Guest User

Scan of pc :P

a guest
Jan 16th, 2016
71
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 167.52 KB | None | 0 0
  1. Additional scan result of Farbar Recovery Scan Tool (x64) Version:10-01-2015 01
  2. Ran by AngryShadow (2016-01-16 23:11:37)
  3. Running from C:\Users\AngryShadow\Desktop
  4. Windows 10 Home (X64) (2015-12-27 14:29:02)
  5. Boot Mode: Normal
  6. ==========================================================
  7.  
  8.  
  9. ==================== Accounts: =============================
  10.  
  11. Administrator (S-1-5-21-3985454009-819291025-207730266-500 - Administrator - Disabled)
  12. AngryShadow (S-1-5-21-3985454009-819291025-207730266-1001 - Administrator - Enabled) => C:\Users\AngryShadow
  13. DefaultAccount (S-1-5-21-3985454009-819291025-207730266-503 - Limited - Disabled)
  14. Guest (S-1-5-21-3985454009-819291025-207730266-501 - Limited - Disabled)
  15.  
  16. ==================== Security Center ========================
  17.  
  18. (If an entry is included in the fixlist, it will be removed.)
  19.  
  20. AV: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
  21. AV: McAfee Anti-Virus and Anti-Spyware (Enabled - Out of date) {DA9F8ED0-D0DE-39CC-F55A-51AB4CC1B556}
  22. AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
  23. AS: McAfee Anti-Virus and Anti-Spyware (Enabled - Out of date) {61FE6F34-F6E4-3642-CFEA-6AD93746FFEB}
  24.  
  25. ==================== Installed Programs ======================
  26.  
  27. (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
  28.  
  29. µTorrent (HKU\S-1-5-21-3985454009-819291025-207730266-1001\...\uTorrent) (Version: 3.4.5.41372 - BitTorrent Inc.)
  30. Anachronox (HKLM-x32\...\Steam App 242940) (Version: - )
  31. Assassin's Creed Syndicate (HKLM-x32\...\Steam App 368500) (Version: - Ubisoft Quebec, in collaboration with Ubisoft Annecy, Bucharest, Kiev, Montreal, Montpellier, Shanghai, Singapore, Sofia, Toronto studios)
  32. Assassin's Creed® III (HKLM-x32\...\Steam App 208480) (Version: - Ubisoft Montreal)
  33. Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment)
  34. Bermuda (HKLM-x32\...\Steam App 337630) (Version: - InvertMouse)
  35. Call of Duty: Ghosts - Multiplayer (HKLM-x32\...\Steam App 209170) (Version: - Infinity Ward)
  36. Call of Duty: Ghosts (HKLM-x32\...\Steam App 209160) (Version: - Infinity Ward)
  37. Call of Duty: Modern Warfare 2 - Multiplayer (HKLM-x32\...\Steam App 10190) (Version: - Infinity Ward)
  38. Call of Duty: Modern Warfare 2 (HKLM-x32\...\Steam App 10180) (Version: - Infinity Ward)
  39. Call of Duty: Modern Warfare 3 - Multiplayer (HKLM-x32\...\Steam App 42690) (Version: - Infinity Ward)
  40. Call of Duty: Modern Warfare 3 (HKLM-x32\...\Steam App 42680) (Version: - Infinity Ward)
  41. City Car Driving Home Edition (HKLM\...\Q2l0eUNhckRyaXZpbmc=_is1) (Version: 1 - )
  42. Command and Conquer: Red Alert 3 (HKLM-x32\...\Steam App 17480) (Version: - EA Los Angeles)
  43. Counter-Strike (HKLM-x32\...\Steam App 10) (Version: - Valve)
  44. Counter-Strike: Condition Zero (HKLM-x32\...\Steam App 80) (Version: - Valve)
  45. Counter-Strike: Condition Zero Deleted Scenes (HKLM-x32\...\Steam App 100) (Version: - Valve)
  46. Counter-Strike: Global Offensive (HKLM-x32\...\Steam App 730) (Version: - Valve)
  47. Counter-Strike: Source (HKLM-x32\...\Steam App 240) (Version: - Valve)
  48. DAEMON Tools Pro (HKLM\...\DAEMON Tools Pro) (Version: 7.0.0.0555 - Disc Soft Ltd)
  49. Daikatana (HKLM-x32\...\Steam App 242980) (Version: - )
  50. Day of Defeat (HKLM-x32\...\Steam App 30) (Version: - Valve)
  51. DayZ (HKLM-x32\...\Steam App 221100) (Version: - Bohemia Interactive)
  52. Dead Effect (HKLM-x32\...\Steam App 286040) (Version: - BadFly Interactive, a.s.)
  53. Dead Island: Epidemic (HKLM-x32\...\Steam App 222900) (Version: - Stunlock Studios)
  54. Deathmatch Classic (HKLM-x32\...\Steam App 40) (Version: - Valve)
  55. Depth Hunter 2: Deep Dive (HKLM-x32\...\Steam App 248530) (Version: - Biart Company LLC)
  56. Deus Ex: Human Revolution - Director's Cut (HKLM-x32\...\Steam App 238010) (Version: - Eidos Montreal)
  57. DiRT Rally (HKLM-x32\...\Steam App 310560) (Version: - Codemasters Racing Studio)
  58. Dota 2 (HKLM-x32\...\Steam App 570) (Version: - Valve)
  59. Dota 2 Test (HKLM-x32\...\Steam App 205790) (Version: - )
  60. Dream Pinball 3D (HKLM-x32\...\Steam App 215790) (Version: - ASK Homework)
  61. Emily Wants To Play (HKLM-x32\...\Steam App 416590) (Version: - Shawn Hitchcock)
  62. Enclave (HKLM-x32\...\Steam App 253980) (Version: - Starbreeze)
  63. Euro Truck Simulator 2 (HKLM-x32\...\Steam App 227300) (Version: - SCS Software)
  64. Europa Universalis III (HKLM-x32\...\Steam App 25800) (Version: - Paradox Development Studio)
  65. Five Nights at Freddy's (HKLM-x32\...\Steam App 319510) (Version: - Scott Cawthon)
  66. FlatOut 2 (HKLM-x32\...\Steam App 2990) (Version: - Bugbear Entertainment)
  67. Flesh Eaters (HKLM-x32\...\Steam App 383580) (Version: - 16bit Nights)
  68. Garry's Mod (HKLM-x32\...\Steam App 4000) (Version: - Facepunch Studios)
  69. Glacier 3: The Meltdown (HKLM-x32\...\Steam App 267940) (Version: - Team 6 Studios)
  70. Google Chrome (HKLM-x32\...\Google Chrome) (Version: 47.0.2526.111 - Google Inc.)
  71. Google Update Helper (x32 Version: 1.3.29.1 - Google Inc.) Hidden
  72. Gorky 17 (HKLM-x32\...\Steam App 253920) (Version: - )
  73. Grand Theft Auto V (HKLM-x32\...\Steam App 271590) (Version: - Rockstar North)
  74. Grand Theft Auto: San Andreas (HKLM-x32\...\Steam App 12120) (Version: - Rockstar Games)
  75. GTA San Andreas (HKLM-x32\...\{D417C96A-FCC7-4590-A1BB-FAF73F5BC98E}) (Version: 1.00.00001 - Rockstar Games)
  76. Gyazo 3.1.6 (HKLM-x32\...\{6DB8C365-E719-4BA5-9594-10DFC244D3FD}_is1) (Version: - Nota Inc.)
  77. H1Z1 (HKLM-x32\...\Steam App 295110) (Version: - Daybreak Games)
  78. H1Z1 Test Server (HKLM-x32\...\Steam App 362300) (Version: - )
  79. Hacker Evolution - Untold (HKLM-x32\...\Steam App 70110) (Version: - exosyphen studios)
  80. Hacker Evolution (HKLM-x32\...\Steam App 70100) (Version: - exosyphen studios)
  81. Half-Life 2 (HKLM-x32\...\Steam App 220) (Version: - Valve)
  82. Half-Life 2: Deathmatch (HKLM-x32\...\Steam App 320) (Version: - Valve)
  83. Half-Life 2: Episode One (HKLM-x32\...\Steam App 380) (Version: - Valve)
  84. Half-Life 2: Episode Two (HKLM-x32\...\Steam App 420) (Version: - Valve)
  85. Half-Life 2: Lost Coast (HKLM-x32\...\Steam App 340) (Version: - Valve)
  86. Hearthstone (HKLM-x32\...\Hearthstone) (Version: - Blizzard Entertainment)
  87. Hitman 2: Silent Assassin (HKLM-x32\...\Steam App 6850) (Version: - IO Interactive)
  88. Hitman: Codename 47 (HKLM-x32\...\Steam App 6900) (Version: - IO Interactive)
  89. Insurgency (HKLM-x32\...\Steam App 222880) (Version: - New World Interactive)
  90. Just Cause 2 (HKLM-x32\...\Steam App 8190) (Version: - Avalanche Studios)
  91. Just Cause 2: Multiplayer Mod (HKLM-x32\...\Steam App 259080) (Version: - Avalanche Studios)
  92. Knights and Merchants (HKLM-x32\...\Steam App 253900) (Version: - Topware Interactive)
  93. KnightShift (HKLM-x32\...\Steam App 254060) (Version: - )
  94. Krater (HKLM-x32\...\Steam App 42170) (Version: - Fatshark)
  95. Landmark (HKLM-x32\...\Steam App 297810) (Version: - Daybreak Games)
  96. League of Legends (HKLM-x32\...\League of Legends 3.0.1) (Version: 3.0.1 - Riot Games)
  97. League of Legends (x32 Version: 3.0.1 - Riot Games) Hidden
  98. Left 4 Dead 2 (HKLM-x32\...\Steam App 550) (Version: - Valve)
  99. Left 4 Dead 2 Beta (HKLM-x32\...\Steam App 223530) (Version: - )
  100. McAfee LiveSafe - Internet Security (HKLM-x32\...\MSC) (Version: 14.0.6136 - McAfee, Inc.)
  101. Metro 2033 (HKLM-x32\...\Steam App 43110) (Version: - 4A Games)
  102. Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
  103. Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
  104. Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
  105. Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
  106. Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
  107. Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
  108. Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
  109. Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
  110. Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
  111. Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
  112. Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
  113. Microsoft XNA Framework Redistributable 4.0 Refresh (HKLM-x32\...\{D69C8EDE-BBC5-436B-8E0E-C5A6D311CF4F}) (Version: 4.0.30901.0 - Microsoft Corporation)
  114. Mini Ninjas (HKLM-x32\...\Steam App 35000) (Version: - IO Interactive)
  115. Mirror's Edge (HKLM-x32\...\Steam App 17410) (Version: - DICE)
  116. N.P.P.D. RUSH - The milk of Ultra violet (HKLM-x32\...\Steam App 270090) (Version: - Rail Slave Games)
  117. Need for Speed: Hot Pursuit (HKLM-x32\...\Steam App 47870) (Version: - Criterion Games)
  118. New kind of adventure (HKLM-x32\...\Steam App 375510) (Version: - Mint Age Studios)
  119. NVIDIA 3D Vision Controller Driver 352.65 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 352.65 - NVIDIA Corporation)
  120. NVIDIA 3D Vision Driver 361.43 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 361.43 - NVIDIA Corporation)
  121. NVIDIA GeForce Experience 2.10.0.60 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.10.0.60 - NVIDIA Corporation)
  122. NVIDIA Graphics Driver 361.43 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 361.43 - NVIDIA Corporation)
  123. NVIDIA HD Audio Driver 1.3.34.4 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.4 - NVIDIA Corporation)
  124. NVIDIA PhysX System Software 9.15.0428 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.15.0428 - NVIDIA Corporation)
  125. Oracle VM VirtualBox 5.0.12 (HKLM\...\{6F93731D-89E1-4A8F-BDA9-D104860DDB02}) (Version: 5.0.12 - Oracle Corporation)
  126. OSC Third Party Libraries (Version: 1.1 - NVIDIA Corporation) Hidden
  127. Outlast (HKLM-x32\...\Steam App 238320) (Version: - Red Barrels)
  128. PAYDAY 2 (HKLM-x32\...\Steam App 218620) (Version: - OVERKILL - a Starbreeze Studio.)
  129. PAYDAY: The Heist (HKLM-x32\...\Steam App 24240) (Version: - OVERKILL Software)
  130. Portal (HKLM-x32\...\Steam App 400) (Version: - Valve)
  131. Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7640 - Realtek Semiconductor Corp.)
  132. Ricochet (HKLM-x32\...\Steam App 60) (Version: - Valve)
  133. RollerCoaster Tycoon: Deluxe (HKLM-x32\...\Steam App 285310) (Version: - Chris Sawyer Productions)
  134. S.T.A.L.K.E.R.: Shadow of Chernobyl (HKLM-x32\...\Steam App 4500) (Version: - GSC Game World)
  135. Saints Row IV (HKLM-x32\...\Steam App 206420) (Version: - Deep Silver Volition)
  136. SHIELD Streaming (Version: 4.1.0260 - NVIDIA Corporation) Hidden
  137. SHIELD Wireless Controller Driver (Version: 2.10.0.60 - NVIDIA Corporation) Hidden
  138. Shower With Your Dad Simulator 2015: Do You Still Shower With Your Dad (HKLM-x32\...\Steam App 359050) (Version: - marbenx)
  139. Skype™ 7.17 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.17.105 - Skype Technologies S.A.)
  140. Smooth Operators (HKLM-x32\...\Steam App 262900) (Version: - Heydeck Games)
  141. Sniper Art of Victory (HKLM-x32\...\Steam App 271500) (Version: - CI Games)
  142. Sniper Ghost Warrior 2 (HKLM-x32\...\Steam App 34870) (Version: - City Interactive)
  143. Sniper: Ghost Warrior (HKLM-x32\...\Steam App 34830) (Version: - City Interactive)
  144. SpeedRunners (HKLM-x32\...\Steam App 207140) (Version: - DoubleDutch Games)
  145. Star Chronicles: Delta Quadrant (HKLM-x32\...\Steam App 383330) (Version: - Alister Software)
  146. STAR WARS™ Knights of the Old Republic™ II: The Sith Lords™ (HKLM-x32\...\Steam App 208580) (Version: - Obsidian Entertainment)
  147. Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
  148. SwiftSearch 1.10.0.27 (HKLM-x32\...\SwiftSearch_1.10.0.27) (Version: 1.10.0.27 - SwiftSearch) <==== ATTENTION
  149. Team Fortress 2 (HKLM-x32\...\Steam App 440) (Version: - Valve)
  150. TeamViewer 11 (HKLM-x32\...\TeamViewer) (Version: 11.0.53254 - TeamViewer)
  151. The Evil Within (HKLM-x32\...\Steam App 268050) (Version: - Tango Gameworks)
  152. The Tower Of Elements (HKLM-x32\...\Steam App 377310) (Version: - Wulo Games)
  153. Thief Gold (HKLM-x32\...\Steam App 211600) (Version: - Looking Glass Studios)
  154. Train Simulator (HKLM-x32\...\Steam App 24010) (Version: - Dovetail Games)
  155. Trine 2 (HKLM-x32\...\Steam App 35720) (Version: - Frozenbyte)
  156. Truffle Saga (HKLM-x32\...\Steam App 302260) (Version: - Colossal Games)
  157. Wajam (HKLM-x32\...\WajaNetEn) (Version: 1.58.1.37 (i1.0) - Wajam) <==== ATTENTION
  158. Watch_Dogs (HKLM-x32\...\Steam App 243470) (Version: - Ubisoft)
  159. WinRAR 5.30 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.30.0 - win.rar GmbH)
  160. World of Warcraft (HKLM-x32\...\World of Warcraft) (Version: - Blizzard Entertainment)
  161. yoursearching (HKLM-x32\...\yoursearching) (Version: 1.0.0.8 - )
  162.  
  163. ==================== Custom CLSID (Whitelisted): ==========================
  164.  
  165. (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
  166.  
  167. CustomCLSID: HKU\S-1-5-21-3985454009-819291025-207730266-1001_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\AngryShadow\AppData\Local\Microsoft\OneDrive\17.3.6281.1202\FileCoAuth.exe (Microsoft Corporation)
  168.  
  169. ==================== Scheduled Tasks (Whitelisted) =============
  170.  
  171. (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
  172.  
  173. Task: {2E77DA24-20C2-4094-8200-00F88846DA42} - System32\Tasks\SwiftSearch Auto Updater 1.10.0.27 Core => C:\Program Files (x86)\SwiftSearch_1.10.0.27\Update\SwiftSearchAutoUpdateClient.exe [2015-10-23] (SS) <==== ATTENTION
  174. Task: {36E9F172-E194-49C8-8986-102AB6520FF8} - System32\Tasks\GyazoUpdateTaskMachine => C:\Program Files (x86)\Gyazo\GyazoUpdate.exe [2015-08-19] ()
  175. Task: {4513EF42-97CA-4D19-86EC-E2AE567F37DE} - System32\Tasks\McAfee\McAfee Idle Detection Task
  176. Task: {5374EE17-069B-45FE-A6EF-8BE2DDE622BD} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-01-14] (Google Inc.)
  177. Task: {7D1773F4-2ED5-4AEC-A285-A07CC575C2A0} - System32\Tasks\McAfeeLogon => C:\Program Files\Common Files\McAfee\Platform\McUICnt.exe [2015-11-02] (McAfee, Inc.)
  178. Task: {CA2B9545-B027-49F3-870C-D4CC6DA8443E} - System32\Tasks\GyazoUpdateTaskMachineDaily => C:\Program Files (x86)\Gyazo\GyazoUpdate.exe [2015-08-19] ()
  179. Task: {CC439579-A557-4238-8C76-058AA8E03C9A} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-01-14] (Google Inc.)
  180. Task: {D11DC6BE-410E-47A9-A912-3AC4BCCCFB1E} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2016-01-15] (Microsoft Corporation)
  181. Task: {D9BAFAFE-3C18-4E7B-9145-E2ECDF99DF1B} - System32\Tasks\Microsoft\Windows\UPnP\UPnPHostConfig => config upnphost start= auto
  182. Task: {EC6E4B0B-E143-4419-8D6B-1B7CEC7C809C} - System32\Tasks\SwiftSearch Auto Updater 1.10.0.27 Pending Update => C:\Program Files (x86)\SwiftSearch_1.10.0.27\Update\SwiftSearchAutoUpdateClient.exe [2015-10-23] (SS) <==== ATTENTION
  183. Task: {F389D861-889E-417B-939F-95E9FACF37C9} - System32\Tasks\McAfee\McAfee Auto Maintenance Task Agent
  184.  
  185. (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
  186.  
  187. Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
  188. Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
  189.  
  190. ==================== Shortcuts =============================
  191.  
  192. (The entries could be listed to be restored or removed.)
  193.  
  194. ShortcutWithArgument: C:\Users\AngryShadow\Desktop\Start Tor Browser.lnk -> C:\Users\AngryShadow\Desktop\Tor Browser\Browser\firefox.exe (Mozilla Corporation) -> hxxp://www.yoursearching.com/?type=sc&ts=1452975515&z=374796605c0902467f0741ag7z7weoftam0w9w7gaw&from=exp2&uid=kingstonxrbu-sc400s37128g_50026b7244033f9e
  195. ShortcutWithArgument: C:\Users\AngryShadow\Desktop\Tor Browser\Start Tor Browser.lnk -> C:\Users\AngryShadow\Desktop\Tor Browser\Browser\firefox.exe (Mozilla Corporation) -> hxxp://www.yoursearching.com/?type=sc&ts=1452975515&z=374796605c0902467f0741ag7z7weoftam0w9w7gaw&from=exp2&uid=kingstonxrbu-sc400s37128g_50026b7244033f9e
  196. ShortcutWithArgument: C:\Users\AngryShadow\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Start Tor Browser.lnk -> C:\Users\AngryShadow\Desktop\Tor Browser\Browser\firefox.exe (Mozilla Corporation) -> hxxp://www.yoursearching.com/?type=sc&ts=1452975515&z=374796605c0902467f0741ag7z7weoftam0w9w7gaw&from=exp2&uid=kingstonxrbu-sc400s37128g_50026b7244033f9e
  197. ShortcutWithArgument: C:\Users\AngryShadow\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome\Chrome App Launcher.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursearching.com/?type=sc&ts=1452975515&z=374796605c0902467f0741ag7z7weoftam0w9w7gaw&from=exp2&uid=kingstonxrbu-sc400s37128g_50026b7244033f9e
  198. ShortcutWithArgument: C:\Users\AngryShadow\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Ad.Block Super (V.1.12).lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursearching.com/?type=sc&ts=1452975515&z=374796605c0902467f0741ag7z7weoftam0w9w7gaw&from=exp2&uid=kingstonxrbu-sc400s37128g_50026b7244033f9e
  199. ShortcutWithArgument: C:\Users\AngryShadow\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursearching.com/?type=sc&ts=1452975515&z=374796605c0902467f0741ag7z7weoftam0w9w7gaw&from=exp2&uid=kingstonxrbu-sc400s37128g_50026b7244033f9e
  200. ShortcutWithArgument: C:\Users\AngryShadow\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursearching.com/?type=sc&ts=1452975515&z=374796605c0902467f0741ag7z7weoftam0w9w7gaw&from=exp2&uid=kingstonxrbu-sc400s37128g_50026b7244033f9e
  201. ShortcutWithArgument: C:\Users\AngryShadow\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\69639df789022856\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursearching.com/?type=sc&ts=1452975515&z=374796605c0902467f0741ag7z7weoftam0w9w7gaw&from=exp2&uid=kingstonxrbu-sc400s37128g_50026b7244033f9e
  202. ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursearching.com/?type=sc&ts=1452975515&z=374796605c0902467f0741ag7z7weoftam0w9w7gaw&from=exp2&uid=kingstonxrbu-sc400s37128g_50026b7244033f9e
  203. ShortcutWithArgument: C:\Users\Public\Desktop\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursearching.com/?type=sc&ts=1452975515&z=374796605c0902467f0741ag7z7weoftam0w9w7gaw&from=exp2&uid=kingstonxrbu-sc400s37128g_50026b7244033f9e
  204. ShortcutWithArgument: C:\Users\Public\Desktop\League of Legends.lnk -> D:\League Of Noobs\lol.launcher.exe () -> hxxp://www.yoursearching.com/?type=sc&ts=1452975515&z=374796605c0902467f0741ag7z7weoftam0w9w7gaw&from=exp2&uid=kingstonxrbu-sc400s37128g_50026b7244033f9e
  205.  
  206. ==================== Loaded Modules (Whitelisted) ==============
  207.  
  208. 2015-10-30 08:17 - 2015-10-30 08:17 - 00028672 _____ () C:\WINDOWS\SYSTEM32\efsext.dll
  209. 2015-10-30 08:18 - 2015-10-30 08:18 - 00185856 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll
  210. 2015-12-28 00:26 - 2015-12-16 15:54 - 00126256 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
  211. 2015-12-27 16:46 - 2016-01-09 08:23 - 00291264 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamBase.dll
  212. 2015-12-13 06:22 - 2015-12-13 06:22 - 02653816 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
  213. 2015-12-13 06:22 - 2015-12-13 06:22 - 02653816 _____ () C:\WINDOWS\System32\CoreUIComponents.dll
  214. 2015-12-27 16:10 - 2015-12-27 16:14 - 00144384 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.12.15004.0_x86__8wekyb3d8bbwe\SkypeHost.exe
  215. 2015-12-18 16:51 - 2015-12-07 05:14 - 00093696 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\Windows.UI.Shell.SharedUtilities.dll
  216. 2015-12-18 16:51 - 2015-12-07 05:00 - 00472064 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll
  217. 2015-12-27 16:16 - 2015-12-27 16:16 - 00012800 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_15.1208.10480.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
  218. 2015-12-27 16:16 - 2015-12-27 16:16 - 11542016 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_15.1208.10480.0_x64__8wekyb3d8bbwe\Microsoft.Photos.dll
  219. 2015-12-27 16:04 - 2015-12-27 16:04 - 00258560 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_15.1208.10480.0_x64__8wekyb3d8bbwe\StoreRatingPromotion.dll
  220. 2016-01-08 03:17 - 2016-01-08 03:17 - 09737216 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsStore_2015.25.15.0_x64__8wekyb3d8bbwe\WinStore.Entertainment.Mobile.dll
  221. 2016-01-13 06:18 - 2016-01-13 06:18 - 02829824 _____ () C:\Program Files\WajaNetEn\6f7dd0d1a6b7295523cc41e34e4b9dfd.exe
  222. 2016-01-13 06:16 - 2016-01-13 06:16 - 02314752 _____ () c:\program files\wajaneten\7b1fae02d59a1789f5b8115c78fb3a25.exe
  223. 2016-01-13 06:18 - 2016-01-13 06:18 - 02829824 _____ () c:\program files\wajaneten\6f7dd0d1a6b7295523cc41e34e4b9dfd.exe
  224. 2016-01-16 21:05 - 2016-01-16 21:05 - 11971584 _____ () c:\program files\wajaneten\WajaNetEnlibs\rhbyok.dll
  225. 2015-04-27 03:50 - 2015-04-27 03:50 - 00412672 _____ () C:\Program Files (x86)\Rockstar Games\GTA San Andreas\samp.exe
  226. 2016-01-13 13:05 - 2016-01-05 02:29 - 07992832 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
  227. 2016-01-13 13:05 - 2016-01-05 02:23 - 00591360 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
  228. 2016-01-13 13:05 - 2016-01-05 02:24 - 02483200 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
  229. 2016-01-13 13:05 - 2016-01-05 02:26 - 04089856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
  230. 2015-12-27 16:10 - 2015-12-27 16:14 - 00141312 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.12.15004.0_x86__8wekyb3d8bbwe\SkypeBackgroundTasks.dll
  231. 2015-12-27 16:10 - 2015-12-27 16:14 - 21845504 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.12.15004.0_x86__8wekyb3d8bbwe\SkyWrap.dll
  232. 2015-12-27 16:46 - 2016-01-09 08:23 - 00018880 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll
  233. 2015-12-27 16:01 - 2015-11-10 20:55 - 00778752 _____ () D:\Steam\SDL2.dll
  234. 2015-12-27 16:01 - 2015-07-03 17:12 - 04962816 _____ () D:\Steam\v8.dll
  235. 2015-12-27 16:01 - 2015-12-14 21:01 - 02547280 _____ () D:\Steam\video.dll
  236. 2015-12-27 16:00 - 2015-09-24 01:33 - 02549248 _____ () D:\Steam\libavcodec-56.dll
  237. 2015-12-27 16:00 - 2015-09-24 01:33 - 00491008 _____ () D:\Steam\libavformat-56.dll
  238. 2015-12-27 16:00 - 2015-09-24 01:33 - 00332800 _____ () D:\Steam\libavresample-2.dll
  239. 2015-12-27 16:00 - 2015-09-24 01:33 - 00442880 _____ () D:\Steam\libavutil-54.dll
  240. 2015-12-27 16:00 - 2015-09-24 01:33 - 00485888 _____ () D:\Steam\libswscale-3.dll
  241. 2015-12-27 16:01 - 2015-07-03 17:12 - 01556992 _____ () D:\Steam\icui18n.dll
  242. 2015-12-27 16:01 - 2015-07-03 17:12 - 01187840 _____ () D:\Steam\icuuc.dll
  243. 2015-12-27 16:00 - 2015-12-14 21:01 - 00804432 _____ () D:\Steam\bin\chromehtml.DLL
  244. 2015-12-27 16:00 - 2015-11-03 23:00 - 00201728 _____ () D:\Steam\bin\openvr_api.dll
  245. 2015-12-27 16:00 - 2015-11-17 01:31 - 47846176 _____ () D:\Steam\bin\libcef.dll
  246. 2015-12-27 16:00 - 2015-09-25 00:56 - 00119208 _____ () D:\Steam\winh264.dll
  247. 2015-12-05 10:21 - 2015-12-05 10:21 - 00933056 ____R () D:\Skype\Phone\ssScreenVVS2.dll
  248. 2016-01-16 21:04 - 2016-01-16 21:05 - 11752448 _____ () c:\program files\wajaneten\WajaNetEnlibs\cibkwi.dll
  249. 2016-01-16 21:04 - 2016-01-16 21:05 - 11752448 _____ () c:\program files\wajaneten\wajanetenlibs\cibkwi.dll
  250. 2016-01-14 10:11 - 2016-01-12 17:35 - 01590088 _____ () C:\Program Files (x86)\Google\Chrome\Application\47.0.2526.111\libglesv2.dll
  251. 2016-01-14 10:11 - 2016-01-12 17:35 - 00087880 _____ () C:\Program Files (x86)\Google\Chrome\Application\47.0.2526.111\libegl.dll
  252. 2016-01-14 10:11 - 2016-01-12 17:35 - 16799048 _____ () C:\Program Files (x86)\Google\Chrome\Application\47.0.2526.111\PepperFlash\pepflashplayer.dll
  253.  
  254. ==================== Alternate Data Streams (Whitelisted) =========
  255.  
  256. (If an entry is included in the fixlist, only the ADS will be removed.)
  257.  
  258.  
  259. ==================== Safe Mode (Whitelisted) ===================
  260.  
  261. (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
  262.  
  263. HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\47634066.sys => ""="Driver"
  264. HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""=""
  265. HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
  266. HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\47634066.sys => ""="Driver"
  267. HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service"
  268. HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McNaiAnn => ""=""
  269. HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""=""
  270. HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""
  271. HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeaack => ""="Service"
  272. HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeaack.sys => ""="Driver"
  273. HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeavfk => ""="Service"
  274. HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeavfk.sys => ""="Driver"
  275. HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefire => ""="Service"
  276. HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek => ""="Service"
  277. HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek.sys => ""="Driver"
  278. HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk => ""="Service"
  279. HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk.sys => ""="Driver"
  280. HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfemms => ""="Service"
  281. HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfetdi2k => ""="Service"
  282. HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfetdi2k.sys => ""="Driver"
  283. HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfevtp => ""="Service"
  284.  
  285. ==================== EXE Association (Whitelisted) ===============
  286.  
  287. (If an entry is included in the fixlist, the registry item will be restored to default or removed.)
  288.  
  289.  
  290. ==================== Internet Explorer trusted/restricted ===============
  291.  
  292. (If an entry is included in the fixlist, it will be removed from the registry.)
  293.  
  294.  
  295. ==================== Hosts content: ==========================
  296.  
  297. (If needed Hosts: directive could be included in the fixlist to reset Hosts.)
  298.  
  299. 2015-12-27 16:07 - 2016-01-08 12:50 - 00000994 ____A C:\WINDOWS\system32\Drivers\etc\hosts
  300.  
  301. 127.0.0.1 down.baidu2016.com
  302. 127.0.0.1 123.sogou.com
  303. 127.0.0.1 www.czzsyzgm.com
  304. 127.0.0.1 www.czzsyzxl.com
  305. 127.0.0.1 localhost
  306.  
  307. ==================== Other Areas ============================
  308.  
  309. (Currently there is no automatic fix for this section.)
  310.  
  311. HKU\S-1-5-21-3985454009-819291025-207730266-1001\Control Panel\Desktop\\Wallpaper -> C:\WINDOWS\web\wallpaper\Windows\img0.jpg
  312. DNS Servers: 192.168.1.1
  313. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
  314. Windows Firewall is disabled.
  315.  
  316. ==================== MSCONFIG/TASK MANAGER disabled items ==
  317.  
  318. (Currently there is no automatic fix for this section.)
  319.  
  320. HKLM\...\StartupApproved\Run32: => "BlueStacks Agent"
  321. HKU\S-1-5-21-3985454009-819291025-207730266-1001\...\StartupApproved\Run: => "uTorrent"
  322. HKU\S-1-5-21-3985454009-819291025-207730266-1001\...\StartupApproved\Run: => "CyberGhost"
  323. HKU\S-1-5-21-3985454009-819291025-207730266-1001\...\StartupApproved\Run: => "DAEMON Tools Lite Automount"
  324. HKU\S-1-5-21-3985454009-819291025-207730266-1001\...\StartupApproved\Run: => "OtLandIPChanger"
  325. HKU\S-1-5-21-3985454009-819291025-207730266-1001\...\StartupApproved\Run: => "Skype"
  326. HKU\S-1-5-21-3985454009-819291025-207730266-1001\...\StartupApproved\Run: => "Steam"
  327. HKU\S-1-5-21-3985454009-819291025-207730266-1001\...\StartupApproved\Run: => "Gyazo"
  328.  
  329. ==================== FirewallRules (Whitelisted) ===============
  330.  
  331. (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
  332.  
  333. FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
  334. FirewallRules: [{D13D47E3-7E6E-4EEC-9DA9-B714FAFD1E41}] => (Allow) D:\Steam\Steam.exe
  335. FirewallRules: [{1227FF41-F7C3-4E90-8786-CCC70AD296D5}] => (Allow) D:\Steam\Steam.exe
  336. FirewallRules: [{0253EB6A-0CA2-4592-B005-948D03E99729}] => (Allow) D:\Steam\bin\steamwebhelper.exe
  337. FirewallRules: [{DC7E6BE5-2763-46A5-A5E3-7717154EA78B}] => (Allow) D:\Steam\bin\steamwebhelper.exe
  338. FirewallRules: [{ABC0DBB9-EF67-4567-8BF9-AC25D8847925}] => (Allow) D:\Skype\Phone\Skype.exe
  339. FirewallRules: [TCP Query User{C76C0D0D-B9DB-4B69-8533-DEEC1C1FA6E7}D:\games\hearthstone\hearthstone.exe] => (Allow) D:\games\hearthstone\hearthstone.exe
  340. FirewallRules: [UDP Query User{A60A5B8D-EA79-4BC8-9D3C-D3E773E965B6}D:\games\hearthstone\hearthstone.exe] => (Allow) D:\games\hearthstone\hearthstone.exe
  341. FirewallRules: [{17069DFC-3732-4F79-B3C2-94DDCB25F4A5}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
  342. FirewallRules: [{7AA9A93E-2977-4A3A-9450-0A92C4DE120E}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
  343. FirewallRules: [{B9E8249D-D20A-44AE-9282-771238251B9B}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
  344. FirewallRules: [{B32BA6FE-C45B-4337-B5A5-CFA53112828C}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
  345. FirewallRules: [{4C37FE2E-6F4A-45C8-9E1D-305FF7B07781}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
  346. FirewallRules: [{58AE6673-7364-4DE2-8AA5-BCB96B2C8FD7}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
  347. FirewallRules: [{A6C73751-B746-4A3D-97A7-C1FA2817416D}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
  348. FirewallRules: [{440FBB1C-DCF6-4BBA-8BEF-73F6C2A9D6C5}] => (Allow) D:\Steam\steamapps\common\Team Fortress 2\hl2.exe
  349. FirewallRules: [{452146A2-E991-47D9-9188-646DFD319197}] => (Allow) D:\Steam\steamapps\common\Team Fortress 2\hl2.exe
  350. FirewallRules: [TCP Query User{6209F594-BA6A-494E-97E0-1E3980D529C5}C:\users\angryshadow\downloads\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => (Allow) C:\users\angryshadow\downloads\runtime\jre-x64\1.8.0_25\bin\javaw.exe
  351. FirewallRules: [UDP Query User{9E662524-7FBD-4BEE-AD0E-8DC9045807A4}C:\users\angryshadow\downloads\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => (Allow) C:\users\angryshadow\downloads\runtime\jre-x64\1.8.0_25\bin\javaw.exe
  352. FirewallRules: [{7505A981-6358-4449-8FFE-55E28049BDD7}] => (Allow) D:\Steam\steamapps\common\Grand Theft Auto V\GTAVLauncher.exe
  353. FirewallRules: [{DD2B8607-ADCF-4FF7-87A1-EF502F7D1997}] => (Allow) D:\Steam\steamapps\common\Grand Theft Auto V\GTAVLauncher.exe
  354. FirewallRules: [{4B1837AB-1263-4105-9195-9CBAE2D6396D}] => (Allow) D:\Steam\steamapps\common\Anachronox\anox.exe
  355. FirewallRules: [{F7E4BDB1-A9B6-4E2E-B823-1FC1769E4380}] => (Allow) D:\Steam\steamapps\common\Anachronox\anox.exe
  356. FirewallRules: [{2FC87526-66B2-46BD-B3DF-437A1F7F240E}] => (Allow) D:\Steam\steamapps\common\Assassin's Creed 3\AC3SP.exe
  357. FirewallRules: [{A1172A05-ED76-4B0B-96A4-99AF3FAF86BC}] => (Allow) D:\Steam\steamapps\common\Assassin's Creed 3\AC3SP.exe
  358. FirewallRules: [{11A11A44-0C7E-40E5-B5CB-7C3A35E56553}] => (Allow) D:\Steam\steamapps\common\Assassin's Creed Syndicate\ACS.exe
  359. FirewallRules: [{BED533E2-14B2-4E40-91D0-5304B42AE87D}] => (Allow) D:\Steam\steamapps\common\Assassin's Creed Syndicate\ACS.exe
  360. FirewallRules: [{0692DD56-E1A3-473B-B07D-D223F37637B0}] => (Allow) D:\Steam\steamapps\common\Bermuda\bermuda.exe
  361. FirewallRules: [{CA55037A-CAEA-42EA-B223-F42F66C2C016}] => (Allow) D:\Steam\steamapps\common\Bermuda\bermuda.exe
  362. FirewallRules: [{3BED4FB8-10C5-4F50-9CEB-A58934748C43}] => (Allow) D:\Steam\steamapps\common\Call of Duty Ghosts\iw6sp64_ship.exe
  363. FirewallRules: [{D54CDBAD-A3CE-4D9D-AEE6-26355C61363E}] => (Allow) D:\Steam\steamapps\common\Call of Duty Ghosts\iw6sp64_ship.exe
  364. FirewallRules: [{F4C6A83C-8801-447C-9E33-A2F06F9C40B5}] => (Allow) D:\Steam\steamapps\common\Call of Duty Ghosts\iw6mp64_ship.exe
  365. FirewallRules: [{68F416F0-53F6-418D-A7D9-A35E1AE19294}] => (Allow) D:\Steam\steamapps\common\Call of Duty Ghosts\iw6mp64_ship.exe
  366. FirewallRules: [{E2F7BC72-F317-4765-B99B-D5B93C94B9BA}] => (Allow) D:\Steam\steamapps\common\Call of Duty Modern Warfare 2\iw4sp.exe
  367. FirewallRules: [{40143CFB-FBF2-450B-9DBC-33DC3D8FDA4B}] => (Allow) D:\Steam\steamapps\common\Call of Duty Modern Warfare 2\iw4sp.exe
  368. FirewallRules: [{B5224DA6-3745-4E2A-8346-313F45CCA226}] => (Allow) D:\Steam\steamapps\common\Call of Duty Modern Warfare 2\iw4mp.exe
  369. FirewallRules: [{372DF5E8-ED17-4B91-A3CE-9EAF40E2BD40}] => (Allow) D:\Steam\steamapps\common\Call of Duty Modern Warfare 2\iw4mp.exe
  370. FirewallRules: [{5A560584-8FE0-4CA9-A23D-7562CFCD93D3}] => (Allow) D:\Steam\steamapps\common\Call of Duty Modern Warfare 3\iw5sp.exe
  371. FirewallRules: [{22E9FD8C-4B9A-4CED-AA8C-CE16750F25C4}] => (Allow) D:\Steam\steamapps\common\Call of Duty Modern Warfare 3\iw5sp.exe
  372. FirewallRules: [{CE54E636-C9D5-45FB-A03A-C7A2789506C6}] => (Allow) D:\Steam\steamapps\common\Call of Duty Modern Warfare 3\iw5mp.exe
  373. FirewallRules: [{CD55F6D9-A4F9-4F64-A3EA-9AF5CF7D8D87}] => (Allow) D:\Steam\steamapps\common\Call of Duty Modern Warfare 3\iw5mp.exe
  374. FirewallRules: [{7F71852F-F3EB-406F-B1F8-2115F146D773}] => (Allow) D:\Steam\steamapps\common\Command and Conquer Red Alert 3\runme.exe
  375. FirewallRules: [{8B1D53B8-05CA-4140-B925-B2FB73C3CE7E}] => (Allow) D:\Steam\steamapps\common\Command and Conquer Red Alert 3\runme.exe
  376. FirewallRules: [{F107A64D-026D-4D73-9B33-D1487A3425BB}] => (Allow) D:\Steam\steamapps\common\Half-Life\hl.exe
  377. FirewallRules: [{36581326-12F7-46C4-90EA-E93929F657C1}] => (Allow) D:\Steam\steamapps\common\Half-Life\hl.exe
  378. FirewallRules: [{5F5218BC-AF5F-4517-AAA4-45330503D357}] => (Allow) D:\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe
  379. FirewallRules: [{4BB944E3-1D1E-46C0-8398-73755DB6E9C7}] => (Allow) D:\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe
  380. FirewallRules: [{FF5AF6B9-C466-4DBD-8EC9-FBF81A8946D6}] => (Allow) D:\Steam\steamapps\common\Daikatana\daikatana.exe
  381. FirewallRules: [{D360ED61-CA86-48B8-856F-CE95745F8FC1}] => (Allow) D:\Steam\steamapps\common\Daikatana\daikatana.exe
  382. FirewallRules: [{C100A41E-E967-4E0B-9510-B34C91C10699}] => (Allow) D:\Steam\steamapps\common\DayZ\DayZ_BE.exe
  383. FirewallRules: [{43C43D4E-9BCB-4D0D-B071-A7E84694A419}] => (Allow) D:\Steam\steamapps\common\DayZ\DayZ_BE.exe
  384. FirewallRules: [{3CF0D4E8-E5C6-4AF0-8D4D-28949C294D66}] => (Allow) D:\Steam\steamapps\common\DeadEffect\DeadEffect.exe
  385. FirewallRules: [{3668B7B2-7D6F-458C-A23A-FE535C3F787B}] => (Allow) D:\Steam\steamapps\common\DeadEffect\DeadEffect.exe
  386. FirewallRules: [{D223B672-86E2-4121-B69B-6283E2CAF905}] => (Allow) D:\Steam\steamapps\common\Dead Island Epidemic\Dead Island Epidemic - Launcher.exe
  387. FirewallRules: [{9C2B5B0A-1F04-419C-8FFE-2BC6CA702E5C}] => (Allow) D:\Steam\steamapps\common\Dead Island Epidemic\Dead Island Epidemic - Launcher.exe
  388. FirewallRules: [{C4FC09A9-AFD5-49B6-8141-CF6DB0F5A31C}] => (Allow) D:\Steam\steamapps\common\DepthHunter2\dh2.exe
  389. FirewallRules: [{89AA7F10-816B-4EF5-ADD1-2B60D186F0FB}] => (Allow) D:\Steam\steamapps\common\DepthHunter2\dh2.exe
  390. FirewallRules: [{57B90B0A-3513-438B-B574-DDED11147758}] => (Allow) D:\Steam\steamapps\common\Deus Ex Human Revolution Director's Cut\DXHRDC.exe
  391. FirewallRules: [{E3B4D56B-76EF-446E-9B5A-F63A04524700}] => (Allow) D:\Steam\steamapps\common\Deus Ex Human Revolution Director's Cut\DXHRDC.exe
  392. FirewallRules: [{69357F98-7A3B-4F4A-94B7-BDEDC2AFF262}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
  393. FirewallRules: [{F34C5977-94DF-4B72-99D1-459DAF6353EE}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
  394. FirewallRules: [{52EAB1A6-99DC-4E68-B7D6-DE0072034EE7}] => (Allow) D:\Steam\steamapps\common\dota 2 test\game\bin\win64\dota2.exe
  395. FirewallRules: [{C794EE68-38AB-4870-BEE4-0E9DD4AD7909}] => (Allow) D:\Steam\steamapps\common\dota 2 test\game\bin\win64\dota2.exe
  396. FirewallRules: [{043B087B-4DBE-4D84-BEEF-E17B00AE62F0}] => (Allow) D:\Steam\steamapps\common\dream_pinball_3D\dp3d.exe
  397. FirewallRules: [{1C2ADECD-5AE7-4223-83D5-5AD227448314}] => (Allow) D:\Steam\steamapps\common\dream_pinball_3D\dp3d.exe
  398. FirewallRules: [{EB6EB93C-2865-4079-8A9A-3FA1A685A4FD}] => (Allow) D:\Steam\steamapps\common\Emily Wants To Play\EmilyWantsToPlay.exe
  399. FirewallRules: [{BB72DF31-8595-4310-ABAC-108BD17FCD14}] => (Allow) D:\Steam\steamapps\common\Emily Wants To Play\EmilyWantsToPlay.exe
  400. FirewallRules: [{AEF12375-38A8-4FFD-8911-30310B4AE7AA}] => (Allow) D:\Steam\steamapps\common\Enclave\Enclave.exe
  401. FirewallRules: [{63E5C8F2-32B1-47AF-BB22-3AB71885AD48}] => (Allow) D:\Steam\steamapps\common\Enclave\Enclave.exe
  402. FirewallRules: [{1039A38A-9200-4528-BA46-0479EF616267}] => (Allow) D:\Steam\steamapps\common\Europa Universalis III - Complete\eu3game.exe
  403. FirewallRules: [{C67F9579-B1C3-4E2C-B796-CD8B3BAF360A}] => (Allow) D:\Steam\steamapps\common\Europa Universalis III - Complete\eu3game.exe
  404. FirewallRules: [{B26903C7-5397-4A34-A99A-6D6DA5AF761B}] => (Allow) D:\Steam\steamapps\common\TheEvilWithin\EvilWithin.exe
  405. FirewallRules: [{B0F54D83-E8C2-4FF4-AD3B-A4DD085691F4}] => (Allow) D:\Steam\steamapps\common\TheEvilWithin\EvilWithin.exe
  406. FirewallRules: [{50B909C6-70D4-4A48-80FF-2BEF5D6BCBDD}] => (Allow) D:\Steam\steamapps\common\Five Nights at Freddy's\FiveNightsatFreddys.exe
  407. FirewallRules: [{83D14F92-6D5F-44E8-9B65-8A086FFA134E}] => (Allow) D:\Steam\steamapps\common\Five Nights at Freddy's\FiveNightsatFreddys.exe
  408. FirewallRules: [{7DCD86BC-BA06-4E7C-AE45-4EB188436086}] => (Allow) D:\Steam\steamapps\common\FlatOut2\FlatOut2.exe
  409. FirewallRules: [{47E50B44-21CC-4ECF-AF29-F2315C0E91E7}] => (Allow) D:\Steam\steamapps\common\FlatOut2\FlatOut2.exe
  410. FirewallRules: [{63B96712-BDC9-4869-B7DC-AD64856769A1}] => (Allow) D:\Steam\steamapps\common\Glacier 3 The Meltdown\Game.exe
  411. FirewallRules: [{6469ACA9-FC0F-4869-A383-B1C68ADDACF0}] => (Allow) D:\Steam\steamapps\common\Glacier 3 The Meltdown\Game.exe
  412. FirewallRules: [{CDCE12F1-6A46-4879-9443-1EA24FECBE36}] => (Allow) D:\Steam\steamapps\common\Gorky 17\gorky17.exe
  413. FirewallRules: [{3DB7D2E9-A0DD-4997-8232-B5B95A43BCEC}] => (Allow) D:\Steam\steamapps\common\Gorky 17\gorky17.exe
  414. FirewallRules: [{AA9C11A6-7D27-4FC8-A8E7-3B78545C700F}] => (Allow) D:\Steam\steamapps\common\Grand Theft Auto San Andreas\gta-sa.exe
  415. FirewallRules: [{0849732F-567D-41BA-BB08-CD922B7F9B86}] => (Allow) D:\Steam\steamapps\common\Grand Theft Auto San Andreas\gta-sa.exe
  416. FirewallRules: [{A5872CD8-84BD-425E-B138-5532658E615E}] => (Allow) D:\Steam\steamapps\common\Flesh Eaters\game.exe
  417. FirewallRules: [{1966BE04-730E-49A5-BE46-41A3D100A8D7}] => (Allow) D:\Steam\steamapps\common\Flesh Eaters\game.exe
  418. FirewallRules: [{FB92F6EE-1E10-4F4A-90F1-7DB35EB828E6}] => (Allow) D:\Steam\steamapps\common\H1Z1\LaunchPad.exe
  419. FirewallRules: [{458F29DF-2F69-4DD8-BCD0-ED8B18E7F42F}] => (Allow) D:\Steam\steamapps\common\H1Z1\LaunchPad.exe
  420. FirewallRules: [{A57EF2E2-7808-48ED-8CD5-4765E6E21EBA}] => (Allow) D:\Steam\steamapps\common\H1Z1 Test\LaunchPad.exe
  421. FirewallRules: [{50678F0C-BAA0-41E2-B178-1C45F9121643}] => (Allow) D:\Steam\steamapps\common\H1Z1 Test\LaunchPad.exe
  422. FirewallRules: [{3E0DF177-5DA5-421B-84A4-63A99AFB6281}] => (Allow) D:\Steam\steamapps\common\Hacker Evolution\HackerEvolution.exe
  423. FirewallRules: [{2C738BDF-8C5A-4D06-AC63-2F1FC4710775}] => (Allow) D:\Steam\steamapps\common\Hacker Evolution\HackerEvolution.exe
  424. FirewallRules: [{B15A56CA-3A99-4A89-A5EE-DB550A3667D6}] => (Allow) D:\Steam\steamapps\common\Hacker Evolution\HackerEvolutionModEditor.exe
  425. FirewallRules: [{E06E544F-F043-49A9-AF0C-E3F414B7114C}] => (Allow) D:\Steam\steamapps\common\Hacker Evolution\HackerEvolutionModEditor.exe
  426. FirewallRules: [{A8E7F649-B235-489C-A4B4-B51BD28C920B}] => (Allow) D:\Steam\steamapps\common\Hacker Evolution Untold\Hacker Evolution Untold.exe
  427. FirewallRules: [{360920C9-7C79-404E-AC19-9D78A99F2C94}] => (Allow) D:\Steam\steamapps\common\Hacker Evolution Untold\Hacker Evolution Untold.exe
  428. FirewallRules: [{D1FAEEAA-C4B4-4333-B288-0E8FA775A215}] => (Allow) D:\Steam\steamapps\common\Hacker Evolution Untold\Hacker Evolution Mod Editor.exe
  429. FirewallRules: [{5EDCCCE7-922F-4AA2-9118-498A14935CB4}] => (Allow) D:\Steam\steamapps\common\Hacker Evolution Untold\Hacker Evolution Mod Editor.exe
  430. FirewallRules: [{E0AC2E83-DC30-430A-B836-0D9904C29432}] => (Allow) D:\Steam\steamapps\common\Half-Life 2\hl2.exe
  431. FirewallRules: [{1146B8B5-DAAF-4F38-A387-5861BC02EEF6}] => (Allow) D:\Steam\steamapps\common\Half-Life 2\hl2.exe
  432. FirewallRules: [{A3AF3346-9409-465A-8229-129E461C58B7}] => (Allow) D:\Steam\steamapps\common\Half-Life 2 Deathmatch\hl2.exe
  433. FirewallRules: [{D4BFA730-6E78-40A9-A5D4-8AB38017683A}] => (Allow) D:\Steam\steamapps\common\Half-Life 2 Deathmatch\hl2.exe
  434. FirewallRules: [{D98AFAB4-491E-4A5D-AFE2-02E917F763DC}] => (Allow) D:\Steam\steamapps\common\Hitman Codename 47\Hitman.Exe
  435. FirewallRules: [{61EAB410-0C0B-47AB-BFD5-F3DB3145709D}] => (Allow) D:\Steam\steamapps\common\Hitman Codename 47\Hitman.Exe
  436. FirewallRules: [{E3061087-538B-4FCC-9172-C5EA9568CF8C}] => (Allow) D:\Steam\steamapps\common\Hitman Codename 47\Setup.exe
  437. FirewallRules: [{F02E99C8-39F6-4444-A770-EEFEB206C8FC}] => (Allow) D:\Steam\steamapps\common\Hitman Codename 47\Setup.exe
  438. FirewallRules: [{CCE56B0E-E1BD-4EC2-A2DE-C698706372BD}] => (Allow) D:\Steam\steamapps\common\Hitman 2 Silent Assassin\hitman2.exe
  439. FirewallRules: [{7115E3C2-76D3-4CC8-BE0B-9324E5D0B230}] => (Allow) D:\Steam\steamapps\common\Hitman 2 Silent Assassin\hitman2.exe
  440. FirewallRules: [{181A5A4B-4CE6-4BDC-9B67-8662275D22D6}] => (Allow) D:\Steam\steamapps\common\Hitman 2 Silent Assassin\config.exe
  441. FirewallRules: [{342C3B9E-CDE8-4667-B0FD-0CBAEBCAB33E}] => (Allow) D:\Steam\steamapps\common\Hitman 2 Silent Assassin\config.exe
  442. FirewallRules: [{BB3FC575-FA62-4BA7-900F-AA53402B018F}] => (Allow) D:\Steam\steamapps\common\Watch_Dogs\bin\watch_dogs.exe
  443. FirewallRules: [{8694BCEC-D04E-4FD6-8D6D-F942FCDD00D7}] => (Allow) D:\Steam\steamapps\common\Watch_Dogs\bin\watch_dogs.exe
  444. FirewallRules: [{E59EFBB3-4B4B-409A-A98A-8365EE5F3DF9}] => (Allow) D:\Steam\steamapps\common\Trine 2\trine2_launcher.exe
  445. FirewallRules: [{58D81264-A693-408A-A3A2-30A7E093B21E}] => (Allow) D:\Steam\steamapps\common\Trine 2\trine2_launcher.exe
  446. FirewallRules: [{9DA1EB87-2133-4A55-81BD-6C4CF1A80A24}] => (Allow) D:\Steam\steamapps\common\RailWorks\RailWorks.exe
  447. FirewallRules: [{8A87A270-DB48-4B07-B1FF-152588717B32}] => (Allow) D:\Steam\steamapps\common\RailWorks\RailWorks.exe
  448. FirewallRules: [{F25356C0-272D-4FD1-92E3-B581B2009A32}] => (Allow) D:\Steam\steamapps\common\The Tower Of Elements\TowerOfElements.exe
  449. FirewallRules: [{E84072C5-396E-404E-B6D3-5339EB7F3BAD}] => (Allow) D:\Steam\steamapps\common\The Tower Of Elements\TowerOfElements.exe
  450. FirewallRules: [{382954C9-286C-4F1A-9B9D-5F2FD01C9ED1}] => (Allow) D:\Steam\steamapps\common\thief_gold\THIEF.EXE
  451. FirewallRules: [{E7DCB0E3-C2F0-4516-A6B4-CF6F3D4633CC}] => (Allow) D:\Steam\steamapps\common\thief_gold\THIEF.EXE
  452. FirewallRules: [{7140F6EC-7E24-4D44-B5A3-D823002E1F68}] => (Allow) D:\Steam\steamapps\common\Knights of the Old Republic II\swkotor2.exe
  453. FirewallRules: [{6D4DFB62-2F94-4B93-A2C8-57E4D47BAA52}] => (Allow) D:\Steam\steamapps\common\Knights of the Old Republic II\swkotor2.exe
  454. FirewallRules: [{FCF33FA2-5812-4245-A675-C9D62227E07D}] => (Allow) D:\Steam\steamapps\common\Star Chronicles Delta Quadrant\Delta Quadrant.exe
  455. FirewallRules: [{99A13297-8DCB-4B77-826C-AC12EFAAAE99}] => (Allow) D:\Steam\steamapps\common\Star Chronicles Delta Quadrant\Delta Quadrant.exe
  456. FirewallRules: [{3BB351E0-DA5A-46B0-B4A1-FBDA417B6CA7}] => (Allow) D:\Steam\steamapps\common\SpeedRunners\SpeedRunners.exe
  457. FirewallRules: [{B89D5D78-D0CC-4E97-8302-0BD2EDE5C256}] => (Allow) D:\Steam\steamapps\common\SpeedRunners\SpeedRunners.exe
  458. FirewallRules: [{C02E5E4C-A0D4-448F-A93A-57D15DA31C8E}] => (Allow) D:\Steam\steamapps\common\SmoothOperators\Smooth Operators.exe
  459. FirewallRules: [{0D34248E-D5F4-46AE-8400-2AF56441725D}] => (Allow) D:\Steam\steamapps\common\SmoothOperators\Smooth Operators.exe
  460. FirewallRules: [{13FD33F2-7BD8-4033-85FF-A66B6ABE363B}] => (Allow) D:\Steam\steamapps\common\Showerdad\SHOWERDAD.exe
  461. FirewallRules: [{1FA6A332-F13D-4B0B-8E9C-599EDD342394}] => (Allow) D:\Steam\steamapps\common\Showerdad\SHOWERDAD.exe
  462. FirewallRules: [{6E482C4D-8DA1-4230-B210-253EB954974C}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
  463. FirewallRules: [{002CB99C-6A3D-48CE-9B9B-592B08582628}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
  464. FirewallRules: [{DF8130D3-5C1B-4428-9F9D-61420AD6EA54}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
  465. FirewallRules: [{6B815673-13F5-453E-BF19-BE7F441BA4C7}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
  466. FirewallRules: [{E5D66418-D83E-42AD-A01C-36CB03B4D8FF}] => (Allow) D:\Steam\steamapps\common\Portal\hl2.exe
  467. FirewallRules: [{1252FC11-18D2-41CE-A823-0CF2B915A692}] => (Allow) D:\Steam\steamapps\common\Portal\hl2.exe
  468. FirewallRules: [{89754926-9022-415A-8CC1-BA623A4C0814}] => (Allow) D:\Steam\steamapps\common\Just Cause 2 - Multiplayer Mod\JcmpLauncher.exe
  469. FirewallRules: [{4FF3E2AE-7FF3-4116-AD5C-111D879AB8C7}] => (Allow) D:\Steam\steamapps\common\Just Cause 2 - Multiplayer Mod\JcmpLauncher.exe
  470. FirewallRules: [{110EEE78-94B2-4674-8419-F6538441A887}] => (Allow) D:\Steam\steamapps\common\Knights and Merchants Historical Version\KM_TPR.exe
  471. FirewallRules: [{1F77DAF5-D028-483E-B137-F0ADD5F75712}] => (Allow) D:\Steam\steamapps\common\Knights and Merchants Historical Version\KM_TPR.exe
  472. FirewallRules: [{1A843F62-B184-4120-97D6-381977B1C6EB}] => (Allow) D:\Steam\steamapps\common\Knights and Merchants Historical Version\hd\Knights_and_Merchants_steam.exe
  473. FirewallRules: [{97A233D1-F53C-430F-A0B7-AD4C0FA561D3}] => (Allow) D:\Steam\steamapps\common\Knights and Merchants Historical Version\hd\Knights_and_Merchants_steam.exe
  474. FirewallRules: [{C7D66EC2-C461-422E-8080-3AAE50055E2A}] => (Allow) D:\Steam\steamapps\common\KnightShift\KnightShift.exe
  475. FirewallRules: [{6A79556C-5AA0-425E-BF08-6C492CA69BEF}] => (Allow) D:\Steam\steamapps\common\KnightShift\KnightShift.exe
  476. FirewallRules: [{6513DDE1-FADD-4D60-AD95-9B02BDC04585}] => (Allow) D:\Steam\steamapps\common\RollerCoaster Tycoon Deluxe\RCT.EXE
  477. FirewallRules: [{C8344AC8-DC57-4492-8436-62F90C108558}] => (Allow) D:\Steam\steamapps\common\RollerCoaster Tycoon Deluxe\RCT.EXE
  478. FirewallRules: [{6F65E3AB-D45B-40BA-814E-E64E0073A519}] => (Allow) D:\Steam\steamapps\common\Left 4 Dead 2\left4dead2.exe
  479. FirewallRules: [{CC9C386D-1233-46C8-9B7C-6129A101E9A5}] => (Allow) D:\Steam\steamapps\common\Left 4 Dead 2\left4dead2.exe
  480. FirewallRules: [{B6A4FB19-7A7D-4EAF-B2AA-0AA758C752D3}] => (Allow) D:\Steam\steamapps\common\Left 4 Dead 2 Beta\left4dead2_beta.exe
  481. FirewallRules: [{A5AE303F-7220-4742-8801-8F6CCA5F3F76}] => (Allow) D:\Steam\steamapps\common\Left 4 Dead 2 Beta\left4dead2_beta.exe
  482. FirewallRules: [{6A8095B6-938E-4C4B-A2C4-C93B7C61E915}] => (Allow) D:\Steam\steamapps\common\Landmark\LaunchPad.exe
  483. FirewallRules: [{29537D10-68F9-4BCB-A8E0-D0DA7DD38ABF}] => (Allow) D:\Steam\steamapps\common\Landmark\LaunchPad.exe
  484. FirewallRules: [{A67563B0-B281-4C85-AE07-117A36DF26F3}] => (Allow) D:\Steam\steamapps\common\New kind of adventure\NKOAgame.exe
  485. FirewallRules: [{AFF42B46-DE83-4ED0-82A1-658EC29B925D}] => (Allow) D:\Steam\steamapps\common\New kind of adventure\NKOAgame.exe
  486. FirewallRules: [{46CB0F81-BA3F-4086-ABFD-7C94E716A154}] => (Allow) D:\Steam\steamapps\common\Outlast\OutlastLauncher.exe
  487. FirewallRules: [{442A0E07-3426-4DE3-90CB-CE041C61E394}] => (Allow) D:\Steam\steamapps\common\Outlast\OutlastLauncher.exe
  488. FirewallRules: [{EE35B909-3B8A-4653-966A-1BD8F77A640D}] => (Allow) D:\Steam\steamapps\common\PAYDAY 2\payday2_win32_release.exe
  489. FirewallRules: [{FFB79FD4-B52B-40F5-8659-ADC67D278E0B}] => (Allow) D:\Steam\steamapps\common\PAYDAY 2\payday2_win32_release.exe
  490. FirewallRules: [{C74B3FE7-1FFD-4204-A430-1177CE468766}] => (Allow) D:\Steam\steamapps\common\Saints Row IV\SaintsRowIV.exe
  491. FirewallRules: [{BA85315B-AA69-42E3-AE69-71E3836F9628}] => (Allow) D:\Steam\steamapps\common\Saints Row IV\SaintsRowIV.exe
  492. FirewallRules: [{44A19B1B-28C6-429A-8ED7-F1E2161620FA}] => (Allow) D:\Steam\steamapps\common\mirrors edge\Binaries\MirrorsEdge.exe
  493. FirewallRules: [{F14FC1D4-C062-4290-B05B-354F44006CC3}] => (Allow) D:\Steam\steamapps\common\mirrors edge\Binaries\MirrorsEdge.exe
  494. FirewallRules: [{2F94C7D8-1336-4465-A4B4-EA24315E065D}] => (Allow) D:\Steam\steamapps\common\Just Cause 2\JustCause2.exe
  495. FirewallRules: [{02D904AB-46CF-4445-881D-9B2EC904E12F}] => (Allow) D:\Steam\steamapps\common\Just Cause 2\JustCause2.exe
  496. FirewallRules: [{FE0FEA8D-CEF2-46C3-8E97-21D24AA34CDC}] => (Allow) D:\Steam\steamapps\common\STALKER Shadow of Chernobyl\bin\XR_3DA.exe
  497. FirewallRules: [{8B8A62BE-9372-40C6-BC1C-E1E2C9A8E012}] => (Allow) D:\Steam\steamapps\common\STALKER Shadow of Chernobyl\bin\XR_3DA.exe
  498. FirewallRules: [{AB0CFF14-C92F-483D-AF11-244A2B1F81ED}] => (Allow) D:\Steam\steamapps\common\PAYDAY The Heist\payday_win32_release.exe
  499. FirewallRules: [{1B3B5376-BC4E-479A-BD24-1F6F6ECA3AE3}] => (Allow) D:\Steam\steamapps\common\PAYDAY The Heist\payday_win32_release.exe
  500. FirewallRules: [{84BDA7E9-CA20-4C7A-8C02-ADE817C50678}] => (Allow) D:\Steam\steamapps\common\Metro 2033\metro2033.exe
  501. FirewallRules: [{64D70BE8-C7C0-4A8A-B2A4-D1C6E053A3C2}] => (Allow) D:\Steam\steamapps\common\Metro 2033\metro2033.exe
  502. FirewallRules: [{9FFA3A2E-4C52-4101-A178-F092F296268D}] => (Allow) D:\Steam\steamapps\common\Mini Ninjas\ninja.exe
  503. FirewallRules: [{8B81E7F6-C774-4ECF-A01D-3E7E0E1E0BC5}] => (Allow) D:\Steam\steamapps\common\Mini Ninjas\ninja.exe
  504. FirewallRules: [{89E0D97B-6353-4425-B979-DE2FF027E277}] => (Allow) D:\Steam\steamapps\common\Krater\run_game.exe
  505. FirewallRules: [{C50F7D15-603C-4F20-BDF0-70E7A1CA804C}] => (Allow) D:\Steam\steamapps\common\Krater\run_game.exe
  506. FirewallRules: [{292DECFB-5F18-499A-A6F0-DF62C7AAC120}] => (Allow) D:\Steam\steamapps\common\insurgency2\insurgency.exe
  507. FirewallRules: [{B7359ED9-4BB9-42A0-A162-0283D1F6FC98}] => (Allow) D:\Steam\steamapps\common\insurgency2\insurgency.exe
  508. FirewallRules: [{68E49064-02AA-47EB-BACB-CA8FAFD361AE}] => (Allow) D:\Steam\steamapps\common\Counter-Strike Source\hl2.exe
  509. FirewallRules: [{AF6E5F9C-88F6-4AF4-83AE-DA0536BB1912}] => (Allow) D:\Steam\steamapps\common\Counter-Strike Source\hl2.exe
  510. FirewallRules: [{04705EFD-B763-4004-94D6-A7F28A148B36}] => (Allow) D:\Steam\steamapps\common\Need for Speed Hot Pursuit\NFS11.exe
  511. FirewallRules: [{98B847DA-83BD-4500-9F37-9B0F4215FB61}] => (Allow) D:\Steam\steamapps\common\Need for Speed Hot Pursuit\NFS11.exe
  512. FirewallRules: [{1F49C09F-AE4F-4B89-A5D5-63EFCD599CFF}] => (Allow) D:\Steam\steamapps\common\Sniper Ghost Warrior\Sniper_x86.exe
  513. FirewallRules: [{90D600C6-5696-45A0-9CC6-F36139F20F45}] => (Allow) D:\Steam\steamapps\common\Sniper Ghost Warrior\Sniper_x86.exe
  514. FirewallRules: [{648AA4EB-DD0C-45CE-9228-D933030C208A}] => (Allow) D:\Steam\steamapps\common\Sniper Art of Victory\Sniper.exe
  515. FirewallRules: [{85F0D49D-95CA-4491-9C37-2D8954C6E3FB}] => (Allow) D:\Steam\steamapps\common\Sniper Art of Victory\Sniper.exe
  516. FirewallRules: [{E8846932-51C2-4442-B1A7-0C719861ECF4}] => (Allow) D:\Steam\steamapps\common\SniperGhostWarrior2\Bin32\SniperGhostWarrior2.exe
  517. FirewallRules: [{2E4FC536-D786-4913-8F3D-CAA544583C6D}] => (Allow) D:\Steam\steamapps\common\SniperGhostWarrior2\Bin32\SniperGhostWarrior2.exe
  518. FirewallRules: [{400EFE22-E7D0-4904-AD64-070E84782AD1}] => (Allow) D:\Steam\steamapps\common\GarrysMod\hl2.exe
  519. FirewallRules: [{F8C4035E-62FC-4F7A-AD1E-42757CFD322B}] => (Allow) D:\Steam\steamapps\common\GarrysMod\hl2.exe
  520. FirewallRules: [{98C13DD0-672F-42A2-A244-79A1D0B36C06}] => (Allow) C:\Users\AngryShadow\AppData\Roaming\uTorrent\uTorrent.exe
  521. FirewallRules: [{51D6C715-63B1-4379-89B4-FD775CAB0C09}] => (Allow) C:\Users\AngryShadow\AppData\Roaming\uTorrent\uTorrent.exe
  522. FirewallRules: [{7D5E9ECD-660F-4C6A-A73E-6263DC522E2B}] => (Allow) C:\Users\AngryShadow\AppData\Roaming\uTorrent\uTorrent.exe
  523. FirewallRules: [{5927FD80-5257-4471-9FA8-0DF8299B08BA}] => (Allow) C:\Users\AngryShadow\AppData\Roaming\uTorrent\uTorrent.exe
  524. FirewallRules: [{7CF75122-7D76-44AA-8D4F-AD8757A915AF}] => (Allow) C:\Users\AngryShadow\AppData\Roaming\uTorrent\uTorrent.exe
  525. FirewallRules: [{B9AD5A91-9CAF-4CE0-9875-A3A1E32772A8}] => (Allow) C:\Users\AngryShadow\AppData\Roaming\uTorrent\uTorrent.exe
  526. FirewallRules: [TCP Query User{BA6CCF23-9963-40FD-AAA5-1F5A8AD24D55}C:\users\angryshadow\downloads\samp037_svr_r2-1-1_win32\samp-server.exe] => (Allow) C:\users\angryshadow\downloads\samp037_svr_r2-1-1_win32\samp-server.exe
  527. FirewallRules: [UDP Query User{902E52F3-B54A-4075-9B82-84F904BBBA31}C:\users\angryshadow\downloads\samp037_svr_r2-1-1_win32\samp-server.exe] => (Allow) C:\users\angryshadow\downloads\samp037_svr_r2-1-1_win32\samp-server.exe
  528. FirewallRules: [{44F376AF-74D8-449C-845F-74753D843603}] => (Allow) LPort=7777
  529. FirewallRules: [{D2DF8CA6-88DD-46F2-AFF1-EC01A355BD0F}] => (Allow) LPort=7777
  530. FirewallRules: [TCP Query User{E920AE0F-216C-4D70-BF81-ED14D5D9B902}C:\program files (x86)\portforward.com\portforward network utilities\pfportchecker.exe] => (Allow) C:\program files (x86)\portforward.com\portforward network utilities\pfportchecker.exe
  531. FirewallRules: [UDP Query User{311A45B8-27A9-49D9-933F-F093BEE3367D}C:\program files (x86)\portforward.com\portforward network utilities\pfportchecker.exe] => (Allow) C:\program files (x86)\portforward.com\portforward network utilities\pfportchecker.exe
  532. FirewallRules: [{DDEDBBB0-1E0D-4EC8-8939-C59B88407C78}] => (Allow) D:\Steam\steamapps\common\DiRT Rally\drt.exe
  533. FirewallRules: [{10CD3B90-F1C9-466F-B92E-41C6C4D71A2F}] => (Allow) D:\Steam\steamapps\common\DiRT Rally\drt.exe
  534. FirewallRules: [TCP Query User{FBAECAF8-C86B-4BAA-89B5-9035D96C0925}C:\users\angryshadow\downloads\darkcometrat531\darkcomet.exe] => (Allow) C:\users\angryshadow\downloads\darkcometrat531\darkcomet.exe
  535. FirewallRules: [UDP Query User{A66F7CE2-04BF-472D-B418-5B3ACE2713D8}C:\users\angryshadow\downloads\darkcometrat531\darkcomet.exe] => (Allow) C:\users\angryshadow\downloads\darkcometrat531\darkcomet.exe
  536. FirewallRules: [TCP Query User{230B911E-B635-4B1D-BB87-FBA17CC89726}C:\users\angryshadow\downloads\nanocore-cracked\nanocore cracked\nanocore_cracked.exe] => (Allow) C:\users\angryshadow\downloads\nanocore-cracked\nanocore cracked\nanocore_cracked.exe
  537. FirewallRules: [UDP Query User{EE3E3B96-50A4-4862-8E74-AAA9FB6E2FFB}C:\users\angryshadow\downloads\nanocore-cracked\nanocore cracked\nanocore_cracked.exe] => (Allow) C:\users\angryshadow\downloads\nanocore-cracked\nanocore cracked\nanocore_cracked.exe
  538. FirewallRules: [{FDBE683C-2D74-4893-ABD1-4962B8726AC6}] => (Allow) D:\Steam\steamapps\common\Euro Truck Simulator 2\bin\win_x86\eurotrucks2.exe
  539. FirewallRules: [{1410C4C1-E129-4BDC-9852-97996A512278}] => (Allow) D:\Steam\steamapps\common\Euro Truck Simulator 2\bin\win_x86\eurotrucks2.exe
  540. FirewallRules: [{4A11FD5E-F9D0-41A7-89FF-69EB77E9D171}] => (Allow) D:\Steam\steamapps\common\Euro Truck Simulator 2\bin\win_x64\eurotrucks2.exe
  541. FirewallRules: [{B66F8DF8-04B2-4690-83BB-33E55023C489}] => (Allow) D:\Steam\steamapps\common\Euro Truck Simulator 2\bin\win_x64\eurotrucks2.exe
  542. FirewallRules: [{788226CA-B619-45C8-AD8A-384589EA1F41}] => (Allow) C:\Program Files (x86)\SpringFiles\SpringFiles.exe
  543. FirewallRules: [{CACEE9BD-64F6-4953-A2F5-2097467F974F}] => (Allow) C:\Program Files (x86)\SpringFiles\SpringFiles.exe
  544. FirewallRules: [{7E5CCAF1-D39E-4EE6-B74C-6618EFD6EDE5}] => (Allow) C:\Program Files (x86)\SpringFiles\downloader.exe
  545. FirewallRules: [{675563DC-9AA3-47FC-8B52-80DE083E02B0}] => (Allow) C:\Program Files (x86)\SpringFiles\downloader.exe
  546. FirewallRules: [{586F0FE1-4716-4CC6-A06B-1BD631CEF2A5}] => (Allow) C:\Users\AngryShadow\AppData\Local\Temp\net.exe
  547. FirewallRules: [{F8A3355F-BC16-41BD-98A8-C762C432F89A}] => (Allow) C:\Users\AngryShadow\AppData\Local\Temp\net.exe
  548. FirewallRules: [{84FCF3B3-9EA4-4254-A9C3-180AC9A2D542}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
  549. FirewallRules: [{A06D0351-0623-4B1E-8EA3-8A11142EC479}] => (Allow) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
  550.  
  551. ==================== Restore Points =========================
  552.  
  553. ATTENTION: System Restore is disabled
  554.  
  555. ==================== Faulty Device Manager Devices =============
  556.  
  557.  
  558. ==================== Event log errors: =========================
  559.  
  560. Application errors:
  561. ==================
  562. Error: (01/16/2016 01:36:41 PM) (Source: Wininit) (EventID: 1015) (User: )
  563. Description: A critical system process, C:\WINDOWS\system32\lsass.exe, failed with status code 1. The machine must now be restarted.
  564.  
  565. Error: (01/16/2016 01:35:19 PM) (Source: Perflib) (EventID: 1008) (User: )
  566. Description: WmiApRplC:\WINDOWS\system32\wbem\wmiaprpl.dll4
  567.  
  568. Error: (01/16/2016 01:35:19 PM) (Source: Perflib) (EventID: 1023) (User: )
  569. Description: rdyboost4
  570.  
  571. Error: (01/16/2016 01:35:19 PM) (Source: PerfNet) (EventID: 2004) (User: )
  572. Description:
  573.  
  574. Error: (01/16/2016 01:35:19 PM) (Source: Perflib) (EventID: 1008) (User: )
  575. Description: MSDTCC:\WINDOWS\system32\msdtcuiu.DLL4
  576.  
  577. Error: (01/16/2016 01:35:19 PM) (Source: Perflib) (EventID: 1008) (User: )
  578. Description: LsaC:\Windows\System32\Secur32.dll4
  579.  
  580. Error: (01/16/2016 01:35:19 PM) (Source: Perflib) (EventID: 1008) (User: )
  581. Description: ESENTC:\WINDOWS\system32\esentprf.dll4
  582.  
  583. Error: (01/16/2016 01:35:19 PM) (Source: Perflib) (EventID: 1008) (User: )
  584. Description: BITSC:\Windows\System32\bitsperf.dll4
  585.  
  586. Error: (01/16/2016 01:35:13 PM) (Source: Application Error) (EventID: 1000) (User: )
  587. Description: Faulting application name: McAfee.TrueKey.Service.exe, version: 3.4.174.0, time stamp: 0x5667423f
  588. Faulting module name: MSVCP120.dll, version: 12.0.21005.1, time stamp: 0x524f8413
  589. Exception code: 0xc0000005
  590. Fault offset: 0x000000000000d2c5
  591. Faulting process ID: 0xb50
  592. Faulting application start time: 0xMcAfee.TrueKey.Service.exe0
  593. Faulting application path: McAfee.TrueKey.Service.exe1
  594. Faulting module path: McAfee.TrueKey.Service.exe2
  595. Report ID: McAfee.TrueKey.Service.exe3
  596. Faulting package full name: McAfee.TrueKey.Service.exe4
  597. Faulting package-relative application ID: McAfee.TrueKey.Service.exe5
  598.  
  599. Error: (01/16/2016 01:35:13 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
  600. Description: Application: McAfee.TrueKey.Service.exe
  601. Framework Version: v4.0.30319
  602. Description: The process was terminated due to an unhandled exception.
  603. Exception Info: System.AccessViolationException
  604. at <Module>.Intel.Pabe.Factor.FactorManager.GetFactorManager(std.shared_ptr<Intel::Pabe::Factor::FactorManager>*)
  605. at BCAAdapter.FactorManager..ctor()
  606. at McAfee.YAP.Service.Common.McBioBCAService.get_BCADeviceIdProvider()
  607. at McAfee.YAP.Service.Common.McBioBCAService.TryGetBcaProvisioningResults()
  608. at McAfee.YAP.Service.Common.McBioBCAService.GetBCAToken()
  609. at McAfee.YAP.Service.ServiceCommands.GetBCATokenCommand.Execute()
  610. at System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
  611. at System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
  612. at System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object)
  613. at System.Threading.ThreadHelper.ThreadStart()
  614.  
  615.  
  616. System errors:
  617. =============
  618. Error: (01/16/2016 09:18:43 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-MTUHMGO)
  619. Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}DESKTOP-MTUHMGOAngryShadowS-1-5-21-3985454009-819291025-207730266-1001LocalHost (Using LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742
  620.  
  621. Error: (01/16/2016 09:18:43 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-MTUHMGO)
  622. Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}DESKTOP-MTUHMGOAngryShadowS-1-5-21-3985454009-819291025-207730266-1001LocalHost (Using LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742
  623.  
  624. Error: (01/16/2016 09:18:43 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-MTUHMGO)
  625. Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}DESKTOP-MTUHMGOAngryShadowS-1-5-21-3985454009-819291025-207730266-1001LocalHost (Using LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742
  626.  
  627. Error: (01/16/2016 09:18:43 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-MTUHMGO)
  628. Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}DESKTOP-MTUHMGOAngryShadowS-1-5-21-3985454009-819291025-207730266-1001LocalHost (Using LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742
  629.  
  630. Error: (01/16/2016 09:18:43 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-MTUHMGO)
  631. Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}DESKTOP-MTUHMGOAngryShadowS-1-5-21-3985454009-819291025-207730266-1001LocalHost (Using LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742
  632.  
  633. Error: (01/16/2016 09:18:43 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-MTUHMGO)
  634. Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}DESKTOP-MTUHMGOAngryShadowS-1-5-21-3985454009-819291025-207730266-1001LocalHost (Using LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742
  635.  
  636. Error: (01/16/2016 09:18:43 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-MTUHMGO)
  637. Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}DESKTOP-MTUHMGOAngryShadowS-1-5-21-3985454009-819291025-207730266-1001LocalHost (Using LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742
  638.  
  639. Error: (01/16/2016 09:18:43 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-MTUHMGO)
  640. Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}DESKTOP-MTUHMGOAngryShadowS-1-5-21-3985454009-819291025-207730266-1001LocalHost (Using LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742
  641.  
  642. Error: (01/16/2016 09:18:43 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-MTUHMGO)
  643. Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}DESKTOP-MTUHMGOAngryShadowS-1-5-21-3985454009-819291025-207730266-1001LocalHost (Using LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742
  644.  
  645. Error: (01/16/2016 09:18:43 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-MTUHMGO)
  646. Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}DESKTOP-MTUHMGOAngryShadowS-1-5-21-3985454009-819291025-207730266-1001LocalHost (Using LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742
  647.  
  648.  
  649. CodeIntegrity:
  650. ===================================
  651. Date: 2016-01-14 03:18:14.105
  652. Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
  653.  
  654. Date: 2016-01-08 21:54:21.973
  655. Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
  656.  
  657. Date: 2016-01-08 16:30:29.222
  658. Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\winhttp.dll because the set of per-page image hashes could not be found on the system.
  659.  
  660. Date: 2016-01-08 16:30:29.216
  661. Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\winhttp.dll because the set of per-page image hashes could not be found on the system.
  662.  
  663. Date: 2016-01-07 21:57:26.535
  664. Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
  665.  
  666. Date: 2016-01-06 21:37:58.490
  667. Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
  668.  
  669. Date: 2016-01-03 20:08:22.989
  670. Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
  671.  
  672. Date: 2016-01-03 11:02:47.151
  673. Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
  674.  
  675. Date: 2016-01-01 11:08:57.325
  676. Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
  677.  
  678. Date: 2015-12-30 13:46:32.193
  679. Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
  680.  
  681.  
  682. ==================== Memory info ===========================
  683.  
  684. Processor: Intel(R) Core(TM) i5-4440S CPU @ 2.80GHz
  685. Percentage of memory in use: 50%
  686. Total physical RAM: 8131.18 MB
  687. Available physical RAM: 4037.92 MB
  688. Total Virtual: 9411.18 MB
  689. Available Virtual: 5491.39 MB
  690.  
  691. ==================== Drives ================================
  692.  
  693. Drive c: () (Fixed) (Total:118.69 GB) (Free:77.06 GB) NTFS
  694. Drive d: (AngryDisc) (Fixed) (Total:931.51 GB) (Free:272.1 GB) NTFS
  695.  
  696. ==================== MBR & Partition Table ==================
  697.  
  698. ========================================================
  699. Disk: 0 (Size: 119.2 GB) (Disk ID: 697E540A)
  700.  
  701. Partition: GPT.
  702.  
  703. ========================================================
  704. Disk: 1 (Size: 931.5 GB) (Disk ID: 00000000)
  705.  
  706. Partition: GPT.
  707.  
  708. ==================== End of Addition.txt ============================
  709.  
  710.  
  711.  
  712.  
  713.  
  714.  
  715.  
  716.  
  717. Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:10-01-2015 01
  718. Ran by AngryShadow (administrator) on DESKTOP-MTUHMGO (16-01-2016 23:11:11)
  719. Running from C:\Users\AngryShadow\Desktop
  720. Loaded Profiles: AngryShadow (Available Profiles: AngryShadow)
  721. Platform: Windows 10 Home Version 1511 (X64) Language: English (United Kingdom)
  722. Internet Explorer Version 11 (Default browser: Chrome)
  723. Boot Mode: Normal
  724. Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
  725.  
  726. ==================== Processes (Whitelisted) =================
  727.  
  728. (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
  729.  
  730. (McAfee, Inc.) C:\Windows\System32\mfevtps.exe
  731. (McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe
  732. (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
  733. (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
  734. (McAfee, Inc.) C:\Windows\System32\mfevtps.exe
  735. (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
  736. (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
  737. (McAfee, Inc.) C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe
  738. (McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
  739. (McAfee, Inc.) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
  740. (Microsoft Corporation) C:\Windows\System32\wlanext.exe
  741. (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
  742. (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
  743. (McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
  744. (Intel(R) Corporation) C:\Program Files\Intel\BCA\pabeSvc64.exe
  745. (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
  746. (McAfee, Inc.) C:\Program Files\McAfee\MSC\McAPExe.exe
  747. (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
  748. (McAfee Inc.) C:\Program Files\TrueKey\McAfee.TrueKey.Service.exe
  749. (Intel Corporation) C:\Program Files\TrueKey\McAfee.TrueKey.ServiceHelper.exe
  750. (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
  751. (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
  752. () C:\Program Files\WindowsApps\Microsoft.Messaging_2.12.15004.0_x86__8wekyb3d8bbwe\SkypeHost.exe
  753. (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
  754. (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
  755. (Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
  756. (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
  757. (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
  758. (Valve Corporation) D:\Steam\Steam.exe
  759. (Valve Corporation) D:\Steam\bin\steamwebhelper.exe
  760. (Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
  761. (Valve Corporation) D:\Steam\bin\steamwebhelper.exe
  762. (Valve Corporation) D:\Steam\bin\steamwebhelper.exe
  763. (McAfee, Inc.) C:\Program Files\Common Files\McAfee\CSP\1.8.203.0\McCSPServiceHost.exe
  764. (McAfee Inc.) C:\Program Files\TrueKey\McTkSchedulerService.exe
  765. () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_15.1208.10480.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
  766. (Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
  767. (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsStore_2015.25.15.0_x64__8wekyb3d8bbwe\WinStore.Mobile.exe
  768. (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.ZuneVideo_3.6.15731.0_x64__8wekyb3d8bbwe\Video.UI.exe
  769. (Microsoft Corporation) C:\Windows\System32\WWAHost.exe
  770. (Skype Technologies S.A.) D:\Skype\Phone\Skype.exe
  771. (BitTorrent Inc.) C:\Users\AngryShadow\AppData\Roaming\uTorrent\uTorrent.exe
  772. (BitTorrent Inc.) C:\Users\AngryShadow\AppData\Roaming\uTorrent\updates\3.4.5_41372\utorrentie.exe
  773. (BitTorrent Inc.) C:\Users\AngryShadow\AppData\Roaming\uTorrent\updates\3.4.5_41372\utorrentie.exe
  774. (McAfee, Inc.) C:\Program Files\Common Files\McAfee\Platform\McUICnt.exe
  775. (Disc Soft Ltd) C:\Users\AngryShadow\DAEMON Tools Pro\DiscSoftBusService.exe
  776. (Disc Soft Ltd) C:\Users\AngryShadow\DAEMON Tools Pro\DTShellHlp.exe
  777. Failed to access process -> sound.exe
  778. (SS) C:\Program Files (x86)\SwiftSearch_1.10.0.27\Service\swsesrvc.exe
  779. Failed to access process -> sound.exe
  780. Failed to access process -> sound.exe
  781. () C:\Program Files\WajaNetEn\6f7dd0d1a6b7295523cc41e34e4b9dfd.exe
  782. () C:\Program Files\WajaNetEn\7b1fae02d59a1789f5b8115c78fb3a25.exe
  783. () C:\Program Files\WajaNetEn\6f7dd0d1a6b7295523cc41e34e4b9dfd.exe
  784. (TData.com) C:\Program Files (x86)\TDataDld\TData.exe
  785. () C:\Program Files (x86)\Rockstar Games\GTA San Andreas\samp.exe
  786. (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
  787. (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
  788. (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
  789. (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
  790. (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
  791. (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
  792. (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
  793. (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
  794. (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
  795.  
  796.  
  797. ==================== Registry (Whitelisted) ===========================
  798.  
  799. (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
  800.  
  801. HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8725248 2015-11-09] (Realtek Semiconductor)
  802. HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1407744 2015-11-09] (Realtek Semiconductor)
  803. HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2785728 2016-01-09] (NVIDIA Corporation)
  804. HKLM\...\Run: [ShadowPlay] => "C:\WINDOWS\system32\rundll32.exe" C:\WINDOWS\system32\nvspcap64.dll,ShadowPlayOnSystemStart
  805. HKLM\...\Run: [MRT] => C:\WINDOWS\system32\MRT.exe [143671360 2016-01-15] (Microsoft Corporation)
  806. HKLM-x32\...\Run: [BlueStacks Agent] => C:\Program Files (x86)\BlueStacks\HD-Agent.exe
  807. HKLM-x32\...\Run: [51FBF9] => C:\Users\AngryShadow\AppData\Roaming\51FBF9\94C976.exe [1313280 2016-01-15] (Digia Plc and/or its subsidiary(-ies))
  808. HKLM-x32\...\RunOnce: [daemontoolspro] => [X]
  809. HKU\S-1-5-21-3985454009-819291025-207730266-1001\...\Run: [Steam] => D:\Steam\steam.exe [3013712 2015-12-14] (Valve Corporation)
  810. HKU\S-1-5-21-3985454009-819291025-207730266-1001\...\Run: [Skype] => D:\Skype\Phone\Skype.exe [50378880 2015-12-17] (Skype Technologies S.A.)
  811. HKU\S-1-5-21-3985454009-819291025-207730266-1001\...\Run: [uTorrent] => C:\Users\AngryShadow\AppData\Roaming\uTorrent\uTorrent.exe [2026520 2016-01-02] (BitTorrent Inc.)
  812. HKU\S-1-5-21-3985454009-819291025-207730266-1001\...\Run: [OtLandIPChanger] => "C:\Users\AngryShadow\Downloads\ipchanger.exe" /tray
  813. HKU\S-1-5-21-3985454009-819291025-207730266-1001\...\Run: [CyberGhost] => "C:\Program Files\CyberGhost 5\CyberGhost.exe" /autostart /min
  814. HKU\S-1-5-21-3985454009-819291025-207730266-1001\...\Run: [Gyazo] => C:\Program Files (x86)\Gyazo\GyStation.exe [3098424 2015-08-19] (Nota Inc.)
  815. HKU\S-1-5-21-3985454009-819291025-207730266-1001\...\Run: [DAEMON Tools Pro Agent] => C:\Users\AngryShadow\DAEMON Tools Pro\DTAgent.exe [4530520 2015-10-22] (Disc Soft Ltd)
  816. HKU\S-1-5-21-3985454009-819291025-207730266-1001\...\RunOnce: [Uninstall C:\Users\AngryShadow\AppData\Local\Microsoft\OneDrive\17.3.5892.0626\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\AngryShadow\AppData\Local\Microsoft\OneDrive\17.3.5892.0626\amd64"
  817. HKU\S-1-5-21-3985454009-819291025-207730266-1001\...\MountPoints2: {852846ab-b13a-11e5-b233-54271e79ff4c} - "K:\Autorun.exe"
  818. Lsa: [Notification Packages] scecli C:\Program Files\TrueKey\McAfeeTrueKeyPasswordFilter
  819.  
  820. ==================== Internet (Whitelisted) ====================
  821.  
  822. (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
  823.  
  824. ProxyServer: [S-1-5-21-3985454009-819291025-207730266-1001] => :80
  825. AutoConfigURL: [S-1-5-21-3985454009-819291025-207730266-1001] => hxxp://unstopp.me/wpad.dat?10059f1f5c50e7e6c53befa742ce03893862147
  826. Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
  827. Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
  828. Tcpip\..\Interfaces\{33665f72-7c60-4174-b287-638bf896bb50}: [DhcpNameServer] 192.168.1.1
  829.  
  830. Internet Explorer:
  831. ==================
  832. SearchScopes: HKU\S-1-5-21-3985454009-819291025-207730266-1001 -> DefaultScope {cf34d395-9ff1-49a0-98a5-8db1636431b1} URL =
  833. Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\McAfee\MSC\McSnIePl64.dll [2015-12-03] (McAfee, Inc.)
  834. Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\MSC\McSnIePl.dll [2015-12-03] (McAfee, Inc.)
  835.  
  836. FireFox:
  837. ========
  838. FF Plugin: @mcafee.com/MSC,version=10 -> c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL [2015-12-03] ()
  839. FF Plugin-x32: @mcafee.com/MSC,version=10 -> c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL [2015-12-03] ()
  840. FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2015-12-16] (NVIDIA Corporation)
  841. FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2015-12-16] (NVIDIA Corporation)
  842. FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2016-01-14] (Google Inc.)
  843. FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2016-01-14] (Google Inc.)
  844. FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK
  845. FF Extension: McAfee Anti-Spam Thunderbird Extension - C:\Program Files\McAfee\MSK [2016-01-14] [not signed]
  846.  
  847. Chrome:
  848. =======
  849. CHR HomePage: Profile 1 -> hxxp://www.yoursearching.com/?type=hp&ts=1452975515&z=374796605c0902467f0741ag7z7weoftam0w9w7gaw&from=exp2&uid=kingstonxrbu-sc400s37128g_50026b7244033f9e
  850. CHR StartupUrls: Profile 1 -> "hxxp://www.yoursearching.com/?type=hp&ts=1452975515&z=374796605c0902467f0741ag7z7weoftam0w9w7gaw&from=exp2&uid=kingstonxrbu-sc400s37128g_50026b7244033f9e"
  851. CHR DefaultSearchURL: Profile 1 -> hxxp://yoursearching.com/web?type=ds&ts=1452975515&z=374796605c0902467f0741ag7z7weoftam0w9w7gaw&from=exp2&uid=kingstonxrbu-sc400s37128g_50026b7244033f9e&q={searchTerms}
  852. CHR DefaultSearchKeyword: Profile 1 -> yoursearching
  853. CHR Profile: C:\Users\AngryShadow\AppData\Local\Google\Chrome\User Data\Default
  854. CHR Profile: C:\Users\AngryShadow\AppData\Local\Google\Chrome\User Data\Profile 1
  855. CHR Extension: (Google Slides) - C:\Users\AngryShadow\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-01-14]
  856. CHR Extension: (Google Docs) - C:\Users\AngryShadow\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2016-01-14]
  857. CHR Extension: (Google Drive) - C:\Users\AngryShadow\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-01-14]
  858. CHR Extension: (YouTube) - C:\Users\AngryShadow\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-01-14]
  859. CHR Extension: (Google Search) - C:\Users\AngryShadow\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2016-01-14]
  860. CHR Extension: (Google Sheets) - C:\Users\AngryShadow\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-01-14]
  861. CHR Extension: (Google Docs Offline) - C:\Users\AngryShadow\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-01-14]
  862. CHR Extension: (AdBlock) - C:\Users\AngryShadow\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2016-01-14]
  863. CHR Extension: (Ad.Block Super (V.1.12)) - C:\Users\AngryShadow\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gkbdoaboglbogefhhjdbidcglknljkpe [2016-01-14]
  864. CHR Extension: (Chrome Web Store Payments) - C:\Users\AngryShadow\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-01-14]
  865. CHR Extension: (Gmail) - C:\Users\AngryShadow\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-01-14]
  866.  
  867. ==================== Services (Whitelisted) ========================
  868.  
  869. (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
  870.  
  871. R3 Disc Soft Pro Bus Service; C:\Users\AngryShadow\DAEMON Tools Pro\DiscSoftBusService.exe [1292632 2015-10-22] (Disc Soft Ltd)
  872. R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1163200 2016-01-09] (NVIDIA Corporation)
  873. R2 HomeNetSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [451960 2015-11-02] (McAfee, Inc.)
  874. R2 IntelBCAsvc; C:\Program Files\Intel\BCA\pabeSvc64.exe [3070104 2015-11-20] (Intel(R) Corporation)
  875. R2 McAPExe; C:\Program Files\McAfee\MSC\McAPExe.exe [863448 2015-12-03] (McAfee, Inc.)
  876. R2 mccspsvc; C:\Program Files\Common Files\McAfee\CSP\1.8.203.0\McCSPServiceHost.exe [1694152 2015-12-02] (McAfee, Inc.)
  877. R2 McNaiAnn; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [451960 2015-11-02] (McAfee, Inc.)
  878. S3 McODS; C:\Program Files\McAfee\VirusScan\mcods.exe [679120 2015-10-20] (McAfee, Inc.)
  879. R2 mcpltsvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [451960 2015-11-02] (McAfee, Inc.)
  880. R2 McProxy; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [451960 2015-11-02] (McAfee, Inc.)
  881. R3 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [233680 2015-09-21] (McAfee, Inc.)
  882. R2 mfemms; C:\Program Files\Common Files\McAfee\SystemCore\\mfemms.exe [378848 2015-10-21] (McAfee, Inc.)
  883. R3 mfevtp; C:\WINDOWS\system32\mfevtps.exe [256840 2015-09-21] (McAfee, Inc.)
  884. R2 MSK80Service; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [451960 2015-11-02] (McAfee, Inc.)
  885. R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1879488 2016-01-09] (NVIDIA Corporation)
  886. R3 NvStreamNetworkSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [6308288 2016-01-09] (NVIDIA Corporation)
  887. R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [4812736 2016-01-09] (NVIDIA Corporation)
  888. S2 SkypeUpdate; D:\Skype\Updater\Updater.exe [327296 2015-07-09] (Skype Technologies)
  889. R2 swsesrvc_1.10.0.27; C:\Program Files (x86)\SwiftSearch_1.10.0.27\Service\swsesrvc.exe [301648 2015-10-23] (SS)
  890. R2 TDataSvr; C:\Program Files (x86)\TDataDld\TData.exe [204528 2016-01-15] (TData.com)
  891. R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [6889232 2015-12-14] (TeamViewer GmbH)
  892. R2 TrueKey; C:\Program Files\TrueKey\McAfee.TrueKey.Service.exe [796992 2015-12-08] (McAfee Inc.)
  893. R2 TrueKeyScheduler; C:\Program Files\TrueKey\McTkSchedulerService.exe [15224 2015-12-08] (McAfee Inc.)
  894. R2 TrueKeyServiceHelper; C:\Program Files\TrueKey\McAfee.TrueKey.ServiceHelper.exe [86864 2015-12-08] (Intel Corporation)
  895. R2 WajaNetEn Monitor; C:\Program Files\WajaNetEn\6f7dd0d1a6b7295523cc41e34e4b9dfd.exe [2829824 2016-01-13] () [File not signed]
  896. S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2015-10-30] (Microsoft Corporation)
  897. S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-10-30] (Microsoft Corporation)
  898.  
  899. ===================== Drivers (Whitelisted) ==========================
  900.  
  901. (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
  902.  
  903. S3 cfwids; C:\Windows\System32\drivers\cfwids.sys [80760 2015-09-23] (McAfee, Inc.)
  904. S3 dtlitescsibus; C:\Windows\System32\drivers\dtlitescsibus.sys [30264 2015-12-11] (Disc Soft Ltd)
  905. S3 dtliteusbbus; C:\Windows\System32\drivers\dtliteusbbus.sys [47672 2016-01-16] (Disc Soft Ltd)
  906. R3 dtproscsibus; C:\Windows\System32\drivers\dtproscsibus.sys [30264 2016-01-16] (Disc Soft Ltd)
  907. R3 e1dexpress; C:\Windows\system32\DRIVERS\e1d65x64.sys [541672 2015-08-23] (Intel Corporation)
  908. R3 MEIx64; C:\Windows\System32\drivers\TeeDriverW8x64.sys [195336 2015-11-09] (Intel Corporation)
  909. R3 mfeaack; C:\Windows\System32\drivers\mfeaack.sys [415976 2015-09-23] (McAfee, Inc.)
  910. R3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [351120 2015-09-23] (McAfee, Inc.)
  911. S0 mfeelamk; C:\Windows\System32\drivers\mfeelamk.sys [82072 2015-09-23] (McAfee, Inc.)
  912. R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [497888 2015-09-23] (McAfee, Inc.)
  913. R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [841944 2015-09-23] (McAfee, Inc.)
  914. R3 mfencbdc; C:\Windows\system32\DRIVERS\mfencbdc.sys [537192 2015-10-06] (McAfee, Inc.)
  915. S3 mfencrk; C:\Windows\system32\DRIVERS\mfencrk.sys [109480 2015-10-06] (McAfee, Inc.)
  916. R0 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [244544 2015-09-23] (McAfee, Inc.)
  917. R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [26560 2016-01-09] (NVIDIA Corporation)
  918. S3 NVSWCFilter; C:\Windows\System32\drivers\nvswcfilter.sys [28344 2015-10-15] (Windows (R) Win 7 DDK provider)
  919. R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [47760 2015-12-18] (NVIDIA Corporation)
  920. R3 RtkBtFilter; C:\Windows\system32\DRIVERS\RtkBtfilter.sys [593624 2015-12-11] (Realtek Semiconductor Corporation)
  921. R3 RTWlanE; C:\Windows\System32\drivers\rtwlane.sys [4705008 2015-09-03] (Realtek Semiconductor Corporation )
  922. R1 swsedrvr_vw_1_10_0_27; C:\Windows\System32\drivers\swsedrvr_vw_1_10_0_27.sys [57720 2015-10-23] (SS)
  923. R1 VBoxNetAdp; C:\Windows\system32\DRIVERS\VBoxNetAdp6.sys [117768 2015-12-18] (Oracle Corporation)
  924. R1 VBoxNetLwf; C:\Windows\system32\DRIVERS\VBoxNetLwf.sys [194976 2015-12-18] (Oracle Corporation)
  925. S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation)
  926. S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation)
  927. S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation)
  928. S3 VBoxNetFlt; \SystemRoot\system32\DRIVERS\VBoxNetFlt.sys [X]
  929. U3 wampapache64; no ImagePath
  930. S1 zrdkzifv; \??\C:\WINDOWS\system32\drivers\zrdkzifv.sys [X]
  931.  
  932. ==================== NetSvcs (Whitelisted) ===================
  933.  
  934. (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
  935.  
  936.  
  937. ==================== One Month Created files and folders ========
  938.  
  939. (If an entry is included in the fixlist, the file/folder will be moved.)
  940.  
  941. 2016-01-16 23:11 - 2016-01-16 23:11 - 00019113 _____ C:\Users\AngryShadow\Desktop\FRST.txt
  942. 2016-01-16 22:49 - 2016-01-16 22:49 - 00069381 _____ C:\Users\AngryShadow\Downloads\Addition.txt
  943. 2016-01-16 22:48 - 2016-01-16 23:11 - 00000000 ____D C:\FRST
  944. 2016-01-16 22:48 - 2016-01-16 22:49 - 00101498 _____ C:\Users\AngryShadow\Downloads\FRST.txt
  945. 2016-01-16 22:48 - 2016-01-16 22:48 - 02370560 _____ (Farbar) C:\Users\AngryShadow\Desktop\FRST64.exe
  946. 2016-01-16 21:19 - 2016-01-16 21:19 - 00000000 ____D C:\Program Files (x86)\TDataDld
  947. 2016-01-16 21:18 - 2016-01-16 21:19 - 00000000 ____D C:\Users\AngryShadow\AppData\Roaming\yoursearching
  948. 2016-01-16 21:04 - 2016-01-16 21:05 - 00000000 ____D C:\Program Files\WajaNetEn
  949. 2016-01-16 21:03 - 2016-01-16 21:03 - 00624696 _____ C:\Users\AngryShadow\AppData\Roaming\im201506.exe
  950. 2016-01-16 21:03 - 2016-01-16 21:03 - 00000000 _____ C:\Users\AngryShadow\AppData\Roaming\g78rfdsafhi
  951. 2016-01-16 21:02 - 2016-01-16 21:03 - 00000000 __SHD C:\Users\AngryShadow\AppData\Roaming\51FBF9
  952. 2016-01-16 21:02 - 2016-01-16 21:02 - 00004320 _____ C:\WINDOWS\System32\Tasks\SwiftSearch Auto Updater 1.10.0.27 Pending Update
  953. 2016-01-16 21:02 - 2016-01-16 21:02 - 00004290 _____ C:\WINDOWS\System32\Tasks\SwiftSearch Auto Updater 1.10.0.27 Core
  954. 2016-01-16 21:02 - 2016-01-16 21:02 - 00000000 ____D C:\Program Files (x86)\SwiftSearch_1.10.0.27
  955. 2016-01-16 21:01 - 2016-01-16 21:02 - 00000000 ____D C:\Users\AngryShadow\AppData\Roaming\DAEMON Tools Pro
  956. 2016-01-16 21:01 - 2016-01-16 21:01 - 00030264 _____ (Disc Soft Ltd) C:\WINDOWS\system32\Drivers\dtproscsibus.sys
  957. 2016-01-16 21:01 - 2016-01-16 21:01 - 00001858 _____ C:\Users\Public\Desktop\DAEMON Tools Pro.lnk
  958. 2016-01-16 21:00 - 2016-01-16 21:01 - 00000000 ____D C:\Users\AngryShadow\DAEMON Tools Pro
  959. 2016-01-16 20:56 - 2016-01-16 20:56 - 02940760 _____ (Disc Soft Ltd) C:\Users\AngryShadow\Downloads\DTProInstaller1.0.exe
  960. 2016-01-16 20:52 - 2016-01-16 20:52 - 00047672 _____ (Disc Soft Ltd) C:\WINDOWS\system32\Drivers\dtliteusbbus.sys
  961. 2016-01-16 20:49 - 2016-01-16 20:49 - 00689160 _____ (Disc Soft Ltd.) C:\Users\AngryShadow\Downloads\DTLiteInstaller.exe
  962. 2016-01-16 18:03 - 2016-01-16 18:03 - 00000000 ____D C:\Users\AngryShadow\Downloads\Fallout.4-CODEX
  963. 2016-01-16 18:02 - 2016-01-16 22:41 - 00000000 ____D C:\Users\AngryShadow\Downloads\Battlefield Hardline [R.G. Games]
  964. 2016-01-16 18:01 - 2016-01-16 18:01 - 00000000 ____D C:\Users\AngryShadow\AppData\LocalLow\uTorrent
  965. 2016-01-16 16:08 - 2016-01-16 16:08 - 00000000 ____D C:\Users\AngryShadow\Downloads\SFCRRPGv1.1
  966. 2016-01-16 16:07 - 2016-01-16 16:07 - 00281200 _____ C:\Users\AngryShadow\Downloads\SFCRRPGv1.1.zip
  967. 2016-01-16 16:07 - 2016-01-16 16:07 - 00000000 ____D C:\Users\AngryShadow\Desktop\SAMP
  968. 2016-01-16 16:06 - 2016-01-16 16:06 - 00000000 ____D C:\Users\AngryShadow\Desktop\txt docs
  969. 2016-01-16 16:03 - 2016-01-16 16:03 - 00633998 _____ C:\Users\AngryShadow\Downloads\Kallelse Psyk 160201.pdf
  970. 2016-01-16 13:39 - 2016-01-16 13:39 - 00000000 ____D C:\Users\AngryShadow\AppData\Local\Bluestacks
  971. 2016-01-16 13:38 - 2016-01-16 13:38 - 00000000 ___HD C:\OneDriveTemp
  972. 2016-01-16 13:35 - 2016-01-16 13:35 - 00000000 ____D C:\WINDOWS\AppReadiness
  973. 2016-01-16 13:31 - 2016-01-16 13:31 - 00000000 ____D C:\WINDOWS\LastGood.Tmp
  974. 2016-01-16 13:31 - 2015-12-18 07:10 - 00099472 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvaudcap64v.dll
  975. 2016-01-16 13:31 - 2015-12-18 07:10 - 00090768 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvaudcap32v.dll
  976. 2016-01-15 23:30 - 2016-01-15 23:30 - 00000000 ____D C:\Users\AngryShadow\Documents\Activision
  977. 2016-01-15 23:06 - 2016-01-15 23:06 - 00000000 ____D C:\Users\AngryShadow\AppData\Roaming\Macromedia
  978. 2016-01-15 22:02 - 2016-01-15 22:02 - 00000000 ____D C:\Users\AngryShadow\AppData\Roaming\Mozilla
  979. 2016-01-15 22:01 - 2016-01-15 22:01 - 00000000 ____D C:\Users\AngryShadow\AppData\Roaming\NVIDIA
  980. 2016-01-15 18:37 - 2016-01-15 18:37 - 00000000 ____D C:\Users\AngryShadow\Desktop\TOOLS
  981. 2016-01-15 18:27 - 2016-01-15 18:29 - 00000000 ____D C:\Users\AngryShadow\Desktop\HEHE
  982. 2016-01-15 14:33 - 2016-01-15 14:33 - 01723904 _____ (njq8) C:\Users\AngryShadow\AppData\LocalqQLUnlWnYN.exe
  983. 2016-01-15 14:33 - 2016-01-15 14:33 - 00353280 _____ (Microsoft Corporation) C:\Users\AngryShadow\AppData\LocalHEb_XBImVW.exe
  984. 2016-01-14 18:33 - 2015-12-18 17:08 - 00965440 _____ (Oracle Corporation) C:\WINDOWS\system32\Drivers\VBoxDrv.sys
  985. 2016-01-14 18:33 - 2015-12-18 17:08 - 00138904 _____ (Oracle Corporation) C:\WINDOWS\system32\Drivers\VBoxUSBMon.sys
  986. 2016-01-14 11:26 - 2016-01-14 11:26 - 00000000 ____D C:\Users\AngryShadow\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
  987. 2016-01-14 11:26 - 2016-01-14 11:26 - 00000000 ____D C:\Users\AngryShadow\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
  988. 2016-01-14 10:23 - 2016-01-14 10:23 - 00001989 _____ C:\Users\Public\Desktop\McAfee LiveSafe - Internet Security.lnk
  989. 2016-01-14 10:22 - 2016-01-14 10:23 - 00000000 ____D C:\Program Files\McAfee
  990. 2016-01-14 10:22 - 2016-01-14 10:22 - 00003138 _____ C:\WINDOWS\System32\Tasks\McAfeeLogon
  991. 2016-01-14 10:22 - 2016-01-14 10:22 - 00000000 ____D C:\Program Files\McAfee.com
  992. 2016-01-14 10:22 - 2016-01-14 10:22 - 00000000 ____D C:\Program Files (x86)\McAfee.com
  993. 2016-01-14 10:22 - 2015-09-23 09:43 - 00497888 _____ (McAfee, Inc.) C:\WINDOWS\system32\Drivers\mfefirek.sys
  994. 2016-01-14 10:22 - 2015-09-23 09:43 - 00244544 _____ (McAfee, Inc.) C:\WINDOWS\system32\Drivers\mfewfpk.sys
  995. 2016-01-14 10:22 - 2015-09-23 09:43 - 00082072 _____ (McAfee, Inc.) C:\WINDOWS\system32\Drivers\mfeelamk.sys
  996. 2016-01-14 10:22 - 2015-09-23 09:43 - 00080760 _____ (McAfee, Inc.) C:\WINDOWS\system32\Drivers\cfwids.sys
  997. 2016-01-14 10:20 - 2015-09-23 09:43 - 00841944 _____ (McAfee, Inc.) C:\WINDOWS\system32\Drivers\mfehidk.sys
  998. 2016-01-14 10:20 - 2015-09-23 09:43 - 00415976 _____ (McAfee, Inc.) C:\WINDOWS\system32\Drivers\mfeaack.sys
  999. 2016-01-14 10:20 - 2015-09-23 09:43 - 00351120 _____ (McAfee, Inc.) C:\WINDOWS\system32\Drivers\mfeavfk.sys
  1000. 2016-01-14 10:20 - 2015-09-21 13:33 - 00256840 _____ (McAfee, Inc.) C:\WINDOWS\system32\mfevtps.exe
  1001. 2016-01-14 10:16 - 2016-01-14 10:18 - 00000000 ____D C:\Users\AngryShadow\AppData\Local\tkdata
  1002. 2016-01-14 10:14 - 2016-01-14 10:23 - 00000000 ____D C:\Program Files (x86)\McAfee
  1003. 2016-01-14 10:14 - 2016-01-14 10:16 - 00000000 ____D C:\Program Files\TrueKey
  1004. 2016-01-14 10:14 - 2016-01-14 10:14 - 00001179 _____ C:\Users\Public\Desktop\True Key.lnk
  1005. 2016-01-14 10:14 - 2016-01-14 10:14 - 00000000 ____D C:\Program Files\Intel Security
  1006. 2016-01-14 10:14 - 2016-01-14 10:14 - 00000000 ____D C:\Program Files\Intel
  1007. 2016-01-14 10:14 - 2016-01-14 10:14 - 00000000 ____D C:\Program Files\Common Files\Intel
  1008. 2016-01-14 10:14 - 2016-01-14 10:14 - 00000000 ____D C:\Program Files\Common Files\AV
  1009. 2016-01-14 10:12 - 2016-01-14 10:23 - 00000000 ____D C:\Program Files\Common Files\McAfee
  1010. 2016-01-14 10:11 - 2016-01-16 22:16 - 00000940 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
  1011. 2016-01-14 10:11 - 2016-01-16 21:18 - 00002640 _____ C:\Users\Public\Desktop\Google Chrome.lnk
  1012. 2016-01-14 10:11 - 2016-01-16 13:38 - 00000936 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
  1013. 2016-01-14 10:11 - 2016-01-14 10:11 - 00003998 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
  1014. 2016-01-14 10:11 - 2016-01-14 10:11 - 00003766 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
  1015. 2016-01-14 10:11 - 2016-01-14 10:11 - 00000000 ____D C:\Users\AngryShadow\AppData\Local\Deployment
  1016. 2016-01-14 10:11 - 2016-01-14 10:11 - 00000000 ____D C:\Users\AngryShadow\AppData\Local\Apps\2.0
  1017. 2016-01-13 21:10 - 2016-01-13 21:10 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
  1018. 2016-01-13 13:05 - 2016-01-05 03:51 - 07477600 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
  1019. 2016-01-13 13:05 - 2016-01-05 03:51 - 01317640 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
  1020. 2016-01-13 13:05 - 2016-01-05 03:51 - 01141496 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
  1021. 2016-01-13 13:05 - 2016-01-05 03:50 - 01173344 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
  1022. 2016-01-13 13:05 - 2016-01-05 03:50 - 00713568 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
  1023. 2016-01-13 13:05 - 2016-01-05 03:50 - 00671472 _____ (Microsoft Corporation) C:\WINDOWS\system32\advapi32.dll
  1024. 2016-01-13 13:05 - 2016-01-05 03:49 - 00513888 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
  1025. 2016-01-13 13:05 - 2016-01-05 03:48 - 00499432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\advapi32.dll
  1026. 2016-01-13 13:05 - 2016-01-05 03:45 - 02587696 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6.dll
  1027. 2016-01-13 13:05 - 2016-01-05 03:42 - 02026736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml6.dll
  1028. 2016-01-13 13:05 - 2016-01-05 03:37 - 02544256 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
  1029. 2016-01-13 13:05 - 2016-01-05 03:37 - 01299504 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfnetsrc.dll
  1030. 2016-01-13 13:05 - 2016-01-05 03:37 - 00858952 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfnetcore.dll
  1031. 2016-01-13 13:05 - 2016-01-05 03:37 - 00848160 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
  1032. 2016-01-13 13:05 - 2016-01-05 03:37 - 00785088 _____ (Microsoft Corporation) C:\WINDOWS\system32\evr.dll
  1033. 2016-01-13 13:05 - 2016-01-05 03:37 - 00245840 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
  1034. 2016-01-13 13:05 - 2016-01-05 03:37 - 00234504 _____ (Microsoft Corporation) C:\WINDOWS\system32\mftranscode.dll
  1035. 2016-01-13 13:05 - 2016-01-05 03:36 - 00808800 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe
  1036. 2016-01-13 13:05 - 2016-01-05 03:33 - 02180128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
  1037. 2016-01-13 13:05 - 2016-01-05 03:33 - 01118208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfnetsrc.dll
  1038. 2016-01-13 13:05 - 2016-01-05 03:33 - 00709688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll
  1039. 2016-01-13 13:05 - 2016-01-05 03:33 - 00701384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfnetcore.dll
  1040. 2016-01-13 13:05 - 2016-01-05 03:33 - 00652312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\evr.dll
  1041. 2016-01-13 13:05 - 2016-01-05 03:33 - 00208176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mftranscode.dll
  1042. 2016-01-13 13:05 - 2016-01-05 03:33 - 00116728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfps.dll
  1043. 2016-01-13 13:05 - 2016-01-05 03:31 - 00703840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe
  1044. 2016-01-13 13:05 - 2016-01-05 03:27 - 01594408 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32.dll
  1045. 2016-01-13 13:05 - 2016-01-05 03:24 - 00796352 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
  1046. 2016-01-13 13:05 - 2016-01-05 03:23 - 01804664 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMALFXGFXDSP.dll
  1047. 2016-01-13 13:05 - 2016-01-05 03:23 - 01309376 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
  1048. 2016-01-13 13:05 - 2016-01-05 03:23 - 00786696 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMADMOD.DLL
  1049. 2016-01-13 13:05 - 2016-01-05 03:23 - 00119320 _____ (Microsoft Corporation) C:\WINDOWS\system32\MP3DMOD.DLL
  1050. 2016-01-13 13:05 - 2016-01-05 03:21 - 01371792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32.dll
  1051. 2016-01-13 13:05 - 2016-01-05 03:17 - 00695752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMADMOD.DLL
  1052. 2016-01-13 13:05 - 2016-01-05 03:16 - 00100160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MP3DMOD.DLL
  1053. 2016-01-13 13:05 - 2016-01-05 02:59 - 22393856 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
  1054. 2016-01-13 13:05 - 2016-01-05 02:57 - 16986112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
  1055. 2016-01-13 13:05 - 2016-01-05 02:57 - 00076288 _____ (Microsoft Corporation) C:\WINDOWS\system32\RMSRoamingSecurity.dll
  1056. 2016-01-13 13:05 - 2016-01-05 02:57 - 00043520 _____ (Microsoft Corporation) C:\WINDOWS\system32\usermgrcli.dll
  1057. 2016-01-13 13:05 - 2016-01-05 02:56 - 00145920 _____ (Microsoft Corporation) C:\WINDOWS\system32\omadmclient.exe
  1058. 2016-01-13 13:05 - 2016-01-05 02:54 - 00245760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BthLEEnum.sys
  1059. 2016-01-13 13:05 - 2016-01-05 02:54 - 00162816 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCensus.exe
  1060. 2016-01-13 13:05 - 2016-01-05 02:53 - 00148992 _____ (Microsoft Corporation) C:\WINDOWS\system32\wshom.ocx
  1061. 2016-01-13 13:05 - 2016-01-05 02:52 - 00210432 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll
  1062. 2016-01-13 13:05 - 2016-01-05 02:51 - 00472576 _____ (Microsoft Corporation) C:\WINDOWS\system32\DscCore.dll
  1063. 2016-01-13 13:05 - 2016-01-05 02:51 - 00248832 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserMgrProxy.dll
  1064. 2016-01-13 13:05 - 2016-01-05 02:50 - 00644096 _____ (Microsoft Corporation) C:\WINDOWS\system32\uReFS.dll
  1065. 2016-01-13 13:05 - 2016-01-05 02:50 - 00638464 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
  1066. 2016-01-13 13:05 - 2016-01-05 02:50 - 00208896 _____ (Microsoft Corporation) C:\WINDOWS\system32\storewuauth.dll
  1067. 2016-01-13 13:05 - 2016-01-05 02:49 - 13018624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
  1068. 2016-01-13 13:05 - 2016-01-05 02:49 - 01582080 _____ (Microsoft Corporation) C:\WINDOWS\system32\aitstatic.exe
  1069. 2016-01-13 13:05 - 2016-01-05 02:49 - 01255936 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMSPDMOE.DLL
  1070. 2016-01-13 13:05 - 2016-01-05 02:49 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
  1071. 2016-01-13 13:05 - 2016-01-05 02:49 - 00749056 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneService.dll
  1072. 2016-01-13 13:05 - 2016-01-05 02:49 - 00167936 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProximityCommon.dll
  1073. 2016-01-13 13:05 - 2016-01-05 02:48 - 01009152 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMSPDMOD.DLL
  1074. 2016-01-13 13:05 - 2016-01-05 02:48 - 00387072 _____ (Microsoft Corporation) C:\WINDOWS\system32\qdvd.dll
  1075. 2016-01-13 13:05 - 2016-01-05 02:48 - 00034816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\usermgrcli.dll
  1076. 2016-01-13 13:05 - 2016-01-05 02:47 - 00628736 _____ (Microsoft Corporation) C:\WINDOWS\system32\MessagingDataModel2.dll
  1077. 2016-01-13 13:05 - 2016-01-05 02:47 - 00479232 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll
  1078. 2016-01-13 13:05 - 2016-01-05 02:47 - 00305664 _____ (Microsoft Corporation) C:\WINDOWS\system32\ksproxy.ax
  1079. 2016-01-13 13:05 - 2016-01-05 02:45 - 00678912 _____ (Microsoft Corporation) C:\WINDOWS\system32\qedit.dll
  1080. 2016-01-13 13:05 - 2016-01-05 02:45 - 00275968 _____ (Microsoft Corporation) C:\WINDOWS\system32\facecredentialprovider.dll
  1081. 2016-01-13 13:05 - 2016-01-05 02:44 - 00125440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wshom.ocx
  1082. 2016-01-13 13:05 - 2016-01-05 02:43 - 00953856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthport.sys
  1083. 2016-01-13 13:05 - 2016-01-05 02:43 - 00912384 _____ (Microsoft Corporation) C:\WINDOWS\system32\usermgr.dll
  1084. 2016-01-13 13:05 - 2016-01-05 02:43 - 00604672 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
  1085. 2016-01-13 13:05 - 2016-01-05 02:43 - 00584704 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
  1086. 2016-01-13 13:05 - 2016-01-05 02:42 - 00166912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserMgrProxy.dll
  1087. 2016-01-13 13:05 - 2016-01-05 02:41 - 18677760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
  1088. 2016-01-13 13:05 - 2016-01-05 02:41 - 01070080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMSPDMOE.DLL
  1089. 2016-01-13 13:05 - 2016-01-05 02:41 - 00558592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\uReFS.dll
  1090. 2016-01-13 13:05 - 2016-01-05 02:40 - 00890880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMSPDMOD.DLL
  1091. 2016-01-13 13:05 - 2016-01-05 02:40 - 00123392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ProximityCommon.dll
  1092. 2016-01-13 13:05 - 2016-01-05 02:39 - 03428864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
  1093. 2016-01-13 13:05 - 2016-01-05 02:39 - 00569856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\qdvd.dll
  1094. 2016-01-13 13:05 - 2016-01-05 02:39 - 00498176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MessagingDataModel2.dll
  1095. 2016-01-13 13:05 - 2016-01-05 02:39 - 00235008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ksproxy.ax
  1096. 2016-01-13 13:05 - 2016-01-05 02:38 - 00389120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schannel.dll
  1097. 2016-01-13 13:05 - 2016-01-05 02:36 - 00573440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\qedit.dll
  1098. 2016-01-13 13:05 - 2016-01-05 02:36 - 00503296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
  1099. 2016-01-13 13:05 - 2016-01-05 02:33 - 01674240 _____ (Microsoft Corporation) C:\WINDOWS\system32\quartz.dll
  1100. 2016-01-13 13:05 - 2016-01-05 02:30 - 02796032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
  1101. 2016-01-13 13:05 - 2016-01-05 02:30 - 02280448 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
  1102. 2016-01-13 13:05 - 2016-01-05 02:29 - 03667456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
  1103. 2016-01-13 13:05 - 2016-01-05 02:28 - 07826432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
  1104. 2016-01-13 13:05 - 2016-01-05 02:28 - 04894720 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
  1105. 2016-01-13 13:05 - 2016-01-05 02:28 - 01542656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\quartz.dll
  1106. 2016-01-13 13:05 - 2016-01-05 02:25 - 05660160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
  1107. 2016-01-13 13:02 - 2016-01-16 13:45 - 00000000 ____D C:\Users\AngryShadow\AppData\Local\dxhr
  1108. 2016-01-13 13:02 - 2016-01-13 13:02 - 00000000 ____D C:\Users\AngryShadow\AppData\Local\238010
  1109. 2016-01-13 13:00 - 2016-01-13 13:37 - 00000000 ____D C:\WINDOWS\CbsTemp
  1110. 2016-01-13 12:54 - 2016-01-13 12:54 - 00000000 ____D C:\Users\AngryShadow\Documents\SavedGames
  1111. 2016-01-13 12:54 - 2016-01-13 12:54 - 00000000 ____D C:\Program Files (x86)\Microsoft XNA
  1112. 2016-01-12 14:17 - 2016-01-15 14:39 - 00000000 ____D C:\AdwCleaner
  1113. 2016-01-11 22:41 - 2016-01-11 22:41 - 00000000 ____D C:\Users\AngryShadow\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Fraps
  1114. 2016-01-10 09:29 - 2016-01-16 21:18 - 00001236 _____ C:\Users\AngryShadow\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Start Tor Browser.lnk
  1115. 2016-01-10 09:29 - 2016-01-16 21:18 - 00001188 _____ C:\Users\AngryShadow\Desktop\Start Tor Browser.lnk
  1116. 2016-01-10 09:29 - 2016-01-10 09:29 - 00000000 ____D C:\Users\AngryShadow\Desktop\Tor Browser
  1117. 2016-01-10 09:00 - 2016-01-10 09:00 - 00001902 _____ C:\csgo.amx
  1118. 2016-01-10 08:20 - 2016-01-10 08:20 - 00001921 _____ C:\Test.amx
  1119. 2016-01-09 13:54 - 2016-01-14 10:22 - 00000000 ____D C:\WINDOWS\System32\Tasks\McAfee
  1120. 2016-01-06 22:28 - 2016-01-06 22:58 - 05929984 ___SH (Microsoft Corp.) C:\Users\AngryShadow\AppData\Roaming\Gambino.exe
  1121. 2016-01-06 22:21 - 2016-01-08 13:14 - 00000000 ____D C:\Users\AngryShadow\AppData\Local\Image Rush
  1122. 2016-01-06 22:03 - 2016-01-16 18:46 - 00004176 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{1295A2DC-2BA2-4259-954A-9532CB94BC86}
  1123. 2016-01-06 22:00 - 2016-01-06 21:59 - 00000967 _____ C:\WINDOWS\system32\Drivers\etc\hp.bak
  1124. 2016-01-06 21:59 - 2016-01-06 22:03 - 00000000 ____D C:\Users\AngryShadow\AppData\Local\Opera Software
  1125. 2016-01-06 19:32 - 2016-01-06 19:32 - 00000000 ____D C:\Users\AngryShadow\AppData\Roaming\Gyazo
  1126. 2016-01-06 19:31 - 2016-01-06 23:00 - 00000000 ____D C:\Program Files (x86)\Gyazo
  1127. 2016-01-06 19:31 - 2016-01-06 19:31 - 00003568 _____ C:\WINDOWS\System32\Tasks\GyazoUpdateTaskMachineDaily
  1128. 2016-01-06 19:31 - 2016-01-06 19:31 - 00003432 _____ C:\WINDOWS\System32\Tasks\GyazoUpdateTaskMachine
  1129. 2016-01-06 19:31 - 2016-01-06 19:31 - 00001051 _____ C:\Users\Public\Desktop\Gyazo.lnk
  1130. 2016-01-06 19:31 - 2016-01-06 19:31 - 00001051 _____ C:\Users\Public\Desktop\Gyazo GIF.lnk
  1131. 2016-01-06 18:21 - 2016-01-06 18:21 - 00001047 _____ C:\Users\AngryShadow\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Optional Features.lnk
  1132. 2016-01-06 16:40 - 2016-01-06 16:40 - 00000000 ____D C:\Users\AngryShadow\AppData\LocalLow\Temp
  1133. 2016-01-06 13:09 - 2016-01-06 13:09 - 00000000 ____D C:\Users\AngryShadow\Documents\My Games
  1134. 2016-01-05 20:46 - 2016-01-05 20:46 - 00000000 ___RD C:\Users\AngryShadow\3D Objects
  1135. 2016-01-03 20:05 - 2016-01-03 20:05 - 00000000 ____D C:\Users\AngryShadow\AppData\Local\OTLand
  1136. 2016-01-02 19:43 - 2016-01-02 19:43 - 00000000 ____D C:\Users\AngryShadow\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Portforward.com
  1137. 2016-01-02 15:53 - 2016-01-13 15:04 - 00000000 ____D C:\Users\AngryShadow\Documents\GTA San Andreas User Files
  1138. 2016-01-02 15:53 - 2016-01-02 15:53 - 00000000 ____D C:\Users\AngryShadow\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\San Andreas Multiplayer
  1139. 2016-01-02 15:49 - 2016-01-02 15:49 - 00001926 _____ C:\Users\Public\Desktop\GTA San Andreas.lnk
  1140. 2016-01-02 15:49 - 2016-01-02 15:49 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
  1141. 2016-01-02 15:49 - 2016-01-02 15:49 - 00000000 ____D C:\Program Files (x86)\Rockstar Games
  1142. 2016-01-02 14:59 - 2016-01-02 14:59 - 00000000 ____D C:\Users\AngryShadow\AppData\Local\Disc_Soft_Ltd
  1143. 2016-01-02 14:57 - 2016-01-02 15:49 - 00000000 ____D C:\Users\AngryShadow\AppData\Roaming\DAEMON Tools Lite
  1144. 2016-01-02 14:47 - 2016-01-16 13:34 - 00002672 _____ C:\Users\AngryShadow\Desktop\µTorrent.lnk
  1145. 2016-01-02 14:46 - 2016-01-16 23:11 - 00000000 ____D C:\Users\AngryShadow\AppData\Roaming\uTorrent
  1146. 2015-12-31 19:44 - 2015-12-31 19:44 - 00000000 ____D C:\Users\AngryShadow\Documents\Criterion Games
  1147. 2015-12-30 23:48 - 2015-12-30 23:48 - 00000000 ____D C:\Users\AngryShadow\Documents\4A Games
  1148. 2015-12-30 19:46 - 2015-12-30 19:46 - 00000000 ____D C:\Users\AngryShadow\AppData\Roaming\WinRAR
  1149. 2015-12-30 19:46 - 2015-12-30 19:46 - 00000000 ____D C:\Users\AngryShadow\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
  1150. 2015-12-30 19:45 - 2015-12-30 19:46 - 00000000 ____D C:\Program Files\WinRAR
  1151. 2015-12-30 02:01 - 2010-06-02 04:55 - 00527192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_7.dll
  1152. 2015-12-30 02:01 - 2010-06-02 04:55 - 00518488 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_7.dll
  1153. 2015-12-30 02:01 - 2010-06-02 04:55 - 00239960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_7.dll
  1154. 2015-12-30 02:01 - 2010-06-02 04:55 - 00176984 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_7.dll
  1155. 2015-12-30 02:01 - 2010-06-02 04:55 - 00077656 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_5.dll
  1156. 2015-12-30 02:01 - 2010-06-02 04:55 - 00074072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_5.dll
  1157. 2015-12-30 02:01 - 2010-05-26 11:41 - 02526056 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_43.dll
  1158. 2015-12-30 02:01 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_43.dll
  1159. 2015-12-30 02:01 - 2010-05-26 11:41 - 01907552 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dcsx_43.dll
  1160. 2015-12-30 02:01 - 2010-05-26 11:41 - 01868128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dcsx_43.dll
  1161. 2015-12-30 02:01 - 2010-02-04 10:01 - 00530776 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_6.dll
  1162. 2015-12-30 02:01 - 2010-02-04 10:01 - 00528216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_6.dll
  1163. 2015-12-30 02:01 - 2010-02-04 10:01 - 00238936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_6.dll
  1164. 2015-12-30 02:01 - 2010-02-04 10:01 - 00176984 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_6.dll
  1165. 2015-12-30 02:01 - 2010-02-04 10:01 - 00078680 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_4.dll
  1166. 2015-12-30 02:01 - 2010-02-04 10:01 - 00074072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_4.dll
  1167. 2015-12-30 02:01 - 2010-02-04 10:01 - 00024920 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_7.dll
  1168. 2015-12-30 02:01 - 2010-02-04 10:01 - 00022360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\X3DAudio1_7.dll
  1169. 2015-12-30 02:01 - 2009-09-04 17:44 - 00517960 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_5.dll
  1170. 2015-12-30 02:01 - 2009-09-04 17:44 - 00515416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_5.dll
  1171. 2015-12-30 02:01 - 2009-09-04 17:44 - 00238936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_5.dll
  1172. 2015-12-30 02:01 - 2009-09-04 17:44 - 00176968 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_5.dll
  1173. 2015-12-30 02:01 - 2009-09-04 17:44 - 00073544 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_3.dll
  1174. 2015-12-30 02:01 - 2009-09-04 17:44 - 00069464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_3.dll
  1175. 2015-12-30 02:01 - 2009-09-04 17:29 - 05554512 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dcsx_42.dll
  1176. 2015-12-30 02:01 - 2009-09-04 17:29 - 05501792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dcsx_42.dll
  1177. 2015-12-30 02:01 - 2009-09-04 17:29 - 02582888 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_42.dll
  1178. 2015-12-30 02:01 - 2009-09-04 17:29 - 02475352 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_42.dll
  1179. 2015-12-30 02:01 - 2009-09-04 17:29 - 01974616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_42.dll
  1180. 2015-12-30 02:01 - 2009-09-04 17:29 - 01892184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_42.dll
  1181. 2015-12-30 02:01 - 2009-09-04 17:29 - 00523088 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_42.dll
  1182. 2015-12-30 02:01 - 2009-09-04 17:29 - 00453456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_42.dll
  1183. 2015-12-30 02:01 - 2009-09-04 17:29 - 00285024 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx11_42.dll
  1184. 2015-12-30 02:01 - 2009-09-04 17:29 - 00235344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx11_42.dll
  1185. 2015-12-30 02:01 - 2009-03-16 14:18 - 00521560 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_4.dll
  1186. 2015-12-30 02:01 - 2009-03-16 14:18 - 00517448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_4.dll
  1187. 2015-12-30 02:01 - 2009-03-16 14:18 - 00235352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_4.dll
  1188. 2015-12-30 02:01 - 2009-03-16 14:18 - 00174936 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_4.dll
  1189. 2015-12-30 02:01 - 2009-03-16 14:18 - 00024920 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_6.dll
  1190. 2015-12-30 02:01 - 2009-03-16 14:18 - 00022360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\X3DAudio1_6.dll
  1191. 2015-12-30 02:01 - 2009-03-09 15:27 - 05425496 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_41.dll
  1192. 2015-12-30 02:01 - 2009-03-09 15:27 - 04178264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_41.dll
  1193. 2015-12-30 02:01 - 2009-03-09 15:27 - 02430312 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_41.dll
  1194. 2015-12-30 02:01 - 2009-03-09 15:27 - 01846632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_41.dll
  1195. 2015-12-30 02:01 - 2009-03-09 15:27 - 00520544 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_41.dll
  1196. 2015-12-30 02:01 - 2009-03-09 15:27 - 00453456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_41.dll
  1197. 2015-12-30 02:01 - 2008-10-27 10:04 - 00518480 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_3.dll
  1198. 2015-12-30 02:01 - 2008-10-27 10:04 - 00514384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_3.dll
  1199. 2015-12-30 02:01 - 2008-10-27 10:04 - 00235856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_3.dll
  1200. 2015-12-30 02:01 - 2008-10-27 10:04 - 00175440 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_3.dll
  1201. 2015-12-30 02:01 - 2008-10-27 10:04 - 00074576 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_2.dll
  1202. 2015-12-30 02:01 - 2008-10-27 10:04 - 00070992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_2.dll
  1203. 2015-12-30 02:01 - 2008-10-27 10:04 - 00025936 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_5.dll
  1204. 2015-12-30 02:01 - 2008-10-27 10:04 - 00023376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\X3DAudio1_5.dll
  1205. 2015-12-30 02:01 - 2008-10-15 06:22 - 05631312 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_40.dll
  1206. 2015-12-30 02:01 - 2008-10-15 06:22 - 04379984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_40.dll
  1207. 2015-12-30 02:01 - 2008-10-15 06:22 - 02605920 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_40.dll
  1208. 2015-12-30 02:01 - 2008-10-15 06:22 - 02036576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_40.dll
  1209. 2015-12-30 02:01 - 2008-10-15 06:22 - 00519000 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_40.dll
  1210. 2015-12-30 02:01 - 2008-10-15 06:22 - 00452440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_40.dll
  1211. 2015-12-30 02:01 - 2008-07-31 10:41 - 00238088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_2.dll
  1212. 2015-12-30 02:01 - 2008-07-31 10:41 - 00177672 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_2.dll
  1213. 2015-12-30 02:01 - 2008-07-31 10:41 - 00072200 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_1.dll
  1214. 2015-12-30 02:01 - 2008-07-31 10:40 - 00513544 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_2.dll
  1215. 2015-12-30 02:01 - 2008-07-10 11:00 - 04992520 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_39.dll
  1216. 2015-12-30 02:01 - 2008-07-10 11:00 - 01942552 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_39.dll
  1217. 2015-12-30 02:01 - 2008-07-10 11:00 - 00540688 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_39.dll
  1218. 2015-12-30 02:01 - 2008-05-30 14:19 - 00511496 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_1.dll
  1219. 2015-12-30 02:01 - 2008-05-30 14:19 - 00507400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_1.dll
  1220. 2015-12-30 02:01 - 2008-05-30 14:18 - 00238088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_1.dll
  1221. 2015-12-30 02:01 - 2008-05-30 14:18 - 00177672 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_1.dll
  1222. 2015-12-30 02:01 - 2008-05-30 14:17 - 00068104 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_0.dll
  1223. 2015-12-30 02:01 - 2008-05-30 14:17 - 00065032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_0.dll
  1224. 2015-12-30 02:01 - 2008-05-30 14:17 - 00025608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\X3DAudio1_4.dll
  1225. 2015-12-30 02:01 - 2008-05-30 14:16 - 00028168 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_4.dll
  1226. 2015-12-30 02:01 - 2008-05-30 14:11 - 04991496 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_38.dll
  1227. 2015-12-30 02:01 - 2008-05-30 14:11 - 03850760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_38.dll
  1228. 2015-12-30 02:01 - 2008-05-30 14:11 - 01941528 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_38.dll
  1229. 2015-12-30 02:01 - 2008-05-30 14:11 - 01491992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_38.dll
  1230. 2015-12-30 02:01 - 2008-05-30 14:11 - 00540688 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_38.dll
  1231. 2015-12-30 02:01 - 2008-05-30 14:11 - 00467984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_38.dll
  1232. 2015-12-30 02:01 - 2008-03-05 16:04 - 00489480 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_0.dll
  1233. 2015-12-30 02:01 - 2008-03-05 16:03 - 00479752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_0.dll
  1234. 2015-12-30 02:01 - 2008-03-05 16:03 - 00238088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_0.dll
  1235. 2015-12-30 02:01 - 2008-03-05 16:03 - 00177672 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_0.dll
  1236. 2015-12-30 02:01 - 2008-03-05 16:00 - 00028168 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_3.dll
  1237. 2015-12-30 02:01 - 2008-03-05 16:00 - 00025608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\X3DAudio1_3.dll
  1238. 2015-12-30 02:01 - 2008-03-05 15:56 - 04910088 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_37.dll
  1239. 2015-12-30 02:01 - 2008-03-05 15:56 - 03786760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_37.dll
  1240. 2015-12-30 02:01 - 2008-03-05 15:56 - 01860120 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_37.dll
  1241. 2015-12-30 02:01 - 2008-03-05 15:56 - 01420824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_37.dll
  1242. 2015-12-30 02:01 - 2008-02-05 23:07 - 00529424 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_37.dll
  1243. 2015-12-30 02:01 - 2008-02-05 23:07 - 00462864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_37.dll
  1244. 2015-12-30 02:01 - 2007-10-22 03:40 - 00411656 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_10.dll
  1245. 2015-12-30 02:01 - 2007-10-22 03:39 - 00267272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_10.dll
  1246. 2015-12-30 02:01 - 2007-10-22 03:37 - 00021000 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_2.dll
  1247. 2015-12-30 02:01 - 2007-10-22 03:37 - 00017928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\X3DAudio1_2.dll
  1248. 2015-12-30 02:01 - 2007-10-12 15:14 - 05081608 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_36.dll
  1249. 2015-12-30 02:01 - 2007-10-12 15:14 - 03734536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_36.dll
  1250. 2015-12-30 02:01 - 2007-10-12 15:14 - 02006552 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_36.dll
  1251. 2015-12-30 02:01 - 2007-10-12 15:14 - 01374232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_36.dll
  1252. 2015-12-30 02:01 - 2007-10-02 09:56 - 00508264 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_36.dll
  1253. 2015-12-30 02:01 - 2007-10-02 09:56 - 00444776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_36.dll
  1254. 2015-12-30 02:01 - 2007-07-20 00:57 - 00411496 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_9.dll
  1255. 2015-12-30 02:01 - 2007-07-20 00:57 - 00267112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_9.dll
  1256. 2015-12-30 02:01 - 2007-07-19 18:14 - 05073256 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_35.dll
  1257. 2015-12-30 02:01 - 2007-07-19 18:14 - 03727720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_35.dll
  1258. 2015-12-30 02:01 - 2007-07-19 18:14 - 01985904 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_35.dll
  1259. 2015-12-30 02:01 - 2007-07-19 18:14 - 01358192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_35.dll
  1260. 2015-12-30 02:01 - 2007-07-19 18:14 - 00508264 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_35.dll
  1261. 2015-12-30 02:01 - 2007-07-19 18:14 - 00444776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_35.dll
  1262. 2015-12-30 02:01 - 2007-06-20 20:49 - 00409960 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_8.dll
  1263. 2015-12-30 02:01 - 2007-06-20 20:46 - 00266088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_8.dll
  1264. 2015-12-30 02:01 - 2007-05-16 16:45 - 04496232 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_34.dll
  1265. 2015-12-30 02:01 - 2007-05-16 16:45 - 03497832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_34.dll
  1266. 2015-12-30 02:01 - 2007-05-16 16:45 - 01401200 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_34.dll
  1267. 2015-12-30 02:01 - 2007-05-16 16:45 - 01124720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_34.dll
  1268. 2015-12-30 02:01 - 2007-05-16 16:45 - 00506728 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_34.dll
  1269. 2015-12-30 02:01 - 2007-05-16 16:45 - 00443752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_34.dll
  1270. 2015-12-30 02:01 - 2007-04-04 18:55 - 00403304 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_7.dll
  1271. 2015-12-30 02:01 - 2007-04-04 18:55 - 00261480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_7.dll
  1272. 2015-12-30 02:01 - 2007-04-04 18:54 - 00107368 _____ (Microsoft Corporation) C:\WINDOWS\system32\xinput1_3.dll
  1273. 2015-12-30 02:01 - 2007-04-04 18:53 - 00081768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xinput1_3.dll
  1274. 2015-12-30 02:01 - 2007-03-15 16:57 - 00506728 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_33.dll
  1275. 2015-12-30 02:01 - 2007-03-15 16:57 - 00443752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_33.dll
  1276. 2015-12-30 02:01 - 2007-03-12 16:42 - 04494184 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_33.dll
  1277. 2015-12-30 02:01 - 2007-03-12 16:42 - 03495784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_33.dll
  1278. 2015-12-30 02:01 - 2007-03-12 16:42 - 01400176 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_33.dll
  1279. 2015-12-30 02:01 - 2007-03-12 16:42 - 01123696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_33.dll
  1280. 2015-12-30 02:01 - 2007-03-05 12:42 - 00017688 _____ (Microsoft Corporation) C:\WINDOWS\system32\x3daudio1_1.dll
  1281. 2015-12-30 02:01 - 2007-03-05 12:42 - 00015128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\x3daudio1_1.dll
  1282. 2015-12-30 02:01 - 2007-01-24 15:27 - 00393576 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_6.dll
  1283. 2015-12-30 02:01 - 2007-01-24 15:27 - 00255848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_6.dll
  1284. 2015-12-30 02:01 - 2006-12-08 12:02 - 00251672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_5.dll
  1285. 2015-12-30 02:01 - 2006-12-08 12:00 - 00390424 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_5.dll
  1286. 2015-12-30 02:01 - 2006-11-29 13:06 - 04398360 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_32.dll
  1287. 2015-12-30 02:01 - 2006-11-29 13:06 - 03426072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_32.dll
  1288. 2015-12-30 02:01 - 2006-11-29 13:06 - 00469264 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10.dll
  1289. 2015-12-30 02:01 - 2006-11-29 13:06 - 00440080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10.dll
  1290. 2015-12-30 02:01 - 2006-09-28 16:05 - 03977496 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_31.dll
  1291. 2015-12-30 02:01 - 2006-09-28 16:05 - 02414360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_31.dll
  1292. 2015-12-30 02:01 - 2006-09-28 16:05 - 00237848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_4.dll
  1293. 2015-12-30 02:01 - 2006-09-28 16:04 - 00364824 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_4.dll
  1294. 2015-12-30 02:01 - 2006-07-28 09:31 - 00083736 _____ (Microsoft Corporation) C:\WINDOWS\system32\xinput1_2.dll
  1295. 2015-12-30 02:01 - 2006-07-28 09:30 - 00363288 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_3.dll
  1296. 2015-12-30 02:01 - 2006-07-28 09:30 - 00236824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_3.dll
  1297. 2015-12-30 02:01 - 2006-07-28 09:30 - 00062744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xinput1_2.dll
  1298. 2015-12-30 02:01 - 2006-05-31 07:24 - 00230168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_2.dll
  1299. 2015-12-30 02:01 - 2006-05-31 07:22 - 00354072 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_2.dll
  1300. 2015-12-30 02:01 - 2006-03-31 12:41 - 03927248 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_30.dll
  1301. 2015-12-30 02:01 - 2006-03-31 12:40 - 02388176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_30.dll
  1302. 2015-12-30 02:01 - 2006-03-31 12:40 - 00352464 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_1.dll
  1303. 2015-12-30 02:01 - 2006-03-31 12:39 - 00229584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_1.dll
  1304. 2015-12-30 02:01 - 2006-03-31 12:39 - 00083664 _____ (Microsoft Corporation) C:\WINDOWS\system32\xinput1_1.dll
  1305. 2015-12-30 02:01 - 2006-03-31 12:39 - 00062672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xinput1_1.dll
  1306. 2015-12-30 02:01 - 2006-02-03 08:43 - 03830992 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_29.dll
  1307. 2015-12-30 02:01 - 2006-02-03 08:43 - 02332368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_29.dll
  1308. 2015-12-30 02:01 - 2006-02-03 08:42 - 00355536 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_0.dll
  1309. 2015-12-30 02:01 - 2006-02-03 08:42 - 00230096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_0.dll
  1310. 2015-12-30 02:01 - 2006-02-03 08:41 - 00016592 _____ (Microsoft Corporation) C:\WINDOWS\system32\x3daudio1_0.dll
  1311. 2015-12-30 02:01 - 2006-02-03 08:41 - 00014032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\x3daudio1_0.dll
  1312. 2015-12-30 02:01 - 2005-12-05 18:09 - 03815120 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_28.dll
  1313. 2015-12-30 02:01 - 2005-12-05 18:09 - 02323664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_28.dll
  1314. 2015-12-30 02:01 - 2005-07-22 19:59 - 03807440 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_27.dll
  1315. 2015-12-30 02:01 - 2005-07-22 19:59 - 02319568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_27.dll
  1316. 2015-12-30 02:01 - 2005-05-26 15:34 - 03767504 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_26.dll
  1317. 2015-12-30 02:01 - 2005-05-26 15:34 - 02297552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_26.dll
  1318. 2015-12-30 02:01 - 2005-03-18 17:19 - 03823312 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_25.dll
  1319. 2015-12-30 02:01 - 2005-02-05 19:45 - 03544272 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_24.dll
  1320. 2015-12-30 02:01 - 2005-02-05 19:45 - 02222800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_24.dll
  1321. 2015-12-30 01:16 - 2015-12-30 01:17 - 00400639 _____ C:\Users\AngryShadow\Desktop\RAT_Logs.rar
  1322. 2015-12-30 00:58 - 2015-12-30 00:58 - 00000000 ____D C:\Users\AngryShadow\AppData\Roaming\TeamViewer
  1323. 2015-12-30 00:44 - 2016-01-06 18:25 - 00000000 ____D C:\Program Files (x86)\TeamViewer
  1324. 2015-12-30 00:44 - 2015-12-30 00:44 - 00001100 _____ C:\Users\Public\Desktop\TeamViewer 11.lnk
  1325. 2015-12-30 00:39 - 2015-12-30 00:39 - 00000889 _____ C:\Users\Public\Desktop\World of Warcraft.lnk
  1326. 2015-12-29 23:59 - 2015-12-29 23:59 - 00002206 _____ C:\Users\Public\Desktop\3D Vision Photo Viewer.lnk
  1327. 2015-12-29 23:59 - 2015-12-16 15:54 - 00523384 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshext.dll
  1328. 2015-12-29 23:59 - 2015-12-16 15:54 - 00075056 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshextr.dll
  1329. 2015-12-29 23:59 - 2015-12-16 15:19 - 00103216 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvStreaming.exe
  1330. 2015-12-29 23:58 - 2015-12-16 17:59 - 42976888 _____ C:\WINDOWS\system32\nvcompiler.dll
  1331. 2015-12-29 23:58 - 2015-12-16 17:59 - 37608568 _____ C:\WINDOWS\SysWOW64\nvcompiler.dll
  1332. 2015-12-29 23:58 - 2015-12-16 17:59 - 31098488 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglv64.dll
  1333. 2015-12-29 23:58 - 2015-12-16 17:59 - 24923768 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglv32.dll
  1334. 2015-12-29 23:58 - 2015-12-16 17:59 - 21131424 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvopencl.dll
  1335. 2015-12-29 23:58 - 2015-12-16 17:59 - 20672376 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll
  1336. 2015-12-29 23:58 - 2015-12-16 17:59 - 17568432 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvopencl.dll
  1337. 2015-12-29 23:58 - 2015-12-16 17:59 - 17164160 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll
  1338. 2015-12-29 23:58 - 2015-12-16 17:59 - 17104016 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvd3dumx.dll
  1339. 2015-12-29 23:58 - 2015-12-16 17:59 - 02560816 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll
  1340. 2015-12-29 23:58 - 2015-12-16 17:59 - 02214192 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll
  1341. 2015-12-29 23:58 - 2015-12-16 17:59 - 01915512 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6436143.dll
  1342. 2015-12-29 23:58 - 2015-12-16 17:59 - 01564976 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6436143.dll
  1343. 2015-12-29 23:58 - 2015-12-16 17:59 - 00938104 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll
  1344. 2015-12-29 23:58 - 2015-12-16 17:59 - 00872056 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll
  1345. 2015-12-29 23:58 - 2015-12-16 17:59 - 00786688 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncMFTH264.dll
  1346. 2015-12-29 23:58 - 2015-12-16 17:59 - 00735024 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll
  1347. 2015-12-29 23:58 - 2015-12-16 17:59 - 00681592 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll
  1348. 2015-12-29 23:58 - 2015-12-16 17:59 - 00632336 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncMFTH264.dll
  1349. 2015-12-29 23:58 - 2015-12-16 17:59 - 00541000 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvumdshimx.dll
  1350. 2015-12-29 23:58 - 2015-12-16 17:59 - 00445728 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvumdshim.dll
  1351. 2015-12-29 23:58 - 2015-12-16 17:59 - 00416560 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFROpenGL.dll
  1352. 2015-12-29 23:58 - 2015-12-16 17:59 - 00378784 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll
  1353. 2015-12-29 23:58 - 2015-12-16 17:59 - 00376440 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvDecMFTMjpeg.dll
  1354. 2015-12-29 23:58 - 2015-12-16 17:59 - 00370992 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFROpenGL.dll
  1355. 2015-12-29 23:58 - 2015-12-16 17:59 - 00339760 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvDecMFTMjpeg.dll
  1356. 2015-12-29 23:58 - 2015-12-16 17:59 - 00316960 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll
  1357. 2015-12-29 23:58 - 2015-12-16 17:59 - 00206968 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.dll
  1358. 2015-12-29 23:58 - 2015-12-16 17:59 - 00194680 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.dll
  1359. 2015-12-29 23:58 - 2015-12-16 17:59 - 00175368 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvinitx.dll
  1360. 2015-12-29 23:58 - 2015-12-16 17:59 - 00153208 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvinit.dll
  1361. 2015-12-29 23:58 - 2015-12-16 17:59 - 00151184 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglshim64.dll
  1362. 2015-12-29 23:58 - 2015-12-16 17:59 - 00128696 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglshim32.dll
  1363. 2015-12-29 23:58 - 2015-12-16 17:59 - 00039240 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvhdap64.dll
  1364. 2015-12-28 17:56 - 2015-12-28 17:56 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
  1365. 2015-12-28 15:57 - 2016-01-14 18:18 - 00000000 ____D C:\Users\AngryShadow\AppData\Local\CrashDumps
  1366. 2015-12-28 15:30 - 2015-12-28 15:30 - 00000000 ____D C:\Users\AngryShadow\AppData\Roaming\LolClient
  1367. 2015-12-28 13:39 - 2016-01-16 21:18 - 00001655 _____ C:\Users\Public\Desktop\League of Legends.lnk
  1368. 2015-12-28 13:39 - 2008-07-31 10:41 - 00068616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_1.dll
  1369. 2015-12-28 13:39 - 2008-07-31 10:40 - 00509448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_2.dll
  1370. 2015-12-28 13:39 - 2008-07-12 08:18 - 03851784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_39.dll
  1371. 2015-12-28 13:39 - 2008-07-12 08:18 - 01493528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_39.dll
  1372. 2015-12-28 13:39 - 2008-07-12 08:18 - 00467984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_39.dll
  1373. 2015-12-28 13:38 - 2015-12-28 13:39 - 00000000 ____D C:\Users\AngryShadow\AppData\Roaming\Riot Games
  1374. 2015-12-28 00:27 - 2016-01-16 13:38 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
  1375. 2015-12-28 00:26 - 2015-12-29 23:59 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
  1376. 2015-12-28 00:26 - 2015-12-28 00:26 - 00319059 _____ C:\WINDOWS\system32\Drivers\RTWAVES40.dat
  1377. 2015-12-28 00:26 - 2015-12-28 00:26 - 00006786 _____ C:\WINDOWS\system32\Drivers\rtwavesEFX.dat
  1378. 2015-12-28 00:26 - 2015-12-28 00:26 - 00002626 _____ C:\WINDOWS\system32\Drivers\rtwavesMFX.dat
  1379. 2015-12-28 00:26 - 2015-12-28 00:26 - 00000000 ____D C:\WINDOWS\SysWOW64\RTCOM
  1380. 2015-12-28 00:26 - 2015-12-28 00:26 - 00000000 ____D C:\Program Files\Realtek
  1381. 2015-12-28 00:26 - 2015-12-27 16:46 - 00000000 ____D C:\Program Files\NVIDIA Corporation
  1382. 2015-12-28 00:26 - 2015-12-16 15:54 - 06359672 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
  1383. 2015-12-28 00:26 - 2015-12-16 15:54 - 02985264 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc64.dll
  1384. 2015-12-28 00:26 - 2015-12-16 15:54 - 02554488 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll
  1385. 2015-12-28 00:26 - 2015-12-16 15:54 - 01256240 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvvsvc.exe
  1386. 2015-12-28 00:26 - 2015-12-16 15:54 - 00385328 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmctray.dll
  1387. 2015-12-28 00:26 - 2015-12-16 15:54 - 00062768 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll
  1388. 2015-12-28 00:26 - 2015-12-16 15:49 - 06090019 _____ C:\WINDOWS\system32\nvcoproc.bin
  1389. 2015-12-28 00:25 - 2015-12-30 13:43 - 00257792 _____ C:\WINDOWS\system32\FNTCACHE.DAT
  1390. 2015-12-28 00:25 - 2015-12-28 00:25 - 00000000 ____D C:\WINDOWS\ServiceProfiles
  1391. 2015-12-28 00:25 - 2015-12-28 00:25 - 00000000 ____D C:\Program Files\Common Files\logishrd
  1392. 2015-12-27 19:46 - 2015-12-27 19:46 - 00000000 ____D C:\Users\AngryShadow\AppData\Roaming\java
  1393. 2015-12-27 17:32 - 2016-01-15 15:35 - 143671360 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
  1394. 2015-12-27 17:32 - 2016-01-15 15:35 - 00000000 ____D C:\WINDOWS\system32\MRT
  1395. 2015-12-27 17:31 - 2015-12-09 04:39 - 00301728 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
  1396. 2015-12-27 16:47 - 2015-12-27 16:47 - 00000000 ____D C:\Users\AngryShadow\AppData\Local\NVIDIA Corporation
  1397. 2015-12-27 16:46 - 2016-01-16 13:31 - 00001450 _____ C:\Users\Public\Desktop\GeForce Experience.lnk
  1398. 2015-12-27 16:46 - 2016-01-09 08:22 - 01567504 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspcap.dll
  1399. 2015-12-27 16:46 - 2016-01-09 08:22 - 01316184 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspbridge.dll
  1400. 2015-12-27 16:46 - 2016-01-09 08:21 - 01902136 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspcap64.dll
  1401. 2015-12-27 16:46 - 2016-01-09 08:21 - 01756608 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspbridge64.dll
  1402. 2015-12-27 16:46 - 2016-01-09 08:21 - 00112032 _____ C:\WINDOWS\system32\NvRtmpStreamer64.dll
  1403. 2015-12-27 16:46 - 2015-12-30 13:49 - 00000000 ____D C:\Users\AngryShadow\AppData\Local\NVIDIA
  1404. 2015-12-27 16:46 - 2010-05-26 11:41 - 02401112 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_43.dll
  1405. 2015-12-27 16:46 - 2010-05-26 11:41 - 01998168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_43.dll
  1406. 2015-12-27 16:46 - 2010-05-26 11:41 - 00511328 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_43.dll
  1407. 2015-12-27 16:46 - 2010-05-26 11:41 - 00470880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_43.dll
  1408. 2015-12-27 16:46 - 2010-05-26 11:41 - 00276832 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx11_43.dll
  1409. 2015-12-27 16:46 - 2010-05-26 11:41 - 00248672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx11_43.dll
  1410. 2015-12-27 16:26 - 2015-12-27 16:26 - 00000000 ____D C:\Users\AngryShadow\AppData\Local\Blizzard
  1411. 2015-12-27 16:13 - 2015-12-27 16:13 - 00000840 _____ C:\Users\Public\Desktop\Hearthstone.lnk
  1412. 2015-12-27 16:12 - 2015-12-27 16:12 - 00000000 ____D C:\Users\AngryShadow\Tracing
  1413. 2015-12-27 16:11 - 2016-01-16 23:08 - 00000000 ____D C:\Users\AngryShadow\AppData\Roaming\Skype
  1414. 2015-12-27 16:11 - 2015-12-27 16:11 - 00002600 _____ C:\Users\Public\Desktop\Skype.lnk
  1415. 2015-12-27 16:11 - 2015-12-27 16:11 - 00000000 ____D C:\Program Files (x86)\Skype
  1416. 2015-12-27 16:10 - 2016-01-06 18:21 - 00000000 ____D C:\WINDOWS\OCR
  1417. 2015-12-27 16:10 - 2015-12-27 16:10 - 00008192 _____ C:\WINDOWS\system32\config\userdiff
  1418. 2015-12-27 16:10 - 2015-12-27 16:10 - 00000000 ____D C:\WINDOWS\Setup
  1419. 2015-12-27 16:10 - 2015-12-27 16:10 - 00000000 ____D C:\WINDOWS\InfusedApps
  1420. 2015-12-27 16:10 - 2015-12-27 16:10 - 00000000 ____D C:\Program Files (x86)\Reference Assemblies
  1421. 2015-12-27 16:10 - 2015-12-27 16:10 - 00000000 ____D C:\Program Files (x86)\MSBuild
  1422. 2015-12-27 16:10 - 2015-12-27 15:28 - 00000000 ___DC C:\WINDOWS\Panther
  1423. 2015-12-27 16:09 - 2015-12-27 16:09 - 00000000 ____D C:\WINDOWS\SysWOW64\winrm
  1424. 2015-12-27 16:09 - 2015-12-27 16:09 - 00000000 ____D C:\WINDOWS\SysWOW64\WCN
  1425. 2015-12-27 16:09 - 2015-12-27 16:09 - 00000000 ____D C:\WINDOWS\SysWOW64\sysprep
  1426. 2015-12-27 16:09 - 2015-12-27 16:09 - 00000000 ____D C:\WINDOWS\SysWOW64\slmgr
  1427. 2015-12-27 16:09 - 2015-12-27 16:09 - 00000000 ____D C:\WINDOWS\SysWOW64\Printing_Admin_Scripts
  1428. 2015-12-27 16:09 - 2015-12-27 16:09 - 00000000 ____D C:\WINDOWS\SysWOW64\0409
  1429. 2015-12-27 16:09 - 2015-12-27 16:09 - 00000000 ____D C:\WINDOWS\system32\winrm
  1430. 2015-12-27 16:09 - 2015-12-27 16:09 - 00000000 ____D C:\WINDOWS\system32\WCN
  1431. 2015-12-27 16:09 - 2015-12-27 16:09 - 00000000 ____D C:\WINDOWS\system32\slmgr
  1432. 2015-12-27 16:09 - 2015-12-27 16:09 - 00000000 ____D C:\WINDOWS\system32\Printing_Admin_Scripts
  1433. 2015-12-27 16:09 - 2015-12-27 16:09 - 00000000 ____D C:\WINDOWS\system32\0409
  1434. 2015-12-27 16:09 - 2015-12-27 16:09 - 00000000 ____D C:\Program Files\Reference Assemblies
  1435. 2015-12-27 16:09 - 2015-12-27 16:09 - 00000000 ____D C:\Program Files\MSBuild
  1436. 2015-12-27 16:08 - 2016-01-03 02:40 - 00826872 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
  1437. 2015-12-27 16:08 - 2016-01-03 02:40 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
  1438. 2015-12-27 16:07 - 2016-01-16 13:39 - 00000000 __RHD C:\Users\Public\Libraries
  1439. 2015-12-27 16:07 - 2016-01-14 10:22 - 00000000 ___HD C:\WINDOWS\ELAMBKUP
  1440. 2015-12-27 16:07 - 2016-01-14 03:15 - 00000000 ____D C:\WINDOWS\system32\appraiser
  1441. 2015-12-27 16:07 - 2016-01-13 17:20 - 00000000 ___HD C:\Program Files\WindowsApps
  1442. 2015-12-27 16:07 - 2016-01-09 22:24 - 00000000 ____D C:\WINDOWS\system32\NDF
  1443. 2015-12-27 16:07 - 2016-01-09 13:58 - 00000000 ____D C:\WINDOWS\system32\WinBioDatabase
  1444. 2015-12-27 16:07 - 2016-01-03 12:26 - 00000000 ____D C:\WINDOWS\rescache
  1445. 2015-12-27 16:07 - 2016-01-01 01:09 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
  1446. 2015-12-27 16:07 - 2015-12-28 03:37 - 00000000 ____D C:\WINDOWS\appcompat
  1447. 2015-12-27 16:07 - 2015-12-28 03:30 - 00000000 ___RD C:\WINDOWS\PurchaseDialog
  1448. 2015-12-27 16:07 - 2015-12-28 03:30 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel
  1449. 2015-12-27 16:07 - 2015-12-28 03:30 - 00000000 ____D C:\WINDOWS\SysWOW64\Dism
  1450. 2015-12-27 16:07 - 2015-12-28 03:30 - 00000000 ____D C:\WINDOWS\system32\SystemResetPlatform
  1451. 2015-12-27 16:07 - 2015-12-28 03:30 - 00000000 ____D C:\WINDOWS\system32\oobe
  1452. 2015-12-27 16:07 - 2015-12-28 03:30 - 00000000 ____D C:\WINDOWS\system32\Dism
  1453. 2015-12-27 16:07 - 2015-12-28 03:30 - 00000000 ____D C:\WINDOWS\Provisioning
  1454. 2015-12-27 16:07 - 2015-12-28 03:30 - 00000000 ____D C:\WINDOWS\bcastdvr
  1455. 2015-12-27 16:07 - 2015-12-28 00:26 - 00000000 ____D C:\WINDOWS\system32\Sysprep
  1456. 2015-12-27 16:07 - 2015-12-28 00:26 - 00000000 ____D C:\WINDOWS\Help
  1457. 2015-12-27 16:07 - 2015-12-27 16:25 - 00028672 _____ C:\WINDOWS\system32\config\BCD-Template
  1458. 2015-12-27 16:07 - 2015-12-27 16:09 - 00000000 ___SD C:\WINDOWS\SysWOW64\F12
  1459. 2015-12-27 16:07 - 2015-12-27 16:09 - 00000000 ___SD C:\WINDOWS\SysWOW64\DiagSvcs
  1460. 2015-12-27 16:07 - 2015-12-27 16:09 - 00000000 ___SD C:\WINDOWS\system32\F12
  1461. 2015-12-27 16:07 - 2015-12-27 16:09 - 00000000 ___SD C:\WINDOWS\system32\dsc
  1462. 2015-12-27 16:07 - 2015-12-27 16:09 - 00000000 ___SD C:\WINDOWS\system32\DiagSvcs
  1463. 2015-12-27 16:07 - 2015-12-27 16:09 - 00000000 ____D C:\WINDOWS\SysWOW64\setup
  1464. 2015-12-27 16:07 - 2015-12-27 16:09 - 00000000 ____D C:\WINDOWS\SysWOW64\oobe
  1465. 2015-12-27 16:07 - 2015-12-27 16:09 - 00000000 ____D C:\WINDOWS\SysWOW64\MUI
  1466. 2015-12-27 16:07 - 2015-12-27 16:09 - 00000000 ____D C:\WINDOWS\SysWOW64\Com
  1467. 2015-12-27 16:07 - 2015-12-27 16:09 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns
  1468. 2015-12-27 16:07 - 2015-12-27 16:09 - 00000000 ____D C:\WINDOWS\system32\setup
  1469. 2015-12-27 16:07 - 2015-12-27 16:09 - 00000000 ____D C:\WINDOWS\system32\MUI
  1470. 2015-12-27 16:07 - 2015-12-27 16:09 - 00000000 ____D C:\WINDOWS\system32\migwiz
  1471. 2015-12-27 16:07 - 2015-12-27 16:09 - 00000000 ____D C:\WINDOWS\system32\Com
  1472. 2015-12-27 16:07 - 2015-12-27 16:09 - 00000000 ____D C:\WINDOWS\PolicyDefinitions
  1473. 2015-12-27 16:07 - 2015-12-27 16:09 - 00000000 ____D C:\WINDOWS\IME
  1474. 2015-12-27 16:07 - 2015-12-27 16:09 - 00000000 ____D C:\Program Files\Windows Photo Viewer
  1475. 2015-12-27 16:07 - 2015-12-27 16:09 - 00000000 ____D C:\Program Files\Windows Journal
  1476. 2015-12-27 16:07 - 2015-12-27 16:09 - 00000000 ____D C:\Program Files\Windows Defender
  1477. 2015-12-27 16:07 - 2015-12-27 16:09 - 00000000 ____D C:\Program Files\Common Files\System
  1478. 2015-12-27 16:07 - 2015-12-27 16:09 - 00000000 ____D C:\Program Files (x86)\Windows Photo Viewer
  1479. 2015-12-27 16:07 - 2015-12-27 16:09 - 00000000 ____D C:\Program Files (x86)\Windows Defender
  1480. 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 __SHD C:\Program Files\Windows Sidebar
  1481. 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 __SHD C:\Program Files (x86)\Windows Sidebar
  1482. 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 __RSD C:\WINDOWS\Media
  1483. 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ___SD C:\WINDOWS\SysWOW64\Nui
  1484. 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ___SD C:\WINDOWS\SysWOW64\Configuration
  1485. 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ___SD C:\WINDOWS\system32\Nui
  1486. 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ___SD C:\WINDOWS\system32\Configuration
  1487. 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ___RD C:\WINDOWS\Offline Web Pages
  1488. 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ___RD C:\WINDOWS\DesktopTileResources
  1489. 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\Web
  1490. 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\Vss
  1491. 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\tracing
  1492. 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\TAPI
  1493. 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
  1494. 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\SysWOW64\SMI
  1495. 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\SysWOW64\ras
  1496. 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\SysWOW64\NDF
  1497. 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\SysWOW64\MsDtc
  1498. 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\SysWOW64\migwiz
  1499. 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\SysWOW64\MailContactsCalendarSync
  1500. 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\SysWOW64\Macromed
  1501. 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\SysWOW64\Ipmi
  1502. 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\SysWOW64\InputMethod
  1503. 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\SysWOW64\inetsrv
  1504. 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\SysWOW64\IME
  1505. 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\SysWOW64\icsxml
  1506. 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\SysWOW64\GroupPolicyUsers
  1507. 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\SysWOW64\GroupPolicy
  1508. 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\SysWOW64\FxsTmp
  1509. 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\SysWOW64\downlevel
  1510. 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\SysWOW64\Bthprops
  1511. 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\SysWOW64\AppLocker
  1512. 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\SysWOW64\AdvancedInstallers
  1513. 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\SystemResources
  1514. 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\SystemApps
  1515. 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\system32\WinMetadata
  1516. 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\system32\winevt
  1517. 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\system32\SecureBootUpdates
  1518. 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\system32\ras
  1519. 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\system32\ProximityToast
  1520. 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\system32\PointOfService
  1521. 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\system32\MsDtc
  1522. 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\system32\MailContactsCalendarSync
  1523. 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\system32\Macromed
  1524. 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\system32\Ipmi
  1525. 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\system32\InputMethod
  1526. 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\system32\inetsrv
  1527. 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\system32\IME
  1528. 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\system32\icsxml
  1529. 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\system32\ias
  1530. 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\system32\GroupPolicyUsers
  1531. 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\system32\GroupPolicy
  1532. 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\system32\downlevel
  1533. 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\system32\config\Journal
  1534. 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\system32\Bthprops
  1535. 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\system32\AppLocker
  1536. 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\system32\AdvancedInstallers
  1537. 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\System
  1538. 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\SKB
  1539. 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\ShellNew
  1540. 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\security
  1541. 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\schemas
  1542. 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\SchCache
  1543. 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\Resources
  1544. 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\Registration
  1545. 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\PLA
  1546. 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\Performance
  1547. 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\L2Schemas
  1548. 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\InputMethod
  1549. 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\Globalization
  1550. 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\Cursors
  1551. 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\Branding
  1552. 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\addins
  1553. 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\Program Files\Windows Portable Devices
  1554. 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\Program Files\Windows NT
  1555. 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\Program Files\Windows Multimedia Platform
  1556. 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\Program Files\Common Files\Services
  1557. 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\Program Files (x86)\Windows Portable Devices
  1558. 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\Program Files (x86)\Windows NT
  1559. 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\Program Files (x86)\Windows Multimedia Platform
  1560. 2015-12-27 16:07 - 2015-12-27 16:06 - 00230912 _____ (Microsoft Corporation) C:\WINDOWS\system32\msclmd.dll
  1561. 2015-12-27 16:07 - 2015-12-27 16:06 - 00215943 _____ C:\WINDOWS\SysWOW64\dssec.dat
  1562. 2015-12-27 16:07 - 2015-12-27 16:06 - 00215943 _____ C:\WINDOWS\system32\dssec.dat
  1563. 2015-12-27 16:07 - 2015-12-27 16:06 - 00209408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msclmd.dll
  1564. 2015-12-27 16:07 - 2015-12-27 16:06 - 00017463 _____ C:\WINDOWS\system32\Drivers\etc\services
  1565. 2015-12-27 16:07 - 2015-12-27 16:06 - 00015462 _____ C:\WINDOWS\system32\OEMDefaultAssociations.xml
  1566. 2015-12-27 16:07 - 2015-12-27 16:06 - 00008798 _____ C:\WINDOWS\SysWOW64\icrav03.rat
  1567. 2015-12-27 16:07 - 2015-12-27 16:06 - 00008798 _____ C:\WINDOWS\system32\icrav03.rat
  1568. 2015-12-27 16:07 - 2015-12-27 16:06 - 00003683 _____ C:\WINDOWS\system32\Drivers\etc\lmhosts.sam
  1569. 2015-12-27 16:07 - 2015-12-27 16:06 - 00001988 _____ C:\WINDOWS\SysWOW64\ticrf.rat
  1570. 2015-12-27 16:07 - 2015-12-27 16:06 - 00001988 _____ C:\WINDOWS\system32\ticrf.rat
  1571. 2015-12-27 16:07 - 2015-12-27 16:06 - 00001358 _____ C:\WINDOWS\system32\Drivers\etc\protocol
  1572. 2015-12-27 16:07 - 2015-12-27 16:06 - 00000858 _____ C:\WINDOWS\system32\DefaultQuestions.json
  1573. 2015-12-27 16:07 - 2015-12-27 16:06 - 00000741 _____ C:\WINDOWS\SysWOW64\NOISE.DAT
  1574. 2015-12-27 16:07 - 2015-12-27 16:06 - 00000741 _____ C:\WINDOWS\system32\NOISE.DAT
  1575. 2015-12-27 16:07 - 2015-12-27 16:06 - 00000407 _____ C:\WINDOWS\system32\Drivers\etc\networks
  1576. 2015-12-27 16:07 - 2015-12-27 16:06 - 00000389 _____ C:\WINDOWS\system32\AutoWorkplace.exe.config
  1577. 2015-12-27 16:07 - 2015-12-27 16:06 - 00000219 _____ C:\WINDOWS\system.ini
  1578. 2015-12-27 16:07 - 2015-12-27 16:06 - 00000092 _____ C:\WINDOWS\win.ini
  1579. 2015-12-27 16:07 - 2015-12-27 15:45 - 00000000 ___RD C:\WINDOWS\DevicesFlow
  1580. 2015-12-27 16:07 - 2015-12-27 15:29 - 00000000 ___RD C:\WINDOWS\PrintDialog
  1581. 2015-12-27 16:07 - 2015-12-27 15:29 - 00000000 ___RD C:\WINDOWS\MiracastView
  1582. 2015-12-27 16:07 - 2015-12-27 15:28 - 00000000 ____D C:\WINDOWS\system32\spool
  1583. 2015-12-27 16:07 - 2015-12-27 15:28 - 00000000 ____D C:\WINDOWS\system32\FxsTmp
  1584. 2015-12-27 16:06 - 2016-01-16 21:01 - 00000000 ____D C:\WINDOWS\INF
  1585. 2015-12-27 16:02 - 2016-01-16 13:37 - 00262144 ___SH C:\WINDOWS\system32\config\BBI
  1586. 2015-12-27 16:02 - 2016-01-14 10:23 - 00032768 ___SH C:\WINDOWS\system32\config\ELAM
  1587. 2015-12-27 16:02 - 2015-12-27 16:09 - 00000000 ____D C:\WINDOWS\servicing
  1588. 2015-12-27 16:02 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\system32\SMI
  1589. 2015-12-27 16:02 - 2015-12-27 16:02 - 00000000 ____D C:\Users\AngryShadow\AppData\Local\Steam
  1590. 2015-12-27 16:02 - 2015-12-27 16:02 - 00000000 ____D C:\Users\AngryShadow\AppData\Local\CEF
  1591. 2015-12-27 16:02 - 2015-12-27 16:02 - 00000000 ____D C:\Users\AngryShadow\AppData\Local\Blizzard Entertainment
  1592. 2015-12-27 16:02 - 2015-10-30 07:33 - 00000164 _____ C:\WINDOWS\system32\config\FP
  1593. 2015-12-27 16:01 - 2016-01-16 13:25 - 00000000 ____D C:\Users\AngryShadow\AppData\Local\Battle.net
  1594. 2015-12-27 16:01 - 2015-12-27 16:04 - 00000000 ____D C:\Users\AngryShadow\AppData\Roaming\Battle.net
  1595. 2015-12-27 16:01 - 2015-12-27 16:01 - 00000711 _____ C:\Users\Public\Desktop\Battle.net.lnk
  1596. 2015-12-27 15:59 - 2015-12-27 15:59 - 00000558 _____ C:\Users\Public\Desktop\Steam.lnk
  1597. 2015-12-27 15:46 - 2015-12-27 15:46 - 00000000 ____D C:\Users\AngryShadow\AppData\Local\Comms
  1598. 2015-12-27 15:36 - 2015-12-27 15:36 - 00000000 ____D C:\Users\AngryShadow\AppData\Local\NetworkTiles
  1599. 2015-12-27 15:33 - 2016-01-16 13:44 - 00879220 _____ C:\WINDOWS\system32\PerfStringBackup.INI
  1600. 2015-12-27 15:31 - 2016-01-16 13:38 - 00000000 ___RD C:\Users\AngryShadow\OneDrive
  1601. 2015-12-27 15:31 - 2016-01-14 10:11 - 00000000 ____D C:\Users\AngryShadow\AppData\Local\Google
  1602. 2015-12-27 15:31 - 2016-01-14 10:11 - 00000000 ____D C:\Program Files (x86)\Google
  1603. 2015-12-27 15:31 - 2015-12-27 15:31 - 00002381 _____ C:\Users\AngryShadow\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
  1604. 2015-12-27 15:31 - 2015-12-27 15:31 - 00000000 ____D C:\Users\AngryShadow\AppData\Local\MicrosoftEdge
  1605. 2015-12-27 15:31 - 2015-12-27 15:31 - 00000000 ____D C:\Users\AngryShadow\AppData\Local\ActiveSync
  1606. 2015-12-27 15:29 - 2016-01-16 21:00 - 00000000 ____D C:\Users\AngryShadow
  1607. 2015-12-27 15:29 - 2016-01-10 09:57 - 00000000 ____D C:\Users\AngryShadow\AppData\Local\VirtualStore
  1608. 2015-12-27 15:29 - 2016-01-06 22:40 - 00000000 __RHD C:\Users\Public\AccountPictures
  1609. 2015-12-27 15:29 - 2016-01-06 18:20 - 00000000 ____D C:\Users\AngryShadow\AppData\Local\Packages
  1610. 2015-12-27 15:29 - 2015-12-27 15:29 - 00000020 ___SH C:\Users\AngryShadow\ntuser.ini
  1611. 2015-12-27 15:29 - 2015-12-27 15:29 - 00000000 ____D C:\Users\AngryShadow\AppData\Roaming\Adobe
  1612. 2015-12-27 15:29 - 2015-12-27 15:29 - 00000000 ____D C:\Users\AngryShadow\AppData\Local\TileDataLayer
  1613. 2015-12-27 15:29 - 2015-12-27 15:29 - 00000000 ____D C:\Users\AngryShadow\AppData\Local\Publishers
  1614. 2015-12-27 15:28 - 2015-10-30 08:17 - 02718208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
  1615. 2015-12-19 22:35 - 2015-12-27 16:25 - 00000000 ___HD C:\$SysReset
  1616. 2015-12-18 17:08 - 2015-12-18 17:08 - 00194976 _____ (Oracle Corporation) C:\WINDOWS\system32\Drivers\VBoxNetLwf.sys
  1617. 2015-12-18 17:08 - 2015-12-18 17:08 - 00117768 _____ (Oracle Corporation) C:\WINDOWS\system32\Drivers\VBoxNetAdp6.sys
  1618. 2015-12-18 16:52 - 2015-12-07 05:57 - 00973664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll
  1619. 2015-12-18 16:52 - 2015-12-07 05:55 - 01281376 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll
  1620. 2015-12-18 16:52 - 2015-12-07 05:48 - 01155944 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfasfsrcsnk.dll
  1621. 2015-12-18 16:52 - 2015-12-07 05:48 - 00983464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfasfsrcsnk.dll
  1622. 2015-12-18 16:52 - 2015-12-07 05:48 - 00823264 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll
  1623. 2015-12-18 16:52 - 2015-12-07 05:48 - 00696160 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupEngine.dll
  1624. 2015-12-18 16:52 - 2015-12-07 05:47 - 00716928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll
  1625. 2015-12-18 16:52 - 2015-12-07 05:46 - 03671888 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
  1626. 2015-12-18 16:52 - 2015-12-07 05:46 - 02919320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
  1627. 2015-12-18 16:52 - 2015-12-07 05:10 - 00824320 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcWebFilter.dll
  1628. 2015-12-18 16:52 - 2015-12-07 04:58 - 24601600 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
  1629. 2015-12-18 16:52 - 2015-12-07 04:53 - 19339264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
  1630. 2015-12-18 16:52 - 2015-12-07 04:51 - 01318912 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifinetworkmanager.dll
  1631. 2015-12-18 16:52 - 2015-12-07 04:45 - 02582016 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
  1632. 2015-12-18 16:52 - 2015-12-07 04:43 - 02598400 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll
  1633. 2015-12-18 16:52 - 2015-12-07 04:41 - 02061824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
  1634. 2015-12-18 16:52 - 2015-12-07 04:40 - 01995776 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActiveSyncProvider.dll
  1635. 2015-12-18 16:52 - 2015-12-07 04:40 - 01706496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActiveSyncProvider.dll
  1636. 2015-12-18 16:51 - 2015-12-07 05:49 - 00412512 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifitask.exe
  1637. 2015-12-18 16:51 - 2015-12-07 05:48 - 01092456 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll
  1638. 2015-12-18 16:51 - 2015-12-07 05:48 - 01065080 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll
  1639. 2015-12-18 16:51 - 2015-12-07 05:48 - 01020096 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsrcsnk.dll
  1640. 2015-12-18 16:51 - 2015-12-07 05:48 - 00884256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll
  1641. 2015-12-18 16:51 - 2015-12-07 05:48 - 00794888 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfds.dll
  1642. 2015-12-18 16:51 - 2015-12-07 05:48 - 00670928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfds.dll
  1643. 2015-12-18 16:51 - 2015-12-07 05:48 - 00526856 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfreadwrite.dll
  1644. 2015-12-18 16:51 - 2015-12-07 05:48 - 00502112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupEngine.dll
  1645. 2015-12-18 16:51 - 2015-12-07 05:48 - 00498448 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFCaptureEngine.dll
  1646. 2015-12-18 16:51 - 2015-12-07 05:48 - 00462760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfreadwrite.dll
  1647. 2015-12-18 16:51 - 2015-12-07 05:48 - 00450904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFCaptureEngine.dll
  1648. 2015-12-18 16:51 - 2015-12-07 05:48 - 00337840 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFPlay.dll
  1649. 2015-12-18 16:51 - 2015-12-07 05:48 - 00289248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFPlay.dll
  1650. 2015-12-18 16:51 - 2015-12-07 05:48 - 00115040 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupApi.dll
  1651. 2015-12-18 16:51 - 2015-12-07 05:48 - 00084832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupApi.dll
  1652. 2015-12-18 16:51 - 2015-12-07 05:47 - 00925064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll
  1653. 2015-12-18 16:51 - 2015-12-07 05:47 - 00898184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsrcsnk.dll
  1654. 2015-12-18 16:51 - 2015-12-07 05:45 - 00264544 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContentDeliveryManager.Utilities.dll
  1655. 2015-12-18 16:51 - 2015-12-07 05:15 - 01035776 _____ (Microsoft Corporation) C:\WINDOWS\system32\XboxNetApiSvc.dll
  1656. 2015-12-18 16:51 - 2015-12-07 05:15 - 00075776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.XboxLive.ProxyStub.dll
  1657. 2015-12-18 16:51 - 2015-12-07 05:09 - 00133120 _____ (Microsoft Corporation) C:\WINDOWS\system32\flvprophandler.dll
  1658. 2015-12-18 16:51 - 2015-12-07 05:09 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanagerprecheck.dll
  1659. 2015-12-18 16:51 - 2015-12-07 05:09 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorageUsage.dll
  1660. 2015-12-18 16:51 - 2015-12-07 05:07 - 00134656 _____ (Microsoft Corporation) C:\WINDOWS\system32\wificonnapi.dll
  1661. 2015-12-18 16:51 - 2015-12-07 05:07 - 00077312 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProvPluginEng.dll
  1662. 2015-12-18 16:51 - 2015-12-07 05:06 - 00572928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WpcWebFilter.dll
  1663. 2015-12-18 16:51 - 2015-12-07 05:06 - 00231936 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCore.dll
  1664. 2015-12-18 16:51 - 2015-12-07 05:06 - 00199168 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe
  1665. 2015-12-18 16:51 - 2015-12-07 05:05 - 00192000 _____ (Microsoft Corporation) C:\WINDOWS\system32\provisioningcsp.dll
  1666. 2015-12-18 16:51 - 2015-12-07 05:05 - 00036864 _____ (Microsoft Corporation) C:\WINDOWS\system32\BackgroundTransferHost.exe
  1667. 2015-12-18 16:51 - 2015-12-07 05:04 - 00066560 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshost.dll
  1668. 2015-12-18 16:51 - 2015-12-07 05:04 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\system32\provtool.exe
  1669. 2015-12-18 16:51 - 2015-12-07 05:02 - 00269824 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshostcore.dll
  1670. 2015-12-18 16:51 - 2015-12-07 05:02 - 00161280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgent.exe
  1671. 2015-12-18 16:51 - 2015-12-07 05:01 - 00543232 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll
  1672. 2015-12-18 16:51 - 2015-12-07 05:01 - 00034304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BackgroundTransferHost.exe
  1673. 2015-12-18 16:51 - 2015-12-07 05:00 - 00618496 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll
  1674. 2015-12-18 16:51 - 2015-12-07 05:00 - 00323072 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSFlacDecoder.dll
  1675. 2015-12-18 16:51 - 2015-12-07 05:00 - 00210432 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmcsp.dll
  1676. 2015-12-18 16:51 - 2015-12-07 05:00 - 00203776 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupSvc.dll
  1677. 2015-12-18 16:51 - 2015-12-07 04:59 - 00558080 _____ (Microsoft Corporation) C:\WINDOWS\system32\MBMediaManager.dll
  1678. 2015-12-18 16:51 - 2015-12-07 04:59 - 00292352 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll
  1679. 2015-12-18 16:51 - 2015-12-07 04:59 - 00286208 _____ (Microsoft Corporation) C:\WINDOWS\system32\provhandlers.dll
  1680. 2015-12-18 16:51 - 2015-12-07 04:59 - 00165376 _____ (Microsoft Corporation) C:\WINDOWS\system32\provdatastore.dll
  1681. 2015-12-18 16:51 - 2015-12-07 04:58 - 00459776 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapConfiguration.dll
  1682. 2015-12-18 16:51 - 2015-12-07 04:57 - 00409088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StoreAgent.dll
  1683. 2015-12-18 16:51 - 2015-12-07 04:57 - 00270848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSFlacDecoder.dll
  1684. 2015-12-18 16:51 - 2015-12-07 04:56 - 00607232 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmsvc.dll
  1685. 2015-12-18 16:51 - 2015-12-07 04:56 - 00497152 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmkvsrcsnk.dll
  1686. 2015-12-18 16:51 - 2015-12-07 04:55 - 07979008 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll
  1687. 2015-12-18 16:51 - 2015-12-07 04:55 - 00346112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapConfiguration.dll
  1688. 2015-12-18 16:51 - 2015-12-07 04:54 - 00850432 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll
  1689. 2015-12-18 16:51 - 2015-12-07 04:53 - 00381952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmkvsrcsnk.dll
  1690. 2015-12-18 16:51 - 2015-12-07 04:51 - 00223232 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapibase.dll
  1691. 2015-12-18 16:51 - 2015-12-07 04:50 - 01131520 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Audio.dll
  1692. 2015-12-18 16:51 - 2015-12-07 04:49 - 01105920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Audio.dll
  1693. 2015-12-18 16:51 - 2015-12-07 04:48 - 06297088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mos.dll
  1694. 2015-12-18 16:51 - 2015-12-07 04:45 - 00900608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.BackgroundTransfer.dll
  1695. 2015-12-18 16:51 - 2015-12-07 04:45 - 00683008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.BackgroundTransfer.dll
  1696. 2015-12-18 16:51 - 2015-12-07 04:43 - 00931328 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSMPEG2ENC.DLL
  1697. 2015-12-18 16:51 - 2015-12-07 04:40 - 03593216 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
  1698. 2015-12-18 16:51 - 2015-12-07 04:39 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll
  1699. 2015-12-18 16:51 - 2015-12-07 04:38 - 00871936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSMPEG2ENC.DLL
  1700. 2015-12-18 16:51 - 2015-12-07 04:33 - 00375296 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDEServer.exe
  1701. 2015-12-18 16:51 - 2015-12-07 04:32 - 00126464 _____ (Microsoft Corporation) C:\WINDOWS\system32\dialserver.dll
  1702.  
  1703. ==================== One Month Modified files and folders ========
  1704.  
  1705. (If an entry is included in the fixlist, the file/folder will be moved.)
  1706.  
  1707. 2016-01-02 15:54 - 2015-10-30 08:17 - 00480256 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnet.dll
  1708. 2016-01-02 15:54 - 2015-10-30 08:17 - 00395264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnet.dll
  1709. 2016-01-02 15:54 - 2015-10-30 08:17 - 00220160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dplayx.dll
  1710. 2016-01-02 15:54 - 2015-10-30 08:17 - 00069120 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnathlp.dll
  1711. 2016-01-02 15:54 - 2015-10-30 08:17 - 00061952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnathlp.dll
  1712. 2016-01-02 15:54 - 2015-10-30 08:17 - 00047104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpwsockx.dll
  1713. 2016-01-02 15:54 - 2015-10-30 08:17 - 00027648 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnsvr.exe
  1714. 2016-01-02 15:54 - 2015-10-30 08:17 - 00025088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpmodemx.dll
  1715. 2016-01-02 15:54 - 2015-10-30 08:17 - 00023040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnsvr.exe
  1716. 2016-01-02 15:54 - 2015-10-30 08:17 - 00020992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dplaysvr.exe
  1717. 2016-01-02 15:54 - 2015-10-30 08:17 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnhupnp.dll
  1718. 2016-01-02 15:54 - 2015-10-30 08:17 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnhpast.dll
  1719. 2016-01-02 15:54 - 2015-10-30 08:17 - 00008704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnhupnp.dll
  1720. 2016-01-02 15:54 - 2015-10-30 08:17 - 00008704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnhpast.dll
  1721. 2016-01-02 15:54 - 2015-10-30 08:17 - 00005632 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnlobby.dll
  1722. 2016-01-02 15:54 - 2015-10-30 08:17 - 00005632 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnaddr.dll
  1723. 2016-01-02 15:54 - 2015-10-30 08:17 - 00004608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnlobby.dll
  1724. 2016-01-02 15:54 - 2015-10-30 08:17 - 00004608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnaddr.dll
  1725. 2015-12-18 09:48 - 2015-12-01 20:33 - 12426896 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvlddmkm.sys
  1726. 2015-12-18 07:11 - 2015-11-15 15:26 - 00047760 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvvad64v.sys
  1727.  
  1728. ==================== Files in the root of some directories =======
  1729.  
  1730. 2016-01-16 21:03 - 2016-01-16 21:03 - 0000000 _____ () C:\Users\AngryShadow\AppData\Roaming\g78rfdsafhi
  1731. 2016-01-06 22:28 - 2016-01-06 22:58 - 5929984 ___SH (Microsoft Corp.) C:\Users\AngryShadow\AppData\Roaming\Gambino.exe
  1732. 2016-01-16 21:03 - 2016-01-16 21:03 - 0624696 _____ () C:\Users\AngryShadow\AppData\Roaming\im201506.exe
  1733. 2015-12-28 00:26 - 2015-12-28 00:26 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
  1734.  
  1735. Some files in TEMP:
  1736. ====================
  1737. C:\Users\AngryShadow\AppData\Local\Temp\0068-c8c2-6ba2-381f.exe
  1738. C:\Users\AngryShadow\AppData\Local\Temp\3ae5-d40e-1d6f-b47f.exe
  1739. C:\Users\AngryShadow\AppData\Local\Temp\8a4b-e41d-f8cb-4af4.exe
  1740. C:\Users\AngryShadow\AppData\Local\Temp\bitool.dll
  1741. C:\Users\AngryShadow\AppData\Local\Temp\fc73-9ff9-0c0b-e5db.exe
  1742. C:\Users\AngryShadow\AppData\Local\Temp\ff60-875e-65d4-506c.exe
  1743. C:\Users\AngryShadow\AppData\Local\Temp\setup.exe
  1744.  
  1745.  
  1746. ==================== Bamital & volsnap =================
  1747.  
  1748. (There is no automatic fix for files that do not pass verification.)
  1749.  
  1750. C:\WINDOWS\system32\winlogon.exe => File is digitally signed
  1751. C:\WINDOWS\system32\wininit.exe => File is digitally signed
  1752. C:\WINDOWS\explorer.exe => File is digitally signed
  1753. C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
  1754. C:\WINDOWS\system32\svchost.exe => File is digitally signed
  1755. C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
  1756. C:\WINDOWS\system32\services.exe => File is digitally signed
  1757. C:\WINDOWS\system32\User32.dll => File is digitally signed
  1758. C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
  1759. C:\WINDOWS\system32\userinit.exe => File is digitally signed
  1760. C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
  1761. C:\WINDOWS\system32\rpcss.dll => File is digitally signed
  1762. C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
  1763. C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
  1764. C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
  1765.  
  1766.  
  1767. LastRegBack: 2016-01-07 00:51
  1768.  
  1769. ==================== End of FRST.txt ============================
Add Comment
Please, Sign In to add comment