Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

media disconnected, bad DNS, no internet connections

baddns

  • Please log in to reply

#1
robyrob

robyrob

    New Member

  • Member
  • Pip
  • 6 posts

After removing a Safesearch infection, now have no internet connection. It actually worked for a couple of days after the removal, and there was a Windows Update possibly done in that time frame, but now I get no internet connection and am at wits end trying to figure this out.

 

 

This is a clean Windows 10 installation, got a Safesearch infection either on a driveby site or infected download; was able to remove the infection with Malwarebytes and ADWCleaner, it still required manual editing of the registry to remove policies to prevent changing default search settings in Chrome and Firefox.

 

At first I thought this was a coincidence and just a bad network card, so I brought another NIC card home from work and installed it and disabled the onboard NIC in the BIOS, rebooted and same problem - bad DNS settings and "media disconnected" in ipconfig /all. I tried replacing the cable, a different router (yet all other PC's attached to same router have no problems) ran netsh winsock reset catalog, netsh int ip reset, ipconfig /release, ipconfig /renew, netsh int ipv4 reset, netsh int ipv6 reset, deleted and reinstalled Winsock and Winsock2, WinsockReset 1.2, all to no avail. I tried a USB wireless card and it does the same thing - ipconfig shows invalid out-of-range DNS addresses and "media disconnected" for ALL network cards. The wireless card sees and I can log on to both my wireless routers but no internet. I can ping 127.0.0.1 but can't ping either router with or without the LAN card disabled.

 

It is difficult to post any screenshots or results because I have to copy everything to a USB drive and transfer everything manually.


  • 0

Advertisements


#2
RKinner

RKinner

    Malware Expert

  • Expert
  • 20,007 posts
  • MVP

I'm working a similar case.  The problem there is that a critical driver is apparently not signed and Windows doesn't want to let it start.  It was working fine until a Windows Update.  

 

Can you run

 

sigverif

 

from an elevated command prompt?  Then Press Start in the new window.  Does it complain about any drivers?  If so which ones?

 

If you look in the Windows, System event logs you might see a red flagged event about a service not starting.  Which one is it?


  • 0

#3
robyrob

robyrob

    New Member

  • Topic Starter
  • Member
  • Pip
  • 6 posts

I'm working a similar case.  The problem there is that a critical driver is apparently not signed and Windows doesn't want to let it start.  It was working fine until a Windows Update.  

 

Can you run

 

sigverif

 

from an elevated command prompt?  Then Press Start in the new window.  Does it complain about any drivers?  If so which ones?

 

If you look in the Windows, System event logs you might see a red flagged event about a service not starting.  Which one is it?

 

i did not see any driver problems, but I did try to reload each of the network card drivers (Win10 would not let me reinstall the orginal NIC drivers until I completely removed them and the card in the BIOS first), but I can run that when I get home. I was going to try run sfc /scannow and see if that finds anything.  


  • 0

#4
robyrob

robyrob

    New Member

  • Topic Starter
  • Member
  • Pip
  • 6 posts

C:\WINDOWS\system32>ipconfig /all

Windows IP Configuration

   Host Name . . . . . . . . . . . . : Robyn-PC
   Primary Dns Suffix  . . . . . . . :
   Node Type . . . . . . . . . . . . : Hybrid
   IP Routing Enabled. . . . . . . . : No
   WINS Proxy Enabled. . . . . . . . : No

Wireless LAN adapter Local Area Connection* 10:

   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . :
   Description . . . . . . . . . . . : Microsoft Wi-Fi Direct Virtual Adapter
   Physical Address. . . . . . . . . : DE-EF-09-D2-DC-C6
   DHCP Enabled. . . . . . . . . . . : Yes
   Autoconfiguration Enabled . . . . : Yes

Wireless LAN adapter Wi-Fi:

   Connection-specific DNS Suffix  . :
   Description . . . . . . . . . . . : NETGEAR A6100 WiFi Adapter
   Physical Address. . . . . . . . . : DC-EF-09-D2-DC-C6
   DHCP Enabled. . . . . . . . . . . : No
   Autoconfiguration Enabled . . . . : Yes
   IPv4 Address. . . . . . . . . . . : 192.168.1.111(Preferred)
   Subnet Mask . . . . . . . . . . . : 255.255.255.0
   Default Gateway . . . . . . . . . : 192.168.1.1
   DNS Servers . . . . . . . . . . . : 8.8.8.8
                                       8.8.4.4
   NetBIOS over Tcpip. . . . . . . . : Enabled

C:\WINDOWS\system32>


**note that the 192.168.1.111 is a static address I manually put in there - and while it says that it is connected to the internet, I can't connect to any websites or ping any domain names. I am able to ping addresses on the network and  can even ping 8.8.8.8 with a response, but even if I try put the IP address for a site in the address bar it says page not found. Occasionally the page not found error message is different and cryptic. If I let it get an IP automatically it gets an invalid 169.254.x.xxx address

I tried to run sfc /scannow which found errors but was unable to fix them. I actually tried to "reset Windows" but it seems to have not worked -at least I was anticipating having to reinstall all programs, but after a couple of hours and subsequent reboots absolutely nothing looks or works any differently.


  • 0

#5
RKinner

RKinner

    Malware Expert

  • Expert
  • 20,007 posts
  • MVP
 

 

Sometimes the following command will fix whatever sfc is complaining about:

 DISM.exe /Online /Cleanup-Image /RestoreHealth

Has to be run from an elevated Command Prompt (admin)

 

Run sfc /scannow again and then

 

The following will let us see what sfc couldn't fix.  This has to run in an elevated Command Prompt (Admin).  Easiest way is to just copy the two lines, open the command prompt (admin) and right click and paste (or edit then paste).  Hit Enter if notepad does not open.  
 

findstr  /c:"[SR]"  \windows\logs\cbs\cbs.log  >  \windows\logs\cbs\junk.txt 
notepad \windows\logs\cbs\junk.txt 

 

If you are able to ping the 8.8.8.8 then you have connectivity.  Either a firewall or a proxy setting is messing up the browser.

 

Let's try clearing the proxy:
 
In IE, Tools, Internet Options, Connections, LAN Settings, then uncheck all boxes and OK. Close IE and restart IE.
 
I think I will have them move this topic to malware so we can run FRST so I can see what is going on.
 

 
Please download Farbar Recovery Scan Tool and save it to your Desktop. 
 
Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version. 
 
  •  
  • Right click to run as administrator (XP users click run after receipt of Windows Security Warning - Open File). When the tool opens click Yes to disclaimer. 
  • Press Scan button. 
  • It will produce a log called FRST.txt in the same directory the tool is run from.  
  • Please copy and paste log back here. 
  • The first time the tool is run it generates another log (Addition.txt - also located in the same directory as FRST.exe/FRST64.exe). Please also paste that along with the FRST.txt into your reply. 
  •  

    • 0

    #6
    robyrob

    robyrob

      New Member

    • Topic Starter
    • Member
    • Pip
    • 6 posts

    junk.text: 2016-03-14 23:22:40, Info                  CSI    0000000a [SR] Verifying 1 components
    2016-03-14 23:22:40, Info                  CSI    0000000b [SR] Beginning Verify and Repair transaction
    2016-03-14 23:22:40, Info                  CSI    0000000d [SR] Verify complete
    2016-03-14 23:22:40, Info                  CSI    0000000e [SR] Verifying 1 components
    2016-03-14 23:22:40, Info                  CSI    0000000f [SR] Beginning Verify and Repair transaction
    2016-03-14 23:22:40, Info                  CSI    00000011 [SR] Verify complete
    2016-03-14 23:22:41, Info                  CSI    00000012 [SR] Verifying 1 components
    2016-03-14 23:22:41, Info                  CSI    00000013 [SR] Beginning Verify and Repair transaction
    2016-03-14 23:22:41, Info                  CSI    00000017 [SR] Verify complete
    2016-03-14 23:22:41, Info                  CSI    00000018 [SR] Verifying 1 components
    2016-03-14 23:22:41, Info                  CSI    00000019 [SR] Beginning Verify and Repair transaction
    2016-03-14 23:22:41, Info                  CSI    0000001b [SR] Verify complete
    2016-03-14 23:47:24, Info                  CSI    0000000a [SR] Verifying 1 components
    2016-03-14 23:47:24, Info                  CSI    0000000b [SR] Beginning Verify and Repair transaction
    2016-03-14 23:47:24, Info                  CSI    0000000d [SR] Verify complete
    2016-03-14 23:47:25, Info                  CSI    0000000e [SR] Verifying 1 components
    2016-03-14 23:47:25, Info                  CSI    0000000f [SR] Beginning Verify and Repair transaction
    2016-03-14 23:47:25, Info                  CSI    00000011 [SR] Verify complete
    2016-03-14 23:47:25, Info                  CSI    00000012 [SR] Verifying 1 components
    2016-03-14 23:47:25, Info                  CSI    00000013 [SR] Beginning Verify and Repair transaction
    2016-03-14 23:47:25, Info                  CSI    00000017 [SR] Verify complete
    2016-03-14 23:47:25, Info                  CSI    00000018 [SR] Verifying 1 components
    2016-03-14 23:47:25, Info                  CSI    00000019 [SR] Beginning Verify and Repair transaction
    2016-03-14 23:47:25, Info                  CSI    0000001b [SR] Verify complete
    2016-03-15 20:12:58, Info                  CSI    0000000a [SR] Verifying 100 (0x0000000000000064) components
    2016-03-15 20:12:58, Info                  CSI    0000000b [SR] Beginning Verify and Repair transaction
    2016-03-15 20:13:01, Info                  CSI    00000070 [SR] Verify complete
    2016-03-15 20:13:01, Info                  CSI    00000071 [SR] Verifying 100 (0x0000000000000064) components
    2016-03-15 20:13:01, Info                  CSI    00000072 [SR] Beginning Verify and Repair transaction
    2016-03-15 20:13:03, Info                  CSI    000000d7 [SR] Verify complete
    2016-03-15 20:13:03, Info                  CSI    000000d8 [SR] Verifying 100 (0x0000000000000064) components
    2016-03-15 20:13:03, Info                  CSI    000000d9 [SR] Beginning Verify and Repair transaction
    2016-03-15 20:13:06, Info                  CSI    0000013e [SR] Verify complete
    2016-03-15 20:13:06, Info                  CSI    0000013f [SR] Verifying 100 (0x0000000000000064) components
    2016-03-15 20:13:06, Info                  CSI    00000140 [SR] Beginning Verify and Repair transaction
    2016-03-15 20:13:08, Info                  CSI    000001a5 [SR] Verify complete
    2016-03-15 20:13:08, Info                  CSI    000001a6 [SR] Verifying 100 (0x0000000000000064) components
    2016-03-15 20:13:08, Info                  CSI    000001a7 [SR] Beginning Verify and Repair transaction
    2016-03-15 20:13:11, Info                  CSI    0000020c [SR] Verify complete
    2016-03-15 20:13:11, Info                  CSI    0000020d [SR] Verifying 100 (0x0000000000000064) components
    2016-03-15 20:13:11, Info                  CSI    0000020e [SR] Beginning Verify and Repair transaction
    2016-03-15 20:13:13, Info                  CSI    00000273 [SR] Verify complete
    2016-03-15 20:13:13, Info                  CSI    00000274 [SR] Verifying 100 (0x0000000000000064) components
    2016-03-15 20:13:13, Info                  CSI    00000275 [SR] Beginning Verify and Repair transaction
    2016-03-15 20:13:16, Info                  CSI    000002da [SR] Verify complete
    2016-03-15 20:13:16, Info                  CSI    000002db [SR] Verifying 100 (0x0000000000000064) components
    2016-03-15 20:13:16, Info                  CSI    000002dc [SR] Beginning Verify and Repair transaction
    2016-03-15 20:13:19, Info                  CSI    00000343 [SR] Verify complete
    2016-03-15 20:13:19, Info                  CSI    00000344 [SR] Verifying 100 (0x0000000000000064) components
    2016-03-15 20:13:19, Info                  CSI    00000345 [SR] Beginning Verify and Repair transaction
    2016-03-15 20:13:22, Info                  CSI    000003aa [SR] Verify complete
    2016-03-15 20:13:22, Info                  CSI    000003ab [SR] Verifying 100 (0x0000000000000064) components
    2016-03-15 20:13:22, Info                  CSI    000003ac [SR] Beginning Verify and Repair transaction
     

    FRST.txt:

     

    Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:05-03-2016 01
    Ran by Robyn (administrator) on ROBYN-PC (16-03-2016 20:59:41)
    Running from D:\Utilities
    Loaded Profiles: Robyn (Available Profiles: Robyn & DefaultAppPool)
    Platform: Windows 10 Pro Version 1511 (X64) Language: English (United States)
    Internet Explorer Version 11 (Default browser: Chrome)
    Boot Mode: Normal
    Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/

    ==================== Processes (Whitelisted) =================

    (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

    (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
    (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
    (Wacom Technology, Corp.) C:\Program Files\Tablet\Wacom\WTabletServicePro.exe
    (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
    (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
    (CHENGDU YIWO Tech Development Co., Ltd) G:\EaseUS\Todo Backup\bin\Agent.exe
    (Microsoft Corporation) C:\Windows\System32\mqsvc.exe
    (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
    (Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
    (Splashtop Inc.) C:\Program Files (x86)\Splashtop\Splashtop Software Updater\SSUService.exe
    (Realtek Semiconductor Corp.) C:\Program Files (x86)\NETGEAR\A6100\RtlService.exe
    (Splashtop Inc.) C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRService.exe
    (Skype Technologies S.A.) C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
    (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
    (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
    (Microsoft Corporation) C:\Windows\System32\vds.exe
    (Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
    (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.29.5\GoogleCrashHandler.exe
    (Microsoft Corporation) C:\Windows\System32\dllhost.exe
    (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.29.5\GoogleCrashHandler64.exe
    (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
    (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
    () G:\EaseUS\Todo Backup\bin\TodoBackupService.exe
    (Splashtop Inc.) C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRFeature.exe
    (Microsoft Corporation) C:\Windows\System32\InputMethod\CHS\ChsIME.exe
    (Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersServer.exe
    () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe
    (NETGEAR) C:\Program Files (x86)\NETGEAR\A6100\A6100.EXE
    (Splashtop Inc.) C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRFeature.exe
    (Wacom Technology, Corp.) C:\Program Files\Tablet\Wacom\Wacom_TabletUser.exe
    (Wacom Technology) C:\Program Files\Tablet\Wacom\WacomHost.exe
    (Wacom Technology, Corp.) C:\Program Files\Tablet\Wacom\Wacom_Tablet.exe
    (Wacom Technology, Corp.) C:\Program Files\Tablet\Wacom\Wacom_TouchUser.exe
    (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
    (Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
    (Logitech, Inc.) C:\Program Files\Common Files\Logishrd\KHAL3\KHALMNPR.exe
    (Logitech, Inc.) C:\Program Files\Logitech\SetPointG\SetPointII.exe
    (Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe
    (Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDMedia.exe
    (Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDCountdown.exe
    (Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDClock.exe
    (Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDPOP3.exe
    (Logitech Inc.) C:\Program Files\Logitech Gaming Software\Applets\LCDRSS.exe
    (Google Inc.) C:\Users\Robyn\AppData\Local\Google\Update\GoogleUpdate.exe
    (Electronic Arts) K:\Origin\Origin.exe
    (Akamai Technologies, Inc.) C:\Users\Robyn\AppData\Local\Akamai\netsession_win.exe
    (Akamai Technologies, Inc.) C:\Users\Robyn\AppData\Local\Akamai\netsession_win.exe
    (Apple Inc.) C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe
    (Valve Corporation) L:\Program Files (x86)\Steam\Steam.exe
    (Spotify Ltd) C:\Users\Robyn\AppData\Roaming\Spotify\SpotifyWebHelper.exe
    (Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
    () G:\EaseUS\TrayPopup\TrayTipAgent.exe
    (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
    (Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
    (Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ink\InputPersonalization.exe
    (Dropbox, Inc.) C:\Users\Robyn\AppData\Local\Dropbox\Update\DropboxUpdate.exe
    (Dropbox, Inc.) C:\Users\Robyn\AppData\Local\Dropbox\Update\DropboxUpdate.exe


    ==================== Registry (Whitelisted) ===========================

    (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

    HKLM\...\Run: [EvtMgr6] => C:\Program Files\Logitech\SetPointP\SetPoint.exe [1744152 2011-10-07] (Logitech, Inc.)
    HKLM\...\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [8290584 2013-08-01] (Logitech Inc.)
    HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [500208 2010-03-06] (Adobe Systems Incorporated)
    HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [170256 2015-08-13] (Apple Inc.)
    HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2789248 2016-02-17] (NVIDIA Corporation)
    HKLM\...\Run: [ShadowPlay] => "C:\WINDOWS\system32\rundll32.exe" C:\WINDOWS\system32\nvspcap64.dll,ShadowPlayOnSystemStart
    HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
    HKLM-x32\...\Run: [AdobeCS5ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe [402432 2010-07-22] (Adobe Systems Incorporated)
    HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [60712 2015-05-15] (Apple Inc.)
    HKLM-x32\...\Run: [Malwarebytes Anti-Exploit] => C:\Program Files (x86)\Malwarebytes Anti-Exploit\mbae.exe
    HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2015-06-17] (Apple Inc.)
    HKLM-x32\...\Run: [EaseUS TB Tray Agent] => G:\EaseUS\TrayPopup\TrayTipAgent.exe [253992 2014-12-15] ()
    HKLM-x32\...\Run: [Aeria Ignite] => G:\Program Files (x86)\Aeria Games\Ignite\aeriaignite.exe [1925656 2013-06-06] (Aeria Games & Entertainment)
    HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1085656 2015-12-14] (Adobe Systems Incorporated)
    HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [594992 2016-01-29] (Oracle Corporation)
    Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
    HKU\S-1-5-21-146372567-257526347-2578419968-1000\...\Run: [Google Update] => C:\Users\Robyn\AppData\Local\Google\Update\GoogleUpdate.exe [144200 2015-08-28] (Google Inc.)
    HKU\S-1-5-21-146372567-257526347-2578419968-1000\...\Run: [EADM] => K:\Origin\Origin.exe [3639280 2016-02-02] (Electronic Arts)
    HKU\S-1-5-21-146372567-257526347-2578419968-1000\...\Run: [Dropbox Update] => C:\Users\Robyn\AppData\Local\Dropbox\Update\DropboxUpdate.exe [134512 2015-06-16] (Dropbox, Inc.)
    HKU\S-1-5-21-146372567-257526347-2578419968-1000\...\Run: [Akamai NetSession Interface] => C:\Users\Robyn\AppData\Local\Akamai\netsession_win.exe [4691384 2015-09-10] (Akamai Technologies, Inc.)
    HKU\S-1-5-21-146372567-257526347-2578419968-1000\...\Run: [Steam] => L:\Program Files (x86)\Steam\steam.exe [3074128 2016-03-10] (Valve Corporation)
    HKU\S-1-5-21-146372567-257526347-2578419968-1000\...\Run: [Skype] => G:\Program Files (x86)\Skype\Phone\Skype.exe [50599552 2016-02-10] (Skype Technologies S.A.)
    HKU\S-1-5-21-146372567-257526347-2578419968-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8619224 2016-01-15] (Piriform Ltd)
    HKU\S-1-5-21-146372567-257526347-2578419968-1000\...\Run: [Spotify Web Helper] => C:\Users\Robyn\AppData\Roaming\Spotify\SpotifyWebHelper.exe [1524848 2016-03-13] (Spotify Ltd)
    HKU\S-1-5-21-146372567-257526347-2578419968-1000\...\Run: [Spotify] => C:\Users\Robyn\AppData\Roaming\Spotify\Spotify.exe [6754928 2016-03-13] (Spotify Ltd)
    HKU\S-1-5-21-146372567-257526347-2578419968-1000\...\Run: [Discord] => C:\Users\Robyn\AppData\Local\Discord\app-0.0.286\Discord.exe [53420216 2016-03-05] (Hammer & Chisel, Inc.)
    HKU\S-1-5-21-146372567-257526347-2578419968-1000\...\RunOnce: [Uninstall C:\Users\Robyn\AppData\Local\Microsoft\OneDrive\17.3.6281.1202_1\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Robyn\AppData\Local\Microsoft\OneDrive\17.3.6281.1202_1\amd64"
    HKU\S-1-5-21-146372567-257526347-2578419968-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\WINDOWS\system32\scrnsave.scr [31744 2015-10-30] (Microsoft Corporation)
    ShellIconOverlayIdentifiers: [  GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-02-24] (Google)
    ShellIconOverlayIdentifiers: [  GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-02-24] (Google)
    ShellIconOverlayIdentifiers: [  GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2016-02-24] (Google)
    ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Robyn\AppData\Roaming\Dropbox\bin\DropboxExt64.33.dll [2016-02-16] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Robyn\AppData\Roaming\Dropbox\bin\DropboxExt64.33.dll [2016-02-16] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Robyn\AppData\Roaming\Dropbox\bin\DropboxExt64.33.dll [2016-02-16] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Robyn\AppData\Roaming\Dropbox\bin\DropboxExt64.33.dll [2016-02-16] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers: [GDriveSharedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} =>  No File
    ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Robyn\AppData\Roaming\Dropbox\bin\DropboxExt.33.dll [2016-02-16] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Robyn\AppData\Roaming\Dropbox\bin\DropboxExt.33.dll [2016-02-16] (Dropbox, Inc.)
    ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Robyn\AppData\Roaming\Dropbox\bin\DropboxExt.33.dll [2016-02-16] (Dropbox, Inc.)
    Startup: C:\Users\Robyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Curse.lnk [2016-03-12]
    ShortcutTarget: Curse.lnk -> C:\Users\Robyn\AppData\Roaming\Curse Client\Bin\Curse.exe (Curse, Inc)
    Startup: C:\Users\Robyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CurseClientStartup.ccip [2013-06-24] ()
    Startup: C:\Users\Robyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2016-03-12]
    ShortcutTarget: Dropbox.lnk -> C:\Users\Robyn\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
    GroupPolicyScripts: Restriction <======= ATTENTION
    CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION

    ==================== Internet (Whitelisted) ====================

    (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

    Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
    Tcpip\..\Interfaces\{53efe221-5d6a-4e49-8dcf-19a24f5267fc}: [NameServer] 8.8.8.8,8.8.4.4

    Internet Explorer:
    ==================
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
    HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com
    SearchScopes: HKLM -> {2f23ab71-4ac6-41f2-a955-ea576e553146} URL =
    SearchScopes: HKLM-x32 -> DefaultScope value is missing
    SearchScopes: HKU\S-1-5-21-146372567-257526347-2578419968-1000 -> _tmp URL = hxxp://duckduckgo.com/?q={searchTerms}
    SearchScopes: HKU\S-1-5-21-146372567-257526347-2578419968-1000 -> {2f23ab71-4ac6-41f2-a955-ea576e553146} URL = hxxp://duckduckgo.com/?q={searchTerms}
    SearchScopes: HKU\S-1-5-21-146372567-257526347-2578419968-1000 -> {C08C99E0-FD77-49F6-A809-D624A9AF8019} URL = hxxps://search.yahoo.com/search?p={searchTerms}&fr=yset_ie_syc_oracle&type=orcl_default
    BHO: No Name -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> No File
    BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll => No File
    BHO-x32: Like -> {2159cb25-ef9a-54c1-b43c-e30d1a4a8277} -> C:\Windows\SysWOW64\mscoree.dll [2015-10-30] (Microsoft Corporation)
    BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_73\bin\ssv.dll [2016-02-09] (Oracle Corporation)
    BHO-x32: ArcPluginIEBHO Class -> {84BFE29A-8139-402a-B2A4-C23AE9E1A75F} -> L:\Arc\Plugins\ArcPluginIE.dll => No File
    BHO-x32: Simple -> {d94f51b0-ba26-454b-bf8d-7c495c5e3db6} -> C:\Windows\SysWOW64\mscoree.dll [2015-10-30] (Microsoft Corporation)
    BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_73\bin\jp2ssv.dll [2016-02-09] (Oracle Corporation)
    DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - G:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2013-09-16] (Skype Technologies S.A.)
    Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - G:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2013-09-16] (Skype Technologies S.A.)
    Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)

    FireFox:
    ========
    FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_21_0_0_182.dll [2016-03-11] ()
    FF Plugin: @java.com/DTPlugin,version=1.6.0_39 -> C:\Windows\system32\npdeployJava1.dll [2013-03-05] (Sun Microsystems, Inc.)
    FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] ( Microsoft Corporation)
    FF Plugin: @wacom.com/wtPlugin,version=2.1.0.3 -> C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll [2012-12-24] (Wacom)
    FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_21_0_0_182.dll [2016-03-11] ()
    FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2015-07-30] ()
    FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2015-05-21] (Google)
    FF Plugin-x32: @java.com/DTPlugin,version=11.73.2 -> C:\Program Files (x86)\Java\jre1.8.0_73\bin\dtplugin\npDeployJava1.dll [2016-02-09] (Oracle Corporation)
    FF Plugin-x32: @java.com/JavaPlugin,version=11.73.2 -> C:\Program Files (x86)\Java\jre1.8.0_73\bin\plugin2\npjp2.dll [2016-02-09] (Oracle Corporation)
    FF Plugin-x32: @logitech.com/HarmonyRemote,version=1.0.0 -> C:\Program Files (x86)\Logitech\Harmony Remote Driver\NprtHarmonyPlugin.dll [2012-09-28] (Logitech Inc.)
    FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.41212.0\npctrl.dll [2015-12-12] ( Microsoft Corporation)
    FF Plugin-x32: @nexon.net/NxGame -> C:\ProgramData\NexonUS\NGM\npNxGameUS.dll [2012-12-11] (Nexon)
    FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2016-02-23] (NVIDIA Corporation)
    FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2016-02-23] (NVIDIA Corporation)
    FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll [No File]
    FF Plugin-x32: @perfectworld.com/npArcPlayNowPlugin -> L:\Arc\Plugins\npArcPluginFF.dll [2015-12-03] (Perfect World Entertainment Inc)
    FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.)
    FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.)
    FF Plugin-x32: @wacom.com/wtPlugin,version=2.1.0.3 -> C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll [2012-12-24] (Wacom)
    FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-12-17] (Adobe Systems Inc.)
    FF Plugin HKU\S-1-5-21-146372567-257526347-2578419968-1000: @tools.google.com/Google Update;version=3 -> C:\Users\Robyn\AppData\Local\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.)
    FF Plugin HKU\S-1-5-21-146372567-257526347-2578419968-1000: @tools.google.com/Google Update;version=9 -> C:\Users\Robyn\AppData\Local\Google\Update\1.3.29.5\npGoogleUpdate3.dll [2016-02-02] (Google Inc.)
    FF Plugin HKU\S-1-5-21-146372567-257526347-2578419968-1000: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll [2013-03-21] (Ubisoft)
    FF Plugin HKU\S-1-5-21-146372567-257526347-2578419968-1000: wacom.com/WacomTabletPlugin -> C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll [2012-12-24] (Wacom)
    FF HKLM-x32\...\Firefox\Extensions: [{[email protected]}] - 1\extensions\{[email protected]} => not found

    Chrome:
    =======
    CHR Profile: C:\Users\Robyn\AppData\Local\Google\Chrome\User Data\Default
    CHR Extension: (Tab) - C:\Users\Robyn\AppData\Local\Google\Chrome\User Data\Default\Extensions\gdfjhiclilbjdpeejgcgebmmihkkofji [2016-03-12]
    CHR Extension: (Night Time In New York City) - C:\Users\Robyn\AppData\Local\Google\Chrome\User Data\Default\Extensions\jnimonidkipnhnpgkhgliocfnnpgkhek [2015-09-27]
    CHR Extension: (Skype) - C:\Users\Robyn\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2016-03-13]
    CHR Extension: (Chrome Web Store Payments) - C:\Users\Robyn\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-03-12]
    CHR Extension: (MyHarmony Chrome Plugin) - C:\Users\Robyn\AppData\Local\Google\Chrome\User Data\Default\Extensions\omaonpoimgkmbllpdihbnmgphjoipdhf [2016-03-12]
    CHR HKU\S-1-5-21-146372567-257526347-2578419968-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [gdfjhiclilbjdpeejgcgebmmihkkofji] - hxxps://clients2.google.com/service/update2/crx
    CHR HKLM-x32\...\Chrome\Extension: [gdfjhiclilbjdpeejgcgebmmihkkofji] - hxxps://clients2.google.com/service/update2/crx
    CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - G:\Program Files (x86)\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx [2013-09-16]
    CHR HKLM-x32\...\Chrome\Extension: [omaonpoimgkmbllpdihbnmgphjoipdhf] - C:\Program Files (x86)\Logitech\Harmony Remote Driver\harmony_chrome.crx [2013-01-06]
    StartMenuInternet: Google Chrome.MNMW62WLIJKEFTEA6VZS2PSLPY - C:\Users\Robyn\AppData\Local\Google\Chrome\Application\chrome.exe

    ==================== Services (Whitelisted) ========================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    S2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77128 2015-05-29] (Apple Inc.)
    S3 ArcService; L:\Arc\ArcService.exe [88400 2015-12-03] (Perfect World Entertainment Inc)
    S3 BRSptStub; C:\ProgramData\BitRaider\BRSptStub.exe [363208 2015-04-17] (BitRaider, LLC)
    R2 EaseUS Agent; G:\EaseUS\Todo Backup\bin\Agent.exe [36904 2015-08-01] (CHENGDU YIWO Tech Development Co., Ltd)
    R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1164672 2016-02-17] (NVIDIA Corporation)
    S2 HiPatchService; L:\HiPatchService.exe [8704 2015-09-02] (Hi-Rez Studios) [File not signed]
    S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1135416 2015-10-05] (Malwarebytes)
    S3 npggsvc; C:\WINDOWS\SysWOW64\GameMon.des [3685968 2015-07-22] (INCA Internet Co., Ltd.)
    R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1880960 2016-02-17] (NVIDIA Corporation)
    S3 NvStreamNetworkSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [6474112 2016-02-17] (NVIDIA Corporation)
    S2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [2609024 2016-02-17] (NVIDIA Corporation)
    S3 Origin Client Service; K:\Origin\OriginClientService.exe [2104840 2016-02-02] (Electronic Arts)
    R2 Realtek8723AU; C:\Program Files (x86)\NETGEAR\A6100\RtlService.exe [45784 2013-07-02] (Realtek Semiconductor Corp.)
    S2 SkypeUpdate; G:\Program Files (x86)\Skype\Updater\Updater.exe [327296 2015-07-09] (Skype Technologies)
    S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
    R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [364464 2015-10-30] (Microsoft Corporation)
    R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-10-30] (Microsoft Corporation)
    R2 WTabletServicePro; C:\Program Files\Tablet\Wacom\WTabletServicePro.exe [598808 2013-06-06] (Wacom Technology, Corp.)

    ===================== Drivers (Whitelisted) ==========================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    R3 A6100; C:\Windows\System32\drivers\A6100.sys [5004560 2016-03-14] (Realtek Semiconductor Corporation                           )
    R1 aswKbd; C:\Windows\System32\Drivers\aswKbd.sys [22600 2013-05-09] (AVAST Software)
    S3 BRDriver64_1_3_3_E02B25FC; C:\ProgramData\BitRaider\support\1.3.3\E02B25FC\BRDriver64.sys [78088 2015-04-17] (BitRaider)
    R3 CMUAC; C:\Windows\system32\DRIVERS\CMUAC.sys [661760 2015-12-25] (C-MEDIA)
    S3 epmntdrv; C:\Windows\system32\epmntdrv.sys [18528 2014-11-18] ()
    S3 epmntdrv; C:\Windows\SysWOW64\epmntdrv.sys [15968 2014-11-18] ()
    R0 EUBKMON; C:\Windows\System32\drivers\EUBKMON.sys [48168 2014-12-15] ()
    S3 EuGdiDrv; C:\Windows\system32\EuGdiDrv.sys [10848 2014-11-18] ()
    S3 EuGdiDrv; C:\Windows\SysWOW64\EuGdiDrv.sys [10208 2014-11-18] ()
    S3 hxsyol; C:\Windows\system32\hxsy64.sys [86352 2015-01-30] ()
    R3 LGSHidFilt; C:\Windows\system32\DRIVERS\LGSHidFilt.Sys [64280 2013-05-30] (Logitech Inc.)
    R3 MBAMProtector; C:\WINDOWS\system32\drivers\mbam.sys [25816 2015-10-05] (Malwarebytes)
    S3 MBAMWebAccessControl; C:\WINDOWS\system32\drivers\mwac.sys [64216 2015-10-05] (Malwarebytes Corporation)
    S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [28032 2016-02-17] (NVIDIA Corporation)
    R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [47760 2015-12-18] (NVIDIA Corporation)
    S3 pwdrvio; C:\Windows\system32\pwdrvio.sys [19152 2013-09-30] ()
    S3 pwdspio; C:\Windows\system32\pwdspio.sys [12504 2013-09-30] ()
    S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44568 2015-10-30] (Microsoft Corporation)
    R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [293216 2015-10-30] (Microsoft Corporation)
    R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [118112 2015-10-30] (Microsoft Corporation)
    S3 WinRing0_1_2_0; C:\Downloads\RealTemp_370 (1)\WinRing0x64.sys [14544 2016-02-03] (OpenLibSys.org)
    S3 xhunter1; C:\WINDOWS\xhunter1.sys [36904 2016-03-13] (Wellbia.com Co., Ltd.)
    U3 idsvc; no ImagePath

    ==================== NetSvcs (Whitelisted) ===================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


    ==================== One Month Created files and folders ========

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2016-03-16 20:31 - 2016-03-16 20:59 - 00000000 ____D C:\FRST
    2016-03-16 08:25 - 2016-03-16 08:25 - 00000000 _____ C:\Recovery.txt
    2016-03-16 08:05 - 2016-03-16 08:05 - 00000000 ___HD C:\$Windows.~BT
    2016-03-16 04:03 - 2016-03-16 08:25 - 00000000 ___HD C:\$SysReset
    2016-03-15 23:45 - 2016-03-15 23:45 - 00000000 _____ C:\Users\Robyn\AppData\Local\{B5D0D767-4EE2-4C02-B431-F57B06EAF781}
    2016-03-15 23:20 - 2016-03-15 23:20 - 00000000 ____D C:\Program Files\stinger
    2016-03-14 23:22 - 2016-03-14 23:22 - 00053248 _____ C:\WINDOWS\SysWOW64\zlib.dll
    2016-03-14 23:22 - 2016-03-14 23:22 - 00000000 ____D C:\Support
    2016-03-14 21:20 - 2016-03-14 21:20 - 05004560 _____ (Realtek Semiconductor Corporation ) C:\WINDOWS\system32\Drivers\A6100.sys
    2016-03-14 21:20 - 2016-03-14 21:20 - 00000000 ____D C:\WINDOWS\Downloaded Installations
    2016-03-14 21:20 - 2016-03-14 21:20 - 00000000 ____D C:\ProgramData\NETGEAR
    2016-03-14 21:20 - 2016-03-14 21:20 - 00000000 ____D C:\Program Files (x86)\NETGEAR
    2016-03-14 21:20 - 2013-08-21 23:20 - 00006588 _____ C:\WINDOWS\system32\Drivers\A6100_LMT.txt
    2016-03-14 21:20 - 2013-08-21 23:20 - 00001529 _____ C:\WINDOWS\system32\Drivers\A6100.txt
    2016-03-12 14:09 - 2016-03-12 14:09 - 00000000 ____D C:\AdsFix
    2016-03-12 14:07 - 2016-03-12 14:07 - 00000000 ____D C:\Users\Robyn\AppData\Roaming\abelhadigital.com
    2016-03-12 14:07 - 2016-03-12 14:07 - 00000000 ____D C:\ProgramData\abelhadigital.com
    2016-03-12 14:06 - 2016-03-12 14:06 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HostsMan
    2016-03-12 14:06 - 2016-03-12 14:06 - 00000000 ____D C:\Program Files (x86)\HostsMan
    2016-03-12 13:31 - 2016-03-12 15:01 - 00001165 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
    2016-03-12 13:31 - 2016-03-12 13:32 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
    2016-03-12 13:31 - 2016-03-12 13:31 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
    2016-03-12 13:31 - 2016-03-12 13:31 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
    2016-03-12 13:31 - 2015-10-05 10:50 - 00109272 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
    2016-03-12 13:31 - 2015-10-05 10:50 - 00064216 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\mwac.sys
    2016-03-12 13:31 - 2015-10-05 10:50 - 00025816 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
    2016-03-12 13:24 - 2016-03-12 13:24 - 00000000 ____D C:\Program Files (x86)\NpackdDetected
    2016-03-12 13:15 - 2016-03-12 13:17 - 00000000 ____D C:\Program Files (x86)\AdwCleaner
    2016-03-12 13:12 - 2016-03-12 13:12 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
    2016-03-12 08:12 - 2016-03-12 08:12 - 00000000 ____D C:\WINDOWS\System32\Tasks\Component System
    2016-03-12 08:11 - 2016-03-12 13:46 - 00000000 ____D C:\Users\Robyn\AppData\Local\intmanager
    2016-03-12 08:11 - 2016-03-12 13:24 - 00000000 ____D C:\ProgramData\Npackd
    2016-03-12 08:11 - 2016-03-12 13:24 - 00000000 ____D C:\Program Files (x86)\Simple
    2016-03-12 08:11 - 2016-03-12 08:11 - 00000000 ____D C:\Program Files (x86)\NpackdCL
    2016-03-12 08:10 - 2016-03-12 15:01 - 00000984 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Google Chrome.lnk
    2016-03-12 08:10 - 2016-03-12 15:00 - 00002194 _____ C:\Users\Robyn\AppData\Roaming\Microsoft\Windows\Start Menu\Amazon.lnk
    2016-03-12 08:10 - 2016-03-12 15:00 - 00001002 _____ C:\Users\Robyn\AppData\Roaming\Microsoft\Windows\Start Menu\Search.lnk
    2016-03-12 08:10 - 2016-03-12 14:59 - 00001149 _____ C:\Users\Robyn\Desktop\Internet Explorer.lnk
    2016-03-12 08:10 - 2016-03-12 08:11 - 00000884 __RSH C:\Users\Robyn\ntuser.pol
    2016-03-12 08:09 - 2016-03-12 08:09 - 00002640 __RSH C:\ProgramData\ntuser.pol
    2016-03-09 12:07 - 2016-03-01 01:31 - 00848168 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
    2016-03-09 12:07 - 2016-03-01 01:22 - 00709688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll
    2016-03-09 12:07 - 2016-02-24 05:52 - 01997328 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
    2016-03-09 12:07 - 2016-02-24 05:51 - 07474528 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
    2016-03-09 12:07 - 2016-02-24 05:34 - 01613664 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
    2016-03-09 12:07 - 2016-02-24 05:28 - 03449168 _____ (Microsoft Corporation) C:\WINDOWS\system32\WSService.dll
    2016-03-09 12:07 - 2016-02-24 05:15 - 01557768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
    2016-03-09 12:07 - 2016-02-24 04:51 - 01322248 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll
    2016-03-09 12:07 - 2016-02-24 04:50 - 00808800 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe
    2016-03-09 12:07 - 2016-02-24 04:46 - 06607080 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
    2016-03-09 12:07 - 2016-02-24 04:43 - 00625000 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipSVC.dll
    2016-03-09 12:07 - 2016-02-24 04:39 - 00141560 _____ (Microsoft Corporation) C:\WINDOWS\system32\AuthHost.exe
    2016-03-09 12:07 - 2016-02-24 04:11 - 01997152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
    2016-03-09 12:07 - 2016-02-24 04:11 - 00957608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll
    2016-03-09 12:07 - 2016-02-24 04:11 - 00652392 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxgi.dll
    2016-03-09 12:07 - 2016-02-24 04:06 - 05242496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
    2016-03-09 12:07 - 2016-02-24 03:39 - 00023552 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExtrasXmlParser.dll
    2016-03-09 12:07 - 2016-02-24 03:38 - 00111616 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataTimeUtil.dll
    2016-03-09 12:07 - 2016-02-24 03:37 - 00045056 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataLanguageUtil.dll
    2016-03-09 12:07 - 2016-02-24 03:36 - 00060416 _____ (Microsoft Corporation) C:\WINDOWS\system32\PimIndexMaintenanceClient.dll
    2016-03-09 12:07 - 2016-02-24 03:35 - 00523752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxgi.dll
    2016-03-09 12:07 - 2016-02-24 03:30 - 00025600 _____ (Microsoft Corporation) C:\WINDOWS\system32\wfapigp.dll
    2016-03-09 12:07 - 2016-02-24 03:28 - 00070656 _____ (Microsoft Corporation) C:\WINDOWS\system32\POSyncServices.dll
    2016-03-09 12:07 - 2016-02-24 03:23 - 00091648 _____ (Microsoft Corporation) C:\WINDOWS\system32\asycfilt.dll
    2016-03-09 12:07 - 2016-02-24 03:22 - 00196608 _____ (Microsoft Corporation) C:\WINDOWS\system32\fwpolicyiomgr.dll
    2016-03-09 12:07 - 2016-02-24 03:20 - 00195072 _____ (Microsoft Corporation) C:\WINDOWS\system32\VCardParser.dll
    2016-03-09 12:07 - 2016-02-24 03:20 - 00167936 _____ (Microsoft Corporation) C:\WINDOWS\system32\dafBth.dll
    2016-03-09 12:07 - 2016-02-24 03:19 - 00031232 _____ (Microsoft Corporation) C:\WINDOWS\system32\seclogon.dll
    2016-03-09 12:07 - 2016-02-24 03:15 - 00365568 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
    2016-03-09 12:07 - 2016-02-24 03:14 - 00274944 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExSMime.dll
    2016-03-09 12:07 - 2016-02-24 03:12 - 00243712 _____ (Microsoft Corporation) C:\WINDOWS\system32\cemapi.dll
    2016-03-09 12:07 - 2016-02-24 03:12 - 00221184 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneCallHistoryApis.dll
    2016-03-09 12:07 - 2016-02-24 03:09 - 00258560 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataAccountApis.dll
    2016-03-09 12:07 - 2016-02-24 03:09 - 00161792 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxSip.dll
    2016-03-09 12:07 - 2016-02-24 03:07 - 00252928 _____ (Microsoft Corporation) C:\WINDOWS\system32\PimIndexMaintenance.dll
    2016-03-09 12:07 - 2016-02-24 03:03 - 00088576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\olepro32.dll
    2016-03-09 12:07 - 2016-02-24 03:01 - 00146432 _____ (Microsoft Corporation) C:\WINDOWS\system32\AuthBroker.dll
    2016-03-09 12:07 - 2016-02-24 03:01 - 00067584 _____ (Microsoft Corporation) C:\WINDOWS\system32\profext.dll
    2016-03-09 12:07 - 2016-02-24 03:00 - 00214528 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Scanners.dll
    2016-03-09 12:07 - 2016-02-24 02:59 - 00318976 _____ (Microsoft Corporation) C:\WINDOWS\system32\domgmt.dll
    2016-03-09 12:07 - 2016-02-24 02:55 - 00790528 _____ (Microsoft Corporation) C:\WINDOWS\system32\EmailApis.dll
    2016-03-09 12:07 - 2016-02-24 02:55 - 00224256 _____ (Microsoft Corporation) C:\WINDOWS\system32\PackageStateRoaming.dll
    2016-03-09 12:07 - 2016-02-24 02:55 - 00018944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExtrasXmlParser.dll
    2016-03-09 12:07 - 2016-02-24 02:54 - 00526336 _____ (Microsoft Corporation) C:\WINDOWS\system32\FirewallAPI.dll
    2016-03-09 12:07 - 2016-02-24 02:54 - 00037888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataTypeHelperUtil.dll
    2016-03-09 12:07 - 2016-02-24 02:53 - 00089088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataTimeUtil.dll
    2016-03-09 12:07 - 2016-02-24 02:53 - 00037888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataLanguageUtil.dll
    2016-03-09 12:07 - 2016-02-24 02:52 - 00048128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PimIndexMaintenanceClient.dll
    2016-03-09 12:07 - 2016-02-24 02:49 - 00726528 _____ (Microsoft Corporation) C:\WINDOWS\system32\ChatApis.dll
    2016-03-09 12:07 - 2016-02-24 02:46 - 00020480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wfapigp.dll
    2016-03-09 12:07 - 2016-02-24 02:44 - 01713664 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRHInproc.dll
    2016-03-09 12:07 - 2016-02-24 02:44 - 00700416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppointmentApis.dll
    2016-03-09 12:07 - 2016-02-24 02:44 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\POSyncServices.dll
    2016-03-09 12:07 - 2016-02-24 02:43 - 00286720 _____ (Microsoft Corporation) C:\WINDOWS\system32\deviceaccess.dll
    2016-03-09 12:07 - 2016-02-24 02:41 - 00982016 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxPackaging.dll
    2016-03-09 12:07 - 2016-02-24 02:41 - 00436736 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll
    2016-03-09 12:07 - 2016-02-24 02:40 - 01224704 _____ (Microsoft Corporation) C:\WINDOWS\system32\Unistore.dll
    2016-03-09 12:07 - 2016-02-24 02:40 - 00056320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataPlatformHelperUtil.dll
    2016-03-09 12:07 - 2016-02-24 02:39 - 01390592 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
    2016-03-09 12:07 - 2016-02-24 02:39 - 00164864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fwpolicyiomgr.dll
    2016-03-09 12:07 - 2016-02-24 02:38 - 00150528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VCardParser.dll
    2016-03-09 12:07 - 2016-02-24 02:34 - 00938496 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContactApis.dll
    2016-03-09 12:07 - 2016-02-24 02:32 - 00223744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExSMime.dll
    2016-03-09 12:07 - 2016-02-24 02:32 - 00098304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppointmentActivation.dll
    2016-03-09 12:07 - 2016-02-24 02:31 - 00200704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cemapi.dll
    2016-03-09 12:07 - 2016-02-24 02:31 - 00169984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PhoneCallHistoryApis.dll
    2016-03-09 12:07 - 2016-02-24 02:28 - 00870912 _____ (Microsoft Corporation) C:\WINDOWS\system32\MPSSVC.dll
    2016-03-09 12:07 - 2016-02-24 02:28 - 00196608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataAccountApis.dll
    2016-03-09 12:07 - 2016-02-24 02:28 - 00135168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxSip.dll
    2016-03-09 12:07 - 2016-02-24 02:23 - 00129024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CallHistoryClient.dll
    2016-03-09 12:07 - 2016-02-24 02:22 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\profext.dll
    2016-03-09 12:07 - 2016-02-24 02:18 - 00575488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EmailApis.dll
    2016-03-09 12:07 - 2016-02-24 02:18 - 00184832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PackageStateRoaming.dll
    2016-03-09 12:07 - 2016-02-24 02:17 - 00369664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FirewallAPI.dll
    2016-03-09 12:07 - 2016-02-24 02:13 - 00540160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ChatApis.dll
    2016-03-09 12:07 - 2016-02-24 02:11 - 03593216 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
    2016-03-09 12:07 - 2016-02-24 02:09 - 00552960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppointmentApis.dll
    2016-03-09 12:07 - 2016-02-24 02:09 - 00228352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\deviceaccess.dll
    2016-03-09 12:07 - 2016-02-24 02:07 - 00949248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Unistore.dll
    2016-03-09 12:07 - 2016-02-24 02:07 - 00890368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxPackaging.dll
    2016-03-09 12:07 - 2016-02-24 02:07 - 00342528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll
    2016-03-09 12:07 - 2016-02-24 02:04 - 01497088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMPDMC.exe
    2016-03-09 12:07 - 2016-02-24 02:03 - 00769536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ContactApis.dll
    2016-03-09 12:07 - 2016-02-24 02:01 - 01831936 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll
    2016-03-09 12:07 - 2016-02-24 02:00 - 02273792 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
    2016-03-09 12:07 - 2016-02-24 02:00 - 01098752 _____ (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll
    2016-03-09 12:07 - 2016-02-24 01:55 - 01996288 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActiveSyncProvider.dll
    2016-03-09 12:07 - 2016-02-24 01:43 - 00184320 _____ (Microsoft Corporation) C:\WINDOWS\system32\fwbase.dll
    2016-03-09 12:07 - 2016-02-24 01:34 - 01707520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActiveSyncProvider.dll
    2016-03-09 12:07 - 2016-02-24 01:22 - 00163328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fwbase.dll
    2016-03-09 12:07 - 2016-02-24 01:20 - 22376960 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
    2016-03-09 12:07 - 2016-02-24 01:18 - 18677760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
    2016-03-09 12:07 - 2016-02-24 01:12 - 19339776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
    2016-03-09 12:07 - 2016-02-24 01:12 - 05321728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
    2016-03-09 12:07 - 2016-02-24 01:10 - 24600576 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
    2016-03-09 12:07 - 2016-02-24 01:09 - 06972416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
    2016-03-09 12:07 - 2016-02-24 01:05 - 12586496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll
    2016-03-09 12:07 - 2016-02-24 01:03 - 14252544 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll
    2016-03-09 12:07 - 2016-02-24 00:59 - 05661696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
    2016-03-09 12:07 - 2016-02-24 00:55 - 07835648 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
    2016-03-09 12:06 - 2016-02-24 05:48 - 00713568 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
    2016-03-09 12:06 - 2016-02-24 05:47 - 01173344 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
    2016-03-09 12:06 - 2016-02-24 05:40 - 00513888 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
    2016-03-09 12:06 - 2016-02-24 04:58 - 00794888 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfds.dll
    2016-03-09 12:06 - 2016-02-24 04:54 - 00127840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBSTOR.SYS
    2016-03-09 12:06 - 2016-02-24 04:39 - 00358752 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll
    2016-03-09 12:06 - 2016-02-24 04:19 - 00670928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfds.dll
    2016-03-09 12:06 - 2016-02-24 04:14 - 00216416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxAllUserStore.dll
    2016-03-09 12:06 - 2016-02-24 04:11 - 00703840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe
    2016-03-09 12:06 - 2016-02-24 04:11 - 00394080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
    2016-03-09 12:06 - 2016-02-24 04:11 - 00258280 _____ (Microsoft Corporation) C:\WINDOWS\system32\sqmapi.dll
    2016-03-09 12:06 - 2016-02-24 04:10 - 00630632 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
    2016-03-09 12:06 - 2016-02-24 04:10 - 00576864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
    2016-03-09 12:06 - 2016-02-24 04:09 - 00640472 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll
    2016-03-09 12:06 - 2016-02-24 04:09 - 00147808 _____ (Microsoft Corporation) C:\WINDOWS\system32\wermgr.exe
    2016-03-09 12:06 - 2016-02-24 03:59 - 00294752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll
    2016-03-09 12:06 - 2016-02-24 03:39 - 00045568 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataTypeHelperUtil.dll
    2016-03-09 12:06 - 2016-02-24 03:38 - 00187744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxAllUserStore.dll
    2016-03-09 12:06 - 2016-02-24 03:35 - 00540752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
    2016-03-09 12:06 - 2016-02-24 03:35 - 00220064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sqmapi.dll
    2016-03-09 12:06 - 2016-02-24 03:35 - 00045568 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
    2016-03-09 12:06 - 2016-02-24 03:33 - 00538736 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wer.dll
    2016-03-09 12:06 - 2016-02-24 03:33 - 00141664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wermgr.exe
    2016-03-09 12:06 - 2016-02-24 03:31 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontsub.dll
    2016-03-09 12:06 - 2016-02-24 03:23 - 00068096 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataPlatformHelperUtil.dll
    2016-03-09 12:06 - 2016-02-24 03:20 - 00087552 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxSysprep.dll
    2016-03-09 12:06 - 2016-02-24 03:19 - 00145408 _____ (Microsoft Corporation) C:\WINDOWS\system32\dssvc.dll
    2016-03-09 12:06 - 2016-02-24 03:13 - 00121856 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppointmentActivation.dll
    2016-03-09 12:06 - 2016-02-24 03:10 - 00093184 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpninprc.dll
    2016-03-09 12:06 - 2016-02-24 03:05 - 00208896 _____ (Microsoft Corporation) C:\WINDOWS\system32\storewuauth.dll
    2016-03-09 12:06 - 2016-02-24 03:02 - 00161280 _____ (Microsoft Corporation) C:\WINDOWS\system32\CallHistoryClient.dll
    2016-03-09 12:06 - 2016-02-24 03:01 - 00764928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
    2016-03-09 12:06 - 2016-02-24 02:59 - 00450560 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Bluetooth.dll
    2016-03-09 12:06 - 2016-02-24 02:59 - 00360448 _____ (Microsoft Corporation) C:\WINDOWS\system32\vaultsvc.dll
    2016-03-09 12:06 - 2016-02-24 02:58 - 00685568 _____ (Microsoft Corporation) C:\WINDOWS\system32\scapi.dll
    2016-03-09 12:06 - 2016-02-24 02:54 - 00288768 _____ (Microsoft Corporation) C:\WINDOWS\system32\vaultcli.dll
    2016-03-09 12:06 - 2016-02-24 02:54 - 00228352 _____ (Microsoft Corporation) C:\WINDOWS\system32\wsqmcons.exe
    2016-03-09 12:06 - 2016-02-24 02:52 - 00451584 _____ (Microsoft Corporation) C:\WINDOWS\system32\werui.dll
    2016-03-09 12:06 - 2016-02-24 02:51 - 00037376 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
    2016-03-09 12:06 - 2016-02-24 02:47 - 00093696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontsub.dll
    2016-03-09 12:06 - 2016-02-24 02:44 - 00915456 _____ (Microsoft Corporation) C:\WINDOWS\system32\configurationclient.dll
    2016-03-09 12:06 - 2016-02-24 02:43 - 00957952 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll
    2016-03-09 12:06 - 2016-02-24 02:40 - 00078848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\asycfilt.dll
    2016-03-09 12:06 - 2016-02-24 02:36 - 01847808 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMPDMC.exe
    2016-03-09 12:06 - 2016-02-24 02:34 - 00303104 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
    2016-03-09 12:06 - 2016-02-24 02:25 - 00401408 _____ (Microsoft Corporation) C:\WINDOWS\system32\sharemediacpl.dll
    2016-03-09 12:06 - 2016-02-24 02:21 - 00315904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Bluetooth.dll
    2016-03-09 12:06 - 2016-02-24 02:21 - 00168448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Scanners.dll
    2016-03-09 12:06 - 2016-02-24 02:18 - 01490432 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataService.dll
    2016-03-09 12:06 - 2016-02-24 02:16 - 00394752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\werui.dll
    2016-03-09 12:06 - 2016-02-24 02:09 - 01443328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRHInproc.dll
    2016-03-09 12:06 - 2016-02-24 02:09 - 00793600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRH.dll
    2016-03-09 12:06 - 2016-02-24 01:57 - 02158592 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
    2016-03-08 10:01 - 2016-03-12 15:01 - 00002200 _____ C:\Users\Public\Desktop\3D Vision Photo Viewer.lnk
    2016-03-08 10:00 - 2016-02-23 15:59 - 00111672 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvStreaming.exe
    2016-03-08 09:58 - 2016-02-23 19:57 - 42983480 _____ C:\WINDOWS\system32\nvcompiler.dll
    2016-03-08 09:58 - 2016-02-23 19:57 - 37616184 _____ C:\WINDOWS\SysWOW64\nvcompiler.dll
    2016-03-08 09:58 - 2016-02-23 19:57 - 24944064 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglv32.dll
    2016-03-08 09:58 - 2016-02-23 19:57 - 21201784 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvopencl.dll
    2016-03-08 09:58 - 2016-02-23 19:57 - 20742072 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuda.dll
    2016-03-08 09:58 - 2016-02-23 19:57 - 17631304 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvopencl.dll
    2016-03-08 09:58 - 2016-02-23 19:57 - 17224472 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuda.dll
    2016-03-08 09:58 - 2016-02-23 19:57 - 17117128 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvd3dumx.dll
    2016-03-08 09:58 - 2016-02-23 19:57 - 02541504 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcuvid.dll
    2016-03-08 09:58 - 2016-02-23 19:57 - 02187712 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvcuvid.dll
    2016-03-08 09:58 - 2016-02-23 19:57 - 01924152 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispco6436200.dll
    2016-03-08 09:58 - 2016-02-23 19:57 - 01571776 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvdispgenco6436200.dll
    2016-03-08 09:58 - 2016-02-23 19:57 - 00950328 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvFBC64.dll
    2016-03-08 09:58 - 2016-02-23 19:57 - 00880576 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFR64.dll
    2016-03-08 09:58 - 2016-02-23 19:57 - 00786688 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncMFTH264.dll
    2016-03-08 09:58 - 2016-02-23 19:57 - 00784824 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncMFThevc.dll
    2016-03-08 09:58 - 2016-02-23 19:57 - 00747064 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvFBC.dll
    2016-03-08 09:58 - 2016-02-23 19:57 - 00689600 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFR.dll
    2016-03-08 09:58 - 2016-02-23 19:57 - 00632336 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncMFTH264.dll
    2016-03-08 09:58 - 2016-02-23 19:57 - 00630776 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncMFThevc.dll
    2016-03-08 09:58 - 2016-02-23 19:57 - 00601936 _____ C:\WINDOWS\system32\nvmcumd.dll
    2016-03-08 09:58 - 2016-02-23 19:57 - 00541184 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvumdshimx.dll
    2016-03-08 09:58 - 2016-02-23 19:57 - 00445912 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvumdshim.dll
    2016-03-08 09:58 - 2016-02-23 19:57 - 00425016 _____ (NVIDIA Corporation) C:\WINDOWS\system32\NvIFROpenGL.dll
    2016-03-08 09:58 - 2016-02-23 19:57 - 00383424 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvDecMFTMjpeg.dll
    2016-03-08 09:58 - 2016-02-23 19:57 - 00379448 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\NvIFROpenGL.dll
    2016-03-08 09:58 - 2016-02-23 19:57 - 00378968 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvEncodeAPI64.dll
    2016-03-08 09:58 - 2016-02-23 19:57 - 00346560 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvDecMFTMjpeg.dll
    2016-03-08 09:58 - 2016-02-23 19:57 - 00316960 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvEncodeAPI.dll
    2016-03-08 09:58 - 2016-02-23 19:57 - 00175552 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvinitx.dll
    2016-03-08 09:58 - 2016-02-23 19:57 - 00153208 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvinit.dll
    2016-03-08 09:58 - 2016-02-23 19:57 - 00151368 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglshim64.dll
    2016-03-08 09:58 - 2016-02-23 19:57 - 00128512 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvoglshim32.dll
    2016-03-08 09:58 - 2016-02-23 19:57 - 00039240 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvhdap64.dll
    2016-03-05 07:44 - 2016-03-12 15:01 - 00001509 _____ C:\Users\Public\Desktop\Blade & Soul.lnk
    2016-03-05 01:33 - 2016-03-05 01:33 - 690255447 _____ C:\WINDOWS\MEMORY.DMP
    2016-03-05 01:33 - 2016-03-05 01:33 - 00878148 _____ C:\WINDOWS\Minidump\030516-10203-01.dmp
    2016-03-05 01:33 - 2016-03-05 01:33 - 00000000 ____D C:\WINDOWS\Minidump
    2016-03-02 09:24 - 2016-02-23 07:25 - 01818696 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
    2016-03-02 09:24 - 2016-02-23 07:25 - 00563552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\acpi.sys
    2016-03-02 09:24 - 2016-02-23 07:15 - 00779384 _____ (Microsoft Corporation) C:\WINDOWS\system32\taskschd.dll
    2016-03-02 09:24 - 2016-02-23 06:34 - 01542816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
    2016-03-02 09:24 - 2016-02-23 06:33 - 00389992 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanapi.dll
    2016-03-02 09:24 - 2016-02-23 06:32 - 08705672 _____ (Microsoft Corp.) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
    2016-03-02 09:24 - 2016-02-23 06:32 - 02544264 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
    2016-03-02 09:24 - 2016-02-23 06:32 - 00369912 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
    2016-03-02 09:24 - 2016-02-23 06:31 - 00536256 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
    2016-03-02 09:24 - 2016-02-23 06:31 - 00476728 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvproc.dll
    2016-03-02 09:24 - 2016-02-23 06:31 - 00408120 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll
    2016-03-02 09:24 - 2016-02-23 06:22 - 00572272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\taskschd.dll
    2016-03-02 09:24 - 2016-02-23 06:17 - 00146272 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\appid.sys
    2016-03-02 09:24 - 2016-02-23 05:45 - 02773096 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11.dll
    2016-03-02 09:24 - 2016-02-23 05:38 - 06952088 _____ (Microsoft Corp.) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
    2016-03-02 09:24 - 2016-02-23 05:38 - 00420928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvproc.dll
    2016-03-02 09:24 - 2016-02-23 05:27 - 21124344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
    2016-03-02 09:24 - 2016-02-23 05:20 - 00238592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\xboxgip.sys
    2016-03-02 09:24 - 2016-02-23 05:19 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\xinputhid.sys
    2016-03-02 09:24 - 2016-02-23 05:10 - 00027648 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiFiConfigSP.dll
    2016-03-02 09:24 - 2016-02-23 05:00 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseDesktopAppMgmtCSP.dll
    2016-03-02 09:24 - 2016-02-23 04:58 - 00069632 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininetlui.dll
    2016-03-02 09:24 - 2016-02-23 04:58 - 00025088 _____ (Microsoft Corporation) C:\WINDOWS\system32\irmon.dll
    2016-03-02 09:24 - 2016-02-23 04:55 - 00114688 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bridge.sys
    2016-03-02 09:24 - 2016-02-23 04:53 - 00115712 _____ (Microsoft Corporation) C:\WINDOWS\system32\srpapi.dll
    2016-03-02 09:24 - 2016-02-23 04:52 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDMAppInstaller.exe
    2016-03-02 09:24 - 2016-02-23 04:48 - 00041984 _____ (Microsoft Corporation) C:\WINDOWS\system32\TimeBrokerClient.dll
    2016-03-02 09:24 - 2016-02-23 04:40 - 00074240 _____ (Microsoft Corporation) C:\WINDOWS\system32\SMSRouter.dll
    2016-03-02 09:24 - 2016-02-23 04:39 - 00178176 _____ (Microsoft Corporation) C:\WINDOWS\system32\psmsrv.dll
    2016-03-02 09:24 - 2016-02-23 04:38 - 00287712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.MediaControl.dll
    2016-03-02 09:24 - 2016-02-23 04:37 - 00274944 _____ (Microsoft Corporation) C:\WINDOWS\system32\DisplayManager.dll
    2016-03-02 09:24 - 2016-02-23 04:36 - 00216576 _____ (Microsoft Corporation) C:\WINDOWS\system32\QuickActionsDataModel.dll
    2016-03-02 09:24 - 2016-02-23 04:34 - 00305664 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifiprofilessettinghandler.dll
    2016-03-02 09:24 - 2016-02-23 04:31 - 00463360 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansec.dll
    2016-03-02 09:24 - 2016-02-23 04:28 - 00275456 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
    2016-03-02 09:24 - 2016-02-23 04:27 - 00307712 _____ (Microsoft Corporation) C:\WINDOWS\system32\usbmon.dll
    2016-03-02 09:24 - 2016-02-23 04:23 - 00412672 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlanmsm.dll
    2016-03-02 09:24 - 2016-02-23 04:20 - 00847360 _____ (Microsoft Corporation) C:\WINDOWS\system32\netlogon.dll
    2016-03-02 09:24 - 2016-02-23 04:20 - 00330240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
    2016-03-02 09:24 - 2016-02-23 04:18 - 00557056 _____ (Microsoft Corporation) C:\WINDOWS\system32\PsmServiceExtHost.dll
    2016-03-02 09:24 - 2016-02-23 04:14 - 00828928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.AccountsControl.dll
    2016-03-02 09:24 - 2016-02-23 04:12 - 00852480 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
    2016-03-02 09:24 - 2016-02-23 04:11 - 00587776 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll
    2016-03-02 09:24 - 2016-02-23 04:10 - 00997376 _____ (Microsoft Corporation) C:\WINDOWS\system32\schedsvc.dll
    2016-03-02 09:24 - 2016-02-23 04:09 - 01054208 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
    2016-03-02 09:24 - 2016-02-23 04:06 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininetlui.dll
    2016-03-02 09:24 - 2016-02-23 04:06 - 00045568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jsproxy.dll
    2016-03-02 09:24 - 2016-02-23 04:04 - 00673792 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.dll
    2016-03-02 09:24 - 2016-02-23 04:04 - 00382464 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll
    2016-03-02 09:24 - 2016-02-23 04:02 - 01318912 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifinetworkmanager.dll
    2016-03-02 09:24 - 2016-02-23 04:00 - 02624512 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll
    2016-03-02 09:24 - 2016-02-23 03:58 - 00345600 _____ (Microsoft Corporation) C:\WINDOWS\system32\TextInputFramework.dll
    2016-03-02 09:24 - 2016-02-23 03:58 - 00175616 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll
    2016-03-02 09:24 - 2016-02-23 03:58 - 00163840 _____ (Microsoft Corporation) C:\WINDOWS\system32\TimeBrokerServer.dll
    2016-03-02 09:24 - 2016-02-23 03:57 - 00031744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TimeBrokerClient.dll
    2016-03-02 09:24 - 2016-02-23 03:49 - 00200704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DisplayManager.dll
    2016-03-02 09:24 - 2016-02-23 03:48 - 00838144 _____ (Microsoft Corporation) C:\WINDOWS\system32\uDWM.dll
    2016-03-02 09:24 - 2016-02-23 03:37 - 01118208 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll
    2016-03-02 09:24 - 2016-02-23 03:37 - 00613376 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSync.dll
    2016-03-02 09:24 - 2016-02-23 03:36 - 00713728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netlogon.dll
    2016-03-02 09:24 - 2016-02-23 03:36 - 00250880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
    2016-03-02 09:24 - 2016-02-23 03:31 - 00585216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.AccountsControl.dll
    2016-03-02 09:24 - 2016-02-23 03:30 - 01731584 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
    2016-03-02 09:24 - 2016-02-23 03:30 - 00646656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll
    2016-03-02 09:24 - 2016-02-23 03:28 - 00555520 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncController.dll
    2016-03-02 09:24 - 2016-02-23 03:28 - 00256512 _____ (Microsoft Corporation) C:\WINDOWS\system32\accountaccessor.dll
    2016-03-02 09:24 - 2016-02-23 03:24 - 04827136 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExplorerFrame.dll
    2016-03-02 09:24 - 2016-02-23 03:24 - 02755584 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
    2016-03-02 09:24 - 2016-02-23 03:22 - 01944576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputService.dll
    2016-03-02 09:24 - 2016-02-23 03:21 - 00245760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TextInputFramework.dll
    2016-03-02 09:24 - 2016-02-23 03:21 - 00133632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Core.TextInput.dll
    2016-03-02 09:24 - 2016-02-23 03:05 - 00503296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSync.dll
    2016-03-02 09:24 - 2016-02-23 03:01 - 02295808 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll
    2016-03-02 09:24 - 2016-02-23 02:59 - 01500672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
    2016-03-02 09:24 - 2016-02-23 02:58 - 00450560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SyncController.dll
    2016-03-02 09:24 - 2016-02-23 02:56 - 04412928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExplorerFrame.dll
    2016-03-02 09:24 - 2016-02-23 02:55 - 04894208 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
    2016-03-02 09:24 - 2016-02-23 02:55 - 02229760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
    2016-03-02 09:24 - 2016-02-23 02:53 - 01799168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Logon.dll
    2016-03-02 09:24 - 2016-02-23 02:52 - 11545600 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
    2016-03-02 09:24 - 2016-02-23 02:51 - 00754176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncCore.dll
    2016-03-02 09:24 - 2016-02-23 02:50 - 09919488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
    2016-03-02 09:24 - 2016-02-23 02:41 - 02912256 _____ (Microsoft Corporation) C:\WINDOWS\system32\CertEnroll.dll
    2016-03-02 09:24 - 2016-02-23 02:39 - 13382656 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
    2016-03-02 09:24 - 2016-02-23 02:36 - 12125696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
    2016-03-02 09:24 - 2016-02-23 02:36 - 03666432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
    2016-03-02 09:24 - 2016-02-23 02:35 - 07533568 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
    2016-03-02 09:24 - 2016-02-23 02:33 - 02604032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CertEnroll.dll
    2016-03-02 09:24 - 2016-02-23 02:28 - 06740992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll
    2016-03-02 09:24 - 2016-02-08 23:24 - 00641536 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
    2016-03-02 09:24 - 2016-02-08 23:18 - 00237056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\thumbcache.dll
    2016-03-02 09:24 - 2016-02-08 23:07 - 01626624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
    2016-03-02 09:24 - 2016-02-08 23:07 - 00086016 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceEnroller.exe
    2016-03-02 09:24 - 2016-02-08 23:04 - 01946624 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
    2016-03-02 09:23 - 2016-02-23 07:29 - 01030416 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
    2016-03-02 09:23 - 2016-02-23 07:29 - 00874968 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
    2016-03-02 09:23 - 2016-02-23 07:27 - 02654872 _____ C:\WINDOWS\system32\CoreUIComponents.dll
    2016-03-02 09:23 - 2016-02-23 07:27 - 01317640 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
    2016-03-02 09:23 - 2016-02-23 07:27 - 01141504 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
    2016-03-02 09:23 - 2016-02-23 07:25 - 02152288 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
    2016-03-02 09:23 - 2016-02-23 07:08 - 00989536 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
    2016-03-02 09:23 - 2016-02-23 06:34 - 01859960 _____ C:\WINDOWS\SysWOW64\CoreUIComponents.dll
    2016-03-02 09:23 - 2016-02-23 06:33 - 00696160 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupEngine.dll
    2016-03-02 09:23 - 2016-02-23 06:32 - 01152328 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfasfsrcsnk.dll
    2016-03-02 09:23 - 2016-02-23 06:32 - 01062480 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll
    2016-03-02 09:23 - 2016-02-23 06:32 - 00498448 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFCaptureEngine.dll
    2016-03-02 09:23 - 2016-02-23 06:31 - 01017032 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsrcsnk.dll
    2016-03-02 09:23 - 2016-02-23 06:31 - 00819648 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmpeg2srcsnk.dll
    2016-03-02 09:23 - 2016-02-23 06:25 - 03671888 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
    2016-03-02 09:23 - 2016-02-23 06:21 - 22564328 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
    2016-03-02 09:23 - 2016-02-23 05:40 - 00430944 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb.sys
    2016-03-02 09:23 - 2016-02-23 05:39 - 00502112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupEngine.dll
    2016-03-02 09:23 - 2016-02-23 05:38 - 02180136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
    2016-03-02 09:23 - 2016-02-23 05:38 - 00980352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfasfsrcsnk.dll
    2016-03-02 09:23 - 2016-02-23 05:38 - 00895080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsrcsnk.dll
    2016-03-02 09:23 - 2016-02-23 05:38 - 00882720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll
    2016-03-02 09:23 - 2016-02-23 05:38 - 00450912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFCaptureEngine.dll
    2016-03-02 09:23 - 2016-02-23 05:37 - 00713824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmpeg2srcsnk.dll
    2016-03-02 09:23 - 2016-02-23 05:32 - 00791744 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
    2016-03-02 09:23 - 2016-02-23 05:30 - 02919320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
    2016-03-02 09:23 - 2016-02-23 05:27 - 00376536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.MediaControl.dll
    2016-03-02 09:23 - 2016-02-23 05:25 - 00534368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBHUB3.SYS
    2016-03-02 09:23 - 2016-02-23 05:20 - 01139712 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblGameSave.dll
    2016-03-02 09:23 - 2016-02-23 05:17 - 00649216 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngcsvc.dll
    2016-03-02 09:23 - 2016-02-23 05:12 - 00077824 _____ (Microsoft Corporation) C:\WINDOWS\system32\provpackageapidll.dll
    2016-03-02 09:23 - 2016-02-23 05:07 - 00037376 _____ (Microsoft Corporation) C:\WINDOWS\system32\LaunchWinApp.exe
    2016-03-02 09:23 - 2016-02-23 05:07 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvcpal.dll
    2016-03-02 09:23 - 2016-02-23 05:06 - 00129536 _____ (Microsoft Corporation) C:\WINDOWS\system32\flvprophandler.dll
    2016-03-02 09:23 - 2016-02-23 05:01 - 00104960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rasl2tp.sys
    2016-03-02 09:23 - 2016-02-23 05:00 - 00048640 _____ (Microsoft Corporation) C:\WINDOWS\system32\wfdprov.dll
    2016-03-02 09:23 - 2016-02-23 04:58 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\system32\jsproxy.dll
    2016-03-02 09:23 - 2016-02-23 04:57 - 00199168 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe
    2016-03-02 09:23 - 2016-02-23 04:56 - 02186864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11.dll
    2016-03-02 09:23 - 2016-02-23 04:53 - 00099328 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngckeyenum.dll
    2016-03-02 09:23 - 2016-02-23 04:50 - 00159232 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCensus.exe
    2016-03-02 09:23 - 2016-02-23 04:48 - 00086528 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppCapture.dll
    2016-03-02 09:23 - 2016-02-23 04:38 - 00320000 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSFlacDecoder.dll
    2016-03-02 09:23 - 2016-02-23 04:37 - 00617984 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll
    2016-03-02 09:23 - 2016-02-23 04:37 - 00204288 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupSvc.dll
    2016-03-02 09:23 - 2016-02-23 04:34 - 00189952 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiFiDisplay.dll
    2016-03-02 09:23 - 2016-02-23 04:33 - 00558080 _____ (Microsoft Corporation) C:\WINDOWS\system32\MBMediaManager.dll
    2016-03-02 09:23 - 2016-02-23 04:32 - 00414720 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.exe
    2016-03-02 09:23 - 2016-02-23 04:29 - 00591872 _____ (Microsoft Corporation) C:\WINDOWS\system32\SmsRouterSvc.dll
    2016-03-02 09:23 - 2016-02-23 04:26 - 00372224 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDEServer.exe
    2016-03-02 09:23 - 2016-02-23 04:22 - 00567808 _____ (Microsoft Corporation) C:\WINDOWS\system32\MCRecvSrc.dll
    2016-03-02 09:23 - 2016-02-23 04:20 - 00606720 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmsvc.dll
    2016-03-02 09:23 - 2016-02-23 04:20 - 00493568 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmkvsrcsnk.dll
    2016-03-02 09:23 - 2016-02-23 04:19 - 00948736 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblAuthManager.dll
    2016-03-02 09:23 - 2016-02-23 04:19 - 00517632 _____ (Microsoft Corporation) C:\WINDOWS\system32\winspool.drv
    2016-03-02 09:23 - 2016-02-23 04:14 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LaunchWinApp.exe
    2016-03-02 09:23 - 2016-02-23 04:10 - 00474624 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetSetupShim.dll
    2016-03-02 09:23 - 2016-02-23 04:09 - 00988160 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedStartModel.dll
    2016-03-02 09:23 - 2016-02-23 04:09 - 00870400 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll
    2016-03-02 09:23 - 2016-02-23 04:06 - 01213440 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
    2016-03-02 09:23 - 2016-02-23 04:05 - 00161280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgent.exe
    2016-03-02 09:23 - 2016-02-23 04:04 - 01131520 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Audio.dll
    2016-03-02 09:23 - 2016-02-23 04:02 - 00755712 _____ (Microsoft Corporation) C:\WINDOWS\system32\spoolsv.exe
    2016-03-02 09:23 - 2016-02-23 04:02 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb10.sys
    2016-03-02 09:23 - 2016-02-23 03:58 - 00108544 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputLocaleManager.dll
    2016-03-02 09:23 - 2016-02-23 03:52 - 00456704 _____ (Microsoft Corporation) C:\WINDOWS\system32\ipnathlp.dll
    2016-03-02 09:23 - 2016-02-23 03:50 - 00266752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSFlacDecoder.dll
    2016-03-02 09:23 - 2016-02-23 03:47 - 00157184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WiFiDisplay.dll
    2016-03-02 09:23 - 2016-02-23 03:38 - 00480256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MCRecvSrc.dll
    2016-03-02 09:23 - 2016-02-23 03:36 - 00379392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmkvsrcsnk.dll
    2016-03-02 09:23 - 2016-02-23 03:35 - 00400896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winspool.drv
    2016-03-02 09:23 - 2016-02-23 03:29 - 00349696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NetSetupShim.dll
    2016-03-02 09:23 - 2016-02-23 03:24 - 01105920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Audio.dll
    2016-03-02 09:23 - 2016-02-23 03:24 - 00489984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.dll
    2016-03-02 09:23 - 2016-02-23 03:20 - 00083456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputLocaleManager.dll
    2016-03-02 09:23 - 2016-02-23 03:17 - 02635264 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll
    2016-03-02 09:23 - 2016-02-23 03:14 - 00990720 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncCore.dll
    2016-03-02 09:23 - 2016-02-23 03:11 - 01390080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Shell.dll
    2016-03-02 09:23 - 2016-02-23 02:42 - 03425792 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
    2016-03-02 09:23 - 2016-02-23 02:39 - 02581504 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
    2016-03-02 09:23 - 2016-02-23 02:32 - 02793472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
    2016-03-02 09:23 - 2016-02-23 02:30 - 02061312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
    2016-03-02 09:23 - 2016-02-09 00:28 - 00277856 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys
    2016-03-02 09:23 - 2016-02-09 00:13 - 00185184 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsd.sys
    2016-03-02 09:23 - 2016-02-08 23:18 - 00297472 _____ (Microsoft Corporation) C:\WINDOWS\system32\thumbcache.dll
    2016-02-28 08:55 - 2016-03-12 15:01 - 00000905 _____ C:\Users\Public\Desktop\Black Desert Online.lnk
    2016-02-28 08:55 - 2016-03-12 15:01 - 00000905 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Black Desert Online.lnk
    2016-02-28 08:55 - 2016-02-28 08:55 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Black Desert Online
    2016-02-27 23:29 - 2016-03-13 22:24 - 00000000 ____D C:\Users\Robyn\AppData\Local\BlackDesertOnline
    2016-02-26 22:35 - 2016-03-13 23:28 - 00000000 ____D C:\Users\Robyn\AppData\Roaming\StardewValley
    2016-02-26 22:35 - 2007-04-04 19:53 - 00081768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\xinput1_3.dll
    2016-02-26 22:32 - 2016-02-26 22:32 - 00000222 _____ C:\Users\Robyn\Desktop\Stardew Valley.url
    2016-02-24 00:00 - 2016-03-12 14:59 - 00002233 _____ C:\Users\Robyn\Desktop\Discord.lnk
    2016-02-24 00:00 - 2016-03-12 13:24 - 00000000 ____D C:\Users\Robyn\AppData\Local\Discord
    2016-02-24 00:00 - 2016-03-11 15:01 - 00000000 ____D C:\Users\Robyn\AppData\Roaming\discord
    2016-02-24 00:00 - 2016-03-05 01:35 - 00000000 ____D C:\Users\Robyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Hammer & Chisel, Inc
    2016-02-24 00:00 - 2016-03-05 01:35 - 00000000 ____D C:\Users\Robyn\AppData\Local\SquirrelTemp
    2016-02-18 01:40 - 2016-03-13 22:25 - 00036904 _____ (Wellbia.com Co., Ltd.) C:\WINDOWS\xhunter1.sys
    2016-02-18 01:07 - 2016-02-18 01:39 - 00000000 ____D C:\Users\Robyn\AppData\Local\BlackDesertOnlineCBT2
    2016-02-18 00:49 - 2016-02-22 07:47 - 00000000 ____D C:\Users\Robyn\AppData\Local\BDOCharacterCreator
    2016-02-17 22:49 - 2016-02-17 22:49 - 00000000 ____D C:\Users\Robyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox

    ==================== One Month Modified files and folders ========

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2016-03-16 20:52 - 2012-08-14 05:41 - 00000924 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
    2016-03-16 20:48 - 2015-06-16 08:38 - 00000918 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-146372567-257526347-2578419968-1000UA.job
    2016-03-16 20:33 - 2015-10-30 03:11 - 00000000 ____D C:\WINDOWS\CbsTemp
    2016-03-16 20:29 - 2016-01-16 05:21 - 01022308 _____ C:\WINDOWS\system32\PerfStringBackup.INI
    2016-03-16 20:29 - 2015-10-30 03:21 - 00000000 ____D C:\WINDOWS\INF
    2016-03-16 20:25 - 2016-02-09 22:05 - 00000000 ____D C:\Users\Robyn\AppData\Local\Spotify
    2016-03-16 20:25 - 2016-02-09 22:04 - 00000000 ____D C:\Users\Robyn\AppData\Roaming\Spotify
    2016-03-16 20:25 - 2012-07-28 19:10 - 00000000 ____D C:\Users\Robyn\AppData\Roaming\Skype
    2016-03-16 20:24 - 2012-08-14 05:41 - 00000920 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
    2016-03-16 07:55 - 2012-11-30 16:09 - 00000926 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-146372567-257526347-2578419968-1000UA.job
    2016-03-16 07:06 - 2014-05-08 06:07 - 00000830 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
    2016-03-16 04:58 - 2015-10-30 03:24 - 00000000 ____D C:\WINDOWS\system32\NDF
    2016-03-16 04:25 - 2016-01-16 05:30 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
    2016-03-16 04:25 - 2016-01-16 05:20 - 00000000 ____D C:\ProgramData\NVIDIA
    2016-03-16 04:04 - 2015-10-30 02:28 - 01310720 ___SH C:\WINDOWS\system32\config\BBI
    2016-03-14 23:50 - 2015-01-07 21:21 - 00000000 ____D C:\Users\Robyn\AppData\Roaming\Curse Client
    2016-03-14 23:50 - 2012-07-30 19:59 - 00000000 ____D C:\ProgramData\Origin
    2016-03-14 23:23 - 2016-01-16 05:21 - 00000000 ____D C:\Users\Robyn
    2016-03-14 22:38 - 2015-01-07 21:20 - 00000000 ____D C:\Users\Robyn\AppData\Roaming\Curse
    2016-03-14 21:35 - 2013-08-11 15:55 - 00000000 ____D C:\Users\Robyn\AppData\Local\ElevatedDiagnostics
    2016-03-14 21:20 - 2012-07-31 20:23 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
    2016-03-14 19:42 - 2016-01-16 05:21 - 00000000 ____D C:\Users\DefaultAppPool
    2016-03-13 20:18 - 2012-08-02 00:48 - 00004150 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{09DD7F3B-A8DE-4220-A71E-69FF742A702B}
    2016-03-13 15:48 - 2015-06-16 08:38 - 00000866 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-146372567-257526347-2578419968-1000Core.job
    2016-03-13 02:12 - 2012-11-30 16:09 - 00000874 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-146372567-257526347-2578419968-1000Core.job
    2016-03-12 15:01 - 2016-02-04 20:04 - 00001869 _____ C:\Users\Public\Desktop\SSDlife Pro.lnk
    2016-03-12 15:01 - 2016-02-03 18:12 - 00000593 _____ C:\Users\Public\Desktop\Fraps.lnk
    2016-03-12 15:01 - 2016-02-01 20:52 - 00001803 _____ C:\Users\Public\Desktop\Defraggler.lnk
    2016-03-12 15:01 - 2016-02-01 20:50 - 00000901 _____ C:\Users\Public\Desktop\CCleaner.lnk
    2016-03-12 15:01 - 2016-01-16 05:26 - 00001519 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
    2016-03-12 15:01 - 2015-11-09 13:40 - 00001067 _____ C:\Users\Public\Desktop\Firestorm-Releasex64.lnk
    2016-03-12 15:01 - 2015-10-11 19:57 - 00000726 _____ C:\Users\Public\Desktop\Steam.lnk
    2016-03-12 15:01 - 2015-10-05 10:28 - 00000644 _____ C:\Users\Public\Desktop\WildStar.lnk
    2016-03-12 15:01 - 2015-09-23 09:14 - 00001832 _____ C:\Users\Public\Desktop\Aeria Ignite.lnk
    2016-03-12 15:01 - 2015-08-19 13:57 - 00001816 _____ C:\Users\Public\Desktop\iTunes.lnk
    2016-03-12 15:01 - 2015-08-16 16:33 - 00000821 _____ C:\Users\Public\Desktop\EaseUS Partition Master 10.5.lnk
    2016-03-12 15:01 - 2015-08-06 14:06 - 00000724 _____ C:\Users\Public\Desktop\World of Warcraft.lnk
    2016-03-12 15:01 - 2015-07-27 00:34 - 00000836 _____ C:\Users\Public\Desktop\Inspirit Online.lnk
    2016-03-12 15:01 - 2015-07-08 17:58 - 00000639 _____ C:\Users\Public\Desktop\Star Wars - The Old Republic.lnk
    2016-03-12 15:01 - 2015-06-13 03:27 - 00002156 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth.lnk
    2016-03-12 15:01 - 2015-05-27 21:22 - 00000677 _____ C:\Users\Public\Desktop\Star Trek Online.lnk
    2016-03-12 15:01 - 2015-05-27 15:04 - 00000675 _____ C:\Users\Public\Desktop\Royal Quest.lnk
    2016-03-12 15:01 - 2015-05-27 14:26 - 00000391 _____ C:\Users\Public\Desktop\Arc.lnk
    2016-03-12 15:01 - 2015-04-09 18:31 - 00000951 _____ C:\Users\Public\Desktop\TERA Launcher.lnk
    2016-03-12 15:01 - 2015-01-06 02:24 - 00000532 _____ C:\Users\Public\Desktop\Hi-Rez Diagnostics and Support.lnk
    2016-03-12 15:01 - 2014-12-15 23:18 - 00002695 _____ C:\Users\Public\Desktop\Tukui Client.lnk
    2016-03-12 15:01 - 2014-09-17 21:59 - 00000874 _____ C:\Users\Public\Desktop\Bejeweled 3.lnk
    2016-03-12 15:01 - 2014-09-01 13:28 - 00001013 _____ C:\Users\Public\Desktop\The Sims 4.lnk
    2016-03-12 15:01 - 2014-06-21 18:55 - 00000724 _____ C:\Users\Public\Desktop\Heroes of the Storm.lnk
    2016-03-12 15:01 - 2014-05-10 19:35 - 00001014 _____ C:\Users\Public\Desktop\Plants vs. Zombies.lnk
    2016-03-12 15:01 - 2014-04-08 18:43 - 00000619 _____ C:\Users\Public\Desktop\StarCraft II.lnk
    2016-03-12 15:01 - 2014-01-02 00:16 - 00000532 _____ C:\Users\Public\Desktop\Origin.lnk
    2016-03-12 15:01 - 2013-12-10 01:30 - 00000720 _____ C:\Users\Public\Desktop\Hearthstone.lnk
    2016-03-12 15:01 - 2013-12-10 01:29 - 00001140 _____ C:\Users\Public\Desktop\Battle.net.lnk
    2016-03-12 15:01 - 2013-10-25 12:51 - 00000876 _____ C:\Users\Public\Desktop\The Secret World.lnk
    2016-03-12 15:01 - 2013-08-23 03:35 - 00001386 _____ C:\Users\Public\Desktop\FINAL FANTASY XIV - A Realm Reborn.lnk
    2016-03-12 15:01 - 2013-08-21 23:03 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
    2016-03-12 15:01 - 2013-08-21 23:03 - 00002013 _____ C:\Users\Public\Desktop\Adobe Reader XI.lnk
    2016-03-12 15:01 - 2013-05-02 14:25 - 00000811 _____ C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk
    2016-03-12 15:01 - 2012-12-01 02:46 - 00000691 _____ C:\Users\Public\Desktop\Diablo III.lnk
    2016-03-12 15:01 - 2012-10-11 01:47 - 00002519 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
    2016-03-12 15:01 - 2012-10-11 01:47 - 00001839 _____ C:\Users\Public\Desktop\QuickTime Player.lnk
    2016-03-12 15:01 - 2012-10-07 18:30 - 00000750 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop CS5 (64 Bit).lnk
    2016-03-12 15:01 - 2012-10-07 18:29 - 00000742 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Device Central CS5.lnk
    2016-03-12 15:01 - 2012-10-07 18:29 - 00000679 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Bridge CS5.lnk
    2016-03-12 15:01 - 2012-10-07 18:27 - 00001519 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe ExtendScript Toolkit CS5.lnk
    2016-03-12 15:01 - 2012-10-07 18:27 - 00000997 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Help.lnk
    2016-03-12 15:01 - 2012-10-07 18:27 - 00000799 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Extension Manager CS5.lnk
    2016-03-12 15:01 - 2012-08-14 05:41 - 00002206 _____ C:\Users\Public\Desktop\Google Earth.lnk
    2016-03-12 15:01 - 2012-07-28 18:54 - 00002486 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Messenger.lnk
    2016-03-12 15:00 - 2016-02-09 22:05 - 00001836 _____ C:\Users\Robyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Spotify.lnk
    2016-03-12 15:00 - 2015-09-26 10:48 - 00001047 _____ C:\Users\Robyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Optional Features.lnk
    2016-03-12 15:00 - 2015-08-16 21:31 - 00002363 _____ C:\Users\Robyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
    2016-03-12 15:00 - 2015-07-18 03:34 - 00001290 _____ C:\Users\Robyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Landmark Beta.lnk
    2016-03-12 15:00 - 2015-01-07 21:21 - 00000980 _____ C:\Users\Robyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Curse.lnk
    2016-03-12 15:00 - 2012-07-29 10:22 - 00002453 _____ C:\Users\Robyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
    2016-03-12 14:59 - 2016-02-09 22:05 - 00001850 _____ C:\Users\Robyn\Desktop\Spotify.lnk
    2016-03-12 14:59 - 2015-10-30 03:24 - 00000000 ____D C:\WINDOWS\AppReadiness
    2016-03-12 14:59 - 2015-08-24 23:29 - 00002037 _____ C:\Users\Robyn\Desktop\Drakensang Online.lnk
    2016-03-12 14:59 - 2015-08-07 02:39 - 00000343 _____ C:\Users\Robyn\Desktop\ons - Shortcut.lnk
    2016-03-12 14:59 - 2015-07-18 03:34 - 00001290 _____ C:\Users\Robyn\Desktop\Landmark Beta.lnk
    2016-03-12 14:59 - 2015-07-14 16:20 - 00000749 _____ C:\Users\Robyn\Desktop\Echo of Soul.lnk
    2016-03-12 14:59 - 2015-07-11 04:16 - 00000775 _____ C:\Users\Robyn\Desktop\RIFT.lnk
    2016-03-12 14:59 - 2015-07-06 18:49 - 00001962 _____ C:\Users\Robyn\Desktop\My.com Games.lnk
    2016-03-12 14:59 - 2015-06-13 03:46 - 00001085 _____ C:\Users\Robyn\Desktop\The Elder Scrolls Online.lnk
    2016-03-12 14:59 - 2015-05-09 02:24 - 00000705 _____ C:\Users\Robyn\Desktop\Old Data - Shortcut - Copy.lnk
    2016-03-12 14:59 - 2015-03-25 23:56 - 00001100 _____ C:\Users\Robyn\Desktop\Front Line Assembly Echogenetic Album - Shortcut.lnk
    2016-03-12 14:59 - 2015-02-22 01:10 - 00000819 _____ C:\Users\Robyn\Desktop\DxDiag - Shortcut.lnk
    2016-03-12 14:59 - 2015-01-07 21:21 - 00000994 _____ C:\Users\Robyn\Desktop\Curse.lnk
    2016-03-12 14:59 - 2014-10-12 20:11 - 00000783 _____ C:\Users\Robyn\Desktop\Trove.lnk
    2016-03-12 14:59 - 2014-09-05 17:49 - 00000807 _____ C:\Users\Robyn\Desktop\Archeage Beta.lnk
    2016-03-12 14:59 - 2014-07-03 21:56 - 00000649 _____ C:\Users\Robyn\Desktop\Glyph.lnk
    2016-03-12 14:59 - 2012-10-13 23:52 - 00000818 _____ C:\Users\Robyn\Desktop\Adobe Photoshop CS5 (64 Bit).lnk
    2016-03-12 14:59 - 2012-07-29 10:27 - 00000705 _____ C:\Users\Robyn\Desktop\Old Data - Shortcut.lnk
    2016-03-12 14:59 - 2012-07-29 10:22 - 00002445 _____ C:\Users\Robyn\Desktop\Google Chrome.lnk
    2016-03-12 14:58 - 2016-02-03 18:50 - 00000000 ____D C:\Users\Robyn\AppData\Local\CrashDumps
    2016-03-12 14:09 - 2015-10-30 03:24 - 00000000 ____D C:\WINDOWS\Web
    2016-03-12 13:48 - 2012-07-28 18:21 - 00000000 ____D C:\Users\Robyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
    2016-03-12 13:48 - 2009-07-14 01:32 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
    2016-03-12 13:31 - 2013-04-10 01:12 - 00000000 ____D C:\ProgramData\Malwarebytes
    2016-03-12 13:24 - 2016-02-03 18:12 - 00000000 ____D C:\Fraps
    2016-03-12 13:24 - 2016-02-01 20:52 - 00000000 ____D C:\Program Files\Defraggler
    2016-03-12 13:24 - 2016-02-01 20:50 - 00000000 ____D C:\Program Files\CCleaner
    2016-03-12 13:24 - 2015-10-15 20:16 - 00000000 ____D C:\Program Files (x86)\OpenAL
    2016-03-12 13:24 - 2015-08-24 23:29 - 00000000 ____D C:\Program Files (x86)\Drakensang Online
    2016-03-12 13:24 - 2015-08-19 13:57 - 00000000 ____D C:\Program Files\iTunes
    2016-03-12 13:24 - 2015-07-14 15:44 - 00000000 ____D C:\Users\Robyn\AppData\Local\Akamai
    2016-03-12 13:24 - 2015-07-01 14:06 - 00000000 ____D C:\Program Files (x86)\QuickTime
    2016-03-12 13:24 - 2013-12-10 01:29 - 00000000 ____D C:\Program Files (x86)\Battle.net
    2016-03-12 13:24 - 2013-08-29 20:51 - 00000000 ____D C:\Program Files\TabletPlugins
    2016-03-12 13:24 - 2013-05-13 20:09 - 00000000 ____D C:\Program Files (x86)\Bonjour
    2016-03-12 13:24 - 2013-03-14 03:00 - 00000000 ____D C:\Program Files\Microsoft Silverlight
    2016-03-12 13:24 - 2012-10-11 01:47 - 00000000 ____D C:\Program Files (x86)\Apple Software Update
    2016-03-12 13:24 - 2012-10-07 18:28 - 00000000 ____D C:\Program Files (x86)\Adobe Media Player
    2016-03-12 13:24 - 2012-07-28 18:54 - 00000000 ____D C:\Program Files (x86)\Windows Live
    2016-03-12 13:23 - 2016-01-16 06:17 - 00000000 ____D C:\Users\Robyn\AppData\Local\Deployment
    2016-03-12 08:09 - 2015-10-30 03:24 - 00000000 ____D C:\WINDOWS\SysWOW64\GroupPolicy
    2016-03-12 08:09 - 2009-07-13 23:20 - 00000000 ___HD C:\WINDOWS\system32\GroupPolicy
    2016-03-11 08:30 - 2015-10-30 03:24 - 00000000 ___HD C:\Program Files\WindowsApps
    2016-03-11 07:53 - 2013-05-25 19:28 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive
    2016-03-10 22:59 - 2015-08-16 21:31 - 00000000 ___RD C:\Users\Robyn\OneDrive
    2016-03-10 09:46 - 2013-09-17 22:11 - 00000000 ____D C:\Users\Robyn\AppData\Roaming\Guild Wars 2
    2016-03-10 02:24 - 2016-01-16 05:18 - 04806136 _____ C:\WINDOWS\system32\FNTCACHE.DAT
    2016-03-10 02:23 - 2015-10-30 03:24 - 00000000 ____D C:\Program Files\Windows Portable Devices
    2016-03-10 02:23 - 2015-10-30 03:24 - 00000000 ____D C:\Program Files\Windows Multimedia Platform
    2016-03-10 02:23 - 2015-10-30 03:24 - 00000000 ____D C:\Program Files (x86)\Windows Portable Devices
    2016-03-10 02:23 - 2015-10-30 03:24 - 00000000 ____D C:\Program Files (x86)\Windows Multimedia Platform
    2016-03-09 14:25 - 2013-08-15 03:01 - 00000000 ____D C:\WINDOWS\system32\MRT
    2016-03-09 14:18 - 2012-07-30 07:09 - 143659408 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
    2016-03-08 10:01 - 2016-02-03 17:59 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
    2016-03-08 10:01 - 2016-01-16 05:19 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
    2016-03-08 09:59 - 2016-01-16 05:19 - 00000000 ____D C:\Program Files\NVIDIA Corporation
    2016-03-08 09:52 - 2015-10-08 12:49 - 00000000 ____D C:\Users\Robyn\AppData\Local\NVIDIA
    2016-03-08 09:52 - 2013-11-12 18:02 - 00000000 ____D C:\Users\Robyn\AppData\Local\NVIDIA Corporation
    2016-03-08 03:12 - 2015-10-30 03:26 - 00829944 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
    2016-03-08 03:12 - 2015-10-30 03:26 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
    2016-03-05 07:44 - 2014-03-18 18:44 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NCSOFT
    2016-03-05 01:35 - 2012-07-28 19:10 - 00000000 ____D C:\ProgramData\Skype
    2016-03-05 01:34 - 2015-10-30 03:24 - 00000000 ____D C:\WINDOWS\LiveKernelReports
    2016-03-03 07:11 - 2015-10-30 03:24 - 00000000 ____D C:\WINDOWS\rescache
    2016-03-03 03:06 - 2015-08-16 21:28 - 00000000 __RHD C:\Users\Public\AccountPictures
    2016-03-03 03:06 - 2015-08-16 21:28 - 00000000 ___RD C:\Users\Robyn\Virtual Machines
    2016-03-03 01:42 - 2015-10-30 05:07 - 00000000 ____D C:\Program Files\Windows Journal
    2016-03-03 01:42 - 2015-10-30 03:24 - 00000000 __RSD C:\WINDOWS\Media
    2016-03-03 01:42 - 2015-10-30 03:24 - 00000000 ___RD C:\WINDOWS\PurchaseDialog
    2016-03-03 01:42 - 2015-10-30 03:24 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns
    2016-03-03 01:42 - 2015-10-30 03:24 - 00000000 ____D C:\WINDOWS\system32\SystemResetPlatform
    2016-03-03 01:42 - 2015-10-30 03:24 - 00000000 ____D C:\WINDOWS\system32\appraiser
    2016-03-03 01:42 - 2015-10-30 03:24 - 00000000 ____D C:\WINDOWS\bcastdvr
    2016-03-03 01:42 - 2015-10-30 02:28 - 00000000 ____D C:\WINDOWS\SysWOW64\Dism
    2016-03-03 01:42 - 2015-10-30 02:28 - 00000000 ____D C:\WINDOWS\system32\Dism
    2016-02-24 21:04 - 2015-07-13 21:45 - 12479040 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvlddmkm.sys
    2016-02-23 19:57 - 2015-10-08 12:44 - 31120952 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvoglv64.dll
    2016-02-23 19:57 - 2015-10-08 12:44 - 00035832 _____ C:\WINDOWS\system32\nvinfo.pb
    2016-02-23 19:57 - 2015-07-13 21:45 - 19779456 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvwgf2umx.dll
    2016-02-23 19:57 - 2015-07-13 21:45 - 17175056 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvwgf2um.dll
    2016-02-23 19:57 - 2015-07-13 21:45 - 14115136 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvd3dum.dll
    2016-02-23 19:57 - 2015-07-13 21:45 - 03649760 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvapi64.dll
    2016-02-23 19:57 - 2015-07-13 21:45 - 03231360 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvapi.dll
    2016-02-23 19:57 - 2015-04-16 20:03 - 00205456 _____ (NVIDIA Corporation) C:\WINDOWS\system32\Drivers\nvhda64v.sys
    2016-02-23 19:57 - 2015-04-16 08:19 - 01572496 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvhdagenco6420103.dll
    2016-02-23 16:28 - 2016-02-03 17:58 - 00530368 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshext.dll
    2016-02-23 16:28 - 2016-02-03 17:58 - 00081856 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nv3dappshextr.dll
    2016-02-23 16:28 - 2016-01-16 05:20 - 06368824 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvcpl.dll
    2016-02-23 16:28 - 2016-01-16 05:20 - 06154909 _____ C:\WINDOWS\system32\nvcoproc.bin
    2016-02-23 16:28 - 2016-01-16 05:20 - 02993720 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvc64.dll
    2016-02-23 16:28 - 2016-01-16 05:20 - 02563128 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvsvcr.dll
    2016-02-23 16:28 - 2016-01-16 05:20 - 01263040 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvvsvc.exe
    2016-02-23 16:28 - 2016-01-16 05:20 - 00393784 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvmctray.dll
    2016-02-23 16:28 - 2016-01-16 05:20 - 00071224 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvshext.dll
    2016-02-19 15:52 - 2015-08-16 21:28 - 00000000 ____D C:\Users\Robyn\AppData\Local\Packages
    2016-02-17 22:48 - 2012-08-17 05:51 - 00000000 ____D C:\Users\Robyn\AppData\Roaming\Dropbox
    2016-02-17 05:39 - 2016-01-16 08:15 - 00000000 ____D C:\Windows.old
    2016-02-17 02:40 - 2016-02-03 18:00 - 01903344 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspcap64.dll
    2016-02-17 02:40 - 2016-02-03 18:00 - 01756424 _____ (NVIDIA Corporation) C:\WINDOWS\system32\nvspbridge64.dll
    2016-02-17 02:40 - 2016-02-03 18:00 - 01571624 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspcap.dll
    2016-02-17 02:40 - 2016-02-03 18:00 - 01316184 _____ (NVIDIA Corporation) C:\WINDOWS\SysWOW64\nvspbridge.dll
    2016-02-17 02:40 - 2016-02-03 18:00 - 00112216 _____ C:\WINDOWS\system32\NvRtmpStreamer64.dll
    2016-02-15 19:31 - 2014-07-03 21:56 - 00000000 ____D C:\Users\Robyn\AppData\Local\Glyph

    ==================== Files in the root of some directories =======

    2013-08-29 16:05 - 2013-08-29 16:05 - 0000132 _____ () C:\Users\Robyn\AppData\Roaming\Adobe PNG Format CS5 Prefs
    2012-12-27 12:37 - 2012-12-27 12:37 - 0000093 _____ () C:\Users\Robyn\AppData\Local\fusioncache.dat
    2016-03-15 23:45 - 2016-03-15 23:45 - 0000000 _____ () C:\Users\Robyn\AppData\Local\{B5D0D767-4EE2-4C02-B431-F57B06EAF781}
    2015-05-14 10:18 - 2015-05-14 10:18 - 0000696 _____ () C:\ProgramData\HirezPipeError.txt

    Some files in TEMP:
    ====================
    C:\Users\Robyn\AppData\Local\Temp\6699d3ee8dd9cf775caae782c8f44f03.dll
    C:\Users\Robyn\AppData\Local\Temp\6c831fbe5a0dedd8bf2ce9b793bed14c.dll
    C:\Users\Robyn\AppData\Local\Temp\GUR65CF.exe
    C:\Users\Robyn\AppData\Local\Temp\GUR8C29.exe
    C:\Users\Robyn\AppData\Local\Temp\GURE963.exe
    C:\Users\Robyn\AppData\Local\Temp\jre-8u73-windows-au.exe
    C:\Users\Robyn\AppData\Local\Temp\nvSCPAPI.dll
    C:\Users\Robyn\AppData\Local\Temp\nvSCPAPI64.dll
    C:\Users\Robyn\AppData\Local\Temp\nvStInst.exe
    C:\Users\Robyn\AppData\Local\Temp\sqlite3.dll


    ==================== Bamital & volsnap =================

    (There is no automatic fix for files that do not pass verification.)

    C:\WINDOWS\system32\winlogon.exe => File is digitally signed
    C:\WINDOWS\system32\wininit.exe => File is digitally signed
    C:\WINDOWS\explorer.exe => File is digitally signed
    C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
    C:\WINDOWS\system32\svchost.exe => File is digitally signed
    C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
    C:\WINDOWS\system32\services.exe => File is digitally signed
    C:\WINDOWS\system32\User32.dll => File is digitally signed
    C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
    C:\WINDOWS\system32\userinit.exe => File is digitally signed
    C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
    C:\WINDOWS\system32\rpcss.dll => File is digitally signed
    C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
    C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
    C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed


    LastRegBack: 2016-03-14 19:30

    ==================== End of FRST.txt ============================

     


    • 0

    #7
    robyrob

    robyrob

      New Member

    • Topic Starter
    • Member
    • Pip
    • 6 posts

    Addition.txt Additional scan result of Farbar Recovery Scan Tool (x64) Version:05-03-2016 01
    Ran by Robyn (2016-03-16 21:00:53)
    Running from D:\Utilities
    Windows 10 Pro Version 1511 (X64) (2016-01-16 09:33:08)
    Boot Mode: Normal
    ==========================================================


    ==================== Accounts: =============================

    Administrator (S-1-5-21-146372567-257526347-2578419968-500 - Administrator - Disabled)
    ASPNET (S-1-5-21-146372567-257526347-2578419968-1004 - Limited - Enabled)
    DefaultAccount (S-1-5-21-146372567-257526347-2578419968-503 - Limited - Disabled)
    Guest (S-1-5-21-146372567-257526347-2578419968-501 - Limited - Disabled)
    Robyn (S-1-5-21-146372567-257526347-2578419968-1000 - Administrator - Enabled) => C:\Users\Robyn

    ==================== Security Center ========================

    (If an entry is included in the fixlist, it will be removed.)

    AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

    ==================== Installed Programs ======================

    (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

    Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 3.7.0.1860 - Adobe Systems Incorporated)
    Adobe Community Help (HKLM-x32\...\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 3.0.0.400 - Adobe Systems Incorporated)
    Adobe Flash Player 21 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 21.0.0.182 - Adobe Systems Incorporated)
    Adobe Media Player (HKLM-x32\...\com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 1.8 - Adobe Systems Incorporated)
    Adobe Photoshop CS5 (HKLM-x32\...\{15FEDA5F-141C-4127-8D7E-B962D1742728}) (Version: 12.0 - Adobe Systems Incorporated)
    Adobe Reader XI (11.0.14) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.14 - Adobe Systems Incorporated)
    Aeria Ignite (HKLM-x32\...\Aeria Ignite 1.13.3296) (Version: 1.13.3296 - Aeria Games & Entertainment)
    Aeria Ignite (HKLM-x32\...\Aeria Ignite) (Version: 1.13.3296 - Aeria Games & Entertainment)
    Aeria Ignite (x32 Version: 1.13.3296 - Aeria Games & Entertainment) Hidden
    Akamai NetSession Interface (HKU\S-1-5-21-146372567-257526347-2578419968-1000\...\Akamai) (Version:  - Akamai Technologies, Inc)
    Apple Application Support (32-bit) (HKLM-x32\...\{7FE25256-B7C1-480D-B736-10A67A833AEA}) (Version: 3.2 - Apple Inc.)
    Apple Application Support (64-bit) (HKLM\...\{B255D495-4734-4E9B-B4F5-96702FD4A7B9}) (Version: 3.2 - Apple Inc.)
    Apple Mobile Device Support (HKLM\...\{5D61F006-168C-4B8B-B7FD-F113C10AE0E4}) (Version: 8.2.1.3 - Apple Inc.)
    Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
    Arc (HKLM-x32\...\{CED8E25B-122A-4E80-B612-7F99B93284B3}) (Version: 1.0.0.9668 - Perfect World Entertainment)
    Battle.net (HKLM-x32\...\Battle.net) (Version:  - Blizzard Entertainment)
    Bejeweled® 3 (HKLM-x32\...\{E99C27B2-EB2E-4244-9F5C-A96F55100F0C}) (Version: 1.1.13.4753 - Electronic Arts, Inc.)
    BitRaider Streaming Client (HKLM-x32\...\BitRaider Streaming Client) (Version: 1.3.3.4098 - BitRaider, LLC)
    Black Desert Online (HKLM-x32\...\{C1F96C92-7B8C-485F-A9CD-37A0708A2A60}) (Version: 1.0.0.5 - Daum Games EU)
    Blade & Soul (HKLM-x32\...\InstallShield_{C3F383C1-D050-4A40-843F-8171A6A02C3A}) (Version: 1.0.63.260 - NC Interactive, LLC)
    Blade & Soul (x32 Version: 1.0.63.260 - NC Interactive, LLC) Hidden
    Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
    Brawlhalla (HKLM-x32\...\Steam App 291550) (Version:  - Blue Mammoth Games)
    CCleaner (HKLM\...\CCleaner) (Version: 5.14 - Piriform)
    CPUID CPU-Z 1.75 (HKLM\...\CPUID CPU-Z_is1) (Version:  - )
    Curse (HKLM-x32\...\{DEE70742-F4E9-44CA-B2B9-EE95DCF37295}) (Version: 6.0.0.0 - Curse)
    Curse Client (HKU\S-1-5-21-146372567-257526347-2578419968-1000\...\101a9f93b8f0bb6f) (Version: 5.1.1.844 - Curse)
    D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
    Dead Rising 2 (x32 Version: 1.0.0002.130 - Capcom) Hidden
    DefianceRuntimes (HKLM-x32\...\{79B1FF35-9EA8-48ED-98D6-19ABE004BE89}) (Version: 1.0.2 - Trion Worlds, Inc.)
    Defraggler (HKLM\...\Defraggler) (Version: 2.20 - Piriform)
    Dell System Detect (HKU\S-1-5-21-146372567-257526347-2578419968-1000\...\9204f5692a8faf3b) (Version: 5.4.0.4 - Dell)
    Devilian Beta-US (HKLM-x32\...\Glyph Devilian Beta-US) (Version:  - Trion Worlds, Inc.)
    Devilian Live-US (HKLM-x32\...\Glyph Devilian Live-US) (Version:  - Trion Worlds, Inc.)
    Diablo III (HKLM-x32\...\Diablo III) (Version:  - Blizzard Entertainment)
    Discord (HKU\S-1-5-21-146372567-257526347-2578419968-1000\...\Discord) (Version: 0.0.286 - Hammer & Chisel, Inc.)
    Drakensang Online (HKLM-x32\...\Drakensang Online) (Version:  - )
    Dropbox (HKU\S-1-5-21-146372567-257526347-2578419968-1000\...\Dropbox) (Version: 3.14.7 - Dropbox, Inc.)
    EaseUS Partition Master 10.5 Trial Edition (HKLM-x32\...\EaseUS Partition Master Trial Edition_is1) (Version:  - EaseUS)
    EaseUS Todo Backup Free 8.6  (HKLM-x32\...\EaseUS Todo Backup_is1) (Version: 8.6 - CHENGDU YIWO Tech Development Co., Ltd)
    EasyBCD 2.2 (HKLM-x32\...\EasyBCD) (Version: 2.2 - NeoSmart Technologies)
    Echo of Soul (HKLM-x32\...\Echo of Soul) (Version:  - )
    eReg (x32 Version: 1.20.138.34 - Logitech, Inc.) Hidden
    FINAL FANTASY VII (HKLM-x32\...\Steam App 39140) (Version:  - Square Enix)
    FINAL FANTASY XIII (HKLM-x32\...\Steam App 292120) (Version:  - SQUARE ENIX)
    FINAL FANTASY XIV - A Realm Reborn (HKLM-x32\...\{2B41E132-07DF-4925-A3D3-F2D1765CCDFE}) (Version: 1.0.0000 - SQUARE ENIX CO., LTD.)
    FINAL FANTASY® XI: Ultimate Collection Seekers Edition NA (HKLM-x32\...\Steam App 230330) (Version:  - Square Enix)
    Firestorm SecondLife and OpenSim viewer (Version: 4.7.47323 - Phoenix Viewer Project) Hidden
    Firestorm-Releasex64 x64 (HKLM-x32\...\{87a36c50-4766-41e3-b23b-2354a2ff60bf}) (Version: 4.7.47323 - Phoenix Firestorm Project Inc)
    Fishing Planet (HKLM-x32\...\Steam App 380600) (Version:  - Fishing Planet LLC)
    Fraps (HKLM-x32\...\Fraps) (Version:  - )
    Gauntlet™  (HKLM-x32\...\Steam App 258970) (Version:  - Arrowhead Game Studios)
    Geeks3D FurMark 1.17.0.0 (HKLM-x32\...\{2397CAD4-2263-4CD0-96BE-E43A980B9C9A}_is1) (Version:  - Geeks3D)
    Glyph (HKLM-x32\...\Glyph) (Version:  - Trion Worlds, Inc.)
    Google Chrome (HKU\S-1-5-21-146372567-257526347-2578419968-1000\...\Google Chrome) (Version: 48.0.2564.116 - Google Inc.)
    Google Drive (HKLM-x32\...\{895D0391-459F-4D45-B8DD-13F0DE70C66E}) (Version: 1.28.1549.1322 - Google, Inc.)
    Google Earth (HKLM-x32\...\{817750FA-EC6A-485D-9901-0683AE6FFDF1}) (Version: 7.1.5.1557 - Google)
    Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
    Google Update Helper (x32 Version: 1.3.29.5 - Google Inc.) Hidden
    Guild Wars 2 (HKLM-x32\...\Guild Wars 2) (Version:  - NCsoft Corporation, Ltd.)
    Hearthstone (HKLM-x32\...\Hearthstone) (Version:  - Blizzard Entertainment)
    Heroes of the Storm (HKLM-x32\...\Heroes of the Storm) (Version:  - Blizzard Entertainment)
    Hi-Rez Studios Authenticate and Update Service (HKLM-x32\...\{3C87E0FF-BC0A-4F5E-951B-68DC3F8DF1FC}) (Version: 3.0.0.0 - Hi-Rez Studios)
    HostsMan 4.6.103 (HKLM-x32\...\{1A3DD1A9-7B7B-4ECA-AD2F-98466F49F62C}_is1) (Version: 4.6.103.0 - abelhadigital.com)
    iCloud (HKLM\...\{709A2D23-C25E-47B5-9268-CB6FEE648504}) (Version: 4.1.1.53 - Apple Inc.)
    Inspirit Online (HKLM-x32\...\{B7BC8356-4027-48F2-ADDF-7D4574B7D07A}) (Version: 1.0.0 - Game Release Entertainment)
    iTunes (HKLM\...\{BFEAB774-C7DC-4032-B05A-DA5F7CB7B365}) (Version: 12.2.2.25 - Apple Inc.)
    Java 8 Update 73 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218073F0}) (Version: 8.0.730.2 - Oracle Corporation)
    Landmark Beta (HKU\S-1-5-21-146372567-257526347-2578419968-1000\...\DG0-Landmark) (Version:  - Daybreak Games)
    Landmark Beta (HKU\S-1-5-21-146372567-257526347-2578419968-1000\...\SOE-Landmark Beta) (Version: 1.0.3.183 - Daybreak Games)
    Logitech Gaming Software 8.50 (HKLM\...\Logitech Gaming Software) (Version: 8.50.281 - Logitech Inc.)
    Logitech Harmony Remote Software (x86) (HKLM-x32\...\{634F79E1-2A41-4C40-9E8D-89EC740AC9D6}) (Version: 2.0 - Logitech)
    Logitech SetPoint 6.32 (HKLM\...\sp6) (Version: 6.32.20 - Logitech)
    Malwarebytes Anti-Malware version 2.2.0.1024 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes)
    Marvel Heroes 2015 (HKLM-x32\...\Steam App 226320) (Version:  - Gazillion Entertainment)
    Microsoft .NET Framework 1.1 (HKLM-x32\...\Microsoft .NET Framework 1.1  (1033)) (Version:  - )
    Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\...\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation)
    Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{832D9DE0-8AFC-4689-9819-4DBBDEBD3E4F}) (Version: 3.5.92.0 - Microsoft Corporation)
    Microsoft Games for Windows Marketplace (HKLM-x32\...\{4CB0307C-565E-4441-86BE-0DF2E4FB828C}) (Version: 3.5.50.0 - Microsoft Corporation)
    Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.41212.0 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{887868A2-D6DE-3255-AA92-AA0B5A59B874}) (Version: 9.0.30729 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
    Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
    Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
    Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
    Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
    Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
    Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
    Microsoft WSE 3.0 Runtime (HKLM-x32\...\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}) (Version: 3.0.5305.0 - Microsoft Corp.)
    Microsoft XNA Framework Redistributable 4.0 Refresh (HKLM-x32\...\{D69C8EDE-BBC5-436B-8E0E-C5A6D311CF4F}) (Version: 4.0.30901.0 - Microsoft Corporation)
    MiniTool Partition Wizard Home Edition 8.1.1 (HKLM-x32\...\{05D996FA-ADCB-4D23-BA3C-A7C184A8FAC6}_is1) (Version:  - MiniTool Solution Ltd.)
    NCLauncher (NCSOFT) (HKLM-x32\...\NCLauncher_NCJapan) (Version:  - NCSOFT)
    NCSOFT Game Launcher (HKLM-x32\...\NCLauncher_NCWest) (Version:  - NCSOFT)
    NETGEAR A6100 Genie (HKLM-x32\...\InstallShield_{15D27BA3-6CCD-4848-8925-07EF083492AD}) (Version: 1.0.0.32 - NETGEAR)
    NETGEAR A6100 Genie (x32 Version: 1.0.0.32 - NETGEAR) Hidden
    Nexon Game Manager (HKLM-x32\...\{EA2DB6E0-72C5-4ef9-A3A0-E6705F4A6A9E}) (Version:  - )
    NpackdCL (HKLM-x32\...\{C32CA36A-DA63-4D55-9B17-87C61033137D}) (Version: 1.18.7 - Npackd)
    NVIDIA 3D Vision Controller Driver 352.65 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 352.65 - NVIDIA Corporation)
    NVIDIA 3D Vision Driver 362.00 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 362.00 - NVIDIA Corporation)
    NVIDIA GeForce Experience 2.10.2.40 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.10.2.40 - NVIDIA Corporation)
    NVIDIA Graphics Driver 362.00 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 362.00 - NVIDIA Corporation)
    NVIDIA HD Audio Driver 1.3.34.4 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.4 - NVIDIA Corporation)
    NVIDIA PhysX System Software 9.15.0428 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.15.0428 - NVIDIA Corporation)
    OpenAL (HKLM-x32\...\OpenAL) (Version:  - )
    Origin (HKLM-x32\...\Origin) (Version: 9.3.11.2762 - Electronic Arts, Inc.)
    PDF Settings CS5 (x32 Version: 10.0 - Adobe Systems Incorporated) Hidden
    Plants vs. Zombies™ (HKLM-x32\...\{5E6536C2-E79A-49CF-83EA-817AD81F9FC8}) (Version: 1.2.0.1093 - Electronic Arts, Inc.)
    QuickTime 7 (HKLM-x32\...\{627FFC10-CE0A-497F-BA2B-208CAC638010}) (Version: 7.77.80.95 - Apple Inc.)
    RIFT (HKLM-x32\...\Glyph RIFT) (Version:  - Trion Worlds, Inc.)
    RollerCoaster Tycoon 3: Platinum! (HKLM-x32\...\Steam App 2700) (Version:  - Frontier)
    SHIELD Streaming (Version: 5.1.0270 - NVIDIA Corporation) Hidden
    SHIELD Wireless Controller Driver (Version: 2.10.2.40 - NVIDIA Corporation) Hidden
    Simple 1.3.1 (HKLM-x32\...\Simple) (Version: 1.3.1 - Simple)
    Skype Click to Call (HKLM-x32\...\{B6CF2967-C81E-40C0-9815-C05774FEF120}) (Version: 6.12.13601 - Skype Technologies S.A.)
    Skype™ 7.18 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.18.112 - Skype Technologies S.A.)
    SMITE (HKLM-x32\...\Steam App 386360) (Version:  - Hi-Rez Studios)
    SNOW (HKLM-x32\...\Steam App 244930) (Version:  - Poppermost Productions)
    Splashtop Software Updater (HKLM-x32\...\Splashtop Software Updater) (Version: 1.5.6.15 - Splashtop Inc.)
    Splashtop Streamer (HKLM-x32\...\{B7C5EA94-B96A-41F5-BE95-25D78B486678}) (Version: 2.5.8.6 - Splashtop Inc.)
    Spotify (HKU\S-1-5-21-146372567-257526347-2578419968-1000\...\Spotify) (Version: 1.0.24.104.g92a22684 - Spotify AB)
    SSDlife Pro (HKLM-x32\...\{6F104B6D-535A-4D27-9A11-8525368AEB1F}) (Version: 2.5.82 - BinarySense Inc.)
    Star Wars The Old Republic (HKLM-x32\...\swtor_swtor) (Version:  - Bioware/EA)
    Star Wars: The Old Republic (HKLM-x32\...\{3B11D799-48E0-48ED-BFD7-EA655676D8BB}) (Version: 1.00 - Electronic Arts, Inc.)
    StarCraft II (HKLM-x32\...\StarCraft II) (Version:  - Blizzard Entertainment)
    Stardew Valley (HKLM-x32\...\Steam App 413150) (Version:  - ConcernedApe)
    Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
    TeamSpeak 3 Client (HKLM\...\TeamSpeak 3 Client) (Version: 3.0.10 - TeamSpeak Systems GmbH)
    TERA (HKLM-x32\...\{A0D70C31-D5CB-4491-A508-5CF2C9F25EE0}) (Version: 1.00.0000 - En Masse Entertainment)
    The Elder Scrolls Online (HKLM-x32\...\The Elder Scrolls Online) (Version: 1.0.0.0 - Zenimax Online Studios)
    The Secret World (HKLM-x32\...\The Secret World_is1) (Version: 1.0.0 - Funcom)
    The Sims™ 4 (HKLM-x32\...\{48EBEBBF-B9F8-4520-A3CF-89A730721917}) (Version: 1.13.106.1010 - Electronic Arts Inc.)
    Theme Hospital (HKLM-x32\...\{5118A4C2-C8A4-4CE5-AC37-F3E51C25402F}) (Version: 3.0.0.5 - Electronic Arts)
    Trove (HKLM-x32\...\Glyph Trove) (Version:  - Trion Worlds, Inc.)
    Tukui Client (HKLM-x32\...\{BAD6EBBD-A6A9-41C9-898A-8C868A552E4C}) (Version: 2.4.6 - Tukui)
    Ubisoft Game Launcher (HKLM-x32\...\{888F1505-C2B3-4FDE-835D-36353EBD4754}) (Version: 1.0.0.0 - UBISOFT)
    Unturned (HKLM-x32\...\Steam App 304930) (Version:  - Nelson Sexton)
    Ventrilo Client for Windows x64 (HKLM\...\{EEB3F6BB-318D-4CE5-989F-8191FCBFB578}) (Version: 3.0.8.0 - Flagship Industries, Inc.)
    Video Card Stability Test (HKLM-x32\...\Video Card Stability Test) (Version: v.1.0.0.3 - FreeStone Group)
    Wacom Tablet (HKLM\...\Wacom Tablet Driver) (Version: 6.3.6w3 - Wacom Technology Corp.)
    WebTablet FB Plugin 32 bit (HKLM-x32\...\Wacom WebTabletPlugin for Internet Explorer and Netscape) (Version: 2.1.0.3 - Wacom Technology Corp.)
    WebTablet FB Plugin 64 bit (HKLM\...\Wacom WebTabletPlugin for Internet Explorer and Netscape) (Version: 2.1.0.3 - Wacom Technology Corp.)
    WildStar (HKLM-x32\...\WildStar) (Version:  - NCSOFT)
    Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3555.0308 - Microsoft Corporation)
    Windows XP Mode (HKLM\...\{1374CC63-B520-4f3f-98E8-E9020BF01CFF}) (Version: 1.3.7600.16423 - Microsoft Corporation)
    World of Warcraft (HKLM-x32\...\World of Warcraft) (Version:  - Blizzard Entertainment)

    ==================== Custom CLSID (Whitelisted): ==========================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    CustomCLSID: HKU\S-1-5-21-146372567-257526347-2578419968-1000_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Robyn\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
    CustomCLSID: HKU\S-1-5-21-146372567-257526347-2578419968-1000_Classes\CLSID\{092dfa86-5807-5a94-bf3b-5a53ba9e5308}\InprocServer32 -> C:\Program Files\TabletPlugins\npWacomTabletPlugin.dll (Wacom)
    CustomCLSID: HKU\S-1-5-21-146372567-257526347-2578419968-1000_Classes\CLSID\{0F22A205-CFB0-4679-8499-A6F44A80A208}\InprocServer32 -> C:\Users\Robyn\AppData\Local\Google\Update\1.3.25.5\psuser_64.dll => No File
    CustomCLSID: HKU\S-1-5-21-146372567-257526347-2578419968-1000_Classes\CLSID\{1423F872-3F7F-4E57-B621-8B1A9D49B448}\InprocServer32 -> C:\Users\Robyn\AppData\Local\Google\Update\1.3.27.5\psuser_64.dll => No File
    CustomCLSID: HKU\S-1-5-21-146372567-257526347-2578419968-1000_Classes\CLSID\{355EC88A-02E2-4547-9DEE-F87426484BD1}\InprocServer32 -> C:\Users\Robyn\AppData\Local\Google\Update\1.3.23.9\psuser_64.dll => No File
    CustomCLSID: HKU\S-1-5-21-146372567-257526347-2578419968-1000_Classes\CLSID\{5C8C2A98-6133-4EBA-BBCC-34D9EA01FC2E}\InprocServer32 -> C:\Users\Robyn\AppData\Local\Google\Update\1.3.28.1\psuser_64.dll => No File
    CustomCLSID: HKU\S-1-5-21-146372567-257526347-2578419968-1000_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\Robyn\AppData\Local\Microsoft\OneDrive\17.3.6302.0225\FileCoAuth.exe (Microsoft Corporation)
    CustomCLSID: HKU\S-1-5-21-146372567-257526347-2578419968-1000_Classes\CLSID\{78550997-5DEF-4A8A-BAF9-D5774E87AC98}\InprocServer32 -> C:\Users\Robyn\AppData\Local\Google\Update\1.3.28.13\psuser_64.dll => No File
    CustomCLSID: HKU\S-1-5-21-146372567-257526347-2578419968-1000_Classes\CLSID\{793EE463-1304-471C-ADF1-68C2FFB01247}\InprocServer32 -> C:\Users\Robyn\AppData\Local\Google\Update\1.3.29.5\psuser_64.dll (Google Inc.)
    CustomCLSID: HKU\S-1-5-21-146372567-257526347-2578419968-1000_Classes\CLSID\{90B3DFBF-AF6A-4EA0-8899-F332194690F8}\InprocServer32 -> C:\Users\Robyn\AppData\Local\Google\Update\1.3.24.15\psuser_64.dll => No File
    CustomCLSID: HKU\S-1-5-21-146372567-257526347-2578419968-1000_Classes\CLSID\{C3BC25C0-FCD3-4F01-AFDD-41373F017C9A}\InprocServer32 -> C:\Users\Robyn\AppData\Local\Google\Update\1.3.26.9\psuser_64.dll => No File
    CustomCLSID: HKU\S-1-5-21-146372567-257526347-2578419968-1000_Classes\CLSID\{CC182BE1-84CE-4A57-B85C-FD4BBDF78CB2}\InprocServer32 -> C:\Users\Robyn\AppData\Local\Google\Update\1.3.29.1\psuser_64.dll => No File
    CustomCLSID: HKU\S-1-5-21-146372567-257526347-2578419968-1000_Classes\CLSID\{D0336C0B-7919-4C04-8CCE-2EBAE2ECE8C9}\InprocServer32 -> C:\Users\Robyn\AppData\Local\Google\Update\1.3.25.11\psuser_64.dll => No File
    CustomCLSID: HKU\S-1-5-21-146372567-257526347-2578419968-1000_Classes\CLSID\{D1EDC4F5-7F4D-4B12-906A-614ECF66DDAF}\InprocServer32 -> C:\Users\Robyn\AppData\Local\Google\Update\1.3.28.15\psuser_64.dll => No File
    CustomCLSID: HKU\S-1-5-21-146372567-257526347-2578419968-1000_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\Robyn\AppData\Local\Google\Update\1.3.29.5\psuser_64.dll (Google Inc.)
    CustomCLSID: HKU\S-1-5-21-146372567-257526347-2578419968-1000_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\Robyn\AppData\Roaming\Dropbox\bin\DropboxExt64.33.dll (Dropbox, Inc.)
    CustomCLSID: HKU\S-1-5-21-146372567-257526347-2578419968-1000_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Robyn\AppData\Roaming\Dropbox\bin\DropboxExt64.33.dll (Dropbox, Inc.)
    CustomCLSID: HKU\S-1-5-21-146372567-257526347-2578419968-1000_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Robyn\AppData\Roaming\Dropbox\bin\DropboxExt64.33.dll (Dropbox, Inc.)
    CustomCLSID: HKU\S-1-5-21-146372567-257526347-2578419968-1000_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Robyn\AppData\Roaming\Dropbox\bin\DropboxExt64.33.dll (Dropbox, Inc.)
    CustomCLSID: HKU\S-1-5-21-146372567-257526347-2578419968-1000_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Robyn\AppData\Roaming\Dropbox\bin\DropboxExt64.33.dll (Dropbox, Inc.)
    CustomCLSID: HKU\S-1-5-21-146372567-257526347-2578419968-1000_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Robyn\AppData\Roaming\Dropbox\bin\DropboxExt64.33.dll (Dropbox, Inc.)
    CustomCLSID: HKU\S-1-5-21-146372567-257526347-2578419968-1000_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Robyn\AppData\Roaming\Dropbox\bin\DropboxExt64.33.dll (Dropbox, Inc.)
    CustomCLSID: HKU\S-1-5-21-146372567-257526347-2578419968-1000_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Robyn\AppData\Roaming\Dropbox\bin\DropboxExt64.33.dll (Dropbox, Inc.)
    CustomCLSID: HKU\S-1-5-21-146372567-257526347-2578419968-1000_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Robyn\AppData\Roaming\Dropbox\bin\DropboxExt64.33.dll (Dropbox, Inc.)
    CustomCLSID: HKU\S-1-5-21-146372567-257526347-2578419968-1000_Classes\CLSID\{FBC9D74C-AF55-4309-9FB2-C426E071637F}\InprocServer32 -> C:\Users\Robyn\AppData\Roaming\Dropbox\bin\DropboxExt64.33.dll (Dropbox, Inc.)
    CustomCLSID: HKU\S-1-5-21-146372567-257526347-2578419968-1000_Classes\CLSID\{FE498BAB-CB4C-4F88-AC3F-3641AAAF5E9E}\InprocServer32 -> C:\Users\Robyn\AppData\Local\Google\Update\1.3.24.7\psuser_64.dll => No File

    ==================== Scheduled Tasks (Whitelisted) =============

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    Task: {026A9F52-7018-4CD4-A00B-E981A5CC174B} - System32\Tasks\{90369F95-C306-4F3A-99C9-94B8A9F4F6ED} => pcalua.exe -a "C:\Program Files (x86)\NCJapan\NCLauncher\Uninstall.exe"
    Task: {028F48FB-6FE7-45FB-B94D-2B60ED85FF33} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\Windows\ehome\ehPrivJob.exe
    Task: {02A3CC2C-3403-40CB-B3D4-14B2DA4FF4E1} - System32\Tasks\{61862628-F8FA-4019-A915-7D84EC6CF619} => pcalua.exe -a "D:\Downloads\setup (2).exe" -d D:\Downloads
    Task: {043FCA18-7DED-4324-AA2A-A25346DA86D7} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\Windows\ehome\mcupdate.exe
    Task: {04647738-0BD2-4BFA-BEC0-5AD54564E42A} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\Windows\ehome\ehPrivJob.exe
    Task: {07F8AECB-A047-443B-8184-B3C341A57791} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\Windows\ehome\mcupdate.exe
    Task: {0D175541-C8A4-472B-8ADF-8CFD9B1C6BAD} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\Windows\ehome\ehPrivJob.exe
    Task: {0E7CF047-4A5B-44C9-97D8-B34E24DE0B4F} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_ERROR_HB => C:\WINDOWS\system32\MRT.exe [2016-03-09] (Microsoft Corporation)
    Task: {1A6FD107-AF7B-4584-A7F5-CEB4FDA2B1E0} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-12-14] (Adobe Systems Incorporated)
    Task: {1E8DE982-8525-4075-8123-983612827139} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\Windows\ehome\ehrec.exe
    Task: {1F49CCCD-7239-4369-B2DD-FFC7870B3AF2} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\Windows\ehome\mcupdate.exe
    Task: {224ABF65-8813-4444-9F1E-6AAD24EA9807} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\Windows\ehome\ehPrivJob.exe
    Task: {248EAB12-E566-4437-9F29-4451F74A17A4} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
    Task: {285992E5-3BD8-4986-81F7-018445EAF73A} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-146372567-257526347-2578419968-1000UA => C:\Users\Robyn\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-16] (Dropbox, Inc.)
    Task: {30EE7E74-B07F-4F46-95C9-86345681EAD5} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\Windows\ehome\MCUpdate.exe
    Task: {36457BA0-1D14-4CF4-BB01-BAF4EB5D268F} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\Windows\ehome\ehPrivJob.exe
    Task: {3C128E1B-EA0D-436F-9FA2-8BE0E75AB27A} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-146372567-257526347-2578419968-1000Core => C:\Users\Robyn\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-16] (Dropbox, Inc.)
    Task: {40C1D722-9F58-421D-B8CA-BEEC3E7758FB} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
    Task: {44212AB5-350C-4009-96B7-3EC1D2BFA3E4} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION
    Task: {46347AA8-5568-4BD5-AD57-D38F0E4472C6} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
    Task: {4D23466E-CC9E-4101-A7DC-AC72D4E04193} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.)
    Task: {533026A7-7568-4783-8177-52D8FC2334B7} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\Windows\ehome\ehPrivJob.exe
    Task: {54432FA6-0EE9-48CF-BB12-CCDD37379A5F} - System32\Tasks\[email protected] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2010-03-06] (Adobe Systems Incorporated)
    Task: {59EF4229-54AB-4249-8C88-1F45CD73F3C4} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-03-11] (Adobe Systems Incorporated)
    Task: {60209FDB-81F4-40AF-9326-75DE161F26E1} - System32\Tasks\{8EB8C1FE-3F8C-459E-9E46-C2516F31D7EB} => Iexplore.exe hxxp://ui.skype.com/ui/0/5.10.0.116/en/abandoninstall?source=lightinstaller&amp;page=tsInstall
    Task: {63D912E0-9467-410F-8B23-CBD8C31F24B5} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
    Task: {6AA042DA-0BEC-4EE6-9C92-82EF8BD9FB12} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\Windows\ehome\ehPrivJob.exe
    Task: {755C559D-D9C8-4D17-AE56-EAE7DEAB87E7} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\Windows\ehome\mcupdate.exe
    Task: {82272D83-8937-4296-BBA5-63DC3986508D} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2016-03-09] (Microsoft Corporation)
    Task: {8476EE02-7086-4BCB-BD6E-EA9605C96F3F} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
    Task: {8634C627-CFC3-4508-BF1E-B4185ACE21B8} - System32\Tasks\{BD6F546D-9665-423B-87D4-1B3FEFFA452A} => pcalua.exe -a "G:\Program Files (x86)\Steam\steam.exe" -c steam://uninstall/15170
    Task: {8772DEFE-E70E-4FF4-90F0-681F8A367200} - System32\Tasks\{70C2FF9A-E86C-4279-946A-55E732B8499C} => pcalua.exe -a D:\Downloads\SP-SpookySounds_Install.exe -d D:\Downloads
    Task: {8AB792AB-160B-4F76-8D76-B718ECD1AD63} - System32\Tasks\Microsoft\Microsoft Antimalware\Microsoft Antimalware Scheduled Scan => C:\Program Files\Microsoft Security Client\MpCmdRun.exe
    Task: {9176545B-3670-40BC-B02D-657C93AAA0DC} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\Windows\ehome\ehPrivJob.exe
    Task: {978830C6-484A-437F-8BB0-E80D3D24DE32} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\Windows\ehome\mcupdate.exe
    Task: {997D3924-7DA9-4DFD-94C4-4E5D0F9B0009} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\Windows\ehome\ehPrivJob.exe
    Task: {A4D70D6C-F0A3-4775-BFFE-516537B9DEDD} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
    Task: {AA15EE09-1E68-4DAB-A6A2-C00545D547C1} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
    Task: {AC4D432D-76B1-402E-A10A-5C5C1E951B74} - System32\Tasks\Microsoft\Windows\Media Center\StartRecording => C:\Windows\ehome\ehrec.exe
    Task: {AC54FE4C-481D-4995-9949-01568340D0CC} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\Windows\ehome\ehPrivJob.exe
    Task: {B2B2E9B3-5A94-42E7-90AD-8E169EBD1391} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\Windows\ehome\ehPrivJob.exe
    Task: {B932D01A-231E-4580-892C-30B5073C1544} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
    Task: {C4D91502-6B1E-4058-BB15-ED088C5E8CE1} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2016-01-15] (Piriform Ltd)
    Task: {C55843ED-FC05-43DE-8307-8B4B44D46E1E} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.)
    Task: {C5C1D15C-D3BB-4DA9-9667-5A09B5A198C2} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\Windows\ehome\mcupdate.exe
    Task: {CA9BC517-968F-4862-B644-3C3E5A09A0F4} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\Windows\ehome\ehPrivJob.exe
    Task: {CEB10634-0A5C-48FC-8E08-9EDB0F2029E4} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\Windows\ehome\ehPrivJob.exe
    Task: {D95F6C1A-1C9A-43AB-A53B-A8BD588528FF} - System32\Tasks\{C0F86405-BD29-4313-90E9-E86FF4B437A6} => pcalua.exe -a "g:\Program Files\AVAST Software\Avast\aswRunDll.exe" -c "g:\Program Files\AVAST Software\Avast\Setup\setiface.dll" RunSetup
    Task: {D9B37314-2E20-42A1-ACC5-D9D8CD934EB4} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-146372567-257526347-2578419968-1000Core => C:\Users\Robyn\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
    Task: {DA8581D2-B237-4C36-87B2-B0BD5A2E8BC6} - System32\Tasks\AdobeAAMUpdater-1.0-Robyn-PC-Robyn => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2010-03-06] (Adobe Systems Incorporated)
    Task: {E515E475-D539-4788-8BF5-749AB8D7C3F5} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
    Task: {E523C270-6AF5-4ADE-9DCE-6623693BF5EB} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-146372567-257526347-2578419968-1000UA => C:\Users\Robyn\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
    Task: {E945CD34-EC61-4B81-B87F-C3DA781344B5} - \IntegrationManager -> No File <==== ATTENTION
    Task: {ED39CEF7-BB23-48C2-A94E-2F7D29692789} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\Windows\ehome\mcupdate.exe
    Task: {F07A94F2-02F7-4F4E-BC67-6236359FF565} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
    Task: {F22E3F12-2263-4FBE-8681-B9870C9DEB47} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
    Task: {F8EF18E0-3262-4E0C-A7B3-0F0F86DDB8C9} - System32\Tasks\Component System\Component => C:\Users\Robyn\AppData\Local\Component\com.exe
    Task: {F9FA1CFF-11C5-48BC-9311-A75D121AE54C} - System32\Tasks\Chromium => C:\Users\Robyn\AppData\Local\Chromium\APPLIC~1\450242~1.0\INSTAL~1\UNINST~1.EXE

    (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

    Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
    Task: C:\WINDOWS\Tasks\Chromium.job => C:\Users\Robyn\AppData\Local\Chromium\APPLIC~1\450242~1.0\INSTAL~1\UNINST~1.EXE
    Task: C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-146372567-257526347-2578419968-1000Core.job => C:\Users\Robyn\AppData\Local\Dropbox\Update\DropboxUpdate.exe
    Task: C:\WINDOWS\Tasks\DropboxUpdateTaskUserS-1-5-21-146372567-257526347-2578419968-1000UA.job => C:\Users\Robyn\AppData\Local\Dropbox\Update\DropboxUpdate.exe
    Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-146372567-257526347-2578419968-1000Core.job => C:\Users\Robyn\AppData\Local\Google\Update\GoogleUpdate.exe
    Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-146372567-257526347-2578419968-1000UA.job => C:\Users\Robyn\AppData\Local\Google\Update\GoogleUpdate.exe

    ==================== Shortcuts =============================

    (The entries could be listed to be restored or removed.)

    ==================== Loaded Modules (Whitelisted) ==============

    2015-10-30 03:18 - 2015-10-30 03:18 - 00185856 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll
    2016-01-16 05:19 - 2016-02-23 16:28 - 00134712 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
    2015-08-16 18:45 - 2015-06-23 01:08 - 00245800 _____ () G:\EaseUS\Todo Backup\bin\TodoBackupService.exe
    2016-03-02 09:23 - 2016-02-23 07:27 - 02654872 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
    2016-03-02 09:23 - 2016-02-23 07:27 - 02654872 _____ () C:\WINDOWS\System32\CoreUIComponents.dll
    2016-01-16 08:14 - 2016-01-16 08:14 - 00591360 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
    2016-01-21 14:37 - 2016-01-21 14:38 - 00144384 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeHost.exe
    2016-01-16 08:14 - 2016-01-16 08:14 - 00093696 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\Windows.UI.Shell.SharedUtilities.dll
    2016-03-02 09:23 - 2016-02-23 04:36 - 00472064 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll
    2016-01-16 08:14 - 2016-01-16 08:14 - 07992832 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
    2016-01-16 08:14 - 2016-01-16 08:14 - 00936960 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Actions.dll
    2016-01-28 13:09 - 2016-01-16 01:10 - 02483200 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
    2016-01-28 13:09 - 2016-01-16 01:13 - 04089856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
    2013-08-29 20:50 - 2013-06-06 13:31 - 01185048 _____ () C:\Program Files\Tablet\Wacom\libxml2.dll
    2015-08-16 18:45 - 2014-12-15 01:04 - 00253992 _____ () G:\EaseUS\TrayPopup\TrayTipAgent.exe
    2015-08-16 18:45 - 2014-12-15 00:53 - 00098856 _____ () G:\EaseUS\Todo Backup\bin\CodeLog.dll
    2015-08-16 18:45 - 2014-12-15 00:53 - 00017448 _____ () G:\EaseUS\Todo Backup\bin\CompressFile.dll
    2015-08-16 18:45 - 2014-12-15 00:53 - 00088616 _____ () G:\EaseUS\Todo Backup\bin\TBGetRemoteNetInfo.dll
    2015-08-16 18:45 - 2014-12-15 00:53 - 01296424 _____ () G:\EaseUS\Todo Backup\bin\libxml2.dll
    2015-08-16 18:45 - 2014-12-15 00:53 - 00060968 _____ () G:\EaseUS\Todo Backup\bin\zlib1.dll
    2015-08-16 18:45 - 2015-08-01 15:10 - 00022568 _____ () G:\EaseUS\Todo Backup\bin\CmcTbProxy.dll
    2015-08-16 18:45 - 2015-08-01 15:10 - 00186920 _____ () G:\EaseUS\Todo Backup\bin\CMCPipeCenter.dll
    2015-08-16 18:45 - 2015-08-01 15:10 - 00165416 _____ () G:\EaseUS\Todo Backup\bin\CMCAdapt.dll
    2015-08-16 18:45 - 2015-08-01 15:10 - 00058408 _____ () G:\EaseUS\Todo Backup\bin\TBInfo.dll
    2015-08-16 18:45 - 2015-08-01 15:10 - 00015912 _____ () G:\EaseUS\Todo Backup\bin\CMCNetTokenProxy.dll
    2015-08-16 18:45 - 2015-06-23 00:58 - 00108072 _____ () G:\EaseUS\Todo Backup\bin\ActivationOnline.dll
    2015-08-16 18:45 - 2014-12-15 00:53 - 00077864 _____ () G:\EaseUS\Todo Backup\bin\logsys.dll
    2015-08-16 18:45 - 2014-12-15 00:53 - 00030248 _____ () G:\EaseUS\Todo Backup\bin\DiskSearchImg.dll
    2015-08-16 18:45 - 2014-12-15 00:53 - 00068136 _____ () G:\EaseUS\Todo Backup\bin\MountImg.dll
    2015-08-16 18:45 - 2014-12-15 00:53 - 00158248 _____ () G:\EaseUS\Todo Backup\bin\ImgFile.dll
    2015-08-16 18:45 - 2015-03-14 11:54 - 00281128 _____ () G:\EaseUS\Todo Backup\bin\DsImgFile.dll
    2015-08-16 18:45 - 2015-03-14 11:54 - 00072232 _____ () G:\EaseUS\Todo Backup\bin\CheckImg.dll
    2015-08-16 18:45 - 2014-12-15 00:53 - 00139816 _____ () G:\EaseUS\Todo Backup\bin\vhdvmdk.dll
    2015-08-16 18:45 - 2015-06-23 00:58 - 00037416 _____ () G:\EaseUS\Todo Backup\bin\BootDriver.dll
    2015-08-16 18:45 - 2015-03-14 11:54 - 00759848 _____ () G:\EaseUS\Todo Backup\bin\ExImage.dll
    2015-08-16 18:45 - 2014-12-15 00:53 - 00193064 _____ () G:\EaseUS\Todo Backup\bin\EmailBackupSize.dll
    2015-08-16 18:45 - 2014-12-15 00:53 - 00407080 _____ () G:\EaseUS\Todo Backup\bin\AndroidImage.dll
    2015-08-16 18:45 - 2015-06-23 00:58 - 00148008 _____ () G:\EaseUS\Todo Backup\bin\EnumDisk.dll
    2015-08-16 18:45 - 2014-12-15 00:53 - 00076840 _____ () G:\EaseUS\Todo Backup\bin\FatLib.dll
    2015-08-16 18:45 - 2014-12-15 00:53 - 00207912 _____ () G:\EaseUS\Todo Backup\bin\NTFSLib.dll
    2015-08-16 18:45 - 2015-06-23 00:58 - 00024616 _____ () G:\EaseUS\Todo Backup\bin\GetDriverInfo.dll
    2015-08-16 18:45 - 2014-12-15 00:53 - 00020520 _____ () G:\EaseUS\Todo Backup\bin\CorrectMbr.dll
    2015-08-16 18:45 - 2014-12-15 00:53 - 00032296 _____ () G:\EaseUS\Todo Backup\bin\EnumTapeDevice.dll
    2015-08-16 18:45 - 2014-12-15 00:53 - 00034856 _____ () G:\EaseUS\Todo Backup\bin\TbTapeBrowse.dll
    2015-08-16 18:45 - 2014-12-15 00:53 - 00064040 _____ () G:\EaseUS\Todo Backup\bin\RegLib.dll
    2015-08-16 18:45 - 2015-08-01 15:10 - 00025128 _____ () G:\EaseUS\Todo Backup\bin\AccountManager.dll
    2015-08-16 18:45 - 2014-12-15 00:53 - 00115752 _____ () G:\EaseUS\Todo Backup\bin\NasOperator.dll
    2015-08-16 18:45 - 2014-12-15 00:53 - 00194088 _____ () G:\EaseUS\Todo Backup\bin\EmailBrowser.dll
    2015-08-16 18:45 - 2014-12-15 00:53 - 00077864 _____ () G:\EaseUS\Todo Backup\bin\CloudOperator.dll
    2015-08-16 18:45 - 2014-12-15 00:53 - 00037928 _____ () G:\EaseUS\Todo Backup\bin\ActiveOnline.dll
    2015-08-16 18:45 - 2015-06-23 00:58 - 00136232 _____ () G:\EaseUS\Todo Backup\bin\VMConfig.dll
    2015-08-16 18:45 - 2014-12-15 00:53 - 00020008 _____ () G:\EaseUS\Todo Backup\bin\AndroidDeviceManager.dll
    2015-08-16 18:45 - 2014-12-15 00:53 - 00043048 _____ () G:\EaseUS\Todo Backup\bin\TbDataSwap.dll
    2015-08-16 18:45 - 2014-12-15 00:53 - 00353832 _____ () G:\EaseUS\Todo Backup\bin\DeviceManager.dll
    2015-08-16 18:45 - 2014-12-15 00:53 - 00027176 _____ () G:\EaseUS\Todo Backup\bin\DeviceAdapter.dll
    2015-08-16 18:45 - 2015-06-23 00:58 - 00137256 _____ () G:\EaseUS\Todo Backup\bin\Device.dll
    2015-08-16 18:45 - 2014-12-15 00:53 - 00146984 _____ () G:\EaseUS\Todo Backup\bin\Partition.dll
    2015-08-16 18:45 - 2014-12-15 00:53 - 00050216 _____ () G:\EaseUS\Todo Backup\bin\FileSystemAnalyser.dll
    2015-08-16 18:45 - 2014-12-15 00:53 - 00061992 _____ () G:\EaseUS\Todo Backup\bin\FATFileSystemAnalyser.dll
    2015-08-16 18:45 - 2014-12-15 00:53 - 00089640 _____ () G:\EaseUS\Todo Backup\bin\Common.dll
    2015-08-16 18:45 - 2014-12-15 00:53 - 00056360 _____ () G:\EaseUS\Todo Backup\bin\NTFSFileSystemAnalyser.dll
    2015-08-16 18:45 - 2015-03-11 23:59 - 00427560 _____ () G:\EaseUS\Todo Backup\bin\uexper.dll
    2015-08-16 18:45 - 2014-12-15 00:53 - 00223784 _____ () G:\EaseUS\Todo Backup\bin\SmartBackup.dll
    2016-01-21 14:37 - 2016-01-21 14:38 - 00141312 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkypeBackgroundTasks.dll
    2016-01-21 14:37 - 2016-01-21 14:38 - 22330368 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.13.20000.0_x86__8wekyb3d8bbwe\SkyWrap.dll
    2016-01-07 09:17 - 2016-01-07 09:17 - 00094208 _____ () C:\Program Files (x86)\NETGEAR\A6100\Realtek.dll
    2012-11-06 09:47 - 2012-11-06 09:47 - 00114688 _____ () C:\Program Files (x86)\NETGEAR\A6100\EnumDevLib.dll
    2015-12-03 15:11 - 2016-02-02 09:42 - 01016832 _____ () K:\Origin\platforms\qwindows.dll
    2014-01-31 10:22 - 2016-02-02 09:41 - 00028160 _____ () K:\Origin\imageformats\qgif.dll
    2014-01-31 10:22 - 2016-02-02 09:41 - 00029696 _____ () K:\Origin\imageformats\qico.dll
    2014-01-31 10:22 - 2016-02-02 09:41 - 00256000 _____ () K:\Origin\imageformats\qjpeg.dll
    2014-01-31 10:22 - 2016-02-02 09:41 - 00266240 _____ () K:\Origin\imageformats\qmng.dll
    2014-01-31 10:22 - 2016-02-02 09:41 - 00023552 _____ () K:\Origin\imageformats\qtga.dll
    2014-01-31 10:22 - 2016-02-02 09:41 - 00346112 _____ () K:\Origin\imageformats\qtiff.dll
    2014-01-31 10:22 - 2016-02-02 09:41 - 00023552 _____ () K:\Origin\imageformats\qwbmp.dll
    2015-08-16 18:45 - 2014-12-15 01:04 - 00223272 _____ () G:\EaseUS\TrayPopup\traynet.dll
    2015-08-16 18:45 - 2014-12-15 01:04 - 00275496 _____ () G:\EaseUS\TrayPopup\libcurl.dll
    2015-08-16 18:45 - 2014-12-15 01:04 - 00118328 _____ () G:\EaseUS\TrayPopup\zlib1.dll
    2015-08-16 18:45 - 2015-03-14 12:05 - 00249896 _____ () G:\EaseUS\TrayPopup\uexper.dll

    ==================== Alternate Data Streams (Whitelisted) =========

    (If an entry is included in the fixlist, only the ADS will be removed.)

    AlternateDataStreams: C:\ProgramData\TEMP:4FC01C57 [128]

    ==================== Safe Mode (Whitelisted) ===================

    (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


    ==================== EXE Association (Whitelisted) ===============

    (If an entry is included in the fixlist, the registry item will be restored to default or removed.)


    ==================== Internet Explorer trusted/restricted ===============

    (If an entry is included in the fixlist, it will be removed from the registry.)

    IE trusted site: HKU\S-1-5-21-146372567-257526347-2578419968-1000\...\aeriagames.com -> hxxps://aeriagames.com
    IE trusted site: HKU\S-1-5-21-146372567-257526347-2578419968-1000\...\aeriagames.com -> hxxp://aeriagames.com
    IE trusted site: HKU\S-1-5-21-146372567-257526347-2578419968-1000\...\clonewarsadventures.com -> clonewarsadventures.com
    IE trusted site: HKU\S-1-5-21-146372567-257526347-2578419968-1000\...\dell.com -> dell.com
    IE trusted site: HKU\S-1-5-21-146372567-257526347-2578419968-1000\...\driversupport.com -> hxxp://apps.driversupport.com
    IE trusted site: HKU\S-1-5-21-146372567-257526347-2578419968-1000\...\driversupport.com -> hxxps://apps.driversupport.com
    IE trusted site: HKU\S-1-5-21-146372567-257526347-2578419968-1000\...\freerealms.com -> freerealms.com
    IE trusted site: HKU\S-1-5-21-146372567-257526347-2578419968-1000\...\soe.com -> soe.com
    IE trusted site: HKU\S-1-5-21-146372567-257526347-2578419968-1000\...\sony.com -> sony.com

    ==================== Hosts content: ==========================

    (If needed Hosts: directive could be included in the fixlist to reset Hosts.)

    2009-07-13 22:34 - 2016-03-12 14:08 - 12788055 ____A C:\WINDOWS\system32\Drivers\etc\hosts

    0.0.0.0 asy.a8ww.net
    0.0.0.0 cms.ad2click.nl
    0.0.0.0 tag1.adaptiveads.com
    0.0.0.0 wad.adbasket.net
    0.0.0.0 www.adchimp.com
    0.0.0.0 show.adclick.lv
    0.0.0.0 servedby.adcombination.com
    0.0.0.0 adcore.ru
    0.0.0.0 222-33544_999.pub.adfirmative.com
    0.0.0.0 c.adfirmative.com
    0.0.0.0 rc.de.adlink.net #[Tracking.Cookie]
    0.0.0.0 tr.de.adlink.net
    0.0.0.0 n.admagnet.net
    0.0.0.0 ads.admodus.com #[Tracking.Cookie]
    0.0.0.0 img.adnet.com.tr
    0.0.0.0 tt11.adobe.com #[adobe.tcliveus.com]
    0.0.0.0 ad02.adonspot.com
    0.0.0.0 e.adpower.bg
    0.0.0.0 pop.adrent.net
    0.0.0.0 cntr.adrime.com
    0.0.0.0 ads-bg.info #[server down?]
    0.0.0.0 f-nod1.adsniper.ru
    0.0.0.0 au-01.adtomafusion.com
    0.0.0.0 adv.adtotal.pl
    0.0.0.0 rek.adtotal.pl
    0.0.0.0 www.adultcommercial.net
    0.0.0.0 www.adult-tracker.de
    0.0.0.0 images.adviews.de
    0.0.0.0 www.adviews.de
    0.0.0.0 img.network.affiliando.com

    There are 367517 more lines.


    ==================== Other Areas ============================

    (Currently there is no automatic fix for this section.)

    HKU\S-1-5-21-146372567-257526347-2578419968-1000\Control Panel\Desktop\\Wallpaper ->
    DNS Servers: 8.8.8.8 - 8.8.4.4
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
    Windows Firewall is enabled.

    ==================== MSCONFIG/TASK MANAGER disabled items ==

    (Currently there is no automatic fix for this section.)

    MSCONFIG\startupfolder: C:^Users^Robyn^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dropbox.lnk => C:\Windows\pss\Dropbox.lnk.Startup
    MSCONFIG\startupreg: iTunesHelper => "F:\Program Files (x86)\iTunes\iTunesHelper.exe"
    HKLM\...\StartupApproved\Run: => "AdobeAAMUpdater-1.0"
    HKLM\...\StartupApproved\Run: => "iTunesHelper"
    HKLM\...\StartupApproved\Run32: => "AdobeCS5ServiceManager"
    HKLM\...\StartupApproved\Run32: => "Aeria Ignite"
    HKLM\...\StartupApproved\Run32: => "Adobe ARM"
    HKLM\...\StartupApproved\Run32: => "AdobeAAMUpdater-1.0"
    HKU\S-1-5-21-146372567-257526347-2578419968-1000\...\StartupApproved\StartupFolder: => "Dropbox.lnk"
    HKU\S-1-5-21-146372567-257526347-2578419968-1000\...\StartupApproved\Run: => "Dropbox Update"

    ==================== FirewallRules (Whitelisted) ===============

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    FirewallRules: [WCF-NetTcpActivator-In-TCP-64bit] => (Allow) LPort=808
    FirewallRules: [MSMQ-Out-UDP] => (Allow) %systemroot%\system32\mqsvc.exe
    FirewallRules: [MSMQ-In-UDP] => (Allow) %systemroot%\system32\mqsvc.exe
    FirewallRules: [MSMQ-Out-TCP] => (Allow) %systemroot%\system32\mqsvc.exe
    FirewallRules: [MSMQ-In-TCP] => (Allow) %systemroot%\system32\mqsvc.exe
    FirewallRules: [{61A4BE09-602F-4F5B-8C91-04D4E0B698C6}] => (Allow) G:\EaseUS\Todo Backup\bin\TodoBackupService.exe
    FirewallRules: [{06952DEF-2499-4980-8570-2F54807A17CA}] => (Allow) G:\EaseUS\Todo Backup\bin\TodoBackupService.exe
    FirewallRules: [{673303C2-2FBA-4E2A-9BBE-D8ECD6D49A2D}] => (Allow) C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRServer.exe
    FirewallRules: [{AB2D4ADF-EE5D-467F-8D67-DA4A0F50B859}] => (Allow) C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\SRFeature.exe
    FirewallRules: [{173FF88C-23CD-4EDA-B50F-AE8893C72925}] => (Allow) C:\Program Files (x86)\Splashtop\Splashtop Remote\Server\DataProxy.exe

    ==================== Restore Points =========================

    ATTENTION: System Restore is disabled

    ==================== Faulty Device Manager Devices =============

    Name: Intel® 82566DC-2 Gigabit Network Connection
    Description: Intel® 82566DC-2 Gigabit Network Connection
    Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
    Manufacturer: Intel
    Service: e1express
    Problem: : This device cannot start. (Code10)
    Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
    On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.

    Name: Ethernet Controller
    Description: Ethernet Controller
    Class Guid:
    Manufacturer:
    Service:
    Problem: : The drivers for this device are not installed. (Code 28)
    Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.


    ==================== Event log errors: =========================

    Application errors:
    ==================
    Error: (03/16/2016 08:26:02 PM) (Source: Application Hang) (EventID: 1002) (User: )
    Description: The program Skype.exe version 7.18.0.112 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.

    Process ID: 270c

    Start Time: 01d17fe378394b0b

    Termination Time: 65

    Application Path: G:\Program Files (x86)\Skype\Phone\Skype.exe

    Report Id: d213bc13-ebd6-11e5-9c2d-dcef09d2dcc6

    Faulting package full name:

    Faulting package-relative application ID:

    Error: (03/16/2016 07:55:17 AM) (Source: Application Error) (EventID: 1000) (User: )
    Description: Faulting application name: dwm.exe, version: 10.0.10586.0, time stamp: 0x5632d756
    Faulting module name: combase.dll, version: 10.0.10586.103, time stamp: 0x56a849ab
    Exception code: 0xc0000005
    Fault offset: 0x0000000000067e3c
    Faulting process id: 0x180
    Faulting application start time: 0xdwm.exe0
    Faulting application path: dwm.exe1
    Faulting module path: dwm.exe2
    Report Id: dwm.exe3
    Faulting package full name: dwm.exe4
    Faulting package-relative application ID: dwm.exe5

    Error: (03/16/2016 05:07:04 AM) (Source: Application Hang) (EventID: 1002) (User: )
    Description: The program Steam.exe version 3.33.99.41 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.

    Process ID: 1d08

    Start Time: 01d17f629bfe48bb

    Termination Time: 2

    Application Path: L:\Program Files (x86)\Steam\Steam.exe

    Report Id: 72016380-eb56-11e5-9c2d-dcef09d2dcc6

    Faulting package full name:

    Faulting package-relative application ID:

    Error: (03/16/2016 05:01:54 AM) (Source: Application Hang) (EventID: 1002) (User: )
    Description: The program Steam.exe version 3.33.99.41 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.

    Process ID: 1f24

    Start Time: 01d17f625869c95e

    Termination Time: 3

    Application Path: L:\Program Files (x86)\Steam\Steam.exe

    Report Id: b8ff84d1-eb55-11e5-9c2d-dcef09d2dcc6

    Faulting package full name:

    Faulting package-relative application ID:

    Error: (03/16/2016 04:28:30 AM) (Source: Application Hang) (EventID: 1002) (User: )
    Description: The program Steam.exe version 3.33.99.41 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.

    Process ID: 203c

    Start Time: 01d17f5d94d79d01

    Termination Time: 4

    Application Path: L:\Program Files (x86)\Steam\Steam.exe

    Report Id: 0de8fdad-eb51-11e5-9c2d-dcef09d2dcc6

    Faulting package full name:

    Faulting package-relative application ID:

    Error: (03/16/2016 04:25:57 AM) (Source: HiRezSoftwareManagerSvc) (EventID: 0) (User: )
    Description: Service cannot be started. System.InvalidOperationException: Could not start IPC server
       at Hirez.Patcher.HiPatchService.InternalStart()
       at Hirez.Patcher.HiPatchService.OnStart(String[] badDontWorkMicrosoftBugArgs)
       at System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)

    Error: (03/16/2016 04:25:50 AM) (Source: MSMQ) (EventID: 2199) (User: )
    Description: Message Queuing Service failed to listen on both IPv4 and IPv6 protocol. Messages will not be accepted from the network through TCP/IP protocols.  Messages addressed to this machine using TCP/IP protocols will not arrive but will accumulate in sender's outgoing queues.   Please fix the TCP/IP protocols issue and restart the computer.

    Error: (03/16/2016 03:54:23 AM) (Source: Application Hang) (EventID: 1002) (User: )
    Description: The program Steam.exe version 3.33.99.41 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.

    Process ID: 1d24

    Start Time: 01d17f58f4606c62

    Termination Time: 4

    Application Path: L:\Program Files (x86)\Steam\Steam.exe

    Report Id: 4a2bace3-eb4c-11e5-9c2c-dcef09d2dcc6

    Faulting package full name:

    Faulting package-relative application ID:

    Error: (03/16/2016 01:03:15 AM) (Source: Application Error) (EventID: 1000) (User: )
    Description: Faulting application name: dwm.exe, version: 10.0.10586.0, time stamp: 0x5632d756
    Faulting module name: combase.dll, version: 10.0.10586.103, time stamp: 0x56a849ab
    Exception code: 0xc0000005
    Fault offset: 0x0000000000067e3c
    Faulting process id: 0x184
    Faulting application start time: 0xdwm.exe0
    Faulting application path: dwm.exe1
    Faulting module path: dwm.exe2
    Report Id: dwm.exe3
    Faulting package full name: dwm.exe4
    Faulting package-relative application ID: dwm.exe5

    Error: (03/16/2016 01:02:43 AM) (Source: HiRezSoftwareManagerSvc) (EventID: 0) (User: )
    Description: Service cannot be started. System.InvalidOperationException: Could not start IPC server
       at Hirez.Patcher.HiPatchService.InternalStart()
       at Hirez.Patcher.HiPatchService.OnStart(String[] badDontWorkMicrosoftBugArgs)
       at System.ServiceProcess.ServiceBase.ServiceQueuedMainCallback(Object state)


    System errors:
    =============
    Error: (03/16/2016 08:58:18 PM) (Source: Service Control Manager) (EventID: 7024) (User: )
    Description: The WinHTTP Web Proxy Auto-Discovery Service service terminated with the following service-specific error:
    %%10044

    Error: (03/16/2016 08:54:16 PM) (Source: Service Control Manager) (EventID: 7024) (User: )
    Description: The WinHTTP Web Proxy Auto-Discovery Service service terminated with the following service-specific error:
    %%10044

    Error: (03/16/2016 08:50:14 PM) (Source: Service Control Manager) (EventID: 7024) (User: )
    Description: The WinHTTP Web Proxy Auto-Discovery Service service terminated with the following service-specific error:
    %%10044

    Error: (03/16/2016 08:49:45 PM) (Source: Service Control Manager) (EventID: 7024) (User: )
    Description: The WinHTTP Web Proxy Auto-Discovery Service service terminated with the following service-specific error:
    %%10044

    Error: (03/16/2016 08:48:43 PM) (Source: Service Control Manager) (EventID: 7024) (User: )
    Description: The WinHTTP Web Proxy Auto-Discovery Service service terminated with the following service-specific error:
    %%10044

    Error: (03/16/2016 08:46:12 PM) (Source: Service Control Manager) (EventID: 7024) (User: )
    Description: The WinHTTP Web Proxy Auto-Discovery Service service terminated with the following service-specific error:
    %%10044

    Error: (03/16/2016 08:42:10 PM) (Source: Service Control Manager) (EventID: 7024) (User: )
    Description: The WinHTTP Web Proxy Auto-Discovery Service service terminated with the following service-specific error:
    %%10044

    Error: (03/16/2016 08:38:10 PM) (Source: Service Control Manager) (EventID: 7024) (User: )
    Description: The WinHTTP Web Proxy Auto-Discovery Service service terminated with the following service-specific error:
    %%10044

    Error: (03/16/2016 08:34:10 PM) (Source: Service Control Manager) (EventID: 7024) (User: )
    Description: The WinHTTP Web Proxy Auto-Discovery Service service terminated with the following service-specific error:
    %%10044

    Error: (03/16/2016 08:33:19 PM) (Source: Service Control Manager) (EventID: 7024) (User: )
    Description: The WinHTTP Web Proxy Auto-Discovery Service service terminated with the following service-specific error:
    %%10044


    CodeIntegrity:
    ===================================
      Date: 2016-03-15 21:01:05.802
      Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

      Date: 2016-03-15 21:01:05.788
      Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

      Date: 2016-03-15 21:01:05.772
      Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

      Date: 2016-03-15 21:01:00.052
      Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

      Date: 2016-03-15 21:00:59.988
      Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

      Date: 2016-03-15 21:00:47.380
      Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

      Date: 2016-03-15 21:00:47.308
      Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

      Date: 2016-03-14 19:48:27.042
      Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

      Date: 2016-03-14 19:48:27.025
      Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

      Date: 2016-03-14 19:48:27.006
      Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.


    ==================== Memory info ===========================

    Processor: Intel® Core™2 Quad CPU Q6600 @ 2.40GHz
    Percentage of memory in use: 30%
    Total physical RAM: 8125.94 MB
    Available physical RAM: 5640.18 MB
    Total Virtual: 16317.94 MB
    Available Virtual: 13834.38 MB

    ==================== Drives ================================

    Drive c: () (Fixed) (Total:111.25 GB) (Free:40.2 GB) NTFS
    Drive d: (USBoot) (Removable) (Total:119.25 GB) (Free:116.89 GB) NTFS
    Drive e: (Programs-32) (Fixed) (Total:140 GB) (Free:34.57 GB) NTFS
    Drive f: (GAMES-32) (Fixed) (Total:108.49 GB) (Free:68.97 GB) FAT32
    Drive g: (Programs) (Fixed) (Total:215.28 GB) (Free:64.03 GB) NTFS
    Drive j: (Data) (Fixed) (Total:1056 GB) (Free:808.47 GB) NTFS
    Drive k: (The Sims) (Fixed) (Total:200 GB) (Free:181.88 GB) NTFS
    Drive l: (Games) (Fixed) (Total:1226.39 GB) (Free:595.76 GB) NTFS
    Drive p: (Photoshop) (Fixed) (Total:111.79 GB) (Free:110.06 GB) NTFS

    ==================== MBR & Partition Table ==================

    ========================================================
    Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 931.5 GB) (Disk ID: E3C4142E)
    Partition 1: (Not Active) - (Size=931.5 GB) - (Type=42)

    ========================================================
    Disk: 1 (MBR Code: Windows 7 or 8) (Size: 111.8 GB) (Disk ID: 9C80D4A7)
    Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
    Partition 2: (Not Active) - (Size=111.3 GB) - (Type=07 NTFS)
    Partition 3: (Not Active) - (Size=450 MB) - (Type=27)

    ========================================================
    Disk: 2 (Size: 2794.5 GB) (Disk ID: 63DE31EF)

    Partition: GPT.

    ========================================================
    Disk: 3 (MBR Code: Windows 7 or 8) (Size: 111.8 GB) (Disk ID: 64B90D90)
    Partition 1: (Not Active) - (Size=111.8 GB) - (Type=07 NTFS)

    ========================================================
    Disk: 4 (MBR Code: Windows 7 or 8) (Size: 119.3 GB) (Disk ID: 051C97FC)
    Partition 1: (Active) - (Size=119.2 GB) - (Type=07 NTFS)

    ==================== End of Addition.txt ============================

     

     

    I think I am going to try and reinstall windows - I bought a new USB drive and am trying to install the Windows Media Creation Tool, but apparently you have to already have a working Win 8 or 10 system (with an active internet connection) to use it, so this is going to be difficult. I have also discovered that the dvd drive is now completely missing so I can't even download and use the ISO to reinstall.


    • 0

    #8
    RKinner

    RKinner

      Malware Expert

    • Expert
    • 20,007 posts
    • MVP
     
    Download the attached fixlist.txt to the same location as FRST
     
    Attached File  fixlist.txt   10.61KB   75 downloads
     
    Run FRST and press Fix
    A fixlog.txt will be generated in the dame folder where FRST lives.  please post that 

    • 0

    #9
    robyrob

    robyrob

      New Member

    • Topic Starter
    • Member
    • Pip
    • 6 posts

    I really appreciate all of your help, but after increasing problems even attempting to do any fixes, I ended up just reinstalling windows. It worked great for a couple of hours and then the problems returned. This was a full disk wipe clean reinstall - nothing left. So I assumed it was a hardware problem after all, so I disabled the onboard LAN in the BIOS and then did ANOTHER clean install of Windows 10 from a USB drive - they really make it a pain if you don't have a working internet connection - and it has been working great for a couple of days now.


    • 0

    #10
    RKinner

    RKinner

      Malware Expert

    • Expert
    • 20,007 posts
    • MVP

    OK.  Thanks for the feedback.


    • 0






    Similar Topics

    0 user(s) are reading this topic

    0 members, 0 guests, 0 anonymous users

    As Featured On:

    Microsoft Yahoo BBC MSN PC Magazine Washington Post HP