Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- FRST
- [spoiler]Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 08-07-2017
- Ran by Qwerty (administrator) on QWERTY-PC (09-07-2017 16:31:46)
- Running from C:\Users\Qwerty\Downloads
- Loaded Profiles: Qwerty (Available Profiles: Qwerty & DefaultAppPool)
- Platform: Windows 7 Ultimate Service Pack 1 (X64) Language: English (United States)
- Internet Explorer Version 11 (Default browser: Chrome)
- Boot Mode: Normal
- Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
- ==================== Processes (Whitelisted) =================
- (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
- (Intel Corporation) C:\Windows\System32\igfxCUIService.exe
- (Stardock Corporation) C:\Program Files (x86)\Stardock\WindowBlinds\WBSrv.exe
- (Stardock Software, Inc) C:\Program Files (x86)\Stardock\WindowBlinds\WBCore.exe
- (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
- (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
- (Windows (R) Win 7 DDK provider) C:\Program Files (x86)\Bluetooth Suite\AdminService.exe
- (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
- (FileZilla Project) C:\Program Files (x86)\FileZilla Server\FileZilla Server.exe
- (Qualcomm®Atheros®) C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe
- (AnchorFree Inc.) C:\Program Files (x86)\Hotspot Shield\bin\cmw_srv.exe
- (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
- (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
- (Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
- (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
- (The SABnzbd-team) C:\Program Files\SABnzbd\SABnzbd.exe
- (Cerulean Studios) C:\Program Files (x86)\Trillian56\trillian.exe
- (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
- (Alexandr Irza) C:\Program Files (x86)\Volume2\Volume2.exe
- (VMware, Inc.) C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe
- () C:\Users\Qwerty\Downloads\d3d\D3DOverrider.exe
- (Qualcomm Atheros) C:\Program Files (x86)\Bluetooth Suite\BtTray.exe
- () C:\Program Files (x86)\NETGEAR\A6210\NetgearSwitchUSB.exe
- (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
- () C:\Windows\SysWOW64\PnkBstrA.exe
- () C:\Windows\SysWOW64\PnkBstrB.exe
- (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
- (Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
- (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
- (Tenorshare Co,Ltd) C:\Program Files (x86)\ReiBoot\TenorshareReibootService.exe
- () C:\Program Files (x86)\TVMOBiLi\bin\tvMobiliService.exe
- (VMware, Inc.) C:\Windows\SysWOW64\vmnat.exe
- (Azzouzi Software) C:\Program Files (x86)\WiFiCreator\WifiCreatorSvc.exe
- (Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
- (VMware, Inc.) C:\Windows\SysWOW64\vmnetdhcp.exe
- (Microsoft Corporation) C:\Windows\System32\alg.exe
- (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
- (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
- (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_w32.exe
- (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_x64.exe
- (Intel Corporation) C:\Windows\System32\igfxEM.exe
- (Intel Corporation) C:\Windows\System32\igfxHK.exe
- () C:\Program Files\WALTR2\x86\WALTR2Service.exe
- (Bandicam Company) C:\Program Files (x86)\Bandicam\bdcam64.bin
- (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe
- (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe
- (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe
- (AVAST Software s.r.o.) C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe
- (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- (Skype Technologies) C:\Program Files (x86)\Skype\Browser\SkypeBrowserHost.exe
- (Skype Technologies) C:\Program Files (x86)\Skype\Browser\SkypeBrowserHost.exe
- (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- (Microsoft Corporation) C:\Windows\System32\dllhost.exe
- ==================== Registry (Whitelisted) ====================
- (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
- HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [213832 2017-07-02] (AVAST Software)
- HKLM\...\Run: [Malwarebytes TrayApp] => C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe [3146704 2017-05-09] (Malwarebytes)
- HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [303928 2017-05-09] (Apple Inc.)
- HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2017-03-15] (Oracle Corporation)
- HKLM-x32\...\Run: [Volume2] => C:\Program Files (x86)\Volume2\Volume2.exe [4797440 2017-03-28] (Alexandr Irza)
- HKLM-x32\...\Run: [vmware-tray.exe] => C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe [104128 2016-04-14] (VMware, Inc.)
- HKLM-x32\...\Run: [D3DOverrider] => C:\Users\Qwerty\Downloads\d3d\D3DOverriderWrapper.exe [40960 2017-07-09] ()
- HKLM-x32\...\Run: [OfficeUpdate] => C:\Users\Qwerty\AppData\Local\Temp\prp\sqb.exe [750320 2012-01-29] (AutoIt Team) <==== ATTENTION
- HKLM-x32\...\Run: [lwsUpdate] => C:\Users\Qwerty\AppData\Roaming\tws\hkg.exe [750320 2012-01-29] (AutoIt Team)
- Winlogon\Notify\igfxcui: igfxdev.dll [X]
- HKLM\...\Policies\Explorer\Run: [BtvStack] => C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [132736 2013-09-25] (Qualcomm®Atheros®)
- HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
- HKU\S-1-5-21-3858528921-1604397686-3684385761-1000\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3042592 2017-06-08] (Valve Corporation)
- HKU\S-1-5-21-3858528921-1604397686-3684385761-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [27784672 2017-06-27] (Skype Technologies S.A.)
- HKU\S-1-5-21-3858528921-1604397686-3684385761-1000\...\Run: [uTorrent] => C:\Program Files (x86)\uTorrent\uTorrent.exe [393728 2017-07-09] (BitTorrent, Inc.)
- HKU\S-1-5-21-3858528921-1604397686-3684385761-1000\...\Run: [GUDelayStartup] => C:\Program Files (x86)\Glary Utilities 5\StartupManager.exe [44016 2017-06-30] (Glarysoft Ltd)
- HKU\S-1-5-21-3858528921-1604397686-3684385761-1000\...\Policies\Explorer: [HideSCAVolume] 1
- HKU\S-1-5-21-3858528921-1604397686-3684385761-1000\...\Policies\Explorer: [HideSCAPower] 0
- HKU\S-1-5-21-3858528921-1604397686-3684385761-1000\...\MountPoints2: {78ed7ff8-431e-11e7-b3f9-40f02f265644} - F:\Autorun.exe
- HKU\S-1-5-21-3858528921-1604397686-3684385761-1000\...\MountPoints2: {78ed7ffb-431e-11e7-b3f9-40f02f265644} - G:\setup.exe
- HKU\S-1-5-21-3858528921-1604397686-3684385761-1000\...\MountPoints2: {b45c9a13-452a-11e7-ae75-40f02f265644} - I:\TDR2000Menu.exe
- Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\TVMOBiLiArtworkManager.lnk [2017-07-02]
- ShortcutTarget: TVMOBiLiArtworkManager.lnk -> C:\Program Files (x86)\TVMOBiLi\bin\iTunesAlbumArtGenerator.exe ()
- Startup: C:\Users\Qwerty\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\SABnzbd.lnk [2017-07-05]
- ShortcutTarget: SABnzbd.lnk -> C:\Program Files\SABnzbd\SABnzbd.exe (The SABnzbd-team)
- Startup: C:\Users\Qwerty\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Trillian.lnk [2017-05-16]
- ShortcutTarget: Trillian.lnk -> C:\Program Files (x86)\Trillian56\trillian.exe (Cerulean Studios)
- BootExecute: autocheck autochk * bootdeleteaswBoot.exe /M:37d52340b6 /wow /dir:"C:\Program Files\AVAST Software\Avast"
- AlternateShell:
- GroupPolicy\User: Restriction <==== ATTENTION
- GroupPolicyScripts\User: Restriction <==== ATTENTION
- ==================== Internet (Whitelisted) ====================
- (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
- Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
- Tcpip\Parameters: [DhcpNameServer] 212.50.160.100 213.249.130.100
- Tcpip\..\Interfaces\{362DD804-0F8C-4B0B-8FEB-A15851E7CF80}: [DhcpNameServer] 212.50.160.100 213.249.130.100
- Internet Explorer:
- ==================
- HKU\S-1-5-21-3858528921-1604397686-3684385761-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/en-gb/?ocid=iehp
- BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_131\bin\ssv.dll [2017-05-12] (Oracle Corporation)
- BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2017-07-02] (AVAST Software)
- BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_131\bin\jp2ssv.dll [2017-05-12] (Oracle Corporation)
- BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_131\bin\ssv.dll [2017-05-12] (Oracle Corporation)
- BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2017-07-02] (AVAST Software)
- BHO-x32: Microsoft Web Test Recorder 14.0 Helper -> {b924f0b4-0b3c-49c0-bab2-213fb9ebd1d3} -> C:\Program Files (x86)\Microsoft Visual Studio 14.0\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll [2015-07-07] (Microsoft Corporation)
- BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_131\bin\jp2ssv.dll [2017-05-12] (Oracle Corporation)
- FireFox:
- ========
- FF DefaultProfile: 96btujvl.default
- FF ProfilePath: C:\Users\Qwerty\AppData\Roaming\oneteam\Profiles\vaywo2pe.default [2017-05-15]
- FF ProfilePath: C:\Users\Qwerty\AppData\Roaming\Mozilla\Firefox\Profiles\96btujvl.default [2017-07-02]
- FF Extension: (uBlock Origin) - C:\Users\Qwerty\AppData\Roaming\Mozilla\Firefox\Profiles\96btujvl.default\Extensions\uBlock0@raymondhill.net.xpi [2017-06-08]
- FF Extension: (Avast Online Security) - C:\Users\Qwerty\AppData\Roaming\Mozilla\Firefox\Profiles\96btujvl.default\Extensions\wrc@avast.com.xpi [2017-06-14]
- FF Plugin: @java.com/DTPlugin,version=11.131.2 -> C:\Program Files\Java\jre1.8.0_131\bin\dtplugin\npDeployJava1.dll [2017-05-12] (Oracle Corporation)
- FF Plugin: @java.com/JavaPlugin,version=11.131.2 -> C:\Program Files\Java\jre1.8.0_131\bin\plugin2\npjp2.dll [2017-05-12] (Oracle Corporation)
- FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
- FF Plugin: @videolan.org/vlc,version=2.2.5.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
- FF Plugin: @videolan.org/vlc,version=2.2.6 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
- FF Plugin-x32: @java.com/DTPlugin,version=11.131.2 -> C:\Program Files (x86)\Java\jre1.8.0_131\bin\dtplugin\npDeployJava1.dll [2017-05-12] (Oracle Corporation)
- FF Plugin-x32: @java.com/JavaPlugin,version=11.131.2 -> C:\Program Files (x86)\Java\jre1.8.0_131\bin\plugin2\npjp2.dll [2017-05-12] (Oracle Corporation)
- FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
- FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll [2013-05-13] ( Microsoft Corporation)
- FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-05-12] (Google Inc.)
- FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-05-12] (Google Inc.)
- Chrome:
- =======
- CHR DefaultProfile: Default
- CHR HomePage: Default -> hxxp://google.com/
- CHR StartupUrls: Default -> "hxxp://widgetpage4u.webs.com/","bdbrowser://tabpage/","hxxp://www.google.com/","hxxp://home.torchbrowser.com/?systemid=448&appid=0&ua=Torch","search.mpc.am","hxxp://iron-start.com/"
- CHR Profile: C:\Users\Qwerty\AppData\Local\Google\Chrome\User Data\Default [2017-07-09]
- CHR Extension: (Google Slides) - C:\Users\Qwerty\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-05-12]
- CHR Extension: (Port Checker Tool) - C:\Users\Qwerty\AppData\Local\Google\Chrome\User Data\Default\Extensions\acineinfhneplngnmlmmmfjojdbpclbp [2017-05-12]
- CHR Extension: (Free Download Manager Chrome extension) - C:\Users\Qwerty\AppData\Local\Google\Chrome\User Data\Default\Extensions\ahmpjcflkgiildlgicmcieglgoilbfdp [2017-05-12]
- CHR Extension: (Google Docs) - C:\Users\Qwerty\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-05-12]
- CHR Extension: (Google Drive) - C:\Users\Qwerty\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-05-12]
- CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Qwerty\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2017-05-12]
- CHR Extension: (MEGA) - C:\Users\Qwerty\AppData\Local\Google\Chrome\User Data\Default\Extensions\bigefpfhnfcobdlfbedofhhaibnlghod [2017-07-02]
- CHR Extension: (YouTube) - C:\Users\Qwerty\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-05-12]
- CHR Extension: (Google Cast for Education) - C:\Users\Qwerty\AppData\Local\Google\Chrome\User Data\Default\Extensions\bnmgbcehmiinmmlmepibeeflglhbhlea [2017-06-02]
- CHR Extension: (DuckieTV - 'Browser Action' mode) - C:\Users\Qwerty\AppData\Local\Google\Chrome\User Data\Default\Extensions\cdfkaloficjmdjbgmckaddgfcghgidei [2017-05-12]
- CHR Extension: (uBlock Origin) - C:\Users\Qwerty\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpalhdlnbpafiamejdnhcphjbkeiagm [2017-06-21]
- CHR Extension: (Spotify - Music for every moment) - C:\Users\Qwerty\AppData\Local\Google\Chrome\User Data\Default\Extensions\cnkjkdjlofllcpbemipjbcpfnglbgieh [2017-05-12]
- CHR Extension: (Netflix) - C:\Users\Qwerty\AppData\Local\Google\Chrome\User Data\Default\Extensions\deceagebecbceejblnlcjooeohmmeldh [2017-05-12]
- CHR Extension: (Tampermonkey) - C:\Users\Qwerty\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhdgffkkebhmkfjojejmpbldmpobfkfo [2017-05-12]
- CHR Extension: (Video Downloader professional) - C:\Users\Qwerty\AppData\Local\Google\Chrome\User Data\Default\Extensions\elicpjhcidhpjomhibiffojpinpmmpil [2017-05-12]
- CHR Extension: (Disable Youtube™ HTML5 Player) - C:\Users\Qwerty\AppData\Local\Google\Chrome\User Data\Default\Extensions\enmofgaijnbjpblfljopnpdogpldapoc [2017-05-12]
- CHR Extension: (Google Play Music) - C:\Users\Qwerty\AppData\Local\Google\Chrome\User Data\Default\Extensions\fahmaaghhglfmonjliepjlchgpgfmobi [2017-07-07]
- CHR Extension: (Google Sheets) - C:\Users\Qwerty\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-05-12]
- CHR Extension: (HTML Revealer and Password Revealer) - C:\Users\Qwerty\AppData\Local\Google\Chrome\User Data\Default\Extensions\fgeopcldenngppapceagonnenonklpbn [2017-05-12]
- CHR Extension: (EditThisCookie) - C:\Users\Qwerty\AppData\Local\Google\Chrome\User Data\Default\Extensions\fngmhnnpilhplaeedifhccceomclgfbg [2017-05-12]
- CHR Extension: (Netease Music) - C:\Users\Qwerty\AppData\Local\Google\Chrome\User Data\Default\Extensions\fogcjafchgdhdoieggbeldnckbghdpkn [2017-05-14]
- CHR Extension: (Chrome Remote Desktop) - C:\Users\Qwerty\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbchcmhmhahfdphkhkmpfmihenigjmpp [2017-06-08]
- CHR Extension: (Google Docs Offline) - C:\Users\Qwerty\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-05-12]
- CHR Extension: (Vysor) - C:\Users\Qwerty\AppData\Local\Google\Chrome\User Data\Default\Extensions\gidgenkbbabolejbgbpnhbimgjbffefm [2017-07-08]
- CHR Extension: (Blockchain) - C:\Users\Qwerty\AppData\Local\Google\Chrome\User Data\Default\Extensions\glaohkkooicollgefkkmndjcbblominl [2017-05-12]
- CHR Extension: (Avast Online Security) - C:\Users\Qwerty\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2017-06-07]
- CHR Extension: (LastPass: Free Password Manager) - C:\Users\Qwerty\AppData\Local\Google\Chrome\User Data\Default\Extensions\hdokiejnpimakedhajhdlcegeplioahd [2017-07-07]
- CHR Extension: (OkayFreedom) - C:\Users\Qwerty\AppData\Local\Google\Chrome\User Data\Default\Extensions\hfnbbbkabnehoejfhcbbhdicagcoobji [2017-05-12]
- CHR Extension: (AllCast Receiver) - C:\Users\Qwerty\AppData\Local\Google\Chrome\User Data\Default\Extensions\hjbljnpdahefgnopeohlaeohgkiidnoe [2017-05-12]
- CHR Extension: (Google Keep - notes and lists) - C:\Users\Qwerty\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmjkmjkepdijhoojdojkdfohbdgmmhki [2017-07-07]
- CHR Extension: (vGet Extension (Video Downloader, DLNA)) - C:\Users\Qwerty\AppData\Local\Google\Chrome\User Data\Default\Extensions\hniladkejehjfchadikcbjmgjaogciic [2017-05-12]
- CHR Extension: (Roms43 for Chrome) - C:\Users\Qwerty\AppData\Local\Google\Chrome\User Data\Default\Extensions\hodglkaodhnbkakchphcmbgdinlgcfgc [2017-05-12]
- CHR Extension: (FireRTC) - C:\Users\Qwerty\AppData\Local\Google\Chrome\User Data\Default\Extensions\iaamfpbohecgihgnbhmppgekdjkbolah [2017-05-12]
- CHR Extension: (VNC® Viewer for Google Chrome™) - C:\Users\Qwerty\AppData\Local\Google\Chrome\User Data\Default\Extensions\iabmpiboiopbgfabjmgeedhcmjenhbla [2017-05-12]
- CHR Extension: (GAuth Authenticator) - C:\Users\Qwerty\AppData\Local\Google\Chrome\User Data\Default\Extensions\ilgcnhelpchnceeipipijaljkblbcobl [2017-05-12]
- CHR Extension: (Avira SafeSearch Plus) - C:\Users\Qwerty\AppData\Local\Google\Chrome\User Data\Default\Extensions\ipmkfpcnmccejididiaagpgchgjfajgp [2017-06-08]
- CHR Extension: (FireRTC Extension) - C:\Users\Qwerty\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmkpkghdacjfjfipnjbknnpdabkllcel [2017-05-12]
- CHR Extension: (Evernote Web) - C:\Users\Qwerty\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbfehkoinhhcknnbdgnnmjhiladcgbol [2017-05-12]
- CHR Extension: (AllDebrid Extension) - C:\Users\Qwerty\AppData\Local\Google\Chrome\User Data\Default\Extensions\mdjbgnpehbhpibonmjjjbjaoechnlcaf [2017-05-12]
- CHR Extension: (Awesome New Tab Page) - C:\Users\Qwerty\AppData\Local\Google\Chrome\User Data\Default\Extensions\mgmiemnjjchgkmgbeljfocdjjnpjnmcg [2017-05-12]
- CHR Extension: (Webresolver.nl) - C:\Users\Qwerty\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjelbipojiljmajjnpkokdkdbmfmmiga [2017-05-12]
- CHR Extension: (Chrome Web Store Payments) - C:\Users\Qwerty\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-05-12]
- CHR Extension: (AdF.ly Skipper ★WORKING: 7/1/2017★) - C:\Users\Qwerty\AppData\Local\Google\Chrome\User Data\Default\Extensions\obnfifcganohemahpomajbhocfkdgmjb [2017-07-02]
- CHR Extension: (Unblock NetEase Music) - C:\Users\Qwerty\AppData\Local\Google\Chrome\User Data\Default\Extensions\okjlonpifkjbibipgioibfecnikmhfil [2017-05-14]
- CHR Extension: (Gmail) - C:\Users\Qwerty\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-05-12]
- CHR Extension: (Chrome Media Router) - C:\Users\Qwerty\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-06-22]
- CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - hxxps://clients2.google.com/service/update2/crx
- ==================== Services (Whitelisted) ====================
- (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
- R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2017-04-03] (Apple Inc.)
- R3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [7430992 2017-07-02] (AVAST Software s.r.o.)
- R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [312448 2013-09-25] (Windows (R) Win 7 DDK provider) [File not signed]
- R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [263312 2017-07-02] (AVAST Software)
- S3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe [1471168 2017-04-24] (Disc Soft Ltd)
- R2 FileZilla Server; C:\Program Files (x86)\FileZilla Server\FileZilla Server.exe [859304 2017-02-08] (FileZilla Project)
- S3 fussvc; C:\Program Files (x86)\Windows Kits\8.1\App Certification Kit\fussvc.exe [142336 2014-02-20] (Microsoft Corporation) [File not signed]
- R2 hshld; C:\Program Files (x86)\Hotspot Shield\bin\cmw_srv.exe [21112 2017-06-28] (AnchorFree Inc.)
- R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [319096 2016-05-12] (Intel Corporation)
- S2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4470736 2017-05-09] (Malwarebytes)
- S2 MSSQL$SQLEXPRESS; c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [57617752 2009-03-30] (Microsoft Corporation)
- R2 NetgearSwitchUSB; C:\Program Files (x86)\NETGEAR\A6210\NetgearSwitchUSB.exe [192232 2015-09-17] ()
- S3 OpenVPNService; C:\Program Files (x86)\OpenVPN\bin\openvpnserv.exe [32384 2016-10-03] (The OpenVPN Project)
- R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2017-05-26] ()
- R2 PnkBstrB; C:\Windows\SysWOW64\PnkBstrB.exe [189248 2017-05-26] ()
- S4 SQLAgent$SQLEXPRESS; c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [427880 2009-03-30] (Microsoft Corporation)
- S3 Te.Service; C:\Program Files (x86)\Windows Kits\8.1\Testing\Runtimes\TAEF\Wex.Services.exe [119808 2013-08-22] (Microsoft Corporation) [File not signed]
- R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [10885360 2017-05-31] (TeamViewer GmbH)
- R2 TenorshareReibootService; C:\Program Files (x86)\ReiBoot\TenorshareReibootService.exe [33208 2017-01-19] (Tenorshare Co,Ltd)
- R2 tvMobiliService; C:\Program Files (x86)\TVMOBiLi\bin\tvMobiliService.exe [2731520 2015-04-20] () [File not signed]
- S3 VMwareHostd; C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe [12471368 2016-04-14] ()
- S3 VSStandardCollectorService140; C:\Program Files (x86)\Microsoft Visual Studio 14.0\Team Tools\DiagnosticsHub\Collector\StandardCollector.Service.exe [56040 2015-11-19] (Microsoft Corporation)
- R2 WALTR2Service; C:\Program Files\WALTR2\x86\WALTR2Service.exe [102312 2017-04-04] ()
- R2 WifiCreatorService; C:\Program Files (x86)\WiFiCreator\WiFiCreatorSvc.exe [626432 2014-01-07] (Azzouzi Software)
- S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
- R2 WindowBlinds; C:\Program Files (x86)\Stardock\WindowBlinds\wbsrv.exe [89600 2015-12-02] (Stardock Corporation) [File not signed]
- R2 ZAtheros Bt and Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [323584 2013-09-25] (Atheros) [File not signed]
- ===================== Drivers (Whitelisted) ======================
- (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
- R3 A6210; C:\Windows\System32\DRIVERS\A6210.sys [2258608 2017-02-10] (MediaTek Inc.)
- R3 AFTrafMgr1.3; C:\Program Files (x86)\Hotspot Shield\bin\TrafMgr_1_3_64.sys [64912 2017-06-09] (AnchorFree Inc.)
- R1 aswbidsdriver; C:\Windows\system32\drivers\aswbidsdrivera.sys [319984 2017-07-02] (AVAST Software s.r.o.)
- R0 aswbidsh; C:\Windows\system32\drivers\aswbidsha.sys [198944 2017-07-02] (AVAST Software s.r.o.)
- R0 aswblog; C:\Windows\system32\drivers\aswbloga.sys [343264 2017-07-02] (AVAST Software s.r.o.)
- R0 aswbuniv; C:\Windows\system32\drivers\aswbuniva.sys [57704 2017-07-02] (AVAST Software s.r.o.)
- S3 aswHdsKe; C:\Windows\system32\drivers\aswHdsKe.sys [92328 2017-06-06] (AVAST Software)
- S3 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [46984 2017-07-02] (AVAST Software)
- R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [146664 2017-07-02] (AVAST Software)
- R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [110352 2017-07-02] (AVAST Software)
- R0 aswRvrt; C:\Windows\system32\drivers\aswRvrt.sys [84392 2017-07-02] (AVAST Software)
- R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1015848 2017-07-02] (AVAST Software)
- R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [585608 2017-07-02] (AVAST Software)
- R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [198768 2017-07-02] (AVAST Software)
- R0 aswVmm; C:\Windows\system32\drivers\aswVmm.sys [361336 2017-07-02] (AVAST Software)
- R3 BTATH_LWFLT; C:\Windows\System32\DRIVERS\btath_lwflt.sys [77464 2013-09-25] (Qualcomm Atheros)
- R3 dtlitescsibus; C:\Windows\System32\DRIVERS\dtlitescsibus.sys [30264 2017-05-27] (Disc Soft Ltd)
- R3 dtliteusbbus; C:\Windows\System32\DRIVERS\dtliteusbbus.sys [47672 2017-05-27] (Disc Soft Ltd)
- R1 ESProtectionDriver; C:\Windows\system32\drivers\mbae64.sys [77376 2017-06-30] ()
- S1 GUBootStartup; C:\Windows\System32\drivers\GUBootStartup.sys [20160 2017-07-09] (Glarysoft Ltd)
- S3 MBAMFarflt; C:\Windows\system32\drivers\farflt.sys [113592 2017-06-24] (Malwarebytes)
- S3 MBAMProtection; C:\Windows\system32\drivers\mbam.sys [44960 2017-06-24] (Malwarebytes)
- S3 MBAMWebProtection; C:\Windows\system32\drivers\mwac.sys [84256 2017-06-25] (Malwarebytes)
- R3 RSP2STOR; C:\Windows\System32\DRIVERS\RtsP2Stor.sys [273040 2013-02-01] (Realtek Semiconductor Corp.)
- S3 RTL8192cu; C:\Windows\System32\DRIVERS\RTL8192cu.sys [748648 2010-08-12] (Realtek Semiconductor Corporation )
- R3 taphss6; C:\Windows\System32\DRIVERS\taphss6.sys [42064 2017-06-15] (Anchorfree Inc.)
- R1 VBoxNetAdp; C:\Windows\System32\DRIVERS\VBoxNetAdp6.sys [131144 2017-04-28] (Oracle Corporation)
- R1 VBoxNetLwf; C:\Windows\System32\DRIVERS\VBoxNetLwf.sys [205952 2017-04-28] (Oracle Corporation)
- R1 veracrypt; C:\Windows\System32\drivers\veracrypt.sys [467368 2017-05-14] (IDRIX)
- R0 vsock; C:\Windows\System32\drivers\vsock.sys [75512 2015-11-05] (VMware, Inc.)
- ==================== NetSvcs (Whitelisted) ===================
- (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
- ==================== One Month Created files and folders ========
- (If an entry is included in the fixlist, the file/folder will be moved.)
- 2017-07-09 16:31 - 2017-07-09 16:33 - 00027495 _____ C:\Users\Qwerty\Downloads\FRST.txt
- 2017-07-09 16:31 - 2017-07-09 16:31 - 02437120 _____ (Farbar) C:\Users\Qwerty\Downloads\FRST64.exe
- 2017-07-09 16:31 - 2017-07-09 16:31 - 00000000 ____D C:\FRST
- 2017-07-09 16:06 - 2017-07-09 16:10 - 00001604 _____ C:\Users\Qwerty\Documents\unlimited free usenet.txt
- 2017-07-09 15:39 - 2017-07-09 15:39 - 00039243 _____ C:\Users\Qwerty\Downloads\TEST1.rar
- 2017-07-09 15:29 - 2017-07-09 15:29 - 00000000 ____D C:\Users\Qwerty\AppData\Local\TechSmith
- 2017-07-09 15:28 - 2017-07-09 15:51 - 00000000 ____D C:\Users\Qwerty\Documents\Camtasia Studio
- 2017-07-09 15:22 - 2017-07-09 15:22 - 00001077 _____ C:\Users\Public\Desktop\Camtasia 9.lnk
- 2017-07-09 15:22 - 2017-07-09 15:22 - 00000000 ____D C:\ProgramData\TechSmith
- 2017-07-09 15:22 - 2017-07-09 15:22 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TechSmith
- 2017-07-09 15:22 - 2017-07-09 15:22 - 00000000 ____D C:\Program Files\TechSmith
- 2017-07-09 15:19 - 2017-07-09 15:19 - 00000000 ____D C:\Program Files (x86)\TechSmith Corporation
- 2017-07-09 15:14 - 2017-07-09 15:14 - 00176594 _____ C:\Users\Qwerty\Downloads\Camtasia_Studio_9.0.5_2021_Inclus_Serial_et_Patch.part1.nzb
- 2017-07-09 15:12 - 2017-07-09 15:12 - 285457368 _____ (TechSmith Corporation) C:\Users\Qwerty\Downloads\camtasia.exe
- 2017-07-09 15:00 - 2017-07-09 15:00 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\VEGAS Pro
- 2017-07-09 15:00 - 2017-07-09 15:00 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\VEGAS
- 2017-07-09 15:00 - 2017-07-09 15:00 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\Publish Providers
- 2017-07-09 15:00 - 2017-07-09 15:00 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\MAGIX
- 2017-07-09 15:00 - 2017-07-09 15:00 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\dclogs
- 2017-07-09 15:00 - 2017-07-09 15:00 - 00000000 ____D C:\Users\Qwerty\AppData\Local\VEGAS Pro
- 2017-07-09 15:00 - 2017-07-09 15:00 - 00000000 ____D C:\Users\Qwerty\AppData\Local\Sony
- 2017-07-09 15:00 - 2017-07-09 15:00 - 00000000 ____D C:\ProgramData\VEGAS Pro
- 2017-07-09 15:00 - 2017-07-09 15:00 - 00000000 ____D C:\ProgramData\Magix
- 2017-07-09 14:59 - 2017-07-09 15:00 - 00000000 ___HD C:\Users\Qwerty\AppData\Roaming\tws
- 2017-07-09 14:59 - 2017-07-09 14:59 - 00003574 _____ C:\Windows\System32\Tasks\yiyu
- 2017-07-09 14:59 - 2017-07-09 14:59 - 00000000 __SHD C:\Users\Qwerty\yiyu
- 2017-07-09 14:59 - 2017-04-21 14:53 - 00045176 ___SH (Microsoft Corporation) C:\Users\Qwerty\RegSvcs.exe
- 2017-07-09 14:58 - 2017-07-09 14:58 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VEGAS
- 2017-07-09 14:57 - 2017-07-09 14:57 - 00000000 ____D C:\Users\Qwerty\AppData\Local\VEGAS
- 2017-07-09 14:57 - 2017-07-09 14:57 - 00000000 ____D C:\ProgramData\VEGAS
- 2017-07-09 14:57 - 2017-07-09 14:57 - 00000000 ____D C:\Program Files\VEGAS
- 2017-07-09 14:57 - 2017-07-09 14:57 - 00000000 ____D C:\Program Files (x86)\VEGAS
- 2017-07-09 14:56 - 2017-07-09 14:56 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\Sony
- 2017-07-09 14:56 - 2017-07-09 14:56 - 00000000 ____D C:\Program Files (x86)\MAGIX Computer Products Intl. Co
- 2017-07-09 14:55 - 2017-07-09 14:55 - 00305388 _____ C:\Users\Qwerty\Downloads\MAGIX_Vegas_Pro_14.0.0_Build_252_-_64bit.nzb
- 2017-07-09 14:53 - 2017-07-09 14:53 - 00060835 _____ C:\Users\Qwerty\Downloads\MAGIX_Vegas_Pro_13.nzb
- 2017-07-09 14:49 - 2017-07-09 14:49 - 00638252 _____ C:\Users\Qwerty\Downloads\Pirates.of.the.Caribbean.Dead.Men.Tell.No.Tales.2017.Custom.DKsubs.720p.Blurr.HDCAM.x265-RELEASED.nzb
- 2017-07-09 14:35 - 2017-07-09 14:35 - 00002039 _____ C:\Users\Public\Desktop\Action!.lnk
- 2017-07-09 14:34 - 2017-07-09 14:34 - 22683849 _____ C:\Users\Qwerty\Downloads\Action Recorder.zip
- 2017-07-09 14:28 - 2017-07-09 14:28 - 00020160 _____ (Glarysoft Ltd) C:\Windows\system32\Drivers\GUBootStartup.sys
- 2017-07-09 14:28 - 2017-07-09 14:28 - 00003316 _____ C:\Windows\System32\Tasks\GlaryInitialize 5
- 2017-07-09 14:28 - 2017-07-09 14:28 - 00001096 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Glary Utilities 5.lnk
- 2017-07-09 14:28 - 2017-07-09 14:28 - 00001084 _____ C:\Users\Public\Desktop\Glary Utilities 5.lnk
- 2017-07-09 14:28 - 2017-07-09 14:28 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\GlarySoft
- 2017-07-09 14:28 - 2017-07-09 14:28 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\DiskDefrag
- 2017-07-09 14:28 - 2017-07-09 14:28 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Glary Utilities 5
- 2017-07-09 14:28 - 2017-07-09 14:28 - 00000000 ____D C:\Program Files (x86)\Glary Utilities 5
- 2017-07-09 14:27 - 2017-07-09 14:27 - 16893520 _____ C:\Users\Qwerty\Downloads\gu5setup.exe
- 2017-07-09 14:21 - 2017-07-09 14:25 - 00000000 ____D C:\Users\Qwerty\Documents\Bandicam
- 2017-07-09 14:21 - 2017-07-09 14:21 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\Bandicam Company
- 2017-07-09 14:20 - 2017-07-09 14:20 - 00000992 _____ C:\Users\Public\Desktop\Bandicam.lnk
- 2017-07-09 14:20 - 2017-07-09 14:20 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bandicam
- 2017-07-09 14:20 - 2017-07-09 14:20 - 00000000 ____D C:\Program Files (x86)\BandiMPEG1
- 2017-07-09 14:20 - 2017-07-09 14:20 - 00000000 ____D C:\Program Files (x86)\Bandicam
- 2017-07-09 14:18 - 2017-07-09 14:20 - 00000000 ____D C:\Users\Qwerty\Documents\bandicamcrack
- 2017-07-09 14:17 - 2017-07-09 14:18 - 17692519 _____ C:\Users\Qwerty\Downloads\Bandicam.3.4.2.1258.rar
- 2017-07-09 14:16 - 2017-07-09 14:17 - 17684928 _____ C:\Users\Qwerty\Downloads\Bandicam.3.4.2.1258.rar.crdownload
- 2017-07-09 14:05 - 2017-07-09 14:05 - 113245088 _____ (obsproject.com) C:\Users\Qwerty\Downloads\OBS-Studio-19.0.3-Full-Installer.exe
- 2017-07-09 14:05 - 2017-07-09 14:05 - 00001202 _____ C:\Users\Public\Desktop\OBS Studio.lnk
- 2017-07-09 14:05 - 2017-07-09 14:05 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OBS Studio
- 2017-07-09 14:05 - 2017-07-09 14:05 - 00000000 ____D C:\Program Files (x86)\obs-studio
- 2017-07-09 13:58 - 2017-07-09 14:35 - 00000000 ____D C:\Users\Qwerty\Documents\actionpre
- 2017-07-09 13:57 - 2017-07-09 13:57 - 23339110 _____ C:\Users\Qwerty\Downloads\M.A_2.5.5 Pable Pre-acted (1).zip
- 2017-07-09 13:53 - 2017-07-09 13:53 - 10855843 _____ C:\Users\Qwerty\Downloads\Mirillis Action Troubleshooter (Updated).zip
- 2017-07-09 13:53 - 2017-07-09 13:53 - 00001223 _____ C:\Users\Qwerty\Downloads\Mirillis_Action_Troubleshooter_(Updated).xht
- 2017-07-08 22:03 - 2017-07-08 22:03 - 00182747 _____ C:\Users\Qwerty\Downloads\3.2017.NEW.HDTS.XviD-VAiN.nzb
- 2017-07-08 21:49 - 2017-07-08 21:49 - 00327323 _____ C:\Users\Qwerty\Downloads\Despicable.Me.3.2017.NEW.HD-TS.x264-CPG (1).nzb
- 2017-07-08 16:51 - 2017-07-08 16:52 - 00000000 ____D C:\Users\Qwerty\AppData\Local\Vysor
- 2017-07-08 16:51 - 2017-07-08 16:51 - 49937408 _____ (ClockworkMod) C:\Users\Qwerty\Downloads\Vysor-win32-ia32 (1).exe
- 2017-07-08 16:43 - 2017-07-08 16:56 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\Vysor
- 2017-07-08 16:43 - 2017-07-08 16:52 - 00002156 _____ C:\Users\Qwerty\Desktop\Vysor.lnk
- 2017-07-08 16:43 - 2017-07-08 16:52 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ClockworkMod
- 2017-07-08 16:41 - 2017-07-08 16:41 - 49937408 _____ (ClockworkMod) C:\Users\Qwerty\Downloads\Vysor-win32-ia32.exe
- 2017-07-08 14:57 - 2017-07-08 14:57 - 01996288 _____ (J Sommer) C:\Users\Qwerty\Downloads\asciiquarium.scr
- 2017-07-08 13:41 - 2017-07-09 13:24 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\tixati
- 2017-07-08 13:41 - 2017-07-08 13:41 - 00000784 _____ C:\Users\Qwerty\Desktop\Tixati.lnk
- 2017-07-08 13:41 - 2017-07-08 13:41 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Tixati
- 2017-07-08 13:40 - 2017-07-08 13:41 - 00000000 ____D C:\Program Files\tixati
- 2017-07-08 13:40 - 2017-07-08 13:40 - 13851288 _____ C:\Users\Qwerty\Downloads\tixati-2.53-1.win64-install.exe
- 2017-07-08 13:29 - 2017-07-08 13:29 - 00241017 _____ C:\Users\Qwerty\Downloads\Collection+of+250+decrypted+3DS+ROMs+for+Citra+Emulator.torrent
- 2017-07-07 23:00 - 2017-07-07 23:00 - 20272152 _____ C:\Users\Qwerty\Downloads\ppsspp_win.zip
- 2017-07-07 23:00 - 2017-07-07 23:00 - 00000000 ____D C:\Users\Qwerty\Downloads\PPSSPP
- 2017-07-07 18:51 - 2017-07-07 18:51 - 00504752 _____ C:\Users\Qwerty\Downloads\Minions.2015.MULTI.1080p.BluRay.x264-Goatlove.nzb
- 2017-07-07 18:38 - 2017-07-07 18:38 - 15179461 _____ C:\Users\Qwerty\Downloads\mkvtoolnix-64bit-13.0.0.7z
- 2017-07-07 18:36 - 2017-07-07 18:36 - 00801365 _____ C:\Users\Qwerty\Downloads\MKVExtractGUI-1.6.4.1Wizard-1.2.zip
- 2017-07-07 18:36 - 2017-07-07 18:36 - 00000000 ____D C:\Users\Qwerty\Downloads\MKVtools
- 2017-07-07 16:29 - 2017-07-07 16:29 - 00023328 _____ C:\Users\Qwerty\Downloads\Jaba_Com_Web_Browser_1.9.98.zip.nzb
- 2017-07-07 16:11 - 2017-07-07 16:11 - 00000600 __RSH C:\Users\Qwerty\ntuser.pol
- 2017-07-07 07:25 - 2017-07-07 07:25 - 00000000 ___HD C:\$AV_ASW
- 2017-07-06 19:40 - 2017-07-06 19:41 - 00014916 _____ C:\Users\Qwerty\Downloads\Builder.rar
- 2017-07-06 19:03 - 2017-07-06 19:03 - 00268376 _____ C:\Users\Qwerty\Downloads\winmd5free.zip
- 2017-07-06 18:18 - 2017-07-06 18:18 - 23339110 _____ C:\Users\Qwerty\Downloads\M.A_2.5.5 Pable Pre-acted.zip
- 2017-07-06 18:18 - 2017-07-06 18:18 - 00000000 ____D C:\Users\Qwerty\Downloads\action
- 2017-07-06 18:14 - 2017-07-06 18:14 - 23644032 _____ (Mirillis Ltd.) C:\Users\Qwerty\Downloads\action_2_5_5_setup.exe
- 2017-07-06 18:13 - 2017-07-06 18:13 - 00008048 _____ C:\Users\Qwerty\Downloads\Mirillis_Action!_1301_Multilingual.rar- (1).nzb
- 2017-07-06 18:12 - 2017-07-06 18:12 - 00000000 ____D C:\Users\Qwerty\Documents\Action!
- 2017-07-06 18:12 - 2017-07-06 18:12 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\Mirillis
- 2017-07-06 18:12 - 2017-07-06 18:12 - 00000000 ____D C:\ProgramData\Mirillis
- 2017-07-06 18:11 - 2017-07-09 14:35 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mirillis
- 2017-07-06 18:11 - 2017-07-09 14:35 - 00000000 ____D C:\Program Files (x86)\Mirillis
- 2017-07-06 18:11 - 2017-07-06 18:20 - 00000000 ____D C:\Users\Qwerty\AppData\Local\Mirillis
- 2017-07-06 17:54 - 2017-07-06 17:54 - 00008048 _____ C:\Users\Qwerty\Downloads\Mirillis_Action!_1301_Multilingual.rar-.nzb
- 2017-07-06 17:11 - 2017-07-06 17:11 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\aipai
- 2017-07-06 17:10 - 2017-07-09 15:12 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\obs-studio
- 2017-07-06 17:10 - 2017-07-09 14:40 - 00000338 _____ C:\Users\Qwerty\AppData\Roaming\basic.ini
- 2017-07-06 17:09 - 2017-07-06 17:09 - 00001596 _____ C:\Users\Qwerty\Desktop\SmartPixel.lnk
- 2017-07-06 17:09 - 2017-07-06 17:09 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SmartPixel
- 2017-07-06 17:09 - 2017-07-06 17:09 - 00000000 ____D C:\SmartPixel
- 2017-07-06 17:09 - 2017-07-06 17:09 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SmartPixel
- 2017-07-06 17:07 - 2017-07-06 17:07 - 48365904 _____ (Beyond Magic Limited) C:\Users\Qwerty\Downloads\smartpixel_setup.exe
- 2017-07-05 21:45 - 2017-07-05 21:45 - 00329458 _____ C:\Users\Qwerty\Downloads\portlistener.zip
- 2017-07-05 21:42 - 2017-07-08 17:24 - 00000000 ____D C:\Program Files\SABnzbd
- 2017-07-05 21:42 - 2017-07-05 21:42 - 00000796 _____ C:\Users\Qwerty\Desktop\SABnzbd.lnk
- 2017-07-05 21:42 - 2017-07-05 21:42 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SABnzbd
- 2017-07-05 20:37 - 2017-07-05 20:37 - 00327323 _____ C:\Users\Qwerty\Downloads\Despicable.Me.3.2017.NEW.HD-TS.x264-CPG.nzb
- 2017-07-05 20:37 - 2017-07-05 20:37 - 00295331 _____ C:\Users\Qwerty\Downloads\Despicable.Me.3.2017.TS.x264.AC3-TiTAN.nzb
- 2017-07-05 20:35 - 2017-07-05 20:35 - 00028871 _____ C:\Users\Qwerty\Downloads\The_Simpsons_-_S06E02_-_Lisas_Rival.nzb
- 2017-07-05 20:35 - 2017-07-05 20:35 - 00028811 _____ C:\Users\Qwerty\Downloads\The_Simpsons_-_S06E03_-_Another_Simpsons_Clip_Show.nzb
- 2017-07-05 20:35 - 2017-07-05 20:35 - 00028773 _____ C:\Users\Qwerty\Downloads\The_Simpsons_-_S06E06_-_Treehouse_Of_Horror.nzb
- 2017-07-05 20:35 - 2017-07-05 20:35 - 00028772 _____ C:\Users\Qwerty\Downloads\The_Simpsons_-_S06E01_-_Bart_of_Darkness.nzb
- 2017-07-05 20:35 - 2017-07-05 20:35 - 00028752 _____ C:\Users\Qwerty\Downloads\The_Simpsons_-_S06E04_-_Itchy_And_Scratchyland.nzb
- 2017-07-05 20:35 - 2017-07-05 20:35 - 00028581 _____ C:\Users\Qwerty\Downloads\The_Simpsons_-_S06E05_-_Sideshow_Bob_Roberts.nzb
- 2017-07-05 20:00 - 2017-07-05 20:00 - 00978628 _____ C:\Users\Qwerty\Downloads\The_Simpsons_S05E02_Cape_Feare_720p_HDTV_UPSCALE_DD5.1_MPEG2-TrollHD.par2.nzb
- 2017-07-05 19:59 - 2017-07-05 19:59 - 00025310 _____ C:\Users\Qwerty\Downloads\The.Simpsons.S05E02.1080p.BluRay.x264-TAXES.rar.nzb
- 2017-07-05 19:57 - 2017-07-05 19:57 - 00026772 _____ C:\Users\Qwerty\Downloads\2017-07-05_08_57_51.nzb
- 2017-07-05 19:54 - 2017-07-05 19:54 - 00023586 _____ C:\Users\Qwerty\Downloads\The_Simpsons_-_S05E02_-_Cape_Feare (1).nzb
- 2017-07-05 19:50 - 2017-07-05 19:50 - 00061845 _____ C:\Users\Qwerty\Downloads\The.Simpsons.S05E19.DVDRip.XviD-MEDiEVAL.nzb
- 2017-07-05 19:50 - 2017-07-05 19:50 - 00061398 _____ C:\Users\Qwerty\Downloads\The.Simpsons.S05E05.INTERNAL.DVDRip.XviD-MEDiEVAL.nzb
- 2017-07-05 19:50 - 2017-07-05 19:50 - 00060544 _____ C:\Users\Qwerty\Downloads\The.Simpsons.S05E02.DVDRip.XviD-MEDiEVAL.nzb
- 2017-07-05 19:46 - 2017-07-05 19:46 - 00024067 _____ C:\Users\Qwerty\Downloads\The_Simpsons_-_S05E01_-_Homer's_Barbershop_Quartet.nzb
- 2017-07-05 19:46 - 2017-07-05 19:46 - 00023957 _____ C:\Users\Qwerty\Downloads\The_Simpsons_-_S05E19_-_Sweet_Seymour_Skinner's_Baadasssss_Song (1).nzb
- 2017-07-05 19:46 - 2017-07-05 19:46 - 00023586 _____ C:\Users\Qwerty\Downloads\The_Simpsons_-_S05E02_-_Cape_Feare.nzb
- 2017-07-05 19:45 - 2017-07-05 19:45 - 00024557 _____ C:\Users\Qwerty\Downloads\The_Simpsons_-_S05E10_-_pringfield_(Or,_How_I_Learned_to_Stop_Worrying_and_Love_Legalized_Gambling).nzb
- 2017-07-05 19:45 - 2017-07-05 19:45 - 00024122 _____ C:\Users\Qwerty\Downloads\The_Simpsons_-_S05E09_-_The_Last_Temptation_of_Homer.nzb
- 2017-07-05 19:45 - 2017-07-05 19:45 - 00024045 _____ C:\Users\Qwerty\Downloads\The_Simpsons_-_S05E17_-_Bart_Gets_an_Elephant.nzb
- 2017-07-05 19:45 - 2017-07-05 19:45 - 00024030 _____ C:\Users\Qwerty\Downloads\The_Simpsons_-_S05E16_-_Homer_Loves_Flanders.nzb
- 2017-07-05 19:45 - 2017-07-05 19:45 - 00023984 _____ C:\Users\Qwerty\Downloads\The_Simpsons_-_S05E06_-_Marge_on_the_Lam.nzb
- 2017-07-05 19:45 - 2017-07-05 19:45 - 00023979 _____ C:\Users\Qwerty\Downloads\The_Simpsons_-_S05E08_-_Boy-Scoutz_N_the_Hood.nzb
- 2017-07-05 19:45 - 2017-07-05 19:45 - 00023967 _____ C:\Users\Qwerty\Downloads\The_Simpsons_-_S05E13_-_Homer_and_Apu.nzb
- 2017-07-05 19:45 - 2017-07-05 19:45 - 00023957 _____ C:\Users\Qwerty\Downloads\The_Simpsons_-_S05E19_-_Sweet_Seymour_Skinner's_Baadasssss_Song.nzb
- 2017-07-05 19:45 - 2017-07-05 19:45 - 00023950 _____ C:\Users\Qwerty\Downloads\The_Simpsons_-_S05E14_-_Lisa_vs._Malibu_Stacy.nzb
- 2017-07-05 19:45 - 2017-07-05 19:45 - 00023947 _____ C:\Users\Qwerty\Downloads\The_Simpsons_-_S05E18_-_Burns'_Heir.nzb
- 2017-07-05 19:45 - 2017-07-05 19:45 - 00023946 _____ C:\Users\Qwerty\Downloads\The_Simpsons_-_S05E03_-_Homer_Goes_to_College.nzb
- 2017-07-05 19:45 - 2017-07-05 19:45 - 00023941 _____ C:\Users\Qwerty\Downloads\The_Simpsons_-_S05E11_-_Homer_the_Vigilante.nzb
- 2017-07-05 19:45 - 2017-07-05 19:45 - 00023906 _____ C:\Users\Qwerty\Downloads\The_Simpsons_-_S05E15_-_Deep_Space_Homer.nzb
- 2017-07-05 19:45 - 2017-07-05 19:45 - 00023900 _____ C:\Users\Qwerty\Downloads\The_Simpsons_-_S05E12_-_Bart_Gets_Famous.nzb
- 2017-07-05 19:45 - 2017-07-05 19:45 - 00023900 _____ C:\Users\Qwerty\Downloads\The_Simpsons_-_S05E07_-_Bart's_Inner_Child.nzb
- 2017-07-05 19:45 - 2017-07-05 19:45 - 00023806 _____ C:\Users\Qwerty\Downloads\The_Simpsons_-_S05E04_-_Rosebud.nzb
- 2017-07-05 19:45 - 2017-07-05 19:45 - 00023723 _____ C:\Users\Qwerty\Downloads\The_Simpsons_-_S05E05_-_Treehouse_of_Horror_IV.nzb
- 2017-07-05 19:44 - 2017-07-05 19:44 - 00024085 _____ C:\Users\Qwerty\Downloads\The_Simpsons_-S05E22_-_Secrets_of_a_Successful_Marriage (1).nzb
- 2017-07-05 19:44 - 2017-07-05 19:44 - 00024076 _____ C:\Users\Qwerty\Downloads\The_Simpsons_-_S05E20_-_The_Boy_Who_Knew_Too_Much.nzb
- 2017-07-05 19:44 - 2017-07-05 19:44 - 00024005 _____ C:\Users\Qwerty\Downloads\The_Simpsons_-_S05E21_-_Lady_Bouvier's_Lover.nzb
- 2017-07-05 19:07 - 2017-07-05 19:07 - 00016896 _____ C:\Users\Qwerty\Downloads\client.exe
- 2017-07-05 18:00 - 2017-07-05 18:00 - 01024131 _____ C:\Users\Qwerty\Downloads\The.Simpsons.S05E06.Marge.On.The.Lam.720p.HDTV.UPSCALE.DD5.1.MPEG2-TrollHD.nzb
- 2017-07-05 18:00 - 2017-07-05 18:00 - 00997461 _____ C:\Users\Qwerty\Downloads\The.Simpsons.S05E05.Treehouse.Of.Horror.IV.720p.HDTV.UPSCALE.DD5.1.MPEG2-TrollHD.nzb
- 2017-07-05 18:00 - 2017-07-05 18:00 - 00989455 _____ C:\Users\Qwerty\Downloads\The.Simpsons.S05E07.Bart's.Inner.Child.720p.HDTV.UPSCALE.DD5.1.MPEG2-TrollHD.nzb
- 2017-07-05 17:57 - 2017-07-05 17:57 - 00999804 _____ C:\Users\Qwerty\Downloads\The.Simpsons.S05E08.Boy-Scoutz.'N.The.Hood.720p.HDTV.UPSCALE.DD5.1.MPEG2-TrollHD.nzb
- 2017-07-05 17:56 - 2017-07-05 17:56 - 01011770 _____ C:\Users\Qwerty\Downloads\The.Simpsons.S05E09.The.Last.Temptation.Of.Homer.720p.HDTV.UPSCALE.DD5.1.MPEG2-TrollHD.nzb
- 2017-07-05 17:56 - 2017-07-05 17:56 - 01010999 _____ C:\Users\Qwerty\Downloads\The.Simpsons.S05E20.The.Boy.Who.Knew.Too.Much.720p.HDTV.UPSCALE.DD5.1.MPEG2-TrollHD.nzb
- 2017-07-05 17:56 - 2017-07-05 17:56 - 01007862 _____ C:\Users\Qwerty\Downloads\The.Simpsons.S05E18.Burns'.Heir.720p.HDTV.UPSCALE.DD5.1.MPEG2-TrollHD.nzb
- 2017-07-05 17:56 - 2017-07-05 17:56 - 01007079 _____ C:\Users\Qwerty\Downloads\The.Simpsons.S05E13.Homer.And.Apu.720p.HDTV.UPSCALE.DD5.1.MPEG2-TrollHD.nzb
- 2017-07-05 17:56 - 2017-07-05 17:56 - 01005734 _____ C:\Users\Qwerty\Downloads\The.Simpsons.S05E16.Homer.Loves.Flanders.720p.HDTV.UPSCALE.DD5.1.MPEG2-TrollHD.nzb
- 2017-07-05 17:56 - 2017-07-05 17:56 - 01003504 _____ C:\Users\Qwerty\Downloads\The.Simpsons.S05E12.Bart.Gets.Famous.720p.HDTV.UPSCALE.DD5.1.MPEG2-TrollHD.nzb
- 2017-07-05 17:56 - 2017-07-05 17:56 - 00999307 _____ C:\Users\Qwerty\Downloads\The.Simpsons.S05E14.Lisa.Vs..Malibu.Stacy.720p.HDTV.UPSCALE.DD5.1.MPEG2-TrollHD.nzb
- 2017-07-05 17:56 - 2017-07-05 17:56 - 00996185 _____ C:\Users\Qwerty\Downloads\The.Simpsons.S05E15.Deep.Space.Homer.720p.HDTV.UPSCALE.DD5.1.MPEG2-TrollHD.nzb
- 2017-07-05 17:56 - 2017-07-05 17:56 - 00993179 _____ C:\Users\Qwerty\Downloads\The.Simpsons.S05E11.Homer.The.Vigilante.720p.HDTV.UPSCALE.DD5.1.MPEG2-TrollHD.nzb
- 2017-07-05 17:56 - 2017-07-05 17:56 - 00988297 _____ C:\Users\Qwerty\Downloads\The.Simpsons.S05E17.Bart.Gets.An.Elephant.720p.HDTV.UPSCALE.DD5.1.MPEG2-TrollHD.nzb
- 2017-07-05 17:54 - 2017-07-09 15:14 - 00000000 ____D C:\Users\Qwerty\Downloads\complete
- 2017-07-05 17:54 - 2017-07-05 17:54 - 00024085 _____ C:\Users\Qwerty\Downloads\The_Simpsons_-S05E22_-_Secrets_of_a_Successful_Marriage.nzb
- 2017-07-05 17:52 - 2017-07-05 17:52 - 01014267 _____ C:\Users\Qwerty\Downloads\The.Simpsons.S05E22.Secrets.Of.A.Successful.Marriage.720p.HDTV.UPSCALE.DD5.1.MPEG2-TrollHD.nzb
- 2017-07-05 17:52 - 2017-07-05 17:52 - 01005087 _____ C:\Users\Qwerty\Downloads\The.Simpsons.S05E21.Lady.Bouvier's.Lover.720p.HDTV.UPSCALE.DD5.1.MPEG2-TrollHD.nzb
- 2017-07-04 22:06 - 2017-07-09 15:14 - 00000000 ____D C:\Users\Qwerty\Downloads\incomplete
- 2017-07-04 22:06 - 2017-07-04 22:06 - 00000000 ____D C:\Users\Qwerty\AppData\Local\sabnzbd
- 2017-07-04 22:05 - 2017-07-04 22:05 - 20207148 _____ C:\Users\Qwerty\Downloads\SABnzbd-2.1.0-win-setup.exe
- 2017-07-04 22:03 - 2017-07-04 22:03 - 00312132 _____ C:\Users\Qwerty\Downloads\Despicable.Me.3.Screener.AC3-DRC.nzb
- 2017-07-04 22:03 - 2017-07-04 22:03 - 00132254 _____ C:\Users\Qwerty\Downloads\Despicable.Me.2.2013.720p.BluRay.H264.AAC-RARBG.nzb
- 2017-07-04 21:33 - 2017-07-04 21:33 - 00501363 _____ (Peter B Clements) C:\Users\Qwerty\Downloads\QuickPar-0.9.1.0.exe
- 2017-07-04 21:33 - 2017-07-04 21:33 - 00001011 _____ C:\Users\Qwerty\Desktop\QuickPar.lnk
- 2017-07-04 21:33 - 2017-07-04 21:33 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\QuickPar
- 2017-07-04 21:33 - 2017-07-04 21:33 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickPar
- 2017-07-04 21:33 - 2017-07-04 21:33 - 00000000 ____D C:\Program Files (x86)\QuickPar
- 2017-07-04 21:32 - 2017-07-04 22:03 - 00000000 ____D C:\Users\Qwerty\Documents\Newsbin Download
- 2017-07-04 21:30 - 2017-07-04 22:06 - 00000000 ____D C:\Users\Qwerty\AppData\Local\NewsBin
- 2017-07-04 21:30 - 2017-07-04 22:01 - 00000000 ____D C:\Program Files\NewsBin
- 2017-07-04 21:30 - 2017-07-04 21:30 - 00000883 _____ C:\Users\Qwerty\Desktop\NewsBin Pro 64.lnk
- 2017-07-04 21:30 - 2017-07-04 21:30 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NewsBin5-64
- 2017-07-04 21:29 - 2017-07-04 21:29 - 04183984 _____ C:\Users\Qwerty\Downloads\nb554-64.exe
- 2017-07-04 21:24 - 2017-07-04 21:24 - 00003655 _____ C:\Users\Qwerty\Downloads\NewsBin.Professional.5.51.(Build.9378).cracked-SND.nzb
- 2017-07-04 20:53 - 2017-07-04 20:53 - 16564488 _____ C:\Users\Qwerty\Downloads\nb672-full.exe
- 2017-07-04 20:30 - 2017-07-04 20:30 - 00096955 _____ C:\Users\Qwerty\Downloads\The.Simpsons.S04E22.Krusty.Gets.Kancelled.720p.HDTV.DD5.1.x264-CtrlHD.nzb
- 2017-07-04 20:10 - 2017-07-04 20:10 - 00088697 _____ C:\Users\Qwerty\Downloads\gsmax0.5.zip
- 2017-07-04 20:01 - 2017-07-04 20:01 - 00557996 _____ C:\Users\Qwerty\Downloads\ZeroGS_KOSMOS_0.97.1_sse2.zip
- 2017-07-04 19:34 - 2017-07-04 19:34 - 206156956 _____ C:\Users\Qwerty\Downloads\PS3UPDAT.PUP
- 2017-07-04 19:12 - 2017-07-04 19:12 - 00000000 ____D C:\Users\Qwerty\Downloads\B795TSG.part1
- 2017-07-04 19:00 - 2017-07-04 19:00 - 24391974 _____ C:\Users\Qwerty\Downloads\B795TSG.part6.rar
- 2017-07-04 18:59 - 2017-07-04 19:10 - 2147483648 _____ C:\Users\Qwerty\Downloads\B795TSG.part4.rar
- 2017-07-04 18:59 - 2017-07-04 19:10 - 2147483648 _____ C:\Users\Qwerty\Downloads\B795TSG.part3.rar
- 2017-07-04 18:59 - 2017-07-04 19:09 - 2147483648 _____ C:\Users\Qwerty\Downloads\B795TSG.part5.rar
- 2017-07-04 18:58 - 2017-07-04 19:08 - 2147483648 _____ C:\Users\Qwerty\Downloads\B795TSG.part2.rar
- 2017-07-04 18:55 - 2017-07-04 18:59 - 2147483648 _____ C:\Users\Qwerty\Downloads\B795TSG.part1.rar
- 2017-07-04 18:52 - 2017-07-04 19:34 - 00000000 ____D C:\Users\Qwerty\Downloads\rpcs3
- 2017-07-04 18:51 - 2017-07-04 18:51 - 18959015 _____ C:\Users\Qwerty\Downloads\rpcs3-v0.0.2-2017-07-03-ba75f383_win64.zip
- 2017-07-04 16:03 - 2017-07-04 16:44 - 1199802187 _____ C:\Users\Qwerty\Downloads\[fmovies.to] Despicable Me 3 (Russian Audio) - TS.mp4
- 2017-07-03 21:49 - 2017-07-09 13:51 - 00000000 ____D C:\Users\Qwerty\Downloads\GrabIt Downloads
- 2017-07-03 21:48 - 2017-07-03 21:48 - 00094802 _____ C:\Users\Qwerty\Downloads\The.Simpsons.S04E21.Marge.in.Chains.720p.HDTV.DD5.1.x264-CtrlHD.nzb
- 2017-07-03 21:47 - 2017-07-04 20:44 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\GrabIt
- 2017-07-03 21:46 - 2017-07-03 21:46 - 00000983 _____ C:\Users\Qwerty\Desktop\GrabIt.lnk
- 2017-07-03 21:46 - 2017-07-03 21:46 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GrabIt
- 2017-07-03 21:46 - 2017-07-03 21:46 - 00000000 ____D C:\Program Files (x86)\GrabIt
- 2017-07-03 21:45 - 2017-07-03 21:45 - 02547810 _____ (Ilan Shemes ) C:\Users\Qwerty\Downloads\GrabIt174b2.exe
- 2017-07-03 15:53 - 2017-07-03 15:53 - 07075640 _____ (Tim Kosse) C:\Users\Qwerty\Downloads\FileZilla_3.26.2_win64-setup.exe
- 2017-07-03 15:53 - 2017-07-03 15:53 - 07070840 _____ (Tim Kosse) C:\Users\Qwerty\Downloads\FileZilla_3.26.1_win64-setup.exe
- 2017-07-02 22:21 - 2017-07-09 16:31 - 00000000 ____D C:\ProgramData\TVMOBiLi
- 2017-07-02 22:21 - 2017-07-02 22:21 - 00001196 _____ C:\Users\Public\Desktop\TVMOBiLi.lnk
- 2017-07-02 22:21 - 2017-07-02 22:21 - 00000000 ____D C:\Program Files (x86)\TVMOBiLi
- 2017-07-02 22:20 - 2017-07-02 22:20 - 10590197 _____ C:\Users\Qwerty\Downloads\tvmobili-windows-i386.exe
- 2017-07-02 21:44 - 2017-07-02 21:44 - 00000835 _____ C:\Users\Qwerty\Downloads\Ftp zoxie@cube64.net.xml
- 2017-07-02 16:40 - 2017-07-02 16:40 - 00001724 _____ C:\Users\Public\Desktop\Defraggler.lnk
- 2017-07-02 16:40 - 2017-07-02 16:40 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Defraggler
- 2017-07-02 16:40 - 2017-07-02 16:40 - 00000000 ____D C:\Program Files\Defraggler
- 2017-07-02 16:39 - 2017-07-02 16:39 - 04619752 _____ (Piriform Ltd) C:\Users\Qwerty\Downloads\dfsetup221.exe
- 2017-07-02 12:07 - 2017-07-02 12:06 - 00400464 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
- 2017-07-01 21:36 - 2016-04-14 17:17 - 00066752 _____ (VMware, Inc.) C:\Windows\system32\Drivers\vmx86.sys
- 2017-07-01 21:35 - 2016-04-14 17:17 - 00392896 _____ (VMware, Inc.) C:\Windows\SysWOW64\vmnat.exe
- 2017-07-01 21:35 - 2016-04-14 17:17 - 00358080 _____ (VMware, Inc.) C:\Windows\SysWOW64\vmnetdhcp.exe
- 2017-07-01 21:34 - 2016-04-14 17:17 - 00934080 _____ (VMware, Inc.) C:\Windows\system32\vnetlib64.dll
- 2017-07-01 21:34 - 2016-04-14 16:53 - 00026816 _____ (VMware, Inc.) C:\Windows\system32\Drivers\vmnetuserif.sys
- 2017-07-01 21:33 - 2016-03-10 08:03 - 00057536 _____ (VMware, Inc.) C:\Windows\system32\Drivers\hcmon.sys
- 2017-07-01 21:32 - 2017-07-01 21:32 - 00001203 _____ C:\Users\Public\Desktop\VMware Workstation Pro.lnk
- 2017-07-01 21:32 - 2017-07-01 21:32 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VMware
- 2017-07-01 21:32 - 2017-07-01 21:32 - 00000000 ____D C:\Program Files\Common Files\VMware
- 2017-07-01 21:26 - 2017-07-01 21:27 - 299983712 _____ C:\Users\Qwerty\Downloads\VMware Workstation Pro 12.1.1 Build 3770994 + Keys [SadeemPC].zip
- 2017-07-01 21:24 - 2017-07-01 21:24 - 00259868 _____ C:\Users\Qwerty\Downloads\Dream+Protector+Advanced.zip
- 2017-06-30 10:17 - 2017-06-30 10:17 - 00001068 _____ C:\Users\Public\Desktop\Hotspot Shield.lnk
- 2017-06-30 10:17 - 2017-06-30 10:17 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hotspot Shield
- 2017-06-29 21:41 - 2017-06-29 21:41 - 00000000 ____D C:\Windows\SysWOW64\Hotspot Shield
- 2017-06-29 20:51 - 2017-06-29 20:51 - 00000000 ____D C:\Program Files\Application Verifier
- 2017-06-29 20:51 - 2017-06-29 20:51 - 00000000 ____D C:\Program Files (x86)\Application Verifier
- 2017-06-29 20:50 - 2017-06-29 20:51 - 00000000 ____D C:\ProgramData\Windows App Certification Kit
- 2017-06-29 20:50 - 2017-06-29 20:51 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Kits
- 2017-06-29 20:44 - 2017-06-29 20:44 - 00000000 ____D C:\Program Files (x86)\HTML Help Workshop
- 2017-06-29 20:42 - 2017-06-29 20:42 - 00001422 _____ C:\Users\Qwerty\Documents\petyavaccine.bat
- 2017-06-29 20:42 - 2017-06-29 20:42 - 00000126 ____R C:\Windows\perfc.dll
- 2017-06-29 20:42 - 2017-06-29 20:42 - 00000126 ____R C:\Windows\perfc.dat
- 2017-06-29 20:42 - 2017-06-29 20:42 - 00000126 ____R C:\Windows\perfc
- 2017-06-29 20:35 - 2017-06-29 20:35 - 00087836 _____ C:\Users\Qwerty\Downloads\Lilith-master.zip
- 2017-06-29 20:35 - 2017-06-29 20:35 - 00000000 ____D C:\Users\Qwerty\Downloads\lilith
- 2017-06-29 19:37 - 2017-06-29 19:37 - 00000016 _____ C:\Users\Qwerty\Documents\conrete5.txt
- 2017-06-29 19:37 - 2017-06-29 19:37 - 00000000 ____D C:\Users\Qwerty\Documents\New folder
- 2017-06-29 19:04 - 2017-06-29 19:04 - 00000000 ____D C:\Users\Qwerty\Downloads\YWW_ziperto.com.part1
- 2017-06-29 18:59 - 2017-06-29 19:02 - 501009349 _____ C:\Users\Qwerty\Downloads\YWW_ziperto.com.part6.rar
- 2017-06-29 18:58 - 2017-06-29 19:03 - 1048576000 _____ C:\Users\Qwerty\Downloads\YWW_ziperto.com.part5.rar
- 2017-06-29 18:58 - 2017-06-29 19:02 - 1048576000 _____ C:\Users\Qwerty\Downloads\YWW_ziperto.com.part4.rar
- 2017-06-29 18:58 - 2017-06-29 19:02 - 1048576000 _____ C:\Users\Qwerty\Downloads\YWW_ziperto.com.part3.rar
- 2017-06-29 18:57 - 2017-06-29 19:01 - 1048576000 _____ C:\Users\Qwerty\Downloads\YWW_ziperto.com.part2.rar
- 2017-06-29 18:57 - 2017-06-29 18:59 - 1048576000 _____ C:\Users\Qwerty\Downloads\YWW_ziperto.com.part1.rar
- 2017-06-28 20:31 - 2017-06-28 21:32 - 00000000 ____D C:\Users\Qwerty\AppData\Local\LoiLo
- 2017-06-28 20:31 - 2017-06-28 20:31 - 00001195 _____ C:\Users\Public\Desktop\Easy Video Editor LoiLo.lnk
- 2017-06-28 20:31 - 2017-06-28 20:31 - 00001026 _____ C:\Users\Public\Desktop\LoiLo Game Recorder.lnk
- 2017-06-28 20:31 - 2017-06-28 20:31 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LoiLoScope 2
- 2017-06-28 20:31 - 2017-06-28 20:31 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LoiLo Game Recorder
- 2017-06-28 20:31 - 2017-06-28 20:31 - 00000000 ____D C:\Program Files\LoiLo
- 2017-06-28 20:30 - 2017-06-28 20:30 - 00000000 ____D C:\Program Files (x86)\LoiLo
- 2017-06-28 20:29 - 2017-06-28 20:29 - 74713080 _____ (LoiLo inc. ) C:\Users\Qwerty\Downloads\LoiLoGameRecorder1.1.0.1.exe
- 2017-06-28 19:26 - 2017-06-28 19:26 - 00000000 ____D C:\Users\Qwerty\Downloads\mk8
- 2017-06-28 18:55 - 2017-06-28 18:55 - 00015863 _____ C:\Users\Qwerty\Downloads\Mario.Kart.8.WiiU.torrent
- 2017-06-28 18:43 - 2017-06-28 20:20 - 00000000 ____D C:\Users\Qwerty\Downloads\cemu
- 2017-06-28 18:35 - 2017-06-28 18:35 - 02311611 _____ C:\Users\Qwerty\Downloads\cemu_1.8.0.zip
- 2017-06-28 17:48 - 2017-06-28 17:48 - 00336123 _____ C:\Users\Qwerty\Downloads\FPS_Limiter_0.2.zip
- 2017-06-28 17:48 - 2017-06-28 17:48 - 00000000 ____D C:\Users\Qwerty\Downloads\fpslimiter
- 2017-06-27 22:08 - 2017-06-27 22:08 - 00008135 _____ C:\Users\Qwerty\Downloads\AppOnFly for Windows users.rdp
- 2017-06-27 16:42 - 2017-06-27 16:42 - 123669848 _____ (Oracle Corporation) C:\Users\Qwerty\Downloads\VirtualBox-5.1.22-115126-Win.exe
- 2017-06-27 16:35 - 2017-06-27 16:36 - 262784320 _____ C:\Users\Qwerty\Downloads\wnjviz.MOV
- 2017-06-26 21:47 - 2017-06-30 10:17 - 00000000 ____D C:\Program Files (x86)\Hotspot Shield
- 2017-06-26 21:46 - 2017-06-30 10:17 - 00000000 ____D C:\ProgramData\Hotspot Shield
- 2017-06-26 21:45 - 2017-06-26 21:45 - 00000000 ____D C:\Users\Qwerty\Downloads\Hotspot Shield VPN Elite 6.20.30 + Patch [CracksNow]
- 2017-06-26 21:36 - 2017-06-26 21:44 - 00000000 ____D C:\Users\Qwerty\Downloads\Windows 7 SP1 Ultimate (64 Bit)
- 2017-06-26 18:08 - 2017-07-02 12:39 - 00000000 ____D C:\Users\Qwerty\Downloads\d3d
- 2017-06-26 18:08 - 2017-06-26 18:08 - 00217335 _____ C:\Users\Qwerty\Downloads\D3DOverrider.7z
- 2017-06-26 18:02 - 2017-06-26 18:02 - 00636326 _____ C:\Users\Qwerty\Downloads\Release (1).zip
- 2017-06-26 17:52 - 2017-06-26 17:52 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\Cxbx-Reloaded
- 2017-06-26 17:51 - 2017-06-26 17:51 - 00639036 _____ C:\Users\Qwerty\Downloads\Release.zip
- 2017-06-26 17:22 - 2017-06-26 17:22 - 00131456 _____ C:\Users\Qwerty\Downloads\Cxbx-0.7.9-Pre4-Trace.zip
- 2017-06-26 17:12 - 2017-06-26 17:15 - 1616649475 _____ C:\Users\Qwerty\Downloads\Simpsons - Hit and Run [!].7z
- 2017-06-26 17:09 - 2017-06-26 18:03 - 00000000 ____D C:\Users\Qwerty\Documents\xbox
- 2017-06-26 17:09 - 2017-06-26 17:09 - 01003490 _____ C:\Users\Qwerty\Downloads\Xeon_10.rar
- 2017-06-26 16:49 - 2017-06-26 16:49 - 98136542 _____ C:\Users\Qwerty\Downloads\Mario Kart 7 (USA) [Decrypted].7z.002
- 2017-06-26 16:48 - 2017-06-26 16:49 - 524288000 _____ C:\Users\Qwerty\Downloads\Mario Kart 7 (USA) [Decrypted].7z.001
- 2017-06-26 16:34 - 2017-06-26 16:34 - 01982110 _____ C:\Users\Qwerty\Downloads\user.zip
- 2017-06-26 16:31 - 2017-06-26 16:31 - 03145728 _____ C:\Users\Qwerty\Downloads\shared_font.bin
- 2017-06-26 16:26 - 2017-07-08 16:52 - 00000000 ____D C:\Users\Qwerty\AppData\Local\SquirrelTemp
- 2017-06-26 16:26 - 2017-07-08 13:22 - 00002230 _____ C:\Users\Qwerty\Desktop\Citra Edge.lnk
- 2017-06-26 16:26 - 2017-07-08 13:22 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Citra Development Team
- 2017-06-26 16:26 - 2017-07-08 13:22 - 00000000 ____D C:\Users\Qwerty\AppData\Local\citra
- 2017-06-26 16:25 - 2017-06-26 16:25 - 27684352 _____ (Citra Development Team) C:\Users\Qwerty\Downloads\CitraSetup.exe
- 2017-06-26 16:12 - 2017-06-26 16:14 - 475057728 _____ C:\Users\Qwerty\Downloads\acnl usa MYGYMPARTNER.rar
- 2017-06-25 13:06 - 2017-06-25 13:06 - 00002794 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC
- 2017-06-25 13:06 - 2017-06-25 13:06 - 00000822 _____ C:\Users\Public\Desktop\CCleaner.lnk
- 2017-06-25 13:06 - 2017-06-25 13:06 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
- 2017-06-25 13:06 - 2017-06-25 13:06 - 00000000 ____D C:\Program Files\CCleaner
- 2017-06-25 13:05 - 2017-06-25 13:05 - 09598376 _____ (Piriform Ltd) C:\Users\Qwerty\Downloads\ccsetup531.exe
- 2017-06-24 18:34 - 2017-06-24 18:34 - 00000000 ____D C:\Users\Qwerty\Documents\Dolphin Emulator
- 2017-06-24 18:32 - 2017-06-24 18:32 - 13042028 _____ C:\Users\Qwerty\Downloads\dolphin-master-5.0-4482-x64.7z
- 2017-06-24 18:32 - 2017-06-24 18:32 - 00000000 ____D C:\Users\Qwerty\Downloads\Dolphin
- 2017-06-24 17:41 - 2017-06-24 17:42 - 1165150683 _____ C:\Users\Qwerty\Downloads\Simpsons, The - Hit & Run (USA) (1).7z
- 2017-06-24 15:50 - 2017-06-24 15:50 - 00005592 _____ C:\Users\Qwerty\Downloads\rdp-mixed.txt
- 2017-06-23 21:15 - 2017-06-23 21:15 - 00001539 _____ C:\Users\Qwerty\Desktop\WALTR2-PRO.lnk
- 2017-06-23 21:15 - 2017-06-23 21:15 - 00000393 _____ C:\Users\Qwerty\Desktop\RunAsDate.cfg
- 2017-06-23 21:15 - 2016-10-10 13:14 - 00032976 _____ C:\Users\Qwerty\Desktop\RunAsDate.exe
- 2017-06-23 21:10 - 2017-06-23 21:10 - 00035563 _____ C:\Users\Qwerty\Downloads\runasdate.zip
- 2017-06-23 21:06 - 2017-06-23 21:06 - 00000784 _____ C:\Users\Public\Desktop\WALTR2.lnk
- 2017-06-23 21:06 - 2017-06-23 21:06 - 00000000 ____D C:\ProgramData\Softorino
- 2017-06-23 21:06 - 2017-06-23 21:06 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WALTR2
- 2017-06-23 21:06 - 2017-06-23 21:06 - 00000000 ____D C:\Program Files\WALTR2
- 2017-06-23 21:05 - 2017-06-23 21:05 - 52983632 _____ (Softorino, Inc. ) C:\Users\Qwerty\Downloads\waltr2windows_2.0.21.exe
- 2017-06-23 20:42 - 2017-06-23 20:47 - 1422712832 _____ C:\Users\Qwerty\Downloads\Scooby-Doo.Pirates.Ahoy.2006.WEB-DLRip.1.36.Rus.Eng.Deadmauvlad.avi
- 2017-06-23 20:36 - 2017-06-23 20:38 - 782882816 _____ C:\Users\Qwerty\Downloads\Scooby-Doo.Pirates.Ahoy.2006.WEB-DLRip.Deadmauvlad.avi
- 2017-06-23 12:03 - 2017-06-23 12:03 - 01725199 _____ (Inekman) C:\Users\Qwerty\AppData\Roaming\Nvidia.exe
- 2017-06-21 21:42 - 2017-06-21 21:42 - 00000000 ____D C:\Users\Qwerty\Downloads\Pokemon - Yellow Version (UE) [C][!]
- 2017-06-21 21:42 - 2017-06-21 21:42 - 00000000 ____D C:\Users\Qwerty\Downloads\Pokemon - Crystal Version (UE) (V1.1) [C][!]
- 2017-06-21 21:40 - 2017-06-21 21:40 - 01030559 _____ C:\Users\Qwerty\Downloads\Pokemon - Crystal Version (UE) (V1.1) [C][!].zip
- 2017-06-21 21:39 - 2017-06-21 21:39 - 00512177 _____ C:\Users\Qwerty\Downloads\Pokemon - Yellow Version (UE) [C][!].zip
- 2017-06-21 21:33 - 2017-06-26 16:26 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\Citra
- 2017-06-21 21:32 - 2017-06-21 21:33 - 00000000 ____D C:\Users\Qwerty\Downloads\sonic
- 2017-06-21 21:31 - 2017-06-21 21:32 - 578185330 _____ C:\Users\Qwerty\Downloads\SGEN-USA-DecrTD-Ziperto.rar
- 2017-06-21 21:23 - 2017-06-21 21:24 - 134941192 _____ C:\Users\Qwerty\Downloads\RetroArch.7z
- 2017-06-21 21:22 - 2017-06-26 16:23 - 00000000 ____D C:\Users\Qwerty\Documents\retroarch
- 2017-06-21 21:22 - 2017-06-21 21:22 - 09195939 _____ C:\Users\Qwerty\Downloads\2017-06-21_RetroArch.7z
- 2017-06-21 19:44 - 2017-07-09 00:16 - 00000000 ____D C:\ProgramData\VMware
- 2017-06-21 19:44 - 2017-06-21 19:44 - 00001449 _____ C:\Users\Public\Desktop\Start Andy.lnk
- 2017-06-21 19:44 - 2017-06-21 19:44 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Andy
- 2017-06-21 19:31 - 2017-06-21 19:31 - 00000000 ____D C:\Users\Qwerty\Andy
- 2017-06-21 19:30 - 2017-06-21 19:44 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\Andy
- 2017-06-21 19:30 - 2017-06-21 19:31 - 00000000 ____D C:\Program Files\Andy
- 2017-06-21 19:30 - 2017-06-21 19:30 - 00000000 ____D C:\Users\Qwert\Andy
- 2017-06-21 19:30 - 2017-06-21 19:30 - 00000000 ____D C:\Users\Qwert
- 2017-06-21 19:22 - 2017-06-21 19:22 - 00000000 ____D C:\Users\Qwerty\.android
- 2017-06-21 19:21 - 2017-06-21 19:21 - 00000045 _____ C:\Users\Qwerty\nuuid.ini
- 2017-06-21 19:21 - 2017-06-21 19:21 - 00000041 _____ C:\Users\Qwerty\inst.ini
- 2017-06-21 19:21 - 2017-06-21 19:21 - 00000000 ____D C:\Users\Qwerty\vmlogs
- 2017-06-21 19:21 - 2017-06-21 19:21 - 00000000 ____D C:\Users\Qwerty\Nox_share
- 2017-06-21 19:19 - 2017-06-21 19:28 - 00000000 ____D C:\Users\Qwerty\AppData\Local\Nox
- 2017-06-21 19:19 - 2017-06-21 19:28 - 00000000 ____D C:\Program Files (x86)\Nox
- 2017-06-21 19:17 - 2017-06-21 19:18 - 305630088 _____ (Duodian Technology Co. Ltd.) C:\Users\Qwerty\Downloads\techapple-nox_setup_v3.8.1.1_full.exe
- 2017-06-21 15:47 - 2017-06-21 15:48 - 07517264 _____ (RealVNC Ltd) C:\Users\Qwerty\Downloads\VNC-Viewer-6.1.1-Windows-64bit (3).exe
- 2017-06-21 15:47 - 2017-06-21 15:48 - 07517264 _____ (RealVNC Ltd) C:\Users\Qwerty\Downloads\VNC-Viewer-6.1.1-Windows-64bit (2).exe
- 2017-06-21 15:47 - 2017-06-21 15:47 - 07517264 _____ (RealVNC Ltd) C:\Users\Qwerty\Downloads\VNC-Viewer-6.1.1-Windows-64bit.exe
- 2017-06-21 15:47 - 2017-06-21 15:47 - 07517264 _____ (RealVNC Ltd) C:\Users\Qwerty\Downloads\VNC-Viewer-6.1.1-Windows-64bit (1).exe
- 2017-06-20 19:16 - 2017-06-20 19:16 - 00002184 _____ C:\Users\Qwerty\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\EmEditor.lnk
- 2017-06-20 19:16 - 2017-06-20 19:16 - 00002176 _____ C:\Users\Qwerty\Desktop\EmEditor.lnk
- 2017-06-20 19:16 - 2017-06-20 19:16 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\Emurasoft
- 2017-06-20 19:16 - 2017-06-20 19:16 - 00000000 ____D C:\Users\Qwerty\AppData\Local\Emurasoft
- 2017-06-20 19:16 - 2017-06-20 19:16 - 00000000 ____D C:\ProgramData\Emurasoft
- 2017-06-20 19:15 - 2017-06-20 19:15 - 07077008 _____ (Emurasoft, Inc.) C:\Users\Qwerty\Downloads\emed64_16.9.3.exe
- 2017-06-20 19:15 - 2017-06-20 19:15 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\Emurasoft, Inc
- 2017-06-20 19:14 - 2017-06-20 19:14 - 00375954 _____ C:\Users\Qwerty\Downloads\LTFViewr.zip
- 2017-06-20 19:11 - 2017-06-20 19:11 - 00051712 _____ C:\Users\Qwerty\Downloads\Large Text File Reader.exe
- 2017-06-20 19:10 - 2017-06-20 19:10 - 00888094 _____ C:\Users\Qwerty\Documents\test.vbs
- 2017-06-20 19:09 - 2017-06-20 19:09 - 04118001 _____ C:\Users\Qwerty\Downloads\Exe+to+VBS.zip
- 2017-06-20 19:09 - 2014-11-24 08:15 - 15530909 _____ C:\Users\Qwerty\Documents\Exe to VBS.exe
- 2017-06-20 19:01 - 2017-06-20 19:03 - 00000318 _____ C:\Users\Qwerty\Documents\dl.vbs
- 2017-06-19 20:04 - 2017-06-19 20:04 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\RealVNC
- 2017-06-19 20:04 - 2017-06-19 20:04 - 00000000 ____D C:\Users\Qwerty\AppData\Local\RealVNC
- 2017-06-19 18:32 - 2017-06-19 18:32 - 00000322 _____ C:\Users\Qwerty\Desktop\iExplorer.appref-ms
- 2017-06-19 18:32 - 2017-06-19 18:32 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Macroplant LLC
- 2017-06-19 18:18 - 2017-06-19 18:18 - 00597016 _____ () C:\Users\Qwerty\Downloads\iExplorerSetup.exe
- 2017-06-19 18:12 - 2017-06-19 18:12 - 00001060 _____ C:\Users\Public\Desktop\iFunbox.lnk
- 2017-06-19 18:12 - 2017-06-19 18:12 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\iFunbox_UserCache
- 2017-06-19 18:12 - 2017-06-19 18:12 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\i-Funbox DevTeam
- 2017-06-19 18:12 - 2017-06-19 18:12 - 00000000 ____D C:\Program Files (x86)\i-Funbox DevTeam
- 2017-06-19 18:10 - 2017-06-19 18:10 - 80762908 _____ C:\Users\Qwerty\Downloads\RetroArch.deb
- 2017-06-19 18:10 - 2017-06-19 18:10 - 35156014 _____ (iFunbox DevTeam ) C:\Users\Qwerty\Downloads\ifunbox_v4106_setup.exe
- 2017-06-19 18:05 - 2017-06-19 18:06 - 166217983 _____ C:\Users\Qwerty\Downloads\RetroArch.zip
- 2017-06-19 16:55 - 2017-06-19 16:55 - 00000000 ____D C:\Users\Qwerty\Downloads\Simpsons, The - Road Rage (Europe) (En,Fr,De,Es,It)
- 2017-06-19 16:53 - 2017-06-19 16:55 - 302774010 _____ C:\Users\Qwerty\Downloads\Simpsons, The - Road Rage (Europe) (En,Fr,De,Es,It).7z
- 2017-06-19 07:40 - 2017-06-19 07:40 - 00000000 ____D C:\Users\Qwerty\Downloads\semirestore9
- 2017-06-19 07:38 - 2017-06-19 07:38 - 01241877 _____ C:\Users\Qwerty\Downloads\SemiRestore9-Windows-1.0.4.zip
- 2017-06-18 14:42 - 2017-06-18 14:42 - 00000000 ____D C:\Users\Qwerty\Downloads\The Simpsons Hit And Run PS2
- 2017-06-18 14:40 - 2017-06-18 14:41 - 13380830 _____ C:\Users\Qwerty\Downloads\ps2_bios.zip
- 2017-06-18 14:40 - 2017-06-18 14:40 - 00000000 ____D C:\Users\Qwerty\Documents\PCSX2
- 2017-06-18 14:39 - 2017-07-04 20:02 - 00000000 ____D C:\Program Files (x86)\PCSX2 1.4.0
- 2017-06-18 14:39 - 2017-06-18 14:41 - 693560658 _____ C:\Users\Qwerty\Downloads\Simpsons, The - Hit & Run (USA).7z
- 2017-06-18 14:39 - 2017-06-18 14:39 - 00001943 _____ C:\Users\Public\Desktop\PCSX2 1.4.0.lnk
- 2017-06-18 14:39 - 2017-06-18 14:39 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PCSX2
- 2017-06-18 14:38 - 2017-06-18 14:38 - 17837152 _____ C:\Users\Qwerty\Downloads\pcsx2-1.4.0-setup.exe
- 2017-06-17 20:48 - 2017-07-02 00:09 - 00000000 ____D C:\Users\Qwerty\Downloads\dynephant-master
- 2017-06-17 20:48 - 2017-06-17 20:48 - 03200868 _____ C:\Users\Qwerty\Downloads\dynephant-master.zip
- 2017-06-17 20:48 - 2017-06-17 20:48 - 00000000 ____D C:\dynephant
- 2017-06-17 20:47 - 2017-06-17 20:47 - 01228800 _____ C:\Users\Qwerty\Downloads\ddnsupdater_2.1-169.spk
- 2017-06-16 19:48 - 2017-06-16 20:05 - 1386748959 _____ C:\Users\Qwerty\Desktop\The Simpsons - Hit & Run.7z
- 2017-06-16 19:34 - 2017-06-16 19:36 - 68959074 _____ C:\Users\Qwerty\Documents\The Simpsons - Hit & Run.7z
- 2017-06-15 17:40 - 2017-06-15 17:40 - 03713472 _____ C:\Users\Qwerty\Downloads\Lucas' Simpsons Hit & Run Mod Launcher 1.15.3.zip
- 2017-06-15 16:42 - 2017-06-15 16:43 - 183880504 _____ (Rockstar Games) C:\Users\Qwerty\Downloads\GTAV_Setup_Tool.exe
- 2017-06-15 12:53 - 2017-06-15 12:53 - 00042064 _____ (Anchorfree Inc.) C:\Windows\system32\Drivers\taphss6.sys
- 2017-06-14 17:27 - 2017-06-14 17:27 - 00000458 _____ C:\memory.txt
- 2017-06-14 17:19 - 2017-06-14 17:19 - 01469560 _____ C:\Users\Qwerty\Downloads\CRASHDAY.V1.1.ALL.MACIOZO.NOCD.ZIP
- 2017-06-14 17:15 - 2017-06-14 17:15 - 00000000 ____D C:\ProgramData\Trymedia
- 2017-06-14 17:10 - 2017-06-14 17:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Atari
- 2017-06-14 17:10 - 2017-06-14 17:10 - 00000000 ____D C:\Program Files (x86)\Atari
- 2017-06-14 10:32 - 2017-06-02 09:28 - 02317824 _____ (Microsoft Corporation) C:\Windows\system32\tquery.dll
- 2017-06-14 10:32 - 2017-06-02 09:28 - 02222080 _____ (Microsoft Corporation) C:\Windows\system32\mssrch.dll
- 2017-06-14 10:32 - 2017-06-02 09:28 - 00778240 _____ (Microsoft Corporation) C:\Windows\system32\mssvp.dll
- 2017-06-14 10:32 - 2017-06-02 09:28 - 00491520 _____ (Microsoft Corporation) C:\Windows\system32\mssph.dll
- 2017-06-14 10:32 - 2017-06-02 09:28 - 00288256 _____ (Microsoft Corporation) C:\Windows\system32\mssphtb.dll
- 2017-06-14 10:32 - 2017-06-02 09:28 - 00115200 _____ (Microsoft Corporation) C:\Windows\system32\mssitlb.dll
- 2017-06-14 10:32 - 2017-06-02 09:28 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\mssprxy.dll
- 2017-06-14 10:32 - 2017-06-02 09:28 - 00075264 _____ (Microsoft Corporation) C:\Windows\system32\msscntrs.dll
- 2017-06-14 10:32 - 2017-06-02 09:28 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\msshooks.dll
- 2017-06-14 10:32 - 2017-06-02 09:11 - 00591872 _____ (Microsoft Corporation) C:\Windows\system32\SearchIndexer.exe
- 2017-06-14 10:32 - 2017-06-02 09:11 - 00249856 _____ (Microsoft Corporation) C:\Windows\system32\SearchProtocolHost.exe
- 2017-06-14 10:32 - 2017-06-02 09:10 - 00733696 _____ (Microsoft Corporation) C:\Windows\HelpPane.exe
- 2017-06-14 10:32 - 2017-06-02 09:10 - 00113664 _____ (Microsoft Corporation) C:\Windows\system32\SearchFilterHost.exe
- 2017-06-14 10:32 - 2017-06-02 09:09 - 01549824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tquery.dll
- 2017-06-14 10:32 - 2017-06-02 09:09 - 01400320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssrch.dll
- 2017-06-14 10:32 - 2017-06-02 09:09 - 00666624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssvp.dll
- 2017-06-14 10:32 - 2017-06-02 09:09 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssph.dll
- 2017-06-14 10:32 - 2017-06-02 09:09 - 00197120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssphtb.dll
- 2017-06-14 10:32 - 2017-06-02 09:09 - 00104448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssitlb.dll
- 2017-06-14 10:32 - 2017-06-02 09:09 - 00059392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msscntrs.dll
- 2017-06-14 10:32 - 2017-06-02 09:09 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssprxy.dll
- 2017-06-14 10:32 - 2017-06-02 08:58 - 00427520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchIndexer.exe
- 2017-06-14 10:32 - 2017-06-02 08:58 - 00164352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchProtocolHost.exe
- 2017-06-14 10:32 - 2017-06-02 08:57 - 00086528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchFilterHost.exe
- 2017-06-14 10:32 - 2017-06-02 08:57 - 00009728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msshooks.dll
- 2017-06-14 10:32 - 2017-05-21 05:28 - 00154856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
- 2017-06-14 10:32 - 2017-05-21 05:28 - 00095464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
- 2017-06-14 10:32 - 2017-05-21 05:24 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
- 2017-06-14 10:32 - 2017-05-21 05:24 - 01212928 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
- 2017-06-14 10:32 - 2017-05-21 05:24 - 00730624 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
- 2017-06-14 10:32 - 2017-05-21 05:24 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
- 2017-06-14 10:32 - 2017-05-21 05:24 - 00463872 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
- 2017-06-14 10:32 - 2017-05-21 05:24 - 00345600 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
- 2017-06-14 10:32 - 2017-05-21 05:24 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
- 2017-06-14 10:32 - 2017-05-21 05:24 - 00312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
- 2017-06-14 10:32 - 2017-05-21 05:24 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
- 2017-06-14 10:32 - 2017-05-21 05:24 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll
- 2017-06-14 10:32 - 2017-05-21 05:24 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
- 2017-06-14 10:32 - 2017-05-21 05:24 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
- 2017-06-14 10:32 - 2017-05-21 05:24 - 00123904 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll
- 2017-06-14 10:32 - 2017-05-21 05:24 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
- 2017-06-14 10:32 - 2017-05-21 05:24 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
- 2017-06-14 10:32 - 2017-05-21 05:24 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
- 2017-06-14 10:32 - 2017-05-21 05:24 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
- 2017-06-14 10:32 - 2017-05-21 05:24 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
- 2017-06-14 10:32 - 2017-05-21 05:24 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
- 2017-06-14 10:32 - 2017-05-21 05:06 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
- 2017-06-14 10:32 - 2017-05-21 05:06 - 00666112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
- 2017-06-14 10:32 - 2017-05-21 05:06 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
- 2017-06-14 10:32 - 2017-05-21 05:06 - 00342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
- 2017-06-14 10:32 - 2017-05-21 05:06 - 00261120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
- 2017-06-14 10:32 - 2017-05-21 05:06 - 00254464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
- 2017-06-14 10:32 - 2017-05-21 05:06 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
- 2017-06-14 10:32 - 2017-05-21 05:06 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
- 2017-06-14 10:32 - 2017-05-21 05:06 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
- 2017-06-14 10:32 - 2017-05-21 05:06 - 00141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll
- 2017-06-14 10:32 - 2017-05-21 05:06 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
- 2017-06-14 10:32 - 2017-05-21 05:06 - 00082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcrypt.dll
- 2017-06-14 10:32 - 2017-05-21 05:06 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
- 2017-06-14 10:32 - 2017-05-21 05:06 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
- 2017-06-14 10:32 - 2017-05-21 05:06 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
- 2017-06-14 10:32 - 2017-05-21 05:06 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
- 2017-06-14 10:32 - 2017-05-21 04:55 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
- 2017-06-14 10:32 - 2017-05-21 04:48 - 00291328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
- 2017-06-14 10:32 - 2017-05-21 04:48 - 00159744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
- 2017-06-14 10:32 - 2017-05-21 04:48 - 00129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
- 2017-06-14 10:32 - 2017-05-21 04:47 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
- 2017-06-14 10:32 - 2017-05-21 04:46 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
- 2017-06-14 10:32 - 2017-05-21 04:42 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
- 2017-06-14 10:32 - 2017-05-12 19:27 - 00631176 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
- 2017-06-14 10:32 - 2017-05-12 19:26 - 05547752 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
- 2017-06-14 10:32 - 2017-05-12 19:26 - 00706792 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
- 2017-06-14 10:32 - 2017-05-12 19:26 - 00382696 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
- 2017-06-14 10:32 - 2017-05-12 19:24 - 01732864 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
- 2017-06-14 10:32 - 2017-05-12 19:22 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
- 2017-06-14 10:32 - 2017-05-12 19:22 - 00880640 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
- 2017-06-14 10:32 - 2017-05-12 19:22 - 00806912 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll
- 2017-06-14 10:32 - 2017-05-12 19:22 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
- 2017-06-14 10:32 - 2017-05-12 19:22 - 00419840 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
- 2017-06-14 10:32 - 2017-05-12 19:22 - 00405504 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
- 2017-06-14 10:32 - 2017-05-12 19:22 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
- 2017-06-14 10:32 - 2017-05-12 19:22 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
- 2017-06-14 10:32 - 2017-05-12 19:22 - 00215552 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
- 2017-06-14 10:32 - 2017-05-12 19:22 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
- 2017-06-14 10:32 - 2017-05-12 19:22 - 00063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
- 2017-06-14 10:32 - 2017-05-12 19:22 - 00059904 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
- 2017-06-14 10:32 - 2017-05-12 19:22 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
- 2017-06-14 10:32 - 2017-05-12 19:22 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
- 2017-06-14 10:32 - 2017-05-12 19:22 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
- 2017-06-14 10:32 - 2017-05-12 19:22 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
- 2017-06-14 10:32 - 2017-05-12 19:22 - 00034816 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
- 2017-06-14 10:32 - 2017-05-12 19:22 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
- 2017-06-14 10:32 - 2017-05-12 19:22 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
- 2017-06-14 10:32 - 2017-05-12 19:22 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
- 2017-06-14 10:32 - 2017-05-12 19:22 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
- 2017-06-14 10:32 - 2017-05-12 19:22 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
- 2017-06-14 10:32 - 2017-05-12 19:22 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
- 2017-06-14 10:32 - 2017-05-12 19:22 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
- 2017-06-14 10:32 - 2017-05-12 19:22 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
- 2017-06-14 10:32 - 2017-05-12 19:22 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
- 2017-06-14 10:32 - 2017-05-12 19:22 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
- 2017-06-14 10:32 - 2017-05-12 19:22 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
- 2017-06-14 10:32 - 2017-05-12 19:22 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
- 2017-06-14 10:32 - 2017-05-12 19:22 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
- 2017-06-14 10:32 - 2017-05-12 19:22 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
- 2017-06-14 10:32 - 2017-05-12 19:22 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
- 2017-06-14 10:32 - 2017-05-12 19:22 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
- 2017-06-14 10:32 - 2017-05-12 19:22 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
- 2017-06-14 10:32 - 2017-05-12 19:22 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
- 2017-06-14 10:32 - 2017-05-12 19:22 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
- 2017-06-14 10:32 - 2017-05-12 19:22 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
- 2017-06-14 10:32 - 2017-05-12 19:22 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
- 2017-06-14 10:32 - 2017-05-12 19:22 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
- 2017-06-14 10:32 - 2017-05-12 19:22 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
- 2017-06-14 10:32 - 2017-05-12 19:22 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
- 2017-06-14 10:32 - 2017-05-12 19:22 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
- 2017-06-14 10:32 - 2017-05-12 19:22 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
- 2017-06-14 10:32 - 2017-05-12 19:22 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
- 2017-06-14 10:32 - 2017-05-12 19:22 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
- 2017-06-14 10:32 - 2017-05-12 19:22 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
- 2017-06-14 10:32 - 2017-05-12 19:22 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
- 2017-06-14 10:32 - 2017-05-12 19:22 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
- 2017-06-14 10:32 - 2017-05-12 19:22 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
- 2017-06-14 10:32 - 2017-05-12 19:07 - 04001000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
- 2017-06-14 10:32 - 2017-05-12 19:07 - 03945704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
- 2017-06-14 10:32 - 2017-05-12 19:07 - 00308456 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
- 2017-06-14 10:32 - 2017-05-12 19:04 - 01314112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
- 2017-06-14 10:32 - 2017-05-12 19:03 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
- 2017-06-14 10:32 - 2017-05-12 19:03 - 00644096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
- 2017-06-14 10:32 - 2017-05-12 19:03 - 00629760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll
- 2017-06-14 10:32 - 2017-05-12 19:03 - 00313344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
- 2017-06-14 10:32 - 2017-05-12 19:03 - 00275456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
- 2017-06-14 10:32 - 2017-05-12 19:03 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
- 2017-06-14 10:32 - 2017-05-12 19:03 - 00050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll
- 2017-06-14 10:32 - 2017-05-12 19:03 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
- 2017-06-14 10:32 - 2017-05-12 19:03 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
- 2017-06-14 10:32 - 2017-05-12 19:03 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
- 2017-06-14 10:32 - 2017-05-12 19:03 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
- 2017-06-14 10:32 - 2017-05-12 19:03 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
- 2017-06-14 10:32 - 2017-05-12 19:03 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
- 2017-06-14 10:32 - 2017-05-12 19:03 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
- 2017-06-14 10:32 - 2017-05-12 19:03 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
- 2017-06-14 10:32 - 2017-05-12 19:03 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
- 2017-06-14 10:32 - 2017-05-12 19:03 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
- 2017-06-14 10:32 - 2017-05-12 19:03 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
- 2017-06-14 10:32 - 2017-05-12 19:03 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
- 2017-06-14 10:32 - 2017-05-12 19:03 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
- 2017-06-14 10:32 - 2017-05-12 19:03 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
- 2017-06-14 10:32 - 2017-05-12 19:03 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
- 2017-06-14 10:32 - 2017-05-12 19:03 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
- 2017-06-14 10:32 - 2017-05-12 19:03 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
- 2017-06-14 10:32 - 2017-05-12 19:03 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
- 2017-06-14 10:32 - 2017-05-12 19:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
- 2017-06-14 10:32 - 2017-05-12 19:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
- 2017-06-14 10:32 - 2017-05-12 19:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
- 2017-06-14 10:32 - 2017-05-12 19:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
- 2017-06-14 10:32 - 2017-05-12 19:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
- 2017-06-14 10:32 - 2017-05-12 19:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
- 2017-06-14 10:32 - 2017-05-12 19:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
- 2017-06-14 10:32 - 2017-05-12 19:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
- 2017-06-14 10:32 - 2017-05-12 19:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
- 2017-06-14 10:32 - 2017-05-12 19:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
- 2017-06-14 10:32 - 2017-05-12 19:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
- 2017-06-14 10:32 - 2017-05-12 18:55 - 00148480 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
- 2017-06-14 10:32 - 2017-05-12 18:54 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
- 2017-06-14 10:32 - 2017-05-12 18:54 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
- 2017-06-14 10:32 - 2017-05-12 18:52 - 03222528 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
- 2017-06-14 10:32 - 2017-05-12 18:51 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
- 2017-06-14 10:32 - 2017-05-12 18:50 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
- 2017-06-14 10:32 - 2017-05-12 18:46 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
- 2017-06-14 10:32 - 2017-05-12 18:43 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
- 2017-06-14 10:32 - 2017-05-12 18:41 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
- 2017-06-14 10:32 - 2017-05-12 18:41 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
- 2017-06-14 10:32 - 2017-05-12 18:41 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
- 2017-06-14 10:32 - 2017-05-12 18:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
- 2017-06-14 10:32 - 2017-05-12 18:40 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
- 2017-06-14 10:32 - 2017-05-12 18:40 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
- 2017-06-14 10:32 - 2017-05-12 18:40 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
- 2017-06-14 10:32 - 2017-05-12 18:40 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
- 2017-06-14 10:32 - 2017-05-12 17:25 - 01251328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
- 2017-06-14 10:32 - 2017-05-12 16:58 - 01648128 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
- 2017-06-14 10:32 - 2017-05-12 16:58 - 01180160 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
- 2017-06-14 10:32 - 2017-05-10 16:33 - 00091368 _____ (Microsoft Corporation) C:\Windows\system32\MigAutoPlay.exe
- 2017-06-14 10:32 - 2017-05-10 16:29 - 14183936 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
- 2017-06-14 10:32 - 2017-05-10 16:29 - 03165184 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
- 2017-06-14 10:32 - 2017-05-10 16:29 - 01867776 _____ (Microsoft Corporation) C:\Windows\system32\ExplorerFrame.dll
- 2017-06-14 10:32 - 2017-05-10 16:29 - 00192512 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
- 2017-06-14 10:32 - 2017-05-10 16:29 - 00098816 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
- 2017-06-14 10:32 - 2017-05-10 16:28 - 00091136 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
- 2017-06-14 10:32 - 2017-05-10 16:16 - 00091368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MigAutoPlay.exe
- 2017-06-14 10:32 - 2017-05-10 16:14 - 02651136 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
- 2017-06-14 10:32 - 2017-05-10 16:13 - 00709120 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
- 2017-06-14 10:32 - 2017-05-10 16:13 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
- 2017-06-14 10:32 - 2017-05-10 16:13 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
- 2017-06-14 10:32 - 2017-05-10 16:13 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
- 2017-06-14 10:32 - 2017-05-10 16:13 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
- 2017-06-14 10:32 - 2017-05-10 16:13 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
- 2017-06-14 10:32 - 2017-05-10 16:12 - 12880896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
- 2017-06-14 10:32 - 2017-05-10 16:12 - 01499648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ExplorerFrame.dll
- 2017-06-14 10:32 - 2017-05-10 16:12 - 00174080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
- 2017-06-14 10:32 - 2017-05-10 16:00 - 00573440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
- 2017-06-14 10:32 - 2017-05-10 16:00 - 00093696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
- 2017-06-14 10:32 - 2017-05-10 16:00 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
- 2017-06-14 10:32 - 2017-05-10 16:00 - 00030208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
- 2017-06-14 10:32 - 2017-05-10 15:52 - 00117248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys
- 2017-06-14 10:32 - 2017-05-09 16:30 - 00757248 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll
- 2017-06-14 10:32 - 2017-05-09 16:29 - 00970240 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll
- 2017-06-14 10:32 - 2017-05-09 16:15 - 00071680 _____ C:\Windows\system32\PrintBrmUi.exe
- 2017-06-14 10:32 - 2017-05-09 16:11 - 00497664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll
- 2017-06-14 10:32 - 2017-05-07 16:33 - 00094440 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mountmgr.sys
- 2017-06-14 10:32 - 2017-05-07 16:29 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\msmmsp.dll
- 2017-06-14 10:32 - 2017-03-30 16:03 - 00046080 _____ (Microsoft Corporation) C:\Windows\system32\rundll32.exe
- 2017-06-14 10:32 - 2017-03-30 15:58 - 00045056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
- 2017-06-13 22:00 - 2017-06-13 22:00 - 00000000 ____D C:\Users\Qwerty\AppData\Local\Criterion Games
- 2017-06-13 21:58 - 2017-06-13 22:10 - 00000000 ____D C:\Users\Qwerty\Documents\Bully Scholarship Edition
- 2017-06-13 21:56 - 2017-06-13 21:56 - 00001425 _____ C:\Users\Public\Desktop\Burnout Paradise - Config Tool.lnk
- 2017-06-13 21:56 - 2017-06-13 21:56 - 00001415 _____ C:\Users\Public\Desktop\Burnout Paradise - The Ultimate Box.lnk
- 2017-06-13 21:56 - 2017-06-13 21:56 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Electronic Arts
- 2017-06-13 21:48 - 2017-06-13 21:48 - 00000000 ____D C:\Program Files (x86)\Electronic Arts
- 2017-06-13 21:11 - 2017-06-13 21:11 - 00001298 _____ C:\Users\Public\Desktop\Bully Scholarship Edition.lnk
- 2017-06-13 20:17 - 2017-06-13 20:17 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\Tenorshare
- 2017-06-13 20:16 - 2017-06-15 21:17 - 00002385 _____ C:\Users\Qwerty\Desktop\The Simpsons - Hit & Run.lnk
- 2017-06-13 20:16 - 2017-06-13 20:16 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\The Simpsons - Hit & Run
- 2017-06-13 20:16 - 2017-06-13 20:16 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\R.G. Mechanics
- 2017-06-13 20:15 - 2017-06-13 20:15 - 00000995 _____ C:\Users\Qwerty\Desktop\ReiBoot.lnk
- 2017-06-13 20:14 - 2017-06-13 20:15 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ReiBoot
- 2017-06-13 20:14 - 2017-06-13 20:15 - 00000000 ____D C:\Program Files (x86)\ReiBoot
- 2017-06-13 20:04 - 2017-06-13 20:04 - 00000000 ____D C:\Program Files (x86)\R.G. Mechanics
- 2017-06-13 19:54 - 2017-06-13 19:54 - 00015847 _____ C:\Users\Qwerty\Downloads\Bully.Scholarship.Edition.MULTi6-PROPHET.torrent
- 2017-06-13 16:39 - 2017-06-13 17:00 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\Apple Computer
- 2017-06-13 16:39 - 2017-06-13 16:39 - 00001753 _____ C:\Users\Public\Desktop\iTunes.lnk
- 2017-06-13 16:39 - 2017-06-13 16:39 - 00000000 ____D C:\Users\Qwerty\AppData\Local\Apple Computer
- 2017-06-13 16:39 - 2017-06-13 16:39 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
- 2017-06-13 16:37 - 2017-06-13 16:39 - 00000000 ____D C:\Program Files\iTunes
- 2017-06-13 16:37 - 2017-06-13 16:37 - 00000000 ____D C:\ProgramData\Apple Computer
- 2017-06-13 16:37 - 2017-06-13 16:37 - 00000000 ____D C:\Program Files\iPod
- 2017-06-13 16:36 - 2017-06-13 16:36 - 00002519 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
- 2017-06-13 16:36 - 2017-06-13 16:36 - 00000000 ____D C:\Windows\System32\Tasks\Apple
- 2017-06-13 16:36 - 2017-06-13 16:36 - 00000000 ____D C:\Users\Qwerty\AppData\Local\Apple
- 2017-06-13 16:36 - 2017-06-13 16:36 - 00000000 ____D C:\Program Files (x86)\Apple Software Update
- 2017-06-13 16:35 - 2017-06-13 16:35 - 00000000 ____D C:\Program Files\Bonjour
- 2017-06-13 16:35 - 2017-06-13 16:35 - 00000000 ____D C:\Program Files (x86)\Bonjour
- 2017-06-13 16:34 - 2017-06-13 16:35 - 00000000 ____D C:\Program Files\Common Files\Apple
- 2017-06-13 16:33 - 2017-06-13 16:36 - 00000000 ____D C:\ProgramData\Apple
- 2017-06-13 15:40 - 2017-06-25 13:08 - 00000000 ____D C:\Windows\Minidump
- 2017-06-12 21:21 - 2017-06-13 15:33 - 00000000 ____D C:\Users\Qwerty\AppData\Local\System3264
- 2017-06-12 17:00 - 2017-06-12 17:00 - 00001151 _____ C:\Users\Public\Desktop\CDBurnerXP.lnk
- 2017-06-12 17:00 - 2017-06-12 17:00 - 00001109 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CDBurnerXP.lnk
- 2017-06-12 17:00 - 2017-06-12 17:00 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\Canneverbe Limited
- 2017-06-12 17:00 - 2017-06-12 17:00 - 00000000 ____D C:\ProgramData\Canneverbe Limited
- 2017-06-12 17:00 - 2017-06-12 17:00 - 00000000 ____D C:\Program Files (x86)\CDBurnerXP
- 2017-06-12 16:17 - 2017-06-12 16:39 - 00000000 ____D C:\Users\Qwerty\Documents\American Epic
- 2017-06-12 16:14 - 2017-06-12 16:16 - 00000000 ____D C:\Users\Qwerty\American Epic
- 2017-06-12 16:09 - 2017-06-12 16:09 - 00675902 _____ C:\Users\Qwerty\Downloads\lame3.99.5.zip
- 2017-06-12 16:09 - 2017-06-12 16:09 - 00000000 ____D C:\Users\Qwerty\Documents\lame
- 2017-06-12 16:08 - 2017-06-12 16:08 - 00891865 _____ C:\Users\Qwerty\Downloads\lame3.99.5-64.zip
- 2017-06-12 16:04 - 2017-06-12 16:04 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\EAC
- 2017-06-12 16:03 - 2017-06-12 16:04 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\AccurateRip
- 2017-06-12 16:03 - 2017-06-12 16:03 - 00001074 _____ C:\Users\Public\Desktop\Exact Audio Copy.lnk
- 2017-06-12 16:03 - 2017-06-12 16:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Exact Audio Copy
- 2017-06-12 16:03 - 2017-06-12 16:03 - 00000000 ____D C:\Program Files (x86)\Exact Audio Copy
- 2017-06-11 15:37 - 2017-06-11 15:41 - 00000000 ____D C:\Users\Qwerty\Downloads\netcrack
- 2017-06-11 15:37 - 2017-06-11 15:37 - 00028431 _____ C:\Users\Qwerty\Downloads\Netflix-Cracker-master.zip
- 2017-06-10 23:59 - 2017-06-10 23:59 - 00012872 _____ (SurfRight B.V.) C:\Windows\system32\bootdelete.exe
- 2017-06-10 23:59 - 2017-06-10 23:59 - 00003296 _____ C:\Windows\system32\bootdelete.lst
- 2017-06-10 23:39 - 2017-06-25 11:51 - 00084256 _____ (Malwarebytes) C:\Windows\system32\Drivers\mwac.sys
- 2017-06-10 23:39 - 2017-06-24 15:48 - 00113592 _____ (Malwarebytes) C:\Windows\system32\Drivers\farflt.sys
- 2017-06-10 23:39 - 2017-06-24 15:48 - 00044960 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
- 2017-06-10 23:39 - 2017-06-10 23:39 - 00188312 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMChameleon.sys
- 2017-06-10 23:38 - 2017-07-09 00:17 - 00253856 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
- 2017-06-10 23:38 - 2017-06-30 12:26 - 00077376 _____ C:\Windows\system32\Drivers\mbae64.sys
- 2017-06-10 23:38 - 2017-06-10 23:38 - 00001867 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
- 2017-06-10 23:38 - 2017-06-10 23:38 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
- 2017-06-10 23:38 - 2017-06-10 23:38 - 00000000 ____D C:\ProgramData\Malwarebytes
- 2017-06-10 23:38 - 2017-06-10 23:38 - 00000000 ____D C:\Program Files\Malwarebytes
- 2017-06-10 23:37 - 2017-06-10 23:37 - 00000000 ____D C:\Program Files\HitmanPro
- 2017-06-10 23:36 - 2017-06-11 00:00 - 00000000 ____D C:\ProgramData\HitmanPro
- 2017-06-10 23:14 - 2017-06-10 23:54 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\Imminent
- 2017-06-10 23:14 - 2017-06-10 23:14 - 00000000 ____D C:\Users\Qwerty\AppData\Local\PhoenixGUI
- 2017-06-10 23:14 - 2017-06-10 23:14 - 00000000 ____D C:\PhoenixGUI
- 2017-06-10 21:17 - 2017-06-10 21:17 - 01931969 _____ C:\Users\Qwerty\Downloads\ProcessExplorer.zip
- 2017-06-10 18:35 - 2017-06-10 18:35 - 00063668 _____ C:\Users\Qwerty\Downloads\Venom Release.rar
- 2017-06-09 15:54 - 2017-06-09 15:56 - 00000000 ____D C:\Users\Qwerty\AppData\Local\PAYDAY 2
- 2017-06-09 15:54 - 2017-06-09 15:54 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
- 2017-06-09 15:54 - 2017-06-09 15:54 - 00000000 ____D C:\Program Files (x86)\AGEIA Technologies
- 2017-06-09 07:37 - 2015-07-16 20:12 - 04922368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
- 2017-06-09 07:37 - 2015-07-16 20:12 - 00269824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aaclient.dll
- 2017-06-09 07:37 - 2015-07-16 20:12 - 00037376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll
- 2017-06-09 07:37 - 2015-07-16 20:11 - 05779456 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
- 2017-06-09 07:37 - 2015-07-16 20:11 - 00322560 _____ (Microsoft Corporation) C:\Windows\system32\aaclient.dll
- 2017-06-09 07:37 - 2015-07-16 20:11 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
- 2017-06-09 07:37 - 2014-12-11 18:47 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
- 2017-06-09 07:37 - 2014-08-29 03:06 - 01125888 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
- 2017-06-09 07:37 - 2014-08-29 02:44 - 01050112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe
- ==================== One Month Modified files and folders ========
- (If an entry is included in the fixlist, the file/folder will be moved.)
- 2017-07-09 16:30 - 2017-05-12 22:20 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\Skype
- 2017-07-09 16:09 - 2017-05-13 01:20 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\vlc
- 2017-07-09 15:25 - 2017-05-12 21:10 - 00060496 _____ C:\Users\Qwerty\AppData\Local\GDIPFONTCACHEV1.DAT
- 2017-07-09 15:21 - 2017-05-12 21:30 - 00000000 ____D C:\ProgramData\Package Cache
- 2017-07-09 14:59 - 2017-05-12 21:00 - 00000000 ____D C:\Users\Qwerty
- 2017-07-09 14:59 - 2009-07-14 03:34 - 00000256 _____ C:\Windows\system.ini
- 2017-07-09 14:41 - 2017-05-13 01:11 - 00000000 ____D C:\Users\Qwerty\AppData\Local\CrashDumps
- 2017-07-09 14:28 - 2017-05-23 20:51 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\AIMP
- 2017-07-09 14:28 - 2017-05-12 21:27 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\TeamViewer
- 2017-07-09 14:28 - 2017-05-12 21:27 - 00000000 ____D C:\Program Files (x86)\Steam
- 2017-07-09 13:43 - 2009-07-14 06:13 - 00963626 _____ C:\Windows\system32\PerfStringBackup.INI
- 2017-07-09 13:43 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\inf
- 2017-07-09 00:26 - 2009-07-14 05:45 - 00026576 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
- 2017-07-09 00:26 - 2009-07-14 05:45 - 00026576 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
- 2017-07-09 00:19 - 2017-05-12 22:55 - 00000000 __SHD C:\Users\Qwerty\IntelGraphicsProfiles
- 2017-07-09 00:15 - 2017-05-21 21:54 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\uTorrent
- 2017-07-09 00:15 - 2017-05-13 15:12 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\Volume2
- 2017-07-09 00:14 - 2017-05-16 21:56 - 00000000 ____D C:\Program Files (x86)\Trillian56
- 2017-07-09 00:14 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
- 2017-07-07 20:20 - 2017-05-12 21:11 - 00002232 ____H C:\Users\Qwerty\Documents\Default.rdp
- 2017-07-07 18:10 - 2017-06-04 22:03 - 00000000 ____D C:\Users\Qwerty\.VirtualBox
- 2017-07-07 16:08 - 2009-07-14 04:20 - 00000000 ___HD C:\Windows\system32\GroupPolicy
- 2017-07-07 07:24 - 2017-05-12 21:27 - 00000000 ____D C:\Program Files (x86)\TeamViewer
- 2017-07-06 19:16 - 2017-06-05 16:29 - 00000000 ____D C:\Users\Qwerty\VirtualBox VMs
- 2017-07-05 22:30 - 2017-05-12 21:31 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\FileZilla
- 2017-07-04 20:17 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\LiveKernelReports
- 2017-07-03 17:53 - 2017-05-13 22:31 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\Kodi
- 2017-07-03 17:10 - 2017-05-12 21:27 - 00000971 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 12.lnk
- 2017-07-03 17:10 - 2017-05-12 21:27 - 00000959 _____ C:\Users\Public\Desktop\TeamViewer 12.lnk
- 2017-07-03 12:23 - 2017-05-14 02:25 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\VMware
- 2017-07-03 12:23 - 2017-05-14 02:25 - 00000000 ____D C:\Users\Qwerty\AppData\Local\VMware
- 2017-07-02 13:03 - 2017-06-04 21:24 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
- 2017-07-02 12:08 - 2017-06-06 21:37 - 00361336 _____ (AVAST Software) C:\Windows\system32\Drivers\aswvmm.sys
- 2017-07-02 12:07 - 2017-06-06 21:37 - 00003914 _____ C:\Windows\System32\Tasks\Avast Emergency Update
- 2017-07-02 12:07 - 2017-06-06 21:33 - 00000000 ____D C:\ProgramData\AVAST Software
- 2017-07-02 12:06 - 2017-06-06 21:37 - 01015848 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
- 2017-07-02 12:06 - 2017-06-06 21:37 - 00585608 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
- 2017-07-02 12:06 - 2017-06-06 21:37 - 00360792 _____ (AVAST Software) C:\Windows\system32\Drivers\aswvmm.sys.149899370806806
- 2017-07-02 12:06 - 2017-06-06 21:37 - 00343264 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbloga.sys
- 2017-07-02 12:06 - 2017-06-06 21:37 - 00319984 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbidsdrivera.sys
- 2017-07-02 12:06 - 2017-06-06 21:37 - 00198944 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbidsha.sys
- 2017-07-02 12:06 - 2017-06-06 21:37 - 00198768 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
- 2017-07-02 12:06 - 2017-06-06 21:37 - 00146664 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
- 2017-07-02 12:06 - 2017-06-06 21:37 - 00110352 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
- 2017-07-02 12:06 - 2017-06-06 21:37 - 00084392 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys
- 2017-07-02 12:06 - 2017-06-06 21:37 - 00057704 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbuniva.sys
- 2017-07-02 12:06 - 2017-06-06 21:37 - 00046984 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHwid.sys
- 2017-07-01 23:18 - 2017-05-12 21:32 - 00000000 ____D C:\ProgramData\Skype
- 2017-07-01 21:39 - 2017-05-14 02:26 - 00000000 ____D C:\Users\Qwerty\Documents\Virtual Machines
- 2017-07-01 21:32 - 2017-05-14 02:23 - 00001024 _____ C:\Windows\SysWOW64\%TMP%
- 2017-07-01 21:32 - 2017-05-13 03:27 - 00968612 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
- 2017-06-30 10:48 - 2017-06-05 21:24 - 00000000 ____D C:\Users\DefaultAppPool
- 2017-06-29 21:10 - 2017-05-15 19:29 - 00000000 ____D C:\Users\Qwerty\Documents\Visual Studio 2015
- 2017-06-29 20:48 - 2017-05-15 16:42 - 00000000 ____D C:\Program Files (x86)\Microsoft SDKs
- 2017-06-29 20:47 - 2017-05-15 16:42 - 00000000 ____D C:\Program Files (x86)\Windows Kits
- 2017-06-27 16:44 - 2017-06-04 22:02 - 00001076 _____ C:\Users\Public\Desktop\Oracle VM VirtualBox.lnk
- 2017-06-27 16:44 - 2017-06-04 22:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Oracle VM VirtualBox
- 2017-06-27 15:51 - 2017-06-05 16:20 - 00000000 ____D C:\Users\Qwerty\AppData\Local\Spotify
- 2017-06-27 10:06 - 2017-06-05 16:19 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\Spotify
- 2017-06-27 08:22 - 2017-05-12 21:11 - 00002195 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
- 2017-06-27 08:22 - 2017-05-12 21:11 - 00002183 _____ C:\Users\Public\Desktop\Google Chrome.lnk
- 2017-06-27 07:38 - 2017-05-19 15:43 - 00000000 ____D C:\Windows\pss
- 2017-06-25 13:08 - 2017-05-27 21:58 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\DAEMON Tools Lite
- 2017-06-25 13:08 - 2017-05-13 05:51 - 00000000 ____D C:\Windows\Panther
- 2017-06-25 13:08 - 2017-05-12 21:39 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\CoreFTP
- 2017-06-21 19:41 - 2017-05-14 02:21 - 00000000 ____D C:\Program Files (x86)\VMware
- 2017-06-21 19:20 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\Registration
- 2017-06-19 18:34 - 2017-05-12 21:10 - 00000000 ____D C:\Users\Qwerty\AppData\Local\Deployment
- 2017-06-18 21:46 - 2017-05-15 21:05 - 00000000 ____D C:\Users\Qwerty\AppData\LocalLow\Mozilla
- 2017-06-18 14:39 - 2017-05-13 00:59 - 00000000 ___HD C:\Windows\msdownld.tmp
- 2017-06-18 14:39 - 2017-05-13 00:59 - 00000000 ____D C:\Windows\SysWOW64\directx
- 2017-06-16 08:09 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache
- 2017-06-15 16:51 - 2017-05-12 21:40 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
- 2017-06-15 16:49 - 2009-07-14 04:20 - 00000000 __RHD C:\Users\Public\Libraries
- 2017-06-15 16:45 - 2017-05-13 00:59 - 00000000 ____D C:\Program Files (x86)\Mr DJ
- 2017-06-15 16:44 - 2017-05-12 23:37 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Rockstar Games
- 2017-06-15 16:44 - 2017-05-12 21:07 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
- 2017-06-15 16:43 - 2017-05-12 23:41 - 00000000 ____D C:\Users\Qwerty\Documents\Rockstar Games
- 2017-06-15 16:43 - 2017-05-12 23:41 - 00000000 ____D C:\Users\Qwerty\AppData\Local\Rockstar Games
- 2017-06-15 16:40 - 2017-05-12 23:39 - 00000000 ____D C:\Program Files (x86)\Rockstar Games
- 2017-06-15 16:40 - 2017-05-12 23:37 - 00000000 ____D C:\Program Files\Rockstar Games
- 2017-06-15 16:23 - 2009-07-14 05:45 - 00268392 _____ C:\Windows\system32\FNTCACHE.DAT
- 2017-06-15 16:21 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\migwiz
- 2017-06-15 16:21 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\migwiz
- 2017-06-14 22:03 - 2017-05-13 13:09 - 00000000 ____D C:\Windows\system32\MRT
- 2017-06-14 21:58 - 2017-05-13 13:09 - 133627792 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
- 2017-06-14 20:49 - 2017-05-15 21:05 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
- 2017-06-14 18:08 - 2017-05-13 01:22 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
- 2017-06-11 14:54 - 2017-06-07 07:48 - 00000000 ____D C:\Program Files (x86)\Remotr
- 2017-06-11 14:51 - 2017-05-12 21:29 - 00000871 _____ C:\Users\Public\Desktop\VLC media player.lnk
- 2017-06-11 14:32 - 2017-06-07 07:48 - 00000000 ____D C:\ProgramData\Remotr
- 2017-06-10 23:59 - 2017-05-24 07:14 - 00000000 ____D C:\Users\Qwerty\Downloads\Windows Loader v2.2.2
- 2017-06-10 00:21 - 2017-06-04 18:36 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\Sia-UI
- 2017-06-09 23:47 - 2017-05-12 21:33 - 00000000 ___RD C:\Program Files (x86)\Skype
- ==================== Files in the root of some directories =======
- 2017-07-06 17:10 - 2017-07-09 14:40 - 0000338 _____ () C:\Users\Qwerty\AppData\Roaming\basic.ini
- 2017-04-13 14:57 - 2017-04-13 14:57 - 1645928 _____ (Adobe Systems Incorporated) C:\Users\Qwerty\AppData\Roaming\NetframeworkD.exe
- 2017-04-14 03:48 - 2017-04-14 03:48 - 1930752 _____ (Microsoft Corporation) C:\Users\Qwerty\AppData\Roaming\NetframeworkG.exe
- 2017-06-23 12:03 - 2017-06-23 12:03 - 1725199 _____ (Inekman) C:\Users\Qwerty\AppData\Roaming\Nvidia.exe
- 2017-05-13 15:04 - 2017-05-13 15:04 - 0001524 _____ () C:\Users\Qwerty\AppData\Local\recently-used.xbel
- 2017-05-16 19:18 - 2017-05-21 00:21 - 0007598 _____ () C:\Users\Qwerty\AppData\Local\Resmon.ResmonCfg
- Files to move or delete:
- ====================
- C:\Users\Qwerty\AppData\Local\Temp\prp\sqb.exe
- C:\Users\Qwerty\RegSvcs.exe
- ==================== Bamital & volsnap ======================
- (There is no automatic fix for files that do not pass verification.)
- C:\Windows\system32\winlogon.exe => File is digitally signed
- C:\Windows\system32\wininit.exe => File is digitally signed
- C:\Windows\SysWOW64\wininit.exe => File is digitally signed
- C:\Windows\explorer.exe => File is digitally signed
- C:\Windows\SysWOW64\explorer.exe => File is digitally signed
- C:\Windows\system32\svchost.exe => File is digitally signed
- C:\Windows\SysWOW64\svchost.exe => File is digitally signed
- C:\Windows\system32\services.exe => File is digitally signed
- C:\Windows\system32\User32.dll => File is digitally signed
- C:\Windows\SysWOW64\User32.dll => File is digitally signed
- C:\Windows\system32\userinit.exe => File is digitally signed
- C:\Windows\SysWOW64\userinit.exe => File is digitally signed
- C:\Windows\system32\rpcss.dll => File is digitally signed
- C:\Windows\system32\dnsapi.dll => File is digitally signed
- C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
- C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
- LastRegBack: 2017-07-02 19:06
- ==================== End of FRST.txt ============================[/spoiler]
- Addition
- [spoiler]Additional scan result of Farbar Recovery Scan Tool (x64) Version: 08-07-2017
- Ran by Qwerty (09-07-2017 16:33:58)
- Running from C:\Users\Qwerty\Downloads
- Windows 7 Ultimate Service Pack 1 (X64) (2017-05-12 20:00:17)
- Boot Mode: Normal
- ==========================================================
- ==================== Accounts: =============================
- Administrator (S-1-5-21-3858528921-1604397686-3684385761-500 - Administrator - Disabled)
- Guest (S-1-5-21-3858528921-1604397686-3684385761-501 - Limited - Disabled)
- HomeGroupUser$ (S-1-5-21-3858528921-1604397686-3684385761-1002 - Limited - Enabled)
- Qwerty (S-1-5-21-3858528921-1604397686-3684385761-1000 - Administrator - Enabled) => C:\Users\Qwerty
- ==================== Security Center ========================
- (If an entry is included in the fixlist, it will be removed.)
- AV: Avast Antivirus (Enabled - Up to date) {8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF}
- AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
- AS: Avast Antivirus (Enabled - Up to date) {35C973AA-9ABB-D3CA-B100-B0DC0E5F2402}
- ==================== Installed Programs ======================
- (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
- µTorrent (HKLM-x32\...\uTorrent) (Version: 2.2.1 - )
- 7-Zip 16.04 (x64) (HKLM\...\7-Zip) (Version: 16.04 - Igor Pavlov)
- Action! (HKLM-x32\...\Mirillis Action!) (Version: 2.3.0 - Mirillis)
- AIMP (HKLM-x32\...\AIMP) (Version: v4.13.1895, 07.05.2017 - AIMP DevTeam)
- Andy OS (HKLM\...\Andy OS) (Version: 46.16 - Andy OS, Inc)
- Apple Application Support (32-bit) (HKLM-x32\...\{E92BB800-BCC5-4C25-8102-AC2C3B7C7C1E}) (Version: 5.5 - Apple Inc.)
- Apple Application Support (64-bit) (HKLM\...\{9C912B1E-06DD-43EF-BB2B-45CB2C88BAAE}) (Version: 5.5 - Apple Inc.)
- Apple Mobile Device Support (HKLM\...\{0A596141-97D5-45FA-9281-98DFAF48D579}) (Version: 10.3.2.3 - Apple Inc.)
- Apple Software Update (HKLM-x32\...\{52D87F32-70E4-4348-8148-C0B9F35B1314}) (Version: 2.3.0.177 - Apple Inc.)
- Application Insights Tools for Visual Studio 2015 (HKLM-x32\...\{D25C9EDD-984F-444C-9229-5A58130C6B10}) (Version: 4.3.60226.3 - Microsoft Corporation)
- Armagetron Advanced 0.2.8.3.4.gcc (HKLM-x32\...\Armagetron Advanced) (Version: 0.2.8.3.4.gcc - Armagetron Advanced Team)
- Avast Free Antivirus (HKLM-x32\...\Avast Antivirus) (Version: 17.5.2302 - AVAST Software)
- Azure AD Authentication Connected Service (HKLM-x32\...\{3FEAC561-1CF6-41D6-B0F3-BECDD9C88A1B}) (Version: 14.0.23107 - Microsoft Corporation) Hidden
- AzureTools.Notifications (HKLM-x32\...\{1E5CA362-39B6-4BD0-B9C0-69CF15F0FEA2}) (Version: 2.7.30611.1601 - Microsoft Corporation) Hidden
- Bandicam (HKLM-x32\...\Bandicam) (Version: 3.4.2.1258 - Bandicam.com)
- Bandicam MPEG-1 Decoder (HKLM-x32\...\BandiMPEG1) (Version: - Bandicam.com)
- Blend for Visual Studio SDK for .NET 4.5 (HKLM-x32\...\{37E53780-3944-4A6A-842F-727128E8616E}) (Version: 3.0.40218.0 - Microsoft Corporation) Hidden
- Bochs 2.6.9 (remove only) (HKLM-x32\...\Bochs 2.6.9) (Version: 2.6.9 - The Bochs Project)
- Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
- Bully - Scholarship Edition (HKLM-x32\...\Bully - Scholarship Edition_is1) (Version: - )
- Burnout Paradise - The Ultimate Box (HKLM-x32\...\Burnout Paradise - The Ultimate Box_is1) (Version: - )
- Camtasia 9 (HKLM\...\{1D09B594-C8B5-4CF1-B927-41D9A487799C}) (Version: 9.0.5.2021 - TechSmith Corporation) Hidden
- Camtasia 9 (HKLM-x32\...\{00ce4b8c-0138-4743-b0b8-379b2715eb44}) (Version: 9.0.5.2021 - TechSmith Corporation)
- Camtasia 9 9.0.5.2021 (HKLM-x32\...\Camtasia 9 9.0.5.2021) (Version: 9.0.5.2021 - TechSmith Corporation)
- Carmageddon 2 Carpocalypse Now (HKLM-x32\...\1207659963_is1) (Version: 2.1.0.28 - GOG.com)
- Carmageddon TDR2000 "MAX-Pack" (HKLM-x32\...\Carmageddon TDR2000 "MAX-Pack") (Version: - )
- Carmageddon TDR2000 (HKLM-x32\...\{204752E6-4202-11D4-8586-0050DA635DCF}) (Version: - )
- CCleaner (HKLM\...\CCleaner) (Version: 5.31 - Piriform)
- CDBurnerXP (HKLM-x32\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.5.7.6623 - CDBurnerXP)
- Citra Edge (HKU\S-1-5-21-3858528921-1604397686-3684385761-1000\...\citra) (Version: 0.1.405 - Citra Development Team)
- Core FTP LE (x64) (HKLM-x32\...\CoreFTP(x64)) (Version: - )
- Crashday (HKLM-x32\...\{9C27ADE1-EAFB-4BB7-9FE3-5DD9BA9A3DD2}) (Version: 0 - ATARI)
- DAEMON Tools Lite (HKLM\...\DAEMON Tools Lite) (Version: 10.5.1.0232 - Disc Soft Ltd)
- Defraggler (HKLM\...\Defraggler) (Version: 2.21 - Piriform)
- DigiByte Core (64-bit) (HKU\S-1-5-21-3858528921-1604397686-3684385761-1000\...\DigiByte Core (64-bit)) (Version: 6.14.2 - DigiByte Core project)
- Dotfuscator and Analytics Community Edition 5.19.0 (HKLM-x32\...\{4C5B1DD0-7E8E-4972-9247-818E6D030552}) (Version: 5.19.0.2930 - PreEmptive Solutions) Hidden
- EmEditor (64-bit) (HKLM\...\{59737FF5-4FCB-432B-A573-A58FB12DEE13}) (Version: 16.9.3 - Emurasoft, Inc.)
- Entity Framework 6.1.3 Tools for Visual Studio 2015 Update 1 (HKLM-x32\...\{2A56910C-69C8-495D-8ED8-9080F0A14E58}) (Version: 14.0.41103.0 - Microsoft Corporation)
- Exact Audio Copy 1.3 (HKLM-x32\...\Exact Audio Copy) (Version: 1.3 - Andre Wiethoff)
- FileZilla Client 3.25.2 (HKLM-x32\...\FileZilla Client) (Version: 3.25.2 - Tim Kosse)
- Fraps (remove only) (HKLM-x32\...\Fraps) (Version: - )
- Gajim (HKLM-x32\...\Gajim) (Version: 0.16.7 - )
- Glary Utilities 5.79 (HKLM-x32\...\Glary Utilities 5) (Version: 5.79.0.100 - Glarysoft Ltd)
- Google Chrome (HKLM-x32\...\Google Chrome) (Version: 59.0.3071.115 - Google Inc.)
- Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.5 - Google Inc.) Hidden
- GrabIt 1.7.4 Beta 2 (build 1014) (HKLM-x32\...\GrabIt_is1) (Version: - Ilan Shemes)
- Hotspot Shield 6.20.31 (HKLM-x32\...\{91992aa0-fd97-42e1-b9d1-5ce98771560d}) (Version: 6.20.31.9929 - AnchorFree Inc.)
- Hotspot Shield 6.20.31 (HKLM-x32\...\{AF599C42-A2E5-4251-B7EE-4925B26899EC}) (Version: 6.20.31.9929 - AnchorFree Inc.) Hidden
- Hotspot Shield 6.20.31 (HKLM-x32\...\HotspotShield) (Version: 6.20.31 - AnchorFree Inc.) Hidden
- HP USB Disk Storage Format Tool (HKLM-x32\...\{0E0DF90C-D0BA-4C89-9262-AD78D1A3DE51}) (Version: - )
- iExplorer (HKU\S-1-5-21-3858528921-1604397686-3684385761-1000\...\2ee35ebaf226322a) (Version: 4.1.5.0 - Macroplant LLC)
- iFunbox (v4.0.4106.1352) (HKLM-x32\...\iFunbox_is1) (Version: v4.0.4106.1352 - iFunbox DevTeam)
- IIS 10.0 Express (HKLM\...\{7A28A2B0-458B-4A58-84AC-C90D2D4B79FB}) (Version: 10.0.1735 - Microsoft Corporation)
- IIS Express Application Compatibility Database for x64 (HKLM\...\{08274920-8908-45c2-9258-8ad67ff77b09}.sdb) (Version: - )
- IIS Express Application Compatibility Database for x86 (HKLM\...\{ad846bae-d44b-4722-abad-f7420e08bcd9}.sdb) (Version: - )
- IMVU Avatar Chat Software (HKU\S-1-5-21-3858528921-1604397686-3684385761-1000\...\IMVU Avatar chat client software BETA) (Version: - )
- Intel(R) Chipset Device Software (HKLM-x32\...\{49bc1e38-39b4-4728-9e75-cbe67ba9a329}) (Version: 10.1.1.42 - Intel(R) Corporation) Hidden
- Intel(R) OpenCL CPU Runtime (HKLM-x32\...\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: - Intel Corporation)
- Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.4425 - Intel Corporation)
- Intel® Hardware Accelerated Execution Manager (HKLM\...\{557D160E-2085-4D38-BDA3-1D5D3F74A3A4}) (Version: 6.0.4 - Intel Corporation)
- iTunes (HKLM\...\{F0C7385A-9D20-45F3-8101-05D383885180}) (Version: 12.6.1.25 - Apple Inc.)
- Java 8 Update 131 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F64180131F0}) (Version: 8.0.1310.11 - Oracle Corporation)
- Java 8 Update 131 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180131F0}) (Version: 8.0.1310.11 - Oracle Corporation)
- Keysticks (HKLM-x32\...\{0CA309CD-E575-4066-9DB5-EDCB331F32EF}) (Version: 1.9 - Keysticks.net)
- Kodi (HKU\S-1-5-21-3858528921-1604397686-3684385761-1000\...\Kodi) (Version: - XBMC-Foundation)
- LoiLo Game Recorder (HKLM\...\{89E4163C-BD19-45A9-BCEB-980741786799}_is1) (Version: 1.1.0.1 - LoiLo inc.)
- LoiLoScope 2 (HKLM-x32\...\{CAB75FFC-2377-4B95-A8FA-C9234B812A92}_is1) (Version: 2.5.4.2 - LoiLo inc)
- Malwarebytes version 3.1.2.1733 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.1.2.1733 - Malwarebytes)
- Microsoft .NET Framework 4 Multi-Targeting Pack (HKLM-x32\...\{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}) (Version: 4.0.30319 - Microsoft Corporation)
- Microsoft .NET Framework 4.5 Multi-Targeting Pack (HKLM-x32\...\{56E962F0-4FB0-3C67-88DB-9EAA6EEFC493}) (Version: 4.5.50710 - Microsoft Corporation)
- Microsoft .NET Framework 4.5.1 Multi-Targeting Pack (ENU) (HKLM-x32\...\{D3517C62-68A5-37CF-92F7-93C029A89681}) (Version: 4.5.50932 - Microsoft Corporation)
- Microsoft .NET Framework 4.5.1 Multi-Targeting Pack (HKLM-x32\...\{6A0C6700-EA93-372C-8871-DCCF13D160A4}) (Version: 4.5.50932 - Microsoft Corporation)
- Microsoft .NET Framework 4.5.1 SDK (HKLM-x32\...\{19A5926D-66E1-46FC-854D-163AA10A52D3}) (Version: 4.5.51641 - Microsoft Corporation)
- Microsoft .NET Framework 4.5.2 Multi-Targeting Pack (ENU) (HKLM-x32\...\{290FC320-2F5A-329E-8840-C4193BD7A9EE}) (Version: 4.5.51209 - Microsoft Corporation)
- Microsoft .NET Framework 4.5.2 Multi-Targeting Pack (HKLM-x32\...\{19E8AE59-4D4A-3534-B567-6CC08FA4102E}) (Version: 4.5.51651 - Microsoft Corporation)
- Microsoft .NET Framework 4.6 SDK (HKLM-x32\...\{B5915D37-0637-4A26-A3AA-C5DC9F856370}) (Version: 4.6.00081 - Microsoft Corporation)
- Microsoft .NET Framework 4.6 Targeting Pack (ENU) (HKLM-x32\...\{034547E9-D8FA-49E7-8B9C-4C9861FB9146}) (Version: 4.6.00127 - Microsoft Corporation)
- Microsoft .NET Framework 4.6 Targeting Pack (HKLM-x32\...\{2CC6A4A7-AAC2-46C9-9DBB-3727B5954F65}) (Version: 4.6.00081 - Microsoft Corporation)
- Microsoft .NET Framework 4.6.1 SDK (HKLM-x32\...\{2F0ECC80-B9E4-4485-8083-CD32F22ABD92}) (Version: 4.6.01055 - Microsoft Corporation)
- Microsoft .NET Framework 4.6.1 Targeting Pack (ENU) (HKLM-x32\...\{8EEB28EE-5141-411C-9CF0-9952264FE4AF}) (Version: 4.6.01055 - Microsoft Corporation)
- Microsoft .NET Framework 4.6.1 Targeting Pack (HKLM-x32\...\{8BC3EEC9-090F-4C53-A8DA-1BEC913040F9}) (Version: 4.6.01055 - Microsoft Corporation)
- Microsoft .NET Framework 4.7 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.7.02053 - Microsoft Corporation)
- Microsoft .NET Version Manager (x64) 1.0.0-beta5 (HKLM\...\{c5a4aba3-1aba-3ef8-b2d5-c3fa37f59738}) (Version: 1.0.10609.0 - Microsoft Corporation)
- Microsoft Chart Controls for Microsoft .NET Framework 3.5 (KB2500170) (HKLM-x32\...\{41785C66-90F2-40CE-8CB5-1C94BFC97280}) (Version: 3.5.30730.0 - Microsoft Corporation)
- Microsoft Help Viewer 1.0 (HKLM\...\Microsoft Help Viewer 1.0) (Version: 1.0.30319 - Microsoft Corporation)
- Microsoft Help Viewer 2.2 (HKLM-x32\...\Microsoft Help Viewer 2.2) (Version: 2.2.24720 - Microsoft Corporation)
- Microsoft Silverlight (HKLM-x32\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.20513.0 - Microsoft Corporation)
- Microsoft SQL Server 2008 (64-bit) (HKLM\...\Microsoft SQL Server 10 Release) (Version: - Microsoft Corporation)
- Microsoft SQL Server 2008 Browser (HKLM-x32\...\{C688457E-03FD-4941-923B-A27F4D42A7DD}) (Version: 10.1.2531.0 - Microsoft Corporation)
- Microsoft SQL Server 2008 Native Client (HKLM\...\{BBDE8A3D-64A2-43A6-95F3-C27B87DF7AC1}) (Version: 10.1.2531.0 - Microsoft Corporation)
- Microsoft SQL Server 2008 R2 Management Objects (HKLM-x32\...\{4E968D9C-21A7-4915-B698-F7AEB913541D}) (Version: 10.50.1447.4 - Microsoft Corporation)
- Microsoft SQL Server 2008 Setup Support Files (HKLM\...\{B40EE88B-400A-4266-A17B-E3DE64E94431}) (Version: 10.1.2731.0 - Microsoft Corporation)
- Microsoft SQL Server 2012 Command Line Utilities (HKLM\...\{9D573E71-1077-4C7E-B4DB-4E22A5D2B48B}) (Version: 11.0.2100.60 - Microsoft Corporation)
- Microsoft SQL Server 2012 Native Client (HKLM\...\{49D665A2-4C2A-476E-9AB8-FCC425F526FC}) (Version: 11.0.2100.60 - Microsoft Corporation)
- Microsoft SQL Server 2014 Express LocalDB (HKLM\...\{AB8DE9BA-19E1-446A-BCFA-6B3DA9751E21}) (Version: 12.0.2000.8 - Microsoft Corporation)
- Microsoft SQL Server 2014 Management Objects (HKLM-x32\...\{2774595F-BC2A-4B12-A25B-0C37A37049B0}) (Version: 12.0.2000.8 - Microsoft Corporation)
- Microsoft SQL Server 2014 Management Objects (x64) (HKLM\...\{1F9EB3B6-AED7-4AA7-B8F1-8E314B74B2A5}) (Version: 12.0.2000.8 - Microsoft Corporation)
- Microsoft SQL Server 2014 Transact-SQL ScriptDom (HKLM\...\{020CDFE0-C127-4047-B571-37C82396B662}) (Version: 12.0.2000.8 - Microsoft Corporation)
- Microsoft SQL Server 2014 T-SQL Language Service (HKLM-x32\...\{47D08E7A-92A1-489B-B0BF-415516497BCE}) (Version: 12.0.2000.8 - Microsoft Corporation)
- Microsoft SQL Server Compact 3.5 SP2 ENU (HKLM-x32\...\{3A9FC03D-C685-4831-94CF-4EDFD3749497}) (Version: 3.5.8080.0 - Microsoft Corporation)
- Microsoft SQL Server Compact 3.5 SP2 x64 ENU (HKLM\...\{D4AD39AD-091E-4D33-BB2B-59F6FCB8ADC3}) (Version: 3.5.8080.0 - Microsoft Corporation)
- Microsoft SQL Server Compact 4.0 SP1 x64 ENU (HKLM\...\{78909610-D229-459C-A936-25D92283D3FD}) (Version: 4.0.8876.1 - Microsoft Corporation)
- Microsoft SQL Server Data Tools - enu (14.0.50616.0) (HKLM-x32\...\{58246C80-3941-4B69-AE31-264644E2ADB8}) (Version: 14.0.50616.0 - Microsoft Corporation)
- Microsoft SQL Server System CLR Types (HKLM-x32\...\{2A2F3AE8-246A-4252-BB26-1BEB45627074}) (Version: 10.50.1447.4 - Microsoft Corporation)
- Microsoft SQL Server VSS Writer (HKLM\...\{0826F9E4-787E-481D-83E0-BC6A57B056D5}) (Version: 10.1.2531.0 - Microsoft Corporation)
- Microsoft System CLR Types for SQL Server 2014 (HKLM\...\{FC3BB979-AA54-4B60-BBA3-2C4DA6E08D80}) (Version: 12.0.2402.29 - Microsoft Corporation)
- Microsoft System CLR Types for SQL Server 2014 (HKLM-x32\...\{091CE6AA-2753-4F6E-AD1C-0E875744EB54}) (Version: 12.0.2402.29 - Microsoft Corporation)
- Microsoft Visual Basic 2010 Express - ENU (HKLM-x32\...\Microsoft Visual Basic 2010 Express - ENU) (Version: 10.0.30319 - Microsoft Corporation)
- Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
- Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
- Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
- Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
- Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
- Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4974 (HKLM-x32\...\{B7E38540-E355-3503-AFD7-635B2F2F76E1}) (Version: 9.0.30729.4974 - Microsoft Corporation)
- Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
- Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
- Microsoft Visual C++ 2010 x64 Runtime - 10.0.30319 (HKLM\...\{94D70749-4281-39AC-AD90-B56A0E0A402E}) (Version: 10.0.30319 - Microsoft Corporation)
- Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
- Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
- Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation)
- Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
- Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\...\{7f51bdb9-ee21-49ee-94d6-90afc321780e}) (Version: 12.0.21005.1 - Microsoft Corporation)
- Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
- Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.40660 (HKLM-x32\...\{ef6b00ec-13e1-4c25-9064-b2f383cb8412}) (Version: 12.0.40660.0 - Microsoft Corporation)
- Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation)
- Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
- Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.40660 (HKLM-x32\...\{61087a79-ac85-455c-934d-1fa22cc64f36}) (Version: 12.0.40660.0 - Microsoft Corporation)
- Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23506 (HKLM-x32\...\{3ee5e5bb-b7cc-4556-8861-a00a82977d6c}) (Version: 14.0.23506.0 - Microsoft Corporation)
- Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation)
- Microsoft Visual Studio 2010 ADO.NET Entity Framework Tools (HKLM-x32\...\{14DD7530-CCD2-3798-B37D-3839ED6A441C}) (Version: 10.0.30319 - Microsoft Corporation)
- Microsoft Visual Studio 2010 Express Prerequisites x64 - ENU (HKLM\...\{BCA26999-EC22-3007-BB79-638913079C9A}) (Version: 10.0.30319 - Microsoft Corporation)
- Microsoft Visual Studio Enterprise 2015 with Updates (HKLM-x32\...\{f90e9ec5-977b-4752-8518-abe39dac065d}) (Version: 14.0.24720.41 - Microsoft Corporation)
- Microsoft Web Deploy 3.6 (HKLM\...\{ED4CC1E5-043E-4157-8452-B5E533FE2BA1}) (Version: 3.1238.1955 - Microsoft Corporation)
- Mozilla Firefox 54.0.1 (x86 en-GB) (HKLM-x32\...\Mozilla Firefox 54.0.1 (x86 en-GB)) (Version: 54.0.1 - Mozilla)
- Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 53.0.3 - Mozilla)
- MSBuild/NuGet Integration 14.0 (x86) (HKLM-x32\...\{FA0599C5-C083-41BE-8AEA-E8EB9070D128}) (Version: 14.0.24720 - Microsoft Corporation) Hidden
- Multi-Device Hybrid Apps using C# - Templates - ENU (HKLM-x32\...\{12D99739-FFD3-3761-8AA6-F929E0FE407E}) (Version: 14.0.23107 - Microsoft Corporation) Hidden
- MusicBrainz Picard (HKLM-x32\...\MusicBrainz Picard) (Version: 1.4.2 - MusicBrainz)
- NETGEAR A6210 Genie (HKLM-x32\...\{24352157-CF75-4215-A0B5-3AF01F78CB0A}) (Version: 36.0.0.0 - NETGEAR) Hidden
- NETGEAR A6210 Genie (HKLM-x32\...\InstallShield_{24352157-CF75-4215-A0B5-3AF01F78CB0A}) (Version: 36.0.0.0 - NETGEAR)
- NewsBin Pro (HKLM\...\NewsBin5-64) (Version: 5.54 - DJI Interprises, LLC)
- NVIDIA PhysX (HKLM-x32\...\{8B922CF8-8A6C-41CE-A858-F1755D7F5D29}) (Version: 9.12.1031 - NVIDIA Corporation)
- OBS Studio (HKLM-x32\...\OBS Studio) (Version: 19.0.3 - OBS Project)
- OpenIV (HKU\S-1-5-21-3858528921-1604397686-3684385761-1000\...\OpenIV) (Version: 2.9.906 - .black/OpenIV Team)
- OpenVPN 2.3.12-I602 (HKLM-x32\...\OpenVPN) (Version: 2.3.12-I602 - )
- Oracle VM VirtualBox 5.1.22 (HKLM\...\{8D5E4D4D-5E0C-4448-B018-5DDEF1E208D9}) (Version: 5.1.22 - Oracle Corporation)
- PAYDAY 2 (HKLM\...\Steam App 218620) (Version: - OVERKILL - a Starbreeze Studio.)
- PCSX2 - Playstation 2 Emulator (HKLM-x32\...\pcsx2) (Version: - )
- Pidgin (HKLM-x32\...\Pidgin) (Version: 2.12.0 - )
- pidgin-otr 4.0.2 (HKLM-x32\...\pidgin-otr) (Version: 4.0.2 - Cypherpunks CA)
- PreEmptive Analytics Visual Studio Components (HKLM-x32\...\{436A18DD-5F2C-4B3C-985E-AD3C13B0CC25}) (Version: 1.2.5134.1 - PreEmptive Solutions) Hidden
- Prerequisites for SSDT (HKLM-x32\...\{21373064-AD95-48DB-A32E-0D9E08EF7355}) (Version: 12.0.2000.8 - Microsoft Corporation)
- PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.992 - Even Balance, Inc.)
- Python 3.5.2 (32-bit) (HKU\S-1-5-21-3858528921-1604397686-3684385761-1000\...\{cf72a2ab-2f1d-49fd-a0d7-1065e6357e1e}) (Version: 3.5.2150.0 - Python Software Foundation)
- Python 3.5.2 Core Interpreter (32-bit) (HKLM-x32\...\{EB0611B2-7F10-4D97-BCF2-DCAAB1199498}) (Version: 3.5.2150.0 - Python Software Foundation) Hidden
- Python 3.5.2 Development Libraries (32-bit) (HKLM-x32\...\{5DB2183B-62D3-407F-BBC1-EAD2F36283FA}) (Version: 3.5.2150.0 - Python Software Foundation) Hidden
- Python 3.5.2 Documentation (32-bit) (HKLM-x32\...\{1FBA5182-78DD-4940-9F06-96E5042B7061}) (Version: 3.5.2150.0 - Python Software Foundation) Hidden
- Python 3.5.2 Executables (32-bit) (HKLM-x32\...\{33B10015-A9B1-4210-B50A-26C6443979B0}) (Version: 3.5.2150.0 - Python Software Foundation) Hidden
- Python 3.5.2 pip Bootstrap (32-bit) (HKLM-x32\...\{9ADF9987-3327-48C6-91B3-B10900366491}) (Version: 3.5.2150.0 - Python Software Foundation) Hidden
- Python 3.5.2 Standard Library (32-bit) (HKLM-x32\...\{FCBB04F4-D2CF-4F55-BE92-B3898696B318}) (Version: 3.5.2150.0 - Python Software Foundation) Hidden
- Python 3.5.2 Tcl/Tk Support (32-bit) (HKLM-x32\...\{C1153533-FDC4-4922-892D-B71810F69566}) (Version: 3.5.2150.0 - Python Software Foundation) Hidden
- Python 3.5.2 Test Suite (32-bit) (HKLM-x32\...\{9D50A6D7-410A-4469-87B7-35FA84CBD479}) (Version: 3.5.2150.0 - Python Software Foundation) Hidden
- Python 3.5.2 Utility Scripts (32-bit) (HKLM-x32\...\{E6DEBF43-7ACF-4E88-9BBF-9B5945683281}) (Version: 3.5.2150.0 - Python Software Foundation) Hidden
- Python 3.6.1 (32-bit) (HKU\S-1-5-21-3858528921-1604397686-3684385761-1000\...\{1babc3bc-6a32-44f7-bf4d-60eec36c9ad1}) (Version: 3.6.1150.0 - Python Software Foundation)
- Python 3.6.1 Core Interpreter (32-bit) (HKLM-x32\...\{E63E60CA-437B-4894-8395-81F2F66483B0}) (Version: 3.6.1150.0 - Python Software Foundation) Hidden
- Python 3.6.1 Development Libraries (32-bit) (HKLM-x32\...\{3029D656-0C32-4AC9-84FB-A15056F356CC}) (Version: 3.6.1150.0 - Python Software Foundation) Hidden
- Python 3.6.1 Documentation (32-bit) (HKLM-x32\...\{D1198C40-C6F5-4FFB-B98C-79BF1FE706C1}) (Version: 3.6.1150.0 - Python Software Foundation) Hidden
- Python 3.6.1 Executables (32-bit) (HKLM-x32\...\{A7036382-80F1-4FC1-B244-D31AA50337F4}) (Version: 3.6.1150.0 - Python Software Foundation) Hidden
- Python 3.6.1 pip Bootstrap (32-bit) (HKLM-x32\...\{899F7F28-F6D3-4E5B-8FBE-F7929036172A}) (Version: 3.6.1150.0 - Python Software Foundation) Hidden
- Python 3.6.1 Standard Library (32-bit) (HKLM-x32\...\{3BCCB89B-CD98-4F78-8436-78847FABFD68}) (Version: 3.6.1150.0 - Python Software Foundation) Hidden
- Python 3.6.1 Tcl/Tk Support (32-bit) (HKLM-x32\...\{F6ED0771-FE83-4A1C-BE65-A06CB65B46D5}) (Version: 3.6.1150.0 - Python Software Foundation) Hidden
- Python 3.6.1 Test Suite (32-bit) (HKLM-x32\...\{F44EF183-905E-48BB-998E-53FC99B36FE3}) (Version: 3.6.1150.0 - Python Software Foundation) Hidden
- Python 3.6.1 Utility Scripts (32-bit) (HKLM-x32\...\{2AA7DAB3-6778-42A7-9F33-22615234540E}) (Version: 3.6.1150.0 - Python Software Foundation) Hidden
- Python Launcher (HKLM-x32\...\{323AC113-C6CE-4F99-842F-4936332D055A}) (Version: 3.6.5923.0 - Python Software Foundation)
- qBittorrent 3.3.12 (HKLM-x32\...\qBittorrent) (Version: 3.3.12 - The qBittorrent project)
- Qemu Manager 7.0 (HKLM-x32\...\Qemu Manager 7.0 - Qemu 0.11.1_is1) (Version: - David T Reynolds)
- Qualcomm Atheros Bluetooth Suite (64) (HKLM\...\{A84A4FB1-D703-48DB-89E0-68B6499D2801}) (Version: 8.0.1.306 - Qualcomm Atheros Communications)
- QuickPar 0.9 (HKLM-x32\...\QuickPar) (Version: 0.9 - Peter B. Clements)
- Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.50.1123.2011 - Realtek)
- Recordit version 0.2 (HKLM-x32\...\{F41ECB1B-8749-4F80-8335-B0A68A8F76EF}_is1) (Version: 0.2 - Freshout)
- ReiBoot (HKLM-x32\...\ReiBoot) (Version: - Tenorshare, Inc.)
- Rocket League (HKLM\...\Steam App 252950) (Version: - Psyonix, Inc.)
- Rockstar Games Social Club (HKLM-x32\...\Rockstar Games Social Club) (Version: 1.2.1.9 - Rockstar Games)
- Roslyn Language Services - x86 (HKLM-x32\...\{3107684C-8011-3031-BD28-10CA30F58267}) (Version: 14.0.24730 - Microsoft Corporation) Hidden
- Roslyn Language Services - x86 (HKLM-x32\...\{6C1985E7-E1C5-3A95-86EF-2C62465F15C3}) (Version: 14.0.23107 - Microsoft Corporation) Hidden
- SABnzbd 2.1.0 (HKLM-x32\...\SABnzbd) (Version: 2.1.0 - The SABnzbd Team)
- Service Pack 1 for SQL Server 2008 (KB968369) (64-bit) (HKLM\...\KB968369) (Version: 10.1.2531.0 - Microsoft Corporation)
- Skype™ 7.38 (HKLM-x32\...\{3B7E914A-93D5-4A29-92BB-AF8C3F66C431}) (Version: 7.38.101 - Skype Technologies S.A.)
- SlimDX Runtime .NET 4.0 x86 (January 2012) (HKLM-x32\...\{7EBD0E43-6AC0-4CA8-9990-00E50069AD29}) (Version: 2.0.13.43 - SlimDX Group)
- SmartPixel (HKLM-x32\...\SmartPixel) (Version: 3.2.0.0 - Beyond Magic Limited)
- Spotify (HKU\S-1-5-21-3858528921-1604397686-3684385761-1000\...\Spotify) (Version: 1.0.57.474.gca9c9538 - Spotify AB)
- Sql Server Customer Experience Improvement Program (HKLM\...\{2F14965D-567B-4E59-ADEB-0A2CC1E3ADDF}) (Version: 10.1.2531.0 - Microsoft Corporation) Hidden
- Stardock WindowBlinds (HKLM-x32\...\Stardock WindowBlinds) (Version: 10.50 - Stardock Software, Inc.)
- Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
- TAP-Windows 9.21.2 (HKLM\...\TAP-Windows) (Version: 9.21.2 - )
- Team Explorer for Microsoft Visual Studio 2015 (HKLM-x32\...\{48992F68-BEE6-35D8-89AC-6A81406F1096}) (Version: 14.0.24712 - Microsoft Corporation) Hidden
- TeamViewer 12 (HKLM-x32\...\TeamViewer) (Version: 12.0.78716 - TeamViewer)
- Test Tools for Microsoft Visual Studio 2015 (HKLM-x32\...\{9EABBFE1-7EED-47D9-8FB8-21D7E4808057}) (Version: 14.0.23107 - Microsoft Corporation) Hidden
- The Simpsons - Hit & Run (HKLM-x32\...\The Simpsons - Hit & Run_R.G. Mechanics_is1) (Version: - R.G. Mechanics, markfiter)
- Tixati (HKLM-x32\...\tixati) (Version: - )
- Trillian (HKLM-x32\...\Trillian) (Version: - Cerulean Studios, LLC)
- TVMOBiLi (HKLM-x32\...\TVMOBiLi) (Version: - )
- TypeScript Power Tool (HKLM-x32\...\{CF436B98-B0FE-447F-8E46-68E0B14FDDE0}) (Version: 1.7.6.0 - Microsoft Corporation) Hidden
- TypeScript Tools for Microsoft Visual Studio 2015 (HKLM-x32\...\{F66F9C2A-E14B-4D30-82C5-A4E32B569286}) (Version: 1.7.6.0 - Microsoft Corporation) Hidden
- TypeScript Tools for Microsoft Visual Studio 2015 1.7.6.0 (HKLM-x32\...\{5ee9a47a-3630-4016-b76d-dc752e9218dd}) (Version: 1.7.24809.0 - Microsoft Corporation)
- Universal CRT Extension SDK (HKLM-x32\...\{1FBCBC17-4527-2340-0832-B1D49C41FF67}) (Version: 10.0.26624 - Microsoft Corporation) Hidden
- Universal CRT Extension SDK (HKLM-x32\...\{284FA9A0-CEDD-81D3-5A19-5858E95FD0C4}) (Version: 10.0.10150 - Microsoft Corporation) Hidden
- Universal CRT Headers Libraries and Sources (HKLM-x32\...\{8BFBEC30-33CC-13B4-849F-3B036F27466A}) (Version: 10.0.26624 - Microsoft Corporation) Hidden
- Universal CRT Headers Libraries and Sources (HKLM-x32\...\{ABD37F71-FC3F-F525-C7B3-BDD95F684C51}) (Version: 10.0.10150 - Microsoft Corporation) Hidden
- Universal CRT Redistributable (HKLM-x32\...\{0460C87B-7F4C-3170-FAC9-B7A6AE5CE4E9}) (Version: 10.0.26624 - Microsoft Corporation) Hidden
- Universal CRT Tools x64 (HKLM\...\{33952D66-D503-10CA-DD8E-E365C15EB4E0}) (Version: 10.0.26624 - Microsoft Corporation) Hidden
- Universal CRT Tools x86 (HKLM-x32\...\{B048B812-32DE-3474-FA64-223B6A63AD47}) (Version: 10.0.26624 - Microsoft Corporation) Hidden
- Uplay (HKLM-x32\...\Uplay) (Version: 32.1 - Ubisoft)
- VEGAS Pro 14.0 (64-bit) (HKLM\...\{F7773180-1A27-11E7-864D-C2A106E0D44C}) (Version: 14.0.252 - VEGAS)
- VEGAS Windows Installer Preloader 1.0 Build 61 (HKLM-x32\...\VEGAS Windows Installer Preloader 1.0 Build 61) (Version: 1.0 Build 61 - MAGIX Computer Products Intl. Co.)
- VeraCrypt (HKLM-x32\...\VeraCrypt) (Version: 1.19 - IDRIX)
- Visual Studio 2010 Tools for SQL Server Compact 3.5 SP2 ENU (HKLM-x32\...\{112C23F2-C036-4D40-BED4-0CB47BF5555C}) (Version: 4.0.8080.0 - Microsoft Corporation)
- Visual Studio 2015 Update 1 (KB3022398) (HKLM-x32\...\{fcaa9dba-9438-48b6-ad91-4e9b4cc7084a}) (Version: 14.0.24720 - Microsoft Corporation)
- VLC media player (HKLM\...\VLC media player) (Version: 2.2.6 - VideoLAN)
- VMware VIX (HKLM-x32\...\{F99FC179-EA67-4BBC-8955-BDDA0CB94B88}) (Version: 1.15.6.00000 - VMware, Inc.)
- VMware Workstation (HKLM\...\{8EB66999-8E67-44D1-A8E3-EC44739C22A9}) (Version: 12.5.6 - VMware, Inc.)
- VMware Workstation (HKLM\...\{F4C0A853-FA3B-4404-954B-799299EB5A98}) (Version: 12.1.1 - VMware, Inc.)
- Volume2 1.1.5 (HKLM-x32\...\Volume2) (Version: 1.1.5 - Alexandr Irza)
- VS Update core components (HKLM-x32\...\{5F7870A1-0586-313E-A9FF-3249DCE9F63A}) (Version: 14.0.24720 - Microsoft Corporation) Hidden
- Vysor (HKU\S-1-5-21-3858528921-1604397686-3684385761-1000\...\Vysor) (Version: 1.7.3 - ClockworkMod)
- Wallpaper Engine (HKLM\...\Steam App 431960) (Version: - Kristjan Skutta)
- WALTR2 version 2.0.21 (HKLM\...\{D20DE4FE-1FCF-4EB1-BFCA-9DA69A80D739}_is1) (Version: 2.0.21 - Softorino, Inc.)
- WCF Data Services 5.6.4 Runtime (HKLM-x32\...\{DB85E7BD-B2DD-43D4-B3C0-23D7B527B597}) (Version: 5.6.62175.4 - Microsoft Corporation) Hidden
- WCF Data Services Tools for Microsoft Visual Studio 2015 (HKLM-x32\...\{0A3B508E-5638-4471-BCC9-954E1868CB86}) (Version: 5.6.62175.4 - Microsoft Corporation) Hidden
- WiFiCreator 12.0 (HKLM-x32\...\{B340C957-0624-48C4-A9D9-BEC0572806C6}_is1) (Version: - TRUE Software)
- Winamp (HKLM-x32\...\Winamp) (Version: 5.666 - Nullsoft, Inc)
- ==================== Custom CLSID (Whitelisted): ==========================
- (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
- CustomCLSID: HKU\S-1-5-21-3858528921-1604397686-3684385761-1000_Classes\CLSID\{00020420-0000-0000-C000-000000000046}\InprocServer32 -> C:\Windows\system32\oleaut32.dll (Microsoft Corporation)
- CustomCLSID: HKU\S-1-5-21-3858528921-1604397686-3684385761-1000_Classes\CLSID\{00020421-0000-0000-C000-000000000046}\InprocServer32 -> C:\Windows\system32\oleaut32.dll (Microsoft Corporation)
- CustomCLSID: HKU\S-1-5-21-3858528921-1604397686-3684385761-1000_Classes\CLSID\{00020422-0000-0000-C000-000000000046}\InprocServer32 -> C:\Windows\system32\oleaut32.dll (Microsoft Corporation)
- CustomCLSID: HKU\S-1-5-21-3858528921-1604397686-3684385761-1000_Classes\CLSID\{00020423-0000-0000-C000-000000000046}\InprocServer32 -> C:\Windows\system32\oleaut32.dll (Microsoft Corporation)
- CustomCLSID: HKU\S-1-5-21-3858528921-1604397686-3684385761-1000_Classes\CLSID\{00020424-0000-0000-C000-000000000046}\InprocServer32 -> C:\Windows\system32\oleaut32.dll (Microsoft Corporation)
- CustomCLSID: HKU\S-1-5-21-3858528921-1604397686-3684385761-1000_Classes\CLSID\{00020425-0000-0000-C000-000000000046}\InprocServer32 -> C:\Windows\system32\oleaut32.dll (Microsoft Corporation)
- CustomCLSID: HKU\S-1-5-21-3858528921-1604397686-3684385761-1000_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\Windows\system32\igfxEM.exe (Intel Corporation)
- CustomCLSID: HKU\S-1-5-21-3858528921-1604397686-3684385761-1000_Classes\CLSID\{D4D48C93-BDC7-4E76-B530-2E4D13B0150F}\InprocServer32 -> C:\Users\Qwerty\AppData\Local\Programs\EmEditor\emedshl64.dll (Emurasoft, Inc.)
- CustomCLSID: HKU\S-1-5-21-3858528921-1604397686-3684385761-1000_Classes\CLSID\{DFA0CC7F-D36B-47D1-8EF5-415C1DA53F57}\InprocServer32 -> C:\Users\Qwerty\AppData\Local\Programs\EmEditor\emedshl64.dll (Emurasoft, Inc.)
- ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-07-02] (AVAST Software)
- ContextMenuHandlers01: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2016-10-04] (Igor Pavlov)
- ContextMenuHandlers01: [AIMP] -> {1F77B17B-F531-44DB-ACA4-76ABB5010A28} => C:\Program Files (x86)\AIMP\System\aimp_menu64.dll [2017-05-23] (AIMP DevTeam)
- ContextMenuHandlers01: [Atheros] -> {B8952421-0E55-400B-94A6-FA858FC0A39F} => C:\Program Files (x86)\Bluetooth Suite\BtvAppExt.dll [2013-09-25] (Qualcomm®Atheros®)
- ContextMenuHandlers01: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-07-02] (AVAST Software)
- ContextMenuHandlers01: [DefragglerShellExtension] -> {4380C993-0C43-4E02-9A7A-0D40B6EA7590} => C:\Program Files\Defraggler\DefragglerShell64.dll [2016-03-08] (Piriform Ltd)
- ContextMenuHandlers01: [Glary Utilities] -> {B3C418F8-922B-4faf-915E-59BC14448CF7} => C:\Program Files (x86)\Glary Utilities 5\x64\ContextHandler.dll [2016-06-23] (Glarysoft Ltd)
- ContextMenuHandlers02: [Glary Utilities] -> {B3C418F8-922B-4faf-915E-59BC14448CF7} => C:\Program Files (x86)\Glary Utilities 5\x64\ContextHandler.dll [2016-06-23] (Glarysoft Ltd)
- ContextMenuHandlers02: [VMDiskMenuHandler] -> {271DC252-6FE1-4D59-9053-E4CF50AB99DE} => -> No File
- ContextMenuHandlers02: [VMDiskMenuHandler64] -> {E4D28EDC-8C0B-43EE-9E7D-C8A8682334DC} => C:\Program Files (x86)\VMware\VMware Workstation\x64\vmdkShellExt64.dll [2016-04-14] (VMware, Inc.)
- ContextMenuHandlers03: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-07-02] (AVAST Software)
- ContextMenuHandlers03: [FTShellContext] -> {AFF81F7B-6942-40c4-AADA-7214EF7B6DD1} => C:\Program Files (x86)\Bluetooth Suite\ShellContextExt.dll [2013-09-25] (Qualcomm®Atheros®)
- ContextMenuHandlers03: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-05-09] (Malwarebytes)
- ContextMenuHandlers04: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2016-10-04] (Igor Pavlov)
- ContextMenuHandlers04: [AIMP] -> {1F77B17B-F531-44DB-ACA4-76ABB5010A28} => C:\Program Files (x86)\AIMP\System\aimp_menu64.dll [2017-05-23] (AIMP DevTeam)
- ContextMenuHandlers05: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => C:\Windows\system32\igfxpph.dll -> No File
- ContextMenuHandlers05: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\Windows\system32\igfxDTCM.dll [2016-05-12] (Intel Corporation)
- ContextMenuHandlers06: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2016-10-04] (Igor Pavlov)
- ContextMenuHandlers06: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-07-02] (AVAST Software)
- ContextMenuHandlers06: [DefragglerShellExtension] -> {4380C993-0C43-4E02-9A7A-0D40B6EA7590} => C:\Program Files\Defraggler\DefragglerShell64.dll [2016-03-08] (Piriform Ltd)
- ContextMenuHandlers06: [Glary Utilities] -> {B3C418F8-922B-4faf-915E-59BC14448CF7} => C:\Program Files (x86)\Glary Utilities 5\x64\ContextHandler.dll [2016-06-23] (Glarysoft Ltd)
- ContextMenuHandlers06: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-05-09] (Malwarebytes)
- ContextMenuHandlers1_S-1-5-21-3858528921-1604397686-3684385761-1000: [EmEditor] -> {D4D48C93-BDC7-4E76-B530-2E4D13B0150F} => C:\Users\Qwerty\AppData\Local\Programs\EmEditor\emedshl64.dll [2017-06-14] (Emurasoft, Inc.)
- ContextMenuHandlers2_S-1-5-21-3858528921-1604397686-3684385761-1000: [EmEditor] -> {D4D48C93-BDC7-4E76-B530-2E4D13B0150F} => C:\Users\Qwerty\AppData\Local\Programs\EmEditor\emedshl64.dll [2017-06-14] (Emurasoft, Inc.)
- ContextMenuHandlers4_S-1-5-21-3858528921-1604397686-3684385761-1000: [EmEditor] -> {D4D48C93-BDC7-4E76-B530-2E4D13B0150F} => C:\Users\Qwerty\AppData\Local\Programs\EmEditor\emedshl64.dll [2017-06-14] (Emurasoft, Inc.)
- ==================== Scheduled Tasks (Whitelisted) =============
- (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
- Task: {3D352A1B-B5CB-4A9F-A3CB-F18EF8DE55BC} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-05-12] (Google Inc.)
- Task: {40396F22-A2D9-4C22-847E-EAEB76C89DD8} - System32\Tasks\BitX Updater Service => C:\Program Files (x86)\BitX\BitXUpdaterService.exe
- Task: {4F074223-4282-4B85-A05C-360F37B6E3B7} - System32\Tasks\yiyu => C:\Users\Qwerty\yiyu\pknwghsz.exe [2016-10-09] (AutoIt Team)
- Task: {685FE978-2166-49F0-9F23-54AC85E5742D} - System32\Tasks\Avast Emergency Update => C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe [2017-07-02] (AVAST Software)
- Task: {7BFBC287-0B5D-47CA-B5D5-419A25268BAD} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-05-12] (Google Inc.)
- Task: {88FAE977-B0E1-433F-9E77-2DB7597F7CCB} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2017-02-14] (Apple Inc.)
- Task: {BAC4C8BF-37A2-4322-A3DB-A5AA91E0D7AE} - System32\Tasks\GlaryInitialize 5 => C:\Program Files (x86)\Glary Utilities 5\Initialize.exe [2017-06-30] (Glarysoft Ltd)
- Task: {C669528C-C6FC-4F47-B2F8-E66759D89162} - System32\Tasks\BitX => C:\Program Files (x86)\BitX\BitXSplash.exe
- Task: {DB3E6498-C5E7-49D8-9A42-268E740D33ED} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2017-06-13] (Piriform Ltd)
- (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
- ==================== Shortcuts & WMI ========================
- (The entries could be listed to be restored or removed.)
- ShortcutWithArgument: C:\Users\Qwerty\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\AllCast Receiver.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=hjbljnpdahefgnopeohlaeohgkiidnoe
- ShortcutWithArgument: C:\Users\Qwerty\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Blockchain.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=glaohkkooicollgefkkmndjcbblominl
- ShortcutWithArgument: C:\Users\Qwerty\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Chrome Remote Desktop.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=gbchcmhmhahfdphkhkmpfmihenigjmpp
- ShortcutWithArgument: C:\Users\Qwerty\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\FireRTC.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=iaamfpbohecgihgnbhmppgekdjkbolah
- ShortcutWithArgument: C:\Users\Qwerty\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Cast for Education.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=bnmgbcehmiinmmlmepibeeflglhbhlea
- ShortcutWithArgument: C:\Users\Qwerty\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Keep - notes and lists.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=hmjkmjkepdijhoojdojkdfohbdgmmhki
- ShortcutWithArgument: C:\Users\Qwerty\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Play Music.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=fahmaaghhglfmonjliepjlchgpgfmobi
- ShortcutWithArgument: C:\Users\Qwerty\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Netease Music.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=fogcjafchgdhdoieggbeldnckbghdpkn
- ShortcutWithArgument: C:\Users\Qwerty\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\VNC® Viewer for Google Chrome™.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=iabmpiboiopbgfabjmgeedhcmjenhbla
- ShortcutWithArgument: C:\Users\Qwerty\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Vysor.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=gidgenkbbabolejbgbpnhbimgjbffefm
- ShortcutWithArgument: C:\Users\Qwerty\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Netease Music.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=fogcjafchgdhdoieggbeldnckbghdpkn
- ==================== Loaded Modules (Whitelisted) ==============
- 2017-05-09 00:44 - 2017-05-09 00:44 - 01354040 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
- 2017-05-09 00:44 - 2017-05-09 00:44 - 00092472 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
- 2013-09-25 03:01 - 2013-09-25 03:01 - 00086016 _____ () C:\Program Files (x86)\Bluetooth Suite\Modules\Map\MAP.dll
- 2017-05-09 03:05 - 2017-05-09 03:05 - 01354040 _____ () C:\Program Files\iTunes\libxml2.dll
- 2017-05-09 03:05 - 2017-05-09 03:05 - 00092472 _____ () C:\Program Files\iTunes\zlib1.dll
- 2017-07-05 21:42 - 2017-07-05 21:42 - 00050688 _____ () C:\Program Files\SABnzbd\lib\_socket.pyd
- 2017-07-05 21:42 - 2017-07-05 21:42 - 02100736 _____ () C:\Program Files\SABnzbd\lib\_ssl.pyd
- 2017-07-05 21:42 - 2017-07-05 21:42 - 01482240 _____ () C:\Program Files\SABnzbd\lib\_hashlib.pyd
- 2017-07-05 21:42 - 2017-07-05 21:42 - 00129024 _____ () C:\Program Files\SABnzbd\lib\win32api.pyd
- 2017-07-05 21:42 - 2017-07-05 21:42 - 00136704 _____ () C:\Program Files\SABnzbd\lib\pywintypes27.dll
- 2017-07-05 21:42 - 2017-07-05 21:42 - 00547328 _____ () C:\Program Files\SABnzbd\lib\pythoncom27.dll
- 2017-07-05 21:42 - 2017-07-05 21:42 - 00120832 _____ () C:\Program Files\SABnzbd\lib\_ctypes.pyd
- 2017-07-05 21:42 - 2017-07-05 21:42 - 00011776 _____ () C:\Program Files\SABnzbd\lib\select.pyd
- 2017-07-05 21:42 - 2017-07-05 21:42 - 00022016 _____ () C:\Program Files\SABnzbd\lib\win32event.pyd
- 2017-07-05 21:42 - 2017-07-05 21:42 - 00052736 _____ () C:\Program Files\SABnzbd\lib\win32service.pyd
- 2017-07-05 21:42 - 2017-07-05 21:42 - 00064000 _____ () C:\Program Files\SABnzbd\lib\_sqlite3.pyd
- 2017-07-05 21:42 - 2017-07-05 21:42 - 00785408 _____ () C:\Program Files\SABnzbd\lib\sqlite3.dll
- 2017-07-05 21:42 - 2017-07-05 21:42 - 00008192 _____ () C:\Program Files\SABnzbd\lib\cryptography.hazmat.bindings._constant_time.pyd
- 2017-07-05 21:42 - 2017-07-05 21:42 - 00158208 _____ () C:\Program Files\SABnzbd\lib\_cffi_backend.pyd
- 2017-07-05 21:42 - 2017-07-05 21:42 - 00692224 _____ () C:\Program Files\SABnzbd\lib\unicodedata.pyd
- 2017-07-05 21:42 - 2017-07-05 21:42 - 02754560 _____ () C:\Program Files\SABnzbd\lib\cryptography.hazmat.bindings._openssl.pyd
- 2017-07-05 21:42 - 2017-07-05 21:42 - 00012288 _____ () C:\Program Files\SABnzbd\lib\sabyenc.pyd
- 2017-07-05 21:42 - 2017-07-05 21:42 - 00044032 _____ () C:\Program Files\SABnzbd\lib\win32process.pyd
- 2017-07-05 21:42 - 2017-07-05 21:42 - 00013824 _____ () C:\Program Files\SABnzbd\lib\Cheetah._namemapper.pyd
- 2017-07-05 21:42 - 2017-07-05 21:42 - 00179712 _____ () C:\Program Files\SABnzbd\lib\pyexpat.pyd
- 2017-07-05 21:42 - 2017-07-05 21:42 - 00092672 _____ () C:\Program Files\SABnzbd\lib\bz2.pyd
- 2017-07-05 21:42 - 2017-07-05 21:42 - 00148480 _____ () C:\Program Files\SABnzbd\lib\win32file.pyd
- 2017-07-05 21:42 - 2017-07-05 21:42 - 00034816 _____ () C:\Program Files\SABnzbd\lib\_multiprocessing.pyd
- 2017-07-05 21:42 - 2017-07-05 21:42 - 00062976 _____ () C:\Program Files\SABnzbd\lib\win32evtlog.pyd
- 2017-07-05 21:42 - 2017-07-05 21:42 - 00031232 _____ () C:\Program Files\SABnzbd\lib\servicemanager.pyd
- 2017-07-05 21:42 - 2017-07-05 21:42 - 00222720 _____ () C:\Program Files\SABnzbd\lib\win32gui.pyd
- 2017-07-05 21:42 - 2017-07-05 21:42 - 00392192 _____ () C:\Program Files\SABnzbd\lib\winxpgui.pyd
- 2017-06-26 18:08 - 2009-08-22 19:25 - 00102400 _____ () C:\Users\Qwerty\Downloads\d3d\D3DOverrider.exe
- 2013-09-25 03:09 - 2013-09-25 03:09 - 00384128 _____ () C:\Program Files (x86)\Bluetooth Suite\ContactsApi.dll
- 2015-09-17 17:42 - 2015-09-17 17:42 - 00192232 _____ () C:\Program Files (x86)\NETGEAR\A6210\NetgearSwitchUSB.exe
- 2017-05-26 20:08 - 2017-05-26 20:08 - 00076888 _____ () C:\Windows\SysWOW64\PnkBstrA.exe
- 2017-05-26 20:08 - 2017-05-26 20:08 - 00189248 _____ () C:\Windows\SysWOW64\PnkBstrB.exe
- 2015-04-20 19:01 - 2015-04-20 19:01 - 02731520 _____ () C:\Program Files (x86)\TVMOBiLi\bin\tvMobiliService.exe
- 2017-06-23 21:06 - 2017-04-04 19:50 - 00102312 _____ () C:\Program Files\WALTR2\x86\WALTR2Service.exe
- 2017-04-30 12:19 - 2017-04-30 12:19 - 00052392 _____ () C:\Program Files\FileZilla FTP Client\fzshellext_64.dll
- 2017-07-02 12:06 - 2017-07-02 12:06 - 00162032 _____ () c:\Program Files\AVAST Software\Avast\x64\vaarclient.dll
- 2017-07-02 12:06 - 2017-07-02 12:06 - 00831664 _____ () C:\Program Files\AVAST Software\Avast\x64\ffl2.dll
- 2017-07-02 12:06 - 2017-07-02 12:06 - 00276808 _____ () c:\Program Files\AVAST Software\Avast\x64\StreamBack.dll
- 2017-06-27 08:22 - 2017-06-23 04:21 - 03807064 _____ () C:\Program Files (x86)\Google\Chrome\Application\59.0.3071.115\libglesv2.dll
- 2017-06-27 08:22 - 2017-06-23 04:21 - 00100184 _____ () C:\Program Files (x86)\Google\Chrome\Application\59.0.3071.115\libegl.dll
- 2017-07-02 12:06 - 2017-07-02 12:06 - 00170224 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
- 2017-07-02 12:06 - 2017-07-02 12:06 - 00192664 _____ () C:\Program Files\AVAST Software\Avast\event_routing_rpc.dll
- 2017-07-02 12:06 - 2017-07-02 12:06 - 00224256 _____ () C:\Program Files\AVAST Software\Avast\tasks_core.dll
- 2017-07-07 16:33 - 2017-07-07 16:33 - 05684224 _____ () C:\Program Files\AVAST Software\Avast\defs\17070700\algo.dll
- 2017-07-02 12:06 - 2017-07-02 12:06 - 00689272 _____ () C:\Program Files\AVAST Software\Avast\ffl2.dll
- 2017-07-02 12:06 - 2017-07-02 12:06 - 00231664 _____ () C:\Program Files\AVAST Software\Avast\streamback.dll
- 2017-07-09 12:19 - 2017-07-09 12:19 - 05684224 _____ () C:\Program Files\AVAST Software\Avast\defs\17070900\algo.dll
- 2017-06-28 16:37 - 2017-06-28 16:37 - 00166520 _____ () C:\Program Files (x86)\Hotspot Shield\bin\CrashRpt1403.dll
- 2017-07-02 12:06 - 2017-07-02 12:06 - 01038952 _____ () C:\Program Files\AVAST Software\Avast\AvChrome.dll
- 2017-07-02 12:06 - 2017-07-02 12:06 - 67109376 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
- 2017-07-02 12:06 - 2017-07-02 12:08 - 02962096 _____ () C:\Program Files\AVAST Software\Avast\aswDataScan.dll
- 2017-06-26 18:08 - 2009-08-22 19:25 - 00032768 _____ () C:\Users\Qwerty\Downloads\d3d\D3DOverriderHooks.dll
- 2017-05-12 21:28 - 2017-05-17 02:54 - 00678176 _____ () C:\Program Files (x86)\Steam\SDL2.dll
- 2017-05-12 21:28 - 2016-09-01 02:02 - 04969248 _____ () C:\Program Files (x86)\Steam\v8.dll
- 2017-05-12 21:28 - 2016-09-01 02:02 - 01563936 _____ () C:\Program Files (x86)\Steam\icui18n.dll
- 2017-05-12 21:28 - 2016-09-01 02:02 - 01195296 _____ () C:\Program Files (x86)\Steam\icuuc.dll
- 2017-05-12 21:28 - 2017-06-08 06:42 - 02485536 _____ () C:\Program Files (x86)\Steam\video.dll
- 2017-05-12 21:28 - 2016-01-27 08:49 - 02549760 _____ () C:\Program Files (x86)\Steam\libavcodec-56.dll
- 2017-05-12 21:28 - 2016-01-27 08:49 - 00442880 _____ () C:\Program Files (x86)\Steam\libavutil-54.dll
- 2017-05-12 21:28 - 2016-01-27 08:49 - 00491008 _____ () C:\Program Files (x86)\Steam\libavformat-56.dll
- 2017-05-12 21:28 - 2016-01-27 08:49 - 00332800 _____ () C:\Program Files (x86)\Steam\libavresample-2.dll
- 2017-05-12 21:28 - 2016-01-27 08:49 - 00485888 _____ () C:\Program Files (x86)\Steam\libswscale-3.dll
- 2017-05-12 21:28 - 2017-06-08 06:42 - 00877856 _____ () C:\Program Files (x86)\Steam\bin\chromehtml.DLL
- 2017-05-12 21:28 - 2016-07-04 23:17 - 00266560 _____ () C:\Program Files (x86)\Steam\openvr_api.dll
- 2017-06-20 11:28 - 2017-06-20 11:28 - 01997792 ____R () C:\Program Files (x86)\Skype\Phone\skypert.dll
- 2015-05-27 00:00 - 2015-05-27 00:00 - 00059904 _____ () C:\Program Files (x86)\Trillian56\zlib1.dll
- 2015-05-27 00:00 - 2015-05-27 00:00 - 00187392 _____ () C:\Program Files (x86)\Trillian56\libpng15.dll
- 2015-05-27 00:00 - 2015-05-27 00:00 - 00006656 _____ () c:\program files (x86)\trillian56\languages\en\trillian.dll
- 2015-05-27 00:00 - 2015-05-27 00:00 - 00065536 _____ () C:\Program Files (x86)\Trillian56\libungif.dll
- 2015-05-27 00:00 - 2015-05-27 00:00 - 00003584 _____ () c:\program files (x86)\trillian56\languages\en\toolkit.dll
- 2015-05-27 00:00 - 2015-05-27 00:00 - 00006656 _____ () c:\program files (x86)\trillian56\languages\en\events.dll
- 2015-05-27 00:00 - 2015-05-27 00:00 - 00010752 _____ () c:\program files (x86)\trillian56\languages\en\buddy.dll
- 2015-05-27 00:00 - 2015-05-27 00:00 - 00007168 _____ () c:\program files (x86)\trillian56\languages\en\talk.dll
- 2017-06-26 18:08 - 2009-08-22 19:25 - 00057344 _____ () C:\Users\Qwerty\Downloads\d3d\RTFC.dll
- 2017-06-26 18:08 - 2009-08-22 19:25 - 00106496 _____ () C:\Users\Qwerty\Downloads\d3d\RTUI.dll
- 2017-05-12 21:32 - 2017-05-08 20:45 - 69516064 _____ () C:\Program Files (x86)\Steam\bin\cef\cef.win7\libcef.dll
- 2017-06-08 07:21 - 2017-05-17 02:54 - 00678176 _____ () C:\Program Files (x86)\Steam\bin\cef\cef.win7\SDL2.dll
- 2017-05-12 21:28 - 2017-06-08 06:42 - 00385312 _____ () C:\Program Files (x86)\Steam\steam.dll
- 2016-04-14 17:16 - 2016-04-14 17:16 - 01309768 _____ () C:\Program Files (x86)\VMware\VMware Workstation\libxml2.dll
- ==================== Alternate Data Streams (Whitelisted) =========
- (If an entry is included in the fixlist, only the ADS will be removed.)
- ==================== Safe Mode (Whitelisted) ===================
- (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
- HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot => "AlternateShell"=""
- HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
- HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
- ==================== Association (Whitelisted) ===============
- (If an entry is included in the fixlist, the registry item will be restored to default or removed.)
- ==================== Internet Explorer trusted/restricted ===============
- (If an entry is included in the fixlist, it will be removed from the registry.)
- IE trusted site: HKU\S-1-5-21-3858528921-1604397686-3684385761-1000\...\localhost -> hxxps://localhost
- ==================== Hosts content: ==========================
- (If needed Hosts: directive could be included in the fixlist to reset Hosts.)
- 2009-07-14 03:34 - 2017-07-09 15:26 - 00002026 _____ C:\Windows\system32\Drivers\etc\hosts
- 0.0.0.0 pubads.g.doubleclick.net
- 0.0.0.0 securepubads.g.doubleclick.net
- 0.0.0.0 www.googletagservices.com
- 0.0.0.0 gads.pubmatic.com
- 0.0.0.0 ads.pubmatic.com
- 0.0.0.0 spclient.wg.spotify.com0.0.0.0 anchorfree.net
- 0.0.0.0 rss2search.com
- 0.0.0.0 techbrowsing.com
- 0.0.0.0 box.anchorfree.net
- 0.0.0.0 www.mefeedia.com
- 0.0.0.0 www.anchorfree.net
- 0.0.0.0 www.mefeedia.com
- 0.0.0.0 anchorfree.us
- 0.0.0.0 a433.com
- 0.0.0.0 anchorfree.net
- 0.0.0.0 rpt.anchorfree.net
- 0.0.0.0 delivery.anchorfree.us/land.php
- 0.0.0.0 hsselite.com
- 0.0.0.0 www.hsselite.com
- 127.0.0.1 bandicam.com
- 127.0.0.1 ssl.bandisoft.com
- 0.0.0.0 activation.cloud.techsmith.com
- 0.0.0.0 assets.cloud.techsmith.com
- 0.0.0.0 camtasiatudi.techsmith.com
- 0.0.0.0 oscount.techsmith.com
- 0.0.0.0 tsccloud.cloudapp.net
- 0.0.0.0 updater.techsmith.com
- 127.0.0.1 camtasiatudio.techsmith.com
- 127.0.0.1 updater.techsmith.com
- 127.0.0.1 activation.cloud.techsmith.com
- There are 8 more lines.
- ==================== Other Areas ============================
- (Currently there is no automatic fix for this section.)
- HKU\S-1-5-21-3858528921-1604397686-3684385761-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Qwerty\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
- DNS Servers: 212.50.160.100 - 213.249.130.100
- HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 0)
- Windows Firewall is disabled.
- ==================== MSCONFIG/TASK MANAGER disabled items ==
- MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HandyAndy.lnk => C:\Windows\pss\HandyAndy.lnk.CommonStartup
- MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^NETGEAR A6210 Genie.lnk => C:\Windows\pss\NETGEAR A6210 Genie.lnk.CommonStartup
- MSCONFIG\startupfolder: C:^Users^Qwerty^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^EmEditor.lnk => C:\Windows\pss\EmEditor.lnk.Startup
- MSCONFIG\startupfolder: C:^Users^Qwerty^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Gajim.lnk => C:\Windows\pss\Gajim.lnk.Startup
- MSCONFIG\startupfolder: C:^Users^Qwerty^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Recordit.lnk => C:\Windows\pss\Recordit.lnk.Startup
- MSCONFIG\startupreg: A6210 => C:\Program Files (x86)\NETGEAR\A6210\A6210.EXE
- MSCONFIG\startupreg: BlueStacks Agent => C:\Program Files (x86)\BlueStacks\HD-Agent.exe
- MSCONFIG\startupreg: CCleaner Monitoring => "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
- MSCONFIG\startupreg: DAEMON Tools Lite Automount => "C:\Program Files\DAEMON Tools Lite\DTAgent.exe" -autorun
- MSCONFIG\startupreg: eM Client => "C:\Program Files (x86)\eM Client\MailClient.exe" /startup
- MSCONFIG\startupreg: iFunBox => C:\Program Files (x86)\i-Funbox DevTeam\iFunBox_x64.exe /tray
- MSCONFIG\startupreg: PhoenixGUI => C:\Users\Qwerty\AppData\Local\PhoenixGUI\Phoenix.exe
- MSCONFIG\startupreg: Spotify => "C:\Users\Qwerty\AppData\Roaming\Spotify\Spotify.exe" -autostart -minimized
- MSCONFIG\startupreg: Spotify Web Helper => "C:\Users\Qwerty\AppData\Roaming\Spotify\SpotifyWebHelper.exe"
- MSCONFIG\startupreg: vmware-tray.exe => "C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe"
- ==================== FirewallRules (Whitelisted) ===============
- (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
- FirewallRules: [{C4903444-0E02-4A31-B5F0-BAF62E01E693}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
- FirewallRules: [{22DEC15E-3660-4DD9-B9DE-FC3CF7F00301}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
- FirewallRules: [{F380D474-637B-4473-BE88-E757B31202E1}] => (Allow) C:\Program Files (x86)\qBittorrent\qbittorrent.exe
- FirewallRules: [{26A18437-F312-4659-B314-0550B6D2D4A3}] => (Allow) C:\Program Files (x86)\qBittorrent\qbittorrent.exe
- FirewallRules: [{2233777A-66E4-4E66-B792-CDCDE5D84488}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
- FirewallRules: [{C7AF6831-7F32-4F79-BDF3-D1B280B12D00}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
- FirewallRules: [{0A2849AE-6604-497B-BDC4-06EE9E8709BB}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
- FirewallRules: [TCP Query User{88F01FC7-55C2-445E-BF43-9B4EB761E1EF}C:\program files (x86)\kodi\kodi.exe] => (Allow) C:\program files (x86)\kodi\kodi.exe
- FirewallRules: [UDP Query User{C9B78D5F-AED5-45DF-B181-EAE33FEA1569}C:\program files (x86)\kodi\kodi.exe] => (Allow) C:\program files (x86)\kodi\kodi.exe
- FirewallRules: [TCP Query User{872D7D0E-B3FC-4E29-A3CE-22113799839A}C:\users\qwerty\documents\screw dc\dcrat\darkcomet.exe] => (Allow) C:\users\qwerty\documents\screw dc\dcrat\darkcomet.exe
- FirewallRules: [UDP Query User{0DBF3274-B6C7-41CC-A83C-37D6DBEAA351}C:\users\qwerty\documents\screw dc\dcrat\darkcomet.exe] => (Allow) C:\users\qwerty\documents\screw dc\dcrat\darkcomet.exe
- FirewallRules: [TCP Query User{DA988D9F-C5B6-4384-BE4F-ED03B863BD21}C:\users\qwerty\documents\screwdc\dcrat\darkcomet.exe] => (Allow) C:\users\qwerty\documents\screwdc\dcrat\darkcomet.exe
- FirewallRules: [UDP Query User{F73C7A99-BA24-425D-89CC-090A0AA97705}C:\users\qwerty\documents\screwdc\dcrat\darkcomet.exe] => (Allow) C:\users\qwerty\documents\screwdc\dcrat\darkcomet.exe
- FirewallRules: [{CF1A9301-8079-4E17-898A-4BF28E5D5829}] => (Allow) C:\Program Files (x86)\Microsoft Visual Studio 14.0\Common7\IDE\devenv.exe
- FirewallRules: [{9DC3B2DB-B8CE-4439-9208-2728B6A9EFB2}] => (Allow) C:\Program Files (x86)\Microsoft Visual Studio 14.0\Common7\IDE\devenv.exe
- FirewallRules: [{BFE5080E-4BBC-4A45-941C-60D0304598E6}] => (Allow) C:\Program Files (x86)\Microsoft Visual Studio 14.0\Common7\IDE\devenv.exe
- FirewallRules: [{D1076C8D-98DE-4EBA-B6C7-22BFD1F8AA2E}] => (Allow) C:\Program Files (x86)\Microsoft Visual Studio 14.0\Common7\IDE\devenv.exe
- FirewallRules: [{18F10BA5-539A-43AC-9648-231B63E4E950}] => (Allow) C:\Program Files (x86)\Microsoft Visual Studio 14.0\Common7\IDE\devenv.exe
- FirewallRules: [{89AF590D-66EF-4E3C-BAFA-12E9E23F31DF}] => (Allow) C:\Program Files (x86)\Microsoft Visual Studio 14.0\Common7\IDE\devenv.exe
- FirewallRules: [{34ABD6D1-2EE4-44F1-8D73-F05BEA8E0243}] => (Allow) C:\Program Files (x86)\Microsoft Visual Studio 14.0\Common7\IDE\devenv.exe
- FirewallRules: [TCP Query User{B58FDB47-5AB0-49FB-85E9-0455CD8DFE97}C:\program files\java\jre1.8.0_131\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_131\bin\javaw.exe
- FirewallRules: [UDP Query User{854A9604-585A-4C3E-8F44-3552373D7410}C:\program files\java\jre1.8.0_131\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_131\bin\javaw.exe
- FirewallRules: [TCP Query User{D43C214D-9E00-4FDB-BB69-C4EFC45F6362}M:\rats\r4t\jrat-v0.7d\njrat v0.7d.exe] => (Allow) M:\rats\r4t\jrat-v0.7d\njrat v0.7d.exe
- FirewallRules: [UDP Query User{6E92F67B-3A03-4E51-9553-31959C470C82}M:\rats\r4t\jrat-v0.7d\njrat v0.7d.exe] => (Allow) M:\rats\r4t\jrat-v0.7d\njrat v0.7d.exe
- FirewallRules: [{A7C37E60-D010-4CCC-A9F5-6D39C746A6E8}] => (Allow) C:\Program Files (x86)\uTorrent\uTorrent.exe
- FirewallRules: [{7ABE91F0-DD2F-4E7B-8C5D-98FF0B752CE8}] => (Allow) C:\Program Files (x86)\uTorrent\uTorrent.exe
- FirewallRules: [{53C07590-D5E6-4447-BC4C-BBA2277FCBD2}] => (Allow) C:\Program Files (x86)\Winamp\winamp.exe
- FirewallRules: [{1C1555CC-4E53-426A-A481-7CC78F82EB22}] => (Allow) C:\Program Files (x86)\Winamp\winamp.exe
- FirewallRules: [{3616633F-B895-4142-A150-764C2FC35707}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\wallpaper_engine\launcher.exe
- FirewallRules: [{08BEA94D-5F35-4CFC-A4E2-A515AE71E9A0}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\wallpaper_engine\launcher.exe
- FirewallRules: [{5F277DA4-A598-4CF9-B9BA-A9FF373B7026}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
- FirewallRules: [{EED162E1-C86E-4B44-8E4D-5F408DB8903A}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
- FirewallRules: [{E5174014-0306-4F52-8C0C-1B9F982B7BD9}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
- FirewallRules: [{DCD8AAA7-523A-4E27-826D-E55EFF211979}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
- FirewallRules: [{3922494D-0D06-494F-907C-53AC267C0037}] => (Allow) C:\Program Files (x86)\MyHotspot\MyHotspot.exe
- FirewallRules: [{2CF471D4-DFCD-407C-BDD8-0458AEDA72F1}] => (Allow) C:\Program Files (x86)\MyHotspot\MyHotspot.exe
- FirewallRules: [{9771BEB8-0AB5-4661-B57A-C48C98EFCB16}] => (Allow) C:\Program Files (x86)\MyHotspot\HotspotService.exe
- FirewallRules: [{375B693E-97F8-420C-AEA0-4E03E94578D6}] => (Allow) C:\Program Files (x86)\MyHotspot\HotspotService.exe
- FirewallRules: [{7806F7E7-AF8B-4D96-8075-9DF5DC1F2861}] => (Allow) C:\Program Files (x86)\WiFiCreator\WiFiCreator.exe
- FirewallRules: [{DF7AA68E-E04D-433F-A47B-E31863CC541B}] => (Allow) C:\Program Files (x86)\WiFiCreator\WiFiCreator.exe
- FirewallRules: [{7740BB2A-F3A4-4015-9A4E-1A328FEB6BA5}] => (Allow) C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe
- FirewallRules: [{F146E381-7714-48CA-B0C0-29F77709F7DC}] => (Allow) C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe
- FirewallRules: [{9F8A2C34-88A6-4203-BFE9-6BF192D4C227}] => (Allow) C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe
- FirewallRules: [{001B0A53-B706-4D2E-B203-773B3648AFC8}] => (Allow) C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe
- FirewallRules: [{168EBCFF-37FD-4E91-8A19-4171238CB558}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
- FirewallRules: [{9F6F8A47-30CC-4118-8270-7BF4F2DB21EE}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
- FirewallRules: [{C53F057B-2CA2-475D-BE0D-2C947B96AD0F}] => (Allow) C:\Program Files (x86)\Remotr\RemotrServer.exe
- FirewallRules: [{1E87CF84-C54E-41C2-AC27-18FF30B69034}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\PAYDAY 2\payday2_win32_release.exe
- FirewallRules: [{664E3AE3-1A0C-4A6F-95CE-F37BBC601203}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\PAYDAY 2\payday2_win32_release.exe
- FirewallRules: [{A99C9973-C8F1-4CC8-924F-7879CAB8BB08}] => (Allow) C:\Program Files\iTunes\iTunes.exe
- FirewallRules: [{640C020E-2ADD-4D4D-B63C-D7248BA2EB9A}] => (Allow) C:\Users\Qwerty\AppData\Local\Temp\andy-x64\Setup.exe
- FirewallRules: [{AA2D4753-17E6-4547-9B5F-4C2E89198135}] => (Allow) C:\Users\Qwerty\AppData\Local\Temp\andy-x64\Setup.exe
- FirewallRules: [{08A4B5AD-0112-482A-B655-732293AF4FC1}] => (Allow) C:\Program Files\Andy\andy.exe
- FirewallRules: [{B4D79CE4-54EC-4DA0-A9DA-5AAA8B00F30B}] => (Allow) C:\Program Files\Andy\andy.exe
- FirewallRules: [{839E5632-7789-443D-B57D-7E215289E592}] => (Allow) C:\Program Files\Andy\AndyConsole.exe
- FirewallRules: [{EC493F75-D294-48E5-8D28-8910A3DC1756}] => (Allow) C:\Program Files\Andy\AndyConsole.exe
- FirewallRules: [{4804EE0D-81AF-4E39-B822-5FA94DC73A35}] => (Allow) C:\Program Files\Andy\HandyAndy.exe
- FirewallRules: [{2F926C9B-C5F0-4F23-BBD7-8DE6B140DF61}] => (Allow) C:\Program Files\Andy\HandyAndy.exe
- FirewallRules: [{D7274424-ABEA-44CB-B4A6-8F2A52342E61}] => (Allow) C:\Program Files\Andy\SetupFiles\Uninstall.exe
- FirewallRules: [{950EBF19-071E-459E-B3B7-E5840B3A9C41}] => (Allow) C:\Program Files\Andy\SetupFiles\Uninstall.exe
- FirewallRules: [{19A605CC-875C-4B2B-BE44-6DAB9B36596E}] => (Allow) C:\Users\Qwerty\AppData\Local\Temp\RemoveTemp.exe
- FirewallRules: [{0FAC1D8A-DACD-4FC6-9309-E699F2A1AC61}] => (Allow) C:\Users\Qwerty\AppData\Local\Temp\RemoveTemp.exe
- FirewallRules: [{905924F9-44B7-43DE-8243-71623B2D26A6}] => (Allow) C:\Program Files\Andy\SetupFiles\VMwareCheck.exe
- FirewallRules: [{205F247B-F0C1-482D-A53A-4F27E1072965}] => (Allow) C:\Program Files\Andy\SetupFiles\VMwareCheck.exe
- FirewallRules: [{9B549D92-BE2D-477D-BA62-A2A82531F8C2}] => (Allow) C:\Program Files\Andy\SetupFiles\AndyDoctor.exe
- FirewallRules: [{39008C39-780E-4F86-8C24-1C26BDFE2CF0}] => (Allow) C:\Program Files\Andy\SetupFiles\AndyDoctor.exe
- FirewallRules: [{020081AC-95DC-41B9-903D-2B106F6646BE}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- FirewallRules: [{4A46FEA5-B989-45AB-BDCC-F8E7E92F7865}] => (Allow) C:\Program Files (x86)\TVMOBiLi\bin\tvMobiliService.exe
- FirewallRules: [{FA5C20AD-6980-4D88-B74F-2EDAC18DA4B4}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
- FirewallRules: [{CEDEBA3B-D73A-4A19-9B56-5F03B1935484}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
- FirewallRules: [{49772EB4-B184-4E0C-9173-552E02A246F1}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
- FirewallRules: [{FD39CD8A-D84D-499B-8EE3-26031606CDEF}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
- FirewallRules: [{2D35755B-305D-45B3-BD49-33B069CECE97}] => (Allow) C:\Program Files\NewsBin\Newsbinpro64.exe
- FirewallRules: [{E56EE37F-7A8A-4471-8E7F-A3001B6C9B26}] => (Allow) C:\Program Files\NewsBin\Newsbinpro64.exe
- FirewallRules: [{8D784FC7-B792-44BE-892D-EFE1F5CD3890}] => (Allow) C:\Program Files\SABnzbd\SABnzbd.exe
- FirewallRules: [{36BE2DC5-3DF4-44E1-8023-B17F7BC0BE3E}] => (Allow) C:\Program Files\SABnzbd\SABnzbd.exe
- FirewallRules: [{10500EBB-D3CA-4DA8-842B-F90466D6733B}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\rocketleague\Binaries\Win32\RocketLeague.exe
- FirewallRules: [{5281E602-BE50-48DE-B317-9F72697A55E5}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\rocketleague\Binaries\Win32\RocketLeague.exe
- FirewallRules: [{213CF73F-50FC-4EBD-95BB-BB244B6BC69D}] => (Block) %ProgramFiles% (x86)\Mirillis\Action!\Action.exe
- FirewallRules: [TCP Query User{D2F0C15C-47CE-47BD-9331-66EEAFFFA0F3}C:\smartpixel\bin\smartpixel.exe] => (Allow) C:\smartpixel\bin\smartpixel.exe
- FirewallRules: [UDP Query User{B924E38C-217F-4E18-AABA-8C02D767B753}C:\smartpixel\bin\smartpixel.exe] => (Allow) C:\smartpixel\bin\smartpixel.exe
- FirewallRules: [TCP Query User{CEDABA48-C015-4BCD-A26D-0C038C28F859}C:\users\qwerty\appdata\roaming\netframeworkd.exe] => (Allow) C:\users\qwerty\appdata\roaming\netframeworkd.exe
- FirewallRules: [UDP Query User{3B9B7150-ACC8-4151-A263-ACFDD34CC591}C:\users\qwerty\appdata\roaming\netframeworkd.exe] => (Allow) C:\users\qwerty\appdata\roaming\netframeworkd.exe
- FirewallRules: [TCP Query User{1F9D216E-6CAE-4878-99E8-99E8B08A8699}C:\program files (x86)\tvmobili\bin\itunesalbumartgenerator.exe] => (Allow) C:\program files (x86)\tvmobili\bin\itunesalbumartgenerator.exe
- FirewallRules: [UDP Query User{BB76B634-DB8A-4379-913C-148F09A8DA68}C:\program files (x86)\tvmobili\bin\itunesalbumartgenerator.exe] => (Allow) C:\program files (x86)\tvmobili\bin\itunesalbumartgenerator.exe
- FirewallRules: [{936DE372-1E28-40D6-8B92-FF9F49D07A79}] => (Allow) LPort=8318
- FirewallRules: [{ED53AA1F-F798-4755-9A93-9BD7B313E589}] => (Block) %ProgramFiles% (x86)\TechSmith Corporation\Camtasia 9\camtasia.exe
- FirewallRules: [{BE2DBCD7-F20E-4DE1-AC8D-5F04B0C9F46C}] => (Block) %ProgramFiles% (x86)\TechSmith Corporation\Camtasia 9\camtasia.exe
- FirewallRules: [TCP Query User{E0BE4825-9DC5-44F0-BA60-6EE258B9A2E4}C:\program files (x86)\skype\browser\skypebrowserhost.exe] => (Allow) C:\program files (x86)\skype\browser\skypebrowserhost.exe
- FirewallRules: [UDP Query User{8D2E0859-A703-4010-9304-57A47CFA41BD}C:\program files (x86)\skype\browser\skypebrowserhost.exe] => (Allow) C:\program files (x86)\skype\browser\skypebrowserhost.exe
- ==================== Restore Points =========================
- 09-07-2017 15:20:35 Camtasia 9
- ==================== Faulty Device Manager Devices =============
- Name: VMware VMCI Host Device
- Description: VMware VMCI Host Device
- Class Guid: {4d36e97d-e325-11ce-bfc1-08002be10318}
- Manufacturer: VMware, Inc.
- Service: vmci
- Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31)
- Resolution: Update the driver
- ==================== Event log errors: =========================
- Application errors:
- ==================
- Error: (07/09/2017 02:41:17 PM) (Source: Application Error) (EventID: 1000) (User: )
- Description: Faulting application name: bdcam.exe, version: 3.4.2.1258, time stamp: 0x5927e449
- Faulting module name: bdcam.exe, version: 3.4.2.1258, time stamp: 0x5927e449
- Exception code: 0xc0000005
- Fault offset: 0x0008d14d
- Faulting process id: 0xa10
- Faulting application start time: 0x01d2f8b9055c42ba
- Faulting application path: C:\Program Files (x86)\Bandicam\bdcam.exe
- Faulting module path: C:\Program Files (x86)\Bandicam\bdcam.exe
- Report Id: 4814712d-64ac-11e7-a4bc-ccf8d483bb0a
- Error: (07/09/2017 02:40:58 PM) (Source: Application Error) (EventID: 1000) (User: )
- Description: Faulting application name: bdcam.exe, version: 3.4.2.1258, time stamp: 0x5927e449
- Faulting module name: bdcam.exe, version: 3.4.2.1258, time stamp: 0x5927e449
- Exception code: 0xc0000005
- Fault offset: 0x0008d14d
- Faulting process id: 0x205c
- Faulting application start time: 0x01d2f8b8ea5cb3b7
- Faulting application path: C:\Program Files (x86)\Bandicam\bdcam.exe
- Faulting module path: C:\Program Files (x86)\Bandicam\bdcam.exe
- Report Id: 3cfe733f-64ac-11e7-a4bc-ccf8d483bb0a
- Error: (07/09/2017 02:30:58 PM) (Source: Application Error) (EventID: 1000) (User: )
- Description: Faulting application name: Explorer.EXE, version: 6.1.7601.23537, time stamp: 0x57c44efe
- Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
- Exception code: 0xc0000005
- Fault offset: 0x0000000002e60fae
- Faulting process id: 0x630
- Faulting application start time: 0x01d2f83fed00d4e5
- Faulting application path: C:\Windows\Explorer.EXE
- Faulting module path: unknown
- Report Id: d6ed341d-64aa-11e7-a4bc-ccf8d483bb0a
- Error: (07/09/2017 12:20:13 AM) (Source: Application Hang) (EventID: 1002) (User: )
- Description: The program tixati.exe version 2.53.1.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
- Process ID: e00
- Start Time: 01d2f8401c4f8bca
- Termination Time: 34
- Application Path: C:\Program Files\tixati\tixati.exe
- Report Id: f8c1f281-6433-11e7-a4bc-ccf8d483bb0a
- Error: (07/09/2017 12:17:25 AM) (Source: WinMgmt) (EventID: 10) (User: )
- Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
- Error: (07/09/2017 12:15:53 AM) (Source: PerfNet) (EventID: 2004) (User: )
- Description: Unable to open the Server service performance object. The first four bytes (DWORD) of the Data section contains the status code.
- Error: (07/08/2017 05:24:14 PM) (Source: Application Error) (EventID: 1000) (User: )
- Description: Faulting application name: Explorer.EXE, version: 6.1.7601.23537, time stamp: 0x57c44efe
- Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
- Exception code: 0xc0000005
- Fault offset: 0x0000000003b30fae
- Faulting process id: 0x608
- Faulting application start time: 0x01d2f7dde699ee4f
- Faulting application path: C:\Windows\Explorer.EXE
- Faulting module path: unknown
- Report Id: e17ac229-63f9-11e7-8a85-cae752885f08
- Error: (07/08/2017 04:58:53 PM) (Source: Application Hang) (EventID: 1002) (User: )
- Description: The program citra-qt.exe version 0.0.0.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
- Process ID: 20dc
- Start Time: 01d2f7ffc863563b
- Termination Time: 11
- Application Path: C:\Users\Qwerty\AppData\Local\citra\app-0.1.405\citra-qt.exe
- Report Id: 54d13c68-63f6-11e7-8a85-cae752885f08
- Error: (07/08/2017 12:35:04 PM) (Source: WinMgmt) (EventID: 10) (User: )
- Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
- Error: (07/07/2017 07:22:54 AM) (Source: WinMgmt) (EventID: 10) (User: )
- Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
- System errors:
- =============
- Error: (07/09/2017 04:35:19 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
- Description: The Computer Browser service depends on the Workstation service which failed to start because of the following error:
- The dependency service or group failed to start.
- Error: (07/09/2017 04:35:19 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
- Description: The Workstation service depends on the SMB 1.x MiniRedirector service which failed to start because of the following error:
- The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
- Error: (07/09/2017 04:35:19 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
- Description: The Computer Browser service depends on the Workstation service which failed to start because of the following error:
- The dependency service or group failed to start.
- Error: (07/09/2017 04:35:19 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
- Description: The Workstation service depends on the SMB 1.x MiniRedirector service which failed to start because of the following error:
- The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
- Error: (07/09/2017 04:35:19 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
- Description: The Computer Browser service depends on the Workstation service which failed to start because of the following error:
- The dependency service or group failed to start.
- Error: (07/09/2017 04:35:19 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
- Description: The Workstation service depends on the SMB 1.x MiniRedirector service which failed to start because of the following error:
- The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
- Error: (07/09/2017 04:35:19 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
- Description: The Computer Browser service depends on the Workstation service which failed to start because of the following error:
- The dependency service or group failed to start.
- Error: (07/09/2017 04:35:19 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
- Description: The Workstation service depends on the SMB 1.x MiniRedirector service which failed to start because of the following error:
- The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
- Error: (07/09/2017 04:35:19 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
- Description: The Computer Browser service depends on the Workstation service which failed to start because of the following error:
- The dependency service or group failed to start.
- Error: (07/09/2017 04:35:19 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
- Description: The Workstation service depends on the SMB 1.x MiniRedirector service which failed to start because of the following error:
- The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
- ==================== Memory info ===========================
- Processor: Intel(R) Pentium(R) CPU 2020M @ 2.40GHz
- Percentage of memory in use: 54%
- Total physical RAM: 6039.36 MB
- Available physical RAM: 2744.95 MB
- Total Virtual: 12076.89 MB
- Available Virtual: 8513.88 MB
- ==================== Drives ================================
- Drive c: () (Fixed) (Total:465.76 GB) (Free:23.91 GB) NTFS ==>[drive with boot components (obtained from BCD)]
- ==================== MBR & Partition Table ==================
- ========================================================
- Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: C196BC2D)
- Partition 1: (Active) - (Size=465.8 GB) - (Type=07 NTFS)
- ========================================================
- Disk: 1 (Size: 29.7 GB) (Disk ID: 00000000)
- Partition: GPT.
- ==================== End of Addition.txt ============================[/spoiler]
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement