Hello,
Since two days ago my Computer has started to randomly freeze softwares or making them very slow, it first started with chrome, and now it has spread for some other programs.
I'm running Comodo, and hasn't have any notification or alerts of it, but I suspect I might have a virus, since the speed of most programs has doubled the amount of time to work.
FRST.txt:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 24-04-2015 Ran by Dominik (administrator) on DOMINIK-PC on 25-04-2015 20:36:53 Running from C:\Users\Dominik\Desktop Loaded Profiles: Dominik (Available profiles: Dominik) Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: English (United States) Internet Explorer Version 8 (Default browser: Chrome) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (COMODO) C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe (AMD) C:\Windows\System32\atiesrxx.exe (AMD) C:\Windows\System32\atieclxx.exe (Binary Fortress Software) C:\Program Files (x86)\DisplayFusion\DisplayFusionService.exe () C:\Program Files (x86)\EasyPHP-Webserver-14.1b2\binaries\dbserver\bin\ews-mysqld.exe (Samsung Electronics Co., Ltd.) C:\Windows\System32\RAPID\SamsungRapidSvc.exe (Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (COMODO) C:\Program Files\COMODO\COMODO Internet Security\cistray.exe () C:\Windows\DAODx.exe (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\RAPID\CacheFilter\SamsungRapidApp.exe (Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe (Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe (Binary Fortress Software) C:\Program Files (x86)\DisplayFusion\DisplayFusion.exe (NEC Electronics Corporation) C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\MOM.exe (Valve Corporation) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe (Dropbox, Inc.) C:\Users\Dominik\AppData\Roaming\Dropbox\bin\Dropbox.exe (Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe (ATI Technologies Inc.) C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\CCC.exe (COMODO) C:\Program Files\COMODO\COMODO Internet Security\cis.exe (Samsung Electronics.) C:\Program Files (x86)\Samsung\Samsung Magician\Samsung Magician.exe (Binary Fortress Software) C:\Program Files (x86)\DisplayFusion\DisplayFusionHookAppWIN6064.exe (Binary Fortress Software) C:\Program Files (x86)\DisplayFusion\DisplayFusionHookAppWIN6032.exe (Valve Corporation) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe (Electronic Arts) C:\Program Files (x86)\Origin\Origin.exe (COMODO) C:\Program Files\COMODO\COMODO Internet Security\cavwp.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\System32\vds.exe () C:\xampp\mysql\bin\mysqld.exe (Apache Software Foundation) C:\xampp\apache\bin\httpd.exe (Apache Software Foundation) C:\xampp\apache\bin\httpd.exe () C:\xampp\xampp-control.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (tards.net) E:\Downloads\Tardsplaya\Tardsplaya.exe (VideoLAN) C:\Program Files (x86)\VideoLAN\VLC\vlc.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [SamsungRapidApp] => C:\Program Files (x86)\Samsung\RAPID\CacheFilter\SamsungRapidApp.exe [281776 2014-09-16] (Samsung Electronics Co., Ltd.) HKLM\...\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [12697368 2014-10-14] (Logitech Inc.) HKLM\...\Run: [COMODO Internet Security] => C:\Program Files\COMODO\COMODO Internet Security\cistray.exe [1426136 2015-04-21] (COMODO) HKLM-x32\...\Run: [NUSB3MON] => C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [106496 2010-01-22] (NEC Electronics Corporation) HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe [767176 2014-11-20] (Advanced Micro Devices, Inc.) HKU\S-1-5-19\...\Run: [Sidebar] => %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun HKU\S-1-5-20\...\Run: [Sidebar] => %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun HKU\S-1-5-21-3750936097-2468696251-2832417832-1000\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [2889408 2015-04-17] (Valve Corporation) HKU\S-1-5-21-3750936097-2468696251-2832417832-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3696912 2014-03-04] (Disc Soft Ltd) HKU\S-1-5-21-3750936097-2468696251-2832417832-1000\...\Run: [f.lux] => C:\Users\Dominik\AppData\Local\FluxSoftware\Flux\flux.exe [1017224 2013-10-23] (Flux Software LLC) HKU\S-1-5-21-3750936097-2468696251-2832417832-1000\...\Run: [DisplayFusion] => C:\Program Files (x86)\DisplayFusion\DisplayFusion.exe [6886752 2015-01-07] (Binary Fortress Software) HKU\S-1-5-21-3750936097-2468696251-2832417832-1000\...\Run: [GoogleChromeAutoLaunch_66F8C29980E8EAA9103CEBF5E167BC0C] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [812872 2015-04-17] (Google Inc.) HKU\S-1-5-21-3750936097-2468696251-2832417832-1000\...\MountPoints2: {7369257d-9780-11e4-ae34-806e6f6e6963} - D:\.\Bin\ASSETUP.exe HKU\S-1-5-18\...\RunOnce: [SPReview] => C:\Windows\System32\SPReview\SPReview.exe [301568 2015-01-09] (Microsoft Corporation) HKU\S-1-5-18\Control Panel\Desktop\\SCRNSAVE.EXE -> Startup: C:\Users\Dominik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2015-02-04] ShortcutTarget: Dropbox.lnk -> C:\Users\Dominik\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) ShellIconOverlayIdentifiers: ["DropboxExt1"] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Dominik\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-02-10] (Dropbox, Inc.) ShellIconOverlayIdentifiers: ["DropboxExt2"] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Dominik\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-02-10] (Dropbox, Inc.) ShellIconOverlayIdentifiers: ["DropboxExt3"] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Dominik\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-02-10] (Dropbox, Inc.) ShellIconOverlayIdentifiers: ["DropboxExt4"] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Dominik\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-02-10] (Dropbox, Inc.) ShellIconOverlayIdentifiers: ["DropboxExt5"] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Dominik\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-02-10] (Dropbox, Inc.) ShellIconOverlayIdentifiers: ["DropboxExt6"] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Dominik\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-02-10] (Dropbox, Inc.) ShellIconOverlayIdentifiers: ["DropboxExt7"] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Dominik\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-02-10] (Dropbox, Inc.) ShellIconOverlayIdentifiers: ["DropboxExt8"] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Dominik\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll [2015-02-10] (Dropbox, Inc.) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page = BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll [2015-01-24] (Oracle Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-01-24] (Oracle Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF ProfilePath: C:\Users\Dominik\AppData\Roaming\Mozilla\Firefox\Profiles\h5uu80l3.default FF DefaultSearchEngine: DuckDuckGo FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_17_0_0_169.dll [2015-04-25] () FF Plugin: @microsoft.com/GENUINE -> disabled No File FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll No File FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_17_0_0_169.dll [2015-04-25] () FF Plugin-x32: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll [2015-01-24] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-01-24] (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-04] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-04] (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-07-22] (VideoLAN) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-03-17] (Adobe Systems Inc.) FF Extension: BetterTTV - C:\Users\Dominik\AppData\Roaming\Mozilla\Firefox\Profiles\h5uu80l3.default\Extensions\[email protected] [2015-04-25] FF Extension: Adblock Plus - C:\Users\Dominik\AppData\Roaming\Mozilla\Firefox\Profiles\h5uu80l3.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-04-25] FF Extension: Tab Mix Plus - C:\Users\Dominik\AppData\Roaming\Mozilla\Firefox\Profiles\h5uu80l3.default\Extensions\{dc572301-7619-498c-a57d-39143191b318}.xpi [2015-04-25] Chrome: ======= CHR HomePage: Default -> hxxp://find.localstrike.net/ CHR DefaultSuggestURL: Default -> {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&gs_ri={google:suggestRid}&xssi=t&q={searchTerms}&{google:inputType}{google:cursorPosition}{google:currentPageUrl}{google:pageClassification}{google:searchVersion}{google:sessionToken}{google:prefetchQuery}sugkey={google:suggestAPIKeyParameter} CHR Profile: C:\Users\Dominik\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Drive) - C:\Users\Dominik\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-01-08] CHR Extension: (James White) - C:\Users\Dominik\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkeidgmehkdjmpjodpjkepolokanalkm [2015-04-25] CHR Extension: (YouTube) - C:\Users\Dominik\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-01-08] CHR Extension: (Adblock Plus) - C:\Users\Dominik\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2015-04-03] CHR Extension: (Spotify - Music for every moment) - C:\Users\Dominik\AppData\Local\Google\Chrome\User Data\Default\Extensions\cnkjkdjlofllcpbemipjbcpfnglbgieh [2015-02-20] CHR Extension: (Google Search) - C:\Users\Dominik\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-01-08] CHR Extension: (Tampermonkey) - C:\Users\Dominik\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhdgffkkebhmkfjojejmpbldmpobfkfo [2015-01-08] CHR Extension: (Bookmark Manager) - C:\Users\Dominik\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmlllbghnfkpflemihljekbapjopfjik [2015-04-21] CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Dominik\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-13] CHR Extension: (Google Wallet) - C:\Users\Dominik\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-01-08] CHR Extension: (Gmail) - C:\Users\Dominik\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-01-08] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 CmdAgent; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [5540424 2015-04-21] (COMODO) S3 cmdvirth; C:\Program Files\COMODO\COMODO Internet Security\cmdvirth.exe [2265816 2015-04-21] (COMODO) R2 DisplayFusionService; C:\Program Files (x86)\DisplayFusion\DisplayFusionService.exe [3169648 2015-01-07] (Binary Fortress Software) S3 EasyAntiCheat; C:\Windows\SysWOW64\EasyAntiCheat.exe [173848 2015-02-09] (EasyAntiCheat Ltd) R2 ews-dbserver; C:\Program Files (x86)\EasyPHP-Webserver-14.1b2\binaries\dbserver\bin\ews-mysqld.exe [10958848 2015-03-21] () [File not signed] S2 ews-httpserver; C:\Program Files (x86)\EasyPHP-Webserver-14.1b2\binaries\httpserver\bin\ews-httpd.exe [20992 2015-03-21] (Apache Software Foundation) [File not signed] S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [1931632 2015-04-11] (Electronic Arts) R2 SamsungRapidSvc; C:\Windows\System32\RAPID\SamsungRapidSvc.exe [28848 2014-09-16] (Samsung Electronics Co., Ltd.) S3 VsEtwService120; C:\Program Files (x86)\Microsoft Visual Studio 12.0\Common7\Packages\Debugger\Services\VsEtwService.exe [89232 2014-07-22] (Microsoft Corporation) R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R1 cmderd; C:\Windows\System32\DRIVERS\cmderd.sys [20696 2015-04-01] (COMODO) R1 cmdGuard; C:\Windows\System32\DRIVERS\cmdguard.sys [797280 2015-04-01] (COMODO) R1 cmdHlp; C:\Windows\System32\DRIVERS\cmdhlp.sys [45880 2015-04-01] (COMODO) R3 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2015-01-22] (Disc Soft Ltd) R1 inspect; C:\Windows\System32\DRIVERS\inspect.sys [104608 2015-04-01] (COMODO) R3 LGSHidFilt; C:\Windows\System32\DRIVERS\LGSHidFilt.Sys [64280 2013-05-30] (Logitech Inc.) R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [15416 2009-07-16] () R0 SamsungRapidDiskFltr; C:\Windows\System32\DRIVERS\SamsungRapidDiskFltr.sys [268976 2014-09-16] (Samsung Electronics Co., Ltd.) R0 SamsungRapidFSFltr; C:\Windows\System32\DRIVERS\SamsungRapidFSFltr.sys [111280 2014-09-16] (Samsung Electronics Co., Ltd.) S3 tap-tb-0901; C:\Windows\System32\DRIVERS\tap-tb-0901.sys [38656 2014-09-29] (The OpenVPN Project) R3 VMfilt; C:\Windows\System32\drivers\VMfilt64.sys [25600 2009-07-31] (Creative Technology Ltd.) ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-04-25 20:36 - 2015-04-25 20:37 - 00016544 _____ () C:\Users\Dominik\Desktop\FRST.txt 2015-04-25 20:36 - 2015-04-25 20:36 - 00000000 ____D () C:\FRST 2015-04-25 20:35 - 2015-04-25 20:35 - 02099712 _____ (Farbar) C:\Users\Dominik\Desktop\FRST64.exe 2015-04-25 20:00 - 2015-04-25 20:00 - 00000000 ____D () C:\Users\Dominik\AppData\Local\Macromedia 2015-04-25 19:57 - 2015-04-25 19:57 - 00003768 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2015-04-25 19:57 - 2015-04-25 19:57 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2015-04-25 19:56 - 2015-04-25 19:56 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2015-04-25 19:56 - 2015-04-25 19:56 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2015-04-25 19:56 - 2015-04-25 19:56 - 00000000 ____D () C:\Windows\SysWOW64\Macromed 2015-04-25 19:56 - 2015-04-25 19:56 - 00000000 ____D () C:\Windows\system32\Macromed 2015-04-25 19:51 - 2015-04-25 19:51 - 01124544 _____ (Adobe Systems Incorporated) C:\Users\Dominik\Downloads\flashplayer17_ha_install.exe 2015-04-24 18:31 - 2015-04-24 18:34 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DisplayFusion 2015-04-24 17:01 - 2015-04-24 17:01 - 00000000 ____D () C:\Users\Dominik\Tracing 2015-04-24 15:56 - 2015-04-24 15:56 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\XAMPP 2015-04-24 15:52 - 2015-04-25 02:55 - 00000000 ____D () C:\xampp 2015-04-23 23:25 - 2015-04-23 23:25 - 00000194 _____ () C:\Users\Dominik\Desktop\Free Spotify Acc Link.txt 2015-04-23 23:06 - 2015-04-23 23:06 - 00003886 _____ () C:\Windows\System32\Tasks\Adobe Acrobat Update Task 2015-04-23 23:06 - 2015-04-23 23:06 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk 2015-04-23 23:06 - 2015-04-23 23:06 - 00002047 _____ () C:\Users\Public\Desktop\Acrobat Reader DC.lnk 2015-04-23 23:06 - 2015-04-23 23:06 - 00000000 ____D () C:\Program Files (x86)\Adobe 2015-04-23 21:39 - 2015-04-23 21:40 - 00000000 ___SD () C:\Windows\system32\GWX 2015-04-23 21:39 - 2015-04-23 21:39 - 00000000 ___SD () C:\Windows\SysWOW64\GWX 2015-04-23 21:39 - 2015-04-23 21:39 - 00000000 ___SD () C:\Windows\system32\CompatTel 2015-04-23 21:39 - 2015-04-23 21:39 - 00000000 ____D () C:\Windows\system32\appraiser 2015-04-23 21:26 - 2015-04-23 21:26 - 02543104 _____ (Microsoft Corporation) C:\Windows\system32\wpdshext.dll 2015-04-23 21:26 - 2015-04-23 21:26 - 02311168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wpdshext.dll 2015-04-23 21:26 - 2015-04-23 21:26 - 01632768 _____ (Microsoft Corporation) C:\Windows\system32\dwmcore.dll 2015-04-23 21:26 - 2015-04-23 21:26 - 01372160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dwmcore.dll 2015-04-23 21:26 - 2015-04-23 21:26 - 01239720 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe 2015-04-23 21:26 - 2015-04-23 21:26 - 01111552 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2015-04-23 21:26 - 2015-04-23 21:26 - 00957952 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll 2015-04-23 21:26 - 2015-04-23 21:26 - 00769536 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll 2015-04-23 21:26 - 2015-04-23 21:26 - 00726528 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll 2015-04-23 21:26 - 2015-04-23 21:26 - 00419840 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll 2015-04-23 21:26 - 2015-04-23 21:26 - 00227328 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2015-04-23 21:26 - 2015-04-23 21:26 - 00192000 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll 2015-04-23 21:26 - 2015-04-23 21:26 - 00082944 _____ (Microsoft Corporation) C:\Windows\system32\dwmapi.dll 2015-04-23 21:26 - 2015-04-23 21:26 - 00067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dwmapi.dll 2015-04-23 21:26 - 2015-04-23 21:26 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll 2015-04-21 16:21 - 2015-04-21 16:21 - 00000218 _____ () C:\Users\Dominik\AppData\Local\recently-used.xbel 2015-04-20 22:10 - 2015-04-21 18:08 - 00000000 ____D () C:\Users\Dominik\Desktop\Trabalho-ED1 2015-04-19 21:46 - 2015-04-19 21:46 - 00000000 ____D () C:\Users\Dominik\Documents\Fax 2015-04-17 20:55 - 2015-04-17 20:55 - 05557696 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2015-04-17 20:55 - 2015-04-17 20:55 - 03976632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2015-04-17 20:55 - 2015-04-17 20:55 - 03920824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2015-04-17 20:55 - 2015-04-17 20:55 - 03298816 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 02553856 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 01882624 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 01727904 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 01461760 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 01309696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00754688 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\http.sys 2015-04-17 20:55 - 2015-04-17 20:55 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00696320 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00566784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00367552 _____ (Microsoft Corporation) C:\Windows\system32\clfs.sys 2015-04-17 20:55 - 2015-04-17 20:55 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00341504 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe 2015-04-17 20:55 - 2015-04-17 20:55 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe 2015-04-17 20:55 - 2015-04-17 20:55 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00221184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00215040 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00191488 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00173056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00155576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2015-04-17 20:55 - 2015-04-17 20:55 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00135168 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe 2015-04-17 20:55 - 2015-04-17 20:55 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe 2015-04-17 20:55 - 2015-04-17 20:55 - 00098304 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00095672 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2015-04-17 20:55 - 2015-04-17 20:55 - 00092672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00079360 _____ (Microsoft Corporation) C:\Windows\system32\clfsw32.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe 2015-04-17 20:55 - 2015-04-17 20:55 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00058880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\clfsw32.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe 2015-04-17 20:55 - 2015-04-17 20:55 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00037376 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe 2015-04-17 20:55 - 2015-04-17 20:55 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00033792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe 2015-04-17 20:55 - 2015-04-17 20:55 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2015-04-17 20:55 - 2015-04-17 20:55 - 00029696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2015-04-17 20:55 - 2015-04-17 20:55 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2015-04-17 20:55 - 2015-04-17 20:55 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2015-04-17 20:55 - 2015-04-17 20:55 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll 2015-04-17 20:55 - 2015-04-17 20:55 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll 2015-04-11 22:15 - 2015-04-11 22:15 - 00000000 ____D () C:\Users\Dominik\Documents\Respawn 2015-04-11 21:38 - 2015-04-11 21:38 - 00001182 _____ () C:\Users\Public\Desktop\Titanfall.lnk 2015-04-11 20:50 - 2015-04-12 13:57 - 00000000 ____D () C:\Users\Dominik\AppData\Roaming\Origin 2015-04-11 20:50 - 2015-04-11 22:15 - 00000000 ____D () C:\Users\Dominik\AppData\Local\Origin 2015-04-11 20:50 - 2015-04-11 20:51 - 00000000 ____D () C:\Program Files (x86)\Origin Games 2015-04-11 20:48 - 2015-04-25 18:31 - 00000000 ____D () C:\ProgramData\Origin 2015-04-11 20:48 - 2015-04-11 22:15 - 00000000 ____D () C:\ProgramData\Electronic Arts 2015-04-11 20:48 - 2015-04-11 20:49 - 00000000 ____D () C:\Program Files (x86)\Origin 2015-04-11 20:48 - 2015-04-11 20:48 - 00000983 _____ () C:\Users\Public\Desktop\Origin.lnk 2015-04-11 20:48 - 2015-04-11 20:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Origin 2015-03-29 01:24 - 2015-03-29 01:27 - 00000000 ____D () C:\Users\Dominik\AppData\Local\Warframe 2015-03-27 23:52 - 2015-03-27 23:52 - 00000000 ____D () C:\Users\Dominik\Documents\FreeReign 2015-03-27 23:52 - 2015-03-27 23:52 - 00000000 ____D () C:\Users\Dominik\AppData\Local\FreeReign 2015-03-27 23:52 - 2015-03-27 23:52 - 00000000 ____D () C:\Users\Dominik\AppData\Local\CrashRpt 2015-03-27 22:07 - 2015-03-27 22:07 - 00000000 ____D () C:\Windows\SysWOW64\directx 2015-03-27 22:07 - 2015-03-27 22:07 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Aftermath 2015-03-27 21:49 - 2015-03-27 21:49 - 00000000 ____D () C:\Users\Dominik\AppData\Roaming\LibreOffice 2015-03-27 21:48 - 2015-03-27 21:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LibreOffice 4.4 2015-03-27 21:48 - 2015-03-27 21:48 - 00000000 ____D () C:\Program Files (x86)\LibreOffice 4 ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-04-25 20:27 - 2015-02-18 01:05 - 01474832 _____ () C:\Windows\system32\Drivers\sfi.dat 2015-04-25 20:20 - 2015-02-20 19:52 - 00000000 ____D () C:\Users\Dominik\AppData\Local\CrashDumps 2015-04-25 20:20 - 2015-01-22 15:07 - 00000000 ____D () C:\Users\Dominik\AppData\Roaming\DAEMON Tools Lite 2015-04-25 20:20 - 2015-01-18 16:50 - 00000000 ____D () C:\Users\Dominik\AppData\Roaming\TS3Client 2015-04-25 20:20 - 2015-01-08 14:39 - 00000000 ____D () C:\Program Files (x86)\Steam 2015-04-25 20:16 - 2015-01-08 14:05 - 00000898 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2015-04-25 20:15 - 2015-01-09 02:52 - 00000000 ____D () C:\Users\Dominik\AppData\Roaming\vlc 2015-04-25 20:10 - 2015-01-11 01:55 - 00000000 ____D () C:\Users\Dominik\AppData\Roaming\Skype 2015-04-25 19:57 - 2015-01-19 19:26 - 00000000 ____D () C:\Users\Dominik\AppData\Local\Adobe 2015-04-25 19:16 - 2015-01-08 14:05 - 00000894 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2015-04-25 14:35 - 2009-07-14 01:45 - 00015152 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-04-25 14:35 - 2009-07-14 01:45 - 00015152 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-04-25 14:34 - 2009-07-14 02:13 - 00170092 _____ () C:\Windows\system32\PerfStringBackup.INI 2015-04-25 14:29 - 2015-02-04 15:57 - 00000000 ___RD () C:\Users\Dominik\Dropbox 2015-04-25 14:29 - 2015-02-04 15:55 - 00000000 ____D () C:\Users\Dominik\AppData\Roaming\Dropbox 2015-04-25 14:27 - 2009-07-14 02:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2015-04-25 03:44 - 2015-01-08 13:01 - 01505010 ____N () C:\Windows\WindowsUpdate.log 2015-04-25 03:00 - 2009-07-14 00:20 - 00000000 ____D () C:\Windows\AppCompat 2015-04-24 18:34 - 2015-02-03 18:06 - 00000000 ____D () C:\Users\Dominik\Documents\DisplayFusion Backups 2015-04-24 18:34 - 2015-02-03 18:05 - 00000000 ____D () C:\Users\Dominik\AppData\Roaming\DisplayFusion 2015-04-24 18:34 - 2015-02-03 18:04 - 00000000 ____D () C:\Program Files (x86)\DisplayFusion 2015-04-24 17:01 - 2015-01-08 13:01 - 00000000 ____D () C:\Users\Dominik 2015-04-24 17:00 - 2015-01-11 01:55 - 00000000 ___RD () C:\Program Files (x86)\Skype 2015-04-24 17:00 - 2015-01-11 01:55 - 00000000 ____D () C:\ProgramData\Skype 2015-04-23 23:27 - 2015-01-19 19:26 - 00000000 ____D () C:\Users\Dominik\AppData\Roaming\Adobe 2015-04-23 23:06 - 2015-01-19 19:25 - 00000000 ____D () C:\ProgramData\Adobe 2015-04-23 21:39 - 2009-07-14 00:20 - 00000000 ____D () C:\Windows\system32\AdvancedInstallers 2015-04-23 20:50 - 2015-02-04 15:56 - 00000000 ____D () C:\Users\Dominik\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2015-04-21 12:23 - 2015-02-18 02:28 - 00255626 _____ () C:\Windows\system32\Drivers\fvstore.dat 2015-04-19 21:47 - 2009-07-14 02:32 - 00000000 ____D () C:\Windows\system32\FxsTmp 2015-04-18 03:23 - 2009-07-14 00:20 - 00000000 ____D () C:\Windows\PolicyDefinitions 2015-04-18 03:07 - 2015-01-08 14:01 - 00027240 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI 2015-04-18 03:06 - 2015-01-09 00:50 - 00000000 ____D () C:\Windows\system32\MRT 2015-04-18 03:01 - 2015-01-09 00:50 - 128913832 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2015-04-11 21:38 - 2009-07-14 02:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games 2015-04-01 14:49 - 2015-01-30 11:27 - 00797280 _____ (COMODO) C:\Windows\system32\Drivers\cmdguard.sys 2015-04-01 14:49 - 2015-01-30 11:27 - 00104608 _____ (COMODO) C:\Windows\system32\Drivers\inspect.sys 2015-04-01 14:49 - 2015-01-30 11:27 - 00045880 _____ (COMODO) C:\Windows\system32\Drivers\cmdhlp.sys 2015-04-01 14:49 - 2015-01-30 11:27 - 00020696 _____ (COMODO) C:\Windows\system32\Drivers\cmderd.sys 2015-04-01 14:48 - 2015-01-30 11:27 - 00576848 _____ (COMODO) C:\Windows\system32\guard64.dll 2015-04-01 14:48 - 2015-01-30 11:27 - 00444472 _____ (COMODO) C:\Windows\SysWOW64\guard32.dll 2015-04-01 14:48 - 2015-01-30 11:27 - 00041248 _____ (COMODO) C:\Windows\system32\cmdcsr.dll 2015-04-01 14:47 - 2015-01-30 11:27 - 00358104 _____ (COMODO) C:\Windows\system32\cmdvrt64.dll 2015-04-01 14:46 - 2015-01-30 11:27 - 00045784 _____ (COMODO) C:\Windows\system32\cmdkbd64.dll 2015-04-01 14:45 - 2015-01-30 11:27 - 00288472 _____ (COMODO) C:\Windows\SysWOW64\cmdvrt32.dll 2015-04-01 14:45 - 2015-01-30 11:27 - 00040664 _____ (COMODO) C:\Windows\SysWOW64\cmdkbd32.dll 2015-03-28 11:37 - 2015-01-08 13:03 - 00073640 _____ () C:\Users\Dominik\AppData\Local\GDIPFONTCACHEV1.DAT 2015-03-28 11:36 - 2009-07-14 01:45 - 00328232 _____ () C:\Windows\system32\FNTCACHE.DAT ==================== Files in the root of some directories ======= 2015-01-22 20:49 - 2015-01-22 20:49 - 0000000 ___SH () C:\Users\Dominik\AppData\Local\LumaEmu 2015-04-21 16:21 - 2015-04-21 16:21 - 0000218 _____ () C:\Users\Dominik\AppData\Local\recently-used.xbel 2015-01-12 18:37 - 2015-01-12 20:31 - 0007599 _____ () C:\Users\Dominik\AppData\Local\Resmon.ResmonCfg Files to move or delete: ==================== C:\Users\Dominik\jagex_cl_oldschool_LIVE.dat C:\Users\Dominik\jagex_cl_speccollect_LIVE.dat C:\Users\Dominik\random.dat Some content of TEMP: ==================== C:\Users\Dominik\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpjwcsub.dll ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-04-17 22:29 ==================== End Of Log ============================
Addition.txt
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 24-04-2015 Ran by Dominik at 2015-04-25 20:37:46 Running from C:\Users\Dominik\Desktop Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-3750936097-2468696251-2832417832-500 - Administrator - Disabled) Dominik (S-1-5-21-3750936097-2468696251-2832417832-1000 - Administrator - Enabled) => C:\Users\Dominik Guest (S-1-5-21-3750936097-2468696251-2832417832-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-3750936097-2468696251-2832417832-1003 - Limited - Enabled) ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: COMODO Antivirus (Enabled - Up to date) {F0BC89B2-8937-0933-021B-B17D981F2A71} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Comodo Defense+ (Enabled - Up to date) {4BDD6856-AF0D-06BD-38AB-8A0FE39860CC} FW: COMODO Firewall (Disabled) {C8870897-C358-086B-2944-184866CC6D0A} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov) Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 15.007.20033 - Adobe Systems Incorporated) Adobe Flash Player 17 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 17.0.0.169 - Adobe Systems Incorporated) Aftermath version 1.0 (HKLM-x32\...\{024D0ADC-6846-4B7A-B12F-D571DF826068}}_is1) (Version: 1.0 - Free Reign Entertainment) AMD Catalyst Install Manager (HKLM\...\{F2A7CE36-57BF-5C86-952D-90DBF3746D82}) (Version: 8.0.916.0 - Advanced Micro Devices, Inc.) Behaviors SDK (Windows Phone) for Visual Studio 2013 (x32 Version: 12.0.50716.0 - Microsoft Corporation) Hidden Behaviors SDK (Windows) for Visual Studio 2013 (x32 Version: 12.0.50429.0 - Microsoft Corporation) Hidden Bloodline Champions (HKLM-x32\...\Steam App 6370) (Version: - Stunlock Studios) Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.) Borderlands: The Pre-Sequel Update and DLC pack (HKLM-x32\...\Qm9yZGVybGFuZHNUaGVQcmVTZXF1ZWw=_is1) (Version: 1 - ) Build Tools - amd64 (Version: 12.0.31101 - Microsoft Corporation) Hidden Build Tools - x86 (x32 Version: 12.0.31101 - Microsoft Corporation) Hidden Build Tools Language Resources - amd64 (Version: 12.0.31101 - Microsoft Corporation) Hidden Build Tools Language Resources - x86 (x32 Version: 12.0.31101 - Microsoft Corporation) Hidden CCleaner (HKLM\...\CCleaner) (Version: 5.01 - Piriform) CDisplayEx 1.10.29 (HKLM\...\CDisplayEx_is1) (Version: - Progdigy Software S.A.R.L.) Cheat Engine 6.4 (HKLM-x32\...\Cheat Engine 6.4_is1) (Version: - Cheat Engine) Cities Skylines - Deluxe Edition v.1.0.5 (HKLM-x32\...\Cities Skylines - Deluxe Edition_is1) (Version: - ) COMODO Internet Security Premium (HKLM\...\{68BE8BAB-5375-4C99-9116-1808F5968D40}) (Version: 8.1.0.4426 - COMODO Security Solutions Inc.) Counter-Strike: Global Offensive (HKLM-x32\...\Steam App 730) (Version: - Valve) DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.49.1.0356 - Disc Soft Ltd) Dead Island: Epidemic (HKLM-x32\...\Steam App 222900) (Version: - Stunlock Studios) DisplayFusion (HKLM-x32\...\Steam App 227260) (Version: - Binary Fortress Software) DisplayFusion 7.1 (HKLM-x32\...\B076073A-5527-4f4f-B46B-B10692277DA2_is1) (Version: 7.1.0.0 - Binary Fortress Software) Dropbox (HKU\S-1-5-21-3750936097-2468696251-2832417832-1000\...\Dropbox) (Version: 3.4.4 - Dropbox, Inc.) Entity Framework 6.1.1 Tools for Visual Studio 2013 (HKLM-x32\...\{85253F13-EE42-4850-A3A5-79B90E92D7AC}) (Version: 12.0.30610.0 - Microsoft Corporation) Epic Games Launcher (HKLM\...\{8727C279-A122-40B8-8ACA-271E1809DAA5}) (Version: 1.1.23.0 - Epic Games, Inc.) f.lux (HKU\S-1-5-21-3750936097-2468696251-2832417832-1000\...\Flux) (Version: - ) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 42.0.2311.90 - Google Inc.) Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden Google Update Helper (x32 Version: 1.3.26.9 - Google Inc.) Hidden Hand of Fate (HKLM-x32\...\1424100574_is1) (Version: 2.0.0.1 - GOG.com) Infestation Survivor Stories version 1.0 (HKLM-x32\...\{BC3051A7-1021-4B57-A3DA-AAC24566FAE7}_is1) (Version: 1.0 - OP Productions LLC) Java 8 Update 31 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218031F0}) (Version: 8.0.310 - Oracle Corporation) Killing Floor (HKLM-x32\...\Steam App 1250) (Version: - Tripwire Interactive) LibreOffice 4.4.1.2 (HKLM-x32\...\{4A754DA6-6E12-40AF-BAF0-B7D60C6BE005}) (Version: 4.4.1.2 - The Document Foundation) LocalESPC (x32 Version: 8.59.29989 - Microsoft Corporation) Hidden Logitech Gaming Software 8.57 (HKLM\...\Logitech Gaming Software) (Version: 8.57.145 - Logitech Inc.) Marvell Miniport Driver (HKLM-x32\...\Marvell Miniport Driver) (Version: 11.24.5.3 - Marvell) Microsoft .NET Framework 4.5 Multi-Targeting Pack (HKLM-x32\...\{56E962F0-4FB0-3C67-88DB-9EAA6EEFC493}) (Version: 4.5.50710 - Microsoft Corporation) Microsoft .NET Framework 4.5 SDK (HKLM-x32\...\{4AE57014-05C4-4864-A13D-86517A7E1BA4}) (Version: 4.5.50710 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 Multi-Targeting Pack (ENU) (HKLM-x32\...\{D3517C62-68A5-37CF-92F7-93C029A89681}) (Version: 4.5.50932 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 Multi-Targeting Pack (HKLM-x32\...\{6A0C6700-EA93-372C-8871-DCCF13D160A4}) (Version: 4.5.50932 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 SDK (HKLM-x32\...\{19A5926D-66E1-46FC-854D-163AA10A52D3}) (Version: 4.5.51641 - Microsoft Corporation) Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation) Microsoft Help Viewer 2.1 (HKLM-x32\...\Microsoft Help Viewer 2.1) (Version: 2.1.21005 - Microsoft Corporation) Microsoft SQL Server 2012 Command Line Utilities (HKLM\...\{58FED865-4F13-408D-A5BF-996019C4B936}) (Version: 11.1.3000.0 - Microsoft Corporation) Microsoft SQL Server 2012 Data-Tier App Framework (HKLM-x32\...\{1B876496-B3A2-4D22-9B12-B608A3FD4B8B}) (Version: 11.1.2902.0 - Microsoft Corporation) Microsoft SQL Server 2012 Data-Tier App Framework (x64) (HKLM\...\{A6BA243E-85A3-4635-A269-32949C98AC7F}) (Version: 11.1.2902.0 - Microsoft Corporation) Microsoft SQL Server 2012 Express LocalDB (HKLM\...\{6C026A91-640F-4A23-8B68-05D589CC6F18}) (Version: 11.1.3000.0 - Microsoft Corporation) Microsoft SQL Server 2012 Management Objects (HKLM-x32\...\{2F7DBBE6-8EBC-495C-9041-46A772F4E311}) (Version: 11.1.3000.0 - Microsoft Corporation) Microsoft SQL Server 2012 Management Objects (x64) (HKLM\...\{43A5C316-9521-49C3-B9B6-FCE5E1005DF0}) (Version: 11.1.3000.0 - Microsoft Corporation) Microsoft SQL Server 2012 Native Client (HKLM\...\{D411E9C9-CE62-4DBF-9D92-4CB22B750ED5}) (Version: 11.1.3000.0 - Microsoft Corporation) Microsoft SQL Server 2012 Transact-SQL ScriptDom (HKLM\...\{54C5041B-0E91-4E92-8417-AAA12493C790}) (Version: 11.1.3000.0 - Microsoft Corporation) Microsoft SQL Server 2012 T-SQL Language Service (HKLM-x32\...\{04DD7AF4-A6D3-4E30-9BB9-3B3670719234}) (Version: 11.1.3000.0 - Microsoft Corporation) Microsoft SQL Server 2014 Express LocalDB (HKLM\...\{AB8DE9BA-19E1-446A-BCFA-6B3DA9751E21}) (Version: 12.0.2000.8 - Microsoft Corporation) Microsoft SQL Server 2014 Management Objects (HKLM-x32\...\{2774595F-BC2A-4B12-A25B-0C37A37049B0}) (Version: 12.0.2000.8 - Microsoft Corporation) Microsoft SQL Server 2014 Management Objects (x64) (HKLM\...\{1F9EB3B6-AED7-4AA7-B8F1-8E314B74B2A5}) (Version: 12.0.2000.8 - Microsoft Corporation) Microsoft SQL Server 2014 Transact-SQL ScriptDom (HKLM\...\{020CDFE0-C127-4047-B571-37C82396B662}) (Version: 12.0.2000.8 - Microsoft Corporation) Microsoft SQL Server 2014 T-SQL Language Service (HKLM-x32\...\{47D08E7A-92A1-489B-B0BF-415516497BCE}) (Version: 12.0.2000.8 - Microsoft Corporation) Microsoft SQL Server Compact 4.0 SP1 x64 ENU (HKLM\...\{78909610-D229-459C-A936-25D92283D3FD}) (Version: 4.0.8876.1 - Microsoft Corporation) Microsoft SQL Server Data Tools - enu (12.0.41012.0) (HKLM-x32\...\{AC8E0CF4-42A1-4151-B684-97CF6FD726CF}) (Version: 12.0.41012.0 - Microsoft Corporation) Microsoft SQL Server Data Tools Build Utilities - enu (12.0.30919.1) (HKLM-x32\...\{6781FF9B-E87D-4A03-9373-A55A288B83FA}) (Version: 12.0.30919.1 - Microsoft Corporation) Microsoft System CLR Types for SQL Server 2012 (HKLM-x32\...\{070C38AC-05CE-43DF-9A20-141332F6AB2B}) (Version: 11.1.3366.16 - Microsoft Corporation) Microsoft System CLR Types for SQL Server 2012 (x64) (HKLM\...\{05FF8209-C4F1-4C77-BC28-791653156D20}) (Version: 11.1.3366.16 - Microsoft Corporation) Microsoft System CLR Types for SQL Server 2014 (HKLM\...\{8C06D6DB-A391-4686-B050-99CC522A7843}) (Version: 12.0.2000.8 - Microsoft Corporation) Microsoft System CLR Types for SQL Server 2014 (HKLM-x32\...\{4AEB505C-95E1-4964-9B64-8D27F3186D30}) (Version: 12.0.2000.8 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 Redistributable - x86 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\...\{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\...\{7f51bdb9-ee21-49ee-94d6-90afc321780e}) (Version: 12.0.21005.1 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation) Microsoft Visual Studio Express 2013 for Windows Desktop - ENU with Update 4 (HKLM-x32\...\{b8a9dbc1-1fd4-4103-a83b-a2896f193ea0}) (Version: 12.0.31101.0 - Microsoft Corporation) Microsoft XNA Framework Redistributable 3.1 (HKLM-x32\...\{19BFDA5D-1FE2-4F25-97F9-1A79DD04EE20}) (Version: 3.1.10527.0 - Microsoft Corporation) Microsoft XNA Framework Redistributable 4.0 (HKLM-x32\...\{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}) (Version: 4.0.20823.0 - Microsoft Corporation) Mozilla Firefox 35.0.1 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 35.0.1 (x86 en-US)) (Version: 35.0.1 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 35.0.1 - Mozilla) NEC Electronics USB 3.0 Host Controller Driver (HKLM-x32\...\InstallShield_{D7BF9739-8A68-4335-BBEE-37752AD9E86B}) (Version: 1.0.19.0 - NEC Electronics Corporation) NEC Electronics USB 3.0 Host Controller Driver (x32 Version: 1.0.19.0 - NEC Electronics Corporation) Hidden Notepad++ (HKLM-x32\...\Notepad++) (Version: 6.7.4 - Notepad++ Team) NVIDIA PhysX (HKLM-x32\...\{8B922CF8-8A6C-41CE-A858-F1755D7F5D29}) (Version: 9.12.1031 - NVIDIA Corporation) Origin (HKLM-x32\...\Origin) (Version: 9.5.12.2862 - Electronic Arts, Inc.) paint.net (HKLM\...\{19BD2C33-16A8-4ED1-B9EA-D9E35B21EC42}) (Version: 4.0.5 - dotPDN LLC) Platform (x32 Version: 1.34 - VIA Technologies, Inc.) Hidden PowreShellIntegration.Notifications (x32 Version: 2.5.21003.1603 - Microsoft Corporation) Hidden Prerequisites for SSDT (HKLM-x32\...\{21373064-AD95-48DB-A32E-0D9E08EF7355}) (Version: 12.0.2000.8 - Microsoft Corporation) Prerequisites for SSDT (HKLM-x32\...\{35C1D9D6-87C0-46A3-B1B4-EDBCC063221C}) (Version: 11.1.3000.0 - Microsoft Corporation) Python Tools Redirection Template (x32 Version: 1.1 - Microsoft Corporation) Hidden RAPID Mode (Version: 1.0.1.81 - Samsung Electronics Co., Ltd.) Hidden Samsung Magician (HKLM-x32\...\{29AE3F9F-7158-4ca7-B1ED-28A73ECDB215}_is1) (Version: 4.5.1 - Samsung Electronics) Skype™ 7.3 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.3.101 - Skype Technologies S.A.) Spotify (HKU\S-1-5-21-3750936097-2468696251-2832417832-1000\...\Spotify) (Version: 0.9.15.27.g87efe634 - Spotify AB) Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation) Team Explorer for Microsoft Visual Studio 2013 (x32 Version: 12.0.21005 - Microsoft Corporation) Hidden TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.16 - TeamSpeak Systems GmbH) Titanfall™ (HKLM-x32\...\{347EE0C3-0690-48F6-A231-53853C2A80D6}) (Version: 1.0.10.1 - Electronic Arts) TypeScript Power Tool (x32 Version: 1.0.5.0 - Microsoft Corporation) Hidden TypeScript Tools for Microsoft Visual Studio 2013 (x32 Version: 1.0.5.0 - Microsoft Corporation) Hidden Update for (KB2504637) (HKLM-x32\...\{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}.KB2504637) (Version: 1 - Microsoft Corporation) VIA Platform Device Manager (HKLM-x32\...\InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}) (Version: 1.34 - VIA Technologies, Inc.) Visual Studio 2013 Update 4 (KB2829760) (HKLM-x32\...\{53d408db-eb91-43fb-9d8f-167681c19763}) (Version: 12.0.31101 - Microsoft Corporation) VLC media player (HKLM-x32\...\VLC media player) (Version: 2.1.5 - VideoLAN) VS Update core components (x32 Version: 12.0.31101 - Microsoft Corporation) Hidden XAMPP (HKLM-x32\...\xampp) (Version: 5.6.8-0 - Bitnami) XCOM - Enemy Unknown. The Complete Edition (HKLM-x32\...\XCOM - Enemy Unknown. The Complete Edition_R.G. Mechanics_is1) (Version: - R.G. Mechanics, markfiter) ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) CustomCLSID: HKU\S-1-5-21-3750936097-2468696251-2832417832-1000_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Dominik\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-3750936097-2468696251-2832417832-1000_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\Dominik\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-3750936097-2468696251-2832417832-1000_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Dominik\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-3750936097-2468696251-2832417832-1000_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Dominik\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-3750936097-2468696251-2832417832-1000_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Dominik\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-3750936097-2468696251-2832417832-1000_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Dominik\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-3750936097-2468696251-2832417832-1000_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Dominik\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-3750936097-2468696251-2832417832-1000_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Dominik\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-3750936097-2468696251-2832417832-1000_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Dominik\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.) CustomCLSID: HKU\S-1-5-21-3750936097-2468696251-2832417832-1000_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Dominik\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.) ==================== Restore Points ========================= ATTENTION: System Restore is disabled. ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-13 23:34 - 2009-06-10 18:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {0E01AFBE-4D47-4547-8841-7F6A59629343} - System32\Tasks\COMODO\COMODO Autostart {D5EFF3B3-E126-4AF6-BCE9-852A72129E10} => C:\Program Files\COMODO\COMODO Internet Security\cistray.exe [2015-04-21] (COMODO) Task: {18938A5E-FFDD-4EE4-8972-E8C8835797F6} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-01-08] (Google Inc.) Task: {1E3727F2-1F8F-4189-914B-2AC163B44512} - System32\Tasks\COMODO\COMODO Signature Update {B9D5C6F9-17D2-4917-8BD0-614BAA1C6A59} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [2015-04-21] (COMODO) Task: {2042D4F9-C8D5-4FF0-8331-20C58824C593} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-03-07] (Adobe Systems Incorporated) Task: {426E9DF0-1DC3-4146-9C47-B996F90F54D2} - System32\Tasks\ASUS\RunDAOD => C:\Windows\DAODx.exe [2009-03-30] () Task: {4D64FDE5-408D-4AA7-BBC6-3322455E640B} - System32\Tasks\Microsoft\Windows\Setup\gwx\runappraiser => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-04-23] (Microsoft Corporation) Task: {68613279-206C-422B-978C-E184309AF9E2} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-12-12] (Piriform Ltd) Task: {820BBD60-DC55-4B7F-ADE5-D82F45FA1387} - System32\Tasks\COMODO\COMODO Cache Builder {0FB77674-7905-4F34-A362-C5A9A26F8CF9} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [2015-04-21] (COMODO) Task: {8EA8BC5B-267C-4B33-8324-796391112BC7} - System32\Tasks\COMODO\COMODO Update {A6D52E4F-569B-4756-B3D8-DF217313DA85} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [2015-04-21] (COMODO) Task: {BA095D18-3E39-4CD9-88EB-1F6E2A2AC014} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-01-08] (Google Inc.) Task: {BB7F7957-7F7A-43CA-B6B0-BFFAA6EA9B63} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-04-25] (Adobe Systems Incorporated) Task: {C3697762-EF9D-4681-970E-2F7D2826F51F} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxcontent => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-04-23] (Microsoft Corporation) Task: {CD96B834-A177-4070-9BC4-CC9AFF74AA98} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-04-23] (Microsoft Corporation) Task: {DEFC2D0D-9AA3-423F-A11F-333B7F93758A} - System32\Tasks\COMODO\COMODO Scan {F140D794-60B6-4F00-9235-D6457AA25B22} => C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe [2015-04-21] (COMODO) Task: {F16D4020-F15D-4403-8942-F8B71BE7837A} - System32\Tasks\SamsungMagician => C:\Program Files (x86)\Samsung\Samsung Magician\Samsung Magician.exe [2014-09-28] (Samsung Electronics.) Task: {F933F14C-5566-4A2A-8BA9-E8F28B799532} - System32\Tasks\Microsoft\Windows\Setup\gwx\launchtrayprocess => C:\Windows\system32\GWX\GWX.exe [2015-04-23] (Microsoft Corporation) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============== 2015-03-21 10:54 - 2015-03-21 10:54 - 10958848 _____ () C:\Program Files (x86)\EasyPHP-Webserver-14.1b2\binaries\dbserver\bin\ews-mysqld.exe 2014-05-12 06:49 - 2014-05-12 06:49 - 00222720 _____ () C:\Program Files (x86)\Notepad++\NppShell_06.dll 2009-03-30 11:32 - 2009-03-30 11:32 - 00032768 ____R () C:\Windows\DAODx.exe 2014-09-18 04:23 - 2014-09-18 04:23 - 00866584 _____ () C:\Program Files\Logitech Gaming Software\libGLESv2.dll 2014-10-14 15:51 - 2014-10-14 15:51 - 01050904 _____ () C:\Program Files\Logitech Gaming Software\platforms\qwindows.dll 2014-09-18 04:23 - 2014-09-18 04:23 - 00059160 _____ () C:\Program Files\Logitech Gaming Software\libEGL.dll 2014-10-14 15:51 - 2014-10-14 15:51 - 00242456 _____ () C:\Program Files\Logitech Gaming Software\imageformats\qjpeg.dll 2013-04-15 16:39 - 2015-01-08 19:02 - 00067808 _____ () C:\Program Files\COMODO\COMODO Internet Security\scanners\smart.cav 2015-04-24 15:52 - 2015-03-25 14:51 - 11045376 _____ () c:\xampp\mysql\bin\mysqld.exe 2015-04-24 15:52 - 2013-06-17 08:42 - 02569216 _____ () C:\xampp\xampp-control.exe 2015-01-08 14:39 - 2015-03-27 21:26 - 00775680 _____ () C:\Program Files (x86)\Steam\SDL2.dll 2015-01-19 17:13 - 2014-12-01 21:29 - 05002752 _____ () C:\Program Files (x86)\Steam\v8.dll 2015-01-19 17:13 - 2014-12-01 21:29 - 01612800 _____ () C:\Program Files (x86)\Steam\icui18n.dll 2015-01-19 17:13 - 2014-12-01 21:29 - 01210368 _____ () C:\Program Files (x86)\Steam\icuuc.dll 2015-01-08 14:39 - 2015-04-17 20:49 - 02371776 _____ () C:\Program Files (x86)\Steam\video.dll 2015-01-08 14:39 - 2014-12-01 18:31 - 02396672 _____ () C:\Program Files (x86)\Steam\libavcodec-56.dll 2015-01-08 14:39 - 2014-12-01 18:31 - 00442880 _____ () C:\Program Files (x86)\Steam\libavutil-54.dll 2015-01-08 14:39 - 2014-12-01 18:31 - 00479744 _____ () C:\Program Files (x86)\Steam\libavformat-56.dll 2015-01-08 14:39 - 2014-12-01 18:31 - 00332800 _____ () C:\Program Files (x86)\Steam\libavresample-2.dll 2015-01-08 14:39 - 2014-12-01 18:31 - 00485888 _____ () C:\Program Files (x86)\Steam\libswscale-3.dll 2015-01-08 14:39 - 2015-04-17 20:49 - 00702656 _____ () C:\Program Files (x86)\Steam\bin\chromehtml.DLL 2015-01-08 14:39 - 2015-03-27 21:26 - 34641288 _____ () C:\Program Files (x86)\Steam\bin\libcef.dll 2015-04-25 14:29 - 2015-04-25 14:29 - 00043008 _____ () c:\users\dominik\appdata\local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpjwcsub.dll 2015-03-04 18:45 - 2015-03-04 18:45 - 00750080 _____ () C:\Users\Dominik\AppData\Roaming\Dropbox\bin\libGLESv2.dll 2015-03-04 18:45 - 2015-03-04 18:45 - 00047616 _____ () C:\Users\Dominik\AppData\Roaming\Dropbox\bin\libEGL.dll 2015-03-04 18:45 - 2015-03-04 18:45 - 00865280 _____ () C:\Users\Dominik\AppData\Roaming\Dropbox\bin\plugins\platforms\qwindows.dll 2015-03-04 18:45 - 2015-03-04 18:45 - 00200704 _____ () C:\Users\Dominik\AppData\Roaming\Dropbox\bin\plugins\imageformats\qjpeg.dll 2015-01-08 13:04 - 2014-09-28 16:59 - 00019872 _____ () C:\Program Files (x86)\Samsung\Samsung Magician\SAMSUNG_SSD.dll 2015-01-08 14:39 - 2015-03-27 21:26 - 01709960 _____ () C:\Program Files (x86)\Steam\bin\ffmpegsumo.dll 2015-04-11 20:49 - 2015-04-11 20:49 - 01007104 _____ () C:\Program Files (x86)\Origin\platforms\qwindows.dll 2015-04-11 20:49 - 2015-04-11 20:49 - 00023552 _____ () C:\Program Files (x86)\Origin\imageformats\qgif.dll 2015-04-11 20:49 - 2015-04-11 20:49 - 00024576 _____ () C:\Program Files (x86)\Origin\imageformats\qico.dll 2015-04-11 20:49 - 2015-04-11 20:49 - 00216576 _____ () C:\Program Files (x86)\Origin\imageformats\qjpeg.dll 2015-04-11 20:49 - 2015-04-11 20:49 - 00261120 _____ () C:\Program Files (x86)\Origin\imageformats\qmng.dll 2015-04-11 20:49 - 2015-04-11 20:49 - 00019456 _____ () C:\Program Files (x86)\Origin\imageformats\qtga.dll 2015-04-11 20:49 - 2015-04-11 20:49 - 00337408 _____ () C:\Program Files (x86)\Origin\imageformats\qtiff.dll 2015-04-11 20:49 - 2015-04-11 20:49 - 00018944 _____ () C:\Program Files (x86)\Origin\imageformats\qwbmp.dll 2015-04-11 20:49 - 2015-04-11 20:49 - 00228352 _____ () C:\Program Files (x86)\Origin\mediaservice\wmfengine.dll 2015-04-17 21:17 - 2015-04-13 18:55 - 01252680 _____ () C:\Program Files (x86)\Google\Chrome\Application\42.0.2311.90\libglesv2.dll 2015-04-17 21:17 - 2015-04-13 18:55 - 00080712 _____ () C:\Program Files (x86)\Google\Chrome\Application\42.0.2311.90\libegl.dll 2015-04-24 15:52 - 2015-01-28 13:04 - 00404480 _____ () c:\xampp\apache\bin\pcre.dll 2015-04-24 15:53 - 2015-04-15 19:30 - 00129536 _____ () C:\xampp\php\libpq.dll 2015-04-24 15:52 - 2015-04-15 19:30 - 00166912 _____ () c:\xampp\apache\bin\libssh2.dll 2015-04-24 15:52 - 2015-01-28 13:04 - 00404480 _____ () C:\xampp\apache\bin\pcre.dll 2015-04-24 15:52 - 2015-04-15 19:30 - 00166912 _____ () C:\xampp\apache\bin\libssh2.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 00113171 _____ () C:\Program Files (x86)\VideoLAN\VLC\libvlc.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 02396691 _____ () C:\Program Files (x86)\VideoLAN\VLC\libvlccore.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 00268307 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\access\libdshow_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 00027667 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\audio_output\libdirectsound_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 00031251 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\audio_output\libwaveout_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 11148307 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\gui\libqt4_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 01248787 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\misc\libxml_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 00066579 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\video_output\libdirectdraw_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 02043411 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\access\liblibbluray_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 00100371 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\access\libaccess_bd_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 00244243 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\access\libdvdnav_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 00076307 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\access\libaccess_vdr_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 00045587 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\access\libfilesystem_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 00060947 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\stream_filter\libsmooth_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 00531475 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\stream_filter\libhttplive_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 00708627 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\stream_filter\libdash_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 00114195 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\access\libzip_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 00040467 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\access\libstream_filter_rar_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 00014867 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\stream_filter\librecord_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 00133139 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\demux\libplaylist_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 01512467 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\meta_engine\libtaglib_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 00296979 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\lua\liblua_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 00054291 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\control\libhotkeys_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 00036371 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\meta_engine\libfolder_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 00038419 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\control\libglobalhotkeys_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 00189971 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\demux\libmp4_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 00091667 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\demux\libavi_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 00067603 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\demux\libasf_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 00077331 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\demux\libflacsys_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 00025619 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\demux\libes_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 00074259 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\demux\libmpc_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 00016403 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\demux\libtta_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 00023059 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\demux\libnuv_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 00021523 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\demux\libwav_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 00929299 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\demux\libsid_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 00118803 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\services_discovery\libsap_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 00144403 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\demux\libogg_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 01194003 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\demux\libmkv_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 00015379 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\demux\libdirac_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 00707603 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\access\liblive555_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 00019987 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\demux\libsmf_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 00018451 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\demux\libpva_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 00014355 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\demux\libxa_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 00017427 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\demux\libaiff_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 00018451 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\demux\libvoc_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 00015891 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\demux\libau_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 00417811 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\demux\libgme_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 00019987 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\demux\librawvid_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 00023059 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\demux\libimage_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 00018963 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\demux\libnsv_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 00525331 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\demux\libmod_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 00127507 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\demux\libts_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 00292371 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libpng_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 00017939 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libcdg_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 01280019 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libschroedinger_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 00018451 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libdts_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 00336403 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libtheora_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 00344595 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libfaad_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 00016403 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\librawvideo_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 00146451 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libspeex_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 00733203 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libvorbis_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 00015891 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libaes3_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 00022035 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\liblpcm_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 00021523 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\packetizer\libpacketizer_flac_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 00030739 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\packetizer\libpacketizer_dirac_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 00021011 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\packetizer\libpacketizer_mlp_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 00063507 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\packetizer\libpacketizer_mpeg4audio_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 00198675 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libflac_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 00027155 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libg711_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 01393171 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\liblibass_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 00018963 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libmpeg_audio_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 00026131 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libaraw_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 00171027 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libopus_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 00019475 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\liba52_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 00019987 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libspudec_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 10447379 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libavcodec_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 00036883 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\packetizer\libpacketizer_vc1_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 00017427 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libsvcdsub_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 00025619 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\packetizer\libpacketizer_mpeg4video_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 00024595 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\packetizer\libpacketizer_mpegvideo_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 00018963 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\codec\libcvdsub_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 00064531 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\packetizer\libpacketizer_h264_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 00746515 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\text_renderer\libfreetype_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 00026643 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\sse2\libi420_yuy2_sse2_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 00019987 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\mmx\libi420_yuy2_mmx_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 00587283 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\video_filter\libswscale_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 00113683 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\sse2\libi420_rgb_sse2_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 00027667 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\sse2\libi422_yuy2_sse2_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 00019987 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\mmx\libi422_yuy2_mmx_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 00053779 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\mmx\libi420_rgb_mmx_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 00016915 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\video_chroma\libyuy2_i422_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 00015379 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\video_chroma\libgrey_yuv_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 00032275 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\video_chroma\libi420_rgb_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 00018963 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\video_chroma\libi420_yuy2_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 00020499 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\video_chroma\libyuy2_i420_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 00017427 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\video_chroma\libi422_yuy2_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 00015379 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\video_chroma\libi422_i420_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 00015379 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\video_filter\libscale_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 00013843 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\audio_mixer\libfloat_mixer_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 00013843 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\video_filter\libyuvp_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 00018963 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\audio_filter\libscaletempo_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 01496083 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\audio_filter\libsamplerate_plugin.dll 2014-07-22 20:29 - 2014-07-22 20:29 - 00068115 _____ () C:\Program Files (x86)\VideoLAN\VLC\plugins\video_output\libdirect3d_plugin.dll 2015-04-17 21:17 - 2015-04-13 18:55 - 14980424 _____ () C:\Program Files (x86)\Google\Chrome\Application\42.0.2311.90\PepperFlash\pepflashplayer.dll ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) AlternateDataStreams: C:\Windows\system32\acmigration.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\adtschema.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\aeinv.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\aepdu.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\aepic.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\aitstatic.exe:$CmdTcID AlternateDataStreams: C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\apisetschema.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\appraiser.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\auditpol.exe:$CmdTcID AlternateDataStreams: C:\Windows\system32\clfs.sys:$CmdTcID AlternateDataStreams: C:\Windows\system32\clfsw32.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\conhost.exe:$CmdTcID AlternateDataStreams: C:\Windows\system32\credssp.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\csrsrv.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\D3DCompiler_33.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\D3DCompiler_34.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\D3DCompiler_35.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\D3DCompiler_36.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\D3DCompiler_37.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\D3DCompiler_38.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\D3DCompiler_39.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\D3DCompiler_40.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\D3DCompiler_41.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\D3DCompiler_42.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\D3DCompiler_43.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\d3dcsx_42.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\d3dcsx_43.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\d3dx10.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\d3dx10_33.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\d3dx10_34.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\d3dx10_35.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\d3dx10_36.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\d3dx10_37.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\d3dx10_38.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\d3dx10_39.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\d3dx10_40.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\d3dx10_41.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\d3dx10_42.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\d3dx10_43.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\d3dx11_42.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\d3dx11_43.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\d3dx9_30.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\d3dx9_31.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\d3dx9_32.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\d3dx9_33.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\d3dx9_34.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\d3dx9_35.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\d3dx9_36.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\D3DX9_37.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\D3DX9_38.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\D3DX9_39.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\D3DX9_40.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\D3DX9_41.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\D3DX9_42.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\D3DX9_43.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\devinv.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\dwmapi.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\dwmcore.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\gdi32.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\generaltel.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\invagent.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\kerberos.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\kernel32.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\KernelBase.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\lsasrv.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\lsass.exe:$CmdTcID AlternateDataStreams: C:\Windows\system32\MRT.exe:$CmdTcID AlternateDataStreams: C:\Windows\system32\msaudite.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\msobjs.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\msv1_0.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\msxml3.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\msxml3r.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\ncrypt.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\ntdll.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\ntoskrnl.exe:$CmdTcID AlternateDataStreams: C:\Windows\system32\ntvdm64.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\rstrui.exe:$CmdTcID AlternateDataStreams: C:\Windows\system32\schannel.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\secur32.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\smss.exe:$CmdTcID AlternateDataStreams: C:\Windows\system32\srclient.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\srcore.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\sspicli.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\sspisrv.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\TSpkg.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\wdigest.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\WinSetupUI.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\winsrv.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\wow64.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\wow64cpu.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\wow64win.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\wpdshext.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\wu.upgrade.ps.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\wuapi.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\wuapp.exe:$CmdTcID AlternateDataStreams: C:\Windows\system32\wuauclt.exe:$CmdTcID AlternateDataStreams: C:\Windows\system32\wuaueng.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\wucltux.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\wudriver.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\wups.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\wups2.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\wuwebv.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\x3daudio1_1.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\X3DAudio1_2.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\X3DAudio1_3.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\X3DAudio1_4.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\X3DAudio1_5.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\X3DAudio1_6.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\X3DAudio1_7.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\xactengine2_1.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\xactengine2_10.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\xactengine2_2.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\xactengine2_3.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\xactengine2_4.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\xactengine2_5.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\xactengine2_6.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\xactengine2_7.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\xactengine2_8.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\xactengine2_9.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\xactengine3_0.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\xactengine3_1.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\xactengine3_2.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\xactengine3_3.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\xactengine3_4.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\xactengine3_5.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\xactengine3_6.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\xactengine3_7.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\XAPOFX1_0.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\XAPOFX1_1.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\XAPOFX1_2.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\XAPOFX1_3.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\XAPOFX1_4.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\XAPOFX1_5.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\XAudio2_0.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\XAudio2_1.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\XAudio2_2.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\XAudio2_3.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\XAudio2_4.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\XAudio2_5.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\XAudio2_6.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\XAudio2_7.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\xinput1_1.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\xinput1_2.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\xinput1_3.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\adtschema.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\apisetschema.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\auditpol.exe:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\clfsw32.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\credssp.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\D3DCompiler_33.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\D3DCompiler_34.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\D3DCompiler_35.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\D3DCompiler_36.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\D3DCompiler_37.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\D3DCompiler_38.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\D3DCompiler_39.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\D3DCompiler_40.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\D3DCompiler_41.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\D3DCompiler_42.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\D3DCompiler_43.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\d3dcsx_42.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\d3dcsx_43.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\d3dx10.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\d3dx10_33.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\d3dx10_34.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\d3dx10_35.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\d3dx10_36.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\d3dx10_37.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\d3dx10_38.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\d3dx10_39.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\d3dx10_40.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\d3dx10_41.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\d3dx10_42.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\d3dx10_43.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\d3dx11_42.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\d3dx11_43.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\d3dx9_24.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\d3dx9_25.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\d3dx9_26.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\d3dx9_27.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\d3dx9_28.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\d3dx9_29.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\d3dx9_30.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\d3dx9_31.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\d3dx9_32.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\d3dx9_33.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\d3dx9_34.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\d3dx9_35.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\d3dx9_36.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\D3DX9_37.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\D3DX9_38.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\D3DX9_39.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\D3DX9_40.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\D3DX9_41.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\D3DX9_42.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\D3DX9_43.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\dwmapi.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\dwmcore.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\gdi32.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\instnm.exe:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\kerberos.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\kernel32.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\KernelBase.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\msaudite.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\msobjs.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\msv1_0.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\msxml3.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\msxml3r.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\ncrypt.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\ntdll.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\ntkrnlpa.exe:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\ntoskrnl.exe:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\ntvdm64.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\schannel.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\secur32.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\setup16.exe:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\srclient.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\sspicli.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\TSpkg.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\user.exe:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\wdigest.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\wow32.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\wpdshext.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\wuapi.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\wuapp.exe:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\wudriver.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\wups.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\wuwebv.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\x3daudio1_0.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\x3daudio1_1.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\X3DAudio1_2.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\X3DAudio1_3.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\X3DAudio1_4.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\X3DAudio1_5.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\X3DAudio1_6.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\X3DAudio1_7.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\xactengine2_0.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\xactengine2_1.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\xactengine2_10.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\xactengine2_2.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\xactengine2_3.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\xactengine2_4.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\xactengine2_5.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\xactengine2_6.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\xactengine2_7.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\xactengine2_8.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\xactengine2_9.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\xactengine3_0.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\xactengine3_1.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\xactengine3_2.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\xactengine3_3.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\xactengine3_4.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\xactengine3_5.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\xactengine3_6.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\xactengine3_7.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\XAPOFX1_0.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\XAPOFX1_1.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\XAPOFX1_2.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\XAPOFX1_3.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\XAPOFX1_4.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\XAPOFX1_5.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\XAudio2_0.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\XAudio2_1.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\XAudio2_2.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\XAudio2_3.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\XAudio2_4.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\XAudio2_5.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\XAudio2_6.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\XAudio2_7.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\xinput1_1.dll:$CmdTcID AlternateDataStreams: C:\Windows\SysWOW64\xinput1_2.dll:$CmdTcID AlternateDataStreams: C:\Windows\system32\Drivers\http.sys:$CmdTcID AlternateDataStreams: C:\Windows\system32\Drivers\ksecdd.sys:$CmdTcID AlternateDataStreams: C:\Windows\system32\Drivers\ksecpkg.sys:$CmdTcID AlternateDataStreams: C:\Users\Dominik\Desktop\FRST64.exe:$CmdTcID AlternateDataStreams: C:\Users\Dominik\Desktop\FRST64.exe:$CmdZnID AlternateDataStreams: C:\Users\Dominik\Downloads\flashplayer17_ha_install.exe:$CmdZnID ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (whitelisted) =============== (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, the associated entry will be removed from the registry.) ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-3750936097-2468696251-2832417832-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Dominik\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: 192.168.1.1 ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) MSCONFIG\Services: Bonjour Service => 2 MSCONFIG\Services: SkypeUpdate => 2 MSCONFIG\Services: TunnelBearMaintenance => 3 MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== System errors: ============= Microsoft Office Sessions: ========================= CodeIntegrity Errors: =================================== Date: 2015-02-15 15:38:06.459 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\ELAMBKUP\klelam.sys because the set of per-page image hashes could not be found on the system. Date: 2015-02-15 15:38:06.459 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\ELAMBKUP\klelam.sys because the set of per-page image hashes could not be found on the system. Date: 2015-02-15 15:38:06.459 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\ELAMBKUP\klelam.sys because the set of per-page image hashes could not be found on the system. Date: 2015-02-15 15:38:06.459 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.1\KLELAMX64\klelam.sys because the set of per-page image hashes could not be found on the system. Date: 2015-02-15 15:38:06.459 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.1\KLELAMX64\klelam.sys because the set of per-page image hashes could not be found on the system. Date: 2015-02-15 15:38:06.443 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.1\KLELAMX64\klelam.sys because the set of per-page image hashes could not be found on the system. Date: 2015-02-11 20:34:46.050 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\ELAMBKUP\klelam.sys because the set of per-page image hashes could not be found on the system. Date: 2015-02-11 20:34:46.050 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\ELAMBKUP\klelam.sys because the set of per-page image hashes could not be found on the system. Date: 2015-02-11 20:34:46.050 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Windows\ELAMBKUP\klelam.sys because the set of per-page image hashes could not be found on the system. Date: 2015-02-11 20:34:46.034 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume5\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 15.0.1\KLELAMX64\klelam.sys because the set of per-page image hashes could not be found on the system. ==================== Memory info =========================== Processor: AMD Phenom(tm) II X6 1055T Processor Percentage of memory in use: 78% Total physical RAM: 6141.16 MB Available physical RAM: 1295.45 MB Total Pagefile: 23547.35 MB Available Pagefile: 17772.38 MB Total Virtual: 8192 MB Available Virtual: 8191.82 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:209.59 GB) (Free:80.51 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive e: (Virtual Memory Disk) (Fixed) (Total:77.72 GB) (Free:61.59 GB) NTFS Drive f: () (Fixed) (Total:292.97 GB) (Free:15.35 GB) NTFS Drive g: (Anime and Backups) (Fixed) (Total:244.14 GB) (Free:148.23 GB) NTFS Drive h: () (Fixed) (Total:77.53 GB) (Free:9.65 GB) NTFS Drive i: () (Fixed) (Total:77.53 GB) (Free:56.56 GB) NTFS Drive j: () (Fixed) (Total:172.79 GB) (Free:69.61 GB) NTFS Drive k: () (Fixed) (Total:221.62 GB) (Free:114.27 GB) NTFS Drive l: («D╧M╛N╛K») (Removable) (Total:3.74 GB) (Free:1.35 GB) FAT32 ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 232.9 GB) (Disk ID: 88B9E050) Partition 1: (Not Active) - (Size=77.7 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=77.5 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=77.5 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: C44D50A3) Partition 1: (Not Active) - (Size=293 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=172.8 GB) - (Type=07 NTFS) ======================================================== Disk: 2 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: B50DEA57) Partition 1: (Not Active) - (Size=244.1 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=221.6 GB) - (Type=07 NTFS) ======================================================== Disk: 3 (MBR Code: Windows 7 or 8) (Size: 232.9 GB) (Disk ID: 6BDC8140) Partition 1: (Active) - (Size=209.6 GB) - (Type=07 NTFS) ======================================================== Disk: 4 (Size: 3.7 GB) (Disk ID: B445B445) Partition 1: (Not Active) - (Size=3.7 GB) - (Type=0B) ==================== End Of Log ============================