Thanks again the for the reply.
[removed]
Platform: Windows 10 Home Single Language Version 1511 (X64) Language: English (United Kingdom)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(ESET) C:\Program Files\ESET\ESET Smart Security\ekrn.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe
(Hewlett-Packard Company) C:\Windows\System32\hpservice.exe
(Intel Corporation) C:\Windows\SysWOW64\IntelCpHeciSvc.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(skype.cog.cc) C:\Program Files (x86)\SkypeUpdateEx\SkypeUpdateEx.exe
(Microsoft Corporation) C:\ProgramData\Windows Security\winsecurity.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
() C:\Users\Haris Hameed\AppData\Roaming\WMPNetworkAcSvc\WMPNetworkAcSvc.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\egui.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
() C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeHost.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
(Microsoft Corporation) C:\ProgramData\Microsoft\Network\Dsq\network\sysnetwk.exe
() C:\ProgramData\Microsoft\Network\Dsq\browser\syshostctl.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe
(CyberLink) C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(© 2015 Microsoft Corporation) C:\Users\Haris Hameed\AppData\Local\Microsoft\BingSvc\BingSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
(Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
() C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.325.12390.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
(Microsoft Corporation) C:\Windows\HelpPane.exe
(Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil_ActiveX.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\NetworkUXBroker.exe
(Microsoft Corporation) C:\Windows\System32\CompatTelRunner.exe
(Microsoft Corporation) C:\Windows\System32\CompatTelRunner.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\…\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [1664000 2014-10-23] (IDT, Inc.)
HKLM\…\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3954352 2016-04-28] (Synaptics Incorporated)
HKLM-x32\…\Run: [RemoteControl10] => C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [91432 2012-03-28] (CyberLink Corp.)
HKLM-x32\…\Run: [HP Quick Launch] => C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe [581024 2012-09-07] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\…\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM-x32\…\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM-x32\…\Run: [] => [X]
HKLM-x32\…\Run: [DivXMediaServer] => C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe
Winlogon\Notify\igfxcui: igfxdev.dll [X]
HKU\S-1-5-21-1503482889-339291205-912318997-1001\…\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [517632 2015-10-30] (Microsoft Corporation)
HKU\S-1-5-21-1503482889-339291205-912318997-1002\…\Run: [BingSvc] => C:\Users\Haris Hameed\AppData\Local\Microsoft\BingSvc\BingSvc.exe [144008 2015-11-12] (© 2015 Microsoft Corporation)
HKU\S-1-5-21-1503482889-339291205-912318997-1002\…\RunOnce: [Uninstall C:\Users\Haris Hameed\AppData\Local\Microsoft\OneDrive\17.3.6201.1019_1\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Haris Hameed\AppData\Local\Microsoft\OneDrive\17.3.6201.1019_1\amd64"
HKU\S-1-5-21-1503482889-339291205-912318997-1002\…\RunOnce: [Uninstall C:\Users\Haris Hameed\AppData\Local\Microsoft\OneDrive\17.3.6201.1019_1] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Haris Hameed\AppData\Local\Microsoft\OneDrive\17.3.6201.1019_1"
HKU\S-1-5-21-1503482889-339291205-912318997-1002\…\RunOnce: [Uninstall C:\Users\Haris Hameed\AppData\Local\Microsoft\OneDrive\17.3.6281.1202\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Haris Hameed\AppData\Local\Microsoft\OneDrive\17.3.6281.1202\amd64"
HKU\S-1-5-21-1503482889-339291205-912318997-1002\…\RunOnce: [Uninstall C:\Users\Haris Hameed\AppData\Local\Microsoft\OneDrive\17.3.6301.0127\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Haris Hameed\AppData\Local\Microsoft\OneDrive\17.3.6301.0127\amd64"
HKU\S-1-5-21-1503482889-339291205-912318997-1002\…\RunOnce: [Uninstall C:\Users\Haris Hameed\AppData\Local\Microsoft\OneDrive\17.3.6302.0225\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Haris Hameed\AppData\Local\Microsoft\OneDrive\17.3.6302.0225\amd64"
HKU\S-1-5-21-1503482889-339291205-912318997-1002\…\RunOnce: [Uninstall C:\Users\Haris Hameed\AppData\Local\Microsoft\OneDrive\17.3.6386.0412\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Haris Hameed\AppData\Local\Microsoft\OneDrive\17.3.6386.0412\amd64"
HKU\S-1-5-21-1503482889-339291205-912318997-1002\…\MountPoints2: {090de58b-1dd4-11e6-bf07-689423aa3bf0} - "E:\HTC_Sync_Manager_PC.exe"
HKU\S-1-5-21-1503482889-339291205-912318997-1002\…\MountPoints2: {98f50cea-04a3-11e6-bf03-689423aa3bf0} - "G:\HTC_Sync_Manager_PC.exe"
HKU\S-1-5-21-1503482889-339291205-912318997-1002\…\MountPoints2: {eb6e8585-d4c0-11e5-befe-689423aa3bf0} - "E:\HTC_Sync_Manager_PC.exe"
HKU\S-1-5-21-1503482889-339291205-912318997-1002\…\MountPoints2: {eb6e860e-d4c0-11e5-befe-689423aa3bf0} - "G:\HTC_Sync_Manager_PC.exe"
AppInit_DLLs: ,C:\WINDOWS\system32\nvinitx.dll => C:\WINDOWS\system32\nvinitx.dll [176904 2015-07-23] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\WINDOWS\SysWOW64\nvinit.dll => C:\WINDOWS\SysWOW64\nvinit.dll [155280 2015-07-23] (NVIDIA Corporation)
Startup: C:\Users\Haris Hameed\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk [2015-01-15]
ShortcutTarget: OneNote 2007 Screen Clipper and Launcher.lnk -> C:\Program Files (x86)\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
ProxyEnable: [S-1-5-21-1503482889-339291205-912318997-1002] => Proxy is enabled.
ProxyServer: [S-1-5-21-1503482889-339291205-912318997-1002] => http=127.0.0.1:8080;https=127.0.0.1:8080
Tcpip\Parameters: [DhcpNameServer] 192.168.110.1
Tcpip\..\Interfaces\{0b9b1adb-6547-4b8a-baae-6777596753e5}: [DhcpNameServer] 192.168.110.1
Internet Explorer:
==================
SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.bing.com/search?q={searchTerms}&form;=MSSEDF&pc;=MSE1
SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.bing.com/search?q={searchTerms}&form;=MSSEDF&pc;=MSE1
SearchScopes: HKLM -> {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = hxxp://uk.search.yahoo.com/search?p={searchTerms}&ei;={inputEncoding}&fr;=chr-hp-psg&type;=HPNTDF
SearchScopes: HKLM-x32 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.bing.com/search?q={searchTerms}&form;=MSSEDF&pc;=MSE1
SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.bing.com/search?q={searchTerms}&form;=MSSEDF&pc;=MSE1
SearchScopes: HKLM-x32 -> {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = hxxp://uk.search.yahoo.com/search?p={searchTerms}&ei;={inputEncoding}&fr;=chr-hp-psg&type;=HPNTDF
SearchScopes: HKU\S-1-5-21-1503482889-339291205-912318997-1002 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-1503482889-339291205-912318997-1002 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
Edge:
======
Edge HomeButtonPage: HKU\S-1-5-21-1503482889-339291205-912318997-1002 -> hxxp://www.google.com/
FireFox:
========
FF ProfilePath: C:\Users\Haris Hameed\AppData\Roaming\Mozilla\Firefox\Profiles\92wy8o4z.default
FF NewTab: about:newtab
FF Homepage: about:home
FF Plugin: @videolan.org/vlc,version=2.0.6 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2014-09-23] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2014-09-23] (VideoLAN)
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\windows\SysWOW64\Adobe\Director\np32dsw.dll [2012-04-26] (Adobe Systems, Inc.)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.66 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2014-10-24] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2014-10-24] (Intel Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.30.3\npGoogleUpdate3.dll [2016-06-02] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.30.3\npGoogleUpdate3.dll [2016-06-02] (Google Inc.)
Chrome:
=======
CHR Profile: C:\Users\Haris Hameed\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\Haris Hameed\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-06-03]
CHR Extension: (Google Docs) - C:\Users\Haris Hameed\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-06-03]
CHR Extension: (Google Drive) - C:\Users\Haris Hameed\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-06-03]
CHR Extension: (YouTube) - C:\Users\Haris Hameed\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-06-03]
CHR Extension: (Google Sheets) - C:\Users\Haris Hameed\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-06-03]
CHR Extension: (Google Docs Offline) - C:\Users\Haris Hameed\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-06-03]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Haris Hameed\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-06-03]
CHR Extension: (Gmail) - C:\Users\Haris Hameed\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-06-03]
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 ekrn; C:\Program Files\ESET\ESET Smart Security\ekrn.exe [2519904 2016-04-13] (ESET)
R2 IconMan_R; C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [2451456 2012-07-14] (Realsil Microelectronics Inc.) [File not signed]
R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [330136 2015-10-13] (Intel Corporation)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [732160 2012-12-10] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [803872 2012-12-10] (Intel(R) Corporation)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [131032 2014-10-24] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165336 2014-10-24] (Intel Corporation)
R2 SkypeUpdateEx; C:\Program Files (x86)\SkypeUpdateEx\SkypeUpdateEx.exe [168376 2016-05-05] (skype.cog.cc)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2015-10-30] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-10-30] (Microsoft Corporation)
R2 WindowsSecurity; C:\ProgramData\Windows Security\winsecurity.exe [2324992 2016-05-30] (Microsoft Corporation) [File not signed]
R2 WMPNetworkAcSvc; C:\Users\Haris Hameed\AppData\Roaming\WMPNetworkAcSvc\WMPNetworkAcSvc.exe [4984448 2016-03-15] ()
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 dc1-controller; C:\Windows\System32\drivers\dc1-controller.sys [57344 2015-10-30] (Microsoft Corp.)
R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [264552 2016-05-12] (ESET)
S0 eelam; C:\Windows\System32\DRIVERS\eelam.sys [14976 2016-05-12] (ESET)
R1 ehdrv; C:\Windows\system32\DRIVERS\ehdrv.sys [186784 2016-05-12] (ESET)
R2 ekbdflt; C:\Windows\system32\DRIVERS\ekbdflt.sys [142976 2016-05-12] (ESET)
R1 epfw; C:\Windows\system32\DRIVERS\epfw.sys [198096 2016-05-12] (ESET)
R1 EpfwLWF; C:\Windows\system32\DRIVERS\EpfwLWF.sys [53384 2016-05-12] (ESET)
R0 epfwwfp; C:\Windows\System32\DRIVERS\epfwwfp.sys [84800 2016-05-12] (ESET)
S3 HtcVCom32; C:\Windows\system32\DRIVERS\HtcVComV64.sys [121800 2010-03-09] (QUALCOMM Incorporated)
R3 netr28x; C:\Windows\system32\DRIVERS\netr28x.sys [2554528 2015-06-12] (MediaTek Inc.)
R3 RSP2STOR; C:\Windows\system32\DRIVERS\RtsP2Stor.sys [310528 2015-06-05] (Realtek Semiconductor Corp.)
R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [589824 2015-10-30] (Realtek )
R3 rtbth; C:\Windows\System32\drivers\rtbth.sys [1219200 2015-06-03] (Ralink Technology, Corp.)
S3 SmbDrv; C:\Windows\System32\drivers\Smb_driver_AMDASF.sys [41272 2012-08-24] (Synaptics Incorporated)
R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [52904 2016-04-28] (Synaptics Incorporated)
S3 ssudserd; C:\Windows\system32\DRIVERS\ssudserd.sys [206080 2014-01-22] (DEVGURU Co., LTD.(www.devguru.co.kr))
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation)
R3 WirelessButtonDriver; C:\Windows\System32\drivers\WirelessButtonDriver64.sys [20800 2013-06-27] (Hewlett-Packard Development Company, L.P.)
S3 HTCAND64; \SystemRoot\System32\Drivers\ANDROIDUSB.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-06-04 12:03 - 2016-06-04 12:04 - 00017786 _____ C:\Users\Haris Hameed\Desktop\FRST.txt
2016-06-04 11:59 - 2016-06-04 12:00 - 02384384 _____ (Farbar) C:\Users\Haris Hameed\Desktop\FRST64.exe
2016-06-04 00:03 - 2016-06-04 00:03 - 00000000 ____D C:\_OTL
2016-06-03 17:42 - 2016-06-03 17:42 - 00000000 ____D C:\Users\Haris Hameed\AppData\Local\ESET
2016-06-03 17:39 - 2016-06-03 17:39 - 00002100 _____ C:\Users\Public\Desktop\ESET Banking & Payment protection.lnk
2016-06-03 17:39 - 2016-06-03 17:39 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ESET
2016-06-03 17:39 - 2016-06-03 17:39 - 00000000 ____D C:\ProgramData\ESET
2016-06-03 17:39 - 2016-06-03 17:39 - 00000000 ____D C:\Program Files\ESET
2016-06-03 17:34 - 2016-06-03 17:35 - 03017376 _____ (ESET) C:\Users\Haris Hameed\Downloads\eset_smart_security_live_installer.exe
2016-06-03 16:35 - 2016-06-03 16:35 - 00000000 ____D C:\Users\Haris Hameed\AppData\Local\NetworkTiles
2016-06-03 16:34 - 2016-06-03 16:34 - 00000000 ____D C:\Users\Haris Hameed\AppData\Local\ActiveSync
2016-06-03 16:33 - 2016-06-03 16:33 - 00000000 ____D C:\Users\Haris Hameed\AppData\Local\VirtualStore
2016-06-03 16:30 - 2016-06-03 16:04 - 00024064 _____ C:\WINDOWS\zoek-delete.exe
2016-06-03 13:11 - 2016-06-03 13:11 - 00000568 _____ C:\Users\Haris Hameed\Desktop\JRT.txt
2016-06-03 10:31 - 2016-06-04 00:03 - 00000000 ____D C:\Users\Haris Hameed\Desktop\Malware Cleaner
2016-06-02 21:27 - 2016-06-02 21:27 - 00000000 ___HD C:\OneDriveTemp
2016-06-02 18:28 - 2016-06-04 12:03 - 00000000 ____D C:\FRST
2016-06-02 17:07 - 2016-06-03 19:24 - 00000000 ____D C:\zoek_backup
2016-06-02 15:37 - 2016-06-03 10:39 - 00000000 ____D C:\AdwCleaner
2016-06-02 15:37 - 2016-06-02 15:37 - 03677248 _____ C:\Users\Haris Hameed\Downloads\adwcleaner_5.119.exe
2016-06-02 11:56 - 2016-06-02 11:56 - 00002344 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-06-02 11:56 - 2016-06-02 11:56 - 00002332 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2016-06-02 11:55 - 2016-06-04 12:05 - 00000918 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2016-06-02 11:55 - 2016-06-04 12:05 - 00000914 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2016-06-02 11:55 - 2016-06-02 12:00 - 00003976 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2016-06-02 11:55 - 2016-06-02 12:00 - 00003744 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2016-06-02 11:55 - 2016-06-02 11:55 - 00987728 _____ (Google Inc.) C:\Users\Haris Hameed\Downloads\ChromeSetup (5).exe
2016-06-02 10:12 - 2016-06-03 17:01 - 00000000 ____D C:\Users\Haris Hameed\AppData\LocalLow\uTorrent
2016-06-01 19:52 - 2016-06-01 19:52 - 00031944 _____ C:\Users\Haris Hameed\Downloads\londonhasfallen2016720pblurayx264-ytsag-english-86360.zip
2016-06-01 18:35 - 2016-06-01 18:35 - 00031500 _____ C:\Users\Haris Hameed\Downloads\London Has Fallen (2016) [1080p] [YTS.AG].torrent
2016-06-01 18:35 - 2016-06-01 18:35 - 00000000 ____D C:\Users\Haris Hameed\Downloads\London Has Fallen (2016) [1080p] [YTS.AG]
2016-05-31 17:11 - 2016-05-31 17:17 - 00000000 ____D C:\Users\Haris Hameed\Downloads\Green Lantern 2011 1080p BluRay x264 AAC - Ozlem
2016-05-31 17:09 - 2016-05-31 17:09 - 00015899 _____ C:\Users\Haris Hameed\Downloads\Green Lantern (2011) [720p] [YTS.AG] (1).torrent
2016-05-30 17:57 - 2016-05-30 17:57 - 00015899 _____ C:\Users\Haris Hameed\Downloads\Green Lantern (2011) [720p] [YTS.AG].torrent
2016-05-29 23:50 - 2016-05-30 00:13 - 00000000 ____D C:\Users\Haris Hameed\Downloads\The Green Hornet (2011) [1080p]
2016-05-28 22:13 - 2016-05-29 12:31 - 1337798588 ____R C:\Users\Haris Hameed\Downloads\Kapoor.and.Sons.2016.Hindi.720p.DVDRiP.x264.ShAaNiG.mkv
2016-05-28 17:51 - 2016-05-28 17:51 - 00000000 ____D C:\Users\Haris Hameed\Downloads\13 Hours The Secret Soldiers Of Benghazi (2016) [YTS.AG]
2016-05-28 17:50 - 2016-05-28 17:50 - 00022187 _____ C:\Users\Haris Hameed\Downloads\13 Hours_ The Secret Soldiers of Benghazi (2016) [720p] [YTS.AG].torrent
2016-05-24 16:24 - 2016-05-24 16:25 - 00000000 ____D C:\Users\Haris Hameed\Downloads\The.Night.Before.2015.HDRip.XViD-ETRG
2016-05-19 18:03 - 2016-05-19 18:03 - 00036089 _____ C:\Users\Haris Hameed\Downloads\triple-9-2016-720p-bluray-x264-english-84820.zip
2016-05-19 18:02 - 2016-05-19 18:03 - 00000000 ____D C:\Users\Haris Hameed\Downloads\Pride And Prejudice And Zombies (2016) [1080p] [YTS.AG]
2016-05-19 18:02 - 2016-05-19 18:02 - 00040342 _____ C:\Users\Haris Hameed\Downloads\Gods of Egypt (2016) [1080p] [YTS.AG].torrent
2016-05-19 18:02 - 2016-05-19 18:02 - 00034358 _____ C:\Users\Haris Hameed\Downloads\Pride and Prejudice and Zombies (2016) [1080p] [YTS.AG].torrent
2016-05-19 18:02 - 2016-05-19 18:02 - 00000000 ____D C:\Users\Haris Hameed\Downloads\Gods Of Egypt (2016) [1080p] [YTS.AG]
2016-05-18 15:26 - 2016-06-02 11:49 - 00000000 ____D C:\ProgramData\Windows Security
2016-05-18 15:20 - 2016-05-18 15:20 - 00000000 ____D C:\Users\Haris Hameed\Downloads\Triple 9 (2016) [1080p] [YTS.AG]
2016-05-18 15:19 - 2016-05-18 15:19 - 00037072 _____ C:\Users\Haris Hameed\Downloads\Triple 9 (2016) [1080p] [YTS.AG].torrent
2016-05-18 15:19 - 2016-05-18 15:19 - 00000000 ____D C:\Users\Haris Hameed\AppData\Roaming\sc
2016-05-18 00:01 - 2016-05-18 00:01 - 00000000 ____D C:\Users\Haris Hameed\AppData\Local\MediationinumData
2016-05-12 12:07 - 2016-05-12 12:07 - 00000000 ____D C:\Users\Haris Hameed\Downloads\The Finest Hours (2016) [1080p] [YTS.AG]
2016-05-12 12:06 - 2016-05-12 12:06 - 00037508 _____ C:\Users\Haris Hameed\Downloads\The Finest Hours (2016) [1080p] [YTS.AG].torrent
2016-05-12 10:48 - 2016-05-12 10:48 - 00264552 _____ (ESET) C:\WINDOWS\system32\Drivers\eamonm.sys
2016-05-12 10:48 - 2016-05-12 10:48 - 00198096 _____ (ESET) C:\WINDOWS\system32\Drivers\epfw.sys
2016-05-12 10:48 - 2016-05-12 10:48 - 00186784 _____ (ESET) C:\WINDOWS\system32\Drivers\ehdrv.sys
2016-05-12 10:48 - 2016-05-12 10:48 - 00142976 _____ (ESET) C:\WINDOWS\system32\Drivers\ekbdflt.sys
2016-05-12 10:48 - 2016-05-12 10:48 - 00084800 _____ (ESET) C:\WINDOWS\system32\Drivers\epfwwfp.sys
2016-05-12 10:48 - 2016-05-12 10:48 - 00053384 _____ (ESET) C:\WINDOWS\system32\Drivers\EpfwLWF.sys
2016-05-12 10:48 - 2016-05-12 10:48 - 00014976 _____ (ESET) C:\WINDOWS\system32\Drivers\eelam.sys
2016-05-11 18:02 - 2016-05-11 18:02 - 00000000 ____D C:\Program Files (x86)\SkypeUpdateEx
2016-05-11 17:04 - 2016-04-23 08:31 - 13018112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2016-05-11 17:04 - 2016-04-23 08:30 - 22379008 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2016-05-11 17:04 - 2016-04-23 08:28 - 16984576 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2016-05-11 17:04 - 2016-04-23 08:26 - 00059904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosStorage.dll
2016-05-11 17:04 - 2016-04-23 08:25 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapsBtSvc.dll
2016-05-11 17:04 - 2016-04-23 08:22 - 00460800 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapConfiguration.dll
2016-05-11 17:04 - 2016-04-23 08:20 - 19344384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2016-05-11 17:04 - 2016-04-23 08:20 - 18676224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2016-05-11 17:04 - 2016-04-23 08:19 - 07977472 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll
2016-05-11 17:04 - 2016-04-23 08:19 - 01056256 _____ (Microsoft Corporation) C:\WINDOWS\system32\JpMapControl.dll
2016-05-11 17:04 - 2016-04-23 08:19 - 00970752 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2016-05-11 17:04 - 2016-04-23 08:19 - 00853504 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll
2016-05-11 17:04 - 2016-04-23 08:18 - 24604672 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2016-05-11 17:04 - 2016-04-23 08:18 - 00988160 _____ (Microsoft Corporation) C:\WINDOWS\system32\NMAA.dll
2016-05-11 17:04 - 2016-04-23 08:18 - 00939520 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlCore.dll
2016-05-11 17:04 - 2016-04-23 08:18 - 00349696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapConfiguration.dll
2016-05-11 17:04 - 2016-04-23 08:16 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\JpMapControl.dll
2016-05-11 17:04 - 2016-04-23 08:15 - 00792064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2016-05-11 17:04 - 2016-04-23 08:15 - 00784896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NMAA.dll
2016-05-11 17:04 - 2016-04-23 08:14 - 00711680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapControlCore.dll
2016-05-11 17:04 - 2016-04-23 08:13 - 07200256 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll
2016-05-11 17:04 - 2016-04-23 08:13 - 06295552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mos.dll
2016-05-11 17:04 - 2016-04-23 08:07 - 05205504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll
2016-05-11 17:03 - 2016-04-30 10:31 - 03591168 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2016-05-11 17:03 - 2016-04-23 10:12 - 01401024 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2016-05-11 17:03 - 2016-04-23 10:12 - 01184960 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2016-05-11 17:03 - 2016-04-23 10:12 - 00713920 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2016-05-11 17:03 - 2016-04-23 10:12 - 00514752 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2016-05-11 17:03 - 2016-04-23 10:12 - 00190144 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCensus.exe
2016-05-11 17:03 - 2016-04-23 10:12 - 00046784 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe
2016-05-11 17:03 - 2016-04-23 09:28 - 01557768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2016-05-11 17:03 - 2016-04-23 09:28 - 01542816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2016-05-11 17:03 - 2016-04-23 09:24 - 07474528 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2016-05-11 17:03 - 2016-04-23 09:24 - 01997328 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2016-05-11 17:03 - 2016-04-23 09:24 - 01819208 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2016-05-11 17:03 - 2016-04-23 09:12 - 00925064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll
2016-05-11 17:03 - 2016-04-23 09:11 - 01092464 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll
2016-05-11 17:03 - 2016-04-23 09:11 - 00498960 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFCaptureEngine.dll
2016-05-11 17:03 - 2016-04-23 09:10 - 03673424 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2016-05-11 17:03 - 2016-04-23 09:10 - 02919832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2016-05-11 17:03 - 2016-04-23 09:09 - 22561256 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2016-05-11 17:03 - 2016-04-23 09:09 - 21123320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2016-05-11 17:03 - 2016-04-23 09:09 - 05240960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2016-05-11 17:03 - 2016-04-23 09:09 - 04074160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2016-05-11 17:03 - 2016-04-23 09:08 - 06605504 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2016-05-11 17:03 - 2016-04-23 09:08 - 04515256 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2016-05-11 17:03 - 2016-04-23 09:01 - 01996640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2016-05-11 17:03 - 2016-04-23 09:01 - 00650304 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll
2016-05-11 17:03 - 2016-04-23 09:01 - 00522176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxgi.dll
2016-05-11 17:03 - 2016-04-23 08:39 - 00089088 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsCSP.dll
2016-05-11 17:03 - 2016-04-23 08:32 - 00028672 _____ (Microsoft Corporation) C:\WINDOWS\system32\mapsupdatetask.dll
2016-05-11 17:03 - 2016-04-23 08:31 - 00074752 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosStorage.dll
2016-05-11 17:03 - 2016-04-23 08:30 - 00120320 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsBtSvc.dll
2016-05-11 17:03 - 2016-04-23 08:29 - 00072704 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshost.dll
2016-05-11 17:03 - 2016-04-23 08:26 - 00269824 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshostcore.dll
2016-05-11 17:03 - 2016-04-23 08:23 - 11545088 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2016-05-11 17:03 - 2016-04-23 08:22 - 09918976 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2016-05-11 17:03 - 2016-04-23 08:20 - 00606720 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmsvc.dll
2016-05-11 17:03 - 2016-04-23 08:19 - 00440320 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredProvDataModel.dll
2016-05-11 17:03 - 2016-04-23 08:18 - 00870400 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll
2016-05-11 17:03 - 2016-04-23 08:18 - 00585728 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
2016-05-11 17:03 - 2016-04-23 08:17 - 00529920 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll
2016-05-11 17:03 - 2016-04-23 08:16 - 01319424 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifinetworkmanager.dll
2016-05-11 17:03 - 2016-04-23 08:15 - 00673280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.dll
2016-05-11 17:03 - 2016-04-23 08:15 - 00348672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CredProvDataModel.dll
2016-05-11 17:03 - 2016-04-23 08:14 - 13383168 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2016-05-11 17:03 - 2016-04-23 08:14 - 00870912 _____ (Microsoft Corporation) C:\WINDOWS\system32\MPSSVC.dll
2016-05-11 17:03 - 2016-04-23 08:14 - 00821760 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll
2016-05-11 17:03 - 2016-04-23 08:10 - 12125696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2016-05-11 17:03 - 2016-04-23 08:10 - 00639488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll
2016-05-11 17:03 - 2016-04-23 08:09 - 03666432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2016-05-11 17:03 - 2016-04-23 08:09 - 02582016 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
2016-05-11 17:03 - 2016-04-23 08:08 - 05324288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
2016-05-11 17:03 - 2016-04-23 08:08 - 02061824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
2016-05-11 17:03 - 2016-04-23 08:07 - 02598912 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll
2016-05-11 17:03 - 2016-04-23 08:07 - 01500160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2016-05-11 17:03 - 2016-04-23 08:06 - 06974464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2016-05-11 17:03 - 2016-04-23 08:05 - 05502976 _____ (Microsoft Corporation) C:\WINDOWS\system32\d2d1.dll
2016-05-11 17:03 - 2016-04-23 08:05 - 02166784 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2016-05-11 17:03 - 2016-04-23 08:05 - 02066432 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll
2016-05-11 17:03 - 2016-04-23 08:05 - 01946112 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2016-05-11 17:03 - 2016-04-23 08:05 - 01626624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2016-05-11 17:03 - 2016-04-23 08:04 - 04759040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1.dll
2016-05-11 17:03 - 2016-04-23 08:04 - 01731072 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2016-05-11 17:03 - 2016-04-23 08:03 - 05660160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2016-05-11 17:03 - 2016-04-23 08:03 - 04894208 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2016-05-11 17:03 - 2016-04-23 08:03 - 02280960 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2016-05-11 17:03 - 2016-04-23 08:03 - 02000896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.appcore.dll
2016-05-11 17:03 - 2016-04-23 08:03 - 00754176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncCore.dll
2016-05-11 17:03 - 2016-04-23 08:02 - 07832576 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2016-05-11 17:03 - 2016-04-23 08:02 - 02444288 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll
2016-05-11 17:03 - 2016-04-23 08:00 - 00984576 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncCore.dll
2016-05-11 17:02 - 2016-05-06 08:53 - 00095072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdport.sys
2016-05-11 17:02 - 2016-05-06 08:05 - 00241664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cryptngc.dll
2016-05-11 17:02 - 2016-05-06 08:03 - 00649216 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngcsvc.dll
2016-05-11 17:02 - 2016-05-06 07:53 - 00351232 _____ (Microsoft Corporation) C:\WINDOWS\system32\NgcCtnr.dll
2016-05-11 17:02 - 2016-05-06 07:49 - 00289792 _____ (Microsoft Corporation) C:\WINDOWS\system32\NgcCtnrSvc.dll
2016-05-11 17:02 - 2016-05-06 07:44 - 00582656 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngccredprov.dll
2016-05-11 17:02 - 2016-05-06 07:43 - 00320000 _____ (Microsoft Corporation) C:\WINDOWS\system32\cryptngc.dll
2016-05-11 17:02 - 2016-05-06 07:23 - 00076288 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngcpopkeysrv.dll
2016-05-11 17:02 - 2016-04-30 10:42 - 01387520 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2016-05-11 17:02 - 2016-04-23 10:12 - 00294592 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2016-05-11 17:02 - 2016-04-23 10:12 - 00092352 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2016-05-11 17:02 - 2016-04-23 09:26 - 00707608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rpcrt4.dll
2016-05-11 17:02 - 2016-04-23 09:24 - 00754664 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll
2016-05-11 17:02 - 2016-04-23 09:24 - 00638816 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fvevol.sys
2016-05-11 17:02 - 2016-04-23 09:24 - 00335712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fastfat.sys
2016-05-11 17:02 - 2016-04-23 09:24 - 00099680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pdc.sys
2016-05-11 17:02 - 2016-04-23 09:22 - 01161120 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcrt4.dll
2016-05-11 17:02 - 2016-04-23 09:18 - 00026408 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuauclt.exe
2016-05-11 17:02 - 2016-04-23 09:13 - 00502104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupEngine.dll
2016-05-11 17:02 - 2016-04-23 09:13 - 00306832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlanapi.dll
2016-05-11 17:02 - 2016-04-23 09:13 - 00084832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupApi.dll
2016-05-11 17:02 - 2016-04-23 09:12 - 00451928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFCaptureEngine.dll
2016-05-11 17:02 - 2016-04-23 09:12 - 00413536 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifitask.exe
2016-05-11 17:02 - 2016-04-23 09:11 - 00696672 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupEngine.dll
2016-05-11 17:02 - 2016-04-23 09:11 - 00390496 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanapi.dll
2016-05-11 17:02 - 2016-04-23 09:11 - 00131424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ufxsynopsys.sys
2016-05-11 17:02 - 2016-04-23 09:11 - 00115040 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupApi.dll
2016-05-11 17:02 - 2016-04-23 09:10 - 00330072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pci.sys
2016-05-11 17:02 - 2016-04-23 09:09 - 00569744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SHCore.dll
2016-05-11 17:02 - 2016-04-23 09:09 - 00565600 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncHost.exe
2016-05-11 17:02 - 2016-04-23 09:09 - 00465760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncHost.exe
2016-05-11 17:02 - 2016-04-23 09:09 - 00303216 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppHost.exe
2016-05-11 17:02 - 2016-04-23 09:09 - 00255168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LockAppHost.exe
2016-05-11 17:02 - 2016-04-23 09:08 - 00725776 _____ (Microsoft Corporation) C:\WINDOWS\system32\SHCore.dll
2016-05-11 17:02 - 2016-04-23 09:07 - 01848072 _____ (Microsoft Corporation) C:\WINDOWS\system32\crypt32.dll
2016-05-11 17:02 - 2016-04-23 09:07 - 01536088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\crypt32.dll
2016-05-11 17:02 - 2016-04-23 09:07 - 00204048 _____ (Microsoft Corporation) C:\WINDOWS\system32\rsaenh.dll
2016-05-11 17:02 - 2016-04-23 09:07 - 00183904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rsaenh.dll
2016-05-11 17:02 - 2016-04-23 09:06 - 00291360 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininit.exe
2016-05-11 17:02 - 2016-04-23 09:02 - 00188256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxAllUserStore.dll
2016-05-11 17:02 - 2016-04-23 09:01 - 00619296 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d10level9.dll
2016-05-11 17:02 - 2016-04-23 09:01 - 00577368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2016-05-11 17:02 - 2016-04-23 09:01 - 00513368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d10level9.dll
2016-05-11 17:02 - 2016-04-23 09:01 - 00393568 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2016-05-11 17:02 - 2016-04-23 09:01 - 00217440 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxAllUserStore.dll
2016-05-11 17:02 - 2016-04-23 09:00 - 01776768 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecs.dll
2016-05-11 17:02 - 2016-04-23 09:00 - 01594920 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32.dll
2016-05-11 17:02 - 2016-04-23 09:00 - 01522152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecs.dll
2016-05-11 17:02 - 2016-04-23 09:00 - 01399224 _____ (Microsoft Corporation) C:\WINDOWS\system32\user32.dll
2016-05-11 17:02 - 2016-04-23 09:00 - 01372304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32.dll
2016-05-11 17:02 - 2016-04-23 09:00 - 01337240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\user32.dll
2016-05-11 17:02 - 2016-04-23 09:00 - 00550656 _____ (Microsoft Corporation) C:\WINDOWS\system32\directmanipulation.dll
2016-05-11 17:02 - 2016-04-23 09:00 - 00453472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\directmanipulation.dll
2016-05-11 17:02 - 2016-04-23 09:00 - 00058208 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwminit.dll
2016-05-11 17:02 - 2016-04-23 08:56 - 00534872 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBHUB3.SYS
2016-05-11 17:02 - 2016-04-23 08:35 - 00066560 _____ (Microsoft Corporation) C:\WINDOWS\system32\MosHostClient.dll
2016-05-11 17:02 - 2016-04-23 08:34 - 00067072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\usbser.sys
2016-05-11 17:02 - 2016-04-23 08:34 - 00059392 _____ (Microsoft Corporation) C:\WINDOWS\system32\hmkd.dll
2016-05-11 17:02 - 2016-04-23 08:34 - 00048128 _____ (Microsoft Corporation) C:\WINDOWS\system32\wups.dll
2016-05-11 17:02 - 2016-04-23 08:33 - 00089600 _____ (Microsoft Corporation) C:\WINDOWS\system32\NFCProvisioningPlugin.dll
2016-05-11 17:02 - 2016-04-23 08:33 - 00063488 _____ (Microsoft Corporation) C:\WINDOWS\system32\wshbth.dll
2016-05-11 17:02 - 2016-04-23 08:33 - 00063488 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\UcmCx.sys
2016-05-11 17:02 - 2016-04-23 08:33 - 00038400 _____ (Microsoft Corporation) C:\WINDOWS\system32\ByteCodeGenerator.exe
2016-05-11 17:02 - 2016-04-23 08:32 - 00134656 _____ (Microsoft Corporation) C:\WINDOWS\system32\wificonnapi.dll
2016-05-11 17:02 - 2016-04-23 08:32 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseDesktopAppMgmtCSP.dll
2016-05-11 17:02 - 2016-04-23 08:30 - 00112640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthenum.sys
2016-05-11 17:02 - 2016-04-23 08:30 - 00050176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MosHostClient.dll
2016-05-11 17:02 - 2016-04-23 08:29 - 00192000 _____ (Microsoft Corporation) C:\WINDOWS\system32\provisioningcsp.dll
2016-05-11 17:02 - 2016-04-23 08:29 - 00151040 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEStoreEventHandlers.dll
2016-05-11 17:02 - 2016-04-23 08:29 - 00087552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\filecrypt.sys
2016-05-11 17:02 - 2016-04-23 08:29 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDMAppInstaller.exe
2016-05-11 17:02 - 2016-04-23 08:29 - 00047104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hmkd.dll
2016-05-11 17:02 - 2016-04-23 08:29 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ByteCodeGenerator.exe
2016-05-11 17:02 - 2016-04-23 08:29 - 00023552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wups.dll
2016-05-11 17:02 - 2016-04-23 08:28 - 00130560 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudDomainJoinDataModelServer.dll
2016-05-11 17:02 - 2016-04-23 08:28 - 00127488 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEDataLayerHelpers.dll
2016-05-11 17:02 - 2016-04-23 08:28 - 00104448 _____ (Microsoft Corporation) C:\WINDOWS\system32\BluetoothApis.dll
2016-05-11 17:02 - 2016-04-23 08:28 - 00086528 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppCapture.dll
2016-05-11 17:02 - 2016-04-23 08:28 - 00051712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wshbth.dll
2016-05-11 17:02 - 2016-04-23 08:27 - 00155136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hidclass.sys
2016-05-11 17:02 - 2016-04-23 08:27 - 00039424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wfdprov.dll
2016-05-11 17:02 - 2016-04-23 08:26 - 00086528 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpdbusenum.dll
2016-05-11 17:02 - 2016-04-23 08:25 - 00630784 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneProviders.dll
2016-05-11 17:02 - 2016-04-23 08:25 - 00617984 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll
2016-05-11 17:02 - 2016-04-23 08:25 - 00210432 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmcsp.dll
2016-05-11 17:02 - 2016-04-23 08:25 - 00207360 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupSvc.dll
2016-05-11 17:02 - 2016-04-23 08:24 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2016-05-11 17:02 - 2016-04-23 08:24 - 00689152 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll
2016-05-11 17:02 - 2016-04-23 08:24 - 00292864 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll
2016-05-11 17:02 - 2016-04-23 08:24 - 00287232 _____ (Microsoft Corporation) C:\WINDOWS\system32\provhandlers.dll
2016-05-11 17:02 - 2016-04-23 08:24 - 00181248 _____ (Microsoft Corporation) C:\WINDOWS\system32\shacct.dll
2016-05-11 17:02 - 2016-04-23 08:24 - 00166400 _____ (Microsoft Corporation) C:\WINDOWS\system32\SubscriptionMgr.dll
2016-05-11 17:02 - 2016-04-23 08:24 - 00084480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VEDataLayerHelpers.dll
2016-05-11 17:02 - 2016-04-23 08:23 - 00414720 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.exe
2016-05-11 17:02 - 2016-04-23 08:23 - 00279040 _____ (Microsoft Corporation) C:\WINDOWS\system32\ListSvc.dll
2016-05-11 17:02 - 2016-04-23 08:23 - 00179712 _____ (Microsoft Corporation) C:\WINDOWS\system32\BrowserSettingSync.dll
2016-05-11 17:02 - 2016-04-23 08:23 - 00080896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BluetoothApis.dll
2016-05-11 17:02 - 2016-04-23 08:22 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEEventDispatcher.dll
2016-05-11 17:02 - 2016-04-23 08:21 - 00479232 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll
2016-05-11 17:02 - 2016-04-23 08:21 - 00314880 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXTaskFactory.dll
2016-05-11 17:02 - 2016-04-23 08:20 - 00497152 _____ (Microsoft Corporation) C:\WINDOWS\system32\tileobjserver.dll
2016-05-11 17:02 - 2016-04-23 08:20 - 00484352 _____ (Microsoft Corporation) C:\WINDOWS\system32\DataSenseHandlers.dll
2016-05-11 17:02 - 2016-04-23 08:20 - 00356864 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActivationManager.dll
2016-05-11 17:02 - 2016-04-23 08:20 - 00307200 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll
2016-05-11 17:02 - 2016-04-23 08:20 - 00137728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shacct.dll
2016-05-11 17:02 - 2016-04-23 08:19 - 00395264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlansec.dll
2016-05-11 17:02 - 2016-04-23 08:19 - 00140800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BrowserSettingSync.dll
2016-05-11 17:02 - 2016-04-23 08:18 - 00988672 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedStartModel.dll
2016-05-11 17:02 - 2016-04-23 08:18 - 00954368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthport.sys
2016-05-11 17:02 - 2016-04-23 08:18 - 00804352 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2016-05-11 17:02 - 2016-04-23 08:18 - 00605184 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2016-05-11 17:02 - 2016-04-23 08:18 - 00515072 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneDriveSettingSyncProvider.dll
2016-05-11 17:02 - 2016-04-23 08:18 - 00471552 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupShim.dll
2016-05-11 17:02 - 2016-04-23 08:18 - 00436736 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll
2016-05-11 17:02 - 2016-04-23 08:18 - 00219648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VEEventDispatcher.dll
2016-05-11 17:02 - 2016-04-23 08:18 - 00084992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BTHUSB.SYS
2016-05-11 17:02 - 2016-04-23 08:17 - 01213440 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
2016-05-11 17:02 - 2016-04-23 08:17 - 00388608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schannel.dll
2016-05-11 17:02 - 2016-04-23 08:17 - 00337920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wlanmsm.dll
2016-05-11 17:02 - 2016-04-23 08:16 - 00848896 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2016-05-11 17:02 - 2016-04-23 08:15 - 01073152 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXService.dll
2016-05-11 17:02 - 2016-04-23 08:15 - 00865792 _____ (Microsoft Corporation) C:\WINDOWS\system32\AzureSettingSyncProvider.dll
2016-05-11 17:02 - 2016-04-23 08:15 - 00400896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OneDriveSettingSyncProvider.dll
2016-05-11 17:02 - 2016-04-23 08:14 - 00647680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2016-05-11 17:02 - 2016-04-23 08:14 - 00503296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2016-05-11 17:02 - 2016-04-23 08:14 - 00354304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupShim.dll
2016-05-11 17:02 - 2016-04-23 08:14 - 00342528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll
2016-05-11 17:02 - 2016-04-23 08:13 - 00705536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2016-05-11 17:02 - 2016-04-23 08:13 - 00489984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.dll
2016-05-11 17:02 - 2016-04-23 08:13 - 00434688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LogonController.dll
2016-05-11 17:02 - 2016-04-23 08:12 - 00667648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AzureSettingSyncProvider.dll
2016-05-11 17:02 - 2016-04-23 08:07 - 00848896 _____ (Microsoft Corporation) C:\WINDOWS\system32\samsrv.dll
2016-05-11 17:02 - 2016-04-23 08:05 - 00613376 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSync.dll
2016-05-11 17:02 - 2016-04-23 08:05 - 00111616 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatepolicy.dll
2016-05-11 17:02 - 2016-04-23 08:05 - 00103936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\updatepolicy.dll
2016-05-11 17:02 - 2016-04-23 08:03 - 02193408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll
2016-05-11 17:02 - 2016-04-23 08:03 - 00503296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSync.dll
2016-05-11 17:02 - 2016-04-23 08:01 - 04775424 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll
2016-05-11 17:02 - 2016-04-23 08:00 - 01390080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Shell.dll
2016-05-11 17:02 - 2016-04-23 07:45 - 00461824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll
2016-05-11 17:02 - 2016-04-23 06:10 - 00215040 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll
2016-05-11 17:01 - 2016-04-23 06:10 - 00002186 _____ C:\WINDOWS\system32\AppxProvisioning.xml
2016-05-11 17:01 - 2016-04-19 02:30 - 00002186 _____ C:\WINDOWS\SysWOW64\AppxProvisioning.xml
2016-05-11 16:55 - 2016-05-11 16:56 - 00000000 ____D C:\Users\Haris Hameed\Downloads\Zoolander 2 (2016) [YTS.AG]
2016-05-11 16:53 - 2016-05-11 16:53 - 00030787 _____ C:\Users\Haris Hameed\Downloads\Zoolander 2 (2016) [720p] [YTS.AG].torrent
2016-05-09 20:42 - 2016-05-09 20:42 - 00009435 _____ C:\Users\Haris Hameed\Downloads\Book1 (2).xlsx
2016-05-09 20:41 - 2016-05-09 20:41 - 00009281 _____ C:\Users\Haris Hameed\Downloads\Book1.xlsx
2016-05-09 20:41 - 2016-05-09 20:41 - 00009281 _____ C:\Users\Haris Hameed\Downloads\Book1 (1).xlsx
2016-05-09 20:38 - 2016-05-09 20:38 - 00009435 _____ C:\Users\Haris Hameed\Documents\Book1.xlsx
2016-05-09 20:09 - 2016-05-09 20:09 - 00009281 _____ C:\Users\Haris Hameed\Desktop\Book1.xlsx
2016-05-07 17:26 - 2016-05-07 17:26 - 00000000 ____D C:\Users\Haris Hameed\Downloads\Lego Scooby-Doo! Haunted Hollywood (2016) [YTS.AG]
2016-05-07 17:25 - 2016-05-07 17:25 - 00022733 _____ C:\Users\Haris Hameed\Downloads\Lego Scooby-Doo!- Haunted Hollywood (2016) [720p] [YTS.AG].torrent
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-06-04 00:08 - 2014-10-25 17:24 - 00000000 __SHD C:\Users\Haris Hameed\IntelGraphicsProfiles
2016-06-04 00:06 - 2015-11-15 11:38 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-06-04 00:05 - 2015-10-30 10:28 - 00524288 ___SH C:\WINDOWS\system32\config\BBI
2016-06-03 22:08 - 2015-10-30 11:21 - 00000000 ____D C:\WINDOWS\INF
2016-06-03 18:32 - 2015-10-30 11:24 - 00000000 ____D C:\WINDOWS\AppReadiness
2016-06-03 18:19 - 2015-09-16 15:24 - 00000000 ____D C:\Users\Haris Hameed\AppData\Roaming\DNSHelper
2016-06-03 18:03 - 2015-07-26 20:51 - 00000000 ____D C:\Users\abc\AppData\Roaming\RunDir
2016-06-03 18:00 - 2015-06-28 17:42 - 00000000 ____D C:\Users\abc\AppData\Roaming\NetService
2016-06-03 17:40 - 2015-10-30 11:24 - 00000000 ___HD C:\WINDOWS\ELAMBKUP
2016-06-03 17:27 - 2016-04-08 18:21 - 00000000 ____D C:\Users\Haris Hameed\AppData\Roaming\WMPNetworkAcSvc
2016-06-03 17:13 - 2014-11-26 13:22 - 00000000 ____D C:\Users\Haris Hameed\AppData\Roaming\uTorrent
2016-06-03 16:58 - 2014-10-25 15:59 - 00004158 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{6CE1D0F4-A213-4B95-AAEA-A9F78F325515}
2016-06-03 16:57 - 2016-02-23 16:08 - 00000000 ____D C:\Program Files (x86)\HTC
2016-06-03 16:50 - 2015-12-16 11:31 - 00000000 ____D C:\Program Files (x86)\Rockstar Games
2016-06-03 16:50 - 2015-12-16 11:30 - 00000000 ____D C:\Program Files\Rockstar Games
2016-06-03 15:51 - 2015-10-07 16:40 - 00000000 ____D C:\Users\Haris Hameed\AppData\LocalLow\Temp
2016-06-03 13:31 - 2015-11-15 11:17 - 00972104 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2016-06-03 13:19 - 2015-10-01 21:37 - 00000000 ____D C:\Users\Haris Hameed\Desktop\HARIS CV
2016-06-03 10:39 - 2014-10-25 17:45 - 00000000 __RDO C:\Users\Haris Hameed\OneDrive
2016-06-02 18:07 - 2015-10-30 11:24 - 00000000 ___HD C:\Program Files\WindowsApps
2016-06-02 17:35 - 2015-09-16 20:30 - 00000008 __RSH C:\ProgramData\ntuser.pol
2016-06-02 17:31 - 2015-11-15 11:18 - 00000000 ____D C:\Users\Haris Hameed
2016-06-02 17:31 - 2015-10-30 11:24 - 00000000 ____D C:\WINDOWS\SysWOW64\GroupPolicy
2016-06-02 17:31 - 2013-08-22 19:36 - 00000000 ___HD C:\WINDOWS\system32\GroupPolicy
2016-06-02 16:13 - 2014-10-23 23:59 - 00000000 ____D C:\Users\Haris Hameed\AppData\Local\Packages
2016-06-02 15:22 - 2015-10-30 11:24 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2016-06-02 15:22 - 2014-10-30 22:10 - 00000000 ____D C:\Users\Haris Hameed\AppData\Roaming\vlc
2016-06-02 15:10 - 2015-09-19 17:48 - 00000000 ____D C:\Users\Haris Hameed\AppData\Roaming\YDWaDPzbP
2016-06-02 15:10 - 2015-09-17 14:30 - 00000000 ____D C:\Users\Haris Hameed\AppData\Roaming\WJwktKvvk
2016-06-02 15:10 - 2015-09-17 14:30 - 00000000 ____D C:\Users\Haris Hameed\AppData\Roaming\Cucckoo
2016-06-02 15:10 - 2015-09-16 22:00 - 00000000 ____D C:\Users\Haris Hameed\AppData\Roaming\PGHkOi0Uwp
2016-06-02 15:10 - 2015-09-16 16:01 - 00000000 ____D C:\Users\Haris Hameed\AppData\Roaming\NShChaGNnj
2016-06-02 15:03 - 2015-10-30 11:24 - 00000000 ____D C:\WINDOWS\registration
2016-06-02 11:56 - 2016-01-19 20:37 - 00000000 ____D C:\Users\Haris Hameed\AppData\Local\Google
2016-06-02 11:56 - 2014-10-24 18:36 - 00000000 ____D C:\Program Files (x86)\Google
2016-06-02 11:37 - 2015-11-15 11:18 - 00000000 ____D C:\Users\UpdatusUser
2016-05-23 21:48 - 2015-10-30 11:24 - 00000000 ____D C:\WINDOWS\system32\NDF
2016-05-23 21:48 - 2014-10-24 00:21 - 00000000 ____D C:\Users\Haris Hameed\AppData\Local\ElevatedDiagnostics
2016-05-20 15:31 - 2015-09-16 20:30 - 00002419 _____ C:\Users\Haris Hameed\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2016-05-15 23:48 - 2015-10-30 11:24 - 00000000 ____D C:\WINDOWS\rescache
2016-05-14 16:40 - 2015-10-30 11:11 - 00000000 ____D C:\WINDOWS\CbsTemp
2016-05-12 12:02 - 2015-01-15 12:16 - 00000000 ____D C:\Users\Haris Hameed\Dodge charger hellcat
2016-05-12 12:02 - 2014-10-23 23:50 - 00000000 __RHD C:\Users\Public\AccountPictures
2016-05-11 23:57 - 2015-10-30 11:26 - 00829944 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2016-05-11 23:57 - 2015-10-30 11:26 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2016-05-11 22:46 - 2015-10-30 11:24 - 00000000 ____D C:\WINDOWS\SysWOW64\en-GB
2016-05-11 22:45 - 2015-10-30 22:19 - 00000000 ____D C:\Program Files\Windows Journal
2016-05-11 22:45 - 2015-10-30 11:24 - 00000000 ____D C:\WINDOWS\system32\oobe
2016-05-11 22:45 - 2015-10-30 11:24 - 00000000 ____D C:\WINDOWS\system32\en-GB
2016-05-11 22:45 - 2015-10-30 11:24 - 00000000 ____D C:\WINDOWS\system32\appraiser
2016-05-11 22:45 - 2015-10-30 11:24 - 00000000 ____D C:\WINDOWS\Provisioning
2016-05-11 22:45 - 2015-10-30 11:24 - 00000000 ____D C:\WINDOWS\bcastdvr
2016-05-11 18:02 - 2012-10-04 20:35 - 00000000 ____D C:\ProgramData\Intel
2016-05-11 17:30 - 2015-10-30 11:24 - 00015703 _____ C:\WINDOWS\system32\OEMDefaultAssociations.xml
2016-05-11 17:25 - 2014-10-24 02:02 - 00000000 ____D C:\WINDOWS\system32\MRT
2016-05-11 17:13 - 2014-10-24 02:02 - 139319312 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2016-05-08 15:09 - 2016-02-23 16:07 - 00000000 ____D C:\Users\Haris Hameed\Hashim
2016-05-06 00:40 - 2016-05-03 18:54 - 00000000 ____D C:\Users\Haris Hameed\New folder (2)
==================== Files in the root of some directories =======
2015-01-18 19:47 - 2015-01-18 19:47 - 0000057 _____ () C:\ProgramData\Ament.ini
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2016-06-02 12:03
==================== End of FRST.txt ============================
Addition.txt Log:-
Additional scan result of Farbar Recovery Scan Tool (x64) Version:03-06-2016
Ran by [removed] (2016-06-04 12:05:12)
Running from C:\Users\[removed]\Desktop
Windows 10 Home Single Language Version 1511 (X64) (2015-11-15 07:46:29)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-1503482889-339291205-912318997-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-1503482889-339291205-912318997-503 - Limited - Disabled)
Guest (S-1-5-21-1503482889-339291205-912318997-501 - Limited - Disabled)
Haris Hameed (S-1-5-21-1503482889-339291205-912318997-1002 - Administrator - Enabled) => C:\Users\Haris Hameed
HomeGroupUser$ (S-1-5-21-1503482889-339291205-912318997-1006 - Limited - Enabled)
UpdatusUser (S-1-5-21-1503482889-339291205-912318997-1001 - Limited - Enabled) => C:\Users\UpdatusUser
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
µTorrent (HKU\S-1-5-21-1503482889-339291205-912318997-1002\…\uTorrent) (Version: 3.4.7.42330 - BitTorrent Inc.)
Adobe Shockwave Player 11.6 (HKLM-x32\…\Adobe Shockwave Player) (Version: 11.6.5.635 - Adobe Systems, Inc.)
CyberLink PhotoDirector (HKLM-x32\…\InstallShield_{4862344A-A39C-4897-ACD4-A1BED5163C5A}) (Version: 2.0.2.3317 - CyberLink Corp.)
CyberLink PowerDirector 10 (HKLM-x32\…\InstallShield_{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}) (Version: 10.0.1.1925 - CyberLink Corp.)
CyberLink PowerDVD (HKLM-x32\…\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.6.4319 - CyberLink Corp.)
CyberLink YouCam (HKLM-x32\…\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 3.5.4.5527 - CyberLink Corp.)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Energy Star (HKLM\…\{0FA995CC-C849-4755-B14B-5404CC75DC24}) (Version: 1.0.8 - Hewlett-Packard)
ESET Smart Security (HKLM\…\{BA1050B5-E274-4693-8A67-CAF5576A07F1}) (Version: 9.0.381.0 - ESET, spol. s r.o.)
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 51.0.2704.79 - Google Inc.)
Google Update Helper (x32 Version: 1.3.30.3 - Google Inc.) Hidden
Hewlett-Packard ACLM.NET v1.2.0.0 (x32 Version: 1.00.0000 - Hewlett-Packard Company) Hidden
HP 3D DriveGuard (HKLM\…\{54CE68A8-4F2D-4328-B1F7-D6C720405F7F}) (Version: 4.2.9.1 - Hewlett-Packard Company)
HP Documentation (HKLM-x32\…\{D044EBE7-94E7-4C49-90FC-9069E3F374E1}) (Version: 1.1.0.0 - Hewlett-Packard)
HP Photo Creations (HKLM-x32\…\HP Photo Creations) (Version: 1.0.0.7702 - HP)
HP Quick Launch (HKLM-x32\…\{E5823036-6F09-4D0A-B05C-E2BAA129288A}) (Version: 3.0.6 - Hewlett-Packard Company)
HP Registration Service (HKLM\…\{E4D6CCF2-0AAF-4B9C-9DE5-893EDC9B4BAA}) (Version: 1.0.5976.4186 - Hewlett-Packard)
HP Software Framework (HKLM-x32\…\{675D093B-815D-47FD-AB2C-192EC751E8E2}) (Version: 4.6.10.1 - Hewlett-Packard Company)
HP Update (HKLM-x32\…\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
HP Utility Center (HKLM-x32\…\{0C57987A-A03A-4B95-A309-D23F78F406CA}) (Version: 1.0.7 - Hewlett-Packard)
HP Wireless Button Driver (HKLM-x32\…\{30B2D1D8-0A07-4B71-9553-0710C5D31E35}) (Version: 1.1.2.1 - Hewlett-Packard Company)
IDT Audio (HKLM-x32\…\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}) (Version: 1.0.6425.0 - IDT)
Intel(R) Management Engine Components (HKLM-x32\…\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.1.30.1349 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\…\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.4276 - Intel Corporation)
Intel(R) SDK for OpenCL - CPU Only Runtime Package (HKLM-x32\…\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: 2.0.0.37149 - Intel Corporation)
Microsoft Office (HKLM-x32\…\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.6120.5004 - Microsoft Corporation)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\…\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft)
Microsoft Office Enterprise 2007 (HKLM-x32\…\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office File Validation Add-In (HKLM-x32\…\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (HKLM\…\{350AA351-21FA-3270-8B7A-835434E766AD}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\…\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\…\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 Redistributable - x64 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 Redistributable - x86 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
NVIDIA Graphics Driver 306.97 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 306.97 - NVIDIA Corporation)
NVIDIA Update 1.10.8 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 1.10.8 - NVIDIA Corporation)
Ralink Bluetooth Stack64 (HKLM\…\{95DF815D-BE2D-9118-F549-39794C5869CF}) (Version: 9.0.725.0 - Ralink Corporation)
Ralink RT3290 802.11bgn Wi-Fi Adapter (HKLM-x32\…\{8FC4F1DD-F7FD-4766-804D-3C8FF1D309AF}) (Version: 5.0.2.0 - Ralink)
Realtek Ethernet Controller Driver (HKLM-x32\…\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.3.730.2012 - Realtek)
Realtek PCIE Card Reader (HKLM-x32\…\{C1594429-8296-4652-BF54-9DBE4932A44C}) (Version: 6.2.8400.29029 - Realtek Semiconductor Corp.)
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Synaptics Pointing Device Driver (HKLM\…\SynTPDeinstKey) (Version: 19.0.12.98 - Synaptics Incorporated)
Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\…\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft)
VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0 - DivX, Inc) Hidden
VLC media player (HKLM\…\VLC media player) (Version: 2.1.5 - VideoLAN)
Windows Live Essentials (HKLM-x32\…\WinLiveSuite) (Version: 15.4.3555.0308 - Microsoft Corporation)
WinRAR 5.20 (32-bit) (HKLM-x32\…\WinRAR archiver) (Version: 5.20.0 - win.rar GmbH)
معرض صور Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-1503482889-339291205-912318997-1002_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\Haris Hameed\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\FileCoAuth.exe (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1503482889-339291205-912318997-1002_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\WINDOWS\system32\igfxEM.exe (Intel Corporation)
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {02D2817B-E890-4C97-9C59-4397795AE0D0} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe
Task: {03125C0E-F5A7-4C71-93F6-8E1271A0F827} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Tuneup => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe
Task: {1F246E43-B50F-4EBD-86CC-562D0DA77507} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe
Task: {3298C6E9-B40B-46DC-95B9-9C053E855258} - System32\Tasks\MirageAgent => C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe [2012-07-27] (CyberLink)
Task: {3FAF0304-6BE2-44A6-85F9-0D1826524D6E} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2016-05-11] (Microsoft Corporation)
Task: {760D219B-ACF8-4B3B-BA2A-41B9CEFB42A3} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Update Check => C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFUpdater.exe [2014-05-12] (Hewlett-Packard Company)
Task: {7A646CAD-8AC6-421A-AB76-BAF4033823F7} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-06-02] (Google Inc.)
Task: {7A943937-9981-47BF-90DA-026F71B51463} - System32\Tasks\Hewlett-Packard\HP CoolSense\HP CoolSense Start at Logon => C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe [2013-11-01] (Hewlett-Packard Development Company, L.P.)
Task: {9860E038-6756-483C-B373-ABE4075EF11D} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-06-02] (Google Inc.)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
==================== Shortcuts =============================
(The entries could be listed to be restored or removed.)
==================== Loaded Modules (Whitelisted) ==============
2015-10-30 11:18 - 2015-10-30 11:18 - 00185856 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll
2015-07-23 04:02 - 2015-07-23 04:02 - 00011920 _____ () C:\Program Files\NVIDIA Corporation\CoProcManager\detoured.dll
2015-11-15 11:12 - 2015-07-23 05:10 - 00116552 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2016-04-08 18:21 - 2016-03-15 10:40 - 04984448 _____ () C:\Users\Haris Hameed\AppData\Roaming\WMPNetworkAcSvc\WMPNetworkAcSvc.exe
2016-04-12 22:30 - 2016-03-29 14:20 - 02656952 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
2016-04-12 22:30 - 2016-03-29 14:20 - 02656952 _____ () C:\WINDOWS\System32\CoreUIComponents.dll
2016-05-20 15:31 - 2016-05-20 15:31 - 00959168 _____ () C:\Users\Haris Hameed\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64\ClientTelemetry.dll
2016-04-19 13:59 - 2016-04-19 14:00 - 00144384 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeHost.exe
2015-12-18 19:06 - 2015-12-07 08:14 - 00093696 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\Windows.UI.Shell.SharedUtilities.dll
2016-05-11 17:01 - 2016-04-23 08:25 - 00472064 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll
2016-05-11 17:02 - 2016-04-23 08:25 - 00674816 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\MtcUvc.dll
2016-05-11 17:03 - 2016-04-23 08:02 - 07992832 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2016-05-11 17:02 - 2016-04-23 07:58 - 00591360 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2016-05-11 17:03 - 2016-04-23 07:58 - 02483200 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2016-05-11 17:04 - 2016-04-23 08:01 - 04089856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2016-05-18 15:27 - 2016-06-02 11:49 - 00200704 _____ () C:\ProgramData\Microsoft\Network\Dsq\browser\syshostctl.exe
2016-04-07 22:04 - 2016-04-07 22:05 - 00016896 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.325.12390.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
2016-04-07 22:04 - 2016-04-07 22:05 - 17535488 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.325.12390.0_x64__8wekyb3d8bbwe\Microsoft.Photos.dll
2016-03-04 15:36 - 2016-03-04 15:40 - 00291328 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_16.325.12390.0_x64__8wekyb3d8bbwe\StoreRatingPromotion.dll
2015-10-30 11:18 - 2015-10-30 11:18 - 00218456 _____ () c:\windows\system32\WerEtw.dll
2016-04-08 18:21 - 2015-11-28 13:45 - 00083456 _____ () C:\Users\Haris Hameed\AppData\Roaming\WMPNetworkAcSvc\Interface.dll
2016-04-19 13:59 - 2016-04-19 14:00 - 00141312 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeBackgroundTasks.dll
2016-04-19 13:59 - 2016-04-19 14:00 - 22284800 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkyWrap.dll
2015-07-23 04:02 - 2015-07-23 04:02 - 00012104 _____ () C:\Program Files (x86)\NVIDIA Corporation\CoProcManager\detoured.dll
2016-05-20 15:31 - 2016-05-20 15:31 - 00679624 _____ () C:\Users\Haris Hameed\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\ClientTelemetry.dll
2012-10-04 20:38 - 2014-10-24 00:51 - 01200088 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
==================== Safe Mode (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
==================== Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
==================== Hosts content: ===============================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2013-08-22 17:25 - 2016-06-04 00:04 - 00000098 ____A C:\WINDOWS\system32\Drivers\etc\hosts
127.0.0.1 localhost
::1 localhost
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-1503482889-339291205-912318997-1001\Control Panel\Desktop\\Wallpaper ->
HKU\S-1-5-21-1503482889-339291205-912318997-1002\Control Panel\Desktop\\Wallpaper -> c:\users\haris hameed\dodge charger hellcat\2015-dodge-charger-white-awesome-car.jpg
DNS Servers: 192.168.110.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is disabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
(Currently there is no automatic fix for this section.)
HKLM\…\StartupApproved\Run32: => "gmsd_ra_005010099"
HKU\S-1-5-21-1503482889-339291205-912318997-1002\…\StartupApproved\StartupFolder: => "Top Gear Season 20 Episode 3 HDTV x264 2HD.lnk"
HKU\S-1-5-21-1503482889-339291205-912318997-1002\…\StartupApproved\Run: => "GoogleChromeAutoLaunch_A6E047D90953B2DDB3FC5CD1C643B18B"
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [TCP Query User{ED8128AE-4CAF-44E2-9D8F-4F8C25BBC2FF}C:\programdata\microsoft\network\dsq\network\sysnetwk.exe] => (Block) C:\programdata\microsoft\network\dsq\network\sysnetwk.exe
FirewallRules: [UDP Query User{AF0164DB-8653-4963-8038-1FC101FF5818}C:\programdata\microsoft\network\dsq\network\sysnetwk.exe] => (Block) C:\programdata\microsoft\network\dsq\network\sysnetwk.exe
FirewallRules: [{E9C2EE48-9EC3-43DE-BEFA-3AC7D0A95418}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Restore Points =========================
28-05-2016 23:37:35 Scheduled Checkpoint
02-06-2016 11:45:57 Removed IPTInstaller
02-06-2016 15:51:37 JRT Pre-Junkware Removal
03-06-2016 13:09:36 JRT Pre-Junkware Removal
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (06/03/2016 11:00:04 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: regedit.exe, version: 10.0.10586.0, time stamp: 0x5632d798
Faulting module name: USER32.dll, version: 10.0.10586.306, time stamp: 0x571af6a4
Exception code: 0xc000041d
Fault offset: 0x000000000001d8a4
Faulting process ID: 0x14bc
Faulting application start time: 0xregedit.exe0
Faulting application path: regedit.exe1
Faulting module path: regedit.exe2
Report ID: regedit.exe3
Faulting package full name: regedit.exe4
Faulting package-relative application ID: regedit.exe5
Error: (06/03/2016 10:05:38 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: svchost.exe, version: 10.0.10586.0, time stamp: 0x5632d7ba
Faulting module name: ESENT.dll, version: 10.0.10586.212, time stamp: 0x56fa1686
Exception code: 0xc0000602
Fault offset: 0x000000000022885f
Faulting process ID: 0x948
Faulting application start time: 0xsvchost.exe0
Faulting application path: svchost.exe1
Faulting module path: svchost.exe2
Report ID: svchost.exe3
Faulting package full name: svchost.exe4
Faulting package-relative application ID: svchost.exe5
Error: (06/03/2016 10:05:38 PM) (Source: ESENT) (EventID: 908) (User: )
Description: svchost (2376) Terminating process due to non-recoverable failure: PV: 10.0.10586.0 SV: 10.0.10586.0 GLE: 0 ERR: -1603(fucb.cxx:359): dllentry.cxx(103) (ESENT[10.0.10586.0] RETAIL RTM MBCS)
Error: (06/03/2016 09:14:39 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: SettingSyncHost.exe, version: 10.0.10586.306, time stamp: 0x571af461
Faulting module name: ntdll.dll, version: 10.0.10586.306, time stamp: 0x571af2eb
Exception code: 0xc0000005
Fault offset: 0x000000000002fe34
Faulting process ID: 0x450
Faulting application start time: 0xSettingSyncHost.exe0
Faulting application path: SettingSyncHost.exe1
Faulting module path: SettingSyncHost.exe2
Report ID: SettingSyncHost.exe3
Faulting package full name: SettingSyncHost.exe4
Faulting package-relative application ID: SettingSyncHost.exe5
Error: (06/03/2016 07:26:03 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: HARIS)
Description: Activation of application Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy!App failed with error: -2144927142 See the Microsoft-Windows-TWinUI/Operational log for additional information.
Error: (06/03/2016 07:21:31 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: HARIS)
Description: Activation of application Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy!App failed with error: -2144927142 See the Microsoft-Windows-TWinUI/Operational log for additional information.
Error: (06/03/2016 07:21:31 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: HARIS)
Description: Activation of application Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy!App failed with error: -2144927142 See the Microsoft-Windows-TWinUI/Operational log for additional information.
Error: (06/03/2016 05:13:08 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: HARIS)
Description: Activation of application Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI failed with error: -2144927141 See the Microsoft-Windows-TWinUI/Operational log for additional information.
Error: (06/03/2016 04:57:02 PM) (Source: Microsoft-Windows-RestartManager) (EventID: 10007) (User: HARIS)
Description: Application or service 'Internet Pass-Through Service' could not be restarted.
Error: (06/03/2016 01:09:48 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.
Details:
AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol.
System Error:
Access is denied.
.
System errors:
=============
Error: (06/04/2016 12:56:46 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: application-specificLocalActivation{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)UnavailableUnavailable
Error: (06/04/2016 12:05:23 AM) (Source: DCOM) (EventID: 10010) (User: HARIS)
Description: {9BA05972-F6A8-11CF-A442-00A0C90A8F39}
Error: (06/04/2016 12:05:20 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The User Data Access_45a09 service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service.
Error: (06/04/2016 12:05:20 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The User Data Storage_45a09 service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service.
Error: (06/04/2016 12:05:20 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Contact Data_45a09 service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service.
Error: (06/04/2016 12:05:20 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Sync Host_45a09 service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 10000 milliseconds: Restart the service.
Error: (06/04/2016 12:05:20 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: application-specificLocalActivation{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)UnavailableUnavailable
Error: (06/04/2016 12:03:52 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Intel(R) Content Protection HECI Service service terminated unexpectedly. It has done this 1 time(s).
Error: (06/03/2016 11:28:37 PM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY)
Description: {F3B4E234-7A68-4E43-B813-E4BA55A065F6}
Error: (06/03/2016 10:07:54 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Windows Presentation Foundation Font Cache 3.0.0.0 service failed to start due to the following error:
%%1053
CodeIntegrity:
===================================
Date: 2016-06-03 11:42:12.383
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2016-06-02 17:57:42.380
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2016-06-02 12:06:56.041
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2016-05-28 18:44:36.305
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2016-05-20 15:37:21.654
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
Date: 2016-05-19 21:25:37.705
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2016-05-15 20:02:01.500
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
Date: 2016-05-14 16:44:23.254
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2016-05-11 22:50:43.206
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
Date: 2016-04-30 17:01:52.272
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Common Files\microsoft shared\OFFICE12\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
==================== Memory info ===========================
Processor: Intel(R) Core(TM) i3-3217U CPU @ 1.80GHz
Percentage of memory in use: 44%
Total physical RAM: 3988.27 MB
Available physical RAM: 2206.79 MB
Total Virtual: 4692.27 MB
Available Virtual: 2886.48 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:447.39 GB) (Free:152.55 GB) NTFS ==>[system with boot components (obtained from drive)]
Drive d: (RECOVERY) (Fixed) (Total:16.34 GB) (Free:16.22 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 465.8 GB) (Disk ID: 12A350F5)
Partition: GPT.
==================== End of Addition.txt ============================