Okay now when I click on the notice to start antivirus it just takes me to the security center. When I click on Turn On it throws me to System32 like it wants me to find the file for it. So I installed Avast. When I entered my email I think I accidentally signed up for a free trial of their paid services. Doesn't matter to me. I had bad luck with Avast last year but it's been awhile so I don't mind trying them again and I don't mind paying for it if it's good stuff. I just don't want it to interfere with anything here.
My system is still booting slow but I never had the chance to finish the ready boot instructions you posted. Windows Office stopped working a couple days ago. A big thing for me is my DAZ 3d program now takes forever to render. I use Iray which is by Nvidia. It uses the GPU and taps into the CPU if necessary. Well the past two days it's been redlining the CPU and it takes 2 hours to get to 5% on a scene that used to take 20 min. And it's doing it with every scene I've tried thus far, not just one. Normally if I scene becomes too cumbersome, I'll split the elements and render them separately, unfortunately that doesn't help either. So this is quite odd for this program and my system.
Okay here are the new logs:
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:17-10-2015
Ran by kathryn (administrator) on KATHRYNLAPTOP (17-10-2015 18:46:13)
Running from C:\Users\kathr\Desktop
Loaded Profiles: kathryn (Available Profiles: kathryn)
Platform: Windows 10 Pro (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Wacom\WTabletServicePro.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\afwServ.exe
(Microsoft Corporation) C:\Windows\System32\snmptrap.exe
(Microsoft Corporation) C:\Windows\System32\Locator.exe
(SecureMix LLC) C:\Program Files (x86)\GlassWire\GWCtlSrv.exe
(Microsoft Corporation) C:\Windows\System32\vds.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Wacom\Wacom_TabletUser.exe
(Wacom Technology) C:\Program Files\Tablet\Wacom\WacomHost.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Wacom\Wacom_TouchUser.exe
(Wacom Technology, Corp.) C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(SecureMix LLC) C:\Program Files (x86)\GlassWire\GWIdlMon.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [3348712 2015-10-17] (ELAN Microelectronics Corp.)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [6134544 2015-10-17] (AVAST Software)
HKLM Group Policy restriction on software: *.txt*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.divx*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.pub*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.txt*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.divx*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.divx*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.txt*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.avi*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.gif*.jse <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*.js <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*\*.bat <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %programfiles%\*\svchost.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.com <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.docx*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.doc*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.divx*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.jse <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.doc*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.com <====== ATTENTION
HKLM Group Policy restriction on software: C:\Users\*.jse <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.com <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.bat <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.gif*.js <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.js <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.txt*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.pub*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.bat <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.bat <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.avi*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.avi*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.jse <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.doc*.jse <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.wav*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.wav*.com <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.gif*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.pub*.bat <====== ATTENTION
HKLM Group Policy restriction on software: C:\Users\*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.docx*.js <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.com <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.docx*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: %programdata%\*.js <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.rar*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.com <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.com <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*\*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.com <====== ATTENTION
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.png*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.wma*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.rar*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.divx*.jse <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.xls*.com <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.png*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.exe <====== ATTENTION
HKLM Group Policy restriction on software: C:\Users\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.wav*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.js <====== ATTENTION
HKLM Group Policy restriction on software: %programdata%\*\svchost.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.7z*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.png*.bat <====== ATTENTION
HKLM Group Policy restriction on software: C:\Users\*.js <====== ATTENTION
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.7z*.js <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.com <====== ATTENTION
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.txt*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.xls*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.7z*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.zip*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.wav*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.rar*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.pub*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.7z*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.xls*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.gif*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.com <====== ATTENTION
HKLM Group Policy restriction on software: ** <====== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.wav*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*\*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.wav*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.txt*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.doc*.com <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.pub*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: %systemdrive%\*\svchost.exe <====== ATTENTION
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.js <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*\*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*\*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.rar*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.js <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.docx*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.pub*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.pub*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.avi*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.png*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.jse <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: lsassw86s.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.gif*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.com <====== ATTENTION
HKLM Group Policy restriction on software: %programfiles(x86)%\*\svchost.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.png*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.gif*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: %programdata%\*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.xls*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.zip*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.avi*.jse <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.rar*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.docx*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.doc*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.com <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.divx*.pif <====== ATTENTION
HKLM Group Policy restriction on software: C:\Users\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: vssadmin.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.txt*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: %programdata%\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.png*.jse <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Appdata\Roaming\Microsoft\Windows\IEUpdate\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.7z*.com <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.bat <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.doc*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.wav*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.js <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.bat <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.jse <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.7z*.jse <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.gif*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.divx*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.xls*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.rar*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.wma*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.avi*.scr <====== ATTENTION
HKLM Group Policy restriction on software: C:\Users\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.jse <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.rar*.bat <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.zip*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.divx*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.7z*.pif <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.com <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: syskey.exe <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*.com <====== ATTENTION
HKLM Group Policy restriction on software: cipher.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.docx*.jse <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.pub*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.js <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.zip*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.avi*.pif <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.wma*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.zip*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.rar*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.xls*.jse <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.wma*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.wma*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: scsvserv.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.zip*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.doc*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.bat <====== ATTENTION
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %programdata%\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.avi*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.wma*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.doc*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.txt*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.7z*.bat <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.bat <====== ATTENTION
HKLM Group Policy restriction on software: %programdata%\*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.docx*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.gif*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.js <====== ATTENTION
HKLM Group Policy restriction on software: C:\Users\*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.png*.pif <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.bat <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.docx*.com <====== ATTENTION
HKLM Group Policy restriction on software: %programdata%\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.xls*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.wma*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.exe <====== ATTENTION
HKLM Group Policy restriction on software: lsassvrtdbks.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.pif <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.wma*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.zip*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *:\$Recycle.Bin <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.bat <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.js <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.zip*.bat <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.png*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.xls*.bat <====== ATTENTION
HKLM Group Policy restriction on software: %programdata%\*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.pif <====== ATTENTION
HKLM Group Policy restriction on software: %programdata%\*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.wav*.exe <====== ATTENTION
HKLM Group Policy restriction on software: "C:\Program Files (x86)\Google\Chrome\Application\46.0.2490.71\Installer\setup.exe" <====== ATTENTION
HKLM\...\Policies\Explorer: [NoWebServices] 1
HKLM\...\Policies\Explorer: [NoOnlinePrintsWizard] 1
HKU\S-1-5-21-4055827758-3256202687-3425098328-1001\...\Run: [HijackThis startup scan] => C:\Users\kathr\Downloads\HijackThis.exe [388608 2015-10-16] (Trend Micro Inc.)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2015-10-17] (AVAST Software)
AlternateShell:
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Hosts: 127.0.0.1 localhost
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{6e290f83-55f8-4f72-918b-7194d9a47859}: [DhcpNameServer] 192.168.1.1
Internet Explorer:
==================
HKU\S-1-5-21-4055827758-3256202687-3425098328-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/
HKU\S-1-5-21-4055827758-3256202687-3425098328-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/?ocid=iehp
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-10-17] (AVAST Software)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-10-17] (AVAST Software)
Handler: AutorunsDisabled - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2015-10-08] (Microsoft Corporation)
Handler-x32: AutorunsDisabled - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2015-10-08] (Microsoft Corporation)
Handler: AutorunsDisabled - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2015-10-08] (Microsoft Corporation)
Handler-x32: AutorunsDisabled - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2015-10-08] (Microsoft Corporation)
Handler: AutorunsDisabled - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2015-10-08] (Microsoft Corporation)
Handler-x32: AutorunsDisabled - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2015-10-08] (Microsoft Corporation)
Handler: AutorunsDisabled - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2015-10-08] (Microsoft Corporation)
Handler-x32: AutorunsDisabled - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2015-10-08] (Microsoft Corporation)
Handler: tmtbim - {0B37915C-8B98-4B9E-80D4-464D2C830D10} - C:\Program Files\Trend Micro\Titanium\UIFramework\ProToolbarIMRatingActiveX.dll No File
FireFox:
========
FF Plugin: @lastpass.com/NPLastPass -> C:\Program Files (x86)\LastPass\nplastpass64.dll [2015-10-03] (LastPass)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2015-10-08] (Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2015-09-17] (Adobe Systems)
FF Plugin: wacom.com/WacomTabletPlugin -> C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll [No File]
FF Plugin-x32: @lastpass.com/NPLastPass -> C:\Program Files (x86)\LastPass\nplastpass64.dll [2015-10-03] (LastPass)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2015-10-08] (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2015-10-02] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2015-10-02] (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-10-03] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-10-03] (Google Inc.)
FF Plugin-x32: Adobe Acrobat -> C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Air\nppdf32.dll [2015-07-03] (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2015-09-17] (Adobe Systems)
FF Plugin-x32: wacom.com/WacomTabletPlugin -> C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll [No File]
FF HKLM-x32\...\Firefox\Extensions: [
[email protected]] - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn
FF Extension: Adobe Acrobat DC - Create PDF - C:\Program Files (x86)\Adobe\Acrobat DC\Acrobat\Browser\WCFirefoxExtn [2015-10-11] [not signed]
FF HKLM-x32\...\Firefox\Extensions: [
[email protected]] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2015-10-17] [not signed]
Chrome:
=======
CHR HomePage: Default -> hxxp://kathrynloch.deviantart.com/
CHR StartupUrls: Default -> "hxxp://www.google.com/", "hxxp://www.google.com"
CHR NewTab: Default -> "chrome-extension://llaficoajjainaijghjlofdfmbjpebpa/newtab.html"
CHR DefaultSearchKeyword: Default -> lp
CHR Plugin: (Widevine Content Decryption Module) - C:\Users\kathr\AppData\Local\Google\Chrome\User Data\WidevineCDM\1.4.8.824\_platform_specific\win_x64\widevinecdmadapter.dll (Google Inc.)
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\46.0.2490.71\PepperFlash\pepflashplayer.dll ()
CHR Profile: C:\Users\kathr\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (BetterTTV) - C:\Users\kathr\AppData\Local\Google\Chrome\User Data\Default\Extensions\ajopnjidmegmdimjlfnijceegpefgped [2015-10-05]
CHR Extension: (Theme Creator) - C:\Users\kathr\AppData\Local\Google\Chrome\User Data\Default\Extensions\akpelnjfckgfiplcikojhomllgombffc [2015-10-05]
CHR Extension: (Google Docs) - C:\Users\kathr\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-10-02]
CHR Extension: (Google Drive) - C:\Users\kathr\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-02]
CHR Extension: (YouTube) - C:\Users\kathr\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-10-02]
CHR Extension: (Assassin's Creed 4 Black Flag [FVD]) - C:\Users\kathr\AppData\Local\Google\Chrome\User Data\Default\Extensions\bpadpijpfghpinpafnpjlipafpahkahk [2015-10-05]
CHR Extension: (Send to Kindle for Google Chrome) - C:\Users\kathr\AppData\Local\Google\Chrome\User Data\Default\Extensions\cgdjpilhipecahhcilnafpblkieebhea [2015-10-05]
CHR Extension: (Google Search) - C:\Users\kathr\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-02]
CHR Extension: (Logitech Smooth Scrolling) - C:\Users\kathr\AppData\Local\Google\Chrome\User Data\Default\Extensions\dkpejdfnpdkhifgbancbammdijojoffk [2015-10-05]
CHR Extension: (Adobe Acrobat) - C:\Users\kathr\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2015-10-05]
CHR Extension: (Gmail Offline) - C:\Users\kathr\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejidjjhkpiempkbhmpbfngldlkglhimk [2015-10-05]
CHR Extension: (App for Outlook.com) - C:\Users\kathr\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejkanjjdncmgmmmeceedfmncfejmbjef [2015-10-05]
CHR Extension: (Readium) - C:\Users\kathr\AppData\Local\Google\Chrome\User Data\Default\Extensions\fepbnnnkkadjhjahcafoaglimekefifl [2015-10-05]
CHR Extension: (Google Docs Offline) - C:\Users\kathr\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-10-03]
CHR Extension: (Save to Google Drive) - C:\Users\kathr\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmbmikajjgmnabiglmofipeabaddhgne [2015-10-05]
CHR Extension: (Avast Online Security) - C:\Users\kathr\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2015-10-17]
CHR Extension: (LastPass: Free Password Manager) - C:\Users\kathr\AppData\Local\Google\Chrome\User Data\Default\Extensions\hdokiejnpimakedhajhdlcegeplioahd [2015-10-05]
CHR Extension: (Kindle Cloud Reader) - C:\Users\kathr\AppData\Local\Google\Chrome\User Data\Default\Extensions\icdipabjmbhpdkjaihfjoikhjjeneebd [2015-10-05]
CHR Extension: (Dropbox) - C:\Users\kathr\AppData\Local\Google\Chrome\User Data\Default\Extensions\ioekoebejdcmnlefjiknokhhafglcjdl [2015-10-05]
CHR Extension: (EverSync - Sync bookmarks, backup favorites) - C:\Users\kathr\AppData\Local\Google\Chrome\User Data\Default\Extensions\iohcojnlgnfbmjfjfkbhahhmppcggdog [2015-10-05]
CHR Extension: (Booktrack Studio) - C:\Users\kathr\AppData\Local\Google\Chrome\User Data\Default\Extensions\kidknbkmfcapkiepmhchinffchkjglog [2015-10-05]
CHR Extension: (Google Hangouts) - C:\Users\kathr\AppData\Local\Google\Chrome\User Data\Default\Extensions\knipolnnllmklapflnccelgolnpehhpl [2015-10-05]
CHR Extension: (Blogger) - C:\Users\kathr\AppData\Local\Google\Chrome\User Data\Default\Extensions\lejliakmhcfhakneflmicaoikhbicggc [2015-10-05]
CHR Extension: (Speed Dial [FVD] - New Tab Page, 3D, Sync...) - C:\Users\kathr\AppData\Local\Google\Chrome\User Data\Default\Extensions\llaficoajjainaijghjlofdfmbjpebpa [2015-10-05]
CHR Extension: (Google Maps) - C:\Users\kathr\AppData\Local\Google\Chrome\User Data\Default\Extensions\lneaknkopdijkpnocmklfnjbeapigfbh [2015-10-05]
CHR Extension: (Mint) - C:\Users\kathr\AppData\Local\Google\Chrome\User Data\Default\Extensions\mhgffcfekbglhpcdjkhhjekhdnddkflg [2015-10-05]
CHR Extension: (Google Play Books) - C:\Users\kathr\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmimngoggfoobjdlefbcabngfnmieonb [2015-10-05]
CHR Extension: (OneDrive) - C:\Users\kathr\AppData\Local\Google\Chrome\User Data\Default\Extensions\nffchahhjecejoiigmnhhicpoabngedk [2015-10-05]
CHR Extension: (Chrome Web Store Payments) - C:\Users\kathr\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-10-03]
CHR Extension: (Chrome Apps & Extensions Developer Tool) - C:\Users\kathr\AppData\Local\Google\Chrome\User Data\Default\Extensions\ohmmkhmmmpcnpikjeljgnaoabkaalbgc [2015-10-05]
CHR Extension: (KDSPY) - C:\Users\kathr\AppData\Local\Google\Chrome\User Data\Default\Extensions\oocoibgfbhcplhnfdjldohepoeboiloo [2015-10-05]
CHR Extension: (Outlook.com) - C:\Users\kathr\AppData\Local\Google\Chrome\User Data\Default\Extensions\pfpeapihoiogbcmdmnibeplnikfnhoge [2015-10-05]
CHR Extension: (Gmail) - C:\Users\kathr\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-10-02]
CHR HKLM\...\Chrome\Extension: [hdokiejnpimakedhajhdlcegeplioahd] - hxxp://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-10-17]
CHR HKLM-x32\...\Chrome\Extension: [hdokiejnpimakedhajhdlcegeplioahd] - hxxp://clients2.google.com/service/update2/crx
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S4 AdobeUpdateService; C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [669872 2015-09-15] (Adobe Systems Incorporated)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [146600 2015-10-17] (AVAST Software)
R2 avast! Firewall; C:\Program Files\AVAST Software\Avast\afwServ.exe [109008 2015-10-17] (AVAST Software)
R2 GlassWire; C:\Program Files (x86)\GlassWire\GWCtlSrv.exe [8902144 2015-10-07] (SecureMix LLC)
R2 WTabletServicePro; C:\Program Files\Tablet\Wacom\WTabletServicePro.exe [716480 2015-08-21] (Wacom Technology, Corp.)
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [28656 2015-10-17] (AVAST Software)
R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [28144 2015-10-17] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [90968 2015-10-17] (AVAST Software)
R0 aswNdisFlt; C:\Windows\System32\DRIVERS\aswNdisFlt.sys [454528 2015-10-17] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-10-17] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65224 2015-10-17] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1049880 2015-10-17] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [448968 2015-10-17] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [153744 2015-10-17] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [274808 2015-10-17] (AVAST Software)
R1 gwdrv; C:\Windows\system32\DRIVERS\gwdrv.sys [33152 2015-05-28] (SecureMix LLC)
S3 hitmanpro37; C:\WINDOWS\system32\drivers\hitmanpro37.sys [41080 2015-10-16] ()
S3 kbfiltr; C:\Windows\System32\drivers\kbfiltr.sys [17280 2015-10-14] ( )
S4 MEIx64; C:\Windows\System32\drivers\TeeDriverW8x64.sys [193336 2015-10-01] (Intel Corporation)
U3 TrueSight; C:\Windows\System32\drivers\TrueSight.sys [35064 2015-10-16] ()
S4 IntcAzAudAddService; \SystemRoot\system32\drivers\RTKVHD64.sys [X]
S4 keycrypt; system32\DRIVERS\KeyCrypt64.sys [X]
U0 SR; no ImagePath
U2 srservice; no ImagePath
U2 TMAgent; no ImagePath
S4 wfpcapture; \SystemRoot\System32\drivers\wfpcapture.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-10-17 18:09 - 2015-10-17 18:09 - 00016148 _____ C:\WINDOWS\system32\KATHRYNLAPTOP_kathryn_HistoryPrediction.bin
2015-10-17 18:04 - 2015-10-17 18:04 - 00002027 _____ C:\Users\Public\Desktop\Avast SafeZone.lnk
2015-10-17 18:04 - 2015-10-17 18:04 - 00001967 _____ C:\Users\Public\Desktop\Avast Internet Security.lnk
2015-10-17 18:04 - 2015-10-17 18:04 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
2015-10-17 18:04 - 2015-10-17 18:03 - 00028144 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswKbd.sys
2015-10-17 18:03 - 2015-10-17 18:03 - 00454528 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswNdisFlt.sys
2015-10-17 18:03 - 2015-10-17 17:55 - 00378880 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe
2015-10-17 17:56 - 2015-10-17 18:04 - 00004006 _____ C:\WINDOWS\System32\Tasks\avast! Emergency Update
2015-10-17 17:56 - 2015-10-17 17:56 - 00000000 ____D C:\Users\kathr\AppData\Roaming\AVAST Software
2015-10-17 17:55 - 2015-10-17 17:55 - 01049880 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSnx.sys
2015-10-17 17:55 - 2015-10-17 17:55 - 00448968 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSP.sys
2015-10-17 17:55 - 2015-10-17 17:55 - 00274808 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswVmm.sys
2015-10-17 17:55 - 2015-10-17 17:55 - 00153744 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswStm.sys
2015-10-17 17:55 - 2015-10-17 17:55 - 00093528 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr2.sys
2015-10-17 17:55 - 2015-10-17 17:55 - 00090968 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys
2015-10-17 17:55 - 2015-10-17 17:55 - 00065224 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRvrt.sys
2015-10-17 17:55 - 2015-10-17 17:55 - 00043112 _____ (AVAST Software) C:\WINDOWS\avastSS.scr
2015-10-17 17:55 - 2015-10-17 17:55 - 00028656 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswHwid.sys
2015-10-17 17:55 - 2015-10-17 17:55 - 00000000 ____D C:\Program Files\AVAST Software
2015-10-17 17:42 - 2015-10-17 17:42 - 05683632 _____ (AVAST Software) C:\Users\kathr\Desktop\avast_free_antivirus_setup_online.exe
2015-10-17 17:42 - 2015-10-17 17:42 - 00000000 ____D C:\ProgramData\AVAST Software
2015-10-17 10:09 - 2015-10-17 10:09 - 00000000 ____D C:\Program Files\Elantech
2015-10-17 09:44 - 2015-10-17 09:44 - 00038079 _____ C:\Users\kathr\Desktop\Addition.txt
2015-10-17 09:43 - 2015-10-17 18:46 - 00043925 _____ C:\Users\kathr\Desktop\FRST.txt
2015-10-16 19:42 - 2015-10-17 09:42 - 00000000 ____D C:\Users\kathr\Desktop\FRST-OlderVersion
2015-10-16 19:37 - 2015-10-16 19:37 - 00000000 ____D C:\Users\kathr\Downloads\backups
2015-10-16 18:51 - 2015-10-16 18:51 - 00007013 _____ C:\Users\kathr\Downloads\hijackthis.log
2015-10-16 18:50 - 2015-10-16 18:50 - 00388608 _____ (Trend Micro Inc.) C:\Users\kathr\Downloads\HiJackThis.exe
2015-10-16 18:46 - 2015-10-16 18:47 - 169374816 _____ (Trend Micro Inc.) C:\Users\Public\Desktop\TTi_10.0_HE_64bit.exe
2015-10-16 18:46 - 2015-10-16 18:46 - 06630392 _____ (Trend Micro Inc.) C:\Users\kathr\Downloads\TrendMicro_MAX_8.0_US-en_Downloader.exe
2015-10-16 18:38 - 2015-10-16 18:38 - 00000370 _____ C:\Users\kathr\OneDrive\Documents\Viruses.csv
2015-10-16 18:33 - 2015-10-16 18:33 - 00004448 _____ C:\Users\kathr\Desktop\rouguekiller.txt
2015-10-16 18:24 - 2015-10-16 18:43 - 00000000 ____D C:\Users\kathr\AppData\Local\CrashDumps
2015-10-16 18:24 - 2015-10-16 18:33 - 00000000 ____D C:\ProgramData\RogueKiller
2015-10-16 18:24 - 2015-10-16 18:24 - 00035064 _____ C:\WINDOWS\system32\Drivers\TrueSight.sys
2015-10-16 17:04 - 2015-10-16 17:15 - 00929872 _____ (Google Inc.) C:\Users\kathr\Downloads\ChromeSetup.exe
2015-10-16 16:46 - 2015-10-16 16:46 - 00041080 _____ C:\WINDOWS\system32\Drivers\hitmanpro37.sys
2015-10-16 16:18 - 2015-10-17 15:02 - 00000000 ____D C:\Program Files\Trend Micro
2015-10-16 15:24 - 2015-10-16 16:17 - 00003130 _____ C:\Users\kathr\Desktop\gore.txt
2015-10-16 15:21 - 2015-10-16 15:21 - 00001974 _____ C:\Users\kathr\Desktop\GlassWire.lnk
2015-10-16 15:21 - 2015-10-16 15:21 - 00000000 ____D C:\Users\kathr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\GlassWire
2015-10-16 15:21 - 2015-10-16 15:21 - 00000000 ____D C:\Program Files (x86)\GlassWire
2015-10-16 15:21 - 2015-05-28 23:30 - 00008392 _____ C:\WINDOWS\system32\Drivers\gwdrv.cat
2015-10-16 15:21 - 2015-05-28 23:15 - 00033152 _____ (SecureMix LLC) C:\WINDOWS\system32\Drivers\gwdrv.sys
2015-10-16 12:33 - 2015-10-16 12:33 - 09325066 _____ C:\Users\kathr\OneDrive\Documents\SoundofMadnessChorus.wav
2015-10-16 12:33 - 2015-10-16 12:33 - 00291036 _____ C:\Users\kathr\OneDrive\Documents\SoundofMadnessChorus.pkf
2015-10-15 13:34 - 2015-10-15 13:34 - 00002672 _____ C:\Users\kathr\Desktop\Kilt02.jpg - Shortcut.lnk
2015-10-15 13:00 - 2015-10-15 13:00 - 00000000 ____D C:\Users\kathr\AppData\Roaming\WTablet
2015-10-15 12:43 - 2015-10-15 12:43 - 00000000 ____D C:\Users\Public\Pixologic
2015-10-15 12:32 - 2015-10-15 13:44 - 00001267 _____ C:\Users\kathr\Desktop\DAZ Studio 4.8 (64-bit) Public Build +Beta+.lnk
2015-10-15 10:54 - 2015-10-15 10:54 - 00002789 _____ C:\Users\kathr\Desktop\Google Hangouts.lnk
2015-10-14 09:20 - 2015-10-14 09:20 - 00447576 _____ (ELAN Microelectronics Corp.) C:\WINDOWS\system32\Drivers\ETD.sys
2015-10-14 07:59 - 2015-10-14 07:59 - 00000000 ____D C:\Users\kathr\temp
2015-10-14 07:59 - 2015-10-14 07:59 - 00000000 ____D C:\Users\kathr\AppData\Roaming\TeamViewer
2015-10-14 07:54 - 2015-10-14 07:55 - 04079264 _____ (SurfRight B.V.) C:\Users\kathr\Desktop\hmpalert3.exe
2015-10-14 07:53 - 2015-10-14 07:53 - 00722448 _____ (Threatstar B.V.) C:\Users\kathr\Desktop\hmpalert64-test.exe
2015-10-14 07:21 - 2015-10-16 18:39 - 00005196 _____ C:\Users\kathr\Desktop\quarantine.txt
2015-10-14 07:20 - 2015-10-16 18:24 - 18832456 _____ C:\Users\kathr\Desktop\RogueKiller.exe
2015-10-14 07:20 - 2015-10-16 18:23 - 00002806 _____ C:\Users\kathr\Desktop\Rkill.txt
2015-10-14 07:19 - 2015-10-14 07:20 - 02019656 _____ (Bleeping Computer, LLC) C:\Users\kathr\Desktop\rkill.exe
2015-10-14 06:42 - 2015-10-17 09:32 - 00000000 ____D C:\EEK
2015-10-14 06:42 - 2015-10-16 18:20 - 00000784 _____ C:\Users\kathr\Desktop\Start Emsisoft Emergency Kit.lnk
2015-10-14 06:41 - 2015-10-14 06:42 - 168430496 _____ C:\Users\kathr\Desktop\EmsisoftEmergencyKit.exe
2015-10-14 06:26 - 2015-10-14 06:26 - 00002148 _____ C:\Users\kathr\Desktop\VirusTotal Uploader 2.2.lnk
2015-10-14 06:26 - 2015-10-14 06:26 - 00000000 ____D C:\Users\kathr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VirusTotal Uploader 2.2
2015-10-14 06:26 - 2015-10-14 06:26 - 00000000 ____D C:\Program Files (x86)\VirusTotalUploader2
2015-10-14 06:25 - 2015-10-14 06:25 - 00142744 _____ C:\Users\kathr\Desktop\vtuploader2.2.exe
2015-10-14 05:59 - 2015-10-16 20:59 - 00000010 _____ C:\Users\kathr\AppData\Local\sponge.last.runtime.cache
2015-10-14 05:14 - 2015-10-14 05:14 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
2015-10-14 04:53 - 2015-10-15 19:18 - 00000000 ____D C:\Program Files\TabletPlugins
2015-10-14 04:53 - 2015-10-15 19:18 - 00000000 ____D C:\Program Files (x86)\TabletPlugins
2015-10-14 04:53 - 2015-10-14 04:53 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wacom Tablet
2015-10-14 04:53 - 2015-04-28 12:08 - 00103192 _____ (Wacom Technology) C:\WINDOWS\system32\Drivers\wachidrouter.sys
2015-10-14 04:53 - 2015-04-28 12:08 - 00015128 _____ (Wacom Technology) C:\WINDOWS\system32\Drivers\wacomrouterfilter.sys
2015-10-14 04:52 - 2015-10-14 04:53 - 00000000 ____D C:\Program Files\Tablet
2015-10-14 04:52 - 2015-08-21 13:33 - 02090176 _____ (Wacom Technology, Corp.) C:\WINDOWS\system32\WacomMT.dll
2015-10-14 04:52 - 2015-08-21 13:33 - 02064576 _____ (Wacom Technology, Corp.) C:\WINDOWS\system32\Wacom_Tablet.dll
2015-10-14 04:52 - 2015-08-21 13:33 - 02057920 _____ (Wacom Technology, Corp.) C:\WINDOWS\system32\Wacom_Touch_Tablet.dll
2015-10-14 04:52 - 2015-08-21 13:33 - 01928896 _____ (Wacom Technology, Corp.) C:\WINDOWS\system32\Wintab32.dll
2015-10-14 04:52 - 2015-08-21 13:33 - 01674944 _____ (Wacom Technology, Corp.) C:\WINDOWS\SysWOW64\WacomMT.dll
2015-10-14 04:52 - 2015-08-21 13:33 - 01672384 _____ (Wacom Technology, Corp.) C:\WINDOWS\SysWOW64\Wacom_Tablet.dll
2015-10-14 04:52 - 2015-08-21 13:33 - 01664704 _____ (Wacom Technology, Corp.) C:\WINDOWS\SysWOW64\Wacom_Touch_Tablet.dll
2015-10-14 04:52 - 2015-08-21 13:33 - 01545408 _____ (Wacom Technology, Corp.) C:\WINDOWS\SysWOW64\Wintab32.dll
2015-10-14 04:51 - 2015-10-14 04:52 - 82016736 _____ C:\Users\kathr\Desktop\WacomTablet_6.3.14-1.exe
2015-10-14 04:43 - 2015-10-14 04:43 - 00000000 ____D C:\Users\kathr\AppData\Roaming\NVIDIA
2015-10-14 04:09 - 2015-10-14 04:09 - 00003268 _____ C:\WINDOWS\System32\Tasks\{A45DFF4C-AC84-4E0C-A331-3CB2D33F75F1}
2015-10-14 03:55 - 2015-10-17 15:02 - 00000000 ____D C:\Users\kathr\AppData\Roaming\Trend Micro
2015-10-14 03:54 - 2015-10-17 14:11 - 00000000 ____D C:\ProgramData\Trend Micro
2015-10-14 03:53 - 2015-10-17 15:02 - 00000000 ____D C:\ProgramData\TMDP_Log
2015-10-14 03:53 - 2015-10-16 16:28 - 00000000 ____D C:\ProgramData\TMDP_Setup
2015-10-14 03:53 - 2015-10-14 03:53 - 00000036 _____ C:\Users\kathr\AppData\Local\housecall.guid.cache
2015-10-14 03:23 - 2015-10-14 03:23 - 21871440 _____ (SecureMix LLC) C:\Users\kathr\Desktop\GlassWireSetup.exe
2015-10-14 03:19 - 2015-10-17 18:07 - 00000000 ____D C:\ProgramData\NVIDIA
2015-10-14 03:19 - 2015-10-14 03:19 - 00000000 ____D C:\WINDOWS\LastGood.Tmp
2015-10-14 03:19 - 2015-10-02 21:28 - 00102520 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvStreaming.exe
2015-10-14 03:18 - 2015-10-14 03:19 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2015-10-14 03:18 - 2015-10-02 23:58 - 00112760 _____ (Khronos Group) C:\WINDOWS\system32\OpenCL.dll
2015-10-14 03:18 - 2015-10-02 23:58 - 00105264 _____ (Khronos Group) C:\WINDOWS\SysWOW64\OpenCL.dll
2015-10-14 03:18 - 2015-10-02 21:38 - 06358648 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
2015-10-14 03:18 - 2015-10-02 21:38 - 02982704 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc64.dll
2015-10-14 03:18 - 2015-10-02 21:38 - 02554488 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll
2015-10-14 03:18 - 2015-10-02 21:38 - 00938800 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvvsvc.exe
2015-10-14 03:18 - 2015-10-02 21:38 - 00385328 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmctray.dll
2015-10-14 03:18 - 2015-10-02 21:38 - 00062768 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll
2015-10-14 03:18 - 2015-10-01 04:30 - 05284082 _____ C:\WINDOWS\system32\nvcoproc.bin
2015-10-14 03:17 - 2015-10-14 03:17 - 02873112 _____ (Reason Company Software Inc.) C:\Users\kathr\Desktop\herdProtectScan_Setup.exe
2015-10-14 03:17 - 2015-10-14 03:17 - 00001162 _____ C:\Users\Public\Desktop\herdProtect.lnk
2015-10-14 03:17 - 2015-10-06 13:45 - 11210056 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvlddmkm.sys
2015-10-14 03:17 - 2015-10-02 23:58 - 42914096 _____ C:\WINDOWS\system32\nvcompiler.dll
2015-10-14 03:17 - 2015-10-02 23:58 - 37882488 _____ C:\WINDOWS\SysWOW64\nvcompiler.dll
2015-10-14 03:17 - 2015-10-02 23:58 - 22342264 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglv64.dll
2015-10-14 03:17 - 2015-10-02 23:58 - 18387064 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglv32.dll
2015-10-14 03:17 - 2015-10-02 23:58 - 18354984 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvwgf2umx.dll
2015-10-14 03:17 - 2015-10-02 23:58 - 16548768 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvopencl.dll
2015-10-14 03:17 - 2015-10-02 23:58 - 15837152 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvd3dumx.dll
2015-10-14 03:17 - 2015-10-02 23:58 - 15803800 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvwgf2um.dll
2015-10-14 03:17 - 2015-10-02 23:58 - 14841232 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll
2015-10-14 03:17 - 2015-10-02 23:58 - 13525200 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvopencl.dll
2015-10-14 03:17 - 2015-10-02 23:58 - 12868120 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvd3dum.dll
2015-10-14 03:17 - 2015-10-02 23:58 - 12038368 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll
2015-10-14 03:17 - 2015-10-02 23:58 - 03534888 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll
2015-10-14 03:17 - 2015-10-02 23:58 - 03121144 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll
2015-10-14 03:17 - 2015-10-02 23:58 - 02313336 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll
2015-10-14 03:17 - 2015-10-02 23:58 - 01994360 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll
2015-10-14 03:17 - 2015-10-02 23:58 - 01905272 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6435850.dll
2015-10-14 03:17 - 2015-10-02 23:58 - 01564792 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6435850.dll
2015-10-14 03:17 - 2015-10-02 23:58 - 00877176 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll
2015-10-14 03:17 - 2015-10-02 23:58 - 00861816 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll
2015-10-14 03:17 - 2015-10-02 23:58 - 00787200 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncMFTH264.dll
2015-10-14 03:17 - 2015-10-02 23:58 - 00689968 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll
2015-10-14 03:17 - 2015-10-02 23:58 - 00673912 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll
2015-10-14 03:17 - 2015-10-02 23:58 - 00632664 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncMFTH264.dll
2015-10-14 03:17 - 2015-10-02 23:58 - 00414000 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFROpenGL.dll
2015-10-14 03:17 - 2015-10-02 23:58 - 00388048 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll
2015-10-14 03:17 - 2015-10-02 23:58 - 00376112 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvDecMFTMjpeg.dll
2015-10-14 03:17 - 2015-10-02 23:58 - 00369272 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFROpenGL.dll
2015-10-14 03:17 - 2015-10-02 23:58 - 00339064 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvDecMFTMjpeg.dll
2015-10-14 03:17 - 2015-10-02 23:58 - 00315936 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll
2015-10-14 03:17 - 2015-10-02 23:58 - 00204648 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvhda64v.sys
2015-10-14 03:17 - 2015-10-02 23:58 - 00040280 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvhdap64.dll
2015-10-14 03:17 - 2015-10-02 23:58 - 00034392 _____ C:\WINDOWS\system32\nvinfo.pb
2015-10-14 03:15 - 2015-10-17 14:10 - 00000000 ____D C:\Users\kathr\AppData\Local\Trend Micro
2015-10-14 03:13 - 2015-10-14 03:13 - 169370152 _____ (Trend Micro Inc.) C:\Users\Public\Desktop\Trend_Micro.exe
2015-10-14 03:12 - 2015-10-14 03:12 - 06924136 _____ (Trend Micro Inc.) C:\Users\kathr\Desktop\TrendMicro_MAX_10.0_US-en_Downloader.exe
2015-10-14 03:11 - 2015-10-14 03:15 - 303687256 _____ (NVIDIA Corporation) C:\Users\kathr\Desktop\358.50-notebook-win10-64bit-international-whql.exe
2015-10-14 03:10 - 2015-10-14 03:10 - 00003646 _____ C:\WINDOWS\System32\Tasks\ATK Package 36D18D69AFC3
2015-10-14 03:10 - 2015-10-14 03:10 - 00002874 _____ C:\WINDOWS\System32\Tasks\ATK Package A22126881260
2015-10-14 03:10 - 2015-10-14 03:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ASUS
2015-10-14 03:10 - 2015-10-14 03:10 - 00000000 ____D C:\Program Files (x86)\ASUS
2015-10-14 03:08 - 2015-10-14 03:08 - 00000000 ____D C:\Users\kathr\Desktop\ATKPackage_Win10_64_VER100039
2015-10-14 03:07 - 2015-10-14 03:07 - 00000000 ____D C:\Users\kathr\Desktop\KBFilter_Win81_64_VER1005
2015-10-14 03:06 - 2015-10-14 03:06 - 00160580 _____ C:\Users\kathr\Desktop\KBFilter_Win81_64_VER1005.zip
2015-10-14 03:05 - 2015-10-14 03:05 - 12379704 _____ C:\Users\kathr\Desktop\ATKPackage_Win10_64_VER100039.zip
2015-10-14 01:51 - 2015-10-14 01:51 - 00003266 _____ C:\WINDOWS\System32\Tasks\{FAE41C42-E035-4FFE-81B1-F4404DFD0C0F}
2015-10-12 11:13 - 2015-10-12 11:14 - 757922649 _____ C:\Users\kathr\OneDrive\Documents\Historical.zip
2015-10-12 11:12 - 2015-10-12 11:12 - 15543068 _____ C:\Users\kathr\OneDrive\Documents\Last of the desktop.zip
2015-10-12 10:15 - 2015-10-08 23:42 - 303687256 _____ (NVIDIA Corporation) C:\Users\kathr\Desktop\358.50-notebook-win10-64bit-international-whql (2).exe
2015-10-12 10:13 - 2015-10-09 00:00 - 304224616 _____ (NVIDIA Corporation) C:\Users\kathr\Desktop\355.98-notebook-win10-64bit-international-whql (2).exe
2015-10-12 10:13 - 2015-10-08 23:44 - 304583336 _____ (NVIDIA Corporation) C:\Users\kathr\Desktop\355.82-notebook-win10-64bit-international-whql (2).exe
2015-10-12 07:45 - 2015-10-12 07:45 - 04296704 _____ C:\Users\kathr\OneDrive\Documents\demon_laird.indd
2015-10-12 07:45 - 2015-10-12 07:45 - 00011486 _____ C:\2HijackPatrol.log
2015-10-12 06:51 - 2015-10-12 06:52 - 03723264 _____ C:\Users\kathr\OneDrive\Documents\mist warrior.indd
2015-10-11 16:12 - 2015-10-12 10:19 - 00003014 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task
2015-10-11 16:11 - 2015-10-11 16:11 - 00002469 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat DC.lnk
2015-10-11 16:11 - 2015-10-11 16:11 - 00002114 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Acrobat Distiller DC.lnk
2015-10-11 16:11 - 2015-10-11 16:11 - 00002091 _____ C:\Users\Public\Desktop\Adobe Acrobat DC.lnk
2015-10-11 06:08 - 2015-10-11 05:56 - 69420720 _____ C:\Users\kathr\OneDrive\Documents\1011150555.mp4
2015-10-11 06:08 - 2015-10-11 05:55 - 40000723 _____ C:\Users\kathr\OneDrive\Documents\1011150553.mp4
2015-10-11 06:08 - 2015-10-11 05:52 - 05270801 _____ C:\Users\kathr\OneDrive\Documents\1011150551.mp4
2015-10-11 06:08 - 2015-10-11 05:51 - 304524280 _____ C:\Users\kathr\OneDrive\Documents\1011150548.mp4
2015-10-11 06:08 - 2015-10-11 05:47 - 39634706 _____ C:\Users\kathr\OneDrive\Documents\1011150543.mp4
2015-10-11 06:08 - 2015-10-11 05:37 - 10247585 _____ C:\Users\kathr\OneDrive\Documents\1011150537.mp4
2015-10-11 06:08 - 2015-10-11 05:36 - 322664427 _____ C:\Users\kathr\OneDrive\Documents\1011150533.mp4
2015-10-11 06:08 - 2015-10-11 04:25 - 174367577 _____ C:\Users\kathr\OneDrive\Documents\1011150423.mp4
2015-10-11 06:08 - 2015-10-11 04:22 - 519388367 _____ C:\Users\kathr\OneDrive\Documents\1011150417.mp4
2015-10-11 03:08 - 2015-10-11 03:08 - 00150348 _____ C:\Users\kathr\Desktop\DAZStudio_error_report_151011-030815.zip
2015-10-11 03:06 - 2015-10-11 03:06 - 00145074 _____ C:\Users\kathr\Desktop\DAZStudio_error_report_151011-030603.zip
2015-10-11 03:04 - 2015-10-11 03:04 - 00129868 _____ C:\Users\kathr\Desktop\DAZStudio_error_report_151011-030437.zip
2015-10-11 03:00 - 2015-10-11 03:00 - 00120877 _____ C:\Users\kathr\Desktop\DAZStudio_error_report_151011-030036.zip
2015-10-10 19:32 - 2015-10-10 19:23 - 00132745 _____ C:\Users\kathr\Desktop\DAZStudio_error_report_151010-192329.zip
2015-10-09 13:27 - 2015-04-28 12:08 - 00014104 _____ (Windows ® Win 7 DDK provider) C:\WINDOWS\system32\Drivers\hidkmdf.sys
2015-10-09 13:27 - 2012-12-11 17:12 - 01721576 _____ (Microsoft Corporation) C:\WINDOWS\system32\wdfcoinstaller01009.dll
2015-10-09 13:27 - 2012-12-11 17:12 - 01721576 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wdfcoinstaller01009.dll
2015-10-09 13:26 - 2015-10-09 12:10 - 82016736 _____ C:\Users\kathr\Desktop\WacomTablet_6.3.14-1 (2015_09_27 15_29_22 UTC).exe
2015-10-09 11:51 - 2015-10-09 11:51 - 00000000 ____D C:\ProgramData\Apple
2015-10-09 11:49 - 2015-10-09 11:51 - 00000000 ____D C:\Users\kathr\AppData\Local\Western Digital
2015-10-09 11:45 - 2015-10-09 11:45 - 00004398 _____ C:\WINDOWS\DPINST.LOG
2015-10-09 11:44 - 2015-10-09 11:49 - 71601392 _____ C:\Users\kathr\Desktop\mc_windows_setup.exe
2015-10-09 11:44 - 2015-10-09 11:44 - 04341113 _____ C:\Users\kathr\Desktop\WD_Quick_View_Setup_for_Windows.zip
2015-10-09 11:44 - 2015-10-09 11:44 - 00000000 ____D C:\Users\kathr\Desktop\WD_Quick_View_Setup_for_Windows
2015-10-09 11:43 - 2015-10-09 11:50 - 63831744 _____ C:\Users\kathr\Desktop\WDMyCloud_win.exe
2015-10-09 07:28 - 2015-10-12 10:19 - 00002406 _____ C:\WINDOWS\System32\Tasks\RtHDVBg_ListenToDevice
2015-10-09 07:28 - 2015-10-09 07:28 - 00000000 ____H C:\ProgramData\DP45977C.lfl
2015-10-09 07:27 - 2015-10-12 10:28 - 00000000 ____D C:\WINDOWS\SysWOW64\RTCOM
2015-10-09 07:27 - 2015-10-09 07:27 - 00000000 ____D C:\Program Files\Realtek
2015-10-09 05:47 - 2015-10-15 20:47 - 00000000 ____D C:\ProgramData\boost_interprocess
2015-10-09 04:31 - 2015-10-09 04:31 - 00000259 _____ C:\AmazonMusic.log
2015-10-09 04:11 - 2015-10-09 04:11 - 00000000 ____D C:\Users\kathr\Desktop\Audio_Realtek_Win81_64_VER6017304
2015-10-09 04:10 - 2015-10-12 10:19 - 00002516 _____ C:\WINDOWS\System32\Tasks\Amazon Music Helper
2015-10-09 04:10 - 2015-10-09 04:10 - 41261584 _____ (Amazon) C:\Users\kathr\Desktop\Amazon_Music_with_Prime_Music_PC_Download.exe
2015-10-08 23:40 - 2015-10-12 10:42 - 303687256 _____ (NVIDIA Corporation) C:\Users\kathr\Desktop\358.50-notebook-win10-64bit-international-whql (1).exe
2015-10-08 23:40 - 2015-10-08 23:44 - 304583336 _____ (NVIDIA Corporation) C:\Users\kathr\Desktop\355.82-notebook-win10-64bit-international-whql.exe
2015-10-08 23:38 - 2015-10-09 00:00 - 304224616 _____ (NVIDIA Corporation) C:\Users\kathr\Desktop\355.98-notebook-win10-64bit-international-whql.exe
2015-10-08 19:14 - 2015-10-08 19:14 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2015-10-08 17:56 - 2015-10-08 17:58 - 02520048 _____ C:\Users\kathr\OneDrive\Documents\KATHRYNLAPTOP2.arn
2015-10-08 17:19 - 2015-10-08 17:48 - 00002834 _____ C:\WINDOWS\System32\Tasks\AdobeAAMUpdater-1.0-KATHRYNLAPTOP-kathryn
2015-10-08 17:08 - 2015-10-14 02:56 - 00000000 ____D C:\WINDOWS\SysWOW64\Atheros_L1e
2015-10-08 16:40 - 2015-10-08 16:40 - 00000000 ____D C:\$WINDOWS.~BT
2015-10-08 16:13 - 2015-10-08 16:13 - 00000029 _____ C:\Users\kathr\OneDrive\Documents\windows10pro.txt
2015-10-08 16:09 - 2015-10-08 16:09 - 00000000 ___HD C:\$Windows.~WS
2015-10-08 16:07 - 2015-10-08 16:07 - 00000000 ____D C:\Program Files\Common Files\DESIGNER
2015-10-08 16:04 - 2015-10-08 16:04 - 00002451 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Word 2016.lnk
2015-10-08 16:04 - 2015-10-08 16:04 - 00002450 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint 2016.lnk
2015-10-08 16:04 - 2015-10-08 16:04 - 00002414 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Access 2016.lnk
2015-10-08 16:04 - 2015-10-08 16:04 - 00002413 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel 2016.lnk
2015-10-08 16:04 - 2015-10-08 16:04 - 00002407 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook 2016.lnk
2015-10-08 16:04 - 2015-10-08 16:04 - 00002401 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Publisher 2016.lnk
2015-10-08 16:04 - 2015-10-08 16:04 - 00002393 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote 2016.lnk
2015-10-08 16:04 - 2015-10-08 16:04 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2016 Tools
2015-10-08 16:00 - 2015-10-08 16:02 - 00000000 ____D C:\Program Files\Microsoft Office
2015-10-08 16:00 - 2015-10-08 16:00 - 00000000 ____D C:\Program Files\Microsoft Office 15
2015-10-08 15:52 - 2015-10-08 15:52 - 00000357 _____ C:\Users\kathr\AppData\Local\LMIR0001.tmp_r.bat
2015-10-08 15:42 - 2015-10-08 15:54 - 00000000 ____D C:\Users\kathr\AppData\Local\LogMeIn Rescue Applet
2015-10-08 15:09 - 2015-10-08 15:09 - 00024288 _____ C:\WINDOWS\system32\WacDriverDLCoinst.dll
2015-10-07 22:53 - 2015-10-07 22:53 - 00016148 _____ C:\WINDOWS\system32\KATHRYNLAPTOP_kathr_HistoryPrediction.bin
2015-10-07 20:20 - 2015-10-07 20:20 - 00000000 ____D C:\ProgramData\OptiTex
2015-10-07 13:36 - 2015-10-08 17:08 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2015-10-07 13:35 - 2015-10-14 03:19 - 00000000 ____D C:\Temp
2015-10-07 13:35 - 2015-10-09 10:46 - 00000000 ____D C:\Users\kathr\Desktop\CardReader_Genesys_Win81_64_VER4307
2015-10-07 00:17 - 2015-10-17 09:19 - 00010394 _____ C:\HijackPatrol.log
2015-10-06 23:45 - 2015-10-06 23:45 - 00000000 ____D C:\NVIDIA
2015-10-06 23:42 - 2015-10-06 23:42 - 00000000 ____D C:\Users\kathr\Desktop\LAN_QualcommAtheros_Win81_64_VER21021
2015-10-06 23:37 - 2015-10-06 23:37 - 02082460 _____ C:\Users\kathr\Desktop\IRST_Intel_Win81_64_VER12801016.zip
2015-10-06 23:36 - 2015-10-06 23:36 - 09993488 _____ C:\Users\kathr\Desktop\CardReader_Genesys_Win81_64_VER4307.zip
2015-10-06 23:35 - 2015-10-06 23:36 - 128469985 _____ C:\Users\kathr\Desktop\Audio_Realtek_Win81_64_VER6017304.zip
2015-10-06 21:17 - 2015-10-06 21:17 - 00000000 ____D C:\WINDOWS\WICCodecs
2015-10-06 18:53 - 2015-10-10 12:16 - 36438016 _____ C:\WINDOWS\system32\config\components.old
2015-10-06 14:14 - 2015-10-07 17:37 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FastPictureViewer
2015-10-06 13:46 - 2015-10-08 15:57 - 00000000 ____D C:\Program Files (x86)\Microsoft Office
2015-10-06 13:43 - 2015-10-08 17:48 - 00002830 _____ C:\WINDOWS\System32\Tasks\AdobeAAMUpdater-1.0-KATHRYNLAPTOP-kathr
2015-10-06 11:27 - 2015-10-06 11:32 - 00830266 _____ C:\WINDOWS\SysWOW64\PerfStringBackup.INI
2015-10-05 12:47 - 2015-10-05 12:47 - 00000207 _____ C:\WINDOWS\tweaking.com-regbackup-KATHRYNLAPTOP-Windows-10-Pro-(64-bit).dat
2015-10-05 12:47 - 2015-10-05 12:47 - 00000000 ____D C:\RegBackup
2015-10-05 11:56 - 2015-10-08 19:19 - 00000214 _____ C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job
2015-10-05 09:09 - 2015-10-05 09:09 - 00000000 ____D C:\Program Files (x86)\Tweaking.com
2015-10-05 08:58 - 2015-10-14 04:09 - 00000000 ____D C:\ProgramData\InstallMate
2015-10-05 08:58 - 2015-10-06 21:26 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinPatrol
2015-10-05 08:58 - 2015-10-05 09:00 - 00000000 ____D C:\Users\kathr\AppData\Roaming\WinPatrol
2015-10-05 08:58 - 2015-10-05 08:58 - 00000000 ____D C:\Program Files (x86)\Ruiware
2015-10-05 05:15 - 2015-10-07 16:32 - 00000000 ____D C:\Users\kathr\AppData\LocalLow\Adobe
2015-10-05 05:13 - 2015-10-08 17:48 - 00002872 _____ C:\WINDOWS\System32\Tasks\
[email protected]
2015-10-05 04:24 - 2015-10-05 04:24 - 00000000 ____D C:\Users\kathr\AppData\Local\AntiLogger Free
2015-10-05 03:37 - 2015-10-05 03:37 - 00034328 _____ (Sysinternals - www.sysinternals.com) C:\WINDOWS\system32\Drivers\PROCEXP152.SYS
2015-10-05 03:37 - 2015-10-05 03:37 - 00000000 ____D C:\Users\kathr\Desktop\ProcessExplorer
2015-10-05 01:36 - 2015-10-05 01:37 - 74520472 _____ (Logitech, Inc.) C:\Users\kathr\Downloads\lws280.exe
2015-10-05 01:26 - 2015-10-12 10:41 - 00587682 _____ C:\Users\kathr\OneDrive\Documents\KATHRYNLAPTOP.arn
2015-10-05 00:19 - 2015-10-05 00:19 - 00001118 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Audition CC 2015.lnk
2015-10-05 00:03 - 2015-10-05 00:03 - 00001073 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe InDesign CC 2015.lnk
2015-10-04 23:48 - 2015-10-16 12:27 - 00000000 ____D C:\Users\kathr\OneDrive\Documents\Adobe
2015-10-04 23:48 - 2015-10-05 05:13 - 00000000 ____D C:\ProgramData\regid.1986-12.com.adobe
2015-10-04 23:48 - 2015-10-04 23:48 - 00001085 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CC 2015.lnk
2015-10-04 23:44 - 2015-10-11 15:53 - 00000000 ____D C:\Program Files\Common Files\Adobe
2015-10-04 23:44 - 2015-10-05 00:19 - 00000000 ____D C:\Program Files\Adobe
2015-10-04 23:36 - 2015-10-14 07:06 - 00000000 ___RD C:\Users\kathr\Creative Cloud Files
2015-10-04 23:34 - 2015-10-04 23:34 - 00001302 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Creative Cloud.lnk
2015-10-04 23:34 - 2015-10-04 23:34 - 00001290 _____ C:\Users\Public\Desktop\Adobe Creative Cloud.lnk
2015-10-04 23:29 - 2015-10-17 14:11 - 00000000 ____D C:\Users\kathr\AppData\Local\Adobe
2015-10-04 23:18 - 2015-10-05 01:10 - 00680600 _____ (Sysinternals - www.sysinternals.com) C:\Users\kathr\Desktop\autoruns.exe
2015-10-04 23:02 - 2015-10-14 03:50 - 00000000 ____D C:\Program Files\Webroot
2015-10-04 22:43 - 2015-10-04 22:43 - 10919784 _____ C:\WINDOWS\SysWOW64\LogiDPP.dll
2015-10-04 22:43 - 2015-10-04 22:43 - 10919784 _____ C:\WINDOWS\system32\LogiDPP.dll
2015-10-04 22:43 - 2015-10-04 22:43 - 04758176 _____ (Logitech Inc.) C:\WINDOWS\system32\Drivers\lvuvc64.sys
2015-10-04 22:43 - 2015-10-04 22:43 - 00768288 _____ (Logitech Inc.) C:\WINDOWS\system32\LVUI64.dll
2015-10-04 22:43 - 2015-10-04 22:43 - 00560416 _____ (Logitech Inc.) C:\WINDOWS\system32\LVUIRC64.dll
2015-10-04 22:43 - 2015-10-04 22:43 - 00542568 _____ (Logitech Inc.) C:\WINDOWS\SysWOW64\LVUI2.dll
2015-10-04 22:43 - 2015-10-04 22:43 - 00538472 _____ (Logitech Inc.) C:\WINDOWS\SysWOW64\LVUI2RC.dll
2015-10-04 22:43 - 2015-10-04 22:43 - 00336232 _____ C:\WINDOWS\SysWOW64\DevManagerCore.dll
2015-10-04 22:43 - 2015-10-04 22:43 - 00336232 _____ C:\WINDOWS\system32\DevManagerCore.dll
2015-10-04 22:43 - 2015-10-04 22:43 - 00305000 _____ (Logitech Inc.) C:\WINDOWS\SysWOW64\lvcodec2.dll
2015-10-04 22:43 - 2015-10-04 22:43 - 00266828 _____ C:\WINDOWS\system32\Drivers\LVAFT.cfg
2015-10-04 22:43 - 2015-10-04 22:43 - 00262432 _____ (Logitech Inc.) C:\WINDOWS\system32\lvco1380853.dll
2015-10-04 22:43 - 2015-10-04 22:43 - 00175392 _____ (Logitech Inc.) C:\WINDOWS\system32\lvcod64.dll
2015-10-04 22:43 - 2015-10-04 22:43 - 00103272 _____ C:\WINDOWS\SysWOW64\LogiDPPApp.exe
2015-10-04 22:43 - 2015-10-04 22:43 - 00103272 _____ C:\WINDOWS\system32\LogiDPPApp.exe
2015-10-04 22:43 - 2015-10-04 22:43 - 00029494 _____ C:\WINDOWS\system32\lvcoin64.ini
2015-10-04 22:36 - 2015-10-16 03:39 - 00000000 ____D C:\Users\kathr\AppData\Roaming\Adobe
2015-10-04 22:16 - 2015-10-12 11:11 - 00001325 _____ C:\Users\Public\Desktop\dMaintenance Home Edition.lnk
2015-10-04 21:05 - 2015-10-12 11:11 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Foolish IT
2015-10-04 21:05 - 2015-10-12 10:24 - 00003518 _____ C:\WINDOWS\System32\Tasks\CryptoPrevent Update
2015-10-04 21:05 - 2015-10-04 21:05 - 00001289 _____ C:\Users\Public\Desktop\CryptoPrevent.lnk
2015-10-04 20:10 - 2015-10-17 18:07 - 00021012 __RSH C:\ProgramData\ntuser.pol
2015-10-04 19:58 - 2015-10-12 10:26 - 00000000 ____D C:\WINDOWS\system32\appmgmt
2015-10-04 19:34 - 2015-10-04 19:36 - 00000000 ____D C:\Users\kathr\OneDrive\Documents\WPA Files
2015-10-04 19:34 - 2015-10-04 19:34 - 00000000 ____D C:\SymCache
2015-10-04 19:31 - 2015-10-04 19:31 - 163577856 _____ C:\WINDOWS\system32\boot_BASE+CSWITCH_1.etl
2015-10-04 19:31 - 2015-10-04 19:31 - 07345250 _____ C:\WINDOWS\system32\boot_BASE+CSWITCH_1.cab
2015-10-04 18:51 - 2015-10-04 18:51 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
2015-10-04 14:37 - 2015-10-04 14:37 - 191889408 _____ C:\WINDOWS\system32\bootPrep_BASE+CSWITCH_2.etl
2015-10-04 14:37 - 2015-10-04 14:37 - 04993712 _____ C:\WINDOWS\system32\bootPrep_BASE+CSWITCH_2.cab
2015-10-04 14:31 - 2015-10-04 14:31 - 220200960 _____ C:\WINDOWS\system32\bootPrep_BASE+CSWITCH_1.etl
2015-10-04 14:31 - 2015-10-04 14:31 - 03730738 _____ C:\WINDOWS\system32\bootPrep_BASE+CSWITCH_1.cab
2015-10-04 14:20 - 2015-10-07 17:37 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Kits
2015-10-04 14:20 - 2015-10-07 17:37 - 00000000 ____D C:\Program Files (x86)\Windows Kits
2015-10-04 00:23 - 2015-10-16 19:49 - 00000000 ____D C:\WINDOWS\CryptoGuard
2015-10-04 00:23 - 2015-10-06 14:12 - 00000000 ____D C:\ProgramData\HitmanPro
2015-10-04 00:16 - 2015-10-17 14:52 - 00000000 ____D C:\ProgramData\HitmanPro.Alert
2015-10-04 00:05 - 2015-10-04 00:05 - 00000000 ____D C:\Users\kathr\AppData\Roaming\Blacksmith3D
2015-10-03 23:06 - 2015-10-03 23:06 - 00002826 _____ C:\Users\kathr\Desktop\AHB_magnaheart_dress_02 - Shortcut.lnk
2015-10-03 21:35 - 2015-10-03 21:35 - 00000000 ____D C:\Users\kathr\OneDrive\Documents\Security
2015-10-03 21:00 - 2015-10-03 21:00 - 00058675 _____ C:\Users\kathr\OneDrive\Documents\registryleaks.txt
2015-10-03 20:43 - 2015-10-11 02:23 - 00000000 ____D C:\Users\kathr\OneDrive\Documents\DAZ 3D
2015-10-03 20:30 - 2015-10-03 20:30 - 00053248 _____ C:\WINDOWS\SysWOW64\zlib.dll
2015-10-03 20:26 - 2015-10-16 15:20 - 00007641 _____ C:\Users\kathr\AppData\Local\Resmon.ResmonCfg
2015-10-03 20:26 - 2015-10-04 22:16 - 00000000 ____D C:\Program Files (x86)\Foolish IT
2015-10-03 20:26 - 2015-10-04 21:05 - 00000000 ____D C:\ProgramData\Foolish IT
2015-10-03 18:45 - 2015-10-04 18:28 - 00000000 ____D C:\AdwCleaner
2015-10-03 18:34 - 2015-10-03 18:34 - 00000000 ____D C:\WINDOWS\SMSS-PFRO20f5.tmp
2015-10-03 17:45 - 2015-10-14 09:21 - 143481208 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2015-10-03 17:10 - 2015-10-17 14:59 - 00004164 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{0AB9CB54-4CE0-4F7C-A83A-83EBCF8FAC11}
2015-10-03 15:40 - 2015-10-17 18:07 - 03335920 _____ C:\WINDOWS\PFRO.log
2015-10-03 15:38 - 2015-10-16 17:16 - 00002336 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2015-10-03 15:38 - 2015-10-03 15:38 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-10-03 15:37 - 2015-10-08 19:15 - 00000924 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2015-10-03 15:37 - 2015-10-08 19:15 - 00000920 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2015-10-03 15:37 - 2015-10-08 17:48 - 00003496 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2015-10-03 15:37 - 2015-10-08 17:48 - 00003272 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2015-10-03 15:32 - 2015-10-03 15:32 - 00003652 _____ C:\WINDOWS\System32\Tasks\CreateExplorerShellUnelevatedTask
2015-10-03 15:18 - 2015-10-17 09:42 - 02196992 _____ (Farbar) C:\Users\kathr\Desktop\FRST64.exe
2015-10-03 15:10 - 2015-10-03 15:10 - 00001704 _____ C:\Users\Public\Desktop\Scrivener.lnk
2015-10-03 15:10 - 2015-10-03 15:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Scrivener
2015-10-03 14:48 - 2015-10-07 17:38 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LastPass
2015-10-03 14:48 - 2015-10-07 17:37 - 00000000 ____D C:\Users\kathr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\LastPass
2015-10-03 14:48 - 2015-10-07 17:37 - 00000000 ____D C:\Program Files (x86)\LastPass
2015-10-03 14:47 - 2015-10-03 15:38 - 00000000 ____D C:\Program Files (x86)\Google
2015-10-03 14:39 - 2015-10-03 14:41 - 00001176 _____ C:\Users\kathr\Desktop\DAZ Studio 4.8 (64-bit).lnk
2015-10-03 14:38 - 2015-10-15 12:43 - 00000000 ____D C:\Program Files\DAZ 3D
2015-10-03 14:38 - 2015-10-03 14:38 - 00000969 _____ C:\Users\kathr\Desktop\Carrara 8.5 Pro (64-bit).lnk
2015-10-03 09:32 - 2015-10-03 09:31 - 00117242 _____ C:\Users\kathr\Desktop\DAZStudio_error_report_151003-093132.zip
2015-10-02 21:35 - 2015-10-02 21:35 - 00000000 ____D C:\Users\kathr\AppData\Local\CEF
2015-10-02 18:55 - 2015-10-03 17:20 - 00000000 ____D C:\Program Files\Sandboxie
2015-10-02 18:49 - 2015-10-02 18:49 - 00000000 ____D C:\Users\kathr\AppData\Local\Scrivener
2015-10-02 18:35 - 2015-10-05 04:33 - 00000000 ____D C:\ProgramData\Adobe
2015-10-02 18:35 - 2015-10-04 14:20 - 00000000 ____D C:\ProgramData\Package Cache
2015-10-02 18:34 - 2015-10-04 23:32 - 00000000 ____D C:\Program Files (x86)\Adobe
2015-10-02 18:31 - 2015-10-03 15:10 - 00000000 ____D C:\Program Files (x86)\Scrivener
2015-10-02 18:29 - 2015-10-15 13:02 - 00000000 ____D C:\ProgramData\DAZ 3D
2015-10-02 18:00 - 2015-10-02 18:00 - 00000000 ____D C:\Users\kathr\AppData\Local\Logitech® Webcam Software
2015-10-02 17:58 - 2015-10-07 17:37 - 00000000 ____D C:\ProgramData\LogiShrd
2015-10-02 17:58 - 2015-10-02 17:58 - 00000000 ____D C:\Users\kathr\AppData\Roaming\Leadertech
2015-10-02 17:57 - 2015-10-07 00:01 - 00010152 _____ C:\WINDOWS\LDPINST.LOG
2015-10-02 17:49 - 2015-10-07 17:37 - 00000000 ____D C:\Program Files\Common Files\logishrd
2015-10-02 17:49 - 2015-10-07 00:01 - 00018015 _____ C:\WINDOWS\system32\lvcoinst.log
2015-10-02 17:43 - 2015-10-02 17:43 - 00000000 ____D C:\Users\kathr\Desktop\Heart's Ransom cover
2015-10-02 17:40 - 2015-10-07 17:37 - 00000000 ____D C:\ProgramData\FastPictureViewer
2015-10-02 17:38 - 2015-10-06 21:30 - 00000000 ____D C:\Users\kathr\Desktop\3d n Art
2015-10-02 17:37 - 2015-10-17 09:42 - 00000000 ____D C:\Users\kathr\Desktop\computer
2015-10-02 16:06 - 2015-10-02 16:06 - 00000000 ____D C:\Users\kathr\AppData\Local\PeerDistRepub
2015-10-02 16:02 - 2015-10-14 03:17 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\herdProtect
2015-10-02 16:02 - 2015-10-02 16:02 - 00000000 ____D C:\Program Files\Reason
2015-10-02 15:50 - 2015-10-02 15:50 - 00000000 ____D C:\Users\kathr\AppData\Local\GlassWire
2015-10-02 15:50 - 2015-10-02 15:50 - 00000000 ____D C:\ProgramData\GlassWire
2015-10-02 15:37 - 2015-10-14 09:53 - 00000000 ____D C:\WINDOWS\system32\MRT
2015-10-02 15:29 - 2015-10-03 17:19 - 00000000 ____D C:\WINDOWS\pss
2015-10-02 15:13 - 2015-10-02 15:13 - 00000000 ____D C:\Users\kathr\AppData\Roaming\Macromedia
2015-10-02 14:47 - 2015-10-02 14:47 - 00000000 ___HD C:\VTRoot
2015-10-02 12:48 - 2015-10-08 16:40 - 00000000 ___DC C:\WINDOWS\Panther
2015-10-02 12:48 - 2015-10-08 13:56 - 00000000 ____D C:\Windows.old
2015-10-02 12:45 - 2015-10-02 12:45 - 00028672 ___SH C:\WINDOWS\system32\config\BCD-Template.LOG
2015-10-02 12:44 - 2015-10-02 12:44 - 00008192 _____ C:\WINDOWS\system32\config\userdiff
2015-10-02 12:43 - 2015-10-02 12:43 - 00000000 ____D C:\WINDOWS\Setup
2015-10-02 12:41 - 2015-10-02 12:41 - 00000000 ____D C:\WINDOWS\OCR
2015-10-02 12:40 - 2015-10-02 12:40 - 00000000 ____D C:\WINDOWS\SysWOW64\winrm
2015-10-02 12:40 - 2015-10-02 12:40 - 00000000 ____D C:\WINDOWS\SysWOW64\WCN
2015-10-02 12:40 - 2015-10-02 12:40 - 00000000 ____D C:\WINDOWS\SysWOW64\sysprep
2015-10-02 12:40 - 2015-10-02 12:40 - 00000000 ____D C:\WINDOWS\SysWOW64\slmgr
2015-10-02 12:40 - 2015-10-02 12:40 - 00000000 ____D C:\WINDOWS\SysWOW64\Printing_Admin_Scripts
2015-10-02 12:40 - 2015-10-02 12:40 - 00000000 ____D C:\WINDOWS\SysWOW64\0409
2015-10-02 12:40 - 2015-10-02 12:40 - 00000000 ____D C:\WINDOWS\system32\winrm
2015-10-02 12:40 - 2015-10-02 12:40 - 00000000 ____D C:\WINDOWS\system32\WCN
2015-10-02 12:40 - 2015-10-02 12:40 - 00000000 ____D C:\WINDOWS\system32\slmgr
2015-10-02 12:40 - 2015-10-02 12:40 - 00000000 ____D C:\WINDOWS\system32\Printing_Admin_Scripts
2015-10-02 12:40 - 2015-10-02 12:40 - 00000000 ____D C:\WINDOWS\system32\0409
2015-10-02 12:40 - 2015-10-02 12:40 - 00000000 ____D C:\WINDOWS\DigitalLocker
2015-10-02 12:38 - 2015-10-01 02:57 - 00812008 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2015-10-02 12:38 - 2015-10-01 02:57 - 00178152 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2015-10-02 12:37 - 2015-10-09 13:29 - 00002177 _____ C:\WINDOWS\DtcInstall.log
2015-10-02 12:36 - 2015-10-17 18:06 - 00000000 ____D C:\WINDOWS\system32\sru
2015-10-02 12:36 - 2015-10-17 17:35 - 00000000 ____D C:\WINDOWS\AppReadiness
2015-10-02 12:36 - 2015-10-17 14:10 - 00000000 ___HD C:\WINDOWS\ELAMBKUP
2015-10-02 12:36 - 2015-10-16 16:28 - 00000215 _____ C:\WINDOWS\win.ini
2015-10-02 12:36 - 2015-10-14 03:18 - 00000000 ____D C:\WINDOWS\Help
2015-10-02 12:36 - 2015-10-14 02:51 - 00000000 ____D C:\WINDOWS\system32\NDF
2015-10-02 12:36 - 2015-10-09 11:37 - 00000000 ___HD C:\WINDOWS\system32\GroupPolicy
2015-10-02 12:36 - 2015-10-09 11:37 - 00000000 ____D C:\WINDOWS\registration
2015-10-02 12:36 - 2015-10-08 17:23 - 00000000 ____D C:\WINDOWS\LiveKernelReports
2015-10-02 12:36 - 2015-10-08 16:07 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2015-10-02 12:36 - 2015-10-08 14:03 - 00000000 ____D C:\WINDOWS\rescache
2015-10-02 12:36 - 2015-10-07 17:37 - 00000000 ____D C:\WINDOWS\system32\WinMetadata
2015-10-02 12:36 - 2015-10-07 17:37 - 00000000 ____D C:\WINDOWS\system32\Sysprep
2015-10-02 12:36 - 2015-10-07 17:37 - 00000000 ____D C:\WINDOWS\system32\oobe
2015-10-02 12:36 - 2015-10-07 17:37 - 00000000 ____D C:\WINDOWS\appcompat
2015-10-02 12:36 - 2015-10-06 21:52 - 00000000 ____D C:\WINDOWS\system32\Recovery
2015-10-02 12:36 - 2015-10-04 23:13 - 00000000 ____D C:\WINDOWS\system32\spool
2015-10-02 12:36 - 2015-10-03 18:37 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility
2015-10-02 12:36 - 2015-10-03 18:36 - 00000000 ___SD C:\WINDOWS\SysWOW64\F12
2015-10-02 12:36 - 2015-10-03 18:36 - 00000000 ___SD C:\WINDOWS\system32\F12
2015-10-02 12:36 - 2015-10-03 18:36 - 00000000 ___RD C:\WINDOWS\PurchaseDialog
2015-10-02 12:36 - 2015-10-03 18:36 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2015-10-02 12:36 - 2015-10-03 18:36 - 00000000 ____D C:\WINDOWS\system32\SystemResetPlatform
2015-10-02 12:36 - 2015-10-03 18:36 - 00000000 ____D C:\WINDOWS\system32\appraiser
2015-10-02 12:36 - 2015-10-03 18:36 - 00000000 ____D C:\WINDOWS\Provisioning
2015-10-02 12:36 - 2015-10-03 18:36 - 00000000 ____D C:\WINDOWS\L2Schemas
2015-10-02 12:36 - 2015-10-03 17:21 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\System Tools
2015-10-02 12:36 - 2015-10-03 17:21 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2015-10-02 12:36 - 2015-10-03 17:21 - 00000000 ____D C:\WINDOWS\SysWOW64\Macromed
2015-10-02 12:36 - 2015-10-03 17:21 - 00000000 ____D C:\WINDOWS\system32\Macromed
2015-10-02 12:36 - 2015-10-02 12:48 - 00028672 _____ C:\WINDOWS\system32\config\BCD-Template
2015-10-02 12:36 - 2015-10-02 12:43 - 00000000 ___RD C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-10-02 12:36 - 2015-10-02 12:43 - 00000000 ___RD C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-10-02 12:36 - 2015-10-02 12:43 - 00000000 ____D C:\WINDOWS\SysWOW64\oobe
2015-10-02 12:36 - 2015-10-02 12:43 - 00000000 ____D C:\WINDOWS\SysWOW64\Dism
2015-10-02 12:36 - 2015-10-02 12:43 - 00000000 ____D C:\WINDOWS\system32\Dism
2015-10-02 12:36 - 2015-10-02 12:43 - 00000000 ____D C:\Program Files\Windows Journal
2015-10-02 12:36 - 2015-10-02 12:40 - 00000000 ___SD C:\WINDOWS\SysWOW64\DiagSvcs
2015-10-02 12:36 - 2015-10-02 12:40 - 00000000 ___SD C:\WINDOWS\system32\dsc
2015-10-02 12:36 - 2015-10-02 12:40 - 00000000 ___SD C:\WINDOWS\system32\DiagSvcs
2015-10-02 12:36 - 2015-10-02 12:40 - 00000000 ____D C:\WINDOWS\SysWOW64\setup
2015-10-02 12:36 - 2015-10-02 12:40 - 00000000 ____D C:\WINDOWS\SysWOW64\MUI
2015-10-02 12:36 - 2015-10-02 12:40 - 00000000 ____D C:\WINDOWS\SysWOW64\Com
2015-10-02 12:36 - 2015-10-02 12:40 - 00000000 ____D C:\WINDOWS\system32\setup
2015-10-02 12:36 - 2015-10-02 12:40 - 00000000 ____D C:\WINDOWS\system32\MUI
2015-10-02 12:36 - 2015-10-02 12:40 - 00000000 ____D C:\WINDOWS\system32\migwiz
2015-10-02 12:36 - 2015-10-02 12:40 - 00000000 ____D C:\WINDOWS\system32\Com
2015-10-02 12:36 - 2015-10-02 12:40 - 00000000 ____D C:\WINDOWS\PolicyDefinitions
2015-10-02 12:36 - 2015-10-02 12:40 - 00000000 ____D C:\WINDOWS\IME
2015-10-02 12:36 - 2015-10-02 12:40 - 00000000 ____D C:\Program Files\Windows Photo Viewer
2015-10-02 12:36 - 2015-10-02 12:40 - 00000000 ____D C:\Program Files\Windows Defender
2015-10-02 12:36 - 2015-10-02 12:40 - 00000000 ____D C:\Program Files\Common Files\System
2015-10-02 12:36 - 2015-10-02 12:40 - 00000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2015-10-02 12:36 - 2015-10-02 12:40 - 00000000 ____D C:\Program Files (x86)\Windows Defender
2015-10-02 12:36 - 2015-10-02 12:37 - 00000000 __RSD C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell
2015-10-02 12:36 - 2015-10-02 12:37 - 00000000 __RSD C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 __SHD C:\WINDOWS\BitLockerDiscoveryVolumeContents
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 __SHD C:\Program Files\Windows Sidebar
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 __SHD C:\Program Files (x86)\Windows Sidebar
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 __RSD C:\WINDOWS\Media
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 __RHD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tablet PC
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ___SD C:\WINDOWS\SysWOW64\Nui
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ___SD C:\WINDOWS\SysWOW64\Configuration
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ___SD C:\WINDOWS\system32\Nui
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ___SD C:\WINDOWS\system32\Configuration
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ___SD C:\Program Files\WindowsPowerShell
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ___SD C:\Program Files (x86)\WindowsPowerShell
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ___RD C:\WINDOWS\Offline Web Pages
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ___RD C:\WINDOWS\DesktopTileResources
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ___RD C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ___RD C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ___RD C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ___RD C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\Web
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\Vss
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\tracing
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\TAPI
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\zh-HK
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\WinMetadata
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\WindowsPowerShell
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\uk-UA
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\tr-TR
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\th-TH
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\sru
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\sr-Latn-RS
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\sr-Latn-CS
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\sppui
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\spp
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\Speech_OneCore
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\Speech
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\SMI
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\sl-SI
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\sk-SK
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\ro-RO
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\restore
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\Recovery
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\RasToast
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\ras
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\networklist
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\NDF
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\MsDtc
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\MSDRM
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\migwiz
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\lv-LV
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\lt-LT
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\Licenses
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\Ipmi
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\InstallShield
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\InputMethod
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\inetsrv
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\IME
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\icsxml
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\hr-HR
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\he-IL
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\GroupPolicy
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\FxsTmp
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\fr-CA
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\et-EE
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\es-MX
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\en-GB
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\downlevel
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\Bthprops
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\bg-BG
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\ar-SA
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\AppLocker
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SysWOW64\AdvancedInstallers
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SystemResources
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\zh-HK
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\winevt
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\WindowsPowerShell
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\uk-UA
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\tr-TR
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\th-TH
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\sr-Latn-RS
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\sr-Latn-CS
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\sppui
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\spp
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\Speech_OneCore
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\Speech
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\sl-SI
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\sk-SK
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\SecureBootUpdates
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\ro-RO
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\RasToast
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\ras
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\ProximityToast
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\PointOfService
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\networklist
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\MsDtc
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\MSDRM
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\MailContactsCalendarSync
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\lv-LV
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\lt-LT
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\Licenses
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\Ipmi
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\InputMethod
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\inetsrv
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\IME
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\icsxml
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\ias
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\hr-HR
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\he-IL
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\fr-CA
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\et-EE
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\es-MX
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\en-GB
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\downlevel
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\config\Journal
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\Bthprops
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\bg-BG
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\ar-SA
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\AppLocker
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\AdvancedInstallers
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system\Speech
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\System
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\Speech_OneCore
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\Speech
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SKB
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\ShellNew
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\security
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\schemas
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\SchCache
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\Resources
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\PLA
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\Performance
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\InputMethod
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\Globalization
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\Cursors
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\Branding
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\addins
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\ProgramData\Comms
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\Program Files\Windows Portable Devices
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\Program Files\Windows NT
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\Program Files\Windows Multimedia Platform
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\Program Files\Common Files\Services
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\Program Files (x86)\Windows Portable Devices
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\Program Files (x86)\Windows NT
2015-10-02 12:36 - 2015-10-02 12:36 - 00000000 ____D C:\Program Files (x86)\Windows Multimedia Platform
2015-10-02 12:36 - 2015-10-02 12:34 - 00229888 _____ (Microsoft Corporation) C:\WINDOWS\system32\msclmd.dll
2015-10-02 12:36 - 2015-10-02 12:34 - 00215943 _____ C:\WINDOWS\SysWOW64\dssec.dat
2015-10-02 12:36 - 2015-10-02 12:34 - 00215943 _____ C:\WINDOWS\system32\dssec.dat
2015-10-02 12:36 - 2015-10-02 12:34 - 00208384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msclmd.dll
2015-10-02 12:36 - 2015-10-02 12:34 - 00017463 _____ C:\WINDOWS\system32\Drivers\etc\services
2015-10-02 12:36 - 2015-10-02 12:34 - 00015462 _____ C:\WINDOWS\system32\OEMDefaultAssociations.xml
2015-10-02 12:36 - 2015-10-02 12:34 - 00008798 _____ C:\WINDOWS\SysWOW64\icrav03.rat
2015-10-02 12:36 - 2015-10-02 12:34 - 00008798 _____ C:\WINDOWS\system32\icrav03.rat
2015-10-02 12:36 - 2015-10-02 12:34 - 00003683 _____ C:\WINDOWS\system32\Drivers\etc\lmhosts.sam
2015-10-02 12:36 - 2015-10-02 12:34 - 00001988 _____ C:\WINDOWS\SysWOW64\ticrf.rat
2015-10-02 12:36 - 2015-10-02 12:34 - 00001988 _____ C:\WINDOWS\system32\ticrf.rat
2015-10-02 12:36 - 2015-10-02 12:34 - 00001358 _____ C:\WINDOWS\system32\Drivers\etc\protocol
2015-10-02 12:36 - 2015-10-02 12:34 - 00000858 _____ C:\WINDOWS\system32\DefaultQuestions.json
2015-10-02 12:36 - 2015-10-02 12:34 - 00000741 _____ C:\WINDOWS\SysWOW64\NOISE.DAT
2015-10-02 12:36 - 2015-10-02 12:34 - 00000741 _____ C:\WINDOWS\system32\NOISE.DAT
2015-10-02 12:36 - 2015-10-02 12:34 - 00000407 _____ C:\WINDOWS\system32\Drivers\etc\networks
2015-10-02 12:36 - 2015-10-02 12:34 - 00000219 ____N C:\WINDOWS\system.ini
2015-10-02 12:36 - 2015-10-02 11:06 - 00000000 ____D C:\WINDOWS\system32\restore
2015-10-02 12:36 - 2015-10-02 10:06 - 00000000 ___RD C:\WINDOWS\PrintDialog
2015-10-02 12:36 - 2015-10-02 10:06 - 00000000 ___RD C:\WINDOWS\MiracastView
2015-10-02 12:36 - 2015-10-02 10:06 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2015-10-02 12:36 - 2015-10-02 10:01 - 00000000 __RHD C:\Users\Public\Libraries
2015-10-02 12:36 - 2015-10-02 10:01 - 00000000 ____D C:\WINDOWS\system32\WinBioDatabase
2015-10-02 12:36 - 2015-10-02 09:59 - 00000000 ____D C:\WINDOWS\CSC
2015-10-02 12:36 - 2015-10-02 09:57 - 00000000 ____D C:\WINDOWS\system32\FxsTmp
2015-10-02 12:36 - 2015-10-02 09:53 - 00000000 ____D C:\ProgramData\USOPrivate
2015-10-02 12:28 - 2015-10-17 18:13 - 00000000 ____D C:\WINDOWS\CbsTemp
2015-10-02 12:24 - 2015-10-17 18:06 - 00131072 ___SH C:\WINDOWS\system32\config\BBI
2015-10-02 12:24 - 2015-10-16 19:49 - 00032768 ___SH C:\WINDOWS\system32\config\ELAM
2015-10-02 12:24 - 2015-10-14 02:05 - 00000000 __RHD C:\Users\Default
2015-10-02 12:24 - 2015-10-03 17:21 - 00000000 ____D C:\WINDOWS\servicing
2015-10-02 12:24 - 2015-10-02 12:36 - 00000000 ____D C:\WINDOWS\system32\SMI
2015-10-02 12:24 - 2015-07-10 04:11 - 00000164 _____ C:\WINDOWS\system32\config\FP
2015-10-02 12:23 - 2015-10-04 15:07 - 00000000 ___HD C:\$SysReset
2015-10-02 11:09 - 2015-10-02 11:09 - 00000000 ____D C:\ProgramData\Shared Space
2015-10-02 11:01 - 2015-10-02 11:01 - 01060864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfc71.dll
2015-10-02 11:01 - 2015-10-02 11:01 - 00348160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvcr71.dll
2015-10-02 10:53 - 2015-10-15 13:02 - 00000000 ____D C:\Users\kathr\AppData\Roaming\DAZ 3D
2015-10-02 10:52 - 2015-10-03 14:39 - 00000000 ____D C:\Users\kathr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DAZ 3D
2015-10-02 10:52 - 2015-10-02 10:52 - 00000000 ____D C:\Program Files (x86)\DAZ 3D
2015-10-02 10:48 - 2015-10-16 16:12 - 00000000 ____D C:\Users\kathr\AppData\Roaming\vlc
2015-10-02 10:48 - 2015-10-03 17:21 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
2015-10-02 10:48 - 2015-10-02 10:48 - 00001143 _____ C:\Users\Public\Desktop\VLC media player.lnk
2015-10-02 10:48 - 2015-10-02 10:48 - 00000000 ____D C:\Program Files (x86)\VideoLAN
2015-10-02 10:38 - 2015-07-05 05:08 - 00300704 _____ (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2015-10-02 10:34 - 2015-10-03 17:21 - 00000000 ____D C:\Users\kathr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-10-02 10:33 - 2015-10-07 00:02 - 00000000 ____D C:\Program Files (x86)\Opera
2015-10-02 10:33 - 2015-10-03 17:10 - 00000000 ____D C:\Users\kathr\AppData\Local\Google
2015-10-02 10:25 - 2015-10-14 09:20 - 02544872 _____ (ELAN Microelectronics Corp.) C:\WINDOWS\ETDUninst.dll
2015-10-02 10:21 - 2015-10-02 10:32 - 00000000 ____D C:\Users\kathr\AppData\Local\MicrosoftEdge
2015-10-02 10:16 - 2015-10-03 15:43 - 00002338 _____ C:\Users\kathr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2015-10-02 10:08 - 2015-10-02 10:08 - 00000000 ____D C:\ProgramData\Microsoft OneDrive
2015-10-02 10:07 - 2015-10-03 15:39 - 00000000 ____D C:\Users\kathr\AppData\Local\Comms
2015-10-02 10:06 - 2015-10-16 18:51 - 00000000 ____D C:\Users\kathr\AppData\Local\VirtualStore
2015-10-02 10:06 - 2015-10-03 14:52 - 00000000 ____D C:\Users\kathr\AppData\Local\Packages
2015-10-02 10:06 - 2015-10-02 10:06 - 00000000 ____D C:\Users\kathr\AppData\Local\TileDataLayer
2015-10-02 10:06 - 2015-10-02 10:06 - 00000000 ____D C:\Users\kathr\AppData\Local\Publishers
2015-10-02 10:05 - 2015-10-17 18:12 - 00830266 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2015-10-02 10:05 - 2015-10-02 10:05 - 00000020 ___SH C:\Users\kathr\ntuser.ini
2015-10-02 10:02 - 2015-10-02 10:02 - 00000000 __SHD C:\Recovery
2015-10-02 10:00 - 2015-10-14 07:59 - 00000000 ____D C:\Users\kathr
2015-10-02 10:00 - 2015-10-03 17:21 - 00000000 __RSD C:\Users\kathr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell
2015-10-02 10:00 - 2015-10-03 17:21 - 00000000 ___RD C:\Users\kathr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-10-02 10:00 - 2015-10-03 17:21 - 00000000 ___RD C:\Users\kathr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-10-02 10:00 - 2015-10-03 17:21 - 00000000 ___RD C:\Users\kathr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2015-10-02 10:00 - 2015-10-02 12:36 - 00000000 ____D C:\Users\kathr\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-10-02 09:54 - 2015-10-17 18:07 - 00000275 _____ C:\WINDOWS\WindowsUpdate.log
2015-10-02 09:53 - 2015-10-14 03:18 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2015-10-02 09:53 - 2015-10-02 09:53 - 00000000 ____D C:\ProgramData\USOShared
2015-10-02 09:53 - 2015-07-10 00:37 - 02718208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2015-10-02 09:51 - 2015-10-16 12:21 - 00023145 _____ C:\WINDOWS\setupact.log
2015-10-02 09:51 - 2015-10-02 09:51 - 00000000 _____ C:\WINDOWS\setuperr.log
2015-10-02 09:50 - 2015-10-17 18:07 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-10-02 09:49 - 2015-10-12 10:56 - 00517808 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2015-10-02 02:37 - 2015-10-03 17:21 - 00000000 ____D C:\Users\kathr\Desktop\Presets-2015-09-09
2015-10-02 01:34 - 2015-10-02 17:39 - 00000000 ____D C:\Users\kathr\Desktop\unzipped
2015-10-01 13:43 - 2015-10-03 17:21 - 00000000 ____D C:\Users\kathr\Desktop\21966-01_ContentCatalogerEasy
2015-10-01 13:32 - 2015-10-01 13:32 - 00000776 _____ C:\Users\kathr\Desktop\Hexagon 2.lnk
2015-10-01 12:35 - 2015-10-05 00:26 - 00000000 ____D C:\Users\kathr\Desktop\renderosity
2015-10-01 08:35 - 2015-10-07 01:11 - 00000000 ____D C:\Users\kathr\AppData\LocalLow\Temp
2015-10-01 02:57 - 2015-10-01 02:57 - 24595456 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 21875712 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 19325440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 18806272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 16708608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 13027840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 08020816 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2015-10-01 02:57 - 2015-10-01 02:57 - 07569408 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 07523328 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 07055872 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 06572032 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanmm.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 06487248 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 06101504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mos.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 05454848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 05120056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 05079552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 04791296 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 03781120 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 03586560 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2015-10-01 02:57 - 2015-10-01 02:57 - 03579904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 03248640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 02987520 _____ (Microsoft Corporation) C:\WINDOWS\system32\esent.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 02824248 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 02740224 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 02660864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 02646528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 02639872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\esent.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 02494712 _____ C:\WINDOWS\system32\CoreUIComponents.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 02464216 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 02446648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2vdec.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 02432336 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2015-10-01 02:57 - 2015-10-01 02:57 - 02417664 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 02236416 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 02228736 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 02226688 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 02207232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 02178560 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 02156400 _____ (Microsoft Corporation) C:\WINDOWS\system32\hevcdecoder.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 02154808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 02093056 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidsvc.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 01983824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2015-10-01 02:57 - 2015-10-01 02:57 - 01918464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 01895568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hevcdecoder.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 01820160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Logon.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 01812480 _____ (Microsoft Corporation) C:\WINDOWS\system32\pnidui.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 01795072 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 01766952 _____ C:\WINDOWS\SysWOW64\CoreUIComponents.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 01601536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Speech.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 01563472 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpmde.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 01563392 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 01423872 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataService.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 01397088 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 01382400 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2015-10-01 02:57 - 2015-10-01 02:57 - 01357888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winmde.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 01331200 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 01295712 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpx.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 01290240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Shell.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 01276416 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifinetworkmanager.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 01216512 _____ (Microsoft Corporation) C:\WINDOWS\system32\netcenter.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 01213440 _____ (Microsoft Corporation) C:\WINDOWS\system32\RemoteNaturalLanguage.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 01205248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Unistore.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 01203712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Bluetooth.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 01181696 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 01171456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netcenter.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 01168736 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys
2015-10-01 02:57 - 2015-10-01 02:57 - 01162240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Speech.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 01104384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 01067520 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 01010176 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXService.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00966416 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00962400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00928256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Unistore.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00928256 _____ (Microsoft Corporation) C:\WINDOWS\system32\JpMapControl.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00910848 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedStartModel.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00899584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RemoteNaturalLanguage.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00894256 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Wdf01000.sys
2015-10-01 02:57 - 2015-10-01 02:57 - 00869376 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlCore.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00859136 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00856576 _____ (Microsoft Corporation) C:\WINDOWS\system32\MPSSVC.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00856576 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContactApis.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00832512 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00828928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Bluetooth.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00809352 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00796160 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00784136 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00781976 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfds.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00780288 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00771072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00764416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.appcore.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00752640 _____ (Microsoft Corporation) C:\WINDOWS\system32\ChatApis.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00720896 _____ (Microsoft Corporation) C:\WINDOWS\system32\EmailApis.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00701952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\JpMapControl.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00690688 _____ (Microsoft Corporation) C:\WINDOWS\system32\CellularAPI.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00689152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00685568 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppointmentApis.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00677888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapControlCore.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00671232 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUDFx02000.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00658528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfds.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00646672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00627712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00625152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ContactApis.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00621056 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00613376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00599552 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnapps.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00591360 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmsvc.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00590336 _____ (Microsoft Corporation) C:\WINDOWS\system32\MessagingDataModel2.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00587264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00584656 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00579584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppointmentApis.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00579072 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
2015-10-01 02:57 - 2015-10-01 02:57 - 00574464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00570880 _____ (Microsoft Corporation) C:\WINDOWS\system32\MbaeApi.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00557568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ChatApis.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00555768 _____ (Microsoft Corporation) C:\WINDOWS\system32\directmanipulation.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00553808 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncHost.exe
2015-10-01 02:57 - 2015-10-01 02:57 - 00537080 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWanAPI.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00526336 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00525312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EmailApis.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00521728 _____ (Microsoft Corporation) C:\WINDOWS\system32\PsmServiceExtHost.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00517632 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationController.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00516448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBHUB3.SYS
2015-10-01 02:57 - 2015-10-01 02:57 - 00513536 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngcsvc.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00512000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00508248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00505696 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2015-10-01 02:57 - 2015-10-01 02:57 - 00504320 _____ (Microsoft Corporation) C:\WINDOWS\system32\DataSenseHandlers.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00503808 _____ (Microsoft Corporation) C:\WINDOWS\system32\tileobjserver.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00501008 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00494592 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00483328 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneDriveSettingSyncProvider.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00480256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Web.Core.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00476760 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFCaptureEngine.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00473088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wpnapps.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00467968 _____ (Microsoft Corporation) C:\WINDOWS\system32\MBMediaManager.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00466432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MessagingDataModel2.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00465920 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanconn.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00464896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00454656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MbaeApi.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00454512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\directmanipulation.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00446976 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapConfiguration.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00441168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncHost.exe
2015-10-01 02:57 - 2015-10-01 02:57 - 00439296 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationWebproxy.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00434376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFCaptureEngine.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00428128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWanAPI.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00421888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Bluetooth.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00414208 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00408064 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredProvDataModel.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00407608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00406864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\FWPKCLNT.SYS
2015-10-01 02:57 - 2015-10-01 02:57 - 00403456 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenrollengine.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00395088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2015-10-01 02:57 - 2015-10-01 02:57 - 00387584 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppBroker.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00378368 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemEventsBrokerServer.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00371712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OneDriveSettingSyncProvider.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00371712 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlasvc.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00366592 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00359936 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncsi.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00347136 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncryptprov.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00346112 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngccredprov.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00342016 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationGeofences.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00336384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CredProvDataModel.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00332624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fastfat.sys
2015-10-01 02:57 - 2015-10-01 02:57 - 00328704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapConfiguration.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00324096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00320000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\portcls.sys
2015-10-01 02:57 - 2015-10-01 02:57 - 00317440 _____ (Microsoft Corporation) C:\WINDOWS\system32\configmanager2.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00313856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LockAppBroker.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00312832 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsApi.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00311808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00288256 _____ (Microsoft Corporation) C:\WINDOWS\system32\PimIndexMaintenance.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00281600 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEEventDispatcher.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00278352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys
2015-10-01 02:57 - 2015-10-01 02:57 - 00274944 _____ (Microsoft Corporation) C:\WINDOWS\system32\syncutil.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00273920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.LockScreen.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00269312 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00268800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ncryptprov.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00268800 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationFramework.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00267776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Management.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00257024 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataAccountApis.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00253440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsApi.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00247808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00243760 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00224256 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCore.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00223232 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneCallHistoryApis.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00221184 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationPeWiFi.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00217088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VEEventDispatcher.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00215552 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationCrowdsource.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00204800 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmcsp.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00204288 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationPeCell.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00202240 _____ (Microsoft Corporation) C:\WINDOWS\system32\accountaccessor.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00195584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataAccountApis.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00195072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.LockScreen.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00193024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Management.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00187904 _____ (Microsoft Corporation) C:\WINDOWS\system32\provisioningcsp.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00186880 _____ (Microsoft Corporation) C:\WINDOWS\system32\cloudAP.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00185344 _____ (Microsoft Corporation) C:\WINDOWS\system32\psmsrv.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00176640 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationPeIP.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00172032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PhoneCallHistoryApis.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00169984 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmregistration.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00168960 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmmigrator.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00163840 _____ (Microsoft Corporation) C:\WINDOWS\system32\CallHistoryClient.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00162304 _____ (Microsoft Corporation) C:\WINDOWS\system32\SubscriptionMgr.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00160256 _____ (Microsoft Corporation) C:\WINDOWS\system32\enrollmentapi.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00154624 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcertinst.exe
2015-10-01 02:57 - 2015-10-01 02:57 - 00149504 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringservice.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00145920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mdmregistration.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00143360 _____ (Microsoft Corporation) C:\WINDOWS\system32\provops.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00137728 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEStoreEventHandlers.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00131072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CallHistoryClient.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00121856 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcsps.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00120832 _____ (Microsoft Corporation) C:\WINDOWS\system32\omadmclient.exe
2015-10-01 02:57 - 2015-10-01 02:57 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCsp.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00106496 _____ (Microsoft Corporation) C:\WINDOWS\system32\KeywordDetectorMsftSidAdapter.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00102304 _____ (Microsoft Corporation) C:\WINDOWS\system32\omadmapi.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00099664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pdc.sys
2015-10-01 02:57 - 2015-10-01 02:57 - 00095744 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationWiFiAdapter.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00088384 _____ (Microsoft Corporation) C:\WINDOWS\system32\remoteaudioendpoint.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00088064 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngckeyenum.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00084480 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDMAppInstaller.exe
2015-10-01 02:57 - 2015-10-01 02:57 - 00083968 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceEnroller.exe
2015-10-01 02:57 - 2015-10-01 02:57 - 00081488 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00079872 _____ (Microsoft Corporation) C:\WINDOWS\system32\HttpsDataSource.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00074880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\remoteaudioendpoint.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00073728 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwancfg.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00068096 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseDesktopAppMgmtCSP.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\usoapi.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00053760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Speech.Pal.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00041472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Speech.Pal.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00036352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\buttonconverter.sys
2015-10-01 02:57 - 2015-10-01 02:57 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\syncmlhook.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00026624 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManagerShellext.exe
2015-10-01 02:20 - 2015-10-09 00:09 - 00000000 ____D C:\Users\kathr\OneDrive\Documents\Keep
2015-10-01 02:20 - 2015-10-02 21:56 - 00000000 ____D C:\Users\kathr\OneDrive\Documents\_1 Writing
2015-10-01 02:20 - 2015-10-01 03:13 - 00000000 ____D C:\Users\kathr\OneDrive\Documents\Scriverner
2015-10-01 02:11 - 2015-10-05 00:01 - 00002126 _____ C:\Users\kathr\Desktop\DAZ Install Manager.lnk
2015-10-01 01:58 - 2015-10-01 01:58 - 00000000 _____ C:\d956d726f5b732d32501
2015-10-01 01:58 - 2015-10-01 01:58 - 00000000 _____ C:\c9112f9ef026831bf709
2015-10-01 01:46 - 2015-10-04 23:36 - 00000000 ___RD C:\Users\kathr\Creative Cloud Files (2)
2015-10-01 01:46 - 2015-10-03 17:20 - 00000000 ___RD C:\Users\kathr\Creative Cloud Files (1)
2015-10-01 01:06 - 2015-10-07 17:37 - 00000000 ____D C:\Users\kathr\AppData\LocalLow\LastPass
2015-10-01 00:20 - 2015-10-11 16:41 - 00000000 ____D C:\Users\kathr\OneDrive
2015-10-01 00:17 - 2015-10-01 00:17 - 00193336 _____ (Intel Corporation) C:\WINDOWS\system32\Drivers\TeeDriverW8x64.sys
2015-09-30 23:26 - 2015-10-02 23:58 - 01567576 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvhdagenco6420103.dll
2015-09-30 23:26 - 2015-09-30 23:26 - 01898312 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6435354.dll
2015-09-30 23:26 - 2015-09-30 23:26 - 01557832 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvir3dgenco64.dll
2015-09-30 23:26 - 2015-09-30 23:26 - 01557648 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6435354.dll
2015-09-30 23:26 - 2015-09-30 23:26 - 00452240 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvstusb.sys
2015-09-30 23:26 - 2015-09-30 23:26 - 00019976 _____ (ASUS) C:\WINDOWS\system32\Drivers\AsHIDSwitch64.sys
2015-09-30 21:54 - 2015-09-30 23:13 - 00000000 ____D C:\ESD
2015-09-30 21:45 - 2015-10-17 18:46 - 00000000 ____D C:\FRST
2015-09-17 23:31 - 2015-10-02 00:23 - 00000000 ____D C:\Users\kathr\Desktop\Settings-2015-09-09
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-10-14 03:07 - 2012-08-06 11:17 - 00017280 _____ ( ) C:\WINDOWS\system32\Drivers\kbfiltr.sys
2015-10-06 23:42 - 2013-07-18 13:55 - 00130248 _____ (Qualcomm Atheros Co., Ltd.) C:\WINDOWS\system32\Drivers\L1C63x64.sys
==================== Files in the root of some directories =======
2015-10-14 03:53 - 2015-10-14 03:53 - 0000036 _____ () C:\Users\kathr\AppData\Local\housecall.guid.cache
2015-10-08 15:52 - 2015-10-08 15:52 - 0000357 _____ () C:\Users\kathr\AppData\Local\LMIR0001.tmp_r.bat
2015-10-03 20:26 - 2015-10-16 15:20 - 0007641 _____ () C:\Users\kathr\AppData\Local\Resmon.ResmonCfg
2015-10-14 05:59 - 2015-10-16 20:59 - 0000010 _____ () C:\Users\kathr\AppData\Local\sponge.last.runtime.cache
2015-10-09 07:28 - 2015-10-09 07:28 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-10-14 09:20
==================== End of FRST.txt ============================
Additional scan result of Farbar Recovery Scan Tool (x64) Version:17-10-2015
Ran by kathryn (2015-10-17 18:46:48)
Running from C:\Users\kathr\Desktop
Windows 10 Pro (X64) (2015-10-02 15:02:37)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-4055827758-3256202687-3425098328-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-4055827758-3256202687-3425098328-503 - Limited - Disabled)
Guest (S-1-5-21-4055827758-3256202687-3425098328-501 - Limited - Disabled)
kathryn (S-1-5-21-4055827758-3256202687-3425098328-1001 - Administrator - Enabled) => C:\Users\kathr
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
FW: avast! Antivirus (Enabled) {2F96FC65-F07D-9D1E-5A6E-3DA5C487EAF0}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Adobe Acrobat DC (HKLM-x32\...\{AC76BA86-1033-FFFF-7760-0C0F074E4100}) (Version: 15.008.20082 - Adobe Systems Incorporated)
Adobe Audition CC 2015 (HKLM-x32\...\{839A3566-AED6-4787-A849-5CBE2B1DC6AE}) (Version: 8.0 - Adobe Systems Incorporated)
Adobe Creative Cloud (HKLM-x32\...\Adobe Creative Cloud) (Version: 3.3.0.151 - Adobe Systems Incorporated)
Adobe InDesign CC 2015 (HKLM-x32\...\{DBFD0312-6E55-1014-8952-E78D43BC0147}) (Version: 11.1.0.122 - Adobe Systems Incorporated)
Adobe Photoshop CC 2015 (HKLM-x32\...\{793C2BF7-A4FE-4608-91C9-9282C5801C21}) (Version: 16.0.1 - Adobe Systems Incorporated)
ATK Package (HKLM-x32\...\{AB5C933E-5C7D-4D30-B314-9C83A49B94BE}) (Version: 1.0.0039 - ASUS)
Avast Internet Security (HKLM-x32\...\Avast) (Version: 10.4.2233 - AVAST Software)
CryptoPrevent (HKLM-x32\...\{5C5B24E7-4694-4049-A222-CCE7D3FAC63F}_is1) (Version: - Foolish IT LLC)
DAZ Install Manager (HKLM-x32\...\DAZ Install Manager 1.1.0.41) (Version: 1.1.0.41 - DAZ 3D)
dMaintenance Home Edition v3.1.0 (HKLM-x32\...\{8198FCBE-715F-4C8A-B22B-DA73C6F2788F}_is1) (Version: - Foolish IT LLC)
ELAN Touchpad 11.5.19.2_X64_WHQL (HKLM\...\Elantech) (Version: 11.5.19.2 - ELAN Microelectronic Corp.)
FastPictureViewer Codec Pack 3.8.0.96 TRIAL EDITION (HKLM-x32\...\{BCFE2AFB-6600-462A-B088-A44AD7B52E69}) (Version: 3.8.0.96 - Axel Rietschin Software Developments)
GlassWire 1.1 (remove only) (HKLM-x32\...\GlassWire 1.1) (Version: 1.1.31 - SecureMix LLC)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 46.0.2490.71 - Google Inc.)
Google Update Helper (x32 Version: 1.3.28.15 - Google Inc.) Hidden
herdProtect Anti-Malware Scanner (HKLM-x32\...\herdProtectScan) (Version: 1.0 - Reason Company Software Inc.)
Kits Configuration Installer (x32 Version: 8.59.25584 - Microsoft) Hidden
LastPass (uninstall only) (HKLM-x32\...\LastPass) (Version: - LastPass)
Microsoft Office 365 - en-us (HKLM\...\O365HomePremRetail - en-us) (Version: 16.0.4229.1029 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23026 (HKLM-x32\...\{e46eca4f-393b-40df-9f49-076faf788d83}) (Version: 14.0.23026.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23026 (HKLM-x32\...\{74d0e5db-b326-4dae-a6b2-445b9de1836e}) (Version: 14.0.23026.0 - Microsoft Corporation)
NVIDIA 3D Vision Driver 358.50 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 358.50 - NVIDIA Corporation)
NVIDIA Graphics Driver 358.50 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 358.50 - NVIDIA Corporation)
NVIDIA HD Audio Driver 1.3.34.3 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.3 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.15.0428 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.15.0428 - NVIDIA Corporation)
Office 16 Click-to-Run Extensibility Component (Version: 16.0.4229.1029 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (Version: 16.0.4229.1029 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (Version: 16.0.4229.1029 - Microsoft Corporation) Hidden
Qualcomm Atheros Inc.® AR81Family Gigabit/Fast Ethernet Driver (HKLM-x32\...\{3108C217-BE83-42E4-AE9E-A56A2A92E549}) (Version: 2.1.0.21 - Qualcomm Atheros Inc.)
Scrivener (HKLM-x32\...\Scrivener 1860) (Version: 1860 - Literature and Latte)
VirusTotal Uploader 2.2 (HKLM-x32\...\VTUploader) (Version: - )
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.1 - VideoLAN)
Wacom Tablet (HKLM\...\Wacom Tablet Driver) (Version: 6.3.14-1 - Wacom Technology Corp.)
Windows Software Development Kit (HKLM-x32\...\{363a2c1e-637f-45ce-933b-5a5463efd945}) (Version: 8.59.29750 - Microsoft Corporation)
WinPatrol (HKLM-x32\...\{6A206A04-6BC1-411B-AA04-4E52EDEEADF2}) (Version: 33.1.2015.0 - Ruiware)
WPT Redistributables (x32 Version: 8.59.29750 - Microsoft) Hidden
WPTx64 (x32 Version: 8.59.29722 - Microsoft) Hidden
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-4055827758-3256202687-3425098328-1001_Classes\CLSID\{0E270DAA-1BE6-48F2-AC49-86B29D68EB0B}\InprocServer32 -> %%systemroot%%\system32\shell32.dll => No File
CustomCLSID: HKU\S-1-5-21-4055827758-3256202687-3425098328-1001_Classes\CLSID\{e8c77137-e224-5791-b6e9-ff0305797a13}\InprocServer32 -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems)
==================== Restore Points =========================
04-10-2015 19:46:14 boot
04-10-2015 19:47:33 boot
04-10-2015 19:48:19 boot
04-10-2015 19:57:06 Removed GeekBuddy.
04-10-2015 20:00:52 Windows Modules Installer
06-10-2015 13:41:08 Removed FastPictureViewer Professional 1.9.348.0 (64-bit)
06-10-2015 14:14:10 Installed FastPictureViewer Codec Pack 3.8.0.96 TRIAL EDITION
06-10-2015 14:22:31 Checkpoint by HitmanPro
06-10-2015 20:36:37 Restore Operation
06-10-2015 21:16:45 Installed FastPictureViewer Codec Pack 3.8.0.96 TRIAL EDITION
06-10-2015 21:45:15 afterrest_c
06-10-2015 21:46:01 afterrestore_G
06-10-2015 21:47:03 afterrestore_E
07-10-2015 01:10:35 Restore Point Created by FRST
07-10-2015 07:02:20 Removed ph.
07-10-2015 07:03:13 Removed WPT Redistributables
07-10-2015 07:03:53 Removed WPTx64
07-10-2015 07:28:47 Removed bl.
07-10-2015 17:31:09 Restore Operation
07-10-2015 17:45:53 Restore Point Created by FRST
08-10-2015 14:45:21 Removed bl.
08-10-2015 14:46:19 Removed ph.
08-10-2015 14:56:19 Restore Point Created by FRST
09-10-2015 10:02:24 Windows Modules Installer
09-10-2015 11:45:26 Installed WD Quick View
12-10-2015 08:57:50 Restore Point Created by FRST
12-10-2015 09:06:09 Restore Point Created by FRST
12-10-2015 10:25:43 Removed WD Quick View
12-10-2015 10:26:08 Removed Bonjour
12-10-2015 10:29:39 Removed WD My Cloud
12-10-2015 10:30:49 Removed WD Quick View
14-10-2015 02:57:27 Configured Qualcomm Atheros Inc.® AR81Family Gigabit/Fast EtheK¡;
14-10-2015 03:10:10 Installed ATK Package
17-10-2015 10:08:10 Windows Update
17-10-2015 15:03:28 Restore Point Created by FRST
==================== Hosts content: ===============================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2015-10-02 12:36 - 2015-10-16 18:33 - 00000768 ____A C:\WINDOWS\system32\Drivers\etc\hosts
127.0.0.1 localhost
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {0AB17DF1-5B8E-44C6-96AE-AED613CA7331} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2015-10-17] (AVAST Software)
Task: {242E0E14-F0F9-495E-93C5-5C05DD6AF25C} - System32\Tasks\Amazon Music Helper => C:\Users\kathr\AppData\Local\Amazon Music\Amazon Music Helper.exe
Task: {2EB45325-6A4E-469E-8808-4434449746EB} - System32\Tasks\
[email protected] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2015-09-04] (Adobe Systems Incorporated)
Task: {3739F324-5D7D-40CD-88CC-8CEDDE1BC848} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-10-03] (Google Inc.)
Task: {48240F87-4CEC-42FC-8F41-44369B6F8353} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2015-10-14] (Microsoft Corporation)
Task: {48682BDB-FA20-45B7-9B97-0017104153B4} - System32\Tasks\CreateExplorerShellUnelevatedTask => C:\WINDOWS\explorer.exe [2015-09-10] (Microsoft Corporation)
Task: {90B7C6D4-F1C9-493E-A34C-126378FFB57C} - System32\Tasks\{FAE41C42-E035-4FFE-81B1-F4404DFD0C0F} => pcalua.exe -a "C:\Program Files (x86)\HitmanPro.Alert\hmpalert.exe"
Task: {984146FB-DD1B-41F6-9D98-8164EBCEFF71} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-10-03] (Google Inc.)
Task: {9A2DED0E-9020-4378-BB78-9E9158D3BF2C} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2015-09-26] (Microsoft Corporation)
Task: {9AF1BA23-9125-4D55-9D32-D8A1EA1A8271} - System32\Tasks\RtHDVBg_ListenToDevice => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
Task: {A2ADAE73-86BC-478A-96C0-870F7DFD4DF2} - System32\Tasks\{A45DFF4C-AC84-4E0C-A331-3CB2D33F75F1} => pcalua.exe -a C:\PROGRA~3\INSTAL~1\{6A206~1\Setup.exe -c /remove /q0
Task: {AFBB18D8-A18A-4F14-8243-0A23C41284E4} - System32\Tasks\ATK Package A22126881260 => C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\SimAppExec.exe [2015-03-10] (ASUSTek Computer Inc.)
Task: {B6339BC1-406C-4290-B10D-CA5F364B6A1D} - System32\Tasks\CryptoPrevent Update => C:\Program Files (x86)\Foolish IT\CryptoPrevent\CryptoPrevent.exe [2015-04-10] (Foolish IT LLC)
Task: {D7C152ED-DE48-40E8-A534-9F9107455BA4} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-06-12] (Adobe Systems Incorporated)
Task: {D94A2258-53DC-4D0C-A0C1-2537DFABF196} - System32\Tasks\AdobeAAMUpdater-1.0-KATHRYNLAPTOP-kathryn => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2015-09-04] (Adobe Systems Incorporated)
Task: {DC819740-0F92-41AB-8412-17CEA0630F2F} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2015-09-26] (Microsoft Corporation)
Task: {F51BFBCD-C30F-425D-AA17-7C45BC376C07} - System32\Tasks\ATK Package 36D18D69AFC3 => C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\SimAppExec.exe [2015-03-10] (ASUSTek Computer Inc.)
Task: {F607940A-806B-43DD-A7AF-9E87BD05E9A3} - System32\Tasks\AdobeAAMUpdater-1.0-KATHRYNLAPTOP-kathr => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2015-09-04] (Adobe Systems Incorporated)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (Whitelisted) ==============
2015-07-09 22:33 - 2015-07-09 22:33 - 00028160 _____ () C:\WINDOWS\SYSTEM32\efsext.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00032768 _____ () C:\WINDOWS\SYSTEM32\licensemanagerapi.dll
2015-10-14 03:18 - 2015-10-02 21:38 - 00116344 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2015-09-10 00:08 - 2015-09-10 00:08 - 00404480 _____ () C:\WINDOWS\System32\diagtrack_wininternal.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 02494712 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
2015-10-14 04:52 - 2015-08-21 13:33 - 01347264 _____ () C:\Program Files\Tablet\Wacom\libxml2.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 02494712 _____ () C:\WINDOWS\System32\CoreUIComponents.dll
2015-10-01 02:57 - 2015-10-01 02:57 - 00429056 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll
2015-10-17 17:55 - 2015-10-17 17:55 - 00103376 _____ () C:\Program Files\AVAST Software\Avast\log.dll
2015-10-17 17:55 - 2015-10-17 17:55 - 00123976 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
2015-10-17 17:55 - 2015-10-17 17:55 - 02994032 _____ () C:\Program Files\AVAST Software\Avast\defs\15101701\algo.dll
2015-10-07 09:18 - 2015-10-07 09:18 - 00246272 _____ () C:\Program Files (x86)\GlassWire\GeoIP.dll
2015-10-17 17:55 - 2015-10-17 17:55 - 40539648 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
==================== Safe Mode (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot => "AlternateShell"=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\AutorunsDisabled => "AlternateShell"="cmd.exe"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppXSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BFE => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BITS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ClipSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MpsSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\msiserver => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SharedAccess => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vss => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WSService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\AppXSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\BITS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ClipSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\msiserver => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\vss => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WRkrn => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WRSVC => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\WSService => ""="Service"
==================== EXE Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
HKU\.DEFAULT\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION
HKU\.DEFAULT\Software\Classes\exefile: "%1" %* <===== ATTENTION
HKU\S-1-5-19\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION
HKU\S-1-5-19\Software\Classes\exefile: "%1" %* <===== ATTENTION
HKU\S-1-5-20\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION
HKU\S-1-5-20\Software\Classes\exefile: "%1" %* <===== ATTENTION
HKU\S-1-5-21-4055827758-3256202687-3425098328-1001\Software\Classes\.exe: exefile => "%1" %* <===== ATTENTION
HKU\S-1-5-21-4055827758-3256202687-3425098328-1001\Software\Classes\exefile: "%1" %* <===== ATTENTION
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
IE trusted site: HKU\S-1-5-21-4055827758-3256202687-3425098328-1001\...\trendmicro.com -> hxxps://pwm.trendmicro.com
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-4055827758-3256202687-3425098328-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\kathr\Desktop\Heart's Ransom cover\Heart's Ransom\Talon and Gwen Renders\best\heartsransomcover1.jpg
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: ) (EnableLUA: 1)
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
(Currently there is no automatic fix for this section.)
HKLM\...\StartupApproved\StartupFolder: => "Install LastPass IE RunOnce.lnk"
HKLM\...\StartupApproved\Run: => "AdobeAAMUpdater-1.0"
HKLM\...\StartupApproved\Run32: => "Adobe Creative Cloud"
HKLM\...\StartupApproved\Run32: => "LWS"
HKLM\...\StartupApproved\Run32: => "WD Quick View"
HKU\S-1-5-21-4055827758-3256202687-3425098328-1001\...\StartupApproved\StartupFolder: => "Logitech . Product Registration.lnk"
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [{A0A4089E-C7AF-490C-89E4-D2AB9341E4C2}] => (Allow) C:\Program Files (x86)\GlassWire\GWCtlSrv.exe
FirewallRules: [{6726C9C0-F095-479D-9C58-3B2C15CE537F}] => (Allow) C:\Program Files (x86)\GlassWire\GWCtlSrv.exe
==================== Faulty Device Manager Devices =============
Name: Intel® Management Engine Interface
Description: Intel® Management Engine Interface
Class Guid: {4d36e97d-e325-11ce-bfc1-08002be10318}
Manufacturer: Intel
Service: MEIx64
Problem: : A driver (service) for this device has been disabled. An alternate driver may be providing this functionality (Code 32)
Resolution: The start type for this driver is set to disabled in the registry.
Uninstall the driver from Device Manager, and then scan for new hardware to install the driver again. If this does not work, you might have to change the device start type parameter in the registry.
Name: ELAN Input Device
Description: ELAN Input Device
Class Guid: {4d36e96f-e325-11ce-bfc1-08002be10318}
Manufacturer: ELAN
Service: i8042prt
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.
==================== Event log errors: =========================
Application errors:
==================
Error: (10/17/2015 06:09:53 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: KATHRYNLAPTOP)
Description: Activation of app Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI failed with error: -2147024894 See the Microsoft-Windows-TWinUI/Operational log for additional information.
Error: (10/17/2015 05:49:11 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: KATHRYNLAPTOP)
Description: Activation of app Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI failed with error: -2147024894 See the Microsoft-Windows-TWinUI/Operational log for additional information.
Error: (10/17/2015 05:46:55 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: KATHRYNLAPTOP)
Description: Activation of app Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI failed with error: -2147024894 See the Microsoft-Windows-TWinUI/Operational log for additional information.
Error: (10/17/2015 05:35:20 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: KATHRYNLAPTOP)
Description: Activation of app Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI failed with error: -2147024894 See the Microsoft-Windows-TWinUI/Operational log for additional information.
Error: (10/17/2015 03:39:04 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: KATHRYNLAPTOP)
Description: Activation of app Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI failed with error: -2147024894 See the Microsoft-Windows-TWinUI/Operational log for additional information.
Error: (10/17/2015 03:27:59 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: KATHRYNLAPTOP)
Description: Activation of app Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI failed with error: -2147024894 See the Microsoft-Windows-TWinUI/Operational log for additional information.
Error: (10/17/2015 03:13:32 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: Wacom_Tablet.exe, version: 6.3.14.1, time stamp: 0x55d76d2d
Faulting module name: Wacom_Tablet.exe, version: 6.3.14.1, time stamp: 0x55d76d2d
Exception code: 0xc0000005
Fault offset: 0x00000000002b9389
Faulting process id: 0x12fc
Faulting application start time: 0xWacom_Tablet.exe0
Faulting application path: Wacom_Tablet.exe1
Faulting module path: Wacom_Tablet.exe2
Report Id: Wacom_Tablet.exe3
Faulting package full name: Wacom_Tablet.exe4
Faulting package-relative application ID: Wacom_Tablet.exe5
Error: (10/17/2015 03:13:25 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: KATHRYNLAPTOP)
Description: Activation of app Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI failed with error: -2147024894 See the Microsoft-Windows-TWinUI/Operational log for additional information.
Error: (10/17/2015 03:07:43 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: KATHRYNLAPTOP)
Description: Activation of app Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI failed with error: -2147024894 See the Microsoft-Windows-TWinUI/Operational log for additional information.
Error: (10/17/2015 03:02:18 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: KATHRYNLAPTOP)
Description: Activation of app Microsoft.Windows.Cortana_cw5n1h2txyewy!CortanaUI failed with error: -2147024894 See the Microsoft-Windows-TWinUI/Operational log for additional information.
System errors:
=============
Error: (10/17/2015 06:11:09 PM) (Source: DCOM) (EventID: 10016) (User: KATHRYNLAPTOP)
Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}KATHRYNLAPTOPkathrynS-1-5-21-4055827758-3256202687-3425098328-1001LocalHost (Using LRPC)Microsoft.Windows.Cortana_1.4.8.176_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742
Error: (10/17/2015 06:11:09 PM) (Source: DCOM) (EventID: 10016) (User: KATHRYNLAPTOP)
Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}KATHRYNLAPTOPkathrynS-1-5-21-4055827758-3256202687-3425098328-1001LocalHost (Using LRPC)Microsoft.Windows.Cortana_1.4.8.176_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742
Error: (10/17/2015 06:11:09 PM) (Source: DCOM) (EventID: 10016) (User: KATHRYNLAPTOP)
Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}KATHRYNLAPTOPkathrynS-1-5-21-4055827758-3256202687-3425098328-1001LocalHost (Using LRPC)Microsoft.Windows.Cortana_1.4.8.176_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742
Error: (10/17/2015 06:11:09 PM) (Source: DCOM) (EventID: 10016) (User: KATHRYNLAPTOP)
Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}KATHRYNLAPTOPkathrynS-1-5-21-4055827758-3256202687-3425098328-1001LocalHost (Using LRPC)Microsoft.Windows.Cortana_1.4.8.176_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742
Error: (10/17/2015 06:11:09 PM) (Source: DCOM) (EventID: 10016) (User: KATHRYNLAPTOP)
Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}KATHRYNLAPTOPkathrynS-1-5-21-4055827758-3256202687-3425098328-1001LocalHost (Using LRPC)Microsoft.Windows.Cortana_1.4.8.176_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742
Error: (10/17/2015 06:11:09 PM) (Source: DCOM) (EventID: 10016) (User: KATHRYNLAPTOP)
Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}KATHRYNLAPTOPkathrynS-1-5-21-4055827758-3256202687-3425098328-1001LocalHost (Using LRPC)Microsoft.Windows.Cortana_1.4.8.176_neutral_neutral_cw5n1h2txyewyS-1-15-2-1861897761-1695161497-2927542615-642690995-327840285-2659745135-2630312742
Error: (10/17/2015 06:09:53 PM) (Source: DCOM) (EventID: 10001) (User: KATHRYNLAPTOP)
Description: "C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe" -ServerName:CortanaUI.AppXa50dqqa5gqv4a428c9y1jjw7m3btvepj.mca2CortanaUIUnavailableUnavailable
Error: (10/17/2015 06:08:06 PM) (Source: NETLOGON) (EventID: 3095) (User: )
Description: This computer is configured as a member of a workgroup, not as
a member of a domain. The Netlogon service does not need to run in this
configuration.
Error: (10/17/2015 06:06:40 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The WWAN AutoConfig service terminated with the following error:
%%997
Error: (10/17/2015 06:07:34 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 5:48:03 PM on 10/17/2015 was unexpected.
CodeIntegrity:
===================================
Date: 2015-10-12 03:54:58.390
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume7\Program Files\Windows Defender\MsMpEng.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2015-10-11 21:03:58.376
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume7\Program Files\Windows Defender\MsMpEng.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2015-10-11 01:46:51.284
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume7\Program Files\Windows Defender\MsMpEng.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2015-10-10 11:28:42.996
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume7\Program Files\Windows Defender\MsMpEng.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2015-10-09 17:49:57.884
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume7\Program Files\Windows Defender\MsMpEng.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2015-10-09 15:50:00.426
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume7\Program Files\Windows Defender\MsMpEng.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2015-10-09 13:31:51.100
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume7\Program Files\Windows Defender\MsMpEng.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2015-10-09 10:49:07.548
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume7\Program Files\Windows Defender\MsMpEng.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2015-10-09 07:27:35.106
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume7\Program Files\Windows Defender\MsMpEng.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2015-10-09 02:45:00.869
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume7\Program Files\Windows Defender\MsMpEng.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
==================== Memory info ===========================
Processor: Intel® Core i7-4700HQ CPU @ 2.40GHz
Percentage of memory in use: 6%
Total physical RAM: 32685.47 MB
Available physical RAM: 30469.59 MB
Total Virtual: 37549.47 MB
Available Virtual: 35348.49 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:697.49 GB) (Free:391.27 GB) NTFS
Drive e: (Seagate) (Fixed) (Total:443.11 GB) (Free:328.57 GB) NTFS
Drive g: (Seagate BK) (Fixed) (Total:488.28 GB) (Free:236.67 GB) NTFS
Drive h: (450) (Fixed) (Total:0.44 GB) (Free:0.42 GB) NTFS
Drive i: () (Removable) (Total:29.72 GB) (Free:21.5 GB) FAT32
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 00000000)
Partition: GPT.
========================================================
Disk: 1 (MBR Code: Windows XP) (Size: 698.6 GB) (Disk ID: 748798B0)
Partition: GPT.
========================================================
Disk: 2 (Size: 29.7 GB) (Disk ID: 00000000)
Partition: GPT.
==================== End of Addition.txt ============================
I do have one question - why is it that even when I'm not connected to the internet every blasted service that is responsible for the network connection and internet communication continues to run? That really chews up my processor and my ram.
Thank you!