My computer is painfully slow, especially running Firefox, but slow everywhere. It will freeze for a minute (until I do ctrl-alt-del to close the program), then starts running again.
I uninstalled things I wasn't using and moved large files (pictures) to external hard drives to make space. But maybe this is spyware or malware? Any help would be greatly appreciated!
11:30:32.609 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0
11:30:32.625 Disk 0 Vendor: ST2000DM001-1ER164 CC26 Size: 1907729MB BusType: 3
11:30:32.734 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 2048
11:30:32.749 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 1907627 MB offset 206848
11:30:58.723 Service WRkrn C:\Windows\System32\drivers\WRkrn.sys **LOCKED** 32
11:30:59.641 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys ataport.SYS pciide.sys
11:30:59.641 3 CLASSPNP.SYS[fffff880018cb43f] -> nt!IofCallDriver -> [0xfffffa800632e520]
11:30:59.641 5 ACPI.sys[fffff88000e0b7a5] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-0[0xfffffa8006330060]
11:31:21.744 Disk 0 MBR has been saved successfully to "C:\Users\User\Desktop\MBR.dat"
11:31:21.744 The log file has been saved successfully to "C:\Users\User\Desktop\aswMBR.txt"
[removed]
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Webroot) C:\Program Files (x86)\Webroot\WRSA.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(Stardock Corporation) C:\Program Files\Dell\DellDock\DockLogin.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe
(Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
(Webroot) C:\Program Files (x86)\Webroot\WRSA.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
(Cybereason) C:\Program Files (x86)\Cybereason\RansomFree\CybereasonRansomFreeServiceHost.exe
(SEIKO EPSON CORPORATION) C:\Program Files\EPSON\EpsonCustomerResearchParticipation\EPCP.exe
(Seiko Epson Corporation) C:\Windows\System32\escsvc64.exe
(Garmin Ltd. or its subsidiaries) C:\Program Files (x86)\Garmin\Device Interaction Service\GarminService.exe
(Siber Systems) C:\Program Files (x86)\Siber Systems\AI RoboForm\robotaskbaricon.exe
(Intuit Inc.) C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Stardock Corporation) C:\Program Files\Dell\DellDock\DellDock.exe
(Microsoft Corporation) C:\Program Files\Microsoft LifeCam\MSCamS64.exe
(Cybereason) C:\Program Files (x86)\Cybereason\RansomFree\CybereasonRansomFree.exe
(Nalpeiron Ltd.) C:\Windows\SysWOW64\nlssrv32.exe
(Intuit Inc.) C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
(Intuit Inc.) C:\Program Files (x86)\Common Files\Intuit\DataProtect\QBIDPService.exe
() C:\Program Files (x86)\Photodex\ProShowGold\scsiaccess.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Elements 11 Organizer\PhotoshopElementsFileAgent.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
(Siber Systems) C:\Program Files (x86)\Siber Systems\AI RoboForm\robotaskbaricon-x64.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\cmd.exe
(Siber Systems Inc.) C:\Program Files (x86)\Siber Systems\AI RoboForm\Chrome\rf-chrome-nm-host.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\…\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
HKLM-x32\…\Run: [WRSVC] => C:\Program Files (x86)\Webroot\WRSA.exe [1253368 2018-02-05] (Webroot)
HKLM-x32\…\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2017-07-21] (Oracle Corporation)
HKU\S-1-5-21-3209421979-1208344015-1759688515-1000\…\Run: [RoboForm] => C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe [110888 2018-04-20] (Siber Systems)
HKU\S-1-5-21-3209421979-1208344015-1759688515-1000\…\Policies\Explorer: [NoDrives] 1
HKU\S-1-5-21-3209421979-1208344015-1759688515-1000\…\MountPoints2: K - K:\LaunchU3.exe -a
HKU\S-1-5-21-3209421979-1208344015-1759688515-1000\…\MountPoints2: {2e2c7b1d-8699-11e3-a28f-b8ac6fa51810} - I:\LaunchU3.exe -a
HKU\S-1-5-21-3209421979-1208344015-1759688515-1000\…\MountPoints2: {a84d016b-aded-11e3-93f5-b8ac6fa51810} - I:\LaunchU3.exe -a
HKU\S-1-5-18\…\Run: [GarminExpressTrayApp] => C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [1462184 2018-03-27] (Garmin Ltd. or its subsidiaries)
HKU\S-1-5-18\…\RunOnce: [SPReview] => "C:\Windows\System32\SPReview\SPReview.exe" /sp:1 /errorfwlink:"hxxp://go.microsoft.com/fwlink/?LinkID=122915" /build:7601
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Intuit Data Protect.lnk [2018-03-29]
ShortcutTarget: Intuit Data Protect.lnk -> C:\Program Files (x86)\Common Files\Intuit\DataProtect\IntuitDataProtect.exe (Intuit Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk [2018-03-29]
ShortcutTarget: QuickBooks Update Agent.lnk -> C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe (Intuit Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\QuickBooks_Standard_21.lnk [2018-03-29]
ShortcutTarget: QuickBooks_Standard_21.lnk -> C:\Program Files (x86)\Intuit\QuickBooks 2018\QBW32.EXE (Intuit Inc.)
Startup: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk [2013-09-25]
ShortcutTarget: Dell Dock.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
CHR HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{77DCE6AA-D6F2-42F6-968F-4D8C4F992ACE}: [DhcpNameServer] 192.168.1.1
Internet Explorer:
==================
HKU\S-1-5-21-3209421979-1208344015-1759688515-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.bbc.com/
SearchScopes: HKU\S-1-5-21-3209421979-1208344015-1759688515-1000 -> {376071A5-9A15-40A5-94DF-DEB8A8EDF3E9} URL = hxxps://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-3209421979-1208344015-1759688515-1000 -> {C05118E6-1418-49EA-8EFB-F163E5DCC570} URL = hxxps://search.yahoo.com/search?p={searchTerms}&fr;=yset_ie_syc_oracle&type;=orcl_default
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2018-02-13] (Microsoft Corporation)
BHO: RoboForm Toolbar Helper -> {724d43a9-0d85-11d4-9908-00400523e39a} -> C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll [2018-04-20] (Siber Systems Inc.)
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_144\bin\ssv.dll [2017-07-26] (Oracle Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL [2017-12-12] (Microsoft Corporation)
BHO: Webroot Filtering Extension -> {C9C42510-9B41-42c1-9DCD-7282A2D07C61} -> C:\Program Files\Common Files\Webroot\WebFiltering\wrflt.dll [2018-02-12] (Webroot)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2018-03-13] (Microsoft Corporation)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_144\bin\jp2ssv.dll [2017-07-26] (Oracle Corporation)
BHO-x32: RoboForm Toolbar Helper -> {724d43a9-0d85-11d4-9908-00400523e39a} -> C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll [2018-04-20] (Siber Systems Inc.)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_144\bin\ssv.dll [2017-07-26] (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL [2017-12-12] (Microsoft Corporation)
BHO-x32: Webroot Filtering Extension -> {C9C42510-9B41-42c1-9DCD-7282A2D07C61} -> C:\Program Files (x86)\Common Files\Webroot\WebFiltering\wrflt.dll [2018-02-12] (Webroot)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_144\bin\jp2ssv.dll [2017-07-26] (Oracle Corporation)
Toolbar: HKLM - &RoboForm; Toolbar - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll [2018-04-20] (Siber Systems Inc.)
Toolbar: HKLM-x32 - &RoboForm; Toolbar - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll [2018-04-20] (Siber Systems Inc.)
Toolbar: HKU\S-1-5-21-3209421979-1208344015-1759688515-1000 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
Toolbar: HKU\S-1-5-21-3209421979-1208344015-1759688515-1000 -> &RoboForm; Toolbar - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll [2018-04-20] (Siber Systems Inc.)
Handler-x32: intu-help-qb11 - {5AFDE6E8-AD0F-450B-818F-21D1CDC2E3EE} - C:\Program Files (x86)\Intuit\QuickBooks 2018\HelpAsyncPluggableProtocol.dll [2018-02-16] (Intuit, Inc.)
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL [2017-07-18] (Microsoft Corporation)
Handler-x32: qbwc - {FC598A64-626C-4447-85B8-53150405FD57} - C:\Windows\system32\mscoree.dll [2010-11-04] (Microsoft Corporation)
FireFox:
========
FF ProfilePath: C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\3pubklj9.default [2018-04-25]
FF Homepage: Mozilla\Firefox\Profiles\3pubklj9.default -> hxxp://www.bbc.com/
FF Session Restore: Mozilla\Firefox\Profiles\3pubklj9.default -> is enabled.
FF Extension: (Flash Video Downloader) - C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\3pubklj9.default\Extensions\[removed] [2018-04-05]
FF Extension: (RoboForm Password Manager) - C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\3pubklj9.default\Extensions\[removed] [2018-04-19]
FF Extension: (uBlock Origin) - C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\3pubklj9.default\Extensions\[removed] [2018-04-19]
FF Extension: (Flash and Video Download) - C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\3pubklj9.default\Extensions\{bee6eb20-01e0-ebd1-da83-080329fb9a3a}.xpi [2018-04-19]
FF Extension: (Adblock Plus) - C:\Users\User\AppData\Roaming\Mozilla\Firefox\Profiles\3pubklj9.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2018-04-23]
FF HKLM\…\Firefox\Extensions: [[removed]] - C:\ProgramData\WRData\PKG\FF_WEBEX
FF Extension: (Webroot Filtering Extension) - C:\ProgramData\WRData\PKG\FF_WEBEX [2018-02-12]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_29_0_0_140.dll [2018-04-10] ()
FF Plugin: @java.com/DTPlugin,version=11.144.2 -> C:\Program Files\Java\jre1.8.0_144\bin\dtplugin\npDeployJava1.dll [2017-07-26] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.144.2 -> C:\Program Files\Java\jre1.8.0_144\bin\plugin2\npjp2.dll [2017-07-26] (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2018-02-14] (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_29_0_0_140.dll [2018-04-10] ()
FF Plugin-x32: @java.com/DTPlugin,version=11.144.2 -> C:\Program Files (x86)\Java\jre1.8.0_144\bin\dtplugin\npDeployJava1.dll [2017-07-26] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.144.2 -> C:\Program Files (x86)\Java\jre1.8.0_144\bin\plugin2\npjp2.dll [2017-07-26] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [2013-11-23] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-13] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-13] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2018-02-11] (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2018-02-14] (Adobe Systems)
FF Plugin HKU\S-1-5-21-3209421979-1208344015-1759688515-1000: @citrixonline.com/appdetectorplugin -> C:\Users\User\AppData\Local\Citrix\Plugins\104\npappdetector.dll [2014-09-09] (Citrix Online)
FF Plugin HKU\S-1-5-21-3209421979-1208344015-1759688515-1000: @zoom.us/ZoomVideoPlugin -> C:\Users\User\AppData\Roaming\Zoom\bin\npzoomplugin.dll [2018-01-03] (Zoom Video Communications, Inc.)
FF Plugin HKU\S-1-5-21-3209421979-1208344015-1759688515-1000: wacom.com/WacomTabletPlugin -> C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll [No File]
FF Plugin ProgramFiles/Appdata: C:\Users\User\AppData\Roaming\mozilla\plugins\npPxPlay.dll [2013-09-25] ( )
Chrome:
=======
CHR HomePage: Default -> hxxps://www.youtube.com/channel/UCtxo0nTZjzlKJq5-vJq6s6g/videos?disable_polymer=1/
CHR DefaultSearchURL: Default -> hxxp://mps.eanswers.com/search/?category=web&s;=sbds&q;={searchTerms}
CHR DefaultSearchKeyword: Default -> Safe Browsing
CHR DefaultSuggestURL: Default -> hxxp://sug.eanswers.com/search/index_sg.php?q={searchTerms}
CHR Session Restore: Default -> is enabled.
CHR Profile: C:\Users\User\AppData\Local\Google\Chrome\User Data\Default [2018-04-25]
CHR Extension: (Slides) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-10-12]
CHR Extension: (Docs) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-12]
CHR Extension: (Google Drive) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-07-05]
CHR Extension: (YouTube) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-07-05]
CHR Extension: (Safe Browsing) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\ecpnacfdmkfdabpdpbnnacjfdfcldklf [2017-10-12]
CHR Extension: (Adobe Acrobat) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2017-12-18]
CHR Extension: (Sheets) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-10-12]
CHR Extension: (Fair Ads) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\gagfkmknmijppikpcikmbbkdkhggcmge [2017-07-05]
CHR Extension: (Google Docs Offline) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-07-05]
CHR Extension: (Personal Finder) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\ieadhjnlaapbkjkccpmlnemhgakcmeel [2017-10-16]
CHR Extension: (Webroot Filtering Extension) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\kjeghcllfecehndceplomkocgfbklffd [2018-01-31]
CHR Extension: (Courses - IPS Mastermind -) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\kkpnhhakakmcnmcohbnmpkeldllfkadl [2018-01-16]
CHR Extension: (Fair AdBlocker) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\lgblnfidahcdcjddiepkckcfdhpknnjh [2017-07-05]
CHR Extension: (Chrome Web Store Payments) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-04-04]
CHR Extension: (Gmail) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-07-05]
CHR Extension: (Chrome Media Router) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-03-23]
CHR Extension: (RoboForm Password Manager) - C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\pnlccmojcmeohlpggmfnbbiapkmbliob [2018-04-16]
CHR HKLM\…\Chrome\Extension: [pnlccmojcmeohlpggmfnbbiapkmbliob] - C:\Program Files (x86)\Siber Systems\AI RoboForm\Chrome\rf-chrome.crx [2014-06-22]
CHR HKU\S-1-5-21-3209421979-1208344015-1759688515-1000\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [kjeghcllfecehndceplomkocgfbklffd] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [pnlccmojcmeohlpggmfnbbiapkmbliob] - C:\Program Files (x86)\Siber Systems\AI RoboForm\Chrome\rf-chrome.crx [2014-06-22]
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AdobeActiveFileMonitor11.0; C:\Program Files (x86)\Adobe\Elements 11 Organizer\PhotoshopElementsFileAgent.exe [171600 2012-09-17] (Adobe Systems Incorporated)
R2 AdobeUpdateService; C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [818128 2018-02-14] (Adobe Systems Incorporated)
R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2319848 2018-01-05] (Adobe Systems, Incorporated)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2017-04-03] (Apple Inc.)
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [3058392 2017-12-12] (Microsoft Corporation)
R2 CybereasonRansomFree; C:\Program Files (x86)\Cybereason\RansomFree\CybereasonRansomFreeServiceHost.exe [13824 2017-11-20] (Cybereason) [File not signed]
S3 EasyAntiCheat; C:\Windows\SysWOW64\EasyAntiCheat.exe [245544 2017-01-23] (EasyAntiCheat Ltd)
R2 EpsonCustomerResearchParticipation; C:\Program Files\EPSON\EpsonCustomerResearchParticipation\EPCP.exe [674768 2018-03-07] (SEIKO EPSON CORPORATION)
R2 EpsonScanSvc; C:\Windows\system32\EscSvc64.exe [145224 2017-05-10] (Seiko Epson Corporation)
R2 Garmin Device Interaction Service; C:\Program Files (x86)\Garmin\Device Interaction Service\GarminService.exe [1175056 2018-03-27] (Garmin Ltd. or its subsidiaries)
R2 Net Driver HPZ12; C:\Windows\system32\HPZinw12.dll [71680 2010-08-06] (Hewlett-Packard) [File not signed]
R2 nlsX86cc; C:\Windows\SysWOW64\nlssrv32.exe [66560 2011-10-24] (Nalpeiron Ltd.) [File not signed]
R2 Pml Driver HPZ12; C:\Windows\system32\HPZipm12.dll [89600 2010-08-06] (Hewlett-Packard) [File not signed]
S3 QBFCService; C:\Program Files (x86)\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe [65536 2018-02-15] (Intuit Inc.) [File not signed]
R2 ScsiAccess; C:\Program Files (x86)\Photodex\ProShowGold\ScsiAccess.exe [181312 2013-09-25] () [File not signed]
S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-26] (Microsoft Corporation)
R2 WRSVC; C:\Program Files (x86)\Webroot\WRSA.exe [1253368 2018-02-05] (Webroot)
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R0 PxHlpa64; C:\Windows\System32\Drivers\PxHlpa64.sys [56336 2012-08-10] (Corel Corporation)
S3 Spyder3; C:\Windows\System32\DRIVERS\Spyder3.sys [15360 2008-09-08] ()
R0 WRkrn; C:\Windows\System32\drivers\WRkrn.sys [144256 2018-02-05] (Webroot)
S3 wrUrlFlt; C:\Windows\system32\DRIVERS\wrUrlFlt.sys [68384 2018-01-31] (Webroot)
S3 cpuz134; \??\C:\Users\User\AppData\Local\Temp\cpuz134\cpuz134_x64.sys [X] <==== ATTENTION
S0 MBAMSwissArmy; system32\drivers\MBAMSwissArmy.sys [X]
U3 aswMBR; \??\C:\Users\User\AppData\Local\Temp\aswMBR.sys [X] <==== ATTENTION
U3 aswVmm; \??\C:\Users\User\AppData\Local\Temp\aswVmm.sys [X] <==== ATTENTION
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2018-04-25 11:34 - 2018-04-25 11:35 - 000022810 _____ C:\Users\User\Downloads\FRST.txt
2018-04-25 11:33 - 2018-04-25 11:34 - 000000000 ____D C:\FRST
2018-04-25 11:33 - 2018-04-25 11:33 - 002405888 _____ (Farbar) C:\Users\User\Downloads\FRST64.exe
2018-04-25 11:31 - 2018-04-25 11:31 - 000001915 _____ C:\Users\User\Desktop\aswMBR.txt
2018-04-25 11:31 - 2018-04-25 11:31 - 000000512 _____ C:\Users\User\Desktop\MBR.dat
2018-04-25 07:45 - 2018-04-25 07:45 - 000526307 ____N C:\Users\Akdfzbx\enterprise_jumped.xlsx
2018-04-25 07:45 - 2018-04-25 07:45 - 000519911 ____N C:\Users\Vk70y\brick.experiences.ill.xlsx
2018-04-25 07:45 - 2018-04-25 07:45 - 000224963 ____N C:\Users\Akdfzbx\nerves-wall-ships-grammar.mdb
2018-04-25 07:45 - 2018-04-25 07:45 - 000208056 ____N C:\Users\Vk70y\corresponding_omit_wind_currency.mdb
2018-04-25 07:45 - 2018-04-25 07:45 - 000078894 ____N C:\Users\Akdfzbx\event_quarrel_roll.xls
2018-04-25 07:45 - 2018-04-25 07:45 - 000072167 ____N C:\Users\Vk70y\northwestendlessallowsstock.xls
2018-04-25 07:45 - 2018-04-25 07:45 - 000058446 ____N C:\Users\Vk70y\random jews lately.pem
2018-04-25 07:45 - 2018-04-25 07:45 - 000058327 ____N C:\Users\Akdfzbx\wagon_distance.pem
2018-04-25 07:45 - 2018-04-25 07:45 - 000035996 ____N C:\Users\Akdfzbx\north fully wet hung.txt
2018-04-25 07:45 - 2018-04-25 07:45 - 000035274 ____N C:\Users\Vk70y\easilysixties.txt
2018-04-25 07:45 - 2018-04-25 07:45 - 000021166 ____N C:\Users\Vk70y\shelf-adventure-depending.sql
2018-04-25 07:45 - 2018-04-25 07:45 - 000020187 ____N C:\Users\Akdfzbx\him_are.sql
2018-04-25 07:45 - 2018-04-25 07:45 - 000000000 __SHD C:\Users\User\Desktop\0K, this directory is for Ransomware detection (just leave it here)
2018-04-25 07:45 - 2018-04-25 07:45 - 000000000 ___HD C:\Users\Vk70y
2018-04-25 07:45 - 2018-04-25 07:45 - 000000000 ___HD C:\Users\User\Documents\Xscan229
2018-04-25 07:45 - 2018-04-25 07:45 - 000000000 ___HD C:\Users\User\Documents\Acscan87
2018-04-25 07:45 - 2018-04-25 07:45 - 000000000 ___HD C:\Users\Akdfzbx
2018-04-25 07:45 - 2018-04-25 07:45 - 000000000 ____D C:\Xlog37
2018-04-25 07:45 - 2018-04-25 07:45 - 000000000 ____D C:\09cdocuments99
2018-04-23 18:29 - 2018-04-23 18:29 - 000054982 _____ C:\Users\User\Desktop\ScottSmith42318.pdf
2018-04-23 18:23 - 2018-04-23 18:23 - 000058201 _____ C:\Users\User\Desktop\Gesa42318.pdf
2018-04-20 18:22 - 2018-04-20 18:22 - 000004206 _____ C:\Windows\System32\Tasks\Open URL by RoboForm
2018-04-19 16:54 - 2018-04-19 16:54 - 000159020 _____ C:\Users\User\Documents\bookmarks_4_19_18.html
2018-04-18 12:50 - 2018-04-18 12:50 - 000201848 _____ C:\Users\User\Documents\Sonja Photography Pricing 2018.pdf
2018-04-17 10:32 - 2018-04-20 16:11 - 000000000 ____D C:\Users\User\AppData\Local\RoboForm
2018-04-17 10:31 - 2018-04-17 10:31 - 023445608 _____ (Siber Systems) C:\Users\User\Downloads\RoboForm-v8-Setup.exe
2018-04-16 16:27 - 2018-04-16 14:21 - 032851452 _____ C:\Users\User\Desktop\Sociology Full Text.pdf
2018-04-16 11:47 - 2018-04-16 11:47 - 000001118 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Media Encoder CC 2018.lnk
2018-04-16 11:41 - 2018-04-16 11:41 - 000001061 _____ C:\Users\User\Desktop\Adobe Lightroom Classic CC.lnk
2018-04-16 11:41 - 2018-04-16 11:41 - 000001061 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Lightroom Classic CC.lnk
2018-04-16 11:33 - 2018-04-16 11:33 - 000001040 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CC 2018.lnk
2018-04-15 20:08 - 2018-04-15 20:08 - 000078592 _____ C:\Users\User\Documents\Retreat Packing List.pdf
2018-04-13 19:28 - 2018-04-13 19:37 - 000000000 ____D C:\Users\User\Documents\School Presentations
2018-04-13 12:02 - 2018-03-30 19:09 - 005583040 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2018-04-13 12:02 - 2018-03-30 19:09 - 000708288 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2018-04-13 12:02 - 2018-03-30 19:09 - 000262336 _____ (Microsoft Corporation) C:\Windows\system32\hal.dll
2018-04-13 12:02 - 2018-03-30 19:09 - 000154816 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2018-04-13 12:02 - 2018-03-30 19:09 - 000095424 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2018-04-13 12:02 - 2018-03-30 18:45 - 000631640 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2018-04-13 12:02 - 2018-03-30 18:39 - 004046528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2018-04-13 12:02 - 2018-03-30 18:39 - 003958464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2018-04-13 12:02 - 2018-03-30 18:38 - 001665336 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2018-04-13 12:02 - 2018-03-30 18:12 - 001314064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2018-04-13 12:02 - 2018-03-28 00:30 - 003225600 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2018-04-13 12:02 - 2018-03-23 11:50 - 000396952 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2018-04-13 12:02 - 2018-03-23 10:59 - 000348824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2018-04-13 12:02 - 2018-03-22 16:00 - 025742336 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2018-04-13 12:02 - 2018-03-22 14:32 - 002724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2018-04-13 12:02 - 2018-03-22 14:32 - 000004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2018-04-13 12:02 - 2018-03-22 14:26 - 020287488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2018-04-13 12:02 - 2018-03-22 14:19 - 002901504 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2018-04-13 12:02 - 2018-03-22 14:18 - 000066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2018-04-13 12:02 - 2018-03-22 14:17 - 000578048 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2018-04-13 12:02 - 2018-03-22 14:17 - 000417280 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2018-04-13 12:02 - 2018-03-22 14:17 - 000088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2018-04-13 12:02 - 2018-03-22 14:17 - 000048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2018-04-13 12:02 - 2018-03-22 14:15 - 005780480 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2018-04-13 12:02 - 2018-03-22 14:10 - 000054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2018-04-13 12:02 - 2018-03-22 14:09 - 000034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2018-04-13 12:02 - 2018-03-22 14:07 - 000615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2018-04-13 12:02 - 2018-03-22 14:06 - 000794112 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2018-04-13 12:02 - 2018-03-22 14:06 - 000144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2018-04-13 12:02 - 2018-03-22 14:06 - 000116224 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2018-04-13 12:02 - 2018-03-22 14:05 - 000814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2018-04-13 12:02 - 2018-03-22 14:04 - 002724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2018-04-13 12:02 - 2018-03-22 13:58 - 000969216 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2018-04-13 12:02 - 2018-03-22 13:55 - 000489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2018-04-13 12:02 - 2018-03-22 13:52 - 000499712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2018-04-13 12:02 - 2018-03-22 13:52 - 000062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2018-04-13 12:02 - 2018-03-22 13:51 - 000341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2018-04-13 12:02 - 2018-03-22 13:51 - 000047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2018-04-13 12:02 - 2018-03-22 13:50 - 000064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2018-04-13 12:02 - 2018-03-22 13:49 - 000077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2018-04-13 12:02 - 2018-03-22 13:48 - 002295296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2018-04-13 12:02 - 2018-03-22 13:48 - 000107520 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2018-04-13 12:02 - 2018-03-22 13:48 - 000087552 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2018-04-13 12:02 - 2018-03-22 13:45 - 000199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2018-04-13 12:02 - 2018-03-22 13:45 - 000047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2018-04-13 12:02 - 2018-03-22 13:45 - 000030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2018-04-13 12:02 - 2018-03-22 13:44 - 000092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2018-04-13 12:02 - 2018-03-22 13:43 - 000476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2018-04-13 12:02 - 2018-03-22 13:42 - 000661504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2018-04-13 12:02 - 2018-03-22 13:42 - 000315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2018-04-13 12:02 - 2018-03-22 13:42 - 000115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2018-04-13 12:02 - 2018-03-22 13:41 - 000620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2018-04-13 12:02 - 2018-03-22 13:40 - 000152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2018-04-13 12:02 - 2018-03-22 13:33 - 000416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2018-04-13 12:02 - 2018-03-22 13:31 - 000262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2018-04-13 12:02 - 2018-03-22 13:29 - 015282688 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2018-04-13 12:02 - 2018-03-22 13:29 - 000809472 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2018-04-13 12:02 - 2018-03-22 13:29 - 000728064 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2018-04-13 12:02 - 2018-03-22 13:29 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2018-04-13 12:02 - 2018-03-22 13:28 - 000091136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2018-04-13 12:02 - 2018-03-22 13:28 - 000073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2018-04-13 12:02 - 2018-03-22 13:27 - 002135552 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2018-04-13 12:02 - 2018-03-22 13:27 - 001359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2018-04-13 12:02 - 2018-03-22 13:25 - 000168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2018-04-13 12:02 - 2018-03-22 13:25 - 000076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2018-04-13 12:02 - 2018-03-22 13:24 - 000279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2018-04-13 12:02 - 2018-03-22 13:22 - 000130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2018-04-13 12:02 - 2018-03-22 13:21 - 004496896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2018-04-13 12:02 - 2018-03-22 13:20 - 013680128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2018-04-13 12:02 - 2018-03-22 13:17 - 000230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2018-04-13 12:02 - 2018-03-22 13:15 - 003241472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2018-04-13 12:02 - 2018-03-22 13:15 - 000696320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2018-04-13 12:02 - 2018-03-22 13:14 - 002059776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2018-04-13 12:02 - 2018-03-22 13:14 - 001155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2018-04-13 12:02 - 2018-03-22 13:04 - 001545728 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2018-04-13 12:02 - 2018-03-22 12:55 - 002767872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2018-04-13 12:02 - 2018-03-22 12:53 - 000800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2018-04-13 12:02 - 2018-03-22 12:52 - 001313792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2018-04-13 12:02 - 2018-03-22 12:51 - 000710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2018-04-13 12:02 - 2018-03-10 10:11 - 000340480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msexcl40.dll
2018-04-13 12:02 - 2018-03-09 11:18 - 000309440 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2018-04-13 12:02 - 2018-03-09 11:12 - 000383680 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2018-04-13 12:02 - 2018-03-09 11:12 - 000111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\t2embed.dll
2018-04-13 12:02 - 2018-03-09 11:12 - 000071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2018-04-13 12:02 - 2018-03-09 11:07 - 000152064 _____ (Microsoft Corporation) C:\Windows\system32\t2embed.dll
2018-04-13 12:02 - 2018-03-09 11:07 - 000100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2018-04-13 12:02 - 2018-03-06 11:13 - 000148160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\basecsp.dll
2018-04-13 12:02 - 2018-03-06 11:11 - 000184320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scksp.dll
2018-04-13 12:02 - 2018-03-06 11:11 - 000052224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wsnmp32.dll
2018-04-13 12:02 - 2018-03-06 11:10 - 000170176 _____ (Microsoft Corporation) C:\Windows\system32\basecsp.dll
2018-04-13 12:02 - 2018-03-06 11:07 - 000229376 _____ (Microsoft Corporation) C:\Windows\system32\scksp.dll
2018-04-13 12:02 - 2018-03-06 11:07 - 000067072 _____ (Microsoft Corporation) C:\Windows\system32\wsnmp32.dll
2018-04-13 12:02 - 2018-02-21 20:28 - 000217600 _____ (Microsoft Corporation) C:\Windows\system32\WinSCard.dll
2018-04-13 12:02 - 2018-02-21 20:06 - 000134656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WinSCard.dll
2018-04-13 12:02 - 2018-02-10 11:35 - 000367296 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msrpc.sys
2018-04-13 12:02 - 2018-02-10 11:35 - 000334528 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\acpi.sys
2018-04-13 12:02 - 2018-02-10 11:35 - 000185024 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\pci.sys
2018-04-13 12:02 - 2018-02-10 11:35 - 000122560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\NV_AGP.SYS
2018-04-13 12:02 - 2018-02-10 11:35 - 000068288 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\volmgr.sys
2018-04-13 12:02 - 2018-02-10 11:35 - 000064192 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ULIAGPKX.SYS
2018-04-13 12:02 - 2018-02-10 11:35 - 000063168 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\termdd.sys
2018-04-13 12:02 - 2018-02-10 11:35 - 000060608 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\AGP440.sys
2018-04-13 12:02 - 2018-02-10 11:35 - 000036032 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\vdrvroot.sys
2018-04-13 12:02 - 2018-02-10 11:35 - 000031936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mssmbios.sys
2018-04-13 12:02 - 2018-02-10 11:35 - 000023744 _____ (Microsoft Corporation) C:\Windows\system32\streamci.dll
2018-04-13 12:02 - 2018-02-10 11:35 - 000020160 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\isapnp.sys
2018-04-13 12:02 - 2018-02-10 11:35 - 000015040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msisadrv.sys
2018-04-13 12:02 - 2018-02-10 11:35 - 000012096 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\swenum.sys
2018-04-13 12:02 - 2018-02-10 11:23 - 002292224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSVidCtl.dll
2018-04-13 12:02 - 2018-02-10 11:23 - 000330240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\zipfldr.dll
2018-04-13 12:02 - 2018-02-10 11:11 - 003665920 _____ (Microsoft Corporation) C:\Windows\system32\MSVidCtl.dll
2018-04-13 12:02 - 2018-02-10 11:11 - 000369664 _____ (Microsoft Corporation) C:\Windows\system32\zipfldr.dll
2018-04-13 12:02 - 2018-02-10 11:11 - 000133120 _____ (Microsoft Corporation) C:\Windows\system32\msrahc.dll
2018-04-13 12:02 - 2018-02-10 11:11 - 000119296 _____ (Microsoft Corporation) C:\Windows\system32\racpldlg.dll
2018-04-13 12:02 - 2018-02-10 10:36 - 000040960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sdchange.exe
2018-04-13 12:02 - 2018-02-10 10:26 - 000653312 _____ (Microsoft Corporation) C:\Windows\system32\msra.exe
2018-04-13 12:02 - 2018-02-10 10:26 - 000051712 _____ (Microsoft Corporation) C:\Windows\system32\sdchange.exe
2018-04-13 12:02 - 2018-02-02 11:40 - 000114368 _____ (Microsoft Corporation) C:\Windows\system32\consent.exe
2018-04-13 12:02 - 2018-02-02 11:29 - 002365952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2018-04-13 12:02 - 2018-02-02 11:29 - 000337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll
2018-04-13 12:02 - 2018-02-02 11:28 - 001806848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2018-04-13 12:02 - 2018-02-02 11:16 - 003246080 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2018-04-13 12:02 - 2018-02-02 11:16 - 000504320 _____ (Microsoft Corporation) C:\Windows\system32\msihnd.dll
2018-04-13 12:02 - 2018-02-02 11:14 - 001942016 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll
2018-04-13 12:02 - 2018-02-02 11:14 - 000070144 _____ (Microsoft Corporation) C:\Windows\system32\appinfo.dll
2018-04-13 12:02 - 2018-02-02 10:46 - 000073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msiexec.exe
2018-04-13 12:02 - 2018-02-02 10:36 - 000128512 _____ (Microsoft Corporation) C:\Windows\system32\msiexec.exe
2018-04-13 12:02 - 2018-01-25 07:05 - 000995272 _____ (Microsoft Corporation) C:\Windows\system32\ucrtbase.dll
2018-04-13 12:02 - 2018-01-25 07:05 - 000063832 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-private-l1-1-0.dll
2018-04-13 12:02 - 2018-01-25 07:05 - 000020824 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-math-l1-1-0.dll
2018-04-13 12:02 - 2018-01-25 07:05 - 000019800 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-multibyte-l1-1-0.dll
2018-04-13 12:02 - 2018-01-25 07:05 - 000017752 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-string-l1-1-0.dll
2018-04-13 12:02 - 2018-01-25 07:05 - 000017752 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-stdio-l1-1-0.dll
2018-04-13 12:02 - 2018-01-25 07:05 - 000016216 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-runtime-l1-1-0.dll
2018-04-13 12:02 - 2018-01-25 07:05 - 000015704 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-convert-l1-1-0.dll
2018-04-13 12:02 - 2018-01-25 07:05 - 000014168 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-time-l1-1-0.dll
2018-04-13 12:02 - 2018-01-25 07:05 - 000014168 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-2-0.dll
2018-04-13 12:02 - 2018-01-25 07:05 - 000013656 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll
2018-04-13 12:02 - 2018-01-25 07:05 - 000012632 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-process-l1-1-0.dll
2018-04-13 12:02 - 2018-01-25 07:05 - 000012632 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-heap-l1-1-0.dll
2018-04-13 12:02 - 2018-01-25 07:05 - 000012632 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-conio-l1-1-0.dll
2018-04-13 12:02 - 2018-01-25 07:05 - 000012120 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-utility-l1-1-0.dll
2018-04-13 12:02 - 2018-01-25 07:05 - 000012120 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-locale-l1-1-0.dll
2018-04-13 12:02 - 2018-01-25 07:05 - 000012120 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-environment-l1-1-0.dll
2018-04-13 12:02 - 2018-01-25 07:05 - 000012120 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-2-0.dll
2018-04-13 12:02 - 2018-01-25 07:05 - 000012120 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-1.dll
2018-04-13 12:02 - 2018-01-25 07:05 - 000011608 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l2-1-0.dll
2018-04-13 12:02 - 2018-01-25 07:05 - 000011608 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-timezone-l1-1-0.dll
2018-04-13 12:02 - 2018-01-25 07:05 - 000011608 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l2-1-0.dll
2018-04-13 12:02 - 2018-01-25 07:05 - 000011608 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-2-0.dll
2018-04-13 12:02 - 2018-01-25 07:04 - 000922944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ucrtbase.dll
2018-04-13 12:02 - 2018-01-25 07:04 - 000066392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-private-l1-1-0.dll
2018-04-13 12:02 - 2018-01-25 07:04 - 000022360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-math-l1-1-0.dll
2018-04-13 12:02 - 2018-01-25 07:04 - 000019800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-multibyte-l1-1-0.dll
2018-04-13 12:02 - 2018-01-25 07:04 - 000017752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-string-l1-1-0.dll
2018-04-13 12:02 - 2018-01-25 07:04 - 000017752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-stdio-l1-1-0.dll
2018-04-13 12:02 - 2018-01-25 07:04 - 000016216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-runtime-l1-1-0.dll
2018-04-13 12:02 - 2018-01-25 07:04 - 000015704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-convert-l1-1-0.dll
2018-04-13 12:02 - 2018-01-25 07:04 - 000014168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-time-l1-1-0.dll
2018-04-13 12:02 - 2018-01-25 07:04 - 000014168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-2-0.dll
2018-04-13 12:02 - 2018-01-25 07:04 - 000013656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-filesystem-l1-1-0.dll
2018-04-13 12:02 - 2018-01-25 07:04 - 000012632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-process-l1-1-0.dll
2018-04-13 12:02 - 2018-01-25 07:04 - 000012632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-heap-l1-1-0.dll
2018-04-13 12:02 - 2018-01-25 07:04 - 000012632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-conio-l1-1-0.dll
2018-04-13 12:02 - 2018-01-25 07:04 - 000012120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-utility-l1-1-0.dll
2018-04-13 12:02 - 2018-01-25 07:04 - 000012120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-locale-l1-1-0.dll
2018-04-13 12:02 - 2018-01-25 07:04 - 000012120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-environment-l1-1-0.dll
2018-04-13 12:02 - 2018-01-25 07:04 - 000012120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-2-0.dll
2018-04-13 12:02 - 2018-01-25 07:04 - 000012120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-1.dll
2018-04-13 12:02 - 2018-01-25 07:04 - 000011608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l2-1-0.dll
2018-04-13 12:02 - 2018-01-25 07:04 - 000011608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-timezone-l1-1-0.dll
2018-04-13 12:02 - 2018-01-25 07:04 - 000011608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l2-1-0.dll
2018-04-13 12:02 - 2018-01-25 07:04 - 000011608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-2-0.dll
2018-04-13 12:02 - 2018-01-12 09:40 - 000407040 _____ (Microsoft Corporation) C:\Windows\system32\scesrv.dll
2018-04-13 12:02 - 2018-01-12 09:26 - 000308224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scesrv.dll
2018-04-13 12:01 - 2018-03-30 18:35 - 001461248 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2018-04-13 12:01 - 2018-03-30 18:35 - 001212928 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2018-04-13 12:01 - 2018-03-30 18:35 - 001163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2018-04-13 12:01 - 2018-03-30 18:35 - 000880640 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2018-04-13 12:01 - 2018-03-30 18:35 - 000731648 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2018-04-13 12:01 - 2018-03-30 18:35 - 000690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2018-04-13 12:01 - 2018-03-30 18:35 - 000503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2018-04-13 12:01 - 2018-03-30 18:35 - 000463872 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2018-04-13 12:01 - 2018-03-30 18:35 - 000419840 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2018-04-13 12:01 - 2018-03-30 18:35 - 000361984 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2018-04-13 12:01 - 2018-03-30 18:35 - 000345600 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2018-04-13 12:01 - 2018-03-30 18:35 - 000316928 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2018-04-13 12:01 - 2018-03-30 18:35 - 000312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2018-04-13 12:01 - 2018-03-30 18:35 - 000243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2018-04-13 12:01 - 2018-03-30 18:35 - 000215552 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2018-04-13 12:01 - 2018-03-30 18:35 - 000210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2018-04-13 12:01 - 2018-03-30 18:35 - 000190464 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll
2018-04-13 12:01 - 2018-03-30 18:35 - 000146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2018-04-13 12:01 - 2018-03-30 18:35 - 000135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2018-04-13 12:01 - 2018-03-30 18:35 - 000123904 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll
2018-04-13 12:01 - 2018-03-30 18:35 - 000094720 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2018-04-13 12:01 - 2018-03-30 18:35 - 000063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2018-04-13 12:01 - 2018-03-30 18:35 - 000060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2018-04-13 12:01 - 2018-03-30 18:35 - 000059904 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2018-04-13 12:01 - 2018-03-30 18:35 - 000050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2018-04-13 12:01 - 2018-03-30 18:35 - 000044032 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2018-04-13 12:01 - 2018-03-30 18:35 - 000043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2018-04-13 12:01 - 2018-03-30 18:35 - 000034816 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2018-04-13 12:01 - 2018-03-30 18:35 - 000028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2018-04-13 12:01 - 2018-03-30 18:35 - 000028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2018-04-13 12:01 - 2018-03-30 18:35 - 000022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2018-04-13 12:01 - 2018-03-30 18:35 - 000016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2018-04-13 12:01 - 2018-03-30 18:35 - 000013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2018-04-13 12:01 - 2018-03-30 18:35 - 000007168 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2018-04-13 12:01 - 2018-03-30 18:35 - 000006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2018-04-13 12:01 - 2018-03-30 18:35 - 000005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2018-04-13 12:01 - 2018-03-30 18:35 - 000004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2018-04-13 12:01 - 2018-03-30 18:35 - 000004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2018-04-13 12:01 - 2018-03-30 18:35 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2018-04-13 12:01 - 2018-03-30 18:35 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2018-04-13 12:01 - 2018-03-30 18:35 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2018-04-13 12:01 - 2018-03-30 18:35 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2018-04-13 12:01 - 2018-03-30 18:35 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2018-04-13 12:01 - 2018-03-30 18:35 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2018-04-13 12:01 - 2018-03-30 18:35 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2018-04-13 12:01 - 2018-03-30 18:35 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2018-04-13 12:01 - 2018-03-30 18:35 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2018-04-13 12:01 - 2018-03-30 18:35 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2018-04-13 12:01 - 2018-03-30 18:35 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2018-04-13 12:01 - 2018-03-30 18:35 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2018-04-13 12:01 - 2018-03-30 18:35 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2018-04-13 12:01 - 2018-03-30 18:35 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2018-04-13 12:01 - 2018-03-30 18:35 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2018-04-13 12:01 - 2018-03-30 18:35 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2018-04-13 12:01 - 2018-03-30 18:35 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2018-04-13 12:01 - 2018-03-30 18:35 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2018-04-13 12:01 - 2018-03-30 18:35 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2018-04-13 12:01 - 2018-03-30 18:35 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2018-04-13 12:01 - 2018-03-30 18:35 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2018-04-13 12:01 - 2018-03-30 18:35 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2018-04-13 12:01 - 2018-03-30 18:35 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2018-04-13 12:01 - 2018-03-30 18:35 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2018-04-13 12:01 - 2018-03-30 18:09 - 001114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2018-04-13 12:01 - 2018-03-30 18:09 - 000690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2018-04-13 12:01 - 2018-03-30 18:09 - 000666112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2018-04-13 12:01 - 2018-03-30 18:09 - 000644096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2018-04-13 12:01 - 2018-03-30 18:09 - 000554496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2018-04-13 12:01 - 2018-03-30 18:09 - 000342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
2018-04-13 12:01 - 2018-03-30 18:09 - 000275456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2018-04-13 12:01 - 2018-03-30 18:09 - 000261120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2018-04-13 12:01 - 2018-03-30 18:09 - 000254464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2018-04-13 12:01 - 2018-03-30 18:09 - 000223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2018-04-13 12:01 - 2018-03-30 18:09 - 000172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2018-04-13 12:01 - 2018-03-30 18:09 - 000146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2018-04-13 12:01 - 2018-03-30 18:09 - 000141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll
2018-04-13 12:01 - 2018-03-30 18:09 - 000096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2018-04-13 12:01 - 2018-03-30 18:09 - 000082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcrypt.dll
2018-04-13 12:01 - 2018-03-30 18:09 - 000070144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2018-04-13 12:01 - 2018-03-30 18:09 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2018-04-13 12:01 - 2018-03-30 18:09 - 000050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll
2018-04-13 12:01 - 2018-03-30 18:09 - 000043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2018-04-13 12:01 - 2018-03-30 18:09 - 000022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2018-04-13 12:01 - 2018-03-30 18:09 - 000017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2018-04-13 12:01 - 2018-03-30 18:09 - 000007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2018-04-13 12:01 - 2018-03-30 18:09 - 000005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2018-04-13 12:01 - 2018-03-30 18:09 - 000005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2018-04-13 12:01 - 2018-03-30 18:09 - 000004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2018-04-13 12:01 - 2018-03-30 18:09 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2018-04-13 12:01 - 2018-03-30 18:09 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2018-04-13 12:01 - 2018-03-30 18:09 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2018-04-13 12:01 - 2018-03-30 18:09 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2018-04-13 12:01 - 2018-03-30 18:09 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2018-04-13 12:01 - 2018-03-30 18:09 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2018-04-13 12:01 - 2018-03-30 18:09 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2018-04-13 12:01 - 2018-03-30 18:09 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2018-04-13 12:01 - 2018-03-30 18:09 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2018-04-13 12:01 - 2018-03-30 18:09 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2018-04-13 12:01 - 2018-03-30 18:09 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2018-04-13 12:01 - 2018-03-30 18:09 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2018-04-13 12:01 - 2018-03-30 18:09 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2018-04-13 12:01 - 2018-03-30 18:09 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2018-04-13 12:01 - 2018-03-30 18:09 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2018-04-13 12:01 - 2018-03-30 18:09 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2018-04-13 12:01 - 2018-03-30 18:09 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2018-04-13 12:01 - 2018-03-30 18:09 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2018-04-13 12:01 - 2018-03-30 18:09 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2018-04-13 12:01 - 2018-03-30 18:09 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2018-04-13 12:01 - 2018-03-30 18:09 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2018-04-13 12:01 - 2018-03-30 18:09 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2018-04-13 12:01 - 2018-03-30 18:06 - 000148480 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2018-04-13 12:01 - 2018-03-30 18:06 - 000064512 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2018-04-13 12:01 - 2018-03-30 18:06 - 000062464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2018-04-13 12:01 - 2018-03-30 18:06 - 000017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2018-04-13 12:01 - 2018-03-30 18:03 - 000338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2018-04-13 12:01 - 2018-03-30 18:02 - 000296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2018-04-13 12:01 - 2018-03-30 18:02 - 000129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\videoprt.sys
2018-04-13 12:01 - 2018-03-30 17:59 - 000160256 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2018-04-13 12:01 - 2018-03-30 17:58 - 000291328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2018-04-13 12:01 - 2018-03-30 17:58 - 000129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2018-04-13 12:01 - 2018-03-30 17:58 - 000112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2018-04-13 12:01 - 2018-03-30 17:58 - 000030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2018-04-13 12:01 - 2018-03-30 17:51 - 000050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2018-04-13 12:01 - 2018-03-30 17:47 - 000036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
2018-04-13 12:01 - 2018-03-30 17:47 - 000025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2018-04-13 12:01 - 2018-03-30 17:47 - 000014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2018-04-13 12:01 - 2018-03-30 17:47 - 000007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2018-04-13 12:01 - 2018-03-30 17:47 - 000006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2018-04-13 12:01 - 2018-03-30 17:47 - 000004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2018-04-13 12:01 - 2018-03-30 17:47 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2018-04-13 12:01 - 2018-03-30 17:47 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2018-04-13 12:01 - 2018-03-30 17:47 - 000002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2018-04-13 12:01 - 2018-03-09 11:12 - 000025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
2018-04-13 12:01 - 2018-03-09 11:11 - 000010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
2018-04-13 12:01 - 2018-03-09 11:07 - 000041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2018-04-13 12:01 - 2018-03-09 11:06 - 000046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2018-04-13 12:01 - 2018-03-09 11:06 - 000014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2018-04-13 12:01 - 2018-03-09 10:31 - 000034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2018-04-13 12:01 - 2018-02-10 11:23 - 000111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\racpldlg.dll
2018-04-13 12:01 - 2018-02-10 10:36 - 000108032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msra.exe
2018-04-13 12:01 - 2018-02-10 10:36 - 000007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MsraLegacy.tlb
2018-04-13 12:01 - 2018-02-10 10:25 - 000014336 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\wmiacpi.sys
2018-04-13 12:01 - 2018-02-10 10:25 - 000009728 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\errdev.sys
2018-04-13 12:01 - 2018-02-10 10:25 - 000007168 _____ (Microsoft Corporation) C:\Windows\system32\MsraLegacy.tlb
2018-04-13 12:01 - 2018-02-02 11:29 - 000025088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msimsg.dll
2018-04-13 12:01 - 2018-02-02 11:16 - 000025088 _____ (Microsoft Corporation) C:\Windows\system32\msimsg.dll
2018-04-13 12:01 - 2018-01-15 12:59 - 000002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2018-04-13 12:01 - 2018-01-15 12:40 - 000002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2018-04-11 07:30 - 2018-03-14 10:14 - 000135360 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe
2018-04-11 07:30 - 2018-03-14 10:09 - 000656384 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2018-04-11 07:30 - 2018-03-14 06:05 - 001993728 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe
2018-04-11 07:30 - 2018-03-14 06:05 - 001559552 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2018-04-11 07:30 - 2018-03-14 06:05 - 000739840 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2018-04-11 07:30 - 2018-03-14 06:05 - 000599552 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2018-04-11 07:30 - 2018-03-14 06:05 - 000450048 _____ (Microsoft Corporation) C:\Windows\system32\centel.dll
2018-04-11 07:30 - 2018-03-14 06:05 - 000414720 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2018-04-11 07:30 - 2018-03-14 06:05 - 000291840 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2018-04-11 07:30 - 2018-03-14 06:05 - 000237056 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2018-04-06 18:01 - 2018-04-06 18:01 - 000057015 _____ C:\Users\User\Desktop\40618.pdf
2018-04-03 09:38 - 2018-04-03 09:38 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Garmin
2018-03-30 08:18 - 2018-02-18 14:34 - 000634272 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
2018-03-29 10:27 - 2018-04-06 18:01 - 000000000 ____D C:\ProgramData\SQL Anywhere 17
2018-03-29 10:25 - 2018-03-29 10:25 - 000000000 ____D C:\Users\User\AppData\Roaming\SQL Anywhere 17
2018-03-29 10:04 - 2018-03-29 10:04 - 000003664 _____ C:\Windows\System32\Tasks\QBScheduledReport
2018-03-29 10:03 - 2018-03-29 10:03 - 000002111 _____ C:\Users\Public\Desktop\QuickBooks Pro 2018.lnk
2018-03-29 10:03 - 2018-03-29 10:03 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickBooks
2018-03-29 09:58 - 2018-03-29 09:58 - 000000000 ____D C:\ProgramData\Nuance
2018-03-29 09:31 - 2018-03-29 09:38 - 772623864 _____ (Intuit, Inc. ) C:\Users\User\Desktop\QuickBooksPro2018.exe
2018-03-29 09:31 - 2018-03-29 09:38 - 000000000 ____D C:\Users\User\AppData\Roaming\Download Manager
2018-03-29 09:31 - 2018-03-29 09:31 - 000000000 ____D C:\Program Files (x86)\Akamai
2018-03-29 09:29 - 2018-03-29 09:29 - 000544776 _____ C:\Users\User\Downloads\Setup_QuickBooksPro2018.exe
2018-03-28 10:24 - 2018-03-28 10:24 - 000550424 _____ () C:\Users\User\Downloads\iExplorerSetup.exe
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2018-04-25 11:22 - 2016-11-18 18:58 - 000000000 ____D C:\Users\User\AppData\LocalLow\Mozilla
2018-04-25 11:17 - 2013-09-20 10:36 - 000000000 ____D C:\Users\User\Documents\Outlook Files
2018-04-25 10:44 - 2017-10-13 11:44 - 000000911 _____ C:\Windows\Tasks\EPSON WF-4730 Series Update {08FA9C7A-10A1-4A59-87F7-A6D3F0CBD42A}.job
2018-04-25 09:34 - 2017-05-04 14:41 - 000000000 ____D C:\ProgramData\WRData
2018-04-25 08:11 - 2009-07-13 21:45 - 000028992 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2018-04-25 08:11 - 2009-07-13 21:45 - 000028992 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2018-04-25 07:57 - 2013-09-25 13:04 - 000000000 ____D C:\Users\User\AppData\Local\Adobe
2018-04-25 07:49 - 2009-07-13 21:45 - 005072600 _____ C:\Windows\system32\FNTCACHE.DAT
2018-04-25 07:44 - 2017-05-04 14:41 - 000182704 _____ (Webroot) C:\Windows\SysWOW64\WRusr.dll
2018-04-25 07:44 - 2017-05-04 14:41 - 000115248 _____ (Webroot) C:\Windows\system32\WRusr.dll
2018-04-25 07:44 - 2009-07-13 22:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2018-04-21 10:26 - 2013-09-25 11:59 - 000000000 ____D C:\Users\User\AppData\Local\CrashDumps
2018-04-21 10:22 - 2017-11-01 15:53 - 000000000 ____D C:\Users\User\.BayPhotoLab
2018-04-20 18:22 - 2013-09-25 11:20 - 000003696 _____ C:\Windows\System32\Tasks\Run RoboForm TaskBar Icon
2018-04-20 18:22 - 2013-09-25 11:19 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RoboForm
2018-04-20 18:04 - 2017-11-01 15:51 - 000000000 ____D C:\ProgramData\SWRoes
2018-04-18 12:05 - 2013-09-26 18:11 - 000000000 ____D C:\ProgramData\regid.1986-12.com.adobe
2018-04-18 06:48 - 2009-07-13 20:20 - 000000000 ____D C:\Windows\rescache
2018-04-18 06:06 - 2009-07-13 22:13 - 000782470 _____ C:\Windows\system32\PerfStringBackup.INI
2018-04-18 06:06 - 2009-07-13 20:20 - 000000000 ____D C:\Windows\inf
2018-04-18 05:54 - 2014-12-11 12:16 - 000000000 ____D C:\Windows\system32\appraiser
2018-04-17 21:01 - 2017-10-11 21:16 - 136971704 ____C (Microsoft Corporation) C:\Windows\system32\MRT-KB890830.exe
2018-04-17 21:01 - 2013-09-18 15:06 - 136971704 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2018-04-17 21:01 - 2013-09-18 15:06 - 000000000 ____D C:\Windows\system32\MRT
2018-04-16 15:41 - 2013-11-23 15:08 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2018-04-16 15:41 - 2013-11-23 15:05 - 000000000 ____D C:\Program Files\Microsoft Office 15
2018-04-16 15:13 - 2018-01-24 15:34 - 000000000 __RHD C:\Users\User\Creative Cloud Files
2018-04-16 11:50 - 2013-09-25 13:20 - 000000000 ____D C:\Program Files\Adobe
2018-04-16 11:50 - 2013-09-25 13:18 - 000000000 ____D C:\Program Files\Common Files\Adobe
2018-04-16 11:33 - 2013-09-25 10:46 - 000000000 ____D C:\Users\User\AppData\Roaming\Adobe
2018-04-16 11:33 - 2013-09-20 10:34 - 000000000 ____D C:\Users\User\Documents\Adobe
2018-04-16 10:45 - 2018-02-19 14:54 - 000001457 _____ C:\Users\User\Desktop\HomeRepairs.txt
2018-04-10 12:46 - 2018-03-13 15:46 - 000004458 _____ C:\Windows\System32\Tasks\Adobe Flash Player NPAPI Notifier
2018-04-10 12:46 - 2013-09-25 11:33 - 000804864 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2018-04-10 12:46 - 2013-09-25 11:33 - 000144896 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2018-04-10 12:46 - 2013-09-25 11:33 - 000004312 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2018-04-10 12:46 - 2013-09-25 11:33 - 000000000 ____D C:\Windows\system32\Macromed
2018-04-10 12:46 - 2013-09-25 10:50 - 000000000 ____D C:\Windows\SysWOW64\Macromed
2018-04-06 07:10 - 2016-10-26 14:15 - 000000000 ____D C:\Program Files (x86)\Mozilla Firefox
2018-04-06 07:10 - 2013-09-25 11:06 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2018-04-03 09:43 - 2013-11-08 22:30 - 000000000 ____D C:\ProgramData\Package Cache
2018-04-03 09:38 - 2017-01-12 14:50 - 000003554 _____ C:\Windows\System32\Tasks\GarminUpdaterTask
2018-04-03 09:38 - 2014-07-10 16:36 - 000000000 ____D C:\Program Files (x86)\Garmin
2018-03-29 10:37 - 2013-09-25 11:47 - 000000000 ____D C:\Users\User\AppData\Local\Intuit
2018-03-29 10:34 - 2013-09-18 15:04 - 000133344 _____ C:\Users\User\AppData\Local\GDIPFONTCACHEV1.DAT
2018-03-29 10:04 - 2013-09-25 11:38 - 000000095 _____ C:\Windows\QBChanUtil_Trigger.ini
2018-03-29 09:58 - 2013-09-25 11:39 - 000000000 ____D C:\ProgramData\Intuit
2018-03-29 09:58 - 2013-09-25 11:39 - 000000000 ____D C:\Program Files (x86)\Intuit
2018-03-29 09:56 - 2013-09-25 11:39 - 000000000 ____D C:\Users\Public\Documents\Intuit
2018-03-29 09:24 - 2018-02-28 18:48 - 000000000 ____D C:\Users\User\Desktop\Bills
2018-03-28 10:22 - 2014-04-05 21:51 - 000000000 ____D C:\Program Files (x86)\iExplorer
2018-03-28 10:20 - 2017-02-21 20:05 - 000000000 ____D C:\Users\User\AppData\Local\Deployment
==================== Files in the root of some directories =======
2014-04-06 17:33 - 2017-12-21 17:33 - 000000132 _____ () C:\Users\User\AppData\Roaming\Adobe PNG Format CS5 Prefs
2013-10-16 12:05 - 2017-10-07 17:06 - 000003072 _____ () C:\Users\User\AppData\Roaming\Bay Designer Prefsv3
2013-09-26 17:23 - 2013-09-26 17:23 - 000038441 _____ () C:\Users\User\AppData\Roaming\Comma Separated Values (Windows).ADR
2013-09-25 12:59 - 2018-03-21 20:07 - 000026192 _____ () C:\Users\User\AppData\Roaming\ProSelect_Prefs_41.xml
2013-09-18 11:24 - 2013-09-18 11:24 - 000000048 ____H () C:\Users\User\AppData\Roaming\system_ps3_settings.ini
2016-07-26 19:29 - 2016-09-03 14:51 - 000005120 _____ () C:\Users\User\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-02-14 15:06 - 2015-02-14 15:06 - 000628496 _____ (CMI Limited) C:\Users\User\AppData\Local\nstB93C.tmp
2014-06-21 15:54 - 2014-06-21 15:54 - 000000017 _____ () C:\Users\User\AppData\Local\resmon.resmoncfg
Some files in TEMP:
====================
2018-03-07 15:05 - 2018-03-07 15:05 - 001195040 _____ () C:\Users\User\AppData\Local\Temp\AirTTLB1Updater.exe
2018-03-07 15:13 - 2018-03-07 15:13 - 000462336 _____ (Dino Chiesa) C:\Users\User\AppData\Local\Temp\Ionic.Zip.dll
2018-03-29 09:57 - 2018-03-29 09:57 - 000111936 _____ (Microsoft Corporation) C:\Users\User\AppData\Local\Temp\MSIZAP.EXE
2018-03-07 15:05 - 2018-03-07 15:13 - 001345536 _____ (Profoto) C:\Users\User\AppData\Local\Temp\profoto.exe
2018-03-07 15:13 - 2018-03-07 15:13 - 000044544 _____ (Madwizard.org) C:\Users\User\AppData\Local\Temp\WinUSBNet.dll
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2018-04-18 06:40
==================== End of FRST.txt ============================
Addition:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 25.04.2018
Ran by [removed] (25-04-2018 11:36:32)
Running from C:\Users\[removed]\Downloads
Windows 7 Home Premium Service Pack 1 (X64) (2013-09-18 18:24:42)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-3209421979-1208344015-1759688515-500 - Administrator - Disabled)
Guest (S-1-5-21-3209421979-1208344015-1759688515-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3209421979-1208344015-1759688515-1002 - Limited - Enabled)
User (S-1-5-21-3209421979-1208344015-1759688515-1000 - Administrator - Enabled) => C:\Users\User
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Webroot SecureAnywhere (Enabled - Up to date) {4646A877-74EB-CD3B-8FDB-210DB94FA61A}
AS: Webroot SecureAnywhere (Enabled - Up to date) {FD274993-52D1-C2B5-B56B-1A7FC2C8ECA7}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
64 Bit HP CIO Components Installer (HKLM\…\{FF21C3E6-97FD-474F-9518-8DCBE94C2854}) (Version: 7.2.8 - Hewlett-Packard) Hidden
Adobe Acrobat Reader DC (HKLM-x32\…\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 18.011.20038 - Adobe Systems Incorporated)
Adobe AIR (HKLM-x32\…\Adobe AIR) (Version: 24.0.0.180 - Adobe Systems Incorporated)
Adobe Community Help (HKLM-x32\…\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 3.0.0.400 - Adobe Systems Incorporated)
Adobe Creative Cloud (HKLM-x32\…\Adobe Creative Cloud) (Version: 4.4.1.298 - Adobe Systems Incorporated)
Adobe Flash Player 29 ActiveX (HKLM-x32\…\Adobe Flash Player ActiveX) (Version: 29.0.0.140 - Adobe Systems Incorporated)
Adobe Flash Player 29 NPAPI (HKLM-x32\…\Adobe Flash Player NPAPI) (Version: 29.0.0.140 - Adobe Systems Incorporated)
Adobe Lightroom Classic CC (HKLM-x32\…\LTRM_7_3) (Version: 7.3 - Adobe Systems Incorporated)
Adobe Media Encoder CC 2018 (HKLM-x32\…\AME_12_1) (Version: 12.1.0 - Adobe Systems Incorporated)
Adobe Media Player (HKLM-x32\…\com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 1.8 - Adobe Systems Incorporated)
Adobe Photoshop CC 2018 (HKLM-x32\…\PHSP_19_1_3) (Version: 19.1.3 - Adobe Systems Incorporated)
Adobe Photoshop CS5 (HKLM-x32\…\{15FEDA5F-141C-4127-8D7E-B962D1742728}) (Version: 12.0 - Adobe Systems Incorporated)
Adobe Premiere Elements 11 (HKLM\…\{66CF1DF9-1715-4325-89BC-76B1CA2EE3BE}) (Version: 11.0 - Adobe Systems Incorporated) Hidden
Adobe Premiere Elements 11 (HKLM\…\PremElem110) (Version: 11.0 - Adobe Systems Incorporated)
ANT Drivers Installer x64 (HKLM\…\{3DE56A70-06BA-4863-8FBB-45D041AF0C7A}) (Version: 2.3.4 - Garmin Ltd or its subsidiaries) Hidden
Apple Application Support (32-bit) (HKLM-x32\…\{D2FE6376-E549-4F63-A2C5-CA24DA035DE4}) (Version: 5.6 - Apple Inc.)
Apple Application Support (64-bit) (HKLM\…\{5905C8CF-1C88-4478-A48E-4E458AD1BC7E}) (Version: 5.0.1 - Apple Inc.)
Apple Application Support (64-bit) (HKLM\…\{BB109E24-EE90-485B-A28B-ADDEFB40540B}) (Version: 5.6 - Apple Inc.)
Apple Mobile Device Support (HKLM\…\{0A596141-97D5-45FA-9281-98DFAF48D579}) (Version: 10.3.2.3 - Apple Inc.)
Apple Software Update (HKLM-x32\…\{52D87F32-70E4-4348-8148-C0B9F35B1314}) (Version: 2.3.0.177 - Apple Inc.)
Bay Designer (HKU\S-1-5-21-3209421979-1208344015-1759688515-1000\…\Bay Designer) (Version: Bay Designer 3.5.0 - Bay Photo Lab)
Bay ROES (HKLM-x32\…\{d4b70026-de82-45b4-b13e-4d0745a4f6ea}) (Version: 2.2.0 - SoftWorks Systems, Inc.)
Bonjour (HKLM\…\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
CCleaner (HKLM\…\CCleaner) (Version: 5.39 - Piriform)
Cybereason RansomFree 2.4.2.0 (HKLM-x32\…\{2A15E1FB-A1F5-4F11-B033-D8DB1E37C1E9}) (Version: 2.4.2.0 - Cybereason Inc.)
D3DX10 (HKLM-x32\…\{E09C4DB7-630C-4F06-A631-8EA7239923AF}) (Version: 15.4.2368.0902 - Microsoft) Hidden
Dell Dock (HKLM\…\{C73A3942-84C8-4597-9F9B-EE227DCBA758}) (Version: 2.0 - Stardock Corporation) Hidden
Dell Dock (HKLM-x32\…\Dell Dock) (Version: 2.0 - Stardock Corporation)
Dell Resource CD (HKLM-x32\…\{42929F0F-CE14-47AF-9FC7-FF297A603021}) (Version: 1.00.0000 - Dell Inc.)
Elements 11 Organizer (HKLM-x32\…\{D4D065E1-3ABF-41D0-B385-FC6F027F4D00}) (Version: 11.0 - Adobe Systems Incorporated) Hidden
Elevated Installer (HKLM-x32\…\{B7768089-44E1-4B51-9213-737959C689E5}) (Version: 6.3.0.0 - Garmin Ltd or its subsidiaries) Hidden
Epson Connect Printer Setup (HKLM-x32\…\{D9B1D51B-EB56-410D-AEB5-1CCFAC4B6C8C}) (Version: 1.4.0 - Seiko Epson Corporation)
Epson Customer Research Participation (HKLM\…\{B26449A6-6007-4460-B4FE-C4776115BCEA}) (Version: 1.82.0000 - Seiko Epson Corporation)
Epson Event Manager (HKLM-x32\…\{E244A764-EDD0-46B0-8689-661F6B28D9E5}) (Version: 3.10.0069 - Seiko Epson Corporation)
Epson FAX Utility (HKLM-x32\…\{0CBE6C93-CB2E-4378-91EE-12BE6D4E2E4A}) (Version: 2.04.00 - Seiko Epson Corporation)
Epson PC-FAX Driver (HKLM-x32\…\EPSON PC-FAX Driver 2) (Version: - Seiko Epson Corporation)
Epson Scan 2 (HKLM-x32\…\Epson Scan 2) (Version: - Seiko Epson Corporation)
EPSON Scan OCR Component (HKLM-x32\…\{563B99D8-8895-4E3E-AE8D-15BE8C05F1C1}) (Version: 3.00.02 - SEIKO EPSON Corp.)
EPSON Scan PDF Extensions (HKLM-x32\…\{F9956472-6E16-4F83-BF9A-F887EF4A45B7}) (Version: 1.03.0001 - SEIKO EPSON Corp.)
Epson Software Updater (HKLM-x32\…\{7BAC3F7A-B963-468E-982E-B5608A87408D}) (Version: 4.4.4 - SEIKO EPSON CORPORATION)
Epson WF-3720_4720_4730 Guide (HKLM-x32\…\UsersGuideEpson WF-3720_4720_4730 Guide_is1) (Version: 1.0 - Epson America, Inc.)
EPSON WF-4730 Series Printer Uninstall (HKLM\…\EPSON WF-4730 Series) (Version: - Seiko Epson Corporation)
EpsonNet Print (HKLM\…\{96ED1D58-440C-4345-8FEE-C4781366C67F}) (Version: 3.1.4.0 - SEIKO EPSON Corporation)
Garmin Express (HKLM-x32\…\{178D3388-656C-4326-BFFF-3607481CA5BB}) (Version: 6.3.0.0 - Garmin Ltd or its subsidiaries) Hidden
Garmin Express (HKLM-x32\…\{aa902576-9ab8-4371-98d1-efde885f775b}) (Version: 6.3.0.0 - Garmin Ltd or its subsidiaries)
Garmin Express Tray (HKLM-x32\…\{C6C8A534-050C-40E9-92FC-4D06A8A487C8}) (Version: 6.3.0.0 - Garmin Ltd or its subsidiaries) Hidden
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 65.0.3325.181 - Google Inc.)
Google Update Helper (HKLM-x32\…\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.7 - Google Inc.) Hidden
Google Update Helper (HKLM-x32\…\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.25.11 - Google Inc.) Hidden
Imagenomic Noiseware 4.2 Professional Plug-in (build 4205) (HKLM\…\ImagenomicNoisewareProPlugin) (Version: - )
Imagenomic Portraiture 2 Plug-in (build 2341) (HKLM\…\ImagenomicPortraiturePlugin) (Version: - )
iTunes (HKLM\…\{02F95875-9527-49CC-B32F-970ADAEBD1EF}) (Version: 12.6.2.20 - Apple Inc.)
Java 8 Update 144 (64-bit) (HKLM\…\{26A24AE4-039D-4CA4-87B4-2F64180144F0}) (Version: 8.0.1440.1 - Oracle Corporation)
Java 8 Update 144 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F32180144F0}) (Version: 8.0.1440.1 - Oracle Corporation)
Microsoft .NET Framework 4.7.1 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.7.02558 - Microsoft Corporation)
Microsoft LifeCam (HKLM\…\{5CE7E3F5-9803-4F32-AA89-2D8848A80109}) (Version: 3.60.253.0 - Microsoft Corporation)
Microsoft Mouse and Keyboard Center (HKLM\…\Microsoft Mouse and Keyboard Center) (Version: 2.3.188.0 - Microsoft Corporation)
Microsoft Office Home and Business 2010 (HKLM-x32\…\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\…\{95140000-0081-0409-0000-0000000FF1CE}) (Version: 14.0.6123.5001 - Microsoft Corporation)
Microsoft Outlook Social Connector Provider for Windows Live Messenger 32-bit (HKLM-x32\…\{95140000-007D-0409-0000-0000000FF1CE}) (Version: 14.0.5120.5000 - Microsoft Corporation)
Microsoft Publisher 2013 - en-us (HKLM\…\PublisherRetail - en-us) (Version: 15.0.5023.1000 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729 (HKLM\…\{4FFA2088-8317-3B14-93CD-4C699DB37843}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\…\{3C3D696B-0DB7-3C6D-A356-3DB8CE541918}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\…\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\…\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\…\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\…\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2017 Redistributable (x64) - 14.12.25810 (HKLM-x32\…\{e2ee15e2-a480-4bc5-bfb7-e9803d1d9823}) (Version: 14.12.25810.0 - Microsoft Corporation)
Microsoft Visual C++ 2017 Redistributable (x86) - 14.12.25810 (HKLM-x32\…\{56e11d69-7cc9-40a5-a4f9-8f6190c4d84d}) (Version: 14.12.25810.0 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\…\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Movie Maker (HKLM-x32\…\{38F03569-A636-4CF3-BDDE-032C8C251304}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Movie Maker (HKLM-x32\…\{DD67BE4B-7E62-4215-AFA3-F123A800A389}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Mozilla Firefox 59.0.2 (x64 en-US) (HKLM\…\Mozilla Firefox 59.0.2 (x64 en-US)) (Version: 59.0.2 - Mozilla)
Mozilla Maintenance Service (HKLM\…\MozillaMaintenanceService) (Version: 53.0.3 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\…\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\…\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
Nik Collection (HKLM-x32\…\Nik Collection) (Version: 1.2.11 - Google)
Office 15 Click-to-Run Extensibility Component (HKLM-x32\…\{90150000-008C-0000-0000-0000000FF1CE}) (Version: 15.0.5023.1000 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Licensing Component (HKLM\…\{90150000-008F-0000-1000-0000000FF1CE}) (Version: 15.0.5023.1000 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Localization Component (HKLM-x32\…\{90150000-008C-0409-0000-0000000FF1CE}) (Version: 15.0.5023.1000 - Microsoft Corporation) Hidden
Pandora (HKLM-x32\…\{CF73D1C4-4D78-890A-BF35-E275B96E678E}) (Version: 2.0.10 - Pandora Media, Inc) Hidden
Pandora (HKLM-x32\…\com.pandora.desktop.66F690BC77738C95E986E1B4A197193F28756A21.1) (Version: 2.0.10 - Pandora Media, Inc)
PDF Settings CS5 (HKLM-x32\…\{A78FE97A-C0C8-49CE-89D0-EDD524A17392}) (Version: 10.0 - Adobe Systems Incorporated) Hidden
Perfect Photo Suite 6 (HKLM-x32\…\{59679381-3F22-4A40-A7AD-890242D74DF4}) (Version: 6.0.0 - onOne Software)
Photodex Presenter (HKLM-x32\…\Photodex Presenter) (Version: - )
photoFXlab (HKLM-x32\…\photoFXlab) (Version: 1.2.8 - Topaz Labs)
PRE11 STI 64Installer (HKLM-x32\…\{B614E5FA-6DA4-45A1-845C-52F870240A89}) (Version: 11.0 - Adobe Systems Incorporated) Hidden
ProSelect (HKLM-x32\…\ProSelect 2012r1.10) (Version: - TimeExposure)
ProSelect (HKLM-x32\…\ProSelect 2012r2.3) (Version: - TimeExposure)
ProSelect (HKLM-x32\…\ProSelect 2013r1.7) (Version: - TimeExposure)
ProShow Gold (HKLM-x32\…\ProShow Gold) (Version: - )
QuickBooks (HKLM-x32\…\{48011BF6-E0BC-4B49-9DCA-C7144EF0C01E}) (Version: 28.0.4005.2806 - Intuit Inc.) Hidden
QuickBooks Pro 2018 (HKLM-x32\…\{92254DF4-E735-4B1F-9E61-D1EE5FAAC03D}) (Version: 28.0.4005.2806 - Intuit Inc.)
QuickBooks Runtime Redistributable (HKLM\…\{F2A4F809-2DE6-4D27-888B-4D2BB8DAF20E}) (Version: 1.00.0000 - Intuit Inc.)
QuickTime 7 (HKLM-x32\…\{FF59BD75-466A-4D5A-AD23-AAD87C5FD44C}) (Version: 7.79.80.95 - Apple Inc.)
Revo Uninstaller 2.0.3 (HKLM\…\{A28DBDA2-3CC7-4ADC-8BFE-66D7743C6C97}_is1) (Version: 2.0.3 - VS Revo Group, Ltd.)
RoboForm 8-4-9-9 (All Users) (HKLM-x32\…\AI RoboForm) (Version: 8-4-9-9 - Siber Systems)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\…\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version: - Microsoft)
Topaz Adjust 5 (HKLM-x32\…\Topaz Adjust 5) (Version: 5.1.0 - Topaz Labs, LLC)
Topaz B&W; Effects (HKLM-x32\…\Topaz BW Effects 2) (Version: 2.1.0 - Topaz Labs, LLC)
Topaz Clarity (HKLM-x32\…\Topaz Clarity) (Version: 1.0.0 - Topaz Labs, LLC)
Topaz Clean 3 (HKLM-x32\…\Topaz Clean 3) (Version: 3.1.0 - Topaz Labs, LLC)
Topaz DeJpeg 4 (HKLM-x32\…\Topaz DeJpeg 4) (Version: 4.0.2 - Topaz Labs, LLC)
Topaz DeNoise 5 (HKLM-x32\…\Topaz DeNoise 5) (Version: 5.1.0 - Topaz Labs, LLC)
Topaz Detail 3 (HKLM-x32\…\Topaz Detail 3) (Version: 3.2.0 - Topaz Labs, LLC)
Topaz Fusion Express 2 (HKLM-x32\…\Topaz Fusion Express 2) (Version: 2.1.3 - Topaz Labs, LLC)
Topaz InFocus (HKLM-x32\…\Topaz InFocus) (Version: 1.0.0 - Topaz Labs, LLC)
Topaz Lens Effects (HKLM-x32\…\Topaz Lens Effects) (Version: 1.2.0 - Topaz Labs, LLC)
Topaz ReMask 4 (HKLM-x32\…\Topaz ReMask 4) (Version: 4.0.0 - Topaz Labs, LLC)
Topaz ReStyle (HKLM-x32\…\Topaz ReStyle) (Version: 1.0.0 - Topaz Labs, LLC)
Topaz Simplify 4 (HKLM-x32\…\Topaz Simplify 4) (Version: 4.1.1 - Topaz Labs, LLC)
Topaz Star Effects (HKLM-x32\…\Topaz Star Effects) (Version: 1.1.0 - Topaz Labs, LLC)
Visual Studio Tools for the Office system 3.0 Runtime (HKLM-x32\…\Visual Studio Tools for the Office system 3.0 Runtime) (Version: - Microsoft Corporation)
Visual Studio Tools for the Office system 3.0 Runtime Service Pack 1 (KB949258) (HKLM-x32\…\{8FB53850-246A-3507-8ADE-0060093FFEA6}.KB949258) (Version: 1 - Microsoft Corporation)
Webroot SecureAnywhere (HKLM-x32\…\WRUNINST) (Version: 9.0.19.43 - Webroot)
Windows Driver Package - Dynastream Innovations, Inc. ANT LibUSB Drivers (04/11/2012 1.2.40.201) (HKLM\…\F9D2A789F9CFF8CEC36B544F53877C80F1F73C46) (Version: 04/11/2012 1.2.40.201 - Dynastream Innovations, Inc.)
Windows Driver Package - Silicon Labs Software (DSI_SiUSBXp_3_1) USB (02/06/2007 3.1) (HKLM\…\D1506E0025B5A3F9EB8270FE81C1EEDD9388B8A2) (Version: 02/06/2007 3.1 - Silicon Labs Software)
Windows Live Essentials (HKLM-x32\…\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation)
WinPatrol (HKLM-x32\…\{6A206A04-6BC1-411B-AA04-4E52EDEEADF2}) (Version: 33.6.2015.18 - Ruiware)
WinX YouTube Downloader 3.2.0 (HKLM-x32\…\WinX YouTube Downloader_is1) (Version: - Digiarty Software, Inc.)
WorkStream DS 2.6 (HKLM-x32\…\WorkStream DS_2.6) (Version: 2.6b - ZBE Inc.)
Zoom (HKU\S-1-5-21-3209421979-1208344015-1759688515-1000\…\ZoomUMX) (Version: 4.1 - Zoom Video Communications, Inc.)
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-3209421979-1208344015-1759688515-1000_Classes\CLSID\{e8c77137-e224-5791-b6e9-ff0305797a13}\InprocServer32 -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems)
ShellIconOverlayIdentifiers: [ AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2018-02-10] ()
ShellIconOverlayIdentifiers: [ AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2018-02-10] ()
ShellIconOverlayIdentifiers: [ AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2018-02-10] ()
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
ContextMenuHandlers1: [AccExt] -> {2A118EB5-5797-4F5E-8B3D-F4ECBA3C98E4} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2018-02-10] ()
ContextMenuHandlers1: [WRShellExt] -> {69D72956-317C-44bd-B369-8E44D4EF9802} => C:\Windows\system32\WRusr.dll [2018-04-25] (Webroot)
ContextMenuHandlers6: [AccExt] -> {2A118EB5-5797-4F5E-8B3D-F4ECBA3C98E4} => C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll [2018-02-10] ()
ContextMenuHandlers6: [WRShellExt] -> {69D72956-317C-44bd-B369-8E44D4EF9802} => C:\Windows\system32\WRusr.dll [2018-04-25] (Webroot)
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {075381CD-F4A0-4169-968C-78C37E2DB1B2} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2017-12-12] (Microsoft Corporation)
Task: {13F4C163-8C74-45B4-8404-BB9B5F472B9D} - System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2014-03-19] (Microsoft Corporation)
Task: {5207C200-6EE5-4EE1-8722-B3E103270F29} - System32\Tasks\GarminUpdaterTask => C:\Program Files (x86)\Garmin\Express SelfUpdater\ExpressSelfUpdater.exe [2018-03-27] ()
Task: {540A009C-F90F-40EF-A4DE-546EF2448693} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2018-01-09] (Piriform Ltd)
Task: {5A90B5AA-8DED-430F-9834-ED5C528A7788} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-31] (Google Inc.)
Task: {71A3C6B8-5511-496B-8396-12CC4033B1F5} - System32\Tasks\AdobeGCInvoker-1.0-User-PC-User => C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe [2018-01-05] (Adobe Systems, Incorporated)
Task: {73BAF2D8-E509-456C-B265-7114AF541F33} - System32\Tasks\Cybereason RansomFree Autostart => C:\Program Files (x86)\Cybereason\RansomFree\CybereasonRansomFree.exe [2017-11-20] (Cybereason)
Task: {78376AA0-AF44-4B2F-9E74-ECE8CA11ECE9} - System32\Tasks\QBScheduledReport => C:\Program Files (x86)\Common Files\Intuit\QuickBooks\ScheduledReports\ScheduledReports.Scheduler.exe [2018-02-16] (Intuit Inc.)
Task: {7B41E111-7D46-4923-9114-99EA12F54BC6} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office 15\root\Office15\msoia.exe [2017-03-14] (Microsoft Corporation)
Task: {8C770CDF-1E99-411E-B2B5-9A054A43B8AB} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2017-02-14] (Apple Inc.)
Task: {A8C91D9E-5A40-4BBC-A3CB-DFF17A637C2A} - System32\Tasks\Open URL by RoboForm => C:\Windows\system32\rundll32.exe url.dll,FileProtocolHandler "hxxps://www.roboform.com/test-pass.html?aaa=KICMIMMJHMIMIMMMIMMMCNIMNJHMLJCNLMMMIMGMCNNJIMLMLJCNKMJJIMIMOJMMOMOMLJOMJJMJJNJICMHMCNLMCNGMFMOMOMCNPMCNGMJMPMPMFMJMCNOMCNIMJMPMOMCNNMJNPICMOMFMEKMICNJJCKFMNMMMNMKMJNHICMMJBJKJLIMJJNBJCMKKMIKJNIJNKJCMJNNICMJNDJCMKJBJJNMJCMPMFMP (the data entry has 40 more characters).
Task: {B0074BBD-C86F-4E4A-979B-A5912123E34E} - System32\Tasks\Microsoft_MKC_Logon_Task_ipoint.exe => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2014-03-19] (Microsoft Corporation)
Task: {C5981497-9135-4D34-B3ED-FB133A304E8A} - System32\Tasks\{E0B33BC4-A0DF-40DE-A600-74E53B65581B} => C:\Windows\system32\pcalua.exe -a "C:\Users\User\Downloads\Perfect_Photo_Suite_6\Perfect Photo Suite 6\setup.exe" -d "C:\Users\User\Downloads\Perfect_Photo_Suite_6\Perfect Photo Suite 6"
Task: {C8628CDE-AA67-44A5-A0A2-79384B800DA5} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2017-12-12] (Microsoft Corporation)
Task: {CF210F42-2AB7-4F54-A8D5-11E5E22D839C} - System32\Tasks\Run RoboForm TaskBar Icon => C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe [2018-04-20] (Siber Systems)
Task: {D388BC3F-7899-4D9B-83AC-247490C08933} - System32\Tasks\Adobe Flash Player NPAPI Notifier => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_29_0_0_140_Plugin.exe [2018-04-10] (Adobe Systems Incorporated)
Task: {DA5BE402-06F0-43D7-881F-FAD7777DD340} - System32\Tasks\Microsoft_Hardware_Launch_itype_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2014-03-19] (Microsoft Corporation)
Task: {DC769CDB-3E12-47EC-BA70-B455E7B07892} - System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\mousekeyboardcenter.exe [2014-03-19] (Microsoft)
Task: {DC8B56EE-4BAF-40E0-AA1C-F0331E88AEB7} - System32\Tasks\EPSON WF-4730 Series Update {08FA9C7A-10A1-4A59-87F7-A6D3F0CBD42A} => C:\Windows\system32\spool\DRIVERS\x64\3\E_YTSQDE.EXE [2013-11-21] (SEIKO EPSON CORPORATION)
Task: {EA59DE0B-4AFB-4E91-896A-50A6E11EC2A4} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-31] (Google Inc.)
Task: {EB65C747-B24E-44CB-95B3-A2AB1DB68219} - System32\Tasks\{702EB8BB-8FE7-4D29-A30B-CB50BB694BCD} => C:\Windows\system32\pcalua.exe -a C:\Users\User\Downloads\LabelMakerInstaller.exe -d C:\Users\User\Downloads
Task: {EBAC45B5-B78F-4C25-80A8-976DED410E98} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office 15\root\Office15\msoia.exe [2017-03-14] (Microsoft Corporation)
Task: {ED3EDF46-89E6-4B53-A00B-AE52683487FF} - System32\Tasks\AdobeAAMUpdater-1.0-User-PC-User => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2016-07-01] (Adobe Systems Incorporated)
Task: {ED421B5D-4E78-4062-BE4C-56F42596E717} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [2018-01-09] (Piriform Ltd)
Task: {F3C2B207-FB61-4027-AAB5-190DFA1924B5} - System32\Tasks\Cybereason RansomFree Keepalive => C:\Program Files (x86)\Cybereason\RansomFree\CybereasonRansomFree.exe [2017-11-20] (Cybereason)
Task: {F5AB5BC4-C1A6-48CC-9D00-124E3F1F20F5} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2018-04-10] (Adobe Systems Incorporated)
Task: {F8A03321-276B-4CAA-BE9E-502625953AA3} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2018-02-09] (Adobe Systems Incorporated)
Task: {FB148E2C-BC7A-4B41-9424-F6D9EA4AD6FD} - System32\Tasks\Microsoft_MKC_Logon_Task_itype.exe => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2014-03-19] (Microsoft Corporation)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\EPSON WF-4730 Series Update {08FA9C7A-10A1-4A59-87F7-A6D3F0CBD42A}.job => C:\Windows\system32\spool\DRIVERS\x64\3\E_YTSQDE.EXE:/EXE:{08FA9C7A-10A1-4A59-87F7-A6D3F0CBD42A} /F:UpdateSYSTEMĊSearches for EPSON software updates, and notifies you when updates are available.If this task is disabled or stopped, your EPSON software will not be automatically kept up to date.Thi
==================== Shortcuts & WMI ========================
(The entries could be listed to be restored or removed.)
ShortcutWithArgument: C:\Users\User\Desktop\Misc\Bay Photo Emerge.lnk -> C:\Windows\SysWOW64\javaws.exe (Oracle Corporation) -> -localfile -J-Djnlp.application.href=hxxp://www.roeslaunch.com/ROES/labs/BayPhotoEmerge/launch.jnlp "C:\Users\Sonja\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\47\2bfd02ef-3ab04fb1"
ShortcutWithArgument: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Courses - IPS Mastermind -.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> –profile-directory=Default –app-id=kkpnhhakakmcnmcohbnmpkeldllfkadl
ShortcutWithArgument: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BWC Photo Imaging ROES\BWC Photo Imaging ROES.lnk -> C:\Program Files (x86)\Java\jre1.8.0_144\bin\javaws.exe (Oracle Corporation) -> -localfile -J-Djnlp.application.href=hxxp://www.roeslaunch.com/ROES/labs/BWC/launch.jnlp "C:\Users\User\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\46\4f49a7ee-2fc2f0b0"
ShortcutWithArgument: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bay Photo Emerge\Bay Photo Emerge.lnk -> C:\Program Files (x86)\Java\jre1.8.0_144\bin\javaws.exe (Oracle Corporation) -> -localfile -J-Djnlp.application.href=hxxp://www.roeslaunch.com/ROES/labs/BayPhotoEmerge/launch.jnlp "C:\Users\User\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\47\2bfd02ef-75c80408"
ShortcutWithArgument: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bay Photo Economy\Bay Photo Economy.lnk -> C:\Program Files (x86)\Java\jre1.8.0_144\bin\javaws.exe (Oracle Corporation) -> -localfile -J-Djnlp.application.href=hxxp://www.roeslaunch.com/ROES/labs/BayPhotoEconomy/launch.jnlp "C:\Users\User\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\40\6599c28-675e2b74"
ShortcutWithArgument: C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ACI Volume\ACI Volume.lnk -> C:\Windows\SysWOW64\javaws.exe (Oracle Corporation) -> -localfile -J-Djnlp.application.href=hxxp://www.roeslaunch.com/ROES/labs/ACIUC/launch.jnlp "C:\Users\User\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\53\15c31035-3eb0274a"
==================== Loaded Modules (Whitelisted) ==============
2017-07-13 20:50 - 2017-07-13 20:50 - 001354040 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2016-09-01 18:12 - 2016-09-01 18:12 - 000092472 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2014-03-19 09:22 - 2017-01-17 04:25 - 000117440 _____ () C:\Program Files\Microsoft Office 15\ClientX64\ApiClient.dll
2018-02-10 02:12 - 2018-02-10 02:12 - 000614856 _____ () C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll
2017-03-21 09:31 - 2017-01-31 05:34 - 008909512 _____ () C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\1033\GrooveIntlResource.dll
2018-02-06 09:57 - 2018-02-06 09:57 - 000472576 _____ () C:\Windows\assembly\NativeImages_v2.0.50727_64\VistaBridgeLibrary\4a45bc35f76dfb0e91194f9388dfc2c4\VistaBridgeLibrary.ni.dll
2013-09-25 17:46 - 2013-09-25 17:46 - 000181312 _____ () C:\Program Files (x86)\Photodex\ProShowGold\ScsiAccess.exe
2018-03-22 15:41 - 2018-03-19 23:00 - 004435288 _____ () C:\Program Files (x86)\Google\Chrome\Application\65.0.3325.181\libglesv2.dll
2018-03-22 15:41 - 2018-03-19 23:00 - 000099672 _____ () C:\Program Files (x86)\Google\Chrome\Application\65.0.3325.181\libegl.dll
2017-05-08 10:35 - 2017-05-08 10:35 - 000325632 _____ () C:\Program Files (x86)\Garmin\Device Interaction Service\GpsImgWrapper.dll
2018-03-27 16:08 - 2018-03-27 16:08 - 000073216 _____ () C:\Program Files (x86)\Garmin\Device Interaction Service\FixBootSector.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
AlternateDataStreams: C:\Windows:nlsPreferences [642]
==================== Safe Mode (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WRkrn => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WRSVC => ""="Service"
==================== Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
==================== Hosts content: ===============================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-13 19:34 - 2009-06-10 14:00 - 000000824 _____ C:\Windows\system32\Drivers\etc\hosts
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-3209421979-1208344015-1759688515-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\User\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
MSCONFIG\startupreg: Adobe Creative Cloud => "C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe" –showwindow=false –onOSstartup=true
MSCONFIG\startupreg: AdobeAAMUpdater-1.0 => "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
MSCONFIG\startupreg: AdobeBridge =>
MSCONFIG\startupreg: AdobeGCInvoker-1.0 => "C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGCInvokerUtility.exe"
MSCONFIG\startupreg: EEventManager => "C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe"
MSCONFIG\startupreg: EPLTarget =>
MSCONFIG\startupreg: FUFAXRCV => "C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXRCV.exe"
MSCONFIG\startupreg: FUFAXSTM => "C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe"
MSCONFIG\startupreg: GarminExpressTrayApp => "C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe"
MSCONFIG\startupreg: iTunesHelper => "C:\Program Files\iTunes\iTunesHelper.exe"
MSCONFIG\startupreg: Steam => "I:\Steam\steam.exe" -silent
MSCONFIG\startupreg: WinPatrol => C:\Program Files (x86)\Ruiware\WinPatrol\winpatrol.exe
MSCONFIG\startupreg: Zoom =>
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [{A46197A4-08DF-4C24-B80F-019B55CC35AB}] => (Allow) C:\Program Files (x86)\HP\Digital Imaging\{7E0E61CC-1C99-429D-BEA7-C4DD5B898D2A}\setup\hpznui40.exe
FirewallRules: [{15758C4B-DDCD-4AD6-B03A-DEEB1E951CDE}] => (Allow) C:\Program Files (x86)\Microsoft LifeCam\LifeCam.exe
FirewallRules: [{CA12942C-1387-4F9B-A318-2CC4ED2FE5BA}] => (Allow) C:\Program Files (x86)\Microsoft LifeCam\LifeCam.exe
FirewallRules: [{A949D16D-9597-434D-8FF7-86E9A6014306}] => (Allow) C:\Program Files (x86)\Microsoft LifeCam\LifeEnC2.exe
FirewallRules: [{7F1ACA64-19B1-44B8-A09E-040293DD3548}] => (Allow) C:\Program Files (x86)\Microsoft LifeCam\LifeEnC2.exe
FirewallRules: [{B352B476-31A4-4213-924B-93557279014A}] => (Allow) C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe
FirewallRules: [{ABF910BA-568C-4F93-86CF-832753378D14}] => (Allow) C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe
FirewallRules: [{F4255465-7345-412B-9AAC-4759A6919584}] => (Allow) C:\Program Files (x86)\Microsoft LifeCam\LifeTray.exe
FirewallRules: [{A3B8F4A2-7DA3-4654-A474-84482A27561F}] => (Allow) C:\Program Files (x86)\Microsoft LifeCam\LifeTray.exe
FirewallRules: [{A3A5E703-E00F-40C6-BE4E-4B91FA2515B3}] => (Allow) C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe
FirewallRules: [{F8411077-9917-4B0E-AC47-6C5AF69871FA}] => (Allow) C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe
FirewallRules: [{B6C2A9A5-593F-46F4-A1DD-F6319117D0E2}] => (Allow) D:\Common\EpsonNet Setup\ENEasyApp.exe
FirewallRules: [{E99B63F9-DCAB-4214-B1D6-C168758E8513}] => (Allow) D:\Common\EpsonNet Setup\ENEasyApp.exe
FirewallRules: [TCP Query User{C9976C26-4E2C-4B42-8151-60F2D4DFEAA0}C:\program files (x86)\epson software\event manager\eeventmanager.exe] => (Allow) C:\program files (x86)\epson software\event manager\eeventmanager.exe
FirewallRules: [UDP Query User{DAF413C7-E658-44AA-9F8D-24DF8EEA9461}C:\program files (x86)\epson software\event manager\eeventmanager.exe] => (Allow) C:\program files (x86)\epson software\event manager\eeventmanager.exe
FirewallRules: [{26989D7E-A798-4FD7-A500-42EF70C4D1D8}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{3FBCA7B4-0782-4A5D-AD0A-EE657D7C5B45}] => (Allow) LPort=2869
FirewallRules: [{FA55F516-C51F-4163-926E-53751138D16D}] => (Allow) LPort=1900
FirewallRules: [TCP Query User{AC250122-8E50-4EEE-9E1F-80A402F8A8D0}C:\program files (x86)\timeexposure\proselect\proselect.exe] => (Allow) C:\program files (x86)\timeexposure\proselect\proselect.exe
FirewallRules: [UDP Query User{4B9153C9-03AB-4EA2-B894-FCDB7DAD26E3}C:\program files (x86)\timeexposure\proselect\proselect.exe] => (Allow) C:\program files (x86)\timeexposure\proselect\proselect.exe
FirewallRules: [TCP Query User{F5321623-EC43-4198-B820-70788C07ACCA}C:\program files (x86)\fathomfocus\fathomfocus.exe] => (Allow) C:\program files (x86)\fathomfocus\fathomfocus.exe
FirewallRules: [UDP Query User{C3126754-2FFA-486D-84D8-A722C262E773}C:\program files (x86)\fathomfocus\fathomfocus.exe] => (Allow) C:\program files (x86)\fathomfocus\fathomfocus.exe
FirewallRules: [{20324F16-9C7D-4FD2-85DF-E611BEC959BF}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{6A2B27F0-2E82-42F7-A436-1E6437F4A5BE}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{752D3596-9911-4C24-A3B9-8F8ED1E62479}C:\users\user\downloads\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => (Block) C:\users\user\downloads\runtime\jre-x64\1.8.0_25\bin\javaw.exe
FirewallRules: [UDP Query User{4E58888D-7B8E-4850-AFB5-420F76C800A8}C:\users\user\downloads\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => (Block) C:\users\user\downloads\runtime\jre-x64\1.8.0_25\bin\javaw.exe
FirewallRules: [TCP Query User{99ED966F-B016-462C-89EF-E67834FA5D7F}C:\program files (x86)\workstream ds\workstreamds.exe] => (Allow) C:\program files (x86)\workstream ds\workstreamds.exe
FirewallRules: [UDP Query User{C14A8D2D-92AE-4579-84B4-73F44244B55E}C:\program files (x86)\workstream ds\workstreamds.exe] => (Allow) C:\program files (x86)\workstream ds\workstreamds.exe
FirewallRules: [TCP Query User{42AFE88E-7E32-47F7-BAFF-C39F5C692CDB}C:\program files (x86)\mozilla firefox\firefox.exe] => (Allow) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [UDP Query User{8DF2B313-D1E1-4CE7-A4C6-75A1530C9A3C}C:\program files (x86)\mozilla firefox\firefox.exe] => (Allow) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [{D89AAA18-AD18-49F6-955A-83F475DACECB}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{87120CB3-937E-40B5-8D87-0AECCA52BF2E}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{FCE4CFF4-7876-49F3-96F9-7779C161815B}C:\program files\java\jre1.8.0_92\bin\javaw.exe] => (Block) C:\program files\java\jre1.8.0_92\bin\javaw.exe
FirewallRules: [UDP Query User{44598391-F251-49EB-BB84-7730E8D7DDAF}C:\program files\java\jre1.8.0_92\bin\javaw.exe] => (Block) C:\program files\java\jre1.8.0_92\bin\javaw.exe
FirewallRules: [{0CFB9BC1-077C-4039-8A48-EEE7C207E741}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{4640338B-DC88-4AF9-9DD1-69844B7FECB2}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{A267E07A-582B-4142-BA27-AFD8FE690AB7}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{E49A72EC-82A7-48BB-89F7-A9672EE57F25}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{31173CCC-3A75-4E89-8357-E6840D4E4093}] => (Allow) I:\Steam\Steam.exe
FirewallRules: [{C60329E2-1867-4D85-98F4-F442AED73563}] => (Allow) I:\Steam\Steam.exe
FirewallRules: [{66756DC3-9C63-4967-9949-31860A3AAACC}] => (Allow) I:\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [{31143BC3-639C-4A8F-B117-EAFD2BD81376}] => (Allow) I:\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [{20B05A03-35AC-43DF-A07C-3FF9A9E50E1F}] => (Allow) C:\Program Files\iTunes\iTunes.exe
FirewallRules: [{688F0274-7817-43DD-AF43-329AECF6511A}] => (Allow) D:\Network\EpsonNetSetup\ENEasyApp.exe
FirewallRules: [{773E6B5D-BCA7-47BE-855E-DE58F01F69AD}] => (Allow) D:\Network\EpsonNetSetup\ENEasyApp.exe
FirewallRules: [{14709830-C8B1-4200-854B-294DEF21EAA9}] => (Allow) C:\Program Files (x86)\EPSON Software\ECPrinterSetup\ENPApp.exe
FirewallRules: [{DBF6D7FD-3742-4E84-9E9B-4A66EA332653}] => (Allow) C:\Program Files (x86)\EPSON Software\ECPrinterSetup\ENPApp.exe
FirewallRules: [{B72688BA-B572-41F3-A48A-D997ED225DD0}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Restore Points =========================
27-03-2018 07:54:26 Windows Update
30-03-2018 08:18:35 Windows Update
01-04-2018 03:00:10 Windows Update
03-04-2018 09:35:50 Garmin Express
06-04-2018 07:23:52 Windows Update
06-04-2018 21:07:11 Windows Update
10-04-2018 07:53:49 Windows Update
10-04-2018 22:31:41 Windows Update
11-04-2018 21:22:05 Windows Update
17-04-2018 09:51:07 Windows Update
17-04-2018 20:58:24 Windows Update
24-04-2018 07:48:30 Windows Update
==================== Faulty Device Manager Devices =============
Name: StorLib bus (virtual storages support)
Description: StorLib bus (virtual storages support)
Class Guid: {1378e71b-ab4d-4348-af26-cba56b12969e}
Manufacturer: EldoS Corporation
Service: cbfs3
Problem: : Windows cannot start this hardware device because its configuration information (in the registry) is incomplete or damaged. (Code 19)
Resolution: A registry problem was detected.
This can occur when more than one service is defined for a device, if there is a failure opening the service subkey, or if the driver name cannot be obtained from the service subkey. Try these options:
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
Click "Uninstall", and then click "Scan for hardware changes" to load a usable driver.
==================== Event log errors: =========================
Application errors:
==================
Error: (04/24/2018 01:05:19 PM) (Source: QuickBooks) (EventID: 4) (User: )
Description: An unexpected error has occured in "QuickBooks Desktop Pro 2018":
Verify Rebuild: PriceRules took 0.001155 milliseconds. ErrorFound:0
Error: (04/24/2018 01:05:19 PM) (Source: QuickBooks) (EventID: 4) (User: )
Description: An unexpected error has occured in "QuickBooks Desktop Pro 2018":
Verify Rebuild: Barcodes took 6.010780 milliseconds. ErrorFound:0
Error: (04/24/2018 01:05:19 PM) (Source: QuickBooks) (EventID: 4) (User: )
Description: An unexpected error has occured in "QuickBooks Desktop Pro 2018":
Verify Rebuild: SerialLotNumberRules took 0.001155 milliseconds. ErrorFound:0
Error: (04/24/2018 01:05:19 PM) (Source: QuickBooks) (EventID: 4) (User: )
Description: An unexpected error has occured in "QuickBooks Desktop Pro 2018":
Verify Rebuild: EncryptionKeyTable took 315.002776 milliseconds. ErrorFound:0
Error: (04/24/2018 01:05:19 PM) (Source: QuickBooks) (EventID: 4) (User: )
Description: An unexpected error has occured in "QuickBooks Desktop Pro 2018":
Verify Rebuild: Permissions took 248.068843 milliseconds. ErrorFound:0
Error: (04/24/2018 01:05:18 PM) (Source: QuickBooks) (EventID: 4) (User: )
Description: An unexpected error has occured in "QuickBooks Desktop Pro 2018":
Verify Rebuild: EmployeeAddresses took 0.088926 milliseconds. ErrorFound:0
Error: (04/24/2018 01:05:18 PM) (Source: QuickBooks) (EventID: 4) (User: )
Description: An unexpected error has occured in "QuickBooks Desktop Pro 2018":
Verify Rebuild: NameContacts took 2.801746 milliseconds. ErrorFound:0
Error: (04/24/2018 01:05:18 PM) (Source: QuickBooks) (EventID: 4) (User: )
Description: An unexpected error has occured in "QuickBooks Desktop Pro 2018":
Verify Rebuild: LeadCenter took 8.208523 milliseconds. ErrorFound:0
System errors:
=============
Error: (04/25/2018 10:38:02 AM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: The following fatal alert was received: 20.
Error: (04/25/2018 07:52:55 AM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: The Windows Update service hung on starting.
Error: (04/25/2018 07:46:01 AM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load:
MBAMSwissArmy
Error: (04/25/2018 07:44:06 AM) (Source: Microsoft-Windows-Kernel-General) (EventID: 5) (User: NT AUTHORITY)
Description: 0x8000002a36\SystemRoot\System32\Config\SOFTWARE
Error: (04/24/2018 08:40:54 AM) (Source: Microsoft-Windows-Kernel-General) (EventID: 5) (User: NT AUTHORITY)
Description: 0x8000002a171\??\Volume{30b17fcc-208c-11e3-b45c-806e6f6e6963}\System Volume Information\SPP\SppCbsHiveStore\{cd42efe1-f6f1-427c-b004-033192c625a4}{149C8C7C-4F57-42F1-8014-F4009A0E4FCC}
Error: (04/24/2018 07:38:47 AM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: The Windows Update service hung on starting.
Error: (04/24/2018 07:33:19 AM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load:
MBAMSwissArmy
Error: (04/24/2018 07:31:42 AM) (Source: Microsoft-Windows-Kernel-General) (EventID: 5) (User: NT AUTHORITY)
Description: 0x8000002a36\SystemRoot\System32\Config\SOFTWARE
Windows Defender:
===================================
Date: 2016-06-15 03:29:56.945
Description:
Windows Defender scan has been stopped before completion.
Scan ID:{1C590E9D-CBE7-486A-8331-0B591AAD9E6D}
Scan Type:AntiSpyware
Scan Parameters:Quick Scan
CodeIntegrity:
===================================
Date: 2016-09-30 06:15:45.892
Description:
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\aswKbd.sys because the set of per-page image hashes could not be found on the system.
Date: 2016-09-30 06:15:45.736
Description:
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\aswSnx.sys because the set of per-page image hashes could not be found on the system.
Date: 2016-09-29 10:57:48.359
Description:
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\aswKbd.sys because the set of per-page image hashes could not be found on the system.
Date: 2016-09-29 10:57:47.875
Description:
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\aswSnx.sys because the set of per-page image hashes could not be found on the system.
Date: 2016-09-28 08:24:20.534
Description:
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\aswKbd.sys because the set of per-page image hashes could not be found on the system.
Date: 2016-09-28 08:24:20.034
Description:
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\aswSnx.sys because the set of per-page image hashes could not be found on the system.
Date: 2016-09-27 05:49:09.293
Description:
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\aswKbd.sys because the set of per-page image hashes could not be found on the system.
Date: 2016-09-27 05:49:09.184
Description:
Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\aswSnx.sys because the set of per-page image hashes could not be found on the system.
==================== Memory info ===========================
Processor: Intel(R) Core(TM) i5 CPU 750 @ 2.67GHz
Percentage of memory in use: 36%
Total physical RAM: 6103.12 MB
Available physical RAM: 3846.38 MB
Total Virtual: 12204.4 MB
Available Virtual: 8987.67 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:1862.92 GB) (Free:574.27 GB) NTFS
\\?\Volume{30b17fcb-208c-11e3-b45c-806e6f6e6963}\ (System Reserved) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 1863 GB) (Disk ID: 3A837E0F)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=1862.9 GB) - (Type=07 NTFS)
==================== End of Addition.txt ============================