Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:05-03-2016 01 Ran by Gareth (administrator) on GARETH-PC (28-03-2016 22:18:42) Running from C:\Users\Gareth\Downloads\Programs Loaded Profiles: Gareth (Available Profiles: Gareth) Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States) Internet Explorer Version 11 (Default browser: Chrome) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (ESET) C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (Creative Technology Ltd) C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe (Acronis) C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe (Acronis) C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe (Schneider Electric) C:\Program Files (x86)\APC\PowerChute Personal Edition\mainserv.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AdminService.exe () C:\Program Files (x86)\Allway Sync\Bin\SyncService.exe (CHENGDU YIWO Tech Development Co., Ltd) C:\Program Files (x86)\EaseUS\Todo Backup\bin\Agent.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe (Intel Corporation) C:\Windows\System32\IPROSetMonitor.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe () C:\Program Files (x86)\OpenVPN Technologies\PrivateTunnel\ovpnagent.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Schneider Electric) C:\Program Files (x86)\APC\PowerChute Personal Edition\dataserv.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE () C:\Program Files (x86)\EaseUS\Todo Backup\bin\TodoBackupService.exe (ESET) C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.29.5\GoogleCrashHandler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.29.5\GoogleCrashHandler64.exe (Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe (Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (Acronis) C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Logitech, Inc.) C:\Program Files\Logitech\SetPointP\SetPoint.exe (Ashampoo Development GmbH & Co. KG) C:\Program Files (x86)\Ashampoo\Ashampoo WinOptimizer 12\LiveTuner2.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudPhotos.exe (Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Nuance Communications, Inc.) C:\Program Files (x86)\ScanSoft\OmniPageSE4\OpWareSE4.exe () C:\Program Files (x86)\EaseUS\TrayPopup\TrayTipAgent.exe (CANON INC.) C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe (CANON INC.) C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE (Acronis) C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe (Acronis International GmbH) C:\Program Files (x86)\Common Files\Acronis\TibMounter\TibMounterMonitor.exe (Logitech, Inc.) C:\Program Files\Common Files\Logishrd\KHAL3\KHALMNPR.exe (Corsair Components Inc) C:\Program Files (x86)\Corsair\K50 Keyboard\K50Hid.exe (Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe (Creative Technology Ltd) C:\Program Files (x86)\Creative\USB Sound Blaster HD\Volume Panel\VolPanlu.exe (Corsair Components Inc) C:\Program Files (x86)\Corsair\K50 Keyboard\CorsTra.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Microsoft Corporation) C:\Windows\splwow64.exe (CANON INC.) C:\Program Files (x86)\Canon\Quick Menu\CNQMUPDT.EXE (Schneider Electric) C:\Program Files (x86)\APC\PowerChute Personal Edition\apcsystray.exe (Microsoft Corporation) C:\Windows\System32\vds.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe (Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe (Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Acronis) C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe () C:\Program Files (x86)\Ashampoo\Ashampoo WinOptimizer 12\LiveTunerService.exe (Tonec Inc.) C:\Program Files (x86)\Internet Download Manager\IDMan.exe (Tonec Inc.) C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe ==================== Registry (Whitelisted) =========================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [AtherosBtStack] => C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [617120 2011-03-13] (Atheros Commnucations) HKLM\...\Run: [AthBtTray] => C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe [379552 2011-03-13] (Atheros Commnucations) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11613288 2010-11-19] (Realtek Semiconductor) HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2789248 2016-02-17] (NVIDIA Corporation) HKLM\...\Run: [ShadowPlay] => "C:\Windows\system32\rundll32.exe" C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart HKLM\...\Run: [Acronis Scheduler2 Service] => C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe [518424 2013-07-18] (Acronis) HKLM\...\Run: [EvtMgr6] => C:\Program Files\Logitech\SetPointP\SetPoint.exe [3113592 2015-08-26] (Logitech, Inc.) HKLM\...\Run: [Ashampoo WinOptimizer Live-Tuner2] => C:\Program Files (x86)\Ashampoo\Ashampoo WinOptimizer 12\LiveTuner2.exe [3822416 2016-01-20] (Ashampoo Development GmbH & Co. KG) HKLM-x32\...\Run: [NUSB3MON] => C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-11-17] (Renesas Electronics Corporation) HKLM-x32\...\Run: [JMB36X IDE Setup] => C:\Windows\RaidTool\xInsIDE.exe HKLM-x32\...\Run: [OpwareSE4] => C:\Program Files (x86)\ScanSoft\OmniPageSE4\OpwareSE4.exe [79400 2007-02-04] (Nuance Communications, Inc.) HKLM-x32\...\Run: [EaseUS TB Tray Agent] => C:\Program Files (x86)\EaseUS\TrayPopup\TrayTipAgent.exe [253992 2015-12-10] () HKLM-x32\...\Run: [IJNetworkScannerSelectorEX] => C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe [449168 2012-03-26] (CANON INC.) HKLM-x32\...\Run: [CanonQuickMenu] => C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE [1298456 2015-04-20] (CANON INC.) HKLM-x32\...\Run: [TrueImageMonitor.exe] => C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe [7805936 2014-02-04] (Acronis) HKLM-x32\...\Run: [AcronisTibMounterMonitor] => C:\Program Files (x86)\Common Files\Acronis\TibMounter\TibMounterMonitor.exe [1102192 2013-10-10] (Acronis International GmbH) HKLM-x32\...\Run: [Corsair K50] => C:\Program Files (x86)\Corsair\K50 Keyboard\K50Hid.exe [1787904 2013-08-06] (Corsair Components Inc) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [Display] => C:\Program Files (x86)\APC\PowerChute Personal Edition\DataCollectionLauncher.exe [284024 2012-01-24] (Schneider Electric) HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [23248464 2016-03-23] (Dropbox, Inc.) HKLM-x32\...\Run: [VolPanel] => C:\Program Files (x86)\Creative\USB Sound Blaster HD\Volume Panel\VolPanlu.exe [241757 2010-12-08] (Creative Technology Ltd) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.) Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X] HKU\S-1-5-21-778663071-3000615460-497893972-1000\...\Run: [TIDAL] => [X] HKU\S-1-5-21-778663071-3000615460-497893972-1000\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [60688 2015-11-30] (Apple Inc.) HKU\S-1-5-21-778663071-3000615460-497893972-1000\...\Run: [iCloudPhotos] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudPhotos.exe [349968 2015-11-30] (Apple Inc.) ShellIconOverlayIdentifiers: [ IDM Shell Extension] -> {CDC95B92-E27C-4745-A8C5-64A52A78855D} => C:\Program Files (x86)\Internet Download Manager\IDMShellExt64.dll [2015-08-14] (Tonec Inc.) ShellIconOverlayIdentifiers: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.30.dll [2016-03-23] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.30.dll [2016-03-23] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.30.dll [2016-03-23] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.30.dll [2016-03-23] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.30.dll [2016-03-23] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.30.dll [2016-03-23] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.30.dll [2016-03-23] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.30.dll [2016-03-23] (Dropbox, Inc.) ShellIconOverlayIdentifiers: [AcronisSyncError] -> {934BC6C0-FEC2-4df5-A100-961DE2C8A0ED} => C:\Program Files (x86)\Acronis\TrueImageHome\tishell64.dll [2013-10-01] () ShellIconOverlayIdentifiers: [AcronisSyncInProgress] -> {00F848DC-B1D4-4892-9C25-CAADC86A215D} => C:\Program Files (x86)\Acronis\TrueImageHome\tishell64.dll [2013-10-01] () ShellIconOverlayIdentifiers: [AcronisSyncOk] -> {71573297-552E-46fc-BE3D-3DFAF88D47B7} => C:\Program Files (x86)\Acronis\TrueImageHome\tishell64.dll [2013-10-01] () ShellIconOverlayIdentifiers-x32: [ DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.30.dll [2016-03-23] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.30.dll [2016-03-23] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt3] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.30.dll [2016-03-23] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt4] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.30.dll [2016-03-23] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt5] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.30.dll [2016-03-23] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt6] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.30.dll [2016-03-23] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt7] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.30.dll [2016-03-23] (Dropbox, Inc.) ShellIconOverlayIdentifiers-x32: [ DropboxExt8] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.30.dll [2016-03-23] (Dropbox, Inc.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\APC UPS Status.lnk [2016-03-15] ShortcutTarget: APC UPS Status.lnk -> C:\Program Files (x86)\APC\PowerChute Personal Edition\Display.exe (Schneider Electric) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 Tcpip\..\Interfaces\{3C3627DB-44A5-4CEF-BCF9-60B36EF6E8BA}: [DhcpNameServer] 192.168.0.1 Internet Explorer: ================== BHO: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files (x86)\Internet Download Manager\IDMIECC64.dll [2015-12-08] (Internet Download Manager, Tonec Inc.) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.) BHO: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll [2015-08-26] (Logitech, Inc.) BHO-x32: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll [2015-12-08] (Internet Download Manager, Tonec Inc.) BHO-x32: CIESpeechBHO Class -> {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} -> C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll [2011-03-13] (Atheros Commnucations) BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.) BHO-x32: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll [2015-08-26] (Logitech, Inc.) DPF: HKLM-x32 {6C269571-C6D7-4818-BCA4-32A035E8C884} DPF: HKLM-x32 {D4B68B83-8710-488B-A692-D74B50BA558E} DPF: HKLM-x32 {F6ACF75C-C32C-447B-9BEF-46B766368D29} hxxp://files.creative.com/Web/softwareupdate/ocx/150323/CTPID.cab FireFox: ======== FF ProfilePath: C:\Users\Gareth\AppData\Roaming\Mozilla\Firefox\Profiles\weu19b0a.default FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_21_0_0_197.dll [2016-03-24] () FF Plugin: @microsoft.com/GENUINE -> disabled [No File] FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_197.dll [2016-03-24] () FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL [2014-07-28] (CANON INC.) FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2015-12-29] (Foxit Corporation) FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2015-12-29] (Foxit Corporation) FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xdp -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2015-12-29] (Foxit Corporation) FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xfdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [2015-12-29] (Foxit Corporation) FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2015-05-21] (Google) FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File] FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2016-02-09] (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2016-02-09] (NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-18] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-18] (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.2.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-01-21] (VideoLAN) FF Extension: IDM integration - C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpi [2016-03-10] FF Extension: Default - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}.xpi [2016-03-20] [not signed] FF HKLM-x32\...\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt FF Extension: Logitech SetPoint - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt [2016-03-03] [not signed] FF HKU\S-1-5-21-778663071-3000615460-497893972-1000\...\Firefox\Extensions: [mozilla_cc2@internetdownloadmanager.com] - C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpi FF HKU\S-1-5-21-778663071-3000615460-497893972-1000\...\SeaMonkey\Extensions: [mozilla_cc@internetdownloadmanager.com] - C:\Users\Gareth\AppData\Roaming\IDM\idmmzcc5 FF Extension: IDM CC - C:\Users\Gareth\AppData\Roaming\IDM\idmmzcc5 [2016-03-28] [not signed] FF HKU\S-1-5-21-778663071-3000615460-497893972-1000\...\SeaMonkey\Extensions: [mozilla_cc2@internetdownloadmanager.com] - C:\Program Files (x86)\Internet Download Manager\idmmzcc2.xpi Chrome: ======= CHR HomePage: Default -> hxxp://www.google.com/ig#m_1 CHR StartupUrls: Default -> "hxxp://www.bbc.com/news/uk" CHR Profile: C:\Users\Gareth\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Translate) - C:\Users\Gareth\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapbdbdomjkkjkaonfhkkikfgjllcleb [2016-02-18] CHR Extension: (Google Slides) - C:\Users\Gareth\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-02-18] CHR Extension: (Duolingo on the Web) - C:\Users\Gareth\AppData\Local\Google\Chrome\User Data\Default\Extensions\aiahmijlpehemcpleichkcokhegllfjl [2016-02-18] CHR Extension: (PasswordBox - Log in with 1-Click) - C:\Users\Gareth\AppData\Local\Google\Chrome\User Data\Default\Extensions\ajgnnllmjadopdlmpplonojbfogkjlcl [2016-02-18] CHR Extension: (Google Translate Pad) - C:\Users\Gareth\AppData\Local\Google\Chrome\User Data\Default\Extensions\ajgpafgiahigeanbnnmdbnkdkllhjndl [2016-02-18] CHR Extension: (Gold Price Charts, Silver Price Charts & News) - C:\Users\Gareth\AppData\Local\Google\Chrome\User Data\Default\Extensions\animfandjbomecobenkahkholebdiihi [2016-02-18] CHR Extension: (Google Drive) - C:\Users\Gareth\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-02-18] CHR Extension: (Keeper® Password Manager) - C:\Users\Gareth\AppData\Local\Google\Chrome\User Data\Default\Extensions\bfogiafebfohielmmehodmfbbebbbpei [2016-02-24] CHR Extension: (YouTube) - C:\Users\Gareth\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-02-18] CHR Extension: (Adblock Plus) - C:\Users\Gareth\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2016-03-09] CHR Extension: (Google Search) - C:\Users\Gareth\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2016-02-18] CHR Extension: (WGT Golf Challenge) - C:\Users\Gareth\AppData\Local\Google\Chrome\User Data\Default\Extensions\dcilimldmomiaihcfkmaldanopfejefg [2016-02-18] CHR Extension: (Logitech Smooth Scrolling) - C:\Users\Gareth\AppData\Local\Google\Chrome\User Data\Default\Extensions\dkpejdfnpdkhifgbancbammdijojoffk [2016-02-18] CHR Extension: (Google Sheets) - C:\Users\Gareth\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-02-18] CHR Extension: (iCloud Bookmarks) - C:\Users\Gareth\AppData\Local\Google\Chrome\User Data\Default\Extensions\fkepacicchenbjecpbpbclokcabebhah [2016-02-18] CHR Extension: (Musixmatch Lyrics for YouTube) - C:\Users\Gareth\AppData\Local\Google\Chrome\User Data\Default\Extensions\gfenjblodoldnbiddmggcbkcapiolbig [2016-02-18] CHR Extension: (Google Docs Offline) - C:\Users\Gareth\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-15] CHR Extension: (Dictionary by Dictionary.com) - C:\Users\Gareth\AppData\Local\Google\Chrome\User Data\Default\Extensions\gikhgcaliglmioibbockkmjknfnepbdh [2016-02-18] CHR Extension: (Open PayPal) - C:\Users\Gareth\AppData\Local\Google\Chrome\User Data\Default\Extensions\glghgmejmmepalcnengjekjfmfbailbl [2016-02-18] CHR Extension: (World Time Buddy) - C:\Users\Gareth\AppData\Local\Google\Chrome\User Data\Default\Extensions\jdhpjomiingppeefgnohkiapmnaeakoj [2016-02-18] CHR Extension: (Zoho Writer) - C:\Users\Gareth\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgaeidloagadfcohacebhbkkapgpiddj [2016-02-18] CHR Extension: (Bubble Translate) - C:\Users\Gareth\AppData\Local\Google\Chrome\User Data\Default\Extensions\jlhlebbhengjlhmcjebbkambaekglhkf [2016-02-18] CHR Extension: (Autodesk Homestyler) - C:\Users\Gareth\AppData\Local\Google\Chrome\User Data\Default\Extensions\kdmmkfaghgcicheaimnpffeeekheafkb [2016-02-18] CHR Extension: (SparkChess 8) - C:\Users\Gareth\AppData\Local\Google\Chrome\User Data\Default\Extensions\khgabmflimjjbclkmljlpmgaleanedem [2016-02-18] CHR Extension: (Google Docs Viewer (by Google)) - C:\Users\Gareth\AppData\Local\Google\Chrome\User Data\Default\Extensions\kkjmcfdcdbbkdacicmpokoddagejpknh [2016-02-18] CHR Extension: (Currency Converter) - C:\Users\Gareth\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbhghjdcfghfhlogkgdklfgmpodeglno [2016-02-18] CHR Extension: (Google Maps) - C:\Users\Gareth\AppData\Local\Google\Chrome\User Data\Default\Extensions\lneaknkopdijkpnocmklfnjbeapigfbh [2016-02-18] CHR Extension: (Google Dictionary (by Google)) - C:\Users\Gareth\AppData\Local\Google\Chrome\User Data\Default\Extensions\mgijmajocgfcbeboacabfgobmjgjcoja [2016-02-24] CHR Extension: (IDM Integration Module) - C:\Users\Gareth\AppData\Local\Google\Chrome\User Data\Default\Extensions\ngpampappnmepgilojfohadhhmbhlaek [2016-03-17] CHR Extension: (Chrome Web Store Payments) - C:\Users\Gareth\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-02-18] CHR Extension: (Evernote Web Clipper) - C:\Users\Gareth\AppData\Local\Google\Chrome\User Data\Default\Extensions\pioclpoplcdbaefihamjohnefbikjilc [2016-03-02] CHR Extension: (Gmail) - C:\Users\Gareth\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-02-18] CHR HKLM\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2016-03-11] CHR HKLM-x32\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2016-03-11] ==================== Services (Whitelisted) ======================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 APC Data Service; C:\Program Files (x86)\APC\PowerChute Personal Edition\dataserv.exe [21880 2012-01-24] (Schneider Electric) R2 APC UPS Service; C:\Program Files (x86)\APC\PowerChute Personal Edition\mainserv.exe [705912 2012-01-24] (Schneider Electric) R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77104 2015-10-07] (Apple Inc.) R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [74912 2011-03-13] (Atheros Commnucations) [File not signed] R2 BotkindSyncService; C:\Program Files (x86)\Allway Sync\Bin\SyncService.exe [182784 2015-10-29] () [File not signed] R2 CTAudSvcService; C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe [286720 2010-02-12] (Creative Technology Ltd) [File not signed] S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-03-22] (Dropbox, Inc.) S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-03-22] (Dropbox, Inc.) R2 EaseUS Agent; C:\Program Files (x86)\EaseUS\Todo Backup\bin\Agent.exe [36904 2015-12-10] (CHENGDU YIWO Tech Development Co., Ltd) R2 ekrn; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [2519904 2016-03-19] (ESET) R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1164672 2016-02-17] (NVIDIA Corporation) R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1880960 2016-02-17] (NVIDIA Corporation) R3 NvStreamNetworkSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [6474112 2016-02-17] (NVIDIA Corporation) R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [2609024 2016-02-17] (NVIDIA Corporation) R2 ovpnagent; C:\Program Files (x86)\OpenVPN Technologies\PrivateTunnel\ovpnagent.exe [1491320 2016-01-23] () R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1738168 2014-06-24] (Safer-Networking Ltd.) R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2088408 2014-06-27] (Safer-Networking Ltd.) R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2014-04-25] (Safer-Networking Ltd.) R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [6942480 2016-03-02] (TeamViewer GmbH) R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation) R2 WO_LiveService2; C:\Program Files (x86)\Ashampoo\Ashampoo WinOptimizer 12\LiveTunerService.exe [231248 2016-01-20] () ===================== Drivers (Whitelisted) ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R3 CORK50; C:\Windows\System32\drivers\CORK50.sys [25600 2012-08-10] ( ) R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [264552 2016-03-19] (ESET) S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation) R1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [186784 2015-11-16] (ESET) R2 epfwwfpr; C:\Windows\System32\DRIVERS\epfwwfpr.sys [170792 2016-03-19] (ESET) S3 epmntdrv; C:\Windows\system32\epmntdrv.sys [18528 2014-11-18] () S3 epmntdrv; C:\Windows\SysWOW64\epmntdrv.sys [14944 2014-11-18] () R0 EUBKMON; C:\Windows\System32\drivers\EUBKMON.sys [48168 2015-12-10] () S3 EuGdiDrv; C:\Windows\system32\EuGdiDrv.sys [10848 2014-11-18] () S3 EuGdiDrv; C:\Windows\SysWOW64\EuGdiDrv.sys [10208 2014-11-18] () R2 LiveTuner2PM; C:\Program Files (x86)\Ashampoo\Ashampoo WinOptimizer 12\LiveTuner64.sys [14320 2014-03-20] () R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [28032 2016-02-17] (NVIDIA Corporation) R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [47760 2015-12-18] (NVIDIA Corporation) R3 ptun0901; C:\Windows\System32\DRIVERS\ptun0901.sys [27136 2015-11-10] (The OpenVPN Project) R3 SaiK075C; C:\Windows\System32\DRIVERS\SaiK075C.sys [181920 2016-02-02] (Saitek) R3 SaiMini; C:\Windows\System32\DRIVERS\SaiMini.sys [23968 2016-02-02] (Saitek) R3 SaiNtBus; C:\Windows\System32\drivers\SaiBus.sys [51616 2016-02-02] (Saitek) R0 tib; C:\Windows\System32\DRIVERS\tib.sys [1120032 2016-02-17] (Acronis International GmbH) R0 tib_mounter; C:\Windows\System32\DRIVERS\tib_mounter.sys [198432 2016-02-17] (Acronis International GmbH) R0 vidsflt; C:\Windows\System32\DRIVERS\vidsflt.sys [117024 2016-02-17] (Acronis International GmbH) S3 ALSysIO; \??\C:\Users\Gareth\AppData\Local\Temp\ALSysIO64.sys [X] U3 DfSdkS; no ImagePath ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One Month Created files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2016-03-28 22:18 - 2016-03-28 22:18 - 00000000 ____D C:\FRST 2016-03-28 22:10 - 2016-03-28 22:10 - 00000000 ___RD C:\Users\Gareth\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BT Devices 2016-03-28 17:03 - 2016-03-28 17:03 - 00415272 _____ C:\Windows\system32\FNTCACHE.DAT 2016-03-28 16:23 - 2016-03-28 16:23 - 00109296 _____ C:\Users\Gareth\AppData\Local\GDIPFONTCACHEV1.DAT 2016-03-28 16:17 - 2016-03-28 16:17 - 00000082 _____ C:\Users\Gareth\Documents\cc_20160328_161745.reg 2016-03-28 16:12 - 2013-01-25 11:08 - 00089600 _____ C:\Windows\SysWOW64\CmdRtr64.DLL 2016-03-28 16:12 - 2013-01-25 11:06 - 00328704 _____ C:\Windows\SysWOW64\APOMgr64.DLL 2016-03-28 16:11 - 2016-03-28 16:11 - 00003010 _____ C:\Windows\System32\Tasks\{D36577A2-C398-493F-84BA-6B617ECC74E5} 2016-03-28 16:11 - 2016-03-28 16:11 - 00003010 _____ C:\Windows\System32\Tasks\{79E23259-D4C8-4C6D-BC43-BD0C5076F08D} 2016-03-28 16:09 - 2016-03-28 16:09 - 00003014 _____ C:\Windows\System32\Tasks\{54D63A48-ECE3-4048-B964-3549F26127DA} 2016-03-28 16:01 - 2014-04-17 11:06 - 00175104 ____N (Creative Technology Ltd) C:\Windows\system32\CtUsAs64.DLL 2016-03-28 15:58 - 2016-03-28 15:58 - 00006962 _____ C:\Users\Gareth\Documents\cc_20160328_155810.reg 2016-03-28 15:56 - 2016-03-28 15:56 - 00096358 _____ C:\Users\Gareth\Documents\cc_20160328_155613.reg 2016-03-28 14:24 - 2016-03-28 14:24 - 00002794 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC 2016-03-28 14:24 - 2016-03-28 14:24 - 00000830 _____ C:\Users\Public\Desktop\CCleaner.lnk 2016-03-28 14:24 - 2016-03-28 14:24 - 00000830 _____ C:\ProgramData\Desktop\CCleaner.lnk 2016-03-28 14:24 - 2016-03-28 14:24 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner 2016-03-28 14:24 - 2016-03-28 14:24 - 00000000 ____D C:\Program Files\CCleaner 2016-03-27 23:04 - 2016-03-28 19:20 - 00000000 ____D C:\Program Files (x86)\TeamViewer 2016-03-27 23:04 - 2016-03-28 15:33 - 00000000 ____D C:\Users\Gareth\AppData\Roaming\TeamViewer 2016-03-27 23:04 - 2016-03-27 23:04 - 00001053 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 11.lnk 2016-03-27 23:04 - 2016-03-27 23:04 - 00001041 _____ C:\Users\Public\Desktop\TeamViewer 11.lnk 2016-03-27 23:04 - 2016-03-27 23:04 - 00001041 _____ C:\ProgramData\Desktop\TeamViewer 11.lnk 2016-03-25 17:55 - 2016-03-25 17:55 - 00000226 _____ C:\Users\Gareth\Desktop\Asus P8Z68 DELUXE Performance Results - UserBenchmark.URL 2016-03-25 11:57 - 2016-03-25 11:57 - 00001148 _____ C:\Users\Public\Desktop\Duplicate Cleaner.lnk 2016-03-25 11:57 - 2016-03-25 11:57 - 00001148 _____ C:\ProgramData\Desktop\Duplicate Cleaner.lnk 2016-03-25 11:57 - 2016-03-25 11:57 - 00000000 ____D C:\Users\Gareth\AppData\Roaming\DigitalVolcano 2016-03-25 11:57 - 2016-03-25 11:57 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Duplicate Cleaner Free 2016-03-25 11:57 - 2016-03-25 11:57 - 00000000 ____D C:\Program Files (x86)\Duplicate Cleaner 2016-03-25 11:53 - 2016-03-25 11:53 - 00000206 _____ C:\Users\Gareth\Desktop\NirSoft - freeware utilities password recovery, system utilities, desktop utilities.URL 2016-03-24 22:05 - 2016-03-24 22:07 - 00000000 ____D C:\3fcd56bc6987896e14736b5f90d9e017 2016-03-24 15:38 - 2016-03-24 15:38 - 00003236 _____ C:\Windows\System32\Tasks\{8AA51621-886D-4A65-85C1-B223581941C0} 2016-03-24 15:25 - 2016-03-24 15:38 - 00001277 _____ C:\Users\Gareth\Desktop\VFXCentral.lnk 2016-03-24 15:25 - 2016-03-24 15:25 - 00000000 ____D C:\Users\Gareth\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OldProp Solutions Inc 2016-03-24 15:25 - 2016-03-24 15:25 - 00000000 ____D C:\Program Files (x86)\OldProp Solutions Inc 2016-03-23 09:23 - 2016-03-23 09:23 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox 2016-03-22 22:06 - 2016-03-22 22:06 - 00000000 ____D C:\Users\Gareth\Desktop\AI Traffic Manager 2016-03-22 22:06 - 2016-03-22 22:06 - 00000000 ____D C:\Users\Gareth\AppData\Local\AirTrafficManager 2016-03-22 17:13 - 2016-03-22 17:13 - 00000000 ____D C:\ProgramData\Creative Labs 2016-03-22 16:56 - 2016-03-28 14:40 - 00000000 ____D C:\ProgramData\Creative 2016-03-22 16:55 - 2016-03-28 16:01 - 00000000 ___HD C:\Program Files (x86)\Creative Installation Information 2016-03-22 16:54 - 2016-03-28 16:21 - 00000000 ____D C:\Program Files (x86)\Creative 2016-03-22 16:54 - 2016-03-28 16:14 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Creative 2016-03-22 16:54 - 2016-03-28 16:01 - 00000000 ____D C:\Program Files\Creative 2016-03-22 16:54 - 2016-03-28 16:00 - 00002339 _____ C:\Users\Public\Desktop\Creative Product Registration.lnk 2016-03-22 16:54 - 2016-03-28 16:00 - 00002339 _____ C:\ProgramData\Desktop\Creative Product Registration.lnk 2016-03-22 16:54 - 2014-04-17 11:06 - 00163840 ____N (Creative Technology Ltd) C:\Windows\SysWOW64\CtUsAsio.DLL 2016-03-22 16:16 - 2016-03-22 16:16 - 00003014 _____ C:\Windows\System32\Tasks\{91FD1F86-90F5-4C9A-BB89-90258E2D367D} 2016-03-22 16:15 - 2016-03-22 16:15 - 00003274 _____ C:\Windows\System32\Tasks\{3C53C8FF-E516-4D98-864D-A4E6C73C88E7} 2016-03-22 16:14 - 2016-03-22 16:14 - 00003074 _____ C:\Windows\System32\Tasks\{DDAD9C5B-590A-4CCA-BC13-172752FA2236} 2016-03-22 15:29 - 2016-03-28 14:14 - 00001325 _____ C:\Users\Gareth\Desktop\FTX Central 2 (P3DV3 - Oceania).lnk 2016-03-22 15:21 - 2016-03-22 15:21 - 00003040 _____ C:\Users\Gareth\Desktop\Support.txt 2016-03-22 15:21 - 2016-03-22 15:20 - 00031931 _____ C:\Users\Gareth\Desktop\CTSi.cab 2016-03-22 15:21 - 2016-03-22 15:15 - 00726532 _____ C:\Users\Gareth\Desktop\CTSi.txt 2016-03-22 15:21 - 2016-03-22 15:15 - 00726532 _____ C:\Users\Gareth\CTSi.txt 2016-03-22 00:33 - 2016-03-28 22:10 - 00000000 ___RD C:\Users\Gareth\Dropbox 2016-03-22 00:33 - 2016-03-22 00:33 - 00001232 _____ C:\Users\Gareth\Desktop\Dropbox.lnk 2016-03-22 00:30 - 2016-03-22 00:30 - 00000000 ____D C:\Users\Gareth\AppData\Roaming\Dropbox 2016-03-22 00:28 - 2016-03-28 22:10 - 00000904 _____ C:\Windows\Tasks\DropboxUpdateTaskMachineCore.job 2016-03-22 00:28 - 2016-03-28 22:01 - 00000908 _____ C:\Windows\Tasks\DropboxUpdateTaskMachineUA.job 2016-03-22 00:28 - 2016-03-23 09:23 - 00000000 ____D C:\Program Files (x86)\Dropbox 2016-03-22 00:28 - 2016-03-23 09:21 - 00000000 ____D C:\Users\Gareth\AppData\Local\Dropbox 2016-03-22 00:28 - 2016-03-22 00:28 - 00003904 _____ C:\Windows\System32\Tasks\DropboxUpdateTaskMachineUA 2016-03-22 00:28 - 2016-03-22 00:28 - 00003652 _____ C:\Windows\System32\Tasks\DropboxUpdateTaskMachineCore 2016-03-22 00:28 - 2016-03-22 00:28 - 00000000 ____D C:\ProgramData\Dropbox 2016-03-22 00:12 - 2016-03-09 00:37 - 33225861 _____ C:\Users\Gareth\Desktop\Cessna Citation Mustang for P3D Pilot's Guide.pdf 2016-03-21 17:32 - 2016-03-21 17:32 - 00000312 _____ C:\Users\Gareth\Desktop\IPHONE 5C 16GB Negro class A - CON 12 meses de GARANTÍA eBay.URL 2016-03-20 22:43 - 2016-03-20 22:43 - 00000000 ____D C:\Users\Gareth\AppData\Roaming\Flight One Software 2016-03-20 22:42 - 2016-03-20 22:42 - 00001479 _____ C:\Users\Gareth\Desktop\revision_history.lnk 2016-03-20 22:42 - 2016-03-20 22:42 - 00000000 ____D C:\Users\Gareth\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Flight One Software 2016-03-20 22:35 - 2016-03-21 10:01 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2016-03-20 22:04 - 2016-03-20 22:04 - 33256339 _____ C:\Users\Gareth\Desktop\Mustang Guide.pdf 2016-03-20 20:50 - 2016-03-20 22:39 - 00000000 ____D C:\Windows\Flight1 Citation Mustang P3D 2016-03-20 20:49 - 2016-03-20 20:49 - 00002048 _____ C:\Windows\mstgp3d.lic 2016-03-20 09:08 - 2016-03-20 09:08 - 00000341 _____ C:\Users\Gareth\Desktop\Hotel Ilunion Alcalá Norte, Madrid, Spain - Booking.com.url 2016-03-18 09:43 - 2016-03-18 09:43 - 00000226 _____ C:\Users\Gareth\Desktop\Blurries - The Prepar3d Process Lassoo.URL 2016-03-17 15:13 - 2016-03-17 15:13 - 00000065 _____ C:\Windows\sbwin.ini 2016-03-17 14:39 - 2013-03-26 13:19 - 00040160 _____ C:\Windows\system32\kschimp.ini 2016-03-17 14:38 - 2016-03-28 16:12 - 00000245 ___RH C:\Windows\ctfile.rfc 2016-03-17 14:38 - 2016-03-28 16:00 - 00466520 _____ (Creative Labs) C:\Windows\system32\wrap_oal.dll 2016-03-17 14:38 - 2016-03-28 16:00 - 00445016 _____ (Creative Labs) C:\Windows\SysWOW64\wrap_oal.dll 2016-03-17 14:38 - 2016-03-28 16:00 - 00123480 _____ (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\system32\OpenAL32.dll 2016-03-17 14:38 - 2016-03-28 16:00 - 00109144 _____ (Portions (C) Creative Labs Inc. and NVIDIA Corp.) C:\Windows\SysWOW64\OpenAL32.dll 2016-03-17 14:38 - 2014-04-25 17:29 - 01609728 _____ (Creative) C:\Windows\SysWOW64\Sens_oal.dll 2016-03-17 14:38 - 2014-04-25 16:33 - 01898496 ____N (Creative) C:\Windows\system32\Sens_oal.dll 2016-03-17 14:38 - 2013-03-26 18:04 - 01086464 _____ (Creative Technology Ltd.) C:\Windows\system32\KSAPO64.dll 2016-03-17 14:38 - 2013-03-26 18:03 - 00904192 _____ (Creative Technology Ltd.) C:\Windows\SysWOW64\KSAPO32.dll 2016-03-17 14:38 - 2013-03-26 17:31 - 01558528 _____ (Creative Technology Ltd.) C:\Windows\system32\Drivers\ksaud.sys 2016-03-17 14:38 - 2013-03-26 13:33 - 00011678 _____ C:\Windows\system32\MixerDefault.reg 2016-03-17 14:38 - 2013-03-26 13:33 - 00001975 _____ C:\Windows\system32\DeviceDefaultVista.reg 2016-03-17 14:38 - 2013-03-26 13:19 - 00032535 _____ C:\Windows\system32\ksaud.ini 2016-03-17 14:38 - 2010-07-14 15:12 - 00057856 _____ (Creative Technology Ltd.) C:\Windows\system32\KSPPLD64.dll 2016-03-17 14:38 - 2010-04-06 15:20 - 00239104 _____ (Creative Technology Ltd.) C:\Windows\system32\KSVSPI64.dll 2016-03-17 14:38 - 2010-04-06 15:19 - 00177152 _____ (Creative Technology Ltd.) C:\Windows\SysWOW64\KSVSPI32.dll 2016-03-17 14:38 - 2010-01-12 15:05 - 00109056 _____ (Creative Technology Ltd.) C:\Windows\system32\SBAVMon.dll 2016-03-17 14:38 - 2009-05-26 16:59 - 00026768 _____ C:\Windows\ksaudENG.reg 2016-03-17 14:38 - 2007-07-05 11:27 - 00002630 _____ C:\Windows\MixerName.reg 2016-03-17 14:38 - 2006-10-06 15:17 - 00053248 ____N (Creative Technology Ltd ) C:\Windows\Ctregrun.exe 2016-03-17 14:38 - 2003-06-13 00:25 - 00007062 _____ C:\Windows\SysWOW64\audiopid.vxd 2016-03-17 14:38 - 2000-05-22 17:58 - 00647872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Mscomct2.ocx 2016-03-17 14:35 - 2016-03-17 14:37 - 159481824 _____ (Creative Technology Ltd) C:\Users\Gareth\Desktop\XUHD_PCDRV_L11_1_02_0021a.exe 2016-03-17 09:15 - 2016-03-17 09:15 - 00000000 ____D C:\Users\Gareth\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Inputwish 2016-03-17 09:15 - 2016-03-17 09:15 - 00000000 ____D C:\Users\Gareth\AppData\Local\Deployment 2016-03-17 09:15 - 2016-03-17 09:15 - 00000000 ____D C:\Users\Gareth\AppData\Local\Apps\2.0 2016-03-17 09:00 - 2016-03-17 09:00 - 00000000 ____D C:\Users\Gareth\AppData\Local\Inputwish 2016-03-16 18:25 - 2016-03-16 18:26 - 00000000 ____D C:\Program Files (x86)\FSWidgets Network Pack 2016-03-16 18:25 - 2016-03-16 18:25 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FSWidgets - Network Pack 2016-03-16 17:35 - 2016-03-16 17:35 - 00000000 ____D C:\Windows\System32\Tasks\Apple 2016-03-16 17:35 - 2016-03-16 17:35 - 00000000 ____D C:\Program Files (x86)\Apple Software Update 2016-03-16 09:11 - 2016-03-16 09:11 - 00001682 _____ C:\Users\Public\Desktop\REX 4 - Texture Direct .lnk 2016-03-16 09:11 - 2016-03-16 09:11 - 00001682 _____ C:\ProgramData\Desktop\REX 4 - Texture Direct .lnk 2016-03-16 09:08 - 2016-03-16 09:08 - 00001658 _____ C:\Users\Public\Desktop\REX Soft Clouds.lnk 2016-03-16 09:08 - 2016-03-16 09:08 - 00001658 _____ C:\ProgramData\Desktop\REX Soft Clouds.lnk 2016-03-16 09:08 - 2016-03-16 09:08 - 00000000 ____D C:\ProgramData\Caphyon 2016-03-15 08:14 - 2016-03-15 08:14 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\APC 2016-03-15 08:13 - 2016-03-15 08:13 - 13923704 _____ (Schneider Electric) C:\Users\Gareth\PCPE Setup.exe 2016-03-15 08:13 - 2016-03-15 08:13 - 13338112 _____ C:\Users\Gareth\PCPE_3.0.1.msi 2016-03-15 08:13 - 2016-03-15 08:13 - 01079808 _____ (Microsoft Corporation) C:\Users\Gareth\mfc80u.dll 2016-03-15 08:13 - 2016-03-15 08:13 - 00626688 _____ (Microsoft Corporation) C:\Users\Gareth\msvcr80.dll 2016-03-15 08:13 - 2016-03-15 08:13 - 00021880 _____ (Schneider Electric) C:\Users\Gareth\grm_res.dll 2016-03-15 08:13 - 2016-03-15 08:13 - 00021880 _____ (Schneider Electric) C:\Users\Gareth\fr_res.dll 2016-03-15 08:13 - 2016-03-15 08:13 - 00021368 _____ (Schneider Electric) C:\Users\Gareth\pt_res.dll 2016-03-15 08:13 - 2016-03-15 08:13 - 00021368 _____ (Schneider Electric) C:\Users\Gareth\it_res.dll 2016-03-15 08:13 - 2016-03-15 08:13 - 00021368 _____ (Schneider Electric) C:\Users\Gareth\es_res.dll 2016-03-15 08:13 - 2016-03-15 08:13 - 00021368 _____ (Schneider Electric) C:\Users\Gareth\en_res.dll 2016-03-15 08:13 - 2016-03-15 08:13 - 00020856 _____ (Schneider Electric) C:\Users\Gareth\ru_res.dll 2016-03-15 08:13 - 2016-03-15 08:13 - 00020344 _____ (Schneider Electric) C:\Users\Gareth\jp_res.dll 2016-03-15 08:13 - 2016-03-15 08:13 - 00019832 _____ (Schneider Electric) C:\Users\Gareth\zh_res.dll 2016-03-15 08:13 - 2016-03-15 08:13 - 00018808 _____ C:\Users\Gareth\ResourceReader.dll 2016-03-15 08:13 - 2016-03-15 08:13 - 00000550 _____ C:\Users\Gareth\Microsoft.VC80.MFC.manifest 2016-03-15 08:13 - 2016-03-15 08:13 - 00000522 _____ C:\Users\Gareth\Microsoft.VC80.CRT.manifest 2016-03-15 08:13 - 2016-03-15 08:13 - 00000035 _____ C:\Users\Gareth\dotnetfolder.txt 2016-03-14 16:58 - 2016-03-14 16:58 - 00000244 _____ C:\Users\Gareth\Desktop\Opus Camera Guide.URL 2016-03-14 16:36 - 2016-03-14 16:36 - 00000000 ____D C:\Users\Gareth\Documents\Prepar3D v2 Files 2016-03-14 16:24 - 2016-03-21 18:21 - 00000000 ____D C:\Users\Public\Documents\Fury_1500 2016-03-14 16:24 - 2016-03-21 18:21 - 00000000 ____D C:\ProgramData\Documents\Fury_1500 2016-03-14 16:24 - 2016-03-14 15:53 - 03084296 _____ C:\Users\Gareth\Downloads\Install_Content.msi 2016-03-14 15:54 - 2016-03-14 16:22 - 1739085956 _____ C:\Users\Gareth\Downloads\cont1.cab 2016-03-14 15:20 - 2016-03-25 11:36 - 00000000 ____D C:\PRO-ATC-X 2016-03-14 15:20 - 2016-03-14 15:20 - 00000612 _____ C:\Users\Gareth\Desktop\PRO-ATC-X.lnk 2016-03-14 15:20 - 2016-03-14 15:20 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PRO-ATC-X 2016-03-11 13:49 - 2016-01-28 11:20 - 00209056 _____ (Tonec Inc.) C:\Windows\system32\Drivers\idmwfp.sys 2016-03-11 08:34 - 2016-03-11 08:35 - 00000000 ___RD C:\Users\Gareth\Desktop\REX4 2016-03-10 23:57 - 2016-03-10 23:57 - 05575160 _____ (Mad catz ) C:\Users\Gareth\Downloads\Saitek_X52_Flight_Controller_7_0_53_6_x64_Drivers.exe 2016-03-10 23:57 - 2016-03-10 23:57 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_SaiK075C_01009.Wdf 2016-03-10 12:54 - 2016-03-14 18:09 - 00001203 _____ C:\Users\Public\Desktop\FS2Crew Deal.lnk 2016-03-10 12:54 - 2016-03-14 18:09 - 00001203 _____ C:\ProgramData\Desktop\FS2Crew Deal.lnk 2016-03-10 12:54 - 2016-03-10 12:54 - 00001361 _____ C:\Users\Public\Desktop\NGX Reboot Config.lnk 2016-03-10 12:54 - 2016-03-10 12:54 - 00001361 _____ C:\ProgramData\Desktop\NGX Reboot Config.lnk 2016-03-10 12:54 - 2016-03-10 12:54 - 00000000 ____D C:\Users\Gareth\AppData\Roaming\FS2Crew2010 2016-03-10 12:54 - 2016-03-10 12:54 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FS2Crew2015 2016-03-10 12:17 - 2016-03-10 12:17 - 00000000 ____D C:\ProgramData\MyTraffic 2016-03-10 11:31 - 2016-03-10 11:33 - 00000000 ____D C:\Users\Gareth\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MyTraffic Professional 6.0a 2016-03-09 23:16 - 2016-03-09 23:16 - 00001227 _____ C:\Users\Public\Desktop\Navigraph FMS Data.lnk 2016-03-09 23:16 - 2016-03-09 23:16 - 00001227 _____ C:\ProgramData\Desktop\Navigraph FMS Data.lnk 2016-03-09 17:53 - 2016-03-16 09:10 - 00000000 ____D C:\REX Soft Clouds 2016-03-09 17:42 - 2016-03-16 09:11 - 00000000 ____D C:\REX Texture Direct 2016-03-09 17:42 - 2016-03-09 17:53 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\REX 4 2016-03-09 14:39 - 2016-02-09 08:53 - 00387792 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2016-03-09 14:39 - 2016-02-09 08:10 - 00341200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2016-03-09 14:39 - 2016-02-08 23:05 - 20352512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2016-03-09 14:39 - 2016-02-08 22:51 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2016-03-09 14:39 - 2016-02-08 22:39 - 00496640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2016-03-09 14:39 - 2016-02-08 22:39 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2016-03-09 14:39 - 2016-02-08 22:38 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2016-03-09 14:39 - 2016-02-08 22:38 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2016-03-09 14:39 - 2016-02-08 22:37 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2016-03-09 14:39 - 2016-02-08 22:34 - 02280448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2016-03-09 14:39 - 2016-02-08 22:32 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2016-03-09 14:39 - 2016-02-08 22:31 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2016-03-09 14:39 - 2016-02-08 22:30 - 00476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2016-03-09 14:39 - 2016-02-08 22:28 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2016-03-09 14:39 - 2016-02-08 22:28 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2016-03-09 14:39 - 2016-02-08 22:28 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2016-03-09 14:39 - 2016-02-08 22:20 - 00416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2016-03-09 14:39 - 2016-02-08 22:16 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2016-03-09 14:39 - 2016-02-08 22:15 - 00091136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2016-03-09 14:39 - 2016-02-08 22:13 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2016-03-09 14:39 - 2016-02-08 22:12 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2016-03-09 14:39 - 2016-02-08 22:11 - 00279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2016-03-09 14:39 - 2016-02-08 22:10 - 04611072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2016-03-09 14:39 - 2016-02-08 22:10 - 00130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2016-03-09 14:39 - 2016-02-08 22:05 - 25816576 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2016-03-09 14:39 - 2016-02-08 22:03 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2016-03-09 14:39 - 2016-02-08 22:02 - 13012480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2016-03-09 14:39 - 2016-02-08 22:02 - 00687104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2016-03-09 14:39 - 2016-02-08 22:01 - 02050560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2016-03-09 14:39 - 2016-02-08 22:01 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2016-03-09 14:39 - 2016-02-08 21:43 - 02121216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2016-03-09 14:39 - 2016-02-08 21:39 - 01311744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2016-03-09 14:39 - 2016-02-08 21:38 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2016-03-09 14:39 - 2016-02-08 20:41 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2016-03-09 14:39 - 2016-02-08 20:41 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2016-03-09 14:39 - 2016-02-08 20:27 - 02887680 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2016-03-09 14:39 - 2016-02-08 20:27 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2016-03-09 14:39 - 2016-02-08 20:26 - 00571904 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2016-03-09 14:39 - 2016-02-08 20:26 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2016-03-09 14:39 - 2016-02-08 20:26 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2016-03-09 14:39 - 2016-02-08 20:26 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2016-03-09 14:39 - 2016-02-08 20:19 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2016-03-09 14:39 - 2016-02-08 20:18 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2016-03-09 14:39 - 2016-02-08 20:16 - 06052352 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2016-03-09 14:39 - 2016-02-08 20:15 - 00615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2016-03-09 14:39 - 2016-02-08 20:14 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2016-03-09 14:39 - 2016-02-08 20:14 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2016-03-09 14:39 - 2016-02-08 20:13 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2016-03-09 14:39 - 2016-02-08 20:13 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2016-03-09 14:39 - 2016-02-08 20:06 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2016-03-09 14:39 - 2016-02-08 20:03 - 00489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2016-03-09 14:39 - 2016-02-08 19:55 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2016-03-09 14:39 - 2016-02-08 19:54 - 00107520 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2016-03-09 14:39 - 2016-02-08 19:52 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2016-03-09 14:39 - 2016-02-08 19:51 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2016-03-09 14:39 - 2016-02-08 19:49 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2016-03-09 14:39 - 2016-02-08 19:47 - 00152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2016-03-09 14:39 - 2016-02-08 19:37 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2016-03-09 14:39 - 2016-02-08 19:35 - 00718336 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2016-03-09 14:39 - 2016-02-08 19:34 - 00798720 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2016-03-09 14:39 - 2016-02-08 19:33 - 14613504 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2016-03-09 14:39 - 2016-02-08 19:33 - 02123264 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2016-03-09 14:39 - 2016-02-08 19:33 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2016-03-09 14:39 - 2016-02-08 19:19 - 02597376 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2016-03-09 14:39 - 2016-02-08 19:07 - 01546752 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2016-03-09 14:39 - 2016-02-08 18:55 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2016-03-09 14:37 - 2016-02-12 20:52 - 03169792 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll 2016-03-09 14:37 - 2016-02-12 20:52 - 00192512 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll 2016-03-09 14:37 - 2016-02-12 20:52 - 00098816 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll 2016-03-09 14:37 - 2016-02-12 20:44 - 00091136 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll 2016-03-09 14:37 - 2016-02-12 20:39 - 00174080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll 2016-03-09 14:37 - 2016-02-12 20:22 - 02610688 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2016-03-09 14:37 - 2016-02-12 20:19 - 00709120 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll 2016-03-09 14:37 - 2016-02-12 20:18 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe 2016-03-09 14:37 - 2016-02-12 20:18 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll 2016-03-09 14:37 - 2016-02-12 20:18 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe 2016-03-09 14:37 - 2016-02-12 20:18 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll 2016-03-09 14:37 - 2016-02-12 20:18 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll 2016-03-09 14:37 - 2016-02-12 20:06 - 00573440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll 2016-03-09 14:37 - 2016-02-12 20:05 - 00093696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll 2016-03-09 14:37 - 2016-02-12 20:05 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe 2016-03-09 14:37 - 2016-02-12 20:05 - 00030208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll 2016-03-09 14:37 - 2016-02-04 19:52 - 03211264 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2016-03-09 14:37 - 2016-02-03 20:58 - 00862208 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll 2016-03-09 14:37 - 2016-02-03 20:52 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\asycfilt.dll 2016-03-09 14:37 - 2016-02-03 20:49 - 00572416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll 2016-03-09 14:37 - 2016-02-03 20:43 - 00067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\asycfilt.dll 2016-03-09 14:37 - 2016-02-03 20:07 - 00091648 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBSTOR.SYS 2016-03-09 14:37 - 2016-01-11 21:11 - 01684416 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys 2016-03-09 14:37 - 2015-11-19 16:07 - 00994760 _____ (Microsoft Corporation) C:\Windows\system32\ucrtbase.dll 2016-03-09 14:37 - 2015-11-19 16:07 - 00063840 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-private-l1-1-0.dll 2016-03-09 14:37 - 2015-11-19 16:07 - 00020832 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-math-l1-1-0.dll 2016-03-09 14:37 - 2015-11-19 16:07 - 00019808 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-multibyte-l1-1-0.dll 2016-03-09 14:37 - 2015-11-19 16:07 - 00017760 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-string-l1-1-0.dll 2016-03-09 14:37 - 2015-11-19 16:07 - 00017760 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-stdio-l1-1-0.dll 2016-03-09 14:37 - 2015-11-19 16:07 - 00016224 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-runtime-l1-1-0.dll 2016-03-09 14:37 - 2015-11-19 16:07 - 00015712 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-convert-l1-1-0.dll 2016-03-09 14:37 - 2015-11-19 16:07 - 00014176 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-time-l1-1-0.dll 2016-03-09 14:37 - 2015-11-19 16:07 - 00014176 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-2-0.dll 2016-03-09 14:37 - 2015-11-19 16:07 - 00013664 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll 2016-03-09 14:37 - 2015-11-19 16:07 - 00012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-process-l1-1-0.dll 2016-03-09 14:37 - 2015-11-19 16:07 - 00012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-heap-l1-1-0.dll 2016-03-09 14:37 - 2015-11-19 16:07 - 00012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-conio-l1-1-0.dll 2016-03-09 14:37 - 2015-11-19 16:07 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-utility-l1-1-0.dll 2016-03-09 14:37 - 2015-11-19 16:07 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-locale-l1-1-0.dll 2016-03-09 14:37 - 2015-11-19 16:07 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-environment-l1-1-0.dll 2016-03-09 14:37 - 2015-11-19 16:07 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-2-0.dll 2016-03-09 14:37 - 2015-11-19 16:07 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-1.dll 2016-03-09 14:37 - 2015-11-19 16:07 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l2-1-0.dll 2016-03-09 14:37 - 2015-11-19 16:07 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-timezone-l1-1-0.dll 2016-03-09 14:37 - 2015-11-19 16:07 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l2-1-0.dll 2016-03-09 14:37 - 2015-11-19 16:07 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-2-0.dll 2016-03-09 14:37 - 2015-11-19 16:06 - 00922432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ucrtbase.dll 2016-03-09 14:37 - 2015-11-19 16:06 - 00066400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-private-l1-1-0.dll 2016-03-09 14:37 - 2015-11-19 16:06 - 00022368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-math-l1-1-0.dll 2016-03-09 14:37 - 2015-11-19 16:06 - 00019808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-multibyte-l1-1-0.dll 2016-03-09 14:37 - 2015-11-19 16:06 - 00017760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-string-l1-1-0.dll 2016-03-09 14:37 - 2015-11-19 16:06 - 00017760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-stdio-l1-1-0.dll 2016-03-09 14:37 - 2015-11-19 16:06 - 00016224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-runtime-l1-1-0.dll 2016-03-09 14:37 - 2015-11-19 16:06 - 00015712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-convert-l1-1-0.dll 2016-03-09 14:37 - 2015-11-19 16:06 - 00014176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-time-l1-1-0.dll 2016-03-09 14:37 - 2015-11-19 16:06 - 00014176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-2-0.dll 2016-03-09 14:37 - 2015-11-19 16:06 - 00013664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-filesystem-l1-1-0.dll 2016-03-09 14:37 - 2015-11-19 16:06 - 00012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-process-l1-1-0.dll 2016-03-09 14:37 - 2015-11-19 16:06 - 00012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-heap-l1-1-0.dll 2016-03-09 14:37 - 2015-11-19 16:06 - 00012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-conio-l1-1-0.dll 2016-03-09 14:37 - 2015-11-19 16:06 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-utility-l1-1-0.dll 2016-03-09 14:37 - 2015-11-19 16:06 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-locale-l1-1-0.dll 2016-03-09 14:37 - 2015-11-19 16:06 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-environment-l1-1-0.dll 2016-03-09 14:37 - 2015-11-19 16:06 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-2-0.dll 2016-03-09 14:37 - 2015-11-19 16:06 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-1.dll 2016-03-09 14:37 - 2015-11-19 16:06 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l2-1-0.dll 2016-03-09 14:37 - 2015-11-19 16:06 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-timezone-l1-1-0.dll 2016-03-09 14:37 - 2015-11-19 16:06 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l2-1-0.dll 2016-03-09 14:37 - 2015-11-19 16:06 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-2-0.dll 2016-03-09 14:32 - 2016-02-11 20:56 - 05572032 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2016-03-09 14:32 - 2016-02-11 20:56 - 00154560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2016-03-09 14:32 - 2016-02-11 20:56 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2016-03-09 14:32 - 2016-02-11 20:52 - 01733592 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2016-03-09 14:32 - 2016-02-11 20:49 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2016-03-09 14:32 - 2016-02-11 20:49 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2016-03-09 14:32 - 2016-02-11 20:49 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll 2016-03-09 14:32 - 2016-02-11 20:49 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2016-03-09 14:32 - 2016-02-11 20:49 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2016-03-09 14:32 - 2016-02-11 20:49 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2016-03-09 14:32 - 2016-02-11 20:49 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2016-03-09 14:32 - 2016-02-11 20:49 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2016-03-09 14:32 - 2016-02-11 20:48 - 01214464 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll 2016-03-09 14:32 - 2016-02-11 20:48 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll 2016-03-09 14:32 - 2016-02-11 20:48 - 00344064 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2016-03-09 14:32 - 2016-02-11 20:48 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll 2016-03-09 14:32 - 2016-02-11 20:48 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2016-03-09 14:32 - 2016-02-11 20:47 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2016-03-09 14:32 - 2016-02-11 20:45 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2016-03-09 14:32 - 2016-02-11 20:45 - 00312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2016-03-09 14:32 - 2016-02-11 20:45 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll 2016-03-09 14:32 - 2016-02-11 20:45 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll 2016-03-09 14:32 - 2016-02-11 20:44 - 03994560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2016-03-09 14:32 - 2016-02-11 20:44 - 03938240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2016-03-09 14:32 - 2016-02-11 20:44 - 01461248 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2016-03-09 14:32 - 2016-02-11 20:44 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2016-03-09 14:32 - 2016-02-11 20:44 - 00730112 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2016-03-09 14:32 - 2016-02-11 20:44 - 00422400 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2016-03-09 14:32 - 2016-02-11 20:42 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll 2016-03-09 14:32 - 2016-02-11 20:42 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll 2016-03-09 14:32 - 2016-02-11 20:42 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2016-03-09 14:32 - 2016-02-11 20:41 - 01314328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2016-03-09 14:32 - 2016-02-11 20:41 - 00880128 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll 2016-03-09 14:32 - 2016-02-11 20:41 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll 2016-03-09 14:32 - 2016-02-11 20:41 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll 2016-03-09 14:32 - 2016-02-11 20:41 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll 2016-03-09 14:32 - 2016-02-11 20:41 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll 2016-03-09 14:32 - 2016-02-11 20:41 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2016-03-09 14:32 - 2016-02-11 20:41 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2016-03-09 14:32 - 2016-02-11 20:41 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2016-03-09 14:32 - 2016-02-11 20:41 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll 2016-03-09 14:32 - 2016-02-11 20:41 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2016-03-09 14:32 - 2016-02-11 20:41 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll 2016-03-09 14:32 - 2016-02-11 20:41 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2016-03-09 14:32 - 2016-02-11 20:41 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2016-03-09 14:32 - 2016-02-11 20:41 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2016-03-09 14:32 - 2016-02-11 20:41 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll 2016-03-09 14:32 - 2016-02-11 20:41 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll 2016-03-09 14:32 - 2016-02-11 20:41 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2016-03-09 14:32 - 2016-02-11 20:41 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll 2016-03-09 14:32 - 2016-02-11 20:41 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2016-03-09 14:32 - 2016-02-11 20:41 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll 2016-03-09 14:32 - 2016-02-11 20:41 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll 2016-03-09 14:32 - 2016-02-11 20:41 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll 2016-03-09 14:32 - 2016-02-11 20:41 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll 2016-03-09 14:32 - 2016-02-11 20:41 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2016-03-09 14:32 - 2016-02-11 20:41 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll 2016-03-09 14:32 - 2016-02-11 20:41 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2016-03-09 14:32 - 2016-02-11 20:41 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2016-03-09 14:32 - 2016-02-11 20:41 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2016-03-09 14:32 - 2016-02-11 20:41 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll 2016-03-09 14:32 - 2016-02-11 20:41 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2016-03-09 14:32 - 2016-02-11 20:41 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll 2016-03-09 14:32 - 2016-02-11 20:38 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2016-03-09 14:32 - 2016-02-11 20:38 - 00665088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll 2016-03-09 14:32 - 2016-02-11 20:38 - 00275456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2016-03-09 14:32 - 2016-02-11 20:38 - 00171520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll 2016-03-09 14:32 - 2016-02-11 20:38 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2016-03-09 14:32 - 2016-02-11 20:38 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll 2016-03-09 14:32 - 2016-02-11 20:38 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2016-03-09 14:32 - 2016-02-11 20:37 - 00251392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2016-03-09 14:32 - 2016-02-11 20:37 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll 2016-03-09 14:32 - 2016-02-11 20:37 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2016-03-09 14:32 - 2016-02-11 20:35 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll 2016-03-09 14:32 - 2016-02-11 20:35 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2016-03-09 14:32 - 2016-02-11 20:35 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll 2016-03-09 14:32 - 2016-02-11 20:34 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll 2016-03-09 14:32 - 2016-02-11 20:33 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2016-03-09 14:32 - 2016-02-11 20:31 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll 2016-03-09 14:32 - 2016-02-11 20:30 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll 2016-03-09 14:32 - 2016-02-11 20:30 - 00642560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll 2016-03-09 14:32 - 2016-02-11 20:30 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll 2016-03-09 14:32 - 2016-02-11 20:30 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll 2016-03-09 14:32 - 2016-02-11 20:30 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll 2016-03-09 14:32 - 2016-02-11 20:30 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll 2016-03-09 14:32 - 2016-02-11 20:30 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll 2016-03-09 14:32 - 2016-02-11 20:30 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll 2016-03-09 14:32 - 2016-02-11 20:30 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll 2016-03-09 14:32 - 2016-02-11 20:30 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll 2016-03-09 14:32 - 2016-02-11 20:30 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll 2016-03-09 14:32 - 2016-02-11 20:30 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll 2016-03-09 14:32 - 2016-02-11 20:30 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll 2016-03-09 14:32 - 2016-02-11 20:30 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll 2016-03-09 14:32 - 2016-02-11 20:30 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll 2016-03-09 14:32 - 2016-02-11 20:30 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll 2016-03-09 14:32 - 2016-02-11 20:30 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll 2016-03-09 14:32 - 2016-02-11 20:30 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll 2016-03-09 14:32 - 2016-02-11 20:30 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll 2016-03-09 14:32 - 2016-02-11 20:30 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll 2016-03-09 14:32 - 2016-02-11 20:30 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll 2016-03-09 14:32 - 2016-02-11 20:30 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll 2016-03-09 14:32 - 2016-02-11 20:30 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll 2016-03-09 14:32 - 2016-02-11 20:30 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll 2016-03-09 14:32 - 2016-02-11 20:30 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll 2016-03-09 14:32 - 2016-02-11 20:30 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll 2016-03-09 14:32 - 2016-02-11 20:30 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll 2016-03-09 14:32 - 2016-02-11 19:48 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe 2016-03-09 14:32 - 2016-02-11 19:43 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe 2016-03-09 14:32 - 2016-02-11 19:41 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe 2016-03-09 14:32 - 2016-02-11 19:40 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe 2016-03-09 14:32 - 2016-02-11 19:34 - 00290816 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys 2016-03-09 14:32 - 2016-02-11 19:34 - 00159232 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys 2016-03-09 14:32 - 2016-02-11 19:33 - 00129024 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys 2016-03-09 14:32 - 2016-02-11 19:32 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe 2016-03-09 14:32 - 2016-02-11 19:32 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2016-03-09 14:32 - 2016-02-11 19:32 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2016-03-09 14:32 - 2016-02-11 19:32 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2016-03-09 14:32 - 2016-02-11 19:32 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2016-03-09 14:32 - 2016-02-11 19:32 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2016-03-09 14:32 - 2016-02-11 19:31 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll 2016-03-09 14:32 - 2016-02-11 19:30 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll 2016-03-09 14:32 - 2016-02-11 19:30 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll 2016-03-09 14:32 - 2016-02-11 19:30 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll 2016-03-09 14:32 - 2016-02-11 19:30 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll 2016-03-09 14:31 - 2016-02-09 11:57 - 14634496 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll 2016-03-09 14:31 - 2016-02-09 11:57 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL 2016-03-09 14:31 - 2016-02-09 11:56 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx 2016-03-09 14:31 - 2016-02-09 11:56 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll 2016-03-09 14:31 - 2016-02-09 11:55 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\seclogon.dll 2016-03-09 14:31 - 2016-02-09 11:54 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll 2016-03-09 14:31 - 2016-02-09 11:51 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL 2016-03-09 14:31 - 2016-02-09 11:51 - 11411456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll 2016-03-09 14:31 - 2016-02-09 11:13 - 00008192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\spwmp.dll 2016-03-09 14:31 - 2016-02-09 11:13 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdxm.ocx 2016-03-09 14:31 - 2016-02-09 11:13 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxmasf.dll 2016-03-09 14:31 - 2016-02-05 20:54 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll 2016-03-09 14:31 - 2016-02-05 20:54 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll 2016-03-09 14:31 - 2016-02-05 20:53 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll 2016-03-09 14:31 - 2016-02-05 20:53 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll 2016-03-09 14:31 - 2016-02-05 20:50 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll 2016-03-09 14:31 - 2016-02-05 20:44 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll 2016-03-09 14:31 - 2016-02-05 20:42 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll 2016-03-09 14:31 - 2016-02-05 19:48 - 00372736 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll 2016-03-09 14:31 - 2016-02-05 19:43 - 00299520 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll 2016-03-09 14:31 - 2016-02-05 19:43 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll 2016-03-09 14:31 - 2016-02-05 03:19 - 00381440 _____ (Microsoft Corporation) C:\Windows\system32\mfds.dll 2016-03-09 14:31 - 2016-02-04 20:41 - 00296448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfds.dll 2016-03-09 14:04 - 2016-03-09 14:05 - 19298208 _____ C:\Users\Gareth\Downloads\SiteDownloadPat.php 2016-03-09 11:55 - 2016-03-09 17:51 - 00000000 ____D C:\rexdownload 2016-03-09 11:45 - 2016-03-09 11:45 - 00000000 ____D C:\Users\Gareth\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Orbx 2016-03-09 10:23 - 2016-03-09 10:23 - 00000000 ____D C:\Users\Gareth\AppData\Local\Foxit Reader 2016-03-09 10:20 - 2016-03-09 10:20 - 00000000 ____D C:\REX Download Manager 2016-03-09 10:20 - 2016-03-09 10:20 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\REX Game Studios 2016-03-09 10:19 - 2016-03-09 10:19 - 00000000 ____D C:\Users\Gareth\AppData\Roaming\REX Game Studios, LLC 2016-03-09 09:07 - 2016-02-19 21:02 - 00038336 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe 2016-03-09 09:07 - 2016-02-19 20:54 - 01168896 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2016-03-09 09:07 - 2016-02-19 16:07 - 01373184 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll 2016-03-09 09:07 - 2016-02-11 16:07 - 00689152 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll 2016-03-09 09:07 - 2016-02-05 16:07 - 00696832 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll 2016-03-09 09:07 - 2016-02-05 16:07 - 00499200 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll 2016-03-09 09:07 - 2016-02-05 16:07 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll 2016-03-08 14:09 - 2016-03-08 14:09 - 00001654 _____ C:\Users\Public\Desktop\Prepar3D v3.lnk 2016-03-08 14:09 - 2016-03-08 14:09 - 00001654 _____ C:\ProgramData\Desktop\Prepar3D v3.lnk 2016-03-08 14:09 - 2016-03-08 14:09 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lockheed Martin 2016-03-08 00:06 - 2016-03-08 00:06 - 08701472 _____ C:\Users\Gareth\Desktop\NGX Tutorial.pdf 2016-03-07 12:03 - 2016-03-07 12:03 - 00000000 ___HD C:\ProgramData\CanonIJEGV 2016-03-07 12:02 - 2016-03-07 12:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon MG5400 series Manual 2016-03-05 16:43 - 2016-03-11 08:39 - 00001230 _____ C:\Users\Gareth\Desktop\Prepar3D v3 Plans.lnk 2016-03-05 16:43 - 2016-03-11 08:37 - 00001318 _____ C:\Users\Gareth\Desktop\NGX Plans.lnk 2016-03-05 00:33 - 2016-03-09 23:16 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Navigraph FMS Data Manager 2016-03-05 00:29 - 2016-03-05 00:33 - 00000000 ____D C:\ProgramData\Navigraph 2016-03-05 00:29 - 2016-03-05 00:33 - 00000000 ____D C:\Program Files (x86)\Navigraph 2016-03-05 00:29 - 2016-03-05 00:29 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Navigraph Charts 2016-03-04 18:21 - 2016-03-04 18:21 - 09757080 _____ C:\Users\Gareth\Desktop\Pro-ATC.pdf 2016-03-04 17:57 - 2016-03-04 17:57 - 00000000 ____D C:\Users\Gareth\AppData\Roaming\PMDG 2016-03-04 10:25 - 2010-02-16 15:22 - 00222528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dblist32.Ocx 2016-03-04 10:25 - 2010-02-16 15:22 - 00126800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSWINSCK.ocx 2016-03-04 10:25 - 2008-09-16 16:46 - 00086016 _____ (10Tec Company) C:\Windows\SysWOW64\10Tec_hTooltip_100.dll 2016-03-04 10:25 - 2007-06-25 15:02 - 00475136 _____ (DMSoft Technologies) C:\Windows\SysWOW64\SkinCrafter2.dll 2016-03-04 10:25 - 2005-06-20 09:15 - 00132880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSINET.Ocx 2016-03-04 10:25 - 2005-04-13 05:00 - 00331784 _____ (VBGold Software) C:\Windows\SysWOW64\AResize.ocx 2016-03-04 10:25 - 2004-11-12 11:14 - 00036864 _____ (DMSoftTechnologies) C:\Windows\SysWOW64\SCLabel.ocx 2016-03-04 10:25 - 2003-11-13 16:44 - 00319488 _____ (Polar sales@polarsoftware.com www.polarsoftware.com) C:\Windows\SysWOW64\PolarZIPLight.dll 2016-03-04 10:25 - 2003-09-05 21:11 - 00139264 _____ (FreeVBCode.com) C:\Windows\SysWOW64\vbsendmail.dll 2016-03-04 10:25 - 2003-06-22 19:57 - 00094208 _____ (vbAccelerator) C:\Windows\SysWOW64\CMDLGD6.dll 2016-03-04 10:25 - 2002-05-30 13:08 - 00880640 _____ (SG InWare) C:\Windows\SysWOW64\SGPView4.ocx 2016-03-04 10:25 - 2001-04-19 14:04 - 00053248 _____ (Meelix Information Technology) C:\Windows\SysWOW64\PRNGMIT.dll 2016-03-04 10:25 - 2000-07-09 20:15 - 00106496 _____ (Marco Bellinaso) C:\Windows\SysWOW64\mbprgbar.ocx 2016-03-03 20:32 - 2016-03-03 20:32 - 01193175 _____ C:\Windows\unins000.exe 2016-03-03 20:32 - 2016-03-03 20:32 - 00037801 _____ C:\Windows\unins000.dat 2016-03-03 20:32 - 2016-03-03 20:32 - 00000000 ____D C:\Users\Gareth\AppData\Roaming\Corsair Software 2016-03-03 20:32 - 2016-03-03 20:32 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Corsair 2016-03-03 20:32 - 2016-03-03 20:32 - 00000000 ____D C:\Program Files (x86)\Corsair 2016-03-03 20:32 - 2012-08-10 18:44 - 00025600 _____ ( ) C:\Windows\system32\Drivers\CORK50.sys 2016-03-03 19:42 - 2016-03-03 19:42 - 00000000 ____D C:\Users\Gareth\AppData\Local\GMap.NET 2016-03-03 19:33 - 2016-03-03 19:33 - 00001603 _____ C:\Users\Gareth\Downloads\Opus_PMDG_737NGX.CDF 2016-03-03 19:32 - 2016-03-03 19:32 - 00000672 _____ C:\Users\Gareth\Downloads\Realair Duke Turbine_peebee.CDF 2016-03-03 17:35 - 2016-03-03 17:35 - 00000000 ____D C:\Users\Public\Documents\Logishrd 2016-03-03 17:35 - 2016-03-03 17:35 - 00000000 ____D C:\ProgramData\Documents\Logishrd 2016-03-03 17:34 - 2016-03-03 17:35 - 00000000 ____D C:\ProgramData\Logishrd 2016-03-03 17:34 - 2016-03-03 17:34 - 00018960 _____ (Logitech, Inc.) C:\Windows\system32\Drivers\LNonPnP.sys 2016-03-03 17:34 - 2016-03-03 17:34 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logitech 2016-03-03 17:34 - 2016-03-03 17:34 - 00000000 ____D C:\Program Files\Logitech 2016-03-03 17:34 - 2016-03-03 17:34 - 00000000 ____D C:\Program Files\Common Files\Logishrd 2016-03-03 17:32 - 2016-03-03 17:35 - 00000000 ____D C:\Users\Gareth\AppData\Roaming\Logitech 2016-03-03 17:32 - 2016-03-03 17:32 - 00000000 ____D C:\Users\Gareth\AppData\Roaming\Logishrd 2016-03-03 17:08 - 2016-03-28 14:09 - 00000000 ____D C:\ProgramData\firebird 2016-03-03 17:08 - 2015-08-25 14:35 - 00057344 _____ (Peter L. Dowson) C:\MakeRwys.exe 2016-03-03 16:33 - 2016-03-17 09:27 - 00000000 ___RD C:\Users\Gareth\Desktop\MISC 2016-03-03 08:22 - 2016-03-03 08:22 - 00000000 ____D C:\Users\Gareth\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Free FLV Player 2016-03-03 08:22 - 2016-03-03 08:22 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Free FLV Player 2016-03-03 08:22 - 2016-03-03 08:22 - 00000000 ____D C:\Program Files\Free FLV Player 2016-03-02 16:34 - 2016-03-02 16:50 - 00000000 ____D C:\Users\Gareth\AppData\Roaming\iFunbox_UserCache 2016-03-02 16:34 - 2016-03-02 16:34 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\i-Funbox DevTeam 2016-03-02 16:34 - 2016-03-02 16:34 - 00000000 ____D C:\Program Files (x86)\i-Funbox DevTeam 2016-03-02 16:11 - 2016-03-03 07:37 - 00000000 ____D C:\Users\Gareth\Documents\SynciOS Data Recovery 2016-03-02 16:10 - 2016-03-02 16:10 - 25888704 _____ (Anvsoft, Inc. ) C:\Users\Gareth\Downloads\syncios-data-recovery.exe 2016-03-02 16:09 - 2016-03-02 16:09 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Syncios 2016-03-02 16:09 - 2016-03-02 16:09 - 00000000 ____D C:\Program Files (x86)\Syncios 2016-03-02 16:07 - 2016-03-02 16:08 - 66390912 _____ (Anvsoft, Inc. ) C:\Users\Gareth\Downloads\setup_syncios.exe 2016-03-01 20:24 - 2016-03-01 20:24 - 00053881 _____ C:\Users\Gareth\Downloads\Predicación Pública Organizada por la Congregación - Formstack.html 2016-03-01 20:24 - 2016-03-01 20:24 - 00000000 ____D C:\Users\Gareth\Downloads\Predicación Pública Organizada por la Congregación - Formstack_files 2016-03-01 13:57 - 2016-03-01 14:03 - 00000000 ____D C:\Users\Gareth\AppData\Local\UmmyVideoDownloader 2016-03-01 13:57 - 2016-03-01 13:57 - 14664456 _____ ( ) C:\Users\Gareth\Downloads\UmmyVideoDownloader_setup.exe 2016-03-01 13:57 - 2016-03-01 13:57 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UmmyVideoDownloader 2016-03-01 13:53 - 2016-03-01 13:53 - 02382728 _____ C:\Users\Gareth\Downloads\UmmyVD-Web-Loader.exe 2016-03-01 08:46 - 2016-03-21 08:59 - 00000000 ___RD C:\Users\Gareth\iCloudDrive 2016-03-01 08:46 - 2016-03-01 08:46 - 00000000 ____D C:\Users\Gareth\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\iCloud 2016-03-01 08:46 - 2016-03-01 08:46 - 00000000 ____D C:\Users\Gareth\AppData\Local\Apple Inc 2016-02-29 14:47 - 2016-02-29 14:47 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCloud 2016-02-29 14:41 - 2016-03-16 17:35 - 00002563 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk 2016-02-29 14:41 - 2016-03-03 07:45 - 00000000 ____D C:\Users\Gareth\AppData\Roaming\Syncios 2016-02-29 14:41 - 2016-03-01 08:59 - 00000000 ____D C:\Users\Gareth\AppData\Local\Apple 2016-02-29 14:41 - 2016-02-29 14:47 - 00000000 ____D C:\Users\Gareth\AppData\Local\Apple Computer 2016-02-29 14:25 - 2016-02-29 14:25 - 00000000 ____D C:\Users\Gareth\AppData\Roaming\ThinkSky 2016-02-29 11:25 - 2016-02-29 16:20 - 00000000 ____D C:\Users\Gareth\AppData\Roaming\WindSolutions 2016-02-29 11:25 - 2016-02-29 11:28 - 00000000 ____D C:\ProgramData\WindSolutions 2016-02-29 11:17 - 2016-03-03 07:51 - 00000000 ____D C:\Users\Gareth\AppData\Roaming\Apple Computer 2016-02-29 11:17 - 2016-03-03 07:51 - 00000000 ____D C:\ProgramData\Apple Computer 2016-02-29 11:17 - 2016-03-03 07:50 - 00000000 ____D C:\Program Files\Common Files\Apple 2016-02-29 11:17 - 2016-02-29 14:20 - 00000000 ____D C:\Program Files (x86)\ThinkSky 2016-02-29 11:17 - 2016-02-29 11:17 - 00000000 ____D C:\ProgramData\Apple 2016-02-29 11:06 - 2016-02-29 11:06 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf 2016-02-29 11:05 - 2016-03-21 08:59 - 00000000 ____D C:\Users\Gareth\AppData\Roaming\SynciOS Data Transfer 2016-02-29 11:05 - 2016-03-17 19:01 - 00000000 ____D C:\Users\Gareth\.android 2016-02-29 11:05 - 2016-02-29 11:05 - 00000000 ____D C:\Users\Gareth\AppData\Local\CrashRpt ==================== One Month Modified files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2016-03-28 22:18 - 2016-02-15 10:00 - 00000000 ____D C:\Users\Gareth\AppData\Roaming\DMCache 2016-03-28 22:18 - 2009-07-14 06:45 - 00020496 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2016-03-28 22:18 - 2009-07-14 06:45 - 00020496 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2016-03-28 22:17 - 2009-07-14 07:13 - 00781298 _____ C:\Windows\system32\PerfStringBackup.INI 2016-03-28 22:17 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\inf 2016-03-28 22:10 - 2016-02-18 15:47 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2016-03-28 22:10 - 2016-02-15 14:56 - 00000000 ____D C:\ProgramData\NVIDIA 2016-03-28 22:10 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2016-03-28 22:09 - 2016-02-16 14:29 - 00036639 _____ C:\Windows\SysWOW64\PCPELog.txt 2016-03-28 22:03 - 2016-02-15 10:00 - 00000000 ____D C:\Users\Gareth\AppData\Roaming\IDM 2016-03-28 22:01 - 2016-02-18 15:47 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2016-03-28 22:01 - 2016-02-16 14:54 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2016-03-28 20:37 - 2016-02-15 09:11 - 00000000 ____D C:\Users\Gareth\Documents\Bluetooth Folder 2016-03-28 19:34 - 2016-02-15 09:13 - 00000000 ____D C:\ProgramData\Atheros 2016-03-28 19:17 - 2016-02-16 12:39 - 00000000 ____D C:\Users\Gareth\AppData\Local\CrashDumps 2016-03-28 16:14 - 2016-02-15 09:10 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2016-03-28 16:12 - 2009-07-14 07:32 - 00000000 ____D C:\Windows\Downloaded Program Files 2016-03-28 16:05 - 2016-02-15 15:44 - 00000000 ___RD C:\Users\Gareth\Desktop\Hold-Delete 2016-03-28 13:17 - 2016-02-15 18:39 - 00000000 ____D C:\Users\Gareth\Documents\Prepar3D v3 Files 2016-03-28 12:56 - 2016-02-15 15:50 - 00000000 ____D C:\OpusFSI 2016-03-26 18:04 - 2016-02-21 19:52 - 00000000 ___RD C:\Users\Gareth\Desktop\NI 2016-03-26 00:09 - 2016-02-16 14:08 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy 2016-03-25 17:00 - 2016-02-15 14:41 - 00000412 _____ C:\Windows\Tasks\One-Click Optimizer WO12.job 2016-03-25 13:04 - 2016-02-15 10:00 - 00000000 ____D C:\Users\Gareth\Downloads\Video 2016-03-25 10:54 - 2016-02-15 10:00 - 00000000 ____D C:\Users\Gareth\Downloads\Compressed 2016-03-24 22:06 - 2016-02-15 12:19 - 00765280 _____ C:\Windows\SysWOW64\PerfStringBackup.INI 2016-03-24 16:59 - 2016-02-16 14:54 - 00797376 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2016-03-24 16:59 - 2016-02-16 14:54 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2016-03-24 16:59 - 2016-02-16 14:54 - 00003768 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2016-03-24 08:23 - 2016-02-15 14:22 - 00000000 ___SD C:\Windows\SysWOW64\GWX 2016-03-24 08:23 - 2016-02-15 14:22 - 00000000 ___SD C:\Windows\system32\GWX 2016-03-22 23:36 - 2016-02-15 23:59 - 00000000 ____D C:\Users\Gareth\AppData\Roaming\vlc 2016-03-22 17:47 - 2016-02-16 21:31 - 00000000 ____D C:\Users\Gareth\AppData\Local\ElevatedDiagnostics 2016-03-22 17:12 - 2009-07-14 07:08 - 00032636 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2016-03-22 15:21 - 2016-02-13 21:04 - 00000000 ____D C:\Users\Gareth 2016-03-21 23:40 - 2016-02-15 10:43 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2016-03-21 23:38 - 2016-02-16 14:47 - 00000000 ____D C:\Users\Gareth\AppData\Local\PrivateTunnel 2016-03-21 09:07 - 2016-02-21 08:43 - 00000000 ____D C:\Windows\pss 2016-03-20 20:49 - 2016-02-18 12:24 - 00000000 ____D C:\Flight One Software 2016-03-19 23:37 - 2015-11-16 13:21 - 00264552 _____ (ESET) C:\Windows\system32\Drivers\eamonm.sys 2016-03-19 23:37 - 2015-11-16 13:21 - 00170792 _____ (ESET) C:\Windows\system32\Drivers\epfwwfpr.sys 2016-03-17 19:01 - 2016-02-15 10:00 - 00000000 ____D C:\Program Files (x86)\Internet Download Manager 2016-03-17 19:01 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\registration 2016-03-16 23:37 - 2016-02-16 15:40 - 00000000 ____D C:\Users\Gareth\Documents\Working files 2016-03-15 20:52 - 2016-02-16 14:53 - 00000000 ____D C:\Users\Gareth\AppData\Local\Adobe 2016-03-15 09:23 - 2016-02-18 12:02 - 00000000 ____D C:\ProgramData\Flight One Software 2016-03-15 08:14 - 2016-02-16 13:43 - 00000000 ____D C:\Program Files (x86)\APC 2016-03-13 23:00 - 2016-02-22 10:59 - 00000000 ____D C:\Users\Gareth\AppData\Roaming\Audacity 2016-03-12 23:52 - 2016-02-18 11:54 - 00000000 ____D C:\Users\Gareth\AppData\Roaming\Orbx systems 2016-03-12 18:25 - 2016-02-18 10:06 - 00001920 ____H C:\Windows\EPMBatch.ept 2016-03-11 08:52 - 2016-02-18 15:48 - 00002203 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2016-03-10 09:08 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache 2016-03-09 23:15 - 2009-07-14 06:57 - 00001547 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk 2016-03-09 18:42 - 2016-02-21 00:08 - 00000000 ____D C:\Windows\system32\MRT 2016-03-09 18:40 - 2016-02-21 00:08 - 143659408 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2016-03-09 18:39 - 2016-02-16 10:23 - 00000000 ____D C:\Windows\system32\appraiser 2016-03-08 17:28 - 2016-02-18 11:53 - 00000000 ____D C:\Users\Gareth\AppData\Local\Orbx 2016-03-07 12:02 - 2016-02-16 15:08 - 00000000 ____D C:\Program Files (x86)\Canon 2016-03-07 11:53 - 2016-02-16 15:35 - 00000000 ____D C:\Users\Gareth\AppData\Local\Canon Easy-PhotoPrint EX 2016-03-07 11:53 - 2009-07-14 07:32 - 00000000 ____D C:\Windows\system32\FxsTmp 2016-03-06 22:45 - 2016-02-15 18:52 - 00000000 ____D C:\Users\Gareth\AppData\Local\Windows Live 2016-03-05 01:09 - 2009-07-14 05:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared 2016-03-04 18:02 - 2016-02-24 13:48 - 00000000 ____D C:\Program Files (x86)\PMDG Operations Center 2016-03-03 06:58 - 2016-02-17 00:59 - 00000000 ____D C:\ProgramData\Acronis 2016-02-29 11:05 - 2016-02-16 15:40 - 00000000 ____D C:\Users\Gareth\Documents\Syncios 2016-02-27 00:31 - 2016-02-22 10:59 - 00000000 ____D C:\Program Files (x86)\Audacity ==================== Files in the root of some directories ======= 2008-02-05 14:28 - 2008-02-05 14:28 - 0000051 _____ () C:\Users\Gareth\AppData\Local\setup.txt Files to move or delete: ==================== C:\Users\Gareth\en_res.dll C:\Users\Gareth\es_res.dll C:\Users\Gareth\fr_res.dll C:\Users\Gareth\grm_res.dll C:\Users\Gareth\it_res.dll C:\Users\Gareth\jp_res.dll C:\Users\Gareth\mfc80u.dll C:\Users\Gareth\msvcr80.dll C:\Users\Gareth\PCPE Setup.exe C:\Users\Gareth\pt_res.dll C:\Users\Gareth\ResourceReader.dll C:\Users\Gareth\ru_res.dll C:\Users\Gareth\zh_res.dll ==================== Bamital & volsnap ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\dnsapi.dll => File is digitally signed C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2016-03-28 17:26 ==================== End of FRST.txt ============================