Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Additional scan result of Farbar Recovery Scan Tool (x64) Version:10-01-2015 01
- Ran by AngryShadow (2016-01-16 23:11:37)
- Running from C:\Users\AngryShadow\Desktop
- Windows 10 Home (X64) (2015-12-27 14:29:02)
- Boot Mode: Normal
- ==========================================================
- ==================== Accounts: =============================
- Administrator (S-1-5-21-3985454009-819291025-207730266-500 - Administrator - Disabled)
- AngryShadow (S-1-5-21-3985454009-819291025-207730266-1001 - Administrator - Enabled) => C:\Users\AngryShadow
- DefaultAccount (S-1-5-21-3985454009-819291025-207730266-503 - Limited - Disabled)
- Guest (S-1-5-21-3985454009-819291025-207730266-501 - Limited - Disabled)
- ==================== Security Center ========================
- (If an entry is included in the fixlist, it will be removed.)
- AV: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
- AV: McAfee Anti-Virus and Anti-Spyware (Enabled - Out of date) {DA9F8ED0-D0DE-39CC-F55A-51AB4CC1B556}
- AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
- AS: McAfee Anti-Virus and Anti-Spyware (Enabled - Out of date) {61FE6F34-F6E4-3642-CFEA-6AD93746FFEB}
- ==================== Installed Programs ======================
- (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
- µTorrent (HKU\S-1-5-21-3985454009-819291025-207730266-1001\...\uTorrent) (Version: 3.4.5.41372 - BitTorrent Inc.)
- Anachronox (HKLM-x32\...\Steam App 242940) (Version: - )
- Assassin's Creed Syndicate (HKLM-x32\...\Steam App 368500) (Version: - Ubisoft Quebec, in collaboration with Ubisoft Annecy, Bucharest, Kiev, Montreal, Montpellier, Shanghai, Singapore, Sofia, Toronto studios)
- Assassin's Creed® III (HKLM-x32\...\Steam App 208480) (Version: - Ubisoft Montreal)
- Battle.net (HKLM-x32\...\Battle.net) (Version: - Blizzard Entertainment)
- Bermuda (HKLM-x32\...\Steam App 337630) (Version: - InvertMouse)
- Call of Duty: Ghosts - Multiplayer (HKLM-x32\...\Steam App 209170) (Version: - Infinity Ward)
- Call of Duty: Ghosts (HKLM-x32\...\Steam App 209160) (Version: - Infinity Ward)
- Call of Duty: Modern Warfare 2 - Multiplayer (HKLM-x32\...\Steam App 10190) (Version: - Infinity Ward)
- Call of Duty: Modern Warfare 2 (HKLM-x32\...\Steam App 10180) (Version: - Infinity Ward)
- Call of Duty: Modern Warfare 3 - Multiplayer (HKLM-x32\...\Steam App 42690) (Version: - Infinity Ward)
- Call of Duty: Modern Warfare 3 (HKLM-x32\...\Steam App 42680) (Version: - Infinity Ward)
- City Car Driving Home Edition (HKLM\...\Q2l0eUNhckRyaXZpbmc=_is1) (Version: 1 - )
- Command and Conquer: Red Alert 3 (HKLM-x32\...\Steam App 17480) (Version: - EA Los Angeles)
- Counter-Strike (HKLM-x32\...\Steam App 10) (Version: - Valve)
- Counter-Strike: Condition Zero (HKLM-x32\...\Steam App 80) (Version: - Valve)
- Counter-Strike: Condition Zero Deleted Scenes (HKLM-x32\...\Steam App 100) (Version: - Valve)
- Counter-Strike: Global Offensive (HKLM-x32\...\Steam App 730) (Version: - Valve)
- Counter-Strike: Source (HKLM-x32\...\Steam App 240) (Version: - Valve)
- DAEMON Tools Pro (HKLM\...\DAEMON Tools Pro) (Version: 7.0.0.0555 - Disc Soft Ltd)
- Daikatana (HKLM-x32\...\Steam App 242980) (Version: - )
- Day of Defeat (HKLM-x32\...\Steam App 30) (Version: - Valve)
- DayZ (HKLM-x32\...\Steam App 221100) (Version: - Bohemia Interactive)
- Dead Effect (HKLM-x32\...\Steam App 286040) (Version: - BadFly Interactive, a.s.)
- Dead Island: Epidemic (HKLM-x32\...\Steam App 222900) (Version: - Stunlock Studios)
- Deathmatch Classic (HKLM-x32\...\Steam App 40) (Version: - Valve)
- Depth Hunter 2: Deep Dive (HKLM-x32\...\Steam App 248530) (Version: - Biart Company LLC)
- Deus Ex: Human Revolution - Director's Cut (HKLM-x32\...\Steam App 238010) (Version: - Eidos Montreal)
- DiRT Rally (HKLM-x32\...\Steam App 310560) (Version: - Codemasters Racing Studio)
- Dota 2 (HKLM-x32\...\Steam App 570) (Version: - Valve)
- Dota 2 Test (HKLM-x32\...\Steam App 205790) (Version: - )
- Dream Pinball 3D (HKLM-x32\...\Steam App 215790) (Version: - ASK Homework)
- Emily Wants To Play (HKLM-x32\...\Steam App 416590) (Version: - Shawn Hitchcock)
- Enclave (HKLM-x32\...\Steam App 253980) (Version: - Starbreeze)
- Euro Truck Simulator 2 (HKLM-x32\...\Steam App 227300) (Version: - SCS Software)
- Europa Universalis III (HKLM-x32\...\Steam App 25800) (Version: - Paradox Development Studio)
- Five Nights at Freddy's (HKLM-x32\...\Steam App 319510) (Version: - Scott Cawthon)
- FlatOut 2 (HKLM-x32\...\Steam App 2990) (Version: - Bugbear Entertainment)
- Flesh Eaters (HKLM-x32\...\Steam App 383580) (Version: - 16bit Nights)
- Garry's Mod (HKLM-x32\...\Steam App 4000) (Version: - Facepunch Studios)
- Glacier 3: The Meltdown (HKLM-x32\...\Steam App 267940) (Version: - Team 6 Studios)
- Google Chrome (HKLM-x32\...\Google Chrome) (Version: 47.0.2526.111 - Google Inc.)
- Google Update Helper (x32 Version: 1.3.29.1 - Google Inc.) Hidden
- Gorky 17 (HKLM-x32\...\Steam App 253920) (Version: - )
- Grand Theft Auto V (HKLM-x32\...\Steam App 271590) (Version: - Rockstar North)
- Grand Theft Auto: San Andreas (HKLM-x32\...\Steam App 12120) (Version: - Rockstar Games)
- GTA San Andreas (HKLM-x32\...\{D417C96A-FCC7-4590-A1BB-FAF73F5BC98E}) (Version: 1.00.00001 - Rockstar Games)
- Gyazo 3.1.6 (HKLM-x32\...\{6DB8C365-E719-4BA5-9594-10DFC244D3FD}_is1) (Version: - Nota Inc.)
- H1Z1 (HKLM-x32\...\Steam App 295110) (Version: - Daybreak Games)
- H1Z1 Test Server (HKLM-x32\...\Steam App 362300) (Version: - )
- Hacker Evolution - Untold (HKLM-x32\...\Steam App 70110) (Version: - exosyphen studios)
- Hacker Evolution (HKLM-x32\...\Steam App 70100) (Version: - exosyphen studios)
- Half-Life 2 (HKLM-x32\...\Steam App 220) (Version: - Valve)
- Half-Life 2: Deathmatch (HKLM-x32\...\Steam App 320) (Version: - Valve)
- Half-Life 2: Episode One (HKLM-x32\...\Steam App 380) (Version: - Valve)
- Half-Life 2: Episode Two (HKLM-x32\...\Steam App 420) (Version: - Valve)
- Half-Life 2: Lost Coast (HKLM-x32\...\Steam App 340) (Version: - Valve)
- Hearthstone (HKLM-x32\...\Hearthstone) (Version: - Blizzard Entertainment)
- Hitman 2: Silent Assassin (HKLM-x32\...\Steam App 6850) (Version: - IO Interactive)
- Hitman: Codename 47 (HKLM-x32\...\Steam App 6900) (Version: - IO Interactive)
- Insurgency (HKLM-x32\...\Steam App 222880) (Version: - New World Interactive)
- Just Cause 2 (HKLM-x32\...\Steam App 8190) (Version: - Avalanche Studios)
- Just Cause 2: Multiplayer Mod (HKLM-x32\...\Steam App 259080) (Version: - Avalanche Studios)
- Knights and Merchants (HKLM-x32\...\Steam App 253900) (Version: - Topware Interactive)
- KnightShift (HKLM-x32\...\Steam App 254060) (Version: - )
- Krater (HKLM-x32\...\Steam App 42170) (Version: - Fatshark)
- Landmark (HKLM-x32\...\Steam App 297810) (Version: - Daybreak Games)
- League of Legends (HKLM-x32\...\League of Legends 3.0.1) (Version: 3.0.1 - Riot Games)
- League of Legends (x32 Version: 3.0.1 - Riot Games) Hidden
- Left 4 Dead 2 (HKLM-x32\...\Steam App 550) (Version: - Valve)
- Left 4 Dead 2 Beta (HKLM-x32\...\Steam App 223530) (Version: - )
- McAfee LiveSafe - Internet Security (HKLM-x32\...\MSC) (Version: 14.0.6136 - McAfee, Inc.)
- Metro 2033 (HKLM-x32\...\Steam App 43110) (Version: - 4A Games)
- Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
- Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
- Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
- Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
- Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
- Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
- Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
- Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
- Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
- Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
- Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
- Microsoft XNA Framework Redistributable 4.0 Refresh (HKLM-x32\...\{D69C8EDE-BBC5-436B-8E0E-C5A6D311CF4F}) (Version: 4.0.30901.0 - Microsoft Corporation)
- Mini Ninjas (HKLM-x32\...\Steam App 35000) (Version: - IO Interactive)
- Mirror's Edge (HKLM-x32\...\Steam App 17410) (Version: - DICE)
- N.P.P.D. RUSH - The milk of Ultra violet (HKLM-x32\...\Steam App 270090) (Version: - Rail Slave Games)
- Need for Speed: Hot Pursuit (HKLM-x32\...\Steam App 47870) (Version: - Criterion Games)
- New kind of adventure (HKLM-x32\...\Steam App 375510) (Version: - Mint Age Studios)
- NVIDIA 3D Vision Controller Driver 352.65 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 352.65 - NVIDIA Corporation)
- NVIDIA 3D Vision Driver 361.43 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 361.43 - NVIDIA Corporation)
- NVIDIA GeForce Experience 2.10.0.60 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.10.0.60 - NVIDIA Corporation)
- NVIDIA Graphics Driver 361.43 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 361.43 - NVIDIA Corporation)
- NVIDIA HD Audio Driver 1.3.34.4 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.4 - NVIDIA Corporation)
- NVIDIA PhysX System Software 9.15.0428 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.15.0428 - NVIDIA Corporation)
- Oracle VM VirtualBox 5.0.12 (HKLM\...\{6F93731D-89E1-4A8F-BDA9-D104860DDB02}) (Version: 5.0.12 - Oracle Corporation)
- OSC Third Party Libraries (Version: 1.1 - NVIDIA Corporation) Hidden
- Outlast (HKLM-x32\...\Steam App 238320) (Version: - Red Barrels)
- PAYDAY 2 (HKLM-x32\...\Steam App 218620) (Version: - OVERKILL - a Starbreeze Studio.)
- PAYDAY: The Heist (HKLM-x32\...\Steam App 24240) (Version: - OVERKILL Software)
- Portal (HKLM-x32\...\Steam App 400) (Version: - Valve)
- Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7640 - Realtek Semiconductor Corp.)
- Ricochet (HKLM-x32\...\Steam App 60) (Version: - Valve)
- RollerCoaster Tycoon: Deluxe (HKLM-x32\...\Steam App 285310) (Version: - Chris Sawyer Productions)
- S.T.A.L.K.E.R.: Shadow of Chernobyl (HKLM-x32\...\Steam App 4500) (Version: - GSC Game World)
- Saints Row IV (HKLM-x32\...\Steam App 206420) (Version: - Deep Silver Volition)
- SHIELD Streaming (Version: 4.1.0260 - NVIDIA Corporation) Hidden
- SHIELD Wireless Controller Driver (Version: 2.10.0.60 - NVIDIA Corporation) Hidden
- Shower With Your Dad Simulator 2015: Do You Still Shower With Your Dad (HKLM-x32\...\Steam App 359050) (Version: - marbenx)
- Skype™ 7.17 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.17.105 - Skype Technologies S.A.)
- Smooth Operators (HKLM-x32\...\Steam App 262900) (Version: - Heydeck Games)
- Sniper Art of Victory (HKLM-x32\...\Steam App 271500) (Version: - CI Games)
- Sniper Ghost Warrior 2 (HKLM-x32\...\Steam App 34870) (Version: - City Interactive)
- Sniper: Ghost Warrior (HKLM-x32\...\Steam App 34830) (Version: - City Interactive)
- SpeedRunners (HKLM-x32\...\Steam App 207140) (Version: - DoubleDutch Games)
- Star Chronicles: Delta Quadrant (HKLM-x32\...\Steam App 383330) (Version: - Alister Software)
- STAR WARS™ Knights of the Old Republic™ II: The Sith Lords™ (HKLM-x32\...\Steam App 208580) (Version: - Obsidian Entertainment)
- Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
- SwiftSearch 1.10.0.27 (HKLM-x32\...\SwiftSearch_1.10.0.27) (Version: 1.10.0.27 - SwiftSearch) <==== ATTENTION
- Team Fortress 2 (HKLM-x32\...\Steam App 440) (Version: - Valve)
- TeamViewer 11 (HKLM-x32\...\TeamViewer) (Version: 11.0.53254 - TeamViewer)
- The Evil Within (HKLM-x32\...\Steam App 268050) (Version: - Tango Gameworks)
- The Tower Of Elements (HKLM-x32\...\Steam App 377310) (Version: - Wulo Games)
- Thief Gold (HKLM-x32\...\Steam App 211600) (Version: - Looking Glass Studios)
- Train Simulator (HKLM-x32\...\Steam App 24010) (Version: - Dovetail Games)
- Trine 2 (HKLM-x32\...\Steam App 35720) (Version: - Frozenbyte)
- Truffle Saga (HKLM-x32\...\Steam App 302260) (Version: - Colossal Games)
- Wajam (HKLM-x32\...\WajaNetEn) (Version: 1.58.1.37 (i1.0) - Wajam) <==== ATTENTION
- Watch_Dogs (HKLM-x32\...\Steam App 243470) (Version: - Ubisoft)
- WinRAR 5.30 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.30.0 - win.rar GmbH)
- World of Warcraft (HKLM-x32\...\World of Warcraft) (Version: - Blizzard Entertainment)
- yoursearching (HKLM-x32\...\yoursearching) (Version: 1.0.0.8 - )
- ==================== Custom CLSID (Whitelisted): ==========================
- (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
- CustomCLSID: HKU\S-1-5-21-3985454009-819291025-207730266-1001_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\AngryShadow\AppData\Local\Microsoft\OneDrive\17.3.6281.1202\FileCoAuth.exe (Microsoft Corporation)
- ==================== Scheduled Tasks (Whitelisted) =============
- (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
- Task: {2E77DA24-20C2-4094-8200-00F88846DA42} - System32\Tasks\SwiftSearch Auto Updater 1.10.0.27 Core => C:\Program Files (x86)\SwiftSearch_1.10.0.27\Update\SwiftSearchAutoUpdateClient.exe [2015-10-23] (SS) <==== ATTENTION
- Task: {36E9F172-E194-49C8-8986-102AB6520FF8} - System32\Tasks\GyazoUpdateTaskMachine => C:\Program Files (x86)\Gyazo\GyazoUpdate.exe [2015-08-19] ()
- Task: {4513EF42-97CA-4D19-86EC-E2AE567F37DE} - System32\Tasks\McAfee\McAfee Idle Detection Task
- Task: {5374EE17-069B-45FE-A6EF-8BE2DDE622BD} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-01-14] (Google Inc.)
- Task: {7D1773F4-2ED5-4AEC-A285-A07CC575C2A0} - System32\Tasks\McAfeeLogon => C:\Program Files\Common Files\McAfee\Platform\McUICnt.exe [2015-11-02] (McAfee, Inc.)
- Task: {CA2B9545-B027-49F3-870C-D4CC6DA8443E} - System32\Tasks\GyazoUpdateTaskMachineDaily => C:\Program Files (x86)\Gyazo\GyazoUpdate.exe [2015-08-19] ()
- Task: {CC439579-A557-4238-8C76-058AA8E03C9A} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-01-14] (Google Inc.)
- Task: {D11DC6BE-410E-47A9-A912-3AC4BCCCFB1E} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2016-01-15] (Microsoft Corporation)
- Task: {D9BAFAFE-3C18-4E7B-9145-E2ECDF99DF1B} - System32\Tasks\Microsoft\Windows\UPnP\UPnPHostConfig => config upnphost start= auto
- Task: {EC6E4B0B-E143-4419-8D6B-1B7CEC7C809C} - System32\Tasks\SwiftSearch Auto Updater 1.10.0.27 Pending Update => C:\Program Files (x86)\SwiftSearch_1.10.0.27\Update\SwiftSearchAutoUpdateClient.exe [2015-10-23] (SS) <==== ATTENTION
- Task: {F389D861-889E-417B-939F-95E9FACF37C9} - System32\Tasks\McAfee\McAfee Auto Maintenance Task Agent
- (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
- Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
- Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
- ==================== Shortcuts =============================
- (The entries could be listed to be restored or removed.)
- ShortcutWithArgument: C:\Users\AngryShadow\Desktop\Start Tor Browser.lnk -> C:\Users\AngryShadow\Desktop\Tor Browser\Browser\firefox.exe (Mozilla Corporation) -> hxxp://www.yoursearching.com/?type=sc&ts=1452975515&z=374796605c0902467f0741ag7z7weoftam0w9w7gaw&from=exp2&uid=kingstonxrbu-sc400s37128g_50026b7244033f9e
- ShortcutWithArgument: C:\Users\AngryShadow\Desktop\Tor Browser\Start Tor Browser.lnk -> C:\Users\AngryShadow\Desktop\Tor Browser\Browser\firefox.exe (Mozilla Corporation) -> hxxp://www.yoursearching.com/?type=sc&ts=1452975515&z=374796605c0902467f0741ag7z7weoftam0w9w7gaw&from=exp2&uid=kingstonxrbu-sc400s37128g_50026b7244033f9e
- ShortcutWithArgument: C:\Users\AngryShadow\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Start Tor Browser.lnk -> C:\Users\AngryShadow\Desktop\Tor Browser\Browser\firefox.exe (Mozilla Corporation) -> hxxp://www.yoursearching.com/?type=sc&ts=1452975515&z=374796605c0902467f0741ag7z7weoftam0w9w7gaw&from=exp2&uid=kingstonxrbu-sc400s37128g_50026b7244033f9e
- ShortcutWithArgument: C:\Users\AngryShadow\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome\Chrome App Launcher.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursearching.com/?type=sc&ts=1452975515&z=374796605c0902467f0741ag7z7weoftam0w9w7gaw&from=exp2&uid=kingstonxrbu-sc400s37128g_50026b7244033f9e
- ShortcutWithArgument: C:\Users\AngryShadow\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Ad.Block Super (V.1.12).lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursearching.com/?type=sc&ts=1452975515&z=374796605c0902467f0741ag7z7weoftam0w9w7gaw&from=exp2&uid=kingstonxrbu-sc400s37128g_50026b7244033f9e
- ShortcutWithArgument: C:\Users\AngryShadow\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursearching.com/?type=sc&ts=1452975515&z=374796605c0902467f0741ag7z7weoftam0w9w7gaw&from=exp2&uid=kingstonxrbu-sc400s37128g_50026b7244033f9e
- ShortcutWithArgument: C:\Users\AngryShadow\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursearching.com/?type=sc&ts=1452975515&z=374796605c0902467f0741ag7z7weoftam0w9w7gaw&from=exp2&uid=kingstonxrbu-sc400s37128g_50026b7244033f9e
- ShortcutWithArgument: C:\Users\AngryShadow\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\69639df789022856\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursearching.com/?type=sc&ts=1452975515&z=374796605c0902467f0741ag7z7weoftam0w9w7gaw&from=exp2&uid=kingstonxrbu-sc400s37128g_50026b7244033f9e
- ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursearching.com/?type=sc&ts=1452975515&z=374796605c0902467f0741ag7z7weoftam0w9w7gaw&from=exp2&uid=kingstonxrbu-sc400s37128g_50026b7244033f9e
- ShortcutWithArgument: C:\Users\Public\Desktop\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> hxxp://www.yoursearching.com/?type=sc&ts=1452975515&z=374796605c0902467f0741ag7z7weoftam0w9w7gaw&from=exp2&uid=kingstonxrbu-sc400s37128g_50026b7244033f9e
- ShortcutWithArgument: C:\Users\Public\Desktop\League of Legends.lnk -> D:\League Of Noobs\lol.launcher.exe () -> hxxp://www.yoursearching.com/?type=sc&ts=1452975515&z=374796605c0902467f0741ag7z7weoftam0w9w7gaw&from=exp2&uid=kingstonxrbu-sc400s37128g_50026b7244033f9e
- ==================== Loaded Modules (Whitelisted) ==============
- 2015-10-30 08:17 - 2015-10-30 08:17 - 00028672 _____ () C:\WINDOWS\SYSTEM32\efsext.dll
- 2015-10-30 08:18 - 2015-10-30 08:18 - 00185856 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll
- 2015-12-28 00:26 - 2015-12-16 15:54 - 00126256 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
- 2015-12-27 16:46 - 2016-01-09 08:23 - 00291264 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamBase.dll
- 2015-12-13 06:22 - 2015-12-13 06:22 - 02653816 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
- 2015-12-13 06:22 - 2015-12-13 06:22 - 02653816 _____ () C:\WINDOWS\System32\CoreUIComponents.dll
- 2015-12-27 16:10 - 2015-12-27 16:14 - 00144384 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.12.15004.0_x86__8wekyb3d8bbwe\SkypeHost.exe
- 2015-12-18 16:51 - 2015-12-07 05:14 - 00093696 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\Windows.UI.Shell.SharedUtilities.dll
- 2015-12-18 16:51 - 2015-12-07 05:00 - 00472064 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll
- 2015-12-27 16:16 - 2015-12-27 16:16 - 00012800 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_15.1208.10480.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
- 2015-12-27 16:16 - 2015-12-27 16:16 - 11542016 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_15.1208.10480.0_x64__8wekyb3d8bbwe\Microsoft.Photos.dll
- 2015-12-27 16:04 - 2015-12-27 16:04 - 00258560 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_15.1208.10480.0_x64__8wekyb3d8bbwe\StoreRatingPromotion.dll
- 2016-01-08 03:17 - 2016-01-08 03:17 - 09737216 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsStore_2015.25.15.0_x64__8wekyb3d8bbwe\WinStore.Entertainment.Mobile.dll
- 2016-01-13 06:18 - 2016-01-13 06:18 - 02829824 _____ () C:\Program Files\WajaNetEn\6f7dd0d1a6b7295523cc41e34e4b9dfd.exe
- 2016-01-13 06:16 - 2016-01-13 06:16 - 02314752 _____ () c:\program files\wajaneten\7b1fae02d59a1789f5b8115c78fb3a25.exe
- 2016-01-13 06:18 - 2016-01-13 06:18 - 02829824 _____ () c:\program files\wajaneten\6f7dd0d1a6b7295523cc41e34e4b9dfd.exe
- 2016-01-16 21:05 - 2016-01-16 21:05 - 11971584 _____ () c:\program files\wajaneten\WajaNetEnlibs\rhbyok.dll
- 2015-04-27 03:50 - 2015-04-27 03:50 - 00412672 _____ () C:\Program Files (x86)\Rockstar Games\GTA San Andreas\samp.exe
- 2016-01-13 13:05 - 2016-01-05 02:29 - 07992832 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
- 2016-01-13 13:05 - 2016-01-05 02:23 - 00591360 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
- 2016-01-13 13:05 - 2016-01-05 02:24 - 02483200 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
- 2016-01-13 13:05 - 2016-01-05 02:26 - 04089856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
- 2015-12-27 16:10 - 2015-12-27 16:14 - 00141312 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.12.15004.0_x86__8wekyb3d8bbwe\SkypeBackgroundTasks.dll
- 2015-12-27 16:10 - 2015-12-27 16:14 - 21845504 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.12.15004.0_x86__8wekyb3d8bbwe\SkyWrap.dll
- 2015-12-27 16:46 - 2016-01-09 08:23 - 00018880 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll
- 2015-12-27 16:01 - 2015-11-10 20:55 - 00778752 _____ () D:\Steam\SDL2.dll
- 2015-12-27 16:01 - 2015-07-03 17:12 - 04962816 _____ () D:\Steam\v8.dll
- 2015-12-27 16:01 - 2015-12-14 21:01 - 02547280 _____ () D:\Steam\video.dll
- 2015-12-27 16:00 - 2015-09-24 01:33 - 02549248 _____ () D:\Steam\libavcodec-56.dll
- 2015-12-27 16:00 - 2015-09-24 01:33 - 00491008 _____ () D:\Steam\libavformat-56.dll
- 2015-12-27 16:00 - 2015-09-24 01:33 - 00332800 _____ () D:\Steam\libavresample-2.dll
- 2015-12-27 16:00 - 2015-09-24 01:33 - 00442880 _____ () D:\Steam\libavutil-54.dll
- 2015-12-27 16:00 - 2015-09-24 01:33 - 00485888 _____ () D:\Steam\libswscale-3.dll
- 2015-12-27 16:01 - 2015-07-03 17:12 - 01556992 _____ () D:\Steam\icui18n.dll
- 2015-12-27 16:01 - 2015-07-03 17:12 - 01187840 _____ () D:\Steam\icuuc.dll
- 2015-12-27 16:00 - 2015-12-14 21:01 - 00804432 _____ () D:\Steam\bin\chromehtml.DLL
- 2015-12-27 16:00 - 2015-11-03 23:00 - 00201728 _____ () D:\Steam\bin\openvr_api.dll
- 2015-12-27 16:00 - 2015-11-17 01:31 - 47846176 _____ () D:\Steam\bin\libcef.dll
- 2015-12-27 16:00 - 2015-09-25 00:56 - 00119208 _____ () D:\Steam\winh264.dll
- 2015-12-05 10:21 - 2015-12-05 10:21 - 00933056 ____R () D:\Skype\Phone\ssScreenVVS2.dll
- 2016-01-16 21:04 - 2016-01-16 21:05 - 11752448 _____ () c:\program files\wajaneten\WajaNetEnlibs\cibkwi.dll
- 2016-01-16 21:04 - 2016-01-16 21:05 - 11752448 _____ () c:\program files\wajaneten\wajanetenlibs\cibkwi.dll
- 2016-01-14 10:11 - 2016-01-12 17:35 - 01590088 _____ () C:\Program Files (x86)\Google\Chrome\Application\47.0.2526.111\libglesv2.dll
- 2016-01-14 10:11 - 2016-01-12 17:35 - 00087880 _____ () C:\Program Files (x86)\Google\Chrome\Application\47.0.2526.111\libegl.dll
- 2016-01-14 10:11 - 2016-01-12 17:35 - 16799048 _____ () C:\Program Files (x86)\Google\Chrome\Application\47.0.2526.111\PepperFlash\pepflashplayer.dll
- ==================== Alternate Data Streams (Whitelisted) =========
- (If an entry is included in the fixlist, only the ADS will be removed.)
- ==================== Safe Mode (Whitelisted) ===================
- (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
- HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\47634066.sys => ""="Driver"
- HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""=""
- HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
- HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\47634066.sys => ""="Driver"
- HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service"
- HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McNaiAnn => ""=""
- HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""=""
- HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""
- HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeaack => ""="Service"
- HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeaack.sys => ""="Driver"
- HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeavfk => ""="Service"
- HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfeavfk.sys => ""="Driver"
- HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefire => ""="Service"
- HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek => ""="Service"
- HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek.sys => ""="Driver"
- HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk => ""="Service"
- HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk.sys => ""="Driver"
- HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfemms => ""="Service"
- HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfetdi2k => ""="Service"
- HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfetdi2k.sys => ""="Driver"
- HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfevtp => ""="Service"
- ==================== EXE Association (Whitelisted) ===============
- (If an entry is included in the fixlist, the registry item will be restored to default or removed.)
- ==================== Internet Explorer trusted/restricted ===============
- (If an entry is included in the fixlist, it will be removed from the registry.)
- ==================== Hosts content: ==========================
- (If needed Hosts: directive could be included in the fixlist to reset Hosts.)
- 2015-12-27 16:07 - 2016-01-08 12:50 - 00000994 ____A C:\WINDOWS\system32\Drivers\etc\hosts
- 127.0.0.1 down.baidu2016.com
- 127.0.0.1 123.sogou.com
- 127.0.0.1 www.czzsyzgm.com
- 127.0.0.1 www.czzsyzxl.com
- 127.0.0.1 localhost
- ==================== Other Areas ============================
- (Currently there is no automatic fix for this section.)
- HKU\S-1-5-21-3985454009-819291025-207730266-1001\Control Panel\Desktop\\Wallpaper -> C:\WINDOWS\web\wallpaper\Windows\img0.jpg
- DNS Servers: 192.168.1.1
- HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
- Windows Firewall is disabled.
- ==================== MSCONFIG/TASK MANAGER disabled items ==
- (Currently there is no automatic fix for this section.)
- HKLM\...\StartupApproved\Run32: => "BlueStacks Agent"
- HKU\S-1-5-21-3985454009-819291025-207730266-1001\...\StartupApproved\Run: => "uTorrent"
- HKU\S-1-5-21-3985454009-819291025-207730266-1001\...\StartupApproved\Run: => "CyberGhost"
- HKU\S-1-5-21-3985454009-819291025-207730266-1001\...\StartupApproved\Run: => "DAEMON Tools Lite Automount"
- HKU\S-1-5-21-3985454009-819291025-207730266-1001\...\StartupApproved\Run: => "OtLandIPChanger"
- HKU\S-1-5-21-3985454009-819291025-207730266-1001\...\StartupApproved\Run: => "Skype"
- HKU\S-1-5-21-3985454009-819291025-207730266-1001\...\StartupApproved\Run: => "Steam"
- HKU\S-1-5-21-3985454009-819291025-207730266-1001\...\StartupApproved\Run: => "Gyazo"
- ==================== FirewallRules (Whitelisted) ===============
- (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
- FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
- FirewallRules: [{D13D47E3-7E6E-4EEC-9DA9-B714FAFD1E41}] => (Allow) D:\Steam\Steam.exe
- FirewallRules: [{1227FF41-F7C3-4E90-8786-CCC70AD296D5}] => (Allow) D:\Steam\Steam.exe
- FirewallRules: [{0253EB6A-0CA2-4592-B005-948D03E99729}] => (Allow) D:\Steam\bin\steamwebhelper.exe
- FirewallRules: [{DC7E6BE5-2763-46A5-A5E3-7717154EA78B}] => (Allow) D:\Steam\bin\steamwebhelper.exe
- FirewallRules: [{ABC0DBB9-EF67-4567-8BF9-AC25D8847925}] => (Allow) D:\Skype\Phone\Skype.exe
- FirewallRules: [TCP Query User{C76C0D0D-B9DB-4B69-8533-DEEC1C1FA6E7}D:\games\hearthstone\hearthstone.exe] => (Allow) D:\games\hearthstone\hearthstone.exe
- FirewallRules: [UDP Query User{A60A5B8D-EA79-4BC8-9D3C-D3E773E965B6}D:\games\hearthstone\hearthstone.exe] => (Allow) D:\games\hearthstone\hearthstone.exe
- FirewallRules: [{17069DFC-3732-4F79-B3C2-94DDCB25F4A5}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
- FirewallRules: [{7AA9A93E-2977-4A3A-9450-0A92C4DE120E}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
- FirewallRules: [{B9E8249D-D20A-44AE-9282-771238251B9B}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
- FirewallRules: [{B32BA6FE-C45B-4337-B5A5-CFA53112828C}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
- FirewallRules: [{4C37FE2E-6F4A-45C8-9E1D-305FF7B07781}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
- FirewallRules: [{58AE6673-7364-4DE2-8AA5-BCB96B2C8FD7}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
- FirewallRules: [{A6C73751-B746-4A3D-97A7-C1FA2817416D}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
- FirewallRules: [{440FBB1C-DCF6-4BBA-8BEF-73F6C2A9D6C5}] => (Allow) D:\Steam\steamapps\common\Team Fortress 2\hl2.exe
- FirewallRules: [{452146A2-E991-47D9-9188-646DFD319197}] => (Allow) D:\Steam\steamapps\common\Team Fortress 2\hl2.exe
- FirewallRules: [TCP Query User{6209F594-BA6A-494E-97E0-1E3980D529C5}C:\users\angryshadow\downloads\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => (Allow) C:\users\angryshadow\downloads\runtime\jre-x64\1.8.0_25\bin\javaw.exe
- FirewallRules: [UDP Query User{9E662524-7FBD-4BEE-AD0E-8DC9045807A4}C:\users\angryshadow\downloads\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => (Allow) C:\users\angryshadow\downloads\runtime\jre-x64\1.8.0_25\bin\javaw.exe
- FirewallRules: [{7505A981-6358-4449-8FFE-55E28049BDD7}] => (Allow) D:\Steam\steamapps\common\Grand Theft Auto V\GTAVLauncher.exe
- FirewallRules: [{DD2B8607-ADCF-4FF7-87A1-EF502F7D1997}] => (Allow) D:\Steam\steamapps\common\Grand Theft Auto V\GTAVLauncher.exe
- FirewallRules: [{4B1837AB-1263-4105-9195-9CBAE2D6396D}] => (Allow) D:\Steam\steamapps\common\Anachronox\anox.exe
- FirewallRules: [{F7E4BDB1-A9B6-4E2E-B823-1FC1769E4380}] => (Allow) D:\Steam\steamapps\common\Anachronox\anox.exe
- FirewallRules: [{2FC87526-66B2-46BD-B3DF-437A1F7F240E}] => (Allow) D:\Steam\steamapps\common\Assassin's Creed 3\AC3SP.exe
- FirewallRules: [{A1172A05-ED76-4B0B-96A4-99AF3FAF86BC}] => (Allow) D:\Steam\steamapps\common\Assassin's Creed 3\AC3SP.exe
- FirewallRules: [{11A11A44-0C7E-40E5-B5CB-7C3A35E56553}] => (Allow) D:\Steam\steamapps\common\Assassin's Creed Syndicate\ACS.exe
- FirewallRules: [{BED533E2-14B2-4E40-91D0-5304B42AE87D}] => (Allow) D:\Steam\steamapps\common\Assassin's Creed Syndicate\ACS.exe
- FirewallRules: [{0692DD56-E1A3-473B-B07D-D223F37637B0}] => (Allow) D:\Steam\steamapps\common\Bermuda\bermuda.exe
- FirewallRules: [{CA55037A-CAEA-42EA-B223-F42F66C2C016}] => (Allow) D:\Steam\steamapps\common\Bermuda\bermuda.exe
- FirewallRules: [{3BED4FB8-10C5-4F50-9CEB-A58934748C43}] => (Allow) D:\Steam\steamapps\common\Call of Duty Ghosts\iw6sp64_ship.exe
- FirewallRules: [{D54CDBAD-A3CE-4D9D-AEE6-26355C61363E}] => (Allow) D:\Steam\steamapps\common\Call of Duty Ghosts\iw6sp64_ship.exe
- FirewallRules: [{F4C6A83C-8801-447C-9E33-A2F06F9C40B5}] => (Allow) D:\Steam\steamapps\common\Call of Duty Ghosts\iw6mp64_ship.exe
- FirewallRules: [{68F416F0-53F6-418D-A7D9-A35E1AE19294}] => (Allow) D:\Steam\steamapps\common\Call of Duty Ghosts\iw6mp64_ship.exe
- FirewallRules: [{E2F7BC72-F317-4765-B99B-D5B93C94B9BA}] => (Allow) D:\Steam\steamapps\common\Call of Duty Modern Warfare 2\iw4sp.exe
- FirewallRules: [{40143CFB-FBF2-450B-9DBC-33DC3D8FDA4B}] => (Allow) D:\Steam\steamapps\common\Call of Duty Modern Warfare 2\iw4sp.exe
- FirewallRules: [{B5224DA6-3745-4E2A-8346-313F45CCA226}] => (Allow) D:\Steam\steamapps\common\Call of Duty Modern Warfare 2\iw4mp.exe
- FirewallRules: [{372DF5E8-ED17-4B91-A3CE-9EAF40E2BD40}] => (Allow) D:\Steam\steamapps\common\Call of Duty Modern Warfare 2\iw4mp.exe
- FirewallRules: [{5A560584-8FE0-4CA9-A23D-7562CFCD93D3}] => (Allow) D:\Steam\steamapps\common\Call of Duty Modern Warfare 3\iw5sp.exe
- FirewallRules: [{22E9FD8C-4B9A-4CED-AA8C-CE16750F25C4}] => (Allow) D:\Steam\steamapps\common\Call of Duty Modern Warfare 3\iw5sp.exe
- FirewallRules: [{CE54E636-C9D5-45FB-A03A-C7A2789506C6}] => (Allow) D:\Steam\steamapps\common\Call of Duty Modern Warfare 3\iw5mp.exe
- FirewallRules: [{CD55F6D9-A4F9-4F64-A3EA-9AF5CF7D8D87}] => (Allow) D:\Steam\steamapps\common\Call of Duty Modern Warfare 3\iw5mp.exe
- FirewallRules: [{7F71852F-F3EB-406F-B1F8-2115F146D773}] => (Allow) D:\Steam\steamapps\common\Command and Conquer Red Alert 3\runme.exe
- FirewallRules: [{8B1D53B8-05CA-4140-B925-B2FB73C3CE7E}] => (Allow) D:\Steam\steamapps\common\Command and Conquer Red Alert 3\runme.exe
- FirewallRules: [{F107A64D-026D-4D73-9B33-D1487A3425BB}] => (Allow) D:\Steam\steamapps\common\Half-Life\hl.exe
- FirewallRules: [{36581326-12F7-46C4-90EA-E93929F657C1}] => (Allow) D:\Steam\steamapps\common\Half-Life\hl.exe
- FirewallRules: [{5F5218BC-AF5F-4517-AAA4-45330503D357}] => (Allow) D:\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe
- FirewallRules: [{4BB944E3-1D1E-46C0-8398-73755DB6E9C7}] => (Allow) D:\Steam\steamapps\common\Counter-Strike Global Offensive\csgo.exe
- FirewallRules: [{FF5AF6B9-C466-4DBD-8EC9-FBF81A8946D6}] => (Allow) D:\Steam\steamapps\common\Daikatana\daikatana.exe
- FirewallRules: [{D360ED61-CA86-48B8-856F-CE95745F8FC1}] => (Allow) D:\Steam\steamapps\common\Daikatana\daikatana.exe
- FirewallRules: [{C100A41E-E967-4E0B-9510-B34C91C10699}] => (Allow) D:\Steam\steamapps\common\DayZ\DayZ_BE.exe
- FirewallRules: [{43C43D4E-9BCB-4D0D-B071-A7E84694A419}] => (Allow) D:\Steam\steamapps\common\DayZ\DayZ_BE.exe
- FirewallRules: [{3CF0D4E8-E5C6-4AF0-8D4D-28949C294D66}] => (Allow) D:\Steam\steamapps\common\DeadEffect\DeadEffect.exe
- FirewallRules: [{3668B7B2-7D6F-458C-A23A-FE535C3F787B}] => (Allow) D:\Steam\steamapps\common\DeadEffect\DeadEffect.exe
- FirewallRules: [{D223B672-86E2-4121-B69B-6283E2CAF905}] => (Allow) D:\Steam\steamapps\common\Dead Island Epidemic\Dead Island Epidemic - Launcher.exe
- FirewallRules: [{9C2B5B0A-1F04-419C-8FFE-2BC6CA702E5C}] => (Allow) D:\Steam\steamapps\common\Dead Island Epidemic\Dead Island Epidemic - Launcher.exe
- FirewallRules: [{C4FC09A9-AFD5-49B6-8141-CF6DB0F5A31C}] => (Allow) D:\Steam\steamapps\common\DepthHunter2\dh2.exe
- FirewallRules: [{89AA7F10-816B-4EF5-ADD1-2B60D186F0FB}] => (Allow) D:\Steam\steamapps\common\DepthHunter2\dh2.exe
- FirewallRules: [{57B90B0A-3513-438B-B574-DDED11147758}] => (Allow) D:\Steam\steamapps\common\Deus Ex Human Revolution Director's Cut\DXHRDC.exe
- FirewallRules: [{E3B4D56B-76EF-446E-9B5A-F63A04524700}] => (Allow) D:\Steam\steamapps\common\Deus Ex Human Revolution Director's Cut\DXHRDC.exe
- FirewallRules: [{69357F98-7A3B-4F4A-94B7-BDEDC2AFF262}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
- FirewallRules: [{F34C5977-94DF-4B72-99D1-459DAF6353EE}] => (Allow) D:\Steam\steamapps\common\dota 2 beta\game\bin\win64\dota2.exe
- FirewallRules: [{52EAB1A6-99DC-4E68-B7D6-DE0072034EE7}] => (Allow) D:\Steam\steamapps\common\dota 2 test\game\bin\win64\dota2.exe
- FirewallRules: [{C794EE68-38AB-4870-BEE4-0E9DD4AD7909}] => (Allow) D:\Steam\steamapps\common\dota 2 test\game\bin\win64\dota2.exe
- FirewallRules: [{043B087B-4DBE-4D84-BEEF-E17B00AE62F0}] => (Allow) D:\Steam\steamapps\common\dream_pinball_3D\dp3d.exe
- FirewallRules: [{1C2ADECD-5AE7-4223-83D5-5AD227448314}] => (Allow) D:\Steam\steamapps\common\dream_pinball_3D\dp3d.exe
- FirewallRules: [{EB6EB93C-2865-4079-8A9A-3FA1A685A4FD}] => (Allow) D:\Steam\steamapps\common\Emily Wants To Play\EmilyWantsToPlay.exe
- FirewallRules: [{BB72DF31-8595-4310-ABAC-108BD17FCD14}] => (Allow) D:\Steam\steamapps\common\Emily Wants To Play\EmilyWantsToPlay.exe
- FirewallRules: [{AEF12375-38A8-4FFD-8911-30310B4AE7AA}] => (Allow) D:\Steam\steamapps\common\Enclave\Enclave.exe
- FirewallRules: [{63E5C8F2-32B1-47AF-BB22-3AB71885AD48}] => (Allow) D:\Steam\steamapps\common\Enclave\Enclave.exe
- FirewallRules: [{1039A38A-9200-4528-BA46-0479EF616267}] => (Allow) D:\Steam\steamapps\common\Europa Universalis III - Complete\eu3game.exe
- FirewallRules: [{C67F9579-B1C3-4E2C-B796-CD8B3BAF360A}] => (Allow) D:\Steam\steamapps\common\Europa Universalis III - Complete\eu3game.exe
- FirewallRules: [{B26903C7-5397-4A34-A99A-6D6DA5AF761B}] => (Allow) D:\Steam\steamapps\common\TheEvilWithin\EvilWithin.exe
- FirewallRules: [{B0F54D83-E8C2-4FF4-AD3B-A4DD085691F4}] => (Allow) D:\Steam\steamapps\common\TheEvilWithin\EvilWithin.exe
- FirewallRules: [{50B909C6-70D4-4A48-80FF-2BEF5D6BCBDD}] => (Allow) D:\Steam\steamapps\common\Five Nights at Freddy's\FiveNightsatFreddys.exe
- FirewallRules: [{83D14F92-6D5F-44E8-9B65-8A086FFA134E}] => (Allow) D:\Steam\steamapps\common\Five Nights at Freddy's\FiveNightsatFreddys.exe
- FirewallRules: [{7DCD86BC-BA06-4E7C-AE45-4EB188436086}] => (Allow) D:\Steam\steamapps\common\FlatOut2\FlatOut2.exe
- FirewallRules: [{47E50B44-21CC-4ECF-AF29-F2315C0E91E7}] => (Allow) D:\Steam\steamapps\common\FlatOut2\FlatOut2.exe
- FirewallRules: [{63B96712-BDC9-4869-B7DC-AD64856769A1}] => (Allow) D:\Steam\steamapps\common\Glacier 3 The Meltdown\Game.exe
- FirewallRules: [{6469ACA9-FC0F-4869-A383-B1C68ADDACF0}] => (Allow) D:\Steam\steamapps\common\Glacier 3 The Meltdown\Game.exe
- FirewallRules: [{CDCE12F1-6A46-4879-9443-1EA24FECBE36}] => (Allow) D:\Steam\steamapps\common\Gorky 17\gorky17.exe
- FirewallRules: [{3DB7D2E9-A0DD-4997-8232-B5B95A43BCEC}] => (Allow) D:\Steam\steamapps\common\Gorky 17\gorky17.exe
- FirewallRules: [{AA9C11A6-7D27-4FC8-A8E7-3B78545C700F}] => (Allow) D:\Steam\steamapps\common\Grand Theft Auto San Andreas\gta-sa.exe
- FirewallRules: [{0849732F-567D-41BA-BB08-CD922B7F9B86}] => (Allow) D:\Steam\steamapps\common\Grand Theft Auto San Andreas\gta-sa.exe
- FirewallRules: [{A5872CD8-84BD-425E-B138-5532658E615E}] => (Allow) D:\Steam\steamapps\common\Flesh Eaters\game.exe
- FirewallRules: [{1966BE04-730E-49A5-BE46-41A3D100A8D7}] => (Allow) D:\Steam\steamapps\common\Flesh Eaters\game.exe
- FirewallRules: [{FB92F6EE-1E10-4F4A-90F1-7DB35EB828E6}] => (Allow) D:\Steam\steamapps\common\H1Z1\LaunchPad.exe
- FirewallRules: [{458F29DF-2F69-4DD8-BCD0-ED8B18E7F42F}] => (Allow) D:\Steam\steamapps\common\H1Z1\LaunchPad.exe
- FirewallRules: [{A57EF2E2-7808-48ED-8CD5-4765E6E21EBA}] => (Allow) D:\Steam\steamapps\common\H1Z1 Test\LaunchPad.exe
- FirewallRules: [{50678F0C-BAA0-41E2-B178-1C45F9121643}] => (Allow) D:\Steam\steamapps\common\H1Z1 Test\LaunchPad.exe
- FirewallRules: [{3E0DF177-5DA5-421B-84A4-63A99AFB6281}] => (Allow) D:\Steam\steamapps\common\Hacker Evolution\HackerEvolution.exe
- FirewallRules: [{2C738BDF-8C5A-4D06-AC63-2F1FC4710775}] => (Allow) D:\Steam\steamapps\common\Hacker Evolution\HackerEvolution.exe
- FirewallRules: [{B15A56CA-3A99-4A89-A5EE-DB550A3667D6}] => (Allow) D:\Steam\steamapps\common\Hacker Evolution\HackerEvolutionModEditor.exe
- FirewallRules: [{E06E544F-F043-49A9-AF0C-E3F414B7114C}] => (Allow) D:\Steam\steamapps\common\Hacker Evolution\HackerEvolutionModEditor.exe
- FirewallRules: [{A8E7F649-B235-489C-A4B4-B51BD28C920B}] => (Allow) D:\Steam\steamapps\common\Hacker Evolution Untold\Hacker Evolution Untold.exe
- FirewallRules: [{360920C9-7C79-404E-AC19-9D78A99F2C94}] => (Allow) D:\Steam\steamapps\common\Hacker Evolution Untold\Hacker Evolution Untold.exe
- FirewallRules: [{D1FAEEAA-C4B4-4333-B288-0E8FA775A215}] => (Allow) D:\Steam\steamapps\common\Hacker Evolution Untold\Hacker Evolution Mod Editor.exe
- FirewallRules: [{5EDCCCE7-922F-4AA2-9118-498A14935CB4}] => (Allow) D:\Steam\steamapps\common\Hacker Evolution Untold\Hacker Evolution Mod Editor.exe
- FirewallRules: [{E0AC2E83-DC30-430A-B836-0D9904C29432}] => (Allow) D:\Steam\steamapps\common\Half-Life 2\hl2.exe
- FirewallRules: [{1146B8B5-DAAF-4F38-A387-5861BC02EEF6}] => (Allow) D:\Steam\steamapps\common\Half-Life 2\hl2.exe
- FirewallRules: [{A3AF3346-9409-465A-8229-129E461C58B7}] => (Allow) D:\Steam\steamapps\common\Half-Life 2 Deathmatch\hl2.exe
- FirewallRules: [{D4BFA730-6E78-40A9-A5D4-8AB38017683A}] => (Allow) D:\Steam\steamapps\common\Half-Life 2 Deathmatch\hl2.exe
- FirewallRules: [{D98AFAB4-491E-4A5D-AFE2-02E917F763DC}] => (Allow) D:\Steam\steamapps\common\Hitman Codename 47\Hitman.Exe
- FirewallRules: [{61EAB410-0C0B-47AB-BFD5-F3DB3145709D}] => (Allow) D:\Steam\steamapps\common\Hitman Codename 47\Hitman.Exe
- FirewallRules: [{E3061087-538B-4FCC-9172-C5EA9568CF8C}] => (Allow) D:\Steam\steamapps\common\Hitman Codename 47\Setup.exe
- FirewallRules: [{F02E99C8-39F6-4444-A770-EEFEB206C8FC}] => (Allow) D:\Steam\steamapps\common\Hitman Codename 47\Setup.exe
- FirewallRules: [{CCE56B0E-E1BD-4EC2-A2DE-C698706372BD}] => (Allow) D:\Steam\steamapps\common\Hitman 2 Silent Assassin\hitman2.exe
- FirewallRules: [{7115E3C2-76D3-4CC8-BE0B-9324E5D0B230}] => (Allow) D:\Steam\steamapps\common\Hitman 2 Silent Assassin\hitman2.exe
- FirewallRules: [{181A5A4B-4CE6-4BDC-9B67-8662275D22D6}] => (Allow) D:\Steam\steamapps\common\Hitman 2 Silent Assassin\config.exe
- FirewallRules: [{342C3B9E-CDE8-4667-B0FD-0CBAEBCAB33E}] => (Allow) D:\Steam\steamapps\common\Hitman 2 Silent Assassin\config.exe
- FirewallRules: [{BB3FC575-FA62-4BA7-900F-AA53402B018F}] => (Allow) D:\Steam\steamapps\common\Watch_Dogs\bin\watch_dogs.exe
- FirewallRules: [{8694BCEC-D04E-4FD6-8D6D-F942FCDD00D7}] => (Allow) D:\Steam\steamapps\common\Watch_Dogs\bin\watch_dogs.exe
- FirewallRules: [{E59EFBB3-4B4B-409A-A98A-8365EE5F3DF9}] => (Allow) D:\Steam\steamapps\common\Trine 2\trine2_launcher.exe
- FirewallRules: [{58D81264-A693-408A-A3A2-30A7E093B21E}] => (Allow) D:\Steam\steamapps\common\Trine 2\trine2_launcher.exe
- FirewallRules: [{9DA1EB87-2133-4A55-81BD-6C4CF1A80A24}] => (Allow) D:\Steam\steamapps\common\RailWorks\RailWorks.exe
- FirewallRules: [{8A87A270-DB48-4B07-B1FF-152588717B32}] => (Allow) D:\Steam\steamapps\common\RailWorks\RailWorks.exe
- FirewallRules: [{F25356C0-272D-4FD1-92E3-B581B2009A32}] => (Allow) D:\Steam\steamapps\common\The Tower Of Elements\TowerOfElements.exe
- FirewallRules: [{E84072C5-396E-404E-B6D3-5339EB7F3BAD}] => (Allow) D:\Steam\steamapps\common\The Tower Of Elements\TowerOfElements.exe
- FirewallRules: [{382954C9-286C-4F1A-9B9D-5F2FD01C9ED1}] => (Allow) D:\Steam\steamapps\common\thief_gold\THIEF.EXE
- FirewallRules: [{E7DCB0E3-C2F0-4516-A6B4-CF6F3D4633CC}] => (Allow) D:\Steam\steamapps\common\thief_gold\THIEF.EXE
- FirewallRules: [{7140F6EC-7E24-4D44-B5A3-D823002E1F68}] => (Allow) D:\Steam\steamapps\common\Knights of the Old Republic II\swkotor2.exe
- FirewallRules: [{6D4DFB62-2F94-4B93-A2C8-57E4D47BAA52}] => (Allow) D:\Steam\steamapps\common\Knights of the Old Republic II\swkotor2.exe
- FirewallRules: [{FCF33FA2-5812-4245-A675-C9D62227E07D}] => (Allow) D:\Steam\steamapps\common\Star Chronicles Delta Quadrant\Delta Quadrant.exe
- FirewallRules: [{99A13297-8DCB-4B77-826C-AC12EFAAAE99}] => (Allow) D:\Steam\steamapps\common\Star Chronicles Delta Quadrant\Delta Quadrant.exe
- FirewallRules: [{3BB351E0-DA5A-46B0-B4A1-FBDA417B6CA7}] => (Allow) D:\Steam\steamapps\common\SpeedRunners\SpeedRunners.exe
- FirewallRules: [{B89D5D78-D0CC-4E97-8302-0BD2EDE5C256}] => (Allow) D:\Steam\steamapps\common\SpeedRunners\SpeedRunners.exe
- FirewallRules: [{C02E5E4C-A0D4-448F-A93A-57D15DA31C8E}] => (Allow) D:\Steam\steamapps\common\SmoothOperators\Smooth Operators.exe
- FirewallRules: [{0D34248E-D5F4-46AE-8400-2AF56441725D}] => (Allow) D:\Steam\steamapps\common\SmoothOperators\Smooth Operators.exe
- FirewallRules: [{13FD33F2-7BD8-4033-85FF-A66B6ABE363B}] => (Allow) D:\Steam\steamapps\common\Showerdad\SHOWERDAD.exe
- FirewallRules: [{1FA6A332-F13D-4B0B-8E9C-599EDD342394}] => (Allow) D:\Steam\steamapps\common\Showerdad\SHOWERDAD.exe
- FirewallRules: [{6E482C4D-8DA1-4230-B210-253EB954974C}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
- FirewallRules: [{002CB99C-6A3D-48CE-9B9B-592B08582628}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
- FirewallRules: [{DF8130D3-5C1B-4428-9F9D-61420AD6EA54}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
- FirewallRules: [{6B815673-13F5-453E-BF19-BE7F441BA4C7}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
- FirewallRules: [{E5D66418-D83E-42AD-A01C-36CB03B4D8FF}] => (Allow) D:\Steam\steamapps\common\Portal\hl2.exe
- FirewallRules: [{1252FC11-18D2-41CE-A823-0CF2B915A692}] => (Allow) D:\Steam\steamapps\common\Portal\hl2.exe
- FirewallRules: [{89754926-9022-415A-8CC1-BA623A4C0814}] => (Allow) D:\Steam\steamapps\common\Just Cause 2 - Multiplayer Mod\JcmpLauncher.exe
- FirewallRules: [{4FF3E2AE-7FF3-4116-AD5C-111D879AB8C7}] => (Allow) D:\Steam\steamapps\common\Just Cause 2 - Multiplayer Mod\JcmpLauncher.exe
- FirewallRules: [{110EEE78-94B2-4674-8419-F6538441A887}] => (Allow) D:\Steam\steamapps\common\Knights and Merchants Historical Version\KM_TPR.exe
- FirewallRules: [{1F77DAF5-D028-483E-B137-F0ADD5F75712}] => (Allow) D:\Steam\steamapps\common\Knights and Merchants Historical Version\KM_TPR.exe
- FirewallRules: [{1A843F62-B184-4120-97D6-381977B1C6EB}] => (Allow) D:\Steam\steamapps\common\Knights and Merchants Historical Version\hd\Knights_and_Merchants_steam.exe
- FirewallRules: [{97A233D1-F53C-430F-A0B7-AD4C0FA561D3}] => (Allow) D:\Steam\steamapps\common\Knights and Merchants Historical Version\hd\Knights_and_Merchants_steam.exe
- FirewallRules: [{C7D66EC2-C461-422E-8080-3AAE50055E2A}] => (Allow) D:\Steam\steamapps\common\KnightShift\KnightShift.exe
- FirewallRules: [{6A79556C-5AA0-425E-BF08-6C492CA69BEF}] => (Allow) D:\Steam\steamapps\common\KnightShift\KnightShift.exe
- FirewallRules: [{6513DDE1-FADD-4D60-AD95-9B02BDC04585}] => (Allow) D:\Steam\steamapps\common\RollerCoaster Tycoon Deluxe\RCT.EXE
- FirewallRules: [{C8344AC8-DC57-4492-8436-62F90C108558}] => (Allow) D:\Steam\steamapps\common\RollerCoaster Tycoon Deluxe\RCT.EXE
- FirewallRules: [{6F65E3AB-D45B-40BA-814E-E64E0073A519}] => (Allow) D:\Steam\steamapps\common\Left 4 Dead 2\left4dead2.exe
- FirewallRules: [{CC9C386D-1233-46C8-9B7C-6129A101E9A5}] => (Allow) D:\Steam\steamapps\common\Left 4 Dead 2\left4dead2.exe
- FirewallRules: [{B6A4FB19-7A7D-4EAF-B2AA-0AA758C752D3}] => (Allow) D:\Steam\steamapps\common\Left 4 Dead 2 Beta\left4dead2_beta.exe
- FirewallRules: [{A5AE303F-7220-4742-8801-8F6CCA5F3F76}] => (Allow) D:\Steam\steamapps\common\Left 4 Dead 2 Beta\left4dead2_beta.exe
- FirewallRules: [{6A8095B6-938E-4C4B-A2C4-C93B7C61E915}] => (Allow) D:\Steam\steamapps\common\Landmark\LaunchPad.exe
- FirewallRules: [{29537D10-68F9-4BCB-A8E0-D0DA7DD38ABF}] => (Allow) D:\Steam\steamapps\common\Landmark\LaunchPad.exe
- FirewallRules: [{A67563B0-B281-4C85-AE07-117A36DF26F3}] => (Allow) D:\Steam\steamapps\common\New kind of adventure\NKOAgame.exe
- FirewallRules: [{AFF42B46-DE83-4ED0-82A1-658EC29B925D}] => (Allow) D:\Steam\steamapps\common\New kind of adventure\NKOAgame.exe
- FirewallRules: [{46CB0F81-BA3F-4086-ABFD-7C94E716A154}] => (Allow) D:\Steam\steamapps\common\Outlast\OutlastLauncher.exe
- FirewallRules: [{442A0E07-3426-4DE3-90CB-CE041C61E394}] => (Allow) D:\Steam\steamapps\common\Outlast\OutlastLauncher.exe
- FirewallRules: [{EE35B909-3B8A-4653-966A-1BD8F77A640D}] => (Allow) D:\Steam\steamapps\common\PAYDAY 2\payday2_win32_release.exe
- FirewallRules: [{FFB79FD4-B52B-40F5-8659-ADC67D278E0B}] => (Allow) D:\Steam\steamapps\common\PAYDAY 2\payday2_win32_release.exe
- FirewallRules: [{C74B3FE7-1FFD-4204-A430-1177CE468766}] => (Allow) D:\Steam\steamapps\common\Saints Row IV\SaintsRowIV.exe
- FirewallRules: [{BA85315B-AA69-42E3-AE69-71E3836F9628}] => (Allow) D:\Steam\steamapps\common\Saints Row IV\SaintsRowIV.exe
- FirewallRules: [{44A19B1B-28C6-429A-8ED7-F1E2161620FA}] => (Allow) D:\Steam\steamapps\common\mirrors edge\Binaries\MirrorsEdge.exe
- FirewallRules: [{F14FC1D4-C062-4290-B05B-354F44006CC3}] => (Allow) D:\Steam\steamapps\common\mirrors edge\Binaries\MirrorsEdge.exe
- FirewallRules: [{2F94C7D8-1336-4465-A4B4-EA24315E065D}] => (Allow) D:\Steam\steamapps\common\Just Cause 2\JustCause2.exe
- FirewallRules: [{02D904AB-46CF-4445-881D-9B2EC904E12F}] => (Allow) D:\Steam\steamapps\common\Just Cause 2\JustCause2.exe
- FirewallRules: [{FE0FEA8D-CEF2-46C3-8E97-21D24AA34CDC}] => (Allow) D:\Steam\steamapps\common\STALKER Shadow of Chernobyl\bin\XR_3DA.exe
- FirewallRules: [{8B8A62BE-9372-40C6-BC1C-E1E2C9A8E012}] => (Allow) D:\Steam\steamapps\common\STALKER Shadow of Chernobyl\bin\XR_3DA.exe
- FirewallRules: [{AB0CFF14-C92F-483D-AF11-244A2B1F81ED}] => (Allow) D:\Steam\steamapps\common\PAYDAY The Heist\payday_win32_release.exe
- FirewallRules: [{1B3B5376-BC4E-479A-BD24-1F6F6ECA3AE3}] => (Allow) D:\Steam\steamapps\common\PAYDAY The Heist\payday_win32_release.exe
- FirewallRules: [{84BDA7E9-CA20-4C7A-8C02-ADE817C50678}] => (Allow) D:\Steam\steamapps\common\Metro 2033\metro2033.exe
- FirewallRules: [{64D70BE8-C7C0-4A8A-B2A4-D1C6E053A3C2}] => (Allow) D:\Steam\steamapps\common\Metro 2033\metro2033.exe
- FirewallRules: [{9FFA3A2E-4C52-4101-A178-F092F296268D}] => (Allow) D:\Steam\steamapps\common\Mini Ninjas\ninja.exe
- FirewallRules: [{8B81E7F6-C774-4ECF-A01D-3E7E0E1E0BC5}] => (Allow) D:\Steam\steamapps\common\Mini Ninjas\ninja.exe
- FirewallRules: [{89E0D97B-6353-4425-B979-DE2FF027E277}] => (Allow) D:\Steam\steamapps\common\Krater\run_game.exe
- FirewallRules: [{C50F7D15-603C-4F20-BDF0-70E7A1CA804C}] => (Allow) D:\Steam\steamapps\common\Krater\run_game.exe
- FirewallRules: [{292DECFB-5F18-499A-A6F0-DF62C7AAC120}] => (Allow) D:\Steam\steamapps\common\insurgency2\insurgency.exe
- FirewallRules: [{B7359ED9-4BB9-42A0-A162-0283D1F6FC98}] => (Allow) D:\Steam\steamapps\common\insurgency2\insurgency.exe
- FirewallRules: [{68E49064-02AA-47EB-BACB-CA8FAFD361AE}] => (Allow) D:\Steam\steamapps\common\Counter-Strike Source\hl2.exe
- FirewallRules: [{AF6E5F9C-88F6-4AF4-83AE-DA0536BB1912}] => (Allow) D:\Steam\steamapps\common\Counter-Strike Source\hl2.exe
- FirewallRules: [{04705EFD-B763-4004-94D6-A7F28A148B36}] => (Allow) D:\Steam\steamapps\common\Need for Speed Hot Pursuit\NFS11.exe
- FirewallRules: [{98B847DA-83BD-4500-9F37-9B0F4215FB61}] => (Allow) D:\Steam\steamapps\common\Need for Speed Hot Pursuit\NFS11.exe
- FirewallRules: [{1F49C09F-AE4F-4B89-A5D5-63EFCD599CFF}] => (Allow) D:\Steam\steamapps\common\Sniper Ghost Warrior\Sniper_x86.exe
- FirewallRules: [{90D600C6-5696-45A0-9CC6-F36139F20F45}] => (Allow) D:\Steam\steamapps\common\Sniper Ghost Warrior\Sniper_x86.exe
- FirewallRules: [{648AA4EB-DD0C-45CE-9228-D933030C208A}] => (Allow) D:\Steam\steamapps\common\Sniper Art of Victory\Sniper.exe
- FirewallRules: [{85F0D49D-95CA-4491-9C37-2D8954C6E3FB}] => (Allow) D:\Steam\steamapps\common\Sniper Art of Victory\Sniper.exe
- FirewallRules: [{E8846932-51C2-4442-B1A7-0C719861ECF4}] => (Allow) D:\Steam\steamapps\common\SniperGhostWarrior2\Bin32\SniperGhostWarrior2.exe
- FirewallRules: [{2E4FC536-D786-4913-8F3D-CAA544583C6D}] => (Allow) D:\Steam\steamapps\common\SniperGhostWarrior2\Bin32\SniperGhostWarrior2.exe
- FirewallRules: [{400EFE22-E7D0-4904-AD64-070E84782AD1}] => (Allow) D:\Steam\steamapps\common\GarrysMod\hl2.exe
- FirewallRules: [{F8C4035E-62FC-4F7A-AD1E-42757CFD322B}] => (Allow) D:\Steam\steamapps\common\GarrysMod\hl2.exe
- FirewallRules: [{98C13DD0-672F-42A2-A244-79A1D0B36C06}] => (Allow) C:\Users\AngryShadow\AppData\Roaming\uTorrent\uTorrent.exe
- FirewallRules: [{51D6C715-63B1-4379-89B4-FD775CAB0C09}] => (Allow) C:\Users\AngryShadow\AppData\Roaming\uTorrent\uTorrent.exe
- FirewallRules: [{7D5E9ECD-660F-4C6A-A73E-6263DC522E2B}] => (Allow) C:\Users\AngryShadow\AppData\Roaming\uTorrent\uTorrent.exe
- FirewallRules: [{5927FD80-5257-4471-9FA8-0DF8299B08BA}] => (Allow) C:\Users\AngryShadow\AppData\Roaming\uTorrent\uTorrent.exe
- FirewallRules: [{7CF75122-7D76-44AA-8D4F-AD8757A915AF}] => (Allow) C:\Users\AngryShadow\AppData\Roaming\uTorrent\uTorrent.exe
- FirewallRules: [{B9AD5A91-9CAF-4CE0-9875-A3A1E32772A8}] => (Allow) C:\Users\AngryShadow\AppData\Roaming\uTorrent\uTorrent.exe
- FirewallRules: [TCP Query User{BA6CCF23-9963-40FD-AAA5-1F5A8AD24D55}C:\users\angryshadow\downloads\samp037_svr_r2-1-1_win32\samp-server.exe] => (Allow) C:\users\angryshadow\downloads\samp037_svr_r2-1-1_win32\samp-server.exe
- FirewallRules: [UDP Query User{902E52F3-B54A-4075-9B82-84F904BBBA31}C:\users\angryshadow\downloads\samp037_svr_r2-1-1_win32\samp-server.exe] => (Allow) C:\users\angryshadow\downloads\samp037_svr_r2-1-1_win32\samp-server.exe
- FirewallRules: [{44F376AF-74D8-449C-845F-74753D843603}] => (Allow) LPort=7777
- FirewallRules: [{D2DF8CA6-88DD-46F2-AFF1-EC01A355BD0F}] => (Allow) LPort=7777
- FirewallRules: [TCP Query User{E920AE0F-216C-4D70-BF81-ED14D5D9B902}C:\program files (x86)\portforward.com\portforward network utilities\pfportchecker.exe] => (Allow) C:\program files (x86)\portforward.com\portforward network utilities\pfportchecker.exe
- FirewallRules: [UDP Query User{311A45B8-27A9-49D9-933F-F093BEE3367D}C:\program files (x86)\portforward.com\portforward network utilities\pfportchecker.exe] => (Allow) C:\program files (x86)\portforward.com\portforward network utilities\pfportchecker.exe
- FirewallRules: [{DDEDBBB0-1E0D-4EC8-8939-C59B88407C78}] => (Allow) D:\Steam\steamapps\common\DiRT Rally\drt.exe
- FirewallRules: [{10CD3B90-F1C9-466F-B92E-41C6C4D71A2F}] => (Allow) D:\Steam\steamapps\common\DiRT Rally\drt.exe
- FirewallRules: [TCP Query User{FBAECAF8-C86B-4BAA-89B5-9035D96C0925}C:\users\angryshadow\downloads\darkcometrat531\darkcomet.exe] => (Allow) C:\users\angryshadow\downloads\darkcometrat531\darkcomet.exe
- FirewallRules: [UDP Query User{A66F7CE2-04BF-472D-B418-5B3ACE2713D8}C:\users\angryshadow\downloads\darkcometrat531\darkcomet.exe] => (Allow) C:\users\angryshadow\downloads\darkcometrat531\darkcomet.exe
- FirewallRules: [TCP Query User{230B911E-B635-4B1D-BB87-FBA17CC89726}C:\users\angryshadow\downloads\nanocore-cracked\nanocore cracked\nanocore_cracked.exe] => (Allow) C:\users\angryshadow\downloads\nanocore-cracked\nanocore cracked\nanocore_cracked.exe
- FirewallRules: [UDP Query User{EE3E3B96-50A4-4862-8E74-AAA9FB6E2FFB}C:\users\angryshadow\downloads\nanocore-cracked\nanocore cracked\nanocore_cracked.exe] => (Allow) C:\users\angryshadow\downloads\nanocore-cracked\nanocore cracked\nanocore_cracked.exe
- FirewallRules: [{FDBE683C-2D74-4893-ABD1-4962B8726AC6}] => (Allow) D:\Steam\steamapps\common\Euro Truck Simulator 2\bin\win_x86\eurotrucks2.exe
- FirewallRules: [{1410C4C1-E129-4BDC-9852-97996A512278}] => (Allow) D:\Steam\steamapps\common\Euro Truck Simulator 2\bin\win_x86\eurotrucks2.exe
- FirewallRules: [{4A11FD5E-F9D0-41A7-89FF-69EB77E9D171}] => (Allow) D:\Steam\steamapps\common\Euro Truck Simulator 2\bin\win_x64\eurotrucks2.exe
- FirewallRules: [{B66F8DF8-04B2-4690-83BB-33E55023C489}] => (Allow) D:\Steam\steamapps\common\Euro Truck Simulator 2\bin\win_x64\eurotrucks2.exe
- FirewallRules: [{788226CA-B619-45C8-AD8A-384589EA1F41}] => (Allow) C:\Program Files (x86)\SpringFiles\SpringFiles.exe
- FirewallRules: [{CACEE9BD-64F6-4953-A2F5-2097467F974F}] => (Allow) C:\Program Files (x86)\SpringFiles\SpringFiles.exe
- FirewallRules: [{7E5CCAF1-D39E-4EE6-B74C-6618EFD6EDE5}] => (Allow) C:\Program Files (x86)\SpringFiles\downloader.exe
- FirewallRules: [{675563DC-9AA3-47FC-8B52-80DE083E02B0}] => (Allow) C:\Program Files (x86)\SpringFiles\downloader.exe
- FirewallRules: [{586F0FE1-4716-4CC6-A06B-1BD631CEF2A5}] => (Allow) C:\Users\AngryShadow\AppData\Local\Temp\net.exe
- FirewallRules: [{F8A3355F-BC16-41BD-98A8-C762C432F89A}] => (Allow) C:\Users\AngryShadow\AppData\Local\Temp\net.exe
- FirewallRules: [{84FCF3B3-9EA4-4254-A9C3-180AC9A2D542}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- FirewallRules: [{A06D0351-0623-4B1E-8EA3-8A11142EC479}] => (Allow) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
- ==================== Restore Points =========================
- ATTENTION: System Restore is disabled
- ==================== Faulty Device Manager Devices =============
- ==================== Event log errors: =========================
- Application errors:
- ==================
- Error: (01/16/2016 01:36:41 PM) (Source: Wininit) (EventID: 1015) (User: )
- Description: A critical system process, C:\WINDOWS\system32\lsass.exe, failed with status code 1. The machine must now be restarted.
- Error: (01/16/2016 01:35:19 PM) (Source: Perflib) (EventID: 1008) (User: )
- Description: WmiApRplC:\WINDOWS\system32\wbem\wmiaprpl.dll4
- Error: (01/16/2016 01:35:19 PM) (Source: Perflib) (EventID: 1023) (User: )
- Description: rdyboost4
- Error: (01/16/2016 01:35:19 PM) (Source: PerfNet) (EventID: 2004) (User: )
- Description:
- Error: (01/16/2016 01:35:19 PM) (Source: Perflib) (EventID: 1008) (User: )
- Description: MSDTCC:\WINDOWS\system32\msdtcuiu.DLL4
- Error: (01/16/2016 01:35:19 PM) (Source: Perflib) (EventID: 1008) (User: )
- Description: LsaC:\Windows\System32\Secur32.dll4
- Error: (01/16/2016 01:35:19 PM) (Source: Perflib) (EventID: 1008) (User: )
- Description: ESENTC:\WINDOWS\system32\esentprf.dll4
- Error: (01/16/2016 01:35:19 PM) (Source: Perflib) (EventID: 1008) (User: )
- Description: BITSC:\Windows\System32\bitsperf.dll4
- Error: (01/16/2016 01:35:13 PM) (Source: Application Error) (EventID: 1000) (User: )
- Description: Faulting application name: McAfee.TrueKey.Service.exe, version: 3.4.174.0, time stamp: 0x5667423f
- Faulting module name: MSVCP120.dll, version: 12.0.21005.1, time stamp: 0x524f8413
- Exception code: 0xc0000005
- Fault offset: 0x000000000000d2c5
- Faulting process ID: 0xb50
- Faulting application start time: 0xMcAfee.TrueKey.Service.exe0
- Faulting application path: McAfee.TrueKey.Service.exe1
- Faulting module path: McAfee.TrueKey.Service.exe2
- Report ID: McAfee.TrueKey.Service.exe3
- Faulting package full name: McAfee.TrueKey.Service.exe4
- Faulting package-relative application ID: McAfee.TrueKey.Service.exe5
- Error: (01/16/2016 01:35:13 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
- Description: Application: McAfee.TrueKey.Service.exe
- Framework Version: v4.0.30319
- Description: The process was terminated due to an unhandled exception.
- Exception Info: System.AccessViolationException
- at <Module>.Intel.Pabe.Factor.FactorManager.GetFactorManager(std.shared_ptr<Intel::Pabe::Factor::FactorManager>*)
- at BCAAdapter.FactorManager..ctor()
- at McAfee.YAP.Service.Common.McBioBCAService.get_BCADeviceIdProvider()
- at McAfee.YAP.Service.Common.McBioBCAService.TryGetBcaProvisioningResults()
- at McAfee.YAP.Service.Common.McBioBCAService.GetBCAToken()
- at McAfee.YAP.Service.ServiceCommands.GetBCATokenCommand.Execute()
- at System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
- at System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
- at System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object)
- at System.Threading.ThreadHelper.ThreadStart()
- System errors:
- =============
- Error: (01/16/2016 09:18:43 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-MTUHMGO)
- Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}DESKTOP-MTUHMGOAngryShadowS-1-5-21-3985454009-819291025-207730266-1001LocalHost (Using LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742
- Error: (01/16/2016 09:18:43 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-MTUHMGO)
- Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}DESKTOP-MTUHMGOAngryShadowS-1-5-21-3985454009-819291025-207730266-1001LocalHost (Using LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742
- Error: (01/16/2016 09:18:43 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-MTUHMGO)
- Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}DESKTOP-MTUHMGOAngryShadowS-1-5-21-3985454009-819291025-207730266-1001LocalHost (Using LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742
- Error: (01/16/2016 09:18:43 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-MTUHMGO)
- Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}DESKTOP-MTUHMGOAngryShadowS-1-5-21-3985454009-819291025-207730266-1001LocalHost (Using LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742
- Error: (01/16/2016 09:18:43 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-MTUHMGO)
- Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}DESKTOP-MTUHMGOAngryShadowS-1-5-21-3985454009-819291025-207730266-1001LocalHost (Using LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742
- Error: (01/16/2016 09:18:43 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-MTUHMGO)
- Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}DESKTOP-MTUHMGOAngryShadowS-1-5-21-3985454009-819291025-207730266-1001LocalHost (Using LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742
- Error: (01/16/2016 09:18:43 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-MTUHMGO)
- Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}DESKTOP-MTUHMGOAngryShadowS-1-5-21-3985454009-819291025-207730266-1001LocalHost (Using LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742
- Error: (01/16/2016 09:18:43 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-MTUHMGO)
- Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}DESKTOP-MTUHMGOAngryShadowS-1-5-21-3985454009-819291025-207730266-1001LocalHost (Using LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742
- Error: (01/16/2016 09:18:43 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-MTUHMGO)
- Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}DESKTOP-MTUHMGOAngryShadowS-1-5-21-3985454009-819291025-207730266-1001LocalHost (Using LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742
- Error: (01/16/2016 09:18:43 PM) (Source: DCOM) (EventID: 10016) (User: DESKTOP-MTUHMGO)
- Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}DESKTOP-MTUHMGOAngryShadowS-1-5-21-3985454009-819291025-207730266-1001LocalHost (Using LRPC)Microsoft.Windows.Cortana_1.6.1.52_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742
- CodeIntegrity:
- ===================================
- Date: 2016-01-14 03:18:14.105
- Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
- Date: 2016-01-08 21:54:21.973
- Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
- Date: 2016-01-08 16:30:29.222
- Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\winhttp.dll because the set of per-page image hashes could not be found on the system.
- Date: 2016-01-08 16:30:29.216
- Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\winhttp.dll because the set of per-page image hashes could not be found on the system.
- Date: 2016-01-07 21:57:26.535
- Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
- Date: 2016-01-06 21:37:58.490
- Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
- Date: 2016-01-03 20:08:22.989
- Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
- Date: 2016-01-03 11:02:47.151
- Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
- Date: 2016-01-01 11:08:57.325
- Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
- Date: 2015-12-30 13:46:32.193
- Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume4\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
- ==================== Memory info ===========================
- Processor: Intel(R) Core(TM) i5-4440S CPU @ 2.80GHz
- Percentage of memory in use: 50%
- Total physical RAM: 8131.18 MB
- Available physical RAM: 4037.92 MB
- Total Virtual: 9411.18 MB
- Available Virtual: 5491.39 MB
- ==================== Drives ================================
- Drive c: () (Fixed) (Total:118.69 GB) (Free:77.06 GB) NTFS
- Drive d: (AngryDisc) (Fixed) (Total:931.51 GB) (Free:272.1 GB) NTFS
- ==================== MBR & Partition Table ==================
- ========================================================
- Disk: 0 (Size: 119.2 GB) (Disk ID: 697E540A)
- Partition: GPT.
- ========================================================
- Disk: 1 (Size: 931.5 GB) (Disk ID: 00000000)
- Partition: GPT.
- ==================== End of Addition.txt ============================
- Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:10-01-2015 01
- Ran by AngryShadow (administrator) on DESKTOP-MTUHMGO (16-01-2016 23:11:11)
- Running from C:\Users\AngryShadow\Desktop
- Loaded Profiles: AngryShadow (Available Profiles: AngryShadow)
- Platform: Windows 10 Home Version 1511 (X64) Language: English (United Kingdom)
- Internet Explorer Version 11 (Default browser: Chrome)
- Boot Mode: Normal
- Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
- ==================== Processes (Whitelisted) =================
- (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
- (McAfee, Inc.) C:\Windows\System32\mfevtps.exe
- (McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe
- (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
- (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
- (McAfee, Inc.) C:\Windows\System32\mfevtps.exe
- (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
- (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
- (McAfee, Inc.) C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe
- (McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
- (McAfee, Inc.) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
- (Microsoft Corporation) C:\Windows\System32\wlanext.exe
- (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
- (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
- (McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
- (Intel(R) Corporation) C:\Program Files\Intel\BCA\pabeSvc64.exe
- (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
- (McAfee, Inc.) C:\Program Files\McAfee\MSC\McAPExe.exe
- (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
- (McAfee Inc.) C:\Program Files\TrueKey\McAfee.TrueKey.Service.exe
- (Intel Corporation) C:\Program Files\TrueKey\McAfee.TrueKey.ServiceHelper.exe
- (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
- (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
- () C:\Program Files\WindowsApps\Microsoft.Messaging_2.12.15004.0_x86__8wekyb3d8bbwe\SkypeHost.exe
- (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
- (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
- (Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
- (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
- (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
- (Valve Corporation) D:\Steam\Steam.exe
- (Valve Corporation) D:\Steam\bin\steamwebhelper.exe
- (Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
- (Valve Corporation) D:\Steam\bin\steamwebhelper.exe
- (Valve Corporation) D:\Steam\bin\steamwebhelper.exe
- (McAfee, Inc.) C:\Program Files\Common Files\McAfee\CSP\1.8.203.0\McCSPServiceHost.exe
- (McAfee Inc.) C:\Program Files\TrueKey\McTkSchedulerService.exe
- () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_15.1208.10480.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
- (Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
- (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsStore_2015.25.15.0_x64__8wekyb3d8bbwe\WinStore.Mobile.exe
- (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.ZuneVideo_3.6.15731.0_x64__8wekyb3d8bbwe\Video.UI.exe
- (Microsoft Corporation) C:\Windows\System32\WWAHost.exe
- (Skype Technologies S.A.) D:\Skype\Phone\Skype.exe
- (BitTorrent Inc.) C:\Users\AngryShadow\AppData\Roaming\uTorrent\uTorrent.exe
- (BitTorrent Inc.) C:\Users\AngryShadow\AppData\Roaming\uTorrent\updates\3.4.5_41372\utorrentie.exe
- (BitTorrent Inc.) C:\Users\AngryShadow\AppData\Roaming\uTorrent\updates\3.4.5_41372\utorrentie.exe
- (McAfee, Inc.) C:\Program Files\Common Files\McAfee\Platform\McUICnt.exe
- (Disc Soft Ltd) C:\Users\AngryShadow\DAEMON Tools Pro\DiscSoftBusService.exe
- (Disc Soft Ltd) C:\Users\AngryShadow\DAEMON Tools Pro\DTShellHlp.exe
- Failed to access process -> sound.exe
- (SS) C:\Program Files (x86)\SwiftSearch_1.10.0.27\Service\swsesrvc.exe
- Failed to access process -> sound.exe
- Failed to access process -> sound.exe
- () C:\Program Files\WajaNetEn\6f7dd0d1a6b7295523cc41e34e4b9dfd.exe
- () C:\Program Files\WajaNetEn\7b1fae02d59a1789f5b8115c78fb3a25.exe
- () C:\Program Files\WajaNetEn\6f7dd0d1a6b7295523cc41e34e4b9dfd.exe
- (TData.com) C:\Program Files (x86)\TDataDld\TData.exe
- () C:\Program Files (x86)\Rockstar Games\GTA San Andreas\samp.exe
- (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
- ==================== Registry (Whitelisted) ===========================
- (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
- HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8725248 2015-11-09] (Realtek Semiconductor)
- HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1407744 2015-11-09] (Realtek Semiconductor)
- HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2785728 2016-01-09] (NVIDIA Corporation)
- HKLM\...\Run: [ShadowPlay] => "C:\WINDOWS\system32\rundll32.exe" C:\WINDOWS\system32\nvspcap64.dll,ShadowPlayOnSystemStart
- HKLM\...\Run: [MRT] => C:\WINDOWS\system32\MRT.exe [143671360 2016-01-15] (Microsoft Corporation)
- HKLM-x32\...\Run: [BlueStacks Agent] => C:\Program Files (x86)\BlueStacks\HD-Agent.exe
- HKLM-x32\...\Run: [51FBF9] => C:\Users\AngryShadow\AppData\Roaming\51FBF9\94C976.exe [1313280 2016-01-15] (Digia Plc and/or its subsidiary(-ies))
- HKLM-x32\...\RunOnce: [daemontoolspro] => [X]
- HKU\S-1-5-21-3985454009-819291025-207730266-1001\...\Run: [Steam] => D:\Steam\steam.exe [3013712 2015-12-14] (Valve Corporation)
- HKU\S-1-5-21-3985454009-819291025-207730266-1001\...\Run: [Skype] => D:\Skype\Phone\Skype.exe [50378880 2015-12-17] (Skype Technologies S.A.)
- HKU\S-1-5-21-3985454009-819291025-207730266-1001\...\Run: [uTorrent] => C:\Users\AngryShadow\AppData\Roaming\uTorrent\uTorrent.exe [2026520 2016-01-02] (BitTorrent Inc.)
- HKU\S-1-5-21-3985454009-819291025-207730266-1001\...\Run: [OtLandIPChanger] => "C:\Users\AngryShadow\Downloads\ipchanger.exe" /tray
- HKU\S-1-5-21-3985454009-819291025-207730266-1001\...\Run: [CyberGhost] => "C:\Program Files\CyberGhost 5\CyberGhost.exe" /autostart /min
- HKU\S-1-5-21-3985454009-819291025-207730266-1001\...\Run: [Gyazo] => C:\Program Files (x86)\Gyazo\GyStation.exe [3098424 2015-08-19] (Nota Inc.)
- HKU\S-1-5-21-3985454009-819291025-207730266-1001\...\Run: [DAEMON Tools Pro Agent] => C:\Users\AngryShadow\DAEMON Tools Pro\DTAgent.exe [4530520 2015-10-22] (Disc Soft Ltd)
- HKU\S-1-5-21-3985454009-819291025-207730266-1001\...\RunOnce: [Uninstall C:\Users\AngryShadow\AppData\Local\Microsoft\OneDrive\17.3.5892.0626\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\AngryShadow\AppData\Local\Microsoft\OneDrive\17.3.5892.0626\amd64"
- HKU\S-1-5-21-3985454009-819291025-207730266-1001\...\MountPoints2: {852846ab-b13a-11e5-b233-54271e79ff4c} - "K:\Autorun.exe"
- Lsa: [Notification Packages] scecli C:\Program Files\TrueKey\McAfeeTrueKeyPasswordFilter
- ==================== Internet (Whitelisted) ====================
- (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
- ProxyServer: [S-1-5-21-3985454009-819291025-207730266-1001] => :80
- AutoConfigURL: [S-1-5-21-3985454009-819291025-207730266-1001] => hxxp://unstopp.me/wpad.dat?10059f1f5c50e7e6c53befa742ce03893862147
- Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
- Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
- Tcpip\..\Interfaces\{33665f72-7c60-4174-b287-638bf896bb50}: [DhcpNameServer] 192.168.1.1
- Internet Explorer:
- ==================
- SearchScopes: HKU\S-1-5-21-3985454009-819291025-207730266-1001 -> DefaultScope {cf34d395-9ff1-49a0-98a5-8db1636431b1} URL =
- Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\McAfee\MSC\McSnIePl64.dll [2015-12-03] (McAfee, Inc.)
- Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\MSC\McSnIePl.dll [2015-12-03] (McAfee, Inc.)
- FireFox:
- ========
- FF Plugin: @mcafee.com/MSC,version=10 -> c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL [2015-12-03] ()
- FF Plugin-x32: @mcafee.com/MSC,version=10 -> c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL [2015-12-03] ()
- FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2015-12-16] (NVIDIA Corporation)
- FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2015-12-16] (NVIDIA Corporation)
- FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2016-01-14] (Google Inc.)
- FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2016-01-14] (Google Inc.)
- FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK
- FF Extension: McAfee Anti-Spam Thunderbird Extension - C:\Program Files\McAfee\MSK [2016-01-14] [not signed]
- Chrome:
- =======
- CHR HomePage: Profile 1 -> hxxp://www.yoursearching.com/?type=hp&ts=1452975515&z=374796605c0902467f0741ag7z7weoftam0w9w7gaw&from=exp2&uid=kingstonxrbu-sc400s37128g_50026b7244033f9e
- CHR StartupUrls: Profile 1 -> "hxxp://www.yoursearching.com/?type=hp&ts=1452975515&z=374796605c0902467f0741ag7z7weoftam0w9w7gaw&from=exp2&uid=kingstonxrbu-sc400s37128g_50026b7244033f9e"
- CHR DefaultSearchURL: Profile 1 -> hxxp://yoursearching.com/web?type=ds&ts=1452975515&z=374796605c0902467f0741ag7z7weoftam0w9w7gaw&from=exp2&uid=kingstonxrbu-sc400s37128g_50026b7244033f9e&q={searchTerms}
- CHR DefaultSearchKeyword: Profile 1 -> yoursearching
- CHR Profile: C:\Users\AngryShadow\AppData\Local\Google\Chrome\User Data\Default
- CHR Profile: C:\Users\AngryShadow\AppData\Local\Google\Chrome\User Data\Profile 1
- CHR Extension: (Google Slides) - C:\Users\AngryShadow\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-01-14]
- CHR Extension: (Google Docs) - C:\Users\AngryShadow\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2016-01-14]
- CHR Extension: (Google Drive) - C:\Users\AngryShadow\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-01-14]
- CHR Extension: (YouTube) - C:\Users\AngryShadow\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-01-14]
- CHR Extension: (Google Search) - C:\Users\AngryShadow\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2016-01-14]
- CHR Extension: (Google Sheets) - C:\Users\AngryShadow\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-01-14]
- CHR Extension: (Google Docs Offline) - C:\Users\AngryShadow\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-01-14]
- CHR Extension: (AdBlock) - C:\Users\AngryShadow\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2016-01-14]
- CHR Extension: (Ad.Block Super (V.1.12)) - C:\Users\AngryShadow\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\gkbdoaboglbogefhhjdbidcglknljkpe [2016-01-14]
- CHR Extension: (Chrome Web Store Payments) - C:\Users\AngryShadow\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-01-14]
- CHR Extension: (Gmail) - C:\Users\AngryShadow\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-01-14]
- ==================== Services (Whitelisted) ========================
- (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
- R3 Disc Soft Pro Bus Service; C:\Users\AngryShadow\DAEMON Tools Pro\DiscSoftBusService.exe [1292632 2015-10-22] (Disc Soft Ltd)
- R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1163200 2016-01-09] (NVIDIA Corporation)
- R2 HomeNetSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [451960 2015-11-02] (McAfee, Inc.)
- R2 IntelBCAsvc; C:\Program Files\Intel\BCA\pabeSvc64.exe [3070104 2015-11-20] (Intel(R) Corporation)
- R2 McAPExe; C:\Program Files\McAfee\MSC\McAPExe.exe [863448 2015-12-03] (McAfee, Inc.)
- R2 mccspsvc; C:\Program Files\Common Files\McAfee\CSP\1.8.203.0\McCSPServiceHost.exe [1694152 2015-12-02] (McAfee, Inc.)
- R2 McNaiAnn; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [451960 2015-11-02] (McAfee, Inc.)
- S3 McODS; C:\Program Files\McAfee\VirusScan\mcods.exe [679120 2015-10-20] (McAfee, Inc.)
- R2 mcpltsvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [451960 2015-11-02] (McAfee, Inc.)
- R2 McProxy; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [451960 2015-11-02] (McAfee, Inc.)
- R3 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [233680 2015-09-21] (McAfee, Inc.)
- R2 mfemms; C:\Program Files\Common Files\McAfee\SystemCore\\mfemms.exe [378848 2015-10-21] (McAfee, Inc.)
- R3 mfevtp; C:\WINDOWS\system32\mfevtps.exe [256840 2015-09-21] (McAfee, Inc.)
- R2 MSK80Service; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [451960 2015-11-02] (McAfee, Inc.)
- R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1879488 2016-01-09] (NVIDIA Corporation)
- R3 NvStreamNetworkSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [6308288 2016-01-09] (NVIDIA Corporation)
- R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [4812736 2016-01-09] (NVIDIA Corporation)
- S2 SkypeUpdate; D:\Skype\Updater\Updater.exe [327296 2015-07-09] (Skype Technologies)
- R2 swsesrvc_1.10.0.27; C:\Program Files (x86)\SwiftSearch_1.10.0.27\Service\swsesrvc.exe [301648 2015-10-23] (SS)
- R2 TDataSvr; C:\Program Files (x86)\TDataDld\TData.exe [204528 2016-01-15] (TData.com)
- R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [6889232 2015-12-14] (TeamViewer GmbH)
- R2 TrueKey; C:\Program Files\TrueKey\McAfee.TrueKey.Service.exe [796992 2015-12-08] (McAfee Inc.)
- R2 TrueKeyScheduler; C:\Program Files\TrueKey\McTkSchedulerService.exe [15224 2015-12-08] (McAfee Inc.)
- R2 TrueKeyServiceHelper; C:\Program Files\TrueKey\McAfee.TrueKey.ServiceHelper.exe [86864 2015-12-08] (Intel Corporation)
- R2 WajaNetEn Monitor; C:\Program Files\WajaNetEn\6f7dd0d1a6b7295523cc41e34e4b9dfd.exe [2829824 2016-01-13] () [File not signed]
- S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2015-10-30] (Microsoft Corporation)
- S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-10-30] (Microsoft Corporation)
- ===================== Drivers (Whitelisted) ==========================
- (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
- S3 cfwids; C:\Windows\System32\drivers\cfwids.sys [80760 2015-09-23] (McAfee, Inc.)
- S3 dtlitescsibus; C:\Windows\System32\drivers\dtlitescsibus.sys [30264 2015-12-11] (Disc Soft Ltd)
- S3 dtliteusbbus; C:\Windows\System32\drivers\dtliteusbbus.sys [47672 2016-01-16] (Disc Soft Ltd)
- R3 dtproscsibus; C:\Windows\System32\drivers\dtproscsibus.sys [30264 2016-01-16] (Disc Soft Ltd)
- R3 e1dexpress; C:\Windows\system32\DRIVERS\e1d65x64.sys [541672 2015-08-23] (Intel Corporation)
- R3 MEIx64; C:\Windows\System32\drivers\TeeDriverW8x64.sys [195336 2015-11-09] (Intel Corporation)
- R3 mfeaack; C:\Windows\System32\drivers\mfeaack.sys [415976 2015-09-23] (McAfee, Inc.)
- R3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [351120 2015-09-23] (McAfee, Inc.)
- S0 mfeelamk; C:\Windows\System32\drivers\mfeelamk.sys [82072 2015-09-23] (McAfee, Inc.)
- R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [497888 2015-09-23] (McAfee, Inc.)
- R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [841944 2015-09-23] (McAfee, Inc.)
- R3 mfencbdc; C:\Windows\system32\DRIVERS\mfencbdc.sys [537192 2015-10-06] (McAfee, Inc.)
- S3 mfencrk; C:\Windows\system32\DRIVERS\mfencrk.sys [109480 2015-10-06] (McAfee, Inc.)
- R0 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [244544 2015-09-23] (McAfee, Inc.)
- R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [26560 2016-01-09] (NVIDIA Corporation)
- S3 NVSWCFilter; C:\Windows\System32\drivers\nvswcfilter.sys [28344 2015-10-15] (Windows (R) Win 7 DDK provider)
- R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [47760 2015-12-18] (NVIDIA Corporation)
- R3 RtkBtFilter; C:\Windows\system32\DRIVERS\RtkBtfilter.sys [593624 2015-12-11] (Realtek Semiconductor Corporation)
- R3 RTWlanE; C:\Windows\System32\drivers\rtwlane.sys [4705008 2015-09-03] (Realtek Semiconductor Corporation )
- R1 swsedrvr_vw_1_10_0_27; C:\Windows\System32\drivers\swsedrvr_vw_1_10_0_27.sys [57720 2015-10-23] (SS)
- R1 VBoxNetAdp; C:\Windows\system32\DRIVERS\VBoxNetAdp6.sys [117768 2015-12-18] (Oracle Corporation)
- R1 VBoxNetLwf; C:\Windows\system32\DRIVERS\VBoxNetLwf.sys [194976 2015-12-18] (Oracle Corporation)
- S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation)
- S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation)
- S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation)
- S3 VBoxNetFlt; \SystemRoot\system32\DRIVERS\VBoxNetFlt.sys [X]
- U3 wampapache64; no ImagePath
- S1 zrdkzifv; \??\C:\WINDOWS\system32\drivers\zrdkzifv.sys [X]
- ==================== NetSvcs (Whitelisted) ===================
- (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
- ==================== One Month Created files and folders ========
- (If an entry is included in the fixlist, the file/folder will be moved.)
- 2016-01-16 23:11 - 2016-01-16 23:11 - 00019113 _____ C:\Users\AngryShadow\Desktop\FRST.txt
- 2016-01-16 22:49 - 2016-01-16 22:49 - 00069381 _____ C:\Users\AngryShadow\Downloads\Addition.txt
- 2016-01-16 22:48 - 2016-01-16 23:11 - 00000000 ____D C:\FRST
- 2016-01-16 22:48 - 2016-01-16 22:49 - 00101498 _____ C:\Users\AngryShadow\Downloads\FRST.txt
- 2016-01-16 22:48 - 2016-01-16 22:48 - 02370560 _____ (Farbar) C:\Users\AngryShadow\Desktop\FRST64.exe
- 2016-01-16 21:19 - 2016-01-16 21:19 - 00000000 ____D C:\Program Files (x86)\TDataDld
- 2016-01-16 21:18 - 2016-01-16 21:19 - 00000000 ____D C:\Users\AngryShadow\AppData\Roaming\yoursearching
- 2016-01-16 21:04 - 2016-01-16 21:05 - 00000000 ____D C:\Program Files\WajaNetEn
- 2016-01-16 21:03 - 2016-01-16 21:03 - 00624696 _____ C:\Users\AngryShadow\AppData\Roaming\im201506.exe
- 2016-01-16 21:03 - 2016-01-16 21:03 - 00000000 _____ C:\Users\AngryShadow\AppData\Roaming\g78rfdsafhi
- 2016-01-16 21:02 - 2016-01-16 21:03 - 00000000 __SHD C:\Users\AngryShadow\AppData\Roaming\51FBF9
- 2016-01-16 21:02 - 2016-01-16 21:02 - 00004320 _____ C:\WINDOWS\System32\Tasks\SwiftSearch Auto Updater 1.10.0.27 Pending Update
- 2016-01-16 21:02 - 2016-01-16 21:02 - 00004290 _____ C:\WINDOWS\System32\Tasks\SwiftSearch Auto Updater 1.10.0.27 Core
- 2016-01-16 21:02 - 2016-01-16 21:02 - 00000000 ____D C:\Program Files (x86)\SwiftSearch_1.10.0.27
- 2016-01-16 21:01 - 2016-01-16 21:02 - 00000000 ____D C:\Users\AngryShadow\AppData\Roaming\DAEMON Tools Pro
- 2016-01-16 21:01 - 2016-01-16 21:01 - 00030264 _____ (Disc Soft Ltd) C:\WINDOWS\system32\Drivers\dtproscsibus.sys
- 2016-01-16 21:01 - 2016-01-16 21:01 - 00001858 _____ C:\Users\Public\Desktop\DAEMON Tools Pro.lnk
- 2016-01-16 21:00 - 2016-01-16 21:01 - 00000000 ____D C:\Users\AngryShadow\DAEMON Tools Pro
- 2016-01-16 20:56 - 2016-01-16 20:56 - 02940760 _____ (Disc Soft Ltd) C:\Users\AngryShadow\Downloads\DTProInstaller1.0.exe
- 2016-01-16 20:52 - 2016-01-16 20:52 - 00047672 _____ (Disc Soft Ltd) C:\WINDOWS\system32\Drivers\dtliteusbbus.sys
- 2016-01-16 20:49 - 2016-01-16 20:49 - 00689160 _____ (Disc Soft Ltd.) C:\Users\AngryShadow\Downloads\DTLiteInstaller.exe
- 2016-01-16 18:03 - 2016-01-16 18:03 - 00000000 ____D C:\Users\AngryShadow\Downloads\Fallout.4-CODEX
- 2016-01-16 18:02 - 2016-01-16 22:41 - 00000000 ____D C:\Users\AngryShadow\Downloads\Battlefield Hardline [R.G. Games]
- 2016-01-16 18:01 - 2016-01-16 18:01 - 00000000 ____D C:\Users\AngryShadow\AppData\LocalLow\uTorrent
- 2016-01-16 16:08 - 2016-01-16 16:08 - 00000000 ____D C:\Users\AngryShadow\Downloads\SFCRRPGv1.1
- 2016-01-16 16:07 - 2016-01-16 16:07 - 00281200 _____ C:\Users\AngryShadow\Downloads\SFCRRPGv1.1.zip
- 2016-01-16 16:07 - 2016-01-16 16:07 - 00000000 ____D C:\Users\AngryShadow\Desktop\SAMP
- 2016-01-16 16:06 - 2016-01-16 16:06 - 00000000 ____D C:\Users\AngryShadow\Desktop\txt docs
- 2016-01-16 16:03 - 2016-01-16 16:03 - 00633998 _____ C:\Users\AngryShadow\Downloads\Kallelse Psyk 160201.pdf
- 2016-01-16 13:39 - 2016-01-16 13:39 - 00000000 ____D C:\Users\AngryShadow\AppData\Local\Bluestacks
- 2016-01-16 13:38 - 2016-01-16 13:38 - 00000000 ___HD C:\OneDriveTemp
- 2016-01-16 13:35 - 2016-01-16 13:35 - 00000000 ____D C:\WINDOWS\AppReadiness
- 2016-01-16 13:31 - 2016-01-16 13:31 - 00000000 ____D C:\WINDOWS\LastGood.Tmp
- 2016-01-16 13:31 - 2015-12-18 07:10 - 00099472 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvaudcap64v.dll
- 2016-01-16 13:31 - 2015-12-18 07:10 - 00090768 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvaudcap32v.dll
- 2016-01-15 23:30 - 2016-01-15 23:30 - 00000000 ____D C:\Users\AngryShadow\Documents\Activision
- 2016-01-15 23:06 - 2016-01-15 23:06 - 00000000 ____D C:\Users\AngryShadow\AppData\Roaming\Macromedia
- 2016-01-15 22:02 - 2016-01-15 22:02 - 00000000 ____D C:\Users\AngryShadow\AppData\Roaming\Mozilla
- 2016-01-15 22:01 - 2016-01-15 22:01 - 00000000 ____D C:\Users\AngryShadow\AppData\Roaming\NVIDIA
- 2016-01-15 18:37 - 2016-01-15 18:37 - 00000000 ____D C:\Users\AngryShadow\Desktop\TOOLS
- 2016-01-15 18:27 - 2016-01-15 18:29 - 00000000 ____D C:\Users\AngryShadow\Desktop\HEHE
- 2016-01-15 14:33 - 2016-01-15 14:33 - 01723904 _____ (njq8) C:\Users\AngryShadow\AppData\LocalqQLUnlWnYN.exe
- 2016-01-15 14:33 - 2016-01-15 14:33 - 00353280 _____ (Microsoft Corporation) C:\Users\AngryShadow\AppData\LocalHEb_XBImVW.exe
- 2016-01-14 18:33 - 2015-12-18 17:08 - 00965440 _____ (Oracle Corporation) C:\WINDOWS\system32\Drivers\VBoxDrv.sys
- 2016-01-14 18:33 - 2015-12-18 17:08 - 00138904 _____ (Oracle Corporation) C:\WINDOWS\system32\Drivers\VBoxUSBMon.sys
- 2016-01-14 11:26 - 2016-01-14 11:26 - 00000000 ____D C:\Users\AngryShadow\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
- 2016-01-14 11:26 - 2016-01-14 11:26 - 00000000 ____D C:\Users\AngryShadow\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
- 2016-01-14 10:23 - 2016-01-14 10:23 - 00001989 _____ C:\Users\Public\Desktop\McAfee LiveSafe - Internet Security.lnk
- 2016-01-14 10:22 - 2016-01-14 10:23 - 00000000 ____D C:\Program Files\McAfee
- 2016-01-14 10:22 - 2016-01-14 10:22 - 00003138 _____ C:\WINDOWS\System32\Tasks\McAfeeLogon
- 2016-01-14 10:22 - 2016-01-14 10:22 - 00000000 ____D C:\Program Files\McAfee.com
- 2016-01-14 10:22 - 2016-01-14 10:22 - 00000000 ____D C:\Program Files (x86)\McAfee.com
- 2016-01-14 10:22 - 2015-09-23 09:43 - 00497888 _____ (McAfee, Inc.) C:\WINDOWS\system32\Drivers\mfefirek.sys
- 2016-01-14 10:22 - 2015-09-23 09:43 - 00244544 _____ (McAfee, Inc.) C:\WINDOWS\system32\Drivers\mfewfpk.sys
- 2016-01-14 10:22 - 2015-09-23 09:43 - 00082072 _____ (McAfee, Inc.) C:\WINDOWS\system32\Drivers\mfeelamk.sys
- 2016-01-14 10:22 - 2015-09-23 09:43 - 00080760 _____ (McAfee, Inc.) C:\WINDOWS\system32\Drivers\cfwids.sys
- 2016-01-14 10:20 - 2015-09-23 09:43 - 00841944 _____ (McAfee, Inc.) C:\WINDOWS\system32\Drivers\mfehidk.sys
- 2016-01-14 10:20 - 2015-09-23 09:43 - 00415976 _____ (McAfee, Inc.) C:\WINDOWS\system32\Drivers\mfeaack.sys
- 2016-01-14 10:20 - 2015-09-23 09:43 - 00351120 _____ (McAfee, Inc.) C:\WINDOWS\system32\Drivers\mfeavfk.sys
- 2016-01-14 10:20 - 2015-09-21 13:33 - 00256840 _____ (McAfee, Inc.) C:\WINDOWS\system32\mfevtps.exe
- 2016-01-14 10:16 - 2016-01-14 10:18 - 00000000 ____D C:\Users\AngryShadow\AppData\Local\tkdata
- 2016-01-14 10:14 - 2016-01-14 10:23 - 00000000 ____D C:\Program Files (x86)\McAfee
- 2016-01-14 10:14 - 2016-01-14 10:16 - 00000000 ____D C:\Program Files\TrueKey
- 2016-01-14 10:14 - 2016-01-14 10:14 - 00001179 _____ C:\Users\Public\Desktop\True Key.lnk
- 2016-01-14 10:14 - 2016-01-14 10:14 - 00000000 ____D C:\Program Files\Intel Security
- 2016-01-14 10:14 - 2016-01-14 10:14 - 00000000 ____D C:\Program Files\Intel
- 2016-01-14 10:14 - 2016-01-14 10:14 - 00000000 ____D C:\Program Files\Common Files\Intel
- 2016-01-14 10:14 - 2016-01-14 10:14 - 00000000 ____D C:\Program Files\Common Files\AV
- 2016-01-14 10:12 - 2016-01-14 10:23 - 00000000 ____D C:\Program Files\Common Files\McAfee
- 2016-01-14 10:11 - 2016-01-16 22:16 - 00000940 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
- 2016-01-14 10:11 - 2016-01-16 21:18 - 00002640 _____ C:\Users\Public\Desktop\Google Chrome.lnk
- 2016-01-14 10:11 - 2016-01-16 13:38 - 00000936 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
- 2016-01-14 10:11 - 2016-01-14 10:11 - 00003998 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
- 2016-01-14 10:11 - 2016-01-14 10:11 - 00003766 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
- 2016-01-14 10:11 - 2016-01-14 10:11 - 00000000 ____D C:\Users\AngryShadow\AppData\Local\Deployment
- 2016-01-14 10:11 - 2016-01-14 10:11 - 00000000 ____D C:\Users\AngryShadow\AppData\Local\Apps\2.0
- 2016-01-13 21:10 - 2016-01-13 21:10 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
- 2016-01-13 13:05 - 2016-01-05 03:51 - 07477600 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
- 2016-01-13 13:05 - 2016-01-05 03:51 - 01317640 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
- 2016-01-13 13:05 - 2016-01-05 03:51 - 01141496 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
- 2016-01-13 13:05 - 2016-01-05 03:50 - 01173344 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
- 2016-01-13 13:05 - 2016-01-05 03:50 - 00713568 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
- 2016-01-13 13:05 - 2016-01-05 03:50 - 00671472 _____ (Microsoft Corporation) C:\WINDOWS\system32\advapi32.dll
- 2016-01-13 13:05 - 2016-01-05 03:49 - 00513888 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
- 2016-01-13 13:05 - 2016-01-05 03:48 - 00499432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\advapi32.dll
- 2016-01-13 13:05 - 2016-01-05 03:45 - 02587696 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml6.dll
- 2016-01-13 13:05 - 2016-01-05 03:42 - 02026736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml6.dll
- 2016-01-13 13:05 - 2016-01-05 03:37 - 02544256 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
- 2016-01-13 13:05 - 2016-01-05 03:37 - 01299504 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfnetsrc.dll
- 2016-01-13 13:05 - 2016-01-05 03:37 - 00858952 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfnetcore.dll
- 2016-01-13 13:05 - 2016-01-05 03:37 - 00848160 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
- 2016-01-13 13:05 - 2016-01-05 03:37 - 00785088 _____ (Microsoft Corporation) C:\WINDOWS\system32\evr.dll
- 2016-01-13 13:05 - 2016-01-05 03:37 - 00245840 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
- 2016-01-13 13:05 - 2016-01-05 03:37 - 00234504 _____ (Microsoft Corporation) C:\WINDOWS\system32\mftranscode.dll
- 2016-01-13 13:05 - 2016-01-05 03:36 - 00808800 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe
- 2016-01-13 13:05 - 2016-01-05 03:33 - 02180128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
- 2016-01-13 13:05 - 2016-01-05 03:33 - 01118208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfnetsrc.dll
- 2016-01-13 13:05 - 2016-01-05 03:33 - 00709688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll
- 2016-01-13 13:05 - 2016-01-05 03:33 - 00701384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfnetcore.dll
- 2016-01-13 13:05 - 2016-01-05 03:33 - 00652312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\evr.dll
- 2016-01-13 13:05 - 2016-01-05 03:33 - 00208176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mftranscode.dll
- 2016-01-13 13:05 - 2016-01-05 03:33 - 00116728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfps.dll
- 2016-01-13 13:05 - 2016-01-05 03:31 - 00703840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe
- 2016-01-13 13:05 - 2016-01-05 03:27 - 01594408 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32.dll
- 2016-01-13 13:05 - 2016-01-05 03:24 - 00796352 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
- 2016-01-13 13:05 - 2016-01-05 03:23 - 01804664 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMALFXGFXDSP.dll
- 2016-01-13 13:05 - 2016-01-05 03:23 - 01309376 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
- 2016-01-13 13:05 - 2016-01-05 03:23 - 00786696 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMADMOD.DLL
- 2016-01-13 13:05 - 2016-01-05 03:23 - 00119320 _____ (Microsoft Corporation) C:\WINDOWS\system32\MP3DMOD.DLL
- 2016-01-13 13:05 - 2016-01-05 03:21 - 01371792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32.dll
- 2016-01-13 13:05 - 2016-01-05 03:17 - 00695752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMADMOD.DLL
- 2016-01-13 13:05 - 2016-01-05 03:16 - 00100160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MP3DMOD.DLL
- 2016-01-13 13:05 - 2016-01-05 02:59 - 22393856 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
- 2016-01-13 13:05 - 2016-01-05 02:57 - 16986112 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
- 2016-01-13 13:05 - 2016-01-05 02:57 - 00076288 _____ (Microsoft Corporation) C:\WINDOWS\system32\RMSRoamingSecurity.dll
- 2016-01-13 13:05 - 2016-01-05 02:57 - 00043520 _____ (Microsoft Corporation) C:\WINDOWS\system32\usermgrcli.dll
- 2016-01-13 13:05 - 2016-01-05 02:56 - 00145920 _____ (Microsoft Corporation) C:\WINDOWS\system32\omadmclient.exe
- 2016-01-13 13:05 - 2016-01-05 02:54 - 00245760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BthLEEnum.sys
- 2016-01-13 13:05 - 2016-01-05 02:54 - 00162816 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCensus.exe
- 2016-01-13 13:05 - 2016-01-05 02:53 - 00148992 _____ (Microsoft Corporation) C:\WINDOWS\system32\wshom.ocx
- 2016-01-13 13:05 - 2016-01-05 02:52 - 00210432 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll
- 2016-01-13 13:05 - 2016-01-05 02:51 - 00472576 _____ (Microsoft Corporation) C:\WINDOWS\system32\DscCore.dll
- 2016-01-13 13:05 - 2016-01-05 02:51 - 00248832 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserMgrProxy.dll
- 2016-01-13 13:05 - 2016-01-05 02:50 - 00644096 _____ (Microsoft Corporation) C:\WINDOWS\system32\uReFS.dll
- 2016-01-13 13:05 - 2016-01-05 02:50 - 00638464 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
- 2016-01-13 13:05 - 2016-01-05 02:50 - 00208896 _____ (Microsoft Corporation) C:\WINDOWS\system32\storewuauth.dll
- 2016-01-13 13:05 - 2016-01-05 02:49 - 13018624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
- 2016-01-13 13:05 - 2016-01-05 02:49 - 01582080 _____ (Microsoft Corporation) C:\WINDOWS\system32\aitstatic.exe
- 2016-01-13 13:05 - 2016-01-05 02:49 - 01255936 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMSPDMOE.DLL
- 2016-01-13 13:05 - 2016-01-05 02:49 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
- 2016-01-13 13:05 - 2016-01-05 02:49 - 00749056 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneService.dll
- 2016-01-13 13:05 - 2016-01-05 02:49 - 00167936 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProximityCommon.dll
- 2016-01-13 13:05 - 2016-01-05 02:48 - 01009152 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMSPDMOD.DLL
- 2016-01-13 13:05 - 2016-01-05 02:48 - 00387072 _____ (Microsoft Corporation) C:\WINDOWS\system32\qdvd.dll
- 2016-01-13 13:05 - 2016-01-05 02:48 - 00034816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\usermgrcli.dll
- 2016-01-13 13:05 - 2016-01-05 02:47 - 00628736 _____ (Microsoft Corporation) C:\WINDOWS\system32\MessagingDataModel2.dll
- 2016-01-13 13:05 - 2016-01-05 02:47 - 00479232 _____ (Microsoft Corporation) C:\WINDOWS\system32\schannel.dll
- 2016-01-13 13:05 - 2016-01-05 02:47 - 00305664 _____ (Microsoft Corporation) C:\WINDOWS\system32\ksproxy.ax
- 2016-01-13 13:05 - 2016-01-05 02:45 - 00678912 _____ (Microsoft Corporation) C:\WINDOWS\system32\qedit.dll
- 2016-01-13 13:05 - 2016-01-05 02:45 - 00275968 _____ (Microsoft Corporation) C:\WINDOWS\system32\facecredentialprovider.dll
- 2016-01-13 13:05 - 2016-01-05 02:44 - 00125440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wshom.ocx
- 2016-01-13 13:05 - 2016-01-05 02:43 - 00953856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bthport.sys
- 2016-01-13 13:05 - 2016-01-05 02:43 - 00912384 _____ (Microsoft Corporation) C:\WINDOWS\system32\usermgr.dll
- 2016-01-13 13:05 - 2016-01-05 02:43 - 00604672 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
- 2016-01-13 13:05 - 2016-01-05 02:43 - 00584704 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
- 2016-01-13 13:05 - 2016-01-05 02:42 - 00166912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserMgrProxy.dll
- 2016-01-13 13:05 - 2016-01-05 02:41 - 18677760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
- 2016-01-13 13:05 - 2016-01-05 02:41 - 01070080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMSPDMOE.DLL
- 2016-01-13 13:05 - 2016-01-05 02:41 - 00558592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\uReFS.dll
- 2016-01-13 13:05 - 2016-01-05 02:40 - 00890880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMSPDMOD.DLL
- 2016-01-13 13:05 - 2016-01-05 02:40 - 00123392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ProximityCommon.dll
- 2016-01-13 13:05 - 2016-01-05 02:39 - 03428864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
- 2016-01-13 13:05 - 2016-01-05 02:39 - 00569856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\qdvd.dll
- 2016-01-13 13:05 - 2016-01-05 02:39 - 00498176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MessagingDataModel2.dll
- 2016-01-13 13:05 - 2016-01-05 02:39 - 00235008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ksproxy.ax
- 2016-01-13 13:05 - 2016-01-05 02:38 - 00389120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\schannel.dll
- 2016-01-13 13:05 - 2016-01-05 02:36 - 00573440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\qedit.dll
- 2016-01-13 13:05 - 2016-01-05 02:36 - 00503296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
- 2016-01-13 13:05 - 2016-01-05 02:33 - 01674240 _____ (Microsoft Corporation) C:\WINDOWS\system32\quartz.dll
- 2016-01-13 13:05 - 2016-01-05 02:30 - 02796032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
- 2016-01-13 13:05 - 2016-01-05 02:30 - 02280448 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
- 2016-01-13 13:05 - 2016-01-05 02:29 - 03667456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
- 2016-01-13 13:05 - 2016-01-05 02:28 - 07826432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
- 2016-01-13 13:05 - 2016-01-05 02:28 - 04894720 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
- 2016-01-13 13:05 - 2016-01-05 02:28 - 01542656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\quartz.dll
- 2016-01-13 13:05 - 2016-01-05 02:25 - 05660160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
- 2016-01-13 13:02 - 2016-01-16 13:45 - 00000000 ____D C:\Users\AngryShadow\AppData\Local\dxhr
- 2016-01-13 13:02 - 2016-01-13 13:02 - 00000000 ____D C:\Users\AngryShadow\AppData\Local\238010
- 2016-01-13 13:00 - 2016-01-13 13:37 - 00000000 ____D C:\WINDOWS\CbsTemp
- 2016-01-13 12:54 - 2016-01-13 12:54 - 00000000 ____D C:\Users\AngryShadow\Documents\SavedGames
- 2016-01-13 12:54 - 2016-01-13 12:54 - 00000000 ____D C:\Program Files (x86)\Microsoft XNA
- 2016-01-12 14:17 - 2016-01-15 14:39 - 00000000 ____D C:\AdwCleaner
- 2016-01-11 22:41 - 2016-01-11 22:41 - 00000000 ____D C:\Users\AngryShadow\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Fraps
- 2016-01-10 09:29 - 2016-01-16 21:18 - 00001236 _____ C:\Users\AngryShadow\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Start Tor Browser.lnk
- 2016-01-10 09:29 - 2016-01-16 21:18 - 00001188 _____ C:\Users\AngryShadow\Desktop\Start Tor Browser.lnk
- 2016-01-10 09:29 - 2016-01-10 09:29 - 00000000 ____D C:\Users\AngryShadow\Desktop\Tor Browser
- 2016-01-10 09:00 - 2016-01-10 09:00 - 00001902 _____ C:\csgo.amx
- 2016-01-10 08:20 - 2016-01-10 08:20 - 00001921 _____ C:\Test.amx
- 2016-01-09 13:54 - 2016-01-14 10:22 - 00000000 ____D C:\WINDOWS\System32\Tasks\McAfee
- 2016-01-06 22:28 - 2016-01-06 22:58 - 05929984 ___SH (Microsoft Corp.) C:\Users\AngryShadow\AppData\Roaming\Gambino.exe
- 2016-01-06 22:21 - 2016-01-08 13:14 - 00000000 ____D C:\Users\AngryShadow\AppData\Local\Image Rush
- 2016-01-06 22:03 - 2016-01-16 18:46 - 00004176 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{1295A2DC-2BA2-4259-954A-9532CB94BC86}
- 2016-01-06 22:00 - 2016-01-06 21:59 - 00000967 _____ C:\WINDOWS\system32\Drivers\etc\hp.bak
- 2016-01-06 21:59 - 2016-01-06 22:03 - 00000000 ____D C:\Users\AngryShadow\AppData\Local\Opera Software
- 2016-01-06 19:32 - 2016-01-06 19:32 - 00000000 ____D C:\Users\AngryShadow\AppData\Roaming\Gyazo
- 2016-01-06 19:31 - 2016-01-06 23:00 - 00000000 ____D C:\Program Files (x86)\Gyazo
- 2016-01-06 19:31 - 2016-01-06 19:31 - 00003568 _____ C:\WINDOWS\System32\Tasks\GyazoUpdateTaskMachineDaily
- 2016-01-06 19:31 - 2016-01-06 19:31 - 00003432 _____ C:\WINDOWS\System32\Tasks\GyazoUpdateTaskMachine
- 2016-01-06 19:31 - 2016-01-06 19:31 - 00001051 _____ C:\Users\Public\Desktop\Gyazo.lnk
- 2016-01-06 19:31 - 2016-01-06 19:31 - 00001051 _____ C:\Users\Public\Desktop\Gyazo GIF.lnk
- 2016-01-06 18:21 - 2016-01-06 18:21 - 00001047 _____ C:\Users\AngryShadow\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Optional Features.lnk
- 2016-01-06 16:40 - 2016-01-06 16:40 - 00000000 ____D C:\Users\AngryShadow\AppData\LocalLow\Temp
- 2016-01-06 13:09 - 2016-01-06 13:09 - 00000000 ____D C:\Users\AngryShadow\Documents\My Games
- 2016-01-05 20:46 - 2016-01-05 20:46 - 00000000 ___RD C:\Users\AngryShadow\3D Objects
- 2016-01-03 20:05 - 2016-01-03 20:05 - 00000000 ____D C:\Users\AngryShadow\AppData\Local\OTLand
- 2016-01-02 19:43 - 2016-01-02 19:43 - 00000000 ____D C:\Users\AngryShadow\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Portforward.com
- 2016-01-02 15:53 - 2016-01-13 15:04 - 00000000 ____D C:\Users\AngryShadow\Documents\GTA San Andreas User Files
- 2016-01-02 15:53 - 2016-01-02 15:53 - 00000000 ____D C:\Users\AngryShadow\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\San Andreas Multiplayer
- 2016-01-02 15:49 - 2016-01-02 15:49 - 00001926 _____ C:\Users\Public\Desktop\GTA San Andreas.lnk
- 2016-01-02 15:49 - 2016-01-02 15:49 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
- 2016-01-02 15:49 - 2016-01-02 15:49 - 00000000 ____D C:\Program Files (x86)\Rockstar Games
- 2016-01-02 14:59 - 2016-01-02 14:59 - 00000000 ____D C:\Users\AngryShadow\AppData\Local\Disc_Soft_Ltd
- 2016-01-02 14:57 - 2016-01-02 15:49 - 00000000 ____D C:\Users\AngryShadow\AppData\Roaming\DAEMON Tools Lite
- 2016-01-02 14:47 - 2016-01-16 13:34 - 00002672 _____ C:\Users\AngryShadow\Desktop\µTorrent.lnk
- 2016-01-02 14:46 - 2016-01-16 23:11 - 00000000 ____D C:\Users\AngryShadow\AppData\Roaming\uTorrent
- 2015-12-31 19:44 - 2015-12-31 19:44 - 00000000 ____D C:\Users\AngryShadow\Documents\Criterion Games
- 2015-12-30 23:48 - 2015-12-30 23:48 - 00000000 ____D C:\Users\AngryShadow\Documents\4A Games
- 2015-12-30 19:46 - 2015-12-30 19:46 - 00000000 ____D C:\Users\AngryShadow\AppData\Roaming\WinRAR
- 2015-12-30 19:46 - 2015-12-30 19:46 - 00000000 ____D C:\Users\AngryShadow\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
- 2015-12-30 19:45 - 2015-12-30 19:46 - 00000000 ____D C:\Program Files\WinRAR
- 2015-12-30 02:01 - 2010-06-02 04:55 - 00527192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_7.dll
- 2015-12-30 02:01 - 2010-06-02 04:55 - 00518488 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_7.dll
- 2015-12-30 02:01 - 2010-06-02 04:55 - 00239960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_7.dll
- 2015-12-30 02:01 - 2010-06-02 04:55 - 00176984 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_7.dll
- 2015-12-30 02:01 - 2010-06-02 04:55 - 00077656 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_5.dll
- 2015-12-30 02:01 - 2010-06-02 04:55 - 00074072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_5.dll
- 2015-12-30 02:01 - 2010-05-26 11:41 - 02526056 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_43.dll
- 2015-12-30 02:01 - 2010-05-26 11:41 - 02106216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_43.dll
- 2015-12-30 02:01 - 2010-05-26 11:41 - 01907552 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dcsx_43.dll
- 2015-12-30 02:01 - 2010-05-26 11:41 - 01868128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dcsx_43.dll
- 2015-12-30 02:01 - 2010-02-04 10:01 - 00530776 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_6.dll
- 2015-12-30 02:01 - 2010-02-04 10:01 - 00528216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_6.dll
- 2015-12-30 02:01 - 2010-02-04 10:01 - 00238936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_6.dll
- 2015-12-30 02:01 - 2010-02-04 10:01 - 00176984 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_6.dll
- 2015-12-30 02:01 - 2010-02-04 10:01 - 00078680 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_4.dll
- 2015-12-30 02:01 - 2010-02-04 10:01 - 00074072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_4.dll
- 2015-12-30 02:01 - 2010-02-04 10:01 - 00024920 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_7.dll
- 2015-12-30 02:01 - 2010-02-04 10:01 - 00022360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\X3DAudio1_7.dll
- 2015-12-30 02:01 - 2009-09-04 17:44 - 00517960 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_5.dll
- 2015-12-30 02:01 - 2009-09-04 17:44 - 00515416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_5.dll
- 2015-12-30 02:01 - 2009-09-04 17:44 - 00238936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_5.dll
- 2015-12-30 02:01 - 2009-09-04 17:44 - 00176968 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_5.dll
- 2015-12-30 02:01 - 2009-09-04 17:44 - 00073544 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_3.dll
- 2015-12-30 02:01 - 2009-09-04 17:44 - 00069464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_3.dll
- 2015-12-30 02:01 - 2009-09-04 17:29 - 05554512 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dcsx_42.dll
- 2015-12-30 02:01 - 2009-09-04 17:29 - 05501792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dcsx_42.dll
- 2015-12-30 02:01 - 2009-09-04 17:29 - 02582888 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_42.dll
- 2015-12-30 02:01 - 2009-09-04 17:29 - 02475352 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_42.dll
- 2015-12-30 02:01 - 2009-09-04 17:29 - 01974616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_42.dll
- 2015-12-30 02:01 - 2009-09-04 17:29 - 01892184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_42.dll
- 2015-12-30 02:01 - 2009-09-04 17:29 - 00523088 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_42.dll
- 2015-12-30 02:01 - 2009-09-04 17:29 - 00453456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_42.dll
- 2015-12-30 02:01 - 2009-09-04 17:29 - 00285024 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx11_42.dll
- 2015-12-30 02:01 - 2009-09-04 17:29 - 00235344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx11_42.dll
- 2015-12-30 02:01 - 2009-03-16 14:18 - 00521560 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_4.dll
- 2015-12-30 02:01 - 2009-03-16 14:18 - 00517448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_4.dll
- 2015-12-30 02:01 - 2009-03-16 14:18 - 00235352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_4.dll
- 2015-12-30 02:01 - 2009-03-16 14:18 - 00174936 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_4.dll
- 2015-12-30 02:01 - 2009-03-16 14:18 - 00024920 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_6.dll
- 2015-12-30 02:01 - 2009-03-16 14:18 - 00022360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\X3DAudio1_6.dll
- 2015-12-30 02:01 - 2009-03-09 15:27 - 05425496 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_41.dll
- 2015-12-30 02:01 - 2009-03-09 15:27 - 04178264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_41.dll
- 2015-12-30 02:01 - 2009-03-09 15:27 - 02430312 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_41.dll
- 2015-12-30 02:01 - 2009-03-09 15:27 - 01846632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_41.dll
- 2015-12-30 02:01 - 2009-03-09 15:27 - 00520544 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_41.dll
- 2015-12-30 02:01 - 2009-03-09 15:27 - 00453456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_41.dll
- 2015-12-30 02:01 - 2008-10-27 10:04 - 00518480 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_3.dll
- 2015-12-30 02:01 - 2008-10-27 10:04 - 00514384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_3.dll
- 2015-12-30 02:01 - 2008-10-27 10:04 - 00235856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_3.dll
- 2015-12-30 02:01 - 2008-10-27 10:04 - 00175440 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_3.dll
- 2015-12-30 02:01 - 2008-10-27 10:04 - 00074576 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_2.dll
- 2015-12-30 02:01 - 2008-10-27 10:04 - 00070992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_2.dll
- 2015-12-30 02:01 - 2008-10-27 10:04 - 00025936 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_5.dll
- 2015-12-30 02:01 - 2008-10-27 10:04 - 00023376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\X3DAudio1_5.dll
- 2015-12-30 02:01 - 2008-10-15 06:22 - 05631312 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_40.dll
- 2015-12-30 02:01 - 2008-10-15 06:22 - 04379984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_40.dll
- 2015-12-30 02:01 - 2008-10-15 06:22 - 02605920 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_40.dll
- 2015-12-30 02:01 - 2008-10-15 06:22 - 02036576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_40.dll
- 2015-12-30 02:01 - 2008-10-15 06:22 - 00519000 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_40.dll
- 2015-12-30 02:01 - 2008-10-15 06:22 - 00452440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_40.dll
- 2015-12-30 02:01 - 2008-07-31 10:41 - 00238088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_2.dll
- 2015-12-30 02:01 - 2008-07-31 10:41 - 00177672 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_2.dll
- 2015-12-30 02:01 - 2008-07-31 10:41 - 00072200 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_1.dll
- 2015-12-30 02:01 - 2008-07-31 10:40 - 00513544 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_2.dll
- 2015-12-30 02:01 - 2008-07-10 11:00 - 04992520 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_39.dll
- 2015-12-30 02:01 - 2008-07-10 11:00 - 01942552 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_39.dll
- 2015-12-30 02:01 - 2008-07-10 11:00 - 00540688 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_39.dll
- 2015-12-30 02:01 - 2008-05-30 14:19 - 00511496 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_1.dll
- 2015-12-30 02:01 - 2008-05-30 14:19 - 00507400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_1.dll
- 2015-12-30 02:01 - 2008-05-30 14:18 - 00238088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_1.dll
- 2015-12-30 02:01 - 2008-05-30 14:18 - 00177672 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_1.dll
- 2015-12-30 02:01 - 2008-05-30 14:17 - 00068104 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAPOFX1_0.dll
- 2015-12-30 02:01 - 2008-05-30 14:17 - 00065032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_0.dll
- 2015-12-30 02:01 - 2008-05-30 14:17 - 00025608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\X3DAudio1_4.dll
- 2015-12-30 02:01 - 2008-05-30 14:16 - 00028168 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_4.dll
- 2015-12-30 02:01 - 2008-05-30 14:11 - 04991496 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_38.dll
- 2015-12-30 02:01 - 2008-05-30 14:11 - 03850760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_38.dll
- 2015-12-30 02:01 - 2008-05-30 14:11 - 01941528 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_38.dll
- 2015-12-30 02:01 - 2008-05-30 14:11 - 01491992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_38.dll
- 2015-12-30 02:01 - 2008-05-30 14:11 - 00540688 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_38.dll
- 2015-12-30 02:01 - 2008-05-30 14:11 - 00467984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_38.dll
- 2015-12-30 02:01 - 2008-03-05 16:04 - 00489480 _____ (Microsoft Corporation) C:\WINDOWS\system32\XAudio2_0.dll
- 2015-12-30 02:01 - 2008-03-05 16:03 - 00479752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_0.dll
- 2015-12-30 02:01 - 2008-03-05 16:03 - 00238088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine3_0.dll
- 2015-12-30 02:01 - 2008-03-05 16:03 - 00177672 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine3_0.dll
- 2015-12-30 02:01 - 2008-03-05 16:00 - 00028168 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_3.dll
- 2015-12-30 02:01 - 2008-03-05 16:00 - 00025608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\X3DAudio1_3.dll
- 2015-12-30 02:01 - 2008-03-05 15:56 - 04910088 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_37.dll
- 2015-12-30 02:01 - 2008-03-05 15:56 - 03786760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_37.dll
- 2015-12-30 02:01 - 2008-03-05 15:56 - 01860120 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_37.dll
- 2015-12-30 02:01 - 2008-03-05 15:56 - 01420824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_37.dll
- 2015-12-30 02:01 - 2008-02-05 23:07 - 00529424 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_37.dll
- 2015-12-30 02:01 - 2008-02-05 23:07 - 00462864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_37.dll
- 2015-12-30 02:01 - 2007-10-22 03:40 - 00411656 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_10.dll
- 2015-12-30 02:01 - 2007-10-22 03:39 - 00267272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_10.dll
- 2015-12-30 02:01 - 2007-10-22 03:37 - 00021000 _____ (Microsoft Corporation) C:\WINDOWS\system32\X3DAudio1_2.dll
- 2015-12-30 02:01 - 2007-10-22 03:37 - 00017928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\X3DAudio1_2.dll
- 2015-12-30 02:01 - 2007-10-12 15:14 - 05081608 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_36.dll
- 2015-12-30 02:01 - 2007-10-12 15:14 - 03734536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_36.dll
- 2015-12-30 02:01 - 2007-10-12 15:14 - 02006552 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_36.dll
- 2015-12-30 02:01 - 2007-10-12 15:14 - 01374232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_36.dll
- 2015-12-30 02:01 - 2007-10-02 09:56 - 00508264 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_36.dll
- 2015-12-30 02:01 - 2007-10-02 09:56 - 00444776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_36.dll
- 2015-12-30 02:01 - 2007-07-20 00:57 - 00411496 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_9.dll
- 2015-12-30 02:01 - 2007-07-20 00:57 - 00267112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_9.dll
- 2015-12-30 02:01 - 2007-07-19 18:14 - 05073256 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_35.dll
- 2015-12-30 02:01 - 2007-07-19 18:14 - 03727720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_35.dll
- 2015-12-30 02:01 - 2007-07-19 18:14 - 01985904 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_35.dll
- 2015-12-30 02:01 - 2007-07-19 18:14 - 01358192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_35.dll
- 2015-12-30 02:01 - 2007-07-19 18:14 - 00508264 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_35.dll
- 2015-12-30 02:01 - 2007-07-19 18:14 - 00444776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_35.dll
- 2015-12-30 02:01 - 2007-06-20 20:49 - 00409960 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_8.dll
- 2015-12-30 02:01 - 2007-06-20 20:46 - 00266088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_8.dll
- 2015-12-30 02:01 - 2007-05-16 16:45 - 04496232 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_34.dll
- 2015-12-30 02:01 - 2007-05-16 16:45 - 03497832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_34.dll
- 2015-12-30 02:01 - 2007-05-16 16:45 - 01401200 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_34.dll
- 2015-12-30 02:01 - 2007-05-16 16:45 - 01124720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_34.dll
- 2015-12-30 02:01 - 2007-05-16 16:45 - 00506728 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_34.dll
- 2015-12-30 02:01 - 2007-05-16 16:45 - 00443752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_34.dll
- 2015-12-30 02:01 - 2007-04-04 18:55 - 00403304 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_7.dll
- 2015-12-30 02:01 - 2007-04-04 18:55 - 00261480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_7.dll
- 2015-12-30 02:01 - 2007-04-04 18:54 - 00107368 _____ (Microsoft Corporation) C:\WINDOWS\system32\xinput1_3.dll
- 2015-12-30 02:01 - 2007-04-04 18:53 - 00081768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xinput1_3.dll
- 2015-12-30 02:01 - 2007-03-15 16:57 - 00506728 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_33.dll
- 2015-12-30 02:01 - 2007-03-15 16:57 - 00443752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_33.dll
- 2015-12-30 02:01 - 2007-03-12 16:42 - 04494184 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_33.dll
- 2015-12-30 02:01 - 2007-03-12 16:42 - 03495784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_33.dll
- 2015-12-30 02:01 - 2007-03-12 16:42 - 01400176 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_33.dll
- 2015-12-30 02:01 - 2007-03-12 16:42 - 01123696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_33.dll
- 2015-12-30 02:01 - 2007-03-05 12:42 - 00017688 _____ (Microsoft Corporation) C:\WINDOWS\system32\x3daudio1_1.dll
- 2015-12-30 02:01 - 2007-03-05 12:42 - 00015128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\x3daudio1_1.dll
- 2015-12-30 02:01 - 2007-01-24 15:27 - 00393576 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_6.dll
- 2015-12-30 02:01 - 2007-01-24 15:27 - 00255848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_6.dll
- 2015-12-30 02:01 - 2006-12-08 12:02 - 00251672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_5.dll
- 2015-12-30 02:01 - 2006-12-08 12:00 - 00390424 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_5.dll
- 2015-12-30 02:01 - 2006-11-29 13:06 - 04398360 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_32.dll
- 2015-12-30 02:01 - 2006-11-29 13:06 - 03426072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_32.dll
- 2015-12-30 02:01 - 2006-11-29 13:06 - 00469264 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10.dll
- 2015-12-30 02:01 - 2006-11-29 13:06 - 00440080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10.dll
- 2015-12-30 02:01 - 2006-09-28 16:05 - 03977496 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_31.dll
- 2015-12-30 02:01 - 2006-09-28 16:05 - 02414360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_31.dll
- 2015-12-30 02:01 - 2006-09-28 16:05 - 00237848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_4.dll
- 2015-12-30 02:01 - 2006-09-28 16:04 - 00364824 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_4.dll
- 2015-12-30 02:01 - 2006-07-28 09:31 - 00083736 _____ (Microsoft Corporation) C:\WINDOWS\system32\xinput1_2.dll
- 2015-12-30 02:01 - 2006-07-28 09:30 - 00363288 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_3.dll
- 2015-12-30 02:01 - 2006-07-28 09:30 - 00236824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_3.dll
- 2015-12-30 02:01 - 2006-07-28 09:30 - 00062744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xinput1_2.dll
- 2015-12-30 02:01 - 2006-05-31 07:24 - 00230168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_2.dll
- 2015-12-30 02:01 - 2006-05-31 07:22 - 00354072 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_2.dll
- 2015-12-30 02:01 - 2006-03-31 12:41 - 03927248 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_30.dll
- 2015-12-30 02:01 - 2006-03-31 12:40 - 02388176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_30.dll
- 2015-12-30 02:01 - 2006-03-31 12:40 - 00352464 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_1.dll
- 2015-12-30 02:01 - 2006-03-31 12:39 - 00229584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_1.dll
- 2015-12-30 02:01 - 2006-03-31 12:39 - 00083664 _____ (Microsoft Corporation) C:\WINDOWS\system32\xinput1_1.dll
- 2015-12-30 02:01 - 2006-03-31 12:39 - 00062672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xinput1_1.dll
- 2015-12-30 02:01 - 2006-02-03 08:43 - 03830992 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_29.dll
- 2015-12-30 02:01 - 2006-02-03 08:43 - 02332368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_29.dll
- 2015-12-30 02:01 - 2006-02-03 08:42 - 00355536 _____ (Microsoft Corporation) C:\WINDOWS\system32\xactengine2_0.dll
- 2015-12-30 02:01 - 2006-02-03 08:42 - 00230096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xactengine2_0.dll
- 2015-12-30 02:01 - 2006-02-03 08:41 - 00016592 _____ (Microsoft Corporation) C:\WINDOWS\system32\x3daudio1_0.dll
- 2015-12-30 02:01 - 2006-02-03 08:41 - 00014032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\x3daudio1_0.dll
- 2015-12-30 02:01 - 2005-12-05 18:09 - 03815120 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_28.dll
- 2015-12-30 02:01 - 2005-12-05 18:09 - 02323664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_28.dll
- 2015-12-30 02:01 - 2005-07-22 19:59 - 03807440 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_27.dll
- 2015-12-30 02:01 - 2005-07-22 19:59 - 02319568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_27.dll
- 2015-12-30 02:01 - 2005-05-26 15:34 - 03767504 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_26.dll
- 2015-12-30 02:01 - 2005-05-26 15:34 - 02297552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_26.dll
- 2015-12-30 02:01 - 2005-03-18 17:19 - 03823312 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_25.dll
- 2015-12-30 02:01 - 2005-02-05 19:45 - 03544272 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx9_24.dll
- 2015-12-30 02:01 - 2005-02-05 19:45 - 02222800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx9_24.dll
- 2015-12-30 01:16 - 2015-12-30 01:17 - 00400639 _____ C:\Users\AngryShadow\Desktop\RAT_Logs.rar
- 2015-12-30 00:58 - 2015-12-30 00:58 - 00000000 ____D C:\Users\AngryShadow\AppData\Roaming\TeamViewer
- 2015-12-30 00:44 - 2016-01-06 18:25 - 00000000 ____D C:\Program Files (x86)\TeamViewer
- 2015-12-30 00:44 - 2015-12-30 00:44 - 00001100 _____ C:\Users\Public\Desktop\TeamViewer 11.lnk
- 2015-12-30 00:39 - 2015-12-30 00:39 - 00000889 _____ C:\Users\Public\Desktop\World of Warcraft.lnk
- 2015-12-29 23:59 - 2015-12-29 23:59 - 00002206 _____ C:\Users\Public\Desktop\3D Vision Photo Viewer.lnk
- 2015-12-29 23:59 - 2015-12-16 15:54 - 00523384 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshext.dll
- 2015-12-29 23:59 - 2015-12-16 15:54 - 00075056 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshextr.dll
- 2015-12-29 23:59 - 2015-12-16 15:19 - 00103216 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvStreaming.exe
- 2015-12-29 23:58 - 2015-12-16 17:59 - 42976888 _____ C:\WINDOWS\system32\nvcompiler.dll
- 2015-12-29 23:58 - 2015-12-16 17:59 - 37608568 _____ C:\WINDOWS\SysWOW64\nvcompiler.dll
- 2015-12-29 23:58 - 2015-12-16 17:59 - 31098488 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglv64.dll
- 2015-12-29 23:58 - 2015-12-16 17:59 - 24923768 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglv32.dll
- 2015-12-29 23:58 - 2015-12-16 17:59 - 21131424 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvopencl.dll
- 2015-12-29 23:58 - 2015-12-16 17:59 - 20672376 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll
- 2015-12-29 23:58 - 2015-12-16 17:59 - 17568432 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvopencl.dll
- 2015-12-29 23:58 - 2015-12-16 17:59 - 17164160 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll
- 2015-12-29 23:58 - 2015-12-16 17:59 - 17104016 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvd3dumx.dll
- 2015-12-29 23:58 - 2015-12-16 17:59 - 02560816 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll
- 2015-12-29 23:58 - 2015-12-16 17:59 - 02214192 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll
- 2015-12-29 23:58 - 2015-12-16 17:59 - 01915512 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6436143.dll
- 2015-12-29 23:58 - 2015-12-16 17:59 - 01564976 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6436143.dll
- 2015-12-29 23:58 - 2015-12-16 17:59 - 00938104 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll
- 2015-12-29 23:58 - 2015-12-16 17:59 - 00872056 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll
- 2015-12-29 23:58 - 2015-12-16 17:59 - 00786688 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncMFTH264.dll
- 2015-12-29 23:58 - 2015-12-16 17:59 - 00735024 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll
- 2015-12-29 23:58 - 2015-12-16 17:59 - 00681592 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll
- 2015-12-29 23:58 - 2015-12-16 17:59 - 00632336 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncMFTH264.dll
- 2015-12-29 23:58 - 2015-12-16 17:59 - 00541000 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvumdshimx.dll
- 2015-12-29 23:58 - 2015-12-16 17:59 - 00445728 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvumdshim.dll
- 2015-12-29 23:58 - 2015-12-16 17:59 - 00416560 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFROpenGL.dll
- 2015-12-29 23:58 - 2015-12-16 17:59 - 00378784 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll
- 2015-12-29 23:58 - 2015-12-16 17:59 - 00376440 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvDecMFTMjpeg.dll
- 2015-12-29 23:58 - 2015-12-16 17:59 - 00370992 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFROpenGL.dll
- 2015-12-29 23:58 - 2015-12-16 17:59 - 00339760 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvDecMFTMjpeg.dll
- 2015-12-29 23:58 - 2015-12-16 17:59 - 00316960 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll
- 2015-12-29 23:58 - 2015-12-16 17:59 - 00206968 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.dll
- 2015-12-29 23:58 - 2015-12-16 17:59 - 00194680 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.dll
- 2015-12-29 23:58 - 2015-12-16 17:59 - 00175368 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvinitx.dll
- 2015-12-29 23:58 - 2015-12-16 17:59 - 00153208 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvinit.dll
- 2015-12-29 23:58 - 2015-12-16 17:59 - 00151184 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglshim64.dll
- 2015-12-29 23:58 - 2015-12-16 17:59 - 00128696 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglshim32.dll
- 2015-12-29 23:58 - 2015-12-16 17:59 - 00039240 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvhdap64.dll
- 2015-12-28 17:56 - 2015-12-28 17:56 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
- 2015-12-28 15:57 - 2016-01-14 18:18 - 00000000 ____D C:\Users\AngryShadow\AppData\Local\CrashDumps
- 2015-12-28 15:30 - 2015-12-28 15:30 - 00000000 ____D C:\Users\AngryShadow\AppData\Roaming\LolClient
- 2015-12-28 13:39 - 2016-01-16 21:18 - 00001655 _____ C:\Users\Public\Desktop\League of Legends.lnk
- 2015-12-28 13:39 - 2008-07-31 10:41 - 00068616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAPOFX1_1.dll
- 2015-12-28 13:39 - 2008-07-31 10:40 - 00509448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XAudio2_2.dll
- 2015-12-28 13:39 - 2008-07-12 08:18 - 03851784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_39.dll
- 2015-12-28 13:39 - 2008-07-12 08:18 - 01493528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_39.dll
- 2015-12-28 13:39 - 2008-07-12 08:18 - 00467984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_39.dll
- 2015-12-28 13:38 - 2015-12-28 13:39 - 00000000 ____D C:\Users\AngryShadow\AppData\Roaming\Riot Games
- 2015-12-28 00:27 - 2016-01-16 13:38 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
- 2015-12-28 00:26 - 2015-12-29 23:59 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
- 2015-12-28 00:26 - 2015-12-28 00:26 - 00319059 _____ C:\WINDOWS\system32\Drivers\RTWAVES40.dat
- 2015-12-28 00:26 - 2015-12-28 00:26 - 00006786 _____ C:\WINDOWS\system32\Drivers\rtwavesEFX.dat
- 2015-12-28 00:26 - 2015-12-28 00:26 - 00002626 _____ C:\WINDOWS\system32\Drivers\rtwavesMFX.dat
- 2015-12-28 00:26 - 2015-12-28 00:26 - 00000000 ____D C:\WINDOWS\SysWOW64\RTCOM
- 2015-12-28 00:26 - 2015-12-28 00:26 - 00000000 ____D C:\Program Files\Realtek
- 2015-12-28 00:26 - 2015-12-27 16:46 - 00000000 ____D C:\Program Files\NVIDIA Corporation
- 2015-12-28 00:26 - 2015-12-16 15:54 - 06359672 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
- 2015-12-28 00:26 - 2015-12-16 15:54 - 02985264 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc64.dll
- 2015-12-28 00:26 - 2015-12-16 15:54 - 02554488 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll
- 2015-12-28 00:26 - 2015-12-16 15:54 - 01256240 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvvsvc.exe
- 2015-12-28 00:26 - 2015-12-16 15:54 - 00385328 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmctray.dll
- 2015-12-28 00:26 - 2015-12-16 15:54 - 00062768 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll
- 2015-12-28 00:26 - 2015-12-16 15:49 - 06090019 _____ C:\WINDOWS\system32\nvcoproc.bin
- 2015-12-28 00:25 - 2015-12-30 13:43 - 00257792 _____ C:\WINDOWS\system32\FNTCACHE.DAT
- 2015-12-28 00:25 - 2015-12-28 00:25 - 00000000 ____D C:\WINDOWS\ServiceProfiles
- 2015-12-28 00:25 - 2015-12-28 00:25 - 00000000 ____D C:\Program Files\Common Files\logishrd
- 2015-12-27 19:46 - 2015-12-27 19:46 - 00000000 ____D C:\Users\AngryShadow\AppData\Roaming\java
- 2015-12-27 17:32 - 2016-01-15 15:35 - 143671360 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
- 2015-12-27 17:32 - 2016-01-15 15:35 - 00000000 ____D C:\WINDOWS\system32\MRT
- 2015-12-27 17:31 - 2015-12-09 04:39 - 00301728 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
- 2015-12-27 16:47 - 2015-12-27 16:47 - 00000000 ____D C:\Users\AngryShadow\AppData\Local\NVIDIA Corporation
- 2015-12-27 16:46 - 2016-01-16 13:31 - 00001450 _____ C:\Users\Public\Desktop\GeForce Experience.lnk
- 2015-12-27 16:46 - 2016-01-09 08:22 - 01567504 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspcap.dll
- 2015-12-27 16:46 - 2016-01-09 08:22 - 01316184 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspbridge.dll
- 2015-12-27 16:46 - 2016-01-09 08:21 - 01902136 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspcap64.dll
- 2015-12-27 16:46 - 2016-01-09 08:21 - 01756608 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspbridge64.dll
- 2015-12-27 16:46 - 2016-01-09 08:21 - 00112032 _____ C:\WINDOWS\system32\NvRtmpStreamer64.dll
- 2015-12-27 16:46 - 2015-12-30 13:49 - 00000000 ____D C:\Users\AngryShadow\AppData\Local\NVIDIA
- 2015-12-27 16:46 - 2010-05-26 11:41 - 02401112 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DX9_43.dll
- 2015-12-27 16:46 - 2010-05-26 11:41 - 01998168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DX9_43.dll
- 2015-12-27 16:46 - 2010-05-26 11:41 - 00511328 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx10_43.dll
- 2015-12-27 16:46 - 2010-05-26 11:41 - 00470880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx10_43.dll
- 2015-12-27 16:46 - 2010-05-26 11:41 - 00276832 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3dx11_43.dll
- 2015-12-27 16:46 - 2010-05-26 11:41 - 00248672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3dx11_43.dll
- 2015-12-27 16:26 - 2015-12-27 16:26 - 00000000 ____D C:\Users\AngryShadow\AppData\Local\Blizzard
- 2015-12-27 16:13 - 2015-12-27 16:13 - 00000840 _____ C:\Users\Public\Desktop\Hearthstone.lnk
- 2015-12-27 16:12 - 2015-12-27 16:12 - 00000000 ____D C:\Users\AngryShadow\Tracing
- 2015-12-27 16:11 - 2016-01-16 23:08 - 00000000 ____D C:\Users\AngryShadow\AppData\Roaming\Skype
- 2015-12-27 16:11 - 2015-12-27 16:11 - 00002600 _____ C:\Users\Public\Desktop\Skype.lnk
- 2015-12-27 16:11 - 2015-12-27 16:11 - 00000000 ____D C:\Program Files (x86)\Skype
- 2015-12-27 16:10 - 2016-01-06 18:21 - 00000000 ____D C:\WINDOWS\OCR
- 2015-12-27 16:10 - 2015-12-27 16:10 - 00008192 _____ C:\WINDOWS\system32\config\userdiff
- 2015-12-27 16:10 - 2015-12-27 16:10 - 00000000 ____D C:\WINDOWS\Setup
- 2015-12-27 16:10 - 2015-12-27 16:10 - 00000000 ____D C:\WINDOWS\InfusedApps
- 2015-12-27 16:10 - 2015-12-27 16:10 - 00000000 ____D C:\Program Files (x86)\Reference Assemblies
- 2015-12-27 16:10 - 2015-12-27 16:10 - 00000000 ____D C:\Program Files (x86)\MSBuild
- 2015-12-27 16:10 - 2015-12-27 15:28 - 00000000 ___DC C:\WINDOWS\Panther
- 2015-12-27 16:09 - 2015-12-27 16:09 - 00000000 ____D C:\WINDOWS\SysWOW64\winrm
- 2015-12-27 16:09 - 2015-12-27 16:09 - 00000000 ____D C:\WINDOWS\SysWOW64\WCN
- 2015-12-27 16:09 - 2015-12-27 16:09 - 00000000 ____D C:\WINDOWS\SysWOW64\sysprep
- 2015-12-27 16:09 - 2015-12-27 16:09 - 00000000 ____D C:\WINDOWS\SysWOW64\slmgr
- 2015-12-27 16:09 - 2015-12-27 16:09 - 00000000 ____D C:\WINDOWS\SysWOW64\Printing_Admin_Scripts
- 2015-12-27 16:09 - 2015-12-27 16:09 - 00000000 ____D C:\WINDOWS\SysWOW64\0409
- 2015-12-27 16:09 - 2015-12-27 16:09 - 00000000 ____D C:\WINDOWS\system32\winrm
- 2015-12-27 16:09 - 2015-12-27 16:09 - 00000000 ____D C:\WINDOWS\system32\WCN
- 2015-12-27 16:09 - 2015-12-27 16:09 - 00000000 ____D C:\WINDOWS\system32\slmgr
- 2015-12-27 16:09 - 2015-12-27 16:09 - 00000000 ____D C:\WINDOWS\system32\Printing_Admin_Scripts
- 2015-12-27 16:09 - 2015-12-27 16:09 - 00000000 ____D C:\WINDOWS\system32\0409
- 2015-12-27 16:09 - 2015-12-27 16:09 - 00000000 ____D C:\Program Files\Reference Assemblies
- 2015-12-27 16:09 - 2015-12-27 16:09 - 00000000 ____D C:\Program Files\MSBuild
- 2015-12-27 16:08 - 2016-01-03 02:40 - 00826872 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
- 2015-12-27 16:08 - 2016-01-03 02:40 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
- 2015-12-27 16:07 - 2016-01-16 13:39 - 00000000 __RHD C:\Users\Public\Libraries
- 2015-12-27 16:07 - 2016-01-14 10:22 - 00000000 ___HD C:\WINDOWS\ELAMBKUP
- 2015-12-27 16:07 - 2016-01-14 03:15 - 00000000 ____D C:\WINDOWS\system32\appraiser
- 2015-12-27 16:07 - 2016-01-13 17:20 - 00000000 ___HD C:\Program Files\WindowsApps
- 2015-12-27 16:07 - 2016-01-09 22:24 - 00000000 ____D C:\WINDOWS\system32\NDF
- 2015-12-27 16:07 - 2016-01-09 13:58 - 00000000 ____D C:\WINDOWS\system32\WinBioDatabase
- 2015-12-27 16:07 - 2016-01-03 12:26 - 00000000 ____D C:\WINDOWS\rescache
- 2015-12-27 16:07 - 2016-01-01 01:09 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
- 2015-12-27 16:07 - 2015-12-28 03:37 - 00000000 ____D C:\WINDOWS\appcompat
- 2015-12-27 16:07 - 2015-12-28 03:30 - 00000000 ___RD C:\WINDOWS\PurchaseDialog
- 2015-12-27 16:07 - 2015-12-28 03:30 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel
- 2015-12-27 16:07 - 2015-12-28 03:30 - 00000000 ____D C:\WINDOWS\SysWOW64\Dism
- 2015-12-27 16:07 - 2015-12-28 03:30 - 00000000 ____D C:\WINDOWS\system32\SystemResetPlatform
- 2015-12-27 16:07 - 2015-12-28 03:30 - 00000000 ____D C:\WINDOWS\system32\oobe
- 2015-12-27 16:07 - 2015-12-28 03:30 - 00000000 ____D C:\WINDOWS\system32\Dism
- 2015-12-27 16:07 - 2015-12-28 03:30 - 00000000 ____D C:\WINDOWS\Provisioning
- 2015-12-27 16:07 - 2015-12-28 03:30 - 00000000 ____D C:\WINDOWS\bcastdvr
- 2015-12-27 16:07 - 2015-12-28 00:26 - 00000000 ____D C:\WINDOWS\system32\Sysprep
- 2015-12-27 16:07 - 2015-12-28 00:26 - 00000000 ____D C:\WINDOWS\Help
- 2015-12-27 16:07 - 2015-12-27 16:25 - 00028672 _____ C:\WINDOWS\system32\config\BCD-Template
- 2015-12-27 16:07 - 2015-12-27 16:09 - 00000000 ___SD C:\WINDOWS\SysWOW64\F12
- 2015-12-27 16:07 - 2015-12-27 16:09 - 00000000 ___SD C:\WINDOWS\SysWOW64\DiagSvcs
- 2015-12-27 16:07 - 2015-12-27 16:09 - 00000000 ___SD C:\WINDOWS\system32\F12
- 2015-12-27 16:07 - 2015-12-27 16:09 - 00000000 ___SD C:\WINDOWS\system32\dsc
- 2015-12-27 16:07 - 2015-12-27 16:09 - 00000000 ___SD C:\WINDOWS\system32\DiagSvcs
- 2015-12-27 16:07 - 2015-12-27 16:09 - 00000000 ____D C:\WINDOWS\SysWOW64\setup
- 2015-12-27 16:07 - 2015-12-27 16:09 - 00000000 ____D C:\WINDOWS\SysWOW64\oobe
- 2015-12-27 16:07 - 2015-12-27 16:09 - 00000000 ____D C:\WINDOWS\SysWOW64\MUI
- 2015-12-27 16:07 - 2015-12-27 16:09 - 00000000 ____D C:\WINDOWS\SysWOW64\Com
- 2015-12-27 16:07 - 2015-12-27 16:09 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns
- 2015-12-27 16:07 - 2015-12-27 16:09 - 00000000 ____D C:\WINDOWS\system32\setup
- 2015-12-27 16:07 - 2015-12-27 16:09 - 00000000 ____D C:\WINDOWS\system32\MUI
- 2015-12-27 16:07 - 2015-12-27 16:09 - 00000000 ____D C:\WINDOWS\system32\migwiz
- 2015-12-27 16:07 - 2015-12-27 16:09 - 00000000 ____D C:\WINDOWS\system32\Com
- 2015-12-27 16:07 - 2015-12-27 16:09 - 00000000 ____D C:\WINDOWS\PolicyDefinitions
- 2015-12-27 16:07 - 2015-12-27 16:09 - 00000000 ____D C:\WINDOWS\IME
- 2015-12-27 16:07 - 2015-12-27 16:09 - 00000000 ____D C:\Program Files\Windows Photo Viewer
- 2015-12-27 16:07 - 2015-12-27 16:09 - 00000000 ____D C:\Program Files\Windows Journal
- 2015-12-27 16:07 - 2015-12-27 16:09 - 00000000 ____D C:\Program Files\Windows Defender
- 2015-12-27 16:07 - 2015-12-27 16:09 - 00000000 ____D C:\Program Files\Common Files\System
- 2015-12-27 16:07 - 2015-12-27 16:09 - 00000000 ____D C:\Program Files (x86)\Windows Photo Viewer
- 2015-12-27 16:07 - 2015-12-27 16:09 - 00000000 ____D C:\Program Files (x86)\Windows Defender
- 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 __SHD C:\Program Files\Windows Sidebar
- 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 __SHD C:\Program Files (x86)\Windows Sidebar
- 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 __RSD C:\WINDOWS\Media
- 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ___SD C:\WINDOWS\SysWOW64\Nui
- 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ___SD C:\WINDOWS\SysWOW64\Configuration
- 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ___SD C:\WINDOWS\system32\Nui
- 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ___SD C:\WINDOWS\system32\Configuration
- 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ___RD C:\WINDOWS\Offline Web Pages
- 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ___RD C:\WINDOWS\DesktopTileResources
- 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\Web
- 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\Vss
- 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\tracing
- 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\TAPI
- 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
- 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\SysWOW64\SMI
- 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\SysWOW64\ras
- 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\SysWOW64\NDF
- 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\SysWOW64\MsDtc
- 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\SysWOW64\migwiz
- 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\SysWOW64\MailContactsCalendarSync
- 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\SysWOW64\Macromed
- 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\SysWOW64\Ipmi
- 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\SysWOW64\InputMethod
- 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\SysWOW64\inetsrv
- 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\SysWOW64\IME
- 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\SysWOW64\icsxml
- 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\SysWOW64\GroupPolicyUsers
- 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\SysWOW64\GroupPolicy
- 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\SysWOW64\FxsTmp
- 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\SysWOW64\downlevel
- 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\SysWOW64\Bthprops
- 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\SysWOW64\AppLocker
- 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\SysWOW64\AdvancedInstallers
- 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\SystemResources
- 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\SystemApps
- 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\system32\WinMetadata
- 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\system32\winevt
- 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\system32\SecureBootUpdates
- 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\system32\ras
- 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\system32\ProximityToast
- 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\system32\PointOfService
- 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\system32\MsDtc
- 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\system32\MailContactsCalendarSync
- 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\system32\Macromed
- 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\system32\Ipmi
- 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\system32\InputMethod
- 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\system32\inetsrv
- 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\system32\IME
- 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\system32\icsxml
- 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\system32\ias
- 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\system32\GroupPolicyUsers
- 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\system32\GroupPolicy
- 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\system32\downlevel
- 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\system32\config\Journal
- 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\system32\Bthprops
- 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\system32\AppLocker
- 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\system32\AdvancedInstallers
- 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\System
- 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\SKB
- 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\ShellNew
- 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\security
- 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\schemas
- 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\SchCache
- 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\Resources
- 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\Registration
- 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\PLA
- 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\Performance
- 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\L2Schemas
- 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\InputMethod
- 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\Globalization
- 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\Cursors
- 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\Branding
- 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\addins
- 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\Program Files\Windows Portable Devices
- 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\Program Files\Windows NT
- 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\Program Files\Windows Multimedia Platform
- 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\Program Files\Common Files\Services
- 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\Program Files (x86)\Windows Portable Devices
- 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\Program Files (x86)\Windows NT
- 2015-12-27 16:07 - 2015-12-27 16:07 - 00000000 ____D C:\Program Files (x86)\Windows Multimedia Platform
- 2015-12-27 16:07 - 2015-12-27 16:06 - 00230912 _____ (Microsoft Corporation) C:\WINDOWS\system32\msclmd.dll
- 2015-12-27 16:07 - 2015-12-27 16:06 - 00215943 _____ C:\WINDOWS\SysWOW64\dssec.dat
- 2015-12-27 16:07 - 2015-12-27 16:06 - 00215943 _____ C:\WINDOWS\system32\dssec.dat
- 2015-12-27 16:07 - 2015-12-27 16:06 - 00209408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msclmd.dll
- 2015-12-27 16:07 - 2015-12-27 16:06 - 00017463 _____ C:\WINDOWS\system32\Drivers\etc\services
- 2015-12-27 16:07 - 2015-12-27 16:06 - 00015462 _____ C:\WINDOWS\system32\OEMDefaultAssociations.xml
- 2015-12-27 16:07 - 2015-12-27 16:06 - 00008798 _____ C:\WINDOWS\SysWOW64\icrav03.rat
- 2015-12-27 16:07 - 2015-12-27 16:06 - 00008798 _____ C:\WINDOWS\system32\icrav03.rat
- 2015-12-27 16:07 - 2015-12-27 16:06 - 00003683 _____ C:\WINDOWS\system32\Drivers\etc\lmhosts.sam
- 2015-12-27 16:07 - 2015-12-27 16:06 - 00001988 _____ C:\WINDOWS\SysWOW64\ticrf.rat
- 2015-12-27 16:07 - 2015-12-27 16:06 - 00001988 _____ C:\WINDOWS\system32\ticrf.rat
- 2015-12-27 16:07 - 2015-12-27 16:06 - 00001358 _____ C:\WINDOWS\system32\Drivers\etc\protocol
- 2015-12-27 16:07 - 2015-12-27 16:06 - 00000858 _____ C:\WINDOWS\system32\DefaultQuestions.json
- 2015-12-27 16:07 - 2015-12-27 16:06 - 00000741 _____ C:\WINDOWS\SysWOW64\NOISE.DAT
- 2015-12-27 16:07 - 2015-12-27 16:06 - 00000741 _____ C:\WINDOWS\system32\NOISE.DAT
- 2015-12-27 16:07 - 2015-12-27 16:06 - 00000407 _____ C:\WINDOWS\system32\Drivers\etc\networks
- 2015-12-27 16:07 - 2015-12-27 16:06 - 00000389 _____ C:\WINDOWS\system32\AutoWorkplace.exe.config
- 2015-12-27 16:07 - 2015-12-27 16:06 - 00000219 _____ C:\WINDOWS\system.ini
- 2015-12-27 16:07 - 2015-12-27 16:06 - 00000092 _____ C:\WINDOWS\win.ini
- 2015-12-27 16:07 - 2015-12-27 15:45 - 00000000 ___RD C:\WINDOWS\DevicesFlow
- 2015-12-27 16:07 - 2015-12-27 15:29 - 00000000 ___RD C:\WINDOWS\PrintDialog
- 2015-12-27 16:07 - 2015-12-27 15:29 - 00000000 ___RD C:\WINDOWS\MiracastView
- 2015-12-27 16:07 - 2015-12-27 15:28 - 00000000 ____D C:\WINDOWS\system32\spool
- 2015-12-27 16:07 - 2015-12-27 15:28 - 00000000 ____D C:\WINDOWS\system32\FxsTmp
- 2015-12-27 16:06 - 2016-01-16 21:01 - 00000000 ____D C:\WINDOWS\INF
- 2015-12-27 16:02 - 2016-01-16 13:37 - 00262144 ___SH C:\WINDOWS\system32\config\BBI
- 2015-12-27 16:02 - 2016-01-14 10:23 - 00032768 ___SH C:\WINDOWS\system32\config\ELAM
- 2015-12-27 16:02 - 2015-12-27 16:09 - 00000000 ____D C:\WINDOWS\servicing
- 2015-12-27 16:02 - 2015-12-27 16:07 - 00000000 ____D C:\WINDOWS\system32\SMI
- 2015-12-27 16:02 - 2015-12-27 16:02 - 00000000 ____D C:\Users\AngryShadow\AppData\Local\Steam
- 2015-12-27 16:02 - 2015-12-27 16:02 - 00000000 ____D C:\Users\AngryShadow\AppData\Local\CEF
- 2015-12-27 16:02 - 2015-12-27 16:02 - 00000000 ____D C:\Users\AngryShadow\AppData\Local\Blizzard Entertainment
- 2015-12-27 16:02 - 2015-10-30 07:33 - 00000164 _____ C:\WINDOWS\system32\config\FP
- 2015-12-27 16:01 - 2016-01-16 13:25 - 00000000 ____D C:\Users\AngryShadow\AppData\Local\Battle.net
- 2015-12-27 16:01 - 2015-12-27 16:04 - 00000000 ____D C:\Users\AngryShadow\AppData\Roaming\Battle.net
- 2015-12-27 16:01 - 2015-12-27 16:01 - 00000711 _____ C:\Users\Public\Desktop\Battle.net.lnk
- 2015-12-27 15:59 - 2015-12-27 15:59 - 00000558 _____ C:\Users\Public\Desktop\Steam.lnk
- 2015-12-27 15:46 - 2015-12-27 15:46 - 00000000 ____D C:\Users\AngryShadow\AppData\Local\Comms
- 2015-12-27 15:36 - 2015-12-27 15:36 - 00000000 ____D C:\Users\AngryShadow\AppData\Local\NetworkTiles
- 2015-12-27 15:33 - 2016-01-16 13:44 - 00879220 _____ C:\WINDOWS\system32\PerfStringBackup.INI
- 2015-12-27 15:31 - 2016-01-16 13:38 - 00000000 ___RD C:\Users\AngryShadow\OneDrive
- 2015-12-27 15:31 - 2016-01-14 10:11 - 00000000 ____D C:\Users\AngryShadow\AppData\Local\Google
- 2015-12-27 15:31 - 2016-01-14 10:11 - 00000000 ____D C:\Program Files (x86)\Google
- 2015-12-27 15:31 - 2015-12-27 15:31 - 00002381 _____ C:\Users\AngryShadow\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
- 2015-12-27 15:31 - 2015-12-27 15:31 - 00000000 ____D C:\Users\AngryShadow\AppData\Local\MicrosoftEdge
- 2015-12-27 15:31 - 2015-12-27 15:31 - 00000000 ____D C:\Users\AngryShadow\AppData\Local\ActiveSync
- 2015-12-27 15:29 - 2016-01-16 21:00 - 00000000 ____D C:\Users\AngryShadow
- 2015-12-27 15:29 - 2016-01-10 09:57 - 00000000 ____D C:\Users\AngryShadow\AppData\Local\VirtualStore
- 2015-12-27 15:29 - 2016-01-06 22:40 - 00000000 __RHD C:\Users\Public\AccountPictures
- 2015-12-27 15:29 - 2016-01-06 18:20 - 00000000 ____D C:\Users\AngryShadow\AppData\Local\Packages
- 2015-12-27 15:29 - 2015-12-27 15:29 - 00000020 ___SH C:\Users\AngryShadow\ntuser.ini
- 2015-12-27 15:29 - 2015-12-27 15:29 - 00000000 ____D C:\Users\AngryShadow\AppData\Roaming\Adobe
- 2015-12-27 15:29 - 2015-12-27 15:29 - 00000000 ____D C:\Users\AngryShadow\AppData\Local\TileDataLayer
- 2015-12-27 15:29 - 2015-12-27 15:29 - 00000000 ____D C:\Users\AngryShadow\AppData\Local\Publishers
- 2015-12-27 15:28 - 2015-10-30 08:17 - 02718208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
- 2015-12-19 22:35 - 2015-12-27 16:25 - 00000000 ___HD C:\$SysReset
- 2015-12-18 17:08 - 2015-12-18 17:08 - 00194976 _____ (Oracle Corporation) C:\WINDOWS\system32\Drivers\VBoxNetLwf.sys
- 2015-12-18 17:08 - 2015-12-18 17:08 - 00117768 _____ (Oracle Corporation) C:\WINDOWS\system32\Drivers\VBoxNetAdp6.sys
- 2015-12-18 16:52 - 2015-12-07 05:57 - 00973664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll
- 2015-12-18 16:52 - 2015-12-07 05:55 - 01281376 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll
- 2015-12-18 16:52 - 2015-12-07 05:48 - 01155944 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfasfsrcsnk.dll
- 2015-12-18 16:52 - 2015-12-07 05:48 - 00983464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfasfsrcsnk.dll
- 2015-12-18 16:52 - 2015-12-07 05:48 - 00823264 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll
- 2015-12-18 16:52 - 2015-12-07 05:48 - 00696160 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupEngine.dll
- 2015-12-18 16:52 - 2015-12-07 05:47 - 00716928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll
- 2015-12-18 16:52 - 2015-12-07 05:46 - 03671888 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
- 2015-12-18 16:52 - 2015-12-07 05:46 - 02919320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
- 2015-12-18 16:52 - 2015-12-07 05:10 - 00824320 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcWebFilter.dll
- 2015-12-18 16:52 - 2015-12-07 04:58 - 24601600 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
- 2015-12-18 16:52 - 2015-12-07 04:53 - 19339264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
- 2015-12-18 16:52 - 2015-12-07 04:51 - 01318912 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifinetworkmanager.dll
- 2015-12-18 16:52 - 2015-12-07 04:45 - 02582016 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
- 2015-12-18 16:52 - 2015-12-07 04:43 - 02598400 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll
- 2015-12-18 16:52 - 2015-12-07 04:41 - 02061824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
- 2015-12-18 16:52 - 2015-12-07 04:40 - 01995776 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActiveSyncProvider.dll
- 2015-12-18 16:52 - 2015-12-07 04:40 - 01706496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActiveSyncProvider.dll
- 2015-12-18 16:51 - 2015-12-07 05:49 - 00412512 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifitask.exe
- 2015-12-18 16:51 - 2015-12-07 05:48 - 01092456 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll
- 2015-12-18 16:51 - 2015-12-07 05:48 - 01065080 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll
- 2015-12-18 16:51 - 2015-12-07 05:48 - 01020096 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsrcsnk.dll
- 2015-12-18 16:51 - 2015-12-07 05:48 - 00884256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll
- 2015-12-18 16:51 - 2015-12-07 05:48 - 00794888 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfds.dll
- 2015-12-18 16:51 - 2015-12-07 05:48 - 00670928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfds.dll
- 2015-12-18 16:51 - 2015-12-07 05:48 - 00526856 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfreadwrite.dll
- 2015-12-18 16:51 - 2015-12-07 05:48 - 00502112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupEngine.dll
- 2015-12-18 16:51 - 2015-12-07 05:48 - 00498448 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFCaptureEngine.dll
- 2015-12-18 16:51 - 2015-12-07 05:48 - 00462760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfreadwrite.dll
- 2015-12-18 16:51 - 2015-12-07 05:48 - 00450904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFCaptureEngine.dll
- 2015-12-18 16:51 - 2015-12-07 05:48 - 00337840 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFPlay.dll
- 2015-12-18 16:51 - 2015-12-07 05:48 - 00289248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFPlay.dll
- 2015-12-18 16:51 - 2015-12-07 05:48 - 00115040 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupApi.dll
- 2015-12-18 16:51 - 2015-12-07 05:48 - 00084832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupApi.dll
- 2015-12-18 16:51 - 2015-12-07 05:47 - 00925064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll
- 2015-12-18 16:51 - 2015-12-07 05:47 - 00898184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsrcsnk.dll
- 2015-12-18 16:51 - 2015-12-07 05:45 - 00264544 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContentDeliveryManager.Utilities.dll
- 2015-12-18 16:51 - 2015-12-07 05:15 - 01035776 _____ (Microsoft Corporation) C:\WINDOWS\system32\XboxNetApiSvc.dll
- 2015-12-18 16:51 - 2015-12-07 05:15 - 00075776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.XboxLive.ProxyStub.dll
- 2015-12-18 16:51 - 2015-12-07 05:09 - 00133120 _____ (Microsoft Corporation) C:\WINDOWS\system32\flvprophandler.dll
- 2015-12-18 16:51 - 2015-12-07 05:09 - 00092160 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanagerprecheck.dll
- 2015-12-18 16:51 - 2015-12-07 05:09 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorageUsage.dll
- 2015-12-18 16:51 - 2015-12-07 05:07 - 00134656 _____ (Microsoft Corporation) C:\WINDOWS\system32\wificonnapi.dll
- 2015-12-18 16:51 - 2015-12-07 05:07 - 00077312 _____ (Microsoft Corporation) C:\WINDOWS\system32\ProvPluginEng.dll
- 2015-12-18 16:51 - 2015-12-07 05:06 - 00572928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WpcWebFilter.dll
- 2015-12-18 16:51 - 2015-12-07 05:06 - 00231936 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCore.dll
- 2015-12-18 16:51 - 2015-12-07 05:06 - 00199168 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe
- 2015-12-18 16:51 - 2015-12-07 05:05 - 00192000 _____ (Microsoft Corporation) C:\WINDOWS\system32\provisioningcsp.dll
- 2015-12-18 16:51 - 2015-12-07 05:05 - 00036864 _____ (Microsoft Corporation) C:\WINDOWS\system32\BackgroundTransferHost.exe
- 2015-12-18 16:51 - 2015-12-07 05:04 - 00066560 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshost.dll
- 2015-12-18 16:51 - 2015-12-07 05:04 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\system32\provtool.exe
- 2015-12-18 16:51 - 2015-12-07 05:02 - 00269824 _____ (Microsoft Corporation) C:\WINDOWS\system32\moshostcore.dll
- 2015-12-18 16:51 - 2015-12-07 05:02 - 00161280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgent.exe
- 2015-12-18 16:51 - 2015-12-07 05:01 - 00543232 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll
- 2015-12-18 16:51 - 2015-12-07 05:01 - 00034304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BackgroundTransferHost.exe
- 2015-12-18 16:51 - 2015-12-07 05:00 - 00618496 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll
- 2015-12-18 16:51 - 2015-12-07 05:00 - 00323072 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSFlacDecoder.dll
- 2015-12-18 16:51 - 2015-12-07 05:00 - 00210432 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmcsp.dll
- 2015-12-18 16:51 - 2015-12-07 05:00 - 00203776 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupSvc.dll
- 2015-12-18 16:51 - 2015-12-07 04:59 - 00558080 _____ (Microsoft Corporation) C:\WINDOWS\system32\MBMediaManager.dll
- 2015-12-18 16:51 - 2015-12-07 04:59 - 00292352 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll
- 2015-12-18 16:51 - 2015-12-07 04:59 - 00286208 _____ (Microsoft Corporation) C:\WINDOWS\system32\provhandlers.dll
- 2015-12-18 16:51 - 2015-12-07 04:59 - 00165376 _____ (Microsoft Corporation) C:\WINDOWS\system32\provdatastore.dll
- 2015-12-18 16:51 - 2015-12-07 04:58 - 00459776 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapConfiguration.dll
- 2015-12-18 16:51 - 2015-12-07 04:57 - 00409088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StoreAgent.dll
- 2015-12-18 16:51 - 2015-12-07 04:57 - 00270848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSFlacDecoder.dll
- 2015-12-18 16:51 - 2015-12-07 04:56 - 00607232 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmsvc.dll
- 2015-12-18 16:51 - 2015-12-07 04:56 - 00497152 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmkvsrcsnk.dll
- 2015-12-18 16:51 - 2015-12-07 04:55 - 07979008 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll
- 2015-12-18 16:51 - 2015-12-07 04:55 - 00346112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapConfiguration.dll
- 2015-12-18 16:51 - 2015-12-07 04:54 - 00850432 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll
- 2015-12-18 16:51 - 2015-12-07 04:53 - 00381952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmkvsrcsnk.dll
- 2015-12-18 16:51 - 2015-12-07 04:51 - 00223232 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapibase.dll
- 2015-12-18 16:51 - 2015-12-07 04:50 - 01131520 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Audio.dll
- 2015-12-18 16:51 - 2015-12-07 04:49 - 01105920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Audio.dll
- 2015-12-18 16:51 - 2015-12-07 04:48 - 06297088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mos.dll
- 2015-12-18 16:51 - 2015-12-07 04:45 - 00900608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Networking.BackgroundTransfer.dll
- 2015-12-18 16:51 - 2015-12-07 04:45 - 00683008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Networking.BackgroundTransfer.dll
- 2015-12-18 16:51 - 2015-12-07 04:43 - 00931328 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSMPEG2ENC.DLL
- 2015-12-18 16:51 - 2015-12-07 04:40 - 03593216 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
- 2015-12-18 16:51 - 2015-12-07 04:39 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll
- 2015-12-18 16:51 - 2015-12-07 04:38 - 00871936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSMPEG2ENC.DLL
- 2015-12-18 16:51 - 2015-12-07 04:33 - 00375296 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDEServer.exe
- 2015-12-18 16:51 - 2015-12-07 04:32 - 00126464 _____ (Microsoft Corporation) C:\WINDOWS\system32\dialserver.dll
- ==================== One Month Modified files and folders ========
- (If an entry is included in the fixlist, the file/folder will be moved.)
- 2016-01-02 15:54 - 2015-10-30 08:17 - 00480256 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnet.dll
- 2016-01-02 15:54 - 2015-10-30 08:17 - 00395264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnet.dll
- 2016-01-02 15:54 - 2015-10-30 08:17 - 00220160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dplayx.dll
- 2016-01-02 15:54 - 2015-10-30 08:17 - 00069120 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnathlp.dll
- 2016-01-02 15:54 - 2015-10-30 08:17 - 00061952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnathlp.dll
- 2016-01-02 15:54 - 2015-10-30 08:17 - 00047104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpwsockx.dll
- 2016-01-02 15:54 - 2015-10-30 08:17 - 00027648 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnsvr.exe
- 2016-01-02 15:54 - 2015-10-30 08:17 - 00025088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpmodemx.dll
- 2016-01-02 15:54 - 2015-10-30 08:17 - 00023040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnsvr.exe
- 2016-01-02 15:54 - 2015-10-30 08:17 - 00020992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dplaysvr.exe
- 2016-01-02 15:54 - 2015-10-30 08:17 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnhupnp.dll
- 2016-01-02 15:54 - 2015-10-30 08:17 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnhpast.dll
- 2016-01-02 15:54 - 2015-10-30 08:17 - 00008704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnhupnp.dll
- 2016-01-02 15:54 - 2015-10-30 08:17 - 00008704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnhpast.dll
- 2016-01-02 15:54 - 2015-10-30 08:17 - 00005632 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnlobby.dll
- 2016-01-02 15:54 - 2015-10-30 08:17 - 00005632 _____ (Microsoft Corporation) C:\WINDOWS\system32\dpnaddr.dll
- 2016-01-02 15:54 - 2015-10-30 08:17 - 00004608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnlobby.dll
- 2016-01-02 15:54 - 2015-10-30 08:17 - 00004608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dpnaddr.dll
- 2015-12-18 09:48 - 2015-12-01 20:33 - 12426896 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvlddmkm.sys
- 2015-12-18 07:11 - 2015-11-15 15:26 - 00047760 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvvad64v.sys
- ==================== Files in the root of some directories =======
- 2016-01-16 21:03 - 2016-01-16 21:03 - 0000000 _____ () C:\Users\AngryShadow\AppData\Roaming\g78rfdsafhi
- 2016-01-06 22:28 - 2016-01-06 22:58 - 5929984 ___SH (Microsoft Corp.) C:\Users\AngryShadow\AppData\Roaming\Gambino.exe
- 2016-01-16 21:03 - 2016-01-16 21:03 - 0624696 _____ () C:\Users\AngryShadow\AppData\Roaming\im201506.exe
- 2015-12-28 00:26 - 2015-12-28 00:26 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
- Some files in TEMP:
- ====================
- C:\Users\AngryShadow\AppData\Local\Temp\0068-c8c2-6ba2-381f.exe
- C:\Users\AngryShadow\AppData\Local\Temp\3ae5-d40e-1d6f-b47f.exe
- C:\Users\AngryShadow\AppData\Local\Temp\8a4b-e41d-f8cb-4af4.exe
- C:\Users\AngryShadow\AppData\Local\Temp\bitool.dll
- C:\Users\AngryShadow\AppData\Local\Temp\fc73-9ff9-0c0b-e5db.exe
- C:\Users\AngryShadow\AppData\Local\Temp\ff60-875e-65d4-506c.exe
- C:\Users\AngryShadow\AppData\Local\Temp\setup.exe
- ==================== Bamital & volsnap =================
- (There is no automatic fix for files that do not pass verification.)
- C:\WINDOWS\system32\winlogon.exe => File is digitally signed
- C:\WINDOWS\system32\wininit.exe => File is digitally signed
- C:\WINDOWS\explorer.exe => File is digitally signed
- C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
- C:\WINDOWS\system32\svchost.exe => File is digitally signed
- C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
- C:\WINDOWS\system32\services.exe => File is digitally signed
- C:\WINDOWS\system32\User32.dll => File is digitally signed
- C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
- C:\WINDOWS\system32\userinit.exe => File is digitally signed
- C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
- C:\WINDOWS\system32\rpcss.dll => File is digitally signed
- C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
- C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
- C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
- LastRegBack: 2016-01-07 00:51
- ==================== End of FRST.txt ============================
Add Comment
Please, Sign In to add comment