This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

PC freezes while performing antivirus scan [Solved]

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi guys,

 

While performing a full scan using Avira,my laptop would freeze not even half way through not giving me the possibility

of doing anything other than restarting manually.

I did have the same issue a little while ago but then I did reset my computer to its factory settings and the problem seemed

gone…till now.

 

I would guess the problem to be either a virus or something to do with my hard drive.

By the way,i'm running windows 8.1.

 

Will appreciate any kind of help.

Thank you guys.

 

Hello zizou84 and welcome to the WTT forum.

My name is Satchfan and I would be glad to help you with your computer problem.

Please read the following guidelines which will help to make cleaning your machine easier:

  • please follow all instructions in the order posted
  • please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear
  • all logs/reports, etc. must be posted in Notepad. Please ensure that word wrap is unchecked. In Notepad click Format, uncheck Word wrap if it is checked
  • if you don't understand something, please don't hesitate to ask for clarification before proceeding
  • the fixes are specific to your problem and should only be used for this issue on this machine.
  • please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!

IMPORTANT:

Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested

===================================================

Run Farbar Recovery Scan Tool

Please download Farbar Recovery Scan Tool and save it to your Desktop.

Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.


  • right click to run as administrator (XP users click run after receipt of Windows Security Warning - Open File). When the tool opens click Yes to disclaimer.
  • press Scan button
  • it will produce a log called Frst.txt in the same directory the tool is run from
  • please copy and paste log back here.

The first time the tool is run it generates another log (Addition.txt - also located in the same directory as FRST.exe/FRST64.exe). Please also paste that along with the Frst.txt into your reply.

================================================

Run Security Check

Download Security Check by screen317 from here or here.
 

  • save it to your Desktop.
  • double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • a Notepad document should open automatically called checkup.txt; please post the contents of that document.

NOTE: If you get the following message: UNSUPPORTED OPERATING SYSTEM! ABORTED!, try rebooting the system and then run SecurityCheck again.

Logs to include with next post:

Frst.txt
Addition.txt
Checkup.txt


Thanks

Satchfan

 

Hi Satchfan,

 

I'd like to thank you first for the quick answer as well as the time and effort you're putting into this. It is much appreciated.

So here are the logs you asked me for;

 

 

Frst.txt

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:28-06-2015 01
Ran by [removed] (administrator) on NEO on 30-06-2015 00:32:00
Running from C:\Users\[removed]\Desktop
[removed] Platform: Windows 8.1 Single Language (X64) OS Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(ASUSTeK Computer Inc.) C:\Windows\System32\FBAgent.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\sched.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avguard.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(IvoSoft) C:\Program Files\Classic Shell\ClassicStartMenu.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avgnt.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Antivirus\avshadow.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe
(ASUS) C:\Program Files\ASUS\P4G\BatteryLife.exe
(ASUSTek Computer INC.) C:\ProgramData\AsTouchPanel\AsPatchTouchPanel64.exe
(ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe
(FreeDownloadManager.ORG) C:\Program Files (x86)\Free Download Manager\fdm.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe
(ASUS) C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe
(ASUS) C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnWMI.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLoader.exe
(Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x64\QuickGesture64.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\QuickGesture\x86\QuickGesture.exe
() C:\Program Files (x86)\ASUS\Splendid\ColorUService.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPHelper.exe
(ASUSTeK) C:\Windows\SysWOW64\ACEngSvr.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Microsoft Corporation) C:\Windows\System32\WWAHost.exe
(Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(AsusTek) C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPCenter.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_18_0_0_194.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_18_0_0_194.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM-x32\…\Run: [avgnt] => C:\Program Files (x86)\Avira\Antivirus\avgnt.exe [730416 2015-05-27] (Avira Operations GmbH & Co. KG)
HKU\S-1-5-21-2352947253-3735842710-969423645-1002\…\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8322328 2015-05-08] (Piriform Ltd)
ShellIconOverlayIdentifiers: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} =>  No File
ShellIconOverlayIdentifiers: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} =>  No File
ShellIconOverlayIdentifiers: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} =>  No File
ShellIconOverlayIdentifiers: [AsusWSShellExt_B] -> {6D4133E5-0742-4ADC-8A8C-9303440F7190} => C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.10.123\ASUSWSShellExt64.dll [2012-03-13] (ASUS Cloud Corporation.)
ShellIconOverlayIdentifiers: [AsusWSShellExt_O] -> {64174815-8D98-4CE6-8646-4C039977D808} => C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.10.123\ASUSWSShellExt64.dll [2012-03-13] (ASUS Cloud Corporation.)
ShellIconOverlayIdentifiers: [AsusWSShellExt_U] -> {1C5AB7B1-0B38-4EC4-9093-7FD277E2AF4D} => C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.10.123\ASUSWSShellExt64.dll [2012-03-13] (ASUS Cloud Corporation.)
ShellIconOverlayIdentifiers: [ShareOverlay] -> {594D4122-1F87-41E2-96C7-825FB4796516} => C:\Program Files\Classic Shell\ClassicExplorer64.dll [2015-05-16] (IvoSoft)
ShellIconOverlayIdentifiers-x32: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} =>  No File
ShellIconOverlayIdentifiers-x32: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} =>  No File
ShellIconOverlayIdentifiers-x32: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} =>  No File
ShellIconOverlayIdentifiers-x32: [ShareOverlay] -> {594D4122-1F87-41E2-96C7-825FB4796516} => C:\Program Files\Classic Shell\ClassicExplorer32.dll [2015-05-16] (IvoSoft)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-2352947253-3735842710-969423645-1002\Software\Microsoft\Internet Explorer\Main,Start Page = http://asus13.msn.com
HKU\S-1-5-21-2352947253-3735842710-969423645-1002\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://asus13.msn.com
SearchScopes: HKU\S-1-5-21-2352947253-3735842710-969423645-1002 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2352947253-3735842710-969423645-1002 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: ExplorerBHO Class -> {449D0D6E-2412-4E61-B68F-1CB625CD9E52} -> C:\Program Files\Classic Shell\ClassicExplorer64.dll [2015-05-16] (IvoSoft)
BHO: ClassicIEBHO Class -> {EA801577-E6AD-4BD5-8F71-4BE0154331A4} -> C:\Program Files\Classic Shell\ClassicIEDLL_64.dll [2015-05-16] (IvoSoft)
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-11-16] (Adobe Systems Incorporated)
BHO-x32: ExplorerBHO Class -> {449D0D6E-2412-4E61-B68F-1CB625CD9E52} -> C:\Program Files\Classic Shell\ClassicExplorer32.dll [2015-05-16] (IvoSoft)
BHO-x32: Free Download Manager -> {CC59E0F9-7E43-44FA-9FAA-8377850BF205} -> C:\Program Files (x86)\Free Download Manager\iefdm2.dll [2015-05-15] (FreeDownloadManager.ORG)
BHO-x32: ClassicIEBHO Class -> {EA801577-E6AD-4BD5-8F71-4BE0154331A4} -> C:\Program Files\Classic Shell\ClassicIEDLL_32.dll [2015-05-16] (IvoSoft)
Toolbar: HKLM - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer64.dll [2015-05-16] (IvoSoft)
Toolbar: HKLM-x32 - Classic Explorer Bar - {553891B7-A0D5-4526-BE18-D3CE461D6310} - C:\Program Files\Classic Shell\ClassicExplorer32.dll [2015-05-16] (IvoSoft)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{60D14A45-F049-4BD5-A79F-894E30D870E0}: [DhcpNameServer] 192.168.1.1

FireFox:
========
FF ProfilePath: C:\Users\sofiane\AppData\Roaming\Mozilla\Firefox\Profiles\cowyqxpx.default
FF Homepage: google.fr
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_18_0_0_194.dll [2015-06-24] ()
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_194.dll [2015-06-24] ()
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-09-13] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-06-21] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.27.5\npGoogleUpdate3.dll [2015-06-21] (Google Inc.)
FF Plugin-x32: @TrendMicro.com/FFExtension -> C:\Program Files\Trend Micro\Titanium\UIFramework\Toolbar\firefoxextension\components\npToolbarChrome.dll No File
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Extension: Avira Browser Safety - C:\Users\sofiane\AppData\Roaming\Mozilla\Firefox\Profiles\cowyqxpx.default\Extensions\[removed] [2015-06-21]
FF Extension: AdBlock for Firefox - C:\Users\sofiane\AppData\Roaming\Mozilla\Firefox\Profiles\cowyqxpx.default\Extensions\[removed] [2015-06-21]
FF HKU\S-1-5-21-2352947253-3735842710-969423645-1002\…\Firefox\Extensions: [[removed]] - C:\ProgramData\Free Download Manager\Firefox\Extensions\1.7.5.2
FF Extension: Free Download Manager plugin - C:\ProgramData\Free Download Manager\Firefox\Extensions\1.7.5.2 [2015-06-29]

Chrome:
=======
CHR Profile: C:\Users\sofiane\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\sofiane\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-06-21]
CHR Extension: (Docs) - C:\Users\sofiane\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-06-21]
CHR Extension: (Google Drive) - C:\Users\sofiane\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-06-21]
CHR Extension: (YouTube) - C:\Users\sofiane\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-06-21]
CHR Extension: (TrendMicro BEP Extension) - C:\Users\sofiane\AppData\Local\Google\Chrome\User Data\Default\Extensions\bmiabdepfhhiieiipmeecdmeljggmfee [2015-06-21]
CHR Extension: (Google Search) - C:\Users\sofiane\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-06-21]
CHR Extension: (Google Sheets) - C:\Users\sofiane\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-06-21]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\sofiane\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-06-21]
CHR Extension: (Google Wallet) - C:\Users\sofiane\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-06-21]
CHR Extension: (Gmail) - C:\Users\sofiane\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-06-21]
CHR HKLM\…\Chrome\Extension: [bmiabdepfhhiieiipmeecdmeljggmfee] - No Path Or update_url value
CHR HKLM\…\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - https://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [bmiabdepfhhiieiipmeecdmeljggmfee] - No Path Or update_url value
CHR HKLM-x32\…\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - https://clients2.google.com/service/update2/crx

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R3 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [344064 2014-07-04] (Advanced Micro Devices, Inc.) [File not signed]
S2 AntiVirMailService; C:\Program Files (x86)\Avira\Antivirus\avmailc7.exe [827184 2015-05-27] (Avira Operations GmbH & Co. KG)
R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\Antivirus\sched.exe [450808 2015-05-27] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files (x86)\Avira\Antivirus\avguard.exe [450808 2015-05-27] (Avira Operations GmbH & Co. KG)
S2 AntiVirWebService; C:\Program Files (x86)\Avira\Antivirus\avwebg7.exe [1188360 2015-05-27] (Avira Operations GmbH & Co. KG)
R3 ASUS InstantOn; C:\Program Files (x86)\ASUS\ASUS InstantOn\InsOnSrv.exe [277120 2012-04-13] (ASUS)
R3 Avira.ServiceHost; C:\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe [217280 2015-06-03] (Avira Operations GmbH & Co. KG)
S3 BcmBtRSupport; C:\Windows\system32\BtwRSupportService.exe [2252504 2013-09-04] (Broadcom Corporation.)
S3 BthHFSrv; C:\Windows\System32\BthHFSrv.dll [324608 2014-11-21] (Microsoft Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366520 2015-06-29] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2015-06-29] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S2 AODDriver4.2.0; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [59648 2013-09-20] (Advanced Micro Devices)
R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdW86.sys [91648 2012-08-21] (Advanced Micro Devices)
R3 ATP; C:\Windows\System32\drivers\AsusTP.sys [62848 2012-11-20] (ASUS Corporation)
R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [153256 2015-05-27] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [132656 2015-05-27] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\system32\DRIVERS\avkmgr.sys [28600 2015-05-27] (Avira Operations GmbH & Co. KG)
R2 avnetflt; C:\Windows\system32\DRIVERS\avnetflt.sys [43576 2015-05-27] (Avira Operations GmbH & Co. KG)
R3 bcbtums; C:\Windows\system32\drivers\bcbtums.sys [170712 2013-09-04] (Broadcom Corporation.)
R3 BCM43XX; C:\Windows\system32\DRIVERS\bcmwl63a.sys [8536752 2013-07-01] (Broadcom Corporation)
R3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [226304 2014-11-21] (Microsoft Corporation)
R3 kbfiltr; C:\Windows\System32\drivers\kbfiltr.sys [14992 2012-08-02] ( )
R3 SensorsAlsDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [226304 2014-11-21] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2015-06-29] (Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-06-30 00:32 - 2015-06-30 00:32 - 00015815 _____ C:\Users\sofiane\Desktop\FRST.txt
2015-06-30 00:31 - 2015-06-30 00:32 - 00000000 ____D C:\FRST
2015-06-30 00:28 - 2015-06-30 00:28 - 02112512 _____ (Farbar) C:\Users\sofiane\Desktop\FRST64.exe
2015-06-30 00:26 - 2015-06-30 00:27 - 00852662 _____ C:\Users\sofiane\Desktop\SecurityCheck.exe
2015-06-29 14:21 - 2015-06-30 00:00 - 00000000 ___DC C:\WINDOWS\Panther
2015-06-29 14:20 - 2015-06-29 14:20 - 02819584 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers.dll
2015-06-29 14:20 - 2015-06-29 14:20 - 00000000 ____D C:\Windows.old
2015-06-29 14:19 - 2015-06-29 14:19 - 18823168 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2015-06-29 14:19 - 2015-06-29 14:19 - 15158784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2015-06-29 14:19 - 2015-06-29 14:19 - 04837376 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncEngine.dll
2015-06-29 14:19 - 2015-06-29 14:19 - 02485056 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2015-06-29 14:19 - 2015-06-29 14:19 - 01574400 _____ (Microsoft Corporation) C:\WINDOWS\system32\vssapi.dll
2015-06-29 14:19 - 2015-06-29 14:19 - 01454080 _____ (Microsoft Corporation) C:\WINDOWS\system32\VSSVC.exe
2015-06-29 14:19 - 2015-06-29 14:19 - 01154048 _____ (Microsoft Corporation) C:\WINDOWS\system32\SkyDrive.exe
2015-06-29 14:19 - 2015-06-29 14:19 - 01142272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vssapi.dll
2015-06-29 14:19 - 2015-06-29 14:19 - 01084416 _____ (Microsoft Corporation) C:\WINDOWS\system32\IKEEXT.DLL
2015-06-29 14:19 - 2015-06-29 14:19 - 01027584 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
2015-06-29 14:19 - 2015-06-29 14:19 - 00962216 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll
2015-06-29 14:19 - 2015-06-29 14:19 - 00952896 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll
2015-06-29 14:19 - 2015-06-29 14:19 - 00885760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
2015-06-29 14:19 - 2015-06-29 14:19 - 00845312 _____ (Microsoft Corporation) C:\WINDOWS\system32\BFE.DLL
2015-06-29 14:19 - 2015-06-29 14:19 - 00827392 _____ (Microsoft Corporation) C:\WINDOWS\system32\spoolsv.exe
2015-06-29 14:19 - 2015-06-29 14:19 - 00801584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll
2015-06-29 14:19 - 2015-06-29 14:19 - 00786120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll
2015-06-29 14:19 - 2015-06-29 14:19 - 00733696 _____ (Microsoft Corporation) C:\WINDOWS\system32\SkyDriveTelemetry.dll
2015-06-29 14:19 - 2015-06-29 14:19 - 00713216 _____ (Microsoft Corporation) C:\WINDOWS\system32\nshwfp.dll
2015-06-29 14:19 - 2015-06-29 14:19 - 00702464 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasapi32.dll
2015-06-29 14:19 - 2015-06-29 14:19 - 00658432 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSDApi.dll
2015-06-29 14:19 - 2015-06-29 14:19 - 00657920 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsapi.dll
2015-06-29 14:19 - 2015-06-29 14:19 - 00624640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasapi32.dll
2015-06-29 14:19 - 2015-06-29 14:19 - 00561664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\nshwfp.dll
2015-06-29 14:19 - 2015-06-29 14:19 - 00558080 _____ (Microsoft Corporation) C:\WINDOWS\system32\untfs.dll
2015-06-29 14:19 - 2015-06-29 14:19 - 00555520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSDApi.dll
2015-06-29 14:19 - 2015-06-29 14:19 - 00551232 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vhdmp.sys
2015-06-29 14:19 - 2015-06-29 14:19 - 00514048 _____ (Microsoft Corporation) C:\WINDOWS\system32\DevicePairing.dll
2015-06-29 14:19 - 2015-06-29 14:19 - 00507392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\untfs.dll
2015-06-29 14:19 - 2015-06-29 14:19 - 00498688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dnsapi.dll
2015-06-29 14:19 - 2015-06-29 14:19 - 00473408 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\netio.sys
2015-06-29 14:19 - 2015-06-29 14:19 - 00465408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DevicePairing.dll
2015-06-29 14:19 - 2015-06-29 14:19 - 00428864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\FWPKCLNT.SYS
2015-06-29 14:19 - 2015-06-29 14:19 - 00422400 _____ (Microsoft Corporation) C:\WINDOWS\system32\FWPUCLNT.DLL
2015-06-29 14:19 - 2015-06-29 14:19 - 00420864 _____ (Microsoft Corporation) C:\WINDOWS\system32\vpnike.dll
2015-06-29 14:19 - 2015-06-29 14:19 - 00309760 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSDMon.dll
2015-06-29 14:19 - 2015-06-29 14:19 - 00272384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FWPUCLNT.DLL
2015-06-29 14:19 - 2015-06-29 14:19 - 00252416 _____ (Microsoft Corporation) C:\WINDOWS\system32\dnsrslvr.dll
2015-06-29 14:19 - 2015-06-29 14:19 - 00242176 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinSCard.dll
2015-06-29 14:19 - 2015-06-29 14:19 - 00211968 _____ (Microsoft Corporation) C:\WINDOWS\system32\QSHVHOST.DLL
2015-06-29 14:19 - 2015-06-29 14:19 - 00182784 _____ (Microsoft Corporation) C:\WINDOWS\system32\rascfg.dll
2015-06-29 14:19 - 2015-06-29 14:19 - 00169984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WinSCard.dll
2015-06-29 14:19 - 2015-06-29 14:19 - 00166912 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxAllUserStore.dll
2015-06-29 14:19 - 2015-06-29 14:19 - 00162304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rascfg.dll
2015-06-29 14:19 - 2015-06-29 14:19 - 00155648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\QSHVHOST.DLL
2015-06-29 14:19 - 2015-06-29 14:19 - 00143360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxAllUserStore.dll
2015-06-29 14:19 - 2015-06-29 14:19 - 00136512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wfplwfs.sys
2015-06-29 14:19 - 2015-06-29 14:19 - 00128512 _____ (Microsoft Corporation) C:\WINDOWS\splwow64.exe
2015-06-29 14:19 - 2015-06-29 14:19 - 00128000 _____ (Microsoft Corporation) C:\WINDOWS\system32\QSVRMGMT.DLL
2015-06-29 14:19 - 2015-06-29 14:19 - 00112640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rasl2tp.sys
2015-06-29 14:19 - 2015-06-29 14:19 - 00108544 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\i8042prt.sys
2015-06-29 14:19 - 2015-06-29 14:19 - 00096768 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\agilevpn.sys
2015-06-29 14:19 - 2015-06-29 14:19 - 00094208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\QSVRMGMT.DLL
2015-06-29 14:19 - 2015-06-29 14:19 - 00086336 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pdc.sys
2015-06-29 14:19 - 2015-06-29 14:19 - 00080896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wanarp.sys
2015-06-29 14:19 - 2015-06-29 14:19 - 00077824 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasdiag.dll
2015-06-29 14:19 - 2015-06-29 14:19 - 00074752 _____ (Microsoft Corporation) C:\WINDOWS\system32\vsstrace.dll
2015-06-29 14:19 - 2015-06-29 14:19 - 00072192 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndproxy.sys
2015-06-29 14:19 - 2015-06-29 14:19 - 00061440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasdiag.dll
2015-06-29 14:19 - 2015-06-29 14:19 - 00059712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\kbdclass.sys
2015-06-29 14:19 - 2015-06-29 14:19 - 00058176 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dam.sys
2015-06-29 14:19 - 2015-06-29 14:19 - 00055296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vsstrace.dll
2015-06-29 14:19 - 2015-06-29 14:19 - 00051008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mouclass.sys
2015-06-29 14:19 - 2015-06-29 14:19 - 00048128 _____ (Microsoft Corporation) C:\WINDOWS\system32\kmddsp.tsp
2015-06-29 14:19 - 2015-06-29 14:19 - 00043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasmxs.dll
2015-06-29 14:19 - 2015-06-29 14:19 - 00039744 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\intelpep.sys
2015-06-29 14:19 - 2015-06-29 14:19 - 00039424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kmddsp.tsp
2015-06-29 14:19 - 2015-06-29 14:19 - 00033280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasmxs.dll
2015-06-29 14:19 - 2015-06-29 14:19 - 00032256 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\kbdhid.sys
2015-06-29 14:19 - 2015-06-29 14:19 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasser.dll
2015-06-29 14:19 - 2015-06-29 14:19 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mouhid.sys
2015-06-29 14:19 - 2015-06-29 14:19 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sermouse.sys
2015-06-29 14:19 - 2015-06-29 14:19 - 00024576 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndistapi.sys
2015-06-29 14:19 - 2015-06-29 14:19 - 00022528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasser.dll
2015-06-29 14:19 - 2015-06-29 14:19 - 00016896 _____ (Microsoft Corporation) C:\WINDOWS\system32\eventcls.dll
2015-06-29 14:19 - 2015-06-29 14:19 - 00015360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eventcls.dll
2015-06-29 14:17 - 2015-06-29 14:17 - 04417536 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbgeng.dll
2015-06-29 14:17 - 2015-06-29 14:17 - 02985984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbgeng.dll
2015-06-29 14:17 - 2015-06-29 14:17 - 01491456 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbghelp.dll
2015-06-29 14:17 - 2015-06-29 14:17 - 01207296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbghelp.dll
2015-06-29 14:17 - 2015-06-29 14:17 - 00535640 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll
2015-06-29 14:17 - 2015-06-29 14:17 - 00531616 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll
2015-06-29 14:17 - 2015-06-29 14:17 - 00448792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wer.dll
2015-06-29 14:17 - 2015-06-29 14:17 - 00413248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Faultrep.dll
2015-06-29 14:17 - 2015-06-29 14:17 - 00372408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Faultrep.dll
2015-06-29 14:17 - 2015-06-29 14:17 - 00229888 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2015-06-29 14:17 - 2015-06-29 14:17 - 00108944 _____ (Microsoft Corporation) C:\WINDOWS\system32\EncDump.dll
2015-06-29 14:17 - 2015-06-29 14:17 - 00038264 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFaultSecure.exe
2015-06-29 14:17 - 2015-06-29 14:17 - 00033584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerFaultSecure.exe
2015-06-29 14:16 - 2015-06-29 14:16 - 00445440 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhotoMetadataHandler.dll
2015-06-29 14:16 - 2015-06-29 14:16 - 00364544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PhotoMetadataHandler.dll
2015-06-29 14:16 - 2015-06-29 14:16 - 00316416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\udfs.sys
2015-06-29 14:15 - 2015-06-29 14:15 - 02171904 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlowUI.dll
2015-06-29 14:15 - 2015-06-29 14:15 - 01090048 _____ (Microsoft Corporation) C:\WINDOWS\system32\MrmCoreR.dll
2015-06-29 14:15 - 2015-06-29 14:15 - 00791040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MrmCoreR.dll
2015-06-29 14:15 - 2015-06-29 14:15 - 00672984 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDMAgent.exe
2015-06-29 14:15 - 2015-06-29 14:15 - 00463872 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.Handlers.dll
2015-06-29 14:15 - 2015-06-29 14:15 - 00275968 _____ (Microsoft Corporation) C:\WINDOWS\system32\authz.dll
2015-06-29 14:15 - 2015-06-29 14:15 - 00273240 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlows.exe
2015-06-29 14:15 - 2015-06-29 14:15 - 00180224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authz.dll
2015-06-29 14:15 - 2015-06-29 14:15 - 00116736 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsDatabase.dll
2015-06-29 14:14 - 2015-06-29 14:14 - 24917504 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2015-06-29 14:14 - 2015-06-29 14:14 - 19607040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2015-06-29 14:14 - 2015-06-29 14:14 - 14404096 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2015-06-29 14:14 - 2015-06-29 14:14 - 12829696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2015-06-29 14:14 - 2015-06-29 14:14 - 06026240 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2015-06-29 14:14 - 2015-06-29 14:14 - 04305920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2015-06-29 14:14 - 2015-06-29 14:14 - 02885632 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2015-06-29 14:14 - 2015-06-29 14:14 - 02865152 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll
2015-06-29 14:14 - 2015-06-29 14:14 - 02426880 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2015-06-29 14:14 - 2015-06-29 14:14 - 02278912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2015-06-29 14:14 - 2015-06-29 14:14 - 02125824 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2015-06-29 14:14 - 2015-06-29 14:14 - 02052608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2015-06-29 14:14 - 2015-06-29 14:14 - 01950720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2015-06-29 14:14 - 2015-06-29 14:14 - 01545728 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2015-06-29 14:14 - 2015-06-29 14:14 - 01309696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2015-06-29 14:14 - 2015-06-29 14:14 - 01042944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll
2015-06-29 14:14 - 2015-06-29 14:14 - 01032704 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll
2015-06-29 14:14 - 2015-06-29 14:14 - 00880128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcomm.dll
2015-06-29 14:14 - 2015-06-29 14:14 - 00816640 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2015-06-29 14:14 - 2015-06-29 14:14 - 00814080 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll
2015-06-29 14:14 - 2015-06-29 14:14 - 00801280 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2015-06-29 14:14 - 2015-06-29 14:14 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2015-06-29 14:14 - 2015-06-29 14:14 - 00710144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2015-06-29 14:14 - 2015-06-29 14:14 - 00689152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2015-06-29 14:14 - 2015-06-29 14:14 - 00664064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2015-06-29 14:14 - 2015-06-29 14:14 - 00633856 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieui.dll
2015-06-29 14:14 - 2015-06-29 14:14 - 00620032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll
2015-06-29 14:14 - 2015-06-29 14:14 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2015-06-29 14:14 - 2015-06-29 14:14 - 00503808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2015-06-29 14:14 - 2015-06-29 14:14 - 00417792 _____ (Microsoft Corporation) C:\WINDOWS\system32\html.iec
2015-06-29 14:14 - 2015-06-29 14:14 - 00374272 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2015-06-29 14:14 - 2015-06-29 14:14 - 00341504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\html.iec
2015-06-29 14:14 - 2015-06-29 14:14 - 00327168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2015-06-29 14:14 - 2015-06-29 14:14 - 00316928 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll
2015-06-29 14:14 - 2015-06-29 14:14 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll
2015-06-29 14:14 - 2015-06-29 14:14 - 00262144 _____ (Microsoft Corporation) C:\WINDOWS\system32\webcheck.dll
2015-06-29 14:14 - 2015-06-29 14:14 - 00145408 _____ (Microsoft Corporation) C:\WINDOWS\system32\iepeers.dll
2015-06-29 14:14 - 2015-06-29 14:14 - 00128000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iepeers.dll
2015-06-29 14:14 - 2015-06-29 14:14 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2015-06-29 14:14 - 2015-06-29 14:14 - 00076288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll
2015-06-29 14:13 - 2015-06-29 14:13 - 01763352 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecs.dll
2015-06-29 14:13 - 2015-06-29 14:13 - 01488040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecs.dll
2015-06-29 14:13 - 2015-06-29 14:13 - 00788680 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleaut32.dll
2015-06-29 14:13 - 2015-06-29 14:13 - 00602776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleaut32.dll
2015-06-29 14:12 - 2015-06-29 14:12 - 01249280 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll
2015-06-29 14:12 - 2015-06-29 14:12 - 01018880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll
2015-06-29 14:12 - 2015-06-29 14:12 - 00971776 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSShared.dll
2015-06-29 14:12 - 2015-06-29 14:12 - 00811008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WSShared.dll
2015-06-29 14:12 - 2015-06-29 14:12 - 00274944 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2015-06-29 14:12 - 2015-06-29 14:12 - 00210944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2015-06-29 14:11 - 2015-06-29 14:11 - 00186368 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpapisrv.dll
2015-06-29 14:11 - 2015-06-29 14:11 - 00124112 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll
2015-06-29 14:11 - 2015-06-29 14:11 - 00102608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2015-06-29 14:09 - 2015-06-29 14:09 - 03547648 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpcorets.dll
2015-06-29 14:09 - 2015-06-29 14:09 - 01113920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys
2015-06-29 14:09 - 2015-06-29 14:09 - 00429568 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll
2015-06-29 14:09 - 2015-06-29 14:09 - 00391680 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlasvc.dll
2015-06-29 14:09 - 2015-06-29 14:09 - 00360448 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncsi.dll
2015-06-29 14:09 - 2015-06-29 14:09 - 00358912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schannel.dll
2015-06-29 14:09 - 2015-06-29 14:09 - 00131584 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpudd.dll
2015-06-29 14:09 - 2015-06-29 14:09 - 00057856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthhfenum.sys
2015-06-29 14:09 - 2015-06-29 14:09 - 00046456 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockScreenContentServer.exe
2015-06-29 14:08 - 2015-06-29 14:08 - 01970432 _____ (Microsoft Corporation) C:\WINDOWS\system32\crypt32.dll
2015-06-29 14:08 - 2015-06-29 14:08 - 01612992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\crypt32.dll
2015-06-29 14:08 - 2015-06-29 14:08 - 01091072 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll
2015-06-29 14:08 - 2015-06-29 14:08 - 00864256 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32spl.dll
2015-06-29 14:08 - 2015-06-29 14:08 - 00477184 _____ (Microsoft Corporation) C:\WINDOWS\system32\puiobj.dll
2015-06-29 14:08 - 2015-06-29 14:08 - 00367104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\puiobj.dll
2015-06-29 14:08 - 2015-06-29 14:08 - 00346112 _____ (Microsoft Corporation) C:\WINDOWS\system32\eappcfg.dll
2015-06-29 14:08 - 2015-06-29 14:08 - 00339456 _____ (Microsoft Corporation) C:\WINDOWS\system32\eapphost.dll
2015-06-29 14:08 - 2015-06-29 14:08 - 00331776 _____ (Microsoft Corporation) C:\WINDOWS\system32\eapp3hst.dll
2015-06-29 14:08 - 2015-06-29 14:08 - 00309760 _____ (Microsoft Corporation) C:\WINDOWS\system32\compstui.dll
2015-06-29 14:08 - 2015-06-29 14:08 - 00278016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eappcfg.dll
2015-06-29 14:08 - 2015-06-29 14:08 - 00266752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eapphost.dll
2015-06-29 14:08 - 2015-06-29 14:08 - 00264000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdFilter.sys
2015-06-29 14:08 - 2015-06-29 14:08 - 00250880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eapp3hst.dll
2015-06-29 14:08 - 2015-06-29 14:08 - 00114496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdNisDrv.sys
2015-06-29 14:08 - 2015-06-29 14:08 - 00102912 _____ (Microsoft Corporation) C:\WINDOWS\system32\eappgnui.dll
2015-06-29 14:08 - 2015-06-29 14:08 - 00091648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eappgnui.dll
2015-06-29 14:08 - 2015-06-29 14:08 - 00044024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdBoot.sys
2015-06-29 14:08 - 2015-06-29 14:08 - 00014848 _____ (Microsoft Corporation) C:\WINDOWS\system32\winshfhc.dll
2015-06-29 14:08 - 2015-06-29 14:08 - 00012800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winshfhc.dll
2015-06-29 14:07 - 2015-06-29 14:07 - 07476032 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2015-06-29 14:07 - 2015-06-29 14:07 - 01733952 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2015-06-29 14:07 - 2015-06-29 14:07 - 01498872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2015-06-29 14:07 - 2015-06-29 14:07 - 00950784 _____ (Microsoft Corporation) C:\WINDOWS\system32\tdh.dll
2015-06-29 14:07 - 2015-06-29 14:07 - 00749568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tdh.dll
2015-06-29 14:07 - 2015-06-29 14:07 - 00653824 _____ (Microsoft Corporation) C:\WINDOWS\system32\comctl32.dll
2015-06-29 14:07 - 2015-06-29 14:07 - 00549888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comctl32.dll
2015-06-29 14:07 - 2015-06-29 14:07 - 00411648 _____ (Microsoft Corporation) C:\WINDOWS\system32\tracerpt.exe
2015-06-29 14:07 - 2015-06-29 14:07 - 00402432 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMPhoto.dll
2015-06-29 14:07 - 2015-06-29 14:07 - 00377152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\clfs.sys
2015-06-29 14:07 - 2015-06-29 14:07 - 00369152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tracerpt.exe
2015-06-29 14:07 - 2015-06-29 14:07 - 00360480 _____ (Microsoft Corporation) C:\WINDOWS\system32\sechost.dll
2015-06-29 14:07 - 2015-06-29 14:07 - 00357376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMPhoto.dll
2015-06-29 14:07 - 2015-06-29 14:07 - 00285184 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64.dll
2015-06-29 14:07 - 2015-06-29 14:07 - 00257216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sechost.dll
2015-06-29 14:07 - 2015-06-29 14:07 - 00246272 _____ (Microsoft Corporation) C:\WINDOWS\system32\microsoft-windows-system-events.dll
2015-06-29 14:07 - 2015-06-29 14:07 - 00075264 _____ (Microsoft Corporation) C:\WINDOWS\system32\clfsw32.dll
2015-06-29 14:07 - 2015-06-29 14:07 - 00058880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\clfsw32.dll
2015-06-29 14:07 - 2015-06-29 14:07 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64cpu.dll
2015-06-29 14:07 - 2015-06-29 14:07 - 00000000 ___SD C:\WINDOWS\SysWOW64\GWX
2015-06-29 14:07 - 2015-06-29 14:07 - 00000000 ___SD C:\WINDOWS\system32\GWX
2015-06-29 14:06 - 2015-06-29 14:06 - 01441792 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2015-06-29 14:06 - 2015-06-29 14:06 - 00561928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2015-06-29 14:06 - 2015-06-29 14:06 - 00513488 _____ C:\WINDOWS\SysWOW64\locale.nls
2015-06-29 14:06 - 2015-06-29 14:06 - 00513488 _____ C:\WINDOWS\system32\locale.nls
2015-06-29 14:06 - 2015-06-29 14:06 - 00445440 _____ (Microsoft Corporation) C:\WINDOWS\system32\certcli.dll
2015-06-29 14:06 - 2015-06-29 14:06 - 00358912 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
2015-06-29 14:06 - 2015-06-29 14:06 - 00324096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certcli.dll
2015-06-29 14:06 - 2015-06-29 14:06 - 00301056 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
2015-06-29 14:06 - 2015-06-29 14:06 - 00239424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys
2015-06-29 14:06 - 2015-06-29 14:06 - 00154432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsd.sys
2015-06-29 14:06 - 2015-06-29 14:06 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSWbPrxy.exe
2015-06-29 14:06 - 2015-06-29 14:06 - 00080384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ahcache.sys
2015-06-29 14:06 - 2015-06-29 14:06 - 00044032 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2015-06-29 14:06 - 2015-06-29 14:06 - 00035840 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
2015-06-29 14:05 - 2015-06-29 14:05 - 01385256 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll
2015-06-29 14:05 - 2015-06-29 14:05 - 01124352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll
2015-06-29 14:05 - 2015-06-29 14:05 - 00177984 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksecpkg.sys
2015-06-29 14:04 - 2015-06-29 14:04 - 04298240 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_47.dll
2015-06-29 14:04 - 2015-06-29 14:04 - 03551744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_47.dll
2015-06-29 14:04 - 2015-06-29 14:04 - 02773504 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll
2015-06-29 14:04 - 2015-06-29 14:04 - 02459136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll
2015-06-29 14:04 - 2015-06-29 14:04 - 02067968 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpdshext.dll
2015-06-29 14:04 - 2015-06-29 14:04 - 01969664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wpdshext.dll
2015-06-29 14:04 - 2015-06-29 14:04 - 01488896 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfc42u.dll
2015-06-29 14:04 - 2015-06-29 14:04 - 01464832 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfc42.dll
2015-06-29 14:04 - 2015-06-29 14:04 - 01230336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfc42u.dll
2015-06-29 14:04 - 2015-06-29 14:04 - 01204224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfc42.dll
2015-06-29 14:04 - 2015-06-29 14:04 - 00780800 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsm.dll
2015-06-29 14:04 - 2015-06-29 14:04 - 00203264 _____ (Microsoft Corporation) C:\WINDOWS\system32\ubpm.dll
2015-06-29 14:04 - 2015-06-29 14:04 - 00035840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\atlthunk.dll
2015-06-29 14:03 - 2015-06-29 14:03 - 01696256 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtsvc.dll
2015-06-29 14:03 - 2015-06-29 14:03 - 00410128 _____ (Microsoft Corporation) C:\WINDOWS\system32\services.exe
2015-06-29 14:03 - 2015-06-29 14:03 - 00325464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS
2015-06-29 14:03 - 2015-06-29 14:03 - 00158720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rgb9rast.dll
2015-06-29 14:03 - 2015-06-29 14:03 - 00075264 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorageContextHandler.dll
2015-06-29 14:03 - 2015-06-29 14:03 - 00060928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StorageContextHandler.dll
2015-06-29 14:03 - 2015-06-29 14:03 - 00034304 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceSetupStatusProvider.dll
2015-06-29 14:03 - 2015-06-29 14:03 - 00028672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DeviceSetupStatusProvider.dll
2015-06-29 14:02 - 2015-06-29 14:02 - 03678720 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2015-06-29 14:02 - 2015-06-29 14:02 - 02373632 _____ (Microsoft Corporation) C:\WINDOWS\system32\wucltux.dll
2015-06-29 14:02 - 2015-06-29 14:02 - 02162176 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll
2015-06-29 14:02 - 2015-06-29 14:02 - 01812992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRH.dll
2015-06-29 14:02 - 2015-06-29 14:02 - 00933888 _____ (Microsoft Corporation) C:\WINDOWS\system32\calc.exe
2015-06-29 14:02 - 2015-06-29 14:02 - 00891392 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2015-06-29 14:02 - 2015-06-29 14:02 - 00816128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\calc.exe
2015-06-29 14:02 - 2015-06-29 14:02 - 00721920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2015-06-29 14:02 - 2015-06-29 14:02 - 00408064 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUSettingsProvider.dll
2015-06-29 14:02 - 2015-06-29 14:02 - 00267264 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinSetupUI.dll
2015-06-29 14:02 - 2015-06-29 14:02 - 00200192 _____ (Microsoft Corporation) C:\WINDOWS\system32\storewuauth.dll
2015-06-29 14:02 - 2015-06-29 14:02 - 00172544 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Input.Inking.dll
2015-06-29 14:02 - 2015-06-29 14:02 - 00141824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Input.Inking.dll
2015-06-29 14:02 - 2015-06-29 14:02 - 00140288 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuwebv.dll
2015-06-29 14:02 - 2015-06-29 14:02 - 00133256 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2015-06-29 14:02 - 2015-06-29 14:02 - 00124928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuwebv.dll
2015-06-29 14:02 - 2015-06-29 14:02 - 00095744 _____ (Microsoft Corporation) C:\WINDOWS\system32\wudriver.dll
2015-06-29 14:02 - 2015-06-29 14:02 - 00081920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wudriver.dll
2015-06-29 14:02 - 2015-06-29 14:02 - 00066048 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups.dll
2015-06-29 14:02 - 2015-06-29 14:02 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups2.dll
2015-06-29 14:02 - 2015-06-29 14:02 - 00035840 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapp.exe
2015-06-29 14:02 - 2015-06-29 14:02 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapp.exe
2015-06-29 14:02 - 2015-06-29 14:02 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wups.dll
2015-06-29 14:02 - 2015-06-29 14:02 - 00017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaext.dll
2015-06-29 14:02 - 2015-06-29 14:02 - 00015360 _____ (Microsoft Corporation) C:\WINDOWS\system32\wu.upgrade.ps.dll
2015-06-29 14:01 - 2015-06-29 14:01 - 04177920 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2015-06-29 14:01 - 2015-06-29 14:01 - 03097600 _____ (Microsoft Corporation) C:\WINDOWS\system32\msftedit.dll
2015-06-29 14:01 - 2015-06-29 14:01 - 02483712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msftedit.dll
2015-06-29 14:01 - 2015-06-29 14:01 - 00723072 _____ (Microsoft Corporation) C:\WINDOWS\system32\SHCore.dll
2015-06-29 14:01 - 2015-06-29 14:01 - 00560392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SHCore.dll
2015-06-29 14:01 - 2015-06-29 14:01 - 00259072 _____ (Microsoft Corporation) C:\WINDOWS\system32\pku2u.dll
2015-06-29 14:01 - 2015-06-29 14:01 - 00225280 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll
2015-06-29 14:01 - 2015-06-29 14:01 - 00208896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\pku2u.dll
2015-06-29 14:01 - 2015-06-29 14:01 - 00140800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxdav.sys
2015-06-29 13:59 - 2015-06-29 13:59 - 02256896 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2015-06-29 13:59 - 2015-06-29 13:59 - 01996800 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWrite.dll
2015-06-29 13:59 - 2015-06-29 13:59 - 01943040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2015-06-29 13:59 - 2015-06-29 13:59 - 01560576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWrite.dll
2015-06-29 13:59 - 2015-06-29 13:59 - 01387008 _____ (Microsoft Corporation) C:\WINDOWS\system32\FntCache.dll
2015-06-29 13:59 - 2015-06-29 13:59 - 00538624 _____ (Microsoft Corporation) C:\WINDOWS\system32\scesrv.dll
2015-06-29 13:59 - 2015-06-29 13:59 - 00467776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBHUB3.SYS
2015-06-29 13:59 - 2015-06-29 13:59 - 00410336 _____ C:\WINDOWS\system32\ApnDatabase.xml
2015-06-29 13:59 - 2015-06-29 13:59 - 00393728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\scesrv.dll
2015-06-29 13:58 - 2015-06-29 13:58 - 03633664 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll
2015-06-29 13:58 - 2015-06-29 13:58 - 02749952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll
2015-06-29 13:58 - 2015-06-29 13:58 - 02551808 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssrch.dll
2015-06-29 13:58 - 2015-06-29 13:58 - 01920000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssrch.dll
2015-06-29 13:58 - 2015-06-29 13:58 - 00903168 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchIndexer.exe
2015-06-29 13:58 - 2015-06-29 13:58 - 00774144 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssvp.dll
2015-06-29 13:58 - 2015-06-29 13:58 - 00710144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchIndexer.exe
2015-06-29 13:58 - 2015-06-29 13:58 - 00699392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssvp.dll
2015-06-29 13:58 - 2015-06-29 13:58 - 00468480 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssph.dll
2015-06-29 13:58 - 2015-06-29 13:58 - 00391680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssph.dll
2015-06-29 13:58 - 2015-06-29 13:58 - 00337408 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchProtocolHost.exe
2015-06-29 13:58 - 2015-06-29 13:58 - 00272896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchProtocolHost.exe
2015-06-29 13:58 - 2015-06-29 13:58 - 00248832 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssphtb.dll
2015-06-29 13:56 - 2015-06-29 13:56 - 02501368 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2015-06-29 13:56 - 2015-06-29 13:56 - 02207488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2015-06-29 13:56 - 2015-06-29 13:56 - 00991552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\http.sys
2015-06-29 13:56 - 2015-06-29 13:56 - 00222208 _____ (Microsoft Corporation) C:\WINDOWS\system32\rastapi.dll
2015-06-29 13:56 - 2015-06-29 13:56 - 00207872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rastapi.dll
2015-06-29 13:56 - 2015-06-29 13:56 - 00146432 _____ (Microsoft Corporation) C:\WINDOWS\system32\poqexec.exe
2015-06-29 13:56 - 2015-06-29 13:56 - 00129536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\poqexec.exe
2015-06-29 13:55 - 2015-06-29 13:55 - 00720384 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2015-06-29 13:55 - 2015-06-29 13:55 - 00490496 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtmsft.dll
2015-06-29 13:55 - 2015-06-29 13:55 - 00418304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtmsft.dll
2015-06-29 13:55 - 2015-06-29 13:55 - 00230400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webcheck.dll
2015-06-29 13:55 - 2015-06-29 13:55 - 00107520 _____ (Microsoft Corporation) C:\WINDOWS\system32\inseng.dll
2015-06-29 13:55 - 2015-06-29 13:55 - 00088064 _____ (Microsoft Corporation) C:\WINDOWS\system32\MshtmlDac.dll
2015-06-29 13:55 - 2015-06-29 13:55 - 00064000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MshtmlDac.dll
2015-06-29 13:53 - 2015-06-29 13:53 - 22291584 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2015-06-29 13:53 - 2015-06-29 13:53 - 19731824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2015-06-29 13:53 - 2015-06-29 13:53 - 00347136 _____ (Microsoft Corporation) C:\WINDOWS\system32\photowiz.dll
2015-06-29 13:53 - 2015-06-29 13:53 - 00290816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\photowiz.dll
2015-06-29 13:53 - 2015-06-29 13:53 - 00025600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\setup16.exe
2015-06-29 13:53 - 2015-06-29 13:53 - 00016896 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntvdm64.dll
2015-06-29 13:53 - 2015-06-29 13:53 - 00014336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntvdm64.dll
2015-06-29 13:53 - 2015-06-29 13:53 - 00008704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\instnm.exe
2015-06-29 13:53 - 2015-06-29 13:53 - 00005632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wow32.dll
2015-06-29 13:53 - 2015-06-29 13:53 - 00004096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user.exe
2015-06-29 13:52 - 2015-06-29 13:52 - 00262144 _____ C:\WINDOWS\system32\config\userdiff
2015-06-29 13:50 - 2015-06-29 13:50 - 00000000 ____D C:\Program Files\Reference Assemblies
2015-06-29 13:50 - 2015-06-29 13:50 - 00000000 ____D C:\Program Files\MSBuild
2015-06-29 13:50 - 2015-06-29 13:50 - 00000000 ____D C:\Program Files (x86)\Reference Assemblies
2015-06-29 13:50 - 2015-06-29 13:50 - 00000000 ____D C:\Program Files (x86)\MSBuild
2015-06-29 13:49 - 2015-06-29 13:49 - 00024576 _____ (Microsoft Corporation) C:\WINDOWS\system32\sdbinst.exe
2015-06-29 13:49 - 2015-06-29 13:49 - 00021504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sdbinst.exe
2015-06-29 13:49 - 2013-08-03 06:48 - 01166520 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationNative_v0300.dll
2015-06-29 13:49 - 2013-08-03 06:48 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\system32\TsWpfWrp.exe
2015-06-29 13:49 - 2013-08-03 06:41 - 00778936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationNative_v0300.dll
2015-06-29 13:49 - 2013-08-03 06:41 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TsWpfWrp.exe
2015-06-29 12:47 - 2015-06-29 12:47 - 00000258 __RSH C:\ProgramData\ntuser.pol
2015-06-29 12:47 - 2015-06-29 12:47 - 00000000 ____D C:\Users\sofiane\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center
2015-06-29 12:47 - 2015-06-29 12:47 - 00000000 ____D C:\Users\sofiane\AppData\Local\AMD
2015-06-29 11:56 - 2015-06-29 11:56 - 00000000 ____D C:\WINDOWS\LastGood.Tmp
2015-06-29 11:54 - 2015-06-29 12:49 - 00000000 ___RD C:\Users\sofiane\OneDrive
2015-06-29 11:54 - 2015-06-29 11:54 - 00000000 ___HD C:\OneDriveTemp
2015-06-29 11:50 - 2015-06-29 11:50 - 00001444 _____ C:\Users\sofiane\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2015-06-29 11:49 - 2015-06-29 11:49 - 00000000 ____D C:\Users\sofiane\AppData\Roaming\ATI
2015-06-29 11:49 - 2015-06-29 11:49 - 00000000 ____D C:\Users\sofiane\AppData\Local\ATI
2015-06-29 11:49 - 2015-06-29 11:49 - 00000000 ____D C:\ProgramData\ATI
2015-06-29 11:48 - 2015-06-29 11:48 - 00000020 ___SH C:\Users\sofiane\ntuser.ini
2015-06-29 04:53 - 2015-06-29 04:53 - 00022744 _____ C:\WINDOWS\system32\emptyregdb.dat
2015-06-29 04:46 - 2015-06-29 04:54 - 00006629 _____ C:\WINDOWS\comsetup.log
2015-06-29 04:40 - 2015-06-29 04:40 - 00001547 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2015-06-29 04:37 - 2015-06-29 04:37 - 00000000 ____D C:\WINDOWS\system32\config\bbimigrate
2015-06-29 04:36 - 2015-06-29 12:44 - 00000000 ____D C:\Users\sofiane
2015-06-29 04:36 - 2015-06-29 04:36 - 00000000 ___RD C:\Users\sofiane\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-06-29 04:36 - 2014-11-21 14:18 - 00000000 ___RD C:\Users\sofiane\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-06-29 04:36 - 2014-11-21 14:18 - 00000000 ___RD C:\Users\sofiane\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2015-06-29 04:36 - 2014-11-21 06:52 - 00000369 _____ C:\Users\sofiane\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pictures.lnk
2015-06-29 04:36 - 2014-11-21 06:52 - 00000369 _____ C:\Users\sofiane\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Documents.lnk
2015-06-29 04:36 - 2013-08-22 17:36 - 00000000 ____D C:\Users\sofiane\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-06-29 04:35 - 2015-06-29 04:54 - 00020958 _____ C:\WINDOWS\diagwrn.xml
2015-06-29 04:35 - 2015-06-29 04:54 - 00020958 _____ C:\WINDOWS\diagerr.xml
2015-06-29 04:27 - 2015-06-29 04:27 - 00060601 _____ C:\WINDOWS\SysWOW64\CCCInstall_201506290427247161.log
2015-06-29 04:27 - 2015-06-29 04:27 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center
2015-06-29 04:26 - 2015-06-29 04:38 - 00000000 ____D C:\ProgramData\AMD
2015-06-29 04:26 - 2015-06-29 04:26 - 00000000 ____D C:\Program Files\ATI Technologies
2015-06-29 04:26 - 2015-06-29 04:26 - 00000000 ____D C:\Program Files (x86)\ATI Technologies
2015-06-29 04:25 - 2015-06-29 12:49 - 00382389 _____ C:\WINDOWS\WindowsUpdate.log
2015-06-29 04:25 - 2015-06-29 04:25 - 00079962 _____ C:\WINDOWS\system32\Drivers\RTWAVES30.dat
2015-06-29 04:25 - 2015-06-29 04:25 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_SensorsAlsDriver_01_11_00.Wdf
2015-06-29 04:25 - 2015-06-29 04:25 - 00000000 ____D C:\WINDOWS\SysWOW64\RTCOM
2015-06-29 04:25 - 2015-06-29 04:25 - 00000000 ____D C:\Program Files\Realtek
2015-06-29 04:25 - 2015-06-29 04:25 - 00000000 ____D C:\Program Files\Common Files\ATI Technologies
2015-06-29 04:25 - 2015-06-29 04:25 - 00000000 ____D C:\Program Files\AMD
2015-06-29 04:25 - 2015-06-29 04:25 - 00000000 ____D C:\AMD
2015-06-29 04:25 - 2015-06-29 04:25 - 00000000 _____ C:\WINDOWS\ativpsrm.bin
2015-06-29 02:56 - 2015-06-29 02:56 - 00000000 ____D C:\ProgramData\Free Download Manager
2015-06-28 12:23 - 2015-06-29 12:43 - 00000000 ____D C:\WINDOWS\system32\AutoUpdateLicense
2015-06-28 00:36 - 2015-06-29 01:07 - 00000000 ____D C:\Users\sofiane\Winamax
2015-06-25 12:56 - 2015-06-25 13:19 - 00000000 ____D C:\Users\sofiane\Desktop\Suits.S05E01.720p.HDTV.x264-KILLERS[rarbg]
2015-06-24 17:05 - 2015-06-24 17:05 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
2015-06-23 18:27 - 2015-03-04 09:26 - 00011105 _____ C:\WINDOWS\system32\AutoconfigV2.cab
2015-06-23 12:55 - 2015-06-23 12:57 - 00000000 ____D C:\Users\sofiane\Documents\Winamax Poker
2015-06-23 12:54 - 2015-06-23 12:54 - 00000000 ____D C:\Users\sofiane\AppData\Roaming\wam.04351C371E530C3762CBA45FA283ED972DCDEFB6.1
2015-06-22 19:24 - 2015-06-22 19:28 - 00000000 ____D C:\WINDOWS\system32\MRT
2015-06-22 19:24 - 2015-05-27 00:04 - 140135120 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2015-06-22 17:33 - 2013-05-04 06:51 - 00014848 _____ (Microsoft) C:\WINDOWS\system32\rars.rs
2015-06-22 17:33 - 2013-05-04 06:10 - 00014848 _____ (Microsoft) C:\WINDOWS\SysWOW64\rars.rs
2015-06-22 05:53 - 2015-06-29 15:45 - 00000000 ____D C:\Users\sofiane\Desktop\series
2015-06-22 00:34 - 2015-06-29 14:21 - 00000000 __SHD C:\Recovery
2015-06-22 00:16 - 2015-06-22 00:16 - 00000000 ____D C:\Users\sofiane\AppData\Roaming\Macromedia
2015-06-22 00:16 - 2015-06-22 00:16 - 00000000 ____D C:\Users\sofiane\AppData\Local\Macromedia
2015-06-22 00:12 - 2015-06-22 00:12 - 00000000 ____D C:\Users\sofiane\Documents\Bluetooth Exchange Folder
2015-06-21 23:38 - 2015-06-21 23:38 - 00000000 ____D C:\sources
2015-06-21 23:04 - 2015-06-30 00:03 - 00000830 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-06-21 23:04 - 2015-06-24 02:03 - 00003718 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2015-06-21 23:04 - 2015-06-21 23:05 - 00000000 ____D C:\Users\sofiane\AppData\Local\Adobe
2015-06-21 23:04 - 2015-06-21 23:04 - 00000000 ____D C:\ProgramData\McAfee
2015-06-21 23:03 - 2015-06-21 23:03 - 01125056 _____ (Adobe Systems Incorporated) C:\Users\sofiane\Downloads\flashplayer18_ga_install.exe
2015-06-21 20:47 - 2015-06-25 04:59 - 00000000 ____D C:\Users\sofiane\Desktop\Movies
2015-06-21 19:07 - 2015-06-29 21:55 - 00000000 ____D C:\Users\sofiane\AppData\Roaming\vlc
2015-06-21 19:07 - 2015-06-29 04:40 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2015-06-21 19:07 - 2015-06-21 19:07 - 00001068 _____ C:\Users\Public\Desktop\VLC media player.lnk
2015-06-21 19:07 - 2015-06-21 19:07 - 00000000 ____D C:\Program Files (x86)\VideoLAN
2015-06-21 19:05 - 2015-06-21 19:06 - 28849904 _____ C:\Users\sofiane\Downloads\vlc-2.2.1-win32.exe
2015-06-21 18:12 - 2015-06-29 17:22 - 00000000 ____D C:\Users\sofiane\AppData\Roaming\Free Download Manager
2015-06-21 18:12 - 2015-06-29 04:40 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free Download Manager
2015-06-21 18:12 - 2015-06-21 18:12 - 00001069 _____ C:\Users\sofiane\Desktop\Free Download Manager.lnk
2015-06-21 18:12 - 2015-06-21 18:12 - 00000000 ____D C:\Users\sofiane\AppData\Roaming\FreeDownloadManager.ORG
2015-06-21 18:12 - 2015-06-21 18:12 - 00000000 ____D C:\ProgramData\FreeDownloadManager.ORG
2015-06-21 18:12 - 2015-06-21 18:12 - 00000000 ____D C:\Program Files (x86)\Free Download Manager
2015-06-21 18:10 - 2015-06-29 11:58 - 00000000 ____D C:\Users\sofiane\AppData\Local\ClassicShell
2015-06-21 18:10 - 2015-06-21 18:10 - 00000000 ____D C:\ProgramData\ClassicShell
2015-06-21 18:10 - 2015-06-21 17:59 - 00002160 _____ C:\Users\sofiane\AppData\Roaming\Microsoft\Windows\Start Menu\startscreen.lnk
2015-06-21 18:06 - 2015-06-21 22:36 - 00114176 ___SH C:\Users\sofiane\Downloads\Thumbs.db
2015-06-21 18:01 - 2015-06-21 18:01 - 00000000 ____D C:\Users\sofiane\AppData\Roaming\Avira
2015-06-21 17:59 - 2015-06-29 04:40 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Classic Shell
2015-06-21 17:59 - 2015-06-21 17:59 - 00000000 ____D C:\Program Files\Classic Shell
2015-06-21 17:59 - 2015-05-27 22:07 - 00153256 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avgntflt.sys
2015-06-21 17:59 - 2015-05-27 22:07 - 00132656 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avipbb.sys
2015-06-21 17:59 - 2015-05-27 22:07 - 00043576 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avnetflt.sys
2015-06-21 17:59 - 2015-05-27 22:07 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\WINDOWS\system32\Drivers\avkmgr.sys
2015-06-21 17:58 - 2015-06-29 04:38 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
2015-06-21 17:58 - 2015-06-21 17:59 - 00000000 ____D C:\ProgramData\Avira
2015-06-21 17:58 - 2015-06-21 17:59 - 00000000 ____D C:\Program Files (x86)\Avira
2015-06-21 17:58 - 2015-06-21 17:58 - 00001190 _____ C:\Users\Public\Desktop\Avira.lnk
2015-06-21 17:58 - 2015-06-21 17:58 - 00000000 ____D C:\ProgramData\Package Cache
2015-06-21 17:57 - 2015-06-21 17:57 - 06596368 _____ (IvoSoft) C:\Users\sofiane\Downloads\ClassicShellSetup_4_2_1.exe
2015-06-21 17:53 - 2015-06-21 17:53 - 04718584 _____ (Avira Operations GmbH & Co. KG) C:\Users\sofiane\Downloads\avira_en_av_5586ddf46aeab__ws1.exe
2015-06-21 15:52 - 2015-06-21 15:52 - 10725888 _____ (FreeDownloadManager.ORG ) C:\Users\sofiane\Downloads\fdminst.exe
2015-06-21 15:44 - 2015-06-29 23:54 - 00000914 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2015-06-21 15:44 - 2015-06-29 12:46 - 00003652 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2015-06-21 15:44 - 2015-06-29 12:46 - 00000910 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2015-06-21 15:44 - 2015-06-29 04:40 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-06-21 15:44 - 2015-06-29 04:40 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2015-06-21 15:44 - 2015-06-21 15:49 - 00003886 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2015-06-21 15:44 - 2015-06-21 15:44 - 00002784 _____ C:\WINDOWS\System32\Tasks\CCleanerSkipUAC
2015-06-21 15:44 - 2015-06-21 15:44 - 00000824 _____ C:\Users\Public\Desktop\CCleaner.lnk
2015-06-21 15:44 - 2015-06-21 15:44 - 00000000 ____D C:\Users\sofiane\AppData\Local\Google
2015-06-21 15:44 - 2015-06-21 15:44 - 00000000 ____D C:\Program Files\CCleaner
2015-06-21 15:44 - 2015-06-21 15:44 - 00000000 ____D C:\Program Files (x86)\Google
2015-06-21 15:42 - 2015-06-21 15:42 - 06549184 _____ (Piriform Ltd) C:\Users\sofiane\Downloads\ccsetup506.exe
2015-06-21 15:40 - 2015-06-21 15:40 - 00001161 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-06-21 15:40 - 2015-06-21 15:40 - 00001149 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-06-21 15:40 - 2015-06-21 15:40 - 00000000 ____D C:\Users\sofiane\AppData\Roaming\Mozilla
2015-06-21 15:40 - 2015-06-21 15:40 - 00000000 ____D C:\Users\sofiane\AppData\Local\Mozilla
2015-06-21 15:40 - 2015-06-21 15:40 - 00000000 ____D C:\ProgramData\Mozilla
2015-06-21 15:40 - 2015-06-21 15:40 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2015-06-21 15:40 - 2015-06-21 15:40 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2015-06-21 15:39 - 2015-06-21 15:39 - 00243400 _____ C:\Users\sofiane\Downloads\Firefox Setup Stub 38.0.5.exe
2015-06-21 15:34 - 2015-06-29 13:02 - 00003598 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2352947253-3735842710-969423645-1002
2015-06-21 15:27 - 2015-06-21 15:27 - 00000000 ____D C:\WINDOWS\System32\Tasks\WPD
2015-06-21 15:27 - 2015-06-21 15:27 - 00000000 ____D C:\Users\sofiane\AppData\Roaming\Adobe
2015-06-21 15:26 - 2015-06-29 12:49 - 00000422 _____ C:\Users\sofiane\AppData\Roaming\sp_data.sys
2015-06-21 15:26 - 2015-06-21 15:26 - 00000000 ____D C:\Users\sofiane\AppData\Roaming\ASUS WebStorage
2015-06-21 15:26 - 2015-06-21 15:26 - 00000000 ____D C:\ProgramData\FolderView
2015-06-21 15:25 - 2015-06-29 11:54 - 00000000 ____D C:\Users\sofiane\AppData\Local\Packages
2015-06-21 15:25 - 2015-06-21 15:26 - 00000000 ____D C:\Users\sofiane\AppData\Local\ASUS
2015-06-21 15:25 - 2015-06-21 15:25 - 00000000 ____D C:\Users\sofiane\AppData\Local\VirtualStore
2015-06-21 15:25 - 2015-06-21 15:25 - 00000000 ____D C:\Users\sofiane\AppData\Local\Broadcom
2015-06-21 15:22 - 2015-06-29 03:38 - 01950831 _____ C:\WINDOWS\WindowsUpdate (1).log

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-06-30 00:00 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\system32\sru
2015-06-29 14:20 - 2013-08-22 17:36 - 00262144 _____ C:\WINDOWS\system32\config\BCD-Template
2015-06-29 14:20 - 2013-08-22 17:36 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2015-06-29 14:19 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\SysWOW64\setup
2015-06-29 14:19 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\system32\setup
2015-06-29 14:17 - 2013-08-22 16:46 - 00287047 _____ C:\WINDOWS\setupact.log
2015-06-29 14:12 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\WinStore
2015-06-29 14:08 - 2014-11-21 06:34 - 02473472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2015-06-29 14:08 - 2013-08-22 17:36 - 00000000 ___RD C:\WINDOWS\ToastData
2015-06-29 14:08 - 2013-08-22 17:36 - 00000000 ___RD C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-06-29 14:08 - 2013-08-22 17:36 - 00000000 ___RD C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-06-29 14:08 - 2013-08-22 17:36 - 00000000 ____D C:\Program Files\Windows Defender
2015-06-29 14:08 - 2013-08-22 17:36 - 00000000 ____D C:\Program Files (x86)\Windows Defender
2015-06-29 14:02 - 2013-08-22 17:36 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2015-06-29 13:56 - 2014-11-21 06:20 - 00000000 ____D C:\Program Files\Windows Journal
2015-06-29 13:53 - 2013-08-22 15:36 - 00000000 ____D C:\WINDOWS\system32\AdvancedInstallers
2015-06-29 12:50 - 2014-11-21 06:44 - 00863592 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2015-06-29 12:46 - 2013-03-28 09:49 - 00003028 _____ C:\WINDOWS\System32\Tasks\ASUS USB Charger Plus
2015-06-29 12:46 - 2013-03-28 09:40 - 00003542 _____ C:\WINDOWS\System32\Tasks\ASUS Touchpad Launcher (x64)
2015-06-29 12:45 - 2013-03-28 09:57 - 00003260 _____ C:\WINDOWS\System32\Tasks\ASUS Patch for Touch Panel
2015-06-29 12:45 - 2013-03-28 09:49 - 00003114 _____ C:\WINDOWS\System32\Tasks\ASUS Live Update
2015-06-29 12:45 - 2013-03-28 09:49 - 00003048 _____ C:\WINDOWS\System32\Tasks\ASUS Splendid ACMON
2015-06-29 12:45 - 2013-03-28 09:47 - 00003056 _____ C:\WINDOWS\System32\Tasks\ASUS P4G
2015-06-29 12:44 - 2013-08-22 16:45 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-06-29 11:59 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\AppReadiness
2015-06-29 11:56 - 2013-08-22 16:46 - 00000262 _____ C:\WINDOWS\setuperr.log
2015-06-29 11:52 - 2014-11-22 00:03 - 00000000 ___HD C:\$Windows.~BT
2015-06-29 11:48 - 2013-03-28 09:58 - 00002453 _____ C:\WINDOWS\system32\ServiceFilter.ini
2015-06-29 04:55 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\rescache
2015-06-29 04:54 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\Registration
2015-06-29 04:50 - 2013-08-22 17:36 - 00000000 __RSD C:\WINDOWS\Media
2015-06-29 04:50 - 2013-08-22 17:36 - 00000000 __RHD C:\Users\Public\Libraries
2015-06-29 04:41 - 2013-08-22 16:44 - 00337808 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2015-06-29 04:40 - 2014-11-21 05:50 - 00000000 ____D C:\WINDOWS\SysWOW64\WCN
2015-06-29 04:40 - 2014-11-21 05:50 - 00000000 ____D C:\WINDOWS\SysWOW64\sysprep
2015-06-29 04:40 - 2013-08-22 17:37 - 00005217 _____ C:\WINDOWS\DtcInstall.log
2015-06-29 04:40 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\SysWOW64\MUI
2015-06-29 04:40 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\SysWOW64\migwiz
2015-06-29 04:40 - 2013-08-22 15:36 - 00000000 ____D C:\WINDOWS\SysWOW64\SMI
2015-06-29 04:40 - 2013-08-22 15:36 - 00000000 ____D C:\WINDOWS\system32\Sysprep
2015-06-29 04:40 - 2013-08-22 15:25 - 00262144 ___SH C:\WINDOWS\system32\config\ELAM
2015-06-29 04:40 - 2013-08-22 15:25 - 00262144 ___SH C:\WINDOWS\system32\config\BBI
2015-06-29 04:40 - 2013-03-28 09:40 - 00000000 ____D C:\WINDOWS\SysWOW64\sda
2015-06-29 04:40 - 2013-03-28 09:37 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD VISION Engine Control Center
2015-06-29 04:40 - 2012-11-27 03:19 - 00000000 ____D C:\WINDOWS\tr
2015-06-29 04:40 - 2012-11-27 03:19 - 00000000 ____D C:\WINDOWS\fr
2015-06-29 04:40 - 2012-11-27 03:19 - 00000000 ____D C:\WINDOWS\es
2015-06-29 04:40 - 2012-11-27 03:19 - 00000000 ____D C:\WINDOWS\en
2015-06-29 04:40 - 2012-11-27 03:19 - 00000000 ____D C:\WINDOWS\ar
2015-06-29 04:40 - 2012-11-27 03:18 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ASUS
2015-06-29 04:40 - 2012-07-26 07:37 - 00000000 ____D C:\Users\Default.migrated
2015-06-29 04:39 - 2014-11-21 05:50 - 00000000 ____D C:\WINDOWS\system32\WCN
2015-06-29 04:39 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\SysWOW64\IME
2015-06-29 04:39 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2015-06-29 04:39 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\system32\spool
2015-06-29 04:39 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\system32\MUI
2015-06-29 04:39 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\system32\IME
2015-06-29 04:39 - 2013-08-22 15:36 - 00000000 ____D C:\WINDOWS\system32\oobe
2015-06-29 04:38 - 2013-08-22 17:43 - 00000000 ____D C:\WINDOWS\DigitalLocker
2015-06-29 04:38 - 2013-08-22 17:36 - 00000000 __SHD C:\Program Files\Windows Sidebar
2015-06-29 04:38 - 2013-08-22 17:36 - 00000000 __SHD C:\Program Files (x86)\Windows Sidebar
2015-06-29 04:38 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\PolicyDefinitions
2015-06-29 04:38 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\IME
2015-06-29 04:38 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\Help
2015-06-29 04:38 - 2013-08-22 17:36 - 00000000 ____D C:\Program Files\Common Files\System
2015-06-29 04:38 - 2013-08-22 17:36 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2015-06-29 04:38 - 2012-08-02 05:36 - 00000000 ____D C:\ProgramData\PRICache
2015-06-29 04:37 - 2013-08-22 17:36 - 00000000 ____D C:\WINDOWS\system32\Recovery
2015-06-29 04:36 - 2012-07-26 10:12 - 00000000 ___HD C:\WINDOWS\system32\GroupPolicy
2015-06-29 04:23 - 2014-11-21 06:31 - 00004688 _____ C:\WINDOWS\PFRO.log
2015-06-29 04:23 - 2013-08-22 15:36 - 00000000 __RHD C:\Users\Default
2015-06-28 23:12 - 2012-07-26 10:12 - 00000000 ____D C:\WINDOWS\AUInstallAgent
2015-06-25 06:28 - 2012-07-26 09:59 - 00000000 ____D C:\WINDOWS\CbsTemp
2015-06-21 23:07 - 2012-11-27 03:20 - 00000000 ____D C:\ProgramData\Trend Micro
2015-06-21 23:07 - 2012-07-26 10:12 - 00000000 ___HD C:\WINDOWS\ELAMBKUP
2015-06-21 15:29 - 2012-11-27 03:18 - 00000000 ____D C:\ProgramData\ChangeFolderView
2015-06-21 15:26 - 2012-08-02 05:52 - 00000000 ____D C:\WINDOWS\Log

==================== Files in the root of some directories =======

2015-06-21 15:26 - 2015-06-29 12:49 - 0000422 _____ () C:\Users\sofiane\AppData\Roaming\sp_data.sys
2012-11-27 03:17 - 2012-09-07 13:40 - 0000256 _____ () C:\ProgramData\SetStretch.cmd
2012-11-27 03:17 - 2009-07-22 12:04 - 0024576 _____ () C:\ProgramData\SetStretch.exe
2012-11-27 03:17 - 2012-09-07 13:37 - 0000103 _____ () C:\ProgramData\SetStretch.VBS

Files to move or delete:
====================
C:\ProgramData\SetStretch.exe
C:\ProgramData\SetStretch.VBS


Some files in TEMP:
====================
C:\Users\sofiane\AppData\Local\Temp\avgnt.exe


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-06-29 04:23

==================== End of log ============================

 

 

 

Addition.txt

 

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version:28-06-2015 01
Ran by [removed] at 2015-06-30 00:33:46
Running from C:\Users\[removed]\Desktop
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-2352947253-3735842710-969423645-500 - Administrator - Disabled)
Guest (S-1-5-21-2352947253-3735842710-969423645-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-2352947253-3735842710-969423645-1006 - Limited - Enabled)
sofiane (S-1-5-21-2352947253-3735842710-969423645-1002 - Administrator - Enabled) => C:\Users\sofiane

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Avira Antivirus (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Avira Antivirus (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Adobe Flash Player 18 NPAPI (HKLM-x32\…\Adobe Flash Player NPAPI) (Version: 18.0.0.194 - Adobe Systems Incorporated)
Adobe Reader X MUI (HKLM-x32\…\{AC76BA86-7AD7-FFFF-7B44-AA0000000001}) (Version: 10.0.0 - Adobe Systems Incorporated)
AMD Catalyst Install Manager (HKLM\…\{07FC05E8-3C9B-3F62-D6D7-9584E2683FCC}) (Version: 8.0.891.0 - Advanced Micro Devices, Inc.)
ASUS Instant Connect (HKLM-x32\…\{89ECB85A-D933-4CEA-9116-5CBC9C2ED95B}) (Version: 1.2.8 - ASUS)
ASUS InstantOn (HKLM-x32\…\{749F674B-2674-47E8-879C-5626A06B2A91}) (Version: 3.0.5 - ASUS)
ASUS LifeFrame3 (HKLM-x32\…\{1DBD1F12-ED93-49C0-A7CC-56CBDE488158}) (Version: 3.1.9 - ASUS)
ASUS Live Update (HKLM-x32\…\{FA540E67-095C-4A1B-97BA-4D547DEC9AF4}) (Version: 3.1.9 - ASUS)
ASUS Power4Gear Hybrid (HKLM\…\{9B6239BF-4E85-4590-8D72-51E30DB1A9AA}) (Version: 2.0.4 - ASUS)
ASUS Product Demo Movie  (HKLM-x32\…\{DC06C90B-C5BE-42F6-B74D-A9503170998C}) (Version: 1.0.3 - ASUS )
ASUS Smart Gesture (HKLM-x32\…\{4D3286A6-F6AB-498A-82A4-E4F040529F3D}) (Version: 1.0.36 - ASUS)
ASUS Splendid Video Enhancement Technology (HKLM-x32\…\{0969AF05-4FF6-4C00-9406-43599238DE0D}) (Version: 1.03.0006 - ASUS)
ASUS Tutor (HKLM-x32\…\{58172D66-2F69-4215-9AEC-ED8196023736}) (Version: 1.0.8 - ASUS)
ASUS USB Charger Plus (HKLM-x32\…\{A859E3E5-C62F-4BFA-AF1D-2B95E03166AF}) (Version: 2.1.5 - ASUS)
ASUS WebStorage Sync Agent (HKLM-x32\…\ASUS WebStorage) (Version: 1.1.10.123 - ASUS Cloud Corporation)
ATK Package (HKLM-x32\…\{AB5C933E-5C7D-4D30-B314-9C83A49B94BE}) (Version: 1.0.0025 - ASUS)
Avira (HKLM-x32\…\{8467e01f-0496-42ce-b247-88ef205b4880}) (Version: 1.1.40.29239 - Avira Operations GmbH & Co. KG)
Avira (x32 Version: 1.1.40.29239 - Avira Operations GmbH & Co. KG) Hidden
Avira Antivirus (HKLM-x32\…\Avira Antivirus) (Version: 15.0.11.579 - Avira Operations GmbH & Co. KG)
Broadcom 802.11 Network Adapter (HKLM\…\Broadcom 802.11 Network Adapter) (Version: 6.30.59.74 - Broadcom Corporation)
Catalyst Control Center (HKLM-x32\…\WUCCCApp) (Version: 1.00.0000 - AMD)
CCleaner (HKLM\…\CCleaner) (Version: 5.06 - Piriform)
Classic Shell (HKLM\…\{7C129CF8-199F-4269-AAEE-60B5D8D716E2}) (Version: 4.2.1 - IvoSoft)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Fotoğraf Galerisi (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Free Download Manager 3.9.5 (HKLM-x32\…\Free Download Manager_is1) (Version:  - FreeDownloadManager.ORG)
Galeria de Fotografias (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Galería de fotos (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Galerie de photos (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 43.0.2357.130 - Google Inc.)
Google Update Helper (x32 Version: 1.3.21.169 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.27.5 - Google Inc.) Hidden
Microsoft Office (HKLM-x32\…\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.6120.5004 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.30319 (HKLM\…\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.30319 (HKLM-x32\…\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\…\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\…\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation)
Movie Maker (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Mozilla Firefox 38.0.5 (x86 en-GB) (HKLM-x32\…\Mozilla Firefox 38.0.5 (x86 en-GB)) (Version: 38.0.5 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\…\MozillaMaintenanceService) (Version: 38.0.5 - Mozilla)
MyBitCast 2.0 (HKLM-x32\…\MyBitCast) (Version: 2.0 - ASUS)
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6777 - Realtek Semiconductor Corp.)
Realtek USB 2.0 Card Reader (HKLM-x32\…\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.8400.39030 - Realtek Semiconductor Corp.)
VLC media player (HKLM-x32\…\VLC media player) (Version: 2.2.1 - VideoLAN)
WIDCOMM Bluetooth Software (HKLM\…\{C6D9ED03-6FCF-4410-9CB7-45CA285F9E11}) (Version: 12.0.0.3100 - Broadcom Corporation)
Windows Driver Package - ASUS (ATP) Mouse  (11/09/2012 1.0.0.153) (HKLM\…\5AB9160B769DD2E134ADCB8010377DECA2479378) (Version: 11/09/2012 1.0.0.153 - ASUS)
Windows Live Essentials (HKLM-x32\…\WinLiveSuite) (Version: 16.4.3505.0912 - Microsoft Corporation)
WinFlash (HKLM-x32\…\{8F21291E-0444-4B1D-B9F9-4370A73E346D}) (Version: 2.41.1 - ASUS)
معرض الصور (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== Restore Points =========================


==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2013-08-22 15:25 - 2013-08-22 15:25 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {3EF819DC-B154-424B-8EB7-F5B257D4D9FF} - System32\Tasks\ASUS P4G => C:\Program Files\ASUS\P4G\BatteryLife.exe [2012-08-25] (ASUS)
Task: {530A63F1-C9EF-4773-AD16-DA0F6181685B} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-06-24] (Adobe Systems Incorporated)
Task: {5FBE1460-F1B6-403E-AC2B-6B29FC7C0B01} - System32\Tasks\ASUS USB Charger Plus => C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe [2012-09-18] (ASUSTek Computer Inc.)
Task: {81BBA650-FE79-4B42-A3C8-51386491A37D} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-06-21] (Google Inc.)
Task: {8DB88266-2FDD-409C-AC47-289F16A82A63} - System32\Tasks\ASUS Touchpad Launcher (x64) => C:\Program Files (x86)\ASUS\ASUS Smart Gesture\AsTPCenter\x64\AsusTPLauncher.exe [2012-11-20] (AsusTek)
Task: {970F5D88-3409-4B18-83FE-0AA3B62BBD18} - System32\Tasks\ASUS Live Update => C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe [2012-08-22] (ASUSTeK Computer Inc.)
Task: {ACB38799-D942-4D34-A00C-14AF31709A96} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-06-21] (Google Inc.)
Task: {BFF3CA10-9E7A-4B3C-A872-B2BCEE9DD885} - System32\Tasks\ASUS Patch for Touch Panel => C:\ProgramData\AsTouchPanel\AsPatchTouchPanel64.exe [2012-12-18] (ASUSTek Computer INC.)
Task: {D45981A2-D66C-4CF7-81D8-AA38AC27FDBC} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-05-08] (Piriform Ltd)
Task: {E454868B-8924-47C5-9BF0-777906D27059} - System32\Tasks\ASUS Splendid ACMON => C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [2012-10-17] (ASUS)
Task: {EE8BB57E-DB79-438C-AE07-0F08DFAABAFB} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2015-05-27] (Microsoft Corporation)
Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (Whitelisted) ==============

2012-10-05 22:27 - 2012-10-05 22:27 - 00047480 _____ () C:\Program Files\WIDCOMM\Bluetooth Software\BtwLeAPI.dll
2012-08-25 02:26 - 2012-08-25 02:26 - 00031360 _____ () C:\Program Files\ASUS\P4G\DevMng.dll
2014-07-04 21:33 - 2014-07-04 21:33 - 00102400 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Proxy.Native.dll
2014-07-04 21:33 - 2014-07-04 21:33 - 00127488 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Container.Wlan.dll
2012-10-17 18:51 - 2012-10-17 18:51 - 00168664 _____ () C:\Program Files (x86)\ASUS\Splendid\ColorUService.exe
2012-10-17 18:51 - 2012-10-17 18:51 - 00011776 _____ () C:\Program Files (x86)\ASUS\Splendid\GLCDdll.dll
2015-06-21 18:12 - 2015-05-15 03:28 - 04912744 _____ () C:\Program Files (x86)\Free Download Manager\fdmbtsupp.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\Users\sofiane\OneDrive:ms-properties

==================== Safe Mode (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== EXE Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-2352947253-3735842710-969423645-1002\Control Panel\Desktop\\Wallpaper -> C:\Users\sofiane\AppData\Local\Microsoft\Windows\Themes\RoamedThemeFiles\DesktopBackground\1686333.jpg
DNS Servers: 192.168.1.1

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)

MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Bluetooth.lnk => C:\Windows\pss\Bluetooth.lnk.CommonStartup
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk => C:\WINDOWS\pss\McAfee Security Scan Plus.lnk.CommonStartup
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: Adobe Reader Speed Launcher => "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
MSCONFIG\startupreg: ASUSWebStorage => C:\Program Files (x86)\ASUS\WebStorage Sync Agent\1.1.10.123\AsusWSPanel.exe /S
MSCONFIG\startupreg: avgnt => "C:\Program Files (x86)\Avira\Antivirus\avgnt.exe" /min
MSCONFIG\startupreg: Avira Systray => C:\Program Files (x86)\Avira\Launcher\Avira.Systray.exe
MSCONFIG\startupreg: CCleaner Monitoring => "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
MSCONFIG\startupreg: Classic Start Menu => "C:\Program Files\Classic Shell\ClassicStartMenu.exe" -autorun
MSCONFIG\startupreg: DisableS3S4 => c:\windows\temp\DisableS3S464\sethigh.cmd
MSCONFIG\startupreg: RtHDVBg => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe /MAXX3
MSCONFIG\startupreg: RTHDVCPL => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
MSCONFIG\startupreg: StartCCC => "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe" MSRun

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [{C2463629-4195-43B4-B4BB-A1C78A7B27B3}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [UDP Query User{984FC503-825A-4A5A-8F07-DA53BD770BA9}C:\program files (x86)\free download manager\fdm.exe] => (Allow) C:\program files (x86)\free download manager\fdm.exe
FirewallRules: [TCP Query User{59D894D1-58B0-4B09-B45D-3A80191D32B4}C:\program files (x86)\free download manager\fdm.exe] => (Allow) C:\program files (x86)\free download manager\fdm.exe
FirewallRules: [{FBD80615-9CC1-4037-8860-AC2064E9E210}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{8B6758F2-C7CE-4D72-88BB-6E0E52003F8E}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{EEDFB4E8-1831-40EB-97E9-E34F0C4D9B74}] => (Allow) LPort=1900
FirewallRules: [{720CF98E-B75D-4905-AA16-F49D65DA57E0}] => (Allow) LPort=2869
FirewallRules: [{902C81E6-6B2D-4B4D-9242-B415569AFFB9}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (06/29/2015 01:00:38 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: NEO)
Description: Activation of app winstore_cw5n1h2txyewy!Windows.Store failed with error: -2144927142 See the Microsoft-Windows-TWinUI/Operational log for additional information.

Error: (06/29/2015 11:48:41 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: avgnt.exe, version: 15.0.11.574, time stamp: 0x55659e55
Faulting module name: ccmsg.dll, version: 15.0.11.574, time stamp: 0x55659e37
Exception code: 0xc0000005
Fault offset: 0x0000ca43
Faulting process id: 0x56c
Faulting application start time: 0xavgnt.exe0
Faulting application path: avgnt.exe1
Faulting module path: avgnt.exe2
Report Id: avgnt.exe3
Faulting package full name: avgnt.exe4
Faulting package-relative application ID: avgnt.exe5

Error: (06/29/2015 04:54:10 AM) (Source: Microsoft-Windows-WMI) (EventID: 24) (User: NT AUTHORITY)
Description: Event provider AVWMIEVTProv attempted to register query "select * from Event_Notification" whose target class "Event_Notification" in //./ROOT/CIMV2/Applications/Avira_AntiVir namespace does not exist. The query will be ignored.

Error: (06/29/2015 04:54:10 AM) (Source: Microsoft-Windows-WMI) (EventID: 24) (User: NT AUTHORITY)
Description: Event provider  attempted to register query "select * from Event_Notification" whose target class "Event_Notification" in //./ROOT/CIMV2/Applications/Avira_AntiVir namespace does not exist. The query will be ignored.

Error: (06/29/2015 04:26:15 AM) (Source: System Restore) (EventID: 8193) (User: )
Description: Failed to create restore point (Process = C:\AMD\WU-CCC2\ccc2_install\VC12RTx64\vcredist_x64.exe /q /norestart; Description = Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727; Error = 0x80042302).

Error: (06/29/2015 04:26:15 AM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine CoCreateInstance.  hr = 0x80070422, The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
.


Operation:
   Instantiating VSS server

Error: (06/29/2015 04:26:15 AM) (Source: VSS) (EventID: 13) (User: )
Description: Volume Shadow Copy Service information: The COM Server with CLSID {e579ab5f-1cc4-44b4-bed9-de0991ff0623} and name IVssCoordinatorEx2 cannot be started. [0x80070422, The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
]


Operation:
   Instantiating VSS server

Error: (06/29/2015 04:25:59 AM) (Source: System Restore) (EventID: 8193) (User: )
Description: Failed to create restore point (Process = C:\AMD\WU-CCC2\ccc2_install\VC12RTx86\vcredist_x86.exe /q /norestart; Description = Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727; Error = 0x80042302).

Error: (06/29/2015 04:25:59 AM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine CoCreateInstance.  hr = 0x80070422, The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
.


Operation:
   Instantiating VSS server

Error: (06/29/2015 04:25:59 AM) (Source: VSS) (EventID: 13) (User: )
Description: Volume Shadow Copy Service information: The COM Server with CLSID {e579ab5f-1cc4-44b4-bed9-de0991ff0623} and name IVssCoordinatorEx2 cannot be started. [0x80070422, The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
]


Operation:
   Instantiating VSS server


System errors:
=============
Error: (06/29/2015 00:46:42 PM) (Source: Service Control Manager) (EventID: 7006) (User: )
Description: The ScRegSetValueExW call failed for DelayedAutostart with the following error:
%%5

Error: (06/29/2015 00:46:42 PM) (Source: Service Control Manager) (EventID: 7006) (User: )
Description: The ScRegSetValueExW call failed for Start with the following error:
%%5

Error: (06/29/2015 00:46:42 PM) (Source: Service Control Manager) (EventID: 7006) (User: )
Description: The ScRegSetValueExW call failed for DelayedAutostart with the following error:
%%5

Error: (06/29/2015 00:46:42 PM) (Source: Service Control Manager) (EventID: 7006) (User: )
Description: The ScRegSetValueExW call failed for Start with the following error:
%%5

Error: (06/29/2015 00:46:42 PM) (Source: Service Control Manager) (EventID: 7006) (User: )
Description: The ScRegSetValueExW call failed for DelayedAutostart with the following error:
%%5

Error: (06/29/2015 00:46:42 PM) (Source: Service Control Manager) (EventID: 7006) (User: )
Description: The ScRegSetValueExW call failed for Start with the following error:
%%5

Error: (06/29/2015 00:46:42 PM) (Source: Service Control Manager) (EventID: 7006) (User: )
Description: The ScRegSetValueExW call failed for DelayedAutostart with the following error:
%%5

Error: (06/29/2015 00:46:42 PM) (Source: Service Control Manager) (EventID: 7006) (User: )
Description: The ScRegSetValueExW call failed for Start with the following error:
%%5

Error: (06/29/2015 00:46:39 PM) (Source: DCOM) (EventID: 10016) (User: NEO)
Description: application-specificLocalLaunch{7022A3B3-D004-4F52-AF11-E9E987FEE25F}{ADA41B3C-C6FD-4A08-8CC1-D6EFDE67BE7D}NeosofianeS-1-5-21-2352947253-3735842710-969423645-1002LocalHost (Using LRPC)UnavailableUnavailable

Error: (06/29/2015 00:46:38 PM) (Source: DCOM) (EventID: 10016) (User: NEO)
Description: application-specificLocalLaunch{7022A3B3-D004-4F52-AF11-E9E987FEE25F}{ADA41B3C-C6FD-4A08-8CC1-D6EFDE67BE7D}NeosofianeS-1-5-21-2352947253-3735842710-969423645-1002LocalHost (Using LRPC)UnavailableUnavailable


Microsoft Office:
=========================
Error: (06/29/2015 01:00:38 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: NEO)
Description: winstore_cw5n1h2txyewy!Windows.Store-2144927142

Error: (06/29/2015 11:48:41 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: avgnt.exe15.0.11.57455659e55ccmsg.dll15.0.11.57455659e37c00000050000ca4356c01d0b250c3fdc24eC:\Program Files (x86)\Avira\Antivirus\avgnt.exec:\program files (x86)\avira\antivirus\ccmsg.dll056b1dcb-1e44-11e5-8250-6c71d9756816

Error: (06/29/2015 04:54:10 AM) (Source: Microsoft-Windows-WMI) (EventID: 24) (User: NT AUTHORITY)
Description: AVWMIEVTProvselect * from Event_NotificationEvent_Notification//./ROOT/CIMV2/Applications/Avira_AntiVir

Error: (06/29/2015 04:54:10 AM) (Source: Microsoft-Windows-WMI) (EventID: 24) (User: NT AUTHORITY)
Description: select * from Event_NotificationEvent_Notification//./ROOT/CIMV2/Applications/Avira_AntiVir

Error: (06/29/2015 04:26:15 AM) (Source: System Restore) (EventID: 8193) (User: )
Description: C:\AMD\WU-CCC2\ccc2_install\VC12RTx64\vcredist_x64.exe /q /norestartMicrosoft Visual C++ 2012 Redistributable (x64) - 11.0.507270x80042302

Error: (06/29/2015 04:26:15 AM) (Source: VSS) (EventID: 8193) (User: )
Description: CoCreateInstance0x80070422, The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.


Operation:
   Instantiating VSS server

Error: (06/29/2015 04:26:15 AM) (Source: VSS) (EventID: 13) (User: )
Description: {e579ab5f-1cc4-44b4-bed9-de0991ff0623}IVssCoordinatorEx20x80070422, The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.


Operation:
   Instantiating VSS server

Error: (06/29/2015 04:25:59 AM) (Source: System Restore) (EventID: 8193) (User: )
Description: C:\AMD\WU-CCC2\ccc2_install\VC12RTx86\vcredist_x86.exe /q /norestartMicrosoft Visual C++ 2012 Redistributable (x86) - 11.0.507270x80042302

Error: (06/29/2015 04:25:59 AM) (Source: VSS) (EventID: 8193) (User: )
Description: CoCreateInstance0x80070422, The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.


Operation:
   Instantiating VSS server

Error: (06/29/2015 04:25:59 AM) (Source: VSS) (EventID: 13) (User: )
Description: {e579ab5f-1cc4-44b4-bed9-de0991ff0623}IVssCoordinatorEx20x80070422, The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.


Operation:
   Instantiating VSS server


==================== Memory info ===========================

Processor: AMD A8-4555M APU with Radeon™ HD Graphics
Percentage of memory in use: 44%
Total physical RAM: 5578.48 MB
Available physical RAM: 3086.75 MB
Total Pagefile: 7178.48 MB
Available Pagefile: 4023.45 MB
Total Virtual: 131072 MB
Available Virtual: 131071.79 MB

==================== Drives ================================

Drive c: (OS) (Fixed) (Total:185.52 GB) (Free:103.34 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive d: (DATA) (Fixed) (Total:258.15 GB) (Free:258.03 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 465.8 GB) (Disk ID: 01A8A7C0)

Partition: GPT Partition Type.

==================== End of log ============================

 

 

 

Checkup.txt

 

 

 Results of screen317's Security Check version 1.004  
   x64 (UAC is enabled)  
 Internet Explorer 11  
``````````````Antivirus/Firewall Check:``````````````
 Windows Firewall Enabled!  
Avira Antivirus    
Windows Defender   
 Antivirus up to date!   
`````````Anti-malware/Other Utilities Check:`````````
 Adobe Flash Player     18.0.0.194  
 Mozilla Firefox (38.0.5)
 Google Chrome (43.0.2357.124)
 Google Chrome (43.0.2357.130)
````````Process Check: objlist.exe by Laurent````````  
 Avira Antivir avgnt.exe
 Avira Antivir avguard.exe
 Avira Antivirus sched.exe  
 Avira Antivirus avshadow.exe  
`````````````````System Health check`````````````````
 Total Fragmentation on Drive C:  %
````````````````````End of Log``````````````````````
 

 

 

Cheers Satchfan!

 

Sofiane.

This does not appear to be a malware issue. There are a few bits that need to be tidied up though.


Run Farbar Recovery Scan Tool

Open notepad. Please copy the contents of the code box below and paste it into Notepad.

ShellIconOverlayIdentifiers: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} =>  No File
ShellIconOverlayIdentifiers: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} =>  No File
ShellIconOverlayIdentifiers: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} =>  No File
ShellIconOverlayIdentifiers-x32: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} =>  No File
ShellIconOverlayIdentifiers-x32: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} =>  No File
ShellIconOverlayIdentifiers-x32: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} =>  No File
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
FF Plugin-x32: @TrendMicro.com/FFExtension -> C:\Program Files\Trend Micro\Titanium\UIFramework\Toolbar\firefoxextension\components\npToolbarChrome.dll No File
CHR HKLM\…\Chrome\Extension: [bmiabdepfhhiieiipmeecdmeljggmfee] - No Path Or update_url value
CHR HKLM-x32\…\Chrome\Extension: [bmiabdepfhhiieiipmeecdmeljggmfee] - No Path Or update_url value
EmptyTemp:

NOTE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system


  • save the files as fixlist.txt in the same folder as FRST – NOTE: It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work
  • run FRST64 then click Fix just once and wait
  • it will create a log (Fixlog.txt); please post it to your reply.

================================================

I’m no expert in Windows’ matters but there seems to be a fault in your Avira installation.

I suggest that if you want to use Avira antivirus, (AV), rather than Windows Defender, that you uninstall the version of Avira that you currently have and then re-install it, making sure that Windows Defender is disabled.

You can download a new version from here:

Avira AntiVir® Personal Edition Classic


To check that Windows Defender is disabled:

  • open the Start screen and type win def, (Windows Defender will appear as the first result in the search)
  • click on the Settings tab
  • in the left window, click on Administrator and remove the checkmark from “Use this App”
  • if necessary, (ie if you had to remove the checkmark), click on the Save changes button and close Windows Defender.

Can you also tell me if this is a new installation of Windows 8.

Please post the fixlog.txt report also.

Thanks

Satchfan

 

Hi Satchfan,

 

So I did follow your instructions and uninstall/reinstall Avira and performed a full scan system. This time appeared to be normal

and I haven't experienced any freeze or whatsoever.

 

As for my OS, it is a built-in windows 8 machine, so no new installation or anything like that.

 

I'll leave you the fixlog.txt report as requested.

 

Thanks again for the follow up.

 

Cheers

 

Sofiane

 

 

Fixlog.txt

 

Fix result of Farbar Recovery Scan Tool (x64) Version:28-06-2015 01
Ran by [removed] at 2015-06-30 16:49:27 Run:1
Running from C:\Users\[removed]\Desktop\New folder
[removed] Boot Mode: Normal
==============================================

fixlist content:
*****************
ShellIconOverlayIdentifiers: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} =>  No File
ShellIconOverlayIdentifiers: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} =>  No File
ShellIconOverlayIdentifiers: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} =>  No File
ShellIconOverlayIdentifiers-x32: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} =>  No File
ShellIconOverlayIdentifiers-x32: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} =>  No File
ShellIconOverlayIdentifiers-x32: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} =>  No File
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
FF Plugin-x32: @TrendMicro.com/FFExtension -> C:\Program Files\Trend Micro\Titanium\UIFramework\Toolbar\firefoxextension\components\npToolbarChrome.dll No File
CHR HKLM\…\Chrome\Extension: [bmiabdepfhhiieiipmeecdmeljggmfee] - No Path Or update_url value
CHR HKLM-x32\…\Chrome\Extension: [bmiabdepfhhiieiipmeecdmeljggmfee] - No Path Or update_url value
EmptyTemp:
*****************

"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ SkyDrive1" => key removed successfully
HKCR\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A} => key not found.
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ SkyDrive2" => key removed successfully
HKCR\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => key not found.
"HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ SkyDrive3" => key removed successfully
HKCR\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524} => key not found.
"HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ SkyDrive1" => key removed successfully
HKCR\Wow6432Node\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A} => key not found.
"HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ SkyDrive2" => key removed successfully
HKCR\Wow6432Node\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => key not found.
"HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\ SkyDrive3" => key removed successfully
HKCR\Wow6432Node\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524} => key not found.
"HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer" => key removed successfully
"HKLM\Software\Wow6432Node\MozillaPlugins\@TrendMicro.com/FFExtension" => key removed successfully
"HKLM\SOFTWARE\Google\Chrome\Extensions\bmiabdepfhhiieiipmeecdmeljggmfee" => key removed successfully
"HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\bmiabdepfhhiieiipmeecdmeljggmfee" => key removed successfully
EmptyTemp: => 308.6 MB temporary data Removed.


The system needed a reboot..

==== End of Fixlog 16:50:10 ====

Yup it got better it's all good so far…

 

But ultimately Satchfan, what do you think was the problem? Just a fault in the Avira set up?

Yes I think so but I also noticed another entry that showed an error with "Volume Shadow Copy Service". This is necessary to do a system restore, (among other things), and I think it may be worth checking in another of our forums for a Windows expert to look at it because I'm not capable of helping with that. It may be nothing but…..

 

I suggest you start a topic here.

 

I'll keep this topic open for 24 hours but if I hear nothing from you, Ill assume all is well and close it.

 

Regards

 

Satchfan

Thanks for the link Satchfan, I will start a topic there soon.

 

About this thread, I think we're all good so you can already close it.

 

I would like to thank you again my friend for the tremendous help, really appreciate it.

 

Regards

 

Sofiane

Please follow these simple steps to tidy up you computer.


Download & run Delfix

  • download Delfix from here to remove many of the tools we've used during the cleaning process.
  • ensure “Remove disinfection tools” is checked.

Also place a checkmark next to:


o    Create registry backup
o    Purge system restore


  • click the Run button.

You can delete all other logs and programs we’ve used that are on your desktop. Just click on them and press Delete.

===================================================

Windows updates

I notice that Windows updates are waiting to be installed. Click here for information on how to get the latest Windows updates:

===================================================

Recommended programs

SpywareBlaster. SpywareBlaster protects against bad ActiveX, it immunizes your PC against them. It blocks over 11,000 bad sites and uses no resources of your computer.

======================

Download Malwarebytes' Anti-Malware. This really is an excellent program that you should update and run on a regular basis, probably weekly.

======================

It’s important to keep programs up to date so that malware doesn't exploit any old security flaws.

FileHippo Update Checker is an extremely helpful program that will tell you which of your programs need to be updated.

======================

Download WOT

Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:


green if it's safe
yellow for caution
red for unsafe

 

You can download the WOT add-on for Firefox, Chrome, Internet Explorer, Opera, and Safari browsers. It does not slow down your browsing experience, it is easy to use and free. Just click “Download” and you are ready to go!

======================

Download and install CryptoPrevent

Crypto Ransomware Warning

There are particularly nasty “Ransomware” infections out there at the moment that encrypt your files and the only way possible to get them “de-crypted” is to pay a ransome. You can read more about this here.

  • download CryptoPrevent
  • save the file to your Desktop and then open the program by clicking Run when prompted from your browser or by going to the desktop where the file was saved and double-clicking.
  • accept all the defaults during the install. The last screen of the install has a checkmark in "Launch CryptoPrevent". This will launch the program once you click Finish
  • you will get a prompt asking if you purchased a Product Key for Automatic Updates. Click No
  • you will then be prompted to learn more about automatic updates or if you want to purchase a key. This is up to you but you don't have to
  • click OK to continue and select your protection level. Go ahead and click OK.
  • click the Apply button to set Default protection
  • you may get a message stating that Windows Sidebar and Desktop Gadgets are a major security vulnerability and asking you if you want to disable them. If you don't use these features, answer Yes.

You are now protected.

Note: The free version doesn't provide automatic updates but should be updated often, (at least weekly), as this infection has serious consequences. To update it manually, open the program, select the “Updates” menu then select Check for Updates to see if there are any available.

Safe computing

Satchfan

 

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI