This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Dllhost / COM Surrogate Virus? [Closed]

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I believe my computer has a Virus, and that is has something to do with the COM Surrogate or mulitple COM Surrogate's in my Background Processes.

I have tried factory resetting my computer, as well as multiple Virus scans with different programs, and I can't figure out how to get this to go away.

These COM Surrogate's exist even after factory resetting.

 

I believe it's making me lag and crash and everything just very slow occasionally.

 

Please Help!

After going into properites I may have noticed something, 

 

It says it's created on July 26 2015 (Probably the day I last factory reset my computer)

 

and then It's last modified on October  28 2014, (Maybe when I got it)?

:welcome:

 

Just saw you post by accident, when you reply to your own post it takes you out of the zero replies catagory that our helpers look for to reply to a post. You have also not given us any info about the OS your using but when you run these scans it will tell us that

 

COM Surrogate  is legit windows file and is needed by the operating system but there is a virus going around that uses it, lets check

 

[external image: 1QYkxTZ.jpg] Please download aswMBR to your desktop.
 
  •  
  • Right click the aswMBR icon and select Run as Administrator
  • XP users just Double Click it to run
  • If it says that this computer supports VIRTUALIZATION TECHNOLOGY do you want to use it say Yes
  • Click the Scan button to start scan.
  • Select Quickscan on the dropdown list
  • If you are asked to update the Avast Virus database please allow it to do so.
  • The scan could take 20 minutes or more , please be patient and let it finish
  • It will say Scan Finished when its done.
  • When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.
 
I just want to see the report….Please Do Not Fix Anything
 

 

============================================================================
 

 
Please download Farbar Recovery Scan Tool and save it to your DESKTOP
 
Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
 
How to determine whether a computer is running a 32-bit version or 64-bit version of the Windows operating system
A simple way to check your system: Start –> Computer (right click) –> Properties
 
[external image: FRST_zps5d956a1a.jpg]
 
 
  •  
  • Right click to run as administrator (XP users click run after receipt of Windows Security Warning - Open File). When the tool opens click Yes to disclaimer.
  • Please make sure All Users is checked
  • Just keep the defaults as in the picture checkmarked
  • Press Scan button.
  • It will produce a log called FRST.txt in the same directory the tool is run from.
  • Please copy and paste log back here.
  • The first time the tool is run it generates another log (Addition.txt - also located in the same directory as FRST.exe/FRST64.exe). Please also paste that along with the FRST.txt into your reply.
 
 

My apologies about replying to myself. Here are the logs for the two programs you wanted:

 

aswMBR Log:

 

aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
Run date: 2015-09-09 15:12:49
—————————–
15:12:49.021    OS Version: Windows x64 6.2.9200 
15:12:49.021    Number of processors: 8 586 0x3A09
15:12:49.022    ComputerName: AWHEELER  UserName: Lestoli
15:12:49.306    Initialize success
15:12:49.306    VM: initialized successfully
15:12:49.306    VM: Intel CPU BiosDisabled 
15:16:10.750    AVAST engine defs: 15090901
15:16:13.640    Disk 0  \Device\Harddisk0\DR0 -> \Device\00000034
15:16:13.640    Disk 0 Vendor: WDC_WD1002FAEX-00Y9A0 05.01D05 Size: 953869MB BusType: 11
15:16:13.656    Disk 1 (boot) \Device\Harddisk1\DR1 -> \Device\00000036
15:16:13.656    Disk 1 Vendor: SAMSUNG_SSD_830_Series CXM03B1Q Size: 244198MB BusType: 11
15:16:13.656    Disk 1 MBR read successfully
15:16:13.656    Disk 1 MBR scan
15:16:13.687    Disk 1 Windows 7 default MBR code
15:16:13.687    Disk 1 Partition 1 80 (A) 07    HPFS/NTFS NTFS          350 MB offset 2048
15:16:13.703    Disk 1 Partition 2 00     07    HPFS/NTFS NTFS       243846 MB offset 718848
15:16:13.734    Disk 1 scanning C:\Windows\system32\drivers
15:16:18.836    Service scanning
15:16:33.502    Modules scanning
15:16:33.502    Disk 1 trace - called modules:
15:16:33.502    ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys storport.sys hal.dll storahci.sys 
15:16:33.502    1 nt!IofCallDriver -> \Device\Harddisk1\DR1[0xffffe001dc6b2060]
15:16:33.502    3 CLASSPNP.SYS[fffff800ac0fe170] -> nt!IofCallDriver -> [0xffffe001db5b7670]
15:16:33.518    5 ACPI.sys[fffff800abb73c21] -> nt!IofCallDriver -> \Device\00000036[0xffffe001db5ae060]
15:16:33.799    AVAST engine scan C:\Windows
15:16:34.268    AVAST engine scan C:\Windows\system32
15:18:00.007    AVAST engine scan C:\Windows\system32\drivers
15:18:06.147    AVAST engine scan C:\Users\Lestoli
15:20:35.452    AVAST engine scan C:\ProgramData
15:22:05.594    Disk 1 statistics 3728294/0/0 @ 35.99 MB/s
15:22:05.597    Scan finished successfully
15:22:55.342    Disk 1 MBR has been saved successfully to "C:\Users\Lestoli\Downloads\MBR.dat"
15:22:55.363    The log file has been saved successfully to "C:\Users\Lestoli\Downloads\aswMBR.txt"
 
 
 
 
FRST:
 
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:07-09-2015
Ran by [removed] (administrator) on AWHEELER (09-09-2015 15:15:21)
Running from C:\Users\[removed]\Downloads
[removed]
Platform: Windows 8.1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome Remote Desktop\45.0.2454.17\remoting_host.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(Hi-Rez Studios) C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome Remote Desktop\45.0.2454.17\remoting_host.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Overwolf LTD) C:\Program Files (x86)\Overwolf\Overwolf.exe
() C:\Program Files (x86)\Razer\Comms\RazerComms.exe
(Microsoft Corporation) C:\Windows\System32\Taskmgr.exe
(Razer Inc.) C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe
(Razer, Inc.) C:\Program Files (x86)\Razer\InGameEngine\32bit\RazerIngameEngine.exe
(Razer, Inc.) C:\Users\Lestoli\AppData\Local\Razer\InGameEngine\cache\RazerComms\RzCefRenderProcess.exe
(Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
(Razer, Inc.) C:\Users\Lestoli\AppData\Local\Razer\InGameEngine\cache\RzSynapse\rzcefrenderprocess.exe
(ASUS) C:\Program Files (x86)\ASUS\USB-AC53 WLAN Card Utilities\WlanMgr.exe
(Overwolf LTD) C:\Program Files (x86)\Common Files\Overwolf\0.88.101.0\OverwolfHelper.exe
(Overwolf LTD) C:\Program Files (x86)\Common Files\Overwolf\0.88.101.0\OverwolfHelper64.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
() C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Razer, Inc.) C:\Users\Lestoli\AppData\Local\Razer\InGameEngine\cache\RazerComms\RzCefRenderProcess.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Overwolf LTD) C:\Program Files (x86)\Overwolf\0.88.101.0\OverwolfBrowser.exe
(Overwolf LTD) C:\Program Files (x86)\Overwolf\0.88.101.0\OverwolfBrowser.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(AVAST Software) C:\Users\Lestoli\Downloads\aswMBR (1).exe
 
 
==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\…\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2754704 2015-06-17] (NVIDIA Corporation)
HKLM\…\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM-x32\…\Run: [] => [X]
HKLM-x32\…\Run: [Razer Synapse] => C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe [592704 2015-07-08] (Razer Inc.)
HKLM-x32\…\Run: [KrakenLauncher] => C:\Program Files (x86)\Razer\Razer_Kraken_Driver\Drivers\SysAudio\KrakenHelper.exe [1599808 2015-02-02] (Razer Inc)
HKLM-x32\…\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [39175960 2015-08-14] (Dropbox, Inc.)
HKU\S-1-5-21-699846955-1419679699-1553032801-1001\…\Run: [uTorrent] => C:\Users\Lestoli\AppData\Roaming\uTorrent\uTorrent.exe [1696096 2015-08-29] (BitTorrent Inc.)
HKU\S-1-5-21-699846955-1419679699-1553032801-1001\…\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [2899136 2015-08-19] (Valve Corporation)
HKU\S-1-5-21-699846955-1419679699-1553032801-1001\…\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [53737488 2015-08-07] (Skype Technologies S.A.)
HKU\S-1-5-21-699846955-1419679699-1553032801-1001\…\Run: [Overwolf] => C:\Program Files (x86)\Overwolf\Overwolf.exe [41200 2015-08-19] (Overwolf LTD)
HKU\S-1-5-21-699846955-1419679699-1553032801-1001\…\Run: [Razer Comms] => C:\Program Files (x86)\Razer\Comms\RazerComms.exe [6721856 2015-08-12] () <===== ATTENTION
ShellIconOverlayIdentifiers: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.dll [2015-08-14] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.dll [2015-08-14] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.dll [2015-08-14] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.dll [2015-08-14] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.dll [2015-08-14] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.dll [2015-08-14] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.dll [2015-08-14] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.27.dll [2015-08-14] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.27.dll [2015-08-14] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.27.dll [2015-08-14] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.27.dll [2015-08-14] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.27.dll [2015-08-14] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.27.dll [2015-08-14] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.27.dll [2015-08-14] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.27.dll [2015-08-14] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.27.dll [2015-08-14] (Dropbox, Inc.)
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Tcpip\Parameters: [DhcpNameServer] 10.0.0.1
Tcpip\..\Interfaces\{63C3515E-B52D-48D1-AA37-9138D30B98BB}: [DhcpNameServer] 10.0.0.1
 
Internet Explorer:
==================
HKU\S-1-5-21-699846955-1419679699-1553032801-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/?ocid=iehp
 
FireFox:
========
FF ProfilePath: C:\Users\Lestoli\AppData\Roaming\Mozilla\Firefox\Profiles\kfiqypfq.default
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll [2015-07-21] ()
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2015-06-16] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2015-06-16] (NVIDIA Corporation)
FF Plugin-x32: @raidcall.en/RCplugin -> C:\Users\Lestoli\AppData\Roaming\raidcall\plugins\nprcplugin.dll [2014-05-27] (Raidcall)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.13\npGoogleUpdate3.dll [2015-08-30] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.13\npGoogleUpdate3.dll [2015-08-30] (Google Inc.)
FF Plugin HKU\S-1-5-21-699846955-1419679699-1553032801-1001: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Lestoli\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2015-06-08] (Unity Technologies ApS)
FF Plugin HKU\S-1-5-21-699846955-1419679699-1553032801-1001: thehappycloud.com/HappyCloudPlugin -> C:\ProgramData\HappyCloud\Application\npHappyCloudPlugin.dll [2013-05-05] (The Happy Cloud)
 
Chrome: 
=======
CHR Profile: C:\Users\Lestoli\AppData\Local\Google\Chrome\User Data\Profile 1
CHR Extension: (Google Slides) - C:\Users\Lestoli\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-07-26]
CHR Extension: (Google Docs) - C:\Users\Lestoli\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2015-07-26]
CHR Extension: (Google Drive) - C:\Users\Lestoli\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-07-26]
CHR Extension: (YouTube) - C:\Users\Lestoli\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-07-26]
CHR Extension: (Adblock Plus) - C:\Users\Lestoli\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2015-07-27]
CHR Extension: (Google Search) - C:\Users\Lestoli\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-07-26]
CHR Extension: (Google Sheets) - C:\Users\Lestoli\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-07-26]
CHR Extension: (Chrome Remote Desktop) - C:\Users\Lestoli\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gbchcmhmhahfdphkhkmpfmihenigjmpp [2015-09-06]
CHR Extension: (Google Docs Offline) - C:\Users\Lestoli\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-09-08]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Lestoli\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-07-26]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Lestoli\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-07-27]
CHR Extension: (Gmail) - C:\Users\Lestoli\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-07-26]
CHR Profile: C:\Users\Lestoli\AppData\Local\Google\Chrome\User Data\Profile 2
CHR Extension: (Google Slides) - C:\Users\Lestoli\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-09-06]
CHR Extension: (Google Docs) - C:\Users\Lestoli\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\aohghmighlieiainnegkcijnfilokake [2015-09-06]
CHR Extension: (Google Drive) - C:\Users\Lestoli\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-09-06]
CHR Extension: (YouTube) - C:\Users\Lestoli\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-06]
CHR Extension: (Google Search) - C:\Users\Lestoli\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-09-06]
CHR Extension: (Google Sheets) - C:\Users\Lestoli\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-09-06]
CHR Extension: (Chrome Remote Desktop) - C:\Users\Lestoli\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\gbchcmhmhahfdphkhkmpfmihenigjmpp [2015-09-06]
CHR Extension: (Google Docs Offline) - C:\Users\Lestoli\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-09-07]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Lestoli\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-09-06]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Lestoli\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-09-06]
CHR Extension: (Gmail) - C:\Users\Lestoli\AppData\Local\Google\Chrome\User Data\Profile 2\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-09-06]
 
==================== Services (Whitelisted) ========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 chromoting; C:\Program Files (x86)\Google\Chrome Remote Desktop\45.0.2454.17\remoting_host.exe [69448 2015-07-24] (Google Inc.)
S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [136048 2015-08-28] (Dropbox, Inc.)
S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [136048 2015-08-28] (Dropbox, Inc.)
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1152656 2015-06-17] (NVIDIA Corporation)
R2 HiPatchService; C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe [8704 2015-07-27] (Hi-Rez Studios) [File not signed]
S2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2015-06-18] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1133880 2015-06-18] (Malwarebytes Corporation)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1893008 2015-06-17] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [23007376 2015-06-17] (NVIDIA Corporation)
S3 OverwolfUpdater; C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [1006320 2015-08-19] (Overwolf LTD)
R2 Razer Game Scanner Service; C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe [187048 2015-06-23] ()
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366552 2015-07-07] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2015-07-07] (Microsoft Corporation)
 
===================== Drivers (Whitelisted) ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R3 Alpham1; C:\Windows\System32\drivers\Alpham164.sys [52992 2007-07-23] (Ideazon Corporation)
R3 Alpham2; C:\Windows\System32\drivers\Alpham264.sys [21760 2007-03-20] (Ideazon Corporation)
R3 BCMH43XX; C:\Windows\system32\DRIVERS\bcmwlhigh63a.sys [2392240 2013-03-01] (Broadcom Corporation)
S0 ebdrv; C:\Windows\System32\drivers\evbda.sys [3357024 2013-08-22] (Broadcom Corporation)
R3 hitmanpro37; C:\Windows\system32\drivers\hitmanpro37.sys [43664 2015-09-09] ()
S3 LcUvcUpper; C:\Windows\system32\DRIVERS\LcUvcUpper.sys [34424 2015-02-09] (Microsoft Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-06-18] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [113880 2015-09-09] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64216 2015-06-18] (Malwarebytes Corporation)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19600 2015-06-17] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [46768 2015-06-17] (NVIDIA Corporation)
R2 rzpmgrk; C:\Windows\system32\drivers\rzpmgrk.sys [37184 2015-06-12] (Razer, Inc.)
R2 rzpnk; C:\Windows\system32\drivers\rzpnk.sys [129472 2015-06-26] (Razer, Inc.)
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44560 2015-07-07] (Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [270168 2015-07-07] (Microsoft Corporation)
R2 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114520 2015-07-07] (Microsoft Corporation)
S3 BCM42RLY; system32\drivers\BCM42RLY.sys [X]
U3 aswMBR; \??\C:\Users\Lestoli\AppData\Local\Temp\aswMBR.sys [X]
U3 aswVmm; \??\C:\Users\Lestoli\AppData\Local\Temp\aswVmm.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-09-09 15:14 - 2015-09-09 15:14 - 02190336 _____ (Farbar) C:\Users\Lestoli\Downloads\FRST64.exe
2015-09-09 15:12 - 2015-09-09 15:12 - 05198336 _____ (AVAST Software) C:\Users\Lestoli\Downloads\aswMBR (1).exe
2015-09-09 15:11 - 2015-09-09 15:12 - 05198336 _____ (AVAST Software) C:\Users\Lestoli\Downloads\aswMBR.exe
2015-09-09 14:58 - 2015-09-09 14:59 - 00043664 _____ C:\Windows\system32\Drivers\hitmanpro37.sys
2015-09-09 14:55 - 2015-09-09 14:55 - 00000888 _____ C:\Windows\system32\.crusader
2015-09-09 14:53 - 2015-09-09 14:53 - 00001908 _____ C:\Users\Public\Desktop\HitmanPro.lnk
2015-09-09 14:53 - 2015-09-09 14:53 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HitmanPro
2015-09-09 14:53 - 2015-09-09 14:53 - 00000000 ____D C:\Program Files\HitmanPro
2015-09-09 14:51 - 2015-09-09 14:55 - 00000000 ____D C:\ProgramData\HitmanPro
2015-09-09 14:50 - 2015-09-09 15:00 - 00113880 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-09-09 14:50 - 2015-09-09 14:51 - 11352032 _____ (SurfRight B.V.) C:\Users\Lestoli\Downloads\HitmanPro_x64.exe
2015-09-09 14:49 - 2015-09-09 14:49 - 24345872 _____ (Malwarebytes Corporation ) C:\Users\Lestoli\Downloads\mbam-setup-2.1.8.1057.exe
2015-09-09 14:49 - 2015-09-09 14:49 - 00001117 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-09-09 14:49 - 2015-09-09 14:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-09-09 14:49 - 2015-09-09 14:49 - 00000000 ____D C:\ProgramData\Malwarebytes
2015-09-09 14:49 - 2015-09-09 14:49 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-09-09 14:49 - 2015-06-18 08:42 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-09-09 14:49 - 2015-06-18 08:41 - 00109272 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-09-09 14:49 - 2015-06-18 08:41 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-09-09 14:48 - 2015-09-09 14:48 - 00008478 _____ C:\Users\Lestoli\Downloads\ESETPoweliksCleaner.exe_20150909.144837.848624.log
2015-09-09 14:48 - 2015-09-09 14:48 - 00000022 _____ C:\Users\Lestoli\Downloads\ESETPoweliksCleaner.exe_20150909.144837.848624.zip
2015-09-09 14:47 - 2015-09-09 14:47 - 00224968 _____ (ESET) C:\Users\Lestoli\Downloads\ESETPoweliksCleaner.exe
2015-09-09 14:13 - 2015-09-09 14:15 - 00026779 _____ C:\Users\Lestoli\Downloads\Addition.txt
2015-09-09 14:11 - 2015-09-09 15:15 - 00018286 _____ C:\Users\Lestoli\Downloads\FRST.txt
2015-09-09 14:11 - 2015-09-09 15:15 - 00000000 ____D C:\FRST
2015-09-08 23:08 - 2015-09-08 23:08 - 00000000 ____D C:\ProgramData\.mono
2015-09-08 23:06 - 2015-09-08 23:06 - 00000000 ____D C:\Users\Lestoli\AppData\Roaming\.mono
2015-09-08 23:02 - 2015-09-08 23:02 - 00001579 _____ C:\Users\Lestoli\Desktop\Pokémon Trading Card Game Online.lnk
2015-09-08 23:02 - 2015-09-08 23:02 - 00000000 ____D C:\Users\Lestoli\AppData\Roaming\Pokémon Trading Card Game Online
2015-09-08 23:02 - 2015-09-08 23:02 - 00000000 ____D C:\Users\Lestoli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pokémon Trading Card Game Online
2015-09-08 23:01 - 2015-09-08 23:02 - 230127616 _____ C:\Users\Lestoli\Downloads\PokemonInstaller.msi
2015-09-08 20:58 - 2015-09-08 20:58 - 00060485 _____ C:\Users\Lestoli\Downloads\[HorribleSubs] Prison School - 05 [1080p].mkv.torrent
2015-09-08 20:14 - 2015-09-08 20:14 - 00002426 _____ C:\Users\Lestoli\Desktop\Anthony - Chrome.lnk
2015-09-08 19:26 - 2015-09-08 19:26 - 00044570 _____ C:\Users\Lestoli\Downloads\[HorribleSubs] Blade and Soul - 01 [1080p].mkv.torrent
2015-09-08 17:33 - 2015-08-26 19:48 - 00136904 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2015-09-08 17:33 - 2015-08-26 11:00 - 00721920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2015-09-08 17:33 - 2015-08-26 11:00 - 00124928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2015-09-08 17:33 - 2015-08-26 11:00 - 00081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2015-09-08 17:33 - 2015-08-26 11:00 - 00029696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2015-09-08 17:33 - 2015-08-26 07:46 - 03705344 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2015-09-08 17:33 - 2015-08-26 07:29 - 02240512 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2015-09-08 17:33 - 2015-08-26 07:27 - 00891904 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2015-09-08 17:33 - 2015-08-26 07:27 - 00409088 _____ (Microsoft Corporation) C:\Windows\system32\WUSettingsProvider.dll
2015-09-08 17:33 - 2015-08-26 07:26 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2015-09-08 17:33 - 2015-08-26 07:26 - 00095744 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2015-09-08 17:33 - 2015-08-26 07:26 - 00035840 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2015-09-08 17:32 - 2015-09-02 19:18 - 02531400 _____ (Microsoft Corporation) C:\Windows\system32\msxml6.dll
2015-09-08 17:32 - 2015-09-02 19:17 - 01903848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml6.dll
2015-09-08 17:32 - 2015-09-02 11:48 - 02345472 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2015-09-08 17:32 - 2015-09-02 10:09 - 01556992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2015-09-08 17:32 - 2015-09-01 19:56 - 04175872 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-09-08 17:32 - 2015-09-01 19:55 - 00358912 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2015-09-08 17:32 - 2015-09-01 19:50 - 00044032 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2015-09-08 17:32 - 2015-09-01 19:17 - 00301568 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2015-09-08 17:32 - 2015-09-01 19:13 - 00035840 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2015-09-08 17:32 - 2015-08-22 11:19 - 25188352 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-09-08 17:32 - 2015-08-22 10:35 - 02886144 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-09-08 17:32 - 2015-08-22 10:34 - 00585216 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-09-08 17:32 - 2015-08-22 10:22 - 19856384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-09-08 17:32 - 2015-08-22 10:21 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-09-08 17:32 - 2015-08-22 10:20 - 05923840 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-09-08 17:32 - 2015-08-22 09:55 - 00504832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2015-09-08 17:32 - 2015-08-22 09:50 - 02279424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-09-08 17:32 - 2015-08-22 09:50 - 01032704 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll
2015-09-08 17:32 - 2015-08-22 09:45 - 00665600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2015-09-08 17:32 - 2015-08-22 09:44 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2015-09-08 17:32 - 2015-08-22 09:41 - 14451712 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-09-08 17:32 - 2015-08-22 09:41 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-09-08 17:32 - 2015-08-22 09:41 - 00720384 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2015-09-08 17:32 - 2015-08-22 09:41 - 00374784 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2015-09-08 17:32 - 2015-08-22 09:39 - 02126336 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-09-08 17:32 - 2015-08-22 09:28 - 04520448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-09-08 17:32 - 2015-08-22 09:26 - 02427392 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-09-08 17:32 - 2015-08-22 09:23 - 00880128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll
2015-09-08 17:32 - 2015-08-22 09:22 - 12857344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-09-08 17:32 - 2015-08-22 09:20 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2015-09-08 17:32 - 2015-08-22 09:18 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2015-09-08 17:32 - 2015-08-22 09:18 - 00689152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2015-09-08 17:32 - 2015-08-22 09:18 - 00327168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2015-09-08 17:32 - 2015-08-22 09:14 - 01545728 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-09-08 17:32 - 2015-08-22 09:01 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2015-09-08 17:32 - 2015-08-22 09:00 - 01951232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-09-08 17:32 - 2015-08-22 08:56 - 01310720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-09-08 17:32 - 2015-08-22 08:55 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2015-09-08 17:32 - 2015-07-31 20:47 - 00229376 _____ (Microsoft Corporation) C:\Windows\system32\schtasks.exe
2015-09-08 17:32 - 2015-07-31 20:45 - 00182784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schtasks.exe
2015-09-08 17:32 - 2015-07-31 20:38 - 01265152 _____ (Microsoft Corporation) C:\Windows\system32\schedsvc.dll
2015-09-08 17:32 - 2015-07-31 20:37 - 00468992 _____ (Microsoft Corporation) C:\Windows\system32\taskeng.exe
2015-09-08 17:32 - 2015-07-31 20:37 - 00359936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\taskeng.exe
2015-09-08 17:32 - 2015-07-30 10:18 - 00268288 _____ (Microsoft Corporation) C:\Windows\system32\InkEd.dll
2015-09-08 17:32 - 2015-07-30 09:22 - 00230912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InkEd.dll
2015-09-08 17:32 - 2015-07-22 07:34 - 02775552 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2015-09-08 17:32 - 2015-07-22 07:33 - 01728000 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Immersive.dll
2015-09-08 17:32 - 2015-07-22 07:25 - 02461184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2015-09-08 17:32 - 2015-07-22 07:25 - 01546752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Immersive.dll
2015-09-08 17:32 - 2015-07-22 07:19 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\UtcResources.dll
2015-09-08 17:32 - 2015-07-22 06:52 - 01633792 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll
2015-09-08 17:32 - 2015-07-18 11:31 - 00194048 _____ (Microsoft Corporation) C:\Windows\system32\shacct.dll
2015-09-08 17:32 - 2015-07-18 11:29 - 00655872 _____ (Microsoft Corporation) C:\Windows\system32\SettingSync.dll
2015-09-08 17:32 - 2015-07-18 11:29 - 00148480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shacct.dll
2015-09-08 17:32 - 2015-07-18 11:27 - 00520192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SettingSync.dll
2015-09-08 17:32 - 2015-07-17 07:15 - 00951296 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll
2015-09-08 17:32 - 2015-07-17 07:10 - 00749568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll
2015-09-08 17:32 - 2015-07-13 20:27 - 00063488 _____ (Microsoft Corporation) C:\Windows\system32\tzsync.exe
2015-09-08 17:32 - 2015-07-13 12:10 - 00411455 _____ C:\Windows\system32\ApnDatabase.xml
2015-09-08 17:32 - 2015-07-09 09:14 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll
2015-09-08 17:32 - 2015-07-03 14:51 - 01380056 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2015-09-08 17:32 - 2015-07-03 07:00 - 01097216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2015-09-08 17:32 - 2015-06-27 04:47 - 00118616 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2015-09-08 17:32 - 2015-06-19 10:07 - 02819072 _____ (Microsoft Corporation) C:\Windows\system32\SettingsHandlers.dll
2015-09-08 17:31 - 2015-08-03 14:15 - 00074928 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2015-09-08 17:31 - 2015-08-03 14:15 - 00065600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll
2015-09-08 17:31 - 2015-08-01 07:22 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2015-09-06 20:33 - 2015-09-06 20:33 - 08380416 _____ C:\Users\Lestoli\Downloads\chromeremotedesktophost.msi
2015-09-06 20:33 - 2015-09-06 20:33 - 00002322 _____ C:\Users\Lestoli\Desktop\Chrome App Launcher.lnk
2015-09-06 20:33 - 2015-09-06 20:33 - 00000000 ____D C:\Users\Lestoli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-09-06 20:33 - 2015-09-06 20:33 - 00000000 ____D C:\ProgramData\Google
2015-09-05 13:51 - 2015-09-05 17:03 - 00000000 ____D C:\Users\Lestoli\AppData\Local\CrashDumps
2015-09-04 20:18 - 2015-09-04 20:18 - 00045609 _____ C:\Users\Lestoli\Downloads\[HorribleSubs] Shokugeki no Soma - 22 [1080p].mkv.torrent
2015-09-04 20:18 - 2015-09-04 20:18 - 00045609 _____ C:\Users\Lestoli\Downloads\[HorribleSubs] Shokugeki no Soma - 22 [1080p].mkv (1).torrent
2015-09-01 17:27 - 2015-09-01 17:27 - 00001337 _____ C:\Users\Public\Desktop\Razer Comms.lnk
2015-09-01 17:26 - 2015-09-01 17:27 - 97494000 _____ (Razer Inc.) C:\Users\Lestoli\Downloads\RazerComms5.11.52.exe
2015-08-31 17:41 - 2015-09-01 17:27 - 00000000 ____D C:\Users\Lestoli\AppData\Roaming\Ventrilo
2015-08-31 17:39 - 2015-08-31 17:39 - 03786512 _____ C:\Users\Lestoli\Downloads\ventrilo-3.0.8-Windows-i386 (1).exe
2015-08-31 17:39 - 2015-08-31 17:39 - 00000886 _____ C:\Users\Public\Desktop\Ventrilo.lnk
2015-08-31 17:39 - 2015-08-31 17:39 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Ventrilo
2015-08-31 17:39 - 2015-08-31 17:39 - 00000000 ____D C:\Program Files (x86)\Ventrilo
2015-08-31 17:38 - 2015-08-31 17:39 - 03786512 _____ C:\Users\Lestoli\Downloads\ventrilo-3.0.8-Windows-i386.exe
2015-08-30 19:10 - 2015-08-30 19:10 - 00060425 _____ C:\Users\Lestoli\Downloads\[HorribleSubs] Prison School - 04 [1080p].mkv.torrent
2015-08-29 23:11 - 2015-08-29 23:11 - 00000000 ____D C:\Program Files (x86)\Microsoft XNA
2015-08-29 23:10 - 2015-08-29 23:10 - 00000221 _____ C:\Users\Lestoli\Desktop\Magicka - Demo.url
2015-08-29 21:28 - 2015-08-29 21:28 - 00045609 _____ C:\Users\Lestoli\Downloads\[HorribleSubs] Shokugeki no Soma - 21 [1080p].mkv.torrent
2015-08-28 18:10 - 2015-08-28 18:10 - 00000000 ____D C:\Users\Lestoli\Documents\Diablo III
2015-08-28 18:05 - 2015-08-28 18:05 - 00000682 _____ C:\Users\Public\Desktop\Diablo III.lnk
2015-08-28 18:05 - 2015-08-28 18:05 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Diablo III
2015-08-28 17:59 - 2015-09-06 12:33 - 00000000 ___RD C:\Users\Lestoli\Dropbox
2015-08-28 17:59 - 2015-08-28 17:59 - 00001245 _____ C:\Users\Lestoli\Desktop\Dropbox.lnk
2015-08-28 17:58 - 2015-08-28 17:58 - 00000000 ____D C:\Users\Lestoli\AppData\Roaming\Dropbox
2015-08-28 17:58 - 2015-08-28 17:58 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox
2015-08-28 17:57 - 2015-09-09 15:02 - 00000928 _____ C:\Windows\Tasks\DropboxUpdateTaskMachineUA.job
2015-08-28 17:57 - 2015-09-09 15:00 - 00000924 _____ C:\Windows\Tasks\DropboxUpdateTaskMachineCore.job
2015-08-28 17:57 - 2015-09-04 19:15 - 00000000 ____D C:\Users\Lestoli\AppData\Local\Dropbox
2015-08-28 17:57 - 2015-08-28 17:58 - 00000000 ____D C:\Program Files (x86)\Dropbox
2015-08-28 17:57 - 2015-08-28 17:57 - 00660960 _____ (Dropbox, Inc.) C:\Users\Lestoli\Downloads\DropboxInstaller.exe
2015-08-28 17:57 - 2015-08-28 17:57 - 00003900 _____ C:\Windows\System32\Tasks\DropboxUpdateTaskMachineUA
2015-08-28 17:57 - 2015-08-28 17:57 - 00003664 _____ C:\Windows\System32\Tasks\DropboxUpdateTaskMachineCore
2015-08-28 17:57 - 2015-08-28 17:57 - 00000000 ____D C:\ProgramData\Dropbox
2015-08-28 17:50 - 2015-08-28 17:51 - 03071032 _____ (Blizzard Entertainment) C:\Users\Lestoli\Downloads\Diablo-III-Setup-enUS.exe
2015-08-26 23:41 - 2015-08-27 00:21 - 00000000 ____D C:\Users\Lestoli\AppData\Local\Glyph
2015-08-26 23:41 - 2015-08-26 23:41 - 00001012 _____ C:\Users\Lestoli\Desktop\Glyph.lnk
2015-08-26 23:41 - 2015-08-26 23:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Glyph
2015-08-26 23:41 - 2015-08-26 23:41 - 00000000 ____D C:\ProgramData\Glyph
2015-08-26 23:41 - 2015-08-26 23:41 - 00000000 ____D C:\Program Files (x86)\Glyph
2015-08-26 23:40 - 2015-08-26 23:41 - 31311736 _____ (Trion Worlds Inc.) C:\Users\Lestoli\Downloads\GlyphInstall-9999-130.exe
2015-08-24 17:35 - 2015-08-24 17:35 - 00000000 ____D C:\Users\Lestoli\AppData\Roaming\NVIDIA
2015-08-24 17:32 - 2015-08-29 10:09 - 00000000 ____D C:\Users\Lestoli\AppData\Local\Purplizer
2015-08-24 17:30 - 2015-08-27 01:02 - 00000000 ____D C:\Program Files (x86)\Overwolf
2015-08-24 17:30 - 2015-08-24 17:30 - 00003728 _____ C:\Windows\System32\Tasks\Overwolf Updater Task
2015-08-24 17:30 - 2015-08-24 17:30 - 00001986 _____ C:\Users\Public\Desktop\Overwolf.lnk
2015-08-24 17:30 - 2015-08-24 17:30 - 00000000 ____D C:\Users\Lestoli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Overwolf
2015-08-24 17:29 - 2015-09-09 15:00 - 00000000 ____D C:\Users\Lestoli\AppData\Local\Overwolf
2015-08-24 17:29 - 2015-08-24 17:31 - 00000000 ____D C:\ProgramData\Overwolf
2015-08-24 17:29 - 2015-08-24 17:29 - 01704176 _____ (Overwolf) C:\Users\Lestoli\Downloads\OverwolfInstaller.exe
2015-08-23 22:29 - 2015-08-23 22:29 - 00004720 _____ C:\Windows\windefendam.log
2015-08-23 22:29 - 2015-08-23 22:29 - 00002054 _____ C:\Users\Public\Desktop\Action!.lnk
2015-08-23 22:29 - 2015-08-23 22:29 - 00000020 _____ C:\Windows\capsys184523.log
2015-08-23 22:29 - 2015-08-23 22:29 - 00000000 ____D C:\Users\Lestoli\AppData\Roaming\Mirillis
2015-08-23 22:29 - 2015-08-23 22:29 - 00000000 ____D C:\Users\Lestoli\AppData\Local\Mirillis
2015-08-23 22:29 - 2015-08-23 22:29 - 00000000 ____D C:\ProgramData\Mirillis
2015-08-23 22:29 - 2015-08-23 22:29 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mirillis
2015-08-23 22:29 - 2015-08-23 22:29 - 00000000 ____D C:\Action!
2015-08-23 22:28 - 2015-08-23 22:28 - 00000000 ____D C:\Program Files (x86)\Mirillis
2015-08-23 22:27 - 2015-08-23 22:27 - 19909352 _____ (Mirillis Ltd.) C:\Users\Lestoli\Downloads\action_1_26_0_setup.exe
2015-08-21 14:35 - 2015-08-21 14:35 - 00045669 _____ C:\Users\Lestoli\Downloads\[HorribleSubs] Shokugeki no Soma - 20 [1080p].mkv.torrent
2015-08-21 12:11 - 2015-08-21 12:11 - 00000000 ___RD C:\Program Files (x86)\Skype
2015-08-21 12:11 - 2015-08-21 12:11 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2015-08-19 20:50 - 2015-08-19 20:50 - 00000000 ____D C:\Users\Lestoli\AppData\Roaming\Unity
2015-08-19 20:45 - 2015-08-19 20:45 - 01088664 _____ (Unity Technologies ApS) C:\Users\Lestoli\Downloads\UnityWebPlayer (5).exe
2015-08-19 20:45 - 2015-08-19 20:45 - 01088664 _____ (Unity Technologies ApS) C:\Users\Lestoli\Downloads\UnityWebPlayer (4).exe
2015-08-19 20:44 - 2015-08-19 20:50 - 00000000 ____D C:\Users\Lestoli\AppData\Local\Mozilla
2015-08-19 20:44 - 2015-08-19 20:44 - 00242768 _____ C:\Users\Lestoli\Downloads\Firefox Setup Stub 40.0.2.exe
2015-08-19 20:44 - 2015-08-19 20:44 - 00001174 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-08-19 20:44 - 2015-08-19 20:44 - 00001162 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2015-08-19 20:44 - 2015-08-19 20:44 - 00000000 ____D C:\Users\Lestoli\AppData\Roaming\Mozilla
2015-08-19 20:44 - 2015-08-19 20:44 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2015-08-19 20:44 - 2015-08-19 20:44 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2015-08-19 20:43 - 2015-08-19 20:43 - 01088664 _____ (Unity Technologies ApS) C:\Users\Lestoli\Downloads\UnityWebPlayer (3).exe
2015-08-19 20:43 - 2015-08-19 20:43 - 01088664 _____ (Unity Technologies ApS) C:\Users\Lestoli\Downloads\UnityWebPlayer (2).exe
2015-08-19 20:40 - 2015-08-19 20:40 - 01088664 _____ (Unity Technologies ApS) C:\Users\Lestoli\Downloads\UnityWebPlayer.exe
2015-08-19 20:40 - 2015-08-19 20:40 - 01088664 _____ (Unity Technologies ApS) C:\Users\Lestoli\Downloads\UnityWebPlayer (1).exe
2015-08-19 20:40 - 2015-08-19 20:40 - 00000000 ____D C:\Users\Lestoli\AppData\Local\Unity
2015-08-19 18:49 - 2015-08-19 18:49 - 00000000 ____D C:\Users\Lestoli\Documents\Strife
2015-08-19 18:49 - 2010-06-02 04:55 - 00239960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_7.dll
2015-08-19 18:49 - 2010-06-02 04:55 - 00176984 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_7.dll
2015-08-19 18:49 - 2010-05-26 11:41 - 01907552 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_43.dll
2015-08-19 18:49 - 2010-05-26 11:41 - 01868128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dcsx_43.dll
2015-08-19 18:49 - 2010-02-04 10:01 - 00530776 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_6.dll
2015-08-19 18:49 - 2010-02-04 10:01 - 00528216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_6.dll
2015-08-19 18:49 - 2010-02-04 10:01 - 00238936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_6.dll
2015-08-19 18:49 - 2010-02-04 10:01 - 00176984 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_6.dll
2015-08-19 18:49 - 2010-02-04 10:01 - 00078680 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_4.dll
2015-08-19 18:49 - 2010-02-04 10:01 - 00074072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_4.dll
2015-08-19 18:49 - 2009-09-04 17:44 - 00517960 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_5.dll
2015-08-19 18:49 - 2009-09-04 17:44 - 00515416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_5.dll
2015-08-19 18:49 - 2009-09-04 17:44 - 00238936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_5.dll
2015-08-19 18:49 - 2009-09-04 17:44 - 00176968 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_5.dll
2015-08-19 18:49 - 2009-09-04 17:44 - 00073544 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_3.dll
2015-08-19 18:49 - 2009-09-04 17:44 - 00069464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_3.dll
2015-08-19 18:49 - 2009-09-04 17:29 - 05554512 _____ (Microsoft Corporation) C:\Windows\system32\d3dcsx_42.dll
2015-08-19 18:49 - 2009-09-04 17:29 - 05501792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dcsx_42.dll
2015-08-19 18:49 - 2009-09-04 17:29 - 02582888 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_42.dll
2015-08-19 18:49 - 2009-09-04 17:29 - 02475352 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_42.dll
2015-08-19 18:49 - 2009-09-04 17:29 - 00523088 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_42.dll
2015-08-19 18:49 - 2009-09-04 17:29 - 00285024 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_42.dll
2015-08-19 18:49 - 2009-03-16 14:18 - 00521560 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_4.dll
2015-08-19 18:49 - 2009-03-16 14:18 - 00517448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_4.dll
2015-08-19 18:49 - 2009-03-16 14:18 - 00235352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_4.dll
2015-08-19 18:49 - 2009-03-16 14:18 - 00174936 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_4.dll
2015-08-19 18:49 - 2009-03-16 14:18 - 00024920 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_6.dll
2015-08-19 18:49 - 2009-03-16 14:18 - 00022360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_6.dll
2015-08-19 18:49 - 2009-03-09 15:27 - 05425496 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_41.dll
2015-08-19 18:49 - 2009-03-09 15:27 - 02430312 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_41.dll
2015-08-19 18:49 - 2009-03-09 15:27 - 01846632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_41.dll
2015-08-19 18:49 - 2009-03-09 15:27 - 00520544 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_41.dll
2015-08-19 18:49 - 2009-03-09 15:27 - 00453456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_41.dll
2015-08-19 18:49 - 2008-10-27 10:04 - 00518480 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_3.dll
2015-08-19 18:49 - 2008-10-27 10:04 - 00514384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_3.dll
2015-08-19 18:49 - 2008-10-27 10:04 - 00235856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_3.dll
2015-08-19 18:49 - 2008-10-27 10:04 - 00175440 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_3.dll
2015-08-19 18:49 - 2008-10-27 10:04 - 00074576 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_2.dll
2015-08-19 18:49 - 2008-10-27 10:04 - 00070992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_2.dll
2015-08-19 18:49 - 2008-10-27 10:04 - 00025936 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_5.dll
2015-08-19 18:49 - 2008-10-27 10:04 - 00023376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_5.dll
2015-08-19 18:49 - 2008-10-15 06:22 - 05631312 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_40.dll
2015-08-19 18:49 - 2008-10-15 06:22 - 04379984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_40.dll
2015-08-19 18:49 - 2008-10-15 06:22 - 02605920 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_40.dll
2015-08-19 18:49 - 2008-10-15 06:22 - 02036576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_40.dll
2015-08-19 18:49 - 2008-10-15 06:22 - 00519000 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_40.dll
2015-08-19 18:49 - 2008-10-15 06:22 - 00452440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_40.dll
2015-08-19 18:49 - 2008-07-31 10:41 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_2.dll
2015-08-19 18:49 - 2008-07-31 10:41 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_2.dll
2015-08-19 18:49 - 2008-07-31 10:41 - 00072200 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_1.dll
2015-08-19 18:49 - 2008-07-31 10:40 - 00513544 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_2.dll
2015-08-19 18:49 - 2008-07-10 11:00 - 04992520 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_39.dll
2015-08-19 18:49 - 2008-07-10 11:00 - 01942552 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_39.dll
2015-08-19 18:49 - 2008-07-10 11:00 - 00540688 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_39.dll
2015-08-19 18:49 - 2008-05-30 14:19 - 00511496 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_1.dll
2015-08-19 18:49 - 2008-05-30 14:19 - 00507400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_1.dll
2015-08-19 18:49 - 2008-05-30 14:18 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_1.dll
2015-08-19 18:49 - 2008-05-30 14:18 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_1.dll
2015-08-19 18:49 - 2008-05-30 14:17 - 00068104 _____ (Microsoft Corporation) C:\Windows\system32\XAPOFX1_0.dll
2015-08-19 18:49 - 2008-05-30 14:17 - 00065032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAPOFX1_0.dll
2015-08-19 18:49 - 2008-05-30 14:17 - 00025608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_4.dll
2015-08-19 18:49 - 2008-05-30 14:16 - 00028168 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_4.dll
2015-08-19 18:49 - 2008-05-30 14:11 - 04991496 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_38.dll
2015-08-19 18:49 - 2008-05-30 14:11 - 03850760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_38.dll
2015-08-19 18:49 - 2008-05-30 14:11 - 01941528 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_38.dll
2015-08-19 18:49 - 2008-05-30 14:11 - 01491992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_38.dll
2015-08-19 18:49 - 2008-05-30 14:11 - 00540688 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_38.dll
2015-08-19 18:49 - 2008-05-30 14:11 - 00467984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_38.dll
2015-08-19 18:49 - 2008-03-05 16:04 - 00489480 _____ (Microsoft Corporation) C:\Windows\system32\XAudio2_0.dll
2015-08-19 18:49 - 2008-03-05 16:03 - 00479752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XAudio2_0.dll
2015-08-19 18:49 - 2008-03-05 16:03 - 00238088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine3_0.dll
2015-08-19 18:49 - 2008-03-05 16:03 - 00177672 _____ (Microsoft Corporation) C:\Windows\system32\xactengine3_0.dll
2015-08-19 18:49 - 2008-03-05 16:00 - 00028168 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_3.dll
2015-08-19 18:49 - 2008-03-05 16:00 - 00025608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_3.dll
2015-08-19 18:49 - 2008-03-05 15:56 - 04910088 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_37.dll
2015-08-19 18:49 - 2008-03-05 15:56 - 03786760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_37.dll
2015-08-19 18:49 - 2008-03-05 15:56 - 01860120 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_37.dll
2015-08-19 18:49 - 2008-03-05 15:56 - 01420824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_37.dll
2015-08-19 18:49 - 2008-02-05 23:07 - 00529424 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_37.dll
2015-08-19 18:49 - 2008-02-05 23:07 - 00462864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_37.dll
2015-08-19 18:49 - 2007-10-22 03:40 - 00411656 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_10.dll
2015-08-19 18:49 - 2007-10-22 03:39 - 00267272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_10.dll
2015-08-19 18:49 - 2007-10-22 03:37 - 00021000 _____ (Microsoft Corporation) C:\Windows\system32\X3DAudio1_2.dll
2015-08-19 18:49 - 2007-10-22 03:37 - 00017928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\X3DAudio1_2.dll
2015-08-19 18:49 - 2007-10-12 15:14 - 05081608 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_36.dll
2015-08-19 18:49 - 2007-10-12 15:14 - 03734536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_36.dll
2015-08-19 18:49 - 2007-10-12 15:14 - 02006552 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_36.dll
2015-08-19 18:49 - 2007-10-12 15:14 - 01374232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_36.dll
2015-08-19 18:49 - 2007-10-02 09:56 - 00508264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_36.dll
2015-08-19 18:49 - 2007-10-02 09:56 - 00444776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_36.dll
2015-08-19 18:49 - 2007-07-20 00:57 - 00411496 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_9.dll
2015-08-19 18:49 - 2007-07-20 00:57 - 00267112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_9.dll
2015-08-19 18:49 - 2007-07-19 18:14 - 05073256 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_35.dll
2015-08-19 18:49 - 2007-07-19 18:14 - 03727720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_35.dll
2015-08-19 18:49 - 2007-07-19 18:14 - 01985904 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_35.dll
2015-08-19 18:49 - 2007-07-19 18:14 - 01358192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_35.dll
2015-08-19 18:49 - 2007-07-19 18:14 - 00508264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_35.dll
2015-08-19 18:49 - 2007-07-19 18:14 - 00444776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_35.dll
2015-08-19 18:49 - 2007-06-20 20:49 - 00409960 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_8.dll
2015-08-19 18:49 - 2007-06-20 20:46 - 00266088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_8.dll
2015-08-19 18:49 - 2007-05-16 16:45 - 04496232 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_34.dll
2015-08-19 18:49 - 2007-05-16 16:45 - 03497832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_34.dll
2015-08-19 18:49 - 2007-05-16 16:45 - 01401200 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_34.dll
2015-08-19 18:49 - 2007-05-16 16:45 - 01124720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_34.dll
2015-08-19 18:49 - 2007-05-16 16:45 - 00506728 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_34.dll
2015-08-19 18:49 - 2007-05-16 16:45 - 00443752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_34.dll
2015-08-19 18:49 - 2007-04-04 18:55 - 00403304 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_7.dll
2015-08-19 18:49 - 2007-04-04 18:55 - 00261480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_7.dll
2015-08-19 18:48 - 2015-08-19 18:48 - 00000000 ____D C:\ProgramData\Package Cache
2015-08-19 18:48 - 2007-03-15 16:57 - 00506728 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_33.dll
2015-08-19 18:48 - 2007-03-15 16:57 - 00443752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_33.dll
2015-08-19 18:48 - 2007-03-12 16:42 - 04494184 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_33.dll
2015-08-19 18:48 - 2007-03-12 16:42 - 01400176 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_33.dll
2015-08-19 18:48 - 2007-03-12 16:42 - 01123696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_33.dll
2015-08-19 18:48 - 2007-03-05 12:42 - 00017688 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_1.dll
2015-08-19 18:48 - 2007-03-05 12:42 - 00015128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\x3daudio1_1.dll
2015-08-19 18:48 - 2007-01-24 15:27 - 00393576 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_6.dll
2015-08-19 18:48 - 2007-01-24 15:27 - 00255848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_6.dll
2015-08-19 18:48 - 2006-12-08 12:02 - 00251672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_5.dll
2015-08-19 18:48 - 2006-12-08 12:00 - 00390424 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_5.dll
2015-08-19 18:48 - 2006-11-29 13:06 - 04398360 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_32.dll
2015-08-19 18:48 - 2006-11-29 13:06 - 03426072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_32.dll
2015-08-19 18:48 - 2006-11-29 13:06 - 00469264 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10.dll
2015-08-19 18:48 - 2006-11-29 13:06 - 00440080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10.dll
2015-08-19 18:48 - 2006-09-28 16:05 - 03977496 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_31.dll
2015-08-19 18:48 - 2006-09-28 16:05 - 02414360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_31.dll
2015-08-19 18:48 - 2006-09-28 16:05 - 00237848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_4.dll
2015-08-19 18:48 - 2006-09-28 16:04 - 00364824 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_4.dll
2015-08-19 18:48 - 2006-07-28 09:31 - 00083736 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_2.dll
2015-08-19 18:48 - 2006-07-28 09:30 - 00363288 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_3.dll
2015-08-19 18:48 - 2006-07-28 09:30 - 00236824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_3.dll
2015-08-19 18:48 - 2006-07-28 09:30 - 00062744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_2.dll
2015-08-19 18:48 - 2006-05-31 07:24 - 00230168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_2.dll
2015-08-19 18:48 - 2006-05-31 07:22 - 00354072 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_2.dll
2015-08-19 18:48 - 2006-03-31 12:41 - 03927248 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_30.dll
2015-08-19 18:48 - 2006-03-31 12:40 - 02388176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_30.dll
2015-08-19 18:48 - 2006-03-31 12:40 - 00352464 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_1.dll
2015-08-19 18:48 - 2006-03-31 12:39 - 00229584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_1.dll
2015-08-19 18:48 - 2006-03-31 12:39 - 00083664 _____ (Microsoft Corporation) C:\Windows\system32\xinput1_1.dll
2015-08-19 18:48 - 2006-03-31 12:39 - 00062672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xinput1_1.dll
2015-08-19 18:48 - 2006-02-03 08:43 - 03830992 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_29.dll
2015-08-19 18:48 - 2006-02-03 08:43 - 02332368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_29.dll
2015-08-19 18:48 - 2006-02-03 08:42 - 00355536 _____ (Microsoft Corporation) C:\Windows\system32\xactengine2_0.dll
2015-08-19 18:48 - 2006-02-03 08:42 - 00230096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xactengine2_0.dll
2015-08-19 18:48 - 2006-02-03 08:41 - 00016592 _____ (Microsoft Corporation) C:\Windows\system32\x3daudio1_0.dll
2015-08-19 18:48 - 2006-02-03 08:41 - 00014032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\x3daudio1_0.dll
2015-08-19 18:48 - 2005-12-05 18:09 - 03815120 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_28.dll
2015-08-19 18:48 - 2005-12-05 18:09 - 02323664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_28.dll
2015-08-19 18:48 - 2005-07-22 19:59 - 03807440 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_27.dll
2015-08-19 18:48 - 2005-07-22 19:59 - 02319568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_27.dll
2015-08-19 18:48 - 2005-05-26 15:34 - 03767504 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_26.dll
2015-08-19 18:48 - 2005-05-26 15:34 - 02297552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_26.dll
2015-08-19 18:48 - 2005-03-18 17:19 - 03823312 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_25.dll
2015-08-19 18:48 - 2005-03-18 17:19 - 02337488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_25.dll
2015-08-19 18:48 - 2005-02-05 19:45 - 03544272 _____ (Microsoft Corporation) C:\Windows\system32\d3dx9_24.dll
2015-08-19 18:48 - 2005-02-05 19:45 - 02222800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_24.dll
2015-08-19 18:33 - 2015-08-19 18:33 - 00000222 _____ C:\Users\Lestoli\Desktop\Strife.url
2015-08-18 20:26 - 2015-08-18 20:26 - 00000000 ____D C:\Users\Lestoli\AppData\Local\Steam
2015-08-18 20:26 - 2015-08-18 20:26 - 00000000 ____D C:\Users\Lestoli\AppData\Local\CEF
2015-08-18 20:24 - 2015-09-09 15:00 - 00000000 ____D C:\Program Files (x86)\Steam
2015-08-18 20:24 - 2015-08-18 20:24 - 01476720 _____ C:\Users\Lestoli\Downloads\SteamSetup.exe
2015-08-18 20:24 - 2015-08-18 20:24 - 00000978 _____ C:\Users\Public\Desktop\Steam.lnk
2015-08-18 20:24 - 2015-08-18 20:24 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
2015-08-17 20:23 - 2015-08-28 21:40 - 00000000 ____D C:\Users\Lestoli\Documents\Heroes of the Storm
2015-08-17 20:16 - 2015-08-17 20:16 - 00000723 _____ C:\Users\Public\Desktop\Heroes of the Storm.lnk
2015-08-17 20:16 - 2015-08-17 20:16 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Heroes of the Storm
2015-08-17 19:56 - 2015-09-07 20:07 - 00000000 ____D C:\Users\Lestoli\AppData\Local\Battle.net
2015-08-17 19:56 - 2015-08-28 17:53 - 00000000 ____D C:\Program Files (x86)\Battle.net
2015-08-17 19:56 - 2015-08-28 17:51 - 00000000 ____D C:\Users\Lestoli\AppData\Roaming\Battle.net
2015-08-17 19:56 - 2015-08-17 20:23 - 00000000 ____D C:\ProgramData\Blizzard Entertainment
2015-08-17 19:56 - 2015-08-17 19:56 - 00001159 _____ C:\Users\Public\Desktop\Battle.net.lnk
2015-08-17 19:56 - 2015-08-17 19:56 - 00000000 ____D C:\Users\Lestoli\AppData\Local\Blizzard Entertainment
2015-08-17 19:56 - 2015-08-17 19:56 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Battle.net
2015-08-17 19:55 - 2015-08-17 19:55 - 00000000 ____D C:\ProgramData\Battle.net
2015-08-17 19:54 - 2015-08-17 19:55 - 03080760 _____ (Blizzard Entertainment) C:\Users\Lestoli\Downloads\Heroes-of-the-Storm-Setup-enUS.exe
2015-08-16 22:25 - 2015-08-16 22:25 - 00060905 _____ C:\Users\Lestoli\Downloads\[HorribleSubs] Prison School - 03 [1080p].mkv.torrent
2015-08-16 22:25 - 2015-08-16 22:25 - 00044381 _____ C:\Users\Lestoli\Downloads\[HorribleSubs] Charlotte - 03 [1080p].mkv.torrent
2015-08-16 15:06 - 2015-08-16 15:06 - 00000833 _____ C:\Users\Lestoli\Desktop\Play Wizard101.lnk
2015-08-16 15:06 - 2015-08-16 15:06 - 00000000 ____D C:\Users\Lestoli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\KingsIsle Entertainment
2015-08-16 15:06 - 2015-08-16 15:06 - 00000000 ____D C:\Users\Lestoli\AppData\Roaming\InstallShield Installation Information
2015-08-16 15:06 - 2015-08-16 15:06 - 00000000 ____D C:\ProgramData\KingsIsle Entertainment
2015-08-16 15:05 - 2015-08-16 15:06 - 12257624 _____ (Acresso Software Inc.) C:\Users\Lestoli\Downloads\InstallWizard101.exe
2015-08-15 21:04 - 2015-09-07 16:54 - 00000000 ____D C:\Users\Lestoli\Desktop\English Patch
2015-08-15 20:58 - 2015-08-15 20:59 - 109621275 _____ C:\Users\Lestoli\Downloads\EnglishPack.2015.7.9.zip
2015-08-15 20:57 - 2015-08-15 20:57 - 03609430 _____ C:\Users\Lestoli\Downloads\BladeAndSoulTWLauncher.0.0.2.4.zip
2015-08-15 20:57 - 2015-08-15 20:57 - 00000000 ____D C:\Users\Lestoli\Desktop\Launcher
2015-08-14 16:59 - 2015-08-14 16:59 - 00045589 _____ C:\Users\Lestoli\Downloads\[HorribleSubs] Shokugeki no Soma - 19 [1080p].mkv.torrent
2015-08-14 14:38 - 2015-08-14 14:38 - 00000000 ____D C:\Users\Lestoli\AppData\Local\Dungeons & Dragons Online
2015-08-14 14:04 - 2015-08-22 14:36 - 00000000 ____D C:\Users\Lestoli\Documents\Dungeons and Dragons Online
2015-08-14 14:04 - 2015-08-14 17:41 - 00001014 _____ C:\Users\Lestoli\Desktop\Dungeons and Dragons Online™.lnk
2015-08-14 14:04 - 2015-08-14 14:05 - 00000000 ____D C:\Users\Lestoli\AppData\Local\Turbine
2015-08-14 14:02 - 2015-08-14 14:01 - 04178264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_41.dll
2015-08-14 14:02 - 2009-09-04 17:29 - 01974616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_42.dll
2015-08-14 14:02 - 2009-09-04 17:29 - 01892184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_42.dll
2015-08-14 14:02 - 2009-09-04 17:29 - 00453456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_42.dll
2015-08-14 14:02 - 2009-09-04 17:29 - 00235344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx11_42.dll
2015-08-14 14:02 - 2007-03-12 16:42 - 03495784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx9_33.dll
2015-08-14 14:01 - 2015-08-14 14:02 - 00880342 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2015-08-14 14:01 - 2015-08-14 14:01 - 00000000 ____D C:\Windows\SysWOW64\URTTEMP
2015-08-14 14:00 - 2015-08-14 14:00 - 00000000 ____D C:\Users\Lestoli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Turbine
2015-08-14 13:59 - 2015-08-22 19:26 - 00000000 ____D C:\ProgramData\HappyCloud
2015-08-14 13:59 - 2015-08-14 13:59 - 00000000 ____D C:\Users\Lestoli\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Happy Cloud
2015-08-14 13:58 - 2015-08-14 13:59 - 08152680 _____ C:\Users\Lestoli\Downloads\DDOProgressive_4.28.exe
2015-08-14 12:29 - 2015-07-30 07:04 - 00124624 _____ (Microsoft Corporation) C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
2015-08-14 12:29 - 2015-07-30 06:48 - 00103120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2015-08-13 20:12 - 2015-08-13 20:12 - 00046109 _____ C:\Users\Lestoli\Downloads\[HorribleSubs] Shokugeki no Soma - 18 [1080p].mkv.torrent
2015-08-13 17:15 - 2015-07-28 16:24 - 00025776 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe
2015-08-13 17:15 - 2015-07-28 07:24 - 01148416 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2015-08-13 17:15 - 2015-07-28 07:24 - 01116160 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2015-08-13 17:15 - 2015-07-28 07:24 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2015-08-13 17:15 - 2015-07-28 07:24 - 00743424 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2015-08-13 17:15 - 2015-07-28 07:24 - 00437248 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2015-08-13 17:15 - 2015-07-28 07:24 - 00069120 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2015-08-13 17:15 - 2015-07-15 17:29 - 07458648 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2015-08-13 17:15 - 2015-07-15 17:29 - 01735000 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2015-08-13 17:15 - 2015-07-15 17:29 - 00101720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mountmgr.sys
2015-08-13 17:15 - 2015-07-15 17:28 - 01499920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2015-08-13 17:15 - 2015-07-10 10:54 - 01217024 _____ (Microsoft Corporation) C:\Windows\system32\sysmain.dll
2015-08-13 17:15 - 2015-07-01 15:19 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll
2015-08-13 17:15 - 2015-07-01 15:16 - 00104448 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll
2015-08-13 17:15 - 2015-07-01 14:37 - 00198656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebClnt.dll
2015-08-13 17:15 - 2015-07-01 14:35 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\davclnt.dll
2015-08-13 17:14 - 2015-07-16 13:36 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-08-13 17:14 - 2015-07-16 13:23 - 00615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-08-13 17:14 - 2015-07-16 12:53 - 00145408 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2015-08-13 17:14 - 2015-07-16 12:50 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2015-08-13 17:14 - 2015-07-16 12:41 - 00479232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2015-08-13 17:14 - 2015-07-16 12:14 - 02880000 _____ (Microsoft Corporation) C:\Windows\system32\actxprxy.dll
2015-08-13 17:14 - 2015-07-16 11:52 - 01048576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\actxprxy.dll
2015-08-13 17:13 - 2015-07-14 14:59 - 01113944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys
2015-08-13 17:13 - 2015-07-14 14:59 - 00487256 _____ (Microsoft Corporation) C:\Windows\system32\netcfgx.dll
2015-08-13 17:13 - 2015-07-14 14:59 - 00393560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\netcfgx.dll
2015-08-13 17:13 - 2015-07-13 12:46 - 00059392 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2015-08-13 17:13 - 2015-07-13 12:45 - 00059392 _____ (Microsoft Corporation) C:\Windows\system32\basesrv.dll
2015-08-13 17:13 - 2015-07-10 11:19 - 01101824 _____ (Microsoft Corporation) C:\Windows\system32\rdvidcrl.dll
2015-08-13 17:13 - 2015-07-10 10:14 - 00856064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdvidcrl.dll
2015-08-13 17:13 - 2015-07-10 10:13 - 07032320 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2015-08-13 17:13 - 2015-07-10 09:31 - 06213120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2015-08-13 17:13 - 2015-07-09 10:13 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\notepad.exe
2015-08-13 17:13 - 2015-07-09 10:13 - 00221184 _____ (Microsoft Corporation) C:\Windows\notepad.exe
2015-08-13 17:13 - 2015-07-09 09:30 - 00212992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
2015-08-13 17:13 - 2015-07-07 02:40 - 00270168 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdFilter.sys
2015-08-13 17:13 - 2015-07-07 02:40 - 00114520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdNisDrv.sys
2015-08-13 17:13 - 2015-07-07 02:40 - 00044560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdBoot.sys
2015-08-13 17:13 - 2015-06-12 10:03 - 18823680 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.dll
2015-08-13 17:13 - 2015-06-12 09:36 - 15159296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.dll
2015-08-13 17:13 - 2015-06-11 13:12 - 02476376 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2015-08-13 17:13 - 2015-06-11 13:12 - 00428888 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS
2015-08-13 17:12 - 2015-07-29 07:37 - 01994752 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2015-08-13 17:12 - 2015-07-29 07:30 - 01381888 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2015-08-13 17:12 - 2015-07-29 07:23 - 01559552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-09-09 15:11 - 2015-07-21 17:34 - 01643810 _____ C:\Windows\WindowsUpdate.log
2015-09-09 15:05 - 2015-07-21 17:40 - 00003596 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-699846955-1419679699-1553032801-1001
2015-09-09 15:04 - 2015-07-21 17:37 - 00892712 _____ C:\Windows\system32\PerfStringBackup.INI
2015-09-09 15:01 - 2015-07-21 17:45 - 00000924 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-09-09 15:00 - 2015-07-24 21:07 - 00000000 ____D C:\Users\Lestoli\AppData\Roaming\uTorrent
2015-09-09 15:00 - 2015-07-21 18:04 - 00000000 ____D C:\Users\Lestoli\AppData\Roaming\Skype
2015-09-09 15:00 - 2015-07-21 17:45 - 00000920 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-09-09 15:00 - 2013-08-22 08:36 - 00000000 ____D C:\Windows\system32\sru
2015-09-09 14:59 - 2015-07-21 17:47 - 00000000 ____D C:\ProgramData\NVIDIA
2015-09-09 14:59 - 2013-08-22 07:46 - 00019877 _____ C:\Windows\setupact.log
2015-09-09 14:59 - 2013-08-22 07:45 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-09-09 14:59 - 2013-08-22 07:44 - 00338032 _____ C:\Windows\system32\FNTCACHE.DAT
2015-09-09 14:58 - 2015-07-21 17:32 - 00009590 _____ C:\Windows\PFRO.log
2015-09-09 14:58 - 2013-08-22 08:36 - 00000000 ____D C:\Windows\PolicyDefinitions
2015-09-09 14:57 - 2013-08-22 06:25 - 00262144 ___SH C:\Windows\system32\config\BBI
2015-09-09 14:56 - 2015-07-21 17:35 - 00000000 ____D C:\Users\Lestoli
2015-09-09 12:11 - 2015-07-21 17:44 - 00003934 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{80D92C5A-C936-4B73-9486-C9B5CA0DA749}
2015-09-09 10:45 - 2015-07-24 21:34 - 00000000 ____D C:\Users\Lestoli\AppData\Roaming\vlc
2015-09-09 05:57 - 2013-08-22 08:36 - 00000000 ____D C:\Windows\rescache
2015-09-08 21:34 - 2013-08-22 12:11 - 00000000 ____D C:\Program Files\Windows Journal
2015-09-08 21:34 - 2013-08-22 08:20 - 00000000 ____D C:\Windows\CbsTemp
2015-09-08 21:33 - 2015-07-23 21:47 - 00000000 ____D C:\Windows\system32\MRT
2015-09-08 20:08 - 2013-08-22 08:36 - 00000000 ____D C:\Windows\system32\NDF
2015-09-06 20:33 - 2015-07-21 17:45 - 00000000 ____D C:\Program Files (x86)\Google
2015-09-04 20:02 - 2015-07-21 17:45 - 00002206 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-09-01 17:27 - 2015-07-25 15:54 - 00000000 ____D C:\Users\Lestoli\AppData\Local\Razer
2015-09-01 17:27 - 2015-07-25 15:53 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Razer
2015-09-01 17:27 - 2015-07-21 17:53 - 00000000 ____D C:\ProgramData\Razer
2015-09-01 17:27 - 2015-07-21 17:53 - 00000000 ____D C:\Program Files (x86)\Razer
2015-08-30 01:56 - 2015-07-21 17:45 - 00003896 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-08-30 01:56 - 2015-07-21 17:45 - 00003660 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2015-08-26 18:37 - 2015-07-23 21:47 - 134753440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-08-22 22:54 - 2013-08-22 08:36 - 00000000 ____D C:\Windows\AppReadiness
2015-08-21 12:11 - 2015-07-21 18:04 - 00002713 _____ C:\Users\Public\Desktop\Skype.lnk
2015-08-21 12:11 - 2015-07-21 18:04 - 00000000 ____D C:\ProgramData\Skype
2015-08-19 18:49 - 2015-07-21 18:35 - 00010450 _____ C:\Windows\DirectX.log
2015-08-14 14:02 - 2013-08-22 08:36 - 00000000 ____D C:\Windows\Registration
2015-08-14 12:30 - 2015-07-30 18:04 - 00000000 ___SD C:\Windows\system32\CompatTel
2015-08-14 12:30 - 2015-07-30 18:04 - 00000000 ____D C:\Windows\system32\appraiser
2015-08-14 12:30 - 2013-08-22 08:36 - 00000000 ___RD C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-08-14 12:30 - 2013-08-22 08:36 - 00000000 ___RD C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-08-14 12:30 - 2013-08-22 08:36 - 00000000 ___RD C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-08-14 12:30 - 2013-08-22 08:36 - 00000000 ___RD C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-08-14 12:30 - 2013-08-22 08:36 - 00000000 ____D C:\Program Files\Windows Defender
2015-08-14 12:30 - 2013-08-22 08:36 - 00000000 ____D C:\Program Files (x86)\Windows Defender
2015-08-13 17:19 - 2015-07-21 17:35 - 00000000 ____D C:\Users\Lestoli\AppData\Local\Packages
 
Files to move or delete:
====================
C:\Program Files (x86)\Razer\Comms\RazerComms.exe
 
 
Some files in TEMP:
====================
C:\Users\Lestoli\AppData\Local\Temp\0KrakenDevProps.dll
C:\Users\Lestoli\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmp9pykdz.dll
C:\Users\Lestoli\AppData\Local\Temp\nvStInst.exe
C:\Users\Lestoli\AppData\Local\Temp\utils.dll
 
 
==================== Bamital & volsnap =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2015-09-06 16:49
 
==================== End of FRST.txt ============================
Additional scan result of Farbar Recovery Scan Tool (x64) Version:07-09-2015
Ran by [removed] (2015-09-09 14:13:46)
Running from C:\Users\[removed]\Downloads
Windows 8.1 (X64) (2015-07-22 00:35:00)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-699846955-1419679699-1553032801-500 - Administrator - Disabled)
ASPNET (S-1-5-21-699846955-1419679699-1553032801-1002 - Limited - Enabled)
Guest (S-1-5-21-699846955-1419679699-1553032801-501 - Limited - Disabled)
Lestoli (S-1-5-21-699846955-1419679699-1553032801-1001 - Administrator - Enabled) => C:\Users\Lestoli
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
µTorrent (HKU\S-1-5-21-699846955-1419679699-1553032801-1001\…\uTorrent) (Version: 3.4.4.40911 - BitTorrent Inc.)
Action! (HKLM-x32\…\Mirillis Action!) (Version: 1.26.0 - Mirillis)
Adobe Flash Player 10 Plugin (HKLM-x32\…\Adobe Flash Player Plugin) (Version: 10.3.183.90 - Adobe Systems Incorporated)
ASUS USB-AC53 WLAN Card Utilities/Driver (HKLM-x32\…\{242E1F53-6A2F-4173-89CE-8CD5D6A02EEC}) (Version: 2.0.5.9 - ASUS)
Battle.net (HKLM-x32\…\Battle.net) (Version:  - Blizzard Entertainment)
Blade & Soul (HKLM-x32\…\InstallShield_{37EEA701-C7E3-4DC9-BCFB-39C89A6998AD}) (Version: 2.02.0000 - NCTAIWAN)
Blade & Soul (x32 Version: 2.02.0000 - NCTAIWAN) Hidden
Chrome Remote Desktop Host (HKLM-x32\…\{912422D4-0A22-4F70-BF8D-802B4BCD0999}) (Version: 45.0.2454.17 - Google Inc.)
Diablo III (HKLM-x32\…\Diablo III) (Version:  - Blizzard Entertainment)
Dropbox (HKLM-x32\…\Dropbox) (Version: 3.8.8 - Dropbox, Inc.)
Dropbox Update Helper (x32 Version: 1.3.27.35 - Dropbox, Inc.) Hidden
Dungeons and Dragons Online (HKU\S-1-5-21-699846955-1419679699-1553032801-1001\…\DDO_highres_en) (Version:  - )
Glyph (HKLM-x32\…\Glyph) (Version:  - Trion Worlds, Inc.)
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 45.0.2454.85 - Google Inc.)
Google Update Helper (x32 Version: 1.3.28.13 - Google Inc.) Hidden
Happy Cloud Client (HKU\S-1-5-21-699846955-1419679699-1553032801-1001\…\HappyCloud) (Version: 4.28 - Happy Cloud, Inc.)
Heroes of the Storm (HKLM-x32\…\Heroes of the Storm) (Version:  - Blizzard Entertainment)
Hi-Rez Studios Authenticate and Update Service (HKLM-x32\…\{3C87E0FF-BC0A-4F5E-951B-68DC3F8DF1FC}) (Version: 3.0.0.0 - Hi-Rez Studios)
League of Legends (HKLM-x32\…\League of Legends 3.0.1) (Version: 3.0.1 - Riot Games)
League of Legends (x32 Version: 3.0.1 - Riot Games) Hidden
Magicka - Demo (HKLM-x32\…\Steam App 73050) (Version:  - Arrowhead Game Studios)
Microsoft .NET Framework 1.1 (HKLM-x32\…\Microsoft .NET Framework 1.1  (1033)) (Version:  - )
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\…\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\…\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft XNA Framework Redistributable 3.1 (HKLM-x32\…\{19BFDA5D-1FE2-4F25-97F9-1A79DD04EE20}) (Version: 3.1.10527.0 - Microsoft Corporation)
Mozilla Firefox 40.0.2 (x86 en-US) (HKLM-x32\…\Mozilla Firefox 40.0.2 (x86 en-US)) (Version: 40.0.2 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\…\MozillaMaintenanceService) (Version: 40.0.2 - Mozilla)
NCLauncher (NCTaiwan) (HKLM-x32\…\NCLauncher_NCTaiwan) (Version:  - NCSOFT)
NVIDIA 3D Vision Controller Driver 352.65 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 352.65 - NVIDIA Corporation)
NVIDIA 3D Vision Driver 353.30 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 353.30 - NVIDIA Corporation)
NVIDIA GeForce Experience 2.4.5.44 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.4.5.44 - NVIDIA Corporation)
NVIDIA Graphics Driver 353.30 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 353.30 - NVIDIA Corporation)
NVIDIA HD Audio Driver 1.3.34.3 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.3 - NVIDIA Corporation)
NVIDIA Miracast Virtual Audio 353.30 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Miracast.VirtualAudio) (Version: 353.30 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.15.0428 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.15.0428 - NVIDIA Corporation)
Overwolf (HKLM-x32\…\Overwolf) (Version: 0.88.101.0 - Overwolf Ltd.)
Pokémon Trading Card Game Online (HKLM-x32\…\{3201D0CA-3E67-431E-ACFE-DF408055ABD0}) (Version: 2.31.0 - The Pokémon Company International)
RaidCall (HKLM-x32\…\RaidCall) (Version: 7.3.6-1.0.13004.105 - raidcall.com)
Razer Comms (HKLM-x32\…\Razer Comms) (Version: 5.11 - Razer Inc.)
Razer Synapse (HKLM-x32\…\{0D78BEE2-F8FF-4498-AF1A-3FF81CED8AC6}) (Version: 1.18.21.26914 - Razer Inc.)
SHIELD Streaming (Version: 4.1.2000 - NVIDIA Corporation) Hidden
SHIELD Wireless Controller Driver (Version: 2.4.5.44 - NVIDIA Corporation) Hidden
Skype™ 7.8 (HKLM-x32\…\{6A0549A9-1B96-498C-ACBC-3943001FEB19}) (Version: 7.8.102 - Skype Technologies S.A.)
Smite (HKLM-x32\…\{3C87E0FF-BC0A-4F5E-951B-68DC3F8DF017}) (Version: 2.10.2868.3 - Hi-Rez Studios)
Steam (HKLM-x32\…\Steam) (Version: 2.10.91.91 - Valve Corporation)
Strife (HKLM-x32\…\Steam App 339280) (Version:  - S2 Games)
Unity Web Player (HKU\S-1-5-21-699846955-1419679699-1553032801-1001\…\UnityWebPlayer) (Version: 5.0.3f2 - Unity Technologies ApS)
Ventrilo Client (HKLM-x32\…\{789289CA-F73A-4A16-A331-54D498CE069F}) (Version: 3.0.8 - Flagship Industries, Inc.)
VLC media player (HKLM-x32\…\VLC media player) (Version: 2.2.1 - VideoLAN)
Wizard101 (HKU\S-1-5-21-699846955-1419679699-1553032801-1001\…\{A9E27FF5-6294-46A8-B8FD-77B1DECA3021}) (Version: 1.0.0 - KingsIsle Entertainment, Inc.)
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== Restore Points =========================
 
18-08-2015 22:43:42 Windows Update
26-08-2015 01:08:00 Scheduled Checkpoint
29-08-2015 23:11:39 Installed DirectX
31-08-2015 17:39:26 Installed Ventrilo Client
06-09-2015 20:33:31 Installed Chrome Remote Desktop Host
 
==================== Hosts content: ===============================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2013-08-22 06:25 - 2013-08-22 06:25 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {2AD166E4-A67D-4010-948C-C95B5BFD9FBD} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-07-21] (Google Inc.)
Task: {45ABE0A4-E6ED-4670-9B20-48B0EFC6EA26} - System32\Tasks\Overwolf Updater Task => C:\Program Files (x86)\Overwolf\OverwolfUpdater.exe [2015-08-19] (Overwolf LTD)
Task: {78718A13-A8F8-4F64-B624-1A697B2C1F76} - System32\Tasks\Microsoft\Windows\Application Experience\ProgramDataUpdater => Rundll32.exe invagent.dll,RunUpdate -noappraiser
Task: {7FFFDD94-7277-4A31-85FC-DD0500E95448} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-07-21] (Google Inc.)
Task: {D2D11415-D699-4047-B0C4-489259D22107} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2015-08-28] (Dropbox, Inc.)
Task: {DBC97C24-5F6C-40FF-8B72-1E58F13C1954} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\Windows\system32\MRT.exe [2015-08-26] (Microsoft Corporation)
Task: {DDBE671C-EF3A-442F-84B9-7A0CDB1377B5} - System32\Tasks\USBAC53WLANMGR => C:\Program Files (x86)\ASUS\USB-AC53 WLAN Card Utilities\WlanMgr.exe [2013-08-20] (ASUS)
Task: {F24096F4-8FEE-4BB3-8F14-007E4BD5CA2E} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2015-08-28] (Dropbox, Inc.)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\Windows\Tasks\DropboxUpdateTaskMachineCore.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
Task: C:\Windows\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
 
==================== Loaded Modules (Whitelisted) ==============
 
2015-07-25 15:58 - 2015-09-04 19:12 - 00619840 _____ () C:\Users\Lestoli\AppData\Local\Temp\0KrakenDevProps.dll
2015-09-04 20:02 - 2015-08-27 17:17 - 01501512 _____ () C:\Program Files (x86)\Google\Chrome\Application\45.0.2454.85\libglesv2.dll
2015-09-04 20:02 - 2015-08-27 17:17 - 00081224 _____ () C:\Program Files (x86)\Google\Chrome\Application\45.0.2454.85\libegl.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
 
==================== EXE Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-699846955-1419679699-1553032801-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Lestoli\AppData\Roaming\Microsoft\Windows Photo Viewer\Windows Photo Viewer Wallpaper.jpg
DNS Servers: 10.0.0.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
(Currently there is no automatic fix for this section.)
 
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [{859165E4-4171-41FC-B37A-0DF96D01FD1C}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{6ECBEBD8-BD21-4AE6-97D9-92E7460BF991}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{C224E5E5-5FCF-49B9-9CAF-85F4CCB5C12F}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
FirewallRules: [{1B6B2C0B-6E84-4CC5-8C58-AF55801510BF}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
FirewallRules: [{35D70BFF-F247-472B-97BE-D21F0F410882}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{7D77C931-2D08-4142-9DC6-182E8023D3A8}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [TCP Query User{F5EF6FC0-7627-45DE-939A-05FAB11F1F16}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [UDP Query User{3AAB6AC4-EE18-488A-8F34-BF4EF61FCBF4}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe
FirewallRules: [TCP Query User{B3DA61DB-4C8B-4831-B4AF-8E1F768F20FC}C:\program files (x86)\hi-rez studios\hirezgames\smite\binaries\win32\smite.exe] => (Allow) C:\program files (x86)\hi-rez studios\hirezgames\smite\binaries\win32\smite.exe
FirewallRules: [UDP Query User{D96F3BA5-0300-41C6-9950-29F777306294}C:\program files (x86)\hi-rez studios\hirezgames\smite\binaries\win32\smite.exe] => (Allow) C:\program files (x86)\hi-rez studios\hirezgames\smite\binaries\win32\smite.exe
FirewallRules: [{49DA9569-57D6-4980-8205-2410610AF8F2}] => (Allow) C:\Users\Lestoli\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{BA14B98C-7C80-410F-ABE1-BE41726A0290}] => (Allow) C:\Users\Lestoli\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{9D45A1D2-38E5-4BC0-A63D-43A25146F427}] => (Allow) C:\Users\Lestoli\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{32CAF41C-CABD-406E-BB35-B633696DFD08}] => (Allow) C:\Users\Lestoli\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{2D3B0E63-4A84-4067-B865-153CAA177D35}] => (Allow) C:\Users\Lestoli\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{2FBBD652-5C95-4625-A5CA-0783B6DBF812}] => (Allow) C:\Users\Lestoli\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{0FC6A45C-FAE0-4F2A-8DD7-A24033CCA9C7}] => (Allow) E:\HappyCloud\Cache\DDO Unlimited\dndclient.exe
FirewallRules: [{64C79BDA-909D-4B38-B2A1-DD3911751DE6}] => (Allow) E:\HappyCloud\Cache\DDO Unlimited\dndclient.exe
FirewallRules: [{CBFAC031-AF27-4A63-AC8C-7778130DBF9A}] => (Allow) E:\HappyCloud\Cache\DDO Unlimited\TurbineLauncher.exe
FirewallRules: [{CFCA6F15-24A7-44C6-B0D3-91CA46E427E8}] => (Allow) E:\HappyCloud\Cache\DDO Unlimited\TurbineLauncher.exe
FirewallRules: [TCP Query User{0113189C-C44B-4606-AD8A-D302C262EFE2}C:\program files (x86)\nctaiwan\blade & soul\bin\nctalk.exe] => (Block) C:\program files (x86)\nctaiwan\blade & soul\bin\nctalk.exe
FirewallRules: [UDP Query User{807AD9C9-90BE-4EC6-88E2-3ED71086E25C}C:\program files (x86)\nctaiwan\blade & soul\bin\nctalk.exe] => (Block) C:\program files (x86)\nctaiwan\blade & soul\bin\nctalk.exe
FirewallRules: [{35DEB7D4-BD84-4708-B474-704FE23A3244}] => (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe
FirewallRules: [{B76995EE-102F-4B61-AB09-BEF00925A245}] => (Allow) C:\Program Files (x86)\Battle.net\Battle.net.exe
FirewallRules: [TCP Query User{AD1481B6-8DDF-43C9-98DE-F4A9E4DAC98C}E:\heroes of the storm\versions\base36144\heroesofthestorm_x64.exe] => (Allow) E:\heroes of the storm\versions\base36144\heroesofthestorm_x64.exe
FirewallRules: [UDP Query User{847BDDCA-E237-44EF-BF26-9B5E10F14384}E:\heroes of the storm\versions\base36144\heroesofthestorm_x64.exe] => (Allow) E:\heroes of the storm\versions\base36144\heroesofthestorm_x64.exe
FirewallRules: [{028E881B-B8B8-40EA-B803-6F67C3D43F14}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{F7576FAA-D99A-4E4A-8023-3D26EDBA943B}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{ED314750-014C-4578-8B36-EF32959FBE90}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{CCC7516C-3819-4B8A-944A-42CD52FB26ED}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{915B67E7-2D29-4B89-A209-9FDD921B944C}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{E0A58771-F316-49EC-9139-C50623973172}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{2E592187-40EE-4B0D-AACB-01CE8DC7A8E5}] => (Allow) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
FirewallRules: [TCP Query User{4633E3CD-585E-4B35-AAD6-BEF5F2C527CA}E:\diablo iii\diablo iii.exe] => (Allow) E:\diablo iii\diablo iii.exe
FirewallRules: [UDP Query User{E94F6D8B-DA48-4FAC-942D-1F67954A87AC}E:\diablo iii\diablo iii.exe] => (Allow) E:\diablo iii\diablo iii.exe
FirewallRules: [TCP Query User{135A8F64-A26E-4350-9987-C560308AD378}E:\heroes of the storm\versions\base37351\heroesofthestorm_x64.exe] => (Allow) E:\heroes of the storm\versions\base37351\heroesofthestorm_x64.exe
FirewallRules: [UDP Query User{5424543E-373C-4382-9A28-385C9165F461}E:\heroes of the storm\versions\base37351\heroesofthestorm_x64.exe] => (Allow) E:\heroes of the storm\versions\base37351\heroesofthestorm_x64.exe
FirewallRules: [{8BD00E90-90C9-4F1F-86D1-7C81F71815AD}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Magicka demo\Magicka.exe
FirewallRules: [{C5CAC5F5-2796-4728-A7EA-231D1B0C176C}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Magicka demo\Magicka.exe
FirewallRules: [{E43E3EE5-D543-4B7E-B8AD-9447D9FCDFF9}] => (Allow) C:\Program Files (x86)\Ventrilo\Ventrilo.exe
FirewallRules: [{F6C25173-508E-4FE7-A68B-69827E594DB5}] => (Allow) C:\Program Files (x86)\Ventrilo\Ventrilo.exe
FirewallRules: [{58E4B0B9-3D3B-4FE7-A0D0-837272C35484}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{13F6156A-E04C-47F5-B133-1453277E9B0D}] => (Allow) C:\Program Files (x86)\Google\Chrome Remote Desktop\45.0.2454.17\remoting_host.exe
FirewallRules: [{E0BBCDA1-32B5-4503-B150-8643AE59E4B8}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\strife\bin\strife.exe
FirewallRules: [{1AB23657-199F-4E7A-8226-32A357F0B286}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\strife\bin\strife.exe
 
==================== Faulty Device Manager Devices =============
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (09/08/2015 09:33:47 PM) (Source: Perflib) (EventID: 1010) (User: )
Description: C:\Windows\System32\winspool.drvSpooler8
 
Error: (09/08/2015 08:14:39 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program uTorrent.exe version 3.4.4.40911 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
 
Process ID: 95da0
 
Start Time: 01d0eaa6f552c680
 
Termination Time: 4294967295
 
Application Path: C:\Users\Lestoli\AppData\Roaming\uTorrent\uTorrent.exe
 
Report Id: e6fc1419-56a0-11e5-8260-3085a93aa035
 
Faulting package full name: 
 
Faulting package-relative application ID:
 
Error: (09/08/2015 08:13:08 PM) (Source: NvStreamSvc) (EventID: 2001) (User: )
Description: An error has occurred (NvNetworkStreamService restarted too many times in a short period. Aborting. [0]).
 
Error: (09/08/2015 06:07:19 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program Steam.exe version 2.92.69.85 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
 
Process ID: 177c
 
Start Time: 01d0e78058ddcb50
 
Termination Time: 4294967295
 
Application Path: C:\Program Files (x86)\Steam\Steam.exe
 
Report Id: 1d13856b-568f-11e5-8260-3085a93aa035
 
Faulting package full name: 
 
Faulting package-relative application ID:
 
Error: (09/07/2015 03:41:30 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: Overwolf.exe, version: 0.88.101.0, time stamp: 0x55d48a25
Faulting module name: libcef.DLL, version: 3.2171.2039.0, time stamp: 0x54f58e4f
Exception code: 0x80000003
Fault offset: 0x0013b2b0
Faulting process id: 0x%9
Faulting application start time: 0xOverwolf.exe0
Faulting application path: Overwolf.exe1
Faulting module path: Overwolf.exe2
Report Id: Overwolf.exe3
Faulting package full name: Overwolf.exe4
Faulting package-relative application ID: Overwolf.exe5
 
Error: (09/07/2015 12:47:08 PM) (Source: OverwolfUpdater) (EventID: 0) (User: )
Description: Service cannot be started. An instance of the service is already running
 
Error: (09/07/2015 12:47:08 PM) (Source: OverwolfUpdater) (EventID: 0) (User: )
Description: Service cannot be started. The handle is invalid
 
Error: (09/07/2015 12:13:42 AM) (Source: OverwolfUpdater) (EventID: 0) (User: )
Description: Service cannot be started. An instance of the service is already running
 
Error: (09/07/2015 12:13:42 AM) (Source: OverwolfUpdater) (EventID: 0) (User: )
Description: Service cannot be started. The handle is invalid
 
Error: (09/06/2015 06:13:42 PM) (Source: OverwolfUpdater) (EventID: 0) (User: )
Description: Service cannot be started. An instance of the service is already running
 
 
System errors:
=============
Error: (09/09/2015 02:15:00 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The BCM42RLY service failed to start due to the following error: 
%%2
 
Error: (09/09/2015 02:15:00 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The BCM42RLY service failed to start due to the following error: 
%%2
 
Error: (09/09/2015 02:14:54 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The BCM42RLY service failed to start due to the following error: 
%%2
 
Error: (09/09/2015 02:14:54 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The BCM42RLY service failed to start due to the following error: 
%%2
 
Error: (09/09/2015 02:14:48 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The BCM42RLY service failed to start due to the following error: 
%%2
 
Error: (09/09/2015 02:14:48 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The BCM42RLY service failed to start due to the following error: 
%%2
 
Error: (09/09/2015 02:14:42 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The BCM42RLY service failed to start due to the following error: 
%%2
 
Error: (09/09/2015 02:14:42 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The BCM42RLY service failed to start due to the following error: 
%%2
 
Error: (09/09/2015 02:14:36 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The BCM42RLY service failed to start due to the following error: 
%%2
 
Error: (09/09/2015 02:14:36 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The BCM42RLY service failed to start due to the following error: 
%%2
 
 
Microsoft Office:
=========================
Error: (09/08/2015 09:33:47 PM) (Source: Perflib) (EventID: 1010) (User: )
Description: C:\Windows\System32\winspool.drvSpooler8
 
Error: (09/08/2015 08:14:39 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: uTorrent.exe3.4.4.4091195da001d0eaa6f552c6804294967295C:\Users\Lestoli\AppData\Roaming\uTorrent\uTorrent.exee6fc1419-56a0-11e5-8260-3085a93aa035
 
Error: (09/08/2015 08:13:08 PM) (Source: NvStreamSvc) (EventID: 2001) (User: )
Description: NvStreamSvcNvNetworkStreamService restarted too many times in a short period. Aborting. [0]
 
Error: (09/08/2015 06:07:19 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Steam.exe2.92.69.85177c01d0e78058ddcb504294967295C:\Program Files (x86)\Steam\Steam.exe1d13856b-568f-11e5-8260-3085a93aa035
 
Error: (09/07/2015 03:41:30 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Overwolf.exe0.88.101.055d48a25libcef.DLL3.2171.2039.054f58e4f800000030013b2b0
 
Error: (09/07/2015 12:47:08 PM) (Source: OverwolfUpdater) (EventID: 0) (User: )
Description: Service cannot be started. An instance of the service is already running
 
Error: (09/07/2015 12:47:08 PM) (Source: OverwolfUpdater) (EventID: 0) (User: )
Description: Service cannot be started. The handle is invalid
 
Error: (09/07/2015 12:13:42 AM) (Source: OverwolfUpdater) (EventID: 0) (User: )
Description: Service cannot be started. An instance of the service is already running
 
Error: (09/07/2015 12:13:42 AM) (Source: OverwolfUpdater) (EventID: 0) (User: )
Description: Service cannot be started. The handle is invalid
 
Error: (09/06/2015 06:13:42 PM) (Source: OverwolfUpdater) (EventID: 0) (User: )
Description: Service cannot be started. An instance of the service is already running
 
 
==================== Memory info =========================== 
 
Processor: Intel(R) Core(TM) i7-3770K CPU @ 3.50GHz
Percentage of memory in use: 44%
Total physical RAM: 16336.88 MB
Available physical RAM: 9067.85 MB
Total Virtual: 19776.88 MB
Available Virtual: 11014.59 MB
 
==================== Drives ================================
 
Drive c: (SSD) (Fixed) (Total:238.13 GB) (Free:157.25 GB) NTFS
Drive d: (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.08 GB) NTFS
Drive e: (Old Harddrive) (Fixed) (Total:931.41 GB) (Free:880.31 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: DA099E47)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=931.4 GB) - (Type=07 NTFS)
 
========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 238.5 GB) (Disk ID: 0146B560)
Partition 1: (Active) - (Size=350 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=238.1 GB) - (Type=07 NTFS)
 
==================== End of Addition.txt ============================

While I am looking over your logs run this program and post the log please

 

Download CKScanner by askey127 from Here & save it to your Desktop.
  •  
  • Doubleclick CKScanner.exe then click Search For Files
  • When the cursor hourglass disappears, click Save List To File
  • A message box will verify the file saved
  • Please Run this program only once
  • Double-click the CKFiles.txt icon on your desktop then copy/paste the contents in your next reply
 

All that came up was ..

 

CKScanner 2.5 - Additional Security Risks - These are not necessarily bad
c:\program files (x86)\hi-rez studios\hirezgames\smite\battlegame\cookedpc\characters\npcs\npc_ward_firecracker.upk
c:\program files (x86)\hi-rez studios\hirezgames\smite\battlegame\cookedpc\sounds\aud_npc_ward_firecracker.upk
c:\program files (x86)\steam\steamapps\common\magicka demo\contentdemo\levels\textures\surface\structure\stone\wall_cracked01_0.xnb
c:\program files (x86)\steam\steamapps\common\magicka demo\contentdemo\levels\textures\surface\structure\stone\wall_cracked_nrm_0.xnb
scanner sequence 3.BB.11.VLLBA0
 —– EOF —– 
 
 
Just looks like files from two games I installed, and don't play anymore.

I would go ahead and uninstall them along with any other that you downloaded via the torrents.  Your using the Torrents to download games and whatever, not all but most programs downloaded via [kickass-to] via the torrents are infected.

 

 
-AdwCleaner-by Xplode
 
Click on this link to download : ADWCleaner TO YOUR DESKTOP
Click on ONE of the Two Blue Download Now buttons That have a blue arrow beside them and save it to your desktop.
Use my link only, do not do a search for AdwCleaner as there is a bogus copy going around by scammers
 
 
Do not click on any links in the top Advertisment.
 
[external image: AdwCleaner4.201_zpsxrbk2llq.jpg]
 
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Scan.
  • After the scan is complete click on "Clean"
  • Confirm each time with Ok.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile with your next reply.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.
  •  
     
    ===============================================================================
     
     
     
    [external image: thisisujrt.gif] Please download Junkware Removal Tool TO YOUR DESKTOP
    • Download the one from Bleeping Computer
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Post the contents of JRT.txt into your next message.
    •  
       
       
      ===============================================================================
       
      Download Malwarebytes' Anti-Malware  TO YOUR DESKTOP
       
      • Windows XP : Double click on the icon to run it.
      • Windows Vista, Windows 7 & 8 : Right click and select "Run as Administrator"
      •  
        [external image: 0841859c-1a35-4dbd-b41a-e720629e3e22_zps]
         
        • On the Dashboard click on Update Now
        • Go to the Setting Tab
        • Under Setting go to Detection and Protection
        • Under PUP and PUM make sure both are set to show Treat Detections as Malware
        • Go to Advanced setting and make sure Automatically Quarantine Detected Items is checked
        • Then on the Dashboard click on Scan
        • Make sure to select THREAT SCAN
        • Then click on Scan
        • When the scan is finished and the log pops up…select Copy to Clipboard
        • Please paste the log back into this thread for review
        • Exit Malwarebytes
        • Adw Cleaner -

           

          # AdwCleaner v5.007 - Logfile created 09/09/2015 at 16:23:08
          # Updated 08/09/2015 by Xplode
          # Database : 2015-09-08.2 [Server]
          # Operating system : Windows 8.1  (x64)
          # Username : Lestoli - AWHEELER
          # Running from : C:\Users\Lestoli\Desktop\AdwCleaner.exe
          # Option : Cleaning
          # Support : http://toolslib.net/forum
           
          ***** [ Services ] *****
           
           
          ***** [ Folders ] *****
           
           
          ***** [ Files ] *****
           
          [-] File Deleted : C:\Users\Lestoli\AppData\Local\Temp\Utils.dll
           
          ***** [ Shortcuts ] *****
           
           
          ***** [ Scheduled tasks ] *****
           
           
          ***** [ Registry ] *****
           
           
          ***** [ Web browsers ] *****
           
           
          *************************
           
          :: Winsock settings cleared
           
          ########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [666 bytes] ##########
           
           
          JRT -
           
          ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
          Junkware Removal Tool (JRT) by Malwarebytes
          Version: 7.6.1 (09.08.2015:1)
          OS: Windows 8.1 x64
          Ran by [removed] on Wed 09/09/2015 at 16:26:31.08
          ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
           
           
           
           
          ~~~ Services
           
           
           
          ~~~ Tasks
           
           
           
          ~~~ Registry Values
           
           
           
          ~~~ Registry Keys
           
           
           
          ~~~ Files
           
           
           
          ~~~ Folders
           
           
           
          ~~~ Chrome
           
           
          [C:\Users\Lestoli\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - default search provider reset
           
          [C:\Users\Lestoli\Appdata\Local\Google\Chrome\User Data\Default\Preferences] - Extensions Deleted:
           
          [C:\Users\Lestoli\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - default search provider reset
           
          [C:\Users\Lestoli\Appdata\Local\Google\Chrome\User Data\Default\Secure Preferences] - Extensions Deleted:
           
           
           
           
           
          ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
          Scan was completed on Wed 09/09/2015 at 16:28:00.46
          End of JRT log
          ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
           
           
          Malwarebytes Anti-Malware -
           
          Malwarebytes Anti-Malware
          www.malwarebytes.org
           
          Scan Date: 9/9/2015
          Scan Time: 4:30 PM
          Logfile: 
          Administrator: Yes
           
          Version: 2.1.8.1057
          Malware Database: v2015.09.09.07
          Rootkit Database: v2015.08.16.01
          License: Trial
          Malware Protection: Enabled
          Malicious Website Protection: Enabled
          Self-protection: Disabled
           
          OS: Windows 8.1
          CPU: x64
          File System: NTFS
          User: Lestoli
           
          Scan Type: Threat Scan
          Result: Completed
          Objects Scanned: 343685
          Time Elapsed: 6 min, 1 sec
           
          Memory: Enabled
          Startup: Enabled
          Filesystem: Enabled
          Archives: Enabled
          Rootkits: Disabled
          Heuristics: Enabled
          PUP: Enabled
          PUM: Enabled
           
          Processes: 0
          (No malicious items detected)
           
          Modules: 0
          (No malicious items detected)
           
          Registry Keys: 0
          (No malicious items detected)
           
          Registry Values: 0
          (No malicious items detected)
           
          Registry Data: 0
          (No malicious items detected)
           
          Folders: 0
          (No malicious items detected)
           
          Files: 0
          (No malicious items detected)
           
          Physical Sectors: 0
          (No malicious items detected)
           
           
          (end)
           
           

          Scans not picking up much to suggest com surrogate is  a virus

           

          I'd like us to scan your machine with ESET OnlineScan
           
          *Note
          It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
          Please don't go surfing while your resident protection is disabled!
          Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.
           
          1. Hold down Control and click on the following link to open ESET OnlineScan in a new window.
          2. ESET OnlineScan
          3. Click the [external image: esetOnline.png] button.
          4. For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
            1. Click on [external image: esetSmartInstall.png] to download the ESET Smart Installer. Save it to your desktop.
            2. Double click on the [external image: esetSmartInstallDesktopIcon.png] icon on your desktop.
            3. Check [external image: esetAcceptTerms.png]
            4. Click the [external image: esetStart.png] button.
            5. Accept any security warnings from your browser.
            6. Check [external image: esetScanArchives.png]
            7. Make sure that the option "Remove found threats" is Unchecked
            8. Push the Start button.
            9. ESET will then download updates for itself, install itself, and begin
            10. scanning your computer. Please be patient as this can take some time.
            11. When the scan completes, push [external image: esetListThreats.png]
            12. Push [external image: esetExport.png], and save the file to your desktop using a unique name, such as
            13. ESETScan. Include the contents of this report in your next reply.
            14. Push the [external image: esetBack.png] button.
            15. Push [external image: esetFinish.png]
            16. Please make sure you include the following items in your next post:
              The log that was produced after running ESET Online Scanner.

              Ask AI

              AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

              Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI