Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 08.11.2018
Ran by Tom (ATTENTION: The user is not administrator) on TOMDELL (10-11-2018 10:51:51)
Running from C:\Users\Tom\Downloads
Loaded Profiles: jl & Tom (Available Profiles: jl & Tom)
Platform: Windows 7 Professional Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
Failed to access process -> smss.exe
Failed to access process -> csrss.exe
Failed to access process -> wininit.exe
Failed to access process -> csrss.exe
Failed to access process -> services.exe
Failed to access process -> lsass.exe
Failed to access process -> lsm.exe
Failed to access process -> winlogon.exe
Failed to access process -> svchost.exe
Failed to access process -> svchost.exe
Failed to access process -> MsMpEng.exe
Failed to access process -> svchost.exe
Failed to access process -> svchost.exe
Failed to access process -> svchost.exe
Failed to access process -> svchost.exe
Failed to access process -> svchost.exe
Failed to access process -> RtkAudioService64.exe
Failed to access process -> RAVBg64.exe
Failed to access process -> RAVBg64.exe
Failed to access process -> svchost.exe
Failed to access process -> WLTRYSVC.EXE
Failed to access process -> BCMWLTRY.EXE
Failed to access process -> spoolsv.exe
Failed to access process -> svchost.exe
Failed to access process -> armsvc.exe
Failed to access process -> AERTSr64.exe
Failed to access process -> btwdins.exe
Failed to access process -> svchost.exe
Failed to access process -> ijplmsvc.exe
Failed to access process -> HeciServer.exe
Failed to access process -> svchost.exe
Failed to access process -> TeamViewer_Service.exe
Failed to access process -> svchost.exe
Failed to access process -> NisSrv.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Dell Inc.) C:\Program Files\Dell\DW WLAN Card\WLTRAY.EXE
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Dell Inc.) C:\Program Files\Dell\QuickSet\quickset.exe
Failed to access process -> WmiPrvSE.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(iMesh Inc) C:\Users\Tom\AppData\Local\Music Toolbar\Datamngr\sysctrl.exe
(iMesh Inc) C:\Users\Tom\AppData\Local\Music Toolbar\Datamngr\x64\sysctrl.exe
Failed to access process -> SearchIndexer.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(iMesh Inc) C:\Users\Tom\AppData\Local\Music Toolbar\Datamngr\DatamngrCoordinator.exe
() C:\Users\Tom\AppData\Local\WSE_Astromenda\BRS\brs.exe
(iMesh Inc) C:\Users\Tom\AppData\Local\Music Toolbar\Datamngr\DatamngrCoordinator.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(Creative Technology Ltd) C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe
(CANON INC.) C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Microsoft Corporation) C:\Windows\splwow64.exe
Failed to access process -> svchost.exe
(CANON INC.) C:\Program Files (x86)\Canon\Quick Menu\CNQMUPDT.EXE
(CANON INC.) C:\Program Files (x86)\Canon\Quick Menu\CNQMSWCS.EXE
Failed to access process -> IAStorDataMgrSvc.exe
Failed to access process -> Jhi_service.exe
Failed to access process -> LMS.exe
Failed to access process -> SftService.exe
Failed to access process -> wmpnetwk.exe
Failed to access process -> svchost.exe
Failed to access process -> SeaPort.EXE
(Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe
Failed to access process -> SteamService.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe
Failed to access process -> rundll32.exe
Failed to access process -> VSSVC.exe
Failed to access process -> svchost.exe
Failed to access process -> OSPPSVC.EXE
Failed to access process -> dllhost.exe
(Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil64_31_0_0_122_ActiveX.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe
Failed to access process -> svchost.exe
Failed to access process -> DbxSvc.exe
(Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
(Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
(Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Google) C:\Users\Tom\AppData\Local\Google\Google Talk Plugin\googletalkplugin.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AcroRd32.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AcroRd32.exe
Failed to access process -> wlanext.exe
Failed to access process -> conhost.exe
Failed to access process -> TrustedInstaller.exe
Failed to access process -> SearchProtocolHost.exe
Failed to access process -> SearchFilterHost.exe
Failed to access process -> svchost.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7202520 2013-08-20] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1321688 2013-08-08] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_PushButton] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1321688 2013-08-08] (Realtek Semiconductor)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2780400 2013-09-14] (Synaptics Incorporated)
HKLM\...\Run: [Broadcom Wireless Manager UI] => C:\Program Files\Dell\DW WLAN Card\WLTRAY.exe [8921600 2013-10-23] (Dell Inc.)
HKLM\...\Run: [QuickSet] => c:\Program Files\Dell\QuickSet\QuickSet.exe [5774664 2013-09-11] (Dell Inc.)
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [287592 2013-08-31] (Intel Corporation)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1353680 2016-11-14] (Microsoft Corporation)
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [292848 2013-09-05] (Intel Corporation)
HKLM-x32\...\Run: [Dell Webcam Central] => C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe [577024 2012-03-07] (Creative Technology Ltd)
HKLM-x32\...\Run: [CanonQuickMenu] => C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE [1279120 2012-09-27] (CANON INC.)
HKLM-x32\...\Run: [RazerCortex] => C:\Program Files (x86)\Razer\Razer Cortex\RazerCortex.exe -autorun
HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [3785536 2018-11-06] (Dropbox, Inc.)
HKLM-x32\...\RunOnce: [GrpConv] => grpconv -o
Winlogon\Notify\igfxcui: C:\Windows\System32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-252852572-1064671646-1800406956-1001\...\Run: [sysctrl] => C:\Users\Tom\AppData\Local\Music Toolbar\Datamngr\sysctrl.exe [70168 2014-06-25] (iMesh Inc)
HKU\S-1-5-21-252852572-1064671646-1800406956-1001\...\Run: [sysctrl64] => C:\Users\Tom\AppData\Local\Music Toolbar\Datamngr\x64\sysctrl.exe [82456 2014-06-25] (iMesh Inc)
HKU\S-1-5-21-252852572-1064671646-1800406956-1001\...\Run: [sysctrlc] => C:\Users\Tom\AppData\Local\Music Toolbar\Datamngr\DatamngrCoordinator.exe [3823128 2014-06-25] (iMesh Inc)
HKU\S-1-5-21-252852572-1064671646-1800406956-1001\...\Run: [BRS] => C:\Users\Tom\AppData\Local\WSE_Astromenda\BRS\brs.exe [1173504 2014-08-08] ()
HKU\S-1-5-21-252852572-1064671646-1800406956-1001\...\Run: [Google Update] => C:\Users\Tom\AppData\Local\Google\Update\1.3.33.17\GoogleUpdateCore.exe [601680 2018-05-19] (Google Inc.)
HKU\S-1-5-21-252852572-1064671646-1800406956-1001\...\Run: [GoogleChromeAutoLaunch_5189939A0645355218FFECE1F1491836] => C:\Users\Tom\AppData\Local\Chromium\Application\chrome.exe [663552 2015-06-28] (The Chromium Authors)
HKU\S-1-5-21-252852572-1064671646-1800406956-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3208992 2018-10-11] (Valve Corporation)
HKU\S-1-5-21-252852572-1064671646-1800406956-1001\...\Run: [World of Tanks] => "C:\Games\World_of_Tanks\WargamingGameUpdater.exe"
HKU\S-1-5-21-252852572-1064671646-1800406956-1001\...\Run: [KakaoTalk] => "C:\Program Files (x86)\Kakao\KakaoTalk\KakaoTalk.exe" -bystartup
HKU\S-1-5-18\...\RunOnce: [JavaInstallRetry] => RUNONCE=1 SPONSORS=0
Lsa: [Notification Packages] scecli c:\Program Files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Bluetooth.lnk [2014-03-14]
ShortcutTarget: Bluetooth.lnk -> C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Broadcom Corporation.)
GroupPolicy: Restriction - Chrome <==== ATTENTION
GroupPolicy\User: Restriction ? <==== ATTENTION
GroupPolicyUsers\S-1-5-21-252852572-1064671646-1800406956-1001\User: Restriction <==== ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.8.1 192.168.8.1
Tcpip\..\Interfaces\{D501FE14-C8C6-42EF-90C4-FD36AA6C8729}: [DhcpNameServer] 192.168.8.1 192.168.8.1
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617911&ResetID=131130558221447530&GUID=DBCFEA2E-669E-4FEF-ADAA-0257FE0762CC
HKU\S-1-5-21-252852572-1064671646-1800406956-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617911&ResetID=131802431285607286&GUID=DBCFEA2E-669E-4FEF-ADAA-0257FE0762CC
HKU\S-1-5-21-252852572-1064671646-1800406956-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://dell13.msn.com/?pc=DCJB
URLSearchHook: [S-1-5-21-252852572-1064671646-1800406956-1000] ATTENTION => Default URLSearchHook is missing
SearchScopes: HKLM -> DefaultScope {747A2953-1CA8-48AC-B80F-BB0DB9E62138} URL = hxxp://
www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM -> {747A2953-1CA8-48AC-B80F-BB0DB9E62138} URL = hxxp://
www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-252852572-1064671646-1800406956-1001 -> DefaultScope {747A2953-1CA8-48AC-B80F-BB0DB9E62138} URL = hxxp://
www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE
SearchScopes: HKU\S-1-5-21-252852572-1064671646-1800406956-1001 -> OldSearch URL = hxxp://searchinterneat-a.akamaihd.net/s?eq=U0EeE1xZE1oZB1ZEfQleBFpCGAYQbV0AAF9cFVcQchRaUVtBDA1BIVtcVFhFRVAQcB9aFQQTSEcFME0FCFwEURNNfWtdEkwdVUZrNVs=&q={searchTerms}
SearchScopes: HKU\S-1-5-21-252852572-1064671646-1800406956-1001 -> {1b31c9d2-7135-442b-bb93-7c002172adc6} URL = hxxp://
www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE
SearchScopes: HKU\S-1-5-21-252852572-1064671646-1800406956-1001 -> {295E555F-A5F0-42ED-917A-617F365F50E9} URL = hxxp://search.yahoo.com/yhs/search?hspart=ddc&hsimp=yhs-ddc_bd&type=bl-bir-dd__alt__ddc_dss_bd_com&p={searchTerms}
SearchScopes: HKU\S-1-5-21-252852572-1064671646-1800406956-1001 -> {2E00D31D-D171-423D-836D-1A4D7EA7F1A9} URL = hxxp://rocket-find.com/results.php?f=4&q={searchTerms}&a=rckt_frmr_14_26_ff&cd=2XzuyEtN2Y1L1Qzu0E0C0FyE0B0Bzz0DtB0FzyyByC0C0DtAtN0D0Tzu0SzytCtDtN1L2XzutBtFtBtCtFzztFtDtN1L1CzutCyEtBzytDyD1V1StN1L1G1B1V1N2Y1L1Qzu2SyB0Azz0E0F0E0C0DtGtCyDyEtBtG0B0AzzyBtGtDyC0E0DtGtDtA0EtDzz0AyByE0AyE0DyE2QtN1M1F1B2Z1V1N2Y1L1Qzu2StCyEzz0AyB0ByCtAtGzz0A0D0EtGyB0AtByCtG0A0B0FzytGtA0E0Azy0CtBtAzytA0EzzyE2Q&cr=1797486999&ir=
SearchScopes: HKU\S-1-5-21-252852572-1064671646-1800406956-1001 -> {747A2953-1CA8-48AC-B80F-BB0DB9E62138} URL = hxxp://
www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE
SearchScopes: HKU\S-1-5-21-252852572-1064671646-1800406956-1001 -> {77AA745B-F4F8-45DA-9B14-61D2D95054C8} URL = hxxp://rocket-find.com/results.php?f=4&q={searchTerms}&a=rckt_frmr_14_26_ff&cd=2XzuyEtN2Y1L1Qzu0E0C0FyE0B0Bzz0DtB0FzyyByC0C0DtAtN0D0Tzu0SzytCtDtN1L2XzutBtFtBtCtFtCtCtFtDtN1L1CzutCyEtBzytDyD1V1TtN1L1G1B1V1N2Y1L1Qzu2StD0BtA0AyD0CtDyEtG0AyByBtAtGzzyD0B0CtGyCtC0E0FtGtC0BtAtD0F0ByE0A0E0F0ByD2QtN1M1F1B2Z1V1N2Y1L1Qzu2StCyEzz0AyB0ByCtAtGzz0A0D0EtGyB0AtByCtG0A0B0FzytGtA0E0Azy0CtBtAzytA0EzzyE2Q&cr=1712688768&ir=
SearchScopes: HKU\S-1-5-21-252852572-1064671646-1800406956-1001 -> {80c554b9-c7f8-4a21-9471-06d606da78a2} URL = hxxp://
www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE
SearchScopes: HKU\S-1-5-21-252852572-1064671646-1800406956-1001 -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2000} URL = hxxp://dts.search.ask.com/sr?src=ieb&gct=ds&appid=&systemid=&v=a15946-1205&apn_uid=4431050210474885&apn_dtid=IME001&o=APN10653&apn_ptnrs=AGE&q={searchTerms}
SearchScopes: HKU\S-1-5-21-252852572-1064671646-1800406956-1001 -> {9BB47C17-9C68-4BB3-B188-DD9AF0FD2001} URL = hxxp://dts.search.ask.com/sr?src=ieb&gct=ds&appid=1066&systemid=1&v=n13124-409&apn_uid=9434405932554208&apn_dtid=IME001&o=APN10653&apn_ptnrs=AGE&q={searchTerms}
SearchScopes: HKU\S-1-5-21-252852572-1064671646-1800406956-1001 -> {a62abdee-78a2-4ddb-9355-1c334abd6e43} URL = hxxp://searchinterneat-a.akamaihd.net/s?eq=U0EeE1xZE1oZB1ZEfQleBFpCGAYQbV0AAF9cFVcQchRaUVtBDA1BIVtcVFhFRVAQcB9aFQQTSEcFME0FCFwEURNNfWtdEkwdVUZrNVs=&q={searchTerms}
SearchScopes: HKU\S-1-5-21-252852572-1064671646-1800406956-1001 -> {f7bb050c-e116-44da-89c2-6f2b68c54836} URL = hxxp://
www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE
BHO: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll [2014-07-07] (CANON INC.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll [2014-07-07] (CANON INC.)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2014-08-11] (Oracle Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Bing Bar Helper -> {d2ce3e00-f94a-4740-988e-03dc2f38c34f} -> C:\Program Files (x86)\Microsoft\BingBar\7.1.362.0\BingExt.dll [2012-02-13] (Microsoft Corporation.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2014-08-11] (Oracle Corporation)
Toolbar: HKLM - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2014-07-07] (CANON INC.)
Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll [2014-07-07] (CANON INC.)
Toolbar: HKLM-x32 - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\7.1.362.0\BingExt.dll [2012-02-13] (Microsoft Corporation.)
Toolbar: HKU\S-1-5-21-252852572-1064671646-1800406956-1001 -> Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2014-07-07] (CANON INC.)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - No File
FireFox:
========
FF ProfilePath: C:\Users\Tom\AppData\Roaming\Mozilla\Firefox\Profiles\6mnczrhu.default-1509552401858 [2018-11-10]
FF Homepage: Mozilla\Firefox\Profiles\6mnczrhu.default-1509552401858 -> hxxps://id.search.yahoo.com/yhs/web?hspart=elm&hsimp=yhs-001&type=hdr_s_17_44_orgnl¶m1=1¶m2=f%3D1%26b%3DFirefox%26cc%3Did%26pa%3Dhodor%26cd%3D2XzuyEtN2Y1L1Qzu0E0C0FyE0B0Bzz0DtB0FzyyByC0C0DtAtN0D0Tzu0StBtCtAyEtN1L2XzutAtFtAtBtFtCtFyCyDtN1L1Czu1M1Q1CtAtBtFtAtFtDtN1L1G1B1V1N2Y1L1Qzu2StB0BtC0EtD0F0EtAtGyB0AtC0CtG0CtAtByEtGyCzy0AtBtGtC0ByCzzyEzyzyyE0A0DtD0C2QtN1M1F1B2Z1V1N2Y1L1Qzu2S0E0D0F0A0FtA0CzytGzy0EyDyCtGyE0CyDyEtGzztCtDtDtGyEzytC0DtCtD0E0FyByBtAyE2QtN0A0LzuyEtN0D0T0S1P1RzutCyDtDzyzzyEtDtBtCyB%26cr%3D1609883092%26a%3Dhdr_s_17_44_orgnl%26os_ver%3D6.1%26os%3DWindows%2B7%2BProfessional
FF SearchPlugin: C:\Users\Tom\AppData\Roaming\Mozilla\Firefox\Profiles\6mnczrhu.default-1509552401858\searchplugins\yhs.xml [2018-01-25]
FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK => not found
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_31_0_0_122.dll [2018-10-10] ()
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_31_0_0_122.dll [2018-10-10] ()
FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files (x86)\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll [2011-11-30] (CANON INC.)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=3.5.29 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-06-01] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-06-01] (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll [2014-08-11] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.67.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll [2014-08-11] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @videolan.org/vlc,version=2.2.8 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-11-29] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2017-11-01] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-252852572-1064671646-1800406956-1001: @talk.google.com/GoogleTalkPlugin -> C:\Users\Tom\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll [2015-12-08] (Google)
FF Plugin HKU\S-1-5-21-252852572-1064671646-1800406956-1001: @talk.google.com/O1DPlugin -> C:\Users\Tom\AppData\Roaming\Mozilla\plugins\npo1d.dll [2015-12-08] (Google)
FF Plugin HKU\S-1-5-21-252852572-1064671646-1800406956-1001: @tools.google.com/Google Update;version=3 -> C:\Users\Tom\AppData\Local\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-05-19] (Google Inc.)
FF Plugin HKU\S-1-5-21-252852572-1064671646-1800406956-1001: @tools.google.com/Google Update;version=9 -> C:\Users\Tom\AppData\Local\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-05-19] (Google Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\Tom\AppData\Roaming\mozilla\plugins\npgoogletalk.dll [2015-12-08] (Google)
FF Plugin ProgramFiles/Appdata: C:\Users\Tom\AppData\Roaming\mozilla\plugins\npo1d.dll [2015-12-08] (Google)
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2018-11-09] (Dropbox, Inc.)
S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2018-11-09] (Dropbox, Inc.)
R2 DbxSvc; C:\Windows\system32\DbxSvc.exe [51024 2018-11-06] (Dropbox, Inc.)
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15720 2013-08-31] (Intel Corporation)
R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [140936 2013-05-15] ()
R2 Intel(R) Capability Licensing Service Interface; c:\Program Files\Intel\iCLS Client\HeciServer.exe [733696 2013-05-12] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; c:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [822232 2013-05-12] (Intel(R) Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-06-01] (Intel Corporation)
R2 lmhosts; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R2 lmhosts; C:\Windows\SysWOW64\svchost.exe [20992 2009-07-14] (Microsoft Corporation)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [119864 2016-11-14] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [361816 2016-11-14] (Microsoft Corporation)
R2 NlaSvc; C:\Windows\System32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R2 NlaSvc; C:\Windows\SysWOW64\svchost.exe [20992 2009-07-14] (Microsoft Corporation)
R2 nsi; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
R2 nsi; C:\Windows\SysWOW64\svchost.exe [20992 2009-07-14] (Microsoft Corporation)
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [246488 2013-06-19] (Realtek Semiconductor)
R2 SftService; C:\Program Files (x86)\Dell Backup and Recovery\SftService.exe [1915920 2013-11-22] (SoftThinks SAS)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2014-03-14] (Microsoft Corporation)
R2 wltrysvc; C:\Program Files\Dell\DW WLAN Card\bcmwltry.exe [6170624 2013-10-23] (Dell Inc.) [File not signed]
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R0 iaStorF; C:\Windows\System32\drivers\iaStorF.sys [28008 2013-08-29] (Intel Corporation)
R3 MEIx64; C:\Windows\System32\DRIVERS\TeeDriverx64.sys [99288 2013-12-19] (Intel Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [295000 2016-08-25] (Microsoft Corporation)
R3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [135928 2016-08-25] (Microsoft Corporation)
S3 PCDSRVC{D3412D80-CF3B4A27-06020200}_0; c:\program files\my dell\pcdsrvc_x64.pkms [25584 2013-08-10] (PC-Doctor, Inc.)
S3 SmbDrv; C:\Windows\system32\drivers\Smb_driver_AMDASF.sys [30448 2013-09-14] (Synaptics Incorporated)
R3 SmbDrvI; C:\Windows\System32\DRIVERS\Smb_driver_Intel.sys [34544 2013-09-14] (Synaptics Incorporated)
S1 mmaennbv; \??\C:\Windows\system32\drivers\mmaennbv.sys [X]
S1 MpKsl9b5e44a7; \??\c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{06717DA4-6C54-415D-AA4E-217CE011D206}\MpKsl9b5e44a7.sys [X]
S1 niatpxbo; \??\C:\Windows\system32\drivers\niatpxbo.sys [X]
S3 OATool; \??\C:\Users\ADMINI~1\AppData\Local\Temp\OAToolx64.sys [X] <==== ATTENTION
S1 spaltjok; \??\C:\Windows\system32\drivers\spaltjok.sys [X]
S1 szftsrbn; \??\C:\Windows\system32\drivers\szftsrbn.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
Error(1) reading file: "C:\Users\Tom\Downloads\Titanfall Rap by JT Machinima, THK and Borderline Disaster - "
2018-11-10 10:51 - 2018-11-10 10:54 - 000025461 _____ C:\Users\Tom\Downloads\FRST.txt
2018-11-10 10:47 - 2018-11-10 10:47 - 000000000 ____D C:\Users\Tom\Downloads\FRST-OlderVersion
2018-11-10 10:46 - 2018-11-10 10:51 - 000000000 ____D C:\FRST
2018-11-10 10:45 - 2018-11-10 10:51 - 002415616 _____ (Farbar) C:\Users\Tom\Downloads\FRST64.exe
2018-11-09 18:08 - 2018-11-09 18:08 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox
2018-11-09 18:05 - 2018-11-09 18:05 - 000000000 ____D C:\Users\jl\AppData\Roaming\Dropbox
2018-11-09 18:03 - 2018-11-10 10:08 - 000000900 _____ C:\Windows\Tasks\DropboxUpdateTaskMachineUA.job
2018-11-09 18:03 - 2018-11-09 18:08 - 000000896 _____ C:\Windows\Tasks\DropboxUpdateTaskMachineCore.job
2018-11-09 18:02 - 2018-11-09 18:09 - 000000000 ____D C:\Program Files (x86)\Dropbox
2018-11-09 17:44 - 2018-11-09 18:14 - 000000000 ____D C:\Users\Tom\AppData\Local\Dropbox
2018-11-09 17:44 - 2018-11-09 18:02 - 000696608 _____ (Dropbox, Inc.) C:\Users\Tom\Downloads\DropboxInstaller.exe
2018-11-09 17:44 - 2018-11-09 17:44 - 000000000 ____D C:\ProgramData\Dropbox
2018-11-06 20:06 - 2018-11-06 20:06 - 000051024 _____ (Dropbox, Inc.) C:\Windows\system32\DbxSvc.exe
2018-11-06 20:06 - 2018-11-06 20:06 - 000047768 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-dev.sys
2018-11-06 20:06 - 2018-11-06 20:06 - 000047768 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-canary.sys
2018-11-06 20:06 - 2018-11-06 20:06 - 000045640 _____ (Dropbox, Inc.) C:\Windows\system32\Drivers\dbx-stable.sys
2018-10-12 11:49 - 2018-10-12 11:49 - 000000020 _____ C:\Users\Tom\Desktop\SOUL.txt
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2018-11-10 10:42 - 2017-11-05 07:06 - 000000266 _____ C:\Windows\Tasks\{58F8473A-A6D6-EB55-AF4D-772F0358E8D9}.job
2018-11-10 10:42 - 2015-09-04 18:04 - 000000000 ____D C:\Users\Tom\AppData\Local\{357E0322-11D6-6F9A-7C4E-4A725826B6EA}
2018-11-10 10:24 - 2016-07-14 00:03 - 000000266 _____ C:\Windows\Tasks\{1B7B29A5-081A-DBB0-79E4-101AD15B16AA}.job
2018-11-10 09:03 - 2016-09-18 09:25 - 000000266 _____ C:\Windows\Tasks\{4B63B3D9-A905-B81E-883E-3B544CC01479}.job
2018-11-10 09:03 - 2016-03-29 20:03 - 000000262 _____ C:\Windows\Tasks\Update_Task.job
2018-11-10 07:46 - 2009-07-14 10:20 - 000000000 ____D C:\Windows\system32\NDF
2018-11-10 05:26 - 2016-11-19 05:51 - 000000000 ____D C:\Users\Tom\AppData\LocalLow\Mozilla
2018-11-10 05:26 - 2014-07-15 19:08 - 000000000 ____D C:\ProgramData\Datamngr
2018-11-10 05:11 - 2018-01-25 06:40 - 000000000 ____D C:\Users\Tom\AppData\Local\Direc
2018-11-09 19:42 - 2014-04-16 10:12 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2018-11-09 19:41 - 2017-12-04 05:08 - 000000000 ____D C:\Program Files (x86)\Mozilla Firefox
2018-11-09 19:39 - 2014-05-20 17:23 - 000000000 ____D C:\Users\Tom\AppData\Local\Unity
2018-11-09 19:37 - 2014-06-29 10:30 - 000000000 ____D C:\Users\Tom\AppData\Local\Rocket
2018-11-09 17:39 - 2017-04-16 16:55 - 000000000 ____D C:\Users\Tom\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2018-11-09 15:10 - 2009-07-14 11:45 - 000030704 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2018-11-09 15:10 - 2009-07-14 11:45 - 000030704 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2018-10-16 04:48 - 2010-11-21 10:27 - 000559880 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2018-10-12 16:33 - 2016-11-06 21:35 - 000000000 ____D C:\Users\Tom\AppData\Local\CrossCode
2018-10-12 14:24 - 2017-04-16 12:44 - 000000000 ____D C:\Program Files (x86)\Steam
2018-10-12 07:20 - 2014-03-14 09:25 - 000000000 ____D C:\Program Files (x86)\Dell Backup and Recovery
2018-10-12 07:17 - 2009-07-14 12:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2018-10-11 18:50 - 2009-07-14 10:20 - 000000000 ____D C:\Windows\rescache
2018-10-11 08:43 - 2014-04-16 06:09 - 000000000 ____D C:\Users\jl
2018-10-11 03:51 - 2009-07-14 12:13 - 000783606 _____ C:\Windows\system32\PerfStringBackup.INI
2018-10-11 03:51 - 2009-07-14 10:20 - 000000000 ____D C:\Windows\inf
2018-10-11 03:44 - 2009-07-14 11:45 - 000342728 _____ C:\Windows\system32\FNTCACHE.DAT
2018-10-11 03:19 - 2014-04-16 06:42 - 000000000 ____D C:\Windows\system32\MRT
2018-10-11 03:13 - 2014-04-16 06:42 - 136745976 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2018-10-11 03:08 - 2011-02-10 21:33 - 000767916 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
==================== Files in the root of some directories =======
2015-03-12 19:07 - 2015-01-11 19:07 - 000000032 ____R () C:\ProgramData\hash.dat
2016-10-21 18:39 - 2016-10-21 18:39 - 003187734 _____ () C:\Users\Tom\AppData\Roaming\sb195.dat
2016-12-13 08:55 - 2016-12-13 08:55 - 003634196 _____ () C:\Users\Tom\AppData\Roaming\sb476.dat
2014-07-31 08:47 - 2018-09-09 18:42 - 000000503 _____ () C:\Users\Tom\AppData\Roaming\WB.CFG
2014-12-02 06:39 - 2014-12-18 00:39 - 000000001 _____ () C:\Users\Tom\AppData\Local\DSI.DAT
2014-12-02 06:39 - 2014-12-02 06:39 - 000022528 _____ () C:\Users\Tom\AppData\Local\dsisetup1488231282.exe
2014-12-18 00:39 - 2014-12-18 00:39 - 000022528 _____ () C:\Users\Tom\AppData\Local\dsisetup3359250182.exe
2018-03-25 21:59 - 2018-03-25 21:59 - 000040960 _____ () C:\Users\Tom\AppData\Local\Web Data
2018-03-25 21:59 - 2018-03-25 21:59 - 000000512 _____ () C:\Users\Tom\AppData\Local\Web Data-journal
2017-12-13 02:46 - 2018-01-09 03:11 - 000000068 _____ () C:\Users\Tom\AppData\Local\xdt9m2fvbr
Files to move or delete:
====================
C:\Windows\Tasks\{1B7B29A5-081A-DBB0-79E4-101AD15B16AA}.job
C:\Windows\Tasks\{4B63B3D9-A905-B81E-883E-3B544CC01479}.job
C:\Windows\Tasks\{58F8473A-A6D6-EB55-AF4D-772F0358E8D9}.job
Some files in TEMP:
====================
2014-05-22 08:55 - 2014-05-22 08:55 - 002936832 _____ () C:\Users\Tom\AppData\Local\Temp\ffmpeg16.exe
2014-05-29 13:56 - 2014-05-29 13:57 - 017938608 _____ (Adobe Systems Incorporated) C:\Users\Tom\AppData\Local\Temp\fp_pl_pfs_installer-1.exe
2014-05-24 11:53 - 2014-05-24 11:54 - 017938608 _____ (Adobe Systems Incorporated) C:\Users\Tom\AppData\Local\Temp\fp_pl_pfs_installer.exe
2016-05-16 18:00 - 2016-05-16 18:01 - 000000000 _____ () C:\Users\Tom\AppData\Local\Temp\GUR280F.exe
2015-01-23 19:03 - 2015-01-21 06:32 - 002124520 _____ () C:\Users\Tom\AppData\Local\Temp\Helper.DLL
2015-03-12 19:08 - 2015-03-12 19:08 - 000058368 ____N () C:\Users\Tom\AppData\Local\Temp\jshortcut-3012483557483484761.dll
2015-03-12 19:40 - 2015-03-12 19:40 - 000058368 ____N () C:\Users\Tom\AppData\Local\Temp\jshortcut-7151043099465511510.dll
2013-06-18 23:53 - 2013-06-18 23:53 - 000865424 ____N (CANON INC.) C:\Users\Tom\AppData\Local\Temp\MSETUP4.EXE
2015-04-11 19:04 - 2015-03-23 07:33 - 001792744 _____ () C:\Users\Tom\AppData\Local\Temp\MusicAppHelper.DLL
2018-03-10 20:08 - 2018-03-10 20:08 - 001857024 _____ (Opera Software) C:\Users\Tom\AppData\Local\Temp\Opera_installer_180310130822301.dll
2018-03-10 20:08 - 2018-03-10 20:08 - 001857024 _____ (Opera Software) C:\Users\Tom\AppData\Local\Temp\Opera_installer_180310130823619.dll
2018-03-10 20:08 - 2018-03-10 20:08 - 001857024 _____ (Opera Software) C:\Users\Tom\AppData\Local\Temp\Opera_installer_180310130824152.dll
2018-03-10 20:08 - 2018-03-10 20:08 - 001857024 _____ (Opera Software) C:\Users\Tom\AppData\Local\Temp\Opera_installer_180310130824917.dll
2018-03-10 20:08 - 2018-03-10 20:08 - 001857024 _____ (Opera Software) C:\Users\Tom\AppData\Local\Temp\Opera_installer_180310130832216.dll
2018-03-10 20:08 - 2018-03-10 20:08 - 001857024 _____ (Opera Software) C:\Users\Tom\AppData\Local\Temp\Opera_installer_180310130835050.dll
2018-03-10 20:08 - 2018-03-10 20:08 - 001857024 _____ (Opera Software) C:\Users\Tom\AppData\Local\Temp\Opera_installer_180310130851423.dll
2018-03-11 20:09 - 2018-03-11 20:09 - 001857024 _____ (Opera Software) C:\Users\Tom\AppData\Local\Temp\Opera_installer_180311130926198.dll
2018-03-14 07:14 - 2018-03-14 07:14 - 001857024 _____ (Opera Software) C:\Users\Tom\AppData\Local\Temp\Opera_installer_180314001435848.dll
2018-03-15 10:15 - 2018-03-15 10:15 - 001857024 _____ (Opera Software) C:\Users\Tom\AppData\Local\Temp\Opera_installer_180315031541953.dll
2018-03-15 13:17 - 2018-03-15 13:17 - 001857024 _____ (Opera Software) C:\Users\Tom\AppData\Local\Temp\Opera_installer_180315061702218.dll
2018-03-15 20:32 - 2018-03-15 20:32 - 001857024 _____ (Opera Software) C:\Users\Tom\AppData\Local\Temp\Opera_installer_180315133218571.dll
2018-03-16 20:24 - 2018-03-16 20:24 - 001857024 _____ (Opera Software) C:\Users\Tom\AppData\Local\Temp\Opera_installer_180316132440582.dll
2018-03-18 07:44 - 2018-03-18 07:44 - 001857024 _____ (Opera Software) C:\Users\Tom\AppData\Local\Temp\Opera_installer_180318004447094.dll
2018-03-18 20:09 - 2018-03-18 20:09 - 001857024 _____ (Opera Software) C:\Users\Tom\AppData\Local\Temp\Opera_installer_180318130924025.dll
2018-03-21 07:16 - 2018-03-21 07:16 - 001857024 _____ (Opera Software) C:\Users\Tom\AppData\Local\Temp\Opera_installer_180321001604795.dll
2018-03-21 20:09 - 2018-03-21 20:09 - 001857024 _____ (Opera Software) C:\Users\Tom\AppData\Local\Temp\Opera_installer_180321130925214.dll
2018-03-22 20:09 - 2018-03-22 20:09 - 001857024 _____ (Opera Software) C:\Users\Tom\AppData\Local\Temp\Opera_installer_180322130924714.dll
2018-03-23 20:09 - 2018-03-23 20:09 - 001857024 _____ (Opera Software) C:\Users\Tom\AppData\Local\Temp\Opera_installer_180323130924452.dll
2018-03-24 06:42 - 2018-03-24 06:42 - 001857024 _____ (Opera Software) C:\Users\Tom\AppData\Local\Temp\Opera_installer_180323234211738.dll
2018-03-24 20:09 - 2018-03-24 20:09 - 001857024 _____ (Opera Software)