Advertisement
Guest User

Untitled

a guest
Jul 9th, 2017
126
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 186.03 KB | None | 0 0
  1. FRST
  2. [spoiler]Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 08-07-2017
  3. Ran by Qwerty (administrator) on QWERTY-PC (09-07-2017 16:31:46)
  4. Running from C:\Users\Qwerty\Downloads
  5. Loaded Profiles: Qwerty (Available Profiles: Qwerty & DefaultAppPool)
  6. Platform: Windows 7 Ultimate Service Pack 1 (X64) Language: English (United States)
  7. Internet Explorer Version 11 (Default browser: Chrome)
  8. Boot Mode: Normal
  9. Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
  10.  
  11. ==================== Processes (Whitelisted) =================
  12.  
  13. (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
  14.  
  15. (Intel Corporation) C:\Windows\System32\igfxCUIService.exe
  16. (Stardock Corporation) C:\Program Files (x86)\Stardock\WindowBlinds\WBSrv.exe
  17. (Stardock Software, Inc) C:\Program Files (x86)\Stardock\WindowBlinds\WBCore.exe
  18. (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
  19. (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
  20. (Windows (R) Win 7 DDK provider) C:\Program Files (x86)\Bluetooth Suite\AdminService.exe
  21. (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
  22. (FileZilla Project) C:\Program Files (x86)\FileZilla Server\FileZilla Server.exe
  23. (Qualcomm®Atheros®) C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe
  24. (AnchorFree Inc.) C:\Program Files (x86)\Hotspot Shield\bin\cmw_srv.exe
  25. (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
  26. (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
  27. (Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
  28. (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
  29. (The SABnzbd-team) C:\Program Files\SABnzbd\SABnzbd.exe
  30. (Cerulean Studios) C:\Program Files (x86)\Trillian56\trillian.exe
  31. (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
  32. (Alexandr Irza) C:\Program Files (x86)\Volume2\Volume2.exe
  33. (VMware, Inc.) C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe
  34. () C:\Users\Qwerty\Downloads\d3d\D3DOverrider.exe
  35. (Qualcomm Atheros) C:\Program Files (x86)\Bluetooth Suite\BtTray.exe
  36. () C:\Program Files (x86)\NETGEAR\A6210\NetgearSwitchUSB.exe
  37. (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
  38. () C:\Windows\SysWOW64\PnkBstrA.exe
  39. () C:\Windows\SysWOW64\PnkBstrB.exe
  40. (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
  41. (Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
  42. (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
  43. (Tenorshare Co,Ltd) C:\Program Files (x86)\ReiBoot\TenorshareReibootService.exe
  44. () C:\Program Files (x86)\TVMOBiLi\bin\tvMobiliService.exe
  45. (VMware, Inc.) C:\Windows\SysWOW64\vmnat.exe
  46. (Azzouzi Software) C:\Program Files (x86)\WiFiCreator\WifiCreatorSvc.exe
  47. (Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
  48. (VMware, Inc.) C:\Windows\SysWOW64\vmnetdhcp.exe
  49. (Microsoft Corporation) C:\Windows\System32\alg.exe
  50. (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
  51. (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
  52. (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_w32.exe
  53. (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_x64.exe
  54. (Intel Corporation) C:\Windows\System32\igfxEM.exe
  55. (Intel Corporation) C:\Windows\System32\igfxHK.exe
  56. () C:\Program Files\WALTR2\x86\WALTR2Service.exe
  57. (Bandicam Company) C:\Program Files (x86)\Bandicam\bdcam64.bin
  58. (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe
  59. (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe
  60. (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v2.0.50727\RegSvcs.exe
  61. (AVAST Software s.r.o.) C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe
  62. (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
  63. (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
  64. (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
  65. (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
  66. (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
  67. (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
  68. (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
  69. (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
  70. (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
  71. (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
  72. (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
  73. (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
  74. (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
  75. (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
  76. (Skype Technologies) C:\Program Files (x86)\Skype\Browser\SkypeBrowserHost.exe
  77. (Skype Technologies) C:\Program Files (x86)\Skype\Browser\SkypeBrowserHost.exe
  78. (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
  79. (Microsoft Corporation) C:\Windows\System32\dllhost.exe
  80.  
  81. ==================== Registry (Whitelisted) ====================
  82.  
  83. (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
  84.  
  85. HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [213832 2017-07-02] (AVAST Software)
  86. HKLM\...\Run: [Malwarebytes TrayApp] => C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe [3146704 2017-05-09] (Malwarebytes)
  87. HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [303928 2017-05-09] (Apple Inc.)
  88. HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2017-03-15] (Oracle Corporation)
  89. HKLM-x32\...\Run: [Volume2] => C:\Program Files (x86)\Volume2\Volume2.exe [4797440 2017-03-28] (Alexandr Irza)
  90. HKLM-x32\...\Run: [vmware-tray.exe] => C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe [104128 2016-04-14] (VMware, Inc.)
  91. HKLM-x32\...\Run: [D3DOverrider] => C:\Users\Qwerty\Downloads\d3d\D3DOverriderWrapper.exe [40960 2017-07-09] ()
  92. HKLM-x32\...\Run: [OfficeUpdate] => C:\Users\Qwerty\AppData\Local\Temp\prp\sqb.exe [750320 2012-01-29] (AutoIt Team) <==== ATTENTION
  93. HKLM-x32\...\Run: [lwsUpdate] => C:\Users\Qwerty\AppData\Roaming\tws\hkg.exe [750320 2012-01-29] (AutoIt Team)
  94. Winlogon\Notify\igfxcui: igfxdev.dll [X]
  95. HKLM\...\Policies\Explorer\Run: [BtvStack] => C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [132736 2013-09-25] (Qualcomm®Atheros®)
  96. HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
  97. HKU\S-1-5-21-3858528921-1604397686-3684385761-1000\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3042592 2017-06-08] (Valve Corporation)
  98. HKU\S-1-5-21-3858528921-1604397686-3684385761-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [27784672 2017-06-27] (Skype Technologies S.A.)
  99. HKU\S-1-5-21-3858528921-1604397686-3684385761-1000\...\Run: [uTorrent] => C:\Program Files (x86)\uTorrent\uTorrent.exe [393728 2017-07-09] (BitTorrent, Inc.)
  100. HKU\S-1-5-21-3858528921-1604397686-3684385761-1000\...\Run: [GUDelayStartup] => C:\Program Files (x86)\Glary Utilities 5\StartupManager.exe [44016 2017-06-30] (Glarysoft Ltd)
  101. HKU\S-1-5-21-3858528921-1604397686-3684385761-1000\...\Policies\Explorer: [HideSCAVolume] 1
  102. HKU\S-1-5-21-3858528921-1604397686-3684385761-1000\...\Policies\Explorer: [HideSCAPower] 0
  103. HKU\S-1-5-21-3858528921-1604397686-3684385761-1000\...\MountPoints2: {78ed7ff8-431e-11e7-b3f9-40f02f265644} - F:\Autorun.exe
  104. HKU\S-1-5-21-3858528921-1604397686-3684385761-1000\...\MountPoints2: {78ed7ffb-431e-11e7-b3f9-40f02f265644} - G:\setup.exe
  105. HKU\S-1-5-21-3858528921-1604397686-3684385761-1000\...\MountPoints2: {b45c9a13-452a-11e7-ae75-40f02f265644} - I:\TDR2000Menu.exe
  106. Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\TVMOBiLiArtworkManager.lnk [2017-07-02]
  107. ShortcutTarget: TVMOBiLiArtworkManager.lnk -> C:\Program Files (x86)\TVMOBiLi\bin\iTunesAlbumArtGenerator.exe ()
  108. Startup: C:\Users\Qwerty\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\SABnzbd.lnk [2017-07-05]
  109. ShortcutTarget: SABnzbd.lnk -> C:\Program Files\SABnzbd\SABnzbd.exe (The SABnzbd-team)
  110. Startup: C:\Users\Qwerty\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Trillian.lnk [2017-05-16]
  111. ShortcutTarget: Trillian.lnk -> C:\Program Files (x86)\Trillian56\trillian.exe (Cerulean Studios)
  112. BootExecute: autocheck autochk * bootdeleteaswBoot.exe /M:37d52340b6 /wow /dir:"C:\Program Files\AVAST Software\Avast"
  113. AlternateShell:
  114. GroupPolicy\User: Restriction <==== ATTENTION
  115. GroupPolicyScripts\User: Restriction <==== ATTENTION
  116.  
  117. ==================== Internet (Whitelisted) ====================
  118.  
  119. (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
  120.  
  121. Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
  122. Tcpip\Parameters: [DhcpNameServer] 212.50.160.100 213.249.130.100
  123. Tcpip\..\Interfaces\{362DD804-0F8C-4B0B-8FEB-A15851E7CF80}: [DhcpNameServer] 212.50.160.100 213.249.130.100
  124.  
  125. Internet Explorer:
  126. ==================
  127. HKU\S-1-5-21-3858528921-1604397686-3684385761-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/en-gb/?ocid=iehp
  128. BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_131\bin\ssv.dll [2017-05-12] (Oracle Corporation)
  129. BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2017-07-02] (AVAST Software)
  130. BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_131\bin\jp2ssv.dll [2017-05-12] (Oracle Corporation)
  131. BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_131\bin\ssv.dll [2017-05-12] (Oracle Corporation)
  132. BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2017-07-02] (AVAST Software)
  133. BHO-x32: Microsoft Web Test Recorder 14.0 Helper -> {b924f0b4-0b3c-49c0-bab2-213fb9ebd1d3} -> C:\Program Files (x86)\Microsoft Visual Studio 14.0\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll [2015-07-07] (Microsoft Corporation)
  134. BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_131\bin\jp2ssv.dll [2017-05-12] (Oracle Corporation)
  135.  
  136. FireFox:
  137. ========
  138. FF DefaultProfile: 96btujvl.default
  139. FF ProfilePath: C:\Users\Qwerty\AppData\Roaming\oneteam\Profiles\vaywo2pe.default [2017-05-15]
  140. FF ProfilePath: C:\Users\Qwerty\AppData\Roaming\Mozilla\Firefox\Profiles\96btujvl.default [2017-07-02]
  141. FF Extension: (uBlock Origin) - C:\Users\Qwerty\AppData\Roaming\Mozilla\Firefox\Profiles\96btujvl.default\Extensions\uBlock0@raymondhill.net.xpi [2017-06-08]
  142. FF Extension: (Avast Online Security) - C:\Users\Qwerty\AppData\Roaming\Mozilla\Firefox\Profiles\96btujvl.default\Extensions\wrc@avast.com.xpi [2017-06-14]
  143. FF Plugin: @java.com/DTPlugin,version=11.131.2 -> C:\Program Files\Java\jre1.8.0_131\bin\dtplugin\npDeployJava1.dll [2017-05-12] (Oracle Corporation)
  144. FF Plugin: @java.com/JavaPlugin,version=11.131.2 -> C:\Program Files\Java\jre1.8.0_131\bin\plugin2\npjp2.dll [2017-05-12] (Oracle Corporation)
  145. FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
  146. FF Plugin: @videolan.org/vlc,version=2.2.5.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
  147. FF Plugin: @videolan.org/vlc,version=2.2.6 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
  148. FF Plugin-x32: @java.com/DTPlugin,version=11.131.2 -> C:\Program Files (x86)\Java\jre1.8.0_131\bin\dtplugin\npDeployJava1.dll [2017-05-12] (Oracle Corporation)
  149. FF Plugin-x32: @java.com/JavaPlugin,version=11.131.2 -> C:\Program Files (x86)\Java\jre1.8.0_131\bin\plugin2\npjp2.dll [2017-05-12] (Oracle Corporation)
  150. FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
  151. FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll [2013-05-13] ( Microsoft Corporation)
  152. FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-05-12] (Google Inc.)
  153. FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-05-12] (Google Inc.)
  154.  
  155. Chrome:
  156. =======
  157. CHR DefaultProfile: Default
  158. CHR HomePage: Default -> hxxp://google.com/
  159. CHR StartupUrls: Default -> "hxxp://widgetpage4u.webs.com/","bdbrowser://tabpage/","hxxp://www.google.com/","hxxp://home.torchbrowser.com/?systemid=448&appid=0&ua=Torch","search.mpc.am","hxxp://iron-start.com/"
  160. CHR Profile: C:\Users\Qwerty\AppData\Local\Google\Chrome\User Data\Default [2017-07-09]
  161. CHR Extension: (Google Slides) - C:\Users\Qwerty\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-05-12]
  162. CHR Extension: (Port Checker Tool) - C:\Users\Qwerty\AppData\Local\Google\Chrome\User Data\Default\Extensions\acineinfhneplngnmlmmmfjojdbpclbp [2017-05-12]
  163. CHR Extension: (Free Download Manager Chrome extension) - C:\Users\Qwerty\AppData\Local\Google\Chrome\User Data\Default\Extensions\ahmpjcflkgiildlgicmcieglgoilbfdp [2017-05-12]
  164. CHR Extension: (Google Docs) - C:\Users\Qwerty\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-05-12]
  165. CHR Extension: (Google Drive) - C:\Users\Qwerty\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-05-12]
  166. CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Qwerty\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2017-05-12]
  167. CHR Extension: (MEGA) - C:\Users\Qwerty\AppData\Local\Google\Chrome\User Data\Default\Extensions\bigefpfhnfcobdlfbedofhhaibnlghod [2017-07-02]
  168. CHR Extension: (YouTube) - C:\Users\Qwerty\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-05-12]
  169. CHR Extension: (Google Cast for Education) - C:\Users\Qwerty\AppData\Local\Google\Chrome\User Data\Default\Extensions\bnmgbcehmiinmmlmepibeeflglhbhlea [2017-06-02]
  170. CHR Extension: (DuckieTV - 'Browser Action' mode) - C:\Users\Qwerty\AppData\Local\Google\Chrome\User Data\Default\Extensions\cdfkaloficjmdjbgmckaddgfcghgidei [2017-05-12]
  171. CHR Extension: (uBlock Origin) - C:\Users\Qwerty\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpalhdlnbpafiamejdnhcphjbkeiagm [2017-06-21]
  172. CHR Extension: (Spotify - Music for every moment) - C:\Users\Qwerty\AppData\Local\Google\Chrome\User Data\Default\Extensions\cnkjkdjlofllcpbemipjbcpfnglbgieh [2017-05-12]
  173. CHR Extension: (Netflix) - C:\Users\Qwerty\AppData\Local\Google\Chrome\User Data\Default\Extensions\deceagebecbceejblnlcjooeohmmeldh [2017-05-12]
  174. CHR Extension: (Tampermonkey) - C:\Users\Qwerty\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhdgffkkebhmkfjojejmpbldmpobfkfo [2017-05-12]
  175. CHR Extension: (Video Downloader professional) - C:\Users\Qwerty\AppData\Local\Google\Chrome\User Data\Default\Extensions\elicpjhcidhpjomhibiffojpinpmmpil [2017-05-12]
  176. CHR Extension: (Disable Youtube™ HTML5 Player) - C:\Users\Qwerty\AppData\Local\Google\Chrome\User Data\Default\Extensions\enmofgaijnbjpblfljopnpdogpldapoc [2017-05-12]
  177. CHR Extension: (Google Play Music) - C:\Users\Qwerty\AppData\Local\Google\Chrome\User Data\Default\Extensions\fahmaaghhglfmonjliepjlchgpgfmobi [2017-07-07]
  178. CHR Extension: (Google Sheets) - C:\Users\Qwerty\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-05-12]
  179. CHR Extension: (HTML Revealer and Password Revealer) - C:\Users\Qwerty\AppData\Local\Google\Chrome\User Data\Default\Extensions\fgeopcldenngppapceagonnenonklpbn [2017-05-12]
  180. CHR Extension: (EditThisCookie) - C:\Users\Qwerty\AppData\Local\Google\Chrome\User Data\Default\Extensions\fngmhnnpilhplaeedifhccceomclgfbg [2017-05-12]
  181. CHR Extension: (Netease Music) - C:\Users\Qwerty\AppData\Local\Google\Chrome\User Data\Default\Extensions\fogcjafchgdhdoieggbeldnckbghdpkn [2017-05-14]
  182. CHR Extension: (Chrome Remote Desktop) - C:\Users\Qwerty\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbchcmhmhahfdphkhkmpfmihenigjmpp [2017-06-08]
  183. CHR Extension: (Google Docs Offline) - C:\Users\Qwerty\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-05-12]
  184. CHR Extension: (Vysor) - C:\Users\Qwerty\AppData\Local\Google\Chrome\User Data\Default\Extensions\gidgenkbbabolejbgbpnhbimgjbffefm [2017-07-08]
  185. CHR Extension: (Blockchain) - C:\Users\Qwerty\AppData\Local\Google\Chrome\User Data\Default\Extensions\glaohkkooicollgefkkmndjcbblominl [2017-05-12]
  186. CHR Extension: (Avast Online Security) - C:\Users\Qwerty\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2017-06-07]
  187. CHR Extension: (LastPass: Free Password Manager) - C:\Users\Qwerty\AppData\Local\Google\Chrome\User Data\Default\Extensions\hdokiejnpimakedhajhdlcegeplioahd [2017-07-07]
  188. CHR Extension: (OkayFreedom) - C:\Users\Qwerty\AppData\Local\Google\Chrome\User Data\Default\Extensions\hfnbbbkabnehoejfhcbbhdicagcoobji [2017-05-12]
  189. CHR Extension: (AllCast Receiver) - C:\Users\Qwerty\AppData\Local\Google\Chrome\User Data\Default\Extensions\hjbljnpdahefgnopeohlaeohgkiidnoe [2017-05-12]
  190. CHR Extension: (Google Keep - notes and lists) - C:\Users\Qwerty\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmjkmjkepdijhoojdojkdfohbdgmmhki [2017-07-07]
  191. CHR Extension: (vGet Extension (Video Downloader, DLNA)) - C:\Users\Qwerty\AppData\Local\Google\Chrome\User Data\Default\Extensions\hniladkejehjfchadikcbjmgjaogciic [2017-05-12]
  192. CHR Extension: (Roms43 for Chrome) - C:\Users\Qwerty\AppData\Local\Google\Chrome\User Data\Default\Extensions\hodglkaodhnbkakchphcmbgdinlgcfgc [2017-05-12]
  193. CHR Extension: (FireRTC) - C:\Users\Qwerty\AppData\Local\Google\Chrome\User Data\Default\Extensions\iaamfpbohecgihgnbhmppgekdjkbolah [2017-05-12]
  194. CHR Extension: (VNC® Viewer for Google Chrome™) - C:\Users\Qwerty\AppData\Local\Google\Chrome\User Data\Default\Extensions\iabmpiboiopbgfabjmgeedhcmjenhbla [2017-05-12]
  195. CHR Extension: (GAuth Authenticator) - C:\Users\Qwerty\AppData\Local\Google\Chrome\User Data\Default\Extensions\ilgcnhelpchnceeipipijaljkblbcobl [2017-05-12]
  196. CHR Extension: (Avira SafeSearch Plus) - C:\Users\Qwerty\AppData\Local\Google\Chrome\User Data\Default\Extensions\ipmkfpcnmccejididiaagpgchgjfajgp [2017-06-08]
  197. CHR Extension: (FireRTC Extension) - C:\Users\Qwerty\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmkpkghdacjfjfipnjbknnpdabkllcel [2017-05-12]
  198. CHR Extension: (Evernote Web) - C:\Users\Qwerty\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbfehkoinhhcknnbdgnnmjhiladcgbol [2017-05-12]
  199. CHR Extension: (AllDebrid Extension) - C:\Users\Qwerty\AppData\Local\Google\Chrome\User Data\Default\Extensions\mdjbgnpehbhpibonmjjjbjaoechnlcaf [2017-05-12]
  200. CHR Extension: (Awesome New Tab Page) - C:\Users\Qwerty\AppData\Local\Google\Chrome\User Data\Default\Extensions\mgmiemnjjchgkmgbeljfocdjjnpjnmcg [2017-05-12]
  201. CHR Extension: (Webresolver.nl) - C:\Users\Qwerty\AppData\Local\Google\Chrome\User Data\Default\Extensions\mjelbipojiljmajjnpkokdkdbmfmmiga [2017-05-12]
  202. CHR Extension: (Chrome Web Store Payments) - C:\Users\Qwerty\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-05-12]
  203. CHR Extension: (AdF.ly Skipper ★WORKING: 7/1/2017★) - C:\Users\Qwerty\AppData\Local\Google\Chrome\User Data\Default\Extensions\obnfifcganohemahpomajbhocfkdgmjb [2017-07-02]
  204. CHR Extension: (Unblock NetEase Music) - C:\Users\Qwerty\AppData\Local\Google\Chrome\User Data\Default\Extensions\okjlonpifkjbibipgioibfecnikmhfil [2017-05-14]
  205. CHR Extension: (Gmail) - C:\Users\Qwerty\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-05-12]
  206. CHR Extension: (Chrome Media Router) - C:\Users\Qwerty\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-06-22]
  207. CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - hxxps://clients2.google.com/service/update2/crx
  208.  
  209. ==================== Services (Whitelisted) ====================
  210.  
  211. (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
  212.  
  213. R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2017-04-03] (Apple Inc.)
  214. R3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [7430992 2017-07-02] (AVAST Software s.r.o.)
  215. R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [312448 2013-09-25] (Windows (R) Win 7 DDK provider) [File not signed]
  216. R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [263312 2017-07-02] (AVAST Software)
  217. S3 Disc Soft Lite Bus Service; C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe [1471168 2017-04-24] (Disc Soft Ltd)
  218. R2 FileZilla Server; C:\Program Files (x86)\FileZilla Server\FileZilla Server.exe [859304 2017-02-08] (FileZilla Project)
  219. S3 fussvc; C:\Program Files (x86)\Windows Kits\8.1\App Certification Kit\fussvc.exe [142336 2014-02-20] (Microsoft Corporation) [File not signed]
  220. R2 hshld; C:\Program Files (x86)\Hotspot Shield\bin\cmw_srv.exe [21112 2017-06-28] (AnchorFree Inc.)
  221. R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [319096 2016-05-12] (Intel Corporation)
  222. S2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4470736 2017-05-09] (Malwarebytes)
  223. S2 MSSQL$SQLEXPRESS; c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\sqlservr.exe [57617752 2009-03-30] (Microsoft Corporation)
  224. R2 NetgearSwitchUSB; C:\Program Files (x86)\NETGEAR\A6210\NetgearSwitchUSB.exe [192232 2015-09-17] ()
  225. S3 OpenVPNService; C:\Program Files (x86)\OpenVPN\bin\openvpnserv.exe [32384 2016-10-03] (The OpenVPN Project)
  226. R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2017-05-26] ()
  227. R2 PnkBstrB; C:\Windows\SysWOW64\PnkBstrB.exe [189248 2017-05-26] ()
  228. S4 SQLAgent$SQLEXPRESS; c:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [427880 2009-03-30] (Microsoft Corporation)
  229. S3 Te.Service; C:\Program Files (x86)\Windows Kits\8.1\Testing\Runtimes\TAEF\Wex.Services.exe [119808 2013-08-22] (Microsoft Corporation) [File not signed]
  230. R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [10885360 2017-05-31] (TeamViewer GmbH)
  231. R2 TenorshareReibootService; C:\Program Files (x86)\ReiBoot\TenorshareReibootService.exe [33208 2017-01-19] (Tenorshare Co,Ltd)
  232. R2 tvMobiliService; C:\Program Files (x86)\TVMOBiLi\bin\tvMobiliService.exe [2731520 2015-04-20] () [File not signed]
  233. S3 VMwareHostd; C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe [12471368 2016-04-14] ()
  234. S3 VSStandardCollectorService140; C:\Program Files (x86)\Microsoft Visual Studio 14.0\Team Tools\DiagnosticsHub\Collector\StandardCollector.Service.exe [56040 2015-11-19] (Microsoft Corporation)
  235. R2 WALTR2Service; C:\Program Files\WALTR2\x86\WALTR2Service.exe [102312 2017-04-04] ()
  236. R2 WifiCreatorService; C:\Program Files (x86)\WiFiCreator\WiFiCreatorSvc.exe [626432 2014-01-07] (Azzouzi Software)
  237. S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
  238. R2 WindowBlinds; C:\Program Files (x86)\Stardock\WindowBlinds\wbsrv.exe [89600 2015-12-02] (Stardock Corporation) [File not signed]
  239. R2 ZAtheros Bt and Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [323584 2013-09-25] (Atheros) [File not signed]
  240.  
  241. ===================== Drivers (Whitelisted) ======================
  242.  
  243. (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
  244.  
  245. R3 A6210; C:\Windows\System32\DRIVERS\A6210.sys [2258608 2017-02-10] (MediaTek Inc.)
  246. R3 AFTrafMgr1.3; C:\Program Files (x86)\Hotspot Shield\bin\TrafMgr_1_3_64.sys [64912 2017-06-09] (AnchorFree Inc.)
  247. R1 aswbidsdriver; C:\Windows\system32\drivers\aswbidsdrivera.sys [319984 2017-07-02] (AVAST Software s.r.o.)
  248. R0 aswbidsh; C:\Windows\system32\drivers\aswbidsha.sys [198944 2017-07-02] (AVAST Software s.r.o.)
  249. R0 aswblog; C:\Windows\system32\drivers\aswbloga.sys [343264 2017-07-02] (AVAST Software s.r.o.)
  250. R0 aswbuniv; C:\Windows\system32\drivers\aswbuniva.sys [57704 2017-07-02] (AVAST Software s.r.o.)
  251. S3 aswHdsKe; C:\Windows\system32\drivers\aswHdsKe.sys [92328 2017-06-06] (AVAST Software)
  252. S3 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [46984 2017-07-02] (AVAST Software)
  253. R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [146664 2017-07-02] (AVAST Software)
  254. R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [110352 2017-07-02] (AVAST Software)
  255. R0 aswRvrt; C:\Windows\system32\drivers\aswRvrt.sys [84392 2017-07-02] (AVAST Software)
  256. R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1015848 2017-07-02] (AVAST Software)
  257. R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [585608 2017-07-02] (AVAST Software)
  258. R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [198768 2017-07-02] (AVAST Software)
  259. R0 aswVmm; C:\Windows\system32\drivers\aswVmm.sys [361336 2017-07-02] (AVAST Software)
  260. R3 BTATH_LWFLT; C:\Windows\System32\DRIVERS\btath_lwflt.sys [77464 2013-09-25] (Qualcomm Atheros)
  261. R3 dtlitescsibus; C:\Windows\System32\DRIVERS\dtlitescsibus.sys [30264 2017-05-27] (Disc Soft Ltd)
  262. R3 dtliteusbbus; C:\Windows\System32\DRIVERS\dtliteusbbus.sys [47672 2017-05-27] (Disc Soft Ltd)
  263. R1 ESProtectionDriver; C:\Windows\system32\drivers\mbae64.sys [77376 2017-06-30] ()
  264. S1 GUBootStartup; C:\Windows\System32\drivers\GUBootStartup.sys [20160 2017-07-09] (Glarysoft Ltd)
  265. S3 MBAMFarflt; C:\Windows\system32\drivers\farflt.sys [113592 2017-06-24] (Malwarebytes)
  266. S3 MBAMProtection; C:\Windows\system32\drivers\mbam.sys [44960 2017-06-24] (Malwarebytes)
  267. S3 MBAMWebProtection; C:\Windows\system32\drivers\mwac.sys [84256 2017-06-25] (Malwarebytes)
  268. R3 RSP2STOR; C:\Windows\System32\DRIVERS\RtsP2Stor.sys [273040 2013-02-01] (Realtek Semiconductor Corp.)
  269. S3 RTL8192cu; C:\Windows\System32\DRIVERS\RTL8192cu.sys [748648 2010-08-12] (Realtek Semiconductor Corporation )
  270. R3 taphss6; C:\Windows\System32\DRIVERS\taphss6.sys [42064 2017-06-15] (Anchorfree Inc.)
  271. R1 VBoxNetAdp; C:\Windows\System32\DRIVERS\VBoxNetAdp6.sys [131144 2017-04-28] (Oracle Corporation)
  272. R1 VBoxNetLwf; C:\Windows\System32\DRIVERS\VBoxNetLwf.sys [205952 2017-04-28] (Oracle Corporation)
  273. R1 veracrypt; C:\Windows\System32\drivers\veracrypt.sys [467368 2017-05-14] (IDRIX)
  274. R0 vsock; C:\Windows\System32\drivers\vsock.sys [75512 2015-11-05] (VMware, Inc.)
  275.  
  276. ==================== NetSvcs (Whitelisted) ===================
  277.  
  278. (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
  279.  
  280.  
  281. ==================== One Month Created files and folders ========
  282.  
  283. (If an entry is included in the fixlist, the file/folder will be moved.)
  284.  
  285. 2017-07-09 16:31 - 2017-07-09 16:33 - 00027495 _____ C:\Users\Qwerty\Downloads\FRST.txt
  286. 2017-07-09 16:31 - 2017-07-09 16:31 - 02437120 _____ (Farbar) C:\Users\Qwerty\Downloads\FRST64.exe
  287. 2017-07-09 16:31 - 2017-07-09 16:31 - 00000000 ____D C:\FRST
  288. 2017-07-09 16:06 - 2017-07-09 16:10 - 00001604 _____ C:\Users\Qwerty\Documents\unlimited free usenet.txt
  289. 2017-07-09 15:39 - 2017-07-09 15:39 - 00039243 _____ C:\Users\Qwerty\Downloads\TEST1.rar
  290. 2017-07-09 15:29 - 2017-07-09 15:29 - 00000000 ____D C:\Users\Qwerty\AppData\Local\TechSmith
  291. 2017-07-09 15:28 - 2017-07-09 15:51 - 00000000 ____D C:\Users\Qwerty\Documents\Camtasia Studio
  292. 2017-07-09 15:22 - 2017-07-09 15:22 - 00001077 _____ C:\Users\Public\Desktop\Camtasia 9.lnk
  293. 2017-07-09 15:22 - 2017-07-09 15:22 - 00000000 ____D C:\ProgramData\TechSmith
  294. 2017-07-09 15:22 - 2017-07-09 15:22 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TechSmith
  295. 2017-07-09 15:22 - 2017-07-09 15:22 - 00000000 ____D C:\Program Files\TechSmith
  296. 2017-07-09 15:19 - 2017-07-09 15:19 - 00000000 ____D C:\Program Files (x86)\TechSmith Corporation
  297. 2017-07-09 15:14 - 2017-07-09 15:14 - 00176594 _____ C:\Users\Qwerty\Downloads\Camtasia_Studio_9.0.5_2021_Inclus_Serial_et_Patch.part1.nzb
  298. 2017-07-09 15:12 - 2017-07-09 15:12 - 285457368 _____ (TechSmith Corporation) C:\Users\Qwerty\Downloads\camtasia.exe
  299. 2017-07-09 15:00 - 2017-07-09 15:00 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\VEGAS Pro
  300. 2017-07-09 15:00 - 2017-07-09 15:00 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\VEGAS
  301. 2017-07-09 15:00 - 2017-07-09 15:00 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\Publish Providers
  302. 2017-07-09 15:00 - 2017-07-09 15:00 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\MAGIX
  303. 2017-07-09 15:00 - 2017-07-09 15:00 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\dclogs
  304. 2017-07-09 15:00 - 2017-07-09 15:00 - 00000000 ____D C:\Users\Qwerty\AppData\Local\VEGAS Pro
  305. 2017-07-09 15:00 - 2017-07-09 15:00 - 00000000 ____D C:\Users\Qwerty\AppData\Local\Sony
  306. 2017-07-09 15:00 - 2017-07-09 15:00 - 00000000 ____D C:\ProgramData\VEGAS Pro
  307. 2017-07-09 15:00 - 2017-07-09 15:00 - 00000000 ____D C:\ProgramData\Magix
  308. 2017-07-09 14:59 - 2017-07-09 15:00 - 00000000 ___HD C:\Users\Qwerty\AppData\Roaming\tws
  309. 2017-07-09 14:59 - 2017-07-09 14:59 - 00003574 _____ C:\Windows\System32\Tasks\yiyu
  310. 2017-07-09 14:59 - 2017-07-09 14:59 - 00000000 __SHD C:\Users\Qwerty\yiyu
  311. 2017-07-09 14:59 - 2017-04-21 14:53 - 00045176 ___SH (Microsoft Corporation) C:\Users\Qwerty\RegSvcs.exe
  312. 2017-07-09 14:58 - 2017-07-09 14:58 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VEGAS
  313. 2017-07-09 14:57 - 2017-07-09 14:57 - 00000000 ____D C:\Users\Qwerty\AppData\Local\VEGAS
  314. 2017-07-09 14:57 - 2017-07-09 14:57 - 00000000 ____D C:\ProgramData\VEGAS
  315. 2017-07-09 14:57 - 2017-07-09 14:57 - 00000000 ____D C:\Program Files\VEGAS
  316. 2017-07-09 14:57 - 2017-07-09 14:57 - 00000000 ____D C:\Program Files (x86)\VEGAS
  317. 2017-07-09 14:56 - 2017-07-09 14:56 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\Sony
  318. 2017-07-09 14:56 - 2017-07-09 14:56 - 00000000 ____D C:\Program Files (x86)\MAGIX Computer Products Intl. Co
  319. 2017-07-09 14:55 - 2017-07-09 14:55 - 00305388 _____ C:\Users\Qwerty\Downloads\MAGIX_Vegas_Pro_14.0.0_Build_252_-_64bit.nzb
  320. 2017-07-09 14:53 - 2017-07-09 14:53 - 00060835 _____ C:\Users\Qwerty\Downloads\MAGIX_Vegas_Pro_13.nzb
  321. 2017-07-09 14:49 - 2017-07-09 14:49 - 00638252 _____ C:\Users\Qwerty\Downloads\Pirates.of.the.Caribbean.Dead.Men.Tell.No.Tales.2017.Custom.DKsubs.720p.Blurr.HDCAM.x265-RELEASED.nzb
  322. 2017-07-09 14:35 - 2017-07-09 14:35 - 00002039 _____ C:\Users\Public\Desktop\Action!.lnk
  323. 2017-07-09 14:34 - 2017-07-09 14:34 - 22683849 _____ C:\Users\Qwerty\Downloads\Action Recorder.zip
  324. 2017-07-09 14:28 - 2017-07-09 14:28 - 00020160 _____ (Glarysoft Ltd) C:\Windows\system32\Drivers\GUBootStartup.sys
  325. 2017-07-09 14:28 - 2017-07-09 14:28 - 00003316 _____ C:\Windows\System32\Tasks\GlaryInitialize 5
  326. 2017-07-09 14:28 - 2017-07-09 14:28 - 00001096 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Glary Utilities 5.lnk
  327. 2017-07-09 14:28 - 2017-07-09 14:28 - 00001084 _____ C:\Users\Public\Desktop\Glary Utilities 5.lnk
  328. 2017-07-09 14:28 - 2017-07-09 14:28 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\GlarySoft
  329. 2017-07-09 14:28 - 2017-07-09 14:28 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\DiskDefrag
  330. 2017-07-09 14:28 - 2017-07-09 14:28 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Glary Utilities 5
  331. 2017-07-09 14:28 - 2017-07-09 14:28 - 00000000 ____D C:\Program Files (x86)\Glary Utilities 5
  332. 2017-07-09 14:27 - 2017-07-09 14:27 - 16893520 _____ C:\Users\Qwerty\Downloads\gu5setup.exe
  333. 2017-07-09 14:21 - 2017-07-09 14:25 - 00000000 ____D C:\Users\Qwerty\Documents\Bandicam
  334. 2017-07-09 14:21 - 2017-07-09 14:21 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\Bandicam Company
  335. 2017-07-09 14:20 - 2017-07-09 14:20 - 00000992 _____ C:\Users\Public\Desktop\Bandicam.lnk
  336. 2017-07-09 14:20 - 2017-07-09 14:20 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bandicam
  337. 2017-07-09 14:20 - 2017-07-09 14:20 - 00000000 ____D C:\Program Files (x86)\BandiMPEG1
  338. 2017-07-09 14:20 - 2017-07-09 14:20 - 00000000 ____D C:\Program Files (x86)\Bandicam
  339. 2017-07-09 14:18 - 2017-07-09 14:20 - 00000000 ____D C:\Users\Qwerty\Documents\bandicamcrack
  340. 2017-07-09 14:17 - 2017-07-09 14:18 - 17692519 _____ C:\Users\Qwerty\Downloads\Bandicam.3.4.2.1258.rar
  341. 2017-07-09 14:16 - 2017-07-09 14:17 - 17684928 _____ C:\Users\Qwerty\Downloads\Bandicam.3.4.2.1258.rar.crdownload
  342. 2017-07-09 14:05 - 2017-07-09 14:05 - 113245088 _____ (obsproject.com) C:\Users\Qwerty\Downloads\OBS-Studio-19.0.3-Full-Installer.exe
  343. 2017-07-09 14:05 - 2017-07-09 14:05 - 00001202 _____ C:\Users\Public\Desktop\OBS Studio.lnk
  344. 2017-07-09 14:05 - 2017-07-09 14:05 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OBS Studio
  345. 2017-07-09 14:05 - 2017-07-09 14:05 - 00000000 ____D C:\Program Files (x86)\obs-studio
  346. 2017-07-09 13:58 - 2017-07-09 14:35 - 00000000 ____D C:\Users\Qwerty\Documents\actionpre
  347. 2017-07-09 13:57 - 2017-07-09 13:57 - 23339110 _____ C:\Users\Qwerty\Downloads\M.A_2.5.5 Pable Pre-acted (1).zip
  348. 2017-07-09 13:53 - 2017-07-09 13:53 - 10855843 _____ C:\Users\Qwerty\Downloads\Mirillis Action Troubleshooter (Updated).zip
  349. 2017-07-09 13:53 - 2017-07-09 13:53 - 00001223 _____ C:\Users\Qwerty\Downloads\Mirillis_Action_Troubleshooter_(Updated).xht
  350. 2017-07-08 22:03 - 2017-07-08 22:03 - 00182747 _____ C:\Users\Qwerty\Downloads\3.2017.NEW.HDTS.XviD-VAiN.nzb
  351. 2017-07-08 21:49 - 2017-07-08 21:49 - 00327323 _____ C:\Users\Qwerty\Downloads\Despicable.Me.3.2017.NEW.HD-TS.x264-CPG (1).nzb
  352. 2017-07-08 16:51 - 2017-07-08 16:52 - 00000000 ____D C:\Users\Qwerty\AppData\Local\Vysor
  353. 2017-07-08 16:51 - 2017-07-08 16:51 - 49937408 _____ (ClockworkMod) C:\Users\Qwerty\Downloads\Vysor-win32-ia32 (1).exe
  354. 2017-07-08 16:43 - 2017-07-08 16:56 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\Vysor
  355. 2017-07-08 16:43 - 2017-07-08 16:52 - 00002156 _____ C:\Users\Qwerty\Desktop\Vysor.lnk
  356. 2017-07-08 16:43 - 2017-07-08 16:52 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ClockworkMod
  357. 2017-07-08 16:41 - 2017-07-08 16:41 - 49937408 _____ (ClockworkMod) C:\Users\Qwerty\Downloads\Vysor-win32-ia32.exe
  358. 2017-07-08 14:57 - 2017-07-08 14:57 - 01996288 _____ (J Sommer) C:\Users\Qwerty\Downloads\asciiquarium.scr
  359. 2017-07-08 13:41 - 2017-07-09 13:24 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\tixati
  360. 2017-07-08 13:41 - 2017-07-08 13:41 - 00000784 _____ C:\Users\Qwerty\Desktop\Tixati.lnk
  361. 2017-07-08 13:41 - 2017-07-08 13:41 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Tixati
  362. 2017-07-08 13:40 - 2017-07-08 13:41 - 00000000 ____D C:\Program Files\tixati
  363. 2017-07-08 13:40 - 2017-07-08 13:40 - 13851288 _____ C:\Users\Qwerty\Downloads\tixati-2.53-1.win64-install.exe
  364. 2017-07-08 13:29 - 2017-07-08 13:29 - 00241017 _____ C:\Users\Qwerty\Downloads\Collection+of+250+decrypted+3DS+ROMs+for+Citra+Emulator.torrent
  365. 2017-07-07 23:00 - 2017-07-07 23:00 - 20272152 _____ C:\Users\Qwerty\Downloads\ppsspp_win.zip
  366. 2017-07-07 23:00 - 2017-07-07 23:00 - 00000000 ____D C:\Users\Qwerty\Downloads\PPSSPP
  367. 2017-07-07 18:51 - 2017-07-07 18:51 - 00504752 _____ C:\Users\Qwerty\Downloads\Minions.2015.MULTI.1080p.BluRay.x264-Goatlove.nzb
  368. 2017-07-07 18:38 - 2017-07-07 18:38 - 15179461 _____ C:\Users\Qwerty\Downloads\mkvtoolnix-64bit-13.0.0.7z
  369. 2017-07-07 18:36 - 2017-07-07 18:36 - 00801365 _____ C:\Users\Qwerty\Downloads\MKVExtractGUI-1.6.4.1Wizard-1.2.zip
  370. 2017-07-07 18:36 - 2017-07-07 18:36 - 00000000 ____D C:\Users\Qwerty\Downloads\MKVtools
  371. 2017-07-07 16:29 - 2017-07-07 16:29 - 00023328 _____ C:\Users\Qwerty\Downloads\Jaba_Com_Web_Browser_1.9.98.zip.nzb
  372. 2017-07-07 16:11 - 2017-07-07 16:11 - 00000600 __RSH C:\Users\Qwerty\ntuser.pol
  373. 2017-07-07 07:25 - 2017-07-07 07:25 - 00000000 ___HD C:\$AV_ASW
  374. 2017-07-06 19:40 - 2017-07-06 19:41 - 00014916 _____ C:\Users\Qwerty\Downloads\Builder.rar
  375. 2017-07-06 19:03 - 2017-07-06 19:03 - 00268376 _____ C:\Users\Qwerty\Downloads\winmd5free.zip
  376. 2017-07-06 18:18 - 2017-07-06 18:18 - 23339110 _____ C:\Users\Qwerty\Downloads\M.A_2.5.5 Pable Pre-acted.zip
  377. 2017-07-06 18:18 - 2017-07-06 18:18 - 00000000 ____D C:\Users\Qwerty\Downloads\action
  378. 2017-07-06 18:14 - 2017-07-06 18:14 - 23644032 _____ (Mirillis Ltd.) C:\Users\Qwerty\Downloads\action_2_5_5_setup.exe
  379. 2017-07-06 18:13 - 2017-07-06 18:13 - 00008048 _____ C:\Users\Qwerty\Downloads\Mirillis_Action!_1301_Multilingual.rar- (1).nzb
  380. 2017-07-06 18:12 - 2017-07-06 18:12 - 00000000 ____D C:\Users\Qwerty\Documents\Action!
  381. 2017-07-06 18:12 - 2017-07-06 18:12 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\Mirillis
  382. 2017-07-06 18:12 - 2017-07-06 18:12 - 00000000 ____D C:\ProgramData\Mirillis
  383. 2017-07-06 18:11 - 2017-07-09 14:35 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mirillis
  384. 2017-07-06 18:11 - 2017-07-09 14:35 - 00000000 ____D C:\Program Files (x86)\Mirillis
  385. 2017-07-06 18:11 - 2017-07-06 18:20 - 00000000 ____D C:\Users\Qwerty\AppData\Local\Mirillis
  386. 2017-07-06 17:54 - 2017-07-06 17:54 - 00008048 _____ C:\Users\Qwerty\Downloads\Mirillis_Action!_1301_Multilingual.rar-.nzb
  387. 2017-07-06 17:11 - 2017-07-06 17:11 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\aipai
  388. 2017-07-06 17:10 - 2017-07-09 15:12 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\obs-studio
  389. 2017-07-06 17:10 - 2017-07-09 14:40 - 00000338 _____ C:\Users\Qwerty\AppData\Roaming\basic.ini
  390. 2017-07-06 17:09 - 2017-07-06 17:09 - 00001596 _____ C:\Users\Qwerty\Desktop\SmartPixel.lnk
  391. 2017-07-06 17:09 - 2017-07-06 17:09 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SmartPixel
  392. 2017-07-06 17:09 - 2017-07-06 17:09 - 00000000 ____D C:\SmartPixel
  393. 2017-07-06 17:09 - 2017-07-06 17:09 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SmartPixel
  394. 2017-07-06 17:07 - 2017-07-06 17:07 - 48365904 _____ (Beyond Magic Limited) C:\Users\Qwerty\Downloads\smartpixel_setup.exe
  395. 2017-07-05 21:45 - 2017-07-05 21:45 - 00329458 _____ C:\Users\Qwerty\Downloads\portlistener.zip
  396. 2017-07-05 21:42 - 2017-07-08 17:24 - 00000000 ____D C:\Program Files\SABnzbd
  397. 2017-07-05 21:42 - 2017-07-05 21:42 - 00000796 _____ C:\Users\Qwerty\Desktop\SABnzbd.lnk
  398. 2017-07-05 21:42 - 2017-07-05 21:42 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SABnzbd
  399. 2017-07-05 20:37 - 2017-07-05 20:37 - 00327323 _____ C:\Users\Qwerty\Downloads\Despicable.Me.3.2017.NEW.HD-TS.x264-CPG.nzb
  400. 2017-07-05 20:37 - 2017-07-05 20:37 - 00295331 _____ C:\Users\Qwerty\Downloads\Despicable.Me.3.2017.TS.x264.AC3-TiTAN.nzb
  401. 2017-07-05 20:35 - 2017-07-05 20:35 - 00028871 _____ C:\Users\Qwerty\Downloads\The_Simpsons_-_S06E02_-_Lisas_Rival.nzb
  402. 2017-07-05 20:35 - 2017-07-05 20:35 - 00028811 _____ C:\Users\Qwerty\Downloads\The_Simpsons_-_S06E03_-_Another_Simpsons_Clip_Show.nzb
  403. 2017-07-05 20:35 - 2017-07-05 20:35 - 00028773 _____ C:\Users\Qwerty\Downloads\The_Simpsons_-_S06E06_-_Treehouse_Of_Horror.nzb
  404. 2017-07-05 20:35 - 2017-07-05 20:35 - 00028772 _____ C:\Users\Qwerty\Downloads\The_Simpsons_-_S06E01_-_Bart_of_Darkness.nzb
  405. 2017-07-05 20:35 - 2017-07-05 20:35 - 00028752 _____ C:\Users\Qwerty\Downloads\The_Simpsons_-_S06E04_-_Itchy_And_Scratchyland.nzb
  406. 2017-07-05 20:35 - 2017-07-05 20:35 - 00028581 _____ C:\Users\Qwerty\Downloads\The_Simpsons_-_S06E05_-_Sideshow_Bob_Roberts.nzb
  407. 2017-07-05 20:00 - 2017-07-05 20:00 - 00978628 _____ C:\Users\Qwerty\Downloads\The_Simpsons_S05E02_Cape_Feare_720p_HDTV_UPSCALE_DD5.1_MPEG2-TrollHD.par2.nzb
  408. 2017-07-05 19:59 - 2017-07-05 19:59 - 00025310 _____ C:\Users\Qwerty\Downloads\The.Simpsons.S05E02.1080p.BluRay.x264-TAXES.rar.nzb
  409. 2017-07-05 19:57 - 2017-07-05 19:57 - 00026772 _____ C:\Users\Qwerty\Downloads\2017-07-05_08_57_51.nzb
  410. 2017-07-05 19:54 - 2017-07-05 19:54 - 00023586 _____ C:\Users\Qwerty\Downloads\The_Simpsons_-_S05E02_-_Cape_Feare (1).nzb
  411. 2017-07-05 19:50 - 2017-07-05 19:50 - 00061845 _____ C:\Users\Qwerty\Downloads\The.Simpsons.S05E19.DVDRip.XviD-MEDiEVAL.nzb
  412. 2017-07-05 19:50 - 2017-07-05 19:50 - 00061398 _____ C:\Users\Qwerty\Downloads\The.Simpsons.S05E05.INTERNAL.DVDRip.XviD-MEDiEVAL.nzb
  413. 2017-07-05 19:50 - 2017-07-05 19:50 - 00060544 _____ C:\Users\Qwerty\Downloads\The.Simpsons.S05E02.DVDRip.XviD-MEDiEVAL.nzb
  414. 2017-07-05 19:46 - 2017-07-05 19:46 - 00024067 _____ C:\Users\Qwerty\Downloads\The_Simpsons_-_S05E01_-_Homer's_Barbershop_Quartet.nzb
  415. 2017-07-05 19:46 - 2017-07-05 19:46 - 00023957 _____ C:\Users\Qwerty\Downloads\The_Simpsons_-_S05E19_-_Sweet_Seymour_Skinner's_Baadasssss_Song (1).nzb
  416. 2017-07-05 19:46 - 2017-07-05 19:46 - 00023586 _____ C:\Users\Qwerty\Downloads\The_Simpsons_-_S05E02_-_Cape_Feare.nzb
  417. 2017-07-05 19:45 - 2017-07-05 19:45 - 00024557 _____ C:\Users\Qwerty\Downloads\The_Simpsons_-_S05E10_-_pringfield_(Or,_How_I_Learned_to_Stop_Worrying_and_Love_Legalized_Gambling).nzb
  418. 2017-07-05 19:45 - 2017-07-05 19:45 - 00024122 _____ C:\Users\Qwerty\Downloads\The_Simpsons_-_S05E09_-_The_Last_Temptation_of_Homer.nzb
  419. 2017-07-05 19:45 - 2017-07-05 19:45 - 00024045 _____ C:\Users\Qwerty\Downloads\The_Simpsons_-_S05E17_-_Bart_Gets_an_Elephant.nzb
  420. 2017-07-05 19:45 - 2017-07-05 19:45 - 00024030 _____ C:\Users\Qwerty\Downloads\The_Simpsons_-_S05E16_-_Homer_Loves_Flanders.nzb
  421. 2017-07-05 19:45 - 2017-07-05 19:45 - 00023984 _____ C:\Users\Qwerty\Downloads\The_Simpsons_-_S05E06_-_Marge_on_the_Lam.nzb
  422. 2017-07-05 19:45 - 2017-07-05 19:45 - 00023979 _____ C:\Users\Qwerty\Downloads\The_Simpsons_-_S05E08_-_Boy-Scoutz_N_the_Hood.nzb
  423. 2017-07-05 19:45 - 2017-07-05 19:45 - 00023967 _____ C:\Users\Qwerty\Downloads\The_Simpsons_-_S05E13_-_Homer_and_Apu.nzb
  424. 2017-07-05 19:45 - 2017-07-05 19:45 - 00023957 _____ C:\Users\Qwerty\Downloads\The_Simpsons_-_S05E19_-_Sweet_Seymour_Skinner's_Baadasssss_Song.nzb
  425. 2017-07-05 19:45 - 2017-07-05 19:45 - 00023950 _____ C:\Users\Qwerty\Downloads\The_Simpsons_-_S05E14_-_Lisa_vs._Malibu_Stacy.nzb
  426. 2017-07-05 19:45 - 2017-07-05 19:45 - 00023947 _____ C:\Users\Qwerty\Downloads\The_Simpsons_-_S05E18_-_Burns'_Heir.nzb
  427. 2017-07-05 19:45 - 2017-07-05 19:45 - 00023946 _____ C:\Users\Qwerty\Downloads\The_Simpsons_-_S05E03_-_Homer_Goes_to_College.nzb
  428. 2017-07-05 19:45 - 2017-07-05 19:45 - 00023941 _____ C:\Users\Qwerty\Downloads\The_Simpsons_-_S05E11_-_Homer_the_Vigilante.nzb
  429. 2017-07-05 19:45 - 2017-07-05 19:45 - 00023906 _____ C:\Users\Qwerty\Downloads\The_Simpsons_-_S05E15_-_Deep_Space_Homer.nzb
  430. 2017-07-05 19:45 - 2017-07-05 19:45 - 00023900 _____ C:\Users\Qwerty\Downloads\The_Simpsons_-_S05E12_-_Bart_Gets_Famous.nzb
  431. 2017-07-05 19:45 - 2017-07-05 19:45 - 00023900 _____ C:\Users\Qwerty\Downloads\The_Simpsons_-_S05E07_-_Bart's_Inner_Child.nzb
  432. 2017-07-05 19:45 - 2017-07-05 19:45 - 00023806 _____ C:\Users\Qwerty\Downloads\The_Simpsons_-_S05E04_-_Rosebud.nzb
  433. 2017-07-05 19:45 - 2017-07-05 19:45 - 00023723 _____ C:\Users\Qwerty\Downloads\The_Simpsons_-_S05E05_-_Treehouse_of_Horror_IV.nzb
  434. 2017-07-05 19:44 - 2017-07-05 19:44 - 00024085 _____ C:\Users\Qwerty\Downloads\The_Simpsons_-S05E22_-_Secrets_of_a_Successful_Marriage (1).nzb
  435. 2017-07-05 19:44 - 2017-07-05 19:44 - 00024076 _____ C:\Users\Qwerty\Downloads\The_Simpsons_-_S05E20_-_The_Boy_Who_Knew_Too_Much.nzb
  436. 2017-07-05 19:44 - 2017-07-05 19:44 - 00024005 _____ C:\Users\Qwerty\Downloads\The_Simpsons_-_S05E21_-_Lady_Bouvier's_Lover.nzb
  437. 2017-07-05 19:07 - 2017-07-05 19:07 - 00016896 _____ C:\Users\Qwerty\Downloads\client.exe
  438. 2017-07-05 18:00 - 2017-07-05 18:00 - 01024131 _____ C:\Users\Qwerty\Downloads\The.Simpsons.S05E06.Marge.On.The.Lam.720p.HDTV.UPSCALE.DD5.1.MPEG2-TrollHD.nzb
  439. 2017-07-05 18:00 - 2017-07-05 18:00 - 00997461 _____ C:\Users\Qwerty\Downloads\The.Simpsons.S05E05.Treehouse.Of.Horror.IV.720p.HDTV.UPSCALE.DD5.1.MPEG2-TrollHD.nzb
  440. 2017-07-05 18:00 - 2017-07-05 18:00 - 00989455 _____ C:\Users\Qwerty\Downloads\The.Simpsons.S05E07.Bart's.Inner.Child.720p.HDTV.UPSCALE.DD5.1.MPEG2-TrollHD.nzb
  441. 2017-07-05 17:57 - 2017-07-05 17:57 - 00999804 _____ C:\Users\Qwerty\Downloads\The.Simpsons.S05E08.Boy-Scoutz.'N.The.Hood.720p.HDTV.UPSCALE.DD5.1.MPEG2-TrollHD.nzb
  442. 2017-07-05 17:56 - 2017-07-05 17:56 - 01011770 _____ C:\Users\Qwerty\Downloads\The.Simpsons.S05E09.The.Last.Temptation.Of.Homer.720p.HDTV.UPSCALE.DD5.1.MPEG2-TrollHD.nzb
  443. 2017-07-05 17:56 - 2017-07-05 17:56 - 01010999 _____ C:\Users\Qwerty\Downloads\The.Simpsons.S05E20.The.Boy.Who.Knew.Too.Much.720p.HDTV.UPSCALE.DD5.1.MPEG2-TrollHD.nzb
  444. 2017-07-05 17:56 - 2017-07-05 17:56 - 01007862 _____ C:\Users\Qwerty\Downloads\The.Simpsons.S05E18.Burns'.Heir.720p.HDTV.UPSCALE.DD5.1.MPEG2-TrollHD.nzb
  445. 2017-07-05 17:56 - 2017-07-05 17:56 - 01007079 _____ C:\Users\Qwerty\Downloads\The.Simpsons.S05E13.Homer.And.Apu.720p.HDTV.UPSCALE.DD5.1.MPEG2-TrollHD.nzb
  446. 2017-07-05 17:56 - 2017-07-05 17:56 - 01005734 _____ C:\Users\Qwerty\Downloads\The.Simpsons.S05E16.Homer.Loves.Flanders.720p.HDTV.UPSCALE.DD5.1.MPEG2-TrollHD.nzb
  447. 2017-07-05 17:56 - 2017-07-05 17:56 - 01003504 _____ C:\Users\Qwerty\Downloads\The.Simpsons.S05E12.Bart.Gets.Famous.720p.HDTV.UPSCALE.DD5.1.MPEG2-TrollHD.nzb
  448. 2017-07-05 17:56 - 2017-07-05 17:56 - 00999307 _____ C:\Users\Qwerty\Downloads\The.Simpsons.S05E14.Lisa.Vs..Malibu.Stacy.720p.HDTV.UPSCALE.DD5.1.MPEG2-TrollHD.nzb
  449. 2017-07-05 17:56 - 2017-07-05 17:56 - 00996185 _____ C:\Users\Qwerty\Downloads\The.Simpsons.S05E15.Deep.Space.Homer.720p.HDTV.UPSCALE.DD5.1.MPEG2-TrollHD.nzb
  450. 2017-07-05 17:56 - 2017-07-05 17:56 - 00993179 _____ C:\Users\Qwerty\Downloads\The.Simpsons.S05E11.Homer.The.Vigilante.720p.HDTV.UPSCALE.DD5.1.MPEG2-TrollHD.nzb
  451. 2017-07-05 17:56 - 2017-07-05 17:56 - 00988297 _____ C:\Users\Qwerty\Downloads\The.Simpsons.S05E17.Bart.Gets.An.Elephant.720p.HDTV.UPSCALE.DD5.1.MPEG2-TrollHD.nzb
  452. 2017-07-05 17:54 - 2017-07-09 15:14 - 00000000 ____D C:\Users\Qwerty\Downloads\complete
  453. 2017-07-05 17:54 - 2017-07-05 17:54 - 00024085 _____ C:\Users\Qwerty\Downloads\The_Simpsons_-S05E22_-_Secrets_of_a_Successful_Marriage.nzb
  454. 2017-07-05 17:52 - 2017-07-05 17:52 - 01014267 _____ C:\Users\Qwerty\Downloads\The.Simpsons.S05E22.Secrets.Of.A.Successful.Marriage.720p.HDTV.UPSCALE.DD5.1.MPEG2-TrollHD.nzb
  455. 2017-07-05 17:52 - 2017-07-05 17:52 - 01005087 _____ C:\Users\Qwerty\Downloads\The.Simpsons.S05E21.Lady.Bouvier's.Lover.720p.HDTV.UPSCALE.DD5.1.MPEG2-TrollHD.nzb
  456. 2017-07-04 22:06 - 2017-07-09 15:14 - 00000000 ____D C:\Users\Qwerty\Downloads\incomplete
  457. 2017-07-04 22:06 - 2017-07-04 22:06 - 00000000 ____D C:\Users\Qwerty\AppData\Local\sabnzbd
  458. 2017-07-04 22:05 - 2017-07-04 22:05 - 20207148 _____ C:\Users\Qwerty\Downloads\SABnzbd-2.1.0-win-setup.exe
  459. 2017-07-04 22:03 - 2017-07-04 22:03 - 00312132 _____ C:\Users\Qwerty\Downloads\Despicable.Me.3.Screener.AC3-DRC.nzb
  460. 2017-07-04 22:03 - 2017-07-04 22:03 - 00132254 _____ C:\Users\Qwerty\Downloads\Despicable.Me.2.2013.720p.BluRay.H264.AAC-RARBG.nzb
  461. 2017-07-04 21:33 - 2017-07-04 21:33 - 00501363 _____ (Peter B Clements) C:\Users\Qwerty\Downloads\QuickPar-0.9.1.0.exe
  462. 2017-07-04 21:33 - 2017-07-04 21:33 - 00001011 _____ C:\Users\Qwerty\Desktop\QuickPar.lnk
  463. 2017-07-04 21:33 - 2017-07-04 21:33 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\QuickPar
  464. 2017-07-04 21:33 - 2017-07-04 21:33 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickPar
  465. 2017-07-04 21:33 - 2017-07-04 21:33 - 00000000 ____D C:\Program Files (x86)\QuickPar
  466. 2017-07-04 21:32 - 2017-07-04 22:03 - 00000000 ____D C:\Users\Qwerty\Documents\Newsbin Download
  467. 2017-07-04 21:30 - 2017-07-04 22:06 - 00000000 ____D C:\Users\Qwerty\AppData\Local\NewsBin
  468. 2017-07-04 21:30 - 2017-07-04 22:01 - 00000000 ____D C:\Program Files\NewsBin
  469. 2017-07-04 21:30 - 2017-07-04 21:30 - 00000883 _____ C:\Users\Qwerty\Desktop\NewsBin Pro 64.lnk
  470. 2017-07-04 21:30 - 2017-07-04 21:30 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NewsBin5-64
  471. 2017-07-04 21:29 - 2017-07-04 21:29 - 04183984 _____ C:\Users\Qwerty\Downloads\nb554-64.exe
  472. 2017-07-04 21:24 - 2017-07-04 21:24 - 00003655 _____ C:\Users\Qwerty\Downloads\NewsBin.Professional.5.51.(Build.9378).cracked-SND.nzb
  473. 2017-07-04 20:53 - 2017-07-04 20:53 - 16564488 _____ C:\Users\Qwerty\Downloads\nb672-full.exe
  474. 2017-07-04 20:30 - 2017-07-04 20:30 - 00096955 _____ C:\Users\Qwerty\Downloads\The.Simpsons.S04E22.Krusty.Gets.Kancelled.720p.HDTV.DD5.1.x264-CtrlHD.nzb
  475. 2017-07-04 20:10 - 2017-07-04 20:10 - 00088697 _____ C:\Users\Qwerty\Downloads\gsmax0.5.zip
  476. 2017-07-04 20:01 - 2017-07-04 20:01 - 00557996 _____ C:\Users\Qwerty\Downloads\ZeroGS_KOSMOS_0.97.1_sse2.zip
  477. 2017-07-04 19:34 - 2017-07-04 19:34 - 206156956 _____ C:\Users\Qwerty\Downloads\PS3UPDAT.PUP
  478. 2017-07-04 19:12 - 2017-07-04 19:12 - 00000000 ____D C:\Users\Qwerty\Downloads\B795TSG.part1
  479. 2017-07-04 19:00 - 2017-07-04 19:00 - 24391974 _____ C:\Users\Qwerty\Downloads\B795TSG.part6.rar
  480. 2017-07-04 18:59 - 2017-07-04 19:10 - 2147483648 _____ C:\Users\Qwerty\Downloads\B795TSG.part4.rar
  481. 2017-07-04 18:59 - 2017-07-04 19:10 - 2147483648 _____ C:\Users\Qwerty\Downloads\B795TSG.part3.rar
  482. 2017-07-04 18:59 - 2017-07-04 19:09 - 2147483648 _____ C:\Users\Qwerty\Downloads\B795TSG.part5.rar
  483. 2017-07-04 18:58 - 2017-07-04 19:08 - 2147483648 _____ C:\Users\Qwerty\Downloads\B795TSG.part2.rar
  484. 2017-07-04 18:55 - 2017-07-04 18:59 - 2147483648 _____ C:\Users\Qwerty\Downloads\B795TSG.part1.rar
  485. 2017-07-04 18:52 - 2017-07-04 19:34 - 00000000 ____D C:\Users\Qwerty\Downloads\rpcs3
  486. 2017-07-04 18:51 - 2017-07-04 18:51 - 18959015 _____ C:\Users\Qwerty\Downloads\rpcs3-v0.0.2-2017-07-03-ba75f383_win64.zip
  487. 2017-07-04 16:03 - 2017-07-04 16:44 - 1199802187 _____ C:\Users\Qwerty\Downloads\[fmovies.to] Despicable Me 3 (Russian Audio) - TS.mp4
  488. 2017-07-03 21:49 - 2017-07-09 13:51 - 00000000 ____D C:\Users\Qwerty\Downloads\GrabIt Downloads
  489. 2017-07-03 21:48 - 2017-07-03 21:48 - 00094802 _____ C:\Users\Qwerty\Downloads\The.Simpsons.S04E21.Marge.in.Chains.720p.HDTV.DD5.1.x264-CtrlHD.nzb
  490. 2017-07-03 21:47 - 2017-07-04 20:44 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\GrabIt
  491. 2017-07-03 21:46 - 2017-07-03 21:46 - 00000983 _____ C:\Users\Qwerty\Desktop\GrabIt.lnk
  492. 2017-07-03 21:46 - 2017-07-03 21:46 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GrabIt
  493. 2017-07-03 21:46 - 2017-07-03 21:46 - 00000000 ____D C:\Program Files (x86)\GrabIt
  494. 2017-07-03 21:45 - 2017-07-03 21:45 - 02547810 _____ (Ilan Shemes ) C:\Users\Qwerty\Downloads\GrabIt174b2.exe
  495. 2017-07-03 15:53 - 2017-07-03 15:53 - 07075640 _____ (Tim Kosse) C:\Users\Qwerty\Downloads\FileZilla_3.26.2_win64-setup.exe
  496. 2017-07-03 15:53 - 2017-07-03 15:53 - 07070840 _____ (Tim Kosse) C:\Users\Qwerty\Downloads\FileZilla_3.26.1_win64-setup.exe
  497. 2017-07-02 22:21 - 2017-07-09 16:31 - 00000000 ____D C:\ProgramData\TVMOBiLi
  498. 2017-07-02 22:21 - 2017-07-02 22:21 - 00001196 _____ C:\Users\Public\Desktop\TVMOBiLi.lnk
  499. 2017-07-02 22:21 - 2017-07-02 22:21 - 00000000 ____D C:\Program Files (x86)\TVMOBiLi
  500. 2017-07-02 22:20 - 2017-07-02 22:20 - 10590197 _____ C:\Users\Qwerty\Downloads\tvmobili-windows-i386.exe
  501. 2017-07-02 21:44 - 2017-07-02 21:44 - 00000835 _____ C:\Users\Qwerty\Downloads\Ftp zoxie@cube64.net.xml
  502. 2017-07-02 16:40 - 2017-07-02 16:40 - 00001724 _____ C:\Users\Public\Desktop\Defraggler.lnk
  503. 2017-07-02 16:40 - 2017-07-02 16:40 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Defraggler
  504. 2017-07-02 16:40 - 2017-07-02 16:40 - 00000000 ____D C:\Program Files\Defraggler
  505. 2017-07-02 16:39 - 2017-07-02 16:39 - 04619752 _____ (Piriform Ltd) C:\Users\Qwerty\Downloads\dfsetup221.exe
  506. 2017-07-02 12:07 - 2017-07-02 12:06 - 00400464 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
  507. 2017-07-01 21:36 - 2016-04-14 17:17 - 00066752 _____ (VMware, Inc.) C:\Windows\system32\Drivers\vmx86.sys
  508. 2017-07-01 21:35 - 2016-04-14 17:17 - 00392896 _____ (VMware, Inc.) C:\Windows\SysWOW64\vmnat.exe
  509. 2017-07-01 21:35 - 2016-04-14 17:17 - 00358080 _____ (VMware, Inc.) C:\Windows\SysWOW64\vmnetdhcp.exe
  510. 2017-07-01 21:34 - 2016-04-14 17:17 - 00934080 _____ (VMware, Inc.) C:\Windows\system32\vnetlib64.dll
  511. 2017-07-01 21:34 - 2016-04-14 16:53 - 00026816 _____ (VMware, Inc.) C:\Windows\system32\Drivers\vmnetuserif.sys
  512. 2017-07-01 21:33 - 2016-03-10 08:03 - 00057536 _____ (VMware, Inc.) C:\Windows\system32\Drivers\hcmon.sys
  513. 2017-07-01 21:32 - 2017-07-01 21:32 - 00001203 _____ C:\Users\Public\Desktop\VMware Workstation Pro.lnk
  514. 2017-07-01 21:32 - 2017-07-01 21:32 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VMware
  515. 2017-07-01 21:32 - 2017-07-01 21:32 - 00000000 ____D C:\Program Files\Common Files\VMware
  516. 2017-07-01 21:26 - 2017-07-01 21:27 - 299983712 _____ C:\Users\Qwerty\Downloads\VMware Workstation Pro 12.1.1 Build 3770994 + Keys [SadeemPC].zip
  517. 2017-07-01 21:24 - 2017-07-01 21:24 - 00259868 _____ C:\Users\Qwerty\Downloads\Dream+Protector+Advanced.zip
  518. 2017-06-30 10:17 - 2017-06-30 10:17 - 00001068 _____ C:\Users\Public\Desktop\Hotspot Shield.lnk
  519. 2017-06-30 10:17 - 2017-06-30 10:17 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Hotspot Shield
  520. 2017-06-29 21:41 - 2017-06-29 21:41 - 00000000 ____D C:\Windows\SysWOW64\Hotspot Shield
  521. 2017-06-29 20:51 - 2017-06-29 20:51 - 00000000 ____D C:\Program Files\Application Verifier
  522. 2017-06-29 20:51 - 2017-06-29 20:51 - 00000000 ____D C:\Program Files (x86)\Application Verifier
  523. 2017-06-29 20:50 - 2017-06-29 20:51 - 00000000 ____D C:\ProgramData\Windows App Certification Kit
  524. 2017-06-29 20:50 - 2017-06-29 20:51 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Kits
  525. 2017-06-29 20:44 - 2017-06-29 20:44 - 00000000 ____D C:\Program Files (x86)\HTML Help Workshop
  526. 2017-06-29 20:42 - 2017-06-29 20:42 - 00001422 _____ C:\Users\Qwerty\Documents\petyavaccine.bat
  527. 2017-06-29 20:42 - 2017-06-29 20:42 - 00000126 ____R C:\Windows\perfc.dll
  528. 2017-06-29 20:42 - 2017-06-29 20:42 - 00000126 ____R C:\Windows\perfc.dat
  529. 2017-06-29 20:42 - 2017-06-29 20:42 - 00000126 ____R C:\Windows\perfc
  530. 2017-06-29 20:35 - 2017-06-29 20:35 - 00087836 _____ C:\Users\Qwerty\Downloads\Lilith-master.zip
  531. 2017-06-29 20:35 - 2017-06-29 20:35 - 00000000 ____D C:\Users\Qwerty\Downloads\lilith
  532. 2017-06-29 19:37 - 2017-06-29 19:37 - 00000016 _____ C:\Users\Qwerty\Documents\conrete5.txt
  533. 2017-06-29 19:37 - 2017-06-29 19:37 - 00000000 ____D C:\Users\Qwerty\Documents\New folder
  534. 2017-06-29 19:04 - 2017-06-29 19:04 - 00000000 ____D C:\Users\Qwerty\Downloads\YWW_ziperto.com.part1
  535. 2017-06-29 18:59 - 2017-06-29 19:02 - 501009349 _____ C:\Users\Qwerty\Downloads\YWW_ziperto.com.part6.rar
  536. 2017-06-29 18:58 - 2017-06-29 19:03 - 1048576000 _____ C:\Users\Qwerty\Downloads\YWW_ziperto.com.part5.rar
  537. 2017-06-29 18:58 - 2017-06-29 19:02 - 1048576000 _____ C:\Users\Qwerty\Downloads\YWW_ziperto.com.part4.rar
  538. 2017-06-29 18:58 - 2017-06-29 19:02 - 1048576000 _____ C:\Users\Qwerty\Downloads\YWW_ziperto.com.part3.rar
  539. 2017-06-29 18:57 - 2017-06-29 19:01 - 1048576000 _____ C:\Users\Qwerty\Downloads\YWW_ziperto.com.part2.rar
  540. 2017-06-29 18:57 - 2017-06-29 18:59 - 1048576000 _____ C:\Users\Qwerty\Downloads\YWW_ziperto.com.part1.rar
  541. 2017-06-28 20:31 - 2017-06-28 21:32 - 00000000 ____D C:\Users\Qwerty\AppData\Local\LoiLo
  542. 2017-06-28 20:31 - 2017-06-28 20:31 - 00001195 _____ C:\Users\Public\Desktop\Easy Video Editor LoiLo.lnk
  543. 2017-06-28 20:31 - 2017-06-28 20:31 - 00001026 _____ C:\Users\Public\Desktop\LoiLo Game Recorder.lnk
  544. 2017-06-28 20:31 - 2017-06-28 20:31 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LoiLoScope 2
  545. 2017-06-28 20:31 - 2017-06-28 20:31 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LoiLo Game Recorder
  546. 2017-06-28 20:31 - 2017-06-28 20:31 - 00000000 ____D C:\Program Files\LoiLo
  547. 2017-06-28 20:30 - 2017-06-28 20:30 - 00000000 ____D C:\Program Files (x86)\LoiLo
  548. 2017-06-28 20:29 - 2017-06-28 20:29 - 74713080 _____ (LoiLo inc. ) C:\Users\Qwerty\Downloads\LoiLoGameRecorder1.1.0.1.exe
  549. 2017-06-28 19:26 - 2017-06-28 19:26 - 00000000 ____D C:\Users\Qwerty\Downloads\mk8
  550. 2017-06-28 18:55 - 2017-06-28 18:55 - 00015863 _____ C:\Users\Qwerty\Downloads\Mario.Kart.8.WiiU.torrent
  551. 2017-06-28 18:43 - 2017-06-28 20:20 - 00000000 ____D C:\Users\Qwerty\Downloads\cemu
  552. 2017-06-28 18:35 - 2017-06-28 18:35 - 02311611 _____ C:\Users\Qwerty\Downloads\cemu_1.8.0.zip
  553. 2017-06-28 17:48 - 2017-06-28 17:48 - 00336123 _____ C:\Users\Qwerty\Downloads\FPS_Limiter_0.2.zip
  554. 2017-06-28 17:48 - 2017-06-28 17:48 - 00000000 ____D C:\Users\Qwerty\Downloads\fpslimiter
  555. 2017-06-27 22:08 - 2017-06-27 22:08 - 00008135 _____ C:\Users\Qwerty\Downloads\AppOnFly for Windows users.rdp
  556. 2017-06-27 16:42 - 2017-06-27 16:42 - 123669848 _____ (Oracle Corporation) C:\Users\Qwerty\Downloads\VirtualBox-5.1.22-115126-Win.exe
  557. 2017-06-27 16:35 - 2017-06-27 16:36 - 262784320 _____ C:\Users\Qwerty\Downloads\wnjviz.MOV
  558. 2017-06-26 21:47 - 2017-06-30 10:17 - 00000000 ____D C:\Program Files (x86)\Hotspot Shield
  559. 2017-06-26 21:46 - 2017-06-30 10:17 - 00000000 ____D C:\ProgramData\Hotspot Shield
  560. 2017-06-26 21:45 - 2017-06-26 21:45 - 00000000 ____D C:\Users\Qwerty\Downloads\Hotspot Shield VPN Elite 6.20.30 + Patch [CracksNow]
  561. 2017-06-26 21:36 - 2017-06-26 21:44 - 00000000 ____D C:\Users\Qwerty\Downloads\Windows 7 SP1 Ultimate (64 Bit)
  562. 2017-06-26 18:08 - 2017-07-02 12:39 - 00000000 ____D C:\Users\Qwerty\Downloads\d3d
  563. 2017-06-26 18:08 - 2017-06-26 18:08 - 00217335 _____ C:\Users\Qwerty\Downloads\D3DOverrider.7z
  564. 2017-06-26 18:02 - 2017-06-26 18:02 - 00636326 _____ C:\Users\Qwerty\Downloads\Release (1).zip
  565. 2017-06-26 17:52 - 2017-06-26 17:52 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\Cxbx-Reloaded
  566. 2017-06-26 17:51 - 2017-06-26 17:51 - 00639036 _____ C:\Users\Qwerty\Downloads\Release.zip
  567. 2017-06-26 17:22 - 2017-06-26 17:22 - 00131456 _____ C:\Users\Qwerty\Downloads\Cxbx-0.7.9-Pre4-Trace.zip
  568. 2017-06-26 17:12 - 2017-06-26 17:15 - 1616649475 _____ C:\Users\Qwerty\Downloads\Simpsons - Hit and Run [!].7z
  569. 2017-06-26 17:09 - 2017-06-26 18:03 - 00000000 ____D C:\Users\Qwerty\Documents\xbox
  570. 2017-06-26 17:09 - 2017-06-26 17:09 - 01003490 _____ C:\Users\Qwerty\Downloads\Xeon_10.rar
  571. 2017-06-26 16:49 - 2017-06-26 16:49 - 98136542 _____ C:\Users\Qwerty\Downloads\Mario Kart 7 (USA) [Decrypted].7z.002
  572. 2017-06-26 16:48 - 2017-06-26 16:49 - 524288000 _____ C:\Users\Qwerty\Downloads\Mario Kart 7 (USA) [Decrypted].7z.001
  573. 2017-06-26 16:34 - 2017-06-26 16:34 - 01982110 _____ C:\Users\Qwerty\Downloads\user.zip
  574. 2017-06-26 16:31 - 2017-06-26 16:31 - 03145728 _____ C:\Users\Qwerty\Downloads\shared_font.bin
  575. 2017-06-26 16:26 - 2017-07-08 16:52 - 00000000 ____D C:\Users\Qwerty\AppData\Local\SquirrelTemp
  576. 2017-06-26 16:26 - 2017-07-08 13:22 - 00002230 _____ C:\Users\Qwerty\Desktop\Citra Edge.lnk
  577. 2017-06-26 16:26 - 2017-07-08 13:22 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Citra Development Team
  578. 2017-06-26 16:26 - 2017-07-08 13:22 - 00000000 ____D C:\Users\Qwerty\AppData\Local\citra
  579. 2017-06-26 16:25 - 2017-06-26 16:25 - 27684352 _____ (Citra Development Team) C:\Users\Qwerty\Downloads\CitraSetup.exe
  580. 2017-06-26 16:12 - 2017-06-26 16:14 - 475057728 _____ C:\Users\Qwerty\Downloads\acnl usa MYGYMPARTNER.rar
  581. 2017-06-25 13:06 - 2017-06-25 13:06 - 00002794 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC
  582. 2017-06-25 13:06 - 2017-06-25 13:06 - 00000822 _____ C:\Users\Public\Desktop\CCleaner.lnk
  583. 2017-06-25 13:06 - 2017-06-25 13:06 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
  584. 2017-06-25 13:06 - 2017-06-25 13:06 - 00000000 ____D C:\Program Files\CCleaner
  585. 2017-06-25 13:05 - 2017-06-25 13:05 - 09598376 _____ (Piriform Ltd) C:\Users\Qwerty\Downloads\ccsetup531.exe
  586. 2017-06-24 18:34 - 2017-06-24 18:34 - 00000000 ____D C:\Users\Qwerty\Documents\Dolphin Emulator
  587. 2017-06-24 18:32 - 2017-06-24 18:32 - 13042028 _____ C:\Users\Qwerty\Downloads\dolphin-master-5.0-4482-x64.7z
  588. 2017-06-24 18:32 - 2017-06-24 18:32 - 00000000 ____D C:\Users\Qwerty\Downloads\Dolphin
  589. 2017-06-24 17:41 - 2017-06-24 17:42 - 1165150683 _____ C:\Users\Qwerty\Downloads\Simpsons, The - Hit & Run (USA) (1).7z
  590. 2017-06-24 15:50 - 2017-06-24 15:50 - 00005592 _____ C:\Users\Qwerty\Downloads\rdp-mixed.txt
  591. 2017-06-23 21:15 - 2017-06-23 21:15 - 00001539 _____ C:\Users\Qwerty\Desktop\WALTR2-PRO.lnk
  592. 2017-06-23 21:15 - 2017-06-23 21:15 - 00000393 _____ C:\Users\Qwerty\Desktop\RunAsDate.cfg
  593. 2017-06-23 21:15 - 2016-10-10 13:14 - 00032976 _____ C:\Users\Qwerty\Desktop\RunAsDate.exe
  594. 2017-06-23 21:10 - 2017-06-23 21:10 - 00035563 _____ C:\Users\Qwerty\Downloads\runasdate.zip
  595. 2017-06-23 21:06 - 2017-06-23 21:06 - 00000784 _____ C:\Users\Public\Desktop\WALTR2.lnk
  596. 2017-06-23 21:06 - 2017-06-23 21:06 - 00000000 ____D C:\ProgramData\Softorino
  597. 2017-06-23 21:06 - 2017-06-23 21:06 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WALTR2
  598. 2017-06-23 21:06 - 2017-06-23 21:06 - 00000000 ____D C:\Program Files\WALTR2
  599. 2017-06-23 21:05 - 2017-06-23 21:05 - 52983632 _____ (Softorino, Inc. ) C:\Users\Qwerty\Downloads\waltr2windows_2.0.21.exe
  600. 2017-06-23 20:42 - 2017-06-23 20:47 - 1422712832 _____ C:\Users\Qwerty\Downloads\Scooby-Doo.Pirates.Ahoy.2006.WEB-DLRip.1.36.Rus.Eng.Deadmauvlad.avi
  601. 2017-06-23 20:36 - 2017-06-23 20:38 - 782882816 _____ C:\Users\Qwerty\Downloads\Scooby-Doo.Pirates.Ahoy.2006.WEB-DLRip.Deadmauvlad.avi
  602. 2017-06-23 12:03 - 2017-06-23 12:03 - 01725199 _____ (Inekman) C:\Users\Qwerty\AppData\Roaming\Nvidia.exe
  603. 2017-06-21 21:42 - 2017-06-21 21:42 - 00000000 ____D C:\Users\Qwerty\Downloads\Pokemon - Yellow Version (UE) [C][!]
  604. 2017-06-21 21:42 - 2017-06-21 21:42 - 00000000 ____D C:\Users\Qwerty\Downloads\Pokemon - Crystal Version (UE) (V1.1) [C][!]
  605. 2017-06-21 21:40 - 2017-06-21 21:40 - 01030559 _____ C:\Users\Qwerty\Downloads\Pokemon - Crystal Version (UE) (V1.1) [C][!].zip
  606. 2017-06-21 21:39 - 2017-06-21 21:39 - 00512177 _____ C:\Users\Qwerty\Downloads\Pokemon - Yellow Version (UE) [C][!].zip
  607. 2017-06-21 21:33 - 2017-06-26 16:26 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\Citra
  608. 2017-06-21 21:32 - 2017-06-21 21:33 - 00000000 ____D C:\Users\Qwerty\Downloads\sonic
  609. 2017-06-21 21:31 - 2017-06-21 21:32 - 578185330 _____ C:\Users\Qwerty\Downloads\SGEN-USA-DecrTD-Ziperto.rar
  610. 2017-06-21 21:23 - 2017-06-21 21:24 - 134941192 _____ C:\Users\Qwerty\Downloads\RetroArch.7z
  611. 2017-06-21 21:22 - 2017-06-26 16:23 - 00000000 ____D C:\Users\Qwerty\Documents\retroarch
  612. 2017-06-21 21:22 - 2017-06-21 21:22 - 09195939 _____ C:\Users\Qwerty\Downloads\2017-06-21_RetroArch.7z
  613. 2017-06-21 19:44 - 2017-07-09 00:16 - 00000000 ____D C:\ProgramData\VMware
  614. 2017-06-21 19:44 - 2017-06-21 19:44 - 00001449 _____ C:\Users\Public\Desktop\Start Andy.lnk
  615. 2017-06-21 19:44 - 2017-06-21 19:44 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Andy
  616. 2017-06-21 19:31 - 2017-06-21 19:31 - 00000000 ____D C:\Users\Qwerty\Andy
  617. 2017-06-21 19:30 - 2017-06-21 19:44 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\Andy
  618. 2017-06-21 19:30 - 2017-06-21 19:31 - 00000000 ____D C:\Program Files\Andy
  619. 2017-06-21 19:30 - 2017-06-21 19:30 - 00000000 ____D C:\Users\Qwert\Andy
  620. 2017-06-21 19:30 - 2017-06-21 19:30 - 00000000 ____D C:\Users\Qwert
  621. 2017-06-21 19:22 - 2017-06-21 19:22 - 00000000 ____D C:\Users\Qwerty\.android
  622. 2017-06-21 19:21 - 2017-06-21 19:21 - 00000045 _____ C:\Users\Qwerty\nuuid.ini
  623. 2017-06-21 19:21 - 2017-06-21 19:21 - 00000041 _____ C:\Users\Qwerty\inst.ini
  624. 2017-06-21 19:21 - 2017-06-21 19:21 - 00000000 ____D C:\Users\Qwerty\vmlogs
  625. 2017-06-21 19:21 - 2017-06-21 19:21 - 00000000 ____D C:\Users\Qwerty\Nox_share
  626. 2017-06-21 19:19 - 2017-06-21 19:28 - 00000000 ____D C:\Users\Qwerty\AppData\Local\Nox
  627. 2017-06-21 19:19 - 2017-06-21 19:28 - 00000000 ____D C:\Program Files (x86)\Nox
  628. 2017-06-21 19:17 - 2017-06-21 19:18 - 305630088 _____ (Duodian Technology Co. Ltd.) C:\Users\Qwerty\Downloads\techapple-nox_setup_v3.8.1.1_full.exe
  629. 2017-06-21 15:47 - 2017-06-21 15:48 - 07517264 _____ (RealVNC Ltd) C:\Users\Qwerty\Downloads\VNC-Viewer-6.1.1-Windows-64bit (3).exe
  630. 2017-06-21 15:47 - 2017-06-21 15:48 - 07517264 _____ (RealVNC Ltd) C:\Users\Qwerty\Downloads\VNC-Viewer-6.1.1-Windows-64bit (2).exe
  631. 2017-06-21 15:47 - 2017-06-21 15:47 - 07517264 _____ (RealVNC Ltd) C:\Users\Qwerty\Downloads\VNC-Viewer-6.1.1-Windows-64bit.exe
  632. 2017-06-21 15:47 - 2017-06-21 15:47 - 07517264 _____ (RealVNC Ltd) C:\Users\Qwerty\Downloads\VNC-Viewer-6.1.1-Windows-64bit (1).exe
  633. 2017-06-20 19:16 - 2017-06-20 19:16 - 00002184 _____ C:\Users\Qwerty\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\EmEditor.lnk
  634. 2017-06-20 19:16 - 2017-06-20 19:16 - 00002176 _____ C:\Users\Qwerty\Desktop\EmEditor.lnk
  635. 2017-06-20 19:16 - 2017-06-20 19:16 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\Emurasoft
  636. 2017-06-20 19:16 - 2017-06-20 19:16 - 00000000 ____D C:\Users\Qwerty\AppData\Local\Emurasoft
  637. 2017-06-20 19:16 - 2017-06-20 19:16 - 00000000 ____D C:\ProgramData\Emurasoft
  638. 2017-06-20 19:15 - 2017-06-20 19:15 - 07077008 _____ (Emurasoft, Inc.) C:\Users\Qwerty\Downloads\emed64_16.9.3.exe
  639. 2017-06-20 19:15 - 2017-06-20 19:15 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\Emurasoft, Inc
  640. 2017-06-20 19:14 - 2017-06-20 19:14 - 00375954 _____ C:\Users\Qwerty\Downloads\LTFViewr.zip
  641. 2017-06-20 19:11 - 2017-06-20 19:11 - 00051712 _____ C:\Users\Qwerty\Downloads\Large Text File Reader.exe
  642. 2017-06-20 19:10 - 2017-06-20 19:10 - 00888094 _____ C:\Users\Qwerty\Documents\test.vbs
  643. 2017-06-20 19:09 - 2017-06-20 19:09 - 04118001 _____ C:\Users\Qwerty\Downloads\Exe+to+VBS.zip
  644. 2017-06-20 19:09 - 2014-11-24 08:15 - 15530909 _____ C:\Users\Qwerty\Documents\Exe to VBS.exe
  645. 2017-06-20 19:01 - 2017-06-20 19:03 - 00000318 _____ C:\Users\Qwerty\Documents\dl.vbs
  646. 2017-06-19 20:04 - 2017-06-19 20:04 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\RealVNC
  647. 2017-06-19 20:04 - 2017-06-19 20:04 - 00000000 ____D C:\Users\Qwerty\AppData\Local\RealVNC
  648. 2017-06-19 18:32 - 2017-06-19 18:32 - 00000322 _____ C:\Users\Qwerty\Desktop\iExplorer.appref-ms
  649. 2017-06-19 18:32 - 2017-06-19 18:32 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Macroplant LLC
  650. 2017-06-19 18:18 - 2017-06-19 18:18 - 00597016 _____ () C:\Users\Qwerty\Downloads\iExplorerSetup.exe
  651. 2017-06-19 18:12 - 2017-06-19 18:12 - 00001060 _____ C:\Users\Public\Desktop\iFunbox.lnk
  652. 2017-06-19 18:12 - 2017-06-19 18:12 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\iFunbox_UserCache
  653. 2017-06-19 18:12 - 2017-06-19 18:12 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\i-Funbox DevTeam
  654. 2017-06-19 18:12 - 2017-06-19 18:12 - 00000000 ____D C:\Program Files (x86)\i-Funbox DevTeam
  655. 2017-06-19 18:10 - 2017-06-19 18:10 - 80762908 _____ C:\Users\Qwerty\Downloads\RetroArch.deb
  656. 2017-06-19 18:10 - 2017-06-19 18:10 - 35156014 _____ (iFunbox DevTeam ) C:\Users\Qwerty\Downloads\ifunbox_v4106_setup.exe
  657. 2017-06-19 18:05 - 2017-06-19 18:06 - 166217983 _____ C:\Users\Qwerty\Downloads\RetroArch.zip
  658. 2017-06-19 16:55 - 2017-06-19 16:55 - 00000000 ____D C:\Users\Qwerty\Downloads\Simpsons, The - Road Rage (Europe) (En,Fr,De,Es,It)
  659. 2017-06-19 16:53 - 2017-06-19 16:55 - 302774010 _____ C:\Users\Qwerty\Downloads\Simpsons, The - Road Rage (Europe) (En,Fr,De,Es,It).7z
  660. 2017-06-19 07:40 - 2017-06-19 07:40 - 00000000 ____D C:\Users\Qwerty\Downloads\semirestore9
  661. 2017-06-19 07:38 - 2017-06-19 07:38 - 01241877 _____ C:\Users\Qwerty\Downloads\SemiRestore9-Windows-1.0.4.zip
  662. 2017-06-18 14:42 - 2017-06-18 14:42 - 00000000 ____D C:\Users\Qwerty\Downloads\The Simpsons Hit And Run PS2
  663. 2017-06-18 14:40 - 2017-06-18 14:41 - 13380830 _____ C:\Users\Qwerty\Downloads\ps2_bios.zip
  664. 2017-06-18 14:40 - 2017-06-18 14:40 - 00000000 ____D C:\Users\Qwerty\Documents\PCSX2
  665. 2017-06-18 14:39 - 2017-07-04 20:02 - 00000000 ____D C:\Program Files (x86)\PCSX2 1.4.0
  666. 2017-06-18 14:39 - 2017-06-18 14:41 - 693560658 _____ C:\Users\Qwerty\Downloads\Simpsons, The - Hit & Run (USA).7z
  667. 2017-06-18 14:39 - 2017-06-18 14:39 - 00001943 _____ C:\Users\Public\Desktop\PCSX2 1.4.0.lnk
  668. 2017-06-18 14:39 - 2017-06-18 14:39 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PCSX2
  669. 2017-06-18 14:38 - 2017-06-18 14:38 - 17837152 _____ C:\Users\Qwerty\Downloads\pcsx2-1.4.0-setup.exe
  670. 2017-06-17 20:48 - 2017-07-02 00:09 - 00000000 ____D C:\Users\Qwerty\Downloads\dynephant-master
  671. 2017-06-17 20:48 - 2017-06-17 20:48 - 03200868 _____ C:\Users\Qwerty\Downloads\dynephant-master.zip
  672. 2017-06-17 20:48 - 2017-06-17 20:48 - 00000000 ____D C:\dynephant
  673. 2017-06-17 20:47 - 2017-06-17 20:47 - 01228800 _____ C:\Users\Qwerty\Downloads\ddnsupdater_2.1-169.spk
  674. 2017-06-16 19:48 - 2017-06-16 20:05 - 1386748959 _____ C:\Users\Qwerty\Desktop\The Simpsons - Hit & Run.7z
  675. 2017-06-16 19:34 - 2017-06-16 19:36 - 68959074 _____ C:\Users\Qwerty\Documents\The Simpsons - Hit & Run.7z
  676. 2017-06-15 17:40 - 2017-06-15 17:40 - 03713472 _____ C:\Users\Qwerty\Downloads\Lucas' Simpsons Hit & Run Mod Launcher 1.15.3.zip
  677. 2017-06-15 16:42 - 2017-06-15 16:43 - 183880504 _____ (Rockstar Games) C:\Users\Qwerty\Downloads\GTAV_Setup_Tool.exe
  678. 2017-06-15 12:53 - 2017-06-15 12:53 - 00042064 _____ (Anchorfree Inc.) C:\Windows\system32\Drivers\taphss6.sys
  679. 2017-06-14 17:27 - 2017-06-14 17:27 - 00000458 _____ C:\memory.txt
  680. 2017-06-14 17:19 - 2017-06-14 17:19 - 01469560 _____ C:\Users\Qwerty\Downloads\CRASHDAY.V1.1.ALL.MACIOZO.NOCD.ZIP
  681. 2017-06-14 17:15 - 2017-06-14 17:15 - 00000000 ____D C:\ProgramData\Trymedia
  682. 2017-06-14 17:10 - 2017-06-14 17:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Atari
  683. 2017-06-14 17:10 - 2017-06-14 17:10 - 00000000 ____D C:\Program Files (x86)\Atari
  684. 2017-06-14 10:32 - 2017-06-02 09:28 - 02317824 _____ (Microsoft Corporation) C:\Windows\system32\tquery.dll
  685. 2017-06-14 10:32 - 2017-06-02 09:28 - 02222080 _____ (Microsoft Corporation) C:\Windows\system32\mssrch.dll
  686. 2017-06-14 10:32 - 2017-06-02 09:28 - 00778240 _____ (Microsoft Corporation) C:\Windows\system32\mssvp.dll
  687. 2017-06-14 10:32 - 2017-06-02 09:28 - 00491520 _____ (Microsoft Corporation) C:\Windows\system32\mssph.dll
  688. 2017-06-14 10:32 - 2017-06-02 09:28 - 00288256 _____ (Microsoft Corporation) C:\Windows\system32\mssphtb.dll
  689. 2017-06-14 10:32 - 2017-06-02 09:28 - 00115200 _____ (Microsoft Corporation) C:\Windows\system32\mssitlb.dll
  690. 2017-06-14 10:32 - 2017-06-02 09:28 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\mssprxy.dll
  691. 2017-06-14 10:32 - 2017-06-02 09:28 - 00075264 _____ (Microsoft Corporation) C:\Windows\system32\msscntrs.dll
  692. 2017-06-14 10:32 - 2017-06-02 09:28 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\msshooks.dll
  693. 2017-06-14 10:32 - 2017-06-02 09:11 - 00591872 _____ (Microsoft Corporation) C:\Windows\system32\SearchIndexer.exe
  694. 2017-06-14 10:32 - 2017-06-02 09:11 - 00249856 _____ (Microsoft Corporation) C:\Windows\system32\SearchProtocolHost.exe
  695. 2017-06-14 10:32 - 2017-06-02 09:10 - 00733696 _____ (Microsoft Corporation) C:\Windows\HelpPane.exe
  696. 2017-06-14 10:32 - 2017-06-02 09:10 - 00113664 _____ (Microsoft Corporation) C:\Windows\system32\SearchFilterHost.exe
  697. 2017-06-14 10:32 - 2017-06-02 09:09 - 01549824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tquery.dll
  698. 2017-06-14 10:32 - 2017-06-02 09:09 - 01400320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssrch.dll
  699. 2017-06-14 10:32 - 2017-06-02 09:09 - 00666624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssvp.dll
  700. 2017-06-14 10:32 - 2017-06-02 09:09 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssph.dll
  701. 2017-06-14 10:32 - 2017-06-02 09:09 - 00197120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssphtb.dll
  702. 2017-06-14 10:32 - 2017-06-02 09:09 - 00104448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssitlb.dll
  703. 2017-06-14 10:32 - 2017-06-02 09:09 - 00059392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msscntrs.dll
  704. 2017-06-14 10:32 - 2017-06-02 09:09 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssprxy.dll
  705. 2017-06-14 10:32 - 2017-06-02 08:58 - 00427520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchIndexer.exe
  706. 2017-06-14 10:32 - 2017-06-02 08:58 - 00164352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchProtocolHost.exe
  707. 2017-06-14 10:32 - 2017-06-02 08:57 - 00086528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchFilterHost.exe
  708. 2017-06-14 10:32 - 2017-06-02 08:57 - 00009728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msshooks.dll
  709. 2017-06-14 10:32 - 2017-05-21 05:28 - 00154856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
  710. 2017-06-14 10:32 - 2017-05-21 05:28 - 00095464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
  711. 2017-06-14 10:32 - 2017-05-21 05:24 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
  712. 2017-06-14 10:32 - 2017-05-21 05:24 - 01212928 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
  713. 2017-06-14 10:32 - 2017-05-21 05:24 - 00730624 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
  714. 2017-06-14 10:32 - 2017-05-21 05:24 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
  715. 2017-06-14 10:32 - 2017-05-21 05:24 - 00463872 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
  716. 2017-06-14 10:32 - 2017-05-21 05:24 - 00345600 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
  717. 2017-06-14 10:32 - 2017-05-21 05:24 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
  718. 2017-06-14 10:32 - 2017-05-21 05:24 - 00312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
  719. 2017-06-14 10:32 - 2017-05-21 05:24 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
  720. 2017-06-14 10:32 - 2017-05-21 05:24 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll
  721. 2017-06-14 10:32 - 2017-05-21 05:24 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
  722. 2017-06-14 10:32 - 2017-05-21 05:24 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
  723. 2017-06-14 10:32 - 2017-05-21 05:24 - 00123904 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll
  724. 2017-06-14 10:32 - 2017-05-21 05:24 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
  725. 2017-06-14 10:32 - 2017-05-21 05:24 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
  726. 2017-06-14 10:32 - 2017-05-21 05:24 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
  727. 2017-06-14 10:32 - 2017-05-21 05:24 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
  728. 2017-06-14 10:32 - 2017-05-21 05:24 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
  729. 2017-06-14 10:32 - 2017-05-21 05:24 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
  730. 2017-06-14 10:32 - 2017-05-21 05:06 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
  731. 2017-06-14 10:32 - 2017-05-21 05:06 - 00666112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
  732. 2017-06-14 10:32 - 2017-05-21 05:06 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
  733. 2017-06-14 10:32 - 2017-05-21 05:06 - 00342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
  734. 2017-06-14 10:32 - 2017-05-21 05:06 - 00261120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
  735. 2017-06-14 10:32 - 2017-05-21 05:06 - 00254464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
  736. 2017-06-14 10:32 - 2017-05-21 05:06 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
  737. 2017-06-14 10:32 - 2017-05-21 05:06 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
  738. 2017-06-14 10:32 - 2017-05-21 05:06 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
  739. 2017-06-14 10:32 - 2017-05-21 05:06 - 00141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll
  740. 2017-06-14 10:32 - 2017-05-21 05:06 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
  741. 2017-06-14 10:32 - 2017-05-21 05:06 - 00082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcrypt.dll
  742. 2017-06-14 10:32 - 2017-05-21 05:06 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
  743. 2017-06-14 10:32 - 2017-05-21 05:06 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
  744. 2017-06-14 10:32 - 2017-05-21 05:06 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
  745. 2017-06-14 10:32 - 2017-05-21 05:06 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
  746. 2017-06-14 10:32 - 2017-05-21 04:55 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
  747. 2017-06-14 10:32 - 2017-05-21 04:48 - 00291328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
  748. 2017-06-14 10:32 - 2017-05-21 04:48 - 00159744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
  749. 2017-06-14 10:32 - 2017-05-21 04:48 - 00129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
  750. 2017-06-14 10:32 - 2017-05-21 04:47 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
  751. 2017-06-14 10:32 - 2017-05-21 04:46 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
  752. 2017-06-14 10:32 - 2017-05-21 04:42 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
  753. 2017-06-14 10:32 - 2017-05-12 19:27 - 00631176 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
  754. 2017-06-14 10:32 - 2017-05-12 19:26 - 05547752 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
  755. 2017-06-14 10:32 - 2017-05-12 19:26 - 00706792 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
  756. 2017-06-14 10:32 - 2017-05-12 19:26 - 00382696 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
  757. 2017-06-14 10:32 - 2017-05-12 19:24 - 01732864 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
  758. 2017-06-14 10:32 - 2017-05-12 19:22 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
  759. 2017-06-14 10:32 - 2017-05-12 19:22 - 00880640 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
  760. 2017-06-14 10:32 - 2017-05-12 19:22 - 00806912 _____ (Microsoft Corporation) C:\Windows\system32\usp10.dll
  761. 2017-06-14 10:32 - 2017-05-12 19:22 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
  762. 2017-06-14 10:32 - 2017-05-12 19:22 - 00419840 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
  763. 2017-06-14 10:32 - 2017-05-12 19:22 - 00405504 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
  764. 2017-06-14 10:32 - 2017-05-12 19:22 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
  765. 2017-06-14 10:32 - 2017-05-12 19:22 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
  766. 2017-06-14 10:32 - 2017-05-12 19:22 - 00215552 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
  767. 2017-06-14 10:32 - 2017-05-12 19:22 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
  768. 2017-06-14 10:32 - 2017-05-12 19:22 - 00063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
  769. 2017-06-14 10:32 - 2017-05-12 19:22 - 00059904 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
  770. 2017-06-14 10:32 - 2017-05-12 19:22 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
  771. 2017-06-14 10:32 - 2017-05-12 19:22 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
  772. 2017-06-14 10:32 - 2017-05-12 19:22 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
  773. 2017-06-14 10:32 - 2017-05-12 19:22 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
  774. 2017-06-14 10:32 - 2017-05-12 19:22 - 00034816 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
  775. 2017-06-14 10:32 - 2017-05-12 19:22 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
  776. 2017-06-14 10:32 - 2017-05-12 19:22 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
  777. 2017-06-14 10:32 - 2017-05-12 19:22 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
  778. 2017-06-14 10:32 - 2017-05-12 19:22 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
  779. 2017-06-14 10:32 - 2017-05-12 19:22 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
  780. 2017-06-14 10:32 - 2017-05-12 19:22 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
  781. 2017-06-14 10:32 - 2017-05-12 19:22 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
  782. 2017-06-14 10:32 - 2017-05-12 19:22 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
  783. 2017-06-14 10:32 - 2017-05-12 19:22 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
  784. 2017-06-14 10:32 - 2017-05-12 19:22 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
  785. 2017-06-14 10:32 - 2017-05-12 19:22 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
  786. 2017-06-14 10:32 - 2017-05-12 19:22 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
  787. 2017-06-14 10:32 - 2017-05-12 19:22 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
  788. 2017-06-14 10:32 - 2017-05-12 19:22 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
  789. 2017-06-14 10:32 - 2017-05-12 19:22 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
  790. 2017-06-14 10:32 - 2017-05-12 19:22 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
  791. 2017-06-14 10:32 - 2017-05-12 19:22 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
  792. 2017-06-14 10:32 - 2017-05-12 19:22 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
  793. 2017-06-14 10:32 - 2017-05-12 19:22 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
  794. 2017-06-14 10:32 - 2017-05-12 19:22 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
  795. 2017-06-14 10:32 - 2017-05-12 19:22 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
  796. 2017-06-14 10:32 - 2017-05-12 19:22 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
  797. 2017-06-14 10:32 - 2017-05-12 19:22 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
  798. 2017-06-14 10:32 - 2017-05-12 19:22 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
  799. 2017-06-14 10:32 - 2017-05-12 19:22 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
  800. 2017-06-14 10:32 - 2017-05-12 19:22 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
  801. 2017-06-14 10:32 - 2017-05-12 19:22 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
  802. 2017-06-14 10:32 - 2017-05-12 19:22 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
  803. 2017-06-14 10:32 - 2017-05-12 19:22 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
  804. 2017-06-14 10:32 - 2017-05-12 19:22 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
  805. 2017-06-14 10:32 - 2017-05-12 19:22 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
  806. 2017-06-14 10:32 - 2017-05-12 19:22 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
  807. 2017-06-14 10:32 - 2017-05-12 19:07 - 04001000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
  808. 2017-06-14 10:32 - 2017-05-12 19:07 - 03945704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
  809. 2017-06-14 10:32 - 2017-05-12 19:07 - 00308456 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
  810. 2017-06-14 10:32 - 2017-05-12 19:04 - 01314112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
  811. 2017-06-14 10:32 - 2017-05-12 19:03 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
  812. 2017-06-14 10:32 - 2017-05-12 19:03 - 00644096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
  813. 2017-06-14 10:32 - 2017-05-12 19:03 - 00629760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\usp10.dll
  814. 2017-06-14 10:32 - 2017-05-12 19:03 - 00313344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
  815. 2017-06-14 10:32 - 2017-05-12 19:03 - 00275456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
  816. 2017-06-14 10:32 - 2017-05-12 19:03 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
  817. 2017-06-14 10:32 - 2017-05-12 19:03 - 00050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll
  818. 2017-06-14 10:32 - 2017-05-12 19:03 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
  819. 2017-06-14 10:32 - 2017-05-12 19:03 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
  820. 2017-06-14 10:32 - 2017-05-12 19:03 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
  821. 2017-06-14 10:32 - 2017-05-12 19:03 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
  822. 2017-06-14 10:32 - 2017-05-12 19:03 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
  823. 2017-06-14 10:32 - 2017-05-12 19:03 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
  824. 2017-06-14 10:32 - 2017-05-12 19:03 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
  825. 2017-06-14 10:32 - 2017-05-12 19:03 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
  826. 2017-06-14 10:32 - 2017-05-12 19:03 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
  827. 2017-06-14 10:32 - 2017-05-12 19:03 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
  828. 2017-06-14 10:32 - 2017-05-12 19:03 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
  829. 2017-06-14 10:32 - 2017-05-12 19:03 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
  830. 2017-06-14 10:32 - 2017-05-12 19:03 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
  831. 2017-06-14 10:32 - 2017-05-12 19:03 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
  832. 2017-06-14 10:32 - 2017-05-12 19:03 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
  833. 2017-06-14 10:32 - 2017-05-12 19:03 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
  834. 2017-06-14 10:32 - 2017-05-12 19:03 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
  835. 2017-06-14 10:32 - 2017-05-12 19:03 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
  836. 2017-06-14 10:32 - 2017-05-12 19:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
  837. 2017-06-14 10:32 - 2017-05-12 19:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
  838. 2017-06-14 10:32 - 2017-05-12 19:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
  839. 2017-06-14 10:32 - 2017-05-12 19:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
  840. 2017-06-14 10:32 - 2017-05-12 19:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
  841. 2017-06-14 10:32 - 2017-05-12 19:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
  842. 2017-06-14 10:32 - 2017-05-12 19:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
  843. 2017-06-14 10:32 - 2017-05-12 19:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
  844. 2017-06-14 10:32 - 2017-05-12 19:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
  845. 2017-06-14 10:32 - 2017-05-12 19:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
  846. 2017-06-14 10:32 - 2017-05-12 19:03 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
  847. 2017-06-14 10:32 - 2017-05-12 18:55 - 00148480 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
  848. 2017-06-14 10:32 - 2017-05-12 18:54 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
  849. 2017-06-14 10:32 - 2017-05-12 18:54 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
  850. 2017-06-14 10:32 - 2017-05-12 18:52 - 03222528 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
  851. 2017-06-14 10:32 - 2017-05-12 18:51 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
  852. 2017-06-14 10:32 - 2017-05-12 18:50 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
  853. 2017-06-14 10:32 - 2017-05-12 18:46 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
  854. 2017-06-14 10:32 - 2017-05-12 18:43 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
  855. 2017-06-14 10:32 - 2017-05-12 18:41 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
  856. 2017-06-14 10:32 - 2017-05-12 18:41 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
  857. 2017-06-14 10:32 - 2017-05-12 18:41 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
  858. 2017-06-14 10:32 - 2017-05-12 18:41 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
  859. 2017-06-14 10:32 - 2017-05-12 18:40 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
  860. 2017-06-14 10:32 - 2017-05-12 18:40 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
  861. 2017-06-14 10:32 - 2017-05-12 18:40 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
  862. 2017-06-14 10:32 - 2017-05-12 18:40 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
  863. 2017-06-14 10:32 - 2017-05-12 17:25 - 01251328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
  864. 2017-06-14 10:32 - 2017-05-12 16:58 - 01648128 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
  865. 2017-06-14 10:32 - 2017-05-12 16:58 - 01180160 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
  866. 2017-06-14 10:32 - 2017-05-10 16:33 - 00091368 _____ (Microsoft Corporation) C:\Windows\system32\MigAutoPlay.exe
  867. 2017-06-14 10:32 - 2017-05-10 16:29 - 14183936 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
  868. 2017-06-14 10:32 - 2017-05-10 16:29 - 03165184 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
  869. 2017-06-14 10:32 - 2017-05-10 16:29 - 01867776 _____ (Microsoft Corporation) C:\Windows\system32\ExplorerFrame.dll
  870. 2017-06-14 10:32 - 2017-05-10 16:29 - 00192512 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
  871. 2017-06-14 10:32 - 2017-05-10 16:29 - 00098816 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
  872. 2017-06-14 10:32 - 2017-05-10 16:28 - 00091136 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
  873. 2017-06-14 10:32 - 2017-05-10 16:16 - 00091368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MigAutoPlay.exe
  874. 2017-06-14 10:32 - 2017-05-10 16:14 - 02651136 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
  875. 2017-06-14 10:32 - 2017-05-10 16:13 - 00709120 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
  876. 2017-06-14 10:32 - 2017-05-10 16:13 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
  877. 2017-06-14 10:32 - 2017-05-10 16:13 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
  878. 2017-06-14 10:32 - 2017-05-10 16:13 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
  879. 2017-06-14 10:32 - 2017-05-10 16:13 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
  880. 2017-06-14 10:32 - 2017-05-10 16:13 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
  881. 2017-06-14 10:32 - 2017-05-10 16:12 - 12880896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
  882. 2017-06-14 10:32 - 2017-05-10 16:12 - 01499648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ExplorerFrame.dll
  883. 2017-06-14 10:32 - 2017-05-10 16:12 - 00174080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
  884. 2017-06-14 10:32 - 2017-05-10 16:00 - 00573440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
  885. 2017-06-14 10:32 - 2017-05-10 16:00 - 00093696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
  886. 2017-06-14 10:32 - 2017-05-10 16:00 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
  887. 2017-06-14 10:32 - 2017-05-10 16:00 - 00030208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
  888. 2017-06-14 10:32 - 2017-05-10 15:52 - 00117248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys
  889. 2017-06-14 10:32 - 2017-05-09 16:30 - 00757248 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll
  890. 2017-06-14 10:32 - 2017-05-09 16:29 - 00970240 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll
  891. 2017-06-14 10:32 - 2017-05-09 16:15 - 00071680 _____ C:\Windows\system32\PrintBrmUi.exe
  892. 2017-06-14 10:32 - 2017-05-09 16:11 - 00497664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll
  893. 2017-06-14 10:32 - 2017-05-07 16:33 - 00094440 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mountmgr.sys
  894. 2017-06-14 10:32 - 2017-05-07 16:29 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\msmmsp.dll
  895. 2017-06-14 10:32 - 2017-03-30 16:03 - 00046080 _____ (Microsoft Corporation) C:\Windows\system32\rundll32.exe
  896. 2017-06-14 10:32 - 2017-03-30 15:58 - 00045056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
  897. 2017-06-13 22:00 - 2017-06-13 22:00 - 00000000 ____D C:\Users\Qwerty\AppData\Local\Criterion Games
  898. 2017-06-13 21:58 - 2017-06-13 22:10 - 00000000 ____D C:\Users\Qwerty\Documents\Bully Scholarship Edition
  899. 2017-06-13 21:56 - 2017-06-13 21:56 - 00001425 _____ C:\Users\Public\Desktop\Burnout Paradise - Config Tool.lnk
  900. 2017-06-13 21:56 - 2017-06-13 21:56 - 00001415 _____ C:\Users\Public\Desktop\Burnout Paradise - The Ultimate Box.lnk
  901. 2017-06-13 21:56 - 2017-06-13 21:56 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Electronic Arts
  902. 2017-06-13 21:48 - 2017-06-13 21:48 - 00000000 ____D C:\Program Files (x86)\Electronic Arts
  903. 2017-06-13 21:11 - 2017-06-13 21:11 - 00001298 _____ C:\Users\Public\Desktop\Bully Scholarship Edition.lnk
  904. 2017-06-13 20:17 - 2017-06-13 20:17 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\Tenorshare
  905. 2017-06-13 20:16 - 2017-06-15 21:17 - 00002385 _____ C:\Users\Qwerty\Desktop\The Simpsons - Hit & Run.lnk
  906. 2017-06-13 20:16 - 2017-06-13 20:16 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\The Simpsons - Hit & Run
  907. 2017-06-13 20:16 - 2017-06-13 20:16 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\R.G. Mechanics
  908. 2017-06-13 20:15 - 2017-06-13 20:15 - 00000995 _____ C:\Users\Qwerty\Desktop\ReiBoot.lnk
  909. 2017-06-13 20:14 - 2017-06-13 20:15 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ReiBoot
  910. 2017-06-13 20:14 - 2017-06-13 20:15 - 00000000 ____D C:\Program Files (x86)\ReiBoot
  911. 2017-06-13 20:04 - 2017-06-13 20:04 - 00000000 ____D C:\Program Files (x86)\R.G. Mechanics
  912. 2017-06-13 19:54 - 2017-06-13 19:54 - 00015847 _____ C:\Users\Qwerty\Downloads\Bully.Scholarship.Edition.MULTi6-PROPHET.torrent
  913. 2017-06-13 16:39 - 2017-06-13 17:00 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\Apple Computer
  914. 2017-06-13 16:39 - 2017-06-13 16:39 - 00001753 _____ C:\Users\Public\Desktop\iTunes.lnk
  915. 2017-06-13 16:39 - 2017-06-13 16:39 - 00000000 ____D C:\Users\Qwerty\AppData\Local\Apple Computer
  916. 2017-06-13 16:39 - 2017-06-13 16:39 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
  917. 2017-06-13 16:37 - 2017-06-13 16:39 - 00000000 ____D C:\Program Files\iTunes
  918. 2017-06-13 16:37 - 2017-06-13 16:37 - 00000000 ____D C:\ProgramData\Apple Computer
  919. 2017-06-13 16:37 - 2017-06-13 16:37 - 00000000 ____D C:\Program Files\iPod
  920. 2017-06-13 16:36 - 2017-06-13 16:36 - 00002519 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
  921. 2017-06-13 16:36 - 2017-06-13 16:36 - 00000000 ____D C:\Windows\System32\Tasks\Apple
  922. 2017-06-13 16:36 - 2017-06-13 16:36 - 00000000 ____D C:\Users\Qwerty\AppData\Local\Apple
  923. 2017-06-13 16:36 - 2017-06-13 16:36 - 00000000 ____D C:\Program Files (x86)\Apple Software Update
  924. 2017-06-13 16:35 - 2017-06-13 16:35 - 00000000 ____D C:\Program Files\Bonjour
  925. 2017-06-13 16:35 - 2017-06-13 16:35 - 00000000 ____D C:\Program Files (x86)\Bonjour
  926. 2017-06-13 16:34 - 2017-06-13 16:35 - 00000000 ____D C:\Program Files\Common Files\Apple
  927. 2017-06-13 16:33 - 2017-06-13 16:36 - 00000000 ____D C:\ProgramData\Apple
  928. 2017-06-13 15:40 - 2017-06-25 13:08 - 00000000 ____D C:\Windows\Minidump
  929. 2017-06-12 21:21 - 2017-06-13 15:33 - 00000000 ____D C:\Users\Qwerty\AppData\Local\System3264
  930. 2017-06-12 17:00 - 2017-06-12 17:00 - 00001151 _____ C:\Users\Public\Desktop\CDBurnerXP.lnk
  931. 2017-06-12 17:00 - 2017-06-12 17:00 - 00001109 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CDBurnerXP.lnk
  932. 2017-06-12 17:00 - 2017-06-12 17:00 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\Canneverbe Limited
  933. 2017-06-12 17:00 - 2017-06-12 17:00 - 00000000 ____D C:\ProgramData\Canneverbe Limited
  934. 2017-06-12 17:00 - 2017-06-12 17:00 - 00000000 ____D C:\Program Files (x86)\CDBurnerXP
  935. 2017-06-12 16:17 - 2017-06-12 16:39 - 00000000 ____D C:\Users\Qwerty\Documents\American Epic
  936. 2017-06-12 16:14 - 2017-06-12 16:16 - 00000000 ____D C:\Users\Qwerty\American Epic
  937. 2017-06-12 16:09 - 2017-06-12 16:09 - 00675902 _____ C:\Users\Qwerty\Downloads\lame3.99.5.zip
  938. 2017-06-12 16:09 - 2017-06-12 16:09 - 00000000 ____D C:\Users\Qwerty\Documents\lame
  939. 2017-06-12 16:08 - 2017-06-12 16:08 - 00891865 _____ C:\Users\Qwerty\Downloads\lame3.99.5-64.zip
  940. 2017-06-12 16:04 - 2017-06-12 16:04 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\EAC
  941. 2017-06-12 16:03 - 2017-06-12 16:04 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\AccurateRip
  942. 2017-06-12 16:03 - 2017-06-12 16:03 - 00001074 _____ C:\Users\Public\Desktop\Exact Audio Copy.lnk
  943. 2017-06-12 16:03 - 2017-06-12 16:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Exact Audio Copy
  944. 2017-06-12 16:03 - 2017-06-12 16:03 - 00000000 ____D C:\Program Files (x86)\Exact Audio Copy
  945. 2017-06-11 15:37 - 2017-06-11 15:41 - 00000000 ____D C:\Users\Qwerty\Downloads\netcrack
  946. 2017-06-11 15:37 - 2017-06-11 15:37 - 00028431 _____ C:\Users\Qwerty\Downloads\Netflix-Cracker-master.zip
  947. 2017-06-10 23:59 - 2017-06-10 23:59 - 00012872 _____ (SurfRight B.V.) C:\Windows\system32\bootdelete.exe
  948. 2017-06-10 23:59 - 2017-06-10 23:59 - 00003296 _____ C:\Windows\system32\bootdelete.lst
  949. 2017-06-10 23:39 - 2017-06-25 11:51 - 00084256 _____ (Malwarebytes) C:\Windows\system32\Drivers\mwac.sys
  950. 2017-06-10 23:39 - 2017-06-24 15:48 - 00113592 _____ (Malwarebytes) C:\Windows\system32\Drivers\farflt.sys
  951. 2017-06-10 23:39 - 2017-06-24 15:48 - 00044960 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
  952. 2017-06-10 23:39 - 2017-06-10 23:39 - 00188312 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMChameleon.sys
  953. 2017-06-10 23:38 - 2017-07-09 00:17 - 00253856 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
  954. 2017-06-10 23:38 - 2017-06-30 12:26 - 00077376 _____ C:\Windows\system32\Drivers\mbae64.sys
  955. 2017-06-10 23:38 - 2017-06-10 23:38 - 00001867 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
  956. 2017-06-10 23:38 - 2017-06-10 23:38 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
  957. 2017-06-10 23:38 - 2017-06-10 23:38 - 00000000 ____D C:\ProgramData\Malwarebytes
  958. 2017-06-10 23:38 - 2017-06-10 23:38 - 00000000 ____D C:\Program Files\Malwarebytes
  959. 2017-06-10 23:37 - 2017-06-10 23:37 - 00000000 ____D C:\Program Files\HitmanPro
  960. 2017-06-10 23:36 - 2017-06-11 00:00 - 00000000 ____D C:\ProgramData\HitmanPro
  961. 2017-06-10 23:14 - 2017-06-10 23:54 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\Imminent
  962. 2017-06-10 23:14 - 2017-06-10 23:14 - 00000000 ____D C:\Users\Qwerty\AppData\Local\PhoenixGUI
  963. 2017-06-10 23:14 - 2017-06-10 23:14 - 00000000 ____D C:\PhoenixGUI
  964. 2017-06-10 21:17 - 2017-06-10 21:17 - 01931969 _____ C:\Users\Qwerty\Downloads\ProcessExplorer.zip
  965. 2017-06-10 18:35 - 2017-06-10 18:35 - 00063668 _____ C:\Users\Qwerty\Downloads\Venom Release.rar
  966. 2017-06-09 15:54 - 2017-06-09 15:56 - 00000000 ____D C:\Users\Qwerty\AppData\Local\PAYDAY 2
  967. 2017-06-09 15:54 - 2017-06-09 15:54 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
  968. 2017-06-09 15:54 - 2017-06-09 15:54 - 00000000 ____D C:\Program Files (x86)\AGEIA Technologies
  969. 2017-06-09 07:37 - 2015-07-16 20:12 - 04922368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
  970. 2017-06-09 07:37 - 2015-07-16 20:12 - 00269824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aaclient.dll
  971. 2017-06-09 07:37 - 2015-07-16 20:12 - 00037376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll
  972. 2017-06-09 07:37 - 2015-07-16 20:11 - 05779456 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
  973. 2017-06-09 07:37 - 2015-07-16 20:11 - 00322560 _____ (Microsoft Corporation) C:\Windows\system32\aaclient.dll
  974. 2017-06-09 07:37 - 2015-07-16 20:11 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll
  975. 2017-06-09 07:37 - 2014-12-11 18:47 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
  976. 2017-06-09 07:37 - 2014-08-29 03:06 - 01125888 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
  977. 2017-06-09 07:37 - 2014-08-29 02:44 - 01050112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe
  978.  
  979. ==================== One Month Modified files and folders ========
  980.  
  981. (If an entry is included in the fixlist, the file/folder will be moved.)
  982.  
  983. 2017-07-09 16:30 - 2017-05-12 22:20 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\Skype
  984. 2017-07-09 16:09 - 2017-05-13 01:20 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\vlc
  985. 2017-07-09 15:25 - 2017-05-12 21:10 - 00060496 _____ C:\Users\Qwerty\AppData\Local\GDIPFONTCACHEV1.DAT
  986. 2017-07-09 15:21 - 2017-05-12 21:30 - 00000000 ____D C:\ProgramData\Package Cache
  987. 2017-07-09 14:59 - 2017-05-12 21:00 - 00000000 ____D C:\Users\Qwerty
  988. 2017-07-09 14:59 - 2009-07-14 03:34 - 00000256 _____ C:\Windows\system.ini
  989. 2017-07-09 14:41 - 2017-05-13 01:11 - 00000000 ____D C:\Users\Qwerty\AppData\Local\CrashDumps
  990. 2017-07-09 14:28 - 2017-05-23 20:51 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\AIMP
  991. 2017-07-09 14:28 - 2017-05-12 21:27 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\TeamViewer
  992. 2017-07-09 14:28 - 2017-05-12 21:27 - 00000000 ____D C:\Program Files (x86)\Steam
  993. 2017-07-09 13:43 - 2009-07-14 06:13 - 00963626 _____ C:\Windows\system32\PerfStringBackup.INI
  994. 2017-07-09 13:43 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\inf
  995. 2017-07-09 00:26 - 2009-07-14 05:45 - 00026576 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
  996. 2017-07-09 00:26 - 2009-07-14 05:45 - 00026576 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
  997. 2017-07-09 00:19 - 2017-05-12 22:55 - 00000000 __SHD C:\Users\Qwerty\IntelGraphicsProfiles
  998. 2017-07-09 00:15 - 2017-05-21 21:54 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\uTorrent
  999. 2017-07-09 00:15 - 2017-05-13 15:12 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\Volume2
  1000. 2017-07-09 00:14 - 2017-05-16 21:56 - 00000000 ____D C:\Program Files (x86)\Trillian56
  1001. 2017-07-09 00:14 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
  1002. 2017-07-07 20:20 - 2017-05-12 21:11 - 00002232 ____H C:\Users\Qwerty\Documents\Default.rdp
  1003. 2017-07-07 18:10 - 2017-06-04 22:03 - 00000000 ____D C:\Users\Qwerty\.VirtualBox
  1004. 2017-07-07 16:08 - 2009-07-14 04:20 - 00000000 ___HD C:\Windows\system32\GroupPolicy
  1005. 2017-07-07 07:24 - 2017-05-12 21:27 - 00000000 ____D C:\Program Files (x86)\TeamViewer
  1006. 2017-07-06 19:16 - 2017-06-05 16:29 - 00000000 ____D C:\Users\Qwerty\VirtualBox VMs
  1007. 2017-07-05 22:30 - 2017-05-12 21:31 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\FileZilla
  1008. 2017-07-04 20:17 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\LiveKernelReports
  1009. 2017-07-03 17:53 - 2017-05-13 22:31 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\Kodi
  1010. 2017-07-03 17:10 - 2017-05-12 21:27 - 00000971 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 12.lnk
  1011. 2017-07-03 17:10 - 2017-05-12 21:27 - 00000959 _____ C:\Users\Public\Desktop\TeamViewer 12.lnk
  1012. 2017-07-03 12:23 - 2017-05-14 02:25 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\VMware
  1013. 2017-07-03 12:23 - 2017-05-14 02:25 - 00000000 ____D C:\Users\Qwerty\AppData\Local\VMware
  1014. 2017-07-02 13:03 - 2017-06-04 21:24 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
  1015. 2017-07-02 12:08 - 2017-06-06 21:37 - 00361336 _____ (AVAST Software) C:\Windows\system32\Drivers\aswvmm.sys
  1016. 2017-07-02 12:07 - 2017-06-06 21:37 - 00003914 _____ C:\Windows\System32\Tasks\Avast Emergency Update
  1017. 2017-07-02 12:07 - 2017-06-06 21:33 - 00000000 ____D C:\ProgramData\AVAST Software
  1018. 2017-07-02 12:06 - 2017-06-06 21:37 - 01015848 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
  1019. 2017-07-02 12:06 - 2017-06-06 21:37 - 00585608 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
  1020. 2017-07-02 12:06 - 2017-06-06 21:37 - 00360792 _____ (AVAST Software) C:\Windows\system32\Drivers\aswvmm.sys.149899370806806
  1021. 2017-07-02 12:06 - 2017-06-06 21:37 - 00343264 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbloga.sys
  1022. 2017-07-02 12:06 - 2017-06-06 21:37 - 00319984 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbidsdrivera.sys
  1023. 2017-07-02 12:06 - 2017-06-06 21:37 - 00198944 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbidsha.sys
  1024. 2017-07-02 12:06 - 2017-06-06 21:37 - 00198768 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
  1025. 2017-07-02 12:06 - 2017-06-06 21:37 - 00146664 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
  1026. 2017-07-02 12:06 - 2017-06-06 21:37 - 00110352 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
  1027. 2017-07-02 12:06 - 2017-06-06 21:37 - 00084392 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys
  1028. 2017-07-02 12:06 - 2017-06-06 21:37 - 00057704 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbuniva.sys
  1029. 2017-07-02 12:06 - 2017-06-06 21:37 - 00046984 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHwid.sys
  1030. 2017-07-01 23:18 - 2017-05-12 21:32 - 00000000 ____D C:\ProgramData\Skype
  1031. 2017-07-01 21:39 - 2017-05-14 02:26 - 00000000 ____D C:\Users\Qwerty\Documents\Virtual Machines
  1032. 2017-07-01 21:32 - 2017-05-14 02:23 - 00001024 _____ C:\Windows\SysWOW64\%TMP%
  1033. 2017-07-01 21:32 - 2017-05-13 03:27 - 00968612 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
  1034. 2017-06-30 10:48 - 2017-06-05 21:24 - 00000000 ____D C:\Users\DefaultAppPool
  1035. 2017-06-29 21:10 - 2017-05-15 19:29 - 00000000 ____D C:\Users\Qwerty\Documents\Visual Studio 2015
  1036. 2017-06-29 20:48 - 2017-05-15 16:42 - 00000000 ____D C:\Program Files (x86)\Microsoft SDKs
  1037. 2017-06-29 20:47 - 2017-05-15 16:42 - 00000000 ____D C:\Program Files (x86)\Windows Kits
  1038. 2017-06-27 16:44 - 2017-06-04 22:02 - 00001076 _____ C:\Users\Public\Desktop\Oracle VM VirtualBox.lnk
  1039. 2017-06-27 16:44 - 2017-06-04 22:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Oracle VM VirtualBox
  1040. 2017-06-27 15:51 - 2017-06-05 16:20 - 00000000 ____D C:\Users\Qwerty\AppData\Local\Spotify
  1041. 2017-06-27 10:06 - 2017-06-05 16:19 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\Spotify
  1042. 2017-06-27 08:22 - 2017-05-12 21:11 - 00002195 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
  1043. 2017-06-27 08:22 - 2017-05-12 21:11 - 00002183 _____ C:\Users\Public\Desktop\Google Chrome.lnk
  1044. 2017-06-27 07:38 - 2017-05-19 15:43 - 00000000 ____D C:\Windows\pss
  1045. 2017-06-25 13:08 - 2017-05-27 21:58 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\DAEMON Tools Lite
  1046. 2017-06-25 13:08 - 2017-05-13 05:51 - 00000000 ____D C:\Windows\Panther
  1047. 2017-06-25 13:08 - 2017-05-12 21:39 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\CoreFTP
  1048. 2017-06-21 19:41 - 2017-05-14 02:21 - 00000000 ____D C:\Program Files (x86)\VMware
  1049. 2017-06-21 19:20 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\Registration
  1050. 2017-06-19 18:34 - 2017-05-12 21:10 - 00000000 ____D C:\Users\Qwerty\AppData\Local\Deployment
  1051. 2017-06-18 21:46 - 2017-05-15 21:05 - 00000000 ____D C:\Users\Qwerty\AppData\LocalLow\Mozilla
  1052. 2017-06-18 14:39 - 2017-05-13 00:59 - 00000000 ___HD C:\Windows\msdownld.tmp
  1053. 2017-06-18 14:39 - 2017-05-13 00:59 - 00000000 ____D C:\Windows\SysWOW64\directx
  1054. 2017-06-16 08:09 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache
  1055. 2017-06-15 16:51 - 2017-05-12 21:40 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
  1056. 2017-06-15 16:49 - 2009-07-14 04:20 - 00000000 __RHD C:\Users\Public\Libraries
  1057. 2017-06-15 16:45 - 2017-05-13 00:59 - 00000000 ____D C:\Program Files (x86)\Mr DJ
  1058. 2017-06-15 16:44 - 2017-05-12 23:37 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Rockstar Games
  1059. 2017-06-15 16:44 - 2017-05-12 21:07 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
  1060. 2017-06-15 16:43 - 2017-05-12 23:41 - 00000000 ____D C:\Users\Qwerty\Documents\Rockstar Games
  1061. 2017-06-15 16:43 - 2017-05-12 23:41 - 00000000 ____D C:\Users\Qwerty\AppData\Local\Rockstar Games
  1062. 2017-06-15 16:40 - 2017-05-12 23:39 - 00000000 ____D C:\Program Files (x86)\Rockstar Games
  1063. 2017-06-15 16:40 - 2017-05-12 23:37 - 00000000 ____D C:\Program Files\Rockstar Games
  1064. 2017-06-15 16:23 - 2009-07-14 05:45 - 00268392 _____ C:\Windows\system32\FNTCACHE.DAT
  1065. 2017-06-15 16:21 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\SysWOW64\migwiz
  1066. 2017-06-15 16:21 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\migwiz
  1067. 2017-06-14 22:03 - 2017-05-13 13:09 - 00000000 ____D C:\Windows\system32\MRT
  1068. 2017-06-14 21:58 - 2017-05-13 13:09 - 133627792 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
  1069. 2017-06-14 20:49 - 2017-05-15 21:05 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
  1070. 2017-06-14 18:08 - 2017-05-13 01:22 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
  1071. 2017-06-11 14:54 - 2017-06-07 07:48 - 00000000 ____D C:\Program Files (x86)\Remotr
  1072. 2017-06-11 14:51 - 2017-05-12 21:29 - 00000871 _____ C:\Users\Public\Desktop\VLC media player.lnk
  1073. 2017-06-11 14:32 - 2017-06-07 07:48 - 00000000 ____D C:\ProgramData\Remotr
  1074. 2017-06-10 23:59 - 2017-05-24 07:14 - 00000000 ____D C:\Users\Qwerty\Downloads\Windows Loader v2.2.2
  1075. 2017-06-10 00:21 - 2017-06-04 18:36 - 00000000 ____D C:\Users\Qwerty\AppData\Roaming\Sia-UI
  1076. 2017-06-09 23:47 - 2017-05-12 21:33 - 00000000 ___RD C:\Program Files (x86)\Skype
  1077.  
  1078. ==================== Files in the root of some directories =======
  1079.  
  1080. 2017-07-06 17:10 - 2017-07-09 14:40 - 0000338 _____ () C:\Users\Qwerty\AppData\Roaming\basic.ini
  1081. 2017-04-13 14:57 - 2017-04-13 14:57 - 1645928 _____ (Adobe Systems Incorporated) C:\Users\Qwerty\AppData\Roaming\NetframeworkD.exe
  1082. 2017-04-14 03:48 - 2017-04-14 03:48 - 1930752 _____ (Microsoft Corporation) C:\Users\Qwerty\AppData\Roaming\NetframeworkG.exe
  1083. 2017-06-23 12:03 - 2017-06-23 12:03 - 1725199 _____ (Inekman) C:\Users\Qwerty\AppData\Roaming\Nvidia.exe
  1084. 2017-05-13 15:04 - 2017-05-13 15:04 - 0001524 _____ () C:\Users\Qwerty\AppData\Local\recently-used.xbel
  1085. 2017-05-16 19:18 - 2017-05-21 00:21 - 0007598 _____ () C:\Users\Qwerty\AppData\Local\Resmon.ResmonCfg
  1086.  
  1087. Files to move or delete:
  1088. ====================
  1089. C:\Users\Qwerty\AppData\Local\Temp\prp\sqb.exe
  1090. C:\Users\Qwerty\RegSvcs.exe
  1091.  
  1092.  
  1093. ==================== Bamital & volsnap ======================
  1094.  
  1095. (There is no automatic fix for files that do not pass verification.)
  1096.  
  1097. C:\Windows\system32\winlogon.exe => File is digitally signed
  1098. C:\Windows\system32\wininit.exe => File is digitally signed
  1099. C:\Windows\SysWOW64\wininit.exe => File is digitally signed
  1100. C:\Windows\explorer.exe => File is digitally signed
  1101. C:\Windows\SysWOW64\explorer.exe => File is digitally signed
  1102. C:\Windows\system32\svchost.exe => File is digitally signed
  1103. C:\Windows\SysWOW64\svchost.exe => File is digitally signed
  1104. C:\Windows\system32\services.exe => File is digitally signed
  1105. C:\Windows\system32\User32.dll => File is digitally signed
  1106. C:\Windows\SysWOW64\User32.dll => File is digitally signed
  1107. C:\Windows\system32\userinit.exe => File is digitally signed
  1108. C:\Windows\SysWOW64\userinit.exe => File is digitally signed
  1109. C:\Windows\system32\rpcss.dll => File is digitally signed
  1110. C:\Windows\system32\dnsapi.dll => File is digitally signed
  1111. C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
  1112. C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
  1113.  
  1114. LastRegBack: 2017-07-02 19:06
  1115.  
  1116. ==================== End of FRST.txt ============================[/spoiler]
  1117. Addition
  1118. [spoiler]Additional scan result of Farbar Recovery Scan Tool (x64) Version: 08-07-2017
  1119. Ran by Qwerty (09-07-2017 16:33:58)
  1120. Running from C:\Users\Qwerty\Downloads
  1121. Windows 7 Ultimate Service Pack 1 (X64) (2017-05-12 20:00:17)
  1122. Boot Mode: Normal
  1123. ==========================================================
  1124.  
  1125.  
  1126. ==================== Accounts: =============================
  1127.  
  1128. Administrator (S-1-5-21-3858528921-1604397686-3684385761-500 - Administrator - Disabled)
  1129. Guest (S-1-5-21-3858528921-1604397686-3684385761-501 - Limited - Disabled)
  1130. HomeGroupUser$ (S-1-5-21-3858528921-1604397686-3684385761-1002 - Limited - Enabled)
  1131. Qwerty (S-1-5-21-3858528921-1604397686-3684385761-1000 - Administrator - Enabled) => C:\Users\Qwerty
  1132.  
  1133. ==================== Security Center ========================
  1134.  
  1135. (If an entry is included in the fixlist, it will be removed.)
  1136.  
  1137. AV: Avast Antivirus (Enabled - Up to date) {8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF}
  1138. AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
  1139. AS: Avast Antivirus (Enabled - Up to date) {35C973AA-9ABB-D3CA-B100-B0DC0E5F2402}
  1140.  
  1141. ==================== Installed Programs ======================
  1142.  
  1143. (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
  1144.  
  1145. µTorrent (HKLM-x32\...\uTorrent) (Version: 2.2.1 - )
  1146. 7-Zip 16.04 (x64) (HKLM\...\7-Zip) (Version: 16.04 - Igor Pavlov)
  1147. Action! (HKLM-x32\...\Mirillis Action!) (Version: 2.3.0 - Mirillis)
  1148. AIMP (HKLM-x32\...\AIMP) (Version: v4.13.1895, 07.05.2017 - AIMP DevTeam)
  1149. Andy OS (HKLM\...\Andy OS) (Version: 46.16 - Andy OS, Inc)
  1150. Apple Application Support (32-bit) (HKLM-x32\...\{E92BB800-BCC5-4C25-8102-AC2C3B7C7C1E}) (Version: 5.5 - Apple Inc.)
  1151. Apple Application Support (64-bit) (HKLM\...\{9C912B1E-06DD-43EF-BB2B-45CB2C88BAAE}) (Version: 5.5 - Apple Inc.)
  1152. Apple Mobile Device Support (HKLM\...\{0A596141-97D5-45FA-9281-98DFAF48D579}) (Version: 10.3.2.3 - Apple Inc.)
  1153. Apple Software Update (HKLM-x32\...\{52D87F32-70E4-4348-8148-C0B9F35B1314}) (Version: 2.3.0.177 - Apple Inc.)
  1154. Application Insights Tools for Visual Studio 2015 (HKLM-x32\...\{D25C9EDD-984F-444C-9229-5A58130C6B10}) (Version: 4.3.60226.3 - Microsoft Corporation)
  1155. Armagetron Advanced 0.2.8.3.4.gcc (HKLM-x32\...\Armagetron Advanced) (Version: 0.2.8.3.4.gcc - Armagetron Advanced Team)
  1156. Avast Free Antivirus (HKLM-x32\...\Avast Antivirus) (Version: 17.5.2302 - AVAST Software)
  1157. Azure AD Authentication Connected Service (HKLM-x32\...\{3FEAC561-1CF6-41D6-B0F3-BECDD9C88A1B}) (Version: 14.0.23107 - Microsoft Corporation) Hidden
  1158. AzureTools.Notifications (HKLM-x32\...\{1E5CA362-39B6-4BD0-B9C0-69CF15F0FEA2}) (Version: 2.7.30611.1601 - Microsoft Corporation) Hidden
  1159. Bandicam (HKLM-x32\...\Bandicam) (Version: 3.4.2.1258 - Bandicam.com)
  1160. Bandicam MPEG-1 Decoder (HKLM-x32\...\BandiMPEG1) (Version: - Bandicam.com)
  1161. Blend for Visual Studio SDK for .NET 4.5 (HKLM-x32\...\{37E53780-3944-4A6A-842F-727128E8616E}) (Version: 3.0.40218.0 - Microsoft Corporation) Hidden
  1162. Bochs 2.6.9 (remove only) (HKLM-x32\...\Bochs 2.6.9) (Version: 2.6.9 - The Bochs Project)
  1163. Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
  1164. Bully - Scholarship Edition (HKLM-x32\...\Bully - Scholarship Edition_is1) (Version: - )
  1165. Burnout Paradise - The Ultimate Box (HKLM-x32\...\Burnout Paradise - The Ultimate Box_is1) (Version: - )
  1166. Camtasia 9 (HKLM\...\{1D09B594-C8B5-4CF1-B927-41D9A487799C}) (Version: 9.0.5.2021 - TechSmith Corporation) Hidden
  1167. Camtasia 9 (HKLM-x32\...\{00ce4b8c-0138-4743-b0b8-379b2715eb44}) (Version: 9.0.5.2021 - TechSmith Corporation)
  1168. Camtasia 9 9.0.5.2021 (HKLM-x32\...\Camtasia 9 9.0.5.2021) (Version: 9.0.5.2021 - TechSmith Corporation)
  1169. Carmageddon 2 Carpocalypse Now (HKLM-x32\...\1207659963_is1) (Version: 2.1.0.28 - GOG.com)
  1170. Carmageddon TDR2000 "MAX-Pack" (HKLM-x32\...\Carmageddon TDR2000 "MAX-Pack") (Version: - )
  1171. Carmageddon TDR2000 (HKLM-x32\...\{204752E6-4202-11D4-8586-0050DA635DCF}) (Version: - )
  1172. CCleaner (HKLM\...\CCleaner) (Version: 5.31 - Piriform)
  1173. CDBurnerXP (HKLM-x32\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.5.7.6623 - CDBurnerXP)
  1174. Citra Edge (HKU\S-1-5-21-3858528921-1604397686-3684385761-1000\...\citra) (Version: 0.1.405 - Citra Development Team)
  1175. Core FTP LE (x64) (HKLM-x32\...\CoreFTP(x64)) (Version: - )
  1176. Crashday (HKLM-x32\...\{9C27ADE1-EAFB-4BB7-9FE3-5DD9BA9A3DD2}) (Version: 0 - ATARI)
  1177. DAEMON Tools Lite (HKLM\...\DAEMON Tools Lite) (Version: 10.5.1.0232 - Disc Soft Ltd)
  1178. Defraggler (HKLM\...\Defraggler) (Version: 2.21 - Piriform)
  1179. DigiByte Core (64-bit) (HKU\S-1-5-21-3858528921-1604397686-3684385761-1000\...\DigiByte Core (64-bit)) (Version: 6.14.2 - DigiByte Core project)
  1180. Dotfuscator and Analytics Community Edition 5.19.0 (HKLM-x32\...\{4C5B1DD0-7E8E-4972-9247-818E6D030552}) (Version: 5.19.0.2930 - PreEmptive Solutions) Hidden
  1181. EmEditor (64-bit) (HKLM\...\{59737FF5-4FCB-432B-A573-A58FB12DEE13}) (Version: 16.9.3 - Emurasoft, Inc.)
  1182. Entity Framework 6.1.3 Tools for Visual Studio 2015 Update 1 (HKLM-x32\...\{2A56910C-69C8-495D-8ED8-9080F0A14E58}) (Version: 14.0.41103.0 - Microsoft Corporation)
  1183. Exact Audio Copy 1.3 (HKLM-x32\...\Exact Audio Copy) (Version: 1.3 - Andre Wiethoff)
  1184. FileZilla Client 3.25.2 (HKLM-x32\...\FileZilla Client) (Version: 3.25.2 - Tim Kosse)
  1185. Fraps (remove only) (HKLM-x32\...\Fraps) (Version: - )
  1186. Gajim (HKLM-x32\...\Gajim) (Version: 0.16.7 - )
  1187. Glary Utilities 5.79 (HKLM-x32\...\Glary Utilities 5) (Version: 5.79.0.100 - Glarysoft Ltd)
  1188. Google Chrome (HKLM-x32\...\Google Chrome) (Version: 59.0.3071.115 - Google Inc.)
  1189. Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.5 - Google Inc.) Hidden
  1190. GrabIt 1.7.4 Beta 2 (build 1014) (HKLM-x32\...\GrabIt_is1) (Version: - Ilan Shemes)
  1191. Hotspot Shield 6.20.31 (HKLM-x32\...\{91992aa0-fd97-42e1-b9d1-5ce98771560d}) (Version: 6.20.31.9929 - AnchorFree Inc.)
  1192. Hotspot Shield 6.20.31 (HKLM-x32\...\{AF599C42-A2E5-4251-B7EE-4925B26899EC}) (Version: 6.20.31.9929 - AnchorFree Inc.) Hidden
  1193. Hotspot Shield 6.20.31 (HKLM-x32\...\HotspotShield) (Version: 6.20.31 - AnchorFree Inc.) Hidden
  1194. HP USB Disk Storage Format Tool (HKLM-x32\...\{0E0DF90C-D0BA-4C89-9262-AD78D1A3DE51}) (Version: - )
  1195. iExplorer (HKU\S-1-5-21-3858528921-1604397686-3684385761-1000\...\2ee35ebaf226322a) (Version: 4.1.5.0 - Macroplant LLC)
  1196. iFunbox (v4.0.4106.1352) (HKLM-x32\...\iFunbox_is1) (Version: v4.0.4106.1352 - iFunbox DevTeam)
  1197. IIS 10.0 Express (HKLM\...\{7A28A2B0-458B-4A58-84AC-C90D2D4B79FB}) (Version: 10.0.1735 - Microsoft Corporation)
  1198. IIS Express Application Compatibility Database for x64 (HKLM\...\{08274920-8908-45c2-9258-8ad67ff77b09}.sdb) (Version: - )
  1199. IIS Express Application Compatibility Database for x86 (HKLM\...\{ad846bae-d44b-4722-abad-f7420e08bcd9}.sdb) (Version: - )
  1200. IMVU Avatar Chat Software (HKU\S-1-5-21-3858528921-1604397686-3684385761-1000\...\IMVU Avatar chat client software BETA) (Version: - )
  1201. Intel(R) Chipset Device Software (HKLM-x32\...\{49bc1e38-39b4-4728-9e75-cbe67ba9a329}) (Version: 10.1.1.42 - Intel(R) Corporation) Hidden
  1202. Intel(R) OpenCL CPU Runtime (HKLM-x32\...\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: - Intel Corporation)
  1203. Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.4425 - Intel Corporation)
  1204. Intel® Hardware Accelerated Execution Manager (HKLM\...\{557D160E-2085-4D38-BDA3-1D5D3F74A3A4}) (Version: 6.0.4 - Intel Corporation)
  1205. iTunes (HKLM\...\{F0C7385A-9D20-45F3-8101-05D383885180}) (Version: 12.6.1.25 - Apple Inc.)
  1206. Java 8 Update 131 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F64180131F0}) (Version: 8.0.1310.11 - Oracle Corporation)
  1207. Java 8 Update 131 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180131F0}) (Version: 8.0.1310.11 - Oracle Corporation)
  1208. Keysticks (HKLM-x32\...\{0CA309CD-E575-4066-9DB5-EDCB331F32EF}) (Version: 1.9 - Keysticks.net)
  1209. Kodi (HKU\S-1-5-21-3858528921-1604397686-3684385761-1000\...\Kodi) (Version: - XBMC-Foundation)
  1210. LoiLo Game Recorder (HKLM\...\{89E4163C-BD19-45A9-BCEB-980741786799}_is1) (Version: 1.1.0.1 - LoiLo inc.)
  1211. LoiLoScope 2 (HKLM-x32\...\{CAB75FFC-2377-4B95-A8FA-C9234B812A92}_is1) (Version: 2.5.4.2 - LoiLo inc)
  1212. Malwarebytes version 3.1.2.1733 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.1.2.1733 - Malwarebytes)
  1213. Microsoft .NET Framework 4 Multi-Targeting Pack (HKLM-x32\...\{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}) (Version: 4.0.30319 - Microsoft Corporation)
  1214. Microsoft .NET Framework 4.5 Multi-Targeting Pack (HKLM-x32\...\{56E962F0-4FB0-3C67-88DB-9EAA6EEFC493}) (Version: 4.5.50710 - Microsoft Corporation)
  1215. Microsoft .NET Framework 4.5.1 Multi-Targeting Pack (ENU) (HKLM-x32\...\{D3517C62-68A5-37CF-92F7-93C029A89681}) (Version: 4.5.50932 - Microsoft Corporation)
  1216. Microsoft .NET Framework 4.5.1 Multi-Targeting Pack (HKLM-x32\...\{6A0C6700-EA93-372C-8871-DCCF13D160A4}) (Version: 4.5.50932 - Microsoft Corporation)
  1217. Microsoft .NET Framework 4.5.1 SDK (HKLM-x32\...\{19A5926D-66E1-46FC-854D-163AA10A52D3}) (Version: 4.5.51641 - Microsoft Corporation)
  1218. Microsoft .NET Framework 4.5.2 Multi-Targeting Pack (ENU) (HKLM-x32\...\{290FC320-2F5A-329E-8840-C4193BD7A9EE}) (Version: 4.5.51209 - Microsoft Corporation)
  1219. Microsoft .NET Framework 4.5.2 Multi-Targeting Pack (HKLM-x32\...\{19E8AE59-4D4A-3534-B567-6CC08FA4102E}) (Version: 4.5.51651 - Microsoft Corporation)
  1220. Microsoft .NET Framework 4.6 SDK (HKLM-x32\...\{B5915D37-0637-4A26-A3AA-C5DC9F856370}) (Version: 4.6.00081 - Microsoft Corporation)
  1221. Microsoft .NET Framework 4.6 Targeting Pack (ENU) (HKLM-x32\...\{034547E9-D8FA-49E7-8B9C-4C9861FB9146}) (Version: 4.6.00127 - Microsoft Corporation)
  1222. Microsoft .NET Framework 4.6 Targeting Pack (HKLM-x32\...\{2CC6A4A7-AAC2-46C9-9DBB-3727B5954F65}) (Version: 4.6.00081 - Microsoft Corporation)
  1223. Microsoft .NET Framework 4.6.1 SDK (HKLM-x32\...\{2F0ECC80-B9E4-4485-8083-CD32F22ABD92}) (Version: 4.6.01055 - Microsoft Corporation)
  1224. Microsoft .NET Framework 4.6.1 Targeting Pack (ENU) (HKLM-x32\...\{8EEB28EE-5141-411C-9CF0-9952264FE4AF}) (Version: 4.6.01055 - Microsoft Corporation)
  1225. Microsoft .NET Framework 4.6.1 Targeting Pack (HKLM-x32\...\{8BC3EEC9-090F-4C53-A8DA-1BEC913040F9}) (Version: 4.6.01055 - Microsoft Corporation)
  1226. Microsoft .NET Framework 4.7 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.7.02053 - Microsoft Corporation)
  1227. Microsoft .NET Version Manager (x64) 1.0.0-beta5 (HKLM\...\{c5a4aba3-1aba-3ef8-b2d5-c3fa37f59738}) (Version: 1.0.10609.0 - Microsoft Corporation)
  1228. Microsoft Chart Controls for Microsoft .NET Framework 3.5 (KB2500170) (HKLM-x32\...\{41785C66-90F2-40CE-8CB5-1C94BFC97280}) (Version: 3.5.30730.0 - Microsoft Corporation)
  1229. Microsoft Help Viewer 1.0 (HKLM\...\Microsoft Help Viewer 1.0) (Version: 1.0.30319 - Microsoft Corporation)
  1230. Microsoft Help Viewer 2.2 (HKLM-x32\...\Microsoft Help Viewer 2.2) (Version: 2.2.24720 - Microsoft Corporation)
  1231. Microsoft Silverlight (HKLM-x32\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.20513.0 - Microsoft Corporation)
  1232. Microsoft SQL Server 2008 (64-bit) (HKLM\...\Microsoft SQL Server 10 Release) (Version: - Microsoft Corporation)
  1233. Microsoft SQL Server 2008 Browser (HKLM-x32\...\{C688457E-03FD-4941-923B-A27F4D42A7DD}) (Version: 10.1.2531.0 - Microsoft Corporation)
  1234. Microsoft SQL Server 2008 Native Client (HKLM\...\{BBDE8A3D-64A2-43A6-95F3-C27B87DF7AC1}) (Version: 10.1.2531.0 - Microsoft Corporation)
  1235. Microsoft SQL Server 2008 R2 Management Objects (HKLM-x32\...\{4E968D9C-21A7-4915-B698-F7AEB913541D}) (Version: 10.50.1447.4 - Microsoft Corporation)
  1236. Microsoft SQL Server 2008 Setup Support Files (HKLM\...\{B40EE88B-400A-4266-A17B-E3DE64E94431}) (Version: 10.1.2731.0 - Microsoft Corporation)
  1237. Microsoft SQL Server 2012 Command Line Utilities (HKLM\...\{9D573E71-1077-4C7E-B4DB-4E22A5D2B48B}) (Version: 11.0.2100.60 - Microsoft Corporation)
  1238. Microsoft SQL Server 2012 Native Client (HKLM\...\{49D665A2-4C2A-476E-9AB8-FCC425F526FC}) (Version: 11.0.2100.60 - Microsoft Corporation)
  1239. Microsoft SQL Server 2014 Express LocalDB (HKLM\...\{AB8DE9BA-19E1-446A-BCFA-6B3DA9751E21}) (Version: 12.0.2000.8 - Microsoft Corporation)
  1240. Microsoft SQL Server 2014 Management Objects (HKLM-x32\...\{2774595F-BC2A-4B12-A25B-0C37A37049B0}) (Version: 12.0.2000.8 - Microsoft Corporation)
  1241. Microsoft SQL Server 2014 Management Objects (x64) (HKLM\...\{1F9EB3B6-AED7-4AA7-B8F1-8E314B74B2A5}) (Version: 12.0.2000.8 - Microsoft Corporation)
  1242. Microsoft SQL Server 2014 Transact-SQL ScriptDom (HKLM\...\{020CDFE0-C127-4047-B571-37C82396B662}) (Version: 12.0.2000.8 - Microsoft Corporation)
  1243. Microsoft SQL Server 2014 T-SQL Language Service (HKLM-x32\...\{47D08E7A-92A1-489B-B0BF-415516497BCE}) (Version: 12.0.2000.8 - Microsoft Corporation)
  1244. Microsoft SQL Server Compact 3.5 SP2 ENU (HKLM-x32\...\{3A9FC03D-C685-4831-94CF-4EDFD3749497}) (Version: 3.5.8080.0 - Microsoft Corporation)
  1245. Microsoft SQL Server Compact 3.5 SP2 x64 ENU (HKLM\...\{D4AD39AD-091E-4D33-BB2B-59F6FCB8ADC3}) (Version: 3.5.8080.0 - Microsoft Corporation)
  1246. Microsoft SQL Server Compact 4.0 SP1 x64 ENU (HKLM\...\{78909610-D229-459C-A936-25D92283D3FD}) (Version: 4.0.8876.1 - Microsoft Corporation)
  1247. Microsoft SQL Server Data Tools - enu (14.0.50616.0) (HKLM-x32\...\{58246C80-3941-4B69-AE31-264644E2ADB8}) (Version: 14.0.50616.0 - Microsoft Corporation)
  1248. Microsoft SQL Server System CLR Types (HKLM-x32\...\{2A2F3AE8-246A-4252-BB26-1BEB45627074}) (Version: 10.50.1447.4 - Microsoft Corporation)
  1249. Microsoft SQL Server VSS Writer (HKLM\...\{0826F9E4-787E-481D-83E0-BC6A57B056D5}) (Version: 10.1.2531.0 - Microsoft Corporation)
  1250. Microsoft System CLR Types for SQL Server 2014 (HKLM\...\{FC3BB979-AA54-4B60-BBA3-2C4DA6E08D80}) (Version: 12.0.2402.29 - Microsoft Corporation)
  1251. Microsoft System CLR Types for SQL Server 2014 (HKLM-x32\...\{091CE6AA-2753-4F6E-AD1C-0E875744EB54}) (Version: 12.0.2402.29 - Microsoft Corporation)
  1252. Microsoft Visual Basic 2010 Express - ENU (HKLM-x32\...\Microsoft Visual Basic 2010 Express - ENU) (Version: 10.0.30319 - Microsoft Corporation)
  1253. Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
  1254. Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
  1255. Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
  1256. Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
  1257. Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
  1258. Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4974 (HKLM-x32\...\{B7E38540-E355-3503-AFD7-635B2F2F76E1}) (Version: 9.0.30729.4974 - Microsoft Corporation)
  1259. Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
  1260. Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
  1261. Microsoft Visual C++ 2010 x64 Runtime - 10.0.30319 (HKLM\...\{94D70749-4281-39AC-AD90-B56A0E0A402E}) (Version: 10.0.30319 - Microsoft Corporation)
  1262. Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
  1263. Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
  1264. Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation)
  1265. Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
  1266. Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\...\{7f51bdb9-ee21-49ee-94d6-90afc321780e}) (Version: 12.0.21005.1 - Microsoft Corporation)
  1267. Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
  1268. Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.40660 (HKLM-x32\...\{ef6b00ec-13e1-4c25-9064-b2f383cb8412}) (Version: 12.0.40660.0 - Microsoft Corporation)
  1269. Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation)
  1270. Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
  1271. Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.40660 (HKLM-x32\...\{61087a79-ac85-455c-934d-1fa22cc64f36}) (Version: 12.0.40660.0 - Microsoft Corporation)
  1272. Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23506 (HKLM-x32\...\{3ee5e5bb-b7cc-4556-8861-a00a82977d6c}) (Version: 14.0.23506.0 - Microsoft Corporation)
  1273. Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation)
  1274. Microsoft Visual Studio 2010 ADO.NET Entity Framework Tools (HKLM-x32\...\{14DD7530-CCD2-3798-B37D-3839ED6A441C}) (Version: 10.0.30319 - Microsoft Corporation)
  1275. Microsoft Visual Studio 2010 Express Prerequisites x64 - ENU (HKLM\...\{BCA26999-EC22-3007-BB79-638913079C9A}) (Version: 10.0.30319 - Microsoft Corporation)
  1276. Microsoft Visual Studio Enterprise 2015 with Updates (HKLM-x32\...\{f90e9ec5-977b-4752-8518-abe39dac065d}) (Version: 14.0.24720.41 - Microsoft Corporation)
  1277. Microsoft Web Deploy 3.6 (HKLM\...\{ED4CC1E5-043E-4157-8452-B5E533FE2BA1}) (Version: 3.1238.1955 - Microsoft Corporation)
  1278. Mozilla Firefox 54.0.1 (x86 en-GB) (HKLM-x32\...\Mozilla Firefox 54.0.1 (x86 en-GB)) (Version: 54.0.1 - Mozilla)
  1279. Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 53.0.3 - Mozilla)
  1280. MSBuild/NuGet Integration 14.0 (x86) (HKLM-x32\...\{FA0599C5-C083-41BE-8AEA-E8EB9070D128}) (Version: 14.0.24720 - Microsoft Corporation) Hidden
  1281. Multi-Device Hybrid Apps using C# - Templates - ENU (HKLM-x32\...\{12D99739-FFD3-3761-8AA6-F929E0FE407E}) (Version: 14.0.23107 - Microsoft Corporation) Hidden
  1282. MusicBrainz Picard (HKLM-x32\...\MusicBrainz Picard) (Version: 1.4.2 - MusicBrainz)
  1283. NETGEAR A6210 Genie (HKLM-x32\...\{24352157-CF75-4215-A0B5-3AF01F78CB0A}) (Version: 36.0.0.0 - NETGEAR) Hidden
  1284. NETGEAR A6210 Genie (HKLM-x32\...\InstallShield_{24352157-CF75-4215-A0B5-3AF01F78CB0A}) (Version: 36.0.0.0 - NETGEAR)
  1285. NewsBin Pro (HKLM\...\NewsBin5-64) (Version: 5.54 - DJI Interprises, LLC)
  1286. NVIDIA PhysX (HKLM-x32\...\{8B922CF8-8A6C-41CE-A858-F1755D7F5D29}) (Version: 9.12.1031 - NVIDIA Corporation)
  1287. OBS Studio (HKLM-x32\...\OBS Studio) (Version: 19.0.3 - OBS Project)
  1288. OpenIV (HKU\S-1-5-21-3858528921-1604397686-3684385761-1000\...\OpenIV) (Version: 2.9.906 - .black/OpenIV Team)
  1289. OpenVPN 2.3.12-I602 (HKLM-x32\...\OpenVPN) (Version: 2.3.12-I602 - )
  1290. Oracle VM VirtualBox 5.1.22 (HKLM\...\{8D5E4D4D-5E0C-4448-B018-5DDEF1E208D9}) (Version: 5.1.22 - Oracle Corporation)
  1291. PAYDAY 2 (HKLM\...\Steam App 218620) (Version: - OVERKILL - a Starbreeze Studio.)
  1292. PCSX2 - Playstation 2 Emulator (HKLM-x32\...\pcsx2) (Version: - )
  1293. Pidgin (HKLM-x32\...\Pidgin) (Version: 2.12.0 - )
  1294. pidgin-otr 4.0.2 (HKLM-x32\...\pidgin-otr) (Version: 4.0.2 - Cypherpunks CA)
  1295. PreEmptive Analytics Visual Studio Components (HKLM-x32\...\{436A18DD-5F2C-4B3C-985E-AD3C13B0CC25}) (Version: 1.2.5134.1 - PreEmptive Solutions) Hidden
  1296. Prerequisites for SSDT (HKLM-x32\...\{21373064-AD95-48DB-A32E-0D9E08EF7355}) (Version: 12.0.2000.8 - Microsoft Corporation)
  1297. PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.992 - Even Balance, Inc.)
  1298. Python 3.5.2 (32-bit) (HKU\S-1-5-21-3858528921-1604397686-3684385761-1000\...\{cf72a2ab-2f1d-49fd-a0d7-1065e6357e1e}) (Version: 3.5.2150.0 - Python Software Foundation)
  1299. Python 3.5.2 Core Interpreter (32-bit) (HKLM-x32\...\{EB0611B2-7F10-4D97-BCF2-DCAAB1199498}) (Version: 3.5.2150.0 - Python Software Foundation) Hidden
  1300. Python 3.5.2 Development Libraries (32-bit) (HKLM-x32\...\{5DB2183B-62D3-407F-BBC1-EAD2F36283FA}) (Version: 3.5.2150.0 - Python Software Foundation) Hidden
  1301. Python 3.5.2 Documentation (32-bit) (HKLM-x32\...\{1FBA5182-78DD-4940-9F06-96E5042B7061}) (Version: 3.5.2150.0 - Python Software Foundation) Hidden
  1302. Python 3.5.2 Executables (32-bit) (HKLM-x32\...\{33B10015-A9B1-4210-B50A-26C6443979B0}) (Version: 3.5.2150.0 - Python Software Foundation) Hidden
  1303. Python 3.5.2 pip Bootstrap (32-bit) (HKLM-x32\...\{9ADF9987-3327-48C6-91B3-B10900366491}) (Version: 3.5.2150.0 - Python Software Foundation) Hidden
  1304. Python 3.5.2 Standard Library (32-bit) (HKLM-x32\...\{FCBB04F4-D2CF-4F55-BE92-B3898696B318}) (Version: 3.5.2150.0 - Python Software Foundation) Hidden
  1305. Python 3.5.2 Tcl/Tk Support (32-bit) (HKLM-x32\...\{C1153533-FDC4-4922-892D-B71810F69566}) (Version: 3.5.2150.0 - Python Software Foundation) Hidden
  1306. Python 3.5.2 Test Suite (32-bit) (HKLM-x32\...\{9D50A6D7-410A-4469-87B7-35FA84CBD479}) (Version: 3.5.2150.0 - Python Software Foundation) Hidden
  1307. Python 3.5.2 Utility Scripts (32-bit) (HKLM-x32\...\{E6DEBF43-7ACF-4E88-9BBF-9B5945683281}) (Version: 3.5.2150.0 - Python Software Foundation) Hidden
  1308. Python 3.6.1 (32-bit) (HKU\S-1-5-21-3858528921-1604397686-3684385761-1000\...\{1babc3bc-6a32-44f7-bf4d-60eec36c9ad1}) (Version: 3.6.1150.0 - Python Software Foundation)
  1309. Python 3.6.1 Core Interpreter (32-bit) (HKLM-x32\...\{E63E60CA-437B-4894-8395-81F2F66483B0}) (Version: 3.6.1150.0 - Python Software Foundation) Hidden
  1310. Python 3.6.1 Development Libraries (32-bit) (HKLM-x32\...\{3029D656-0C32-4AC9-84FB-A15056F356CC}) (Version: 3.6.1150.0 - Python Software Foundation) Hidden
  1311. Python 3.6.1 Documentation (32-bit) (HKLM-x32\...\{D1198C40-C6F5-4FFB-B98C-79BF1FE706C1}) (Version: 3.6.1150.0 - Python Software Foundation) Hidden
  1312. Python 3.6.1 Executables (32-bit) (HKLM-x32\...\{A7036382-80F1-4FC1-B244-D31AA50337F4}) (Version: 3.6.1150.0 - Python Software Foundation) Hidden
  1313. Python 3.6.1 pip Bootstrap (32-bit) (HKLM-x32\...\{899F7F28-F6D3-4E5B-8FBE-F7929036172A}) (Version: 3.6.1150.0 - Python Software Foundation) Hidden
  1314. Python 3.6.1 Standard Library (32-bit) (HKLM-x32\...\{3BCCB89B-CD98-4F78-8436-78847FABFD68}) (Version: 3.6.1150.0 - Python Software Foundation) Hidden
  1315. Python 3.6.1 Tcl/Tk Support (32-bit) (HKLM-x32\...\{F6ED0771-FE83-4A1C-BE65-A06CB65B46D5}) (Version: 3.6.1150.0 - Python Software Foundation) Hidden
  1316. Python 3.6.1 Test Suite (32-bit) (HKLM-x32\...\{F44EF183-905E-48BB-998E-53FC99B36FE3}) (Version: 3.6.1150.0 - Python Software Foundation) Hidden
  1317. Python 3.6.1 Utility Scripts (32-bit) (HKLM-x32\...\{2AA7DAB3-6778-42A7-9F33-22615234540E}) (Version: 3.6.1150.0 - Python Software Foundation) Hidden
  1318. Python Launcher (HKLM-x32\...\{323AC113-C6CE-4F99-842F-4936332D055A}) (Version: 3.6.5923.0 - Python Software Foundation)
  1319. qBittorrent 3.3.12 (HKLM-x32\...\qBittorrent) (Version: 3.3.12 - The qBittorrent project)
  1320. Qemu Manager 7.0 (HKLM-x32\...\Qemu Manager 7.0 - Qemu 0.11.1_is1) (Version: - David T Reynolds)
  1321. Qualcomm Atheros Bluetooth Suite (64) (HKLM\...\{A84A4FB1-D703-48DB-89E0-68B6499D2801}) (Version: 8.0.1.306 - Qualcomm Atheros Communications)
  1322. QuickPar 0.9 (HKLM-x32\...\QuickPar) (Version: 0.9 - Peter B. Clements)
  1323. Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.50.1123.2011 - Realtek)
  1324. Recordit version 0.2 (HKLM-x32\...\{F41ECB1B-8749-4F80-8335-B0A68A8F76EF}_is1) (Version: 0.2 - Freshout)
  1325. ReiBoot (HKLM-x32\...\ReiBoot) (Version: - Tenorshare, Inc.)
  1326. Rocket League (HKLM\...\Steam App 252950) (Version: - Psyonix, Inc.)
  1327. Rockstar Games Social Club (HKLM-x32\...\Rockstar Games Social Club) (Version: 1.2.1.9 - Rockstar Games)
  1328. Roslyn Language Services - x86 (HKLM-x32\...\{3107684C-8011-3031-BD28-10CA30F58267}) (Version: 14.0.24730 - Microsoft Corporation) Hidden
  1329. Roslyn Language Services - x86 (HKLM-x32\...\{6C1985E7-E1C5-3A95-86EF-2C62465F15C3}) (Version: 14.0.23107 - Microsoft Corporation) Hidden
  1330. SABnzbd 2.1.0 (HKLM-x32\...\SABnzbd) (Version: 2.1.0 - The SABnzbd Team)
  1331. Service Pack 1 for SQL Server 2008 (KB968369) (64-bit) (HKLM\...\KB968369) (Version: 10.1.2531.0 - Microsoft Corporation)
  1332. Skype™ 7.38 (HKLM-x32\...\{3B7E914A-93D5-4A29-92BB-AF8C3F66C431}) (Version: 7.38.101 - Skype Technologies S.A.)
  1333. SlimDX Runtime .NET 4.0 x86 (January 2012) (HKLM-x32\...\{7EBD0E43-6AC0-4CA8-9990-00E50069AD29}) (Version: 2.0.13.43 - SlimDX Group)
  1334. SmartPixel (HKLM-x32\...\SmartPixel) (Version: 3.2.0.0 - Beyond Magic Limited)
  1335. Spotify (HKU\S-1-5-21-3858528921-1604397686-3684385761-1000\...\Spotify) (Version: 1.0.57.474.gca9c9538 - Spotify AB)
  1336. Sql Server Customer Experience Improvement Program (HKLM\...\{2F14965D-567B-4E59-ADEB-0A2CC1E3ADDF}) (Version: 10.1.2531.0 - Microsoft Corporation) Hidden
  1337. Stardock WindowBlinds (HKLM-x32\...\Stardock WindowBlinds) (Version: 10.50 - Stardock Software, Inc.)
  1338. Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
  1339. TAP-Windows 9.21.2 (HKLM\...\TAP-Windows) (Version: 9.21.2 - )
  1340. Team Explorer for Microsoft Visual Studio 2015 (HKLM-x32\...\{48992F68-BEE6-35D8-89AC-6A81406F1096}) (Version: 14.0.24712 - Microsoft Corporation) Hidden
  1341. TeamViewer 12 (HKLM-x32\...\TeamViewer) (Version: 12.0.78716 - TeamViewer)
  1342. Test Tools for Microsoft Visual Studio 2015 (HKLM-x32\...\{9EABBFE1-7EED-47D9-8FB8-21D7E4808057}) (Version: 14.0.23107 - Microsoft Corporation) Hidden
  1343. The Simpsons - Hit & Run (HKLM-x32\...\The Simpsons - Hit & Run_R.G. Mechanics_is1) (Version: - R.G. Mechanics, markfiter)
  1344. Tixati (HKLM-x32\...\tixati) (Version: - )
  1345. Trillian (HKLM-x32\...\Trillian) (Version: - Cerulean Studios, LLC)
  1346. TVMOBiLi (HKLM-x32\...\TVMOBiLi) (Version: - )
  1347. TypeScript Power Tool (HKLM-x32\...\{CF436B98-B0FE-447F-8E46-68E0B14FDDE0}) (Version: 1.7.6.0 - Microsoft Corporation) Hidden
  1348. TypeScript Tools for Microsoft Visual Studio 2015 (HKLM-x32\...\{F66F9C2A-E14B-4D30-82C5-A4E32B569286}) (Version: 1.7.6.0 - Microsoft Corporation) Hidden
  1349. TypeScript Tools for Microsoft Visual Studio 2015 1.7.6.0 (HKLM-x32\...\{5ee9a47a-3630-4016-b76d-dc752e9218dd}) (Version: 1.7.24809.0 - Microsoft Corporation)
  1350. Universal CRT Extension SDK (HKLM-x32\...\{1FBCBC17-4527-2340-0832-B1D49C41FF67}) (Version: 10.0.26624 - Microsoft Corporation) Hidden
  1351. Universal CRT Extension SDK (HKLM-x32\...\{284FA9A0-CEDD-81D3-5A19-5858E95FD0C4}) (Version: 10.0.10150 - Microsoft Corporation) Hidden
  1352. Universal CRT Headers Libraries and Sources (HKLM-x32\...\{8BFBEC30-33CC-13B4-849F-3B036F27466A}) (Version: 10.0.26624 - Microsoft Corporation) Hidden
  1353. Universal CRT Headers Libraries and Sources (HKLM-x32\...\{ABD37F71-FC3F-F525-C7B3-BDD95F684C51}) (Version: 10.0.10150 - Microsoft Corporation) Hidden
  1354. Universal CRT Redistributable (HKLM-x32\...\{0460C87B-7F4C-3170-FAC9-B7A6AE5CE4E9}) (Version: 10.0.26624 - Microsoft Corporation) Hidden
  1355. Universal CRT Tools x64 (HKLM\...\{33952D66-D503-10CA-DD8E-E365C15EB4E0}) (Version: 10.0.26624 - Microsoft Corporation) Hidden
  1356. Universal CRT Tools x86 (HKLM-x32\...\{B048B812-32DE-3474-FA64-223B6A63AD47}) (Version: 10.0.26624 - Microsoft Corporation) Hidden
  1357. Uplay (HKLM-x32\...\Uplay) (Version: 32.1 - Ubisoft)
  1358. VEGAS Pro 14.0 (64-bit) (HKLM\...\{F7773180-1A27-11E7-864D-C2A106E0D44C}) (Version: 14.0.252 - VEGAS)
  1359. VEGAS Windows Installer Preloader 1.0 Build 61 (HKLM-x32\...\VEGAS Windows Installer Preloader 1.0 Build 61) (Version: 1.0 Build 61 - MAGIX Computer Products Intl. Co.)
  1360. VeraCrypt (HKLM-x32\...\VeraCrypt) (Version: 1.19 - IDRIX)
  1361. Visual Studio 2010 Tools for SQL Server Compact 3.5 SP2 ENU (HKLM-x32\...\{112C23F2-C036-4D40-BED4-0CB47BF5555C}) (Version: 4.0.8080.0 - Microsoft Corporation)
  1362. Visual Studio 2015 Update 1 (KB3022398) (HKLM-x32\...\{fcaa9dba-9438-48b6-ad91-4e9b4cc7084a}) (Version: 14.0.24720 - Microsoft Corporation)
  1363. VLC media player (HKLM\...\VLC media player) (Version: 2.2.6 - VideoLAN)
  1364. VMware VIX (HKLM-x32\...\{F99FC179-EA67-4BBC-8955-BDDA0CB94B88}) (Version: 1.15.6.00000 - VMware, Inc.)
  1365. VMware Workstation (HKLM\...\{8EB66999-8E67-44D1-A8E3-EC44739C22A9}) (Version: 12.5.6 - VMware, Inc.)
  1366. VMware Workstation (HKLM\...\{F4C0A853-FA3B-4404-954B-799299EB5A98}) (Version: 12.1.1 - VMware, Inc.)
  1367. Volume2 1.1.5 (HKLM-x32\...\Volume2) (Version: 1.1.5 - Alexandr Irza)
  1368. VS Update core components (HKLM-x32\...\{5F7870A1-0586-313E-A9FF-3249DCE9F63A}) (Version: 14.0.24720 - Microsoft Corporation) Hidden
  1369. Vysor (HKU\S-1-5-21-3858528921-1604397686-3684385761-1000\...\Vysor) (Version: 1.7.3 - ClockworkMod)
  1370. Wallpaper Engine (HKLM\...\Steam App 431960) (Version: - Kristjan Skutta)
  1371. WALTR2 version 2.0.21 (HKLM\...\{D20DE4FE-1FCF-4EB1-BFCA-9DA69A80D739}_is1) (Version: 2.0.21 - Softorino, Inc.)
  1372. WCF Data Services 5.6.4 Runtime (HKLM-x32\...\{DB85E7BD-B2DD-43D4-B3C0-23D7B527B597}) (Version: 5.6.62175.4 - Microsoft Corporation) Hidden
  1373. WCF Data Services Tools for Microsoft Visual Studio 2015 (HKLM-x32\...\{0A3B508E-5638-4471-BCC9-954E1868CB86}) (Version: 5.6.62175.4 - Microsoft Corporation) Hidden
  1374. WiFiCreator 12.0 (HKLM-x32\...\{B340C957-0624-48C4-A9D9-BEC0572806C6}_is1) (Version: - TRUE Software)
  1375. Winamp (HKLM-x32\...\Winamp) (Version: 5.666 - Nullsoft, Inc)
  1376.  
  1377. ==================== Custom CLSID (Whitelisted): ==========================
  1378.  
  1379. (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
  1380.  
  1381. CustomCLSID: HKU\S-1-5-21-3858528921-1604397686-3684385761-1000_Classes\CLSID\{00020420-0000-0000-C000-000000000046}\InprocServer32 -> C:\Windows\system32\oleaut32.dll (Microsoft Corporation)
  1382. CustomCLSID: HKU\S-1-5-21-3858528921-1604397686-3684385761-1000_Classes\CLSID\{00020421-0000-0000-C000-000000000046}\InprocServer32 -> C:\Windows\system32\oleaut32.dll (Microsoft Corporation)
  1383. CustomCLSID: HKU\S-1-5-21-3858528921-1604397686-3684385761-1000_Classes\CLSID\{00020422-0000-0000-C000-000000000046}\InprocServer32 -> C:\Windows\system32\oleaut32.dll (Microsoft Corporation)
  1384. CustomCLSID: HKU\S-1-5-21-3858528921-1604397686-3684385761-1000_Classes\CLSID\{00020423-0000-0000-C000-000000000046}\InprocServer32 -> C:\Windows\system32\oleaut32.dll (Microsoft Corporation)
  1385. CustomCLSID: HKU\S-1-5-21-3858528921-1604397686-3684385761-1000_Classes\CLSID\{00020424-0000-0000-C000-000000000046}\InprocServer32 -> C:\Windows\system32\oleaut32.dll (Microsoft Corporation)
  1386. CustomCLSID: HKU\S-1-5-21-3858528921-1604397686-3684385761-1000_Classes\CLSID\{00020425-0000-0000-C000-000000000046}\InprocServer32 -> C:\Windows\system32\oleaut32.dll (Microsoft Corporation)
  1387. CustomCLSID: HKU\S-1-5-21-3858528921-1604397686-3684385761-1000_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\Windows\system32\igfxEM.exe (Intel Corporation)
  1388. CustomCLSID: HKU\S-1-5-21-3858528921-1604397686-3684385761-1000_Classes\CLSID\{D4D48C93-BDC7-4E76-B530-2E4D13B0150F}\InprocServer32 -> C:\Users\Qwerty\AppData\Local\Programs\EmEditor\emedshl64.dll (Emurasoft, Inc.)
  1389. CustomCLSID: HKU\S-1-5-21-3858528921-1604397686-3684385761-1000_Classes\CLSID\{DFA0CC7F-D36B-47D1-8EF5-415C1DA53F57}\InprocServer32 -> C:\Users\Qwerty\AppData\Local\Programs\EmEditor\emedshl64.dll (Emurasoft, Inc.)
  1390. ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-07-02] (AVAST Software)
  1391. ContextMenuHandlers01: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2016-10-04] (Igor Pavlov)
  1392. ContextMenuHandlers01: [AIMP] -> {1F77B17B-F531-44DB-ACA4-76ABB5010A28} => C:\Program Files (x86)\AIMP\System\aimp_menu64.dll [2017-05-23] (AIMP DevTeam)
  1393. ContextMenuHandlers01: [Atheros] -> {B8952421-0E55-400B-94A6-FA858FC0A39F} => C:\Program Files (x86)\Bluetooth Suite\BtvAppExt.dll [2013-09-25] (Qualcomm®Atheros®)
  1394. ContextMenuHandlers01: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-07-02] (AVAST Software)
  1395. ContextMenuHandlers01: [DefragglerShellExtension] -> {4380C993-0C43-4E02-9A7A-0D40B6EA7590} => C:\Program Files\Defraggler\DefragglerShell64.dll [2016-03-08] (Piriform Ltd)
  1396. ContextMenuHandlers01: [Glary Utilities] -> {B3C418F8-922B-4faf-915E-59BC14448CF7} => C:\Program Files (x86)\Glary Utilities 5\x64\ContextHandler.dll [2016-06-23] (Glarysoft Ltd)
  1397. ContextMenuHandlers02: [Glary Utilities] -> {B3C418F8-922B-4faf-915E-59BC14448CF7} => C:\Program Files (x86)\Glary Utilities 5\x64\ContextHandler.dll [2016-06-23] (Glarysoft Ltd)
  1398. ContextMenuHandlers02: [VMDiskMenuHandler] -> {271DC252-6FE1-4D59-9053-E4CF50AB99DE} => -> No File
  1399. ContextMenuHandlers02: [VMDiskMenuHandler64] -> {E4D28EDC-8C0B-43EE-9E7D-C8A8682334DC} => C:\Program Files (x86)\VMware\VMware Workstation\x64\vmdkShellExt64.dll [2016-04-14] (VMware, Inc.)
  1400. ContextMenuHandlers03: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-07-02] (AVAST Software)
  1401. ContextMenuHandlers03: [FTShellContext] -> {AFF81F7B-6942-40c4-AADA-7214EF7B6DD1} => C:\Program Files (x86)\Bluetooth Suite\ShellContextExt.dll [2013-09-25] (Qualcomm®Atheros®)
  1402. ContextMenuHandlers03: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-05-09] (Malwarebytes)
  1403. ContextMenuHandlers04: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2016-10-04] (Igor Pavlov)
  1404. ContextMenuHandlers04: [AIMP] -> {1F77B17B-F531-44DB-ACA4-76ABB5010A28} => C:\Program Files (x86)\AIMP\System\aimp_menu64.dll [2017-05-23] (AIMP DevTeam)
  1405. ContextMenuHandlers05: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => C:\Windows\system32\igfxpph.dll -> No File
  1406. ContextMenuHandlers05: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\Windows\system32\igfxDTCM.dll [2016-05-12] (Intel Corporation)
  1407. ContextMenuHandlers06: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2016-10-04] (Igor Pavlov)
  1408. ContextMenuHandlers06: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-07-02] (AVAST Software)
  1409. ContextMenuHandlers06: [DefragglerShellExtension] -> {4380C993-0C43-4E02-9A7A-0D40B6EA7590} => C:\Program Files\Defraggler\DefragglerShell64.dll [2016-03-08] (Piriform Ltd)
  1410. ContextMenuHandlers06: [Glary Utilities] -> {B3C418F8-922B-4faf-915E-59BC14448CF7} => C:\Program Files (x86)\Glary Utilities 5\x64\ContextHandler.dll [2016-06-23] (Glarysoft Ltd)
  1411. ContextMenuHandlers06: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-05-09] (Malwarebytes)
  1412. ContextMenuHandlers1_S-1-5-21-3858528921-1604397686-3684385761-1000: [EmEditor] -> {D4D48C93-BDC7-4E76-B530-2E4D13B0150F} => C:\Users\Qwerty\AppData\Local\Programs\EmEditor\emedshl64.dll [2017-06-14] (Emurasoft, Inc.)
  1413. ContextMenuHandlers2_S-1-5-21-3858528921-1604397686-3684385761-1000: [EmEditor] -> {D4D48C93-BDC7-4E76-B530-2E4D13B0150F} => C:\Users\Qwerty\AppData\Local\Programs\EmEditor\emedshl64.dll [2017-06-14] (Emurasoft, Inc.)
  1414. ContextMenuHandlers4_S-1-5-21-3858528921-1604397686-3684385761-1000: [EmEditor] -> {D4D48C93-BDC7-4E76-B530-2E4D13B0150F} => C:\Users\Qwerty\AppData\Local\Programs\EmEditor\emedshl64.dll [2017-06-14] (Emurasoft, Inc.)
  1415.  
  1416. ==================== Scheduled Tasks (Whitelisted) =============
  1417.  
  1418. (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
  1419.  
  1420. Task: {3D352A1B-B5CB-4A9F-A3CB-F18EF8DE55BC} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-05-12] (Google Inc.)
  1421. Task: {40396F22-A2D9-4C22-847E-EAEB76C89DD8} - System32\Tasks\BitX Updater Service => C:\Program Files (x86)\BitX\BitXUpdaterService.exe
  1422. Task: {4F074223-4282-4B85-A05C-360F37B6E3B7} - System32\Tasks\yiyu => C:\Users\Qwerty\yiyu\pknwghsz.exe [2016-10-09] (AutoIt Team)
  1423. Task: {685FE978-2166-49F0-9F23-54AC85E5742D} - System32\Tasks\Avast Emergency Update => C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe [2017-07-02] (AVAST Software)
  1424. Task: {7BFBC287-0B5D-47CA-B5D5-419A25268BAD} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-05-12] (Google Inc.)
  1425. Task: {88FAE977-B0E1-433F-9E77-2DB7597F7CCB} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2017-02-14] (Apple Inc.)
  1426. Task: {BAC4C8BF-37A2-4322-A3DB-A5AA91E0D7AE} - System32\Tasks\GlaryInitialize 5 => C:\Program Files (x86)\Glary Utilities 5\Initialize.exe [2017-06-30] (Glarysoft Ltd)
  1427. Task: {C669528C-C6FC-4F47-B2F8-E66759D89162} - System32\Tasks\BitX => C:\Program Files (x86)\BitX\BitXSplash.exe
  1428. Task: {DB3E6498-C5E7-49D8-9A42-268E740D33ED} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2017-06-13] (Piriform Ltd)
  1429.  
  1430. (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
  1431.  
  1432.  
  1433. ==================== Shortcuts & WMI ========================
  1434.  
  1435. (The entries could be listed to be restored or removed.)
  1436.  
  1437.  
  1438. ShortcutWithArgument: C:\Users\Qwerty\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\AllCast Receiver.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=hjbljnpdahefgnopeohlaeohgkiidnoe
  1439. ShortcutWithArgument: C:\Users\Qwerty\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Blockchain.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=glaohkkooicollgefkkmndjcbblominl
  1440. ShortcutWithArgument: C:\Users\Qwerty\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Chrome Remote Desktop.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=gbchcmhmhahfdphkhkmpfmihenigjmpp
  1441. ShortcutWithArgument: C:\Users\Qwerty\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\FireRTC.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=iaamfpbohecgihgnbhmppgekdjkbolah
  1442. ShortcutWithArgument: C:\Users\Qwerty\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Cast for Education.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=bnmgbcehmiinmmlmepibeeflglhbhlea
  1443. ShortcutWithArgument: C:\Users\Qwerty\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Keep - notes and lists.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=hmjkmjkepdijhoojdojkdfohbdgmmhki
  1444. ShortcutWithArgument: C:\Users\Qwerty\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Play Music.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=fahmaaghhglfmonjliepjlchgpgfmobi
  1445. ShortcutWithArgument: C:\Users\Qwerty\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Netease Music.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=fogcjafchgdhdoieggbeldnckbghdpkn
  1446. ShortcutWithArgument: C:\Users\Qwerty\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\VNC® Viewer for Google Chrome™.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=iabmpiboiopbgfabjmgeedhcmjenhbla
  1447. ShortcutWithArgument: C:\Users\Qwerty\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Vysor.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=gidgenkbbabolejbgbpnhbimgjbffefm
  1448. ShortcutWithArgument: C:\Users\Qwerty\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Netease Music.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=fogcjafchgdhdoieggbeldnckbghdpkn
  1449.  
  1450. ==================== Loaded Modules (Whitelisted) ==============
  1451.  
  1452. 2017-05-09 00:44 - 2017-05-09 00:44 - 01354040 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
  1453. 2017-05-09 00:44 - 2017-05-09 00:44 - 00092472 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
  1454. 2013-09-25 03:01 - 2013-09-25 03:01 - 00086016 _____ () C:\Program Files (x86)\Bluetooth Suite\Modules\Map\MAP.dll
  1455. 2017-05-09 03:05 - 2017-05-09 03:05 - 01354040 _____ () C:\Program Files\iTunes\libxml2.dll
  1456. 2017-05-09 03:05 - 2017-05-09 03:05 - 00092472 _____ () C:\Program Files\iTunes\zlib1.dll
  1457. 2017-07-05 21:42 - 2017-07-05 21:42 - 00050688 _____ () C:\Program Files\SABnzbd\lib\_socket.pyd
  1458. 2017-07-05 21:42 - 2017-07-05 21:42 - 02100736 _____ () C:\Program Files\SABnzbd\lib\_ssl.pyd
  1459. 2017-07-05 21:42 - 2017-07-05 21:42 - 01482240 _____ () C:\Program Files\SABnzbd\lib\_hashlib.pyd
  1460. 2017-07-05 21:42 - 2017-07-05 21:42 - 00129024 _____ () C:\Program Files\SABnzbd\lib\win32api.pyd
  1461. 2017-07-05 21:42 - 2017-07-05 21:42 - 00136704 _____ () C:\Program Files\SABnzbd\lib\pywintypes27.dll
  1462. 2017-07-05 21:42 - 2017-07-05 21:42 - 00547328 _____ () C:\Program Files\SABnzbd\lib\pythoncom27.dll
  1463. 2017-07-05 21:42 - 2017-07-05 21:42 - 00120832 _____ () C:\Program Files\SABnzbd\lib\_ctypes.pyd
  1464. 2017-07-05 21:42 - 2017-07-05 21:42 - 00011776 _____ () C:\Program Files\SABnzbd\lib\select.pyd
  1465. 2017-07-05 21:42 - 2017-07-05 21:42 - 00022016 _____ () C:\Program Files\SABnzbd\lib\win32event.pyd
  1466. 2017-07-05 21:42 - 2017-07-05 21:42 - 00052736 _____ () C:\Program Files\SABnzbd\lib\win32service.pyd
  1467. 2017-07-05 21:42 - 2017-07-05 21:42 - 00064000 _____ () C:\Program Files\SABnzbd\lib\_sqlite3.pyd
  1468. 2017-07-05 21:42 - 2017-07-05 21:42 - 00785408 _____ () C:\Program Files\SABnzbd\lib\sqlite3.dll
  1469. 2017-07-05 21:42 - 2017-07-05 21:42 - 00008192 _____ () C:\Program Files\SABnzbd\lib\cryptography.hazmat.bindings._constant_time.pyd
  1470. 2017-07-05 21:42 - 2017-07-05 21:42 - 00158208 _____ () C:\Program Files\SABnzbd\lib\_cffi_backend.pyd
  1471. 2017-07-05 21:42 - 2017-07-05 21:42 - 00692224 _____ () C:\Program Files\SABnzbd\lib\unicodedata.pyd
  1472. 2017-07-05 21:42 - 2017-07-05 21:42 - 02754560 _____ () C:\Program Files\SABnzbd\lib\cryptography.hazmat.bindings._openssl.pyd
  1473. 2017-07-05 21:42 - 2017-07-05 21:42 - 00012288 _____ () C:\Program Files\SABnzbd\lib\sabyenc.pyd
  1474. 2017-07-05 21:42 - 2017-07-05 21:42 - 00044032 _____ () C:\Program Files\SABnzbd\lib\win32process.pyd
  1475. 2017-07-05 21:42 - 2017-07-05 21:42 - 00013824 _____ () C:\Program Files\SABnzbd\lib\Cheetah._namemapper.pyd
  1476. 2017-07-05 21:42 - 2017-07-05 21:42 - 00179712 _____ () C:\Program Files\SABnzbd\lib\pyexpat.pyd
  1477. 2017-07-05 21:42 - 2017-07-05 21:42 - 00092672 _____ () C:\Program Files\SABnzbd\lib\bz2.pyd
  1478. 2017-07-05 21:42 - 2017-07-05 21:42 - 00148480 _____ () C:\Program Files\SABnzbd\lib\win32file.pyd
  1479. 2017-07-05 21:42 - 2017-07-05 21:42 - 00034816 _____ () C:\Program Files\SABnzbd\lib\_multiprocessing.pyd
  1480. 2017-07-05 21:42 - 2017-07-05 21:42 - 00062976 _____ () C:\Program Files\SABnzbd\lib\win32evtlog.pyd
  1481. 2017-07-05 21:42 - 2017-07-05 21:42 - 00031232 _____ () C:\Program Files\SABnzbd\lib\servicemanager.pyd
  1482. 2017-07-05 21:42 - 2017-07-05 21:42 - 00222720 _____ () C:\Program Files\SABnzbd\lib\win32gui.pyd
  1483. 2017-07-05 21:42 - 2017-07-05 21:42 - 00392192 _____ () C:\Program Files\SABnzbd\lib\winxpgui.pyd
  1484. 2017-06-26 18:08 - 2009-08-22 19:25 - 00102400 _____ () C:\Users\Qwerty\Downloads\d3d\D3DOverrider.exe
  1485. 2013-09-25 03:09 - 2013-09-25 03:09 - 00384128 _____ () C:\Program Files (x86)\Bluetooth Suite\ContactsApi.dll
  1486. 2015-09-17 17:42 - 2015-09-17 17:42 - 00192232 _____ () C:\Program Files (x86)\NETGEAR\A6210\NetgearSwitchUSB.exe
  1487. 2017-05-26 20:08 - 2017-05-26 20:08 - 00076888 _____ () C:\Windows\SysWOW64\PnkBstrA.exe
  1488. 2017-05-26 20:08 - 2017-05-26 20:08 - 00189248 _____ () C:\Windows\SysWOW64\PnkBstrB.exe
  1489. 2015-04-20 19:01 - 2015-04-20 19:01 - 02731520 _____ () C:\Program Files (x86)\TVMOBiLi\bin\tvMobiliService.exe
  1490. 2017-06-23 21:06 - 2017-04-04 19:50 - 00102312 _____ () C:\Program Files\WALTR2\x86\WALTR2Service.exe
  1491. 2017-04-30 12:19 - 2017-04-30 12:19 - 00052392 _____ () C:\Program Files\FileZilla FTP Client\fzshellext_64.dll
  1492. 2017-07-02 12:06 - 2017-07-02 12:06 - 00162032 _____ () c:\Program Files\AVAST Software\Avast\x64\vaarclient.dll
  1493. 2017-07-02 12:06 - 2017-07-02 12:06 - 00831664 _____ () C:\Program Files\AVAST Software\Avast\x64\ffl2.dll
  1494. 2017-07-02 12:06 - 2017-07-02 12:06 - 00276808 _____ () c:\Program Files\AVAST Software\Avast\x64\StreamBack.dll
  1495. 2017-06-27 08:22 - 2017-06-23 04:21 - 03807064 _____ () C:\Program Files (x86)\Google\Chrome\Application\59.0.3071.115\libglesv2.dll
  1496. 2017-06-27 08:22 - 2017-06-23 04:21 - 00100184 _____ () C:\Program Files (x86)\Google\Chrome\Application\59.0.3071.115\libegl.dll
  1497. 2017-07-02 12:06 - 2017-07-02 12:06 - 00170224 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
  1498. 2017-07-02 12:06 - 2017-07-02 12:06 - 00192664 _____ () C:\Program Files\AVAST Software\Avast\event_routing_rpc.dll
  1499. 2017-07-02 12:06 - 2017-07-02 12:06 - 00224256 _____ () C:\Program Files\AVAST Software\Avast\tasks_core.dll
  1500. 2017-07-07 16:33 - 2017-07-07 16:33 - 05684224 _____ () C:\Program Files\AVAST Software\Avast\defs\17070700\algo.dll
  1501. 2017-07-02 12:06 - 2017-07-02 12:06 - 00689272 _____ () C:\Program Files\AVAST Software\Avast\ffl2.dll
  1502. 2017-07-02 12:06 - 2017-07-02 12:06 - 00231664 _____ () C:\Program Files\AVAST Software\Avast\streamback.dll
  1503. 2017-07-09 12:19 - 2017-07-09 12:19 - 05684224 _____ () C:\Program Files\AVAST Software\Avast\defs\17070900\algo.dll
  1504. 2017-06-28 16:37 - 2017-06-28 16:37 - 00166520 _____ () C:\Program Files (x86)\Hotspot Shield\bin\CrashRpt1403.dll
  1505. 2017-07-02 12:06 - 2017-07-02 12:06 - 01038952 _____ () C:\Program Files\AVAST Software\Avast\AvChrome.dll
  1506. 2017-07-02 12:06 - 2017-07-02 12:06 - 67109376 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
  1507. 2017-07-02 12:06 - 2017-07-02 12:08 - 02962096 _____ () C:\Program Files\AVAST Software\Avast\aswDataScan.dll
  1508. 2017-06-26 18:08 - 2009-08-22 19:25 - 00032768 _____ () C:\Users\Qwerty\Downloads\d3d\D3DOverriderHooks.dll
  1509. 2017-05-12 21:28 - 2017-05-17 02:54 - 00678176 _____ () C:\Program Files (x86)\Steam\SDL2.dll
  1510. 2017-05-12 21:28 - 2016-09-01 02:02 - 04969248 _____ () C:\Program Files (x86)\Steam\v8.dll
  1511. 2017-05-12 21:28 - 2016-09-01 02:02 - 01563936 _____ () C:\Program Files (x86)\Steam\icui18n.dll
  1512. 2017-05-12 21:28 - 2016-09-01 02:02 - 01195296 _____ () C:\Program Files (x86)\Steam\icuuc.dll
  1513. 2017-05-12 21:28 - 2017-06-08 06:42 - 02485536 _____ () C:\Program Files (x86)\Steam\video.dll
  1514. 2017-05-12 21:28 - 2016-01-27 08:49 - 02549760 _____ () C:\Program Files (x86)\Steam\libavcodec-56.dll
  1515. 2017-05-12 21:28 - 2016-01-27 08:49 - 00442880 _____ () C:\Program Files (x86)\Steam\libavutil-54.dll
  1516. 2017-05-12 21:28 - 2016-01-27 08:49 - 00491008 _____ () C:\Program Files (x86)\Steam\libavformat-56.dll
  1517. 2017-05-12 21:28 - 2016-01-27 08:49 - 00332800 _____ () C:\Program Files (x86)\Steam\libavresample-2.dll
  1518. 2017-05-12 21:28 - 2016-01-27 08:49 - 00485888 _____ () C:\Program Files (x86)\Steam\libswscale-3.dll
  1519. 2017-05-12 21:28 - 2017-06-08 06:42 - 00877856 _____ () C:\Program Files (x86)\Steam\bin\chromehtml.DLL
  1520. 2017-05-12 21:28 - 2016-07-04 23:17 - 00266560 _____ () C:\Program Files (x86)\Steam\openvr_api.dll
  1521. 2017-06-20 11:28 - 2017-06-20 11:28 - 01997792 ____R () C:\Program Files (x86)\Skype\Phone\skypert.dll
  1522. 2015-05-27 00:00 - 2015-05-27 00:00 - 00059904 _____ () C:\Program Files (x86)\Trillian56\zlib1.dll
  1523. 2015-05-27 00:00 - 2015-05-27 00:00 - 00187392 _____ () C:\Program Files (x86)\Trillian56\libpng15.dll
  1524. 2015-05-27 00:00 - 2015-05-27 00:00 - 00006656 _____ () c:\program files (x86)\trillian56\languages\en\trillian.dll
  1525. 2015-05-27 00:00 - 2015-05-27 00:00 - 00065536 _____ () C:\Program Files (x86)\Trillian56\libungif.dll
  1526. 2015-05-27 00:00 - 2015-05-27 00:00 - 00003584 _____ () c:\program files (x86)\trillian56\languages\en\toolkit.dll
  1527. 2015-05-27 00:00 - 2015-05-27 00:00 - 00006656 _____ () c:\program files (x86)\trillian56\languages\en\events.dll
  1528. 2015-05-27 00:00 - 2015-05-27 00:00 - 00010752 _____ () c:\program files (x86)\trillian56\languages\en\buddy.dll
  1529. 2015-05-27 00:00 - 2015-05-27 00:00 - 00007168 _____ () c:\program files (x86)\trillian56\languages\en\talk.dll
  1530. 2017-06-26 18:08 - 2009-08-22 19:25 - 00057344 _____ () C:\Users\Qwerty\Downloads\d3d\RTFC.dll
  1531. 2017-06-26 18:08 - 2009-08-22 19:25 - 00106496 _____ () C:\Users\Qwerty\Downloads\d3d\RTUI.dll
  1532. 2017-05-12 21:32 - 2017-05-08 20:45 - 69516064 _____ () C:\Program Files (x86)\Steam\bin\cef\cef.win7\libcef.dll
  1533. 2017-06-08 07:21 - 2017-05-17 02:54 - 00678176 _____ () C:\Program Files (x86)\Steam\bin\cef\cef.win7\SDL2.dll
  1534. 2017-05-12 21:28 - 2017-06-08 06:42 - 00385312 _____ () C:\Program Files (x86)\Steam\steam.dll
  1535. 2016-04-14 17:16 - 2016-04-14 17:16 - 01309768 _____ () C:\Program Files (x86)\VMware\VMware Workstation\libxml2.dll
  1536.  
  1537. ==================== Alternate Data Streams (Whitelisted) =========
  1538.  
  1539. (If an entry is included in the fixlist, only the ADS will be removed.)
  1540.  
  1541.  
  1542. ==================== Safe Mode (Whitelisted) ===================
  1543.  
  1544. (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
  1545.  
  1546. HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot => "AlternateShell"=""
  1547. HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
  1548. HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
  1549.  
  1550. ==================== Association (Whitelisted) ===============
  1551.  
  1552. (If an entry is included in the fixlist, the registry item will be restored to default or removed.)
  1553.  
  1554.  
  1555. ==================== Internet Explorer trusted/restricted ===============
  1556.  
  1557. (If an entry is included in the fixlist, it will be removed from the registry.)
  1558.  
  1559. IE trusted site: HKU\S-1-5-21-3858528921-1604397686-3684385761-1000\...\localhost -> hxxps://localhost
  1560.  
  1561. ==================== Hosts content: ==========================
  1562.  
  1563. (If needed Hosts: directive could be included in the fixlist to reset Hosts.)
  1564.  
  1565. 2009-07-14 03:34 - 2017-07-09 15:26 - 00002026 _____ C:\Windows\system32\Drivers\etc\hosts
  1566.  
  1567. 0.0.0.0 pubads.g.doubleclick.net
  1568. 0.0.0.0 securepubads.g.doubleclick.net
  1569. 0.0.0.0 www.googletagservices.com
  1570. 0.0.0.0 gads.pubmatic.com
  1571. 0.0.0.0 ads.pubmatic.com
  1572. 0.0.0.0 spclient.wg.spotify.com0.0.0.0 anchorfree.net
  1573. 0.0.0.0 rss2search.com
  1574. 0.0.0.0 techbrowsing.com
  1575. 0.0.0.0 box.anchorfree.net
  1576. 0.0.0.0 www.mefeedia.com
  1577. 0.0.0.0 www.anchorfree.net
  1578. 0.0.0.0 www.mefeedia.com
  1579. 0.0.0.0 anchorfree.us
  1580. 0.0.0.0 a433.com
  1581. 0.0.0.0 anchorfree.net
  1582. 0.0.0.0 rpt.anchorfree.net
  1583. 0.0.0.0 delivery.anchorfree.us/land.php
  1584. 0.0.0.0 hsselite.com
  1585. 0.0.0.0 www.hsselite.com
  1586. 127.0.0.1 bandicam.com
  1587. 127.0.0.1 ssl.bandisoft.com
  1588. 0.0.0.0 activation.cloud.techsmith.com
  1589. 0.0.0.0 assets.cloud.techsmith.com
  1590. 0.0.0.0 camtasiatudi.techsmith.com
  1591. 0.0.0.0 oscount.techsmith.com
  1592. 0.0.0.0 tsccloud.cloudapp.net
  1593. 0.0.0.0 updater.techsmith.com
  1594. 127.0.0.1 camtasiatudio.techsmith.com
  1595. 127.0.0.1 updater.techsmith.com
  1596. 127.0.0.1 activation.cloud.techsmith.com
  1597.  
  1598. There are 8 more lines.
  1599.  
  1600.  
  1601. ==================== Other Areas ============================
  1602.  
  1603. (Currently there is no automatic fix for this section.)
  1604.  
  1605. HKU\S-1-5-21-3858528921-1604397686-3684385761-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Qwerty\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
  1606. DNS Servers: 212.50.160.100 - 213.249.130.100
  1607. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 0)
  1608. Windows Firewall is disabled.
  1609.  
  1610. ==================== MSCONFIG/TASK MANAGER disabled items ==
  1611.  
  1612. MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HandyAndy.lnk => C:\Windows\pss\HandyAndy.lnk.CommonStartup
  1613. MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^NETGEAR A6210 Genie.lnk => C:\Windows\pss\NETGEAR A6210 Genie.lnk.CommonStartup
  1614. MSCONFIG\startupfolder: C:^Users^Qwerty^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^EmEditor.lnk => C:\Windows\pss\EmEditor.lnk.Startup
  1615. MSCONFIG\startupfolder: C:^Users^Qwerty^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Gajim.lnk => C:\Windows\pss\Gajim.lnk.Startup
  1616. MSCONFIG\startupfolder: C:^Users^Qwerty^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Recordit.lnk => C:\Windows\pss\Recordit.lnk.Startup
  1617. MSCONFIG\startupreg: A6210 => C:\Program Files (x86)\NETGEAR\A6210\A6210.EXE
  1618. MSCONFIG\startupreg: BlueStacks Agent => C:\Program Files (x86)\BlueStacks\HD-Agent.exe
  1619. MSCONFIG\startupreg: CCleaner Monitoring => "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
  1620. MSCONFIG\startupreg: DAEMON Tools Lite Automount => "C:\Program Files\DAEMON Tools Lite\DTAgent.exe" -autorun
  1621. MSCONFIG\startupreg: eM Client => "C:\Program Files (x86)\eM Client\MailClient.exe" /startup
  1622. MSCONFIG\startupreg: iFunBox => C:\Program Files (x86)\i-Funbox DevTeam\iFunBox_x64.exe /tray
  1623. MSCONFIG\startupreg: PhoenixGUI => C:\Users\Qwerty\AppData\Local\PhoenixGUI\Phoenix.exe
  1624. MSCONFIG\startupreg: Spotify => "C:\Users\Qwerty\AppData\Roaming\Spotify\Spotify.exe" -autostart -minimized
  1625. MSCONFIG\startupreg: Spotify Web Helper => "C:\Users\Qwerty\AppData\Roaming\Spotify\SpotifyWebHelper.exe"
  1626. MSCONFIG\startupreg: vmware-tray.exe => "C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe"
  1627.  
  1628. ==================== FirewallRules (Whitelisted) ===============
  1629.  
  1630. (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
  1631.  
  1632. FirewallRules: [{C4903444-0E02-4A31-B5F0-BAF62E01E693}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
  1633. FirewallRules: [{22DEC15E-3660-4DD9-B9DE-FC3CF7F00301}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
  1634. FirewallRules: [{F380D474-637B-4473-BE88-E757B31202E1}] => (Allow) C:\Program Files (x86)\qBittorrent\qbittorrent.exe
  1635. FirewallRules: [{26A18437-F312-4659-B314-0550B6D2D4A3}] => (Allow) C:\Program Files (x86)\qBittorrent\qbittorrent.exe
  1636. FirewallRules: [{2233777A-66E4-4E66-B792-CDCDE5D84488}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
  1637. FirewallRules: [{C7AF6831-7F32-4F79-BDF3-D1B280B12D00}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
  1638. FirewallRules: [{0A2849AE-6604-497B-BDC4-06EE9E8709BB}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
  1639. FirewallRules: [TCP Query User{88F01FC7-55C2-445E-BF43-9B4EB761E1EF}C:\program files (x86)\kodi\kodi.exe] => (Allow) C:\program files (x86)\kodi\kodi.exe
  1640. FirewallRules: [UDP Query User{C9B78D5F-AED5-45DF-B181-EAE33FEA1569}C:\program files (x86)\kodi\kodi.exe] => (Allow) C:\program files (x86)\kodi\kodi.exe
  1641. FirewallRules: [TCP Query User{872D7D0E-B3FC-4E29-A3CE-22113799839A}C:\users\qwerty\documents\screw dc\dcrat\darkcomet.exe] => (Allow) C:\users\qwerty\documents\screw dc\dcrat\darkcomet.exe
  1642. FirewallRules: [UDP Query User{0DBF3274-B6C7-41CC-A83C-37D6DBEAA351}C:\users\qwerty\documents\screw dc\dcrat\darkcomet.exe] => (Allow) C:\users\qwerty\documents\screw dc\dcrat\darkcomet.exe
  1643. FirewallRules: [TCP Query User{DA988D9F-C5B6-4384-BE4F-ED03B863BD21}C:\users\qwerty\documents\screwdc\dcrat\darkcomet.exe] => (Allow) C:\users\qwerty\documents\screwdc\dcrat\darkcomet.exe
  1644. FirewallRules: [UDP Query User{F73C7A99-BA24-425D-89CC-090A0AA97705}C:\users\qwerty\documents\screwdc\dcrat\darkcomet.exe] => (Allow) C:\users\qwerty\documents\screwdc\dcrat\darkcomet.exe
  1645. FirewallRules: [{CF1A9301-8079-4E17-898A-4BF28E5D5829}] => (Allow) C:\Program Files (x86)\Microsoft Visual Studio 14.0\Common7\IDE\devenv.exe
  1646. FirewallRules: [{9DC3B2DB-B8CE-4439-9208-2728B6A9EFB2}] => (Allow) C:\Program Files (x86)\Microsoft Visual Studio 14.0\Common7\IDE\devenv.exe
  1647. FirewallRules: [{BFE5080E-4BBC-4A45-941C-60D0304598E6}] => (Allow) C:\Program Files (x86)\Microsoft Visual Studio 14.0\Common7\IDE\devenv.exe
  1648. FirewallRules: [{D1076C8D-98DE-4EBA-B6C7-22BFD1F8AA2E}] => (Allow) C:\Program Files (x86)\Microsoft Visual Studio 14.0\Common7\IDE\devenv.exe
  1649. FirewallRules: [{18F10BA5-539A-43AC-9648-231B63E4E950}] => (Allow) C:\Program Files (x86)\Microsoft Visual Studio 14.0\Common7\IDE\devenv.exe
  1650. FirewallRules: [{89AF590D-66EF-4E3C-BAFA-12E9E23F31DF}] => (Allow) C:\Program Files (x86)\Microsoft Visual Studio 14.0\Common7\IDE\devenv.exe
  1651. FirewallRules: [{34ABD6D1-2EE4-44F1-8D73-F05BEA8E0243}] => (Allow) C:\Program Files (x86)\Microsoft Visual Studio 14.0\Common7\IDE\devenv.exe
  1652. FirewallRules: [TCP Query User{B58FDB47-5AB0-49FB-85E9-0455CD8DFE97}C:\program files\java\jre1.8.0_131\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_131\bin\javaw.exe
  1653. FirewallRules: [UDP Query User{854A9604-585A-4C3E-8F44-3552373D7410}C:\program files\java\jre1.8.0_131\bin\javaw.exe] => (Allow) C:\program files\java\jre1.8.0_131\bin\javaw.exe
  1654. FirewallRules: [TCP Query User{D43C214D-9E00-4FDB-BB69-C4EFC45F6362}M:\rats\r4t\jrat-v0.7d\njrat v0.7d.exe] => (Allow) M:\rats\r4t\jrat-v0.7d\njrat v0.7d.exe
  1655. FirewallRules: [UDP Query User{6E92F67B-3A03-4E51-9553-31959C470C82}M:\rats\r4t\jrat-v0.7d\njrat v0.7d.exe] => (Allow) M:\rats\r4t\jrat-v0.7d\njrat v0.7d.exe
  1656. FirewallRules: [{A7C37E60-D010-4CCC-A9F5-6D39C746A6E8}] => (Allow) C:\Program Files (x86)\uTorrent\uTorrent.exe
  1657. FirewallRules: [{7ABE91F0-DD2F-4E7B-8C5D-98FF0B752CE8}] => (Allow) C:\Program Files (x86)\uTorrent\uTorrent.exe
  1658. FirewallRules: [{53C07590-D5E6-4447-BC4C-BBA2277FCBD2}] => (Allow) C:\Program Files (x86)\Winamp\winamp.exe
  1659. FirewallRules: [{1C1555CC-4E53-426A-A481-7CC78F82EB22}] => (Allow) C:\Program Files (x86)\Winamp\winamp.exe
  1660. FirewallRules: [{3616633F-B895-4142-A150-764C2FC35707}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\wallpaper_engine\launcher.exe
  1661. FirewallRules: [{08BEA94D-5F35-4CFC-A4E2-A515AE71E9A0}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\wallpaper_engine\launcher.exe
  1662. FirewallRules: [{5F277DA4-A598-4CF9-B9BA-A9FF373B7026}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
  1663. FirewallRules: [{EED162E1-C86E-4B44-8E4D-5F408DB8903A}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
  1664. FirewallRules: [{E5174014-0306-4F52-8C0C-1B9F982B7BD9}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
  1665. FirewallRules: [{DCD8AAA7-523A-4E27-826D-E55EFF211979}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
  1666. FirewallRules: [{3922494D-0D06-494F-907C-53AC267C0037}] => (Allow) C:\Program Files (x86)\MyHotspot\MyHotspot.exe
  1667. FirewallRules: [{2CF471D4-DFCD-407C-BDD8-0458AEDA72F1}] => (Allow) C:\Program Files (x86)\MyHotspot\MyHotspot.exe
  1668. FirewallRules: [{9771BEB8-0AB5-4661-B57A-C48C98EFCB16}] => (Allow) C:\Program Files (x86)\MyHotspot\HotspotService.exe
  1669. FirewallRules: [{375B693E-97F8-420C-AEA0-4E03E94578D6}] => (Allow) C:\Program Files (x86)\MyHotspot\HotspotService.exe
  1670. FirewallRules: [{7806F7E7-AF8B-4D96-8075-9DF5DC1F2861}] => (Allow) C:\Program Files (x86)\WiFiCreator\WiFiCreator.exe
  1671. FirewallRules: [{DF7AA68E-E04D-433F-A47B-E31863CC541B}] => (Allow) C:\Program Files (x86)\WiFiCreator\WiFiCreator.exe
  1672. FirewallRules: [{7740BB2A-F3A4-4015-9A4E-1A328FEB6BA5}] => (Allow) C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe
  1673. FirewallRules: [{F146E381-7714-48CA-B0C0-29F77709F7DC}] => (Allow) C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe
  1674. FirewallRules: [{9F8A2C34-88A6-4203-BFE9-6BF192D4C227}] => (Allow) C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe
  1675. FirewallRules: [{001B0A53-B706-4D2E-B203-773B3648AFC8}] => (Allow) C:\Program Files (x86)\VMware\VMware Workstation\vmware-hostd.exe
  1676. FirewallRules: [{168EBCFF-37FD-4E91-8A19-4171238CB558}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
  1677. FirewallRules: [{9F6F8A47-30CC-4118-8270-7BF4F2DB21EE}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
  1678. FirewallRules: [{C53F057B-2CA2-475D-BE0D-2C947B96AD0F}] => (Allow) C:\Program Files (x86)\Remotr\RemotrServer.exe
  1679. FirewallRules: [{1E87CF84-C54E-41C2-AC27-18FF30B69034}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\PAYDAY 2\payday2_win32_release.exe
  1680. FirewallRules: [{664E3AE3-1A0C-4A6F-95CE-F37BBC601203}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\PAYDAY 2\payday2_win32_release.exe
  1681. FirewallRules: [{A99C9973-C8F1-4CC8-924F-7879CAB8BB08}] => (Allow) C:\Program Files\iTunes\iTunes.exe
  1682. FirewallRules: [{640C020E-2ADD-4D4D-B63C-D7248BA2EB9A}] => (Allow) C:\Users\Qwerty\AppData\Local\Temp\andy-x64\Setup.exe
  1683. FirewallRules: [{AA2D4753-17E6-4547-9B5F-4C2E89198135}] => (Allow) C:\Users\Qwerty\AppData\Local\Temp\andy-x64\Setup.exe
  1684. FirewallRules: [{08A4B5AD-0112-482A-B655-732293AF4FC1}] => (Allow) C:\Program Files\Andy\andy.exe
  1685. FirewallRules: [{B4D79CE4-54EC-4DA0-A9DA-5AAA8B00F30B}] => (Allow) C:\Program Files\Andy\andy.exe
  1686. FirewallRules: [{839E5632-7789-443D-B57D-7E215289E592}] => (Allow) C:\Program Files\Andy\AndyConsole.exe
  1687. FirewallRules: [{EC493F75-D294-48E5-8D28-8910A3DC1756}] => (Allow) C:\Program Files\Andy\AndyConsole.exe
  1688. FirewallRules: [{4804EE0D-81AF-4E39-B822-5FA94DC73A35}] => (Allow) C:\Program Files\Andy\HandyAndy.exe
  1689. FirewallRules: [{2F926C9B-C5F0-4F23-BBD7-8DE6B140DF61}] => (Allow) C:\Program Files\Andy\HandyAndy.exe
  1690. FirewallRules: [{D7274424-ABEA-44CB-B4A6-8F2A52342E61}] => (Allow) C:\Program Files\Andy\SetupFiles\Uninstall.exe
  1691. FirewallRules: [{950EBF19-071E-459E-B3B7-E5840B3A9C41}] => (Allow) C:\Program Files\Andy\SetupFiles\Uninstall.exe
  1692. FirewallRules: [{19A605CC-875C-4B2B-BE44-6DAB9B36596E}] => (Allow) C:\Users\Qwerty\AppData\Local\Temp\RemoveTemp.exe
  1693. FirewallRules: [{0FAC1D8A-DACD-4FC6-9309-E699F2A1AC61}] => (Allow) C:\Users\Qwerty\AppData\Local\Temp\RemoveTemp.exe
  1694. FirewallRules: [{905924F9-44B7-43DE-8243-71623B2D26A6}] => (Allow) C:\Program Files\Andy\SetupFiles\VMwareCheck.exe
  1695. FirewallRules: [{205F247B-F0C1-482D-A53A-4F27E1072965}] => (Allow) C:\Program Files\Andy\SetupFiles\VMwareCheck.exe
  1696. FirewallRules: [{9B549D92-BE2D-477D-BA62-A2A82531F8C2}] => (Allow) C:\Program Files\Andy\SetupFiles\AndyDoctor.exe
  1697. FirewallRules: [{39008C39-780E-4F86-8C24-1C26BDFE2CF0}] => (Allow) C:\Program Files\Andy\SetupFiles\AndyDoctor.exe
  1698. FirewallRules: [{020081AC-95DC-41B9-903D-2B106F6646BE}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
  1699. FirewallRules: [{4A46FEA5-B989-45AB-BDCC-F8E7E92F7865}] => (Allow) C:\Program Files (x86)\TVMOBiLi\bin\tvMobiliService.exe
  1700. FirewallRules: [{FA5C20AD-6980-4D88-B74F-2EDAC18DA4B4}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
  1701. FirewallRules: [{CEDEBA3B-D73A-4A19-9B56-5F03B1935484}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
  1702. FirewallRules: [{49772EB4-B184-4E0C-9173-552E02A246F1}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
  1703. FirewallRules: [{FD39CD8A-D84D-499B-8EE3-26031606CDEF}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
  1704. FirewallRules: [{2D35755B-305D-45B3-BD49-33B069CECE97}] => (Allow) C:\Program Files\NewsBin\Newsbinpro64.exe
  1705. FirewallRules: [{E56EE37F-7A8A-4471-8E7F-A3001B6C9B26}] => (Allow) C:\Program Files\NewsBin\Newsbinpro64.exe
  1706. FirewallRules: [{8D784FC7-B792-44BE-892D-EFE1F5CD3890}] => (Allow) C:\Program Files\SABnzbd\SABnzbd.exe
  1707. FirewallRules: [{36BE2DC5-3DF4-44E1-8023-B17F7BC0BE3E}] => (Allow) C:\Program Files\SABnzbd\SABnzbd.exe
  1708. FirewallRules: [{10500EBB-D3CA-4DA8-842B-F90466D6733B}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\rocketleague\Binaries\Win32\RocketLeague.exe
  1709. FirewallRules: [{5281E602-BE50-48DE-B317-9F72697A55E5}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\rocketleague\Binaries\Win32\RocketLeague.exe
  1710. FirewallRules: [{213CF73F-50FC-4EBD-95BB-BB244B6BC69D}] => (Block) %ProgramFiles% (x86)\Mirillis\Action!\Action.exe
  1711. FirewallRules: [TCP Query User{D2F0C15C-47CE-47BD-9331-66EEAFFFA0F3}C:\smartpixel\bin\smartpixel.exe] => (Allow) C:\smartpixel\bin\smartpixel.exe
  1712. FirewallRules: [UDP Query User{B924E38C-217F-4E18-AABA-8C02D767B753}C:\smartpixel\bin\smartpixel.exe] => (Allow) C:\smartpixel\bin\smartpixel.exe
  1713. FirewallRules: [TCP Query User{CEDABA48-C015-4BCD-A26D-0C038C28F859}C:\users\qwerty\appdata\roaming\netframeworkd.exe] => (Allow) C:\users\qwerty\appdata\roaming\netframeworkd.exe
  1714. FirewallRules: [UDP Query User{3B9B7150-ACC8-4151-A263-ACFDD34CC591}C:\users\qwerty\appdata\roaming\netframeworkd.exe] => (Allow) C:\users\qwerty\appdata\roaming\netframeworkd.exe
  1715. FirewallRules: [TCP Query User{1F9D216E-6CAE-4878-99E8-99E8B08A8699}C:\program files (x86)\tvmobili\bin\itunesalbumartgenerator.exe] => (Allow) C:\program files (x86)\tvmobili\bin\itunesalbumartgenerator.exe
  1716. FirewallRules: [UDP Query User{BB76B634-DB8A-4379-913C-148F09A8DA68}C:\program files (x86)\tvmobili\bin\itunesalbumartgenerator.exe] => (Allow) C:\program files (x86)\tvmobili\bin\itunesalbumartgenerator.exe
  1717. FirewallRules: [{936DE372-1E28-40D6-8B92-FF9F49D07A79}] => (Allow) LPort=8318
  1718. FirewallRules: [{ED53AA1F-F798-4755-9A93-9BD7B313E589}] => (Block) %ProgramFiles% (x86)\TechSmith Corporation\Camtasia 9\camtasia.exe
  1719. FirewallRules: [{BE2DBCD7-F20E-4DE1-AC8D-5F04B0C9F46C}] => (Block) %ProgramFiles% (x86)\TechSmith Corporation\Camtasia 9\camtasia.exe
  1720. FirewallRules: [TCP Query User{E0BE4825-9DC5-44F0-BA60-6EE258B9A2E4}C:\program files (x86)\skype\browser\skypebrowserhost.exe] => (Allow) C:\program files (x86)\skype\browser\skypebrowserhost.exe
  1721. FirewallRules: [UDP Query User{8D2E0859-A703-4010-9304-57A47CFA41BD}C:\program files (x86)\skype\browser\skypebrowserhost.exe] => (Allow) C:\program files (x86)\skype\browser\skypebrowserhost.exe
  1722.  
  1723. ==================== Restore Points =========================
  1724.  
  1725. 09-07-2017 15:20:35 Camtasia 9
  1726.  
  1727. ==================== Faulty Device Manager Devices =============
  1728.  
  1729. Name: VMware VMCI Host Device
  1730. Description: VMware VMCI Host Device
  1731. Class Guid: {4d36e97d-e325-11ce-bfc1-08002be10318}
  1732. Manufacturer: VMware, Inc.
  1733. Service: vmci
  1734. Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31)
  1735. Resolution: Update the driver
  1736.  
  1737.  
  1738. ==================== Event log errors: =========================
  1739.  
  1740. Application errors:
  1741. ==================
  1742. Error: (07/09/2017 02:41:17 PM) (Source: Application Error) (EventID: 1000) (User: )
  1743. Description: Faulting application name: bdcam.exe, version: 3.4.2.1258, time stamp: 0x5927e449
  1744. Faulting module name: bdcam.exe, version: 3.4.2.1258, time stamp: 0x5927e449
  1745. Exception code: 0xc0000005
  1746. Fault offset: 0x0008d14d
  1747. Faulting process id: 0xa10
  1748. Faulting application start time: 0x01d2f8b9055c42ba
  1749. Faulting application path: C:\Program Files (x86)\Bandicam\bdcam.exe
  1750. Faulting module path: C:\Program Files (x86)\Bandicam\bdcam.exe
  1751. Report Id: 4814712d-64ac-11e7-a4bc-ccf8d483bb0a
  1752.  
  1753. Error: (07/09/2017 02:40:58 PM) (Source: Application Error) (EventID: 1000) (User: )
  1754. Description: Faulting application name: bdcam.exe, version: 3.4.2.1258, time stamp: 0x5927e449
  1755. Faulting module name: bdcam.exe, version: 3.4.2.1258, time stamp: 0x5927e449
  1756. Exception code: 0xc0000005
  1757. Fault offset: 0x0008d14d
  1758. Faulting process id: 0x205c
  1759. Faulting application start time: 0x01d2f8b8ea5cb3b7
  1760. Faulting application path: C:\Program Files (x86)\Bandicam\bdcam.exe
  1761. Faulting module path: C:\Program Files (x86)\Bandicam\bdcam.exe
  1762. Report Id: 3cfe733f-64ac-11e7-a4bc-ccf8d483bb0a
  1763.  
  1764. Error: (07/09/2017 02:30:58 PM) (Source: Application Error) (EventID: 1000) (User: )
  1765. Description: Faulting application name: Explorer.EXE, version: 6.1.7601.23537, time stamp: 0x57c44efe
  1766. Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
  1767. Exception code: 0xc0000005
  1768. Fault offset: 0x0000000002e60fae
  1769. Faulting process id: 0x630
  1770. Faulting application start time: 0x01d2f83fed00d4e5
  1771. Faulting application path: C:\Windows\Explorer.EXE
  1772. Faulting module path: unknown
  1773. Report Id: d6ed341d-64aa-11e7-a4bc-ccf8d483bb0a
  1774.  
  1775. Error: (07/09/2017 12:20:13 AM) (Source: Application Hang) (EventID: 1002) (User: )
  1776. Description: The program tixati.exe version 2.53.1.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
  1777.  
  1778. Process ID: e00
  1779.  
  1780. Start Time: 01d2f8401c4f8bca
  1781.  
  1782. Termination Time: 34
  1783.  
  1784. Application Path: C:\Program Files\tixati\tixati.exe
  1785.  
  1786. Report Id: f8c1f281-6433-11e7-a4bc-ccf8d483bb0a
  1787.  
  1788. Error: (07/09/2017 12:17:25 AM) (Source: WinMgmt) (EventID: 10) (User: )
  1789. Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
  1790.  
  1791. Error: (07/09/2017 12:15:53 AM) (Source: PerfNet) (EventID: 2004) (User: )
  1792. Description: Unable to open the Server service performance object. The first four bytes (DWORD) of the Data section contains the status code.
  1793.  
  1794. Error: (07/08/2017 05:24:14 PM) (Source: Application Error) (EventID: 1000) (User: )
  1795. Description: Faulting application name: Explorer.EXE, version: 6.1.7601.23537, time stamp: 0x57c44efe
  1796. Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
  1797. Exception code: 0xc0000005
  1798. Fault offset: 0x0000000003b30fae
  1799. Faulting process id: 0x608
  1800. Faulting application start time: 0x01d2f7dde699ee4f
  1801. Faulting application path: C:\Windows\Explorer.EXE
  1802. Faulting module path: unknown
  1803. Report Id: e17ac229-63f9-11e7-8a85-cae752885f08
  1804.  
  1805. Error: (07/08/2017 04:58:53 PM) (Source: Application Hang) (EventID: 1002) (User: )
  1806. Description: The program citra-qt.exe version 0.0.0.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
  1807.  
  1808. Process ID: 20dc
  1809.  
  1810. Start Time: 01d2f7ffc863563b
  1811.  
  1812. Termination Time: 11
  1813.  
  1814. Application Path: C:\Users\Qwerty\AppData\Local\citra\app-0.1.405\citra-qt.exe
  1815.  
  1816. Report Id: 54d13c68-63f6-11e7-8a85-cae752885f08
  1817.  
  1818. Error: (07/08/2017 12:35:04 PM) (Source: WinMgmt) (EventID: 10) (User: )
  1819. Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
  1820.  
  1821. Error: (07/07/2017 07:22:54 AM) (Source: WinMgmt) (EventID: 10) (User: )
  1822. Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
  1823.  
  1824.  
  1825. System errors:
  1826. =============
  1827. Error: (07/09/2017 04:35:19 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
  1828. Description: The Computer Browser service depends on the Workstation service which failed to start because of the following error:
  1829. The dependency service or group failed to start.
  1830.  
  1831. Error: (07/09/2017 04:35:19 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
  1832. Description: The Workstation service depends on the SMB 1.x MiniRedirector service which failed to start because of the following error:
  1833. The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
  1834.  
  1835. Error: (07/09/2017 04:35:19 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
  1836. Description: The Computer Browser service depends on the Workstation service which failed to start because of the following error:
  1837. The dependency service or group failed to start.
  1838.  
  1839. Error: (07/09/2017 04:35:19 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
  1840. Description: The Workstation service depends on the SMB 1.x MiniRedirector service which failed to start because of the following error:
  1841. The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
  1842.  
  1843. Error: (07/09/2017 04:35:19 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
  1844. Description: The Computer Browser service depends on the Workstation service which failed to start because of the following error:
  1845. The dependency service or group failed to start.
  1846.  
  1847. Error: (07/09/2017 04:35:19 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
  1848. Description: The Workstation service depends on the SMB 1.x MiniRedirector service which failed to start because of the following error:
  1849. The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
  1850.  
  1851. Error: (07/09/2017 04:35:19 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
  1852. Description: The Computer Browser service depends on the Workstation service which failed to start because of the following error:
  1853. The dependency service or group failed to start.
  1854.  
  1855. Error: (07/09/2017 04:35:19 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
  1856. Description: The Workstation service depends on the SMB 1.x MiniRedirector service which failed to start because of the following error:
  1857. The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
  1858.  
  1859. Error: (07/09/2017 04:35:19 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
  1860. Description: The Computer Browser service depends on the Workstation service which failed to start because of the following error:
  1861. The dependency service or group failed to start.
  1862.  
  1863. Error: (07/09/2017 04:35:19 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
  1864. Description: The Workstation service depends on the SMB 1.x MiniRedirector service which failed to start because of the following error:
  1865. The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
  1866.  
  1867.  
  1868. ==================== Memory info ===========================
  1869.  
  1870. Processor: Intel(R) Pentium(R) CPU 2020M @ 2.40GHz
  1871. Percentage of memory in use: 54%
  1872. Total physical RAM: 6039.36 MB
  1873. Available physical RAM: 2744.95 MB
  1874. Total Virtual: 12076.89 MB
  1875. Available Virtual: 8513.88 MB
  1876.  
  1877. ==================== Drives ================================
  1878.  
  1879. Drive c: () (Fixed) (Total:465.76 GB) (Free:23.91 GB) NTFS ==>[drive with boot components (obtained from BCD)]
  1880.  
  1881. ==================== MBR & Partition Table ==================
  1882.  
  1883. ========================================================
  1884. Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: C196BC2D)
  1885. Partition 1: (Active) - (Size=465.8 GB) - (Type=07 NTFS)
  1886.  
  1887. ========================================================
  1888. Disk: 1 (Size: 29.7 GB) (Disk ID: 00000000)
  1889.  
  1890. Partition: GPT.
  1891.  
  1892. ==================== End of Addition.txt ============================[/spoiler]
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement