AZNative
Posts: 56 +0
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-08-25 13:05 - 2017-08-25 13:06 - 255308582 _____ C:\Users\AIRWORX 2\Documents\Book1.xlsx
2017-08-25 12:37 - 2017-08-25 12:37 - 010485794 _____ C:\Users\AIRWORX 2\Documents\txtunicode.txt
2017-08-25 12:37 - 2017-08-25 12:37 - 005242896 _____ C:\Users\AIRWORX 2\Documents\txtansi.txt
2017-08-25 12:36 - 2017-08-25 12:36 - 005731140 _____ C:\Users\AIRWORX 2\Documents\txt.txt
2017-08-25 12:00 - 2017-08-25 12:00 - 000044221 _____ C:\Users\AIRWORX 2\Downloads\08.15.17Bradford Ltr (Certified).pdf
2017-08-25 11:50 - 2017-08-25 11:50 - 000874058 _____ C:\Users\AIRWORX 2\Downloads\Cosmic Jump Employee Manual No Jumping 1-30-14.pdf
2017-08-25 11:49 - 2017-08-25 11:49 - 000836044 _____ C:\Users\AIRWORX 2\Downloads\Cosmic Jump Employee Manual No Jumping.pdf
2017-08-25 10:58 - 2017-08-25 10:58 - 005731140 _____ C:\Users\AIRWORX 2\Documents\utf-8 format.txt
2017-08-25 09:59 - 2017-08-25 10:00 - 000364544 _____ C:\Users\AIRWORX 2\Documents\Database4.accdb
2017-08-25 02:33 - 2017-08-25 02:33 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DB Browser for SQLite
2017-08-24 18:28 - 2017-08-24 18:28 - 000069632 _____ C:\Users\AIRWORX 2\Documents\dev.evtx
2017-08-24 18:26 - 2017-08-24 18:26 - 000069632 _____ C:\Users\AIRWORX 2\Documents\device events.evtx
2017-08-24 09:55 - 2017-08-24 09:55 - 016119416 _____ C:\Users\AIRWORX 2\Downloads\DB.Browser.for.SQLite-3.10.0-beta2-win64.exe
2017-08-24 09:46 - 2017-08-24 09:57 - 000352256 _____ C:\Users\AIRWORX 2\Documents\Database3.accdb
2017-08-24 08:33 - 2017-08-24 08:37 - 000352256 _____ C:\Users\AIRWORX 2\Documents\Database2.accdb
2017-08-24 08:26 - 2017-08-26 12:25 - 000000372 _____ C:\WINDOWS\Tasks\HPCeeScheduleForAIRWORX 2.job
2017-08-24 08:25 - 2017-08-24 08:25 - 005718872 _____ (Microsoft Corporation) C:\Users\AIRWORX 2\Downloads\vcredist_x64.exe
2017-08-24 07:41 - 2017-08-24 07:42 - 399261754 _____ C:\Users\AIRWORX 2\Downloads\mysql-5.7.19-winx64-debug-test.zip
2017-08-24 07:38 - 2017-08-24 07:38 - 008527872 _____ C:\Users\AIRWORX 2\Downloads\mysql-connector-odbc-5.3.9-winx64.msi
2017-08-24 07:33 - 2017-08-24 07:33 - 000000155 _____ C:\WINDOWS\system32\report.txt
2017-08-24 07:29 - 2017-08-24 07:34 - 000000289 _____ C:\WINDOWS\ODBC.INI
2017-08-24 04:32 - 2017-08-24 07:21 - 000352256 _____ C:\Users\AIRWORX 2\Documents\Database1.accdb
2017-08-24 02:07 - 2017-08-26 13:15 - 000004693 _____ C:\Users\AIRWORX 2\Desktop\Fixlog.txt
2017-08-23 07:56 - 2017-08-23 07:56 - 000001046 _____ C:\Users\Public\Desktop\EPSON Scan.lnk
2017-08-23 07:56 - 2012-07-24 00:00 - 000470528 _____ (Seiko Epson Corporation) C:\WINDOWS\system32\esxw2_86.dll
2017-08-23 07:56 - 2011-12-12 00:00 - 000135824 _____ (Seiko Epson Corporation) C:\WINDOWS\system32\escsvc64.exe
2017-08-23 07:49 - 2017-08-23 07:49 - 005957560 _____ C:\Users\AIRWORX 2\Desktop\epson19043.exe
2017-08-23 07:30 - 2017-08-23 07:30 - 000120690 _____ C:\Users\AIRWORX 2\Downloads\combined.pdf
2017-08-23 07:28 - 2017-08-23 07:28 - 000123377 _____ C:\Users\AIRWORX 2\Desktop\alldocs.pdf
2017-08-23 06:57 - 2017-08-23 06:57 - 001240712 _____ C:\Users\AIRWORX 2\Desktop\this is ms.txt
2017-08-23 06:56 - 2017-08-23 06:56 - 001240712 _____ C:\Users\AIRWORX 2\Desktop\this is msi log.txt
2017-08-23 06:55 - 2017-08-23 06:55 - 001240712 _____ C:\Users\AIRWORX 2\Desktop\MSI6857e.txt
2017-08-23 06:51 - 2017-08-23 06:51 - 000036289 _____ C:\Users\AIRWORX 2\Desktop\setupact1.txt
2017-08-23 06:47 - 2017-08-23 06:47 - 000187717 _____ C:\Users\AIRWORX 2\Desktop\WidnowsUpdateLog 8-15-17.txt
2017-08-23 06:13 - 2017-08-23 06:13 - 000108484 _____ C:\Users\AIRWORX 2\Desktop\balance of 90 day created files.txt
2017-08-23 05:22 - 2017-08-23 05:22 - 000017880 _____ C:\Users\AIRWORX 2\Desktop\app crash viewer reports.txt
2017-08-23 04:31 - 2017-08-23 04:31 - 000345927 _____ C:\Users\AIRWORX 2\Desktop\eset 12 found 11 corrected.txt
2017-08-23 04:30 - 2017-08-23 04:30 - 000203442 _____ C:\Users\AIRWORX 2\Desktop\6-28-17 eset all.txt
2017-08-23 04:28 - 2017-08-23 04:28 - 000511683 _____ C:\Users\AIRWORX 2\Desktop\eset 42 found.txt
2017-08-23 04:22 - 2017-08-23 04:22 - 000486514 _____ C:\Users\AIRWORX 2\Desktop\1 found eset.txt
2017-08-23 04:20 - 2017-08-23 04:20 - 000012117 _____ C:\Users\AIRWORX 2\Desktop\eset detected threats.txt
2017-08-23 04:17 - 2017-08-23 04:17 - 000000099 _____ C:\Users\AIRWORX 2\Desktop\eset last complete scan.txt
2017-08-23 04:13 - 2017-08-23 04:13 - 000000152 _____ C:\Users\AIRWORX 2\Desktop\6-28-17 eset.txt
2017-08-23 04:08 - 2017-08-23 04:08 - 000012117 _____ C:\Users\AIRWORX 2\Desktop\eset threats.txt
2017-08-22 20:17 - 2017-08-22 20:17 - 000072689 _____ C:\Users\AIRWORX 2\Downloads\02234217-WebDetail.pdf
2017-08-22 19:57 - 2017-08-22 19:57 - 000010810 _____ C:\Users\AIRWORX 2\Desktop\Brandi-Copas.pdfresume.pdf
2017-08-22 19:35 - 2017-08-22 19:36 - 297077664 _____ C:\Users\AIRWORX 2\Documents\regedits.REG
2017-08-21 15:38 - 2017-08-21 15:38 - 000092808 _____ C:\Users\AIRWORX 2\Downloads\Instructions-for-Completing-an-Affidavit-of-Affixture.pdf
2017-08-21 15:38 - 2017-08-21 15:38 - 000092808 _____ C:\Users\AIRWORX 2\Downloads\Instructions-for-Completing-an-Affidavit-of-Affixture (2).pdf
2017-08-21 15:38 - 2017-08-21 15:38 - 000092808 _____ C:\Users\AIRWORX 2\Downloads\Instructions-for-Completing-an-Affidavit-of-Affixture (1).pdf
2017-08-21 13:48 - 2017-08-21 13:53 - 000002324 _____ C:\Users\AIRWORX 2\Desktop\page 2.html
2017-08-21 13:35 - 2017-08-21 13:39 - 000098816 _____ C:\Users\AIRWORX 2\Documents\Publication1.pub
2017-08-21 12:59 - 2017-08-21 13:40 - 000024476 _____ C:\Users\AIRWORX 2\Documents\Publication1.htm
2017-08-21 12:59 - 2017-08-21 13:40 - 000000000 ____D C:\Users\AIRWORX 2\Documents\Publication1_files
2017-08-21 08:15 - 2017-08-21 08:15 - 000010221 _____ C:\Users\AIRWORX 2\Documents\booking list allen.xlsx
2017-08-21 07:27 - 2017-08-21 07:27 - 000006863 _____ C:\Users\AIRWORX 2\Desktop\sam's invoice 8-18-2017.pdf
2017-08-19 13:30 - 2017-08-19 13:33 - 000155362 _____ C:\Users\AIRWORX 2\Documents\Nick LIVING WILL.pdf
2017-08-19 13:29 - 2017-08-19 13:29 - 000159096 _____ C:\Users\AIRWORX 2\Documents\Nick LAST WILL AND TESTAMENT.pdf
2017-08-18 11:30 - 2017-08-18 11:30 - 000000000 ____D C:\Users\AIRWORX 2\AppData\Local\IsolatedStorage
2017-08-18 11:20 - 2016-04-23 14:16 - 000000000 ____D C:\Users\AIRWORX 2\.oracle_jre_usage
2017-08-18 10:37 - 2017-08-18 11:13 - 000002951 _____ C:\Users\AIRWORX 2\Desktop\SeaTools for Windows.lnk
2017-08-18 10:37 - 2017-08-18 10:37 - 000000000 ____D C:\Users\AIRWORX 2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Seagate
2017-08-18 10:31 - 2017-08-18 10:31 - 000000000 ____D C:\WINDOWS\System32\Tasks\Leader Technologies
2017-08-18 10:30 - 2017-08-18 10:30 - 000000000 ____D C:\Users\AIRWORX 2\AppData\Local\SeagateMenu
2017-08-18 10:16 - 2017-08-21 08:15 - 000024746 _____ C:\Users\AIRWORX 2\Documents\allen new.xlsx
2017-08-18 07:56 - 2017-08-18 07:57 - 000000000 ____D C:\Users\airwo\AppData\Local\Dropbox
2017-08-18 07:50 - 2017-08-18 07:50 - 000000000 ____D C:\Users\airwo\AppData\Roaming\Zeon
2017-08-18 07:40 - 2017-08-18 08:14 - 000000000 ____D C:\Users\airwo
2017-08-18 07:40 - 2017-08-18 07:40 - 000000020 ___SH C:\Users\airwo\ntuser.ini
2017-08-18 07:40 - 2017-08-18 07:40 - 000000000 ____D C:\Users\airwo\AppData\Local\TileDataLayer
2017-08-18 07:40 - 2017-08-18 07:40 - 000000000 ____D C:\Users\airwo\AppData\Local\ESET
2017-08-18 07:40 - 2016-09-30 14:21 - 000000000 ____D C:\Users\airwo\Documents\hp.system.package.metadata
2017-08-18 07:40 - 2016-09-30 14:21 - 000000000 ____D C:\Users\airwo\Documents\hp.applications.package.appdata
2017-08-18 07:40 - 2016-09-30 14:21 - 000000000 ____D C:\Users\airwo\AppData\Local\Microsoft Help
2017-08-18 07:40 - 2016-09-30 14:21 - 000000000 ____D C:\Users\airwo\AppData\Local\Google
2017-08-18 07:31 - 2017-08-18 07:31 - 000087960 _____ C:\Users\AIRWORX 2\Documents\wmi reports.txt
2017-08-18 06:46 - 2017-08-18 06:46 - 000001352 _____ C:\Users\AIRWORX 2\Desktop\hdwwiz.exe - Shortcut.lnk
2017-08-18 06:45 - 2017-08-18 06:45 - 000000981 _____ C:\Users\AIRWORX 2\Desktop\hdwwiz.cpl - Shortcut.lnk
2017-08-18 04:14 - 2017-08-18 04:14 - 000012508 _____ C:\Users\AIRWORX 2\Desktop\1F_REVGenEdChkFYComp_0.pdf
2017-08-18 04:03 - 2017-08-18 04:03 - 000114643 _____ C:\Users\AIRWORX 2\Desktop\MCCCD Program Description.pdf
2017-08-17 21:19 - 2017-08-17 21:20 - 000000823 _____ C:\Users\AIRWORX 2\Desktop\JRT.txt
2017-08-17 21:14 - 2017-08-17 21:14 - 001790024 _____ (Malwarebytes) C:\Users\AIRWORX 2\Desktop\JRT.exe
2017-08-17 21:07 - 2017-08-17 21:07 - 008185288 _____ (Malwarebytes) C:\Users\AIRWORX 2\Desktop\AdwCleaner.exe
2017-08-17 13:39 - 2017-08-17 13:39 - 000001955 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2017-08-17 13:39 - 2017-08-17 13:39 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2017-08-17 13:39 - 2017-06-27 12:06 - 000077376 _____ C:\WINDOWS\system32\Drivers\mbae64.sys
2017-08-17 12:39 - 2017-08-17 12:39 - 000069632 _____ C:\WINDOWS\calc diag.evtx
2017-08-17 12:38 - 2017-08-17 12:39 - 000000000 ____D C:\WINDOWS\LocaleMetaData
2017-08-17 12:38 - 2017-08-17 12:38 - 000069632 _____ C:\WINDOWS\calc debug.evtx
2017-08-17 11:22 - 2017-08-26 12:26 - 000253856 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2017-08-17 11:22 - 2017-08-23 02:05 - 000109272 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2017-08-17 09:21 - 2017-08-17 09:21 - 000000000 ____D C:\Program Files\Malwarebytes
2017-08-17 09:20 - 2017-08-17 09:20 - 065033984 _____ (Malwarebytes ) C:\Users\AIRWORX 2\Desktop\mb3-setup-consumer-3.1.2.1733-1.0.160-1.0.2251 (1).exe
2017-08-17 05:52 - 2017-08-17 05:52 - 035688304 _____ (Adlice Software ) C:\Users\AIRWORX 2\Desktop\RogueKiller_setup.exe
2017-08-17 05:50 - 2017-08-17 05:50 - 000003429 _____ C:\Users\AIRWORX 2\Documents\to do techspot.txt
2017-08-17 03:42 - 2017-08-17 03:42 - 000069632 _____ C:\Users\AIRWORX 2\Documents\antimalware.evtx
2017-08-15 13:35 - 2017-08-15 13:35 - 000714224 _____ C:\Users\AIRWORX 2\Desktop\Windows10andWindowsServer2016PolicySettings (1).xlsx
2017-08-15 13:33 - 2017-08-15 13:33 - 000714224 _____ C:\Users\AIRWORX 2\Desktop\Windows10andWindowsServer2016PolicySettings.xlsx
2017-08-15 13:12 - 2017-08-15 13:12 - 000248729 _____ C:\Users\AIRWORX 2\Downloads\pop-securing-lateral-account-movement.pdf
2017-08-15 11:38 - 2017-08-15 11:38 - 000767631 _____ C:\Users\AIRWORX 2\Desktop\F4183E84-3D51-4F88-8145-9312C2D88DC6.pdf
2017-08-15 08:02 - 2017-01-02 13:47 - 000068873 _____ C:\Users\AIRWORX 2\Downloads\Inv_3303_from_3_ATOMS_LLC_3656 - Copy.pdf
2017-08-15 04:58 - 2017-08-22 10:05 - 002395648 _____ (Farbar) C:\Users\AIRWORX 2\Desktop\FRST64.exe
2017-08-15 02:24 - 2017-08-15 02:24 - 021715575 _____ C:\Users\AIRWORX 2\Desktop\windows10.0-kb4034662-x64_f2380ab75c39045ffdde4fa875029e1b70bb5aec.msu
2017-08-14 14:40 - 2017-08-14 14:43 - 904101495 _____ C:\Users\AIRWORX 2\Desktop\windows10.0-kb4034674-x64_cae3409b2e93b492093c43a18aa81f66cc70cdad.msu
2017-08-14 14:40 - 2017-08-14 14:42 - 564953013 _____ C:\Users\AIRWORX 2\Desktop\windows10.0-kb4034674-x64_delta_891202a55f2b6051b8a03b309ea9922ba19e1cf6.msu
2017-08-14 12:03 - 2017-08-14 12:03 - 000583304 _____ (ESET spol. s r.o.) C:\Users\AIRWORX 2\Desktop\ESETHfsReader (1).exe
2017-08-14 11:59 - 2017-08-14 11:59 - 002273880 _____ (ESET) C:\Users\AIRWORX 2\Desktop\ERARemover_x86.exe
2017-08-14 11:59 - 2017-08-14 11:59 - 000115008 _____ (ESET) C:\WINDOWS\SysWOW64\Drivers\efavdrv.sys
2017-08-14 11:57 - 2017-08-14 11:57 - 002991832 _____ (ESET) C:\Users\AIRWORX 2\Desktop\ERARemover_x64 (1).exe
2017-08-14 09:04 - 2017-08-14 09:04 - 000001860 _____ C:\Users\AIRWORX 2\Desktop\sc-cleaner1.txt
2017-08-11 12:22 - 2017-08-23 03:36 - 000000000 ____D C:\Users\AIRWORX 2\Desktop\mbar
2017-08-11 12:22 - 2017-08-11 12:22 - 016563352 _____ (Malwarebytes Corp.) C:\Users\AIRWORX 2\Desktop\mbar-1.09.3.1001 (1).exe
2017-08-11 10:22 - 2017-08-26 12:23 - 000000000 ____D C:\AdwCleaner
2017-08-11 10:18 - 2017-08-11 10:18 - 006754944 _____ (ESET spol. s r.o.) C:\Users\AIRWORX 2\Desktop\esetonlinescanner_enu.exe
2017-08-11 09:51 - 2017-08-11 09:51 - 000001613 _____ C:\Users\AIRWORX 2\Desktop\ProcmonConfiguration.pmc
2017-08-11 09:47 - 2017-08-11 09:47 - 000001737 _____ C:\Users\AIRWORX 2\Desktop\cross reference processes.CSV
2017-08-11 09:46 - 2017-08-11 09:46 - 000001188 _____ C:\Users\AIRWORX 2\Desktop\network events.CSV
2017-08-11 09:43 - 2017-08-14 09:03 - 000001860 _____ C:\Users\AIRWORX 2\Desktop\sc-cleaner.txt
2017-08-11 09:42 - 2017-08-11 09:42 - 000059971 _____ C:\Users\AIRWORX 2\Desktop\MTB1.txt
2017-08-11 09:41 - 2017-08-11 09:41 - 000059971 _____ C:\Users\AIRWORX 2\Desktop\MTB.txt
2017-08-11 08:04 - 2017-08-11 08:04 - 000892416 _____ (Farbar) C:\Users\AIRWORX 2\Desktop\MiniToolBox.exe
2017-08-11 08:03 - 2017-08-11 08:03 - 000467072 _____ (Bleeping Computer, LLC) C:\Users\AIRWORX 2\Desktop\sc-cleaner.exe
2017-08-11 04:17 - 2017-08-11 04:17 - 000488556 _____ C:\Users\AIRWORX 2\Desktop\5-15-17 eset.xml
2017-08-11 04:16 - 2017-08-11 04:16 - 000211414 _____ C:\Users\AIRWORX 2\Desktop\6-27-17 eset findings.xml
2017-08-11 02:29 - 2017-08-11 02:29 - 000148871 _____ C:\Users\AIRWORX 2\Desktop\ssasbug.android findings eset.txt
2017-08-11 02:27 - 2017-08-11 02:27 - 000203442 _____ C:\Users\AIRWORX 2\Desktop\tv lite.jsn findings eset.txt
2017-08-11 02:26 - 2017-08-11 02:26 - 002683721 _____ C:\Users\AIRWORX 2\Desktop\Ink cant open .txt
2017-08-11 02:25 - 2017-08-11 02:25 - 000000201 _____ C:\Users\AIRWORX 2\Desktop\safe os mount eset.txt
2017-08-11 02:22 - 2017-08-11 02:22 - 000109866 _____ C:\Users\AIRWORX 2\Desktop\eset history and NT Auth updates too.txt
2017-08-10 20:28 - 2017-08-10 20:28 - 000000000 ____D C:\Users\AIRWORX 2\Desktop\ESET Rootkit Detector.app
2017-08-10 20:22 - 2017-08-10 20:22 - 002991832 _____ (ESET) C:\Users\AIRWORX 2\Desktop\ERARemover_x64.exe
2017-08-10 20:21 - 2017-08-14 12:03 - 000001244 _____ C:\Users\AIRWORX 2\Desktop\HfsReader_Log.txt
2017-08-10 20:15 - 2017-08-10 20:15 - 000000000 ____D C:\Users\AIRWORX 2\Desktop\ESET_Rootkit_Detector
2017-08-10 20:10 - 2017-08-10 20:10 - 000260296 _____ (ESET) C:\Users\AIRWORX 2\Desktop\ESETNecursCleaner.exe
2017-08-10 20:09 - 2017-08-10 20:09 - 009757824 _____ (ESET) C:\Users\AIRWORX 2\Desktop\avremover_nt64_enu.exe
2017-08-10 20:09 - 2017-08-10 20:09 - 000616883 _____ C:\Users\AIRWORX 2\Desktop\ESET_Rootkit_Detector.zip
2017-08-10 20:09 - 2017-08-10 20:09 - 000583304 _____ (ESET spol. s r.o.) C:\Users\AIRWORX 2\Desktop\ESETHfsReader.exe
2017-08-10 12:19 - 2017-08-11 09:22 - 000100017 _____ C:\Users\AIRWORX 2\Desktop\DigiData.Vault.Adapter.log.1.txt
2017-08-10 11:44 - 2017-08-10 11:44 - 000069632 _____ C:\Users\AIRWORX 2\Documents\search UI.evtx
2017-08-10 11:44 - 2017-08-10 11:44 - 000069632 _____ C:\Users\AIRWORX 2\Documents\oneCore online setup.evtx
2017-08-10 11:43 - 2017-08-10 11:43 - 000069632 _____ C:\Users\AIRWORX 2\Documents\defender.evtx
2017-08-10 11:35 - 2017-08-10 11:35 - 000069632 _____ C:\Users\AIRWORX 2\Documents\Analytic.evtx
2017-08-10 07:54 - 2017-08-23 05:14 - 000091976 ____H (Sysinternals - www.sysinternals.com) C:\WINDOWS\system32\Drivers\PROCMON23.SYS
2017-08-10 07:54 - 2017-08-18 08:33 - 000000000 ____D C:\Users\AIRWORX 2\Desktop\ProcessMonitor
2017-08-10 07:53 - 2017-08-10 07:53 - 001005016 _____ C:\Users\AIRWORX 2\Desktop\ProcessMonitor.zip
2017-08-10 07:30 - 2017-08-10 07:30 - 000022715 _____ C:\Users\AIRWORX 2\Desktop\Employee-Referral-Form.pdf
2017-08-09 11:55 - 2017-08-18 10:23 - 000206120 ____N C:\WINDOWS\Minidump\081817-24515-01.dmp
2017-08-09 10:44 - 2017-08-09 10:44 - 000000646 _____ C:\windows reg did not find any errors.txt
2017-08-09 10:23 - 2017-08-09 10:23 - 000009985 _____ C:\Users\AIRWORX 2\Desktop\cmd we ran 8-9-17.txt
2017-08-09 09:20 - 2017-08-09 09:20 - 000000347 _____ C:\Users\AIRWORX 2\Desktop\junk text commandtxt.txt
2017-08-09 09:10 - 2017-08-09 09:10 - 000035172 _____ C:\Users\AIRWORX 2\Desktop\services.xlsx
2017-08-09 08:52 - 2017-08-09 08:52 - 016563352 _____ (Malwarebytes Corp.) C:\Users\AIRWORX 2\Desktop\mbar-1.09.3.1001.exe
2017-08-09 05:56 - 2017-08-09 05:56 - 002396604 _____ C:\Users\AIRWORX 2\Desktop\WVCheck.exe
2017-08-09 05:53 - 2017-08-09 05:53 - 000380928 _____ C:\Users\AIRWORX 2\Desktop\n0i6wip8.exe
2017-08-09 02:29 - 2017-08-09 02:29 - 065033984 _____ (Malwarebytes ) C:\Users\AIRWORX 2\Desktop\mb3-setup-consumer-3.1.2.1733-1.0.160-1.0.2251.exe
2017-08-08 21:28 - 2017-08-08 21:28 - 000000000 ____D C:\Users\AIRWORX 2\AppData\Local\Publishers
2017-08-08 14:49 - 2017-08-08 14:50 - 021567079 _____ C:\Users\AIRWORX 2\Desktop\eset ignore known.xml
2017-08-08 11:20 - 2017-08-08 11:40 - 000007704 _____ C:\Users\AIRWORX 2\Desktop\SystemLook.txt
2017-08-08 11:18 - 2017-08-08 11:18 - 000165376 _____ C:\Users\AIRWORX 2\Desktop\SystemLook_x64.exe
2017-08-08 09:39 - 2017-08-08 09:39 - 000000000 ___RD C:\Users\AIRWORX 2\Downloads\Cosmic Jump AIRWORX Team Folder
2017-08-08 06:43 - 2017-08-08 06:43 - 000224885 _____ C:\Users\AIRWORX 2\Desktop\HHS Syllabus Signature Form -signed.pdf
2017-08-08 06:41 - 2017-08-08 06:41 - 000079927 _____ C:\Users\AIRWORX 2\Desktop\HHS Syllabus Signature Form .pdf
2017-08-08 06:37 - 2017-08-08 06:37 - 000130011 _____ C:\Users\AIRWORX 2\Desktop\ACFrOgBX20iFWV0zlOfIcnVvXuWFsRsWFHxh-F_BkAp8bDwqqj0Yv8DmcWC9UunIF7Yc3GQ_FPzGqJGE3Udx6ZkfZbWjV2IWVIT2uMiJq5IMsfJkGNwBJkC4onio8yk=.pdf
2017-08-08 06:15 - 2017-08-09 09:10 - 000065097 _____ C:\Users\AIRWORX 2\Desktop\services.csv
2017-08-08 05:16 - 2017-08-08 05:16 - 000081951 _____ C:\Users\AIRWORX 2\Desktop\myeventviewer-x64.zip
2017-08-08 05:07 - 2017-08-08 05:07 - 000061440 _____ ( ) C:\Users\AIRWORX 2\Desktop\VEW.exe
2017-08-08 04:21 - 2017-08-08 04:21 - 001770460 _____ C:\Users\AIRWORX 2\Downloads\Windows Defender ATP - Ransomware response playbook.pdf
2017-08-08 04:20 - 2017-08-24 11:05 - 000000000 ____D C:\Users\AIRWORX 2\AppData\Local\CrashDumps
2017-08-08 04:14 - 2017-08-08 04:14 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Enhanced Mitigation Experience Toolkit
2017-08-08 04:14 - 2017-08-08 04:14 - 000000000 ____D C:\Program Files (x86)\EMET 5.5
2017-08-08 04:13 - 2017-08-08 04:13 - 026812416 _____ C:\Users\AIRWORX 2\Downloads\EMET Setup.msi
2017-08-08 04:10 - 2017-08-08 04:39 - 000768464 _____ C:\Users\AIRWORX 2\Downloads\Windows10andWindowsServer2016PolicySettings.xlsx
2017-08-08 02:55 - 2017-08-08 02:55 - 000000000 ____D C:\Users\AIRWORX 2\AppData\Roaming\JetBrains
2017-08-08 02:49 - 2017-08-24 04:32 - 000000000 ____D C:\Users\AIRWORX 2\AppData\Local\Microsoft Help
2017-08-08 02:43 - 2017-08-09 11:24 - 000000000 ____D C:\Android
2017-08-08 02:42 - 2017-08-09 11:20 - 000000000 ____D C:\Program Files\Android
2017-08-07 13:01 - 2017-08-07 13:04 - 000790638 _____ C:\TDSSKiller.3.1.0.15_07.08.2017_13.01.55_log.txt
2017-08-07 12:43 - 2017-08-07 12:44 - 000008106 _____ C:\TDSSKiller.3.1.0.15_07.08.2017_12.43.03_log.txt
2017-08-07 12:41 - 2017-08-07 12:41 - 004922400 _____ (AO Kaspersky Lab) C:\Users\AIRWORX 2\Desktop\tdsskiller.exe
2017-08-07 12:25 - 2017-08-07 12:25 - 000000155 _____ C:\WINDOWS\system32\all.txt
2017-08-07 10:00 - 2017-08-07 10:00 - 000879551 _____ C:\Users\AIRWORX 2\Desktop\CryptoSearch.zip
2017-08-04 11:10 - 2017-08-04 14:39 - 000000000 ____D C:\Users\AIRWORX 2\Desktop\AP
2017-08-04 10:48 - 2017-08-17 05:54 - 000000942 _____ C:\Users\Public\Desktop\RogueKiller.lnk
2017-08-04 10:37 - 2017-08-04 10:37 - 000000546 _____ C:\Users\AIRWORX 2\Desktop\Encrypted documents - Copy.zip
2017-08-04 10:01 - 2017-08-04 10:02 - 000047265 _____ C:\Users\AIRWORX 2\Desktop\appcrashview (1).zip
2017-08-04 05:40 - 2017-08-04 09:24 - 000004816 _____ C:\Users\AIRWORX 2\Desktop\links to findings.txt
2017-08-03 20:55 - 2017-08-03 20:55 - 000055111 _____ C:\Users\AIRWORX 2\Desktop\ACFrOgAjZaC8g0bE5UVjMkDU-EGyfCbydESYIcl5Ek-Jk2dgOtZdX5ShW7Uo0TTTXhI7ZV4o60JCCrjfMp-q84aBwoJKcJbRGbK_B2rm9Yaii0wppseh1AkAy87pTKo=.pdf
2017-08-03 12:52 - 2017-08-03 12:52 - 000011327 _____ C:\Users\AIRWORX 2\Desktop\eset scans.txt
2017-08-03 07:53 - 2017-08-03 07:53 - 000333952 _____ (ESET) C:\Users\AIRWORX 2\Downloads\ESETEternalBlueChecker.exe
2017-08-03 07:38 - 2017-08-03 07:38 - 004836307 _____ C:\Users\AIRWORX 2\Downloads\eset_sysrescue_userguide_enu.pdf
2017-08-03 04:01 - 2017-08-26 12:25 - 100401152 _____ C:\WINDOWS\system32\config\SOFTWARE
2017-08-03 03:58 - 2017-08-03 03:59 - 000000000 ____D C:\WINDOWS\Microsoft Antimalware
2017-08-02 15:53 - 2017-08-02 15:53 - 044003024 _____ (Microsoft Corporation) C:\Users\AIRWORX 2\Desktop\Windows-KB890830-x64-V5.50 (1).exe
2017-08-02 10:02 - 2017-08-02 10:02 - 000000000 ____D C:\Users\AIRWORX 2\AppData\Local\LogMeIn
2017-08-02 07:44 - 2017-08-02 07:44 - 000000000 ____D C:\Users\AIRWORX 2\Documents\Security
2017-08-02 07:20 - 2017-08-24 18:28 - 000000000 ____D C:\Users\AIRWORX 2\Documents\LocaleMetaData
2017-08-02 07:19 - 2017-08-02 07:20 - 000069632 _____ C:\Users\AIRWORX 2\Documents\events.evtx
2017-08-02 03:08 - 2017-08-02 03:08 - 145707800 _____ (Microsoft Corporation) C:\Users\AIRWORX 2\Desktop\msert.exe
2017-08-02 03:05 - 2017-08-02 03:05 - 000001174 _____ C:\Users\AIRWORX 2\Desktop\app crash viewer.txt
2017-08-02 03:03 - 2017-08-23 05:22 - 000000469 _____ C:\Users\AIRWORX 2\Desktop\AppCrashView.cfg
2017-08-01 08:19 - 2017-08-01 08:19 - 000011327 _____ C:\Users\AIRWORX 2\Desktop\eset yesterday.txt
2017-08-01 06:18 - 2017-08-22 10:05 - 000000000 ____D C:\Users\AIRWORX 2\Desktop\FRST-OlderVersion
2017-08-01 05:58 - 2017-08-01 05:58 - 000000000 ____D C:\WINDOWS\Panther
2017-07-31 15:33 - 2017-07-31 15:33 - 000000000 ____D C:\Users\AIRWORX 2\AppData\Local\NetworkTiles
2017-07-31 15:25 - 2017-07-31 15:25 - 000000000 ____D C:\Users\AIRWORX 2\AppData\Local\MicrosoftEdge
2017-07-31 13:36 - 2017-07-31 13:36 - 006754944 _____ (ESET spol. s r.o.) C:\Users\AIRWORX 2\Downloads\esetonlinescanner_enu (1).exe
2017-07-28 08:44 - 2017-07-28 08:44 - 000000000 _____ C:\WINDOWS\system32\set
2017-07-28 06:15 - 2017-07-28 06:15 - 000576231 _____ C:\Users\AIRWORX 2\Downloads\DTec13656.pdf
2017-07-28 06:06 - 2017-07-28 06:06 - 000075669 _____ C:\Users\AIRWORX 2\Downloads\COSMIC JUMP (4).pdf
2017-07-28 06:01 - 2017-07-28 06:01 - 000053739 _____ C:\Users\AIRWORX 2\Downloads\HS-2.8.17 #2888 CJump KCity Jan Inv&Rep SH (1).pdf
2017-07-28 05:54 - 2017-07-28 05:54 - 000151083 _____ C:\Users\AIRWORX 2\Downloads\COSMIC JUMP - Inv.pdf
2017-07-28 05:39 - 2017-07-28 06:17 - 000002182 _____ C:\Users\AIRWORX 2\Downloads\data (35).csv
2017-07-28 05:17 - 2017-07-28 05:17 - 000002299 _____ C:\Users\AIRWORX 2\Desktop\Google Chrome.lnk
2017-07-28 03:35 - 2017-07-28 03:35 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Seagate
2017-07-27 07:33 - 2017-07-27 07:33 - 008162248 _____ (Malwarebytes) C:\Users\AIRWORX 2\Downloads\AdwCleaner.exe
2017-07-27 07:33 - 2017-07-27 07:33 - 001790024 _____ (Malwarebytes) C:\Users\AIRWORX 2\Downloads\JRT.exe
2017-07-27 06:25 - 2017-07-27 06:25 - 000995572 _____ C:\Users\AIRWORX 2\Desktop\rel.XML
2017-07-27 06:02 - 2017-07-27 06:02 - 000000000 ____D C:\Users\AIRWORX 2\AppData\Local\.IdentityService
2017-07-27 04:08 - 2017-07-27 04:08 - 000183220 _____ C:\Users\AIRWORX 2\Downloads\Appsdiagnostic10.diagcab
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-08-25 13:05 - 2017-08-25 13:06 - 255308582 _____ C:\Users\AIRWORX 2\Documents\Book1.xlsx
2017-08-25 12:37 - 2017-08-25 12:37 - 010485794 _____ C:\Users\AIRWORX 2\Documents\txtunicode.txt
2017-08-25 12:37 - 2017-08-25 12:37 - 005242896 _____ C:\Users\AIRWORX 2\Documents\txtansi.txt
2017-08-25 12:36 - 2017-08-25 12:36 - 005731140 _____ C:\Users\AIRWORX 2\Documents\txt.txt
2017-08-25 12:00 - 2017-08-25 12:00 - 000044221 _____ C:\Users\AIRWORX 2\Downloads\08.15.17Bradford Ltr (Certified).pdf
2017-08-25 11:50 - 2017-08-25 11:50 - 000874058 _____ C:\Users\AIRWORX 2\Downloads\Cosmic Jump Employee Manual No Jumping 1-30-14.pdf
2017-08-25 11:49 - 2017-08-25 11:49 - 000836044 _____ C:\Users\AIRWORX 2\Downloads\Cosmic Jump Employee Manual No Jumping.pdf
2017-08-25 10:58 - 2017-08-25 10:58 - 005731140 _____ C:\Users\AIRWORX 2\Documents\utf-8 format.txt
2017-08-25 09:59 - 2017-08-25 10:00 - 000364544 _____ C:\Users\AIRWORX 2\Documents\Database4.accdb
2017-08-25 02:33 - 2017-08-25 02:33 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DB Browser for SQLite
2017-08-24 18:28 - 2017-08-24 18:28 - 000069632 _____ C:\Users\AIRWORX 2\Documents\dev.evtx
2017-08-24 18:26 - 2017-08-24 18:26 - 000069632 _____ C:\Users\AIRWORX 2\Documents\device events.evtx
2017-08-24 09:55 - 2017-08-24 09:55 - 016119416 _____ C:\Users\AIRWORX 2\Downloads\DB.Browser.for.SQLite-3.10.0-beta2-win64.exe
2017-08-24 09:46 - 2017-08-24 09:57 - 000352256 _____ C:\Users\AIRWORX 2\Documents\Database3.accdb
2017-08-24 08:33 - 2017-08-24 08:37 - 000352256 _____ C:\Users\AIRWORX 2\Documents\Database2.accdb
2017-08-24 08:26 - 2017-08-26 12:25 - 000000372 _____ C:\WINDOWS\Tasks\HPCeeScheduleForAIRWORX 2.job
2017-08-24 08:25 - 2017-08-24 08:25 - 005718872 _____ (Microsoft Corporation) C:\Users\AIRWORX 2\Downloads\vcredist_x64.exe
2017-08-24 07:41 - 2017-08-24 07:42 - 399261754 _____ C:\Users\AIRWORX 2\Downloads\mysql-5.7.19-winx64-debug-test.zip
2017-08-24 07:38 - 2017-08-24 07:38 - 008527872 _____ C:\Users\AIRWORX 2\Downloads\mysql-connector-odbc-5.3.9-winx64.msi
2017-08-24 07:33 - 2017-08-24 07:33 - 000000155 _____ C:\WINDOWS\system32\report.txt
2017-08-24 07:29 - 2017-08-24 07:34 - 000000289 _____ C:\WINDOWS\ODBC.INI
2017-08-24 04:32 - 2017-08-24 07:21 - 000352256 _____ C:\Users\AIRWORX 2\Documents\Database1.accdb
2017-08-24 02:07 - 2017-08-26 13:15 - 000004693 _____ C:\Users\AIRWORX 2\Desktop\Fixlog.txt
2017-08-23 07:56 - 2017-08-23 07:56 - 000001046 _____ C:\Users\Public\Desktop\EPSON Scan.lnk
2017-08-23 07:56 - 2012-07-24 00:00 - 000470528 _____ (Seiko Epson Corporation) C:\WINDOWS\system32\esxw2_86.dll
2017-08-23 07:56 - 2011-12-12 00:00 - 000135824 _____ (Seiko Epson Corporation) C:\WINDOWS\system32\escsvc64.exe
2017-08-23 07:49 - 2017-08-23 07:49 - 005957560 _____ C:\Users\AIRWORX 2\Desktop\epson19043.exe
2017-08-23 07:30 - 2017-08-23 07:30 - 000120690 _____ C:\Users\AIRWORX 2\Downloads\combined.pdf
2017-08-23 07:28 - 2017-08-23 07:28 - 000123377 _____ C:\Users\AIRWORX 2\Desktop\alldocs.pdf
2017-08-23 06:57 - 2017-08-23 06:57 - 001240712 _____ C:\Users\AIRWORX 2\Desktop\this is ms.txt
2017-08-23 06:56 - 2017-08-23 06:56 - 001240712 _____ C:\Users\AIRWORX 2\Desktop\this is msi log.txt
2017-08-23 06:55 - 2017-08-23 06:55 - 001240712 _____ C:\Users\AIRWORX 2\Desktop\MSI6857e.txt
2017-08-23 06:51 - 2017-08-23 06:51 - 000036289 _____ C:\Users\AIRWORX 2\Desktop\setupact1.txt
2017-08-23 06:47 - 2017-08-23 06:47 - 000187717 _____ C:\Users\AIRWORX 2\Desktop\WidnowsUpdateLog 8-15-17.txt
2017-08-23 06:13 - 2017-08-23 06:13 - 000108484 _____ C:\Users\AIRWORX 2\Desktop\balance of 90 day created files.txt
2017-08-23 05:22 - 2017-08-23 05:22 - 000017880 _____ C:\Users\AIRWORX 2\Desktop\app crash viewer reports.txt
2017-08-23 04:31 - 2017-08-23 04:31 - 000345927 _____ C:\Users\AIRWORX 2\Desktop\eset 12 found 11 corrected.txt
2017-08-23 04:30 - 2017-08-23 04:30 - 000203442 _____ C:\Users\AIRWORX 2\Desktop\6-28-17 eset all.txt
2017-08-23 04:28 - 2017-08-23 04:28 - 000511683 _____ C:\Users\AIRWORX 2\Desktop\eset 42 found.txt
2017-08-23 04:22 - 2017-08-23 04:22 - 000486514 _____ C:\Users\AIRWORX 2\Desktop\1 found eset.txt
2017-08-23 04:20 - 2017-08-23 04:20 - 000012117 _____ C:\Users\AIRWORX 2\Desktop\eset detected threats.txt
2017-08-23 04:17 - 2017-08-23 04:17 - 000000099 _____ C:\Users\AIRWORX 2\Desktop\eset last complete scan.txt
2017-08-23 04:13 - 2017-08-23 04:13 - 000000152 _____ C:\Users\AIRWORX 2\Desktop\6-28-17 eset.txt
2017-08-23 04:08 - 2017-08-23 04:08 - 000012117 _____ C:\Users\AIRWORX 2\Desktop\eset threats.txt
2017-08-22 20:17 - 2017-08-22 20:17 - 000072689 _____ C:\Users\AIRWORX 2\Downloads\02234217-WebDetail.pdf
2017-08-22 19:57 - 2017-08-22 19:57 - 000010810 _____ C:\Users\AIRWORX 2\Desktop\Brandi-Copas.pdfresume.pdf
2017-08-22 19:35 - 2017-08-22 19:36 - 297077664 _____ C:\Users\AIRWORX 2\Documents\regedits.REG
2017-08-21 15:38 - 2017-08-21 15:38 - 000092808 _____ C:\Users\AIRWORX 2\Downloads\Instructions-for-Completing-an-Affidavit-of-Affixture.pdf
2017-08-21 15:38 - 2017-08-21 15:38 - 000092808 _____ C:\Users\AIRWORX 2\Downloads\Instructions-for-Completing-an-Affidavit-of-Affixture (2).pdf
2017-08-21 15:38 - 2017-08-21 15:38 - 000092808 _____ C:\Users\AIRWORX 2\Downloads\Instructions-for-Completing-an-Affidavit-of-Affixture (1).pdf
2017-08-21 13:48 - 2017-08-21 13:53 - 000002324 _____ C:\Users\AIRWORX 2\Desktop\page 2.html
2017-08-21 13:35 - 2017-08-21 13:39 - 000098816 _____ C:\Users\AIRWORX 2\Documents\Publication1.pub
2017-08-21 12:59 - 2017-08-21 13:40 - 000024476 _____ C:\Users\AIRWORX 2\Documents\Publication1.htm
2017-08-21 12:59 - 2017-08-21 13:40 - 000000000 ____D C:\Users\AIRWORX 2\Documents\Publication1_files
2017-08-21 08:15 - 2017-08-21 08:15 - 000010221 _____ C:\Users\AIRWORX 2\Documents\booking list allen.xlsx
2017-08-21 07:27 - 2017-08-21 07:27 - 000006863 _____ C:\Users\AIRWORX 2\Desktop\sam's invoice 8-18-2017.pdf
2017-08-19 13:30 - 2017-08-19 13:33 - 000155362 _____ C:\Users\AIRWORX 2\Documents\Nick LIVING WILL.pdf
2017-08-19 13:29 - 2017-08-19 13:29 - 000159096 _____ C:\Users\AIRWORX 2\Documents\Nick LAST WILL AND TESTAMENT.pdf
2017-08-18 11:30 - 2017-08-18 11:30 - 000000000 ____D C:\Users\AIRWORX 2\AppData\Local\IsolatedStorage
2017-08-18 11:20 - 2016-04-23 14:16 - 000000000 ____D C:\Users\AIRWORX 2\.oracle_jre_usage
2017-08-18 10:37 - 2017-08-18 11:13 - 000002951 _____ C:\Users\AIRWORX 2\Desktop\SeaTools for Windows.lnk
2017-08-18 10:37 - 2017-08-18 10:37 - 000000000 ____D C:\Users\AIRWORX 2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Seagate
2017-08-18 10:31 - 2017-08-18 10:31 - 000000000 ____D C:\WINDOWS\System32\Tasks\Leader Technologies
2017-08-18 10:30 - 2017-08-18 10:30 - 000000000 ____D C:\Users\AIRWORX 2\AppData\Local\SeagateMenu
2017-08-18 10:16 - 2017-08-21 08:15 - 000024746 _____ C:\Users\AIRWORX 2\Documents\allen new.xlsx
2017-08-18 07:56 - 2017-08-18 07:57 - 000000000 ____D C:\Users\airwo\AppData\Local\Dropbox
2017-08-18 07:50 - 2017-08-18 07:50 - 000000000 ____D C:\Users\airwo\AppData\Roaming\Zeon
2017-08-18 07:40 - 2017-08-18 08:14 - 000000000 ____D C:\Users\airwo
2017-08-18 07:40 - 2017-08-18 07:40 - 000000020 ___SH C:\Users\airwo\ntuser.ini
2017-08-18 07:40 - 2017-08-18 07:40 - 000000000 ____D C:\Users\airwo\AppData\Local\TileDataLayer
2017-08-18 07:40 - 2017-08-18 07:40 - 000000000 ____D C:\Users\airwo\AppData\Local\ESET
2017-08-18 07:40 - 2016-09-30 14:21 - 000000000 ____D C:\Users\airwo\Documents\hp.system.package.metadata
2017-08-18 07:40 - 2016-09-30 14:21 - 000000000 ____D C:\Users\airwo\Documents\hp.applications.package.appdata
2017-08-18 07:40 - 2016-09-30 14:21 - 000000000 ____D C:\Users\airwo\AppData\Local\Microsoft Help
2017-08-18 07:40 - 2016-09-30 14:21 - 000000000 ____D C:\Users\airwo\AppData\Local\Google
2017-08-18 07:31 - 2017-08-18 07:31 - 000087960 _____ C:\Users\AIRWORX 2\Documents\wmi reports.txt
2017-08-18 06:46 - 2017-08-18 06:46 - 000001352 _____ C:\Users\AIRWORX 2\Desktop\hdwwiz.exe - Shortcut.lnk
2017-08-18 06:45 - 2017-08-18 06:45 - 000000981 _____ C:\Users\AIRWORX 2\Desktop\hdwwiz.cpl - Shortcut.lnk
2017-08-18 04:14 - 2017-08-18 04:14 - 000012508 _____ C:\Users\AIRWORX 2\Desktop\1F_REVGenEdChkFYComp_0.pdf
2017-08-18 04:03 - 2017-08-18 04:03 - 000114643 _____ C:\Users\AIRWORX 2\Desktop\MCCCD Program Description.pdf
2017-08-17 21:19 - 2017-08-17 21:20 - 000000823 _____ C:\Users\AIRWORX 2\Desktop\JRT.txt
2017-08-17 21:14 - 2017-08-17 21:14 - 001790024 _____ (Malwarebytes) C:\Users\AIRWORX 2\Desktop\JRT.exe
2017-08-17 21:07 - 2017-08-17 21:07 - 008185288 _____ (Malwarebytes) C:\Users\AIRWORX 2\Desktop\AdwCleaner.exe
2017-08-17 13:39 - 2017-08-17 13:39 - 000001955 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2017-08-17 13:39 - 2017-08-17 13:39 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2017-08-17 13:39 - 2017-06-27 12:06 - 000077376 _____ C:\WINDOWS\system32\Drivers\mbae64.sys
2017-08-17 12:39 - 2017-08-17 12:39 - 000069632 _____ C:\WINDOWS\calc diag.evtx
2017-08-17 12:38 - 2017-08-17 12:39 - 000000000 ____D C:\WINDOWS\LocaleMetaData
2017-08-17 12:38 - 2017-08-17 12:38 - 000069632 _____ C:\WINDOWS\calc debug.evtx
2017-08-17 11:22 - 2017-08-26 12:26 - 000253856 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2017-08-17 11:22 - 2017-08-23 02:05 - 000109272 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2017-08-17 09:21 - 2017-08-17 09:21 - 000000000 ____D C:\Program Files\Malwarebytes
2017-08-17 09:20 - 2017-08-17 09:20 - 065033984 _____ (Malwarebytes ) C:\Users\AIRWORX 2\Desktop\mb3-setup-consumer-3.1.2.1733-1.0.160-1.0.2251 (1).exe
2017-08-17 05:52 - 2017-08-17 05:52 - 035688304 _____ (Adlice Software ) C:\Users\AIRWORX 2\Desktop\RogueKiller_setup.exe
2017-08-17 05:50 - 2017-08-17 05:50 - 000003429 _____ C:\Users\AIRWORX 2\Documents\to do techspot.txt
2017-08-17 03:42 - 2017-08-17 03:42 - 000069632 _____ C:\Users\AIRWORX 2\Documents\antimalware.evtx
2017-08-15 13:35 - 2017-08-15 13:35 - 000714224 _____ C:\Users\AIRWORX 2\Desktop\Windows10andWindowsServer2016PolicySettings (1).xlsx
2017-08-15 13:33 - 2017-08-15 13:33 - 000714224 _____ C:\Users\AIRWORX 2\Desktop\Windows10andWindowsServer2016PolicySettings.xlsx
2017-08-15 13:12 - 2017-08-15 13:12 - 000248729 _____ C:\Users\AIRWORX 2\Downloads\pop-securing-lateral-account-movement.pdf
2017-08-15 11:38 - 2017-08-15 11:38 - 000767631 _____ C:\Users\AIRWORX 2\Desktop\F4183E84-3D51-4F88-8145-9312C2D88DC6.pdf
2017-08-15 08:02 - 2017-01-02 13:47 - 000068873 _____ C:\Users\AIRWORX 2\Downloads\Inv_3303_from_3_ATOMS_LLC_3656 - Copy.pdf
2017-08-15 04:58 - 2017-08-22 10:05 - 002395648 _____ (Farbar) C:\Users\AIRWORX 2\Desktop\FRST64.exe
2017-08-15 02:24 - 2017-08-15 02:24 - 021715575 _____ C:\Users\AIRWORX 2\Desktop\windows10.0-kb4034662-x64_f2380ab75c39045ffdde4fa875029e1b70bb5aec.msu
2017-08-14 14:40 - 2017-08-14 14:43 - 904101495 _____ C:\Users\AIRWORX 2\Desktop\windows10.0-kb4034674-x64_cae3409b2e93b492093c43a18aa81f66cc70cdad.msu
2017-08-14 14:40 - 2017-08-14 14:42 - 564953013 _____ C:\Users\AIRWORX 2\Desktop\windows10.0-kb4034674-x64_delta_891202a55f2b6051b8a03b309ea9922ba19e1cf6.msu
2017-08-14 12:03 - 2017-08-14 12:03 - 000583304 _____ (ESET spol. s r.o.) C:\Users\AIRWORX 2\Desktop\ESETHfsReader (1).exe
2017-08-14 11:59 - 2017-08-14 11:59 - 002273880 _____ (ESET) C:\Users\AIRWORX 2\Desktop\ERARemover_x86.exe
2017-08-14 11:59 - 2017-08-14 11:59 - 000115008 _____ (ESET) C:\WINDOWS\SysWOW64\Drivers\efavdrv.sys
2017-08-14 11:57 - 2017-08-14 11:57 - 002991832 _____ (ESET) C:\Users\AIRWORX 2\Desktop\ERARemover_x64 (1).exe
2017-08-14 09:04 - 2017-08-14 09:04 - 000001860 _____ C:\Users\AIRWORX 2\Desktop\sc-cleaner1.txt
2017-08-11 12:22 - 2017-08-23 03:36 - 000000000 ____D C:\Users\AIRWORX 2\Desktop\mbar
2017-08-11 12:22 - 2017-08-11 12:22 - 016563352 _____ (Malwarebytes Corp.) C:\Users\AIRWORX 2\Desktop\mbar-1.09.3.1001 (1).exe
2017-08-11 10:22 - 2017-08-26 12:23 - 000000000 ____D C:\AdwCleaner
2017-08-11 10:18 - 2017-08-11 10:18 - 006754944 _____ (ESET spol. s r.o.) C:\Users\AIRWORX 2\Desktop\esetonlinescanner_enu.exe
2017-08-11 09:51 - 2017-08-11 09:51 - 000001613 _____ C:\Users\AIRWORX 2\Desktop\ProcmonConfiguration.pmc
2017-08-11 09:47 - 2017-08-11 09:47 - 000001737 _____ C:\Users\AIRWORX 2\Desktop\cross reference processes.CSV
2017-08-11 09:46 - 2017-08-11 09:46 - 000001188 _____ C:\Users\AIRWORX 2\Desktop\network events.CSV
2017-08-11 09:43 - 2017-08-14 09:03 - 000001860 _____ C:\Users\AIRWORX 2\Desktop\sc-cleaner.txt
2017-08-11 09:42 - 2017-08-11 09:42 - 000059971 _____ C:\Users\AIRWORX 2\Desktop\MTB1.txt
2017-08-11 09:41 - 2017-08-11 09:41 - 000059971 _____ C:\Users\AIRWORX 2\Desktop\MTB.txt
2017-08-11 08:04 - 2017-08-11 08:04 - 000892416 _____ (Farbar) C:\Users\AIRWORX 2\Desktop\MiniToolBox.exe
2017-08-11 08:03 - 2017-08-11 08:03 - 000467072 _____ (Bleeping Computer, LLC) C:\Users\AIRWORX 2\Desktop\sc-cleaner.exe
2017-08-11 04:17 - 2017-08-11 04:17 - 000488556 _____ C:\Users\AIRWORX 2\Desktop\5-15-17 eset.xml
2017-08-11 04:16 - 2017-08-11 04:16 - 000211414 _____ C:\Users\AIRWORX 2\Desktop\6-27-17 eset findings.xml
2017-08-11 02:29 - 2017-08-11 02:29 - 000148871 _____ C:\Users\AIRWORX 2\Desktop\ssasbug.android findings eset.txt
2017-08-11 02:27 - 2017-08-11 02:27 - 000203442 _____ C:\Users\AIRWORX 2\Desktop\tv lite.jsn findings eset.txt
2017-08-11 02:26 - 2017-08-11 02:26 - 002683721 _____ C:\Users\AIRWORX 2\Desktop\Ink cant open .txt
2017-08-11 02:25 - 2017-08-11 02:25 - 000000201 _____ C:\Users\AIRWORX 2\Desktop\safe os mount eset.txt
2017-08-11 02:22 - 2017-08-11 02:22 - 000109866 _____ C:\Users\AIRWORX 2\Desktop\eset history and NT Auth updates too.txt
2017-08-10 20:28 - 2017-08-10 20:28 - 000000000 ____D C:\Users\AIRWORX 2\Desktop\ESET Rootkit Detector.app
2017-08-10 20:22 - 2017-08-10 20:22 - 002991832 _____ (ESET) C:\Users\AIRWORX 2\Desktop\ERARemover_x64.exe
2017-08-10 20:21 - 2017-08-14 12:03 - 000001244 _____ C:\Users\AIRWORX 2\Desktop\HfsReader_Log.txt
2017-08-10 20:15 - 2017-08-10 20:15 - 000000000 ____D C:\Users\AIRWORX 2\Desktop\ESET_Rootkit_Detector
2017-08-10 20:10 - 2017-08-10 20:10 - 000260296 _____ (ESET) C:\Users\AIRWORX 2\Desktop\ESETNecursCleaner.exe
2017-08-10 20:09 - 2017-08-10 20:09 - 009757824 _____ (ESET) C:\Users\AIRWORX 2\Desktop\avremover_nt64_enu.exe
2017-08-10 20:09 - 2017-08-10 20:09 - 000616883 _____ C:\Users\AIRWORX 2\Desktop\ESET_Rootkit_Detector.zip
2017-08-10 20:09 - 2017-08-10 20:09 - 000583304 _____ (ESET spol. s r.o.) C:\Users\AIRWORX 2\Desktop\ESETHfsReader.exe
2017-08-10 12:19 - 2017-08-11 09:22 - 000100017 _____ C:\Users\AIRWORX 2\Desktop\DigiData.Vault.Adapter.log.1.txt
2017-08-10 11:44 - 2017-08-10 11:44 - 000069632 _____ C:\Users\AIRWORX 2\Documents\search UI.evtx
2017-08-10 11:44 - 2017-08-10 11:44 - 000069632 _____ C:\Users\AIRWORX 2\Documents\oneCore online setup.evtx
2017-08-10 11:43 - 2017-08-10 11:43 - 000069632 _____ C:\Users\AIRWORX 2\Documents\defender.evtx
2017-08-10 11:35 - 2017-08-10 11:35 - 000069632 _____ C:\Users\AIRWORX 2\Documents\Analytic.evtx
2017-08-10 07:54 - 2017-08-23 05:14 - 000091976 ____H (Sysinternals - www.sysinternals.com) C:\WINDOWS\system32\Drivers\PROCMON23.SYS
2017-08-10 07:54 - 2017-08-18 08:33 - 000000000 ____D C:\Users\AIRWORX 2\Desktop\ProcessMonitor
2017-08-10 07:53 - 2017-08-10 07:53 - 001005016 _____ C:\Users\AIRWORX 2\Desktop\ProcessMonitor.zip
2017-08-10 07:30 - 2017-08-10 07:30 - 000022715 _____ C:\Users\AIRWORX 2\Desktop\Employee-Referral-Form.pdf
2017-08-09 11:55 - 2017-08-18 10:23 - 000206120 ____N C:\WINDOWS\Minidump\081817-24515-01.dmp
2017-08-09 10:44 - 2017-08-09 10:44 - 000000646 _____ C:\windows reg did not find any errors.txt
2017-08-09 10:23 - 2017-08-09 10:23 - 000009985 _____ C:\Users\AIRWORX 2\Desktop\cmd we ran 8-9-17.txt
2017-08-09 09:20 - 2017-08-09 09:20 - 000000347 _____ C:\Users\AIRWORX 2\Desktop\junk text commandtxt.txt
2017-08-09 09:10 - 2017-08-09 09:10 - 000035172 _____ C:\Users\AIRWORX 2\Desktop\services.xlsx
2017-08-09 08:52 - 2017-08-09 08:52 - 016563352 _____ (Malwarebytes Corp.) C:\Users\AIRWORX 2\Desktop\mbar-1.09.3.1001.exe
2017-08-09 05:56 - 2017-08-09 05:56 - 002396604 _____ C:\Users\AIRWORX 2\Desktop\WVCheck.exe
2017-08-09 05:53 - 2017-08-09 05:53 - 000380928 _____ C:\Users\AIRWORX 2\Desktop\n0i6wip8.exe
2017-08-09 02:29 - 2017-08-09 02:29 - 065033984 _____ (Malwarebytes ) C:\Users\AIRWORX 2\Desktop\mb3-setup-consumer-3.1.2.1733-1.0.160-1.0.2251.exe
2017-08-08 21:28 - 2017-08-08 21:28 - 000000000 ____D C:\Users\AIRWORX 2\AppData\Local\Publishers
2017-08-08 14:49 - 2017-08-08 14:50 - 021567079 _____ C:\Users\AIRWORX 2\Desktop\eset ignore known.xml
2017-08-08 11:20 - 2017-08-08 11:40 - 000007704 _____ C:\Users\AIRWORX 2\Desktop\SystemLook.txt
2017-08-08 11:18 - 2017-08-08 11:18 - 000165376 _____ C:\Users\AIRWORX 2\Desktop\SystemLook_x64.exe
2017-08-08 09:39 - 2017-08-08 09:39 - 000000000 ___RD C:\Users\AIRWORX 2\Downloads\Cosmic Jump AIRWORX Team Folder
2017-08-08 06:43 - 2017-08-08 06:43 - 000224885 _____ C:\Users\AIRWORX 2\Desktop\HHS Syllabus Signature Form -signed.pdf
2017-08-08 06:41 - 2017-08-08 06:41 - 000079927 _____ C:\Users\AIRWORX 2\Desktop\HHS Syllabus Signature Form .pdf
2017-08-08 06:37 - 2017-08-08 06:37 - 000130011 _____ C:\Users\AIRWORX 2\Desktop\ACFrOgBX20iFWV0zlOfIcnVvXuWFsRsWFHxh-F_BkAp8bDwqqj0Yv8DmcWC9UunIF7Yc3GQ_FPzGqJGE3Udx6ZkfZbWjV2IWVIT2uMiJq5IMsfJkGNwBJkC4onio8yk=.pdf
2017-08-08 06:15 - 2017-08-09 09:10 - 000065097 _____ C:\Users\AIRWORX 2\Desktop\services.csv
2017-08-08 05:16 - 2017-08-08 05:16 - 000081951 _____ C:\Users\AIRWORX 2\Desktop\myeventviewer-x64.zip
2017-08-08 05:07 - 2017-08-08 05:07 - 000061440 _____ ( ) C:\Users\AIRWORX 2\Desktop\VEW.exe
2017-08-08 04:21 - 2017-08-08 04:21 - 001770460 _____ C:\Users\AIRWORX 2\Downloads\Windows Defender ATP - Ransomware response playbook.pdf
2017-08-08 04:20 - 2017-08-24 11:05 - 000000000 ____D C:\Users\AIRWORX 2\AppData\Local\CrashDumps
2017-08-08 04:14 - 2017-08-08 04:14 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Enhanced Mitigation Experience Toolkit
2017-08-08 04:14 - 2017-08-08 04:14 - 000000000 ____D C:\Program Files (x86)\EMET 5.5
2017-08-08 04:13 - 2017-08-08 04:13 - 026812416 _____ C:\Users\AIRWORX 2\Downloads\EMET Setup.msi
2017-08-08 04:10 - 2017-08-08 04:39 - 000768464 _____ C:\Users\AIRWORX 2\Downloads\Windows10andWindowsServer2016PolicySettings.xlsx
2017-08-08 02:55 - 2017-08-08 02:55 - 000000000 ____D C:\Users\AIRWORX 2\AppData\Roaming\JetBrains
2017-08-08 02:49 - 2017-08-24 04:32 - 000000000 ____D C:\Users\AIRWORX 2\AppData\Local\Microsoft Help
2017-08-08 02:43 - 2017-08-09 11:24 - 000000000 ____D C:\Android
2017-08-08 02:42 - 2017-08-09 11:20 - 000000000 ____D C:\Program Files\Android
2017-08-07 13:01 - 2017-08-07 13:04 - 000790638 _____ C:\TDSSKiller.3.1.0.15_07.08.2017_13.01.55_log.txt
2017-08-07 12:43 - 2017-08-07 12:44 - 000008106 _____ C:\TDSSKiller.3.1.0.15_07.08.2017_12.43.03_log.txt
2017-08-07 12:41 - 2017-08-07 12:41 - 004922400 _____ (AO Kaspersky Lab) C:\Users\AIRWORX 2\Desktop\tdsskiller.exe
2017-08-07 12:25 - 2017-08-07 12:25 - 000000155 _____ C:\WINDOWS\system32\all.txt
2017-08-07 10:00 - 2017-08-07 10:00 - 000879551 _____ C:\Users\AIRWORX 2\Desktop\CryptoSearch.zip
2017-08-04 11:10 - 2017-08-04 14:39 - 000000000 ____D C:\Users\AIRWORX 2\Desktop\AP
2017-08-04 10:48 - 2017-08-17 05:54 - 000000942 _____ C:\Users\Public\Desktop\RogueKiller.lnk
2017-08-04 10:37 - 2017-08-04 10:37 - 000000546 _____ C:\Users\AIRWORX 2\Desktop\Encrypted documents - Copy.zip
2017-08-04 10:01 - 2017-08-04 10:02 - 000047265 _____ C:\Users\AIRWORX 2\Desktop\appcrashview (1).zip
2017-08-04 05:40 - 2017-08-04 09:24 - 000004816 _____ C:\Users\AIRWORX 2\Desktop\links to findings.txt
2017-08-03 20:55 - 2017-08-03 20:55 - 000055111 _____ C:\Users\AIRWORX 2\Desktop\ACFrOgAjZaC8g0bE5UVjMkDU-EGyfCbydESYIcl5Ek-Jk2dgOtZdX5ShW7Uo0TTTXhI7ZV4o60JCCrjfMp-q84aBwoJKcJbRGbK_B2rm9Yaii0wppseh1AkAy87pTKo=.pdf
2017-08-03 12:52 - 2017-08-03 12:52 - 000011327 _____ C:\Users\AIRWORX 2\Desktop\eset scans.txt
2017-08-03 07:53 - 2017-08-03 07:53 - 000333952 _____ (ESET) C:\Users\AIRWORX 2\Downloads\ESETEternalBlueChecker.exe
2017-08-03 07:38 - 2017-08-03 07:38 - 004836307 _____ C:\Users\AIRWORX 2\Downloads\eset_sysrescue_userguide_enu.pdf
2017-08-03 04:01 - 2017-08-26 12:25 - 100401152 _____ C:\WINDOWS\system32\config\SOFTWARE
2017-08-03 03:58 - 2017-08-03 03:59 - 000000000 ____D C:\WINDOWS\Microsoft Antimalware
2017-08-02 15:53 - 2017-08-02 15:53 - 044003024 _____ (Microsoft Corporation) C:\Users\AIRWORX 2\Desktop\Windows-KB890830-x64-V5.50 (1).exe
2017-08-02 10:02 - 2017-08-02 10:02 - 000000000 ____D C:\Users\AIRWORX 2\AppData\Local\LogMeIn
2017-08-02 07:44 - 2017-08-02 07:44 - 000000000 ____D C:\Users\AIRWORX 2\Documents\Security
2017-08-02 07:20 - 2017-08-24 18:28 - 000000000 ____D C:\Users\AIRWORX 2\Documents\LocaleMetaData
2017-08-02 07:19 - 2017-08-02 07:20 - 000069632 _____ C:\Users\AIRWORX 2\Documents\events.evtx
2017-08-02 03:08 - 2017-08-02 03:08 - 145707800 _____ (Microsoft Corporation) C:\Users\AIRWORX 2\Desktop\msert.exe
2017-08-02 03:05 - 2017-08-02 03:05 - 000001174 _____ C:\Users\AIRWORX 2\Desktop\app crash viewer.txt
2017-08-02 03:03 - 2017-08-23 05:22 - 000000469 _____ C:\Users\AIRWORX 2\Desktop\AppCrashView.cfg
2017-08-01 08:19 - 2017-08-01 08:19 - 000011327 _____ C:\Users\AIRWORX 2\Desktop\eset yesterday.txt
2017-08-01 06:18 - 2017-08-22 10:05 - 000000000 ____D C:\Users\AIRWORX 2\Desktop\FRST-OlderVersion
2017-08-01 05:58 - 2017-08-01 05:58 - 000000000 ____D C:\WINDOWS\Panther
2017-07-31 15:33 - 2017-07-31 15:33 - 000000000 ____D C:\Users\AIRWORX 2\AppData\Local\NetworkTiles
2017-07-31 15:25 - 2017-07-31 15:25 - 000000000 ____D C:\Users\AIRWORX 2\AppData\Local\MicrosoftEdge
2017-07-31 13:36 - 2017-07-31 13:36 - 006754944 _____ (ESET spol. s r.o.) C:\Users\AIRWORX 2\Downloads\esetonlinescanner_enu (1).exe
2017-07-28 08:44 - 2017-07-28 08:44 - 000000000 _____ C:\WINDOWS\system32\set
2017-07-28 06:15 - 2017-07-28 06:15 - 000576231 _____ C:\Users\AIRWORX 2\Downloads\DTec13656.pdf
2017-07-28 06:06 - 2017-07-28 06:06 - 000075669 _____ C:\Users\AIRWORX 2\Downloads\COSMIC JUMP (4).pdf
2017-07-28 06:01 - 2017-07-28 06:01 - 000053739 _____ C:\Users\AIRWORX 2\Downloads\HS-2.8.17 #2888 CJump KCity Jan Inv&Rep SH (1).pdf
2017-07-28 05:54 - 2017-07-28 05:54 - 000151083 _____ C:\Users\AIRWORX 2\Downloads\COSMIC JUMP - Inv.pdf
2017-07-28 05:39 - 2017-07-28 06:17 - 000002182 _____ C:\Users\AIRWORX 2\Downloads\data (35).csv
2017-07-28 05:17 - 2017-07-28 05:17 - 000002299 _____ C:\Users\AIRWORX 2\Desktop\Google Chrome.lnk
2017-07-28 03:35 - 2017-07-28 03:35 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Seagate
2017-07-27 07:33 - 2017-07-27 07:33 - 008162248 _____ (Malwarebytes) C:\Users\AIRWORX 2\Downloads\AdwCleaner.exe
2017-07-27 07:33 - 2017-07-27 07:33 - 001790024 _____ (Malwarebytes) C:\Users\AIRWORX 2\Downloads\JRT.exe
2017-07-27 06:25 - 2017-07-27 06:25 - 000995572 _____ C:\Users\AIRWORX 2\Desktop\rel.XML
2017-07-27 06:02 - 2017-07-27 06:02 - 000000000 ____D C:\Users\AIRWORX 2\AppData\Local\.IdentityService
2017-07-27 04:08 - 2017-07-27 04:08 - 000183220 _____ C:\Users\AIRWORX 2\Downloads\Appsdiagnostic10.diagcab
==================== One Month Modified files and folders ========