 - 000012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-1.dll
2017-11-02 13:33 - 2015-07-18 16:08 - 000012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-utility-l1-1-0.dll
2017-11-02 13:33 - 2015-07-18 16:08 - 000012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-locale-l1-1-0.dll
2017-11-02 13:33 - 2015-07-18 16:08 - 000012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-environment-l1-1-0.dll
2017-11-02 13:33 - 2015-07-18 16:08 - 000012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-2-0.dll
2017-11-02 13:33 - 2015-07-18 16:08 - 000012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-1.dll
2017-11-02 13:33 - 2015-07-18 16:08 - 000011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-eventing-provider-l1-1-0.dll
2017-11-02 13:33 - 2015-07-18 16:08 - 000011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l2-1-0.dll
2017-11-02 13:33 - 2015-07-18 16:08 - 000011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-timezone-l1-1-0.dll
2017-11-02 13:33 - 2015-07-18 16:08 - 000011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l2-1-0.dll
2017-11-02 13:33 - 2015-07-18 16:08 - 000011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-2-0.dll
2017-11-02 13:33 - 2015-07-18 16:08 - 000011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-eventing-provider-l1-1-0.dll
2017-11-02 13:33 - 2015-07-18 16:08 - 000011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l2-1-0.dll
2017-11-02 13:33 - 2015-07-18 16:08 - 000011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-timezone-l1-1-0.dll
2017-11-02 13:33 - 2015-07-18 16:08 - 000011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l2-1-0.dll
2017-11-02 13:33 - 2015-07-18 16:08 - 000011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-2-0.dll
2017-11-02 13:32 - 2017-11-02 13:32 - 000002167 _____ C:\Users\Personal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft OneDrive.lnk
2017-11-02 13:32 - 2017-11-02 13:32 - 000002106 _____ C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft OneDrive.lnk
2017-11-02 13:32 - 2017-11-02 13:32 - 000002106 _____ C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft OneDrive.lnk
2017-11-02 13:32 - 2017-11-02 13:32 - 000000000 ___RD C:\Users\Personal\OneDrive
2017-11-02 13:32 - 2017-11-02 13:32 - 000000000 ____D C:\ProgramData\Microsoft OneDrive
2017-11-02 13:32 - 2017-11-02 13:32 - 000000000 ____D C:\Program Files (x86)\Microsoft OneDrive
2017-11-02 13:25 - 2017-11-02 13:25 - 000000000 ____D C:\Windows\System32\Tasks\OfficeSoftwareProtectionPlatform
2017-11-02 13:08 - 2017-11-02 13:08 - 000000000 ____D C:\Users\Personal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2017-11-02 13:08 - 2017-11-02 13:08 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2017-11-02 13:08 - 2017-11-02 13:08 - 000000000 ____D C:\Program Files (x86)\WinRAR
2017-11-02 13:04 - 2017-11-02 13:04 - 001987408 _____ C:\Users\Personal\Downloads\wrar550.exe
2017-11-01 14:58 - 2017-11-01 14:58 - 000051016 _____ (Dropbox, Inc.) C:\Windows\system32\DbxSvc.exe
2017-11-01 14:58 - 2017-11-01 14:58 - 000045672 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-dev.sys
2017-11-01 14:58 - 2017-11-01 14:58 - 000045640 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-stable.sys
2017-11-01 14:58 - 2017-11-01 14:58 - 000045640 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-canary.sys
2017-10-31 16:23 - 2017-10-31 16:25 - 000000000 ___RD C:\Users\Personal\Dropbox
2017-10-31 16:23 - 2017-10-31 16:23 - 000001232 _____ C:\Users\Personal\Desktop\Dropbox.lnk
2017-10-31 16:17 - 2017-10-31 16:17 - 000000000 ____D C:\Users\Personal\AppData\Roaming\Dropbox
2017-10-31 16:11 - 2017-11-10 05:20 - 000000912 _____ C:\Windows\Tasks\DropboxUpdateTaskMachineUA.job
2017-10-31 16:11 - 2017-11-10 05:19 - 000000908 _____ C:\Windows\Tasks\DropboxUpdateTaskMachineCore.job
2017-10-31 16:11 - 2017-11-02 23:07 - 000000000 ____D C:\Program Files (x86)\Dropbox
2017-10-31 16:11 - 2017-11-01 22:47 - 000000000 ____D C:\Users\Personal\AppData\Local\Dropbox
2017-10-31 16:11 - 2017-10-31 16:11 - 000690080 _____ (Dropbox, Inc.) C:\Users\Personal\Downloads\DropboxInstaller.exe
2017-10-31 16:11 - 2017-10-31 16:11 - 000003908 _____ C:\Windows\System32\Tasks\DropboxUpdateTaskMachineUA
2017-10-31 16:11 - 2017-10-31 16:11 - 000003656 _____ C:\Windows\System32\Tasks\DropboxUpdateTaskMachineCore
2017-10-31 16:11 - 2017-10-31 16:11 - 000000000 ____D C:\ProgramData\Dropbox
2017-10-30 23:12 - 2017-10-30 23:12 - 000000000 ____D C:\Users\Personal\AppData\Roaming\dvdcss
2017-10-27 18:57 - 2017-11-06 11:52 - 000000344 _____ C:\Windows\Tasks\HPCeeScheduleForPersonal.job
2017-10-27 18:57 - 2017-11-06 11:48 - 000003204 _____ C:\Windows\System32\Tasks\HPCeeScheduleForPersonal
2017-10-27 18:57 - 2017-10-27 18:57 - 000000000 ____D C:\Users\Personal\AppData\Local\HP_Inc
2017-10-27 18:52 - 2017-10-27 18:52 - 000000000 ____D C:\Users\Personal\AppData\Roaming\Hewlett-Packard
2017-10-27 18:48 - 2017-10-27 18:48 - 000002233 _____ C:\Users\Public\Desktop\HP Support Assistant.lnk
2017-10-27 18:48 - 2017-10-27 18:48 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP Help and Support
2017-10-27 18:46 - 2017-10-28 12:43 - 000000000 ____D C:\ProgramData\Hewlett-Packard
2017-10-27 18:46 - 2017-10-27 18:46 - 000000000 ____D C:\System.sav
2017-10-27 18:46 - 2017-10-27 18:46 - 000000000 ____D C:\ProgramData\HP Inc
2017-10-27 18:45 - 2017-10-28 12:43 - 000000000 ____D C:\Windows\System32\Tasks\Hewlett-Packard
2017-10-27 18:45 - 2017-10-27 18:52 - 000000000 ____D C:\Users\Personal\AppData\Local\Hewlett-Packard
2017-10-27 18:45 - 2017-10-27 18:45 - 000000000 ____D C:\Users\Personal\AppData\Roaming\hpqLog
2017-10-27 18:45 - 2017-10-27 18:45 - 000000000 ____D C:\Program Files (x86)\HP
2017-10-27 18:44 - 2017-10-27 18:46 - 000000000 ____D C:\Program Files (x86)\Hewlett-Packard
2017-10-27 18:44 - 2017-10-27 18:44 - 000000000 ____D C:\swsetup
2017-10-27 18:40 - 2017-10-27 18:44 - 035357824 _____ (HP Inc. ) C:\Users\Personal\Downloads\sp82049.exe
2017-10-27 16:25 - 2017-10-27 16:25 - 000000000 ____D C:\Users\Personal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Python 3.5
2017-10-27 16:25 - 2017-10-27 16:25 - 000000000 ____D C:\Users\Personal\AppData\Local\Package Cache
2017-10-27 16:18 - 2017-11-06 20:24 - 000000000 ____D C:\Users\Personal\AppData\Roaming\qBittorrent
2017-10-27 16:18 - 2017-10-27 16:26 - 000000000 ____D C:\Users\Personal\AppData\Local\qBittorrent
2017-10-27 16:18 - 2017-10-27 16:18 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\qBittorrent
2017-10-27 16:18 - 2017-10-27 16:18 - 000000000 ____D C:\Program Files\qBittorrent
2017-10-27 16:14 - 2017-10-27 16:15 - 019756156 _____ (The qBittorrent project) C:\Users\Personal\Downloads\qbittorrent_3.3.16_x64_setup.exe
2017-10-27 15:58 - 2017-10-27 15:58 - 000000836 _____ C:\Users\Personal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Start Tor Browser.lnk
2017-10-27 15:58 - 2017-10-27 15:58 - 000000788 _____ C:\Users\Personal\Desktop\Start Tor Browser.lnk
2017-10-27 15:58 - 2017-10-27 15:58 - 000000000 ____D C:\Users\Personal\Desktop\Tor Browser
2017-10-27 15:53 - 2017-10-27 15:53 - 001005568 _____ (Microsoft Corporation) C:\Users\Personal\Downloads\dotNetFx45_Full_setup.exe
2017-10-27 15:51 - 2017-10-27 15:57 - 053739632 _____ C:\Users\Personal\Downloads\torbrowser-install-7.5a6_en-US.exe
2017-10-27 15:43 - 2017-10-27 15:43 - 000000000 ____D C:\Users\Personal\.swt
2017-10-27 15:42 - 2017-10-27 20:58 - 000000000 ____D C:\Users\Personal\AppData\Roaming\Azureus
2017-10-27 15:40 - 2017-10-27 15:40 - 000000000 ____D C:\ProgramData\Oracle
2017-10-27 15:38 - 2017-10-27 15:38 - 000091808 _____ (Azureus Software, Inc.) C:\Users\Personal\Downloads\VuzeBittorrentClientInstaller.exe
2017-10-27 15:24 - 2017-10-27 15:25 - 000000000 ____D C:\Program Files (x86)\CrystalDiskInfo
2017-10-27 15:24 - 2017-10-27 15:24 - 000001206 _____ C:\Users\Personal\Desktop\CrystalDiskInfo.lnk
2017-10-27 15:24 - 2017-10-27 15:24 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CrystalDiskInfo
2017-10-27 15:23 - 2017-10-27 15:24 - 003928200 _____ (Crystal Dew World ) C:\Users\Personal\Downloads\CrystalDiskInfo7_1_1.exe
2017-10-27 15:07 - 2017-10-27 15:07 - 000002273 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-10-27 15:07 - 2017-10-27 15:07 - 000002261 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2017-10-27 15:07 - 2017-10-27 15:07 - 000000000 ____D C:\Users\Personal\AppData\Roaming\Google
2017-10-27 15:03 - 2017-11-03 01:55 - 000000000 ____D C:\Program Files (x86)\Google
2017-10-27 15:03 - 2017-10-31 15:28 - 000000000 ____D C:\Users\Personal\AppData\Local\Google
2017-10-27 15:03 - 2017-10-27 15:03 - 000003330 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2017-10-27 15:03 - 2017-10-27 15:03 - 000003202 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2017-10-27 15:02 - 2017-11-02 21:09 - 000000000 ____D C:\Users\Personal\AppData\Local\Deployment
2017-10-27 15:02 - 2017-10-27 15:02 - 000000000 ____D C:\Users\Personal\AppData\Local\Apps\2.0
2017-10-27 14:54 - 2017-10-27 14:54 - 000000000 ____D C:\ProgramData\Microsoft Toolkit
2017-10-27 02:40 - 2017-10-26 15:53 - 000000000 ____D C:\Windows\Panther
2017-10-27 01:45 - 2017-10-27 01:45 - 000001345 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
2017-10-27 01:45 - 2017-10-27 01:45 - 000001326 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
2017-10-26 17:21 - 2017-10-26 17:21 - 000000000 ____D C:\Users\Personal\AppData\Roaming\ATI
2017-10-26 17:21 - 2017-10-26 17:21 - 000000000 ____D C:\Users\Personal\AppData\Local\ATI
2017-10-26 17:21 - 2017-10-26 17:21 - 000000000 ____D C:\ProgramData\ATI
2017-10-26 17:19 - 2017-10-26 17:19 - 000000000 ____D C:\Program Files\Common Files\Intel
2017-10-26 17:18 - 2017-10-26 17:18 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Catalyst Control Center
2017-10-26 17:17 - 2017-10-26 17:17 - 000000000 _____ C:\Windows\ativpsrm.bin
2017-10-26 17:17 - 2011-01-12 22:03 - 000003155 _____ C:\Windows\SysWOW64\atipblup.dat
2017-10-26 17:17 - 2011-01-12 22:03 - 000003155 _____ C:\Windows\system32\atipblup.dat
2017-10-26 17:15 - 2017-10-26 17:18 - 000000000 ____D C:\Program Files\ATI Technologies
2017-10-26 17:15 - 2017-10-26 17:17 - 000000000 ____D C:\Program Files (x86)\ATI Technologies
2017-10-26 17:15 - 2017-10-26 17:15 - 000000000 ____D C:\Users\Personal\AppData\Roaming\DRPNPS
2017-10-26 17:14 - 2017-10-26 17:14 - 000000000 ____D C:\Users\Personal\AppData\Local\Ahead
2017-10-26 17:14 - 2017-10-26 17:14 - 000000000 ____D C:\Program Files\ATI
2017-10-26 17:12 - 2011-01-27 20:29 - 000013476 _____ C:\Windows\system32\iglhxs64.vp
2017-10-26 17:12 - 2011-01-27 20:15 - 000509976 _____ (Intel Corporation) C:\Windows\system32\igfxsrvc.exe
2017-10-26 17:12 - 2011-01-27 20:15 - 000418328 _____ (Intel Corporation) C:\Windows\system32\igfxpers.exe
2017-10-26 17:12 - 2011-01-27 20:15 - 000239128 _____ (Intel Corporation) C:\Windows\system32\igfxext.exe
2017-10-26 17:12 - 2011-01-27 20:15 - 000167960 _____ (Intel Corporation) C:\Windows\system32\igfxtray.exe
2017-10-26 17:12 - 2011-01-27 19:55 - 000960940 _____ C:\Windows\SysWOW64\igkrng600.bin
2017-10-26 17:12 - 2011-01-27 19:55 - 000960940 _____ C:\Windows\system32\igkrng600.bin
2017-10-26 17:12 - 2011-01-27 19:55 - 000213332 _____ C:\Windows\SysWOW64\igfcg600m.bin
2017-10-26 17:12 - 2011-01-27 19:55 - 000213332 _____ C:\Windows\system32\igfcg600m.bin
2017-10-26 17:12 - 2011-01-27 19:48 - 000575488 _____ (Intel Corporation) C:\Windows\SysWOW64\igdumdx32.dll
2017-10-26 17:12 - 2011-01-27 19:25 - 000287232 _____ (Intel Corporation) C:\Windows\system32\igfxrfra.lrc
2017-10-26 17:12 - 2011-01-27 19:25 - 000287232 _____ (Intel Corporation) C:\Windows\system32\igfxresn.lrc
2017-10-26 17:12 - 2011-01-27 19:25 - 000287232 _____ (Intel Corporation) C:\Windows\system32\igfxrell.lrc
2017-10-26 17:12 - 2011-01-27 19:25 - 000286720 _____ (Intel Corporation) C:\Windows\system32\igfxrsky.lrc
2017-10-26 17:12 - 2011-01-27 19:25 - 000286720 _____ (Intel Corporation) C:\Windows\system32\igfxrrus.lrc
2017-10-26 17:12 - 2011-01-27 19:25 - 000286720 _____ (Intel Corporation) C:\Windows\system32\igfxrrom.lrc
2017-10-26 17:12 - 2011-01-27 19:25 - 000286720 _____ (Intel Corporation) C:\Windows\system32\igfxrptg.lrc
2017-10-26 17:12 - 2011-01-27 19:25 - 000286720 _____ (Intel Corporation) C:\Windows\system32\igfxrplk.lrc
2017-10-26 17:12 - 2011-01-27 19:25 - 000286720 _____ (Intel Corporation) C:\Windows\system32\igfxrnld.lrc
2017-10-26 17:12 - 2011-01-27 19:25 - 000286720 _____ (Intel Corporation) C:\Windows\system32\igfxrita.lrc
2017-10-26 17:12 - 2011-01-27 19:25 - 000286720 _____ (Intel Corporation) C:\Windows\system32\igfxrhrv.lrc
2017-10-26 17:12 - 2011-01-27 19:25 - 000286720 _____ (Intel Corporation) C:\Windows\system32\igfxrdeu.lrc
2017-10-26 17:12 - 2011-01-27 19:25 - 000286720 _____ (Intel Corporation) C:\Windows\system32\igfxrcsy.lrc
2017-10-26 17:12 - 2011-01-27 19:25 - 000286208 _____ (Intel Corporation) C:\Windows\system32\igfxrtrk.lrc
2017-10-26 17:12 - 2011-01-27 19:25 - 000286208 _____ (Intel Corporation) C:\Windows\system32\igfxrsve.lrc
2017-10-26 17:12 - 2011-01-27 19:25 - 000286208 _____ (Intel Corporation) C:\Windows\system32\igfxrslv.lrc
2017-10-26 17:12 - 2011-01-27 19:25 - 000286208 _____ (Intel Corporation) C:\Windows\system32\igfxrptb.lrc
2017-10-26 17:12 - 2011-01-27 19:25 - 000286208 _____ (Intel Corporation) C:\Windows\system32\igfxrnor.lrc
2017-10-26 17:12 - 2011-01-27 19:25 - 000286208 _____ (Intel Corporation) C:\Windows\system32\igfxrhun.lrc
2017-10-26 17:12 - 2011-01-27 19:25 - 000286208 _____ (Intel Corporation) C:\Windows\system32\igfxrfin.lrc
2017-10-26 17:12 - 2011-01-27 19:25 - 000285696 _____ (Intel Corporation) C:\Windows\system32\igfxrtha.lrc
2017-10-26 17:12 - 2011-01-27 19:25 - 000285696 _____ (Intel Corporation) C:\Windows\system32\igfxrdan.lrc
2017-10-26 17:12 - 2011-01-27 19:25 - 000285184 _____ (Intel Corporation) C:\Windows\system32\igfxrheb.lrc
2017-10-26 17:12 - 2011-01-27 19:25 - 000285184 _____ (Intel Corporation) C:\Windows\system32\igfxrara.lrc
2017-10-26 17:12 - 2011-01-27 19:25 - 000283648 _____ (Intel Corporation) C:\Windows\system32\igfxrjpn.lrc
2017-10-26 17:12 - 2011-01-27 19:25 - 000283136 _____ (Intel Corporation) C:\Windows\system32\igfxrkor.lrc
2017-10-26 17:12 - 2011-01-27 19:25 - 000282624 _____ (Intel Corporation) C:\Windows\system32\igfxrcht.lrc
2017-10-26 17:12 - 2011-01-27 19:25 - 000282624 _____ (Intel Corporation) C:\Windows\system32\igfxrchs.lrc
2017-10-26 17:12 - 2011-01-27 19:25 - 000126976 _____ (Intel Corporation) C:\Windows\system32\igfxcpl.cpl
2017-10-26 17:12 - 2011-01-27 19:24 - 000380928 _____ (Intel Corporation) C:\Windows\system32\igfxTMM.dll
2017-10-26 17:12 - 2011-01-27 19:24 - 000335872 _____ (Intel Corporation) C:\Windows\system32\igfxpph.dll
2017-10-26 17:12 - 2011-01-27 19:24 - 000028672 _____ (Intel Corporation) C:\Windows\system32\igfxexps.dll
2017-10-26 17:12 - 2011-01-27 19:23 - 000004096 _____ ( ) C:\Windows\system32\IGFXDEVLib.dll
2017-10-26 17:12 - 2011-01-27 19:22 - 000285696 _____ (Intel Corporation) C:\Windows\system32\igfxrenu.lrc
2017-10-26 17:12 - 2011-01-27 19:22 - 000142336 _____ (Intel Corporation) C:\Windows\system32\igfxdo.dll
2017-10-26 17:12 - 2011-01-27 19:18 - 000024576 _____ (Intel Corporation) C:\Windows\SysWOW64\igfxexps32.dll
2017-10-26 17:12 - 2011-01-27 19:17 - 000288768 _____ (Intel Corporation) C:\Windows\SysWOW64\igfxdv32.dll
2017-10-26 17:12 - 2011-01-27 19:11 - 001991936 _____ C:\Windows\system32\iglhxa64.cpa
2017-10-26 17:12 - 2011-01-27 19:11 - 000368640 _____ (Intel Corporation) C:\Windows\SysWOW64\iglhsip32.dll
2017-10-26 17:12 - 2011-01-27 19:11 - 000364032 _____ (Intel Corporation) C:\Windows\system32\iglhsip64.dll
2017-10-26 17:12 - 2011-01-27 19:11 - 000142848 _____ (Intel Corporation) C:\Windows\SysWOW64\igfxcmrt32.dll
2017-10-26 17:12 - 2011-01-27 19:11 - 000122368 _____ (Intel Corporation) C:\Windows\system32\igfxcmrt64.dll
2017-10-26 17:12 - 2011-01-27 19:11 - 000095744 _____ (Intel Corporation) C:\Windows\system32\iglhcp64.dll
2017-10-26 17:12 - 2011-01-27 19:11 - 000086528 _____ (Intel Corporation) C:\Windows\SysWOW64\iglhcp32.dll
 
2017-10-26 17:12 - 2011-01-27 19:11 - 000060254 _____ C:\Windows\system32\iglhxg64.vp
2017-10-26 17:12 - 2011-01-27 19:11 - 000060226 _____ C:\Windows\system32\iglhxc64.vp
2017-10-26 17:12 - 2011-01-27 19:11 - 000060015 _____ C:\Windows\system32\iglhxo64.vp
2017-10-26 17:12 - 2011-01-27 19:11 - 000001090 _____ C:\Windows\system32\iglhxa64.vp
2017-10-26 17:11 - 2017-10-26 17:11 - 000000000 ____D C:\ProgramData\CyberLink
2017-10-26 17:11 - 2011-03-15 21:28 - 009259520 _____ (ATI Technologies Inc.) C:\Windows\system32\Drivers\atikmdag.sys
2017-10-26 17:11 - 2011-03-15 21:26 - 022518272 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atio6axx.dll
2017-10-26 17:11 - 2011-03-15 21:06 - 017397248 _____ (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\atioglxx.dll
2017-10-26 17:11 - 2011-03-15 21:02 - 000680960 _____ (ATI Technologies Inc. ) C:\Windows\SysWOW64\aticfx32.dll
2017-10-26 17:11 - 2011-03-15 21:02 - 000152384 _____ C:\Windows\system32\atiapfxx.blb
2017-10-26 17:11 - 2011-03-15 21:02 - 000143360 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atiapfxx.exe
2017-10-26 17:11 - 2011-03-15 21:01 - 000796160 _____ (ATI Technologies Inc. ) C:\Windows\system32\aticfx64.dll
2017-10-26 17:11 - 2011-03-15 20:59 - 000480256 _____ (AMD) C:\Windows\system32\atieclxx.exe
2017-10-26 17:11 - 2011-03-15 20:59 - 000462848 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\ATIDEMGX.dll
2017-10-26 17:11 - 2011-03-15 20:58 - 000203776 _____ (AMD) C:\Windows\system32\atiesrxx.exe
2017-10-26 17:11 - 2011-03-15 20:57 - 000423424 _____ (ATI Technologies, Inc.) C:\Windows\system32\atipdl64.dll
2017-10-26 17:11 - 2011-03-15 20:57 - 000356352 _____ (ATI Technologies, Inc.) C:\Windows\SysWOW64\atipdlxx.dll
2017-10-26 17:11 - 2011-03-15 20:57 - 000278528 _____ (ATI Technologies, Inc.) C:\Windows\SysWOW64\Oemdspif.dll
2017-10-26 17:11 - 2011-03-15 20:57 - 000120320 _____ (AMD) C:\Windows\system32\atitmm64.dll
2017-10-26 17:11 - 2011-03-15 20:56 - 000059392 _____ (ATI Technologies, Inc.) C:\Windows\system32\atiedu64.dll
2017-10-26 17:11 - 2011-03-15 20:56 - 000043520 _____ (ATI Technologies, Inc.) C:\Windows\SysWOW64\ati2edxx.dll
2017-10-26 17:11 - 2011-03-15 20:56 - 000016384 _____ (AMD) C:\Windows\system32\atimuixx.dll
2017-10-26 17:11 - 2011-03-15 20:54 - 004277760 _____ (ATI Technologies Inc. ) C:\Windows\SysWOW64\atidxx32.dll
2017-10-26 17:11 - 2011-03-15 20:46 - 005044224 _____ (ATI Technologies Inc. ) C:\Windows\system32\atidxx64.dll
2017-10-26 17:11 - 2011-03-15 20:39 - 007025152 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\aticaldd64.dll
2017-10-26 17:11 - 2011-03-15 20:39 - 000051200 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\aticalrt64.dll
2017-10-26 17:11 - 2011-03-15 20:39 - 000046080 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticalrt.dll
2017-10-26 17:11 - 2011-03-15 20:39 - 000044544 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\aticalcl64.dll
2017-10-26 17:11 - 2011-03-15 20:39 - 000044032 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticalcl.dll
2017-10-26 17:11 - 2011-03-15 20:38 - 005619200 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\aticaldd.dll
2017-10-26 17:11 - 2011-03-15 20:37 - 004294656 _____ (ATI Technologies Inc. ) C:\Windows\SysWOW64\atiumdag.dll
2017-10-26 17:11 - 2011-03-15 20:35 - 003239936 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiumd6a.dll
2017-10-26 17:11 - 2011-03-15 20:35 - 001912832 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiumdmv.dll
2017-10-26 17:11 - 2011-03-15 20:35 - 001208320 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiumd6v.dll
2017-10-26 17:11 - 2011-03-15 20:32 - 000788800 _____ C:\Windows\system32\atiumd6a.cap
2017-10-26 17:11 - 2011-03-15 20:31 - 005438976 _____ (ATI Technologies Inc. ) C:\Windows\system32\atiumd64.dll
2017-10-26 17:11 - 2011-03-15 20:31 - 000058880 _____ (AMD) C:\Windows\system32\coinst.dll
2017-10-26 17:11 - 2011-03-15 20:28 - 003471872 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiumdva.dll
2017-10-26 17:11 - 2011-03-15 20:27 - 000788800 _____ C:\Windows\SysWOW64\atiumdva.cap
2017-10-26 17:11 - 2011-03-15 20:25 - 000360448 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atiadlxx.dll
2017-10-26 17:11 - 2011-03-15 20:25 - 000258048 _____ (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\atiadlxy.dll
2017-10-26 17:11 - 2011-03-15 20:25 - 000014848 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atig6pxx.dll
2017-10-26 17:11 - 2011-03-15 20:24 - 000301056 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\Drivers\atikmpag.sys
2017-10-26 17:11 - 2011-03-15 20:24 - 000039936 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiuxp64.dll
2017-10-26 17:11 - 2011-03-15 20:24 - 000039936 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atig6txx.dll
2017-10-26 17:11 - 2011-03-15 20:24 - 000032768 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atigktxx.dll
2017-10-26 17:11 - 2011-03-15 20:24 - 000012800 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiglpxx.dll
2017-10-26 17:11 - 2011-03-15 20:23 - 000053248 _____ (ATI Technologies Inc.) C:\Windows\system32\Drivers\ati2erec.dll
2017-10-26 17:11 - 2011-03-15 20:23 - 000038400 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiu9p64.dll
2017-10-26 17:11 - 2011-03-15 20:23 - 000031232 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiuxpag.dll
2017-10-26 17:11 - 2011-03-15 20:23 - 000028672 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atiu9pag.dll
2017-10-26 17:11 - 2011-03-15 20:16 - 000053760 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atimpc64.dll
2017-10-26 17:11 - 2011-03-15 20:16 - 000053760 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\amdpcom64.dll
2017-10-26 17:11 - 2011-03-15 20:16 - 000052736 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\atimpc32.dll
2017-10-26 17:11 - 2011-03-15 20:16 - 000052736 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\amdpcom32.dll
2017-10-26 17:11 - 2011-02-02 04:01 - 000227586 _____ C:\Windows\system32\atiicdxx.dat
2017-10-26 17:11 - 2011-01-27 20:15 - 004368920 _____ (Intel Corporation) C:\Windows\system32\GfxUI.exe
2017-10-26 17:11 - 2011-01-27 20:15 - 000391704 _____ (Intel Corporation) C:\Windows\system32\hkcmd.exe
2017-10-26 17:11 - 2011-01-27 20:15 - 000179736 _____ C:\Windows\system32\difx64.exe
2017-10-26 17:11 - 2011-01-27 19:57 - 012273408 _____ (Intel Corporation) C:\Windows\system32\Drivers\igdpmd64.sys
2017-10-26 17:11 - 2011-01-27 19:57 - 012273408 _____ (Intel Corporation) C:\Windows\system32\Drivers\igdkmd64.sys
2017-10-26 17:11 - 2011-01-27 19:57 - 007470080 _____ (Intel Corporation) C:\Windows\system32\igdumd64.dll
2017-10-26 17:11 - 2011-01-27 19:55 - 000145804 _____ C:\Windows\SysWOW64\igcompkrng600.bin
2017-10-26 17:11 - 2011-01-27 19:55 - 000145804 _____ C:\Windows\system32\igcompkrng600.bin
2017-10-26 17:11 - 2011-01-27 19:51 - 005689344 _____ (Intel Corporation) C:\Windows\SysWOW64\igdumd32.dll
2017-10-26 17:11 - 2011-01-27 19:47 - 007386112 _____ (Intel Corporation) C:\Windows\system32\igd10umd64.dll
2017-10-26 17:11 - 2011-01-27 19:44 - 006068224 _____ (Intel Corporation) C:\Windows\SysWOW64\igd10umd32.dll
2017-10-26 17:11 - 2011-01-27 19:38 - 019591680 _____ (Intel Corporation) C:\Windows\system32\ig4icd64.dll
2017-10-26 17:11 - 2011-01-27 19:30 - 014292992 _____ (Intel Corporation) C:\Windows\SysWOW64\ig4icd32.dll
2017-10-26 17:11 - 2011-01-27 19:26 - 000208335 _____ C:\Windows\system32\Gfxres.th-TH.resources
2017-10-26 17:11 - 2011-01-27 19:26 - 000135119 _____ C:\Windows\system32\Gfxres.ro-RO.resources
2017-10-26 17:11 - 2011-01-27 19:26 - 000133868 _____ C:\Windows\system32\Gfxres.tr-TR.resources
2017-10-26 17:11 - 2011-01-27 19:26 - 000132422 _____ C:\Windows\system32\Gfxres.sv-SE.resources
2017-10-26 17:11 - 2011-01-27 19:26 - 000130414 _____ C:\Windows\system32\Gfxres.hr-HR.resources
2017-10-26 17:11 - 2011-01-27 19:26 - 000127599 _____ C:\Windows\system32\Gfxres.sl-SI.resources
2017-10-26 17:11 - 2011-01-27 19:26 - 000116413 _____ C:\Windows\system32\Gfxres.zh-TW.resources
2017-10-26 17:11 - 2011-01-27 19:26 - 000115195 _____ C:\Windows\system32\Gfxres.zh-CN.resources
2017-10-26 17:11 - 2011-01-27 19:25 - 000195681 _____ C:\Windows\system32\Gfxres.el-GR.resources
2017-10-26 17:11 - 2011-01-27 19:25 - 000180246 _____ C:\Windows\system32\Gfxres.ru-RU.resources
2017-10-26 17:11 - 2011-01-27 19:25 - 000154366 _____ C:\Windows\system32\Gfxres.ar-SA.resources
2017-10-26 17:11 - 2011-01-27 19:25 - 000151350 _____ C:\Windows\system32\Gfxres.ja-JP.resources
2017-10-26 17:11 - 2011-01-27 19:25 - 000147392 _____ C:\Windows\system32\Gfxres.he-IL.resources
2017-10-26 17:11 - 2011-01-27 19:25 - 000138635 _____ C:\Windows\system32\Gfxres.it-IT.resources
2017-10-26 17:11 - 2011-01-27 19:25 - 000137000 _____ C:\Windows\system32\Gfxres.ko-KR.resources
2017-10-26 17:11 - 2011-01-27 19:25 - 000136226 _____ C:\Windows\system32\Gfxres.de-DE.resources
2017-10-26 17:11 - 2011-01-27 19:25 - 000136172 _____ C:\Windows\system32\Gfxres.es-ES.resources
2017-10-26 17:11 - 2011-01-27 19:25 - 000134081 _____ C:\Windows\system32\Gfxres.fr-FR.resources
2017-10-26 17:11 - 2011-01-27 19:25 - 000133321 _____ C:\Windows\system32\Gfxres.pt-BR.resources
2017-10-26 17:11 - 2011-01-27 19:25 - 000132876 _____ C:\Windows\system32\Gfxres.nl-NL.resources
2017-10-26 17:11 - 2011-01-27 19:25 - 000132861 _____ C:\Windows\system32\Gfxres.hu-HU.resources
2017-10-26 17:11 - 2011-01-27 19:25 - 000132299 _____ C:\Windows\system32\Gfxres.pt-PT.resources
2017-10-26 17:11 - 2011-01-27 19:25 - 000131897 _____ C:\Windows\system32\Gfxres.cs-CZ.resources
2017-10-26 17:11 - 2011-01-27 19:25 - 000131711 _____ C:\Windows\system32\Gfxres.pl-PL.resources
2017-10-26 17:11 - 2011-01-27 19:25 - 000131456 _____ C:\Windows\system32\Gfxres.fi-FI.resources
2017-10-26 17:11 - 2011-01-27 19:25 - 000131290 _____ C:\Windows\system32\Gfxres.sk-SK.resources
2017-10-26 17:11 - 2011-01-27 19:25 - 000127367 _____ C:\Windows\system32\Gfxres.nb-NO.resources
2017-10-26 17:11 - 2011-01-27 19:25 - 000127109 _____ C:\Windows\system32\Gfxres.da-DK.resources
2017-10-26 17:11 - 2011-01-27 19:25 - 000122646 _____ C:\Windows\system32\Gfxres.en-US.resources
2017-10-26 17:11 - 2011-01-27 19:23 - 000144896 _____ (Intel Corporation) C:\Windows\system32\gfxSrvc.dll
2017-10-26 17:11 - 2011-01-27 19:15 - 000000151 _____ C:\Windows\system32\GfxUI.exe.config
2017-10-26 17:11 - 2011-01-14 23:00 - 000030831 _____ C:\Windows\atiogl.xml
2017-10-26 17:11 - 2011-01-13 09:03 - 000003155 _____ C:\Windows\SysWOW64\atipblag.dat
2017-10-26 17:11 - 2011-01-13 09:03 - 000003155 _____ C:\Windows\system32\atipblag.dat
2017-10-26 17:11 - 2010-10-15 12:28 - 000317440 _____ (Intel(R) Corporation) C:\Windows\system32\Drivers\IntcDAud.sys
2017-10-26 17:11 - 2010-10-15 12:27 - 000014848 _____ (Intel(R) Corporation) C:\Windows\system32\IntcDAuC.dll
2017-10-26 17:11 - 2009-05-12 04:35 - 000118784 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atibtmon.exe
2017-10-26 17:10 - 2017-11-08 04:55 - 000001945 _____ C:\Windows\epplauncher.mif
2017-10-26 17:10 - 2017-11-02 14:06 - 000109752 _____ C:\Users\Personal\AppData\Local\GDIPFONTCACHEV1.DAT
2017-10-26 17:10 - 2017-10-26 17:10 - 000001145 _____ C:\Users\Personal\Desktop\CyberLink YouCam.lnk
2017-10-26 17:09 - 2017-10-27 18:48 - 000000000 ____D C:\Program Files (x86)\InstallShield Installation Information
2017-10-26 17:09 - 2017-10-26 17:11 - 000000000 ____D C:\Users\Personal\Documents\YouCam
2017-10-26 17:09 - 2017-10-26 17:09 - 000000000 ____D C:\Users\Personal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink YouCam
2017-10-26 17:09 - 2017-10-26 17:09 - 000000000 ____D C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink YouCam
2017-10-26 17:09 - 2017-10-26 17:09 - 000000000 ____D C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink YouCam
2017-10-26 17:08 - 2017-10-26 17:09 - 000000000 ____D C:\Program Files (x86)\CyberLink
2017-10-26 17:01 - 2017-11-03 02:28 - 000000000 ____D C:\Program Files (x86)\Microsoft Office
2017-10-26 17:01 - 2017-10-26 17:01 - 000000000 ____D C:\Users\Personal\AppData\Local\Microsoft Help
2017-10-26 17:00 - 2017-11-09 10:50 - 000000000 ____D C:\Users\Personal\AppData\Roaming\Skype
2017-10-26 17:00 - 2017-11-03 02:13 - 000002697 _____ C:\Users\Public\Desktop\Skype.lnk
2017-10-26 17:00 - 2017-11-03 02:13 - 000000000 ____D C:\ProgramData\Skype
2017-10-26 17:00 - 2017-10-26 17:00 - 000000000 ____D C:\Users\Personal\Tracing
2017-10-26 16:56 - 2017-10-27 16:26 - 000000000 ____D C:\ProgramData\Package Cache
2017-10-26 16:55 - 2017-11-09 11:44 - 000000000 ____D C:\Users\Personal\AppData\LocalLow\Mozilla
2017-10-26 16:55 - 2017-10-26 16:55 - 000000936 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2017-10-26 16:55 - 2017-10-26 16:55 - 000000924 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2017-10-26 16:55 - 2017-10-26 16:55 - 000000000 ____D C:\Users\Personal\AppData\Roaming\Mozilla
2017-10-26 16:55 - 2017-10-26 16:55 - 000000000 ____D C:\Users\Personal\AppData\Local\Mozilla
2017-10-26 16:55 - 2017-10-26 16:55 - 000000000 ____D C:\Program Files\Mozilla Firefox
2017-10-26 16:55 - 2017-10-26 16:55 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2017-10-26 16:54 - 2017-10-26 16:54 - 000002746 _____ C:\Users\Public\Desktop\Nero StartSmart.lnk
2017-10-26 16:54 - 2017-10-26 16:54 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nero 7 Ultra Edition
2017-10-26 16:53 - 2017-10-27 14:56 - 000000000 ____D C:\Users\Personal\AppData\Roaming\Ahead
2017-10-26 16:53 - 2017-10-26 16:53 - 000000000 ____D C:\ProgramData\Nero
2017-10-26 16:53 - 2017-10-26 16:53 - 000000000 ____D C:\Program Files (x86)\Nero
2017-10-26 16:52 - 2006-03-31 12:40 - 002388176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_30.dll
2017-10-26 16:52 - 2005-12-05 18:09 - 002323664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_28.dll
2017-10-26 16:47 - 2017-10-26 16:47 - 003306652 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2017-10-26 16:44 - 2017-11-03 02:02 - 000004476 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2017-10-26 16:43 - 2017-11-06 18:04 - 000000000 ____D C:\Users\Personal\AppData\Roaming\vlc
2017-10-26 16:43 - 2017-10-26 16:43 - 000002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2017-10-26 16:43 - 2017-10-26 16:43 - 000002047 _____ C:\Users\Public\Desktop\Acrobat Reader DC.lnk
2017-10-26 16:43 - 2017-10-26 16:43 - 000000871 _____ C:\Users\Public\Desktop\VLC media player.lnk
2017-10-26 16:43 - 2017-10-26 16:43 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2017-10-26 16:43 - 2017-10-26 16:43 - 000000000 ____D C:\Program Files\VideoLAN
2017-10-26 16:43 - 2017-10-26 16:43 - 000000000 ____D C:\Program Files (x86)\Adobe
2017-10-26 16:42 - 2017-10-27 14:49 - 000000000 ____D C:\ProgramData\Adobe
2017-10-26 16:35 - 2017-10-26 16:35 - 000000000 ____D C:\Program Files\Common Files\ATI Technologies
2017-10-26 16:35 - 2017-10-26 16:35 - 000000000 ____D C:\Program Files\AMD
2017-10-26 16:34 - 2015-10-09 21:27 - 000161304 _____ C:\Windows\system32\hsa-thunk64.dll
2017-10-26 16:34 - 2015-10-09 21:27 - 000151576 _____ C:\Windows\SysWOW64\hsa-thunk.dll
2017-10-26 16:34 - 2015-10-09 21:27 - 000151056 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\mantle64.dll
2017-10-26 16:34 - 2015-10-09 21:27 - 000126480 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\mantle32.dll
2017-10-26 16:34 - 2015-10-09 21:27 - 000117776 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\mantleaxl64.dll
2017-10-26 16:34 - 2015-10-09 21:27 - 000098320 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\mantleaxl32.dll
2017-10-26 16:34 - 2015-10-09 21:26 - 000873488 _____ (AMD) C:\Windows\system32\coinst_15.20.dll
2017-10-26 16:34 - 2015-10-09 21:26 - 000012816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\detoured.dll
2017-10-26 16:34 - 2015-10-09 21:26 - 000012816 _____ (Microsoft Corporation) C:\Windows\system32\detoured.dll
2017-10-26 16:34 - 2015-10-09 21:24 - 000451096 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\atidemgy.dll
2017-10-26 16:34 - 2015-10-09 21:24 - 000099344 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\atiglpxx.dll
2017-10-26 16:34 - 2015-10-09 21:23 - 047794200 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\amdocl64.dll
2017-10-26 16:34 - 2015-10-09 21:23 - 000943128 _____ (Advanced Micro Devices, Inc.) C:\Windows\SysWOW64\atiadlxx.dll
2017-10-26 16:34 - 2015-10-09 21:23 - 000061976 _____ C:\Windows\system32\amdverag.dll
2017-10-26 16:34 - 2015-10-09 21:22 - 027544592 _____ (Advanced Micro Devices Inc.) C:\Windows\system32\amdocl12cl64.dll
2017-10-26 16:34 - 2015-10-09 21:22 - 022327320 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\amdocl12cl.dll
2017-10-26 16:34 - 2015-10-09 21:21 - 039720976 _____ (Advanced Micro Devices Inc.) C:\Windows\SysWOW64\amdocl.dll
2017-10-26 16:34 - 2015-10-09 21:21 - 006354456 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\amdmantle64.dll
2017-10-26 16:34 - 2015-10-09 21:21 - 000059416 _____ (Advanced Micro Devices, Inc. ) C:\Windows\system32\amdmmcl6.dll
2017-10-26 16:34 - 2015-10-09 21:21 - 000047128 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\amdmmcl.dll
2017-10-26 16:34 - 2015-10-09 21:20 - 005138456 _____ (Advanced Micro Devices, Inc. ) C:\Windows\SysWOW64\amdmantle32.dll
2017-10-26 16:34 - 2015-10-09 21:20 - 000305400 _____ (Advanced Micro Devices) C:\Windows\system32\Drivers\amdacpksd.sys
2017-10-26 16:34 - 2015-10-09 21:20 - 000073752 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll
2017-10-26 16:34 - 2015-10-09 21:20 - 000068112 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll
2017-10-26 16:34 - 2015-10-09 18:27 - 000662480 _____ C:\Windows\SysWOW64\atiapfxx.blb
2017-10-26 16:34 - 2015-10-09 18:27 - 000322868 _____ C:\Windows\system32\ativvaxy_vi.dat
2017-10-26 16:34 - 2015-10-09 18:27 - 000321200 _____ C:\Windows\system32\ativvaxy_vi_nd.dat
2017-10-26 16:34 - 2015-10-09 18:27 - 000255808 _____ C:\Windows\system32\ativvaxy_cz_nd.dat
2017-10-26 16:34 - 2015-10-09 18:27 - 000250884 _____ C:\Windows\system32\ativvaxy_FJ.dat
2017-10-26 16:34 - 2015-10-09 18:27 - 000249088 _____ C:\Windows\system32\ativvaxy_FJ_nd.dat
2017-10-26 16:34 - 2015-10-09 18:27 - 000234420 _____ C:\Windows\system32\ativvaxy_cik.dat
2017-10-26 16:34 - 2015-10-09 18:27 - 000232752 _____ C:\Windows\system32\ativvaxy_cik_nd.dat
2017-10-26 16:34 - 2015-10-09 18:27 - 000204952 _____ C:\Windows\SysWOW64\ativvsvl.dat
2017-10-26 16:34 - 2015-10-09 18:27 - 000204952 _____ C:\Windows\system32\ativvsvl.dat
2017-10-26 16:34 - 2015-10-09 18:27 - 000177344 _____ C:\Windows\system32\ativce03.dat
2017-10-26 16:34 - 2015-10-09 18:27 - 000157144 _____ C:\Windows\SysWOW64\ativvsva.dat
2017-10-26 16:34 - 2015-10-09 18:27 - 000157144 _____ C:\Windows\system32\ativvsva.dat
2017-10-26 16:34 - 2015-10-09 18:27 - 000100816 _____ C:\Windows\system32\ativce02.dat
2017-10-26 16:34 - 2015-10-09 18:27 - 000020790 _____ C:\Windows\SysWOW64\ativvsnl.dat
2017-10-26 16:34 - 2015-10-09 18:27 - 000020790 _____ C:\Windows\system32\ativvsnl.dat
2017-10-26 16:34 - 2015-10-09 18:27 - 000000025 _____ C:\Windows\SysWOW64\ativvsny.dat
2017-10-26 16:34 - 2015-10-09 18:27 - 000000025 _____ C:\Windows\system32\ativvsny.dat
2017-10-26 16:34 - 2015-10-09 18:26 - 000842001 _____ C:\Windows\system32\amdicdxx.dat
2017-10-26 16:34 - 2015-10-09 18:26 - 000175648 _____ C:\Windows\system32\amde31a.dat
2017-10-26 16:33 - 2015-10-09 21:26 - 000243728 _____ C:\Windows\system32\clinfo.exe
2017-10-26 16:33 - 2015-10-09 21:20 - 000237584 _____ C:\Windows\system32\amdgfxinfo64.dll
2017-10-26 16:33 - 2015-10-09 21:20 - 000209936 _____ C:\Windows\SysWOW64\amdgfxinfo32.dll
2017-10-26 16:32 - 2015-10-09 21:25 - 000341520 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\ATIODE.exe
2017-10-26 16:32 - 2015-10-09 21:25 - 000059920 _____ (Advanced Micro Devices, Inc.) C:\Windows\system32\ATIODCLI.exe
2017-10-26 16:32 - 2015-10-09 21:24 - 000219160 _____ C:\Windows\system32\atieah64.exe
2017-10-26 16:32 - 2015-10-09 21:24 - 000198168 _____ C:\Windows\SysWOW64\atieah32.exe
2017-10-26 16:32 - 2015-10-09 21:21 - 001196072 _____ C:\Windows\system32\amdocl_as64.exe
2017-10-26 16:32 - 2015-10-09 21:21 - 001070632 _____ C:\Windows\system32\amdocl_ld64.exe
2017-10-26 16:32 - 2015-10-09 21:21 - 001004072 _____ C:\Windows\SysWOW64\amdocl_as32.exe
2017-10-26 16:32 - 2015-10-09 21:21 - 000807464 _____ C:\Windows\SysWOW64\amdocl_ld32.exe
2017-10-26 16:24 - 2017-10-26 16:24 - 000000000 ____H C:\Windows\system32\Drivers\MsftWdf_Kernel_01011_Coinstaller_Critical.Wdf
2017-10-26 16:24 - 2017-10-26 16:24 - 000000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_WinUSB_01009.Wdf
2017-10-26 16:24 - 2017-10-26 16:24 - 000000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_TeeDriverx64_01011.Wdf
2017-10-26 16:24 - 2017-10-26 16:24 - 000000000 ____D C:\Windows\SysWOW64\sda
2017-10-26 16:24 - 2012-09-24 12:40 - 000043840 _____ (Hewlett-Packard Company) C:\Windows\system32\Drivers\Accelerometer.sys
2017-10-26 16:24 - 2012-09-24 12:40 - 000031040 _____ (Hewlett-Packard Company) C:\Windows\system32\Drivers\hpdskflt.sys
2017-10-26 16:24 - 2012-07-26 07:55 - 000785512 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Wdf01000.sys
2017-10-26 16:24 - 2012-07-26 07:55 - 000054376 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdfLdr.sys
2017-10-26 16:24 - 2012-07-26 05:36 - 000009728 _____ (Microsoft Corporation) C:\Windows\system32\Wdfres.dll
2017-10-26 16:24 - 2012-06-02 17:35 - 000000003 _____ C:\Windows\system32\Drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
2017-10-26 16:23 - 2015-10-08 22:15 - 000180480 _____ (Intel Corporation) C:\Windows\system32\Drivers\TeeDriverx64.sys
2017-10-26 16:23 - 2015-05-04 10:06 - 011531536 _____ (Intel Corporation) C:\Windows\system32\Drivers\NETwsw00.sys
2017-10-26 16:23 - 2013-07-09 20:53 - 001002728 _____ (Microsoft Corporation) C:\Windows\system32\WinUSBCoInstaller2.dll
2017-10-26 16:23 - 2012-09-24 12:40 - 000031040 _____ (Hewlett-Packard Company) C:\Windows\system32\hpservice.exe
2017-10-26 16:23 - 2012-09-24 12:40 - 000021312 _____ (Hewlett-Packard Company) C:\Windows\system32\accelerometerdll.DLL
2017-10-26 16:23 - 2012-09-24 12:40 - 000018240 _____ (Hewlett-Packard Company) C:\Windows\system32\HPMDPCoInst12.dll
2017-10-26 16:23 - 2012-08-03 06:51 - 001721576 _____ (Microsoft Corporation) C:\Windows\system32\WdfCoInstaller01009.dll
2017-10-26 16:22 - 2015-10-16 11:26 - 000367320 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\Drivers\RtsPStor.sys
2017-10-26 16:22 - 2014-10-20 17:50 - 000083160 _____ (Realtek Semiconductor.) C:\Windows\system32\RtCRX64.dll
2017-10-26 16:22 - 2014-01-27 13:39 - 009890008 _____ (Realtek Semiconductor Corp.) C:\Windows\SysWOW64\RsCRIcon.dll
2017-10-26 16:22 - 2012-08-17 11:57 - 001795952 _____ (Microsoft Corporation) C:\Windows\system32\WdfCoInstaller01011.dll
2017-10-26 16:13 - 2017-10-26 17:19 - 000000000 ____D C:\Program Files (x86)\Intel
2017-10-26 16:13 - 2017-10-26 16:13 - 000000000 ____D C:\Intel
2017-10-26 16:13 - 2012-08-27 18:39 - 000226696 _____ (Renesas Electronics Corporation) C:\Windows\system32\Drivers\nusb3xhc.sys
2017-10-26 16:13 - 2012-08-27 18:39 - 000107912 _____ (Renesas Electronics Corporation) C:\Windows\system32\Drivers\nusb3hub.sys
2017-10-26 16:13 - 2011-12-26 08:38 - 000081920 _____ (Renesas Electronics Corporation) C:\Windows\system32\nusb3co3.dll
2017-10-26 16:12 - 2015-06-04 22:20 - 000116224 _____ (Intel Corporation) C:\Windows\system32\igfxCoIn_v4229.dll
2017-10-26 16:12 - 2015-05-26 20:50 - 003511296 _____ (Intel Corporation) C:\Windows\system32\igfxcmjit64.dll
2017-10-26 16:12 - 2015-05-26 20:50 - 003121152 _____ (Intel Corporation) C:\Windows\SysWOW64\igfxcmjit32.dll
2017-10-26 16:12 - 2015-05-26 20:50 - 000575488 _____ (Intel Corporation) C:\Windows\system32\igfx11cmrt64.dll
2017-10-26 16:12 - 2015-05-26 20:50 - 000542720 _____ (Intel Corporation) C:\Windows\SysWOW64\igfx11cmrt32.dll
2017-10-26 16:12 - 2015-05-26 20:50 - 000059104 _____ C:\Windows\system32\iglhxc64_dev.vp
2017-10-26 16:12 - 2015-05-26 20:50 - 000058796 _____ C:\Windows\system32\iglhxg64_dev.vp
2017-10-26 16:12 - 2015-05-26 20:50 - 000058109 _____ C:\Windows\system32\iglhxo64_dev.vp
2017-10-26 16:12 - 2011-01-27 19:24 - 000062464 _____ (Intel Corporation) C:\Windows\system32\igfxsrvc.dll
2017-10-26 16:12 - 2011-01-27 19:23 - 000385024 _____ (Intel Corporation) C:\Windows\system32\igfxdev.dll
2017-10-26 16:12 - 2011-01-27 19:22 - 009014784 _____ (Intel Corporation) C:\Windows\system32\igfxress.dll
2017-10-26 16:11 - 2015-05-26 20:53 - 000101376 _____ C:\Windows\system32\igdde64.dll
2017-10-26 16:11 - 2015-05-26 20:53 - 000081408 _____ C:\Windows\SysWOW64\igdde32.dll
2017-10-26 16:11 - 2015-05-26 20:50 - 000094208 _____ C:\Windows\system32\IccLibDll_x64.dll
2017-10-26 16:11 - 2011-01-27 19:23 - 000109056 _____ (Intel Corporation) C:\Windows\system32\hccutils.dll
2017-10-26 16:10 - 2015-06-04 22:21 - 000280680 _____ (Intel Corporation) C:\Windows\SysWOW64\IntelCpHeciSvc.exe
2017-10-26 16:10 - 2015-05-29 17:05 - 000646408 _____ (Intel Corporation) C:\Windows\system32\Drivers\iaStorA.sys
2017-10-26 16:10 - 2015-05-29 17:05 - 000030960 _____ (Intel Corporation) C:\Windows\system32\Drivers\iaStorF.sys
2017-10-26 16:10 - 2015-05-26 20:50 - 000963452 _____ C:\Windows\SysWOW64\igcodeckrng600.bin
2017-10-26 16:10 - 2015-05-26 20:50 - 000963452 _____ C:\Windows\system32\igcodeckrng600.bin
2017-10-26 16:10 - 2015-05-26 20:50 - 000272928 _____ C:\Windows\SysWOW64\igvpkrng600.bin
2017-10-26 16:10 - 2015-05-26 20:50 - 000272928 _____ C:\Windows\system32\igvpkrng600.bin
2017-10-26 16:04 - 2014-06-22 17:57 - 000095096 _____ (TOSHIBA CORPORATION) C:\Windows\system32\Drivers\tosrfusb.sys
2017-10-26 16:04 - 2009-09-09 12:23 - 000051712 _____ (Intel Corporation) C:\Windows\system32\Drivers\flashud.sys
2017-10-26 16:04 - 2009-06-18 20:42 - 000040832 _____ (TOSHIBA CORPORATION.) C:\Windows\system32\Drivers\TosBtCi.dll
2017-10-26 16:00 - 2014-01-08 19:23 - 000898264 _____ (Realtek ) C:\Windows\system32\Drivers\Rt64win7.sys
2017-10-26 16:00 - 2014-01-08 19:23 - 000107552 _____ (Realtek Semiconductor Corporation) C:\Windows\system32\RTNUninst64.dll
2017-10-26 16:00 - 2014-01-08 19:23 - 000073800 _____ (Realtek Semiconductor Corporation) C:\Windows\system32\RtNicProp64.dll
2017-10-26 15:54 - 2017-11-02 20:16 - 000001419 _____ C:\Users\Personal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2017-10-26 15:53 - 2017-11-02 13:32 - 000000000 ____D C:\Users\Personal
2017-10-26 15:53 - 2017-10-26 15:53 - 000000020 ___SH C:\Users\Personal\ntuser.ini
2017-10-26 15:53 - 2017-10-26 15:53 - 000000000 ____D C:\Users\Personal\AppData\Local\VirtualStore
2017-10-26 15:53 - 2010-11-21 10:16 - 000000000 ____D C:\Users\Personal\AppData\Roaming\Media Center Programs

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2017-11-09 10:56 - 2009-07-14 05:34 - 000000215 _____ C:\Windows\system.ini
2017-11-09 10:15 - 2009-07-14 07:45 - 000016944 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2017-11-09 10:15 - 2009-07-14 07:45 - 000016944 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2017-11-09 10:06 - 2009-07-14 08:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2017-11-08 06:36 - 2009-07-14 08:13 - 000781298 _____ C:\Windows\system32\PerfStringBackup.INI
2017-11-08 06:36 - 2009-07-14 06:20 - 000000000 ____D C:\Windows\inf
2017-11-03 02:27 - 2009-07-14 06:20 - 000000000 ____D C:\Program Files\Common Files\Microsoft Shared
2017-11-02 22:59 - 2009-07-14 06:20 - 000000000 ____D C:\Windows\rescache
2017-11-02 20:08 - 2009-07-14 07:45 - 000445200 _____ C:\Windows\system32\FNTCACHE.DAT
2017-11-02 20:01 - 2009-07-14 06:20 - 000000000 ____D C:\Windows\PolicyDefinitions
2017-11-02 18:28 - 2009-07-14 06:20 - 000000000 ____D C:\Windows\system32\NDF
2017-11-02 13:54 - 2010-11-21 10:17 - 000000000 ____D C:\Windows\ShellNew
2017-11-02 13:54 - 2009-07-14 08:32 - 000000000 ____D C:\Program Files (x86)\MSBuild
2017-10-28 12:38 - 2009-07-14 08:09 - 000000000 ____D C:\Windows\System32\Tasks\WPD
2017-10-27 19:54 - 2010-11-21 10:17 - 000000000 ____D C:\Program Files\Windows Journal
2017-10-27 19:54 - 2009-07-14 08:32 - 000000000 ____D C:\Program Files\Windows Sidebar
2017-10-27 19:54 - 2009-07-14 08:32 - 000000000 ____D C:\Program Files\Windows Photo Viewer
2017-10-27 19:54 - 2009-07-14 08:32 - 000000000 ____D C:\Program Files\Windows Defender
2017-10-27 19:54 - 2009-07-14 08:32 - 000000000 ____D C:\Program Files (x86)\Windows Sidebar
2017-10-27 19:54 - 2009-07-14 08:32 - 000000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2017-10-27 19:54 - 2009-07-14 06:20 - 000000000 ____D C:\Program Files\Common Files\System
2017-10-27 19:53 - 2010-11-21 10:06 - 000000000 ____D C:\Windows\SysWOW64\winrm
2017-10-27 19:53 - 2010-11-21 10:06 - 000000000 ____D C:\Windows\SysWOW64\WCN
2017-10-27 19:53 - 2010-11-21 10:06 - 000000000 ____D C:\Windows\SysWOW64\sysprep
2017-10-27 19:53 - 2010-11-21 10:06 - 000000000 ____D C:\Windows\SysWOW64\slmgr
2017-10-27 19:53 - 2010-11-21 10:06 - 000000000 ____D C:\Windows\SysWOW64\Printing_Admin_Scripts
2017-10-27 19:53 - 2010-11-21 10:06 - 000000000 ____D C:\Windows\system32\winrm
2017-10-27 19:53 - 2010-11-21 10:06 - 000000000 ____D C:\Windows\system32\WCN
2017-10-27 19:53 - 2010-11-21 10:06 - 000000000 ____D C:\Windows\system32\slmgr
2017-10-27 19:53 - 2010-11-21 10:06 - 000000000 ____D C:\Windows\system32\Printing_Admin_Scripts
2017-10-27 19:53 - 2009-07-14 08:32 - 000000000 ____D C:\Program Files (x86)\Windows Defender
2017-10-27 19:53 - 2009-07-14 06:20 - 000000000 ____D C:\Windows\SysWOW64\Setup
2017-10-27 19:53 - 2009-07-14 06:20 - 000000000 ____D C:\Windows\SysWOW64\oobe
2017-10-27 19:53 - 2009-07-14 06:20 - 000000000 ____D C:\Windows\SysWOW64\MUI
2017-10-27 19:53 - 2009-07-14 06:20 - 000000000 ____D C:\Windows\SysWOW64\migwiz
2017-10-27 19:53 - 2009-07-14 06:20 - 000000000 ____D C:\Windows\SysWOW64\Dism
2017-10-27 19:53 - 2009-07-14 06:20 - 000000000 ____D C:\Windows\SysWOW64\com
2017-10-27 19:53 - 2009-07-14 06:20 - 000000000 ____D C:\Windows\system32\sysprep
2017-10-27 19:53 - 2009-07-14 06:20 - 000000000 ____D C:\Windows\system32\Setup
2017-10-27 19:53 - 2009-07-14 06:20 - 000000000 ____D C:\Windows\system32\oobe
2017-10-27 19:53 - 2009-07-14 06:20 - 000000000 ____D C:\Windows\system32\MUI
2017-10-27 19:53 - 2009-07-14 06:20 - 000000000 ____D C:\Windows\system32\migwiz
2017-10-27 19:53 - 2009-07-14 06:20 - 000000000 ____D C:\Windows\system32\Dism
2017-10-27 19:53 - 2009-07-14 06:20 - 000000000 ____D C:\Windows\system32\com
2017-10-27 19:53 - 2009-07-14 06:20 - 000000000 ____D C:\Windows\servicing
2017-10-27 19:52 - 2009-07-14 06:20 - 000000000 ____D C:\Windows\IME
2017-10-27 18:48 - 2009-07-14 06:20 - 000000000 ____D C:\Windows\Help
2017-10-27 14:59 - 2009-07-14 06:20 - 000000000 __RHD C:\Users\Public\Libraries
2017-10-27 02:40 - 2009-07-14 08:32 - 000028672 _____ C:\Windows\system32\config\BCD-Template
2017-10-27 01:41 - 2010-11-21 10:17 - 000000000 ____D C:\Windows\CSC
2017-10-26 17:01 - 2009-07-14 05:34 - 000000478 _____ C:\Windows\win.ini

==================== Files in the root of some directories =======

2017-11-06 20:45 - 2017-11-06 20:45 - 000048896 _____ () C:\ProgramData\agent.1509990317.bdinstall.bin
2017-11-08 04:54 - 2017-11-08 04:54 - 000030402 _____ () C:\ProgramData\agent.uninstall.1510106092.bdinstall.bin

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2017-11-09 04:56

==================== End of FRST.txt ============================
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 02-11-2017
Ran by Personal (10-11-2017 05:23:36)
Running from C:\Users\Personal\Desktop
Windows 7 Professional Service Pack 1 (X64) (2017-10-26 12:53:30)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-3766277524-2784970969-2751085713-500 - Administrator - Disabled)
Guest (S-1-5-21-3766277524-2784970969-2751085713-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3766277524-2784970969-2751085713-1002 - Limited - Enabled)
Personal (S-1-5-21-3766277524-2784970969-2751085713-1000 - Administrator - Enabled) => C:\Users\Personal

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Avast Antivirus (Enabled - Up to date) {8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF}
AV: Malwarebytes (Enabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B}
AS: Malwarebytes (Enabled - Up to date) {98619B37-4FC4-67F2-1C99-EEF6D47DBD96}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Avast Antivirus (Enabled - Up to date) {35C973AA-9ABB-D3CA-B100-B0DC0E5F2402}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 15.017.20050 - Adobe Systems Incorporated)
ATI Catalyst Install Manager (HKLM\...\{DA0D8FDA-D538-1145-8BA2-6F22C4EB4F75}) (Version: 3.0.816.0 - ATI Technologies, Inc.)
Avast Free Antivirus (HKLM-x32\...\Avast Antivirus) (Version: 17.7.2314 - AVAST Software)
CrystalDiskInfo 7.1.1 (HKLM-x32\...\CrystalDiskInfo_is1) (Version: 7.1.1 - Crystal Dew World)
CyberLink YouCam (HKLM-x32\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 2.0.1519 - CyberLink Corp.)
Dropbox (HKLM-x32\...\Dropbox) (Version: 38.4.27 - Dropbox, Inc.)
Dropbox Update Helper (HKLM-x32\...\{099218A5-A723-43DC-8DB5-6173656A1E94}) (Version: 1.3.65.1 - Dropbox, Inc.) Hidden
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 62.0.3202.75 - Google Inc.)
Google Toolbar for Internet Explorer (HKLM-x32\...\{18455581-E099-4BA8-BC6B-F34B2F06600C}) (Version: 1.0.0 - Google Inc.) Hidden
Google Toolbar for Internet Explorer (HKLM-x32\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.8231.2252 - Google Inc.)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.5 - Google Inc.) Hidden
HP Support Assistant (HKLM-x32\...\{4AAC4B07-77EF-4BCF-88DC-D24E4DE683E8}) (Version: 8.5.37.19 - HP Inc.)
HP Support Solutions Framework (HKLM-x32\...\{63F82052-C045-4F97-A3CA-C41D2CCA1FFA}) (Version: 12.8.37.11 - HP Inc.)
Intel(R) Display Audio Driver (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 6.14.00.3074 - Intel Corporation)
Malwarebytes version 3.2.2.2029 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.2.2.2029 - Malwarebytes)
Microsoft .NET Framework 4.5 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50709 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-3766277524-2784970969-2751085713-1000\...\OneDriveSetup.exe) (Version: 17.3.4604.0120 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23026 (HKLM-x32\...\{e46eca4f-393b-40df-9f49-076faf788d83}) (Version: 14.0.23026.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23026 (HKLM-x32\...\{74d0e5db-b326-4dae-a6b2-445b9de1836e}) (Version: 14.0.23026.0 - Microsoft Corporation)
Mozilla Firefox 52.0 (x64 en-US) (HKLM\...\Mozilla Firefox 52.0 (x64 en-US)) (Version: 52.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 52.0 - Mozilla)
Nero 7 Ultra Edition (HKLM-x32\...\{43FFE159-3199-4188-A1CD-629166AD1033}) (Version: 7.02.6445 - Nero AG)
PX Profile Update (HKLM-x32\...\{1C34B2AF-0D61-1784-8BC8-219F969BEFD6}) (Version: 1.00.1. - AMD) Hidden
Python 3.5.2 (32-bit) (HKU\S-1-5-21-3766277524-2784970969-2751085713-1000\...\{cf72a2ab-2f1d-49fd-a0d7-1065e6357e1e}) (Version: 3.5.2150.0 - Python Software Foundation)
Python 3.5.2 Core Interpreter (32-bit) (HKLM-x32\...\{EB0611B2-7F10-4D97-BCF2-DCAAB1199498}) (Version: 3.5.2150.0 - Python Software Foundation) Hidden
Python 3.5.2 Development Libraries (32-bit) (HKLM-x32\...\{5DB2183B-62D3-407F-BBC1-EAD2F36283FA}) (Version: 3.5.2150.0 - Python Software Foundation) Hidden
Python 3.5.2 Documentation (32-bit) (HKLM-x32\...\{1FBA5182-78DD-4940-9F06-96E5042B7061}) (Version: 3.5.2150.0 - Python Software Foundation) Hidden
Python 3.5.2 Executables (32-bit) (HKLM-x32\...\{33B10015-A9B1-4210-B50A-26C6443979B0}) (Version: 3.5.2150.0 - Python Software Foundation) Hidden
Python 3.5.2 pip Bootstrap (32-bit) (HKLM-x32\...\{9ADF9987-3327-48C6-91B3-B10900366491}) (Version: 3.5.2150.0 - Python Software Foundation) Hidden
Python 3.5.2 Standard Library (32-bit) (HKLM-x32\...\{FCBB04F4-D2CF-4F55-BE92-B3898696B318}) (Version: 3.5.2150.0 - Python Software Foundation) Hidden
Python 3.5.2 Tcl/Tk Support (32-bit) (HKLM-x32\...\{C1153533-FDC4-4922-892D-B71810F69566}) (Version: 3.5.2150.0 - Python Software Foundation) Hidden
Python 3.5.2 Test Suite (32-bit) (HKLM-x32\...\{9D50A6D7-410A-4469-87B7-35FA84CBD479}) (Version: 3.5.2150.0 - Python Software Foundation) Hidden
Python 3.5.2 Utility Scripts (32-bit) (HKLM-x32\...\{E6DEBF43-7ACF-4E88-9BBF-9B5945683281}) (Version: 3.5.2150.0 - Python Software Foundation) Hidden
Python Launcher (HKLM-x32\...\{963ECCDD-F09F-4C24-9367-8B5D748AA7C8}) (Version: 3.5.2121.0 - Python Software Foundation)
qBittorrent 3.3.16 (HKLM-x32\...\qBittorrent) (Version: 3.3.16 - The qBittorrent project)
RogueKiller version 12.11.23.0 (HKLM\...\8B3D7924-ED89-486B-8322-E8594065D5CB_is1) (Version: 12.11.23.0 - Adlice Software)
Skype™ 7.40 (HKLM-x32\...\{3B7E914A-93D5-4A29-92BB-AF8C3F66C431}) (Version: 7.40.103 - Skype Technologies S.A.)
VLC media player (HKLM\...\VLC media player) (Version: 2.2.6 - VideoLAN)
WinRAR archiver (HKLM-x32\...\WinRAR archiver) (Version: - )

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

ShellIconOverlayIdentifiers: [ DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2017-11-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2017-11-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2017-11-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2017-11-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2017-11-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2017-11-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2017-11-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2017-11-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2017-11-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2017-11-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-11-03] (AVAST Software)
ShellIconOverlayIdentifiers-x32: [ DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2017-11-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2017-11-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2017-11-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2017-11-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2017-11-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2017-11-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2017-11-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2017-11-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2017-11-01] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2017-11-01] (Dropbox, Inc.)
ContextMenuHandlers1: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-11-03] (AVAST Software)
ContextMenuHandlers1-x32: [Cover Designer] -> {73FCA462-9BD5-4065-A73F-A8E5F6904EF7} => C:\Program Files (x86)\Nero\Nero 7\Nero CoverDesigner\CoverEdExtension.dll [2007-02-28] (Nero AG)
ContextMenuHandlers1-x32: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2017-11-01] (Dropbox, Inc.)
ContextMenuHandlers1-x32: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext64.dll [2005-06-07] ()
ContextMenuHandlers1-x32-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext.dll [2006-07-03] ()
ContextMenuHandlers3: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-11-03] (AVAST Software)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-08-30] (Malwarebytes)
ContextMenuHandlers4: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2017-11-01] (Dropbox, Inc.)
ContextMenuHandlers4: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext64.dll [2005-06-07] ()
ContextMenuHandlers4-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext.dll [2006-07-03] ()
ContextMenuHandlers5: [ACE] -> {5E2121EE-0300-11D4-8D3B-444553540000} => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\atiacm64.dll [2011-03-15] (Advanced Micro Devices, Inc.)
ContextMenuHandlers5: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.19.0.dll [2017-11-01] (Dropbox, Inc.)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => C:\Windows\system32\igfxpph.dll [2011-01-27] (Intel Corporation)
ContextMenuHandlers6: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-11-03] (AVAST Software)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-08-30] (Malwarebytes)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext64.dll [2005-06-07] ()
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files (x86)\WinRAR\rarext.dll [2006-07-03] ()

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {2349899B-F223-4E7D-B72A-B1B10B98F275} - System32\Tasks\HPCeeScheduleForPersonal => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2016-06-24] (HP Inc.)
Task: {24975BB3-483A-4206-B830-E35D6F775712} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2017-09-27] (HP Inc.)
Task: {3DE04FDF-33D0-411D-BAF5-F66A40CBA6DE} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSFReport.exe [2017-09-27] (HP Inc.)
Task: {758987D2-C8A1-468D-8F9D-F52E67A3799A} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2017-09-27] (HP Inc.)
Task: {7987ED90-E824-42B0-A9A9-A31B25226401} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Product Configurator => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\ProductConfig.exe [2017-10-11] (HP Inc.)
Task: {BEC2C0AC-A564-46E5-92D8-2923641B3031} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2017-09-27] (HP Inc.)
Task: {BF5A7ACF-A8BD-47C5-979C-F56AAF33C1D9} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2017-10-31] (Dropbox, Inc.)
Task: {C4E168C0-72A9-4DA8-8178-446A2925792E} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [2017-09-27] (HP Inc.)
Task: {C70C6C6D-7504-408F-BBAE-42F26BABB359} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-10-27] (Google Inc.)
Task: {D4239F68-BE7B-4AF3-940E-3DCD882663F0} - System32\Tasks\Avast Emergency Update => C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe [2017-11-03] (AVAST Software)
Task: {D6C6FA7A-B0F2-4291-8C1E-BCDA680E83C4} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2017-10-31] (Dropbox, Inc.)
Task: {D8881422-CDE4-4DBC-9168-ED981F73AF17} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-10-27] (Google Inc.)
Task: {F6F1F239-6DFB-4DA7-897D-D6A96F7B28C2} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2017-07-19] (Adobe Systems Incorporated)
Task: {FE53B6E5-CB2B-4762-A2DF-49B25C05EA37} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2017-09-27] (HP Inc.)
Task: {FFC474F9-AAF4-458F-9968-8AEF8E2C8267} - System32\Tasks\Hewlett-Packard\HP Active Health\HP Active Health Scan (HPSA) => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPActiveHealth\ActiveHealth.exe [2017-09-27] (HP Inc.)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\Windows\Tasks\DropboxUpdateTaskMachineCore.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
Task: C:\Windows\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
Task: C:\Windows\Tasks\HPCeeScheduleForPersonal.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe

==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)


==================== Loaded Modules (Whitelisted) ==============

2017-10-26 16:11 - 2015-05-26 20:50 - 000094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2011-03-14 14:21 - 2011-03-14 14:21 - 000016384 _____ () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Branding\Branding.dll
2011-03-15 09:57 - 2011-03-15 09:57 - 000243712 _____ () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll
2017-11-02 13:08 - 2005-06-07 12:26 - 000043008 _____ () C:\Program Files (x86)\WinRAR\rarext64.dll
2017-11-03 01:44 - 2017-11-03 01:44 - 000067408 _____ () C:\Program Files\AVAST Software\Avast\x64\module_lifetime.dll
2017-10-27 15:07 - 2017-10-26 09:30 - 004135768 _____ () C:\Program Files (x86)\Google\Chrome\Application\62.0.3202.75\libglesv2.dll
2017-10-27 15:07 - 2017-10-26 09:30 - 000100184 _____ () C:\Program Files (x86)\Google\Chrome\Application\62.0.3202.75\libegl.dll
2017-11-02 17:05 - 2017-10-04 13:15 - 002289096 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\SelfProtectionSdk.dll
2017-11-02 17:05 - 2017-10-04 13:15 - 002358728 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\MwacLib.dll
2017-11-03 01:44 - 2017-11-03 01:44 - 000169832 _____ () c:\Program Files\AVAST Software\Avast\x64\vaarclient.dll
2017-11-03 02:00 - 2017-11-03 02:02 - 000851928 _____ () C:\Program Files\AVAST Software\Avast\x64\ffl2.dll
2017-11-03 01:44 - 2017-11-03 01:44 - 000286712 _____ () c:\Program Files\AVAST Software\Avast\x64\StreamBack.dll
2017-11-03 01:44 - 2017-11-03 01:44 - 000059040 _____ () C:\Program Files\AVAST Software\Avast\module_lifetime.dll
2017-11-03 01:44 - 2017-11-03 01:44 - 000167096 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
2017-11-03 01:44 - 2017-11-03 01:44 - 000217088 _____ () C:\Program Files\AVAST Software\Avast\event_routing_rpc.dll
2017-11-03 01:44 - 2017-11-03 01:44 - 000244584 _____ () C:\Program Files\AVAST Software\Avast\tasks_core.dll
2017-11-03 01:44 - 2017-11-03 01:44 - 000151104 _____ () C:\Program Files\AVAST Software\Avast\network_notifications.dll
2017-11-09 04:07 - 2017-11-09 04:07 - 005884088 _____ () C:\Program Files\AVAST Software\Avast\defs\17110802\algo.dll
2017-11-03 02:00 - 2017-11-03 02:02 - 000703336 _____ () C:\Program Files\AVAST Software\Avast\ffl2.dll
2017-11-03 01:44 - 2017-11-03 01:44 - 000241448 _____ () C:\Program Files\AVAST Software\Avast\streamback.dll
2017-11-09 14:26 - 2017-11-09 14:26 - 005884088 _____ () C:\Program Files\AVAST Software\Avast\defs\17110900\algo.dll
2017-11-10 05:20 - 2017-11-10 05:20 - 005883064 _____ () C:\Program Files\AVAST Software\Avast\defs\17110902\algo.dll
2017-11-03 01:44 - 2017-11-03 01:44 - 067109376 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2017-11-03 01:43 - 2017-11-03 01:43 - 000234280 _____ () C:\Program Files\AVAST Software\Avast\gaming_mode_ui.dll
2017-11-02 23:06 - 2017-11-01 14:58 - 000724288 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox_watchdog.dll
2017-11-02 23:06 - 2017-11-01 14:58 - 002002752 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox_crashpad.dll
2017-11-02 23:06 - 2017-11-01 14:57 - 000100296 _____ () C:\Program Files (x86)\Dropbox\Client\_ctypes.pyd
2017-11-02 23:06 - 2017-11-01 14:57 - 000018888 _____ () C:\Program Files (x86)\Dropbox\Client\select.pyd
2017-11-02 23:06 - 2017-11-01 15:01 - 000020800 _____ () C:\Program Files (x86)\Dropbox\Client\tornado.speedups.pyd
2017-11-02 23:06 - 2017-11-01 14:57 - 000035792 _____ () C:\Program Files (x86)\Dropbox\Client\_multiprocessing.pyd
2017-11-02 23:06 - 2017-11-01 14:57 - 000694224 _____ () C:\Program Files (x86)\Dropbox\Client\unicodedata.pyd
2017-11-02 23:06 - 2017-11-01 15:01 - 000021848 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._constant_time.pyd
2017-11-02 23:06 - 2017-11-01 14:57 - 000130512 _____ () C:\Program Files (x86)\Dropbox\Client\_cffi_backend.pyd
2017-11-02 23:06 - 2017-11-01 15:01 - 001856848 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._openssl.pyd
2017-11-02 23:06 - 2017-11-01 15:01 - 000022864 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._padding.pyd
2017-11-02 23:06 - 2017-11-01 14:57 - 000145864 _____ () C:\Program Files (x86)\Dropbox\Client\pyexpat.pyd
2017-11-02 23:06 - 2017-11-01 14:58 - 000116688 _____ () C:\Program Files (x86)\Dropbox\Client\pywintypes27.dll
2017-11-02 23:06 - 2017-11-01 14:57 - 000105928 _____ () C:\Program Files (x86)\Dropbox\Client\win32api.pyd
2017-11-02 23:06 - 2017-11-01 15:01 - 000022864 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.crt.compiled._winffi_crt.pyd
2017-11-02 23:06 - 2017-11-01 15:01 - 000062784 _____ () C:\Program Files (x86)\Dropbox\Client\psutil._psutil_windows.pyd
2017-11-02 23:06 - 2017-11-01 14:57 - 000024528 _____ () C:\Program Files (x86)\Dropbox\Client\win32event.pyd
2017-11-02 23:06 - 2017-11-01 15:01 - 000040248 _____ () C:\Program Files (x86)\Dropbox\Client\fastpath.pyd
2017-11-02 23:06 - 2017-11-01 14:57 - 000020936 _____ () C:\Program Files (x86)\Dropbox\Client\mmapfile.pyd
2017-11-02 23:06 - 2017-11-01 14:57 - 000124880 _____ () C:\Program Files (x86)\Dropbox\Client\win32file.pyd
2017-11-02 23:06 - 2017-11-01 14:57 - 000116176 _____ () C:\Program Files (x86)\Dropbox\Client\win32security.pyd
2017-11-02 23:06 - 2017-11-01 14:58 - 000392656 _____ () C:\Program Files (x86)\Dropbox\Client\pythoncom27.dll
2017-11-02 23:06 - 2017-11-01 15:01 - 000392512 _____ () C:\Program Files (x86)\Dropbox\Client\win32com.shell.shell.pyd
2017-11-02 23:06 - 2017-11-01 15:01 - 000026456 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.kernel32.compiled._winffi_kernel32.pyd
2017-11-02 23:06 - 2017-11-01 14:57 - 000024016 _____ () C:\Program Files (x86)\Dropbox\Client\win32clipboard.pyd
2017-11-02 23:06 - 2017-11-01 14:57 - 000175560 _____ () C:\Program Files (x86)\Dropbox\Client\win32gui.pyd
2017-11-02 23:06 - 2017-11-01 14:57 - 000030160 _____ () C:\Program Files (x86)\Dropbox\Client\win32pipe.pyd
2017-11-02 23:06 - 2017-11-01 14:57 - 000043472 _____ () C:\Program Files (x86)\Dropbox\Client\win32process.pyd
2017-11-02 23:06 - 2017-11-01 14:57 - 000026056 _____ () C:\Program Files (x86)\Dropbox\Client\win32job.pyd
2017-11-02 23:06 - 2017-11-01 14:57 - 000048592 _____ () C:\Program Files (x86)\Dropbox\Client\win32service.pyd
2017-11-02 23:06 - 2017-11-01 14:57 - 000057808 _____ () C:\Program Files (x86)\Dropbox\Client\win32evtlog.pyd
2017-11-02 23:06 - 2017-11-01 15:01 - 000021824 _____ () C:\Program Files (x86)\Dropbox\Client\cpuid.compiled._cpuid.pyd
2017-11-02 23:06 - 2017-11-01 15:01 - 000023368 _____ () C:\Program Files (x86)\Dropbox\Client\winshell.compiled._winshell.pyd
2017-11-02 23:06 - 2017-11-01 15:01 - 000022856 _____ () C:\Program Files (x86)\Dropbox\Client\crashpad.compiled._Crashpad.pyd
2017-11-02 23:06 - 2017-11-01 15:01 - 000066392 _____ () C:\Program Files (x86)\Dropbox\Client\winenumhandles.compiled._WinEnumHandles.pyd
2017-11-02 23:06 - 2017-11-01 15:01 - 001796920 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtCore.pyd
2017-11-02 23:06 - 2017-11-01 14:57 - 000084424 _____ () C:\Program Files (x86)\Dropbox\Client\sip.pyd
2017-11-02 23:06 - 2017-11-01 15:01 - 001956152 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtGui.pyd
2017-11-02 23:06 - 2017-11-01 15:01 - 003859264 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWidgets.pyd
2017-11-02 23:06 - 2017-11-01 15:01 - 000154440 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebEngineWidgets.pyd
2017-11-02 23:06 - 2017-11-01 15:01 - 000521024 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtNetwork.pyd
2017-11-02 23:06 - 2017-11-01 15:01 - 000050496 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebEngineCore.pyd
2017-11-02 23:06 - 2017-11-01 15:01 - 000042304 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebChannel.pyd
2017-11-02 23:06 - 2017-11-01 15:01 - 000131384 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebKit.pyd
2017-11-02 23:06 - 2017-11-01 15:01 - 000218944 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebKitWidgets.pyd
2017-11-02 23:06 - 2017-11-01 15:01 - 000204096 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtPrintSupport.pyd
2017-11-02 23:06 - 2017-11-01 15:01 - 000025432 _____ () C:\Program Files (x86)\Dropbox\Client\winscreenshot.compiled._CaptureScreenshot.pyd
2017-11-02 23:06 - 2017-11-01 14:57 - 000060880 _____ () C:\Program Files (x86)\Dropbox\Client\win32print.pyd
2017-11-02 23:06 - 2017-11-01 15:01 - 000054608 _____ () C:\Program Files (x86)\Dropbox\Client\winrpcserver.compiled._RPCServer.pyd
2017-11-02 23:06 - 2017-11-01 14:57 - 000024016 _____ () C:\Program Files (x86)\Dropbox\Client\win32profile.pyd
2017-11-02 23:06 - 2017-11-01 15:01 - 000022864 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.user32.compiled._winffi_user32.pyd
2017-11-02 23:06 - 2017-11-01 14:57 - 000028616 _____ () C:\Program Files (x86)\Dropbox\Client\win32ts.pyd
2017-11-02 23:06 - 2017-11-01 15:01 - 000022360 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.iphlpapi.compiled._winffi_iphlpapi.pyd
2017-11-02 23:06 - 2017-11-01 15:01 - 000021848 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.winerror.compiled._winffi_winerror.pyd
2017-11-02 23:06 - 2017-11-01 15:01 - 000022360 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.wininet.compiled._winffi_wininet.pyd
2017-11-02 23:06 - 2017-11-01 15:01 - 000027488 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox.infinite.win.compiled._driverinstallation.pyd
2017-11-02 23:06 - 2017-11-01 14:57 - 000349128 _____ () C:\Program Files (x86)\Dropbox\Client\winxpgui.pyd
2017-11-02 23:06 - 2017-11-01 15:01 - 000023896 _____ () C:\Program Files (x86)\Dropbox\Client\winverifysignature.compiled._VerifySignature.pyd
2017-11-02 23:06 - 2017-11-01 15:01 - 000025424 _____ () C:\Program Files (x86)\Dropbox\Client\librsyncffi.compiled._librsyncffi.pyd
2017-11-02 23:06 - 2017-11-01 14:58 - 000036296 _____ () C:\Program Files (x86)\Dropbox\Client\librsync.dll
2017-11-02 23:06 - 2017-11-01 15:01 - 000181056 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox_sqlite_ext.DLL
2017-11-02 23:06 - 2017-11-01 15:01 - 000030536 _____ () C:\Program Files (x86)\Dropbox\Client\wind3d11.compiled._wind3d11.pyd
2017-11-02 23:06 - 2017-11-01 15:01 - 000024368 _____ () C:\Program Files (x86)\Dropbox\Client\libEGL.DLL
2017-11-02 23:06 - 2017-11-01 15:01 - 001638200 _____ () C:\Program Files (x86)\Dropbox\Client\libGLESv2.dll
2017-11-02 23:06 - 2017-11-01 15:01 - 000026456 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.winhttp.compiled._winffi_winhttp.pyd
2017-11-02 23:06 - 2017-11-01 15:01 - 000545080 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtQuick.pyd
2017-11-02 23:06 - 2017-11-01 15:01 - 000359224 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtQml.pyd
2017-11-02 23:06 - 2017-11-01 15:01 - 000038208 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebEngine.pyd

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\Users\Personal\Desktop\Screenshot 2017-11-06 13.57.02.png:com.dropbox.attributes [168]

==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"

==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-14 05:34 - 2017-11-09 10:56 - 000000027 _____ C:\Windows\system32\Drivers\etc\hosts

127.0.0.1 localhost

==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-3766277524-2784970969-2751085713-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Personal\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.10.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

MSCONFIG\startupreg: GrooveMonitor => "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
MSCONFIG\startupreg: Skype => "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
MSCONFIG\startupreg: UCam_Menu => "C:\Program Files (x86)\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\YouCam" update "Software\CyberLink\YouCam\2.0"

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [SPPSVC-In-TCP] => (Allow) %SystemRoot%\system32\sppsvc.exe
FirewallRules: [SPPSVC-In-TCP-NoScope] => (Allow) %SystemRoot%\system32\sppsvc.exe
FirewallRules: [{26EBFE29-4801-4D1D-B607-5CC7F729C9F8}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{16298A24-C654-4450-8AAE-E2B5EBB4CD29}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{B76D13BA-193F-4DFF-9503-6E0773E27E20}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{52811C57-8711-450F-96B4-D0CD644BF8B2}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{AD4272E3-C3D4-4455-8AF0-250445969411}] => (Allow) C:\Program Files\Vuze\Azureus.exe
FirewallRules: [{D074B2E7-8D2D-45E0-8350-2A89D78735B1}] => (Allow) C:\Program Files\Vuze\Azureus.exe
FirewallRules: [{A4E632F6-D4A8-4233-A787-276A6C03218D}] => (Allow) C:\Program Files\qBittorrent\qbittorrent.exe
FirewallRules: [{3C2B13ED-B55A-43C8-87BA-FE0A14A618D9}] => (Allow) C:\Program Files\qBittorrent\qbittorrent.exe
FirewallRules: [{DB039F57-CCB9-4949-8525-FBD8B46C430C}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe
FirewallRules: [{684304AF-A9F0-40AA-A7FC-ECB47CC50876}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe
FirewallRules: [{5811275A-9EAD-4699-A046-D0DF414A0A6E}] => (Allow) C:\Users\Personal\AppData\Local\Microsoft\OneDrive\OneDrive.exe
FirewallRules: [{EF62CDB2-3263-43BD-B804-8D16BB94A2B3}] => (Allow) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe

==================== Restore Points =========================

02-11-2017 13:32:47 Windows Update
02-11-2017 13:50:45 Removed Microsoft Office Enterprise 2007
02-11-2017 14:05:28 Device Driver Package Install: TAP Provider V9 for Private Tunnel Network adapters
02-11-2017 19:48:43 Windows Modules Installer
09-11-2017 10:51:04 ComboFix created restore point

==================== Faulty Device Manager Devices =============

Name: Bluetooth Peripheral Device
Description: Bluetooth Peripheral Device
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.


==================== Event log errors: =========================

Application errors:
==================
Error: (11/10/2017 05:20:36 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 4107) (User: )
Description: Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.
.

Error: (11/10/2017 05:20:36 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 4107) (User: )
Description: Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.
.

Error: (11/10/2017 05:20:36 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 4107) (User: )
Description: Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.
.

Error: (11/10/2017 05:20:36 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 4107) (User: )
Description: Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.
.

Error: (11/10/2017 05:20:36 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 4107) (User: )
Description: Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.
.

Error: (11/10/2017 05:20:36 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 4107) (User: )
Description: Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.
.

Error: (11/10/2017 05:19:30 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 4107) (User: )
Description: Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.
.

Error: (11/10/2017 05:19:30 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 4107) (User: )
Description: Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.
.

Error: (11/10/2017 05:19:30 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 4107) (User: )
Description: Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.
.

Error: (11/10/2017 05:19:29 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 4107) (User: )
Description: Failed extract of third-party root list from auto update cab at: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab> with error: A required certificate is not within its validity period when verifying against the current system clock or the timestamp in the signed file.
.


System errors:
=============
Error: (11/09/2017 02:25:24 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: The server {995C996E-D918-4A8C-A302-45719A6F4EA7} did not register with DCOM within the required timeout.

Error: (11/09/2017 10:56:45 AM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: The PEVSystemStart service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.

Error: (11/09/2017 10:56:18 AM) (Source: Application Popup) (EventID: 1060) (User: )
Description: \??\C:\ComboFix\catchme.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.

Error: (11/09/2017 10:54:37 AM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: The PEVSystemStart service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.

Error: (11/09/2017 04:14:48 AM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: The following fatal alert was generated: 10. The internal error state is 10.

Error: (11/09/2017 04:03:20 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Spybot-S&D 2 Security Center Service service failed to start due to the following error:
Windows cannot verify the digital signature for this file. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Error: (11/08/2017 06:30:27 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Spybot-S&D 2 Security Center Service service failed to start due to the following error:
Windows cannot verify the digital signature for this file. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Error: (11/08/2017 06:29:15 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Windows Media Player Network Sharing Service service failed to start due to the following error:
The service did not start due to a logon failure.

Error: (11/08/2017 06:29:15 AM) (Source: Service Control Manager) (EventID: 7038) (User: )
Description: The WMPNetworkSvc service was unable to log on as NT AUTHORITY\NetworkService with the currently configured password due to the following error:
The request is not supported.


To ensure that the service is configured properly, use the Services snap-in in Microsoft Management Console (MMC).

Error: (11/08/2017 06:29:07 AM) (Source: DCOM) (EventID: 10010) (User: )
Description: The server {F9717507-6651-4EDB-BFF7-AE615179BCCF} did not register with DCOM within the required timeout.


CodeIntegrity:
===================================
Date: 2017-11-09 10:56:18.829
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2017-11-09 10:56:18.814
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Date: 2017-11-09 04:03:20.519
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe because the set of per-page image hashes could not be found on the system.

Date: 2017-11-08 06:30:27.002
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe because the set of per-page image hashes could not be found on the system.

Date: 2017-11-08 05:41:32.756
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe because the set of per-page image hashes could not be found on the system.

Date: 2017-11-07 12:29:42.387
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe because the set of per-page image hashes could not be found on the system.

Date: 2017-11-07 12:29:42.362
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe because the set of per-page image hashes could not be found on the system.

Date: 2017-11-07 12:29:42.337
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe because the set of per-page image hashes could not be found on the system.

Date: 2017-11-07 12:29:42.310
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe because the set of per-page image hashes could not be found on the system.

Date: 2017-11-07 11:05:59.307
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe because the set of per-page image hashes could not be found on the system.


==================== Memory info ===========================

Processor: Intel(R) Core(TM) i7-2670QM CPU @ 2.20GHz
Percentage of memory in use: 53%
Total physical RAM: 6091.86 MB
Available physical RAM: 2807.22 MB
Total Virtual: 12181.9 MB
Available Virtual: 8432.53 MB

==================== Drives ================================

Drive c: (OS) (Fixed) (Total:292.87 GB) (Free:253.55 GB) NTFS
Drive d: (DATA) (Fixed) (Total:638.54 GB) (Free:638.4 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 3C7E929E)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=292.9 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=638.5 GB) - (Type=07 NTFS)

==================== End of Addition.txt ============================
 
Download attached fixlist.txt file and save it to the Desktop.
NOTE. It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work.

NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

Run FRST(FRST64) and press the Fix button just once and wait.
The tool will make a log on the Desktop (Fixlog.txt). Please post it to your reply.
 

Attachments

  • fixlist.txt
    483 bytes · Views: 1
Fix result of Farbar Recovery Scan Tool (x64) Version: 02-11-2017
Ran by Personal (10-11-2017 06:04:56) Run:1
Running from C:\Users\Personal\Desktop
Loaded Profiles: Personal (Available Profiles: Personal)
Boot Mode: Normal
==============================================

fixlist content:
*****************
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
U1 aswbdisk; no ImagePath
U3 catchme; \??\C:\ComboFix\catchme.sys [X]
2017-11-06 20:45 - 2017-11-06 20:45 - 000048896 _____ () C:\ProgramData\agent.1509990317.bdinstall.bin
2017-11-08 04:54 - 2017-11-08 04:54 - 000030402 _____ () C:\ProgramData\agent.uninstall.1510106092.bdinstall.bin
AlternateDataStreams: C:\Users\Personal\Desktop\Screenshot 2017-11-06 13.57.02.png:com.dropbox.attributes [168]

*****************

HKLM\SOFTWARE\Policies\Microsoft\Windows Defender => key removed successfully
HKLM\System\CurrentControlSet\Services\aswbdisk => key could not remove, key could be protected
HKLM\System\CurrentControlSet\Services\catchme => key removed successfully
catchme => service removed successfully
C:\ProgramData\agent.1509990317.bdinstall.bin => moved successfully
C:\ProgramData\agent.uninstall.1510106092.bdinstall.bin => moved successfully
C:\Users\Personal\Desktop\Screenshot 2017-11-06 13.57.02.png => ":com.dropbox.attributes" ADS removed successfully.

Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 10-11-2017 06:07:16)


Result of scheduled keys to remove after reboot:

HKLM\System\CurrentControlSet\Services\aswbdisk => key could not remove, key could be protected

==== End of Fixlog 06:07:16 ====
 
Back